<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.2.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-gilda-wimse-agent-audit-record-01" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Agent Audit Record">An Audit Record Format for AI Agent Authorization Decisions</title>
    <seriesInfo name="Internet-Draft" value="draft-gilda-wimse-agent-audit-record-01"/>
    <author fullname="Sankalp Gilda">
      <address>
        <email>sankalp.gilda@gmail.com</email>
      </address>
    </author>
    <date year="2026" month="September" day="25"/>
    <area>Applications and Real-Time</area>
    <workgroup>Workload Identity in Multi System Environments</workgroup>
    <keyword>audit</keyword>
    <keyword>agent</keyword>
    <keyword>attestation</keyword>
    <keyword>tamper-evident</keyword>
    <abstract>

<t>This document defines a record format for AI agent authorization decisions. The format is one in-toto predicate type, signed inside a DSSE envelope. It carries the seven minimum audit fields that the WIMSE AI Identity Management System framework requires, and two properties that make those fields checkable: a canonicalization contract, and both the authorization decision and the observed effect with a derived three-valued agreement between them. That framework places the record format out of scope and takes no IANA action. This document supplies the format. It defines no policy.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-gilda-wimse-agent-audit-record/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Workload Identity in Multi System Environments Working Group mailing list (<eref target="mailto:wimse@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/wimse/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/wimse/"/>.
      </t>
    </note>
  </front>
  <middle>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This document defines one record format for the audit events that Section 11 of <xref target="AIMS"/> requires, and it defines nothing else. It specifies no policy model, no compliance criteria and no retention rule, and it does not extend or amend <xref target="AIMS"/>.</t>
      <t>The goals are:</t>
      <ul spacing="normal">
        <li>
          <t>to make an audit record from one deployment comparable with one from another;</t>
        </li>
        <li>
          <t>to make "tamper-evident" a property a verifier can test on the bytes it holds;</t>
        </li>
        <li>
          <t>to carry the authorization decision and the observed effect in one signed record, so a disagreement between them is detectable;</t>
        </li>
        <li>
          <t>to give the seven minimum fields of Section 11 of <xref target="AIMS"/> one member each.</t>
        </li>
      </ul>
      <t>Policy belongs to a deployment, and a record format belongs to everyone who has to read the record. Two implementations that each satisfy Section 11 in their own format produce audit trails that cannot be compared, correlated across a service boundary, or checked by a party that trusts neither producer. Section 11 asks for all three.</t>
      <t>Comparable has a narrow meaning here. Two records are comparable when a third party holding both can decide, from the bytes alone, whether they describe the same request, whether their decisions agree, and whether either was enforced.</t>
      <t>The consequence is concrete: two deployments that each hash a request differently cannot join their records on a request digest, so a delegation that crossed between them is reconstructable in neither log.</t>
      <t>Section 11 of <xref target="AIMS"/> is normative about the existence of agent audit records and silent about their form. It requires that "deployments <bcp14>MUST</bcp14> produce durable audit logs covering authorization decisions and subsequent remediations", that "Audit records <bcp14>MUST</bcp14> be tamper-evident and retained according to the security policy of the deployment", and that audit events record seven minimum fields.</t>
      <t>Section 12 then places the policy model and document format out of scope, stating that they are "not recommended as a target for standardization within this specification". Section 13 places compliance criteria out of scope, and Section 16 records no IANA actions. <xref target="rationale"/> sets out the canonicalization contract and the reason the decision and the observed effect belong in one record.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>

</section>
    <section anchor="terminology">
      <name>Terminology</name>
      <t>The following terms are used throughout this document. Two of them, <em>observer</em> and <em>decision point</em>, are defined here; the rest are taken from the documents named beside them.</t>
      <dl>
        <dt>Agent, Tool, Service, Resource, LLM:</dt>
        <dd>
          <t>as <xref target="AIMS"/> uses them.</t>
        </dd>
        <dt>Agent identifier:</dt>
        <dd>
          <t>a WIMSE identifier as defined in <xref target="WIMSE-ID"/>.</t>
        </dd>
        <dt>Statement, subject, predicate:</dt>
        <dd>
          <t>as <xref target="IN-TOTO"/> uses them.</t>
        </dd>
        <dt>Observer:</dt>
        <dd>
          <t>the party that produces a record under this document. An observer watches from a layer the agent cannot address. A host-side view of a guest filesystem, a hypervisor-level read of guest state, and kernel-level supervision below the observed process are such layers. An in-process library, a wrapper the agent links, and an importer holding another party's log are not.</t>
        </dd>
        <dt>Decision point:</dt>
        <dd>
          <t>the party that evaluated the authorization request, whatever its architecture.</t>
        </dd>
        <dt>Interval:</dt>
        <dd>
          <t>the period between the before-state and the after-state that one record covers.</t>
        </dd>
        <dt>Tier:</dt>
        <dd>
          <t>the degree to which a record's own members corroborate what it claims about how it was observed. A verifier derives the tier under the rule in <xref target="observation"/> and never reads it from the record.</t>
        </dd>
      </dl>
      <t>Every digest in this document is written as lowercase hexadecimal in the algorithm the record declares in its <tt>hashAlgorithm</tt> member.</t>
    </section>
    <section anchor="audit-record-specification">
      <name>Audit Record Specification</name>
      <t>A record is an in-toto Statement <xref target="IN-TOTO"/> carried in a DSSE envelope <xref target="DSSE"/>. Its <tt>predicateType</tt> is</t>
      <artwork><![CDATA[
=========== NOTE: "\" line wrapping per RFC 8792 ============

https://probityai.github.io/agent-evidence-vectors/predicate/v1/\
agent-audit-record
]]></artwork>
      <t>Sixteen predicate members are defined in <xref target="members"/>. Each of the sixteen is required unless a rule in that section makes it conditional, no member has a default, and a verifier <bcp14>MUST NOT</bcp14> supply one for an absent member (vector <tt>F1</tt>). Two members are conditional on a sibling value, <tt>resource.argumentsDigest</tt> and <tt>correlation.externalAnchor</tt>, and each is specified where it is defined.</t>
      <t>A verifier <bcp14>MUST</bcp14> reject a value outside any closed vocabulary this document defines, and <bcp14>MUST NOT</bcp14> ignore the member (vector <tt>V1</tt>). The closed vocabularies reuse terms registered in <xref target="VOCABULARY"/>.</t>
      <section anchor="canonical">
        <name>Canonical form</name>
        <t>Two implementations derive the same bytes from the same Statement only if they agree on the serialization and on what makes a Statement malformed. Both are fixed below.</t>
        <section anchor="json-profile">
          <name>JSON profile</name>
          <t>Producers and verifiers <bcp14>MUST</bcp14> canonicalize the Statement with <xref target="RFC8785"/>, and the signature covers those bytes and no other serialization (vector <tt>T2</tt>). Producers and verifiers <bcp14>MUST</bcp14> enforce the <xref target="RFC7493"/> I-JSON safe-integer profile: an integer of magnitude at or above 2^53 makes the Statement malformed (vector <tt>T5</tt>).</t>
        </section>
        <section anchor="duplicate-members-and-nesting-depth">
          <name>Duplicate members and nesting depth</name>
          <t>A member name repeated at any depth makes the Statement malformed. A verifier <bcp14>MUST</bcp14> reject such a Statement and <bcp14>MUST NOT</bcp14> retain any one occurrence (vector <tt>T3</tt>). A Statement nested deeper than 128 levels <bcp14>MUST</bcp14> be rejected (vector <tt>T4</tt>).</t>
        </section>
      </section>
      <section anchor="subject">
        <name>Subject convention</name>
        <t>A record carries two subject entries. The first is the request, by digest: its <tt>name</tt> is the correlation identifier and its <tt>sha256</tt> digest is the request digest defined in <xref target="members"/>. The second is the after-state root of the interval the predicate carries, and its <tt>name</tt> is the first entry's <tt>name</tt> with the suffix <tt>/after</tt>.</t>
        <sourcecode type="json"><![CDATA[
"subject": [
  { "name": "urn:example:corr:7f3a",
    "digest": { "sha256": "9f86d081884c7d659a2feaa0c55ad015..." } },
  { "name": "urn:example:corr:7f3a/after",
    "digest": { "sha256": "60303ae22b998861bce3b28f33eec1be..." } }
]
]]></sourcecode>
        <t>A verifier <bcp14>MUST</bcp14> bind on the <tt>digest</tt> map and <bcp14>MUST NOT</bcp14> bind on either <tt>name</tt>. A name is a correlation identifier a producer chooses; a digest is a value a verifier recomputes from the bytes it holds. The names exist so that a reader can tell the two entries apart.</t>
        <t>The second entry <bcp14>MUST</bcp14> be present if and only if the predicate carries an interval (vectors <tt>S1</tt> and <tt>I1r</tt>), and its digest <bcp14>MUST</bcp14> equal the interval's after-state root (vector <tt>S2</tt>).</t>
        <t>A decision that permitted nothing, and a decision that was denied, still carry an interval whose before-state and after-state roots are equal and whose write set is empty (vector <tt>A2</tt>). A consumer therefore reads an absence of effect from the members of a record it holds, and never from a record it does not have.</t>
      </section>
      <section anchor="timestamps">
        <name>Timestamps and correlation</name>
        <t>Every time value in a record <bcp14>MUST</bcp14> be an <xref target="RFC3339"/> date-time. A producer <bcp14>SHOULD</bcp14> express it in UTC with the "Z" offset, so that two records from different deployments sort together without a conversion step. The correlation identifier is the first subject entry's <tt>name</tt>, so one identifier binds the request digest, the interval and the record.</t>
      </section>
      <section anchor="tamper">
        <name>Tamper-evidence</name>
        <t>A record satisfies the tamper-evidence requirement of Section 11 of <xref target="AIMS"/> when all three of the following hold.</t>
        <t>The DSSE pre-authentication encoding covers the <xref target="RFC8785"/> canonical bytes of the whole Statement, and every one of the seven minimum fields is inside that pre-image.</t>
        <artwork><![CDATA[
DSSE PAE = "DSSEv1" SP len("application/vnd.in-toto+json") SP
           "application/vnd.in-toto+json" SP
           len(JCS(statement)) SP JCS(statement)
]]></artwork>
        <t>The request digest, the ordered write chain of the effect, and both <tt>agreement</tt> values are recomputable from other members of the same record. A verifier therefore still refuses a record that the key holder altered and signed again (vector <tt>T1</tt>).</t>
        <t>The canonical form is fixed as in <xref target="canonical"/>, so two verifiers derive identical bytes from identical documents. Any one of the three failing is a refusal.</t>
        <t>This document does not address the retention half of the Section 11 requirement. Retention is a property of a deployment, and a record cannot assert it about itself. A record under this document <bcp14>SHOULD</bcp14> state that in its <tt>doesNotAssert</tt> member, so that a reader need not infer coverage.</t>
      </section>
      <section anchor="mapping">
        <name>Mapping to the seven minimum fields</name>
        <table>
          <name>The seven minimum fields of Section 11 and the members that carry them</name>
          <thead>
            <tr>
              <th align="left">Section 11 field</th>
              <th align="left">Members</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">authenticated agent identifier</td>
              <td align="left">
                <tt>agent.id</tt>, <tt>agent.credentialDigest</tt>, <tt>agent.authentication</tt>, <tt>agent.signers</tt></td>
            </tr>
            <tr>
              <td align="left">delegated subject, when present</td>
              <td align="left">
                <tt>delegation.subject</tt>, <tt>delegation.subjectKind</tt>, <tt>delegation.authorityDigest</tt></td>
            </tr>
            <tr>
              <td align="left">resource or tool being accessed</td>
              <td align="left">
                <tt>resource.kind</tt>, <tt>resource.id</tt>, <tt>resource.binding</tt>, <tt>resource.argumentsDigest</tt></td>
            </tr>
            <tr>
              <td align="left">action requested and authorization decision</td>
              <td align="left">
                <tt>decision</tt> and <tt>effect</tt>, with the derived <tt>agreement</tt></td>
            </tr>
            <tr>
              <td align="left">timestamp and correlation identifier</td>
              <td align="left">
                <tt>correlation</tt> and the interval timestamps</td>
            </tr>
            <tr>
              <td align="left">posture assessment or risk state</td>
              <td align="left">
                <tt>posture</tt>, carrying both vantages and <tt>assessedAt</tt></td>
            </tr>
            <tr>
              <td align="left">remediation or revocation events and cause</td>
              <td align="left">
                <tt>remediation</tt></td>
            </tr>
          </tbody>
        </table>
        <t>Each field also carries an evidence partition in <tt>fieldEvidence</tt>, stating whether the observing substrate covered the value or the producer asserted it. All seven fields can be recorded by an agent about itself. A record that says which ones were is checkable; a record that does not say is not.</t>
        <t>The fourth field pairs an action with a decision, and this format carries <tt>decision</tt>, <tt>effect</tt> and the derived <tt>agreement</tt> together. A record whose decision and effect disagree is well formed, and the disagreement is visible in signed bytes:</t>
        <sourcecode type="json"><![CDATA[
"decision": { "action": "write", "reported": "deny" },
"effect":   {
  "observed": "occurred",
  "writes": [ { "path": "/srv/ledger/settlements.jsonl" } ]
},
"agreement": "disagree"
]]></sourcecode>
        <t>A log that carries the decision alone records that case as a clean denial, because it has no other value to disagree with.</t>
      </section>
      <section anchor="verifying">
        <name>Verifying a record</name>
        <t>A verifier holds a DSSE envelope and reaches a verdict from the bytes inside it. The checks below are the ones this document has already stated, in the order a verifier can apply them without reading a member twice.</t>
        <t>The envelope's signature comes first, over the <xref target="RFC8785"/> canonical bytes of the whole Statement. A statement whose signature does not verify is malformed, and nothing further is read from it. A verifier scored against <xref target="vectors"/> reports it as malformed (vector <tt>T2</tt>).</t>
        <t>The JSON profile comes second: the safe-integer bound of <xref target="RFC7493"/>, no member name repeated at any depth, and no nesting past 128 levels. Each of the three makes a Statement malformed, so a verifier that finds one of them has nothing further to check.</t>
        <t>Membership comes third. Every one of the sixteen members is present unless a rule in <xref target="members"/> makes it conditional on a sibling value, and every value sits inside the closed vocabulary its member declares.</t>
        <t>The recomputes come last, and a signature cannot supply them. The three that <xref target="tamper"/> requires come first: a verifier derives the request digest from the four members <xref target="members"/> names and compares it with the first subject entry, it replays the write chain from the before-state root and compares the result with the second subject entry, and it derives both agreement values from the members they are functions of.</t>
        <t>A fourth recompute binds the prior commitment rather than the record's content. A verifier recomputes the commitment digest, checks that the commitment precedes the interval, and checks that the commitment key is absent from <tt>agent.signers</tt>.</t>
        <t>The tier follows from those results. A verifier reads the five clauses of <xref target="observation"/> against the members it has just checked and assigns <tt>authoritative</tt> or <tt>voluntary</tt> itself.</t>
        <t>This document requires no particular order and no particular reporting shape. A verifier that stops at the first failure and a verifier that reports every failure are both conformant.</t>
      </section>
    </section>
    <section anchor="members">
      <name>Predicate members</name>
      <sourcecode type="json"><![CDATA[
{
  "recordId": "...",
  "tier": "authoritative",
  "hashAlgorithm": "sha256",
  "agent": {
    "id": "spiffe://prod.example.org/ns/payments/sa/reconciler",
    "credentialDigest": "...",
    "authentication": "wimse-wpt",
    "signers": ["..."]
  },
  "delegation": {
    "subject": "user:alice@example.org",
    "subjectKind": "user",
    "authorityDigest": "..."
  },
  "resource": {
    "kind": "tool",
    "id": "mcp://files/write",
    "binding": "digest-bound",
    "argumentsDigest": "..."
  },
  "decision": {
    "action": "write",
    "requestDigest": "...",
    "reported": "deny",
    "decisionPointId": "pdp://prod.example.org/authz-1",
    "policyDigest": "...",
    "reportedAt": "2026-09-19T11:04:02Z"
  },
  "effect": {
    "observed": "occurred",
    "interval": {
      "beforeRoot": "...",
      "afterRoot": "...",
      "baseResolution": "supplied",
      "openedAt": "2026-09-19T11:04:01Z",
      "sealedAt": "2026-09-19T11:04:06Z"
    },
    "pathScope": ["/srv/ledger/"],
    "writes": [
      {
        "path": "/srv/ledger/settlements.jsonl",
        "preStateDigest": "...",
        "postStateDigest": "...",
        "requestDigest": "...",
        "inScope": true
      }
    ]
  },
  "agreement": "disagree",
  "correlation": {
    "id": "req:7f3a91c4",
    "scope": "cross-party",
    "timeBasis": "beacon-anchored",
    "externalAnchor": { "kind": "rfc3161", "digest": "..." }
  },
  "posture": {
    "reported": "sinkhole",
    "reportedDigest": "...",
    "observed": "allowlist",
    "observedDigest": "...",
    "assessedAt": "2026-09-19T06:00:00Z",
    "agreement": "disagree"
  },
  "remediation": [
    {
      "cause": "session-revoked",
      "signalReceivedAt": "2026-09-19T11:04:07Z",
      "enforcedAt": "2026-09-19T11:04:09Z",
      "enforcement": "session-terminated",
      "postEnforcementEffect": "none",
      "postEnforcementRoot": "..."
    }
  ],
  "observation": {
    "vantage": "below-observed",
    "coverage": { "scopeComplete": true, "gaps": [] },
    "priorCommitment": {
      "committedAt": "2026-09-19T11:03:58Z",
      "witnessNonce": "...",
      "commitmentDigest": "...",
      "keyid": "...",
      "sig": "..."
    }
  },
  "fieldEvidence": {
    "agent": "producer-asserted",
    "correlation": "producer-asserted",
    "decision": "producer-asserted",
    "delegation": "producer-asserted",
    "posture": "substrate-covered",
    "remediation": "substrate-covered",
    "resource": "substrate-covered"
  },
  "doesNotAssert": ["..."],
  "issuedAt": "2026-09-19T11:04:11Z"
}
]]></sourcecode>
      <section anchor="hashalg">
        <name>Record identity and hash algorithm</name>
        <t><tt>recordId</tt> is the producer's identifier for this record. It is opaque to a verifier except where the commitment digest is recomputed, which reads it as one of its four inputs.</t>
        <t><tt>hashAlgorithm</tt> names the algorithm every digest in the record is taken under. One value governs the whole record: the subject digests, the credential, authority, policy and posture digests, the interval roots, the write pre-state and post-state digests, and the commitment digest are all taken under it.</t>
        <t>A record carrying digests in two algorithms is therefore not representable, and that is the point. A verifier comparing two roots has to know they were taken under the same algorithm, and a per-member choice would let a producer choose which comparison a reader could make.</t>
        <t><tt>issuedAt</tt> is the time the producer sealed the record, and it is at or after the interval's <tt>sealedAt</tt> because the record cannot be issued before the interval it describes has closed.</t>
        <t>A verifier that does not implement the declared algorithm cannot recompute anything the record binds. It has no verdict to reach on such a record, and reporting that it could not read one is the honest outcome rather than a refusal on the record's content.</t>
      </section>
      <section anchor="identity-delegation-and-resource">
        <name>Identity, delegation and resource</name>
        <t><tt>agent.id</tt> carries the WIMSE identifier verbatim, and <tt>agent.credentialDigest</tt> the digest of the credential the identifier was read from. <tt>agent.authentication</tt> is the mechanism, over the closed set <tt>wimse-wpt</tt>, <tt>http-message-signature</tt>, <tt>mtls</tt>, <tt>oauth-access-token</tt>, <tt>none</tt>, drawn from Section 9 of <xref target="AIMS"/>. <tt>agent.signers</tt> is the set of key identifiers the agent signs its own records with, as the observer knows them, and it <bcp14>MAY</bcp14> be empty.</t>
        <t><tt>delegation.subjectKind</tt> is one of <tt>user</tt>, <tt>system</tt>, <tt>none</tt>. Field 2 of Section 11 is the only conditional one, so an absent delegated subject is conformant and is spelled <tt>subjectKind</tt> of <tt>none</tt> beside a <tt>subject</tt> of the literal <tt>none</tt>.</t>
        <t>A <tt>subjectKind</tt> of <tt>none</tt> beside any other subject value is malformed and a verifier <bcp14>MUST NOT</bcp14> prefer either member (vector <tt>F2</tt>). <tt>delegation.authorityDigest</tt> is required unconditionally, and a decision taken under no authority carries the digest of the explicit deny-all document.</t>
        <t><tt>resource.kind</tt> is one of <tt>path</tt>, <tt>uri</tt>, <tt>tool</tt>, the three shapes the single category of external endpoints in Section 4 of <xref target="AIMS"/> takes. <tt>resource.binding</tt> of <tt>digest-bound</tt> <bcp14>MUST</bcp14> carry <tt>argumentsDigest</tt>, and <tt>not-bindable</tt> <bcp14>MUST NOT</bcp14> carry it in any spelling, including <tt>null</tt> and the empty string (vectors <tt>F3</tt>, <tt>F3b</tt> and <tt>F3c</tt>).</t>
        <t>Where a decision point can canonicalize the arguments of a call, it <bcp14>SHOULD</bcp14> bind them by digest. A tool call whose arguments it cannot canonicalize has nothing to bind, so that call is representable and it cannot reach the strongest tier.</t>
      </section>
      <section anchor="decision-effect-and-agreement">
        <name>Decision, effect and agreement</name>
        <t><tt>decision.reported</tt> is one of <tt>permit</tt>, <tt>deny</tt>, <tt>permit-with-conditions</tt>. <tt>decision.requestDigest</tt> <bcp14>MUST</bcp14> equal the first subject entry's sha256 digest and <bcp14>MUST</bcp14> equal the <xref target="RFC8785"/> digest over the members <tt>action</tt>, <tt>argumentsDigest</tt>, <tt>resourceId</tt> and <tt>resourceKind</tt> (vector <tt>F4</tt>). The hashed object holds <tt>argumentsDigest</tt> exactly when <tt>resource.binding</tt> is <tt>digest-bound</tt>. Under <tt>not-bindable</tt> it holds the other three members and no <tt>argumentsDigest</tt> member at all, so every conforming implementation derives one digest for a given request (vector <tt>A6</tt>). Altering the action, the resource or the arguments after signing therefore breaks a recompute even where the signature was applied again.</t>
        <t>Each write carries <tt>requestDigest</tt>: the request digest of the request the observer attributes the write to, or the literal <tt>unattributed</tt> where the observer cannot attribute it. An attribution is an observation, and an observer that cannot tie a write to a request says so rather than guessing.</t>
        <t><tt>effect.observed</tt> describes this record's request, not the whole interval, and it is one of <tt>occurred</tt>, <tt>none</tt>, <tt>unknown</tt>. It <bcp14>MUST</bcp14> be derivable from the write set: <tt>occurred</tt> when at least one write is attributed to <tt>decision.requestDigest</tt>; <tt>none</tt> when no write is attributed to it and no <tt>unattributed</tt> write lies inside <tt>pathScope</tt>; and <tt>unknown</tt> otherwise. A write attributed to a different request belongs to that request's record and does not enter this one's value (vectors <tt>A7</tt> and <tt>T1</tt>). A value of <tt>none</tt> beside an empty write set requires the before-state and after-state roots to be equal (vector <tt>E1</tt>).</t>
        <t>The ordered write chain <bcp14>MUST</bcp14> reproduce the after-state root from the before-state root (vector <tt>E2</tt>). A <tt>baseResolution</tt> of <tt>empty-tree</tt> <bcp14>MUST</bcp14> carry the empty-tree constant for the declared hash algorithm (vector <tt>E3</tt>).</t>
        <t>A member of <tt>pathScope</tt> <bcp14>MUST NOT</bcp14> contain a glob metacharacter, and a universal scope is the single literal <tt>/</tt> (vector <tt>V2</tt>). A write outside <tt>pathScope</tt> <bcp14>MUST</bcp14> carry <tt>inScope</tt> of <tt>false</tt>, which is derived from the path and never a producer opinion (vector <tt>V3</tt>).</t>
        <t><tt>agreement</tt> is one of <tt>agree</tt>, <tt>disagree</tt>, <tt>not-exercised</tt>, <tt>indeterminate</tt>, <tt>one-sided</tt>, and it <bcp14>MUST</bcp14> be derivable from <tt>decision.reported</tt> and <tt>effect.observed</tt> by the table below (vectors <tt>D1</tt>, <tt>D2</tt> and <tt>D3</tt>). <tt>posture.agreement</tt> <bcp14>MUST</bcp14> be derivable from the two carried postures on the same terms: <tt>agree</tt> when they are equal byte for byte, <tt>disagree</tt> when both are present and unequal (vector <tt>F6</tt>).</t>
        <table>
          <name>Deriving agreement from the reported decision and the observed effect</name>
          <thead>
            <tr>
              <th align="left">decision.reported</th>
              <th align="left">effect.observed</th>
              <th align="left">agreement</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <tt>permit</tt> or <tt>permit-with-conditions</tt></td>
              <td align="left">
                <tt>occurred</tt></td>
              <td align="left">
                <tt>agree</tt></td>
            </tr>
            <tr>
              <td align="left">
                <tt>deny</tt></td>
              <td align="left">
                <tt>none</tt></td>
              <td align="left">
                <tt>agree</tt></td>
            </tr>
            <tr>
              <td align="left">
                <tt>deny</tt></td>
              <td align="left">
                <tt>occurred</tt></td>
              <td align="left">
                <tt>disagree</tt></td>
            </tr>
            <tr>
              <td align="left">
                <tt>permit</tt> or <tt>permit-with-conditions</tt></td>
              <td align="left">
                <tt>none</tt></td>
              <td align="left">
                <tt>not-exercised</tt></td>
            </tr>
            <tr>
              <td align="left">any</td>
              <td align="left">
                <tt>unknown</tt></td>
              <td align="left">
                <tt>indeterminate</tt></td>
            </tr>
          </tbody>
        </table>
        <t>A permit allows an action and does not require it, so a permitted call that failed or was never made is <tt>not-exercised</tt>, and a deny that leaked is <tt>disagree</tt>. The two are different facts and an incident review needs to tell them apart (vector <tt>A9</tt>). An unattributed write inside <tt>pathScope</tt> leaves the observer unable to rule the request's effect in or out, so the record says <tt>indeterminate</tt> rather than choosing (vector <tt>A8</tt>).</t>
        <t>The table never produces <tt>one-sided</tt>. <tt>one-sided</tt> is in the closed set and this version never produces it, because <tt>decision</tt> and <tt>effect</tt> are both required and neither side can be absent. It is reserved so that a version admitting a record with one side missing does not have to change a closed vocabulary, and a record carrying it under this version is malformed (vector <tt>D2</tt>).</t>
        <t>A verifier <bcp14>MUST NOT</bcp14> reject a record because either agreement value is <tt>disagree</tt>, <tt>not-exercised</tt> or <tt>indeterminate</tt> (vectors <tt>A3</tt>, <tt>A8</tt> and <tt>A9</tt>). A disagreement is the record working, and what it means for admission is a consumer policy decision.</t>
      </section>
      <section anchor="correlation-posture-and-remediation">
        <name>Correlation, posture and remediation</name>
        <t><tt>correlation.scope</tt> is one of <tt>producer</tt>, <tt>cross-party</tt>, and it is required because Section 11 asks systems to "correlate events across Agents, Tools, Services, Resources and LLMs", which a producer-scoped identifier cannot do. A record a producer distributes beyond its own deployment <bcp14>SHOULD</bcp14> carry a scope of <tt>cross-party</tt>.</t>
        <t><tt>correlation.timeBasis</tt> of <tt>beacon-anchored</tt> <bcp14>MUST</bcp14> carry <tt>externalAnchor</tt>, and <tt>asserted</tt> <bcp14>MUST NOT</bcp14> carry it (vector <tt>F5</tt>). <tt>externalAnchor.kind</tt> is one of <tt>rfc3161</tt>, <tt>transparency-log</tt>, <tt>opentimestamps</tt>, of which <xref target="RFC3161"/> and <xref target="RFC9162"/> define the first two. No offline validation rule for an anchor token is defined here, and vector <tt>N1</tt> records both readings a conforming verifier can reach.</t>
        <t><tt>posture.reported</tt> and <tt>posture.observed</tt> are over the closed set <tt>no_network</tt>, <tt>allowlist</tt>, <tt>sinkhole</tt>, <tt>unsafe_bypass_egress</tt>, each with a digest pinning the posture document. <tt>posture.assessedAt</tt> carries the time the assessment was made, which <xref target="rationale"/> gives the reason for. A consumer weighing either posture <bcp14>SHOULD</bcp14> read <tt>assessedAt</tt> beside it.</t>
        <t><tt>remediation</tt> carries one member per event. Its <tt>cause</tt> is one of <tt>session-revoked</tt>, <tt>risk-elevated</tt>, <tt>subject-disabled</tt>, <tt>token-replay-suspected</tt>, <tt>policy-changed</tt>, <tt>operator-action</tt>. Its <tt>enforcement</tt> is one of <tt>access-attenuated</tt>, <tt>session-terminated</tt>, <tt>tokens-discarded</tt>, <tt>privileges-reduced</tt>, <tt>reevaluated</tt>, <tt>not-enforced</tt>. In each member <tt>enforcedAt</tt> <bcp14>MUST</bcp14> be at or after <tt>signalReceivedAt</tt> (vector <tt>F7</tt>).</t>
        <t>A verifier <bcp14>MUST NOT</bcp14> reject a record because <tt>enforcement</tt> is <tt>not-enforced</tt> (vector <tt>A4</tt>). A record carries that value when a remediation signal arrived and enforcement did not follow it.</t>
        <t><tt>postEnforcementEffect</tt> and <tt>postEnforcementRoot</tt> make the Section 11 delay requirement checkable by a third party. A revocation that arrived, was recorded, and was followed by an observed effect is a recorded enforcement failure. This document defines no bound on the delay, because Section 11 carries no unit for "undue", and vector <tt>N2</tt> records that case as indeterminate.</t>
      </section>
      <section anchor="observation">
        <name>Observation and tier</name>
        <t><tt>observation.vantage</tt> is one of <tt>below-observed</tt>, <tt>peer</tt>, <tt>self</tt>. An observer that could not read part of <tt>pathScope</tt> <bcp14>SHOULD</bcp14> name that path in <tt>coverage.gaps</tt>, because the tier recompute below reads the gap list and not the observer's confidence. <tt>observation.priorCommitment</tt> is the observer's commitment, made before the interval opened, to the before-state and to a nonce the observer chose.</t>
        <t>Its <tt>committedAt</tt> <bcp14>MUST</bcp14> be strictly before the interval's <tt>openedAt</tt> (vector <tt>C2</tt>). Its <tt>commitmentDigest</tt> <bcp14>MUST</bcp14> recompute as the <xref target="RFC8785"/> digest over <tt>authorityDigest</tt>, <tt>beforeRoot</tt>, <tt>recordId</tt> and <tt>witnessNonce</tt> (vector <tt>C3</tt>). Its <tt>keyid</tt> <bcp14>MUST NOT</bcp14> appear in <tt>agent.signers</tt> (vector <tt>C1</tt>), and that disjointness is the one byte-pure discriminator between an observer and a self-observing party.</t>
        <t><tt>doesNotAssert</tt> is the negative-scope member the sections above refer to: an array of explicit statements about what this record does not claim. A record under this version <bcp14>SHOULD</bcp14> carry two entries. The first entry records that it makes no claim about retention. The second records that it makes no claim that the reported decision is the decision the policy engine evaluated.</t>
        <t><tt>fieldEvidence</tt> carries exactly the seven keys named in the mapping table, each one of <tt>substrate-covered</tt> or <tt>producer-asserted</tt>. Both terms are reused unchanged from the field-evidence partition registered in <xref target="VOCABULARY"/>, as the four posture values above are reused from its containment-posture terms. A missing key is malformed (vector <tt>FE1</tt>), and no key may declare <tt>substrate-covered</tt> while <tt>vantage</tt> is <tt>self</tt> (vector <tt>FE2</tt>).</t>
        <t><tt>tier</tt> is one of <tt>voluntary</tt>, <tt>authoritative</tt>. A verifier <bcp14>MUST</bcp14> recompute it and <bcp14>MUST NOT</bcp14> take the declared value as the tier. Vectors <tt>TI1</tt> through <tt>TI5</tt> each declare <tt>authoritative</tt> while failing one clause, so a verifier that reads the declared value passes all five.</t>
        <t>A record is <tt>authoritative</tt> if and only if all five of these hold, and <tt>voluntary</tt> otherwise: <tt>vantage</tt> is <tt>below-observed</tt> (vector <tt>TI1</tt>); <tt>priorCommitment</tt> is present and complete (vector <tt>TI2</tt>); <tt>pathScope</tt> is non-empty (vector <tt>TI3</tt>); <tt>coverage.scopeComplete</tt> is true or every gap names a path outside <tt>pathScope</tt> (vector <tt>TI4</tt>); and <tt>resource.binding</tt> is <tt>digest-bound</tt> (vector <tt>TI5</tt>).</t>
        <t>A record declaring <tt>authoritative</tt> that fails a clause is malformed, and a verifier <bcp14>MUST NOT</bcp14> downgrade it to <tt>voluntary</tt> (vector <tt>TI1</tt>). Downgrading would let a producer emit an authoritative-shaped record and rely on the verifier to relabel it.</t>
        <t>The opposite mismatch is well formed. A record declaring <tt>voluntary</tt> while meeting all five clauses is not malformed, and a verifier reads it at the tier the recompute gives. Treating the two directions differently is deliberate: a producer that over-claims is relying on somebody else to correct it, and a producer that under-claims is not.</t>
        <t>A verifier <bcp14>MUST NOT</bcp14> read a <tt>voluntary</tt> record as evidence that its content corresponds to any independently observed fact (vector <tt>A5</tt>).</t>
      </section>
      <section anchor="worked">
        <name>A worked reading of the example</name>
        <t>The record at the head of <xref target="members"/> reports a write that was denied and happened anyway. Each rule above lands on one of its members.</t>
        <t><tt>decision.reported</tt> is <tt>deny</tt>, and the single write is attributed to the record's own request, so <tt>effect.observed</tt> derives as <tt>occurred</tt>. The third row of the agreement table maps that pair to <tt>disagree</tt>, which is the value the record carries, so the derivation holds and vector <tt>D1</tt> does not apply.</t>
        <t><tt>posture.reported</tt> is <tt>sinkhole</tt> and <tt>posture.observed</tt> is <tt>allowlist</tt>. Both are present and they are unequal, so <tt>posture.agreement</tt> derives as <tt>disagree</tt>, which is again the carried value.</t>
        <t>The tier recompute passes all five clauses. <tt>vantage</tt> is <tt>below-observed</tt>; <tt>priorCommitment</tt> carries all five of its own members; <tt>pathScope</tt> holds one entry; <tt>coverage.scopeComplete</tt> is true with no gaps; and <tt>resource.binding</tt> is <tt>digest-bound</tt>. The declared <tt>authoritative</tt> is therefore the tier a verifier derives.</t>
        <t>The ordering checks hold on the timestamps as written. Vector <tt>C2</tt> tests the first: <tt>committedAt</tt> at 11:03:58Z falls strictly before <tt>openedAt</tt> at 11:04:01Z. Vector <tt>F7</tt> tests the second: <tt>enforcedAt</tt> at 11:04:09Z falls two seconds after <tt>signalReceivedAt</tt> at 11:04:07Z.</t>
        <t>The single write lies under <tt>/srv/ledger/</tt>, the one member of <tt>pathScope</tt>, so its <tt>inScope</tt> of true is derived from the path and vector <tt>V3</tt> does not apply. <tt>fieldEvidence</tt> carries all seven keys, so vector <tt>FE1</tt> does not apply, and <tt>vantage</tt> is not <tt>self</tt>, so vector <tt>FE2</tt> does not either.</t>
        <t>What the record says, read whole, is that a write was denied and happened anyway, that the posture the decision point read was not the posture an observer saw, and that a revocation signal was enforced two seconds after it arrived. All three are well formed, and a verifier accepts the record.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>A record is checkable for internal coherence and says nothing about the world outside its own bytes. Where a consumer needs a fact about that world, it has to establish that fact somewhere else.</t>
      <section anchor="the-vantage-claim-is-not-self-proving">
        <name>The vantage claim is not self-proving</name>
        <t>The vantage claim in a record is an assertion about the world, and the record makes it coherent with its own members without making it self-proving. A consumer that requires the vantage to be true <bcp14>MUST</bcp14> anchor the observer's key out of band, exactly as it would anchor any signer. Such a consumer <bcp14>MUST</bcp14> read <tt>authoritative</tt> as coherence with a claimed <tt>observation.vantage</tt>, and never as proof of one (vector <tt>A5</tt>).</t>
      </section>
      <section anchor="a-producer-that-observes-only-itself">
        <name>A producer that observes only itself</name>
        <t>A producer that observes only itself can satisfy every field of this format, and the <tt>observation.priorCommitment</tt> member raises the cost of doing so. It binds the before-state, the authority and the record identifier under the observer's signature before the interval opens. A forgery therefore has to be decided on before the forger knows what it will be lying about.</t>
        <t>It does not reduce the cost to zero, and a producer holding two keys satisfies every clause. That residual is detectable by a key inventory outside the record and by no function of the bytes inside it. A consumer that depends on the vantage <bcp14>SHOULD</bcp14> keep such an inventory.</t>
      </section>
      <section anchor="withheld-rows">
        <name>Withheld rows</name>
        <t>A record can omit a remediation event, or a claimed access that the observer saw, and no function of a Statement detects a row that was never written. No quantity of extra carried material changes that, because extra material is material a withholding producer also declines to carry.</t>
        <t>The <tt>coverage</tt>, <tt>fieldEvidence</tt> and <tt>doesNotAssert</tt> members exist so that a blind spot travels where the observer is honest about it. An observer that knows of a blind spot <bcp14>SHOULD</bcp14> record it in the <tt>doesNotAssert</tt> member. None of these members is a defence against a producer that conceals one.</t>
      </section>
      <section anchor="well-formed-disagreement">
        <name>Well-formed disagreement</name>
        <t>A disagreement between the reported decision and the observed effect is well formed, as is a disagreement between the two postures, and as is a remediation event recording that enforcement did not occur. A verifier <bcp14>MUST</bcp14> accept all three (vectors <tt>A3</tt> and <tt>A4</tt>). A format that refused to represent a failed enforcement would mean that no record ever reports one. This clause prevents that.</t>
      </section>
      <section anchor="revocation-without-a-bound">
        <name>Revocation without a bound</name>
        <t>Section 11 of <xref target="AIMS"/> requires that revoked or downgraded authorization be enforced "without undue delay" and specifies no bound. This document carries <tt>signalReceivedAt</tt> and <tt>enforcedAt</tt>, and defines no bound of its own. A record with an arbitrarily large gap between them is well formed. A consumer <bcp14>SHOULD</bcp14> set a bound on that gap as policy and read a record that exceeds it accordingly.</t>
      </section>
      <section anchor="relationship-to-other-tamper-evidence-mechanisms">
        <name>Relationship to other tamper-evidence mechanisms</name>
        <t>A signature over canonical bytes detects an editor who cannot sign. A trusted timestamp <xref target="RFC3161"/> adds an assertion about when the bytes existed, and an append-only log <xref target="RFC6962"/> <xref target="RFC9162"/> adds an assertion that they were published. This document requires neither, and a deployment <bcp14>MAY</bcp14> carry a record under this format in such a log.</t>
        <t>None of the three detects a producer that signed a false record. The recomputes in <xref target="tamper"/> address that case.</t>
      </section>
      <section anchor="two-implementations-that-both-differ-from-the-canonical-form">
        <name>Two implementations that both differ from the canonical form</name>
        <t><xref target="rationale"/> gives the mechanism by which two implementations can share a serialization that is not <xref target="RFC8785"/>. Neither party can see the failure from inside it. Every signature each of them produces verifies for the other, and the records fail only for a third party that canonicalizes correctly.</t>
        <t>A consumer therefore derives the canonical bytes itself and does not accept a producer's report of them. <xref target="canonical"/> is normative for that reason, and vector <tt>T2</tt> is the member that tests it.</t>
      </section>
    </section>
    <section anchor="privacy-considerations">
      <name>Privacy Considerations</name>
      <t>A record under this document carries an agent identifier, a delegated subject, a resource identifier and a set of paths. The delegated subject in particular may identify a natural person. Deployments <bcp14>SHOULD</bcp14> consider which of these a given consumer needs before distributing a record. The <tt>doesNotAssert</tt> member is the place to record what a distributed record deliberately omits.</t>
      <t>The format binds five documents by digest and carries none of them: the credential, the authority document, the policy, and both posture documents. A consumer that needs their content <bcp14>SHOULD</bcp14> resolve them out of band.</t>
      <t>That separation is deliberate and is the privacy-preserving default, because it lets a record travel to a party entitled to verify the decision without carrying the material the decision was made from. A consumer entitled to the decision receives the digest and resolves the document only if it needs the content.</t>
    </section>
    <section anchor="iana">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions. The predicate type is a URI under a namespace the author controls and requires no registration to be used, consistent with the in-toto Attestation Framework's treatment of predicate type identifiers <xref target="IN-TOTO"/>.</t>
      <t>A registered identifier would be the alternative. It is not proposed here, because a record carries its predicate type inside the bytes its producer signed. A later revision <bcp14>SHOULD NOT</bcp14> move the URI once records carrying it exist, since moving it invalidates every signature over them.</t>
    </section>
  </middle>
  <back>
<references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="AIMS">
          <front>
            <title>AI Identity Management System</title>
            <author fullname="Pieter Kasselman" initials="P." surname="Kasselman">
              <organization>Defakto Security</organization>
            </author>
            <author fullname="Jeff Lombardo" initials="J." surname="Lombardo">
              <organization>AWS</organization>
            </author>
            <author fullname="Yaroslav Rosomakho" initials="Y." surname="Rosomakho">
              <organization>Zscaler</organization>
            </author>
            <author fullname="Brian Campbell" initials="B." surname="Campbell">
              <organization>Ping Identity</organization>
            </author>
            <author fullname="Nick Steele" initials="N." surname="Steele">
              <organization>OpenAI</organization>
            </author>
            <author fullname="Aaron Parecki" initials="A." surname="Parecki">
              <organization>Okta</organization>
            </author>
            <date day="15" month="September" year="2026"/>
            <abstract>
              <t>   This document proposes best practices for authentication and
   authorization of AI agent interactions.  It leverages existing
   standards such as the Workload Identity in Multi-System Environments
   (WIMSE) architecture and OAuth 2.0 family of specifications.  Rather
   than defining new protocols, this document describes how existing and
   widely deployed standards can be applied or extended to establish
   agent authentication and authorization.  By doing so, it aims to
   provide a framework within which to use existing standards, identify
   gaps and guide future standardization efforts for agent
   authentication and authorization.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-wimse-aims-00"/>
        </reference>
        <reference anchor="WIMSE-ID">
          <front>
            <title>Workload Identifier</title>
            <author fullname="Yaroslav Rosomakho" initials="Y." surname="Rosomakho">
              <organization>Zscaler</organization>
            </author>
            <author fullname="Joseph A. Salowey" initials="J. A." surname="Salowey">
              <organization>Palo Alto Networks</organization>
            </author>
            <date day="6" month="July" year="2026"/>
            <abstract>
              <t>   This document defines a canonical identifier for workloads, referred
   to as the Workload Identifier.  A Workload Identifier is a URI that
   uniquely identifies a workload within the context of a specific trust
   domain.  This identifier can be embedded in Workload Identity
   Credentials, including X.509 certificates and JWT-based tokens, to
   support authentication, authorization, and policy enforcement across
   diverse systems.  The Workload Identifier format ensures
   interoperability, facilitates secure identity federation, and enables
   consistent identity semantics.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-wimse-identifier-03"/>
        </reference>
        <reference anchor="RFC3339">
          <front>
            <title>Date and Time on the Internet: Timestamps</title>
            <author fullname="G. Klyne" initials="G." surname="Klyne"/>
            <author fullname="C. Newman" initials="C." surname="Newman"/>
            <date month="July" year="2002"/>
            <abstract>
              <t>This document defines a date and time format for use in Internet protocols that is a profile of the ISO 8601 standard for representation of dates and times using the Gregorian calendar.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3339"/>
          <seriesInfo name="DOI" value="10.17487/RFC3339"/>
        </reference>
        <reference anchor="RFC7493">
          <front>
            <title>The I-JSON Message Format</title>
            <author fullname="T. Bray" initials="T." role="editor" surname="Bray"/>
            <date month="March" year="2015"/>
            <abstract>
              <t>I-JSON (short for "Internet JSON") is a restricted profile of JSON designed to maximize interoperability and increase confidence that software can process it successfully with predictable results.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7493"/>
          <seriesInfo name="DOI" value="10.17487/RFC7493"/>
        </reference>
        <reference anchor="RFC8785">
          <front>
            <title>JSON Canonicalization Scheme (JCS)</title>
            <author fullname="A. Rundgren" initials="A." surname="Rundgren"/>
            <author fullname="B. Jordan" initials="B." surname="Jordan"/>
            <author fullname="S. Erdtman" initials="S." surname="Erdtman"/>
            <date month="June" year="2020"/>
            <abstract>
              <t>Cryptographic operations like hashing and signing need the data to be expressed in an invariant format so that the operations are reliably repeatable. One way to address this is to create a canonical representation of the data. Canonicalization also permits data to be exchanged in its original form on the "wire" while cryptographic operations performed on the canonicalized counterpart of the data in the producer and consumer endpoints generate consistent results.</t>
              <t>This document describes the JSON Canonicalization Scheme (JCS). This specification defines how to create a canonical representation of JSON data by building on the strict serialization methods for JSON primitives defined by ECMAScript, constraining JSON data to the Internet JSON (I-JSON) subset, and by using deterministic property sorting.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8785"/>
          <seriesInfo name="DOI" value="10.17487/RFC8785"/>
        </reference>
        <reference anchor="IN-TOTO" target="https://github.com/in-toto/attestation/blob/main/spec/README.md">
          <front>
            <title>in-toto Attestation Framework Specification</title>
            <author>
              <organization>in-toto</organization>
            </author>
            <date year="2026"/>
          </front>
        </reference>
        <reference anchor="DSSE" target="https://github.com/secure-systems-lab/dsse">
          <front>
            <title>Dead Simple Signing Envelope</title>
            <author>
              <organization>Secure Systems Lab</organization>
            </author>
            <date year="2026"/>
          </front>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC3161">
          <front>
            <title>Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)</title>
            <author fullname="C. Adams" initials="C." surname="Adams"/>
            <author fullname="P. Cain" initials="P." surname="Cain"/>
            <author fullname="D. Pinkas" initials="D." surname="Pinkas"/>
            <author fullname="R. Zuccherato" initials="R." surname="Zuccherato"/>
            <date month="August" year="2001"/>
            <abstract>
              <t>This document describes the format of a request sent to a Time Stamping Authority (TSA) and of the response that is returned. It also establishes several security-relevant requirements for TSA operation, with regards to processing requests to generate responses. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3161"/>
          <seriesInfo name="DOI" value="10.17487/RFC3161"/>
        </reference>
        <reference anchor="RFC6962">
          <front>
            <title>Certificate Transparency</title>
            <author fullname="B. Laurie" initials="B." surname="Laurie"/>
            <author fullname="A. Langley" initials="A." surname="Langley"/>
            <author fullname="E. Kasper" initials="E." surname="Kasper"/>
            <date month="June" year="2013"/>
            <abstract>
              <t>This document describes an experimental protocol for publicly logging the existence of Transport Layer Security (TLS) certificates as they are issued or observed, in a manner that allows anyone to audit certificate authority (CA) activity and notice the issuance of suspect certificates as well as to audit the certificate logs themselves. The intent is that eventually clients would refuse to honor certificates that do not appear in a log, effectively forcing CAs to add all issued certificates to the logs.</t>
              <t>Logs are network services that implement the protocol operations for submissions and queries that are defined in this document.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6962"/>
          <seriesInfo name="DOI" value="10.17487/RFC6962"/>
        </reference>
        <reference anchor="RFC9162">
          <front>
            <title>Certificate Transparency Version 2.0</title>
            <author fullname="B. Laurie" initials="B." surname="Laurie"/>
            <author fullname="E. Messeri" initials="E." surname="Messeri"/>
            <author fullname="R. Stradling" initials="R." surname="Stradling"/>
            <date month="December" year="2021"/>
            <abstract>
              <t>This document describes version 2.0 of the Certificate Transparency (CT) protocol for publicly logging the existence of Transport Layer Security (TLS) server certificates as they are issued or observed, in a manner that allows anyone to audit certification authority (CA) activity and notice the issuance of suspect certificates as well as to audit the certificate logs themselves. The intent is that eventually clients would refuse to honor certificates that do not appear in a log, effectively forcing CAs to add all issued certificates to the logs.</t>
              <t>This document obsoletes RFC 6962. It also specifies a new TLS extension that is used to send various CT log artifacts.</t>
              <t>Logs are network services that implement the protocol operations for submissions and queries that are defined in this document.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9162"/>
          <seriesInfo name="DOI" value="10.17487/RFC9162"/>
        </reference>
        <reference anchor="VECTORS" target="https://github.com/probityai/agent-evidence-vectors">
          <front>
            <title>Agent evidence conformance vectors</title>
            <author>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="VOCABULARY" target="https://github.com/probityai/agent-evidence-vocabulary">
          <front>
            <title>Agent evidence vocabulary</title>
            <author>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
      </references>

<section anchor="rationale">
      <name>Design rationale</name>
      <t>Two requirements of this document are not derivable from Section 11 of <xref target="AIMS"/> on its own: the canonicalization contract, and carrying the observed effect beside the reported decision. Neither is restated normatively here.</t>
      <section anchor="the-canonicalization-contract">
        <name>The canonicalization contract</name>
        <t>The word "tamper-evident" appears once in <xref target="AIMS"/> and is not defined there. Read narrowly it means a record whose alteration is detectable, which a signature provides. Two gaps remain.</t>
        <t>A signature over a serialization is only as good as the agreement on which bytes were signed, and that agreement is a property of a written contract between two implementations; neither one's code establishes it. Two implementations can agree with each other on a canonical form and both differ from <xref target="RFC8785"/>, and no amount of signing or hash-chaining detects that.</t>
        <t>Each verifies its own records and rejects the other's, or worse, accepts a record whose meaning it has silently changed. A canonicalization contract is therefore part of the tamper-evidence requirement; it is not an implementation detail, and <xref target="canonical"/> makes it normative.</t>
        <t>A signature also says nothing about the producer. The party that holds the signing key can alter a record and sign it again, and every signature check still passes.</t>
        <t>Detecting that requires fields whose values are recomputable from other fields in the same record, so that an internally inconsistent record is refusable regardless of who signed it. A hash chain catches an alteration by a party with no signing key; only a recompute catches the key holder, and <xref target="tamper"/> specifies three of them.</t>
      </section>
      <section anchor="the-decision-and-the-observed-effect">
        <name>The decision and the observed effect</name>
        <t>The fourth of the seven minimum fields pairs "action requested and authorization decision". A record carrying only the decision is a self-report: it states what an enforcement point concluded, and a deployment that mis-enforces its own conclusion produces a clean audit trail of the decision it failed to apply. Section 11 asks for enough to "reconstruct agent behavior and authorization context after execution", and behaviour is not reconstructable from a decision.</t>
        <t>This document therefore requires both sides in one record: the decision as reported by the enforcement point, and the effect as observed. It also requires a three-valued <tt>agreement</tt> between them, which a verifier derives from the two values; it is not a claim the record makes. A decision reported as denied beside an effect observed as having occurred is then a refusable inconsistency in signed bytes. Today it is undetectable.</t>
        <t>The same construction applies to the sixth field. Section 8 of <xref target="AIMS"/> defines posture assessment as an evaluation performed at credential provisioning, while the sixth field asks for the posture "influencing the decision".</t>
        <t>A conformant record may therefore carry a posture that was accurate at issuance and inaccurate at decision time, with nothing in the record to say which. Carrying <tt>posture</tt> as the decision point read it, beside the posture as it was observed and its <tt>assessedAt</tt>, makes that difference visible without constraining either value.</t>
      </section>
      <section anchor="why-the-tier-carries-five-clauses">
        <name>Why the tier carries five clauses</name>
        <t>Each clause of the tier recompute closes one route by which a record could claim an observer's vantage while carrying nothing that distinguishes it from a self-report.</t>
        <t><tt>vantage</tt> of <tt>below-observed</tt> is the claim itself, and the four clauses under it make the claim cost something. The prior commitment binds the before-state before the interval opens, so a producer cannot decide after the fact what it saw. A non-empty <tt>pathScope</tt> means the record names the ground it covers. A complete coverage claim, or a gap list naming only paths outside that ground, means the record does not quietly exclude the interesting part. And a digest-bound resource means the arguments of the call are pinned.</t>
        <t>Dropping any one of them admits a record that carries the authority of the rest while resting on nothing. That is why the corpus in <xref target="vectors"/> carries one reject member per clause.</t>
      </section>
    </section>
    <section anchor="vectors">
      <name>Conformance vectors</name>
      <t>The table below is the conformance corpus for this format. Each row gives a member identifier, the accept member it derives from, its input, and the verdict a conforming verifier reaches. A reject differs from the accept member in its <tt>from</tt> column by one mutation, so refusing every input scores nothing on this corpus.</t>
      <t>An accept member has no parent and its <tt>from</tt> column reads <tt>root</tt>. An indeterminate member has more than one conforming verdict and its row gives each.</t>
      <t>Every row names the rule it tests. Three rules this document adds have no member in the table: the binding on the digest map in <xref target="subject"/>, the <xref target="RFC3339"/> requirement in <xref target="timestamps"/>, and the single hash algorithm of <xref target="hashalg"/>. An implementation <bcp14>SHOULD</bcp14> be run against every member of the corpus before it is described as conforming to this document, and the three rules above are checked by reading them.</t>
      <t>The corpus travels with the predicate schema: the revision of this document that freezes the predicate type URI is the revision that publishes these members in <xref target="VECTORS"/>, in that repository's manifest layout.</t>
      <table>
        <name>The conformance corpus, one member for every normative rule this document adds</name>
        <thead>
          <tr>
            <th align="left">id</th>
            <th align="left">from</th>
            <th align="left">what it is</th>
            <th align="left">expected</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">root</td>
            <td align="left">every member present, <tt>permit</tt> beside <tt>occurred</tt>, all five tier clauses met</td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A2</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>deny</tt> beside <tt>none</tt>, equal roots, empty write set</td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A3</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>deny</tt> beside <tt>occurred</tt> and <tt>agreement</tt> of <tt>disagree</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> plus a remediation event with <tt>enforcement</tt> of <tt>not-enforced</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A5</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>vantage</tt> of <tt>self</tt>, no prior commitment, <tt>tier</tt> of <tt>voluntary</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>binding</tt> of <tt>not-bindable</tt>, <tt>argumentsDigest</tt> absent from the record and from the request-digest preimage, <tt>tier</tt> of <tt>voluntary</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A7</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A2</tt> plus one in-scope write inside the interval attributed to a different request, roots and chain moved to match</td>
            <td align="left">valid, <tt>agreement</tt> of <tt>agree</tt></td>
          </tr>
          <tr>
            <td align="left">
              <tt>A8</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A2</tt> plus one in-scope <tt>unattributed</tt> write inside the interval, <tt>effect.observed</tt> of <tt>unknown</tt></td>
            <td align="left">valid, <tt>agreement</tt> of <tt>indeterminate</tt></td>
          </tr>
          <tr>
            <td align="left">
              <tt>A9</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>permit</tt> beside an empty write set, equal roots, <tt>effect.observed</tt> of <tt>none</tt></td>
            <td align="left">valid, <tt>agreement</tt> of <tt>not-exercised</tt></td>
          </tr>
          <tr>
            <td align="left">
              <tt>F1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>A1</tt> with the whole <tt>agent</tt> member removed</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>subjectKind</tt> of <tt>none</tt> beside a named subject</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>digest-bound</tt> with <tt>argumentsDigest</tt> removed</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F3b</tt></td>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">
              <tt>not-bindable</tt> carrying <tt>argumentsDigest</tt> of <tt>null</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F3c</tt></td>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">
              <tt>not-bindable</tt> carrying <tt>argumentsDigest</tt> of the empty string</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F4</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>action</tt> changed, <tt>requestDigest</tt> left at its original value</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F5</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>beacon-anchored</tt> with <tt>externalAnchor</tt> removed</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F6</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">two unequal postures declared as <tt>agree</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F7</tt></td>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">
              <tt>enforcedAt</tt> one second before <tt>signalReceivedAt</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>effect.observed</tt> edited to <tt>none</tt>, writes intact, signed again with the real key</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">serialized in declaration order, not <xref target="RFC8785"/> order</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a member name repeated at depth three</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T4</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">nesting 129 levels deep</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T5</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">an integer of magnitude exactly 2^53</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>D1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>agreement</tt> of <tt>disagree</tt> with both sides agreeing</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>D2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>agreement</tt> of <tt>one-sided</tt> with both values present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>D3</tt></td>
            <td align="left">
              <tt>A9</tt></td>
            <td align="left">
              <tt>agreement</tt> of <tt>disagree</tt> beside <tt>permit</tt> and <tt>none</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>S1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">second subject entry removed, interval left present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>S2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">second subject entry's digest set to the before-state root</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>I1r</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">interval removed, second subject entry left present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with <tt>vantage</tt> of <tt>self</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with no prior commitment</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with an empty <tt>pathScope</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI4</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with a coverage gap inside <tt>pathScope</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI5</tt></td>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared on <tt>A6</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>C1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">commitment <tt>keyid</tt> added to <tt>agent.signers</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>C2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>committedAt</tt> one second after <tt>openedAt</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>C3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>witnessNonce</tt> changed, <tt>commitmentDigest</tt> left at its original value</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>E1</tt></td>
            <td align="left">
              <tt>A2</tt></td>
            <td align="left">
              <tt>observed</tt> of <tt>none</tt> with a non-empty write set</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>E2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a second write whose pre-state is not the first write's post-state</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>E3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>empty-tree</tt> under sha256 carrying the sha1 constant</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>V1</tt></td>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">
              <tt>enforcement</tt> of <tt>quarantined</tt>, outside the closed set</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>V2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a <tt>pathScope</tt> member carrying a glob metacharacter</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>V3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a write outside <tt>pathScope</tt> carrying <tt>inScope</tt> of <tt>true</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>FE1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">six of the seven <tt>fieldEvidence</tt> keys present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>FE2</tt></td>
            <td align="left">
              <tt>A5</tt></td>
            <td align="left">
              <tt>substrate-covered</tt> declared beside <tt>vantage</tt> of <tt>self</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>N1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">an anchor token digest carried with no offline validation rule defined</td>
            <td align="left">indeterminate</td>
          </tr>
          <tr>
            <td align="left">
              <tt>N2</tt></td>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">enforcement forty days after the signal, ordering intact</td>
            <td align="left">indeterminate</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section numbered="false" anchor="document-history">
      <name>Document History</name>
      <t>Changes in -01:</t>
      <ul spacing="normal">
        <li>
          <t>The request-digest preimage under <tt>not-bindable</tt> is stated: three members, with no <tt>argumentsDigest</tt> member in any spelling. Under -00 the text named four members and forbade the fourth, so the preimage was open and three spellings gave three digests.</t>
        </li>
        <li>
          <t>Each write carries the request digest it is attributed to, or <tt>unattributed</tt>. <tt>effect.observed</tt> describes this record's request, and it gains <tt>unknown</tt> for an unattributed write inside the scope. A write that belongs to another request no longer changes this record's agreement.</t>
        </li>
        <li>
          <t><tt>agreement</tt> gains <tt>not-exercised</tt>, for a permit beside no effect, and <tt>indeterminate</tt>, for an effect the observer could not attribute. Under -00 a permitted call that was never made read as <tt>disagree</tt>, the value a leaked deny also takes.</t>
        </li>
        <li>
          <t>A statement whose signature fails is malformed, so <xref target="verifying"/> and vector <tt>T2</tt> report the same verdict.</t>
        </li>
        <li>
          <t>Six members are added to <xref target="vectors"/>: <tt>A7</tt>, <tt>A8</tt>, <tt>A9</tt>, <tt>F3b</tt>, <tt>F3c</tt> and <tt>D3</tt>.</t>
        </li>
      </ul>
      <t>-00 was the first revision.</t>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>No acknowledgments are recorded for this revision.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA6V963rbyJXgfz4Flv7R6V6SsiRf1ZOZKJY88Wzb7rXUnS89
0xOCZElCDAIMCpTM2M6z7LPsk+25Vp0CQNnJzjczLYNAXU6d+62m0+moLdrS
nWTj0yo73a6KNnvnlnWzyl7WzTpvs6u6yU5fZafXrmrhhfamboq/5W1RV9mZ
WxYe/vDjUb5YNO4WR5H34kDj0TJv3XXd7E6yorqqR6NVvazyNcy5avKrdnpd
lKt8elesvZvm+Pk0x8+nDX0+fXg48tvFuvA4VbvbwHevzi9fjqrteuGak9EK
Rj8ZLWEZrvJbf5K1zdaNYC3Ho7xxOa5psymLJa3ZZ3m1goXl5fSyWLvx6K5u
3l839XYD7/0R/i7rfJW9WsEqinYH681eb8u2yC52vnXr7Ly6LZq6WsPPsOn3
bgefr05G2TSjJdMfuAP6o22db2lW/GebrzeumbrbAgcf3bpqC8vOsn928ixj
WNCHRXWd/TsOhM/XeVHCcwLo7wrXXs3q5hp/yJvlDfxw07Ybf3JwgO/ho+LW
zfS1A3xwsGjqO+8OaISD8WiU07HjPmGULLvaliUf4Pgir97n5Sb7dzzDMf3q
ZH7PP83oeH93jU9ny3oNw1WEWTAt7v/01esLONHpGa1B0QD+P/z2R/jtfPrq
rPc7wbC4KlwDb717+eL4+Pj5Cf/59NHzY/nz2dNnj/HPV2+ml28v357Q8hTd
i2ra1m2dncZjyl42sCvEiOxiA7h9JUjD+2rz5tq1J5mC77pob7YL3NKBjHVg
jvxgUdYLBHF14GGsg3fnp2evz2frFY0VAEr/M80A8nFJPB2hdXb08OgJ/PPs
4uI8Xf6ZA1S5KNab0sF/rivEAEAQV9Yb98X1erfcNm7qCa/8tMwXByvv3T1L
u6AvBBN99kO+6K1yhMRtDhaP5fDJofz55PmTI/nz+SH/+fP5i8u37y7SfTH/
YCpZugzImgbFv2/dsq0b/8XdbZp6AfSTFwfMTXSwqQyAU799cfr7n344ffen
e2e/rZf5YgtEsvv/mDSMMRpNp8AWFr5t8mU7Gl3eFD4DXrhFis5W7qqoHPCn
jPledpXwXxpVDkf570r57yy7vHH6AQxaVy5T/N40boV47IhfTDIPyOJW8LOH
BcJsiFqZE8yZZa/abJk3TQEraWFM74BRZeuiKtbbNTO5DMiuXOHPMBm+Q1SK
awyc63VewXppW8K7rgJlNe6v26JxfkKcuL3DFcLMTctTwpjr/D0s9qb2Tqda
3rjl+3yBR5TD8qq6gh2VCgbAEYIoj7io2xta1jCseFb4uV5419wCJNzVFeBF
dgdnCaOvXFPg0/amcXB4ebmFf+TX8A/azsK1dw4gAiOsEep4QGFrmzJfCtzS
M6y38H9XmV/CRnkBsEWfVXX26vTNaQZrh5XhcBYh/BbFlozHA9HxKKLA15sa
5Npuxoi1Llar0o1GD7JXAI96taVR96EZokgf0RhueMh47q0cCBA/wfDwEHfx
8SOy7M+fOydZ2JW1N8iPXOkZozxzU7vobF2vXDnBB0A+sFEi8WVTtHAAOY0I
PzWuRZSCuZtt6eJENc+SuQ/w+wp4VAZnAH/o2ma4bZdd13kJFNUAPxp9lwEx
EGrllexR99/Ua4LHym3KekdgwjXlDaIcIwb+TO/luDnXfG/GG6eifQxYJCi9
gz9vYT8oqBBvMxQPMBbBebGDf+FubmrAcRkQaW/3z6AvKAu4RqFu3hkQe40o
XfhhBEZWsQIIL1vcqKzgGtB/gPSFEuH892ADzr52qJJlLl/ewAn8yAe9AM5S
XXscOzcg5sPscjvzMkzf7HDUu5s6u8npWYNSL9IXkAzwDxKCOKRoeISzuIbM
wxN/tbNLLmjrRZPVd5VOuiFqUcwHXlKUMgqcGaLZwglCOIApTNy4EhgqrH7Z
1B5ZNp5FASMs6m21AlY/QZQkrgVvLRAN4ON2Jzyz2XogrcoViEk6ezOzy8z9
e08UmZcl8yIA6IuIlAiPPKsAW+o7AHtO8h9GcwwSBg+hfoLKN3CiOYxXAMR5
RYh8+C2xTURRxLQVkBphe8TTHM4FnsIItGj4fzt41QPBLgRdgAKJJQCKJ+8B
rIOgYk7KR6+vCBjuYEcOhf3SrYR8SaeHAZEzAKrCP5fIEE5IakRMsicOcLkh
pKJ1AOoDdTTwTrnTs/xLHVBAoYRkZT65ph0w6bjSXTMFMj7geeORdqgIR6pA
rm+ZlBDL9HjL+hq2s4doCmRjojOBZoByAmHpPhQgNXHb8LJK/six2IjxRUk/
6FewIcRnYrjKmnnVYwur1z9dXAaMX20ZMXh0WCpCGTkWYMQeXYPn3i74ZHCq
NSgYTHrjiUx4mqyWpkQ0SfgkDQTnCSoykRK+i/MCmTP7AY0TlQmRFwAJfBy3
MhYNAidMZJZwlCH+ZU/iCMerrNC2konGDlJzQI4DhiDDwQWLIrQjchsjkuES
1iiRcGdIqaw5EkXDZ8gjVgpZlC+EkoAMPjE7DEc41nUOCct0Wbjw8N2TcAip
sgEq48ePDU2Tlw4w0TuAnOLfXhUriB9gxF7k2BdFE/N0lVDCuVFPeVFXtyze
GavOUH8o6N/MAMDAzu5o9WPEIThx+m/25i39/e78f//06t35Gf598YfTH34I
f4zkjYs/vP3ph7P4V/zyxdvXr8/fnPHH8DRLHo3Gr0//JAg2fvvj5au3b05/
GGd6TAEv8MABXxdI8XAWG2RPeOIjZY2oaGe/f/Hj//0/h48A4v8DzJ+jw8Pn
AHD+x7PDp4/gH8iYeba6AlbF/0SUGuWbjcsbHAUlwTLfFC3oNBPEKn+DMoyY
Pqg3/4mQ+fUk+5fFcnP46F/lAW44eagwSx4SzPpPeh8zEAceDUwToJk870A6
Xe/pn5J/K9zNw3/5txK4RTY9fPZv/zpCFLp0DVB4DZxrxyhzVZdlfUdkCT+x
BNx6Vujr7fUNo7g5QxaYzF3Wk+w7wd7mOzqO7wJ2b0ButN9NaEBWdFcE+++F
HrxgA2iEVRSeOgvQH8hHFBxkdpH5MBqRuTnJLusaNOEL1iEm2Tvn622Df/3w
w+uT0QmedZAYsBeffJ5FXwi9K+ZYfIqf64IBjT5+VK8KqckXwMQc62PA1P/i
0IwKJmOYXDwonfnfCqjwNeKfUccRAWPMWVCMSB9IQH9aKbdABaAFjcmLmp2V
+c6JQULbFPGdr1YAa2Bfp6C6+HZK4Lwt3B2JyuyaZPgViEZ2bsB5ZTdg9wJo
fd1MS5AJJWuR8Dq/jGxc2OZ711SulLfA/qLP8PCRhd2lzA12CPtjBPNbUD1o
wZ72BLa3/lwWi4YUwjy7a5CY7Z4Amd+L+QSaF+ixdQNYG3QysTUYrt94lM80
HTwG6J8lmDlwBg6tV9JT+/aEUdTgDQR/0XpyEBZoD2yJp7xCngaDhLFB2tSJ
8gN/g0hzU4JhEAD5FXwnz2glxtgk9QLl8GUREWflUC1ETnp3UyxvAtLAnpHF
sVnhSfOuF3WD4+K60XhalugrFC0IGCI+Q1VSzwkRJZhgbNyzsG/xgSKlI/uS
yYO/JDABvpMhSgBCrCF7LRB3EGXnaKqI5tgXEvD3HYjqFnVvPMQ71yxzDzq8
+5Aje1nnpZglwOOv4YzaGzs+CtgyR2UOXsJTmqOSe6pvzgU8JFETB37iwwRu
oeMVnrBN/EOBASRkzj4gYhgdFxG8hv8G5gGKJiwmMItLILM5DD4a/f3vfx/9
Nv4PCofzk2z8X+OMuDfRAeI3EgPIwOzZ0+dHmfngt6ORetiCW20mvrai3uPV
OwgLObg9PPivUT+SQOsaXRQfWsTe6BdT9LKcnTBBfsCtnqNxISqolxFI7yc9
G7lbScwg4BHhvRc1bE3uHsTWuloVrHSR60MMZrbmYO58WwbDOGCtynH2CO3Y
F4GmYYXORDw5GeY3DIps/vJw/i3LNbs3MzmbPL5YlHgO5OWaZPNGBM8MlFWW
WmeE0nNa0VwNX/RVoeOlgYFOqyVwlTmvmSywqMU6svFg4qJlTwOBFuVWZ2+N
Q7mDW8aFoBbKvskKjLayRuEdnagd2hKXE88fAFVcg1XFZmkXND8zaFDJ7QyN
7qnGgXwTzaFx12iFNYoN0WdMgvMB6K+qJpN9kH18EPTmz8DfBjwTzH+iucym
deAn9CzSI6mCxZWYFsQhReX2qPYH5ZzVRuaIjGm5GQW4C64OOeHv0cZHTLgq
PpAuAryIdvIg+4+Lt29QpKHkHI1+FJcEq+V6WGLIGeOAtxLnIlfZx48Sevn8
eRJEAvqlchQrIgDEvyu+BXb2sbBL9xbO7fIIz+3ehYn3gOajRWAoCHjZqynt
zudXbopq+jU7XXCrJ8wJ+RmQ9zq/BgNki8jXkldxAavNjv778bFANt1vgK1Z
52NYJ8P0bMthR8NhSJh4shrBkG1vkBYEQyv2n4C2TyZES+hPL90/dSLgLDmR
UmIxISERNrxpEuQn9RKs7YZcDnErxwjyUzMCrt2hQHKsx+RoRj/LSF+KZj7P
nwDlkQAlu2AdE3mRmH5ANqJ4fjYyKsQggIrkZzjfFp9JsKNoPLEVFpSizSxU
Cp+wpESgzvUtw78S9Zh8yvCyv8mPHj+ZBzmejK1P9wmIS3ZZ1NVKP7RaUFPX
rYqPQrQqVqmCFJIdT+J6ksXzfhEEqAnKb0RvRF7bK6DpbH5Ak85nJIOzv4CJ
PhoL+MYn2X+OsuxjNsZv4V/jbVOdgAqCPOoEYXPy9Oo4B9sXI11j3i68Bh8w
YPCT51fPnqwePjt89uzR8unqyePn+dGVy/OHy8eP89XDw8ez2Wycfc4+T75i
Jl7r/fM9eXj88Dh3R0eL58+fPXtyuFi648XRs6vjY+eWhwun841+ZeHeJYVF
wbwRYTRfiTBb55uUFvQt8dgxcBHziSZRXdqLO8F7m4EcBI7mvyeHuyKQijQj
zck1tNkmjD8NBTAy4dyePYHoi2Q3FymhIZZQMg4hjQhtZDnq/+I+FXQknAnE
CQhHKgPIleBuYBnTx0VljoStQsyAexeHohC8Omzm30aElW0zL/7rVjBcBwCs
7VFEYBAXR8QgTqMzia1ItO5bZCUSUlLdKH3tjizcqkDvPDBX8pNgGMUu/47l
Tddc6S6JNSVePTup8TNU3xGedKZuvQELKyz99Ii5JDqAQScha6KhacRiUDWN
vbniEwtHr6KBrFdV0AURJsb6EKs4vhFiYDf5rWPmihktHp2sLGkszn580IYf
P6vBgo8EQYsqDq6oklcsRjG5AsQohvqn+AnuNqC9+H/cB0QswmEY6qfLF5E3
jX8Zw+6uAHqTgMitiVHQzoKjPvHrg8kO79bXHCjAEdHKy1l6NIQAIJA2os8N
k2jCP60oiXyU1kUx8/gZ8oQhATBJeXj0h6pXE47Burnh1AH29MTKN45MaXS3
7XwhZgVrgXsjbhzN0fiQipfoAEMcElZAFhyc0BS9ALhHNgoBDsuaXA1BK3NW
f4u6nrAomQOoojTKiGj/hFOkTFztDyAWXlMPxE8EOhloXY5F1ogW+uPpefbb
bIx/3x6Os4sfQcOofjPOYxrXwW21mokF+z9RzI2/hdckZ4X+5/63Oy/j8P/x
4uI3Xnf0LQ6XpY9YwlzuwQg4VDIVmFUsb1C5EjgwyZvshHkIx86Z/JjrqGSg
iAwHpQnvDYswgTaOfxqBF/kO80D4BznrAl2HhA10qyNyoAAr2cLhgBLFjvNr
XHvU3Q6JNV/asADbO3CUbEjkntWhaP58ZlIHKo86uhg/TGMRpWij8WFwmKIj
LUEnxvKrvCCbteCNwRbzctZLclDeKN5CIVHNJbgB3VlHNbRlqG6WvQtv00wh
oE98em8UW52UHqwYck+xXwqkoyuv8LT2O0OVkxq3mfp7cDtv6vaURlV/z6Sv
FVSOJSWmWaKSgDTNpAVc6bU4XUJ4bYA4Pz5Y81vAqj5Z0NDv2afstaDip9Gn
6XRK/wcvGqZC+JN6peGzOT2bFStgtfL3ErAO38hL8TGEX1IWFZ8TejZ+jpNr
YNatotea2KGqNzBnjN3O5B0cq//0fwGn7/wivtJ2p/4PnFK9I2gXtnUN+OvI
SbtEP69D6EQHynsZMzwo0n+idIGP5/c6XQi0S+uuFULdkxpCe+a/RUFjzgOz
BGGs6U2WBeE8QTvoaQ7pQZpf5kH4RYsmKiA46Kb2ZPIjOXjP0gwU4MK/FyyH
AeUdWCPpbCEV4TavWjh31mTmPIJbnYazCEFnGtKhF4clGseAaRc5OnPoWMLb
+PnHE873++348uvSXHSfyoglNUQyddZjVKjQ9cVUkpe+thp0kOqomhcM0yqb
08vn8ts8RpNN5oQ4sfEpBtxbcnwTVYtPX/xljajvopIx90EbFSMsIAl4i5pL
l1dspCMjkuyUSpMMhrkV+zLznRf3fI1JXnfk2TO5ed93JE1gwvAlJzqoYXIF
CN8quDZ50bCSvAzhcKPhqwup8BqEV9BGZJ8ETA9HNYTnqkianbF6n0SwRUHX
pCny3qOlxd6W6NFKsqrgJYwUSeqHCFKSbyfWFNeJ2MzlDaOZS0oDBqIbRyGg
FT4ExNiN0ZQe85LgGRjVoLaMNbaBb4njZkV2NA/k0dTHCTZ5e4PvHPjm9qB0
q2vXHIAa3rJP0s9wUSXaz7+OcJqwHZpdtjdWwxqDTwHxVXGNkCtjjCcQiHec
/LAsHSUWVQW6vReOCROtnNxHxx8jM4inAHpEBRZeP6MWQcwh4NjHB7f68HNi
+JPp1ItacLJJThFGssbB1G17Fjhrpkg3pO8gansJ/uXiUCbkTyU3ue9LFMI7
ZmyAJhLQIbWwmwWYkxufcofUpsGPeXviDmzviqUTetFNgMFi/ajoHyCzZpIh
T/gnlXekBh89uEQQcZZAxAxsRPTgeRTzVJI9r5Cm2d6i+CrrdW2iono4OdUw
PQacxKdAyaSI+WRA5n7QsXoU9FDrrBY4sK/jRBRk4+iljDw2m4JH2IZe9rtd
dXvBY7vJYc3R35kGhVg7vcf9LhllRl3HnFuyMqOSuxaSSEGKeaGIirB9UcBu
io1snHL5YCk940uCVCqz4FhUN+rFqowjczBUNRgtiiYfE65HVTWYdv3wyo50
WYG6hjRnalAFnxjuKitzHzRrg/GsXEsUrJUMbAU9wfPjRzG1Y3Yyj0h0cmLh
b2PBHR9v4AooqAIELZTYOceqEuWFEsiCljXgbJhklBC3KVGMEhkaQzGyIeuf
IhdZModkmmxLM5d4+TqThYxs3iSpVFFcidHZc0K1msR2ta04TQzQifxyIrLD
QRn/yKYpMNm1Xq+LlkYHNeVGwwPRN/INJXC2wnGG3KHsow/DqHUtXDhYr+YV
wOglmBE+0UJ58/d8heYvGnUcOyUgdEwMQUtKEWB/SgAWskc+At/ZR75ST9Mt
Yn9Oxjcxnk5GgXA/C3iRhX/ZwnNNGyb097gk0HXUIqFM0TmqfPPbutyCjtzs
5qqxdc3gQAKYdY/K5xIJUWUSMzfznFkwaZs3+cZ1nAuoArY1uhZbg+NojpOK
n4as6XVl6cwlwpuNk2RjLe1pKXXhx148HqxRITijQ5ECxBj1ihQgDAGQ7oOn
hQ8SUPFPScIEviMRBvqRjh41Mg5EFDSq36BDkhMQVjOJXVCBXOUPNjn7Jw98
fkCZv0sQRCGS0bVs7SIzXl40b8daqDe927T6iqAhqnH05a/wmEIq42ijxgXH
+M4YUK45yUvQHH5nlhyGjfauvmwXZQxeXXKYV43UOOt7GQUtYR2FQbdebgBu
lIJ1IIot/yxGL2uXOM2UhHNYQ2r/9tZglWf5oqtA82Ph5oPQ7ynYGn6SwX/E
XCpGrM1qM3T+CKq/TQ/1Q84ZvneuU/oBa+SmD59PD59fHh6ePHx08vDol7i5
oOLL1vaq+AhmYXThbYQtCY53IDHSRSCUMMQx+MsCNHRMNiy3CkepOVrFd0Dt
rPZv4fCX+KZ3ebn/zSe/cAndZ4UbCIkLTFgmLLcWyvhXeSUaMzKF7jb7WtNm
Yj5oHCllQyclB+nb+9+4B6/kXHRDVIHMTz/TfyMFDxtZ9JPxrXTZEUxNMdPn
h8tHgZxlsjEVJUwp8U9/Q0fM73NfIPQAN3LgUdOcUnUiGqUpPGySKlU3V0us
3USTdJVsl/bDOxHPTVyqpS1fVO/RzujSwiChWGTPUdqWhW+7Pw4z0+AX6mDd
wycnDx/C//4S3hw2biODCy6igHCBuMhepV05KkKfor/pvaUSUlLLd6CNoNdh
Hw08NdSipS773n3ef1dXr6toKfcZ7Zb4Kh7KeXz9XNnKGExBt/c1yx1GirVE
hmOju8STFuccIxec1zScoMpAcT1LPB8xFYuXStcqeQBmXecbou5fI1NAVfJF
0NQsg2P9bR83PT55/MwADJRjMNr8G5DMrsf1oiY4TMlj0A+LVe8pHHEPRIw7
iSfPSCfRK8bqmJuqYy5CyRL8/veM5LvvJaMa7H8tUu04+BSn4lOMxGqJ4b73
glYw8FIU3DZ8EZUa+q3wfruXCA5BvIw+swPqwQNNay20yhh1Tq73ClmzHx/g
A/g3qIxz1RJDDo0CBUwR49XmutdC64aofgprqDf5X9kfZfRa92HpNq2kNQ7a
K1oNRjbNaiIe05A7nAdrH61hsi+LCl5FS7ib18tGZpoW7HqZxiFNGDdJxQcU
XJplbyt1EF/jiVTeeH/4E3GXiOXIg3oOZ0YldpIF5XCiFVIIeXXuJ5+FSADl
UkyMobtJ0i42lLpP/wzfq2O1D1I0GSjOHbeHnqVOuhi5B2U0As1dHQHnBQck
Qso1WuIQQee1qSVTZEFNMLGB2AynGBqmL1C2iNSlvq+4PGDHbnG70BCyDWtR
zwaG/MUfAhIYy0fv6m25yoBL9hOLBJFkDV5KFjkZiL5Cxw0ikVJUwHrK8kgC
BKypGdwJ/oLCa+IjKo3d/J25qnjz4MQ1+BdrZXkJ4sxI8YJ8ElwaxcBjN1Ga
FJyGD0ISrXqc0XO0MjQhE0ffRF7t2IFmVkf+CqJtcTqrC5iriimqoSmTFijR
KG614oDAzTNiHUnlFNI36BumKkHyOVk/SIhVazZazylCLE47KExs5Skvg1kt
HHCIpSae+F7VD+xvAd8Ltu2Lukoog8hMPIfxHT66OCTmWQXf7mxPvFaBsXZL
2Hjh18Y7LT5BTKSaB6sXwzeY7g+04EEtAzahHj/8Zd2WHv9b4zRTDrZOW9C+
KOyDWg38d9Xkd+JF07Ddc5sqM+vFkAttb0HbJo9Q2KfwXIqIsfsFeTUWomh8
A51vVIIXg3SwQ2QCXBsV6On16Z+QIChlDIlzT/RZe3bAUuZoluPWuH4pbHKW
vaRw2VEnNikboTy+1GXr2OMcigR6IXOpqRYnDC+ZkvdL5A7zZIG4MlqHVrDl
4YW5Ik6J5agwtSwYSfpLg2CGBxGJLkmy0WwEYF81BHDvq1g+3iuBoLS8e4P6
af2GAV656+cZGo4OzCOMlUbDEjpyHzABiRhetZui/Ap1b6Sc2FQBiwBo2uKx
b5sC/4MOlvnExBjIOSfoC3wJQyDSX4vyC8Wqy1y1IhFGslAR5lGSQEZdSGYD
aQm0DuujmWvqP8a8591MBWExwBKnOALK03k8J/6IEwPxwAnBKJezqJbllsJe
82pbljF6yymWoE/ibzHx9OUxAuTl8ULSG14eLykm9EdSx8xp0cYp1NYrVghr
50we+KUk17xk31AqMAViQio56gCU74HvSoAsjlKEysRkKhvGwQJhGDYm7NBA
hH1GA1GWEaQZyiQ65LapK0Is9HCynDgL0XEJVxO6qolLjIZfmKnhnaIY5dVy
0ku1w//ykykytmmgBD+fZXYk4/6Yd9N8h/Mr2c8a9DhNuo6f2Xilko9KC/UD
z9nPR5lAPcwLyIt6PmGFPmCeExnCIy38QTUbSL7mpXK4uDcyEBJMK7XYQyRS
+A6JzLKfiD106ECTeZlNi0ZAsUJbFFIPrEBYGsYkEUm9tERRnk1ZcEmBUQj3
UDMbiWWhMkdNXUIWkcldfkK5y5gDqOoSw3qioaaY8ZTQDquHXvqORb16AWj7
XlMOWRmj3JNoMMVwHmoTObsbOSYykzQaiYxpmkeKdydDATvhuPo0kcp5C2xk
EQJMPHhbT3RTQWptq/Aq4E1ccRhJk/v0LY5uV+GBJgtqTXPehvyV3NQ528Yy
QNFUGMxrMl1IKNsGTtzqkFiujBwfxQeT/Uz9LnOjVRtb9hsfS2NoumAApsGy
orXcQf3NRsEC4KB2U81Jg9YEcUK3mK0aweuxSVocRzKVW7Bscs/VwPwemRsK
cwTAPm7zvSoONBJQy57vizaQU+c46X1qpyUx6nnwQMPoxDh0j0yld4WnEBh/
mU6Tm3x1PTHTuUiiX/T8m9CPhBuKaOOqqtUEUNgXvMSKT5R1p0+FnVH+LZqh
nOvVV6FEWsYaBdP85asqHriBBfPkwBrOY9rvUGqzFJppHxniDt3qjnui2nEa
qZ6Yp7EI1kBoY9MWmGWifwQNgX6iwos2r2IDs2AidpxDcdJjqTYRDqtaF2OD
0VzANKMiuey6rBfwdgvsKcc+KJh+yxritiowcx5Ax93dikQzC8zlwEiin2XP
DE+tdu2tQJQtiSowRK7y0iM9sjOg8CHPLcAaRzFlI8aPUG+KKimp/JnBYFPk
DBegp6QiiLOc2UE7dR9cA0TK/AHEnAt+aLLTKkc9GVbzaAQNs4shHcVkrRre
tuAzZzWJs7EioZwd4rRnR/LxGRUtalrpzOztHq6F/hyteJcvfai1Rd8NVQSf
KFCYC4VkCaYczLEiFMQ/LNj47YXW3moWDq52W3Wo7uUTOpJPWQ822aesAxd4
EjM6TEK2JGWrkke5AnvUO0yOjVz6U9gffU+qIT5kfrPv1+T7uOl/ZAlhghS9
OAEaLIZPhjd/6uJcktB7hmdLeXQBMqZbg0DySw2LxpRPyOvNcs7+iPmpCRsX
VgtYLuldsWJtyZU5OedIOGpSiCoP0+U6XxGv6FGU2p2VNPEAkYnJIKxtCnAl
7Qn9m+SAVVF0BUv0oZtIteQ2W42j9ihYHMDSSeoG11wsaLTB58SX0Mw14k4k
bU9o4so0fyroNvAlEhb61DC3zChlIOJMp8IG2Z4YRMFFRzpP93StAkSeUGMS
wpKfBSnF3IGhG7rPGHY0s//gMqSuTypkGmtxWWc0PGV1fO5JtY/pLcG1wMyY
vRQERMnAZreMhhuQKxAOxqoOXUW+QpRKkl9DT0oakHpjo/PblgRy1mAOliNl
4HaS8Xp1K+I/L1pbm6IrKAYzMs+0aLPvmwkdHdT7KlATMHQy0VLs7okZYh8d
tDCKEjkFABH4HASJe+nZBs/uuGG2diFkry72UJSOiyvpNa6Vv1LXKbGPwJm5
BUQM4U1ivQM5bEMMDUSsbZ3hmXysOS4iGjdigvlzq5wHdFJQdptFSjNnPPYQ
WHShHIIbVVLDKM8Np3zoOOVjyynmHj/88Bpb+WkvnhBLpJWvrEdYzJhVbXLq
jcoBhxCMr4Xb1VIojK5U02tVXC9Ssyt6FMLFwmLWgWLIcGDFqJPjkKpQg81K
5hoZHXJVRYH8mNSJdIS+z07yJchf1wAiYbpmtdxNy5pqfDCJJtbGwBP4hqHL
BbbwqbQaon9jg2z0h1CrAeNdAY4/y95gs7IraqQDxFOs8tAeNzSFoUVm5CQ3
jVeoW9lEGmfw7t4czoNPW5gWpaEL3quXIUleb6S7a1CxOtqbPo7qG7LEwRBA
Vf+5ci2SI/l2NPODvN+SP8K2J2Z0/3mx28CR/RlbRXmEITnItFqE/QCg4apD
IsYnQ7OxqBSaaiLrvw2RMlOwdEfZ6Cs3CQdmuyZemxRiaogIIEuKwe9ccc29
kKXZq6xKcJ6iKUl1k5h1hTiJTeGSrtQ02sUuHETh0ouJOEOCmJ2MFXKYFf79
1JXuFmMBBGt22k2RZYIMXbHXGZBnyvnKU7/Fjj7yNrPBKYuWlWA3wKRupuKn
k8WYrJXUsOAYDvbKr7ZhDb2clrAKjwuDza9kftTwSgfnDctDNiOVdaHbWRAg
kmGD66kYWwRs85h8E80CG/ecd/N5rB/x6T8s9XqgSNdn1JlHLLy6TVBQRrGk
lA6+tv6N15rhu7eibpj5gDQ4WMl5zIJYg2lChoA7uUFz7cmeiJ0V8OJdUqse
asG457HpM8y7ClV6rOHwiicSV+R6NJHKuZcFhwq1XsPrWNns0h1LpnG3n7rp
my5FIdq/FLYxGZKrCn/4Asx8djCM4cutG3f46FHko0ntU6K1sMbwNvoGWeFE
FPr4wOaIwwGZf84k2yohojTtij34Ejd05dU87azIS0rD1qT6dxwfwpSoJIar
89GZgMWKoZQYc7bmkyT83yZp/GKfx3R4+CJDrq7FQonBwPHvK06dQg3dbLuT
DBZitsm3+uuELaqhlAPOYJ1o4XO/YyHabRWminXcvRjpwS6IxFlj+llkGajc
UIxgYFpMl9DcWUPhL8j3Y4aMeWhzdaqFNIZ+PwYbIpl3A5oTRAtNA2amqAlQ
RNg2K84u6TgsiTLfjD4Um8924+fx60NtAcNZG4XHBts0UYxNc33ddMP5Quio
JopAZ4n0krQOcqn7ATyexgJY5iIY2UqL4WWOiqK8t4511FBEx/Ux0mGYenlx
0LitqfMX0HcuUVOJ1YZKOG0peccFJMGlHo0s6jw5XNOvdlOi2Zo2PbaFFYXK
Uu5RaB83vBwBZ5G1hA4GSbupL3waKmD6/o+iU8TJahNZOa66Rg0zCFWEfFqx
HLijBsoY2BjtATTSfrdiZK+1+QDnWkm+jago3cxB8Rd1Mxjn0sAu9vWlbn0U
u2dlxBRu4VKnA5XX9zX1CxkdlJanmpo26CDsMbNKfaNXLzEizVQ/ojUibqhp
LjVHA1b0y/NAQXBm+N4636kPexA6oIiChJ1bscBc3w7KtvkcmXMiOGLV0KRb
VTTUSU55UdFpH9eqPhCc7dLoKjZXnWU/q41++eoQM42oATP+6/GcUSDsslPe
xDvUVh+4dK6nGqyhjKKms5YN6dWUOYg1WbO0BWp3zk5DLP1KYovYrrUuRTux
pVchVnTSOZGOhDaFrACMb78nRbYn36xzeCkJ0/bLI/4yimyqq6+mnZ5Ul6+O
6cUgtpMMbGaaDXcO4JAyCmmpaWShPxSVMMM/wuGTaPs9gXH74WNRnpPWtpQB
0jmO4DnlAnKuGO8VHw/lBa3qu+q6If8qZffZ00oPYZadybvUeGEo+dKRD7jK
ktVNKQVHOa+4e6gxK6FhRE9MLSxzwARWuymYtgEegR5V4Axr7HjdaTBgBIoB
jtkC08baOfYIKppqwSE3WrgHTjEVuY3qm3rHmNjJqgUZA6+2ak7TlRug54sw
tRdrkIuhLBZoBdINTQF63PwZpp5Km2YSo+WOqRqIee0W9WpHFwWRvxIdPKjb
h+rfdCgSsWYsbikxbIrl+LkFnJ6Wjx05RGSGJExegN/UFbvKMfiAKvwGb3Kg
vQYrBH3txnDTrp8Y1qub94QcjFYhG4xKyEDT598/x8rnZqVncSONyW2psVZR
hjSBtOOdZMFvSNXEBd/lO6lMJ58Qy60y5zpzm3wuU8z2ZgtpclDs4UoxzT2h
9ySplZMlJfMAePZQvgKnquTehJC0nhvNRrzYRmAXHbns5AdtwquBUjScNxC9
xyE2SrTITSVslrK02ZTYA0cDuS0UN44wdt0ZiK3YSwrLzocdXySB1WO1zw1G
Mif4uEw3Xsv0Q1BRQoMMvYFopoXf0Oa5ixd53CSwSaCwlc2R4DuSUpnJ7H6R
NiTDQt8bIz7V5SsIlwowBjqiJSnCXyG0yOUHqhKaol8vhBi1gobQk/62OiCw
xX67AJsSQX3zuMwcd6Hs3zRBykPnd1WGyAKka8BMW8KTjn0JiB2KmoDRlCAD
u6amsS3lbarGjNO8fGqn0fYYiecrfvhcp6F2u/Su3+8Ki989/UVbjVrWQFk2
bA3NbX2mZLEa/2XqfyBcp4ZnNueBzvzeTAeTz9Cl1m6bpQQ/o7FCM1uFvDOO
qn2GGPA31ro7Hx+Zj9npSxmqwQgLoc4JCynKx5owAlLYj4F4P4efRLMumBzW
kuMEWB6fM1GTd6217fM7e5GS9dKJZ9HezDWAIUXw5HG3Kc5uRB7W65tk6Am9
wJvWxuWoC8CF3vr0oqaIMzvbfaq6RzcjeuTI44LrXNZIwSjXqZshRpM1BTde
rQXSF0lV1FtlTdQgZ5ZpInFw33PQPGdpr4Og/MVRJtq2AS+r8yiaCn+jiis2
4Ab1htMI6SJE7g1KMonQSOxzwSVyd4C2g84OpqnOa6ZBKycZsl1MbsR0d1Fi
y/ump8sNZwoQD+3w5dCLCF6XULBdVKfHbd7JM9PVcjIZES0pYxqMSh13aObK
rVWLHFOj1YmQcyMVUsXlU8oZJ7/TLLvgAp2wDrFS8z5Dx9KigA8SJSJIIvMf
8q7aZrs5WmJ1TU0ikV0N6nkdLZc358WApIYclEbyxbcoqqY3FUqvDCr1IO0n
9D2Lp3q/l1RYa5MXPvRU4RTZVU29PWpKOYj9W6xDlDl0rG7oIJKJ/MbiNnOs
Mbl3nyOWnCLw07XjRD6RuEJFCyfXD5IwNWPwF1JhoyH7O+xyCp+wPUFEQO5a
m54TshMJCDDF31xT94wLvXAHmRs5r2J7Xkm5JoVILnxtMESHaVuFvT6TQx7k
56HW9lSPIWzGgJCawO5Qf9EeO6rl9lqQdemN7ZCQmKYUJ07G985tpICtiktg
ZP0j4P8NohTe652UTcLsZOEmESUKKVKCdKQZjtpFsdOXH50t2SZYDCUK2FCd
pFgwTGxBQ3pTZ6Dycm0vV7I0edBegQLoYgjJaeGVxEAEvxxeIk+B/J0T+esR
xy6J2KYR9UEKCunVq6LPBCUUvWQdFYJUgcGWrP127dgxC0TRpqZrRemWhIHE
8sJr6aA2YByI3zDuE2DNqCGOrG3BC212P7RAhHFlXFqmORhdP8PCU/oTdY1v
7HPj8D5dGELQCuT7VPyZNt+GGrnvuXT269Pw+p0XdaH7hqbLpCV9U2jca5yw
g90CsVDXORQxJbO07xRlzcU03k5ykSQLSQK50rJSxOUVX0RXx8IfUi0oO9Au
gMUfZiTxl5U2S8/kIir2COA5cIxT/GMwaLy1eSY180Gbi+3TySLaeydpeneo
JA4gMwiOtW4HWsweV/1wrNNQnJSDq2NWyOwl0LSEboQ2lHwM2ByUYxeNFz7e
fkg3WJu2ySdJf4z2LAqgwqYA0VvifZzk9uxe5drxxQUWrO2ZXYBgpoFsHAZV
hlgcL+4n2w4VWwc48bzpXaflTk+Js5qor1+rDTG7XeFDRS2x8ChraylOSZo9
BpYLCL8qUHnBa5S1hR58S2VteBMxomTo/pvkI61Wg4qmZj/LTHxZrWr41N0S
xNSUNBxsGkpDPnlOKU02vak/fLxIlaroN1vSqF0PT2JfMzawYtZsyCnDwltN
KOvH54Qsi1DxzZf0GuYopB0FV8oLtVV6Rgn5asBk6tGThnYUYQoNCWMvckkQ
EItg3w3WlJDFftZo9KYt2EejfelIAVdQ2WCnUDswEameN9RfoXPxkrZCQHQx
EWiQIJrJRBcN0gBOlDTp8MaRsajHcG/KiK8uts1cx+RaYbI+lHHU8Wij/uRp
FlafubTNXmatpVWhDtOrS5kobfCSDtsHsktEoqAnKd/K/m03EebIuqdZ2go/
veSZd8dhK6/lYabHaSyflwg2kgS3tNA+ecVtvrzHQB7qLW/aUXfbs0+ycM21
7aaex+q/zl1JuVbNowPGq1+tV1te2daCGNKUYZAiCREAykAYHqPZZ+bOD42Z
y/a05bSqLFrL2DHRxVYICac2W5qXOKwRhW4feLsyi2ZpDE36W0xgDdGeGOrA
cAAoz+oT1BvsybAi32e8/DUUE3NkL+QVxcavXNdo266klpiONTFRenOlRDfb
0ffNBykAoIvCNd4R1Edfl3wx3dra5bQzuscQb5DXAscIAe0ZQEtivJxuOJOd
rziTCw1Ny+fStfZKClKKOQWHSZj6X5SsJknP4cSzpepFyFjn9ALR9dNXJXVT
2lUYeNhJkk8aVjmScn5tv1GG50pVGisuDHBtPw++cDsl1OzjgyKv8s/dXp3S
lSS9ovvyxt7K1O42chvVT+9eCZnnHLbd5FqERwjD93XXpZfFxzagnP8gZ8kW
NyqlE6Y33wbnEFvufEXoaYsciL952cB8GML6Bt3xLm/1kpruOk07DXOxqAR/
YxKG6S5CWu9C9lGSUw9ZplZIIPPFazgof5hzmRWvkjqGghl3b0GxNXFg7qYl
Dgl0RBJMm6cbBQqbwoMxxXUtdzci+Gu+p4dlki2fIHVogh5xVNnIdcZ2mWRr
B59CR4Fr+U7l6XQKpLd8j+hz5vCdLEh4wJ0o7fmGSZN96YPDKLmenPLz05K3
PYp/XanyfJJKw+4t8JPAxQIF9u98N46PjsEXdQiue6GO6VFEAk3JnebiL927
Dua7eEF8Nk6U5XYsqWuez4kUMdmlsCwGCyfGkzKAV76A0l7Bruo7cs5JTUgs
uuHWD4iZhheq/yfWS8SDJdfpimLpdxywQkuUS917GnxXAyvESwiM4bquV5pa
E01fuvMTp2R8Jp2Z8dg69G0RTPceG72WWAEajaG+rvh9KGLiguVlDecb3N5E
T7NBZZY63od+/qL9yUDUgSO5VChINKv59q4UxRYsa7DBiPNoG4KaLtK9mVKF
Mssf1t7FHKageFAzuz19mFP+RT4Q9fMbT24wQDFMPtKYRQcjEE2EypGLe7Dn
KVdAstJI8uxD4TTwqEm5ZIDsvxPse6kJInW06jeBaEFFnkg5iVVEQxwg0FoH
D8kntidwoqxSpFLUt2N3Cz0IdILSqSOpRGiREwAZGprA6GSyTeRNm3eM7sgd
VhyYpsvO8SiDuyaINLnUhA/iK+7S0lvITG2vdvsKXrsqhJSQDVRGMsb4C3fz
WlArveu8WVFHfarqqdU4ZBcu1aBzzfxSLrhXyIjzZBd0H41sGzh+LzzABOt1
GNxAvMlLzzuYm9HdYq+HW0e2+iX/W3JXy31XuvENLuN/4KqicafIQRKCyo6u
RxyLYlAsQ04yzdCVIAA6N4zfTNr+1NRWKMYcjVuADnhdeC2+iGyAv+LgqZqk
enMJXSKOuipanledNYb6XlRiOejcLc1Dm89VlPyI1XnUMhyUsC3GFK/ZiXmT
3xZ1MwAyUic/tBJrdR/ckps1i+7PH24bZQdm7Ij6sTNSr0V85D2BpIj7ovQm
MonXupykG899lOxSoN87i2i9a5siH7CM1DpiOGHmnFF1SnSc3t1jvXRR0vYu
c0gq+pkdJMwy5ESnsVEqGI02gOwqRuBNrw3eRyCVHLsYko6nSUzC0WPLP74U
KHCR5a57RRBw1HqV72Sd2yrqFJpdgWwqnCsBn/rm+HCZW/FB71OK2PcsUe7U
VTpwJ1cu11RRqjcRgGu091pr2wGSOoMwoupZTkTsTB8R3uYbjIvqCs6iWqq6
GBmBeGW0CV04FRsdVEdeTHWQAFKOMCc7tKWmk7kG/4vK/hQT3Iu1myibZQGX
9lBtSfwxfs2yF8qawi1lqoQNJVpwdXhQeyOgKVZpMF+qen1S+DcJt3xTFQVn
V8Ju9FqpYPcSGoiCIwqZZnZhSOZGemVwuSZbQzanS9QgiRiorpGmg1GNJidl
NTXV9OwCySnXJmNNihMqGwPWsCSjR+DuoRmaVImgLN+q4qhsyvB6TLQL+TYD
FU/qdpDsCHLURXZDGfyaEqsNY2MRG39EIWFM0qCVqbXducxkOE6+P76tfSBC
91apkKawtmmrShkiGsn2+R1dNx0yuW2GHFshBkljX+DrhuIQlNmBNSfs5JC0
cQ1h8m4lnBuqsWCQIHTJkWeC1RjSoJEn/cmDHxR4tkMt130gaRtBEW5LaiiM
uQrluZyJF/2KceykKR+bnmXJuZFFVVH1yRkYLlRCkie3gq65O0L3llNb1Rt9
aKFNmG8FPXWx2OuhDmjAnu87ISUYdbMVZ368r8pW40rdpynKlXwBNOJfKHND
YpZAId5dxgPZ3hVcOVcEN1L4TFYQGlWzp1GzfOEb9vuHu8Osc5cgwC5r/bVN
xOUk44ubNlsjrrU57nAZuNyjxkqc9I5GhmXkb2dKucgUf57DkOV2TYovpQJu
W2mfQKoASEzibGQU0Kr41rBoklBwglqXIlRQgFSd6cSXRkX4beS2yeycBj/H
blRcLZmUatqR1kzoOetCKTwYSDJBPAkpkefABz6OJMt3bolPH5ENdXN82L1U
jsJj1MgjXlYmworQhdUxSXgNtazsssQb7glfxRuPZjP+bK/ztnW7HKiKF4R/
7iV9d1ppkWahrdY/M/xSK1T7aeLmqpBTwMcasz8NfQlHZSVIu9mtOI8rgJz0
HQOluM7WADLWauldSotdyMcXI+gyzhwyM9TvGT2HHgZY59pzUFyCPTcbp/zB
/H9zvjMAuR7RXxhakNza++236jxp03wMKk07f3H59t0FHkZRqdlLxSM19dYE
3lBc4WmX+Y5Tnz4B5WefmAg/BeECM3/CAkeq4O82itJmUaeH2FqJerN9Sk9J
MhUmsZuTKDm2T2BI92a9QwQvSFYYjfye3A/q9MjMIi2kdDTpNMgNsaR9fLez
XTrYsR0MN0AH2Bk2tqfiph/RpOAet6FfVTL0o+7QG7ANB/NIeM6kwJ979NkC
/3Twx8PrTrQdySxGLtbRSLAtAhX1pdV8nTmeDM+RNPhN+pQONFdNbkgzKgAC
0jwjc3+qHTgaR9e5f90qnyarPBIwU0f1Sip5k/ZTibr1xZaME+lvSM5q8sCg
B5/e5sorWcykhxa2hxl2FvrSIgebTQ6seTJQCEM9v2N3sz0r6vU8+0StjgYP
uUOn/Q6RHSobXpM2ZduzoIFWbfOXxESEl8QFIQS46yhXkcccVccH8snUxfJA
R3agLzUi50pjDTz3Bzu2g6WViQywHuLvXxj2ng701en0G2yd/oC0ampxPTDk
8p8dkhwrtlV2f/BHdu/Sn0Ud05Nub92sdFdUF0hOsaa4LjCtnkuo+kM/tkP3
+i8JX0w7L90D2CdmNHTeaGvE0I4xXvzgI4H2hnnKw/C2bbELNUvjgnktoeln
mfXGu0wwukcnmFkljWtFfPGdZUjwFCfTPCEqxgrEAKpISa7b/nwW8TUcxLXq
vH+98pw8vp3cHLnYsT+oJYBgJPQuvqVLb0WP6o9hEUkvxD08ei534cLHbjPw
lcUR8atfs+YHQqIqWjQcNfX/6L8fH/eHOEtOYK/4JtgazyU9HiSJs6N7BjQd
AuOIElbQlM3+iALf5/cvUTUSZc/SM78awuOLwwQP+je8KiVNojwk4t27yIuj
L4z4jVfrATWtoWYpImk6A786bMzI8QIgXd/g6u9fK7ULMGeUVnYERrBPbRoa
8OirBxxQuYYGPP7qAYP8tU6dgREfff2I0bdzTZZer1R/YPjHVsrsGx54i7zS
+f6FPREDGW0ZA9aqMMJOo5j+SMlRJHWPhkdL8WGscuyPk5xA2tsmCrh+k51/
RMady655yUP6kZxH9NxZY6U7mt15rjuVcj8KYMZLsopYtMdtYui1b7y9Oas/
QQIS2z2bXaByG0OSuAHPDmML7d6QPx8OCNTI3UBEN1ixUZEVaMtdTJ+//qAp
IFJnJ9+HpUscar09MGAq4fY31o76VNJWG8vVhrSJ84QNFx/SMGi3MIQqh/Yy
tZd6/I9Vqe32dQlUqJLia1jbG7vEbvNHYehaQ6P8bV//SM2H+dRxhvFERwYT
knZrNcauV5g1EN3brFtNYqE0a0QDQ8fmzZeDbs+JLRi+Ch1LYkatdBru+s6w
i/OD7Ewf/aHw6DeB6aotDuVWvx1T8ja+90JqikDNmj48PBmNvpNU7kHbVmub
O/d8eA5NU5zU3O8R4k37b/joXIyjF4lMHz5k1xbGf9nISS6kJzu8bhb5Sovk
MFQfOhuE5VLsaeM00E93CMlUHgTIbUh257vzZrD7gXs4jLEf7h9se20gKMyQ
msOzwe4PX7itQhrfktvQ2MfS4XR/g2rCPSTs2GCfk+nj7Qx5xakguhk4GfyN
Or5paZldU1DoEDBWvZPFdTt4c1q6tA8XUoY5GAZSSd5tmy/7kuiyScbQ2/2S
i0csggy3HO80GudylLRTBLn5uWeTNhmnruMUkueboWC/p7EjmsiomKjD3XnS
pjzwLUZJMG8X0EvS7Wx6u6TKh+wbcaLjXBfAYANuY+RUdQoTdzkhrxE3fJ6Q
zi03Qk3EktZLADCVEsBzpy29SIiq95UCM6dLRCrsTUA0OcwZ3gC+pO+F9CLq
OxliMnHo/wd9EdkjVLcAAA==

-->

</rfc>
