<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.40 (Ruby 4.0.5) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

<!ENTITY RFC2119 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY RFC8174 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
<!ENTITY RFC9635 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9635.xml">
<!ENTITY RFC8693 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8693.xml">
<!ENTITY RFC2693 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2693.xml">
]>


<rfc ipr="trust200902" docName="draft-zagarella-verified-human-root-01" category="info" submissionType="IETF">
  <front>
    <title abbrev="Verified Human Root">Verified Human Root Attestation for Agent Delegation Chains and Audit Records</title>

    <author fullname="Roberto Antonio Zagarella">
      <organization>Violet Shores Pty Ltd</organization>
      <address>
        <email>rob@violetshores.com</email>
      </address>
    </author>

    <date year="2026" month="August" day="24"/>

    <area>Security</area>
    
    <keyword>agent identity</keyword> <keyword>delegation</keyword> <keyword>audit</keyword> <keyword>biometric attestation</keyword> <keyword>provenance</keyword>

    <abstract>


<?line 28?>

<t>Autonomous software agents increasingly act under delegated authority, and
emerging audit-record data models capture what an agent did, under which
delegation, with which authorization state. In current practice the head of
every such chain, and the identity axis of every such record, is a key, an
account, or a workload identity. No standardized element establishes that an
identified natural person, verified as live and present, stands at the head
of the chain or behind the recorded action.</t>

<t>This document defines the Verified Human Root Attestation (VHRA): a compact,
privacy-preserving data structure asserting that a biometric proof-of-human
verification of an identified natural person (or an M-of-N quorum of such
persons) occurred at a specific issuance event. It further defines how a
delegation chain binds a VHRA at its root such that the binding survives
attenuation, and how audit and interaction records reference a VHRA so that
any recorded agent action can be resolved to an accountable natural person
without the verifier receiving any biometric material.</t>

<t>This document is offered as input to the proposed AUDIT working group's data
model work. It deliberately does not standardize biometric verification
methods; it standardizes only the attestation structure, its bindings, and
verifier obligations.</t>



    </abstract>



  </front>

  <middle>


<?line 52?>

<section anchor="introduction"><name>Introduction</name>

<t>Delegation and audit mechanisms for autonomous agents are converging quickly:
attenuable token chains, delegation receipts, agent identity attestations,
and audit-record architectures are all active areas of specification. These
mechanisms share a structural property: authority is rooted in the
possession of a cryptographic key, an account at an identity provider, or a
workload identity. Attribution therefore terminates at a credential.</t>

<t>A large class of deployments — legal instruments, regulated industries,
critical infrastructure, government — carries a requirement that
credential-level attribution alone does not address. The governing question
in these settings is: which accountable
natural person authorized this, and can that be proven years later, to a
party who was not present, without that party being granted standing access
to personal data? Keys are delegated, stolen, shared, and escrowed; accounts
are administered; workloads are ephemeral. A credential at the head of a
chain does not answer the question.</t>

<t>This document defines a small data structure, the Verified Human Root
Attestation (VHRA), that closes this gap in a composable way:</t>

<t><list style="symbols">
  <t>A VHRA asserts that a biometric proof-of-human verification of an
identified natural person occurred at a specific issuance event, at a
stated assurance level, optionally as an M-of-N quorum of distinct
persons.</t>
  <t>A delegation chain MAY bind a VHRA at its root such that every
attenuation hop preserves a resolvable reference to it, and a verifier of
any leaf action can validate the human root and fail closed if it is
absent, invalid, or revoked.</t>
  <t>An audit or interaction record MAY carry a reference to the VHRA under
which the recorded action was performed, so that audit resolution reaches
a natural person rather than terminating at an agent identifier.</t>
</list></t>

<t>The VHRA is intentionally agnostic to how biometric verification is
performed. Verification methods, liveness detection techniques, and their
quality are the province of certification programs and are out of scope. The
structure standardized here is the interface: what an issuer asserts, what
travels in the chain, what a record references, and what a verifier is
obliged to check.</t>

<section anchor="relationship-to-the-proposed-audit-work"><name>Relationship to the proposed AUDIT work</name>

<t>The proposed AUDIT working group contemplates data models for interaction
records, agent identity, delegation context, authorization state over time,
and action provenance. Each of those elements is strengthened by, and none
currently provides, an optional verified-human-root binding. This document
proposes that the audit-record data model include an OPTIONAL field carrying
a VHRA reference (Section 6), so that deployments with accountability
requirements can resolve records to natural persons while deployments
without such requirements omit the field entirely.</t>

</section>
</section>
<section anchor="conventions-and-definitions"><name>Conventions and Definitions</name>

<t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
"SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
"OPTIONAL" in this document are to be interpreted as described in BCP 14
<xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they appear in all capitals, as
shown here.</t>

</section>
<section anchor="terminology"><name>Terminology</name>

<dl>
  <dt>Human Principal:</dt>
  <dd>
    <t>An identified natural person on whose authority a delegation chain is
issued or an action is performed.</t>
  </dd>
  <dt>Liveness Event:</dt>
  <dd>
    <t>A discrete biometric verification of a Human Principal, performed at a
specific time, asserting that the person was live and present. The methods
by which liveness is established are out of scope.</t>
  </dd>
  <dt>Verified Human Root Attestation (VHRA):</dt>
  <dd>
    <t>The data structure defined in Section 4, asserting one Liveness Event (or
an M-of-N quorum of Liveness Events) bound to a specific issuance event.</t>
  </dd>
  <dt>Issuance Event:</dt>
  <dd>
    <t>The act of creating a delegation chain, credential, or session for which
the VHRA establishes the human root, identified by a unique nonce.</t>
  </dd>
  <dt>Quorum Root:</dt>
  <dd>
    <t>A VHRA whose assertion covers M-of-N Liveness Events of N distinct Human
Principals.</t>
  </dd>
  <dt>Delegation Chain:</dt>
  <dd>
    <t>Any mechanism by which authority is conveyed from an issuer through zero
or more attenuation hops to a leaf credential under which an agent acts.
This document is agnostic to the token format.</t>
  </dd>
  <dt>Audit Record:</dt>
  <dd>
    <t>Any record, per an audit-record data model, describing an agent
interaction or action, its delegation context, and its authorization
state.</t>
  </dd>
</dl>

</section>
<section anchor="the-verified-human-root-attestation"><name>The Verified Human Root Attestation</name>

<t>A VHRA is a signed structure with the following logical fields. Encodings
(CBOR, JSON) are expected to be profiled by the consuming ecosystem; field
semantics are normative, serialization is not, in this version.</t>

<dl>
  <dt>subject:</dt>
  <dd>
    <t>A reference to the Human Principal's identity credential. This is a
reference, not the credential itself and not biometric material.</t>
  </dd>
  <dt>liveness:</dt>
  <dd>
    <t>Metadata about the Liveness Event(s): the count and class of verification
modalities employed (e.g., "multi-modal, fused"), the assurance level
asserted by the issuer against a stated assurance framework, and the time
of the event. This field carries no biometric samples, templates, or
model outputs.</t>
  </dd>
  <dt>issuance_nonce:</dt>
  <dd>
    <t>The unique identifier of the Issuance Event to which this VHRA is bound.
A VHRA MUST be bound to exactly one Issuance Event. This binding is the
anti-replay anchor: a VHRA MUST NOT be accepted for any issuance other
than the one named by this nonce.</t>
  </dd>
  <dt>freshness:</dt>
  <dd>
    <t>The validity window within which the Liveness Event must have occurred
relative to the Issuance Event, as asserted by the issuer.</t>
  </dd>
  <dt>quorum:</dt>
  <dd>
    <t>OPTIONAL. Present when the VHRA is a Quorum Root: the values M and N,
and, for each constituent Liveness Event, an independently-signed
sub-assertion bound to the same issuance_nonce. Constituent
sub-assertions MUST be independently produced and signed such that
satisfaction of the quorum requires M distinct Human Principals; M
qualifying sub-assertions from a single person is a protocol violation.</t>
  </dd>
  <dt>revocation:</dt>
  <dd>
    <t>A pointer (URI or equivalent) at which the current validity of this VHRA
can be checked. Revocation semantics are defined in Section 5.5.</t>
  </dd>
  <dt>issuer, signature:</dt>
  <dd>
    <t>The attestation issuer's identifier and signature over all fields above.</t>
  </dd>
</dl>

</section>
<section anchor="binding-a-vhra-to-a-delegation-chain"><name>Binding a VHRA to a Delegation Chain</name>

<t>This section is written for the general case of an attenuated chain. A
chain with no attenuation hops is in scope and is a distinct case: in it the
chain itself performs no checking, and the whole of verification rests on
the standing of a single event. Readers SHOULD read Section 5.1 before
assuming that the hop-by-hop machinery in Sections 5.2 through 5.4 is where
verification happens.</t>

<section anchor="chains-of-length-zero"><name>Chains of length zero</name>

<t>A credential issued directly by the Human Principal, with no attenuation
hop between the Issuance Event and the credential presented to a verifier,
is a delegation chain of length zero. A consent grant signed by the
subject's own key is the canonical example.</t>

<t>At length zero:</t>

<t><list style="symbols">
  <t>Binding is the Issuance Event's binding of the signing key to a verified
natural person, and nothing else. There is no root position distinct from
the credential itself; the VHRA (or the commitment to it) is carried by
the credential directly. Section 5.2 applies trivially.</t>
  <t>There is nothing to attenuate, so Section 5.3 imposes no obligation, and
the chain contributes no verification of its own. A verifier MUST NOT
infer any assurance from the absence of hops.</t>
  <t>The relying party's entire verification is the resolution of that one
Issuance Event's standing at the time of the act: the VHRA resolves,
validates, is fresh, satisfies any quorum, and is not revoked (Section
5.4, steps 1 through 5, applied to the single event). Continuation and
revocation semantics (Section 5.5) apply to it unchanged and carry the
full verification burden.</t>
</list></t>

<t>A profile that carries a subject-signed consent grant and requires that the
signing key be bound to a credentialed unique human is satisfied at length
zero by the Issuance Event alone.</t>

</section>
<section anchor="root-placement"><name>Root placement</name>

<t>A delegation chain that claims a verified human root MUST bind the VHRA (or
a cryptographic commitment to it) in a root position with the following
properties:</t>

<t><list style="symbols">
  <t>It is covered by the signature of the root credential and, transitively,
by every signature in the chain, such that its removal or alteration
invalidates the chain.</t>
  <t>It is non-removable: no attenuation hop can produce a valid derivative
credential that omits the binding.</t>
</list></t>

</section>
<section anchor="preservation-across-attenuation"><name>Preservation across attenuation</name>

<t>Each attenuation hop, whatever else it narrows, MUST preserve a resolvable
cryptographic reference to the root VHRA. A verifier presented with any
leaf credential of the chain MUST be able to resolve the reference and
validate the VHRA without cooperation from intermediate hops.</t>

</section>
<section anchor="verifier-obligations"><name>Verifier obligations</name>

<t>A verifier of an action requested under a chain that claims a verified
human root MUST, in addition to whatever chain validation the token format
requires:</t>

<t><list style="numbers" type="1">
  <t>resolve the root VHRA reference;</t>
  <t>validate the VHRA signature and its binding to the chain's Issuance
Event via issuance_nonce;</t>
  <t>check freshness and, where present, quorum satisfaction;</t>
  <t>check current validity via the revocation pointer; and</t>
  <t>reject the action if the VHRA is absent, unresolvable, invalid, stale,
quorum-deficient, or revoked (fail closed).</t>
</list></t>

<t>A verifier MUST NOT treat the absence of a VHRA as equivalent to a present
but unverifiable VHRA: a chain that claims a human root and cannot prove it
is invalid, whereas a chain that never claimed one is simply outside this
document's scope.</t>

</section>
<section anchor="revocation"><name>Revocation</name>

<t>Revocation of a VHRA by or on behalf of the Human Principal invalidates the
chain rooted in it. Post-revocation, verification per Section 5.4 fails,
and all leaf authority derived from the chain is extinguished at the
identity layer, independent of the revocation state of any individual key
in the chain.</t>

</section>
</section>
<section anchor="referencing-a-vhra-from-audit-records"><name>Referencing a VHRA from Audit Records</name>

<t>An audit-record data model SHOULD provide an OPTIONAL field, suggested name
verified_human_root, with the following contents:</t>

<t><list style="symbols">
  <t>a reference to the VHRA under which the recorded action's authority was
rooted;</t>
  <t>a cryptographic digest of the VHRA as validated at action time; and</t>
  <t>the validity status observed at action time.</t>
</list></t>

<t>This triple permits a later audit consumer to establish that the recorded
action resolved, at the time it was performed, to a then-valid verified
human root — and to re-resolve the reference if the underlying attestation
is still available — without the record itself carrying any personal data
beyond an opaque reference.</t>

<t>Records for actions performed under chains with no VHRA simply omit the
field. Audit tooling can therefore filter, without heuristics, between
human-rooted and credential-rooted actions — which is precisely the
distinction that liability-bearing deployments need to make.</t>

</section>
<section anchor="privacy-considerations"><name>Privacy Considerations</name>

<t>The design constraint of this document is that accountability must not cost
surveillance:</t>

<t><list style="symbols">
  <t>No biometric samples, templates, feature vectors, or model outputs appear
in the VHRA, the delegation chain, or any audit record.</t>
  <t>A verifier receives only: an opaque subject reference, liveness metadata,
a digest, and a validity status. Resolution of the subject reference to a
legal identity is a governed act, available to authorized oversight
parties under the deployment's disclosure rules, and is out of band with
respect to this document.</t>
  <t>An oversight party can confirm THAT an accountable verified person stands
behind an action without learning WHO, unless and until disclosure is
authorized. This "standing-access-free" property is deliberate and
deployments SHOULD preserve it.</t>
  <t>The issuance_nonce binding prevents cross-context correlation of VHRAs:
an attestation is meaningful only for its named Issuance Event.</t>
</list></t>

</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<dl>
  <dt>Replay:</dt>
  <dd>
    <t>The issuance_nonce binding (Section 4) is mandatory precisely because a
liveness assertion detached from its issuance context is a replayable
bearer of trust. Verifiers MUST reject VHRA presentations whose nonce
does not match the chain's Issuance Event.</t>
  </dd>
  <dt>Freshness:</dt>
  <dd>
    <t>A stale Liveness Event weakens the live-and-present claim. Issuers assert
a freshness window; verifiers enforce it. Deployments choose windows
proportional to risk.</t>
  </dd>
  <dt>Quorum independence:</dt>
  <dd>
    <t>The value of a Quorum Root depends on constituent sub-assertions being
independently produced. Implementations MUST NOT permit a single capture
pipeline to emit multiple constituent sub-assertions for one issuance.</t>
  </dd>
  <dt>Downgrade:</dt>
  <dd>
    <t>An attacker who can strip a VHRA binding converts a human-rooted chain
into a credential-rooted one. The non-removability requirement (Section
5.1) exists to make this a signature-breaking operation.</t>
  </dd>
  <dt>Verification quality:</dt>
  <dd>
    <t>This document standardizes the interface, not the strength, of biometric
verification. An attestation is only as strong as its issuer's practices;
conformance and certification of issuers is expected to be addressed by
external programs and is a natural complement to this specification.</t>
  </dd>
</dl>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>

<t>This document has no IANA actions. A future version may register the
verified_human_root audit-record field and a VHRA media type, subject to
working-group adoption.</t>

</section>


  </middle>

  <back>


<references title='References' anchor="sec-combined-references">

    <references title='Normative References' anchor="sec-normative-references">

&RFC2119;
&RFC8174;


    </references>

    <references title='Informative References' anchor="sec-informative-references">

&RFC9635;
&RFC8693;
&RFC2693;


    </references>

</references>


<?line 354?>

<section anchor="binding-to-existing-authorization-ecosystems"><name>Binding to Existing Authorization Ecosystems</name>

<t>This appendix sketches, informatively, how the VHRA composes with current
mechanisms; none of these bindings changes the host protocol.</t>

<dl>
  <dt>GNAP (<xref target="RFC9635"/>):</dt>
  <dd>
    <t>The VHRA functions as interaction-derived evidence bound to a grant: the
grant's issuance is the Issuance Event, and access tokens derived from
the grant carry the root reference.</t>
  </dd>
  <dt>OAuth 2.0 Token Exchange (<xref target="RFC8693"/>):</dt>
  <dd>
    <t>A token-exchange chain preserves the VHRA reference as a claim that MUST
survive exchange; the verifier obligations of Section 5.4 apply at
resource access.</t>
  </dd>
  <dt>Attenuable token formats (macaroon- and biscuit-class):</dt>
  <dd>
    <t>The VHRA commitment is the first caveat; attenuation appends caveats but
cannot remove it.</t>
  </dd>
  <dt>SPKI-style authorization certificates (<xref target="RFC2693"/>):</dt>
  <dd>
    <t>The VHRA is carried in the root certificate; delegated certificates
reference it.</t>
  </dd>
  <dt>Workload identity ecosystems:</dt>
  <dd>
    <t>A workload credential remains workload-scoped; where a workload acts
under human-rooted delegated authority, the workload's requests carry the
chain, and the chain carries the VHRA. Human root and workload identity
are complementary, not competing, axes.</t>
  </dd>
</dl>

</section>
<section numbered="false" anchor="changes-from-00"><name>Changes from -00</name>

<t><list style="symbols">
  <t>Added Section 5.1, chains of length zero, and a lead-in note to Section 5
directing readers to it. Renumbered the remaining subsections of Section
5 and updated internal cross-references, including two in -00 that
pointed to the wrong subsection (Sections 4 and 10 referenced revocation
and verifier obligations by the wrong numbers).</t>
  <t>No change to the VHRA structure, processing rules, or IANA
considerations.</t>
</list></t>

</section>
<section numbered="false" anchor="acknowledgments"><name>Acknowledgments</name>

<t>This document responds to the direction of the proposed AUDIT work and to
the broader delegation-receipt and agent-identity efforts whose gap it aims
to fill.</t>

<t>Blake Morrison identified that -00 was written only for the attenuated
case and that, at length zero, continuation and revocation carry the whole
verification burden; Section 5.1 is the result.</t>

</section>


  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA41b7ZLbxnL9P08xtf4h7S2SJcmyE+9WKllLcqxcfd2V7FvJ
H9cQGJKIQIDGALuiXa7KQ+QJ8yTp090zGICUfF0um0sCg5n+OH36A8vl0vRV
X/sre/Gz76pN5Uv747B3jb1t297e9L0PveurtrGbtrM3W9/09rmv/Va+fLZz
VROsa0p7M5RVb2990XZluDBuve783fl1L0zZFo3b02PLzm365W9u6zpf1255
p1cvd7h62dHVy0ePTeF6v22745Wtmk1rwrDeVyHQDvrjgVZ5+eLDD6Y6dFe2
74bQP3n06LtHTwwt6WgD730xdFV/vDAf/fGedndl7NI6PkpV0n/pN3xTpmPx
7zgOPqyrdu/7riqsG6WBHw5de+cb1xTeuKHftR3WNZb+2Qx1Lce7bde+61t7
0/RtU7X2v+JB+bq227qm+o1XvLI/V23te/ueVvLBvuuP9lVf8nV+76r6ynbt
+t/u+KLA16yKdm+attvTAneenm5vf3j25PHj7/TjPz/+p6dXBgKbXvLdt19/
Ey/59ruv44380SyXdPZ16DtX9MbcDLTvdt8OwYZ209/T5kVygRRRkHxD1Wzr
o6WL7dCUvotSJH2LUEi4C9iH8XvfbelqkeyyY0Oxpeud3bd0V7CFO/QDPeB+
53q6RVVUVuVC177fVcXOjHpa2Puq38nX8XEiTQs9+ZV92VhSfod1DjhRVXjb
77zdeVfadmM82dvRhoHuL2DKvFW+IlqGdZ+qQJfa7FLZ+8LSD86SUeEu44qi
HZp+QVqlb8nOPtYtPSSus7JvWuyqKV1XVr+RfOgYe2wMNrWuq7AjrfdydCN3
sds0joTianvwXcCRo4dYF2xNSuUdH8gcPB7OT6Bt9emYhvaOz3w+bG7td5Ue
Ug6CtQpIbWXMhx0dirxz4K2VflM1vC1v/wwfHv784+3N5RWdnczyQAsuzKGr
7lxxXPLuujson/VN1jUUrGoX6IceP8jJM28j92o3S/qXkcDIsQt5Fh2JtvBZ
IdmH0EFjX+P2N/bXoe2GPW6C9oxcEy5tW7BtlJafHA6+wBNIq2GAV0PjTU82
1JNDdySCLslj195blxmiCnddsewtJIFFK3ITIJhYDZ8QksRlOHIYSCZ3PhgA
SzOoSUOdvD7jKf6qmt53oiHVGC3rN57MmnapjwstP8C45piplT1Iby1IImvo
PLT1Hf1IsAQnE7MlC/QzKRo4VzvIntXqOqztK1YlnjSqixCGLnH1iQ2x92Cz
bLFVc8CKLS9KKj60gX64+en5yw/sM1h427XD4UFgWzGMDfwTa4L+qAhS6WGE
OmVLumgg39Gvsi3lJmPou11bhmtSSn45ba6hlbCbDN5HC12wElVjQZAsyaIl
txUDCCtBzn1VlrU35itCnr5ry4FFb0wWMqFR0e3ek9k0VdgHDq5uxFqFWKBt
0TZ3Cpy/DlXxsT5eRXuByvr2o1fzo91lFsl6OvTY8iTS5ccMC5N2EwHZdcWu
6j0fXnbg6ppNCFADxGdHUmfhZVb2A2GXN9l5wo7vTHKEUZGyydcphKfAANuA
f3jYOHRgyByC58DOPm6L7njo223nDoTxEWqjzVoJE+lkCMj0RycQbM5AMOFV
V60HFhAc2pPcSYa+21dk+z4IElBc4zvYmG9s7bot6aEmrMKmSn+o2+OeFfR/
//O/FhKvaf84Kn+7INlvh9rJsUriI13lSdQFHZkkhms3ncssbEs8omvYWbBg
4TrcQBvpPKm8kyjBzj3ubFkTOtVQZjqQq9vGjz7hypI0GFg5+ggxItI+bFIk
HrwNvgcCk2+GqxhLR1AwM2iNYRYAQn4ueAVoYXhbe6VF9uhdRwEKqLBgqDEH
R9qnB7T23skWU9QakYbWkOvWXqDANZAjeyyDTlHQoQwtKPuhjQEm/tX+1R/F
XBMBQTAkskSQytZYylZ9KLr23pfX8ZDBsKmWZAJV6IFT1yl6y4r+sAN5IXOw
N5lx5EGWrdVIFBg10IR7QglcE6X+2QhLrrKHo03j4+JzkdecRt6FSK+oCVED
68Zu3QGOJRG5DQwY944AxPyFTiJRigNw+LPwa0/DL7HGzwfgfyi0LvhXWofJ
GsIDRUT+mY2b3PiAx5FYjggd5wJ6SSojIkpEXZ8MIMbhTmLz65v/ZBj/cnhm
kkeLZRGZgvHBKoNRr0QAZWGOUZgMsurFwtwYLIlhWo6TtXebPA7fuboiVSsZ
ZQnzTnD/hsi+qJHwY4N4VQUssxZfqRq+mUGOMizC/1LO3GhYoe9PGQOfH8hy
5BNk22YLg0SYY9ODBALO0EP2WxIz8gl2r1bNhh/LYhn0ka4gaMGm54ZBkXvH
PgHEUNxlv84YfzKrjt1Ft1cFPlYzmsS2aUn7BQ4BwnQ+8EN4ac8r9SX9STnB
gnk0eSH5pUfo4/BAwayp4LcpJ6g68+tAskcQ7XxkMMSFSJBkiwWYbFqbfiHw
2ktujMuBb4icBYVBBmUz0uBJXoC4hNNyFgJFblzhr1JWBB8iCarjLvh7Q+na
HVIoAfWYy8gt0QKS1vVE+msyVhIUExqhhqTA4iPJ/6uvKKevhS7sqsMXqJvo
6kucDmSm9/tDzbE2T/02U6M1SnPn5GXCcHixT3C608zPIt7Zvtp7pThFVIqm
7Cv7gmzUcm5E243JGIIg4Nc3WzplQ8dYS/pKgN54o7lknbgGizLhlD1TvYjc
ESrPgN+onMKYFnwmL0aiXQ8l8jz79t2Hl2/f3Lyy9JC6FH+mtY1i2ujXD9+r
GX97Ofppzlw4cU5hvoJRm4xuBEYpTRVS0kG6n7pzAFjUPl85ZQ2aKWdLtvtK
Tiq7h0o7ovEwMvsMNJd9WzzmOeJixX+LXRH3gzHRLi5e//T+w8VC/m/fvOXP
ty/+9tPL2xfP8fn9jzevXqUPcoWhP97+9Ep/x6fxzmdvX79+8ea53Ezf2tlX
BJ0XwvwvogIuxNPySM6Q0IIBsSFTxJCYRsIhykFJC5Pc75+9s4+fmt9/11LN
H39Y/oxaDX2+33lNATktkT9JZIQ4hwMxKg7nRBMKd6h6V8P8ggmEfg3DBovy
A8NqW7fbozFCGd51ZETVwdVX5gqB4guBuwFDCz4j6e40mHJAYiAqraTa6mBV
FiBoM68irr6AcvnhCNkFZPM5vGbeP9v2Ylw1cYbIKdjJ54UEhig50f2ZOomQ
YoV/Wmx91KiXAgEdZKzLnAFwY/7BegidGc+a1T2E9rFFRE99mh8CTH4qPNQ0
mEyckqDpheHSrsmrJb//bFXDmJfxi6Qb7BOFPMQyCuESl0+Uv8goMJOQmLAB
w6VCZ0dSMS1u5VxnkVvhGmY2cLwF0hYQ8N/kgBCsWA4vqNYpkuIoQNYTolBm
osBR3iSSKJqi3SW7AlucV7PFRY5jdj5axyRx5cT8SHvfdO0+C8z9jkLddmd/
811rUOMlGO/8nFEGUQ/zwiylyOqcIx8indBGrT2pq+QMCMKVYoCUe5G6ZhX5
eKpYujx4cdvzMWcRQUvqPLIPuHzGK+H3hZSsQKTPBmYUr1DHyAN05PuCVX9e
WEQKHgkg2XO1bTgfjJ7EgYyDSlvX7T02TMjHeTaHGUqAXzRFy+Ub8/DZ929v
F/Y/3r99cymp3Sfyj14Yj+SuG4pnbI/Moyj8DHusSRIKR0oP99eyrAmeNkuy
lxQxVeEp2nIZLLKRilPBRQoXMFbJA8Ow/m96tpj2CSOfAeCDMJY5svKEmAQE
Q1JNayw4++T9j5ZFevD1RqlMf75wF9EPe3rte8cG4daxBjh1rofh8kqFxLUY
lAFijWRSebOwKdBmFDXA/lp4zUO/2q4ouO6Huq+WfMXCbgZijheXkvbO0kGA
H3v9qJ5IhbeofnGiOU8kN0TBPTjoWNhHvIBfSlVca7wsx5FUVZzBZ0IKjvYN
tpfoK6BPjkYUjSR0GOCkJsLsL4xiEVUV2cbEJj5+CsJQfsy+aD/R6hnOAQDq
CMx7yFoTzPtP5IlEFxA1pivqyWLFWbIKDiMk9I5YmyPgbQo0r2JiHFkVnoBq
ywES5fpkcxyjSIs0joHeScqBZ6Pnpcphuxcc31DM3UWzgjQ4f4Ulk7eWlLjB
hasmyztnkW8/kHJ3lOCksgJbe80OFx1meu4FFwzOmgvtSEInthP53IpcjZkB
U64xfDHm5IFIiuGuprzQvmaberNgeRKmQkjIfBk2yFUHrDc9C6cLdGp/8E3J
mcRSEA2oOKyXY1xLysUDyfy8nZrWCpQ5PmV+d0g2MnkW8K0cCngIrR2hNBY/
sAiJNGwiwG+0dMWnVyaPU0/jaRZNr+1rWoRz5M1ROhyTTUmktNwzTPyMRUwb
69uipQyqaiXZJDWhuiEYIiB5aDn+2Ic/3b5E+MGOSBV0tEuwwtF+YssvGRof
RT2KdqidEE5xURS4TQ+yU1g/Q9O+WX2jbo7CJmQIAp08PW8iyEUJutnvo+D5
JslSweclVAFr7yQwfq8eq07JZGHOVLSWGHzi3vdETnqhACwICtuoW9KBg9em
WeQhdCqmcyt7o3VLjqSEeidMhSsvwnslpENjyQiwNtryVpI7XUzDjdJ2RlMW
N51phGLicrWfxwtknWBujWHLj4VfTgvUchS0b70rwf00n+tQhx3V9JhUjPK+
QTTYTzIDOtVyfVyisLcnfyUVd8dMx4HufpJ43Derpyxa5FfTLuQOORlXHL/6
Kk5C0DZrLh4I/zOTgrFmTCX5EeO14tJJsnNGEwabXfv+3is8zSJHFGn2NM11
tNOX6jwLI/qb53TTnXOpm0SBtbkIH+FC9hzZCxk3ck8k51qxIt9qG6ZfFJUQ
NEFE+3xpLj9/P4lIs9M8GCOWghAejj/xoPw0wM15g1wpzo5pWx2k2CYlNZIp
12QObeDawmjFgCbNW05I0/UYDx6qYxXtfl/1e43ZFQEQMgJmDhDR6UpR56vM
Qp8gqa/BNYhj3FUoanIlN9uunKIfTcFzOWdc42tb7aWORGcb+5FSrrBZ4x+k
nFtFcuk85QZNJ01C7akgGJkAE/+NFwaQcytCcyZqqExLDRR4Ec+AEM1RgBs6
pFMp+Myrs1ppTsVj1jg5Kupt9tQwxk5Qn+hctBIKXFejrrR6FRCfY7098NAG
M5KFRjtutdHBJM4tIsKBJGt5PVXTaCFCA/SVPMHi4xEiFqrJMWBnQHXJoZrM
bEgNYOYvZ2LOwyzKXPKaR7EvYpDIRrcauqWQL1QOw0ZTma6HjsyOe5ea0Ghr
KDUW1XuVe8wcHQ9I0T5ipsk9MOeeebuUllKmK2k+gpPKmOs2AgIGIBCxbw5j
6GFq1ZkdtXYFVw9xmBPI0oaXq1BmHwdjsn6K0KA47hJd2Mwby2fcGW2zKVac
ZppGe9okVAa1l70UBu542kFPmEV7sVJeNW8jgjv2JHo8hxKd40IqUjpwlG6f
1vbHnhW3sfy+JRvnpLxGjq7mqs0irrenm1fjXgmrl3LvGkOAp9GfuZLSRsgY
q5EiMNiDzYJMjScRv91XfcjnXESd76SDpi5QdG0Ik/hmuB4/e7q0MCAIRnI4
QkNG3N6TH7NqY19u0pYzU+We5NasANjCBO3GcCm18eZo5tWZySRVZNg6hpGK
5QJnaToH8yJ5s0+KWFojL1rYj85XAk6Z4FISVeFyBVMS3s9nJk7gEVmjMSvC
wnmJQ7E3opzkvuguZuYuXKtwZSlGzxmpqkBW0dPoCMWk5hQ7CPCGx6upRKLM
R9lcmycreyqb0eBj+ShyAVUfb4MiQYQOjEgKelAMnWVJ1+brlRBPm9JQcTjm
c+MEgmY5eQJ0bZ7Ge08SCjxJFJ1QXLOTa1b5Nzg9IDbGJY51m2liqQ3doRlN
N2vvUqCjv3E42dsSyUhReR0xTLEpaxdfriZGkTL5HtXceaiOffCQ5VEC6CoU
Q2SBNifLsZXjhqvPmNOsiU2wIRMeBIakRMM5hJ6MRY/8PF+oERPDcmgqNEyA
ApEb1DWGPlAOxTmciQVQcAEtxXOPMirCmCydG89JgEpSQ3T0O0eZifryjHvP
AVOzmXFIqaK8410bUDOND1lMoy8qq2MYf8rt/DhoRZFaJgFSIZmhNBaRR3BB
++ETCvCD9h8kCKcaYO2OSD+z7D5Fl4xXSCd0I5Ub8qG7qqTcHCHc5MGEE85b
dcss6eQ9Tca6ybw+WzOOaZh2Rk/blYhZ260AEypFcY6u/IVt5xdpCpyp53I9
ueklxn5xeuHzswsPQib0e4emjyj1mtecRoyywjajRKObRMOQFpROCZC1isf/
JVaGBCAg+4Eo9ZrD0/yWOAZEjPwglRAOmk7mpXSgQorP6Ci0YxtlTGLjAU1C
fZnrXEyYMa0zm9pgF0dzeynB/FwcwBiaE37X+eX5yKZoxnIXnp/Px3MbvcLk
4B3ZP6MHFs1HStWCtFIQe9lsrJPZLrP2xxbeg0a7A7tMm1jB2aU3vUn9iOy0
ahUyHpnSag0zAi3akzZsois1975ta7Y8l88JEpPmabZ4iJ0fOuSPBbERTc3N
2PiPVH0c2Yvf6i5ZHmyv6JqSNKrgZRTVxLRUgiyYc6VN+uXau44HqbNmfuMl
89i7j1I9eieD11wixERkZAzcifSIsFKj7EgufaqO5a0lGeyZzAdIHRaoXhAA
Gkwve9Kw4zo32f+bPyuYb7zE9TtCx7bjCvq0fq5NbuatyfWkGXDahdSKdBw+
ghXo7NdsVllnfK8yA9L8J2+ZpM7vXhsfXNZVKEiDXVP3RglqmreeWVqGH22c
E40IzkUYGcsUm1hkroJbxjlL7nBW2x1PuTlON9SwRTLREDAyXQVQAUi5G+o4
6YMRbGler3nwh+yXM1A0h3UYO1N/nCZLj9WJTDgDWc2m6vb2w483H+bT4yn/
0sKuvIqAXEZeOBgJanQgioUylPr3H9+CB9XKzugjYUd+GJmASyLRtsZFLAYs
ZSx0SRzPX6RJY5x7nBfXvDv3mxSxNImo+lS7mNLIREHpUmkscwKz1E4niaXr
dEgKUobZhivp1k8LwmRdDiempF0mPHjwCS7MrZNZ8wauHN9eOvHlW+7exLrz
Z/abCgpPuUK1x5gZ+d4xw5u1L9yAljpsNDrB2IcoyR2KXWQoFU9I6Sbj6SuZ
isR2OP2Cxl2nTS68j7VKCYw2JpQbMxAr25RjaXufDwFlxVFaSi5ibX/G/pOo
fsjbTDdCn+edpHtPCNlIdoqzLkkeS92AcM8VL4yNiggYBMbUQTpW1wliUNQi
FRZsO/Z5ZlvFrsVJ5AZYLw98dToohsBahY/jlMPI5MauIbeZhMJmLSgrFwLU
Jo2mWa+F56cZSc81gOiYwOf9KPiULAgZGYvt+lYWTlAdyJsahiePa7h3CwLz
hX1smHWPBoqJi/a+IapVep1GIhdxxUdmby2jDCbmD4m4qynLixB9yjViOGWD
kNmEaTUqXoCKEsszK3ZIQMvn6yc1vseXRL8rtCE0qgpCujE5Xa4pheHJxpTB
p5kgpd86KyrazMPr5PWTyZTn2LmPM4gLRu0YVlHJzB6xUunlAMOo4niIsQWb
CslnuRUV34IL1yjdtPJuoBYqZhOsqAqrL3A6MpmU0LcLYrWbYIACmbzlMY69
sshieR4z6PrGW4w407dI+K2Zmzc3Z1hLLr0dvzwgVyqVQh1nMyi34PkKUhrU
u+WJfqZUZ5KNaSYj3X83TohzGcbiBdNFiup9a3SidSkTra6U4U99/2dNhpy3
7+ikLz4xmdsStczHVF/EgZJ4QG4mldUnGz76HuPTC5u9ulkfFzzknBISGen3
ymq1QJG9gnPNE6vKSkKKCAAm1JF1GouIXOq90hH+/c3NO/uQBxLxkugff6T5
NUkIh0a5qwv5LNAyZrEemR/Hn7E8zEXlKy1W8x8Pshhytv+jdItjuhSYwiRR
1saGlKtTLVxSlzw3eAuR2yerR/YDV6lefJLD6xHx8qse8UYes/TxCknDx7H/
rKuQSntcwUDQELYMBOVGPL/VZ+NS0j06984YlJNXCqTez414pFwDwooIgXto
s3e+xDSCfbh3JIKWtMBSWxNpGsiqeRZnqr6syq1iJy4XIME7YubXk+KrWGPQ
3yicDL00zqUvsm8jXXr/7q8vl6E/1n42hz2CCYlPBP5kFHjaVNY3U9Iv9fHx
7uvsneJ80XzkSfby9/kbX+PYlrKC9E5YVtXt8Ho1qIf+tuSyEt4C4hJh9i4v
BvHoqcK9J0Ho7FvP3OLWex+EWJYNk+7N7K1j7dVpoyYa3UrLVKm6dvJqG2gK
vyyYonp3XGiutj/4Xtrun3yQYWuFAKZ0y0ePzO9XzbBfo2vxLxcbVwd/8Qcn
ASUKKFlLfRFT6WmzOKZHxOfLJe2fnsskId0JKscNUOBgp2177rQghYrP1qoA
tKHDIyE25EdPQXyWHOFQ6it2GnqEkudvOcjkPOPwfQvzorPGURcp16aG3T1H
y/GRiQ8E+5Qf9/jRaG1lVmWT4Z/z/q0dIFlbThkuV5IqK87kJazstS/CZPg9
i0vyOKJRCHkStbPwyAq9KT427X3ty63M4J/V5zSMIvtrGxnq5zRS9DMmsmde
5NCaEA9mrLvWZe/7V8yt+JVTMQZMjC5HP9wQXPWR3vN7aXRdtec3+TZVjeDz
fQ2i9ZpSqYrngsbpYIZX6A6lrDjjktKnfuezqRbDsy7iT05eMZtYajFrxeYF
0zGU8GSKOdNVvZ5MmIzda2LCK/P/v5ytnE9DAAA=

-->

</rfc>

