<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 4.0.5) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

<!ENTITY RFC2119 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY RFC8174 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
<!ENTITY RFC9635 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.9635.xml">
<!ENTITY RFC8693 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8693.xml">
<!ENTITY RFC2693 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2693.xml">
]>


<rfc ipr="trust200902" docName="draft-zagarella-verified-human-root-00" category="info" submissionType="IETF">
  <front>
    <title abbrev="Verified Human Root">Verified Human Root Attestation for Agent Delegation Chains and Audit Records</title>

    <author fullname="Roberto Antonio Zagarella">
      <organization>Violet Shores Pty Ltd</organization>
      <address>
        <postal><country>AU</country></postal>
        <email>rob@violetshores.com</email>
      </address>
</author>

    <date year="2026" month="July" day="19"/>

    <area>Security</area>
    
    <keyword>agent identity</keyword> <keyword>delegation</keyword> <keyword>audit</keyword> <keyword>biometric attestation</keyword> <keyword>provenance</keyword>

    <abstract>


<?line 28?>

<t>Autonomous software agents increasingly act under delegated authority, and
emerging audit-record data models capture what an agent did, under which
delegation, with which authorization state. In current practice the head of
every such chain, and the identity axis of every such record, is a key, an
account, or a workload identity. No standardized element establishes that an
identified natural person, verified as live and present, stands at the head
of the chain or behind the recorded action.</t>

<t>This document defines the Verified Human Root Attestation (VHRA): a compact,
privacy-preserving data structure asserting that a biometric proof-of-human
verification of an identified natural person (or an M-of-N quorum of such
persons) occurred at a specific issuance event. It further defines how a
delegation chain binds a VHRA at its root such that the binding survives
attenuation, and how audit and interaction records reference a VHRA so that
any recorded agent action can be resolved to an accountable natural person
without the verifier receiving any biometric material.</t>

<t>This document is offered as input to the proposed AUDIT working group's data
model work. It deliberately does not standardize biometric verification
methods; it standardizes only the attestation structure, its bindings, and
verifier obligations.</t>



    </abstract>



  </front>

  <middle>


<?line 52?>

<section anchor="introduction"><name>Introduction</name>

<t>Delegation and audit mechanisms for autonomous agents are converging quickly:
attenuable token chains, delegation receipts, agent identity attestations,
and audit-record architectures are all active areas of specification. These
mechanisms share a structural property: authority is rooted in the
possession of a cryptographic key, an account at an identity provider, or a
workload identity. Attribution therefore terminates at a credential.</t>

<t>A large class of deployments — legal instruments, regulated industries,
critical infrastructure, government — carries a requirement that
credential-level attribution alone does not address. The governing question
in these settings is: which accountable
natural person authorized this, and can that be proven years later, to a
party who was not present, without that party being granted standing access
to personal data? Keys are delegated, stolen, shared, and escrowed; accounts
are administered; workloads are ephemeral. A credential at the head of a
chain does not answer the question.</t>

<t>This document defines a small data structure, the Verified Human Root
Attestation (VHRA), that closes this gap in a composable way:</t>

<t><list style="symbols">
  <t>A VHRA asserts that a biometric proof-of-human verification of an
identified natural person occurred at a specific issuance event, at a
stated assurance level, optionally as an M-of-N quorum of distinct
persons.</t>
  <t>A delegation chain MAY bind a VHRA at its root such that every
attenuation hop preserves a resolvable reference to it, and a verifier of
any leaf action can validate the human root and fail closed if it is
absent, invalid, or revoked.</t>
  <t>An audit or interaction record MAY carry a reference to the VHRA under
which the recorded action was performed, so that audit resolution reaches
a natural person rather than terminating at an agent identifier.</t>
</list></t>

<t>The VHRA is intentionally agnostic to how biometric verification is
performed. Verification methods, liveness detection techniques, and their
quality are the province of certification programs and are out of scope. The
structure standardized here is the interface: what an issuer asserts, what
travels in the chain, what a record references, and what a verifier is
obliged to check.</t>

<section anchor="relationship-to-the-proposed-audit-work"><name>Relationship to the proposed AUDIT work</name>

<t>The proposed AUDIT working group contemplates data models for interaction
records, agent identity, delegation context, authorization state over time,
and action provenance. Each of those elements is strengthened by, and none
currently provides, an optional verified-human-root binding. This document
proposes that the audit-record data model include an OPTIONAL field carrying
a VHRA reference (Section 6), so that deployments with accountability
requirements can resolve records to natural persons while deployments
without such requirements omit the field entirely.</t>

</section>
</section>
<section anchor="conventions-and-definitions"><name>Conventions and Definitions</name>

<t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
"SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
"OPTIONAL" in this document are to be interpreted as described in BCP 14
<xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they appear in all capitals, as
shown here.</t>

</section>
<section anchor="terminology"><name>Terminology</name>

<dl>
  <dt>Human Principal:</dt>
  <dd>
    <t>An identified natural person on whose authority a delegation chain is
issued or an action is performed.</t>
  </dd>
  <dt>Liveness Event:</dt>
  <dd>
    <t>A discrete biometric verification of a Human Principal, performed at a
specific time, asserting that the person was live and present. The methods
by which liveness is established are out of scope.</t>
  </dd>
  <dt>Verified Human Root Attestation (VHRA):</dt>
  <dd>
    <t>The data structure defined in Section 4, asserting one Liveness Event (or
an M-of-N quorum of Liveness Events) bound to a specific issuance event.</t>
  </dd>
  <dt>Issuance Event:</dt>
  <dd>
    <t>The act of creating a delegation chain, credential, or session for which
the VHRA establishes the human root, identified by a unique nonce.</t>
  </dd>
  <dt>Quorum Root:</dt>
  <dd>
    <t>A VHRA whose assertion covers M-of-N Liveness Events of N distinct Human
Principals.</t>
  </dd>
  <dt>Delegation Chain:</dt>
  <dd>
    <t>Any mechanism by which authority is conveyed from an issuer through zero
or more attenuation hops to a leaf credential under which an agent acts.
This document is agnostic to the token format.</t>
  </dd>
  <dt>Audit Record:</dt>
  <dd>
    <t>Any record, per an audit-record data model, describing an agent
interaction or action, its delegation context, and its authorization
state.</t>
  </dd>
</dl>

</section>
<section anchor="the-verified-human-root-attestation"><name>The Verified Human Root Attestation</name>

<t>A VHRA is a signed structure with the following logical fields. Encodings
(CBOR, JSON) are expected to be profiled by the consuming ecosystem; field
semantics are normative, serialization is not, in this version.</t>

<dl>
  <dt>subject:</dt>
  <dd>
    <t>A reference to the Human Principal's identity credential. This is a
reference, not the credential itself and not biometric material.</t>
  </dd>
  <dt>liveness:</dt>
  <dd>
    <t>Metadata about the Liveness Event(s): the count and class of verification
modalities employed (e.g., "multi-modal, fused"), the assurance level
asserted by the issuer against a stated assurance framework, and the time
of the event. This field carries no biometric samples, templates, or
model outputs.</t>
  </dd>
  <dt>issuance_nonce:</dt>
  <dd>
    <t>The unique identifier of the Issuance Event to which this VHRA is bound.
A VHRA MUST be bound to exactly one Issuance Event. This binding is the
anti-replay anchor: a VHRA MUST NOT be accepted for any issuance other
than the one named by this nonce.</t>
  </dd>
  <dt>freshness:</dt>
  <dd>
    <t>The validity window within which the Liveness Event must have occurred
relative to the Issuance Event, as asserted by the issuer.</t>
  </dd>
  <dt>quorum:</dt>
  <dd>
    <t>OPTIONAL. Present when the VHRA is a Quorum Root: the values M and N,
and, for each constituent Liveness Event, an independently-signed
sub-assertion bound to the same issuance_nonce. Constituent
sub-assertions MUST be independently produced and signed such that
satisfaction of the quorum requires M distinct Human Principals; M
qualifying sub-assertions from a single person is a protocol violation.</t>
  </dd>
  <dt>revocation:</dt>
  <dd>
    <t>A pointer (URI or equivalent) at which the current validity of this VHRA
can be checked. Revocation semantics are defined in Section 5.3.</t>
  </dd>
  <dt>issuer, signature:</dt>
  <dd>
    <t>The attestation issuer's identifier and signature over all fields above.</t>
  </dd>
</dl>

</section>
<section anchor="binding-a-vhra-to-a-delegation-chain"><name>Binding a VHRA to a Delegation Chain</name>

<section anchor="root-placement"><name>Root placement</name>

<t>A delegation chain that claims a verified human root MUST bind the VHRA (or
a cryptographic commitment to it) in a root position with the following
properties:</t>

<t><list style="symbols">
  <t>It is covered by the signature of the root credential and, transitively,
by every signature in the chain, such that its removal or alteration
invalidates the chain.</t>
  <t>It is non-removable: no attenuation hop can produce a valid derivative
credential that omits the binding.</t>
</list></t>

</section>
<section anchor="preservation-across-attenuation"><name>Preservation across attenuation</name>

<t>Each attenuation hop, whatever else it narrows, MUST preserve a resolvable
cryptographic reference to the root VHRA. A verifier presented with any
leaf credential of the chain MUST be able to resolve the reference and
validate the VHRA without cooperation from intermediate hops.</t>

</section>
<section anchor="verifier-obligations"><name>Verifier obligations</name>

<t>A verifier of an action requested under a chain that claims a verified
human root MUST, in addition to whatever chain validation the token format
requires:</t>

<t><list style="numbers" type="1">
  <t>resolve the root VHRA reference;</t>
  <t>validate the VHRA signature and its binding to the chain's Issuance
Event via issuance_nonce;</t>
  <t>check freshness and, where present, quorum satisfaction;</t>
  <t>check current validity via the revocation pointer; and</t>
  <t>reject the action if the VHRA is absent, unresolvable, invalid, stale,
quorum-deficient, or revoked (fail closed).</t>
</list></t>

<t>A verifier MUST NOT treat the absence of a VHRA as equivalent to a present
but unverifiable VHRA: a chain that claims a human root and cannot prove it
is invalid, whereas a chain that never claimed one is simply outside this
document's scope.</t>

</section>
<section anchor="revocation"><name>Revocation</name>

<t>Revocation of a VHRA by or on behalf of the Human Principal invalidates the
chain rooted in it. Post-revocation, verification per Section 5.3 fails,
and all leaf authority derived from the chain is extinguished at the
identity layer, independent of the revocation state of any individual key
in the chain.</t>

</section>
</section>
<section anchor="referencing-a-vhra-from-audit-records"><name>Referencing a VHRA from Audit Records</name>

<t>An audit-record data model SHOULD provide an OPTIONAL field, suggested name
verified_human_root, with the following contents:</t>

<t><list style="symbols">
  <t>a reference to the VHRA under which the recorded action's authority was
rooted;</t>
  <t>a cryptographic digest of the VHRA as validated at action time; and</t>
  <t>the validity status observed at action time.</t>
</list></t>

<t>This triple permits a later audit consumer to establish that the recorded
action resolved, at the time it was performed, to a then-valid verified
human root — and to re-resolve the reference if the underlying attestation
is still available — without the record itself carrying any personal data
beyond an opaque reference.</t>

<t>Records for actions performed under chains with no VHRA simply omit the
field. Audit tooling can therefore filter, without heuristics, between
human-rooted and credential-rooted actions — which is precisely the
distinction that liability-bearing deployments need to make.</t>

</section>
<section anchor="privacy-considerations"><name>Privacy Considerations</name>

<t>The design constraint of this document is that accountability must not cost
surveillance:</t>

<t><list style="symbols">
  <t>No biometric samples, templates, feature vectors, or model outputs appear
in the VHRA, the delegation chain, or any audit record.</t>
  <t>A verifier receives only: an opaque subject reference, liveness metadata,
a digest, and a validity status. Resolution of the subject reference to a
legal identity is a governed act, available to authorized oversight
parties under the deployment's disclosure rules, and is out of band with
respect to this document.</t>
  <t>An oversight party can confirm THAT an accountable verified person stands
behind an action without learning WHO, unless and until disclosure is
authorized. This "standing-access-free" property is deliberate and
deployments SHOULD preserve it.</t>
  <t>The issuance_nonce binding prevents cross-context correlation of VHRAs:
an attestation is meaningful only for its named Issuance Event.</t>
</list></t>

</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<dl>
  <dt>Replay:</dt>
  <dd>
    <t>The issuance_nonce binding (Section 4) is mandatory precisely because a
liveness assertion detached from its issuance context is a replayable
bearer of trust. Verifiers MUST reject VHRA presentations whose nonce
does not match the chain's Issuance Event.</t>
  </dd>
  <dt>Freshness:</dt>
  <dd>
    <t>A stale Liveness Event weakens the live-and-present claim. Issuers assert
a freshness window; verifiers enforce it. Deployments choose windows
proportional to risk.</t>
  </dd>
  <dt>Quorum independence:</dt>
  <dd>
    <t>The value of a Quorum Root depends on constituent sub-assertions being
independently produced. Implementations MUST NOT permit a single capture
pipeline to emit multiple constituent sub-assertions for one issuance.</t>
  </dd>
  <dt>Downgrade:</dt>
  <dd>
    <t>An attacker who can strip a VHRA binding converts a human-rooted chain
into a credential-rooted one. The non-removability requirement (Section
5.1) exists to make this a signature-breaking operation.</t>
  </dd>
  <dt>Verification quality:</dt>
  <dd>
    <t>This document standardizes the interface, not the strength, of biometric
verification. An attestation is only as strong as its issuer's practices;
conformance and certification of issuers is expected to be addressed by
external programs and is a natural complement to this specification.</t>
  </dd>
</dl>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>

<t>This document has no IANA actions. A future version may register the
verified_human_root audit-record field and a VHRA media type, subject to
working-group adoption.</t>

</section>


  </middle>

  <back>


<references title='References' anchor="sec-combined-references">

    <references title='Normative References' anchor="sec-normative-references">

&RFC2119;
&RFC8174;


    </references>

    <references title='Informative References' anchor="sec-informative-references">

&RFC9635;
&RFC8693;
&RFC2693;


    </references>

</references>


<?line 318?>

<section anchor="binding-to-existing-authorization-ecosystems"><name>Binding to Existing Authorization Ecosystems</name>

<t>This appendix sketches, informatively, how the VHRA composes with current
mechanisms; none of these bindings changes the host protocol.</t>

<dl>
  <dt>GNAP (<xref target="RFC9635"/>):</dt>
  <dd>
    <t>The VHRA functions as interaction-derived evidence bound to a grant: the
grant's issuance is the Issuance Event, and access tokens derived from
the grant carry the root reference.</t>
  </dd>
  <dt>OAuth 2.0 Token Exchange (<xref target="RFC8693"/>):</dt>
  <dd>
    <t>A token-exchange chain preserves the VHRA reference as a claim that MUST
survive exchange; the verifier obligations of Section 5.3 apply at
resource access.</t>
  </dd>
  <dt>Attenuable token formats (macaroon- and biscuit-class):</dt>
  <dd>
    <t>The VHRA commitment is the first caveat; attenuation appends caveats but
cannot remove it.</t>
  </dd>
  <dt>SPKI-style authorization certificates (<xref target="RFC2693"/>):</dt>
  <dd>
    <t>The VHRA is carried in the root certificate; delegated certificates
reference it.</t>
  </dd>
  <dt>Workload identity ecosystems:</dt>
  <dd>
    <t>A workload credential remains workload-scoped; where a workload acts
under human-rooted delegated authority, the workload's requests carry the
chain, and the chain carries the VHRA. Human root and workload identity
are complementary, not competing, axes.</t>
  </dd>
</dl>

</section>
<section numbered="false" anchor="acknowledgments"><name>Acknowledgments</name>

<t>This document responds to the direction of the proposed AUDIT work and to
the broader delegation-receipt and agent-identity efforts whose gap it aims
to fill.</t>

</section>


  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA41b7XIbx3L9P08xRf+QeAtASbLsxGSlElqSI+VKlC5F+1by
xzXYHQATLXbgnV1SsEtVeYg8YZ4kp7tnZmcBUL4ul00Su/PRn6dPN+bzuepd
39gLffaL7dzK2Vq/Hram1Tfe9/qq723oTe98q1e+01dr2/b6pW3sWv74YmNc
G7Rpa3011K7XN7byXR3OlFkuO3t3et0zVfuqNVtsW3dm1c9/N2vT2aYx87v4
9HxDT887PD1/8kRVprdr3+0vtGtXXoVhuXUh4AT9fodV3ry6/Um5XXeh+24I
/bMnT3548kxhSYMDfLTV0Ll+f6Y+2f09Tneh9Fwbvoqr8V98Rn+p87X4c7oO
/bB0fmv7zlXajNKgD3adv7OtaSurzNBvfEfrKo1/VkPTyPVu/NJ2vddXbe9b
5/V/pYvyc75bm9b9zite6F+cb2yvP2IlG/SHfq/f9jU/Z7fGNRe688t/u+OH
Aj+zqPxWtb7bYoE7i931zU8vnj19+kP88Z+f/tPzC0UCmz7yw/fffpce+f6H
b9OL/KOaz3H3Zeg7U/VKXQ04t9/6IejgV/09Di+SC1BEBfkG166bvcbDemhr
2yUpQt8iFAh3Rvah7NZ2azwtkp13bCi6Nr3RW4+3gq7Mrh+wwf3G9Hglqqh2
9Syufb9x1UaNeprpe9dv5M9pO5GmJj3ZhX7Taii/o3V2dCNXWd1vrN5YU2u/
Uhb2ttdhwPsVmTIflZ9IlqHNZxfwqC4elbPPND4wGkZFbylTVX5o+xm0ir/C
zj41HpukdRb62tOp2tp0tfsd8sE1tnQwsqll48IGWu/l6kreYrdpDYRiGr2z
XaArJw/RJugGSuUT72AOljbnHXCsPl9T4ez0M9+PDre0GxcvKRehtSqS2kKp
2w0uBe8c+Gi1XbmWj2X1n8WHx7+8vrk6v8DdYZY7LDhTu87dmWo/59N1d6R8
1jesa6hY1Sbgg54+kJsX3gb38qs5/uVIoOTaleyFK+EIDwpJPyYdtPodvX6t
fxt8N2zpJdKekmfCufYV20ateeewsxXtAK2GgbyaNN72sKEeDt1BBF2Wx8bf
a1MYYhTu0rHsNUmCFnVwE4pgYjV8Q5IkPUZXDgNkcmeDosDSDtGkSZ28PsdT
+s21ve1EQ1FjWNauLMwap4zbBc8bKNPuC7WyB8VXK0hkSToPvrnDhwhL5GRi
trBAeyBFRc7lBzlztLqO1raOVUk7jepChMEjpjmyIfYeOixbrGt3tKLnRaHi
nQ/44Ornl29u2Wdo4XXnh92jwLaiODbwR6wJ/OIQUrEZok7toYuW5Dv6VXGk
0mQU/rbxdbiEUsrHcbgWK9FpivA+WuiMlRg1FiSSZVl4uK0YQFhI5Ny6um6s
Ut8g8vSdrwcWvVJFyiSNim63FmbTurANnFzNGGtjiKVoW/n2LgbO3wZXfWr2
F8leSGW9/2Sj+eF0hUWynnY9HXmS6cprhpnKp0kB2XTVxvWWLy8nME3DJkSh
hiI+O1J0Fl5moW8Ru6wq7hM2/GaWIxkVlA1fRwrPiYFsg/zDko2TDhTMIVhO
7Ozjuur2u96vO7NDjE+hNtmsljSRb0YJGb90EoLViRCMeNW55cACIoe2kDtk
aLutg+3bIJEAeY3fYGO+0o3p1tBDg1hFh6rtrvH7LSvo//7nfzVJvMH56ar8
1xlkvx4aI9eqgUc6ZyHqCleGxOjZVWcKC1sDR3QtOwstWJmOXsBBOguVd5Il
2LnHk80bRKeGlJkvZBrf2tEnTF1Dg4GVE7cQI4L2ySZF4sHqYHuKwPDNcJFy
6RgU1EFoTWmWAgj8XOIVhRYOb0sbYZHeW9MhQVFUmHGoUTsD7WMDr++NHDFn
rTHSYA15bmklFJiW5Mgey0GnqnAphQXlPDgYhYl/1X+1ezHXDEAoGQIsIaSy
NdZyVBuqzt/b+jJdMig21Rom4EJPceoyZ29Z0e42BF5gDvqqMI4yybK1KskC
owbacI8oQc8kqT+YYeEqW3K0aX6cPZR51XHmnYn0qgYRNbBu9NrsyLEkI/vA
AePeIICov+AmkqU4AYc/S7/6OP0CNT6cgP+h1DrjT7EOgzVKD8iI/DEbN9x4
R9tBLHtKHacSeg2VAYgCqMedKRDT5Y5y87ur/+Qw/vX0zCAPixUZGcl4pyOC
iV5JCZSFOWZhGKTrxcLMmCyBMDXnycaaVZmH70zjoOoIRlnCfBJ6fwWwL2pE
/FhRvnKBllmKr7iWX+YghwoL8b+WO7cxreDvx4iB70+RZc83KI7NFkYSYYyN
jSQEnICH7LcQM9UT7F4+mg1vy2IZ4pamQmihQx8aBjL3hn2CIkaMu+zXBeLP
ZtWxu8TjucDXakeTWLce2q/oEgSYTid+El4+8yL6UvwoYoIZ42h4IfzSUurj
9IBk1jry21wTuE79NkD2lEQ7mxAMsBAECVusCMnmtfEJgtdWamN6nOIbZc4K
aZCDshph8KQuoLxEt+UqhBS5MpW9yFUR+RAkGB13xn9XKNfuqISSoJ5qGXkl
WUDWerxR/DQbKwTFgEagIRRYfYL8v/kGNX0jcGHjdl+BbqKrr2E6AjO93e4a
zrVl6beaGq2KMPcQvEwQDi/2mZzuuPLTlO9077Y2QpwqKSWW7Av9CjaquTbC
cVMxRkmQwq9t17hli2sspXxFQG+tirVkk7EGizLHKX2CvUjYkVReBH4V5RTG
suCBupgK7Waoqc7T7z/cvnl/ffVWY5OmFn/G2irGtNGvH3+MZvz9+einJXLh
wjmneUdGrQq4EThKxVIhFx3Q/dSdAwWLxpYr56ohVsrFkn7r5KZyelJpBxhP
RqZfEMxl3xaPeUl50fHvYlfAfmRMOMXZu58/3p7N5P/6+j3/fPPqbz+/uXn1
kn7++Prq7dv8gzyh8Mv7n9/Gz+mn8c0X79+9e3X9Ul7GX/XBnxA6zwT5nyUF
nImnlZmcQ4InBMSGjIwhOQ3CAeRA0cIg98cXH/TT5+qPPyJV8+WL5p+Jq8HP
9xsbS0AuS+RXiAwRZ7cDouJ0DphQmZ3rTUPmF1RA9Gs5bLAobzms+sav90oJ
ZPjQwYjczjQX6oISxVcSd0sILdgCpJvjZMoJiQNRraXUjg7migSBw7xNcfUV
KZc3p5RdkWweiteM+w+OPRtXzZghYQp28kMigUOU3Oj+BE8ioDiGfyy23Mes
lxMBLjLyMicCuFL/IB+CO9NeB7yHwD62iOSpz8tLEJKfCo84DQYTxyBo+mA4
10t4tdT3D7IaSr1Jf8i6oXMSkUe5DClc8vKR8mcFBGYQkgo2iuHC0OkRVEzJ
rRLrzEorXJKZDZxvKdJWJOC/yQVJsGI5vGC0TpEUZwFYT0hCORAFXeU6g0TR
FE6X7YrQ4iGbLS6yH6vz0TomhSsX5nucfdX5bZGY+w1S3Xqjf7edV8TxIox3
9hBRBlEP48KipCh4zhEPQSc4qNZHvEqJgEi4QgYI3Uula8HIp1sl6nJnxW1P
55xZClrC88g5yOULXEl+XwllRUD6ZGIm8op4jDJBJ7wvserPiUUqwRMAhD27
dcv1YPIkTmScVHzT+Hs6MCIf19mcZlAAv2orz/SNevzix/c3M/0fH99fn0tp
9xn+0Qvikdp1hXzG9sg4Culn2NKakFDYozzcXsqyKlgcFrKXEjGz8Mi2TIMl
NOK4FJzldEHGKnVgGJb/jb3FtI8Q+UEAfBRGmqOgJ8QkSDCQal5jxtUnn3+0
LOjBNqsIZfrTxF2KfnSmd7Y3bBBmmTjAqXM9DucXUUjMxRANkDiSCfOmyaYI
NhOpQejPk9c8tov1Asl1OzS9m/MTM70agBzPzqXsPSgHKfix14/qSVB4TewX
F5qHheQKENwSBh2JfcoX5JfCikeOl+U4girHFXwhpGBwbkJ7Gb5S6JOrAaJB
QruBnFSlMPsrR7EUVWNkGwubtP00CJPyU/WF8ySr53BOASA6AuMeWGsO8/Yz
PBFwgbLGdMV4s8Q4S1XBaQRC74DaDAJvW1HzKhXGCVXRDsS27EiizE+2+zGL
eCrjONAbKTlob+p5ReWw3UscXyHnbpJZkTS4fiVLhrfWKNzIhV1b1J0HmW87
QLkbFDiZVmBrb9jhksNM7z1jwuCkueBEkjrpOAnPLeBqjAwYco3pi2NOmYiE
DDcN6kL9jm3qesbyREwlIVHly2EDrjrQetO7cLmAW9udbWuuJOYS0SgqDsv5
mNeycmlDmJ/VU9NaEGROuxy+HbKNTPai+FYPFXkI1k6hNJEftAhEGlYpwK8i
dcW3j0iebj3Np0U2vdTvsAjXyKu9dDgmh5JMqblnmPEZixgH633lUUE5L8Um
1ETshsQQCZI7z/lHP/755g2lHzoRVIGrnRMqHO0ntfyyofFVokfhhLETwiUu
kQI3eSM9DesnYNp3i2+jmxOxSTIkAJ09vWwiyEM5dLPfJ8HzS1KlEp6XVEWx
9k4S44/RY6NTMlg4RCpSnFO6hB9XXGRRsjxC65EXNI7YiLF/WNBOYi2pK8g7
Etw85N8rv0UJt42RykHszC7yEihmnZBERwlZReofUZWpxze94Kc7bgpF5yyE
InbHq5ZsK7lYj7BO+yAf7GcC3GNfNr8+pUBGao/ZPrv1MArGLg1BmZigIqfG
tER+eTGeFR43l3eXNCuB1HBIEJJJRe8iGdNqUAT1P+mwZHPjTfg4VAyHsh0o
XMsHIRpjq6jqfAjlXkoxbXGwuzA9JAhtG6BjoL4WWczfI0uxahN9OWEv1VS5
RxCEFUC2QLR3ZoliBQXFCYXQ7tUhiJ00nFMgit2qzCkIv5ibmNRWKzlRwfqR
Sqg82U8cQ6EYwnEAucbR44SmRXi/nGjMkUcUfGxRq1JEg6/iJoK6zVfdRR24
C0M6U9di9Jy4owpklXib2GmaQPNEtJA3PF1MJZJkPsrmUj1b6GPZjAafUHZK
8lF9fAwEn5QYaZJE8umdMwfJ5FJ9u5BwqHO2Foe7ZzYyN2piMijzxKV6nt49
iru0kyg6B9gYxC9Z5d/R7QkFC+CLHMJqmn8j7z20o+kWLDiCLX6ny8nZ5hSz
K2fjJEZkyPXjglU/X0yMIgOenopeOQntKaxuaheEIt1IOI5CUcuBZl9kObZy
euHiAXM64PoRNqQRhmAIJSomuePNWPQEY8qFWjExWo64l5aZ4uAASveEQgNS
Dac6lepEWEBiLJjKTYpQqsh64z0RUCE1wh92Y1AvRF8+yPSHATN2vsZergPy
/IDadD5qfjaleagALXIqdz1SPxoJURomud7mUJpq7TG4EEvzmXiKIdI0rD6V
SyXAW8rSBQjK2aVI+UIYrwTgwofuXA0IQ4yjKpMJ5+Wb6JZFbuYzTabfYF4P
ltY6so+RQD5mdSlnrdcSmAhQp3GD+le2nV+FOzlR9nLZ3faSY7/a5Hm4xfMo
FEK/N8SNiVIvec1pxqgdHTNJNLlJMgxh6mIzBdYqHv+XBKAlQJDsB5SMS05P
h6+kbilKsJ0ARk6aRtrKse8kNToRL35km0YWMF1Q5agv4y+z1L6ljShjHjS3
2MWpBzCXZH4qD1C33ghK7+z8dGaL0Yzl3uyl1TVyG9xtcDRgcQf75+hBi5aT
N9GCYv2eKH821kkLXC3t3pP3UD/CULmZD7EgZxcKf5Vpm+K20SpkikRMCxAn
phkJLZG6V2yii2juvfcNW54pxylWruGmf7rExg4dVQwV0MjS9vfWtmrsj8Ri
pJhsSH+Np2R5sL0SuQxpuGBlYkelQkSSLPTZuNjLmC+t6XjerOh5tFaInq35
JCD7g8yncSVFgyMJMTBhaynDSinXQS59LiJKBk76n5M2ipSrFNUrBEBFQ14W
GjZMB8D+r/+MV1hZyet3iI6+Y6JhSjPEXgDj1ux6wpkck7WxcE89WrKC2CI/
GOmKo1AXhQFFiqpkljJBvo38EFe/MRTk/vfUvanAyr3hGC2OlpYZEZ3GaVIE
5+pQplfEJmaFq9Ar4zgKE8FuveFhAMPlRjRskUwyBJosc4GgAEm5G5rUEKVJ
NeH4l9wfhf0y0UAcepxZK9Sfmu552zi4Qs4Aq1m5bqtvX1/dHg7Z5for1r8y
sUm1jMxljgA1ORByoczu/P31e8JBTURn+BGxo7yMDApkkUT25yxNz8xlemYO
jGfP8kAW3Xscq+MorSd+kzNWLCKc3P12c8hJZAiKR4V/5wJmHglhiKXrYi+Z
pExmGy6kqTGtm2Fdhm68GhpphHF/mFyYGaYDjotcOQ15H/nyDZNcqTx/4Ly5
Xfr8nHenbjx8b1/Em6WtzECdB7LR5AQjXVPDHapNQiiOG8nxkOn2ToZH6Dhc
fpHGTRe5QBpbX+QCJvI3ERtzII5oU64VuyB8CVJWmjhCcZEokAP0n0X1U8nG
XQl8PiTc7i0iZCvVKd11DnnM4wEEey54YTqoiICDwFg6CLF3mUMMYBpNoVds
O/plYVvVxtNN5AWyXu6Ld7GfTonVhU9jM2hEciO5ymycQNiCqdPyIAW1CR93
QEnxmBlH0lM8Ga5J8Xk7Cj4XCwJGRjYrDq/TDdwO3tRyeLL0DFPcBGC+co4V
o+7RQKkx5e9bQK3axqYtXMRUnxi9eY4yNFi4y8A9mrLMi/a51kjplA1CWjh+
MuOYHsDu0hYtyA5JaOUYYvIUrPTd4uk54DdycEhZVSKkGYvT+RIlDA+A5Ao+
t04j/I4jNaLNMr1OpnQnwzBjgyONasw4aqe0isOVtcYiSq8MMBxVDM96eEJT
IfssM3bpywLhkqgbL1+hiETFwaAPNnbRF7gcmTSU4hAm01xYCWEAiUyGYcfp
IBZZ6sPTqF78YkDKONNhWx4uvrq+OoFaSulteMZSnoxQinic1RCxBbehoDRS
75oHHxlSnSg2ppWMNEnMOEjHNIym7+HMclbvvYqDP3MZ/DG1zMjEMeklDLlk
OXHTV58ZzK0BLctpnlep75YuSNgHL33W4ZPtacpspotvuDT7Gc+C5YJEJh9t
RLWRoCgmlS95sCeikpAzAgUm065T0xpALlPUuMK/X1990I95boO+S/PlS27z
S0E4tBG7mlC2TOepirVU+XH+GRv1POl6Edsz/MujIofEcbCjJgePNlFOF4Ip
TArl2IfnxeLsX+aYytrgPYlcP1s80bfMUr36LJePV6TvCMUrXsk2c5uekDJ8
nI7Mci+oPWYwKGkIWqYIyv0K/vKDTktd6snXDAoGj5RTMgWwAPLdXrCZHyit
iBCI1zkcjRfTCPrx1kAEHlpgqS0BmgZYNbcsp+orWO4odmC5QBK8AzK/nJCv
Yo0hfoZ0MvTSX2hZxluf4NLHD399Mw/9vrEH42pjMIH4RODPRoGX04/SmEyj
8pEfH9++LL56VS5adoblLH8/HIwfu9sRFeTR+YLV7ehbaAQ94mdzppVoWJop
wuIrTzSvgF0Fe0+S0Mkvh9Fl0ruPQqJlw2ixJNHpl7PE7FKnNhndItJUmV07
+gYAwRT+TkXO6t1+Fmu17c5S/MEmny3zyfqq+tT6+8bWa5ls++OiHbZLalr8
y9nKNMGefTmMulQs+FZG5bjqQN6cdNNOjEdGCkFxL6DDccdv0TlOxfxFDvF1
msOYj2pbwbr7hAZ52hvPuS3Px6MMR6z6f9KUZK/iOQAA

-->

</rfc>

