<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.3.8) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

]>


<rfc ipr="trust200902" docName="draft-gallagher-openpgp-grease-02" category="std" consensus="true" submissionType="IETF" updates="9580" tocInclude="true" sortRefs="true" symRefs="true">
  <front>
    <title abbrev="pgp-grease">GREASE Code Points in OpenPGP</title>

    <author fullname="Andrew Gallagher" role="editor">
      <organization>PGPKeys.EU</organization>
      <address>
        <email>andrewg@andrewg.com</email>
      </address>
    </author>

    <date year="2026" month="October" day="06"/>

    <area>int</area>
    <workgroup>openpgp</workgroup>
    <keyword>Internet-Draft</keyword>

    <abstract>


<?line 35?>

<t>This document reserves entries in various OpenPGP registries for use in interoperability testing, by analogy with GREASE in TLS.</t>



    </abstract>

    <note title="About This Document" removeInRFC="true">
      <t>
        The latest revision of this draft can be found at <eref target="https://andrewgdotcom.gitlab.io/openpgp-grease"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-gallagher-openpgp-grease/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        OpenPGP Working Group mailing list (<eref target="mailto:openpgp@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/openpgp/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/openpgp/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://gitlab.com/andrewgdotcom/openpgp-grease"/>.</t>
    </note>


  </front>

  <middle>


<?line 39?>

<section anchor="introduction"><name>Introduction</name>

<t>GREASE <xref target="RFC8701"></xref> is an existing specification to ensure forwards compatibility of assigned code points in TLS.
We wish to specify a similar mechanism for OpenPGP.
This will be particularly useful in the OpenPGP Interoperability Test Suite <xref target="INTEROP"></xref>, but is not restricted to controlled environments.
It is expected that implementations will include PGP-GREASE values in real-world artifacts on an ongoing basis, to encourage forwards-compatible coding across multiple implementations.</t>

</section>
<section anchor="conventions-definitions"><name>Conventions and Definitions</name>

<t>The term "OpenPGP Certificate" is used in this document interchangeably with "OpenPGP Transferable Public Key", as defined in <xref section="10.1" sectionFormat="of" target="RFC9580"/>.</t>

<t>For avoidance of confusion with GREASE in TLS, we will use the term "PGP-GREASE" for the equivalent mechanism in OpenPGP.</t>

<t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>

<?line -18?>

</section>
<section anchor="code-points"><name>Reservation of PGP-GREASE Code Points</name>

<t>We assign the following one-octet code points to PGP-GREASE:</t>

<texttable title="OpenPGP GREASE Code Points" anchor="grease-code-points">
      <ttcol align='left'>Sequence</ttcol>
      <ttcol align='left'>Code Point (Decimal)</ttcol>
      <ttcol align='left'>Code Point (Hexadecimal)</ttcol>
      <c>1</c>
      <c>51</c>
      <c>0x33</c>
      <c>2</c>
      <c>58</c>
      <c>0x3a</c>
      <c>3</c>
      <c>68</c>
      <c>0x44</c>
      <c>4</c>
      <c>75</c>
      <c>0x4b</c>
      <c>5</c>
      <c>85</c>
      <c>0x55</c>
      <c>6</c>
      <c>92</c>
      <c>0x5c</c>
      <c>7</c>
      <c>119</c>
      <c>0x77</c>
      <c>8</c>
      <c>126</c>
      <c>0x7e</c>
</texttable>

<t>These code points will be reserved for PGP-GREASE in the following registries:</t>

<texttable title="OpenPGP GREASE Registries" anchor="grease-registries">
      <ttcol align='left'>Registry Name</ttcol>
      <ttcol align='left'>Notes</ttcol>
      <c>OpenPGP String-to-Key (S2K) Types</c>
      <c>(1)</c>
      <c>OpenPGP User Attribute Subpacket Types</c>
      <c>&#160;</c>
      <c>OpenPGP Image Attribute Encoding Format</c>
      <c>&#160;</c>
      <c>OpenPGP Signature Subpacket Types</c>
      <c>(2)</c>
      <c>OpenPGP Reason for Revocation (Revocation Octet)</c>
      <c>(1)</c>
      <c>OpenPGP Public Key Algorithms</c>
      <c>&#160;</c>
      <c>OpenPGP Symmetric Key Algorithms</c>
      <c>&#160;</c>
      <c>OpenPGP Hash Algorithms</c>
      <c>&#160;</c>
      <c>OpenPGP Compression Algorithms</c>
      <c>&#160;</c>
      <c>OpenPGP Secret Key Encryption (S2K Usage Octet)</c>
      <c>(3)</c>
      <c>OpenPGP Signature Types</c>
      <c>&#160;</c>
      <c>OpenPGP Image Attribute Versions</c>
      <c>&#160;</c>
      <c>OpenPGP AEAD Algorithms</c>
      <c>&#160;</c>
      <c>OpenPGP Key and Signature Versions</c>
      <c>&#160;</c>
</texttable>

<t><list style="numbers" type="1">
  <t>The use of PGP-GREASE code points in the String-to-Key Types and Reason for Revocation registries is not currently specified, however the code points will be reserved for consistency.</t>
  <t>When PGP-GREASE code points from the Signature Subpacket Types registry are used, the critical bit <bcp14>MUST NOT</bcp14> be set.</t>
  <t>All code points allocated in the Symmetric Key Algorithms registry are automatically also allocated in the S2K Usage Octet registry.</t>
</list></t>

<t>Due to the smaller number of allocatable code points (63) in the OpenPGP Packet Types registry, and the division of the registry into critical and non-critical ranges, most PGP-GREASE values cannot be used as Packet Types.
In addition, implementations pre-dating <xref target="RFC9580"></xref> are not required to ignore unknown non-critical packet types.
A Marker packet (<xref section="5.8" sectionFormat="of" target="RFC9580"/>) <bcp14>SHOULD</bcp14> therefore be used instead.
Packet Types 51 and 58 <bcp14>MAY</bcp14> be used if it is known, or it is reasonable to expect, that the receiving implementation supports <xref target="RFC9580"></xref>.</t>

<t>To avoid any potential ambiguity, no PGP-GREASE code points have been assigned in the Private and Experimental range.</t>

<t>Note also that <xref target="INTEROP"></xref> currently uses signature version 23 as a de-facto GREASE code point.</t>

</section>
<section anchor="flag-bits"><name>Reservation of PGP-GREASE Flag Bits</name>

<t>We assign the following flag bits to PGP-GREASE:</t>

<texttable title="OpenPGP GREASE Flag Bits" anchor="grease-flag-bits">
      <ttcol align='left'>Sequence</ttcol>
      <ttcol align='left'>Flag Bit</ttcol>
      <c>1</c>
      <c>0x40...</c>
      <c>2</c>
      <c>0x0020...</c>
      <c>3</c>
      <c>0x000010...</c>
      <c>4</c>
      <c>0x00000008...</c>
</texttable>

<t>These flag bits will be reserved for PGP-GREASE in the following registries:</t>

<texttable title="OpenPGP GREASE Flag Registries" anchor="grease-flag-registries">
      <ttcol align='left'>Registry Name</ttcol>
      <ttcol align='left'>Notes</ttcol>
      <c>OpenPGP Keyserver Preference Flags</c>
      <c>(1)</c>
      <c>OpenPGP Features Flags</c>
      <c>&#160;</c>
      <c>OpenPGP Key Flags</c>
      <c>&#160;</c>
      <c>OpenPGP Notation Flags</c>
      <c>&#160;</c>
</texttable>

<t><list style="numbers" type="1">
  <t><xref section="5.2.3.25" sectionFormat="of" target="RFC9580"/> states that undefined Keyserver Flags "<bcp14>MUST</bcp14> be zero", but self-signatures containing undefined Keyserver Flags are not known to be rejected by any receiving implementation; we therefore interpret this narrowly, to mean only that undefined Keyserver Flags <bcp14>MUST</bcp14> be set to zero by the generating implementation.</t>
</list></t>

<t>A receiving implementation <bcp14>MUST</bcp14> ignore unknown flag bits.</t>

<t>Notation Flags are limited to four octets, while the other registries permit unlimited numbers of flag octets.
No PGP-GREASE flag bits have been allocated outside the range of Notation Flags.</t>

</section>
<section anchor="usage-of-pgp-grease-code-points-and-flag-bits"><name>Usage of PGP-GREASE Code Points and Flag Bits</name>

<t>An implementation <bcp14>MAY</bcp14> insert dummy packets or subpackets into otherwise valid packet sequences.
It <bcp14>MAY</bcp14> also include PGP-GREASE values in preference lists.
The data section of dummy packets and subpackets <bcp14>SHOULD</bcp14> contain only the ten octets "PGP-GREASE", in UTF-8 encoding.
All other fields of dummy packets and subpackets <bcp14>SHOULD</bcp14> correspond to those of a real packet or subpacket.</t>

<t>A generating implementation <bcp14>SHOULD</bcp14> choose PGP-GREASE values deterministically, while ensuring that all PGP-GREASE values are eventually used.</t>

<t>(TODO: how often should we add GREASE?)</t>

<t>A receiving implementation <bcp14>MUST</bcp14> gracefully ignore unknown code points or flag bits when required to by <xref target="RFC9580"></xref>, including PGP-GREASE.
It <bcp14>MUST NOT</bcp14> treat PGP-GREASE values any differently from other unknown values; this includes detecting or indicating the presence of PGP-GREASE.</t>

<t>PGP-GREASE <bcp14>MAY</bcp14> be used in either certificates or messages.</t>

<t>Since existing legacy implementations have not consistently followed the requirement to ignore unknown code points or flag bits, a generating implementation is <bcp14>RECOMMENDED</bcp14> to introduce PGP-GREASE gradually, over several release cycles.
This should ensure that legacy receiving implementations are not overwhelmed by errors in a short period of time.</t>

<section anchor="certificates"><name>Certificates</name>

<t>An implementation <bcp14>MAY</bcp14> use PGP-GREASE values in the following certificate contexts:</t>

<t><list style="symbols">
  <t>Dummy algorithm IDs in algorithm-preference signature subpackets (subpacket types 11, 21, 22, and 39).</t>
  <t>Dummy flags in keyserver preferences, feature flags, key flags, and notation subpackets.</t>
  <t>Signature subpacket IDs of dummy signature subpackets, in either the hashed or unhashed area.</t>
  <t>User attribute subpacket types, versions and encoding formats of dummy user attribute subpackets.</t>
  <t>Packet versions and algorithm IDs in dummy subkey packets.</t>
  <t>Signature and hash algorithm IDs and signature version numbers in dummy third-party certification signatures.</t>
  <t>Hash algorithm IDs in dummy self-signatures.</t>
  <t>Packet and signature types in dummy packets.</t>
</list></t>

<t>A generating implementation <bcp14>MAY</bcp14> also generate dummy primary keys with PGP-GREASE version numbers or algorithm IDs.</t>

</section>
<section anchor="messages"><name>Messages</name>

<t>An implementation <bcp14>MAY</bcp14> use PGP-GREASE values in the following message contexts:</t>

<t><list style="symbols">
  <t>Signature subpacket IDs of dummy signature subpackets in the hashed or unhashed signature subpacket area.</t>
  <t>Signature and hash algorithm IDs and signature version numbers in dummy document signature packets and their corresponding OPS packets.</t>
  <t>Packet and signature types in dummy packets.</t>
</list></t>

<t>Note that when an OPS packet is present, any PGP-GREASE code points it contains <bcp14>MUST</bcp14> be duplicated in the corresponding signature packet.</t>

</section>
</section>
<section anchor="private-and-experimental-ranges"><name>Private and Experimental Ranges</name>

<t>Unlike PGP-GREASE reservations, code points in the Private and Experimental ranges <bcp14>MAY</bcp14> be treated specially by a receiving implementation.
This <bcp14>MAY</bcp14> include emitting an explicit warning that an unknown code point in the Private and Experimental range has been encountered.
To simplify the recognition of Private and Experimental code points, each Private and Experimental range in the OpenPGP group of registries will be expanded to cover the code points 96-111, i.e. 0x60-0x6f.
Aligning this range to nybble boundaries will allow the use of a bit mask, and will provide additional Private and Experimental code points for future use.</t>

</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<t>Legacy implementations that do not properly ignore unknown code points or flag bits will experience failures; this is intentional.
None of these failures should have security consequences in themselves, unless other coding errors are present in the legacy implementation.
While this should result in increased security in the long term, exposing such bugs may cause problems in the short term.</t>

<t>Generating implementations are therefore <bcp14>RECOMMENDED</bcp14> to be cautious in deploying PGP-GREASE initially.
In particular, implementations <bcp14>SHOULD NOT</bcp14> generate PGP-GREASE values in production unless they have been tested first in a controlled environment such as the Interoperability Test Suite <xref target="INTEROP"></xref>.</t>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>

<t>IANA is requested to allocate the code points listed in <xref target="grease-code-points"/> in each of the registries listed in <xref target="grease-registries"/>, with the description "Reserved (PGP-GREASE)" and a reference pointing to this document.</t>

<t>IANA is requested to allocate the flag bits listed in <xref target="grease-flag-bits"/> in each of the registries listed in <xref target="grease-flag-registries"/>, with the description "Reserved (PGP-GREASE)" and a reference pointing to this document.</t>

<t>IANA is also requested to allocate code points 51 and 58 in the "OpenPGP Packet Types" registry, with the description "Reserved (PGP-GREASE)" and a reference pointing to this document.</t>

<t>IANA is also requested to adjust the extent of the Private and Experimental range in each of the registries listed in <xref target="grease-registries"/>, from "100-110" to "96-111".</t>

</section>


  </middle>

  <back>


<references title='References' anchor="sec-combined-references">

    <references title='Normative References' anchor="sec-normative-references">



<reference anchor="RFC9580">
  <front>
    <title>OpenPGP</title>
    <author fullname="P. Wouters" initials="P." role="editor" surname="Wouters"/>
    <author fullname="D. Huigens" initials="D." surname="Huigens"/>
    <author fullname="J. Winter" initials="J." surname="Winter"/>
    <author fullname="Y. Niibe" initials="Y." surname="Niibe"/>
    <date month="July" year="2024"/>
    <abstract>
      <t>This document specifies the message formats used in OpenPGP. OpenPGP provides encryption with public key or symmetric cryptographic algorithms, digital signatures, compression, and key management.</t>
      <t>This document is maintained in order to publish all necessary information needed to develop interoperable applications based on the OpenPGP format. It is not a step-by-step cookbook for writing an application. It describes only the format and methods needed to read, check, generate, and write conforming packets crossing any network. It does not deal with storage and implementation questions. It does, however, discuss implementation issues necessary to avoid security flaws.</t>
      <t>This document obsoletes RFCs 4880 ("OpenPGP Message Format"), 5581 ("The Camellia Cipher in OpenPGP"), and 6637 ("Elliptic Curve Cryptography (ECC) in OpenPGP").</t>
    </abstract>
  </front>
  <seriesInfo name="RFC" value="9580"/>
  <seriesInfo name="DOI" value="10.17487/RFC9580"/>
</reference>
<reference anchor="RFC2119">
  <front>
    <title>Key words for use in RFCs to Indicate Requirement Levels</title>
    <author fullname="S. Bradner" initials="S." surname="Bradner"/>
    <date month="March" year="1997"/>
    <abstract>
      <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
    </abstract>
  </front>
  <seriesInfo name="BCP" value="14"/>
  <seriesInfo name="RFC" value="2119"/>
  <seriesInfo name="DOI" value="10.17487/RFC2119"/>
</reference>
<reference anchor="RFC8174">
  <front>
    <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
    <author fullname="B. Leiba" initials="B." surname="Leiba"/>
    <date month="May" year="2017"/>
    <abstract>
      <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
    </abstract>
  </front>
  <seriesInfo name="BCP" value="14"/>
  <seriesInfo name="RFC" value="8174"/>
  <seriesInfo name="DOI" value="10.17487/RFC8174"/>
</reference>



    </references>

    <references title='Informative References' anchor="sec-informative-references">

<reference anchor="INTEROP" target="https://tests.sequoia-pgp.org/">
  <front>
    <title>OpenPGP Interoperability Test Suite</title>
    <author >
      <organization></organization>
    </author>
    <date year="n.d."/>
  </front>
</reference>


<reference anchor="RFC8701">
  <front>
    <title>Applying Generate Random Extensions And Sustain Extensibility (GREASE) to TLS Extensibility</title>
    <author fullname="D. Benjamin" initials="D." surname="Benjamin"/>
    <date month="January" year="2020"/>
    <abstract>
      <t>This document describes GREASE (Generate Random Extensions And Sustain Extensibility), a mechanism to prevent extensibility failures in the TLS ecosystem. It reserves a set of TLS protocol values that may be advertised to ensure peers correctly handle unknown values.</t>
    </abstract>
  </front>
  <seriesInfo name="RFC" value="8701"/>
  <seriesInfo name="DOI" value="10.17487/RFC8701"/>
</reference>



    </references>

</references>


<?line 222?>

<section anchor="acknowledgments"><name>Acknowledgments</name>

<t>The author would like to thank Daniel Huigens for GREASEy code points, and Daniel Kahn Gillmor for GREASEy flag bits.</t>

</section>
<section anchor="document-history"><name>Document History</name>

<t>Note to RFC Editor: this section should be removed before publication.</t>

<section anchor="changes-between-draft-gallagher-openpgp-grease-00-and-draft-gallagher-openpgp-grease-01"><name>Changes Between draft-gallagher-openpgp-grease-00 and draft-gallagher-openpgp-grease-01</name>

<t><list style="symbols">
  <t>Moved code points.</t>
  <t>Expanded private and experimental ranges.</t>
  <t>Added flag bits.</t>
</list></t>

</section>
</section>


  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA8Va6XLbSJL+j6eopf9IEwRNSj5kzuz0qC3ZVrRtaSV5OyYc
jo0iUCRrBKC4KEAyx9a77LPsk+2XWYWLBCV79lJEt4lCHXnnl4kKwzAodJGo
qRi8vTw9vjoVr02sxIXRWWGFzsT5SmUXby8GgZzNcnWLeavFKlzkSlo1CCJZ
qIXJ11NhizgoVzGe7VS8en40DmITZTLFznEu50W4kEkiF0uVhwZbNpuE44NA
r/KpKPLSFgfj8SsMSLya4vgiuDP5zSI35Woq/LrgRq0xGk/FWVaoPFNFeEIn
BLacpdpabbLr9Qrnnp1evwluVVaqaSCE32RQMyREwdMGv+MInS3EW5pB46nU
Ccb9eX/RqpiPTL6gVzKPlni1LIqVnT59SjNpSN+qUTXtKQ08neXmzqqnfo+n
tDZXK9Nau4Dc5WwUmfSpzOJc3S1iU9BTVz60MiGxFq21nQUjv5M2W0ttgZn/
JhOTgdG1ssFKT8XnwkRDYU1e5Gpu8Wud0o8vgSyLpckhrBBnCjEvk8Rp8JiP
E28rFfJrsCoz/XdZQOBTAZH+ptZ2dPqJXyonQ0/nX/y/xCy/zg2ZnIp1YfIg
M3mKXW5ZTZdvXpP1TAOdzdvjZx+vTy/PL6a8vJD5QkEelThIOnZk1b+XRssQ
AmA9uKnOur3WnclASrmc6UQXa3GNpeKq1IUS/OdIOHo5nkyDIAxDIWe2yGVU
BMH1UlsBqy5TlRXQplX5rbICD7lW7Cy3MtemtPVpuVpo696CGVFaRbP0Jg1E
PgxwKGZrSAzaWqzFnS6Wwrsk1ly/vxo5elIdx4kKgifES27iMiIFiG9PdOvx
Pgj82s+emy8CxMtMqK+aDxN2pSI91xHrTxQGfNgyV0ToncxjK6CrFV56Gs1c
SPjWIlMx3iBErOoQwbT9rkCyXdJGbmewIqxOyT9EqqIlbMWmLAYvnZET6J1O
EjHDfjIvdFRierImScH6aPNiqX5IeZ+9gXyBFMuCmM0MKwnijwoQDcIiQyJK
Ejyp7FbnJiNN2lFwxgvUVxDOU5cSA+kqUfSeBeTp1FmUlBQf316EXsC3Mimd
9uFzSYjIlMSCeJnDaKyAbCF1ky0MCX0mrYbHsbQjU+Zy0Qg8rASeKJIwTZdR
bqwVaZkUGtRs0jQiK3htMsQ4RyPcTJyouc60e/72JGrehnHz5p6sWcHw8rSO
iOK1IqrJItSA5AElxE4Fbbtn6yV1LpScJd5Q6z2uc5nZOWkI5F6Us0RHAnFh
MIT1CCbA7fnt25VyhjsZjyZkXd7x7+/B1RtYibw1OpZZpOgl2JiXFNl7/GIo
7pTTDvlXUbPV6GjAZkdvECE0FEZ8NDbZZLmREwsSjKAMY8Xgw6eraxDP/4qP
5/z78vRfPp1dnp7Q76t3x+/f1z8CP+Pq3fmn9yfNr2bl6/MPH04/nrjFGBWd
oWDw4fivJCvocXB+cX12/vH4/WBbB0iPZEMz5bSxyhWZrbRBrGyU65mT8a+v
L/7zPybPIOt/gnAPJpNX9/f+4Wjy8hke7pYqc6eZjFTJj5DTOpCrlYLjYhfE
fBHJlS5kYlmLdmnuMoEsoCCuP3wmyXyZij/NotXk2Z/9ADHcGaxk1hlkmW2P
bC12QuwZ6jmmlmZnfEPSXXqP/9p5ruTeGvzTLwkMV4STo1/+HJDTXXLwd6ET
5tkKB234RO4Xq9BFSrgcYqSLoWyLc0Qic0dujuwcGkSeohNZoeBmXySjb1OX
zP65drbtIwfiiUdVnZOvYPcIOOp7a67YO0GYTmWy3x19p77K2L+hhMN/38O+
v/5R/AUTl0zFd/G8+tn6+y7GXw8Pg4Nm0tGOSTI4rB9f7Jj07FnwrH58+XzH
pFnwvH482jHp+fPgRf346mDHpCh4WT/Cp3onvXwZHDWTDl70T1IcbqzqqL3K
hx5fxBy7WgamN62nARkPGcllPauxkWblfeDfr8VHIL5tznv+vouPBsgl2GUE
u/8auwkqKq9ARrYICxMiW4i9q4Pf9gWheNtz7N5kv173CUISxwVWI+srYIHZ
SkY38KStxd/rNWcppd1m0Wnm0+0bBpy9a67gtbIgfPTAERV9Bw19lxA0YgTp
8FLdGo+29lq/z8nx9zf5alKnOE5QYSHrpdtnbdC4TlNFcOfRZc2adxKY7ZET
Nte8Bk6BdXI6fnhpizYVIUkxYRB3vl45OUDPUCGpoxIDyeFwv0fu/dL+Ef3+
q8otw6EH1hyfHp/8rByIGcqdDY27TvoeBJORIGhBEKWbMDbANPl21xkc43RQ
vzG1igyPeqMyzwETkNE9yFfxUCBrq1vlYNCj8QZ4C0C1QM5Yj4KDkfgdyGAX
0fPcpI7snT6SV8GFgAvByqEjA8IG3MTxuhAVbCBarCpGweEICkk6RwGLENcV
LFW7Tb5zIupaQ5UkjoJMgGNMz05dS6w3AMY5KRlt0SyLrJhAiFmZzvAPFUVu
I+lRe03q3ovD/c365aJPJg5/0bRY32rrEQU91zxgQ9MIi6ZnJgvrgZywOLBZ
alANbVcmkczIKGZO8oTg2nSg+AHGi2OuC4ZbVQ8cPYwlF4yfPUL/wjJ11RXg
dO5qK+jekHKzm4zgYYdAbwuFO+9YfJD5DaTnh/eaWuD56KhTCuwLj/MKgptz
OqBiQ2cwTxmPgo5QgTZIPMATQHXN3LnQXOExbUMBA3fPOTsU645KMq7/hq78
cwqIFHQC3rtiEbZcrUwOLdcyocrBuJoFFKxhBQWVXaSudKYXKFGh6Mzs8qGl
vCXW4GR1ke1t5yJHwYIgRmydgsBcMxle6ziWkrCzaaa7roNbUQBCAGyvvfPW
RSlxcEjGIFGWhVSrGrFF2OhhrPsmkQvxq2akO8fvEH78EM6lOeTrP4Ft6yMa
1NI6qcG11bxexNqCo0CC49Fo1MKe46/j8QGPHXbGxuMJjz7bGMXfEY176Nbw
9L8E3JizPvTGcvhZCPczoK0HplGLj5gDY/BH+CTV50Sh3QQwbxQbm63e7k6h
PRM2ZoFkZ369e1FqbYeQg9Hh6OB5J44IW1AH1XlImVV9iIYbt7Gr8qHCv6vc
DFwjyapkHta+Y7mHJHVG+tu9URUgXSx0lXqu/ua6S9zkW+8MLn+kdkYT7+oC
37UAMpnn5i5Zcw8pVdxagoc/wljFl6VtDLNHZJA5LlSmchfgu3TAwo93R0De
cSPm167golJbZSSQRKfaN+LmpkTypDyLtHW31Inr2xhiu41nEO6wBgdUa13e
taRcPs3tMcJxbU9rfLIVV+uEb8rC6tidyEGUduvSy3HPoYHd1T1F5Do8QVjZ
loyQgpCmVF6IuEzTtU94lvKPrRCSddmdWb/TCCjI2sghPjdaH+Bcj5I25Ej/
YBty1Xhmoqkvzj0tJHGJ7aIqjHcpIl5aJPms6229MjFqrGVe5J322pCO/XT9
JjzitibVUkjziIZOocCfSWx//FCkLbsyWexAl3GIWXJ7tZJLW4JsqDvNuN52
aWinbYnFitqF8GjrAWJlkdwPpw3ZuagNtr2Y7FpRg7VkaEloA+TsXZ+fnE8J
cYNykpldmjKJybGBtHxg/2X/cQdb5DKiRji23vC1NniAMFpZiJB6G5jBz2uU
MvSWQ+c1zDjbquB3ATn3wUiKWbGes2kRqGDY7xRcEeVm/tFFKm+jTsARa4Zw
VxbzJwcWqyJbtcr3eNsEBa3zO0guE0rzmVHTrGYJpChI4a/kuleadqw/dCRq
IaP1FrLl0MDVUlXrMFecnVXs8R+LkVuu2xB3lwoA6B8wR0im1Yjkbf13m45x
QvNx6azRUBy3VLsR6lMJJX8RraNEWf8JxZuX/4DD5uqZ3mVeTYqi3WEzSeoy
k0J6yTmMSNoWoYsgp4m5JgH0pMj4pP2lYGfkK3u9bQsEtfTI8UZ9LQgO/UGc
cKyQVUknzk4cWdVA2IpzDbZtxZO9+rerPMRkMhQH9N+Bq7kOX+2P6oPmnKdw
wE2dO5sDoNO5wzNu3pA/Efifrh6rK4PqfNr6apsu5qMOhX2ED1tWTrJaSruk
tEV+5n/T53Han7tfsm50bDA8rJC+C7VVaBbuu2qLinLHNsyDr686W21pxXNT
zkguvQKgZUT9xlrOAVuVSZXm650RUfI4pE+E65bFsMBraEbnvds+oaGui+Ra
vHWJcMZSL6u5eTDL1KnZT1HVatRrEpCcrMp9u2r7xAa79NWrTbtztg8+sv03
Hc0HyK6T/UMGWu3dY5g902tj/Z+yhforWDO3jShAmc5bKIJ4P7+4Etsm/YNq
5wKbgyrnVkDuZjsK5y6HFUPOkLsae0UFphowHperRHd6UF2iN9ljULqzHXDJ
TaAg+ASsfNMxiLyp3xESetqND7cYbJWAGRiQjqmnyHCHKpmdKcbnJgeCHVxV
APHsPHwPgbiHXO5knjUoK+tJrz9GJ1mUg/r8aZ3KJgJj14ZuIeCs+brq6ZiF
+wrOoGPXni05DYWS0fKx4zd6fXzdiE5olTNVhwC8Y5PqTkJfU/bVi3BC6UqP
1EiMv74Yh/jfnEA1jMJJi9pXfDA2ydYz6mHNwHYsm6Oo5rnjvcsKRFOnNZX2
xqUtnrXKzS3VQ1UTEBz9iFS4vTEv2UCxPVsninBAZsTo14SpYo6V7h6C9W/C
qPPmPgje98MzNofYMEZZ8aWPnwHBxJdiwhkfzKVOKOZX0JSLLnctQiZUPWbK
N11tM7mCVQwUK/oZLVZFmdd5isxyS+kWdSqCrAfFPtl6QEVwyweKylJ6ceko
+N2Xww2uw7IyKdzNoYh7P3FDT7WZIaNAITMkvo3lAFLCamclYE0qQbgkI4Ao
YSlp7fsO49FCKPDtrvTm6G+aEhsIFiaN3Qu++kQBVK0Ss+7WGIJvnlDU4IZz
c9lnu+XcfNpvkumOQre+/eQlT1cXWjU/3auiPpzObeEgbf8NICcpyet/7JIR
W/vZ8cfjbUvXMpPbVs5zueMM27G+DVL1JLbcn+r26p5Mz/f8e0aIFJO6XwrI
8XuWtnqE90MHQvhzA98VcR/iBpdV03KvEfX+wIE90QBtJoDjj+leSRn9CIuN
g/ZQ2bR1f5K9zT7o/wWPDPX6GW3rsfkc4d1t0PcpaND6FvT/QXn8t9K6Dx7A
heQOXuyPJ7x/1Aa5dzCYjMfIcuMBETFwGW/gLznOIB5yseOIIj3cdcE39dz1
LHdNVdxxcGS0w/zK7EacyEyrRLwrNUKHS1FOWutuQueLcm7ub3KZibdIGCml
kNaCdjvziTipUOc78GHydYULDXWZxSnfZJ36sO27bD58c+83NaS+mQufK/64
X3VZqZ5eOqT1qyruKHA9dmN6zAw8NmtCCP8DH9xingDwaQVAVi0Vq23oR3OP
Y5rYEsZ/AUTa4XY0LgAA

-->

</rfc>

