
From nobody Thu Feb  2 08:28:22 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D45B11297A5 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 08:28:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.689
X-Spam-Level: 
X-Spam-Status: No, score=-2.689 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_FREEMAIL_DOC_PDF=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VmwmwRoynA_i for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 08:28:19 -0800 (PST)
Received: from mail-oi0-x234.google.com (mail-oi0-x234.google.com [IPv6:2607:f8b0:4003:c06::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5795A129712 for <sacm@ietf.org>; Thu,  2 Feb 2017 08:28:19 -0800 (PST)
Received: by mail-oi0-x234.google.com with SMTP id w204so12219812oiw.0 for <sacm@ietf.org>; Thu, 02 Feb 2017 08:28:19 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to;  bh=VIMXMn5RenQSN4kVFtn2ODpDFgOpXov7DUSYPbdT9Q4=; b=KKRC9SgdfyrgzlH3djOD+E6sroIrm0SAkZMDL8L/M6podx1oE+drxPPCnfMe/TarHu 3jBL62t0FDqC1vmqd0WHuxlteF5UAYgnaSnO6ftnV/OKTdJ+fzn1HZnguPQZuknRsJS/ jEcJRapsN9HVn03xJ2MfSmM+5z3paFRBf95a04FQfMuXUMZgSKQ7bAPqxNeljfYoqJoo MXnZcC/4vLjTjvBIkfcRSAwCCJTPhU7/ry4m213jBd2fg+qNOuy6wYqQbhjxmicU4Y+J P0w27ohQ3PVxGj++OVmNUEAOBtZ45Tww9gu1ueD+c5SGNEe3L03yYy+rydjSIAUpchqp CJXA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=VIMXMn5RenQSN4kVFtn2ODpDFgOpXov7DUSYPbdT9Q4=; b=L3eq5hGBkyYPekommjtG+nhXSYRGMjIChOzOjTYWJjuNFCjX/mu8imvdlpRK8012Nv M+KC+WXjoz3pBnJvgYhoTqC2ggHXKj/fMGg0YyND2PBZBkrtzLQBPeeUMk63R8vlAJOS TsUtMimGVLW89mkYiiPKZzkjuUyrfNjqnQVloFr3jITZvziq4jam7Iz2tf8NDOFRzLCm d7G9LGpmHyA3eOuSD+RCqGpKcLi6vE+Lra0vFDJeyEvBk3YUaAgnZLnOGxYb8xMteU/h BAgCs36j+JRz/WwM/Ej8RlJn8d6IHVN9il7iSmlfzsEFuE8uokxqtrYZ8EroTw9IaaoA ulGA==
X-Gm-Message-State: AIkVDXJSdFw4Df9CnUhw0TV5dt1JTirkfmShfMHShg88SEvp/IuBtYABf8fWpZHGABpW3DvCqDDummbKpRkjEg==
X-Received: by 10.202.237.139 with SMTP id l133mr4755271oih.55.1486052898124;  Thu, 02 Feb 2017 08:28:18 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com>
In-Reply-To: <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 16:28:07 +0000
Message-ID: <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com>
To: "sacm@ietf.org" <sacm@ietf.org>
Content-Type: multipart/mixed; boundary=001a113d328a1cf76705478ea7ea
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/vKILA0gyPIEHxiHBfxDm6XKxBGM>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 16:28:22 -0000

--001a113d328a1cf76705478ea7ea
Content-Type: multipart/alternative; boundary=001a113d328a1cf76505478ea7e8

--001a113d328a1cf76505478ea7e8
Content-Type: text/plain; charset=UTF-8

Hi Everyone.  A few of us were able to make the vulnerability scenario call
today and I think we had a good, though at times spirited, discussion.  We
did record the meeting, which is available at [1].  We discussed the
attached (annotated with some meeting notes) UML-ish sequence diagram.  I
had created that diagram to start a conversation (mission accomplished on
that front I think) -- a conversation that would lead us toward identifying
the discrete components, interfaces, and information required to be sent
over those interfaces.  The UML-ish diagram represents a *single* flow
through the system -- a "one-time" flow through the system.  It ignores,
for the time being, the continuous aspect of our charter in favor of
getting started with the basics.  Once we have a good understanding of the
basics -- the components, interfaces, and information required -- we can
start look at a continuous monitoring sequence (which could be represented
as a distinct diagram) to determine what more we need.  Then, I think, we
can start drafting solutions.

One of the first issues is that we need to figure out if the components in
the base flow are accurate.  The main suggestion we've tossed around so far
is to combine the Endpoint Repository with the Assessment Result Repository.

We talked briefly about what interface we could use for the VDD Repository,
and naturally ROLIE came up as an option.

We talked a little bit about the first "get endpoints" operation between
the Vulnerability Assessor and the Endpoint Repository -- specifically
about whether we should represent on this sequence diagram that information
supporting a judgement of "stale" would be needed.

We left open the time when we would next meet, favoring to work that out
on-list.  Next week is TCG, so that may be difficult; the following week is
RSA, so that may be difficult.

For those who were in attendance today, please add to this note with your
comments/corrections.

Kind regards,

Adam

[1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E

On Mon, Jan 30, 2017 at 11:21 AM Adam Montville <adam.w.montville@gmail.com>
wrote:

> Hi everyone.  Just a friendly reminder that we are planning to meet again
> this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC) using SACM's
> meeting room at https://ietf.webex.com/meet/sacm.
>
> Kind regards,
>
> Adam
>
>
> On Thu, Jan 19, 2017 at 11:35 AM Adam Montville <
> adam.w.montville@gmail.com> wrote:
>
> Hello. A few of us met informally today to discuss the vulnerability
> scenario in some more detail with the goal of maintaining the narrow focus
> on a vulnerability assessment slice through our notional environment.  We
> are tending to look at major components as black boxes with interfaces and
> data format expectations, and we are not necessarily concerned with how
> those components do things internally/behind the scenes.
>
> The meeting was recorded (you can find it with today's date at [1]).  The
> topic of discussion was primarily in the "phase 1" area of what Danny sent
> to the list not very long ago [2], and resulted in a *starting point*
> diagram [3].
>
> The group who met today are (roughly) agreed on the six main "components"
> represented in that diagram, but also see that we have some work ahead.
> Specifically, we quickly recognized that some of the assumptions the
> vulnerability draft makes may be assumptions we cannot afford to make and
> need to include in the exploration.
>
> We thought it would be a good idea to have another informal discussion in
> a couple of weeks (February 2) at the same time (10am Eastern / 3pm UTC),
> using the same WebEx [4].   At that time we intend to roll through the
> vulnerability assessment scenario assumptions in an effort to determine
> which ones can be left as assumptions and which ones cannot.  Then we'll
> take another look at the diagram and work on its next version.
>
> Stay tuned.
>
> Thanks to Danny, Stephen, and Jerome for joining and contributing!
>
> Kind regards,
>
> Adam
>
>
> [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> [2] https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> [3] https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> [4] https://ietf.webex.com/meet/sacm
>
>

--001a113d328a1cf76505478ea7e8
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi Everyone.=C2=A0 A few of us were able to make the vulne=
rability scenario call today and I think we had a good, though at times spi=
rited, discussion.=C2=A0 We did record the meeting, which is available at [=
1].=C2=A0 We discussed the attached (annotated with some meeting notes) UML=
-ish sequence diagram.=C2=A0 I had created that diagram to start a conversa=
tion (mission accomplished on that front I think) -- a conversation that wo=
uld lead us toward identifying the discrete components, interfaces, and inf=
ormation required to be sent over those interfaces.=C2=A0 The UML-ish diagr=
am represents a *single* flow through the system -- a &quot;one-time&quot; =
flow through the system.=C2=A0 It ignores, for the time being, the continuo=
us aspect of our charter in favor of getting started with the basics.=C2=A0=
 Once we have a good understanding of the basics -- the components, interfa=
ces, and information required -- we can start look at a continuous monitori=
ng sequence (which could be represented as a distinct diagram) to determine=
 what more we need.=C2=A0 Then, I think, we can start drafting solutions.=
=C2=A0<div><br></div><div>One of the first issues is that we need to figure=
 out if the components in the base flow are accurate.=C2=A0 The main sugges=
tion we&#39;ve tossed around so far is to combine the Endpoint Repository w=
ith the Assessment Result Repository.</div><div><br></div><div>We talked br=
iefly about what interface we could use for the VDD Repository, and natural=
ly ROLIE came up as an option.</div><div><br></div><div>We talked a little =
bit about the first &quot;get endpoints&quot; operation between the Vulnera=
bility Assessor and the Endpoint Repository -- specifically about whether w=
e should represent on this sequence diagram that information supporting a j=
udgement of &quot;stale&quot; would be needed.</div><div><br></div><div>We =
left open the time when we would next meet, favoring to work that out on-li=
st.=C2=A0 Next week is TCG, so that may be difficult; the following week is=
 RSA, so that may be difficult.</div><div><br></div><div>For those who were=
 in attendance today, please add to this note with your comments/correction=
s.</div><div><br></div><div>Kind regards,</div><div><br></div><div>Adam</di=
v><div><div><br></div><div>[1]=C2=A0<a href=3D"https://drive.google.com/ope=
n?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E">https://drive.google.com/open?id=3D0B8=
Wf9Un5FdCbWGhDOHpVR0tMd1E</a>=C2=A0</div></div><br><div class=3D"gmail_quot=
e"><div dir=3D"ltr">On Mon, Jan 30, 2017 at 11:21 AM Adam Montville &lt;<a =
href=3D"mailto:adam.w.montville@gmail.com">adam.w.montville@gmail.com</a>&g=
t; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr" class=3D=
"gmail_msg">Hi everyone.=C2=A0 Just a friendly reminder that we are plannin=
g to meet again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)=
 using SACM&#39;s meeting room at <a href=3D"https://ietf.webex.com/meet/sa=
cm" class=3D"gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/sacm<=
/a>.=C2=A0<div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=
=3D"gmail_msg">Kind regards,</div><div class=3D"gmail_msg"><br class=3D"gma=
il_msg"></div><div class=3D"gmail_msg">Adam</div></div><div dir=3D"ltr" cla=
ss=3D"gmail_msg"><div class=3D"gmail_msg"><br class=3D"gmail_msg"><br class=
=3D"gmail_msg"><div class=3D"gmail_quote gmail_msg"><div dir=3D"ltr" class=
=3D"gmail_msg">On Thu, Jan 19, 2017 at 11:35 AM Adam Montville &lt;<a href=
=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank=
">adam.w.montville@gmail.com</a>&gt; wrote:<br class=3D"gmail_msg"></div><b=
lockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;border=
-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr" class=3D"gmail_msg"=
>Hello. A few of us met informally today to discuss the vulnerability scena=
rio in some more detail with the goal of maintaining the narrow focus on a =
vulnerability assessment slice through our notional environment.=C2=A0 We a=
re tending to look at major components as black boxes with interfaces and d=
ata format expectations, and we are not necessarily concerned with how thos=
e components do things internally/behind the scenes.<div class=3D"gmail_msg=
"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">The meeting was re=
corded (you can find it with today&#39;s date at [1]).=C2=A0 The topic of d=
iscussion was primarily in the &quot;phase 1&quot; area of what Danny sent =
to the list not very long ago [2], and resulted in a *starting point* diagr=
am [3].<div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D=
"gmail_msg">The group who met today are (roughly) agreed on the six main &q=
uot;components&quot; represented in that diagram, but also see that we have=
 some work ahead.=C2=A0 Specifically, we quickly recognized that some of th=
e assumptions the vulnerability draft makes may be assumptions we cannot af=
ford to make and need to include in the exploration.</div><div class=3D"gma=
il_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">We thought i=
t would be a good idea to have another informal discussion in a couple of w=
eeks (February 2) at the same time (10am Eastern / 3pm UTC), using the same=
 WebEx [4]. =C2=A0 At that time we intend to roll through the vulnerability=
 assessment scenario assumptions in an effort to determine which ones can b=
e left as assumptions and which ones cannot.=C2=A0 Then we&#39;ll take anot=
her look at the diagram and work on its next version.</div><div class=3D"gm=
ail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">Stay tuned.=
</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"=
gmail_msg">Thanks to Danny, Stephen, and Jerome for joining and contributin=
g!</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=
=3D"gmail_msg">Kind regards,</div><div class=3D"gmail_msg"><br class=3D"gma=
il_msg"></div><div class=3D"gmail_msg">Adam<br class=3D"gmail_msg"><div cla=
ss=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg"><br=
 class=3D"gmail_msg"></div><div class=3D"gmail_msg">[1]=C2=A0<a href=3D"htt=
ps://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" class=3D"gmai=
l_msg" target=3D"_blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E</a></div><div class=3D"gmail_msg">[2]=C2=A0<a href=3D"https:/=
/mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM" class=3D"g=
mail_msg" target=3D"_blank">https://mailarchive.ietf.org/arch/msg/sacm/_LiK=
lyvAws_OVLFhB5NSU58MXDM</a></div><div class=3D"gmail_msg">[3]=C2=A0<a href=
=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc" class=
=3D"gmail_msg" target=3D"_blank">https://drive.google.com/open?id=3D0B8Wf9U=
n5FdCbMU5pdTRjejJtNHc</a></div><div class=3D"gmail_msg">[4] <a href=3D"http=
s://ietf.webex.com/meet/sacm" class=3D"gmail_msg" target=3D"_blank">https:/=
/ietf.webex.com/meet/sacm</a>=C2=A0</div><div class=3D"gmail_msg"><br class=
=3D"gmail_msg"></div></div></div></div></blockquote></div></div></div></blo=
ckquote></div></div>

--001a113d328a1cf76505478ea7e8--

--001a113d328a1cf76705478ea7ea
Content-Type: application/pdf; 
	name="vulnerability_scenario_sequence_diagram_v2.pdf"
Content-Disposition: attachment; 
	filename="vulnerability_scenario_sequence_diagram_v2.pdf"
Content-Transfer-Encoding: base64
Content-ID: <159ffa4c9e49659e75e1>
X-Attachment-Id: 159ffa4c9e49659e75e1

JVBERi0xLjMKJcTl8uXrp/Og0MTGCjQgMCBvYmoKPDwgL0xlbmd0aCA1IDAgUiAvRmlsdGVyIC9G
bGF0ZURlY29kZSA+PgpzdHJlYW0KeAErVAhUKFTQD0gtSk4tKClNzFEoygQKGBqaGSoYAKGZAYg0
UEjOVdD3zDVUcMkHaggEAKGcDh4KZW5kc3RyZWFtCmVuZG9iago1IDAgb2JqCjU2CmVuZG9iagoy
IDAgb2JqCjw8IC9UeXBlIC9QYWdlIC9QYXJlbnQgMyAwIFIgL1Jlc291cmNlcyA2IDAgUiAvQ29u
dGVudHMgNCAwIFIgL01lZGlhQm94IFswIDAgMTE2MSA2MDBdCi9Sb3RhdGUgMCA+PgplbmRvYmoK
NiAwIG9iago8PCAvUHJvY1NldCBbIC9QREYgL0ltYWdlQiAvSW1hZ2VDIC9JbWFnZUkgXSAvWE9i
amVjdCA8PCAvSW0xIDcgMCBSID4+ID4+CmVuZG9iago3IDAgb2JqCjw8IC9MZW5ndGggOCAwIFIg
L1R5cGUgL1hPYmplY3QgL1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAxMTYxIC9IZWlnaHQgNjAwIC9J
bnRlcnBvbGF0ZQp0cnVlIC9Db2xvclNwYWNlIDkgMCBSIC9TTWFzayAxMCAwIFIgL0JpdHNQZXJD
b21wb25lbnQgOCAvRmlsdGVyIC9GbGF0ZURlY29kZQo+PgpzdHJlYW0KeAHs3QXc5UX1P3CVEumS
7gaRULqRBulupBuERaRRSkJEQEA6JKRBShpEERBEEFB0EezE7p/zf8OB4fu/99lnn7rP3t0997Wv
Z+fOnTjzmfnO93zmnJkpJT+JQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAI
JAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgk
AolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQC
iUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJ
QCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolA
IpAIJAKJQCKQCCQCicCgEPj73//+pS996bOf/eyJJ5542mmnnXrqqQK+PvDAA9/61reuu+66QZXe
yHzvvfd+9atfbUQMU/C3v/3tWWeddc455/zf//1fe5V/+MMfLr300tdee639p7Er5k9/+tNll132
yiuv9FHs//73v08++eQ111zTx/SR7F//+tcNN9xw22231Vz/+9//fvrTn4L39ddff/bZZz/3uc/F
+PniF79oCBldkfLf//633n/sscdqxs4FCKmi4447jjydqyVLTgQSgUQgEUgEEoFEIBFIBIYWgT//
+c/77LPPxz/+8Y033niSSSaZe+65N9lkkw022ODyyy+nY6+xxhr9rY6ivuqqq6I8LRmRvoMOOqgl
stNfaelYwwc/+MFLLrkEiYjqRJ533nlHHHGEGFzmQx/60EMPPdRpSTpd/i9/+cvtt9/+0Ucf7b0i
XGm//fa76qqrgICJr7baar2nb/n1H//4x+GHHz7vvPP+8Y9/jJ+Uc8opp8w888y/+tWvFDjRRBNt
vvnmW2655eqrrz7PPPNsuummBJPyL3/5y/LLLy9vs0BZdtxxx29/+9vNyMGHf/GLX6y44oqbbbbZ
D3/4w8GXliUkAolAIpAIJAKJQCKQCCQCw4/A0ksvffzxx9d6qdwbbrghY9OPfvQj6m6NF/jrX/9K
7/3973/fjBRmi3n88cc/8IEPMFgISyD7b37zm9/97neU86rPS8nIEtnFV9KE1kkZ5VcjlwTqqlxP
YmF/o9gWAd54443vf//7yol4Kffcc8+NNtqomm/Eq2L//fdff/31/appyyyzzDe+8Q3GNWHUoxbI
0DNy5Mif//znNaYG/ITSkkErqsUtBNNq5StNYjE/+clPXnzxRYlrXpG//vWvn3/+eX+bkcqR2K81
knja8rOf/azGwOTHP/7xD37wg2Zz4lc/Sf/Pf/7TV2Ft6TGZ5qy00kpHHnkkoBgTcXACv/rqqy3N
1L9Ia/RFrT1KfuaZZxCxu+66K+JZ6/B3dC+43nLLLRfxZHjhhReWWmqp3XffXRU6UbKjjjqqliaB
ohZddNFrr70W7CQ3PP7zn//AwV84GB6gq/AGsIEeEFQXRUVKQEUTJHv66acVe8899yhHGilBARC9
5qv00COPGo0TYfUSBoVEFSVQgo4IRhlV5N9EIBFIBBKBRCARSAQSgURgmBH4yEc+cvTRR9dKOaeJ
2XnnnT/60Y8uvPDCDE/xExsT9X7JJZekh19wwQXU2pqFcrvWWmtNMMEEEuAUW221Fa63yCKLfPnL
Xz7jjDMOOOAAKf/2t7+x07FVfexjHzvssMO22GILnIL+fOCBBy622GIUeMY1kaEnc4NcYYUV1LXs
sstefPHF9GpK9bbbbvvpT3+a+s0Vs1ZND7/pppuIqmTp+WTSvTlkzj777KiEdlG5JaafsxnNMccc
TGmf+cxnKOHauNNOO6lXgUwtSKgWIQUIHWahjexrZK4VKYdxij1o7733JpvqJCC/NCGYXNz50DEN
WXzxxSVgRgx7ltpB8eEPf3ihhRYianh4YkCoDTFQ4x122AFfUAVmgTPKLvKkk04Sg0ypEURLLLHE
uuuu+73vfa+KJIBKbLPNNhz5cCVsSDIgoJ/4UU0GkJNPPnnqqadeYIEFVH3++edLs8suu6iCSBde
eKGUKnr44YcJrBU6EcJiagkC2sXAusceewgHvZplllnuv/9+CLCakbnS24Aa/uhVOzVTDpPZZJNN
Jgtwbr/9duB/4hOfYMgDyFe+8hX4aL7PwQcfjEBhXvqIm+Iqq6xiNBpauLlO/9rXvkZ+yZQDdsm2
3nrrKaaYYs0112SPe/nll0mrdRJst912uLZuYhEWBpef7rvvPl0Jf8UaY4arXgOL2q+44opmwzOc
CCQCiUAikAgkAolAIpAIDBsCLdSMVWXCCSe88sormRUQqxlnnJExheo7//zzY2RUXJuJKN5f//rX
q4R09W9+85uU/+9+97vC9OH55pvv5ptvRitov5iClLRrJIhZjdpMf55uuun8igYuuOCC3/nOdxjI
qMpTTTUVasaaw3fOFip1Uf4JwLxF80d2KNt33HEH5TyqRtlwEHVddNFFEmMo2AfVmv7PaqZAVVQh
NQcN5LcpQFfnd8efk1WF5QWjOf3007EbomIEDDfPPfccdsaAWLOjKmxGE088MR0ejyPYXHPNBRDs
A0fAuW699VYo4X3wDHufJoOCKQ04WOH111+v6jPPPFOTNZMtCZ9FElEY5A5rwFUxlBNOOEFdmkwA
BqYbb7xRw9npiAdM9Fara/PFYxN33303zgUcAqhir732CjpchcfguBoee+yxupKrJ2aE8IIRqdGV
DHkwD2qpFrRFc2wuq9kFEC5Z9CACFXQMkUGd2qmZAWA7G16MIrVTM78aA/JCQ5+iS/xpMW6Uk/A8
EnFYaTQfvMYYyaecckq9xgTGLsbzFpdULHaMEgLKaNQ0/QUrCCD1sqBp6J526QhsDhkEiy6eZppp
sFR16T4kHUoS8LnF6chgZOLymBqUmm3PcCKQCCQCiUAikAgkAolAIjA8CLRQM3QJ14iqWZGmn356
PMKhGQgF5oUK0Wap0GhOUzyOcNNOO62UIvERhcSvtF9GCmxC9mqAYxvCjGjOUtr/FSnxF4o3voA7
sI+89NJL3P9oyxjKIYccghrgBdhBs1K84Oyzz6aZU+bFYwqYC7Wczv/JT34S2WkmFknxRoIIwzVO
FVhe5Np11101B0Occ845yYasqVqlqlZvFBLUjNg4QuTC/mywQhOgQb0XSf9feeWV8R1htSCAakEW
0AGcKygV2oi0ap3mSBnNhAwjFLRxw7XXXptJCE1TsgZKPNNMM6EVpNLAJmtQIGpGSDI7o0Oyz3/+
8wppSUYYudZbbz1EW4GoN/ahXbIrU5NlYa4iz1NPPaV/MZd11lnHFjYZ60dioOkgNJBgLFnHHHOM
X9upmZTQm3XWWTHlSNl0aKwyI0dkMK6MAXxQUb4aRQYAMXQ0wW655RaDBKt95JFHJNAKHA3BVKxO
hxVhsG/x7GhYNpaKvuFoTGmxl43FEGUOsmyo6AX9KDETIR6HJAoz3mH0qiaAzgKOltaGZyARSAQS
gUQgEUgEEoFEIBEYNgRaqBlTEce5qJ3SzvzBnCGSxcEeJfqwv1R31p+mhAgLahZ70yjbvAfjV9SM
9YouPdtss9VjN2JbkCysY7TrWhciQxV3agSLhlqwCdURRl2IFbMONbtZqUi+kYhVRNLDeaYxyYln
/GqnZjgCfzbsgBqPfobCj8jwGLQNjY1m0kknxYxU6mPDHeEZ46JwOjyrGR7EKCNGXcxb0qBaPAAZ
GUUCij3ozjvvjCy+4giseHhfk+mEAODC6SqkjDthQdttt92wBnwEzWRxwxcQN66GWKEjNbC2KNzf
SnNESsZ0yD1PMhalimokRl7AiN9hUuhb9K/sqBljKC6GtenfaHiI5DSYWlEEQMHNFSHFvHAZBEp8
OzUDFHl0NwrfIzXTTPQH2mRGzTRNFkVBkg+nnwjAw5M5D99E9g0SEkpAALwbvya5wtnCAIXB8SxF
0IKaMdixo0GAHVAWVTz44IM6BQtD+R1UIq9I1EyvGYGqZqFDS3WWtqBmukxR8uYnEUgEEoFEIBFI
BBKBRCARGGYE2qkZThQyBDVDuHjusZhgCtRX2iySRT9vyhnULM7BQM2CqkgQVjNWLZSh+sj5leKN
49iPVkkcGxbLkRI4quEL9PCoi2qNQSAXqBkzSrNS/Ih5DpmKSFnQQNRmVNTMORj4GuW8hZrxAETN
3BrA8IQ2qlfJGqiZEkfhrC04F08/zEIMQmdvlx1b2AeGFRuUOPvhbrCSQEYlYFiMRww9YTUTCUwE
BNfAONiGgKk6G/QUzpESZZAX0dBqCZgU2Q3REBnZ4HAQnEgzQySRYTWTF0QaJYbF59BDD0VygRDJ
/IUeNs1epq4WasYdlKUM+1Ny0BNtx1bgULNHgKh6UOeOGDEC/w1LpQL1Fz5VExMPsdIpfuqRmiFN
6I8GBjVDJwUUzj5oVLBdCrM/qgg1Q9Wb1AyBZa1D4gIotkUUj0GW1c9mPVYzhJG9DO9mOyOSbuIZ
a4SrFDWzmZHYQc3YN5vUTBcQOKlZ7ccMJAKJQCKQCCQCiUAikAgMPwJMDzba1HqZS+yBiq8Ufg6N
1Fq8wJ4vJ0hgFtRXHKoe1hcpMQJ7gpzqQO9lg7CHKOL33Xdfthhh+jxuxahBqaYqK4H6bTeW2p94
4glOZQiOKqjifPwE2FPUpRYWNBSJjm1HmBM/otj4S82mgbOb2H9kxxbiZoMS7z6sBCWkxjcTYxw2
grGV4FZYjFM1woqnZPuSsDPMiAwsXIoiJ5LVPLgSNVMysxpHRyq9ulAG3AH7QDTo/+pSL/bERsPz
E59C91SnfK1DOpxJiOqy0CEyyJeNY/gaPzqRCCODDnaAZfC749Rn85RkOKwTORSoRmiwbSEdlXMF
NQMmlORCTJSGXvGuJDyiUZuPmjneBGlFh5kgESs/yY6UIY/qUj6OphAEB9FD03q8+4wNi4STTz55
HB6iELWoDhRyYUm4G16mczXZr8DBvGBSJRHQTDLjiYgVcsrCFdRMXhkxWQMA/3LgpzGAe4KuWs2c
GYJfawVpyYDIGwAaqzukNJbwMkDxocWa9bKhxUTIhIrNQY8/ZFAzXS8X2osGElWjNFxbWBuNUjA2
Bc5wIpAIJAKJQCKQCCQCiUAiMDwIcBJjUKh10Za50sVXhMuuIlTFV7o35R95oVdLU9NHAPHBL5AI
ircCcbSI5wmJJQlLwFMRs2BPoV3jWfRqOjlWqFhkMCIxC4kZUNSiLunDIIVcoFp81aLY+lcJzmNU
LxKEIrFY0b3VxZTzqU99qiYTwK0Yg2jvmALt3aazMAxJzDXR0Y4ycntzgCS/QUXFoRm1BNkxIGY+
zSSYcsKlk5HISY+1vVgVzhXycMzDbZVASIiJlJFFEtFAi/AL/oEaiCPghhoeliOcEZ0Rj1AoXIE8
90DEyiN7OGFWqRTCVRKdkYxgckkGCjE1TQjAOklmf52/Ef1LBv2LOAdD0TpkUBXkibM4miVEGFaY
uyqw9YjRNPzRQSUMnT66VaNsG4xfg/Y2R5f4ILBERdINKhxKw8VjasKKwhyRaOPBOS2MaLxG8dzI
yCB47rnnSq8VzGqcISGjp5SJmhl4yKaeQo21S3OIqjuQbkiS0w5EvSw74xo5kXSJkTuUzZqAtrgD
AoyKCvnzbyIwbAj8tfz1rnLXV8tXf1F+8Urp9+LA0+Xpm8vNVdo/lD+cWc4cWUbWmCEP/KD84Lhy
XLPYN8obp5fTmzE1/JXyle+XNyfD/n5eKO8eNtvfvB1N/2p59e7CHf/uR8ojPy4D2Z365/Ln88p5
z5Xn2uX8TvlOFP5EeeLX5d37VtpT9j2mZYT0PWOmTAQSgUQgEehaBCjAzCtxaEOPQrKSUPh7/Amr
CgXbr9zPaOa0Zco5E0mkRw0YLGrhflUXY0ePpbVESsxEovaW+PavLCP4Qnt8jaG6MxHGeSY1UoA+
T0KsDaP0QYWavzbDEED9gs8249WLfzXxEWasaUmpyTDBcGteyaRBoHqXXDJcA2ijSia+aUqr5deA
/mUwYtGrMZ0L6Cy0qKV8TdBw5tSIF9AdLWnqV0OFwRHUNaYZUDg02vuxmSbDiUCXIPBYeWyzstnI
MhK7OauctWnZtL+CvVZeo3vXXH8pf1mprPRUeXNDaIc+vyy/nK5M1yz8n+Wfd5a3d9o244UfL49L
3xI52q9YyRxljn+Vdx0ARpulcwn+Xf7dQsF2KjvtXnb/dvn2hmXDfcu+/a0aGd+obISPy4iM/7e8
Ox/+p/xnnjLPl8uX7yn3LFYWu6q8vXe7v1U00zdHyMvl5eZPGU4EEoFEIBEYDxFgB+H2xhxjrxN/
udiQZadYHIf+hS98gbkkzjbsTnBQM7vhGJ5GxQW6U+yUKhFIBLocgZ+Xn89SZvl9+X2V8/Pl8xH+
P7cIlndXJ7AD8S06fP0av0ZGuv0mZZNKzWoav0ayZrEi/8fB2Z93Pj3Wq8z4vQZmK7OJaRZVZehR
1Jq9mUVkU7xIE38Z/pYty15TrmlGqr1mD0lq9hqQXnN8rTFSNsNKiPbWQFRR0/ja0oTPlM98vXy9
KcnR5ehjyjFiGLkmKBP8rby9C1hMs5ymwM3swruV3VAzCdYua1foIg1m/UB5QBgIy5Xlmhlr4YFD
RSPSBCY1fbPhUcVD5aEQuz195G0psBaVgUQgEUgEEoFxCQEWGVuZuBE6UDHuXNY6DnL80yKSv1k3
t5f5ho3GDqlq1+tmaVO2RCARGFsQuLJcuUxZpiltsAZOgNeWa2nvXyhf+Ef5xwHlgB3KDqwz85Z5
f1h+KA0GJwHbjV8PKgcdXg5XyDPlGYHrynWzl9lRM8mk8XXrsjX2d1m5bPmy/IHlwH3K217rsvCE
vKPcsWPZkdLua7NehrBPlk9uV7Y7qZy0YFlQOZwY5yvzqUXKWcusp5ZTFygLHFmO9PXycvnKZeV2
Ublorl5WZ1ATWLWs+uny6e3L9kuXpcMcdmI58b5y37ZlW01gN1ROfPAIbIhsK5YV34kr5L+13Lpu
WVdepOb2cvvB5WCMqaWZLEQXlgvPLecqoQnUr8qv1ixrHl+OV9eiZVEZ9y57L14WZ2RsKeHScimg
jipHLVmWBMhPyk8IfFg57KXytpsHkYKaITKSKTaE/Fb51v3l/kPLoReVi8RUgX9Xfqfv8CyG0W3K
NrDyK6ObVrCZTlumvbhc7KcoxN+gZujex8rHQBTxzcIZIucqc32pfAn+qpPgj+WPny2fvaBcsHHZ
+GflZ82G1xEisHPZmZlPX7ekRzBnLjMrcImyxFZlK+NBF7B1CjdZZ5UwA4lAIpAIJAKJQCKQCCQC
icA4hsCnyqe2LFu2NIpqvX558wClv5e/T1mmpLQjCzR5MceWY+nPyMJqZTUKf/gxUvVHlBF+pXVj
QAIMMagZBR6DQGeo69LgLIhV0yxC66arS/98ef5r5Wvt9SIme5W9JDi/nL9f2U/gi+WLQRZo8lR9
EjKfsf0Ff5GgRVQxu5RdwtcRkby6XC1mlbLKi+VFnnVrlTdPnUIzm6YcMdeX6200YyHi0/jd8l0x
PiuUFcjpq/hdy643lhvJjy61NFNLDymHsAEBpwWoPcoeuKqicNUbyg0CXEm/Ub7RUgKSiLshgA+W
B3ETyT5RPtFuNWOa1BCtq5DiX9DGyBYpiyBHTYEBiDopCs8VFghqJsB9sd1qpkMhfEm5RIL4tBQ+
Q5nht+W38J+qTKXT0e1vljf3+aLP8rY0vI4QSwFBpVvSyzh3mfv18uZOW66bOCn5gwxG7fk3EUgE
EoFEIBFIBBKBRCARGLcRsJ+InaKljbeV24KaiWc3YdXCaI4obx52yoh2RjlDwJkbHywfZB4S5vVH
G2f9manM5KuPDWuoGR4XTCQiESgughGOv6w2SEeNaa8Xf0FzJFBOsD+8g51IDMNcZGTOw0ewA6Yl
Me2i7ln2DGqGjGivNEgN3uS4EkYfYiMLbGdRWvxFHGy28m+LsgU+FZH3lntViqEgTfZn8fRjj9Oo
lmYqEF3CdxAuGZtAYZfaKBLfDJEwU1W3lICihhshGojtSt8jNUMnkTgixTY0Un2ofChEjb9NgftL
zTg03lRuWqospViltRfOahm12LPm2BCj6MnypBhmuI+Ujwg0Gx4jRGSlZu3p5y/z49pRJssmoLBI
BC1i8m8ikAgkAonA+IaAozwctdGhVjt/z/GGcWRih6poL5bHpiP36/kn7Ql6jHHMiDMqnb5Yf3Wo
hbMKHe3OL9QZ9VdffbWDKx236HawemDI/946cdGh935yeYESHAVpi1wtZHgCxHDaoVun+3Iqy4BF
Aoi2a6bGOlUmWg0Qp+I7oQXmvZzTMuBKM2Mi0AkEqNwzlhkZbmrhCAXXOzaR0Ip59LFlOAuiSc0w
AvThR+VHjErO+mPbCt7E8BE2JtSMyQPzWqesw7SkFsViMS3Ok+xuSohjAMnQXq9DI0dLzUjIRqPw
oGYtomoXbhU8iH9mk5ppIKbJa1FzavMFnK1xS3n7Fks+deyG5BT/aHn0T+VPDIJKE2arwuk0vKWZ
GqJkkRrbAhRa1yM1aynhp+WnLdQs9oU1hVR1UFSsR0VBagRij9jD5WEyNAVmtwqnUzTwnHKOoqrV
jJMq41ezcOa24KooJAfU+KmlcMMm4jcoG6gd6wSmGHxQyS0NryNE74QYLellRM2qGEyWuBv7bFSR
fxOBRCARSATGQwQo2G6hsqtrqNr+v7cOLXRVmVPineLoYi/XhA2scBzH5VlHH330aLOr1DGJKnUe
ozMGHUdfbwEbbV4JZHceoyNT3DtQ09vg5nBI5707PtFRJLPNNptz48W4yNst2LF3D/d0uMoEE0zg
pjDH7zvH3o1vDvZ3EXYtZxgCSJPD892G4LwU/Mg1cHEr2dBWjaI6SN/J+U7In3rqqaeZZpo4+V+k
A/Ah4ALx0dZoSDiE331no02ZCRKBjiLwvfI9fnGYF/2ZUQP7UJ09WUxLTFR2D/F2w25o4DwS+QTa
mYVnfbx8HAvADvxqJxoKZvcQxZtGLdIWKiYPP7E68Ytj9KG9IxHTl+lbTqTHFNjaJAtPyGa9fALx
Mj6HaKD9WTZ5CWA3DEmE9DX2u4Vhzk405dgH1yIqXmnnlGJ/U36Du7E04XEfLh+WF+1CDFm+2H3C
2U/D0SIchLNiYK5ALHXzsjnnPSY/pIwLqNqBgOzgDohYSzMxFGkwFAzItrgKlN12Nrv5SRUAx60E
7CmDQEsJSualyRbGe3PhsjDWeXY5G8L1CgDER6PsrXu1vEpORjooMVpxCp2zzKlFDF7imwK7boAh
j7ehHrSTCywoLViAzKkS/2JDjCbrXE3WpzoUV+IbKSx9S+FOyGQzZVF1CL+MzIi8EAFiTxysmg1v
jhB7yhYqCyHILek1beoytU4MGfyFefN0mhqfgUQgEUgEEoFOIECFDhJE7aejRhUi//XWVcUihUVi
Cow49TzzKolbqFp0filFRvaazIHtsjMe1RgB90z1eEK7xH6SAA/yESCGG81a8qqlGdOeDEmJpqnF
HcQLL7ywe77EaEWUFvJooARRUS1QgmiCX7WoxoPI3WeuDKttEdC0FvGkVyCDjluM3a6l/NVXX51l
R2nEDkhrmdrbDqxf8Y6DDjoI8wrZSI5ozDzzzOxljtZ355pbnqMQ2U8++WS3cuMjQc0cdBnmKrnc
3oXH7bHHHoFGrTfwEVnvJlARUat4foqwBC0N9JM+ahFbdoOhmskAKI2UbJTuH2cJjdLgqZbo4hBG
PGGEFQjhKoAYhcRPVeweAzDEuF2IFr8qwT1lmCkjIxhb5FQgOQ2qSEwSt6e5xlohPRaekYnAcCLA
MORA9WaNNPPqYNaMF7bZir7d46VXbGRyNc+U4ODXkr3la0uCXuptyYht1W1WLT/15SvrmM1cqkOC
HJGBsvWeS5OxuTAmYjSIQxOf2go/ASEQ6AWo9rpqCe0/iVF7j/EtkWqvUjUFlox9k/lSe1uyaBE5
WyJ7/NosnEMjgZtjRjl6JDL20vDakGb6lur89LnyuZbI/JoIJAKJQCLQOQSYWuj/hx12GNODD4uV
ulAY1x+7glmMK7dYfzbaaCN2GRr+8ccfH6oydd01vviOK4Z33313yraMzz33nAuC3QKMidx449ur
nbfddhv7hZRUZSfPS4aeUKRd3KzAvffeu0VzdgHxnnvuKdkNN9zA6uRuaNefuamZ35pIFamu5vWV
qs80s9dee7mf2uXCjuKnz2NMmAtp3cVM6yb/5JNPvtpqq+FoDvB3PzU9XC1sJVtssQXTErHrjcYM
VWp0W7GUBKjn5FP4+cgxUU077bSuLY6vGgUZRrHm2ZJE4mHo3urJJpvM7dJPPPGEK7ZBShKkSY1x
ixkkL774YjK7ys2N0jw5NbB+lO/Gt1lmmaVeik0wiGFJ2ARq1jSo6Q4WNFUok3lOLRVVjEm3MrHp
x1o4iNxfcNRRRzkYE2tTFydAtzy76hpWwnLdeuutUDU2mKJ8An9UK3pZqwFOBkWJfPLJJ9nI9DIo
GCXF4KRKVukOO+wABxzTZd/6a//99ycesqYf44ptfo9SuhycAIA95phjAOgDefdHE6aKPaqA3tR2
9sRIoDnuDXdrtovOlWlAMtsBhKhu1hOjdl1seIg0PhkW4ezecwlGVUXGJwKJQIcQcIIi08wV5QrG
vuaeuA5VNy4VixHz8+wjoetvwxnpnLLCRNvfjJk+EUgEEoFEYMAIOMr+Pe95D32YCn3aaadNP/30
Dodnl5l44omxlZtuugkLwB0wKRzNLi1K7DnnnKO6ESNG0G+xBoq6yNNPP50ZAoHCpFzyi6fMOOOM
eBBV3P1l559/Ph3YtWWyCCBNSN/rr7+ODcly5plnNuXHLBAQMTT8973vfSoiEh/CWWedlX1KRRjB
q6++Ki9Gg1tRy5lLNtlkk+eff57kyIXD7UXS9qeaaqrDDz+cLQklRCWwRc51qAcBGHco53iWSNYo
1ANTwGsuuugil6zxWrzvvvuQnZlmmmnkyHe3P7C2wArTJABjEKOYRmFhaMtcc81F7a8NoeRfe+21
qAprkf1iiInEWCeaRn4ed7gPhkgq1EAD3SaAyhG7liCgOvyCRUwY+UIDwSsMhxZqxjaEhuCe7dQs
yBT0muJJv88++wQ+RHrhhRfQJW1BD4GjmwRcP2cYYO5+BSlyJ6UOVYu82KVdbxqlv7BFo2Xfffcl
mN1tiDNzFSKmHOgZNmJAJC/5QYG1+ayzzjo8LQl82WWXTTTRRDrx3nvvFZ5vvvnsU4MPZISNkyYm
PYbbqRmrmc5Vhd6//fbbdYSS3T3NV5YMSJ/CCW9g6B1sccMNN+Tvig/2WH5GJgKJQEcR4FLIT693
c1VHBRhLC+c8yf2V2bET8jvpkQ9nJ0rOMhOBRCARSARGhQBqZkNTdVfDmJAdnng4WpwsQZ/nREep
jhJOOukkpADBwV+ctxCR7BosLM5hUBQGR9elojOc0eoZyJAClhfqPY7gVyo3Yw1bGwsUmuZDD2+K
x5CEvIhBzSjPLCDCmMIcc8yBDfEnlBffkREZVJFNTJRwciqHFea4447TCro6e9ymm24qL31b7cpE
B7RUJH6HmmFY7GISoFFiGH3QH7wDNxGp3vvvvx91orH7Gh8pGZso/AKYLDIV8dzw2MIQlncSuiP2
TUMS8vjKK68oFh9hhfQrcx6aiciQBB2QBf/CFBjIkLtHH320lhCJw3+SMEqTwF/x7dRMsYxNWkQw
lKppNdN8TYBemCyjfPgwem6wwQa+oml6BA/VcT6gxpdd/I3LoNXqkoa0DH/MTDBReByvEZWK1xdr
rLEGBIhHAAxIkzEyNBmx0unGDFMsmo9q4bwK1CIJjA1dhsgjcXAQ76uwsURC4FRDmJ96+bRTM9xQ
7XGejCYwnvJaJJuVBGMSs4aG3jHYjCLkl9Wyl/Lzp0QgEUgEEoFEIBFIBBKBRKDTCCAaPO6C/qiL
/xgzE+MFMwftWgwrUtiwQhI6M82cBj777LM756EpHsYx3XTTsUrQ1ZEXZITBSwLqMdMPJV85LCys
JDR5vEAVFHU6My7QLKdSM+Y5/C5+YonD+xjpglPQ3uXdbrvtxCOS73//+1EDlfrIstVWW2FeqBkL
l+xYEvpGD6euN6kZ17tLLrlEAho7JgIHFInzG5oZuZjhsLymeFKirhpIDOWztoR42I3GstzF18jO
GIfjvPzyy5R/UkFSPDqDCCBleAqRNITnpAIRQ8RKW2oJUQgqgZGxP7ItsprJLr6dmpGHBUqxPVrN
GLCQIIXUwqVnZWPnEoNX6gUefRAgiR4kiZ5C8aohL9qLa2uFNCGGugCI82o+B0JED5PVIiRUF6OZ
Qc30EQOlr6DA6H1VKcLoK8KoU3B8xBBnF68ijqbkwe/0BV/HKnMvAblaHBpZzVh74xgQpI9J1MCW
zAAmv3ZpJuJ/6aWX6p0TTzyR16Vx0ksV+VMiMEYQsPHKuR/Nqp1N4XqyZkyEnyhPOEOj+a8XI9TI
MtKxGI+UR9rLaY9xbn9zz1p7gohxWnvU7tCMuLd6VCn7Ht/e/L7n7URKLpdw63vJDE8OCWl2RL9a
pK8dAtP36jJlIpAIJAKJwNiOAEc1vKkqpTTkc889l2UEb6Kyap0NX6hB5W5MMzgXOwhPP35i0Xxa
N982RUnJ6sF6hTvQil966SUUKfZw0cPPO++8SSedlPWEIYkyT2EWxlkwgiaMTWpGhabD+5WZAzVD
CeWlYDN8yIuOMT+JdAIGUsOUQ5/nHIgzSkPDt8NIXq1DcPCgFqsZakYzlwDhYj2kqysWF6O9i9Rk
dj2MssVqxr6GAJKfqo/JSumD8YVHX3z1V6XEQM3CaqaZ2iUeqWF5xKHASwDkCA4QAykrEr5WS4gA
goy7SQYlPDoig5rZVRdfwy7GrVQCdMkJjXbPESl+JaptXFgSuhQx/sIHNQszn7A9ZYgMkxlJfFA5
jojKYe1C3KRX2uabb86eyP/TgInClYyQQsNX/RtiONIf4dJY/VKpWVjN2GExen2hwIA3rGYOSME6
SR7xxhIWr3YjrR0Qado/mtBOzZTJA1PiSs04NzK52l9pqGgsyVFLHcE0idi2F5sxicAYR8AhhMeX
40MMR7sLOIhvsjJZj4K5TsuxezgaloTQ+dtjMpFxFr3tXaNK0Ix3fqBjK5oxEXbIRgsFc/bggmVB
l027aq3lbq/27H2JaW9+X3K1p7m/3N9jE9pT9h5zUbnoA+UDvaeJX6NGFPi95b3NEw6bLRptOb30
9WjzZoJEIBFIBBKBsREBRMw2H8dEcFnk4oVw0ZxZzZg/gpqxcVCn6clIFnXdnh1mI0o4JsIzkNIr
AVMIakM5ZzWzhYeezPOQk6GwLWwzzDADaxeqIiXTDMrG2mXzGp0fJ7LxB8NqQscug9GIYcnCaNQl
jJqphfGLPcW2LFxAXuc2yEvNtlOMzQ6LQXCYrhh3yMBQIiCvEuKQQCYYzZSAL6Lm0Pyr1cw2K3Yr
XMMuMPwUHUPxECgbrLS6iqdSDFR1KrWvDTL4FMqDGOIjcKsptdfRiGDkqYhfKLNazRABbAtHI7OW
2rRFKiZC5BEtqiVEQI0cO50MD89KElEztio2QZiTE0dGQxA93RHUTGKYo8ZkYMNCXYNv1sLhg+4x
/ImJXV1aiksCVrsQc2G81dkp3BoVa5ccMyXKphOxG23RalZFHMoQksDAQMoUhfJoLBrOSOfXcGjU
TALIYtjoPoCg8IYB+2aY3hx6GdSMPNBgtsPEjQ0wItTsd3CowrcHNIfrY6VXeB+rmTKr1QxxwyJ1
EGTY6eDMLAgW2Bo2KCdirhXtJWdMIjDGEcCAyPBcec5B7gKukA5q1s411ixrxi3Dkjk4Hf8SiOwt
iR0e6Cz9oGaO+5Ms/grEp54u6GsNtxS1RlnjlPLu7R5SxknyAu6bfk95DxmiNH+bAqirl+okVmNN
EJWeVc5ifqqlVZEippm+pqkBvzphPsoR2V57s5A4alKa5pmTtTq90CM1a7ZOac0aJyoToWbNBFWS
KLb5U0hSY2wla9LwGl8FjkDUWBFrKcTXqLElQc2bgUQgEUgEEoHuQSCO5uDiRbFndsGwyEY5p9aG
Q6OvDnbg+kXfpmk7WwOpEUlFR4tYQxho6L0RSY1HRqTk9GgbF2WbkoyAUOZZKPzEjEV7t/OLPQWb
8KG0M680AaHhO0NPDMsLS01QMxq+unABXE8WJh55FUL/VwXKwGVOExAWmj/eFCSLjS9KRjOdjig9
xoEVUshxEMwrTqQkJ+WfCQwRwHo0R6OUJqVim9RMAnVR7/E+VbBbaVogw+GQJM2GICBazcbEdrPl
llsGOQpyh5VISU5VqEtzAN7izRhFaT6oQUeqWr6SEUnMwlkr2LTeQbLqqY8qip/8inDpJqbPpmDC
hEd8WNMinlTaohaowjCoED7OaKgJOKwAc6HEuo/VSUoy45JOsDROAOiUD1DoOGbHbbbZBs3RalUj
y3iTTkH3WFdxZBl1JfLFDghbeZ2XsvHGGwtUYRz8OMUUU6BXIjHEphEw0rT81Rw0nB0w4gGFxTvv
BQsTwxh68MEHY8QcVp1IqS2ssXpQegGsH7/GBLWldwLYUml+TQSGEAFOg9OUaUaWkaxOLozmQOiK
KxdjuTXYEXwq2qZsQ8l3aJ4bqd5f3u8CMkp7vYY4JEHNlipL4RTuLNu57CzSCXuTl8ndnDVpmdRN
ZGLiZmQZJygToGbKYeGSy9dIcH253kXV5JmvzIc7SP++8j4kq6Uo94gR4KPlo3GLdAgQ1AwFUOO0
ZdqIZGk6rZyGM7rJi0WPPOuV9fyVIMijr9o1U5mJJ6QsrnVmp3PzGj/AaD40XMdMTgRNgmb6Z8uz
7uHC2iYuE7sHTTNfLi9L71oxzoQhANsT0xVAOBNqo7oWKAtoY/zq7/PlecKsVlZzGdwkZRJ80yVi
QCYeMIHjWje1uFtNyqBmIrcr2ymw2bpaYLNGvaZSRNglbhLUDj2hnHB0OdodZE16q3zNdz+ai94k
rjRcM1145xzLsEU60J6jo7xso36aqky1fFl+rjKXHgEambVRF89eZncduQKh7Ya7RcuiVcIMJAKJ
QCKQCHQnAlzgGDIoz1hP6PbkpNnSdYMThdiUWySIEttsBS2dXabJXPyKbjBV1KIive1atN/wbIwY
+rwCae9hm2spVu1ilB97moQJIxIzEpYXm1NLM69ImjwTUi2Kmu1Tv8rOUhORwQLEqCISRF3KZzQk
PIueNA6swEqQtVqIAEmgoZkRRj0Iw1TUTFPDylGpojSk1hVfI40akU22reC2NWNLQPaQucYTXuHx
Ea7xArrvnV/+pmcroWumEQ4oaqR2cTjUI5xC41cEFmdn6sKn0MNmSsxLq1sitRRvNZBCVE0jWIwi
dfk15PSXIUyZtUUx3mr5EsfWv+h9uGlF/XVUAbnqaJFG7b76G+lrY0VaGcD0CaZeTY5k2K4+DWlH
VUXGJwKdQwCboMOzbrgsmCKtIvcRY0bBgHxFaqYoUwigZugD+oPIICBi6gc1Yx6i2NPYY0uU3WQS
U9fdF0ZRlxLBocwLSImaYV70eeYYbAK7EY/dhHmFwh++lBOWCVGz9qLmL/M3aYW8qBkOIiNaV200
2ASqhSAoH2uYscyIkkiMiqIPB5eD1y5r+4p2kURAM28uN2OIpKrN37PsuUJZwa/t6dXlVz9Jr7Hw
YaVq2RGmCbDFdFziLKUEjHqIlXB8OIKiM8JQ+mR5c5PyLGUWfeHoeDdBawu43GEd1AxTCxYpWUvr
ojR/o0YB3YopKwH59bW2iNhxK3ST2zJExi3bKjUkKjVzrzd+B0YYcpVEkxnUiIcwKpMf6T5lHwHI
u3va7eQ6QuKZykyYIIpKhtodkuUnEUgEEoFEoGsRiGMGqwbbtXIOj2C0dO5/bDrshi4OYFLhMzl+
quvBj9jyWnhfpzsCEeYtyXLHlNbpurL8RKCrEKDks4xsX7anYNPPBYiHRgVhaVKziMGq0JxmE5oO
jWEzotsH0cN0kDJmICawyBIOjeKDrVDdmZaeKc/gLKHGM5yFeyTFHjVrKUohPVIzBiwkDg2JbWhY
IbrUFFK9TrcQ4zCTZcuyTD/rl/V9lVLVJDy5nCw7NMTU5ldq1p4eq3L8SFTBMMeeJXE1mUV8EKUj
y5HRWJGI4THlbbcKX1XnV4GFy8JBSNnp4rblsEBhar6iZtAIfiRxe+tExqdJzWKvWSBfW4Rh6Rrc
Cpd8JxNqOpmOrl8rNWtJxq+S1QyFDLbO0npiOVEu2DqoZJWyStDMKEf5MWBqsRlIBBKBRCAR6FoE
bL9yYGBSs9pBqAEPTL52fCntqsNQ6k/jVYCtys4sXqnDiQAWzIbIEZFD46iMfeNVL2RjxysEKNU0
cBYZFhC6dBz6UfXquu2oxqBm2FYTImQKMakxKIZcTWrmJ5QBHROgxnPGE2YP8hX5CqKHSUWC5cvy
YYsJatZeFLdAXnm1OgGGLa6MAvuX/TWB3UdY4IxyhgCrE6uZei8sF/qKxLHv4BdifP11+XWY7c4p
57jmjFTkr43du+zNX1Gy9vSoWRUDVyJt2Nckrh+txo8QK/STDOKRmiYJGhU1Yx1jk5KekQtnDKuZ
hrAthjdmS+taavQ10BMIalZbpJkoMFGXLkvXXIinTvSVKY3/ZKVm2r5qWZXkCJ2OME7wXwa46Fwd
0aRm0ICeDoUGhGuNio2210D9WgXIQCKQCCQCiUAi0IUIJFftwk5JkRKBcR4BGjV1GqOp5jAuf1R6
Zy3yx8MvtixbYj1iqOh83nCZ8E6EDI2dSQhTYG7bumxtsxJCxJ8tDFi2KUlMS8dx0AoEyl6qtcpa
WJjS2I+2LdtyelQO45HtVAxPnOJwh3vKPYxZzFLtRRGAwLeV26JfkAXb4vyLkyFxGRu4GMiOK8eR
AZsYUUZIiYjhQTwhg2torELQQJQkKJsmIGUMaghabb5zRciPgLSk5yuoRozGyYchBmfOMHvF1/jL
5mWz1cgyUkUE4F25XdmuJrAhi6VSjTAUQJeChzI/oT9gX64sp0dwQBnB9UB5gN+j1mlyS+tqmVHj
xeVi6OFKeLfAdeW62iLOqCC1hZBfYs3FHVHvQEB/iYzEqtPdIrFmhlHxCLi9eJw2CQMTP+G5RNWn
bJGGyqxlVj8xa4LLgEFIby23oqJBfsVoi3L8Fa61ZyARSAQSgUQgEUgEEoFEIBFIBAIBlo6WQBMZ
Knfz64DDaqGxx04r1Ayhc3RGODFGmehhcx9WLxX1USSb5tQY5WBGTDnYULPYF8uL1YKjTA579WtN
1qyrmb4miAD3yGZbIlJp9XhD28eqMC15e/yK9ClQ9vZiI32zdbWEZo01shmQCwg9ShL2uGbiCDfj
w0lST7Una09c02C7wtoSI42lssJS02QgEUgEEoFEYAwi4BRxp9h1zkjkoLyWw0P63lgubXHOed+z
dE9KJ0A6UqP3wz16kdapJrL720uaAf/Eb9DpJbpmwCVERsNGIc0ruQdZYCeyO2yk/bCaTlSUZSYC
YyMCfBrZs4ZTcjYyDoGdqJHhj52oOjd2ooosMxFIBBKBRCAR6CgCjlV3XnpfTsDruxh2J7lyKy7h
cmS9G5b7nreZErtxLr3jOJqRY0UY90EHHPLvbxXY7i1HPtZro2t8ewDlcYaho+njdub2BIOM0UEu
I3MtXd/LIbwLuJ3ZqGk1l3MgnZNfbyio8V0VcJikm7UHPAi7qi0pTCIwtAiw7CAyXNp6uZx6aGtU
kRMqOAGOygI1mOp4/fEYHEwJmTcRSAQSgUQgERizCKA/zg9v6tvtxy+IaY+UpZmrtkJKZbqq2Dnq
Ip0q76j55q+U/Pq1BtrL9xOGQjal1WT1uPUa0wwoub0ckS1y+tqjDM2iariZt71wyXo0OMqFmbZQ
M8c/ujvMmYe1cIEeZQ5q5pRCJ8xL016vXLXepoRRcjOmPa80EugUB8hH+lH9VUUFivDuBXM6Sq1X
rqBmxx13nHCPFY2qv5qF1NrbSyBnjylFNtsYJbRnFy+ZU/Fdrp3UrOKcgUQgEUgEEoFEIBFIBBKB
7kTA7WBUa2qtW4YvvPBC6jfusNVWW7n7icDMK+6kdmny8ssvf+KJJ4Z7HnX9vPPOc7D8uuuue8kl
l4Ty7BpiKR3oJy8jxcQTT8wYx2bkgio3VkdRLmVWlCuJHVAfRfnVhcJHHXWUC4i33377FtdHx7Yf
f/zx/Ppkd4sWKw+yo/wWTzzq98iRI/faay/XQ6+22mrEQBlEunVLpOoQijC9YQqOZI+bst1B7AJi
jINUcRk0EB577DG3MAs8/PDDjEEA2WCDDdz17N4xur0W7bLLLuoijzQO2GcTVBr545oz5SvKPXFu
lHa6o6qr1Uz6hx56yJ3dLoM+9thjief6sEMPPVQaMjsuvsliQBpWM4W4CJvp8KyzzpJAvFvDdtxx
R7ncOOaCb33xwAMP7L///m4fC5AvvvhiuaR8+eWX3aqsN90S3mJ9k8vpixquTGbTuEtaFrfCab62
iL/iiivUu+yyyx522GG8Xl1L587oWWaZBSxVVDi7wVn5zrR0kTRwXnnlFWIo/8YbbwQ7OSVwzXd0
B1vqddddB7TVV1+d8GpEvSPSeZgi4SCvEkIAJWimQcKqK/7uu+82HgxUY88V1fpISoW4IG+HHXaQ
nfAcNUOAZ599ljz6wvA2tBz5KD4/iUAikAgkAolAIpAIJAKJQNcicNVVV33oQx+iCe+5555TTjkl
lvHggw9SszEO6vQ111wz11xzUcsff/zxhRZayK8agr6hGHfdddctt9wy33zzOXtfJLY16aST4k3X
X3/9/fffP/XUU2MT+Neaa6555JFvXhaD2igBnUElllhiiQMOePNyT7xj2mmnVaBI/nu841QqPj6y
L7bYYsgUjrbgggsqAXc44ogjFlhggeYmLARBvYibK6dp/rPNNpu/lPmddtpJvEhtnH322REEO9c0
BxmhzNPt/cokJ0ClVyMQrr76ajUKXH755ZNMMsluu+3mcgFNmGGGGQ466CD8DkXFd/AsAhPp/PPP
F8A1fNSIj6id1x8QkE1Ept6yrV1oCJA1E9FzWTY2gXogg6TVIh6G77T7TbqBTMmODAIZ25p55plv
u+02rdY1+KZfVS0BZo2szTrrrICVnfPe4osvju1inUQ98MAD2S7hv+iiiwZpiiowbnRMF2OmqJbD
6sUHeZQdpZULUHfccYfyCbnrrruyfkJDo0BHvCgH8kjojDPOiPjw1QTUJpts4le8ksDI19NPP73f
fvtpMuYocsIJJ1TprbfeSngyo/P4Y7B4zUSEoaez4K/JmKCeuv3229F5t8uR2YKAToEhXokPLrzw
wm+88Ybm6zJrAgQg5zrrrCNSY4m68847a4L0JMRDQ+b8mwgkAolAIpAIJAKJQCKQCHQnAsgXxznK
MF2XhSKERDHmnXdeejsFfs4554xzQn7+85/zr2NAEUO7loUhQwIqNOpEN6Yqh8mDFk0ZRkCUxrLG
0qEoqvidd94Z5dOip5lmGjwCF9tyyy0jkgEO45MyvvqLmjG70M/5pEnPHObSMfHsaM17kFWHDLL1
IEe4G00eU8C5sADKOUscssAIyEqFZyFZ9kwpWQKsDbnYYostgjxqUUXjyiuvhEDYj9AEYWRKRWgX
64zsjEHc5LSXJEgHTvHoo4+uv/76LGIkDJvaPPPMg3rU5sh+9tlnr7XWWuQBKRiDuIlHHBgECRCJ
JUC+JGAnEkNU1h/kVwLCI2g+WA/kcUm/IkSHHHJIVIqn6KMLLrjAxdmSwRNoeMqpp57alMSWN13j
V8WyWPlJdhyc5ZGjIxKqB5ml4KMQFihCMsZhoLUQAb/qQQxXONBD84GDhOoRbBSAeCIOi+6xdU4/
/fRBIYFGYGIjVsyI+kUJIvFuGBKYtQ7U4NWnBsDcc89ttCB0ysfylAxYdBvyDHYsm/L6AA2MeDFm
rckkUSxSiTM2my8yP4lAIpAIJAKJQCKQCCQCiUC3IVDJCGqGa4R4rBLMYXRynAgHQTEYPnjfYTfo
DDsXHzz6sA+zDjsLbRk1o2lHdmSBvs1K5Sv9n1HMIX7UcuQuEvAJnG666ajlPM0YRCKSBo5WULDj
q79Ua9SMUUmYGxsxWH8YcdCTmkYAkeHuyEaG9RCMLQlhRDQwCxo+gxQh6flKJic/RvYgCjw3RWSh
hZphOkFUufMpCi/AONhxNF9FwsTg5odxEAyR3HDDDVEJbWQQxEEkY9uSEndAuxSFKlZRg4KhCRgH
8otlBJP1l20IfwFvJNYipINt0V8xhGScYrLUKJSHqVFLNUpL+U8GJ9ILyOOIESMY9bSUi6NfiQcu
H+0Ni2eUT5IeqRmXSzK/9tprdqKxdgFKixjptAKJs1EujGK1RUHNomSt4LlKZkYrAwA3VC85lYCz
I8i6G9nE2mQnM7iQ6GCgiFtEag5g3TpttHDFDHi5LxoYDGGombCU4DWiIMbmiBsaGAx/OkJ15Gd/
5MQIpZDTGIYGd9z4mn8TgUQgEUgEEoFEIBFIBBKB7kSgSc1o4yEk7oOa0bGp6NR4ejXfM1YYCjCy
gJqhMNR1RjRf+bxRlZnGWqhZ7BFDW7A2/nXMXvWUdQamqaaaSiTGERYr9aqiR2rGCIJr4B0UftwB
Q1SUSiue9nPNP//8dG9Uix7OQZHVDIshPELBPsW1koXFliVkE5tgVOI+x1qHNWBDdPiQIdhHpWZY
gMRIBAualKoT5nSHmqmFUWbvvfdmuwGCDw9A3AExgYyUwa2Qr7rXTGRQM/SBbAyIZFZ+xHPV03ZM
0FefyK5SzMVXyRBkdCMcMlEP5EUrVlxxRdUBH7XBaPAasnGwBJcNYmLUTjY9Ba44MPOt4t+UpEnN
whYWhBHfQc2gTRhUmvlMt+JQjFYIL69R1UUhIRhmFCc0yi4xDoj/wh8UXF4VhT3hsEHN9IKAjATQ
KYYTvjbHHHNoTkTCAcNitpNSgpBfGv60QNBwxFZKMkCbqOg/Si6LEt7qh+8bdX4y5NA6KX3Y4OzO
C7fbiMm/iUAikAgkAolAIpAIJAKJQBcigJqhAEgHq1mTmnHhQ4WYG+wwCrFPO+00RiiKN/LCOiOS
huzED8q5AOKAE0VKWjSrGc1cPGrmJ1yDeo8vUOB9WHaCocjbpGa4DFpRUWI1UxeFH0PhvBfMDiVh
zQkXuEhJb1cdkojycMnjssi+g5fhKeieNBqCX/B8Y/OixhNPSvRTdVgAqXAEabAG9JOc0GA14w8p
ZVAzjEM5Qc2Yq8QTGxok1BxET0Y0BBraCyKlsQaSpO41kx0f4ZPJGKSNiBJmgfRBhg0OGvaFRXP8
DWqm0krNAAVGhA6RcdKFShkT0dtggmiUqkGkHGG/MsPxscRVdQH+yE2xaWqs1EyLuGuyRWJeKIxa
YKt8cupNvyqK8yqTHLdAbC7Kr3LCAbFtUjOMDK1z/gY3UclwYe3iywpbwkw22WQ2DKodVritEUU2
Oxw1DS9Wr510bKzQwxZZVAkvni8i+6wAalatZvgXeyiuSn5IyqtY1l7wqghQ7JhYIag5hSJ66tIc
g4TZscqfgUQgEUgEEoFEIBFIBBKBRKB7EKDhoxi0Vjagyg6ouDRbGjL3RcYdBgjbkdjRggjQeLmo
cVdDXpw1YSOS5rBThDYujFkwr1DyGTIE7GYSiUApCnOxo40ZJXKxmoViLwEfP2SkhZohShwdFejQ
DAyCiQRNYEJCCmSJD2qDR9DP/fVRZjjF0eQRTHSDqYWBCUtCxDAC+r9IpaEJOJrm2MoEBHWhANgH
NDgxOlAiqJlWY17qEu8IQewA/VGUxOLtAiOSzU1BgpSDByGAGo5Xhj0o5FQXXoCvoVGKwil44slO
HrBgK2+35y0AkTKFYxkiiaH57JK8AVEPKKkaJ1KFLmD4i5KnmGIK5qooRBaUUzfhpNKj0k1gKzUj
M46DT2lCNJ8wmoYFq13hagGUXWaqYI/jZ4i/E77WgkARzFckjkOjtqNmaCA2BHZgouEiCYMW8WJV
JgCtBhhU6DOLnjJt3xMPLjhgiLrbTjq5RBotINVHZGZTk0BdxCYhKmoUIcKMYkYUfq0Enqt+ZfC1
lw28xoMsupLJT0p72ZQZwuffRCARSAQSgUQgEUgEEoFEoKsQoMPT7Wmz9GSfkI0az9uQhuwrcwmV
G4NresRhQ+wy7GKyRxYKOaW6No0azKLBqCRSOOIjl4MgaM4Rw1hTf1WUukhSCxEmW1RB8+cGyZhl
B1mlBjUl64yjRSjwavSrqhVLfgTHAY9MbFwQI7E2MqNgW5hCxKhFYxXLgqPhrHLi0VKBEEaYYJFY
+eIDGYnlAk6TVWkaYsvRDn3T9hZRERwMMbwcFYJfsLhxhpQ4yq9/ZdR2fEQMMSpQAuR3xIqfIIPC
RF6lIW7NcsRg1uyGtaW1cHm5d9ZTX8gMWzRHi/QRqKVUEdwYVYMeiiE8pkn4gKVFMF/VDij1+mim
0xGll5hjpEKUjwIzn+kmjqlQ9RNnRRQePcTcHQ2qH5UTHz2F4jX7zq/Ei18JqdcCH2Eemzoi7KqR
wE9Q0hf6S68Zn6pTJlTfriD/SwQSgUQgEUgEEoFEIBFIBBKBRGDMIYA3IUTMYUyHwyaFSvFlJ+oH
8416RaJsIrkjDpskWVEikAgkAolAIpAIJAKJQCKQCCQC3YAAc5KtZFwNHWs5bPKwWLGg8a6s5ktV
i2SKFdnka8MmUlaUCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQC
iUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJ
QCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCYzUCDjrOT98R
GKv7erTC9x2HTBkIjBbSbkuQHddfBLqtB1OeJgL97c1M30Qvw8OAQA65/iIwDJ3SnVX0F6jxPH13
dmIfpYq+cweogL//fefzn/wMGoHAsmIbUPexX8ZIsjoYyByfaMKgkcgC/vPOg/XfAHZMDYaot9nR
VbAMDAkC+rd2rsAYeZDHn0qb41kY+EPSiVlIRaBlPOeQ7u/DlUO0jqUOBVqGaH87qHvSx1AhjxbF
p0OIjZ/FgrT5MHZPv7dIEkKSNropfq1fqzL97/z0B4GKmwBg4RnACoupY6OlL8b41+ZgIGcOhv70
eW9p63iIwQDnOh7qYKiRHR0G0cX+qjcGp7+uIfb551uff+RnEAgEhsA0GgLe2uOBfEc7dzwsPFA1
mJvjGfgxngfRk5n1HzGY/a3jOYZ0oJ3juY+PWx2ipgIfGPrkEB2SB6x9iAbIhmjA7m8fu6kbktWh
Qv46VDx9Plo6JIiNz4X0OJV17ThpjoFf//rXDz300E033XTDDTdc/87nuvwMAoFAEZ4+t99++09+
8hOPhmnZcxezRzdMCFWGOhhI+Ne//vWb3/zmLbfcQvJ3xsL1g0Ais14XMH71q18FqafsySef/Pvf
/14Hw/CMBxNR9LJ6DcU//OEPv/3tbz34v/rVr375y1/+4he/+Plbn5/lp58IBG4ABCMwf/Ob3/zu
d7/785//7K1KE+vO570++GNvoDmePU1vvPFGjGe94JPjuZ+j+N3kdTwbzM3xTL3J8dyv5yWGKNBM
BX/729/qlJtD9N3RNqBQ+xD9/e9//5e//AXOQdBC6+5XZ43ZxF7NPnWoaE5zNov2+jsgtMbfTHWc
xBNH24GqxzC0L2jD3FAZs13fUjt5gpvHfHvttdd++MMfXnTRRT/60Y9+JD9DigBIp59++s985jN/
+tOfgryHttbSI2Pwa32DEI/e/vLLLwNgkUUWWWqppYYUiSzsIwbDvPPOu9xyy73++uv4UWjvwzA/
1C5Woy5+6aWX5pprrg9+8IMz5KcDCMw888x77bWXmb+bV2PG4IQz+Kqb45nS+53vfGeBBRYY2Hie
8Z1PcyBEXDOmGY5fB1Zds5wew4pVfnvhM731ifgqnoBof3ssaqgiZ5tttl122YU+E++v7lRpBj+o
hraEqmKZci3U3HrrrXPPPXd7tw5VH43n5cw///zHHHOM8eljfFKx4O8ztH3aodIoAKGNGyoI5kUX
XbT44ovnUOnQkIbt3XffHUS+DpUO9Wx/izViKy9jIjHlXnDBBdttt91TTz3lNZefIUdgp512Ouqo
oyynB9oewJg6+ttxHUofyzXmNCNB2+k5K664IisqLjnkUGSB3tErrLDCD37wA5MDNIZnMDS7WC9/
4xvfmGaaab773e/iaPkZWgS+973vffazn11ppZXwMioZtMM8OrboCR2aZIa22OZ4/uMf//jAAw/Q
zdj6B9CVzzzzzOOPP/7000/XvC+88IKYJ5544sUXX6yRNSAysjz33HM1cggDCle1UdQsU6Vad//9
93tmv//973/rW99ieZfAXC3y29/+tvW0H/3oR6+++qqJpZlx8GE1fv7zn19++eXhbDzHgpL3ly4Y
2j4dx0oLFQtcZgBr9Zdeeukqq6yivwbfI+0l6H39/sP//9PHkSBvZPe3veTeYyKjantP1ulfPQ5H
HHEEDdYr1QfmY9HqgfeCR8k7ggJGH2DZOemkk6zs3XfffZ3GbTws/+tf//r666//la98hWeLB7MO
lS6ZfIKaxUgw3/qce+656IM5v0skHMfE2GOPPT71qU/99Kc/5XUTb7eYOrqkmV4iCIKBGoPBRIea
ed2L7xIJxyUx7rnnHtTs+eefZ1hHfkN1Nzl3VHVXfrOLH3zwQYvt2b+dGFdespdddpku9rDrYqqC
mVZkp7u4E23p2jLreA4/Rs8Urw/h/grsEbAgueSSS26zzTb0Itl11m233bbEEkt8+tOf7rE0HYqq
6F/rGz0mGEyktbsvfvGLpl/csFmOmZk82ohCjhw5cpllljnkkEOIylUeJz3rrLMMMA3hLG0BsJlx
8GG1cMNGzSiNxnO8v3I8jxZYQwt0BpVhyb2WKWTDDTekCo4248AS0CjM8PolPsJi+l4UaT1TfU8f
Kb2zvL/iwelv3iFMT83+whe+sPXWW/MDNEQ9RNF84vkMYUWdKIqEMVSI7TGnJZ544oke9tdee60T
1Y3nZdpYZJxcccUVHskwPRgq8O+SceIZ9Px6psgWHq3eNTvssENSsw6NW9Tsk5/85I9//GNvNxO1
Z9CkPYCZsBPiGZPmcK8Mg8EUZ3PBww8/TPGwctuvub0Tso2TZTKmc2ikYvF/rqpORycHXex5r11s
EJIBNeucnjBOdlwfGwXqiy++eNlll/UoNZ/3jnZxH2UbN5I1pyzKmK0UGMpiiy3mXTaABnpZYzoe
B4tRsnskd9ttNzblL33pSz2WRn067LDDONt87Wtf6zHBYCJNwtb/Fe4JbZZD+8X3raWzUzCrTT75
5JtuuimlgimNtDfffDOx/coJyuzdzDj4sFnCbmEQURoN6fr+8nboEn1m8G0c8hJaVCzWTMNpgw02
wOuHvC4FMpBZW7Ce4Cn40FsfXlu77767R2O01RlFVuqYEk4++WRz1GjTNxO88sor22677UYbbSTQ
jK9hOJCBAaijuiW95cwzz9xiiy3o26ZcT+jwLHjWZg4mEEPFAx7aOC3x+OOPt5JvzAym2MzbIwLg
3XLLLb2gMV/DBuaGiqmsG7Rx06kH0POIIHivGczeTaeeeur222/f0cenR6DGk0jU7IADDmAo8Xaz
qmnq8L7rkldbzAwGg3cusmAwWILGHZKadWhwgpfe/thjj5l7Q3U3LXd0MOjieN6ji21zc8ZLUrMO
9W9QM5sK9a/5H1+o83+qskOCeXPKQha8bR2wM2Bqxgx03HHHTTXVVKeddpoOYpOi4s4333wCjzzy
yJFHHsl1ULwXpf3Cllv1JsUp2BNCdMopp1x11VW8lPfcc0+Urb5DvVut5HOysigXJjAZP/e5z9EK
aMIWxj2G0px33nkWRXfeeefLL7+c3i6NGqebbjqaPL+mvffe+8YbbzQ5eF+oggDmZ9Rs6qmnpmB4
qDlVUuSovnfddZetvJNNNpksOKO8SpBAXtY023AGTCSDmimc/k/m5vurG/SZIRlRQ15IqFg6NFQs
nmMsm6iZ9+yQ16VAQ8L4/8AHPoCWIdFLL720V8y+++5r0I62OoMEtTeeaSlGy2jTNxMYD+w7Bx10
0KhMPAaPI7C8azwazYxDGw5qtvHGG5sKqFgwr6vfXT7lEs9QsVBvqGiF/uJNbQYYMWJEUrOhHSRR
mhGCwpt1rXFB2wQOeY9AfxclOiFbDAaPjLeAadZUb8q1OcJLpL5WOlHv+FymSW+fffbxijQwYjzQ
xqlw3TBvxMxAP6FDmmktf9EBTO9JzTo0YlEzr07aFBf9eI+YHDpqRdXFnndd7Hn3DlWvZfCkZh3q
X8/1JZdcwkfOdOppckiU+Z+qYP5PVXZIMAej58X7y5RlPNuHhRxRSgdmNdNftqpNMcUUXtkeE1u3
EB+mKE8l2sV8duGFF6qRmRvxWW+99axvhGHLg+xRmnLKKaWfffbZZ5lllgknnJAvoqeMJKwY73vf
+5ixlDzHHHPccccdHvZZZ51V+mmnnXaeeeZhpDv00EMnmGACkc7ZkMx+ZI3yt2Z8z3veo3AkyxDy
EnHcB6OYbWhBzUir4QokD78XoirNwPvyl79sZcBZNLaJWQZEJHE9j/zAwFeLvOgqGhjjmerr/ZXj
uRc8TblW44Fv6YCKpSMQ/85Rs2effVYHoWMUjKZUZLAs4CQBw4bVlcJvEUOkNHrQdnKD7fTTTz/7
7LMNUaTeUiEmZVBZPUDnyYxURoGGAZUAETMOmagojeKxiWuuucZ6hWbiFCryXuP+qiLVGbQGDGOu
Ibruuusqs0MKDzHOOOMM/qKmXAgQxnMU1pAO1dgEeTBh4qHDdaigY1g29HySmg0G2FHlteC2+eab
Wycxm3kwDfgYKh7YUWUZtniDIeYNrxg0wbPjmfIYJjXrXBeYzXzsTTDRxUJ6p7XxvrfFYKDneIkY
paY1g8Hs7c2e1KzvGPYrJY3OEvSdd97Jimr6jclBF3RuclCyF6suZhV1VoAu9jJNatavXut74qBm
tgXRl7AGzzvNIZbmkpr1HcZeUtYpK0xmcGaKGjA1UxGfK2rtggsuiGoxbAWR0WXC+I7CdRyVCaXi
u9WkZt6eEuNZZkuTJ2cDj5W9up5xJgyGLTQNKZORw5jETmfli2ibmGU6igGDGh0Meee+yGy36qqr
BjWbdNJJ2dFQOZwIC8O2jCKLe6jZo48+2qRm9rPjdAxnyCA6yfahak86lVullghAhC0Cpy++bT1i
buqgrjPK4JIxntXVPe+vHmUe45Ghb+MmOtegAp3V745SMx6MCy200JVXXolwIUEMvrRQw8/YeP/7
3495GRuWDqwDIGK6D/8yVnF/vxrDDpFmZaOvrrbaapYg8Ho0X3rHGREed2BZU8hEE03kifBXMkea
eJWsvPLKXmfCuJhxa5FBscpUoBUDA5sB+r3vfa9IXztElIKaYX8eUioWtdZDOhZRMzTZUPGEGipm
j4MPPpiRMalZJ55iD8Vmm21mzYEvBF2oDhVv7U5U168yg6fHYDD5h++6xRA+w2k16xeSfU+Ml+26
667mTNq4sUEbj83UY1xVi8EQertRamawvnf11Vc7Nj+pWd/7t18p6U50LS6FVEqTA7pEldIFnaNm
oSd4W3nerXaq155070qV9kvyTNwXBIKaUYapNFSd5vPeuS7ui2DjTJqW8YzmWK538wvKMLA2hk8j
3dUxetbencPvSWmhZp6aHqkZFRTtsrRCP7S86bFig+MwQ611QMdaa61l3y5NlVmN0kVNrSxJK0y2
DGcYGYsbdZeWG9SMJAidtiBWdGO/2lO2//7790LNqHasHox0alcy5Zy0NimYxineaN3AkJHLLIEh
omZ8sI1nDLSuJqlowMWOwxm9VU0CVCzmRZwaWbAqy2m2c9TMQGI1w7Pqx7C03u6JOOGEE1AtI9PM
z/yKWG211VbYPSIz55xzenBMU9YQGLb2228/+snHPvYx44292IA3oqS3gICSE97odcuSJQW70owu
A1I5q6++uoVcnIhHrorWXnttkY6jQe7QN81H2YQPPPBAgHSo04OaqdpoxxY5/4jhqKAXxriK1XuT
DRXWZ6ISGFZwtvYC2KRmveM24F+DmvEnZ03GfQyV8AEwVPTFgIsdkozGaswbHluDwUjGH63dccBI
ajYkCLcXgpo5AJOt3wzW1MbH+LwR1KzydC8Rg8FcmtSsvROHKubee+/1GmWa5CJlcrBWhjTpgg7p
7VVPiMnfM+5d7B2d1GyoOrSlHLMrDd+1gBauLSazlVj0wL6t4naoi1sEGOe/QpgyE3qv8ewle845
5wyGmikQo6GFcuSmf1pGgyFqZnFVpHUME7WnlcGrxWpmLQuN2mSTTZrUDC3yfLEg8JzhZ+Xj0EV2
aq9a9jVMzZPoqZQX38GbOBxyQaQnM28FNRNpfiCDyYHzM0uH2mnOvVOzOAbEAqCMhhzF2EVaTBUk
ZKMXObBPUDPwapfxTMOP8Sw+qVmPkOpc+rbxw2jF9oGqhOtg56gZGuWdYgghYtjW+eef7yVung9q
xpLlATH5cGtktzWGHSHORuwwfwuDhi4XREMLfyfqGmuswYJMg9W5hg2yz8pgOVFGqxYeOk1WsuUL
VAjlXHPNNYOaqdFIs09KAhSeKc2pnppvJBOAhtkjVkMS6YHylCGVplxQqBTy8O9+n1sTCyEtDVnu
gDn8OVQzX1qx0YohAScLaSIAZAcoeUw8CyZk6wwxVLwCPLbNlMMfjnnDq41IBDMYrMgZCY6UTGrW
oe5AzSxg2qntDeuN3D2vNoOh6jkWEEJvp4qY59Nq1qHBgJpxPrH8CGFcmPZlxRs165CeU7s4lmI8
71bv6YpJzTrUvx4ojmSci6iyFjo875yagpp1qIs71JCuLRbC9K5YarDOz5pj78BgqJmW0lFpkowO
zA3W/MV4JN0pwy8R5TExchGceOKJHTXgaQ2+Q18NaiayUjMqLj3cM86C4HwPL1m6Ig9GvpHsTbhS
UDNNkJ01jTlDXmd9MFswkAU1E8+QgdTzV8QHQ4Xu3aGRVN4yhKdmBz4MH7FnDd+E1YB7M6iZ8Uyf
p5OjZsaz1aSkZqOCNFQsXUnf1ulMWvRtY6bT1MwA9hJvShXUjCMi7o+amZGsPKBmQbUYvIzP6N9K
zRAcSwSsxpWaGYqVmhlmyqfGYHZIWQs1UwilVwJjHl8LasbkOjzUTHNi9YD6HY5Jnqwxvvrd7I72
MPEIiZpV32xThwknqVk7VkMSY2xYSTv22GM9knQh/DeGCoLssR2SKgZcSMwbsaRj3vAQebXxbkXN
mFMHXGxm7AUBL03+onxUvNpo415tprhueLVVvd27O3h67BpOatZLbw7yJ3OvjUhc/UEd3hcGg6WS
DunttYu9hU1E1jNDlU1qNsh+HFX2Ss1YybFvhlF6ThhGO9TFo5JkXI0P6kHtjPFMH3MuwSCpGe2I
lwsuw5JFTQIdVZYKylggkjmAfssQxg0Myz788MPF2EfDBQJ14tBIJFMoJZaVwXqsJ5ozGJ9GyirO
JTGrmWHgoWNN8CuVzIuA6QH1E8PLEZVjafWQ2lxgm4/q5EIGOYNxfpbFWehK8/DSKCaZZBJ80Bsk
9podffTRXuhsfEQlsBcN4Y09XmfEG+TheKG6o2aWFmM1SUPIE3t5xtUxNph2hYqFmsXeXq4yqI0x
01FqZrlv4YUXZqLSRxbbfUz1mJo9bsaSo2wqNaOaWjLC9zncWhMwDrH+pkOjBQSLSyYu9lxWY+PH
0gTXXMPVlX+0F2fO2AJphBuKrGzVamZ82toGukrNaMKomWHvhGra72BQ7SWvR4/VjGOwKVfTPJUe
YfiPLdQshoqlGEOFpZK6yInU5NZLk/OngSEQ1Mw6m6FizcRQqSzeYzuwMocqV6hqZnIioWYGAysw
T+CkZkOFcHs5njX+oi7fYbCohpKuomb0HNTMZM7VmTdOUrP2ThyqGNSM+me/Ni3Lmj+nYl4inaZm
8bybl7w0Pe9U2aRmQ9WhLeUENbOqTB+jIFnvoiBRZTtnGG0RYJz/GtTM+4v2Yjxb/3TK3MCombeh
R48KTeGk02I3Tpyj14nxl0Ub/6Kg2rbDZmRitA/XA0t9cjB+uEAIyCKl+ZNi7CuRZPduZXRzmoej
xc38OFfEUHqlVLhR4UD7OHJfLbib8xnouoYN1VcVqCINjfIssUoRNIWboo0oCWi8KjXAPMuy88Qw
mQjzKDOHGwPwoU6jivBRuxl+YCsDQc2MZ9KqjpZOclNWUrNRPWhNakbfNk6wWgSnc9SMoyleVjea
RcBbBkl3jQKjlaGImlFHTfvrrLOOsSEGHWOfnWuuuRhbHSbziU98whBCtRB/w8bHEgF/Wp3uGTHy
MS8rCYibBOKZzKRnGrP9QRsNbI64FhbAQh61c4w01KNS6wx223VI+63UzLvVUwxzD+DYRc08v+zR
YNRlFmGSmo3q4RpkPBXIopZJ0jQb24vMrjFUOjQ4+y5weLcShkg4o4fIKh9qZnNoWs36DmO/Unr/
Yr5WnEJV655VR6Oxqed479PbaSCW4ExxA3uV9wuZ8TBxUDObpmlQXm1eXt4sqBO0OzE5KDO82T3v
sRTjebfGmNSsQ2OvUjMKM8MoVTbYd1CzTnRxhxrStcXW8RxLDXQ/7oIDo2Y6xd4cZ3TYp2MjGNsQ
0wArQ3xEMkJhJSJ5gkVApLCUdFSfGileMvF0Xdn9jVxsE9JHTJQvpa9RuF8li1oibxRe65VASh+B
SKBSgYgPmSWWQI2EoaLvsssunnROnnRyXl40EIo0RzXjcAB9WqkZgkkbZ+hXjikLdIZ6jud2SKlY
QKNiVX0b0eai1jlqhim78obXYvPjTEV8nFLHeR5bIaevVg88L8K6j+ctzy5H1nDm4cQbvBs1szAr
i2fKT5FReg+dgeRmPbqivWwePZEsyFingaE0LzI2XOsS4q1E0XbCesserUaj0Vc/deJjNFqcYQc0
5dJbuBmjZmTTC/qim4co8Zj2+FTEUGHyg5KjVpOadWKcKDOomQUEQwUR7ioWn9SsQ53eS7FJzXoB
Z3z7qRuomRdZUrMODbykZh0CthZbqRkCQhUcDDWjttGLlDPOfOgerGkUZiYPfM3WM2s+zIvWA43M
imHfA0nN+o5VpGynZgyOnaNm1tzc72D7MENY88MIa55nYPUTc+qpp57KKCzM9iqMefnJB2nyER/n
h+Dy9pohdDiCXyNjpBcWoxDpa4Fq8REpxmEjEkRFEa8WHzX6OBypEr3+Qtp7+nZqhukkNesdtPHz
16BmNn5WamaodImBNanZ8I/JpGbDj3nX1pjUrGu7ZkgES2o2JDD2UsgQUrNeahl7f8I3KRt2UtA6
Bt+KpGb9xXCYqRnfJ2f6cdMa5GfHHXekstqx5Xo+djQGskEW2JKdkIrtL5h9SZ/UrC8oZRoIJDXL
YdBEIKlZE43xPNzl1IxeYe+MdVG7b6KnxNjYYlHUG5AT5ptrrGedZXWUu4vVYE4ykYw3bKyO+ska
LA+ZHjcyc4iqyaTkG+Pc8k77nFAvrdlazuU4Slo+JHbKdKjSpGadfsCTmnUa4Wb5Sc2aaPQlPMzU
rC8i9TGNvmbYsunJDNnHLN2QLKlZv3rBG8q6jZc4Js7MKmxG7aUE3N9OQ/sguK1yanVLgm1Q/Xp7
2udoRKmlX7l6EWnAPyU1GzB042TGpGbjZLcOrFFdTs1MnnzdbSRHoKKB/KPsFrcrnOuXlc+WzeY2
Jji7QEoeLC0/uY+J20ALStxmWpL5ao+82bsl5RB+JbmdCHapc/7xfnGq+XrrrVdJ5RBWpKikZkOL
Z3tpY4Sa0bdpFx0dpe0t7YaYpGb97YWxl5r1t6Vdkj6pWd87wokujuu0odVr14GuPsJWWdnZR1WI
/Yl28tpjaAcfF1lnxrpz3CAfVfr2eHuu2WRtbFRC+6/DGZPUbDjR7v66kpp1fx8Nm4RdTs3ggE+9
973vdU54rHE55980jq/5af/99xd26pezRp1Z51AvXx0eLqXpXRjr8ZPzzB1qZ9p3WAFa1MTWtgjJ
HDMumRnbznG73uyLsSc3kjlNjmXN1piay3liImnFlu9sNq/xAvaYS2zdT4IaTxjJRJqH4ygbdMme
d9vV6ZmYprPKMU2MMn7111qxXUu1UiV4iXjjewFJTwB/bV6IKrzFpAwDXK20BpKaVSg6FBh+aqbr
jWd7cNz7jNp3qF3dWWxSs/72yzBQMxNU89NfCQeWXru6c3UiqVkfO9SY8XLnsOq9bA/gU089xWrm
Kh9nBzn4xa/KMdc5RdzpVc6WiWI5wEiDmlnYZGtzDJGthUHNvNy9Oh3ZygulymDG8H50GEu8QE3X
drxawnUUnndurG55h7qdwbtbmqhXCd6z3qre6d7mHbLbJjWr3ZQBCCQ1y2FQEeh+amZudIAA8hJU
Zdddd0Wmwv5FNRV2+lY0h5pqkmdTMz+7qdxPjqWtLd1www3FmPNrjEBQsxEjRtRIBizJUKf41eF1
vk411VQ2zseEv/LKKzufGekT724pT5OlP4ndPuDoOZGIpKU/ThciZSGDa3fQPYJZrPOKMeFvttlm
GBmGtdNOO0000UR+XXLJJeM+aDzRFVTKcYi0K6K8FKR3WY9tFw678yaySDjLLLPAwWtF+Q43dqYf
Xqm69k9Ss3ZMhjZmmKkZJYSiEsPS+eGWFIa2OV1eWlKz/nZQp6kZR3EX0ToD3+UI7n22huZ2njgO
sb+i9j29YaAKq3AOyTfFeTXwYK+rVX0vpxMpk5r1EVWEyAvOa86FIE7RlMu73nvTFXXe6d7mbuhY
YYUV4v3oDWgjg35vp2ZsZxHvfgSvTvcneimbJBWIcCFxqvBSdvasDQuWcD/+8Y8r09WNBqp3rhgH
xrqCweKtSxacVu2FbnStvfbaTjF1EI13fbji9LFdfU+W1KzvWI0PKZOajQ+93Mc2dj8105Cwjpkt
qcEO6EZP4i0c1MxdS7Wx5lKkhpnMZi4Bc379SVhMXEJaI4OamYTZy1zu5rIbfobeAt4LFvEwLxc3
iLfCJu8pp5wiI0oljKDZ74ajCXOeRJEsxJnt7SDjoUFCXJLpDV/zsth0003N/65SRfHcGIVqMXm4
x8fBCA6vi6t8SMKnURoX++61117k91IggIAXlgK9XFAwPznT2HHl/DNltwXPWeVEUmZtVDOQ1KyJ
RifCw0zNjDTLDgaVB8Fwai4+GCf0Cg+FXRuuD4vGovbCFhYOOeQQFmdpxLPMMss6WkF2OzTDXIvp
29fjUmAluM+CUThKoDUZ0pyH6VFxSVmUYJE5Elu7jsSeGuqTzaGO1HNwOr0oShjCv0nN+gtmp6kZ
fwDXlNNsLaBZGeN1YEo0OA2D/ora9/SeAufzY4JGJuuJkcnJzRzb9xI6lzKpWR+xZd5CjtypYUJr
z+LiJFcnuIDD2fLey0iTl6bzb1uomZFmsjIvoVeWN0844QQeNbwcTXfOuXWbsxe6E2Cc/2+EeF97
z9pULpc3OOpnbkTwfbWLwdWNSvD2NyVSKrxVjWr1etHXre7tcg4mJqnZYNAb9/ImNRv3+nTALRor
qBkhEROzK33Sex89ifa2UzNrthL0SM3MvX7qkZqJrx9KL7qkfH6SIrFCO45jSxrXC3q4udqNqPRS
aRjvpDHzM15YiGPJEimNy/jM6l4TrpK0Fuf9wtRlJRDdQyp9VlppJaY0SgVKpVjsjDUN1bK+5/Uh
AYXKnTjuVLXEh7Ixw0kftjzaqbaggVwiUT8VeQEFIO1/k5q1YzK0McNMzQwGTN84cTY4em4ghY8u
hdBzYTDQkDH6aaaZhhJCg/XXyKEwWysQT29BoIwceQ1dg9ZgpvkYJ1aGaSO+Go3MuBYlWJ8Ny+23
316xIv1VL9VIYg+FNQFj2wqDR4a9mNmC263RK8aAV53HdmihVlpSs/5C2mlqZtgss8wyRovTGMxm
rplD+Y0i95ur2lDhkOasBh+zN28x6wCIvInRNZomavFmxfAi85cXmc1ElGfMri4OGMYmQwOemzqN
3WpDeH3zTFOpgxa32GIL49myGD+EKOT6669XCB8J2i/E2EEko9j7ahZVr0nevXjK8RHpiTCA+4tt
j+mTmvUIS3uk/uVGghZZrmz51bDR3aayww8/nHHNuPIy1cX8Hg2PpkOj7PrdC5cjweabb45t6XcJ
OMlYU3U/Mrsbzm7MmI7sWDcIfRWJFRotVj4tex5wwAHmVXMLAxyPFPOh4acQK72GTQzOFgmH5GtS
syGBcZwpJKnZONOVg2/IWEHNUBXzpxUt5gD6pNd6NLyFmpl+OS3QNjkz0EilbFrNcBwxNIEmaJGM
eyGO431tazCl1Lztfc0RQnqcaJFFFrHg5rPRRht5xQtQU8P6wB1CdRb36AAU1zCrycvAJ54abLYn
s4VBRdFjabBInBdNk5pRbLyD8DK6CpOZdwqVxuvAoh+N2iKeN4gXEA98VI7wrBt0DNUxsamR6YSO
0WxUM+wdx+eHqoxF5pXTTWSGKjyc1EzX02OtCTtGxoChkWJAzhQ1YBgv+DdSJ2iY1AmKsdUAuyQs
VuBTNFWOZ2xnnIWkZG6Q2JDwpHCUVaAbftm58H1rEbZGGjPceKjBEk8++eTLL788Bdv42W677TgF
UWMsR3Ac8jQp1iAM0mdt2ToDx13PGh1JsqECuZaT1KxC0ceAsQE0+q0BwyrKlM8oMIT3mgU1Yzgz
GRLJDGnwMFWYnVAqN02bu8x+PqZNa1yMsLYU4W5MbIaWeM4AVGtj22DjwCDGJIzvmxiNbZIzjRmu
skhvMLORKcTYE6khhp8lLLOrhQXjnO7N36AWYuhaRjCX8nywXmE6NRtbxCAwPwcPi2fEtE+xV0sf
Ie09WVKz3vGpv1rJ8QbXiY5QDvpjDDC1o076BRczYHAl71Pxxoy3JAsawmUdoO41M7osohoDhpzX
pbfkW+/qRW08N6jMft6nxnytVMC8x/VRAnMXjxddry5jlQwGlQIVbjJUi9myo0eFJDVr9kuGk5rl
GKgIjBXUjLQ0RrTF9ItlePuH/EHN8CBfacgcq7ygrdubzE3L3s5e4pHSoii1kzJpUTdi4m9QM84P
8ZWNwIvbi14V1uKUwNeCbkDnDGpj9qYAeMWHHsIQJo3dYRZvcTH2BeWQxOoc6sTdi93B8ix1Gpmy
QkjfoCEovEnN8DUvHXos5kXTVj4xvIzCIsZE4l3vfUHrFgg5BRjv6DZeQ94yVK+Ib/+b1Kwdk6GN
GU5qZuQYWkYy5YEOY3gL2+ljWFqCpsrSaSm6m2yyCc9GCxoMap4RFmeGM2zOkKajyoiLeRYMRR/K
jPFMZzbCjXxDlE4iF15Gq5fY0oRiqUnGucVkRjd1WVum9KpC1cq0cuK581CgZn5yqPXQglxLS2pW
oehjYBiomSnIcDJTWRCgCTOnBiFC53mLmbERNOtp2JBBYt0AuzeZm/fEM4RRzjEm0x2KNMMMM9j5
SzNn+8DC2EFMrYwX5jo+Zny5aS9IH184I9xsKYshKtIIpFebb2WXkV+BQriieWUwnUhjVUGlZEDB
rI8xlJh1zf9+sr+YALE7qY+o9pIsqVkv4DR/spTqlY1PWWKyLOknNF+Pm2owIwNDgKsMGm6ecfAR
qxmmxlTqVdikZqY1xM0iqsTe78aGsWSooORWkMIN0szJ19pSrfWloGb2aNuiaBQZOUYUCmZmi33c
mJqJzhtWPDNuU+ahDSc1G1o8x/bSkpqN7T04hPKPLdTM8ikS5GPdrDbfzCmG6rjaaqtZAhXGjzhc
ScAdwlc8y09UVi9lX83hNW8EvALEU0Tjq7eqGZ52akK2+mqR1ldKwrbbbquEqJriKosyfaXWCtun
Rj/3CpAGhfQSoQ94j3B6tICsNOqKnRF8MyTwTmE1Y5jj9xUOjWgaQwPZsDNppGee847wAqIqe6Hg
hvRtzaxmCC81OomqEUApWxrV/JrUrIlGJ8LDSc0MGAYvVIuViv5pfCJNVFzxNHCMydgzPg0bCbjX
GicUG4OcHYHSKzEV1FDEnqg9Hh8KqiHHy5fGIrH1asYyy8iGFr2X71CsY0tjEcAoVSP9hxKrBJs1
wnZMwaA5ewCp4nRylmvL0Z2AWplJzfoL7PBQMxMvHds0haMZe9iQ5SwashgMiPWBJmwIYW3YkAFp
dPF71BaDFuU3fkyA5j2jiO1MPMaE1qFyFGnuB8qnQm+zzTZmVF4ENG0BQ5oWbfDzTAjHAFMuK7BC
zN4Kia/oGGLowCUlmKvFG0X8HFBCOyjtNjLJE89U6afBf5Ka9R1DHWSoeC3qMtzZVGbw6CmjAn1m
8/IGZ95i5dR3vFOsF8UuMK9RZAr1Nlk5oZHfCHurLdjWqRyWZch5pyvcO9qqlANqFGLsGRt8YyyT
elkbFQaDIWohy9BVqcFgHPrJNIgAGq7GrdHV9+b0N2VSs/4iNm6nT2o2bvdvv1o3tlAzL1Nrp+iJ
RdTaQG4MyJEp17xtUjXHmlTjV1qln0T6icnJHmGOEDVjDVBTJePBXmNYvszJFtzE8PyhGwTPsgxL
HxBJBkYHeq+3hvcC01jkZTLgx+V1T2GgoJr/xRPb2yE0FumtKqNXfCdY0NgXcC76AE977xTumiZq
uq6XjpQqFcn2pxD1eu9YlA4BxFC36NL0ZMlCkwkZ2v8mNWvHZGhjho2asQXTTKi+hhOdwYe+YfQa
b4axZWdKjtVjQ85DHb49rFcHHXQQozB1kaJCRUHo2CysDCBQDuuwSkBHpSTLbgHZqObZaIjSeIOF
0XmsS1CnDVqLHrJ7IpjJqEmeAhZhhjn7NRjvGODozAwolOSkZkM7xgZT2jBQM+tUFgSYwwwGHgLG
oSFqKJpFDRLTL0qF8qM/7LwmRtOalSu+ZNplqNCKkSMTqWMejS4EXzz7FwOK5SkFsoNYPeBOQG+3
GIXB+dW0GdSMim7pwKi78847DWNjuxaiKGWaWnlWqMXUTTMPMHE3KTECJ+Go3Qk5gwG5mTepWRON
0Yb1kdUeL3Ezm7+Mnjo3cpnu7DUwlflY3vRyN5hRaa9CRN7chVt5M5q42O5tIQyS5aVsbgwzHA9e
s59lKO9lb2cLvFLy7DW/eb3iYjigcYsVWmuSRmle+mZao1RpDgaJnbyjbcXAEiQ1Gxhu42qupGbj
as8OoF1dTs14MnB6wbOslfnLhCRgRSs+dhaIiY+wn3gYxk+R+J0frxPpp2beZjJ546u/kZG+Kkzj
9cpGAGmz9s7Ibi2XhmBRzvtXyhovsQTK4aGB6Hll+CpSFvJTRSgeVBExvvobkitBmMZLzeA5SVph
CRTLf94bJyqN9FVIby62DKoFXkbxIBI/kFF1fVKzUSEzVPEQpiQws1IydYp3ugGA3SM4Q1VFlIPI
o/l23NRTX1B168aMWdYTjAqapzAzMTssrmSpmdaKvrE40JwtQXNcRJ3IiWphXngWOf3KEkddMfxY
bOkn1kAQN+oQN2AGMvqSYqWx4CAXVZZ9zcikSjHPcfux6C0NPVwhng5qOZVjaNteS0M8yUkPJxva
SDx6OwdgzJFCVZNloCIwPNSssiF9YcI0iqi1ltHYJpgqjAcqrsmN36wlAvMhnwHrAPZ5WWIyOH1M
tlRlWrR5T296MRlUBrMEPAS4LhhdiJU1AcsRqJaZuVIz+rxVODO8sW3Vy/xsuUAh1GwFWpGw2wg3
9IDEmhtwlGa1DdeTgP3XakNFbJCBpGZ9BFAXmC3jpWxgGDbovHdivCLjXelNyoXbW9Wh+uIljhd0
vA2FBSLsV0NCYoWYIqIQQ86vXGiMH7/6qgQfkYYZD9h453rdeztLY/22WYtfMcHOGc6SmvVxqIwn
yZKajScd3Zdmdjk1s6jlXUwntMLpw9kgAvWvmPjUmBp455c3/6+R7YH2X/8fe/cBbVlR5g2frASJ
kkFAUkOTmvCCNJJzbGKD5CTQ5JyaIDmHBgQkiSCCCEpSBhmygKC8C0GiYJjRURjDYJpZ3+j+flC6
13nPDX3uSbfOPs9erGbf2lW1q/5VZ9fzrydUbYp7TjpkXQU1w+fdbhuRgE07M5vanKlmq7z8demK
S/SoNr3uPr0iVZLy16aUzVYPqdgSQwAmGDOJ9yez/KHGOqjZUMi0K72OmlnKGdh0gpohgGRazIie
lKrOxTnCvUgICBrRlyTMntbvBbdC7Uk+OBR/CiavbMMojj0lo6IwlLPkE4ZkcpJ7sRuJqB8Rhd8H
WZqmjGikuFewLBLNjEkkbYUXoZxerTHEY+IuymaPmsQLB484g9iFQAntHrQL4dp6Smrm7YT2oGa1
4Ax632lqZgbSPdFM4VwawIDWHGBFRhViv4JC1i4BKm1PAA8y32wl2XpC9uXxLaVTc8NUwJw0pj5r
/vTpYzngIlRTfPAYEuzI3gLtBp2IqWjcidb2FmxTmHXeokIUzK9PJXYVykpU6HXWERMbp6M3SSiZ
w8igbC5vN3sHRa+JxKBmDYLm94ueW1UthWnJs0SWK1268Uiiq265rMtWl7n2aap8YA0pva5g3Vu0
zaePWq3BHo00W1CzkSJW7fxBzao9viPqXebUjPkBYSyfiwRLGLDdSjS1uHe/YbaCk1DBasgOoXsy
8DByhUecMohGKYwJkQaptLNN5NYX8I5otkTmgQhA2GQgH9qxF3nAxr5zdlAzIA/M3EoKFQMbG2oI
Vl6EzHRRWjEn40FGIyCdhOyG6sqNf+VJ97JJJ0JTT7jRvHTvKX1HylkmKiWbDHK6r6tWNomptvQ6
/6ZqJWqexvAZsaHdSmeHKusXZ8ebSM96DWdkk4l7ogOhNRsKsU5TMzsA1A3mfJrwfg5MEG0X0Fv5
NNkxoPiwCWDqykMBwRAC4cKeyCG2BSh87Sz5BWm/rQBjKh0LIxJTjKZOGWIWaIJ1sDcTyYGRgG+X
jQifYuuXjxidF1NJfkZch1RC5k+V+DedhKJtdtVYwYk+WgKV3NlYM9qmKBNbvwlq1iCGpofB6v4a
2vgb02rrF9Rgj0aaLajZSBGrdn7fK34BtP/cCrJa2nxjk5yTrIPIOYyNbRRb9x1r4mtc7XEZld5l
Ts1GBZMqvTSoWadHM32yyGOkPkKjTxZJldmhfVqKqnRRLbV+UWbx0KGxHf4SYMFVlycl1qWnRDmZ
n5WPBs0pT5l50JrrEnkY4Wutd7m2hoQkjQkiiWn6cNnNJl1zcCP/E7digRh0qg+kZlhtu4LnU3Ux
K6V+clG5YmH0+Fg5VsUwzD2TMOpX/3pE1+8RwcMPhGsPpkaZhWhLry0rP7uylK4GBd1jT7iVdDcq
SW9JNuopQzJgU096JFuqxI0U6d6ikapyT8mLJLI3sIdgRnF3ImDgjIMCONLEgdSMElnlpqixyHk3
TPNwJb8mdJuyUpBDKkjGIRSg9p1GikPknyoCQc2mClFfZQhq1lfDPXxng5oNj0+vPw1q1ukRhDCf
L/IYdSSbLjv2ZEvCDJtAhlicAcl+aJqoL9RbRMGmL8WZ3zC5ae+lYXzQ+PUkm592Vc6Areme1hbU
PL1GS9E0ZplCQ/Ce483HMo1xJgFSJMCgZsNMclyAbp21KoIgVBHQ2kjNmMKa6lSlw1y0qEmRKo/R
FAqJVxHyLpooZx9jXVu2zOymTC8T6zLXZSiLlPnLlDKnG1ZqwveJEslxkrmjvV/UjEkkOXkYGBt/
5FOAdZqxDBUwPk6gkIc/1tM5/UvjzRsmZ1CzYcDpxKOgZp1AtXfrDGrWu2PX9pYHNWs7pFlVGNSs
08NBWcM6lE0dsytKHFvNIonZw2fQxXudzxfvMEoKkRK5egl0kNvFcgwvI0lqYW5t0x7h/RmqMWM7
44wzMDKCNC2J8A60k8wqqF2SjRy5N7Rmg071WmqGJrADFEkenjwHR4UpaA/ywnCRambQBncnkQUy
lZAp1PbX+RQ4Q9kPSowLXwNTNKhZ20GuRoVBzaoxju3qRVCzdiFZgXqCmlVgEIfpQlCzYcBpy6Pk
McFgiQBGDBOkEWtgaiWkmLBjbLdE4UArEDTysEug73wu7RFcmisi7Z4W5tOw1BLnVbm4EVFq4GWi
qCG8bNJ8tegj6ChpKsnYyfHTQLRlQCtWSUnNuAnwyRK1A2UQ0pCFqiDkvMB4rbr4OHTnEkiffxnd
mZgeDb4xFfFvg/mnmk1VlNraIKJ+u6pNMMIT52XNy/6W2ykiTPyGPMvP0JpV7JfVeneCmrWOYZVq
CGpWpdFssS9BzVoEMPPiQc06PUDJCojBkjAdmALvXT5QzO04tnByEYNFlAPqMzZOyIVLLIJ8Lu3B
enhvOT9II/NpWGqJ5gl3id4iZddff70zJvgZCezw1FNPoRh0QKwZRXhgUMpmb1R0QJ2eXa3Xj5r5
CGCv5meKVGPrwLQUZF5gDcodBn4M/zh0mwZivIjlktWlSc6mFICRe1qezYMb9JhKMtcUQVesEqxT
mEonbdmogTnk0+5B5lM0fcrC16z1H12DNQQ1axCoPskW1KxPBrqRbgY1awSl3s0T1KzTY0eeATJ2
QKShOKOYcNopey175uzuUogDEQm41dD4OFAsq4uIzkSQcM6BSyOzapvGaB7chElPoR7EbfC9wss4
TLEd5ehE6EWKOx1IrdNTqKP1J2pmfuKwtg7EaDU5wSg+BnhFeU02t6LOsmjlhJXbxaIV0xFHUeB9
Ue5zax4rZa3icOfMQbscTpdwQiXFLkczAVJ8CmDOgBP+vhJBzTo61Xuu8qBmPTdkHW1wULOOwttb
lQc1663xGmlrg5qNFLGR5if68nJircSmkQwmYCBtjlCNQogLgWvnnOsZRQ+aJmwdQ8fcLnwH9xG2
Ls/mcQgCHfcoikjqHnaMNBFUk+Jh8jLj10PopTIzBAZipGPXJ/l9BLBXWFEyorSILTCNOzKOmNPn
OopOUA62o7lZtGoPm9sDDjjAcQkUu+hPbi1kGlra3NLwOu/YrwntTY5mAozAHPLpsJKgZn3yi2uw
m0HNGgSqT7IFNeuTgW6km0HNGkGpd/MENevC2JG4sAPSL3bG9YkwxoqJDIyg4REkYXoKkRvtoud5
oZA5Nw96bES57TBipPTBfGkiEi9LLjxJHxHUbKipzgsvTU6gkQapcoy4Lz+Vroj0YhUKW8FqFLMQ
O9HFOzKfi2krd0hGg/zCtDCfhqWWaB6zW8oyNrd8S7FdNrdUZk5YM11TmJqk2M1/98B3zBZTGDQO
9Ttqe3pQs7ZD2tMVBjXr6eFrb+ODmrUXz9xqC2rWhREh0iTFmb1x7IzlGMtGARsRNLIZjmbzHKdw
iVyR4ZVaSGLPsG1AoyPTQoHfGYtSlmG+4irQROBlzopCilGP4GXDzHP4ELnBlbS6kLRjgIw/+uij
lJLOemAvyo+PwS1jvNwuVpfnnHOOkyNYNrJuza15yey2tLmlE6clx8teeuklJzuwuU2+kPDPf5YG
NRvmR9SJR0HNOoFq79YZ1Kx3x67tLe8+NUMW+EQTrnyXrF9O/+QxvcACC5Cy2t67qLCOmpFySQul
gU3g0xYE8AJyF6gJYNQTZGA7z0QykxxHQyVYOWJqkM/w8jMk/foOCGaeYfM0CXQA1DxKH0pJs5ca
gh1j4mVIMZEyqNkwMxk+JqeZaVryzgMp1iBuvNDuSATjRvaiOBqL1g+Pjs7vQh6vvfZaIU/zbCE6
xuaWpqzW5tZuDN2uL4C9GsjDP/9ZmqiZH1c6cppJtlkRR04P88tq8VEdNbOPZ72Av3Vk1D9oJoNd
L43x1dUwRgtENW6VIpGSIlrseBQfFIGgZoPC0p+Jo0vNbN7yH+HsENSsQ9OvlpqxYgpq1iGcEztL
ujOUgTCGO+BoljbyMDaBqWV4aRtBXaQ+4Rm1OcMWahL0tJOIC0yQApbo4jK3MeL8Jd4OTbkRVVtq
dYGJnWG7VJC+BmxuCV3sRZPNLaaW4cUMWPP8m2fbNIwKkhck02WEl5432dwm3W6arvAfdWF7qhOm
jprpDsrJ0U+QEwYAUy0eGUaKAGo2YcIEHpT2RvwMS/NXH7dRny1BzUY6mq3nD2rWOoaVqWFUqJnV
injga88aX7w1bg4LLrhgZSDNqiPEV7vNDq5iZkO8sZdLFCfoJrf0rJra642xmFrOkAViGNhtOeJo
6cJ6XDDP7dIqAuR2220nwr/G59a81J6PwPsLJD8iZP8NWAgnUqbNoy7D9MS8TdMShr69fv4+v0lJ
iqDhET4LaFq2BrcaRs2nkRka3KYmaaHmJZtbyjKKcghjwexDYG669sRE1Ug/MRsgdDdmBbLw0EMP
oWZCr+DyPTHPe6uRjAF22mmnU089FTWzTd0/1EzHyX6s033Me2vIOtraoGYdhbe3Kh9dambP1n4j
B+qZZ55ZbCtHF7m4pWd+MQDjYpB5IzUPmERuB7wut9xyjG3sjfPZ8VUMata5HymmkC5yjotIXF4k
tAwv1EzsO5H6YJJh8zSpBNBNQjUh3LlBrF7NEIOkHQOyN3ZG/KaOZB1KCMfRCN4umzZoRW6XViE+
4kmyr9PI3JqX2qORvqsYGesvpAy2lLxwxstgnuatIch8XvlxJWqWbNiQBZSBQaPz6Ln79cTSzBXR
6uzfzFfnDwWd668XGXXVVVdFzXh9oiqUaL7GfptGYdRni8mAN2lM2w0aiR+77rrrXHPNtfHGG3Nw
zvxH0Ujz/N4toKIAwaqR/EPlCWo2FDJ9mD5a1IxDukXNliNVDrWOk5WWXnppR4suuuiijhZl3zjf
fPPNm+WlYdNMM80ss8yScwsBuPDCCy+++OJLLrmk4GZ2PkVxZ6BiX5f8kNwfiGp9OOGjy3UIWE22
3XbbRM3qHsWfVUIgsTO/eoJfUp/R6RC9SEr0Oy4Chs9ybpeGsRU0RcUqQXZya15qD+i0E5I+rVDV
TqpeOKeNBcinK/PplKRxNsMIApqALFg1HNb22c9+Nq3OiyyyiNV5/vnnz3Jl/rBRs88++4wzzjjb
bLPl2UIyA/RgSM4h7SyzzDLOKL/qqqu4ddimpkXC6+GPE5kwoztbOkfN+Kw51J4QZZgcM+FnUttT
+xi1f6b7QRMHZkspWj7w0aCJA7M1l+LHssYaaxBiDWJzNaRSQc1aQa9iZbtMzaBntbJsWctsgTIC
sexqg1+obS4hiM8880zmE7xNDznkkIMOOujA/C4N89lfb7313OTWOj/tgw8+2Cmowk3bixPe2Wdf
PGfu876Hllr2S0Rx8gPZbESfu4pN++hOiYDJYJ7YHi9T4qaqCJD3iCh++D7CtDkkQN8BVzIZzdOc
VfOobyh2BQPR8jwbqVUJQ3KmC7CJlEG7J0hZmvCaquWoJXUqmkCjwaZFeBOHHtIIOLng9NNPdzS5
UJmTJk2y1mS4/G2zzTZjx46l5suweeQZMgPZhoRDzhH9jOLMUQu+vaQgqmGb1Zg+/P02q0rN9MsR
ijj+aqutNueccx511FH2itP08zM3o+wkr7LKKmYaNGRGdoC24oorrrzyykQaXjASsVeK0Q022EAl
RB0bzn5oQHPUu6FHeDfZZBOfC9n8DMmWm2++OZ+OjTbayEy2GUXydByhZtBa8rPeZ599UsSD9ddf
3+n27HjTj9dppMxNV1ppJYn89P00mB5p4RVXXOGliBjdn0hKhszJhkj3PPPMQ8WshU0vH0HNmoau
egVHhZpZbW0wMqRh0J6CNIoKJnoz6zvfK9t0p5xyis+XVYADcm6XI1DppPyi3eTWtmOPPRZoGubL
Rt72DfEFu/POOy2vtJOWWguuZdcni/zQ0X2k6v1SokeBQAUQINiUly+AKzE10kiel+aR2Xbeeed7
771Xy/NspFZpZ7pAWiLspofmjNaSb6n8bJyyz7RxyoiUrR3h1rEFdvmc4IZTCFthdbbW5Lb8Wfsm
Tpw4btw4sTUybJ4mwY1sQ8LBc9Pp5CSfxx57jEELb0okBfJovlEY9WljGiMjbTdoZEG96aab8rDg
EmKkcCtUyMSTjk+x83F84fjx41klmWkw2WqrrSgZ99hjD+rFWWed1dyTk2xD+YiD01VRvdm3IUkK
WYN/Kbv33nujfgwmCbckH+9CoyTSVFKqykYQWn311TnRoIGf/vSnP/axj9lsR/1wuo9//ON77rkn
emVcaIoVoTKee+655eQPwlZ2scUWm2OOOdZcc01sUQ1Ymx1vEpcaZNtvv/1o0Joeu6BmTUNXvYLd
p2bWL9TMT57VhJ9AsmlMijP6HftIXM8QNCefsm+3rZHb5YxRP/wdd9zRTW5t055zzz1Xw0RW8eX3
JbFNJLYzuxQU2IfOfpGPv8XXV9e3t3rzOXoUCAQCFUMANfO9Rc0q1q/cukNCxjGp/2ycEoBFpRBw
UlRM6gPKHWe3OcLAdh+CRjbOcHW29pGN11prLZJ8hs3TJFINUpZOJ7cXTbNDZUY1iSyUBi3wNwqj
Pjc6RM0cx4AB0T1RimEi6AypDxtFfOin6Mtuu+02GwLmG1hcUhAuOwPYq0TqLf7yqJZEQiMfT18G
6iq+qMQeJG733Xc3YwU9u+OOO0xgkYd5diDsCtpk4DuDxJE5nZPIqJJQ5NuClC211FIUlzR0qKJH
GmAiqZaymAaBtg7zYtNFd4DKbb/99irRDJlRPL8RfVlnnXVo8dTcysAFNWsFvYqV7T4185OnsqG1
xxFsE5nkth38Bv2a7FRQSfup4hTsG/0uuMDkdtntQc3s7Whkbm2zdAINdOkI1HvuucceEVNGanf2
ElRmyZox7cv11o5uxX53WXUn7fln1aRoTCBQIsBgyW6571iZEjedQMCKkDZOmVVwerKPR/4kvoqi
jEGgxgwwEAoroB1Ua40rqxVQq1iaUa+w6s9QeACXFhIbSDiQxCZIX05ewA7McGpKpnHJoMUodGJ8
R1RnJ6iZCUbTSp/FFJA9DyHKfaJpdgOMGoUUH7RPfvKTLAlxJSIi7wx2jxKRONoxxj9kRSSO/osf
/ZgxY1gS0qYZbvvPG2644UwzzSSz9DPOOIN4idCxY0yJ2BySldTBKBWfFEzKJMfFzBn32PHaa69N
E2fCb7nlljR3tHhK0Z1RkLGBdMwTakbvSY5SuVKiuBg+mjIFU4UjArkuc1CzOkD6+c/uUzM/T/p6
W0OcXHz/7Xv4Ltl58Eu0s/Hd737XHh3fKB8uzIIpRW6XhjFLYN3hJre2aY9WYbj2piymLCXsIDEY
wMt8PXxM+Kqnjz9pPKhZP//wy76bEpMnT6ZaLVPiJhDIDQHCamj5uzAocGZQYe+OqEz+tJvHrJHw
ydcGNSYtCKfvW4GmZbg6axLaSHeGBOXZPKsz2YaEYyManmQe+9KsWahdGBHBHPLwryo1w33Qmemn
n37aaadFoNK/tFcIF0sq8gnxj06W+gnb4iBGLKS0IsZIFM6R7SJXMiPLEhKfwnA5f5mTrBbVbCEj
51BEYn+0YKLBKKVO2wsSGbsiWTPMMAOtJaVYScfIn+5ZLaJmtGwYlj+xPwfKfOpTn6Ij1iSXLW7H
i2DWyBonNYOF4imFmhnBRM1Ca9aFD1T/vGJUqJkvD8UZszrfIpPcr4PuzM/KJPersQogFGiab5ed
kAwvO12al2HDIObSNi302bfh6eNmbWU46htlU44dafr4k3OCmvXPz3yYnhLALEN2v4fJE48CgUCg
HxCwLtg4JSczayHrJnZm75TFHYLG6szqTKeQ5/JnRdawJDxkuDqXzYMhOxbSDpkHtuQfOEObRAT5
THZNO6E1oyukdeJTxrAHS0Wy3NN/3Xzzzcg+TZZQ0igSoZSDGBPBKVOm0GFRscGKOSKHLzaExpcD
Gt5E74bTCUoj9otEinWmkmwO8Vx+arRpOBQtKg2aeiQyKBUlgBu+aTwMNfNGgpPIHowYadnIUcg+
1ZsWombiatrJHJSa8T5DEkm2TX8oQmvWNHTVK9h9agbD9P0v2ZnAFIiDDTq7FnaQfK8sBOx+0Qo/
yQwvXw/Ny7BhmgQ0bdNCjMxnHymjsvflZxuQeBnYM/n4V+/X1Is9ssow17fo9GLjo82BQCDQRgTs
19k4TWYtiZ35PlidrSNWZwqItDpbZVwZroDWviQ8ZNg2iKXm0b9AEp5kHtiyHbJHDW28DPI5qMzM
qLZTM13DvJgs0mky3UmT1rqDZIm8YbyE/fSU4SKyhkOxUaSZEtCSQSO7R4+E/uCmh8Paf6Z9Y2RI
NfaJT3wCjeIaiUMxKaRuYw/JFlGkDhTMVj8rR+o2jmMSsT9sjmiE4iUjRq+QM2nNkvJLHo0x4Xks
qlxgEGo+tpREU34itGbInR8FdZ5S9HcyswFjlimzao1y07/HoGZNQ1e9gqNCzdL3n+IeTaDEYdmI
OPhA+X35pdhE8sny08jz0jbbhn6A2TZSw+wRYWQ++0gZZZkvv4+hD0jiZb66oTKr3m+5uR4FNWsO
tyjVNQQsBOIaEbS69sZ+fpHVATuwOlsv6HGszlYQqzNZNP/VGeuhkMLOcl6dLc2QJO3YlCb5QDjp
yxIvy2Rpbjs1I+nRbTHmxO6TcEI+QVGJoDRiLBLtJAv0IZSZYCmyIUqkF/ZUzBFTBBVuGhLNQ7OR
YovWjPOXRNKORJkRMVyPyoy/iWkAZIkcOuRMieibV3uXN7KTxI59W8p7lUv0p5cqqD2iqLGKdKIi
XuYVmDW9mLeYXS6Z2TrK5hGCxp1EqASdanoEg5r184e3ru+jQs20wexNu3PlEoA7+EbZEvGx8snK
9rK7Zb+FRt5Nto20mEISI6Mp005fRTtyoE4BH5r+dNRNnvizAghYg8SaDoPGCgxlVbvAlE5UNAZF
Ve1gbv1K7AxTsJWXCJp1JP/V2ZJHpKdnISHnLEVom6XZReZByiCc7BizsmZpOzXzKxZqnoqKxSAX
rXRRM0lxuXGJrin6oiulyDNoonSVpMz+lSfVViaqwX1KH5gonUFj+dK6+7JC6rPyFSrxCilKpZpT
JWVmiR6RDFlpGtPmftFBzZrDrZKlRouaATOxMwTNFylp0HygfKbwCHM728sny48UNXOTbSM1DIzp
m295LUmZNgcvq+QPuelO+dGxD7H113QNUTAQ6CgCdqR32WUX0Y06+paovBYBK4XL0oygWT58JVzW
FFe2q56VTvArgf4oXxKjzLOpMExLM0jT0gxnaGe1NGuPtqHk9u5ol+ieLBNor18i1WTtVGnwHg+l
daL7ps+q5JXsJ2n0yLQNYlKXLahZHSD9/OcoUjOw+xa5PlwDPjKi8K9vVOaXZtshcdCGm8ybqnm+
Ei7AJqi1Oa5AIBAIBHoIgaBmozVYHy7MH10WkfwXOy1lYCbcuhAT7vNvsBZqZ1qa/TtaozzoezWs
vdRs0LdEYi0CQc1q0ejz+9GlZgPBLz9T2d5oM702h1A32TaybNhAhCMlEAgEAoEeQiAMGjMZrHJZ
yfMGShyFhOyjYM2zhXWtymRYB21GULNBYeloYlCzjsLbW5XnRs16Aj0xf/iH9kRTo5GBwPAI2Lll
r8IMY/hs8TQQGC0EmFQJBSBiwGg1IN7bKwgwunPqqMPXeqXB2bYzH2qmJbzzxPRIlzgbzCwltgs6
Vq9CsrC3bGOdzbUtqFktbmQSY/3PYf/w/4aJfXVtnqHuZVPctGliTAV1ESiGyfFQlXcnPahZEzib
JH7ITRSMIoFAbgj4gokSfNNNN+XWsGhPIBAIBAIjQoBA5YNG2B5Rqcg8EAEybSYGjUZz7733XnTR
RUXFF0VfdH33hx56qB1FWsiBLR9pyu23384OSrBHwdNEj7z55pvFYOQGONJ6Ws8f1KzE0I4xr8ZF
FlnEqQcGPV0OtmPc3gjbso/H7WjixInGtKyzwRvBahzoIJqoNgxaRAOc0HfbbbeJ5DNohrYkBjVr
C4xRSSDQowgIni/8nUNkerT90exAIBAIBAKB9iKQDzUTYnrzzTd3NtnGG2+Mo+28884OF5thhhnS
cWat91q8fVzvjDPOQOrFEFD5BRdcQOHSes0jrSGoWYkYWuSUOufWOewbR3PsOJ7l5Lt33323EWrm
6LqFFlqIeRvxpqyzwZsbb7zR1BIYbZgXrbTSSksttZSTFxqss4lsQc2aAC2KBAKVQSDONavMUFa1
I8k6RVy7qnYw+hUI5IZAbtTs05/+tPNkk7TsBDGC8aabbkoCJ8M7MWHffffddtttHYjm2DKqNPo+
LidI3AYbbHDUUUc5hVY2QSZPOeUUptGOgWAS6eyzL3zhC85EE22blsR5ak8++SSNiZOj1157bUE+
u28ZFdSs/BUYr/XXX98h46J61lEkh9Mdd9xxQv1QdG633XYnnniiQUx5BGg1E/baay/HmqNmZgjx
xvQ48sgjH3zwQabOdqGnTJnilI30ou9973vOCsfgjLsT64R4lU5tOnny5GTT6EC9K664wmTYZ599
dtttN3RJHvvYCy64IO3t0Ucf7dVtUd2WHS9vgpqVUDR+Q5X56quvNp4/cgYC2SIQWrNshyYalhDw
sd1///2tsAFIIDA8Ag4CTkcGD58tnk4Vgdyo2WKLLSa6C6HahVXRcx100EG/+MUv6Lk8mnfeedGr
j3/84+Rnho6O6ZTBgWXrrLPO7LPP7l8SvtPullxySUyNBxOvJZI/uieMf6JmhHDSvoPJZpppJnZ0
BPImbOGmiurwGYKalfigZhgTmnz88ccbTWwI2/rXf/1XzAh1QosYOi677LK423TTTbfffvvRcjp8
fOGFF55++uklzjnnnPSqqBlNqNPG1WOGSJ955pmnmWYabA43f/zxx2lIaWNXWWUVGcwTpq0MWbfZ
Zht/emqmjRkzZpZZZjGX3FDhmRjPPfccojfHHHN87GMf22yzzRwkUcccyy60eBPUrAkAnWuWIjQ2
UTaKBAJZIeDYdHKv3YasWhWNCQRKBERotAFOcCpT4iYQGBSBMnj+oE8jsXEEsqJmW2+9NdpFVYFb
0YaQitEuKg8RG4jHBGw6EcGCdt99d/5o1jJKEN5JFGFoGvXZNddcg8TRfdC1HXPMMUqhZgqSt7mV
JWpGgE8GjYjeueee231eZmiCmpXzEzVjyogNYVLlRR2Ggt16662o2YQJEwwiTajxwq3YFrJ7NDGY
p6JUTFKxp0TNTAO0a6eddjIHaNzMARyNUyENmjwIOwdV+znzzTcfYm5uyGkWUaGqh+EilkcZJ4/Z
ZRLyMnPPkW3s2LFvvvlmh1RmcAhqVk6Gxm98Fr7yla80nj9yBgLZImAJ9gkKa7FsBygaFueaxRxo
EAH76o5Fvu+++xrMH9mGQiArarbVVlsl5dcOO+xA3qYBwaqMtS/DaqutRsAeN27cZz7zGYozwjyF
10UXXeSeSE+uJsOL2CmWCFNGzC5RMzxuKGqG6J133nlBzWonBgLCqpzTHxsbJIiBKOZCmbXyyisj
O2hUbea23KuTMarhu/jii6nDjKB/DbdmJGqGfGmPcRQbRDNs36255pq0ZokuYV40XJtssokGJ2qm
FEqlWvOBpoxNLKWbsgwX9Y7xquK0Y7RgtdRMhsT7dIquTUH10KwlasYfLahZW4a7XZUENWsXklFP
IBAIBALDIxBas+HxiaclAkHNSihavMmKmgkDgjEZXKK1089PPfVUeo3TTjuN4kxwxeWXX574fcMN
N4gzLIYD4sCbTIQ92Yj3xGlaEubQ9COl1oxLmigThPMf/OAHdVozL4owIHWTZ1SoWfI1GxiSMVEz
jmbp1IPEnqwRxPKkDtNadqp0rMnXrKRmKBV7yBRShmfZiiuuuMwyy7z99tvys29EwQw9tlVLzajG
sDBm0gBJ1IxSJlGzktbVYdWuP0Nr1gSSBpGFcxMFMyniq2sGfvWrX00fOt61Z511lt2GqTZPflPa
12yqOZvOwIH3nnvusSdT1uCHY6PGJ9dG1ve//3125pd/dBkCOzb6knIKZOrjbMfMw6uvvtoeC313
WUlbbiwKfvJqdgMEv51Bq/XL9cjSUPtUO3mMspafqn7KB0c2mWuLx30g0LcI8BPZc8892Sz1LQLR
8QYRYNAojFvYvjYI1zDZMqRmBpcEos1WefoR+i9hQChBllhiCWZm5GcaFm5H999/v6ANNCaIG62K
+6TsoHlB4qSTYcSCYAhHMq+jZvyYpIsyoTaCxzD4dOJRGDSWqBpotJo+VORMkmp5GVAGqwwaUTNa
MzIeisTskIhojeBKxjDVekF1Puuss9YaNPJcI1WaJwwXTQP5oc2PjPGqWcTklQWsoCKMWnfcccfS
oBE1w/0HUjOJZt0zzzxDi1e2ub03Qc2awNM34bHHHmui4OgWsWNgA8GOkGnvM+WbhgdR+Jp+PB/T
9Bumhb5UCB3Tgo6yBkpnMXNsgLhJjdHs008/nSmCpkLeL47luWbIY5fjkEMO8QvVNr8vlsa00iI1
+Rn66vrNYp3D9Gikj8DFF9XSr0m27Lxo0Bp4b7F119Tap8ridNrMB7k2feA97saT0eqAAA582vYU
TND3isl922uOCgOBtiBgr4ObgI3NttQWlVQYAXvsnE246le4j93pWlbUzIK+wAILEFYTNTPE7BVp
N6g8HnnkETaNZHIWj0JAWHmdaXXllVeyZyNgU5MRGBQnrtvaFSSENC4zcUKoB9K1vVZrOks2Mgax
nPROHOJSRMInb3QH6vItQc1KKAg/n/3sZ4XyKB3N0g3tJ+lIDBA2q8mg0RAvvfTSxCpDSeQTFQSh
ow8lDVKMlgaNZEXka9pppzXutKvESxJjeoV5ohS+RlxEtYiX5oyZQPdqnlCuJYn32GOPlZ4MGu0A
mEWK+OB0SE4LalZOhh69QRNMM9yEAyNSUNsLwoxjIMpEnyaej75OpHGleBiZVBTBtolooySa6mVx
4lCdLCSFhYDws2WedKOgelAPJ3HX1uCpGlgOeOTeR9VUT0ou/7pPu1LKypbSZfOnjy3FdKmb006E
C1XRAHxniy22SO+V066FIEv2VRI14yD87LPPpqd6jbX5hYIlpZT/yuwjDBk1p0QNKJmgFL1Iui05
dQpp1ceUU7qWQ0/cXaEJUmLK5vebSsFZBFdAqZNImWLwAsFXxacgtUcRmVVe1pyqSv8qhffV6d1q
M7Tx3jaUzSJ2422sM6oKBAKBQCAQ6F0EMqFmFkpLJH3ZvffeS9NhMfWnLWKKUVudFlBrMQtGXEzA
c7oVy6uF1YJOimALJLy5RzyP0hIvKgiDNCkUakRf+jXyiacMdcgbQkywvRERgtWNvfc6YaYLQxnU
rASZsCf4xh133CFqYu1FbEOpRHTBiUhiZC2D6CLvKfLSSy/RnF522WVGk+mRITbuyaBRjEelEDrV
SjRJ5DeRpJMtL7300ldeecXUchl6tq/EOZNBJbQYxEXphGSb2N6uuIKstuhYUT9TtGx2G2+CmrUR
zO5XlZwiRdhDQ+wdcYZl1Geq4EEmFUaD17OV9S1CDdhU859lCWAemn577LGHbx2yhv47zBHX4GOb
Tlo0bw8//HAq47JH6vQRozj2iygT3ZjeTHAFOLWF5akotfYupGuYqcszV5OQKYzJPHcjJKm2+a6u
tdZaqnLvk+scSTyrrFYb6IttW0mRbvsCU1Otd6FmvHfLnDqlkfiXyv1YWBeXajINRnBsizGALPO7
8SX34xVj02YIfOyfqNZX/eCDD05t8FvDufwe/QChysPUNhqzZ4jpFLtKmycq8dlP1MzP1hdV32Wz
O6enPhd65B62EunlLRO11Exxo4OmAYflM6f1ul+3b45NPG+vbXmH7vWXBt8+ZIfqj2oDgUAgEAgE
eguBTKhZWmpJDuL1WTEJGOPHjxdJz/KaUvxJOeLPdMkjxWXZleJf2eSvK2hB9zTV4KkbKSlPKkUe
IFF0eciCmiXAiUPEUZIeubTuMliG23j51ygbMveuNHZpJvjTaKZ/SafoOY2qQJ3UbTRipkTKrHjK
nyZJqjDNHC9NE0kl5kPKr07pKZt/lRJLhPTYoUkS1KwJYMnwpZanieJtLELgRzTo6Flf41kiCzHk
SxtBlLx0r4R8ltXUsmYRyoAs0PjjPiYqNmFfiOKJ1gz9sWlA52tLwe/CzoDEkuZoMA5lZwn7U2Ft
+5E4dWJAuIxPGV0POR8+6lluueXShoOdiuQy6ZFfisl86KGH4oPoAL0S+0BHjdTW6WtsoyPZNMqM
CvmZSHRfR828yB4X0wWNF2mnlpqpUO/8smoJjlGznQIivfaUgbF75sqoIpMG+yQqpNsCnc03WyLa
kNSOhx12mB9mWib8utMNagZ/5hBoprI4mpNWmInCGe2Fue4blJNPPhlu9vf81nTE62y/SLF9R2Pl
LUiiGLC1COipAfLbRzlr0ztxH9SsE6hGnW1EwI6oX6Ud7zbWGVVVEgGLl2943U5XJXva6U5lQs2M
JsMeMgwdGW/Trl1MVuzNdhrkuvqDmpWA0H/55rc43OYMTw276OypCFSkRBOpxTrL4ionc5qfZZvb
exPUrAk8SeBwa6Jg24skakY5pWbfUnooahr6fV6uCH56HfpDieNCo/zr549nmag0RygG6sFYl822
pxMnTsRB1Kn42muvXWvjJxHDUqcitb1Qir6M06VESiVsyw4D5a9NJzo4xETNFEkUW5iIp3ZCMBcW
dC6kDPXwojowdUR8D3QPhfF5pNtCOdU/KDXzCcUiURsdqaNmmsGHjm1hbYO9kS26NngFD1AsTPwT
XBVXShbI1IWKWNxZL2s/joa3GnGxX/RdEeSrpGay4VwsHmV+4oknqC/tsajcARyJEsqgfn30i6Z3
s+cjM3c/RE+DgePTYQcGFa1tJCQp2nRcKNfa9E7co4dQCoPGTmAbdbYFAbKZXR3q9bbUFpVUGAEL
AROR7piCVxhGXcuEmlUb5LreBTWrA6Qtf5IDbZuTHttSW9cqCWrWBNTs0OhGmyjY9iIYE4s+ojUK
4Fv66quvUsGQZGiasIn0OnOS35O4GWgUyiDIRi01sxeNmqEP6AC+pmvICPbBray2tciIFHYFytam
J0KHsEhUAz0daobpUC1RG3kpLuYSKsepIpgjBRPDYFZ8tF0YpX8Rk4GhFKm00EDbHZgL5pVMCwZS
M29kjUzZhxmhOXXUDEVCP5NhZGozlLwLONRhQNM8TBZTUzObRlow9SBEtmuAieGK+aOR0EC42IUO
pGayQdtZhLLRHtJz6an38hIVJyS9FHeTyAyeMSdqBnCsjZIOmHAAzpZbbkl/V4sqkKksvVHltemd
uEd+CTNoYycqjzoDgdYR8N1wnCgb4NarihqqjQCnJCYZrCCq3c0u9C6oWRdArntFULM6QPr5z6Bm
TYw+wZ4OqImCbS+SqBkzwkTNaGwTNaNmKuMHJuURNRYahWugbINSMzVQ6FAeCT6PoBGHaluLldCa
YSh1mw911AxjRc1I+9iKjW56NyRLtA0UjJmldERMMFvMRSLNkfb406tr3+Vev7hnYklHHnkkXZ5l
QmKiZhhNmVnX0CvqOTVgWLVhQPSRD5fYO8n3LRVRA4tKfaSJRusYN/LFw+nUT7XHrQxJ0UK+xi7s
UsgUVE5O8VphUkfNNEzv0Cvmiykb68SkNdOvAw44wEtTw2DiTBYgoGaUZUiuvkNDcQairCu1oeyU
G2+kNaNr06na9LgPBPoQgaBmfTjozXXZZzaOnG4OurpSnaZmVkbiQVpq/Wsp7JxtWG3XyAAMpEkO
SaiofTTq90HNRn0I8mlAULMmxoI6IxNqhizwNUNPfOh8aih6eHiRZCib6GWYAKEMTOkonoj6voT4
Ah2NRAoyvmaKU+LQOiUKIAOFDt0TVlX34fLZtCGJnpRRDRNuqBmDxmSPh1DgJvgUYkWZJXYivsNe
jh3jmDFjsA9fxRNOOIFnnFgl3sX8j8eZaCEDh0B3KPI0jP+mqDgpg+K80kQIUa0IS/qFE+kmu0f5
+cc57YL6yVMmiKL08EETe6e2I2qwp6qFXMPYCnK7K7mbpYFjmr4nDaDFAsmiZNR+FWJJukAdpqfU
bXCjjNNx2VA5TBOkmoSzU5+pXM0axuFO9CdkkAYwOf2ph2LOWLDwxBxVTpmITde69emsduo1HVwd
2gOBipRAoPII0B1TSYdBY+UHuvUOBjVrHcNUg3XTOm7/0CJFSGApymIf7aW/bouZPc8CBjy2Q0ks
PL4tryxqbAuzPWtXFwatx4JrjbbKe5GI+qQIm8bdYYWDtqc2MahZLRp9fh/UrIkJwEwuE4NGbAjN
oQjDTVzoDOaFDkhHiFjr0ddoLU8iHx+KJJYePoPnnHMO1sDby7cXj8BBOFXBQR6aHdSJ9d1AWLAP
tAgPqn2EYVFsJU8l9QsV4tPt7dKZI4r+kcLgICOpfjcqIWvJQxWF5KZX19aZ7hNPxGXscaUUhOjC
Cy/kg+ZME2QTu6GbS0oxfacIw3GkeyqPgmIz4ji1NVtuKBZhog2OnmQLSvPleyhde/BKDmVp3dEX
hpd0auqhf9RBCi+KPEE/sFe4ia/LKy1BanHRTXjKht95xIIUDuwYkTX/8mlVv6XN66wItuzktCop
JTCI2LDaX9tOPA71S95qtemduPdqKOlRJyqPOgOB1hEgGdoSoVxuvaqoodoIhEFju8a309TMsm5J
dfiU/V4SiIXSNqxzrGw1c4hoVy8G1sN03wY1+c22p6hi9maRNaLFwJzdTwlq1n3Ms31jULMmhgav
YZbWRMFOFCFau8qay3s3Pj68z+qi/FEPueSvzZmKo2b8oVCGkg2V1brx+RLRlB6qNtG9emqrqr0X
/U8DaNZqi5QZUtnaRwPvazOn/FKsGq66R7VPBz6qrRnpo8JLIOBWdGHl07qCACQWYlUy6AXGJEPK
U3sjG2KoKtnQLjuNKQ/KY0eulvWkdNncWICQ6LrRSS1hWUo3R1uX/uzov5rh7AMBPDv6lqg8EAgE
AoFOI2D/kMWIr26nX1T5+q2wVq7Oac0suwxObBSL2eJd8LTJbFuVftzqbH20FWOHk57ORnEiayIe
29K0w8m3wppFdk2LuLKKsJMRv4tdDRkmiRwWbkoxkc04Tdgv5UQvJ02ZcNYImmycIxxA7KkNXp1V
id1alaBsDG/ICfIzbrHLzSRG89gC0eux80mqPTvM/uSZznhGztavoGatY1iZGoKaVWYoW+wIHkFt
ZCPLiVqDVuVr+e6779INoSGDZojEtiBgWTEQVofuWFmwVxHnhDawLY2PSgKBQCAQCAR6HYGuUTNU
C4ey2CVqxinegaQcLkQno1P7+Mc/PtNMM/GDQKwwl7nmmovTAcOeaaedlv8CloSd2f7lMiAbFZh/
nYLKIMceKbMZTg0cKzihzzjjjCiYPU9rK9MaXgZnnHGGSGXTTTedPNgfx/PaSrxFJSrn1JBOg/XS
k046iY4Pf2Q3ayfWsTjzzDOPtyCwbRnuoGZtgbEalQQ1q8Y4tt4LXyE7TiJU0A0NVZvPkb2mOpvG
oTJHenMIoGZ26oay82yuzmFKxblmw4ATjwKBQCAQ6EMEukDNGP/PNttsrHRsCHMxmHPOOf1LwEDN
eAHwSuBTIDgzHw3siakq1jbHHHPQavGmt5eIIiFTeBkNGookJLJFUxGeDiqkCOOJMN988+FiKuEK
gVjZW8bm+LArwpWDSg6Pk0LtJW4zCsYLQ7pgsNR5lHrcH1g/aqR72WhjbVzLRnkn8DLLFh4QXlQa
w7Q4T4KatQhglYoHNWtiNNmhDWry10RVUSQQGF0EUDMhLtlsjG4z4u2BwFAIJF8zNkVDZYj0QCAh
QH9BM8LCPABpEYGuUTMe8eJycEunluIGLt4Ik1R8DQPC3dAfai86rxtvvJHai/5LOCDGh+ibzEqx
J5QHj2P/jyLZYbacpRhc2BbNmlBjfMZZoSQP95KasX3lnUE79vWvf511Jd9zdIwVpY6rRJ2oH7tH
L6WMo0FLRpL0ZWoTwcyJw3gZa8k2Ws8GNWtx0lapeFCzJkbTngyr4yYKRpFAIDcEUDPm/b1l0GgJ
ZgPj3/ImN1SjPW1EICI0thHMaldF50LeJjZXu5td6F0XqFnyNTNkrHHorSZNmkQpJgyIFKwHA0J8
6MJEUzz//PNRNoQI58LF5E/UTOAvEmxJzcCCVYkvTcuGQ+Hp4pKJlsxwEbkTkhrpEwAkac1QM9yt
pGb0dNRt9n8SNaNx8y7UbO+993bDjiX5jPMN56FGuycsMz4ohFeibG0ZkaBmbYGxGpUENWtiHP0w
na3cRMEoEgjkhoAVh0mGrebcGjZUe6zLlmkrJl9sLReBGbscKnNdOo8Ghii0MHXp8WfOCMS5ZjmP
TlZtE2GYlVqcTt76oHSNmgkDkryq8a8FFliASwUzQgfHoF04GgUoPZd4IAwXGTTyNeN2IQOGhRk5
VFREZWScdozvGHtFcT8ETKZQU9ZBOYqwZrS6oVp4H87OvlFBBo2oGVUai0f6OITu6KOPph0TvLq0
ihQ8WcwQ9pO11Ayw2slbjZWj+NJ2jVqHuqwhqFkJRdwENWtiDuRz5HQTjY8igUBPI0BfZkeUxQuS
5fPllLrGTUrsozqVgI1KTyPQb40PatZvI950f30ZUDM6jqZriIIJgS5QM3aMWA8OlaiZ6Ih0WLRR
mJStb7othIsFo8ge7DqcW+o0GdSMWxkGJ9E91oZV+T6sv/769GJMEJkvsoSUjtM53QYdY6ZIYHOD
7nFFQcQQK6RMXBFBHdVPxeYU0eeff14lqk2VJCc1urzddttNM5IVZUKG5SQF3DTTTEPplqI+tmvO
BDVrF5IVqCeoWRODGFqzJkCLIoHAVBEQJpQftz1SR8ilAMUkBCu1NZT/NbkrWTBazf0GHd7NN9ze
ZqJmytoUveCCC1i8lOfUpE1XDuAOrxEMmbqNU7k9VZYqap5qeyJDDgjYmmakFEdO5zAWmbeB1oxA
Hlqz1oep09TM19gvmg+Xr7d3+bAjXxiZDzXPL39iQL75RlPkRhouPXJ+K1Z15ZVXWg4mT57sjFS8
TE6PxL0XKZGOTOhFq0MyMvTxv+uuu1B1mi9hQN544w3betiZt1DVCeHI3IJFoiOB2DFaPlQyZcoU
b7FePPXUUypRuSUG0ROVOpnQe5eW+xylA9FSgP3W0U41BDVrF5IVqCeoWRODSI3OdbSJglEkEMgN
ASsOWxE0Z9QbRqXFKGXMmDF77rmnHU4m/Qz7X375Zad+8yZgwcgBAfPSYPGWa6kZ9ZmcDF2cri4b
smZ5tWrb0rTnKacAyKuttpqz0Z2MQ93G4kWIrbRVO+q9jgZMFQExlwxcmKFOFajIQORmEfed73wn
oGgRgY5SM6zH2WSsF/bYY49ddtkF03FNnDjRl1/Kzjvv7M9d/3ntvvvuO+20E48z8T2otOy8IVxY
jOcpp8wqkU0NPMvKdKX8KdFTN/6Vkt5iXXCvuFKpDf6sq0SKmuXUKo9o7qw+mB1GydhScEjn26KN
bYylHNSsxUlbpeJBzZoYTQcg2mNpomAUCQRyQ8DOodXKEjO6DeNBRqzCy4hV9iptYKJm7nmCY1tS
+MRRqMnA/l8crVpqxiXcPjmrFRuwctrhdO9kHFuyQnh5qqwPHX5HvLfE20Qd3c7G2wOBQKATCPil
2+EpleadeEWf1NlRamaYbLY4BpqWapiLIswlg0OiGamiV8nti0pLSOGBBVPmuvSP6viwkgavQStR
VhusR1ihNYgtJZ81YfZtErYxWHdQsz75cTXSzaBmjaAUeQKBqiKAmtmNZEA4uh20j8oLgNqLZKUl
GBY7fwSN8SETl9Q2zAsjsziyPympmXCpsjn9004mB+2zzz6brYt6xPvi2W01T2VJGg7sYypDMRe+
ZqM71vH2QCAQyByBjlKz5vrOOuLNN9+0Llgdmquh9VK25R1ObcXpBP0Patb6AFWmhqBmTQzleeed
R/ZjGRVXIJAJAoz90lXXHonmqlgZa621ln/T0Zm1cx41Y7Yx6ueasfznRKCRacmz+ErhfcBV3P5q
ajDTkXHjxrElrqNmYnAxVqQgQ81SpGXdscPptFCLXSqrQqTPwsp/IahZ7QTI/56JAtVn4uz5tzZa
GAhUAIEMqVkFUB2+C0HNhsenr54GNWtiuJ2vwaDdZn5cgUA+CHzjo6tsD5N4RiAs/ThNi30x7bTT
zjnnnOznWQPWznnUbMKECaN+rhkTF61daqmlBEZGo7Aw4Y65FWibmIoazMXMx4oxCe+zWoNGWjOZ
WaHwJku0jt8ZgiYz1wBsVM3KCiGCgbJ1jAiNtaPfE/dMWHkLCovdE62NRo4iAiyWxQISUH0U21CN
Vwc16/44BjXrPubZvjGoWRNDw5OFVVUTBaNIINA1BFASlvC+9o5f2XDDDZEX1iAD387Gz/kvPLMG
PupyilAkvN4EAEGp+IVttdVWzPgxTXyNjeKll146fvx48YrpUMRhcyAp+0afL4zMDZGMQlDxa665
hhEjviauo5Bc1HD+xNRwNHFCaF44OAjz5fdL9uhyB+N1zSEgQiOH/W9+85vNFY9S/YOAeHosmWOq
tD7iQc1ax3CkNQQ1GyliFc4f1KyJwUXNvvKVrzRRMIoEAp1GQDwN57wI/4uR4S8OcOE0jaYN9V4q
Kn5enbCcH+qNQ6Vrya9//evLL79c6A+avhQ0UsMEwkIeHWoj6DFeRmbAxe644w4xGDlis2/kfSCR
/f9pp50mxAdmxyvBW8RgZBIpUfxkZVMwZKZxAikrHtRsqIHILd18FiEtIqLnNi4ZtifONWvXoAQ1
axeSjdcT1KxxrCqfM6hZE0Mc1KwJ0KJIpxHAUOwYsANcYoklRPp1TyPW6ZdG/YFApxEIrVmnEa5M
/UHN2jWUQc3ahWTj9QQ1axyryucMatbEEAut4BTCJgpGkUCgQwhQOVEzOc9LiEL6I3926EVRbSDQ
ZQS4H3Lv5XjY5ffG63oOgWTQGKeTtz5wQc1ax3CkNQQ1GyliFc4f1KyJwRV/uy6WQhOVRJFAIAcE
mAXedNNNMZ9zGItow6AIMMd977332KMO+jQSA4ESAScCsxYQ3rxMiZvmEAhq1hxurZQKatYKehUr
G9SsYgMa3QkERoQA9y42kF/84hdHVCoyBwKBQCAQCFQVgaBm3R/ZoGbdxzzbNwY1y3ZoomGBQBcQ
yORcs4E9DZvMgZhESiAQCAQCXUAgqFkXQK57RVCzOkD6+c+gZk2M/l/+8hdx8JooGEUCgdwQyJOa
/e53vxNZcURmlgLjX3zxxYwzh0JYdEcqQmec1WYQKeX44493PnUKBbnddttt8dHl5uSTT+blVJs5
7kcFAaPmyD5HIYzK2+OlPYSAoKx+yP7toTbn2dSgZt0fl6Bm3cc82zcGNWtiaHbbbbf777+/iYJR
JBDIDQFyr0PEcjNo/NWvfrXxxhsLjN84XH/605/uvPPOoYJF2Et59tlnN9poIyeg1dYplv64ceMc
+saVyZloCy644EUXXXTdddedf/752JkTrp1gW5s/7ruPgAiNIo5GbIfuI99zb3z++ef9ch977LGe
a3luDQ5q1v0RCWrWfcyzfWNQsyaGZtVVV/3yl7/cRMEoEgjkhoCQ+zfccMPTTz/duYaJNCKo9X33
3YcHeYs9bedBu37605+St5977rlyl1vAh+9973vCrL366qtbb731PffcQ9VFXUK3pYVqoONL7SQ5
iEgpAzqmnlSt+nE6LOydd95xtJkjtmX44Q9/6Okf/vAH/MtBbw7X1uVUiX8dkeZYaswUNbv++usd
Bidnevrb3/72gAMO+MxnPvP73/++zB833UcgzjXrPuY9+kafDqcixpHTrQ9fULPWMRxpDUHNRopY
hfMHNWticONcsyZAiyJ9iAB/MVoqKo911lln8803R4IcHIz7nHLKKSll0003XW655c4991ySAP0d
KrTCCisgZeuuu64jKnAxIdfQJRo0xbEkpaQgX2wd11xzTelqWH311Wmx0beDDz74zDPPZAzpfOr1
119fkU022WTppZemDsPaRDuZe+65P/e5z7377rvlWNRRs9VWW00z0lOEEU9cfPHFn3jiiTJ/3HQf
gaBm3ce8R98Y55q1a+CCmrULycbrCWrWOFaVzxnUrIkhJiuK0NtEwSgSCPQVAvRNJ5544s4778wB
hFqKeg47o+Q65phjll12WSI3K8Qrr7zSXsd//Md/+E2tvPLKr7/+Ok3Z7bffvsgii6BmL7/88mKL
LXbcccepAY1S1d577001ttNOO6kER6MCO++888aPH08Nt++++yJ9ONpee+2FZDnfDQ3kMrbBBht4
0ZNPPvnZz372tddeqx2CYagZXvnWW29p0q233lpbJO67jEAYNHYZ8N593aOPPnrEEUfY/+ndLmTS
8qBm3R+IoGbdxzzbNwY1a2Jo7NLXSWu3FbedXZztv9uL2/+j+I+R1rlRsdHvi99fXly+e7F7WfZ/
iv85uTj5+OL4MmXgjdel995Y3Phq8WptBs1QfN9i3/uK+1L6s8WzKfOdxZ1lzm8V30qJjxWPnVec
l+7Tv/+3+L9lNjepkbUpI7r3ol2LXU8rThtRqTJzg8XBeE5xjvbfUNyQyt5d3O3PW4tbU+/8+1Dx
0J+LOCPpH9AiIPiLyDYl1G28YXNIt7XffvuhXQJ0nHPOOQsvvLBvDgKFYXmRoBz+xNcwMjqvI488
Mr0d+cKnmDv+6Ec/8nN76qmnpGuk393aa6/tT1yMSksidsYkko0x3ZYaEjWjfUPcPMXy7rjjDro2
JFEp1MyL0ivSv8NTM+SOJxqeWFsk7ruMAC5/6aWXfv/73+/ye+N1PYcAanb44YcHNWt94IKatY7h
SGsIajZSxCqcP6hZE4PL7YVEV1uQqD9DMcPnis9hQzMWM365GJknmlKI2DHFMfMX85fV/rX46+bF
5v+n+D9lysAbebx3z2JPfORjxccOLg5OeZCvBYsFcb0XihfGFePWLdZN6WOKMYsWi9bVM3sxuxdJ
PKo4SiXPF8/775LikkOKQ2pzpkbWpqR7fX+8eHxgem0KlqcjeJPG1KY3eD+i4l8svjhNMQ0emipH
Uecq5vqv4r+wVL3D1KYUUxYrFluhWOH/KyLMZkHHRJjhsdXgWIwo289//vOxY8duttlmOJfd7KOP
PvrCCy+kLKPJOvTQQ1WFmj3yyCOoGTNFpoYOc0/1U6Ixa0zUDJ966aWXpONZd999N0vFhx9+GEHD
2iQmakZHxs2kpGYHHXTQ5MmTUxHOZWpAzUaqNeP4JqjIEksskbzVUsPi30AgEMgWgffff5+bqq9H
ti3slYYFNev+SAU16z7m2b4xqFm7hma2YrZLi0vVtmKx4pLFkqla1Km2fn+WdCA9wshkSPdUYIma
lXlQreGpmbKIFRrlZptiG21w88fij+ih2tyna+Zi5i8UX3C/cbHxasVq/0z+x/+RuMOLw/2B1MxS
zJJSNeyN4v+JVl32JamcUstl3rDY8Pzi/H/UVejPhz1KV9nfk4qT1i7W/mfyP/pb/llbRGLdn1KG
L16+paxw7mJuRCz9iZ/6z/1FxUWfKD5R5pmnmOezxWfLP/v2RmCNCRMmXHvttZ1AgN8WX7ATTjhB
5dRzQnNQf+BrrBwnTZoksaRmQnZI5JWWcjI7FLLD7jeDxhVXXDEFRBUe/+yzzxY4kZ0haibEh8zJ
+pHZoWghBx54YNKaoWannnpqepqoGQc01Iz6rC5CY53WjGmltyjoovLbcccdhdJnS5lS4t9AIBAI
BPoBgaBm3R/loGbdxzzbNwY1a9fQlNSMjmbnYmfVblFsgfIsUCxATePP/Yv9KZ4+WXwSdUKUJheT
qZCQmjuKO6Yrpnu/eN8NnoXZUYQdXRytCL0Vavab4jdUXUsUS+BELxcvu5e5bHaiZlK8F/OSTmdH
bVRmcLNysXJii41Qs78Vf6Np2qHYobaGspEoj56OL8aje5OKSc8Uz8xazLp6sTorQbotHGrHYkcK
KfdzFnPiPjMVM11XXLd0sfR8xXy6fGFx4YRigo5vVWyl/leKV8CyT7HPp4pP+bO2hvLtTxdPl8Ul
1qJa+xaavrIIs0nNS39uUGyQbuqoGYTLPGXBPrzp6Llm/MtuvPFGgT4YIlJ4YV677rqrPW3qMzaH
0KaZcqaYiB/4GoNDDmgUZzjXHnvsIY69SGtUY5/61KdEBWGXeMUVV6y00krqYYF50kknoVHuWRt6
ipHZMKd345XmZp999kl8kA2kDJxDUTOqN3SP2s59OdDCg6B1U6ZM0dSrr75anJBjjz1WG/zLolLD
hNwvM8fNaCEgJAtZcbTeHu8NBPoNgaBm3R/xoGbdxzzbNwY1a2JoXnzxxYEmEwgL/RHiwLzwt8Vv
GQduWmyqciob5MUNlc29xb13FXfRCi1VLHVccRw+hdF4hIslaoZe+ZPRHbWXm0TN3LAYxCOQJi5U
KIaU8kLN1ijWQO4QnJSIH/mzzOBGwyiJ3EyVmk1fTK+eicVE9Kq2BvepkU8WTzILxC6pCJNtJN6U
tGasIpE19BMde7R4VB8/X3w+VXJgcSA25x6zY2NJPYe4+VPDvlF8ww0myNyxroZU1r9l8YGo1r6l
zA8oAGLE/O92K3ZL6XXU7KriqjoCWxbvqxvUbIcddhA3vkO9RnnwMtaJLvE6GBZKcYJwcuAiclOQ
SRepnnLqwQcflG3ixImi2WvSD37wA9aPzB1xJbSLdq8Mv4NeKUWlRbGFsikrRL8jLdhAivghWwqg
TSv3wgsvoGM4GnXYBRdcYPlLwfZTf1M9/NSQRGq1/fff36mF+CNyR8GXov13CJmotkEEKElR74iT
2SBc/ZzNZ4T+/b333utnENrS96BmbYFxRJUENRsRXNXOHNSsifEVxPu2226rK1hqzVI6xdCWxZbu
sRgUgB5KAArEB+WRgrnIj578sPihPHhEomalr5mcPy9+XlIzeRYvFj+lOGWTYhO8I70i/Zu0ZqKF
4G5qlijuhzcms8OUhyYuOXlNlZqVBo2lr1b5rtTIF4sXtVwijkkR5qakZmV3UhF+beJvpPuSW9H6
0Zrxqku2hUhrrbarroZU1r9l8YGo1r6lzO+G8m6hYiH//qz4WUqvo2Z7F3uH1gwyqJloh1/60pdq
0evEPe7TYLWlfgRxsw3CU+yVV15R1p91Ncg5MLEuT/zZ6wiI0IiAI9293pFof6cRcNj0UUcdleyf
O/2uatcf1Kz74xvUrPuYZ/vGoGZNDA37qLoIjSrBMmr1WdgHHy7pzBFpkdxQ0/xb8W+0V2cWZ7rn
UMb9isLLozpqJlsqUkvNhChEJQQ5lL/2wnFYCUpZrliO4WJ6xGxS2XSPo9FzMQv0Jy3VqsWqKd2/
9Gv+ZXJJ2+XmmuKaWrainWVON6mRdF511GyZYpnkyMb2cr1iPcwR8ZQNaUrpyh5QHPCZ4jNukC96
N2aQqRJUS+BH6bSHbxVv1dUgPV1l8YGo1r7ln9k//P8vi19OW0y7TrFOmUi1V/qaeao7qftlhv68
oVcSgkNExAy7j3aJyydCI/VZhs2LJnUHgTjXrDs4V+AtETy/XYMY1KxdSDZeT1CzxrGqfM6gZk0M
MSeX0rAqFedOhQhgRlRdKYV5HhaGj6Ae1xcfWovhbsjOmsWamJcIgegGnsW07+HiYUouCiZ0hgqM
expXNcHeRbdYqVgJyfpJ8ZNU58LFwuV97Xtl815WlAide3ooNIeln7efUZwhBeeSnyKMwSSaxtKS
B5aacTqxHFkqLlss+0TxBJtDvWAB+Lnic1hSIk3pRWUjNZtGj4ElhZTX0fqxRdRTqjqMTB/VTzfH
klBfMC+hEfVXY+Yo5lAKMfReEUuYXN5Y3PhA8QAyqJTavKi2hvRe/9YWr0O19i2lqqUs6O0ONUjp
dGdj/z52+r9Pr7V6R9OXYqekzCJUpKssGzc5IGBQWCGKjV+G5sihVdGGLiOAmjnPLiKidxn2Xnxd
HDndrlELatYuJBuvJ6hZ41hVPmdQsyaGWKTugVqzQet5rXittD9MQTzSn2gXkoVo1JXyVJG6xPSn
RxzZBn00VCKFnUAZQz1tY3qt8STTzdqaSdfci4Tmc5PSUUg3yfYypdQVqfuztrZ0X4tqShFBnREL
LyGh4Mv8r73/Go8h4SME5eOmtNFH18Ybb+yYLaEnUjY+SmeddVZ6tOGGG2677bYXXXQRh4WykrgJ
BAKB0UWAQSNqlpwHR7cl8fbMEaA1O+yww4LFtz5MQc1ax3CkNQQ1GyliFc4f1KyJwRU2octyAs0X
xdNA/68mGt/lIjyMBGYX8Lyj77WOiLI+zzzzlOdzsYXDv2afffbnn3/e2cQenXnmmQj1NddcI7L6
/PPPL3aEJgkZseWWW/JmEkHi5ptvdiayw4uF5hM4vaMNzqdy5FQQwrqQ8vk0b9CWlDR/0KeRWDEE
BOSkObW9U7F+RXfajoBPma02Rxy2veZ+qzCoWfdHPKhZ9zHP9o1BzZoYGiHmeOg0UbDpIkwiU8CQ
pmtoe8HEhvjmk+rFqxT83CvIzMLf3XXXXWgRIzR/OjfKaVPchZzTXUZskK6Is0HFoBAp/YEHHiB9
pRbKg0yxF03uRektr7/+uqdUY6Lt/exnH4b1kE2ACGHSUyn/IlliBYjjl+R2Efkcaux4YiPl1Z/+
9Ke9LmXGFvGyRRZZRCwvpdBGnuPpkbLvvPPOMsssc/rpp5c1V/smhQHpRIRGY2cyXHXVVU43awVD
mtArr7zSrDBwdsUNq6+WWI4lDW+wciTUZYhNIRxcxxssGNkCgUCgJxCwRjjo0L890dqcGxnUrPuj
E9Ss+5hn+8agZtkOTc4NIyRTP+E7W221FTtA5/86RsqCSGB2QDCyw26QlSDJXBgH50YttNBCJ598
skUzdQpdEuLSGVU0VjIrglUJfi6D86rkFzMQm3OPOqlZHiuFGNqOuBLenHT97rvvKlWyLdWqE6Fb
aqmlUkQL/6bzqpA4B2YtscQSP/zhh8Ew00Us13hhCRM1YwPzzycF6f20006jO+sy+y4b0OUbUHQo
eL75gBSz/k3xFZvuFxZv8iBlKJ55tcsuu4hbQstpBjZepyD5jiq75JJLTCSU/JBDDrFp0HjxyBkI
BAKBQP8gENSs+2Md1Kz7mGf7xqBm2Q5Ntg3DjAjbSy+99Ne//nX3b7zxhnuKJzqsNddc0xHDWk6x
uPvuu6NRSByVBwZXqsw8xXrYFrI25CCWqNNiiy2GxFGfjR07llLDuuAVY8aMIZC7JPL/euihh+aa
ay40EINzMBbq5y21KDmFCjWjTFGniU0vRgU2KDVDA9dZZx2HJQ2kZok2ag8XudrKq3qPmuHF7dKa
ffDBB+iYA8Kgh5oxJR0/fjwmBT1/0n4aTadIl5NBoqcS0aWEsBllrNWgbIr+IY9G0qvSk+LjN9xw
g+FTf3IJlN8j+b23jBaiCNrOrsm/MphO3rLNNttY+xA9Q4y5J+rtX0dRa0BS+2oDfSvWZo4p6421
dZrqciYdblXnQ4b98jOHfHiAZjg00aSqIhDUrPsjG9Ss+5hn+8agZk0MjRNsmVc1UbAaRci9TBbx
JgomPSLE4mVHHHEETOadd97zzz+fc5kjgwXlIEgTdJm0oWZKld0nD6NmjodTluSMi9GtEHoPP/xw
6irKLMWvvvpqPIvjAH2HRAfWMEJjG7n55psza3QGcWmFWFbrXT5uIga4oQjbfvvtPRqGmqlkKGpG
y1bK5GX9lbyhihIjxZC12LtEfzbbbDPKSuNFvYVco9uJmmFPbEQ9wog9ZZQIeTzOsdES+fqZDH5W
iLyYD8xQcXwc3LTBg9AomjKMjNprjjnm8PTb3/62aC2YtcFN+VdZZZVx48ZRwlLUehd9qz9V61+l
SPVTpkxZYIEFlltuOfVoGFUvxSvGd/DBB8vj7cKu0uSapdqs8TYWFKfYpbHF5pDByy+/PNXpCOwv
fOELmtoiYlG8QQS4kTJUvu+++xrMH9n6FgEU3tokpGffItCujgc1axeSjdcT1KxxrCqfM6hZE0NM
DrzllluaKFiNIogV1RiDw9Sdkpo9/vjjs802G1Ox448/njxMFIeSp0lrlpQUqUiiZgRg++GJmqnt
kUceETuRnxcLRsVVcu6557JFxLME7iBsT5w4UZ599933ggsuIKtTotXhSa5OejfcjaR9++23yzCQ
mnkjHc3CCy/MUW4gNfM64rq2lZqdurdU7E+05bjjjqOFbLFf6jnggAOEuOQaRuvk5uijj6Z1wsVo
rDgkbrHFFvi1MTJPll9+eQ77LFTxMs6GaA4NFytW4zJ58uTEqVWI75s8ahOYhQUjCo+yicBDZWaS
mGkUtYT2XXfdVQpShhjid6rdZJNNbBSYZvi+PQR+ixjonnvuyTDSu7RKAyjF0H88C0cz6OqnnCXU
adiCCy6o8e+9956J5McuPoxX42UUstr/zDPP4IBKtYhYFG8QgRQ8v8uRlxpsW2TLCgGfkUmTJsXp
5K0PSlCz1jEcaQ1BzUaKWIXzBzVrYnAHnmvWRCW9WwRnMW34aqXwDrRLACHKknXxHYKrrpFg5aH8
IgmLuUH9UdvfRM2SRWJJzUjR9GLUZyknldzFF19MipYZxaOAoy+jQLnuuuvoOFxE99o60z1eoAbi
OkGaTkRiomZa+9pr/ziVAB+kcSOHk71Rs0QiUnHrUZLMcc+BlVc1BcKt81C2o3RMKTSH2vApyg6T
IWnNAEv3ZAi+9rWvHXnkkYYD6WaASjW23nrroUXuNcNw4GI8CnEoA2FqmR44l6nCkVDYTPlFmEHE
ZKB6o1OjCEtHIXipnMidegw91RhuLg9r2yeeeMLEYF5ru0A2k8p0EvQPp6PkTcMqAOC6667Lfw2P
s1GQNt7NEMpfeUw82jo0E01j+pj0xVWdD7n1y1jYiomI6LmNS4btiXPN2jUoQc3ahWTj9QQ1axyr
yucMatbEEPc5NYMYbQVGQ7VESUFqomU45phjqB7oTQjPX/3qV7EqIjGrRRyNNM6WjJxMZk5ou8F9
CO1Ja0aiJmA//PDDKbiHbc+7776bBo3lGzGYcE6kn3nmmfkKWS9E85hhhhmQL+kDxy4F8ZhppplU
kp4SxUnms8wyC7M9nz5KNzL24osvzihOBlyANoflpEesJSluPNILDRtYeaQMhYBxYVhIFcXnq8xj
6PmLJa0ZrZMhQ6hhS0mHFxsUpWjTTjzxROkcAykrzSuzyIQxEAaFjoxuFMurpWYGrqRmVGOUYpzF
ypeqEzvDp8xDY2rHAFVP1MyMEuClpGa4IeUXVpjKomabbropO0kTLLVZuvbssccedgxUayrS6Jm0
mCMFXCL+5XvjpnMIxLlmncO2YjUHNWvXgPri2Va1OWYD1lfaV9FXlBmD5b7c5GzXu6KehEBQs5gJ
JQJBzUooGr/pc4PGBBSplSOYjwlFA6GavC2dzEz63XrrrTl8sS1MOX3bfdI5dpW6BuIxjx4+aD7+
8tB/oXg++JYDYja5l8zM78yKkGpQUIbkbML17OyzzzZv06O6f9XAfA5PJM6lRxicelhIUpo4gdq/
7CTLSA4agCRqv0cuCh2b8zhFXbXx51QRQKtZJ6ZwIggvysNckGaKxxb1GV0nikQJZTj4g8iJGVFF
JVWI8WXriIsxbiRcqUo2T/Frpolo3VDUjO0iUo/KaR53MF6KdgM4hTFTND/TZKDLEyGE1gwrd7Zd
Sc3QOg5l2JayXpcUcKzmGDHWUjN5OMRR+SUDWrsKalthhRWSuexUYYkMrSPgF814daiffOv1Rw2V
QSAMGts1lEHN2oVk4/UENWscq8rnDGrWxBALwU1+a6JgNYqQY2kQ2IaRfvVIMAeqhFL7IMVXvcWe
lvq1FuuJ4lNFwL6oEBmY0VRzDp9B8A1GhvRcDFPRlmWXXRZRYjpIxcwgjTkiI0ZnK9CN7rXXXp/8
5CfF3EDDqVZZvZK9aVrXWGMNbmj0XCxXWRXSuCHLtGwmG37HkpBii6khym8HANem5XSDTTOJ1P6b
brrJS7mZpBvKNZc93vnmm8/bMXoEnGEtnZofL5dG9rfSKd3wQYaXntKa2SXAGbWEPaT+4pJqsAVh
3wDF88N3w2hTN1HI4QGJp+1CAJs2S9M2TrvqjHoqiYBfN4sLe0GV7F03OxXUrJtop3cFNes+5tm+
MahZtkOTc8PoIByGxeCQ5IyX0XMhaDk3ONo2FAJ0mmxT8aOhMjSezsZPtBZEiY2okI9kaaooHIof
mUfUoAwXqVORLN5b9CBejZGhXZy8aMcovMgDrFtxN4nsTs0u1ox2AJA+jM+sUxu6RyunEupauwT0
WTwHvZSmVaIapKicQaO4MeqkYxVGxvz0rfMWhJEWVQZETyJHSBNYmBE0kA4OC0DZvAUf1HF8k4kj
rZxoNo6K8BZNZcdLOShn48hEzkAgEAgEegiBoGbdH6ygZt3HPNs3BjXLdmgybxix1qlkBF2ajvDM
ynywhmke0tTGc828iHWia+Ab0Shzxr/pUWk1KjOOhvuURUgFlFyIWJky/I06VVKraZVCz1KWqn1U
JpY3vNto38o/h7lBNsEVs30YiOJRIBAIVACBkpr54gnxxMIhfM06PazsQGwnctzgCGBX0+ahddDK
WK6VnW7AUPVbT62hdkSZkfAvoJVmW2I7l2sPv4BRb95Qze7p9ETN7C1zoGDDY6+YSY8hCLSHGVaC
3KDC5zBF4lEgkCcCbadmeXYzWtW7CIjMyfQ0mZj2bi+i5V1AwOYJn9OwfW0d6iSNA7OkZkI88RnH
HSIMSOvwDloDaiZosB3vbKkZC5aSmjGMCWo26Di2JTFRMwtfULPG8XTuUpyc0jhckTNnBGishL5s
i0Fjg9206Nv8GV6T1WBVka0fEBDSJz65/TDQrffRiRuOgxcMpPWq+rwGX+nEcylKaM38BomIqJlA
u0HNOjQ3GN6jZpypBUmjNbMllZvWjCkLavajH/2IJzhq5ogioTvDtr8T84H7PPd2Lvkc4W1L8gox
GUJrNjzUYs3RMw6fJ54GAj2BAPM8+wzsVbrT2tJpi0tXd94Yb+l1BOJcs14fwa61n0fqYYcdFkfg
tQ54LTXj/+s3SBoX+pi/rX089IFyx7+ZXwJPuTJvJCQTmLyYKSWFAuZPLY6xGMUMtLIyaGRTx7IO
U6DX43At7pZjkvzcUvszx7mHJoOmiiYtWBlnfNtN4qRxukfNSGth0DjMxy3ONRsGnHgUCAyFgA+L
77mojDbc4gszFEqRXodAULM6QOLPoRCIc82GQmak6cmg0S59smEjjRMRyeGC04q1u9hiizmJ0nmm
Tix1iYKb2zX//POLAzzrrLPONddc7nNrnvZolQuGCy+8sLMyHagKWAGKH3nkEaooMalQM3GoMqFm
1mvLN2qGI2AKXMxEKsbTtVnLTYaFFloo28mQ0DYZZp999gxnQu1kAOOiiy7q9wVVVB3tTSpUjod4
elCz4b9jYmszAR0+TzwNBAKBWgTEAHF2s2D1zg6rTY/7QGB4BKh0w6BxeIjiaUKA1ozRXWjNWp8P
qFkpjTOmYsRIUfKd73zHKTmXXXaZLf3jjz/+0EMP5R6199577/HR5QjIrC7hrbAe0Xd32203Dcyq
bdojELGjNh3ago45XlPUYjuWLFj49NmMYkQq1LBgVqiZkCytD2grNaTJkOJl4QjpABpmw3Q6V155
pcNlTjzxRBGYRZgU6Dg3qNO4Q9ue8IorrmgyZDUTUmMEOQcdi1afL2GuhZV2pBHyy6zRQUIAZ92K
mhmCMB8dZiY70JYJ6DAZ4lEg0CsI+OzzJsCbOtpgrxCv3knTHBY6+qKovHoIkAwdWV4eIl+9DkaP
2oUArZmDDsW4a1eFfVtPSc0IhNQ3lDhERIKijTXs7Oqrr77wwgsRNMeaHHfccY4vcUE+qwttXGKJ
JRwNgzVk2DzWoSeccAJSZscS273hhhuI4shvMmDj0kVfaV0WcS4TaoYk0uJxTnf6DPKIQvqhUVJg
lI6Y4eN5yimnIOyYZoZoaxVe5vge+wl5Ng90p556Kp576aWXgtThsMwayUs8+959912wJxXqqE+G
nD+JhARhixppIRhB6ivXSObIEwg0jYCZZg1tgmH5/tvs8h1o+tXDFzT5mUAwoV9nnXXCv2x4rOJp
IBAItIKAbyC5sfFzN1p5V7XL+m7bny+lccIhm0buZriDEx6dIMnjjAx5wQUX2OHH0Vxn5HRpD87I
W0fcktNOOy235oGKEH7eeechNfQjDiGigaLtdRQRa0ZaEsqpFCxdMJYcBEiTAUmkxSP6cjezlLNp
FEXQCe8CL5gMl19+ebaTAdqY4+qrr77hhhuiPxlOBk3C0E0GB61y+kB46U/pJVkzUljbnEw83WQI
atbKhzeJo6arY3OdsRuR9lsBM8o2goAoxxwBbAr5dfuwN/779aWdMGGCXZpG3jLSPJrhG+6g5+22
2455xkiLR/5AIBAIBAKB7iNQUjPbfagu4dCywrTYgVbf/va3yY2oBIJGjKRBu+qqq/CLrC5NIuuK
U0F3hjVk2EK4WXYpy1Cbu+66SyQNOl98x4pZakkYsAllnA8143uIMKKNtKgUZ3Q62JnJcMcdd9xy
yy1sGwi9WU2DsjEaxtpt8803t59QJuZzY35qoclAJf21r32NbhovsxPiCDl7TcmaMR0LksNk6P7n
qPU32lUQpoY5K7tWPpIMcd9+++3Wq40aAoHhEbCA2oWbZppppp122rnnnnuHHXagCGNGOHwpT1Gz
9h45Xb6Rq4K4r7aqDjjgALr4Mj1uAoERIYDg272PuDEjAi0yBwKtIJComV16kQd8vZOuRER37IzF
HRKBoLFn+8Y3vkGJxhKPPJnbhSwwCLnkkkuwyAxbqElUToRwEqPQHzjvCy+8QDXJy4wFKQZkTffd
o67KQRr3EUYSUUWTgQYnUXXszGSg6Xv44YdNBhwt28kAbXaMVGbkomwnAwDBiO2CFEkHL/rA6Mje
SPI6tAjmMBla+bB0tOwTTzxhZta+AlxgpDcXV3+55Zbj2mk/IU5uqoUo7juKgM84wxLUrLymn356
+wOs2X3zh9HbWnPxOJuf7W2eNd0XhnU3C+ph3t7el0ZtlURAHGmeAqTBSvYuOtVGBGxGcc0g2bax
zr6tijROFMQObNcL3M3sgSUb3RmEGd2Rya0sZCGhV1w2+TO8Mm8b3z0AUo6wW+Mmw3QNL6OTwn2I
4nhQPgZsRFyTwVJuMmBn/HTIwHRnuCS2jkekyaBHGU6D1KSemAyIg8kAUsDSl/nF+aax07ZDAvxM
eHq2n0TB80vfHJKtPRnC7QorrMCqmeOeT1m2LY+GVRUBH0yW3iUvq72ZeeaZGToy6hj0qFA/fI5g
N954YxuRsabQy7Pz593cxmqjqv5EgNCy00472VHsz+5HrxtHAH+PCI2NwzV8TtI4UdAOM5HG1h92
RtohkKMPCBq7OxzNjjQxElMTJCTDy6cjw1ZpEsTg5gIgJKkj0Rznx+G/VCS4jzU0N1E8Kc4SO0MW
TAYsUptNBqJF/pMB2tlO1DQfTFeMDJhpMiSSDmp2pGAPldnw3ytPHe3BNBQTpy53oAMxmLLs3HPP
ZTBMfvAvzT7j23TV3v8zLf4fCLQZAWb/vBprGVndPUNHx2cIQs7D1FaMZTddVl6bMwjaPxP+n/+b
7f6e6i+iNgOSyN8NLyu3L2qfxn0gMFIESC+77LJLREQfKW59mN/GeFCzdo27Lz9pvGRnPuykRMSB
xoTQKISgC02zfDC7yvBCGZIqKsO2pSZBD7VxMVpDyqzC+G/SlyVRHP4jXX/bNfoD60mToVZ3ZjIg
aJTUJAqTgYtctlCbpfy28EesJ89GamGaDHY/OJeZDIxakfSkLwN7qMwGzsm6FDoIIV940DjNMAnA
CBrPsrXXXtuRZ2ha7TUwpfZp3AcCbUFglVVWcYZLHR0b+OdMM80kSBHLcJYSLt9/V1p803361yOU
LX0NPG18gbB2s2AcO3YsGanuVxN/BgLNIYCa2XaI4/CaQ6+vSiWtGX+Nvup15zpby84sDXbvqc+I
i4RGYjm7O5I5pubCLLK6NIz2wWlWvOEIuhm2EFxaRQKHJDwtnYCFMB1lWpQbX3Y7NwHqaq5lZ/R6
aTIkwp7zZAA1kJ1WwLIIi8x2Mpi0YDQZMHSo2gzBywhjwcvq5uFQf6666qrpyGm7BGLsIGXjxo0T
CIiZKBiHKhXpgUDnEPArdmblQC6WUmaccUaqXhlsHPm6akZac9OXFvlKlz9dHrlqm2pWy5Ae1abX
3fsAOn6UuS/LgbpH8Wcg0DQCoTVrGrp+K8iU5bDDDgsW38Zxtxb48vv+kw8tBFgD7kBiTDSNcO6i
6MntsiBSjmy66aZiPpB1M2zkR8h9+I+mJkaWSJlN0UZW2zYOceNVpclgPpgM2pk2ck0GXXClHuU2
E1J7YOuAb8fw4cLamWEjE3pgNBnQXpefW5oMaT40Pkx9m9Nx53zKyu6brhw52VGIukAudZY3tamp
W2aIm0Cg0wj4XdeFAUHKpptuOqo0XyS2hbaMWIUJYr/lllsKIevabMCV0v27xRZbyLbVVls5qt6u
oy+Dj7ApPShx0zXp1PFbb721pZBhQ6c7G/X3FQLmNnZmR7Gveh2dbQIBHvSOQhbfrImyUWQoBEg4
rkTQrAWuJJkTHdOVRPSs/tVChmGWMDw9qR6yap7G/BO8fxioaHDCdqhFdqjR6XJ6ORnSfNDsdJXd
yQ3n1B7Npj1xfBhtVJ4tLAFMePbEZOjy3Jvq60BnWg7MZnPGFs2uu+66+OKLk1GvueYaeoSB2SIl
EGg7AnXUbI455sCtBPdgze5DxIZZ4FAmuBRnjV+sdh1JRhHmK2F1U489nLRw1LbfU06s48ePx+Ns
SdU+ivtAIBAIBLqGQBIXB12du9aGCr8oieUD/wV4bpdRYMdot9B5YYTe3JqnPQNhTCm9Mn+Gan+G
UGsSVIWGcMAQfVmeLRwUz16ZDD3RTgjTpDvukLC65JJLUqGicj3R8mhk7yKAmmFSM8www0orrXTK
KaeIAYVJmYrU4raJqHGdL/biiy+OqIM+Yuedd564o3hZihlljUPE0jckVYWsiZer8kMPPZQufkT1
R+ZAIBAIBAKBQKATCHApmjBhwkMPPWTZ6kT9UWdvIXDIIYcI1keq6a1mR2vbjgCp2FkPoogHNWs7
tlFhHQKImBNS7BCWXx7rEa6El7EEw9Q4SPKFrCs1/J+qYgAgtL5KeNEmdpaMn7EzZdlvO2Jy2WWX
tRmFsg1fWzwNBJpDwLaDSGsEreaKR6lAIBDoQwSsgAyhxVVIq1UfIhBdrkVAWBjmQyGo1GJSsfvJ
kyfjXBXrVHSnMgjQ1yNQeBMyxcKQyf0zzzwjhKN/R9THRM123HFH0XEZh7DXxfVwwLTVwFmVyS7/
yptuumlE1UbmQGBECEQYkBHB1c+ZHRFlL3Sk5gH9jFj0PRAIBAKBaiBAyr3llluq0ZfoRfUQQM0Q
KNSJqssBNMxrBS5beeWVm6NmIodwWBPcg/YtKc7Un1jbmDFjIk519eZPbj1CzSJ4fm6Dkmd7fOgm
TZoUp5PnOTrRqkAgEAgEOoeAMIwpeH7nXhE1BwJNI5CoGTMwKjMa/B//+Mfs7VdcccXmqJkgVywB
HN+ZFGdIn2qZbTehhmu6R1GwnxEIrVk/j/6I+h7nmo0IrmpnZtD43HPPCcUWBo3VHugGe+dMH2JM
uBc1CFcvZgtq1ouj1j9tZk3NmpFiiyGimPb8dGwjr7DCCs1RM7H01YDfOauR09kbb7zBxHHdddd9
/fXX+wfS6OkoImD67bTTTqEKGcUh6JVXBzXrlZHqQjuRsm222eaBBx6IMCBdQDv/V4jQ6IAhclH+
TY0WNodAGDQ2h1uU6g4CydHMgfL0XAgUzwtnOowdO7Y5aiZ+vtOCxHhk0/jkk0+KO8rEUc3d6Uu8
JRCwG+BUPlJ3QBEIDI9AGDQOj09fPU3UzBG0Qc36atyH6uxBBx0U1GwocKqRft1119nIrUZfohfV
QwA1Ex0UNRMAhC0iow5HTi+//PLNUbMNN9zQieomvGCM48aNc4C1mFfVAy16lC0CyUA3DFGyHaB8
GsYrlijuo5dPk6Ilo4VAULPRQj7P9wY1y3NcolWBQJ8ggJo5iUxARXquV155BSO79dZbHTndBDVz
VhpqJh7pZZddttRSSx199NFsGtUfEWj7ZC5FNwOBQCAQ6EUE2PNvscUW6cjpXmx/tLm9CBxwwAEO
AxLKrL3VRm2BQCAQCDSCQKJmwjOKAcIQEbG6+eabUTPKr0aKl3lSGMZ11lnnpJNOWnTRRU877TRB
GiVyZAtqVqIUN4FAIBAIBAK5IWBz8sgjj7T8hcI9t6EZlfacc845N954o8jVo/L2eGkXEKAoj/Ht
As7xiuYQSNSM2SFq9vLLLzuK2hdJoPuRUjMxHmnNZptttiWWWOLcc89lLGQfktYsqFlz4xKlmkOA
Xe61114rvlZzxaNU/yDg00QgZzPQP12Ong6FgMCMDPuDlw2FT7+l+ziIL91vve6r/m655ZZ33313
X3U5OttDCKBmtg6EuH/33XcFHm+Fmp1++unzzjvvhRdeSDAWjcEpaVzYfOKsdxGRuIemRE831dzb
fvvtI0JjTw9idxr/9NNPT548+eGHH+7O6+ItgUAgEAgEApkgsNpqq3HeyaQx0YxAoA6BdlGzZNC4
3nrrPf74488//3xQszqc48/uIBDnmnUH5wq85dFHHz3ssMO+9a1vVaAv0YVAIBAIBAKBxhGIc80a
xypydh+BtlMzAk9Qs+6PY7wxIRDULGZCgwjEuWYNAtUP2QR8uPjii+ncwzO6H4Z7qn3k1vHNb36T
jetUc0aGHkVgjTXWCK1Zj45dPzQ7qFk/jHL/9NHBDWHQ2D/D3UpPbSIdccQRoTVrBcPKlOUZvdlm
m913331xrlllxrSVjuy333585yNCYysYZl5WzLqvfvWrmTcymte3CAQ169uhr2THnW9+2223OQai
kr2LTrURAabXTid/4IEH2lhnVNWjCMS5Zj06cB1qdpxr1iFg86n27bffFgwhn/ZESwKBWgSCmtWi
EfeBQCDQJwj88Y9/FKooNsb7ZLiH72ZQs+Hx6benQc36bcSjv4FAVggENctqOKIxgUAgEAgEAl1G
IAwauwx45q8Lg8bMByiaFwhUG4GgZtUe337rnZMaBAuNI2n6bdyjv4FAKwg4QYbjyVtvvRVhQFqB
sTJl77//fuePxzpSmQEd2JF77rnnzTffHJgeKYFADggENcthFKIN7ULgxz/+8cEHHxyHVbULzwrX
w5rR0WbOc6xwH6NrgUAgEAgEAgMRiHPNBmISKfkgENQsn7GIlrSOgAiNO++8s7jHrVcVNVQbgTjX
rNrjG70LBAKBQGAoBOJcs6GQifQcEAhqlsMoRBvahUCca9YuJCtfT5xrVvkhbryD7Bjff//9v/71
r40XiZwVRuC3v/0tw/i///3vFe5jn3ctqFmfT4DMux/ULPMBiuaNCAHULLRmI0KsbzMHNevboR/Y
8ffee2+fffahSLUgDnwaKf2GwIknnnjllVd+8MEH/dbx/unvuHHjvvzlL/dPf6OnvYVAULPeGq9o
7fAIvPzyy5/73OccHTt8tngaCHz3u9899NBDw/Y1ZgIERGjcaqutHHIXR07HfIDAgQceeOaZZ1Kc
BRpVRYBP+r/8y79UtXfRr15HIKhZr49gtL8WgT//+c/CrDFHqU2M+0BgIAI//OEPp0yZIhLIwEeR
0m8IxLlm/Tbiw/c3zjUbHp94GggEAh1FIKhZR+GNygOBQCAQCAQyRwA123rrrR988MHQmmU+Ut1p
3uc///mzzjortGbdQTveEggEAnUIBDWrAyT+DAQCgUAgEOgrBH7zm9/suOOO3/nOd4Ka9dW4D9XZ
ww477MILLwxqNhQ+kR4IBAIdRSCoWUfhjcq7jMDvf//75557zpFVXX5vvC4QCAR6FwFH1b/xxht/
+MMfIihf7w5iG1v+zjvv/PKXv4zzx9sIaW5VHXXUUSJB5daqaE8gkBAIahYzoUoIxLlmVRrNjvZF
MM9rr70Wke/oW6LyQCAQCAQCgdwQiAiNuY1ItKcWgaBmtWjEfa8jkILnf+tb3+r1jkT7O42ACI2T
Jk2KCI2dxjnqDwQCgUAgNwTiXLPcRiTaU4tAULNaNOK+1xGII6d7fQS71v4416xrUOf/IodNO9SM
IfTf/va3/FsbLew0As8++6xzWEhHnX5R1D9aCAQ1Gy3k472NIBDUrBGUIk+vIMCgkTv/vffe2ysN
jnaOFgJBzUYL+QzfK0LjFltsEeeaZTg0o9KkONdsVGDv5ksZNN5yyy3dfGO8KxBoHIGgZo1jFTnz
R8ChZqeeeuoTTzyRf1OjhaOLQDJoDBY/uqOQydvjXLNMBiKTZsS5ZpkMROeawZSdtNC5+qPmQKAV
BIKatYJelM0QAWG1wiopw3HJrUms15555pmf/vSnuTUs2tN9BIKadR/znN8Y1Czn0Ym2BQKVRyCo
WeWHODoYCAQCgUAgMAwCv/rVrxg03nfffXGu2TAo9c+j/fff/8wzz3SYQv90OXoaCAQC+SAQ1Cyf
sYiWBAKBQCAQCHQfgd/97ncnn3yy4A8OOOv+2+ONuSFwySWXfOUrX/nzn/+cW8OiPe1CwNF1TkFt
V21RTyDQXgSCmrUXz6htdBFgn3bxxRd///vfH91mxNvzR+BPf/oTXckHH3yQf1OjhV1AwFIY5013
AeeeeIXJEOdN98RINd3IjTba6M4772y6eBQMBDqKQFCzjsIblXcZAREat99++4jt0GXYe/F1Tz75
5IknnvjQQw/1YuOjzYFAIBAIBAJNI7D66qvfeuutTRePgoFARxEIatZReKPyLiMQ55p1GfDefZ1z
rA4//PA4nbx3R7C9LQ+VWXvx7OnaTIaYDz09glNtfJxrNlWIIsMoIhDUbBTBj1e3HYGgZm2HtKoV
xrlmVR3ZJvol4MNZZ531wgsvhK9ZE+hVr8jVV1991113ha9Z9Ua27FFozUoo4iZDBIKaZTgo0aSm
EQiDxqah67eCtGZHHHFEaM36bdwH7S+vw8033zwiNA4KTh8mRoTGyg96+JpVfoh7uoNBzXp6+KLx
dQj8+te/5mj2xhtv1KXHn4FAHQJ8zU444YTwNauDpT//jHPN+nPch+p1nGs2FDKVSf/lL3/5xz/+
sTLdiY5UDIGgZhUb0OhOIBAINILAX/7yl//8z/8Mm6VGsKp8nqBmlR/iEXUwqNmI4IrMgUAg0F4E
gpq1F8+oLRAIBAKBQKC3EEDNwqCxt4aso60Ng8aOwhuVBwKBwPAIBDUbHp942lsI/M///M9vfvMb
R1b1VrOjtYFAIDCKCFCh8jp89913//a3v41iM+LVmSDw3e9+1+GYVpNM2hPNaDsCIue/8sorba82
KgwE2oJAULO2wBiVZIKAj60Nz3AgymQ4cm7Gz372s0ceeeStt97KuZHRtkAgEAgEAoG2I7Dqqqt+
+ctfbnu1UWEg0BYEUDPeFu+///5Pf/rTl19++YknnrjxxhvHjBnzve99b0T1/9d//deZZ5653nrr
iXv23HPPicPAy/L3v//9X//61//93/8dUVXVziw4M5lQQLDGu2mM2NuMqEjjlVcspwiNO++88ze/
+c2K9Su603YEbIwfeuihMVXaDmxUGAgEAoFA5gjEuWaZD1CfN6+OmoladtNNN7VIzZ5//vkqUbP/
/u//fuqpp+6///62TJXf/va3kyZNuuSSSxqv7d/+7d/OOOOMU045ZagiP//5z++44w6GfENl6J/0
ONesf8a6xZ7GuWYtAlil4vYPfWbDELpKY9pKX0T6tVKHdWsrGGZeNqhZ5gPU582rpWY/+tGPnn76
6VtuuWX55Zd/8cUXR4TMBx98cPbZZ6+//vqPP/44I+0333yzMlozp5GiRXQxIwJkqMyCwon+dMEF
FwyVYWD68Fqzv//97zAfP348VjKwbL+lhNas30a86f4GNWsauuoVfO+993bbbbeHH37Yx7Z6vYse
jRSBY445xvYpqWakBSN/ryCwyiqrkHV7pbXRzn5DIFEzfIHm5dVXX2XHyDty8cUXP+ecc+756HJK
VHkx/klXmeImZbvtttsmTpy44YYbUjD94Ac/4MHBAA+poXLK06DRhtjbb7997LHH7r777mw4b7/9
9meffdbo8wengdppp52k6xqDTH1cccUVl1lmmS9+8Yu104Np4gsvvPD5z39+2223vfjii3/3u9/p
6euvv37ZZZdBaa+99sLmlEWdpFMjHn300Vb/yy+/fO+9977ooouYgMopwyGHHCInAL1L/axADcHW
W2+95ZZbXnXVVaqVwnmK2s69mr/0pS+pZMKECQjjO++8w3VdhfPPP//BBx8MdgRNkwzEUUcd1Ydk
zfYC5B988MHakYr7QGAgAgwa6a/9AAc+ipR+Q4DFuE/uAw88EJEf+m3oB+3vgQceeNZZZ1mjB30a
iRVA4LjjjrOnXYGORBcqiUCiZnT3zDlee+01bmLf+MY3nJO+0EILzTvvvHPNNdccc8zxiU98YrbZ
Zpt11llnmWWWaaaZZtppp3XvkujpnHPOOffcc88333zLLrvskUceSe/20ksv/eQnP2Ffly01Q5c4
fOmm5RjT2XXXXVEbPIjb3bXXXms75YYbbpgyZcrqq69+zTXXIDjbb7/9uuuum7hbmgZ4GaxkwI9Q
OewM7WIPw9UObpiRehxou+SSSyrlXbzwdthhB26nu+yyy8ILL3zFFVf8+7//O7q33HLLueemt+aa
ayqChSGAa6211vXXX69h4jn7gADz+OOPh+0vfvELwuSiiy6KUV599dUbb7zxvvvuiwIjemPHjr3u
uuvoKzUDRyNjoGY6iLhVct4O1Sn01kyOJXUofCK9RIBrrZ856+syJW76FoE416xvh37Qjse5ZoPC
EomBQCDQHQRQDNIsdQz7Q5oddozIhZ3km2++mWqGjeLJJ59MyKfZIfDvs88+FGpIyv/P3nuATVWd
bdspphkTE2OixqhJBEtUQpFPERCV3rsU6e2gFwEp0qv0Kr33Kr2JLyC9CH4gXUQEMYaqoFii2f+Z
rO/d/xxPGeaZmb1nl2viQfasWXut+77WfmbWte5m3rZs2RKO0L17d9zzIBQwFKwVWM3Y85BUBBcR
/AG8aTXDNDZr1izYEEKCMxZD2BDUDO5TsGBBLGg0GppGOwSTAzRsMZErAofCCkajMYrBRnPkyEHC
N9SHcJFNhc5AiocnwzJXvnz5GMfMVaBAgWHDhkHN4IBYJ2kkDcugQYMw1cHj+Bc+SCPntywEaDMs
IAM14uFoAZFkyaCBEL2iRYtCgbmrWLFiR44cYfmYEa7Hp0hIOyMzlF5CQAgIASGQGQKymmWGTDjb
ZTUL57pLayHgEQTwtWOfj5WB3ya847AQQS7wncO/DraFOQZWgmEIqw3UAC6WLVs2jDXYg3jbqVMn
KMOAAQPgAvgELly4cMOGDZxCY32DROAkCUGAX3gwlhaWhOS1atVCfRYCgla7du1Ro0ZBKu+8804U
xExWvnz5559/nlhRDE9YtegcuWSECZcsWRJbFUyKnpi3CNDDdRmPUMK+QJLOQIo1beDAgSTxwJhl
bgcWiC1kFmoGNzRp3qGKoMeA0FsMeVgeTWfAhHxBwWxqBuasBZ+aW+iMkYj+GMgIs2JwSF/27Nkx
5/HjAkOEOZqh9K8QEAJCQAhkiIBizTKEJbSNijUL/NJjlfDg1jTwsEvBGBHg4cSwhXmL3yb87mBV
OMVhpsFeg60HHzloFwQN/oUF7dVXX4WAGLrBW/gFRADPOnjZ/PnzIXQkeIQgEPGEwQhLHPQBh0kP
Pv9QUSgndMwwF3gW3ApqRlWsBx54AI1wVoQW8S92KLw9e/ToQedISLFVwcgwYAEXPXlhooIlbdq0
CTuXTc3Kli0LSpjG8GY0t2PGMrFmhpqZxI9w2Llz5xJxRtlTQswYhM58dRCWzmishU3NOnfubFOz
BQsWRFIzaDVME8wBH69UfB0haJDlSLEDf81jDNslijDwmkrBBBHge4m/Fw9+OyWol26PAwGeBL69
+R6O417dEjwEOFZVhsbgLWukRoTks7+KbNG1EPAOAoaa8ZMEkyJqyRjOYBnEyEMTIFykpIB5wdGI
hCJtxeOPPw4fIUaDtwRD4feI+9/ixYtxZcRGQ1oMyB3+geyQoT/Y46BmHjTcwEZJ8YEuZI3gGk0J
4MJKCKnB/AQDZYGuX7+OvvhwYmKDmpHkJHLV0K5bt26Y1fB7REfsVpA7XAoBIQ01wy+U3B3Y18iy
AtuCvWJ5pJG5yC6CIZJdAYY5LnjBDbGvIQCNkDgsbpAvbHm0GIfG9NQMisfsSAJJxOKJdc9k/zAh
cpRCiBQ78NecDFSuXBkyG3hNpWCCCJCtiHMn/nYSHEe3CwEhIASEgL8QyJUrl0pO+2vJQiUtvMmE
m8E14AKcHGJxgLCwz4dEYHPBBgGzgMhgiMGy07BhQ7z7aIGO8e+KFSvWrVtHGurt27fv378fXkaU
GSdOED04C6yHwT1IzVhiQrFwWiALB6SG+Cz+TqFmCAzHhDGR/xBOhGsiZAc7FAZE8pxgaLOfDSgt
QOGCSBAZZCpPnjzwOLw3idSLdGjEBAYLw88QikcMWs2aNYsXL04HEvMaasa8cDoEoB3YmQtUsXYx
MhY3WB4I4x2KBynSwnm5IDEIYtATqxn3Qs0gdGhBf2YnJBBhMJnhlsl03GvLHIYLCCmJVuDaYVBW
OiaCAKdPHIbw55bIILpXCAgBISAEfIeA6pr5bslCJTC8yRjOYFKwFaxdsDNSAmLiwQABQcOCxsEy
WUbxsuNf8+Ia8xDcjY/w5eP8GcsOWURwicT0hicAHpLGZMbgHqRmiIS+UEhkNqn+8dI0RS4wV8G5
4GIQHzqYhwELGs6NxhplPx4MAgNla4dVEfVppwX7I+hB8XgLLTXpULimHQ6LFRIDGc6QvOBZxJph
32GLyCA2h+IuBCDoDPJLZ+7FKockUDlzAcJmLtaL8eGDvJgUCTHwIRLsEp9MXCVDmANE1IxnQ69Y
EFBds1hQCkkfTro4z+H7lh+skKgsNaMgwI8yLkD8sEbpo498jUDevHnZ5vlaBQkfbAQgFMZwZrMz
Nv+QLHb7VOnCSQ9rDjtemBovOIi5oIVr7DX0ocA0P2qQC4K24GXGlZGvNWgOg3sQPfSFyGCTgmlC
RfH6gyWhqZuigjDmrbDFgjmNMA8nKVzk0Og0zgEYX9QsAIuYLBU4+8IDARcF7caTBamvxzHeQSap
sq8VkfCZIZA7d245NGYGjtq9gADsiaNCLDLYuWBnfB1BrzCfQdBwloNwYZqBeRGGZqxpWJq45gW5
wPRDBww6kDJsNJhsjL3MuDJ602RmMEdUEifiT0jFMZwJ3Q8IBTSyO+II6oVnIDAy8FiSdIU8mYHR
SIo4hAAH4y1atJBDo0Pw+mtYqBkO4fgbiJr5a+EcklZ1zRwC1jvDkuyOna135JEkQiA9ArAzLFzY
kqBUEDS872BY+MvBX6BphErB1HhBxEj8TuoP7GK45NHCR3SgJy3cwo2MwK8bQ3nfMwStkRlS6X1R
0y+ZWoSAEEgEAf7wcWbGaJ7IILo3GAiImgVjHZOlhahZspDUOEJACCSCgLGdGYIGt4Kg8cIDHzsa
kVa8oF38fpEcgyTzdDON/EsHusHIDCnjI14iO4mshe4VAkJACAgB1xDARUQOja6h7f2J5NDo/TWS
hEIgDAhAzewXxMowLIxfODraLyxlBPKQyRBA7EYu6Gb6c6MZJAyISUchIASEgBAIAAK48ZOAl8wP
/JYFQB2pkCAC5NFauHAhx84JjqPbPYsAeRJCmCfNs8shwbKEgE3WzAXUjNLJ1DhjkDQfZWlYdRYC
DiFAOCRbLEXwOQRvkIZlN06sAT7bQVJKusSNgDw94oYueDfqhDl4a5pGo4IFC1INKk2j3goBPyJg
rGaGmvlRfskceASUoTHwS5wsBcnOShn3VatWJWtAjSMEhIAQEAK+QIDqsTNnzvSFqBJSCERHgBg0
AudJBhK9mz4VAqlCQHXNUoW87+alPnvr1q1Vndx3C+eQwHjmYytxaHAN6y8EeBiI0fCXzJI2Swio
5HSW4FJnISAEhEDcCIiaxQ1d2G5UXbOwrXgUffFr7dKly86dOxVrFgWl8Hw0dOhQ6hEr1izAKy6r
WYAXN41qOKu///77JJNP0x7at5w7EftD/V8FdIT2GUhEcZKCUhmc+lMkAo1xHBwaK1eurJLTMcIV
5m5YzVq1aiWrWZifAVt3MjSWLFlSJadtQEJ+oQyNgX8A+HtfvHhx4NWUgiDABrJw4cLTp0+PHQ3O
6DjnJxqRzPOx35Wqnlj5SWtDHeroAuAWAhdbunRprVq17rrrrhw5clCWOvot+lQIpEeAenkENvL8
ELE7ePDgI0eO3NTJhJxL69ato/B0+tHUIgQiEdi2bVu3bt3crzUfKYOuPYKA6pp5ZCE8Iobqmnlk
IZwTgz0q9aGcG18jewcBqBl7yMmTJ8cuEhZz+j/77LPUPo79rlT1JA1ItWrVoihIMNqOHTteeeWV
hx566Mc//vEPfvAD/s2dO7fquqZqyfw+L1yMowCqnJcuXfpvf/sbtRtmz55908MBv2st+V1AgC8r
vrF9cSbmAhohn0LULOQPQBr1Rc3SAKK3QiC1CGDG4tQdAlK+fHlO7CmmfPDgwQ4dOvDVjWB8is/D
a6+9hv2IM/xGjRoVKFDgxRdf3LBhA5/yQw/Jmjp1KmR84MCBJoM3PRctWjRjxgw6sBkgJwylLQsV
KtSpUyecKA4cOJA/f/57770XR/fPP/+c6bCgkaCeMefNm5cqv3cTDW3yx0b+a5Lnjx8/Hl1ot7MN
I+exY8dGjx4NGrfddhuMzH6JmoGVXokjwN8Of4kkxn/66aexo/HTiaOjLw40EtddIwgBIeAoAvy+
4+BEuk6+ZxydSIP7AoHGjRv36tWLLZkvpJWQQiDYCEAxCD14+OGHx4wZAzMihUvbtm1JSPjAAw/M
mTMH3dkKQqxopCYOUYTNmjXbsmVLjx497r//fpiaoWac8OOIxb1TpkzhFmhamzZt6taty+CMyVCQ
L34CYGdsLzn/ZxC2mitXruQuWE/OnDkhdxMnTmSEQYMGuQm4YWEQLkwVvCCV/E7x4mDZvKBmFSpU
MCWnaafn+fPnFyxYUKVKFRwXbToWeQE1AyiV9nNzHYM9F8cXWGZJe84fCP7DODoePXqUx9VozZ8b
f7D8eQYbBGknBIRAEhHge4PYQ36O7fPGJA6uoXyHAAlhOAlkC+Q7ySVwjAhQVXz//v0xdla31CJA
2oEiRYr07dsXMdjsYQu77777zpw5Q7Q4uQVgLocPH86ePTvRYbAwKAm7RP54Wd8HH3xw9erVNjVj
Z4gtzASd8Z3PNhL7GgOS02DTpk0Mjpsrszz33HOMgB2tePHidKP+Kf6Qxr6GoyMEDQPBhQsXXMDE
mMD4VYI/wrkiZ4zka7bVjEZ+xbp37w6NjSRiGV5jR2MXjWp6CYGsIoAZmlfkXZxp8EfK67HHHvvJ
T37CI/frX/+aE4M333yTB/jQoUO1a9dWsarIP2FdZ4gAGYpwgeBILcNP1SgEhIAQEAJBRQAjSJby
QgQVB1/o9emnn2LVeuaZZ9jp4dCIgezPf/4zPoecpz3++OOQkVGjRpUrV44dIDwLe1mdOnXo89RT
T91zzz1r1qzJjJq1a9cOagYC2MWwx5UtW5bTfqKxihUrZigYF7C5PXv2MB07TwJqmIWLvHnznjx5
0gXooFpoBM3EOgb/IjoeIXHw4IWCMEdeXCD27bffjuQE/oDSL3/5ywy5WGTjD3/4Q0yKmDYm6SUE
so4AgY2RN2GJ5uyCb9R+/frxcP7sZz+74447eDix5JIclceYDI1Vq1ZdtmyZC381msLXCOAQ27x5
cz0qvl5ECS8EhIAQiAMB7AXUR4jjRt3iPgL43WH/gpjs27cPosS/uE7hxEg+fJgIW0SiwPBXhMVw
RP+Xv/wFpoYFDfaUK1cuDuojqRn9bfsXkWtQMwxk9erVwwQAiSODHEaxF154wVAz9pZQM6xvjzzy
CGOa2RFg7969dHAaB8M0IWVY7rAbEjWGLaxJkyaE1KV/jRgxgpIftONsyTXxZeYF+SpVqlQkKTPX
cmh0evlCNT5PKUXPidMkqhFTGhGdcDFMvTYIqmtmQ6GL6Aiorll0fEL1Kd8hJ06c4OyU451QKS5l
M0Tg9OnTpAJgp5fhp2oMAAKiZj5aRHgQR+7Vq1dHZkxIhIbhNwVpYkOI/yEJ4vLly0d0FS5/BIXh
TwWR4Sud4gi//e1v165da6gZnIsLDEydO3eG9eADiSWuadOmUDwcFAlMY3AcGpkIh0ZmhOtxQQtW
Oabr2rUrHRhh5MiRuGZB6JwGkB8jtICXMSm/TbiEER0GPczSvGg3YMAA6Cr33nLLLTZHUxqQLMGo
zhkiwPOJUYy/iKJFi3JuQFEGjB38YabvLKtZekzUkiEComYZwhLORnxFiFkgA1gaf/5woiGtW7Zs
yeGz0oAE+EmQQ6OPFhcmhekKcoGHIQayv//977Az5KcdqkLMFCk7zFv4C0yNc3tcH/lK5wwfB0ji
wvBCxAWLr3ccF++8804IGnSMuDOoGfwO8kK6DJJm4IsF7Xr00UdJ3kjAKS5/lDi8dOkS0W2kBClT
pgz+hNjd2Dw4jZ5xZUQ2w8v4hcIqQbp7iv5kaWq+xMhoVLNmTagrBX9JewJNg6D96Ec/4k9AyfOz
BKY6GwT4u+OBJKiT0xLcaHGpxXGRGnlRTrY5CeFPiXMSYSgEoiNgHBpVnTw6SiH5lAyN/OwSMC5q
FpIVj64mXkNkAxY1i46Srz/t3bs3TnG+ViFUwrPrYzeIIQw3VBKA2Lqbc3tsW6aFbpi8ybVIxBmW
L27ZvHkzFi5SeZg+7Co5wOdsHzcJ/CGxiHEjlri33357/vz5x48fx1ZOFBsXNFLHGfdFLriLEejA
dpTAN3t25y6YkXkxmWGDgFqy7yXnP2TKZP6PfV5DzWCpiI1fKEQPP08MiHBMTIEqOR07kuppI8CD
NGTIEEzVGKA5M+EptT/K7IKHmbtcsDVnJoDa/YIACUDIu8tz5ReBJadzCKiumXPY+nFk1TXz46pJ
ZiEQGASgZsZkhs0O/ojbGIfJmAvjo2aYDgmjg9LCVfH2ZHAYKCYzpggMYlLENQR4eDjW4OXajJpI
CAiBECJAYBG5rVTXLIRLn6HKqmuWISxqFAJCwB0EDDUjUgyTGQY7TpLJUvLEE0/ER834daPIFIZC
3BrZUWNPxNrojiKaRQgIASEgBIRAHAjw80eSLlIxY3aP43bdEjAEyDRFQjacfwKml9SxEWB3qj92
Gw1dJBcBzAqQKZLzT5gwgdx0+FJCtbI0BSPgJ4Y7IseGFPrBCZPgCyoFxEfNiAZiBNgZZX+NWyP2
MqbIkkjqLATiRgB/WuI3yTIa9wi6MSQIcGrEt5POjkKy3NHV5HeTH6xYXKajj6NPg4EAB8tsiqIE
NQdDzTBrQQD7ypUrw4yAdHcOAX5QMHWR1BFO9Ne//pXc+9it2rRpQwwFoV6x/NCYQDM4HXYuNrRk
OyHMjeST8VEzEugRNHfw4EEC8fBp5MtN1My51dfI6RHgZICygMrtkB4ZtaRBYPfu3eRlciHVUpp5
9VYICAEhIARSiwDJ7kx9q9SKodmDjQCWKQ79yElCxTHSJJLdkQSJhIyRB5IyZCR+JOArQ4Ma1Iyc
CVAzMnVg7dq1axe0juST8VEzKrVxI+lNMMBBzUzdAVnNgv3seUo71TXz1HJ4WRi810iRrZLTXl4j
ySYEhIAQcAIB1TVzAlWNGR0B3GjJxUGVFspnkxM4b9682bJl41/yDuH6uHXrVlzr7RFw6YGa4YJI
okiI1cyZM8nqHwc169mz5/PPP08KSkxvhJuR80rUzAZZF+4gIGrmDs4BmEV1zQKwiMlSgaRV5FvG
1UQHicmC1Nfj4OrGNknpy3y9iNGFZz9MGvboffSpEHAOAfylKSQN7Vq4cCFRaZS3xpoG+aIoW/v2
7bGRYSnD/5BYM/gU1zyufJrVig/4LkLNGJwNDz6NJhMI1AynSv3YObe4GjkNAlhs5dCYBhO9zRAB
rGatW7devnx5hp+qMVQI8PNXvHjxFStWqK5ZqNY9M2UbNGjAfoYNTGYd1O53BKBmmCH8roXkDwwC
uDWSKgHmNWXKlEaNGlFfGyJGSkaKZVMXG3/I/v37Z8+ePQ5qRslpBmHDA7+jXhvBa1BCUbPAPDm+
UARj8fDhw/fu3esLaSVkChHgm6pVq1aiZilcAu9Mrbpm3lkLL0iiumZeWAVHZWCLa8oNOzqLBhcC
8SFArBkhZiS1I5dIyZIliVC766677r77buhVlgbEamZTM+LroWY89vhJQs1wmFSmoyyBqc5CQAg4
jQCVHA8fPsw5ldMTaXzvIyBq5v01clNCUTM30dZcQkAIpEEA3gR7wnCPkYuNCifJAwcOfPDBBxOx
momapQFZb4WAEBACQsCzCMih0bNLkxLB5NCYEtg1qRAQAgYBrGZEQJMVhHAzUiiQ43HatGnxxZrJ
aqaHKuUIYJ8ltjHDZKQpl00CCAEh4E0Erl27Nnr06EOHDiky2psL5LJUs2fPXr16NafWLs+r6VxD
gJQIHMi4Np0mEgJZQiA9NSMGjfpospplCUZ19ggC5J/p3LkzJwwekUdieBYBqspSyZEaH56VUIIJ
ASEgBISAEwjky5cPAu7EyBpTCCSOgKhZ4hhqBO8gQMnpypUrq+S0d1bEs5Js2rSpbdu2JOXzrIQS
TAgIASEgBJxAQBkanUBVYyYLAVGzZCGpcbyAgOqaeWEVfCEDcbVKnu+LlXJBSByhb9y4QeS1C3Np
Cu8jgCujipp5f5kSkVAlpxNBT/c6jYComdMIa3w3EYCaVa1aVRnR3cTcp3Op5LRPF84JsfFubdOm
DVWGxc6cgNd3Y/br14/IDsLwfSe5BI4RgTx58qiuWYxYqZv7CIiauY+5ZnQOARwaoWbLli1zbgqN
HAwEsJq1bNlSLD4Yq5mgFiQEoHbMypUrVXI6QSSDcTslX0lrppLTwVjNDLWoUqWKvvwzREaNXkBA
1MwLqyAZkoUAP6ZkXqISRLIG1DhBRWDnzp19+/aFoAVVQekVOwKqaxY7VmHoqbpmgV9lOTAHfol9
raComa+XT8ILASEQHwKkSSecRA5s8aEXsLtEzQK2oAmqI2qWIIC6XQgIgUQQEDVLBD3dKwSEgBAQ
An5HwFCzVatWyaHR70uZFPmbNGmCSf3zzz9PymgaRAgIASGQJQREzbIElzp7HAECtylWdenSJY/L
KfGEgBDwDgIwsl27dkHQSNXoHakkSaoQOHDgACUyZVJPFf4uzDtw4ED+5F2YSFMIgTgQEDWLAzTd
4lkEDh48WKNGDRWr8uwCeUcwKPyCBQtI6ekdkSSJEBACQkAIuIBAzpw5p0+f7sJEmkIIxIGAqFkc
oOkWzyJgkucrQ6NnF8g7gm3cuLF58+aqTu6dFZEkQkAICAF3EFBdM3dw1izxISBqFh9uusubCKjk
tDfXxYNSqa6ZBxclVSLh0MhXx8WLF+XQmKol8NS8R48e/fDDD8kU5CmpJEwSERA1SyKYGirpCIia
JR1SDZhCBKhrRr0SWc1SuAR+mVrUzC8r5YKcRJlVqFBhzZo1SgPiAtren6JZs2b9+/dXGhDvr1Tc
EsqhMW7odKMLCIiauQCypnANgSNHjuCltmHDBtdm1EQ+RUAOjT5dOCfEhpqVKVNm9erVomZOwOu7
MZWh0XdLllWBhw8fvm/fvqzepf5CwB0ERM3cwVmzuIMALijXrl3T/sodtH09y8mTJ5cuXXro0CFf
ayHhk4IA1Kxs2bKiZkkBMwCDqK5ZABZRKggB/yIgaubftZPkQkAICAEhkDgCn3zySalSpVauXKlT
ncTBDMAIjRs37tWrlxwaA7CUUkEI+BEBUTM/rppkFgJCQAgIgWQhQCXEpk2bbt68mR/EZI2pcfyL
QI8ePcaPH3/9+nX/qiDJoyNw5cqVr776KnoffSoEUoWAqFmqkNe8TiBw/vz5GTNmyEvNCWwDNib2
EbZeX3/9dcD0kjpxIPD9999jIhEviwO6QN6CV/yNGzeUrjOQi2uUIu2PKqcEeH39rpqomd9XUPJH
InDgwIGKFSvqKzcSE11niMCOHTt69+795ptvZvipGoWAEBACQiCoCOTJk2fmzJlB1U56+R0BUTO/
r6Dkj0RAdc0i0dB1FATeeuutli1bLl++PEoffSQEhIAQEALBQ0B1zYK3pkHSSNQsSKspXUTN9AzE
iIDqmsUIVBi64do6efJkSm+oynAYlvumOi5atIjiGopFuilQ/u2QN2/eWbNm+Vd+SR5sBETNgr2+
YdNODo1hW/G49cVq1rp1a1nN4gYwSDeSobF48eIrVqxQhsYgLWvcujRo0KBnz56fffZZ3CPoRo8j
8PTTT8+ePdvjQkq80CIgahbapQ+k4ufOnZs0adK7774bSO2kVBIRwGrWtm1bduNJHFND+RQB1TXz
6cI5JLbqmjkErHeGPXjw4IULF7wjjyQRApEIiJpFoqFrISAEQoIAR+IffPDB5cuXQ6Kv1IyCgKhZ
FHBC+JGoWQgXXSoLAe8gIGrmnbWQJEJACAgBIeA+AnJodB9zL88oh0Yvr45kEwKBR0DULPBLHCoF
qU9EPRqe6lBpLWWFgBBIBAHSgEyZMuXo0aNKA5IIjIG5d/HixUoDEpjVzFAR6st/9NFHGX6kRiGQ
cgREzVK+BBIgiQgcO3asXbt2ZHhI4pgaKpAIEGhAPk/MJYHUTkoJASEgBIRAZggoQ2NmyKjdCwiI
mnlhFSRDshAgAUiVKlVUcjpZeAZ4HGVoDPDiSjUhIASEQBQERM2igKOPUo6AqFnKl0ACJBEB1TVL
IpjBHsrUNVPy/GCvcoza4QhNWhhlzo8RrsB3+/zzz3GM//e//x14TUOroEpOh3bpfaG4qJkvlklC
xogA1Kxq1arLli2Lsb+6hRYBlZwO7dKnV/zSpUtNmjQh/IQfxPSfqiVsCHTv3n3cuHFEIIZN8fDo
mzt37hkzZoRHX2nqLwREzfy1XpI2OgJQs2rVqskUEh0lfQoChPm3bNlSLF4PAwgQcliqVKmVK1fK
cKbnAQQaN27cq1cvbGdCI6gI1KlTZ/Xq1UHVTnr5HQFRM7+voOSPRIBzTpWSjARE15khsHfv3sGD
B2MoyayD2sODgOqahWetY9FUdc1iQcnXfcjFKodVX69gsIWHmn355ZcXL1788MMP2dNu2bKFHMKP
PPLIjh07sqQ450ucMhUqVIjg+l27dh0/fvz8+fNXr1796quvlI44S0iqsxAQAi4gwO+yfp1dwNkX
U0DNypQpwym6rGa+WC+nhcS7tW/fvrKaOY2zxhcCQiBDBNJQs7fffnvq1KkJUrPdu3eLmmWIthqF
gBAQAkLAawh8+umnFSpUWLt2raiZ15YmJfI0b968f//+omYpAV+TCgEhEEnNDh06tG3btunTp//t
b3/bt29flsC5du0ap0zPPfccDkJ79uw5ceKErGZZAlCdk4IAz+GBAwc4A0/KaBpECAiBMCDA7yBO
I5cvX5aPUxiW+6Y6Uh/zzJkzcvi5KVD+7dC1a1csEf6VX5IHGwFDzchPRWH0w4cP48c4c+bMP//5
z/CsJUuWLE33omIUrzTN9Jw1a9aLL774wgsvbN269Z133jl58iSB1aQj/vrrr/X9FuxHyFPaKXm+
p5bDy8K89957HENl9QzKyxpJNiEgBISAEIgFgZw5c/L9H0tP9REC7iNgqBmnhefOnTt69ChhYvCs
IkWK/PGPf/z973//29/+9vbbb//Vr3512223/fK/r5///Oe/+MUvzDWNfPqb3/zmd7/73V133fXw
ww+3adMGuxtmi1OnTv3zn/8UNXN/QUM+o8nQqLR7IX8MYlGfDI24LXHQFEtn9RECQkAICIHAIKC6
ZoFZykAq8q9//YtMHVeuXMH/kAAxzpDJ48F2Zdq0aSNGjMB21qVLl3bt2jVr1oycRWSUbdCgQcOG
DQmSbdq0KamnO3ToQAWQ1157jSIg8+bNI4waqxmeISQVuXDhAt5lspr58bEhM8yRI0c++OCDL774
AjdXXDuSogUnADB3CHtSRkszCBVCeXr79evHwQJJsNN8mqW3PLTvv/8+jzGFaGO8kZ78BeHKy70x
3mJ3A2QYJTPaLbpwAQHVNXMBZL9MQYgZHiM4Qsuh0S9L5qicHC/j08juyNFZNHgKERA1SyH4mvqm
COBtCDUj3JVfJbbibBHhVuxsZ8+eDdsiuXSfPn1wyu3YsWP79u3btm0LTTMv3nbq1AleNmDAgJEj
R5LXceHChRs2bCAHCNa3s2fP4iTJnpOfvNj3tzeVVh3cQQCaABknDpqfp3r16rG+sc+LLyuPRHqi
QbrOOXPmvPrqq7EH2uNkO3bs2J07d950dh5jnttcuXI99dRTzzzzzIoVK256S5QOGHyHDBmCSQWb
cpRukR9BDDnQqFKlCicSke32NYBkCAsd+DPhL+6VV16Jg9bZ4+siqwiImmUVsQD3NxkaV61aFfu3
U4DRkGrK0Bj4Z0AOjYFfYl8rCG9iQ4h5iy0lxhFYFSf/b775JvtMwscmTJjAthyCxq4SCxrp8c2r
d+/evMVYNmzYMDbP8LL58+ezvSSs8t1332VzjgUBSxz7VTa3omaeekI4Fmb7wdJESsUa0WJvS+AR
LVq0GDhwINQMO+no0aNNZ+7laUkTPMi9sHte9KED9RcgR1jHIs+fueYcEnsrn5qh0sxoj48MZnxu
2b9/P2nTeA4jh7JvZ0aby2Dmw2hbrly5TZs2de7cmV236WZ3tlWzW7jgUDRNOxPxxFJLgsceozDX
ZmqktecyI9DOvTaMvEUezIIIz7V52Vjxlj+N/Pnz8y/XjGDUt6kfaXNat26NO7EZXP+6gIAcGl0A
2S9TQM3Kli2r5Pl+WS+n5VRdM6cRTvn4kyZNwhKRcjEkgBDIEAGz5+TcHiZF4g4MZ/hxYadg37J8
+XIIF1lBYF5wtPHjx7NfZffLpt285dkmjnLu3LmLFy/mR41dN1VcIXcYOyB6WOLYrNqb2wxnV6PL
CBjSAXV68sknu3XrxoaEBYKMv/TSS5icWNxFixbRkp6awTigadCHZ599ls5kmTbsgwcGi2ru3Llp
f/3113l4+PSOO+6oXr06npC2djgxUpShTp06PGmMj+ch19xVvnx5UspAkXhB6vGYLViwIGSQZwnD
K0/a3XffXaJEiUiqxROLeBht8+TJ8/zzz0Mbscfx4JEd9E9/+lOrVq0QySaPnDkwPnrxKQa706dP
w6dgQOg+fPjwUqVKFS9enMeYRm4hDQ6WMqbDWZcXNmIOGbAa0xN1qNnHAQXkC6V4vPlbAEacIrAd
477LCNu3b4fMfvzxx5DEnj179ujRA0zq1q0LvIhkYKlWrRp8E95auXJl5Oft+vXrQZK/PsTglANw
bNB04SgCPAxr1qzhqXZ0Fg3uCwREzXyxTK4JKWrmGtSaSAgIgfQIsC1kVwyHgkmxbycZCPteNtXs
Jznhx0GR3QtJFTCimTSMefPmxdaPwxh0jHYu1q1bx86ZfSl7TngZ21R+5thqYsjAasDgxkyQfmq1
uIwAFGbMmDGwCfgXa1esWDHYCoQIfgTnYvn4NF++fLgdpqdmkJTatWtDmvAbJAgRnsKDwdOCdyux
XRB5mBdcA6IEMYH34RALLbIV5KmATOEZSwtDQViwoEGFcJplKJ40rqtWrQqx4kHCkRImhekWOyyD
Y5zlybSHwraLPatixYrEhnB0YDpwqmDuQhLbksUFTyn8aPLkybTjmQkVooARjZA4rhmf2DQeaeIr
kapmzZqVKlVCL4zC2bJlQxgY3+OPP/7000/D7zijQFQ4F566qFmgQAF68uTXqFEDZCBrCFO0aFG2
+gRg3nvvvZiV8Y9iTODlLwJADCzgDNHDtIfKkD7GhM/yZ8Lf2ssvvwyktqa6EAJCwB0E+AIpWbIk
Xwicsbgzo2bxMgKNGjXCQcihsGgvKy7ZhIAQ8AIC8CZjOINJsXVnh8nmkPyK7BvZtEPQsKBxyI8V
g4Jl2EowarDHppEWdtR8RHAZ2fLZXpJFhG0zv3FYFtiWG5MZg4uaeWGhkQHiDCkgPJBraAuLCGfh
hScPDqg0YqiCHdSvXx//OuiPcWiEQ8EgoHJURuCRwOzFOFiXMGnxAMAs4Ozcy6LThycEmxSkD1JD
o/3icapVqxZEjBYSjMBWoDMQQB4SnjfmxTLLXbRcv36dZwmbGvlnOCLgLmIY7XGwbcGGkAThaeQ8
AWMuhAhbFbNTvsEoYvpjFkELXjyNnBUgGzwOWzDnCVA/nm26kUEdTBgEnoUAeF3SiDw85BjO6FO4
cGEjNj/TGIvBCp9JJjKNyAOtg/0hFfStdOnSUDNMcozJuQQvwEFarGb8mTA+A+JEwQU4Ix6rwJ8M
I/NngkbsB9LgZhTRv0JACDiKAF9fnDLxc8YhiaMTaXBfIICDBIeN/Nj5QloJGQcCbBXYbMRxo24R
Au4gYBvObHYGvWLHCEFjn8lGmh0y+0k2zNgp2KniqUW7aWFnyzU7efaZbGgxSfAbZ1wZjZOYeJk7
ixjLLDBouAOhW3ZnmPjQoUOxhRlLE/Yg0l+Qy4JlhdEYagZfGDRoEL521FOA2uDvB7OAjNAB0gQ1
i3RcZGTMXnRLEzbF00LUGIYnOjAXXnz0odoCFAlahE0Nwsj4uBcyPlSL8SE4ECVsUlijbIG5l7d0
ww5FI9zH5owwIxgT1AYChWWKT3l0GY366TgucoH3IzciM863GN2ggfSBZqI+dkBgQUIzrHH7xJII
n4KLYRc2c8HpGAf7Fz0x6tHIC+dMGpHKUDMG5LgVixsf8SdgbsEkByCoDP/i5wC+hjPko48+iqZg
glL8mbA62PU48fjvqPrHcQSAnQeeLz3HZ9IEnkeAP0CeB9sR2vPySkBnEeCXRfZTZyFO9ej8auM+
lGopNL8QyBQBfpU4tCfIBRMGGxXO8KFXbNohaBgjIFzsnGFe/MsmHGqGpxYfYQiAvhFWRgfOHyBl
bGixTRh7Gd9sHD/KZJYp6Kn4AJtXmTJlCJJicn53sHLCa7CI4XRnnA9ZSo6OsVhFWs2gZvA1jhDx
dYR28RhAaqBaGMKwNEExDJuAccA+sAoZamZsUraWPDkwvokTJ9LCY8bTxYEkg+CsyLBwQFLNQMeQ
kCeN8SFlZhao2YIFC+xxEBuZeQgRg0ZjNeMtjyJ8Bx9FHBeZCP9bPuXQgBaMX3xKf5SC/qAjI0RS
M6yEo0aNgrLB4OjJjRA0HB3JUQk1oxFDG438aSAJMWK4KWL1YxAabasZTC09NeOvIA01Y0DU5y8F
uOB0kDi8HInW5G8QxIA6DaVlCr0cQgATCQ69hnc7NIWGFQJCQAgIAQ8iQPyFOSv2oGwSSQgYBNgZ
ssmETLGZZOvItpm9Ov6NUC1oGmfL7KXJKA4F45wB2xmNvKWRj7imJ5tkbuFGc9xkeJng9RQCJjSM
cCp4NCQIRoZbHSYknFRhH1APXPWgOfAUaBH+ijh1wG4Mc8F3Eeo0Y8YMKDyWKRgTHn0Y1+A4ZH1n
9eFExgQG++AC78HII2gIF3MRw8WTBj/C6sRQgMP4MEHCxGB5JDCEyPD8EM7GsBAWCB2GMMxqkckx
sIhh+4PKccqNJZf0GjgfwnTgTRAx3AvRy5ApHlGOETgcg45x4AC7xAQGo2SWSGpG4Bu6YM9CbKLt
GArvRISBmqEp2fhx6eQ5R1nsaxRVx5rMR8DCk8/IRJ/B1LgghA0eh9WMFkyKaGeoGaY6rGbAgtkO
NaGupCUxjAByahgrWOEwjK2Nnp56ZgIsDI8Ky2QelQCrKdU8gsAB68A6a92b1pufWZ9dtC6ut9bz
9oh1JG7xtlpbJ1gT4r49qzfutfaOsEZwl32R1RHo/w/rH/Ot+aOt0d9Z38Vxu24RAslCQHXNkoWk
xnEUAfbMGLkMQcM2AUHjxe6XHTubVfOCeZnG/234z//TgW7sQnlxIyPwYihHpdXgcSDAumCNgprl
yJEDWxXRXjAmSAcVEB577DGYFyYwIrxgHJhEMZ/h64ilCRoCc4HaUIWcUiCkv4C2kJaQG3kYoGC0
YPohVwaNdINckNADGgIFs4VkTAaBzvCEcCMOhKTXwMGPoYgmQww6kFsDweCJNJIXEboHl4QKMTj8
0R6K5w0SRCPdEBhihemWRoxWXMOqbGrGI438TGqGZTosa8gMNaMPDIsxMR2S1oaAO6ZDQaRCHTw2
4Z4kLYGaMQXIMBfZQjCZcRfHDti2YHwcuyEtzAu7IX8CDE4HBoTSkgmEwVEWyeGhUF1eMEeYL/Y1
rIQAjjcjq0AqMJgyf1mkT8GGiCK2prpwFAEeFXxWeRgcnUWD+wIBvrhw2+brkb9uhwT+3vr+Yeth
iIkZH5pT0CqYyFzLrGWlrdKJjJCle7dZ2/6P9X+4xb6Ifvu31rcfWB+k6VPbqk3LQGvgGes//gme
fZEvF9cLvtU9K6EESxABftBlNUsQQ93uAgLsY+2X4Wjs5PmdwmAR+aIP7ZEtXNONRl7Gg5E+Lgis
KeJDAOMmxhrsTTYLgEHAp9ipQmRYRIZlHSHd/DDxFtZgfqFYZdwCsTVgPzLdTE+oFr55kfdiRYVt
2ePTjf7YwiCDWOt4y4zYy6At2KqMLyWNPEjwF8bnI/MI8S9iwBPZONHBfjEarraYmVDE/vXkZICh
sKlhETMOjaY/8iMenU0cGY30hIgZFfjXaEo7AiA2Vi38dZGQG6FmGNqQE3wwe0WKgY6Yj40F2Uxk
D4tIjGkaGYe7mAVIuTCwQA8xCOIYyfhGftohxYTgmbv0rwsI8KRBzWQ1cwFq70/BnzxnLPB0/mCd
k/YZ65n/sf7HjD/XmlvJqmTP9S8ra5SQ/v/X+r+R1CyrI2Rot/o3pSmt///nGzrJf0bIc9Y5Q83s
C9OeZhz7bR+rDyZCW0EurlhXQMC0QNy4sAePFJ5rZLBb7IvIoZy+xkEC54fIL3ynZ9T4LiPAsSqe
OS5PqumEQFIQYG8c+WLvioWCrXhko7lOynQaJMAIYBvCLobByHAihzRli0XyfxKAJGV8qBO2LafD
kdgNQhOIicN/OClia5BYEICtY9yEIMfSWX2CjQDnNuYQxn1qhn9jX6svronlrfIfWx+/Zb11r3Uv
jn9jrbF5rDznrfMYmMpZ5QyXMavQ3eo+05rZymplqBkcbaQ1kkHqW/VtIvOF9UVlq3InqxNjQoiM
L2Jbqy2OlJ9Yn2Bxw6uwhdUiclnfsN5YZa3CsLXZ2kw75BEbX0OrIYPzlnEMNbMv0ozzqfXpdGv6
VGtqdas6Mue18nawOhyz/l/dwK+trwdbg7NZ2aZYU+iTz8rX2mrdzGqWRv2D1kHUn2PNqWJVgbou
shZVsCrUtGoigJsv1TVzE+2UzIUDDOerKZlakwqB5CJA+gJ8xkyUUHJH1mhhQACjG4kQofZ+URZT
IIkiIz0znZCcs1mKmtkpH52YQmOmRwDLJkQe+2n6j9QSNgRco2btrHaTrEn8B+UxVjPoyU7rP6VA
elo9O1oduShhlSAwDZJ1h3XHVesqDoSHrEP2ihDq1dRqylvuMtQst5XbmJ8KWYXWWGvsnrut3XA6
3vaz+nWxunAxjv9Z1mvWa9Cu5dbyR6xH3rf+k6iW15fWl3Wtuly8Z7232loN/yplleLtDevGr61f
I4bNyOyLNONgJjNyjrJGfWV91cBqkMZq9pH1UX4rP2NyAUczMqdXP7uVHWZKt7usuwjK4+Ie655I
Wx4tTr9EzZxGWOMLASGQLATIq4C3GMnJkzWgxhECQkAICAEhkFoEUujQmNPKCdtCfSgYZjIuMBW1
sdrAjxpbjbGdjbfGR4LT2eqMwYsWDExQM6xOv7J+ZWgOhrP2VvvIzn+3/v5P659DraHwHVgYiUf4
9DnrOYxxkd24XmuthUzZjSusFYaa0VLYKow1zWZk9kWacbCpnbXO2iNEoWbM/pT1lOmZXv3HrMc+
t/5zYEJoHoSRiwesB2xroD2+oxdyaHQUXg0uBIRAEhGAmpHowKRAT+KwGkoIJAsBAuIwQhHMlawB
NY4QEAKBR4DAWEoTElJKTKhzyuLFh7+iGX+2NbuiVZFrvAqNx+AGa0MjqxEt31jfYM963XodpvO4
9TgWrkiRZlgz8PGjBWpW3CrOBVwGn0YuMI3hChjZGVKG4eyUdYqRMdIZBveK9QoWOuxQkDUCx0z/
S9al+6374XG83W5txzvx99bvja0KUxeS2IzMvkgzDt6ScENux4mR0TALQvcihcHLEQRogZoZ30iu
06v/N+tvKadm+DlTXIPw4Uj5dR0kBEgmRs6uIGkkXUKLANSM/H6ymoX2AfC+4kSZ4YuifBreX6mU
S0j+T1LTkIAl5ZJIgDAggP/hndaduCxi57pgXahh1cAqdNg6DD/KZeXC1ZDILOO/BxrEYRnnQOLF
DE+xIeJtMasY8Vz0wRb2ofUhFq4nrSdnWbO6Wd0M+bI7w7Doyds91h4+Ne3MiNEKQoejo92Tix5W
j7utuwnyIoiMtxA9OCDhYyZF/wJrAY6FsDz7Is04R62jKMLIxqiHWyPM0a4OgGBYAH9n/Q43y3nW
PKBAd2ZJoz5vf2v9Fo24kQv8M3GwxCy4ydoUKaquhUCCCKiuWYIA6nbvIEAhM2LNpk+f7h2RJIkQ
iESADJCk7jf1oCPbdS0E0iBA6hXqmulRSQOL3rqPAMYpyFrkvMaRjxb7IvJTrjFLkViDQDDTjqGN
cLA0fcxbewT7wrRft66n75+mERZJ1Fj6bpEtaW6JfBuZuiTyljTX6dVP00FvhUDSEVBds6RDqgFT
hQDOHhjOFDifKvw1700RIJ0+VaqVEf2mQKmD6poF+xkgzQsvfrOogsFF9MSwfMrBoxyhg/1IxK4d
uarY55B9OvZb1NNfCIia+Wu9JK0QEAL+RQBqJquZf5fPTclFzdxE2/25Bg8eTGmqs2fPjhw5kgvK
vkSRwTiEbNy4kQIxRBhRr5Dc2lxHuUUfBRiBV155ZdSoUXbNzQBrGlrVcuXKpWTjoV19KS4EhICb
CFBK+6WXXlq5cqWbk2ouPyLAPrxFixZyaPTj2sUic9euXSkpTixh7969uaByfZS7Ll++XK5cOSoY
QscoL1ilSpXJkyfLPyQKYsH+qHHjxjw2egACvMrNmzdXwZoAr2+oVCONFa5ihPOESmsp6yMEOPGm
trUck3y0ZKkS9cCBA9RA3759e6oE0LzxIQDJ6t+/f82aNbGLkcsFrzP4FCn1KNrepEmTNWvW4L7I
yFQkbNeuHdSsX79+bdu25S56knavU6dO2ETefvvtGzf+X6DWnj17iDr805/+xLB8e8yePfvvf/97
qVKliEa0+8QnapS77ESL9kWazoSPkSef3CBp2jN7SygZRahNZo/mVnMyaZie1C8jEwhVqulAJhBS
iJCvI7NBPNh+0jrZy+r1tvW2m7KprpmbaGsuISAEEkGAn60KFSqMGzeODHicMeolBLyGQPny5anv
wFPqNcEkjxMIsNzmFTm4aeExqF69Oht4/h0yZMiZM2cS+erTvR5B4P3334c0EU8KjXr66aehYxSy
Hz58+HPPPde9e3foGH5KxuCVnprhv0S39u3bd+zY0USa4LHGb1nBggV5SLJly3brrbcOGjRoypQp
efPmJRcx9M25Qx5y4//S+iWo2hc2wnCozdZm/qX2tJ1k3v40swsyN9LZFKEmpyKp9en5rvUujWQI
IXdiXisv2Q5Jmw9Ny2yQ6O1GsOh9kvspyfxfsF6ApVKiup5VL7mDRxkNjt+nTx9ZzaJApI+EgBDw
CAJ2XTMiel7TSwh4DwF2ViNGjGAr7j3RJJEjCLDikeNiSWGjTkudOnXuv//+H/zgB/feey+bdmKO
PPItKjESQaBHjx6Q7sOH/5N3fcuWLV26dFmxYkXRokXnzZuHUweNPADw9EOHDrHottUMOrZ79244
O+mFTQARjw2ez1hO+Rcj2rFjx7iAoMH4qHZUu3ZtejqxM7cTHlJm2lAz+8KGBTIy0BrI22ZWM0PN
4Cb2p5kVX2ZkCqUZakZnMxF2t2esZ8y9P7d+Dreyx4kck872sJHtpr/dYgtmD2ImsjuYt5GfprmO
nIh0+pGp/iMHoZ23/EeFNZL8Mwh2QNhZmtGce9uqVSueEMWaOYewRhYCQiBZCNjULFkDahwhkFwE
+DHl3ID8WskdVqP5BQEChdauXUuoyDPPPIPhY9KkSVhVMqsjrAxsfllWIycF5WvVqgUdO3/+vGlh
BQkQK1GixN69e00Lq1+8eHF8FCFxNjWDfC1ZsiRfvnzY04kxIfQM01uBAgWWLl1asmRJrGzUqcce
x7cHjwopQWrUqMGTQ2MS8cGMhd3qJeslqoMx7D5rn6Fm9oWZCzJCO3XKKOkFH3nAegBC9FPrp9jR
6IBrH/89aD042Zps+vPvaes0RrF2VjsKgUHNsJT9xvoN3bZZ2yh89gfrD/gxUh76h9YPa1u1YYLc
O9ganMfKU8eqYzoXtAoyBZXXcImkXNp91n3UL6tv1b/Nuo1607+wfoEkkYKZqSFQ5a3y3PJX66+0
LLQWwg0LW4XhUFCwmlbNP1p/pE8RqwgVtCMnorQZ8mC8+4v1lxHWCPpEzosYoFTVqorito4PWQ9F
qmy3O3TBl8Ynn3wSPaunQ1NrWHcQaNOmDR7L7sylWYSAowjg0MiBJA6Njs6iwYVA3AgQCEkI/xtv
vBH3CLrRjwhg4MCGwlb8ySeffOqpp0gB8c4770T3RuNRGT9+/M6dO/2obzhl/uabbyBNLK6hZqwv
++fFixdDzfbt22cwWbhwYbFixXibhprRjgMkroyEks2dO3fRokWbN2/ev38/ne2MHzxFDMjLCWo2
xZoywBrwD+sfUCRMVDYjsy/sNYVPGasZhMjYjJ63nodV4ZcICaISNGWdKVdt9y9llYJP8ZY4MmM1
gxxBzWhpbDWGW5met1i3GFPa49bjDNLQaggdgxbRuYnVhD64QRawCvARhacbWY0I7/qZ9TPqlA2z
hkHW6GALZgaErMEBiQWbbc2mBQZnTG+3W7czO9QSqmiGNbfbE1FZG3bJR29Yb+BgmWZeps5t5UZU
MyzdYLUlrZJc6CUEkoWAMjQmC0mNk3IEOEXEXWTDhg0pl0QCCIEMETDJ81XXLENwgteIGeXo0aN8
KRFD9MQTT9SvX590EBjOYtFUGRpjQclrfSBcZcuWfe+99xBs6tSpdevW5RzmhRdemDNnDvXLaOzQ
oQOWtRMnTkTGmtEIBy9SpMjYsWOvXv1PaWb8FUkPgu8iLIzzc+Pv2vm/Lwan0ZjSkqg+zoGVrcp9
rb4/tn4M77AZmX1hz2UzIKiZcWjEOFXWKgtFetR61O5mX2DbWmIt4W0lq5KhZlipMqNmUC0Il30v
F3RGKi6etZ7FemV/hGCMzFvMYZjeuLAFs/swHUwTI9dH1kc/sH5gqBmGM0xy6amZPVFvqzdD2YOk
mRf2ComDSELZTB8oLRTS7q8LIZA4AqprljiGGkEICAEhEAsCUDOVnI4FqGD04bCI0EKCjyZOnEii
j8wcFzNUVnXNMoTF4424HeKUiDtivXr1cuTIwerjvTxs2DAsYnixEiNGBg8KIpBZESdGfBdJzAib
44I6ZeT3yJ8/f8OGDbmXjRnmM3I58hgUKlSIYoh8b+TJk4d7aSS7CLZXfCAN3UsKJli+cBFkKEgH
/MhmZPaFPQvOe5AX3kLN8IHkAmpWxipzxjoDraM/LdA0uz9EBk9C3kLNilvFubCpGRaofFY+09PM
yzUOk0OtoVyMtEZCeehspuPf31m/w6SFeNAiXB/TUDNbMDMgZjWE+R/rf5DqvHUexgeJ4yNmJErO
OEDyFlHvte7lwp4IQxu3HLb+EzA4zhqXZl5akIpG4/BJH7wr+dfNF4lb+SlRYTs3MXd5LlEzlwHX
dEJACIQWAbzU2KjLoTEkDwBcDCc3bGdx6CtqFgdoXrjl448/xiMROsYKmjz5xARt2rSJDB40ktmD
ChrISWYPsoWQGwQLGoYwkyQE2xkpYgYOHIgro+lmeg4dOjR79uzTpk0zXAwCSF4RiiTafRJXnDT4
uPwVtYriRkiyQVwQf2T9CF5jX9hTwLCgSNCcJ6wn7rTuJPYKP0aCzi5bl7kdKxVMh5T4dv951rxb
rVvpTBQbH221tv7a+jX8CEsWrA33QuLUplnTsGo1tZqSyBEfQpgRvogdrY7wIzoTqkY7dj1uRypM
WjhPQuvoxr0Y+5B5v7XfCGan5Wfeu6y7YHnGZ7Kr1RUx8I3EKxLzGZZByFoOKwcyk4FkgbXAngjJ
sZQxEdMRg5ZmXmgmHptYyqpYVYyOP7F+YgiprbLTF40aNerVq5cTeWCcllzjx4iAHBpjBErdfIEA
50jxbYR8oZ2E9DsCJ0+exJGJrNd+V0TyO42AcWgUi3caZ1+Mj+kNYxwpRBw1lMCtQAOb1E0xMakR
M+xGPvn03n1QIWxq56xz6T/KcBB4E+Qrw4/wJ8yw3TRGCkYGRd4a45f5FNUQw76dTxGJieB9dqN9
kWYi+y2yYbmLHAeTnH2XOxeqa+YOzimchagHTmBSKICmFgLJQoAgDkKwFciTLDw1jhMIYElR5j0n
gA3YmKSS2LFjh+qdBWxZ41PnH//4ByFsq1evxggb3wi6K0gIiJoFaTWlixAINgJ2yelgqynthIAQ
EAJCIDwIkJWRLPqUSBM1C8+iR9GUgEQcGpNbPSHKdPpICAgBIRA3AqprFjd0ulEICAEhIAS8iYBx
CNm1a5fc9b25QC5LRdl6ssSY+ESXp9Z07iBAXiCTrNWd6TSLEHAOAVEz57DVyElB4PTp06RS3717
d1JG0yABRoAMEvg0KtI/wEucJdUgZXKEzhJiAe7Mw4BjfIAVlGpU3Jg/f75wEAIBQEAOjQFYxGCr
QIbGihUrKrdDsFc5KdqRK4b86mvWrEnKaBpECAgBISAE/ILAk08+OXPmTL9IKzmFQBQEyCS8detW
DMFR+ugjIZBCBFTXLIXg+2vqt956q1WrVkpq5K9Vc05aWUmcw9Z3IyuXlO+WLKsCq65ZVhFTfyEg
BIRAfAiImsWHWwjvUl2zEC56ZioTdULah7179yrWLDOIQtU+ZsyYBQsWKNYswIsuq1mAF1eqCQEh
4CkE5NDoqeXwsjBYzVq3bi2rmZfXyDXZyNBYokQJZWh0DXCPT6QMjR5foMTFK1KkCOw78XE0ghBI
OQKcKJ44cYKIs5RLIgGEQIYIkKlm2bJlPKUZfqpGIWAjQKxZ586dsxRrxtO1fv16qqF99dVX9ji6
CAACqmsWgEWMVIF8UFOnTj1y5Eh8ZlDVNYsEM5DX/Ml/8cUXgVRNSoUNgQsXLtSoUYNvvLApLn2F
gBAIGALQq8uXL8fis0QuR+gYPO6JJ5644447unXrpryOAXsYRM0CtqCHDx8uX778gw8+WK5cuVmz
ZrG+WYolFDUL2PMgdYRAgBHg0Jj0dxMmTAiwjlJNCAgBIQAC33777fvvv0/UCa4vt99++w/++/r1
r39NUNK1a9cEUZAQYOsuh8YgLSi6UAoBq1mfPn1I+PDII480adKE8NIbN27EoqYcGmNBSX2EgBDw
AgKqa+aFVZAMURD45ptvcLiVo0IUiPTRTRHAPWDp0qW1a9f+4x//aBiZ/S/UrHfv3tjRbjqIOvgI
AUyoq1ev/uijj7JkW/GRgmEWFcv45s2bmzZtitUbmta/f/+jR49Gd3SExO3bt49fkzDjFmzdp0+f
fujQoWDrKO1CgoCsZiFZaP+q+d577zVo0CBLAUT+VVaSJ4LAhx9+uGHDhsiwROO4SLGzxx577Kc/
/alNxyIvoGY4NF66dIlKInoFBgE24RhZsJMGRqMwK8JqwrV5GRAMC2N9z5w5M2XKlKJFi+LoWKlS
pblz52bV0TGRLxzd6ykEcuXKNWPGDE+JJGGEQHwIXLx4sXHjxnPmzInvdt0lBJxGgAyNVatWJROI
0xNpfL8jsHHjxhYtWphHBTMrZcpxXLz11lsjiVj661tuueXPf/5zwYIFn9MrQAg8//zzhQsXfuGF
FwKkU3hVYTXz589foECBNBDwB16yZEk8V++///4f//jH/HVz8eqrr+JoAXHz+xea5M8SAqprliW4
1NnLCODs8dlnn8Xore1lRSRbUBFQXbOgrmzS9Yqsa8Y329mzZ2fOnFm5cuW77777hz/8YXpSZlp+
8YtfVKhQYeLEiXTWKzAITJs2DT+3119/nYP0wCgVZkWwjvGKXM158+bNnz9/8uTJjRo14m8csziV
rXr06LF//36Ma2m+XiimgGVc3q1pYAnSW1GzIK2mdBECQsDLCITcasZeguSBOOZpU3HTpzSSmtmd
cYU6duzY8OHDOW/HdzE9QSMfSL9+/WLJ62iPqQvvI8CRY7169bZs2fLdd995X1pJGAcCp06dGjly
ZKFChWBkxJ0RfRYlmU+7du2GDBkSpUMcAugWTyGQM2dOws08JZKEEQJCQAgEEgECe+vWrUtEfyC1
u6lSRIO+9tprY8eOzSxPBdEW77zzDmkubjpU4Dvg0Ni8eXP8GDPUFAC3bdvWsWPHNHFnytCYIVx+
byTmqEyZMqtWrVLmB78vZRr5z58/P3v2bFLoP/roo7gyshv/+OOPb3pyReAGqR1VIyMNmEF6S0wx
RzFB0ki6hBYBIjIINNu9e3doEZDiHkcA1xR+eUN72knQBKETAwcOzAwBdinsOrZu3erxdXRBPFg8
3k179uyJPhdsd8mSJTVr1rznnnswot122204QWUGb/Sh9KlnEYCalS1bliMdUTPPrlGWBONoBbsY
5cnIypg3b16yquLrHj0rY+T4qmsWiYauhYAQ8DICbPw4fRo3bpyXhZRsQsDvCLCFgDJg1qEmMrpQ
XcvkEmR38eabb2Lo6dSp09ChQ+3sgkRGEFcCZYBrtGrVavDgwXAHjnzJcdGsWTOSXSxfvvzq1atU
+aG4D44c9Dx9+jS7l3Xr1mEY6tu3L46gcuWK8tiQu+/48eOjRo2iji3ujqJmUbDy40eymvlx1aLI
zAHyM888w9cd36JxRMfLahYFW30kBISApxBQXTNPLYeECSoC7CWgVy1btiTuCR0hVmwVqLRF+EP2
7Nk5HoGakQK6Ro0akLUPPvgAxzySyxEfQYaKbNmyDRgwgBh2uBt9YGEdOnQgwmL06NEHDx5kTM6Q
6UBlHzrg4YNfR/369fHmgvGJnd30iWJpcB4QUDcFyl8dcPHFMMoBCBzcX5JL2gwRIHM+5ydx511s
3779sGHDdAKTIbbBaOQv/aZ+rcHQVFoEHgFRs8Avsd8VZIu1cuVKzEy+VoT9P7ypbdu2WGpQBI0w
fkHQ8FSEl+GoQyORUFCzESNGYCmrVq3a2rVraaRMKtd472BHI3DG+NJz/fLLL0PBAIc0ZbCz7du3
Y30j7wGVfbgLgxpukK1btz537hxvQ/LidxmGpV/nkCx3dDV5EghKUqn66CiF51O2Ongs6MshwCtO
ok6cRgKsoFQLDwI4NOKQL4fG8Ky47zTFMY/855nldvCLOhlSM7wTDV8zxPOjjz7CTNa5c+euXbvi
xGicG/HLoiCyiTWjCuHixYvbtGlDKR9MadjO2G/AxWB50DrC4an7A1bcC1njunr16tjg/AJR4nKS
DgXXRIXdJY6kRhACQkAI+AuB3Llzq+S0v5ZM0maGANErJH9TWpvM8FF7yhGAXLz44osYmFIuSSIC
GGoGqzKEi3I8derUgZrhYwPDIkyMwaFmGMJ69uwJF4NbnTx5kkaoGUxt0KBB+C4SYlaqVKkxY8as
X78eAxzdIqnZ1KlT8YHs0qULdjT42qJFi3bt2oX5LBGx/XUvQSjgZkpO+0tySSsEhIAQEAKJIKC6
Zomgp3uFgBAQArEjEAxqhhs8lIr4MsqhQtNI00HU2IoVKzCHkYbCnI289dZbL730EmVVJ02ahPHL
1AvYsWMH4WYUz4Wc0gj/Ajqyf9ATTkcAGiyM5GOYinCApAPOkHQgHwg1lJmRDrFD7feeGdY187tS
kj8+BPgrw9TOoYd82OIDMGB34e9NIhGl6wzYskaqQ8z1rFmzIlt0LQSEgBAQAk4ggENjxYoV/e7Q
CDLsDYoXL46fIerkypULamYcGh966KHChQuTuKNgwYL4IlKnDP9GKqjyFipHZ5JFw+CgqPThdhrx
VKTKKm6NjIkFjaFwsycDJN0orEwH7IzY1xg/9uTSTqydy2OKmrkMuJenw9xMShxOP7Qb9/IyuSZb
w4YNe/XqRSFy12bURC4jIIdGlwHXdM4hQL6jL7/8ktJRzk2hkYVAIgiQrhCb0c6dOxMZxAv3wpKg
V+PHj6cS2d69e9977z2O9HFoxE2RFoKkqDBIBTcjKok+cHokqSPki7sAgdtPnTqFQW3kyJEc/0Lf
1qxZw0cYyDC6kSHEVH+jPyY57GUkbIw7m5kX4IpDBsyOcmiMA7dA3gI1U12zQK5sfEqprll8uPno
LhzaOdj0kcASVQhkhgA5i0j1Rm6BzDqoXQgIAYcQIH0cQWTEl+kHJSkIE3mHv6hNb5MypgbxKQKi
Zj5dOIfEFjVzCFgNKwSEQNIRIEMjkSyc5Cd9ZA0oBIRAdAQwWGMCI5uHqFl0oPSpEMgqAtid5dCY
VdAC3F8OjQFeXKkmBAKGAOfMpA4gY0DA9JI6QsD7COBwSB1VCJrqHXt/sSShvxAgqqhPnz7UUwhV
uKW/1shNaakQRNJavmzdnFRzuYnAoUOHKPTp5oyaSwg4hADUrFKlSqJmDsGrYRNHgAArwrep25X4
UBoh2AiwGycoDyftYKsp7WJEIGyxljHCEs5uehgCv+7kyCJfceDVlIJhQMBQswkTJoRBWenoRwQC
k6HRj+D7S+bNmzcTOUtGFH+JLWmFgBAQAkIgQQTIWjxz5swEB9HtQsALCJBY+MCBA2fPnvWCMJJB
CKRHgCSEMZacxi3w2rVrypWdHsOQtJChsXXr1n6vTh6SxXJBTb4KZCtxAWdfTEFlSfmN+2Kl4hZS
Jafjhk43CgEhIASyhMBNqRm7LzzZKLhcr149SBzRJVkaX50Dg4DqmgVmKRNX5MqVK506daLohmLN
EgczACMMGTKEesQkxQ2ALlIhQwRkNcsQFjUKASEgBJKOAA6NVapUybDktLH5du3a9amnnqIuM85s
b7/99o0bN5Iugwb0BQKmrpmsZr5YLKeFJEMjNdlVctppnP0yfqNGjVRy2i+LFZ+cpUuXVh2o+KDT
XV5DACs/aW3OnTvnNcEkjxAwCFy8eHH9+vVUZ7YB+f7776ldNXXq1HLlyj388MMVK1bEw1ypmWx8
QntBrpju3bvztIQWASluI6C6ZjYUugAB1TUL/GOA88zXX38deDWlYBgQIA0IPmCTJ08Og7LS0e8I
XL9+fcOGDS1atMiVK1exYsWGDRtG/ka/KyX5k4UAnB1DqiJKkoWnr8cRNfP18iVdeFGzpEOqAYWA
EHAIAWVodAhYDZtcBKj/RTQZjOyWW2659dZb8+fP365du969e2MlwaGxy39fnTt37vjfl3mrf0OI
AA8Drzlz5rAzT+4TqNH8hQAPAA6NpOtUXiB/LZxD0jZu3BiHxs8//9yh8TWsEBACQiBZCEDNVHI6
WWBqHCcQIHbsww8/xF9x165dLVu2xGTGv82aNeOntmHEi1CCBg0a1P3vK6JZlyFCgEeiadOmTZo0
GTt2rJy0nfhj9NGYHOZs2rQJz2dsqT4SW6I6hAA/H8RuEMHh0PgaNuUIjB49WknAUr4KEiApCEDN
KlSoMH78+KSMpkGEQNIR4Pe0Vq1aKlaVdGCDNyAUHn/X48ePB081aSQEhIAQEAJREMiZM+f06dOj
dNBHQsAvCFy6dIlKQAsXLvSLwJIzbAiQobFq1arLli0Lm+LSN6sIbNy4sXnz5npUsoqb+gsBISAE
/I6A6pr5fQUlv40ANaFw/JA3vg2ILryGwE3rmnlNYMmTKgRU1yxVyHtwXsqZHTt27OrVq6o67cHV
cV8kEkadP39eOYLcR961GUXNXINaEwkBIRByBGQ1C/kDELv6omaxYxX4np9++ilh1OQO0sFj4Nc6
FgWJUB40aJDSgMSClU/7yKHRpwsnsYWAEPAdAocPHybFx7p163wnuQR2GQHj0JhhdXKXJdF0KUeA
DI1lypRZvXq1qFnK18ILApAdqE+fPqJmXlgLh2To27fvzp07HRpcwwoBNxG4du3apEmTtm7d6uak
mksIxI4AObWIiCRPY+y3qGc4ETh69OjcuXMPHDgQTvWldSQCqmsWiYauVddMz4AQEAJ+QQCvj7Jl
y44bN84vAktOISAEhIAQEALREfjkk09KlSqlumbRUQrPp6prFp61lqZCwO8IqK6Z31dQ8gsBISAE
hEAaBKiEWL9+/bfeekulrNIgE863Xbp0GTVq1PXr18Opfhi0/uKLL/THHoaFDoOOomZhWGVf64hj
EsUd8FXztRYS3gUESMpHvln+dWEuTeFxBKg0jSM0z4PH5ZR47iBw5coVwjeUrtMdtFMyS7Vq1Vas
WJGSqTWpEEguAnJoTC6eGi3pCJChsWLFisrtkHRggzfgrl27+vfvT57G4KkmjYSAEBACQiAKArlz
554xY0aUDvpICPgFAez7U6dOVVobv6xXCOVUXbMQLnp8KuO9RopslZyODz3dJQSEgBDwLwKqa+bf
tZPkQkAI+AsBUTN/rVcKpVVdsxSC77WpCTyZM2fOiRMnVGXYa0uTEnlwdduyZcvXX3+dktk1qQsI
5M2bd9asWS5MpCmEgBAQAiFHgFzocmgM+TMQo/pYzVq3br18+fIY+6tbgBEgQ2Px4sXZkKuuWYBX
OXbVGjRo0LNnz88++yz2W9TTXwhAzWbOnOkvmSWtEMgQAWKlr169+uWXX2b4qRqFQMoROHPmzMiR
I/ft25dySSSAxxGAmrVq1UrUzOPL5I54qmvmDs5+mUV1zfyyUnHLSazx+fPn475dNwoB7yBADqsW
LVrMnz/fOyJJEiEgBIRAHAjwbUYmT7LOxnGvbgkYAqJmAVvQBNURNUsQQN0uBISAawiwjalQocL4
8eNdm1ETCQEhIASEgBBwFAE5NDoKr+8Gl0Oj75ZMAguB0CKgumahXXq/KE4lGipVKZbfL+slOYWA
FxCgiNXYsWMPHTqkrw4vLEfKZSAnzJo1a1TnLuUL4ZwAcmh0DluN7DICULNKlSpNnDjR5Xk1nRCI
EQFyrHXq1Gnz5s0x9le30CIgh8bQLr0UFwJCIOQIPP3007Nnzw45CFI/GAhAzapWrTpp0qRgqCMt
gocAJacrV66sktPBW9mka0Ty/LZt25KUL+kja0AhIASEgBDwMgLK0Ojl1ZFsWULg22+/PX78+Kef
fpqlu9RZCLiGgOqauQa13ydS8ny/r2AS5ccRmszD+EIncUwN5V8Ebty4oaJm/l2+WCRXyelYUFIf
ISAEhEDiCEDNMOwqI3riSAZ+BJWcDvwSx67g5cuXqaSwdetWjh9jv0s9g4pA3759J0+eTCHyoCoo
vfLkyTNjxgzhIASEgBAQAk4jgEMj1GzZsmVOT6Tx/Y4AVrOWLVuKxft9HZMiPxkaS5YsuXLlSpWc
Tgqefh+kUaNGvXr1Uslpv69jFPl1hBsFHH3kLwQw8XOu+P777/tL7JBL+/HHH48ZM2bdunUnT57s
168fiTJiB4QV5zyZ7crZs2eHDRvm/cAcfkz37t3LRit2HdUznAiQoYs/BwhaONWX1pEIqK5ZJBq6
Vl2zwD8DpN+UA3PgVzkkCip5vh8X+siRI7Vq1Ro5ciR70RdeeGHHjh0xakEe6bfffrt69eqYoiA7
U6ZMefPNN2O8V92EgMcR4PHmzEHJ0j2+TO6IJ2rmDs5+mUXUzC8rJTmFgBBQ8nxPPQOErpOSBScc
EhKePn3ayEb88oEDB+bPnw+r4prGY8eO1a9fn6o9e/bswWkHgkYjm1KMaKtWrdq/f7/tw0OcxalT
p5YsWYKJjdTiV69eff3115955pmZM2ey9LAzGrnX7rZ27VraaWEibmR7c/ToUcrBkCuGxsgXTvtM
R4d9+/Z98MEHfIR5ixT3GzdupNH0ZJP80UcfLV26lBGw9NFIYP6HH37IFBjCEMk00o7iFy9epBuK
GxsuIvEpnc+dO7dhwwYQMEp9//33jA9E2Pv41ExkbsdcQrSR0ci0618hIATCiQDfEmXLll29erX9
ZRhOHKS1QUDUTE+CEBACfkGATTKZyVXXzAvrBZHZvXt30aJFn3rqqYIFCz777LNwjQsXLgwcODBn
zpzFixfPnz9/w4YN2XKkp2ZwLiogkDyW2wsVKtS6dWuYDjxo8eLFxMYyFHSMAnZwH0xmf/jDH156
6SVIEN3Gjx8PyaIb2Y2KFCnCvKVLl4bxMUW1atWYlFeBAgX4NE36erJzMBfEkMH5yESE0bNw4cLc
ApmCW8HUMOrRwr8lSpTYvn37e++9x/hMVKxYsXz58vERJj8UZ0b2UcxOTwaEh0JR+/fvDxSMdv/9
92fLlm3w4MGMCacrU6YMOjL7888/TwwaPgyQ01KlStH43HPPMc62bdu8sKCSQQgIgVQhACPj65Sv
Ec5tUiWD5vUOAvxgcZYohzfvrEjSJWHDsHPnzqQPqwGFgPsI8MtVoUKFcePGuT+1ZkyDwJkzZ0hi
ULNmTcxPGJs6duzYokULbEOwFQxMWIveeeedcuXKkWkqkppBSfg6ImAQlgRPYR+CgQkWNmLECH6M
6N+7d28YDZyIkTG0YXqjESqEOaxevXqjR4+GVfEMEHfGvchAWrO6detyLyPTE0lobN68OS6Ukb9r
CAPpo5FPsa+1a9cO2nj9+nUo4aBBgxiQ30FEhQmyRzp//jzycAKAiY26kIwPl8Qs2KxZM6TiokOH
DjReu3btypUro0aNgruxrerRo0fu3Lkx8FWpUgVmB0cjqg4VIHfMAmllQPgaVjaAevnll81Er776
6osvvogkaeDV28AjwN/FvHnzeJ4Dr6kUFAJCQAgIgUgEOMGePn16ZIuuhYBPEWAn/Morr6QxiPhU
F7+LDdmBXhH/hSIQMQjawYMHYUwQE8OJ4NF9+vSByxBrBg8yDo3wFIxTU6dO5XsJE9icOXNwWSxf
vjycCKYGxzHnSIyAhZTUH7j8wZuwPbGPbdCgAQFr8D7sUIzJvBja5s6dCynD7FW7dm2IG42kDaFb
jRo1IvkO0jI1zop0wIUS/ti4cWM2xmSvhVRiESOKjevs2bPjewnBxNgH9eMuZJs9ezZ3EbTL7RjO
SKmHtFjKaKQPdjRwINHxa6+9hpqAAAJNmzaFJ3LNLY8++ijka8GCBfg6cgu6QPcgd0jOjG3atHny
yScPHz7MR3qFCgGcaTlD0LdZqBZdygoBISAEQEB1zfQYBAkBNu0QgSBp5EddDCXBSS9yYwkXw/BU
p04doxHcigR0UDN4B6mAbWoG24I64fUHOWJriukNyxEsCZqG3+ChQ4dsQEjPiJMk1My4LELNhg8f
DoODLmH8ohvUDIoENcP1EZsa/IhGorewZDFvGmoGVzLmPMiU8aVkagxYbdu2xUaGKY3RmK5JkyY5
cuTgaxN5sOjBqggAYViMXFzA7yBZeNUyFI08inBJGiGYWN8wq0HH+JQLpoM/QuhwX8QVE5vdE088
gfybNm165JFHUIqpeWG/g1HaUWyMqVdIEOAPgQfD+0lHQ7IcqVWTrxe+bTCv89WaWkk0uxcQ4LeD
mGjlCPLCWjgkg6iZQ8BqWCEQZgTgIMRJQb4AATaEaR6PPhgKPAW7FY147mGBgvikcWjEmxHWQ4iW
SdaBryCUh0QZGBFoNDtV/BIHDBgwa9asLVu2wGLYtBirGZyLDS2+giY+y4S2Ge4GJbwpNSNtCIIh
OXY3PCe5hlshBsJDzZAB/0ka4ZjogiLMAu+DVNKInHjSQrjgiZjkkIRGNlQY0Qg6W79+PUF2GMtw
raxYsSIXRirMeYbZcTsEkPgyWmCgAMXtnDMgzLRp01RaFDTC9hI1C9uKR9EXMz0nTnxX8JUSpZs+
CgkC/IIQi/T555+HRN8QqimHxhAuulQWAk4jAB3DfRHfPLzyuCClhgnOwpSGNQqjEuyGNBcQMQ4A
sWGZ5PmkwsDMhGkMjoPVDK6EoQ1qAyMjgSHGJqjQwoULsaORRYR7ieHiU2gapAmXRSbiLBHzGbez
jYE0MSCMiQEp4GiCEBFsyJAhmK4irWa4EUKISAgJLBxNE/NFphE8FSGJcCjmxW4FWUNgk3eRUDLs
WcSacbSFjnA3iJWZy4xPo7kdIoZTIs6K3bt3RzAoJMm1aCHcDBKHhOQGwa0RaWlnWFgnE0FCSWYC
KaNb+/bttR9z+nH14PhyaPTgoqRKJKgZ50WiZqnC32vzKkOj11Yk6fKwIyJiIunDakAh4D4CHCKx
Q8brzP2pNWN6BDBaUUsa2xkZFOE4pO+AYpDYEA6FYQvmhV2Au0xJMlYNVoVHH/YprEVkP8B1ELqE
IyI+fmZw2Fm3bt3YouAAae7FgMUt5PrgdjJssJvF4Qd7HHSGKbBeYVljXogVKR8xsTEOFigCxyZM
mIA/pC0zDpB8E9rekrAzeBy0iJNqnihiGOkJaeratatJ5IgYiI21Dg5oMo3A4LjFlANAcUbjdhox
lmElJNQOdomEuKDwlPKVC4sknQg7LnglavIi9YcxFNIIeeR28p/AZyMppC2wLgKPAJln8Acm403g
NZWCN0WA7wS+SEXNbgpUSDqImoVkoaWmEAgAAmzU2Sob40gA1AmMCmmi/3gbixnIdEtzb4yYQNDg
dwm64jN1JH1jaoZFcsO/uMZqRk5+7GhcQwDTyGY6p2nM8K09ZuSnCB8LSpG36FoICIFAIsBBENmE
8KnWd0Ig1zerSnE42atXLzk0ZhU39RcCQsB9BFTXzH3MQzsjzAuPRI4CIlOdhBYNKS4EhIBzCOAm
jVs1btvpj4Ccm1QjexaBnj174vghhwrPLlDiguFsYw6BEx9KIwiB1CIgapZa/MM2O7k7cE3E1yh2
xXGtJILM9pyM/Ub1DBsC2Ec4FU9jtw0bCNLXIMBBEHUSxcv0PBgEIGVk9+WpECBBRYBgClPNJ6gK
Sq/wIIBDIw75cmgMz4r7TlPC00gMIkOb7xbOfYEp4sDZOHGR7k+tGYWAEBACQiCFCFBPh+D0FAqg
qYVAshCg8hTJFshPnqwBNY4QSC4CPJyUQiOjfnKH1WjBQ4DMNuQy1aMSvJWVRkJACAiB6Aiorll0
fPRp4BGIL9FE4GGRgk4gIGrmBKqBHFN1zQK5rPEphQMbyVqpM5JgaqP4ZtddXkNgwYIF2NPxafSa
YJInWQjkzZuX/NLJGk3jCAFfIAAdO3v2LIG0VapUmTp1qi9klpABQEAOjQFYRHdUwGrWunVrWc3c
Qdvjs5ChkWog+IQoQ6PHV8od8SiRibczNVncmU6zuI9Avnz5KI3q/ryaUQgkHQFOFAk3i55Rlk/J
dk5t34ceeoiyxRSQgqMlXRINKAQyRIDa01OmTJHPbYbgqDESAcr5tW3blt14ZKOuw4mA6pqFc90z
01p1zTJDJjDtVLSkvmpg1JEiYUaAJ5l6HxkeNZDbav/+/VQKzpkzZ44cOTiOpvaxsp+F+WmR7kLA
ywhwJE6NdVIoe1lIyeYOAqJm7uDsl1lEzfyyUpJTCAgBkudXqFBh/PjxNhQ4LmKnwGWxdOnSuXPn
rlWr1urVq8lCbHfQhRAQAkJACAgBLyMgh0Yvr477ssmh0X3MNaMQEALxIRBZ14ySH5CyJk2a3HXX
XT/60Y/uu+8+DppGjhw5ZsyYESNGDP3f16BBg/r16/e/7/T/QsBZBIYNGzZq1KjIJ9DZ+TS6TxDA
s5o8DzixxPfVp7uCjQBpQKZPn3706FGlAQn2Qseo3ZIlS4hFldtPjHD5sRtGhFOnTvlRcsksBNIg
ADWrVKkSyT1oh5px0kj26erVq9euXZvgMv7lOvJV7b8v6kzVqFEjsl3XQsAJBHjMSpUqde+99xYs
WPCll15yYgqN6VME+Cpq1qwZWRntMrJ8fe3evfujjz5K8y2nt0JACAgBIRBsBMjQqLpmwV7i8Gh3
4cIFdr9Zzbio5PnheUJSrqmS56d8CfwigDI0+mWlJKcQEAJCILkIKHl+cvHUaClEAGcPDpkVOJ/C
JdDU0REw1Exp96KjpE9BwNQ1U/J8PQwgwPkhaWHkwKaHwSBAoukvvvjCtrALluAhoJLTwVtTaSQE
hIA3EYCaVa1addmyZd4UT1J5BwGVnPbOWqRcEpIPEzdNPQVSDadcGAmQcgTINf36668TgZhySSSA
QwiQtm7GjBkODa5hhYAQEAJCwEYAakZUkaxmNiC6yAyBjRs3EiorFp8ZPqFqJ/CQMNWVK1eq5HSo
1j0zZRs3btyrV6/oJVwzu1ftvkCgXr16VOD1hagSUghER+DGjRsbNmw4cuRI9G76VAikCgHOOQ8f
PkxQZKoE0Lx+QWDv3r1kl9yyZYtfBJacziGgumbOYevHkVXXzI+rliWZ8WGWw2qWEFNnzyKQvq6Z
Z0WVYEJACAiBKAjwu0zwrH6do0AUno+gZmXKlCGftqxm4Vn0KJri3dqnTx9ZzaJApI+EgBDwCAKR
dc08IpLEEAJCQAgIASGQCAKffvpphQoV1q5dK2qWCIyBubd58+YDBgwQNQvMgkoRIRBgBETNAry4
wVCNH9N33nmHM/BgqCMthIAQcAEBsn9Qjpzkw7KiuoC296c4ceIEyahVf9z7KxW3hJ07d5Y3e9zo
6UZPIcDRYvny5ceNG+cpqSSMELARUIZGGwpdREfg0KFDlGgk4ix6N30qBISAEBACAUMgZ86c06dP
D5hSUiecCFy9erV379445IdTfWntfQQMNVOxKu+vVMolJEMjbkvK0JjyhZAAQkAICAGXEVBdM5cB
13RCQAiEFgGo2YsvvihqFtoHIHbFVdcsdqwC35Ni09u3byeFvhwaA7/WsSiIV/zRo0f/9a9/xdJZ
ffyIgKiZH1dNMgsBIeBHBN59990qVaq88cYbfhReMruJgKiZm2h7fC6ToXHVqlVKA+LxlXJHPOqa
KUOjO1CnahY5NKYKec3rBAIqBuEEqhozWQgcP368Y8eOmzZtStaAGieoCBiHRrH4oK5vlvRSXbMs
wRX4zqprFvglnjJlysGDBwOvphQMAwKfffYZGWXXrVsXBmWlox8RwB+Jc29l1vLj2rks8+nTp/kq
O3bsmMvzajoPIiBq5sFFSaFIomYpBF9TCwEhkCUElKExS3CpsxAQAkJACHgfAaLMSpYsuWLFCjk0
en+xXJCwUaNGvXr14izahbk0hRAQAkIgEQRU1ywR9HSvEBACQkAIeBABKpq1b99+27ZtyvzgwdVx
X6SBAwdOmzbtiy++cH9qzegOAh9//PG1a9fcmUuzCAFHERA1cxReDZ44AtQJHTt2LPm1Eh9KIwQb
gRs3bly8eFG7r2Cvcoza4Qj91VdfyRE6RrgC342MnbKfBnuVixcvvmjRomDrKO1CgoAcGkOy0P5V
88CBAxUrVlRuB/+uoGuSb926tWvXroqcdQ1wTSQEhIAQ8AgCefLkmTlzpkeEkRhCIBEEOGcmrRn1
PhIZRPcKAecQUF0z57AN2MhvvfVWy5YtVQIvYMsqdYSAEBACN0VAdc1uCpE6CAEhIASSgoCoWVJg
DMMgqmsWhlWOUUcSPgwaNGj//v2KNYsRsWB3mzhx4tKlSzmLDraaYdYub968spqF+QGQ7kJACLiG
ACWn5dDoGtq+ngirWevWrWU18/UiJkt4MjSWKFFCGRqThaffx2nYsGHPnj2VodHv6xhF/meffXbe
vHlROugjIeAXBDhRJM3CpUuX/CKw5AwbAmyx5s+ff+TIkbApLn2zisDmzZs7dOiwatWqrN6o/sFD
QHXNgremiWikumaJoOeLe6lrKerti5WSkDdF4MKFC3Xr1p0+ffpNe6qDEBACQsDLCJCbESKv/Mle
XiPXZBM1cw1qX0wkauaLZZKQQkAIgADJ8/EWmzBhgtAQAkJACAgBIRAMBCDpJNOWQ2MwVjNxLRo0
aCCHxsRh1AhCQAi4gIDqmrkAsqZIBAF8bq9cuUKJokQG0b1CQAiECoEvv/xywYIF77///vfffx8q
xaVshgisWbNm+/btVDfL8FM1BgCBhQsXHjt2LACKSAUhIKuZngGPI3D48GF8UVSsyuPL5AXxzp49
u2XLlg8++MALwkgGISAEhIAQcA0B6prNmDHDtek0kRBwDoGLFy/Wq1dPGUcTQfi77777+OOPidqL
fRAsQSCfpVtiHzxgPcnQWLVq1WXLlgVML6mTdARMXTM9KkkHVgMKASEgBDyOgOqaeXyBJF7sCODs
AUEIW+D8N998s2vXrg0bNsQOVJSely9fbtWq1fDhw6P0SfPRuXPn8Ht/9dVX07Tbb+F6b7zxhrgb
gKiumf1U6CI6AqprFh2fUH3KiRk+IapjFapFj6IsZ6Gk7/v3v/8dpY8+8jUComa+Xj4JLwT4ioYW
vfjii0mBgtIDTZo0ee2112IfDW4IO6NsQWa34JeVP3/+gwcPZtYhPO1QM1nNwrPciWgqapYIegG7
l3OtOnXqbNy48dtvvw2YalInDgQ6duw4cuTIsJ1CxwGUf2/JlSuXHBr9u3ySPKgIYAE8c+ZMjx49
GjduTCUsrE579+5FWTJI4OPEz3SjRo3Wrl1LIDBpu3Lnzv3II49MnTo1Eg38DA8dOtS2bdtq1aq9
/vrrfI1z9Eog+bhx44h1atq0KYOYoCfmoogG/I5CluPHj69fv/7gwYPpzzUd2rdvT8+lS5dCwRj/
888/X7RoEUywcuXKU6ZMoRvckD0DZrurV68SnjxnzpyJEyfWqFGjX79+xMt8+OGHqHD33XdTP/fU
qVOU9GrXrl2pUqW6dOly9OjRSIHDcA0/rVWr1sqVK8OgrHRMBAH+plq0aCGHxkQwDMy9ZGgsXbo0
Re7Ml3Bg9JIi8SHAT2rv3r35LY7vdt3lfQRatmzJT4D35ZSEQuCmCJDGCgpz4MCBm/b0fgdITYkS
JQoXLszhWKVKle65556xY8ei4LRp05544okRI0Zg2IKRQY7279/Pr3a+fPmoUWvrBQt75513sIm3
adNm8uTJJF4mCo/bCWC56667ChUqNGzYMP72s2fPvmfPHmxeRYoUKVmyJAyuQoUK999/P5OeP3/+
oYceevTRR/v37//KK68wFHPxWzBp0iSuuR0ZuKtr165kKuAQj4mQmc0kt/Mv4j333HMY4PBm7Nu3
78MPPzxq1Cjmql27NpJQ5h5uWLRoUeinLXMYLnBJgp/CYcOgrHRMBAG+x/iT37FjRyKD6N5gIKC6
ZsFYx2RpobpmyUJS4wgBIeA0Ap9++inMAquQ0xM5PT6mMWxPTz75JL/IzIVJK2/evGPGjIFDwXdM
nhMq0qIpjoLQpT59+mDYipSKzT90CQMNjdA0tnk5cuTARWrr1q3ZsmWDoNEOaXr22WehY3Pnzn36
6adxZcR3nblgeTAvPs2ZM2evXr3oSZjDgAED8MTbvXs39jJIFo0Y7BYvXgzLY7Tu3btjXEM8LGJ0
Q7br169T+xvuhivOzp07ixUrhr1s3759yE/hOc5+mQ55WDKG0ksICAEhIAQyQ4AfgjJlyshqlhk+
YWvnzJMffVnNwrbu0lcI+BGBwNQ1w0UQV8aXXnoJVsVCwG4gWRAi3OF+//vfYwKDH1WpUuX555/H
cAaZgkAZFmavGpQHp0HoGN6M9MSsht0Kj0cO4WFzGG7oyc99uXLlBg4cyO3Vq1c398KYmjVrhs0L
avbUU0+xGaDdVNXBrIZrJTsE+J3pDFPD8gVVNNQMq1mnTp2ghHyKeYjCHHSGr23btg3zH8kJUQQb
3F//+lfYH1Y2jGhmHP0rBISAEBACmSHATxtHXriXK9YsM4hC1U50wKBBgxRrFuBF55ycV4AVlGrh
QSAw1IzTMOhS3bp1zd8mPAtuBTV777337rvvviFDhvAbvX79+jfffBPWQ05FEiSmp2bQIkgZfehJ
IBgmKsK+cHrEUmaKJRknGVgYXuv0NM8JqZ8aNGjA176hZsSO0Y4VDFJGcBmRLzA+0nrQCG1kcKxm
S5YssalZ586dbWpGjdRIakYGDNTBXka8G8FosEJMgWao8DyiWDNZMuhqeFSWpvEh8J8fZv00x4dd
4O4icJivTX4X9EgEbm3jUYhAAMIPVX88Hux8cg+JshVr5pO1kpg3QQAKU7Zs2WA4NJJqA5vX8ePH
4TIQMQK48Dwk/gsqBJMCCOPQSDgwJjaomW32MhjRSBQYtipOWflZJ4UIVAiXQqhQGmpGyBh+icSv
nThxgp7k4ScAjUaoGQKQRYQB+SHAyNW8eXPyimCGMwJgX4MkwtTwliSFCA6NWM3SUzPGwcr2wgsv
EPu2fft2eB9iMCZMDe9T4teMwCH5F9MhLJiIyJDoKzXjRoBHhT95xZrFDaBuFAJCQAj4FAFlaPTp
wkns9AjAR4YOHYopJ/1HvmvBFoZj4WOPPYb7ImQK6gTlJLyLTIk0QsTIDUKAGMriOoinIo6OuCba
anKeduzYMagZsV2k3SBsjXyJ3M45DHfZDo0MTlgZfoYkVCTjB7kZacGYRYZGaCCTPv744xAovBYZ
inwjeDbCGfnSqFixIka0ggULQutIm2/SgHDRoUOHl19+GTHoiaGNEDMsRPhhogK3YLwjCSR+krA8
3CNxy8Qb05Y5DBcmef7y5cvDoKx0TAQBZWhMBD3dKwSEgBDwLwIkW5s1a5Z/5ZfkQiCQCEC4YEyw
Iexc+DHCj8jNiKYYtnhLWnvomJ3eEEcXcnEQ+RUJBa4veHiSTgRPSPMRLbDXw4cPw9HoiUEN+gYF
45p2/BKxYZHQHjsXL3gWHAoiBo9gEMPm6IkVDwHI+kiImcl+Twud8ZbkApGMVHBDzGp0oJHpmHTT
pk1XrlxBKRwdcZjkX1wyIgUOwzXUDEIqahaGtU5QR9U1SxDAIN3OzwF+6bglyIctSMsaty44omBV
V+Bh3AB6/0ZRM++vkSQMGwLGsZD0hjgiQnBINY8lC9uTmzjAsLC1BcME6SZu0efi9xRroxwao6Ok
T0FA1EyPgY0AccG4GVAPkZMuu1EXoUWAqqZEoytDY4AfADk0BnhxQ6gav1zwmgAoDiOjmhguhbgC
konRfTsLjogE7r399tsBANM7KhDLT8oUO8WldwSTJF5DQA6NXluRFMpjUjatXr1a1CyFq+CdqVXX
zDtr4ZAknMOwW3BocA0rBNxEAH850lCQRdDNSZ2by/gE4sSSqp9j/CXkP5P09cWtlFfSh9WAAUMA
T2Ny8hj34ICpJnWyioCoWVYRC3Z/UbNgr6+0EwJBQoAMjcRkBSBDY5AWRboIASEgBIRAIggQlotD
44oVK1J1TJeI8Lo36QiQTQuHRiLEkz6yBhQCQkAIJBeBwNQ1Sy4sGk0ICAEhIAT8iwD1ELt164YV
NRju+v5dCI9ITnUbcnORBtkj8kiMpCNw8uRJ3MCSPqwGFALuIyBq5j7mmjFLCFAsgBrfbLGydJc6
hxCB69evkyhVB+MhXPoMVYaUyRE6Q2RC2MjDoFiDYK87GQYoPxRsHaVdSBAwDo0klg+JvlLTdwiQ
oZH6bsrQ6LuFc19gqmaQCGjNmjXuT60ZhYAQEAJCIIUIkB+b+kQpFEBTC4FkIUD9rB07dtgVuJI1
rMYRAslCQHXNkoVk4MehUmGrVq3cT80aeGB9quB3333nU8kldtIRwGQmE2rSUfXUgKpr5qnlkDBC
QAgEGAFRswAvbnJVU12z5OLp69GINevZs+eePXsUa+brdUyW8KNGjcLbTbFmycLTg+PIaubBRZFI
7iDA0RPVu3AZ4ofPnRk1S5AQ4Jdx//7927Zt++qrr2LUSyWnYwRK3bCatW7dWlYzPQkgQIbGEiVK
KEOjHgaDgDI0Bv5JKFq06MKFCwOvphQMAwLU4Tpx4gQRZ/9fe2ceJFV19mFNKvGLiWYpU8aKGCOG
UlmEjBSKC4jIvu/oiAIDpSNMEBEKiAzbgKDITkYEZtiRRXRA9jCEsG9mWIZFdpFCBmRxWIwx9T0f
t76urpmhp7d7+9x7f/3HVE/3uee85zl9u8/vvO95T6mdZYs9iqxLly733ntv5cqVOTus1EtUQASK
ECCB0sSJEytUqPDcc8+NHz8+nAMiyVTDZJvkS0Wq0r8iUIQAp71zSuOyZcuKvK5/fUhA55r5cNBD
dFnnmoWA4423mMfKK+qNoVQvzp492759+6lTp94MBdoNN8egQYMqVar005/+9JZbbvnxj39cpUoV
fGc3u0Svi0AIAsQXsbcRXVarVq3y5cvz8Vu0aBGfwxCX6C0RCIcArli0/9WrV8MprDLeJiBp5u3x
jbR3kmaRElN5ERCBRBHAJdGiRYvMzMwiBrCB+vjx41OmTKlbt+6vf/1rFFnggTT785//LGlWhJj+
jZQAE+ktW7aQUi8pKYlPVM+ePclIo3l1pBhVXgREoDgBpJkCGotj8e0rCmj07dCr4yLgOgJFzjUj
hRGnAhER1LFjx/vuuy8gx4KfIM3Ybnn+/HnXdVYGm0mgsLCQBA6vvfZa1apVGzZsSMQjZ5kFsmmR
RJRZFvG0Zhovq0RABAwkwCIPEfgsMOo0KwNHx3mTcnNzd+zY8d133znftFp0hgDRX3l5ec60pVZE
wFYCSDMOjeJcM2bCTIAHDBjw0EMPBQuxEp/feeednO7HmqQeIhApgQYNGtSvXz/4KuRYs2bN+Pvo
o4/+5Cc/ufXWW3/729+2bdt27dq1fCz37NnDQsHSpUttvRFUuQcIoOhXrFhx4MABD/RFXRABERAB
EQifABttsrOzwy+vkiJgLIFz584Rgz1r1iwsJOkiu36Sk5PvvvvuEhWZ9SIzZzKBkJf4fT1EIHIC
o0ePDr6If8eNGzdhwgSWBYieve222+64444aNWq89957+/fvR5qRobF169aLFy829iaSYYYQWL16
9euvv66PiiHDITNEQAREwDECOtfMMdThN0TQQn5+fqkZuZnpkXDg2LFj4dccoiSNkhOGCMAQZQx/
CyDYH8yNTsGHCXPNmjVvv/324hrNCmhE0xneNZnnCgJkBSH74qhRo9BlBDSy44w8e8EfSJ1r5opx
NMFInWtmwigYYgPbpUkjrEBoQ4Yj4WZ89dVXTFoU3ZrwgbDPAEkz+9hGVzNfwpyU9PLLL5eaORMl
Qr7uF198MS7K4tKlSyXm0AjRCwwghnDhwoXh5KsPUY8Db7HHh9jsPn36VKxYEU9ZQKMpDYgD8D3f
hDVxmjx5MnGM5cqVa9my5ezZs0vM0yivmec/DPHqoKRZvEh6oB5+ZwmKJsCVJMMe6I66ECOBHj16
vPvuu5cvX46xHl1uLAEOdcrKyjLWPB8ahkRq06YNU7tw+s6C/Ntvv002+HAKhy5Du7Vr1+aU+dDF
gt9lRspUkzQa27ZtC37d2OdoSWTskiVLXnrpJeIYEWg/+tGPuAWUodHYITPZMD5OJJDJyclh+9jD
Dz/MjsWRI0fiNeO+uJnZ7DV75ZVXtNfsZnz0eoAAAY2pqakff/xx4BU98S0Btk43atSIXy5lfvDt
ZyC44xzJOnjwYOZswS/quZcIcKglITde6pGr+8Kkjl/kp556itAFgqP4Kp4/f/6kSZPQX5aLil1R
+LaGDh166tQpeopHe/PmzdWrVz99+jT/cvn69evZb/XCCy8g7viXk3EyMjIQULxLDUeOHBk2bBhL
cAT+sUeGJAbsfKEkX/iswNSpU4edMjiY2BpD5BWX4LlbcOPBc5JEcTo55Zs0acKKDRqnoKCAycPv
fvc7pqac7sSFzDmZeaakpPCE5rjKvgf1F3kAbfr06QCh0SJv8W+wJZABBQlDOHL9mWee0ZHTwXD0
PEwCfP6JXSRbflpaGvddOOFG3CPEooRTMkwbVMyrBHbv3k2SLresenl1FAzpF9KscePG/KpKmhky
Iok1Q+eaJZa/WvcbAbxgb775Jpm36TjP33jjDdK7sW+FM7nQUzxp1aoV6oMgRnILMMejGPku8Ft9
+umnyA0CHoinwomG6GDG2K9fP1J5oz6YOlKSb3VmkmyBQZfxCqF9SC1UGP6jefPmUdKSZizFkNhw
zpw5XIL+4gQNlBfGUPj+++/n1LAPPvgA8ditWzdK4iYoW7YsUhHHExKPOlFtI0aM4Gin4ueLUWEs
j4Daoqc8kK5Ed9ApHsx4eRBXSUQZ6pJWrFesdylGYS5ByVqVBMzgdTQavQu8oiciECYBPjzclcya
wiyvYiIgAiIQBQG+ZPhpk9csCnSevEReM08OqzplLAH0EfoLdYOFlkxDYeHPQmKQ9q1atWoU4C3k
GJsELe2DY4u9LbjVeAsvGCqJAsgQjkFBYZ04cWLmzJkoJuQYa/W1atUaM2YMUoU0hqzKUpKILFrs
27dvQJrRXKVKlRBi1ruvvvoq3wMonQ0bNliBWCgyWiFnOH40ArTwOuGV47fjueeeY7sNV2ES671Y
GC+HO3oKVcWDfoGCJoo8rALMk3EpIkt5l8K8WKQY/9L3gEYr/q5eEQEREAEREAGjCLBxlfXYVatW
8ftllGEyJiEEWMAn6kl7zRIC35lGmegyU3WmLbVSKgE0Fw4p3FKURJr16tWL+ECeI4LQR2XKlGEv
MCGFPB588EHkmPUWji0cbfiM2PDC5VYZpBPnLG/ZsoXXH3nkEU5eJkaRs5bYC4NmwcmFvOIUsKef
fhrHHHGSN5NmuM67du1KQ4g7nHc0jQSj9aZNmyLBdu3aRYtE3ZBSkjT1eOjYKEcZtq2VL1+etrgw
9gcG8ynlVwmFyI8UXjk2i7Vv375du3Z0NvBAl9111130kXhOzOB1CvCgJK+ACGlJPVSCv8PSbiXK
t9gNVg0iUCIBPr04uMneU+K7elEEAgT4guIbj7+BV/TEtwT42WLx01qY9S0EdTxAgN8R9qroyyEA
xHtPmNUzafdev1zaI+TPk08+yeYy7LekWadOnXiONEMfESWIL4zxInBx5cqVBw8etN5CvpGxB58R
Egw1x1tWmTVr1nD/ci0FECb4y4iH5BK+5J944gkE1CeffMKRpigXK/TRCmhkKQYvG3vcKMk3AAIH
dUY9RDCiwgin3LlzJ0GDhL4HSzOObUIJsq9t+Y0HNrCHMS57avj+sXQZQGiRXv/pT38iugOrij8I
1OQwIFgVeYuYTCI5+UtV1BOszuimHiLgDAH8y/i4ldvBGdqubmX79u0sjGsnuKsHUcaLgAiIQBQE
mO3ryOkouNl0CdIDKWRlXAyWZiyf4rH64x//aKX7QDHhtEL+YAYraagk9nzxhAQdONd4Ea8QieMo
g6SynqPaGGsOMEXp4D7DU0YyeXxGR48eRelY8ZCWNENPEaM4fPhwSuIUY/Maoox9bY8//jgHhFE5
G9BwWhEGicChAElI8M0h9/CU9e/fnwL0goBGdFCJwYcUiOiBkXQBGhiGV5EQSvbWMW+JqBL0JvlP
8J1RD/oXuWr5i6mcR0RVqbAIRE1A55pFjc5vF5IPii9eHTntt3FXf0VABERA55oZ9RlAL+CQwreF
XkBE4AtDBFkWokqSk5ORV2z+YtNZhw4drEhjZBrp3zkKDSW1adOmChUqNGvWjHd5gpqzrkVM4Qhj
6xlKjVe4hMhDAg5RT7ifeM6ONhIbIs0QX9jAXyIDEXq4yagHPxS7xtiPRkQlB66hBHlwOfvRCIxE
mrGFDcXEJmUEIAGEBBPyucLBFztbOFghiJYuwzOIzw4I9DeiyrF/4MCByF4wQgN1Bl4EL5VLmkVE
UoVjISBpFgs9X12rc818NdyhO8tq56JFi0iDzK986JJ61w8EWJZnsheXpW8/4HJjH4nymjFjhhst
96TNyAQ2baFrjh07xnP+Bm9LwddDCCJJQlA9yAoIWB6xevXqWTLNuuTDDz9E36GVAoj4PqcearZe
oRhOrmnTppEhBK8ZsgUXGwlDCEq0sj5S+bp164hdxCnG6/wicCFNEIhF5bzILwWRNvjdMIBq2cOF
3uH53r17ycJBMhDSHgZaj+UJlmOM5epCUaIEyUZSpUoV/kZUrSXNiCWj43gekahoPSusERoRVaXC
IhA1AQIa2eCpgMaoAfrnQkkz/4x1qT3lZ4swFbapajZeKis/FGAjEkvNrDD7obP+7CPuEgU0GjX0
yBB2fnHfhWMVQYxsRps7d244hd1YBmnGjxHdJJMkshGRyAY6En1EJ82I8ESKHj9+HO9bwHEmaebG
D4ZLbebjR6gwC54utV9mO0aALzoFNDpG2/CGkGZEquhcM8OHyTHz2Eo/ZMgQFpwda1ENOUyApTnc
Ig43quZCEEApoEHI5kHoXYhivIVsIQE+h4ZbHrTQhV36Ln3Et4XDDpcZPsR9+/bhMSQ4MzppRvQm
Pj4SiUAYxxm+P9DRhEvhyGwREAGvEmD5CB+rFcbg1T6qX2ESkDQLE5RPikma+WSg1U3TCLAHKhzJ
YPhWKcxDB+EBxK+HwwuHYKScqYGrWB0iCpEamKsQDMb2t+ikGZGf1IA6YzmioKAAZxy6jyYitUrl
RUAEREAERMAZAvz88eOlgEZnaJvfigIazR8jWSgCxhJA9bB/jdT95C25//77iZ4l8cioUaNIPsYy
YJjaE2mGh4vVY/L8k5iR3CNRSzPynGzdujUvLw8HHIvSKD5JM2M/PF41TAG0Xh1Z9UsEbCJA+D3n
kFqbu21qQtW6iADnKy1YsIDkAy6yWaZGRICMYcxRI7pEhUUgIgLMRQkdZIcXyUZI89ioUSOy35ct
Wxa9lpqaShrJjRs3kkWkxDoJOOT7B2l28uRJvF2kkZw1axZ5IKPzmpFJkgtJY4IDztpuJmlWIna9
aBMBsvEMGDAg0vyiNhmjak0mQEA7yZRu9sVosuWyTQREQAREIBYCZEdnrhtLDbpWBCIigFJDarFL
jijH7t27c4ZapUqVUFvPPvts7969cYqxXBC8vxV1RnlCEEn/iIgjb+TDDz8chTRLT0+nCSux5KFD
h3DbsRQpaRbR2KlwjASIp9WR0zEy9Mnla9eu7dmzJyeS+KS/6qYIiIAIiIBFAP8Fc13REIFEESCs
kWBFpFZmZibhjgQ9Eq/IyWUNGjQgBxFJPzgFgAJnzpxh2xqp7SxphkaLyGC0HtKsZs2a5L0hptHK
BGIladRes4hIqnAsBHSuWSz0fHUtGRrT0tI4LcVXvVZnb0aATMXhbAG42eV63UsE+DBwVpGXeqS+
FCHAEVo616wIE/2bQAIIJcJ4li1bNnLkSI6uxkHGSdl8SkkdjE9twoQJbFUrV65cFNKMbCQ1atRg
wkNUJNvWkHuEDLGRTdIsgcPtt6aRZq1bt9Z822/jHkV/da5ZFNC8eglnx/DzxwKmJuReHeKI+jVi
xAjWqMljFtFVKuwiAjgp5DVz0Xj5zVS+fHbu3Ml+NI74IfTx97///d13333PPfcgryJCgdcsIM22
bNmCNDt16hRxkkgzfuyUmSEimCocNQECGlu1aqUjp6MG6J8LrXPNpOL9M+IhekqGxvr16ytDYwhE
vnorJSWF+QxhP77qta8626RJk0WLFvmqy+qsiwjg0mI7GMIKJxceh+XLlw8aNOiBBx6I9NBeSTMX
DbqHTWU1gBwg5LTxcB/VtbgQIDCAGOyVK1fGpTZV4moCOtfM1cMXd+N1rlnckZpWIVNWwlZNs0r2
iIBFgBwgOM44b/ro0aNIM5J4ZGVlEeUYS0CjvGb6dImACBhOgK8+Etvq19nwYXLGPEkzZzi7pRVJ
M7eMlOwUAU8SKCLN1q1bR3Aju88kzTw53OqUCIiACIhAEQJIM/Jika5TUr0IGX/+26VLF8KHcKz4
s/vqtQiIQGIJSJollr9ajy8BDukjyw35Z+JbrWoTARHwMAGi+nNzc4nqV5JGD49y+F0j8oezhJgd
hX+JSrqLwJgxY7Zv3+4um2WtfwhImvlnrP3Q07y8vOTkZM5e90Nn1cdYCHD24uLFizk6JJZKdK0I
iIAIiIDrCFSuXJnNO64zWwb7hICkmU8G2ifdtJLnM+X2SX/VzagJrF69OjU1Vck8owaoC0VABETA
pQR0rplLB84nZkua+WSgfdJNpBmn9Skjuk+GO5Zu6lyzWOh57Fp+B/Pz88nvqnNePDay0XXn8OHD
X375pY5kjY6eK66SNHPFMPnWSEkz3w69JzvOuWYcOS2vmScHN76dkjSLL09X13bmzJkWLVosW7ZM
aUBcPY7xMp5jXocPH640IPHiaWA9Cmg0cFBkUoCApFkAhZ54gAB7t0muxfF8HuiLumArAQU02orX
XZWTobFRo0ZLly6VNHPXwNlkbdeuXQcPHixpZhNeE6rNyMjYvHmzCZbIBhEoTkDSrDgTveJeAnye
iUoiT6N7uyDLnSGwf//+OXPm4GZ1pjm1YjIBnWtm8ug4b5vONXOeuVoUAREIEJA0C6DQExEQAREQ
AR8SOH36tM418+G436zLhF4MHDhQXrOb8dHrIiACthKQNLMVryoXAREQAREwnEBBQUHnzp3ZfsgP
ouGmyjwHCPTr12/cuHHffvutA22piYQQYHAVvZwQ8mo0HAKSZuFQUhm3ECAwae7cufv27XOLwbIz
UQS+//57Al81FU8Uf6Pa5aTp8+fPX7t2zSirZEyiCFy4cIGpu9J1Joq/A+2SLkyZnB3grCaiIyBp
Fh03XWUmAbYONW/eXIdVmTk6RlnFHvChQ4euWbPGKKtkjAiIgAiIgN0EkpKSsrOz7W5F9YtAdAQk
zaLjpqvMJKBzzcwcFwOtQpSRIlvnLBg4NDJJBERABGwloHPNbMWrymMkIGkWI0BdbhQBSTOjhsNk
Y3Sumcmj47BthYWFM2bMOHjwoE4Zdpi8mc2xYpObm3v9+nUzzZNVsROoWrUqt3zs9agGEbCDgKSZ
HVRVZ6II7Nq1SwGNiYLvrnbxmqWlpWm7gbtGzSZrydBYt27dTz/9VJkBbCLsrmo7deqUnp5+8eJF
d5kta8MnIK9Z+KxU0nkCkmbOM1eL9hE4ceLE2LFjd+zYYV8TqtkbBCyvmaSZN0Yzxl7oXLMYAXrs
cp1r5rEBLd6drVu3siBT/HW9IgImEJA0M2EUZIMIiIDDBMjId+DAga+//trhdtWcgQQkzQwclASa
JGmWQPhqWgREQNJMnwEREAEREAE/E1BAo59Hv3jfFdBYnIleEQERcIyApJljqNWQAwQ4iYaPtPby
O4BaTYiAZwhwiNXEiRP37Nmjrw7PjGksHZk9e/by5ct1zl0sDA2/dtOmTadOnTLcSJnnWwKSZr4d
ek92nBxrb7311tq1az3ZO3UqjgTOnTvH0eRnzpyJY52qSgREQAREwHwC1apVmzlzpvl2ykJ/EpA0
8+e4e7XXHDndsmVLHTnt1fGNY79IA9KjRw+S8sWxTlUlAiIgAiJgPgElzzd/jPxsoaSZn0ffe33X
uWbeG1ObeqTk+TaBdWO1BEJztNn333/vRuNlc9wJXLlyRdGMcadqVIVKnm/UcMiYIgQkzYoA0b+u
JoA0a926tTKiu3oQnTFeR047w9kVrZCus1u3buvXr+cH0RUGy0hbCQwaNGjy5MmodVtbUeUJJJCU
lJSdnZ1AA9S0CIQgIGkWAo7ech0BS5otXrzYdZbLYIcJ4DVjNq6PisPYzWyODI3169fPycnRkdNm
DpDDVqWkpAwcOFBHTjuM3cnm2rZtq2h2J4GrrYgISJpFhEuFDSdw6dKl7du3c0qR4XbKvIQT2Lx5
c0ZGBr6zhFsiAxJOQOeaJXwIjDJA55oZNRx2GHP9+nWlY7UDrOqMCwFJs7hgVCUiIALuIsDvMt9+
+nV216jZZK2kmU1gXVqtpJlLB05mi4A3CEiaeWMc1QsREAEREIHoCEiaRcfNq1chzYYOHUoMhlc7
qH6JgAiYTEDSzOTRkW2REuDoWA6rOnv2bKQXqrwIiIBvCbDFbNu2bV9//TWpGn0LQR0PENi9e/cX
X3yhjJ0BIN57MmTIkI0bN3qvX+qRNwhImnljHNULiwBpQNq1a6ftvfo8lEogPz9/9uzZu3btKrWk
CoiACIiACHiJQOXKlbOysrzUI/XFSwQkzbw0muqLMjTqMxAmgdWrV6empup08jBxqZgIiIAIeIaA
zjXzzFB6siOSZp4cVt92CmnWpk0bnWvm2w9A+B3XuWbhs/J8SQIad+7cSSC0Aho9P9bhdHDv3r1H
jhxRQGM4rFxaRtLMpQPnE7MlzXwy0D7p5ueff96qVSu5Qnwy3LF0U9IsFnoeu5Y0IE2aNFm6dKnO
NfPYyEbXnVdffVVpQKJD55arFNDolpHyp52SZv4cd6/2mg1Er7/++qpVq7zaQfUrXgQU0Bgvkh6o
RxkaPTCIceyCkufHEaaZVY0bN27Hjh1m2iarRABpduXKlYKCgmPHjuXl5f3jH/+YOnXqQw89FGnu
GtLMDhw4sEaNGmvWrNmyZcuBAwe++uqrCxcuXLt2TScH6WPmGAE+bHyetfTtGHD3NkQGtsWLFxO5
5N4uyPJ4EZA0ixdJb9QjaeaNcVQvRMClBIKlGQlj//nPf5K15pFHHiGTcEQ9QpqRjLRmzZq5ublb
t249ePCgpFlEAFVYBAwksH//fgL/uJcNtE0miUC8CJw+fbp+/fo5OTla1YkXUlfXk5KSwlLzxYsX
Xd0LGS8CIuBSApY0O3fu3PHjx1lA3rBhw/Tp0x944IGxY8euDXoguHisu/Gwnlt/A0WWLFny8ssv
16pVC78bbmKkGT92fLNdv35dXjOXfjZktjMEfvjhB7bIvfXWW9yDzrQYfiv40F955RVuar4ZmKsQ
BBj+tSopAm4hwC8g6Tr5nPOD6BabZad9BAYNGvTBBx9wSqZ9TajmxBIgVOzq1auJtUGti8DNCFjS
7Pz58ydPnmSfzubNmxcsWPDkk0/eddddv/zlL++4446f//znt99++89+9rP/ufG45ZZbbr31Vutf
/vLWL37xC0r+6le/+sMf/vDaa6/hd+OooMOHD3N8p6TZzbDrdZsInDp1asqUKYTm2lR/XKpFi33z
zTdkALOOxmb5goPYateujavayglGTOaJEye+/PJL4oFpkaxxPOFRWFjIrWot7DNtoLN4q4ubZBXm
d4fC1q8PFeL5otFAAjoWTLhDjx49atXA65ThgW1USBO0hTEs1BDbw5LMRx991LRp0w8//JDKKUCs
Mtdiv3sXXsBO363uFGeoV3xFgM8/N5R0ma8GPURn+fbjmyHwbRmipN5yKYHGjRsvWrTIpcbLbM8T
YPbFVxBzNmZubBDbvn07C+Oos8mTJ48aNSo9Pb13795/+ctfmJ7h4u/QoUOZMmWqV6/Ov127dmWZ
8Y033ujXr19GRsb48eNnzJjBDHP9+vVMjNm5xrTt8uXL8pp5/iNkVAdZFmjevLnJGRqZAc6bN4+b
qEKFCniZWZvFW92yZcvf/OY3PXr0OHToEFs1O3XqVOnGo3v37oQZcwlhxqx7UIybkft02bJlLVq0
SEpKev7556dNm8aNFhgFppfz58/nQg4R6NixI4st3JLcuRR+5plnRo8efebMGRYMubsff/xxGmnU
qBFnDfAKt/D7779v5Q/HCT548GBgIs24zfnL7c9yTd26dVeuXAneBg0aVKxYkTUc3OtcG2jdRU/w
A/L9RndcZLNMFQEREAERiJ0AP4j8rsVej2oQATsIsOiNNMO9xT5olvEJrCKoA4WFzpo4ceLIkSPx
7Pft27dXr149e/ZkvkeG4eTkZJ7zQLX99a9/RZcx30PKsa6+YsUKJpZ43/DBESLC0hPL79Y6vB3G
q04RKELA/HPNsBDxOGbMGATXwoULGzZsyC3z2Wef1atXD68Ze7vI28yNRpIK1klefPFFbj38Uwil
8uXLcyfu27eP/JMvvfQS9yaeNXQZhwXMnTs3sMCLNCP3FLqJTJXUgADp3Llz//79qYRFQgTdpEmT
uFXbt2/PX1TViBEjWGDZtGkTOqVPnz4s0VDVzJkzMQMPuOU14zuB5RquJb4RI1F83PWs51ADKpId
OkVGwRX/krCoW7duOgLPFYMlI0VABEQgjgR0rlkcYaqquBNAN1mBPayW4+pCVTFRZO7HLC47O5tZ
HLLrnXfeYSbGThMeKDWmcNaT4cOHv/vuu8wDCXOaM2cOgo4pHOKOlX8reor4KEmzuA+ZKgxBwHxp
tmfPHlxOKCOiBAkLtDzLiCCED+4wcgYifLiVrD6y4sG/JOLgBkQrsYUTNze+LS5HzSHfuONeeOEF
JFUgstGSZigmsvFQCeGdrVu3RrtZWq9Lly7oEW5YnGVpaWlsC8UGgh4JbhwwYADSjy2iSLPZs2ej
7Kydp/jHecKRT7je0GLYT4v471iH4SqWX/gCCTEixr6lc82MHRrnDWOdJDMzk8+2ewN0nYfm4Rb5
wsSfrmhnDw9x1apV5TXz8Pi6vWuWNGN+ZcU0skeMyS2Z81FnhC3xBYVAYyL3t7/9bcKECYQ84Urj
wRNUG79lrKKzwE4AFRFQJAZhNoi4I5sBczZrHwcTxcB6vttZyX7zCZgf0MgdQZAh2oo8qMQ0ssrB
qgjSrFmzZrjMuN2QQviwLNTcgJZSe++999BfOKO5VXGBPfjggwRDklPOehBVyLYy6xLq5w4lNpI4
Se5udBwNPf300+hBChMAOWzYMBZhcHXhvCtXrly1atW4wfGpYUlAmmEGSpDvAX68AtIMVx2hmLSC
44yQZoIhsZ94Zrzt5n8wiluI1wxxKq9ZcTI+fIUVCYJ1WRKxNnL6kIC6HEyApS2WoJWhMZiJx56z
p2DWrFke65S64xkC6CZruxlKiikimQdYXWezGL4zVvVZGGcKx0o+kVcsmDNRRI6x7QUtxgPPGhMb
tr0wyWFuyQo80VbM8fiZQ+jhMmM5ncolzTzzaTG/I2TGYLnA2DQgaCViCBFNzABZviBsmO1aOLbQ
YkgznGLcZWix5cuXg5rC+KwRRGwWI3yR+GGkGRfiQWvbti36jkVdfF7cd6yHBFb7LWnGljRaoRKW
UJBgVMjNiIeOhRceNMR9yuWERHLmBVHKeL2HDh2KNCOwmapQgjSBVQFpxtqL5TVjqxpucariHuen
De8bwZlunNCSXRYB69JoTPPvRHdZqHPN3DVedlvL0hNfjIFQBLubU/3OE2CyyqYb59tViyIQDgF0
EzMxpm0oKaZ5TBeZ/qHOmNfhgECgsXJO0BQeMWYy1o4Y5m8IMcKB0G5MGpkisqWF+R5r/qzGo8tY
wA+4zKhc0iycgVAZPxDgduDeIRkjcgyNhm8aWYTA4UarU6cOSxw7d+4kWT0xh9yA3GKk8iDOkPBg
5BibzlBSUCK2ELWFeuJf3FvEFvIXHWcBRJrh1KYGorN4hVhEKmFPKFqMNRbCJkkAggecHWr8y/2O
y4xjL6gTGUi1LMLwOhbiYkOasQ7DVjVsZpWGhvDBoWVw+dE6s1lSBmEtLnUadd3w8R2Ffx+B6TrL
ZXDcCUiaxR2pqyuUNHP18Ml4EfAAgYDjjFgp1Bm+M6aCiCzWxlFbTBHxQbCDDPHFNO/ZZ59lmscq
/f8tvv/rX6SP4zl7ZAhqYqLID5yly9i9wkK6dJkHPh7qQnwJoAVwPZMeCn8ZcYZvv/02Hig0AokQ
ia/jVmINBDH12GOPkUEROcZtyI1JIkfUEOseGMPNxV4w0oYQLU+AItoqOPAGPzUuMKIWWWChMKIJ
hxeaiwpr1KjB5lAqwbdIu9RPUAd3tHWCD7c5O9GIUaRm4nmIb2RxBrc4gT0IRix888038ZEhzVCC
aLcnnniCGoiu5LsivohUmwg4TICbQgGNDjM3uTkFNJo8OrJNBPxAAGnGkjtTOAKc8J0xzUNesZzO
rxXxjUzJmHqhvHiwDs+0jQV8tBu70niLB4qMmZ6VkZtpJ/NM6rFCGalWLjM/fITM6SOrAVbyGXNM
Km4JRuIyY02D+yjwLi+iufjLK3SB24p70Po3UCb4CfcpN2Zgi1nwW8Wfk+WAwqy6BO5HFByts/ZC
DYEX+RLgX27h4jXwCpcE2FIMFcmN70Z/WYm904t+JsANwoIDH+kQd5yf+fit72zWYImMaYzfOu6f
/rLGaK1e+qfL6qnrCDA34yeJqRffRcwP+Z1ieoYHjQkY4bhMI5klMq8jJopc3wRE8a71Cm9RhpJM
FHmR5X1qwF9GVYEIK9fRkMHuJYDeIbUggYLu7YIsd4YAypRgbCSwM82pFREQAREQAUMIEEaiDI2G
jIXMuBkBpBlKCnXGw3Kf4fniwSI5astSavwlXpHkAGwtQXkhxHjwIgUoRuGAKKMS6bKbodbrthIg
8tbaRWVrK6rcAwTY2cf5ccrQ6IGhVBdEQAREICICbAcgDVdEl6iwCDhPAHUWeKCtEF88kGk88IJZ
D/QXjjPcZ7z1/699Z5W5Ufz/PGWBSpzvgloUAfY/slFL8219EkoloHPNSkXknwL8chGNrwA2/4x4
6J6SI4g1ZyYzoYvpXfcS0JHT7h07P1seUFjBTwK+sGAJFlzAz8TUdxMIIM04YZkcgyYYIxtMJiBp
ZvLoOGwbkfkpKSlsL2Kl0eGm1ZyBBDiukTS2BAUZaJtMiguBKlWqsL00LlWpEhEQAREQgRAEkGbt
2rXj6NgQZfSWCECAzP8cMSAVrw8DBMh5xZns5DIlGkRARIBctaSo1blmHv4kkISTM3k93EF1zT8E
yBDC2bWk0/dPl9VTdxFgnZOjJFkDd5fZstZ5ApzGyHkEHNrofNNq0TQCOtfMtBFJrD061yyx/B1o
3Qr9cqAhNSECdhMgK2OzZs1IA2J3Q6pfBERABGwlEIjEtrUVVe4KAkgzzuzj4HV5zVwxXnYb2bVr
18GDB8trZjdn1S8CIhA7AaRZy5YtOaA29qpUgwiIgAiIgAiYQIBzOTmWnQAnSTMThiPhNnACy7Bh
wyTNEj4QMkAERKBUApJmpSJSgcQS4Md027ZtrIEn1gy1LgIi4CICZP8gUJ8kjfhSXWS2TLWJwKFD
h06ePEmqapvqV7UJJ9CnT59169Yl3AwZIAKxE2BpsWnTppmZmbFXpRpEwA4CpAHh6L2cnBw7Kled
XiKwZ8+erKwshLyXOqW+iIAIiIAIlEqgcuXKfP+XWkwFRMB8AhcvXkxPT69du3bFihXL6yEC5hEo
W7bsnXfeWaZMGfNMk0VmEbjvvvv4qNx7771mmSVrYiNQ4cajSB38YJErO+nG49FHHyVP/pEjR8z/
wZWFIiACNhHQuWY2gVW1CSHA0dL5+fkkJ9dDBAwkMGbMmKeeeopTaQy0TSYZRWDIkCFkfujfv79R
VsmYGAngMQ/UQDL8zz77bNWqVbNmzerevfs999xz2223PfbYY+PHjy+SxJXDptevX08K/cDZnQn5
eVWjhhDAmU6mX2Y7htgjM+JOQNIs7khVoQiIgAiUSICAxjZt2iigsUQ4ejGYQG5ubs+ePfVRCWbi
vedsGho5cuTzzz+PImO4OVS6sLCweDfZnapzzYpj8e0rnGumDI3eHn0FNHp7fP3WOzbGal3Rb4Pu
ov4ePHiwd+/ezLpdZLNMTQgBjpxOTU39+OOPE9K6GrWVAP6vKVOmNG7cuFy5cmQVnjFjBuIrRIoP
3qWwkufbOiguqlznmrlosKIzderUqbt3747uWl0lAkYRuHDhQkZGho5QN2pQZEwwAWZfRKEos1Yw
Ez0vkcCxY8dWrFhx4MCBEt/Viy4lsGHDhrS0NPaaVa9efeDAgeRdJPtiqX2RNCsVka8KSJr5arjV
WRFwNQErQ+OkSZNc3QsZLwIiIAIi4D0CrMzw80TgIi7Ry5cvh99BvGz169dnk5rONQsfmodLkigG
XU/eMw/3UV0TARHwBgGda+aNcVQvREAEREAEAgTOnz/fq1cvPG7K/BBg4ucn77zzDpnVS9yW6Gcs
Xuo759ZFtHrjpb6rLx4jIGnmsQH1XndOnDgxduzYHTt2eK9r6lF8CVy5cuXs2bOafcWXqktrw91G
kkYFQrt0+OJuNh8GifS4UzWqwjp16nz00UdGmSRjRCA6AgpojI6brnKMwK5du5o3b67cDo4Bd29D
JEvv27fv8uXL3dsFWS4CIiACIhAFAVK2Tp8+PYoLdYkImEbg2rVra9as2b9/v2mGyR4RsAhYyfM/
+eQTARGB0AT4KuvWrZs+KqEp6V0REAER8B4BnWvmvTFVj0RABMwkIGlm5rgYaNXf//53UvmR+cFA
22SSwwRI+DB8+PCdO3cqjM1h8mY2l5mZuXDhwqtXr5ppnqyKnUDVqlXlNYsdo2oQAREQgVIJfP75
5wpoLJWSCkAArxnSTF4zfRggQIbGevXqKUOjPgwWgc6dO6enpytDo4c/DzVq1JgzZ46HO6iu+YcA
K4rHjx8vKCjwT5fVU3cR4HyiefPm5efnu8tsWes8gXXr1pGUj1OGnW9aLZpGQOeamTYiibVH55ol
lr8DrTOVvXTpkgMNqQkRsJsACc06dOgwbdo0uxtS/SIgAiJgKwEyNJLXSPmTbYXslsolzdwyUs7Y
KWnmDGe1IgIiEDsBkucTLUYYduxVqQYREAEREAERMIEAAY1169ZVQKMJY2GCDZ06ddKR0yYMhGwQ
AREolYDONSsVkQoklsC///3vb775Rtu3EzsKal0E3EUAF+qCBQu++OKLH374wV2Wy1o7CHCmxsaN
G7/77js7KledJhCYO3euNj6YMBCyIXYC8prFzlA12Epg7969Xbp00WFVtkL2RuUnT57Mzc09fPiw
N7qjXoiACIiACIRJICkpKTs7O8zCKiYCJhMgAUjHjh2VcdTkMfK5bWRobN269eLFi33OQd0vlYB1
rpk+KqWCUgEREAER8BgBnWvmsQH1c3cI9kCdffvtt36GoL6bTEDnmpk8OkbZpnPNjBqOxBrzn//8
h5wwhDUm1gy1bggBMp5duHDhv//9ryH2yIy4E5A0iztSVSgCIiACJRJAmslrViIZvViEgKRZESB+
/pepeHJy8urVq9ms6mcO6rtFgGM1Ro8erfStHv48VKlSJSsry8MdVNdEQAREwBACeXl5TLFycnIM
sUdmGEuAeXhqaqoCGo0dICcNI0Njw4YNlyxZoswPTmI3ti02LA8aNEjnXhk7QLEblpaWRkx77PWo
BhFIOIHCwkLS2mzbti3hlsgAESiRALkZjx49SixKie/qRREIEGBb4sSJE8nDFnhFT3xLQMnzfTv0
JXac5Pnp6ekXL14s8V29KAIiIALmEMC/P2XKlA0bNphjkiwRAREQAREQgVgIsIGan7Z9+/ax6SyW
enStNwjMnz8fr/q1a9e80R31QgREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQARE
QAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQARE
QAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQARE
QAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQARE
QAREQAREQAREQAREQAREQAREQAREQAREQAREQAREQATCIfC/++Kv5gplbmRzdHJlYW0KZW5kb2Jq
CjggMCBvYmoKMTAwMjYxCmVuZG9iagoxMCAwIG9iago8PCAvTGVuZ3RoIDExIDAgUiAvVHlwZSAv
WE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDExNjEgL0hlaWdodCA2MDAgL0NvbG9yU3Bh
Y2UKL0RldmljZUdyYXkgL0ludGVycG9sYXRlIHRydWUgL0JpdHNQZXJDb21wb25lbnQgOCAvRmls
dGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHt0IEAAAAAwyB/6h3khVBhwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wMD7wAAovhXCCmVuZHN0cmVhbQplbmRvYmoKMTEgMCBvYmoKMzA2MAplbmRvYmoKMTIgMCBvYmoK
PDwgL0xlbmd0aCAxMyAwIFIgL04gMyAvQWx0ZXJuYXRlIC9EZXZpY2VSR0IgL0ZpbHRlciAvRmxh
dGVEZWNvZGUgPj4Kc3RyZWFtCngBhVVbiBtVGP6TOckKu87T2tUtpEO9dCm7S7YV3aW0mluTtGsa
stnVFkGzk5NkzOwkzkzSC30qguKLq75JQby9LQiC0nrB1gf7UqlQVnfrIig+tHhBKPRFt/E7k2Qm
WWqbZc988/3f+W/nnxmigbVCva77FaIlwzZzyajy3NFjysA6+ekhGqRRGiyoVj2Szc4SfkIrrv2/
Wz+QTzBXJ+5s71dvuRsscksl8t0Hvla01CXgE0SBs2rdtIkGhsFPH7frAoschk0kCPyiwOU2ho2G
F9v4NUeTz8WgOQssq5VCEXgFeHyxhy/34HYOUMBPkhvc1FRF9CJr1kqazh1De7mHuUd5N7ikN1Cz
89uBdciqzh3GdQy1v1IsxAWeBF5RC4k54EeArzW1hUwH367b0RzwY0T+nY3qfAR4N3CqZB6cB4Yf
v1lppLr4nVOV/LPgt4H/xljMHOnsXVOtGHpJO8HfrvC06G+ISFI0O50Hhh/pgFnLCT1ykEpFHk8A
jwO/Xq0dFjnAp/SZ1ZwTvMhn7VQlJvIU/OWXCoeywKPAv3I9KfSIJf1bt7OdHFjI0DMiLmKxOLec
euGHhexKPgUecZlum/nOXrZc0g6mO/pPKmZK8GLvtbruzChyC/jNRk7UjliByYKZSALDZyDLjXnR
T4GbtOArEKcaLWJVyaBNUihHSYriWicTlhJppIPhsHIwHHddzYSzz6IqeI2ajs3CmnWU7Z1drUJl
sAZdd7QqxUIfUQOeKvQH2IrrU6EY7hrgyv/jp53LjY6fGhthYbYX//vYLNvPptkMKewp9jQ7wOJg
Z9g+13cWe7oViXxuIErbz8uIyB3dAmq/iBptKmD9BYoaWa6Hvq4sjzbGPMsZ8wVNvfLG3z290rCz
6iom+jp65F49D/wWuB5Yxboe2HB9KIGfAhv4W0dvvFpqnr3TZXFSGk601qfbehZdVQSV6s7OJXRB
Q828p+aJXh+XTn/5oBdtlZ17/urQpdMlY3nUY0UX+KuZWxk6M+6x4R/Df4ZXw++FPwz/Lr0tfSp9
JZ2XPpcukyJdkC5KX0vfSh9LX7j6u82Qe/YkMhdzJfIW09WtsLfXmFg5Km+XH5bj8g75UXnWVSny
iDwlp+RdsGx3z82bb6W3cvTlKKJ1+3PnWOJZ0VxPOAPf/ZgAzYvYNwPzyFij4/Bpot9i3gw6CW3v
k9epiIXYFEtvme5pMfNd38FEMB6MkBLcHZwJTgUPCdx9loO7YJvBmujNDfPhKvoq5TY/Ib4nFKvV
T5pauWIre8LhJ5UIPn1cSRvq5LhS0HXFMVmKyS1uNnlxksR3U+wjuplzvoe+bVc8zn6GaP9fePd9
73HHGkQrFtHI4x43hnflA+8SnXtCbZjNtj/y+b4jskp79zj3vqEo3l8/t1o38R4beIto881W65/3
W63ND+B/g+iC/h+gn3xVCmVuZHN0cmVhbQplbmRvYmoKMTMgMCBvYmoKMTA3OQplbmRvYmoKOSAw
IG9iagpbIC9JQ0NCYXNlZCAxMiAwIFIgXQplbmRvYmoKMyAwIG9iago8PCAvVHlwZSAvUGFnZXMg
L01lZGlhQm94IFswIDAgNjEyIDc5Ml0gL0NvdW50IDEgL0tpZHMgWyAyIDAgUiBdID4+CmVuZG9i
agoxNCAwIG9iago8PCAvVHlwZSAvQ2F0YWxvZyAvUGFnZXMgMyAwIFIgL1ZlcnNpb24gLzEuNCA+
PgplbmRvYmoKMTUgMCBvYmoKKE1hYyBPUyBYIDEwLjEyLjMgUXVhcnR6IFBERkNvbnRleHQpCmVu
ZG9iagoxNiAwIG9iagooRDoyMDE3MDIwMjE2MDM1OVowMCcwMCcpCmVuZG9iagoxIDAgb2JqCjw8
IC9Qcm9kdWNlciAxNSAwIFIgL0NyZWF0aW9uRGF0ZSAxNiAwIFIgL01vZERhdGUgMTYgMCBSID4+
CmVuZG9iagp4cmVmCjAgMTcKMDAwMDAwMDAwMCA2NTUzNSBmIAowMDAwMTA1NjExIDAwMDAwIG4g
CjAwMDAwMDAxNzAgMDAwMDAgbiAKMDAwMDEwNTM2OSAwMDAwMCBuIAowMDAwMDAwMDIyIDAwMDAw
IG4gCjAwMDAwMDAxNTIgMDAwMDAgbiAKMDAwMDAwMDI4NSAwMDAwMCBuIAowMDAwMDAwMzc0IDAw
MDAwIG4gCjAwMDAxMDA4MzQgMDAwMDAgbiAKMDAwMDEwNTMzMyAwMDAwMCBuIAowMDAwMTAwODU2
IDAwMDAwIG4gCjAwMDAxMDQxMDkgMDAwMDAgbiAKMDAwMDEwNDEzMCAwMDAwMCBuIAowMDAwMTA1
MzEyIDAwMDAwIG4gCjAwMDAxMDU0NTIgMDAwMDAgbiAKMDAwMDEwNTUxNiAwMDAwMCBuIAowMDAw
MTA1NTY5IDAwMDAwIG4gCnRyYWlsZXIKPDwgL1NpemUgMTcgL1Jvb3QgMTQgMCBSIC9JbmZvIDEg
MCBSIC9JRCBbIDw5ZGE0NjM2YzBkMGE2ZjU1YmFjMmY5MGJiYTU3MWExYT4KPDlkYTQ2MzZjMGQw
YTZmNTViYWMyZjkwYmJhNTcxYTFhPiBdID4+CnN0YXJ0eHJlZgoxMDU2ODYKJSVFT0YK
--001a113d328a1cf76705478ea7ea--


From nobody Thu Feb  2 08:41:04 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 828EA1294BC for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 08:41:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z373JiM928Cq for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 08:41:01 -0800 (PST)
Received: from mail-ot0-x22b.google.com (mail-ot0-x22b.google.com [IPv6:2607:f8b0:4003:c0f::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BF7641294A3 for <sacm@ietf.org>; Thu,  2 Feb 2017 08:41:00 -0800 (PST)
Received: by mail-ot0-x22b.google.com with SMTP id 65so16022394otq.2 for <sacm@ietf.org>; Thu, 02 Feb 2017 08:41:00 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to;  bh=1Oj/g2NsTHgPxdNqt0YkqSh7BPIAfzuBBwW+lKR+yLI=; b=Gq0ijt/3OhkSO6aQDM1pcQ0VxkwTjbF0Ge1chlynfZPsGGmPkiLMPX44QzdkWdDTLY osM1e/0yiJMw9zYMFSr9VAs2eifgiq237ZEixo2L4iJM5VTBLuZKqJhwiwJbucOoJUTT DlP76uoSYaHBL11oAesGpLEdyWqNrCafYptVSeRwlTiSHiasXn3C0krgMMvf/19+WrIz rkj19nCvyqkprYD8UdIo43w+XNkEYmg0NXIacZo+6gDOe5Kqbk1J0zGrLb9g7qmgNF5N HXvemQh30bKDpbHFqIMiBIPcbls48Myu5S/y7EVpH2vbzzew6C53XwAknBnEo2yoLuU8 8Wkg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=1Oj/g2NsTHgPxdNqt0YkqSh7BPIAfzuBBwW+lKR+yLI=; b=LbiiLShRUYhbgbikXSxga/7Ia6w1tqvXc/o1b7mLA9dJdNU0Bk9er1iY/4xxgVvI+r ctl8VLR0FY0oKqL24wDk73vFHkTqD7F0GwfINuC9Olj4jrklBZCex6MyvW4/tVscyqhF EJrsZx8pC39uA+iSNY3CzO0u3m/o2ZrqcBQpG4/axNpaCicxI/X4zzWI29c61G/VPafT 3kx0k4czELVvS8aThCbDJteo0p+CX1vuttKI/UtVJc3izIviK1Rv/eI2XirLymZEWCQM BL/3QWgrBiPJuYcHQjAyD7O4TJILtEfElwt3/Db/5q7zFhN/+QTjbAR2MK4jmzqlGhY3 xdRg==
X-Gm-Message-State: AMke39masW0kVTCpDfC8hBcQFFiJLvswIZdtx3h8worXdKcfyn+rQYkBqXyG7JGiVJwtTX7ZQ2joNO6gX9euqg==
X-Received: by 10.157.47.236 with SMTP id b41mr4966770otd.236.1486053659633; Thu, 02 Feb 2017 08:40:59 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com>
In-Reply-To: <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 16:40:49 +0000
Message-ID: <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com>
To: "sacm@ietf.org" <sacm@ietf.org>
Content-Type: multipart/alternative; boundary=001a113b197a7ff4c805478ed4aa
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/3Xvm7gWJW91-qsrfRxpLToIqemc>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 16:41:03 -0000

--001a113b197a7ff4c805478ed4aa
Content-Type: text/plain; charset=UTF-8

Once folks have had an opportunity to review the vulnerability scenario
information we've been working on, what are your thoughts on the main
components we're presently focused on for this narrowly scoped exercise?
These are:

Vulnerability Detection Data Repository
Vulnerability Assessor
Endpoint Repository
Collector
Assessment Result Repository
Endpoint




On Thu, Feb 2, 2017 at 10:28 AM Adam Montville <adam.w.montville@gmail.com>
wrote:

> Hi Everyone.  A few of us were able to make the vulnerability scenario
> call today and I think we had a good, though at times spirited,
> discussion.  We did record the meeting, which is available at [1].  We
> discussed the attached (annotated with some meeting notes) UML-ish sequence
> diagram.  I had created that diagram to start a conversation (mission
> accomplished on that front I think) -- a conversation that would lead us
> toward identifying the discrete components, interfaces, and information
> required to be sent over those interfaces.  The UML-ish diagram represents
> a *single* flow through the system -- a "one-time" flow through the
> system.  It ignores, for the time being, the continuous aspect of our
> charter in favor of getting started with the basics.  Once we have a good
> understanding of the basics -- the components, interfaces, and information
> required -- we can start look at a continuous monitoring sequence (which
> could be represented as a distinct diagram) to determine what more we
> need.  Then, I think, we can start drafting solutions.
>
> One of the first issues is that we need to figure out if the components in
> the base flow are accurate.  The main suggestion we've tossed around so far
> is to combine the Endpoint Repository with the Assessment Result Repository.
>
> We talked briefly about what interface we could use for the VDD
> Repository, and naturally ROLIE came up as an option.
>
> We talked a little bit about the first "get endpoints" operation between
> the Vulnerability Assessor and the Endpoint Repository -- specifically
> about whether we should represent on this sequence diagram that information
> supporting a judgement of "stale" would be needed.
>
> We left open the time when we would next meet, favoring to work that out
> on-list.  Next week is TCG, so that may be difficult; the following week is
> RSA, so that may be difficult.
>
> For those who were in attendance today, please add to this note with your
> comments/corrections.
>
> Kind regards,
>
> Adam
>
> [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>
> On Mon, Jan 30, 2017 at 11:21 AM Adam Montville <
> adam.w.montville@gmail.com> wrote:
>
> Hi everyone.  Just a friendly reminder that we are planning to meet again
> this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC) using SACM's
> meeting room at https://ietf.webex.com/meet/sacm.
>
> Kind regards,
>
> Adam
>
>
> On Thu, Jan 19, 2017 at 11:35 AM Adam Montville <
> adam.w.montville@gmail.com> wrote:
>
> Hello. A few of us met informally today to discuss the vulnerability
> scenario in some more detail with the goal of maintaining the narrow focus
> on a vulnerability assessment slice through our notional environment.  We
> are tending to look at major components as black boxes with interfaces and
> data format expectations, and we are not necessarily concerned with how
> those components do things internally/behind the scenes.
>
> The meeting was recorded (you can find it with today's date at [1]).  The
> topic of discussion was primarily in the "phase 1" area of what Danny sent
> to the list not very long ago [2], and resulted in a *starting point*
> diagram [3].
>
> The group who met today are (roughly) agreed on the six main "components"
> represented in that diagram, but also see that we have some work ahead.
> Specifically, we quickly recognized that some of the assumptions the
> vulnerability draft makes may be assumptions we cannot afford to make and
> need to include in the exploration.
>
> We thought it would be a good idea to have another informal discussion in
> a couple of weeks (February 2) at the same time (10am Eastern / 3pm UTC),
> using the same WebEx [4].   At that time we intend to roll through the
> vulnerability assessment scenario assumptions in an effort to determine
> which ones can be left as assumptions and which ones cannot.  Then we'll
> take another look at the diagram and work on its next version.
>
> Stay tuned.
>
> Thanks to Danny, Stephen, and Jerome for joining and contributing!
>
> Kind regards,
>
> Adam
>
>
> [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> [2] https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> [3] https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> [4] https://ietf.webex.com/meet/sacm
>
>

--001a113b197a7ff4c805478ed4aa
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Once folks have had an opportunity to review the vuln=
erability scenario information we&#39;ve been working on, what are your tho=
ughts on the main components we&#39;re presently focused on for this narrow=
ly scoped exercise?=C2=A0 These are:</div><div><br></div><div>Vulnerability=
 Detection Data Repository</div><div>Vulnerability Assessor</div><div>Endpo=
int Repository</div><div>Collector</div><div>Assessment Result Repository</=
div><div>Endpoint</div><div><br></div><div><br></div><div><br></div></div><=
br><div class=3D"gmail_quote"><div dir=3D"ltr">On Thu, Feb 2, 2017 at 10:28=
 AM Adam Montville &lt;<a href=3D"mailto:adam.w.montville@gmail.com">adam.w=
.montville@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quo=
te" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"=
><div dir=3D"ltr" class=3D"gmail_msg">Hi Everyone.=C2=A0 A few of us were a=
ble to make the vulnerability scenario call today and I think we had a good=
, though at times spirited, discussion.=C2=A0 We did record the meeting, wh=
ich is available at [1].=C2=A0 We discussed the attached (annotated with so=
me meeting notes) UML-ish sequence diagram.=C2=A0 I had created that diagra=
m to start a conversation (mission accomplished on that front I think) -- a=
 conversation that would lead us toward identifying the discrete components=
, interfaces, and information required to be sent over those interfaces.=C2=
=A0 The UML-ish diagram represents a *single* flow through the system -- a =
&quot;one-time&quot; flow through the system.=C2=A0 It ignores, for the tim=
e being, the continuous aspect of our charter in favor of getting started w=
ith the basics.=C2=A0 Once we have a good understanding of the basics -- th=
e components, interfaces, and information required -- we can start look at =
a continuous monitoring sequence (which could be represented as a distinct =
diagram) to determine what more we need.=C2=A0 Then, I think, we can start =
drafting solutions.=C2=A0<div class=3D"gmail_msg"><br class=3D"gmail_msg"><=
/div><div class=3D"gmail_msg">One of the first issues is that we need to fi=
gure out if the components in the base flow are accurate.=C2=A0 The main su=
ggestion we&#39;ve tossed around so far is to combine the Endpoint Reposito=
ry with the Assessment Result Repository.</div><div class=3D"gmail_msg"><br=
 class=3D"gmail_msg"></div><div class=3D"gmail_msg">We talked briefly about=
 what interface we could use for the VDD Repository, and naturally ROLIE ca=
me up as an option.</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"><=
/div><div class=3D"gmail_msg">We talked a little bit about the first &quot;=
get endpoints&quot; operation between the Vulnerability Assessor and the En=
dpoint Repository -- specifically about whether we should represent on this=
 sequence diagram that information supporting a judgement of &quot;stale&qu=
ot; would be needed.</div><div class=3D"gmail_msg"><br class=3D"gmail_msg">=
</div><div class=3D"gmail_msg">We left open the time when we would next mee=
t, favoring to work that out on-list.=C2=A0 Next week is TCG, so that may b=
e difficult; the following week is RSA, so that may be difficult.</div><div=
 class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg"=
>For those who were in attendance today, please add to this note with your =
comments/corrections.</div></div><div dir=3D"ltr" class=3D"gmail_msg"><div =
class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">=
Kind regards,</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><=
div class=3D"gmail_msg">Adam</div><div class=3D"gmail_msg"><div class=3D"gm=
ail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">[1]=C2=A0<a=
 href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" c=
lass=3D"gmail_msg" target=3D"_blank">https://drive.google.com/open?id=3D0B8=
Wf9Un5FdCbWGhDOHpVR0tMd1E</a>=C2=A0</div></div><br class=3D"gmail_msg"></di=
v><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quote gmail_msg"=
><div dir=3D"ltr" class=3D"gmail_msg">On Mon, Jan 30, 2017 at 11:21 AM Adam=
 Montville &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail=
_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt; wrote:<br class=
=3D"gmail_msg"></div><blockquote class=3D"gmail_quote gmail_msg" style=3D"m=
argin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"l=
tr" class=3D"gmail_msg">Hi everyone.=C2=A0 Just a friendly reminder that we=
 are planning to meet again this Thursday at the same time (2/2 @ 10am East=
ern/3pm UTC) using SACM&#39;s meeting room at <a href=3D"https://ietf.webex=
.com/meet/sacm" class=3D"gmail_msg" target=3D"_blank">https://ietf.webex.co=
m/meet/sacm</a>.=C2=A0<div class=3D"gmail_msg"><br class=3D"gmail_msg"></di=
v><div class=3D"gmail_msg">Kind regards,</div><div class=3D"gmail_msg"><br =
class=3D"gmail_msg"></div><div class=3D"gmail_msg">Adam</div></div><div dir=
=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_msg"><br class=3D"gmail_ms=
g"><br class=3D"gmail_msg"><div class=3D"gmail_quote gmail_msg"><div dir=3D=
"ltr" class=3D"gmail_msg">On Thu, Jan 19, 2017 at 11:35 AM Adam Montville &=
lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" target=
=3D"_blank">adam.w.montville@gmail.com</a>&gt; wrote:<br class=3D"gmail_msg=
"></div><blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .=
8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr" class=3D"=
gmail_msg">Hello. A few of us met informally today to discuss the vulnerabi=
lity scenario in some more detail with the goal of maintaining the narrow f=
ocus on a vulnerability assessment slice through our notional environment.=
=C2=A0 We are tending to look at major components as black boxes with inter=
faces and data format expectations, and we are not necessarily concerned wi=
th how those components do things internally/behind the scenes.<div class=
=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">The m=
eeting was recorded (you can find it with today&#39;s date at [1]).=C2=A0 T=
he topic of discussion was primarily in the &quot;phase 1&quot; area of wha=
t Danny sent to the list not very long ago [2], and resulted in a *starting=
 point* diagram [3].<div class=3D"gmail_msg"><br class=3D"gmail_msg"></div>=
<div class=3D"gmail_msg">The group who met today are (roughly) agreed on th=
e six main &quot;components&quot; represented in that diagram, but also see=
 that we have some work ahead.=C2=A0 Specifically, we quickly recognized th=
at some of the assumptions the vulnerability draft makes may be assumptions=
 we cannot afford to make and need to include in the exploration.</div><div=
 class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg"=
>We thought it would be a good idea to have another informal discussion in =
a couple of weeks (February 2) at the same time (10am Eastern / 3pm UTC), u=
sing the same WebEx [4]. =C2=A0 At that time we intend to roll through the =
vulnerability assessment scenario assumptions in an effort to determine whi=
ch ones can be left as assumptions and which ones cannot.=C2=A0 Then we&#39=
;ll take another look at the diagram and work on its next version.</div><di=
v class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg=
">Stay tuned.</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><=
div class=3D"gmail_msg">Thanks to Danny, Stephen, and Jerome for joining an=
d contributing!</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div=
><div class=3D"gmail_msg">Kind regards,</div><div class=3D"gmail_msg"><br c=
lass=3D"gmail_msg"></div><div class=3D"gmail_msg">Adam<br class=3D"gmail_ms=
g"><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gma=
il_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">[1]=C2=A0<a =
href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" cl=
ass=3D"gmail_msg" target=3D"_blank">https://drive.google.com/open?id=3D0B8W=
f9Un5FdCbWGhDOHpVR0tMd1E</a></div><div class=3D"gmail_msg">[2]=C2=A0<a href=
=3D"https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM"=
 class=3D"gmail_msg" target=3D"_blank">https://mailarchive.ietf.org/arch/ms=
g/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM</a></div><div class=3D"gmail_msg">[3]=C2=
=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtN=
Hc" class=3D"gmail_msg" target=3D"_blank">https://drive.google.com/open?id=
=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a></div><div class=3D"gmail_msg">[4] <a hr=
ef=3D"https://ietf.webex.com/meet/sacm" class=3D"gmail_msg" target=3D"_blan=
k">https://ietf.webex.com/meet/sacm</a>=C2=A0</div><div class=3D"gmail_msg"=
><br class=3D"gmail_msg"></div></div></div></div></blockquote></div></div><=
/div></blockquote></div></div></blockquote></div>

--001a113b197a7ff4c805478ed4aa--


From nobody Thu Feb  2 08:53:53 2017
Return-Path: <henk.birkholz@sit.fraunhofer.de>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1FC8B1294C7 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 08:53:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.099
X-Spam-Level: 
X-Spam-Status: No, score=-10.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-3.199] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ciBl780tO7lY for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 08:53:50 -0800 (PST)
Received: from mailext.sit.fraunhofer.de (mailext.sit.fraunhofer.de [141.12.72.89]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 26597129859 for <sacm@ietf.org>; Thu,  2 Feb 2017 08:53:48 -0800 (PST)
Received: from mail.sit.fraunhofer.de (mail.sit.fraunhofer.de [141.12.84.171]) by mailext.sit.fraunhofer.de (8.14.4/8.14.4/Debian-2ubuntu2.1) with ESMTP id v12GrgAE006044 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 2 Feb 2017 17:53:43 +0100
Received: from [134.102.160.226] (134.102.160.226) by mail.sit.fraunhofer.de (141.12.84.171) with Microsoft SMTP Server (TLS) id 14.3.319.2; Thu, 2 Feb 2017 17:53:37 +0100
To: Adam Montville <adam.w.montville@gmail.com>, "sacm@ietf.org" <sacm@ietf.org>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com>
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Message-ID: <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de>
Date: Thu, 2 Feb 2017 17:53:37 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com>
Content-Type: text/plain; charset="windows-1252"; format=flowed
Content-Transfer-Encoding: 8bit
X-Originating-IP: [134.102.160.226]
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/ERLay8D2kkzZ88_zpBiabFk7IPw>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 16:53:53 -0000

## A Few Comments

* I agree that the diagram pretty much captures a "one time snapshot".
* Collapsing the highlighted components seems to be a feasible idea.
* I agree that the diagram could be implemented given an appropriate set 
of initial data.
* I suppose there is the risk that one has to scrap everything 
implemented when we start trying to make it a continuous process.
* I'd recommend to start with a generic block of PoC code that provides 
the functions of a SACM component to get input and create output (maybe 
using dbus, chained event-loops, blocking waits on fifos, or IP over 
loopback? A better coder than me should bash these suggestions).

## One, Two, or Three Tasks

* Creating component code that can create the (downstream?) flow of 
information is urgent and important, I think.
* Enhancing the diagram to represent the continuous cycle with at least 
one trigger (as illustrated by Bill; new software, new VDI, new 
endpoints, stale results, etc.) is important, but not as urgent. It 
might save time though by reducing the afore mentioned risk to shoot 
your self in the foot by creating a too specific proof of concept of the 
one time snapshot approach, I think.
* Selecting a set of initial data derived from OVAL to be used in the 
one shot snapshot seems to be a feasible approach to me, but I am not 
sure how the group thinks about that.

Does that assessment represent the general opinion, or is that just mine?

Viele Grüße,

Henk

On 02/02/2017 05:28 PM, Adam Montville wrote:
> Hi Everyone.  A few of us were able to make the vulnerability scenario
> call today and I think we had a good, though at times spirited,
> discussion.  We did record the meeting, which is available at [1].  We
> discussed the attached (annotated with some meeting notes) UML-ish
> sequence diagram.  I had created that diagram to start a conversation
> (mission accomplished on that front I think) -- a conversation that
> would lead us toward identifying the discrete components, interfaces,
> and information required to be sent over those interfaces.  The UML-ish
> diagram represents a *single* flow through the system -- a "one-time"
> flow through the system.  It ignores, for the time being, the continuous
> aspect of our charter in favor of getting started with the basics.  Once
> we have a good understanding of the basics -- the components,
> interfaces, and information required -- we can start look at a
> continuous monitoring sequence (which could be represented as a distinct
> diagram) to determine what more we need.  Then, I think, we can start
> drafting solutions.
>
> One of the first issues is that we need to figure out if the components
> in the base flow are accurate.  The main suggestion we've tossed around
> so far is to combine the Endpoint Repository with the Assessment Result
> Repository.
>
> We talked briefly about what interface we could use for the VDD
> Repository, and naturally ROLIE came up as an option.
>
> We talked a little bit about the first "get endpoints" operation between
> the Vulnerability Assessor and the Endpoint Repository -- specifically
> about whether we should represent on this sequence diagram that
> information supporting a judgement of "stale" would be needed.
>
> We left open the time when we would next meet, favoring to work that out
> on-list.  Next week is TCG, so that may be difficult; the following week
> is RSA, so that may be difficult.
>
> For those who were in attendance today, please add to this note with
> your comments/corrections.
>
> Kind regards,
>
> Adam
>
> [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>
> On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
> <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote:
>
>     Hi everyone.  Just a friendly reminder that we are planning to meet
>     again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)
>     using SACM's meeting room at https://ietf.webex.com/meet/sacm.
>
>     Kind regards,
>
>     Adam
>
>
>     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>     <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote:
>
>         Hello. A few of us met informally today to discuss the
>         vulnerability scenario in some more detail with the goal of
>         maintaining the narrow focus on a vulnerability assessment slice
>         through our notional environment.  We are tending to look at
>         major components as black boxes with interfaces and data format
>         expectations, and we are not necessarily concerned with how
>         those components do things internally/behind the scenes.
>
>         The meeting was recorded (you can find it with today's date at
>         [1]).  The topic of discussion was primarily in the "phase 1"
>         area of what Danny sent to the list not very long ago [2], and
>         resulted in a *starting point* diagram [3].
>
>         The group who met today are (roughly) agreed on the six main
>         "components" represented in that diagram, but also see that we
>         have some work ahead.  Specifically, we quickly recognized that
>         some of the assumptions the vulnerability draft makes may be
>         assumptions we cannot afford to make and need to include in the
>         exploration.
>
>         We thought it would be a good idea to have another informal
>         discussion in a couple of weeks (February 2) at the same time
>         (10am Eastern / 3pm UTC), using the same WebEx [4].   At that
>         time we intend to roll through the vulnerability assessment
>         scenario assumptions in an effort to determine which ones can be
>         left as assumptions and which ones cannot.  Then we'll take
>         another look at the diagram and work on its next version.
>
>         Stay tuned.
>
>         Thanks to Danny, Stephen, and Jerome for joining and contributing!
>
>         Kind regards,
>
>         Adam
>
>
>         [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>         [2] https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
>         [3] https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>         [4] https://ietf.webex.com/meet/sacm
>
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>


From nobody Thu Feb  2 09:45:02 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7A2951298D2 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 09:45:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.989
X-Spam-Level: 
X-Spam-Status: No, score=-1.989 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_FREEMAIL_DOC_PDF=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VS-tdKJYcMZB for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 09:44:57 -0800 (PST)
Received: from mail-ot0-x22f.google.com (mail-ot0-x22f.google.com [IPv6:2607:f8b0:4003:c0f::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 823221298AC for <sacm@ietf.org>; Thu,  2 Feb 2017 09:44:57 -0800 (PST)
Received: by mail-ot0-x22f.google.com with SMTP id 65so17519163otq.2 for <sacm@ietf.org>; Thu, 02 Feb 2017 09:44:57 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to;  bh=/tEeL6Znk/FHMxqhu0GEb7PQYWrSjbKtrZNO8aVNWi8=; b=csJEvd+NNBogAf2vW0wpvN60WiSQKCMTrggnsnZDdi0Fwrybo4P64fek6Ec9gfz01X T1F85JTH8QlUoj1kmn/F6FLIqgsTPT8zC9b8ObLoOkizKHK84VbhNnORquFSPyXf7gEn Pj7S1g6uYb+8I8i1t9IVRPTLkRZnKaBO5cgXyaW4shaTPmy/4WSYqNdPeCT57AnD0dCD vP4zMbzCZx0NRlUGunFB6NK5rtN0lLSrvcSvcbD5JTKpM4NDZN0Z3ud9F7d/68j442xW odAy5lWqWjCAQ6gOpE7R87zigpLvmUYJ33En2Zi0Nc+WppOLF6106UsPJZt91QFi90Zf nEpQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=/tEeL6Znk/FHMxqhu0GEb7PQYWrSjbKtrZNO8aVNWi8=; b=Z63XT2Rnawjzkl3/a7owqK5UL+zVXQqjFpk5xHcNWBCljL2Gc1BvYl8uBnOpHML2n8 iE3/HGym2ZkzqAUCLP7ADyAave26OVqzmc8qaLFd/KZjJ1ZQrH/PyIJfObT2BArCRdtS bL5/j1rWJNzOCNSpPbv0jov+6+gVOoWSljX2df/vyA7gbHfuQvlWx0rkAp00SLmvkstO 7lekZJ1W/RvnJbaRZDYJXbvm0IuFi5+aIZC6W+eRPui4o9TTEr0T9NzDllF4l+/ibhID 7FWycmKFY0vrGV5TaA9tUCXJuljxZryYIF/0Dpn1Q9vXQhPZlCYiIm8irHc/USofUZXM wf2g==
X-Gm-Message-State: AMke39mL4vQrCTmvkAzQDrR2V9XSO4Tci9sOWf6lFcV6aUzvJSM0big2tNSo2dhLTHpPoWcqFhFzpC2lrCAJqQ==
X-Received: by 10.157.41.204 with SMTP id g12mr4326826otd.165.1486057496708; Thu, 02 Feb 2017 09:44:56 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de>
In-Reply-To: <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 17:44:46 +0000
Message-ID: <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com>
To: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Content-Type: multipart/mixed; boundary=001a113dd774352df205478fb9d4
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/j7-41BlqiiJGhERyO83_Jd7Q5h4>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 17:45:00 -0000

--001a113dd774352df205478fb9d4
Content-Type: multipart/alternative; boundary=001a113dd774352ded05478fb9d2

--001a113dd774352ded05478fb9d2
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Thanks for the feedback!  I've attached a modified version of the diagram
that collapses the endpoint and assessment result repositories (by keeping
the endpoint repository).  Where would you propose we focus on enhancing
the diagram?  Remember that it's a sequence diagram, which might do well
with some more specific details captured in text or a different form of
diagram.

What do folks think about using one or more OVAL definitions as a starting
point?

Adam


On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz <
henk.birkholz@sit.fraunhofer.de> wrote:

> ## A Few Comments
>
> * I agree that the diagram pretty much captures a "one time snapshot".
> * Collapsing the highlighted components seems to be a feasible idea.
> * I agree that the diagram could be implemented given an appropriate set
> of initial data.
> * I suppose there is the risk that one has to scrap everything
> implemented when we start trying to make it a continuous process.
> * I'd recommend to start with a generic block of PoC code that provides
> the functions of a SACM component to get input and create output (maybe
> using dbus, chained event-loops, blocking waits on fifos, or IP over
> loopback? A better coder than me should bash these suggestions).
>
> ## One, Two, or Three Tasks
>
> * Creating component code that can create the (downstream?) flow of
> information is urgent and important, I think.
> * Enhancing the diagram to represent the continuous cycle with at least
> one trigger (as illustrated by Bill; new software, new VDI, new
> endpoints, stale results, etc.) is important, but not as urgent. It
> might save time though by reducing the afore mentioned risk to shoot
> your self in the foot by creating a too specific proof of concept of the
> one time snapshot approach, I think.
> * Selecting a set of initial data derived from OVAL to be used in the
> one shot snapshot seems to be a feasible approach to me, but I am not
> sure how the group thinks about that.
>
> Does that assessment represent the general opinion, or is that just mine?
>
> Viele Gr=C3=BC=C3=9Fe,
>
> Henk
>
> On 02/02/2017 05:28 PM, Adam Montville wrote:
> > Hi Everyone.  A few of us were able to make the vulnerability scenario
> > call today and I think we had a good, though at times spirited,
> > discussion.  We did record the meeting, which is available at [1].  We
> > discussed the attached (annotated with some meeting notes) UML-ish
> > sequence diagram.  I had created that diagram to start a conversation
> > (mission accomplished on that front I think) -- a conversation that
> > would lead us toward identifying the discrete components, interfaces,
> > and information required to be sent over those interfaces.  The UML-ish
> > diagram represents a *single* flow through the system -- a "one-time"
> > flow through the system.  It ignores, for the time being, the continuou=
s
> > aspect of our charter in favor of getting started with the basics.  Onc=
e
> > we have a good understanding of the basics -- the components,
> > interfaces, and information required -- we can start look at a
> > continuous monitoring sequence (which could be represented as a distinc=
t
> > diagram) to determine what more we need.  Then, I think, we can start
> > drafting solutions.
> >
> > One of the first issues is that we need to figure out if the components
> > in the base flow are accurate.  The main suggestion we've tossed around
> > so far is to combine the Endpoint Repository with the Assessment Result
> > Repository.
> >
> > We talked briefly about what interface we could use for the VDD
> > Repository, and naturally ROLIE came up as an option.
> >
> > We talked a little bit about the first "get endpoints" operation betwee=
n
> > the Vulnerability Assessor and the Endpoint Repository -- specifically
> > about whether we should represent on this sequence diagram that
> > information supporting a judgement of "stale" would be needed.
> >
> > We left open the time when we would next meet, favoring to work that ou=
t
> > on-list.  Next week is TCG, so that may be difficult; the following wee=
k
> > is RSA, so that may be difficult.
> >
> > For those who were in attendance today, please add to this note with
> > your comments/corrections.
> >
> > Kind regards,
> >
> > Adam
> >
> > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >
> > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
> > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote:
> >
> >     Hi everyone.  Just a friendly reminder that we are planning to meet
> >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)
> >     using SACM's meeting room at https://ietf.webex.com/meet/sacm.
> >
> >     Kind regards,
> >
> >     Adam
> >
> >
> >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
> >     <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>>
> wrote:
> >
> >         Hello. A few of us met informally today to discuss the
> >         vulnerability scenario in some more detail with the goal of
> >         maintaining the narrow focus on a vulnerability assessment slic=
e
> >         through our notional environment.  We are tending to look at
> >         major components as black boxes with interfaces and data format
> >         expectations, and we are not necessarily concerned with how
> >         those components do things internally/behind the scenes.
> >
> >         The meeting was recorded (you can find it with today's date at
> >         [1]).  The topic of discussion was primarily in the "phase 1"
> >         area of what Danny sent to the list not very long ago [2], and
> >         resulted in a *starting point* diagram [3].
> >
> >         The group who met today are (roughly) agreed on the six main
> >         "components" represented in that diagram, but also see that we
> >         have some work ahead.  Specifically, we quickly recognized that
> >         some of the assumptions the vulnerability draft makes may be
> >         assumptions we cannot afford to make and need to include in the
> >         exploration.
> >
> >         We thought it would be a good idea to have another informal
> >         discussion in a couple of weeks (February 2) at the same time
> >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At that
> >         time we intend to roll through the vulnerability assessment
> >         scenario assumptions in an effort to determine which ones can b=
e
> >         left as assumptions and which ones cannot.  Then we'll take
> >         another look at the diagram and work on its next version.
> >
> >         Stay tuned.
> >
> >         Thanks to Danny, Stephen, and Jerome for joining and
> contributing!
> >
> >         Kind regards,
> >
> >         Adam
> >
> >
> >         [1]
> https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >         [2]
> https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> >         [3]
> https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> >         [4] https://ietf.webex.com/meet/sacm
> >
> >
> >
> > _______________________________________________
> > sacm mailing list
> > sacm@ietf.org
> > https://www.ietf.org/mailman/listinfo/sacm
> >
>

--001a113dd774352ded05478fb9d2
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thanks for the feedback!=C2=A0 I&#39;ve attached a modifie=
d version of the diagram that collapses the endpoint and assessment result =
repositories (by keeping the endpoint repository).=C2=A0 Where would you pr=
opose we focus on enhancing the diagram?=C2=A0 Remember that it&#39;s a seq=
uence diagram, which might do well with some more specific details captured=
 in text or a different form of diagram.<div><br></div><div>What do folks t=
hink about using one or more OVAL definitions as a starting point?</div><di=
v><br></div><div>Adam</div><div><br></div><br><div class=3D"gmail_quote"><d=
iv dir=3D"ltr">On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz &lt;<a href=3D=
"mailto:henk.birkholz@sit.fraunhofer.de">henk.birkholz@sit.fraunhofer.de</a=
>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0=
 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">## A Few Comments<br c=
lass=3D"gmail_msg">
<br class=3D"gmail_msg">
* I agree that the diagram pretty much captures a &quot;one time snapshot&q=
uot;.<br class=3D"gmail_msg">
* Collapsing the highlighted components seems to be a feasible idea.<br cla=
ss=3D"gmail_msg">
* I agree that the diagram could be implemented given an appropriate set<br=
 class=3D"gmail_msg">
of initial data.<br class=3D"gmail_msg">
* I suppose there is the risk that one has to scrap everything<br class=3D"=
gmail_msg">
implemented when we start trying to make it a continuous process.<br class=
=3D"gmail_msg">
* I&#39;d recommend to start with a generic block of PoC code that provides=
<br class=3D"gmail_msg">
the functions of a SACM component to get input and create output (maybe<br =
class=3D"gmail_msg">
using dbus, chained event-loops, blocking waits on fifos, or IP over<br cla=
ss=3D"gmail_msg">
loopback? A better coder than me should bash these suggestions).<br class=
=3D"gmail_msg">
<br class=3D"gmail_msg">
## One, Two, or Three Tasks<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
* Creating component code that can create the (downstream?) flow of<br clas=
s=3D"gmail_msg">
information is urgent and important, I think.<br class=3D"gmail_msg">
* Enhancing the diagram to represent the continuous cycle with at least<br =
class=3D"gmail_msg">
one trigger (as illustrated by Bill; new software, new VDI, new<br class=3D=
"gmail_msg">
endpoints, stale results, etc.) is important, but not as urgent. It<br clas=
s=3D"gmail_msg">
might save time though by reducing the afore mentioned risk to shoot<br cla=
ss=3D"gmail_msg">
your self in the foot by creating a too specific proof of concept of the<br=
 class=3D"gmail_msg">
one time snapshot approach, I think.<br class=3D"gmail_msg">
* Selecting a set of initial data derived from OVAL to be used in the<br cl=
ass=3D"gmail_msg">
one shot snapshot seems to be a feasible approach to me, but I am not<br cl=
ass=3D"gmail_msg">
sure how the group thinks about that.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Does that assessment represent the general opinion, or is that just mine?<b=
r class=3D"gmail_msg">
<br class=3D"gmail_msg">
Viele Gr=C3=BC=C3=9Fe,<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Henk<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
On 02/02/2017 05:28 PM, Adam Montville wrote:<br class=3D"gmail_msg">
&gt; Hi Everyone.=C2=A0 A few of us were able to make the vulnerability sce=
nario<br class=3D"gmail_msg">
&gt; call today and I think we had a good, though at times spirited,<br cla=
ss=3D"gmail_msg">
&gt; discussion.=C2=A0 We did record the meeting, which is available at [1]=
.=C2=A0 We<br class=3D"gmail_msg">
&gt; discussed the attached (annotated with some meeting notes) UML-ish<br =
class=3D"gmail_msg">
&gt; sequence diagram.=C2=A0 I had created that diagram to start a conversa=
tion<br class=3D"gmail_msg">
&gt; (mission accomplished on that front I think) -- a conversation that<br=
 class=3D"gmail_msg">
&gt; would lead us toward identifying the discrete components, interfaces,<=
br class=3D"gmail_msg">
&gt; and information required to be sent over those interfaces.=C2=A0 The U=
ML-ish<br class=3D"gmail_msg">
&gt; diagram represents a *single* flow through the system -- a &quot;one-t=
ime&quot;<br class=3D"gmail_msg">
&gt; flow through the system.=C2=A0 It ignores, for the time being, the con=
tinuous<br class=3D"gmail_msg">
&gt; aspect of our charter in favor of getting started with the basics.=C2=
=A0 Once<br class=3D"gmail_msg">
&gt; we have a good understanding of the basics -- the components,<br class=
=3D"gmail_msg">
&gt; interfaces, and information required -- we can start look at a<br clas=
s=3D"gmail_msg">
&gt; continuous monitoring sequence (which could be represented as a distin=
ct<br class=3D"gmail_msg">
&gt; diagram) to determine what more we need.=C2=A0 Then, I think, we can s=
tart<br class=3D"gmail_msg">
&gt; drafting solutions.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; One of the first issues is that we need to figure out if the component=
s<br class=3D"gmail_msg">
&gt; in the base flow are accurate.=C2=A0 The main suggestion we&#39;ve tos=
sed around<br class=3D"gmail_msg">
&gt; so far is to combine the Endpoint Repository with the Assessment Resul=
t<br class=3D"gmail_msg">
&gt; Repository.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; We talked briefly about what interface we could use for the VDD<br cla=
ss=3D"gmail_msg">
&gt; Repository, and naturally ROLIE came up as an option.<br class=3D"gmai=
l_msg">
&gt;<br class=3D"gmail_msg">
&gt; We talked a little bit about the first &quot;get endpoints&quot; opera=
tion between<br class=3D"gmail_msg">
&gt; the Vulnerability Assessor and the Endpoint Repository -- specifically=
<br class=3D"gmail_msg">
&gt; about whether we should represent on this sequence diagram that<br cla=
ss=3D"gmail_msg">
&gt; information supporting a judgement of &quot;stale&quot; would be neede=
d.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; We left open the time when we would next meet, favoring to work that o=
ut<br class=3D"gmail_msg">
&gt; on-list.=C2=A0 Next week is TCG, so that may be difficult; the followi=
ng week<br class=3D"gmail_msg">
&gt; is RSA, so that may be difficult.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; For those who were in attendance today, please add to this note with<b=
r class=3D"gmail_msg">
&gt; your comments/corrections.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; Kind regards,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; [1] <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHp=
VR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">https://=
drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br class=3D"gma=
il_msg">
&gt;<br class=3D"gmail_msg">
&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montville<br class=3D"gmail_msg"=
>
&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" =
target=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto:<a href=3D"mail=
to:adam.w.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w=
.montville@gmail.com</a>&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a friendly reminder that we=
 are planning to meet<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the same time (2/2 @ 10am Ea=
stern/3pm UTC)<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting room at <a href=3D"https:/=
/ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"gmail_msg" target=3D=
"_blank">https://ietf.webex.com/meet/sacm</a>.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:35 AM Adam Montville<br =
class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montville@gmail.com" c=
lass=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &lt;mai=
lto:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" targe=
t=3D"_blank">adam.w.montville@gmail.com</a>&gt;&gt; wrote:<br class=3D"gmai=
l_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few of us met informally tod=
ay to discuss the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability scenario in some more d=
etail with the goal of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining the narrow focus on a vul=
nerability assessment slice<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our notional environment.=C2=
=A0 We are tending to look at<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major components as black boxes with =
interfaces and data format<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations, and we are not necessar=
ily concerned with how<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those components do things internally=
/behind the scenes.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting was recorded (you can fin=
d it with today&#39;s date at<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 The topic of discussion w=
as primarily in the &quot;phase 1&quot;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what Danny sent to the list n=
ot very long ago [2], and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a *starting point* diagra=
m [3].<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who met today are (roughly)=
 agreed on the six main<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;components&quot; represented in=
 that diagram, but also see that we<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some work ahead.=C2=A0 Specifica=
lly, we quickly recognized that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the assumptions the vulnerabi=
lity draft makes may be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions we cannot afford to make =
and need to include in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it would be a good idea to=
 have another informal<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in a couple of weeks (Febr=
uary 2) at the same time<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern / 3pm UTC), using the s=
ame WebEx [4].=C2=A0 =C2=A0At that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we intend to roll through the vu=
lnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assumptions in an effort to =
determine which ones can be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assumptions and which ones ca=
nnot.=C2=A0 Then we&#39;ll take<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look at the diagram and work =
on its next version.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Danny, Stephen, and Jerome =
for joining and contributing!<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmai=
l_msg" target=3D"_blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2] <a href=3D"https://mailarchive.ie=
tf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=
=3D"gmail_msg" target=3D"_blank">https://mailarchive.ietf.org/arch/msg/sacm=
/_LiKlyvAws_OVLFhB5NSU58MXDM</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"gmai=
l_msg" target=3D"_blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU=
5pdTRjejJtNHc</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=3D"https://ietf.webex.com=
/meet/sacm" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">https:=
//ietf.webex.com/meet/sacm</a><br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; _______________________________________________<br class=3D"gmail_msg"=
>
&gt; sacm mailing list<br class=3D"gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank"=
>sacm@ietf.org</a><br class=3D"gmail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferr=
er" class=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/list=
info/sacm</a><br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
</blockquote></div></div>

--001a113dd774352ded05478fb9d2--

--001a113dd774352df205478fb9d4
Content-Type: application/pdf; 
	name="vulnerability_scenario_sequence_diagram_v3.pdf"
Content-Disposition: attachment; 
	filename="vulnerability_scenario_sequence_diagram_v3.pdf"
Content-Transfer-Encoding: base64
Content-ID: <159ffedab3a9667fedf1>
X-Attachment-Id: 159ffedab3a9667fedf1

JVBERi0xLjMKJcTl8uXrp/Og0MTGCjQgMCBvYmoKPDwgL0xlbmd0aCA1IDAgUiAvRmlsdGVyIC9G
bGF0ZURlY29kZSA+PgpzdHJlYW0KeAG9WkuTG7cRvuNX4Mg9cITXYGaOieSDdIptVnKwfFAorndV
XK1ErpTyn81vydcAugfzIHeVVMUuewEMHo1+ft3gV/2z/qoN/h2M023b6tNB/0N/1q9en63en7VN
/573ejs0LSbQ/x+0bY2T7rF0VWxag386fcyzq/7ddP2tfvW3w2l/+PL07cNRn+5Bg/VEhdERpGDr
EGzTqv2DfvX2weo3j4lOnhMG7Ty+69ASGXmWm89qrQ4+7dUa2cvzLD+k4zqjXddpb4ayTVif4AL2
KFNaNaMHNEdrmq6QXabF9Z18KN87fFfEfr6W9a3uoms6Bzn42DWxt32Z3OfNXv1yOH54uv9+eP14
fDzdPxyeTvd7YqCjK4YhgEiIx/XEnNSDdHKvjc0QQOIxzQXrpH9XRsrqW23VO4j9U1aC178mRhn9
62uiNXW2Vm/piLal/4P/btAx0Mm+owYORcMayKh1rcKRg/TwEQeW+b9Crka/w3/pNKfTadOTuqBD
FxvnfEcKsQ1tEzvfe92my25tE2MwEeqL/lHTlhWd1Woi1IK7pjNe5cXQD+M7a1+0Nvim69uunBtC
JiPtlI+F0TgyGqNhMJdp+OsOMil8dNV9gtpB33c7Cy7vbvVvevP3Nzd6axqnN9LQNzoN/MJfDtz4
Ur48pr9qc+YP9+XDU/6iNyf+8ueN/l3v3umfdmCahRxI6r9pMBzjRn9MGqBepAGQh4VTMJA39ICk
E2ID/XVFJORQVO1QXCDbZZX1ZKOisqUX+8Z3/YAdymQZUFChyXqwK1NcsX2movAHSUd9m5TvqKkx
mMY6a5KOYgJ3s5LyipdoqRuiDr1tBj8kv7X1LbRlMFFDQYklbmhs62D9qb/Q03o9Kar3zWDMEFRZ
Pt3uur7N95op3LiVX2rcDTxPE/XmW1GaY/n7ufwVdRMl+pC1SW3+WaawvvFS7j9B3bI2Q4lHvask
VhOebN11jbFd28NgMhNj3X+Wibi4aRCSnNrtJzY37gtTq41u85fz+XA+P+J2u0+rdqHYLrKvopg1
9VdTtfOmJa2KpGTQAuqyZcAvkmYtQm2obOGh+Fh25tnjhph9XZlJPWx2B6c+WtGDft4mQjYFHBKL
30ZDDR7qT59Sg3b9AW/dGniPPgdLtXVtMwzODmwEW99411v4iHUrqFeT6Nri2mm2gg1NthP2rTrd
yVYzCxj3WVrAT6zpH4s6T/2q3rA687ynos0qedFKmycUbAFYvO97hMWsyltLlyHYlQYWuiyrkyFg
TrTBRV7tQtMZZ9vnFufg3EAxEAjpIHDRm5qSywfT2hnjxkuQ3ahJsHouIumrEUllz/CiiPS85RHP
WuuhwcltULMNfQlFlYhsgDlCG5c3zTpqyi0hpBKSd0Ur7tiXiUPkyPxUZpygKPlSf4yNck1ZdOJV
iM158m1Zzh94u/mBasMzoKB56Uk22csB5zNPE3JkZNx6ThavGQHI2wtknYr71xvYA5EB4MFXEHJO
D9hw1eNfFwAjopH9P3rXQhR073BTLnniawtDZJIIiu/PU+Um+YPa8Ie5VLRIZWTdArudRDpfmCg5
4CxU8RHy6QTj6IBB9aaZCQNU2a7p1GZXPghZIh3e7b8ThO0LUhglIXQK98BiVkQ+TSbJJT7zjZnF
MkXUUmg+n4FCsmo/yN5wy3lI36iEhPksOYJ3XjLhu+zCcz6x0spJZ96Ppyy3ESWUhuwr15MRoRdC
G03gObRKcDpYCnk98sDOwnkHW/wXJ0yVH5tiDjcAa6YF43qV11fbtY2jbIaQKU9fxAI7IGEK3iOT
RuwIyEv3D2oWEzpKOkOBUaN+iFqIXJixIvHbIsE/mdXvxXpktfDxX6Pccwa0MLDRI4oGfZeWHApU
mvVHPgG35hH5JL5CCLuphceZ0kUBDMitte0pI2aGK+oKYkm1lVzwQKroCCBqnxiJFR3EQRJH7pMT
TuQ/4xh03gaf4N503S2QaM6kL9JVJD0jDHvjOAJ9TCxo77N25GQ96UdaNcuuJ3qn+iDXFg4cdWlS
pQCJIU/hcRzOWXudPqvqDrZHlt5CCT3CuS01kZkSIqdZU8Li0NVG1IiVkCX7g4qmRhNe4HbC9r5z
Seh9ahFH0QJYozum76V9Rz2VZ6PgUlLv6tITzmpvCcjYHiW1ZLD0N/dwBBjcKsoscUSal9s4YrKq
5BqrYNm3wJNgIG6wNHCEFmMixL+1hIeoRDGa+V7MW6xHGmJG+4rrIwOr207OJ9CZ0zY9S9uAXGPf
A8jNgMHm8Pnjl8f7z0/67RsIljO3awfUFRhPWSYKbmDpIszt5TbiL85jjP73Xkb5iuJoHjnSiYqh
IrN6+5msUZQa4gBqIBGgdQix70Kv7NA3JrATqe42XR6GDs7fteR8PMqCyLdi6o7Oh+ow4ny8MQ18
jcmlQ29t09MKGiZHk5RKxsQhkf5ineJ1L3A+3vRwDwvC2NGokdggDomOGVddcz66NeSl0vYohDIP
kMjmNvYkbo6z5EuqYQpz1s0DpVEPHQVDswei/OKylpJ1zgLi5o/Dk2YthR6wii7KYslJmJy2JOeR
2tmRuDYWN5JbyYmAQ3n2WLe9qBvFPSCMU9QnMqnUXFwINqLMtDgRSDb32I3QzAcuWKxyyaHEhVwq
q8Qyo3JIYfsAxDEzXtQ5xTuP8VrMToDZwtKw6nfF1cuLd3adbeww4KqRC3Hp4hHlyVQO5xrMpDqJ
ek1yiKUm3uFq5B9LSZ27Yw2d55eRFJ55TOrqF2mMcGzgXCpPorRd2kegfWorLqRDNmVmNXLHY2k1
XYZhQIqnKwX12AH64TJ1Ud2hsGb8kAvhUI626l63jZXdZrFZ9mabsJJNv2bohSiSwDzEXv2t4vae
Z9ZV7NGbcgSdF6+lVKCuFemgl8SRqoBdRrhUB84TZzNqr7HJ1Pd6PH6RiyBLiajKJeCeB/IGLJpV
TSCnEjvyXBf3qDZFvpfhe70kn/JVyTNNQNAYEDkgUYTUDODnRZ1UTGTZLCO72ogtSkMMto7sSXDv
KdMueJpDImMtiYhcIOAPskJCpWRNkmIJzigBVnHBQUsyfn7/YzA9dgNBnoQpqS7G0ZLHitSvCo1K
RzlG8aoLO1W7m6YfooWOTBeW4yrdCBHIt6cSIb18RB9L3KnBS0te7bL09GXpqY1IrwItRXYiCZbR
WLQ4L2UiaS8Jf2mV1ZWmBhMJaUQE14AHWERnuArCK0rGXmA2JIHWUl4hq9Z34t0xj0rLLSH12cJi
P/BPhI/wzNn2sOaIOqsDvHAwoKuR36Z31ylG3nz78vHDE9jCIZ9dVWWlU6ZkxBKmCI66mTrOO6YI
DkFihuDsCoKzQFPJbVBel5EfrxMEd829ERZbEMYIrjKgguBSGCxKnq7zAgSXtx95UHCaChMEl9nB
s4jtwpxVbOIZwdn/C4IDeqfUv9doZOyWqM85YGlm9JZmVhng6LqnSpGhW5hgmNxj+AZoi7PyvNTG
I+l0VUE6qwwq4A2RYoncUPsxtsUL+xK5vd+MfuH9jfjxF+C4sYY6cRkXXYXguBB7Ym6CrwH1UN/R
49dVzfJ4hm0dySRgWYrK1M2rrrp3MvcWRgNPsLZ+3A4vI6WcNk5fUBUMojsVMPA2jmqaeJPan1Ox
bepBAJClKClRcGR7dtCqEsRYNpWAzaF4koKyJ7Hwd5Z+s9BReRlAHwkUwAsRiooNHrXTL1Jk7DiO
+R4/Vwk9WR+v1dXYnYzWO1baPjraqbZ32NdRxoGfw4CMTAiqZDSmZAyElDHKlQHQ4adBCK+txkAI
j8pqJDP4+Q1L/xJY7vFUnCih3xJ1eMEn+xjfNfPPSORZs/oxSKXIq3tUr5t5E1SG8lspdY/qmrGu
bjhH3fxWykZLMs4/K/nxJ04J6uAYx6+LUPvqe3iPnxckflpKPyAxwCUZW4Xb9S9pplrSI6UEWMYP
QbqBslPVIeSleoeMSVSYVlwjXqiDxvspXlHxBAjcjUJ3qns4FEACyp9wKdUYKjKDoVoIsq35Ugmc
FwlVKFoRPBFCdUUoak94ECe9FeKR9cGBk3+i4+qlYNZVR9f7MOGInrEIFpN5RokleJaYP1kiMwL0
nrgqHFwNGzB+AFO4RtQcG9/HsIJQUT/8nxDqiCd//g+bb1BHCmVuZHN0cmVhbQplbmRvYmoKNSAw
IG9iagozMDkzCmVuZG9iagoyIDAgb2JqCjw8IC9UeXBlIC9QYWdlIC9QYXJlbnQgMyAwIFIgL1Jl
c291cmNlcyA2IDAgUiAvQ29udGVudHMgNCAwIFIgL01lZGlhQm94IFswIDAgOTAyIDU1NV0KL1Jv
dGF0ZSAwID4+CmVuZG9iago2IDAgb2JqCjw8IC9Qcm9jU2V0IFsgL1BERiAvVGV4dCAvSW1hZ2VC
IC9JbWFnZUMgL0ltYWdlSSBdIC9Db2xvclNwYWNlIDw8IC9DczEgNyAwIFIKL0NzMiAyNCAwIFIg
Pj4gL0ZvbnQgPDwgL1RUMSAyNSAwIFIgL1RUMiAyNiAwIFIgPj4gL1hPYmplY3QgPDwgL0ltNCAx
NCAwIFIKL0ltMiAxMCAwIFIgL0ltMyAxMiAwIFIgL0ltNSAxNiAwIFIgL0ltOCAyMiAwIFIgL0lt
MSA4IDAgUiAvSW02IDE4IDAgUiAvSW03CjIwIDAgUiA+PiA+PgplbmRvYmoKMTQgMCBvYmoKPDwg
L0xlbmd0aCAxNSAwIFIgL1R5cGUgL1hPYmplY3QgL1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAzOSAv
SGVpZ2h0IDcwIC9JbnRlcnBvbGF0ZQp0cnVlIC9Db2xvclNwYWNlIDI3IDAgUiAvU01hc2sgMjgg
MCBSIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUKPj4Kc3RyZWFtCngB
7dABDQAAAMKg909tDjeIQGHAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgx8Dwwf/gAB
CmVuZHN0cmVhbQplbmRvYmoKMTUgMCBvYmoKNTkKZW5kb2JqCjEwIDAgb2JqCjw8IC9MZW5ndGgg
MTEgMCBSIC9UeXBlIC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMTMwIC9IZWlnaHQg
NDkgL0ludGVycG9sYXRlCnRydWUgL0NvbG9yU3BhY2UgMjcgMCBSIC9TTWFzayAzMCAwIFIgL0Jp
dHNQZXJDb21wb25lbnQgOCAvRmlsdGVyIC9GbGF0ZURlY29kZQo+PgpzdHJlYW0KeAHt0DEBAAAA
wqD1T+1vBohAYcCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCA
AQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYOAHBkqmAAEKZW5kc3RyZWFtCmVuZG9i
agoxMSAwIG9iagoxMDcKZW5kb2JqCjEyIDAgb2JqCjw8IC9MZW5ndGggMTMgMCBSIC9UeXBlIC9Y
T2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMTMwIC9IZWlnaHQgNTEgL0ludGVycG9sYXRl
CnRydWUgL0NvbG9yU3BhY2UgMjcgMCBSIC9TTWFzayAzMiAwIFIgL0JpdHNQZXJDb21wb25lbnQg
OCAvRmlsdGVyIC9GbGF0ZURlY29kZQo+PgpzdHJlYW0KeAHt0IEAAAAAw6D5U1/gCIVQYcCAAQMG
DBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgw
YMCAAQMGDBgwYMCAAQMGDBgwYMCAAQN/YE2yAAEKZW5kc3RyZWFtCmVuZG9iagoxMyAwIG9iagox
MTAKZW5kb2JqCjE2IDAgb2JqCjw8IC9MZW5ndGggMTcgMCBSIC9UeXBlIC9YT2JqZWN0IC9TdWJ0
eXBlIC9JbWFnZSAvV2lkdGggMzkgL0hlaWdodCA3MCAvSW50ZXJwb2xhdGUKdHJ1ZSAvQ29sb3JT
cGFjZSAyNyAwIFIgL1NNYXNrIDM0IDAgUiAvQml0c1BlckNvbXBvbmVudCA4IC9GaWx0ZXIgL0Zs
YXRlRGVjb2RlCj4+CnN0cmVhbQp4Ae3QAQ0AAADCoPdPbQ43iEBhwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMfA8MH/4AAQplbmRzdHJlYW0KZW5kb2JqCjE3IDAgb2JqCjU5CmVuZG9i
agoyMiAwIG9iago8PCAvTGVuZ3RoIDIzIDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1h
Z2UgL1dpZHRoIDEzMCAvSGVpZ2h0IDEzNSAvSW50ZXJwb2xhdGUKdHJ1ZSAvQ29sb3JTcGFjZSAy
NyAwIFIgL1NNYXNrIDM2IDAgUiAvQml0c1BlckNvbXBvbmVudCA4IC9GaWx0ZXIgL0ZsYXRlRGVj
b2RlCj4+CnN0cmVhbQp4Ae3QMQEAAADCoPVP7W8GiEBhwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwICBHxjNqgABCmVuZHN0cmVhbQplbmRvYmoK
MjMgMCBvYmoKMjUzCmVuZG9iago4IDAgb2JqCjw8IC9MZW5ndGggOSAwIFIgL1R5cGUgL1hPYmpl
Y3QgL1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAxMzAgL0hlaWdodCA2MCAvSW50ZXJwb2xhdGUKdHJ1
ZSAvQ29sb3JTcGFjZSAyNyAwIFIgL1NNYXNrIDM4IDAgUiAvQml0c1BlckNvbXBvbmVudCA4IC9G
aWx0ZXIgL0ZsYXRlRGVjb2RlCj4+CnN0cmVhbQp4Ae3QAQ0AAADCoPdPbQ43iEBhwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIAB
AwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg4G9gW2gAAQplbmRzdHJlYW0KZW5kb2Jq
CjkgMCBvYmoKMTI1CmVuZG9iagoxOCAwIG9iago8PCAvTGVuZ3RoIDE5IDAgUiAvVHlwZSAvWE9i
amVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDEzMCAvSGVpZ2h0IDYwIC9JbnRlcnBvbGF0ZQp0
cnVlIC9Db2xvclNwYWNlIDI3IDAgUiAvU01hc2sgNDAgMCBSIC9CaXRzUGVyQ29tcG9uZW50IDgg
L0ZpbHRlciAvRmxhdGVEZWNvZGUKPj4Kc3RyZWFtCngB7dABDQAAAMKg909tDjeIQGHAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDgb2BbaAABCmVuZHN0cmVhbQplbmRv
YmoKMTkgMCBvYmoKMTI1CmVuZG9iagoyMCAwIG9iago8PCAvTGVuZ3RoIDIxIDAgUiAvVHlwZSAv
WE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDM5IC9IZWlnaHQgNzAgL0ludGVycG9sYXRl
CnRydWUgL0NvbG9yU3BhY2UgMjcgMCBSIC9TTWFzayA0MiAwIFIgL0JpdHNQZXJDb21wb25lbnQg
OCAvRmlsdGVyIC9GbGF0ZURlY29kZQo+PgpzdHJlYW0KeAHt0AENAAAAwqD3T20ON4hAYcCAAQMG
DBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDHwPDB/+AAEKZW5kc3RyZWFtCmVuZG9iagoyMSAw
IG9iago1OQplbmRvYmoKMzQgMCBvYmoKPDwgL0xlbmd0aCAzNSAwIFIgL1R5cGUgL1hPYmplY3Qg
L1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAzOSAvSGVpZ2h0IDcwIC9Db2xvclNwYWNlCi9EZXZpY2VH
cmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVE
ZWNvZGUgPj4Kc3RyZWFtCngB7ZbvSxpxHMe9X3r69S4vPQ9v3XJdrhW3ynSDqyaRmwo1BCXWsIQG
cxRCW2kPCqwgUfrBkoqkoBmZA2koheVQ6F/bXcMfC/Z8jF4P7tH7+/n+4D6f91uh+CeAIOjv54Ag
GEZQFKuBoggM318gaVBMhWsA0GoJgtBqAdDgKgyVlM2VYQTDAalrNdBGRsZIG1p1JMAxpFkHI0o1
QRlZztzBd8rwHWaONVKEWonAjXIwpib1rNnS02u12WVs1t4ei5nVk2qsUQ5CcULP8oJNdDhdbo/H
43Y5HaJN4Fk9gaP108EYoEx8r+gc800GgjKBSd+YU+zlTRTA6rvCKoI2C6LbHwyFv0Si0WjkSzgU
9LtFwUwTqoYMbzFZbE7/THgptpFIJpOJjdhSeMbvtFlMLThSuwOiprhucWw6vBzf2TtMp9OHezvx
5fD0mNjNURq0JkM1+vbnDt/Hpfju0Wk2l8tlT49240sffY7n7XrQkAHDk/7Rd+HYzlE2XygWi4V8
9mgnFn432v/EALB6NUDzA28Cnzf2MvnL63K5fH2Zz+xtfA68GeBpbZPMyNvd04uJw2zhulKtVivX
hexhYnHabeeNDRmmZTrtnmA0mc4Vy9Xb29tquZhLJ6NBj72TIbDa+z7IHh7k4Q/53YIPvfD/9QIK
5GkZjCTS58WbuzF4UzxPJyLBP6elLLO5phbiB2c/Sj8rlcrP0o+zg/jClMvWPFRRQHdYX7+fX0+d
fC9clUqlq8L3k9T6/PvX1g66eZIbzH0jE7MrmwffcvmLi4t87tvB5srsxEifuWngI5pWThj2ziys
be0fn2QymZPj/a21hRnvsMC1NlwGwalHXS/dk58iscT211Qq9XU7EYt8mnS/7HpEqeueBeMkw/c5
3gZC89GV2OrqamwlOh8KvHX08QzZsDZYCfRcl31kfGLqQ2h2bm5uNvRhamJ8xN7F6YGybpSQ5OHG
x8+sg6Oeca9PxjvuGR20PntslF285lkQogQ6hrMI1hfi0CuZIfGFVbBwjA4okZrJKBQwigMdzbbz
T7t7BJme7qd8O0vrAI7WiykUEIypNCRlYExsGyfTxpoYA0VqVE3BQdobkkKNlGkIUkf9RkcSUq6R
Yk1jS/mIckLCMKUKr6FSYlKkuae6u4ycppq4n6PuNP/i5xdtzIFwCmVuZHN0cmVhbQplbmRvYmoK
MzUgMCBvYmoKODc4CmVuZG9iagozOCAwIG9iago8PCAvTGVuZ3RoIDM5IDAgUiAvVHlwZSAvWE9i
amVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDEzMCAvSGVpZ2h0IDYwIC9Db2xvclNwYWNlCi9E
ZXZpY2VHcmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAv
RmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB7Zn/SxNhHMd3X57dbc/ttnN3OzyZW56Ks0ubG8LKhrhy
A9NiQzLmBhop0sCyuR8SVoFjEo0SMYeBGc0Fo9goNMNF/1q3wt0M+vGRfrjXD/frvZ/383m+fN6P
waDzPzqAIeXfI8YwHCdIEpwDJEngOIad1aL+ngQUbYaQYSxIYRgIzTQFSFVEqwacADRkbW284BAR
4xD4NhsLaUC0SsAJo8nCOSSnu0vuRozc5XZKDs5iMhK4ZgIOTKxdcvf0D3h9fsT4vAP9PW7JzpqA
ZgJG0ha7JCu+QDA0Ho4gJTweCgZ8iizZLTTZrAQcQK5dHgiEJqIz8SRi4jPRiVBgQG7nIGhOA05Z
BLcSCMeSC6lH6VWkpB+lFpKxcEBxCxZKU0Bb23t8odhcKpNdz28gJb+ezaTmYiFfT7uVJk5LkTBx
Tk9gIpF6kits7RSRsrNVyD1JJSYCHidnJk8VkGa761Iwej+Te737vlRGSun97utc5n40eMllh5oC
yF+4PHYnlS3slirVGlKqldJuIZu6M3b5Ag9B0wMoyEM34g/Xt/YrX46OkXL0pbK/tf4wfmNIFpgW
BQ7ZH048zu+UqkcndaScHFVLO/nHibBfdmgKACN2+yPJ1Y1iuXZc/4mU+nGtXNxYTUb83aIFnG5J
ugKDQfdA96CxK+l1oHug18Gf81lfC/pa0NeCvhb0e6J2VyZho19IpvPFg9q3+g+k1L/VDor5dPJs
v9BQ4BufXcltf/h8+P0EKd8PP3/Yzq3MjvtaOxYSCl3e63eXn2/ufax+PUTK1+rHvc3ny3eve7vO
dG28e3B0emntxZt35conpFTK7968WFuaHh10t3SuhLmtUxm5Nb/y7OX22719pOy93X75bGX+1ojS
2ablBwTNdfQNh2cW09l84dUmUl4V8tn04kx4uK+DMzUzFJxmRXkwOBVfWM6sZZ8iJbuWWV6ITwUH
ZZHVUhzcyPDOPv/ozenEvcWlB0hZWryXmL456u9z8oyxmWRhwGR1uDxDV8cik7ejMaREb09Gxq4O
eVwOqxpp/jmXDAaMMEJO7OxVvMNXRq4FkXJt5MqwV+ntFDlIEafHgsGAq7m2TZBccq/nooKYi55e
2SUJNjXbblqgmoADysxyvCh1OJHTIYk8x0KqJVZWJwNTnxdoM8NabRxybFaWMdNGUsu1f1dD44UF
ACNFnwOUEaiPC38JaKhQn5fwc0L91e9x6x/dgaYDvwBNTSfgCmVuZHN0cmVhbQplbmRvYmoKMzkg
MCBvYmoKOTI2CmVuZG9iagozMiAwIG9iago8PCAvTGVuZ3RoIDMzIDAgUiAvVHlwZSAvWE9iamVj
dCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDEzMCAvSGVpZ2h0IDUxIC9Db2xvclNwYWNlCi9EZXZp
Y2VHcmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxh
dGVEZWNvZGUgPj4Kc3RyZWFtCngB7ZixT+JQHMdL+56UvhZFaEmbEKuFQYNELUsXBhuFhA0GTUiJ
Djp10CAMDkwQWEhMGCBMmBAGFogDIZHk/rWreFDOuxsfNbl+hqad+u33vba/75cgXL6jAx6s/PuJ
PR6SpACAGwAAiiQ9nt+1WLcH0EszCLEshxWWRYihvRBYItY1kBSkkX9nN8QLYcwIfGh3x49oSK1L
IKktHxcQpIh8oEQxoxzIEUkIcL4tirRNIKHPH5Tk2FHiVE1iRj1NHMVkKej3QdsED6C5oKTEVS2l
X6YzWElf6ilNjStSkKPBaieQEAVEJaHp2dx1oYiZwnUuq2sJRQwguFoG0svxclxL54v35uNTGStP
j+Z9MZ/W4jLPeW0F9LYYU/X8rVmp1hpNrDRq1Yp5m9fVmLhNU8utSPkCkUMta5jP9Va708VKp92q
P5tGVjuMBBiwVACY4N5xKndXqb/0XgdDrAxeey/1yl0udbwXRLYCFNo/Ob8yq63eYDSeYGU8GvRa
VfPq/GQ/hODKA8QrZxeFh1q7P3qbzrAyfRv127WHwsWZwrNrCgQlmTZKjc5gPH2fY+V9Oh50GiUj
nVQEWwFkw9FkplhudoeT2fwHVuazybDbLBczyWiYg8tPkquAIFwPXA8+vkruPnA9cPfB5//ZfRcI
AiCn5wPwDWYkp+dEam1W7uOelft/m5Wdzwvkr8x0s6nMdPM1M61yo2HlxhLW2FguWbnR+DM3QsaJ
7MzY2dn5/oBYdCjiJjsUcdGhfP4UPo7O90iWBIe7NMsFu09kMbPqE+01WJw53al+keNe/ncO/AQ+
13PACmVuZHN0cmVhbQplbmRvYmoKMzMgMCBvYmoKNjExCmVuZG9iagozMCAwIG9iago8PCAvTGVu
Z3RoIDMxIDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDEzMCAvSGVp
Z2h0IDQ5IC9Db2xvclNwYWNlCi9EZXZpY2VHcmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9CaXRzUGVy
Q29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB7ZjvSxpxHMfP+6Hn
nXd1empeSWenRmKi6Rq2YTQ3LQwGhhSIVy0SggOLzNqIYmBcNGpjLvrhkzWcgzZIClpjwf61nYM8
I/bwGz3w9fAe3Od97++H+3y+bwhq8RAd0ADl/1+s0cAwgqLYPYCiCAxrNLe1KOVRTIcTJGkwUEAx
GEiSwHUYqoho1gAjGE7S7UbWbLECxmJmje00iWNIswQY0eopxsLZ+R7BCRihh7dzFobSaxFYNQHG
9LSJ410eXyAYAkww4PO4eM5E6zHVBA2KUyZO8AbDkWgsPgqUeCwaCQe9AmeicLTRCTBGMjbBF44m
klNpETDpqWQiGvYJNobEGscA6ygz7w3HJ8SstJRfAUp+ScqKE/GwlzdTOlUB3mZzBaMTs1Jhoyhv
A0UubhSk2Ylo0GVrw5GbVkT0jL0vnMhIb7Z2SweHQDko7W69kTKJcJ+dIdAbBShh6u6PJOcLWx+O
TypVoFROjj9sFeaTkf5uE6kqIFmH/9mktLF7XDk9qwHl7LRyvLshTT7zO1gSa3hAmoWBF+nFYunz
6fnlFVAuz08/l4qL6RcDgtnQpMAihOKZZfmgcnb5+xoovy/PKgfyciYeEiyqAsxgdYZGxZXtw2rt
6voPUK6vatXD7RVxNOS0UtjNL6mlAIJaHrQ8qP+VWn3Q8uBh9AFK1ieTmL+/yZQXb0+muoKBWHqp
+Onk+8XPX0D5efH95FNxKR0baJ6NqLKhBKJT0uZe+euP2jlQaj++lvc2palo4NaGQrC8bziZXZM/
lr9UvwGl+qX8UV7LJod9PKtuaYjeaPcMjYu5dfn9/lEZKEf77+X1nDg+5LEb1U0Vxts5d+h5ai73
+q288w4oO/Lb17m51POQm2tXt3VYR1t479BYamYhl19dA8pqPrcwkxob8vIWGldvLMqtjXP6n8Re
ptLTs6+AMjudTr2MPfE7OYbUNhQoN1ea7XL5Hj0diY0lxoGSGIuNPH3kc3WxdNPNFYIxgmY5R6/X
Hxx8DJjBoN/b6+BYmsCQm0UVgmBUS9BGa2d3j9Pt7gWK2+3s6e60GmlCizYOAYI0igQlxWFYs7XD
BpgOq5lllBRHEaBaUJeAYFolyDJQNHAogxJlaW/HSPX5+C/Mq0d5WsDUa/yL8+pV7wA0y2x6+Z3C
rQctB/4CV5OOEwplbmRzdHJlYW0KZW5kb2JqCjMxIDAgb2JqCjg3OQplbmRvYmoKNDIgMCBvYmoK
PDwgL0xlbmd0aCA0MyAwIFIgL1R5cGUgL1hPYmplY3QgL1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAz
OSAvSGVpZ2h0IDcwIC9Db2xvclNwYWNlCi9EZXZpY2VHcmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9C
aXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB7ZbvSxpx
HMe9X3r69S4vPQ9v3XJdrhW3ynSDqyaRmwo1BCXWsIQGcxRCW2kPCqwgUfrBkoqkoBmZA2koheVQ
6F/bXcMfC/Z8jF4P7tH7+/n+4D6f91uh+CeAIOjv54AgGEZQFKuBoggM318gaVBMhWsA0GoJgtBq
AdDgKgyVlM2VYQTDAalrNdBGRsZIG1p1JMAxpFkHI0o1QRlZztzBd8rwHWaONVKEWonAjXIwpib1
rNnS02u12WVs1t4ei5nVk2qsUQ5CcULP8oJNdDhdbo/H43Y5HaJN4Fk9gaP108EYoEx8r+gc800G
gjKBSd+YU+zlTRTA6rvCKoI2C6LbHwyFv0Si0WjkSzgU9LtFwUwTqoYMbzFZbE7/THgptpFIJpOJ
jdhSeMbvtFlMLThSuwOiprhucWw6vBzf2TtMp9OHezvx5fD0mNjNURq0JkM1+vbnDt/Hpfju0Wk2
l8tlT49240sffY7n7XrQkAHDk/7Rd+HYzlE2XygWi4V89mgnFn432v/EALB6NUDzA28Cnzf2MvnL
63K5fH2Zz+xtfA68GeBpbZPMyNvd04uJw2zhulKtVivXhexhYnHabeeNDRmmZTrtnmA0mc4Vy9Xb
29tquZhLJ6NBj72TIbDa+z7IHh7k4Q/53YIPvfD/9QIK5GkZjCTS58WbuzF4UzxPJyLBP6elLLO5
phbiB2c/Sj8rlcrP0o+zg/jClMvWPFRRQHdYX7+fX0+dfC9clUqlq8L3k9T6/PvX1g66eZIbzH0j
E7MrmwffcvmLi4t87tvB5srsxEifuWngI5pWThj2ziysbe0fn2QymZPj/a21hRnvsMC1NlwGwalH
XS/dk58iscT211Qq9XU7EYt8mnS/7HpEqeueBeMkw/c53gZC89GV2OrqamwlOh8KvHX08QzZsDZY
CfRcl31kfGLqQ2h2bm5uNvRhamJ8xN7F6YGybpSQ5OHGx8+sg6Oeca9PxjvuGR20PntslF285lkQ
ogQ6hrMI1hfi0CuZIfGFVbBwjA4okZrJKBQwigMdzbbzT7t7BJme7qd8O0vrAI7WiykUEIypNCRl
YExsGyfTxpoYA0VqVE3BQdobkkKNlGkIUkf9RkcSUq6RYk1jS/mIckLCMKUKr6FSYlKkuae6u4yc
ppq4n6PuNP/i5xdtzIFwCmVuZHN0cmVhbQplbmRvYmoKNDMgMCBvYmoKODc4CmVuZG9iagoyOCAw
IG9iago8PCAvTGVuZ3RoIDI5IDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dp
ZHRoIDM5IC9IZWlnaHQgNzAgL0NvbG9yU3BhY2UKL0RldmljZUdyYXkgL0ludGVycG9sYXRlIHRy
dWUgL0JpdHNQZXJDb21wb25lbnQgOCAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHt
lu9LGnEcx71fevr1Li89D2/dcl2uFbfKdIOrJpGbCjUEJdawhAZzFEJbaQ8KrCBR+sGSiqSgGZkD
aSiF5VDoX9tdwx8L9nyMXg/u0fv7+f7gPp/3W6H4J4Ag6O/ngCAYRlAUq4GiCAzfXyBpUEyFawDQ
agmC0GoB0OAqDJWUzZVhBMMBqWs10EZGxkgbWnUkwDGkWQcjSjVBGVnO3MF3yvAdZo41UoRaicCN
cjCmJvWs2dLTa7XZZWzW3h6LmdWTaqxRDkJxQs/ygk10OF1uj8fjdjkdok3gWT2Bo/XTwRigTHyv
6BzzTQaCMoFJ35hT7OVNFMDqu8IqgjYLotsfDIW/RKLRaORLOBT0u0XBTBOqhgxvMVlsTv9MeCm2
kUgmk4mN2FJ4xu+0WUwtOFK7A6KmuG5xbDq8HN/ZO0yn04d7O/Hl8PSY2M1RGrQmQzX69ucO38el
+O7RaTaXy2VPj3bjSx99juftetCQAcOT/tF34djOUTZfKBaLhXz2aCcWfjfa/8QAsHo1QPMDbwKf
N/Yy+cvrcrl8fZnP7G18DrwZ4Gltk8zI293Ti4nDbOG6Uq1WK9eF7GFicdpt540NGaZlOu2eYDSZ
zhXL1dvb22q5mEsno0GPvZMhsNr7PsgeHuThD/ndgg+98P/1AgrkaRmMJNLnxZu7MXhTPE8nIsE/
p6Uss7mmFuIHZz9KPyuVys/Sj7OD+MKUy9Y8VFFAd1hfv59fT518L1yVSqWrwveT1Pr8+9fWDrp5
khvMfSMTsyubB99y+YuLi3zu28HmyuzESJ+5aeAjmlZOGPbOLKxt7R+fZDKZk+P9rbWFGe+wwLU2
XAbBqUddL92TnyKxxPbXVCr1dTsRi3yadL/sekSp654F4yTD9zneBkLz0ZXY6upqbCU6Hwq8dfTx
DNmwNlgJ9FyXfWR8YupDaHZubm429GFqYnzE3sXpgbJulJDk4cbHz6yDo55xr0/GO+4ZHbQ+e2yU
XbzmWRCiBDqGswjWF+LQK5kh8YVVsHCMDiiRmskoFDCKAx3NtvNPu3sEmZ7up3w7S+sAjtaLKRQQ
jKk0JGVgTGwbJ9PGmhgDRWpUTcFB2huSQo2UaQhSR/1GRxJSrpFiTWNL+YhyQsIwpQqvoVJiUqS5
p7q7jJymmrifo+40/+LnF23MgXAKZW5kc3RyZWFtCmVuZG9iagoyOSAwIG9iago4NzgKZW5kb2Jq
CjM2IDAgb2JqCjw8IC9MZW5ndGggMzcgMCBSIC9UeXBlIC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFn
ZSAvV2lkdGggMTMwIC9IZWlnaHQgMTM1IC9Db2xvclNwYWNlCi9EZXZpY2VHcmF5IC9JbnRlcnBv
bGF0ZSB0cnVlIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3Ry
ZWFtCngB7ZvLTxpRGMVhHhXmAR1eIlFBBhdY1PJIlIXGSgpWNwoxtkFJG60LnURtxTSNmhihuCip
0bRM3JS2owuSCrpA09L4r3VGioBNl7dp0u8siKzm83DP4d4bfioV6F90QI1Uf/6P1WoMwwmC/Asi
CBzD1OrmWeTHE2SLhqJphmGRimFomtK0kIQ8ROMMGE5qaN1dg8lsaUUsi9lkuKujNSTeOAKG39Gy
nMXW4XDyLsTinY4Om4VjtXdwrG4CRmp1Rpuju6fP6w8glt/b19PtsBl1WrJugprQsEYb7/EHh0Ph
yBhSRcKh4aDfw9uMrIa4WQkYSXNtfF8wNBF9HE8gVvxxdCIU7OPbOJq8+RiwFtbs8AQjscSisLae
RKr1NWExEYsEPQ4z21KfQKNv6/aHYs+Eje1UZg+pMqntDeFZLOTvbtNr8NpSxLVchzs4MSe8TmcP
cyJS5Q6z6dfC3ETQ3cFRRG0CgjLae4ejzzfS+0efpBOkkj4d7ac3nkeHe+1Guj4Bbeq6PzojbGeP
pEKxhFTFgnSU3RZmRu93mWjyxgPazPsexldTh/nCefkSqcrnhfxhajX+0MebmYYJLHwgMvcyk5OK
5e8VpPpeLkq5zMu5SIC31CcgmVZXYCyR3BNPSpeVK6SqXJZOxL1kYizgamXJWiXBBCoVeAAeKK0E
6wA8gHVQ/X6GLEAWIAuQBdgnwl4ZzgtwZoJzI5yd4f4A7lCursAD8EC5qIR1AB7AOqhe2UMWIAuQ
BchC1QHIAmQBsgBZqDkAfQB9AH1QSwPslaEPoA+gD6APag5AH0AfQB/U0gD7A+gD6APoA+iDmgPQ
B/92HygUSWI9Ix6XLio/kKpyUToWM+uJZoqEoOUJwjLH8kE6LX9DirFUvpVPpQ8yxxJu4liIXyzP
7kG+cFa+QKryWSF/sPs7y3PNMy1vZcXPha9FpPpa+Cxmt5Zv8Uy4wnQNTS0kU+/Ej18kpPryUXyX
Si5MDTUxXTLX1u4eHJ8VXqXeHrzPIdX7g7epV8Ls+KC7vYFrw2S2z+UbjT5dTm7upN8gVXpnM7n8
NDrqczWyfQrfaL83GI7G55dWXiDWytJ8PBoevGdv4htJirM6ewcePJqcfhKfRar4k+nJRw8Gep1W
jqoznjLnyhhszh7vwNBIKIxYoZGhAW+P02ZgGjhXlcz6sgar3eX29Ht9fqTyefs9bpfdamBl1rf6
g23lVQGuGc5kbe+UgWfEcjo6260mjlGQ6/oE1yNQrJ4zytA3YplNRk7PUrcGkF245t61MviOXpS2
yr03OHD9p8L+y/A/cvpffgSusP+3nw/v/3MHfgJjBA/kCmVuZHN0cmVhbQplbmRvYmoKMzcgMCBv
YmoKOTk4CmVuZG9iago0MCAwIG9iago8PCAvTGVuZ3RoIDQxIDAgUiAvVHlwZSAvWE9iamVjdCAv
U3VidHlwZSAvSW1hZ2UgL1dpZHRoIDEzMCAvSGVpZ2h0IDYwIC9Db2xvclNwYWNlCi9EZXZpY2VH
cmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVE
ZWNvZGUgPj4Kc3RyZWFtCngB7Zn/SxNhHMd3X57dbc/ttnN3OzyZW56Ks0ubG8LKhrhyA9NiQzLm
Bhop0sCyuR8SVoFjEo0SMYeBGc0Fo9goNMNF/1q3wt0M+vGRfrjXD/frvZ/383m+fN6PwaDzPzqA
IeXfI8YwHCdIEpwDJEngOIad1aL+ngQUbYaQYSxIYRgIzTQFSFVEqwacADRkbW284BAR4xD4NhsL
aUC0SsAJo8nCOSSnu0vuRozc5XZKDs5iMhK4ZgIOTKxdcvf0D3h9fsT4vAP9PW7JzpqAZgJG0ha7
JCu+QDA0Ho4gJTweCgZ8iizZLTTZrAQcQK5dHgiEJqIz8SRi4jPRiVBgQG7nIGhOA05ZBLcSCMeS
C6lH6VWkpB+lFpKxcEBxCxZKU0Bb23t8odhcKpNdz28gJb+ezaTmYiFfT7uVJk5LkTBxTk9gIpF6
kits7RSRsrNVyD1JJSYCHidnJk8VkGa761Iwej+Te737vlRGSun97utc5n40eMllh5oCyF+4PHYn
lS3slirVGlKqldJuIZu6M3b5Ag9B0wMoyEM34g/Xt/YrX46OkXL0pbK/tf4wfmNIFpgWBQ7ZH048
zu+UqkcndaScHFVLO/nHibBfdmgKACN2+yPJ1Y1iuXZc/4mU+nGtXNxYTUb83aIFnG5JugKDQfdA
96CxK+l1oHug18Gf81lfC/pa0NeCvhb0e6J2VyZho19IpvPFg9q3+g+k1L/VDor5dPJsv9BQ4Buf
Xcltf/h8+P0EKd8PP3/Yzq3MjvtaOxYSCl3e63eXn2/ufax+PUTK1+rHvc3ny3eve7vOdG28e3B0
emntxZt35conpFTK7968WFuaHh10t3SuhLmtUxm5Nb/y7OX22719pOy93X75bGX+1ojS2ablBwTN
dfQNh2cW09l84dUmUl4V8tn04kx4uK+DMzUzFJxmRXkwOBVfWM6sZZ8iJbuWWV6ITwUHZZHVUhzc
yPDOPv/ozenEvcWlB0hZWryXmL456u9z8oyxmWRhwGR1uDxDV8cik7ejMaREb09Gxq4OeVwOqxpp
/jmXDAaMMEJO7OxVvMNXRq4FkXJt5MqwV+ntFDlIEafHgsGAq7m2TZBccq/nooKYi55e2SUJNjXb
blqgmoADysxyvCh1OJHTIYk8x0KqJVZWJwNTnxdoM8NabRxybFaWMdNGUsu1f1dD44UFACNFnwOU
EaiPC38JaKhQn5fwc0L91e9x6x/dgaYDvwBNTSfgCmVuZHN0cmVhbQplbmRvYmoKNDEgMCBvYmoK
OTI2CmVuZG9iago0NCAwIG9iago8PCAvTGVuZ3RoIDQ1IDAgUiAvTiAzIC9BbHRlcm5hdGUgL0Rl
dmljZVJHQiAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAGFVVuIG1UY/pM5yQq7ztPa
1S2kQ710KbtLthXdpbSaW5O0axqy2dUWQbOTk2TM7CTOTNILfSqC4ourvklBvL0tCILSesHWB/tS
qVBWd+siKD60eEEo9EW38TuTZCZZaptlz3zz/d/5b+efGaKBtUK9rvsVoiXDNnPJqPLc0WPKwDr5
6SEapFEaLKhWPZLNzhJ+Qiuu/b9bP5BPMFcn7mzvV2+5GyxySyXy3Qe+VrTUJeATRIGzat20iQaG
wU8ft+sCixyGTSQI/KLA5TaGjYYX2/g1R5PPxaA5CyyrlUIReAV4fLGHL/fgdg5QwE+SG9zUVEX0
ImvWSprOHUN7uYe5R3k3uKQ3ULPz24F1yKrOHcZ1DLW/UizEBZ4EXlELiTngR4CvNbWFTAffrtvR
HPBjRP6djep8BHg3cKpkHpwHhh+/WWmkuvidU5X8s+C3gf/GWMwc6exdU60Yekk7wd+u8LTob4hI
UjQ7nQeGH+mAWcsJPXKQSkUeTwCPA79erR0WOcCn9JnVnBO8yGftVCUm8hT85ZcKh7LAo8C/cj0p
9Igl/Vu3s50cWMjQMyIuYrE4t5x64YeF7Eo+BR5xmW6b+c5etlzSDqY7+k8qZkrwYu+1uu7MKHIL
+M1GTtSOWIHJgplIAsNnIMuNedFPgZu04CsQpxotYlXJoE1SKEdJiuJaJxOWEmmkg+GwcjAcd13N
hLPPoip4jZqOzcKadZTtnV2tQmWwBl13tCrFQh9RA54q9AfYiutToRjuGuDK/+OnncuNjp8aG2Fh
thf/+9gs28+m2Qwp7Cn2NDvA4mBn2D7XdxZ7uhWJfG4gStvPy4jIHd0Car+IGm0qYP0FihpZroe+
riyPNsY8yxnzBU298sbfPb3SsLPqKib6OnrkXj0P/Ba4HljFuh7YcH0ogZ8CG/hbR2+8WmqevdNl
cVIaTrTWp9t6Fl1VBJXqzs4ldEFDzbyn5oleH5dOf/mgF22VnXv+6tCl0yVjedRjRRf4q5lbGToz
7rHhH8N/hlfD74U/DP8uvS19Kn0lnZc+ly6TIl2QLkpfS99KH0tfuPq7zZB79iQyF3Ml8hbT1a2w
t9eYWDkqb5cfluPyDvlRedZVKfKIPCWn5F2wbHfPzZtvpbdy9OUoonX7c+dY4lnRXE84A9/9mADN
i9g3A/PIWKPj8Gmi32LeDDoJbe+T16mIhdgUS2+Z7mkx813fwUQwHoyQEtwdnAlOBQ8J3H2Wg7tg
m8Ga6M0N8+Eq+irlNj8hvicUq9VPmlq5Yit7wuEnlQg+fVxJG+rkuFLQdcUxWYrJLW42eXGSxHdT
7CO6mXO+h75tVzzOfoZo/194933vcccaRCsW0cjjHjeGd+UD7xKde0JtmM22P/L5viOySnv3OPe+
oSjeXz+3WjfxHht4i2jzzVbrn/dbrc0P4H+D6IL+H6CffFUKZW5kc3RyZWFtCmVuZG9iago0NSAw
IG9iagoxMDc5CmVuZG9iago3IDAgb2JqClsgL0lDQ0Jhc2VkIDQ0IDAgUiBdCmVuZG9iago0NiAw
IG9iago8PCAvTGVuZ3RoIDQ3IDAgUiAvTiAxIC9BbHRlcm5hdGUgL0RldmljZUdyYXkgL0ZpbHRl
ciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngBhVVdaBxVFD67c2cDEgcftA0ttIM/bQnpMolWE4u1
2026SRO362ZTmyrKdHY2O81kZpyZ3SahT6XgmxYE6augPsaCCLYqNi/2paXFkko1DwoRWowgKH1S
8Dsz22R2QTLDnfnuueeee8537rmXqOtv3fPstEo054R+oZybPjl9Su26TWlSqJvw6Ebg5UqlCcaO
65j8b38e3qUUS+7sZ1vtY1v25KoZGNC6huZWA2OOKKURZWqG54dEXZcgHzwbeoxvAz85WynngdeA
ldZcQHqqYDqmbxlqwdcX1JLv1iw76etW42xjy2fObrCv/OxG6w5mJ8fx74XPF0xnahJ4H/CSoY8w
7gO+27ROFGOcTnvhkXKsn842ZqdyLfnJmn90qiW/UG+MMs4SpZcW65U3gJ8AXnVOF4+39Ndn3XG2
00Mk9RhB/hTws8Ba3RzjPKnAFd8tsz7Lw6o5PAL8MvAlKxyrAMO+9EPQnGQ5sKDFep79xFoie0Y/
VgLeBnzItAu8FuyIiheW2OYg8LxjF3ktxC4um0EUL2IXP4X1ymisL6dDv8JznyaS99Sso2PA4EQe
rfujLIc/cujZ0d56EXjJb5Q59j3Aa7o/UgCGzcxjVX2YeX4BeIBOpHQyyaXT+Brk0L+INyCLmhHy
yMdYDX2bCtBw0Hz0DGgVgHRaAColtEz0WCeeo1IVPZVmollBhNjK/ahvUH7Xp9SAtE7rkNaBXqNf
Isk8/Upz6OchbWBspsNuHl44tAgP2BO2+aBl0xXbhSaeRzsoJsQrYlAMkSpeFYfFITEM6ZA4GM2J
vU/6zn4+2LD0LtZN+r4MDkKsZ8MzB6xwNAE8+AfrzkaaCbYu7mjs87yP3j/vv2MZtz74s429APox
J7/BogtrJiXmXj/3TU/CQ3VFfPXWne7r5+h4MktR3qqdWZLX5PvyCr735NWkDflneRXvvbZcPcoL
/5O5zSFGO5LNQc48m1G0ccYbwCG4qUVz9rdZTLLptmK0YMlClJ2ruP/LCfPDPLexUnMu7vC8tz9j
Ns33ig+LdL5Pu6yta59oP2p/aCvax0C/Sx9KX0rfSlekq9INUqVr0rL0nfS99Ln0NXpfQLosXenY
SXHsG7sHfsZ71mjtMGaGsxQQ88LazApLH/F3BmOb+TOh1V4Dnbt/Yy3liLJTeUYZVnYrzykTSq9y
QDmsbFcG0PqVUWUvRnZusGRjPc6AhX+SZ4umI67iPLFXdbDnw0sd76ZfXMPWhjXYST0Ontnapg6v
EVe/FVVjvDtdnAY6TSFii84ich86nB8nqv7O2VyTODVSb+KUsMQu0S/GWjWYEwdQheNt9TjIVZoZ
yQxncqRmejNDmf7MMcZRrNH5ktmL0SF8RxLeM8sx/5s1xGcY7x3mqAlso4dbKzTncd8R5V1vwbdm
6qE6oGkvqTlcr6Y65hjZPlW3bTUaClTfDEy/aVazxHc3zyP66/XoTk5tu2E0/GYso1TqJtF/t4+T
NAplbmRzdHJlYW0KZW5kb2JqCjQ3IDAgb2JqCjExMTYKZW5kb2JqCjI0IDAgb2JqClsgL0lDQ0Jh
c2VkIDQ2IDAgUiBdCmVuZG9iago0OCAwIG9iago8PCAvTGVuZ3RoIDQ5IDAgUiAvTiAzIC9BbHRl
cm5hdGUgL0RldmljZVJHQiAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAGdlndUU9kW
h8+9N73QEiIgJfQaegkg0jtIFQRRiUmAUAKGhCZ2RAVGFBEpVmRUwAFHhyJjRRQLg4Ji1wnyEFDG
wVFEReXdjGsJ7601896a/cdZ39nnt9fZZ+9917oAUPyCBMJ0WAGANKFYFO7rwVwSE8vE9wIYEAEO
WAHA4WZmBEf4RALU/L09mZmoSMaz9u4ugGS72yy/UCZz1v9/kSI3QyQGAApF1TY8fiYX5QKUU7PF
GTL/BMr0lSkyhjEyFqEJoqwi48SvbPan5iu7yZiXJuShGlnOGbw0noy7UN6aJeGjjAShXJgl4Gej
fAdlvVRJmgDl9yjT0/icTAAwFJlfzOcmoWyJMkUUGe6J8gIACJTEObxyDov5OWieAHimZ+SKBIlJ
YqYR15hp5ejIZvrxs1P5YjErlMNN4Yh4TM/0tAyOMBeAr2+WRQElWW2ZaJHtrRzt7VnW5mj5v9nf
Hn5T/T3IevtV8Sbsz55BjJ5Z32zsrC+9FgD2JFqbHbO+lVUAtG0GQOXhrE/vIADyBQC03pzzHoZs
XpLE4gwnC4vs7GxzAZ9rLivoN/ufgm/Kv4Y595nL7vtWO6YXP4EjSRUzZUXlpqemS0TMzAwOl89k
/fcQ/+PAOWnNycMsnJ/AF/GF6FVR6JQJhIlou4U8gViQLmQKhH/V4X8YNicHGX6daxRodV8AfYU5
ULhJB8hvPQBDIwMkbj96An3rWxAxCsi+vGitka9zjzJ6/uf6Hwtcim7hTEEiU+b2DI9kciWiLBmj
34RswQISkAd0oAo0gS4wAixgDRyAM3AD3iAAhIBIEAOWAy5IAmlABLJBPtgACkEx2AF2g2pwANSB
etAEToI2cAZcBFfADXALDIBHQAqGwUswAd6BaQiC8BAVokGqkBakD5lC1hAbWgh5Q0FQOBQDxUOJ
kBCSQPnQJqgYKoOqoUNQPfQjdBq6CF2D+qAH0CA0Bv0BfYQRmALTYQ3YALaA2bA7HAhHwsvgRHgV
nAcXwNvhSrgWPg63whfhG/AALIVfwpMIQMgIA9FGWAgb8URCkFgkAREha5EipAKpRZqQDqQbuY1I
kXHkAwaHoWGYGBbGGeOHWYzhYlZh1mJKMNWYY5hWTBfmNmYQM4H5gqVi1bGmWCesP3YJNhGbjS3E
VmCPYFuwl7ED2GHsOxwOx8AZ4hxwfrgYXDJuNa4Etw/XjLuA68MN4SbxeLwq3hTvgg/Bc/BifCG+
Cn8cfx7fjx/GvyeQCVoEa4IPIZYgJGwkVBAaCOcI/YQRwjRRgahPdCKGEHnEXGIpsY7YQbxJHCZO
kxRJhiQXUiQpmbSBVElqIl0mPSa9IZPJOmRHchhZQF5PriSfIF8lD5I/UJQoJhRPShxFQtlOOUq5
QHlAeUOlUg2obtRYqpi6nVpPvUR9Sn0vR5Mzl/OX48mtk6uRa5Xrl3slT5TXl3eXXy6fJ18hf0r+
pvy4AlHBQMFTgaOwVqFG4bTCPYVJRZqilWKIYppiiWKD4jXFUSW8koGStxJPqUDpsNIlpSEaQtOl
edK4tE20Otpl2jAdRzek+9OT6cX0H+i99AllJWVb5SjlHOUa5bPKUgbCMGD4M1IZpYyTjLuMj/M0
5rnP48/bNq9pXv+8KZX5Km4qfJUilWaVAZWPqkxVb9UU1Z2qbapP1DBqJmphatlq+9Uuq43Pp893
ns+dXzT/5PyH6rC6iXq4+mr1w+o96pMamhq+GhkaVRqXNMY1GZpumsma5ZrnNMe0aFoLtQRa5Vrn
tV4wlZnuzFRmJbOLOaGtru2nLdE+pN2rPa1jqLNYZ6NOs84TXZIuWzdBt1y3U3dCT0svWC9fr1Hv
oT5Rn62fpL9Hv1t/ysDQINpgi0GbwaihiqG/YZ5ho+FjI6qRq9Eqo1qjO8Y4Y7ZxivE+41smsImd
SZJJjclNU9jU3lRgus+0zwxr5mgmNKs1u8eisNxZWaxG1qA5wzzIfKN5m/krCz2LWIudFt0WXyzt
LFMt6ywfWSlZBVhttOqw+sPaxJprXWN9x4Zq42Ozzqbd5rWtqS3fdr/tfTuaXbDdFrtOu8/2DvYi
+yb7MQc9h3iHvQ732HR2KLuEfdUR6+jhuM7xjOMHJ3snsdNJp9+dWc4pzg3OowsMF/AX1C0YctFx
4bgccpEuZC6MX3hwodRV25XjWuv6zE3Xjed2xG3E3dg92f24+ysPSw+RR4vHlKeT5xrPC16Il69X
kVevt5L3Yu9q76c+Oj6JPo0+E752vqt9L/hh/QL9dvrd89fw5/rX+08EOASsCegKpARGBFYHPgsy
CRIFdQTDwQHBu4IfL9JfJFzUFgJC/EN2hTwJNQxdFfpzGC4sNKwm7Hm4VXh+eHcELWJFREPEu0iP
yNLIR4uNFksWd0bJR8VF1UdNRXtFl0VLl1gsWbPkRoxajCCmPRYfGxV7JHZyqffS3UuH4+ziCuPu
LjNclrPs2nK15anLz66QX8FZcSoeGx8d3xD/iRPCqeVMrvRfuXflBNeTu4f7kufGK+eN8V34ZfyR
BJeEsoTRRJfEXYljSa5JFUnjAk9BteB1sl/ygeSplJCUoykzqdGpzWmEtPi000IlYYqwK10zPSe9
L8M0ozBDuspp1e5VE6JA0ZFMKHNZZruYjv5M9UiMJJslg1kLs2qy3mdHZZ/KUcwR5vTkmuRuyx3J
88n7fjVmNXd1Z752/ob8wTXuaw6thdauXNu5Tnddwbrh9b7rj20gbUjZ8MtGy41lG99uit7UUaBR
sL5gaLPv5sZCuUJR4b0tzlsObMVsFWzt3WazrWrblyJe0fViy+KK4k8l3JLr31l9V/ndzPaE7b2l
9qX7d+B2CHfc3em681iZYlle2dCu4F2t5czyovK3u1fsvlZhW3FgD2mPZI+0MqiyvUqvakfVp+qk
6oEaj5rmvep7t+2d2sfb17/fbX/TAY0DxQc+HhQcvH/I91BrrUFtxWHc4azDz+ui6rq/Z39ff0Tt
SPGRz0eFR6XHwo911TvU1zeoN5Q2wo2SxrHjccdv/eD1Q3sTq+lQM6O5+AQ4ITnx4sf4H++eDDzZ
eYp9qukn/Z/2ttBailqh1tzWibakNml7THvf6YDTnR3OHS0/m/989Iz2mZqzymdLz5HOFZybOZ93
fvJCxoXxi4kXhzpXdD66tOTSna6wrt7LgZevXvG5cqnbvfv8VZerZ645XTt9nX297Yb9jdYeu56W
X+x+aem172296XCz/ZbjrY6+BX3n+l37L972un3ljv+dGwOLBvruLr57/17cPel93v3RB6kPXj/M
ejj9aP1j7OOiJwpPKp6qP6391fjXZqm99Oyg12DPs4hnj4a4Qy//lfmvT8MFz6nPK0a0RupHrUfP
jPmM3Xqx9MXwy4yX0+OFvyn+tveV0auffnf7vWdiycTwa9HrmT9K3qi+OfrW9m3nZOjk03dp76an
it6rvj/2gf2h+2P0x5Hp7E/4T5WfjT93fAn88ngmbWbm3/eE8/sKZW5kc3RyZWFtCmVuZG9iago0
OSAwIG9iagoyNjEyCmVuZG9iagoyNyAwIG9iagpbIC9JQ0NCYXNlZCA0OCAwIFIgXQplbmRvYmoK
MyAwIG9iago8PCAvVHlwZSAvUGFnZXMgL01lZGlhQm94IFswIDAgNjEyIDc5Ml0gL0NvdW50IDEg
L0tpZHMgWyAyIDAgUiBdID4+CmVuZG9iago1MCAwIG9iago8PCAvVHlwZSAvQ2F0YWxvZyAvUGFn
ZXMgMyAwIFIgL1ZlcnNpb24gLzEuNCA+PgplbmRvYmoKMjUgMCBvYmoKPDwgL1R5cGUgL0ZvbnQg
L1N1YnR5cGUgL1RydWVUeXBlIC9CYXNlRm9udCAvT1lFSVlSK0hlbHZldGljYS1Cb2xkIC9Gb250
RGVzY3JpcHRvcgo1MSAwIFIgL0VuY29kaW5nIC9NYWNSb21hbkVuY29kaW5nIC9GaXJzdENoYXIg
MzIgL0xhc3RDaGFyIDEyMSAvV2lkdGhzIFsgMjc4CjAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCA3MjIgMCA3MjIKNzIyIDY2NyAw
IDAgMCAwIDAgMCAwIDAgMCAwIDAgMCA3MjIgMCAwIDAgNjY3IDAgMCAwIDAgMCAwIDAgMCAwIDAg
NTU2IDYxMQo1NTYgNjExIDU1NiAwIDAgMCAyNzggMCAwIDI3OCAwIDYxMSA2MTEgNjExIDAgMzg5
IDU1NiAzMzMgNjExIDAgMCAwIDU1NiBdCj4+CmVuZG9iago1MSAwIG9iago8PCAvVHlwZSAvRm9u
dERlc2NyaXB0b3IgL0ZvbnROYW1lIC9PWUVJWVIrSGVsdmV0aWNhLUJvbGQgL0ZsYWdzIDMyIC9G
b250QkJveApbLTEwMTggLTQ4MSAxNDM2IDExNTldIC9JdGFsaWNBbmdsZSAwIC9Bc2NlbnQgNzcw
IC9EZXNjZW50IC0yMzAgL0NhcEhlaWdodAo3MjAgL1N0ZW1WIDAgL1hIZWlnaHQgNjQ0IC9NYXhX
aWR0aCAxNTAwIC9Gb250RmlsZTIgNTIgMCBSID4+CmVuZG9iago1MiAwIG9iago8PCAvTGVuZ3Ro
IDUzIDAgUiAvTGVuZ3RoMSAxMDMyNCAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHF
egt4VNW1/9rnOa8kM5PMM5mcmcxMJo/Jk2RCSCCHkEAgGQgBQoKJJoRwAxc00BhACqWiBoJWbKsg
8r9qxX8pXvufBIuDXv1zufRqFb6LYi9WUestWq2m1F58wpy5a58JKeR6/fi++vXOyTprv87ea//W
2mvts08G1t/aC0mwDVhoXtbdvxLUX/YdAOR0z9ru/kQ+7SDykz2DA+5Eng8CsDtW9v/d2kRe8xSA
fs/frdk0/rzlAICxr6+3e0WiHi4jD9GCRJ6UIff1rR3YmMinNSHvWHNLz3i9ZQDzxWu7N46PD+cw
7765e21von12B/Kc/lu+Q9vhL9uAt+b+9b3j7UkbyncGCJba4DbQwhrQAANGvFBC8QP9HuCwltYj
/XO9ft9NKdWfgkmDBQA/CRRuo/zM9hdWf37uckC/VTsb22nV9rQCnxFylVwAA8H6N/VbJ2poLf3Z
otCRH4UWpAakGUhlSHn5Ixr5GbIb0jovyloicaCXXnf88XlSiDp4X71HSKFsSAJtz/ZqqWf79obc
mVrSCBUcAYnUg0/ldaO+J6QomTHq8yKbnmDMaIULcyBrK3xSrGK5dLkiqiFyuvSF70fS50if+Wqk
T30l0ivY7nTFHOnUTKwflV7OizLIXvJFOSKnSC/6vi/9oiJXeqqiShoNYNmoNDIT2RHpQMX3pcfu
UEt+kqeyR31Rsm9UeoSyI9LD2P8D29WK+xMP3p5g/XeoA91yWGU3H44yTxyR1vqypeX4IJH1Uqdv
jdThq5QWz4wS/6gUpo8dkZoCp6RGOvSoJCcGCiV6L/epEpcmhg36npVyEiNk0dZyquT2NUku7D/4
yANS0HejNDMvSg4+3ZCT52sIPBCKkovqGJShoJTdnGA9gefIT2EO5JJl4CcPHm7IRZnJ7lFpO7J9
hxtyKvxR9gPZLB0ONATuQAoh+ZGWRMliOSjuEVeIS8QpYr6YK2aLHjFTTBfTNGaNUZOsMWh0Go1G
0HAaRgOatGj8t3I+taQ0wUiZwNE7p6aNDE3jDe/AEA0D8yAqwJ3WwRp7jXmGqXJ23dfcutTCrrr8
v/zsf0nm24kr8kDjorbIIVd7pJQm4q72q+r/mmRvLT7d2LLpcMumj1rre731Xd76XqSuyK7BPntk
23K3e+SjTbTCHWGzu5b39FHe3RvZ5O2ti3zkrXOPtKjPTapupdUt3roRaK1f3DbSKvfWjbbILfXe
7rr2w831DfOvGWvnxFgN9V8zVj3trIGO1aw+N2ms+bS6mY41n441n47VLDerY+Xn169aVAv8MTDx
x6GA3wMurhZcAPE3kN6kXFkUv8CfBl08Fh9j0buRLErvXCJp8P9AhKdhK3qcV+EQ0YIXxkgp/Ia4
SB68Dgq8Cf8BTtgFj+C9Hj4gn6Gn+ZDkYJsQ3A7/AA/H+6EfavD6gPBgganwYXxz/MX4l1ALw3CC
iCSVuOJHoQiG8NoH+4mBWR4fATs0wQbYhn38Ct6Ij8b/gP2H4D1iIkVcVfwtNDAeSyphJxyCp4mH
eEkeuSH+HpbbUcYOOBQPxwfxuQvYqgjmw2Yc7V0ikWyST/aRt9mx+Lb4D3BuGVi3BHrwWgvfh72w
H55UWy3nMngL9l8HjVj3AzgJH8Cf0enmklqykfk1+wf2T1wVty9+AuVYguN1wcOERVR8ZAlZQfrJ
k+Qp8i/kM6aC6WYr2V9z/dyjKNsS2AGPwnPwApyBt+AjGIOvIEY4lGkGWUA2k/+Dz/0HM4XpZLYw
dzNvMBfYEvZtTuR28Xfyz8a5+K/jX6HMmZAHVbjSF0Ib9OK1Em6GW+F7cAcRYQ+MwL+gtO/AO0RH
jKSIlJA5ZDG5gfw92QT3kQPkGXKOnCfvkw9RulRGYrxMETOI493O7GSeZEaZo8wYa2IH2C3sMfZt
9jPOwnVyx/B6hy/gB4QMoVFcqPxYeSdeEN8d34d6seLlg1wogBmEQxTXwh2oyZ2I2X44AE/Az2EU
RuOXSCWcgFdQrnfhAnyOGsvAy0NKyVTSTBaihGvIWvI9shclPESOoJTPkmfhLDlLLuGlgIPRMgXM
DUw3swmvfbCXOaPiY2A9bA5bwDayi+KfsE+yI+yfOT+3jFvHbeaGub3cw3wGP51fyi/j+/n7+SP8
y/y/8xf4i4JLGBIOCE8JZ0SNWCbuFRWShbK4iR+egufR6h5g+zHvg1nkDtRqK5xE6x2DX8Il+BKO
wU+JCxSWajM7/ihE4ztQm8/BL9jvQjXcx/yImRevYQ+yWlIa/xz7KkZ9TVxyXm5OINvv82Z53FKm
KyPd6bDbrJa0VLPJmJKcZNDrtBpR4DmWIRCs987uckeyuyJctrehoYDmvd1Y0H1VQVfEjUWzr20T
cdPnurHqmpYytlw5qaWcaClPtCRGdzVUFwTd9V535FSd1x0lyxa2YfqeOm+7OzKmpsNqereaTsK0
x4MPuOvtfXXuCOly10dmD/YN13fVFQTJURmDga4gCEcBZNDTjiMwq3sLOleYRVvUR5zeuvqIw4tp
rGP99d0rIs0L2+rr0j2e9oJghMzq8S6PgLc2kpI//jh9Dp2gv6UNxy4Iroqg/LDLsMK7YldUhuVd
NNXd0RZhu9sjTBcdw5QfsXnrIrbb3rP/JXslVX/3VZURxj+7u3d4dkTu2oWg02wXzXXfjbnGRW7s
lrmzvS1C7kThqBCq7IlZJMKEv2u1O6L11nr7hld3IebQ3DbqlJ313q669gi0tI06ZIeaKQgetW+t
8iAoRwtmFsykvMpj35rgv9+eKH/1GOX2rSd+i7yxZQIXQsf2zkUxI+4eHASxQFmn0lvvVBjumYrw
4a+d4CxXoTyzIgyaEuuP8P653ZFti8bF6O6rGxdudd2o1uFU41JtO7bvGjZOQwVie6PXPfwpoGa9
Yx9fW9I9XiL4jZ8CraT6nzChCOm+kh6k8dOPIanP7u2j6htUVY15r73+qgLM07hVgBvOYGMUtM1t
I4T8oD1K4ndGoc51FAMMe9ONWJ1PDW5VHQ6HmWAQC/I8mEIJZuNAs6lluIfdw3NXDLtnu/vQpDi/
yrGid7i9CAFb1IawwOI2T0RuT59I9ra3T8N+Cmk/+Ag2H27HHlaP94BcLSqKYaOiYCPOKru5bWFb
ZFtdekSua0fQ0YiPNbdFjqH9trdjq+IJSVHiLavs4zKXoMzFeVhfmugFtzXbsIv24WHa56I2rydy
bHg4fZiuukQed8iTC+TxgijQJhThKNnWjM8i83rSVcg9Xg+K1U4xnYIGfMWAcFv/zQiXT8iNT4ZQ
2nIV4YpvCeGp14Nw5XUhPG1C0msQrkKZp1GEq/92CE+/BuEZ34xwzYTcKKSM0taoCM/8lhCuvR6E
Z10XwnUTkl6DcD3KXEcRnv23Q3jONQg3fDPCcyfkRiHnobRzVYQbvyWEm64H4fB1ITx/QtJrEF6A
Ms+nCDf/7RBeeA3CLd+M8KIJuVHIxSjtIhXhJd8Swq3Xg/DS60K4bULSaxBuR5nbKMLLJhCW0yNw
tR/eNsntwrfumG+4BvKOb4a8c2IiKPWNKH6nCvlN3xLkXdcDefd1Qb58QtJrIO9BmZdTyFf8L0Le
exXkwL8A+5hKoLwMqQNpP98KjyN/DHkR9x2o4n4Hm5HPQV6DvAjb70TahfkhpFqkLawLbse6WuYQ
WGge0xbc/ybO6/DQDQR8vwBwwzJ6QPJX/ugxC4vv5vz/2I8wXiN+bQsNbqZ0oEepEr8klSXjPQVP
G03IzZAKaeoMaJWV3qAMr+OkjAyTf2KCzFY2i72N/YCr5f6d1/F5/G38aaFQ2CgoYoO4X1OGb737
ENXpePbA4rvrDNnDCy58t+FEFws6nnOxLOPUCqKLgEOjPeRZU40HP/MvVodj1fONn1WHjbFqqKmO
VVMqKZ5i8pgCSPu4x6KXT/HHv5oR5Vou/ZxKxaJUwB/EcRh1Tufkv+9jSIDP0U0VKrQNQp9uo24H
t0PYx97P7RUOsY9zB4UoiepeJC/qXmdf11mIKAgMaLRavOmIyDNpOp3fjNk0nvebsU7U5NEzLZ0e
X84ErY7lNfokm82p13ECHyVpo1qWQXZE5zD03rrenj8433jRHo5VVuKfqdKB5zZ179uLoMZWHa6p
rjZXVhbhlPihwvwtxkbcPnLH0iPcifahQvt4AYsF7Il2E7bEvyFjdbWIVFJMOqGTePT48uzBl18P
YYrIYPQJ0sHolNGbYu+uVJ5nnsF35Tqy8KsZpEh5RUWkI36W38xfwLMDCQbk3KW6H4s/1rA3MO3p
ba6V3Aayk/9Z2ij3tO5fuRf0bzBvpr1lfyf9C7vRFiV62evUaJyGmRLLmmc6tZK1wqapkDJFpyel
ItPh9jzoebJV1Vl4DDUWNlWOvTaG0xyrqR4zVxYZxxISmytCHrfNavNkB7K9WYwlzTqltCJU4RHA
4w5km0jHvz1FrGTgH28SlZOZRYsfP3j81D/8ZEmRREpylKeVuHL8yBFmN7f0lSMXdw6vDnUpn3zx
xeerK9d/orx68hTpZZ2o9f2o/804Wy2emy+SSzeYiagJiAFDm3m1eTN3NzvMDZv3snu5veYn2SQm
z6LNszIWjVBhdDqI3+KwO6LEfdjTMj6ZGJ3MGNTUjF2ZAjF5UOTysmxvCCdiNVuMIpOLheQFkvFG
a9E9rz53w0Nd4amDjyijsTuZzdzxyzPODj727idK5pQdN8dhQHnjpDKG8lFv8DjKymBaD0X0lP0Z
dAtaaMRTdsEYxa8X8AyuFQ0WPIMtQOV0nTfmF5cQD9r/+MW9ffkiczJWxhZfeoyr5J5TXoiDcqfy
OR2EgcdwjHWY1OHpQ5uc5/am2y18IDU7j+DxRV4uE3BpXO6sVMGWJVTY0pcanUEI+HMc+cEoybwK
B7oOw+dPxE6gJZoqK3E11lDFxipNtkrU7TgoqNWQ1ZZJLGmCmIlHJmkIkYUqu4gUEq8qLzlNOvvK
OtpLV7z502nFU1fftnKJxhBUnkwWDIRhenYox5UzzBnuuDJgz/vuXYXO2Oy6qTuWrno5L3fPQz29
vsp0f0nmjJk777kx9jzOiuC5HvBVmBJgg+wp5Ti/mRf4UkL8ZiwSWB4/NzAso9HgGmWARIlplOVx
yZuOcA7xv63Q8fVJZ1dNVyc/FL6yMhlciMzXrEycPK5BvNhLRFa0yltKMplLZOqV+OOXHlV9UlX8
bW4qdxMk41niNLhXXlDFlIc2kZ2Eez2TZP/n+3m/9yYn8XiamerMxzMhLrswuzCPFnDp+qx0a3Ca
JObp9MFS/bTUMIQLp5Xnzch2VjvD6QWacLmjqvqfiAM80EB+DuNL8KK6CM+bKk+99566CtFxnqo0
mW3UiRDKKeWPu5FkkkIEUVBXY6giEEqYd5YoiB5Me0rxZMqUhlpFVRaSALb0ZmWXl+G6TWXeTq8o
lpcFahdO63iIfXJB1vTOZb15mTplTDtnHUk9vGsXw2ZkKC8l6diqcMfAj//5oSWP9zNmk0VrMNoC
LXNnrrn3gi7FWTFrSqm/5t6O3XPm/FIxlM2bmpOU55nmlwvKf/bQr5aVWMhrCCPa8ub477j9/DGM
R26olf1atz7ZbACHzyzqdW4fr7fcwTizXJJOSgroHZ6svZ7m+QlAYhfPjy/kMVzKNSacPlotmC1p
jDcrkB2wUNPEuU4x48qmrimBBvuz//zT2aGWkkrlQ5IRmhne4L8ts/LBh6Zlfvd73DLlpU8VZTTk
bt7JH4tdbMopvTwwet9A0+57GjfcHU3IOyf+BleGenehx71Zrn/QetDKDGWQuZY2c595o26TOWp5
IfVFi8bOCJzrVc6X6RStyTqD8WmDL02faQylSBDKtLmcbk3I5pDcQ56G8fmM+9jYRdXHjuGCrERH
q3Kq03UYG1QPS6dhQx9LXawoeNxMuRGmlHI2who1nuLe3eUZGVPuWbFYS7y6xXcpXypffkHMn5wi
vF1JZ56dXlJ7b9PWjXN3rGm9feBZMvVL4iBTox+SA6ouatCme1EXRpzdAjn4gQEjp8XFGFmw+Yyi
oHP5dHoL60yVBIkNcE7JGUpyZEp7PQ31V4UJ1AtqgoaJhFbQPFEtnWC1UedWnky8WUBFvqIW1UaZ
2/bhmlM+mr5/4P8rlwg5+/TW3hktW27dsInrWBpmNF/Je7rbSPmfiY3Il9c/de+LrWXP3b3nF7g3
KIqf46ahPjDcQBY8Ic+drRlK20MexNhNtLxg5J2N/GzjXPdd5M6UIUnHWllbqjXV1qBpsjbZ5jo7
rB22Zc5z5E3uQ9fv3Z+7jfPIbOMOfruRw5B/vzxlQfJNybcks8nJ6YIvyyPazMF0vZVlstiQbXNW
Zpdhm4ExOH2MlHx/psPrQyiuWCc1zk6MmefHihJwnEqEzc4YorGuk6zrBFyL6EHRueIlevA2Hjjp
YgSTEaoIOb02mTwrbr5hxxtz5FQ9E7MK3VWL2ioybcSrX3b35dPKcSK9l8YOfHf1uls/Wnlz97bG
ew7U5pamF3eveJgY0EGn4+dbVbc7MTgd4l9W92pVclYTNJEO6MBPFCPokgRRp0VnCkKAiLhZG/U0
JzSqbtbo9gajZU0YAz7doGBcpHRIeQc1phKHn3uUDZdw+0vwixEQuldjwS+nonfW8bTjAHFw/ES3
4Zi6Z8JOS4rVOHtQ+R1x4UPoD4YAuG7UpxVjfaNcwBML8ZMK0qbv0wvEbBS0PgQrmdPZ+JAthXE6
TMmBFIzwz18RORw7Qd0CblbQSaLLH6uppMEM7c+C9nfFEVBTtFDnEGCHzyrnbHmD94UylPMktaKk
bWgV1zFyKpbF7GktXLx5Zm9slJMfXuyvZRFHFmpx/e/nejF62/CLVFjOsbFEY9hh2GFkbUn2lJVJ
LO+zp4l6X7LebtcwIZvTqQmZHA5nlAwenjAPdbHj2h7fTqGA62H9Op+6B8lSV4QPt09QXkbvFsJ8
dNddW7YMDW1hCpWPld/j9TFJw6XrIGmxM78aPXBgZOTAgdGVyhNkyZ8+JsuU//sxIyOWW5RF3D5u
GX7Fd8M8OdeWqtFlOBmfW3QKOl+q3pGsSbInhYzOLEFKl+wBx9f6V9V61dWMLjaxmMedqeqFys3U
VFWPOwEqO/Cd76NH7a1u2bDFRbRK7OTtrUUFyvvEVFh203bm4eM/mr/x+XBB9EGmUnlfuaD8Vnl1
pq8+9iJ/4dE5uXMRZrSj29EYLnEd+JYy7yiwZM5hJiUJY/wc2ZEqJgkGnZspZmSGtdA9QLI+YHCk
WaJkxWFP88rx8HDiNdXIwp3UdhHq16j5ohPCJUdDwYSwzFv61PS8pH+s8ijvEmNtSfM2roMQ5RzL
9Ndsj33O1T6/NmcWlYlB3b+J36C6IR+CsFVeoDUK2Y4kVst59PpG3Vz9HE+duyH3LKtxZbkNOs6a
z1mdwaBZ5II5+mAwxaJzu6zhLNFSIIb9zkIDuMIpBRDOdxQUXhUFLuIWTI1rF9GEMQgg/AkjiZ0y
nlI3Zjd23kg6ieou1Mjmx7BQXhaiMSCxB1cDBHUquGXzurPLCenRZpbfu7gnJ0eJH21qGjt7kpBU
5XeCo2hd54K8vPihJYs/uazEP8UPch1N7srS0mKHY3phfd22Pb957MUK97RpgRKrbWrOwpbNPzn1
m4MsLgQClvgfmI18H67TeUeMwRTJEDQ9Q9YBRzpkqwgdAhHsqJoU4SKnDcAPUU/2KEk+7Omi6nmt
+nys+mI11c8fw+pL4FgNho2S4tRy+h44xeI10beIUIVFFHBuJste4hwZyVqa5EoeemleMbv2ZVKs
nH45dmyWh5Bf82K4ZCXzMLX3+AfcEvQdDvw23CQX6qxOa551qrVV7BUFp6gDwZqcpOMxDjuTdAGn
Xe/MICG7Iz3jL86DrktzZTj2moo5jcDoohBt3Cup3rmcmg3GMJGGMSqanzxqDaz/YQg/eSofcW7r
rC2L/7y4iHzM1cZu6SxaNCivYhZeen4fX5paHfx517PMfS6U06LM4ZpRTvoG/hu5P6Br1a3U3a87
oDujE3gdEYQM0ZRUILqTposlSY1ip0i93wZxU1KSLSWUNKTdod+rj+qFtDSDJolxGwwBs16vE0RG
0mgC+F5Lk0k6i0Gv1QiiFiQmmCoZU9JEKyokOUlviBLDYazQIZcNqT/UOHot1p8lNDM4/2L4vP0y
7j0oTWyda8LnY+drEvtnapEEX255fLtt2XjbL6eMv9jSNG5DK4sSu5V1nRKxhipmkADxpONWmqE7
zAAZ8eU1OR35nNJPpv/xXXyLHV6z9bnswkJy+ysMozOb1hi49ZfPsb5Lp5WX7ieskEbXnfqL0y/i
X/ezYSGLX6qzIQA5UK5+26+H2fgdvQH/12ABfk1vgUX4hb4VluJ3dfo/WgR3m0TtSqAnIAva6+e2
t+Q39K4Z7B1Y1dNdUHvLmhW01ZUfZvB/HQC2Ie1GegQpgnQM6TTSb5H+lHiAGJG7kYqRZKRmpC6k
fqRtSLuRHkGKIB2Lj/8AfxNpgt762vzMSXnVHV3Vvm5Sff2kfMukfOukfPek/PJJ+Z5JeYrH1fKq
erlKnlWT6tdMyt88KX/LpDxidU3/6yflvzMpPzApf+uk/Caa/y/FUOnLCmVuZHN0cmVhbQplbmRv
YmoKNTMgMCBvYmoKNjQyOQplbmRvYmoKMjYgMCBvYmoKPDwgL1R5cGUgL0ZvbnQgL1N1YnR5cGUg
L1RydWVUeXBlIC9CYXNlRm9udCAvV0tIQVVKK0hlbHZldGljYSAvRm9udERlc2NyaXB0b3IKNTQg
MCBSIC9FbmNvZGluZyAvTWFjUm9tYW5FbmNvZGluZyAvRmlyc3RDaGFyIDMyIC9MYXN0Q2hhciAy
MjIgL1dpZHRocyBbIDI3OAowIDAgMCAwIDAgMCAwIDMzMyAzMzMgMCAwIDAgMCAyNzggMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwCjAgNzIyIDAgMCAwIDAgMjc4IDAgMCAw
IDAgMCAwIDAgMCAwIDAgNjExIDAgNjY3IDAgMCAwIDAgMCAwIDAgMCAwIDAgNTU2IDU1Ngo1MDAg
NTU2IDU1NiAyNzggNTU2IDU1NiAyMjIgMjIyIDAgMjIyIDgzMyA1NTYgNTU2IDU1NiAwIDMzMyA1
MDAgMjc4IDU1NiA1MDAKNzIyIDAgNTAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMAowIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAw
IDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwCjAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgNTAw
IF0gPj4KZW5kb2JqCjU0IDAgb2JqCjw8IC9UeXBlIC9Gb250RGVzY3JpcHRvciAvRm9udE5hbWUg
L1dLSEFVSitIZWx2ZXRpY2EgL0ZsYWdzIDMyIC9Gb250QkJveCBbLTk1MSAtNDgxIDE0NDUgMTEy
Ml0KL0l0YWxpY0FuZ2xlIDAgL0FzY2VudCA3NzAgL0Rlc2NlbnQgLTIzMCAvQ2FwSGVpZ2h0IDcx
NyAvU3RlbVYgMCAvWEhlaWdodAo2MzcgL01heFdpZHRoIDE1MDAgL0ZvbnRGaWxlMiA1NSAwIFIg
Pj4KZW5kb2JqCjU1IDAgb2JqCjw8IC9MZW5ndGggNTYgMCBSIC9MZW5ndGgxIDEyNTM2IC9GaWx0
ZXIgL0ZsYXRlRGVjb2RlID4+CnN0cmVhbQp4Ad17eXhURbZ41d17Saf3vdPd6XR3OktnI5sJ5BKy
sSQGgpAgwQQIBIQRMERR4UWBAaKiyCr4VFwgwGiakIEGBh/DQwHHN4ILKKOOPtFxfObTNw91FNL9
O3U7iSGzfPzhN3/87s2pqlNVt+6pU6dOnXP6pm3Z8hYUhzoQjWpnNC+Zh6Qr2IYQtWbO4uYlMVw3
CiG8bU57myuGs8kI0YvmLZm/OIYLWxCSO+YvWjHwvEGNkPmD1pbmubF2dB3yvFaoiOEYxkNJrYvb
7o3h2l7IOxbdNWegXf8G4KWLm+8deD/6AHDXL5oXt8T6B2shT1py191tMTz9K8jnLlnWMtAf1wN9
byIMtS70BJKhOxGPKKSGuxEh/gu5AzHQStrhuktUPn1HfPG3SCNI+B3Vj0n526vPtP615bpfsUn4
ASpkg/1JzgUiAYSUGNr7FJuGWqTnIHGFUV1qGI0HKAHIBUhNHWtGHXgPehzgWQAaLcAPoxUAGwCe
BGCGSvsAO4of7mEE8Rhegax4gqhgnFP1FqdZrnC+FcZc79PO982fHscWWL1PsKUnDsnGyvGz+Bk0
Fznxi8iL70NVKBnvPBRY5GyCpn1oCUAHAC2lGO/rSch2voLTkJfB8IwPJTD4sPNPWenOz7LCFO5x
nvKHGch+mwCYGO886Xja+R+O+c5XAA7EmvYHoMdh5z7HIufmhDDe2eN8whHG8MymWLbcAY8edi4O
bHPOzZLaJ20LUwd6nIXQPk1UOPMK3M5cxxVnhj8sYMDTHZOcKVn/5UyCB6GbCwb1ihqn3bHZeQs0
JTjK/bcAHMf78S6Ugnf1eCc4j0ERpntofKBgWxjff6gqOcsbxveJeVXJ2wJVfm9gktMbqPD7oTzt
LL+Gv50fy2fzqXwy7+PdvI3XC1pBLagEpSAXBIEP41/1lDi54/gAKgG2HDgkcAIbxi9DJXMcvyRV
vnREYARKQII+HP0YhBcjfRgf6AWxxwgKhzmpxIXxS4diVS+JToaUGKlBTZEyJJAiCgsUmoBC+NEw
h9Ya20vMJdoxmsKKsn+UNEktg2nqP77M2BHaNrGuPrTf0RDKJoWoo2Gwu3mw8A/ztuXQ1FKamjpx
yopD7UsWzitv8ZQ3ecpbAJpCD7e3mkMds12ugwuXkAZXiPY1zZ7TSvLmltAST0tZaKGnzHWwXXpu
RPM80tzuKTuI5pVPrT84T2wp62kX28s9zWUNh2aXLmu84V0bht61rPTvvKuUDLaMvGu29NyIdzWS
5tnkXY3kXY3kXbPF2dK7yOTLF9SV3t0G0ukqXzDRFUquC42fPKM+5GpuKAvjPVBZthyxJ5GaPYGS
2Q5kZTKQE6Ho+wCXSR65Lfo5ewapI4uj/0sXwaIeJUBFSorRSfQo2oW6EYe6oJyMZqEd6BxeCHt7
JupFF3ECCoLuZVAYTUJv4Gj0ApqHXoD+begU2ooOIiU8sxgZoHUj9kbvA1yE8my0JvocSkIF6Jfo
BCqEUTeivui+6CFonYJuQ/vRAXj+d9hDHWR00ZejV5CAJsOYa6DlQnRStBtpURoqRbVQuwa9gr30
5WgrMqMioO4p9AzajX6LvsIP4d5oa7Q9ej76CYiqGdlRHdwrcS/+hO5mfhl9KvplNAKcSEYp8NYm
tBk9D+N3w30SVGs5vhO34c14KyVSD1G9zFrWFOkHPgRQJdxV6C60HjhwFJ1Gf0E/4K8pM62m2+hX
o7nR/0MKNBFmSWbSgtrhXgf3RpjTcczhTDwO1+KVeAveit+mUqjbqHrqHupe6nO6hp5Jr6DfZu5m
ethH2B2cIvJt9Hj0TPRdZEIOdDtahlbB7E6h8+gq+hHTMJYde3ERLsWz4O7Au6ijeDc+StXik/g8
tR//EX+Kv8bXKJZSUgYqlWqjNlMHqFPU7+kF9Fb6SfqP9LfMGJZid7OfcV7+D5HZkQ2R30eLop9E
/woqVkBuWJlSVIPuQM0w2yVoFPo3mMVLcHfDqp1Gr6Jz0v0ptqM+9FfgAsJabMXZuBruGnwrnocX
4KfxMbhfkWj5joKFoGSUhjJRdqqOmk0tpjqod6kO2kan0BPoGXQ33Gfpi/Q1+hrDMjrGwFQy49Ej
zGJmJ9x7mC6mh3mTLWTHsDXsNLaD3cA+Qs9hL7AXuVXcRq6H+5r7BtTiJP4u/hFYnXMgs78FWf7p
YnASUJ+NfoHm4DI8G22D1diNm1EnSNdcvB74tQQlRxvpVXQllQnS8Aq6H6R1J1qJNtAz0e7oe/R+
dAkkZREM2YH2MqXIwW6H1XkIZYIUDdxiICWQ7Pd5kzyJbheofLvNajGbjAa9TqtRxykVcpnAcyxD
UxillXsqmlwhX1OI8XmqqtIJ7mmGiuZhFU2wlV2hihv7hFzkuWZouqGnCD3njegpxnqKQz2x2lWM
itPTXOUeV+i/yjyuMJ4xuR7Kj5Z5GlyhPqlcLZUfl8pxUHa74QFXubm1zBXCTa7yUEV7a2d5U1l6
Gj4qAjvk6WlEcYhIQQYOoXHNK0HBonGkR3nI6ikrD1k8UIY22lvePDdUO7m+vMzmdjdAHVRNqYd3
pKctCAGd6GHlXM/ch8Mimt1ESs0z60N0c0OIaiJjaVJDJk9ZyHTfZ+af0MFS+SPDGkOUt6K5pbMi
JDY9DMwlaBPBmh8BbGKdC4al1jbUh/DaASIIjQuBUkJu7EzwNi10hWSeUk9r58ImYC6aUt9jFa2S
8g2h2voei2iRkPS0o+ZVRW6Y/dH0seljSV7kNq+K5X9aHat/6yTJzatOfwz5xClDDMCEA57xQGfI
NUd6iQeILSBJSwHqnFMAfIKrAcM0FwA940IUyAztDbHe8c2hjrpBMlrLYsQ1LSzrkVms0iFU2gD9
mzrVt8BKQX+1x9X5LZzWTZ6+r26saR6o4bzqbxFpJAs9JCsh3DxYbieHpRdm3Wr2tJL1bZfWFHCP
uXxYBeCENYTmkB4O8Np6d8jVABVgTaZNDCNZbf1BjDc2hHF0bRiVOY6CjUrfMQua04ioLSiD9wOS
ngYVKW4oBdNcFfDmCiIrrk5X5/i5na4KVysIE+OVcmho6WzIAA7W1QOf0FR4o9hgGyq2NDTcAuNk
kHHgEeje2QAjLBwYAXKpKqMfOmWmwWFK+2rrJ9eHOspsIbGsAVYBxPdkbX3oJEhuQwP0yhqiFChe
ucA8QHM20JyVAu05sVHAdumAIRo6O8mYdfUed+hkZ6etk+y3GB7GaGSFOFARRqQLYXkYd9TCs5B5
3DZpDdweN5DVQHg6CkR6UKLAZv/nHM4bohuezAdq8yQOF/xMHC68GQ7fclMcLhqi9AYOFwPNRYTD
o/91HB5zA4dL/jmHxSG6gcixQK0ocbj0Z+LwuJvhcNlNcbh8iNIbOFwBNJcTDlf+6zhcdQOHx/9z
Dk8YohuInAjUTpA4POln4nD1zXC45qY4fOsQpTdwuBZovpVwePK/jsNTbuBw3T/n8NQhuoHI24Da
qRKHp/1MHJ5+MxyuvykONwxRegOHZwDNDYTDtw9xWLSF0HA93DFC7aKfXTHPHMZysJRYLSqlCsFx
3o82ApRBuRv8rxchP8d8itzsNDSKuRtNAWgHp7sI8gKAKmi3Qz4aYA0+QyB6GfIN3H60htQBkL7t
MOYGeI68wwR4B5QVML4WcgOAHUgYjB0pEYfXA+5C/0Fc+RsuCryAwQseu+mLHerJDZWGF3hAYoGq
4bWkLENy8J2UEBFSoXiIdWnAz0NIh/TgQRrBC4KgHLIgK7LBHByAJQD8/3GBPy5deSgPvLyT6GPw
6maAP/I5FaKt9FOMwLzFJrCvcUauDDydZ3k7fy//jTBb6JKtl70nz5afVbQrlcpfwBgU+GyIOQ++
Pg0xw3GxOJ6QEUYMgKAOI3QegOBQpj+AMuQ85DTksg/QMXgKoWmpx2AkFvLMrByNW+MHKGU2hq//
N3vix3FhpvoaxIVAYjZGZlHN7LuwQmNEmV4j0xlNJqvsOH4KVliPnxJVIojfJLXFYPzevWiKOcxn
r01Nrbla3Wf90Nr3Tl9NeUvZ56ikJCsTUzynUZuMOk8Q+31+X646P09Hzfr3jMrJ2ZtXPFERKDAq
GouOs+9G3nz8D5FPIh99syXy5ZVVi7Z0Tb8VJ/9pM/ZK9JQBPSagR4fyRKWgQToD0MNMitcRkkDA
gCSZYNEbvneX3A8BJELJO30fDqNDp83P06j9PjonAZsSsEHNc3TlM8EKQsXOsb7MwKyiY5FZOG/j
JezG7m+2YON3d7esvLo08t4XWyMfSTR0A2M60GXgv0/U4RRazgINeC6yMOxc95yW2Gv7B6Ze3ZeV
mZ9j8HRfuHAZgjFk/V4EDTEH1i8OpH2+6Fyn2aalsgVFQjyFEkyCkKWzWuO8KovFetHdvmFwNPV3
1X2opL+kPytz3ArRh40ar8HH8SzP8DRP8SwnVwvZGBshkWkV2ZjXgxecmopTU1NSUx9s9Gbn55E7
V0153Bra7TIZNXqeCmDqfMvYtglF1vj3/zfyzFmqDmfs3Vq/K/LL/u79Bv9dDQ/XVWINDl7bweou
nYpc+PJEpEfiwTngwROSDJpI5PiYpFyCqRAnIqJHZWRm6XI0nnPnzhFxgkY3yCyUQfZGiVbMJSCe
YgQZ8A1do2gvy1zjLMIjs8ypNeqr1VeL+4uvDkpOcXV/MUiPwa3xaNy5zLmI5vWIhj3R/eNfWBUs
BJFRiNWzeTA2hx4Tyx7Hz2JKxFMxZcT4XvZzTM1nWtn1DG1JprxammaQV8txLGYpmqMRxTKCQCSI
op9mEX6as/AbgQoLkGGu7i8shD+LRIkZlRSXmIq1hXhddTB1XdBMYo6iEoOLT0NwGlMcu05YqT4t
JUBvI2pcunSZjMrBHozVeA/e/cf+L97u/zN74pqD+fTHcUAuXDSaEv1AioDEQ2yrGH0oFqRkYrla
YVPa/TlV6gWyhWq+UNAqZbQtm0+SOdRKR1EqFQwUHSmiirJTvFo1zwp2f6LJHsadosfkcPJ+R1BB
OXIVxXxxsV3PB1K6kqxjbAH7hHh/gWX0mN/g7bAYR/E2NLA9rvbVgGxd6T+tLcyAndpH7j5toUZr
KmzUaAuDfcE+DLnGVChJXnJeviERYYsX58W7kTnB5kZGlx62SiLKp9zI6jC5YbEgAalIxepiEr98
8MEHUSNuTDLmgBSOxiocjzmeM2Aij6N8nkSe4z1jcE42hFA0eugEr1BhTyKoCZL5ckfl5euwalnN
HQ3b3K3Zi2dn1eHeMQbl6vseLXLLu9jvnz/RvtzkVSZoUtJ8jSlGWf7vH9h64tj2zjdnpI3fs8lg
51Rx9oz5eJGQZk6fWTcppe61XVVVO/q32xNpeq2SK/WIVQt/vX7rCzp8hezP9uhHjJc9BadTAloi
Bvfwe+2X7HSiEJ9AwdFncrC8Rp7gUCj0fsHqsgbVQRxAGovTtc59olFiKsjslSuEq7Bj+whLNYWa
GPfMWiMnN3J6H9bKITHwJh/WyRJ8sZ1K2ATbhrBCq9FTEgcMnqQYkziD3mTMae8ueqHp7A/fXb5v
anbhHmrepk2P3n/UV3mKPdX/P9WTI32Rq5FIqMhTvWHlF6/s++jwhe2zDoKcUQiifvR5pkY6W/eK
GXsteIe5S9hvpicIml16mtZzDisf59ArbLzNZlL7tZj2UxqrQ+43WezwUwh/yL1s5YDEwMyKq/sK
C0FKBiQGCmrQc6CYRiGL4FUa5D6k0qlhlpp4NW8BjEW0G2OKoRXGOB+K10IiM3M+zGDODTpKEhUi
LOpiSWQkeUFGExwWRDwMManIIeJA5apRDk9d/NTUrV626lcTMtc/sWS1pTvhm+Nv/Yi179iZmtCl
Oau7Fj+7+4MN97z7Ks75HEKWt7DAg4LoZboP1lWBHOgeMTtfVamartrL7LOxXkFPxTvUSHA4eJ2c
cpgUbFAXVAc0WqtT4bdaEpzr3MtKh08fFnjk2lrNdpkcYWxWwNzskCAL5UNym+CDCcKftAu0RLwl
oecMyGQ0aUBL5pJpodxR2pzvnti9cvee+9bvw511maNfeq7kV3cdivz49Uf4ji8unfvdf55/ncof
lTCRcvw4Zuucepz+45d4OuiQquhlxgpRVDtE3L1YKa7YLjxp3eukWRUVz+oNKm28QS8qRb0QsOKJ
isP0Gfwafcb2nvC+7KLzPc8Xpi88ijOaM1pqpsC6k+J3Gh1JhRzPG90OOy93GBVefrt9r/0I7AHG
a4z32lmLXMlrVP54h5+1+pOCvN9i8fnfce+JCT/IviT67/QXagtBjRRCltEY0yxQAt2u7oNaSVoq
kIdhaQhRY5bhnD6NWqvWqfVqhlN6E21JPrBaHT6c4JCZeB9SGFQ+HKfyWN1QxUIimEGu4tSQEFUT
0zWS8KSkpjyIlzaipY2NIEJwG9wJsKXg+AMBAl3DAbc1IEQYzBBPIsdjqvdiQZ5Wff1r9vHtj07N
1B/kb82asmLslLORL7H5v7FTkTzhpQe6WOxhKu+8bfKiCc89/2pjXmXRpmCtXQ36nYNToDTiW17x
0KFOTH4IhjMJbHCwU94Cm7ZaTOUdnNxB43h9oTGO08otcOCo4jQBk5bXxqucKkp1XW8xW66756+K
iVh/Y+FpiVHDD8ESMGSyMsF6yck2mgxkX3AGsCvgWPTk5uT+2lPSq0ky2S2KKa6e3p6tW9nSUTMp
6gUK3/byxutz6ac2dknnzehIEf0FyIoTpcMvO0fE6jz9eGG8rF5okK1X7rN1Ofb596QetSlEgTYm
BlSn5YlwpDBcwGGRax3y+CAfDLJ2OmgMpgdYa6ZS5Y8b4/PbLRmZwzbI1b5CIgH9V76FdR48U0r6
pGWPrXuaJ9maoNAkedU+T4LPh5KtkGgUKjeKVynjvI5EH/bbAqAnlFowHH7SDlCSdhHZObk5YMBw
7kSfPweWmCyvdFokkZVF0qEiaQ04YjD1wKyc3D3FSyLnXvpKdSTOP3r1m6KPztux8uXINcwfw2Uv
/NsrFd7ND5y6NS1ygSkd4xm37nr2G+2Xd71Y5S9+YtqHU2q/xw4ch4OR3Sd77tj56xPdc9ZQ6dI6
r4FDnOgUI6oT02DXCCbeJPgZv245v1wQdHGUzoCQxsHxBqU8LiC3mrEhgIwWkxl+IT/knh3TKcTG
GTguiqXTohCTDSIdBnBGxg5Gj2aUJK4GjWdNr5gz/aE/16UfTchat+RwLyj/Dya7C59veLp/MvV8
e379zov9Z4kcUvDrGcJFYGwQXyFPtPOfMSCcHC0nphfIbYCnQWHL9v9Eyen+4tNDYldCrFdiyGlA
0tYcgYtJuXaRPUG+fqCilyO1uEAaW0OMvjqwAonoT4NvCTDxOc7HfA/ZebAKVdBBk3EM6CC+R2YW
BqHFY3Au6D9YRTjk/bigtzfy3IqsXl9JKM7hZPrO/zCK8cxkDl/LX37LbEpyVTHaAG8YLb0zIAJn
B2xvKoBosL6HTQMYOuR6kAls6O2VLFFCIPCE8zKVyIfWikW8wKu4eJNgUpni/YIf1FqVZZpivkLp
8cqtDo9FTjEmr9thcsRxPOJsdi+tkycD8zQB+EEd91gD5DsCEfR+0AsCa/Enh3Hc8IW9or7ad3XQ
GTAVl5TA0Qn6z1RIjKrBVTYMrLJp0AqCxSaqCdZ62Kr3iKMalnbUpCUVP9fyXk3K8TurFz55xBpY
Mm9vL5Ox49ak0SVJFdPqnpq6sT+f+uLO2o17+jdRxxdnT3z6TSINkizQfbD3iYc9S8w6wp3hKIbT
c359O9fGs3olpTerwbpBnFkht/JWK1IGZFY7DpoDFmSxgYl5g8jG1Hxsh8O8+jSFg2KLwYoxDJsK
kVvQuyoM88FrDkza33qlNu2II3OVGJhQkG7rxXuB/llTnpn+HJHf2cVz44yluUsX9L8JxILEFEXf
Z9xguyil6MDjYs4OYZv6SeOLTJewR73PGBbOCpeYz1R/1itvETiHmVc6tAoLb7EYKH+81SbzGyxW
WxjLwIIZOKEki/cn60U6itIglOJT6GRwmmgoH+ZNUGLjoCTXK30gz5AIRjBYaBUk0nlDklQwVJK0
uQM7E6wULZwslBtOc8lI+Xht5qRjL27b9jz8kH498v2HketY+yeuDcfv2TZry/WeA1foy5GvwGTr
j7yMU6+DYSwSO6U9chvjhamrUCJqE9P2CXtNVLLgsmtUnMPAx3Mqh12RqKL8ZmuSHKxPdyAx3uJJ
+rvWp2R+aiQ5A+PMbrQh1upjfMgGE2ONkGCLyodokzQnaVrEBiUWZ2zNJJsT58TkE37cJFsVzHKN
h3ptr7fi2PFyL6SRYHeeePv9hyNH2naumJJZ1Lvi7bc6Zh48PnfnA9P30Ac3jk8ujvwZ5vjctjty
E8b3f0j2IOxj6gnYgxp0q+jz0764fLqSYVSCmlLJNDKlXyBiqJELVh0mdhiyaHVhXA4bK3ZEEgu7
Rk0iC9Ulp/tPEyuD7KeYzpREb+iMhL1/wPDCnazZobap1z8BW+Vo3i6KfoWmupf17yD7ojR6iT7M
TITzMAMHxccKZDvYbdon9TsMO1K45CSvP89d4a5MqvRPS5run5c037dCuSJuhard05bU5m3z7Uno
StPRYJ6w6UxQh6wGm8luNqTrg8nxigWCz5vnpbyJcXImVWd+ze7Q8YwjuDNVkcHLVGqKRxnuDKvT
bDT7TWOSfbw/2ZqlcvrVY5A/aMnM6hmyqUCFxM7UQjWUyHQLMyCFLUcMK+KxEZWyVJLkSTid8hm8
Vp9b5XQjGXxChOk08PnYFCg5tFBn05vd2BWf6EbuRFWc4Je7sc8rk+N0xg3fjUGSoLG7scUIiWRa
SUa5lEgiMij44NJBOChm0Pp9GcScAleNnFa8J2ZaEfFxYmKB6WM6/mvBW9Y1d8do/92PbRjb9oej
f7lzHLWf9Y15ct6C8uSae06VLnj/o6/P8PgIrp2ROX367eVJYI0mpox/cMdvNs5oHZ1dWSNWpFh0
joy08i2PnX//WeoHkCVT9GtKxs4A7TDl13FB+UkVDuMS0csYC000p5JrrKCu4WuKADKoDPG0k6bo
60aIroC9NeDRjLC3MoiS7i/uU/dfkU4/YmUR32vQL/XlEpOr6/CBAz5DVlyC3jnOv2rGpk3sjMi7
m/vLC3QKTG2UCQ/Op17dLJ3BHdFP6Y9gP5uAwlniLWH9WT0l0wl6i86iT+buoS+B2YBYlRxxcXIW
dJeZN5vBTQrKA0qF1YoDhNi3Bk/oaqK8iPjD8sdsq5JiIhBE9HEjjhEKRg9xLPIlWxdWRePFBdbM
1b8p8/bupzyj5m/+rC4ddzMZ/YVTRjV1zfh3SnXtwtOjU6Y+OWUD9Z6V7E8FKN4vmQyIHlNisBS/
iik0H7VSrfR8bh2znt2LuigBvpKhypkJ7C+ZDewZ5iwrjE++O5kXJFUrmbIQIglHl/SCce9iwnj1
EZperKUwBd+qrRYTOG4xBH8xyzE0HojGwDcTchKNobupY5hYLmsO4W7OYqkhwZiPP+4fGYqBaWsL
eYjHqGuuVPOxLHXi5BWilwpIoZ7AsFDP4ODgg3ZDqGdo3L8X5GF5dSr8QRwH3IjGpToZJnGcD3AC
Tn01suhkZDmTcX0H3XrtAnAIkxg2uxtKSuwSV1Uy+2Ww/LiCH69YR3cKa+WvU6fp1/hzwmvycwrF
PH6h0CJfoGjnVwjt8hWKtXynQk76UpX0Pehelp6ebEwGb5EpwkXMY/gxhpMxmFZQNMspWcQJcgXN
y1XAI4j47RJo5rSckp1WILxLaYkjPB8euRoRvwLjAwJYENUhHFKywBsevnbSKpUKdp06Ff5guXpl
8O2KPIwfFnVacNd5jmFJR46XCTI5rOzDokrLgBOvhGlLj8bCYeqVp80sCYpBCOxVqbAOYmFDNSQe
tnTpUnDIbFSOjfBSAey89PsLr7/1h97IueOX3z4e+R2wtJeedP0oXXntAj36+n8CQ0E3GyLjJX+F
/C7wuviLTsN6814zzXMmrkBbpa3Xzufvoe/hH9HvQNvZHYbtxu2mLtRlVFehiYZK0zkDU8a+xlLr
2D1oD97LdpnYpGTWbDAZwQY2KBXxDkFFDAWjDRhKZMJkMHcrHzOCvfBOzBkD0au+Yr6BkbFtB8HB
bEuGuaS4GGKChZgEA7UG+BHDuFhrMplZjIlwm9eBTAJrSCZADlzIylxKYoM4h6MpnpKUYi5xTvPy
x+B84AxNu8/4Vs8ufarjKV8gISNFnZ2hZseoIm1vYCdmMuZHNkW+ejkyr5cTXojj3GZhSxJTA6L4
ELGTwOek75V8Thv4d81inu0zC/rJ93SA8+nUyN0wV1tCwOz8GxfU5X7LPX8gyjGkEi+Cwz5gShfD
bEEvEke0pA//Y1/Um5tj4EH9/I1PSul64fpbz9T5xhtnrl2UdCUk8MViC3xX9/cuF1TCUQuWoAb5
4QvBfPiCrQyVowrpi73x8JEq+S6vGt0qfTk4Bb4GvA1NQ9NRPWpAM9BM+N2FXGTHYqnEwW9QaPrE
qrG3TUitalnU3tK2YE6z1ENqhmQ9wBaAFwDgM1r4Kg6hdwCuAFyFoRgAPUASwCiAMoCpAHMB2gDW
AGwBeAGgF+A0wDsAVwCugoAzAHqAJIBRAGUAUwHmArRFBy54FxoqY+QagSePwAMj8OAIHN5xw3hg
ZN+Aw/tvwKeNwAmHhtMzewQ+ZwQOc7mhv7S2w+Yzb0T7/BF46wh8wQh84QicfLs3nD7pfwCGvY/8
ija8/a4R+JIR+LIR+N0j8LYR+PIRePsI/J4R+Iob8WuSbP4/BlmWKQplbmRzdHJlYW0KZW5kb2Jq
CjU2IDAgb2JqCjgwNTEKZW5kb2JqCjU3IDAgb2JqCihNYWMgT1MgWCAxMC4xMi4zIFF1YXJ0eiBQ
REZDb250ZXh0KQplbmRvYmoKNTggMCBvYmoKKEFkYW0gTW9udHZpbGxlKQplbmRvYmoKNTkgMCBv
YmoKKE9tbmlHcmFmZmxlIFByb2Zlc3Npb25hbCA1LjQuNCkKZW5kb2JqCjYwIDAgb2JqCihEOjIw
MTcwMjAyMTczNTA1WjAwJzAwJykKZW5kb2JqCjEgMCBvYmoKPDwgL0F1dGhvciA1OCAwIFIgL1By
b2R1Y2VyIDU3IDAgUiAvQ3JlYXRvciA1OSAwIFIgL0NyZWF0aW9uRGF0ZSA2MCAwIFIgL01vZERh
dGUKNjAgMCBSID4+CmVuZG9iagp4cmVmCjAgNjEKMDAwMDAwMDAwMCA2NTUzNSBmIAowMDAwMDM2
Njc5IDAwMDAwIG4gCjAwMDAwMDMyMDkgMDAwMDAgbiAKMDAwMDAyMDE3OCAwMDAwMCBuIAowMDAw
MDAwMDIyIDAwMDAwIG4gCjAwMDAwMDMxODkgMDAwMDAgbiAKMDAwMDAwMzMyMyAwMDAwMCBuIAow
MDAwMDE2MDkxIDAwMDAwIG4gCjAwMDAwMDUyNjQgMDAwMDAgbiAKMDAwMDAwNTU4NyAwMDAwMCBu
IAowMDAwMDAzODU2IDAwMDAwIG4gCjAwMDAwMDQxNjMgMDAwMDAgbiAKMDAwMDAwNDE4MyAwMDAw
MCBuIAowMDAwMDA0NDkzIDAwMDAwIG4gCjAwMDAwMDM1NzkgMDAwMDAgbiAKMDAwMDAwMzgzNyAw
MDAwMCBuIAowMDAwMDA0NTEzIDAwMDAwIG4gCjAwMDAwMDQ3NzEgMDAwMDAgbiAKMDAwMDAwNTYw
NiAwMDAwMCBuIAowMDAwMDA1OTMxIDAwMDAwIG4gCjAwMDAwMDU5NTEgMDAwMDAgbiAKMDAwMDAw
NjIwOSAwMDAwMCBuIAowMDAwMDA0NzkwIDAwMDAwIG4gCjAwMDAwMDUyNDQgMDAwMDAgbiAKMDAw
MDAxNzM2OCAwMDAwMCBuIAowMDAwMDIwMzI1IDAwMDAwIG4gCjAwMDAwMjc0OTggMDAwMDAgbiAK
MDAwMDAyMDE0MSAwMDAwMCBuIAowMDAwMDExNDUzIDAwMDAwIG4gCjAwMDAwMTI1MjEgMDAwMDAg
biAKMDAwMDAwOTI3NSAwMDAwMCBuIAowMDAwMDEwMzQ1IDAwMDAwIG4gCjAwMDAwMDg0NTMgMDAw
MDAgbiAKMDAwMDAwOTI1NSAwMDAwMCBuIAowMDAwMDA2MjI4IDAwMDAwIG4gCjAwMDAwMDcyOTYg
MDAwMDAgbiAKMDAwMDAxMjU0MSAwMDAwMCBuIAowMDAwMDEzNzMxIDAwMDAwIG4gCjAwMDAwMDcz
MTYgMDAwMDAgbiAKMDAwMDAwODQzMyAwMDAwMCBuIAowMDAwMDEzNzUxIDAwMDAwIG4gCjAwMDAw
MTQ4NjggMDAwMDAgbiAKMDAwMDAxMDM2NSAwMDAwMCBuIAowMDAwMDExNDMzIDAwMDAwIG4gCjAw
MDAwMTQ4ODggMDAwMDAgbiAKMDAwMDAxNjA3MCAwMDAwMCBuIAowMDAwMDE2MTI3IDAwMDAwIG4g
CjAwMDAwMTczNDcgMDAwMDAgbiAKMDAwMDAxNzQwNSAwMDAwMCBuIAowMDAwMDIwMTIwIDAwMDAw
IG4gCjAwMDAwMjAyNjEgMDAwMDAgbiAKMDAwMDAyMDcyNiAwMDAwMCBuIAowMDAwMDIwOTU3IDAw
MDAwIG4gCjAwMDAwMjc0NzcgMDAwMDAgbiAKMDAwMDAyODExNCAwMDAwMCBuIAowMDAwMDI4MzM5
IDAwMDAwIG4gCjAwMDAwMzY0ODEgMDAwMDAgbiAKMDAwMDAzNjUwMiAwMDAwMCBuIAowMDAwMDM2
NTU1IDAwMDAwIG4gCjAwMDAwMzY1ODggMDAwMDAgbiAKMDAwMDAzNjYzNyAwMDAwMCBuIAp0cmFp
bGVyCjw8IC9TaXplIDYxIC9Sb290IDUwIDAgUiAvSW5mbyAxIDAgUiAvSUQgWyA8MWIyOTdlMDhl
MmQ0NjNhZTNlOTFjYmMwZmFiYTQ2Nzc+CjwxYjI5N2UwOGUyZDQ2M2FlM2U5MWNiYzBmYWJhNDY3
Nz4gXSA+PgpzdGFydHhyZWYKMzY3ODUKJSVFT0YK
--001a113dd774352df205478fb9d4--


From nobody Thu Feb  2 09:57:18 2017
Return-Path: <bill.munyan.ietf@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 213DB1294D8 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 09:57:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.999
X-Spam-Level: 
X-Spam-Status: No, score=-0.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q6Dm6e6HW-qE for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 09:57:14 -0800 (PST)
Received: from mail-ot0-x22f.google.com (mail-ot0-x22f.google.com [IPv6:2607:f8b0:4003:c0f::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2CE411294E0 for <sacm@ietf.org>; Thu,  2 Feb 2017 09:57:02 -0800 (PST)
Received: by mail-ot0-x22f.google.com with SMTP id 32so17737827oth.3 for <sacm@ietf.org>; Thu, 02 Feb 2017 09:57:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=zgIn4TIpIMIxKw4BBsLSa12n0XDTLCM0k7tczxdqcGI=; b=imsg8dTiUMnpRSciL9RI1ISfUoQnAhC4XIJPpMQD5MA4ByQoBkDDf/Viel9gKu80N7 FoOlWh0tP4y6uWMcfD7MHAEqDgAyXNiVPY9FvBTHJZR59arSyehpNrHQTGR9S6Q7nbG8 Y+WAHnlrzUIS7t1e6HfKXqMjNcBbUm/4GpISIl6kU9LznwXCDJlRhT0sD9fpnRlq+Fpn nErw5a8gZoo+SYdYc/OJcUJp1doItyxdplPnaMCEH+IVWM4S1G6t+qCpC8gJXqsFXvZa 7xBelwfJ66+Mq7cvKFipVtHBO+mFmXIGJ/boq9wOA9zdAnJunw0o3MCEBRvFU19KsEAW yXTw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=zgIn4TIpIMIxKw4BBsLSa12n0XDTLCM0k7tczxdqcGI=; b=dit/D4UaLRDHbmXR4Q5Xk+vYHnN3CAyva5RRsoOldtKB/Tc/AUHUyjxax+Gv753Eus 9Rvbk/SqfA84VALrI6GCpaWrAwkn8L78bDCGrk5kQ0tUzEzdEsP/3x5/a+EfAIekQGY/ XcscBJeNeSYtueUCmkLkrZWWXk//L69gct9EDUcGqEPtgvukgwPmUQcOdyzt2JWPsGh1 Tv7+oyq8S4DG+AU/7i837GHSzv1LFcL8VnGZ0TBhwIf/7wL7KOtWw2LHxLsW5LxtEYDp AeiDGrgD8pIlvvMg3K4mpO4YFrce7IjOrD9vjai1GMOqK1k5B5eRA3uuHAWhyxMy8p0Q 5itA==
X-Gm-Message-State: AIkVDXJN5TuQ0TruUnVQC0ygdcuJ0eAEBvHFtbzyN/XwNUwRRmYseRkc3nGkXSZNz5e8o59j0y1BuQc0eDgmPw==
X-Received: by 10.157.53.42 with SMTP id o39mr5237045otc.157.1486058221272; Thu, 02 Feb 2017 09:57:01 -0800 (PST)
MIME-Version: 1.0
Received: by 10.182.65.168 with HTTP; Thu, 2 Feb 2017 09:57:00 -0800 (PST)
In-Reply-To: <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com>
From: Bill Munyan <bill.munyan.ietf@gmail.com>
Date: Thu, 2 Feb 2017 12:57:00 -0500
Message-ID: <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com>
To: Adam Montville <adam.w.montville@gmail.com>
Content-Type: multipart/alternative; boundary=001a11c00e4e6503e105478fe4e6
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/2DgBiiBEK-RpmLzPAvQD2jYWedc>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 17:57:16 -0000

--001a11c00e4e6503e105478fe4e6
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Is it worth noting in the diagram (if not, I think it needs to be noted
somewhere nonetheless) that the steps of "get endpoints" and subsequent
"evaluate" should be making some determination of whether or not to collect
for an endpoint?  For example, if an endpoint has no assessment results or
the assessment results are considered "stale", then the collection step
would take place.  I understand that could be too much detail for the scope
of the diagram, but I just wanted to note it somewhere.

Cheers,
-Bill M.


On Thu, Feb 2, 2017 at 12:44 PM, Adam Montville <adam.w.montville@gmail.com=
>
wrote:

> Thanks for the feedback!  I've attached a modified version of the diagram
> that collapses the endpoint and assessment result repositories (by keepin=
g
> the endpoint repository).  Where would you propose we focus on enhancing
> the diagram?  Remember that it's a sequence diagram, which might do well
> with some more specific details captured in text or a different form of
> diagram.
>
> What do folks think about using one or more OVAL definitions as a startin=
g
> point?
>
> Adam
>
>
> On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz <
> henk.birkholz@sit.fraunhofer.de> wrote:
>
>> ## A Few Comments
>>
>> * I agree that the diagram pretty much captures a "one time snapshot".
>> * Collapsing the highlighted components seems to be a feasible idea.
>> * I agree that the diagram could be implemented given an appropriate set
>> of initial data.
>> * I suppose there is the risk that one has to scrap everything
>> implemented when we start trying to make it a continuous process.
>> * I'd recommend to start with a generic block of PoC code that provides
>> the functions of a SACM component to get input and create output (maybe
>> using dbus, chained event-loops, blocking waits on fifos, or IP over
>> loopback? A better coder than me should bash these suggestions).
>>
>> ## One, Two, or Three Tasks
>>
>> * Creating component code that can create the (downstream?) flow of
>> information is urgent and important, I think.
>> * Enhancing the diagram to represent the continuous cycle with at least
>> one trigger (as illustrated by Bill; new software, new VDI, new
>> endpoints, stale results, etc.) is important, but not as urgent. It
>> might save time though by reducing the afore mentioned risk to shoot
>> your self in the foot by creating a too specific proof of concept of the
>> one time snapshot approach, I think.
>> * Selecting a set of initial data derived from OVAL to be used in the
>> one shot snapshot seems to be a feasible approach to me, but I am not
>> sure how the group thinks about that.
>>
>> Does that assessment represent the general opinion, or is that just mine=
?
>>
>> Viele Gr=C3=BC=C3=9Fe,
>>
>> Henk
>>
>> On 02/02/2017 05:28 PM, Adam Montville wrote:
>> > Hi Everyone.  A few of us were able to make the vulnerability scenario
>> > call today and I think we had a good, though at times spirited,
>> > discussion.  We did record the meeting, which is available at [1].  We
>> > discussed the attached (annotated with some meeting notes) UML-ish
>> > sequence diagram.  I had created that diagram to start a conversation
>> > (mission accomplished on that front I think) -- a conversation that
>> > would lead us toward identifying the discrete components, interfaces,
>> > and information required to be sent over those interfaces.  The UML-is=
h
>> > diagram represents a *single* flow through the system -- a "one-time"
>> > flow through the system.  It ignores, for the time being, the continuo=
us
>> > aspect of our charter in favor of getting started with the basics.  On=
ce
>> > we have a good understanding of the basics -- the components,
>> > interfaces, and information required -- we can start look at a
>> > continuous monitoring sequence (which could be represented as a distin=
ct
>> > diagram) to determine what more we need.  Then, I think, we can start
>> > drafting solutions.
>> >
>> > One of the first issues is that we need to figure out if the component=
s
>> > in the base flow are accurate.  The main suggestion we've tossed aroun=
d
>> > so far is to combine the Endpoint Repository with the Assessment Resul=
t
>> > Repository.
>> >
>> > We talked briefly about what interface we could use for the VDD
>> > Repository, and naturally ROLIE came up as an option.
>> >
>> > We talked a little bit about the first "get endpoints" operation betwe=
en
>> > the Vulnerability Assessor and the Endpoint Repository -- specifically
>> > about whether we should represent on this sequence diagram that
>> > information supporting a judgement of "stale" would be needed.
>> >
>> > We left open the time when we would next meet, favoring to work that o=
ut
>> > on-list.  Next week is TCG, so that may be difficult; the following we=
ek
>> > is RSA, so that may be difficult.
>> >
>> > For those who were in attendance today, please add to this note with
>> > your comments/corrections.
>> >
>> > Kind regards,
>> >
>> > Adam
>> >
>> > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>> >
>> > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>> > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote=
:
>> >
>> >     Hi everyone.  Just a friendly reminder that we are planning to mee=
t
>> >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)
>> >     using SACM's meeting room at https://ietf.webex.com/meet/sacm.
>> >
>> >     Kind regards,
>> >
>> >     Adam
>> >
>> >
>> >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>> >     <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>>
>> wrote:
>> >
>> >         Hello. A few of us met informally today to discuss the
>> >         vulnerability scenario in some more detail with the goal of
>> >         maintaining the narrow focus on a vulnerability assessment sli=
ce
>> >         through our notional environment.  We are tending to look at
>> >         major components as black boxes with interfaces and data forma=
t
>> >         expectations, and we are not necessarily concerned with how
>> >         those components do things internally/behind the scenes.
>> >
>> >         The meeting was recorded (you can find it with today's date at
>> >         [1]).  The topic of discussion was primarily in the "phase 1"
>> >         area of what Danny sent to the list not very long ago [2], and
>> >         resulted in a *starting point* diagram [3].
>> >
>> >         The group who met today are (roughly) agreed on the six main
>> >         "components" represented in that diagram, but also see that we
>> >         have some work ahead.  Specifically, we quickly recognized tha=
t
>> >         some of the assumptions the vulnerability draft makes may be
>> >         assumptions we cannot afford to make and need to include in th=
e
>> >         exploration.
>> >
>> >         We thought it would be a good idea to have another informal
>> >         discussion in a couple of weeks (February 2) at the same time
>> >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At that
>> >         time we intend to roll through the vulnerability assessment
>> >         scenario assumptions in an effort to determine which ones can =
be
>> >         left as assumptions and which ones cannot.  Then we'll take
>> >         another look at the diagram and work on its next version.
>> >
>> >         Stay tuned.
>> >
>> >         Thanks to Danny, Stephen, and Jerome for joining and
>> contributing!
>> >
>> >         Kind regards,
>> >
>> >         Adam
>> >
>> >
>> >         [1] https://drive.google.com/open?id=3D
>> 0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>> >         [2] https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_
>> OVLFhB5NSU58MXDM
>> >         [3] https://drive.google.com/open?id=3D
>> 0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>> >         [4] https://ietf.webex.com/meet/sacm
>> >
>> >
>> >
>> > _______________________________________________
>> > sacm mailing list
>> > sacm@ietf.org
>> > https://www.ietf.org/mailman/listinfo/sacm
>> >
>>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>

--001a11c00e4e6503e105478fe4e6
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:verdana,=
sans-serif">Is it worth noting in the diagram (if not, I think it needs to =
be noted somewhere nonetheless) that the steps of &quot;get endpoints&quot;=
 and subsequent &quot;evaluate&quot; should be making some determination of=
 whether or not to collect for an endpoint?=C2=A0 For example, if an endpoi=
nt has no assessment results or the assessment results are considered &quot=
;stale&quot;, then the collection step would take place.=C2=A0 I understand=
 that could be too much detail for the scope of the diagram, but I just wan=
ted to note it somewhere.</div><div class=3D"gmail_default" style=3D"font-f=
amily:verdana,sans-serif"><br></div><div class=3D"gmail_default" style=3D"f=
ont-family:verdana,sans-serif">Cheers,=C2=A0</div><div class=3D"gmail_defau=
lt" style=3D"font-family:verdana,sans-serif">-Bill M.</div><div class=3D"gm=
ail_default" style=3D"font-family:verdana,sans-serif"><br></div></div><div =
class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Thu, Feb 2, 2017 at=
 12:44 PM, Adam Montville <span dir=3D"ltr">&lt;<a href=3D"mailto:adam.w.mo=
ntville@gmail.com" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;</sp=
an> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;=
border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Thanks for th=
e feedback!=C2=A0 I&#39;ve attached a modified version of the diagram that =
collapses the endpoint and assessment result repositories (by keeping the e=
ndpoint repository).=C2=A0 Where would you propose we focus on enhancing th=
e diagram?=C2=A0 Remember that it&#39;s a sequence diagram, which might do =
well with some more specific details captured in text or a different form o=
f diagram.<div><br></div><div>What do folks think about using one or more O=
VAL definitions as a starting point?</div><span class=3D"HOEnZb"><font colo=
r=3D"#888888"><div><br></div><div>Adam</div></font></span><div><div class=
=3D"h5"><div><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr">On T=
hu, Feb 2, 2017 at 10:53 AM Henk Birkholz &lt;<a href=3D"mailto:henk.birkho=
lz@sit.fraunhofer.de" target=3D"_blank">henk.birkholz@sit.fraunhofer.<wbr>d=
e</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin=
:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">## A Few Comments<=
br class=3D"m_-1926012925832773148gmail_msg">
<br class=3D"m_-1926012925832773148gmail_msg">
* I agree that the diagram pretty much captures a &quot;one time snapshot&q=
uot;.<br class=3D"m_-1926012925832773148gmail_msg">
* Collapsing the highlighted components seems to be a feasible idea.<br cla=
ss=3D"m_-1926012925832773148gmail_msg">
* I agree that the diagram could be implemented given an appropriate set<br=
 class=3D"m_-1926012925832773148gmail_msg">
of initial data.<br class=3D"m_-1926012925832773148gmail_msg">
* I suppose there is the risk that one has to scrap everything<br class=3D"=
m_-1926012925832773148gmail_msg">
implemented when we start trying to make it a continuous process.<br class=
=3D"m_-1926012925832773148gmail_msg">
* I&#39;d recommend to start with a generic block of PoC code that provides=
<br class=3D"m_-1926012925832773148gmail_msg">
the functions of a SACM component to get input and create output (maybe<br =
class=3D"m_-1926012925832773148gmail_msg">
using dbus, chained event-loops, blocking waits on fifos, or IP over<br cla=
ss=3D"m_-1926012925832773148gmail_msg">
loopback? A better coder than me should bash these suggestions).<br class=
=3D"m_-1926012925832773148gmail_msg">
<br class=3D"m_-1926012925832773148gmail_msg">
## One, Two, or Three Tasks<br class=3D"m_-1926012925832773148gmail_msg">
<br class=3D"m_-1926012925832773148gmail_msg">
* Creating component code that can create the (downstream?) flow of<br clas=
s=3D"m_-1926012925832773148gmail_msg">
information is urgent and important, I think.<br class=3D"m_-19260129258327=
73148gmail_msg">
* Enhancing the diagram to represent the continuous cycle with at least<br =
class=3D"m_-1926012925832773148gmail_msg">
one trigger (as illustrated by Bill; new software, new VDI, new<br class=3D=
"m_-1926012925832773148gmail_msg">
endpoints, stale results, etc.) is important, but not as urgent. It<br clas=
s=3D"m_-1926012925832773148gmail_msg">
might save time though by reducing the afore mentioned risk to shoot<br cla=
ss=3D"m_-1926012925832773148gmail_msg">
your self in the foot by creating a too specific proof of concept of the<br=
 class=3D"m_-1926012925832773148gmail_msg">
one time snapshot approach, I think.<br class=3D"m_-1926012925832773148gmai=
l_msg">
* Selecting a set of initial data derived from OVAL to be used in the<br cl=
ass=3D"m_-1926012925832773148gmail_msg">
one shot snapshot seems to be a feasible approach to me, but I am not<br cl=
ass=3D"m_-1926012925832773148gmail_msg">
sure how the group thinks about that.<br class=3D"m_-1926012925832773148gma=
il_msg">
<br class=3D"m_-1926012925832773148gmail_msg">
Does that assessment represent the general opinion, or is that just mine?<b=
r class=3D"m_-1926012925832773148gmail_msg">
<br class=3D"m_-1926012925832773148gmail_msg">
Viele Gr=C3=BC=C3=9Fe,<br class=3D"m_-1926012925832773148gmail_msg">
<br class=3D"m_-1926012925832773148gmail_msg">
Henk<br class=3D"m_-1926012925832773148gmail_msg">
<br class=3D"m_-1926012925832773148gmail_msg">
On 02/02/2017 05:28 PM, Adam Montville wrote:<br class=3D"m_-19260129258327=
73148gmail_msg">
&gt; Hi Everyone.=C2=A0 A few of us were able to make the vulnerability sce=
nario<br class=3D"m_-1926012925832773148gmail_msg">
&gt; call today and I think we had a good, though at times spirited,<br cla=
ss=3D"m_-1926012925832773148gmail_msg">
&gt; discussion.=C2=A0 We did record the meeting, which is available at [1]=
.=C2=A0 We<br class=3D"m_-1926012925832773148gmail_msg">
&gt; discussed the attached (annotated with some meeting notes) UML-ish<br =
class=3D"m_-1926012925832773148gmail_msg">
&gt; sequence diagram.=C2=A0 I had created that diagram to start a conversa=
tion<br class=3D"m_-1926012925832773148gmail_msg">
&gt; (mission accomplished on that front I think) -- a conversation that<br=
 class=3D"m_-1926012925832773148gmail_msg">
&gt; would lead us toward identifying the discrete components, interfaces,<=
br class=3D"m_-1926012925832773148gmail_msg">
&gt; and information required to be sent over those interfaces.=C2=A0 The U=
ML-ish<br class=3D"m_-1926012925832773148gmail_msg">
&gt; diagram represents a *single* flow through the system -- a &quot;one-t=
ime&quot;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; flow through the system.=C2=A0 It ignores, for the time being, the con=
tinuous<br class=3D"m_-1926012925832773148gmail_msg">
&gt; aspect of our charter in favor of getting started with the basics.=C2=
=A0 Once<br class=3D"m_-1926012925832773148gmail_msg">
&gt; we have a good understanding of the basics -- the components,<br class=
=3D"m_-1926012925832773148gmail_msg">
&gt; interfaces, and information required -- we can start look at a<br clas=
s=3D"m_-1926012925832773148gmail_msg">
&gt; continuous monitoring sequence (which could be represented as a distin=
ct<br class=3D"m_-1926012925832773148gmail_msg">
&gt; diagram) to determine what more we need.=C2=A0 Then, I think, we can s=
tart<br class=3D"m_-1926012925832773148gmail_msg">
&gt; drafting solutions.<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; One of the first issues is that we need to figure out if the component=
s<br class=3D"m_-1926012925832773148gmail_msg">
&gt; in the base flow are accurate.=C2=A0 The main suggestion we&#39;ve tos=
sed around<br class=3D"m_-1926012925832773148gmail_msg">
&gt; so far is to combine the Endpoint Repository with the Assessment Resul=
t<br class=3D"m_-1926012925832773148gmail_msg">
&gt; Repository.<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; We talked briefly about what interface we could use for the VDD<br cla=
ss=3D"m_-1926012925832773148gmail_msg">
&gt; Repository, and naturally ROLIE came up as an option.<br class=3D"m_-1=
926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; We talked a little bit about the first &quot;get endpoints&quot; opera=
tion between<br class=3D"m_-1926012925832773148gmail_msg">
&gt; the Vulnerability Assessor and the Endpoint Repository -- specifically=
<br class=3D"m_-1926012925832773148gmail_msg">
&gt; about whether we should represent on this sequence diagram that<br cla=
ss=3D"m_-1926012925832773148gmail_msg">
&gt; information supporting a judgement of &quot;stale&quot; would be neede=
d.<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; We left open the time when we would next meet, favoring to work that o=
ut<br class=3D"m_-1926012925832773148gmail_msg">
&gt; on-list.=C2=A0 Next week is TCG, so that may be difficult; the followi=
ng week<br class=3D"m_-1926012925832773148gmail_msg">
&gt; is RSA, so that may be difficult.<br class=3D"m_-1926012925832773148gm=
ail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; For those who were in attendance today, please add to this note with<b=
r class=3D"m_-1926012925832773148gmail_msg">
&gt; your comments/corrections.<br class=3D"m_-1926012925832773148gmail_msg=
">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; Kind regards,<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; Adam<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; [1] <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHp=
VR0tMd1E" rel=3D"noreferrer" class=3D"m_-1926012925832773148gmail_msg" targ=
et=3D"_blank">https://drive.google.com/open?<wbr>id=3D<wbr>0B8Wf9Un5FdCbWGh=
DOHpVR0tMd1E</a><br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montville<br class=3D"m_-1926012=
925832773148gmail_msg">
&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"m_-19260129=
25832773148gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &lt;=
mailto:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"m_-1926012925=
832773148gmail_msg" target=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&g=
t;&gt; wrote:<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a friendly reminder that we=
 are planning to meet<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the same time (2/2 @ 10am Ea=
stern/3pm UTC)<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting room at <a href=3D"https:/=
/ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"m_-19260129258327731=
48gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/<wbr>sacm</a>.<b=
r class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"m_-1926012925832773148gma=
il_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:35 AM Adam Montville<br =
class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montville@gmail.com" c=
lass=3D"m_-1926012925832773148gmail_msg" target=3D"_blank">adam.w.montville=
@gmail.com</a> &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" cla=
ss=3D"m_-1926012925832773148gmail_msg" target=3D"_blank">adam.w.montville@<=
wbr>gmail.com</a>&gt;&gt; wrote:<br class=3D"m_-1926012925832773148gmail_ms=
g">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few of us met informally tod=
ay to discuss the<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability scenario in some more d=
etail with the goal of<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining the narrow focus on a vul=
nerability assessment slice<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our notional environment.=C2=
=A0 We are tending to look at<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major components as black boxes with =
interfaces and data format<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations, and we are not necessar=
ily concerned with how<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those components do things internally=
/behind the scenes.<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting was recorded (you can fin=
d it with today&#39;s date at<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 The topic of discussion w=
as primarily in the &quot;phase 1&quot;<br class=3D"m_-1926012925832773148g=
mail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what Danny sent to the list n=
ot very long ago [2], and<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a *starting point* diagra=
m [3].<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who met today are (roughly)=
 agreed on the six main<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;components&quot; represented in=
 that diagram, but also see that we<br class=3D"m_-1926012925832773148gmail=
_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some work ahead.=C2=A0 Specifica=
lly, we quickly recognized that<br class=3D"m_-1926012925832773148gmail_msg=
">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the assumptions the vulnerabi=
lity draft makes may be<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions we cannot afford to make =
and need to include in the<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<br class=3D"m_-192601292=
5832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it would be a good idea to=
 have another informal<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in a couple of weeks (Febr=
uary 2) at the same time<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern / 3pm UTC), using the s=
ame WebEx [4].=C2=A0 =C2=A0At that<br class=3D"m_-1926012925832773148gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we intend to roll through the vu=
lnerability assessment<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assumptions in an effort to =
determine which ones can be<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assumptions and which ones ca=
nnot.=C2=A0 Then we&#39;ll take<br class=3D"m_-1926012925832773148gmail_msg=
">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look at the diagram and work =
on its next version.<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<br class=3D"m_-1926012925=
832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Danny, Stephen, and Jerome =
for joining and contributing!<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"m_-19260129=
25832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=3D"m_-19260129258327731=
48gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"m_-1=
926012925832773148gmail_msg" target=3D"_blank">https://drive.google.com/ope=
n?<wbr>id=3D<wbr>0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br class=3D"m_-1926012925=
832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2] <a href=3D"https://mailarchive.ie=
tf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=
=3D"m_-1926012925832773148gmail_msg" target=3D"_blank">https://mailarchive.=
ietf.org/<wbr>arch/msg/sacm/_LiKlyvAws_<wbr>OVLFhB5NSU58MXDM</a><br class=
=3D"m_-1926012925832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"m_-1=
926012925832773148gmail_msg" target=3D"_blank">https://drive.google.com/ope=
n?<wbr>id=3D<wbr>0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><br class=3D"m_-1926012925=
832773148gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=3D"https://ietf.webex.com=
/meet/sacm" rel=3D"noreferrer" class=3D"m_-1926012925832773148gmail_msg" ta=
rget=3D"_blank">https://ietf.webex.com/meet/<wbr>sacm</a><br class=3D"m_-19=
26012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
&gt; ______________________________<wbr>_________________<br class=3D"m_-19=
26012925832773148gmail_msg">
&gt; sacm mailing list<br class=3D"m_-1926012925832773148gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"m_-1926012925832773148gmail_=
msg" target=3D"_blank">sacm@ietf.org</a><br class=3D"m_-1926012925832773148=
gmail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferr=
er" class=3D"m_-1926012925832773148gmail_msg" target=3D"_blank">https://www=
.ietf.org/mailman/<wbr>listinfo/sacm</a><br class=3D"m_-1926012925832773148=
gmail_msg">
&gt;<br class=3D"m_-1926012925832773148gmail_msg">
</blockquote></div></div></div></div>
<br>______________________________<wbr>_________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/sacm</a><br>
<br></blockquote></div><br></div>

--001a11c00e4e6503e105478fe4e6--


From nobody Thu Feb  2 10:00:41 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 21F8B1298D9 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 10:00:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MSPY29V1HQkk for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 10:00:37 -0800 (PST)
Received: from mail-ot0-x234.google.com (mail-ot0-x234.google.com [IPv6:2607:f8b0:4003:c0f::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 361E512995B for <sacm@ietf.org>; Thu,  2 Feb 2017 10:00:05 -0800 (PST)
Received: by mail-ot0-x234.google.com with SMTP id f9so17841602otd.1 for <sacm@ietf.org>; Thu, 02 Feb 2017 10:00:05 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=d/+c1KHVEPYH9x6QC+dMkEujcmZnp2A2b8AbvF/oWjI=; b=syPkaGVlKEIkeDDR6a5bVDsHe/agwCJ1AG29IZcH+zeSj4rVUN4So1i7+zP0NFUOt0 VlZFyrtdKC9t/DqtR93HoVtvckJFCdIFMWhxJfO6HdC3e4oz80F3+lEn/vlhr/exsk44 LWPfHXctJJG2eYWmiN9W34pHU/w4gkiaM61RZLszOOQcf4dgx9DSAFdwyy9VKN9wlpJF tRcuewUC6FnuxU+KLJ836rv5XH4FQ9AzeENp9PywFjeQVck7S/qrzkGox13gzqJ65OhV ixAxKWXayb0yBfB0E3ho/pr0ouOethMArSIHHvTjgY7OEQccEfZWDTBRG0ypSdO5U4tK TdXg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=d/+c1KHVEPYH9x6QC+dMkEujcmZnp2A2b8AbvF/oWjI=; b=DdmyckgasWMkzwiI4WsEKP8IeQ84iRBvKaLwjyK+x97EmwFJ7/WXzLvnRUylZGLSq2 1ROzR3bAgRCTlwsnioiU8RsOaMuVhMNOaObRExCVNixyd4umL93FTq5XL9u6N4oNjxkU 5SnLeuzUzBUeIHfhtqmw6UFkqi5GipNBZb2vNPGbducFA31yhNFDjVGxdqVzhip3bAuK 8GZEXAh2pTx3JhnwENqxTpdXhrOO/unXf88OEP7v8xOzPrGh/VO0LaSdJxNzBJVpSqHy cc+6x7mOFewZZfPJkCAgSmGce/4tMZGx51cXsR8cKvX80TeUIne3Ndsb84T+eagBAr3z qVdA==
X-Gm-Message-State: AMke39kkuj2FDLDyRY09JMIfz9WJpCF8hlS9HDFlZ35jQWWEXzcUqmc5u0KSSvdl9LV7pizJm5HejpEZ+uhf6w==
X-Received: by 10.157.6.138 with SMTP id 10mr4551442otx.73.1486058404130; Thu, 02 Feb 2017 10:00:04 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com>
In-Reply-To: <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 17:59:53 +0000
Message-ID: <CACknUNVs3XCMdVYi3-FnTMpQ1x8x6_gr3tQ7pzuPBKsiWF4duw@mail.gmail.com>
To: Bill Munyan <bill.munyan.ietf@gmail.com>
Content-Type: multipart/alternative; boundary=94eb2c11ed404b47d505478fef47
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/Q8bMYbPqLz7bI0VIYfLUVZXvrcA>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 18:00:40 -0000

--94eb2c11ed404b47d505478fef47
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Yes! Noting that information is critical, but if we set out to put all of
that in the diagram, we'll lose.  What if we agree to the sequence at the
high level, then number the steps, and then write about those steps in the
wiki after talking about them here and in informal sessions for the win?

On Thu, Feb 2, 2017 at 11:57 AM Bill Munyan <bill.munyan.ietf@gmail.com>
wrote:

> Is it worth noting in the diagram (if not, I think it needs to be noted
> somewhere nonetheless) that the steps of "get endpoints" and subsequent
> "evaluate" should be making some determination of whether or not to colle=
ct
> for an endpoint?  For example, if an endpoint has no assessment results o=
r
> the assessment results are considered "stale", then the collection step
> would take place.  I understand that could be too much detail for the sco=
pe
> of the diagram, but I just wanted to note it somewhere.
>
> Cheers,
> -Bill M.
>
>
> On Thu, Feb 2, 2017 at 12:44 PM, Adam Montville <
> adam.w.montville@gmail.com> wrote:
>
> Thanks for the feedback!  I've attached a modified version of the diagram
> that collapses the endpoint and assessment result repositories (by keepin=
g
> the endpoint repository).  Where would you propose we focus on enhancing
> the diagram?  Remember that it's a sequence diagram, which might do well
> with some more specific details captured in text or a different form of
> diagram.
>
> What do folks think about using one or more OVAL definitions as a startin=
g
> point?
>
> Adam
>
>
> On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz <
> henk.birkholz@sit.fraunhofer.de> wrote:
>
> ## A Few Comments
>
> * I agree that the diagram pretty much captures a "one time snapshot".
> * Collapsing the highlighted components seems to be a feasible idea.
> * I agree that the diagram could be implemented given an appropriate set
> of initial data.
> * I suppose there is the risk that one has to scrap everything
> implemented when we start trying to make it a continuous process.
> * I'd recommend to start with a generic block of PoC code that provides
> the functions of a SACM component to get input and create output (maybe
> using dbus, chained event-loops, blocking waits on fifos, or IP over
> loopback? A better coder than me should bash these suggestions).
>
> ## One, Two, or Three Tasks
>
> * Creating component code that can create the (downstream?) flow of
> information is urgent and important, I think.
> * Enhancing the diagram to represent the continuous cycle with at least
> one trigger (as illustrated by Bill; new software, new VDI, new
> endpoints, stale results, etc.) is important, but not as urgent. It
> might save time though by reducing the afore mentioned risk to shoot
> your self in the foot by creating a too specific proof of concept of the
> one time snapshot approach, I think.
> * Selecting a set of initial data derived from OVAL to be used in the
> one shot snapshot seems to be a feasible approach to me, but I am not
> sure how the group thinks about that.
>
> Does that assessment represent the general opinion, or is that just mine?
>
> Viele Gr=C3=BC=C3=9Fe,
>
> Henk
>
> On 02/02/2017 05:28 PM, Adam Montville wrote:
> > Hi Everyone.  A few of us were able to make the vulnerability scenario
> > call today and I think we had a good, though at times spirited,
> > discussion.  We did record the meeting, which is available at [1].  We
> > discussed the attached (annotated with some meeting notes) UML-ish
> > sequence diagram.  I had created that diagram to start a conversation
> > (mission accomplished on that front I think) -- a conversation that
> > would lead us toward identifying the discrete components, interfaces,
> > and information required to be sent over those interfaces.  The UML-ish
> > diagram represents a *single* flow through the system -- a "one-time"
> > flow through the system.  It ignores, for the time being, the continuou=
s
> > aspect of our charter in favor of getting started with the basics.  Onc=
e
> > we have a good understanding of the basics -- the components,
> > interfaces, and information required -- we can start look at a
> > continuous monitoring sequence (which could be represented as a distinc=
t
> > diagram) to determine what more we need.  Then, I think, we can start
> > drafting solutions.
> >
> > One of the first issues is that we need to figure out if the components
> > in the base flow are accurate.  The main suggestion we've tossed around
> > so far is to combine the Endpoint Repository with the Assessment Result
> > Repository.
> >
> > We talked briefly about what interface we could use for the VDD
> > Repository, and naturally ROLIE came up as an option.
> >
> > We talked a little bit about the first "get endpoints" operation betwee=
n
> > the Vulnerability Assessor and the Endpoint Repository -- specifically
> > about whether we should represent on this sequence diagram that
> > information supporting a judgement of "stale" would be needed.
> >
> > We left open the time when we would next meet, favoring to work that ou=
t
> > on-list.  Next week is TCG, so that may be difficult; the following wee=
k
> > is RSA, so that may be difficult.
> >
> > For those who were in attendance today, please add to this note with
> > your comments/corrections.
> >
> > Kind regards,
> >
> > Adam
> >
> > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >
> > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
> > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote:
> >
> >     Hi everyone.  Just a friendly reminder that we are planning to meet
> >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)
> >     using SACM's meeting room at https://ietf.webex.com/meet/sacm.
> >
> >     Kind regards,
> >
> >     Adam
> >
> >
> >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
> >     <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>>
> wrote:
> >
> >         Hello. A few of us met informally today to discuss the
> >         vulnerability scenario in some more detail with the goal of
> >         maintaining the narrow focus on a vulnerability assessment slic=
e
> >         through our notional environment.  We are tending to look at
> >         major components as black boxes with interfaces and data format
> >         expectations, and we are not necessarily concerned with how
> >         those components do things internally/behind the scenes.
> >
> >         The meeting was recorded (you can find it with today's date at
> >         [1]).  The topic of discussion was primarily in the "phase 1"
> >         area of what Danny sent to the list not very long ago [2], and
> >         resulted in a *starting point* diagram [3].
> >
> >         The group who met today are (roughly) agreed on the six main
> >         "components" represented in that diagram, but also see that we
> >         have some work ahead.  Specifically, we quickly recognized that
> >         some of the assumptions the vulnerability draft makes may be
> >         assumptions we cannot afford to make and need to include in the
> >         exploration.
> >
> >         We thought it would be a good idea to have another informal
> >         discussion in a couple of weeks (February 2) at the same time
> >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At that
> >         time we intend to roll through the vulnerability assessment
> >         scenario assumptions in an effort to determine which ones can b=
e
> >         left as assumptions and which ones cannot.  Then we'll take
> >         another look at the diagram and work on its next version.
> >
> >         Stay tuned.
> >
> >         Thanks to Danny, Stephen, and Jerome for joining and
> contributing!
> >
> >         Kind regards,
> >
> >         Adam
> >
> >
> >         [1]
> https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >         [2]
> https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> >         [3]
> https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> >         [4] https://ietf.webex.com/meet/sacm
> >
> >
> >
> > _______________________________________________
> > sacm mailing list
> > sacm@ietf.org
> > https://www.ietf.org/mailman/listinfo/sacm
> >
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>
>

--94eb2c11ed404b47d505478fef47
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Yes! Noting that information is critical, but if we set ou=
t to put all of that in the diagram, we&#39;ll lose.=C2=A0 What if we agree=
 to the sequence at the high level, then number the steps, and then write a=
bout those steps in the wiki after talking about them here and in informal =
sessions for the win?</div><br><div class=3D"gmail_quote"><div dir=3D"ltr">=
On Thu, Feb 2, 2017 at 11:57 AM Bill Munyan &lt;<a href=3D"mailto:bill.muny=
an.ietf@gmail.com">bill.munyan.ietf@gmail.com</a>&gt; wrote:<br></div><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #cc=
c solid;padding-left:1ex"><div dir=3D"ltr" class=3D"gmail_msg"><div class=
=3D"gmail_default gmail_msg" style=3D"font-family:verdana,sans-serif">Is it=
 worth noting in the diagram (if not, I think it needs to be noted somewher=
e nonetheless) that the steps of &quot;get endpoints&quot; and subsequent &=
quot;evaluate&quot; should be making some determination of whether or not t=
o collect for an endpoint?=C2=A0 For example, if an endpoint has no assessm=
ent results or the assessment results are considered &quot;stale&quot;, the=
n the collection step would take place.=C2=A0 I understand that could be to=
o much detail for the scope of the diagram, but I just wanted to note it so=
mewhere.</div><div class=3D"gmail_default gmail_msg" style=3D"font-family:v=
erdana,sans-serif"><br class=3D"gmail_msg"></div><div class=3D"gmail_defaul=
t gmail_msg" style=3D"font-family:verdana,sans-serif">Cheers,=C2=A0</div><d=
iv class=3D"gmail_default gmail_msg" style=3D"font-family:verdana,sans-seri=
f">-Bill M.</div><div class=3D"gmail_default gmail_msg" style=3D"font-famil=
y:verdana,sans-serif"><br class=3D"gmail_msg"></div></div><div class=3D"gma=
il_extra gmail_msg"><br class=3D"gmail_msg"><div class=3D"gmail_quote gmail=
_msg">On Thu, Feb 2, 2017 at 12:44 PM, Adam Montville <span dir=3D"ltr" cla=
ss=3D"gmail_msg">&lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D=
"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;</span> wro=
te:<br class=3D"gmail_msg"><blockquote class=3D"gmail_quote gmail_msg" styl=
e=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div di=
r=3D"ltr" class=3D"gmail_msg">Thanks for the feedback!=C2=A0 I&#39;ve attac=
hed a modified version of the diagram that collapses the endpoint and asses=
sment result repositories (by keeping the endpoint repository).=C2=A0 Where=
 would you propose we focus on enhancing the diagram?=C2=A0 Remember that i=
t&#39;s a sequence diagram, which might do well with some more specific det=
ails captured in text or a different form of diagram.<div class=3D"gmail_ms=
g"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">What do folks thi=
nk about using one or more OVAL definitions as a starting point?</div><span=
 class=3D"m_947929965395893272HOEnZb gmail_msg"><font color=3D"#888888" cla=
ss=3D"gmail_msg"><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><di=
v class=3D"gmail_msg">Adam</div></font></span><div class=3D"gmail_msg"><div=
 class=3D"m_947929965395893272h5 gmail_msg"><div class=3D"gmail_msg"><br cl=
ass=3D"gmail_msg"></div><br class=3D"gmail_msg"><div class=3D"gmail_quote g=
mail_msg"><div dir=3D"ltr" class=3D"gmail_msg">On Thu, Feb 2, 2017 at 10:53=
 AM Henk Birkholz &lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" cl=
ass=3D"gmail_msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a>&gt;=
 wrote:<br class=3D"gmail_msg"></div><blockquote class=3D"gmail_quote gmail=
_msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1e=
x">## A Few Comments<br class=3D"m_947929965395893272m_-1926012925832773148=
gmail_msg gmail_msg">
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
* I agree that the diagram pretty much captures a &quot;one time snapshot&q=
uot;.<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail=
_msg">
* Collapsing the highlighted components seems to be a feasible idea.<br cla=
ss=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
* I agree that the diagram could be implemented given an appropriate set<br=
 class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
of initial data.<br class=3D"m_947929965395893272m_-1926012925832773148gmai=
l_msg gmail_msg">
* I suppose there is the risk that one has to scrap everything<br class=3D"=
m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
implemented when we start trying to make it a continuous process.<br class=
=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
* I&#39;d recommend to start with a generic block of PoC code that provides=
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
the functions of a SACM component to get input and create output (maybe<br =
class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
using dbus, chained event-loops, blocking waits on fifos, or IP over<br cla=
ss=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
loopback? A better coder than me should bash these suggestions).<br class=
=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
## One, Two, or Three Tasks<br class=3D"m_947929965395893272m_-192601292583=
2773148gmail_msg gmail_msg">
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
* Creating component code that can create the (downstream?) flow of<br clas=
s=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
information is urgent and important, I think.<br class=3D"m_947929965395893=
272m_-1926012925832773148gmail_msg gmail_msg">
* Enhancing the diagram to represent the continuous cycle with at least<br =
class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
one trigger (as illustrated by Bill; new software, new VDI, new<br class=3D=
"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
endpoints, stale results, etc.) is important, but not as urgent. It<br clas=
s=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
might save time though by reducing the afore mentioned risk to shoot<br cla=
ss=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
your self in the foot by creating a too specific proof of concept of the<br=
 class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
one time snapshot approach, I think.<br class=3D"m_947929965395893272m_-192=
6012925832773148gmail_msg gmail_msg">
* Selecting a set of initial data derived from OVAL to be used in the<br cl=
ass=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
one shot snapshot seems to be a feasible approach to me, but I am not<br cl=
ass=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
sure how the group thinks about that.<br class=3D"m_947929965395893272m_-19=
26012925832773148gmail_msg gmail_msg">
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
Does that assessment represent the general opinion, or is that just mine?<b=
r class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
Viele Gr=C3=BC=C3=9Fe,<br class=3D"m_947929965395893272m_-19260129258327731=
48gmail_msg gmail_msg">
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
Henk<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
On 02/02/2017 05:28 PM, Adam Montville wrote:<br class=3D"m_947929965395893=
272m_-1926012925832773148gmail_msg gmail_msg">
&gt; Hi Everyone.=C2=A0 A few of us were able to make the vulnerability sce=
nario<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail=
_msg">
&gt; call today and I think we had a good, though at times spirited,<br cla=
ss=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; discussion.=C2=A0 We did record the meeting, which is available at [1]=
.=C2=A0 We<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg =
gmail_msg">
&gt; discussed the attached (annotated with some meeting notes) UML-ish<br =
class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; sequence diagram.=C2=A0 I had created that diagram to start a conversa=
tion<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; (mission accomplished on that front I think) -- a conversation that<br=
 class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; would lead us toward identifying the discrete components, interfaces,<=
br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; and information required to be sent over those interfaces.=C2=A0 The U=
ML-ish<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmai=
l_msg">
&gt; diagram represents a *single* flow through the system -- a &quot;one-t=
ime&quot;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg g=
mail_msg">
&gt; flow through the system.=C2=A0 It ignores, for the time being, the con=
tinuous<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gma=
il_msg">
&gt; aspect of our charter in favor of getting started with the basics.=C2=
=A0 Once<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gm=
ail_msg">
&gt; we have a good understanding of the basics -- the components,<br class=
=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; interfaces, and information required -- we can start look at a<br clas=
s=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; continuous monitoring sequence (which could be represented as a distin=
ct<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_ms=
g">
&gt; diagram) to determine what more we need.=C2=A0 Then, I think, we can s=
tart<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; drafting solutions.<br class=3D"m_947929965395893272m_-192601292583277=
3148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; One of the first issues is that we need to figure out if the component=
s<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg=
">
&gt; in the base flow are accurate.=C2=A0 The main suggestion we&#39;ve tos=
sed around<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg =
gmail_msg">
&gt; so far is to combine the Endpoint Repository with the Assessment Resul=
t<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg=
">
&gt; Repository.<br class=3D"m_947929965395893272m_-1926012925832773148gmai=
l_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; We talked briefly about what interface we could use for the VDD<br cla=
ss=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; Repository, and naturally ROLIE came up as an option.<br class=3D"m_94=
7929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; We talked a little bit about the first &quot;get endpoints&quot; opera=
tion between<br class=3D"m_947929965395893272m_-1926012925832773148gmail_ms=
g gmail_msg">
&gt; the Vulnerability Assessor and the Endpoint Repository -- specifically=
<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
>
&gt; about whether we should represent on this sequence diagram that<br cla=
ss=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; information supporting a judgement of &quot;stale&quot; would be neede=
d.<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_ms=
g">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; We left open the time when we would next meet, favoring to work that o=
ut<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_ms=
g">
&gt; on-list.=C2=A0 Next week is TCG, so that may be difficult; the followi=
ng week<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gma=
il_msg">
&gt; is RSA, so that may be difficult.<br class=3D"m_947929965395893272m_-1=
926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; For those who were in attendance today, please add to this note with<b=
r class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; your comments/corrections.<br class=3D"m_947929965395893272m_-19260129=
25832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; Kind regards,<br class=3D"m_947929965395893272m_-1926012925832773148gm=
ail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; Adam<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg g=
mail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; [1] <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHp=
VR0tMd1E" rel=3D"noreferrer" class=3D"m_947929965395893272m_-19260129258327=
73148gmail_msg gmail_msg" target=3D"_blank">https://drive.google.com/open?i=
d=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br class=3D"m_947929965395893272m_-192=
6012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montville<br class=3D"m_94792996=
5395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"m_947929965=
395893272m_-1926012925832773148gmail_msg gmail_msg" target=3D"_blank">adam.=
w.montville@gmail.com</a> &lt;mailto:<a href=3D"mailto:adam.w.montville@gma=
il.com" class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;&gt; wrote:<br cla=
ss=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a friendly reminder that we=
 are planning to meet<br class=3D"m_947929965395893272m_-192601292583277314=
8gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the same time (2/2 @ 10am Ea=
stern/3pm UTC)<br class=3D"m_947929965395893272m_-1926012925832773148gmail_=
msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting room at <a href=3D"https:/=
/ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"m_947929965395893272=
m_-1926012925832773148gmail_msg gmail_msg" target=3D"_blank">https://ietf.w=
ebex.com/meet/sacm</a>.<br class=3D"m_947929965395893272m_-1926012925832773=
148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"m_947929965395893272m_-19=
26012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"m_947929965395893272m_-19260129258=
32773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:35 AM Adam Montville<br =
class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montville@gmail.com" c=
lass=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg" targ=
et=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto:<a href=3D"mailto:a=
dam.w.montville@gmail.com" class=3D"m_947929965395893272m_-1926012925832773=
148gmail_msg gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt=
;&gt; wrote:<br class=3D"m_947929965395893272m_-1926012925832773148gmail_ms=
g gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few of us met informally tod=
ay to discuss the<br class=3D"m_947929965395893272m_-1926012925832773148gma=
il_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability scenario in some more d=
etail with the goal of<br class=3D"m_947929965395893272m_-19260129258327731=
48gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining the narrow focus on a vul=
nerability assessment slice<br class=3D"m_947929965395893272m_-192601292583=
2773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our notional environment.=C2=
=A0 We are tending to look at<br class=3D"m_947929965395893272m_-1926012925=
832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major components as black boxes with =
interfaces and data format<br class=3D"m_947929965395893272m_-1926012925832=
773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations, and we are not necessar=
ily concerned with how<br class=3D"m_947929965395893272m_-19260129258327731=
48gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those components do things internally=
/behind the scenes.<br class=3D"m_947929965395893272m_-1926012925832773148g=
mail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting was recorded (you can fin=
d it with today&#39;s date at<br class=3D"m_947929965395893272m_-1926012925=
832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 The topic of discussion w=
as primarily in the &quot;phase 1&quot;<br class=3D"m_947929965395893272m_-=
1926012925832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what Danny sent to the list n=
ot very long ago [2], and<br class=3D"m_947929965395893272m_-19260129258327=
73148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a *starting point* diagra=
m [3].<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmai=
l_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who met today are (roughly)=
 agreed on the six main<br class=3D"m_947929965395893272m_-1926012925832773=
148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;components&quot; represented in=
 that diagram, but also see that we<br class=3D"m_947929965395893272m_-1926=
012925832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some work ahead.=C2=A0 Specifica=
lly, we quickly recognized that<br class=3D"m_947929965395893272m_-19260129=
25832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the assumptions the vulnerabi=
lity draft makes may be<br class=3D"m_947929965395893272m_-1926012925832773=
148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions we cannot afford to make =
and need to include in the<br class=3D"m_947929965395893272m_-1926012925832=
773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<br class=3D"m_9479299653=
95893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it would be a good idea to=
 have another informal<br class=3D"m_947929965395893272m_-19260129258327731=
48gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in a couple of weeks (Febr=
uary 2) at the same time<br class=3D"m_947929965395893272m_-192601292583277=
3148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern / 3pm UTC), using the s=
ame WebEx [4].=C2=A0 =C2=A0At that<br class=3D"m_947929965395893272m_-19260=
12925832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we intend to roll through the vu=
lnerability assessment<br class=3D"m_947929965395893272m_-19260129258327731=
48gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assumptions in an effort to =
determine which ones can be<br class=3D"m_947929965395893272m_-192601292583=
2773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assumptions and which ones ca=
nnot.=C2=A0 Then we&#39;ll take<br class=3D"m_947929965395893272m_-19260129=
25832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look at the diagram and work =
on its next version.<br class=3D"m_947929965395893272m_-1926012925832773148=
gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<br class=3D"m_94792996539=
5893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Danny, Stephen, and Jerome =
for joining and contributing!<br class=3D"m_947929965395893272m_-1926012925=
832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"m_947929965=
395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=3D"m_947929965395893272=
m_-1926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"m_94=
7929965395893272m_-1926012925832773148gmail_msg gmail_msg" target=3D"_blank=
">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br cl=
ass=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2] <a href=3D"https://mailarchive.ie=
tf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=
=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg" target=
=3D"_blank">https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NS=
U58MXDM</a><br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg=
 gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"m_94=
7929965395893272m_-1926012925832773148gmail_msg gmail_msg" target=3D"_blank=
">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><br cl=
ass=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=3D"https://ietf.webex.com=
/meet/sacm" rel=3D"noreferrer" class=3D"m_947929965395893272m_-192601292583=
2773148gmail_msg gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/s=
acm</a><br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gma=
il_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
&gt; _______________________________________________<br class=3D"m_94792996=
5395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; sacm mailing list<br class=3D"m_947929965395893272m_-19260129258327731=
48gmail_msg gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"m_947929965395893272m_-19260=
12925832773148gmail_msg gmail_msg" target=3D"_blank">sacm@ietf.org</a><br c=
lass=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferr=
er" class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg"=
 target=3D"_blank">https://www.ietf.org/mailman/listinfo/sacm</a><br class=
=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_msg">
&gt;<br class=3D"m_947929965395893272m_-1926012925832773148gmail_msg gmail_=
msg">
</blockquote></div></div></div></div>
<br class=3D"gmail_msg">_______________________________________________<br =
class=3D"gmail_msg">
sacm mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm=
@ietf.org</a><br class=3D"gmail_msg">
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" c=
lass=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/listinfo/=
sacm</a><br class=3D"gmail_msg">
<br class=3D"gmail_msg"></blockquote></div><br class=3D"gmail_msg"></div>
</blockquote></div>

--94eb2c11ed404b47d505478fef47--


From nobody Thu Feb  2 10:02:25 2017
Return-Path: <bill.munyan.ietf@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6EAA1294E0 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 10:02:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.999
X-Spam-Level: 
X-Spam-Status: No, score=-0.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id INrB8-ZqXPSQ for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 10:02:21 -0800 (PST)
Received: from mail-ot0-x22b.google.com (mail-ot0-x22b.google.com [IPv6:2607:f8b0:4003:c0f::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20F59129500 for <sacm@ietf.org>; Thu,  2 Feb 2017 10:01:23 -0800 (PST)
Received: by mail-ot0-x22b.google.com with SMTP id 32so17836878oth.3 for <sacm@ietf.org>; Thu, 02 Feb 2017 10:01:23 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=V6Qbt+1s/M/Yo9Y6Sm3aldeNzpC9ZfLYQzrtM1ka8Gs=; b=FkfIXKMi9Pb/q+MZjg72GB+EGm8KeNiANVp5mKjmOdvffJm8xUeYtd2biwy4ZHf9yw l2bnMipBYJ0Zd2bNNK6sjrIf1VA7MxiZ/wC6WDmhe+B5fMhvFzihckCpbuKxQusBpZT6 JqryNFIZPrMBvTUeORzrJ0lvbvvfrzSc41GHNNSDlXKIP9OwPz/ClM9pD05fgfVV90H/ 9Ok4h0yCZSEem9JqCUs+FwwXxLXp+KqmnumXwz/+za0w+1IvQLtyJWzKFd3ZlvSg5X5s pxOP5g8SSpCz3GVQTvyTh5ITZZxkutN1mpDLj9yqFqWZz56AX/kMSmuV/ssrEW3pwjbr 8h3A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=V6Qbt+1s/M/Yo9Y6Sm3aldeNzpC9ZfLYQzrtM1ka8Gs=; b=MNPjG7YmUkHiSfP5RIPupTg4SrqNxNDphzSR2+LjwV4C29XTJWWm4qUKoUj+3+UoW+ v9Fjh+9EatAapGeZcaYFSbI9JJwJCdmO1oJIXQs6gwOFVgffYl0moeduUo/ZFH3Ajy4l SKZqJ8lrcxEPWgxTFdYyXgt0l/0gQF7k+I9bR8frWVAs6kaR1MNhrY2XvctpFk+cn5fG v1WZlwJ1bDtKMNLRrwRYgTzJ16bo9DF+7blucKem9qtmVW0waVPrmXdEmRi7qIYAZaaZ X6Vn3mEHdj/EREDpZDrf3Efoz+kieYhwWn3nVGJBT/lfx9s4IcYUQm2ZllJJLG0wGloK /ukA==
X-Gm-Message-State: AIkVDXLiMoAODf3ewUIuvgIX19kPNtMousLNEGfSo3+EWBmpvPhlKrQV4vSLVLle2GdGtd5Ad3vRnYlbMD28Ew==
X-Received: by 10.157.53.42 with SMTP id o39mr5246521otc.157.1486058482201; Thu, 02 Feb 2017 10:01:22 -0800 (PST)
MIME-Version: 1.0
Received: by 10.182.65.168 with HTTP; Thu, 2 Feb 2017 10:01:21 -0800 (PST)
In-Reply-To: <CACknUNVs3XCMdVYi3-FnTMpQ1x8x6_gr3tQ7pzuPBKsiWF4duw@mail.gmail.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com> <CACknUNVs3XCMdVYi3-FnTMpQ1x8x6_gr3tQ7pzuPBKsiWF4duw@mail.gmail.com>
From: Bill Munyan <bill.munyan.ietf@gmail.com>
Date: Thu, 2 Feb 2017 13:01:21 -0500
Message-ID: <CAKUOEQx2wQY5xhhQmLLJsVhKPz5TMFo=TrCe9FykU7TymqV=rw@mail.gmail.com>
To: Adam Montville <adam.w.montville@gmail.com>
Content-Type: multipart/alternative; boundary=001a11c00e4ef27d3d05478ff38b
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/pwCWLBsuvZ9dzkdChWBIgzNDiMI>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 18:02:24 -0000

--001a11c00e4ef27d3d05478ff38b
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

+1


On Thu, Feb 2, 2017 at 12:59 PM, Adam Montville <adam.w.montville@gmail.com=
>
wrote:

> Yes! Noting that information is critical, but if we set out to put all of
> that in the diagram, we'll lose.  What if we agree to the sequence at the
> high level, then number the steps, and then write about those steps in th=
e
> wiki after talking about them here and in informal sessions for the win?
>
> On Thu, Feb 2, 2017 at 11:57 AM Bill Munyan <bill.munyan.ietf@gmail.com>
> wrote:
>
>> Is it worth noting in the diagram (if not, I think it needs to be noted
>> somewhere nonetheless) that the steps of "get endpoints" and subsequent
>> "evaluate" should be making some determination of whether or not to coll=
ect
>> for an endpoint?  For example, if an endpoint has no assessment results =
or
>> the assessment results are considered "stale", then the collection step
>> would take place.  I understand that could be too much detail for the sc=
ope
>> of the diagram, but I just wanted to note it somewhere.
>>
>> Cheers,
>> -Bill M.
>>
>>
>> On Thu, Feb 2, 2017 at 12:44 PM, Adam Montville <
>> adam.w.montville@gmail.com> wrote:
>>
>> Thanks for the feedback!  I've attached a modified version of the diagra=
m
>> that collapses the endpoint and assessment result repositories (by keepi=
ng
>> the endpoint repository).  Where would you propose we focus on enhancing
>> the diagram?  Remember that it's a sequence diagram, which might do well
>> with some more specific details captured in text or a different form of
>> diagram.
>>
>> What do folks think about using one or more OVAL definitions as a
>> starting point?
>>
>> Adam
>>
>>
>> On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz <
>> henk.birkholz@sit.fraunhofer.de> wrote:
>>
>> ## A Few Comments
>>
>> * I agree that the diagram pretty much captures a "one time snapshot".
>> * Collapsing the highlighted components seems to be a feasible idea.
>> * I agree that the diagram could be implemented given an appropriate set
>> of initial data.
>> * I suppose there is the risk that one has to scrap everything
>> implemented when we start trying to make it a continuous process.
>> * I'd recommend to start with a generic block of PoC code that provides
>> the functions of a SACM component to get input and create output (maybe
>> using dbus, chained event-loops, blocking waits on fifos, or IP over
>> loopback? A better coder than me should bash these suggestions).
>>
>> ## One, Two, or Three Tasks
>>
>> * Creating component code that can create the (downstream?) flow of
>> information is urgent and important, I think.
>> * Enhancing the diagram to represent the continuous cycle with at least
>> one trigger (as illustrated by Bill; new software, new VDI, new
>> endpoints, stale results, etc.) is important, but not as urgent. It
>> might save time though by reducing the afore mentioned risk to shoot
>> your self in the foot by creating a too specific proof of concept of the
>> one time snapshot approach, I think.
>> * Selecting a set of initial data derived from OVAL to be used in the
>> one shot snapshot seems to be a feasible approach to me, but I am not
>> sure how the group thinks about that.
>>
>> Does that assessment represent the general opinion, or is that just mine=
?
>>
>> Viele Gr=C3=BC=C3=9Fe,
>>
>> Henk
>>
>> On 02/02/2017 05:28 PM, Adam Montville wrote:
>> > Hi Everyone.  A few of us were able to make the vulnerability scenario
>> > call today and I think we had a good, though at times spirited,
>> > discussion.  We did record the meeting, which is available at [1].  We
>> > discussed the attached (annotated with some meeting notes) UML-ish
>> > sequence diagram.  I had created that diagram to start a conversation
>> > (mission accomplished on that front I think) -- a conversation that
>> > would lead us toward identifying the discrete components, interfaces,
>> > and information required to be sent over those interfaces.  The UML-is=
h
>> > diagram represents a *single* flow through the system -- a "one-time"
>> > flow through the system.  It ignores, for the time being, the continuo=
us
>> > aspect of our charter in favor of getting started with the basics.  On=
ce
>> > we have a good understanding of the basics -- the components,
>> > interfaces, and information required -- we can start look at a
>> > continuous monitoring sequence (which could be represented as a distin=
ct
>> > diagram) to determine what more we need.  Then, I think, we can start
>> > drafting solutions.
>> >
>> > One of the first issues is that we need to figure out if the component=
s
>> > in the base flow are accurate.  The main suggestion we've tossed aroun=
d
>> > so far is to combine the Endpoint Repository with the Assessment Resul=
t
>> > Repository.
>> >
>> > We talked briefly about what interface we could use for the VDD
>> > Repository, and naturally ROLIE came up as an option.
>> >
>> > We talked a little bit about the first "get endpoints" operation betwe=
en
>> > the Vulnerability Assessor and the Endpoint Repository -- specifically
>> > about whether we should represent on this sequence diagram that
>> > information supporting a judgement of "stale" would be needed.
>> >
>> > We left open the time when we would next meet, favoring to work that o=
ut
>> > on-list.  Next week is TCG, so that may be difficult; the following we=
ek
>> > is RSA, so that may be difficult.
>> >
>> > For those who were in attendance today, please add to this note with
>> > your comments/corrections.
>> >
>> > Kind regards,
>> >
>> > Adam
>> >
>> > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>> >
>> > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>> > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote=
:
>> >
>> >     Hi everyone.  Just a friendly reminder that we are planning to mee=
t
>> >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)
>> >     using SACM's meeting room at https://ietf.webex.com/meet/sacm.
>> >
>> >     Kind regards,
>> >
>> >     Adam
>> >
>> >
>> >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>> >     <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>>
>> wrote:
>> >
>> >         Hello. A few of us met informally today to discuss the
>> >         vulnerability scenario in some more detail with the goal of
>> >         maintaining the narrow focus on a vulnerability assessment sli=
ce
>> >         through our notional environment.  We are tending to look at
>> >         major components as black boxes with interfaces and data forma=
t
>> >         expectations, and we are not necessarily concerned with how
>> >         those components do things internally/behind the scenes.
>> >
>> >         The meeting was recorded (you can find it with today's date at
>> >         [1]).  The topic of discussion was primarily in the "phase 1"
>> >         area of what Danny sent to the list not very long ago [2], and
>> >         resulted in a *starting point* diagram [3].
>> >
>> >         The group who met today are (roughly) agreed on the six main
>> >         "components" represented in that diagram, but also see that we
>> >         have some work ahead.  Specifically, we quickly recognized tha=
t
>> >         some of the assumptions the vulnerability draft makes may be
>> >         assumptions we cannot afford to make and need to include in th=
e
>> >         exploration.
>> >
>> >         We thought it would be a good idea to have another informal
>> >         discussion in a couple of weeks (February 2) at the same time
>> >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At that
>> >         time we intend to roll through the vulnerability assessment
>> >         scenario assumptions in an effort to determine which ones can =
be
>> >         left as assumptions and which ones cannot.  Then we'll take
>> >         another look at the diagram and work on its next version.
>> >
>> >         Stay tuned.
>> >
>> >         Thanks to Danny, Stephen, and Jerome for joining and
>> contributing!
>> >
>> >         Kind regards,
>> >
>> >         Adam
>> >
>> >
>> >         [1] https://drive.google.com/open?id=3D
>> 0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>> >         [2] https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_
>> OVLFhB5NSU58MXDM
>> >         [3] https://drive.google.com/open?id=3D
>> 0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>> >         [4] https://ietf.webex.com/meet/sacm
>> >
>> >
>> >
>> > _______________________________________________
>> > sacm mailing list
>> > sacm@ietf.org
>> > https://www.ietf.org/mailman/listinfo/sacm
>> >
>>
>>
>> _______________________________________________
>> sacm mailing list
>> sacm@ietf.org
>> https://www.ietf.org/mailman/listinfo/sacm
>>
>>
>>

--001a11c00e4ef27d3d05478ff38b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:verdana,=
sans-serif">+1</div><div class=3D"gmail_default" style=3D"font-family:verda=
na,sans-serif"><br></div></div><div class=3D"gmail_extra"><br><div class=3D=
"gmail_quote">On Thu, Feb 2, 2017 at 12:59 PM, Adam Montville <span dir=3D"=
ltr">&lt;<a href=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">ad=
am.w.montville@gmail.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmai=
l_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left=
:1ex"><div dir=3D"ltr">Yes! Noting that information is critical, but if we =
set out to put all of that in the diagram, we&#39;ll lose.=C2=A0 What if we=
 agree to the sequence at the high level, then number the steps, and then w=
rite about those steps in the wiki after talking about them here and in inf=
ormal sessions for the win?</div><div class=3D"HOEnZb"><div class=3D"h5"><b=
r><div class=3D"gmail_quote"><div dir=3D"ltr">On Thu, Feb 2, 2017 at 11:57 =
AM Bill Munyan &lt;<a href=3D"mailto:bill.munyan.ietf@gmail.com" target=3D"=
_blank">bill.munyan.ietf@gmail.com</a>&gt; wrote:<br></div><blockquote clas=
s=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;pad=
ding-left:1ex"><div dir=3D"ltr" class=3D"m_-9073974425086588983gmail_msg"><=
div class=3D"gmail_default m_-9073974425086588983gmail_msg" style=3D"font-f=
amily:verdana,sans-serif">Is it worth noting in the diagram (if not, I thin=
k it needs to be noted somewhere nonetheless) that the steps of &quot;get e=
ndpoints&quot; and subsequent &quot;evaluate&quot; should be making some de=
termination of whether or not to collect for an endpoint?=C2=A0 For example=
, if an endpoint has no assessment results or the assessment results are co=
nsidered &quot;stale&quot;, then the collection step would take place.=C2=
=A0 I understand that could be too much detail for the scope of the diagram=
, but I just wanted to note it somewhere.</div><div class=3D"gmail_default =
m_-9073974425086588983gmail_msg" style=3D"font-family:verdana,sans-serif"><=
br class=3D"m_-9073974425086588983gmail_msg"></div><div class=3D"gmail_defa=
ult m_-9073974425086588983gmail_msg" style=3D"font-family:verdana,sans-seri=
f">Cheers,=C2=A0</div><div class=3D"gmail_default m_-9073974425086588983gma=
il_msg" style=3D"font-family:verdana,sans-serif">-Bill M.</div><div class=
=3D"gmail_default m_-9073974425086588983gmail_msg" style=3D"font-family:ver=
dana,sans-serif"><br class=3D"m_-9073974425086588983gmail_msg"></div></div>=
<div class=3D"gmail_extra m_-9073974425086588983gmail_msg"><br class=3D"m_-=
9073974425086588983gmail_msg"><div class=3D"gmail_quote m_-9073974425086588=
983gmail_msg">On Thu, Feb 2, 2017 at 12:44 PM, Adam Montville <span dir=3D"=
ltr" class=3D"m_-9073974425086588983gmail_msg">&lt;<a href=3D"mailto:adam.w=
.montville@gmail.com" class=3D"m_-9073974425086588983gmail_msg" target=3D"_=
blank">adam.w.montville@gmail.com</a>&gt;</span> wrote:<br class=3D"m_-9073=
974425086588983gmail_msg"><blockquote class=3D"gmail_quote m_-9073974425086=
588983gmail_msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padd=
ing-left:1ex"><div dir=3D"ltr" class=3D"m_-9073974425086588983gmail_msg">Th=
anks for the feedback!=C2=A0 I&#39;ve attached a modified version of the di=
agram that collapses the endpoint and assessment result repositories (by ke=
eping the endpoint repository).=C2=A0 Where would you propose we focus on e=
nhancing the diagram?=C2=A0 Remember that it&#39;s a sequence diagram, whic=
h might do well with some more specific details captured in text or a diffe=
rent form of diagram.<div class=3D"m_-9073974425086588983gmail_msg"><br cla=
ss=3D"m_-9073974425086588983gmail_msg"></div><div class=3D"m_-9073974425086=
588983gmail_msg">What do folks think about using one or more OVAL definitio=
ns as a starting point?</div><span class=3D"m_-9073974425086588983m_9479299=
65395893272HOEnZb m_-9073974425086588983gmail_msg"><font color=3D"#888888" =
class=3D"m_-9073974425086588983gmail_msg"><div class=3D"m_-9073974425086588=
983gmail_msg"><br class=3D"m_-9073974425086588983gmail_msg"></div><div clas=
s=3D"m_-9073974425086588983gmail_msg">Adam</div></font></span><div class=3D=
"m_-9073974425086588983gmail_msg"><div class=3D"m_-9073974425086588983m_947=
929965395893272h5 m_-9073974425086588983gmail_msg"><div class=3D"m_-9073974=
425086588983gmail_msg"><br class=3D"m_-9073974425086588983gmail_msg"></div>=
<br class=3D"m_-9073974425086588983gmail_msg"><div class=3D"gmail_quote m_-=
9073974425086588983gmail_msg"><div dir=3D"ltr" class=3D"m_-9073974425086588=
983gmail_msg">On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz &lt;<a href=3D"=
mailto:henk.birkholz@sit.fraunhofer.de" class=3D"m_-9073974425086588983gmai=
l_msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.<wbr>de</a>&gt; wrote=
:<br class=3D"m_-9073974425086588983gmail_msg"></div><blockquote class=3D"g=
mail_quote m_-9073974425086588983gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex">## A Few Comments<br class=3D"m_-9=
073974425086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-90=
73974425086588983gmail_msg">
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
* I agree that the diagram pretty much captures a &quot;one time snapshot&q=
uot;.<br class=3D"m_-9073974425086588983m_947929965395893272m_-192601292583=
2773148gmail_msg m_-9073974425086588983gmail_msg">
* Collapsing the highlighted components seems to be a feasible idea.<br cla=
ss=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail=
_msg m_-9073974425086588983gmail_msg">
* I agree that the diagram could be implemented given an appropriate set<br=
 class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148g=
mail_msg m_-9073974425086588983gmail_msg">
of initial data.<br class=3D"m_-9073974425086588983m_947929965395893272m_-1=
926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
* I suppose there is the risk that one has to scrap everything<br class=3D"=
m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_msg m=
_-9073974425086588983gmail_msg">
implemented when we start trying to make it a continuous process.<br class=
=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_m=
sg m_-9073974425086588983gmail_msg">
* I&#39;d recommend to start with a generic block of PoC code that provides=
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
the functions of a SACM component to get input and create output (maybe<br =
class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gm=
ail_msg m_-9073974425086588983gmail_msg">
using dbus, chained event-loops, blocking waits on fifos, or IP over<br cla=
ss=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail=
_msg m_-9073974425086588983gmail_msg">
loopback? A better coder than me should bash these suggestions).<br class=
=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_m=
sg m_-9073974425086588983gmail_msg">
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
## One, Two, or Three Tasks<br class=3D"m_-9073974425086588983m_94792996539=
5893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
* Creating component code that can create the (downstream?) flow of<br clas=
s=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_=
msg m_-9073974425086588983gmail_msg">
information is urgent and important, I think.<br class=3D"m_-90739744250865=
88983m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442508658=
8983gmail_msg">
* Enhancing the diagram to represent the continuous cycle with at least<br =
class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gm=
ail_msg m_-9073974425086588983gmail_msg">
one trigger (as illustrated by Bill; new software, new VDI, new<br class=3D=
"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_msg =
m_-9073974425086588983gmail_msg">
endpoints, stale results, etc.) is important, but not as urgent. It<br clas=
s=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_=
msg m_-9073974425086588983gmail_msg">
might save time though by reducing the afore mentioned risk to shoot<br cla=
ss=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail=
_msg m_-9073974425086588983gmail_msg">
your self in the foot by creating a too specific proof of concept of the<br=
 class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148g=
mail_msg m_-9073974425086588983gmail_msg">
one time snapshot approach, I think.<br class=3D"m_-9073974425086588983m_94=
7929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail=
_msg">
* Selecting a set of initial data derived from OVAL to be used in the<br cl=
ass=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmai=
l_msg m_-9073974425086588983gmail_msg">
one shot snapshot seems to be a feasible approach to me, but I am not<br cl=
ass=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmai=
l_msg m_-9073974425086588983gmail_msg">
sure how the group thinks about that.<br class=3D"m_-9073974425086588983m_9=
47929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmai=
l_msg">
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
Does that assessment represent the general opinion, or is that just mine?<b=
r class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148=
gmail_msg m_-9073974425086588983gmail_msg">
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
Viele Gr=C3=BC=C3=9Fe,<br class=3D"m_-9073974425086588983m_9479299653958932=
72m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
Henk<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
On 02/02/2017 05:28 PM, Adam Montville wrote:<br class=3D"m_-90739744250865=
88983m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442508658=
8983gmail_msg">
&gt; Hi Everyone.=C2=A0 A few of us were able to make the vulnerability sce=
nario<br class=3D"m_-9073974425086588983m_947929965395893272m_-192601292583=
2773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; call today and I think we had a good, though at times spirited,<br cla=
ss=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail=
_msg m_-9073974425086588983gmail_msg">
&gt; discussion.=C2=A0 We did record the meeting, which is available at [1]=
.=C2=A0 We<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012=
925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; discussed the attached (annotated with some meeting notes) UML-ish<br =
class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gm=
ail_msg m_-9073974425086588983gmail_msg">
&gt; sequence diagram.=C2=A0 I had created that diagram to start a conversa=
tion<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; (mission accomplished on that front I think) -- a conversation that<br=
 class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148g=
mail_msg m_-9073974425086588983gmail_msg">
&gt; would lead us toward identifying the discrete components, interfaces,<=
br class=3D"m_-9073974425086588983m_947929965395893272m_-192601292583277314=
8gmail_msg m_-9073974425086588983gmail_msg">
&gt; and information required to be sent over those interfaces.=C2=A0 The U=
ML-ish<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258=
32773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; diagram represents a *single* flow through the system -- a &quot;one-t=
ime&quot;<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129=
25832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; flow through the system.=C2=A0 It ignores, for the time being, the con=
tinuous<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925=
832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; aspect of our charter in favor of getting started with the basics.=C2=
=A0 Once<br class=3D"m_-9073974425086588983m_947929965395893272m_-192601292=
5832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; we have a good understanding of the basics -- the components,<br class=
=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_m=
sg m_-9073974425086588983gmail_msg">
&gt; interfaces, and information required -- we can start look at a<br clas=
s=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_=
msg m_-9073974425086588983gmail_msg">
&gt; continuous monitoring sequence (which could be represented as a distin=
ct<br class=3D"m_-9073974425086588983m_947929965395893272m_-192601292583277=
3148gmail_msg m_-9073974425086588983gmail_msg">
&gt; diagram) to determine what more we need.=C2=A0 Then, I think, we can s=
tart<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; drafting solutions.<br class=3D"m_-9073974425086588983m_94792996539589=
3272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; One of the first issues is that we need to figure out if the component=
s<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773=
148gmail_msg m_-9073974425086588983gmail_msg">
&gt; in the base flow are accurate.=C2=A0 The main suggestion we&#39;ve tos=
sed around<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012=
925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; so far is to combine the Endpoint Repository with the Assessment Resul=
t<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773=
148gmail_msg m_-9073974425086588983gmail_msg">
&gt; Repository.<br class=3D"m_-9073974425086588983m_947929965395893272m_-1=
926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; We talked briefly about what interface we could use for the VDD<br cla=
ss=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail=
_msg m_-9073974425086588983gmail_msg">
&gt; Repository, and naturally ROLIE came up as an option.<br class=3D"m_-9=
073974425086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-90=
73974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; We talked a little bit about the first &quot;get endpoints&quot; opera=
tion between<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260=
12925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; the Vulnerability Assessor and the Endpoint Repository -- specifically=
<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg">
&gt; about whether we should represent on this sequence diagram that<br cla=
ss=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail=
_msg m_-9073974425086588983gmail_msg">
&gt; information supporting a judgement of &quot;stale&quot; would be neede=
d.<br class=3D"m_-9073974425086588983m_947929965395893272m_-192601292583277=
3148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; We left open the time when we would next meet, favoring to work that o=
ut<br class=3D"m_-9073974425086588983m_947929965395893272m_-192601292583277=
3148gmail_msg m_-9073974425086588983gmail_msg">
&gt; on-list.=C2=A0 Next week is TCG, so that may be difficult; the followi=
ng week<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925=
832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; is RSA, so that may be difficult.<br class=3D"m_-9073974425086588983m_=
947929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gma=
il_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; For those who were in attendance today, please add to this note with<b=
r class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148=
gmail_msg m_-9073974425086588983gmail_msg">
&gt; your comments/corrections.<br class=3D"m_-9073974425086588983m_9479299=
65395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg"=
>
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; Kind regards,<br class=3D"m_-9073974425086588983m_947929965395893272m_=
-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; Adam<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129=
25832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; [1] <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHp=
VR0tMd1E" rel=3D"noreferrer" class=3D"m_-9073974425086588983m_9479299653958=
93272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg" targe=
t=3D"_blank">https://drive.google.com/open?<wbr>id=3D<wbr>0B8Wf9Un5FdCbWGhD=
OHpVR0tMd1E</a><br class=3D"m_-9073974425086588983m_947929965395893272m_-19=
26012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montville<br class=3D"m_-9073974=
425086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-90739744=
25086588983gmail_msg">
&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"m_-90739744=
25086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442=
5086588983gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &lt;m=
ailto:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"m_-90739744250=
86588983m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442508=
6588983gmail_msg" target=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&gt;=
&gt; wrote:<br class=3D"m_-9073974425086588983m_947929965395893272m_-192601=
2925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a friendly reminder that we=
 are planning to meet<br class=3D"m_-9073974425086588983m_94792996539589327=
2m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the same time (2/2 @ 10am Ea=
stern/3pm UTC)<br class=3D"m_-9073974425086588983m_947929965395893272m_-192=
6012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting room at <a href=3D"https:/=
/ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"m_-90739744250865889=
83m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442508658898=
3gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/<wbr>sacm</a>.<br=
 class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148g=
mail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"m_-9073974425086588983m_9=
47929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmai=
l_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"m_-9073974425086588983m_9479299653=
95893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:35 AM Adam Montville<br =
class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gm=
ail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montville@gmail.com" c=
lass=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gma=
il_msg m_-9073974425086588983gmail_msg" target=3D"_blank">adam.w.montville@=
gmail.com</a> &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_=
msg m_-9073974425086588983gmail_msg" target=3D"_blank">adam.w.montville@<wb=
r>gmail.com</a>&gt;&gt; wrote:<br class=3D"m_-9073974425086588983m_94792996=
5395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few of us met informally tod=
ay to discuss the<br class=3D"m_-9073974425086588983m_947929965395893272m_-=
1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability scenario in some more d=
etail with the goal of<br class=3D"m_-9073974425086588983m_9479299653958932=
72m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining the narrow focus on a vul=
nerability assessment slice<br class=3D"m_-9073974425086588983m_94792996539=
5893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our notional environment.=C2=
=A0 We are tending to look at<br class=3D"m_-9073974425086588983m_947929965=
395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major components as black boxes with =
interfaces and data format<br class=3D"m_-9073974425086588983m_947929965395=
893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations, and we are not necessar=
ily concerned with how<br class=3D"m_-9073974425086588983m_9479299653958932=
72m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those components do things internally=
/behind the scenes.<br class=3D"m_-9073974425086588983m_947929965395893272m=
_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting was recorded (you can fin=
d it with today&#39;s date at<br class=3D"m_-9073974425086588983m_947929965=
395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 The topic of discussion w=
as primarily in the &quot;phase 1&quot;<br class=3D"m_-9073974425086588983m=
_947929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gm=
ail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what Danny sent to the list n=
ot very long ago [2], and<br class=3D"m_-9073974425086588983m_9479299653958=
93272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a *starting point* diagra=
m [3].<br class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258=
32773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who met today are (roughly)=
 agreed on the six main<br class=3D"m_-9073974425086588983m_947929965395893=
272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;components&quot; represented in=
 that diagram, but also see that we<br class=3D"m_-9073974425086588983m_947=
929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some work ahead.=C2=A0 Specifica=
lly, we quickly recognized that<br class=3D"m_-9073974425086588983m_9479299=
65395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the assumptions the vulnerabi=
lity draft makes may be<br class=3D"m_-9073974425086588983m_947929965395893=
272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions we cannot afford to make =
and need to include in the<br class=3D"m_-9073974425086588983m_947929965395=
893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<br class=3D"m_-907397442=
5086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-9073974425=
086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it would be a good idea to=
 have another informal<br class=3D"m_-9073974425086588983m_9479299653958932=
72m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in a couple of weeks (Febr=
uary 2) at the same time<br class=3D"m_-9073974425086588983m_94792996539589=
3272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern / 3pm UTC), using the s=
ame WebEx [4].=C2=A0 =C2=A0At that<br class=3D"m_-9073974425086588983m_9479=
29965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_m=
sg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we intend to roll through the vu=
lnerability assessment<br class=3D"m_-9073974425086588983m_9479299653958932=
72m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assumptions in an effort to =
determine which ones can be<br class=3D"m_-9073974425086588983m_94792996539=
5893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assumptions and which ones ca=
nnot.=C2=A0 Then we&#39;ll take<br class=3D"m_-9073974425086588983m_9479299=
65395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look at the diagram and work =
on its next version.<br class=3D"m_-9073974425086588983m_947929965395893272=
m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<br class=3D"m_-9073974425=
086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-90739744250=
86588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Danny, Stephen, and Jerome =
for joining and contributing!<br class=3D"m_-9073974425086588983m_947929965=
395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"m_-90739744=
25086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442=
5086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=3D"m_-90739744250865889=
83m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442508658898=
3gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"m_-9=
073974425086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-90=
73974425086588983gmail_msg" target=3D"_blank">https://drive.google.com/open=
?<wbr>id=3D<wbr>0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br class=3D"m_-90739744250=
86588983m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442508=
6588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2] <a href=3D"https://mailarchive.ie=
tf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=
=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_m=
sg m_-9073974425086588983gmail_msg" target=3D"_blank">https://mailarchive.i=
etf.org/<wbr>arch/msg/sacm/_LiKlyvAws_<wbr>OVLFhB5NSU58MXDM</a><br class=3D=
"m_-9073974425086588983m_947929965395893272m_-1926012925832773148gmail_msg =
m_-9073974425086588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"m_-9=
073974425086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-90=
73974425086588983gmail_msg" target=3D"_blank">https://drive.google.com/open=
?<wbr>id=3D<wbr>0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><br class=3D"m_-90739744250=
86588983m_947929965395893272m_-1926012925832773148gmail_msg m_-907397442508=
6588983gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=3D"https://ietf.webex.com=
/meet/sacm" rel=3D"noreferrer" class=3D"m_-9073974425086588983m_94792996539=
5893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg" tar=
get=3D"_blank">https://ietf.webex.com/meet/<wbr>sacm</a><br class=3D"m_-907=
3974425086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-9073=
974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; ______________________________<wbr>_________________<br class=3D"m_-90=
73974425086588983m_947929965395893272m_-1926012925832773148gmail_msg m_-907=
3974425086588983gmail_msg">
&gt; sacm mailing list<br class=3D"m_-9073974425086588983m_9479299653958932=
72m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"m_-9073974425086588983m_9479=
29965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gmail_m=
sg" target=3D"_blank">sacm@ietf.org</a><br class=3D"m_-9073974425086588983m=
_947929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gm=
ail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferr=
er" class=3D"m_-9073974425086588983m_947929965395893272m_-19260129258327731=
48gmail_msg m_-9073974425086588983gmail_msg" target=3D"_blank">https://www.=
ietf.org/mailman/<wbr>listinfo/sacm</a><br class=3D"m_-9073974425086588983m=
_947929965395893272m_-1926012925832773148gmail_msg m_-9073974425086588983gm=
ail_msg">
&gt;<br class=3D"m_-9073974425086588983m_947929965395893272m_-1926012925832=
773148gmail_msg m_-9073974425086588983gmail_msg">
</blockquote></div></div></div></div>
<br class=3D"m_-9073974425086588983gmail_msg">_____________________________=
_<wbr>_________________<br class=3D"m_-9073974425086588983gmail_msg">
sacm mailing list<br class=3D"m_-9073974425086588983gmail_msg">
<a href=3D"mailto:sacm@ietf.org" class=3D"m_-9073974425086588983gmail_msg" =
target=3D"_blank">sacm@ietf.org</a><br class=3D"m_-9073974425086588983gmail=
_msg">
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" c=
lass=3D"m_-9073974425086588983gmail_msg" target=3D"_blank">https://www.ietf=
.org/mailman/<wbr>listinfo/sacm</a><br class=3D"m_-9073974425086588983gmail=
_msg">
<br class=3D"m_-9073974425086588983gmail_msg"></blockquote></div><br class=
=3D"m_-9073974425086588983gmail_msg"></div>
</blockquote></div>
</div></div></blockquote></div><br></div>

--001a11c00e4ef27d3d05478ff38b--


From nobody Thu Feb  2 10:34:11 2017
Return-Path: <david.waltermire@nist.gov>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1BB511298AC for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 10:34:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nistgov.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oCajr7r_zZY8 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 10:34:07 -0800 (PST)
Received: from gcc01-dm2-obe.outbound.protection.outlook.com (mail-dm2gcc01on0138.outbound.protection.outlook.com [23.103.201.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B3A3E129509 for <sacm@ietf.org>; Thu,  2 Feb 2017 10:34:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nistgov.onmicrosoft.com; s=selector1-nist-gov; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=OVM7FxB4VXospCDKKlHJ9H+AVp7yLahH4djjMI/B+tM=; b=mlpcb5mf7Q9X6KhS9O1dSHiwhNf+L9UTvGAnMU1js0AhFyajb0u+I7A+su8s0tgn6pIqUBrt9w36gJGhWkYlyeS/y8H+U8nabIpa092hd9pmBNMXM2MACy8kZashBcgIgRTZtgt2yaKP0zteKUsrY6VSSWqb8rDv4VdFe1fLcYo=
Received: from MWHPR09MB1440.namprd09.prod.outlook.com (10.173.50.14) by MWHPR09MB1438.namprd09.prod.outlook.com (10.173.50.12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.874.12; Thu, 2 Feb 2017 18:34:05 +0000
Received: from MWHPR09MB1440.namprd09.prod.outlook.com ([10.173.50.14]) by MWHPR09MB1440.namprd09.prod.outlook.com ([10.173.50.14]) with mapi id 15.01.0874.024; Thu, 2 Feb 2017 18:34:04 +0000
From: "Waltermire, David A. (Fed)" <david.waltermire@nist.gov>
To: Bill Munyan <bill.munyan.ietf@gmail.com>, Adam Montville <adam.w.montville@gmail.com>
Thread-Topic: [sacm] Notes on Vulnerability Scenario Working Session
Thread-Index: AQHScnptH3jO8EKoM0q4MAYNszel+KFRVaqAgASoDICAAAcggIAADksAgAADawCAAAgBkA==
Date: Thu, 2 Feb 2017 18:34:04 +0000
Message-ID: <MWHPR09MB144086C8D167D5BEB1BC5258F04C0@MWHPR09MB1440.namprd09.prod.outlook.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com>
In-Reply-To: <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=david.waltermire@nist.gov; 
x-originating-ip: [129.6.224.58]
x-ms-office365-filtering-correlation-id: c81286a8-70e9-428f-334f-08d44b9a110c
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(48565401081); SRVR:MWHPR09MB1438; 
x-microsoft-exchange-diagnostics: 1; MWHPR09MB1438; 7:QLySszxw3iOUvhciPUiGFkRJh3s76SFFuuDLlrd5g1FtG9sXYFCfAE16JEcADkjPrzJCFx72M2vq92Q4qyiBKWEvdqXYOxaS+7CRz/ToRkJdBRiUOk6/5OjlBqcAZ6yp4HAGTNOPANMUNHUgJjqOcru553PFKygpRrE2RWIdAFXZeAvRDoLwOwMVN6+z1niHeFagOsQ0//NUU38cNV+SMOs1C+bmSlkI3zleBZ77JOKzDU3rb9SEKwmCTmVjAEaHwFVfb/SUiBZov5Oj6dRkYsVFeOtT/eP+YgA8FPJq7SRDAvuSBh/7W2I0FIcr4C5otiCBE7OibVJsMStrfajerzpMFQ5kAAfaTQwSN2gC3zi1Aa8zERMRwSOOWJyo4iNR9D3YrU4f96k7tiXYbjuQFO3/1dZvmFiKQLh8YIyRPtsiqxF4evYok3KR4HZiIB0Qbrk4EjWRnw20v9mbNtHlc85qYEPGZCTyu8P7Lbo97sId0ZPy0ooA5F8fjUToKFFpt6BJbP5qTKTLeyoOa2vecNWdYYPTFTJ6K3sccQ2EdHJw6IqVPhGC8EsKYd2oFXG4
x-microsoft-antispam-prvs: <MWHPR09MB14381DBC9531227733DA36D4F04C0@MWHPR09MB1438.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(72170088055959)(94707916325470)(211936372134217)(21748063052155)(145926492361056);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6055026)(6041248)(20161123560025)(20161123558025)(20161123555025)(20161123562025)(20161123564025)(6072148); SRVR:MWHPR09MB1438; BCL:0; PCL:0; RULEID:; SRVR:MWHPR09MB1438; 
x-forefront-prvs: 02065A9E77
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(7916002)(39410400002)(39840400002)(39450400003)(39860400002)(39850400002)(189002)(199003)(377454003)(46034005)(51914003)(24454002)(51694002)(53754006)(7696004)(39060400001)(229853002)(55016002)(4326007)(99286003)(54906002)(5890100001)(9686003)(7736002)(54896002)(236005)(6306002)(6116002)(102836003)(86362001)(6436002)(8676002)(50986999)(122556002)(575784001)(105586002)(606005)(54356999)(3660700001)(790700001)(2906002)(3846002)(7906003)(53936002)(5660300001)(81156014)(189998001)(81166006)(33656002)(8936002)(68736007)(74316002)(76176999)(101416001)(5001770100001)(97736004)(6506006)(25786008)(19609705001)(2950100002)(106116001)(92566002)(93886004)(66066001)(3280700002)(31430400001)(77096006)(106356001)(14971765001)(38730400001)(2900100001); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR09MB1438; H:MWHPR09MB1440.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_MWHPR09MB144086C8D167D5BEB1BC5258F04C0MWHPR09MB1440namp_"
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Feb 2017 18:34:04.7209 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR09MB1438
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/b8TP2bnzaEzOfBiTQ-JZFNXLgSA>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 18:34:10 -0000

--_000_MWHPR09MB144086C8D167D5BEB1BC5258F04C0MWHPR09MB1440namp_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SXMgdGhlIG9wZXJhdGlvbiDigJxnZXQgZW5kcG9pbnRz4oCdIGEgc2luZ2xlIG9wZXJhdGlvbiBv
ciBpcyBpdCBtdWx0aXBsZSBvcGVyYXRpb25zIOKAnGdldCBlbmRwb2ludCBjaGFyYWN0ZXJpc3Rp
Y3PigJ0gYW5kIOKAnGdldCBwcmV2aW91c2x5IGNvbGxlY3RlZCBkYXRh4oCdLCBvciBldmVuIOKA
nHF1ZXJ5IGlmIHRoZXJlIGlzIHByZXZpb3VzbHkgY29sbGVjdGVkIGRhdGEgdGhhdCBtYXRjaGVz
IFggaW4gdGltZWZyYW1lIFk/4oCdIEl0IHdvdWxkIGJlIGhlbHBmdWwgdG8gYmUgbW9yZSBzcGVj
aWZpYyBoZXJlIHNpbmNlIHRoZSBpbmZvcm1hdGlvbiBleGNoYW5nZXMgbWF5IGRpZmZlci4NCg0K
U2hvdWxkIHRoZSDigJxjb2xsZWN04oCdIGJldHdlZW4gdnVsbmVyYWJpbGl0eSBhc3Nlc3NvciBh
bmQgY29sbGVjdG9yIHNob3VsZCBiZSDigJxyZXF1ZXN0IGNvbGxlY3Rpb24gKGZvciBhIHNldCBv
ZiBlbmRwb2ludHMp4oCdPw0KDQpUaGUgZmlyc3Qg4oCcZXZhbHVhdGXigJ0gKGZyb20gdGhlIHRv
cCkgY291bGQgYmUgdGhvdWdodCBvZiBhcyBhbiBhcHBsaWNhYmlsaXR5IC8gc3RhbGVuZXNzIGV2
YWx1YXRpb24uIFRoaXMgZHJpdmVzIHdoYXQgZ2FwcyBpbiBpbmZvcm1hdGlvbiBhbmQgZW5kcG9p
bnRzIHNob3VsZCBiZSB0YXJnZXRlZCBmb3IgY29sbGVjdGlvbi4NCg0KVGhlIHNlY29uZCDigJwo
cmUpZXZhbHVhdGXigJ0gaXMgdGhlIGFjdHVhbCBwb3N0dXJlIGV2YWx1YXRpb24gd2UgYXJlIHdv
cmtpbmcgdG8gc3VwcG9ydC4gUmlnaHQ/DQoNClJlZ2FyZHMsDQpEYXZlDQoNCkZyb206IHNhY20g
W21haWx0bzpzYWNtLWJvdW5jZXNAaWV0Zi5vcmddIE9uIEJlaGFsZiBPZiBCaWxsIE11bnlhbg0K
U2VudDogVGh1cnNkYXksIEZlYnJ1YXJ5IDAyLCAyMDE3IDEyOjU3IFBNDQpUbzogQWRhbSBNb250
dmlsbGUgPGFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPg0KQ2M6IEhlbmsgQmlya2hvbHogPGhl
bmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGU+OyBzYWNtQGlldGYub3JnDQpTdWJqZWN0OiBS
ZTogW3NhY21dIE5vdGVzIG9uIFZ1bG5lcmFiaWxpdHkgU2NlbmFyaW8gV29ya2luZyBTZXNzaW9u
DQoNCklzIGl0IHdvcnRoIG5vdGluZyBpbiB0aGUgZGlhZ3JhbSAoaWYgbm90LCBJIHRoaW5rIGl0
IG5lZWRzIHRvIGJlIG5vdGVkIHNvbWV3aGVyZSBub25ldGhlbGVzcykgdGhhdCB0aGUgc3RlcHMg
b2YgImdldCBlbmRwb2ludHMiIGFuZCBzdWJzZXF1ZW50ICJldmFsdWF0ZSIgc2hvdWxkIGJlIG1h
a2luZyBzb21lIGRldGVybWluYXRpb24gb2Ygd2hldGhlciBvciBub3QgdG8gY29sbGVjdCBmb3Ig
YW4gZW5kcG9pbnQ/ICBGb3IgZXhhbXBsZSwgaWYgYW4gZW5kcG9pbnQgaGFzIG5vIGFzc2Vzc21l
bnQgcmVzdWx0cyBvciB0aGUgYXNzZXNzbWVudCByZXN1bHRzIGFyZSBjb25zaWRlcmVkICJzdGFs
ZSIsIHRoZW4gdGhlIGNvbGxlY3Rpb24gc3RlcCB3b3VsZCB0YWtlIHBsYWNlLiAgSSB1bmRlcnN0
YW5kIHRoYXQgY291bGQgYmUgdG9vIG11Y2ggZGV0YWlsIGZvciB0aGUgc2NvcGUgb2YgdGhlIGRp
YWdyYW0sIGJ1dCBJIGp1c3Qgd2FudGVkIHRvIG5vdGUgaXQgc29tZXdoZXJlLg0KDQpDaGVlcnMs
DQotQmlsbCBNLg0KDQoNCk9uIFRodSwgRmViIDIsIDIwMTcgYXQgMTI6NDQgUE0sIEFkYW0gTW9u
dHZpbGxlIDxhZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53Lm1vbnR2aWxs
ZUBnbWFpbC5jb20+PiB3cm90ZToNClRoYW5rcyBmb3IgdGhlIGZlZWRiYWNrISAgSSd2ZSBhdHRh
Y2hlZCBhIG1vZGlmaWVkIHZlcnNpb24gb2YgdGhlIGRpYWdyYW0gdGhhdCBjb2xsYXBzZXMgdGhl
IGVuZHBvaW50IGFuZCBhc3Nlc3NtZW50IHJlc3VsdCByZXBvc2l0b3JpZXMgKGJ5IGtlZXBpbmcg
dGhlIGVuZHBvaW50IHJlcG9zaXRvcnkpLiAgV2hlcmUgd291bGQgeW91IHByb3Bvc2Ugd2UgZm9j
dXMgb24gZW5oYW5jaW5nIHRoZSBkaWFncmFtPyAgUmVtZW1iZXIgdGhhdCBpdCdzIGEgc2VxdWVu
Y2UgZGlhZ3JhbSwgd2hpY2ggbWlnaHQgZG8gd2VsbCB3aXRoIHNvbWUgbW9yZSBzcGVjaWZpYyBk
ZXRhaWxzIGNhcHR1cmVkIGluIHRleHQgb3IgYSBkaWZmZXJlbnQgZm9ybSBvZiBkaWFncmFtLg0K
DQpXaGF0IGRvIGZvbGtzIHRoaW5rIGFib3V0IHVzaW5nIG9uZSBvciBtb3JlIE9WQUwgZGVmaW5p
dGlvbnMgYXMgYSBzdGFydGluZyBwb2ludD8NCg0KQWRhbQ0KDQoNCk9uIFRodSwgRmViIDIsIDIw
MTcgYXQgMTA6NTMgQU0gSGVuayBCaXJraG9seiA8aGVuay5iaXJraG9sekBzaXQuZnJhdW5ob2Zl
ci5kZTxtYWlsdG86aGVuay5iaXJraG9sekBzaXQuZnJhdW5ob2Zlci5kZT4+IHdyb3RlOg0KIyMg
QSBGZXcgQ29tbWVudHMNCg0KKiBJIGFncmVlIHRoYXQgdGhlIGRpYWdyYW0gcHJldHR5IG11Y2gg
Y2FwdHVyZXMgYSAib25lIHRpbWUgc25hcHNob3QiLg0KKiBDb2xsYXBzaW5nIHRoZSBoaWdobGln
aHRlZCBjb21wb25lbnRzIHNlZW1zIHRvIGJlIGEgZmVhc2libGUgaWRlYS4NCiogSSBhZ3JlZSB0
aGF0IHRoZSBkaWFncmFtIGNvdWxkIGJlIGltcGxlbWVudGVkIGdpdmVuIGFuIGFwcHJvcHJpYXRl
IHNldA0Kb2YgaW5pdGlhbCBkYXRhLg0KKiBJIHN1cHBvc2UgdGhlcmUgaXMgdGhlIHJpc2sgdGhh
dCBvbmUgaGFzIHRvIHNjcmFwIGV2ZXJ5dGhpbmcNCmltcGxlbWVudGVkIHdoZW4gd2Ugc3RhcnQg
dHJ5aW5nIHRvIG1ha2UgaXQgYSBjb250aW51b3VzIHByb2Nlc3MuDQoqIEknZCByZWNvbW1lbmQg
dG8gc3RhcnQgd2l0aCBhIGdlbmVyaWMgYmxvY2sgb2YgUG9DIGNvZGUgdGhhdCBwcm92aWRlcw0K
dGhlIGZ1bmN0aW9ucyBvZiBhIFNBQ00gY29tcG9uZW50IHRvIGdldCBpbnB1dCBhbmQgY3JlYXRl
IG91dHB1dCAobWF5YmUNCnVzaW5nIGRidXMsIGNoYWluZWQgZXZlbnQtbG9vcHMsIGJsb2NraW5n
IHdhaXRzIG9uIGZpZm9zLCBvciBJUCBvdmVyDQpsb29wYmFjaz8gQSBiZXR0ZXIgY29kZXIgdGhh
biBtZSBzaG91bGQgYmFzaCB0aGVzZSBzdWdnZXN0aW9ucykuDQoNCiMjIE9uZSwgVHdvLCBvciBU
aHJlZSBUYXNrcw0KDQoqIENyZWF0aW5nIGNvbXBvbmVudCBjb2RlIHRoYXQgY2FuIGNyZWF0ZSB0
aGUgKGRvd25zdHJlYW0/KSBmbG93IG9mDQppbmZvcm1hdGlvbiBpcyB1cmdlbnQgYW5kIGltcG9y
dGFudCwgSSB0aGluay4NCiogRW5oYW5jaW5nIHRoZSBkaWFncmFtIHRvIHJlcHJlc2VudCB0aGUg
Y29udGludW91cyBjeWNsZSB3aXRoIGF0IGxlYXN0DQpvbmUgdHJpZ2dlciAoYXMgaWxsdXN0cmF0
ZWQgYnkgQmlsbDsgbmV3IHNvZnR3YXJlLCBuZXcgVkRJLCBuZXcNCmVuZHBvaW50cywgc3RhbGUg
cmVzdWx0cywgZXRjLikgaXMgaW1wb3J0YW50LCBidXQgbm90IGFzIHVyZ2VudC4gSXQNCm1pZ2h0
IHNhdmUgdGltZSB0aG91Z2ggYnkgcmVkdWNpbmcgdGhlIGFmb3JlIG1lbnRpb25lZCByaXNrIHRv
IHNob290DQp5b3VyIHNlbGYgaW4gdGhlIGZvb3QgYnkgY3JlYXRpbmcgYSB0b28gc3BlY2lmaWMg
cHJvb2Ygb2YgY29uY2VwdCBvZiB0aGUNCm9uZSB0aW1lIHNuYXBzaG90IGFwcHJvYWNoLCBJIHRo
aW5rLg0KKiBTZWxlY3RpbmcgYSBzZXQgb2YgaW5pdGlhbCBkYXRhIGRlcml2ZWQgZnJvbSBPVkFM
IHRvIGJlIHVzZWQgaW4gdGhlDQpvbmUgc2hvdCBzbmFwc2hvdCBzZWVtcyB0byBiZSBhIGZlYXNp
YmxlIGFwcHJvYWNoIHRvIG1lLCBidXQgSSBhbSBub3QNCnN1cmUgaG93IHRoZSBncm91cCB0aGlu
a3MgYWJvdXQgdGhhdC4NCg0KRG9lcyB0aGF0IGFzc2Vzc21lbnQgcmVwcmVzZW50IHRoZSBnZW5l
cmFsIG9waW5pb24sIG9yIGlzIHRoYXQganVzdCBtaW5lPw0KDQpWaWVsZSBHcsO8w59lLA0KDQpI
ZW5rDQoNCk9uIDAyLzAyLzIwMTcgMDU6MjggUE0sIEFkYW0gTW9udHZpbGxlIHdyb3RlOg0KPiBI
aSBFdmVyeW9uZS4gIEEgZmV3IG9mIHVzIHdlcmUgYWJsZSB0byBtYWtlIHRoZSB2dWxuZXJhYmls
aXR5IHNjZW5hcmlvDQo+IGNhbGwgdG9kYXkgYW5kIEkgdGhpbmsgd2UgaGFkIGEgZ29vZCwgdGhv
dWdoIGF0IHRpbWVzIHNwaXJpdGVkLA0KPiBkaXNjdXNzaW9uLiAgV2UgZGlkIHJlY29yZCB0aGUg
bWVldGluZywgd2hpY2ggaXMgYXZhaWxhYmxlIGF0IFsxXS4gIFdlDQo+IGRpc2N1c3NlZCB0aGUg
YXR0YWNoZWQgKGFubm90YXRlZCB3aXRoIHNvbWUgbWVldGluZyBub3RlcykgVU1MLWlzaA0KPiBz
ZXF1ZW5jZSBkaWFncmFtLiAgSSBoYWQgY3JlYXRlZCB0aGF0IGRpYWdyYW0gdG8gc3RhcnQgYSBj
b252ZXJzYXRpb24NCj4gKG1pc3Npb24gYWNjb21wbGlzaGVkIG9uIHRoYXQgZnJvbnQgSSB0aGlu
aykgLS0gYSBjb252ZXJzYXRpb24gdGhhdA0KPiB3b3VsZCBsZWFkIHVzIHRvd2FyZCBpZGVudGlm
eWluZyB0aGUgZGlzY3JldGUgY29tcG9uZW50cywgaW50ZXJmYWNlcywNCj4gYW5kIGluZm9ybWF0
aW9uIHJlcXVpcmVkIHRvIGJlIHNlbnQgb3ZlciB0aG9zZSBpbnRlcmZhY2VzLiAgVGhlIFVNTC1p
c2gNCj4gZGlhZ3JhbSByZXByZXNlbnRzIGEgKnNpbmdsZSogZmxvdyB0aHJvdWdoIHRoZSBzeXN0
ZW0gLS0gYSAib25lLXRpbWUiDQo+IGZsb3cgdGhyb3VnaCB0aGUgc3lzdGVtLiAgSXQgaWdub3Jl
cywgZm9yIHRoZSB0aW1lIGJlaW5nLCB0aGUgY29udGludW91cw0KPiBhc3BlY3Qgb2Ygb3VyIGNo
YXJ0ZXIgaW4gZmF2b3Igb2YgZ2V0dGluZyBzdGFydGVkIHdpdGggdGhlIGJhc2ljcy4gIE9uY2UN
Cj4gd2UgaGF2ZSBhIGdvb2QgdW5kZXJzdGFuZGluZyBvZiB0aGUgYmFzaWNzIC0tIHRoZSBjb21w
b25lbnRzLA0KPiBpbnRlcmZhY2VzLCBhbmQgaW5mb3JtYXRpb24gcmVxdWlyZWQgLS0gd2UgY2Fu
IHN0YXJ0IGxvb2sgYXQgYQ0KPiBjb250aW51b3VzIG1vbml0b3Jpbmcgc2VxdWVuY2UgKHdoaWNo
IGNvdWxkIGJlIHJlcHJlc2VudGVkIGFzIGEgZGlzdGluY3QNCj4gZGlhZ3JhbSkgdG8gZGV0ZXJt
aW5lIHdoYXQgbW9yZSB3ZSBuZWVkLiAgVGhlbiwgSSB0aGluaywgd2UgY2FuIHN0YXJ0DQo+IGRy
YWZ0aW5nIHNvbHV0aW9ucy4NCj4NCj4gT25lIG9mIHRoZSBmaXJzdCBpc3N1ZXMgaXMgdGhhdCB3
ZSBuZWVkIHRvIGZpZ3VyZSBvdXQgaWYgdGhlIGNvbXBvbmVudHMNCj4gaW4gdGhlIGJhc2UgZmxv
dyBhcmUgYWNjdXJhdGUuICBUaGUgbWFpbiBzdWdnZXN0aW9uIHdlJ3ZlIHRvc3NlZCBhcm91bmQN
Cj4gc28gZmFyIGlzIHRvIGNvbWJpbmUgdGhlIEVuZHBvaW50IFJlcG9zaXRvcnkgd2l0aCB0aGUg
QXNzZXNzbWVudCBSZXN1bHQNCj4gUmVwb3NpdG9yeS4NCj4NCj4gV2UgdGFsa2VkIGJyaWVmbHkg
YWJvdXQgd2hhdCBpbnRlcmZhY2Ugd2UgY291bGQgdXNlIGZvciB0aGUgVkREDQo+IFJlcG9zaXRv
cnksIGFuZCBuYXR1cmFsbHkgUk9MSUUgY2FtZSB1cCBhcyBhbiBvcHRpb24uDQo+DQo+IFdlIHRh
bGtlZCBhIGxpdHRsZSBiaXQgYWJvdXQgdGhlIGZpcnN0ICJnZXQgZW5kcG9pbnRzIiBvcGVyYXRp
b24gYmV0d2Vlbg0KPiB0aGUgVnVsbmVyYWJpbGl0eSBBc3Nlc3NvciBhbmQgdGhlIEVuZHBvaW50
IFJlcG9zaXRvcnkgLS0gc3BlY2lmaWNhbGx5DQo+IGFib3V0IHdoZXRoZXIgd2Ugc2hvdWxkIHJl
cHJlc2VudCBvbiB0aGlzIHNlcXVlbmNlIGRpYWdyYW0gdGhhdA0KPiBpbmZvcm1hdGlvbiBzdXBw
b3J0aW5nIGEganVkZ2VtZW50IG9mICJzdGFsZSIgd291bGQgYmUgbmVlZGVkLg0KPg0KPiBXZSBs
ZWZ0IG9wZW4gdGhlIHRpbWUgd2hlbiB3ZSB3b3VsZCBuZXh0IG1lZXQsIGZhdm9yaW5nIHRvIHdv
cmsgdGhhdCBvdXQNCj4gb24tbGlzdC4gIE5leHQgd2VlayBpcyBUQ0csIHNvIHRoYXQgbWF5IGJl
IGRpZmZpY3VsdDsgdGhlIGZvbGxvd2luZyB3ZWVrDQo+IGlzIFJTQSwgc28gdGhhdCBtYXkgYmUg
ZGlmZmljdWx0Lg0KPg0KPiBGb3IgdGhvc2Ugd2hvIHdlcmUgaW4gYXR0ZW5kYW5jZSB0b2RheSwg
cGxlYXNlIGFkZCB0byB0aGlzIG5vdGUgd2l0aA0KPiB5b3VyIGNvbW1lbnRzL2NvcnJlY3Rpb25z
Lg0KPg0KPiBLaW5kIHJlZ2FyZHMsDQo+DQo+IEFkYW0NCj4NCj4gWzFdIGh0dHBzOi8vZHJpdmUu
Z29vZ2xlLmNvbS9vcGVuP2lkPTBCOFdmOVVuNUZkQ2JXR2hET0hwVlIwdE1kMUUNCj4NCj4gT24g
TW9uLCBKYW4gMzAsIDIwMTcgYXQgMTE6MjEgQU0gQWRhbSBNb250dmlsbGUNCj4gPGFkYW0udy5t
b250dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbT4gPG1h
aWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBn
bWFpbC5jb20+Pj4gd3JvdGU6DQo+DQo+ICAgICBIaSBldmVyeW9uZS4gIEp1c3QgYSBmcmllbmRs
eSByZW1pbmRlciB0aGF0IHdlIGFyZSBwbGFubmluZyB0byBtZWV0DQo+ICAgICBhZ2FpbiB0aGlz
IFRodXJzZGF5IGF0IHRoZSBzYW1lIHRpbWUgKDIvMiBAIDEwYW0gRWFzdGVybi8zcG0gVVRDKQ0K
PiAgICAgdXNpbmcgU0FDTSdzIG1lZXRpbmcgcm9vbSBhdCBodHRwczovL2lldGYud2ViZXguY29t
L21lZXQvc2FjbS4NCj4NCj4gICAgIEtpbmQgcmVnYXJkcywNCj4NCj4gICAgIEFkYW0NCj4NCj4N
Cj4gICAgIE9uIFRodSwgSmFuIDE5LCAyMDE3IGF0IDExOjM1IEFNIEFkYW0gTW9udHZpbGxlDQo+
ICAgICA8YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5tb250dmlsbGVA
Z21haWwuY29tPiA8bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFt
LncubW9udHZpbGxlQGdtYWlsLmNvbT4+PiB3cm90ZToNCj4NCj4gICAgICAgICBIZWxsby4gQSBm
ZXcgb2YgdXMgbWV0IGluZm9ybWFsbHkgdG9kYXkgdG8gZGlzY3VzcyB0aGUNCj4gICAgICAgICB2
dWxuZXJhYmlsaXR5IHNjZW5hcmlvIGluIHNvbWUgbW9yZSBkZXRhaWwgd2l0aCB0aGUgZ29hbCBv
Zg0KPiAgICAgICAgIG1haW50YWluaW5nIHRoZSBuYXJyb3cgZm9jdXMgb24gYSB2dWxuZXJhYmls
aXR5IGFzc2Vzc21lbnQgc2xpY2UNCj4gICAgICAgICB0aHJvdWdoIG91ciBub3Rpb25hbCBlbnZp
cm9ubWVudC4gIFdlIGFyZSB0ZW5kaW5nIHRvIGxvb2sgYXQNCj4gICAgICAgICBtYWpvciBjb21w
b25lbnRzIGFzIGJsYWNrIGJveGVzIHdpdGggaW50ZXJmYWNlcyBhbmQgZGF0YSBmb3JtYXQNCj4g
ICAgICAgICBleHBlY3RhdGlvbnMsIGFuZCB3ZSBhcmUgbm90IG5lY2Vzc2FyaWx5IGNvbmNlcm5l
ZCB3aXRoIGhvdw0KPiAgICAgICAgIHRob3NlIGNvbXBvbmVudHMgZG8gdGhpbmdzIGludGVybmFs
bHkvYmVoaW5kIHRoZSBzY2VuZXMuDQo+DQo+ICAgICAgICAgVGhlIG1lZXRpbmcgd2FzIHJlY29y
ZGVkICh5b3UgY2FuIGZpbmQgaXQgd2l0aCB0b2RheSdzIGRhdGUgYXQNCj4gICAgICAgICBbMV0p
LiAgVGhlIHRvcGljIG9mIGRpc2N1c3Npb24gd2FzIHByaW1hcmlseSBpbiB0aGUgInBoYXNlIDEi
DQo+ICAgICAgICAgYXJlYSBvZiB3aGF0IERhbm55IHNlbnQgdG8gdGhlIGxpc3Qgbm90IHZlcnkg
bG9uZyBhZ28gWzJdLCBhbmQNCj4gICAgICAgICByZXN1bHRlZCBpbiBhICpzdGFydGluZyBwb2lu
dCogZGlhZ3JhbSBbM10uDQo+DQo+ICAgICAgICAgVGhlIGdyb3VwIHdobyBtZXQgdG9kYXkgYXJl
IChyb3VnaGx5KSBhZ3JlZWQgb24gdGhlIHNpeCBtYWluDQo+ICAgICAgICAgImNvbXBvbmVudHMi
IHJlcHJlc2VudGVkIGluIHRoYXQgZGlhZ3JhbSwgYnV0IGFsc28gc2VlIHRoYXQgd2UNCj4gICAg
ICAgICBoYXZlIHNvbWUgd29yayBhaGVhZC4gIFNwZWNpZmljYWxseSwgd2UgcXVpY2tseSByZWNv
Z25pemVkIHRoYXQNCj4gICAgICAgICBzb21lIG9mIHRoZSBhc3N1bXB0aW9ucyB0aGUgdnVsbmVy
YWJpbGl0eSBkcmFmdCBtYWtlcyBtYXkgYmUNCj4gICAgICAgICBhc3N1bXB0aW9ucyB3ZSBjYW5u
b3QgYWZmb3JkIHRvIG1ha2UgYW5kIG5lZWQgdG8gaW5jbHVkZSBpbiB0aGUNCj4gICAgICAgICBl
eHBsb3JhdGlvbi4NCj4NCj4gICAgICAgICBXZSB0aG91Z2h0IGl0IHdvdWxkIGJlIGEgZ29vZCBp
ZGVhIHRvIGhhdmUgYW5vdGhlciBpbmZvcm1hbA0KPiAgICAgICAgIGRpc2N1c3Npb24gaW4gYSBj
b3VwbGUgb2Ygd2Vla3MgKEZlYnJ1YXJ5IDIpIGF0IHRoZSBzYW1lIHRpbWUNCj4gICAgICAgICAo
MTBhbSBFYXN0ZXJuIC8gM3BtIFVUQyksIHVzaW5nIHRoZSBzYW1lIFdlYkV4IFs0XS4gICBBdCB0
aGF0DQo+ICAgICAgICAgdGltZSB3ZSBpbnRlbmQgdG8gcm9sbCB0aHJvdWdoIHRoZSB2dWxuZXJh
YmlsaXR5IGFzc2Vzc21lbnQNCj4gICAgICAgICBzY2VuYXJpbyBhc3N1bXB0aW9ucyBpbiBhbiBl
ZmZvcnQgdG8gZGV0ZXJtaW5lIHdoaWNoIG9uZXMgY2FuIGJlDQo+ICAgICAgICAgbGVmdCBhcyBh
c3N1bXB0aW9ucyBhbmQgd2hpY2ggb25lcyBjYW5ub3QuICBUaGVuIHdlJ2xsIHRha2UNCj4gICAg
ICAgICBhbm90aGVyIGxvb2sgYXQgdGhlIGRpYWdyYW0gYW5kIHdvcmsgb24gaXRzIG5leHQgdmVy
c2lvbi4NCj4NCj4gICAgICAgICBTdGF5IHR1bmVkLg0KPg0KPiAgICAgICAgIFRoYW5rcyB0byBE
YW5ueSwgU3RlcGhlbiwgYW5kIEplcm9tZSBmb3Igam9pbmluZyBhbmQgY29udHJpYnV0aW5nIQ0K
Pg0KPiAgICAgICAgIEtpbmQgcmVnYXJkcywNCj4NCj4gICAgICAgICBBZGFtDQo+DQo+DQo+ICAg
ICAgICAgWzFdIGh0dHBzOi8vZHJpdmUuZ29vZ2xlLmNvbS9vcGVuP2lkPTBCOFdmOVVuNUZkQ2JX
R2hET0hwVlIwdE1kMUUNCj4gICAgICAgICBbMl0gaHR0cHM6Ly9tYWlsYXJjaGl2ZS5pZXRmLm9y
Zy9hcmNoL21zZy9zYWNtL19MaUtseXZBd3NfT1ZMRmhCNU5TVTU4TVhETQ0KPiAgICAgICAgIFsz
XSBodHRwczovL2RyaXZlLmdvb2dsZS5jb20vb3Blbj9pZD0wQjhXZjlVbjVGZENiTVU1cGRUUmpl
akp0TkhjDQo+ICAgICAgICAgWzRdIGh0dHBzOi8vaWV0Zi53ZWJleC5jb20vbWVldC9zYWNtDQo+
DQo+DQo+DQo+IF9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
DQo+IHNhY20gbWFpbGluZyBsaXN0DQo+IHNhY21AaWV0Zi5vcmc8bWFpbHRvOnNhY21AaWV0Zi5v
cmc+DQo+IGh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vc2FjbQ0KPg0KDQpf
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0Kc2FjbSBtYWls
aW5nIGxpc3QNCnNhY21AaWV0Zi5vcmc8bWFpbHRvOnNhY21AaWV0Zi5vcmc+DQpodHRwczovL3d3
dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY20NCg0K

--_000_MWHPR09MB144086C8D167D5BEB1BC5258F04C0MWHPR09MB1440namp_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpWZXJkYW5hOw0KCXBhbm9zZS0xOjIgMTEg
NiA0IDMgNSA0IDQgMiA0O30NCi8qIFN0eWxlIERlZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwg
bGkuTXNvTm9ybWFsLCBkaXYuTXNvTm9ybWFsDQoJe21hcmdpbjowaW47DQoJbWFyZ2luLWJvdHRv
bTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6IlRpbWVzIE5ldyBS
b21hbiIsc2VyaWY7fQ0KYTpsaW5rLCBzcGFuLk1zb0h5cGVybGluaw0KCXttc28tc3R5bGUtcHJp
b3JpdHk6OTk7DQoJY29sb3I6Ymx1ZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCmE6
dmlzaXRlZCwgc3Bhbi5Nc29IeXBlcmxpbmtGb2xsb3dlZA0KCXttc28tc3R5bGUtcHJpb3JpdHk6
OTk7DQoJY29sb3I6cHVycGxlOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KcC5tc29u
b3JtYWwwLCBsaS5tc29ub3JtYWwwLCBkaXYubXNvbm9ybWFsMA0KCXttc28tc3R5bGUtbmFtZTpt
c29ub3JtYWw7DQoJbXNvLW1hcmdpbi10b3AtYWx0OmF1dG87DQoJbWFyZ2luLXJpZ2h0OjBpbjsN
Cgltc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0bzsNCgltYXJnaW4tbGVmdDowaW47DQoJZm9udC1z
aXplOjEyLjBwdDsNCglmb250LWZhbWlseToiVGltZXMgTmV3IFJvbWFuIixzZXJpZjt9DQpzcGFu
LmhvZW56Yg0KCXttc28tc3R5bGUtbmFtZTpob2VuemI7fQ0Kc3Bhbi5FbWFpbFN0eWxlMTkNCgl7
bXNvLXN0eWxlLXR5cGU6cGVyc29uYWwtcmVwbHk7DQoJZm9udC1mYW1pbHk6IkNhbGlicmkiLHNh
bnMtc2VyaWY7DQoJY29sb3I6d2luZG93dGV4dDt9DQouTXNvQ2hwRGVmYXVsdA0KCXttc28tc3R5
bGUtdHlwZTpleHBvcnQtb25seTsNCglmb250LWZhbWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjt9
DQpAcGFnZSBXb3JkU2VjdGlvbjENCgl7c2l6ZTo4LjVpbiAxMS4waW47DQoJbWFyZ2luOjEuMGlu
IDEuMGluIDEuMGluIDEuMGluO30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7cGFnZTpXb3JkU2VjdGlv
bjE7fQ0KLS0+PC9zdHlsZT48IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlZGVmYXVs
dHMgdjpleHQ9ImVkaXQiIHNwaWRtYXg9IjEwMjYiIC8+DQo8L3htbD48IVtlbmRpZl0tLT48IS0t
W2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlbGF5b3V0IHY6ZXh0PSJlZGl0Ij4NCjxvOmlk
bWFwIHY6ZXh0PSJlZGl0IiBkYXRhPSIxIiAvPg0KPC9vOnNoYXBlbGF5b3V0PjwveG1sPjwhW2Vu
ZGlmXS0tPg0KPC9oZWFkPg0KPGJvZHkgbGFuZz0iRU4tVVMiIGxpbms9ImJsdWUiIHZsaW5rPSJw
dXJwbGUiPg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkm
cXVvdDssc2Fucy1zZXJpZiI+SXMgdGhlIG9wZXJhdGlvbiDigJxnZXQgZW5kcG9pbnRz4oCdIGEg
c2luZ2xlIG9wZXJhdGlvbiBvciBpcyBpdCBtdWx0aXBsZSBvcGVyYXRpb25zIOKAnGdldCBlbmRw
b2ludCBjaGFyYWN0ZXJpc3RpY3PigJ0gYW5kIOKAnGdldCBwcmV2aW91c2x5IGNvbGxlY3RlZCBk
YXRh4oCdLCBvciBldmVuIOKAnHF1ZXJ5IGlmIHRoZXJlDQogaXMgcHJldmlvdXNseSBjb2xsZWN0
ZWQgZGF0YSB0aGF0IG1hdGNoZXMgWCBpbiB0aW1lZnJhbWUgWT/igJ0gSXQgd291bGQgYmUgaGVs
cGZ1bCB0byBiZSBtb3JlIHNwZWNpZmljIGhlcmUgc2luY2UgdGhlIGluZm9ybWF0aW9uIGV4Y2hh
bmdlcyBtYXkgZGlmZmVyLjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6
JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5TaG91bGQgdGhlIOKAnGNvbGxlY3TigJ0g
YmV0d2VlbiB2dWxuZXJhYmlsaXR5IGFzc2Vzc29yIGFuZCBjb2xsZWN0b3Igc2hvdWxkIGJlIOKA
nHJlcXVlc3QgY29sbGVjdGlvbiAoZm9yIGEgc2V0IG9mIGVuZHBvaW50cynigJ0/PG86cD48L286
cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6
ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj48bzpw
PiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHls
ZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMt
c2VyaWYiPlRoZSBmaXJzdCDigJxldmFsdWF0ZeKAnSAoZnJvbSB0aGUgdG9wKSBjb3VsZCBiZSB0
aG91Z2h0IG9mIGFzIGFuIGFwcGxpY2FiaWxpdHkgLyBzdGFsZW5lc3MgZXZhbHVhdGlvbi4gVGhp
cyBkcml2ZXMgd2hhdCBnYXBzIGluIGluZm9ybWF0aW9uIGFuZCBlbmRwb2ludHMgc2hvdWxkIGJl
IHRhcmdldGVkIGZvcg0KIGNvbGxlY3Rpb24uPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6
JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48
L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtm
b250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPlRoZSBzZWNvbmQg4oCc
KHJlKWV2YWx1YXRl4oCdIGlzIHRoZSBhY3R1YWwgcG9zdHVyZSBldmFsdWF0aW9uIHdlIGFyZSB3
b3JraW5nIHRvIHN1cHBvcnQuIFJpZ2h0PzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZx
dW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9w
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5SZWdhcmRzLDxvOnA+PC9v
OnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNp
emU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJpZiI+RGF2
ZTxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxl
PSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1z
ZXJpZiI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5v
bmU7Ym9yZGVyLWxlZnQ6c29saWQgYmx1ZSAxLjVwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDQuMHB0
Ij4NCjxkaXY+DQo8ZGl2IHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItdG9wOnNvbGlkICNFMUUx
RTEgMS4wcHQ7cGFkZGluZzozLjBwdCAwaW4gMGluIDBpbiI+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48Yj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxp
YnJpJnF1b3Q7LHNhbnMtc2VyaWYiPkZyb206PC9zcGFuPjwvYj48c3BhbiBzdHlsZT0iZm9udC1z
aXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPiBz
YWNtIFttYWlsdG86c2FjbS1ib3VuY2VzQGlldGYub3JnXQ0KPGI+T24gQmVoYWxmIE9mIDwvYj5C
aWxsIE11bnlhbjxicj4NCjxiPlNlbnQ6PC9iPiBUaHVyc2RheSwgRmVicnVhcnkgMDIsIDIwMTcg
MTI6NTcgUE08YnI+DQo8Yj5Ubzo8L2I+IEFkYW0gTW9udHZpbGxlICZsdDthZGFtLncubW9udHZp
bGxlQGdtYWlsLmNvbSZndDs8YnI+DQo8Yj5DYzo8L2I+IEhlbmsgQmlya2hvbHogJmx0O2hlbmsu
Ymlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGUmZ3Q7OyBzYWNtQGlldGYub3JnPGJyPg0KPGI+U3Vi
amVjdDo8L2I+IFJlOiBbc2FjbV0gTm90ZXMgb24gVnVsbmVyYWJpbGl0eSBTY2VuYXJpbyBXb3Jr
aW5nIFNlc3Npb248bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1
b3Q7LHNhbnMtc2VyaWYiPklzIGl0IHdvcnRoIG5vdGluZyBpbiB0aGUgZGlhZ3JhbSAoaWYgbm90
LCBJIHRoaW5rIGl0IG5lZWRzIHRvIGJlIG5vdGVkIHNvbWV3aGVyZSBub25ldGhlbGVzcykgdGhh
dCB0aGUgc3RlcHMgb2YgJnF1b3Q7Z2V0IGVuZHBvaW50cyZxdW90OyBhbmQgc3Vic2VxdWVudCAm
cXVvdDtldmFsdWF0ZSZxdW90OyBzaG91bGQgYmUgbWFraW5nIHNvbWUgZGV0ZXJtaW5hdGlvbg0K
IG9mIHdoZXRoZXIgb3Igbm90IHRvIGNvbGxlY3QgZm9yIGFuIGVuZHBvaW50PyZuYnNwOyBGb3Ig
ZXhhbXBsZSwgaWYgYW4gZW5kcG9pbnQgaGFzIG5vIGFzc2Vzc21lbnQgcmVzdWx0cyBvciB0aGUg
YXNzZXNzbWVudCByZXN1bHRzIGFyZSBjb25zaWRlcmVkICZxdW90O3N0YWxlJnF1b3Q7LCB0aGVu
IHRoZSBjb2xsZWN0aW9uIHN0ZXAgd291bGQgdGFrZSBwbGFjZS4mbmJzcDsgSSB1bmRlcnN0YW5k
IHRoYXQgY291bGQgYmUgdG9vIG11Y2ggZGV0YWlsIGZvciB0aGUgc2NvcGUgb2YgdGhlDQogZGlh
Z3JhbSwgYnV0IEkganVzdCB3YW50ZWQgdG8gbm90ZSBpdCBzb21ld2hlcmUuPG86cD48L286cD48
L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5
bGU9ImZvbnQtZmFtaWx5OiZxdW90O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4mbmJz
cDs8L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+
Q2hlZXJzLCZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1
b3Q7LHNhbnMtc2VyaWYiPi1CaWxsIE0uPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8
ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90
O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwv
bzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5PbiBUaHUsIEZlYiAyLCAyMDE3
IGF0IDEyOjQ0IFBNLCBBZGFtIE1vbnR2aWxsZSAmbHQ7PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5t
b250dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFp
bC5jb208L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJi
b3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGluIDBp
biAwaW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFyZ2luLXJpZ2h0OjBpbiI+DQo8ZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+VGhhbmtzIGZvciB0aGUgZmVlZGJhY2shJm5ic3A7IEkndmUg
YXR0YWNoZWQgYSBtb2RpZmllZCB2ZXJzaW9uIG9mIHRoZSBkaWFncmFtIHRoYXQgY29sbGFwc2Vz
IHRoZSBlbmRwb2ludCBhbmQgYXNzZXNzbWVudCByZXN1bHQgcmVwb3NpdG9yaWVzIChieSBrZWVw
aW5nIHRoZSBlbmRwb2ludCByZXBvc2l0b3J5KS4mbmJzcDsgV2hlcmUgd291bGQgeW91IHByb3Bv
c2Ugd2UgZm9jdXMgb24gZW5oYW5jaW5nIHRoZSBkaWFncmFtPyZuYnNwOw0KIFJlbWVtYmVyIHRo
YXQgaXQncyBhIHNlcXVlbmNlIGRpYWdyYW0sIHdoaWNoIG1pZ2h0IGRvIHdlbGwgd2l0aCBzb21l
IG1vcmUgc3BlY2lmaWMgZGV0YWlscyBjYXB0dXJlZCBpbiB0ZXh0IG9yIGEgZGlmZmVyZW50IGZv
cm0gb2YgZGlhZ3JhbS48bzpwPjwvbzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPldoYXQgZG8gZm9sa3MgdGhpbmsgYWJvdXQgdXNpbmcgb25lIG9yIG1vcmUgT1ZBTCBkZWZp
bml0aW9ucyBhcyBhIHN0YXJ0aW5nIHBvaW50PzxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImNvbG9yOiM4ODg4ODgiPjxvOnA+
Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIHN0eWxlPSJjb2xvcjojODg4ODg4Ij5BZGFtPG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpw
PiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJz
cDs8L286cD48L3A+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPk9uIFRodSwg
RmViIDIsIDIwMTcgYXQgMTA6NTMgQU0gSGVuayBCaXJraG9seiAmbHQ7PGEgaHJlZj0ibWFpbHRv
OmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGUiIHRhcmdldD0iX2JsYW5rIj5oZW5rLmJp
cmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPC9hPiZndDsgd3JvdGU6PG86cD48L286cD48L3A+DQo8
L2Rpdj4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAj
Q0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAwaW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7
bWFyZ2luLXJpZ2h0OjBpbiI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj4jIyBBIEZldyBDb21tZW50
czxicj4NCjxicj4NCiogSSBhZ3JlZSB0aGF0IHRoZSBkaWFncmFtIHByZXR0eSBtdWNoIGNhcHR1
cmVzIGEgJnF1b3Q7b25lIHRpbWUgc25hcHNob3QmcXVvdDsuPGJyPg0KKiBDb2xsYXBzaW5nIHRo
ZSBoaWdobGlnaHRlZCBjb21wb25lbnRzIHNlZW1zIHRvIGJlIGEgZmVhc2libGUgaWRlYS48YnI+
DQoqIEkgYWdyZWUgdGhhdCB0aGUgZGlhZ3JhbSBjb3VsZCBiZSBpbXBsZW1lbnRlZCBnaXZlbiBh
biBhcHByb3ByaWF0ZSBzZXQ8YnI+DQpvZiBpbml0aWFsIGRhdGEuPGJyPg0KKiBJIHN1cHBvc2Ug
dGhlcmUgaXMgdGhlIHJpc2sgdGhhdCBvbmUgaGFzIHRvIHNjcmFwIGV2ZXJ5dGhpbmc8YnI+DQpp
bXBsZW1lbnRlZCB3aGVuIHdlIHN0YXJ0IHRyeWluZyB0byBtYWtlIGl0IGEgY29udGludW91cyBw
cm9jZXNzLjxicj4NCiogSSdkIHJlY29tbWVuZCB0byBzdGFydCB3aXRoIGEgZ2VuZXJpYyBibG9j
ayBvZiBQb0MgY29kZSB0aGF0IHByb3ZpZGVzPGJyPg0KdGhlIGZ1bmN0aW9ucyBvZiBhIFNBQ00g
Y29tcG9uZW50IHRvIGdldCBpbnB1dCBhbmQgY3JlYXRlIG91dHB1dCAobWF5YmU8YnI+DQp1c2lu
ZyBkYnVzLCBjaGFpbmVkIGV2ZW50LWxvb3BzLCBibG9ja2luZyB3YWl0cyBvbiBmaWZvcywgb3Ig
SVAgb3Zlcjxicj4NCmxvb3BiYWNrPyBBIGJldHRlciBjb2RlciB0aGFuIG1lIHNob3VsZCBiYXNo
IHRoZXNlIHN1Z2dlc3Rpb25zKS48YnI+DQo8YnI+DQojIyBPbmUsIFR3bywgb3IgVGhyZWUgVGFz
a3M8YnI+DQo8YnI+DQoqIENyZWF0aW5nIGNvbXBvbmVudCBjb2RlIHRoYXQgY2FuIGNyZWF0ZSB0
aGUgKGRvd25zdHJlYW0/KSBmbG93IG9mPGJyPg0KaW5mb3JtYXRpb24gaXMgdXJnZW50IGFuZCBp
bXBvcnRhbnQsIEkgdGhpbmsuPGJyPg0KKiBFbmhhbmNpbmcgdGhlIGRpYWdyYW0gdG8gcmVwcmVz
ZW50IHRoZSBjb250aW51b3VzIGN5Y2xlIHdpdGggYXQgbGVhc3Q8YnI+DQpvbmUgdHJpZ2dlciAo
YXMgaWxsdXN0cmF0ZWQgYnkgQmlsbDsgbmV3IHNvZnR3YXJlLCBuZXcgVkRJLCBuZXc8YnI+DQpl
bmRwb2ludHMsIHN0YWxlIHJlc3VsdHMsIGV0Yy4pIGlzIGltcG9ydGFudCwgYnV0IG5vdCBhcyB1
cmdlbnQuIEl0PGJyPg0KbWlnaHQgc2F2ZSB0aW1lIHRob3VnaCBieSByZWR1Y2luZyB0aGUgYWZv
cmUgbWVudGlvbmVkIHJpc2sgdG8gc2hvb3Q8YnI+DQp5b3VyIHNlbGYgaW4gdGhlIGZvb3QgYnkg
Y3JlYXRpbmcgYSB0b28gc3BlY2lmaWMgcHJvb2Ygb2YgY29uY2VwdCBvZiB0aGU8YnI+DQpvbmUg
dGltZSBzbmFwc2hvdCBhcHByb2FjaCwgSSB0aGluay48YnI+DQoqIFNlbGVjdGluZyBhIHNldCBv
ZiBpbml0aWFsIGRhdGEgZGVyaXZlZCBmcm9tIE9WQUwgdG8gYmUgdXNlZCBpbiB0aGU8YnI+DQpv
bmUgc2hvdCBzbmFwc2hvdCBzZWVtcyB0byBiZSBhIGZlYXNpYmxlIGFwcHJvYWNoIHRvIG1lLCBi
dXQgSSBhbSBub3Q8YnI+DQpzdXJlIGhvdyB0aGUgZ3JvdXAgdGhpbmtzIGFib3V0IHRoYXQuPGJy
Pg0KPGJyPg0KRG9lcyB0aGF0IGFzc2Vzc21lbnQgcmVwcmVzZW50IHRoZSBnZW5lcmFsIG9waW5p
b24sIG9yIGlzIHRoYXQganVzdCBtaW5lPzxicj4NCjxicj4NClZpZWxlIEdyw7zDn2UsPGJyPg0K
PGJyPg0KSGVuazxicj4NCjxicj4NCk9uIDAyLzAyLzIwMTcgMDU6MjggUE0sIEFkYW0gTW9udHZp
bGxlIHdyb3RlOjxicj4NCiZndDsgSGkgRXZlcnlvbmUuJm5ic3A7IEEgZmV3IG9mIHVzIHdlcmUg
YWJsZSB0byBtYWtlIHRoZSB2dWxuZXJhYmlsaXR5IHNjZW5hcmlvPGJyPg0KJmd0OyBjYWxsIHRv
ZGF5IGFuZCBJIHRoaW5rIHdlIGhhZCBhIGdvb2QsIHRob3VnaCBhdCB0aW1lcyBzcGlyaXRlZCw8
YnI+DQomZ3Q7IGRpc2N1c3Npb24uJm5ic3A7IFdlIGRpZCByZWNvcmQgdGhlIG1lZXRpbmcsIHdo
aWNoIGlzIGF2YWlsYWJsZSBhdCBbMV0uJm5ic3A7IFdlPGJyPg0KJmd0OyBkaXNjdXNzZWQgdGhl
IGF0dGFjaGVkIChhbm5vdGF0ZWQgd2l0aCBzb21lIG1lZXRpbmcgbm90ZXMpIFVNTC1pc2g8YnI+
DQomZ3Q7IHNlcXVlbmNlIGRpYWdyYW0uJm5ic3A7IEkgaGFkIGNyZWF0ZWQgdGhhdCBkaWFncmFt
IHRvIHN0YXJ0IGEgY29udmVyc2F0aW9uPGJyPg0KJmd0OyAobWlzc2lvbiBhY2NvbXBsaXNoZWQg
b24gdGhhdCBmcm9udCBJIHRoaW5rKSAtLSBhIGNvbnZlcnNhdGlvbiB0aGF0PGJyPg0KJmd0OyB3
b3VsZCBsZWFkIHVzIHRvd2FyZCBpZGVudGlmeWluZyB0aGUgZGlzY3JldGUgY29tcG9uZW50cywg
aW50ZXJmYWNlcyw8YnI+DQomZ3Q7IGFuZCBpbmZvcm1hdGlvbiByZXF1aXJlZCB0byBiZSBzZW50
IG92ZXIgdGhvc2UgaW50ZXJmYWNlcy4mbmJzcDsgVGhlIFVNTC1pc2g8YnI+DQomZ3Q7IGRpYWdy
YW0gcmVwcmVzZW50cyBhICpzaW5nbGUqIGZsb3cgdGhyb3VnaCB0aGUgc3lzdGVtIC0tIGEgJnF1
b3Q7b25lLXRpbWUmcXVvdDs8YnI+DQomZ3Q7IGZsb3cgdGhyb3VnaCB0aGUgc3lzdGVtLiZuYnNw
OyBJdCBpZ25vcmVzLCBmb3IgdGhlIHRpbWUgYmVpbmcsIHRoZSBjb250aW51b3VzPGJyPg0KJmd0
OyBhc3BlY3Qgb2Ygb3VyIGNoYXJ0ZXIgaW4gZmF2b3Igb2YgZ2V0dGluZyBzdGFydGVkIHdpdGgg
dGhlIGJhc2ljcy4mbmJzcDsgT25jZTxicj4NCiZndDsgd2UgaGF2ZSBhIGdvb2QgdW5kZXJzdGFu
ZGluZyBvZiB0aGUgYmFzaWNzIC0tIHRoZSBjb21wb25lbnRzLDxicj4NCiZndDsgaW50ZXJmYWNl
cywgYW5kIGluZm9ybWF0aW9uIHJlcXVpcmVkIC0tIHdlIGNhbiBzdGFydCBsb29rIGF0IGE8YnI+
DQomZ3Q7IGNvbnRpbnVvdXMgbW9uaXRvcmluZyBzZXF1ZW5jZSAod2hpY2ggY291bGQgYmUgcmVw
cmVzZW50ZWQgYXMgYSBkaXN0aW5jdDxicj4NCiZndDsgZGlhZ3JhbSkgdG8gZGV0ZXJtaW5lIHdo
YXQgbW9yZSB3ZSBuZWVkLiZuYnNwOyBUaGVuLCBJIHRoaW5rLCB3ZSBjYW4gc3RhcnQ8YnI+DQom
Z3Q7IGRyYWZ0aW5nIHNvbHV0aW9ucy48YnI+DQomZ3Q7PGJyPg0KJmd0OyBPbmUgb2YgdGhlIGZp
cnN0IGlzc3VlcyBpcyB0aGF0IHdlIG5lZWQgdG8gZmlndXJlIG91dCBpZiB0aGUgY29tcG9uZW50
czxicj4NCiZndDsgaW4gdGhlIGJhc2UgZmxvdyBhcmUgYWNjdXJhdGUuJm5ic3A7IFRoZSBtYWlu
IHN1Z2dlc3Rpb24gd2UndmUgdG9zc2VkIGFyb3VuZDxicj4NCiZndDsgc28gZmFyIGlzIHRvIGNv
bWJpbmUgdGhlIEVuZHBvaW50IFJlcG9zaXRvcnkgd2l0aCB0aGUgQXNzZXNzbWVudCBSZXN1bHQ8
YnI+DQomZ3Q7IFJlcG9zaXRvcnkuPGJyPg0KJmd0Ozxicj4NCiZndDsgV2UgdGFsa2VkIGJyaWVm
bHkgYWJvdXQgd2hhdCBpbnRlcmZhY2Ugd2UgY291bGQgdXNlIGZvciB0aGUgVkREPGJyPg0KJmd0
OyBSZXBvc2l0b3J5LCBhbmQgbmF0dXJhbGx5IFJPTElFIGNhbWUgdXAgYXMgYW4gb3B0aW9uLjxi
cj4NCiZndDs8YnI+DQomZ3Q7IFdlIHRhbGtlZCBhIGxpdHRsZSBiaXQgYWJvdXQgdGhlIGZpcnN0
ICZxdW90O2dldCBlbmRwb2ludHMmcXVvdDsgb3BlcmF0aW9uIGJldHdlZW48YnI+DQomZ3Q7IHRo
ZSBWdWxuZXJhYmlsaXR5IEFzc2Vzc29yIGFuZCB0aGUgRW5kcG9pbnQgUmVwb3NpdG9yeSAtLSBz
cGVjaWZpY2FsbHk8YnI+DQomZ3Q7IGFib3V0IHdoZXRoZXIgd2Ugc2hvdWxkIHJlcHJlc2VudCBv
biB0aGlzIHNlcXVlbmNlIGRpYWdyYW0gdGhhdDxicj4NCiZndDsgaW5mb3JtYXRpb24gc3VwcG9y
dGluZyBhIGp1ZGdlbWVudCBvZiAmcXVvdDtzdGFsZSZxdW90OyB3b3VsZCBiZSBuZWVkZWQuPGJy
Pg0KJmd0Ozxicj4NCiZndDsgV2UgbGVmdCBvcGVuIHRoZSB0aW1lIHdoZW4gd2Ugd291bGQgbmV4
dCBtZWV0LCBmYXZvcmluZyB0byB3b3JrIHRoYXQgb3V0PGJyPg0KJmd0OyBvbi1saXN0LiZuYnNw
OyBOZXh0IHdlZWsgaXMgVENHLCBzbyB0aGF0IG1heSBiZSBkaWZmaWN1bHQ7IHRoZSBmb2xsb3dp
bmcgd2Vlazxicj4NCiZndDsgaXMgUlNBLCBzbyB0aGF0IG1heSBiZSBkaWZmaWN1bHQuPGJyPg0K
Jmd0Ozxicj4NCiZndDsgRm9yIHRob3NlIHdobyB3ZXJlIGluIGF0dGVuZGFuY2UgdG9kYXksIHBs
ZWFzZSBhZGQgdG8gdGhpcyBub3RlIHdpdGg8YnI+DQomZ3Q7IHlvdXIgY29tbWVudHMvY29ycmVj
dGlvbnMuPGJyPg0KJmd0Ozxicj4NCiZndDsgS2luZCByZWdhcmRzLDxicj4NCiZndDs8YnI+DQom
Z3Q7IEFkYW08YnI+DQomZ3Q7PGJyPg0KJmd0OyBbMV0gPGEgaHJlZj0iaHR0cHM6Ly9kcml2ZS5n
b29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERPSHBWUjB0TWQxRSIgdGFyZ2V0PSJf
YmxhbmsiPg0KaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldH
aERPSHBWUjB0TWQxRTwvYT48YnI+DQomZ3Q7PGJyPg0KJmd0OyBPbiBNb24sIEphbiAzMCwgMjAx
NyBhdCAxMToyMSBBTSBBZGFtIE1vbnR2aWxsZTxicj4NCiZndDsgJmx0OzxhIGhyZWY9Im1haWx0
bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250
dmlsbGVAZ21haWwuY29tPC9hPiAmbHQ7bWFpbHRvOjxhIGhyZWY9Im1haWx0bzphZGFtLncubW9u
dHZpbGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21haWwu
Y29tPC9hPiZndDsmZ3Q7IHdyb3RlOjxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAm
bmJzcDtIaSBldmVyeW9uZS4mbmJzcDsgSnVzdCBhIGZyaWVuZGx5IHJlbWluZGVyIHRoYXQgd2Ug
YXJlIHBsYW5uaW5nIHRvIG1lZXQ8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDthZ2FpbiB0
aGlzIFRodXJzZGF5IGF0IHRoZSBzYW1lIHRpbWUgKDIvMiBAIDEwYW0gRWFzdGVybi8zcG0gVVRD
KTxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO3VzaW5nIFNBQ00ncyBtZWV0aW5nIHJvb20g
YXQgPGEgaHJlZj0iaHR0cHM6Ly9pZXRmLndlYmV4LmNvbS9tZWV0L3NhY20iIHRhcmdldD0iX2Js
YW5rIj4NCmh0dHBzOi8vaWV0Zi53ZWJleC5jb20vbWVldC9zYWNtPC9hPi48YnI+DQomZ3Q7PGJy
Pg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7S2luZCByZWdhcmRzLDxicj4NCiZndDs8YnI+DQom
Z3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDtBZGFtPGJyPg0KJmd0Ozxicj4NCiZndDs8YnI+DQomZ3Q7
Jm5ic3A7ICZuYnNwOyAmbmJzcDtPbiBUaHUsIEphbiAxOSwgMjAxNyBhdCAxMTozNSBBTSBBZGFt
IE1vbnR2aWxsZTxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyZsdDs8YSBocmVmPSJtYWls
dG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9u
dHZpbGxlQGdtYWlsLmNvbTwvYT4gJmx0O21haWx0bzo8YSBocmVmPSJtYWlsdG86YWRhbS53Lm1v
bnR2aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9udHZpbGxlQGdtYWls
LmNvbTwvYT4mZ3Q7Jmd0OyB3cm90ZTo8YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDtIZWxsby4gQSBmZXcgb2YgdXMgbWV0IGluZm9ybWFsbHkgdG9k
YXkgdG8gZGlzY3VzcyB0aGU8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZu
YnNwO3Z1bG5lcmFiaWxpdHkgc2NlbmFyaW8gaW4gc29tZSBtb3JlIGRldGFpbCB3aXRoIHRoZSBn
b2FsIG9mPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDttYWludGFp
bmluZyB0aGUgbmFycm93IGZvY3VzIG9uIGEgdnVsbmVyYWJpbGl0eSBhc3Nlc3NtZW50IHNsaWNl
PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDt0aHJvdWdoIG91ciBu
b3Rpb25hbCBlbnZpcm9ubWVudC4mbmJzcDsgV2UgYXJlIHRlbmRpbmcgdG8gbG9vayBhdDxicj4N
CiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7bWFqb3IgY29tcG9uZW50cyBh
cyBibGFjayBib3hlcyB3aXRoIGludGVyZmFjZXMgYW5kIGRhdGEgZm9ybWF0PGJyPg0KJmd0OyZu
YnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtleHBlY3RhdGlvbnMsIGFuZCB3ZSBhcmUg
bm90IG5lY2Vzc2FyaWx5IGNvbmNlcm5lZCB3aXRoIGhvdzxicj4NCiZndDsmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7dGhvc2UgY29tcG9uZW50cyBkbyB0aGluZ3MgaW50ZXJuYWxs
eS9iZWhpbmQgdGhlIHNjZW5lcy48YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDtUaGUgbWVldGluZyB3YXMgcmVjb3JkZWQgKHlvdSBjYW4gZmluZCBp
dCB3aXRoIHRvZGF5J3MgZGF0ZSBhdDxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7WzFdKS4mbmJzcDsgVGhlIHRvcGljIG9mIGRpc2N1c3Npb24gd2FzIHByaW1hcmls
eSBpbiB0aGUgJnF1b3Q7cGhhc2UgMSZxdW90Ozxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7YXJlYSBvZiB3aGF0IERhbm55IHNlbnQgdG8gdGhlIGxpc3Qgbm90IHZl
cnkgbG9uZyBhZ28gWzJdLCBhbmQ8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwO3Jlc3VsdGVkIGluIGEgKnN0YXJ0aW5nIHBvaW50KiBkaWFncmFtIFszXS48YnI+DQom
Z3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtUaGUgZ3JvdXAg
d2hvIG1ldCB0b2RheSBhcmUgKHJvdWdobHkpIGFncmVlZCBvbiB0aGUgc2l4IG1haW48YnI+DQom
Z3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyZxdW90O2NvbXBvbmVudHMmcXVv
dDsgcmVwcmVzZW50ZWQgaW4gdGhhdCBkaWFncmFtLCBidXQgYWxzbyBzZWUgdGhhdCB3ZTxicj4N
CiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7aGF2ZSBzb21lIHdvcmsgYWhl
YWQuJm5ic3A7IFNwZWNpZmljYWxseSwgd2UgcXVpY2tseSByZWNvZ25pemVkIHRoYXQ8YnI+DQom
Z3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3NvbWUgb2YgdGhlIGFzc3VtcHRp
b25zIHRoZSB2dWxuZXJhYmlsaXR5IGRyYWZ0IG1ha2VzIG1heSBiZTxicj4NCiZndDsmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7YXNzdW1wdGlvbnMgd2UgY2Fubm90IGFmZm9yZCB0
byBtYWtlIGFuZCBuZWVkIHRvIGluY2x1ZGUgaW4gdGhlPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDtleHBsb3JhdGlvbi48YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtXZSB0aG91Z2h0IGl0IHdvdWxkIGJlIGEgZ29v
ZCBpZGVhIHRvIGhhdmUgYW5vdGhlciBpbmZvcm1hbDxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZu
YnNwOyAmbmJzcDsgJm5ic3A7ZGlzY3Vzc2lvbiBpbiBhIGNvdXBsZSBvZiB3ZWVrcyAoRmVicnVh
cnkgMikgYXQgdGhlIHNhbWUgdGltZTxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7KDEwYW0gRWFzdGVybiAvIDNwbSBVVEMpLCB1c2luZyB0aGUgc2FtZSBXZWJFeCBb
NF0uJm5ic3A7ICZuYnNwO0F0IHRoYXQ8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwO3RpbWUgd2UgaW50ZW5kIHRvIHJvbGwgdGhyb3VnaCB0aGUgdnVsbmVyYWJpbGl0
eSBhc3Nlc3NtZW50PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtz
Y2VuYXJpbyBhc3N1bXB0aW9ucyBpbiBhbiBlZmZvcnQgdG8gZGV0ZXJtaW5lIHdoaWNoIG9uZXMg
Y2FuIGJlPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtsZWZ0IGFz
IGFzc3VtcHRpb25zIGFuZCB3aGljaCBvbmVzIGNhbm5vdC4mbmJzcDsgVGhlbiB3ZSdsbCB0YWtl
PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDthbm90aGVyIGxvb2sg
YXQgdGhlIGRpYWdyYW0gYW5kIHdvcmsgb24gaXRzIG5leHQgdmVyc2lvbi48YnI+DQomZ3Q7PGJy
Pg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtTdGF5IHR1bmVkLjxicj4N
CiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1RoYW5rcyB0
byBEYW5ueSwgU3RlcGhlbiwgYW5kIEplcm9tZSBmb3Igam9pbmluZyBhbmQgY29udHJpYnV0aW5n
ITxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0tp
bmQgcmVnYXJkcyw8YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDtBZGFtPGJyPg0KJmd0Ozxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwO1sxXSA8YSBocmVmPSJodHRwczovL2RyaXZlLmdvb2dsZS5jb20v
b3Blbj9pZD0wQjhXZjlVbjVGZENiV0doRE9IcFZSMHRNZDFFIiB0YXJnZXQ9Il9ibGFuayI+DQpo
dHRwczovL2RyaXZlLmdvb2dsZS5jb20vb3Blbj9pZD0wQjhXZjlVbjVGZENiV0doRE9IcFZSMHRN
ZDFFPC9hPjxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7WzJdIDxh
IGhyZWY9Imh0dHBzOi8vbWFpbGFyY2hpdmUuaWV0Zi5vcmcvYXJjaC9tc2cvc2FjbS9fTGlLbHl2
QXdzX09WTEZoQjVOU1U1OE1YRE0iIHRhcmdldD0iX2JsYW5rIj4NCmh0dHBzOi8vbWFpbGFyY2hp
dmUuaWV0Zi5vcmcvYXJjaC9tc2cvc2FjbS9fTGlLbHl2QXdzX09WTEZoQjVOU1U1OE1YRE08L2E+
PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtbM10gPGEgaHJlZj0i
aHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYk1VNXBkVFJqZWpK
dE5IYyIgdGFyZ2V0PSJfYmxhbmsiPg0KaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9
MEI4V2Y5VW41RmRDYk1VNXBkVFJqZWpKdE5IYzwvYT48YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwO1s0XSA8YSBocmVmPSJodHRwczovL2lldGYud2ViZXguY29tL21l
ZXQvc2FjbSIgdGFyZ2V0PSJfYmxhbmsiPmh0dHBzOi8vaWV0Zi53ZWJleC5jb20vbWVldC9zYWNt
PC9hPjxicj4NCiZndDs8YnI+DQomZ3Q7PGJyPg0KJmd0Ozxicj4NCiZndDsgX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX188YnI+DQomZ3Q7IHNhY20gbWFpbGlu
ZyBsaXN0PGJyPg0KJmd0OyA8YSBocmVmPSJtYWlsdG86c2FjbUBpZXRmLm9yZyIgdGFyZ2V0PSJf
YmxhbmsiPnNhY21AaWV0Zi5vcmc8L2E+PGJyPg0KJmd0OyA8YSBocmVmPSJodHRwczovL3d3dy5p
ZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY20iIHRhcmdldD0iX2JsYW5rIj5odHRwczovL3d3
dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY208L2E+PGJyPg0KJmd0OzxvOnA+PC9vOnA+
PC9wPg0KPC9ibG9ja3F1b3RlPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxicj4NCl9fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPGJyPg0Kc2FjbSBtYWls
aW5nIGxpc3Q8YnI+DQo8YSBocmVmPSJtYWlsdG86c2FjbUBpZXRmLm9yZyI+c2FjbUBpZXRmLm9y
ZzwvYT48YnI+DQo8YSBocmVmPSJodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZv
L3NhY20iIHRhcmdldD0iX2JsYW5rIj5odHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3Rp
bmZvL3NhY208L2E+PG86cD48L286cD48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8L2Rpdj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwv
ZGl2Pg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_MWHPR09MB144086C8D167D5BEB1BC5258F04C0MWHPR09MB1440namp_--


From nobody Thu Feb  2 11:07:15 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 04893129538 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 11:07:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JuzeaGhuKrm1 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 11:07:10 -0800 (PST)
Received: from mail-ot0-x235.google.com (mail-ot0-x235.google.com [IPv6:2607:f8b0:4003:c0f::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 26DAA12959D for <sacm@ietf.org>; Thu,  2 Feb 2017 11:07:10 -0800 (PST)
Received: by mail-ot0-x235.google.com with SMTP id 65so19336463otq.2 for <sacm@ietf.org>; Thu, 02 Feb 2017 11:07:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=gKqY1dejx5KcMGXNj/KPdWcfUqPWeQeFkfak/tcgNN8=; b=FYm3acfzKP5+0YUAAnHGSOR566RJWVWXUUS2YCbC9t6K1dm2U6Y1g2mjrp0qvhWG9i W9BR4mIdISvLnmeSQByuoxe9NuRcBQO86dccPDi7J4hzOEiYx1APh5HH1XphS8Xu3L/U GNyah5FMlzNrixoRYT4VJVEu9dEo84rbhm8X9N0bhtm5py8TqHuBQp7QphyVbKBzK7a9 KJOze2VdS2ub3AsxntAblMRYwoivyvZVp6IPz+A9IDJreuXWcrKmOgNnZw/K3+dZ6Zss jyOoIn9rX5vVepQPOg0ibQLK+wJu/AN9gnR2cRQYDb+gRglxCu2QgtgmTBhX7q6Nuimk 5Kbw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=gKqY1dejx5KcMGXNj/KPdWcfUqPWeQeFkfak/tcgNN8=; b=WamwDsMUVy+H5M5qEk2q0Frh1BqsIfiuNubi8ruOARoC1F3F78wJIsz2W3wKfNRoXz 87cy3Tc2wOJIQogTjxzfI/LoFU+ytgFMz+IVAWzm1qwxbWv0GBy7PdHZWNgvwb7mOvRm KJaHXJe191+wCH9564w1BK/wJhxn5F6WGQyc5dokGYhQeUNWYq/QiU5opC82UsJRvzvQ 7cpVZzAhigYupzvY9Zh8mMnJwVvwEYIZnibrKq2/cv4CXAfBuX1m4d+mnmKdImlKH0vK 0hMJ28Y2GFtO47lgpunovBPE+4/VrjVNK+ZGGEj7Tikj+OREwxY+cahoKrpDC+jicPUJ oxrw==
X-Gm-Message-State: AIkVDXI9FUc10tVtiVwaIANfGSrQNea/b0GTbhA8dGGwbdvtSQ6x3BAK4TJZWSAJqNYeVryAI7Uy16eOYfmABw==
X-Received: by 10.157.57.194 with SMTP id y60mr4577729otb.92.1486062429071; Thu, 02 Feb 2017 11:07:09 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com> <MWHPR09MB144086C8D167D5BEB1BC5258F04C0@MWHPR09MB1440.namprd09.prod.outlook.com>
In-Reply-To: <MWHPR09MB144086C8D167D5BEB1BC5258F04C0@MWHPR09MB1440.namprd09.prod.outlook.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 19:06:58 +0000
Message-ID: <CACknUNW1Kb4Eya-y4cd3wKTwUdOhyAFkwveQwUHjeLmMUQc8aw@mail.gmail.com>
To: "Waltermire, David A. (Fed)" <david.waltermire@nist.gov>, Bill Munyan <bill.munyan.ietf@gmail.com>
Content-Type: multipart/alternative; boundary=001a1141a48c32ed91054790df7f
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/Aek5qKTaCF4TZwAx0N2hNNOaqRQ>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 19:07:14 -0000

--001a1141a48c32ed91054790df7f
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Will try inline...

On Thu, Feb 2, 2017 at 12:34 PM Waltermire, David A. (Fed) <
david.waltermire@nist.gov> wrote:

> Is the operation =E2=80=9Cget endpoints=E2=80=9D a single operation or is=
 it multiple
> operations =E2=80=9Cget endpoint characteristics=E2=80=9D and =E2=80=9Cge=
t previously collected
> data=E2=80=9D, or even =E2=80=9Cquery if there is previously collected da=
ta that matches X
> in timeframe Y?=E2=80=9D It would be helpful to be more specific here sin=
ce the
> information exchanges may differ.
>

Don't know yet - this is exactly the sort of conversation we should be
having! What if we numbered them as is, then discuss each in turn, if for
no other reason than tracking what we need to do and what we've done?


>
>
> Should the =E2=80=9Ccollect=E2=80=9D between vulnerability assessor and c=
ollector should
> be =E2=80=9Crequest collection (for a set of endpoints)=E2=80=9D?
>

I don't see why not.  That was the intent -- request or otherwise invoke
collection.


>
>
> The first =E2=80=9Cevaluate=E2=80=9D (from the top) could be thought of a=
s an
> applicability / staleness evaluation. This drives what gaps in informatio=
n
> and endpoints should be targeted for collection.
>

Yes, that was the intent.  Evaluate what we can with available on-hand
information.


>
>
> The second =E2=80=9C(re)evaluate=E2=80=9D is the actual posture evaluatio=
n we are working
> to support. Right?
>

Yep, that's my take.


>
>
> Regards,
>
> Dave
>
>
>
> *From:* sacm [mailto:sacm-bounces@ietf.org] *On Behalf Of *Bill Munyan
> *Sent:* Thursday, February 02, 2017 12:57 PM
> *To:* Adam Montville <adam.w.montville@gmail.com>
> *Cc:* Henk Birkholz <henk.birkholz@sit.fraunhofer.de>; sacm@ietf.org
>
>
> *Subject:* Re: [sacm] Notes on Vulnerability Scenario Working Session
>
>
>
> Is it worth noting in the diagram (if not, I think it needs to be noted
> somewhere nonetheless) that the steps of "get endpoints" and subsequent
> "evaluate" should be making some determination of whether or not to colle=
ct
> for an endpoint?  For example, if an endpoint has no assessment results o=
r
> the assessment results are considered "stale", then the collection step
> would take place.  I understand that could be too much detail for the sco=
pe
> of the diagram, but I just wanted to note it somewhere.
>
>
>
> Cheers,
>
> -Bill M.
>
>
>
>
>
> On Thu, Feb 2, 2017 at 12:44 PM, Adam Montville <
> adam.w.montville@gmail.com> wrote:
>
> Thanks for the feedback!  I've attached a modified version of the diagram
> that collapses the endpoint and assessment result repositories (by keepin=
g
> the endpoint repository).  Where would you propose we focus on enhancing
> the diagram?  Remember that it's a sequence diagram, which might do well
> with some more specific details captured in text or a different form of
> diagram.
>
>
>
> What do folks think about using one or more OVAL definitions as a startin=
g
> point?
>
>
>
> Adam
>
>
>
>
>
> On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz <
> henk.birkholz@sit.fraunhofer.de> wrote:
>
> ## A Few Comments
>
> * I agree that the diagram pretty much captures a "one time snapshot".
> * Collapsing the highlighted components seems to be a feasible idea.
> * I agree that the diagram could be implemented given an appropriate set
> of initial data.
> * I suppose there is the risk that one has to scrap everything
> implemented when we start trying to make it a continuous process.
> * I'd recommend to start with a generic block of PoC code that provides
> the functions of a SACM component to get input and create output (maybe
> using dbus, chained event-loops, blocking waits on fifos, or IP over
> loopback? A better coder than me should bash these suggestions).
>
> ## One, Two, or Three Tasks
>
> * Creating component code that can create the (downstream?) flow of
> information is urgent and important, I think.
> * Enhancing the diagram to represent the continuous cycle with at least
> one trigger (as illustrated by Bill; new software, new VDI, new
> endpoints, stale results, etc.) is important, but not as urgent. It
> might save time though by reducing the afore mentioned risk to shoot
> your self in the foot by creating a too specific proof of concept of the
> one time snapshot approach, I think.
> * Selecting a set of initial data derived from OVAL to be used in the
> one shot snapshot seems to be a feasible approach to me, but I am not
> sure how the group thinks about that.
>
> Does that assessment represent the general opinion, or is that just mine?
>
> Viele Gr=C3=BC=C3=9Fe,
>
> Henk
>
> On 02/02/2017 05:28 PM, Adam Montville wrote:
> > Hi Everyone.  A few of us were able to make the vulnerability scenario
> > call today and I think we had a good, though at times spirited,
> > discussion.  We did record the meeting, which is available at [1].  We
> > discussed the attached (annotated with some meeting notes) UML-ish
> > sequence diagram.  I had created that diagram to start a conversation
> > (mission accomplished on that front I think) -- a conversation that
> > would lead us toward identifying the discrete components, interfaces,
> > and information required to be sent over those interfaces.  The UML-ish
> > diagram represents a *single* flow through the system -- a "one-time"
> > flow through the system.  It ignores, for the time being, the continuou=
s
> > aspect of our charter in favor of getting started with the basics.  Onc=
e
> > we have a good understanding of the basics -- the components,
> > interfaces, and information required -- we can start look at a
> > continuous monitoring sequence (which could be represented as a distinc=
t
> > diagram) to determine what more we need.  Then, I think, we can start
> > drafting solutions.
> >
> > One of the first issues is that we need to figure out if the components
> > in the base flow are accurate.  The main suggestion we've tossed around
> > so far is to combine the Endpoint Repository with the Assessment Result
> > Repository.
> >
> > We talked briefly about what interface we could use for the VDD
> > Repository, and naturally ROLIE came up as an option.
> >
> > We talked a little bit about the first "get endpoints" operation betwee=
n
> > the Vulnerability Assessor and the Endpoint Repository -- specifically
> > about whether we should represent on this sequence diagram that
> > information supporting a judgement of "stale" would be needed.
> >
> > We left open the time when we would next meet, favoring to work that ou=
t
> > on-list.  Next week is TCG, so that may be difficult; the following wee=
k
> > is RSA, so that may be difficult.
> >
> > For those who were in attendance today, please add to this note with
> > your comments/corrections.
> >
> > Kind regards,
> >
> > Adam
> >
> > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >
> > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
> > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote:
> >
> >     Hi everyone.  Just a friendly reminder that we are planning to meet
> >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)
> >     using SACM's meeting room at https://ietf.webex.com/meet/sacm.
> >
> >     Kind regards,
> >
> >     Adam
> >
> >
> >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
> >     <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>>
> wrote:
> >
> >         Hello. A few of us met informally today to discuss the
> >         vulnerability scenario in some more detail with the goal of
> >         maintaining the narrow focus on a vulnerability assessment slic=
e
> >         through our notional environment.  We are tending to look at
> >         major components as black boxes with interfaces and data format
> >         expectations, and we are not necessarily concerned with how
> >         those components do things internally/behind the scenes.
> >
> >         The meeting was recorded (you can find it with today's date at
> >         [1]).  The topic of discussion was primarily in the "phase 1"
> >         area of what Danny sent to the list not very long ago [2], and
> >         resulted in a *starting point* diagram [3].
> >
> >         The group who met today are (roughly) agreed on the six main
> >         "components" represented in that diagram, but also see that we
> >         have some work ahead.  Specifically, we quickly recognized that
> >         some of the assumptions the vulnerability draft makes may be
> >         assumptions we cannot afford to make and need to include in the
> >         exploration.
> >
> >         We thought it would be a good idea to have another informal
> >         discussion in a couple of weeks (February 2) at the same time
> >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At that
> >         time we intend to roll through the vulnerability assessment
> >         scenario assumptions in an effort to determine which ones can b=
e
> >         left as assumptions and which ones cannot.  Then we'll take
> >         another look at the diagram and work on its next version.
> >
> >         Stay tuned.
> >
> >         Thanks to Danny, Stephen, and Jerome for joining and
> contributing!
> >
> >         Kind regards,
> >
> >         Adam
> >
> >
> >         [1]
> https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >         [2]
> https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> >         [3]
> https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> >         [4] https://ietf.webex.com/meet/sacm
> >
> >
> >
> > _______________________________________________
> > sacm mailing list
> > sacm@ietf.org
> > https://www.ietf.org/mailman/listinfo/sacm
> >
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>
>

--001a1141a48c32ed91054790df7f
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Will try inline...<br><br><div class=3D"gmail_quote"><div =
dir=3D"ltr">On Thu, Feb 2, 2017 at 12:34 PM Waltermire, David A. (Fed) &lt;=
<a href=3D"mailto:david.waltermire@nist.gov">david.waltermire@nist.gov</a>&=
gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0=
 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple" class=3D"gmail_msg">
<div class=3D"m_-244727941466904360WordSection1 gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg">Is the operation =E2=
=80=9Cget endpoints=E2=80=9D a single operation or is it multiple operation=
s =E2=80=9Cget endpoint characteristics=E2=80=9D and =E2=80=9Cget previousl=
y collected data=E2=80=9D, or even =E2=80=9Cquery if there
 is previously collected data that matches X in timeframe Y?=E2=80=9D It wo=
uld be helpful to be more specific here since the information exchanges may=
 differ.</span></p></div></div></blockquote><div><br></div><div>Don&#39;t k=
now yet - this is exactly the sort of conversation we should be having! Wha=
t if we numbered them as is, then discuss each in turn, if for no other rea=
son than tracking what we need to do and what we&#39;ve done?</div><div>=C2=
=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;borde=
r-left:1px #ccc solid;padding-left:1ex"><div lang=3D"EN-US" link=3D"blue" v=
link=3D"purple" class=3D"gmail_msg"><div class=3D"m_-244727941466904360Word=
Section1 gmail_msg"><p class=3D"MsoNormal gmail_msg"><span style=3D"font-si=
ze:11.0pt;font-family:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><=
u class=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><u class=3D"gmail_msg=
"></u>=C2=A0<u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg">Should the =E2=80=9Cc=
ollect=E2=80=9D between vulnerability assessor and collector should be =E2=
=80=9Crequest collection (for a set of endpoints)=E2=80=9D?</span></p></div=
></div></blockquote><div><br></div><div>I don&#39;t see why not.=C2=A0 That=
 was the intent -- request or otherwise invoke collection.</div><div>=C2=A0=
</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-l=
eft:1px #ccc solid;padding-left:1ex"><div lang=3D"EN-US" link=3D"blue" vlin=
k=3D"purple" class=3D"gmail_msg"><div class=3D"m_-244727941466904360WordSec=
tion1 gmail_msg"><p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:=
11.0pt;font-family:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><u c=
lass=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><u class=3D"gmail_msg=
"></u>=C2=A0<u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg">The first =E2=80=9Cev=
aluate=E2=80=9D (from the top) could be thought of as an applicability / st=
aleness evaluation. This drives what gaps in information and endpoints shou=
ld be targeted for
 collection.</span></p></div></div></blockquote><div><br></div><div>Yes, th=
at was the intent.=C2=A0 Evaluate what we can with available on-hand inform=
ation.</div><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div lang=3D"EN=
-US" link=3D"blue" vlink=3D"purple" class=3D"gmail_msg"><div class=3D"m_-24=
4727941466904360WordSection1 gmail_msg"><p class=3D"MsoNormal gmail_msg"><s=
pan style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif" c=
lass=3D"gmail_msg"><u class=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></=
span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><u class=3D"gmail_msg=
"></u>=C2=A0<u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg">The second =E2=80=9C(=
re)evaluate=E2=80=9D is the actual posture evaluation we are working to sup=
port. Right?</span></p></div></div></blockquote><div><br></div><div>Yep, th=
at&#39;s my take.</div><div>=C2=A0</div><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div=
 lang=3D"EN-US" link=3D"blue" vlink=3D"purple" class=3D"gmail_msg"><div cla=
ss=3D"m_-244727941466904360WordSection1 gmail_msg"><p class=3D"MsoNormal gm=
ail_msg"><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,sa=
ns-serif" class=3D"gmail_msg"><u class=3D"gmail_msg"></u><u class=3D"gmail_=
msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><u class=3D"gmail_msg=
"></u>=C2=A0<u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg">Regards,<u class=3D"g=
mail_msg"></u><u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg">Dave<u class=3D"gmail=
_msg"></u><u class=3D"gmail_msg"></u></span></p>
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-famil=
y:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><u class=3D"gmail_msg=
"></u>=C2=A0<u class=3D"gmail_msg"></u></span></p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt" class=3D"gmail_msg">
<div class=3D"gmail_msg">
<div style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in =
0in 0in" class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><b class=3D"gmail_msg"><span style=3D"font=
-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif" class=3D"gmail_msg=
">From:</span></b><span style=3D"font-size:11.0pt;font-family:&quot;Calibri=
&quot;,sans-serif" class=3D"gmail_msg"> sacm [mailto:<a href=3D"mailto:sacm=
-bounces@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm-bounces@ietf.=
org</a>]
<b class=3D"gmail_msg">On Behalf Of </b>Bill Munyan<br class=3D"gmail_msg">
<b class=3D"gmail_msg">Sent:</b> Thursday, February 02, 2017 12:57 PM<br cl=
ass=3D"gmail_msg">
<b class=3D"gmail_msg">To:</b> Adam Montville &lt;<a href=3D"mailto:adam.w.=
montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville=
@gmail.com</a>&gt;<br class=3D"gmail_msg">
<b class=3D"gmail_msg">Cc:</b> Henk Birkholz &lt;<a href=3D"mailto:henk.bir=
kholz@sit.fraunhofer.de" class=3D"gmail_msg" target=3D"_blank">henk.birkhol=
z@sit.fraunhofer.de</a>&gt;; <a href=3D"mailto:sacm@ietf.org" class=3D"gmai=
l_msg" target=3D"_blank">sacm@ietf.org</a></span></p></div></div></div></di=
v></div><div lang=3D"EN-US" link=3D"blue" vlink=3D"purple" class=3D"gmail_m=
sg"><div class=3D"m_-244727941466904360WordSection1 gmail_msg"><div style=
=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt" cla=
ss=3D"gmail_msg"><div class=3D"gmail_msg"><div style=3D"border:none;border-=
top:solid #e1e1e1 1.0pt;padding:3.0pt 0in 0in 0in" class=3D"gmail_msg"><p c=
lass=3D"MsoNormal gmail_msg"><span style=3D"font-size:11.0pt;font-family:&q=
uot;Calibri&quot;,sans-serif" class=3D"gmail_msg"><br class=3D"gmail_msg">
<b class=3D"gmail_msg">Subject:</b> Re: [sacm] Notes on Vulnerability Scena=
rio Working Session<u class=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></=
span></p></div></div></div></div></div><div lang=3D"EN-US" link=3D"blue" vl=
ink=3D"purple" class=3D"gmail_msg"><div class=3D"m_-244727941466904360WordS=
ection1 gmail_msg"><div style=3D"border:none;border-left:solid blue 1.5pt;p=
adding:0in 0in 0in 4.0pt" class=3D"gmail_msg"><div class=3D"gmail_msg"><div=
 style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in 0in =
0in" class=3D"gmail_msg"><p class=3D"MsoNormal gmail_msg"><span style=3D"fo=
nt-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif" class=3D"gmail_m=
sg"></span></p>
</div>
</div>
<p class=3D"MsoNormal gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u class=
=3D"gmail_msg"></u></p>
<div class=3D"gmail_msg">
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-family:&quot;Verdana&q=
uot;,sans-serif" class=3D"gmail_msg">Is it worth noting in the diagram (if =
not, I think it needs to be noted somewhere nonetheless) that the steps of =
&quot;get endpoints&quot; and subsequent &quot;evaluate&quot; should be mak=
ing some determination
 of whether or not to collect for an endpoint?=C2=A0 For example, if an end=
point has no assessment results or the assessment results are considered &q=
uot;stale&quot;, then the collection step would take place.=C2=A0 I underst=
and that could be too much detail for the scope of the
 diagram, but I just wanted to note it somewhere.<u class=3D"gmail_msg"></u=
><u class=3D"gmail_msg"></u></span></p>
</div>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-family:&quot;Verdana&q=
uot;,sans-serif" class=3D"gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u cl=
ass=3D"gmail_msg"></u></span></p>
</div>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-family:&quot;Verdana&q=
uot;,sans-serif" class=3D"gmail_msg">Cheers,=C2=A0<u class=3D"gmail_msg"></=
u><u class=3D"gmail_msg"></u></span></p>
</div>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-family:&quot;Verdana&q=
uot;,sans-serif" class=3D"gmail_msg">-Bill M.<u class=3D"gmail_msg"></u><u =
class=3D"gmail_msg"></u></span></p>
</div>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"font-family:&quot;Verdana&q=
uot;,sans-serif" class=3D"gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u cl=
ass=3D"gmail_msg"></u></span></p>
</div>
</div></div></div></div><div lang=3D"EN-US" link=3D"blue" vlink=3D"purple" =
class=3D"gmail_msg"><div class=3D"m_-244727941466904360WordSection1 gmail_m=
sg"><div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt" class=3D"gmail_msg">
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u class=
=3D"gmail_msg"></u></p>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg">On Thu, Feb 2, 2017 at 12:44 PM, Adam Mont=
ville &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg"=
 target=3D"_blank">adam.w.montville@gmail.com</a>&gt; wrote:<u class=3D"gma=
il_msg"></u><u class=3D"gmail_msg"></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class=3D"gmail_msg">
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg">Thanks for the feedback!=C2=A0 I&#39;ve at=
tached a modified version of the diagram that collapses the endpoint and as=
sessment result repositories (by keeping the endpoint repository).=C2=A0 Wh=
ere would you propose we focus on enhancing the diagram?=C2=A0
 Remember that it&#39;s a sequence diagram, which might do well with some m=
ore specific details captured in text or a different form of diagram.<u cla=
ss=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></p>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u class=
=3D"gmail_msg"></u></p>
</div>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg">What do folks think about using one or mor=
e OVAL definitions as a starting point?<u class=3D"gmail_msg"></u><u class=
=3D"gmail_msg"></u></p>
</div>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"color:#888888" class=3D"gma=
il_msg"><u class=3D"gmail_msg"></u>=C2=A0<u class=3D"gmail_msg"></u></span>=
</p>
</div>
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><span style=3D"color:#888888" class=3D"gma=
il_msg">Adam<u class=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></span></=
p>
</div>
<div class=3D"gmail_msg">
<div class=3D"gmail_msg">
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u class=
=3D"gmail_msg"></u></p>
</div>
<p class=3D"MsoNormal gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u class=
=3D"gmail_msg"></u></p>
<div class=3D"gmail_msg">
<div class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg">On Thu, Feb 2, 2017 at 10:53 AM Henk Birkh=
olz &lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D"gmail_m=
sg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a>&gt; wrote:<u clas=
s=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></p>
</div>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in" class=3D"gmail_msg">
<p class=3D"MsoNormal gmail_msg">## A Few Comments<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
* I agree that the diagram pretty much captures a &quot;one time snapshot&q=
uot;.<br class=3D"gmail_msg">
* Collapsing the highlighted components seems to be a feasible idea.<br cla=
ss=3D"gmail_msg">
* I agree that the diagram could be implemented given an appropriate set<br=
 class=3D"gmail_msg">
of initial data.<br class=3D"gmail_msg">
* I suppose there is the risk that one has to scrap everything<br class=3D"=
gmail_msg">
implemented when we start trying to make it a continuous process.<br class=
=3D"gmail_msg">
* I&#39;d recommend to start with a generic block of PoC code that provides=
<br class=3D"gmail_msg">
the functions of a SACM component to get input and create output (maybe<br =
class=3D"gmail_msg">
using dbus, chained event-loops, blocking waits on fifos, or IP over<br cla=
ss=3D"gmail_msg">
loopback? A better coder than me should bash these suggestions).<br class=
=3D"gmail_msg">
<br class=3D"gmail_msg">
## One, Two, or Three Tasks<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
* Creating component code that can create the (downstream?) flow of<br clas=
s=3D"gmail_msg">
information is urgent and important, I think.<br class=3D"gmail_msg">
* Enhancing the diagram to represent the continuous cycle with at least<br =
class=3D"gmail_msg">
one trigger (as illustrated by Bill; new software, new VDI, new<br class=3D=
"gmail_msg">
endpoints, stale results, etc.) is important, but not as urgent. It<br clas=
s=3D"gmail_msg">
might save time though by reducing the afore mentioned risk to shoot<br cla=
ss=3D"gmail_msg">
your self in the foot by creating a too specific proof of concept of the<br=
 class=3D"gmail_msg">
one time snapshot approach, I think.<br class=3D"gmail_msg">
* Selecting a set of initial data derived from OVAL to be used in the<br cl=
ass=3D"gmail_msg">
one shot snapshot seems to be a feasible approach to me, but I am not<br cl=
ass=3D"gmail_msg">
sure how the group thinks about that.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Does that assessment represent the general opinion, or is that just mine?<b=
r class=3D"gmail_msg">
<br class=3D"gmail_msg">
Viele Gr=C3=BC=C3=9Fe,<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Henk<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
On 02/02/2017 05:28 PM, Adam Montville wrote:<br class=3D"gmail_msg">
&gt; Hi Everyone.=C2=A0 A few of us were able to make the vulnerability sce=
nario<br class=3D"gmail_msg">
&gt; call today and I think we had a good, though at times spirited,<br cla=
ss=3D"gmail_msg">
&gt; discussion.=C2=A0 We did record the meeting, which is available at [1]=
.=C2=A0 We<br class=3D"gmail_msg">
&gt; discussed the attached (annotated with some meeting notes) UML-ish<br =
class=3D"gmail_msg">
&gt; sequence diagram.=C2=A0 I had created that diagram to start a conversa=
tion<br class=3D"gmail_msg">
&gt; (mission accomplished on that front I think) -- a conversation that<br=
 class=3D"gmail_msg">
&gt; would lead us toward identifying the discrete components, interfaces,<=
br class=3D"gmail_msg">
&gt; and information required to be sent over those interfaces.=C2=A0 The U=
ML-ish<br class=3D"gmail_msg">
&gt; diagram represents a *single* flow through the system -- a &quot;one-t=
ime&quot;<br class=3D"gmail_msg">
&gt; flow through the system.=C2=A0 It ignores, for the time being, the con=
tinuous<br class=3D"gmail_msg">
&gt; aspect of our charter in favor of getting started with the basics.=C2=
=A0 Once<br class=3D"gmail_msg">
&gt; we have a good understanding of the basics -- the components,<br class=
=3D"gmail_msg">
&gt; interfaces, and information required -- we can start look at a<br clas=
s=3D"gmail_msg">
&gt; continuous monitoring sequence (which could be represented as a distin=
ct<br class=3D"gmail_msg">
&gt; diagram) to determine what more we need.=C2=A0 Then, I think, we can s=
tart<br class=3D"gmail_msg">
&gt; drafting solutions.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; One of the first issues is that we need to figure out if the component=
s<br class=3D"gmail_msg">
&gt; in the base flow are accurate.=C2=A0 The main suggestion we&#39;ve tos=
sed around<br class=3D"gmail_msg">
&gt; so far is to combine the Endpoint Repository with the Assessment Resul=
t<br class=3D"gmail_msg">
&gt; Repository.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; We talked briefly about what interface we could use for the VDD<br cla=
ss=3D"gmail_msg">
&gt; Repository, and naturally ROLIE came up as an option.<br class=3D"gmai=
l_msg">
&gt;<br class=3D"gmail_msg">
&gt; We talked a little bit about the first &quot;get endpoints&quot; opera=
tion between<br class=3D"gmail_msg">
&gt; the Vulnerability Assessor and the Endpoint Repository -- specifically=
<br class=3D"gmail_msg">
&gt; about whether we should represent on this sequence diagram that<br cla=
ss=3D"gmail_msg">
&gt; information supporting a judgement of &quot;stale&quot; would be neede=
d.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; We left open the time when we would next meet, favoring to work that o=
ut<br class=3D"gmail_msg">
&gt; on-list.=C2=A0 Next week is TCG, so that may be difficult; the followi=
ng week<br class=3D"gmail_msg">
&gt; is RSA, so that may be difficult.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; For those who were in attendance today, please add to this note with<b=
r class=3D"gmail_msg">
&gt; your comments/corrections.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; Kind regards,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; [1] <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHp=
VR0tMd1E" class=3D"gmail_msg" target=3D"_blank">
https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br clas=
s=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montville<br class=3D"gmail_msg"=
>
&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" =
target=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto:<a href=3D"mail=
to:adam.w.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w=
.montville@gmail.com</a>&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a friendly reminder that we=
 are planning to meet<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the same time (2/2 @ 10am Ea=
stern/3pm UTC)<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting room at <a href=3D"https:/=
/ietf.webex.com/meet/sacm" class=3D"gmail_msg" target=3D"_blank">
https://ietf.webex.com/meet/sacm</a>.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:35 AM Adam Montville<br =
class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montville@gmail.com" c=
lass=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &lt;mai=
lto:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" targe=
t=3D"_blank">adam.w.montville@gmail.com</a>&gt;&gt; wrote:<br class=3D"gmai=
l_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few of us met informally tod=
ay to discuss the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability scenario in some more d=
etail with the goal of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining the narrow focus on a vul=
nerability assessment slice<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our notional environment.=C2=
=A0 We are tending to look at<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major components as black boxes with =
interfaces and data format<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations, and we are not necessar=
ily concerned with how<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those components do things internally=
/behind the scenes.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting was recorded (you can fin=
d it with today&#39;s date at<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 The topic of discussion w=
as primarily in the &quot;phase 1&quot;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what Danny sent to the list n=
ot very long ago [2], and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a *starting point* diagra=
m [3].<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who met today are (roughly)=
 agreed on the six main<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;components&quot; represented in=
 that diagram, but also see that we<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some work ahead.=C2=A0 Specifica=
lly, we quickly recognized that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the assumptions the vulnerabi=
lity draft makes may be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions we cannot afford to make =
and need to include in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it would be a good idea to=
 have another informal<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in a couple of weeks (Febr=
uary 2) at the same time<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern / 3pm UTC), using the s=
ame WebEx [4].=C2=A0 =C2=A0At that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we intend to roll through the vu=
lnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assumptions in an effort to =
determine which ones can be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assumptions and which ones ca=
nnot.=C2=A0 Then we&#39;ll take<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look at the diagram and work =
on its next version.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Danny, Stephen, and Jerome =
for joining and contributing!<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" class=3D"gmail_msg" target=3D"_b=
lank">
https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br clas=
s=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2] <a href=3D"https://mailarchive.ie=
tf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM" class=3D"gmail_msg" targe=
t=3D"_blank">
https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3] <a href=3D"https://drive.google.c=
om/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc" class=3D"gmail_msg" target=3D"_b=
lank">
https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><br clas=
s=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=3D"https://ietf.webex.com=
/meet/sacm" class=3D"gmail_msg" target=3D"_blank">https://ietf.webex.com/me=
et/sacm</a><br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; _______________________________________________<br class=3D"gmail_msg"=
>
&gt; sacm mailing list<br class=3D"gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank"=
>sacm@ietf.org</a><br class=3D"gmail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" class=3D"gmail_=
msg" target=3D"_blank">https://www.ietf.org/mailman/listinfo/sacm</a><br cl=
ass=3D"gmail_msg">
&gt;<u class=3D"gmail_msg"></u><u class=3D"gmail_msg"></u></p>
</blockquote>
</div>
</div>
</div>
</div>
<p class=3D"MsoNormal gmail_msg" style=3D"margin-bottom:12.0pt"><br class=
=3D"gmail_msg">
_______________________________________________<br class=3D"gmail_msg">
sacm mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm=
@ietf.org</a><br class=3D"gmail_msg">
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" class=3D"gmail_msg" =
target=3D"_blank">https://www.ietf.org/mailman/listinfo/sacm</a><u class=3D=
"gmail_msg"></u><u class=3D"gmail_msg"></u></p>
</blockquote>
</div>
<p class=3D"MsoNormal gmail_msg"><u class=3D"gmail_msg"></u>=C2=A0<u class=
=3D"gmail_msg"></u></p>
</div>
</div></div></div></blockquote></div></div>

--001a1141a48c32ed91054790df7f--


From nobody Thu Feb  2 11:21:31 2017
Return-Path: <carl-heinz.genzel@hs-bremen.de>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 457D612947D for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 11:21:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.1
X-Spam-Level: 
X-Spam-Status: No, score=-5.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-3.199, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mvGF3vZB3mtt for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 11:21:27 -0800 (PST)
Received: from fmail2.hs-bremen.de (fmail2.hs-bremen.de [IPv6:2001:638:703:2::15]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3D21F1293E1 for <sacm@ietf.org>; Thu,  2 Feb 2017 11:21:26 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by fmail2.hs-bremen.de (Postfix) with ESMTP id B9722278AC for <sacm@ietf.org>; Thu,  2 Feb 2017 20:21:24 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at fmail2.hs-bremen.de
Received: from fmail2.hs-bremen.de ([127.0.0.1]) by localhost (fmail2.hs-bremen.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QYWGzR8ReDqd for <sacm@ietf.org>; Thu,  2 Feb 2017 20:21:23 +0100 (CET)
Received: from mail.hs-bremen.de (mail.hs-bremen.de [194.94.24.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.hs-bremen.de", Issuer "Hochschule Bremen CA 1" (verified OK)) by fmail2.hs-bremen.de (Postfix) with ESMTPS id E0F092789B for <sacm@ietf.org>; Thu,  2 Feb 2017 20:21:23 +0100 (CET)
Received: from localhost (localhost [127.0.0.1]) by mail.hs-bremen.de (Postfix) with ESMTP id CDD9C316F7 for <sacm@ietf.org>; Thu,  2 Feb 2017 20:21:23 +0100 (CET)
X-Virus-Scanned: by amavisd-new at mail.hs-bremen.de
Received: from mail.hs-bremen.de ([127.0.0.1]) by localhost (mail.hs-bremen.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d3ubfva2DBJP for <sacm@ietf.org>; Thu,  2 Feb 2017 20:21:22 +0100 (CET)
Received: from [172.24.16.90] (x4e336733.dyn.telefonica.de [78.51.103.51]) (Authenticated sender: cagenzel) by mail.hs-bremen.de (Postfix) with ESMTPSA id A9C2C311B7 for <sacm@ietf.org>; Thu,  2 Feb 2017 20:21:22 +0100 (CET)
To: sacm@ietf.org
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com>
From: Carl-Heinz Genzel <carl-heinz.genzel@hs-bremen.de>
Message-ID: <48e46164-e532-7002-2738-b25c4c36d6bf@hs-bremen.de>
Date: Thu, 2 Feb 2017 20:21:22 +0100
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/QD6xbd6BdKwtTeZ3uvqGkmbvQu4>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 19:21:30 -0000

Hello Everybody,

you all may have seen my name in the WebEx today. However I didn't
introduce myself yet. I apologize for that. Please don't hold that
against me. I just didn't want to hinder the discussion, since I am very
new to this work group and the IETF work in general.

My name is Carl-Heinz Genzel and I am a research assistant at the
University of Applied Sciences Bremen (Germany) usually working on
topics around security, smart grids, and trusted computing.

I find the SACM WG very interesting, however I am not certain at the
moment about how I'm be able to contribute. However I enjoyed your
discussion to day.

There may be one thing, I like to comment about the diagram. I hope I do
understand the SACM drafts as well as the diagram correctly, and will
not sound absurd.

For me it seems that a direct call from the vulnerability assessor to
the collector would raise a question about separation of concerns, since
the endpoint repository is the central component for endpoint
information. In this regard, should not the endpoint repository call
collect as consequence of the get endpoints call instead of a direct
call to the collector, if information is stale or missing?

Best Regards,
Carl-Heinz Genzel







Am 02.02.2017 um 18:44 schrieb Adam Montville:
> Thanks for the feedback!  I've attached a modified version of the
> diagram that collapses the endpoint and assessment result repositories
> (by keeping the endpoint repository).  Where would you propose we focus
> on enhancing the diagram?  Remember that it's a sequence diagram, which
> might do well with some more specific details captured in text or a
> different form of diagram.
> 
> What do folks think about using one or more OVAL definitions as a
> starting point?
> 
> Adam
> 
> 
> On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz
> <henk.birkholz@sit.fraunhofer.de
> <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
> 
>     ## A Few Comments
> 
>     * I agree that the diagram pretty much captures a "one time snapshot".
>     * Collapsing the highlighted components seems to be a feasible idea.
>     * I agree that the diagram could be implemented given an appropriate set
>     of initial data.
>     * I suppose there is the risk that one has to scrap everything
>     implemented when we start trying to make it a continuous process.
>     * I'd recommend to start with a generic block of PoC code that provides
>     the functions of a SACM component to get input and create output (maybe
>     using dbus, chained event-loops, blocking waits on fifos, or IP over
>     loopback? A better coder than me should bash these suggestions).
> 
>     ## One, Two, or Three Tasks
> 
>     * Creating component code that can create the (downstream?) flow of
>     information is urgent and important, I think.
>     * Enhancing the diagram to represent the continuous cycle with at least
>     one trigger (as illustrated by Bill; new software, new VDI, new
>     endpoints, stale results, etc.) is important, but not as urgent. It
>     might save time though by reducing the afore mentioned risk to shoot
>     your self in the foot by creating a too specific proof of concept of the
>     one time snapshot approach, I think.
>     * Selecting a set of initial data derived from OVAL to be used in the
>     one shot snapshot seems to be a feasible approach to me, but I am not
>     sure how the group thinks about that.
> 
>     Does that assessment represent the general opinion, or is that just
>     mine?
> 
>     Viele Grüße,
> 
>     Henk
> 
>     On 02/02/2017 05:28 PM, Adam Montville wrote:
>     > Hi Everyone.  A few of us were able to make the vulnerability scenario
>     > call today and I think we had a good, though at times spirited,
>     > discussion.  We did record the meeting, which is available at [1].  We
>     > discussed the attached (annotated with some meeting notes) UML-ish
>     > sequence diagram.  I had created that diagram to start a conversation
>     > (mission accomplished on that front I think) -- a conversation that
>     > would lead us toward identifying the discrete components, interfaces,
>     > and information required to be sent over those interfaces.  The
>     UML-ish
>     > diagram represents a *single* flow through the system -- a "one-time"
>     > flow through the system.  It ignores, for the time being, the
>     continuous
>     > aspect of our charter in favor of getting started with the
>     basics.  Once
>     > we have a good understanding of the basics -- the components,
>     > interfaces, and information required -- we can start look at a
>     > continuous monitoring sequence (which could be represented as a
>     distinct
>     > diagram) to determine what more we need.  Then, I think, we can start
>     > drafting solutions.
>     >
>     > One of the first issues is that we need to figure out if the
>     components
>     > in the base flow are accurate.  The main suggestion we've tossed
>     around
>     > so far is to combine the Endpoint Repository with the Assessment
>     Result
>     > Repository.
>     >
>     > We talked briefly about what interface we could use for the VDD
>     > Repository, and naturally ROLIE came up as an option.
>     >
>     > We talked a little bit about the first "get endpoints" operation
>     between
>     > the Vulnerability Assessor and the Endpoint Repository -- specifically
>     > about whether we should represent on this sequence diagram that
>     > information supporting a judgement of "stale" would be needed.
>     >
>     > We left open the time when we would next meet, favoring to work
>     that out
>     > on-list.  Next week is TCG, so that may be difficult; the
>     following week
>     > is RSA, so that may be difficult.
>     >
>     > For those who were in attendance today, please add to this note with
>     > your comments/corrections.
>     >
>     > Kind regards,
>     >
>     > Adam
>     >
>     > [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >
>     > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >     Hi everyone.  Just a friendly reminder that we are planning to
>     meet
>     >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC)
>     >     using SACM's meeting room at https://ietf.webex.com/meet/sacm.
>     >
>     >     Kind regards,
>     >
>     >     Adam
>     >
>     >
>     >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>     >     <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >         Hello. A few of us met informally today to discuss the
>     >         vulnerability scenario in some more detail with the goal of
>     >         maintaining the narrow focus on a vulnerability assessment
>     slice
>     >         through our notional environment.  We are tending to look at
>     >         major components as black boxes with interfaces and data
>     format
>     >         expectations, and we are not necessarily concerned with how
>     >         those components do things internally/behind the scenes.
>     >
>     >         The meeting was recorded (you can find it with today's date at
>     >         [1]).  The topic of discussion was primarily in the "phase 1"
>     >         area of what Danny sent to the list not very long ago [2], and
>     >         resulted in a *starting point* diagram [3].
>     >
>     >         The group who met today are (roughly) agreed on the six main
>     >         "components" represented in that diagram, but also see that we
>     >         have some work ahead.  Specifically, we quickly recognized
>     that
>     >         some of the assumptions the vulnerability draft makes may be
>     >         assumptions we cannot afford to make and need to include
>     in the
>     >         exploration.
>     >
>     >         We thought it would be a good idea to have another informal
>     >         discussion in a couple of weeks (February 2) at the same time
>     >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At that
>     >         time we intend to roll through the vulnerability assessment
>     >         scenario assumptions in an effort to determine which ones
>     can be
>     >         left as assumptions and which ones cannot.  Then we'll take
>     >         another look at the diagram and work on its next version.
>     >
>     >         Stay tuned.
>     >
>     >         Thanks to Danny, Stephen, and Jerome for joining and
>     contributing!
>     >
>     >         Kind regards,
>     >
>     >         Adam
>     >
>     >
>     >         [1]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >         [2]
>     https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
>     >         [3]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>     >         [4] https://ietf.webex.com/meet/sacm
>     >
>     >
>     >
>     > _______________________________________________
>     > sacm mailing list
>     > sacm@ietf.org <mailto:sacm@ietf.org>
>     > https://www.ietf.org/mailman/listinfo/sacm
>     >
> 
> 
> 
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
> 

-- 
______________________________________________________________________________________

Carl-Heinz Genzel
Wissenschaftlicher Mitarbeiter
Rechnernetze / Informationssicherheit
Institut für Informatik und Automation
Hochschule Bremen / University of Applied Sciences
Flughafenallee 10, 28199 Bremen, Germany
tel.:  +49 421 5905 5442
mobil: +49 179 1636844
email: carl-heinz.genzel@hs-bremen.de
___________________________________________________________________________


From nobody Thu Feb  2 12:06:06 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC0111294E6 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 12:06:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level: 
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WG9CutW7nVor for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 12:06:02 -0800 (PST)
Received: from mail-oi0-x230.google.com (mail-oi0-x230.google.com [IPv6:2607:f8b0:4003:c06::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1C885129552 for <sacm@ietf.org>; Thu,  2 Feb 2017 12:06:02 -0800 (PST)
Received: by mail-oi0-x230.google.com with SMTP id w204so15980907oiw.0 for <sacm@ietf.org>; Thu, 02 Feb 2017 12:06:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to;  bh=xD34Wx8DW2c2Qnh2qQruovoxR+if1TtY+WsgcGygtIc=; b=U6DtN4kUIVMK11SDFTGJ8YSvD3KHXZ08buihmCyCg5GtTdf09XTATqIJUp/95EiILq Yb1G877r4TMMrfIq+t8Xst+1te68+ah1OYY8PfDwFQIyvUWcV161cBXv+f765fGGjZFL E7kBmnAs1Fhe0JPQE0yuG2e+z/BeA/FKgFLjHvGuEeWMUorj53aP0Hj5lSSJm0tubw4d 0erdSzsSuBEeu+bD1i6Ksp6XHaLsGGAmSBPZyIzxwFKBoPcnt5Ug5UXvpUjf7MtN9OKM 5/HyBOVKDFsVQ9nD580reK/iaH/w4CkcdZTglfe2zfwl1VR1tmPwvH8f49clFwSEnB+5 ZOfg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=xD34Wx8DW2c2Qnh2qQruovoxR+if1TtY+WsgcGygtIc=; b=gvaDSZtr4IRm7SI3v7WhRAQICh31MoEtX/1S578ZVTEXQsVkkJTVwYZHwwr9cOIoAf bmVhTakfyZnlD0+b8AHdkvx14e/lA4fX9v31Fi/j0XDZF7+JxWaPQuch8TMD4l5vdn0Q WoBqaSt3t4Dt2MMYw4SHpXbtH5qOjTx/snvtVJQvxyFQQFvf6snSR1qVwgVNdz6Z/lUR wAKLI3WbCTNbT29WeLimZ6tQL8hwcpxf72iPEVZ1Z5UZRq+cCnKV+laWn9rR8C6Q1GVt cvr1qaenb3hcSagOkYjhRwnPqtad2Xuwus8DGe8oNrYr+LFiYr/3+kRx6gZ8wP10uVQ3 tJww==
X-Gm-Message-State: AIkVDXK4nkf5UwSNjE65zqixrVHUUc6WRF28HTECkuEXFTnWySlVcLhOXLa63m9JbrMpT25T42dR/cfl+oYw+Q==
X-Received: by 10.202.74.213 with SMTP id x204mr5317876oia.51.1486065961199; Thu, 02 Feb 2017 12:06:01 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <48e46164-e532-7002-2738-b25c4c36d6bf@hs-bremen.de>
In-Reply-To: <48e46164-e532-7002-2738-b25c4c36d6bf@hs-bremen.de>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 20:05:50 +0000
Message-ID: <CACknUNU53bVXGeHNCfJDCUXDCErRczWvJooBZbd9p0mFEf9i+g@mail.gmail.com>
To: Carl-Heinz Genzel <carl-heinz.genzel@hs-bremen.de>, sacm@ietf.org
Content-Type: multipart/alternative; boundary=001a1134fbc0bafad4054791b182
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/y4yIJ0aRgiuHvUBOb_3tYFGarf8>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 20:06:05 -0000

--001a1134fbc0bafad4054791b182
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Thu, Feb 2, 2017 at 1:21 PM Carl-Heinz Genzel <
carl-heinz.genzel@hs-bremen.de> wrote:

> Hello Everybody,
>
> you all may have seen my name in the WebEx today. However I didn't
> introduce myself yet. I apologize for that. Please don't hold that
> against me. I just didn't want to hinder the discussion, since I am very
> new to this work group and the IETF work in general.
>
> My name is Carl-Heinz Genzel and I am a research assistant at the
> University of Applied Sciences Bremen (Germany) usually working on
> topics around security, smart grids, and trusted computing.
>

We're happy to have you here, thank you for joining.


>
> I find the SACM WG very interesting, however I am not certain at the
> moment about how I'm be able to contribute. However I enjoyed your
> discussion to day.
>
> There may be one thing, I like to comment about the diagram. I hope I do
> understand the SACM drafts as well as the diagram correctly, and will
> not sound absurd.
>
> For me it seems that a direct call from the vulnerability assessor to
> the collector would raise a question about separation of concerns, since
> the endpoint repository is the central component for endpoint
> information. In this regard, should not the endpoint repository call
> collect as consequence of the get endpoints call instead of a direct
> call to the collector, if information is stale or missing?
>

This seems reasonable.  I am interested in what others think about the
suggestion as well.

In practice today, many vulnerability assessors are themselves collectors.
Still, it seams feasible for the vulnerability assessor to react after
initial evaluation by telling the endpoint repository that it has not
enough information, which could then cause the endpoint repository to
trigger additional collection.

I am not sure it is written that way in our draft, which does not mean that
we can't change...




>
> Best Regards,
> Carl-Heinz Genzel
>
>
>
>
>
>
>
> Am 02.02.2017 um 18:44 schrieb Adam Montville:
> > Thanks for the feedback!  I've attached a modified version of the
> > diagram that collapses the endpoint and assessment result repositories
> > (by keeping the endpoint repository).  Where would you propose we focus
> > on enhancing the diagram?  Remember that it's a sequence diagram, which
> > might do well with some more specific details captured in text or a
> > different form of diagram.
> >
> > What do folks think about using one or more OVAL definitions as a
> > starting point?
> >
> > Adam
> >
> >
> > On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz
> > <henk.birkholz@sit.fraunhofer.de
> > <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
> >
> >     ## A Few Comments
> >
> >     * I agree that the diagram pretty much captures a "one time
> snapshot".
> >     * Collapsing the highlighted components seems to be a feasible idea=
.
> >     * I agree that the diagram could be implemented given an appropriat=
e
> set
> >     of initial data.
> >     * I suppose there is the risk that one has to scrap everything
> >     implemented when we start trying to make it a continuous process.
> >     * I'd recommend to start with a generic block of PoC code that
> provides
> >     the functions of a SACM component to get input and create output
> (maybe
> >     using dbus, chained event-loops, blocking waits on fifos, or IP ove=
r
> >     loopback? A better coder than me should bash these suggestions).
> >
> >     ## One, Two, or Three Tasks
> >
> >     * Creating component code that can create the (downstream?) flow of
> >     information is urgent and important, I think.
> >     * Enhancing the diagram to represent the continuous cycle with at
> least
> >     one trigger (as illustrated by Bill; new software, new VDI, new
> >     endpoints, stale results, etc.) is important, but not as urgent. It
> >     might save time though by reducing the afore mentioned risk to shoo=
t
> >     your self in the foot by creating a too specific proof of concept o=
f
> the
> >     one time snapshot approach, I think.
> >     * Selecting a set of initial data derived from OVAL to be used in t=
he
> >     one shot snapshot seems to be a feasible approach to me, but I am n=
ot
> >     sure how the group thinks about that.
> >
> >     Does that assessment represent the general opinion, or is that just
> >     mine?
> >
> >     Viele Gr=C3=BC=C3=9Fe,
> >
> >     Henk
> >
> >     On 02/02/2017 05:28 PM, Adam Montville wrote:
> >     > Hi Everyone.  A few of us were able to make the vulnerability
> scenario
> >     > call today and I think we had a good, though at times spirited,
> >     > discussion.  We did record the meeting, which is available at
> [1].  We
> >     > discussed the attached (annotated with some meeting notes) UML-is=
h
> >     > sequence diagram.  I had created that diagram to start a
> conversation
> >     > (mission accomplished on that front I think) -- a conversation th=
at
> >     > would lead us toward identifying the discrete components,
> interfaces,
> >     > and information required to be sent over those interfaces.  The
> >     UML-ish
> >     > diagram represents a *single* flow through the system -- a
> "one-time"
> >     > flow through the system.  It ignores, for the time being, the
> >     continuous
> >     > aspect of our charter in favor of getting started with the
> >     basics.  Once
> >     > we have a good understanding of the basics -- the components,
> >     > interfaces, and information required -- we can start look at a
> >     > continuous monitoring sequence (which could be represented as a
> >     distinct
> >     > diagram) to determine what more we need.  Then, I think, we can
> start
> >     > drafting solutions.
> >     >
> >     > One of the first issues is that we need to figure out if the
> >     components
> >     > in the base flow are accurate.  The main suggestion we've tossed
> >     around
> >     > so far is to combine the Endpoint Repository with the Assessment
> >     Result
> >     > Repository.
> >     >
> >     > We talked briefly about what interface we could use for the VDD
> >     > Repository, and naturally ROLIE came up as an option.
> >     >
> >     > We talked a little bit about the first "get endpoints" operation
> >     between
> >     > the Vulnerability Assessor and the Endpoint Repository --
> specifically
> >     > about whether we should represent on this sequence diagram that
> >     > information supporting a judgement of "stale" would be needed.
> >     >
> >     > We left open the time when we would next meet, favoring to work
> >     that out
> >     > on-list.  Next week is TCG, so that may be difficult; the
> >     following week
> >     > is RSA, so that may be difficult.
> >     >
> >     > For those who were in attendance today, please add to this note
> with
> >     > your comments/corrections.
> >     >
> >     > Kind regards,
> >     >
> >     > Adam
> >     >
> >     > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd=
1E
> >     >
> >     > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
> >     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
> >     <mailto:adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>>> wrote:
> >     >
> >     >     Hi everyone.  Just a friendly reminder that we are planning t=
o
> >     meet
> >     >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm
> UTC)
> >     >     using SACM's meeting room at https://ietf.webex.com/meet/sacm=
.
> >     >
> >     >     Kind regards,
> >     >
> >     >     Adam
> >     >
> >     >
> >     >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
> >     >     <adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>
> >     <mailto:adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>>> wrote:
> >     >
> >     >         Hello. A few of us met informally today to discuss the
> >     >         vulnerability scenario in some more detail with the goal =
of
> >     >         maintaining the narrow focus on a vulnerability assessmen=
t
> >     slice
> >     >         through our notional environment.  We are tending to look
> at
> >     >         major components as black boxes with interfaces and data
> >     format
> >     >         expectations, and we are not necessarily concerned with h=
ow
> >     >         those components do things internally/behind the scenes.
> >     >
> >     >         The meeting was recorded (you can find it with today's
> date at
> >     >         [1]).  The topic of discussion was primarily in the "phas=
e
> 1"
> >     >         area of what Danny sent to the list not very long ago [2]=
,
> and
> >     >         resulted in a *starting point* diagram [3].
> >     >
> >     >         The group who met today are (roughly) agreed on the six
> main
> >     >         "components" represented in that diagram, but also see
> that we
> >     >         have some work ahead.  Specifically, we quickly recognize=
d
> >     that
> >     >         some of the assumptions the vulnerability draft makes may
> be
> >     >         assumptions we cannot afford to make and need to include
> >     in the
> >     >         exploration.
> >     >
> >     >         We thought it would be a good idea to have another inform=
al
> >     >         discussion in a couple of weeks (February 2) at the same
> time
> >     >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At
> that
> >     >         time we intend to roll through the vulnerability assessme=
nt
> >     >         scenario assumptions in an effort to determine which ones
> >     can be
> >     >         left as assumptions and which ones cannot.  Then we'll ta=
ke
> >     >         another look at the diagram and work on its next version.
> >     >
> >     >         Stay tuned.
> >     >
> >     >         Thanks to Danny, Stephen, and Jerome for joining and
> >     contributing!
> >     >
> >     >         Kind regards,
> >     >
> >     >         Adam
> >     >
> >     >
> >     >         [1]
> >     https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >     >         [2]
> >
> https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> >     >         [3]
> >     https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> >     >         [4] https://ietf.webex.com/meet/sacm
> >     >
> >     >
> >     >
> >     > _______________________________________________
> >     > sacm mailing list
> >     > sacm@ietf.org <mailto:sacm@ietf.org>
> >     > https://www.ietf.org/mailman/listinfo/sacm
> >     >
> >
> >
> >
> > _______________________________________________
> > sacm mailing list
> > sacm@ietf.org
> > https://www.ietf.org/mailman/listinfo/sacm
> >
>
> --
>
> _________________________________________________________________________=
_____________
>
> Carl-Heinz Genzel
> Wissenschaftlicher Mitarbeiter
> Rechnernetze / Informationssicherheit
> Institut f=C3=BCr Informatik und Automation
> Hochschule Bremen / University of Applied Sciences
> Flughafenallee 10, 28199 Bremen, Germany
> tel.:  +49 421 5905 5442 <+49%20421%2059055442>
> mobil: +49 179 1636844 <+49%20179%201636844>
> email: carl-heinz.genzel@hs-bremen.de
> _________________________________________________________________________=
__
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>

--001a1134fbc0bafad4054791b182
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><br><div class=3D"gmail_quote"><div dir=3D"ltr">On Thu=
, Feb 2, 2017 at 1:21 PM Carl-Heinz Genzel &lt;<a href=3D"mailto:carl-heinz=
.genzel@hs-bremen.de">carl-heinz.genzel@hs-bremen.de</a>&gt; wrote:<br></di=
v><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:=
1px #ccc solid;padding-left:1ex">Hello Everybody,<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
you all may have seen my name in the WebEx today. However I didn&#39;t<br c=
lass=3D"gmail_msg">
introduce myself yet. I apologize for that. Please don&#39;t hold that<br c=
lass=3D"gmail_msg">
against me. I just didn&#39;t want to hinder the discussion, since I am ver=
y<br class=3D"gmail_msg">
new to this work group and the IETF work in general.<br class=3D"gmail_msg"=
>
<br class=3D"gmail_msg">
My name is Carl-Heinz Genzel and I am a research assistant at the<br class=
=3D"gmail_msg">
University of Applied Sciences Bremen (Germany) usually working on<br class=
=3D"gmail_msg">
topics around security, smart grids, and trusted computing.<br class=3D"gma=
il_msg"></blockquote><div><br></div><div>We&#39;re happy to have you here, =
thank you for joining.</div><div>=C2=A0</div><blockquote class=3D"gmail_quo=
te" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"=
>
<br class=3D"gmail_msg">
I find the SACM WG very interesting, however I am not certain at the<br cla=
ss=3D"gmail_msg">
moment about how I&#39;m be able to contribute. However I enjoyed your<br c=
lass=3D"gmail_msg">
discussion to day.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
There may be one thing, I like to comment about the diagram. I hope I do<br=
 class=3D"gmail_msg">
understand the SACM drafts as well as the diagram correctly, and will<br cl=
ass=3D"gmail_msg">
not sound absurd.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
For me it seems that a direct call from the vulnerability assessor to<br cl=
ass=3D"gmail_msg">
the collector would raise a question about separation of concerns, since<br=
 class=3D"gmail_msg">
the endpoint repository is the central component for endpoint<br class=3D"g=
mail_msg">
information. In this regard, should not the endpoint repository call<br cla=
ss=3D"gmail_msg">
collect as consequence of the get endpoints call instead of a direct<br cla=
ss=3D"gmail_msg">
call to the collector, if information is stale or missing?<br class=3D"gmai=
l_msg"></blockquote><div><br></div><div>This seems reasonable.=C2=A0 I am i=
nterested in what others think about the suggestion as well. =C2=A0</div><d=
iv><br></div><div>In practice today, many vulnerability assessors are thems=
elves collectors.=C2=A0 Still, it seams feasible for the vulnerability asse=
ssor to react after initial evaluation by telling the endpoint repository t=
hat it has not enough information, which could then cause the endpoint repo=
sitory to trigger additional collection.=C2=A0</div><div><br></div><div>I a=
m not sure it is written that way in our draft, which does not mean that we=
 can&#39;t change...</div><div><br></div><div><br></div><div>=C2=A0</div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px =
#ccc solid;padding-left:1ex">
<br class=3D"gmail_msg">
Best Regards,<br class=3D"gmail_msg">
Carl-Heinz Genzel<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Am 02.02.2017 um 18:44 schrieb Adam Montville:<br class=3D"gmail_msg">
&gt; Thanks for the feedback!=C2=A0 I&#39;ve attached a modified version of=
 the<br class=3D"gmail_msg">
&gt; diagram that collapses the endpoint and assessment result repositories=
<br class=3D"gmail_msg">
&gt; (by keeping the endpoint repository).=C2=A0 Where would you propose we=
 focus<br class=3D"gmail_msg">
&gt; on enhancing the diagram?=C2=A0 Remember that it&#39;s a sequence diag=
ram, which<br class=3D"gmail_msg">
&gt; might do well with some more specific details captured in text or a<br=
 class=3D"gmail_msg">
&gt; different form of diagram.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; What do folks think about using one or more OVAL definitions as a<br c=
lass=3D"gmail_msg">
&gt; starting point?<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz<br class=3D"gmail_msg">
&gt; &lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D"gmail_=
msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a><br class=3D"gmai=
l_msg">
&gt; &lt;mailto:<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D=
"gmail_msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a>&gt;&gt; w=
rote:<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0## A Few Comments<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I agree that the diagram pretty much captures a &=
quot;one time snapshot&quot;.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Collapsing the highlighted components seems to be=
 a feasible idea.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I agree that the diagram could be implemented giv=
en an appropriate set<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0of initial data.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I suppose there is the risk that one has to scrap=
 everything<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0implemented when we start trying to make it a conti=
nuous process.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I&#39;d recommend to start with a generic block o=
f PoC code that provides<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0the functions of a SACM component to get input and =
create output (maybe<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using dbus, chained event-loops, blocking waits on =
fifos, or IP over<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0loopback? A better coder than me should bash these =
suggestions).<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0## One, Two, or Three Tasks<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Creating component code that can create the (down=
stream?) flow of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0information is urgent and important, I think.<br cl=
ass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Enhancing the diagram to represent the continuous=
 cycle with at least<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one trigger (as illustrated by Bill; new software, =
new VDI, new<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0endpoints, stale results, etc.) is important, but n=
ot as urgent. It<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0might save time though by reducing the afore mentio=
ned risk to shoot<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0your self in the foot by creating a too specific pr=
oof of concept of the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one time snapshot approach, I think.<br class=3D"gm=
ail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Selecting a set of initial data derived from OVAL=
 to be used in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one shot snapshot seems to be a feasible approach t=
o me, but I am not<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0sure how the group thinks about that.<br class=3D"g=
mail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Does that assessment represent the general opinion,=
 or is that just<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0mine?<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Viele Gr=C3=BC=C3=9Fe,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Henk<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0On 02/02/2017 05:28 PM, Adam Montville wrote:<br cl=
ass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Hi Everyone.=C2=A0 A few of us were able to ma=
ke the vulnerability scenario<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; call today and I think we had a good, though a=
t times spirited,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; discussion.=C2=A0 We did record the meeting, w=
hich is available at [1].=C2=A0 We<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; discussed the attached (annotated with some me=
eting notes) UML-ish<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; sequence diagram.=C2=A0 I had created that dia=
gram to start a conversation<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; (mission accomplished on that front I think) -=
- a conversation that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; would lead us toward identifying the discrete =
components, interfaces,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; and information required to be sent over those=
 interfaces.=C2=A0 The<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0UML-ish<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; diagram represents a *single* flow through the=
 system -- a &quot;one-time&quot;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; flow through the system.=C2=A0 It ignores, for=
 the time being, the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0continuous<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; aspect of our charter in favor of getting star=
ted with the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0basics.=C2=A0 Once<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; we have a good understanding of the basics -- =
the components,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; interfaces, and information required -- we can=
 start look at a<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; continuous monitoring sequence (which could be=
 represented as a<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0distinct<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; diagram) to determine what more we need.=C2=A0=
 Then, I think, we can start<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; drafting solutions.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; One of the first issues is that we need to fig=
ure out if the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0components<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; in the base flow are accurate.=C2=A0 The main =
suggestion we&#39;ve tossed<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0around<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; so far is to combine the Endpoint Repository w=
ith the Assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Result<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Repository.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We talked briefly about what interface we coul=
d use for the VDD<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Repository, and naturally ROLIE came up as an =
option.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We talked a little bit about the first &quot;g=
et endpoints&quot; operation<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0between<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; the Vulnerability Assessor and the Endpoint Re=
pository -- specifically<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; about whether we should represent on this sequ=
ence diagram that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; information supporting a judgement of &quot;st=
ale&quot; would be needed.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We left open the time when we would next meet,=
 favoring to work<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0that out<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; on-list.=C2=A0 Next week is TCG, so that may b=
e difficult; the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0following week<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; is RSA, so that may be difficult.<br class=3D"=
gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; For those who were in attendance today, please=
 add to this note with<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; your comments/corrections.<br class=3D"gmail_m=
sg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Kind regards,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Adam<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; [1] <a href=3D"https://drive.google.com/open?i=
d=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" ta=
rget=3D"_blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0t=
Md1E</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montvill=
e<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.c=
om" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &l=
t;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" =
target=3D"_blank">adam.w.montville@gmail.com</a>&gt;<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a f=
riendly reminder that we are planning to<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0meet<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the =
same time (2/2 @ 10am Eastern/3pm UTC)<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting ro=
om at <a href=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=
=3D"gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/sacm</a>.<br c=
lass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"g=
mail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:=
35 AM Adam Montville<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.=
w.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montvil=
le@gmail.com</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few =
of us met informally today to discuss the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability=
 scenario in some more detail with the goal of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining t=
he narrow focus on a vulnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0slice<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our n=
otional environment.=C2=A0 We are tending to look at<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major compone=
nts as black boxes with interfaces and data<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0format<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations,=
 and we are not necessarily concerned with how<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those compone=
nts do things internally/behind the scenes.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting w=
as recorded (you can find it with today&#39;s date at<br class=3D"gmail_msg=
">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 T=
he topic of discussion was primarily in the &quot;phase 1&quot;<br class=3D=
"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what =
Danny sent to the list not very long ago [2], and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a=
 *starting point* diagram [3].<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who=
 met today are (roughly) agreed on the six main<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;compone=
nts&quot; represented in that diagram, but also see that we<br class=3D"gma=
il_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some wor=
k ahead.=C2=A0 Specifically, we quickly recognized<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the a=
ssumptions the vulnerability draft makes may be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions w=
e cannot afford to make and need to include<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it=
 would be a good idea to have another informal<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in=
 a couple of weeks (February 2) at the same time<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern=
 / 3pm UTC), using the same WebEx [4].=C2=A0 =C2=A0At that<br class=3D"gmai=
l_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we inten=
d to roll through the vulnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assu=
mptions in an effort to determine which ones<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0can be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assum=
ptions and which ones cannot.=C2=A0 Then we&#39;ll take<br class=3D"gmail_m=
sg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look =
at the diagram and work on its next version.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<b=
r class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Dan=
ny, Stephen, and Jerome for joining and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0contributing!<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,=
<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf=
9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_=
blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://mailarchive.ietf.org/arch/msg/sa=
cm/_LiKlyvAws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=3D"gmail_msg" targ=
et=3D"_blank">https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5=
NSU58MXDM</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf=
9Un5FdCbMU5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_=
blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=
=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"gmail_msg=
" target=3D"_blank">https://ietf.webex.com/meet/sacm</a><br class=3D"gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; ______________________________________________=
_<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; sacm mailing list<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmai=
l_msg" target=3D"_blank">sacm@ietf.org</a> &lt;mailto:<a href=3D"mailto:sac=
m@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm@ietf.org</a>&gt;<br =
class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; <a href=3D"https://www.ietf.org/mailman/listin=
fo/sacm" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">https://w=
ww.ietf.org/mailman/listinfo/sacm</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; _______________________________________________<br class=3D"gmail_msg"=
>
&gt; sacm mailing list<br class=3D"gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank"=
>sacm@ietf.org</a><br class=3D"gmail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferr=
er" class=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/list=
info/sacm</a><br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
--<br class=3D"gmail_msg">
___________________________________________________________________________=
___________<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Carl-Heinz Genzel<br class=3D"gmail_msg">
Wissenschaftlicher Mitarbeiter<br class=3D"gmail_msg">
Rechnernetze / Informationssicherheit<br class=3D"gmail_msg">
Institut f=C3=BCr Informatik und Automation<br class=3D"gmail_msg">
Hochschule Bremen / University of Applied Sciences<br class=3D"gmail_msg">
Flughafenallee 10, 28199 Bremen, Germany<br class=3D"gmail_msg">
tel.:=C2=A0 <a href=3D"tel:+49%20421%2059055442" value=3D"+4942159055442" c=
lass=3D"gmail_msg" target=3D"_blank">+49 421 5905 5442</a><br class=3D"gmai=
l_msg">
mobil: <a href=3D"tel:+49%20179%201636844" value=3D"+491791636844" class=3D=
"gmail_msg" target=3D"_blank">+49 179 1636844</a><br class=3D"gmail_msg">
email: <a href=3D"mailto:carl-heinz.genzel@hs-bremen.de" class=3D"gmail_msg=
" target=3D"_blank">carl-heinz.genzel@hs-bremen.de</a><br class=3D"gmail_ms=
g">
___________________________________________________________________________=
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
_______________________________________________<br class=3D"gmail_msg">
sacm mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm=
@ietf.org</a><br class=3D"gmail_msg">
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" c=
lass=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/listinfo/=
sacm</a><br class=3D"gmail_msg">
</blockquote></div></div>

--001a1134fbc0bafad4054791b182--


From nobody Thu Feb  2 13:12:11 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 57A7212952D for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 13:12:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m2u6qWAWryJG for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 13:12:07 -0800 (PST)
Received: from mail-ot0-x22a.google.com (mail-ot0-x22a.google.com [IPv6:2607:f8b0:4003:c0f::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9D9B51293E4 for <sacm@ietf.org>; Thu,  2 Feb 2017 13:12:07 -0800 (PST)
Received: by mail-ot0-x22a.google.com with SMTP id f9so159697otd.1 for <sacm@ietf.org>; Thu, 02 Feb 2017 13:12:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to;  bh=jfyPQMz0ArvxlbmiZK75s4Yr3bHUAf0slQ2N8mEO8Uk=; b=K3rC7aZH7crJpLb3woMhBM+kZhUvEG0ZdOZz3oLuVRchl5QEgHHxtlzFBx6A69S6gB XnP1IUWZCJInKdnT1+VSeO+650og8xGe5ddIiRD9zKlUVJ83T8yq6W+Mv0d8hnTr4XtV QG/GX9zkndkMdDjJex+IwxIvqQVDAwcwR2fUehQqucdT7vm5uTiVbJHEvOEf+GCBwkyi l9GYwQZxt539Cl2IEnY5qKXl8NMi9sJ86YfpMryGnq2ws0jG6i5h7wt3qINswcXvk/Xz QI17SfntO7o8TbAtcvT7LhdY+s6RcQ91qYsEMcEfqrHCtXgnHInLKgY8nm6cKjQ/WfeZ 5tqA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=jfyPQMz0ArvxlbmiZK75s4Yr3bHUAf0slQ2N8mEO8Uk=; b=s5QR48HR7qkl+C4XmT8MzqDQKajk7U8GJJuPqfrCc/eeCArCPfL+VYeYXb3t1NZ6wT YAsvKbfmeqRLUm43kKc3PCkFeus7zVc0cr0gH70koGQiLYN7FL7a3OPBUbiUOU/LbVVC IDO93Ks4GshR5raiQlDKckDpVKLxeIFDHHoveou+GqjA9XuSmz2vQtQ9dga0DMUd2TRG Db8HhBr4SF2ZYc3xsV9bF6FEvjdDNkVt/a2oAPZMq8HWxlmVlfW2/yGXdQCzsebmShb+ YA5KI/5fMP0+oLCD2zzdRrOZmScxbSIBVLCjZF0C/1m+fsKNimanCxbNUoa2+Li3lZ1D kF4Q==
X-Gm-Message-State: AIkVDXJldh1tRenlw1Bmt1ZSwaXcJ8T4i8Ql8IpCBOr8Ev7rD513QsEB1KaiONLv3b7VQy47Z6AbWM+j2a0H5w==
X-Received: by 10.157.57.194 with SMTP id y60mr4842627otb.92.1486069926624; Thu, 02 Feb 2017 13:12:06 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <48e46164-e532-7002-2738-b25c4c36d6bf@hs-bremen.de> <CACknUNU53bVXGeHNCfJDCUXDCErRczWvJooBZbd9p0mFEf9i+g@mail.gmail.com>
In-Reply-To: <CACknUNU53bVXGeHNCfJDCUXDCErRczWvJooBZbd9p0mFEf9i+g@mail.gmail.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 21:11:56 +0000
Message-ID: <CACknUNXQ2bjGCQ7PZBp=SsmeNfiZ+FBoRC9jQqYP4+WkUz2Qbg@mail.gmail.com>
To: Carl-Heinz Genzel <carl-heinz.genzel@hs-bremen.de>, sacm@ietf.org
Content-Type: multipart/alternative; boundary=001a1141a48c16858b0547929ea2
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/_m-yfKRHi0vf92E1tcSENlm-lak>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 21:12:10 -0000

--001a1141a48c16858b0547929ea2
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Just to follow up on this, I've attached an alternate to v3, which puts the
Endpoint Repository between the Vulnerability Assessor and Collector.

Also, for what it's worth, here's the sentence I based the diagram on in
the first place: "If the data possessed by the endpoint management
capabilities is insufficient, a Collection Task is triggered and the
necessary data is collected from the target endpoint".

Adam


On Thu, Feb 2, 2017 at 2:05 PM Adam Montville <adam.w.montville@gmail.com>
wrote:

> On Thu, Feb 2, 2017 at 1:21 PM Carl-Heinz Genzel <
> carl-heinz.genzel@hs-bremen.de> wrote:
>
> Hello Everybody,
>
> you all may have seen my name in the WebEx today. However I didn't
> introduce myself yet. I apologize for that. Please don't hold that
> against me. I just didn't want to hinder the discussion, since I am very
> new to this work group and the IETF work in general.
>
> My name is Carl-Heinz Genzel and I am a research assistant at the
> University of Applied Sciences Bremen (Germany) usually working on
> topics around security, smart grids, and trusted computing.
>
>
> We're happy to have you here, thank you for joining.
>
>
>
> I find the SACM WG very interesting, however I am not certain at the
> moment about how I'm be able to contribute. However I enjoyed your
> discussion to day.
>
> There may be one thing, I like to comment about the diagram. I hope I do
> understand the SACM drafts as well as the diagram correctly, and will
> not sound absurd.
>
> For me it seems that a direct call from the vulnerability assessor to
> the collector would raise a question about separation of concerns, since
> the endpoint repository is the central component for endpoint
> information. In this regard, should not the endpoint repository call
> collect as consequence of the get endpoints call instead of a direct
> call to the collector, if information is stale or missing?
>
>
> This seems reasonable.  I am interested in what others think about the
> suggestion as well.
>
> In practice today, many vulnerability assessors are themselves
> collectors.  Still, it seams feasible for the vulnerability assessor to
> react after initial evaluation by telling the endpoint repository that it
> has not enough information, which could then cause the endpoint repositor=
y
> to trigger additional collection.
>
> I am not sure it is written that way in our draft, which does not mean
> that we can't change...
>
>
>
>
>
> Best Regards,
> Carl-Heinz Genzel
>
>
>
>
>
>
>
> Am 02.02.2017 um 18:44 schrieb Adam Montville:
> > Thanks for the feedback!  I've attached a modified version of the
> > diagram that collapses the endpoint and assessment result repositories
> > (by keeping the endpoint repository).  Where would you propose we focus
> > on enhancing the diagram?  Remember that it's a sequence diagram, which
> > might do well with some more specific details captured in text or a
> > different form of diagram.
> >
> > What do folks think about using one or more OVAL definitions as a
> > starting point?
> >
> > Adam
> >
> >
> > On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz
> > <henk.birkholz@sit.fraunhofer.de
> > <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
> >
> >     ## A Few Comments
> >
> >     * I agree that the diagram pretty much captures a "one time
> snapshot".
> >     * Collapsing the highlighted components seems to be a feasible idea=
.
> >     * I agree that the diagram could be implemented given an appropriat=
e
> set
> >     of initial data.
> >     * I suppose there is the risk that one has to scrap everything
> >     implemented when we start trying to make it a continuous process.
> >     * I'd recommend to start with a generic block of PoC code that
> provides
> >     the functions of a SACM component to get input and create output
> (maybe
> >     using dbus, chained event-loops, blocking waits on fifos, or IP ove=
r
> >     loopback? A better coder than me should bash these suggestions).
> >
> >     ## One, Two, or Three Tasks
> >
> >     * Creating component code that can create the (downstream?) flow of
> >     information is urgent and important, I think.
> >     * Enhancing the diagram to represent the continuous cycle with at
> least
> >     one trigger (as illustrated by Bill; new software, new VDI, new
> >     endpoints, stale results, etc.) is important, but not as urgent. It
> >     might save time though by reducing the afore mentioned risk to shoo=
t
> >     your self in the foot by creating a too specific proof of concept o=
f
> the
> >     one time snapshot approach, I think.
> >     * Selecting a set of initial data derived from OVAL to be used in t=
he
> >     one shot snapshot seems to be a feasible approach to me, but I am n=
ot
> >     sure how the group thinks about that.
> >
> >     Does that assessment represent the general opinion, or is that just
> >     mine?
> >
> >     Viele Gr=C3=BC=C3=9Fe,
> >
> >     Henk
> >
> >     On 02/02/2017 05:28 PM, Adam Montville wrote:
> >     > Hi Everyone.  A few of us were able to make the vulnerability
> scenario
> >     > call today and I think we had a good, though at times spirited,
> >     > discussion.  We did record the meeting, which is available at
> [1].  We
> >     > discussed the attached (annotated with some meeting notes) UML-is=
h
> >     > sequence diagram.  I had created that diagram to start a
> conversation
> >     > (mission accomplished on that front I think) -- a conversation th=
at
> >     > would lead us toward identifying the discrete components,
> interfaces,
> >     > and information required to be sent over those interfaces.  The
> >     UML-ish
> >     > diagram represents a *single* flow through the system -- a
> "one-time"
> >     > flow through the system.  It ignores, for the time being, the
> >     continuous
> >     > aspect of our charter in favor of getting started with the
> >     basics.  Once
> >     > we have a good understanding of the basics -- the components,
> >     > interfaces, and information required -- we can start look at a
> >     > continuous monitoring sequence (which could be represented as a
> >     distinct
> >     > diagram) to determine what more we need.  Then, I think, we can
> start
> >     > drafting solutions.
> >     >
> >     > One of the first issues is that we need to figure out if the
> >     components
> >     > in the base flow are accurate.  The main suggestion we've tossed
> >     around
> >     > so far is to combine the Endpoint Repository with the Assessment
> >     Result
> >     > Repository.
> >     >
> >     > We talked briefly about what interface we could use for the VDD
> >     > Repository, and naturally ROLIE came up as an option.
> >     >
> >     > We talked a little bit about the first "get endpoints" operation
> >     between
> >     > the Vulnerability Assessor and the Endpoint Repository --
> specifically
> >     > about whether we should represent on this sequence diagram that
> >     > information supporting a judgement of "stale" would be needed.
> >     >
> >     > We left open the time when we would next meet, favoring to work
> >     that out
> >     > on-list.  Next week is TCG, so that may be difficult; the
> >     following week
> >     > is RSA, so that may be difficult.
> >     >
> >     > For those who were in attendance today, please add to this note
> with
> >     > your comments/corrections.
> >     >
> >     > Kind regards,
> >     >
> >     > Adam
> >     >
> >     > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd=
1E
> >     >
> >     > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
> >     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
> >     <mailto:adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>>> wrote:
> >     >
> >     >     Hi everyone.  Just a friendly reminder that we are planning t=
o
> >     meet
> >     >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm
> UTC)
> >     >     using SACM's meeting room at https://ietf.webex.com/meet/sacm=
.
> >     >
> >     >     Kind regards,
> >     >
> >     >     Adam
> >     >
> >     >
> >     >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
> >     >     <adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>
> >     <mailto:adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>>> wrote:
> >     >
> >     >         Hello. A few of us met informally today to discuss the
> >     >         vulnerability scenario in some more detail with the goal =
of
> >     >         maintaining the narrow focus on a vulnerability assessmen=
t
> >     slice
> >     >         through our notional environment.  We are tending to look
> at
> >     >         major components as black boxes with interfaces and data
> >     format
> >     >         expectations, and we are not necessarily concerned with h=
ow
> >     >         those components do things internally/behind the scenes.
> >     >
> >     >         The meeting was recorded (you can find it with today's
> date at
> >     >         [1]).  The topic of discussion was primarily in the "phas=
e
> 1"
> >     >         area of what Danny sent to the list not very long ago [2]=
,
> and
> >     >         resulted in a *starting point* diagram [3].
> >     >
> >     >         The group who met today are (roughly) agreed on the six
> main
> >     >         "components" represented in that diagram, but also see
> that we
> >     >         have some work ahead.  Specifically, we quickly recognize=
d
> >     that
> >     >         some of the assumptions the vulnerability draft makes may
> be
> >     >         assumptions we cannot afford to make and need to include
> >     in the
> >     >         exploration.
> >     >
> >     >         We thought it would be a good idea to have another inform=
al
> >     >         discussion in a couple of weeks (February 2) at the same
> time
> >     >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At
> that
> >     >         time we intend to roll through the vulnerability assessme=
nt
> >     >         scenario assumptions in an effort to determine which ones
> >     can be
> >     >         left as assumptions and which ones cannot.  Then we'll ta=
ke
> >     >         another look at the diagram and work on its next version.
> >     >
> >     >         Stay tuned.
> >     >
> >     >         Thanks to Danny, Stephen, and Jerome for joining and
> >     contributing!
> >     >
> >     >         Kind regards,
> >     >
> >     >         Adam
> >     >
> >     >
> >     >         [1]
> >     https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >     >         [2]
> >
> https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> >     >         [3]
> >     https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> >     >         [4] https://ietf.webex.com/meet/sacm
> >     >
> >     >
> >     >
> >     > _______________________________________________
> >     > sacm mailing list
> >     > sacm@ietf.org <mailto:sacm@ietf.org>
> >     > https://www.ietf.org/mailman/listinfo/sacm
> >     >
> >
> >
> >
> > _______________________________________________
> > sacm mailing list
> > sacm@ietf.org
> > https://www.ietf.org/mailman/listinfo/sacm
> >
>
> --
>
> _________________________________________________________________________=
_____________
>
> Carl-Heinz Genzel
> Wissenschaftlicher Mitarbeiter
> Rechnernetze / Informationssicherheit
> Institut f=C3=BCr Informatik und Automation
> Hochschule Bremen / University of Applied Sciences
> Flughafenallee 10, 28199 Bremen, Germany
> tel.:  +49 421 5905 5442 <+49%20421%2059055442>
> mobil: +49 179 1636844 <+49%20179%201636844>
> email: carl-heinz.genzel@hs-bremen.de
> _________________________________________________________________________=
__
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>

--001a1141a48c16858b0547929ea2
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Just to follow up on this, I&#39;ve attached an alternate =
to v3, which puts the Endpoint Repository between the Vulnerability Assesso=
r and Collector. =C2=A0<div><br></div><div>Also, for what it&#39;s worth, h=
ere&#39;s the sentence I based the diagram on in the first place: &quot;If =
the data possessed by the endpoint management capabilities is insufficient,=
 a Collection Task is triggered and the necessary data is collected from th=
e target endpoint&quot;. =C2=A0</div><div><br></div><div>Adam</div><div><br=
></div><div><br><div class=3D"gmail_quote"><div dir=3D"ltr">On Thu, Feb 2, =
2017 at 2:05 PM Adam Montville &lt;<a href=3D"mailto:adam.w.montville@gmail=
.com">adam.w.montville@gmail.com</a>&gt; wrote:<br></div><blockquote class=
=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padd=
ing-left:1ex"><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quot=
e gmail_msg"><div dir=3D"ltr" class=3D"gmail_msg">On Thu, Feb 2, 2017 at 1:=
21 PM Carl-Heinz Genzel &lt;<a href=3D"mailto:carl-heinz.genzel@hs-bremen.d=
e" class=3D"gmail_msg" target=3D"_blank">carl-heinz.genzel@hs-bremen.de</a>=
&gt; wrote:<br class=3D"gmail_msg"></div><blockquote class=3D"gmail_quote g=
mail_msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-lef=
t:1ex">Hello Everybody,<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
you all may have seen my name in the WebEx today. However I didn&#39;t<br c=
lass=3D"gmail_msg">
introduce myself yet. I apologize for that. Please don&#39;t hold that<br c=
lass=3D"gmail_msg">
against me. I just didn&#39;t want to hinder the discussion, since I am ver=
y<br class=3D"gmail_msg">
new to this work group and the IETF work in general.<br class=3D"gmail_msg"=
>
<br class=3D"gmail_msg">
My name is Carl-Heinz Genzel and I am a research assistant at the<br class=
=3D"gmail_msg">
University of Applied Sciences Bremen (Germany) usually working on<br class=
=3D"gmail_msg">
topics around security, smart grids, and trusted computing.<br class=3D"gma=
il_msg"></blockquote><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div=
></div></div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quote=
 gmail_msg"><div class=3D"gmail_msg">We&#39;re happy to have you here, than=
k you for joining.</div></div></div><div dir=3D"ltr" class=3D"gmail_msg"><d=
iv class=3D"gmail_quote gmail_msg"><div class=3D"gmail_msg">=C2=A0</div><bl=
ockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;border-=
left:1px #ccc solid;padding-left:1ex">
<br class=3D"gmail_msg">
I find the SACM WG very interesting, however I am not certain at the<br cla=
ss=3D"gmail_msg">
moment about how I&#39;m be able to contribute. However I enjoyed your<br c=
lass=3D"gmail_msg">
discussion to day.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
There may be one thing, I like to comment about the diagram. I hope I do<br=
 class=3D"gmail_msg">
understand the SACM drafts as well as the diagram correctly, and will<br cl=
ass=3D"gmail_msg">
not sound absurd.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
For me it seems that a direct call from the vulnerability assessor to<br cl=
ass=3D"gmail_msg">
the collector would raise a question about separation of concerns, since<br=
 class=3D"gmail_msg">
the endpoint repository is the central component for endpoint<br class=3D"g=
mail_msg">
information. In this regard, should not the endpoint repository call<br cla=
ss=3D"gmail_msg">
collect as consequence of the get endpoints call instead of a direct<br cla=
ss=3D"gmail_msg">
call to the collector, if information is stale or missing?<br class=3D"gmai=
l_msg"></blockquote><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div>=
</div></div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quote =
gmail_msg"><div class=3D"gmail_msg">This seems reasonable.=C2=A0 I am inter=
ested in what others think about the suggestion as well. =C2=A0</div><div c=
lass=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">I=
n practice today, many vulnerability assessors are themselves collectors.=
=C2=A0 Still, it seams feasible for the vulnerability assessor to react aft=
er initial evaluation by telling the endpoint repository that it has not en=
ough information, which could then cause the endpoint repository to trigger=
 additional collection.=C2=A0</div><div class=3D"gmail_msg"><br class=3D"gm=
ail_msg"></div><div class=3D"gmail_msg">I am not sure it is written that wa=
y in our draft, which does not mean that we can&#39;t change...</div></div>=
</div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quote gmail_=
msg"><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"g=
mail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">=C2=A0</di=
v><blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bo=
rder-left:1px #ccc solid;padding-left:1ex">
<br class=3D"gmail_msg">
Best Regards,<br class=3D"gmail_msg">
Carl-Heinz Genzel<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Am 02.02.2017 um 18:44 schrieb Adam Montville:<br class=3D"gmail_msg">
&gt; Thanks for the feedback!=C2=A0 I&#39;ve attached a modified version of=
 the<br class=3D"gmail_msg">
&gt; diagram that collapses the endpoint and assessment result repositories=
<br class=3D"gmail_msg">
&gt; (by keeping the endpoint repository).=C2=A0 Where would you propose we=
 focus<br class=3D"gmail_msg">
&gt; on enhancing the diagram?=C2=A0 Remember that it&#39;s a sequence diag=
ram, which<br class=3D"gmail_msg">
&gt; might do well with some more specific details captured in text or a<br=
 class=3D"gmail_msg">
&gt; different form of diagram.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; What do folks think about using one or more OVAL definitions as a<br c=
lass=3D"gmail_msg">
&gt; starting point?<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz<br class=3D"gmail_msg">
&gt; &lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D"gmail_=
msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a><br class=3D"gmai=
l_msg">
&gt; &lt;mailto:<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D=
"gmail_msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a>&gt;&gt; w=
rote:<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0## A Few Comments<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I agree that the diagram pretty much captures a &=
quot;one time snapshot&quot;.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Collapsing the highlighted components seems to be=
 a feasible idea.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I agree that the diagram could be implemented giv=
en an appropriate set<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0of initial data.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I suppose there is the risk that one has to scrap=
 everything<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0implemented when we start trying to make it a conti=
nuous process.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I&#39;d recommend to start with a generic block o=
f PoC code that provides<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0the functions of a SACM component to get input and =
create output (maybe<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using dbus, chained event-loops, blocking waits on =
fifos, or IP over<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0loopback? A better coder than me should bash these =
suggestions).<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0## One, Two, or Three Tasks<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Creating component code that can create the (down=
stream?) flow of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0information is urgent and important, I think.<br cl=
ass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Enhancing the diagram to represent the continuous=
 cycle with at least<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one trigger (as illustrated by Bill; new software, =
new VDI, new<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0endpoints, stale results, etc.) is important, but n=
ot as urgent. It<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0might save time though by reducing the afore mentio=
ned risk to shoot<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0your self in the foot by creating a too specific pr=
oof of concept of the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one time snapshot approach, I think.<br class=3D"gm=
ail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Selecting a set of initial data derived from OVAL=
 to be used in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one shot snapshot seems to be a feasible approach t=
o me, but I am not<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0sure how the group thinks about that.<br class=3D"g=
mail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Does that assessment represent the general opinion,=
 or is that just<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0mine?<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Viele Gr=C3=BC=C3=9Fe,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Henk<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0On 02/02/2017 05:28 PM, Adam Montville wrote:<br cl=
ass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Hi Everyone.=C2=A0 A few of us were able to ma=
ke the vulnerability scenario<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; call today and I think we had a good, though a=
t times spirited,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; discussion.=C2=A0 We did record the meeting, w=
hich is available at [1].=C2=A0 We<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; discussed the attached (annotated with some me=
eting notes) UML-ish<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; sequence diagram.=C2=A0 I had created that dia=
gram to start a conversation<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; (mission accomplished on that front I think) -=
- a conversation that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; would lead us toward identifying the discrete =
components, interfaces,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; and information required to be sent over those=
 interfaces.=C2=A0 The<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0UML-ish<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; diagram represents a *single* flow through the=
 system -- a &quot;one-time&quot;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; flow through the system.=C2=A0 It ignores, for=
 the time being, the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0continuous<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; aspect of our charter in favor of getting star=
ted with the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0basics.=C2=A0 Once<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; we have a good understanding of the basics -- =
the components,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; interfaces, and information required -- we can=
 start look at a<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; continuous monitoring sequence (which could be=
 represented as a<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0distinct<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; diagram) to determine what more we need.=C2=A0=
 Then, I think, we can start<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; drafting solutions.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; One of the first issues is that we need to fig=
ure out if the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0components<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; in the base flow are accurate.=C2=A0 The main =
suggestion we&#39;ve tossed<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0around<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; so far is to combine the Endpoint Repository w=
ith the Assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Result<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Repository.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We talked briefly about what interface we coul=
d use for the VDD<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Repository, and naturally ROLIE came up as an =
option.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We talked a little bit about the first &quot;g=
et endpoints&quot; operation<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0between<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; the Vulnerability Assessor and the Endpoint Re=
pository -- specifically<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; about whether we should represent on this sequ=
ence diagram that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; information supporting a judgement of &quot;st=
ale&quot; would be needed.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We left open the time when we would next meet,=
 favoring to work<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0that out<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; on-list.=C2=A0 Next week is TCG, so that may b=
e difficult; the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0following week<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; is RSA, so that may be difficult.<br class=3D"=
gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; For those who were in attendance today, please=
 add to this note with<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; your comments/corrections.<br class=3D"gmail_m=
sg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Kind regards,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Adam<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; [1] <a href=3D"https://drive.google.com/open?i=
d=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" ta=
rget=3D"_blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0t=
Md1E</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montvill=
e<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.c=
om" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &l=
t;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" =
target=3D"_blank">adam.w.montville@gmail.com</a>&gt;<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a f=
riendly reminder that we are planning to<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0meet<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the =
same time (2/2 @ 10am Eastern/3pm UTC)<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting ro=
om at <a href=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=
=3D"gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/sacm</a>.<br c=
lass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"g=
mail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:=
35 AM Adam Montville<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.=
w.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montvil=
le@gmail.com</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few =
of us met informally today to discuss the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability=
 scenario in some more detail with the goal of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining t=
he narrow focus on a vulnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0slice<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our n=
otional environment.=C2=A0 We are tending to look at<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major compone=
nts as black boxes with interfaces and data<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0format<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations,=
 and we are not necessarily concerned with how<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those compone=
nts do things internally/behind the scenes.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting w=
as recorded (you can find it with today&#39;s date at<br class=3D"gmail_msg=
">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 T=
he topic of discussion was primarily in the &quot;phase 1&quot;<br class=3D=
"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what =
Danny sent to the list not very long ago [2], and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a=
 *starting point* diagram [3].<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who=
 met today are (roughly) agreed on the six main<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;compone=
nts&quot; represented in that diagram, but also see that we<br class=3D"gma=
il_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some wor=
k ahead.=C2=A0 Specifically, we quickly recognized<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the a=
ssumptions the vulnerability draft makes may be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions w=
e cannot afford to make and need to include<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it=
 would be a good idea to have another informal<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in=
 a couple of weeks (February 2) at the same time<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern=
 / 3pm UTC), using the same WebEx [4].=C2=A0 =C2=A0At that<br class=3D"gmai=
l_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we inten=
d to roll through the vulnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assu=
mptions in an effort to determine which ones<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0can be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assum=
ptions and which ones cannot.=C2=A0 Then we&#39;ll take<br class=3D"gmail_m=
sg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look =
at the diagram and work on its next version.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<b=
r class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Dan=
ny, Stephen, and Jerome for joining and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0contributing!<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,=
<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf=
9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_=
blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://mailarchive.ietf.org/arch/msg/sa=
cm/_LiKlyvAws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=3D"gmail_msg" targ=
et=3D"_blank">https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5=
NSU58MXDM</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf=
9Un5FdCbMU5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_=
blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=
=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"gmail_msg=
" target=3D"_blank">https://ietf.webex.com/meet/sacm</a><br class=3D"gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; ______________________________________________=
_<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; sacm mailing list<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmai=
l_msg" target=3D"_blank">sacm@ietf.org</a> &lt;mailto:<a href=3D"mailto:sac=
m@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm@ietf.org</a>&gt;<br =
class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; <a href=3D"https://www.ietf.org/mailman/listin=
fo/sacm" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">https://w=
ww.ietf.org/mailman/listinfo/sacm</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; _______________________________________________<br class=3D"gmail_msg"=
>
&gt; sacm mailing list<br class=3D"gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank"=
>sacm@ietf.org</a><br class=3D"gmail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferr=
er" class=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/list=
info/sacm</a><br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
--<br class=3D"gmail_msg">
___________________________________________________________________________=
___________<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Carl-Heinz Genzel<br class=3D"gmail_msg">
Wissenschaftlicher Mitarbeiter<br class=3D"gmail_msg">
Rechnernetze / Informationssicherheit<br class=3D"gmail_msg">
Institut f=C3=BCr Informatik und Automation<br class=3D"gmail_msg">
Hochschule Bremen / University of Applied Sciences<br class=3D"gmail_msg">
Flughafenallee 10, 28199 Bremen, Germany<br class=3D"gmail_msg">
tel.:=C2=A0 <a href=3D"tel:+49%20421%2059055442" value=3D"+4942159055442" c=
lass=3D"gmail_msg" target=3D"_blank">+49 421 5905 5442</a><br class=3D"gmai=
l_msg">
mobil: <a href=3D"tel:+49%20179%201636844" value=3D"+491791636844" class=3D=
"gmail_msg" target=3D"_blank">+49 179 1636844</a><br class=3D"gmail_msg">
email: <a href=3D"mailto:carl-heinz.genzel@hs-bremen.de" class=3D"gmail_msg=
" target=3D"_blank">carl-heinz.genzel@hs-bremen.de</a><br class=3D"gmail_ms=
g">
___________________________________________________________________________=
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
_______________________________________________<br class=3D"gmail_msg">
sacm mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm=
@ietf.org</a><br class=3D"gmail_msg">
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" c=
lass=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/listinfo/=
sacm</a><br class=3D"gmail_msg">
</blockquote></div></div></blockquote></div></div></div>

--001a1141a48c16858b0547929ea2--


From nobody Thu Feb  2 13:12:43 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9680E129867 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 13:12:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.989
X-Spam-Level: 
X-Spam-Status: No, score=-1.989 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_FREEMAIL_DOC_PDF=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PPothjmE7l15 for <sacm@ietfa.amsl.com>; Thu,  2 Feb 2017 13:12:38 -0800 (PST)
Received: from mail-ot0-x236.google.com (mail-ot0-x236.google.com [IPv6:2607:f8b0:4003:c0f::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 05D6A129568 for <sacm@ietf.org>; Thu,  2 Feb 2017 13:12:38 -0800 (PST)
Received: by mail-ot0-x236.google.com with SMTP id 32so90842oth.3 for <sacm@ietf.org>; Thu, 02 Feb 2017 13:12:37 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to;  bh=f6RPVtFm04VvzPiLEXY3gL8k1k+AFvaaeFoFfZYlDAY=; b=td7Bxlgv9rEVxMM6qfDdifFGJcl7b3hHImOzhpkScfKip5dp2T13HjFvNnwqPnEYfW 7NgN2WiS3ZVptBc50JUw3uLaVlnFDwxb1R2TBZJr6ZNndiWuSQsiUdK7JJgWRM8g6yBs jkvSXv+wn53NJO9A/bcYJuf18UXv6GabZ69EWlyTsbDUi9dPrShZsMbmLAiJ03nWXb1G FWfZ42DAcC5ZFbmN8SkSIXgn2jQV/+BWoDx5w6hhac1ckj0pVLNIG1YANA1TLDu4hq2B 4hBv/d/IxGffPGV8++xiHDj2xK7mEX/JxaHFElQUWH3bsPo3tKovZQB7oiDiPaNtCnfR 7zAA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=f6RPVtFm04VvzPiLEXY3gL8k1k+AFvaaeFoFfZYlDAY=; b=o4Kjh7iBGI2i84q0Hia2/3XEQkY92TPUpTXKEain5EaKJXiEwBJZlNuCak05+4/zom nBkAMBGyQUs1NK4DwLpyDyG1Mz//RStKbqvMZ80jHkzxXArgynxYfPCpa8M9GGXaKhcs XWZbn0ts07/0jOEK8vtvsJ9M+YcpIkPhyiiy3bj3gTxMhbeuDMec9zqbCExIg5dmt7ks FlUFZadI8IT0R/2GIzv0/CQll3P/sWlWprd7i3Ig75bnhKOwCCGEUxxEpIQxTMLiKZeG ajJ5vOCgDrDrIwWSKaaPdZO863PD8xeSRyUFxh55tJj9VRhBKgJcwgDO0tq149ZDhGAY ruVQ==
X-Gm-Message-State: AMke39m7mp3MVHkcg3+asYcN2bsI9aHb225LY/RRS4CldCYEgLEJCKg9Ktdy6/DqjZ3ECZRN5ch+qB8RubL7kw==
X-Received: by 10.157.47.236 with SMTP id b41mr5639575otd.236.1486069956970; Thu, 02 Feb 2017 13:12:36 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <48e46164-e532-7002-2738-b25c4c36d6bf@hs-bremen.de> <CACknUNU53bVXGeHNCfJDCUXDCErRczWvJooBZbd9p0mFEf9i+g@mail.gmail.com> <CACknUNXQ2bjGCQ7PZBp=SsmeNfiZ+FBoRC9jQqYP4+WkUz2Qbg@mail.gmail.com>
In-Reply-To: <CACknUNXQ2bjGCQ7PZBp=SsmeNfiZ+FBoRC9jQqYP4+WkUz2Qbg@mail.gmail.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Thu, 02 Feb 2017 21:12:26 +0000
Message-ID: <CACknUNXJFpzMG5PXwSnDXF91N_zUWNQoDhEVn3S3sbHwbark9A@mail.gmail.com>
To: Carl-Heinz Genzel <carl-heinz.genzel@hs-bremen.de>, sacm@ietf.org
Content-Type: multipart/mixed; boundary=001a113b197ae5aaee0547929fdd
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/7e56Olyqwo5ypH5DOrFeN5hUxNo>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 21:12:40 -0000

--001a113b197ae5aaee0547929fdd
Content-Type: multipart/alternative; boundary=001a113b197ae5aaea0547929fdb

--001a113b197ae5aaea0547929fdb
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

This time with the attachment.

On Thu, Feb 2, 2017 at 3:11 PM Adam Montville <adam.w.montville@gmail.com>
wrote:

> Just to follow up on this, I've attached an alternate to v3, which puts
> the Endpoint Repository between the Vulnerability Assessor and Collector.
>
> Also, for what it's worth, here's the sentence I based the diagram on in
> the first place: "If the data possessed by the endpoint management
> capabilities is insufficient, a Collection Task is triggered and the
> necessary data is collected from the target endpoint".
>
> Adam
>
>
> On Thu, Feb 2, 2017 at 2:05 PM Adam Montville <adam.w.montville@gmail.com=
>
> wrote:
>
> On Thu, Feb 2, 2017 at 1:21 PM Carl-Heinz Genzel <
> carl-heinz.genzel@hs-bremen.de> wrote:
>
> Hello Everybody,
>
> you all may have seen my name in the WebEx today. However I didn't
> introduce myself yet. I apologize for that. Please don't hold that
> against me. I just didn't want to hinder the discussion, since I am very
> new to this work group and the IETF work in general.
>
> My name is Carl-Heinz Genzel and I am a research assistant at the
> University of Applied Sciences Bremen (Germany) usually working on
> topics around security, smart grids, and trusted computing.
>
>
> We're happy to have you here, thank you for joining.
>
>
>
> I find the SACM WG very interesting, however I am not certain at the
> moment about how I'm be able to contribute. However I enjoyed your
> discussion to day.
>
> There may be one thing, I like to comment about the diagram. I hope I do
> understand the SACM drafts as well as the diagram correctly, and will
> not sound absurd.
>
> For me it seems that a direct call from the vulnerability assessor to
> the collector would raise a question about separation of concerns, since
> the endpoint repository is the central component for endpoint
> information. In this regard, should not the endpoint repository call
> collect as consequence of the get endpoints call instead of a direct
> call to the collector, if information is stale or missing?
>
>
> This seems reasonable.  I am interested in what others think about the
> suggestion as well.
>
> In practice today, many vulnerability assessors are themselves
> collectors.  Still, it seams feasible for the vulnerability assessor to
> react after initial evaluation by telling the endpoint repository that it
> has not enough information, which could then cause the endpoint repositor=
y
> to trigger additional collection.
>
> I am not sure it is written that way in our draft, which does not mean
> that we can't change...
>
>
>
>
>
> Best Regards,
> Carl-Heinz Genzel
>
>
>
>
>
>
>
> Am 02.02.2017 um 18:44 schrieb Adam Montville:
> > Thanks for the feedback!  I've attached a modified version of the
> > diagram that collapses the endpoint and assessment result repositories
> > (by keeping the endpoint repository).  Where would you propose we focus
> > on enhancing the diagram?  Remember that it's a sequence diagram, which
> > might do well with some more specific details captured in text or a
> > different form of diagram.
> >
> > What do folks think about using one or more OVAL definitions as a
> > starting point?
> >
> > Adam
> >
> >
> > On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz
> > <henk.birkholz@sit.fraunhofer.de
> > <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
> >
> >     ## A Few Comments
> >
> >     * I agree that the diagram pretty much captures a "one time
> snapshot".
> >     * Collapsing the highlighted components seems to be a feasible idea=
.
> >     * I agree that the diagram could be implemented given an appropriat=
e
> set
> >     of initial data.
> >     * I suppose there is the risk that one has to scrap everything
> >     implemented when we start trying to make it a continuous process.
> >     * I'd recommend to start with a generic block of PoC code that
> provides
> >     the functions of a SACM component to get input and create output
> (maybe
> >     using dbus, chained event-loops, blocking waits on fifos, or IP ove=
r
> >     loopback? A better coder than me should bash these suggestions).
> >
> >     ## One, Two, or Three Tasks
> >
> >     * Creating component code that can create the (downstream?) flow of
> >     information is urgent and important, I think.
> >     * Enhancing the diagram to represent the continuous cycle with at
> least
> >     one trigger (as illustrated by Bill; new software, new VDI, new
> >     endpoints, stale results, etc.) is important, but not as urgent. It
> >     might save time though by reducing the afore mentioned risk to shoo=
t
> >     your self in the foot by creating a too specific proof of concept o=
f
> the
> >     one time snapshot approach, I think.
> >     * Selecting a set of initial data derived from OVAL to be used in t=
he
> >     one shot snapshot seems to be a feasible approach to me, but I am n=
ot
> >     sure how the group thinks about that.
> >
> >     Does that assessment represent the general opinion, or is that just
> >     mine?
> >
> >     Viele Gr=C3=BC=C3=9Fe,
> >
> >     Henk
> >
> >     On 02/02/2017 05:28 PM, Adam Montville wrote:
> >     > Hi Everyone.  A few of us were able to make the vulnerability
> scenario
> >     > call today and I think we had a good, though at times spirited,
> >     > discussion.  We did record the meeting, which is available at
> [1].  We
> >     > discussed the attached (annotated with some meeting notes) UML-is=
h
> >     > sequence diagram.  I had created that diagram to start a
> conversation
> >     > (mission accomplished on that front I think) -- a conversation th=
at
> >     > would lead us toward identifying the discrete components,
> interfaces,
> >     > and information required to be sent over those interfaces.  The
> >     UML-ish
> >     > diagram represents a *single* flow through the system -- a
> "one-time"
> >     > flow through the system.  It ignores, for the time being, the
> >     continuous
> >     > aspect of our charter in favor of getting started with the
> >     basics.  Once
> >     > we have a good understanding of the basics -- the components,
> >     > interfaces, and information required -- we can start look at a
> >     > continuous monitoring sequence (which could be represented as a
> >     distinct
> >     > diagram) to determine what more we need.  Then, I think, we can
> start
> >     > drafting solutions.
> >     >
> >     > One of the first issues is that we need to figure out if the
> >     components
> >     > in the base flow are accurate.  The main suggestion we've tossed
> >     around
> >     > so far is to combine the Endpoint Repository with the Assessment
> >     Result
> >     > Repository.
> >     >
> >     > We talked briefly about what interface we could use for the VDD
> >     > Repository, and naturally ROLIE came up as an option.
> >     >
> >     > We talked a little bit about the first "get endpoints" operation
> >     between
> >     > the Vulnerability Assessor and the Endpoint Repository --
> specifically
> >     > about whether we should represent on this sequence diagram that
> >     > information supporting a judgement of "stale" would be needed.
> >     >
> >     > We left open the time when we would next meet, favoring to work
> >     that out
> >     > on-list.  Next week is TCG, so that may be difficult; the
> >     following week
> >     > is RSA, so that may be difficult.
> >     >
> >     > For those who were in attendance today, please add to this note
> with
> >     > your comments/corrections.
> >     >
> >     > Kind regards,
> >     >
> >     > Adam
> >     >
> >     > [1] https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd=
1E
> >     >
> >     > On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
> >     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
> >     <mailto:adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>>> wrote:
> >     >
> >     >     Hi everyone.  Just a friendly reminder that we are planning t=
o
> >     meet
> >     >     again this Thursday at the same time (2/2 @ 10am Eastern/3pm
> UTC)
> >     >     using SACM's meeting room at https://ietf.webex.com/meet/sacm=
.
> >     >
> >     >     Kind regards,
> >     >
> >     >     Adam
> >     >
> >     >
> >     >     On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
> >     >     <adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>
> >     <mailto:adam.w.montville@gmail.com
> >     <mailto:adam.w.montville@gmail.com>>> wrote:
> >     >
> >     >         Hello. A few of us met informally today to discuss the
> >     >         vulnerability scenario in some more detail with the goal =
of
> >     >         maintaining the narrow focus on a vulnerability assessmen=
t
> >     slice
> >     >         through our notional environment.  We are tending to look
> at
> >     >         major components as black boxes with interfaces and data
> >     format
> >     >         expectations, and we are not necessarily concerned with h=
ow
> >     >         those components do things internally/behind the scenes.
> >     >
> >     >         The meeting was recorded (you can find it with today's
> date at
> >     >         [1]).  The topic of discussion was primarily in the "phas=
e
> 1"
> >     >         area of what Danny sent to the list not very long ago [2]=
,
> and
> >     >         resulted in a *starting point* diagram [3].
> >     >
> >     >         The group who met today are (roughly) agreed on the six
> main
> >     >         "components" represented in that diagram, but also see
> that we
> >     >         have some work ahead.  Specifically, we quickly recognize=
d
> >     that
> >     >         some of the assumptions the vulnerability draft makes may
> be
> >     >         assumptions we cannot afford to make and need to include
> >     in the
> >     >         exploration.
> >     >
> >     >         We thought it would be a good idea to have another inform=
al
> >     >         discussion in a couple of weeks (February 2) at the same
> time
> >     >         (10am Eastern / 3pm UTC), using the same WebEx [4].   At
> that
> >     >         time we intend to roll through the vulnerability assessme=
nt
> >     >         scenario assumptions in an effort to determine which ones
> >     can be
> >     >         left as assumptions and which ones cannot.  Then we'll ta=
ke
> >     >         another look at the diagram and work on its next version.
> >     >
> >     >         Stay tuned.
> >     >
> >     >         Thanks to Danny, Stephen, and Jerome for joining and
> >     contributing!
> >     >
> >     >         Kind regards,
> >     >
> >     >         Adam
> >     >
> >     >
> >     >         [1]
> >     https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> >     >         [2]
> >
> https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> >     >         [3]
> >     https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> >     >         [4] https://ietf.webex.com/meet/sacm
> >     >
> >     >
> >     >
> >     > _______________________________________________
> >     > sacm mailing list
> >     > sacm@ietf.org <mailto:sacm@ietf.org>
> >     > https://www.ietf.org/mailman/listinfo/sacm
> >     >
> >
> >
> >
> > _______________________________________________
> > sacm mailing list
> > sacm@ietf.org
> > https://www.ietf.org/mailman/listinfo/sacm
> >
>
> --
>
> _________________________________________________________________________=
_____________
>
> Carl-Heinz Genzel
> Wissenschaftlicher Mitarbeiter
> Rechnernetze / Informationssicherheit
> Institut f=C3=BCr Informatik und Automation
> Hochschule Bremen / University of Applied Sciences
> Flughafenallee 10, 28199 Bremen, Germany
> tel.:  +49 421 5905 5442 <+49%20421%2059055442>
> mobil: +49 179 1636844 <+49%20179%201636844>
> email: carl-heinz.genzel@hs-bremen.de
> _________________________________________________________________________=
__
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>

--001a113b197ae5aaea0547929fdb
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">This time with the attachment.<br><br><div class=3D"gmail_=
quote"><div dir=3D"ltr">On Thu, Feb 2, 2017 at 3:11 PM Adam Montville &lt;<=
a href=3D"mailto:adam.w.montville@gmail.com">adam.w.montville@gmail.com</a>=
&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 =
0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr" class=
=3D"gmail_msg">Just to follow up on this, I&#39;ve attached an alternate to=
 v3, which puts the Endpoint Repository between the Vulnerability Assessor =
and Collector. =C2=A0<div class=3D"gmail_msg"><br class=3D"gmail_msg"></div=
><div class=3D"gmail_msg">Also, for what it&#39;s worth, here&#39;s the sen=
tence I based the diagram on in the first place: &quot;If the data possesse=
d by the endpoint management capabilities is insufficient, a Collection Tas=
k is triggered and the necessary data is collected from the target endpoint=
&quot;. =C2=A0</div></div><div dir=3D"ltr" class=3D"gmail_msg"><div class=
=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">Adam<=
/div></div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_msg"><b=
r class=3D"gmail_msg"></div><div class=3D"gmail_msg"><br class=3D"gmail_msg=
"><div class=3D"gmail_quote gmail_msg"><div dir=3D"ltr" class=3D"gmail_msg"=
>On Thu, Feb 2, 2017 at 2:05 PM Adam Montville &lt;<a href=3D"mailto:adam.w=
.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montvill=
e@gmail.com</a>&gt; wrote:<br class=3D"gmail_msg"></div><blockquote class=
=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc =
solid;padding-left:1ex"><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"=
gmail_quote gmail_msg"><div dir=3D"ltr" class=3D"gmail_msg">On Thu, Feb 2, =
2017 at 1:21 PM Carl-Heinz Genzel &lt;<a href=3D"mailto:carl-heinz.genzel@h=
s-bremen.de" class=3D"gmail_msg" target=3D"_blank">carl-heinz.genzel@hs-bre=
men.de</a>&gt; wrote:<br class=3D"gmail_msg"></div><blockquote class=3D"gma=
il_quote gmail_msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;p=
adding-left:1ex">Hello Everybody,<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
you all may have seen my name in the WebEx today. However I didn&#39;t<br c=
lass=3D"gmail_msg">
introduce myself yet. I apologize for that. Please don&#39;t hold that<br c=
lass=3D"gmail_msg">
against me. I just didn&#39;t want to hinder the discussion, since I am ver=
y<br class=3D"gmail_msg">
new to this work group and the IETF work in general.<br class=3D"gmail_msg"=
>
<br class=3D"gmail_msg">
My name is Carl-Heinz Genzel and I am a research assistant at the<br class=
=3D"gmail_msg">
University of Applied Sciences Bremen (Germany) usually working on<br class=
=3D"gmail_msg">
topics around security, smart grids, and trusted computing.<br class=3D"gma=
il_msg"></blockquote><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div=
></div></div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quote=
 gmail_msg"><div class=3D"gmail_msg">We&#39;re happy to have you here, than=
k you for joining.</div></div></div><div dir=3D"ltr" class=3D"gmail_msg"><d=
iv class=3D"gmail_quote gmail_msg"><div class=3D"gmail_msg">=C2=A0</div><bl=
ockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;border-=
left:1px #ccc solid;padding-left:1ex">
<br class=3D"gmail_msg">
I find the SACM WG very interesting, however I am not certain at the<br cla=
ss=3D"gmail_msg">
moment about how I&#39;m be able to contribute. However I enjoyed your<br c=
lass=3D"gmail_msg">
discussion to day.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
There may be one thing, I like to comment about the diagram. I hope I do<br=
 class=3D"gmail_msg">
understand the SACM drafts as well as the diagram correctly, and will<br cl=
ass=3D"gmail_msg">
not sound absurd.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
For me it seems that a direct call from the vulnerability assessor to<br cl=
ass=3D"gmail_msg">
the collector would raise a question about separation of concerns, since<br=
 class=3D"gmail_msg">
the endpoint repository is the central component for endpoint<br class=3D"g=
mail_msg">
information. In this regard, should not the endpoint repository call<br cla=
ss=3D"gmail_msg">
collect as consequence of the get endpoints call instead of a direct<br cla=
ss=3D"gmail_msg">
call to the collector, if information is stale or missing?<br class=3D"gmai=
l_msg"></blockquote><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div>=
</div></div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quote =
gmail_msg"><div class=3D"gmail_msg">This seems reasonable.=C2=A0 I am inter=
ested in what others think about the suggestion as well. =C2=A0</div><div c=
lass=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">I=
n practice today, many vulnerability assessors are themselves collectors.=
=C2=A0 Still, it seams feasible for the vulnerability assessor to react aft=
er initial evaluation by telling the endpoint repository that it has not en=
ough information, which could then cause the endpoint repository to trigger=
 additional collection.=C2=A0</div><div class=3D"gmail_msg"><br class=3D"gm=
ail_msg"></div><div class=3D"gmail_msg">I am not sure it is written that wa=
y in our draft, which does not mean that we can&#39;t change...</div></div>=
</div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_quote gmail_=
msg"><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"g=
mail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">=C2=A0</di=
v><blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bo=
rder-left:1px #ccc solid;padding-left:1ex">
<br class=3D"gmail_msg">
Best Regards,<br class=3D"gmail_msg">
Carl-Heinz Genzel<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Am 02.02.2017 um 18:44 schrieb Adam Montville:<br class=3D"gmail_msg">
&gt; Thanks for the feedback!=C2=A0 I&#39;ve attached a modified version of=
 the<br class=3D"gmail_msg">
&gt; diagram that collapses the endpoint and assessment result repositories=
<br class=3D"gmail_msg">
&gt; (by keeping the endpoint repository).=C2=A0 Where would you propose we=
 focus<br class=3D"gmail_msg">
&gt; on enhancing the diagram?=C2=A0 Remember that it&#39;s a sequence diag=
ram, which<br class=3D"gmail_msg">
&gt; might do well with some more specific details captured in text or a<br=
 class=3D"gmail_msg">
&gt; different form of diagram.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; What do folks think about using one or more OVAL definitions as a<br c=
lass=3D"gmail_msg">
&gt; starting point?<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; Adam<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; On Thu, Feb 2, 2017 at 10:53 AM Henk Birkholz<br class=3D"gmail_msg">
&gt; &lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D"gmail_=
msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a><br class=3D"gmai=
l_msg">
&gt; &lt;mailto:<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D=
"gmail_msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a>&gt;&gt; w=
rote:<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0## A Few Comments<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I agree that the diagram pretty much captures a &=
quot;one time snapshot&quot;.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Collapsing the highlighted components seems to be=
 a feasible idea.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I agree that the diagram could be implemented giv=
en an appropriate set<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0of initial data.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I suppose there is the risk that one has to scrap=
 everything<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0implemented when we start trying to make it a conti=
nuous process.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* I&#39;d recommend to start with a generic block o=
f PoC code that provides<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0the functions of a SACM component to get input and =
create output (maybe<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0using dbus, chained event-loops, blocking waits on =
fifos, or IP over<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0loopback? A better coder than me should bash these =
suggestions).<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0## One, Two, or Three Tasks<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Creating component code that can create the (down=
stream?) flow of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0information is urgent and important, I think.<br cl=
ass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Enhancing the diagram to represent the continuous=
 cycle with at least<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one trigger (as illustrated by Bill; new software, =
new VDI, new<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0endpoints, stale results, etc.) is important, but n=
ot as urgent. It<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0might save time though by reducing the afore mentio=
ned risk to shoot<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0your self in the foot by creating a too specific pr=
oof of concept of the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one time snapshot approach, I think.<br class=3D"gm=
ail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0* Selecting a set of initial data derived from OVAL=
 to be used in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0one shot snapshot seems to be a feasible approach t=
o me, but I am not<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0sure how the group thinks about that.<br class=3D"g=
mail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Does that assessment represent the general opinion,=
 or is that just<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0mine?<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Viele Gr=C3=BC=C3=9Fe,<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Henk<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0On 02/02/2017 05:28 PM, Adam Montville wrote:<br cl=
ass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Hi Everyone.=C2=A0 A few of us were able to ma=
ke the vulnerability scenario<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; call today and I think we had a good, though a=
t times spirited,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; discussion.=C2=A0 We did record the meeting, w=
hich is available at [1].=C2=A0 We<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; discussed the attached (annotated with some me=
eting notes) UML-ish<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; sequence diagram.=C2=A0 I had created that dia=
gram to start a conversation<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; (mission accomplished on that front I think) -=
- a conversation that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; would lead us toward identifying the discrete =
components, interfaces,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; and information required to be sent over those=
 interfaces.=C2=A0 The<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0UML-ish<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; diagram represents a *single* flow through the=
 system -- a &quot;one-time&quot;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; flow through the system.=C2=A0 It ignores, for=
 the time being, the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0continuous<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; aspect of our charter in favor of getting star=
ted with the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0basics.=C2=A0 Once<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; we have a good understanding of the basics -- =
the components,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; interfaces, and information required -- we can=
 start look at a<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; continuous monitoring sequence (which could be=
 represented as a<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0distinct<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; diagram) to determine what more we need.=C2=A0=
 Then, I think, we can start<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; drafting solutions.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; One of the first issues is that we need to fig=
ure out if the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0components<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; in the base flow are accurate.=C2=A0 The main =
suggestion we&#39;ve tossed<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0around<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; so far is to combine the Endpoint Repository w=
ith the Assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0Result<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Repository.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We talked briefly about what interface we coul=
d use for the VDD<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Repository, and naturally ROLIE came up as an =
option.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We talked a little bit about the first &quot;g=
et endpoints&quot; operation<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0between<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; the Vulnerability Assessor and the Endpoint Re=
pository -- specifically<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; about whether we should represent on this sequ=
ence diagram that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; information supporting a judgement of &quot;st=
ale&quot; would be needed.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; We left open the time when we would next meet,=
 favoring to work<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0that out<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; on-list.=C2=A0 Next week is TCG, so that may b=
e difficult; the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0following week<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; is RSA, so that may be difficult.<br class=3D"=
gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; For those who were in attendance today, please=
 add to this note with<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; your comments/corrections.<br class=3D"gmail_m=
sg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Kind regards,<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; Adam<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; [1] <a href=3D"https://drive.google.com/open?i=
d=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" ta=
rget=3D"_blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0t=
Md1E</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; On Mon, Jan 30, 2017 at 11:21 AM Adam Montvill=
e<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.c=
om" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &l=
t;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" =
target=3D"_blank">adam.w.montville@gmail.com</a>&gt;<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Hi everyone.=C2=A0 Just a f=
riendly reminder that we are planning to<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0meet<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0again this Thursday at the =
same time (2/2 @ 10am Eastern/3pm UTC)<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0using SACM&#39;s meeting ro=
om at <a href=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=
=3D"gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/sacm</a>.<br c=
lass=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Kind regards,<br class=3D"g=
mail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0On Thu, Jan 19, 2017 at 11:=
35 AM Adam Montville<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.=
w.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montvil=
le@gmail.com</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&lt;mailto:<a href=3D"mailto:adam.w.montville@gmail=
.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&=
gt;&gt;&gt; wrote:<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hello. A few =
of us met informally today to discuss the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0vulnerability=
 scenario in some more detail with the goal of<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0maintaining t=
he narrow focus on a vulnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0slice<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0through our n=
otional environment.=C2=A0 We are tending to look at<br class=3D"gmail_msg"=
>
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0major compone=
nts as black boxes with interfaces and data<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0format<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0expectations,=
 and we are not necessarily concerned with how<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0those compone=
nts do things internally/behind the scenes.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The meeting w=
as recorded (you can find it with today&#39;s date at<br class=3D"gmail_msg=
">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]).=C2=A0 T=
he topic of discussion was primarily in the &quot;phase 1&quot;<br class=3D=
"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0area of what =
Danny sent to the list not very long ago [2], and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0resulted in a=
 *starting point* diagram [3].<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The group who=
 met today are (roughly) agreed on the six main<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;compone=
nts&quot; represented in that diagram, but also see that we<br class=3D"gma=
il_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0have some wor=
k ahead.=C2=A0 Specifically, we quickly recognized<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0that<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some of the a=
ssumptions the vulnerability draft makes may be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0assumptions w=
e cannot afford to make and need to include<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0in the<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0exploration.<=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We thought it=
 would be a good idea to have another informal<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0discussion in=
 a couple of weeks (February 2) at the same time<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0(10am Eastern=
 / 3pm UTC), using the same WebEx [4].=C2=A0 =C2=A0At that<br class=3D"gmai=
l_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0time we inten=
d to roll through the vulnerability assessment<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario assu=
mptions in an effort to determine which ones<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0can be<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0left as assum=
ptions and which ones cannot.=C2=A0 Then we&#39;ll take<br class=3D"gmail_m=
sg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0another look =
at the diagram and work on its next version.<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Stay tuned.<b=
r class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Thanks to Dan=
ny, Stephen, and Jerome for joining and<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0contributing!<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,=
<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf=
9Un5FdCbWGhDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_=
blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[2]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://mailarchive.ietf.org/arch/msg/sa=
cm/_LiKlyvAws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=3D"gmail_msg" targ=
et=3D"_blank">https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5=
NSU58MXDM</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[3]<br class=
=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf=
9Un5FdCbMU5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_=
blank">https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><=
br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[4] <a href=
=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"gmail_msg=
" target=3D"_blank">https://ietf.webex.com/meet/sacm</a><br class=3D"gmail_=
msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; ______________________________________________=
_<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; sacm mailing list<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmai=
l_msg" target=3D"_blank">sacm@ietf.org</a> &lt;mailto:<a href=3D"mailto:sac=
m@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm@ietf.org</a>&gt;<br =
class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt; <a href=3D"https://www.ietf.org/mailman/listin=
fo/sacm" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">https://w=
ww.ietf.org/mailman/listinfo/sacm</a><br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 =C2=A0&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; _______________________________________________<br class=3D"gmail_msg"=
>
&gt; sacm mailing list<br class=3D"gmail_msg">
&gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank"=
>sacm@ietf.org</a><br class=3D"gmail_msg">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferr=
er" class=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/list=
info/sacm</a><br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
--<br class=3D"gmail_msg">
___________________________________________________________________________=
___________<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Carl-Heinz Genzel<br class=3D"gmail_msg">
Wissenschaftlicher Mitarbeiter<br class=3D"gmail_msg">
Rechnernetze / Informationssicherheit<br class=3D"gmail_msg">
Institut f=C3=BCr Informatik und Automation<br class=3D"gmail_msg">
Hochschule Bremen / University of Applied Sciences<br class=3D"gmail_msg">
Flughafenallee 10, 28199 Bremen, Germany<br class=3D"gmail_msg">
tel.:=C2=A0 <a href=3D"tel:+49%20421%2059055442" value=3D"+4942159055442" c=
lass=3D"gmail_msg" target=3D"_blank">+49 421 5905 5442</a><br class=3D"gmai=
l_msg">
mobil: <a href=3D"tel:+49%20179%201636844" value=3D"+491791636844" class=3D=
"gmail_msg" target=3D"_blank">+49 179 1636844</a><br class=3D"gmail_msg">
email: <a href=3D"mailto:carl-heinz.genzel@hs-bremen.de" class=3D"gmail_msg=
" target=3D"_blank">carl-heinz.genzel@hs-bremen.de</a><br class=3D"gmail_ms=
g">
___________________________________________________________________________=
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
_______________________________________________<br class=3D"gmail_msg">
sacm mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm=
@ietf.org</a><br class=3D"gmail_msg">
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" c=
lass=3D"gmail_msg" target=3D"_blank">https://www.ietf.org/mailman/listinfo/=
sacm</a><br class=3D"gmail_msg">
</blockquote></div></div></blockquote></div></div></div></blockquote></div>=
</div>

--001a113b197ae5aaea0547929fdb--

--001a113b197ae5aaee0547929fdd
Content-Type: application/pdf; 
	name="vulnerability_scenario_sequence_diagram_v3 alternate.pdf"
Content-Disposition: attachment; 
	filename="vulnerability_scenario_sequence_diagram_v3 alternate.pdf"
Content-Transfer-Encoding: base64
Content-ID: <15a00aba62c8d8390791>
X-Attachment-Id: 15a00aba62c8d8390791

JVBERi0xLjMKJcTl8uXrp/Og0MTGCjQgMCBvYmoKPDwgL0xlbmd0aCA1IDAgUiAvRmlsdGVyIC9G
bGF0ZURlY29kZSA+PgpzdHJlYW0KeAG9Wktz3LgRvuNX4Dg6DI03yWNi78E+ZXdVyWG9B2csreQa
WfaM7NT+2fyWfA2gmyA5M5KTqthlDwDi0ejn101+1T/rr9rg72icjjHqw43+h/6sX70+Wr07apv/
Hnd6O3YRE+j/B22jcdLd165KXTT40+t9md307+brb/Wrv90cdjdfnr592OvDPWiwnqgwOoEUbB2C
7aLaPehXbx+sfvOY6eQ5YdTO47kOkcgos9xyVrQ6+LxXNLKX51l+zMf1Rru+196MdZtweoIL2KNO
iWpBD2hO1nR9JbtOS6d38qE+7/FcEfv5WtZH3SfX9Q5y8Knv0mCHOnkom7365Wb/4en++83rx/3j
4f7h5ulwvyMGOrpiGAOIhHjcQMzJPUin9GLqxgAS93kuWCf9uzpSV99qq95B7J+KErz+NTPK6F9f
E625s7V6S0fESP+D/27UKdDJvqcGDkXDGsgouqhw5Cg9PMSBdf6vkKvR7/Avn+Z0Pm1+Uh906FPn
nO9JIbYhdqn3g9cxX3Zru5SCSVBf9PeatmzobFYToRbcNb3xqiyGfhjfW/uitcF3/RD7em4IhYy8
UzkWRuPIaIyGwZyn4a/XkEnlo2vuE9Q19P362oLL17f6N735+5srvTWd0xtp6CudB37hJzfc+FKf
POZftTnyg/v64Kk80ZsDP/nzSv+ur9/pn67BNAs5kNR/02A4xo3+mDVAvUgDIA8Lp2Agb+gBSSek
DvrrqkjIoajWobhAtssq68lGRWVrLw2d74cRO9TJMqCgQrP1YFehuGH7QkXhD7KO+piVb6+pMZrO
OmuyjmICd4uS8oqXaKkbkw6D7UY/Zr+19RHaMpqkoaDEEjd2NjpYf+6v9LRdT4rqfTcaMwZVl8+3
u6xvy70WCjdt5dcadwXP0yW9+VaVZl9/P9dfUTdRog9Fm9Tmn3UK6xsv5f4T1K1oM5R40rtGYi3h
2dZd3xnbxwEGU5iY2v6zTMTFTYeQ5NT1bmZz074wtdboNn85Hm+Ox0fc7vrTSbtQbBfFV1HMmvur
udp5E0mrEikZtIC6bBnwi6RZq1AbGlt4qD6WnXnxuCEVX1dnUg+b3cGpT1b0oJ+3iVBMAYek6rfR
UKOH+tOj3KBdf8BbRwPvMZRgqbYuduPo7MhGsPWdd4OFjzhtBe1qEl2srp1mK9jQbDth30mnO9tq
YQHTPmsL+Ik1/WNV57lf1RtWZ573VLVZZS/aaPOMgi0Ai/fDgLBYVHlr6TIEu/LASpdldTYEzEk2
uMSrXeh642x8bnEJzh0UA4GQDgIXvWkpOX8wrV0wbroE2Y2aBavnIpK+GJFU8QwvikjPWx7xLFoP
Dc5ug5oxDDUUNSKyAeYIbVzftOioqbeEkGpIvq5acce+TBwiR+anOuMARSmX+mNq1GvKogOvQmwu
k2/rcn7A2y0PVBueAQUtSw+yyU4OOB55mpAjI9PWS7J4zQRA3p4h61Ddv97AHogMAA++gpBzeMCG
Jz3+ZQEwIprY/6N3rURB926u6iUPfG1hiEwSQfH9earcpDxQG36wlIoWqUysW2G3g0jnCxMlBxyF
Kj5CHh1gHD0wqN50C2GAKtt3vdpc1wdClkiHd/vvBGGHihQmSQidwj2wmBWRT5NJconPfGNmsUwR
tRSaj0egkKLaD7I33HIZ0lcqI2E+S47gnddM+C678JxPrLRy0pH34ynrbUQJpSH7yvVkROiF0CYT
eA6tEpwOlkLegDywt3DewVb/xQlT48fmmMONwJp5wbRelfXNdrFzlM0QMuXpq1hgRyRMwXtk0ogd
AXnp7kEtYkJPSWeoMGrSD1ELkQszViR+WyX4J7P6vViPrBY+/muSe8mAVgY2eUTRoO/SkkOBSov+
yCPg1jIij8RXCGFXrfA4UzorgBG5tbYDZcTMcEVdQSy5tlIKHkgVHQFE7TMjsaKHOEjiyH1Kwon8
ZxqDztvgM9ybr7sFEi2Z9Fm6qqQXhGFvHEegj4kF7UPRjpKsZ/3IqxbZ9Uzv1BDk2sKBva5NqhQg
MeQpPI7DOWtv02fV3MEOyNIjlNAjnNtaE1koIXKaU0pYHbraiBqxErJkf1DR1GTCK9xO2N73Lgt9
yC3iKFoAa3TH/Ly276inymwUXGrq3Vx6xlntLQEZO6Cklg2WfksPR4DBUVFmiSPyvNLGEbNVNdc4
CZZ9BJ4EA3GDtYEjtBiTIP6tJTxEJYrJzHdi3mI90hAz2jVcnxjY3HZ2PoHOkrbpRdoG5JqGAUBu
AQw2N58/fnm8//yk376BYDlzu3RAW4HxlGWi4AaWrsLcTm4j/uI4xeh/72SUryiO5pEjnagYKjIn
b7+QNYpSYxpBDSQCtA4hDn0YlB2HzgR2Is3d5svD2MP5u0jOx6MsiHwr5e7kfKgOI87HG9PB15hS
OvTWdgOtoGFyNFmpZEwcEukv1ile9wLn480A97AijB2NmogN4pDomGnVJeejoyEvlbdHIZR5gES2
tLEncXOaJU9yDVOYc9o8UBr10FEwtHggyi/OaylZ5yIgbv64edKspdADVtFVWSw7CVPSluw8crs4
EhdTdSOllZ0IOFRmT3Xbs7pR3QPCOEV9IpNKzdWFYCPKTKsTgWRLj90IzXzggsVJLjmUuJBLFZVY
Z1QOKewQgDgWxos6p3jnKV6L2QkwW1kaVv2uuHp59s6ut50dR1w1cSEuXzyhPJnL4VyDmVUnUa/J
DrHWxHtcjfxjLalzd6qh8/w6ksMzj0ld/SyNCY4NnMvlSZS2a3sPtE9txYV0yKbObEbueCyvpssw
DMjx9ERBPfWAfrhMW1R3KKwZP5ZCOJQjNt3LtnFit0Vslr3ZJqxk068ZeiGKZDAPsTe/Tdze8cy2
ij15U46gy+K1lArUpSId9JI40hSw6wiX6sB54mxB7S02mftej5df5CLIUgLsKwP3MlA2YNGc1IRc
tIC7s+f3aDZFvlfge2yWlFO+KnlNEwzSh2B7SBQhtQD4ZVEnFxNZNuvIrjZii9IQg20jexbce8q0
K57mkMhYSyIiFwj4gayQUClZk6RYgjNqgFVccNCSjB/f/xhMj8AzgDwZU1JdjKMlj1WpXxQalY5K
jOJVZ3ZqdjfdMCYLHZkvrMc1ugGD7HykXJDefCSfatxpwUskr3Zeevq89NRGpNeAlio7kQTLaCpa
HNcykbSXhL+2yuZKc4NJhDQSgmvAC1hEZ7gKwitKxl5gNiSBaCmvkFWnd+LdMY9Ky5GQ+mJhtR/4
J8JHeM0J5ncxoc7qAC8cDOhi5Lf5vescI2++ffn44Qls4ZDPrqqx0jlTCmIJcwRH3UId5x1zBIcg
sUBw9gSCs/AV2W1QXleQH68TBHfJvREWWxHGCK4xoIrgchisSp6v8wIEV7afeFBxmgozBFfYwbOI
7cKck9jEM4Kz/xcEB/ROqf+g0SjYLVNfcsDaLOgtz2wywMl1z5WiQLcwwzClx/AN0BZnlXm5jZek
81UV6ZxkUAVvY/7gYBHAUfsxNuIN+xq5vd9MfuH9lfjxF+C4qYY6cxlnXYXguJAGYm6GrwH1UN/T
y6+LmuXxGjY6kokEUOqWVRfd+xSTT66ftsObkVpOK/F42r+5EUXjXMDAu3FU08SbtP6cim1zDwKA
LEVJiYIT24uDVo0gprKpBGwOxbMUlD2Jhb+z9M1CT+VlAH0kUPjIgiotqNjgpXb+IkXG9tOYH/C5
ShjI+nitbsbuZLTdsdH2ydHOtb3Hvo4yDnwOAzIKIaiS0ZiSMRBSxyhXBkCHnwYhvLYZAyE8KquR
zODzG5b+ObA84FVxpoS+JerxBp/CzfRes3xGIq81m49BGrGf3KN5u1k2QWWovCul7l5dMtaTGy6M
Vt5xstGSjMtnJT/+ilOCOjjG8ess1L74PnzA5wWZn5bSD0gMcEnGTsLt9kuauZYMSNKAH0KfAXdC
GZtKF6oMSDyY11oTCo6oQuCTnwedCF7l8ohJXAKdxvB+liy6pHLNKgmU5wlDkYpqKivCgNVq9GVi
MclznQWZ3GzdJZemBnwgMt295QSsovLFk/k28+QJtFjY40o1aPnFUt8NCS6SwgJ/hrZQMJQFl8BT
wVVdLghWdEnA84UwMXtgGLan4h+qdCQ3ZCwlteKxF3hyKmymnupCz+zU7B4A1EcqpC0WFutsLDxS
jt+jQkBfJY2+fLa34Nf5NKu+mBRnLQ2JpwLUGY2fT7PURmLE/5hmVbIkE5AYMk+zfv4P7GCgdwpl
bmRzdHJlYW0KZW5kb2JqCjUgMCBvYmoKMzE2OQplbmRvYmoKMiAwIG9iago8PCAvVHlwZSAvUGFn
ZSAvUGFyZW50IDMgMCBSIC9SZXNvdXJjZXMgNiAwIFIgL0NvbnRlbnRzIDQgMCBSIC9NZWRpYUJv
eCBbMCAwIDkwMiA1NTVdCi9Sb3RhdGUgMCA+PgplbmRvYmoKNiAwIG9iago8PCAvUHJvY1NldCBb
IC9QREYgL1RleHQgL0ltYWdlQiAvSW1hZ2VDIC9JbWFnZUkgXSAvQ29sb3JTcGFjZSA8PCAvQ3Mx
IDcgMCBSCi9DczIgMjQgMCBSID4+IC9Gb250IDw8IC9UVDEgMjUgMCBSIC9UVDIgMjYgMCBSID4+
IC9YT2JqZWN0IDw8IC9JbTggMjIgMCBSCi9JbTEgOCAwIFIgL0ltMyAxMiAwIFIgL0ltNCAxNCAw
IFIgL0ltMiAxMCAwIFIgL0ltNyAyMCAwIFIgL0ltNiAxOCAwIFIgL0ltNQoxNiAwIFIgPj4gPj4K
ZW5kb2JqCjIyIDAgb2JqCjw8IC9MZW5ndGggMjMgMCBSIC9UeXBlIC9YT2JqZWN0IC9TdWJ0eXBl
IC9JbWFnZSAvV2lkdGggMTMwIC9IZWlnaHQgMTM1IC9JbnRlcnBvbGF0ZQp0cnVlIC9Db2xvclNw
YWNlIDI3IDAgUiAvU01hc2sgMjggMCBSIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxh
dGVEZWNvZGUKPj4Kc3RyZWFtCngB7dAxAQAAAMKg9U/tbwaIQGHAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgIEfGM2qAAEKZW5kc3RyZWFtCmVu
ZG9iagoyMyAwIG9iagoyNTMKZW5kb2JqCjggMCBvYmoKPDwgL0xlbmd0aCA5IDAgUiAvVHlwZSAv
WE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDEzMCAvSGVpZ2h0IDYwIC9JbnRlcnBvbGF0
ZQp0cnVlIC9Db2xvclNwYWNlIDI3IDAgUiAvU01hc2sgMzAgMCBSIC9CaXRzUGVyQ29tcG9uZW50
IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUKPj4Kc3RyZWFtCngB7dABDQAAAMKg909tDjeIQGHAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDgb2BbaAABCmVuZHN0cmVhbQpl
bmRvYmoKOSAwIG9iagoxMjUKZW5kb2JqCjEyIDAgb2JqCjw8IC9MZW5ndGggMTMgMCBSIC9UeXBl
IC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMTMwIC9IZWlnaHQgNTEgL0ludGVycG9s
YXRlCnRydWUgL0NvbG9yU3BhY2UgMjcgMCBSIC9TTWFzayAzMiAwIFIgL0JpdHNQZXJDb21wb25l
bnQgOCAvRmlsdGVyIC9GbGF0ZURlY29kZQo+PgpzdHJlYW0KeAHt0IEAAAAAw6D5U1/gCIVQYcCA
AQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMG
DBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQN/YE2yAAEKZW5kc3RyZWFtCmVuZG9iagoxMyAwIG9i
agoxMTAKZW5kb2JqCjE0IDAgb2JqCjw8IC9MZW5ndGggMTUgMCBSIC9UeXBlIC9YT2JqZWN0IC9T
dWJ0eXBlIC9JbWFnZSAvV2lkdGggMzkgL0hlaWdodCA3MCAvSW50ZXJwb2xhdGUKdHJ1ZSAvQ29s
b3JTcGFjZSAyNyAwIFIgL1NNYXNrIDM0IDAgUiAvQml0c1BlckNvbXBvbmVudCA4IC9GaWx0ZXIg
L0ZsYXRlRGVjb2RlCj4+CnN0cmVhbQp4Ae3QAQ0AAADCoPdPbQ43iEBhwIABAwYMGDBgwIABAwYM
GDBgwIABAwYMGDBgwIABAwYMfA8MH/4AAQplbmRzdHJlYW0KZW5kb2JqCjE1IDAgb2JqCjU5CmVu
ZG9iagoxMCAwIG9iago8PCAvTGVuZ3RoIDExIDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAv
SW1hZ2UgL1dpZHRoIDEzMCAvSGVpZ2h0IDQ5IC9JbnRlcnBvbGF0ZQp0cnVlIC9Db2xvclNwYWNl
IDI3IDAgUiAvU01hc2sgMzYgMCBSIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVE
ZWNvZGUKPj4Kc3RyZWFtCngB7dAxAQAAAMKg9U/tbwaIQGHAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDgBwZKpgABCmVuZHN0cmVhbQplbmRvYmoKMTEgMCBvYmoKMTA3CmVuZG9iagoyMCAwIG9iago8
PCAvTGVuZ3RoIDIxIDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDM5
IC9IZWlnaHQgNzAgL0ludGVycG9sYXRlCnRydWUgL0NvbG9yU3BhY2UgMjcgMCBSIC9TTWFzayAz
OCAwIFIgL0JpdHNQZXJDb21wb25lbnQgOCAvRmlsdGVyIC9GbGF0ZURlY29kZQo+PgpzdHJlYW0K
eAHt0AENAAAAwqD3T20ON4hAYcCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDBgwYMCAAQMGDHwPDB/+
AAEKZW5kc3RyZWFtCmVuZG9iagoyMSAwIG9iago1OQplbmRvYmoKMTggMCBvYmoKPDwgL0xlbmd0
aCAxOSAwIFIgL1R5cGUgL1hPYmplY3QgL1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAxMzAgL0hlaWdo
dCA2MCAvSW50ZXJwb2xhdGUKdHJ1ZSAvQ29sb3JTcGFjZSAyNyAwIFIgL1NNYXNrIDQwIDAgUiAv
Qml0c1BlckNvbXBvbmVudCA4IC9GaWx0ZXIgL0ZsYXRlRGVjb2RlCj4+CnN0cmVhbQp4Ae3QAQ0A
AADCoPdPbQ43iEBhwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg
wIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBgwIABAwYMGDBg4G9g
W2gAAQplbmRzdHJlYW0KZW5kb2JqCjE5IDAgb2JqCjEyNQplbmRvYmoKMTYgMCBvYmoKPDwgL0xl
bmd0aCAxNyAwIFIgL1R5cGUgL1hPYmplY3QgL1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAzOSAvSGVp
Z2h0IDcwIC9JbnRlcnBvbGF0ZQp0cnVlIC9Db2xvclNwYWNlIDI3IDAgUiAvU01hc2sgNDIgMCBS
IC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUKPj4Kc3RyZWFtCngB7dAB
DQAAAMKg909tDjeIQGHAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgx8Dwwf/gABCmVu
ZHN0cmVhbQplbmRvYmoKMTcgMCBvYmoKNTkKZW5kb2JqCjQwIDAgb2JqCjw8IC9MZW5ndGggNDEg
MCBSIC9UeXBlIC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMTMwIC9IZWlnaHQgNjAg
L0NvbG9yU3BhY2UKL0RldmljZUdyYXkgL0ludGVycG9sYXRlIHRydWUgL0JpdHNQZXJDb21wb25l
bnQgOCAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHtmf9LE2Ecx3dfnt1tz+22c3c7
PJlbnoqzS5sbwsqGuHID02JDMuYGGinSwLK5HxJWgWMSjRIxh4EZzQWj2Cg0w0X/WrfC3Qz68ZF+
uNcP9+u9n/fzeb583o/BoPM/OoAh5d8jxjAcJ0gSnAMkSeA4hp3Vov6eBBRthpBhLEhhGAjNNAVI
VUSrBpwANGRtbbzgEBHjEPg2GwtpQLRKwAmjycI5JKe7S+5GjNzldkoOzmIyErhmAg5MrF1y9/QP
eH1+xPi8A/09bsnOmoBmAkbSFrskK75AMDQejiAlPB4KBnyKLNktNNmsBBxArl0eCIQmojPxJGLi
M9GJUGBAbucgaE4DTlkEtxIIx5ILqUfpVaSkH6UWkrFwQHELFkpTQFvbe3yh2Fwqk13PbyAlv57N
pOZiIV9Pu5UmTkuRMHFOT2AikXqSK2ztFJGys1XIPUklJgIeJ2cmTxWQZrvrUjB6P5N7vfu+VEZK
6f3u61zmfjR4yWWHmgLIX7g8dieVLeyWKtUaUqqV0m4hm7ozdvkCD0HTAyjIQzfiD9e39itfjo6R
cvSlsr+1/jB+Y0gWmBYFDtkfTjzO75SqRyd1pJwcVUs7+ceJsF92aAoAI3b7I8nVjWK5dlz/iZT6
ca1c3FhNRvzdogWcbkm6AoNB90D3oLEr6XWge6DXwZ/zWV8L+lrQ14K+FvR7onZXJmGjX0im88WD
2rf6D6TUv9UOivl08my/0FDgG59dyW1/+Hz4/QQp3w8/f9jOrcyO+1o7FhIKXd7rd5efb+59rH49
RMrX6se9zefLd697u850bbx7cHR6ae3Fm3flyiekVMrv3rxYW5oeHXS3dK6Eua1TGbk1v/Ls5fbb
vX2k7L3dfvlsZf7WiNLZpuUHBM119A2HZxbT2Xzh1SZSXhXy2fTiTHi4r4MzNTMUnGZFeTA4FV9Y
zqxlnyIlu5ZZXohPBQdlkdVSHNzI8M4+/+jN6cS9xaUHSFlavJeYvjnq73PyjLGZZGHAZHW4PENX
xyKTt6MxpERvT0bGrg55XA6rGmn+OZcMBowwQk7s7FW8w1dGrgWRcm3kyrBX6e0UOUgRp8eCwYCr
ubZNkFxyr+eigpiLnl7ZJQk2NdtuWqCagAPKzHK8KHU4kdMhiTzHQqolVlYnA1OfF2gzw1ptHHJs
VpYx00ZSy7V/V0PjhQUAI0WfA5QRqI8LfwloqFCfl/BzQv3V73HrH92BpgO/AE1NJ+AKZW5kc3Ry
ZWFtCmVuZG9iago0MSAwIG9iago5MjYKZW5kb2JqCjM2IDAgb2JqCjw8IC9MZW5ndGggMzcgMCBS
IC9UeXBlIC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMTMwIC9IZWlnaHQgNDkgL0Nv
bG9yU3BhY2UKL0RldmljZUdyYXkgL0ludGVycG9sYXRlIHRydWUgL0JpdHNQZXJDb21wb25lbnQg
OCAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHtmO9LGnEcx8/7oeedd3V6al5JZ6dG
YqLpGrZhNDctDAaGFIhXLRKCA4vM2ohiYFw0amMu+uGTNZyDNkgKWmPB/rWdgzwj9vAbPfD18B7c
533v74f7fL5vCGrxEB3QAOX/X6zRwDCCotg9gKIIDGs0t7Uo5VFMhxMkaTBQQDEYSJLAdRiqiGjW
ACMYTtLtRtZssQLGYmaN7TSJY0izBBjR6inGwtn5HsEJGKGHt3MWhtJrEVg1Acb0tInjXR5fIBgC
TDDg87h4zkTrMdUEDYpTJk7wBsORaCw+CpR4LBoJB70CZ6JwtNEJMEYyNsEXjiaSU2kRMOmpZCIa
9gk2hsQaxwDrKDPvDccnxKy0lF8BSn5JyooT8bCXN1M6VQHeZnMFoxOzUmGjKG8DRS5uFKTZiWjQ
ZWvDkZtWRPSMvS+cyEhvtnZLB4dAOSjtbr2RMolwn50h0BsFKGHq7o8k5wtbH45PKlWgVE6OP2wV
5pOR/m4TqSogWYf/2aS0sXtcOT2rAeXstHK8uyFNPvM7WBJreECahYEX6cVi6fPp+eUVUC7PTz+X
iovpFwOC2dCkwCKE4pll+aBydvn7Gii/L88qB/JyJh4SLKoCzGB1hkbFle3Dau3q+g9Qrq9q1cPt
FXE05LRS2M0vqaUAgloetDyo/5VafdDy4GH0AUrWJ5OYv7/JlBdvT6a6goFYeqn46eT7xc9fQPl5
8f3kU3EpHRtono2osqEEolPS5l7564/aOVBqP76W9zalqWjg1oZCsLxvOJldkz+Wv1S/AaX6pfxR
Xssmh308q25piN5o9wyNi7l1+f3+URkoR/vv5fWcOD7ksRvVTRXG2zl36HlqLvf6rbzzDig78tvX
ubnU85Cba1e3dVhHW3jv0FhqZiGXX10Dymo+tzCTGhvy8hYaV28syq2Nc/qfxF6m0tOzr4AyO51O
vYw98Ts5htQ2FCg3V5rtcvkePR2JjSXGgZIYi408feRzdbF0080VgjGCZjlHr9cfHHwMmMGg39vr
4FiawJCbRRWCYFRL0EZrZ3eP0+3uBYrb7ezp7rQaaUKLNg4BgjSKBCXFYViztcMGmA6rmWWUFEcR
oFpQl4BgWiXIMlA0cCiDEmVpb8dI9fn4L8yrR3lawNRr/Ivz6lXvADTLbHr5ncKtBy0H/gJXk44T
CmVuZHN0cmVhbQplbmRvYmoKMzcgMCBvYmoKODc5CmVuZG9iagozMCAwIG9iago8PCAvTGVuZ3Ro
IDMxIDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDEzMCAvSGVpZ2h0
IDYwIC9Db2xvclNwYWNlCi9EZXZpY2VHcmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9CaXRzUGVyQ29t
cG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB7Zn/SxNhHMd3X57dbc/t
tnN3OzyZW56Ks0ubG8LKhrhyA9NiQzLmBhop0sCyuR8SVoFjEo0SMYeBGc0Fo9goNMNF/1q3wt0M
+vGRfrjXD/frvZ/383m+fN6PwaDzPzqAIeXfI8YwHCdIEpwDJEngOIad1aL+ngQUbYaQYSxIYRgI
zTQFSFVEqwacADRkbW284BAR4xD4NhsLaUC0SsAJo8nCOSSnu0vuRozc5XZKDs5iMhK4ZgIOTKxd
cvf0D3h9fsT4vAP9PW7JzpqAZgJG0ha7JCu+QDA0Ho4gJTweCgZ8iizZLTTZrAQcQK5dHgiEJqIz
8SRi4jPRiVBgQG7nIGhOA05ZBLcSCMeSC6lH6VWkpB+lFpKxcEBxCxZKU0Bb23t8odhcKpNdz28g
Jb+ezaTmYiFfT7uVJk5LkTBxTk9gIpF6kits7RSRsrNVyD1JJSYCHidnJk8VkGa761Iwej+Te737
vlRGSun97utc5n40eMllh5oCyF+4PHYnlS3slirVGlKqldJuIZu6M3b5Ag9B0wMoyEM34g/Xt/Yr
X46OkXL0pbK/tf4wfmNIFpgWBQ7ZH048zu+UqkcndaScHFVLO/nHibBfdmgKACN2+yPJ1Y1iuXZc
/4mU+nGtXNxYTUb83aIFnG5JugKDQfdA96CxK+l1oHug18Gf81lfC/pa0NeCvhb0e6J2VyZho19I
pvPFg9q3+g+k1L/VDor5dPJsv9BQ4BufXcltf/h8+P0EKd8PP3/Yzq3MjvtaOxYSCl3e63eXn2/u
fax+PUTK1+rHvc3ny3eve7vOdG28e3B0emntxZt35conpFTK7968WFuaHh10t3SuhLmtUxm5Nb/y
7OX22719pOy93X75bGX+1ojS2ablBwTNdfQNh2cW09l84dUmUl4V8tn04kx4uK+DMzUzFJxmRXkw
OBVfWM6sZZ8iJbuWWV6ITwUHZZHVUhzcyPDOPv/ozenEvcWlB0hZWryXmL456u9z8oyxmWRhwGR1
uDxDV8cik7ejMaREb09Gxq4OeVwOqxpp/jmXDAaMMEJO7OxVvMNXRq4FkXJt5MqwV+ntFDlIEafH
gsGAq7m2TZBccq/nooKYi55e2SUJNjXbblqgmoADysxyvCh1OJHTIYk8x0KqJVZWJwNTnxdoM8Na
bRxybFaWMdNGUsu1f1dD44UFACNFnwOUEaiPC38JaKhQn5fwc0L91e9x6x/dgaYDvwBNTSfgCmVu
ZHN0cmVhbQplbmRvYmoKMzEgMCBvYmoKOTI2CmVuZG9iago0MiAwIG9iago8PCAvTGVuZ3RoIDQz
IDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDM5IC9IZWlnaHQgNzAg
L0NvbG9yU3BhY2UKL0RldmljZUdyYXkgL0ludGVycG9sYXRlIHRydWUgL0JpdHNQZXJDb21wb25l
bnQgOCAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHtlu9LGnEcx71fevr1Li89D2/d
cl2uFbfKdIOrJpGbCjUEJdawhAZzFEJbaQ8KrCBR+sGSiqSgGZkDaSiF5VDoX9tdwx8L9nyMXg/u
0fv7+f7gPp/3W6H4J4Ag6O/ngCAYRlAUq4GiCAzfXyBpUEyFawDQagmC0GoB0OAqDJWUzZVhBMMB
qWs10EZGxkgbWnUkwDGkWQcjSjVBGVnO3MF3yvAdZo41UoRaicCNcjCmJvWs2dLTa7XZZWzW3h6L
mdWTaqxRDkJxQs/ygk10OF1uj8fjdjkdok3gWT2Bo/XTwRigTHyv6BzzTQaCMoFJ35hT7OVNFMDq
u8IqgjYLotsfDIW/RKLRaORLOBT0u0XBTBOqhgxvMVlsTv9MeCm2kUgmk4mN2FJ4xu+0WUwtOFK7
A6KmuG5xbDq8HN/ZO0yn04d7O/Hl8PSY2M1RGrQmQzX69ucO38el+O7RaTaXy2VPj3bjSx99juft
etCQAcOT/tF34djOUTZfKBaLhXz2aCcWfjfa/8QAsHo1QPMDbwKfN/Yy+cvrcrl8fZnP7G18DrwZ
4Gltk8zI293Ti4nDbOG6Uq1WK9eF7GFicdpt540NGaZlOu2eYDSZzhXL1dvb22q5mEsno0GPvZMh
sNr7PsgeHuThD/ndgg+98P/1AgrkaRmMJNLnxZu7MXhTPE8nIsE/p6Uss7mmFuIHZz9KPyuVys/S
j7OD+MKUy9Y8VFFAd1hfv59fT518L1yVSqWrwveT1Pr8+9fWDrp5khvMfSMTsyubB99y+YuLi3zu
28HmyuzESJ+5aeAjmlZOGPbOLKxt7R+fZDKZk+P9rbWFGe+wwLU2XAbBqUddL92TnyKxxPbXVCr1
dTsRi3yadL/sekSp654F4yTD9zneBkLz0ZXY6upqbCU6Hwq8dfTxDNmwNlgJ9FyXfWR8YupDaHZu
bm429GFqYnzE3sXpgbJulJDk4cbHz6yDo55xr0/GO+4ZHbQ+e2yUXbzmWRCiBDqGswjWF+LQK5kh
8YVVsHCMDiiRmskoFDCKAx3NtvNPu3sEmZ7up3w7S+sAjtaLKRQQjKk0JGVgTGwbJ9PGmhgDRWpU
TcFB2huSQo2UaQhSR/1GRxJSrpFiTWNL+YhyQsIwpQqvoVJiUqS5p7q7jJymmrifo+40/+LnF23M
gXAKZW5kc3RyZWFtCmVuZG9iago0MyAwIG9iago4NzgKZW5kb2JqCjI4IDAgb2JqCjw8IC9MZW5n
dGggMjkgMCBSIC9UeXBlIC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMTMwIC9IZWln
aHQgMTM1IC9Db2xvclNwYWNlCi9EZXZpY2VHcmF5IC9JbnRlcnBvbGF0ZSB0cnVlIC9CaXRzUGVy
Q29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB7ZvLTxpRGMVhHhXm
AR1eIlFBBhdY1PJIlIXGSgpWNwoxtkFJG60LnURtxTSNmhihuCip0bRM3JS2owuSCrpA09L4r3VG
ioBNl7dp0u8siKzm83DP4d4bfioV6F90QI1Uf/6P1WoMwwmC/AsiCBzD1OrmWeTHE2SLhqJphmGR
imFomtK0kIQ8ROMMGE5qaN1dg8lsaUUsi9lkuKujNSTeOAKG39GynMXW4XDyLsTinY4Om4VjtXdw
rG4CRmp1Rpuju6fP6w8glt/b19PtsBl1WrJugprQsEYb7/EHh0PhyBhSRcKh4aDfw9uMrIa4WQkY
SXNtfF8wNBF9HE8gVvxxdCIU7OPbOJq8+RiwFtbs8AQjscSisLaeRKr1NWExEYsEPQ4z21KfQKNv
6/aHYs+Eje1UZg+pMqntDeFZLOTvbtNr8NpSxLVchzs4MSe8TmcPcyJS5Q6z6dfC3ETQ3cFRRG0C
gjLae4ejzzfS+0efpBOkkj4d7ac3nkeHe+1Guj4Bbeq6PzojbGePpEKxhFTFgnSU3RZmRu93mWjy
xgPazPsexldTh/nCefkSqcrnhfxhajX+0MebmYYJLHwgMvcyk5OK5e8VpPpeLkq5zMu5SIC31Ccg
mVZXYCyR3BNPSpeVK6SqXJZOxL1kYizgamXJWiXBBCoVeAAeKK0E6wA8gHVQ/X6GLEAWIAuQBdgn
wl4ZzgtwZoJzI5yd4f4A7lCursAD8EC5qIR1AB7AOqhe2UMWIAuQBchC1QHIAmQBsgBZqDkAfQB9
AH1QSwPslaEPoA+gD6APag5AH0AfQB/U0gD7A+gD6APoA+iDmgPQB/92HygUSWI9Ix6XLio/kKpy
UToWM+uJZoqEoOUJwjLH8kE6LX9DirFUvpVPpQ8yxxJu4liIXyzP7kG+cFa+QKryWSF/sPs7y3PN
My1vZcXPha9FpPpa+Cxmt5Zv8Uy4wnQNTS0kU+/Ej18kpPryUXyXSi5MDTUxXTLX1u4eHJ8VXqXe
HrzPIdX7g7epV8Ls+KC7vYFrw2S2z+UbjT5dTm7upN8gVXpnM7n8NDrqczWyfQrfaL83GI7G55dW
XiDWytJ8PBoevGdv4htJirM6ewcePJqcfhKfRar4k+nJRw8Gep1WjqoznjLnyhhszh7vwNBIKIxY
oZGhAW+P02ZgGjhXlcz6sgar3eX29Ht9fqTyefs9bpfdamBl1rf6g23lVQGuGc5kbe+UgWfEcjo6
260mjlGQ6/oE1yNQrJ4zytA3YplNRk7PUrcGkF245t61MviOXpS2yr03OHD9p8L+y/A/cvpffgSu
sP+3nw/v/3MHfgJjBA/kCmVuZHN0cmVhbQplbmRvYmoKMjkgMCBvYmoKOTk4CmVuZG9iagozMiAw
IG9iago8PCAvTGVuZ3RoIDMzIDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1hZ2UgL1dp
ZHRoIDEzMCAvSGVpZ2h0IDUxIC9Db2xvclNwYWNlCi9EZXZpY2VHcmF5IC9JbnRlcnBvbGF0ZSB0
cnVlIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB
7ZixT+JQHMdL+56UvhZFaEmbEKuFQYNELUsXBhuFhA0GTUiJDjp10CAMDkwQWEhMGCBMmBAGFogD
IZHk/rWreFDOuxsfNbl+hqad+u33vba/75cgXL6jAx6s/PuJPR6SpACAGwAAiiQ9nt+1WLcH0Esz
CLEshxWWRYihvRBYItY1kBSkkX9nN8QLYcwIfGh3x49oSK1LIKktHxcQpIh8oEQxoxzIEUkIcL4t
irRNIKHPH5Tk2FHiVE1iRj1NHMVkKej3QdsED6C5oKTEVS2lX6YzWElf6ilNjStSkKPBaieQEAVE
JaHp2dx1oYiZwnUuq2sJRQwguFoG0svxclxL54v35uNTGStPj+Z9MZ/W4jLPeW0F9LYYU/X8rVmp
1hpNrDRq1Yp5m9fVmLhNU8utSPkCkUMta5jP9Va708VKp92qP5tGVjuMBBiwVACY4N5xKndXqb/0
XgdDrAxeey/1yl0udbwXRLYCFNo/Ob8yq63eYDSeYGU8GvRaVfPq/GQ/hODKA8QrZxeFh1q7P3qb
zrAyfRv127WHwsWZwrNrCgQlmTZKjc5gPH2fY+V9Oh50GiUjnVQEWwFkw9FkplhudoeT2fwHVuaz
ybDbLBczyWiYg8tPkquAIFwPXA8+vkruPnA9cPfB5//ZfRcIAiCn5wPwDWYkp+dEam1W7uOelft/
m5Wdzwvkr8x0s6nMdPM1M61yo2HlxhLW2FguWbnR+DM3QsaJ7MzY2dn5/oBYdCjiJjsUcdGhfP4U
Po7O90iWBIe7NMsFu09kMbPqE+01WJw53al+keNe/ncO/AQ+13PACmVuZHN0cmVhbQplbmRvYmoK
MzMgMCBvYmoKNjExCmVuZG9iagozNCAwIG9iago8PCAvTGVuZ3RoIDM1IDAgUiAvVHlwZSAvWE9i
amVjdCAvU3VidHlwZSAvSW1hZ2UgL1dpZHRoIDM5IC9IZWlnaHQgNzAgL0NvbG9yU3BhY2UKL0Rl
dmljZUdyYXkgL0ludGVycG9sYXRlIHRydWUgL0JpdHNQZXJDb21wb25lbnQgOCAvRmlsdGVyIC9G
bGF0ZURlY29kZSA+PgpzdHJlYW0KeAHtlu9LGnEcx71fevr1Li89D2/dcl2uFbfKdIOrJpGbCjUE
JdawhAZzFEJbaQ8KrCBR+sGSiqSgGZkDaSiF5VDoX9tdwx8L9nyMXg/u0fv7+f7gPp/3W6H4J4Ag
6O/ngCAYRlAUq4GiCAzfXyBpUEyFawDQagmC0GoB0OAqDJWUzZVhBMMBqWs10EZGxkgbWnUkwDGk
WQcjSjVBGVnO3MF3yvAdZo41UoRaicCNcjCmJvWs2dLTa7XZZWzW3h6LmdWTaqxRDkJxQs/ygk10
OF1uj8fjdjkdok3gWT2Bo/XTwRigTHyv6BzzTQaCMoFJ35hT7OVNFMDqu8IqgjYLotsfDIW/RKLR
aORLOBT0u0XBTBOqhgxvMVlsTv9MeCm2kUgmk4mN2FJ4xu+0WUwtOFK7A6KmuG5xbDq8HN/ZO0yn
04d7O/Hl8PSY2M1RGrQmQzX69ucO38el+O7RaTaXy2VPj3bjSx99juftetCQAcOT/tF34djOUTZf
KBaLhXz2aCcWfjfa/8QAsHo1QPMDbwKfN/Yy+cvrcrl8fZnP7G18DrwZ4Gltk8zI293Ti4nDbOG6
Uq1WK9eF7GFicdpt540NGaZlOu2eYDSZzhXL1dvb22q5mEsno0GPvZMhsNr7PsgeHuThD/ndgg+9
8P/1AgrkaRmMJNLnxZu7MXhTPE8nIsE/p6Uss7mmFuIHZz9KPyuVys/Sj7OD+MKUy9Y8VFFAd1hf
v59fT518L1yVSqWrwveT1Pr8+9fWDrp5khvMfSMTsyubB99y+YuLi3zu28HmyuzESJ+5aeAjmlZO
GPbOLKxt7R+fZDKZk+P9rbWFGe+wwLU2XAbBqUddL92TnyKxxPbXVCr1dTsRi3yadL/sekSp654F
4yTD9zneBkLz0ZXY6upqbCU6Hwq8dfTxDNmwNlgJ9FyXfWR8YupDaHZubm429GFqYnzE3sXpgbJu
lJDk4cbHz6yDo55xr0/GO+4ZHbQ+e2yUXbzmWRCiBDqGswjWF+LQK5kh8YVVsHCMDiiRmskoFDCK
Ax3NtvNPu3sEmZ7up3w7S+sAjtaLKRQQjKk0JGVgTGwbJ9PGmhgDRWpUTcFB2huSQo2UaQhSR/1G
RxJSrpFiTWNL+YhyQsIwpQqvoVJiUqS5p7q7jJymmrifo+40/+LnF23MgXAKZW5kc3RyZWFtCmVu
ZG9iagozNSAwIG9iago4NzgKZW5kb2JqCjM4IDAgb2JqCjw8IC9MZW5ndGggMzkgMCBSIC9UeXBl
IC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMzkgL0hlaWdodCA3MCAvQ29sb3JTcGFj
ZQovRGV2aWNlR3JheSAvSW50ZXJwb2xhdGUgdHJ1ZSAvQml0c1BlckNvbXBvbmVudCA4IC9GaWx0
ZXIgL0ZsYXRlRGVjb2RlID4+CnN0cmVhbQp4Ae2W70sacRzHvV96+vUuLz0Pb91yXa4Vt8p0g6sm
kZsKNQQl1rCEBnMUQltpDwqsIFH6wZKKpKAZmQNpKIXlUOhf213DHwv2fIxeD+7R+/v5/uA+n/db
ofgngCDo7+eAIBhGUBSrgaIIDN9fIGlQTIVrANBqCYLQagHQ4CoMlZTNlWEEwwGpazXQRkbGSBta
dSTAMaRZByNKNUEZWc7cwXfK8B1mjjVShFqJwI1yMKYm9azZ0tNrtdllbNbeHouZ1ZNqrFEOQnFC
z/KCTXQ4XW6Px+N2OR2iTeBZPYGj9dPBGKBMfK/oHPNNBoIygUnfmFPs5U0UwOq7wiqCNgui2x8M
hb9EotFo5Es4FPS7RcFME6qGDG8xWWxO/0x4KbaRSCaTiY3YUnjG77RZTC04UrsDoqa4bnFsOrwc
39k7TKfTh3s78eXw9JjYzVEatCZDNfr25w7fx6X47tFpNpfLZU+PduNLH32O5+160JABw5P+0Xfh
2M5RNl8oFouFfPZoJxZ+N9r/xACwejVA8wNvAp839jL5y+tyuXx9mc/sbXwOvBngaW2TzMjb3dOL
icNs4bpSrVYr14XsYWJx2m3njQ0ZpmU67Z5gNJnOFcvV29vbarmYSyejQY+9kyGw2vs+yB4e5OEP
+d2CD73w//UCCuRpGYwk0ufFm7sxeFM8TyciwT+npSyzuaYW4gdnP0o/K5XKz9KPs4P4wpTL1jxU
UUB3WF+/n19PnXwvXJVKpavC95PU+vz719YOunmSG8x9IxOzK5sH33L5i4uLfO7bwebK7MRIn7lp
4COaVk4Y9s4srG3tH59kMpmT4/2ttYUZ77DAtTZcBsGpR10v3ZOfIrHE9tdUKvV1OxGLfJp0v+x6
RKnrngXjJMP3Od4GQvPRldjq6mpsJTofCrx19PEM2bA2WAn0XJd9ZHxi6kNodm5ubjb0YWpifMTe
xemBsm6UkOThxsfPrIOjnnGvT8Y77hkdtD57bJRdvOZZEKIEOoazCNYX4tArmSHxhVWwcIwOKJGa
ySgUMIoDHc2280+7ewSZnu6nfDtL6wCO1ospFBCMqTQkZWBMbBsn08aaGANFalRNwUHaG5JCjZRp
CFJH/UZHElKukWJNY0v5iHJCwjClCq+hUmJSpLmnuruMnKaauJ+j7jT/4ucXbcyBcAplbmRzdHJl
YW0KZW5kb2JqCjM5IDAgb2JqCjg3OAplbmRvYmoKNDQgMCBvYmoKPDwgL0xlbmd0aCA0NSAwIFIg
L04gMyAvQWx0ZXJuYXRlIC9EZXZpY2VSR0IgL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFt
CngBhVVbiBtVGP6TOckKu87T2tUtpEO9dCm7S7YV3aW0mluTtGsastnVFkGzk5NkzOwkzkzSC30q
guKLq75JQby9LQiC0nrB1gf7UqlQVnfrIig+tHhBKPRFt/E7k2QmWWqbZc988/3f+W/nnxmigbVC
va77FaIlwzZzyajy3NFjysA6+ekhGqRRGiyoVj2Szc4SfkIrrv2/Wz+QTzBXJ+5s71dvuRsscksl
8t0Hvla01CXgE0SBs2rdtIkGhsFPH7frAoschk0kCPyiwOU2ho2GF9v4NUeTz8WgOQssq5VCEXgF
eHyxhy/34HYOUMBPkhvc1FRF9CJr1kqazh1De7mHuUd5N7ikN1Cz89uBdciqzh3GdQy1v1IsxAWe
BF5RC4k54EeArzW1hUwH367b0RzwY0T+nY3qfAR4N3CqZB6cB4Yfv1lppLr4nVOV/LPgt4H/xljM
HOnsXVOtGHpJO8HfrvC06G+ISFI0O50Hhh/pgFnLCT1ykEpFHk8AjwO/Xq0dFjnAp/SZ1ZwTvMhn
7VQlJvIU/OWXCoeywKPAv3I9KfSIJf1bt7OdHFjI0DMiLmKxOLeceuGHhexKPgUecZlum/nOXrZc
0g6mO/pPKmZK8GLvtbruzChyC/jNRk7UjliByYKZSALDZyDLjXnRT4GbtOArEKcaLWJVyaBNUihH
SYriWicTlhJppIPhsHIwHHddzYSzz6IqeI2ajs3CmnWU7Z1drUJlsAZdd7QqxUIfUQOeKvQH2Irr
U6EY7hrgyv/jp53LjY6fGhthYbYX//vYLNvPptkMKewp9jQ7wOJgZ9g+13cWe7oViXxuIErbz8uI
yB3dAmq/iBptKmD9BYoaWa6Hvq4sjzbGPMsZ8wVNvfLG3z290rCz6iom+jp65F49D/wWuB5Yxboe
2HB9KIGfAhv4W0dvvFpqnr3TZXFSGk601qfbehZdVQSV6s7OJXRBQ828p+aJXh+XTn/5oBdtlZ17
/urQpdMlY3nUY0UX+KuZWxk6M+6x4R/Df4ZXw++FPwz/Lr0tfSp9JZ2XPpcukyJdkC5KX0vfSh9L
X7j6u82Qe/YkMhdzJfIW09WtsLfXmFg5Km+XH5bj8g75UXnWVSnyiDwlp+RdsGx3z82bb6W3cvTl
KKJ1+3PnWOJZ0VxPOAPf/ZgAzYvYNwPzyFij4/Bpot9i3gw6CW3vk9epiIXYFEtvme5pMfNd38FE
MB6MkBLcHZwJTgUPCdx9loO7YJvBmujNDfPhKvoq5TY/Ib4nFKvVT5pauWIre8LhJ5UIPn1cSRvq
5LhS0HXFMVmKyS1uNnlxksR3U+wjuplzvoe+bVc8zn6GaP9fePd973HHGkQrFtHI4x43hnflA+8S
nXtCbZjNtj/y+b4jskp79zj3vqEo3l8/t1o38R4beIto881W65/3W63ND+B/g+iC/h+gn3xVCmVu
ZHN0cmVhbQplbmRvYmoKNDUgMCBvYmoKMTA3OQplbmRvYmoKNyAwIG9iagpbIC9JQ0NCYXNlZCA0
NCAwIFIgXQplbmRvYmoKNDYgMCBvYmoKPDwgL0xlbmd0aCA0NyAwIFIgL04gMSAvQWx0ZXJuYXRl
IC9EZXZpY2VHcmF5IC9GaWx0ZXIgL0ZsYXRlRGVjb2RlID4+CnN0cmVhbQp4AYVVXWgcVRQ+u3Nn
AxIHH7QNLbSDP20J6TKJVhOLtdtNukkTt+tmU5sqynR2NjvNZGacmd0moU+l4JsWBOmroD7Gggi2
KjYv9qWlxZJKNQ8KEVqMICh9UvA7M9tkdkEyw5357rnnnnvOd+65l6jrb93z7LRKNOeEfqGcmz45
fUrtuk1pUqib8OhG4OVKpQnGjuuY/G9/Ht6lFEvu7Gdb7WNb9uSqGRjQuobmVgNjjiilEWVqhueH
RF2XIB88G3qMbwM/OVsp54HXgJXWXEB6qmA6pm8ZasHXF9SS79YsO+nrVuNsY8tnzm6wr/zsRusO
ZifH8e+FzxdMZ2oSeB/wkqGPMO4Dvtu0ThRjnE574ZFyrJ/ONmanci35yZp/dKolv1BvjDLOEqWX
FuuVN4CfAF51ThePt/TXZ91xttNDJPUYQf4U8LPAWt0c4zypwBXfLbM+y8OqOTwC/DLwJSscqwDD
vvRD0JxkObCgxXqe/cRaIntGP1YC3gZ8yLQLvBbsiIoXltjmIPC8Yxd5LcQuLptBFC9iFz+F9cpo
rC+nQ7/Cc58mkvfUrKNjwOBEHq37oyyHP3Lo2dHeehF4yW+UOfY9wGu6P1IAhs3MY1V9mHl+AXiA
TqR0Msml0/ga5NC/iDcgi5oR8sjHWA19mwrQcNB89AxoFYB0WgAqJbRM9FgnnqNSFT2VZqJZQYTY
yv2ob1B+16fUgLRO65DWgV6jXyLJPP1Kc+jnIW1gbKbDbh5eOLQID9gTtvmgZdMV24Umnkc7KCbE
K2JQDJEqXhWHxSExDOmQOBjNib1P+s5+Ptiw9C7WTfq+DA5CrGfDMwescDQBPPgH685Gmgm2Lu5o
7PO8j94/779jGbc++LONvQD6MSe/waILayYl5l4/901PwkN1RXz11p3u6+foeDJLUd6qnVmS1+T7
8gq+9+TVpA35Z3kV7722XD3KC/+Tuc0hRjuSzUHOPJtRtHHGG8AhuKlFc/a3WUyy6bZitGDJQpSd
q7j/ywnzwzy3sVJzLu7wvLc/YzbN94oPi3S+T7usrWufaD9qf2gr2sdAv0sfSl9K30pXpKvSDVKl
a9Ky9J30vfS59DV6X0C6LF3p2Elx7Bu7B37Ge9Zo7TBmhrMUEPPC2swKSx/xdwZjm/kzodVeA527
f2Mt5YiyU3lGGVZ2K88pE0qvckA5rGxXBtD6lVFlL0Z2brBkYz3OgIV/kmeLpiOu4jyxV3Ww58NL
He+mX1zD1oY12Ek9Dp7Z2qYOrxFXvxVVY7w7XZwGOk0hYovOInIfOpwfJ6r+ztlckzg1Um/ilLDE
LtEvxlo1mBMHUIXjbfU4yFWaGckMZ3KkZnozQ5n+zDHGUazR+ZLZi9EhfEcS3jPLMf+bNcRnGO8d
5qgJbKOHWys053HfEeVdb8G3ZuqhOqBpL6k5XK+mOuYY2T5Vt201GgpU3wxMv2lWs8R3N88j+uv1
6E5ObbthNPxmLKNU6ibRf7ePkzQKZW5kc3RyZWFtCmVuZG9iago0NyAwIG9iagoxMTE2CmVuZG9i
agoyNCAwIG9iagpbIC9JQ0NCYXNlZCA0NiAwIFIgXQplbmRvYmoKNDggMCBvYmoKPDwgL0xlbmd0
aCA0OSAwIFIgL04gMyAvQWx0ZXJuYXRlIC9EZXZpY2VSR0IgL0ZpbHRlciAvRmxhdGVEZWNvZGUg
Pj4Kc3RyZWFtCngBnZZ3VFPZFofPvTe90BIiICX0GnoJINI7SBUEUYlJgFAChoQmdkQFRhQRKVZk
VMABR4ciY0UUC4OCYtcJ8hBQxsFRREXl3YxrCe+tNfPemv3HWd/Z57fX2Wfvfde6AFD8ggTCdFgB
gDShWBTu68FcEhPLxPcCGBABDlgBwOFmZgRH+EQC1Py9PZmZqEjGs/buLoBku9ssv1Amc9b/f5Ei
N0MkBgAKRdU2PH4mF+UClFOzxRky/wTK9JUpMoYxMhahCaKsIuPEr2z2p+Yru8mYlybkoRpZzhm8
NJ6Mu1DemiXho4wEoVyYJeBno3wHZb1USZoA5fco09P4nEwAMBSZX8znJqFsiTJFFBnuifICAAiU
xDm8cg6L+TlongB4pmfkigSJSWKmEdeYaeXoyGb68bNT+WIxK5TDTeGIeEzP9LQMjjAXgK9vlkUB
JVltmWiR7a0c7e1Z1uZo+b/Z3x5+U/09yHr7VfEm7M+eQYyeWd9s7KwvvRYA9iRamx2zvpVVALRt
BkDl4axP7yAA8gUAtN6c8x6GbF6SxOIMJwuL7OxscwGfay4r6Df7n4Jvyr+GOfeZy+77VjumFz+B
I0kVM2VF5aanpktEzMwMDpfPZP33EP/jwDlpzcnDLJyfwBfxhehVUeiUCYSJaLuFPIFYkC5kCoR/
1eF/GDYnBxl+nWsUaHVfAH2FOVC4SQfIbz0AQyMDJG4/egJ961sQMQrIvrxorZGvc48yev7n+h8L
XIpu4UxBIlPm9gyPZHIloiwZo9+EbMECEpAHdKAKNIEuMAIsYA0cgDNwA94gAISASBADlgMuSAJp
QASyQT7YAApBMdgBdoNqcADUgXrQBE6CNnAGXARXwA1wCwyAR0AKhsFLMAHegWkIgvAQFaJBqpAW
pA+ZQtYQG1oIeUNBUDgUA8VDiZAQkkD50CaoGCqDqqFDUD30I3Qaughdg/qgB9AgNAb9AX2EEZgC
02EN2AC2gNmwOxwIR8LL4ER4FZwHF8Db4Uq4Fj4Ot8IX4RvwACyFX8KTCEDICAPRRlgIG/FEQpBY
JAERIWuRIqQCqUWakA6kG7mNSJFx5AMGh6FhmBgWxhnjh1mM4WJWYdZiSjDVmGOYVkwX5jZmEDOB
+YKlYtWxplgnrD92CTYRm40txFZgj2BbsJexA9hh7DscDsfAGeIccH64GFwybjWuBLcP14y7gOvD
DeEm8Xi8Kt4U74IPwXPwYnwhvgp/HH8e348fxr8nkAlaBGuCDyGWICRsJFQQGgjnCP2EEcI0UYGo
T3QihhB5xFxiKbGO2EG8SRwmTpMUSYYkF1IkKZm0gVRJaiJdJj0mvSGTyTpkR3IYWUBeT64knyBf
JQ+SP1CUKCYUT0ocRULZTjlKuUB5QHlDpVINqG7UWKqYup1aT71EfUp9L0eTM5fzl+PJrZOrkWuV
65d7JU+U15d3l18unydfIX9K/qb8uAJRwUDBU4GjsFahRuG0wj2FSUWaopViiGKaYolig+I1xVEl
vJKBkrcST6lA6bDSJaUhGkLTpXnSuLRNtDraZdowHUc3pPvTk+nF9B/ovfQJZSVlW+Uo5RzlGuWz
ylIGwjBg+DNSGaWMk4y7jI/zNOa5z+PP2zavaV7/vCmV+SpuKnyVIpVmlQGVj6pMVW/VFNWdqm2q
T9QwaiZqYWrZavvVLquNz6fPd57PnV80/+T8h+qwuol6uPpq9cPqPeqTGpoavhoZGlUalzTGNRma
bprJmuWa5zTHtGhaC7UEWuVa57VeMJWZ7sxUZiWzizmhra7tpy3RPqTdqz2tY6izWGejTrPOE12S
Lls3Qbdct1N3Qk9LL1gvX69R76E+UZ+tn6S/R79bf8rA0CDaYItBm8GooYqhv2GeYaPhYyOqkavR
KqNaozvGOGO2cYrxPuNbJrCJnUmSSY3JTVPY1N5UYLrPtM8Ma+ZoJjSrNbvHorDcWVmsRtagOcM8
yHyjeZv5Kws9i1iLnRbdFl8s7SxTLessH1kpWQVYbbTqsPrD2sSaa11jfceGauNjs86m3ea1rakt
33a/7X07ml2w3Ra7TrvP9g72Ivsm+zEHPYd4h70O99h0dii7hH3VEevo4bjO8YzjByd7J7HTSaff
nVnOKc4NzqMLDBfwF9QtGHLRceG4HHKRLmQujF94cKHUVduV41rr+sxN143ndsRtxN3YPdn9uPsr
D0sPkUeLx5Snk+cazwteiJevV5FXr7eS92Lvau+nPjo+iT6NPhO+dr6rfS/4Yf0C/Xb63fPX8Of6
1/tPBDgErAnoCqQERgRWBz4LMgkSBXUEw8EBwbuCHy/SXyRc1BYCQvxDdoU8CTUMXRX6cxguLDSs
Jux5uFV4fnh3BC1iRURDxLtIj8jSyEeLjRZLFndGyUfFRdVHTUV7RZdFS5dYLFmz5EaMWowgpj0W
HxsVeyR2cqn30t1Lh+Ps4grj7i4zXJaz7NpyteWpy8+ukF/BWXEqHhsfHd8Q/4kTwqnlTK70X7l3
5QTXk7uH+5LnxivnjfFd+GX8kQSXhLKE0USXxF2JY0muSRVJ4wJPQbXgdbJf8oHkqZSQlKMpM6nR
qc1phLT4tNNCJWGKsCtdMz0nvS/DNKMwQ7rKadXuVROiQNGRTChzWWa7mI7+TPVIjCSbJYNZC7Nq
st5nR2WfylHMEeb05JrkbssdyfPJ+341ZjV3dWe+dv6G/ME17msOrYXWrlzbuU53XcG64fW+649t
IG1I2fDLRsuNZRvfbore1FGgUbC+YGiz7+bGQrlCUeG9Lc5bDmzFbBVs7d1ms61q25ciXtH1Ysvi
iuJPJdyS699ZfVf53cz2hO29pfal+3fgdgh33N3puvNYmWJZXtnQruBdreXM8qLyt7tX7L5WYVtx
YA9pj2SPtDKosr1Kr2pH1afqpOqBGo+a5r3qe7ftndrH29e/321/0wGNA8UHPh4UHLx/yPdQa61B
bcVh3OGsw8/rouq6v2d/X39E7Ujxkc9HhUelx8KPddU71Nc3qDeUNsKNksax43HHb/3g9UN7E6vp
UDOjufgEOCE58eLH+B/vngw82XmKfarpJ/2f9rbQWopaodbc1om2pDZpe0x73+mA050dzh0tP5v/
fPSM9pmas8pnS8+RzhWcmzmfd37yQsaF8YuJF4c6V3Q+urTk0p2usK7ey4GXr17xuXKp2737/FWX
q2euOV07fZ19ve2G/Y3WHruell/sfmnpte9tvelws/2W462OvgV95/pd+y/e9rp95Y7/nRsDiwb6
7i6+e/9e3D3pfd790QepD14/zHo4/Wj9Y+zjoicKTyqeqj+t/dX412apvfTsoNdgz7OIZ4+GuEMv
/5X5r0/DBc+pzytGtEbqR61Hz4z5jN16sfTF8MuMl9Pjhb8p/rb3ldGrn353+71nYsnE8GvR65k/
St6ovjn61vZt52To5NN3ae+mp4req74/9oH9oftj9MeR6exP+E+Vn40/d3wJ/PJ4Jm1m5t/3hPP7
CmVuZHN0cmVhbQplbmRvYmoKNDkgMCBvYmoKMjYxMgplbmRvYmoKMjcgMCBvYmoKWyAvSUNDQmFz
ZWQgNDggMCBSIF0KZW5kb2JqCjMgMCBvYmoKPDwgL1R5cGUgL1BhZ2VzIC9NZWRpYUJveCBbMCAw
IDYxMiA3OTJdIC9Db3VudCAxIC9LaWRzIFsgMiAwIFIgXSA+PgplbmRvYmoKNTAgMCBvYmoKPDwg
L1R5cGUgL0NhdGFsb2cgL1BhZ2VzIDMgMCBSIC9WZXJzaW9uIC8xLjQgPj4KZW5kb2JqCjI2IDAg
b2JqCjw8IC9UeXBlIC9Gb250IC9TdWJ0eXBlIC9UcnVlVHlwZSAvQmFzZUZvbnQgL1NRT0hTRitI
ZWx2ZXRpY2EgL0ZvbnREZXNjcmlwdG9yCjUxIDAgUiAvRW5jb2RpbmcgL01hY1JvbWFuRW5jb2Rp
bmcgL0ZpcnN0Q2hhciAzMiAvTGFzdENoYXIgMjIyIC9XaWR0aHMgWyAyNzgKMCAwIDAgMCAwIDAg
MCAzMzMgMzMzIDAgMCAwIDAgMjc4IDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAw
IDAgMAowIDcyMiAwIDAgMCAwIDI3OCAwIDAgMCAwIDAgMCAwIDAgMCAwIDYxMSAwIDY2NyAwIDAg
MCAwIDAgMCAwIDAgMCAwIDU1NiA1NTYKNTAwIDU1NiA1NTYgMjc4IDU1NiA1NTYgMjIyIDIyMiAw
IDIyMiA4MzMgNTU2IDU1NiA1NTYgMCAzMzMgNTAwIDI3OCA1NTYgNTAwCjcyMiAwIDUwMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAw
IDAKMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMAowIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAw
IDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDUwMCBdID4+CmVuZG9iago1MSAwIG9iago8PCAvVHlw
ZSAvRm9udERlc2NyaXB0b3IgL0ZvbnROYW1lIC9TUU9IU0YrSGVsdmV0aWNhIC9GbGFncyAzMiAv
Rm9udEJCb3ggWy05NTEgLTQ4MSAxNDQ1IDExMjJdCi9JdGFsaWNBbmdsZSAwIC9Bc2NlbnQgNzcw
IC9EZXNjZW50IC0yMzAgL0NhcEhlaWdodCA3MTcgL1N0ZW1WIDAgL1hIZWlnaHQKNjM3IC9NYXhX
aWR0aCAxNTAwIC9Gb250RmlsZTIgNTIgMCBSID4+CmVuZG9iago1MiAwIG9iago8PCAvTGVuZ3Ro
IDUzIDAgUiAvTGVuZ3RoMSAxMjUzNiAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHd
e3l4VEW2eNXde0mn973T3el0dzpLZyMhMYFcQjaWhCUICRJMgEBAGAFDNCq8KDBAVBRZBZ+KCwQY
TRMy0MDgY3go4PhGcAFl1NEnOo7PfPrmoY5Cun+nbicxySyff/jNH797c6rqVNWte+rUqVPnnL5p
WbmqCcWhdkSjqbMbly9E0hVsQYhaN39Z4/IYrhuFEN4xv7XFFcPZZITopQuXL1oWw4VtCMkdi5a2
9T9vUCNkfr+5qXFBrB3dhDyvGSpiOIbxUFLzspZ7Yri2B/L2pXfO72/Xvw54ybLGe/rfj94H3PWL
xmVNsf7BqZAnLb/zrpYYnv4l5AuWr2zq749rgb43EIZaF3ocydAdiEcUUsNdjxD/udyBGGgl7XDd
KSqfuj2+6BukEST89qpHpfytteea/9p006/YInwPFbKB/iTnApEAQkoM7b2KLYMt0nOQuMKoJjWM
JgAUA+QCpKaOM6N2vA89BvAMAI0W44dQG8AmgCcAmMHSAcCO44e6GUE8gduQFU8UFYxzht7iNMsV
zjfDmOt5yvme+ZOT2AKr9zG2dMch2Tg5fgY/jRYgJ34BefG9qBIl491HAkudDdB0AC0HaAegpRTj
A90J2c6XcRryMhie8aEEBh91/ikr3flpVpjC3c4z/jAD2W8TABPjnacdTzn/w7HI+TLAoVjTwQD0
OOo84Fjq3JoQxru7nY87whie2RLLVjng0aPOZYEdzgVZUvvkHWHqULezANpnigpnXr7bmeu45szw
hwUMeLpjsjMl67+cSfAgdHPBoF5R47Q7tjpvgaYER5n/FoCT+CDeg1Lwnm7vROcJKMJ0j0wI5O8I
4/uOVCZnecP4XjGvMnlHoNLvDUx2egPlfj+UZ57n1/G38eP4bD6VT+Z9vJu38XpBK6gFlaAU5IIg
8GH8q+5iJ3cSH0LFwJZDRwROYMP4JahkTuIXpcoXjwmMQAlI0IejH4HwYqQP40M9IPYYQeEoJ5W4
MH7xSKzqRdHJkBIjNagpUoYEUkRhgUITUQg/EubQemNrsblYO1ZTUF76j5IGqWUgTf3Hlxk7Qjsm
1dSGDjrqQtmkEHXUDXQ3DxT+Yd6yCpqaSlJTJ01vO9K6fMnCsiZPWYOnrAmgIfRQa7M51D7P5Tq8
ZDlpcIVoX8O8+c0kb2wKLfc0lYaWeEpdh1ul50Y0LyTNrZ7Sw2hh2YzawwvFptLuVrG1zNNYWndk
XsnK+mHv2jT4rpUlf+ddJWSwleRd86TnRryrnjTPI++qJ++qJ++aJ86T3kUmX7a4puSuFpBOV9ni
Sa5Qck1owrTZtSFXY11pGO+DytJViD2N1OwplMy2IyuTgZwIRd8DuEryyK3Rz9hzSB1ZFv1fuhAW
9TgBKlJchE6jR9Ae1IU41AnlZDQX7UIX8BLY23NQD7qME1AQdC+Dwmgyeh1Ho5fQQvQ89G9BZ9B2
dBgp4ZllyACtm7E3ei/gIpTnoXXRZ1ESyke/RKdQAYy6GfVGD0SPQOt0dCs6iA7B87/DHuowo4u+
FL2GBDQNxlwHLZeik6NdSIvSUAmaCrXr0MvYS1+NNiMzKgTqnkRPo73ot+hL/CDuiTZHW6MXox+D
qJqRHdXAvRr34I/pLuaX0SejX0QjwIlklAJvbUBb0XMwfhfcp0G1luE7cAveirdTIvUg1cOsZ02R
PuBDAFXAXYnuRBuBA8fRWfQX9D3+ijLTarqFfiWaG/0/pECTYJZkJk2oFe4NcG+GOZ3EHM7E4/FU
vBpvw9vxW1QKdStVS91N3UN9RlfTc+g2+i3mLqabfZjdxSki30RPRs9F30Em5EC3oZVoDczuDLqI
rqMfMA1j2bEXF+ISPBfudryHOo734uPUVHwaX6QO4j/iT/BX+AbFUkrKQKVSLdRW6hB1hvo9vZje
Tj9B/5H+hhnLUuxe9lPOy/8hMi+yKfL7aGH04+hfQcUKyA0rU4Kq0e2oEWa7HI1C/wazeBHuLli1
s+gVdEG6P8F21Iv+ClxAWIutOBtXwV2Np+CFeDF+Cp+A+2WJlm8pWAhKRmkoE2Wnaqh51DKqnXqH
aqdtdAo9kZ5Nd8F9nr5M36BvMCyjYwxMBTMBPcwsY3bDvY/pZLqZN9gCdixbzc5k29lN7MP0fPYS
e5lbw23murmvuK9BLU7m7+QfhtW5ADL7W5DlHy8GJwH12egXaD4uxfPQDliNvbgRdYB0LcAbgV/L
UXK0nl5DV1CZIA0vo/tAWnej1WgTPQftjb5LH0RXQFKWwpDtaD9TghzsTlidB1EmSFH/LQZSAsl+
nzfJk+h2gcq326wWs8lo0Ou0GnWcUiGXCTzHMjSFUVqZp7zBFfI1hBifp7IyneCeRqhoHFLRAFvZ
FSof3ifkIs81QtOwniL0XDiipxjrKQ72xGpXESpKT3OVeVyh/yr1uMJ49rRaKD9S6qlzhXqlcpVU
fkwqx0HZ7YYHXGXm5lJXCDe4ykLlrc0dZQ2l6Wn4uAjskKenEcUhIgUZOITGN64GBYvGkx5lIaun
tCxk8UAZ2mhvWeOC0NRptWWlNre7DuqganotvCM9bXEI6EQPKRd4FjwUFtG8BlJqnFMbohvrQlQD
GUuTGjJ5SkOmez81/4gOlMoeHtIYorzljU0d5SGx4SFgLkEbCNb4MGCTalwwLLW+rjaE1/cTQWhc
ApQScmNngrdhiSsk85R4mjuWNABz0fTabqtolZRvCE2t7baIFglJTztuXlPohtkfTx+XPo7khW7z
mlj+p7Wx+jdPk9y85uxHkE+aPsgATDjgmQB0hlzzpZd4gNh8kjTlo475+cAnuOowTHMx0DM+RIHM
0N4Q653QGGqvGSCjuTRGXMOS0m6ZxSodQiV10L+hQ30LrBT0V3tcHd/Aad3g6f1yeE1jfw3nVX+D
SCNZ6EFZCeHGgXIrOSy9MOtms6eZrG+rtKaAe8xlQyoAJ6whNIf0cIBPrXWHXHVQAdZk2qQwkk2t
PYzx5rowjq4Po1LHcbBR6dvnQnMaEbXFpfB+QNLToCLFDaVgmqsc3lxOZMXV4eqYsKDDVe5qBmFi
vFIODU0ddRnAwZpa4BOaAW8U62yDxaa6ultgnAwyDjwC3TvqYIQl/SNALlVl9EGnzDQ4TGnf1Npp
taH2UltILK2DVQDxPT21NnQaJLeuDnplDVIKFK9ebO6nORtozkqB9pzYKGC7tMMQdR0dZMyaWo87
dLqjw9ZB9lsMD2M0skLsrwgj0oWwPIzbp8KzkHncNmkN3B43kFVHeDoKRHpAosBm/+cczhukG54c
DdTmSRzO/5k4XPBTOHzLT+Jw4SClwzhcBDQXEg6P+ddxeOwwDhf/cw6Lg3QDkeOAWlHicMnPxOHx
P4XDpT+Jw2WDlA7jcDnQXEY4XPGv43DlMA5P+OccnjhINxA5CaidKHF48s/E4aqfwuHqn8ThKYOU
DuPwVKB5CuHwtH8dh6cP43DNP+fwjEG6gchbgdoZEodn/kwcnvVTOFz7kzhcN0jpMA7PBprrCIdv
G+SwaAuhoXq4fYTaRT+7Yp4zhOVgKbFaVEIVgON8EG0GKIVyF/hfL0B+gfkEudmZaBRzF5oO0ApO
dyHk+QCV0G6HfAzAOnyOQPQq5Ju4g2gdqQMgfVthzE3wHHmHCfB2KCtgfC3kBgA7kDAQO1IiDm8E
3IX+g7jywy4KvICBCx77yRc72JMbLA0t8IDEAlVDa0lZhuTgOykhIqRC8RDr0oCfh5AO6cGDNIIX
BEE5ZEFWZIM5OABLAPj/4wJ/XLryUB54eafRR+DVzQZ/5DMqRFvpJxmBeZNNYF/ljFwpeDrP8Hb+
Hv5rYZ7QKdsoe1eeLT+vaFUqlb+AMSjw2RBzEXx9GmKG42NxPCEjjBgAQR1G6CIAwaFMvw9lyHnI
achl76MT8BRCM1NPwEgs5JlZORq3xg9QwmwO3/xv9tQP48NM1Q2IC4HEbI7MpRrZd2CFxooyvUam
M5pMVtlJ/CSssB4/KapEEL/JaovB+J176XRzmM9en5pafb2q1/qBtfft3uqyptLPUHFxViameE6j
Nhl1niD2+/y+XPXoPB01998zKqZlb217vDyQb1TUF55k34m88dgfIh9HPvx6W+SLa2uWbuucNQUn
/2kr9kr0lAI9JqBHh/JEpaBBOgPQw0yO1xGSQMCAJJlg0Ru+cxffBwEkQsnbvR8MoUOnHZ2nUft9
dE4CNiVgg5rn6Iqng+WEit3jfJmBuYUnInNx3uYr2I3dX2/Dxm/valp9fUXk3c+3Rz6UaOgCxrSj
q8B/n6jDKbScBRrwAmRh2AXu+U2x1/b1T72qNytzdI7B03Xp0lUIxpD1ewE0xHxYvziQ9kWic4Nm
h5bKFhQJ8RRKMAlCls5qjfOqLBbrZXfrpoHR1N9W9aLivuK+rMzxbaIPGzVeg4/jWZ7haZ7iWU6u
FrIxNkIi0yqyMa8HLzg1FaempqSmPlDvzR6dR+5cNeVxa2i3y2TU6HkqgKmLTeNaJhZa49/738jT
56kanLF/e+2eyC/7ug4a/HfWPVRTgTU4eGMXq7tyJnLpi1ORbokHF4AHj0syaCKR4xOScgmmQpyI
iB6VkZmly9F4Lly4QMQJGt0gs1AG2RslWjGXgHiKEWTAN3SDor0sc4OzCA/PNadWq69XXS/qK7o+
IDlFVX1FID0Gt8ajcecyFyKa1yIa9lTXD39hVbAQREYhVs/mwdgcelQsfQw/gykRz8CUEeN72M8w
tYhpZjcytCWZ8mppmkFeLcexmKVojkYUywgCkSCKfopF+CnOwm8GKixAhrmqr6AA/iwSJWZUXFRs
KtIW4A1VwdQNQTOJOYpKDC4+DcFpTHHsBmG1+qyUAL31qH7FipUyKgd7MFbjfXjvH/s+f6vvz+yp
Gw7mkx/GA7lw0Wh69H0pAhIPsa0i9IGYn5KJ5WqFTWn351SqF8uWqPkCQauU0bZsPknmUCsdhalU
MFB4rJAqzE7xatU8K9j9iSZ7GHeIHpPDyfsdQQXlyFUU8UVFdj0fSOlMso61BewT4/35ljFjf4N3
wmIcxztQ//a43lsNsnWt76y2IAN2ai+5e7UFGq2poF6jLQj2Bnsx5BpTgSR5yXmjDYkIW7w4L96N
zAk2NzK69LBVEtFoyo2sDpMbFgsSkIpUrC4i8csHHngA1eP6JGMOSOEYrMLxmOM5AybyOMrnSeQ5
3jMW52RDCEWjh07wChX2JIKaIJkvd1TeaB1Wray+vW6Huzl72bysGtwz1qBce+8jhW55J/vdc6da
V5m8ygRNSpqvPsUoG/37+7efOrGz443ZaRP2bTHYOVWcPWMRXiqkmdPn1ExOqXl1T2Xlrr6d9kSa
Xq/kSjxi5ZJfb9z+vA5fI/uzNfoh42XPwOmUgJaLwX38fvsVO50oxCdQcPSZHCyvkSc4FAq9X7C6
rEF1EAeQxuJ0bXCfqpeYCjJ77RrhKuzYXsJSTYEmxj2z1sjJjZzeh7VySAy8yYd1sgRfbKcSNsG2
IazQavSUxAGDJynGJM6gNxlzWrsKn284//23V++dkV2wj1q4Zcsj9x33VZxhz/T9T9W0SG/keiQS
KvRUbVr9+csHPjx6aefcwyBnFIKoH32RqZbO1v1ixn4L3mXuFA6a6YmCZo+epvWcw8rHOfQKG2+z
mdR+Lab9lMbqkPtNFjv8FMIfca9c3S8xMLOiqt6CApCSfomBghr0HCimUcgieJUGuQ+pdGqYpSZe
zVsAYxHtxphiaIUxzofitZDIzJwPM5hzg46SRIUIi7pIEhlJXpDRBIcFEQ9DTCpyiDhQuWqUw1OX
PzF1qVeu+dXEzI2PL19r6Ur4+uSbP2Dt23amOnRl/trOZc/sfX/T3e+8gnM+g5DlLSzwID96le6F
dVUgB7pbzB6tqlDNUu1nDthYr6Cn4h1qJDgcvE5OOUwKNqgLqgMardWp8FstCc4N7pUlQ6cPCzxy
ba1mu0yOMDYrYG52SJCF8iG5TfDBBOFP2gVaIt6S0HMGZDKaNKAlc8m0UO4obc63j+9dvXffvRsP
4I6azDEvPlv8qzuPRH746kN8++dXLvzuPy++Ro0elTCJcvwwdvv8Wpz+wxd4FuiQyuhVxgpRVDtE
3L1YKbbtFJ6w7nfSrIqKZ/UGlTbeoBeVol4IWPEkxVH6HH6VPmd7V3hPdtn5rudz0+cexTnNOS01
R2DdSfG7jY6kAo7njW6HnZc7jAovv9O+334M9gDjNcZ77axFruQ1Kn+8w89a/UlB3m+x+Pxvu/fF
hB9kXxL9t/sKtAWgRgogy6iPaRYogW5X90KtJC3lyMOwNISoMctwTp9GrVXr1Ho1wym9ibYkH1it
Dh9OcMhMvA8pDCofjlN5rG6oYiERzCBXcWpIiKqJ6RpJeFJSUx7AK+rRivp6ECG4De4E2FJw/IEA
ga7hgNsaECIMZognkeMx1XM5P0+rvvkV+9jOR2Zk6g/zU7Kmt42bfj7yBTb/N3Yqkie+eH8niz1M
xR23Tls68dnnXqnPqyjcEpxqV4N+5+AUKIn4VpU/eKQDkx+C4UwCGxzslDfBpq0SU3kHJ3fQOF5f
YIzjtHILHDiqOE3ApOW18SqnilLd1FvMlpvuRWtiItZXX3BWYtTQQ7AYDJmsTLBecrKNJgPZF5wB
7Ao4Fj25Obm/9hT3aJJMdotiuqu7p3v7drZk1ByKep7Ct760+eYC+snNndJ5MyZSSH8OsuJE6fDL
zjGxKk8/QZggqxXqZBuVB2ydjgP+fanHbQpRoI2JAdVZeSIcKQwXcFjkWoc8PsgHg6ydDhqD6QHW
mqlU+ePG+vx2S0bmkA1yvbeASEDftW9gnQfOlOJeadlj657mSbYmKDRJXrXPk+DzoWQrJBqFyo3i
Vco4ryPRh/22AOgJpRYMhx+1A5SkXUR2Tm4OGDCcO9Hnz4ElJssrnRZJZGWRdKhIWgOOGEzdPzcn
d1/R8siFF79UHYvzj1n7huij83atfilyA/MncOnz//ZyuXfr/WempEUuMSVjPeM33Mx+vfXqnhcq
/UWPz/xg+tTvsAPH4WBk7+nu23f/+lTX/HVUurTO6+AQJzrFiGrENNg1gok3CX7Gr1vFrxIEXRyl
MyCkcXC8QSmPC8itZmwIIKPFZIZfyI+458V0CrFx+o+LIum0KMBkg0iHAZyRsYPRoxkliatB41nX
I+bMevDPNenHE7I2LD/aA8r//WnugufqnuqbRj3XOrp29+W+80QOKfj1DOFCMDaIr5An2vlPGRBO
jpYT0wvkNsDToLBlB3+k5Gxf0dlBsSsm1isx5DQgaeuOwcWk3LjMniJfP1DRq5GpOF8aW0OMvhqw
Aonoz4RvCTDxOS7GfA/ZRbAKVdBBk3EC6CC+R2YWBqHFY3Eu6D9YRTjk/Ti/pyfybFtWj684FOdw
Mr0Xvx/FeOYwR2+MXnXLPEpyVTHaBG8YI70zIAJn+21vKoBosL6HTAMYOuh6kAls6umRLFFCIPCE
8zIVyIfWi4W8wKu4eJNgUpni/YIf1FqlZaZikULp8cqtDo9FTjEmr9thcsRxPOJsdi+tkycD8zQB
+EEdd1sD5DsCEfR+0AsCa/Enh3Hc0IW9pr7ee33AGTAVFRfD0Qn6z1RAjKqBVTb0r7JpwAqCxSaq
CdZ6yKp3i6PqVrRXpyUVPdv0bnXKyTuqljxxzBpYvnB/D5Oxa0rSmOKk8pk1T87Y3Dea+vyOqZv3
9W2hTi7LnvTUG0QaJFmge2HvEw97rph1jDvHUQyn5/z6Vq6FZ/VKSm9Wg3WDOLNCbuWtVqQMyKx2
HDQHLMhiAxNzmMjG1Hxsh8O8ejUFA2KLwYoxDJkKkVvQuyoM88HrDk0+2HxtatoxR+YaMTAxP93W
g/cD/XOnPz3rWSK/84oWxBlLclcs7nsDiAWJKYy+x7jBdlFK0YHHxJxdwg71E8YXmE5hn/qAMSyc
F64wn6r+rFfeInAOM690aBUW3mIxUP54q03mN1istjCWgQXTf0JJFu+P1ot0FKVBKMWn0MngNNFQ
PsyboMTGQUmuV/pAniERjGCw0CpIpPOGJKlgqCRpc/t3JlgpWjhZKDec5pKR8tH6zMknXtix4zn4
If1m5LsPIjex9k9cC47ft2Putpvdh67RVyNfgsnWF3kJp94Ew1gkdkpr5FbGC1NXoUTUIqYdEPab
qGTBZdeoOIeBj+dUDrsiUUX5zdYkOVif7kBivMWT9HetT8n81EhyBsaZ3WhDrNXH+JANJsYaIcEW
lQ/RJmlO0rSIDUosztiaSTYnzonJJ/y4SbYqmOUaD/Xqfm/5iZNlXkgjwa488bb7jkaOtexum55Z
2NP21pvtcw6fXLD7/ln76MObJyQXRf4Mc3x2x+25CRP6PiB7EPYx9TjsQQ2aIvr8tC9uNF3BMCpB
TalkGpnSLxAx1MgFqw4TOwxZtLowLoONFTsiiYVdrSaRharis31niZVB9lNMZ0qiN3hGwt4/ZHj+
DtbsUNvUGx+HrXI8bw9Fv0xTXSv7dpF9URK9Qh9lJsF5mIGD4qP5sl3sDu0T+l2GXSlccpLXn+cu
d1ckVfhnJs3yL0xa5GtTtsW1qVo9LUkt3hbfvoTONB0N5gmbzgR1yGqwmexmQ7o+mByvWCz4vHle
ypsYJ2dSdeZX7Q4dzziCu1MVGbxMpaZ4lOHOsDrNRrPfNDbZx/uTrVkqp189FvmDlsys7kGbClRI
7EwtUEOJTLcgA1LYcsSwIh4bUSkrJEmejNMpn8Fr9blVTjeSwSdEmE4Dn49NgZJDC3U2vdmNXfGJ
buROVMUJfrkb+7wyOU5n3PDdGCQJGrsbW4yQSKaVZJRLiSQiA4IPLh2Eg2IGrd+XQcwpcNXIacV7
YqYVER8nJhaYPqbjvxK8pZ0Ldo3x3/XopnEtfzj+lzvGUwdZ39gnFi4uS66++0zJ4vc+/Oocj4/h
qbMzZ826rSwJrNHElAkP7PrN5tnNY7IrqsXyFIvOkZFWtu3Ri+89Q30PsmSKfkXJ2NmgHab/Oi4o
P63CYVwsehljgYnmVHKNFdQ1fE0RQAaVIZ520hR90wjRFbC3+j2aEfZWBlHSfUW96r5r0ulHrCzi
ew34pb5cYnJ1Hj10yGfIikvQO8f718zesoWdHXlna19Zvk6Bqc0y4YFF1CtbpTO4PfoJ/SHsZxNQ
OFe8Jaw/r6dkOkFv0Vn0ydzd9BUwGxCrkiMuTs6C7jLzZjO4SUF5QKmwWnGAEPvmwAldRZQXEX9Y
/phtVVxEBIKIPq7HMULB6CGOxWjJ1oVV0XhxvjVz7W9KvT0HKc+oRVs/rUnHXUxGX8H0UQ2ds/+d
Ut249NSYlBlPTN9EvWsl+1MBivcLJgOix5QYLMGvYAotQs1UM72I28BsZPejTkqAr2SoMmYi+0tm
E3uOOc8KE5LvSuYFSdVKpiyESMLR5T1g3LuYMF57jKaXaSlMwbdqa8UEjlsGwV/McgyN+6Mx8M2E
nERj6C7qBCaWy7ojuIuzWKpJMOajj/pGhmJg2toCHuIx6uprVXwsS500rU30UgEp1BMYEuoZGBx8
0C4I9QyO+/eCPCyvToU/iOOAG1G/QifDJI7zPk7Aqa9Elp6OrGIybu6im29cAg5hEsNm90JJiV3i
mgrmoAyWH5fzExQb6A5hvfw16iz9Kn9BeFV+QaFYyC8RmuSLFa18m9Aqb1Os5zsUctKXqqDvRvew
9KxkYzJ4i0whLmQexY8ynIzBtIKiWU7JIk6QK2hergIeQcRvj0AzZ+WU7KwC4T1KSxzh+dDI1Yj4
FRgfEMCCqA7hkJIF3vDwtZNWqVSwG9Sp8AfL1SODb1fkYfyQqNOCu85zDEs6crxMkMlhZR8SVVoG
nHglTFt6NBYOU68+a2ZJUAxCYK9IhQ0QCxusIfGwFStWgENmo3JshJcKYOeV31967c0/9EQunLz6
1snI74ClPfTkm8fpihuX6DE3/xMYCrrZEJkg+Svkd4HXxF90GDaa95tpnjNx+dpKba12EX83fTf/
sH4X2snuMuw07jR1ok6juhJNMlSYLhiYUvZVltrA7kP78H6208QmJbNmg8kINrBBqYh3CCpiKBht
wFAiEyaDuUv5qBHshbdjzhiIXtU18zBGxrYdBAezLRnm4qIiiAkWYBIM1BrgRwzjMq3JZGYxJsJt
3gAyCawhmQA5cCErcwWJDeIcjqZ4SlKKucQ5zRs9Fo8GztC0+5xv7bySJ9uf9AUSMlLU2Rlqdqwq
0vI6dmImY1FkS+TLlyILezjh+TjObRa2JTHVIIoPEjsJfE76HsnntIF/1yjm2T61oB99Twc4n06N
3A1ztSUEzM6/cUFd7jfdi/qjHIMq8TI47P2mdBHMFvQicUSLe/E/9kW9uTkGHtTP3/iklK4Hrr/1
TJ2vv37uxmVJV0ICXyw2wXd1f+9yQSUctWAJapAfvhAcDV+wlaIyVC59sTcBPlIl3+VVoSnSl4PT
4WvAW9FMNAvVojo0G82B313IRXYslkoc/AaFaqZNqawpT61sWtra1LJ4fqPUQ2qGZCPANoDnAeAz
WvgqDqG3Aa4BXIehGAA9QBLAKIBSgBkACwBaANYBbAN4HqAH4CzA2wDXAK6DgDMAeoAkgFEApQAz
ABYAtET7L3gXGixj5BqBJ4/AAyPw4Agc3jFsPDCyh+Hw/mH4zBE44dBQeuaNwOePwGEuw/pLaztk
PgtHtC8agTePwBePwJeMwMm3e0Ppk/4HYMj7yK9oQ9vvHIEvH4GvHIHfNQJvGYGvGoG3jsDvHoG3
DcdvSLL5/wAgKJYzCmVuZHN0cmVhbQplbmRvYmoKNTMgMCBvYmoKODA1MgplbmRvYmoKMjUgMCBv
YmoKPDwgL1R5cGUgL0ZvbnQgL1N1YnR5cGUgL1RydWVUeXBlIC9CYXNlRm9udCAvRVdNTEtTK0hl
bHZldGljYS1Cb2xkIC9Gb250RGVzY3JpcHRvcgo1NCAwIFIgL0VuY29kaW5nIC9NYWNSb21hbkVu
Y29kaW5nIC9GaXJzdENoYXIgMzIgL0xhc3RDaGFyIDEyMSAvV2lkdGhzIFsgMjc4CjAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCA3
MjIgMCA3MjIKNzIyIDY2NyAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCA3MjIgMCAwIDAgNjY3IDAg
MCAwIDAgMCAwIDAgMCAwIDAgNTU2IDYxMQo1NTYgNjExIDU1NiAwIDAgMCAyNzggMCAwIDI3OCAw
IDYxMSA2MTEgNjExIDAgMzg5IDU1NiAzMzMgNjExIDAgMCAwIDU1NiBdCj4+CmVuZG9iago1NCAw
IG9iago8PCAvVHlwZSAvRm9udERlc2NyaXB0b3IgL0ZvbnROYW1lIC9FV01MS1MrSGVsdmV0aWNh
LUJvbGQgL0ZsYWdzIDMyIC9Gb250QkJveApbLTEwMTggLTQ4MSAxNDM2IDExNTldIC9JdGFsaWNB
bmdsZSAwIC9Bc2NlbnQgNzcwIC9EZXNjZW50IC0yMzAgL0NhcEhlaWdodAo3MjAgL1N0ZW1WIDAg
L1hIZWlnaHQgNjQ0IC9NYXhXaWR0aCAxNTAwIC9Gb250RmlsZTIgNTUgMCBSID4+CmVuZG9iago1
NSAwIG9iago8PCAvTGVuZ3RoIDU2IDAgUiAvTGVuZ3RoMSAxMDMyNCAvRmlsdGVyIC9GbGF0ZURl
Y29kZSA+PgpzdHJlYW0KeAHFegt4VNW1/9rnOa8kM5PMM5mcmcxMJo/Jk2RCSCCHkEAgGQgBQoKJ
JoRwAxc00BhACqWiBoJWbKsg8r9qxX8pXvufBIuDXv1zufRqFb6LYi9WUestWq2m1F58wpy5a58J
KeR6/fi++vXOyTprv87ea//W2mvts08G1t/aC0mwDVhoXtbdvxLUX/YdAOR0z9ru/kQ+7SDykz2D
A+5Eng8CsDtW9v/d2kRe8xSAfs/frdk0/rzlAICxr6+3e0WiHi4jD9GCRJ6UIff1rR3YmMinNSHv
WHNLz3i9ZQDzxWu7N46PD+cw7765e21von12B/Kc/lu+Q9vhL9uAt+b+9b3j7UkbyncGCJba4DbQ
whrQAANGvFBC8QP9HuCwltYj/XO9ft9NKdWfgkmDBQA/CRRuo/zM9hdWf37uckC/VTsb22nV9rQC
nxFylVwAA8H6N/VbJ2poLf3ZotCRH4UWpAakGUhlSHn5Ixr5GbIb0jovyloicaCXXnf88XlSiDp4
X71HSKFsSAJtz/ZqqWf79obcmVrSCBUcAYnUg0/ldaO+J6QomTHq8yKbnmDMaIULcyBrK3xSrGK5
dLkiqiFyuvSF70fS50if+WqkT30l0ivY7nTFHOnUTKwflV7OizLIXvJFOSKnSC/6vi/9oiJXeqqi
ShoNYNmoNDIT2RHpQMX3pcfuUEt+kqeyR31Rsm9UeoSyI9LD2P8D29WK+xMP3p5g/XeoA91yWGU3
H44yTxyR1vqypeX4IJH1UqdvjdThq5QWz4wS/6gUpo8dkZoCp6RGOvSoJCcGCiV6L/epEpcmhg36
npVyEiNk0dZyquT2NUku7D/4yANS0HejNDMvSg4+3ZCT52sIPBCKkovqGJShoJTdnGA9gefIT2EO
5JJl4CcPHm7IRZnJ7lFpO7J9hxtyKvxR9gPZLB0ONATuQAoh+ZGWRMliOSjuEVeIS8QpYr6YK2aL
HjFTTBfTNGaNUZOsMWh0Go1G0HAaRgOatGj8t3I+taQ0wUiZwNE7p6aNDE3jDe/AEA0D8yAqwJ3W
wRp7jXmGqXJ23dfcutTCrrr8v/zsf0nm24kr8kDjorbIIVd7pJQm4q72q+r/mmRvLT7d2LLpcMum
j1rre731Xd76XqSuyK7BPntk23K3e+SjTbTCHWGzu5b39FHe3RvZ5O2ti3zkrXOPtKjPTapupdUt
3roRaK1f3DbSKvfWjbbILfXe7rr2w831DfOvGWvnxFgN9V8zVj3trIGO1aw+N2ms+bS6mY41n441
n47VLDerY+Xn169aVAv8MTDxx6GA3wMurhZcAPE3kN6kXFkUv8CfBl08Fh9j0buRLErvXCJp8P9A
hKdhK3qcV+EQ0YIXxkgp/Ia4SB68Dgq8Cf8BTtgFj+C9Hj4gn6Gn+ZDkYJsQ3A7/AA/H+6EfavD6
gPBgganwYXxz/MX4l1ALw3CCiCSVuOJHoQiG8NoH+4mBWR4fATs0wQbYhn38Ct6Ij8b/gP2H4D1i
IkVcVfwtNDAeSyphJxyCp4mHeEkeuSH+HpbbUcYOOBQPxwfxuQvYqgjmw2Yc7V0ikWyST/aRt9mx
+Lb4D3BuGVi3BHrwWgvfh72wH55UWy3nMngL9l8HjVj3AzgJH8Cf0enmklqykfk1+wf2T1wVty9+
AuVYguN1wcOERVR8ZAlZQfrJk+Qp8i/kM6aC6WYr2V9z/dyjKNsS2AGPwnPwApyBt+AjGIOvIEY4
lGkGWUA2k/+Dz/0HM4XpZLYwdzNvMBfYEvZtTuR28Xfyz8a5+K/jX6HMmZAHVbjSF0Ib9OK1Em6G
W+F7cAcRYQ+MwL+gtO/AO0RHjKSIlJA5ZDG5gfw92QT3kQPkGXKOnCfvkw9RulRGYrxMETOI493O
7GSeZEaZo8wYa2IH2C3sMfZt9jPOwnVyx/B6hy/gB4QMoVFcqPxYeSdeEN8d34d6seLlg1wogBmE
QxTXwh2oyZ2I2X44AE/Az2EURuOXSCWcgFdQrnfhAnyOGsvAy0NKyVTSTBaihGvIWvI9shclPESO
oJTPkmfhLDlLLuGlgIPRMgXMDUw3swmvfbCXOaPiY2A9bA5bwDayi+KfsE+yI+yfOT+3jFvHbeaG
ub3cw3wGP51fyi/j+/n7+SP8y/y/8xf4i4JLGBIOCE8JZ0SNWCbuFRWShbK4iR+egufR6h5g+zHv
g1nkDtRqK5xE6x2DX8Il+BKOwU+JCxSWajM7/ihE4ztQm8/BL9jvQjXcx/yImRevYQ+yWlIa/xz7
KkZ9TVxyXm5OINvv82Z53FKmKyPd6bDbrJa0VLPJmJKcZNDrtBpR4DmWIRCs987uckeyuyJctreh
oYDmvd1Y0H1VQVfEjUWzr20TcdPnurHqmpYytlw5qaWcaClPtCRGdzVUFwTd9V535FSd1x0lyxa2
YfqeOm+7OzKmpsNqereaTsK0x4MPuOvtfXXuCOly10dmD/YN13fVFQTJURmDga4gCEcBZNDTjiMw
q3sLOleYRVvUR5zeuvqIw4tprGP99d0rIs0L2+rr0j2e9oJghMzq8S6PgLc2kpI//jh9Dp2gv6UN
xy4Iroqg/LDLsMK7YldUhuVdNNXd0RZhu9sjTBcdw5QfsXnrIrbb3rP/JXslVX/3VZURxj+7u3d4
dkTu2oWg02wXzXXfjbnGRW7slrmzvS1C7kThqBCq7IlZJMKEv2u1O6L11nr7hld3IebQ3DbqlJ31
3q669gi0tI06ZIeaKQgetW+t8iAoRwtmFsykvMpj35rgv9+eKH/1GOX2rSd+i7yxZQIXQsf2zkUx
I+4eHASxQFmn0lvvVBjumYrw4a+d4CxXoTyzIgyaEuuP8P653ZFti8bF6O6rGxdudd2o1uFU41Jt
O7bvGjZOQwVie6PXPfwpoGa9Yx9fW9I9XiL4jZ8CraT6nzChCOm+kh6k8dOPIanP7u2j6htUVY15
r73+qgLM07hVgBvOYGMUtM1tI4T8oD1K4ndGoc51FAMMe9ONWJ1PDW5VHQ6HmWAQC/I8mEIJZuNA
s6lluIfdw3NXDLtnu/vQpDi/yrGid7i9CAFb1IawwOI2T0RuT59I9ra3T8N+Cmk/+Ag2H27HHlaP
94BcLSqKYaOiYCPOKru5bWFbZFtdekSua0fQ0YiPNbdFjqH9trdjq+IJSVHiLavs4zKXoMzFeVhf
mugFtzXbsIv24WHa56I2rydybHg4fZiuukQed8iTC+TxgijQJhThKNnWjM8i83rSVcg9Xg+K1U4x
nYIGfMWAcFv/zQiXT8iNT4ZQ2nIV4YpvCeGp14Nw5XUhPG1C0msQrkKZp1GEq/92CE+/BuEZ34xw
zYTcKKSM0taoCM/8lhCuvR6EZ10XwnUTkl6DcD3KXEcRnv23Q3jONQg3fDPCcyfkRiHnobRzVYQb
vyWEm64H4fB1ITx/QtJrEF6AMs+nCDf/7RBeeA3CLd+M8KIJuVHIxSjtIhXhJd8Swq3Xg/DS60K4
bULSaxBuR5nbKMLLJhCW0yNwtR/eNsntwrfumG+4BvKOb4a8c2IiKPWNKH6nCvlN3xLkXdcDefd1
Qb58QtJrIO9BmZdTyFf8L0LeexXkwL8A+5hKoLwMqQNpP98KjyN/DHkR9x2o4n4Hm5HPQV6DvAjb
70TahfkhpFqkLawLbse6WuYQWGge0xbc/ybO6/DQDQR8vwBwwzJ6QPJX/ugxC4vv5vz/2I8wXiN+
bQsNbqZ0oEepEr8klSXjPQVPG03IzZAKaeoMaJWV3qAMr+OkjAyTf2KCzFY2i72N/YCr5f6d1/F5
/G38aaFQ2CgoYoO4X1OGb737ENXpePbA4rvrDNnDCy58t+FEFws6nnOxLOPUCqKLgEOjPeRZU40H
P/MvVodj1fONn1WHjbFqqKmOVVMqKZ5i8pgCSPu4x6KXT/HHv5oR5Vou/ZxKxaJUwB/EcRh1Tufk
v+9jSIDP0U0VKrQNQp9uo24Ht0PYx97P7RUOsY9zB4UoiepeJC/qXmdf11mIKAgMaLRavOmIyDNp
Op3fjNk0nvebsU7U5NEzLZ0eX84ErY7lNfokm82p13ECHyVpo1qWQXZE5zD03rrenj8433jRHo5V
VuKfqdKB5zZ179uLoMZWHa6prjZXVhbhlPihwvwtxkbcPnLH0iPcifahQvt4AYsF7Il2E7bEvyFj
dbWIVFJMOqGTePT48uzBl18PYYrIYPQJ0sHolNGbYu+uVJ5nnsF35Tqy8KsZpEh5RUWkI36W38xf
wLMDCQbk3KW6H4s/1rA3MO3pba6V3Aayk/9Z2ij3tO5fuRf0bzBvpr1lfyf9C7vRFiV62evUaJyG
mRLLmmc6tZK1wqapkDJFpyelItPh9jzoebJV1Vl4DDUWNlWOvTaG0xyrqR4zVxYZxxISmytCHrfN
avNkB7K9WYwlzTqltCJU4RHA4w5km0jHvz1FrGTgH28SlZOZRYsfP3j81D/8ZEmRREpylKeVuHL8
yBFmN7f0lSMXdw6vDnUpn3zxxeerK9d/orx68hTpZZ2o9f2o/804Wy2emy+SSzeYiagJiAFDm3m1
eTN3NzvMDZv3snu5veYn2SQmz6LNszIWjVBhdDqI3+KwO6LEfdjTMj6ZGJ3MGNTUjF2ZAjF5UOTy
smxvCCdiNVuMIpOLheQFkvFGa9E9rz53w0Nd4amDjyijsTuZzdzxyzPODj727idK5pQdN8dhQHnj
pDKG8lFv8DjKymBaD0X0lP0ZdAtaaMRTdsEYxa8X8AyuFQ0WPIMtQOV0nTfmF5cQD9r/+MW9ffki
czJWxhZfeoyr5J5TXoiDcqfyOR2EgcdwjHWY1OHpQ5uc5/am2y18IDU7j+DxRV4uE3BpXO6sVMGW
JVTY0pcanUEI+HMc+cEoybwKB7oOw+dPxE6gJZoqK3E11lDFxipNtkrU7TgoqNWQ1ZZJLGmCmIlH
JmkIkYUqu4gUEq8qLzlNOvvKOtpLV7z502nFU1fftnKJxhBUnkwWDIRhenYox5UzzBnuuDJgz/vu
XYXO2Oy6qTuWrno5L3fPQz29vsp0f0nmjJk777kx9jzOiuC5HvBVmBJgg+wp5Ti/mRf4UkL8ZiwS
WB4/NzAso9HgGmWARIlplOVxyZuOcA7xv63Q8fVJZ1dNVyc/FL6yMhlciMzXrEycPK5BvNhLRFa0
yltKMplLZOqV+OOXHlV9UlX8bW4qdxMk41niNLhXXlDFlIc2kZ2Eez2TZP/n+3m/9yYn8XiamerM
xzMhLrswuzCPFnDp+qx0a3CaJObp9MFS/bTUMIQLp5Xnzch2VjvD6QWacLmjqvqfiAM80EB+DuNL
8KK6CM+bKk+99566CtFxnqo0mW3UiRDKKeWPu5FkkkIEUVBXY6giEEqYd5YoiB5Me0rxZMqUhlpF
VRaSALb0ZmWXl+G6TWXeTq8olpcFahdO63iIfXJB1vTOZb15mTplTDtnHUk9vGsXw2ZkKC8l6diq
cMfAj//5oSWP9zNmk0VrMNoCLXNnrrn3gi7FWTFrSqm/5t6O3XPm/FIxlM2bmpOU55nmlwvKf/bQ
r5aVWMhrCCPa8ub477j9/DGMR26olf1atz7ZbACHzyzqdW4fr7fcwTizXJJOSgroHZ6svZ7m+QlA
YhfPjy/kMVzKNSacPlotmC1pjDcrkB2wUNPEuU4x48qmrimBBvuz//zT2aGWkkrlQ5IRmhne4L8t
s/LBh6Zlfvd73DLlpU8VZTTkbt7JH4tdbMopvTwwet9A0+57GjfcHU3IOyf+BleGenehx71Zrn/Q
etDKDGWQuZY2c595o26TOWp5IfVFi8bOCJzrVc6X6RStyTqD8WmDL02faQylSBDKtLmcbk3I5pDc
Q56G8fmM+9jYRdXHjuGCrERHq3Kq03UYG1QPS6dhQx9LXawoeNxMuRGmlHI2who1nuLe3eUZGVPu
WbFYS7y6xXcpXypffkHMn5wivF1JZ56dXlJ7b9PWjXN3rGm9feBZMvVL4iBTox+SA6ouatCme1EX
RpzdAjn4gQEjp8XFGFmw+YyioHP5dHoL60yVBIkNcE7JGUpyZEp7PQ31V4UJ1AtqgoaJhFbQPFEt
nWC1UedWnky8WUBFvqIW1UaZ2/bhmlM+mr5/4P8rlwg5+/TW3hktW27dsInrWBpmNF/Je7rbSPmf
iY3Il9c/de+LrWXP3b3nF7g3KIqf46ahPjDcQBY8Ic+drRlK20MexNhNtLxg5J2N/GzjXPdd5M6U
IUnHWllbqjXV1qBpsjbZ5jo7rB22Zc5z5E3uQ9fv3Z+7jfPIbOMOfruRw5B/vzxlQfJNybcks8nJ
6YIvyyPazMF0vZVlstiQbXNWZpdhm4ExOH2MlHx/psPrQyiuWCc1zk6MmefHihJwnEqEzc4YorGu
k6zrBFyL6EHRueIlevA2HjjpYgSTEaoIOb02mTwrbr5hxxtz5FQ9E7MK3VWL2ioybcSrX3b35dPK
cSK9l8YOfHf1uls/Wnlz97bGew7U5pamF3eveJgY0EGn4+dbVbc7MTgd4l9W92pVclYTNJEO6MBP
FCPokgRRp0VnCkKAiLhZG/U0JzSqbtbo9gajZU0YAz7doGBcpHRIeQc1phKHn3uUDZdw+0vwixEQ
uldjwS+nonfW8bTjAHFw/ES34Zi6Z8JOS4rVOHtQ+R1x4UPoD4YAuG7UpxVjfaNcwBML8ZMK0qbv
0wvEbBS0PgQrmdPZ+JAthXE6TMmBFIzwz18RORw7Qd0CblbQSaLLH6uppMEM7c+C9nfFEVBTtFDn
EGCHzyrnbHmD94UylPMktaKkbWgV1zFyKpbF7GktXLx5Zm9slJMfXuyvZRFHFmpx/e/nejF62/CL
VFjOsbFEY9hh2GFkbUn2lJVJLO+zp4l6X7LebtcwIZvTqQmZHA5nlAwenjAPdbHj2h7fTqGA62H9
Op+6B8lSV4QPt09QXkbvFsJ8dNddW7YMDW1hCpWPld/j9TFJw6XrIGmxM78aPXBgZOTAgdGVyhNk
yZ8+JsuU//sxIyOWW5RF3D5uGX7Fd8M8OdeWqtFlOBmfW3QKOl+q3pGsSbInhYzOLEFKl+wBx9f6
V9V61dWMLjaxmMedqeqFys3UVFWPOwEqO/Cd76NH7a1u2bDFRbRK7OTtrUUFyvvEVFh203bm4eM/
mr/x+XBB9EGmUnlfuaD8Vnl1pq8+9iJ/4dE5uXMRZrSj29EYLnEd+JYy7yiwZM5hJiUJY/wc2ZEq
JgkGnZspZmSGtdA9QLI+YHCkWaJkxWFP88rx8HDiNdXIwp3UdhHq16j5ohPCJUdDwYSwzFv61PS8
pH+s8ijvEmNtSfM2roMQ5RzL9Ndsj33O1T6/NmcWlYlB3b+J36C6IR+CsFVeoDUK2Y4kVst59PpG
3Vz9HE+duyH3LKtxZbkNOs6az1mdwaBZ5II5+mAwxaJzu6zhLNFSIIb9zkIDuMIpBRDOdxQUXhUF
LuIWTI1rF9GEMQgg/AkjiZ0ynlI3Zjd23kg6ieou1Mjmx7BQXhaiMSCxB1cDBHUquGXzurPLCenR
Zpbfu7gnJ0eJH21qGjt7kpBU5XeCo2hd54K8vPihJYs/uazEP8UPch1N7srS0mKHY3phfd22Pb95
7MUK97RpgRKrbWrOwpbNPzn1m4MsLgQClvgfmI18H67TeUeMwRTJEDQ9Q9YBRzpkqwgdAhHsqJoU
4SKnDcAPUU/2KEk+7Omi6nmt+nys+mI11c8fw+pL4FgNho2S4tRy+h44xeI10beIUIVFFHBuJste
4hwZyVqa5EoeemleMbv2ZVKsnH45dmyWh5Bf82K4ZCXzMLX3+AfcEvQdDvw23CQX6qxOa551qrVV
7BUFp6gDwZqcpOMxDjuTdAGnXe/MICG7Iz3jL86DrktzZTj2moo5jcDoohBt3Cup3rmcmg3GMJGG
MSqanzxqDaz/YQg/eSofcW7rrC2L/7y4iHzM1cZu6SxaNCivYhZeen4fX5paHfx517PMfS6U06LM
4ZpRTvoG/hu5P6Br1a3U3a87oDujE3gdEYQM0ZRUILqTposlSY1ip0i93wZxU1KSLSWUNKTdod+r
j+qFtDSDJolxGwwBs16vE0RG0mgC+F5Lk0k6i0Gv1QiiFiQmmCoZU9JEKyokOUlviBLDYazQIZcN
qT/UOHot1p8lNDM4/2L4vP0y7j0oTWyda8LnY+drEvtnapEEX255fLtt2XjbL6eMv9jSNG5DK4sS
u5V1nRKxhipmkADxpONWmqE7zAAZ8eU1OR35nNJPpv/xXXyLHV6z9bnswkJy+ysMozOb1hi49ZfP
sb5Lp5WX7ieskEbXnfqL0y/iX/ezYSGLX6qzIQA5UK5+26+H2fgdvQH/12ABfk1vgUX4hb4VluJ3
dfo/WgR3m0TtSqAnIPVLw02Ni/IbetcM9g6s6ukuqL1lzQra6soPM/i/DgDbkHYjPYIUQTqGdBrp
t0h/SjxAjMjdSMVIMlIzUhdSP9I2pN1IjyBFkI7Fx3+Av4k0QW99bX7mpLzqjq5qXzepvn5SvmVS
vnVSvntSfvmkfM+kPMXjanlVvVwlz6pJ9Wsm5W+elL9lUh6xuqb/9ZPy35mUH5iUv3VSfhPN/xeq
2Om9CmVuZHN0cmVhbQplbmRvYmoKNTYgMCBvYmoKNjQyOQplbmRvYmoKNTcgMCBvYmoKKHZ1bG5l
cmFiaWxpdHlfc2NlbmFyaW9fc2VxdWVuY2VfZGlhZ3JhbV92MyBhbHRlcm5hdGUpCmVuZG9iago1
OCAwIG9iagooTWFjIE9TIFggMTAuMTIuMyBRdWFydHogUERGQ29udGV4dCkKZW5kb2JqCjU5IDAg
b2JqCihBZGFtIE1vbnR2aWxsZSkKZW5kb2JqCjYwIDAgb2JqCihPbW5pR3JhZmZsZSBQcm9mZXNz
aW9uYWwgNS40LjQpCmVuZG9iago2MSAwIG9iagooRDoyMDE3MDIwMjIxMDczNVowMCcwMCcpCmVu
ZG9iagoxIDAgb2JqCjw8IC9UaXRsZSA1NyAwIFIgL0F1dGhvciA1OSAwIFIgL1Byb2R1Y2VyIDU4
IDAgUiAvQ3JlYXRvciA2MCAwIFIgL0NyZWF0aW9uRGF0ZQo2MSAwIFIgL01vZERhdGUgNjEgMCBS
ID4+CmVuZG9iagp4cmVmCjAgNjIKMDAwMDAwMDAwMCA2NTUzNSBmIAowMDAwMDM2ODI3IDAwMDAw
IG4gCjAwMDAwMDMyODUgMDAwMDAgbiAKMDAwMDAyMDI1NCAwMDAwMCBuIAowMDAwMDAwMDIyIDAw
MDAwIG4gCjAwMDAwMDMyNjUgMDAwMDAgbiAKMDAwMDAwMzM5OSAwMDAwMCBuIAowMDAwMDE2MTY3
IDAwMDAwIG4gCjAwMDAwMDQxMjkgMDAwMDAgbiAKMDAwMDAwNDQ1MiAwMDAwMCBuIAowMDAwMDA1
MDc4IDAwMDAwIG4gCjAwMDAwMDUzODUgMDAwMDAgbiAKMDAwMDAwNDQ3MSAwMDAwMCBuIAowMDAw
MDA0NzgxIDAwMDAwIG4gCjAwMDAwMDQ4MDEgMDAwMDAgbiAKMDAwMDAwNTA1OSAwMDAwMCBuIAow
MDAwMDA2MDI3IDAwMDAwIG4gCjAwMDAwMDYyODUgMDAwMDAgbiAKMDAwMDAwNTY4MiAwMDAwMCBu
IAowMDAwMDA2MDA3IDAwMDAwIG4gCjAwMDAwMDU0MDUgMDAwMDAgbiAKMDAwMDAwNTY2MyAwMDAw
MCBuIAowMDAwMDAzNjU1IDAwMDAwIG4gCjAwMDAwMDQxMDkgMDAwMDAgbiAKMDAwMDAxNzQ0NCAw
MDAwMCBuIAowMDAwMDI5NDA2IDAwMDAwIG4gCjAwMDAwMjA0MDEgMDAwMDAgbiAKMDAwMDAyMDIx
NyAwMDAwMCBuIAowMDAwMDEwNzU2IDAwMDAwIG4gCjAwMDAwMTE5NDYgMDAwMDAgbiAKMDAwMDAw
ODUzMSAwMDAwMCBuIAowMDAwMDA5NjQ4IDAwMDAwIG4gCjAwMDAwMTE5NjYgMDAwMDAgbiAKMDAw
MDAxMjc2OCAwMDAwMCBuIAowMDAwMDEyNzg4IDAwMDAwIG4gCjAwMDAwMTM4NTYgMDAwMDAgbiAK
MDAwMDAwNzQ0MSAwMDAwMCBuIAowMDAwMDA4NTExIDAwMDAwIG4gCjAwMDAwMTM4NzYgMDAwMDAg
biAKMDAwMDAxNDk0NCAwMDAwMCBuIAowMDAwMDA2MzA0IDAwMDAwIG4gCjAwMDAwMDc0MjEgMDAw
MDAgbiAKMDAwMDAwOTY2OCAwMDAwMCBuIAowMDAwMDEwNzM2IDAwMDAwIG4gCjAwMDAwMTQ5NjQg
MDAwMDAgbiAKMDAwMDAxNjE0NiAwMDAwMCBuIAowMDAwMDE2MjAzIDAwMDAwIG4gCjAwMDAwMTc0
MjMgMDAwMDAgbiAKMDAwMDAxNzQ4MSAwMDAwMCBuIAowMDAwMDIwMTk2IDAwMDAwIG4gCjAwMDAw
MjAzMzcgMDAwMDAgbiAKMDAwMDAyMTAxNyAwMDAwMCBuIAowMDAwMDIxMjQyIDAwMDAwIG4gCjAw
MDAwMjkzODUgMDAwMDAgbiAKMDAwMDAyOTgwNyAwMDAwMCBuIAowMDAwMDMwMDM4IDAwMDAwIG4g
CjAwMDAwMzY1NTggMDAwMDAgbiAKMDAwMDAzNjU3OSAwMDAwMCBuIAowMDAwMDM2NjUwIDAwMDAw
IG4gCjAwMDAwMzY3MDMgMDAwMDAgbiAKMDAwMDAzNjczNiAwMDAwMCBuIAowMDAwMDM2Nzg1IDAw
MDAwIG4gCnRyYWlsZXIKPDwgL1NpemUgNjIgL1Jvb3QgNTAgMCBSIC9JbmZvIDEgMCBSIC9JRCBb
IDxlZmQzNDkyMGRiZDU5NzU3YzFmMzNiMDkxNmM2YjhlYT4KPGVmZDM0OTIwZGJkNTk3NTdjMWYz
M2IwOTE2YzZiOGVhPiBdID4+CnN0YXJ0eHJlZgozNjk0NwolJUVPRgo=
--001a113b197ae5aaee0547929fdd--


From nobody Fri Feb  3 08:44:15 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 683B5129693 for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 08:44:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E3meixZZov35 for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 08:44:11 -0800 (PST)
Received: from mail-ot0-x235.google.com (mail-ot0-x235.google.com [IPv6:2607:f8b0:4003:c0f::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 62178129691 for <sacm@ietf.org>; Fri,  3 Feb 2017 08:44:11 -0800 (PST)
Received: by mail-ot0-x235.google.com with SMTP id 73so18403661otj.0 for <sacm@ietf.org>; Fri, 03 Feb 2017 08:44:11 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to;  bh=4EsLQYktqSqZUyv1a+8n6EEkTtWgAwdc/o3iyoE+4Z4=; b=gjslUAKX9yRn8g5X+x8x6BJN1MFXFjgry4Ymb8QUCMbNVAfiTUeYe4tJoky9gC9XBD fXPfHMuLJBYKrhY9oKc7/SC+NRMpV8ZaViXS2pwMFUnsq5KBO+c++XZolls3RpsIjECm pTvMHL/r65HEjvsNS/rkzaSHWYOvbKccthf2i/N225wUFsgFrX3C6wPEd+9lRpHHNSZI VVANod/seJnfVfx7GA9rB2LTgsTpUdLGfEubBHP3IH3bfIKcUk9XW86ZjFkUanwGrCUU vZ6zLbvWd2JHtrw3w9Od7hE2iSXaqUpNPYzTbZL8Zs9zGUc7agCWDZYG0Zg3hubPjE5S OaMg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=4EsLQYktqSqZUyv1a+8n6EEkTtWgAwdc/o3iyoE+4Z4=; b=fmk2akxNulDdSY1QNX9GE8nltX30Zv9nVO5hlvi+CkTWkQONJtIsoLjGk2kvZAQssW gMcGWOQVzAcJV0rI9rD7eyJ/xkhGlFix3xLO6I8HtJDRGzwoy4NRh8x/DcoCrfxIUfse eoueRPvjtpIC4vo/+f1nC7squQYixMwFMwmNk2U7/7GvtECbuDJxXFuWugs+HNZLDAgd mCNezZAwpoKE5jTf+RX2vIndwXJCsK7ykEFxeA8DUAE/J/LoLQwn8RoNcG6WtksLq43M svaXKk33+Go/5CRaeZQcFzAkVnO4dknvc+gnNqxpUa9SLVOow04c4tiBZSBO0LWIH8N+ oruQ==
X-Gm-Message-State: AMke39m2+FusYs9eTXxtPDSJpbayVX7lnESEU7jcbAOpGNb3FaHxEdlcTLBCv+YYB8xB5ITo5/SsJZaa8iPzow==
X-Received: by 10.157.47.236 with SMTP id b41mr7859573otd.236.1486140250374; Fri, 03 Feb 2017 08:44:10 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com>
In-Reply-To: <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Fri, 03 Feb 2017 16:43:59 +0000
Message-ID: <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com>
To: "sacm@ietf.org" <sacm@ietf.org>
Content-Type: multipart/alternative; boundary=001a113b197ab5c9840547a2fdd1
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/yESZfeoeYlYM--x6EKSsc5Pmw6I>
Subject: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 16:44:13 -0000

--001a113b197ab5c9840547a2fdd1
Content-Type: text/plain; charset=UTF-8

I thought I'd try to break this discussion out of it's former thread into
one of its own, in case that makes it easier for folks to opine.  The list
of "components" or "function groups" seems reasonable to me.  In practice,
there *may* be a desire to have that software acting as an endpoint
repository also act as the repository for assessment results.  Or, these
could be implemented in distinct services.

What works for our purposes?

Adam

On Thu, Feb 2, 2017 at 10:40 AM Adam Montville <adam.w.montville@gmail.com>
wrote:

> Once folks have had an opportunity to review the vulnerability scenario
> information we've been working on, what are your thoughts on the main
> components we're presently focused on for this narrowly scoped exercise?
> These are:
>
> Vulnerability Detection Data Repository
> Vulnerability Assessor
> Endpoint Repository
> Collector
> Assessment Result Repository
> Endpoint
>
>
>
>
> On Thu, Feb 2, 2017 at 10:28 AM Adam Montville <adam.w.montville@gmail.com>
> wrote:
>
> Hi Everyone.  A few of us were able to make the vulnerability scenario
> call today and I think we had a good, though at times spirited,
> discussion.  We did record the meeting, which is available at [1].  We
> discussed the attached (annotated with some meeting notes) UML-ish sequence
> diagram.  I had created that diagram to start a conversation (mission
> accomplished on that front I think) -- a conversation that would lead us
> toward identifying the discrete components, interfaces, and information
> required to be sent over those interfaces.  The UML-ish diagram represents
> a *single* flow through the system -- a "one-time" flow through the
> system.  It ignores, for the time being, the continuous aspect of our
> charter in favor of getting started with the basics.  Once we have a good
> understanding of the basics -- the components, interfaces, and information
> required -- we can start look at a continuous monitoring sequence (which
> could be represented as a distinct diagram) to determine what more we
> need.  Then, I think, we can start drafting solutions.
>
> One of the first issues is that we need to figure out if the components in
> the base flow are accurate.  The main suggestion we've tossed around so far
> is to combine the Endpoint Repository with the Assessment Result Repository.
>
> We talked briefly about what interface we could use for the VDD
> Repository, and naturally ROLIE came up as an option.
>
> We talked a little bit about the first "get endpoints" operation between
> the Vulnerability Assessor and the Endpoint Repository -- specifically
> about whether we should represent on this sequence diagram that information
> supporting a judgement of "stale" would be needed.
>
> We left open the time when we would next meet, favoring to work that out
> on-list.  Next week is TCG, so that may be difficult; the following week is
> RSA, so that may be difficult.
>
> For those who were in attendance today, please add to this note with your
> comments/corrections.
>
> Kind regards,
>
> Adam
>
> [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>
> On Mon, Jan 30, 2017 at 11:21 AM Adam Montville <
> adam.w.montville@gmail.com> wrote:
>
> Hi everyone.  Just a friendly reminder that we are planning to meet again
> this Thursday at the same time (2/2 @ 10am Eastern/3pm UTC) using SACM's
> meeting room at https://ietf.webex.com/meet/sacm.
>
> Kind regards,
>
> Adam
>
>
> On Thu, Jan 19, 2017 at 11:35 AM Adam Montville <
> adam.w.montville@gmail.com> wrote:
>
> Hello. A few of us met informally today to discuss the vulnerability
> scenario in some more detail with the goal of maintaining the narrow focus
> on a vulnerability assessment slice through our notional environment.  We
> are tending to look at major components as black boxes with interfaces and
> data format expectations, and we are not necessarily concerned with how
> those components do things internally/behind the scenes.
>
> The meeting was recorded (you can find it with today's date at [1]).  The
> topic of discussion was primarily in the "phase 1" area of what Danny sent
> to the list not very long ago [2], and resulted in a *starting point*
> diagram [3].
>
> The group who met today are (roughly) agreed on the six main "components"
> represented in that diagram, but also see that we have some work ahead.
> Specifically, we quickly recognized that some of the assumptions the
> vulnerability draft makes may be assumptions we cannot afford to make and
> need to include in the exploration.
>
> We thought it would be a good idea to have another informal discussion in
> a couple of weeks (February 2) at the same time (10am Eastern / 3pm UTC),
> using the same WebEx [4].   At that time we intend to roll through the
> vulnerability assessment scenario assumptions in an effort to determine
> which ones can be left as assumptions and which ones cannot.  Then we'll
> take another look at the diagram and work on its next version.
>
> Stay tuned.
>
> Thanks to Danny, Stephen, and Jerome for joining and contributing!
>
> Kind regards,
>
> Adam
>
>
> [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
> [2] https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
> [3] https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
> [4] https://ietf.webex.com/meet/sacm
>
>

--001a113b197ab5c9840547a2fdd1
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I thought I&#39;d try to break this discussion out of it&#=
39;s former thread into one of its own, in case that makes it easier for fo=
lks to opine.=C2=A0 The list of &quot;components&quot; or &quot;function gr=
oups&quot; seems reasonable to me.=C2=A0 In practice, there *may* be a desi=
re to have that software acting as an endpoint repository also act as the r=
epository for assessment results.=C2=A0 Or, these could be implemented in d=
istinct services.<div><br></div><div>What works for our purposes?<br><div><=
br></div><div>Adam<br><br><div class=3D"gmail_quote"><div dir=3D"ltr">On Th=
u, Feb 2, 2017 at 10:40 AM Adam Montville &lt;<a href=3D"mailto:adam.w.mont=
ville@gmail.com">adam.w.montville@gmail.com</a>&gt; wrote:<br></div><blockq=
uote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc =
solid;padding-left:1ex"><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"=
gmail_msg">Once folks have had an opportunity to review the vulnerability s=
cenario information we&#39;ve been working on, what are your thoughts on th=
e main components we&#39;re presently focused on for this narrowly scoped e=
xercise?=C2=A0 These are:</div><div class=3D"gmail_msg"><br class=3D"gmail_=
msg"></div><div class=3D"gmail_msg">Vulnerability Detection Data Repository=
</div><div class=3D"gmail_msg">Vulnerability Assessor</div><div class=3D"gm=
ail_msg">Endpoint Repository</div><div class=3D"gmail_msg">Collector</div><=
div class=3D"gmail_msg">Assessment Result Repository</div><div class=3D"gma=
il_msg">Endpoint</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></di=
v><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmai=
l_msg"><br class=3D"gmail_msg"></div></div><br class=3D"gmail_msg"><div cla=
ss=3D"gmail_quote gmail_msg"><div dir=3D"ltr" class=3D"gmail_msg">On Thu, F=
eb 2, 2017 at 10:28 AM Adam Montville &lt;<a href=3D"mailto:adam.w.montvill=
e@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.c=
om</a>&gt; wrote:<br class=3D"gmail_msg"></div><blockquote class=3D"gmail_q=
uote gmail_msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;paddi=
ng-left:1ex"><div dir=3D"ltr" class=3D"gmail_msg">Hi Everyone.=C2=A0 A few =
of us were able to make the vulnerability scenario call today and I think w=
e had a good, though at times spirited, discussion.=C2=A0 We did record the=
 meeting, which is available at [1].=C2=A0 We discussed the attached (annot=
ated with some meeting notes) UML-ish sequence diagram.=C2=A0 I had created=
 that diagram to start a conversation (mission accomplished on that front I=
 think) -- a conversation that would lead us toward identifying the discret=
e components, interfaces, and information required to be sent over those in=
terfaces.=C2=A0 The UML-ish diagram represents a *single* flow through the =
system -- a &quot;one-time&quot; flow through the system.=C2=A0 It ignores,=
 for the time being, the continuous aspect of our charter in favor of getti=
ng started with the basics.=C2=A0 Once we have a good understanding of the =
basics -- the components, interfaces, and information required -- we can st=
art look at a continuous monitoring sequence (which could be represented as=
 a distinct diagram) to determine what more we need.=C2=A0 Then, I think, w=
e can start drafting solutions.=C2=A0<div class=3D"gmail_msg"><br class=3D"=
gmail_msg"></div><div class=3D"gmail_msg">One of the first issues is that w=
e need to figure out if the components in the base flow are accurate.=C2=A0=
 The main suggestion we&#39;ve tossed around so far is to combine the Endpo=
int Repository with the Assessment Result Repository.</div><div class=3D"gm=
ail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">We talked b=
riefly about what interface we could use for the VDD Repository, and natura=
lly ROLIE came up as an option.</div><div class=3D"gmail_msg"><br class=3D"=
gmail_msg"></div><div class=3D"gmail_msg">We talked a little bit about the =
first &quot;get endpoints&quot; operation between the Vulnerability Assesso=
r and the Endpoint Repository -- specifically about whether we should repre=
sent on this sequence diagram that information supporting a judgement of &q=
uot;stale&quot; would be needed.</div><div class=3D"gmail_msg"><br class=3D=
"gmail_msg"></div><div class=3D"gmail_msg">We left open the time when we wo=
uld next meet, favoring to work that out on-list.=C2=A0 Next week is TCG, s=
o that may be difficult; the following week is RSA, so that may be difficul=
t.</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=
=3D"gmail_msg">For those who were in attendance today, please add to this n=
ote with your comments/corrections.</div></div><div dir=3D"ltr" class=3D"gm=
ail_msg"><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=
=3D"gmail_msg">Kind regards,</div><div class=3D"gmail_msg"><br class=3D"gma=
il_msg"></div><div class=3D"gmail_msg">Adam</div><div class=3D"gmail_msg"><=
div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_m=
sg">[1]=C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGh=
DOHpVR0tMd1E" class=3D"gmail_msg" target=3D"_blank">https://drive.google.co=
m/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a>=C2=A0</div></div><br class=3D"=
gmail_msg"></div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_q=
uote gmail_msg"><div dir=3D"ltr" class=3D"gmail_msg">On Mon, Jan 30, 2017 a=
t 11:21 AM Adam Montville &lt;<a href=3D"mailto:adam.w.montville@gmail.com"=
 class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt; w=
rote:<br class=3D"gmail_msg"></div><blockquote class=3D"gmail_quote gmail_m=
sg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"=
><div dir=3D"ltr" class=3D"gmail_msg">Hi everyone.=C2=A0 Just a friendly re=
minder that we are planning to meet again this Thursday at the same time (2=
/2 @ 10am Eastern/3pm UTC) using SACM&#39;s meeting room at <a href=3D"http=
s://ietf.webex.com/meet/sacm" class=3D"gmail_msg" target=3D"_blank">https:/=
/ietf.webex.com/meet/sacm</a>.=C2=A0<div class=3D"gmail_msg"><br class=3D"g=
mail_msg"></div><div class=3D"gmail_msg">Kind regards,</div><div class=3D"g=
mail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">Adam</div>=
</div><div dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_msg"><br cla=
ss=3D"gmail_msg"><br class=3D"gmail_msg"><div class=3D"gmail_quote gmail_ms=
g"><div dir=3D"ltr" class=3D"gmail_msg">On Thu, Jan 19, 2017 at 11:35 AM Ad=
am Montville &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gma=
il_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt; wrote:<br clas=
s=3D"gmail_msg"></div><blockquote class=3D"gmail_quote gmail_msg" style=3D"=
margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"=
ltr" class=3D"gmail_msg">Hello. A few of us met informally today to discuss=
 the vulnerability scenario in some more detail with the goal of maintainin=
g the narrow focus on a vulnerability assessment slice through our notional=
 environment.=C2=A0 We are tending to look at major components as black box=
es with interfaces and data format expectations, and we are not necessarily=
 concerned with how those components do things internally/behind the scenes=
.<div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail=
_msg">The meeting was recorded (you can find it with today&#39;s date at [1=
]).=C2=A0 The topic of discussion was primarily in the &quot;phase 1&quot; =
area of what Danny sent to the list not very long ago [2], and resulted in =
a *starting point* diagram [3].<div class=3D"gmail_msg"><br class=3D"gmail_=
msg"></div><div class=3D"gmail_msg">The group who met today are (roughly) a=
greed on the six main &quot;components&quot; represented in that diagram, b=
ut also see that we have some work ahead.=C2=A0 Specifically, we quickly re=
cognized that some of the assumptions the vulnerability draft makes may be =
assumptions we cannot afford to make and need to include in the exploration=
.</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D=
"gmail_msg">We thought it would be a good idea to have another informal dis=
cussion in a couple of weeks (February 2) at the same time (10am Eastern / =
3pm UTC), using the same WebEx [4]. =C2=A0 At that time we intend to roll t=
hrough the vulnerability assessment scenario assumptions in an effort to de=
termine which ones can be left as assumptions and which ones cannot.=C2=A0 =
Then we&#39;ll take another look at the diagram and work on its next versio=
n.</div><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=
=3D"gmail_msg">Stay tuned.</div><div class=3D"gmail_msg"><br class=3D"gmail=
_msg"></div><div class=3D"gmail_msg">Thanks to Danny, Stephen, and Jerome f=
or joining and contributing!</div><div class=3D"gmail_msg"><br class=3D"gma=
il_msg"></div><div class=3D"gmail_msg">Kind regards,</div><div class=3D"gma=
il_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg">Adam<br clas=
s=3D"gmail_msg"><div class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div=
 class=3D"gmail_msg"><br class=3D"gmail_msg"></div><div class=3D"gmail_msg"=
>[1]=C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOH=
pVR0tMd1E" class=3D"gmail_msg" target=3D"_blank">https://drive.google.com/o=
pen?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a></div><div class=3D"gmail_msg">[2]=
=C2=A0<a href=3D"https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLF=
hB5NSU58MXDM" class=3D"gmail_msg" target=3D"_blank">https://mailarchive.iet=
f.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM</a></div><div class=3D"gmai=
l_msg">[3]=C2=A0<a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCb=
MU5pdTRjejJtNHc" class=3D"gmail_msg" target=3D"_blank">https://drive.google=
.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a></div><div class=3D"gmail_ms=
g">[4] <a href=3D"https://ietf.webex.com/meet/sacm" class=3D"gmail_msg" tar=
get=3D"_blank">https://ietf.webex.com/meet/sacm</a>=C2=A0</div><div class=
=3D"gmail_msg"><br class=3D"gmail_msg"></div></div></div></div></blockquote=
></div></div></div></blockquote></div></div></blockquote></div></blockquote=
></div></div></div></div>

--001a113b197ab5c9840547a2fdd1--


From nobody Fri Feb  3 09:41:19 2017
Return-Path: <dhaynes@mitre.org>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3EA2C1294A6 for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 09:41:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.397
X-Spam-Level: 
X-Spam-Status: No, score=-7.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-3.199, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=mitre.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6gLKhb2Reu-r for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 09:41:15 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (smtpvmsrv1.mitre.org [192.52.194.136]) by ietfa.amsl.com (Postfix) with ESMTP id 058F012944B for <sacm@ietf.org>; Fri,  3 Feb 2017 09:41:14 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id 11B1EEBDC8E; Fri,  3 Feb 2017 12:41:14 -0500 (EST)
Received: from imshyb01.MITRE.ORG (imshyb01.mitre.org [129.83.29.2]) by smtpvmsrv1.mitre.org (Postfix) with ESMTP id E8CA36FC616; Fri,  3 Feb 2017 12:41:13 -0500 (EST)
Received: from imshyb02.MITRE.ORG (129.83.29.3) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Fri, 3 Feb 2017 12:41:13 -0500
Received: from gcc01-CY1-obe.outbound.protection.outlook.com (10.140.19.249) by imshyb02.MITRE.ORG (129.83.29.3) with Microsoft SMTP Server (TLS) id 15.0.1263.5 via Frontend Transport; Fri, 3 Feb 2017 12:41:13 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mitre.onmicrosoft.com;  s=selector1-mitre-org; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=pedsiDYGDBIS/nwdUwbm9NzIOcGmkXtsLUwiXlGzzgw=; b=Ui01tpZynU2lpNpEjvqpnfV51nkcL98VLGLXWnS/3NYXsHPLNAfxlgnvzcq0Jt9fVWld++xiI32IrW4zuclxKW+zuvQ9oZY9ZVQoSgYDdkGzmmc6wXXvwkXQA6UjoFZQE5YK5bZtJCEpU2h6kvcRZwhcyVFwHbIaxH9zQJjlF0A=
Received: from BN6PR09MB1458.namprd09.prod.outlook.com (10.173.202.22) by BN6PR09MB1457.namprd09.prod.outlook.com (10.173.202.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.888.16; Fri, 3 Feb 2017 17:41:06 +0000
Received: from BN6PR09MB1458.namprd09.prod.outlook.com ([10.173.202.22]) by BN6PR09MB1458.namprd09.prod.outlook.com ([10.173.202.22]) with mapi id 15.01.0888.021; Fri, 3 Feb 2017 17:41:06 +0000
From: "Haynes, Dan" <dhaynes@mitre.org>
To: Adam Montville <adam.w.montville@gmail.com>, Bill Munyan <bill.munyan.ietf@gmail.com>
Thread-Topic: [sacm] Notes on Vulnerability Scenario Working Session
Thread-Index: AQHScnqFraRrjs8/rEyZzQVQK8LSq6FRVaqAgASoDICAAAcggIAADkoAgAADawCAAADPgIABjQSg
Date: Fri, 3 Feb 2017 17:41:06 +0000
Message-ID: <BN6PR09MB14580BE5DCFB0162BC69F1A7A54F0@BN6PR09MB1458.namprd09.prod.outlook.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com> <CACknUNVs3XCMdVYi3-FnTMpQ1x8x6_gr3tQ7pzuPBKsiWF4duw@mail.gmail.com>
In-Reply-To: <CACknUNVs3XCMdVYi3-FnTMpQ1x8x6_gr3tQ7pzuPBKsiWF4duw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=dhaynes@mitre.org; 
x-originating-ip: [192.160.51.87]
x-ms-office365-filtering-correlation-id: 95847689-9c53-459f-c196-08d44c5bd540
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(48565401081); SRVR:BN6PR09MB1457; 
x-microsoft-exchange-diagnostics: 1; BN6PR09MB1457; 7:6c/P2dDY+bCozMCJEFFg96zW2DG2iSyFiZzuzMTwPtvCSkp8uU4jxY6LbMAzCHI03/vgMkvnVtooaAb8c3dgonU+mBVdzMoRtkpJb/qoXPxvT1cWIIsbxeaGZ41D5xm6iqYmGUi/4JiCZMInZlDSQCpUGwJqQ/qAci3YAX1DAAfhBiO+9/dVqPMmf50gs88Tr85hbbSZN83HfTwCP/t8zxF8yculGcgJlNtZYvfzGSbUbbD7TU9TQptpxfg+1LGfKKe4EWlD643YW/STXPQaz3gspv+/FpV74fG1mbKLIajYm7XTwmYZsyvGQ+qrayZUoEzWlYU09D3jJ+dzfSt7KzRafvvb2Ly+EepZwKv67QSrFu8+EzQvdN04+Tld+J6kGLCTMWnSkJl9H04Q7n1zfQab0pWQZBM6f1SxFg6GcEKn/KMurRsHO+cHGva9so2ruiSVrSspX71mbwb0Du98k9MY9hCxN/UXs+Kx9IUH/3M3iytP0eHDqn4LKDmcyA2fkn9fUsYKj81Sv4juwq9xsw==
x-microsoft-antispam-prvs: <BN6PR09MB1457D0FA5C3113C950E51189A54F0@BN6PR09MB1457.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(72170088055959)(94707916325470)(211936372134217)(21748063052155)(145926492361056);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6055026)(6041248)(20161123558025)(20161123560025)(20161123555025)(20161123562025)(20161123564025)(6072148); SRVR:BN6PR09MB1457; BCL:0; PCL:0; RULEID:; SRVR:BN6PR09MB1457; 
x-forefront-prvs: 02070414A1
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(7916002)(39450400003)(39410400002)(39850400002)(39840400002)(46034005)(51694002)(199003)(51914003)(24454002)(377454003)(189002)(53754006)(3280700002)(6306002)(106116001)(101416001)(33656002)(25786008)(68736007)(7736002)(2906002)(106356001)(54896002)(6506006)(9686003)(54356999)(76176999)(50986999)(4326007)(99286003)(54906002)(236005)(93886004)(122556002)(606005)(77096006)(5001770100001)(97736004)(105586002)(66066001)(31430400001)(55016002)(6436002)(102836003)(81156014)(92566002)(53936002)(3846002)(53546003)(6246003)(6116002)(2950100002)(790700001)(8936002)(5660300001)(81166006)(8676002)(575784001)(19609705001)(39060400001)(86362001)(189998001)(7906003)(7696004)(38730400001)(5890100001)(3660700001)(14971765001)(2900100001)(74316002)(229853002); DIR:OUT; SFP:1101; SCL:1; SRVR:BN6PR09MB1457; H:BN6PR09MB1458.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: mitre.org does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_BN6PR09MB14580BE5DCFB0162BC69F1A7A54F0BN6PR09MB1458namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Feb 2017 17:41:06.7966 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c620dc48-1d50-4952-8b39-df4d54d74d82
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN6PR09MB1457
X-OriginatorOrg: mitre.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/4tIuf2YVDmuSPHpOGX-0QqyTGTk>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 17:41:18 -0000

--_000_BN6PR09MB14580BE5DCFB0162BC69F1A7A54F0BN6PR09MB1458namp_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

VGhhdCB3b3JrcyBmb3IgbWUuDQoNClRoYW5rcywNCg0KRGFubnkNCg0KRnJvbTogc2FjbSBbbWFp
bHRvOnNhY20tYm91bmNlc0BpZXRmLm9yZ10gT24gQmVoYWxmIE9mIEFkYW0gTW9udHZpbGxlDQpT
ZW50OiBUaHVyc2RheSwgRmVicnVhcnkgMDIsIDIwMTcgMTowMCBQTQ0KVG86IEJpbGwgTXVueWFu
IDxiaWxsLm11bnlhbi5pZXRmQGdtYWlsLmNvbT4NCkNjOiBIZW5rIEJpcmtob2x6IDxoZW5rLmJp
cmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPjsgc2FjbUBpZXRmLm9yZw0KU3ViamVjdDogUmU6IFtz
YWNtXSBOb3RlcyBvbiBWdWxuZXJhYmlsaXR5IFNjZW5hcmlvIFdvcmtpbmcgU2Vzc2lvbg0KDQpZ
ZXMhIE5vdGluZyB0aGF0IGluZm9ybWF0aW9uIGlzIGNyaXRpY2FsLCBidXQgaWYgd2Ugc2V0IG91
dCB0byBwdXQgYWxsIG9mIHRoYXQgaW4gdGhlIGRpYWdyYW0sIHdlJ2xsIGxvc2UuICBXaGF0IGlm
IHdlIGFncmVlIHRvIHRoZSBzZXF1ZW5jZSBhdCB0aGUgaGlnaCBsZXZlbCwgdGhlbiBudW1iZXIg
dGhlIHN0ZXBzLCBhbmQgdGhlbiB3cml0ZSBhYm91dCB0aG9zZSBzdGVwcyBpbiB0aGUgd2lraSBh
ZnRlciB0YWxraW5nIGFib3V0IHRoZW0gaGVyZSBhbmQgaW4gaW5mb3JtYWwgc2Vzc2lvbnMgZm9y
IHRoZSB3aW4/DQoNCk9uIFRodSwgRmViIDIsIDIwMTcgYXQgMTE6NTcgQU0gQmlsbCBNdW55YW4g
PGJpbGwubXVueWFuLmlldGZAZ21haWwuY29tPG1haWx0bzpiaWxsLm11bnlhbi5pZXRmQGdtYWls
LmNvbT4+IHdyb3RlOg0KSXMgaXQgd29ydGggbm90aW5nIGluIHRoZSBkaWFncmFtIChpZiBub3Qs
IEkgdGhpbmsgaXQgbmVlZHMgdG8gYmUgbm90ZWQgc29tZXdoZXJlIG5vbmV0aGVsZXNzKSB0aGF0
IHRoZSBzdGVwcyBvZiAiZ2V0IGVuZHBvaW50cyIgYW5kIHN1YnNlcXVlbnQgImV2YWx1YXRlIiBz
aG91bGQgYmUgbWFraW5nIHNvbWUgZGV0ZXJtaW5hdGlvbiBvZiB3aGV0aGVyIG9yIG5vdCB0byBj
b2xsZWN0IGZvciBhbiBlbmRwb2ludD8gIEZvciBleGFtcGxlLCBpZiBhbiBlbmRwb2ludCBoYXMg
bm8gYXNzZXNzbWVudCByZXN1bHRzIG9yIHRoZSBhc3Nlc3NtZW50IHJlc3VsdHMgYXJlIGNvbnNp
ZGVyZWQgInN0YWxlIiwgdGhlbiB0aGUgY29sbGVjdGlvbiBzdGVwIHdvdWxkIHRha2UgcGxhY2Uu
ICBJIHVuZGVyc3RhbmQgdGhhdCBjb3VsZCBiZSB0b28gbXVjaCBkZXRhaWwgZm9yIHRoZSBzY29w
ZSBvZiB0aGUgZGlhZ3JhbSwgYnV0IEkganVzdCB3YW50ZWQgdG8gbm90ZSBpdCBzb21ld2hlcmUu
DQoNCkNoZWVycywNCi1CaWxsIE0uDQoNCg0KT24gVGh1LCBGZWIgMiwgMjAxNyBhdCAxMjo0NCBQ
TSwgQWRhbSBNb250dmlsbGUgPGFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFt
LncubW9udHZpbGxlQGdtYWlsLmNvbT4+IHdyb3RlOg0KVGhhbmtzIGZvciB0aGUgZmVlZGJhY2sh
ICBJJ3ZlIGF0dGFjaGVkIGEgbW9kaWZpZWQgdmVyc2lvbiBvZiB0aGUgZGlhZ3JhbSB0aGF0IGNv
bGxhcHNlcyB0aGUgZW5kcG9pbnQgYW5kIGFzc2Vzc21lbnQgcmVzdWx0IHJlcG9zaXRvcmllcyAo
Ynkga2VlcGluZyB0aGUgZW5kcG9pbnQgcmVwb3NpdG9yeSkuICBXaGVyZSB3b3VsZCB5b3UgcHJv
cG9zZSB3ZSBmb2N1cyBvbiBlbmhhbmNpbmcgdGhlIGRpYWdyYW0/ICBSZW1lbWJlciB0aGF0IGl0
J3MgYSBzZXF1ZW5jZSBkaWFncmFtLCB3aGljaCBtaWdodCBkbyB3ZWxsIHdpdGggc29tZSBtb3Jl
IHNwZWNpZmljIGRldGFpbHMgY2FwdHVyZWQgaW4gdGV4dCBvciBhIGRpZmZlcmVudCBmb3JtIG9m
IGRpYWdyYW0uDQoNCldoYXQgZG8gZm9sa3MgdGhpbmsgYWJvdXQgdXNpbmcgb25lIG9yIG1vcmUg
T1ZBTCBkZWZpbml0aW9ucyBhcyBhIHN0YXJ0aW5nIHBvaW50Pw0KDQpBZGFtDQoNCg0KT24gVGh1
LCBGZWIgMiwgMjAxNyBhdCAxMDo1MyBBTSBIZW5rIEJpcmtob2x6IDxoZW5rLmJpcmtob2x6QHNp
dC5mcmF1bmhvZmVyLmRlPG1haWx0bzpoZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPj4g
d3JvdGU6DQojIyBBIEZldyBDb21tZW50cw0KDQoqIEkgYWdyZWUgdGhhdCB0aGUgZGlhZ3JhbSBw
cmV0dHkgbXVjaCBjYXB0dXJlcyBhICJvbmUgdGltZSBzbmFwc2hvdCIuDQoqIENvbGxhcHNpbmcg
dGhlIGhpZ2hsaWdodGVkIGNvbXBvbmVudHMgc2VlbXMgdG8gYmUgYSBmZWFzaWJsZSBpZGVhLg0K
KiBJIGFncmVlIHRoYXQgdGhlIGRpYWdyYW0gY291bGQgYmUgaW1wbGVtZW50ZWQgZ2l2ZW4gYW4g
YXBwcm9wcmlhdGUgc2V0DQpvZiBpbml0aWFsIGRhdGEuDQoqIEkgc3VwcG9zZSB0aGVyZSBpcyB0
aGUgcmlzayB0aGF0IG9uZSBoYXMgdG8gc2NyYXAgZXZlcnl0aGluZw0KaW1wbGVtZW50ZWQgd2hl
biB3ZSBzdGFydCB0cnlpbmcgdG8gbWFrZSBpdCBhIGNvbnRpbnVvdXMgcHJvY2Vzcy4NCiogSSdk
IHJlY29tbWVuZCB0byBzdGFydCB3aXRoIGEgZ2VuZXJpYyBibG9jayBvZiBQb0MgY29kZSB0aGF0
IHByb3ZpZGVzDQp0aGUgZnVuY3Rpb25zIG9mIGEgU0FDTSBjb21wb25lbnQgdG8gZ2V0IGlucHV0
IGFuZCBjcmVhdGUgb3V0cHV0IChtYXliZQ0KdXNpbmcgZGJ1cywgY2hhaW5lZCBldmVudC1sb29w
cywgYmxvY2tpbmcgd2FpdHMgb24gZmlmb3MsIG9yIElQIG92ZXINCmxvb3BiYWNrPyBBIGJldHRl
ciBjb2RlciB0aGFuIG1lIHNob3VsZCBiYXNoIHRoZXNlIHN1Z2dlc3Rpb25zKS4NCg0KIyMgT25l
LCBUd28sIG9yIFRocmVlIFRhc2tzDQoNCiogQ3JlYXRpbmcgY29tcG9uZW50IGNvZGUgdGhhdCBj
YW4gY3JlYXRlIHRoZSAoZG93bnN0cmVhbT8pIGZsb3cgb2YNCmluZm9ybWF0aW9uIGlzIHVyZ2Vu
dCBhbmQgaW1wb3J0YW50LCBJIHRoaW5rLg0KKiBFbmhhbmNpbmcgdGhlIGRpYWdyYW0gdG8gcmVw
cmVzZW50IHRoZSBjb250aW51b3VzIGN5Y2xlIHdpdGggYXQgbGVhc3QNCm9uZSB0cmlnZ2VyIChh
cyBpbGx1c3RyYXRlZCBieSBCaWxsOyBuZXcgc29mdHdhcmUsIG5ldyBWREksIG5ldw0KZW5kcG9p
bnRzLCBzdGFsZSByZXN1bHRzLCBldGMuKSBpcyBpbXBvcnRhbnQsIGJ1dCBub3QgYXMgdXJnZW50
LiBJdA0KbWlnaHQgc2F2ZSB0aW1lIHRob3VnaCBieSByZWR1Y2luZyB0aGUgYWZvcmUgbWVudGlv
bmVkIHJpc2sgdG8gc2hvb3QNCnlvdXIgc2VsZiBpbiB0aGUgZm9vdCBieSBjcmVhdGluZyBhIHRv
byBzcGVjaWZpYyBwcm9vZiBvZiBjb25jZXB0IG9mIHRoZQ0Kb25lIHRpbWUgc25hcHNob3QgYXBw
cm9hY2gsIEkgdGhpbmsuDQoqIFNlbGVjdGluZyBhIHNldCBvZiBpbml0aWFsIGRhdGEgZGVyaXZl
ZCBmcm9tIE9WQUwgdG8gYmUgdXNlZCBpbiB0aGUNCm9uZSBzaG90IHNuYXBzaG90IHNlZW1zIHRv
IGJlIGEgZmVhc2libGUgYXBwcm9hY2ggdG8gbWUsIGJ1dCBJIGFtIG5vdA0Kc3VyZSBob3cgdGhl
IGdyb3VwIHRoaW5rcyBhYm91dCB0aGF0Lg0KDQpEb2VzIHRoYXQgYXNzZXNzbWVudCByZXByZXNl
bnQgdGhlIGdlbmVyYWwgb3Bpbmlvbiwgb3IgaXMgdGhhdCBqdXN0IG1pbmU/DQoNClZpZWxlIEdy
w7zDn2UsDQoNCkhlbmsNCg0KT24gMDIvMDIvMjAxNyAwNToyOCBQTSwgQWRhbSBNb250dmlsbGUg
d3JvdGU6DQo+IEhpIEV2ZXJ5b25lLiAgQSBmZXcgb2YgdXMgd2VyZSBhYmxlIHRvIG1ha2UgdGhl
IHZ1bG5lcmFiaWxpdHkgc2NlbmFyaW8NCj4gY2FsbCB0b2RheSBhbmQgSSB0aGluayB3ZSBoYWQg
YSBnb29kLCB0aG91Z2ggYXQgdGltZXMgc3Bpcml0ZWQsDQo+IGRpc2N1c3Npb24uICBXZSBkaWQg
cmVjb3JkIHRoZSBtZWV0aW5nLCB3aGljaCBpcyBhdmFpbGFibGUgYXQgWzFdLiAgV2UNCj4gZGlz
Y3Vzc2VkIHRoZSBhdHRhY2hlZCAoYW5ub3RhdGVkIHdpdGggc29tZSBtZWV0aW5nIG5vdGVzKSBV
TUwtaXNoDQo+IHNlcXVlbmNlIGRpYWdyYW0uICBJIGhhZCBjcmVhdGVkIHRoYXQgZGlhZ3JhbSB0
byBzdGFydCBhIGNvbnZlcnNhdGlvbg0KPiAobWlzc2lvbiBhY2NvbXBsaXNoZWQgb24gdGhhdCBm
cm9udCBJIHRoaW5rKSAtLSBhIGNvbnZlcnNhdGlvbiB0aGF0DQo+IHdvdWxkIGxlYWQgdXMgdG93
YXJkIGlkZW50aWZ5aW5nIHRoZSBkaXNjcmV0ZSBjb21wb25lbnRzLCBpbnRlcmZhY2VzLA0KPiBh
bmQgaW5mb3JtYXRpb24gcmVxdWlyZWQgdG8gYmUgc2VudCBvdmVyIHRob3NlIGludGVyZmFjZXMu
ICBUaGUgVU1MLWlzaA0KPiBkaWFncmFtIHJlcHJlc2VudHMgYSAqc2luZ2xlKiBmbG93IHRocm91
Z2ggdGhlIHN5c3RlbSAtLSBhICJvbmUtdGltZSINCj4gZmxvdyB0aHJvdWdoIHRoZSBzeXN0ZW0u
ICBJdCBpZ25vcmVzLCBmb3IgdGhlIHRpbWUgYmVpbmcsIHRoZSBjb250aW51b3VzDQo+IGFzcGVj
dCBvZiBvdXIgY2hhcnRlciBpbiBmYXZvciBvZiBnZXR0aW5nIHN0YXJ0ZWQgd2l0aCB0aGUgYmFz
aWNzLiAgT25jZQ0KPiB3ZSBoYXZlIGEgZ29vZCB1bmRlcnN0YW5kaW5nIG9mIHRoZSBiYXNpY3Mg
LS0gdGhlIGNvbXBvbmVudHMsDQo+IGludGVyZmFjZXMsIGFuZCBpbmZvcm1hdGlvbiByZXF1aXJl
ZCAtLSB3ZSBjYW4gc3RhcnQgbG9vayBhdCBhDQo+IGNvbnRpbnVvdXMgbW9uaXRvcmluZyBzZXF1
ZW5jZSAod2hpY2ggY291bGQgYmUgcmVwcmVzZW50ZWQgYXMgYSBkaXN0aW5jdA0KPiBkaWFncmFt
KSB0byBkZXRlcm1pbmUgd2hhdCBtb3JlIHdlIG5lZWQuICBUaGVuLCBJIHRoaW5rLCB3ZSBjYW4g
c3RhcnQNCj4gZHJhZnRpbmcgc29sdXRpb25zLg0KPg0KPiBPbmUgb2YgdGhlIGZpcnN0IGlzc3Vl
cyBpcyB0aGF0IHdlIG5lZWQgdG8gZmlndXJlIG91dCBpZiB0aGUgY29tcG9uZW50cw0KPiBpbiB0
aGUgYmFzZSBmbG93IGFyZSBhY2N1cmF0ZS4gIFRoZSBtYWluIHN1Z2dlc3Rpb24gd2UndmUgdG9z
c2VkIGFyb3VuZA0KPiBzbyBmYXIgaXMgdG8gY29tYmluZSB0aGUgRW5kcG9pbnQgUmVwb3NpdG9y
eSB3aXRoIHRoZSBBc3Nlc3NtZW50IFJlc3VsdA0KPiBSZXBvc2l0b3J5Lg0KPg0KPiBXZSB0YWxr
ZWQgYnJpZWZseSBhYm91dCB3aGF0IGludGVyZmFjZSB3ZSBjb3VsZCB1c2UgZm9yIHRoZSBWREQN
Cj4gUmVwb3NpdG9yeSwgYW5kIG5hdHVyYWxseSBST0xJRSBjYW1lIHVwIGFzIGFuIG9wdGlvbi4N
Cj4NCj4gV2UgdGFsa2VkIGEgbGl0dGxlIGJpdCBhYm91dCB0aGUgZmlyc3QgImdldCBlbmRwb2lu
dHMiIG9wZXJhdGlvbiBiZXR3ZWVuDQo+IHRoZSBWdWxuZXJhYmlsaXR5IEFzc2Vzc29yIGFuZCB0
aGUgRW5kcG9pbnQgUmVwb3NpdG9yeSAtLSBzcGVjaWZpY2FsbHkNCj4gYWJvdXQgd2hldGhlciB3
ZSBzaG91bGQgcmVwcmVzZW50IG9uIHRoaXMgc2VxdWVuY2UgZGlhZ3JhbSB0aGF0DQo+IGluZm9y
bWF0aW9uIHN1cHBvcnRpbmcgYSBqdWRnZW1lbnQgb2YgInN0YWxlIiB3b3VsZCBiZSBuZWVkZWQu
DQo+DQo+IFdlIGxlZnQgb3BlbiB0aGUgdGltZSB3aGVuIHdlIHdvdWxkIG5leHQgbWVldCwgZmF2
b3JpbmcgdG8gd29yayB0aGF0IG91dA0KPiBvbi1saXN0LiAgTmV4dCB3ZWVrIGlzIFRDRywgc28g
dGhhdCBtYXkgYmUgZGlmZmljdWx0OyB0aGUgZm9sbG93aW5nIHdlZWsNCj4gaXMgUlNBLCBzbyB0
aGF0IG1heSBiZSBkaWZmaWN1bHQuDQo+DQo+IEZvciB0aG9zZSB3aG8gd2VyZSBpbiBhdHRlbmRh
bmNlIHRvZGF5LCBwbGVhc2UgYWRkIHRvIHRoaXMgbm90ZSB3aXRoDQo+IHlvdXIgY29tbWVudHMv
Y29ycmVjdGlvbnMuDQo+DQo+IEtpbmQgcmVnYXJkcywNCj4NCj4gQWRhbQ0KPg0KPiBbMV0gaHR0
cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERPSHBWUjB0TWQx
RQ0KPg0KPiBPbiBNb24sIEphbiAzMCwgMjAxNyBhdCAxMToyMSBBTSBBZGFtIE1vbnR2aWxsZQ0K
PiA8YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21h
aWwuY29tPiA8bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFtLncu
bW9udHZpbGxlQGdtYWlsLmNvbT4+PiB3cm90ZToNCj4NCj4gICAgIEhpIGV2ZXJ5b25lLiAgSnVz
dCBhIGZyaWVuZGx5IHJlbWluZGVyIHRoYXQgd2UgYXJlIHBsYW5uaW5nIHRvIG1lZXQNCj4gICAg
IGFnYWluIHRoaXMgVGh1cnNkYXkgYXQgdGhlIHNhbWUgdGltZSAoMi8yIEAgMTBhbSBFYXN0ZXJu
LzNwbSBVVEMpDQo+ICAgICB1c2luZyBTQUNNJ3MgbWVldGluZyByb29tIGF0IGh0dHBzOi8vaWV0
Zi53ZWJleC5jb20vbWVldC9zYWNtLg0KPg0KPiAgICAgS2luZCByZWdhcmRzLA0KPg0KPiAgICAg
QWRhbQ0KPg0KPg0KPiAgICAgT24gVGh1LCBKYW4gMTksIDIwMTcgYXQgMTE6MzUgQU0gQWRhbSBN
b250dmlsbGUNCj4gICAgIDxhZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53
Lm1vbnR2aWxsZUBnbWFpbC5jb20+IDxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208
bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPj4+IHdyb3RlOg0KPg0KPiAgICAgICAg
IEhlbGxvLiBBIGZldyBvZiB1cyBtZXQgaW5mb3JtYWxseSB0b2RheSB0byBkaXNjdXNzIHRoZQ0K
PiAgICAgICAgIHZ1bG5lcmFiaWxpdHkgc2NlbmFyaW8gaW4gc29tZSBtb3JlIGRldGFpbCB3aXRo
IHRoZSBnb2FsIG9mDQo+ICAgICAgICAgbWFpbnRhaW5pbmcgdGhlIG5hcnJvdyBmb2N1cyBvbiBh
IHZ1bG5lcmFiaWxpdHkgYXNzZXNzbWVudCBzbGljZQ0KPiAgICAgICAgIHRocm91Z2ggb3VyIG5v
dGlvbmFsIGVudmlyb25tZW50LiAgV2UgYXJlIHRlbmRpbmcgdG8gbG9vayBhdA0KPiAgICAgICAg
IG1ham9yIGNvbXBvbmVudHMgYXMgYmxhY2sgYm94ZXMgd2l0aCBpbnRlcmZhY2VzIGFuZCBkYXRh
IGZvcm1hdA0KPiAgICAgICAgIGV4cGVjdGF0aW9ucywgYW5kIHdlIGFyZSBub3QgbmVjZXNzYXJp
bHkgY29uY2VybmVkIHdpdGggaG93DQo+ICAgICAgICAgdGhvc2UgY29tcG9uZW50cyBkbyB0aGlu
Z3MgaW50ZXJuYWxseS9iZWhpbmQgdGhlIHNjZW5lcy4NCj4NCj4gICAgICAgICBUaGUgbWVldGlu
ZyB3YXMgcmVjb3JkZWQgKHlvdSBjYW4gZmluZCBpdCB3aXRoIHRvZGF5J3MgZGF0ZSBhdA0KPiAg
ICAgICAgIFsxXSkuICBUaGUgdG9waWMgb2YgZGlzY3Vzc2lvbiB3YXMgcHJpbWFyaWx5IGluIHRo
ZSAicGhhc2UgMSINCj4gICAgICAgICBhcmVhIG9mIHdoYXQgRGFubnkgc2VudCB0byB0aGUgbGlz
dCBub3QgdmVyeSBsb25nIGFnbyBbMl0sIGFuZA0KPiAgICAgICAgIHJlc3VsdGVkIGluIGEgKnN0
YXJ0aW5nIHBvaW50KiBkaWFncmFtIFszXS4NCj4NCj4gICAgICAgICBUaGUgZ3JvdXAgd2hvIG1l
dCB0b2RheSBhcmUgKHJvdWdobHkpIGFncmVlZCBvbiB0aGUgc2l4IG1haW4NCj4gICAgICAgICAi
Y29tcG9uZW50cyIgcmVwcmVzZW50ZWQgaW4gdGhhdCBkaWFncmFtLCBidXQgYWxzbyBzZWUgdGhh
dCB3ZQ0KPiAgICAgICAgIGhhdmUgc29tZSB3b3JrIGFoZWFkLiAgU3BlY2lmaWNhbGx5LCB3ZSBx
dWlja2x5IHJlY29nbml6ZWQgdGhhdA0KPiAgICAgICAgIHNvbWUgb2YgdGhlIGFzc3VtcHRpb25z
IHRoZSB2dWxuZXJhYmlsaXR5IGRyYWZ0IG1ha2VzIG1heSBiZQ0KPiAgICAgICAgIGFzc3VtcHRp
b25zIHdlIGNhbm5vdCBhZmZvcmQgdG8gbWFrZSBhbmQgbmVlZCB0byBpbmNsdWRlIGluIHRoZQ0K
PiAgICAgICAgIGV4cGxvcmF0aW9uLg0KPg0KPiAgICAgICAgIFdlIHRob3VnaHQgaXQgd291bGQg
YmUgYSBnb29kIGlkZWEgdG8gaGF2ZSBhbm90aGVyIGluZm9ybWFsDQo+ICAgICAgICAgZGlzY3Vz
c2lvbiBpbiBhIGNvdXBsZSBvZiB3ZWVrcyAoRmVicnVhcnkgMikgYXQgdGhlIHNhbWUgdGltZQ0K
PiAgICAgICAgICgxMGFtIEVhc3Rlcm4gLyAzcG0gVVRDKSwgdXNpbmcgdGhlIHNhbWUgV2ViRXgg
WzRdLiAgIEF0IHRoYXQNCj4gICAgICAgICB0aW1lIHdlIGludGVuZCB0byByb2xsIHRocm91Z2gg
dGhlIHZ1bG5lcmFiaWxpdHkgYXNzZXNzbWVudA0KPiAgICAgICAgIHNjZW5hcmlvIGFzc3VtcHRp
b25zIGluIGFuIGVmZm9ydCB0byBkZXRlcm1pbmUgd2hpY2ggb25lcyBjYW4gYmUNCj4gICAgICAg
ICBsZWZ0IGFzIGFzc3VtcHRpb25zIGFuZCB3aGljaCBvbmVzIGNhbm5vdC4gIFRoZW4gd2UnbGwg
dGFrZQ0KPiAgICAgICAgIGFub3RoZXIgbG9vayBhdCB0aGUgZGlhZ3JhbSBhbmQgd29yayBvbiBp
dHMgbmV4dCB2ZXJzaW9uLg0KPg0KPiAgICAgICAgIFN0YXkgdHVuZWQuDQo+DQo+ICAgICAgICAg
VGhhbmtzIHRvIERhbm55LCBTdGVwaGVuLCBhbmQgSmVyb21lIGZvciBqb2luaW5nIGFuZCBjb250
cmlidXRpbmchDQo+DQo+ICAgICAgICAgS2luZCByZWdhcmRzLA0KPg0KPiAgICAgICAgIEFkYW0N
Cj4NCj4NCj4gICAgICAgICBbMV0gaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4
V2Y5VW41RmRDYldHaERPSHBWUjB0TWQxRQ0KPiAgICAgICAgIFsyXSBodHRwczovL21haWxhcmNo
aXZlLmlldGYub3JnL2FyY2gvbXNnL3NhY20vX0xpS2x5dkF3c19PVkxGaEI1TlNVNThNWERNDQo+
ICAgICAgICAgWzNdIGh0dHBzOi8vZHJpdmUuZ29vZ2xlLmNvbS9vcGVuP2lkPTBCOFdmOVVuNUZk
Q2JNVTVwZFRSamVqSnROSGMNCj4gICAgICAgICBbNF0gaHR0cHM6Ly9pZXRmLndlYmV4LmNvbS9t
ZWV0L3NhY20NCj4NCj4NCj4NCj4gX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX18NCj4gc2FjbSBtYWlsaW5nIGxpc3QNCj4gc2FjbUBpZXRmLm9yZzxtYWlsdG86
c2FjbUBpZXRmLm9yZz4NCj4gaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9z
YWNtDQo+DQoNCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
DQpzYWNtIG1haWxpbmcgbGlzdA0Kc2FjbUBpZXRmLm9yZzxtYWlsdG86c2FjbUBpZXRmLm9yZz4N
Cmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vc2FjbQ0KDQo=

--_000_BN6PR09MB14580BE5DCFB0162BC69F1A7A54F0BN6PR09MB1458namp_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpWZXJkYW5hOw0KCXBhbm9zZS0xOjIgMTEg
NiA0IDMgNSA0IDQgMiA0O30NCi8qIFN0eWxlIERlZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwg
bGkuTXNvTm9ybWFsLCBkaXYuTXNvTm9ybWFsDQoJe21hcmdpbjowaW47DQoJbWFyZ2luLWJvdHRv
bTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6IlRpbWVzIE5ldyBS
b21hbiIsc2VyaWY7fQ0KYTpsaW5rLCBzcGFuLk1zb0h5cGVybGluaw0KCXttc28tc3R5bGUtcHJp
b3JpdHk6OTk7DQoJY29sb3I6Ymx1ZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCmE6
dmlzaXRlZCwgc3Bhbi5Nc29IeXBlcmxpbmtGb2xsb3dlZA0KCXttc28tc3R5bGUtcHJpb3JpdHk6
OTk7DQoJY29sb3I6cHVycGxlOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KcC5tc29u
b3JtYWwwLCBsaS5tc29ub3JtYWwwLCBkaXYubXNvbm9ybWFsMA0KCXttc28tc3R5bGUtbmFtZTpt
c29ub3JtYWw7DQoJbXNvLW1hcmdpbi10b3AtYWx0OmF1dG87DQoJbWFyZ2luLXJpZ2h0OjBpbjsN
Cgltc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0bzsNCgltYXJnaW4tbGVmdDowaW47DQoJZm9udC1z
aXplOjEyLjBwdDsNCglmb250LWZhbWlseToiVGltZXMgTmV3IFJvbWFuIixzZXJpZjt9DQpzcGFu
LmdtYWlsbXNnDQoJe21zby1zdHlsZS1uYW1lOmdtYWlsX21zZzt9DQpzcGFuLm05NDc5Mjk5NjUz
OTU4OTMyNzJob2VuemINCgl7bXNvLXN0eWxlLW5hbWU6bV85NDc5Mjk5NjUzOTU4OTMyNzJob2Vu
emI7fQ0Kc3Bhbi5FbWFpbFN0eWxlMjANCgl7bXNvLXN0eWxlLXR5cGU6cGVyc29uYWwtcmVwbHk7
DQoJZm9udC1mYW1pbHk6IkNhbGlicmkiLHNhbnMtc2VyaWY7DQoJY29sb3I6d2luZG93dGV4dDt9
DQouTXNvQ2hwRGVmYXVsdA0KCXttc28tc3R5bGUtdHlwZTpleHBvcnQtb25seTsNCglmb250LWZh
bWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjt9DQpAcGFnZSBXb3JkU2VjdGlvbjENCgl7c2l6ZTo4
LjVpbiAxMS4waW47DQoJbWFyZ2luOjEuMGluIDEuMGluIDEuMGluIDEuMGluO30NCmRpdi5Xb3Jk
U2VjdGlvbjENCgl7cGFnZTpXb3JkU2VjdGlvbjE7fQ0KLS0+PC9zdHlsZT48IS0tW2lmIGd0ZSBt
c28gOV0+PHhtbD4NCjxvOnNoYXBlZGVmYXVsdHMgdjpleHQ9ImVkaXQiIHNwaWRtYXg9IjEwMjYi
IC8+DQo8L3htbD48IVtlbmRpZl0tLT48IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBl
bGF5b3V0IHY6ZXh0PSJlZGl0Ij4NCjxvOmlkbWFwIHY6ZXh0PSJlZGl0IiBkYXRhPSIxIiAvPg0K
PC9vOnNoYXBlbGF5b3V0PjwveG1sPjwhW2VuZGlmXS0tPg0KPC9oZWFkPg0KPGJvZHkgbGFuZz0i
RU4tVVMiIGxpbms9ImJsdWUiIHZsaW5rPSJwdXJwbGUiPg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rp
b24xIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0
O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJpZiI+VGhhdCB3b3JrcyBm
b3IgbWUuPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4g
c3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90Oyxz
YW5zLXNlcmlmIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxp
YnJpJnF1b3Q7LHNhbnMtc2VyaWYiPlRoYW5rcyw8YnI+DQo8YnI+DQpEYW5ueTxvOnA+PC9vOnA+
PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4m
bmJzcDs8L286cD48L3NwYW4+PC9wPg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxl
ZnQ6c29saWQgYmx1ZSAxLjVwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDQuMHB0Ij4NCjxkaXY+DQo8
ZGl2IHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItdG9wOnNvbGlkICNFMUUxRTEgMS4wcHQ7cGFk
ZGluZzozLjBwdCAwaW4gMGluIDBpbiI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48Yj48c3BhbiBz
dHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNh
bnMtc2VyaWYiPkZyb206PC9zcGFuPjwvYj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtm
b250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPiBzYWNtIFttYWlsdG86
c2FjbS1ib3VuY2VzQGlldGYub3JnXQ0KPGI+T24gQmVoYWxmIE9mIDwvYj5BZGFtIE1vbnR2aWxs
ZTxicj4NCjxiPlNlbnQ6PC9iPiBUaHVyc2RheSwgRmVicnVhcnkgMDIsIDIwMTcgMTowMCBQTTxi
cj4NCjxiPlRvOjwvYj4gQmlsbCBNdW55YW4gJmx0O2JpbGwubXVueWFuLmlldGZAZ21haWwuY29t
Jmd0Ozxicj4NCjxiPkNjOjwvYj4gSGVuayBCaXJraG9seiAmbHQ7aGVuay5iaXJraG9sekBzaXQu
ZnJhdW5ob2Zlci5kZSZndDs7IHNhY21AaWV0Zi5vcmc8YnI+DQo8Yj5TdWJqZWN0OjwvYj4gUmU6
IFtzYWNtXSBOb3RlcyBvbiBWdWxuZXJhYmlsaXR5IFNjZW5hcmlvIFdvcmtpbmcgU2Vzc2lvbjxv
OnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5ZZXMh
IE5vdGluZyB0aGF0IGluZm9ybWF0aW9uIGlzIGNyaXRpY2FsLCBidXQgaWYgd2Ugc2V0IG91dCB0
byBwdXQgYWxsIG9mIHRoYXQgaW4gdGhlIGRpYWdyYW0sIHdlJ2xsIGxvc2UuJm5ic3A7IFdoYXQg
aWYgd2UgYWdyZWUgdG8gdGhlIHNlcXVlbmNlIGF0IHRoZSBoaWdoIGxldmVsLCB0aGVuIG51bWJl
ciB0aGUgc3RlcHMsIGFuZCB0aGVuIHdyaXRlIGFib3V0IHRob3NlIHN0ZXBzIGluIHRoZSB3aWtp
IGFmdGVyIHRhbGtpbmcNCiBhYm91dCB0aGVtIGhlcmUgYW5kIGluIGluZm9ybWFsIHNlc3Npb25z
IGZvciB0aGUgd2luPzxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+T24gVGh1LCBGZWIgMiwgMjAxNyBhdCAxMTo1NyBBTSBCaWxsIE11bnlhbiAmbHQ7PGEgaHJl
Zj0ibWFpbHRvOmJpbGwubXVueWFuLmlldGZAZ21haWwuY29tIj5iaWxsLm11bnlhbi5pZXRmQGdt
YWlsLmNvbTwvYT4mZ3Q7IHdyb3RlOjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8YmxvY2txdW90
ZSBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0NDQyAxLjBwdDtwYWRk
aW5nOjBpbiAwaW4gMGluIDYuMHB0O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdpbi1yaWdodDowaW4i
Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1m
YW1pbHk6JnF1b3Q7VmVyZGFuYSZxdW90OyxzYW5zLXNlcmlmIj5JcyBpdCB3b3J0aCBub3Rpbmcg
aW4gdGhlIGRpYWdyYW0gKGlmIG5vdCwgSSB0aGluayBpdCBuZWVkcyB0byBiZSBub3RlZCBzb21l
d2hlcmUgbm9uZXRoZWxlc3MpIHRoYXQgdGhlIHN0ZXBzIG9mICZxdW90O2dldCBlbmRwb2ludHMm
cXVvdDsgYW5kIHN1YnNlcXVlbnQgJnF1b3Q7ZXZhbHVhdGUmcXVvdDsgc2hvdWxkIGJlIG1ha2lu
ZyBzb21lIGRldGVybWluYXRpb24NCiBvZiB3aGV0aGVyIG9yIG5vdCB0byBjb2xsZWN0IGZvciBh
biBlbmRwb2ludD8mbmJzcDsgRm9yIGV4YW1wbGUsIGlmIGFuIGVuZHBvaW50IGhhcyBubyBhc3Nl
c3NtZW50IHJlc3VsdHMgb3IgdGhlIGFzc2Vzc21lbnQgcmVzdWx0cyBhcmUgY29uc2lkZXJlZCAm
cXVvdDtzdGFsZSZxdW90OywgdGhlbiB0aGUgY29sbGVjdGlvbiBzdGVwIHdvdWxkIHRha2UgcGxh
Y2UuJm5ic3A7IEkgdW5kZXJzdGFuZCB0aGF0IGNvdWxkIGJlIHRvbyBtdWNoIGRldGFpbCBmb3Ig
dGhlIHNjb3BlIG9mIHRoZQ0KIGRpYWdyYW0sIGJ1dCBJIGp1c3Qgd2FudGVkIHRvIG5vdGUgaXQg
c29tZXdoZXJlLjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1b3Q7
LHNhbnMtc2VyaWYiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTomcXVvdDtWZXJk
YW5hJnF1b3Q7LHNhbnMtc2VyaWYiPkNoZWVycywmbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3A+
DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1m
YW1pbHk6JnF1b3Q7VmVyZGFuYSZxdW90OyxzYW5zLXNlcmlmIj4tQmlsbCBNLjxvOnA+PC9vOnA+
PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0
eWxlPSJmb250LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1b3Q7LHNhbnMtc2VyaWYiPjxvOnA+Jm5i
c3A7PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1z
b05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+T24gVGh1LCBGZWIgMiwgMjAxNyBhdCAxMjo0NCBQTSwgQWRhbSBNb250dmlsbGUgPHNwYW4g
Y2xhc3M9ImdtYWlsbXNnIj4NCiZsdDs8YSBocmVmPSJtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBn
bWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTwvYT4m
Z3Q7PC9zcGFuPiB3cm90ZTo8bzpwPjwvbzpwPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3Jk
ZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAw
aW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFyZ2luLXJpZ2h0OjBpbiI+DQo8ZGl2Pg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+VGhhbmtzIGZvciB0aGUgZmVlZGJhY2shJm5ic3A7IEkndmUgYXR0
YWNoZWQgYSBtb2RpZmllZCB2ZXJzaW9uIG9mIHRoZSBkaWFncmFtIHRoYXQgY29sbGFwc2VzIHRo
ZSBlbmRwb2ludCBhbmQgYXNzZXNzbWVudCByZXN1bHQgcmVwb3NpdG9yaWVzIChieSBrZWVwaW5n
IHRoZSBlbmRwb2ludCByZXBvc2l0b3J5KS4mbmJzcDsgV2hlcmUgd291bGQgeW91IHByb3Bvc2Ug
d2UgZm9jdXMgb24gZW5oYW5jaW5nIHRoZSBkaWFncmFtPyZuYnNwOw0KIFJlbWVtYmVyIHRoYXQg
aXQncyBhIHNlcXVlbmNlIGRpYWdyYW0sIHdoaWNoIG1pZ2h0IGRvIHdlbGwgd2l0aCBzb21lIG1v
cmUgc3BlY2lmaWMgZGV0YWlscyBjYXB0dXJlZCBpbiB0ZXh0IG9yIGEgZGlmZmVyZW50IGZvcm0g
b2YgZGlhZ3JhbS48bzpwPjwvbzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48
bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PldoYXQgZG8gZm9sa3MgdGhpbmsgYWJvdXQgdXNpbmcgb25lIG9yIG1vcmUgT1ZBTCBkZWZpbml0
aW9ucyBhcyBhIHN0YXJ0aW5nIHBvaW50PzxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImNvbG9yOiM4ODg4ODgiPjxvOnA+Jm5i
c3A7PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxzcGFuIHN0eWxlPSJjb2xvcjojODg4ODg4Ij5BZGFtPG86cD48L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZu
YnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8
L286cD48L3A+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPk9uIFRodSwgRmVi
IDIsIDIwMTcgYXQgMTA6NTMgQU0gSGVuayBCaXJraG9seiAmbHQ7PGEgaHJlZj0ibWFpbHRvOmhl
bmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGUiIHRhcmdldD0iX2JsYW5rIj5oZW5rLmJpcmto
b2x6QHNpdC5mcmF1bmhvZmVyLmRlPC9hPiZndDsgd3JvdGU6PG86cD48L286cD48L3A+DQo8L2Rp
dj4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0ND
Q0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAwaW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFy
Z2luLXJpZ2h0OjBpbiI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj4jIyBBIEZldyBDb21tZW50czxi
cj4NCjxicj4NCiogSSBhZ3JlZSB0aGF0IHRoZSBkaWFncmFtIHByZXR0eSBtdWNoIGNhcHR1cmVz
IGEgJnF1b3Q7b25lIHRpbWUgc25hcHNob3QmcXVvdDsuPGJyPg0KKiBDb2xsYXBzaW5nIHRoZSBo
aWdobGlnaHRlZCBjb21wb25lbnRzIHNlZW1zIHRvIGJlIGEgZmVhc2libGUgaWRlYS48YnI+DQoq
IEkgYWdyZWUgdGhhdCB0aGUgZGlhZ3JhbSBjb3VsZCBiZSBpbXBsZW1lbnRlZCBnaXZlbiBhbiBh
cHByb3ByaWF0ZSBzZXQ8YnI+DQpvZiBpbml0aWFsIGRhdGEuPGJyPg0KKiBJIHN1cHBvc2UgdGhl
cmUgaXMgdGhlIHJpc2sgdGhhdCBvbmUgaGFzIHRvIHNjcmFwIGV2ZXJ5dGhpbmc8YnI+DQppbXBs
ZW1lbnRlZCB3aGVuIHdlIHN0YXJ0IHRyeWluZyB0byBtYWtlIGl0IGEgY29udGludW91cyBwcm9j
ZXNzLjxicj4NCiogSSdkIHJlY29tbWVuZCB0byBzdGFydCB3aXRoIGEgZ2VuZXJpYyBibG9jayBv
ZiBQb0MgY29kZSB0aGF0IHByb3ZpZGVzPGJyPg0KdGhlIGZ1bmN0aW9ucyBvZiBhIFNBQ00gY29t
cG9uZW50IHRvIGdldCBpbnB1dCBhbmQgY3JlYXRlIG91dHB1dCAobWF5YmU8YnI+DQp1c2luZyBk
YnVzLCBjaGFpbmVkIGV2ZW50LWxvb3BzLCBibG9ja2luZyB3YWl0cyBvbiBmaWZvcywgb3IgSVAg
b3Zlcjxicj4NCmxvb3BiYWNrPyBBIGJldHRlciBjb2RlciB0aGFuIG1lIHNob3VsZCBiYXNoIHRo
ZXNlIHN1Z2dlc3Rpb25zKS48YnI+DQo8YnI+DQojIyBPbmUsIFR3bywgb3IgVGhyZWUgVGFza3M8
YnI+DQo8YnI+DQoqIENyZWF0aW5nIGNvbXBvbmVudCBjb2RlIHRoYXQgY2FuIGNyZWF0ZSB0aGUg
KGRvd25zdHJlYW0/KSBmbG93IG9mPGJyPg0KaW5mb3JtYXRpb24gaXMgdXJnZW50IGFuZCBpbXBv
cnRhbnQsIEkgdGhpbmsuPGJyPg0KKiBFbmhhbmNpbmcgdGhlIGRpYWdyYW0gdG8gcmVwcmVzZW50
IHRoZSBjb250aW51b3VzIGN5Y2xlIHdpdGggYXQgbGVhc3Q8YnI+DQpvbmUgdHJpZ2dlciAoYXMg
aWxsdXN0cmF0ZWQgYnkgQmlsbDsgbmV3IHNvZnR3YXJlLCBuZXcgVkRJLCBuZXc8YnI+DQplbmRw
b2ludHMsIHN0YWxlIHJlc3VsdHMsIGV0Yy4pIGlzIGltcG9ydGFudCwgYnV0IG5vdCBhcyB1cmdl
bnQuIEl0PGJyPg0KbWlnaHQgc2F2ZSB0aW1lIHRob3VnaCBieSByZWR1Y2luZyB0aGUgYWZvcmUg
bWVudGlvbmVkIHJpc2sgdG8gc2hvb3Q8YnI+DQp5b3VyIHNlbGYgaW4gdGhlIGZvb3QgYnkgY3Jl
YXRpbmcgYSB0b28gc3BlY2lmaWMgcHJvb2Ygb2YgY29uY2VwdCBvZiB0aGU8YnI+DQpvbmUgdGlt
ZSBzbmFwc2hvdCBhcHByb2FjaCwgSSB0aGluay48YnI+DQoqIFNlbGVjdGluZyBhIHNldCBvZiBp
bml0aWFsIGRhdGEgZGVyaXZlZCBmcm9tIE9WQUwgdG8gYmUgdXNlZCBpbiB0aGU8YnI+DQpvbmUg
c2hvdCBzbmFwc2hvdCBzZWVtcyB0byBiZSBhIGZlYXNpYmxlIGFwcHJvYWNoIHRvIG1lLCBidXQg
SSBhbSBub3Q8YnI+DQpzdXJlIGhvdyB0aGUgZ3JvdXAgdGhpbmtzIGFib3V0IHRoYXQuPGJyPg0K
PGJyPg0KRG9lcyB0aGF0IGFzc2Vzc21lbnQgcmVwcmVzZW50IHRoZSBnZW5lcmFsIG9waW5pb24s
IG9yIGlzIHRoYXQganVzdCBtaW5lPzxicj4NCjxicj4NClZpZWxlIEdyw7zDn2UsPGJyPg0KPGJy
Pg0KSGVuazxicj4NCjxicj4NCk9uIDAyLzAyLzIwMTcgMDU6MjggUE0sIEFkYW0gTW9udHZpbGxl
IHdyb3RlOjxicj4NCiZndDsgSGkgRXZlcnlvbmUuJm5ic3A7IEEgZmV3IG9mIHVzIHdlcmUgYWJs
ZSB0byBtYWtlIHRoZSB2dWxuZXJhYmlsaXR5IHNjZW5hcmlvPGJyPg0KJmd0OyBjYWxsIHRvZGF5
IGFuZCBJIHRoaW5rIHdlIGhhZCBhIGdvb2QsIHRob3VnaCBhdCB0aW1lcyBzcGlyaXRlZCw8YnI+
DQomZ3Q7IGRpc2N1c3Npb24uJm5ic3A7IFdlIGRpZCByZWNvcmQgdGhlIG1lZXRpbmcsIHdoaWNo
IGlzIGF2YWlsYWJsZSBhdCBbMV0uJm5ic3A7IFdlPGJyPg0KJmd0OyBkaXNjdXNzZWQgdGhlIGF0
dGFjaGVkIChhbm5vdGF0ZWQgd2l0aCBzb21lIG1lZXRpbmcgbm90ZXMpIFVNTC1pc2g8YnI+DQom
Z3Q7IHNlcXVlbmNlIGRpYWdyYW0uJm5ic3A7IEkgaGFkIGNyZWF0ZWQgdGhhdCBkaWFncmFtIHRv
IHN0YXJ0IGEgY29udmVyc2F0aW9uPGJyPg0KJmd0OyAobWlzc2lvbiBhY2NvbXBsaXNoZWQgb24g
dGhhdCBmcm9udCBJIHRoaW5rKSAtLSBhIGNvbnZlcnNhdGlvbiB0aGF0PGJyPg0KJmd0OyB3b3Vs
ZCBsZWFkIHVzIHRvd2FyZCBpZGVudGlmeWluZyB0aGUgZGlzY3JldGUgY29tcG9uZW50cywgaW50
ZXJmYWNlcyw8YnI+DQomZ3Q7IGFuZCBpbmZvcm1hdGlvbiByZXF1aXJlZCB0byBiZSBzZW50IG92
ZXIgdGhvc2UgaW50ZXJmYWNlcy4mbmJzcDsgVGhlIFVNTC1pc2g8YnI+DQomZ3Q7IGRpYWdyYW0g
cmVwcmVzZW50cyBhICpzaW5nbGUqIGZsb3cgdGhyb3VnaCB0aGUgc3lzdGVtIC0tIGEgJnF1b3Q7
b25lLXRpbWUmcXVvdDs8YnI+DQomZ3Q7IGZsb3cgdGhyb3VnaCB0aGUgc3lzdGVtLiZuYnNwOyBJ
dCBpZ25vcmVzLCBmb3IgdGhlIHRpbWUgYmVpbmcsIHRoZSBjb250aW51b3VzPGJyPg0KJmd0OyBh
c3BlY3Qgb2Ygb3VyIGNoYXJ0ZXIgaW4gZmF2b3Igb2YgZ2V0dGluZyBzdGFydGVkIHdpdGggdGhl
IGJhc2ljcy4mbmJzcDsgT25jZTxicj4NCiZndDsgd2UgaGF2ZSBhIGdvb2QgdW5kZXJzdGFuZGlu
ZyBvZiB0aGUgYmFzaWNzIC0tIHRoZSBjb21wb25lbnRzLDxicj4NCiZndDsgaW50ZXJmYWNlcywg
YW5kIGluZm9ybWF0aW9uIHJlcXVpcmVkIC0tIHdlIGNhbiBzdGFydCBsb29rIGF0IGE8YnI+DQom
Z3Q7IGNvbnRpbnVvdXMgbW9uaXRvcmluZyBzZXF1ZW5jZSAod2hpY2ggY291bGQgYmUgcmVwcmVz
ZW50ZWQgYXMgYSBkaXN0aW5jdDxicj4NCiZndDsgZGlhZ3JhbSkgdG8gZGV0ZXJtaW5lIHdoYXQg
bW9yZSB3ZSBuZWVkLiZuYnNwOyBUaGVuLCBJIHRoaW5rLCB3ZSBjYW4gc3RhcnQ8YnI+DQomZ3Q7
IGRyYWZ0aW5nIHNvbHV0aW9ucy48YnI+DQomZ3Q7PGJyPg0KJmd0OyBPbmUgb2YgdGhlIGZpcnN0
IGlzc3VlcyBpcyB0aGF0IHdlIG5lZWQgdG8gZmlndXJlIG91dCBpZiB0aGUgY29tcG9uZW50czxi
cj4NCiZndDsgaW4gdGhlIGJhc2UgZmxvdyBhcmUgYWNjdXJhdGUuJm5ic3A7IFRoZSBtYWluIHN1
Z2dlc3Rpb24gd2UndmUgdG9zc2VkIGFyb3VuZDxicj4NCiZndDsgc28gZmFyIGlzIHRvIGNvbWJp
bmUgdGhlIEVuZHBvaW50IFJlcG9zaXRvcnkgd2l0aCB0aGUgQXNzZXNzbWVudCBSZXN1bHQ8YnI+
DQomZ3Q7IFJlcG9zaXRvcnkuPGJyPg0KJmd0Ozxicj4NCiZndDsgV2UgdGFsa2VkIGJyaWVmbHkg
YWJvdXQgd2hhdCBpbnRlcmZhY2Ugd2UgY291bGQgdXNlIGZvciB0aGUgVkREPGJyPg0KJmd0OyBS
ZXBvc2l0b3J5LCBhbmQgbmF0dXJhbGx5IFJPTElFIGNhbWUgdXAgYXMgYW4gb3B0aW9uLjxicj4N
CiZndDs8YnI+DQomZ3Q7IFdlIHRhbGtlZCBhIGxpdHRsZSBiaXQgYWJvdXQgdGhlIGZpcnN0ICZx
dW90O2dldCBlbmRwb2ludHMmcXVvdDsgb3BlcmF0aW9uIGJldHdlZW48YnI+DQomZ3Q7IHRoZSBW
dWxuZXJhYmlsaXR5IEFzc2Vzc29yIGFuZCB0aGUgRW5kcG9pbnQgUmVwb3NpdG9yeSAtLSBzcGVj
aWZpY2FsbHk8YnI+DQomZ3Q7IGFib3V0IHdoZXRoZXIgd2Ugc2hvdWxkIHJlcHJlc2VudCBvbiB0
aGlzIHNlcXVlbmNlIGRpYWdyYW0gdGhhdDxicj4NCiZndDsgaW5mb3JtYXRpb24gc3VwcG9ydGlu
ZyBhIGp1ZGdlbWVudCBvZiAmcXVvdDtzdGFsZSZxdW90OyB3b3VsZCBiZSBuZWVkZWQuPGJyPg0K
Jmd0Ozxicj4NCiZndDsgV2UgbGVmdCBvcGVuIHRoZSB0aW1lIHdoZW4gd2Ugd291bGQgbmV4dCBt
ZWV0LCBmYXZvcmluZyB0byB3b3JrIHRoYXQgb3V0PGJyPg0KJmd0OyBvbi1saXN0LiZuYnNwOyBO
ZXh0IHdlZWsgaXMgVENHLCBzbyB0aGF0IG1heSBiZSBkaWZmaWN1bHQ7IHRoZSBmb2xsb3dpbmcg
d2Vlazxicj4NCiZndDsgaXMgUlNBLCBzbyB0aGF0IG1heSBiZSBkaWZmaWN1bHQuPGJyPg0KJmd0
Ozxicj4NCiZndDsgRm9yIHRob3NlIHdobyB3ZXJlIGluIGF0dGVuZGFuY2UgdG9kYXksIHBsZWFz
ZSBhZGQgdG8gdGhpcyBub3RlIHdpdGg8YnI+DQomZ3Q7IHlvdXIgY29tbWVudHMvY29ycmVjdGlv
bnMuPGJyPg0KJmd0Ozxicj4NCiZndDsgS2luZCByZWdhcmRzLDxicj4NCiZndDs8YnI+DQomZ3Q7
IEFkYW08YnI+DQomZ3Q7PGJyPg0KJmd0OyBbMV0gPGEgaHJlZj0iaHR0cHM6Ly9kcml2ZS5nb29n
bGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERPSHBWUjB0TWQxRSIgdGFyZ2V0PSJfYmxh
bmsiPg0KaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERP
SHBWUjB0TWQxRTwvYT48YnI+DQomZ3Q7PGJyPg0KJmd0OyBPbiBNb24sIEphbiAzMCwgMjAxNyBh
dCAxMToyMSBBTSBBZGFtIE1vbnR2aWxsZTxicj4NCiZndDsgJmx0OzxhIGhyZWY9Im1haWx0bzph
ZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmls
bGVAZ21haWwuY29tPC9hPiAmbHQ7bWFpbHRvOjxhIGhyZWY9Im1haWx0bzphZGFtLncubW9udHZp
bGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21haWwuY29t
PC9hPiZndDsmZ3Q7IHdyb3RlOjxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJz
cDtIaSBldmVyeW9uZS4mbmJzcDsgSnVzdCBhIGZyaWVuZGx5IHJlbWluZGVyIHRoYXQgd2UgYXJl
IHBsYW5uaW5nIHRvIG1lZXQ8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDthZ2FpbiB0aGlz
IFRodXJzZGF5IGF0IHRoZSBzYW1lIHRpbWUgKDIvMiBAIDEwYW0gRWFzdGVybi8zcG0gVVRDKTxi
cj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO3VzaW5nIFNBQ00ncyBtZWV0aW5nIHJvb20gYXQg
PGEgaHJlZj0iaHR0cHM6Ly9pZXRmLndlYmV4LmNvbS9tZWV0L3NhY20iIHRhcmdldD0iX2JsYW5r
Ij4NCmh0dHBzOi8vaWV0Zi53ZWJleC5jb20vbWVldC9zYWNtPC9hPi48YnI+DQomZ3Q7PGJyPg0K
Jmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7S2luZCByZWdhcmRzLDxicj4NCiZndDs8YnI+DQomZ3Q7
Jm5ic3A7ICZuYnNwOyAmbmJzcDtBZGFtPGJyPg0KJmd0Ozxicj4NCiZndDs8YnI+DQomZ3Q7Jm5i
c3A7ICZuYnNwOyAmbmJzcDtPbiBUaHUsIEphbiAxOSwgMjAxNyBhdCAxMTozNSBBTSBBZGFtIE1v
bnR2aWxsZTxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyZsdDs8YSBocmVmPSJtYWlsdG86
YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9udHZp
bGxlQGdtYWlsLmNvbTwvYT4gJmx0O21haWx0bzo8YSBocmVmPSJtYWlsdG86YWRhbS53Lm1vbnR2
aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9udHZpbGxlQGdtYWlsLmNv
bTwvYT4mZ3Q7Jmd0OyB3cm90ZTo8YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDtIZWxsby4gQSBmZXcgb2YgdXMgbWV0IGluZm9ybWFsbHkgdG9kYXkg
dG8gZGlzY3VzcyB0aGU8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNw
O3Z1bG5lcmFiaWxpdHkgc2NlbmFyaW8gaW4gc29tZSBtb3JlIGRldGFpbCB3aXRoIHRoZSBnb2Fs
IG9mPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDttYWludGFpbmlu
ZyB0aGUgbmFycm93IGZvY3VzIG9uIGEgdnVsbmVyYWJpbGl0eSBhc3Nlc3NtZW50IHNsaWNlPGJy
Pg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDt0aHJvdWdoIG91ciBub3Rp
b25hbCBlbnZpcm9ubWVudC4mbmJzcDsgV2UgYXJlIHRlbmRpbmcgdG8gbG9vayBhdDxicj4NCiZn
dDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7bWFqb3IgY29tcG9uZW50cyBhcyBi
bGFjayBib3hlcyB3aXRoIGludGVyZmFjZXMgYW5kIGRhdGEgZm9ybWF0PGJyPg0KJmd0OyZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtleHBlY3RhdGlvbnMsIGFuZCB3ZSBhcmUgbm90
IG5lY2Vzc2FyaWx5IGNvbmNlcm5lZCB3aXRoIGhvdzxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZu
YnNwOyAmbmJzcDsgJm5ic3A7dGhvc2UgY29tcG9uZW50cyBkbyB0aGluZ3MgaW50ZXJuYWxseS9i
ZWhpbmQgdGhlIHNjZW5lcy48YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDtUaGUgbWVldGluZyB3YXMgcmVjb3JkZWQgKHlvdSBjYW4gZmluZCBpdCB3
aXRoIHRvZGF5J3MgZGF0ZSBhdDxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsg
Jm5ic3A7WzFdKS4mbmJzcDsgVGhlIHRvcGljIG9mIGRpc2N1c3Npb24gd2FzIHByaW1hcmlseSBp
biB0aGUgJnF1b3Q7cGhhc2UgMSZxdW90Ozxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7YXJlYSBvZiB3aGF0IERhbm55IHNlbnQgdG8gdGhlIGxpc3Qgbm90IHZlcnkg
bG9uZyBhZ28gWzJdLCBhbmQ8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZu
YnNwO3Jlc3VsdGVkIGluIGEgKnN0YXJ0aW5nIHBvaW50KiBkaWFncmFtIFszXS48YnI+DQomZ3Q7
PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtUaGUgZ3JvdXAgd2hv
IG1ldCB0b2RheSBhcmUgKHJvdWdobHkpIGFncmVlZCBvbiB0aGUgc2l4IG1haW48YnI+DQomZ3Q7
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyZxdW90O2NvbXBvbmVudHMmcXVvdDsg
cmVwcmVzZW50ZWQgaW4gdGhhdCBkaWFncmFtLCBidXQgYWxzbyBzZWUgdGhhdCB3ZTxicj4NCiZn
dDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7aGF2ZSBzb21lIHdvcmsgYWhlYWQu
Jm5ic3A7IFNwZWNpZmljYWxseSwgd2UgcXVpY2tseSByZWNvZ25pemVkIHRoYXQ8YnI+DQomZ3Q7
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3NvbWUgb2YgdGhlIGFzc3VtcHRpb25z
IHRoZSB2dWxuZXJhYmlsaXR5IGRyYWZ0IG1ha2VzIG1heSBiZTxicj4NCiZndDsmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7YXNzdW1wdGlvbnMgd2UgY2Fubm90IGFmZm9yZCB0byBt
YWtlIGFuZCBuZWVkIHRvIGluY2x1ZGUgaW4gdGhlPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDtleHBsb3JhdGlvbi48YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtXZSB0aG91Z2h0IGl0IHdvdWxkIGJlIGEgZ29vZCBp
ZGVhIHRvIGhhdmUgYW5vdGhlciBpbmZvcm1hbDxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7ZGlzY3Vzc2lvbiBpbiBhIGNvdXBsZSBvZiB3ZWVrcyAoRmVicnVhcnkg
MikgYXQgdGhlIHNhbWUgdGltZTxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsg
Jm5ic3A7KDEwYW0gRWFzdGVybiAvIDNwbSBVVEMpLCB1c2luZyB0aGUgc2FtZSBXZWJFeCBbNF0u
Jm5ic3A7ICZuYnNwO0F0IHRoYXQ8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwO3RpbWUgd2UgaW50ZW5kIHRvIHJvbGwgdGhyb3VnaCB0aGUgdnVsbmVyYWJpbGl0eSBh
c3Nlc3NtZW50PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtzY2Vu
YXJpbyBhc3N1bXB0aW9ucyBpbiBhbiBlZmZvcnQgdG8gZGV0ZXJtaW5lIHdoaWNoIG9uZXMgY2Fu
IGJlPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtsZWZ0IGFzIGFz
c3VtcHRpb25zIGFuZCB3aGljaCBvbmVzIGNhbm5vdC4mbmJzcDsgVGhlbiB3ZSdsbCB0YWtlPGJy
Pg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDthbm90aGVyIGxvb2sgYXQg
dGhlIGRpYWdyYW0gYW5kIHdvcmsgb24gaXRzIG5leHQgdmVyc2lvbi48YnI+DQomZ3Q7PGJyPg0K
Jmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtTdGF5IHR1bmVkLjxicj4NCiZn
dDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1RoYW5rcyB0byBE
YW5ueSwgU3RlcGhlbiwgYW5kIEplcm9tZSBmb3Igam9pbmluZyBhbmQgY29udHJpYnV0aW5nITxi
cj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0tpbmQg
cmVnYXJkcyw8YnI+DQomZ3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDtBZGFtPGJyPg0KJmd0Ozxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7ICZuYnNwO1sxXSA8YSBocmVmPSJodHRwczovL2RyaXZlLmdvb2dsZS5jb20vb3Bl
bj9pZD0wQjhXZjlVbjVGZENiV0doRE9IcFZSMHRNZDFFIiB0YXJnZXQ9Il9ibGFuayI+DQpodHRw
czovL2RyaXZlLmdvb2dsZS5jb20vb3Blbj9pZD0wQjhXZjlVbjVGZENiV0doRE9IcFZSMHRNZDFF
PC9hPjxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7WzJdIDxhIGhy
ZWY9Imh0dHBzOi8vbWFpbGFyY2hpdmUuaWV0Zi5vcmcvYXJjaC9tc2cvc2FjbS9fTGlLbHl2QXdz
X09WTEZoQjVOU1U1OE1YRE0iIHRhcmdldD0iX2JsYW5rIj4NCmh0dHBzOi8vbWFpbGFyY2hpdmUu
aWV0Zi5vcmcvYXJjaC9tc2cvc2FjbS9fTGlLbHl2QXdzX09WTEZoQjVOU1U1OE1YRE08L2E+PGJy
Pg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtbM10gPGEgaHJlZj0iaHR0
cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYk1VNXBkVFJqZWpKdE5I
YyIgdGFyZ2V0PSJfYmxhbmsiPg0KaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4
V2Y5VW41RmRDYk1VNXBkVFJqZWpKdE5IYzwvYT48YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7ICZuYnNwO1s0XSA8YSBocmVmPSJodHRwczovL2lldGYud2ViZXguY29tL21lZXQv
c2FjbSIgdGFyZ2V0PSJfYmxhbmsiPmh0dHBzOi8vaWV0Zi53ZWJleC5jb20vbWVldC9zYWNtPC9h
Pjxicj4NCiZndDs8YnI+DQomZ3Q7PGJyPg0KJmd0Ozxicj4NCiZndDsgX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX188YnI+DQomZ3Q7IHNhY20gbWFpbGluZyBs
aXN0PGJyPg0KJmd0OyA8YSBocmVmPSJtYWlsdG86c2FjbUBpZXRmLm9yZyIgdGFyZ2V0PSJfYmxh
bmsiPnNhY21AaWV0Zi5vcmc8L2E+PGJyPg0KJmd0OyA8YSBocmVmPSJodHRwczovL3d3dy5pZXRm
Lm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY20iIHRhcmdldD0iX2JsYW5rIj5odHRwczovL3d3dy5p
ZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY208L2E+PGJyPg0KJmd0OzxvOnA+PC9vOnA+PC9w
Pg0KPC9ibG9ja3F1b3RlPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxicj4NCl9fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPGJyPg0Kc2FjbSBtYWlsaW5n
IGxpc3Q8YnI+DQo8YSBocmVmPSJtYWlsdG86c2FjbUBpZXRmLm9yZyIgdGFyZ2V0PSJfYmxhbmsi
PnNhY21AaWV0Zi5vcmc8L2E+PGJyPg0KPGEgaHJlZj0iaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFp
bG1hbi9saXN0aW5mby9zYWNtIiB0YXJnZXQ9Il9ibGFuayI+aHR0cHM6Ly93d3cuaWV0Zi5vcmcv
bWFpbG1hbi9saXN0aW5mby9zYWNtPC9hPjxvOnA+PC9vOnA+PC9wPg0KPC9ibG9ja3F1b3RlPg0K
PC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2
Pg0KPC9ibG9ja3F1b3RlPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9ib2R5Pg0KPC9odG1s
Pg0K

--_000_BN6PR09MB14580BE5DCFB0162BC69F1A7A54F0BN6PR09MB1458namp_--


From nobody Fri Feb  3 09:52:49 2017
Return-Path: <dhaynes@mitre.org>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3B84D1294B2 for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 09:52:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.397
X-Spam-Level: 
X-Spam-Status: No, score=-7.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-3.199, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=mitre.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qz3pkP0aivTF for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 09:52:44 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (smtpvmsrv1.mitre.org [192.52.194.136]) by ietfa.amsl.com (Postfix) with ESMTP id A419F12948B for <sacm@ietf.org>; Fri,  3 Feb 2017 09:52:44 -0800 (PST)
Received: from smtpvmsrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id 5AAAFEBDCE2; Fri,  3 Feb 2017 12:52:44 -0500 (EST)
Received: from imshyb01.MITRE.ORG (imshyb01.mitre.org [129.83.29.2]) by smtpvmsrv1.mitre.org (Postfix) with ESMTP id 4314CEBDCF7; Fri,  3 Feb 2017 12:52:44 -0500 (EST)
Received: from imshyb01.MITRE.ORG (129.83.29.2) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Fri, 3 Feb 2017 12:52:43 -0500
Received: from gcc01-CY1-obe.outbound.protection.outlook.com (10.140.19.249) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1263.5 via Frontend Transport; Fri, 3 Feb 2017 12:52:43 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mitre.onmicrosoft.com;  s=selector1-mitre-org; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=sbYm2CMg9YS7RoPUYUdvi1ox+6/ZF7m3V5gw9ZFQ63o=; b=dF7xy8B6SDwL6XoDNeE71+ndhstJ149lVL8IpVhtmQFl6B7wm8hJkhql0QLASe+lswNl1bjYrnFX5+8czoQnfSruNHGEj/harxfQDApSYy1DMQLpNh5RpQgm1dzVO578XfEz8ImFSophcdgJHv42qzcwhr0ZisZNPHogc8xO7hI=
Received: from BN6PR09MB1458.namprd09.prod.outlook.com (10.173.202.22) by BN6PR09MB1457.namprd09.prod.outlook.com (10.173.202.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.888.16; Fri, 3 Feb 2017 17:52:42 +0000
Received: from BN6PR09MB1458.namprd09.prod.outlook.com ([10.173.202.22]) by BN6PR09MB1458.namprd09.prod.outlook.com ([10.173.202.22]) with mapi id 15.01.0888.021; Fri, 3 Feb 2017 17:52:42 +0000
From: "Haynes, Dan" <dhaynes@mitre.org>
To: Adam Montville <adam.w.montville@gmail.com>, "Waltermire, David A. (Fed)" <david.waltermire@nist.gov>, Bill Munyan <bill.munyan.ietf@gmail.com>
Thread-Topic: [sacm] Notes on Vulnerability Scenario Working Session
Thread-Index: AQHScnqFraRrjs8/rEyZzQVQK8LSq6FRVaqAgASoDICAAAcggIAADkoAgAADawCAAApcAIAACTEAgAF69AA=
Date: Fri, 3 Feb 2017 17:52:41 +0000
Message-ID: <BN6PR09MB14586B8180578BD1857D406EA54F0@BN6PR09MB1458.namprd09.prod.outlook.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <a3b37b4f-3e49-492c-393b-94b7d6945e00@sit.fraunhofer.de> <CACknUNWUQUj+9aeQtxuStN5ywPj71rD=JXktnZ8m4SBmP4WeQA@mail.gmail.com> <CAKUOEQxYrgbwMYp=avZitYDF_gu8dhFwMy_T4Uu3Qpub5p+z3Q@mail.gmail.com> <MWHPR09MB144086C8D167D5BEB1BC5258F04C0@MWHPR09MB1440.namprd09.prod.outlook.com> <CACknUNW1Kb4Eya-y4cd3wKTwUdOhyAFkwveQwUHjeLmMUQc8aw@mail.gmail.com>
In-Reply-To: <CACknUNW1Kb4Eya-y4cd3wKTwUdOhyAFkwveQwUHjeLmMUQc8aw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=dhaynes@mitre.org; 
x-originating-ip: [192.160.51.87]
x-ms-office365-filtering-correlation-id: 6941c0f6-37e0-4dcf-da11-08d44c5d739e
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(48565401081); SRVR:BN6PR09MB1457; 
x-microsoft-exchange-diagnostics: 1; BN6PR09MB1457; 7:DN1MjwDMVe8/YsTl3HH8EkFk0W/msMQkFpqPFc/XWN+iCq6pzqsy/qTyyDAsH7aPLgyMPkKb4/WKMON16HuM9kBrG8cWn8uN4WGOzYTvISpUTMMgEPIMn087JS3vRxvMpUcneWB3NKy5bXrz6v6nTCDhXBOcEzb8Z951flq40BgHMguMA6BJDr5OD1zoz84gS1GSmirq2C12Vqu7YA0FQPLOiQ19athnXVT/oTf+41U0Dru9Kg66VwZ4zoYEUAoW+ujDLCbNBieZl0dWsNTCGSSv4AJ9c8rWHdIdIKnVAPIkgdbiYjHYwp7wdUWOE3Tar3l+wPnokJhfEZm5Tu05bjhwq+vHmY2de+LjyzAdMUvAX40iD1mscL5YjuW54N7Kp+/KupfzWvvS3Jf1pB1oR47kABGeUFyz3qbFmnnu+ZLR8i4AAOQrddI16pOxr4oZVBixtBAm3H9ATnrM2fpAuEzCsd+hIhVPOSKE7/qlyKXXF/o1fZ0WmtgHMDfy0QfLaXzc2R5bww4gMp+dTGbyvw==
x-microsoft-antispam-prvs: <BN6PR09MB145734AE6A8086721B2FCA1BA54F0@BN6PR09MB1457.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(65766998875637)(72170088055959)(94707916325470)(211936372134217)(21748063052155)(145926492361056);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6055026)(6041248)(20161123558025)(20161123560025)(20161123555025)(20161123562025)(20161123564025)(6072148); SRVR:BN6PR09MB1457; BCL:0; PCL:0; RULEID:; SRVR:BN6PR09MB1457; 
x-forefront-prvs: 02070414A1
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(7916002)(39450400003)(39410400002)(39850400002)(39840400002)(46034005)(51694002)(199003)(51914003)(24454002)(377454003)(189002)(53754006)(3280700002)(6306002)(106116001)(101416001)(33656002)(25786008)(68736007)(7736002)(2906002)(106356001)(54896002)(8656002)(6506006)(9686003)(54356999)(76176999)(50986999)(4326007)(99286003)(54906002)(236005)(93886004)(122556002)(606005)(77096006)(5001770100001)(97736004)(105586002)(66066001)(31430400001)(55016002)(6436002)(102836003)(81156014)(92566002)(53936002)(3846002)(53546003)(6246003)(6116002)(2950100002)(790700001)(8936002)(5660300001)(81166006)(8676002)(575784001)(19609705001)(39060400001)(86362001)(189998001)(7906003)(7696004)(38730400001)(5890100001)(3660700001)(14971765001)(2900100001)(74316002)(229853002); DIR:OUT; SFP:1101; SCL:1; SRVR:BN6PR09MB1457; H:BN6PR09MB1458.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: mitre.org does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_BN6PR09MB14586B8180578BD1857D406EA54F0BN6PR09MB1458namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Feb 2017 17:52:41.9820 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c620dc48-1d50-4952-8b39-df4d54d74d82
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN6PR09MB1457
X-OriginatorOrg: mitre.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/eftNqdCx57Lt0HNTKfGCiJxI1qk>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Notes on Vulnerability Scenario Working Session
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 17:52:47 -0000

--_000_BN6PR09MB14586B8180578BD1857D406EA54F0BN6PR09MB1458namp_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SSB3aWxsIHRyeSBzb21lIG1vcmUgY29tbWVudHMgaW5saW5lIDspLg0KDQpUaGFua3MsDQoNCkRh
bm55DQoNCkZyb206IHNhY20gW21haWx0bzpzYWNtLWJvdW5jZXNAaWV0Zi5vcmddIE9uIEJlaGFs
ZiBPZiBBZGFtIE1vbnR2aWxsZQ0KU2VudDogVGh1cnNkYXksIEZlYnJ1YXJ5IDAyLCAyMDE3IDI6
MDcgUE0NClRvOiBXYWx0ZXJtaXJlLCBEYXZpZCBBLiAoRmVkKSA8ZGF2aWQud2FsdGVybWlyZUBu
aXN0Lmdvdj47IEJpbGwgTXVueWFuIDxiaWxsLm11bnlhbi5pZXRmQGdtYWlsLmNvbT4NCkNjOiBI
ZW5rIEJpcmtob2x6IDxoZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPjsgc2FjbUBpZXRm
Lm9yZw0KU3ViamVjdDogUmU6IFtzYWNtXSBOb3RlcyBvbiBWdWxuZXJhYmlsaXR5IFNjZW5hcmlv
IFdvcmtpbmcgU2Vzc2lvbg0KDQpXaWxsIHRyeSBpbmxpbmUuLi4NCk9uIFRodSwgRmViIDIsIDIw
MTcgYXQgMTI6MzQgUE0gV2FsdGVybWlyZSwgRGF2aWQgQS4gKEZlZCkgPGRhdmlkLndhbHRlcm1p
cmVAbmlzdC5nb3Y8bWFpbHRvOmRhdmlkLndhbHRlcm1pcmVAbmlzdC5nb3Y+PiB3cm90ZToNCklz
IHRoZSBvcGVyYXRpb24g4oCcZ2V0IGVuZHBvaW50c+KAnSBhIHNpbmdsZSBvcGVyYXRpb24gb3Ig
aXMgaXQgbXVsdGlwbGUgb3BlcmF0aW9ucyDigJxnZXQgZW5kcG9pbnQgY2hhcmFjdGVyaXN0aWNz
4oCdIGFuZCDigJxnZXQgcHJldmlvdXNseSBjb2xsZWN0ZWQgZGF0YeKAnSwgb3IgZXZlbiDigJxx
dWVyeSBpZiB0aGVyZSBpcyBwcmV2aW91c2x5IGNvbGxlY3RlZCBkYXRhIHRoYXQgbWF0Y2hlcyBY
IGluIHRpbWVmcmFtZSBZP+KAnSBJdCB3b3VsZCBiZSBoZWxwZnVsIHRvIGJlIG1vcmUgc3BlY2lm
aWMgaGVyZSBzaW5jZSB0aGUgaW5mb3JtYXRpb24gZXhjaGFuZ2VzIG1heSBkaWZmZXIuDQoNCkRv
bid0IGtub3cgeWV0IC0gdGhpcyBpcyBleGFjdGx5IHRoZSBzb3J0IG9mIGNvbnZlcnNhdGlvbiB3
ZSBzaG91bGQgYmUgaGF2aW5nISBXaGF0IGlmIHdlIG51bWJlcmVkIHRoZW0gYXMgaXMsIHRoZW4g
ZGlzY3VzcyBlYWNoIGluIHR1cm4sIGlmIGZvciBubyBvdGhlciByZWFzb24gdGhhbiB0cmFja2lu
ZyB3aGF0IHdlIG5lZWQgdG8gZG8gYW5kIHdoYXQgd2UndmUgZG9uZT8NCg0KW2Rhbm55XSBpcyBp
dCBwb3NzaWJsZSB0aGF0IGl0IGRlcGVuZHMgb24gaG93IHRoZSBkYXRhIGlzIHN0b3JlZC9vcmdh
bml6ZWQgaW4gdGhlIOKAnGVuZHBvaW50IHJlcG9zaXRvcnnigJ0/IEZvciBleGFtcGxlLCBvbmUg
dmVuZG9yIG1pZ2h0IG1ha2UgZW5kcG9pbnRzIGl0cyBvd24gdGFibGUgd2hlcmVhcyBhbm90aGVy
IHZlbmRvciBtaWdodCBoYXZlIHRoZSBkYXRhIHNwcmVhZCBhY3Jvc3MgbXVsdGlwbGUgdGFibGVz
IGFuZCByZXF1aXJlIG11bHRpcGxlIHF1ZXJpZXMgdG8gZ2V0IHRoZSBlbmRwb2ludHMuIFdpdGgg
dGhhdCBzYWlkLCBkbyB3ZSBjYXJlIGlmIGl0IHRha2VzIG9uZSBxdWVyeSBvciBtYW55IHF1ZXJp
ZXMgYXMgbG9uZyBhcyB3ZSAoMSkgaGF2ZSBhIHN0YW5kYXJkIGludGVyZmFjZSB0byBxdWVyeSB0
aGUgcmVwb3NpdG9yeSBhbmQgKDIpIGdldCB0aGUgcmVzdWx0aW5nIGRhdGEgaW4gYSBmb3JtYXQg
dGhhdCB3ZSB1bmRlcnN0YW5kIChpbiB0aGlzIGNhc2UgYSBsaXN0IG9mIGVuZHBvaW50cyk/DQpT
aG91bGQgdGhlIOKAnGNvbGxlY3TigJ0gYmV0d2VlbiB2dWxuZXJhYmlsaXR5IGFzc2Vzc29yIGFu
ZCBjb2xsZWN0b3Igc2hvdWxkIGJlIOKAnHJlcXVlc3QgY29sbGVjdGlvbiAoZm9yIGEgc2V0IG9m
IGVuZHBvaW50cynigJ0/DQoNCkkgZG9uJ3Qgc2VlIHdoeSBub3QuICBUaGF0IHdhcyB0aGUgaW50
ZW50IC0tIHJlcXVlc3Qgb3Igb3RoZXJ3aXNlIGludm9rZSBjb2xsZWN0aW9uLg0KDQpbZGFubnld
IHdvcmtzIGZvciBtZS4NCg0KVGhlIGZpcnN0IOKAnGV2YWx1YXRl4oCdIChmcm9tIHRoZSB0b3Ap
IGNvdWxkIGJlIHRob3VnaHQgb2YgYXMgYW4gYXBwbGljYWJpbGl0eSAvIHN0YWxlbmVzcyBldmFs
dWF0aW9uLiBUaGlzIGRyaXZlcyB3aGF0IGdhcHMgaW4gaW5mb3JtYXRpb24gYW5kIGVuZHBvaW50
cyBzaG91bGQgYmUgdGFyZ2V0ZWQgZm9yIGNvbGxlY3Rpb24uDQoNClllcywgdGhhdCB3YXMgdGhl
IGludGVudC4gIEV2YWx1YXRlIHdoYXQgd2UgY2FuIHdpdGggYXZhaWxhYmxlIG9uLWhhbmQgaW5m
b3JtYXRpb24uDQoNCltkYW5ueV0gYWdyZWUuDQogVGhlIHNlY29uZCDigJwocmUpZXZhbHVhdGXi
gJ0gaXMgdGhlIGFjdHVhbCBwb3N0dXJlIGV2YWx1YXRpb24gd2UgYXJlIHdvcmtpbmcgdG8gc3Vw
cG9ydC4gUmlnaHQ/DQpZZXAsIHRoYXQncyBteSB0YWtlLg0KDQpbZGFubnldIGFncmVlIGhlcmUg
dG9vLg0KDQpSZWdhcmRzLA0KRGF2ZQ0KDQpGcm9tOiBzYWNtIFttYWlsdG86c2FjbS1ib3VuY2Vz
QGlldGYub3JnPG1haWx0bzpzYWNtLWJvdW5jZXNAaWV0Zi5vcmc+XSBPbiBCZWhhbGYgT2YgQmls
bCBNdW55YW4NClNlbnQ6IFRodXJzZGF5LCBGZWJydWFyeSAwMiwgMjAxNyAxMjo1NyBQTQ0KVG86
IEFkYW0gTW9udHZpbGxlIDxhZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53
Lm1vbnR2aWxsZUBnbWFpbC5jb20+Pg0KQ2M6IEhlbmsgQmlya2hvbHogPGhlbmsuYmlya2hvbHpA
c2l0LmZyYXVuaG9mZXIuZGU8bWFpbHRvOmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGU+
Pjsgc2FjbUBpZXRmLm9yZzxtYWlsdG86c2FjbUBpZXRmLm9yZz4NCg0KU3ViamVjdDogUmU6IFtz
YWNtXSBOb3RlcyBvbiBWdWxuZXJhYmlsaXR5IFNjZW5hcmlvIFdvcmtpbmcgU2Vzc2lvbg0KDQpJ
cyBpdCB3b3J0aCBub3RpbmcgaW4gdGhlIGRpYWdyYW0gKGlmIG5vdCwgSSB0aGluayBpdCBuZWVk
cyB0byBiZSBub3RlZCBzb21ld2hlcmUgbm9uZXRoZWxlc3MpIHRoYXQgdGhlIHN0ZXBzIG9mICJn
ZXQgZW5kcG9pbnRzIiBhbmQgc3Vic2VxdWVudCAiZXZhbHVhdGUiIHNob3VsZCBiZSBtYWtpbmcg
c29tZSBkZXRlcm1pbmF0aW9uIG9mIHdoZXRoZXIgb3Igbm90IHRvIGNvbGxlY3QgZm9yIGFuIGVu
ZHBvaW50PyAgRm9yIGV4YW1wbGUsIGlmIGFuIGVuZHBvaW50IGhhcyBubyBhc3Nlc3NtZW50IHJl
c3VsdHMgb3IgdGhlIGFzc2Vzc21lbnQgcmVzdWx0cyBhcmUgY29uc2lkZXJlZCAic3RhbGUiLCB0
aGVuIHRoZSBjb2xsZWN0aW9uIHN0ZXAgd291bGQgdGFrZSBwbGFjZS4gIEkgdW5kZXJzdGFuZCB0
aGF0IGNvdWxkIGJlIHRvbyBtdWNoIGRldGFpbCBmb3IgdGhlIHNjb3BlIG9mIHRoZSBkaWFncmFt
LCBidXQgSSBqdXN0IHdhbnRlZCB0byBub3RlIGl0IHNvbWV3aGVyZS4NCg0KQ2hlZXJzLA0KLUJp
bGwgTS4NCg0KDQpPbiBUaHUsIEZlYiAyLCAyMDE3IGF0IDEyOjQ0IFBNLCBBZGFtIE1vbnR2aWxs
ZSA8YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21h
aWwuY29tPj4gd3JvdGU6DQpUaGFua3MgZm9yIHRoZSBmZWVkYmFjayEgIEkndmUgYXR0YWNoZWQg
YSBtb2RpZmllZCB2ZXJzaW9uIG9mIHRoZSBkaWFncmFtIHRoYXQgY29sbGFwc2VzIHRoZSBlbmRw
b2ludCBhbmQgYXNzZXNzbWVudCByZXN1bHQgcmVwb3NpdG9yaWVzIChieSBrZWVwaW5nIHRoZSBl
bmRwb2ludCByZXBvc2l0b3J5KS4gIFdoZXJlIHdvdWxkIHlvdSBwcm9wb3NlIHdlIGZvY3VzIG9u
IGVuaGFuY2luZyB0aGUgZGlhZ3JhbT8gIFJlbWVtYmVyIHRoYXQgaXQncyBhIHNlcXVlbmNlIGRp
YWdyYW0sIHdoaWNoIG1pZ2h0IGRvIHdlbGwgd2l0aCBzb21lIG1vcmUgc3BlY2lmaWMgZGV0YWls
cyBjYXB0dXJlZCBpbiB0ZXh0IG9yIGEgZGlmZmVyZW50IGZvcm0gb2YgZGlhZ3JhbS4NCg0KV2hh
dCBkbyBmb2xrcyB0aGluayBhYm91dCB1c2luZyBvbmUgb3IgbW9yZSBPVkFMIGRlZmluaXRpb25z
IGFzIGEgc3RhcnRpbmcgcG9pbnQ/DQoNCkFkYW0NCg0KDQpPbiBUaHUsIEZlYiAyLCAyMDE3IGF0
IDEwOjUzIEFNIEhlbmsgQmlya2hvbHogPGhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGU8
bWFpbHRvOmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGU+PiB3cm90ZToNCiMjIEEgRmV3
IENvbW1lbnRzDQoNCiogSSBhZ3JlZSB0aGF0IHRoZSBkaWFncmFtIHByZXR0eSBtdWNoIGNhcHR1
cmVzIGEgIm9uZSB0aW1lIHNuYXBzaG90Ii4NCiogQ29sbGFwc2luZyB0aGUgaGlnaGxpZ2h0ZWQg
Y29tcG9uZW50cyBzZWVtcyB0byBiZSBhIGZlYXNpYmxlIGlkZWEuDQoqIEkgYWdyZWUgdGhhdCB0
aGUgZGlhZ3JhbSBjb3VsZCBiZSBpbXBsZW1lbnRlZCBnaXZlbiBhbiBhcHByb3ByaWF0ZSBzZXQN
Cm9mIGluaXRpYWwgZGF0YS4NCiogSSBzdXBwb3NlIHRoZXJlIGlzIHRoZSByaXNrIHRoYXQgb25l
IGhhcyB0byBzY3JhcCBldmVyeXRoaW5nDQppbXBsZW1lbnRlZCB3aGVuIHdlIHN0YXJ0IHRyeWlu
ZyB0byBtYWtlIGl0IGEgY29udGludW91cyBwcm9jZXNzLg0KKiBJJ2QgcmVjb21tZW5kIHRvIHN0
YXJ0IHdpdGggYSBnZW5lcmljIGJsb2NrIG9mIFBvQyBjb2RlIHRoYXQgcHJvdmlkZXMNCnRoZSBm
dW5jdGlvbnMgb2YgYSBTQUNNIGNvbXBvbmVudCB0byBnZXQgaW5wdXQgYW5kIGNyZWF0ZSBvdXRw
dXQgKG1heWJlDQp1c2luZyBkYnVzLCBjaGFpbmVkIGV2ZW50LWxvb3BzLCBibG9ja2luZyB3YWl0
cyBvbiBmaWZvcywgb3IgSVAgb3Zlcg0KbG9vcGJhY2s/IEEgYmV0dGVyIGNvZGVyIHRoYW4gbWUg
c2hvdWxkIGJhc2ggdGhlc2Ugc3VnZ2VzdGlvbnMpLg0KDQojIyBPbmUsIFR3bywgb3IgVGhyZWUg
VGFza3MNCg0KKiBDcmVhdGluZyBjb21wb25lbnQgY29kZSB0aGF0IGNhbiBjcmVhdGUgdGhlIChk
b3duc3RyZWFtPykgZmxvdyBvZg0KaW5mb3JtYXRpb24gaXMgdXJnZW50IGFuZCBpbXBvcnRhbnQs
IEkgdGhpbmsuDQoqIEVuaGFuY2luZyB0aGUgZGlhZ3JhbSB0byByZXByZXNlbnQgdGhlIGNvbnRp
bnVvdXMgY3ljbGUgd2l0aCBhdCBsZWFzdA0Kb25lIHRyaWdnZXIgKGFzIGlsbHVzdHJhdGVkIGJ5
IEJpbGw7IG5ldyBzb2Z0d2FyZSwgbmV3IFZESSwgbmV3DQplbmRwb2ludHMsIHN0YWxlIHJlc3Vs
dHMsIGV0Yy4pIGlzIGltcG9ydGFudCwgYnV0IG5vdCBhcyB1cmdlbnQuIEl0DQptaWdodCBzYXZl
IHRpbWUgdGhvdWdoIGJ5IHJlZHVjaW5nIHRoZSBhZm9yZSBtZW50aW9uZWQgcmlzayB0byBzaG9v
dA0KeW91ciBzZWxmIGluIHRoZSBmb290IGJ5IGNyZWF0aW5nIGEgdG9vIHNwZWNpZmljIHByb29m
IG9mIGNvbmNlcHQgb2YgdGhlDQpvbmUgdGltZSBzbmFwc2hvdCBhcHByb2FjaCwgSSB0aGluay4N
CiogU2VsZWN0aW5nIGEgc2V0IG9mIGluaXRpYWwgZGF0YSBkZXJpdmVkIGZyb20gT1ZBTCB0byBi
ZSB1c2VkIGluIHRoZQ0Kb25lIHNob3Qgc25hcHNob3Qgc2VlbXMgdG8gYmUgYSBmZWFzaWJsZSBh
cHByb2FjaCB0byBtZSwgYnV0IEkgYW0gbm90DQpzdXJlIGhvdyB0aGUgZ3JvdXAgdGhpbmtzIGFi
b3V0IHRoYXQuDQoNCkRvZXMgdGhhdCBhc3Nlc3NtZW50IHJlcHJlc2VudCB0aGUgZ2VuZXJhbCBv
cGluaW9uLCBvciBpcyB0aGF0IGp1c3QgbWluZT8NCg0KVmllbGUgR3LDvMOfZSwNCg0KSGVuaw0K
DQpPbiAwMi8wMi8yMDE3IDA1OjI4IFBNLCBBZGFtIE1vbnR2aWxsZSB3cm90ZToNCj4gSGkgRXZl
cnlvbmUuICBBIGZldyBvZiB1cyB3ZXJlIGFibGUgdG8gbWFrZSB0aGUgdnVsbmVyYWJpbGl0eSBz
Y2VuYXJpbw0KPiBjYWxsIHRvZGF5IGFuZCBJIHRoaW5rIHdlIGhhZCBhIGdvb2QsIHRob3VnaCBh
dCB0aW1lcyBzcGlyaXRlZCwNCj4gZGlzY3Vzc2lvbi4gIFdlIGRpZCByZWNvcmQgdGhlIG1lZXRp
bmcsIHdoaWNoIGlzIGF2YWlsYWJsZSBhdCBbMV0uICBXZQ0KPiBkaXNjdXNzZWQgdGhlIGF0dGFj
aGVkIChhbm5vdGF0ZWQgd2l0aCBzb21lIG1lZXRpbmcgbm90ZXMpIFVNTC1pc2gNCj4gc2VxdWVu
Y2UgZGlhZ3JhbS4gIEkgaGFkIGNyZWF0ZWQgdGhhdCBkaWFncmFtIHRvIHN0YXJ0IGEgY29udmVy
c2F0aW9uDQo+IChtaXNzaW9uIGFjY29tcGxpc2hlZCBvbiB0aGF0IGZyb250IEkgdGhpbmspIC0t
IGEgY29udmVyc2F0aW9uIHRoYXQNCj4gd291bGQgbGVhZCB1cyB0b3dhcmQgaWRlbnRpZnlpbmcg
dGhlIGRpc2NyZXRlIGNvbXBvbmVudHMsIGludGVyZmFjZXMsDQo+IGFuZCBpbmZvcm1hdGlvbiBy
ZXF1aXJlZCB0byBiZSBzZW50IG92ZXIgdGhvc2UgaW50ZXJmYWNlcy4gIFRoZSBVTUwtaXNoDQo+
IGRpYWdyYW0gcmVwcmVzZW50cyBhICpzaW5nbGUqIGZsb3cgdGhyb3VnaCB0aGUgc3lzdGVtIC0t
IGEgIm9uZS10aW1lIg0KPiBmbG93IHRocm91Z2ggdGhlIHN5c3RlbS4gIEl0IGlnbm9yZXMsIGZv
ciB0aGUgdGltZSBiZWluZywgdGhlIGNvbnRpbnVvdXMNCj4gYXNwZWN0IG9mIG91ciBjaGFydGVy
IGluIGZhdm9yIG9mIGdldHRpbmcgc3RhcnRlZCB3aXRoIHRoZSBiYXNpY3MuICBPbmNlDQo+IHdl
IGhhdmUgYSBnb29kIHVuZGVyc3RhbmRpbmcgb2YgdGhlIGJhc2ljcyAtLSB0aGUgY29tcG9uZW50
cywNCj4gaW50ZXJmYWNlcywgYW5kIGluZm9ybWF0aW9uIHJlcXVpcmVkIC0tIHdlIGNhbiBzdGFy
dCBsb29rIGF0IGENCj4gY29udGludW91cyBtb25pdG9yaW5nIHNlcXVlbmNlICh3aGljaCBjb3Vs
ZCBiZSByZXByZXNlbnRlZCBhcyBhIGRpc3RpbmN0DQo+IGRpYWdyYW0pIHRvIGRldGVybWluZSB3
aGF0IG1vcmUgd2UgbmVlZC4gIFRoZW4sIEkgdGhpbmssIHdlIGNhbiBzdGFydA0KPiBkcmFmdGlu
ZyBzb2x1dGlvbnMuDQo+DQo+IE9uZSBvZiB0aGUgZmlyc3QgaXNzdWVzIGlzIHRoYXQgd2UgbmVl
ZCB0byBmaWd1cmUgb3V0IGlmIHRoZSBjb21wb25lbnRzDQo+IGluIHRoZSBiYXNlIGZsb3cgYXJl
IGFjY3VyYXRlLiAgVGhlIG1haW4gc3VnZ2VzdGlvbiB3ZSd2ZSB0b3NzZWQgYXJvdW5kDQo+IHNv
IGZhciBpcyB0byBjb21iaW5lIHRoZSBFbmRwb2ludCBSZXBvc2l0b3J5IHdpdGggdGhlIEFzc2Vz
c21lbnQgUmVzdWx0DQo+IFJlcG9zaXRvcnkuDQo+DQo+IFdlIHRhbGtlZCBicmllZmx5IGFib3V0
IHdoYXQgaW50ZXJmYWNlIHdlIGNvdWxkIHVzZSBmb3IgdGhlIFZERA0KPiBSZXBvc2l0b3J5LCBh
bmQgbmF0dXJhbGx5IFJPTElFIGNhbWUgdXAgYXMgYW4gb3B0aW9uLg0KPg0KPiBXZSB0YWxrZWQg
YSBsaXR0bGUgYml0IGFib3V0IHRoZSBmaXJzdCAiZ2V0IGVuZHBvaW50cyIgb3BlcmF0aW9uIGJl
dHdlZW4NCj4gdGhlIFZ1bG5lcmFiaWxpdHkgQXNzZXNzb3IgYW5kIHRoZSBFbmRwb2ludCBSZXBv
c2l0b3J5IC0tIHNwZWNpZmljYWxseQ0KPiBhYm91dCB3aGV0aGVyIHdlIHNob3VsZCByZXByZXNl
bnQgb24gdGhpcyBzZXF1ZW5jZSBkaWFncmFtIHRoYXQNCj4gaW5mb3JtYXRpb24gc3VwcG9ydGlu
ZyBhIGp1ZGdlbWVudCBvZiAic3RhbGUiIHdvdWxkIGJlIG5lZWRlZC4NCj4NCj4gV2UgbGVmdCBv
cGVuIHRoZSB0aW1lIHdoZW4gd2Ugd291bGQgbmV4dCBtZWV0LCBmYXZvcmluZyB0byB3b3JrIHRo
YXQgb3V0DQo+IG9uLWxpc3QuICBOZXh0IHdlZWsgaXMgVENHLCBzbyB0aGF0IG1heSBiZSBkaWZm
aWN1bHQ7IHRoZSBmb2xsb3dpbmcgd2Vlaw0KPiBpcyBSU0EsIHNvIHRoYXQgbWF5IGJlIGRpZmZp
Y3VsdC4NCj4NCj4gRm9yIHRob3NlIHdobyB3ZXJlIGluIGF0dGVuZGFuY2UgdG9kYXksIHBsZWFz
ZSBhZGQgdG8gdGhpcyBub3RlIHdpdGgNCj4geW91ciBjb21tZW50cy9jb3JyZWN0aW9ucy4NCj4N
Cj4gS2luZCByZWdhcmRzLA0KPg0KPiBBZGFtDQo+DQo+IFsxXSBodHRwczovL2RyaXZlLmdvb2ds
ZS5jb20vb3Blbj9pZD0wQjhXZjlVbjVGZENiV0doRE9IcFZSMHRNZDFFDQo+DQo+IE9uIE1vbiwg
SmFuIDMwLCAyMDE3IGF0IDExOjIxIEFNIEFkYW0gTW9udHZpbGxlDQo+IDxhZGFtLncubW9udHZp
bGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20+IDxtYWlsdG86
YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwu
Y29tPj4+IHdyb3RlOg0KPg0KPiAgICAgSGkgZXZlcnlvbmUuICBKdXN0IGEgZnJpZW5kbHkgcmVt
aW5kZXIgdGhhdCB3ZSBhcmUgcGxhbm5pbmcgdG8gbWVldA0KPiAgICAgYWdhaW4gdGhpcyBUaHVy
c2RheSBhdCB0aGUgc2FtZSB0aW1lICgyLzIgQCAxMGFtIEVhc3Rlcm4vM3BtIFVUQykNCj4gICAg
IHVzaW5nIFNBQ00ncyBtZWV0aW5nIHJvb20gYXQgaHR0cHM6Ly9pZXRmLndlYmV4LmNvbS9tZWV0
L3NhY20uDQo+DQo+ICAgICBLaW5kIHJlZ2FyZHMsDQo+DQo+ICAgICBBZGFtDQo+DQo+DQo+ICAg
ICBPbiBUaHUsIEphbiAxOSwgMjAxNyBhdCAxMTozNSBBTSBBZGFtIE1vbnR2aWxsZQ0KPiAgICAg
PGFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWls
LmNvbT4gPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53Lm1v
bnR2aWxsZUBnbWFpbC5jb20+Pj4gd3JvdGU6DQo+DQo+ICAgICAgICAgSGVsbG8uIEEgZmV3IG9m
IHVzIG1ldCBpbmZvcm1hbGx5IHRvZGF5IHRvIGRpc2N1c3MgdGhlDQo+ICAgICAgICAgdnVsbmVy
YWJpbGl0eSBzY2VuYXJpbyBpbiBzb21lIG1vcmUgZGV0YWlsIHdpdGggdGhlIGdvYWwgb2YNCj4g
ICAgICAgICBtYWludGFpbmluZyB0aGUgbmFycm93IGZvY3VzIG9uIGEgdnVsbmVyYWJpbGl0eSBh
c3Nlc3NtZW50IHNsaWNlDQo+ICAgICAgICAgdGhyb3VnaCBvdXIgbm90aW9uYWwgZW52aXJvbm1l
bnQuICBXZSBhcmUgdGVuZGluZyB0byBsb29rIGF0DQo+ICAgICAgICAgbWFqb3IgY29tcG9uZW50
cyBhcyBibGFjayBib3hlcyB3aXRoIGludGVyZmFjZXMgYW5kIGRhdGEgZm9ybWF0DQo+ICAgICAg
ICAgZXhwZWN0YXRpb25zLCBhbmQgd2UgYXJlIG5vdCBuZWNlc3NhcmlseSBjb25jZXJuZWQgd2l0
aCBob3cNCj4gICAgICAgICB0aG9zZSBjb21wb25lbnRzIGRvIHRoaW5ncyBpbnRlcm5hbGx5L2Jl
aGluZCB0aGUgc2NlbmVzLg0KPg0KPiAgICAgICAgIFRoZSBtZWV0aW5nIHdhcyByZWNvcmRlZCAo
eW91IGNhbiBmaW5kIGl0IHdpdGggdG9kYXkncyBkYXRlIGF0DQo+ICAgICAgICAgWzFdKS4gIFRo
ZSB0b3BpYyBvZiBkaXNjdXNzaW9uIHdhcyBwcmltYXJpbHkgaW4gdGhlICJwaGFzZSAxIg0KPiAg
ICAgICAgIGFyZWEgb2Ygd2hhdCBEYW5ueSBzZW50IHRvIHRoZSBsaXN0IG5vdCB2ZXJ5IGxvbmcg
YWdvIFsyXSwgYW5kDQo+ICAgICAgICAgcmVzdWx0ZWQgaW4gYSAqc3RhcnRpbmcgcG9pbnQqIGRp
YWdyYW0gWzNdLg0KPg0KPiAgICAgICAgIFRoZSBncm91cCB3aG8gbWV0IHRvZGF5IGFyZSAocm91
Z2hseSkgYWdyZWVkIG9uIHRoZSBzaXggbWFpbg0KPiAgICAgICAgICJjb21wb25lbnRzIiByZXBy
ZXNlbnRlZCBpbiB0aGF0IGRpYWdyYW0sIGJ1dCBhbHNvIHNlZSB0aGF0IHdlDQo+ICAgICAgICAg
aGF2ZSBzb21lIHdvcmsgYWhlYWQuICBTcGVjaWZpY2FsbHksIHdlIHF1aWNrbHkgcmVjb2duaXpl
ZCB0aGF0DQo+ICAgICAgICAgc29tZSBvZiB0aGUgYXNzdW1wdGlvbnMgdGhlIHZ1bG5lcmFiaWxp
dHkgZHJhZnQgbWFrZXMgbWF5IGJlDQo+ICAgICAgICAgYXNzdW1wdGlvbnMgd2UgY2Fubm90IGFm
Zm9yZCB0byBtYWtlIGFuZCBuZWVkIHRvIGluY2x1ZGUgaW4gdGhlDQo+ICAgICAgICAgZXhwbG9y
YXRpb24uDQo+DQo+ICAgICAgICAgV2UgdGhvdWdodCBpdCB3b3VsZCBiZSBhIGdvb2QgaWRlYSB0
byBoYXZlIGFub3RoZXIgaW5mb3JtYWwNCj4gICAgICAgICBkaXNjdXNzaW9uIGluIGEgY291cGxl
IG9mIHdlZWtzIChGZWJydWFyeSAyKSBhdCB0aGUgc2FtZSB0aW1lDQo+ICAgICAgICAgKDEwYW0g
RWFzdGVybiAvIDNwbSBVVEMpLCB1c2luZyB0aGUgc2FtZSBXZWJFeCBbNF0uICAgQXQgdGhhdA0K
PiAgICAgICAgIHRpbWUgd2UgaW50ZW5kIHRvIHJvbGwgdGhyb3VnaCB0aGUgdnVsbmVyYWJpbGl0
eSBhc3Nlc3NtZW50DQo+ICAgICAgICAgc2NlbmFyaW8gYXNzdW1wdGlvbnMgaW4gYW4gZWZmb3J0
IHRvIGRldGVybWluZSB3aGljaCBvbmVzIGNhbiBiZQ0KPiAgICAgICAgIGxlZnQgYXMgYXNzdW1w
dGlvbnMgYW5kIHdoaWNoIG9uZXMgY2Fubm90LiAgVGhlbiB3ZSdsbCB0YWtlDQo+ICAgICAgICAg
YW5vdGhlciBsb29rIGF0IHRoZSBkaWFncmFtIGFuZCB3b3JrIG9uIGl0cyBuZXh0IHZlcnNpb24u
DQo+DQo+ICAgICAgICAgU3RheSB0dW5lZC4NCj4NCj4gICAgICAgICBUaGFua3MgdG8gRGFubnks
IFN0ZXBoZW4sIGFuZCBKZXJvbWUgZm9yIGpvaW5pbmcgYW5kIGNvbnRyaWJ1dGluZyENCj4NCj4g
ICAgICAgICBLaW5kIHJlZ2FyZHMsDQo+DQo+ICAgICAgICAgQWRhbQ0KPg0KPg0KPiAgICAgICAg
IFsxXSBodHRwczovL2RyaXZlLmdvb2dsZS5jb20vb3Blbj9pZD0wQjhXZjlVbjVGZENiV0doRE9I
cFZSMHRNZDFFDQo+ICAgICAgICAgWzJdIGh0dHBzOi8vbWFpbGFyY2hpdmUuaWV0Zi5vcmcvYXJj
aC9tc2cvc2FjbS9fTGlLbHl2QXdzX09WTEZoQjVOU1U1OE1YRE0NCj4gICAgICAgICBbM10gaHR0
cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYk1VNXBkVFJqZWpKdE5I
Yw0KPiAgICAgICAgIFs0XSBodHRwczovL2lldGYud2ViZXguY29tL21lZXQvc2FjbQ0KPg0KPg0K
Pg0KPiBfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KPiBz
YWNtIG1haWxpbmcgbGlzdA0KPiBzYWNtQGlldGYub3JnPG1haWx0bzpzYWNtQGlldGYub3JnPg0K
PiBodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY20NCj4NCg0KX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18NCnNhY20gbWFpbGluZyBs
aXN0DQpzYWNtQGlldGYub3JnPG1haWx0bzpzYWNtQGlldGYub3JnPg0KaHR0cHM6Ly93d3cuaWV0
Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9zYWNtDQoNCg==

--_000_BN6PR09MB14586B8180578BD1857D406EA54F0BN6PR09MB1458namp_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpWZXJkYW5hOw0KCXBhbm9zZS0xOjIgMTEg
NiA0IDMgNSA0IDQgMiA0O30NCi8qIFN0eWxlIERlZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwg
bGkuTXNvTm9ybWFsLCBkaXYuTXNvTm9ybWFsDQoJe21hcmdpbjowaW47DQoJbWFyZ2luLWJvdHRv
bTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6IlRpbWVzIE5ldyBS
b21hbiIsc2VyaWY7fQ0KYTpsaW5rLCBzcGFuLk1zb0h5cGVybGluaw0KCXttc28tc3R5bGUtcHJp
b3JpdHk6OTk7DQoJY29sb3I6Ymx1ZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCmE6
dmlzaXRlZCwgc3Bhbi5Nc29IeXBlcmxpbmtGb2xsb3dlZA0KCXttc28tc3R5bGUtcHJpb3JpdHk6
OTk7DQoJY29sb3I6cHVycGxlOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KcC5tc29u
b3JtYWwwLCBsaS5tc29ub3JtYWwwLCBkaXYubXNvbm9ybWFsMA0KCXttc28tc3R5bGUtbmFtZTpt
c29ub3JtYWw7DQoJbXNvLW1hcmdpbi10b3AtYWx0OmF1dG87DQoJbWFyZ2luLXJpZ2h0OjBpbjsN
Cgltc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0bzsNCgltYXJnaW4tbGVmdDowaW47DQoJZm9udC1z
aXplOjEyLjBwdDsNCglmb250LWZhbWlseToiVGltZXMgTmV3IFJvbWFuIixzZXJpZjt9DQpzcGFu
LmdtYWlsbXNnDQoJe21zby1zdHlsZS1uYW1lOmdtYWlsX21zZzt9DQpzcGFuLkVtYWlsU3R5bGUx
OQ0KCXttc28tc3R5bGUtdHlwZTpwZXJzb25hbDsNCglmb250LWZhbWlseToiQ2FsaWJyaSIsc2Fu
cy1zZXJpZjsNCgljb2xvcjp3aW5kb3d0ZXh0O30NCnNwYW4uRW1haWxTdHlsZTIwDQoJe21zby1z
dHlsZS10eXBlOnBlcnNvbmFsLWNvbXBvc2U7DQoJZm9udC1mYW1pbHk6IkNhbGlicmkiLHNhbnMt
c2VyaWY7DQoJY29sb3I6d2luZG93dGV4dDt9DQouTXNvQ2hwRGVmYXVsdA0KCXttc28tc3R5bGUt
dHlwZTpleHBvcnQtb25seTsNCglmb250LWZhbWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjt9DQpA
cGFnZSBXb3JkU2VjdGlvbjENCgl7c2l6ZTo4LjVpbiAxMS4waW47DQoJbWFyZ2luOjEuMGluIDEu
MGluIDEuMGluIDEuMGluO30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7cGFnZTpXb3JkU2VjdGlvbjE7
fQ0KLS0+PC9zdHlsZT48IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlZGVmYXVsdHMg
djpleHQ9ImVkaXQiIHNwaWRtYXg9IjEwMjYiIC8+DQo8L3htbD48IVtlbmRpZl0tLT48IS0tW2lm
IGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlbGF5b3V0IHY6ZXh0PSJlZGl0Ij4NCjxvOmlkbWFw
IHY6ZXh0PSJlZGl0IiBkYXRhPSIxIiAvPg0KPC9vOnNoYXBlbGF5b3V0PjwveG1sPjwhW2VuZGlm
XS0tPg0KPC9oZWFkPg0KPGJvZHkgbGFuZz0iRU4tVVMiIGxpbms9ImJsdWUiIHZsaW5rPSJwdXJw
bGUiPg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxz
cGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVv
dDssc2Fucy1zZXJpZiI+SSB3aWxsIHRyeSBzb21lIG1vcmUgY29tbWVudHMgaW5saW5lIDspLjxv
OnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJm
b250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJp
ZiI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90
OyxzYW5zLXNlcmlmIj5UaGFua3MsPGJyPg0KPGJyPg0KRGFubnk8bzpwPjwvbzpwPjwvc3Bhbj48
L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtm
b250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPjxvOnA+Jm5ic3A7PC9v
OnA+PC9zcGFuPjwvcD4NCjxkaXYgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNvbGlk
IGJsdWUgMS41cHQ7cGFkZGluZzowaW4gMGluIDBpbiA0LjBwdCI+DQo8ZGl2Pg0KPGRpdiBzdHls
ZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLXRvcDpzb2xpZCAjRTFFMUUxIDEuMHB0O3BhZGRpbmc6My4w
cHQgMGluIDBpbiAwaW4iPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PGI+PHNwYW4gc3R5bGU9ImZv
bnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlm
Ij5Gcm9tOjwvc3Bhbj48L2I+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1p
bHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj4gc2FjbSBbbWFpbHRvOnNhY20tYm91
bmNlc0BpZXRmLm9yZ10NCjxiPk9uIEJlaGFsZiBPZiA8L2I+QWRhbSBNb250dmlsbGU8YnI+DQo8
Yj5TZW50OjwvYj4gVGh1cnNkYXksIEZlYnJ1YXJ5IDAyLCAyMDE3IDI6MDcgUE08YnI+DQo8Yj5U
bzo8L2I+IFdhbHRlcm1pcmUsIERhdmlkIEEuIChGZWQpICZsdDtkYXZpZC53YWx0ZXJtaXJlQG5p
c3QuZ292Jmd0OzsgQmlsbCBNdW55YW4gJmx0O2JpbGwubXVueWFuLmlldGZAZ21haWwuY29tJmd0
Ozxicj4NCjxiPkNjOjwvYj4gSGVuayBCaXJraG9seiAmbHQ7aGVuay5iaXJraG9sekBzaXQuZnJh
dW5ob2Zlci5kZSZndDs7IHNhY21AaWV0Zi5vcmc8YnI+DQo8Yj5TdWJqZWN0OjwvYj4gUmU6IFtz
YWNtXSBOb3RlcyBvbiBWdWxuZXJhYmlsaXR5IFNjZW5hcmlvIFdvcmtpbmcgU2Vzc2lvbjxvOnA+
PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48
bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0i
bWFyZ2luLWJvdHRvbToxMi4wcHQiPldpbGwgdHJ5IGlubGluZS4uLjxvOnA+PC9vOnA+PC9wPg0K
PGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5PbiBUaHUsIEZlYiAyLCAyMDE3IGF0
IDEyOjM0IFBNIFdhbHRlcm1pcmUsIERhdmlkIEEuIChGZWQpICZsdDs8YSBocmVmPSJtYWlsdG86
ZGF2aWQud2FsdGVybWlyZUBuaXN0LmdvdiI+ZGF2aWQud2FsdGVybWlyZUBuaXN0LmdvdjwvYT4m
Z3Q7IHdyb3RlOjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8YmxvY2txdW90ZSBzdHlsZT0iYm9y
ZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0NDQyAxLjBwdDtwYWRkaW5nOjBpbiAwaW4g
MGluIDYuMHB0O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdpbi1yaWdodDowaW4iPg0KPGRpdj4NCjxk
aXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87
bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxzcGFuIGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4g
c3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90Oyxz
YW5zLXNlcmlmIj5JcyB0aGUgb3BlcmF0aW9uIOKAnGdldCBlbmRwb2ludHPigJ0gYSBzaW5nbGUg
b3BlcmF0aW9uIG9yIGlzIGl0IG11bHRpcGxlIG9wZXJhdGlvbnMg4oCcZ2V0IGVuZHBvaW50DQog
Y2hhcmFjdGVyaXN0aWNz4oCdIGFuZCDigJxnZXQgcHJldmlvdXNseSBjb2xsZWN0ZWQgZGF0YeKA
nSwgb3IgZXZlbiDigJxxdWVyeSBpZiB0aGVyZSBpcyBwcmV2aW91c2x5IGNvbGxlY3RlZCBkYXRh
IHRoYXQgbWF0Y2hlcyBYIGluIHRpbWVmcmFtZSBZP+KAnSBJdCB3b3VsZCBiZSBoZWxwZnVsIHRv
IGJlIG1vcmUgc3BlY2lmaWMgaGVyZSBzaW5jZSB0aGUgaW5mb3JtYXRpb24gZXhjaGFuZ2VzIG1h
eSBkaWZmZXIuPC9zcGFuPjwvc3Bhbj48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8
L2Jsb2NrcXVvdGU+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286
cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5Eb24ndCBrbm93IHll
dCAtIHRoaXMgaXMgZXhhY3RseSB0aGUgc29ydCBvZiBjb252ZXJzYXRpb24gd2Ugc2hvdWxkIGJl
IGhhdmluZyEgV2hhdCBpZiB3ZSBudW1iZXJlZCB0aGVtIGFzIGlzLCB0aGVuIGRpc2N1c3MgZWFj
aCBpbiB0dXJuLCBpZiBmb3Igbm8gb3RoZXIgcmVhc29uIHRoYW4gdHJhY2tpbmcgd2hhdCB3ZSBu
ZWVkIHRvIGRvIGFuZCB3aGF0IHdlJ3ZlIGRvbmU/PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxk
aXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWxlZnQ6NS4yNXB0Ij48bzpw
PiZuYnNwOzwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxiPjxpPjxzcGFuIHN0eWxl
PSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1z
ZXJpZiI+W2Rhbm55XSBpcyBpdCBwb3NzaWJsZSB0aGF0IGl0IGRlcGVuZHMgb24gaG93IHRoZSBk
YXRhIGlzIHN0b3JlZC9vcmdhbml6ZWQgaW4gdGhlIOKAnGVuZHBvaW50IHJlcG9zaXRvcnnigJ0/
IEZvciBleGFtcGxlLCBvbmUgdmVuZG9yIG1pZ2h0IG1ha2UgZW5kcG9pbnRzIGl0cyBvd24gdGFi
bGUgd2hlcmVhcw0KIGFub3RoZXIgdmVuZG9yIG1pZ2h0IGhhdmUgdGhlIGRhdGEgc3ByZWFkIGFj
cm9zcyBtdWx0aXBsZSB0YWJsZXMgYW5kIHJlcXVpcmUgbXVsdGlwbGUgcXVlcmllcyB0byBnZXQg
dGhlIGVuZHBvaW50cy4gV2l0aCB0aGF0IHNhaWQsIGRvIHdlIGNhcmUgaWYgaXQgdGFrZXMgb25l
IHF1ZXJ5IG9yIG1hbnkgcXVlcmllcyBhcyBsb25nIGFzIHdlICgxKSBoYXZlIGEgc3RhbmRhcmQg
aW50ZXJmYWNlIHRvIHF1ZXJ5IHRoZSByZXBvc2l0b3J5IGFuZCAoMikNCiBnZXQgdGhlIHJlc3Vs
dGluZyBkYXRhIGluIGEgZm9ybWF0IHRoYXQgd2UgdW5kZXJzdGFuZCAoaW4gdGhpcyBjYXNlIGEg
bGlzdCBvZiBlbmRwb2ludHMpPzxvOnA+PC9vOnA+PC9zcGFuPjwvaT48L2I+PC9wPg0KPC9kaXY+
DQo8YmxvY2txdW90ZSBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0ND
QyAxLjBwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDYuMHB0O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdp
bi1yaWdodDowaW4iPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0i
bXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxzcGFu
IGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1p
bHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5TaG91bGQgdGhlIOKAnGNvbGxlY3Ti
gJ0gYmV0d2VlbiB2dWxuZXJhYmlsaXR5IGFzc2Vzc29yIGFuZCBjb2xsZWN0b3Igc2hvdWxkIGJl
IOKAnHJlcXVlc3QgY29sbGVjdGlvbg0KIChmb3IgYSBzZXQgb2YgZW5kcG9pbnRzKeKAnT88L3Nw
YW4+PC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90ZT4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2
Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPkkgZG9uJ3Qgc2VlIHdoeSBub3QuJm5ic3A7
IFRoYXQgd2FzIHRoZSBpbnRlbnQgLS0gcmVxdWVzdCBvciBvdGhlcndpc2UgaW52b2tlIGNvbGxl
Y3Rpb24uPG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij4mbmJzcDs8bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxiPjxpPjxzcGFu
IHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDss
c2Fucy1zZXJpZiI+W2Rhbm55XSB3b3JrcyBmb3IgbWUuPC9zcGFuPjwvaT48L2I+PHNwYW4gc3R5
bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5z
LXNlcmlmIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxibG9ja3F1b3RlIHN0eWxl
PSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGlu
IDBpbiAwaW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFyZ2luLXJpZ2h0OjBpbiI+DQo8ZGl2
Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6
YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gY2xhc3M9ImdtYWlsbXNnIj48
c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1
b3Q7LHNhbnMtc2VyaWYiPiZuYnNwOzwvc3Bhbj48L3NwYW4+PG86cD48L286cD48L3A+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdp
bi1ib3R0b20tYWx0OmF1dG8iPjxzcGFuIGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZv
bnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlm
Ij5UaGUgZmlyc3Qg4oCcZXZhbHVhdGXigJ0gKGZyb20gdGhlIHRvcCkgY291bGQgYmUgdGhvdWdo
dCBvZiBhcyBhbiBhcHBsaWNhYmlsaXR5IC8gc3RhbGVuZXNzIGV2YWx1YXRpb24uDQogVGhpcyBk
cml2ZXMgd2hhdCBnYXBzIGluIGluZm9ybWF0aW9uIGFuZCBlbmRwb2ludHMgc2hvdWxkIGJlIHRh
cmdldGVkIGZvciBjb2xsZWN0aW9uLjwvc3Bhbj48L3NwYW4+PG86cD48L286cD48L3A+DQo8L2Rp
dj4NCjwvZGl2Pg0KPC9ibG9ja3F1b3RlPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxv
OnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
WWVzLCB0aGF0IHdhcyB0aGUgaW50ZW50LiZuYnNwOyBFdmFsdWF0ZSB3aGF0IHdlIGNhbiB3aXRo
IGF2YWlsYWJsZSBvbi1oYW5kIGluZm9ybWF0aW9uLjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8
ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48Yj48aT48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZh
bWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPltkYW5ueV0gYWdyZWUuPG86cD48
L286cD48L3NwYW4+PC9pPjwvYj48L3A+DQo8L2Rpdj4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3Jk
ZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAw
aW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFyZ2luLXJpZ2h0OjBpbiI+DQo8ZGl2Pg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bztt
c28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gY2xhc3M9ImdtYWlsbXNnIj48c3BhbiBz
dHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNh
bnMtc2VyaWYiPiZuYnNwO1RoZSBzZWNvbmQg4oCcKHJlKWV2YWx1YXRl4oCdIGlzIHRoZSBhY3R1
YWwgcG9zdHVyZSBldmFsdWF0aW9uIHdlIGFyZSB3b3JraW5nIHRvIHN1cHBvcnQuIFJpZ2h0Pzwv
c3Bhbj48L3NwYW4+PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9ibG9ja3F1b3Rl
Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPlllcCwgdGhhdCdzIG15IHRha2UuPG86cD48
L286cD48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48Yj48aT48c3BhbiBzdHlsZT0iZm9udC1z
aXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPjxv
OnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvaT48L2I+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
PGI+PGk+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2Fs
aWJyaSZxdW90OyxzYW5zLXNlcmlmIj5bZGFubnldIGFncmVlIGhlcmUgdG9vLjwvc3Bhbj48L2k+
PC9iPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssc2Fucy1zZXJpZiI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8Ymxv
Y2txdW90ZSBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0NDQyAxLjBw
dDtwYWRkaW5nOjBpbiAwaW4gMGluIDYuMHB0O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdpbi1yaWdo
dDowaW4iPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1h
cmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxzcGFuIGNsYXNz
PSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1
b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj4mbmJzcDs8L3NwYW4+PC9zcGFuPjxvOnA+PC9v
OnA+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDph
dXRvO21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBjbGFzcz0iZ21haWxtc2ciPjxz
cGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVv
dDssc2Fucy1zZXJpZiI+UmVnYXJkcyw8L3NwYW4+PC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21zby1tYXJn
aW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBjbGFzcz0iZ21haWxtc2ciPjxzcGFuIHN0eWxlPSJm
b250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJp
ZiI+RGF2ZTwvc3Bhbj48L3NwYW4+PG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
IiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1
dG8iPjxzcGFuIGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7
Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj4mbmJzcDs8L3NwYW4+
PC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxl
ZnQ6c29saWQgYmx1ZSAxLjVwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDQuMHB0Ij4NCjxkaXY+DQo8
ZGl2IHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItdG9wOnNvbGlkICNFMUUxRTEgMS4wcHQ7cGFk
ZGluZzozLjBwdCAwaW4gMGluIDBpbiI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNv
LW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxzcGFuIGNs
YXNzPSJnbWFpbG1zZyI+PGI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1p
bHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5Gcm9tOjwvc3Bhbj48L2I+PC9zcGFu
PjxzcGFuIGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj4NCiBzYWNtIFttYWlsdG86
PGEgaHJlZj0ibWFpbHRvOnNhY20tYm91bmNlc0BpZXRmLm9yZyIgdGFyZ2V0PSJfYmxhbmsiPnNh
Y20tYm91bmNlc0BpZXRmLm9yZzwvYT5dDQo8Yj5PbiBCZWhhbGYgT2YgPC9iPkJpbGwgTXVueWFu
PC9zcGFuPjwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTom
cXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPjxicj4NCjxzcGFuIGNsYXNzPSJnbWFpbG1z
ZyI+PGI+U2VudDo8L2I+IFRodXJzZGF5LCBGZWJydWFyeSAwMiwgMjAxNyAxMjo1NyBQTTwvc3Bh
bj48YnI+DQo8c3BhbiBjbGFzcz0iZ21haWxtc2ciPjxiPlRvOjwvYj4gQWRhbSBNb250dmlsbGUg
Jmx0OzxhIGhyZWY9Im1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJf
YmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPC9hPiZndDs8L3NwYW4+PGJyPg0KPHNw
YW4gY2xhc3M9ImdtYWlsbXNnIj48Yj5DYzo8L2I+IEhlbmsgQmlya2hvbHogJmx0OzxhIGhyZWY9
Im1haWx0bzpoZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlIiB0YXJnZXQ9Il9ibGFuayI+
aGVuay5iaXJraG9sekBzaXQuZnJhdW5ob2Zlci5kZTwvYT4mZ3Q7Ow0KPGEgaHJlZj0ibWFpbHRv
OnNhY21AaWV0Zi5vcmciIHRhcmdldD0iX2JsYW5rIj5zYWNtQGlldGYub3JnPC9hPjwvc3Bhbj48
L3NwYW4+PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwv
ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8ZGl2IHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpz
b2xpZCBibHVlIDEuNXB0O3BhZGRpbmc6MGluIDBpbiAwaW4gNC4wcHQiPg0KPGRpdj4NCjxkaXYg
c3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci10b3A6c29saWQgI0UxRTFFMSAxLjBwdDtwYWRkaW5n
OjMuMHB0IDBpbiAwaW4gMGluIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFy
Z2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gc3R5bGU9
ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNl
cmlmIj48YnI+DQo8c3BhbiBjbGFzcz0iZ21haWxtc2ciPjxiPlN1YmplY3Q6PC9iPiBSZTogW3Nh
Y21dIE5vdGVzIG9uIFZ1bG5lcmFiaWxpdHkgU2NlbmFyaW8gV29ya2luZyBTZXNzaW9uPC9zcGFu
Pjwvc3Bhbj48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0K
PC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxkaXYgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0
OnNvbGlkIGJsdWUgMS41cHQ7cGFkZGluZzowaW4gMGluIDBpbiA0LjBwdCI+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0
b20tYWx0OmF1dG8iPiZuYnNwOzxvOnA+PC9vOnA+PC9wPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1i
b3R0b20tYWx0OmF1dG8iPjxzcGFuIGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZvbnQt
ZmFtaWx5OiZxdW90O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+SXMgaXQgd29ydGggbm90aW5n
IGluIHRoZSBkaWFncmFtIChpZiBub3QsIEkgdGhpbmsgaXQgbmVlZHMgdG8gYmUgbm90ZWQgc29t
ZXdoZXJlIG5vbmV0aGVsZXNzKSB0aGF0IHRoZSBzdGVwcw0KIG9mICZxdW90O2dldCBlbmRwb2lu
dHMmcXVvdDsgYW5kIHN1YnNlcXVlbnQgJnF1b3Q7ZXZhbHVhdGUmcXVvdDsgc2hvdWxkIGJlIG1h
a2luZyBzb21lIGRldGVybWluYXRpb24gb2Ygd2hldGhlciBvciBub3QgdG8gY29sbGVjdCBmb3Ig
YW4gZW5kcG9pbnQ/Jm5ic3A7IEZvciBleGFtcGxlLCBpZiBhbiBlbmRwb2ludCBoYXMgbm8gYXNz
ZXNzbWVudCByZXN1bHRzIG9yIHRoZSBhc3Nlc3NtZW50IHJlc3VsdHMgYXJlIGNvbnNpZGVyZWQg
JnF1b3Q7c3RhbGUmcXVvdDssIHRoZW4gdGhlIGNvbGxlY3Rpb24gc3RlcA0KIHdvdWxkIHRha2Ug
cGxhY2UuJm5ic3A7IEkgdW5kZXJzdGFuZCB0aGF0IGNvdWxkIGJlIHRvbyBtdWNoIGRldGFpbCBm
b3IgdGhlIHNjb3BlIG9mIHRoZSBkaWFncmFtLCBidXQgSSBqdXN0IHdhbnRlZCB0byBub3RlIGl0
IHNvbWV3aGVyZS48L3NwYW4+PC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21zby1t
YXJnaW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBjbGFzcz0iZ21haWxtc2ciPjxzcGFuIHN0eWxl
PSJmb250LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1b3Q7LHNhbnMtc2VyaWYiPiZuYnNwOzwvc3Bh
bj48L3NwYW4+PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0
OmF1dG8iPjxzcGFuIGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiZx
dW90O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+Q2hlZXJzLCZuYnNwOzwvc3Bhbj48L3NwYW4+
PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHls
ZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxz
cGFuIGNsYXNzPSJnbWFpbG1zZyI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O1ZlcmRh
bmEmcXVvdDssc2Fucy1zZXJpZiI+LUJpbGwgTS48L3NwYW4+PC9zcGFuPjxvOnA+PC9vOnA+PC9w
Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4t
dG9wLWFsdDphdXRvO21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBjbGFzcz0iZ21h
aWxtc2ciPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1b3Q7LHNhbnMt
c2VyaWYiPiZuYnNwOzwvc3Bhbj48L3NwYW4+PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjwvZGl2
Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8ZGl2IHN0eWxlPSJib3Jk
ZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCBibHVlIDEuNXB0O3BhZGRpbmc6MGluIDBpbiAwaW4g
NC4wcHQiPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRv
cC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+Jm5ic3A7PG86cD48L286cD48
L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFs
dDphdXRvO21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvIj5PbiBUaHUsIEZlYiAyLCAyMDE3IGF0
IDEyOjQ0IFBNLCBBZGFtIE1vbnR2aWxsZSAmbHQ7PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5tb250
dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5j
b208L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3Jk
ZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAw
aW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tcmlnaHQ6
MGluO21hcmdpbi1ib3R0b206NS4wcHQiPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0
eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+
VGhhbmtzIGZvciB0aGUgZmVlZGJhY2shJm5ic3A7IEkndmUgYXR0YWNoZWQgYSBtb2RpZmllZCB2
ZXJzaW9uIG9mIHRoZSBkaWFncmFtIHRoYXQgY29sbGFwc2VzIHRoZSBlbmRwb2ludCBhbmQgYXNz
ZXNzbWVudCByZXN1bHQgcmVwb3NpdG9yaWVzIChieSBrZWVwaW5nIHRoZSBlbmRwb2ludCByZXBv
c2l0b3J5KS4mbmJzcDsgV2hlcmUNCiB3b3VsZCB5b3UgcHJvcG9zZSB3ZSBmb2N1cyBvbiBlbmhh
bmNpbmcgdGhlIGRpYWdyYW0/Jm5ic3A7IFJlbWVtYmVyIHRoYXQgaXQncyBhIHNlcXVlbmNlIGRp
YWdyYW0sIHdoaWNoIG1pZ2h0IGRvIHdlbGwgd2l0aCBzb21lIG1vcmUgc3BlY2lmaWMgZGV0YWls
cyBjYXB0dXJlZCBpbiB0ZXh0IG9yIGEgZGlmZmVyZW50IGZvcm0gb2YgZGlhZ3JhbS48bzpwPjwv
bzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10
b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPiZuYnNwOzxvOnA+PC9vOnA+
PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJn
aW4tdG9wLWFsdDphdXRvO21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvIj5XaGF0IGRvIGZvbGtz
IHRoaW5rIGFib3V0IHVzaW5nIG9uZSBvciBtb3JlIE9WQUwgZGVmaW5pdGlvbnMgYXMgYSBzdGFy
dGluZyBwb2ludD88bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1h
bHQ6YXV0byI+PHNwYW4gY2xhc3M9ImdtYWlsbXNnIj48c3BhbiBzdHlsZT0iY29sb3I6Izg4ODg4
OCI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFy
Z2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gY2xhc3M9ImdtYWlsbXNnIj48c3BhbiBzdHlsZT0i
Y29sb3I6Izg4ODg4OCI+QWRhbTwvc3Bhbj48L3NwYW4+PG86cD48L286cD48L3A+DQo8L2Rpdj4N
CjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFy
Z2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+Jm5ic3A7PG86cD48
L286cD48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2lu
LXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+Jm5ic3A7PG86cD48L286
cD48L3A+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFy
Z2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+T24gVGh1LCBGZWIg
MiwgMjAxNyBhdCAxMDo1MyBBTSBIZW5rIEJpcmtob2x6ICZsdDs8YSBocmVmPSJtYWlsdG86aGVu
ay5iaXJraG9sekBzaXQuZnJhdW5ob2Zlci5kZSIgdGFyZ2V0PSJfYmxhbmsiPmhlbmsuYmlya2hv
bHpAc2l0LmZyYXVuaG9mZXIuZGU8L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvcD4NCjwvZGl2
Pg0KPGJsb2NrcXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNvbGlkICNDQ0ND
Q0MgMS4wcHQ7cGFkZGluZzowaW4gMGluIDBpbiA2LjBwdDttYXJnaW4tbGVmdDo0LjhwdDttYXJn
aW4tdG9wOjUuMHB0O21hcmdpbi1yaWdodDowaW47bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdp
bi1ib3R0b20tYWx0OmF1dG8iPiMjIEEgRmV3IENvbW1lbnRzPGJyPg0KPGJyPg0KKiBJIGFncmVl
IHRoYXQgdGhlIGRpYWdyYW0gcHJldHR5IG11Y2ggY2FwdHVyZXMgYSAmcXVvdDtvbmUgdGltZSBz
bmFwc2hvdCZxdW90Oy48YnI+DQoqIENvbGxhcHNpbmcgdGhlIGhpZ2hsaWdodGVkIGNvbXBvbmVu
dHMgc2VlbXMgdG8gYmUgYSBmZWFzaWJsZSBpZGVhLjxicj4NCiogSSBhZ3JlZSB0aGF0IHRoZSBk
aWFncmFtIGNvdWxkIGJlIGltcGxlbWVudGVkIGdpdmVuIGFuIGFwcHJvcHJpYXRlIHNldDxicj4N
Cm9mIGluaXRpYWwgZGF0YS48YnI+DQoqIEkgc3VwcG9zZSB0aGVyZSBpcyB0aGUgcmlzayB0aGF0
IG9uZSBoYXMgdG8gc2NyYXAgZXZlcnl0aGluZzxicj4NCmltcGxlbWVudGVkIHdoZW4gd2Ugc3Rh
cnQgdHJ5aW5nIHRvIG1ha2UgaXQgYSBjb250aW51b3VzIHByb2Nlc3MuPGJyPg0KKiBJJ2QgcmVj
b21tZW5kIHRvIHN0YXJ0IHdpdGggYSBnZW5lcmljIGJsb2NrIG9mIFBvQyBjb2RlIHRoYXQgcHJv
dmlkZXM8YnI+DQp0aGUgZnVuY3Rpb25zIG9mIGEgU0FDTSBjb21wb25lbnQgdG8gZ2V0IGlucHV0
IGFuZCBjcmVhdGUgb3V0cHV0IChtYXliZTxicj4NCnVzaW5nIGRidXMsIGNoYWluZWQgZXZlbnQt
bG9vcHMsIGJsb2NraW5nIHdhaXRzIG9uIGZpZm9zLCBvciBJUCBvdmVyPGJyPg0KbG9vcGJhY2s/
IEEgYmV0dGVyIGNvZGVyIHRoYW4gbWUgc2hvdWxkIGJhc2ggdGhlc2Ugc3VnZ2VzdGlvbnMpLjxi
cj4NCjxicj4NCiMjIE9uZSwgVHdvLCBvciBUaHJlZSBUYXNrczxicj4NCjxicj4NCiogQ3JlYXRp
bmcgY29tcG9uZW50IGNvZGUgdGhhdCBjYW4gY3JlYXRlIHRoZSAoZG93bnN0cmVhbT8pIGZsb3cg
b2Y8YnI+DQppbmZvcm1hdGlvbiBpcyB1cmdlbnQgYW5kIGltcG9ydGFudCwgSSB0aGluay48YnI+
DQoqIEVuaGFuY2luZyB0aGUgZGlhZ3JhbSB0byByZXByZXNlbnQgdGhlIGNvbnRpbnVvdXMgY3lj
bGUgd2l0aCBhdCBsZWFzdDxicj4NCm9uZSB0cmlnZ2VyIChhcyBpbGx1c3RyYXRlZCBieSBCaWxs
OyBuZXcgc29mdHdhcmUsIG5ldyBWREksIG5ldzxicj4NCmVuZHBvaW50cywgc3RhbGUgcmVzdWx0
cywgZXRjLikgaXMgaW1wb3J0YW50LCBidXQgbm90IGFzIHVyZ2VudC4gSXQ8YnI+DQptaWdodCBz
YXZlIHRpbWUgdGhvdWdoIGJ5IHJlZHVjaW5nIHRoZSBhZm9yZSBtZW50aW9uZWQgcmlzayB0byBz
aG9vdDxicj4NCnlvdXIgc2VsZiBpbiB0aGUgZm9vdCBieSBjcmVhdGluZyBhIHRvbyBzcGVjaWZp
YyBwcm9vZiBvZiBjb25jZXB0IG9mIHRoZTxicj4NCm9uZSB0aW1lIHNuYXBzaG90IGFwcHJvYWNo
LCBJIHRoaW5rLjxicj4NCiogU2VsZWN0aW5nIGEgc2V0IG9mIGluaXRpYWwgZGF0YSBkZXJpdmVk
IGZyb20gT1ZBTCB0byBiZSB1c2VkIGluIHRoZTxicj4NCm9uZSBzaG90IHNuYXBzaG90IHNlZW1z
IHRvIGJlIGEgZmVhc2libGUgYXBwcm9hY2ggdG8gbWUsIGJ1dCBJIGFtIG5vdDxicj4NCnN1cmUg
aG93IHRoZSBncm91cCB0aGlua3MgYWJvdXQgdGhhdC48YnI+DQo8YnI+DQpEb2VzIHRoYXQgYXNz
ZXNzbWVudCByZXByZXNlbnQgdGhlIGdlbmVyYWwgb3Bpbmlvbiwgb3IgaXMgdGhhdCBqdXN0IG1p
bmU/PGJyPg0KPGJyPg0KVmllbGUgR3LDvMOfZSw8YnI+DQo8YnI+DQpIZW5rPGJyPg0KPGJyPg0K
T24gMDIvMDIvMjAxNyAwNToyOCBQTSwgQWRhbSBNb250dmlsbGUgd3JvdGU6PGJyPg0KJmd0OyBI
aSBFdmVyeW9uZS4mbmJzcDsgQSBmZXcgb2YgdXMgd2VyZSBhYmxlIHRvIG1ha2UgdGhlIHZ1bG5l
cmFiaWxpdHkgc2NlbmFyaW88YnI+DQomZ3Q7IGNhbGwgdG9kYXkgYW5kIEkgdGhpbmsgd2UgaGFk
IGEgZ29vZCwgdGhvdWdoIGF0IHRpbWVzIHNwaXJpdGVkLDxicj4NCiZndDsgZGlzY3Vzc2lvbi4m
bmJzcDsgV2UgZGlkIHJlY29yZCB0aGUgbWVldGluZywgd2hpY2ggaXMgYXZhaWxhYmxlIGF0IFsx
XS4mbmJzcDsgV2U8YnI+DQomZ3Q7IGRpc2N1c3NlZCB0aGUgYXR0YWNoZWQgKGFubm90YXRlZCB3
aXRoIHNvbWUgbWVldGluZyBub3RlcykgVU1MLWlzaDxicj4NCiZndDsgc2VxdWVuY2UgZGlhZ3Jh
bS4mbmJzcDsgSSBoYWQgY3JlYXRlZCB0aGF0IGRpYWdyYW0gdG8gc3RhcnQgYSBjb252ZXJzYXRp
b248YnI+DQomZ3Q7IChtaXNzaW9uIGFjY29tcGxpc2hlZCBvbiB0aGF0IGZyb250IEkgdGhpbmsp
IC0tIGEgY29udmVyc2F0aW9uIHRoYXQ8YnI+DQomZ3Q7IHdvdWxkIGxlYWQgdXMgdG93YXJkIGlk
ZW50aWZ5aW5nIHRoZSBkaXNjcmV0ZSBjb21wb25lbnRzLCBpbnRlcmZhY2VzLDxicj4NCiZndDsg
YW5kIGluZm9ybWF0aW9uIHJlcXVpcmVkIHRvIGJlIHNlbnQgb3ZlciB0aG9zZSBpbnRlcmZhY2Vz
LiZuYnNwOyBUaGUgVU1MLWlzaDxicj4NCiZndDsgZGlhZ3JhbSByZXByZXNlbnRzIGEgKnNpbmds
ZSogZmxvdyB0aHJvdWdoIHRoZSBzeXN0ZW0gLS0gYSAmcXVvdDtvbmUtdGltZSZxdW90Ozxicj4N
CiZndDsgZmxvdyB0aHJvdWdoIHRoZSBzeXN0ZW0uJm5ic3A7IEl0IGlnbm9yZXMsIGZvciB0aGUg
dGltZSBiZWluZywgdGhlIGNvbnRpbnVvdXM8YnI+DQomZ3Q7IGFzcGVjdCBvZiBvdXIgY2hhcnRl
ciBpbiBmYXZvciBvZiBnZXR0aW5nIHN0YXJ0ZWQgd2l0aCB0aGUgYmFzaWNzLiZuYnNwOyBPbmNl
PGJyPg0KJmd0OyB3ZSBoYXZlIGEgZ29vZCB1bmRlcnN0YW5kaW5nIG9mIHRoZSBiYXNpY3MgLS0g
dGhlIGNvbXBvbmVudHMsPGJyPg0KJmd0OyBpbnRlcmZhY2VzLCBhbmQgaW5mb3JtYXRpb24gcmVx
dWlyZWQgLS0gd2UgY2FuIHN0YXJ0IGxvb2sgYXQgYTxicj4NCiZndDsgY29udGludW91cyBtb25p
dG9yaW5nIHNlcXVlbmNlICh3aGljaCBjb3VsZCBiZSByZXByZXNlbnRlZCBhcyBhIGRpc3RpbmN0
PGJyPg0KJmd0OyBkaWFncmFtKSB0byBkZXRlcm1pbmUgd2hhdCBtb3JlIHdlIG5lZWQuJm5ic3A7
IFRoZW4sIEkgdGhpbmssIHdlIGNhbiBzdGFydDxicj4NCiZndDsgZHJhZnRpbmcgc29sdXRpb25z
Ljxicj4NCiZndDs8YnI+DQomZ3Q7IE9uZSBvZiB0aGUgZmlyc3QgaXNzdWVzIGlzIHRoYXQgd2Ug
bmVlZCB0byBmaWd1cmUgb3V0IGlmIHRoZSBjb21wb25lbnRzPGJyPg0KJmd0OyBpbiB0aGUgYmFz
ZSBmbG93IGFyZSBhY2N1cmF0ZS4mbmJzcDsgVGhlIG1haW4gc3VnZ2VzdGlvbiB3ZSd2ZSB0b3Nz
ZWQgYXJvdW5kPGJyPg0KJmd0OyBzbyBmYXIgaXMgdG8gY29tYmluZSB0aGUgRW5kcG9pbnQgUmVw
b3NpdG9yeSB3aXRoIHRoZSBBc3Nlc3NtZW50IFJlc3VsdDxicj4NCiZndDsgUmVwb3NpdG9yeS48
YnI+DQomZ3Q7PGJyPg0KJmd0OyBXZSB0YWxrZWQgYnJpZWZseSBhYm91dCB3aGF0IGludGVyZmFj
ZSB3ZSBjb3VsZCB1c2UgZm9yIHRoZSBWREQ8YnI+DQomZ3Q7IFJlcG9zaXRvcnksIGFuZCBuYXR1
cmFsbHkgUk9MSUUgY2FtZSB1cCBhcyBhbiBvcHRpb24uPGJyPg0KJmd0Ozxicj4NCiZndDsgV2Ug
dGFsa2VkIGEgbGl0dGxlIGJpdCBhYm91dCB0aGUgZmlyc3QgJnF1b3Q7Z2V0IGVuZHBvaW50cyZx
dW90OyBvcGVyYXRpb24gYmV0d2Vlbjxicj4NCiZndDsgdGhlIFZ1bG5lcmFiaWxpdHkgQXNzZXNz
b3IgYW5kIHRoZSBFbmRwb2ludCBSZXBvc2l0b3J5IC0tIHNwZWNpZmljYWxseTxicj4NCiZndDsg
YWJvdXQgd2hldGhlciB3ZSBzaG91bGQgcmVwcmVzZW50IG9uIHRoaXMgc2VxdWVuY2UgZGlhZ3Jh
bSB0aGF0PGJyPg0KJmd0OyBpbmZvcm1hdGlvbiBzdXBwb3J0aW5nIGEganVkZ2VtZW50IG9mICZx
dW90O3N0YWxlJnF1b3Q7IHdvdWxkIGJlIG5lZWRlZC48YnI+DQomZ3Q7PGJyPg0KJmd0OyBXZSBs
ZWZ0IG9wZW4gdGhlIHRpbWUgd2hlbiB3ZSB3b3VsZCBuZXh0IG1lZXQsIGZhdm9yaW5nIHRvIHdv
cmsgdGhhdCBvdXQ8YnI+DQomZ3Q7IG9uLWxpc3QuJm5ic3A7IE5leHQgd2VlayBpcyBUQ0csIHNv
IHRoYXQgbWF5IGJlIGRpZmZpY3VsdDsgdGhlIGZvbGxvd2luZyB3ZWVrPGJyPg0KJmd0OyBpcyBS
U0EsIHNvIHRoYXQgbWF5IGJlIGRpZmZpY3VsdC48YnI+DQomZ3Q7PGJyPg0KJmd0OyBGb3IgdGhv
c2Ugd2hvIHdlcmUgaW4gYXR0ZW5kYW5jZSB0b2RheSwgcGxlYXNlIGFkZCB0byB0aGlzIG5vdGUg
d2l0aDxicj4NCiZndDsgeW91ciBjb21tZW50cy9jb3JyZWN0aW9ucy48YnI+DQomZ3Q7PGJyPg0K
Jmd0OyBLaW5kIHJlZ2FyZHMsPGJyPg0KJmd0Ozxicj4NCiZndDsgQWRhbTxicj4NCiZndDs8YnI+
DQomZ3Q7IFsxXSA8YSBocmVmPSJodHRwczovL2RyaXZlLmdvb2dsZS5jb20vb3Blbj9pZD0wQjhX
ZjlVbjVGZENiV0doRE9IcFZSMHRNZDFFIiB0YXJnZXQ9Il9ibGFuayI+DQpodHRwczovL2RyaXZl
Lmdvb2dsZS5jb20vb3Blbj9pZD0wQjhXZjlVbjVGZENiV0doRE9IcFZSMHRNZDFFPC9hPjxicj4N
CiZndDs8YnI+DQomZ3Q7IE9uIE1vbiwgSmFuIDMwLCAyMDE3IGF0IDExOjIxIEFNIEFkYW0gTW9u
dHZpbGxlPGJyPg0KJmd0OyAmbHQ7PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21h
aWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+ICZs
dDttYWlsdG86PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tIiB0YXJn
ZXQ9Il9ibGFuayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+Jmd0OyZndDsgd3JvdGU6
PGJyPg0KJmd0Ozxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO0hpIGV2ZXJ5b25lLiZuYnNw
OyBKdXN0IGEgZnJpZW5kbHkgcmVtaW5kZXIgdGhhdCB3ZSBhcmUgcGxhbm5pbmcgdG8gbWVldDxi
cj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO2FnYWluIHRoaXMgVGh1cnNkYXkgYXQgdGhlIHNh
bWUgdGltZSAoMi8yIEAgMTBhbSBFYXN0ZXJuLzNwbSBVVEMpPGJyPg0KJmd0OyZuYnNwOyAmbmJz
cDsgJm5ic3A7dXNpbmcgU0FDTSdzIG1lZXRpbmcgcm9vbSBhdCA8YSBocmVmPSJodHRwczovL2ll
dGYud2ViZXguY29tL21lZXQvc2FjbSIgdGFyZ2V0PSJfYmxhbmsiPg0KaHR0cHM6Ly9pZXRmLndl
YmV4LmNvbS9tZWV0L3NhY208L2E+Ljxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAm
bmJzcDtLaW5kIHJlZ2FyZHMsPGJyPg0KJmd0Ozxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNw
O0FkYW08YnI+DQomZ3Q7PGJyPg0KJmd0Ozxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO09u
IFRodSwgSmFuIDE5LCAyMDE3IGF0IDExOjM1IEFNIEFkYW0gTW9udHZpbGxlPGJyPg0KJmd0OyZu
YnNwOyAmbmJzcDsgJm5ic3A7Jmx0OzxhIGhyZWY9Im1haWx0bzphZGFtLncubW9udHZpbGxlQGdt
YWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPC9hPiAm
bHQ7bWFpbHRvOjxhIGhyZWY9Im1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbSIgdGFy
Z2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPC9hPiZndDsmZ3Q7IHdyb3Rl
Ojxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0hl
bGxvLiBBIGZldyBvZiB1cyBtZXQgaW5mb3JtYWxseSB0b2RheSB0byBkaXNjdXNzIHRoZTxicj4N
CiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7dnVsbmVyYWJpbGl0eSBzY2Vu
YXJpbyBpbiBzb21lIG1vcmUgZGV0YWlsIHdpdGggdGhlIGdvYWwgb2Y8YnI+DQomZ3Q7Jm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO21haW50YWluaW5nIHRoZSBuYXJyb3cgZm9jdXMg
b24gYSB2dWxuZXJhYmlsaXR5IGFzc2Vzc21lbnQgc2xpY2U8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwO3Rocm91Z2ggb3VyIG5vdGlvbmFsIGVudmlyb25tZW50LiZu
YnNwOyBXZSBhcmUgdGVuZGluZyB0byBsb29rIGF0PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDttYWpvciBjb21wb25lbnRzIGFzIGJsYWNrIGJveGVzIHdpdGggaW50
ZXJmYWNlcyBhbmQgZGF0YSBmb3JtYXQ8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwO2V4cGVjdGF0aW9ucywgYW5kIHdlIGFyZSBub3QgbmVjZXNzYXJpbHkgY29uY2Vy
bmVkIHdpdGggaG93PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDt0
aG9zZSBjb21wb25lbnRzIGRvIHRoaW5ncyBpbnRlcm5hbGx5L2JlaGluZCB0aGUgc2NlbmVzLjxi
cj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1RoZSBt
ZWV0aW5nIHdhcyByZWNvcmRlZCAoeW91IGNhbiBmaW5kIGl0IHdpdGggdG9kYXkncyBkYXRlIGF0
PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtbMV0pLiZuYnNwOyBU
aGUgdG9waWMgb2YgZGlzY3Vzc2lvbiB3YXMgcHJpbWFyaWx5IGluIHRoZSAmcXVvdDtwaGFzZSAx
JnF1b3Q7PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDthcmVhIG9m
IHdoYXQgRGFubnkgc2VudCB0byB0aGUgbGlzdCBub3QgdmVyeSBsb25nIGFnbyBbMl0sIGFuZDxi
cj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7cmVzdWx0ZWQgaW4gYSAq
c3RhcnRpbmcgcG9pbnQqIGRpYWdyYW0gWzNdLjxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZu
YnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1RoZSBncm91cCB3aG8gbWV0IHRvZGF5IGFyZSAocm91
Z2hseSkgYWdyZWVkIG9uIHRoZSBzaXggbWFpbjxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7JnF1b3Q7Y29tcG9uZW50cyZxdW90OyByZXByZXNlbnRlZCBpbiB0aGF0
IGRpYWdyYW0sIGJ1dCBhbHNvIHNlZSB0aGF0IHdlPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDtoYXZlIHNvbWUgd29yayBhaGVhZC4mbmJzcDsgU3BlY2lmaWNhbGx5
LCB3ZSBxdWlja2x5IHJlY29nbml6ZWQgdGhhdDxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7c29tZSBvZiB0aGUgYXNzdW1wdGlvbnMgdGhlIHZ1bG5lcmFiaWxpdHkg
ZHJhZnQgbWFrZXMgbWF5IGJlPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDthc3N1bXB0aW9ucyB3ZSBjYW5ub3QgYWZmb3JkIHRvIG1ha2UgYW5kIG5lZWQgdG8gaW5j
bHVkZSBpbiB0aGU8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO2V4
cGxvcmF0aW9uLjxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwO1dlIHRob3VnaHQgaXQgd291bGQgYmUgYSBnb29kIGlkZWEgdG8gaGF2ZSBhbm90aGVy
IGluZm9ybWFsPGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtkaXNj
dXNzaW9uIGluIGEgY291cGxlIG9mIHdlZWtzIChGZWJydWFyeSAyKSBhdCB0aGUgc2FtZSB0aW1l
PGJyPg0KJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsoMTBhbSBFYXN0ZXJu
IC8gM3BtIFVUQyksIHVzaW5nIHRoZSBzYW1lIFdlYkV4IFs0XS4mbmJzcDsgJm5ic3A7QXQgdGhh
dDxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7dGltZSB3ZSBpbnRl
bmQgdG8gcm9sbCB0aHJvdWdoIHRoZSB2dWxuZXJhYmlsaXR5IGFzc2Vzc21lbnQ8YnI+DQomZ3Q7
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3NjZW5hcmlvIGFzc3VtcHRpb25zIGlu
IGFuIGVmZm9ydCB0byBkZXRlcm1pbmUgd2hpY2ggb25lcyBjYW4gYmU8YnI+DQomZ3Q7Jm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO2xlZnQgYXMgYXNzdW1wdGlvbnMgYW5kIHdoaWNo
IG9uZXMgY2Fubm90LiZuYnNwOyBUaGVuIHdlJ2xsIHRha2U8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwO2Fub3RoZXIgbG9vayBhdCB0aGUgZGlhZ3JhbSBhbmQgd29y
ayBvbiBpdHMgbmV4dCB2ZXJzaW9uLjxicj4NCiZndDs8YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwO1N0YXkgdHVuZWQuPGJyPg0KJmd0Ozxicj4NCiZndDsmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7VGhhbmtzIHRvIERhbm55LCBTdGVwaGVuLCBhbmQg
SmVyb21lIGZvciBqb2luaW5nIGFuZCBjb250cmlidXRpbmchPGJyPg0KJmd0Ozxicj4NCiZndDsm
bmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7S2luZCByZWdhcmRzLDxicj4NCiZndDs8
YnI+DQomZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0FkYW08YnI+DQomZ3Q7
PGJyPg0KJmd0Ozxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7WzFd
IDxhIGhyZWY9Imh0dHBzOi8vZHJpdmUuZ29vZ2xlLmNvbS9vcGVuP2lkPTBCOFdmOVVuNUZkQ2JX
R2hET0hwVlIwdE1kMUUiIHRhcmdldD0iX2JsYW5rIj4NCmh0dHBzOi8vZHJpdmUuZ29vZ2xlLmNv
bS9vcGVuP2lkPTBCOFdmOVVuNUZkQ2JXR2hET0hwVlIwdE1kMUU8L2E+PGJyPg0KJmd0OyZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtbMl0gPGEgaHJlZj0iaHR0cHM6Ly9tYWlsYXJj
aGl2ZS5pZXRmLm9yZy9hcmNoL21zZy9zYWNtL19MaUtseXZBd3NfT1ZMRmhCNU5TVTU4TVhETSIg
dGFyZ2V0PSJfYmxhbmsiPg0KaHR0cHM6Ly9tYWlsYXJjaGl2ZS5pZXRmLm9yZy9hcmNoL21zZy9z
YWNtL19MaUtseXZBd3NfT1ZMRmhCNU5TVTU4TVhETTwvYT48YnI+DQomZ3Q7Jm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwO1szXSA8YSBocmVmPSJodHRwczovL2RyaXZlLmdvb2dsZS5j
b20vb3Blbj9pZD0wQjhXZjlVbjVGZENiTVU1cGRUUmplakp0TkhjIiB0YXJnZXQ9Il9ibGFuayI+
DQpodHRwczovL2RyaXZlLmdvb2dsZS5jb20vb3Blbj9pZD0wQjhXZjlVbjVGZENiTVU1cGRUUmpl
akp0TkhjPC9hPjxicj4NCiZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7WzRd
IDxhIGhyZWY9Imh0dHBzOi8vaWV0Zi53ZWJleC5jb20vbWVldC9zYWNtIiB0YXJnZXQ9Il9ibGFu
ayI+aHR0cHM6Ly9pZXRmLndlYmV4LmNvbS9tZWV0L3NhY208L2E+PGJyPg0KJmd0Ozxicj4NCiZn
dDs8YnI+DQomZ3Q7PGJyPg0KJmd0OyBfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fXzxicj4NCiZndDsgc2FjbSBtYWlsaW5nIGxpc3Q8YnI+DQomZ3Q7IDxhIGhy
ZWY9Im1haWx0bzpzYWNtQGlldGYub3JnIiB0YXJnZXQ9Il9ibGFuayI+c2FjbUBpZXRmLm9yZzwv
YT48YnI+DQomZ3Q7IDxhIGhyZWY9Imh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGlu
Zm8vc2FjbSIgdGFyZ2V0PSJfYmxhbmsiPmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlz
dGluZm8vc2FjbTwvYT48YnI+DQomZ3Q7PG86cD48L286cD48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8
L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxl
PSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttYXJnaW4tYm90dG9tOjEyLjBwdCI+PGJyPg0KX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX188YnI+DQpzYWNtIG1h
aWxpbmcgbGlzdDxicj4NCjxhIGhyZWY9Im1haWx0bzpzYWNtQGlldGYub3JnIiB0YXJnZXQ9Il9i
bGFuayI+c2FjbUBpZXRmLm9yZzwvYT48YnI+DQo8YSBocmVmPSJodHRwczovL3d3dy5pZXRmLm9y
Zy9tYWlsbWFuL2xpc3RpbmZvL3NhY20iIHRhcmdldD0iX2JsYW5rIj5odHRwczovL3d3dy5pZXRm
Lm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY208L2E+PG86cD48L286cD48L3A+DQo8L2Jsb2NrcXVv
dGU+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1h
bHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+Jm5ic3A7PG86cD48L286cD48L3A+
DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90ZT4NCjwvZGl2Pg0K
PC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_BN6PR09MB14586B8180578BD1857D406EA54F0BN6PR09MB1458namp_--


From nobody Fri Feb  3 13:25:18 2017
Return-Path: <henk.birkholz@sit.fraunhofer.de>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ADE751294C8 for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 13:25:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.098
X-Spam-Level: 
X-Spam-Status: No, score=-10.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-3.199, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZtaIzf_Uz4Ig for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 13:25:14 -0800 (PST)
Received: from mailext.sit.fraunhofer.de (mailext.sit.fraunhofer.de [141.12.72.89]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 19CB612955F for <sacm@ietf.org>; Fri,  3 Feb 2017 13:25:12 -0800 (PST)
Received: from mail.sit.fraunhofer.de (mail.sit.fraunhofer.de [141.12.84.171]) by mailext.sit.fraunhofer.de (8.14.4/8.14.4/Debian-2ubuntu2.1) with ESMTP id v13LP8Oo028784 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 3 Feb 2017 22:25:09 +0100
Received: from [192.168.16.50] (134.102.43.163) by mail.sit.fraunhofer.de (141.12.84.171) with Microsoft SMTP Server (TLS) id 14.3.319.2; Fri, 3 Feb 2017 22:25:02 +0100
To: Adam Montville <adam.w.montville@gmail.com>, "sacm@ietf.org" <sacm@ietf.org>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com> <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com>
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Message-ID: <147f77a8-ea0f-ed43-f585-a70a231110fe@sit.fraunhofer.de>
Date: Fri, 3 Feb 2017 22:25:01 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com>
Content-Type: text/plain; charset="windows-1252"; format=flowed
Content-Transfer-Encoding: 7bit
X-Originating-IP: [134.102.43.163]
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/BQBymkP5J39nThi-pd0ioFKU8Y8>
Subject: Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 21:25:17 -0000

Hi group,

to recap my understanding:

There will be trigger conditions that initiate collections of fresh 
endpoint attributes (from which endpoint posture can be derived) from a 
target endpoint.

The obvious trigger condition that an asserting component (in every 
diagram, I think, that is the Vulnerability Assessor. This assumption is 
based on the interpretation of the diagram, not based on the name of the 
component). From my point of view, in order to assert that a known 
record is, for example, "stale" (aka does not satisfy an declarative 
guidance that expresses the quality of freshness) or, as another 
example, is not yet created the Vulnerability Assessor requires an 
always up-to-date and exhaustive list of all Assessment Result records.

In consequence, I would assume that either the the Assessment Result 
Repository component collapses with the Vulnerability Assessor or the 
Vulnerability Assessor always retains a complete in-sync copy of the 
Assessment Result Repository.

Alternatively, the Assessment Result Repository component is collapsed 
with the Endpoint Repository (as proposed in diagram v3), in which case 
now the Vulnerability Assessor to retain an continuously in-sync copy of 
the Endpoint Repository? If it is to trigger on the "stale" condition?

The "keeping pools of data in-sync" seems to be introducing extra steps 
in the work-flow.

A pro for this would be that there could be multiple additional 
consumers of Assessment Results that justify an interface that provides 
that data to multiple parties.

A con for this is the universal "redundant data stores always pose a 
source of complexity and hence risk of inconsistency" argument.

Another point of view could be that the "evaluation task" is independent 
from the "trigger collection" (I just made that one up) task? Or maybe 
it is associated with the worn component?

Multiple emerging architectures include an orchestration component that 
consumes notification of changes and derives appropriate actions that it 
can trigger or even conduct. Please note, I am not advocating to 
introduce yet another component type (which would again add complexity, 
error, scope creep...) :)

I just try to get a feasible grasp of the actual workflow that the 
diagram is intended to represent.

What am I missing? I actually am surprised that the Assessment Result 
Repository merges with the Endpoint Repository and not the Vulnerability 
Assessor. What is the advantage?

Best,

Henk

On 02/03/2017 05:43 PM, Adam Montville wrote:
> I thought I'd try to break this discussion out of it's former thread
> into one of its own, in case that makes it easier for folks to opine.
> The list of "components" or "function groups" seems reasonable to me.
> In practice, there *may* be a desire to have that software acting as an
> endpoint repository also act as the repository for assessment results.
> Or, these could be implemented in distinct services.
>
> What works for our purposes?
>
> Adam
>
> On Thu, Feb 2, 2017 at 10:40 AM Adam Montville
> <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote:
>
>     Once folks have had an opportunity to review the vulnerability
>     scenario information we've been working on, what are your thoughts
>     on the main components we're presently focused on for this narrowly
>     scoped exercise?  These are:
>
>     Vulnerability Detection Data Repository
>     Vulnerability Assessor
>     Endpoint Repository
>     Collector
>     Assessment Result Repository
>     Endpoint
>
>
>
>
>     On Thu, Feb 2, 2017 at 10:28 AM Adam Montville
>     <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>> wrote:
>
>         Hi Everyone.  A few of us were able to make the vulnerability
>         scenario call today and I think we had a good, though at times
>         spirited, discussion.  We did record the meeting, which is
>         available at [1].  We discussed the attached (annotated with
>         some meeting notes) UML-ish sequence diagram.  I had created
>         that diagram to start a conversation (mission accomplished on
>         that front I think) -- a conversation that would lead us toward
>         identifying the discrete components, interfaces, and information
>         required to be sent over those interfaces.  The UML-ish diagram
>         represents a *single* flow through the system -- a "one-time"
>         flow through the system.  It ignores, for the time being, the
>         continuous aspect of our charter in favor of getting started
>         with the basics.  Once we have a good understanding of the
>         basics -- the components, interfaces, and information required
>         -- we can start look at a continuous monitoring sequence (which
>         could be represented as a distinct diagram) to determine what
>         more we need.  Then, I think, we can start drafting solutions.
>
>         One of the first issues is that we need to figure out if the
>         components in the base flow are accurate.  The main suggestion
>         we've tossed around so far is to combine the Endpoint Repository
>         with the Assessment Result Repository.
>
>         We talked briefly about what interface we could use for the VDD
>         Repository, and naturally ROLIE came up as an option.
>
>         We talked a little bit about the first "get endpoints" operation
>         between the Vulnerability Assessor and the Endpoint Repository
>         -- specifically about whether we should represent on this
>         sequence diagram that information supporting a judgement of
>         "stale" would be needed.
>
>         We left open the time when we would next meet, favoring to work
>         that out on-list.  Next week is TCG, so that may be difficult;
>         the following week is RSA, so that may be difficult.
>
>         For those who were in attendance today, please add to this note
>         with your comments/corrections.
>
>         Kind regards,
>
>         Adam
>
>         [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>
>         On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>         <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>>
>         wrote:
>
>             Hi everyone.  Just a friendly reminder that we are planning
>             to meet again this Thursday at the same time (2/2 @ 10am
>             Eastern/3pm UTC) using SACM's meeting room at
>             https://ietf.webex.com/meet/sacm.
>
>             Kind regards,
>
>             Adam
>
>
>             On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>             <adam.w.montville@gmail.com
>             <mailto:adam.w.montville@gmail.com>> wrote:
>
>                 Hello. A few of us met informally today to discuss the
>                 vulnerability scenario in some more detail with the goal
>                 of maintaining the narrow focus on a vulnerability
>                 assessment slice through our notional environment.  We
>                 are tending to look at major components as black boxes
>                 with interfaces and data format expectations, and we are
>                 not necessarily concerned with how those components do
>                 things internally/behind the scenes.
>
>                 The meeting was recorded (you can find it with today's
>                 date at [1]).  The topic of discussion was primarily in
>                 the "phase 1" area of what Danny sent to the list not
>                 very long ago [2], and resulted in a *starting point*
>                 diagram [3].
>
>                 The group who met today are (roughly) agreed on the six
>                 main "components" represented in that diagram, but also
>                 see that we have some work ahead.  Specifically, we
>                 quickly recognized that some of the assumptions the
>                 vulnerability draft makes may be assumptions we cannot
>                 afford to make and need to include in the exploration.
>
>                 We thought it would be a good idea to have another
>                 informal discussion in a couple of weeks (February 2) at
>                 the same time (10am Eastern / 3pm UTC), using the same
>                 WebEx [4].   At that time we intend to roll through the
>                 vulnerability assessment scenario assumptions in an
>                 effort to determine which ones can be left as
>                 assumptions and which ones cannot.  Then we'll take
>                 another look at the diagram and work on its next version.
>
>                 Stay tuned.
>
>                 Thanks to Danny, Stephen, and Jerome for joining and
>                 contributing!
>
>                 Kind regards,
>
>                 Adam
>
>
>                 [1] https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>                 [2] https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
>                 [3] https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>                 [4] https://ietf.webex.com/meet/sacm
>
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>


From nobody Fri Feb  3 14:20:03 2017
Return-Path: <henk.birkholz@sit.fraunhofer.de>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF879129A52 for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 14:20:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.098
X-Spam-Level: 
X-Spam-Status: No, score=-10.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-3.199, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id soD-ucc13q_k for <sacm@ietfa.amsl.com>; Fri,  3 Feb 2017 14:19:58 -0800 (PST)
Received: from mailext.sit.fraunhofer.de (mailext.sit.fraunhofer.de [141.12.72.89]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A6DFD129A47 for <sacm@ietf.org>; Fri,  3 Feb 2017 14:19:56 -0800 (PST)
Received: from mail.sit.fraunhofer.de (mail.sit.fraunhofer.de [141.12.84.171]) by mailext.sit.fraunhofer.de (8.14.4/8.14.4/Debian-2ubuntu2.1) with ESMTP id v13MJpoH030826 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 3 Feb 2017 23:19:52 +0100
Received: from [192.168.16.50] (134.102.43.163) by mail.sit.fraunhofer.de (141.12.84.171) with Microsoft SMTP Server (TLS) id 14.3.319.2; Fri, 3 Feb 2017 23:19:45 +0100
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
To: Adam Montville <adam.w.montville@gmail.com>, "<sacm@ietf.org>" <sacm@ietf.org>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com> <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com> <147f77a8-ea0f-ed43-f585-a70a231110fe@sit.fraunhofer.de> <CACknUNXx=F6DatwikXgs4NGFgbbQMnMPCiGfX4UKfYLh67RUog@mail.gmail.com>
Message-ID: <cc9e09ec-05fc-1af2-9f9b-50cf3ef16fd1@sit.fraunhofer.de>
Date: Fri, 3 Feb 2017 23:19:45 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <CACknUNXx=F6DatwikXgs4NGFgbbQMnMPCiGfX4UKfYLh67RUog@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"; format=flowed
Content-Transfer-Encoding: 7bit
X-Originating-IP: [134.102.43.163]
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/fWwnVx39mnd46gZ5Dt16G1VqOB0>
Subject: Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 22:20:01 -0000

Also inline. I hope it is still readable.

On 02/03/2017 10:55 PM, Adam Montville wrote:
> Thanks for chiming in Henk.  I'll go inline.  Nothing being said as
> chair.  Just making observations.
>
> On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz
> <henk.birkholz@sit.fraunhofer.de
> <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
>
>     Hi group,
>
>     to recap my understanding:
>
>     There will be trigger conditions that initiate collections of fresh
>     endpoint attributes (from which endpoint posture can be derived) from a
>     target endpoint.
>
>     The obvious trigger condition that an asserting component (in every
>     diagram, I think, that is the Vulnerability Assessor. This assumption is
>     based on the interpretation of the diagram, not based on the name of the
>     component). From my point of view, in order to assert that a known
>     record is, for example, "stale" (aka does not satisfy an declarative
>     guidance that expresses the quality of freshness) or, as another
>     example, is not yet created the Vulnerability Assessor requires an
>     always up-to-date and exhaustive list of all Assessment Result records.
>
>
> I would disagree.  I have a record from the endpoint repository that it
> timestamped as 3 days old.  My policy says I should not rely on anything
> older than 2 days old.  Then the information is stale, and I instruct to
> collect anew.

If the "I" is the Vulnerability Assessor, how does it always have the 
Assessment Result records to check that declarative guidance? Or do you 
propose (in v3) that the Endpoint Repository is checking that freshness 
continuously and notifying the Vulnerability Assessor?

>
>
>
>     In consequence, I would assume that either the the Assessment Result
>     Repository component collapses with the Vulnerability Assessor or the
>     Vulnerability Assessor always retains a complete in-sync copy of the
>     Assessment Result Repository.
>
>
> I would again disagree.  It may well be that actual software collapses
> these components into one, but it may be that there is a results
> repository, which is used downstream from vulnerability assessment, into
> which the assessor dumps results.

Yes, downstream records are dumped as a result in the corresponding 
repo. But how does the information of not satisfying declarative 
guidance (a result got stale) makes it "upstream" again to trigger 
collection - including imperative guidance what to collect (what just 
got stale)?

>
> Consider when we have configuration assessment down the road.  Would we
> then have a vulnerability assessor and a configuration assessor each
> with their own repository conceptually, or would we be better off with
> one "results repository"?  I think the one.

It depends on scalability, I guess, but in the bare-bone first proof of 
concept it seems to be feasible to collapse related pools of data into 
justthe one, as there are no multiple consumers?


>
> In practice, applications can choose to implement more than one
> conceptual component.

Yes, that is why it is not a problem to collapse sets of functions into 
a single component, in general. I hope this will remain a core feature 
of the architecture at all time.

>
>
>
>     Alternatively, the Assessment Result Repository component is collapsed
>     with the Endpoint Repository (as proposed in diagram v3), in which case
>     now the Vulnerability Assessor to retain an continuously in-sync copy of
>     the Endpoint Repository? If it is to trigger on the "stale" condition?
>
>
> Again, I am not necessarily in favor of this viewpoint (and I'm not
> necessarily against).  The endpoint repository represents an interface
> to acquire information about endpoints, which does not necessarily need
> to include assessment results pertaining to those endpoints entirely.

But isn't that what is depicted in the diagram v3: the assessment 
results repo is merged with endpoint repo? Maybe I am actually a little 
bit dense right now :)

>
>
>
>
>     The "keeping pools of data in-sync" seems to be introducing extra steps
>     in the work-flow.
>
>
> Is it really data in sync?  I understand what you're saying, but to me
> the endpoint repository component is where we find assertions about the
> endpoints, the assessors take those assertions and apply some logic to
> pass judgement on the endpoint, and that judgement is stored in the
> assessment results repository component.

I simply did not assume that a repository is more than a data store. If 
it does continuous assessments of endpoint records it contains, it most 
certainly can trigger a collection. Maybe the label of the component is 
just misleading me here.

>
>
>
>     A pro for this would be that there could be multiple additional
>     consumers of Assessment Results that justify an interface that provides
>     that data to multiple parties.
>
>
> Yes!  There are in practice.  Assessment results have downstream uses
> outside the scope of our charter.

I thought so, but it is of course not part of the single snapshot 
diagram and is therefore only implied at best.

>
>
>
>     A con for this is the universal "redundant data stores always pose a
>     source of complexity and hence risk of inconsistency" argument.
>
>     Another point of view could be that the "evaluation task" is independent
>     from the "trigger collection" (I just made that one up) task? Or maybe
>     it is associated with the worn component?
>
>     Multiple emerging architectures include an orchestration component that
>     consumes notification of changes and derives appropriate actions that it
>     can trigger or even conduct. Please note, I am not advocating to
>     introduce yet another component type (which would again add complexity,
>     error, scope creep...) :)
>
>
> Bill mentioned something to me offline yesterday about orchestration.
> In the vulnerability scenario, the orchestration is really being
> performed by the assessor.

I think that in the reply above you illustrated that the Endpoint Repo 
also does this assessment by checking for staleness? Or would it "just" 
notify the Assessor to trigger a task? Why not trigger the collector 
directly? What about the imperative guidance what to actually collect again?

It seems that I really have a difficult time to wrap my head around the 
proposal still. Please stay patient with me! :)

>
>
>
>     I just try to get a feasible grasp of the actual workflow that the
>     diagram is intended to represent.
>
>
> The most basic path through the system.
>
>
>
>     What am I missing? I actually am surprised that the Assessment Result
>     Repository merges with the Endpoint Repository and not the Vulnerability
>     Assessor. What is the advantage?
>
>
> I think we're still talking this one through.  What's the advantage to
> collapsing them at all?

Collapsing redundant pools of data is reducing redundancy :) Tasks that 
depend on data that has to be acquired to be conducted benefit from high 
availability and low latency. But I totally understand the "multiple 
consumer" argument.

>
>
>
>     Best,
>
>     Henk
>
>     On 02/03/2017 05:43 PM, Adam Montville wrote:
>     > I thought I'd try to break this discussion out of it's former thread
>     > into one of its own, in case that makes it easier for folks to opine.
>     > The list of "components" or "function groups" seems reasonable to me.
>     > In practice, there *may* be a desire to have that software acting
>     as an
>     > endpoint repository also act as the repository for assessment results.
>     > Or, these could be implemented in distinct services.
>     >
>     > What works for our purposes?
>     >
>     > Adam
>     >
>     > On Thu, Feb 2, 2017 at 10:40 AM Adam Montville
>     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >     Once folks have had an opportunity to review the vulnerability
>     >     scenario information we've been working on, what are your thoughts
>     >     on the main components we're presently focused on for this
>     narrowly
>     >     scoped exercise?  These are:
>     >
>     >     Vulnerability Detection Data Repository
>     >     Vulnerability Assessor
>     >     Endpoint Repository
>     >     Collector
>     >     Assessment Result Repository
>     >     Endpoint
>     >
>     >
>     >
>     >
>     >     On Thu, Feb 2, 2017 at 10:28 AM Adam Montville
>     >     <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >         Hi Everyone.  A few of us were able to make the vulnerability
>     >         scenario call today and I think we had a good, though at times
>     >         spirited, discussion.  We did record the meeting, which is
>     >         available at [1].  We discussed the attached (annotated with
>     >         some meeting notes) UML-ish sequence diagram.  I had created
>     >         that diagram to start a conversation (mission accomplished on
>     >         that front I think) -- a conversation that would lead us
>     toward
>     >         identifying the discrete components, interfaces, and
>     information
>     >         required to be sent over those interfaces.  The UML-ish
>     diagram
>     >         represents a *single* flow through the system -- a "one-time"
>     >         flow through the system.  It ignores, for the time being, the
>     >         continuous aspect of our charter in favor of getting started
>     >         with the basics.  Once we have a good understanding of the
>     >         basics -- the components, interfaces, and information required
>     >         -- we can start look at a continuous monitoring sequence
>     (which
>     >         could be represented as a distinct diagram) to determine what
>     >         more we need.  Then, I think, we can start drafting solutions.
>     >
>     >         One of the first issues is that we need to figure out if the
>     >         components in the base flow are accurate.  The main suggestion
>     >         we've tossed around so far is to combine the Endpoint
>     Repository
>     >         with the Assessment Result Repository.
>     >
>     >         We talked briefly about what interface we could use for
>     the VDD
>     >         Repository, and naturally ROLIE came up as an option.
>     >
>     >         We talked a little bit about the first "get endpoints"
>     operation
>     >         between the Vulnerability Assessor and the Endpoint Repository
>     >         -- specifically about whether we should represent on this
>     >         sequence diagram that information supporting a judgement of
>     >         "stale" would be needed.
>     >
>     >         We left open the time when we would next meet, favoring to
>     work
>     >         that out on-list.  Next week is TCG, so that may be difficult;
>     >         the following week is RSA, so that may be difficult.
>     >
>     >         For those who were in attendance today, please add to this
>     note
>     >         with your comments/corrections.
>     >
>     >         Kind regards,
>     >
>     >         Adam
>     >
>     >         [1]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >
>     >         On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>     >         <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>>>
>     >         wrote:
>     >
>     >             Hi everyone.  Just a friendly reminder that we are
>     planning
>     >             to meet again this Thursday at the same time (2/2 @ 10am
>     >             Eastern/3pm UTC) using SACM's meeting room at
>     >             https://ietf.webex.com/meet/sacm.
>     >
>     >             Kind regards,
>     >
>     >             Adam
>     >
>     >
>     >             On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>     >             <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     >             <mailto:adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >                 Hello. A few of us met informally today to discuss the
>     >                 vulnerability scenario in some more detail with
>     the goal
>     >                 of maintaining the narrow focus on a vulnerability
>     >                 assessment slice through our notional environment.  We
>     >                 are tending to look at major components as black boxes
>     >                 with interfaces and data format expectations, and
>     we are
>     >                 not necessarily concerned with how those components do
>     >                 things internally/behind the scenes.
>     >
>     >                 The meeting was recorded (you can find it with today's
>     >                 date at [1]).  The topic of discussion was
>     primarily in
>     >                 the "phase 1" area of what Danny sent to the list not
>     >                 very long ago [2], and resulted in a *starting point*
>     >                 diagram [3].
>     >
>     >                 The group who met today are (roughly) agreed on
>     the six
>     >                 main "components" represented in that diagram, but
>     also
>     >                 see that we have some work ahead.  Specifically, we
>     >                 quickly recognized that some of the assumptions the
>     >                 vulnerability draft makes may be assumptions we cannot
>     >                 afford to make and need to include in the exploration.
>     >
>     >                 We thought it would be a good idea to have another
>     >                 informal discussion in a couple of weeks (February
>     2) at
>     >                 the same time (10am Eastern / 3pm UTC), using the same
>     >                 WebEx [4].   At that time we intend to roll
>     through the
>     >                 vulnerability assessment scenario assumptions in an
>     >                 effort to determine which ones can be left as
>     >                 assumptions and which ones cannot.  Then we'll take
>     >                 another look at the diagram and work on its next
>     version.
>     >
>     >                 Stay tuned.
>     >
>     >                 Thanks to Danny, Stephen, and Jerome for joining and
>     >                 contributing!
>     >
>     >                 Kind regards,
>     >
>     >                 Adam
>     >
>     >
>     >                 [1]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >                 [2]
>     https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
>     >                 [3]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>     >                 [4] https://ietf.webex.com/meet/sacm
>     >
>     >
>     >
>     > _______________________________________________
>     > sacm mailing list
>     > sacm@ietf.org <mailto:sacm@ietf.org>
>     > https://www.ietf.org/mailman/listinfo/sacm
>     >
>


From nobody Mon Feb  6 06:17:34 2017
Return-Path: <bill.munyan.ietf@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B1DF129DA4 for <sacm@ietfa.amsl.com>; Mon,  6 Feb 2017 06:17:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.699
X-Spam-Level: 
X-Spam-Status: No, score=-1.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tDdS37pSAZBw for <sacm@ietfa.amsl.com>; Mon,  6 Feb 2017 06:17:30 -0800 (PST)
Received: from mail-wm0-x22a.google.com (mail-wm0-x22a.google.com [IPv6:2a00:1450:400c:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 91D4E129DA3 for <sacm@ietf.org>; Mon,  6 Feb 2017 06:17:29 -0800 (PST)
Received: by mail-wm0-x22a.google.com with SMTP id r141so115851591wmg.1 for <sacm@ietf.org>; Mon, 06 Feb 2017 06:17:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=S56OCSb79dldGQQ4B5NJvOWYmA4Nq7xRGt/Ve3XJu1o=; b=j6QwDOoQ/wMdkg3DOWId/F/O5fjqOenoArIHvXPW2tOyOvVLkk1mmNC6QL/vYqQ53i 1ac4SYWwz4sppCzUQcdJ6AfD2f5YFGYv9MPMPM5A1ADSZKqtJY5tKw7rbOCz+L0egedx PKPWxYlRNokJW7UzW37xWiBYWfuDF1mEIyfubAmqwycLA3Fhv9hR31o+FXAY2Z5WprKl /ebsLYTXI6p0DjJLvlT/OdOp7Np2BOkh6jmbHYf53mEWWfhPOxBplDXZnZNkj1RLKOPe qFW24rh3hDY5ebSU2y98dnBuKrfF41xlqmCxkg43b1BmvF8okzK82F86PDscoUZqHrsE pUcg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=S56OCSb79dldGQQ4B5NJvOWYmA4Nq7xRGt/Ve3XJu1o=; b=esQiaGy5JVha/6FhxmnarRBGy5hjH/QqBiJYgcgxbyQuf07Bg06CyE/fc0bMbGEtBn 3V1+9hugbQbJ3R5HsvR4vESZS4nRsR+Rtxdu/qZ18rsqLB9REAq3kqFypQBxf3EjkDC7 2ffHcz81Ffep7ytP8uXAmcm73b+Z536omF2vaHLBRBfjnPvmevqKG0+Kw84paUtCO4zZ cBnGvVEvOo19l+ZA4ITWwVP/mMxL7XQ7DKMOeauskqIaiRrsIwbiwVXBmHyCS/uQW6+r rGQLp81qSAHRvVGq3gvCKEHVueXHOsxBLFTEhlR8wPfNJYKC0DYsBGDDYzm60lm/Xl7H yc8w==
X-Gm-Message-State: AIkVDXLR20WSZSe/yz26cbe4G6xJyu0tZEWI87U+OW5Jpdfd0h5TOpkf4mLUKPHKdENYH6RSNXbAmmAKtFrXAA==
X-Received: by 10.223.136.206 with SMTP id g14mr9081074wrg.52.1486390647314; Mon, 06 Feb 2017 06:17:27 -0800 (PST)
MIME-Version: 1.0
Received: by 10.223.140.138 with HTTP; Mon, 6 Feb 2017 06:17:26 -0800 (PST)
In-Reply-To: <cc9e09ec-05fc-1af2-9f9b-50cf3ef16fd1@sit.fraunhofer.de>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com> <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com> <147f77a8-ea0f-ed43-f585-a70a231110fe@sit.fraunhofer.de> <CACknUNXx=F6DatwikXgs4NGFgbbQMnMPCiGfX4UKfYLh67RUog@mail.gmail.com> <cc9e09ec-05fc-1af2-9f9b-50cf3ef16fd1@sit.fraunhofer.de>
From: Bill Munyan <bill.munyan.ietf@gmail.com>
Date: Mon, 6 Feb 2017 09:17:26 -0500
Message-ID: <CAKUOEQxTQWLuPGcnhuZEZTK3MJ80W-u74iho9d4yH9StB7jO0A@mail.gmail.com>
To: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Content-Type: multipart/alternative; boundary=001a11492d1487e2880547dd4aac
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/CjHUKTghd9Bl4jRdVaOFbSoMvVo>
Cc: Adam Montville <adam.w.montville@gmail.com>, "<sacm@ietf.org>" <sacm@ietf.org>
Subject: Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Feb 2017 14:17:32 -0000

--001a11492d1487e2880547dd4aac
Content-Type: text/plain; charset=UTF-8

I wanted to clarify one assumption I have been making when viewing the
diagram.  I am viewing the overall vulnerability scenario as a series of
event-driven use-cases, with this diagram simply depicting one of those
use-cases:  When new VDD is introduced into the scenario.

Feasibly, a number of different events could trigger entry into the
vulnerability scenario, such as a "staleness trigger", or a "new endpoint
added trigger", and many more.  Each of these events could (and should)
have their own diagram outlining how the components interact to request
new/updated VDD, determine the endpoints which should be assessed, and what
to do with their results.  As such, each of the components in the diagrams
can be seen as conceptual, allowing for implementers to determine how best
to consolidate components for their use.

Please bash my thought process if I'm way off on this, but I thought it
might help in this discussion, because it seems like some of the
"disagreement" in the diagram is stemming from "events" which aren't
necessarily applicable to this particular "event use-case".

Cheers,
-Bill M.


On Fri, Feb 3, 2017 at 5:19 PM, Henk Birkholz <
henk.birkholz@sit.fraunhofer.de> wrote:

> Also inline. I hope it is still readable.
>
> On 02/03/2017 10:55 PM, Adam Montville wrote:
>
>> Thanks for chiming in Henk.  I'll go inline.  Nothing being said as
>> chair.  Just making observations.
>>
>> On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz
>> <henk.birkholz@sit.fraunhofer.de
>> <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
>>
>>     Hi group,
>>
>>     to recap my understanding:
>>
>>     There will be trigger conditions that initiate collections of fresh
>>     endpoint attributes (from which endpoint posture can be derived) from
>> a
>>     target endpoint.
>>
>>     The obvious trigger condition that an asserting component (in every
>>     diagram, I think, that is the Vulnerability Assessor. This assumption
>> is
>>     based on the interpretation of the diagram, not based on the name of
>> the
>>     component). From my point of view, in order to assert that a known
>>     record is, for example, "stale" (aka does not satisfy an declarative
>>     guidance that expresses the quality of freshness) or, as another
>>     example, is not yet created the Vulnerability Assessor requires an
>>     always up-to-date and exhaustive list of all Assessment Result
>> records.
>>
>>
>> I would disagree.  I have a record from the endpoint repository that it
>> timestamped as 3 days old.  My policy says I should not rely on anything
>> older than 2 days old.  Then the information is stale, and I instruct to
>> collect anew.
>>
>
> If the "I" is the Vulnerability Assessor, how does it always have the
> Assessment Result records to check that declarative guidance? Or do you
> propose (in v3) that the Endpoint Repository is checking that freshness
> continuously and notifying the Vulnerability Assessor?
>
>
>>
>>
>>     In consequence, I would assume that either the the Assessment Result
>>     Repository component collapses with the Vulnerability Assessor or the
>>     Vulnerability Assessor always retains a complete in-sync copy of the
>>     Assessment Result Repository.
>>
>>
>> I would again disagree.  It may well be that actual software collapses
>> these components into one, but it may be that there is a results
>> repository, which is used downstream from vulnerability assessment, into
>> which the assessor dumps results.
>>
>
> Yes, downstream records are dumped as a result in the corresponding repo.
> But how does the information of not satisfying declarative guidance (a
> result got stale) makes it "upstream" again to trigger collection -
> including imperative guidance what to collect (what just got stale)?
>
>
>> Consider when we have configuration assessment down the road.  Would we
>> then have a vulnerability assessor and a configuration assessor each
>> with their own repository conceptually, or would we be better off with
>> one "results repository"?  I think the one.
>>
>
> It depends on scalability, I guess, but in the bare-bone first proof of
> concept it seems to be feasible to collapse related pools of data into
> justthe one, as there are no multiple consumers?
>
>
>
>> In practice, applications can choose to implement more than one
>> conceptual component.
>>
>
> Yes, that is why it is not a problem to collapse sets of functions into a
> single component, in general. I hope this will remain a core feature of the
> architecture at all time.
>
>
>>
>>
>>     Alternatively, the Assessment Result Repository component is collapsed
>>     with the Endpoint Repository (as proposed in diagram v3), in which
>> case
>>     now the Vulnerability Assessor to retain an continuously in-sync copy
>> of
>>     the Endpoint Repository? If it is to trigger on the "stale" condition?
>>
>>
>> Again, I am not necessarily in favor of this viewpoint (and I'm not
>> necessarily against).  The endpoint repository represents an interface
>> to acquire information about endpoints, which does not necessarily need
>> to include assessment results pertaining to those endpoints entirely.
>>
>
> But isn't that what is depicted in the diagram v3: the assessment results
> repo is merged with endpoint repo? Maybe I am actually a little bit dense
> right now :)
>
>
>>
>>
>>
>>     The "keeping pools of data in-sync" seems to be introducing extra
>> steps
>>     in the work-flow.
>>
>>
>> Is it really data in sync?  I understand what you're saying, but to me
>> the endpoint repository component is where we find assertions about the
>> endpoints, the assessors take those assertions and apply some logic to
>> pass judgement on the endpoint, and that judgement is stored in the
>> assessment results repository component.
>>
>
> I simply did not assume that a repository is more than a data store. If it
> does continuous assessments of endpoint records it contains, it most
> certainly can trigger a collection. Maybe the label of the component is
> just misleading me here.
>
>
>>
>>
>>     A pro for this would be that there could be multiple additional
>>     consumers of Assessment Results that justify an interface that
>> provides
>>     that data to multiple parties.
>>
>>
>> Yes!  There are in practice.  Assessment results have downstream uses
>> outside the scope of our charter.
>>
>
> I thought so, but it is of course not part of the single snapshot diagram
> and is therefore only implied at best.
>
>
>>
>>
>>     A con for this is the universal "redundant data stores always pose a
>>     source of complexity and hence risk of inconsistency" argument.
>>
>>     Another point of view could be that the "evaluation task" is
>> independent
>>     from the "trigger collection" (I just made that one up) task? Or maybe
>>     it is associated with the worn component?
>>
>>     Multiple emerging architectures include an orchestration component
>> that
>>     consumes notification of changes and derives appropriate actions that
>> it
>>     can trigger or even conduct. Please note, I am not advocating to
>>     introduce yet another component type (which would again add
>> complexity,
>>     error, scope creep...) :)
>>
>>
>> Bill mentioned something to me offline yesterday about orchestration.
>> In the vulnerability scenario, the orchestration is really being
>> performed by the assessor.
>>
>
> I think that in the reply above you illustrated that the Endpoint Repo
> also does this assessment by checking for staleness? Or would it "just"
> notify the Assessor to trigger a task? Why not trigger the collector
> directly? What about the imperative guidance what to actually collect again?
>
> It seems that I really have a difficult time to wrap my head around the
> proposal still. Please stay patient with me! :)
>
>
>>
>>
>>     I just try to get a feasible grasp of the actual workflow that the
>>     diagram is intended to represent.
>>
>>
>> The most basic path through the system.
>>
>>
>>
>>     What am I missing? I actually am surprised that the Assessment Result
>>     Repository merges with the Endpoint Repository and not the
>> Vulnerability
>>     Assessor. What is the advantage?
>>
>>
>> I think we're still talking this one through.  What's the advantage to
>> collapsing them at all?
>>
>
> Collapsing redundant pools of data is reducing redundancy :) Tasks that
> depend on data that has to be acquired to be conducted benefit from high
> availability and low latency. But I totally understand the "multiple
> consumer" argument.
>
>
>>
>>
>>     Best,
>>
>>     Henk
>>
>>     On 02/03/2017 05:43 PM, Adam Montville wrote:
>>     > I thought I'd try to break this discussion out of it's former thread
>>     > into one of its own, in case that makes it easier for folks to
>> opine.
>>     > The list of "components" or "function groups" seems reasonable to
>> me.
>>     > In practice, there *may* be a desire to have that software acting
>>     as an
>>     > endpoint repository also act as the repository for assessment
>> results.
>>     > Or, these could be implemented in distinct services.
>>     >
>>     > What works for our purposes?
>>     >
>>     > Adam
>>     >
>>     > On Thu, Feb 2, 2017 at 10:40 AM Adam Montville
>>     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
>>     <mailto:adam.w.montville@gmail.com
>>     <mailto:adam.w.montville@gmail.com>>> wrote:
>>     >
>>     >     Once folks have had an opportunity to review the vulnerability
>>     >     scenario information we've been working on, what are your
>> thoughts
>>     >     on the main components we're presently focused on for this
>>     narrowly
>>     >     scoped exercise?  These are:
>>     >
>>     >     Vulnerability Detection Data Repository
>>     >     Vulnerability Assessor
>>     >     Endpoint Repository
>>     >     Collector
>>     >     Assessment Result Repository
>>     >     Endpoint
>>     >
>>     >
>>     >
>>     >
>>     >     On Thu, Feb 2, 2017 at 10:28 AM Adam Montville
>>     >     <adam.w.montville@gmail.com
>>     <mailto:adam.w.montville@gmail.com>
>>     <mailto:adam.w.montville@gmail.com
>>
>>     <mailto:adam.w.montville@gmail.com>>> wrote:
>>     >
>>     >         Hi Everyone.  A few of us were able to make the
>> vulnerability
>>     >         scenario call today and I think we had a good, though at
>> times
>>     >         spirited, discussion.  We did record the meeting, which is
>>     >         available at [1].  We discussed the attached (annotated with
>>     >         some meeting notes) UML-ish sequence diagram.  I had created
>>     >         that diagram to start a conversation (mission accomplished
>> on
>>     >         that front I think) -- a conversation that would lead us
>>     toward
>>     >         identifying the discrete components, interfaces, and
>>     information
>>     >         required to be sent over those interfaces.  The UML-ish
>>     diagram
>>     >         represents a *single* flow through the system -- a
>> "one-time"
>>     >         flow through the system.  It ignores, for the time being,
>> the
>>     >         continuous aspect of our charter in favor of getting started
>>     >         with the basics.  Once we have a good understanding of the
>>     >         basics -- the components, interfaces, and information
>> required
>>     >         -- we can start look at a continuous monitoring sequence
>>     (which
>>     >         could be represented as a distinct diagram) to determine
>> what
>>     >         more we need.  Then, I think, we can start drafting
>> solutions.
>>     >
>>     >         One of the first issues is that we need to figure out if the
>>     >         components in the base flow are accurate.  The main
>> suggestion
>>     >         we've tossed around so far is to combine the Endpoint
>>     Repository
>>     >         with the Assessment Result Repository.
>>     >
>>     >         We talked briefly about what interface we could use for
>>     the VDD
>>     >         Repository, and naturally ROLIE came up as an option.
>>     >
>>     >         We talked a little bit about the first "get endpoints"
>>     operation
>>     >         between the Vulnerability Assessor and the Endpoint
>> Repository
>>     >         -- specifically about whether we should represent on this
>>     >         sequence diagram that information supporting a judgement of
>>     >         "stale" would be needed.
>>     >
>>     >         We left open the time when we would next meet, favoring to
>>     work
>>     >         that out on-list.  Next week is TCG, so that may be
>> difficult;
>>     >         the following week is RSA, so that may be difficult.
>>     >
>>     >         For those who were in attendance today, please add to this
>>     note
>>     >         with your comments/corrections.
>>     >
>>     >         Kind regards,
>>     >
>>     >         Adam
>>     >
>>     >         [1]
>>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>>     >
>>     >         On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>>     >         <adam.w.montville@gmail.com
>>     <mailto:adam.w.montville@gmail.com>
>>     <mailto:adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com
>> >>>
>>     >         wrote:
>>     >
>>     >             Hi everyone.  Just a friendly reminder that we are
>>     planning
>>     >             to meet again this Thursday at the same time (2/2 @ 10am
>>     >             Eastern/3pm UTC) using SACM's meeting room at
>>     >             https://ietf.webex.com/meet/sacm.
>>     >
>>     >             Kind regards,
>>     >
>>     >             Adam
>>     >
>>     >
>>     >             On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>>     >             <adam.w.montville@gmail.com
>>     <mailto:adam.w.montville@gmail.com>
>>     >             <mailto:adam.w.montville@gmail.com
>>
>>     <mailto:adam.w.montville@gmail.com>>> wrote:
>>     >
>>     >                 Hello. A few of us met informally today to discuss
>> the
>>     >                 vulnerability scenario in some more detail with
>>     the goal
>>     >                 of maintaining the narrow focus on a vulnerability
>>     >                 assessment slice through our notional environment.
>> We
>>     >                 are tending to look at major components as black
>> boxes
>>     >                 with interfaces and data format expectations, and
>>     we are
>>     >                 not necessarily concerned with how those components
>> do
>>     >                 things internally/behind the scenes.
>>     >
>>     >                 The meeting was recorded (you can find it with
>> today's
>>     >                 date at [1]).  The topic of discussion was
>>     primarily in
>>     >                 the "phase 1" area of what Danny sent to the list
>> not
>>     >                 very long ago [2], and resulted in a *starting
>> point*
>>     >                 diagram [3].
>>     >
>>     >                 The group who met today are (roughly) agreed on
>>     the six
>>     >                 main "components" represented in that diagram, but
>>     also
>>     >                 see that we have some work ahead.  Specifically, we
>>     >                 quickly recognized that some of the assumptions the
>>     >                 vulnerability draft makes may be assumptions we
>> cannot
>>     >                 afford to make and need to include in the
>> exploration.
>>     >
>>     >                 We thought it would be a good idea to have another
>>     >                 informal discussion in a couple of weeks (February
>>     2) at
>>     >                 the same time (10am Eastern / 3pm UTC), using the
>> same
>>     >                 WebEx [4].   At that time we intend to roll
>>     through the
>>     >                 vulnerability assessment scenario assumptions in an
>>     >                 effort to determine which ones can be left as
>>     >                 assumptions and which ones cannot.  Then we'll take
>>     >                 another look at the diagram and work on its next
>>     version.
>>     >
>>     >                 Stay tuned.
>>     >
>>     >                 Thanks to Danny, Stephen, and Jerome for joining and
>>     >                 contributing!
>>     >
>>     >                 Kind regards,
>>     >
>>     >                 Adam
>>     >
>>     >
>>     >                 [1]
>>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>>     >                 [2]
>>     https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB
>> 5NSU58MXDM
>>     >                 [3]
>>     https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>>     >                 [4] https://ietf.webex.com/meet/sacm
>>     >
>>     >
>>     >
>>     > _______________________________________________
>>     > sacm mailing list
>>     > sacm@ietf.org <mailto:sacm@ietf.org>
>>     > https://www.ietf.org/mailman/listinfo/sacm
>>     >
>>
>>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>

--001a11492d1487e2880547dd4aac
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:verdana,=
sans-serif">I wanted to clarify one assumption I have been making when view=
ing the diagram.=C2=A0 I am viewing the overall vulnerability scenario as a=
 series of event-driven use-cases, with this diagram simply depicting one o=
f those use-cases: =C2=A0When new VDD is introduced into the scenario. =C2=
=A0</div><div class=3D"gmail_default" style=3D"font-family:verdana,sans-ser=
if"><br></div><div class=3D"gmail_default" style=3D"font-family:verdana,san=
s-serif">Feasibly, a number of different events could trigger entry into th=
e vulnerability scenario, such as a &quot;staleness trigger&quot;, or a &qu=
ot;new endpoint added trigger&quot;, and many more.=C2=A0 Each of these eve=
nts could (and should) have their own diagram outlining how the components =
interact to request new/updated VDD, determine the endpoints which should b=
e assessed, and what to do with their results.=C2=A0 As such, each of the c=
omponents in the diagrams can be seen as conceptual, allowing for implement=
ers to determine how best to consolidate components for their use.</div><di=
v class=3D"gmail_default" style=3D"font-family:verdana,sans-serif"><br></di=
v><div class=3D"gmail_default" style=3D"font-family:verdana,sans-serif">Ple=
ase bash my thought process if I&#39;m way off on this, but I thought it mi=
ght help in this discussion, because it seems like some of the &quot;disagr=
eement&quot; in the diagram is stemming from &quot;events&quot; which aren&=
#39;t necessarily applicable to this particular &quot;event use-case&quot;.=
</div><div class=3D"gmail_default" style=3D"font-family:verdana,sans-serif"=
><br></div><div class=3D"gmail_default" style=3D"font-family:verdana,sans-s=
erif">Cheers,=C2=A0</div><div class=3D"gmail_default" style=3D"font-family:=
verdana,sans-serif">-Bill M.</div><div class=3D"gmail_default" style=3D"fon=
t-family:verdana,sans-serif"><br></div></div><div class=3D"gmail_extra"><br=
><div class=3D"gmail_quote">On Fri, Feb 3, 2017 at 5:19 PM, Henk Birkholz <=
span dir=3D"ltr">&lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" tar=
get=3D"_blank">henk.birkholz@sit.fraunhofer.de</a>&gt;</span> wrote:<br><bl=
ockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #=
ccc solid;padding-left:1ex">Also inline. I hope it is still readable.<br>
<br>
On 02/03/2017 10:55 PM, Adam Montville wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Thanks for chiming in Henk.=C2=A0 I&#39;ll go inline.=C2=A0 Nothing being s=
aid as<br>
chair.=C2=A0 Just making observations.<br>
<br>
On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz<br>
&lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" target=3D"_blank">he=
nk.birkholz@sit.fraunhofer.<wbr>de</a><span class=3D""><br>
&lt;mailto:<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" target=3D"_bl=
ank">henk.birkholz@sit.frau<wbr>nhofer.de</a>&gt;&gt; wrote:<br>
<br>
=C2=A0 =C2=A0 Hi group,<br>
<br>
=C2=A0 =C2=A0 to recap my understanding:<br>
<br>
=C2=A0 =C2=A0 There will be trigger conditions that initiate collections of=
 fresh<br>
=C2=A0 =C2=A0 endpoint attributes (from which endpoint posture can be deriv=
ed) from a<br>
=C2=A0 =C2=A0 target endpoint.<br>
<br>
=C2=A0 =C2=A0 The obvious trigger condition that an asserting component (in=
 every<br>
=C2=A0 =C2=A0 diagram, I think, that is the Vulnerability Assessor. This as=
sumption is<br>
=C2=A0 =C2=A0 based on the interpretation of the diagram, not based on the =
name of the<br>
=C2=A0 =C2=A0 component). From my point of view, in order to assert that a =
known<br>
=C2=A0 =C2=A0 record is, for example, &quot;stale&quot; (aka does not satis=
fy an declarative<br>
=C2=A0 =C2=A0 guidance that expresses the quality of freshness) or, as anot=
her<br>
=C2=A0 =C2=A0 example, is not yet created the Vulnerability Assessor requir=
es an<br>
=C2=A0 =C2=A0 always up-to-date and exhaustive list of all Assessment Resul=
t records.<br>
<br>
<br></span>
I would disagree.=C2=A0 I have a record from the endpoint repository that i=
t<br>
timestamped as 3 days old.=C2=A0 My policy says I should not rely on anythi=
ng<br>
older than 2 days old.=C2=A0 Then the information is stale, and I instruct =
to<br>
collect anew.<br>
</blockquote>
<br>
If the &quot;I&quot; is the Vulnerability Assessor, how does it always have=
 the Assessment Result records to check that declarative guidance? Or do yo=
u propose (in v3) that the Endpoint Repository is checking that freshness c=
ontinuously and notifying the Vulnerability Assessor?<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span class=3D"">
<br>
<br>
<br>
=C2=A0 =C2=A0 In consequence, I would assume that either the the Assessment=
 Result<br>
=C2=A0 =C2=A0 Repository component collapses with the Vulnerability Assesso=
r or the<br>
=C2=A0 =C2=A0 Vulnerability Assessor always retains a complete in-sync copy=
 of the<br>
=C2=A0 =C2=A0 Assessment Result Repository.<br>
<br>
<br></span>
I would again disagree.=C2=A0 It may well be that actual software collapses=
<br>
these components into one, but it may be that there is a results<br>
repository, which is used downstream from vulnerability assessment, into<br=
>
which the assessor dumps results.<br>
</blockquote>
<br>
Yes, downstream records are dumped as a result in the corresponding repo. B=
ut how does the information of not satisfying declarative guidance (a resul=
t got stale) makes it &quot;upstream&quot; again to trigger collection - in=
cluding imperative guidance what to collect (what just got stale)?<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
Consider when we have configuration assessment down the road.=C2=A0 Would w=
e<br>
then have a vulnerability assessor and a configuration assessor each<br>
with their own repository conceptually, or would we be better off with<br>
one &quot;results repository&quot;?=C2=A0 I think the one.<br>
</blockquote>
<br>
It depends on scalability, I guess, but in the bare-bone first proof of con=
cept it seems to be feasible to collapse related pools of data into justthe=
 one, as there are no multiple consumers?<br>
<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
In practice, applications can choose to implement more than one<br>
conceptual component.<br>
</blockquote>
<br>
Yes, that is why it is not a problem to collapse sets of functions into a s=
ingle component, in general. I hope this will remain a core feature of the =
architecture at all time.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span class=3D"">
<br>
<br>
<br>
=C2=A0 =C2=A0 Alternatively, the Assessment Result Repository component is =
collapsed<br>
=C2=A0 =C2=A0 with the Endpoint Repository (as proposed in diagram v3), in =
which case<br>
=C2=A0 =C2=A0 now the Vulnerability Assessor to retain an continuously in-s=
ync copy of<br>
=C2=A0 =C2=A0 the Endpoint Repository? If it is to trigger on the &quot;sta=
le&quot; condition?<br>
<br>
<br></span>
Again, I am not necessarily in favor of this viewpoint (and I&#39;m not<br>
necessarily against).=C2=A0 The endpoint repository represents an interface=
<br>
to acquire information about endpoints, which does not necessarily need<br>
to include assessment results pertaining to those endpoints entirely.<br>
</blockquote>
<br>
But isn&#39;t that what is depicted in the diagram v3: the assessment resul=
ts repo is merged with endpoint repo? Maybe I am actually a little bit dens=
e right now :)<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span class=3D"">
<br>
<br>
<br>
<br>
=C2=A0 =C2=A0 The &quot;keeping pools of data in-sync&quot; seems to be int=
roducing extra steps<br>
=C2=A0 =C2=A0 in the work-flow.<br>
<br>
<br></span>
Is it really data in sync?=C2=A0 I understand what you&#39;re saying, but t=
o me<br>
the endpoint repository component is where we find assertions about the<br>
endpoints, the assessors take those assertions and apply some logic to<br>
pass judgement on the endpoint, and that judgement is stored in the<br>
assessment results repository component.<br>
</blockquote>
<br>
I simply did not assume that a repository is more than a data store. If it =
does continuous assessments of endpoint records it contains, it most certai=
nly can trigger a collection. Maybe the label of the component is just misl=
eading me here.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span class=3D"">
<br>
<br>
<br>
=C2=A0 =C2=A0 A pro for this would be that there could be multiple addition=
al<br>
=C2=A0 =C2=A0 consumers of Assessment Results that justify an interface tha=
t provides<br>
=C2=A0 =C2=A0 that data to multiple parties.<br>
<br>
<br></span>
Yes!=C2=A0 There are in practice.=C2=A0 Assessment results have downstream =
uses<br>
outside the scope of our charter.<br>
</blockquote>
<br>
I thought so, but it is of course not part of the single snapshot diagram a=
nd is therefore only implied at best.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span class=3D"">
<br>
<br>
<br>
=C2=A0 =C2=A0 A con for this is the universal &quot;redundant data stores a=
lways pose a<br>
=C2=A0 =C2=A0 source of complexity and hence risk of inconsistency&quot; ar=
gument.<br>
<br>
=C2=A0 =C2=A0 Another point of view could be that the &quot;evaluation task=
&quot; is independent<br>
=C2=A0 =C2=A0 from the &quot;trigger collection&quot; (I just made that one=
 up) task? Or maybe<br>
=C2=A0 =C2=A0 it is associated with the worn component?<br>
<br>
=C2=A0 =C2=A0 Multiple emerging architectures include an orchestration comp=
onent that<br>
=C2=A0 =C2=A0 consumes notification of changes and derives appropriate acti=
ons that it<br>
=C2=A0 =C2=A0 can trigger or even conduct. Please note, I am not advocating=
 to<br>
=C2=A0 =C2=A0 introduce yet another component type (which would again add c=
omplexity,<br>
=C2=A0 =C2=A0 error, scope creep...) :)<br>
<br>
<br></span>
Bill mentioned something to me offline yesterday about orchestration.<br>
In the vulnerability scenario, the orchestration is really being<br>
performed by the assessor.<br>
</blockquote>
<br>
I think that in the reply above you illustrated that the Endpoint Repo also=
 does this assessment by checking for staleness? Or would it &quot;just&quo=
t; notify the Assessor to trigger a task? Why not trigger the collector dir=
ectly? What about the imperative guidance what to actually collect again?<b=
r>
<br>
It seems that I really have a difficult time to wrap my head around the pro=
posal still. Please stay patient with me! :)<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span class=3D"">
<br>
<br>
<br>
=C2=A0 =C2=A0 I just try to get a feasible grasp of the actual workflow tha=
t the<br>
=C2=A0 =C2=A0 diagram is intended to represent.<br>
<br>
<br></span>
The most basic path through the system.<span class=3D""><br>
<br>
<br>
<br>
=C2=A0 =C2=A0 What am I missing? I actually am surprised that the Assessmen=
t Result<br>
=C2=A0 =C2=A0 Repository merges with the Endpoint Repository and not the Vu=
lnerability<br>
=C2=A0 =C2=A0 Assessor. What is the advantage?<br>
<br>
<br></span>
I think we&#39;re still talking this one through.=C2=A0 What&#39;s the adva=
ntage to<br>
collapsing them at all?<br>
</blockquote>
<br>
Collapsing redundant pools of data is reducing redundancy :) Tasks that dep=
end on data that has to be acquired to be conducted benefit from high avail=
ability and low latency. But I totally understand the &quot;multiple consum=
er&quot; argument.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span class=3D"">
<br>
<br>
<br>
=C2=A0 =C2=A0 Best,<br>
<br>
=C2=A0 =C2=A0 Henk<br>
<br>
=C2=A0 =C2=A0 On 02/03/2017 05:43 PM, Adam Montville wrote:<br>
=C2=A0 =C2=A0 &gt; I thought I&#39;d try to break this discussion out of it=
&#39;s former thread<br>
=C2=A0 =C2=A0 &gt; into one of its own, in case that makes it easier for fo=
lks to opine.<br>
=C2=A0 =C2=A0 &gt; The list of &quot;components&quot; or &quot;function gro=
ups&quot; seems reasonable to me.<br>
=C2=A0 =C2=A0 &gt; In practice, there *may* be a desire to have that softwa=
re acting<br>
=C2=A0 =C2=A0 as an<br>
=C2=A0 =C2=A0 &gt; endpoint repository also act as the repository for asses=
sment results.<br>
=C2=A0 =C2=A0 &gt; Or, these could be implemented in distinct services.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; What works for our purposes?<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; On Thu, Feb 2, 2017 at 10:40 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" target=
=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto:<a href=3D"mailto:ada=
m.w.montville@gmail.com" target=3D"_blank">adam.w.montville@gmail<wbr>.com<=
/a>&gt;<br></span>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a><span class=3D""><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Once folks have had an opportunity to=
 review the vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scenario information we&#39;ve been w=
orking on, what are your thoughts<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0on the main components we&#39;re pres=
ently focused on for this<br>
=C2=A0 =C2=A0 narrowly<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scoped exercise?=C2=A0 These are:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Detection Data Reposito=
ry<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Assessor<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Collector<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Assessment Result Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0On Thu, Feb 2, 2017 at 10:28 AM Adam =
Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montvill=
e@gmail.com" target=3D"_blank">adam.w.montville@gmail.com</a><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;<br></span>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a><div><div class=3D"h5"><br=
>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi Everyone.=C2=A0 A fe=
w of us were able to make the vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario call today and=
 I think we had a good, though at times<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0spirited, discussion.=
=C2=A0 We did record the meeting, which is<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0available at [1].=C2=A0=
 We discussed the attached (annotated with<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some meeting notes) UML=
-ish sequence diagram.=C2=A0 I had created<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that diagram to start a=
 conversation (mission accomplished on<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that front I think) -- =
a conversation that would lead us<br>
=C2=A0 =C2=A0 toward<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0identifying the discret=
e components, interfaces, and<br>
=C2=A0 =C2=A0 information<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0required to be sent ove=
r those interfaces.=C2=A0 The UML-ish<br>
=C2=A0 =C2=A0 diagram<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0represents a *single* f=
low through the system -- a &quot;one-time&quot;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0flow through the system=
.=C2=A0 It ignores, for the time being, the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0continuous aspect of ou=
r charter in favor of getting started<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the basics.=C2=A0 =
Once we have a good understanding of the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0basics -- the component=
s, interfaces, and information required<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- we can start look at=
 a continuous monitoring sequence<br>
=C2=A0 =C2=A0 (which<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0could be represented as=
 a distinct diagram) to determine what<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0more we need.=C2=A0 The=
n, I think, we can start drafting solutions.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0One of the first issues=
 is that we need to figure out if the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0components in the base =
flow are accurate.=C2=A0 The main suggestion<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0we&#39;ve tossed around=
 so far is to combine the Endpoint<br>
=C2=A0 =C2=A0 Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the Assessment Res=
ult Repository.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked briefly about=
 what interface we could use for<br>
=C2=A0 =C2=A0 the VDD<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Repository, and natural=
ly ROLIE came up as an option.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked a little bit =
about the first &quot;get endpoints&quot;<br>
=C2=A0 =C2=A0 operation<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0between the Vulnerabili=
ty Assessor and the Endpoint Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- specifically about w=
hether we should represent on this<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0sequence diagram that i=
nformation supporting a judgement of<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;stale&quot; would=
 be needed.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We left open the time w=
hen we would next meet, favoring to<br>
=C2=A0 =C2=A0 work<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that out on-list.=C2=A0=
 Next week is TCG, so that may be difficult;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0the following week is R=
SA, so that may be difficult.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0For those who were in a=
ttendance today, please add to this<br>
=C2=A0 =C2=A0 note<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with your comments/corr=
ections.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" rel=3D"noreferrer" target=3D"_blank">https://drive.google.co=
m/open?<wbr>id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1<wbr>E</a><br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Mon, Jan 30, 2017 at=
 11:21 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:a=
dam.w.montville@gmail.com" target=3D"_blank">adam.w.montville@gmail.com</a>=
<br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;<br></div></div>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a> &lt;mailto:<a href=3D"mai=
lto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.montville@gmail<wb=
r>.com</a>&gt;&gt;&gt;<span class=3D""><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi everyo=
ne.=C2=A0 Just a friendly reminder that we are<br>
=C2=A0 =C2=A0 planning<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0to meet a=
gain this Thursday at the same time (2/2 @ 10am<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Eastern/3=
pm UTC) using SACM&#39;s meeting room at<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=
=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" target=3D"_blank">=
https://ietf.webex.com/meet/s<wbr>acm</a>.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind rega=
rds,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Thu, J=
an 19, 2017 at 11:35 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a hr=
ef=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.montville=
@gmail.com</a><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;<br></span>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;mailt=
o:<a href=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.mo=
ntville@gmai<wbr>l.com</a><div><div class=3D"h5"><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Hello. A few of us met informally today to discuss the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability scenario in some more detail with<br>
=C2=A0 =C2=A0 the goal<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0of maintaining the narrow focus on a vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assessment slice through our notional environment.=C2=A0 We<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0are tending to look at major components as black boxes<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0with interfaces and data format expectations, and<br>
=C2=A0 =C2=A0 we are<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0not necessarily concerned with how those components do<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0things internally/behind the scenes.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The meeting was recorded (you can find it with today&#39;s<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0date at [1]).=C2=A0 The topic of discussion was<br>
=C2=A0 =C2=A0 primarily in<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the &quot;phase 1&quot; area of what Danny sent to the list not<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0very long ago [2], and resulted in a *starting point*<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0diagram [3].<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The group who met today are (roughly) agreed on<br>
=C2=A0 =C2=A0 the six<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0main &quot;components&quot; represented in that diagram, but<br>
=C2=A0 =C2=A0 also<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0see that we have some work ahead.=C2=A0 Specifically, we<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0quickly recognized that some of the assumptions the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability draft makes may be assumptions we cannot<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0afford to make and need to include in the exploration.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0We thought it would be a good idea to have another<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0informal discussion in a couple of weeks (February<br>
=C2=A0 =C2=A0 2) at<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the same time (10am Eastern / 3pm UTC), using the same<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0WebEx [4].=C2=A0 =C2=A0At that time we intend to roll<br>
=C2=A0 =C2=A0 through the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability assessment scenario assumptions in an<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0effort to determine which ones can be left as<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assumptions and which ones cannot.=C2=A0 Then we&#39;ll take<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0another look at the diagram and work on its next<br>
=C2=A0 =C2=A0 version.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Stay tuned.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Thanks to Danny, Stephen, and Jerome for joining and<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0contributing!<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Kind regards,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[1]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" rel=3D"noreferrer" target=3D"_blank">https://drive.google.co=
m/open?<wbr>id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1<wbr>E</a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[2]<br>
=C2=A0 =C2=A0 <a href=3D"https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyv=
Aws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" target=3D"_blank">https://mailarch=
ive.ietf.org/a<wbr>rch/msg/sacm/_LiKlyvAws_OVLFhB<wbr>5NSU58MXDM</a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[3]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU=
5pdTRjejJtNHc" rel=3D"noreferrer" target=3D"_blank">https://drive.google.co=
m/open?<wbr>id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNH<wbr>c</a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[4] <a href=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" t=
arget=3D"_blank">https://ietf.webex.com/meet/sa<wbr>cm</a><br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; ______________________________<wbr>_________________<br>
=C2=A0 =C2=A0 &gt; sacm mailing list<br></div></div>
=C2=A0 =C2=A0 &gt; <a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@=
ietf.org</a> &lt;mailto:<a href=3D"mailto:sacm@ietf.org" target=3D"_blank">=
sacm@ietf.org</a>&gt;<br>
=C2=A0 =C2=A0 &gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" r=
el=3D"noreferrer" target=3D"_blank">https://www.ietf.org/mailman/l<wbr>isti=
nfo/sacm</a><br>
=C2=A0 =C2=A0 &gt;<br>
<br>
</blockquote><div class=3D"HOEnZb"><div class=3D"h5">
<br>
______________________________<wbr>_________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/l<wbr>istinfo/sacm</a><br>
</div></div></blockquote></div><br></div>

--001a11492d1487e2880547dd4aac--


From nobody Mon Feb  6 09:22:31 2017
Return-Path: <adam.w.montville@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 88616129540 for <sacm@ietfa.amsl.com>; Mon,  6 Feb 2017 09:22:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lIIpm09Ft6kI for <sacm@ietfa.amsl.com>; Mon,  6 Feb 2017 09:22:27 -0800 (PST)
Received: from mail-ot0-x233.google.com (mail-ot0-x233.google.com [IPv6:2607:f8b0:4003:c0f::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 24BFB129480 for <sacm@ietf.org>; Mon,  6 Feb 2017 09:22:27 -0800 (PST)
Received: by mail-ot0-x233.google.com with SMTP id 73so67060776otj.0 for <sacm@ietf.org>; Mon, 06 Feb 2017 09:22:27 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=KvWQZHrc8Z2iqDkZFOZreSB/lBg0MbWJ5MDKhLz6hc0=; b=FLx6xjB7sW8W7QHosnKUan0W6XBICTgM5WNb+gtD8HkWY5LGJguHil+BMbyfWC8bgs pOfwaVDZxhuRHVSzQyNY8PEDu954FA2Afgxk9iqVnRjYRaCu9ZxxgRq6dJb2lK+s5MkG YBhiU3JhJeCre2exEnDctCTtUYeFCXrL+MSo2iWceRBrh5rdxir++I5WI1D0OgVEWkVA KUM+NYTO1S06yfcvm7Mhq04gh9iUigOh+Au8se22trjx7JTPprovNIoKOHNPgZo36ey3 4E36mOgy3UrKQuBhaedlobbVVCEiFJq5uvHM6e1hIGP+bgbErtKByIArMGMVVSAVzG86 mmdg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=KvWQZHrc8Z2iqDkZFOZreSB/lBg0MbWJ5MDKhLz6hc0=; b=M12rWmdai8M74yIye6ueLmJHBsnxFAWolhW+xfqoWYwG2bsyy57hSAGhnbapZZBXRP lGXV2m12L+F2cssoBSgNPtt8dRrJXykWs3PYrBQAG80WDOR7r156xFO/35Mbj7R7ifHV TaL3UE6fwH3M4T4cWzQHpcrOowHGMNYNXi4jwGrd/ErpiWxltk/10oDr7ELDMOhc2lx/ jsDP7QSrDMu3ed8Sgol4/BqmV1izLVv/g5RaKwl4YPVSMg09YhyPkw1/GF+Dz5ZeD3Mu AaKEXEbB+KA+4j1/Y/KCr3mkduzJs3YDhiUYUwnHS4U1tTTfsCei+jLpqfiusW3TdMBS +01g==
X-Gm-Message-State: AMke39lRBq3jnwJ/VDqNn9JKj3Ku9dBRVhe4YBGtAg/1d0JGr8sdEXkKGgmozPm0hdHLqYn63FXfzgGKKj6FhA==
X-Received: by 10.157.46.235 with SMTP id w98mr6440917ota.219.1486401746163; Mon, 06 Feb 2017 09:22:26 -0800 (PST)
MIME-Version: 1.0
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com> <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com> <147f77a8-ea0f-ed43-f585-a70a231110fe@sit.fraunhofer.de> <CACknUNXx=F6DatwikXgs4NGFgbbQMnMPCiGfX4UKfYLh67RUog@mail.gmail.com> <cc9e09ec-05fc-1af2-9f9b-50cf3ef16fd1@sit.fraunhofer.de> <CAKUOEQxTQWLuPGcnhuZEZTK3MJ80W-u74iho9d4yH9StB7jO0A@mail.gmail.com>
In-Reply-To: <CAKUOEQxTQWLuPGcnhuZEZTK3MJ80W-u74iho9d4yH9StB7jO0A@mail.gmail.com>
From: Adam Montville <adam.w.montville@gmail.com>
Date: Mon, 06 Feb 2017 17:22:15 +0000
Message-ID: <CACknUNVkgSMrJsDFaBahMHA0w0=jOM-LRZGGjLsLi6EvhcDrLQ@mail.gmail.com>
To: Bill Munyan <bill.munyan.ietf@gmail.com>,  Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Content-Type: multipart/alternative; boundary=001a113f05f812dd250547dfe0b8
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/jRBazcGDsKeaL4wO49lSkNhNfz8>
Cc: "<sacm@ietf.org>" <sacm@ietf.org>
Subject: Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Feb 2017 17:22:29 -0000

--001a113f05f812dd250547dfe0b8
Content-Type: text/plain; charset=UTF-8

Thanks, Bill.  I agree with your thought process on this.

And, to get back to Henk's questions, I have been thinking of the endpoint
repository as one piece of a larger endpoint management capability.
Whether that endpoint management capability actively or passively collects
such endpoint state information is never explicitly stated in the
vulnerability scenario.  However, I see that going both ways.

Also, I was suggesting that not all pools of data would be redundant.
Endpoint repository doesn't have to store assessment results any more than
assessment results has to store every detail about endpoints.



On Mon, Feb 6, 2017 at 8:17 AM Bill Munyan <bill.munyan.ietf@gmail.com>
wrote:

> I wanted to clarify one assumption I have been making when viewing the
> diagram.  I am viewing the overall vulnerability scenario as a series of
> event-driven use-cases, with this diagram simply depicting one of those
> use-cases:  When new VDD is introduced into the scenario.
>
> Feasibly, a number of different events could trigger entry into the
> vulnerability scenario, such as a "staleness trigger", or a "new endpoint
> added trigger", and many more.  Each of these events could (and should)
> have their own diagram outlining how the components interact to request
> new/updated VDD, determine the endpoints which should be assessed, and what
> to do with their results.  As such, each of the components in the diagrams
> can be seen as conceptual, allowing for implementers to determine how best
> to consolidate components for their use.
>
> Please bash my thought process if I'm way off on this, but I thought it
> might help in this discussion, because it seems like some of the
> "disagreement" in the diagram is stemming from "events" which aren't
> necessarily applicable to this particular "event use-case".
>
> Cheers,
> -Bill M.
>
>
> On Fri, Feb 3, 2017 at 5:19 PM, Henk Birkholz <
> henk.birkholz@sit.fraunhofer.de> wrote:
>
> Also inline. I hope it is still readable.
>
> On 02/03/2017 10:55 PM, Adam Montville wrote:
>
> Thanks for chiming in Henk.  I'll go inline.  Nothing being said as
> chair.  Just making observations.
>
> On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz
> <henk.birkholz@sit.fraunhofer.de
> <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
>
>     Hi group,
>
>     to recap my understanding:
>
>     There will be trigger conditions that initiate collections of fresh
>     endpoint attributes (from which endpoint posture can be derived) from a
>     target endpoint.
>
>     The obvious trigger condition that an asserting component (in every
>     diagram, I think, that is the Vulnerability Assessor. This assumption
> is
>     based on the interpretation of the diagram, not based on the name of
> the
>     component). From my point of view, in order to assert that a known
>     record is, for example, "stale" (aka does not satisfy an declarative
>     guidance that expresses the quality of freshness) or, as another
>     example, is not yet created the Vulnerability Assessor requires an
>     always up-to-date and exhaustive list of all Assessment Result records.
>
>
> I would disagree.  I have a record from the endpoint repository that it
> timestamped as 3 days old.  My policy says I should not rely on anything
> older than 2 days old.  Then the information is stale, and I instruct to
> collect anew.
>
>
> If the "I" is the Vulnerability Assessor, how does it always have the
> Assessment Result records to check that declarative guidance? Or do you
> propose (in v3) that the Endpoint Repository is checking that freshness
> continuously and notifying the Vulnerability Assessor?
>
>
>
>
>     In consequence, I would assume that either the the Assessment Result
>     Repository component collapses with the Vulnerability Assessor or the
>     Vulnerability Assessor always retains a complete in-sync copy of the
>     Assessment Result Repository.
>
>
> I would again disagree.  It may well be that actual software collapses
> these components into one, but it may be that there is a results
> repository, which is used downstream from vulnerability assessment, into
> which the assessor dumps results.
>
>
> Yes, downstream records are dumped as a result in the corresponding repo.
> But how does the information of not satisfying declarative guidance (a
> result got stale) makes it "upstream" again to trigger collection -
> including imperative guidance what to collect (what just got stale)?
>
>
> Consider when we have configuration assessment down the road.  Would we
> then have a vulnerability assessor and a configuration assessor each
> with their own repository conceptually, or would we be better off with
> one "results repository"?  I think the one.
>
>
> It depends on scalability, I guess, but in the bare-bone first proof of
> concept it seems to be feasible to collapse related pools of data into
> justthe one, as there are no multiple consumers?
>
>
>
> In practice, applications can choose to implement more than one
> conceptual component.
>
>
> Yes, that is why it is not a problem to collapse sets of functions into a
> single component, in general. I hope this will remain a core feature of the
> architecture at all time.
>
>
>
>
>     Alternatively, the Assessment Result Repository component is collapsed
>     with the Endpoint Repository (as proposed in diagram v3), in which case
>     now the Vulnerability Assessor to retain an continuously in-sync copy
> of
>     the Endpoint Repository? If it is to trigger on the "stale" condition?
>
>
> Again, I am not necessarily in favor of this viewpoint (and I'm not
> necessarily against).  The endpoint repository represents an interface
> to acquire information about endpoints, which does not necessarily need
> to include assessment results pertaining to those endpoints entirely.
>
>
> But isn't that what is depicted in the diagram v3: the assessment results
> repo is merged with endpoint repo? Maybe I am actually a little bit dense
> right now :)
>
>
>
>
>
>     The "keeping pools of data in-sync" seems to be introducing extra steps
>     in the work-flow.
>
>
> Is it really data in sync?  I understand what you're saying, but to me
> the endpoint repository component is where we find assertions about the
> endpoints, the assessors take those assertions and apply some logic to
> pass judgement on the endpoint, and that judgement is stored in the
> assessment results repository component.
>
>
> I simply did not assume that a repository is more than a data store. If it
> does continuous assessments of endpoint records it contains, it most
> certainly can trigger a collection. Maybe the label of the component is
> just misleading me here.
>
>
>
>
>     A pro for this would be that there could be multiple additional
>     consumers of Assessment Results that justify an interface that provides
>     that data to multiple parties.
>
>
> Yes!  There are in practice.  Assessment results have downstream uses
> outside the scope of our charter.
>
>
> I thought so, but it is of course not part of the single snapshot diagram
> and is therefore only implied at best.
>
>
>
>
>     A con for this is the universal "redundant data stores always pose a
>     source of complexity and hence risk of inconsistency" argument.
>
>     Another point of view could be that the "evaluation task" is
> independent
>     from the "trigger collection" (I just made that one up) task? Or maybe
>     it is associated with the worn component?
>
>     Multiple emerging architectures include an orchestration component that
>     consumes notification of changes and derives appropriate actions that
> it
>     can trigger or even conduct. Please note, I am not advocating to
>     introduce yet another component type (which would again add complexity,
>     error, scope creep...) :)
>
>
> Bill mentioned something to me offline yesterday about orchestration.
> In the vulnerability scenario, the orchestration is really being
> performed by the assessor.
>
>
> I think that in the reply above you illustrated that the Endpoint Repo
> also does this assessment by checking for staleness? Or would it "just"
> notify the Assessor to trigger a task? Why not trigger the collector
> directly? What about the imperative guidance what to actually collect again?
>
> It seems that I really have a difficult time to wrap my head around the
> proposal still. Please stay patient with me! :)
>
>
>
>
>     I just try to get a feasible grasp of the actual workflow that the
>     diagram is intended to represent.
>
>
> The most basic path through the system.
>
>
>
>     What am I missing? I actually am surprised that the Assessment Result
>     Repository merges with the Endpoint Repository and not the
> Vulnerability
>     Assessor. What is the advantage?
>
>
> I think we're still talking this one through.  What's the advantage to
> collapsing them at all?
>
>
> Collapsing redundant pools of data is reducing redundancy :) Tasks that
> depend on data that has to be acquired to be conducted benefit from high
> availability and low latency. But I totally understand the "multiple
> consumer" argument.
>
>
>
>
>     Best,
>
>     Henk
>
>     On 02/03/2017 05:43 PM, Adam Montville wrote:
>     > I thought I'd try to break this discussion out of it's former thread
>     > into one of its own, in case that makes it easier for folks to opine.
>     > The list of "components" or "function groups" seems reasonable to me.
>     > In practice, there *may* be a desire to have that software acting
>     as an
>     > endpoint repository also act as the repository for assessment
> results.
>     > Or, these could be implemented in distinct services.
>     >
>     > What works for our purposes?
>     >
>     > Adam
>     >
>     > On Thu, Feb 2, 2017 at 10:40 AM Adam Montville
>     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >     Once folks have had an opportunity to review the vulnerability
>     >     scenario information we've been working on, what are your
> thoughts
>     >     on the main components we're presently focused on for this
>     narrowly
>     >     scoped exercise?  These are:
>     >
>     >     Vulnerability Detection Data Repository
>     >     Vulnerability Assessor
>     >     Endpoint Repository
>     >     Collector
>     >     Assessment Result Repository
>     >     Endpoint
>     >
>     >
>     >
>     >
>     >     On Thu, Feb 2, 2017 at 10:28 AM Adam Montville
>     >     <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >         Hi Everyone.  A few of us were able to make the vulnerability
>     >         scenario call today and I think we had a good, though at
> times
>     >         spirited, discussion.  We did record the meeting, which is
>     >         available at [1].  We discussed the attached (annotated with
>     >         some meeting notes) UML-ish sequence diagram.  I had created
>     >         that diagram to start a conversation (mission accomplished on
>     >         that front I think) -- a conversation that would lead us
>     toward
>     >         identifying the discrete components, interfaces, and
>     information
>     >         required to be sent over those interfaces.  The UML-ish
>     diagram
>     >         represents a *single* flow through the system -- a "one-time"
>     >         flow through the system.  It ignores, for the time being, the
>     >         continuous aspect of our charter in favor of getting started
>     >         with the basics.  Once we have a good understanding of the
>     >         basics -- the components, interfaces, and information
> required
>     >         -- we can start look at a continuous monitoring sequence
>     (which
>     >         could be represented as a distinct diagram) to determine what
>     >         more we need.  Then, I think, we can start drafting
> solutions.
>     >
>     >         One of the first issues is that we need to figure out if the
>     >         components in the base flow are accurate.  The main
> suggestion
>     >         we've tossed around so far is to combine the Endpoint
>     Repository
>     >         with the Assessment Result Repository.
>     >
>     >         We talked briefly about what interface we could use for
>     the VDD
>     >         Repository, and naturally ROLIE came up as an option.
>     >
>     >         We talked a little bit about the first "get endpoints"
>     operation
>     >         between the Vulnerability Assessor and the Endpoint
> Repository
>     >         -- specifically about whether we should represent on this
>     >         sequence diagram that information supporting a judgement of
>     >         "stale" would be needed.
>     >
>     >         We left open the time when we would next meet, favoring to
>     work
>     >         that out on-list.  Next week is TCG, so that may be
> difficult;
>     >         the following week is RSA, so that may be difficult.
>     >
>     >         For those who were in attendance today, please add to this
>     note
>     >         with your comments/corrections.
>     >
>     >         Kind regards,
>     >
>     >         Adam
>     >
>     >         [1]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >
>     >         On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>     >         <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com
> >>>
>     >         wrote:
>     >
>     >             Hi everyone.  Just a friendly reminder that we are
>     planning
>     >             to meet again this Thursday at the same time (2/2 @ 10am
>     >             Eastern/3pm UTC) using SACM's meeting room at
>     >             https://ietf.webex.com/meet/sacm.
>     >
>     >             Kind regards,
>     >
>     >             Adam
>     >
>     >
>     >             On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>     >             <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     >             <mailto:adam.w.montville@gmail.com
>
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >                 Hello. A few of us met informally today to discuss
> the
>     >                 vulnerability scenario in some more detail with
>     the goal
>     >                 of maintaining the narrow focus on a vulnerability
>     >                 assessment slice through our notional environment.
> We
>     >                 are tending to look at major components as black
> boxes
>     >                 with interfaces and data format expectations, and
>     we are
>     >                 not necessarily concerned with how those components
> do
>     >                 things internally/behind the scenes.
>     >
>     >                 The meeting was recorded (you can find it with
> today's
>     >                 date at [1]).  The topic of discussion was
>     primarily in
>     >                 the "phase 1" area of what Danny sent to the list not
>     >                 very long ago [2], and resulted in a *starting point*
>     >                 diagram [3].
>     >
>     >                 The group who met today are (roughly) agreed on
>     the six
>     >                 main "components" represented in that diagram, but
>     also
>     >                 see that we have some work ahead.  Specifically, we
>     >                 quickly recognized that some of the assumptions the
>     >                 vulnerability draft makes may be assumptions we
> cannot
>     >                 afford to make and need to include in the
> exploration.
>     >
>     >                 We thought it would be a good idea to have another
>     >                 informal discussion in a couple of weeks (February
>     2) at
>     >                 the same time (10am Eastern / 3pm UTC), using the
> same
>     >                 WebEx [4].   At that time we intend to roll
>     through the
>     >                 vulnerability assessment scenario assumptions in an
>     >                 effort to determine which ones can be left as
>     >                 assumptions and which ones cannot.  Then we'll take
>     >                 another look at the diagram and work on its next
>     version.
>     >
>     >                 Stay tuned.
>     >
>     >                 Thanks to Danny, Stephen, and Jerome for joining and
>     >                 contributing!
>     >
>     >                 Kind regards,
>     >
>     >                 Adam
>     >
>     >
>     >                 [1]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >                 [2]
>     https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
>     >                 [3]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>     >                 [4] https://ietf.webex.com/meet/sacm
>     >
>     >
>     >
>     > _______________________________________________
>     > sacm mailing list
>     > sacm@ietf.org <mailto:sacm@ietf.org>
>     > https://www.ietf.org/mailman/listinfo/sacm
>     >
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
>
> https://www.ietf.org/mailman/listinfo/sacm
>
>
>

--001a113f05f812dd250547dfe0b8
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thanks, Bill.=C2=A0 I agree with your thought process on t=
his.<div><br></div><div>And, to get back to Henk&#39;s questions, I have be=
en thinking of the endpoint repository as one piece of a larger endpoint ma=
nagement capability.=C2=A0 Whether that endpoint management capability acti=
vely or passively collects such endpoint state information is never explici=
tly stated in the vulnerability scenario.=C2=A0 However, I see that going b=
oth ways.</div><div><br></div><div>Also, I was suggesting that not all pool=
s of data would be redundant.=C2=A0 Endpoint repository doesn&#39;t have to=
 store assessment results any more than assessment results has to store eve=
ry detail about endpoints. =C2=A0</div><div><br></div><div><br></div></div>=
<br><div class=3D"gmail_quote"><div dir=3D"ltr">On Mon, Feb 6, 2017 at 8:17=
 AM Bill Munyan &lt;<a href=3D"mailto:bill.munyan.ietf@gmail.com">bill.muny=
an.ietf@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote"=
 style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><d=
iv dir=3D"ltr" class=3D"gmail_msg"><div class=3D"gmail_default gmail_msg" s=
tyle=3D"font-family:verdana,sans-serif">I wanted to clarify one assumption =
I have been making when viewing the diagram.=C2=A0 I am viewing the overall=
 vulnerability scenario as a series of event-driven use-cases, with this di=
agram simply depicting one of those use-cases: =C2=A0When new VDD is introd=
uced into the scenario. =C2=A0</div><div class=3D"gmail_default gmail_msg" =
style=3D"font-family:verdana,sans-serif"><br class=3D"gmail_msg"></div><div=
 class=3D"gmail_default gmail_msg" style=3D"font-family:verdana,sans-serif"=
>Feasibly, a number of different events could trigger entry into the vulner=
ability scenario, such as a &quot;staleness trigger&quot;, or a &quot;new e=
ndpoint added trigger&quot;, and many more.=C2=A0 Each of these events coul=
d (and should) have their own diagram outlining how the components interact=
 to request new/updated VDD, determine the endpoints which should be assess=
ed, and what to do with their results.=C2=A0 As such, each of the component=
s in the diagrams can be seen as conceptual, allowing for implementers to d=
etermine how best to consolidate components for their use.</div><div class=
=3D"gmail_default gmail_msg" style=3D"font-family:verdana,sans-serif"><br c=
lass=3D"gmail_msg"></div><div class=3D"gmail_default gmail_msg" style=3D"fo=
nt-family:verdana,sans-serif">Please bash my thought process if I&#39;m way=
 off on this, but I thought it might help in this discussion, because it se=
ems like some of the &quot;disagreement&quot; in the diagram is stemming fr=
om &quot;events&quot; which aren&#39;t necessarily applicable to this parti=
cular &quot;event use-case&quot;.</div><div class=3D"gmail_default gmail_ms=
g" style=3D"font-family:verdana,sans-serif"><br class=3D"gmail_msg"></div><=
div class=3D"gmail_default gmail_msg" style=3D"font-family:verdana,sans-ser=
if">Cheers,=C2=A0</div><div class=3D"gmail_default gmail_msg" style=3D"font=
-family:verdana,sans-serif">-Bill M.</div><div class=3D"gmail_default gmail=
_msg" style=3D"font-family:verdana,sans-serif"><br class=3D"gmail_msg"></di=
v></div><div class=3D"gmail_extra gmail_msg"><br class=3D"gmail_msg"><div c=
lass=3D"gmail_quote gmail_msg"></div></div><div class=3D"gmail_extra gmail_=
msg"><div class=3D"gmail_quote gmail_msg">On Fri, Feb 3, 2017 at 5:19 PM, H=
enk Birkholz <span dir=3D"ltr" class=3D"gmail_msg">&lt;<a href=3D"mailto:he=
nk.birkholz@sit.fraunhofer.de" class=3D"gmail_msg" target=3D"_blank">henk.b=
irkholz@sit.fraunhofer.de</a>&gt;</span> wrote:<br class=3D"gmail_msg"></di=
v></div><div class=3D"gmail_extra gmail_msg"><div class=3D"gmail_quote gmai=
l_msg"><blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8=
ex;border-left:1px #ccc solid;padding-left:1ex">Also inline. I hope it is s=
till readable.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
On 02/03/2017 10:55 PM, Adam Montville wrote:<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex">
Thanks for chiming in Henk.=C2=A0 I&#39;ll go inline.=C2=A0 Nothing being s=
aid as<br class=3D"gmail_msg">
chair.=C2=A0 Just making observations.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz<br class=3D"gmail_msg">
&lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D"gmail_msg" =
target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a><span class=3D"gmail_m=
sg"><br class=3D"gmail_msg">
&lt;mailto:<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" class=3D"gmai=
l_msg" target=3D"_blank">henk.birkholz@sit.fraunhofer.de</a>&gt;&gt; wrote:=
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Hi group,<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 to recap my understanding:<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 There will be trigger conditions that initiate collections of=
 fresh<br class=3D"gmail_msg">
=C2=A0 =C2=A0 endpoint attributes (from which endpoint posture can be deriv=
ed) from a<br class=3D"gmail_msg">
=C2=A0 =C2=A0 target endpoint.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 The obvious trigger condition that an asserting component (in=
 every<br class=3D"gmail_msg">
=C2=A0 =C2=A0 diagram, I think, that is the Vulnerability Assessor. This as=
sumption is<br class=3D"gmail_msg">
=C2=A0 =C2=A0 based on the interpretation of the diagram, not based on the =
name of the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 component). From my point of view, in order to assert that a =
known<br class=3D"gmail_msg">
=C2=A0 =C2=A0 record is, for example, &quot;stale&quot; (aka does not satis=
fy an declarative<br class=3D"gmail_msg">
=C2=A0 =C2=A0 guidance that expresses the quality of freshness) or, as anot=
her<br class=3D"gmail_msg">
=C2=A0 =C2=A0 example, is not yet created the Vulnerability Assessor requir=
es an<br class=3D"gmail_msg">
=C2=A0 =C2=A0 always up-to-date and exhaustive list of all Assessment Resul=
t records.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
I would disagree.=C2=A0 I have a record from the endpoint repository that i=
t<br class=3D"gmail_msg">
timestamped as 3 days old.=C2=A0 My policy says I should not rely on anythi=
ng<br class=3D"gmail_msg">
older than 2 days old.=C2=A0 Then the information is stale, and I instruct =
to<br class=3D"gmail_msg">
collect anew.<br class=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
If the &quot;I&quot; is the Vulnerability Assessor, how does it always have=
 the Assessment Result records to check that declarative guidance? Or do yo=
u propose (in v3) that the Endpoint Repository is checking that freshness c=
ontinuously and notifying the Vulnerability Assessor?<br class=3D"gmail_msg=
">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><span class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 In consequence, I would assume that either the the Assessment=
 Result<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Repository component collapses with the Vulnerability Assesso=
r or the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Vulnerability Assessor always retains a complete in-sync copy=
 of the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Assessment Result Repository.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
I would again disagree.=C2=A0 It may well be that actual software collapses=
<br class=3D"gmail_msg">
these components into one, but it may be that there is a results<br class=
=3D"gmail_msg">
repository, which is used downstream from vulnerability assessment, into<br=
 class=3D"gmail_msg">
which the assessor dumps results.<br class=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
Yes, downstream records are dumped as a result in the corresponding repo. B=
ut how does the information of not satisfying declarative guidance (a resul=
t got stale) makes it &quot;upstream&quot; again to trigger collection - in=
cluding imperative guidance what to collect (what just got stale)?<br class=
=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex">
<br class=3D"gmail_msg">
Consider when we have configuration assessment down the road.=C2=A0 Would w=
e<br class=3D"gmail_msg">
then have a vulnerability assessor and a configuration assessor each<br cla=
ss=3D"gmail_msg">
with their own repository conceptually, or would we be better off with<br c=
lass=3D"gmail_msg">
one &quot;results repository&quot;?=C2=A0 I think the one.<br class=3D"gmai=
l_msg">
</blockquote>
<br class=3D"gmail_msg">
It depends on scalability, I guess, but in the bare-bone first proof of con=
cept it seems to be feasible to collapse related pools of data into justthe=
 one, as there are no multiple consumers?<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex">
<br class=3D"gmail_msg">
In practice, applications can choose to implement more than one<br class=3D=
"gmail_msg">
conceptual component.<br class=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
Yes, that is why it is not a problem to collapse sets of functions into a s=
ingle component, in general. I hope this will remain a core feature of the =
architecture at all time.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><span class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Alternatively, the Assessment Result Repository component is =
collapsed<br class=3D"gmail_msg">
=C2=A0 =C2=A0 with the Endpoint Repository (as proposed in diagram v3), in =
which case<br class=3D"gmail_msg">
=C2=A0 =C2=A0 now the Vulnerability Assessor to retain an continuously in-s=
ync copy of<br class=3D"gmail_msg">
=C2=A0 =C2=A0 the Endpoint Repository? If it is to trigger on the &quot;sta=
le&quot; condition?<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
Again, I am not necessarily in favor of this viewpoint (and I&#39;m not<br =
class=3D"gmail_msg">
necessarily against).=C2=A0 The endpoint repository represents an interface=
<br class=3D"gmail_msg">
to acquire information about endpoints, which does not necessarily need<br =
class=3D"gmail_msg">
to include assessment results pertaining to those endpoints entirely.<br cl=
ass=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
But isn&#39;t that what is depicted in the diagram v3: the assessment resul=
ts repo is merged with endpoint repo? Maybe I am actually a little bit dens=
e right now :)<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><span class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 The &quot;keeping pools of data in-sync&quot; seems to be int=
roducing extra steps<br class=3D"gmail_msg">
=C2=A0 =C2=A0 in the work-flow.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
Is it really data in sync?=C2=A0 I understand what you&#39;re saying, but t=
o me<br class=3D"gmail_msg">
the endpoint repository component is where we find assertions about the<br =
class=3D"gmail_msg">
endpoints, the assessors take those assertions and apply some logic to<br c=
lass=3D"gmail_msg">
pass judgement on the endpoint, and that judgement is stored in the<br clas=
s=3D"gmail_msg">
assessment results repository component.<br class=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
I simply did not assume that a repository is more than a data store. If it =
does continuous assessments of endpoint records it contains, it most certai=
nly can trigger a collection. Maybe the label of the component is just misl=
eading me here.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><span class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 A pro for this would be that there could be multiple addition=
al<br class=3D"gmail_msg">
=C2=A0 =C2=A0 consumers of Assessment Results that justify an interface tha=
t provides<br class=3D"gmail_msg">
=C2=A0 =C2=A0 that data to multiple parties.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
Yes!=C2=A0 There are in practice.=C2=A0 Assessment results have downstream =
uses<br class=3D"gmail_msg">
outside the scope of our charter.<br class=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
I thought so, but it is of course not part of the single snapshot diagram a=
nd is therefore only implied at best.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><span class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 A con for this is the universal &quot;redundant data stores a=
lways pose a<br class=3D"gmail_msg">
=C2=A0 =C2=A0 source of complexity and hence risk of inconsistency&quot; ar=
gument.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Another point of view could be that the &quot;evaluation task=
&quot; is independent<br class=3D"gmail_msg">
=C2=A0 =C2=A0 from the &quot;trigger collection&quot; (I just made that one=
 up) task? Or maybe<br class=3D"gmail_msg">
=C2=A0 =C2=A0 it is associated with the worn component?<br class=3D"gmail_m=
sg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Multiple emerging architectures include an orchestration comp=
onent that<br class=3D"gmail_msg">
=C2=A0 =C2=A0 consumes notification of changes and derives appropriate acti=
ons that it<br class=3D"gmail_msg">
=C2=A0 =C2=A0 can trigger or even conduct. Please note, I am not advocating=
 to<br class=3D"gmail_msg">
=C2=A0 =C2=A0 introduce yet another component type (which would again add c=
omplexity,<br class=3D"gmail_msg">
=C2=A0 =C2=A0 error, scope creep...) :)<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
Bill mentioned something to me offline yesterday about orchestration.<br cl=
ass=3D"gmail_msg">
In the vulnerability scenario, the orchestration is really being<br class=
=3D"gmail_msg">
performed by the assessor.<br class=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
I think that in the reply above you illustrated that the Endpoint Repo also=
 does this assessment by checking for staleness? Or would it &quot;just&quo=
t; notify the Assessor to trigger a task? Why not trigger the collector dir=
ectly? What about the imperative guidance what to actually collect again?<b=
r class=3D"gmail_msg">
<br class=3D"gmail_msg">
It seems that I really have a difficult time to wrap my head around the pro=
posal still. Please stay patient with me! :)<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><span class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 I just try to get a feasible grasp of the actual workflow tha=
t the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 diagram is intended to represent.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
The most basic path through the system.<span class=3D"gmail_msg"><br class=
=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 What am I missing? I actually am surprised that the Assessmen=
t Result<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Repository merges with the Endpoint Repository and not the Vu=
lnerability<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Assessor. What is the advantage?<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg"></span>
I think we&#39;re still talking this one through.=C2=A0 What&#39;s the adva=
ntage to<br class=3D"gmail_msg">
collapsing them at all?<br class=3D"gmail_msg">
</blockquote>
<br class=3D"gmail_msg">
Collapsing redundant pools of data is reducing redundancy :) Tasks that dep=
end on data that has to be acquired to be conducted benefit from high avail=
ability and low latency. But I totally understand the &quot;multiple consum=
er&quot; argument.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<blockquote class=3D"gmail_quote gmail_msg" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><span class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Best,<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Henk<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
=C2=A0 =C2=A0 On 02/03/2017 05:43 PM, Adam Montville wrote:<br class=3D"gma=
il_msg">
=C2=A0 =C2=A0 &gt; I thought I&#39;d try to break this discussion out of it=
&#39;s former thread<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; into one of its own, in case that makes it easier for fo=
lks to opine.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; The list of &quot;components&quot; or &quot;function gro=
ups&quot; seems reasonable to me.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; In practice, there *may* be a desire to have that softwa=
re acting<br class=3D"gmail_msg">
=C2=A0 =C2=A0 as an<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; endpoint repository also act as the repository for asses=
sment results.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; Or, these could be implemented in distinct services.<br =
class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; What works for our purposes?<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; Adam<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; On Thu, Feb 2, 2017 at 10:40 AM Adam Montville<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" class=
=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto:=
<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" target=3D=
"_blank">adam.w.montville@gmail.com</a>&gt;<br class=3D"gmail_msg"></span>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><span class=
=3D"gmail_msg"><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;&gt;&gt=
; wrote:<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Once folks have had an opportunity to=
 review the vulnerability<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scenario information we&#39;ve been w=
orking on, what are your thoughts<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0on the main components we&#39;re pres=
ently focused on for this<br class=3D"gmail_msg">
=C2=A0 =C2=A0 narrowly<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scoped exercise?=C2=A0 These are:<br =
class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Detection Data Reposito=
ry<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Assessor<br class=3D"gm=
ail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint Repository<br class=3D"gmail=
_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Collector<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Assessment Result Repository<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0On Thu, Feb 2, 2017 at 10:28 AM Adam =
Montville<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montvill=
e@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.c=
om</a><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;<br cla=
ss=3D"gmail_msg"></span>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a><div class=
=3D"gmail_msg"><div class=3D"m_-216931544986182412h5 gmail_msg"><br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;&gt;&gt=
; wrote:<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi Everyone.=C2=A0 A fe=
w of us were able to make the vulnerability<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario call today and=
 I think we had a good, though at times<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0spirited, discussion.=
=C2=A0 We did record the meeting, which is<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0available at [1].=C2=A0=
 We discussed the attached (annotated with<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some meeting notes) UML=
-ish sequence diagram.=C2=A0 I had created<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that diagram to start a=
 conversation (mission accomplished on<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that front I think) -- =
a conversation that would lead us<br class=3D"gmail_msg">
=C2=A0 =C2=A0 toward<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0identifying the discret=
e components, interfaces, and<br class=3D"gmail_msg">
=C2=A0 =C2=A0 information<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0required to be sent ove=
r those interfaces.=C2=A0 The UML-ish<br class=3D"gmail_msg">
=C2=A0 =C2=A0 diagram<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0represents a *single* f=
low through the system -- a &quot;one-time&quot;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0flow through the system=
.=C2=A0 It ignores, for the time being, the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0continuous aspect of ou=
r charter in favor of getting started<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the basics.=C2=A0 =
Once we have a good understanding of the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0basics -- the component=
s, interfaces, and information required<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- we can start look at=
 a continuous monitoring sequence<br class=3D"gmail_msg">
=C2=A0 =C2=A0 (which<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0could be represented as=
 a distinct diagram) to determine what<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0more we need.=C2=A0 The=
n, I think, we can start drafting solutions.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0One of the first issues=
 is that we need to figure out if the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0components in the base =
flow are accurate.=C2=A0 The main suggestion<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0we&#39;ve tossed around=
 so far is to combine the Endpoint<br class=3D"gmail_msg">
=C2=A0 =C2=A0 Repository<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the Assessment Res=
ult Repository.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked briefly about=
 what interface we could use for<br class=3D"gmail_msg">
=C2=A0 =C2=A0 the VDD<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Repository, and natural=
ly ROLIE came up as an option.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked a little bit =
about the first &quot;get endpoints&quot;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 operation<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0between the Vulnerabili=
ty Assessor and the Endpoint Repository<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- specifically about w=
hether we should represent on this<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0sequence diagram that i=
nformation supporting a judgement of<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;stale&quot; would=
 be needed.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We left open the time w=
hen we would next meet, favoring to<br class=3D"gmail_msg">
=C2=A0 =C2=A0 work<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that out on-list.=C2=A0=
 Next week is TCG, so that may be difficult;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0the following week is R=
SA, so that may be difficult.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0For those who were in a=
ttendance today, please add to this<br class=3D"gmail_msg">
=C2=A0 =C2=A0 note<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with your comments/corr=
ections.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br class=3D"gmail_=
msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]<br class=3D"gmail_m=
sg">
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">htt=
ps://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Mon, Jan 30, 2017 at=
 11:21 AM Adam Montville<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:a=
dam.w.montville@gmail.com" class=3D"gmail_msg" target=3D"_blank">adam.w.mon=
tville@gmail.com</a><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;<br cla=
ss=3D"gmail_msg"></div></div>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto=
:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" target=
=3D"_blank">adam.w.montville@gmail.com</a>&gt;&gt;&gt;<span class=3D"gmail_=
msg"><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0wrote:<br class=3D"gmai=
l_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi everyo=
ne.=C2=A0 Just a friendly reminder that we are<br class=3D"gmail_msg">
=C2=A0 =C2=A0 planning<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0to meet a=
gain this Thursday at the same time (2/2 @ 10am<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Eastern/3=
pm UTC) using SACM&#39;s meeting room at<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=
=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" class=3D"gmail_msg=
" target=3D"_blank">https://ietf.webex.com/meet/sacm</a>.<br class=3D"gmail=
_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind rega=
rds,<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br c=
lass=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Thu, J=
an 19, 2017 at 11:35 AM Adam Montville<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a hr=
ef=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" target=3D"_bla=
nk">adam.w.montville@gmail.com</a><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;<br cla=
ss=3D"gmail_msg"></span>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;mailt=
o:<a href=3D"mailto:adam.w.montville@gmail.com" class=3D"gmail_msg" target=
=3D"_blank">adam.w.montville@gmail.com</a><div class=3D"gmail_msg"><div cla=
ss=3D"m_-216931544986182412h5 gmail_msg"><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" clas=
s=3D"gmail_msg" target=3D"_blank">adam.w.montville@gmail.com</a>&gt;&gt;&gt=
; wrote:<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Hello. A few of us met informally today to discuss the<br class=3D"gm=
ail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability scenario in some more detail with<br class=3D"gmail_msg=
">
=C2=A0 =C2=A0 the goal<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0of maintaining the narrow focus on a vulnerability<br class=3D"gmail_=
msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assessment slice through our notional environment.=C2=A0 We<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0are tending to look at major components as black boxes<br class=3D"gm=
ail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0with interfaces and data format expectations, and<br class=3D"gmail_m=
sg">
=C2=A0 =C2=A0 we are<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0not necessarily concerned with how those components do<br class=3D"gm=
ail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0things internally/behind the scenes.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The meeting was recorded (you can find it with today&#39;s<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0date at [1]).=C2=A0 The topic of discussion was<br class=3D"gmail_msg=
">
=C2=A0 =C2=A0 primarily in<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the &quot;phase 1&quot; area of what Danny sent to the list not<br cl=
ass=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0very long ago [2], and resulted in a *starting point*<br class=3D"gma=
il_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0diagram [3].<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The group who met today are (roughly) agreed on<br class=3D"gmail_msg=
">
=C2=A0 =C2=A0 the six<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0main &quot;components&quot; represented in that diagram, but<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 also<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0see that we have some work ahead.=C2=A0 Specifically, we<br class=3D"=
gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0quickly recognized that some of the assumptions the<br class=3D"gmail=
_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability draft makes may be assumptions we cannot<br class=3D"gm=
ail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0afford to make and need to include in the exploration.<br class=3D"gm=
ail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0We thought it would be a good idea to have another<br class=3D"gmail_=
msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0informal discussion in a couple of weeks (February<br class=3D"gmail_=
msg">
=C2=A0 =C2=A0 2) at<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the same time (10am Eastern / 3pm UTC), using the same<br class=3D"gm=
ail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0WebEx [4].=C2=A0 =C2=A0At that time we intend to roll<br class=3D"gma=
il_msg">
=C2=A0 =C2=A0 through the<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability assessment scenario assumptions in an<br class=3D"gmail=
_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0effort to determine which ones can be left as<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assumptions and which ones cannot.=C2=A0 Then we&#39;ll take<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0another look at the diagram and work on its next<br class=3D"gmail_ms=
g">
=C2=A0 =C2=A0 version.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Stay tuned.<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Thanks to Danny, Stephen, and Jerome for joining and<br class=3D"gmai=
l_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0contributing!<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Kind regards,<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Adam<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[1]<br class=3D"gmail_msg">
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">htt=
ps://drive.google.com/open?id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</a><br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[2]<br class=3D"gmail_msg">
=C2=A0 =C2=A0 <a href=3D"https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyv=
Aws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_bla=
nk">https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM<=
/a><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[3]<br class=3D"gmail_msg">
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU=
5pdTRjejJtNHc" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">htt=
ps://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNHc</a><br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[4] <a href=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" c=
lass=3D"gmail_msg" target=3D"_blank">https://ietf.webex.com/meet/sacm</a><b=
r class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; _______________________________________________<br class=
=3D"gmail_msg">
=C2=A0 =C2=A0 &gt; sacm mailing list<br class=3D"gmail_msg"></div></div>
=C2=A0 =C2=A0 &gt; <a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" tar=
get=3D"_blank">sacm@ietf.org</a> &lt;mailto:<a href=3D"mailto:sacm@ietf.org=
" class=3D"gmail_msg" target=3D"_blank">sacm@ietf.org</a>&gt;<br class=3D"g=
mail_msg">
=C2=A0 =C2=A0 &gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" r=
el=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">https://www.ietf.or=
g/mailman/listinfo/sacm</a><br class=3D"gmail_msg">
=C2=A0 =C2=A0 &gt;<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
</blockquote></blockquote></div></div><div class=3D"gmail_extra gmail_msg">=
<div class=3D"gmail_quote gmail_msg"><blockquote class=3D"gmail_quote gmail=
_msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1e=
x"><div class=3D"m_-216931544986182412HOEnZb gmail_msg"><div class=3D"m_-21=
6931544986182412h5 gmail_msg">
<br class=3D"gmail_msg">
_______________________________________________<br class=3D"gmail_msg">
sacm mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:sacm@ietf.org" class=3D"gmail_msg" target=3D"_blank">sacm=
@ietf.org</a><br class=3D"gmail_msg">
</div></div></blockquote></div></div><div class=3D"gmail_extra gmail_msg"><=
div class=3D"gmail_quote gmail_msg"><blockquote class=3D"gmail_quote gmail_=
msg" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex=
"><div class=3D"m_-216931544986182412HOEnZb gmail_msg"><div class=3D"m_-216=
931544986182412h5 gmail_msg"><a href=3D"https://www.ietf.org/mailman/listin=
fo/sacm" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">https://w=
ww.ietf.org/mailman/listinfo/sacm</a><br class=3D"gmail_msg">
</div></div></blockquote></div><br class=3D"gmail_msg"></div>
</blockquote></div>

--001a113f05f812dd250547dfe0b8--


From nobody Thu Feb  9 18:08:03 2017
Return-Path: <noreply@github.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B25A12966E for <sacm@ietfa.amsl.com>; Thu,  9 Feb 2017 18:08:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.367
X-Spam-Level: 
X-Spam-Status: No, score=-7.367 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, MISSING_HEADERS=1.021, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-1.887, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UQF6snPArD_C for <sacm@ietfa.amsl.com>; Thu,  9 Feb 2017 18:08:00 -0800 (PST)
Received: from github-smtp2b-ext-cp1-prd.iad.github.net (github-smtp2-ext3.iad.github.net [192.30.252.194]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0CC6A129664 for <sacm@ietf.org>; Thu,  9 Feb 2017 18:08:00 -0800 (PST)
Date: Thu, 09 Feb 2017 18:07:59 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1486692479; bh=cnpX8/wVmrHO6PisRUCrprbE3k5ZD2l9K3xgTXfcokI=; h=From:Subject:From; b=FcPDz7dquzbnJMNb53GfkyCgD6SXWR3wmerEwI0W8J/3SIZOBqwLVZmpmBGqOGU92 6gPbZm/EW6OU4NFNSKiaKEJkV++XQpfekKKMO0xUoU8I+Wte3J/hFxRar5IMzRqWeJ /yJrw8XQG1bli5xZ71aCh0jAFVV+8PdJT0I12czQ=
From: GitHub <noreply@github.com>
Message-ID: <589d207f37bd2_1cd693ffc08bd713c1051@github-api44-cp1-prd.iad.github.net.mail>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Auto-Response-Suppress: All
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/aAqq4MiaIe6Wklf0uVsn_11Ruws>
Subject: [sacm] [GitHub] A new public key was added to sacmwg/draft-ietf-sacm-coswid
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Feb 2017 02:08:01 -0000

The following SSH key was added to the sacmwg/draft-ietf-sacm-coswid repository by henkbirkholz:

CircleCI
13:b4:69:d2:4d:9a:e1:52:51:26:b3:a9:47:13:73:e0

If you believe this key was added in error, you can remove the key and disable
access at the following location:

https://github.com/sacmwg/draft-ietf-sacm-coswid/settings/keys


From nobody Sat Feb 11 01:37:18 2017
Return-Path: <prvs=208561b18=smansourfarag@expedia.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A9D1F1296F6; Sat, 11 Feb 2017 01:37:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.921
X-Spam-Level: 
X-Spam-Status: No, score=-6.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=expediacorp.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6Q1fJG4wqtNz; Sat, 11 Feb 2017 01:37:16 -0800 (PST)
Received: from mx1b.expedia.com (mx1b.expedia.com [216.251.112.223]) (using TLSv1.2 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E073C129468; Sat, 11 Feb 2017 01:37:15 -0800 (PST)
X-SRBS: None
X-HAT: Sender Group RELAYLIST, Policy $RELAYED applied.
X-MailPolicy: Default Outgoing Mail Policy
Received: from unknown (HELO CHCXEXCHMBX006.SEA.CORP.EXPECN.com) ([10.184.69.10]) by mx1b.sea.corp.expecn.com with ESMTP; 11 Feb 2017 01:37:14 -0800
Received: from CHCXEXCHEDG003.sea.corp.expecn.com (10.184.134.52) by CHCXEXCHMBX006.SEA.CORP.EXPECN.com (10.184.69.10) with Microsoft SMTP Server (TLS) id 15.0.1178.4; Sat, 11 Feb 2017 01:37:14 -0800
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (216.32.180.47) by edge.expedia.com (10.184.134.52) with Microsoft SMTP Server (TLS) id 15.0.1178.4; Sat, 11 Feb 2017 01:36:48 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=expediacorp.onmicrosoft.com; s=selector1-expedia-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=breDuE3KW+nEF11pyrwZLF4r0Ykct0cwsZ4TqFVx3Rk=; b=h6EDI5Ccsoo1rdVpTSCHC/vwezyyzkcr6t9RQqSHVjjKZ9VjqswSY8M/qn/wstAFXlslJSyZClrShj7n3S5waBprNX5Sm+M53PF8IaP1h4jp4PGijHVEQWolVZY8CxlWUoIw+ylJiQzR22YMMeO3Y6TraVNdV0QWhKzaJUonbAE=
Received: from BN1PR0201MB0802.namprd02.prod.outlook.com (10.160.170.147) by BN1PR0201MB0804.namprd02.prod.outlook.com (10.160.170.149) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.874.12; Sat, 11 Feb 2017 09:37:11 +0000
Received: from BN1PR0201MB0802.namprd02.prod.outlook.com ([10.160.170.147]) by BN1PR0201MB0802.namprd02.prod.outlook.com ([10.160.170.147]) with mapi id 15.01.0874.015; Sat, 11 Feb 2017 09:37:11 +0000
From: Sherif Mansour Farag <smansourfarag@expedia.com>
To: "sacm@ietf.org" <sacm@ietf.org>, "sacm-bounces@ietf.org" <sacm-bounces@ietf.org>
Thread-Topic: Knowledge sharing between SACM and OSQuery
Thread-Index: AQHShEprCAF1egpEa0uxVKx3bj7VMg==
Date: Sat, 11 Feb 2017 09:37:11 +0000
Message-ID: <BN1PR0201MB0802BFEA2927149C3F0403F8A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=smansourfarag@expedia.com; 
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [132.245.3.213]
x-ms-office365-filtering-correlation-id: 47b2b035-8050-42ca-ef0a-08d452618df6
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001); SRVR:BN1PR0201MB0804; 
x-microsoft-exchange-diagnostics: 1; BN1PR0201MB0804; 7:echFvm/Z2lZAK+jqGAyUWWL03+4G/d0qEYF6wlcKL+u+F9OBA22t2T9iu4H9XD0Jvo4n2QFD/13Xcm7MJtTvb5tcLhe9S2dfZtl8Z4YzXYhW7ThtNffKtWGoTlvZlRQJ2ZwUjpLAtQMA2OVCVvs+M/BE4VH7gAQKcNH9AVf4y7AW3aPNUeKnotrrybKEoVGo+pv3l1kF9ZMknYFl3mqgfx/5zEpvD71Fgm2f/aWeeLFIYmFBzgYFDCvh7T7mJWWCHTj0R8F/8bmcwdQ3RZ6jOoXj+1T/PIRfxLp5/L+R1Hc9RPgVNgOxpD/+v/GHcPLB/q9ZCl05IJPHnfpKRIu7v2/5CHB6NyYHZw1wJOZ9pPTveqT0Bfa4rOWiu7AxxqBkY8h9mbuHjHpMjRJrU4i/AAhWBwyk7LspJemT5d9uBFbivmPT7epuhsPAOuB6rdYn4uLXZTOLuLeLk6Fve6BEwDWbl2/eX0cAevJPt85DcYW1zxvJLRLf1/jqIUPz7fkS6lrny4ThTxWp8tlFwPS6Rw==; 20:E3UxHWYtdLSoCDbWQ7aD8NKukssJPeHDZge38uh56clsq4fJ6WPa17kZEKDhWZwiV1fXFfQmR8glyh3/jYT3EdxWEkmiaxAvxXKNYW9x5ho7wk1h+FrvJ1wZVkgZw75hRPXb22P4vSUhHll06/Lhuqom0hVWzBPJTEeHg4eO4aXGlzZDAnuxgMlsU39y+tjU3eJj2JiRrAUt65ufs9MwyXfKZGUfp6CIXI3qrJjNtdPNLTinL5ZofPqjyiZV483a
x-microsoft-antispam-prvs: <BN1PR0201MB0804A4D089C386D6D43C98E0A8470@BN1PR0201MB0804.namprd02.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(81227570615382);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6041248)(20161123555025)(20161123562025)(20161123564025)(20161123560025)(20161123558025)(6072148); SRVR:BN1PR0201MB0804; BCL:0; PCL:0; RULEID:; SRVR:BN1PR0201MB0804; 
x-forefront-prvs: 0215D7173F
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(7916002)(39450400003)(189002)(199003)(2900100001)(38730400002)(102836003)(106356001)(5660300001)(54356999)(105586002)(6116002)(7696004)(8676002)(7906003)(8936002)(3280700002)(106116001)(3660700001)(6506006)(81156014)(3846002)(74316002)(86362001)(305945005)(6436002)(77096006)(33656002)(54896002)(81166006)(99286003)(55016002)(606005)(6306002)(7736002)(101416001)(189998001)(50986999)(9686003)(92566002)(66066001)(122556002)(97736004)(25786008)(2906002)(53386004)(450100001)(2501003)(68736007)(53936002)(236005)(9030500004); DIR:OUT; SFP:1102; SCL:1; SRVR:BN1PR0201MB0804; H:BN1PR0201MB0802.namprd02.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_BN1PR0201MB0802BFEA2927149C3F0403F8A8470BN1PR0201MB0802_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Feb 2017 09:37:11.1667 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 79efa2e2-5409-4b35-9714-ada0138ee76c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN1PR0201MB0804
X-OriginatorOrg: expedia.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/tgH_KQx2xC_ZO59e7O0o_QgxHAo>
Subject: [sacm] Knowledge sharing between SACM and OSQuery
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 11 Feb 2017 09:37:18 -0000

--_000_BN1PR0201MB0802BFEA2927149C3F0403F8A8470BN1PR0201MB0802_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Apologies if you have already see this but has anyone reached out to OSQuer=
y.io<http://OSQuery.io> ? It's an open source solution created by Facebook =
to address some of the same challenges we are trying to slove. Might be wor=
th exchanging notes at the very least.

OSQuery provides Performant Endpoint Visibility:
osquery allows you to easily ask questions about your Linux, Windows, and O=
S X infrastructure. Whether your goal is intrusion detection, infrastructur=
e reliability, or compliance, osquery gives you the ability to empower and =
inform a broad set of organizations within your company.

The syntax is SQL-like, example:
osquery> SELECT uid, name FROM listening_ports l, processes p WHERE l.pid=
=3Dp.pid;

Here is a list of signals they can pull from an endpoint:
https://osquery.io/docs/tables/

And here are some "pre-canned" queries they have released:
https://osquery.io/docs/packs/

They are really nice BTW and I have asked them to include container introsp=
ection as well. The plan is to have that done in the next couple of weeks.

-Sherif

--_000_BN1PR0201MB0802BFEA2927149C3F0403F8A8470BN1PR0201MB0802_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
</head>
<body>
Apologies if you have already see this but has anyone reached out to <a dir=
=3D"ltr" href=3D"http://OSQuery.io" x-apple-data-detectors=3D"true" x-apple=
-data-detectors-type=3D"link" x-apple-data-detectors-result=3D"0">
OSQuery.io</a> ? It's an open source solution created by Facebook to addres=
s some of the same challenges we are trying to slove. Might be worth exchan=
ging notes at the very least.
<div><br>
</div>
<div>OSQuery provides Performant Endpoint Visibility:</div>
<div>osquery allows you to easily ask questions about your Linux, Windows, =
and OS X infrastructure. Whether your goal is intrusion detection, infrastr=
ucture reliability, or compliance, osquery gives you the ability to empower=
 and inform a broad set of organizations
 within your company.<br>
<br>
</div>
<div>The syntax is SQL-like, example:</div>
<div>osquery&gt; SELECT uid, name FROM listening_ports l, processes p WHERE=
 l.pid=3Dp.pid;</div>
<div><br>
</div>
<div>Here is a list of signals they can pull from an endpoint:</div>
<div><a dir=3D"ltr" href=3D"https://osquery.io/docs/tables/" x-apple-data-d=
etectors=3D"true" x-apple-data-detectors-type=3D"link" x-apple-data-detecto=
rs-result=3D"1">https://osquery.io/docs/tables/</a></div>
<div><br>
</div>
<div>And here are some &quot;pre-canned&quot; queries they have released:</=
div>
<div><a dir=3D"ltr" href=3D"https://osquery.io/docs/packs/" x-apple-data-de=
tectors=3D"true" x-apple-data-detectors-type=3D"link" x-apple-data-detector=
s-result=3D"2">https://osquery.io/docs/packs/</a></div>
<div><br>
</div>
<div>They are really nice BTW and I have asked them to include container in=
trospection as well. The plan is to have that done in the next couple of we=
eks.</div>
<div><br>
</div>
<div>-Sherif</div>
</body>
</html>

--_000_BN1PR0201MB0802BFEA2927149C3F0403F8A8470BN1PR0201MB0802_--


From nobody Sat Feb 11 05:02:15 2017
Return-Path: <athiasjerome@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC0031295E0 for <sacm@ietfa.amsl.com>; Sat, 11 Feb 2017 05:02:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id asQCgDaQ3fPt for <sacm@ietfa.amsl.com>; Sat, 11 Feb 2017 05:02:12 -0800 (PST)
Received: from mail-ua0-x233.google.com (mail-ua0-x233.google.com [IPv6:2607:f8b0:400c:c08::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E4A471295DA for <sacm@ietf.org>; Sat, 11 Feb 2017 05:02:11 -0800 (PST)
Received: by mail-ua0-x233.google.com with SMTP id 35so44920260uak.1 for <sacm@ietf.org>; Sat, 11 Feb 2017 05:02:11 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=GxjbuvKJYnOuJN5hnSAvkGDm3H90uzv2uNQsts+d8iY=; b=V6ZvRNOToQvgUPS8rlmrX5kqZI+esEmlJuKnbJFJl/KkwcKUj5Nc3i/K6NiRxTRKUs KQSeqcsAPzB7XmWnUUJqU3ggUn7VAeSvMkpjXIMOmcI+j2s2IO7Q3SsFPjWPED0uVXHF W7gRCxS+nmF2DJLfaBCK0HeSGYqMaZwPTcTh6+hDVoPDtlHYeRTQSGl3Zc1bgTmoPd2I zNsoXdjzvBtOnyLLO7EPr0rJmgJkc8HhJ8fyCO0cwlbqXUv9Fqcst3yn8S2CmJkDG7pP 314erzWY7jnlZWxUvVCRe10osFPFox5/kFeTdiIrtPqxrRsiV826zpbplH1oxhz05WrE YPVw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=GxjbuvKJYnOuJN5hnSAvkGDm3H90uzv2uNQsts+d8iY=; b=A5Bss/IahoU8CKNWqY2IXKuiUA1xSQL/UDad//qeikUmtayTtOJjaGxg9IPUMK+wBT 7uiqqiPwl7Nb9UfdJuKxSszT38XE9RYYxB6wx8GYrlh9yk8B3HXI2ux891x/GSBqMKxh erLQXH1e7be8tx2bewojZLHaJDLnJRhnBf7ihzpGaC4O2yj5U87nBiNFW62TxoIAlPLf aBjkIjhRaxZmDjdY5jJ4yOfzf5wME50vAG/5KggcN9TcYRiHmMn1pDYBfFJ1Re+eb8YI Sm4fkql8WDyj6S1bulG3ckRPPN1YyWVTdc4/4tCO2j4BIU/4kDpkFy5xjR+z4wICScAT shfQ==
X-Gm-Message-State: AMke39n3EDEt76mi2iUMtyYCAcDUShMe8KDFqXEHeFZKT3z0RDlaGsKgWzJLdU9XTVDPZ28X6/9qHz7G16XEAQ==
X-Received: by 10.176.85.26 with SMTP id t26mr6117675uaa.1.1486818130669; Sat, 11 Feb 2017 05:02:10 -0800 (PST)
MIME-Version: 1.0
Received: by 10.31.160.14 with HTTP; Sat, 11 Feb 2017 05:02:10 -0800 (PST)
In-Reply-To: <BN1PR0201MB0802BFEA2927149C3F0403F8A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>
References: <BN1PR0201MB0802BFEA2927149C3F0403F8A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>
From: Jerome Athias <athiasjerome@gmail.com>
Date: Sat, 11 Feb 2017 16:02:10 +0300
Message-ID: <CAA=AuEfG8ZpU5=mePkdMb3z+bbp1vfcK3rFSkh53s65zKYzT-Q@mail.gmail.com>
To: Sherif Mansour Farag <smansourfarag@expedia.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/46r8q6OP4qLS2Ys0dlRsLI0zbw4>
Cc: "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Knowledge sharing between SACM and OSQuery
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 11 Feb 2017 13:02:14 -0000

Sherif,

I get your point...
It's one 'implementation' (one cool technical tool, easy to use by
technicians, that just 'works'). Probably very cool and powerful, yes
(and we need things like this)
However...

This is (still/again) not based on a proper Ontology. (but can help to
complete one)
Leading to another Language, a non mature/structured, nor strict, 'data model'
e.g.: redundancy in the "sql schema", very simple types, etc.
(I'm not objective there, but the SQL-like approach is interesting* :p)

Yet for sure it's interesting, but MUST use (and may be used to
complete) more structured/mature data models for providing improved
Interoperability (and covering more use cases) for better Automation
(especially M2M).

That would help if they could use/improve something more structured
like MILE or OASIS CTI CybOX objects Models
Ref. https://cyboxproject.github.io/documentation/objects/ (not latest
version... but hopefully illustrates the point)
That would help to leverage the tool (as an embedded data model) in a
more global (interoperable/compatible) and efficient Model/Ontology.
* e.g.: https://github.com/athiasjerome/XORCISM/tree/master/MODELS


On Sat, Feb 11, 2017 at 12:37 PM, Sherif Mansour Farag
<smansourfarag@expedia.com> wrote:
> Apologies if you have already see this but has anyone reached out to
> OSQuery.io ? It's an open source solution created by Facebook to address
> some of the same challenges we are trying to slove. Might be worth
> exchanging notes at the very least.
>
> OSQuery provides Performant Endpoint Visibility:
> osquery allows you to easily ask questions about your Linux, Windows, and OS
> X infrastructure. Whether your goal is intrusion detection, infrastructure
> reliability, or compliance, osquery gives you the ability to empower and
> inform a broad set of organizations within your company.
>
> The syntax is SQL-like, example:
> osquery> SELECT uid, name FROM listening_ports l, processes p WHERE
> l.pid=p.pid;
>
> Here is a list of signals they can pull from an endpoint:
> https://osquery.io/docs/tables/
>
> And here are some "pre-canned" queries they have released:
> https://osquery.io/docs/packs/
>
> They are really nice BTW and I have asked them to include container
> introspection as well. The plan is to have that done in the next couple of
> weeks.
>
> -Sherif
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>


From nobody Sat Feb 11 05:16:49 2017
Return-Path: <prvs=208561b18=smansourfarag@expedia.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6139612961D for <sacm@ietfa.amsl.com>; Sat, 11 Feb 2017 05:16:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.921
X-Spam-Level: 
X-Spam-Status: No, score=-6.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=expediacorp.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id paI6pUWCWyuX for <sacm@ietfa.amsl.com>; Sat, 11 Feb 2017 05:16:44 -0800 (PST)
Received: from mx1a.expedia.com (mx1a.expedia.com [216.251.112.221]) (using TLSv1.2 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A71261293DB for <sacm@ietf.org>; Sat, 11 Feb 2017 05:16:44 -0800 (PST)
X-SRBS: None
X-HAT: Sender Group RELAYLIST, Policy $RELAYED applied.
X-MailPolicy: Default Outgoing Mail Policy
Received: from unknown (HELO CHCXEXCHMBX006.SEA.CORP.EXPECN.com) ([10.184.69.10]) by mx1a.sea.corp.expecn.com with ESMTP; 11 Feb 2017 05:16:43 -0800
Received: from CHCXEXCHEDG003.sea.corp.expecn.com (10.184.134.52) by CHCXEXCHMBX006.SEA.CORP.EXPECN.com (10.184.69.10) with Microsoft SMTP Server (TLS) id 15.0.1178.4; Sat, 11 Feb 2017 05:16:43 -0800
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (207.46.163.116) by edge.expedia.com (10.184.134.52) with Microsoft SMTP Server (TLS) id 15.0.1178.4; Sat, 11 Feb 2017 05:16:16 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=expediacorp.onmicrosoft.com; s=selector1-expedia-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=yX0LBENgbPvKEBRX9otgNNl4XBYcWZGehy6WxruUIAM=; b=bsmLLvV0+H8kWYivVsSqzvwdQrGr6UzceihZ3tAeNbt4WUikD6eO3NAvJIN8dufD4BK4Nqzwm6XhFQJ+yy2rPRIAhME8Zbc0npASt7yeL0e5ztW6aYyU92ErCmu48YGyyjPPere71VMLqeMnES/55Za0L2ipGZYsjB7m1Xp6D+I=
Received: from BN1PR0201MB0802.namprd02.prod.outlook.com (10.160.170.147) by BN1PR0201MB0802.namprd02.prod.outlook.com (10.160.170.147) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.874.12; Sat, 11 Feb 2017 13:16:41 +0000
Received: from BN1PR0201MB0802.namprd02.prod.outlook.com ([10.160.170.147]) by BN1PR0201MB0802.namprd02.prod.outlook.com ([10.160.170.147]) with mapi id 15.01.0874.015; Sat, 11 Feb 2017 13:16:41 +0000
From: Sherif Mansour Farag <smansourfarag@expedia.com>
To: Jerome Athias <athiasjerome@gmail.com>
Thread-Topic: [sacm] Knowledge sharing between SACM and OSQuery
Thread-Index: AQHShEprCAF1egpEa0uxVKx3bj7VMqFjxYcAgAAEDQQ=
Date: Sat, 11 Feb 2017 13:16:40 +0000
Message-ID: <BN1PR0201MB0802906FA040E64E3A45AC51A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>
References: <BN1PR0201MB0802BFEA2927149C3F0403F8A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>, <CAA=AuEfG8ZpU5=mePkdMb3z+bbp1vfcK3rFSkh53s65zKYzT-Q@mail.gmail.com>
In-Reply-To: <CAA=AuEfG8ZpU5=mePkdMb3z+bbp1vfcK3rFSkh53s65zKYzT-Q@mail.gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=smansourfarag@expedia.com; 
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [132.245.3.213]
x-ms-office365-filtering-correlation-id: 08cea4ac-9ff1-4c27-753e-08d4528037da
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001); SRVR:BN1PR0201MB0802; 
x-microsoft-exchange-diagnostics: 1; BN1PR0201MB0802; 7:pO417tTxFtajgLnH5zAeJ809OQMN+ozbtJjCYZitFHbBuKm8Umg+fG7selZy8igcGNtMUYdZhWMqa94vaVxl2MlL1f2YE44RumQgTkGDk6mmfpgxsi3vEaN4rcHOQkCw9HGQQ6lWMzq0d0FHqW4lmHl8nvta3g3nAjQ7vjmQGtOxdQmDQCc/l3PhI6dfsLrGgVk5QmpHyrQlTQ7ubEU5yrwEUcZuwnop45PQlVZu1tpTI6iLO2DD8nyBR0XLv4MJB45oRqeC8qbnN5901b3dcmJeMlqM/D/ZcUs3Ia8dMcB4/wu6bJGnragzCQdSfeRGu8LYPfIRgRFTPDqaO9nlK39hRMz9GuAJBb/XHXZ6ZVNrwScgM+eIADnQXHMxaSdw11R0OpfxTGdQd//z9xpPGFM/uFXfmQxofbMlKWTT8sbYT5QUx5jwaPp5ZJnnca9+iDWgugR1kNJbhD53fMufdx8hFhadmet6tS0yN//lIgZvAb2qXkU9c3ZvKf7a1TgJMKI2yIwu/d5CyAZ6wdgxKg==; 20:NLpf0iPg2wm+EmZXgkLFKmPYxfxQpgDiL3nYCgSExiKMnBKtXhTo+39+OxfpWXNlK7+HiKJ0sYJtvrQg9PcxaW44aJtlzhfsgoB+BoRDrlQx63nvd16dMClEBEK/UXl3ei2SzvasEldR8L20mh2sSgLRchAqPmWo4t+epLntmTUoJMDM3p5HoPINlWF9gBt1eGbJ+JzIkuFoWe6r8JckZtidbeJeHTQW40lgX6dt/IMsQm5vuWTybRWLdYxjtf+H
x-microsoft-antispam-prvs: <BN1PR0201MB08020C5291526FCDDB84F326A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(158342451672863)(166708455590820)(256989393225994)(81227570615382); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(5005006)(8121501046)(10201501046)(3002001)(6041248)(20161123560025)(20161123562025)(20161123555025)(20161123564025)(20161123558025)(6072148); SRVR:BN1PR0201MB0802; BCL:0; PCL:0; RULEID:; SRVR:BN1PR0201MB0802; 
x-forefront-prvs: 0215D7173F
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(7916002)(39450400003)(24454002)(377454003)(199003)(189002)(33656002)(8676002)(3846002)(2950100002)(189998001)(9686003)(7696004)(50986999)(6916009)(3660700001)(1411001)(105586002)(6116002)(74316002)(68736007)(55016002)(92566002)(229853002)(7906003)(4326007)(54356999)(101416001)(77096006)(53936002)(76176999)(5660300001)(7736002)(106116001)(25786008)(2906002)(606005)(6436002)(38730400002)(106356001)(86362001)(102836003)(110136004)(99286003)(54896002)(66066001)(53546003)(122556002)(6306002)(6246003)(97736004)(81166006)(3280700002)(81156014)(2900100001)(39060400001)(236005)(8936002)(6506006)(9030500004); DIR:OUT; SFP:1102; SCL:1; SRVR:BN1PR0201MB0802; H:BN1PR0201MB0802.namprd02.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_BN1PR0201MB0802906FA040E64E3A45AC51A8470BN1PR0201MB0802_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Feb 2017 13:16:40.4241 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 79efa2e2-5409-4b35-9714-ada0138ee76c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN1PR0201MB0802
X-OriginatorOrg: expedia.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/qdOMAvoJcWw3t_3cA8Fp5lAtv7c>
Cc: "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Knowledge sharing between SACM and OSQuery
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 11 Feb 2017 13:16:46 -0000

--_000_BN1PR0201MB0802906FA040E64E3A45AC51A8470BN1PR0201MB0802_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Jason,
Agree completely at the very most I' suggesting that both teams exchange no=
tes I think it might be worth it. I.e. We get some pointers on prodictionis=
ed and a battle hardened solution vs. What would be the ideal.

I think it would be benifitical to talk to get their info in the challenges=
 they faced vs. Some of the long term issues we are trying to solve for.

Also some rfc's codefied what is already out there vs. What has been agreed=
 (cookies come to mind), not suggesting that will happen, but it does pay t=
o look at how other have solved & implemented some of these challenges.

Knowledge sharing never hurt.
Who knows they might be the first team to implement sacm in full.

-Sherif
________________________________
From: Jerome Athias <athiasjerome@gmail.com>
Sent: Saturday, February 11, 2017 3:02:10 PM
To: Sherif Mansour Farag
Cc: sacm@ietf.org
Subject: Re: [sacm] Knowledge sharing between SACM and OSQuery

Sherif,

I get your point...
It's one 'implementation' (one cool technical tool, easy to use by
technicians, that just 'works'). Probably very cool and powerful, yes
(and we need things like this)
However...

This is (still/again) not based on a proper Ontology. (but can help to
complete one)
Leading to another Language, a non mature/structured, nor strict, 'data mod=
el'
e.g.: redundancy in the "sql schema", very simple types, etc.
(I'm not objective there, but the SQL-like approach is interesting* :p)

Yet for sure it's interesting, but MUST use (and may be used to
complete) more structured/mature data models for providing improved
Interoperability (and covering more use cases) for better Automation
(especially M2M).

That would help if they could use/improve something more structured
like MILE or OASIS CTI CybOX objects Models
Ref. https://cyboxproject.github.io/documentation/objects/ (not latest
version... but hopefully illustrates the point)
That would help to leverage the tool (as an embedded data model) in a
more global (interoperable/compatible) and efficient Model/Ontology.
* e.g.: https://github.com/athiasjerome/XORCISM/tree/master/MODELS


On Sat, Feb 11, 2017 at 12:37 PM, Sherif Mansour Farag
<smansourfarag@expedia.com> wrote:
> Apologies if you have already see this but has anyone reached out to
> OSQuery.io ? It's an open source solution created by Facebook to address
> some of the same challenges we are trying to slove. Might be worth
> exchanging notes at the very least.
>
> OSQuery provides Performant Endpoint Visibility:
> osquery allows you to easily ask questions about your Linux, Windows, and=
 OS
> X infrastructure. Whether your goal is intrusion detection, infrastructur=
e
> reliability, or compliance, osquery gives you the ability to empower and
> inform a broad set of organizations within your company.
>
> The syntax is SQL-like, example:
> osquery> SELECT uid, name FROM listening_ports l, processes p WHERE
> l.pid=3Dp.pid;
>
> Here is a list of signals they can pull from an endpoint:
> https://osquery.io/docs/tables/
>
> And here are some "pre-canned" queries they have released:
> https://osquery.io/docs/packs/
>
> They are really nice BTW and I have asked them to include container
> introspection as well. The plan is to have that done in the next couple o=
f
> weeks.
>
> -Sherif
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>

--_000_BN1PR0201MB0802906FA040E64E3A45AC51A8470BN1PR0201MB0802_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; pad=
ding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>Hi Jason,
<div>Agree completely at the very most I' suggesting that both teams exchan=
ge notes I think it might be worth it. I.e. We get some pointers on prodict=
ionised and a battle hardened solution vs. What would be the ideal.<br>
</div>
<div><br>
</div>
<div>I think it would be benifitical to talk to get their info in the chall=
enges they faced vs. Some of the long term issues we are trying to solve fo=
r.</div>
<div><br>
</div>
<div>Also some rfc's codefied what is already out there vs. What has been a=
greed (cookies come to mind), not suggesting that will happen, but it does =
pay to look at how other have solved &amp; implemented some of these challe=
nges.</div>
<div><br>
</div>
<div>Knowledge sharing never hurt.</div>
<div>Who knows they might be the first team to implement sacm in full.<br>
<br>
</div>
<div>-Sherif</div>
<hr tabindex=3D"-1" style=3D"display:inline-block; width:98%">
<div id=3D"x_divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" =
color=3D"#000000" style=3D"font-size:11pt"><b>From:</b> Jerome Athias &lt;a=
thiasjerome@gmail.com&gt;<br>
<b>Sent:</b> Saturday, February 11, 2017 3:02:10 PM<br>
<b>To:</b> Sherif Mansour Farag<br>
<b>Cc:</b> sacm@ietf.org<br>
<b>Subject:</b> Re: [sacm] Knowledge sharing between SACM and OSQuery</font=
>
<div>&nbsp;</div>
</div>
</div>
<font size=3D"2"><span style=3D"font-size:10pt;">
<div class=3D"PlainText">Sherif,<br>
<br>
I get your point...<br>
It's one 'implementation' (one cool technical tool, easy to use by<br>
technicians, that just 'works'). Probably very cool and powerful, yes<br>
(and we need things like this)<br>
However...<br>
<br>
This is (still/again) not based on a proper Ontology. (but can help to<br>
complete one)<br>
Leading to another Language, a non mature/structured, nor strict, 'data mod=
el'<br>
e.g.: redundancy in the &quot;sql schema&quot;, very simple types, etc.<br>
(I'm not objective there, but the SQL-like approach is interesting* :p)<br>
<br>
Yet for sure it's interesting, but MUST use (and may be used to<br>
complete) more structured/mature data models for providing improved<br>
Interoperability (and covering more use cases) for better Automation<br>
(especially M2M).<br>
<br>
That would help if they could use/improve something more structured<br>
like MILE or OASIS CTI CybOX objects Models<br>
Ref. <a href=3D"https://cyboxproject.github.io/documentation/objects/">http=
s://cyboxproject.github.io/documentation/objects/</a> (not latest<br>
version... but hopefully illustrates the point)<br>
That would help to leverage the tool (as an embedded data model) in a<br>
more global (interoperable/compatible) and efficient Model/Ontology.<br>
* e.g.: <a href=3D"https://github.com/athiasjerome/XORCISM/tree/master/MODE=
LS">https://github.com/athiasjerome/XORCISM/tree/master/MODELS</a><br>
<br>
<br>
On Sat, Feb 11, 2017 at 12:37 PM, Sherif Mansour Farag<br>
&lt;smansourfarag@expedia.com&gt; wrote:<br>
&gt; Apologies if you have already see this but has anyone reached out to<b=
r>
&gt; OSQuery.io ? It's an open source solution created by Facebook to addre=
ss<br>
&gt; some of the same challenges we are trying to slove. Might be worth<br>
&gt; exchanging notes at the very least.<br>
&gt;<br>
&gt; OSQuery provides Performant Endpoint Visibility:<br>
&gt; osquery allows you to easily ask questions about your Linux, Windows, =
and OS<br>
&gt; X infrastructure. Whether your goal is intrusion detection, infrastruc=
ture<br>
&gt; reliability, or compliance, osquery gives you the ability to empower a=
nd<br>
&gt; inform a broad set of organizations within your company.<br>
&gt;<br>
&gt; The syntax is SQL-like, example:<br>
&gt; osquery&gt; SELECT uid, name FROM listening_ports l, processes p WHERE=
<br>
&gt; l.pid=3Dp.pid;<br>
&gt;<br>
&gt; Here is a list of signals they can pull from an endpoint:<br>
&gt; <a href=3D"https://osquery.io/docs/tables/">https://osquery.io/docs/ta=
bles/</a><br>
&gt;<br>
&gt; And here are some &quot;pre-canned&quot; queries they have released:<b=
r>
&gt; <a href=3D"https://osquery.io/docs/packs/">https://osquery.io/docs/pac=
ks/</a><br>
&gt;<br>
&gt; They are really nice BTW and I have asked them to include container<br=
>
&gt; introspection as well. The plan is to have that done in the next coupl=
e of<br>
&gt; weeks.<br>
&gt;<br>
&gt; -Sherif<br>
&gt;<br>
&gt; _______________________________________________<br>
&gt; sacm mailing list<br>
&gt; sacm@ietf.org<br>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm">https://www.iet=
f.org/mailman/listinfo/sacm</a><br>
&gt;<br>
</div>
</span></font>
</body>
</html>

--_000_BN1PR0201MB0802906FA040E64E3A45AC51A8470BN1PR0201MB0802_--


From nobody Sat Feb 11 05:55:59 2017
Return-Path: <athiasjerome@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE0D0129451 for <sacm@ietfa.amsl.com>; Sat, 11 Feb 2017 05:55:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.698
X-Spam-Level: 
X-Spam-Status: No, score=-2.698 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 03j8KGAXGH1R for <sacm@ietfa.amsl.com>; Sat, 11 Feb 2017 05:55:57 -0800 (PST)
Received: from mail-vk0-x232.google.com (mail-vk0-x232.google.com [IPv6:2607:f8b0:400c:c05::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0087F129527 for <sacm@ietf.org>; Sat, 11 Feb 2017 05:55:56 -0800 (PST)
Received: by mail-vk0-x232.google.com with SMTP id r136so41465673vke.1 for <sacm@ietf.org>; Sat, 11 Feb 2017 05:55:56 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=ls06nhpr9F7y6kxIurFdmYMjANTNLP3+XZTHB+eJuXE=; b=KytZK58nlCMj8c14qewKqxiZuEGZTWeMyCWzXJcr35YQ2yVjaXIZ3feg3FTKoaYlWi 3vzmebJJr8uiqrofmn4dOkvEqkAD81TXCAkao0JiK7hy6ZwSC8ceov/+M8uDcJ9ybLt3 nQEI2s25M1fPsUf812wiJfzLBTxBo7uWla966hNipoAihT9RrzKGMajfCzLToflTBsut JkwX0ke4LK8NdOxBPvjpPHkXeh1udC2J/HXHYjjZ4Jbavu6MrI9LDStYJ/lVe1E/fIyO fJpSTmKzithv6SWSRWyCjpaNhxXSajBG/6y3bLd32rLdrX4qTsW+hobGYbUTBwvlmsOb aJBA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=ls06nhpr9F7y6kxIurFdmYMjANTNLP3+XZTHB+eJuXE=; b=omI+n4Lf0s8j2NAKtPVUsidMpkEcVgVjqqCHAikMrGuiTyWQyJ+PNoGlPblTNO0PcI wjLNB6gjOy7Y57iXU92o4i2KUsE5pP8U99/71CmkJwg1zzzavox14Y9k4o3TUDDHyjBx 5PZtw9/lu5yZoaVMCgtQRT1+PEH6sUmX2wM4gRQ3euhMZsFzD+DrFSAp5qJEgxl6cPJx J79y3NGCFqBffIFRmC2qhrK7JkGVLeYbTcQLpprbS1eddHRMfjLjhHsGjIBY8Lrqr+49 Llc0OhGyMxXq21V7UvY8DKl3723dQZtbhcjEIKCpfjIkPrV05hDHcxOm1gdGtpoG2lPA 9hQQ==
X-Gm-Message-State: AMke39ktkCmTo53a/IsnoryodhZMT2ekickKJ7fvqP5A/uWJSwBef3fNtMq/hgL+21dSRappHoD5GW4KC1Fl5A==
X-Received: by 10.31.4.211 with SMTP id 202mr7025701vke.105.1486821355993; Sat, 11 Feb 2017 05:55:55 -0800 (PST)
MIME-Version: 1.0
Received: by 10.31.160.14 with HTTP; Sat, 11 Feb 2017 05:55:55 -0800 (PST)
In-Reply-To: <BN1PR0201MB0802906FA040E64E3A45AC51A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>
References: <BN1PR0201MB0802BFEA2927149C3F0403F8A8470@BN1PR0201MB0802.namprd02.prod.outlook.com> <CAA=AuEfG8ZpU5=mePkdMb3z+bbp1vfcK3rFSkh53s65zKYzT-Q@mail.gmail.com> <BN1PR0201MB0802906FA040E64E3A45AC51A8470@BN1PR0201MB0802.namprd02.prod.outlook.com>
From: Jerome Athias <athiasjerome@gmail.com>
Date: Sat, 11 Feb 2017 16:55:55 +0300
Message-ID: <CAA=AuEd86t=2N_6oJNGcX+fkcbrMW7JDJNm+5NRH1zYV8usQwg@mail.gmail.com>
To: Sherif Mansour Farag <smansourfarag@expedia.com>
Content-Type: multipart/alternative; boundary=001a11429d6ec4c0e905484192d9
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/h2A91lSTsxSQ883CuGQC7whffVU>
Cc: "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Knowledge sharing between SACM and OSQuery
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 11 Feb 2017 13:55:58 -0000

--001a11429d6ec4c0e905484192d9
Content-Type: text/plain; charset=UTF-8

Sure

On Sat, Feb 11, 2017 at 4:16 PM, Sherif Mansour Farag <
smansourfarag@expedia.com> wrote:

> Hi Jason,
> Agree completely at the very most I' suggesting that both teams exchange
> notes I think it might be worth it. I.e. We get some pointers on
> prodictionised and a battle hardened solution vs. What would be the ideal.
>
> I think it would be benifitical to talk to get their info in the
> challenges they faced vs. Some of the long term issues we are trying to
> solve for.
>
> Also some rfc's codefied what is already out there vs. What has been
> agreed (cookies come to mind), not suggesting that will happen, but it does
> pay to look at how other have solved & implemented some of these challenges.
>
> Knowledge sharing never hurt.
> Who knows they might be the first team to implement sacm in full.
>
> -Sherif
> ------------------------------
> *From:* Jerome Athias <athiasjerome@gmail.com>
> *Sent:* Saturday, February 11, 2017 3:02:10 PM
> *To:* Sherif Mansour Farag
> *Cc:* sacm@ietf.org
> *Subject:* Re: [sacm] Knowledge sharing between SACM and OSQuery
>
> Sherif,
>
> I get your point...
> It's one 'implementation' (one cool technical tool, easy to use by
> technicians, that just 'works'). Probably very cool and powerful, yes
> (and we need things like this)
> However...
>
> This is (still/again) not based on a proper Ontology. (but can help to
> complete one)
> Leading to another Language, a non mature/structured, nor strict, 'data
> model'
> e.g.: redundancy in the "sql schema", very simple types, etc.
> (I'm not objective there, but the SQL-like approach is interesting* :p)
>
> Yet for sure it's interesting, but MUST use (and may be used to
> complete) more structured/mature data models for providing improved
> Interoperability (and covering more use cases) for better Automation
> (especially M2M).
>
> That would help if they could use/improve something more structured
> like MILE or OASIS CTI CybOX objects Models
> Ref. https://cyboxproject.github.io/documentation/objects/ (not latest
> version... but hopefully illustrates the point)
> That would help to leverage the tool (as an embedded data model) in a
> more global (interoperable/compatible) and efficient Model/Ontology.
> * e.g.: https://github.com/athiasjerome/XORCISM/tree/master/MODELS
>
>
> On Sat, Feb 11, 2017 at 12:37 PM, Sherif Mansour Farag
> <smansourfarag@expedia.com> wrote:
> > Apologies if you have already see this but has anyone reached out to
> > OSQuery.io ? It's an open source solution created by Facebook to address
> > some of the same challenges we are trying to slove. Might be worth
> > exchanging notes at the very least.
> >
> > OSQuery provides Performant Endpoint Visibility:
> > osquery allows you to easily ask questions about your Linux, Windows,
> and OS
> > X infrastructure. Whether your goal is intrusion detection,
> infrastructure
> > reliability, or compliance, osquery gives you the ability to empower and
> > inform a broad set of organizations within your company.
> >
> > The syntax is SQL-like, example:
> > osquery> SELECT uid, name FROM listening_ports l, processes p WHERE
> > l.pid=p.pid;
> >
> > Here is a list of signals they can pull from an endpoint:
> > https://osquery.io/docs/tables/
> >
> > And here are some "pre-canned" queries they have released:
> > https://osquery.io/docs/packs/
> >
> > They are really nice BTW and I have asked them to include container
> > introspection as well. The plan is to have that done in the next couple
> of
> > weeks.
> >
> > -Sherif
> >
> > _______________________________________________
> > sacm mailing list
> > sacm@ietf.org
> > https://www.ietf.org/mailman/listinfo/sacm
> >
>

--001a11429d6ec4c0e905484192d9
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Sure</div><div class=3D"gmail_extra"><br><div class=3D"gma=
il_quote">On Sat, Feb 11, 2017 at 4:16 PM, Sherif Mansour Farag <span dir=
=3D"ltr">&lt;<a href=3D"mailto:smansourfarag@expedia.com" target=3D"_blank"=
>smansourfarag@expedia.com</a>&gt;</span> wrote:<br><blockquote class=3D"gm=
ail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-le=
ft:1ex">





<div>
<div>Hi Jason,
<div>Agree completely at the very most I&#39; suggesting that both teams ex=
change notes I think it might be worth it. I.e. We get some pointers on pro=
dictionised and a battle hardened solution vs. What would be the ideal.<br>
</div>
<div><br>
</div>
<div>I think it would be benifitical to talk to get their info in the chall=
enges they faced vs. Some of the long term issues we are trying to solve fo=
r.</div>
<div><br>
</div>
<div>Also some rfc&#39;s codefied what is already out there vs. What has be=
en agreed (cookies come to mind), not suggesting that will happen, but it d=
oes pay to look at how other have solved &amp; implemented some of these ch=
allenges.</div>
<div><br>
</div>
<div>Knowledge sharing never hurt.</div>
<div>Who knows they might be the first team to implement sacm in full.<br>
<br>
</div>
<div>-Sherif</div>
<hr style=3D"display:inline-block;width:98%">
<div id=3D"m_-470359191153686102x_divRplyFwdMsg" dir=3D"ltr"><font face=3D"=
Calibri, sans-serif" color=3D"#000000" style=3D"font-size:11pt"><b>From:</b=
> Jerome Athias &lt;<a href=3D"mailto:athiasjerome@gmail.com" target=3D"_bl=
ank">athiasjerome@gmail.com</a>&gt;<br>
<b>Sent:</b> Saturday, February 11, 2017 3:02:10 PM<br>
<b>To:</b> Sherif Mansour Farag<br>
<b>Cc:</b> <a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org=
</a><br>
<b>Subject:</b> Re: [sacm] Knowledge sharing between SACM and OSQuery</font=
>
<div>=C2=A0</div>
</div>
</div><div><div class=3D"h5">
<font size=3D"2"><span style=3D"font-size:10pt">
<div class=3D"m_-470359191153686102PlainText">Sherif,<br>
<br>
I get your point...<br>
It&#39;s one &#39;implementation&#39; (one cool technical tool, easy to use=
 by<br>
technicians, that just &#39;works&#39;). Probably very cool and powerful, y=
es<br>
(and we need things like this)<br>
However...<br>
<br>
This is (still/again) not based on a proper Ontology. (but can help to<br>
complete one)<br>
Leading to another Language, a non mature/structured, nor strict, &#39;data=
 model&#39;<br>
e.g.: redundancy in the &quot;sql schema&quot;, very simple types, etc.<br>
(I&#39;m not objective there, but the SQL-like approach is interesting* :p)=
<br>
<br>
Yet for sure it&#39;s interesting, but MUST use (and may be used to<br>
complete) more structured/mature data models for providing improved<br>
Interoperability (and covering more use cases) for better Automation<br>
(especially M2M).<br>
<br>
That would help if they could use/improve something more structured<br>
like MILE or OASIS CTI CybOX objects Models<br>
Ref. <a href=3D"https://cyboxproject.github.io/documentation/objects/" targ=
et=3D"_blank">https://cyboxproject.github.<wbr>io/documentation/objects/</a=
> (not latest<br>
version... but hopefully illustrates the point)<br>
That would help to leverage the tool (as an embedded data model) in a<br>
more global (interoperable/compatible) and efficient Model/Ontology.<br>
* e.g.: <a href=3D"https://github.com/athiasjerome/XORCISM/tree/master/MODE=
LS" target=3D"_blank">https://github.com/<wbr>athiasjerome/XORCISM/tree/<wb=
r>master/MODELS</a><br>
<br>
<br>
On Sat, Feb 11, 2017 at 12:37 PM, Sherif Mansour Farag<br>
&lt;<a href=3D"mailto:smansourfarag@expedia.com" target=3D"_blank">smansour=
farag@expedia.com</a>&gt; wrote:<br>
&gt; Apologies if you have already see this but has anyone reached out to<b=
r>
&gt; OSQuery.io ? It&#39;s an open source solution created by Facebook to a=
ddress<br>
&gt; some of the same challenges we are trying to slove. Might be worth<br>
&gt; exchanging notes at the very least.<br>
&gt;<br>
&gt; OSQuery provides Performant Endpoint Visibility:<br>
&gt; osquery allows you to easily ask questions about your Linux, Windows, =
and OS<br>
&gt; X infrastructure. Whether your goal is intrusion detection, infrastruc=
ture<br>
&gt; reliability, or compliance, osquery gives you the ability to empower a=
nd<br>
&gt; inform a broad set of organizations within your company.<br>
&gt;<br>
&gt; The syntax is SQL-like, example:<br>
&gt; osquery&gt; SELECT uid, name FROM listening_ports l, processes p WHERE=
<br>
&gt; l.pid=3Dp.pid;<br>
&gt;<br>
&gt; Here is a list of signals they can pull from an endpoint:<br>
&gt; <a href=3D"https://osquery.io/docs/tables/" target=3D"_blank">https://=
osquery.io/docs/<wbr>tables/</a><br>
&gt;<br>
&gt; And here are some &quot;pre-canned&quot; queries they have released:<b=
r>
&gt; <a href=3D"https://osquery.io/docs/packs/" target=3D"_blank">https://o=
squery.io/docs/packs/</a><br>
&gt;<br>
&gt; They are really nice BTW and I have asked them to include container<br=
>
&gt; introspection as well. The plan is to have that done in the next coupl=
e of<br>
&gt; weeks.<br>
&gt;<br>
&gt; -Sherif<br>
&gt;<br>
&gt; ______________________________<wbr>_________________<br>
&gt; sacm mailing list<br>
&gt; <a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org</a><b=
r>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"_blan=
k">https://www.ietf.org/mailman/<wbr>listinfo/sacm</a><br>
&gt;<br>
</div>
</span></font>
</div></div></div>

</blockquote></div><br></div>

--001a11429d6ec4c0e905484192d9--


From nobody Mon Feb 13 07:43:43 2017
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA80B1296CB for <sacm@ietfa.amsl.com>; Mon, 13 Feb 2017 07:43:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tMu8xZxypI2d for <sacm@ietfa.amsl.com>; Mon, 13 Feb 2017 07:43:40 -0800 (PST)
Received: from mail-qt0-x22b.google.com (mail-qt0-x22b.google.com [IPv6:2607:f8b0:400d:c0d::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 51716129406 for <sacm@ietf.org>; Mon, 13 Feb 2017 07:43:40 -0800 (PST)
Received: by mail-qt0-x22b.google.com with SMTP id k15so86644805qtg.3 for <sacm@ietf.org>; Mon, 13 Feb 2017 07:43:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:from:date:message-id:subject:to; bh=SjBWRUMQ7LgS/xx5tcmbcJaFq0UdGhfx+d+Q+NKAbs4=; b=gGXWCx9xEM4H2CYQEmhqCQ6T+POrrkweXFFU25GKKqv8E1W1U3++p8M6O8NuhgbSER ouMdeaTqKE3maWRxbeZBbUPi83vv4vMdRtiAMgPNtQgEsCE4iZe30TTbXMiTPg2i51id NmgPY9hP9i388EFuOBlat8+Fpm9UmXEu2Eime9eKGHxsu1+wfHeAz1qJjucXC/G5P6jk 0VS2agFO3NOghXtZwYsODugt1dMbtLYmmsfGTFhEJZ/WsSGMfXs88NKVGPRfJ4/jxK7C UsIFiKJg4Y2zKrcUU/yTE6fuCJ5uc8VrlhQ8D4FdL44/Qiq3fKyVCg55qLjd7gwZqCb0 Je7w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=SjBWRUMQ7LgS/xx5tcmbcJaFq0UdGhfx+d+Q+NKAbs4=; b=QZxNQiwz8ab0uuxpStNi5o8u/U05xkXzeawkGHLBjBMpQYaB/nLVoXHgNgAEMU7Apw 2nEiXhBrpsxrt0nWgZQhXIKNtOjMlzzyqIn8NnmoFSelSz1w7lvWsKP2TrJD9QlfXESK AMxepjdF6qipNFGZ1F92SqoyBj9QTkU/5QMF0vDPbotY+4N9DHaGwgefmVz4an7ZvWkD 6CgQpmKCbw5LpE+P41fZzzNtOSmjG2RJFc7OfPqRfFSs1IafV3nWhq5fdNp1osJcpgKB j0Kwwz+6zJKsHTQwTXLC6cMJxXxWMVPgfV0vTL/iTaZVWLwVb2A0xBtEgh2mGueOmohb IThQ==
X-Gm-Message-State: AMke39koDPMTIBqwItsjK63y4mwoaBCcfREqrbOfNFCtKHsenI/ESKbucVV7scPmHqJEkXL7iXE/gbmZLy9icg==
X-Received: by 10.200.37.141 with SMTP id e13mr20980377qte.226.1487000619266;  Mon, 13 Feb 2017 07:43:39 -0800 (PST)
MIME-Version: 1.0
Received: by 10.12.170.30 with HTTP; Mon, 13 Feb 2017 07:43:38 -0800 (PST)
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
Date: Mon, 13 Feb 2017 10:43:38 -0500
Message-ID: <CAHbuEH5zDfXbPmiojzhsGthvPQE-ao+e0PAC-MB6bnaradpy_g@mail.gmail.com>
To: "sacm@ietf.org" <sacm@ietf.org>
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/JpXID9zs0oByRSUujVsamphOGrA>
Subject: [sacm] Last call for draft-ietf-sacm-requirements
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Feb 2017 15:43:42 -0000

Hello,

FYI - I will start the last call as soon as the shepherd report is ready.

Thanks.

-- 

Best regards,
Kathleen


From nobody Thu Feb 16 13:01:31 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: sacm@ietf.org
Delivered-To: sacm@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B0A64129569; Thu, 16 Feb 2017 13:01:25 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.44.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <148727888571.967.4929748666818729276.idtracker@ietfa.amsl.com>
Date: Thu, 16 Feb 2017 13:01:25 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/UECKBtLTD0VnZiLa9CELbY2FmUU>
Cc: sacm@ietf.org
Subject: [sacm] I-D Action: draft-ietf-sacm-coswid-01.txt
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 21:01:26 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Security Automation and Continuous Monitoring of the IETF.

        Title           : Concise Software Identifiers
        Authors         : Henk Birkholz
                          Jessica Fitzgerald-McKay
                          Charles Schmidt
                          David Waltermire
	Filename        : draft-ietf-sacm-coswid-01.txt
	Pages           : 16
	Date            : 2017-02-16

Abstract:
   This document defines a concise representation of ISO 19770-2:2015
   Software Identifiers (SWID tags) that is interoperable with the XML
   schema definition of ISO 19770-2:2015 and augmented for application
   in Constrained-Node Networks.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-sacm-coswid/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-sacm-coswid-01

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-sacm-coswid-01


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Feb 28 02:38:50 2017
Return-Path: <athiasjerome@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C24E126FDC for <sacm@ietfa.amsl.com>; Tue, 28 Feb 2017 02:38:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.999
X-Spam-Level: 
X-Spam-Status: No, score=-0.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DDYR3fXY3YTu for <sacm@ietfa.amsl.com>; Tue, 28 Feb 2017 02:38:47 -0800 (PST)
Received: from mail-ua0-x22a.google.com (mail-ua0-x22a.google.com [IPv6:2607:f8b0:400c:c08::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A00DA129449 for <sacm@ietf.org>; Tue, 28 Feb 2017 02:38:46 -0800 (PST)
Received: by mail-ua0-x22a.google.com with SMTP id x24so8655009uab.0 for <sacm@ietf.org>; Tue, 28 Feb 2017 02:38:46 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=xgVwoOKw6Yv70lnPeycY/tAf/oHB2KyFE70P0lOMaUY=; b=CkjfnArUjRo6zI3xS+SAA8yTJSqP8/Ee78CTAL8BhUBmbfglwykoyaY2pS+7GVrYfp 938dyCW8vjxuQ5r+yyDQSwZtUmYmpej5BXau0rHvYxrKsEbnLsKLwLZtfgdaspCtN1Un zo38n/Pj8SsJtLrIz0jNjV5NrVUwTRquGwZtcu0IfaQQlOs/2fuXbVC4ZrvP/9uPY7g9 tP0JHDe3VrOQ6ca3PfYojqVlKFhoTokNrY6Of5pMyRngIsCYMhRymZOAUQFY+BtUfe8C vr3sfL/pc1b3NbglObbprSvO1PV1WQtV5XnlVj+9aosni73Y17dCz8M+hQgRTkhI/bxw oWsw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=xgVwoOKw6Yv70lnPeycY/tAf/oHB2KyFE70P0lOMaUY=; b=QS6V5x5BF4xoxFQKgtsALzwNi+Q/gPmIMr2HcenBTVdVnuOjrX2pUcbKxZEKTy07CO gfbB/Um2eVD+c8OZMM5hhbr1tyTguCOrbgAaTOGGcqwy/vDhqHSgBsWruladghY+QEiz J70txsjJdXPa2Si1mCV+BOjPIOEi/Qb4ceKfRhGZHHvD1Mh+Noz/oj1fVGHHlr+40KSo cXzYSiqEok1C66/WE3EJeybflASSPvdMtJY5hs+w62wY4ilYfuDxsvvW1jMPTgAwcCQB 7QlF4uUAdlhGNWTSEHifQYCMTLpkljtxPJcO2Wd9tF2f3QbRfsB3IVBcdaN+4FVDupxi FRsQ==
X-Gm-Message-State: AMke39nIBiw3lgVHDVP5BCOTbEdIy/x26HZu/1WpeEjXHGbqXQtI0zNxpiAx3/4NI9/449tn6l6BL4brny80Bw==
X-Received: by 10.176.68.199 with SMTP id n65mr531262uan.1.1488278325491; Tue, 28 Feb 2017 02:38:45 -0800 (PST)
MIME-Version: 1.0
Received: by 10.31.160.14 with HTTP; Tue, 28 Feb 2017 02:38:45 -0800 (PST)
In-Reply-To: <CAKUOEQxTQWLuPGcnhuZEZTK3MJ80W-u74iho9d4yH9StB7jO0A@mail.gmail.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com> <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com> <147f77a8-ea0f-ed43-f585-a70a231110fe@sit.fraunhofer.de> <CACknUNXx=F6DatwikXgs4NGFgbbQMnMPCiGfX4UKfYLh67RUog@mail.gmail.com> <cc9e09ec-05fc-1af2-9f9b-50cf3ef16fd1@sit.fraunhofer.de> <CAKUOEQxTQWLuPGcnhuZEZTK3MJ80W-u74iho9d4yH9StB7jO0A@mail.gmail.com>
From: Jerome Athias <athiasjerome@gmail.com>
Date: Tue, 28 Feb 2017 13:38:45 +0300
Message-ID: <CAA=AuEfDzOmpRsLQ6b2DWcDn7ZYhBZ=PB_R8M6SG_mypgLFAkQ@mail.gmail.com>
To: Bill Munyan <bill.munyan.ietf@gmail.com>
Content-Type: multipart/alternative; boundary=94eb2c060046eafeef054994cc1e
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/JYkKhiMbOzWwimz6OzR4QKIVcCE>
Cc: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "<sacm@ietf.org>" <sacm@ietf.org>, Adam Montville <adam.w.montville@gmail.com>
Subject: Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Feb 2017 10:38:49 -0000

--94eb2c060046eafeef054994cc1e
Content-Type: text/plain; charset=UTF-8

Greetings,

So taking IACD (Ref [0] Appendix A1) as an example for illustration, would
that help to first list triggering "events"/preconditions?

Regards

[0]
https://secwww.jhuapl.edu/iacdcommunityday/Resources/IACD%20Baseline%20Reference%20Architecture%20-%20Final%20PR.pdf



On Mon, Feb 6, 2017 at 5:17 PM, Bill Munyan <bill.munyan.ietf@gmail.com>
wrote:

> I wanted to clarify one assumption I have been making when viewing the
> diagram.  I am viewing the overall vulnerability scenario as a series of
> event-driven use-cases, with this diagram simply depicting one of those
> use-cases:  When new VDD is introduced into the scenario.
>
> Feasibly, a number of different events could trigger entry into the
> vulnerability scenario, such as a "staleness trigger", or a "new endpoint
> added trigger", and many more.  Each of these events could (and should)
> have their own diagram outlining how the components interact to request
> new/updated VDD, determine the endpoints which should be assessed, and what
> to do with their results.  As such, each of the components in the diagrams
> can be seen as conceptual, allowing for implementers to determine how best
> to consolidate components for their use.
>
> Please bash my thought process if I'm way off on this, but I thought it
> might help in this discussion, because it seems like some of the
> "disagreement" in the diagram is stemming from "events" which aren't
> necessarily applicable to this particular "event use-case".
>
> Cheers,
> -Bill M.
>
>
> On Fri, Feb 3, 2017 at 5:19 PM, Henk Birkholz <
> henk.birkholz@sit.fraunhofer.de> wrote:
>
>> Also inline. I hope it is still readable.
>>
>> On 02/03/2017 10:55 PM, Adam Montville wrote:
>>
>>> Thanks for chiming in Henk.  I'll go inline.  Nothing being said as
>>> chair.  Just making observations.
>>>
>>> On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz
>>> <henk.birkholz@sit.fraunhofer.de
>>> <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
>>>
>>>     Hi group,
>>>
>>>     to recap my understanding:
>>>
>>>     There will be trigger conditions that initiate collections of fresh
>>>     endpoint attributes (from which endpoint posture can be derived)
>>> from a
>>>     target endpoint.
>>>
>>>     The obvious trigger condition that an asserting component (in every
>>>     diagram, I think, that is the Vulnerability Assessor. This
>>> assumption is
>>>     based on the interpretation of the diagram, not based on the name of
>>> the
>>>     component). From my point of view, in order to assert that a known
>>>     record is, for example, "stale" (aka does not satisfy an declarative
>>>     guidance that expresses the quality of freshness) or, as another
>>>     example, is not yet created the Vulnerability Assessor requires an
>>>     always up-to-date and exhaustive list of all Assessment Result
>>> records.
>>>
>>>
>>> I would disagree.  I have a record from the endpoint repository that it
>>> timestamped as 3 days old.  My policy says I should not rely on anything
>>> older than 2 days old.  Then the information is stale, and I instruct to
>>> collect anew.
>>>
>>
>> If the "I" is the Vulnerability Assessor, how does it always have the
>> Assessment Result records to check that declarative guidance? Or do you
>> propose (in v3) that the Endpoint Repository is checking that freshness
>> continuously and notifying the Vulnerability Assessor?
>>
>>
>>>
>>>
>>>     In consequence, I would assume that either the the Assessment Result
>>>     Repository component collapses with the Vulnerability Assessor or the
>>>     Vulnerability Assessor always retains a complete in-sync copy of the
>>>     Assessment Result Repository.
>>>
>>>
>>> I would again disagree.  It may well be that actual software collapses
>>> these components into one, but it may be that there is a results
>>> repository, which is used downstream from vulnerability assessment, into
>>> which the assessor dumps results.
>>>
>>
>> Yes, downstream records are dumped as a result in the corresponding repo.
>> But how does the information of not satisfying declarative guidance (a
>> result got stale) makes it "upstream" again to trigger collection -
>> including imperative guidance what to collect (what just got stale)?
>>
>>
>>> Consider when we have configuration assessment down the road.  Would we
>>> then have a vulnerability assessor and a configuration assessor each
>>> with their own repository conceptually, or would we be better off with
>>> one "results repository"?  I think the one.
>>>
>>
>> It depends on scalability, I guess, but in the bare-bone first proof of
>> concept it seems to be feasible to collapse related pools of data into
>> justthe one, as there are no multiple consumers?
>>
>>
>>
>>> In practice, applications can choose to implement more than one
>>> conceptual component.
>>>
>>
>> Yes, that is why it is not a problem to collapse sets of functions into a
>> single component, in general. I hope this will remain a core feature of the
>> architecture at all time.
>>
>>
>>>
>>>
>>>     Alternatively, the Assessment Result Repository component is
>>> collapsed
>>>     with the Endpoint Repository (as proposed in diagram v3), in which
>>> case
>>>     now the Vulnerability Assessor to retain an continuously in-sync
>>> copy of
>>>     the Endpoint Repository? If it is to trigger on the "stale"
>>> condition?
>>>
>>>
>>> Again, I am not necessarily in favor of this viewpoint (and I'm not
>>> necessarily against).  The endpoint repository represents an interface
>>> to acquire information about endpoints, which does not necessarily need
>>> to include assessment results pertaining to those endpoints entirely.
>>>
>>
>> But isn't that what is depicted in the diagram v3: the assessment results
>> repo is merged with endpoint repo? Maybe I am actually a little bit dense
>> right now :)
>>
>>
>>>
>>>
>>>
>>>     The "keeping pools of data in-sync" seems to be introducing extra
>>> steps
>>>     in the work-flow.
>>>
>>>
>>> Is it really data in sync?  I understand what you're saying, but to me
>>> the endpoint repository component is where we find assertions about the
>>> endpoints, the assessors take those assertions and apply some logic to
>>> pass judgement on the endpoint, and that judgement is stored in the
>>> assessment results repository component.
>>>
>>
>> I simply did not assume that a repository is more than a data store. If
>> it does continuous assessments of endpoint records it contains, it most
>> certainly can trigger a collection. Maybe the label of the component is
>> just misleading me here.
>>
>>
>>>
>>>
>>>     A pro for this would be that there could be multiple additional
>>>     consumers of Assessment Results that justify an interface that
>>> provides
>>>     that data to multiple parties.
>>>
>>>
>>> Yes!  There are in practice.  Assessment results have downstream uses
>>> outside the scope of our charter.
>>>
>>
>> I thought so, but it is of course not part of the single snapshot diagram
>> and is therefore only implied at best.
>>
>>
>>>
>>>
>>>     A con for this is the universal "redundant data stores always pose a
>>>     source of complexity and hence risk of inconsistency" argument.
>>>
>>>     Another point of view could be that the "evaluation task" is
>>> independent
>>>     from the "trigger collection" (I just made that one up) task? Or
>>> maybe
>>>     it is associated with the worn component?
>>>
>>>     Multiple emerging architectures include an orchestration component
>>> that
>>>     consumes notification of changes and derives appropriate actions
>>> that it
>>>     can trigger or even conduct. Please note, I am not advocating to
>>>     introduce yet another component type (which would again add
>>> complexity,
>>>     error, scope creep...) :)
>>>
>>>
>>> Bill mentioned something to me offline yesterday about orchestration.
>>> In the vulnerability scenario, the orchestration is really being
>>> performed by the assessor.
>>>
>>
>> I think that in the reply above you illustrated that the Endpoint Repo
>> also does this assessment by checking for staleness? Or would it "just"
>> notify the Assessor to trigger a task? Why not trigger the collector
>> directly? What about the imperative guidance what to actually collect again?
>>
>> It seems that I really have a difficult time to wrap my head around the
>> proposal still. Please stay patient with me! :)
>>
>>
>>>
>>>
>>>     I just try to get a feasible grasp of the actual workflow that the
>>>     diagram is intended to represent.
>>>
>>>
>>> The most basic path through the system.
>>>
>>>
>>>
>>>     What am I missing? I actually am surprised that the Assessment Result
>>>     Repository merges with the Endpoint Repository and not the
>>> Vulnerability
>>>     Assessor. What is the advantage?
>>>
>>>
>>> I think we're still talking this one through.  What's the advantage to
>>> collapsing them at all?
>>>
>>
>> Collapsing redundant pools of data is reducing redundancy :) Tasks that
>> depend on data that has to be acquired to be conducted benefit from high
>> availability and low latency. But I totally understand the "multiple
>> consumer" argument.
>>
>>
>>>
>>>
>>>     Best,
>>>
>>>     Henk
>>>
>>>     On 02/03/2017 05:43 PM, Adam Montville wrote:
>>>     > I thought I'd try to break this discussion out of it's former
>>> thread
>>>     > into one of its own, in case that makes it easier for folks to
>>> opine.
>>>     > The list of "components" or "function groups" seems reasonable to
>>> me.
>>>     > In practice, there *may* be a desire to have that software acting
>>>     as an
>>>     > endpoint repository also act as the repository for assessment
>>> results.
>>>     > Or, these could be implemented in distinct services.
>>>     >
>>>     > What works for our purposes?
>>>     >
>>>     > Adam
>>>     >
>>>     > On Thu, Feb 2, 2017 at 10:40 AM Adam Montville
>>>     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
>>>     <mailto:adam.w.montville@gmail.com
>>>     <mailto:adam.w.montville@gmail.com>>> wrote:
>>>     >
>>>     >     Once folks have had an opportunity to review the vulnerability
>>>     >     scenario information we've been working on, what are your
>>> thoughts
>>>     >     on the main components we're presently focused on for this
>>>     narrowly
>>>     >     scoped exercise?  These are:
>>>     >
>>>     >     Vulnerability Detection Data Repository
>>>     >     Vulnerability Assessor
>>>     >     Endpoint Repository
>>>     >     Collector
>>>     >     Assessment Result Repository
>>>     >     Endpoint
>>>     >
>>>     >
>>>     >
>>>     >
>>>     >     On Thu, Feb 2, 2017 at 10:28 AM Adam Montville
>>>     >     <adam.w.montville@gmail.com
>>>     <mailto:adam.w.montville@gmail.com>
>>>     <mailto:adam.w.montville@gmail.com
>>>
>>>     <mailto:adam.w.montville@gmail.com>>> wrote:
>>>     >
>>>     >         Hi Everyone.  A few of us were able to make the
>>> vulnerability
>>>     >         scenario call today and I think we had a good, though at
>>> times
>>>     >         spirited, discussion.  We did record the meeting, which is
>>>     >         available at [1].  We discussed the attached (annotated
>>> with
>>>     >         some meeting notes) UML-ish sequence diagram.  I had
>>> created
>>>     >         that diagram to start a conversation (mission accomplished
>>> on
>>>     >         that front I think) -- a conversation that would lead us
>>>     toward
>>>     >         identifying the discrete components, interfaces, and
>>>     information
>>>     >         required to be sent over those interfaces.  The UML-ish
>>>     diagram
>>>     >         represents a *single* flow through the system -- a
>>> "one-time"
>>>     >         flow through the system.  It ignores, for the time being,
>>> the
>>>     >         continuous aspect of our charter in favor of getting
>>> started
>>>     >         with the basics.  Once we have a good understanding of the
>>>     >         basics -- the components, interfaces, and information
>>> required
>>>     >         -- we can start look at a continuous monitoring sequence
>>>     (which
>>>     >         could be represented as a distinct diagram) to determine
>>> what
>>>     >         more we need.  Then, I think, we can start drafting
>>> solutions.
>>>     >
>>>     >         One of the first issues is that we need to figure out if
>>> the
>>>     >         components in the base flow are accurate.  The main
>>> suggestion
>>>     >         we've tossed around so far is to combine the Endpoint
>>>     Repository
>>>     >         with the Assessment Result Repository.
>>>     >
>>>     >         We talked briefly about what interface we could use for
>>>     the VDD
>>>     >         Repository, and naturally ROLIE came up as an option.
>>>     >
>>>     >         We talked a little bit about the first "get endpoints"
>>>     operation
>>>     >         between the Vulnerability Assessor and the Endpoint
>>> Repository
>>>     >         -- specifically about whether we should represent on this
>>>     >         sequence diagram that information supporting a judgement of
>>>     >         "stale" would be needed.
>>>     >
>>>     >         We left open the time when we would next meet, favoring to
>>>     work
>>>     >         that out on-list.  Next week is TCG, so that may be
>>> difficult;
>>>     >         the following week is RSA, so that may be difficult.
>>>     >
>>>     >         For those who were in attendance today, please add to this
>>>     note
>>>     >         with your comments/corrections.
>>>     >
>>>     >         Kind regards,
>>>     >
>>>     >         Adam
>>>     >
>>>     >         [1]
>>>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>>>     >
>>>     >         On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>>>     >         <adam.w.montville@gmail.com
>>>     <mailto:adam.w.montville@gmail.com>
>>>     <mailto:adam.w.montville@gmail.com <mailto:adam.w.montville@gmail
>>> .com>>>
>>>     >         wrote:
>>>     >
>>>     >             Hi everyone.  Just a friendly reminder that we are
>>>     planning
>>>     >             to meet again this Thursday at the same time (2/2 @
>>> 10am
>>>     >             Eastern/3pm UTC) using SACM's meeting room at
>>>     >             https://ietf.webex.com/meet/sacm.
>>>     >
>>>     >             Kind regards,
>>>     >
>>>     >             Adam
>>>     >
>>>     >
>>>     >             On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>>>     >             <adam.w.montville@gmail.com
>>>     <mailto:adam.w.montville@gmail.com>
>>>     >             <mailto:adam.w.montville@gmail.com
>>>
>>>     <mailto:adam.w.montville@gmail.com>>> wrote:
>>>     >
>>>     >                 Hello. A few of us met informally today to discuss
>>> the
>>>     >                 vulnerability scenario in some more detail with
>>>     the goal
>>>     >                 of maintaining the narrow focus on a vulnerability
>>>     >                 assessment slice through our notional
>>> environment.  We
>>>     >                 are tending to look at major components as black
>>> boxes
>>>     >                 with interfaces and data format expectations, and
>>>     we are
>>>     >                 not necessarily concerned with how those
>>> components do
>>>     >                 things internally/behind the scenes.
>>>     >
>>>     >                 The meeting was recorded (you can find it with
>>> today's
>>>     >                 date at [1]).  The topic of discussion was
>>>     primarily in
>>>     >                 the "phase 1" area of what Danny sent to the list
>>> not
>>>     >                 very long ago [2], and resulted in a *starting
>>> point*
>>>     >                 diagram [3].
>>>     >
>>>     >                 The group who met today are (roughly) agreed on
>>>     the six
>>>     >                 main "components" represented in that diagram, but
>>>     also
>>>     >                 see that we have some work ahead.  Specifically, we
>>>     >                 quickly recognized that some of the assumptions the
>>>     >                 vulnerability draft makes may be assumptions we
>>> cannot
>>>     >                 afford to make and need to include in the
>>> exploration.
>>>     >
>>>     >                 We thought it would be a good idea to have another
>>>     >                 informal discussion in a couple of weeks (February
>>>     2) at
>>>     >                 the same time (10am Eastern / 3pm UTC), using the
>>> same
>>>     >                 WebEx [4].   At that time we intend to roll
>>>     through the
>>>     >                 vulnerability assessment scenario assumptions in an
>>>     >                 effort to determine which ones can be left as
>>>     >                 assumptions and which ones cannot.  Then we'll take
>>>     >                 another look at the diagram and work on its next
>>>     version.
>>>     >
>>>     >                 Stay tuned.
>>>     >
>>>     >                 Thanks to Danny, Stephen, and Jerome for joining
>>> and
>>>     >                 contributing!
>>>     >
>>>     >                 Kind regards,
>>>     >
>>>     >                 Adam
>>>     >
>>>     >
>>>     >                 [1]
>>>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>>>     >                 [2]
>>>     https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB
>>> 5NSU58MXDM
>>>     >                 [3]
>>>     https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>>>     >                 [4] https://ietf.webex.com/meet/sacm
>>>     >
>>>     >
>>>     >
>>>     > _______________________________________________
>>>     > sacm mailing list
>>>     > sacm@ietf.org <mailto:sacm@ietf.org>
>>>     > https://www.ietf.org/mailman/listinfo/sacm
>>>     >
>>>
>>>
>> _______________________________________________
>> sacm mailing list
>> sacm@ietf.org
>> https://www.ietf.org/mailman/listinfo/sacm
>>
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>

--94eb2c060046eafeef054994cc1e
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Greetings,<div><br></div><div>So taking IACD (Ref [0] Appe=
ndix A1) as an example for illustration, would that help to first list trig=
gering &quot;events&quot;/preconditions?</div><div><br></div><div>Regards</=
div><div><br></div><div>[0]=C2=A0<a href=3D"https://secwww.jhuapl.edu/iacdc=
ommunityday/Resources/IACD%20Baseline%20Reference%20Architecture%20-%20Fina=
l%20PR.pdf">https://secwww.jhuapl.edu/iacdcommunityday/Resources/IACD%20Bas=
eline%20Reference%20Architecture%20-%20Final%20PR.pdf</a></div><div><br></d=
iv><div><br></div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_=
quote">On Mon, Feb 6, 2017 at 5:17 PM, Bill Munyan <span dir=3D"ltr">&lt;<a=
 href=3D"mailto:bill.munyan.ietf@gmail.com" target=3D"_blank">bill.munyan.i=
etf@gmail.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" st=
yle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div =
dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:verdana,sans-=
serif">I wanted to clarify one assumption I have been making when viewing t=
he diagram.=C2=A0 I am viewing the overall vulnerability scenario as a seri=
es of event-driven use-cases, with this diagram simply depicting one of tho=
se use-cases: =C2=A0When new VDD is introduced into the scenario. =C2=A0</d=
iv><div class=3D"gmail_default" style=3D"font-family:verdana,sans-serif"><b=
r></div><div class=3D"gmail_default" style=3D"font-family:verdana,sans-seri=
f">Feasibly, a number of different events could trigger entry into the vuln=
erability scenario, such as a &quot;staleness trigger&quot;, or a &quot;new=
 endpoint added trigger&quot;, and many more.=C2=A0 Each of these events co=
uld (and should) have their own diagram outlining how the components intera=
ct to request new/updated VDD, determine the endpoints which should be asse=
ssed, and what to do with their results.=C2=A0 As such, each of the compone=
nts in the diagrams can be seen as conceptual, allowing for implementers to=
 determine how best to consolidate components for their use.</div><div clas=
s=3D"gmail_default" style=3D"font-family:verdana,sans-serif"><br></div><div=
 class=3D"gmail_default" style=3D"font-family:verdana,sans-serif">Please ba=
sh my thought process if I&#39;m way off on this, but I thought it might he=
lp in this discussion, because it seems like some of the &quot;disagreement=
&quot; in the diagram is stemming from &quot;events&quot; which aren&#39;t =
necessarily applicable to this particular &quot;event use-case&quot;.</div>=
<div class=3D"gmail_default" style=3D"font-family:verdana,sans-serif"><br><=
/div><div class=3D"gmail_default" style=3D"font-family:verdana,sans-serif">=
Cheers,=C2=A0</div><div class=3D"gmail_default" style=3D"font-family:verdan=
a,sans-serif">-Bill M.</div><div class=3D"gmail_default" style=3D"font-fami=
ly:verdana,sans-serif"><br></div></div><div class=3D"HOEnZb"><div class=3D"=
h5"><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Fri, Feb 3=
, 2017 at 5:19 PM, Henk Birkholz <span dir=3D"ltr">&lt;<a href=3D"mailto:he=
nk.birkholz@sit.fraunhofer.de" target=3D"_blank">henk.birkholz@sit.fraunhof=
er.<wbr>de</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Also inl=
ine. I hope it is still readable.<br>
<br>
On 02/03/2017 10:55 PM, Adam Montville wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Thanks for chiming in Henk.=C2=A0 I&#39;ll go inline.=C2=A0 Nothing being s=
aid as<br>
chair.=C2=A0 Just making observations.<br>
<br>
On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz<br>
&lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" target=3D"_blank">he=
nk.birkholz@sit.fraunhofer.<wbr>de</a><span><br>
&lt;mailto:<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" target=3D"_bl=
ank">henk.birkholz@sit.frau<wbr>nhofer.de</a>&gt;&gt; wrote:<br>
<br>
=C2=A0 =C2=A0 Hi group,<br>
<br>
=C2=A0 =C2=A0 to recap my understanding:<br>
<br>
=C2=A0 =C2=A0 There will be trigger conditions that initiate collections of=
 fresh<br>
=C2=A0 =C2=A0 endpoint attributes (from which endpoint posture can be deriv=
ed) from a<br>
=C2=A0 =C2=A0 target endpoint.<br>
<br>
=C2=A0 =C2=A0 The obvious trigger condition that an asserting component (in=
 every<br>
=C2=A0 =C2=A0 diagram, I think, that is the Vulnerability Assessor. This as=
sumption is<br>
=C2=A0 =C2=A0 based on the interpretation of the diagram, not based on the =
name of the<br>
=C2=A0 =C2=A0 component). From my point of view, in order to assert that a =
known<br>
=C2=A0 =C2=A0 record is, for example, &quot;stale&quot; (aka does not satis=
fy an declarative<br>
=C2=A0 =C2=A0 guidance that expresses the quality of freshness) or, as anot=
her<br>
=C2=A0 =C2=A0 example, is not yet created the Vulnerability Assessor requir=
es an<br>
=C2=A0 =C2=A0 always up-to-date and exhaustive list of all Assessment Resul=
t records.<br>
<br>
<br></span>
I would disagree.=C2=A0 I have a record from the endpoint repository that i=
t<br>
timestamped as 3 days old.=C2=A0 My policy says I should not rely on anythi=
ng<br>
older than 2 days old.=C2=A0 Then the information is stale, and I instruct =
to<br>
collect anew.<br>
</blockquote>
<br>
If the &quot;I&quot; is the Vulnerability Assessor, how does it always have=
 the Assessment Result records to check that declarative guidance? Or do yo=
u propose (in v3) that the Endpoint Repository is checking that freshness c=
ontinuously and notifying the Vulnerability Assessor?<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span>
<br>
<br>
<br>
=C2=A0 =C2=A0 In consequence, I would assume that either the the Assessment=
 Result<br>
=C2=A0 =C2=A0 Repository component collapses with the Vulnerability Assesso=
r or the<br>
=C2=A0 =C2=A0 Vulnerability Assessor always retains a complete in-sync copy=
 of the<br>
=C2=A0 =C2=A0 Assessment Result Repository.<br>
<br>
<br></span>
I would again disagree.=C2=A0 It may well be that actual software collapses=
<br>
these components into one, but it may be that there is a results<br>
repository, which is used downstream from vulnerability assessment, into<br=
>
which the assessor dumps results.<br>
</blockquote>
<br>
Yes, downstream records are dumped as a result in the corresponding repo. B=
ut how does the information of not satisfying declarative guidance (a resul=
t got stale) makes it &quot;upstream&quot; again to trigger collection - in=
cluding imperative guidance what to collect (what just got stale)?<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
Consider when we have configuration assessment down the road.=C2=A0 Would w=
e<br>
then have a vulnerability assessor and a configuration assessor each<br>
with their own repository conceptually, or would we be better off with<br>
one &quot;results repository&quot;?=C2=A0 I think the one.<br>
</blockquote>
<br>
It depends on scalability, I guess, but in the bare-bone first proof of con=
cept it seems to be feasible to collapse related pools of data into justthe=
 one, as there are no multiple consumers?<br>
<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
In practice, applications can choose to implement more than one<br>
conceptual component.<br>
</blockquote>
<br>
Yes, that is why it is not a problem to collapse sets of functions into a s=
ingle component, in general. I hope this will remain a core feature of the =
architecture at all time.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span>
<br>
<br>
<br>
=C2=A0 =C2=A0 Alternatively, the Assessment Result Repository component is =
collapsed<br>
=C2=A0 =C2=A0 with the Endpoint Repository (as proposed in diagram v3), in =
which case<br>
=C2=A0 =C2=A0 now the Vulnerability Assessor to retain an continuously in-s=
ync copy of<br>
=C2=A0 =C2=A0 the Endpoint Repository? If it is to trigger on the &quot;sta=
le&quot; condition?<br>
<br>
<br></span>
Again, I am not necessarily in favor of this viewpoint (and I&#39;m not<br>
necessarily against).=C2=A0 The endpoint repository represents an interface=
<br>
to acquire information about endpoints, which does not necessarily need<br>
to include assessment results pertaining to those endpoints entirely.<br>
</blockquote>
<br>
But isn&#39;t that what is depicted in the diagram v3: the assessment resul=
ts repo is merged with endpoint repo? Maybe I am actually a little bit dens=
e right now :)<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span>
<br>
<br>
<br>
<br>
=C2=A0 =C2=A0 The &quot;keeping pools of data in-sync&quot; seems to be int=
roducing extra steps<br>
=C2=A0 =C2=A0 in the work-flow.<br>
<br>
<br></span>
Is it really data in sync?=C2=A0 I understand what you&#39;re saying, but t=
o me<br>
the endpoint repository component is where we find assertions about the<br>
endpoints, the assessors take those assertions and apply some logic to<br>
pass judgement on the endpoint, and that judgement is stored in the<br>
assessment results repository component.<br>
</blockquote>
<br>
I simply did not assume that a repository is more than a data store. If it =
does continuous assessments of endpoint records it contains, it most certai=
nly can trigger a collection. Maybe the label of the component is just misl=
eading me here.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span>
<br>
<br>
<br>
=C2=A0 =C2=A0 A pro for this would be that there could be multiple addition=
al<br>
=C2=A0 =C2=A0 consumers of Assessment Results that justify an interface tha=
t provides<br>
=C2=A0 =C2=A0 that data to multiple parties.<br>
<br>
<br></span>
Yes!=C2=A0 There are in practice.=C2=A0 Assessment results have downstream =
uses<br>
outside the scope of our charter.<br>
</blockquote>
<br>
I thought so, but it is of course not part of the single snapshot diagram a=
nd is therefore only implied at best.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span>
<br>
<br>
<br>
=C2=A0 =C2=A0 A con for this is the universal &quot;redundant data stores a=
lways pose a<br>
=C2=A0 =C2=A0 source of complexity and hence risk of inconsistency&quot; ar=
gument.<br>
<br>
=C2=A0 =C2=A0 Another point of view could be that the &quot;evaluation task=
&quot; is independent<br>
=C2=A0 =C2=A0 from the &quot;trigger collection&quot; (I just made that one=
 up) task? Or maybe<br>
=C2=A0 =C2=A0 it is associated with the worn component?<br>
<br>
=C2=A0 =C2=A0 Multiple emerging architectures include an orchestration comp=
onent that<br>
=C2=A0 =C2=A0 consumes notification of changes and derives appropriate acti=
ons that it<br>
=C2=A0 =C2=A0 can trigger or even conduct. Please note, I am not advocating=
 to<br>
=C2=A0 =C2=A0 introduce yet another component type (which would again add c=
omplexity,<br>
=C2=A0 =C2=A0 error, scope creep...) :)<br>
<br>
<br></span>
Bill mentioned something to me offline yesterday about orchestration.<br>
In the vulnerability scenario, the orchestration is really being<br>
performed by the assessor.<br>
</blockquote>
<br>
I think that in the reply above you illustrated that the Endpoint Repo also=
 does this assessment by checking for staleness? Or would it &quot;just&quo=
t; notify the Assessor to trigger a task? Why not trigger the collector dir=
ectly? What about the imperative guidance what to actually collect again?<b=
r>
<br>
It seems that I really have a difficult time to wrap my head around the pro=
posal still. Please stay patient with me! :)<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span>
<br>
<br>
<br>
=C2=A0 =C2=A0 I just try to get a feasible grasp of the actual workflow tha=
t the<br>
=C2=A0 =C2=A0 diagram is intended to represent.<br>
<br>
<br></span>
The most basic path through the system.<span><br>
<br>
<br>
<br>
=C2=A0 =C2=A0 What am I missing? I actually am surprised that the Assessmen=
t Result<br>
=C2=A0 =C2=A0 Repository merges with the Endpoint Repository and not the Vu=
lnerability<br>
=C2=A0 =C2=A0 Assessor. What is the advantage?<br>
<br>
<br></span>
I think we&#39;re still talking this one through.=C2=A0 What&#39;s the adva=
ntage to<br>
collapsing them at all?<br>
</blockquote>
<br>
Collapsing redundant pools of data is reducing redundancy :) Tasks that dep=
end on data that has to be acquired to be conducted benefit from high avail=
ability and low latency. But I totally understand the &quot;multiple consum=
er&quot; argument.<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><span>
<br>
<br>
<br>
=C2=A0 =C2=A0 Best,<br>
<br>
=C2=A0 =C2=A0 Henk<br>
<br>
=C2=A0 =C2=A0 On 02/03/2017 05:43 PM, Adam Montville wrote:<br>
=C2=A0 =C2=A0 &gt; I thought I&#39;d try to break this discussion out of it=
&#39;s former thread<br>
=C2=A0 =C2=A0 &gt; into one of its own, in case that makes it easier for fo=
lks to opine.<br>
=C2=A0 =C2=A0 &gt; The list of &quot;components&quot; or &quot;function gro=
ups&quot; seems reasonable to me.<br>
=C2=A0 =C2=A0 &gt; In practice, there *may* be a desire to have that softwa=
re acting<br>
=C2=A0 =C2=A0 as an<br>
=C2=A0 =C2=A0 &gt; endpoint repository also act as the repository for asses=
sment results.<br>
=C2=A0 =C2=A0 &gt; Or, these could be implemented in distinct services.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; What works for our purposes?<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; On Thu, Feb 2, 2017 at 10:40 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" target=
=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto:<a href=3D"mailto:ada=
m.w.montville@gmail.com" target=3D"_blank">adam.w.montville@gmail<wbr>.com<=
/a>&gt;<br></span>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a><span><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Once folks have had an opportunity to=
 review the vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scenario information we&#39;ve been w=
orking on, what are your thoughts<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0on the main components we&#39;re pres=
ently focused on for this<br>
=C2=A0 =C2=A0 narrowly<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scoped exercise?=C2=A0 These are:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Detection Data Reposito=
ry<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Assessor<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Collector<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Assessment Result Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0On Thu, Feb 2, 2017 at 10:28 AM Adam =
Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montvill=
e@gmail.com" target=3D"_blank">adam.w.montville@gmail.com</a><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;<br></span>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a><div><div class=3D"m_40475=
48327838465042h5"><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi Everyone.=C2=A0 A fe=
w of us were able to make the vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario call today and=
 I think we had a good, though at times<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0spirited, discussion.=
=C2=A0 We did record the meeting, which is<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0available at [1].=C2=A0=
 We discussed the attached (annotated with<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some meeting notes) UML=
-ish sequence diagram.=C2=A0 I had created<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that diagram to start a=
 conversation (mission accomplished on<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that front I think) -- =
a conversation that would lead us<br>
=C2=A0 =C2=A0 toward<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0identifying the discret=
e components, interfaces, and<br>
=C2=A0 =C2=A0 information<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0required to be sent ove=
r those interfaces.=C2=A0 The UML-ish<br>
=C2=A0 =C2=A0 diagram<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0represents a *single* f=
low through the system -- a &quot;one-time&quot;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0flow through the system=
.=C2=A0 It ignores, for the time being, the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0continuous aspect of ou=
r charter in favor of getting started<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the basics.=C2=A0 =
Once we have a good understanding of the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0basics -- the component=
s, interfaces, and information required<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- we can start look at=
 a continuous monitoring sequence<br>
=C2=A0 =C2=A0 (which<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0could be represented as=
 a distinct diagram) to determine what<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0more we need.=C2=A0 The=
n, I think, we can start drafting solutions.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0One of the first issues=
 is that we need to figure out if the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0components in the base =
flow are accurate.=C2=A0 The main suggestion<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0we&#39;ve tossed around=
 so far is to combine the Endpoint<br>
=C2=A0 =C2=A0 Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the Assessment Res=
ult Repository.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked briefly about=
 what interface we could use for<br>
=C2=A0 =C2=A0 the VDD<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Repository, and natural=
ly ROLIE came up as an option.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked a little bit =
about the first &quot;get endpoints&quot;<br>
=C2=A0 =C2=A0 operation<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0between the Vulnerabili=
ty Assessor and the Endpoint Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- specifically about w=
hether we should represent on this<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0sequence diagram that i=
nformation supporting a judgement of<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;stale&quot; would=
 be needed.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We left open the time w=
hen we would next meet, favoring to<br>
=C2=A0 =C2=A0 work<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that out on-list.=C2=A0=
 Next week is TCG, so that may be difficult;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0the following week is R=
SA, so that may be difficult.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0For those who were in a=
ttendance today, please add to this<br>
=C2=A0 =C2=A0 note<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with your comments/corr=
ections.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" rel=3D"noreferrer" target=3D"_blank">https://drive.google.co=
m/open?<wbr>id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1<wbr>E</a><br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Mon, Jan 30, 2017 at=
 11:21 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:a=
dam.w.montville@gmail.com" target=3D"_blank">adam.w.montville@gmail.com</a>=
<br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;<br></div></div>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a> &lt;mailto:<a href=3D"mai=
lto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.montville@gmail<wb=
r>.com</a>&gt;&gt;&gt;<span><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi everyo=
ne.=C2=A0 Just a friendly reminder that we are<br>
=C2=A0 =C2=A0 planning<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0to meet a=
gain this Thursday at the same time (2/2 @ 10am<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Eastern/3=
pm UTC) using SACM&#39;s meeting room at<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=
=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" target=3D"_blank">=
https://ietf.webex.com/meet/s<wbr>acm</a>.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind rega=
rds,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Thu, J=
an 19, 2017 at 11:35 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a hr=
ef=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.montville=
@gmail.com</a><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;<br></span>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;mailt=
o:<a href=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.mo=
ntville@gmai<wbr>l.com</a><div><div class=3D"m_4047548327838465042h5"><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@gmail<wbr>.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Hello. A few of us met informally today to discuss the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability scenario in some more detail with<br>
=C2=A0 =C2=A0 the goal<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0of maintaining the narrow focus on a vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assessment slice through our notional environment.=C2=A0 We<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0are tending to look at major components as black boxes<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0with interfaces and data format expectations, and<br>
=C2=A0 =C2=A0 we are<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0not necessarily concerned with how those components do<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0things internally/behind the scenes.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The meeting was recorded (you can find it with today&#39;s<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0date at [1]).=C2=A0 The topic of discussion was<br>
=C2=A0 =C2=A0 primarily in<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the &quot;phase 1&quot; area of what Danny sent to the list not<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0very long ago [2], and resulted in a *starting point*<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0diagram [3].<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The group who met today are (roughly) agreed on<br>
=C2=A0 =C2=A0 the six<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0main &quot;components&quot; represented in that diagram, but<br>
=C2=A0 =C2=A0 also<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0see that we have some work ahead.=C2=A0 Specifically, we<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0quickly recognized that some of the assumptions the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability draft makes may be assumptions we cannot<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0afford to make and need to include in the exploration.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0We thought it would be a good idea to have another<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0informal discussion in a couple of weeks (February<br>
=C2=A0 =C2=A0 2) at<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the same time (10am Eastern / 3pm UTC), using the same<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0WebEx [4].=C2=A0 =C2=A0At that time we intend to roll<br>
=C2=A0 =C2=A0 through the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability assessment scenario assumptions in an<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0effort to determine which ones can be left as<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assumptions and which ones cannot.=C2=A0 Then we&#39;ll take<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0another look at the diagram and work on its next<br>
=C2=A0 =C2=A0 version.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Stay tuned.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Thanks to Danny, Stephen, and Jerome for joining and<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0contributing!<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Kind regards,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[1]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" rel=3D"noreferrer" target=3D"_blank">https://drive.google.co=
m/open?<wbr>id=3D0B8Wf9Un5FdCbWGhDOHpVR0tMd1<wbr>E</a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[2]<br>
=C2=A0 =C2=A0 <a href=3D"https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyv=
Aws_OVLFhB5NSU58MXDM" rel=3D"noreferrer" target=3D"_blank">https://mailarch=
ive.ietf.org/a<wbr>rch/msg/sacm/_LiKlyvAws_OVLFhB<wbr>5NSU58MXDM</a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[3]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU=
5pdTRjejJtNHc" rel=3D"noreferrer" target=3D"_blank">https://drive.google.co=
m/open?<wbr>id=3D0B8Wf9Un5FdCbMU5pdTRjejJtNH<wbr>c</a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[4] <a href=3D"https://ietf.webex.com/meet/sacm" rel=3D"noreferrer" t=
arget=3D"_blank">https://ietf.webex.com/meet/sa<wbr>cm</a><br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; ______________________________<wbr>_________________<br>
=C2=A0 =C2=A0 &gt; sacm mailing list<br></div></div>
=C2=A0 =C2=A0 &gt; <a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@=
ietf.org</a> &lt;mailto:<a href=3D"mailto:sacm@ietf.org" target=3D"_blank">=
sacm@ietf.org</a>&gt;<br>
=C2=A0 =C2=A0 &gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" r=
el=3D"noreferrer" target=3D"_blank">https://www.ietf.org/mailman/l<wbr>isti=
nfo/sacm</a><br>
=C2=A0 =C2=A0 &gt;<br>
<br>
</blockquote><div class=3D"m_4047548327838465042HOEnZb"><div class=3D"m_404=
7548327838465042h5">
<br>
______________________________<wbr>_________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/l<wbr>istinfo/sacm</a><br>
</div></div></blockquote></div><br></div>
</div></div><br>______________________________<wbr>_________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/sacm</a><br>
<br></blockquote></div><br></div>

--94eb2c060046eafeef054994cc1e--


From nobody Tue Feb 28 10:31:27 2017
Return-Path: <david.waltermire@nist.gov>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 11D4C12967A for <sacm@ietfa.amsl.com>; Tue, 28 Feb 2017 10:31:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nistgov.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LtjJkLyzqX2Z for <sacm@ietfa.amsl.com>; Tue, 28 Feb 2017 10:31:22 -0800 (PST)
Received: from gcc01-CY1-obe.outbound.protection.outlook.com (mail-cy1gcc01on0117.outbound.protection.outlook.com [23.103.200.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D0171129678 for <sacm@ietf.org>; Tue, 28 Feb 2017 10:31:21 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nistgov.onmicrosoft.com; s=selector1-nist-gov; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=wDi92PHP7UQoAz/7TCN6OS2XlLpnCQgjDrdWcjscuxE=; b=Ny/HeRrIY/S3C6Te5LrmgQcLffhisHVA58KAZeT9bKTI57ZRwGtYL8kyr1ZAj19TbsZfF4mFoRtd+ezj27/AaGjMOAlBh0cbUvOpJFkRpXDlT6SqRp7ABZTe5Ml3Urj7+4RYtAfiVDs0Mn04PwpaBnh9Xe29jCYFsi9B8DIxmSY=
Received: from MWHPR09MB1440.namprd09.prod.outlook.com (10.173.50.14) by MWHPR09MB1438.namprd09.prod.outlook.com (10.173.50.12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.933.12; Tue, 28 Feb 2017 18:31:20 +0000
Received: from MWHPR09MB1440.namprd09.prod.outlook.com ([10.173.50.14]) by MWHPR09MB1440.namprd09.prod.outlook.com ([10.173.50.14]) with mapi id 15.01.0933.016; Tue, 28 Feb 2017 18:31:19 +0000
From: "Waltermire, David A. (Fed)" <david.waltermire@nist.gov>
To: Jerome Athias <athiasjerome@gmail.com>, Bill Munyan <bill.munyan.ietf@gmail.com>
Thread-Topic: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
Thread-Index: AQHSfjzEprAz2cN3NUqLvalNAHprEKFXy3qAgAAPZyeABDAhAIAiVjCAgACDa4A=
Date: Tue, 28 Feb 2017 18:31:19 +0000
Message-ID: <MWHPR09MB144041D0D82277BABA7C85A2F0560@MWHPR09MB1440.namprd09.prod.outlook.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com> <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com> <147f77a8-ea0f-ed43-f585-a70a231110fe@sit.fraunhofer.de> <CACknUNXx=F6DatwikXgs4NGFgbbQMnMPCiGfX4UKfYLh67RUog@mail.gmail.com> <cc9e09ec-05fc-1af2-9f9b-50cf3ef16fd1@sit.fraunhofer.de> <CAKUOEQxTQWLuPGcnhuZEZTK3MJ80W-u74iho9d4yH9StB7jO0A@mail.gmail.com> <CAA=AuEfDzOmpRsLQ6b2DWcDn7ZYhBZ=PB_R8M6SG_mypgLFAkQ@mail.gmail.com>
In-Reply-To: <CAA=AuEfDzOmpRsLQ6b2DWcDn7ZYhBZ=PB_R8M6SG_mypgLFAkQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=david.waltermire@nist.gov; 
x-originating-ip: [129.6.224.58]
x-ms-office365-filtering-correlation-id: 373bb495-5d96-467b-c8c6-08d46007fd78
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(48565401081); SRVR:MWHPR09MB1438; 
x-microsoft-exchange-diagnostics: 1; MWHPR09MB1438; 7:JqRpTeIw9CrwQRKaxts9jXPweUpIvh6THE/4KmXk3KcI7pHtFG1FuQCaG2YwRiTghr+KzZcVfRZHwO/AnSE5ZVbzn2hg1FBaXLFvgEdotlWU1+MzywBQvvexJjdpj62JN8Fb6RhmQ30oS7AOYt/m6Cdzs8+2z0ojwc8tF5fXS0As+Ev/s2hbYM8ZWTspgiQ31WwCCeVYyI8n8rn0Gk++RuIO4n8Uyi04okKS4MK/xYea357BQXv+P13vtSLD8H74xvWk/Z+foua02q1ysrXKZ+oeh3lZobSMw3v+7WS5+XXFwvqM1gDXgZc3ixXGYqLasiqyKPAhyV3hT/90WaiuFQ==
x-microsoft-antispam-prvs: <MWHPR09MB14385042B8B594BB503A1164F0560@MWHPR09MB1438.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(278428928389397)(72170088055959)(271806183753584)(35073007944872)(94707916325470)(211936372134217)(21748063052155)(145926492361056);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6055026)(6041248)(20161123560025)(20161123555025)(20161123558025)(20161123564025)(20161123562025)(6072148); SRVR:MWHPR09MB1438; BCL:0; PCL:0; RULEID:; SRVR:MWHPR09MB1438; 
x-forefront-prvs: 0232B30BBC
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(7916002)(39860400002)(39450400003)(39850400002)(39410400002)(39840400002)(46034005)(189002)(24454002)(199003)(52054003)(377454003)(51444003)(53754006)(86362001)(2950100002)(8936002)(81166006)(68736007)(54356999)(92566002)(229853002)(101416001)(2906002)(5660300001)(77096006)(6436002)(8676002)(7696004)(76176999)(81156014)(105586002)(106356001)(6506006)(106116001)(2900100001)(14971765001)(31430400001)(53946003)(7736002)(19609705001)(122556002)(236005)(54906002)(55016002)(9686003)(6306002)(50986999)(39060400002)(6246003)(99286003)(33656002)(54896002)(97736004)(53546006)(53936002)(25786008)(74316002)(102836003)(3846002)(5890100001)(7906003)(38730400002)(3280700002)(93886004)(189998001)(6116002)(606005)(575784001)(66066001)(561944003)(3660700001)(790700001)(4326008); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR09MB1438; H:MWHPR09MB1440.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_MWHPR09MB144041D0D82277BABA7C85A2F0560MWHPR09MB1440namp_"
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Feb 2017 18:31:19.8370 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR09MB1438
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/d8m4N9Qwr6EG-JrSCD1rX0yQ4r0>
Cc: Adam Montville <adam.w.montville@gmail.com>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "<sacm@ietf.org>" <sacm@ietf.org>
Subject: Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Feb 2017 18:31:26 -0000

--_000_MWHPR09MB144041D0D82277BABA7C85A2F0560MWHPR09MB1440namp_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SmVyb21lLA0KDQpJTUhPLCB3ZSBuZWVkIHRvIGlkZW50aWZ5IHRoZSBwbGFjZXMgd2l0aGluIHRo
ZSB3b3JrZmxvdyB3aGVyZSB0cmlnZ2VycyBtYXkgb2NjdXIuIFRoZXNlIGFyZSB0aGUgd29ya2Zs
b3cgZW50cnkgcG9pbnRzLiBJdCB3b3VsZCBhbHNvIGJlIHVzZWZ1bCB0byBpZGVudGlmeSB0aGUg
ZXZlbnRzIHRoYXQgbWF5IGNhdXNlIHRoZXNlIHRyaWdnZXJzIGZvciBjbGFyaXR5IHNha2UuDQoN
CklzIHRoaXMgd2hhdCB5b3UgYXJlIHNheWluZz8NCg0KUmVnYXJkcywNCkRhdmUNCg0KDQpGcm9t
OiBzYWNtIFttYWlsdG86c2FjbS1ib3VuY2VzQGlldGYub3JnXSBPbiBCZWhhbGYgT2YgSmVyb21l
IEF0aGlhcw0KU2VudDogVHVlc2RheSwgRmVicnVhcnkgMjgsIDIwMTcgNTozOSBBTQ0KVG86IEJp
bGwgTXVueWFuIDxiaWxsLm11bnlhbi5pZXRmQGdtYWlsLmNvbT4NCkNjOiBIZW5rIEJpcmtob2x6
IDxoZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPjsgPHNhY21AaWV0Zi5vcmc+IDxzYWNt
QGlldGYub3JnPjsgQWRhbSBNb250dmlsbGUgPGFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPg0K
U3ViamVjdDogUmU6IFtzYWNtXSBNYWluIENvbXBvbmVudHM6IFdBUyAoUmU6IE5vdGVzIG9uIFZ1
bG5lcmFiaWxpdHkgU2NlbmFyaW8gV29ya2luZyBTZXNzaW9uKQ0KDQpHcmVldGluZ3MsDQoNClNv
IHRha2luZyBJQUNEIChSZWYgWzBdIEFwcGVuZGl4IEExKSBhcyBhbiBleGFtcGxlIGZvciBpbGx1
c3RyYXRpb24sIHdvdWxkIHRoYXQgaGVscCB0byBmaXJzdCBsaXN0IHRyaWdnZXJpbmcgImV2ZW50
cyIvcHJlY29uZGl0aW9ucz8NCg0KUmVnYXJkcw0KDQpbMF0gaHR0cHM6Ly9zZWN3d3cuamh1YXBs
LmVkdS9pYWNkY29tbXVuaXR5ZGF5L1Jlc291cmNlcy9JQUNEJTIwQmFzZWxpbmUlMjBSZWZlcmVu
Y2UlMjBBcmNoaXRlY3R1cmUlMjAtJTIwRmluYWwlMjBQUi5wZGYNCg0KDQoNCk9uIE1vbiwgRmVi
IDYsIDIwMTcgYXQgNToxNyBQTSwgQmlsbCBNdW55YW4gPGJpbGwubXVueWFuLmlldGZAZ21haWwu
Y29tPG1haWx0bzpiaWxsLm11bnlhbi5pZXRmQGdtYWlsLmNvbT4+IHdyb3RlOg0KSSB3YW50ZWQg
dG8gY2xhcmlmeSBvbmUgYXNzdW1wdGlvbiBJIGhhdmUgYmVlbiBtYWtpbmcgd2hlbiB2aWV3aW5n
IHRoZSBkaWFncmFtLiAgSSBhbSB2aWV3aW5nIHRoZSBvdmVyYWxsIHZ1bG5lcmFiaWxpdHkgc2Nl
bmFyaW8gYXMgYSBzZXJpZXMgb2YgZXZlbnQtZHJpdmVuIHVzZS1jYXNlcywgd2l0aCB0aGlzIGRp
YWdyYW0gc2ltcGx5IGRlcGljdGluZyBvbmUgb2YgdGhvc2UgdXNlLWNhc2VzOiAgV2hlbiBuZXcg
VkREIGlzIGludHJvZHVjZWQgaW50byB0aGUgc2NlbmFyaW8uDQoNCkZlYXNpYmx5LCBhIG51bWJl
ciBvZiBkaWZmZXJlbnQgZXZlbnRzIGNvdWxkIHRyaWdnZXIgZW50cnkgaW50byB0aGUgdnVsbmVy
YWJpbGl0eSBzY2VuYXJpbywgc3VjaCBhcyBhICJzdGFsZW5lc3MgdHJpZ2dlciIsIG9yIGEgIm5l
dyBlbmRwb2ludCBhZGRlZCB0cmlnZ2VyIiwgYW5kIG1hbnkgbW9yZS4gIEVhY2ggb2YgdGhlc2Ug
ZXZlbnRzIGNvdWxkIChhbmQgc2hvdWxkKSBoYXZlIHRoZWlyIG93biBkaWFncmFtIG91dGxpbmlu
ZyBob3cgdGhlIGNvbXBvbmVudHMgaW50ZXJhY3QgdG8gcmVxdWVzdCBuZXcvdXBkYXRlZCBWREQs
IGRldGVybWluZSB0aGUgZW5kcG9pbnRzIHdoaWNoIHNob3VsZCBiZSBhc3Nlc3NlZCwgYW5kIHdo
YXQgdG8gZG8gd2l0aCB0aGVpciByZXN1bHRzLiAgQXMgc3VjaCwgZWFjaCBvZiB0aGUgY29tcG9u
ZW50cyBpbiB0aGUgZGlhZ3JhbXMgY2FuIGJlIHNlZW4gYXMgY29uY2VwdHVhbCwgYWxsb3dpbmcg
Zm9yIGltcGxlbWVudGVycyB0byBkZXRlcm1pbmUgaG93IGJlc3QgdG8gY29uc29saWRhdGUgY29t
cG9uZW50cyBmb3IgdGhlaXIgdXNlLg0KDQpQbGVhc2UgYmFzaCBteSB0aG91Z2h0IHByb2Nlc3Mg
aWYgSSdtIHdheSBvZmYgb24gdGhpcywgYnV0IEkgdGhvdWdodCBpdCBtaWdodCBoZWxwIGluIHRo
aXMgZGlzY3Vzc2lvbiwgYmVjYXVzZSBpdCBzZWVtcyBsaWtlIHNvbWUgb2YgdGhlICJkaXNhZ3Jl
ZW1lbnQiIGluIHRoZSBkaWFncmFtIGlzIHN0ZW1taW5nIGZyb20gImV2ZW50cyIgd2hpY2ggYXJl
bid0IG5lY2Vzc2FyaWx5IGFwcGxpY2FibGUgdG8gdGhpcyBwYXJ0aWN1bGFyICJldmVudCB1c2Ut
Y2FzZSIuDQoNCkNoZWVycywNCi1CaWxsIE0uDQoNCg0KT24gRnJpLCBGZWIgMywgMjAxNyBhdCA1
OjE5IFBNLCBIZW5rIEJpcmtob2x6IDxoZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPG1h
aWx0bzpoZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPj4gd3JvdGU6DQpBbHNvIGlubGlu
ZS4gSSBob3BlIGl0IGlzIHN0aWxsIHJlYWRhYmxlLg0KDQpPbiAwMi8wMy8yMDE3IDEwOjU1IFBN
LCBBZGFtIE1vbnR2aWxsZSB3cm90ZToNClRoYW5rcyBmb3IgY2hpbWluZyBpbiBIZW5rLiAgSSds
bCBnbyBpbmxpbmUuICBOb3RoaW5nIGJlaW5nIHNhaWQgYXMNCmNoYWlyLiAgSnVzdCBtYWtpbmcg
b2JzZXJ2YXRpb25zLg0KDQpPbiBGcmksIEZlYiAzLCAyMDE3IGF0IDM6MjUgUE0gSGVuayBCaXJr
aG9seg0KPGhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGU8bWFpbHRvOmhlbmsuYmlya2hv
bHpAc2l0LmZyYXVuaG9mZXIuZGU+DQo8bWFpbHRvOmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9m
ZXIuZGU8bWFpbHRvOmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGU+Pj4gd3JvdGU6DQoN
CiAgICBIaSBncm91cCwNCg0KICAgIHRvIHJlY2FwIG15IHVuZGVyc3RhbmRpbmc6DQoNCiAgICBU
aGVyZSB3aWxsIGJlIHRyaWdnZXIgY29uZGl0aW9ucyB0aGF0IGluaXRpYXRlIGNvbGxlY3Rpb25z
IG9mIGZyZXNoDQogICAgZW5kcG9pbnQgYXR0cmlidXRlcyAoZnJvbSB3aGljaCBlbmRwb2ludCBw
b3N0dXJlIGNhbiBiZSBkZXJpdmVkKSBmcm9tIGENCiAgICB0YXJnZXQgZW5kcG9pbnQuDQoNCiAg
ICBUaGUgb2J2aW91cyB0cmlnZ2VyIGNvbmRpdGlvbiB0aGF0IGFuIGFzc2VydGluZyBjb21wb25l
bnQgKGluIGV2ZXJ5DQogICAgZGlhZ3JhbSwgSSB0aGluaywgdGhhdCBpcyB0aGUgVnVsbmVyYWJp
bGl0eSBBc3Nlc3Nvci4gVGhpcyBhc3N1bXB0aW9uIGlzDQogICAgYmFzZWQgb24gdGhlIGludGVy
cHJldGF0aW9uIG9mIHRoZSBkaWFncmFtLCBub3QgYmFzZWQgb24gdGhlIG5hbWUgb2YgdGhlDQog
ICAgY29tcG9uZW50KS4gRnJvbSBteSBwb2ludCBvZiB2aWV3LCBpbiBvcmRlciB0byBhc3NlcnQg
dGhhdCBhIGtub3duDQogICAgcmVjb3JkIGlzLCBmb3IgZXhhbXBsZSwgInN0YWxlIiAoYWthIGRv
ZXMgbm90IHNhdGlzZnkgYW4gZGVjbGFyYXRpdmUNCiAgICBndWlkYW5jZSB0aGF0IGV4cHJlc3Nl
cyB0aGUgcXVhbGl0eSBvZiBmcmVzaG5lc3MpIG9yLCBhcyBhbm90aGVyDQogICAgZXhhbXBsZSwg
aXMgbm90IHlldCBjcmVhdGVkIHRoZSBWdWxuZXJhYmlsaXR5IEFzc2Vzc29yIHJlcXVpcmVzIGFu
DQogICAgYWx3YXlzIHVwLXRvLWRhdGUgYW5kIGV4aGF1c3RpdmUgbGlzdCBvZiBhbGwgQXNzZXNz
bWVudCBSZXN1bHQgcmVjb3Jkcy4NCg0KDQpJIHdvdWxkIGRpc2FncmVlLiAgSSBoYXZlIGEgcmVj
b3JkIGZyb20gdGhlIGVuZHBvaW50IHJlcG9zaXRvcnkgdGhhdCBpdA0KdGltZXN0YW1wZWQgYXMg
MyBkYXlzIG9sZC4gIE15IHBvbGljeSBzYXlzIEkgc2hvdWxkIG5vdCByZWx5IG9uIGFueXRoaW5n
DQpvbGRlciB0aGFuIDIgZGF5cyBvbGQuICBUaGVuIHRoZSBpbmZvcm1hdGlvbiBpcyBzdGFsZSwg
YW5kIEkgaW5zdHJ1Y3QgdG8NCmNvbGxlY3QgYW5ldy4NCg0KSWYgdGhlICJJIiBpcyB0aGUgVnVs
bmVyYWJpbGl0eSBBc3Nlc3NvciwgaG93IGRvZXMgaXQgYWx3YXlzIGhhdmUgdGhlIEFzc2Vzc21l
bnQgUmVzdWx0IHJlY29yZHMgdG8gY2hlY2sgdGhhdCBkZWNsYXJhdGl2ZSBndWlkYW5jZT8gT3Ig
ZG8geW91IHByb3Bvc2UgKGluIHYzKSB0aGF0IHRoZSBFbmRwb2ludCBSZXBvc2l0b3J5IGlzIGNo
ZWNraW5nIHRoYXQgZnJlc2huZXNzIGNvbnRpbnVvdXNseSBhbmQgbm90aWZ5aW5nIHRoZSBWdWxu
ZXJhYmlsaXR5IEFzc2Vzc29yPw0KDQoNCg0KICAgIEluIGNvbnNlcXVlbmNlLCBJIHdvdWxkIGFz
c3VtZSB0aGF0IGVpdGhlciB0aGUgdGhlIEFzc2Vzc21lbnQgUmVzdWx0DQogICAgUmVwb3NpdG9y
eSBjb21wb25lbnQgY29sbGFwc2VzIHdpdGggdGhlIFZ1bG5lcmFiaWxpdHkgQXNzZXNzb3Igb3Ig
dGhlDQogICAgVnVsbmVyYWJpbGl0eSBBc3Nlc3NvciBhbHdheXMgcmV0YWlucyBhIGNvbXBsZXRl
IGluLXN5bmMgY29weSBvZiB0aGUNCiAgICBBc3Nlc3NtZW50IFJlc3VsdCBSZXBvc2l0b3J5Lg0K
DQoNCkkgd291bGQgYWdhaW4gZGlzYWdyZWUuICBJdCBtYXkgd2VsbCBiZSB0aGF0IGFjdHVhbCBz
b2Z0d2FyZSBjb2xsYXBzZXMNCnRoZXNlIGNvbXBvbmVudHMgaW50byBvbmUsIGJ1dCBpdCBtYXkg
YmUgdGhhdCB0aGVyZSBpcyBhIHJlc3VsdHMNCnJlcG9zaXRvcnksIHdoaWNoIGlzIHVzZWQgZG93
bnN0cmVhbSBmcm9tIHZ1bG5lcmFiaWxpdHkgYXNzZXNzbWVudCwgaW50bw0Kd2hpY2ggdGhlIGFz
c2Vzc29yIGR1bXBzIHJlc3VsdHMuDQoNClllcywgZG93bnN0cmVhbSByZWNvcmRzIGFyZSBkdW1w
ZWQgYXMgYSByZXN1bHQgaW4gdGhlIGNvcnJlc3BvbmRpbmcgcmVwby4gQnV0IGhvdyBkb2VzIHRo
ZSBpbmZvcm1hdGlvbiBvZiBub3Qgc2F0aXNmeWluZyBkZWNsYXJhdGl2ZSBndWlkYW5jZSAoYSBy
ZXN1bHQgZ290IHN0YWxlKSBtYWtlcyBpdCAidXBzdHJlYW0iIGFnYWluIHRvIHRyaWdnZXIgY29s
bGVjdGlvbiAtIGluY2x1ZGluZyBpbXBlcmF0aXZlIGd1aWRhbmNlIHdoYXQgdG8gY29sbGVjdCAo
d2hhdCBqdXN0IGdvdCBzdGFsZSk/DQoNCkNvbnNpZGVyIHdoZW4gd2UgaGF2ZSBjb25maWd1cmF0
aW9uIGFzc2Vzc21lbnQgZG93biB0aGUgcm9hZC4gIFdvdWxkIHdlDQp0aGVuIGhhdmUgYSB2dWxu
ZXJhYmlsaXR5IGFzc2Vzc29yIGFuZCBhIGNvbmZpZ3VyYXRpb24gYXNzZXNzb3IgZWFjaA0Kd2l0
aCB0aGVpciBvd24gcmVwb3NpdG9yeSBjb25jZXB0dWFsbHksIG9yIHdvdWxkIHdlIGJlIGJldHRl
ciBvZmYgd2l0aA0Kb25lICJyZXN1bHRzIHJlcG9zaXRvcnkiPyAgSSB0aGluayB0aGUgb25lLg0K
DQpJdCBkZXBlbmRzIG9uIHNjYWxhYmlsaXR5LCBJIGd1ZXNzLCBidXQgaW4gdGhlIGJhcmUtYm9u
ZSBmaXJzdCBwcm9vZiBvZiBjb25jZXB0IGl0IHNlZW1zIHRvIGJlIGZlYXNpYmxlIHRvIGNvbGxh
cHNlIHJlbGF0ZWQgcG9vbHMgb2YgZGF0YSBpbnRvIGp1c3R0aGUgb25lLCBhcyB0aGVyZSBhcmUg
bm8gbXVsdGlwbGUgY29uc3VtZXJzPw0KDQoNCkluIHByYWN0aWNlLCBhcHBsaWNhdGlvbnMgY2Fu
IGNob29zZSB0byBpbXBsZW1lbnQgbW9yZSB0aGFuIG9uZQ0KY29uY2VwdHVhbCBjb21wb25lbnQu
DQoNClllcywgdGhhdCBpcyB3aHkgaXQgaXMgbm90IGEgcHJvYmxlbSB0byBjb2xsYXBzZSBzZXRz
IG9mIGZ1bmN0aW9ucyBpbnRvIGEgc2luZ2xlIGNvbXBvbmVudCwgaW4gZ2VuZXJhbC4gSSBob3Bl
IHRoaXMgd2lsbCByZW1haW4gYSBjb3JlIGZlYXR1cmUgb2YgdGhlIGFyY2hpdGVjdHVyZSBhdCBh
bGwgdGltZS4NCg0KDQoNCiAgICBBbHRlcm5hdGl2ZWx5LCB0aGUgQXNzZXNzbWVudCBSZXN1bHQg
UmVwb3NpdG9yeSBjb21wb25lbnQgaXMgY29sbGFwc2VkDQogICAgd2l0aCB0aGUgRW5kcG9pbnQg
UmVwb3NpdG9yeSAoYXMgcHJvcG9zZWQgaW4gZGlhZ3JhbSB2MyksIGluIHdoaWNoIGNhc2UNCiAg
ICBub3cgdGhlIFZ1bG5lcmFiaWxpdHkgQXNzZXNzb3IgdG8gcmV0YWluIGFuIGNvbnRpbnVvdXNs
eSBpbi1zeW5jIGNvcHkgb2YNCiAgICB0aGUgRW5kcG9pbnQgUmVwb3NpdG9yeT8gSWYgaXQgaXMg
dG8gdHJpZ2dlciBvbiB0aGUgInN0YWxlIiBjb25kaXRpb24/DQoNCg0KQWdhaW4sIEkgYW0gbm90
IG5lY2Vzc2FyaWx5IGluIGZhdm9yIG9mIHRoaXMgdmlld3BvaW50IChhbmQgSSdtIG5vdA0KbmVj
ZXNzYXJpbHkgYWdhaW5zdCkuICBUaGUgZW5kcG9pbnQgcmVwb3NpdG9yeSByZXByZXNlbnRzIGFu
IGludGVyZmFjZQ0KdG8gYWNxdWlyZSBpbmZvcm1hdGlvbiBhYm91dCBlbmRwb2ludHMsIHdoaWNo
IGRvZXMgbm90IG5lY2Vzc2FyaWx5IG5lZWQNCnRvIGluY2x1ZGUgYXNzZXNzbWVudCByZXN1bHRz
IHBlcnRhaW5pbmcgdG8gdGhvc2UgZW5kcG9pbnRzIGVudGlyZWx5Lg0KDQpCdXQgaXNuJ3QgdGhh
dCB3aGF0IGlzIGRlcGljdGVkIGluIHRoZSBkaWFncmFtIHYzOiB0aGUgYXNzZXNzbWVudCByZXN1
bHRzIHJlcG8gaXMgbWVyZ2VkIHdpdGggZW5kcG9pbnQgcmVwbz8gTWF5YmUgSSBhbSBhY3R1YWxs
eSBhIGxpdHRsZSBiaXQgZGVuc2UgcmlnaHQgbm93IDopDQoNCg0KDQoNCiAgICBUaGUgImtlZXBp
bmcgcG9vbHMgb2YgZGF0YSBpbi1zeW5jIiBzZWVtcyB0byBiZSBpbnRyb2R1Y2luZyBleHRyYSBz
dGVwcw0KICAgIGluIHRoZSB3b3JrLWZsb3cuDQoNCg0KSXMgaXQgcmVhbGx5IGRhdGEgaW4gc3lu
Yz8gIEkgdW5kZXJzdGFuZCB3aGF0IHlvdSdyZSBzYXlpbmcsIGJ1dCB0byBtZQ0KdGhlIGVuZHBv
aW50IHJlcG9zaXRvcnkgY29tcG9uZW50IGlzIHdoZXJlIHdlIGZpbmQgYXNzZXJ0aW9ucyBhYm91
dCB0aGUNCmVuZHBvaW50cywgdGhlIGFzc2Vzc29ycyB0YWtlIHRob3NlIGFzc2VydGlvbnMgYW5k
IGFwcGx5IHNvbWUgbG9naWMgdG8NCnBhc3MganVkZ2VtZW50IG9uIHRoZSBlbmRwb2ludCwgYW5k
IHRoYXQganVkZ2VtZW50IGlzIHN0b3JlZCBpbiB0aGUNCmFzc2Vzc21lbnQgcmVzdWx0cyByZXBv
c2l0b3J5IGNvbXBvbmVudC4NCg0KSSBzaW1wbHkgZGlkIG5vdCBhc3N1bWUgdGhhdCBhIHJlcG9z
aXRvcnkgaXMgbW9yZSB0aGFuIGEgZGF0YSBzdG9yZS4gSWYgaXQgZG9lcyBjb250aW51b3VzIGFz
c2Vzc21lbnRzIG9mIGVuZHBvaW50IHJlY29yZHMgaXQgY29udGFpbnMsIGl0IG1vc3QgY2VydGFp
bmx5IGNhbiB0cmlnZ2VyIGEgY29sbGVjdGlvbi4gTWF5YmUgdGhlIGxhYmVsIG9mIHRoZSBjb21w
b25lbnQgaXMganVzdCBtaXNsZWFkaW5nIG1lIGhlcmUuDQoNCg0KDQogICAgQSBwcm8gZm9yIHRo
aXMgd291bGQgYmUgdGhhdCB0aGVyZSBjb3VsZCBiZSBtdWx0aXBsZSBhZGRpdGlvbmFsDQogICAg
Y29uc3VtZXJzIG9mIEFzc2Vzc21lbnQgUmVzdWx0cyB0aGF0IGp1c3RpZnkgYW4gaW50ZXJmYWNl
IHRoYXQgcHJvdmlkZXMNCiAgICB0aGF0IGRhdGEgdG8gbXVsdGlwbGUgcGFydGllcy4NCg0KDQpZ
ZXMhICBUaGVyZSBhcmUgaW4gcHJhY3RpY2UuICBBc3Nlc3NtZW50IHJlc3VsdHMgaGF2ZSBkb3du
c3RyZWFtIHVzZXMNCm91dHNpZGUgdGhlIHNjb3BlIG9mIG91ciBjaGFydGVyLg0KDQpJIHRob3Vn
aHQgc28sIGJ1dCBpdCBpcyBvZiBjb3Vyc2Ugbm90IHBhcnQgb2YgdGhlIHNpbmdsZSBzbmFwc2hv
dCBkaWFncmFtIGFuZCBpcyB0aGVyZWZvcmUgb25seSBpbXBsaWVkIGF0IGJlc3QuDQoNCg0KDQog
ICAgQSBjb24gZm9yIHRoaXMgaXMgdGhlIHVuaXZlcnNhbCAicmVkdW5kYW50IGRhdGEgc3RvcmVz
IGFsd2F5cyBwb3NlIGENCiAgICBzb3VyY2Ugb2YgY29tcGxleGl0eSBhbmQgaGVuY2UgcmlzayBv
ZiBpbmNvbnNpc3RlbmN5IiBhcmd1bWVudC4NCg0KICAgIEFub3RoZXIgcG9pbnQgb2YgdmlldyBj
b3VsZCBiZSB0aGF0IHRoZSAiZXZhbHVhdGlvbiB0YXNrIiBpcyBpbmRlcGVuZGVudA0KICAgIGZy
b20gdGhlICJ0cmlnZ2VyIGNvbGxlY3Rpb24iIChJIGp1c3QgbWFkZSB0aGF0IG9uZSB1cCkgdGFz
az8gT3IgbWF5YmUNCiAgICBpdCBpcyBhc3NvY2lhdGVkIHdpdGggdGhlIHdvcm4gY29tcG9uZW50
Pw0KDQogICAgTXVsdGlwbGUgZW1lcmdpbmcgYXJjaGl0ZWN0dXJlcyBpbmNsdWRlIGFuIG9yY2hl
c3RyYXRpb24gY29tcG9uZW50IHRoYXQNCiAgICBjb25zdW1lcyBub3RpZmljYXRpb24gb2YgY2hh
bmdlcyBhbmQgZGVyaXZlcyBhcHByb3ByaWF0ZSBhY3Rpb25zIHRoYXQgaXQNCiAgICBjYW4gdHJp
Z2dlciBvciBldmVuIGNvbmR1Y3QuIFBsZWFzZSBub3RlLCBJIGFtIG5vdCBhZHZvY2F0aW5nIHRv
DQogICAgaW50cm9kdWNlIHlldCBhbm90aGVyIGNvbXBvbmVudCB0eXBlICh3aGljaCB3b3VsZCBh
Z2FpbiBhZGQgY29tcGxleGl0eSwNCiAgICBlcnJvciwgc2NvcGUgY3JlZXAuLi4pIDopDQoNCg0K
QmlsbCBtZW50aW9uZWQgc29tZXRoaW5nIHRvIG1lIG9mZmxpbmUgeWVzdGVyZGF5IGFib3V0IG9y
Y2hlc3RyYXRpb24uDQpJbiB0aGUgdnVsbmVyYWJpbGl0eSBzY2VuYXJpbywgdGhlIG9yY2hlc3Ry
YXRpb24gaXMgcmVhbGx5IGJlaW5nDQpwZXJmb3JtZWQgYnkgdGhlIGFzc2Vzc29yLg0KDQpJIHRo
aW5rIHRoYXQgaW4gdGhlIHJlcGx5IGFib3ZlIHlvdSBpbGx1c3RyYXRlZCB0aGF0IHRoZSBFbmRw
b2ludCBSZXBvIGFsc28gZG9lcyB0aGlzIGFzc2Vzc21lbnQgYnkgY2hlY2tpbmcgZm9yIHN0YWxl
bmVzcz8gT3Igd291bGQgaXQgImp1c3QiIG5vdGlmeSB0aGUgQXNzZXNzb3IgdG8gdHJpZ2dlciBh
IHRhc2s/IFdoeSBub3QgdHJpZ2dlciB0aGUgY29sbGVjdG9yIGRpcmVjdGx5PyBXaGF0IGFib3V0
IHRoZSBpbXBlcmF0aXZlIGd1aWRhbmNlIHdoYXQgdG8gYWN0dWFsbHkgY29sbGVjdCBhZ2Fpbj8N
Cg0KSXQgc2VlbXMgdGhhdCBJIHJlYWxseSBoYXZlIGEgZGlmZmljdWx0IHRpbWUgdG8gd3JhcCBt
eSBoZWFkIGFyb3VuZCB0aGUgcHJvcG9zYWwgc3RpbGwuIFBsZWFzZSBzdGF5IHBhdGllbnQgd2l0
aCBtZSEgOikNCg0KDQoNCiAgICBJIGp1c3QgdHJ5IHRvIGdldCBhIGZlYXNpYmxlIGdyYXNwIG9m
IHRoZSBhY3R1YWwgd29ya2Zsb3cgdGhhdCB0aGUNCiAgICBkaWFncmFtIGlzIGludGVuZGVkIHRv
IHJlcHJlc2VudC4NCg0KDQpUaGUgbW9zdCBiYXNpYyBwYXRoIHRocm91Z2ggdGhlIHN5c3RlbS4N
Cg0KDQoNCiAgICBXaGF0IGFtIEkgbWlzc2luZz8gSSBhY3R1YWxseSBhbSBzdXJwcmlzZWQgdGhh
dCB0aGUgQXNzZXNzbWVudCBSZXN1bHQNCiAgICBSZXBvc2l0b3J5IG1lcmdlcyB3aXRoIHRoZSBF
bmRwb2ludCBSZXBvc2l0b3J5IGFuZCBub3QgdGhlIFZ1bG5lcmFiaWxpdHkNCiAgICBBc3Nlc3Nv
ci4gV2hhdCBpcyB0aGUgYWR2YW50YWdlPw0KDQoNCkkgdGhpbmsgd2UncmUgc3RpbGwgdGFsa2lu
ZyB0aGlzIG9uZSB0aHJvdWdoLiAgV2hhdCdzIHRoZSBhZHZhbnRhZ2UgdG8NCmNvbGxhcHNpbmcg
dGhlbSBhdCBhbGw/DQoNCkNvbGxhcHNpbmcgcmVkdW5kYW50IHBvb2xzIG9mIGRhdGEgaXMgcmVk
dWNpbmcgcmVkdW5kYW5jeSA6KSBUYXNrcyB0aGF0IGRlcGVuZCBvbiBkYXRhIHRoYXQgaGFzIHRv
IGJlIGFjcXVpcmVkIHRvIGJlIGNvbmR1Y3RlZCBiZW5lZml0IGZyb20gaGlnaCBhdmFpbGFiaWxp
dHkgYW5kIGxvdyBsYXRlbmN5LiBCdXQgSSB0b3RhbGx5IHVuZGVyc3RhbmQgdGhlICJtdWx0aXBs
ZSBjb25zdW1lciIgYXJndW1lbnQuDQoNCg0KDQogICAgQmVzdCwNCg0KICAgIEhlbmsNCg0KICAg
IE9uIDAyLzAzLzIwMTcgMDU6NDMgUE0sIEFkYW0gTW9udHZpbGxlIHdyb3RlOg0KICAgID4gSSB0
aG91Z2h0IEknZCB0cnkgdG8gYnJlYWsgdGhpcyBkaXNjdXNzaW9uIG91dCBvZiBpdCdzIGZvcm1l
ciB0aHJlYWQNCiAgICA+IGludG8gb25lIG9mIGl0cyBvd24sIGluIGNhc2UgdGhhdCBtYWtlcyBp
dCBlYXNpZXIgZm9yIGZvbGtzIHRvIG9waW5lLg0KICAgID4gVGhlIGxpc3Qgb2YgImNvbXBvbmVu
dHMiIG9yICJmdW5jdGlvbiBncm91cHMiIHNlZW1zIHJlYXNvbmFibGUgdG8gbWUuDQogICAgPiBJ
biBwcmFjdGljZSwgdGhlcmUgKm1heSogYmUgYSBkZXNpcmUgdG8gaGF2ZSB0aGF0IHNvZnR3YXJl
IGFjdGluZw0KICAgIGFzIGFuDQogICAgPiBlbmRwb2ludCByZXBvc2l0b3J5IGFsc28gYWN0IGFz
IHRoZSByZXBvc2l0b3J5IGZvciBhc3Nlc3NtZW50IHJlc3VsdHMuDQogICAgPiBPciwgdGhlc2Ug
Y291bGQgYmUgaW1wbGVtZW50ZWQgaW4gZGlzdGluY3Qgc2VydmljZXMuDQogICAgPg0KICAgID4g
V2hhdCB3b3JrcyBmb3Igb3VyIHB1cnBvc2VzPw0KICAgID4NCiAgICA+IEFkYW0NCiAgICA+DQog
ICAgPiBPbiBUaHUsIEZlYiAyLCAyMDE3IGF0IDEwOjQwIEFNIEFkYW0gTW9udHZpbGxlDQogICAg
PiA8YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21h
aWwuY29tPiA8bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFtLncu
bW9udHZpbGxlQGdtYWlsLmNvbT4+DQogICAgPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWls
LmNvbTxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20+DQogICAgPG1haWx0bzphZGFt
LncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20+
Pj4+IHdyb3RlOg0KICAgID4NCiAgICA+ICAgICBPbmNlIGZvbGtzIGhhdmUgaGFkIGFuIG9wcG9y
dHVuaXR5IHRvIHJldmlldyB0aGUgdnVsbmVyYWJpbGl0eQ0KICAgID4gICAgIHNjZW5hcmlvIGlu
Zm9ybWF0aW9uIHdlJ3ZlIGJlZW4gd29ya2luZyBvbiwgd2hhdCBhcmUgeW91ciB0aG91Z2h0cw0K
ICAgID4gICAgIG9uIHRoZSBtYWluIGNvbXBvbmVudHMgd2UncmUgcHJlc2VudGx5IGZvY3VzZWQg
b24gZm9yIHRoaXMNCiAgICBuYXJyb3dseQ0KICAgID4gICAgIHNjb3BlZCBleGVyY2lzZT8gIFRo
ZXNlIGFyZToNCiAgICA+DQogICAgPiAgICAgVnVsbmVyYWJpbGl0eSBEZXRlY3Rpb24gRGF0YSBS
ZXBvc2l0b3J5DQogICAgPiAgICAgVnVsbmVyYWJpbGl0eSBBc3Nlc3Nvcg0KICAgID4gICAgIEVu
ZHBvaW50IFJlcG9zaXRvcnkNCiAgICA+ICAgICBDb2xsZWN0b3INCiAgICA+ICAgICBBc3Nlc3Nt
ZW50IFJlc3VsdCBSZXBvc2l0b3J5DQogICAgPiAgICAgRW5kcG9pbnQNCiAgICA+DQogICAgPg0K
ICAgID4NCiAgICA+DQogICAgPiAgICAgT24gVGh1LCBGZWIgMiwgMjAxNyBhdCAxMDoyOCBBTSBB
ZGFtIE1vbnR2aWxsZQ0KICAgID4gICAgIDxhZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWls
dG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20+DQogICAgPG1haWx0bzphZGFtLncubW9udHZp
bGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20+Pg0KICAgIDxt
YWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5tb250dmlsbGVA
Z21haWwuY29tPg0KDQogICAgPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWls
dG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20+Pj4+IHdyb3RlOg0KICAgID4NCiAgICA+ICAg
ICAgICAgSGkgRXZlcnlvbmUuICBBIGZldyBvZiB1cyB3ZXJlIGFibGUgdG8gbWFrZSB0aGUgdnVs
bmVyYWJpbGl0eQ0KICAgID4gICAgICAgICBzY2VuYXJpbyBjYWxsIHRvZGF5IGFuZCBJIHRoaW5r
IHdlIGhhZCBhIGdvb2QsIHRob3VnaCBhdCB0aW1lcw0KICAgID4gICAgICAgICBzcGlyaXRlZCwg
ZGlzY3Vzc2lvbi4gIFdlIGRpZCByZWNvcmQgdGhlIG1lZXRpbmcsIHdoaWNoIGlzDQogICAgPiAg
ICAgICAgIGF2YWlsYWJsZSBhdCBbMV0uICBXZSBkaXNjdXNzZWQgdGhlIGF0dGFjaGVkIChhbm5v
dGF0ZWQgd2l0aA0KICAgID4gICAgICAgICBzb21lIG1lZXRpbmcgbm90ZXMpIFVNTC1pc2ggc2Vx
dWVuY2UgZGlhZ3JhbS4gIEkgaGFkIGNyZWF0ZWQNCiAgICA+ICAgICAgICAgdGhhdCBkaWFncmFt
IHRvIHN0YXJ0IGEgY29udmVyc2F0aW9uIChtaXNzaW9uIGFjY29tcGxpc2hlZCBvbg0KICAgID4g
ICAgICAgICB0aGF0IGZyb250IEkgdGhpbmspIC0tIGEgY29udmVyc2F0aW9uIHRoYXQgd291bGQg
bGVhZCB1cw0KICAgIHRvd2FyZA0KICAgID4gICAgICAgICBpZGVudGlmeWluZyB0aGUgZGlzY3Jl
dGUgY29tcG9uZW50cywgaW50ZXJmYWNlcywgYW5kDQogICAgaW5mb3JtYXRpb24NCiAgICA+ICAg
ICAgICAgcmVxdWlyZWQgdG8gYmUgc2VudCBvdmVyIHRob3NlIGludGVyZmFjZXMuICBUaGUgVU1M
LWlzaA0KICAgIGRpYWdyYW0NCiAgICA+ICAgICAgICAgcmVwcmVzZW50cyBhICpzaW5nbGUqIGZs
b3cgdGhyb3VnaCB0aGUgc3lzdGVtIC0tIGEgIm9uZS10aW1lIg0KICAgID4gICAgICAgICBmbG93
IHRocm91Z2ggdGhlIHN5c3RlbS4gIEl0IGlnbm9yZXMsIGZvciB0aGUgdGltZSBiZWluZywgdGhl
DQogICAgPiAgICAgICAgIGNvbnRpbnVvdXMgYXNwZWN0IG9mIG91ciBjaGFydGVyIGluIGZhdm9y
IG9mIGdldHRpbmcgc3RhcnRlZA0KICAgID4gICAgICAgICB3aXRoIHRoZSBiYXNpY3MuICBPbmNl
IHdlIGhhdmUgYSBnb29kIHVuZGVyc3RhbmRpbmcgb2YgdGhlDQogICAgPiAgICAgICAgIGJhc2lj
cyAtLSB0aGUgY29tcG9uZW50cywgaW50ZXJmYWNlcywgYW5kIGluZm9ybWF0aW9uIHJlcXVpcmVk
DQogICAgPiAgICAgICAgIC0tIHdlIGNhbiBzdGFydCBsb29rIGF0IGEgY29udGludW91cyBtb25p
dG9yaW5nIHNlcXVlbmNlDQogICAgKHdoaWNoDQogICAgPiAgICAgICAgIGNvdWxkIGJlIHJlcHJl
c2VudGVkIGFzIGEgZGlzdGluY3QgZGlhZ3JhbSkgdG8gZGV0ZXJtaW5lIHdoYXQNCiAgICA+ICAg
ICAgICAgbW9yZSB3ZSBuZWVkLiAgVGhlbiwgSSB0aGluaywgd2UgY2FuIHN0YXJ0IGRyYWZ0aW5n
IHNvbHV0aW9ucy4NCiAgICA+DQogICAgPiAgICAgICAgIE9uZSBvZiB0aGUgZmlyc3QgaXNzdWVz
IGlzIHRoYXQgd2UgbmVlZCB0byBmaWd1cmUgb3V0IGlmIHRoZQ0KICAgID4gICAgICAgICBjb21w
b25lbnRzIGluIHRoZSBiYXNlIGZsb3cgYXJlIGFjY3VyYXRlLiAgVGhlIG1haW4gc3VnZ2VzdGlv
bg0KICAgID4gICAgICAgICB3ZSd2ZSB0b3NzZWQgYXJvdW5kIHNvIGZhciBpcyB0byBjb21iaW5l
IHRoZSBFbmRwb2ludA0KICAgIFJlcG9zaXRvcnkNCiAgICA+ICAgICAgICAgd2l0aCB0aGUgQXNz
ZXNzbWVudCBSZXN1bHQgUmVwb3NpdG9yeS4NCiAgICA+DQogICAgPiAgICAgICAgIFdlIHRhbGtl
ZCBicmllZmx5IGFib3V0IHdoYXQgaW50ZXJmYWNlIHdlIGNvdWxkIHVzZSBmb3INCiAgICB0aGUg
VkREDQogICAgPiAgICAgICAgIFJlcG9zaXRvcnksIGFuZCBuYXR1cmFsbHkgUk9MSUUgY2FtZSB1
cCBhcyBhbiBvcHRpb24uDQogICAgPg0KICAgID4gICAgICAgICBXZSB0YWxrZWQgYSBsaXR0bGUg
Yml0IGFib3V0IHRoZSBmaXJzdCAiZ2V0IGVuZHBvaW50cyINCiAgICBvcGVyYXRpb24NCiAgICA+
ICAgICAgICAgYmV0d2VlbiB0aGUgVnVsbmVyYWJpbGl0eSBBc3Nlc3NvciBhbmQgdGhlIEVuZHBv
aW50IFJlcG9zaXRvcnkNCiAgICA+ICAgICAgICAgLS0gc3BlY2lmaWNhbGx5IGFib3V0IHdoZXRo
ZXIgd2Ugc2hvdWxkIHJlcHJlc2VudCBvbiB0aGlzDQogICAgPiAgICAgICAgIHNlcXVlbmNlIGRp
YWdyYW0gdGhhdCBpbmZvcm1hdGlvbiBzdXBwb3J0aW5nIGEganVkZ2VtZW50IG9mDQogICAgPiAg
ICAgICAgICJzdGFsZSIgd291bGQgYmUgbmVlZGVkLg0KICAgID4NCiAgICA+ICAgICAgICAgV2Ug
bGVmdCBvcGVuIHRoZSB0aW1lIHdoZW4gd2Ugd291bGQgbmV4dCBtZWV0LCBmYXZvcmluZyB0bw0K
ICAgIHdvcmsNCiAgICA+ICAgICAgICAgdGhhdCBvdXQgb24tbGlzdC4gIE5leHQgd2VlayBpcyBU
Q0csIHNvIHRoYXQgbWF5IGJlIGRpZmZpY3VsdDsNCiAgICA+ICAgICAgICAgdGhlIGZvbGxvd2lu
ZyB3ZWVrIGlzIFJTQSwgc28gdGhhdCBtYXkgYmUgZGlmZmljdWx0Lg0KICAgID4NCiAgICA+ICAg
ICAgICAgRm9yIHRob3NlIHdobyB3ZXJlIGluIGF0dGVuZGFuY2UgdG9kYXksIHBsZWFzZSBhZGQg
dG8gdGhpcw0KICAgIG5vdGUNCiAgICA+ICAgICAgICAgd2l0aCB5b3VyIGNvbW1lbnRzL2NvcnJl
Y3Rpb25zLg0KICAgID4NCiAgICA+ICAgICAgICAgS2luZCByZWdhcmRzLA0KICAgID4NCiAgICA+
ICAgICAgICAgQWRhbQ0KICAgID4NCiAgICA+ICAgICAgICAgWzFdDQogICAgaHR0cHM6Ly9kcml2
ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERPSHBWUjB0TWQxRQ0KICAgID4N
CiAgICA+ICAgICAgICAgT24gTW9uLCBKYW4gMzAsIDIwMTcgYXQgMTE6MjEgQU0gQWRhbSBNb250
dmlsbGUNCiAgICA+ICAgICAgICAgPGFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPG1haWx0bzph
ZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbT4NCiAgICA8bWFpbHRvOmFkYW0udy5tb250dmlsbGVA
Z21haWwuY29tPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbT4+DQogICAgPG1haWx0
bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFp
bC5jb20+IDxtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5t
b250dmlsbGVAZ21haWwuY29tPj4+Pg0KICAgID4gICAgICAgICB3cm90ZToNCiAgICA+DQogICAg
PiAgICAgICAgICAgICBIaSBldmVyeW9uZS4gIEp1c3QgYSBmcmllbmRseSByZW1pbmRlciB0aGF0
IHdlIGFyZQ0KICAgIHBsYW5uaW5nDQogICAgPiAgICAgICAgICAgICB0byBtZWV0IGFnYWluIHRo
aXMgVGh1cnNkYXkgYXQgdGhlIHNhbWUgdGltZSAoMi8yIEAgMTBhbQ0KICAgID4gICAgICAgICAg
ICAgRWFzdGVybi8zcG0gVVRDKSB1c2luZyBTQUNNJ3MgbWVldGluZyByb29tIGF0DQogICAgPiAg
ICAgICAgICAgICBodHRwczovL2lldGYud2ViZXguY29tL21lZXQvc2FjbS4NCiAgICA+DQogICAg
PiAgICAgICAgICAgICBLaW5kIHJlZ2FyZHMsDQogICAgPg0KICAgID4gICAgICAgICAgICAgQWRh
bQ0KICAgID4NCiAgICA+DQogICAgPiAgICAgICAgICAgICBPbiBUaHUsIEphbiAxOSwgMjAxNyBh
dCAxMTozNSBBTSBBZGFtIE1vbnR2aWxsZQ0KICAgID4gICAgICAgICAgICAgPGFkYW0udy5tb250
dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbT4NCiAgICA8
bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPG1haWx0bzphZGFtLncubW9udHZpbGxl
QGdtYWlsLmNvbT4+DQogICAgPiAgICAgICAgICAgICA8bWFpbHRvOmFkYW0udy5tb250dmlsbGVA
Z21haWwuY29tPG1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbT4NCg0KICAgIDxtYWls
dG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208bWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21h
aWwuY29tPj4+PiB3cm90ZToNCiAgICA+DQogICAgPiAgICAgICAgICAgICAgICAgSGVsbG8uIEEg
ZmV3IG9mIHVzIG1ldCBpbmZvcm1hbGx5IHRvZGF5IHRvIGRpc2N1c3MgdGhlDQogICAgPiAgICAg
ICAgICAgICAgICAgdnVsbmVyYWJpbGl0eSBzY2VuYXJpbyBpbiBzb21lIG1vcmUgZGV0YWlsIHdp
dGgNCiAgICB0aGUgZ29hbA0KICAgID4gICAgICAgICAgICAgICAgIG9mIG1haW50YWluaW5nIHRo
ZSBuYXJyb3cgZm9jdXMgb24gYSB2dWxuZXJhYmlsaXR5DQogICAgPiAgICAgICAgICAgICAgICAg
YXNzZXNzbWVudCBzbGljZSB0aHJvdWdoIG91ciBub3Rpb25hbCBlbnZpcm9ubWVudC4gIFdlDQog
ICAgPiAgICAgICAgICAgICAgICAgYXJlIHRlbmRpbmcgdG8gbG9vayBhdCBtYWpvciBjb21wb25l
bnRzIGFzIGJsYWNrIGJveGVzDQogICAgPiAgICAgICAgICAgICAgICAgd2l0aCBpbnRlcmZhY2Vz
IGFuZCBkYXRhIGZvcm1hdCBleHBlY3RhdGlvbnMsIGFuZA0KICAgIHdlIGFyZQ0KICAgID4gICAg
ICAgICAgICAgICAgIG5vdCBuZWNlc3NhcmlseSBjb25jZXJuZWQgd2l0aCBob3cgdGhvc2UgY29t
cG9uZW50cyBkbw0KICAgID4gICAgICAgICAgICAgICAgIHRoaW5ncyBpbnRlcm5hbGx5L2JlaGlu
ZCB0aGUgc2NlbmVzLg0KICAgID4NCiAgICA+ICAgICAgICAgICAgICAgICBUaGUgbWVldGluZyB3
YXMgcmVjb3JkZWQgKHlvdSBjYW4gZmluZCBpdCB3aXRoIHRvZGF5J3MNCiAgICA+ICAgICAgICAg
ICAgICAgICBkYXRlIGF0IFsxXSkuICBUaGUgdG9waWMgb2YgZGlzY3Vzc2lvbiB3YXMNCiAgICBw
cmltYXJpbHkgaW4NCiAgICA+ICAgICAgICAgICAgICAgICB0aGUgInBoYXNlIDEiIGFyZWEgb2Yg
d2hhdCBEYW5ueSBzZW50IHRvIHRoZSBsaXN0IG5vdA0KICAgID4gICAgICAgICAgICAgICAgIHZl
cnkgbG9uZyBhZ28gWzJdLCBhbmQgcmVzdWx0ZWQgaW4gYSAqc3RhcnRpbmcgcG9pbnQqDQogICAg
PiAgICAgICAgICAgICAgICAgZGlhZ3JhbSBbM10uDQogICAgPg0KICAgID4gICAgICAgICAgICAg
ICAgIFRoZSBncm91cCB3aG8gbWV0IHRvZGF5IGFyZSAocm91Z2hseSkgYWdyZWVkIG9uDQogICAg
dGhlIHNpeA0KICAgID4gICAgICAgICAgICAgICAgIG1haW4gImNvbXBvbmVudHMiIHJlcHJlc2Vu
dGVkIGluIHRoYXQgZGlhZ3JhbSwgYnV0DQogICAgYWxzbw0KICAgID4gICAgICAgICAgICAgICAg
IHNlZSB0aGF0IHdlIGhhdmUgc29tZSB3b3JrIGFoZWFkLiAgU3BlY2lmaWNhbGx5LCB3ZQ0KICAg
ID4gICAgICAgICAgICAgICAgIHF1aWNrbHkgcmVjb2duaXplZCB0aGF0IHNvbWUgb2YgdGhlIGFz
c3VtcHRpb25zIHRoZQ0KICAgID4gICAgICAgICAgICAgICAgIHZ1bG5lcmFiaWxpdHkgZHJhZnQg
bWFrZXMgbWF5IGJlIGFzc3VtcHRpb25zIHdlIGNhbm5vdA0KICAgID4gICAgICAgICAgICAgICAg
IGFmZm9yZCB0byBtYWtlIGFuZCBuZWVkIHRvIGluY2x1ZGUgaW4gdGhlIGV4cGxvcmF0aW9uLg0K
ICAgID4NCiAgICA+ICAgICAgICAgICAgICAgICBXZSB0aG91Z2h0IGl0IHdvdWxkIGJlIGEgZ29v
ZCBpZGVhIHRvIGhhdmUgYW5vdGhlcg0KICAgID4gICAgICAgICAgICAgICAgIGluZm9ybWFsIGRp
c2N1c3Npb24gaW4gYSBjb3VwbGUgb2Ygd2Vla3MgKEZlYnJ1YXJ5DQogICAgMikgYXQNCiAgICA+
ICAgICAgICAgICAgICAgICB0aGUgc2FtZSB0aW1lICgxMGFtIEVhc3Rlcm4gLyAzcG0gVVRDKSwg
dXNpbmcgdGhlIHNhbWUNCiAgICA+ICAgICAgICAgICAgICAgICBXZWJFeCBbNF0uICAgQXQgdGhh
dCB0aW1lIHdlIGludGVuZCB0byByb2xsDQogICAgdGhyb3VnaCB0aGUNCiAgICA+ICAgICAgICAg
ICAgICAgICB2dWxuZXJhYmlsaXR5IGFzc2Vzc21lbnQgc2NlbmFyaW8gYXNzdW1wdGlvbnMgaW4g
YW4NCiAgICA+ICAgICAgICAgICAgICAgICBlZmZvcnQgdG8gZGV0ZXJtaW5lIHdoaWNoIG9uZXMg
Y2FuIGJlIGxlZnQgYXMNCiAgICA+ICAgICAgICAgICAgICAgICBhc3N1bXB0aW9ucyBhbmQgd2hp
Y2ggb25lcyBjYW5ub3QuICBUaGVuIHdlJ2xsIHRha2UNCiAgICA+ICAgICAgICAgICAgICAgICBh
bm90aGVyIGxvb2sgYXQgdGhlIGRpYWdyYW0gYW5kIHdvcmsgb24gaXRzIG5leHQNCiAgICB2ZXJz
aW9uLg0KICAgID4NCiAgICA+ICAgICAgICAgICAgICAgICBTdGF5IHR1bmVkLg0KICAgID4NCiAg
ICA+ICAgICAgICAgICAgICAgICBUaGFua3MgdG8gRGFubnksIFN0ZXBoZW4sIGFuZCBKZXJvbWUg
Zm9yIGpvaW5pbmcgYW5kDQogICAgPiAgICAgICAgICAgICAgICAgY29udHJpYnV0aW5nIQ0KICAg
ID4NCiAgICA+ICAgICAgICAgICAgICAgICBLaW5kIHJlZ2FyZHMsDQogICAgPg0KICAgID4gICAg
ICAgICAgICAgICAgIEFkYW0NCiAgICA+DQogICAgPg0KICAgID4gICAgICAgICAgICAgICAgIFsx
XQ0KICAgIGh0dHBzOi8vZHJpdmUuZ29vZ2xlLmNvbS9vcGVuP2lkPTBCOFdmOVVuNUZkQ2JXR2hE
T0hwVlIwdE1kMUUNCiAgICA+ICAgICAgICAgICAgICAgICBbMl0NCiAgICBodHRwczovL21haWxh
cmNoaXZlLmlldGYub3JnL2FyY2gvbXNnL3NhY20vX0xpS2x5dkF3c19PVkxGaEI1TlNVNThNWERN
DQogICAgPiAgICAgICAgICAgICAgICAgWzNdDQogICAgaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29t
L29wZW4/aWQ9MEI4V2Y5VW41RmRDYk1VNXBkVFJqZWpKdE5IYw0KICAgID4gICAgICAgICAgICAg
ICAgIFs0XSBodHRwczovL2lldGYud2ViZXguY29tL21lZXQvc2FjbQ0KICAgID4NCiAgICA+DQog
ICAgPg0KICAgID4gX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X18NCiAgICA+IHNhY20gbWFpbGluZyBsaXN0DQogICAgPiBzYWNtQGlldGYub3JnPG1haWx0bzpz
YWNtQGlldGYub3JnPiA8bWFpbHRvOnNhY21AaWV0Zi5vcmc8bWFpbHRvOnNhY21AaWV0Zi5vcmc+
Pg0KICAgID4gaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9zYWNtDQogICAg
Pg0KDQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0Kc2Fj
bSBtYWlsaW5nIGxpc3QNCnNhY21AaWV0Zi5vcmc8bWFpbHRvOnNhY21AaWV0Zi5vcmc+DQpodHRw
czovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL3NhY20NCg0KDQpfX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0Kc2FjbSBtYWlsaW5nIGxpc3QNCnNh
Y21AaWV0Zi5vcmc8bWFpbHRvOnNhY21AaWV0Zi5vcmc+DQpodHRwczovL3d3dy5pZXRmLm9yZy9t
YWlsbWFuL2xpc3RpbmZvL3NhY20NCg0K

--_000_MWHPR09MB144041D0D82277BABA7C85A2F0560MWHPR09MB1440namp_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpWZXJkYW5hOw0KCXBhbm9zZS0xOjIgMTEg
NiA0IDMgNSA0IDQgMiA0O30NCi8qIFN0eWxlIERlZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwg
bGkuTXNvTm9ybWFsLCBkaXYuTXNvTm9ybWFsDQoJe21hcmdpbjowaW47DQoJbWFyZ2luLWJvdHRv
bTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6IlRpbWVzIE5ldyBS
b21hbiIsc2VyaWY7fQ0KYTpsaW5rLCBzcGFuLk1zb0h5cGVybGluaw0KCXttc28tc3R5bGUtcHJp
b3JpdHk6OTk7DQoJY29sb3I6Ymx1ZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCmE6
dmlzaXRlZCwgc3Bhbi5Nc29IeXBlcmxpbmtGb2xsb3dlZA0KCXttc28tc3R5bGUtcHJpb3JpdHk6
OTk7DQoJY29sb3I6cHVycGxlOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KcC5tc29u
b3JtYWwwLCBsaS5tc29ub3JtYWwwLCBkaXYubXNvbm9ybWFsMA0KCXttc28tc3R5bGUtbmFtZTpt
c29ub3JtYWw7DQoJbXNvLW1hcmdpbi10b3AtYWx0OmF1dG87DQoJbWFyZ2luLXJpZ2h0OjBpbjsN
Cgltc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0bzsNCgltYXJnaW4tbGVmdDowaW47DQoJZm9udC1z
aXplOjEyLjBwdDsNCglmb250LWZhbWlseToiVGltZXMgTmV3IFJvbWFuIixzZXJpZjt9DQpzcGFu
LkVtYWlsU3R5bGUxOA0KCXttc28tc3R5bGUtdHlwZTpwZXJzb25hbC1yZXBseTsNCglmb250LWZh
bWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjsNCgljb2xvcjp3aW5kb3d0ZXh0O30NCi5Nc29DaHBE
ZWZhdWx0DQoJe21zby1zdHlsZS10eXBlOmV4cG9ydC1vbmx5Ow0KCWZvbnQtZmFtaWx5OiJDYWxp
YnJpIixzYW5zLXNlcmlmO30NCkBwYWdlIFdvcmRTZWN0aW9uMQ0KCXtzaXplOjguNWluIDExLjBp
bjsNCgltYXJnaW46MS4waW4gMS4waW4gMS4waW4gMS4waW47fQ0KZGl2LldvcmRTZWN0aW9uMQ0K
CXtwYWdlOldvcmRTZWN0aW9uMTt9DQotLT48L3N0eWxlPjwhLS1baWYgZ3RlIG1zbyA5XT48eG1s
Pg0KPG86c2hhcGVkZWZhdWx0cyB2OmV4dD0iZWRpdCIgc3BpZG1heD0iMTAyNiIgLz4NCjwveG1s
PjwhW2VuZGlmXS0tPjwhLS1baWYgZ3RlIG1zbyA5XT48eG1sPg0KPG86c2hhcGVsYXlvdXQgdjpl
eHQ9ImVkaXQiPg0KPG86aWRtYXAgdjpleHQ9ImVkaXQiIGRhdGE9IjEiIC8+DQo8L286c2hhcGVs
YXlvdXQ+PC94bWw+PCFbZW5kaWZdLS0+DQo8L2hlYWQ+DQo8Ym9keSBsYW5nPSJFTi1VUyIgbGlu
az0iYmx1ZSIgdmxpbms9InB1cnBsZSI+DQo8ZGl2IGNsYXNzPSJXb3JkU2VjdGlvbjEiPg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1p
bHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5KZXJvbWUsPG86cD48L286cD48L3Nw
YW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4w
cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj48bzpwPiZuYnNw
OzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9u
dC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYi
PklNSE8sIHdlIG5lZWQgdG8gaWRlbnRpZnkgdGhlIHBsYWNlcyB3aXRoaW4gdGhlIHdvcmtmbG93
IHdoZXJlIHRyaWdnZXJzIG1heSBvY2N1ci4gVGhlc2UgYXJlIHRoZSB3b3JrZmxvdyBlbnRyeSBw
b2ludHMuIEl0IHdvdWxkIGFsc28gYmUgdXNlZnVsIHRvIGlkZW50aWZ5IHRoZSBldmVudHMgdGhh
dA0KIG1heSBjYXVzZSB0aGVzZSB0cmlnZ2VycyBmb3IgY2xhcml0eSBzYWtlLjxvOnA+PC9vOnA+
PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4m
bmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9
ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNl
cmlmIj5JcyB0aGlzIHdoYXQgeW91IGFyZSBzYXlpbmc/PG86cD48L286cD48L3NwYW4+PC9wPg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1m
YW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj48bzpwPiZuYnNwOzwvbzpwPjwv
c3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjEx
LjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPlJlZ2FyZHMs
PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9
ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNl
cmlmIj5EYXZlPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90
OyxzYW5zLXNlcmlmIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtD
YWxpYnJpJnF1b3Q7LHNhbnMtc2VyaWYiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxk
aXYgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNvbGlkIGJsdWUgMS41cHQ7cGFkZGlu
ZzowaW4gMGluIDBpbiA0LjBwdCI+DQo8ZGl2Pg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9y
ZGVyLXRvcDpzb2xpZCAjRTFFMUUxIDEuMHB0O3BhZGRpbmc6My4wcHQgMGluIDBpbiAwaW4iPg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PGI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5Gcm9tOjwvc3Bhbj48L2I+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZx
dW90OyxzYW5zLXNlcmlmIj4gc2FjbSBbbWFpbHRvOnNhY20tYm91bmNlc0BpZXRmLm9yZ10NCjxi
Pk9uIEJlaGFsZiBPZiA8L2I+SmVyb21lIEF0aGlhczxicj4NCjxiPlNlbnQ6PC9iPiBUdWVzZGF5
LCBGZWJydWFyeSAyOCwgMjAxNyA1OjM5IEFNPGJyPg0KPGI+VG86PC9iPiBCaWxsIE11bnlhbiAm
bHQ7YmlsbC5tdW55YW4uaWV0ZkBnbWFpbC5jb20mZ3Q7PGJyPg0KPGI+Q2M6PC9iPiBIZW5rIEJp
cmtob2x6ICZsdDtoZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlJmd0OzsgJmx0O3NhY21A
aWV0Zi5vcmcmZ3Q7ICZsdDtzYWNtQGlldGYub3JnJmd0OzsgQWRhbSBNb250dmlsbGUgJmx0O2Fk
YW0udy5tb250dmlsbGVAZ21haWwuY29tJmd0Ozxicj4NCjxiPlN1YmplY3Q6PC9iPiBSZTogW3Nh
Y21dIE1haW4gQ29tcG9uZW50czogV0FTIChSZTogTm90ZXMgb24gVnVsbmVyYWJpbGl0eSBTY2Vu
YXJpbyBXb3JraW5nIFNlc3Npb24pPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPkdyZWV0aW5ncyw8bzpwPjwvbzpwPjwvcD4NCjxkaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPlNvIHRha2luZyBJQUNEIChSZWYgWzBdIEFwcGVuZGl4IEExKSBh
cyBhbiBleGFtcGxlIGZvciBpbGx1c3RyYXRpb24sIHdvdWxkIHRoYXQgaGVscCB0byBmaXJzdCBs
aXN0IHRyaWdnZXJpbmcgJnF1b3Q7ZXZlbnRzJnF1b3Q7L3ByZWNvbmRpdGlvbnM/PG86cD48L286
cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwv
bzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPlJlZ2FyZHM8bzpw
PjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5i
c3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+WzBdJm5i
c3A7PGEgaHJlZj0iaHR0cHM6Ly9zZWN3d3cuamh1YXBsLmVkdS9pYWNkY29tbXVuaXR5ZGF5L1Jl
c291cmNlcy9JQUNEJTIwQmFzZWxpbmUlMjBSZWZlcmVuY2UlMjBBcmNoaXRlY3R1cmUlMjAtJTIw
RmluYWwlMjBQUi5wZGYiPmh0dHBzOi8vc2Vjd3d3LmpodWFwbC5lZHUvaWFjZGNvbW11bml0eWRh
eS9SZXNvdXJjZXMvSUFDRCUyMEJhc2VsaW5lJTIwUmVmZXJlbmNlJTIwQXJjaGl0ZWN0dXJlJTIw
LSUyMEZpbmFsJTIwUFIucGRmPC9hPjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+
DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+T24gTW9uLCBGZWIgNiwgMjAxNyBhdCA1OjE3IFBNLCBC
aWxsIE11bnlhbiAmbHQ7PGEgaHJlZj0ibWFpbHRvOmJpbGwubXVueWFuLmlldGZAZ21haWwuY29t
IiB0YXJnZXQ9Il9ibGFuayI+YmlsbC5tdW55YW4uaWV0ZkBnbWFpbC5jb208L2E+Jmd0OyB3cm90
ZTo8bzpwPjwvbzpwPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXIt
bGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAwaW4gNi4wcHQ7bWFyZ2lu
LWxlZnQ6NC44cHQ7bWFyZ2luLXJpZ2h0OjBpbiI+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1b3Q7LHNh
bnMtc2VyaWYiPkkgd2FudGVkIHRvIGNsYXJpZnkgb25lIGFzc3VtcHRpb24gSSBoYXZlIGJlZW4g
bWFraW5nIHdoZW4gdmlld2luZyB0aGUgZGlhZ3JhbS4mbmJzcDsgSSBhbSB2aWV3aW5nIHRoZSBv
dmVyYWxsIHZ1bG5lcmFiaWxpdHkgc2NlbmFyaW8gYXMgYSBzZXJpZXMgb2YgZXZlbnQtZHJpdmVu
IHVzZS1jYXNlcywgd2l0aCB0aGlzIGRpYWdyYW0gc2ltcGx5DQogZGVwaWN0aW5nIG9uZSBvZiB0
aG9zZSB1c2UtY2FzZXM6ICZuYnNwO1doZW4gbmV3IFZERCBpcyBpbnRyb2R1Y2VkIGludG8gdGhl
IHNjZW5hcmlvLiAmbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6JnF1b3Q7VmVyZGFu
YSZxdW90OyxzYW5zLXNlcmlmIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6JnF1
b3Q7VmVyZGFuYSZxdW90OyxzYW5zLXNlcmlmIj5GZWFzaWJseSwgYSBudW1iZXIgb2YgZGlmZmVy
ZW50IGV2ZW50cyBjb3VsZCB0cmlnZ2VyIGVudHJ5IGludG8gdGhlIHZ1bG5lcmFiaWxpdHkgc2Nl
bmFyaW8sIHN1Y2ggYXMgYSAmcXVvdDtzdGFsZW5lc3MgdHJpZ2dlciZxdW90Oywgb3IgYSAmcXVv
dDtuZXcgZW5kcG9pbnQgYWRkZWQgdHJpZ2dlciZxdW90OywgYW5kIG1hbnkgbW9yZS4mbmJzcDsg
RWFjaCBvZiB0aGVzZSBldmVudHMNCiBjb3VsZCAoYW5kIHNob3VsZCkgaGF2ZSB0aGVpciBvd24g
ZGlhZ3JhbSBvdXRsaW5pbmcgaG93IHRoZSBjb21wb25lbnRzIGludGVyYWN0IHRvIHJlcXVlc3Qg
bmV3L3VwZGF0ZWQgVkRELCBkZXRlcm1pbmUgdGhlIGVuZHBvaW50cyB3aGljaCBzaG91bGQgYmUg
YXNzZXNzZWQsIGFuZCB3aGF0IHRvIGRvIHdpdGggdGhlaXIgcmVzdWx0cy4mbmJzcDsgQXMgc3Vj
aCwgZWFjaCBvZiB0aGUgY29tcG9uZW50cyBpbiB0aGUgZGlhZ3JhbXMgY2FuIGJlIHNlZW4gYXMN
CiBjb25jZXB0dWFsLCBhbGxvd2luZyBmb3IgaW1wbGVtZW50ZXJzIHRvIGRldGVybWluZSBob3cg
YmVzdCB0byBjb25zb2xpZGF0ZSBjb21wb25lbnRzIGZvciB0aGVpciB1c2UuPG86cD48L286cD48
L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5
bGU9ImZvbnQtZmFtaWx5OiZxdW90O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4mbmJz
cDs8L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+
UGxlYXNlIGJhc2ggbXkgdGhvdWdodCBwcm9jZXNzIGlmIEknbSB3YXkgb2ZmIG9uIHRoaXMsIGJ1
dCBJIHRob3VnaHQgaXQgbWlnaHQgaGVscCBpbiB0aGlzIGRpc2N1c3Npb24sIGJlY2F1c2UgaXQg
c2VlbXMgbGlrZSBzb21lIG9mIHRoZSAmcXVvdDtkaXNhZ3JlZW1lbnQmcXVvdDsgaW4gdGhlIGRp
YWdyYW0gaXMgc3RlbW1pbmcgZnJvbSAmcXVvdDtldmVudHMmcXVvdDsNCiB3aGljaCBhcmVuJ3Qg
bmVjZXNzYXJpbHkgYXBwbGljYWJsZSB0byB0aGlzIHBhcnRpY3VsYXIgJnF1b3Q7ZXZlbnQgdXNl
LWNhc2UmcXVvdDsuPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O1ZlcmRhbmEmcXVv
dDssc2Fucy1zZXJpZiI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O1Zl
cmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+Q2hlZXJzLCZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwv
cD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250
LWZhbWlseTomcXVvdDtWZXJkYW5hJnF1b3Q7LHNhbnMtc2VyaWYiPi1CaWxsIE0uPG86cD48L286
cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4g
c3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O1ZlcmRhbmEmcXVvdDssc2Fucy1zZXJpZiI+PG86cD4m
bmJzcDs8L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPk9uIEZyaSwgRmViIDMsIDIwMTcgYXQgNToxOSBQTSwgSGVuayBC
aXJraG9seiAmbHQ7PGEgaHJlZj0ibWFpbHRvOmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIu
ZGUiIHRhcmdldD0iX2JsYW5rIj5oZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPC9hPiZn
dDsgd3JvdGU6PG86cD48L286cD48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0iYm9yZGVyOm5vbmU7
Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0NDQyAxLjBwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDYuMHB0
O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdpbi1yaWdodDowaW4iPg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+QWxzbyBpbmxpbmUuIEkgaG9wZSBpdCBpcyBzdGlsbCByZWFkYWJsZS48YnI+DQo8YnI+DQpP
biAwMi8wMy8yMDE3IDEwOjU1IFBNLCBBZGFtIE1vbnR2aWxsZSB3cm90ZTo8bzpwPjwvbzpwPjwv
cD4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0ND
Q0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAwaW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFy
Z2luLXJpZ2h0OjBpbiI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5UaGFua3MgZm9yIGNoaW1pbmcg
aW4gSGVuay4mbmJzcDsgSSdsbCBnbyBpbmxpbmUuJm5ic3A7IE5vdGhpbmcgYmVpbmcgc2FpZCBh
czxicj4NCmNoYWlyLiZuYnNwOyBKdXN0IG1ha2luZyBvYnNlcnZhdGlvbnMuPGJyPg0KPGJyPg0K
T24gRnJpLCBGZWIgMywgMjAxNyBhdCAzOjI1IFBNIEhlbmsgQmlya2hvbHo8YnI+DQombHQ7PGEg
aHJlZj0ibWFpbHRvOmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGUiIHRhcmdldD0iX2Js
YW5rIj5oZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPC9hPjxicj4NCiZsdDttYWlsdG86
PGEgaHJlZj0ibWFpbHRvOmhlbmsuYmlya2hvbHpAc2l0LmZyYXVuaG9mZXIuZGUiIHRhcmdldD0i
X2JsYW5rIj5oZW5rLmJpcmtob2x6QHNpdC5mcmF1bmhvZmVyLmRlPC9hPiZndDsmZ3Q7IHdyb3Rl
Ojxicj4NCjxicj4NCiZuYnNwOyAmbmJzcDsgSGkgZ3JvdXAsPGJyPg0KPGJyPg0KJm5ic3A7ICZu
YnNwOyB0byByZWNhcCBteSB1bmRlcnN0YW5kaW5nOjxicj4NCjxicj4NCiZuYnNwOyAmbmJzcDsg
VGhlcmUgd2lsbCBiZSB0cmlnZ2VyIGNvbmRpdGlvbnMgdGhhdCBpbml0aWF0ZSBjb2xsZWN0aW9u
cyBvZiBmcmVzaDxicj4NCiZuYnNwOyAmbmJzcDsgZW5kcG9pbnQgYXR0cmlidXRlcyAoZnJvbSB3
aGljaCBlbmRwb2ludCBwb3N0dXJlIGNhbiBiZSBkZXJpdmVkKSBmcm9tIGE8YnI+DQombmJzcDsg
Jm5ic3A7IHRhcmdldCBlbmRwb2ludC48YnI+DQo8YnI+DQombmJzcDsgJm5ic3A7IFRoZSBvYnZp
b3VzIHRyaWdnZXIgY29uZGl0aW9uIHRoYXQgYW4gYXNzZXJ0aW5nIGNvbXBvbmVudCAoaW4gZXZl
cnk8YnI+DQombmJzcDsgJm5ic3A7IGRpYWdyYW0sIEkgdGhpbmssIHRoYXQgaXMgdGhlIFZ1bG5l
cmFiaWxpdHkgQXNzZXNzb3IuIFRoaXMgYXNzdW1wdGlvbiBpczxicj4NCiZuYnNwOyAmbmJzcDsg
YmFzZWQgb24gdGhlIGludGVycHJldGF0aW9uIG9mIHRoZSBkaWFncmFtLCBub3QgYmFzZWQgb24g
dGhlIG5hbWUgb2YgdGhlPGJyPg0KJm5ic3A7ICZuYnNwOyBjb21wb25lbnQpLiBGcm9tIG15IHBv
aW50IG9mIHZpZXcsIGluIG9yZGVyIHRvIGFzc2VydCB0aGF0IGEga25vd248YnI+DQombmJzcDsg
Jm5ic3A7IHJlY29yZCBpcywgZm9yIGV4YW1wbGUsICZxdW90O3N0YWxlJnF1b3Q7IChha2EgZG9l
cyBub3Qgc2F0aXNmeSBhbiBkZWNsYXJhdGl2ZTxicj4NCiZuYnNwOyAmbmJzcDsgZ3VpZGFuY2Ug
dGhhdCBleHByZXNzZXMgdGhlIHF1YWxpdHkgb2YgZnJlc2huZXNzKSBvciwgYXMgYW5vdGhlcjxi
cj4NCiZuYnNwOyAmbmJzcDsgZXhhbXBsZSwgaXMgbm90IHlldCBjcmVhdGVkIHRoZSBWdWxuZXJh
YmlsaXR5IEFzc2Vzc29yIHJlcXVpcmVzIGFuPGJyPg0KJm5ic3A7ICZuYnNwOyBhbHdheXMgdXAt
dG8tZGF0ZSBhbmQgZXhoYXVzdGl2ZSBsaXN0IG9mIGFsbCBBc3Nlc3NtZW50IFJlc3VsdCByZWNv
cmRzLjxicj4NCjxicj4NCjxicj4NCkkgd291bGQgZGlzYWdyZWUuJm5ic3A7IEkgaGF2ZSBhIHJl
Y29yZCBmcm9tIHRoZSBlbmRwb2ludCByZXBvc2l0b3J5IHRoYXQgaXQ8YnI+DQp0aW1lc3RhbXBl
ZCBhcyAzIGRheXMgb2xkLiZuYnNwOyBNeSBwb2xpY3kgc2F5cyBJIHNob3VsZCBub3QgcmVseSBv
biBhbnl0aGluZzxicj4NCm9sZGVyIHRoYW4gMiBkYXlzIG9sZC4mbmJzcDsgVGhlbiB0aGUgaW5m
b3JtYXRpb24gaXMgc3RhbGUsIGFuZCBJIGluc3RydWN0IHRvPGJyPg0KY29sbGVjdCBhbmV3Ljxv
OnA+PC9vOnA+PC9wPg0KPC9ibG9ja3F1b3RlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9
Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48YnI+DQpJZiB0aGUgJnF1b3Q7SSZxdW90OyBpcyB0aGUg
VnVsbmVyYWJpbGl0eSBBc3Nlc3NvciwgaG93IGRvZXMgaXQgYWx3YXlzIGhhdmUgdGhlIEFzc2Vz
c21lbnQgUmVzdWx0IHJlY29yZHMgdG8gY2hlY2sgdGhhdCBkZWNsYXJhdGl2ZSBndWlkYW5jZT8g
T3IgZG8geW91IHByb3Bvc2UgKGluIHYzKSB0aGF0IHRoZSBFbmRwb2ludCBSZXBvc2l0b3J5IGlz
IGNoZWNraW5nIHRoYXQgZnJlc2huZXNzIGNvbnRpbnVvdXNseSBhbmQgbm90aWZ5aW5nIHRoZSBW
dWxuZXJhYmlsaXR5DQogQXNzZXNzb3I/PG86cD48L286cD48L3A+DQo8YmxvY2txdW90ZSBzdHls
ZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0NDQyAxLjBwdDtwYWRkaW5nOjBp
biAwaW4gMGluIDYuMHB0O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdpbi1yaWdodDowaW4iPg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+PGJyPg0KPGJyPg0KPGJyPg0KJm5ic3A7ICZuYnNwOyBJbiBjb25z
ZXF1ZW5jZSwgSSB3b3VsZCBhc3N1bWUgdGhhdCBlaXRoZXIgdGhlIHRoZSBBc3Nlc3NtZW50IFJl
c3VsdDxicj4NCiZuYnNwOyAmbmJzcDsgUmVwb3NpdG9yeSBjb21wb25lbnQgY29sbGFwc2VzIHdp
dGggdGhlIFZ1bG5lcmFiaWxpdHkgQXNzZXNzb3Igb3IgdGhlPGJyPg0KJm5ic3A7ICZuYnNwOyBW
dWxuZXJhYmlsaXR5IEFzc2Vzc29yIGFsd2F5cyByZXRhaW5zIGEgY29tcGxldGUgaW4tc3luYyBj
b3B5IG9mIHRoZTxicj4NCiZuYnNwOyAmbmJzcDsgQXNzZXNzbWVudCBSZXN1bHQgUmVwb3NpdG9y
eS48YnI+DQo8YnI+DQo8YnI+DQpJIHdvdWxkIGFnYWluIGRpc2FncmVlLiZuYnNwOyBJdCBtYXkg
d2VsbCBiZSB0aGF0IGFjdHVhbCBzb2Z0d2FyZSBjb2xsYXBzZXM8YnI+DQp0aGVzZSBjb21wb25l
bnRzIGludG8gb25lLCBidXQgaXQgbWF5IGJlIHRoYXQgdGhlcmUgaXMgYSByZXN1bHRzPGJyPg0K
cmVwb3NpdG9yeSwgd2hpY2ggaXMgdXNlZCBkb3duc3RyZWFtIGZyb20gdnVsbmVyYWJpbGl0eSBh
c3Nlc3NtZW50LCBpbnRvPGJyPg0Kd2hpY2ggdGhlIGFzc2Vzc29yIGR1bXBzIHJlc3VsdHMuPG86
cD48L286cD48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0i
bWFyZ2luLWJvdHRvbToxMi4wcHQiPjxicj4NClllcywgZG93bnN0cmVhbSByZWNvcmRzIGFyZSBk
dW1wZWQgYXMgYSByZXN1bHQgaW4gdGhlIGNvcnJlc3BvbmRpbmcgcmVwby4gQnV0IGhvdyBkb2Vz
IHRoZSBpbmZvcm1hdGlvbiBvZiBub3Qgc2F0aXNmeWluZyBkZWNsYXJhdGl2ZSBndWlkYW5jZSAo
YSByZXN1bHQgZ290IHN0YWxlKSBtYWtlcyBpdCAmcXVvdDt1cHN0cmVhbSZxdW90OyBhZ2FpbiB0
byB0cmlnZ2VyIGNvbGxlY3Rpb24gLSBpbmNsdWRpbmcgaW1wZXJhdGl2ZSBndWlkYW5jZSB3aGF0
IHRvIGNvbGxlY3QNCiAod2hhdCBqdXN0IGdvdCBzdGFsZSk/PG86cD48L286cD48L3A+DQo8Ymxv
Y2txdW90ZSBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0NDQyAxLjBw
dDtwYWRkaW5nOjBpbiAwaW4gMGluIDYuMHB0O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdpbi1yaWdo
dDowaW4iPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PGJyPg0KQ29uc2lkZXIgd2hlbiB3ZSBoYXZl
IGNvbmZpZ3VyYXRpb24gYXNzZXNzbWVudCBkb3duIHRoZSByb2FkLiZuYnNwOyBXb3VsZCB3ZTxi
cj4NCnRoZW4gaGF2ZSBhIHZ1bG5lcmFiaWxpdHkgYXNzZXNzb3IgYW5kIGEgY29uZmlndXJhdGlv
biBhc3Nlc3NvciBlYWNoPGJyPg0Kd2l0aCB0aGVpciBvd24gcmVwb3NpdG9yeSBjb25jZXB0dWFs
bHksIG9yIHdvdWxkIHdlIGJlIGJldHRlciBvZmYgd2l0aDxicj4NCm9uZSAmcXVvdDtyZXN1bHRz
IHJlcG9zaXRvcnkmcXVvdDs/Jm5ic3A7IEkgdGhpbmsgdGhlIG9uZS48bzpwPjwvbzpwPjwvcD4N
CjwvYmxvY2txdW90ZT4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9t
OjEyLjBwdCI+PGJyPg0KSXQgZGVwZW5kcyBvbiBzY2FsYWJpbGl0eSwgSSBndWVzcywgYnV0IGlu
IHRoZSBiYXJlLWJvbmUgZmlyc3QgcHJvb2Ygb2YgY29uY2VwdCBpdCBzZWVtcyB0byBiZSBmZWFz
aWJsZSB0byBjb2xsYXBzZSByZWxhdGVkIHBvb2xzIG9mIGRhdGEgaW50byBqdXN0dGhlIG9uZSwg
YXMgdGhlcmUgYXJlIG5vIG11bHRpcGxlIGNvbnN1bWVycz88YnI+DQo8YnI+DQo8bzpwPjwvbzpw
PjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAj
Q0NDQ0NDIDEuMHB0O3BhZGRpbmc6MGluIDBpbiAwaW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7
bWFyZ2luLXJpZ2h0OjBpbiI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48YnI+DQpJbiBwcmFjdGlj
ZSwgYXBwbGljYXRpb25zIGNhbiBjaG9vc2UgdG8gaW1wbGVtZW50IG1vcmUgdGhhbiBvbmU8YnI+
DQpjb25jZXB0dWFsIGNvbXBvbmVudC48bzpwPjwvbzpwPjwvcD4NCjwvYmxvY2txdW90ZT4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PGJyPg0KWWVz
LCB0aGF0IGlzIHdoeSBpdCBpcyBub3QgYSBwcm9ibGVtIHRvIGNvbGxhcHNlIHNldHMgb2YgZnVu
Y3Rpb25zIGludG8gYSBzaW5nbGUgY29tcG9uZW50LCBpbiBnZW5lcmFsLiBJIGhvcGUgdGhpcyB3
aWxsIHJlbWFpbiBhIGNvcmUgZmVhdHVyZSBvZiB0aGUgYXJjaGl0ZWN0dXJlIGF0IGFsbCB0aW1l
LjxvOnA+PC9vOnA+PC9wPg0KPGJsb2NrcXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1s
ZWZ0OnNvbGlkICNDQ0NDQ0MgMS4wcHQ7cGFkZGluZzowaW4gMGluIDBpbiA2LjBwdDttYXJnaW4t
bGVmdDo0LjhwdDttYXJnaW4tcmlnaHQ6MGluIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxicj4N
Cjxicj4NCjxicj4NCiZuYnNwOyAmbmJzcDsgQWx0ZXJuYXRpdmVseSwgdGhlIEFzc2Vzc21lbnQg
UmVzdWx0IFJlcG9zaXRvcnkgY29tcG9uZW50IGlzIGNvbGxhcHNlZDxicj4NCiZuYnNwOyAmbmJz
cDsgd2l0aCB0aGUgRW5kcG9pbnQgUmVwb3NpdG9yeSAoYXMgcHJvcG9zZWQgaW4gZGlhZ3JhbSB2
MyksIGluIHdoaWNoIGNhc2U8YnI+DQombmJzcDsgJm5ic3A7IG5vdyB0aGUgVnVsbmVyYWJpbGl0
eSBBc3Nlc3NvciB0byByZXRhaW4gYW4gY29udGludW91c2x5IGluLXN5bmMgY29weSBvZjxicj4N
CiZuYnNwOyAmbmJzcDsgdGhlIEVuZHBvaW50IFJlcG9zaXRvcnk/IElmIGl0IGlzIHRvIHRyaWdn
ZXIgb24gdGhlICZxdW90O3N0YWxlJnF1b3Q7IGNvbmRpdGlvbj88YnI+DQo8YnI+DQo8YnI+DQpB
Z2FpbiwgSSBhbSBub3QgbmVjZXNzYXJpbHkgaW4gZmF2b3Igb2YgdGhpcyB2aWV3cG9pbnQgKGFu
ZCBJJ20gbm90PGJyPg0KbmVjZXNzYXJpbHkgYWdhaW5zdCkuJm5ic3A7IFRoZSBlbmRwb2ludCBy
ZXBvc2l0b3J5IHJlcHJlc2VudHMgYW4gaW50ZXJmYWNlPGJyPg0KdG8gYWNxdWlyZSBpbmZvcm1h
dGlvbiBhYm91dCBlbmRwb2ludHMsIHdoaWNoIGRvZXMgbm90IG5lY2Vzc2FyaWx5IG5lZWQ8YnI+
DQp0byBpbmNsdWRlIGFzc2Vzc21lbnQgcmVzdWx0cyBwZXJ0YWluaW5nIHRvIHRob3NlIGVuZHBv
aW50cyBlbnRpcmVseS48bzpwPjwvbzpwPjwvcD4NCjwvYmxvY2txdW90ZT4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PGJyPg0KQnV0IGlzbid0IHRo
YXQgd2hhdCBpcyBkZXBpY3RlZCBpbiB0aGUgZGlhZ3JhbSB2MzogdGhlIGFzc2Vzc21lbnQgcmVz
dWx0cyByZXBvIGlzIG1lcmdlZCB3aXRoIGVuZHBvaW50IHJlcG8/IE1heWJlIEkgYW0gYWN0dWFs
bHkgYSBsaXR0bGUgYml0IGRlbnNlIHJpZ2h0IG5vdyA6KTxvOnA+PC9vOnA+PC9wPg0KPGJsb2Nr
cXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNvbGlkICNDQ0NDQ0MgMS4wcHQ7
cGFkZGluZzowaW4gMGluIDBpbiA2LjBwdDttYXJnaW4tbGVmdDo0LjhwdDttYXJnaW4tcmlnaHQ6
MGluIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxicj4NCjxicj4NCjxicj4NCjxicj4NCiZuYnNw
OyAmbmJzcDsgVGhlICZxdW90O2tlZXBpbmcgcG9vbHMgb2YgZGF0YSBpbi1zeW5jJnF1b3Q7IHNl
ZW1zIHRvIGJlIGludHJvZHVjaW5nIGV4dHJhIHN0ZXBzPGJyPg0KJm5ic3A7ICZuYnNwOyBpbiB0
aGUgd29yay1mbG93Ljxicj4NCjxicj4NCjxicj4NCklzIGl0IHJlYWxseSBkYXRhIGluIHN5bmM/
Jm5ic3A7IEkgdW5kZXJzdGFuZCB3aGF0IHlvdSdyZSBzYXlpbmcsIGJ1dCB0byBtZTxicj4NCnRo
ZSBlbmRwb2ludCByZXBvc2l0b3J5IGNvbXBvbmVudCBpcyB3aGVyZSB3ZSBmaW5kIGFzc2VydGlv
bnMgYWJvdXQgdGhlPGJyPg0KZW5kcG9pbnRzLCB0aGUgYXNzZXNzb3JzIHRha2UgdGhvc2UgYXNz
ZXJ0aW9ucyBhbmQgYXBwbHkgc29tZSBsb2dpYyB0bzxicj4NCnBhc3MganVkZ2VtZW50IG9uIHRo
ZSBlbmRwb2ludCwgYW5kIHRoYXQganVkZ2VtZW50IGlzIHN0b3JlZCBpbiB0aGU8YnI+DQphc3Nl
c3NtZW50IHJlc3VsdHMgcmVwb3NpdG9yeSBjb21wb25lbnQuPG86cD48L286cD48L3A+DQo8L2Js
b2NrcXVvdGU+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4w
cHQiPjxicj4NCkkgc2ltcGx5IGRpZCBub3QgYXNzdW1lIHRoYXQgYSByZXBvc2l0b3J5IGlzIG1v
cmUgdGhhbiBhIGRhdGEgc3RvcmUuIElmIGl0IGRvZXMgY29udGludW91cyBhc3Nlc3NtZW50cyBv
ZiBlbmRwb2ludCByZWNvcmRzIGl0IGNvbnRhaW5zLCBpdCBtb3N0IGNlcnRhaW5seSBjYW4gdHJp
Z2dlciBhIGNvbGxlY3Rpb24uIE1heWJlIHRoZSBsYWJlbCBvZiB0aGUgY29tcG9uZW50IGlzIGp1
c3QgbWlzbGVhZGluZyBtZSBoZXJlLjxvOnA+PC9vOnA+PC9wPg0KPGJsb2NrcXVvdGUgc3R5bGU9
ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNvbGlkICNDQ0NDQ0MgMS4wcHQ7cGFkZGluZzowaW4g
MGluIDBpbiA2LjBwdDttYXJnaW4tbGVmdDo0LjhwdDttYXJnaW4tcmlnaHQ6MGluIj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxicj4NCjxicj4NCjxicj4NCiZuYnNwOyAmbmJzcDsgQSBwcm8gZm9y
IHRoaXMgd291bGQgYmUgdGhhdCB0aGVyZSBjb3VsZCBiZSBtdWx0aXBsZSBhZGRpdGlvbmFsPGJy
Pg0KJm5ic3A7ICZuYnNwOyBjb25zdW1lcnMgb2YgQXNzZXNzbWVudCBSZXN1bHRzIHRoYXQganVz
dGlmeSBhbiBpbnRlcmZhY2UgdGhhdCBwcm92aWRlczxicj4NCiZuYnNwOyAmbmJzcDsgdGhhdCBk
YXRhIHRvIG11bHRpcGxlIHBhcnRpZXMuPGJyPg0KPGJyPg0KPGJyPg0KWWVzISZuYnNwOyBUaGVy
ZSBhcmUgaW4gcHJhY3RpY2UuJm5ic3A7IEFzc2Vzc21lbnQgcmVzdWx0cyBoYXZlIGRvd25zdHJl
YW0gdXNlczxicj4NCm91dHNpZGUgdGhlIHNjb3BlIG9mIG91ciBjaGFydGVyLjxvOnA+PC9vOnA+
PC9wPg0KPC9ibG9ja3F1b3RlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1i
b3R0b206MTIuMHB0Ij48YnI+DQpJIHRob3VnaHQgc28sIGJ1dCBpdCBpcyBvZiBjb3Vyc2Ugbm90
IHBhcnQgb2YgdGhlIHNpbmdsZSBzbmFwc2hvdCBkaWFncmFtIGFuZCBpcyB0aGVyZWZvcmUgb25s
eSBpbXBsaWVkIGF0IGJlc3QuPG86cD48L286cD48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0iYm9y
ZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29saWQgI0NDQ0NDQyAxLjBwdDtwYWRkaW5nOjBpbiAwaW4g
MGluIDYuMHB0O21hcmdpbi1sZWZ0OjQuOHB0O21hcmdpbi1yaWdodDowaW4iPg0KPHAgY2xhc3M9
Ik1zb05vcm1hbCI+PGJyPg0KPGJyPg0KPGJyPg0KJm5ic3A7ICZuYnNwOyBBIGNvbiBmb3IgdGhp
cyBpcyB0aGUgdW5pdmVyc2FsICZxdW90O3JlZHVuZGFudCBkYXRhIHN0b3JlcyBhbHdheXMgcG9z
ZSBhPGJyPg0KJm5ic3A7ICZuYnNwOyBzb3VyY2Ugb2YgY29tcGxleGl0eSBhbmQgaGVuY2Ugcmlz
ayBvZiBpbmNvbnNpc3RlbmN5JnF1b3Q7IGFyZ3VtZW50Ljxicj4NCjxicj4NCiZuYnNwOyAmbmJz
cDsgQW5vdGhlciBwb2ludCBvZiB2aWV3IGNvdWxkIGJlIHRoYXQgdGhlICZxdW90O2V2YWx1YXRp
b24gdGFzayZxdW90OyBpcyBpbmRlcGVuZGVudDxicj4NCiZuYnNwOyAmbmJzcDsgZnJvbSB0aGUg
JnF1b3Q7dHJpZ2dlciBjb2xsZWN0aW9uJnF1b3Q7IChJIGp1c3QgbWFkZSB0aGF0IG9uZSB1cCkg
dGFzaz8gT3IgbWF5YmU8YnI+DQombmJzcDsgJm5ic3A7IGl0IGlzIGFzc29jaWF0ZWQgd2l0aCB0
aGUgd29ybiBjb21wb25lbnQ/PGJyPg0KPGJyPg0KJm5ic3A7ICZuYnNwOyBNdWx0aXBsZSBlbWVy
Z2luZyBhcmNoaXRlY3R1cmVzIGluY2x1ZGUgYW4gb3JjaGVzdHJhdGlvbiBjb21wb25lbnQgdGhh
dDxicj4NCiZuYnNwOyAmbmJzcDsgY29uc3VtZXMgbm90aWZpY2F0aW9uIG9mIGNoYW5nZXMgYW5k
IGRlcml2ZXMgYXBwcm9wcmlhdGUgYWN0aW9ucyB0aGF0IGl0PGJyPg0KJm5ic3A7ICZuYnNwOyBj
YW4gdHJpZ2dlciBvciBldmVuIGNvbmR1Y3QuIFBsZWFzZSBub3RlLCBJIGFtIG5vdCBhZHZvY2F0
aW5nIHRvPGJyPg0KJm5ic3A7ICZuYnNwOyBpbnRyb2R1Y2UgeWV0IGFub3RoZXIgY29tcG9uZW50
IHR5cGUgKHdoaWNoIHdvdWxkIGFnYWluIGFkZCBjb21wbGV4aXR5LDxicj4NCiZuYnNwOyAmbmJz
cDsgZXJyb3IsIHNjb3BlIGNyZWVwLi4uKSA6KTxicj4NCjxicj4NCjxicj4NCkJpbGwgbWVudGlv
bmVkIHNvbWV0aGluZyB0byBtZSBvZmZsaW5lIHllc3RlcmRheSBhYm91dCBvcmNoZXN0cmF0aW9u
Ljxicj4NCkluIHRoZSB2dWxuZXJhYmlsaXR5IHNjZW5hcmlvLCB0aGUgb3JjaGVzdHJhdGlvbiBp
cyByZWFsbHkgYmVpbmc8YnI+DQpwZXJmb3JtZWQgYnkgdGhlIGFzc2Vzc29yLjxvOnA+PC9vOnA+
PC9wPg0KPC9ibG9ja3F1b3RlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1i
b3R0b206MTIuMHB0Ij48YnI+DQpJIHRoaW5rIHRoYXQgaW4gdGhlIHJlcGx5IGFib3ZlIHlvdSBp
bGx1c3RyYXRlZCB0aGF0IHRoZSBFbmRwb2ludCBSZXBvIGFsc28gZG9lcyB0aGlzIGFzc2Vzc21l
bnQgYnkgY2hlY2tpbmcgZm9yIHN0YWxlbmVzcz8gT3Igd291bGQgaXQgJnF1b3Q7anVzdCZxdW90
OyBub3RpZnkgdGhlIEFzc2Vzc29yIHRvIHRyaWdnZXIgYSB0YXNrPyBXaHkgbm90IHRyaWdnZXIg
dGhlIGNvbGxlY3RvciBkaXJlY3RseT8gV2hhdCBhYm91dCB0aGUgaW1wZXJhdGl2ZSBndWlkYW5j
ZQ0KIHdoYXQgdG8gYWN0dWFsbHkgY29sbGVjdCBhZ2Fpbj88YnI+DQo8YnI+DQpJdCBzZWVtcyB0
aGF0IEkgcmVhbGx5IGhhdmUgYSBkaWZmaWN1bHQgdGltZSB0byB3cmFwIG15IGhlYWQgYXJvdW5k
IHRoZSBwcm9wb3NhbCBzdGlsbC4gUGxlYXNlIHN0YXkgcGF0aWVudCB3aXRoIG1lISA6KTxvOnA+
PC9vOnA+PC9wPg0KPGJsb2NrcXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNv
bGlkICNDQ0NDQ0MgMS4wcHQ7cGFkZGluZzowaW4gMGluIDBpbiA2LjBwdDttYXJnaW4tbGVmdDo0
LjhwdDttYXJnaW4tcmlnaHQ6MGluIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxicj4NCjxicj4N
Cjxicj4NCiZuYnNwOyAmbmJzcDsgSSBqdXN0IHRyeSB0byBnZXQgYSBmZWFzaWJsZSBncmFzcCBv
ZiB0aGUgYWN0dWFsIHdvcmtmbG93IHRoYXQgdGhlPGJyPg0KJm5ic3A7ICZuYnNwOyBkaWFncmFt
IGlzIGludGVuZGVkIHRvIHJlcHJlc2VudC48YnI+DQo8YnI+DQo8YnI+DQpUaGUgbW9zdCBiYXNp
YyBwYXRoIHRocm91Z2ggdGhlIHN5c3RlbS48YnI+DQo8YnI+DQo8YnI+DQo8YnI+DQombmJzcDsg
Jm5ic3A7IFdoYXQgYW0gSSBtaXNzaW5nPyBJIGFjdHVhbGx5IGFtIHN1cnByaXNlZCB0aGF0IHRo
ZSBBc3Nlc3NtZW50IFJlc3VsdDxicj4NCiZuYnNwOyAmbmJzcDsgUmVwb3NpdG9yeSBtZXJnZXMg
d2l0aCB0aGUgRW5kcG9pbnQgUmVwb3NpdG9yeSBhbmQgbm90IHRoZSBWdWxuZXJhYmlsaXR5PGJy
Pg0KJm5ic3A7ICZuYnNwOyBBc3Nlc3Nvci4gV2hhdCBpcyB0aGUgYWR2YW50YWdlPzxicj4NCjxi
cj4NCjxicj4NCkkgdGhpbmsgd2UncmUgc3RpbGwgdGFsa2luZyB0aGlzIG9uZSB0aHJvdWdoLiZu
YnNwOyBXaGF0J3MgdGhlIGFkdmFudGFnZSB0bzxicj4NCmNvbGxhcHNpbmcgdGhlbSBhdCBhbGw/
PG86cD48L286cD48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHls
ZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxicj4NCkNvbGxhcHNpbmcgcmVkdW5kYW50IHBvb2xz
IG9mIGRhdGEgaXMgcmVkdWNpbmcgcmVkdW5kYW5jeSA6KSBUYXNrcyB0aGF0IGRlcGVuZCBvbiBk
YXRhIHRoYXQgaGFzIHRvIGJlIGFjcXVpcmVkIHRvIGJlIGNvbmR1Y3RlZCBiZW5lZml0IGZyb20g
aGlnaCBhdmFpbGFiaWxpdHkgYW5kIGxvdyBsYXRlbmN5LiBCdXQgSSB0b3RhbGx5IHVuZGVyc3Rh
bmQgdGhlICZxdW90O211bHRpcGxlIGNvbnN1bWVyJnF1b3Q7IGFyZ3VtZW50LjxvOnA+PC9vOnA+
PC9wPg0KPGJsb2NrcXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNvbGlkICND
Q0NDQ0MgMS4wcHQ7cGFkZGluZzowaW4gMGluIDBpbiA2LjBwdDttYXJnaW4tbGVmdDo0LjhwdDtt
YXJnaW4tcmlnaHQ6MGluIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxicj4NCjxicj4NCjxicj4N
CiZuYnNwOyAmbmJzcDsgQmVzdCw8YnI+DQo8YnI+DQombmJzcDsgJm5ic3A7IEhlbms8YnI+DQo8
YnI+DQombmJzcDsgJm5ic3A7IE9uIDAyLzAzLzIwMTcgMDU6NDMgUE0sIEFkYW0gTW9udHZpbGxl
IHdyb3RlOjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyBJIHRob3VnaHQgSSdkIHRyeSB0byBicmVh
ayB0aGlzIGRpc2N1c3Npb24gb3V0IG9mIGl0J3MgZm9ybWVyIHRocmVhZDxicj4NCiZuYnNwOyAm
bmJzcDsgJmd0OyBpbnRvIG9uZSBvZiBpdHMgb3duLCBpbiBjYXNlIHRoYXQgbWFrZXMgaXQgZWFz
aWVyIGZvciBmb2xrcyB0byBvcGluZS48YnI+DQombmJzcDsgJm5ic3A7ICZndDsgVGhlIGxpc3Qg
b2YgJnF1b3Q7Y29tcG9uZW50cyZxdW90OyBvciAmcXVvdDtmdW5jdGlvbiBncm91cHMmcXVvdDsg
c2VlbXMgcmVhc29uYWJsZSB0byBtZS48YnI+DQombmJzcDsgJm5ic3A7ICZndDsgSW4gcHJhY3Rp
Y2UsIHRoZXJlICptYXkqIGJlIGEgZGVzaXJlIHRvIGhhdmUgdGhhdCBzb2Z0d2FyZSBhY3Rpbmc8
YnI+DQombmJzcDsgJm5ic3A7IGFzIGFuPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7IGVuZHBvaW50
IHJlcG9zaXRvcnkgYWxzbyBhY3QgYXMgdGhlIHJlcG9zaXRvcnkgZm9yIGFzc2Vzc21lbnQgcmVz
dWx0cy48YnI+DQombmJzcDsgJm5ic3A7ICZndDsgT3IsIHRoZXNlIGNvdWxkIGJlIGltcGxlbWVu
dGVkIGluIGRpc3RpbmN0IHNlcnZpY2VzLjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZu
YnNwOyAmbmJzcDsgJmd0OyBXaGF0IHdvcmtzIGZvciBvdXIgcHVycG9zZXM/PGJyPg0KJm5ic3A7
ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7IEFkYW08YnI+DQombmJzcDsgJm5i
c3A7ICZndDs8YnI+DQombmJzcDsgJm5ic3A7ICZndDsgT24gVGh1LCBGZWIgMiwgMjAxNyBhdCAx
MDo0MCBBTSBBZGFtIE1vbnR2aWxsZTxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyAmbHQ7PGEgaHJl
Zj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+YWRh
bS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+ICZsdDttYWlsdG86PGEgaHJlZj0ibWFpbHRvOmFk
YW0udy5tb250dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+YWRhbS53Lm1vbnR2aWxs
ZUBnbWFpbC5jb208L2E+Jmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmx0O21haWx0bzo8YSBocmVm
PSJtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFt
LncubW9udHZpbGxlQGdtYWlsLmNvbTwvYT48YnI+DQombmJzcDsgJm5ic3A7ICZsdDttYWlsdG86
PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFu
ayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+Jmd0OyZndDsmZ3Q7IHdyb3RlOjxicj4N
CiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsg
Jm5ic3A7T25jZSBmb2xrcyBoYXZlIGhhZCBhbiBvcHBvcnR1bml0eSB0byByZXZpZXcgdGhlIHZ1
bG5lcmFiaWxpdHk8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO3Nj
ZW5hcmlvIGluZm9ybWF0aW9uIHdlJ3ZlIGJlZW4gd29ya2luZyBvbiwgd2hhdCBhcmUgeW91ciB0
aG91Z2h0czxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7b24gdGhl
IG1haW4gY29tcG9uZW50cyB3ZSdyZSBwcmVzZW50bHkgZm9jdXNlZCBvbiBmb3IgdGhpczxicj4N
CiZuYnNwOyAmbmJzcDsgbmFycm93bHk8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5i
c3A7ICZuYnNwO3Njb3BlZCBleGVyY2lzZT8mbmJzcDsgVGhlc2UgYXJlOjxicj4NCiZuYnNwOyAm
bmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7VnVs
bmVyYWJpbGl0eSBEZXRlY3Rpb24gRGF0YSBSZXBvc2l0b3J5PGJyPg0KJm5ic3A7ICZuYnNwOyAm
Z3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDtWdWxuZXJhYmlsaXR5IEFzc2Vzc29yPGJyPg0KJm5ic3A7
ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDtFbmRwb2ludCBSZXBvc2l0b3J5PGJyPg0K
Jm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDtDb2xsZWN0b3I8YnI+DQombmJz
cDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO0Fzc2Vzc21lbnQgUmVzdWx0IFJlcG9z
aXRvcnk8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwO0VuZHBvaW50
PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5i
c3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNw
OyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDtPbiBUaHUsIEZlYiAyLCAyMDE3IGF0IDEwOjI4IEFN
IEFkYW0gTW9udHZpbGxlPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJz
cDsmbHQ7PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9
Il9ibGFuayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+PGJyPg0KJm5ic3A7ICZuYnNw
OyAmbHQ7bWFpbHRvOjxhIGhyZWY9Im1haWx0bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbSIg
dGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tPC9hPiZndDs8YnI+DQom
bmJzcDsgJm5ic3A7ICZsdDttYWlsdG86PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVA
Z21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+
PG86cD48L286cD48L3A+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxicj4N
CiZuYnNwOyAmbmJzcDsgJmx0O21haWx0bzo8YSBocmVmPSJtYWlsdG86YWRhbS53Lm1vbnR2aWxs
ZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTwv
YT4mZ3Q7Jmd0OyZndDsgd3JvdGU6PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7
ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0hpIEV2ZXJ5b25l
LiZuYnNwOyBBIGZldyBvZiB1cyB3ZXJlIGFibGUgdG8gbWFrZSB0aGUgdnVsbmVyYWJpbGl0eTxi
cj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtz
Y2VuYXJpbyBjYWxsIHRvZGF5IGFuZCBJIHRoaW5rIHdlIGhhZCBhIGdvb2QsIHRob3VnaCBhdCB0
aW1lczxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDtzcGlyaXRlZCwgZGlzY3Vzc2lvbi4mbmJzcDsgV2UgZGlkIHJlY29yZCB0aGUgbWVldGlu
Zywgd2hpY2ggaXM8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7YXZhaWxhYmxlIGF0IFsxXS4mbmJzcDsgV2UgZGlzY3Vzc2VkIHRoZSBhdHRh
Y2hlZCAoYW5ub3RhdGVkIHdpdGg8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7c29tZSBtZWV0aW5nIG5vdGVzKSBVTUwtaXNoIHNlcXVlbmNl
IGRpYWdyYW0uJm5ic3A7IEkgaGFkIGNyZWF0ZWQ8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJz
cDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7dGhhdCBkaWFncmFtIHRvIHN0YXJ0IGEgY29u
dmVyc2F0aW9uIChtaXNzaW9uIGFjY29tcGxpc2hlZCBvbjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0
OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDt0aGF0IGZyb250IEkgdGhpbmspIC0t
IGEgY29udmVyc2F0aW9uIHRoYXQgd291bGQgbGVhZCB1czxicj4NCiZuYnNwOyAmbmJzcDsgdG93
YXJkPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZu
YnNwO2lkZW50aWZ5aW5nIHRoZSBkaXNjcmV0ZSBjb21wb25lbnRzLCBpbnRlcmZhY2VzLCBhbmQ8
YnI+DQombmJzcDsgJm5ic3A7IGluZm9ybWF0aW9uPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3JlcXVpcmVkIHRvIGJlIHNlbnQgb3ZlciB0
aG9zZSBpbnRlcmZhY2VzLiZuYnNwOyBUaGUgVU1MLWlzaDxicj4NCiZuYnNwOyAmbmJzcDsgZGlh
Z3JhbTxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDtyZXByZXNlbnRzIGEgKnNpbmdsZSogZmxvdyB0aHJvdWdoIHRoZSBzeXN0ZW0gLS0gYSAm
cXVvdDtvbmUtdGltZSZxdW90Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDtmbG93IHRocm91Z2ggdGhlIHN5c3RlbS4mbmJzcDsgSXQgaWdu
b3JlcywgZm9yIHRoZSB0aW1lIGJlaW5nLCB0aGU8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJz
cDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7Y29udGludW91cyBhc3BlY3Qgb2Ygb3VyIGNo
YXJ0ZXIgaW4gZmF2b3Igb2YgZ2V0dGluZyBzdGFydGVkPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3dpdGggdGhlIGJhc2ljcy4mbmJzcDsg
T25jZSB3ZSBoYXZlIGEgZ29vZCB1bmRlcnN0YW5kaW5nIG9mIHRoZTxicj4NCiZuYnNwOyAmbmJz
cDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtiYXNpY3MgLS0gdGhlIGNv
bXBvbmVudHMsIGludGVyZmFjZXMsIGFuZCBpbmZvcm1hdGlvbiByZXF1aXJlZDxicj4NCiZuYnNw
OyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDstLSB3ZSBjYW4g
c3RhcnQgbG9vayBhdCBhIGNvbnRpbnVvdXMgbW9uaXRvcmluZyBzZXF1ZW5jZTxicj4NCiZuYnNw
OyAmbmJzcDsgKHdoaWNoPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7ICZuYnNwO2NvdWxkIGJlIHJlcHJlc2VudGVkIGFzIGEgZGlzdGluY3QgZGlhZ3Jh
bSkgdG8gZGV0ZXJtaW5lIHdoYXQ8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7bW9yZSB3ZSBuZWVkLiZuYnNwOyBUaGVuLCBJIHRoaW5rLCB3
ZSBjYW4gc3RhcnQgZHJhZnRpbmcgc29sdXRpb25zLjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxi
cj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtP
bmUgb2YgdGhlIGZpcnN0IGlzc3VlcyBpcyB0aGF0IHdlIG5lZWQgdG8gZmlndXJlIG91dCBpZiB0
aGU8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7Y29tcG9uZW50cyBpbiB0aGUgYmFzZSBmbG93IGFyZSBhY2N1cmF0ZS4mbmJzcDsgVGhlIG1h
aW4gc3VnZ2VzdGlvbjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDt3ZSd2ZSB0b3NzZWQgYXJvdW5kIHNvIGZhciBpcyB0byBjb21iaW5lIHRo
ZSBFbmRwb2ludDxicj4NCiZuYnNwOyAmbmJzcDsgUmVwb3NpdG9yeTxicj4NCiZuYnNwOyAmbmJz
cDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDt3aXRoIHRoZSBBc3Nlc3Nt
ZW50IFJlc3VsdCBSZXBvc2l0b3J5Ljxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZuYnNw
OyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtXZSB0YWxrZWQg
YnJpZWZseSBhYm91dCB3aGF0IGludGVyZmFjZSB3ZSBjb3VsZCB1c2UgZm9yPGJyPg0KJm5ic3A7
ICZuYnNwOyB0aGUgVkREPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7ICZuYnNwO1JlcG9zaXRvcnksIGFuZCBuYXR1cmFsbHkgUk9MSUUgY2FtZSB1cCBh
cyBhbiBvcHRpb24uPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAm
Z3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1dlIHRhbGtlZCBhIGxpdHRsZSBi
aXQgYWJvdXQgdGhlIGZpcnN0ICZxdW90O2dldCBlbmRwb2ludHMmcXVvdDs8YnI+DQombmJzcDsg
Jm5ic3A7IG9wZXJhdGlvbjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDtiZXR3ZWVuIHRoZSBWdWxuZXJhYmlsaXR5IEFzc2Vzc29yIGFuZCB0
aGUgRW5kcG9pbnQgUmVwb3NpdG9yeTxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJz
cDsgJm5ic3A7ICZuYnNwOyAmbmJzcDstLSBzcGVjaWZpY2FsbHkgYWJvdXQgd2hldGhlciB3ZSBz
aG91bGQgcmVwcmVzZW50IG9uIHRoaXM8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7c2VxdWVuY2UgZGlhZ3JhbSB0aGF0IGluZm9ybWF0aW9u
IHN1cHBvcnRpbmcgYSBqdWRnZW1lbnQgb2Y8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7JnF1b3Q7c3RhbGUmcXVvdDsgd291bGQgYmUgbmVl
ZGVkLjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtXZSBsZWZ0IG9wZW4gdGhlIHRpbWUgd2hlbiB3
ZSB3b3VsZCBuZXh0IG1lZXQsIGZhdm9yaW5nIHRvPGJyPg0KJm5ic3A7ICZuYnNwOyB3b3JrPGJy
Pg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3Ro
YXQgb3V0IG9uLWxpc3QuJm5ic3A7IE5leHQgd2VlayBpcyBUQ0csIHNvIHRoYXQgbWF5IGJlIGRp
ZmZpY3VsdDs8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7dGhlIGZvbGxvd2luZyB3ZWVrIGlzIFJTQSwgc28gdGhhdCBtYXkgYmUgZGlmZmlj
dWx0Ljxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtGb3IgdGhvc2Ugd2hvIHdlcmUgaW4gYXR0ZW5k
YW5jZSB0b2RheSwgcGxlYXNlIGFkZCB0byB0aGlzPGJyPg0KJm5ic3A7ICZuYnNwOyBub3RlPGJy
Pg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3dp
dGggeW91ciBjb21tZW50cy9jb3JyZWN0aW9ucy48YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+
DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7S2lu
ZCByZWdhcmRzLDxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0
OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtBZGFtPGJyPg0KJm5ic3A7ICZuYnNw
OyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwO1sxXTxicj4NCiZuYnNwOyAmbmJzcDsgPGEgaHJlZj0iaHR0cHM6Ly9kcml2ZS5nb29n
bGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERPSHBWUjB0TWQxRSIgdGFyZ2V0PSJfYmxh
bmsiPg0KaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERP
SHBWUjB0TWQxRTwvYT48YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQombmJzcDsgJm5ic3A7
ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7T24gTW9uLCBKYW4gMzAsIDIw
MTcgYXQgMTE6MjEgQU0gQWRhbSBNb250dmlsbGU8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJz
cDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7Jmx0OzxhIGhyZWY9Im1haWx0bzphZGFtLncu
bW9udHZpbGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21h
aWwuY29tPC9hPjxicj4NCiZuYnNwOyAmbmJzcDsgJmx0O21haWx0bzo8YSBocmVmPSJtYWlsdG86
YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9udHZp
bGxlQGdtYWlsLmNvbTwvYT4mZ3Q7PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+Jm5ic3A7ICZuYnNwOyAmbHQ7bWFpbHRvOjxhIGhyZWY9Im1haWx0
bzphZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250
dmlsbGVAZ21haWwuY29tPC9hPiAmbHQ7bWFpbHRvOjxhIGhyZWY9Im1haWx0bzphZGFtLncubW9u
dHZpbGxlQGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmFkYW0udy5tb250dmlsbGVAZ21haWwu
Y29tPC9hPiZndDsmZ3Q7Jmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDt3cm90ZTo8YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQom
bmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDtIaSBldmVyeW9uZS4mbmJzcDsgSnVzdCBhIGZyaWVuZGx5IHJlbWluZGVyIHRoYXQg
d2UgYXJlPGJyPg0KJm5ic3A7ICZuYnNwOyBwbGFubmluZzxicj4NCiZuYnNwOyAmbmJzcDsgJmd0
OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3RvIG1lZXQg
YWdhaW4gdGhpcyBUaHVyc2RheSBhdCB0aGUgc2FtZSB0aW1lICgyLzIgQCAxMGFtPGJyPg0KJm5i
c3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsg
Jm5ic3A7RWFzdGVybi8zcG0gVVRDKSB1c2luZyBTQUNNJ3MgbWVldGluZyByb29tIGF0PGJyPg0K
Jm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7PGEgaHJlZj0iaHR0cHM6Ly9pZXRmLndlYmV4LmNvbS9tZWV0L3NhY20iIHRhcmdl
dD0iX2JsYW5rIj5odHRwczovL2lldGYud2ViZXguY29tL21lZXQvc2FjbTwvYT4uPGJyPg0KJm5i
c3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7S2luZCByZWdhcmRzLDxicj4NCiZuYnNwOyAm
bmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZu
YnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0FkYW08YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+
DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtPbiBUaHUsIEphbiAxOSwgMjAxNyBh
dCAxMTozNSBBTSBBZGFtIE1vbnR2aWxsZTxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyZsdDs8YSBocmVmPSJtYWls
dG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5hZGFtLncubW9u
dHZpbGxlQGdtYWlsLmNvbTwvYT48YnI+DQombmJzcDsgJm5ic3A7ICZsdDttYWlsdG86PGEgaHJl
Zj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+YWRh
bS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+Jmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZu
YnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyZsdDttYWlsdG86
PGEgaHJlZj0ibWFpbHRvOmFkYW0udy5tb250dmlsbGVAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFu
ayI+YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb208L2E+PG86cD48L286cD48L3A+DQo8ZGl2Pg0K
PGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxicj4NCiZuYnNwOyAmbmJzcDsgJmx0O21haWx0
bzo8YSBocmVmPSJtYWlsdG86YWRhbS53Lm1vbnR2aWxsZUBnbWFpbC5jb20iIHRhcmdldD0iX2Js
YW5rIj5hZGFtLncubW9udHZpbGxlQGdtYWlsLmNvbTwvYT4mZ3Q7Jmd0OyZndDsgd3JvdGU6PGJy
Pg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtIZWxsby4g
QSBmZXcgb2YgdXMgbWV0IGluZm9ybWFsbHkgdG9kYXkgdG8gZGlzY3VzcyB0aGU8YnI+DQombmJz
cDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwO3Z1bG5lcmFiaWxpdHkgc2NlbmFyaW8gaW4gc29tZSBtb3JlIGRl
dGFpbCB3aXRoPGJyPg0KJm5ic3A7ICZuYnNwOyB0aGUgZ29hbDxicj4NCiZuYnNwOyAmbmJzcDsg
Jmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7b2YgbWFpbnRhaW5pbmcgdGhlIG5hcnJvdyBmb2N1cyBvbiBhIHZ1bG5lcmFiaWxp
dHk8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO2Fzc2Vzc21lbnQgc2xpY2UgdGhyb3VnaCBv
dXIgbm90aW9uYWwgZW52aXJvbm1lbnQuJm5ic3A7IFdlPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDthcmUgdGVuZGluZyB0byBsb29rIGF0IG1ham9yIGNvbXBvbmVudHMgYXMgYmxhY2sgYm94
ZXM8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3dpdGggaW50ZXJmYWNlcyBhbmQgZGF0YSBm
b3JtYXQgZXhwZWN0YXRpb25zLCBhbmQ8YnI+DQombmJzcDsgJm5ic3A7IHdlIGFyZTxicj4NCiZu
YnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7bm90IG5lY2Vzc2FyaWx5IGNvbmNlcm5lZCB3aXRoIGhvdyB0
aG9zZSBjb21wb25lbnRzIGRvPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDt0aGluZ3MgaW50
ZXJuYWxseS9iZWhpbmQgdGhlIHNjZW5lcy48YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQom
bmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwO1RoZSBtZWV0aW5nIHdhcyByZWNvcmRlZCAoeW91IGNhbiBm
aW5kIGl0IHdpdGggdG9kYXknczxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ZGF0ZSBhdCBb
MV0pLiZuYnNwOyBUaGUgdG9waWMgb2YgZGlzY3Vzc2lvbiB3YXM8YnI+DQombmJzcDsgJm5ic3A7
IHByaW1hcmlseSBpbjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7dGhlICZxdW90O3BoYXNl
IDEmcXVvdDsgYXJlYSBvZiB3aGF0IERhbm55IHNlbnQgdG8gdGhlIGxpc3Qgbm90PGJyPg0KJm5i
c3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDt2ZXJ5IGxvbmcgYWdvIFsyXSwgYW5kIHJlc3VsdGVkIGluIGEg
KnN0YXJ0aW5nIHBvaW50Kjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ZGlhZ3JhbSBbM10u
PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZu
YnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtUaGUg
Z3JvdXAgd2hvIG1ldCB0b2RheSBhcmUgKHJvdWdobHkpIGFncmVlZCBvbjxicj4NCiZuYnNwOyAm
bmJzcDsgdGhlIHNpeDxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7bWFpbiAmcXVvdDtjb21w
b25lbnRzJnF1b3Q7IHJlcHJlc2VudGVkIGluIHRoYXQgZGlhZ3JhbSwgYnV0PGJyPg0KJm5ic3A7
ICZuYnNwOyBhbHNvPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtzZWUgdGhhdCB3ZSBoYXZl
IHNvbWUgd29yayBhaGVhZC4mbmJzcDsgU3BlY2lmaWNhbGx5LCB3ZTxicj4NCiZuYnNwOyAmbmJz
cDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7cXVpY2tseSByZWNvZ25pemVkIHRoYXQgc29tZSBvZiB0aGUgYXNzdW1wdGlv
bnMgdGhlPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDt2dWxuZXJhYmlsaXR5IGRyYWZ0IG1h
a2VzIG1heSBiZSBhc3N1bXB0aW9ucyB3ZSBjYW5ub3Q8YnI+DQombmJzcDsgJm5ic3A7ICZndDsm
bmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZu
YnNwO2FmZm9yZCB0byBtYWtlIGFuZCBuZWVkIHRvIGluY2x1ZGUgaW4gdGhlIGV4cGxvcmF0aW9u
Ljxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7V2Ug
dGhvdWdodCBpdCB3b3VsZCBiZSBhIGdvb2QgaWRlYSB0byBoYXZlIGFub3RoZXI8YnI+DQombmJz
cDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwO2luZm9ybWFsIGRpc2N1c3Npb24gaW4gYSBjb3VwbGUgb2Ygd2Vl
a3MgKEZlYnJ1YXJ5PGJyPg0KJm5ic3A7ICZuYnNwOyAyKSBhdDxicj4NCiZuYnNwOyAmbmJzcDsg
Jmd0OyZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJz
cDsgJm5ic3A7dGhlIHNhbWUgdGltZSAoMTBhbSBFYXN0ZXJuIC8gM3BtIFVUQyksIHVzaW5nIHRo
ZSBzYW1lPGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDtXZWJFeCBbNF0uJm5ic3A7ICZuYnNw
O0F0IHRoYXQgdGltZSB3ZSBpbnRlbmQgdG8gcm9sbDxicj4NCiZuYnNwOyAmbmJzcDsgdGhyb3Vn
aCB0aGU8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO3Z1bG5lcmFiaWxpdHkgYXNzZXNzbWVu
dCBzY2VuYXJpbyBhc3N1bXB0aW9ucyBpbiBhbjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7
ZWZmb3J0IHRvIGRldGVybWluZSB3aGljaCBvbmVzIGNhbiBiZSBsZWZ0IGFzPGJyPg0KJm5ic3A7
ICZuYnNwOyAmZ3Q7Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDthc3N1bXB0aW9ucyBhbmQgd2hpY2ggb25lcyBjYW5ub3QuJm5ic3A7
IFRoZW4gd2UnbGwgdGFrZTxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7YW5vdGhlciBsb29r
IGF0IHRoZSBkaWFncmFtIGFuZCB3b3JrIG9uIGl0cyBuZXh0PGJyPg0KJm5ic3A7ICZuYnNwOyB2
ZXJzaW9uLjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0Ozxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OyZu
YnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7U3RheSB0dW5lZC48YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQombmJzcDsgJm5ic3A7
ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwO1RoYW5rcyB0byBEYW5ueSwgU3RlcGhlbiwgYW5kIEplcm9tZSBmb3Igam9pbmlu
ZyBhbmQ8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO2NvbnRyaWJ1dGluZyE8YnI+DQombmJz
cDsgJm5ic3A7ICZndDs8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNw
OyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0tpbmQgcmVnYXJkcyw8
YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO0FkYW08
YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQombmJzcDsgJm5ic3A7ICZndDs8YnI+DQombmJz
cDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAm
bmJzcDsgJm5ic3A7ICZuYnNwO1sxXTxicj4NCiZuYnNwOyAmbmJzcDsgPGEgaHJlZj0iaHR0cHM6
Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYldHaERPSHBWUjB0TWQxRSIg
dGFyZ2V0PSJfYmxhbmsiPg0KaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5
VW41RmRDYldHaERPSHBWUjB0TWQxRTwvYT48YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsg
Jm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1sy
XTxicj4NCiZuYnNwOyAmbmJzcDsgPGEgaHJlZj0iaHR0cHM6Ly9tYWlsYXJjaGl2ZS5pZXRmLm9y
Zy9hcmNoL21zZy9zYWNtL19MaUtseXZBd3NfT1ZMRmhCNU5TVTU4TVhETSIgdGFyZ2V0PSJfYmxh
bmsiPg0KaHR0cHM6Ly9tYWlsYXJjaGl2ZS5pZXRmLm9yZy9hcmNoL21zZy9zYWNtL19MaUtseXZB
d3NfT1ZMRmhCNU5TVTU4TVhETTwvYT48YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1szXTxi
cj4NCiZuYnNwOyAmbmJzcDsgPGEgaHJlZj0iaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/
aWQ9MEI4V2Y5VW41RmRDYk1VNXBkVFJqZWpKdE5IYyIgdGFyZ2V0PSJfYmxhbmsiPg0KaHR0cHM6
Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MEI4V2Y5VW41RmRDYk1VNXBkVFJqZWpKdE5IYzwv
YT48YnI+DQombmJzcDsgJm5ic3A7ICZndDsmbmJzcDsgJm5ic3A7ICZuYnNwOyAmbmJzcDsgJm5i
c3A7ICZuYnNwOyAmbmJzcDsgJm5ic3A7ICZuYnNwO1s0XSA8YSBocmVmPSJodHRwczovL2lldGYu
d2ViZXguY29tL21lZXQvc2FjbSIgdGFyZ2V0PSJfYmxhbmsiPg0KaHR0cHM6Ly9pZXRmLndlYmV4
LmNvbS9tZWV0L3NhY208L2E+PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZu
YnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7PGJyPg0KJm5ic3A7ICZuYnNwOyAmZ3Q7
IF9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPGJyPg0KJm5i
c3A7ICZuYnNwOyAmZ3Q7IHNhY20gbWFpbGluZyBsaXN0PG86cD48L286cD48L3A+DQo8L2Rpdj4N
CjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0
Ij4mbmJzcDsgJm5ic3A7ICZndDsgPGEgaHJlZj0ibWFpbHRvOnNhY21AaWV0Zi5vcmciIHRhcmdl
dD0iX2JsYW5rIj4NCnNhY21AaWV0Zi5vcmc8L2E+ICZsdDttYWlsdG86PGEgaHJlZj0ibWFpbHRv
OnNhY21AaWV0Zi5vcmciIHRhcmdldD0iX2JsYW5rIj5zYWNtQGlldGYub3JnPC9hPiZndDs8YnI+
DQombmJzcDsgJm5ic3A7ICZndDsgPGEgaHJlZj0iaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1h
bi9saXN0aW5mby9zYWNtIiB0YXJnZXQ9Il9ibGFuayI+aHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFp
bG1hbi9saXN0aW5mby9zYWNtPC9hPjxicj4NCiZuYnNwOyAmbmJzcDsgJmd0OzxvOnA+PC9vOnA+
PC9wPg0KPC9ibG9ja3F1b3RlPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48
YnI+DQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXzxicj4N
CnNhY20gbWFpbGluZyBsaXN0PGJyPg0KPGEgaHJlZj0ibWFpbHRvOnNhY21AaWV0Zi5vcmciIHRh
cmdldD0iX2JsYW5rIj5zYWNtQGlldGYub3JnPC9hPjxicj4NCjxhIGhyZWY9Imh0dHBzOi8vd3d3
LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vc2FjbSIgdGFyZ2V0PSJfYmxhbmsiPmh0dHBzOi8v
d3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vc2FjbTwvYT48bzpwPjwvbzpwPjwvcD4NCjwv
ZGl2Pg0KPC9kaXY+DQo8L2Jsb2NrcXVvdGU+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPHAgY2xhc3M9
Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48YnI+DQpfX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXzxicj4NCnNhY20gbWFpbGluZyBs
aXN0PGJyPg0KPGEgaHJlZj0ibWFpbHRvOnNhY21AaWV0Zi5vcmciPnNhY21AaWV0Zi5vcmc8L2E+
PGJyPg0KPGEgaHJlZj0iaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9zYWNt
IiB0YXJnZXQ9Il9ibGFuayI+aHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9z
YWNtPC9hPjxvOnA+PC9vOnA+PC9wPg0KPC9ibG9ja3F1b3RlPg0KPC9kaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4N
CjwvYm9keT4NCjwvaHRtbD4NCg==

--_000_MWHPR09MB144041D0D82277BABA7C85A2F0560MWHPR09MB1440namp_--


From nobody Tue Feb 28 21:45:46 2017
Return-Path: <athiasjerome@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4014E127058 for <sacm@ietfa.amsl.com>; Tue, 28 Feb 2017 21:45:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.698
X-Spam-Level: 
X-Spam-Status: No, score=-1.698 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 48zIOIWU-eGU for <sacm@ietfa.amsl.com>; Tue, 28 Feb 2017 21:45:41 -0800 (PST)
Received: from mail-vk0-x22a.google.com (mail-vk0-x22a.google.com [IPv6:2607:f8b0:400c:c05::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 60DE8120726 for <sacm@ietf.org>; Tue, 28 Feb 2017 21:45:41 -0800 (PST)
Received: by mail-vk0-x22a.google.com with SMTP id t8so3831465vke.3 for <sacm@ietf.org>; Tue, 28 Feb 2017 21:45:41 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=ZW9kB9EO43/oKbXNcxLr7JBSTcABpYWYFdGHiEA+BeQ=; b=iZhWFSgupwkR5ijFUuwP2d7Kk3iOjhPnX2PZs/RF1Ic9q4FA+dhM7oLuEHDd+OuByy 6sOmGl9XmjIHhYcg3Bj0SXLl9kAxwqF2EvHSKSnXOfILGoFrQoWrkRA+Ji1uXFANzj7n oaYgujg6L+h+itbP7/MPh7asdpW+OdIM35ekmTF7G2A7CCOF9hAo3mCaZz+1gpSCqEnD BPIJnSop1HAxcTgHpaK/Px83++DxBUPiXFo+0T51zZSroCsdcULDdejnhj4dbzuD936N q9cX2Ke0ZkgmtFjl0r/GglSs+Y+l6Tpchl5Nd3dwubT5zyxPEfF72BG1ugxmHwmAOt+f MBmA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=ZW9kB9EO43/oKbXNcxLr7JBSTcABpYWYFdGHiEA+BeQ=; b=ZZXWVtCWqcCwY2Mn0eR+l70oj4z9nYxu5E8bEcNjIHHr9pfHQfK5GRTaQyQmRIu5qR +mfo5nEW3okWcRzEnTz1TD82WskXkmb4y5zemiN+DkC4rDkWC/+Ld8v++M7kgCLzKZKg nWQ1oEUndAhKF0uqmS83+8ceF0ypuwio3lhXO7l2iHwuu2EV+IOyBVJMQE5pTE2Yaf24 A5uJo8YWENuOHB1afVKqi4Vo/IJMR5xxdLqAeNneuIlvke6nR8fkwOuXvlwM0Gl6ZC+K O+ZGOAJhmGIW4+7hjCfqkYBYJQDZLkZ/kLsVeOtaSzmR6esxTidL+v0i0p0qWdwCorUF LGOg==
X-Gm-Message-State: AMke39n9a3Kuf3WDAUKlPE6KXmG+H0CZEpvwZdx0R7ejI7Cy2GEYr2e3MEoY3C5GAl93yrLt5pblbc2FozMN3Q==
X-Received: by 10.31.50.20 with SMTP id y20mr2806862vky.165.1488347140027; Tue, 28 Feb 2017 21:45:40 -0800 (PST)
MIME-Version: 1.0
Received: by 10.31.160.14 with HTTP; Tue, 28 Feb 2017 21:45:39 -0800 (PST)
In-Reply-To: <MWHPR09MB144041D0D82277BABA7C85A2F0560@MWHPR09MB1440.namprd09.prod.outlook.com>
References: <CACknUNU_5RX_cDLeOSXfJuCCQ0pEkvNjVAku8htORbAq6cEm8g@mail.gmail.com> <CACknUNXUJ=VqG8WObL4h_YO-e0XSE6pHTjV7Ox4qKzMVgv7-dA@mail.gmail.com> <CACknUNVi1mYiJNujX8a--XDyoK6PkfodsiX6RAoL+DPGOLMNDg@mail.gmail.com> <CACknUNXHdUr7DpaozypV+KkydO77XjQa=6siu1VbJdEWiGNbBw@mail.gmail.com> <CACknUNWFhWqBV485XrLT4Rs+8rz0-5aLWJRqBstOH1743RX3VA@mail.gmail.com> <147f77a8-ea0f-ed43-f585-a70a231110fe@sit.fraunhofer.de> <CACknUNXx=F6DatwikXgs4NGFgbbQMnMPCiGfX4UKfYLh67RUog@mail.gmail.com> <cc9e09ec-05fc-1af2-9f9b-50cf3ef16fd1@sit.fraunhofer.de> <CAKUOEQxTQWLuPGcnhuZEZTK3MJ80W-u74iho9d4yH9StB7jO0A@mail.gmail.com> <CAA=AuEfDzOmpRsLQ6b2DWcDn7ZYhBZ=PB_R8M6SG_mypgLFAkQ@mail.gmail.com> <MWHPR09MB144041D0D82277BABA7C85A2F0560@MWHPR09MB1440.namprd09.prod.outlook.com>
From: Jerome Athias <athiasjerome@gmail.com>
Date: Wed, 1 Mar 2017 08:45:39 +0300
Message-ID: <CAA=AuEfAdSiGpC9Of82A=4xf5Tn8uPuwa3PsStbpK_=49fko0w@mail.gmail.com>
To: "Waltermire, David A. (Fed)" <david.waltermire@nist.gov>
Content-Type: multipart/alternative; boundary=001a11430fb2957cdc0549a4d200
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/tJc6Bku9Dm0LV7uvfMNOmAz87hs>
Cc: Bill Munyan <bill.munyan.ietf@gmail.com>, Adam Montville <adam.w.montville@gmail.com>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, "<sacm@ietf.org>" <sacm@ietf.org>
Subject: Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability Scenario Working Session)
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Mar 2017 05:45:45 -0000

--001a11430fb2957cdc0549a4d200
Content-Type: text/plain; charset=UTF-8

Yes correct.
I concur with your recommended approach of identifying the workflow entry
points.

An example is a change in the endpoint repository, lets say event: a new
device is connected, one would want to trigger an assessment "a la NAC"


On Tue, Feb 28, 2017 at 9:31 PM, Waltermire, David A. (Fed) <
david.waltermire@nist.gov> wrote:

> Jerome,
>
>
>
> IMHO, we need to identify the places within the workflow where triggers
> may occur. These are the workflow entry points. It would also be useful to
> identify the events that may cause these triggers for clarity sake.
>
>
>
> Is this what you are saying?
>
>
>
> Regards,
>
> Dave
>
>
>
>
>
> *From:* sacm [mailto:sacm-bounces@ietf.org] *On Behalf Of *Jerome Athias
> *Sent:* Tuesday, February 28, 2017 5:39 AM
> *To:* Bill Munyan <bill.munyan.ietf@gmail.com>
> *Cc:* Henk Birkholz <henk.birkholz@sit.fraunhofer.de>; <sacm@ietf.org> <
> sacm@ietf.org>; Adam Montville <adam.w.montville@gmail.com>
> *Subject:* Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability
> Scenario Working Session)
>
>
>
> Greetings,
>
>
>
> So taking IACD (Ref [0] Appendix A1) as an example for illustration, would
> that help to first list triggering "events"/preconditions?
>
>
>
> Regards
>
>
>
> [0] https://secwww.jhuapl.edu/iacdcommunityday/Resources/
> IACD%20Baseline%20Reference%20Architecture%20-%20Final%20PR.pdf
>
>
>
>
>
>
>
> On Mon, Feb 6, 2017 at 5:17 PM, Bill Munyan <bill.munyan.ietf@gmail.com>
> wrote:
>
> I wanted to clarify one assumption I have been making when viewing the
> diagram.  I am viewing the overall vulnerability scenario as a series of
> event-driven use-cases, with this diagram simply depicting one of those
> use-cases:  When new VDD is introduced into the scenario.
>
>
>
> Feasibly, a number of different events could trigger entry into the
> vulnerability scenario, such as a "staleness trigger", or a "new endpoint
> added trigger", and many more.  Each of these events could (and should)
> have their own diagram outlining how the components interact to request
> new/updated VDD, determine the endpoints which should be assessed, and what
> to do with their results.  As such, each of the components in the diagrams
> can be seen as conceptual, allowing for implementers to determine how best
> to consolidate components for their use.
>
>
>
> Please bash my thought process if I'm way off on this, but I thought it
> might help in this discussion, because it seems like some of the
> "disagreement" in the diagram is stemming from "events" which aren't
> necessarily applicable to this particular "event use-case".
>
>
>
> Cheers,
>
> -Bill M.
>
>
>
>
>
> On Fri, Feb 3, 2017 at 5:19 PM, Henk Birkholz <
> henk.birkholz@sit.fraunhofer.de> wrote:
>
> Also inline. I hope it is still readable.
>
> On 02/03/2017 10:55 PM, Adam Montville wrote:
>
> Thanks for chiming in Henk.  I'll go inline.  Nothing being said as
> chair.  Just making observations.
>
> On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz
> <henk.birkholz@sit.fraunhofer.de
> <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
>
>     Hi group,
>
>     to recap my understanding:
>
>     There will be trigger conditions that initiate collections of fresh
>     endpoint attributes (from which endpoint posture can be derived) from a
>     target endpoint.
>
>     The obvious trigger condition that an asserting component (in every
>     diagram, I think, that is the Vulnerability Assessor. This assumption
> is
>     based on the interpretation of the diagram, not based on the name of
> the
>     component). From my point of view, in order to assert that a known
>     record is, for example, "stale" (aka does not satisfy an declarative
>     guidance that expresses the quality of freshness) or, as another
>     example, is not yet created the Vulnerability Assessor requires an
>     always up-to-date and exhaustive list of all Assessment Result records.
>
>
> I would disagree.  I have a record from the endpoint repository that it
> timestamped as 3 days old.  My policy says I should not rely on anything
> older than 2 days old.  Then the information is stale, and I instruct to
> collect anew.
>
>
> If the "I" is the Vulnerability Assessor, how does it always have the
> Assessment Result records to check that declarative guidance? Or do you
> propose (in v3) that the Endpoint Repository is checking that freshness
> continuously and notifying the Vulnerability Assessor?
>
>
>
>
>     In consequence, I would assume that either the the Assessment Result
>     Repository component collapses with the Vulnerability Assessor or the
>     Vulnerability Assessor always retains a complete in-sync copy of the
>     Assessment Result Repository.
>
>
> I would again disagree.  It may well be that actual software collapses
> these components into one, but it may be that there is a results
> repository, which is used downstream from vulnerability assessment, into
> which the assessor dumps results.
>
>
> Yes, downstream records are dumped as a result in the corresponding repo.
> But how does the information of not satisfying declarative guidance (a
> result got stale) makes it "upstream" again to trigger collection -
> including imperative guidance what to collect (what just got stale)?
>
>
> Consider when we have configuration assessment down the road.  Would we
> then have a vulnerability assessor and a configuration assessor each
> with their own repository conceptually, or would we be better off with
> one "results repository"?  I think the one.
>
>
> It depends on scalability, I guess, but in the bare-bone first proof of
> concept it seems to be feasible to collapse related pools of data into
> justthe one, as there are no multiple consumers?
>
>
> In practice, applications can choose to implement more than one
> conceptual component.
>
>
> Yes, that is why it is not a problem to collapse sets of functions into a
> single component, in general. I hope this will remain a core feature of the
> architecture at all time.
>
>
>
>
>     Alternatively, the Assessment Result Repository component is collapsed
>     with the Endpoint Repository (as proposed in diagram v3), in which case
>     now the Vulnerability Assessor to retain an continuously in-sync copy
> of
>     the Endpoint Repository? If it is to trigger on the "stale" condition?
>
>
> Again, I am not necessarily in favor of this viewpoint (and I'm not
> necessarily against).  The endpoint repository represents an interface
> to acquire information about endpoints, which does not necessarily need
> to include assessment results pertaining to those endpoints entirely.
>
>
> But isn't that what is depicted in the diagram v3: the assessment results
> repo is merged with endpoint repo? Maybe I am actually a little bit dense
> right now :)
>
>
>
>
>
>     The "keeping pools of data in-sync" seems to be introducing extra steps
>     in the work-flow.
>
>
> Is it really data in sync?  I understand what you're saying, but to me
> the endpoint repository component is where we find assertions about the
> endpoints, the assessors take those assertions and apply some logic to
> pass judgement on the endpoint, and that judgement is stored in the
> assessment results repository component.
>
>
> I simply did not assume that a repository is more than a data store. If it
> does continuous assessments of endpoint records it contains, it most
> certainly can trigger a collection. Maybe the label of the component is
> just misleading me here.
>
>
>
>
>     A pro for this would be that there could be multiple additional
>     consumers of Assessment Results that justify an interface that provides
>     that data to multiple parties.
>
>
> Yes!  There are in practice.  Assessment results have downstream uses
> outside the scope of our charter.
>
>
> I thought so, but it is of course not part of the single snapshot diagram
> and is therefore only implied at best.
>
>
>
>
>     A con for this is the universal "redundant data stores always pose a
>     source of complexity and hence risk of inconsistency" argument.
>
>     Another point of view could be that the "evaluation task" is
> independent
>     from the "trigger collection" (I just made that one up) task? Or maybe
>     it is associated with the worn component?
>
>     Multiple emerging architectures include an orchestration component that
>     consumes notification of changes and derives appropriate actions that
> it
>     can trigger or even conduct. Please note, I am not advocating to
>     introduce yet another component type (which would again add complexity,
>     error, scope creep...) :)
>
>
> Bill mentioned something to me offline yesterday about orchestration.
> In the vulnerability scenario, the orchestration is really being
> performed by the assessor.
>
>
> I think that in the reply above you illustrated that the Endpoint Repo
> also does this assessment by checking for staleness? Or would it "just"
> notify the Assessor to trigger a task? Why not trigger the collector
> directly? What about the imperative guidance what to actually collect again?
>
> It seems that I really have a difficult time to wrap my head around the
> proposal still. Please stay patient with me! :)
>
>
>
>
>     I just try to get a feasible grasp of the actual workflow that the
>     diagram is intended to represent.
>
>
> The most basic path through the system.
>
>
>
>     What am I missing? I actually am surprised that the Assessment Result
>     Repository merges with the Endpoint Repository and not the
> Vulnerability
>     Assessor. What is the advantage?
>
>
> I think we're still talking this one through.  What's the advantage to
> collapsing them at all?
>
>
> Collapsing redundant pools of data is reducing redundancy :) Tasks that
> depend on data that has to be acquired to be conducted benefit from high
> availability and low latency. But I totally understand the "multiple
> consumer" argument.
>
>
>
>
>     Best,
>
>     Henk
>
>     On 02/03/2017 05:43 PM, Adam Montville wrote:
>     > I thought I'd try to break this discussion out of it's former thread
>     > into one of its own, in case that makes it easier for folks to opine.
>     > The list of "components" or "function groups" seems reasonable to me.
>     > In practice, there *may* be a desire to have that software acting
>     as an
>     > endpoint repository also act as the repository for assessment
> results.
>     > Or, these could be implemented in distinct services.
>     >
>     > What works for our purposes?
>     >
>     > Adam
>     >
>     > On Thu, Feb 2, 2017 at 10:40 AM Adam Montville
>     > <adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >     Once folks have had an opportunity to review the vulnerability
>     >     scenario information we've been working on, what are your
> thoughts
>     >     on the main components we're presently focused on for this
>     narrowly
>     >     scoped exercise?  These are:
>     >
>     >     Vulnerability Detection Data Repository
>     >     Vulnerability Assessor
>     >     Endpoint Repository
>     >     Collector
>     >     Assessment Result Repository
>     >     Endpoint
>     >
>     >
>     >
>     >
>     >     On Thu, Feb 2, 2017 at 10:28 AM Adam Montville
>     >     <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     <mailto:adam.w.montville@gmail.com
>
>
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >         Hi Everyone.  A few of us were able to make the vulnerability
>     >         scenario call today and I think we had a good, though at
> times
>     >         spirited, discussion.  We did record the meeting, which is
>     >         available at [1].  We discussed the attached (annotated with
>     >         some meeting notes) UML-ish sequence diagram.  I had created
>     >         that diagram to start a conversation (mission accomplished on
>     >         that front I think) -- a conversation that would lead us
>     toward
>     >         identifying the discrete components, interfaces, and
>     information
>     >         required to be sent over those interfaces.  The UML-ish
>     diagram
>     >         represents a *single* flow through the system -- a "one-time"
>     >         flow through the system.  It ignores, for the time being, the
>     >         continuous aspect of our charter in favor of getting started
>     >         with the basics.  Once we have a good understanding of the
>     >         basics -- the components, interfaces, and information
> required
>     >         -- we can start look at a continuous monitoring sequence
>     (which
>     >         could be represented as a distinct diagram) to determine what
>     >         more we need.  Then, I think, we can start drafting
> solutions.
>     >
>     >         One of the first issues is that we need to figure out if the
>     >         components in the base flow are accurate.  The main
> suggestion
>     >         we've tossed around so far is to combine the Endpoint
>     Repository
>     >         with the Assessment Result Repository.
>     >
>     >         We talked briefly about what interface we could use for
>     the VDD
>     >         Repository, and naturally ROLIE came up as an option.
>     >
>     >         We talked a little bit about the first "get endpoints"
>     operation
>     >         between the Vulnerability Assessor and the Endpoint
> Repository
>     >         -- specifically about whether we should represent on this
>     >         sequence diagram that information supporting a judgement of
>     >         "stale" would be needed.
>     >
>     >         We left open the time when we would next meet, favoring to
>     work
>     >         that out on-list.  Next week is TCG, so that may be
> difficult;
>     >         the following week is RSA, so that may be difficult.
>     >
>     >         For those who were in attendance today, please add to this
>     note
>     >         with your comments/corrections.
>     >
>     >         Kind regards,
>     >
>     >         Adam
>     >
>     >         [1]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >
>     >         On Mon, Jan 30, 2017 at 11:21 AM Adam Montville
>     >         <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>
>     <mailto:adam.w.montville@gmail.com <mailto:adam.w.montville@gmail.com
> >>>
>     >         wrote:
>     >
>     >             Hi everyone.  Just a friendly reminder that we are
>     planning
>     >             to meet again this Thursday at the same time (2/2 @ 10am
>     >             Eastern/3pm UTC) using SACM's meeting room at
>     >             https://ietf.webex.com/meet/sacm.
>     >
>     >             Kind regards,
>     >
>     >             Adam
>     >
>     >
>     >             On Thu, Jan 19, 2017 at 11:35 AM Adam Montville
>     >             <adam.w.montville@gmail.com
>     <mailto:adam.w.montville@gmail.com>
>     >             <mailto:adam.w.montville@gmail.com
>
>
>     <mailto:adam.w.montville@gmail.com>>> wrote:
>     >
>     >                 Hello. A few of us met informally today to discuss
> the
>     >                 vulnerability scenario in some more detail with
>     the goal
>     >                 of maintaining the narrow focus on a vulnerability
>     >                 assessment slice through our notional environment.
> We
>     >                 are tending to look at major components as black
> boxes
>     >                 with interfaces and data format expectations, and
>     we are
>     >                 not necessarily concerned with how those components
> do
>     >                 things internally/behind the scenes.
>     >
>     >                 The meeting was recorded (you can find it with
> today's
>     >                 date at [1]).  The topic of discussion was
>     primarily in
>     >                 the "phase 1" area of what Danny sent to the list not
>     >                 very long ago [2], and resulted in a *starting point*
>     >                 diagram [3].
>     >
>     >                 The group who met today are (roughly) agreed on
>     the six
>     >                 main "components" represented in that diagram, but
>     also
>     >                 see that we have some work ahead.  Specifically, we
>     >                 quickly recognized that some of the assumptions the
>     >                 vulnerability draft makes may be assumptions we
> cannot
>     >                 afford to make and need to include in the
> exploration.
>     >
>     >                 We thought it would be a good idea to have another
>     >                 informal discussion in a couple of weeks (February
>     2) at
>     >                 the same time (10am Eastern / 3pm UTC), using the
> same
>     >                 WebEx [4].   At that time we intend to roll
>     through the
>     >                 vulnerability assessment scenario assumptions in an
>     >                 effort to determine which ones can be left as
>     >                 assumptions and which ones cannot.  Then we'll take
>     >                 another look at the diagram and work on its next
>     version.
>     >
>     >                 Stay tuned.
>     >
>     >                 Thanks to Danny, Stephen, and Jerome for joining and
>     >                 contributing!
>     >
>     >                 Kind regards,
>     >
>     >                 Adam
>     >
>     >
>     >                 [1]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbWGhDOHpVR0tMd1E
>     >                 [2]
>     https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyvAws_OVLFhB5NSU58MXDM
>     >                 [3]
>     https://drive.google.com/open?id=0B8Wf9Un5FdCbMU5pdTRjejJtNHc
>     >                 [4] https://ietf.webex.com/meet/sacm
>     >
>     >
>     >
>     > _______________________________________________
>     > sacm mailing list
>
>     > sacm@ietf.org <mailto:sacm@ietf.org>
>     > https://www.ietf.org/mailman/listinfo/sacm
>     >
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>
>
>

--001a11430fb2957cdc0549a4d200
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Yes correct.<div>I concur with your recommended approach o=
f identifying the workflow entry points.</div><div><br></div><div>An exampl=
e is a change in the=C2=A0<span style=3D"font-size:12.8px">endpoint reposit=
ory, lets say event: a new device is connected, one would want to trigger a=
n assessment &quot;a la NAC&quot;</span></div><div><span style=3D"font-size=
:12.8px"><br></span></div></div><div class=3D"gmail_extra"><br><div class=
=3D"gmail_quote">On Tue, Feb 28, 2017 at 9:31 PM, Waltermire, David A. (Fed=
) <span dir=3D"ltr">&lt;<a href=3D"mailto:david.waltermire@nist.gov" target=
=3D"_blank">david.waltermire@nist.gov</a>&gt;</span> wrote:<br><blockquote =
class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid=
;padding-left:1ex">





<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"m_-4573674949002270255WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif">Jerome,<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif">IMHO, we need to identify the places within the wor=
kflow where triggers may occur. These are the workflow entry points. It wou=
ld also be useful to identify the events that
 may cause these triggers for clarity sake.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif">Is this what you are saying?<u></u><u></u></span></=
p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif">Regards,<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif">Dave<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&quot=
;Calibri&quot;,sans-serif">From:</span></b><span style=3D"font-size:11.0pt;=
font-family:&quot;Calibri&quot;,sans-serif"> sacm [mailto:<a href=3D"mailto=
:sacm-bounces@ietf.org" target=3D"_blank">sacm-bounces@ietf.org</a>]
<b>On Behalf Of </b>Jerome Athias<br>
<b>Sent:</b> Tuesday, February 28, 2017 5:39 AM<br>
<b>To:</b> Bill Munyan &lt;<a href=3D"mailto:bill.munyan.ietf@gmail.com" ta=
rget=3D"_blank">bill.munyan.ietf@gmail.com</a>&gt;<br>
<b>Cc:</b> Henk Birkholz &lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer=
.de" target=3D"_blank">henk.birkholz@sit.fraunhofer.<wbr>de</a>&gt;; &lt;<a=
 href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org</a>&gt; &lt;=
<a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org</a>&gt;; A=
dam Montville &lt;<a href=3D"mailto:adam.w.montville@gmail.com" target=3D"_=
blank">adam.w.montville@gmail.com</a>&gt;<br>
<b>Subject:</b> Re: [sacm] Main Components: WAS (Re: Notes on Vulnerability=
 Scenario Working Session)<u></u><u></u></span></p>
</div>
</div><div><div class=3D"h5">
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<p class=3D"MsoNormal">Greetings,<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">So taking IACD (Ref [0] Appendix A1) as an example f=
or illustration, would that help to first list triggering &quot;events&quot=
;/preconditions?<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Regards<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">[0]=C2=A0<a href=3D"https://secwww.jhuapl.edu/iacdco=
mmunityday/Resources/IACD%20Baseline%20Reference%20Architecture%20-%20Final=
%20PR.pdf" target=3D"_blank">https://secwww.jhuapl.edu/<wbr>iacdcommunityda=
y/Resources/<wbr>IACD%20Baseline%20Reference%<wbr>20Architecture%20-%20Fina=
l%<wbr>20PR.pdf</a><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<p class=3D"MsoNormal">On Mon, Feb 6, 2017 at 5:17 PM, Bill Munyan &lt;<a h=
ref=3D"mailto:bill.munyan.ietf@gmail.com" target=3D"_blank">bill.munyan.iet=
f@gmail.com</a>&gt; wrote:<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif">I wanted to clarify one assumption I have been making when viewing t=
he diagram.=C2=A0 I am viewing the overall vulnerability scenario as a seri=
es of event-driven use-cases, with this diagram simply
 depicting one of those use-cases: =C2=A0When new VDD is introduced into th=
e scenario. =C2=A0<u></u><u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif"><u></u>=C2=A0<u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif">Feasibly, a number of different events could trigger entry into the =
vulnerability scenario, such as a &quot;staleness trigger&quot;, or a &quot=
;new endpoint added trigger&quot;, and many more.=C2=A0 Each of these event=
s
 could (and should) have their own diagram outlining how the components int=
eract to request new/updated VDD, determine the endpoints which should be a=
ssessed, and what to do with their results.=C2=A0 As such, each of the comp=
onents in the diagrams can be seen as
 conceptual, allowing for implementers to determine how best to consolidate=
 components for their use.<u></u><u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif"><u></u>=C2=A0<u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif">Please bash my thought process if I&#39;m way off on this, but I tho=
ught it might help in this discussion, because it seems like some of the &q=
uot;disagreement&quot; in the diagram is stemming from &quot;events&quot;
 which aren&#39;t necessarily applicable to this particular &quot;event use=
-case&quot;.<u></u><u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif"><u></u>=C2=A0<u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif">Cheers,=C2=A0<u></u><u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif">-Bill M.<u></u><u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Verdana&quot;,sans-=
serif"><u></u>=C2=A0<u></u></span></p>
</div>
</div>
<div>
<div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<p class=3D"MsoNormal">On Fri, Feb 3, 2017 at 5:19 PM, Henk Birkholz &lt;<a=
 href=3D"mailto:henk.birkholz@sit.fraunhofer.de" target=3D"_blank">henk.bir=
kholz@sit.fraunhofer.<wbr>de</a>&gt; wrote:<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal">Also inline. I hope it is still readable.<br>
<br>
On 02/03/2017 10:55 PM, Adam Montville wrote:<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal">Thanks for chiming in Henk.=C2=A0 I&#39;ll go inline=
.=C2=A0 Nothing being said as<br>
chair.=C2=A0 Just making observations.<br>
<br>
On Fri, Feb 3, 2017 at 3:25 PM Henk Birkholz<br>
&lt;<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" target=3D"_blank">he=
nk.birkholz@sit.fraunhofer.<wbr>de</a><br>
&lt;mailto:<a href=3D"mailto:henk.birkholz@sit.fraunhofer.de" target=3D"_bl=
ank">henk.birkholz@sit.<wbr>fraunhofer.de</a>&gt;&gt; wrote:<br>
<br>
=C2=A0 =C2=A0 Hi group,<br>
<br>
=C2=A0 =C2=A0 to recap my understanding:<br>
<br>
=C2=A0 =C2=A0 There will be trigger conditions that initiate collections of=
 fresh<br>
=C2=A0 =C2=A0 endpoint attributes (from which endpoint posture can be deriv=
ed) from a<br>
=C2=A0 =C2=A0 target endpoint.<br>
<br>
=C2=A0 =C2=A0 The obvious trigger condition that an asserting component (in=
 every<br>
=C2=A0 =C2=A0 diagram, I think, that is the Vulnerability Assessor. This as=
sumption is<br>
=C2=A0 =C2=A0 based on the interpretation of the diagram, not based on the =
name of the<br>
=C2=A0 =C2=A0 component). From my point of view, in order to assert that a =
known<br>
=C2=A0 =C2=A0 record is, for example, &quot;stale&quot; (aka does not satis=
fy an declarative<br>
=C2=A0 =C2=A0 guidance that expresses the quality of freshness) or, as anot=
her<br>
=C2=A0 =C2=A0 example, is not yet created the Vulnerability Assessor requir=
es an<br>
=C2=A0 =C2=A0 always up-to-date and exhaustive list of all Assessment Resul=
t records.<br>
<br>
<br>
I would disagree.=C2=A0 I have a record from the endpoint repository that i=
t<br>
timestamped as 3 days old.=C2=A0 My policy says I should not rely on anythi=
ng<br>
older than 2 days old.=C2=A0 Then the information is stale, and I instruct =
to<br>
collect anew.<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
If the &quot;I&quot; is the Vulnerability Assessor, how does it always have=
 the Assessment Result records to check that declarative guidance? Or do yo=
u propose (in v3) that the Endpoint Repository is checking that freshness c=
ontinuously and notifying the Vulnerability
 Assessor?<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
<br>
<br>
=C2=A0 =C2=A0 In consequence, I would assume that either the the Assessment=
 Result<br>
=C2=A0 =C2=A0 Repository component collapses with the Vulnerability Assesso=
r or the<br>
=C2=A0 =C2=A0 Vulnerability Assessor always retains a complete in-sync copy=
 of the<br>
=C2=A0 =C2=A0 Assessment Result Repository.<br>
<br>
<br>
I would again disagree.=C2=A0 It may well be that actual software collapses=
<br>
these components into one, but it may be that there is a results<br>
repository, which is used downstream from vulnerability assessment, into<br=
>
which the assessor dumps results.<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
Yes, downstream records are dumped as a result in the corresponding repo. B=
ut how does the information of not satisfying declarative guidance (a resul=
t got stale) makes it &quot;upstream&quot; again to trigger collection - in=
cluding imperative guidance what to collect
 (what just got stale)?<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
Consider when we have configuration assessment down the road.=C2=A0 Would w=
e<br>
then have a vulnerability assessor and a configuration assessor each<br>
with their own repository conceptually, or would we be better off with<br>
one &quot;results repository&quot;?=C2=A0 I think the one.<u></u><u></u></p=
>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
It depends on scalability, I guess, but in the bare-bone first proof of con=
cept it seems to be feasible to collapse related pools of data into justthe=
 one, as there are no multiple consumers?<br>
<br>
<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
In practice, applications can choose to implement more than one<br>
conceptual component.<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
Yes, that is why it is not a problem to collapse sets of functions into a s=
ingle component, in general. I hope this will remain a core feature of the =
architecture at all time.<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
<br>
<br>
=C2=A0 =C2=A0 Alternatively, the Assessment Result Repository component is =
collapsed<br>
=C2=A0 =C2=A0 with the Endpoint Repository (as proposed in diagram v3), in =
which case<br>
=C2=A0 =C2=A0 now the Vulnerability Assessor to retain an continuously in-s=
ync copy of<br>
=C2=A0 =C2=A0 the Endpoint Repository? If it is to trigger on the &quot;sta=
le&quot; condition?<br>
<br>
<br>
Again, I am not necessarily in favor of this viewpoint (and I&#39;m not<br>
necessarily against).=C2=A0 The endpoint repository represents an interface=
<br>
to acquire information about endpoints, which does not necessarily need<br>
to include assessment results pertaining to those endpoints entirely.<u></u=
><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
But isn&#39;t that what is depicted in the diagram v3: the assessment resul=
ts repo is merged with endpoint repo? Maybe I am actually a little bit dens=
e right now :)<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
<br>
<br>
<br>
=C2=A0 =C2=A0 The &quot;keeping pools of data in-sync&quot; seems to be int=
roducing extra steps<br>
=C2=A0 =C2=A0 in the work-flow.<br>
<br>
<br>
Is it really data in sync?=C2=A0 I understand what you&#39;re saying, but t=
o me<br>
the endpoint repository component is where we find assertions about the<br>
endpoints, the assessors take those assertions and apply some logic to<br>
pass judgement on the endpoint, and that judgement is stored in the<br>
assessment results repository component.<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
I simply did not assume that a repository is more than a data store. If it =
does continuous assessments of endpoint records it contains, it most certai=
nly can trigger a collection. Maybe the label of the component is just misl=
eading me here.<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
<br>
<br>
=C2=A0 =C2=A0 A pro for this would be that there could be multiple addition=
al<br>
=C2=A0 =C2=A0 consumers of Assessment Results that justify an interface tha=
t provides<br>
=C2=A0 =C2=A0 that data to multiple parties.<br>
<br>
<br>
Yes!=C2=A0 There are in practice.=C2=A0 Assessment results have downstream =
uses<br>
outside the scope of our charter.<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
I thought so, but it is of course not part of the single snapshot diagram a=
nd is therefore only implied at best.<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
<br>
<br>
=C2=A0 =C2=A0 A con for this is the universal &quot;redundant data stores a=
lways pose a<br>
=C2=A0 =C2=A0 source of complexity and hence risk of inconsistency&quot; ar=
gument.<br>
<br>
=C2=A0 =C2=A0 Another point of view could be that the &quot;evaluation task=
&quot; is independent<br>
=C2=A0 =C2=A0 from the &quot;trigger collection&quot; (I just made that one=
 up) task? Or maybe<br>
=C2=A0 =C2=A0 it is associated with the worn component?<br>
<br>
=C2=A0 =C2=A0 Multiple emerging architectures include an orchestration comp=
onent that<br>
=C2=A0 =C2=A0 consumes notification of changes and derives appropriate acti=
ons that it<br>
=C2=A0 =C2=A0 can trigger or even conduct. Please note, I am not advocating=
 to<br>
=C2=A0 =C2=A0 introduce yet another component type (which would again add c=
omplexity,<br>
=C2=A0 =C2=A0 error, scope creep...) :)<br>
<br>
<br>
Bill mentioned something to me offline yesterday about orchestration.<br>
In the vulnerability scenario, the orchestration is really being<br>
performed by the assessor.<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
I think that in the reply above you illustrated that the Endpoint Repo also=
 does this assessment by checking for staleness? Or would it &quot;just&quo=
t; notify the Assessor to trigger a task? Why not trigger the collector dir=
ectly? What about the imperative guidance
 what to actually collect again?<br>
<br>
It seems that I really have a difficult time to wrap my head around the pro=
posal still. Please stay patient with me! :)<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
<br>
<br>
=C2=A0 =C2=A0 I just try to get a feasible grasp of the actual workflow tha=
t the<br>
=C2=A0 =C2=A0 diagram is intended to represent.<br>
<br>
<br>
The most basic path through the system.<br>
<br>
<br>
<br>
=C2=A0 =C2=A0 What am I missing? I actually am surprised that the Assessmen=
t Result<br>
=C2=A0 =C2=A0 Repository merges with the Endpoint Repository and not the Vu=
lnerability<br>
=C2=A0 =C2=A0 Assessor. What is the advantage?<br>
<br>
<br>
I think we&#39;re still talking this one through.=C2=A0 What&#39;s the adva=
ntage to<br>
collapsing them at all?<u></u><u></u></p>
</blockquote>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
Collapsing redundant pools of data is reducing redundancy :) Tasks that dep=
end on data that has to be acquired to be conducted benefit from high avail=
ability and low latency. But I totally understand the &quot;multiple consum=
er&quot; argument.<u></u><u></u></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0i=
n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class=3D"MsoNormal"><br>
<br>
<br>
=C2=A0 =C2=A0 Best,<br>
<br>
=C2=A0 =C2=A0 Henk<br>
<br>
=C2=A0 =C2=A0 On 02/03/2017 05:43 PM, Adam Montville wrote:<br>
=C2=A0 =C2=A0 &gt; I thought I&#39;d try to break this discussion out of it=
&#39;s former thread<br>
=C2=A0 =C2=A0 &gt; into one of its own, in case that makes it easier for fo=
lks to opine.<br>
=C2=A0 =C2=A0 &gt; The list of &quot;components&quot; or &quot;function gro=
ups&quot; seems reasonable to me.<br>
=C2=A0 =C2=A0 &gt; In practice, there *may* be a desire to have that softwa=
re acting<br>
=C2=A0 =C2=A0 as an<br>
=C2=A0 =C2=A0 &gt; endpoint repository also act as the repository for asses=
sment results.<br>
=C2=A0 =C2=A0 &gt; Or, these could be implemented in distinct services.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; What works for our purposes?<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; On Thu, Feb 2, 2017 at 10:40 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt; &lt;<a href=3D"mailto:adam.w.montville@gmail.com" target=
=3D"_blank">adam.w.montville@gmail.com</a> &lt;mailto:<a href=3D"mailto:ada=
m.w.montville@gmail.com" target=3D"_blank">adam.w.montville@<wbr>gmail.com<=
/a>&gt;<br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Once folks have had an opportunity to=
 review the vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scenario information we&#39;ve been w=
orking on, what are your thoughts<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0on the main components we&#39;re pres=
ently focused on for this<br>
=C2=A0 =C2=A0 narrowly<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0scoped exercise?=C2=A0 These are:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Detection Data Reposito=
ry<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Vulnerability Assessor<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Collector<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Assessment Result Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0Endpoint<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0On Thu, Feb 2, 2017 at 10:28 AM Adam =
Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:adam.w.montvill=
e@gmail.com" target=3D"_blank">adam.w.montville@gmail.com</a><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&gt;<br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a><u></u><u></u></p>
<div>
<div>
<p class=3D"MsoNormal"><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi Everyone.=C2=A0 A fe=
w of us were able to make the vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0scenario call today and=
 I think we had a good, though at times<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0spirited, discussion.=
=C2=A0 We did record the meeting, which is<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0available at [1].=C2=A0=
 We discussed the attached (annotated with<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0some meeting notes) UML=
-ish sequence diagram.=C2=A0 I had created<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that diagram to start a=
 conversation (mission accomplished on<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that front I think) -- =
a conversation that would lead us<br>
=C2=A0 =C2=A0 toward<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0identifying the discret=
e components, interfaces, and<br>
=C2=A0 =C2=A0 information<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0required to be sent ove=
r those interfaces.=C2=A0 The UML-ish<br>
=C2=A0 =C2=A0 diagram<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0represents a *single* f=
low through the system -- a &quot;one-time&quot;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0flow through the system=
.=C2=A0 It ignores, for the time being, the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0continuous aspect of ou=
r charter in favor of getting started<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the basics.=C2=A0 =
Once we have a good understanding of the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0basics -- the component=
s, interfaces, and information required<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- we can start look at=
 a continuous monitoring sequence<br>
=C2=A0 =C2=A0 (which<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0could be represented as=
 a distinct diagram) to determine what<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0more we need.=C2=A0 The=
n, I think, we can start drafting solutions.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0One of the first issues=
 is that we need to figure out if the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0components in the base =
flow are accurate.=C2=A0 The main suggestion<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0we&#39;ve tossed around=
 so far is to combine the Endpoint<br>
=C2=A0 =C2=A0 Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with the Assessment Res=
ult Repository.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked briefly about=
 what interface we could use for<br>
=C2=A0 =C2=A0 the VDD<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Repository, and natural=
ly ROLIE came up as an option.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We talked a little bit =
about the first &quot;get endpoints&quot;<br>
=C2=A0 =C2=A0 operation<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0between the Vulnerabili=
ty Assessor and the Endpoint Repository<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0-- specifically about w=
hether we should represent on this<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0sequence diagram that i=
nformation supporting a judgement of<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&quot;stale&quot; would=
 be needed.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0We left open the time w=
hen we would next meet, favoring to<br>
=C2=A0 =C2=A0 work<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0that out on-list.=C2=A0=
 Next week is TCG, so that may be difficult;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0the following week is R=
SA, so that may be difficult.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0For those who were in a=
ttendance today, please add to this<br>
=C2=A0 =C2=A0 note<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0with your comments/corr=
ections.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind regards,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0[1]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" target=3D"_blank">
https://drive.google.com/open?<wbr>id=3D<wbr>0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</=
a><br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Mon, Jan 30, 2017 at=
 11:21 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a href=3D"mailto:a=
dam.w.montville@gmail.com" target=3D"_blank">adam.w.montville@gmail.com</a>=
<br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&gt;<u></u><u></u></p>
</div>
</div>
<p class=3D"MsoNormal">=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.mo=
ntville@gmail.com" target=3D"_blank">adam.w.montville@<wbr>gmail.com</a> &l=
t;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">ad=
am.w.montville@<wbr>gmail.com</a>&gt;&gt;&gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Hi everyo=
ne.=C2=A0 Just a friendly reminder that we are<br>
=C2=A0 =C2=A0 planning<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0to meet a=
gain this Thursday at the same time (2/2 @ 10am<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Eastern/3=
pm UTC) using SACM&#39;s meeting room at<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=
=3D"https://ietf.webex.com/meet/sacm" target=3D"_blank">https://ietf.webex.=
com/meet/<wbr>sacm</a>.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Kind rega=
rds,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0On Thu, J=
an 19, 2017 at 11:35 AM Adam Montville<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;<a hr=
ef=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.montville=
@gmail.com</a><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0&lt;mailt=
o:<a href=3D"mailto:adam.w.montville@gmail.com" target=3D"_blank">adam.w.mo=
ntville@<wbr>gmail.com</a><u></u><u></u></p>
<div>
<div>
<p class=3D"MsoNormal"><br>
=C2=A0 =C2=A0 &lt;mailto:<a href=3D"mailto:adam.w.montville@gmail.com" targ=
et=3D"_blank">adam.w.montville@<wbr>gmail.com</a>&gt;&gt;&gt; wrote:<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Hello. A few of us met informally today to discuss the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability scenario in some more detail with<br>
=C2=A0 =C2=A0 the goal<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0of maintaining the narrow focus on a vulnerability<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assessment slice through our notional environment.=C2=A0 We<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0are tending to look at major components as black boxes<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0with interfaces and data format expectations, and<br>
=C2=A0 =C2=A0 we are<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0not necessarily concerned with how those components do<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0things internally/behind the scenes.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The meeting was recorded (you can find it with today&#39;s<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0date at [1]).=C2=A0 The topic of discussion was<br>
=C2=A0 =C2=A0 primarily in<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the &quot;phase 1&quot; area of what Danny sent to the list not<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0very long ago [2], and resulted in a *starting point*<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0diagram [3].<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0The group who met today are (roughly) agreed on<br>
=C2=A0 =C2=A0 the six<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0main &quot;components&quot; represented in that diagram, but<br>
=C2=A0 =C2=A0 also<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0see that we have some work ahead.=C2=A0 Specifically, we<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0quickly recognized that some of the assumptions the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability draft makes may be assumptions we cannot<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0afford to make and need to include in the exploration.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0We thought it would be a good idea to have another<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0informal discussion in a couple of weeks (February<br>
=C2=A0 =C2=A0 2) at<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0the same time (10am Eastern / 3pm UTC), using the same<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0WebEx [4].=C2=A0 =C2=A0At that time we intend to roll<br>
=C2=A0 =C2=A0 through the<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0vulnerability assessment scenario assumptions in an<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0effort to determine which ones can be left as<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0assumptions and which ones cannot.=C2=A0 Then we&#39;ll take<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0another look at the diagram and work on its next<br>
=C2=A0 =C2=A0 version.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Stay tuned.<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Thanks to Danny, Stephen, and Jerome for joining and<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0contributing!<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Kind regards,<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0Adam<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[1]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbWG=
hDOHpVR0tMd1E" target=3D"_blank">
https://drive.google.com/open?<wbr>id=3D<wbr>0B8Wf9Un5FdCbWGhDOHpVR0tMd1E</=
a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[2]<br>
=C2=A0 =C2=A0 <a href=3D"https://mailarchive.ietf.org/arch/msg/sacm/_LiKlyv=
Aws_OVLFhB5NSU58MXDM" target=3D"_blank">
https://mailarchive.ietf.org/<wbr>arch/msg/sacm/_LiKlyvAws_<wbr>OVLFhB5NSU5=
8MXDM</a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[3]<br>
=C2=A0 =C2=A0 <a href=3D"https://drive.google.com/open?id=3D0B8Wf9Un5FdCbMU=
5pdTRjejJtNHc" target=3D"_blank">
https://drive.google.com/open?<wbr>id=3D<wbr>0B8Wf9Un5FdCbMU5pdTRjejJtNHc</=
a><br>
=C2=A0 =C2=A0 &gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0[4] <a href=3D"https://ietf.webex.com/meet/sacm" target=3D"_blank">
https://ietf.webex.com/meet/<wbr>sacm</a><br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt;<br>
=C2=A0 =C2=A0 &gt; ______________________________<wbr>_________________<br>
=C2=A0 =C2=A0 &gt; sacm mailing list<u></u><u></u></p>
</div>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt">=C2=A0 =C2=A0 &gt; <a=
 href=3D"mailto:sacm@ietf.org" target=3D"_blank">
sacm@ietf.org</a> &lt;mailto:<a href=3D"mailto:sacm@ietf.org" target=3D"_bl=
ank">sacm@ietf.org</a>&gt;<br>
=C2=A0 =C2=A0 &gt; <a href=3D"https://www.ietf.org/mailman/listinfo/sacm" t=
arget=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/sacm</a><br>
=C2=A0 =C2=A0 &gt;<u></u><u></u></p>
</blockquote>
<div>
<div>
<p class=3D"MsoNormal"><br>
______________________________<wbr>_________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"_blank">ht=
tps://www.ietf.org/mailman/<wbr>listinfo/sacm</a><u></u><u></u></p>
</div>
</div>
</blockquote>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
</div>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
______________________________<wbr>_________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"_blank">ht=
tps://www.ietf.org/mailman/<wbr>listinfo/sacm</a><u></u><u></u></p>
</blockquote>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
</div></div></div>
</div>
</div>

</blockquote></div><br></div>

--001a11430fb2957cdc0549a4d200--

