<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-opsawg-rfc5706bis-07" category="bcp" consensus="true" submissionType="IETF" obsoletes="5706" updates="2360" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Operations &amp; Management Considerations">Guidelines for Considering Operations and Management in IETF Specifications</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-opsawg-rfc5706bis-07"/>
    <author fullname="Benoit Claise">
      <organization>Everything OPS &amp; Arrcus</organization>
      <address>
        <email>benoit@everything-ops.net</email>
      </address>
    </author>
    <author fullname="Joe Clarke">
      <organization>Cisco</organization>
      <address>
        <email>jclarke@cisco.com</email>
      </address>
    </author>
    <author fullname="Adrian Farrel">
      <organization>Old Dog Consulting</organization>
      <address>
        <email>adrian@olddog.co.uk</email>
      </address>
    </author>
    <author fullname="Samier Barguil">
      <organization>Nokia</organization>
      <address>
        <email>samier.barguil_giraldo@nokia.com</email>
      </address>
    </author>
    <author fullname="Carlos Pignataro">
      <organization>Blue Fern Consulting</organization>
      <address>
        <email>carlos@bluefern.consulting</email>
        <uri>https://bluefern.consulting</uri>
      </address>
    </author>
    <author fullname="Ran Chen">
      <organization>ZTE</organization>
      <address>
        <email>chen.ran@zte.com.cn</email>
      </address>
    </author>
    <date year="2026" month="September" day="07"/>
    <area>Operations and Management</area>
    <workgroup>Operations and Management Area Working Group</workgroup>
    <keyword>management</keyword>
    <keyword>operations</keyword>
    <keyword>operations and management</keyword>
    <keyword>ops considerations</keyword>
    <abstract>
      <?line 91?>

<t>New Protocols and Protocol Extensions are best designed with due
   consideration of the functionality needed to operate and manage them.
   Retrofitting operations and management considerations is suboptimal.
   The purpose of this document is to provide guidance to authors and
   reviewers on what operational and management aspects should be
   addressed when writing documents in the IETF Stream that document a specification for New Protocols or Protocol Extensions or describe their use.</t>
      <t>This document obsoletes RFC 5706, replacing it completely and updating
   it with new operational and management techniques and mechanisms. It also
   updates RFC 2360 to obsolete mandatory MIB creation. Finally, it introduces a
   requirement to include an "Operational Considerations" section in new RFCs in
   the IETF Stream that define New Protocols or Protocol Extensions or describe their use (including relevant YANG
   Models), while providing an escape clause if no new considerations are identified.</t>
    </abstract>
  </front>
  <middle>
    <?line 107?>

<section anchor="sec-intro">
      <name>Introduction</name>
      <t>Often, when New Protocols or Protocol Extensions are developed, not
   enough consideration is given to how they will be deployed,
   operated, and managed. Retrofitting operations and management
   mechanisms is often hard and architecturally unpleasant, and certain
   protocol design choices may make deployment, operations, and
   management particularly difficult or insecure.
   To ensure deployability, the operational environment and manageability
   must be considered during design.</t>
      <t>This document provides guidelines to help Protocol Designers and Working
   Groups (WGs) consider the operations and management functionality for
   their New Protocol or Protocol Extension at an early phase in the design
   process.</t>
      <t>This document obsoletes <xref target="RFC5706"/> and updates its content
   with new operational and management considerations. It also
   introduces a requirement to include an "Operational Considerations"
   section in new RFCs in the IETF Stream that define New Protocols or
   Protocol Extensions or describe their use (including relevant YANG
   Data Models). This section must cover both operational and management considerations.</t>
      <t>Additionally, this document updates Section <xref target="RFC2360" section="2.14" sectionFormat="bare"/> of RFC 2360 <xref target="BCP22"/> on "Guide for Internet Standards Writers"
   to obsolete references to mandatory MIBs and instead focus on documenting holistic manageability and operational
   considerations as described in <xref target="sec-doc-req-ietf-spec"/>. The update is provided in <xref target="sec-2360-update"/>.
   Further, this document removes outdated
   references and aligns with current practices, protocols, and
   technologies used in operating and managing devices, networks, and
   services. Refer to <xref target="sec-changes-since-5706"/> for more details.</t>
      <section anchor="sec-this-doc">
        <name>This Document</name>
        <t>This document provides a set of guidelines for considering
   operations and management in an IETF technical specification
   with an eye toward being flexible while also striving for
   interoperability.</t>
        <t>Entirely New Protocols may require significant consideration of expected
   operations and management, while Protocol Extensions to existing, widely
   deployed protocols may have established de facto operations and
   management practices that are already well understood. This document does
   not mandate a comprehensive inventory of all operational considerations.
   Instead, it guides authors to focus on key aspects that are essential for
   the technology's deployability, operation, and maintenance.</t>
        <t>Suitable operational and management approaches may vary for different areas, WGs,
   and protocols in the IETF. This document does not prescribe
   a fixed solution or format in dealing with operational and management
   aspects of IETF protocols. However, these aspects should be
   considered for any New Protocol or Protocol Extension.</t>
        <t>A WG may decide that its protocol does not need interoperable
   operational and management or a standardized Data Model, but this should be a
   deliberate and documented decision, not the result of omission. This document
   provides some guidelines for those considerations.</t>
        <t>This document recognizes a distinction between management and operational
   considerations, although the two are closely related. However, for New
   Protocols or Protocol Extensions only an "Operational Considerations" section is required.
   This section is intended to address both management and operational aspects.
   Operational considerations pertain to the deployment and functioning of protocols
   within a network, regardless of whether a management protocol is in active use.
   Management considerations focus on the use of management technologies, such as
   management protocols and the design of management Data Models. Both topics should
   be described within the "Operational Considerations" section.</t>
        <t>It is possible that the operational considerations will require significant amounts of text and need to be presented in
   a separate document. This saves the protocol specification from becoming overwhelmed or bloated. In this case the
   Operational Considerations section may contain just a short overview description of the material and a reference to
   other documents that contain the details, but those references must be normative.</t>
      </section>
      <section anchor="sec-audience">
        <name>Audience</name>
        <t>The guidelines are intended to be useful to authors
   writing protocol specifications.
   They outline what to consider for operations, management, and deployment, how to document
   those aspects, and how to present them in a consistent format.
    This document is intended to offer a flexible set of
   guiding principles applicable to various circumstances. It provides a framework for WGs
   to ensure that operational considerations are an integral part of the protocol design process, and
   its use should not be misinterpreted as imposing new hurdles on work in other areas.</t>
        <t>Protocol Designers should consider which operations and management
   needs are relevant to their protocol, document how those needs could
   be addressed, and suggest (preferably standard) management protocols
   and Data Models that could be used to address those needs. This is
   similar to a WG that considers which security threats are relevant to
   their protocol, documents (in the required Security Considerations section,
   per Guidelines for Writing RFC Text on Security Considerations <xref target="BCP72"/>)
   how threats should be mitigated, and then suggests appropriate standard
   protocols that could mitigate the threats.</t>
        <t>It is not the intention that a protocol specification document should be held up waiting for operations and management solutions, or for supporting tooling, to be developed.  This is particularly the case when a protocol extension is proposed, but the base protocol is missing operations or management solutions.  However, it is the intent that new documents should clearly articulate the operations and management of that new work to fill any such gaps. Some operational and tooling guidance can only be determined through deployment experience. In such cases, authors should document what is reasonably foreseeable at design time.</t>
        <t>A core principle of this document is to encourage early-on discussions rather than mandating any specific solution.
   It does not impose a specific management or operational solution,
   imply that a formal Data Model is needed, or imply that using a specific management
   protocol is mandatory. Specifically, this document does not require developing solutions to accommodate
   identified operational considerations within the document that specifies
   a New Protocol or Protocol Extension itself.</t>
        <t>If Protocol Designers conclude that the technology can be
   managed solely by using Proprietary Interfaces or that it does
   not need any structured or standardized Data Model, this might be fine,
   but it is a decision that should be explicit in an operational considerations discussion
   -- that this is how the protocol will need to be operated and managed.
   Protocol Designers should avoid deferring operations and manageability to a later
   phase of the development of the specification.</t>
        <t>When a WG considers operations and management functionality for a
   protocol, the document should contain enough information for readers
   to understand how the protocol will be deployed, operated, and managed. The considerations
   do not need to be comprehensive and exhaustive; focus should be on key aspects. The WG
   should expect that considerations for operations and management may
   need to be updated in the future, after further operational
   experience has been gained.</t>
        <t>The Ops Directorate (OpsDir) can use this document to inform their reviews. A list of guidelines and a
   checklist of questions to consider, which a reviewer can use to evaluate whether the protocol and
   documentation address common operations and management needs, is provided in <xref target="CHECKLIST"/>.</t>
        <t>Similarly, the Performance Metrics Directorate <xref target="PERFMETRDIR"/> can use this document,
   together with the guidelines in <xref target="RFC6390"/>, to inform reviews of the performance management aspects
   of a New Protocol or Protocol Extension.</t>
        <t>This document is also of interest to the broader community, who wants to understand, contribute to,
   and review Internet-Drafts, taking operational considerations into account.</t>
      </section>
    </section>
    <section anchor="sec-terms">
      <name>Terminology</name>
      <t>This document does not describe interoperability requirements. As such, it does not use the capitalized keywords defined in <xref target="BCP14"/>.</t>
      <t>This section defines key terms used throughout the document to ensure clarity and consistency. Some terms are drawn from existing RFCs and IETF Internet-Drafts, while others are defined here for the purposes of this document. Where appropriate, references are provided for further reading or authoritative definitions.</t>
      <ul spacing="normal">
        <li>
          <t>Cause: See <xref target="RFC9940"/>.</t>
        </li>
        <li>
          <t>CLI: Command Line Interface. A human-oriented interface, typically
    a Proprietary Interface, to hardware or software devices
    (e.g., hosts, routers, or operating systems). The commands, their syntax,
    and the precise semantics of the parameters may vary considerably
    between different vendors, between products from the same
    vendor, and even between different versions or releases of a single
    product. No attempt at standardizing CLIs has been made by the IETF.</t>
        </li>
        <li>
          <t>Data Model: A set of mechanisms for representing, organizing, storing,
    and handling data within a particular type of data store or repository.
    This usually comprises a collection of data structures such as lists, tables,
    relations, etc., a collection of operations that can be applied to the
    structures such as retrieval, update, summation, etc., and a collection of
    integrity rules that define the legal states (set of values) or changes of
    state (operations on values). A Data Model may be derived by mapping the
    contents of an Information Model or may be developed ab initio. Further
    discussion of Data Models can be found in <xref target="RFC3444"/>, <xref target="sec-interop"/>,
    and <xref target="sec-mgmt-info"/>.</t>
        </li>
        <li>
          <t>Fault: See <xref target="RFC9940"/>.</t>
        </li>
        <li>
          <t>Fault Management: The process of interpreting Fault notifications and other alerts
    and alarms, isolating Faults, correlating them, and deducing underlying
    Causes. See <xref target="sec-fm-mgmt"/> for more information.</t>
        </li>
        <li>
          <t>Information Model: An abstraction and representation of the
    entities in a managed environment, their properties, attributes
    and operations, and the way that they relate to each other. The model is
    independent of any specific software usage, protocol,
    or platform <xref target="RFC3444"/>. See Sections <xref format="counter" target="sec-interop"/> and <xref format="counter" target="sec-im-design"/> for
    further discussion of Information Models.</t>
        </li>
        <li>
          <t>Network Device: A device that implements one or more network
    protocols and participates in network operations. This term
    encompasses a broad range of implementations, including conventional
    network infrastructure equipment (e.g., routers and switches), end
    hosts, Internet of Things (IoT) devices, virtual network functions, and containerized
    workloads. In this document, the term is used generically to mean
    any managed entity implementing the protocol under consideration.</t>
        </li>
        <li>
          <t>New Protocol and Protocol Extension: These terms are used in this document
    to identify entirely new protocols, new versions of existing
    protocols, and extensions to protocols.
    The application of New Protocols and Protocol Extensions to different
    scenarios, and their use in delivering services, procedures, mechanisms,
    or applications, falls within the scope of this definition.</t>
        </li>
        <li>
          <t>OAM: Operations, Administration, and Maintenance <xref target="RFC6291"/>
            <xref target="RFC10014"/> is the term given to the
    combination of:  </t>
          <ol spacing="normal" type="1"><li>
              <t>Operation activities that are undertaken to keep the
network running as intended. They include monitoring of the network.</t>
            </li>
            <li>
              <t>Administration activities that keep track of resources in the
network and how they are used. They include the bookkeeping necessary
to track networking resources.</t>
            </li>
            <li>
              <t>Maintenance activities focused on facilitating repairs and upgrades.
They also involve corrective and preventive measures to make the
managed network run more effectively.</t>
            </li>
          </ol>
          <t>
The broader concept of "operations and management" that is the
 subject of this document encompasses OAM, in addition to other
 management and provisioning tools and concepts. This is
 sometimes known as "OAM and Management" or "O&amp;M" as
 explained in <xref target="RFC6291"/>.</t>
        </li>
        <li>
          <t>Operator: A person or organization responsible for deploying and managing
    systems, services, or networks that run or rely on a protocol implementation.
    This includes, but is not limited to,
    network operators, cloud service administrators, IoT device fleet
    managers, home network administrators, and DNS/NTP server
    administrators. The term "operator" is used throughout this document
    in this broad sense unless the context explicitly requires a narrower
    scope.</t>
        </li>
        <li>
          <t>Performance Metrics: See <xref target="RFC7799"/>.</t>
        </li>
        <li>
          <t>Probable Root Cause: See <xref target="I-D.ietf-nmop-network-incident-yang"/>.</t>
        </li>
        <li>
          <t>Problem: See <xref target="RFC9940"/>.</t>
        </li>
        <li>
          <t>Proprietary Interface: An interface to manage a network element
    that is not standardized. As such, the user interface, syntax, and
    semantics typically vary significantly between implementations.
    Examples of proprietary interfaces include CLI,
    management web portal and Browser User Interface (BUI),
    Graphical User Interface (GUI), and vendor-specific application
    programming interface (API).</t>
        </li>
        <li>
          <t>Protocol Designer: An individual, a group of
    people, or an IETF WG involved in the development and specification
    of New Protocols or Protocol Extensions.</t>
        </li>
        <li>
          <t>Technical Document:
    This includes any document that describes the
    design, specification, implementation, or deployment of a new Protocol or Protocol Extensions.</t>
        </li>
      </ul>
    </section>
    <section anchor="sec-doc-req-ietf-spec">
      <name>Documentation Requirements for IETF Specifications</name>
      <section anchor="sec-oper-manag-considerations">
        <name>"Operational Considerations" Section</name>
        <t>All Internet-Drafts that document a technical specification for a New Protocol
   or Protocol Extension or describe their use are required to include an "Operational Considerations" section
   if it is the intention that they will be advanced for publication as IETF RFCs.
   Internet-Drafts that do not document technical specifications, such as process, policy, or administrative
   Internet-Drafts, are not required to include such a section.</t>
        <t>After evaluating the operational (<xref target="sec-oper-consid"/>) and manageability (<xref target="sec-mgmt-consid"/>) aspects of a New
   Protocol or Protocol Extension, the resulting practices and
   requirements should be documented
   in an "Operational Considerations" section within the
   specification. Since protocols are intended for operational deployment and
   management within real networks, it is expected that such considerations
   will be present.</t>
        <t>It is also recommended that operational and manageability considerations
   be addressed early in the protocol design process. Consequently, early
   revisions of Internet-Drafts are highly encouraged to include an "Operational
   Considerations" section.</t>
        <t>An "Operational Considerations" section should include a discussion of
   the management and operations topics raised in this document.
   When one or more of these topics is not relevant, it would be helpful
   to include a brief statement explaining why it is not
   relevant or applicable for the New Protocol or Protocol Extension.
   Of course, additional relevant operational and manageability topics
   should be included as well. A concise checklist of key questions is
   provided in <xref target="sec-checklist"/>.</t>
        <t>The section is always present. What it contains depends on the case:</t>
        <ul spacing="normal">
          <li>
            <t>Where the New Protocol or Protocol Extension raises operational and
manageability considerations, the section discusses the relevant
topics raised in this document.</t>
          </li>
          <li>
            <t>Where one or more of those topics is not relevant, the section
briefly explains why.</t>
          </li>
          <li>
            <t>Where there are no new operations or manageability requirements at
all, the section contains the statement in <xref target="sec-null-sec"/>, followed
by a brief rationale.</t>
          </li>
          <li>
            <t>Where the considerations are already described in other parts of the
same document, the section summarizes them and points to the relevant
sections rather than repeating the material.</t>
          </li>
          <li>
            <t>Where the considerations require significant text and are presented in
a separate document, the section contains a short overview and a
normative reference to that document, as described in
<xref target="sec-this-doc"/>.</t>
          </li>
        </ul>
        <t>For New Protocol or Protocol Extension specifications that contain
  Data Models (e.g., YANG) and other schema artifacts (JSON schema, YAML, CDDL, etc.), such artifacts
  may be consumed out of the RFCs that specify them. As such, it is recommended
  that operational aspects for a Data Model (and similar artifacts) are
  documented as part of the model itself. Such considerations should not be
  duplicated in the narrative part of a specification that includes such artifacts.</t>
        <t>For example:</t>
        <ul empty="true">
          <li>
            <t>Readers may refer to the following non-exhaustive list for examples of specifications, covering various areas,
with adequate documentation of operational considerations, including manageability: <xref target="RFC9953"/>,
<xref target="I-D.ietf-suit-mti"/>, <xref target="RFC9937"/>, <xref target="RFC7574"/>, <xref target="RFC9877"/>, and <xref target="RFC9552"/>.
Given the various available transport alternatives, <xref target="RFC9953"/> discusses co-existence with
those and clarifies some key deployment aspects such as redirection, forwarding loop prevention, and error handling.
Also, <xref target="I-D.ietf-ippm-ioam-integrity-yang"/> is an example of a document that follows
the above guidance by documenting operational aspects as part of the YANG module itself.</t>
          </li>
        </ul>
        <t>For architecture documents, an "Operational Considerations" section is expected only where the architecture introduces new operational considerations with normative implications for downstream protocol designs. When included, it should focus on describing the intended deployment environment, assumptions about network operations, potential impacts on existing operational practices, and any high-level requirements that future protocol designs should address. It is not expected to detail specific configuration parameters or management interfaces unless they are integral to the architecture itself. If the architecture document does not introduce new operational considerations, the exemption statement in <xref target="sec-null-sec"/> applies.</t>
      </section>
      <section anchor="sec-null-sec">
        <name>"Operational Considerations" Section Boilerplate When No New Considerations Exist</name>
        <t>After a Protocol Designer has considered the manageability
   requirements of a New Protocol or Protocol Extension, they may determine that no
   management functionality or operational best-practice clarifications are
   needed. It would be helpful to
   reviewers, those who may update or write extensions to the protocol in the
   future, and those deploying the protocol, to know the rationale
   for the decisions on the protocol's manageability at the
   time of its design.</t>
        <t>If there are no new manageability or deployment considerations, the "Operational Considerations" section
   must contain the following simple statement, followed by a brief explanation of
   why that is the case.</t>
        <artwork><![CDATA[
  "There are no new operations or manageability requirements introduced
    by this document.

    [Brief rationale goes here]"
]]></artwork>
        <t>The presence of such a
   section would indicate to the reader that due
   consideration has been given to manageability and operations.</t>
        <t>When the specification is a Protocol Extension, and the base protocol
   already addresses the relevant operational and manageability
   considerations, it is helpful to reference the considerations section
   of the base document.</t>
      </section>
      <section anchor="sec-placement-sec">
        <name>Placement of the "Operational Considerations" Section</name>
        <t>It is recommended that the section be
   placed immediately before the Security Considerations section.
   Reviewers interested in this section will find it easily, and this
   placement could simplify the development of tools to detect its
   presence.</t>
      </section>
      <section anchor="sec-changes-since-5706">
        <name>Changes Since RFC 5706</name>
        <t>The following changes have been made to the guidelines published in  <xref target="RFC5706"/>:</t>
        <ul spacing="normal">
          <li>
            <t>Change intended status from Informational to Best Current Practice</t>
          </li>
          <li>
            <t>Indicate that this document updates RFC 2360 and add the relevant updated text</t>
          </li>
          <li>
            <t>Move the "Operational Considerations" checklist in <xref section="A" sectionFormat="of" target="RFC5706"/> to a Checklist <xref target="CHECKLIST"/> maintained in GitHub</t>
          </li>
          <li>
            <t>Add a concise "Operational Considerations Checklist" appendix (<xref target="sec-checklist"/>) with key questions that should be addressed in protocol specifications</t>
          </li>
          <li>
            <t>Add a requirement for an "Operational Considerations" section in all new RFCs that document a technical specification for a New Protocol or Protocol Extension or describe their use in the IETF Stream, along with specific guidance on its content.</t>
          </li>
          <li>
            <t>Update the operational and manageability-related technologies to reflect over 15 years of advancements  </t>
            <ul spacing="normal">
              <li>
                <t>Provide focus and details on YANG-based standards, deprioritizing MIB Modules.</t>
              </li>
              <li>
                <t>Add a "YANG Data Model Considerations" section</t>
              </li>
              <li>
                <t>Update the "Available Management Technologies" landscape</t>
              </li>
            </ul>
          </li>
          <li>
            <t>Add an "Operational and Management Tooling Considerations" section</t>
          </li>
        </ul>
      </section>
      <section anchor="sec-2360-update">
        <name>Update to RFC 2360</name>
        <t>This document replaces this text from Section <xref target="RFC2360" section="2.14" sectionFormat="bare"/> of RFC 2360 <xref target="BCP22"/>:</t>
        <blockquote>
          <t>When relevant, each standard needs to discuss how to manage the
protocol being specified.  This management process should be
compatible with the current IETF Standard management protocol.  In
addition, a MIB must be defined within the standard or in a companion
document.  The MIB must be compatible with current Structure of
Management Information (SMI) and parseable using a tool such as
SMICng.  Where management or a MIB is not necessary this section of
the standard should explain the reason it is not relevant to the
protocol.</t>
        </blockquote>
        <t>with the following:</t>
        <blockquote>
          <t>When relevant, each standard needs to discuss how to manage the
protocol being specified. Refer to RFC XXXX for holistic manageability and operational
considerations.</t>
        </blockquote>
        <ul empty="true">
          <li>
            <t>Note to the RFC Editor: Please replace RFC XXXX with the RFC number to be assigned to this document.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-oper-consid">
      <name>How Will the New Protocol or Protocol Extension Fit into the Current Environment?</name>
      <t>Designers of a New Protocol or Protocol Extension should carefully consider the operational
   aspects of real-world deployments, which can directly
   impact its success. Such aspects include
   interactions with existing solutions, upgrade or deployment paths,
   the ability to debug problems, ease of configuration,
   and a state diagram that operations
   staff can understand. This exercise
   need not be reflected directly in their document, but could help visualize how
   to apply the protocol in the environments where it will be deployed.
   <xref target="RFC5218"/> provides a more detailed discussion on what makes for a successful protocol.</t>
      <t>Not every operational consideration can be foreseen at design time. Some considerations reside in how a specification is applied and deployed rather than in the specification itself, and may only become apparent once operational experience has been gained.  In some cases, the relevant questions are not even known in advance. Authors should document what is reasonably foreseeable without speculating, and should expect that operational considerations may need to be revisited as deployment experience accumulates.</t>
      <t>For example:</t>
      <ul empty="true">
        <li>
          <t>BGP flap damping <xref target="RFC2439"/> was designed to block high-frequency route flaps. Some BGP implementations were memory-constrained and elected not to support this function. Others found a conflict where path exploration caused false flap damping resulting in loss of reachability. As a result, flap damping was often not enabled network-wide, contrary to the intentions of the original designers. This behavior emerged only from operational experience at scale, and little text written at design time would have changed the outcome.</t>
        </li>
      </ul>
      <section anchor="sec-install">
        <name>Installation and Initial Setup</name>
        <t>Anything that can be configured can be misconfigured.
   <xref section="3.8" sectionFormat="of" target="RFC1958"/> ("Architectural Principles of the Internet")
   states:</t>
        <blockquote>
          <t>Avoid
   options and parameters whenever possible. Any options and parameters
   should be configured or negotiated dynamically rather than manually.</t>
        </blockquote>
        <t>The New Protocol or Protocol Extension should be able to operate "out of the box".
   To simplify configuration, Protocol Designers should
   specify reasonable defaults, including default modes and
   parameters. For example, define
   default values for modes, timers, default state of logical control
   variables, default transports, and so on.</t>
        <t>Protocol Designers should explain the background of the chosen default
   values and provide the rationale.
   In many cases, as
   technology changes, the documented values might make less and less
   sense. It is helpful to understand whether defaults are based on
   best current practice and are expected to change as technologies
   advance, or whether they have a more universal value that should not
   be changed lightly. For example, the default interface speed might
   change over time as network speeds increase,
   and cryptographic algorithms might be expected to change
   over time as older algorithms are "broken".</t>
        <t>Default values should generally favor the conservative side over the
   "optimizing performance" side (e.g., the initial Round-Trip Time (RTT) and
   Round-Trip Time Variance (RTTVAR) values of a TCP connection <xref target="RFC6298"/>).</t>
        <t>For parameters that can vary (e.g., speed-dependent), instead of using a
   constant, set the default value as a function of the
   variable to reduce the
   risk of problems caused by technology advancement.</t>
        <t>It must always be possible for an operator to retrieve the actual value in use,
   to determine that the element is running at a known
   default. This is important for troubleshooting, auditing, and ensuring
   consistent behavior across implementations.</t>
        <t>For example:</t>
        <ul empty="true">
          <li>
            <t>Where protocols involve cryptographic keys, Protocol Designers should
   consider not only key generation and validation mechanisms but also the
   format in which private keys are stored, transmitted, and restored.
   Designers should specify any expected consistency checks
   (e.g., recomputing an expanded key from the seed) that help verify
   correctness and integrity. Additionally, guidance should be given on
   data retention, restoration limits, and cryptographic module
   interoperability when importing/exporting private key material. Refer to <xref target="RFC9881"/> for an example of how such considerations are incorporated.</t>
          </li>
        </ul>
      </section>
      <section anchor="sec-migration">
        <name>Migration Path</name>
        <t>If the New Protocol or Protocol Extension is a new version of an existing one, or if it is
   replacing another technology, the Protocol Designer should consider
   how deployments should transition to the New Protocol or Protocol
   Extension. This should include coexistence with previously deployed
   protocols and/or previous versions of the same protocol, management of
   incompatibilities between versions, translation between versions,
   and consideration of potential side effects. A key question is:
   Are older protocols or versions disabled, or do they coexist
   with the New Protocol or Protocol Extension in the network?</t>
        <t>Many protocols benefit from being incrementally deployable --
   operators may deploy some aspects of a protocol before deploying
   it fully, or may deploy to only some nodes in a network before applying to all nodes in the network. In those cases, the operational considerations should
   also specify whether the New Protocol or Protocol Extension requires any changes to
   the existing infrastructure, particularly the network.
   If so, the protocol specification should describe the nature of those
   changes, where they are required, and how they can be introduced in
   a manner that facilitates deployment. Where possible, backward-compatible approaches
   should be preferred over non-backward-compatible ones, since they typically provide a
   smoother migration path with lower cost and impact on existing deployments.</t>
        <t>Security operations (<xref target="sec-impact-secops"/>) are important to ensure the stability and security of networks. Good security operation practices should be encouraged when migrating to a New Protocol or Protocol Extension. For example, patching (i.e., installing new versions that have fixes for security vulnerabilities) is fundamental for security operations, and can be made much easier if Protocol Designers consider supporting cheap and fast connection hand-offs and reconnections.</t>
        <t>When Protocol Designers are considering how deployments should transition to the New Protocol or Protocol Extension, impacts to current techniques employed by operators should be documented and mitigations included, where possible, so that consistent security operations and management can be achieved. Note that transitioning between security mechanisms can be challenging, but it is not desirable to take an easier approach if that leaves data in an open or less-protected
state during the transition.
   Refer to <xref target="RFC8170"/> for a detailed discussion on transition versus coexistence.</t>
      </section>
      <section anchor="sec-other">
        <name>Requirements on Other Protocols and Functional Components</name>
        <t>Protocol Designers should consider the requirements that the New
   Protocol might put on other protocols and functional components and
   should also document the requirements from other protocols and
   functional components that have been considered in designing the New
   Protocol.</t>
        <t>These considerations should generally remain illustrative to avoid
   creating restrictions or dependencies, or potentially impacting the
   behavior of existing protocols, or restricting the extensibility of
   other protocols, or assuming other protocols will not be extended in
   certain ways. If restrictions or dependencies exist, they should be
   stated.</t>
        <t>Where a New Protocol or Protocol Extension depends on another protocol or component to function correctly, that dependency is a normative property of the specification and belongs in its main body rather than only in the "Operational Considerations" section, so that implementers and operators can identify it easily. For example, if correct operation relies on an accurate time source (such as NTP <xref target="RFC5905"/>), the specification should state that requirement, and the acceptable means of satisfying it, explicitly.</t>
        <t>Another example:</t>
        <ul empty="true">
          <li>
            <t>The design of the Resource ReSerVation Protocol (RSVP)
   <xref target="RFC2205"/> required each router to look at the RSVP PATH message and,
   if the router understood RSVP, add its own address to the message to
   enable automatic tunneling through non-RSVP routers. But in reality,
   routers cannot look at an otherwise normal IP packet and potentially
   take it off the fast path! The initial designers overlooked that a
   new "deep-packet inspection" requirement was being put on the
   functional components of a router. The "router alert" option
   (<xref target="RFC2113"/>, <xref target="RFC2711"/>) was finally developed to solve this problem,
   for RSVP and other protocols that require the router to take some
   packets off the fast-forwarding path. Yet, Router Alert has its own
   problems in impacting router performance and security. Refer to <xref target="RFC9805"/> for
   deprecation of the IPv6 Router Alert Option for New Protocols and
   Section <xref target="RFC7126" section="4.8" sectionFormat="bare"/> of RFC 7126 <xref target="BCP186"/> for threats and advice related to IPv4 Router Alert.</t>
          </li>
        </ul>
      </section>
      <section anchor="sec-impact">
        <name>Impact on Network Operation</name>
        <t>The introduction of a New Protocol or Protocol Extension may
   have an impact on the operation of existing networks, as well as on the
   hosts, devices, and systems that implement or depend on the protocol.
   As discussed in <xref section="2.1" sectionFormat="of" target="RFC6709"/>
   major extensions may have characteristics leading to a risk of
   operational
   problems. Protocol
   Designers should outline such operational impacts (which may be positive),
   including scaling benefits or concerns, and interactions with other protocols.
   Protocol Designers should describe the scenarios in which the New
   Protocol or its extensions are expected to be applicable or
   beneficial. This includes any relevant deployment environments,
   network topologies, usage constraints such as limited domains
   <xref target="RFC8799"/>, or use cases that justify or constrain adoption.
   For example, a New Protocol or Protocol Extension that doubles the number of active,
   reachable addresses in a network might have implications for the
   scalability of interior gateway protocols, and such impacts should
   be evaluated accordingly. Per Section <xref target="RFC2360" section="2.15" sectionFormat="bare"/> of RFC 2360 <xref target="BCP22"/>, New Protocol or Protocol Extension specifications
   should establish the limitations on the scale of use and limits on the resources used.</t>
        <t>If the protocol specification requires changes to end hosts or network
   infrastructure, it should indicate whether safeguards exist to protect
   both end hosts and devices and the broader network from potential
   overload. Moreover, per Section <xref target="RFC2360" section="2.16" sectionFormat="bare"/> of RFC 2360 <xref target="BCP22"/>, New Protocol
   or Protocol Extension specifications should address any possible destabilizing events,
   and means by which the protocol resists or recovers from them. For instance, a congestion control algorithm must
   comply with <xref target="BCP133"/> to prevent congestion collapse and ensure
   network stability.</t>
        <t>A protocol could send active monitoring packets on the wire. Without careful
   consideration, active monitoring might achieve high accuracy at the cost of
   generating an excessive number of monitoring packets.</t>
        <t>Protocol Designers should consider the potential impact on the
   behavior of other protocols in the network and on the traffic levels
   and traffic patterns that might change, including specific types of
   traffic, such as multicast. Also, consider the need to install new
   components that are added to the network as a result of changes in
   the configuration, such as servers performing auto-configuration
   operations.</t>
        <t>Protocol Designers should also consider the impact on infrastructure
   applications such as the DNS <xref target="RFC1034"/>, the
   registries, or the size of routing tables.</t>
        <t>For example:</t>
        <ul empty="true">
          <li>
            <t>SMTP <xref target="RFC5321"/> servers use a reverse DNS lookup to filter
   out incoming connection requests: when Berkeley installed a new spam filter that used reverse DNS lookup,
   their mail server stopped functioning because of overload of the DNS
   cache resolver.</t>
          </li>
        </ul>
        <t>The impact of New Protocols or Protocol Extensions, and the results
of new OAM tools developed for them,
must be considered with respect to
traffic delivery performance and ongoing manageability. For
example, it must be noted whether the New Protocol, Protocol Extension,
or OAM tools cause increased delay or jitter in real-time traffic
applications, or increased response time in client-server
applications. Further, if the additional traffic caused by OAM tools
and data collection could result in the management plane becoming
overwhelmed, then this must be called out, and suitable mechanisms to
rate limit the OAM traffic must be considered. Potential options include: document the limitations, propose solution track(s), include an optional rate limiting feature in the specifications, or impose a rate limiting feature in the specifications.</t>
        <t>For example:</t>
        <ul empty="true">
          <li>
            <t>(1) In Bidirectional Forwarding Detection (BFD) for MPLS <xref target="RFC5884"/> it is
possible to configure very rapid BFD transmissions (of the order of
3ms) on a very large number of parallel Label Switched Paths (LSPs)
with the result that the management systems and end nodes may become
overwhelmed -- this can be protected by applying limits to
the number of LSPs that may be tested at once.</t>
            <t>(2) Notifications or logs from systems (through YANG or other means)
should be rate-limited so that they do not flood the receiving
management station.</t>
            <t>(3) The application of sophisticated encryption or filtering rules
needs to be considered in the light of the additional processing
they may impose on the hardware forwarding path for traffic.</t>
          </li>
        </ul>
        <t>New metrics may be required to assess traffic performance. Protocol Designers may refer to <xref target="RFC6390"/> for guidelines for considering new performance metrics.</t>
        <t>Protocol Designers should account for MTU constraints when designing protocols that carry management traffic or measurement data, including any reduction in effective payload size introduced by tunnel or encapsulation overhead. <xref target="RFC8899"/> specifies path MTU discovery for datagram transports, and <xref section="6.1" sectionFormat="of" target="RFC8900"/> gives recommendations for protocol developers on avoiding reliance on IP fragmentation.</t>
      </section>
      <section anchor="sec-impact-secops">
        <name>Impact on Security Operations</name>
        <t>Security Operations (SecOps) is a collaborative approach that combines security and operational teams to improve the ability of operators to protect and manage the network effectively and efficiently <xref target="SECOPS"/>. Security operators detect malicious activity and respond to threats and are a crucial part of defending against attacks alongside the management and operation of the network.</t>
        <t>Protocol Designers should consider the impacts of a New Protocol or Protocol Extension on Security Operations in networks that the protocol will be deployed in.</t>
        <t>Security operators extensively rely upon Indicators of Compromise (IoCs) <xref target="RFC9424"/>. The deployment of a New Protocol or Protocol Extension may change the type, locations, or availability of IoCs. Protocol Designers should outline such changes to ensure operators can manage and defend their networks, systems, and devices consistently.
Consider the operators' requirement for digital forensics from the network or endpoints with critical information found in logs. Logging events schema and guidance for operators should be considered when designing a New Protocol or Protocol Extension to ensure operators have the information they need. <xref target="I-D.ietf-quic-qlog-main-schema"/> is an example of extensible structured logging.</t>
        <t>An increasing number of New Protocols and Protocol Extensions encrypt metadata that was previously available to passive inspection, such as QUIC <xref target="RFC9000"/>, TLS 1.3 <xref target="RFC9846"/>, Encrypted Client Hello <xref target="RFC9849"/>, and DNS over HTTPS (DoH) <xref target="RFC8484"/>. This creates a tension between the privacy goals of such protocols and the visibility that security operators have historically relied upon. Protocol Designers should acknowledge this tension and, where passive visibility is reduced, consider alternative diagnostic mechanisms, such as endpoint-based telemetry or logging, that preserve operators' ability to detect and respond to threats without undermining the protocol's privacy objectives.</t>
        <t>Tooling needed by security operators should be considered when designing and deploying a New Protocol or Protocol Extension. Operators may require new tooling or methods for managing network traffic in response to protocol changes to ensure consistent availability and performance of networks. Similarly, updating and augmenting existing forensic tools such as protocol dissectors is expected when a New Protocol is deployed, but having to completely rebuild such tooling would greatly reduce the effectiveness of security operators, so protocol extensibility should be considered. The absence of such tooling is not, by itself, a reason to delay publication of the specification. Indicators of compromise, and the means to detect exploitation, tend to evolve only as operational experience accumulates and as attacks emerge.  Detailed forensic and tooling guidance may therefore be developed after the protocol is specified and is expected to be refined over time (see also <xref target="sec-oper-mgmt-tooling"/>).</t>
        <t>For further information on the security operations considerations discussed in this section, refer to <xref target="I-D.parsons-opsawg-security-operations"/>.</t>
      </section>
      <section anchor="sec-oper-verify">
        <name>Verifying Correct Operation</name>
        <t>An important function that should be provided is guidance on how to
   verify the correct operation of a protocol. A Protocol Designer
   may suggest testing techniques for qualifying and quantifying the impact of the protocol on
   the network before it is partially or fully deployed, as well as testing techniques for
   identifying the effects that the protocol might have on the network after being
   deployed.</t>
        <t>Protocol Designers should consider techniques for testing the
   effect the protocol has had on the infrastructure by sending data
   through it and observing its behavior (also known as active
   monitoring). Protocol Designers should consider how the correct
   end-to-end operation of the New Protocol or Protocol Extension can be tested
   actively and passively, and how the correct data- or forwarding-plane
   function of each involved element can be verified to be working
   correctly with the New Protocol or Protocol Extension.</t>
        <t>Protocol Designers should consider how to test the correct end-to-end
   operation of the service or network, how to verify correct
   protocol behavior, and whether such verification is achieved by testing
   the service function and/or the forwarding function of
   each network element. This may be accomplished through the collection of status and
   statistical information gathered from devices.</t>
        <t>Having simple protocol status and health indicators on involved
   devices is a recommended means to check correct operation.</t>
      </section>
      <section anchor="sec-messages">
        <name>Message Formats</name>
        <t>Where protocol specifications result in messages (such as errors or warnings) being carried as text strings or output for consumption by human operators, consideration should be given to making it possible for implementations to be configured so that the messages can be viewed in the local language. In such cases, it is helpful to transmit a specific message code (i.e., a number) along with the message text, and to include a language tag (as described in <xref target="BCP47"/>) to enable correct identification and rendering in the appropriate language. Protocol specifications should not assume English as the default language.</t>
        <t>Further discussion of Internationalization issues may be found in <xref target="BCP166"/>.</t>
      </section>
    </section>
    <section anchor="sec-mgmt-consid">
      <name>How Will the Protocol Be Managed?</name>
      <t>The considerations of manageability should start from identifying the
   entities to be managed, as well as how the managed protocol is
   supposed to be installed, configured, and monitored.</t>
      <t>Considerations for management should describe what aspects of the system
   require management and the management functions that need to be
   supported. This includes identifying any assumptions or constraints
   relevant to management interactions, such as the types of interfaces or
   protocols required. These considerations should avoid dependence on a
   specific management deployment model and should remain applicable
   regardless of where management systems are located or how they are
   accessed.</t>
      <t>The management model should take into account factors such as:</t>
      <ul spacing="normal">
        <li>
          <t>What type of management entities will be involved (agents, network
management systems)?</t>
        </li>
        <li>
          <t>What is the possible architecture (client-server, manager-agent,
poll-driven or event-driven, auto-configuration, two-levels or
hierarchical)?</t>
        </li>
        <li>
          <t>What are the management operations (initial configuration, dynamic
configuration, alarm and exception reporting, logging, performance
monitoring, performance reporting, debugging)?</t>
        </li>
        <li>
          <t>How are these operations performed (locally, remotely, atomic
operation, scripts)? Are they performed immediately or are they
time scheduled, or event triggered?</t>
        </li>
      </ul>
      <t>Protocol Designers should consider how the New Protocol or Protocol Extension will be
   managed in different deployment scales. It might be sensible to use
   a local management interface to manage the New Protocol or Protocol Extension on a single
   device, but in a large network, remote management using a centralized
   server and/or using distributed management functionality might make
   more sense. Auto-configuration and default parameters might be
   possible for some New Protocols or Protocol Extensions.</t>
      <t>Management needs to be considered not only from the perspective of a
   device, but also from the perspective of network and service
   management. A service might be network and operational functionality
   derived from the implementation and deployment of a New Protocol or Protocol Extension.
   Often, an individual network element is unaware of the service being
   delivered.</t>
      <t>WGs should consider how to configure multiple related/co-operating
   devices and how to back off if one of those configurations fails or
   causes trouble. Network Configuration Protocol (NETCONF) <xref target="RFC6241"/>
   addresses this in a generic manner
   by allowing an operator to lock the configuration on multiple
   devices, perform the configuration settings/changes, check that they
   are OK (undo if not), and then unlock the devices.</t>
      <t>Techniques for debugging protocol interactions in a network must be
   part of the network management discussion. Implementation source
   code should be debugged before ever being added to a network, so
   asserts and memory dumps do not normally belong in management data
   models. However, debugging on-the-wire interactions is a protocol
   issue: while the messages can be seen by sniffing, it is enormously
   helpful if a protocol specification supports features that make
   debugging of network interactions and behaviors easier. There could
   be alerts issued when messages are received or when there are state
   transitions in the protocol state machine. However, the state
   machine is often not part of the on-the-wire protocol; the state
   machine explains how the protocol works so that an implementer can
   decide, in an implementation-specific manner, how to react to a
   received event.</t>
      <t>In a client/server protocol, it may be more important to instrument
   the server end of a protocol than the client end, since the
   performance of the server might impact more nodes than the
   performance of a specific client.</t>
      <t>The subsections from <xref target="sec-fm-mgmt"/> through <xref target="sec-security-mgmt"/> are organized following
   the Fault, Configuration, Accounting, Performance, and Security (FCAPS) network management
   framework.</t>
      <section anchor="sec-mgmt-tech">
        <name>Available Management Technologies</name>
        <t>The IETF provides several standardized management protocols suitable for
   various operational purposes, for example as outlined in <xref target="RFC6632"/>.
   Note that SNMP is no longer recommended for configuration (read-write)
   operations.  Better programmatic alternatives are discussed
   further in Section <xref format="counter" target="sec-interop"/>. This document formally deprecates the following recommendation from <xref target="BCP22"/>:</t>
        <blockquote>
          <t>a MIB must be defined within the standard or in a companion document.</t>
        </blockquote>
        <t>Data collection practice has evolved substantially since <xref target="RFC6632"/> was
   published. Designers should also consider mechanisms developed since,
   including the BGP Monitoring Protocol (BMP) <xref target="RFC7854"/>, subscription to
   YANG notifications <xref target="RFC8639"/> <xref target="RFC8641"/>, and the alarm management
   model <xref target="RFC8632"/>; <xref target="RFC9232"/> provides a framework relating these to
   one another.</t>
        <t>Readers seeking more in-depth definitions or explanations should consult
   the referenced materials.</t>
      </section>
      <section anchor="sec-interop">
        <name>Interoperability</name>
        <t>Management interoperability is critical for enabling information exchange
   and operations across diverse network devices and management applications,
   regardless of vendor, model, or software release. It facilitates the use
   of third-party applications and outsourced management services.</t>
        <t>While individual device management via Proprietary Interfaces may
   suffice for small deployments, large-scale networks comprising equipment
   from multiple vendors necessitate consistent, automated management.
   Relying on vendor- and model-specific interfaces for extensive deployments,
   such as hundreds of branch offices, severely impedes scalability and automation
   of operational processes. The primary goal of management interoperability is to
   enable the scalable deployment and lifecycle management of new network functions
   and services, while ensuring a clear understanding of their operational impact
   and total cost of ownership.</t>
        <t>Achieving universal agreement on a single management syntax and protocol is
   challenging. However, the IETF has significantly evolved its approach to
   network management, moving beyond Structure of Management Information
   version 2 (SMIv2) and SNMP. Modern IETF management solutions primarily
   leverage YANG <xref target="RFC7950"/> for Data Modeling and NETCONF <xref target="RFC6241"/> or
   RESTful Configuration Protocol (RESTCONF) <xref target="RFC8040"/> for protocol
   interactions. This shift, as further elaborated in <xref target="RFC6632"/>, emphasizes
   structured Data Models and programmatic interfaces to enhance automation and
   interoperability. Other protocols, such as IP Flow Information Export
   (IPFIX) <xref target="RFC7011"/> for flow accounting and syslog (System Logging
   Protocol) <xref target="RFC5424"/> for logging, continue to play specific roles in
   comprehensive network management.</t>
        <t>Interoperability must address both syntactic and semantic aspects. While syntactic variations
   across implementations can often be handled through adaptive processing, semantic differences pose a
   greater challenge, as the meaning of data is intrinsically tied to the managed entity.</t>
        <t>Information Models (IMs) enable and provide the foundation for semantic interoperability. An IM defines the
   conceptual understanding of managed information, independent of specific protocols or vendor
   implementations. This allows for consistent interpretation and correlation of data across different
   Data Models (and hence management protocols), such as a YANG Data Model and IPFIX Information Elements concerning the same
   event. For instance, an IM can standardize how error conditions are counted, ensuring that a counter
   has the same meaning whether collected via NETCONF or exported via IPFIX.</t>
        <t>Protocol Designers should consider developing an IM, when multiple Data Model (DM)
   representations (e.g., YANG and/or IPFIX) are required, to ensure lossless
   semantic mapping. IMs are also beneficial for complex or numerous DMs. As illustrated in <xref target="fig-im-dm"/>, an
   IM serves as a conceptual blueprint for designers and operators, from which concrete DMs are derived
   for implementers. <xref target="RFC3444"/> provides further guidance on distinguishing IMs from DMs.</t>
        <figure anchor="fig-im-dm">
          <name>Information Models (IMs) and Data Models (DMs)</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="144" width="464" viewBox="0 0 464 144" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px" stroke-linecap="round">
                <path d="M 8,64 L 8,80" fill="none" stroke="black"/>
                <path d="M 96,48 L 96,80" fill="none" stroke="black"/>
                <path d="M 176,64 L 176,80" fill="none" stroke="black"/>
                <path d="M 232,32 L 248,32" fill="none" stroke="black"/>
                <path d="M 8,64 L 176,64" fill="none" stroke="black"/>
                <path d="M 232,96 L 248,96" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="256,96 244,90.4 244,101.6" fill="black" transform="rotate(0,248,96)"/>
                <polygon class="arrowhead" points="256,32 244,26.4 244,37.6" fill="black" transform="rotate(0,248,32)"/>
                <g class="text">
                  <text x="100" y="36">IM</text>
                  <text x="336" y="36">conceptual/abstract</text>
                  <text x="440" y="36">model</text>
                  <text x="272" y="52">for</text>
                  <text x="328" y="52">designers</text>
                  <text x="376" y="52">&amp;</text>
                  <text x="424" y="52">operators</text>
                  <text x="12" y="100">DM</text>
                  <text x="100" y="100">DM</text>
                  <text x="180" y="100">DM</text>
                  <text x="328" y="100">concrete/detailed</text>
                  <text x="424" y="100">model</text>
                  <text x="296" y="116">for</text>
                  <text x="364" y="116">implementers</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
           IM               --> conceptual/abstract model
           |                    for designers & operators
+----------+---------+
|          |         |
DM         DM        DM     --> concrete/detailed model
                                   for implementers

]]></artwork>
          </artset>
        </figure>
        <t>Protocol Designers must identify the essential operational, configuration, state, and statistical
   information required for effective monitoring, control, and troubleshooting of New Protocols or Protocol Extensions.
   This includes defining relevant parameters, performance metrics, error indicators,
   and contextual data crucial for diagnostics and lifecycle management.</t>
        <t>To ensure interoperability, management protocol and Data Model standards should incorporate clear
   compliance clauses, specifying the expected level of support.</t>
      </section>
      <section anchor="sec-mgmt-info">
        <name>Management Information</name>
        <t>Languages used to describe an Information Model can influence the
   nature of the model. Using a particular data modeling language, such
   as YANG, influences the model to use certain types of structures, for
   example, hierarchical trees, groupings, and reusable types.
   YANG, as described in <xref target="RFC6020"/> and <xref target="RFC7950"/>, provides advantages
   for expressing network information, including clear separation of
   configuration data and operational state, support for constraints and
   dependencies, and extensibility for evolving requirements. Its ability
   to represent relationships and dependencies in a structured and modular
   way makes it an effective choice for defining management information
   models.</t>
        <t>While an Information Model is typically described in English text
   (or sometimes the Unified Modeling Language (UML)) to define the conceptual
   management requirements,
   authors may choose to express it using YANG Data Structure Extensions <xref target="RFC8791"/>
   as described in <xref target="sec-im-design"/>.  Using YANG for the Information Model can make
   it easier to link abstract concepts to concrete data types in the corresponding Data Model,
   helping maintain consistency between high-level design and practical deployment.</t>
        <t>A management Information Model should include a discussion of what is
   manageable, which aspects of the protocol need to be configured, what
   types of operations are allowed, what protocol-specific events might
   occur, which events can be counted, and for which events an operator
   should be notified.</t>
        <t>There may be a need to support both CLI (e.g., for
   troubleshooting) and a programmatic interface (e.g., for automated
   monitoring and Cause analysis). The APIs and CLI should
   expose consistent information so that an operator receives the same
   view of the protocol state regardless of which interface is used.
   Counter definitions, in particular, should be unambiguous and
   consistently defined across both types of interface.</t>
        <t>When defining management information, it is important to categorize
   data into configuration, operational state, and statistics. Conflating
   these distinct types into a single element makes it difficult for operators
   to distinguish between administratively set values and the dynamic state of
   the protocol. The model should be structured to allow these categories to be
   handled independently.</t>
        <t>What is typically difficult to work through are relationships between
   abstract objects. Ideally, an Information Model would describe the
   relationships between the objects and concepts in the information
   model.</t>
        <t>Is there always just one instance of this object or can there be
   multiple instances? Does this object relate to exactly one other
   object, or may it relate to multiple? When is it possible to change a
   relationship?</t>
        <t>Do objects (such as instances in lists) share fate? For example, if an
   instance in list A must exist before a related instance in list B can be
   created, what happens to the instance in list B if the related instance in
   list A is deleted? Does the existence of relationships between
   objects have an impact on fate sharing? YANG's relationships and
   constraints can help express and enforce these relationships.</t>
        <section anchor="sec-im-design">
          <name>Information Model Design</name>
          <t>This document recommends keeping the Information Model as simple as
   possible by applying the following criteria:</t>
          <ol spacing="normal" type="1"><li>
              <t>Start with a small set of essential objects and make additions only as
further objects are needed, with the objective of keeping the absolute
number of objects as small as possible while still delivering the
required function. Essential objects are those needed to answer the
diagnostic, configuration, and operational questions the protocol is
expected to support; objects that are technically accessible but do not
serve these functions should be excluded. There should be no duplication
between objects, and where one piece of information can be derived from
other pieces of information, it should not itself be represented as an
object.</t>
            </li>
            <li>
              <t>Verify that each object serves a distinct management purpose and cannot
be derived from other objects already in the model. Objects that are
redundant or that conflate multiple concerns should be split or
eliminated.</t>
            </li>
            <li>
              <t>Consider evidence of current use of the managed protocol, and the perceived utility of objects added to the Information Model.</t>
            </li>
            <li>
              <t>Exclude objects that can be derived from others in this or
other Information Models.</t>
            </li>
            <li>
              <t>Avoid heavy instrumentation of performance-critical code paths or
state that is expensive to query or compute. A guideline is to limit
instrumentation to one counter per significant processing stage or
operational boundary per layer.</t>
            </li>
            <li>
              <t>When expressing an Information Model using YANG Data Structure Extensions <xref target="RFC8791"/> (thereby keeping it abstract and implementation-agnostic per <xref target="RFC3444"/>), ensure that the Information Model remains simple, modular, and clear by following the authoring guidelines in <xref target="RFC9907"/>.</t>
            </li>
            <li>
              <t>When illustrating the abstract Information Model, use YANG Tree Diagrams <xref target="RFC8340"/> to provide a simple, standardized, and implementation-neutral model structure.</t>
            </li>
          </ol>
        </section>
        <section anchor="sec-yang-dm">
          <name>YANG Data Model Considerations</name>
          <t>When considering YANG Data Models for a new specification, there
  are multiple types of Data Models that may be applicable. The
  hierarchy and relationship between these types is described in
  <xref section="3.5.1" sectionFormat="of" target="RFC9907"/>. A new specification
  may require or benefit from one or more of these YANG Data Model types.</t>
          <ul spacing="normal">
            <li>
              <t>Device Models - Also called Network Element Models,
represent the configuration, operational state, and notifications of
individual devices. These models are designed to distinguish
between these types of data and support querying and updating
device-specific parameters. Consideration should be given to
how device-level models might fit with broader network and
service Data Models.</t>
            </li>
            <li>
              <t>Network Models - Also called Network Service Models, define abstractions
for managing the behavior and relationships of multiple devices
and device subsystems within a network. As described in <xref target="RFC8199"/>,
these models are used to manage network-wide services. These abstractions are
useful to network operators and applications that interface with network
controllers. Examples of network models include the L3VPN Network Model
(L3NM) <xref target="RFC9182"/> and the L2VPN Network Model (L2VPN) <xref target="RFC9291"/>.</t>
            </li>
            <li>
              <t>Service Models - Also called Customer Service Models,
defined in <xref target="RFC8309"/>, are designed to abstract the customer interface
into a service. They consider customer-centric parameters such as
Service Level Agreement (SLA) and high-level policy (e.g., network intent).
Given that different operators and different customers may have widely-varying
business processes, these models should focus on common aspects of a service
with strong multi-party consensus. Examples of service models include
the L3VPN Service Model (L3SM) <xref target="RFC8299"/> and the L2VPN Service Model (L2SM)
<xref target="RFC8466"/>.</t>
            </li>
          </ul>
          <t>A common challenge in YANG Data Model development lies in defining the
  relationships between abstract service or network constructs and the
  underlying device models. Therefore, when designing Network and Service
  YANG modules, consider how the status and relationships of abstract or
  distributed constructs can be reflected based on parameters available
  in the network.</t>
          <t>The status of a service may depend on the operational state
  of multiple network elements to which the service is attached. In such
  cases, the YANG Data Model (and its accompanying documentation) should
  clearly describe how service-level status is derived from underlying
  network-level abstractions and device-level information. Similarly, it is beneficial to define
  events (and relevant triggered notifications) at the device, network, and
  service levels that indicate changes in an underlying state, enabling
  reliable detection and correlation of service-affecting conditions across
  these levels. Including such mechanisms improves the robustness of
  integrations and helps ensure consistent behavior across
  implementations.</t>
          <t>For example:</t>
          <ul empty="true">
            <li>
              <t>A device YANG module may define a notification indicating that a
  hardware component, such as a line card, has failed. An implementation
  (e.g., a network controller that is aware of device inventory) can
  correlate such a device-level notification with the interfaces hosted
  on the affected line card and their subsequent down status to determine
  that a link supporting the network is no longer operational, and expose
  a corresponding network-level notification using a Network Model such
  as L3NM <xref target="RFC9182"/>. Likewise, an implementation managing the service layer can
  correlate that network-level notification with the affected service and
  use a Service Model such as L3SM <xref target="RFC8299"/> to report a
  service-degraded event to the customer, without requiring the
  service-facing model to expose device-level detail.</t>
            </li>
          </ul>
          <t>Specific guidelines to consider when authoring any type of YANG
  modules are described in <xref target="RFC9907"/>.</t>
        </section>
      </section>
      <section anchor="sec-fm-mgmt">
        <name>Fault Management</name>
        <t>Protocol Designers should identify and document
   essential Faults, health indicators, alarms, and events that must be
   propagated to management applications or exposed through a Data
   Model. It is also recommended to describe how the Protocol Extension
   will affect the existing alarms and notification structure of the
   base Protocol, and to outline the potential impact of misconfigurations
   of the Protocol Extensions.</t>
        <t>Protocol Designers should consider how Fault information will be
   propagated. Will it be done using asynchronous notifications or
   polling of health indicators?</t>
        <t>If notifications are used to alert operators to certain conditions,
   then Protocol Designers should discuss mechanisms to throttle
   notifications to prevent congestion and duplications of event
   notifications. Will there be a hierarchy of Faults, and will the
   Fault reporting be done by each Fault in the hierarchy, or will only
   the lowest Fault be reported and the higher levels be suppressed?
   Should there be aggregated status indicators based on concatenation
   of propagated Faults from a given domain or device?</t>
        <t>The alarm management model <xref target="RFC8632"/> already addresses many of these
   questions, including alarm identification, severity, root cause and
   impacted resource, and shelving for suppression; it also distinguishes
   alarm state from the notifications that report it. Protocol Designers
   should consider reusing it rather than defining new notification
   structures.</t>
        <t>Notifications (e.g., SNMP traps and informs, syslog, or protocol-specific mechanisms) can alert an operator when an
   aspect of the New Protocol or Protocol Extension fails or encounters an error or failure
   condition.
   Should the event reporting provide guaranteed accurate delivery of
   the event information within a given (high) margin of confidence?
   Can the latest events in the box be polled?</t>
        <section anchor="sec-monitor">
          <name>Liveness Detection and Monitoring</name>
          <t>Protocol Designers should build in basic testing features
   (e.g., ICMP echo, UDP
   or TCP echo services, and null Remote Procedure Calls
   (RPCs)) that can be used to test for liveness, with the option to
   enable or disable them.</t>
          <t>Mechanisms for monitoring the liveness of the protocol and for
   detecting Faults in protocol connectivity are usually built into
   protocols. In some cases, mechanisms already exist within other
   protocols responsible for maintaining lower-layer connectivity (e.g.,
   ICMP echo), but often new procedures are required to detect failures
   and to report rapidly, allowing remedial action to be taken.</t>
          <t>These liveness monitoring mechanisms do not typically require
   additional management capabilities. However, when a system detects a
   Fault, there is often a requirement to coordinate recovery action
   through management applications or at least to record the fact in an
   event log.</t>
        </section>
        <section anchor="sec-fault-determ">
          <name>Fault Determination</name>
          <t>It can be helpful to describe how Faults can be pinpointed using
   management information. For example, counters might record instances
   of error conditions. Some Faults might be able to be pinpointed by
   comparing the outputs of one device and the inputs of another device,
   looking for anomalies. Protocol Designers should consider what
   counters should count. If a single counter provided by vendor A
   counts three types of error conditions, while the corresponding
   counter provided by vendor B counts seven types of error conditions,
   these counters cannot be compared effectively -- they are not
   interoperable counters.</t>
          <t>How do you distinguish between faulty messages and good messages?</t>
          <t>Would some threshold-based mechanisms be usable to help determine
   error conditions? Are notifications for all events needed, or
   are there some "standard" notifications that could be used? Or can
   relevant counters be polled as needed?</t>
          <t>For example:</t>
          <ul empty="true">
            <li>
              <t>Remote Monitoring (RMON) events/alarms provide a threshold-based mechanism.</t>
            </li>
          </ul>
        </section>
        <section anchor="sec-cause-analysis">
          <name>Probable Root Cause Analysis</name>
          <t>Probable Root Cause analysis is about working out where the foundational
   Fault or Problem might be. Since one Fault may give rise to another Fault or
   Problem, a Probable Root Cause is commonly meant to describe the original,
   source event or combination of circumstances that is the foundation of all
   related Faults.</t>
          <t>For example:</t>
          <ul empty="true">
            <li>
              <t>If end-to-end data delivery is failing (e.g., reported by a
   notification), Probable Root Cause analysis can help find the failed link
   or node, or mis-configuration, within the end-to-end path.</t>
            </li>
          </ul>
        </section>
        <section anchor="sec-fault-isol">
          <name>Fault Isolation</name>
          <t>It might be useful to isolate or quarantine Faults. Protocol Designers
   should consider Fault isolation mechanisms appropriate to the deployment
   environment. At the network level, this might involve configuring
   next-hop devices to drop faulty messages to prevent them from
   propagating through the network, such as isolating a device that emits
   malformed messages that are necessary to coordinate connections properly.
   At the host level, isolation mechanisms may include process quarantine,
   container or virtual machine isolation, or disabling a misbehaving
   protocol implementation without disrupting other services on the same
   device. The range of appropriate isolation mechanisms will depend on
   where the protocol is deployed and the nature of the Fault.</t>
        </section>
      </section>
      <section anchor="sec-config-mgmt">
        <name>Configuration Management</name>
        <t>Configuration management applies to a broad range of deployment
   environments, including conventional network devices, IoT device fleets,
   containerized workloads, cloud-hosted services, and home network
   equipment. While many examples in this section are drawn from network
   device management, the principles apply equally to any environment where
   the protocol is deployed. Protocol Designers should consider how
   configuration is managed in the environments relevant to their protocol,
   acknowledging centralized configuration management approaches (e.g.,
   intent-based or model-driven systems) beyond conventional per-device
   management.</t>
        <t>A Protocol Designer should document the basic configuration
   parameters that need to be instrumented for a New Protocol or Protocol Extension, as well
   as default values and modes of operation.</t>
        <t>What information should be maintained across reboots of the device,
   or restarts of the management system?</t>
        <t>"Requirements for Configuration Management of IP-based Networks"
    <xref target="RFC3139"/> discusses requirements for configuration management, including
    discussion of different levels of management, high-level policies,
    network-wide configuration data, and device-local configuration. Network
    configuration extends beyond simple multi-device push or pull operations.
    It also involves ensuring that the configurations being pushed are
    semantically compatible across devices and that the resulting behavior of
    all involved devices corresponds to the intended behavior. Is the
    attachment between them configured compatibly on both ends? Is the
    IS-IS metric the same?
    Answering those questions for a network with one thousand devices is not that easy.</t>
        <t>Several efforts have existed in the IETF to develop policy-based
   configuration management. "Terminology for Policy-Based Management"
   <xref target="RFC3198"/> was written to standardize the terminology across these
   efforts.</t>
        <t>Implementations should not arbitrarily modify configuration data. If a
   Protocol Designer defines mechanisms for configuration, it would be
   preferable to standardize the order of elements for consistency of
   configuration and of reporting across vendors and across releases
   from vendors.</t>
        <t>Network-wide configurations may be stored in central databases
   and transformed into readable formats that can be pushed to devices, either by
   generating sequences of CLI commands or complete textual configuration files
   that are pushed to devices. There is no common database schema for
   network configuration, although the models used by various operators
   are probably very similar. It is operationally beneficial to
   extract, document, and standardize the common parts of these network-wide
   configuration database schemas. A Protocol Designer should
   consider how to standardize the common parts of configuring the New
   Protocol, while recognizing that vendors may also have proprietary
   aspects of their configurations.</t>
        <t>It is important to enable operators to concentrate on the
   configuration of the network or service as a whole, rather than individual
   devices. Support for configuration transactions across several
   devices could significantly simplify network configuration
   management. The ability to distribute configurations to multiple
   devices, or to modify candidate configurations on multiple devices,
   and then activate them in a near-simultaneous manner might help.
   Protocol Designers can consider how it would make sense for their
   protocol to be configured across multiple devices. Configuration
   templates might also be helpful.</t>
        <t>Consensus of the 2002 IAB Network Management Workshop <xref target="RFC3535"/> was that textual
   configuration files should be able to contain international characters.
   For human-readable strings carried in protocols, <xref target="RFC5198"/> provides
   guidance on the use of UTF-8 with NFC normalization for consistent
   encoding of Unicode text; protocol elements that are not intended for
   human consumption may remain in ASCII. Requirements for the encoding of
   device-local configuration files are generally outside the scope of IETF
   standardization and should be handled appropriately for the deployment
   environment.</t>
        <t>A mechanism to dump-and-restore configurations is a primitive
   operation needed by operators. Standards for pulling and pushing
   configurations from/to devices are highly beneficial.</t>
        <t>Given configuration A and configuration B, it should be possible to
   generate the operations necessary to get from A to B with minimal
   state changes and effects on network and systems. It is important to
   minimize the impact caused by configuration changes.</t>
        <t>A Protocol Designer should consider the configurable items that exist
   for the control of function via the protocol elements described in
   the protocol specification. For example, sometimes the protocol
   requires that timers can be configured by the operator to ensure
   specific policy-based behavior by the implementation. These timers
   should have default values suggested in the protocol specification
   and may not need to be otherwise configurable.</t>
      </section>
      <section anchor="sec-acc-mgmt">
        <name>Accounting Management</name>
        <t>A Protocol Designer should consider whether it would be appropriate
   to collect usage information related to this protocol and, if so,
   what usage information would be appropriate to collect.</t>
        <t>"Introduction to Accounting Management" <xref target="RFC2975"/> discusses a number
   of factors relevant to monitoring usage of protocols for purposes of
   capacity and trend analysis, cost allocation, auditing, and billing.
   The document also discusses how some existing protocols can be used
   for these purposes. These factors should be considered when
   designing a protocol whose usage might need to be monitored or when
   recommending a protocol to do usage accounting.</t>
      </section>
      <section anchor="sec-perf-mgmt">
        <name>Performance Management</name>
        <t>From a manageability point of view, it is important to determine how
   well a network deploying the protocol or technology defined in the
   document is doing. In order to do this, the network operators need
   to consider information that would be useful to determine the
   performance characteristics of a deployed system using the target
   protocol.</t>
        <t>The IETF, via the Benchmarking Methodology WG (BMWG), has defined
   recommendations for the measurement of the performance
   characteristics of various internetworking technologies in a
   laboratory environment, including the systems or services that are
   built from these technologies, building on the foundational methodology
   in <xref target="RFC2544"/>. Each benchmarking recommendation
   describes the class of equipment, system, or service being addressed;
   discusses the performance characteristics that are pertinent to that
   class; clearly identifies a set of metrics that aid in the
   description of those characteristics; specifies the methodologies
   required to collect said metrics; and lastly, presents the
   requirements for the common, unambiguous reporting of benchmarking
   results.</t>
        <t>Performance metrics may be useful in multiple environments and for
   different protocols. The IETF, via the IP Performance Measurement
   (IPPM) WG, has developed a set of standard metrics, building on the
   framework defined in <xref target="RFC2330"/>, that can be
   applied to the quality, performance, and reliability of Internet data
   delivery services. These metrics are designed such that they can be
   performed by network operators, end users, or independent testing
   groups. The existing metrics might be applicable to the new
   protocol. Search for "metric" in the RFC search tool. In some
   cases, new metrics need to be defined. It would be useful if the
   protocol documentation identified the need for such new metrics. For
   performance management, it is often more important to report the time
   spent in a state rather than just the current state. Snapshots alone
   are typically of less value. <xref target="RFC7799"/> classifies measurement methods as active,
   passive, or hybrid.  This classification is relevant to the protocol, device, network,
   and service monitoring approaches discussed in <xref target="sec-monitor-proto"/>, <xref target="sec-monitor-dev"/>,
   <xref target="sec-monitor-net"/>, and <xref target="sec-monitor-svc"/>.</t>
        <t>There are several parts of performance management to consider:
   protocol monitoring, device monitoring (the impact of new
   functionality/service activation on the device), network monitoring,
   and service monitoring (the impact of service activation on the
   network). Hence, if the implementation of the
   New Protocol or Protocol Extension has any significant hardware/software performance implications
   (e.g., increased CPU utilization, memory consumption, or forwarding
   performance degradation), the Protocol Designers should clearly
   describe these impacts in the specification, along with any
   conditions under which they may occur and possible mitigation
   strategies.</t>
        <section anchor="sec-monitor-proto">
          <name>Monitoring the Protocol</name>
          <t>Certain properties of protocols are useful to monitor. The number of
   protocol packets received, the number of packets sent, and the number
   of packets dropped are usually very helpful to operators.</t>
          <t>Packet drops should be reflected in counter variable(s) somewhere
   that can be inspected -- both from the security point of view and
   from the troubleshooting point of view.</t>
          <t>Counter definitions should be unambiguous about what is included in
   the count and what is not included in the count.</t>
          <t>Consider the expected behaviors for counters -- what is a reasonable
   maximum value for expected usage? Should they stop counting at the
   maximum value and retain it, or should they rollover?
   Guidance should explain how rollovers are detected, including multiple
   occurrences.</t>
          <t>Consider whether multiple management applications will share a
   counter; if so, then no one management application should be allowed
   to reset the value to zero since this will impact other applications.</t>
          <t>Could events, such as hot-swapping a blade in a chassis, cause
   discontinuities in counter? Does this make any difference in
   evaluating the performance of a protocol?</t>
          <t>The protocol specification should clearly define any inherent
   limitations and describe expected behavior when those limits
   are exceeded. These considerations should be made independently
   of any specific management protocol or data modeling language.
   In other words, focus on what makes sense for the protocol being
   managed, not the protocol used for management. If a constraint
   is not specific to a management protocol, then it should be left
   to Data Model designers of that protocol to determine how to handle it.</t>
          <t>For example:</t>
          <ul empty="true">
            <li>
              <t>VLAN identifiers (VLAN IDs) are defined by the standard to range from 1 to 4094.
   Therefore, a YANG "vlan-id" definition representing the
   12-bit VLAN ID used in the VLAN Tag header uses a range of "1..4094".</t>
            </li>
          </ul>
        </section>
        <section anchor="sec-monitor-dev">
          <name>Monitoring the Device</name>
          <t>Consider whether device performance will be affected by the number of
   protocol entities being instantiated on the device. Designers of an
   Information Model should include information, accessible at runtime,
   about the maximum number of instances an implementation can support,
   the current number of instances, and the expected behavior when the
   current instances exceed the capacity of the implementation or the
   capacity of the device.</t>
        </section>
        <section anchor="sec-monitor-net">
          <name>Monitoring the Network</name>
          <t>Consider whether network performance will be affected by the number
   of protocol entities being deployed.</t>
          <t>Consider the capability of determining the operational activity, such
   as the number of messages in and the messages out, the number of
   received messages rejected due to format Problems, and the expected
   behaviors when a malformed message is received.</t>
          <t>What are the principal performance factors that need to be considered
   when measuring the operational performance of a network built using
   the protocol? Is it important to measure setup times, end-to-end
   connectivity, hop-by-hop connectivity, or network throughput?</t>
        </section>
        <section anchor="sec-monitor-svc">
          <name>Monitoring the Service</name>
          <t>What are the principal performance factors that need to be considered
   when measuring the performance of a service using the protocol? Is
   it important to measure application-specific throughput, client-server
   associations, end-to-end application quality, service interruptions,
   or user experience (UX)?</t>
          <t>Note that monitoring a service must consider the utility to the user.
   This includes responsiveness, smoothness (absence of jitter), throughput,
   and other "quality of experience" factors.</t>
        </section>
      </section>
      <section anchor="sec-security-mgmt">
        <name>Security Management</name>
        <t>Protocol Designers should consider how to monitor and manage security
   aspects and vulnerabilities of the New Protocol or Protocol Extension.
   Likewise, Protocol Designers should consider how some operations (e.g., logging)
   might include privacy-sensitive information, which ought to be controlled
   to avoid access by unauthorized entities.</t>
        <t>Protocol Designers should consider whether a system automatically
   notifies operators of every event occurrence as default behavior or
   should define an operator-defined threshold to control when a
   notification is sent to an operator.</t>
        <t>Protocol Designers should assess whether and which statistics need to
   be collected about the operation of the New Protocol that might be
   useful for detecting attacks (e.g., the receipt of malformed
   messages, messages out of order, or messages with invalid
   timestamps). If such statistics are collected, care should be taken
   to evaluate whether it is important to count them separately for
   each sender to help identify the source of attacks.</t>
        <t>Security-oriented manageability topics may include risks of insufficient
   monitoring, regulatory issues with missing audit trails, log capacity
   limits, and security exposures in recommended management mechanisms.</t>
        <t>Protocol Designers should consider security threats that may be
   introduced by management operations.</t>
        <t>For example:</t>
        <ul empty="true">
          <li>
            <t>Control and Provisioning of Wireless Access
   Points (CAPWAP) <xref target="RFC5415"/> breaks the structure of monolithic Access Points
   (APs) into Access Controllers and Wireless Termination Points (WTPs).
   By using a control protocol or management protocol, internal
   information that was previously not accessible is now exposed over
   the network and to management applications and may become a source of
   potential security threats.</t>
          </li>
        </ul>
        <t>The granularity of access control needed on management interfaces
   needs to match operational needs. Typical requirements are a role-based
   access control model and the principle of least privilege,
   where a user can be given only the minimum access necessary to
   perform a required task.</t>
        <t>Some operators wish to do consistency checks of Access Control Lists (ACLs)
   across devices. Protocol Designers should consider Information
   Models to promote comparisons across devices and across vendors to
   permit checking the consistency of security configurations.</t>
        <t>Protocol Designers should consider how to provide a secure transport,
   authentication, identity, and access control that integrates well
   with existing key and credential management infrastructure. It is a
   good idea to start with defining the threat model for the protocol,
   and from that deducing what is required.</t>
        <t>Protocol Designers should consider how ACLs are
   maintained and updated.</t>
        <t>Notifications (e.g., syslog messages) might
   already exist, or can be defined, to alert operators to the
   conditions identified in the Security Considerations for the New
   Protocol or Protocol Extension. The syslog should also record events,
   such as failed logins, but it must be secured.</t>
        <t>For example:</t>
        <ul empty="true">
          <li>
            <t>All commands entered by operators can be logged via syslog to provide
   an audit trail.  Authentication events, including logins, logouts, and
   failed login attempts, can be recorded using the Secure Shell (SSH)
   Protocol <xref target="RFC4251"/>, capturing the source of each connection.</t>
          </li>
        </ul>
        <t>Different management protocols use different assumptions about
   message security and data-access controls. A Protocol Designer that
   recommends using different protocols should consider how security
   will be applied in a balanced manner across multiple management
   interfaces. SNMP authority levels and policy are data-oriented,
   while CLI authority levels and policy are usually command-oriented
   (i.e., task-oriented). Depending on the management function,
   sometimes data-oriented or task-oriented approaches make more sense.
   Protocol Designers should consider both data-oriented and task-oriented
   authority levels and policy. Refer also to <xref target="RFC8341"/> for more details on access control types and rules.</t>
      </section>
    </section>
    <section anchor="sec-oper-mgmt-tooling">
      <name>Operational and Management Tooling Considerations</name>
      <t>The operational community's ability to effectively adopt and
   use new specifications is significantly influenced by the availability
   and adaptability of appropriate tooling. In this context, "tools" refers
   to software systems or utilities used by network operators to deploy,
   configure, monitor, troubleshoot, and manage networks or network protocols
   in real-world operational environments. While the introduction of a new
   specification does not automatically mandate the development of entirely
   new tools, careful consideration must be given to how existing tools can be
   leveraged or extended to support the management and operation of these new
   specifications.</t>
      <t>The <xref target="NEMOPS"/> workshop highlighted a
   consistent theme applicable beyond network management protocols: the
   "ease of use" and adaptability of existing tools are critical factors
   for successful adoption. Therefore, a new specification should provide
   examples using existing, common tooling, or running code that demonstrate
   how to perform key operational tasks.</t>
      <t>Specifically, the following tooling-related aspects should be considered in the operational considerations section,
   prioritizing the adaptation of existing tools:</t>
      <ul spacing="normal">
        <li>
          <t>Leveraging Existing Tooling: Before considering new tools, assess whether
existing tooling, such as monitoring systems, logging platforms,
configuration management systems, and/or orchestration frameworks, can be
adapted to support the new specification. This may involve developing
plugins, modules, or drivers that enable these tools to interact with
the new specification.</t>
        </li>
        <li>
          <t>Extending Existing Tools: Identify areas where existing tools can be
extended to provide the necessary visibility and control over the new
specification. For example, if a new transport protocol is introduced,
consider whether existing network monitoring tools can be extended to
track its performance metrics or whether existing security tools can be
adapted to analyze its traffic patterns.</t>
        </li>
        <li>
          <t>New Tools: Only when existing tools are demonstrably
inadequate for managing and operating the elements of the new specification
should the development of new tools be considered. In such cases,
carefully define the specific requirements for these new tools, focusing
on the functionalities that cannot be achieved through adaptation or
extension of existing solutions.</t>
        </li>
        <li>
          <t>IETF Hackathons for Manageability Testing:
IETF Hackathons <xref target="IETF-HACKATHONS"/>
provide an opportunity to test the functionality, interoperability,
and manageability of New Protocols or Protocol Extensions. These events can be specifically
leveraged to assess the operational (including manageability) implications
of a New Protocol or Protocol Extension by focusing tasks on:  </t>
          <ul spacing="normal">
            <li>
              <t>Adapting existing tools to interact with the new specification.</t>
            </li>
            <li>
              <t>Developing example management scripts or modules for existing management
platforms.</t>
            </li>
            <li>
              <t>Testing the specification's behavior under various operational conditions.</t>
            </li>
            <li>
              <t>Identifying potential tooling gaps and areas for improvement.</t>
            </li>
            <li>
              <t>Creating example flows and use cases for manageability.</t>
            </li>
          </ul>
        </li>
        <li>
          <t>Open Source for Tooling: If new tools are deemed necessary, or if significant
adaptations to existing tools are required, prioritize open source development
with community involvement. Open source tools lower the barrier to entry,
encourage collaboration, and provide operators with the flexibility to customize
and extend the tools to meet their specific needs.</t>
        </li>
      </ul>
      <section anchor="sec-ai-tooling">
        <name>AI Tooling Considerations</name>
        <t>With the increasing adoption of Artificial Intelligence (AI)
   in network operations, Protocol Designers
   must consider the implication such functions may have on New Protocols
   and Protocol Extensions. AI
   models often require extensive and granular data for training and
   inference, requiring efficient, scalable, and secure mechanisms
   for telemetry, logging, and state information collection. Protocol Designers
   should anticipate that AI-powered management tools may generate
   frequent and potentially aggressive querying patterns on network
   devices and controllers. Therefore, protocols should be designed with Data
   Models and mechanisms intended to prevent overload from automated
   interactions, such as subscription to YANG notifications <xref target="RFC8639"/>
          <xref target="RFC8641"/>, which bounds that load and provides change semantics rather
   than repeated snapshots, while also accounting for AI-specific security
   considerations such as data integrity and protection against
   adversarial attacks on management interfaces. These considerations
   are also relevant to Performance Management (Section <xref format="counter" target="sec-perf-mgmt"/>)
   and Security Management (Section <xref format="counter" target="sec-security-mgmt"/>).</t>
      </section>
    </section>
    <section anchor="sec-iana">
      <name>IANA Considerations</name>
      <t>This document does not have any IANA actions required.</t>
    </section>
    <section anchor="sec-oper-mgmt-consid">
      <name>Operational Considerations</name>
      <t>There are no new operations or manageability requirements introduced
   by this document.</t>
      <t>Although this document focuses on operations and manageability guidance, it does not define a New Protocol, a Protocol Extension, or an architecture.</t>
    </section>
    <section anchor="sec-security">
      <name>Security Considerations</name>
      <t>This document provides guidelines for Protocol Designers for
   considering manageability and operations. It introduces no new
   security concerns. Protocol Designers seeking guidance on security-related
   management considerations for New Protocols or Protocol Extensions,
   such as monitoring, access control, and secure transport, should
   refer to <xref target="sec-security-mgmt"/>.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <referencegroup anchor="BCP22" target="https://www.rfc-editor.org/info/bcp22">
          <reference anchor="RFC2360" target="https://www.rfc-editor.org/info/rfc2360">
            <front>
              <title>Guide for Internet Standards Writers</title>
              <author fullname="G. Scott" initials="G." surname="Scott"/>
              <date month="June" year="1998"/>
              <abstract>
                <t>This document is a guide for Internet standard writers. It defines those characteristics that make standards coherent, unambiguous, and easy to interpret. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="22"/>
            <seriesInfo name="RFC" value="2360"/>
            <seriesInfo name="DOI" value="10.17487/RFC2360"/>
          </reference>
        </referencegroup>
        <reference anchor="RFC8791">
          <front>
            <title>YANG Data Structure Extensions</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Björklund" initials="M." surname="Björklund"/>
            <author fullname="K. Watsen" initials="K." surname="Watsen"/>
            <date month="June" year="2020"/>
            <abstract>
              <t>This document describes YANG mechanisms for defining abstract data structures with YANG.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8791"/>
          <seriesInfo name="DOI" value="10.17487/RFC8791"/>
        </reference>
        <reference anchor="RFC8340">
          <front>
            <title>YANG Tree Diagrams</title>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <author fullname="L. Berger" initials="L." role="editor" surname="Berger"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>This document captures the current syntax used in YANG module tree diagrams. The purpose of this document is to provide a single location for this definition. This syntax may be updated from time to time based on the evolution of the YANG language.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="215"/>
          <seriesInfo name="RFC" value="8340"/>
          <seriesInfo name="DOI" value="10.17487/RFC8340"/>
        </reference>
        <reference anchor="RFC9940">
          <front>
            <title>Some Key Terms for Network Fault and Problem Management</title>
            <author fullname="N. Davis" initials="N." role="editor" surname="Davis"/>
            <author fullname="A. Farrel" initials="A." role="editor" surname="Farrel"/>
            <author fullname="T. Graf" initials="T." surname="Graf"/>
            <author fullname="Q. Wu" initials="Q." surname="Wu"/>
            <author fullname="C. Yu" initials="C." surname="Yu"/>
            <date month="April" year="2026"/>
            <abstract>
              <t>This document sets out some terms that are fundamental to a common understanding of network fault and problem management within the IETF.</t>
              <t>The purpose of this document is to bring clarity to discussions and other work related to network fault and problem management -- in particular, to YANG data models and management protocols that report, make visible, or manage network faults and problems.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9940"/>
          <seriesInfo name="DOI" value="10.17487/RFC9940"/>
        </reference>
        <reference anchor="RFC7799">
          <front>
            <title>Active and Passive Metrics and Methods (with Hybrid Types In-Between)</title>
            <author fullname="A. Morton" initials="A." surname="Morton"/>
            <date month="May" year="2016"/>
            <abstract>
              <t>This memo provides clear definitions for Active and Passive performance assessment. The construction of Metrics and Methods can be described as either "Active" or "Passive". Some methods may use a subset of both Active and Passive attributes, and we refer to these as "Hybrid Methods". This memo also describes multiple dimensions to help evaluate new methods as they emerge.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7799"/>
          <seriesInfo name="DOI" value="10.17487/RFC7799"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="CHECKLIST" target="https://github.com/IETF-OPS-DIR/Review-Template/tree/main">
          <front>
            <title>Operations and Management Review Checklist</title>
            <author>
              <organization/>
            </author>
            <date year="2025"/>
          </front>
        </reference>
        <reference anchor="IETF-OPS-Dir" target="https://datatracker.ietf.org/group/opsdir/about/">
          <front>
            <title>Ops Directorate (opsdir)</title>
            <author>
              <organization/>
            </author>
            <date year="2025"/>
          </front>
        </reference>
        <reference anchor="PERFMETRDIR" target="https://datatracker.ietf.org/group/perfmetrdir/about/">
          <front>
            <title>Performance Metrics Directorate (perfmetrdir)</title>
            <author>
              <organization/>
            </author>
            <date year="2026"/>
          </front>
        </reference>
        <reference anchor="IETF-HACKATHONS" target="https://www.ietf.org/meeting/hackathons/">
          <front>
            <title>IETF Hackathons</title>
            <author>
              <organization>IETF</organization>
            </author>
            <date year="2025" month="May" day="01"/>
          </front>
        </reference>
        <reference anchor="SECOPS" target="https://niccs.cisa.gov/resources/glossary">
          <front>
            <title>NICCS Glossary</title>
            <author>
              <organization/>
            </author>
            <date year="2025" month="August"/>
          </front>
        </reference>
        <referencegroup anchor="BCP186" target="https://www.rfc-editor.org/info/bcp186">
          <reference anchor="RFC7126" target="https://www.rfc-editor.org/info/rfc7126">
            <front>
              <title>Recommendations on Filtering of IPv4 Packets Containing IPv4 Options</title>
              <author fullname="F. Gont" initials="F." surname="Gont"/>
              <author fullname="R. Atkinson" initials="R." surname="Atkinson"/>
              <author fullname="C. Pignataro" initials="C." surname="Pignataro"/>
              <date month="February" year="2014"/>
              <abstract>
                <t>This document provides advice on the filtering of IPv4 packets based on the IPv4 options they contain. Additionally, it discusses the operational and interoperability implications of dropping packets based on the IP options they contain.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="186"/>
            <seriesInfo name="RFC" value="7126"/>
            <seriesInfo name="DOI" value="10.17487/RFC7126"/>
          </reference>
        </referencegroup>
        <reference anchor="RFC5706">
          <front>
            <title>Guidelines for Considering Operations and Management of New Protocols and Protocol Extensions</title>
            <author fullname="D. Harrington" initials="D." surname="Harrington"/>
            <date month="November" year="2009"/>
            <abstract>
              <t>New protocols or protocol extensions are best designed with due consideration of the functionality needed to operate and manage the protocols. Retrofitting operations and management is sub-optimal. The purpose of this document is to provide guidance to authors and reviewers of documents that define new protocols or protocol extensions regarding aspects of operations and management that should be considered. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5706"/>
          <seriesInfo name="DOI" value="10.17487/RFC5706"/>
        </reference>
        <referencegroup anchor="BCP72" target="https://www.rfc-editor.org/info/bcp72">
          <reference anchor="RFC3552" target="https://www.rfc-editor.org/info/rfc3552">
            <front>
              <title>Guidelines for Writing RFC Text on Security Considerations</title>
              <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
              <author fullname="B. Korver" initials="B." surname="Korver"/>
              <date month="July" year="2003"/>
              <abstract>
                <t>All RFCs are required to have a Security Considerations section. Historically, such sections have been relatively weak. This document provides guidelines to RFC authors on how to write a good Security Considerations section. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="72"/>
            <seriesInfo name="RFC" value="3552"/>
            <seriesInfo name="DOI" value="10.17487/RFC3552"/>
          </reference>
          <reference anchor="RFC9416" target="https://www.rfc-editor.org/info/rfc9416">
            <front>
              <title>Security Considerations for Transient Numeric Identifiers Employed in Network Protocols</title>
              <author fullname="F. Gont" initials="F." surname="Gont"/>
              <author fullname="I. Arce" initials="I." surname="Arce"/>
              <date month="July" year="2023"/>
              <abstract>
                <t>Poor selection of transient numerical identifiers in protocols such as the TCP/IP suite has historically led to a number of attacks on implementations, ranging from Denial of Service (DoS) or data injection to information leakages that can be exploited by pervasive monitoring. Due diligence in the specification of transient numeric identifiers is required even when cryptographic techniques are employed, since these techniques might not mitigate all the associated issues. This document formally updates RFC 3552, incorporating requirements for transient numeric identifiers, to prevent flaws in future protocols and implementations.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="72"/>
            <seriesInfo name="RFC" value="9416"/>
            <seriesInfo name="DOI" value="10.17487/RFC9416"/>
          </reference>
        </referencegroup>
        <reference anchor="RFC6390">
          <front>
            <title>Guidelines for Considering New Performance Metric Development</title>
            <author fullname="A. Clark" initials="A." surname="Clark"/>
            <author fullname="B. Claise" initials="B." surname="Claise"/>
            <date month="October" year="2011"/>
            <abstract>
              <t>This document describes a framework and a process for developing Performance Metrics of protocols and applications transported over IETF-specified protocols. These metrics can be used to characterize traffic on live networks and services. This memo documents an Internet Best Current Practice.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="170"/>
          <seriesInfo name="RFC" value="6390"/>
          <seriesInfo name="DOI" value="10.17487/RFC6390"/>
        </reference>
        <referencegroup anchor="BCP14" target="https://www.rfc-editor.org/info/bcp14">
          <reference anchor="RFC2119" target="https://www.rfc-editor.org/info/rfc2119">
            <front>
              <title>Key words for use in RFCs to Indicate Requirement Levels</title>
              <author fullname="S. Bradner" initials="S." surname="Bradner"/>
              <date month="March" year="1997"/>
              <abstract>
                <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="14"/>
            <seriesInfo name="RFC" value="2119"/>
            <seriesInfo name="DOI" value="10.17487/RFC2119"/>
          </reference>
          <reference anchor="RFC8174" target="https://www.rfc-editor.org/info/rfc8174">
            <front>
              <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
              <author fullname="B. Leiba" initials="B." surname="Leiba"/>
              <date month="May" year="2017"/>
              <abstract>
                <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="14"/>
            <seriesInfo name="RFC" value="8174"/>
            <seriesInfo name="DOI" value="10.17487/RFC8174"/>
          </reference>
        </referencegroup>
        <reference anchor="RFC3444">
          <front>
            <title>On the Difference between Information Models and Data Models</title>
            <author fullname="A. Pras" initials="A." surname="Pras"/>
            <author fullname="J. Schoenwaelder" initials="J." surname="Schoenwaelder"/>
            <date month="January" year="2003"/>
            <abstract>
              <t>There has been ongoing confusion about the differences between Information Models and Data Models for defining managed objects in network management. This document explains the differences between these terms by analyzing how existing network management model specifications (from the IETF and other bodies such as the International Telecommunication Union (ITU) or the Distributed Management Task Force (DMTF)) fit into the universe of Information Models and Data Models. This memo documents the main results of the 8th workshop of the Network Management Research Group (NMRG) of the Internet Research Task Force (IRTF) hosted by the University of Texas at Austin. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3444"/>
          <seriesInfo name="DOI" value="10.17487/RFC3444"/>
        </reference>
        <reference anchor="RFC6291">
          <front>
            <title>Guidelines for the Use of the "OAM" Acronym in the IETF</title>
            <author fullname="L. Andersson" initials="L." surname="Andersson"/>
            <author fullname="H. van Helvoort" initials="H." surname="van Helvoort"/>
            <author fullname="R. Bonica" initials="R." surname="Bonica"/>
            <author fullname="D. Romascanu" initials="D." surname="Romascanu"/>
            <author fullname="S. Mansfield" initials="S." surname="Mansfield"/>
            <date month="June" year="2011"/>
            <abstract>
              <t>At first glance, the acronym "OAM" seems to be well-known and well-understood. Looking at the acronym a bit more closely reveals a set of recurring problems that are revisited time and again.</t>
              <t>This document provides a definition of the acronym "OAM" (Operations, Administration, and Maintenance) for use in all future IETF documents that refer to OAM. There are other definitions and acronyms that will be discussed while exploring the definition of the constituent parts of the "OAM" term. This memo documents an Internet Best Current Practice.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="161"/>
          <seriesInfo name="RFC" value="6291"/>
          <seriesInfo name="DOI" value="10.17487/RFC6291"/>
        </reference>
        <reference anchor="RFC10014">
          <front>
            <title>Guidelines for Characterizing the Term "OAM"</title>
            <author fullname="C. Pignataro" initials="C." surname="Pignataro"/>
            <author fullname="A. Farrel" initials="A." surname="Farrel"/>
            <author fullname="T. Mizrahi" initials="T." surname="Mizrahi"/>
            <date month="June" year="2026"/>
            <abstract>
              <t>As the IETF continues to produce and standardize different Operations, Administration, and Maintenance (OAM) protocols and technologies, various qualifiers and modifiers are prepended to the OAM abbreviation. While, at first glance, the most used qualifiers appear to be well understood, the same qualifier may be interpreted differently in different contexts. A case in point is the qualifiers "in-band" and "out-of-band", which have their origins in the radio lexicon, and which have been extrapolated into other communication networks. This document recommends not to use these two terms when referring to OAM.</t>
              <t>This document considers some common qualifiers and modifiers that are prepended, within the context of packet networks, to the OAM abbreviation and lays out guidelines for their use in IETF documents.</t>
              <t>This document extends RFC 6291 by adding to the guidelines for the use of the term "OAM" with qualifiers. It does not modify any part of RFC 6291.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="161"/>
          <seriesInfo name="RFC" value="10014"/>
          <seriesInfo name="DOI" value="10.17487/RFC10014"/>
        </reference>
        <reference anchor="I-D.ietf-nmop-network-incident-yang">
          <front>
            <title>A YANG Data Model for Network Incident Management</title>
            <author fullname="Tong Hu" initials="T." surname="Hu">
              <organization>CMCC</organization>
            </author>
            <author fullname="Luis M. Contreras" initials="L. M." surname="Contreras">
              <organization>Telefonica</organization>
            </author>
            <author fullname="Qin Wu" initials="Q." surname="Wu">
              <organization>Huawei</organization>
            </author>
            <author fullname="Nigel Davis" initials="N." surname="Davis">
              <organization>Ciena</organization>
            </author>
            <author fullname="Chong Feng" initials="C." surname="Feng">
         </author>
            <date day="18" month="August" year="2026"/>
            <abstract>
              <t>   This document defines a YANG Module for the network incident
   lifecycle management.  This YANG module is meant to provide a
   standard way to report, diagnose, and help reduce troubleshooting
   tickets and resolve network incidents for the sake of network service
   health and probable root cause analysis.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-nmop-network-incident-yang-14"/>
        </reference>
        <reference anchor="RFC9953">
          <front>
            <title>DNS over CoAP (DoC)</title>
            <author fullname="M. S. Lenders" initials="M. S." surname="Lenders"/>
            <author fullname="C. Amsüss" initials="C." surname="Amsüss"/>
            <author fullname="C. Gündoğan" initials="C." surname="Gündoğan"/>
            <author fullname="T. C. Schmidt" initials="T. C." surname="Schmidt"/>
            <author fullname="M. Wählisch" initials="M." surname="Wählisch"/>
            <date month="March" year="2026"/>
            <abstract>
              <t>This document defines a protocol for exchanging DNS queries (OPCODE 0) over the Constrained Application Protocol (CoAP). These CoAP messages can be protected by (D)TLS-Secured CoAP or Object Security for Constrained RESTful Environments (OSCORE) to provide encrypted DNS message exchange for constrained devices in the Internet of Things (IoT).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9953"/>
          <seriesInfo name="DOI" value="10.17487/RFC9953"/>
        </reference>
        <reference anchor="I-D.ietf-suit-mti">
          <front>
            <title>Cryptographic Algorithms for Internet of Things (IoT) Devices</title>
            <author fullname="Brendan Moran" initials="B." surname="Moran">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Øyvind Rønningstad" initials="O." surname="Rønningstad">
              <organization>Nordic Semiconductor</organization>
            </author>
            <author fullname="Akira Tsukamoto" initials="A." surname="Tsukamoto">
              <organization>Openchip &amp; Software Technologies, S.L.</organization>
            </author>
            <date day="22" month="July" year="2025"/>
            <abstract>
              <t>   The SUIT manifest, as defined in "A Manifest Information Model for
   Firmware Updates in Internet of Things (IoT) Devices" (RFC 9124),
   provides a flexible and extensible format for describing how firmware
   and software updates are to be fetched, verified, decrypted, and
   installed on resource-constrained devices.  To ensure the security of
   these update processes, the manifest relies on cryptographic
   algorithms for functions such as digital signature verification,
   integrity checking, and confidentiality.

   This document defines cryptographic algorithm profiles for use with
   the Software Updates for Internet of Things (SUIT) manifest.  These
   profiles specify sets of algorithms to promote interoperability
   across implementations.

   Given the diversity of IoT deployments and the evolving cryptographic
   landscape, algorithm agility is essential.  This document groups
   algorithms into named profiles to accommodate varying levels of
   device capabilities and security requirements.  These profiles
   support the use cases laid out in the SUIT architecture, published in
   "A Firmware Update Architecture for Internet of Things" (RFC 9019).

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-suit-mti-23"/>
        </reference>
        <reference anchor="RFC9937">
          <front>
            <title>Proportional Rate Reduction (PRR)</title>
            <author fullname="M. Mathis" initials="M." surname="Mathis"/>
            <author fullname="N. Cardwell" initials="N." surname="Cardwell"/>
            <author fullname="Y. Cheng" initials="Y." surname="Cheng"/>
            <author fullname="N. Dukkipati" initials="N." surname="Dukkipati"/>
            <date month="December" year="2025"/>
            <abstract>
              <t>This document specifies a Standards Track version of the Proportional Rate Reduction (PRR) algorithm that obsoletes the Experimental version described in RFC 6937. PRR regulates the amount of data sent by TCP or other transport protocols during fast recovery. PRR accurately regulates the actual flight size through recovery such that at the end of recovery it will be as close as possible to the slow start threshold (ssthresh), as determined by the congestion control algorithm.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9937"/>
          <seriesInfo name="DOI" value="10.17487/RFC9937"/>
        </reference>
        <reference anchor="RFC7574">
          <front>
            <title>Peer-to-Peer Streaming Peer Protocol (PPSPP)</title>
            <author fullname="A. Bakker" initials="A." surname="Bakker"/>
            <author fullname="R. Petrocco" initials="R." surname="Petrocco"/>
            <author fullname="V. Grishchenko" initials="V." surname="Grishchenko"/>
            <date month="July" year="2015"/>
            <abstract>
              <t>The Peer-to-Peer Streaming Peer Protocol (PPSPP) is a protocol for disseminating the same content to a group of interested parties in a streaming fashion. PPSPP supports streaming of both prerecorded (on- demand) and live audio/video content. It is based on the peer-to- peer paradigm, where clients consuming the content are put on equal footing with the servers initially providing the content, to create a system where everyone can potentially provide upload bandwidth. It has been designed to provide short time-till-playback for the end user and to prevent disruption of the streams by malicious peers. PPSPP has also been designed to be flexible and extensible. It can use different mechanisms to optimize peer uploading, prevent freeriding, and work with different peer discovery schemes (centralized trackers or Distributed Hash Tables). It supports multiple methods for content integrity protection and chunk addressing. Designed as a generic protocol that can run on top of various transport protocols, it currently runs on top of UDP using Low Extra Delay Background Transport (LEDBAT) for congestion control.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7574"/>
          <seriesInfo name="DOI" value="10.17487/RFC7574"/>
        </reference>
        <reference anchor="RFC9877">
          <front>
            <title>Registration Data Access Protocol (RDAP) Extension for Geofeed Data</title>
            <author fullname="J. Singh" initials="J." surname="Singh"/>
            <author fullname="T. Harrison" initials="T." surname="Harrison"/>
            <date month="October" year="2025"/>
            <abstract>
              <t>This document defines a new Registration Data Access Protocol (RDAP) extension, "geofeed1", for indicating that an RDAP server hosts geofeed URLs for its IP network objects. It also defines a new media type and a new link relation type for the associated link objects included in responses.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9877"/>
          <seriesInfo name="DOI" value="10.17487/RFC9877"/>
        </reference>
        <reference anchor="RFC9552">
          <front>
            <title>Distribution of Link-State and Traffic Engineering Information Using BGP</title>
            <author fullname="K. Talaulikar" initials="K." role="editor" surname="Talaulikar"/>
            <date month="December" year="2023"/>
            <abstract>
              <t>In many environments, a component external to a network is called upon to perform computations based on the network topology and the current state of the connections within the network, including Traffic Engineering (TE) information. This is information typically distributed by IGP routing protocols within the network.</t>
              <t>This document describes a mechanism by which link-state and TE information can be collected from networks and shared with external components using the BGP routing protocol. This is achieved using a BGP Network Layer Reachability Information (NLRI) encoding format. The mechanism applies to physical and virtual (e.g., tunnel) IGP links. The mechanism described is subject to policy control.</t>
              <t>Applications of this technique include Application-Layer Traffic Optimization (ALTO) servers and Path Computation Elements (PCEs).</t>
              <t>This document obsoletes RFC 7752 by completely replacing that document. It makes some small changes and clarifications to the previous specification. This document also obsoletes RFC 9029 by incorporating the updates that it made to RFC 7752.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9552"/>
          <seriesInfo name="DOI" value="10.17487/RFC9552"/>
        </reference>
        <reference anchor="I-D.ietf-ippm-ioam-integrity-yang">
          <front>
            <title>A YANG Data Model for In Situ Operations, Administration, and Maintenance (IOAM) Integrity-Protected Options</title>
            <author fullname="Justin Iurman" initials="J." surname="Iurman">
              <organization>University of Liege</organization>
            </author>
            <author fullname="Tianran Zhou" initials="T." surname="Zhou">
              <organization>Huawei</organization>
            </author>
            <date day="8" month="May" year="2026"/>
            <abstract>
              <t>   In Situ Operations, Administration, and Maintenance (IOAM) is an
   example of an on-path hybrid measurement method to collect
   operational and telemetry information.  The collected data may then
   be exported to systems that will use it to, e.g., monitor, measure,
   or (re)configure the network.  Integrity Protection of In Situ
   Operations, Administration, and Maintenance (IOAM) Data Fields (RFC
   YYYY) defines IOAM Options with integrity protection, also called
   Integrity-Protected Options.  This document defines a YANG data model
   for the management of these Integrity-Protected Options.  The
   document also defines an IANA-maintained YANG module for IOAM
   Integrity Protection Methods.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-ippm-ioam-integrity-yang-08"/>
        </reference>
        <reference anchor="RFC5218">
          <front>
            <title>What Makes for a Successful Protocol?</title>
            <author fullname="D. Thaler" initials="D." surname="Thaler"/>
            <author fullname="B. Aboba" initials="B." surname="Aboba"/>
            <date month="July" year="2008"/>
            <abstract>
              <t>The Internet community has specified a large number of protocols to date, and these protocols have achieved varying degrees of success. Based on case studies, this document attempts to ascertain factors that contribute to or hinder a protocol's success. It is hoped that these observations can serve as guidance for future protocol work. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5218"/>
          <seriesInfo name="DOI" value="10.17487/RFC5218"/>
        </reference>
        <reference anchor="RFC2439">
          <front>
            <title>BGP Route Flap Damping</title>
            <author fullname="C. Villamizar" initials="C." surname="Villamizar"/>
            <author fullname="R. Chandra" initials="R." surname="Chandra"/>
            <author fullname="R. Govindan" initials="R." surname="Govindan"/>
            <date month="November" year="1998"/>
            <abstract>
              <t>A usage of the BGP routing protocol is described which is capable of reducing the routing traffic passed on to routing peers and therefore the load on these peers without adversely affecting route convergence time for relatively stable routes. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2439"/>
          <seriesInfo name="DOI" value="10.17487/RFC2439"/>
        </reference>
        <reference anchor="RFC1958">
          <front>
            <title>Architectural Principles of the Internet</title>
            <author fullname="B. Carpenter" initials="B." role="editor" surname="Carpenter"/>
            <date month="June" year="1996"/>
            <abstract>
              <t>The Internet and its architecture have grown in evolutionary fashion from modest beginnings, rather than from a Grand Plan. While this process of evolution is one of the main reasons for the technology's success, it nevertheless seems useful to record a snapshot of the current principles of the Internet architecture. This is intended for general guidance and general interest, and is in no way intended to be a formal or invariant reference model. This memo provides information for the Internet community. This memo does not specify an Internet standard of any kind.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="1958"/>
          <seriesInfo name="DOI" value="10.17487/RFC1958"/>
        </reference>
        <reference anchor="RFC6298">
          <front>
            <title>Computing TCP's Retransmission Timer</title>
            <author fullname="V. Paxson" initials="V." surname="Paxson"/>
            <author fullname="M. Allman" initials="M." surname="Allman"/>
            <author fullname="J. Chu" initials="J." surname="Chu"/>
            <author fullname="M. Sargent" initials="M." surname="Sargent"/>
            <date month="June" year="2011"/>
            <abstract>
              <t>This document defines the standard algorithm that Transmission Control Protocol (TCP) senders are required to use to compute and manage their retransmission timer. It expands on the discussion in Section 4.2.3.1 of RFC 1122 and upgrades the requirement of supporting the algorithm from a SHOULD to a MUST. This document obsoletes RFC 2988. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6298"/>
          <seriesInfo name="DOI" value="10.17487/RFC6298"/>
        </reference>
        <reference anchor="RFC9881">
          <front>
            <title>Internet X.509 Public Key Infrastructure -- Algorithm Identifiers for the Module-Lattice-Based Digital Signature Algorithm (ML-DSA)</title>
            <author fullname="J. Massimo" initials="J." surname="Massimo"/>
            <author fullname="P. Kampanakis" initials="P." surname="Kampanakis"/>
            <author fullname="S. Turner" initials="S." surname="Turner"/>
            <author fullname="B. E. Westerbaan" initials="B. E." surname="Westerbaan"/>
            <date month="October" year="2025"/>
            <abstract>
              <t>Digital signatures are used within X.509 certificates and Certificate Revocation Lists (CRLs), and to sign messages. This document specifies the conventions for using FIPS 204, the Module-Lattice-Based Digital Signature Algorithm (ML-DSA) in Internet X.509 certificates and CRLs. The conventions for the associated signatures, subject public keys, and private key are also described.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9881"/>
          <seriesInfo name="DOI" value="10.17487/RFC9881"/>
        </reference>
        <reference anchor="RFC8170">
          <front>
            <title>Planning for Protocol Adoption and Subsequent Transitions</title>
            <author fullname="D. Thaler" initials="D." role="editor" surname="Thaler"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>Over the many years since the introduction of the Internet Protocol, we have seen a number of transitions throughout the protocol stack, such as deploying a new protocol, or updating or replacing an existing protocol. Many protocols and technologies were not designed to enable smooth transition to alternatives or to easily deploy extensions; thus, some transitions, such as the introduction of IPv6, have been difficult. This document attempts to summarize some basic principles to enable future transitions, and it also summarizes what makes for a good transition plan.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8170"/>
          <seriesInfo name="DOI" value="10.17487/RFC8170"/>
        </reference>
        <reference anchor="RFC5905">
          <front>
            <title>Network Time Protocol Version 4: Protocol and Algorithms Specification</title>
            <author fullname="D. Mills" initials="D." surname="Mills"/>
            <author fullname="J. Martin" initials="J." role="editor" surname="Martin"/>
            <author fullname="J. Burbank" initials="J." surname="Burbank"/>
            <author fullname="W. Kasch" initials="W." surname="Kasch"/>
            <date month="June" year="2010"/>
            <abstract>
              <t>The Network Time Protocol (NTP) is widely used to synchronize computer clocks in the Internet. This document describes NTP version 4 (NTPv4), which is backwards compatible with NTP version 3 (NTPv3), described in RFC 1305, as well as previous versions of the protocol. NTPv4 includes a modified protocol header to accommodate the Internet Protocol version 6 address family. NTPv4 includes fundamental improvements in the mitigation and discipline algorithms that extend the potential accuracy to the tens of microseconds with modern workstations and fast LANs. It includes a dynamic server discovery scheme, so that in many cases, specific server configuration is not required. It corrects certain errors in the NTPv3 design and implementation and includes an optional extension mechanism.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5905"/>
          <seriesInfo name="DOI" value="10.17487/RFC5905"/>
        </reference>
        <reference anchor="RFC2205">
          <front>
            <title>Resource ReSerVation Protocol (RSVP) -- Version 1 Functional Specification</title>
            <author fullname="R. Braden" initials="R." role="editor" surname="Braden"/>
            <author fullname="L. Zhang" initials="L." surname="Zhang"/>
            <author fullname="S. Berson" initials="S." surname="Berson"/>
            <author fullname="S. Herzog" initials="S." surname="Herzog"/>
            <author fullname="S. Jamin" initials="S." surname="Jamin"/>
            <date month="September" year="1997"/>
            <abstract>
              <t>This memo describes version 1 of RSVP, a resource reservation setup protocol designed for an integrated services Internet. RSVP provides receiver-initiated setup of resource reservations for multicast or unicast data flows, with good scaling and robustness properties. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2205"/>
          <seriesInfo name="DOI" value="10.17487/RFC2205"/>
        </reference>
        <reference anchor="RFC2113">
          <front>
            <title>IP Router Alert Option</title>
            <author fullname="D. Katz" initials="D." surname="Katz"/>
            <date month="February" year="1997"/>
            <abstract>
              <t>This memo describes a new IP Option type that alerts transit routers to more closely examine the contents of an IP packet. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2113"/>
          <seriesInfo name="DOI" value="10.17487/RFC2113"/>
        </reference>
        <reference anchor="RFC2711">
          <front>
            <title>IPv6 Router Alert Option</title>
            <author fullname="C. Partridge" initials="C." surname="Partridge"/>
            <author fullname="A. Jackson" initials="A." surname="Jackson"/>
            <date month="October" year="1999"/>
            <abstract>
              <t>This memo describes a new IPv6 Hop-by-Hop Option type that alerts transit routers to more closely examine the contents of an IP datagram. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2711"/>
          <seriesInfo name="DOI" value="10.17487/RFC2711"/>
        </reference>
        <reference anchor="RFC9805">
          <front>
            <title>Deprecation of the IPv6 Router Alert Option for New Protocols</title>
            <author fullname="R. Bonica" initials="R." surname="Bonica"/>
            <date month="June" year="2025"/>
            <abstract>
              <t>This document deprecates the IPv6 Router Alert option. Protocols that use the IPv6 Router Alert option may continue to do so, even in future versions. However, new protocols that are standardized in the future must not use the IPv6 Router Alert option.</t>
              <t>This document updates RFC 2711.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9805"/>
          <seriesInfo name="DOI" value="10.17487/RFC9805"/>
        </reference>
        <reference anchor="RFC6709">
          <front>
            <title>Design Considerations for Protocol Extensions</title>
            <author fullname="B. Carpenter" initials="B." surname="Carpenter"/>
            <author fullname="B. Aboba" initials="B." role="editor" surname="Aboba"/>
            <author fullname="S. Cheshire" initials="S." surname="Cheshire"/>
            <date month="September" year="2012"/>
            <abstract>
              <t>This document discusses architectural issues related to the extensibility of Internet protocols, with a focus on design considerations. It is intended to assist designers of both base protocols and extensions. Case studies are included. A companion document, RFC 4775 (BCP 125), discusses procedures relating to the extensibility of IETF protocols. This document is not an Internet Standards Track specification; it is published for informational purposes.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6709"/>
          <seriesInfo name="DOI" value="10.17487/RFC6709"/>
        </reference>
        <reference anchor="RFC8799">
          <front>
            <title>Limited Domains and Internet Protocols</title>
            <author fullname="B. Carpenter" initials="B." surname="Carpenter"/>
            <author fullname="B. Liu" initials="B." surname="Liu"/>
            <date month="July" year="2020"/>
            <abstract>
              <t>There is a noticeable trend towards network behaviors and semantics that are specific to a particular set of requirements applied within a limited region of the Internet. Policies, default parameters, the options supported, the style of network management, and security requirements may vary between such limited regions. This document reviews examples of such limited domains (also known as controlled environments), notes emerging solutions, and includes a related taxonomy. It then briefly discusses the standardization of protocols for limited domains. Finally, it shows the need for a precise definition of "limited domain membership" and for mechanisms to allow nodes to join a domain securely and to find other members, including boundary nodes.</t>
              <t>This document is the product of the research of the authors. It has been produced through discussions and consultation within the IETF but is not the product of IETF consensus.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8799"/>
          <seriesInfo name="DOI" value="10.17487/RFC8799"/>
        </reference>
        <referencegroup anchor="BCP133" target="https://www.rfc-editor.org/info/bcp133">
          <reference anchor="RFC9743" target="https://www.rfc-editor.org/info/rfc9743">
            <front>
              <title>Specifying New Congestion Control Algorithms</title>
              <author fullname="M. Duke" initials="M." role="editor" surname="Duke"/>
              <author fullname="G. Fairhurst" initials="G." role="editor" surname="Fairhurst"/>
              <date month="March" year="2025"/>
              <abstract>
                <t>RFC 5033 discusses the principles and guidelines for standardizing new congestion control algorithms. This document obsoletes RFC 5033 to reflect changes in the congestion control landscape by providing a framework for the development and assessment of congestion control mechanisms, promoting stability across diverse network paths. This document seeks to ensure that proposed congestion control algorithms operate efficiently and without harm when used in the global Internet. It emphasizes the need for comprehensive testing and validation to prevent adverse interactions with existing flows.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="133"/>
            <seriesInfo name="RFC" value="9743"/>
            <seriesInfo name="DOI" value="10.17487/RFC9743"/>
          </reference>
        </referencegroup>
        <reference anchor="RFC1034">
          <front>
            <title>Domain names - concepts and facilities</title>
            <author fullname="P. Mockapetris" initials="P." surname="Mockapetris"/>
            <date month="November" year="1987"/>
            <abstract>
              <t>This RFC is the revised basic definition of The Domain Name System. It obsoletes RFC-882. This memo describes the domain style names and their used for host address look up and electronic mail forwarding. It discusses the clients and servers in the domain name system and the protocol used between them.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="13"/>
          <seriesInfo name="RFC" value="1034"/>
          <seriesInfo name="DOI" value="10.17487/RFC1034"/>
        </reference>
        <reference anchor="RFC5321">
          <front>
            <title>Simple Mail Transfer Protocol</title>
            <author fullname="J. Klensin" initials="J." surname="Klensin"/>
            <date month="October" year="2008"/>
            <abstract>
              <t>This document is a specification of the basic protocol for Internet electronic mail transport. It consolidates, updates, and clarifies several previous documents, making all or parts of most of them obsolete. It covers the SMTP extension mechanisms and best practices for the contemporary Internet, but does not provide details about particular extensions. Although SMTP was designed as a mail transport and delivery protocol, this specification also contains information that is important to its use as a "mail submission" protocol for "split-UA" (User Agent) mail reading systems and mobile environments. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5321"/>
          <seriesInfo name="DOI" value="10.17487/RFC5321"/>
        </reference>
        <reference anchor="RFC5884">
          <front>
            <title>Bidirectional Forwarding Detection (BFD) for MPLS Label Switched Paths (LSPs)</title>
            <author fullname="R. Aggarwal" initials="R." surname="Aggarwal"/>
            <author fullname="K. Kompella" initials="K." surname="Kompella"/>
            <author fullname="T. Nadeau" initials="T." surname="Nadeau"/>
            <author fullname="G. Swallow" initials="G." surname="Swallow"/>
            <date month="June" year="2010"/>
            <abstract>
              <t>One desirable application of Bidirectional Forwarding Detection (BFD) is to detect a Multiprotocol Label Switching (MPLS) Label Switched Path (LSP) data plane failure. LSP Ping is an existing mechanism for detecting MPLS data plane failures and for verifying the MPLS LSP data plane against the control plane. BFD can be used for the former, but not for the latter. However, the control plane processing required for BFD Control packets is relatively smaller than the processing required for LSP Ping messages. A combination of LSP Ping and BFD can be used to provide faster data plane failure detection and/or make it possible to provide such detection on a greater number of LSPs. This document describes the applicability of BFD in relation to LSP Ping for this application. It also describes procedures for using BFD in this environment. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5884"/>
          <seriesInfo name="DOI" value="10.17487/RFC5884"/>
        </reference>
        <reference anchor="RFC8899">
          <front>
            <title>Packetization Layer Path MTU Discovery for Datagram Transports</title>
            <author fullname="G. Fairhurst" initials="G." surname="Fairhurst"/>
            <author fullname="T. Jones" initials="T." surname="Jones"/>
            <author fullname="M. Tüxen" initials="M." surname="Tüxen"/>
            <author fullname="I. Rüngeler" initials="I." surname="Rüngeler"/>
            <author fullname="T. Völker" initials="T." surname="Völker"/>
            <date month="September" year="2020"/>
            <abstract>
              <t>This document specifies Datagram Packetization Layer Path MTU Discovery (DPLPMTUD). This is a robust method for Path MTU Discovery (PMTUD) for datagram Packetization Layers (PLs). It allows a PL, or a datagram application that uses a PL, to discover whether a network path can support the current size of datagram. This can be used to detect and reduce the message size when a sender encounters a packet black hole. It can also probe a network path to discover whether the maximum packet size can be increased. This provides functionality for datagram transports that is equivalent to the PLPMTUD specification for TCP, specified in RFC 4821, which it updates. It also updates the UDP Usage Guidelines to refer to this method for use with UDP datagrams and updates SCTP.</t>
              <t>The document provides implementation notes for incorporating Datagram PMTUD into IETF datagram transports or applications that use datagram transports.</t>
              <t>This specification updates RFC 4960, RFC 4821, RFC 6951, RFC 8085, and RFC 8261.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8899"/>
          <seriesInfo name="DOI" value="10.17487/RFC8899"/>
        </reference>
        <reference anchor="RFC8900">
          <front>
            <title>IP Fragmentation Considered Fragile</title>
            <author fullname="R. Bonica" initials="R." surname="Bonica"/>
            <author fullname="F. Baker" initials="F." surname="Baker"/>
            <author fullname="G. Huston" initials="G." surname="Huston"/>
            <author fullname="R. Hinden" initials="R." surname="Hinden"/>
            <author fullname="O. Troan" initials="O." surname="Troan"/>
            <author fullname="F. Gont" initials="F." surname="Gont"/>
            <date month="September" year="2020"/>
            <abstract>
              <t>This document describes IP fragmentation and explains how it introduces fragility to Internet communication.</t>
              <t>This document also proposes alternatives to IP fragmentation and provides recommendations for developers and network operators.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="230"/>
          <seriesInfo name="RFC" value="8900"/>
          <seriesInfo name="DOI" value="10.17487/RFC8900"/>
        </reference>
        <reference anchor="RFC9424">
          <front>
            <title>Indicators of Compromise (IoCs) and Their Role in Attack Defence</title>
            <author fullname="K. Paine" initials="K." surname="Paine"/>
            <author fullname="O. Whitehouse" initials="O." surname="Whitehouse"/>
            <author fullname="J. Sellwood" initials="J." surname="Sellwood"/>
            <author fullname="A. Shaw" initials="A." surname="Shaw"/>
            <date month="August" year="2023"/>
            <abstract>
              <t>Cyber defenders frequently rely on Indicators of Compromise (IoCs) to identify, trace, and block malicious activity in networks or on endpoints. This document reviews the fundamentals, opportunities, operational limitations, and recommendations for IoC use. It highlights the need for IoCs to be detectable in implementations of Internet protocols, tools, and technologies -- both for the IoCs' initial discovery and their use in detection -- and provides a foundation for approaches to operational challenges in network security.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9424"/>
          <seriesInfo name="DOI" value="10.17487/RFC9424"/>
        </reference>
        <reference anchor="I-D.ietf-quic-qlog-main-schema">
          <front>
            <title>qlog: Structured Logging for Network Protocols</title>
            <author fullname="Robin Marx" initials="R." surname="Marx">
              <organization>Akamai</organization>
            </author>
            <author fullname="Luca Niccolini" initials="L." surname="Niccolini">
              <organization>Meta</organization>
            </author>
            <author fullname="Marten Seemann" initials="M." surname="Seemann">
         </author>
            <author fullname="Lucas Pardue" initials="L." surname="Pardue">
              <organization>Cloudflare</organization>
            </author>
            <date day="6" month="July" year="2026"/>
            <abstract>
              <t>   qlog provides extensible structured logging for network protocols,
   allowing for easy sharing of data that benefits common debug and
   analysis methods and tooling.  This document describes key concepts
   of qlog: formats, files, traces, events, and extension points.  This
   definition includes the high-level log file schemas, and generic
   event schemas.  Requirements and guidelines for creating protocol-
   specific event schemas are also presented.  All schemas are defined
   independent of serialization format, allowing logs to be represented
   in various ways such as JSON, CSV, or protobuf.

Note to Readers

      Note to RFC editor: Please remove this section before publication.

   Feedback and discussion are welcome at https://github.com/quicwg/qlog
   (https://github.com/quicwg/qlog).  Readers are advised to refer to
   the "editor's draft" at that URL for an up-to-date version of this
   document.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-quic-qlog-main-schema-14"/>
        </reference>
        <reference anchor="RFC9000">
          <front>
            <title>QUIC: A UDP-Based Multiplexed and Secure Transport</title>
            <author fullname="J. Iyengar" initials="J." role="editor" surname="Iyengar"/>
            <author fullname="M. Thomson" initials="M." role="editor" surname="Thomson"/>
            <date month="May" year="2021"/>
            <abstract>
              <t>This document defines the core of the QUIC transport protocol. QUIC provides applications with flow-controlled streams for structured communication, low-latency connection establishment, and network path migration. QUIC includes security measures that ensure confidentiality, integrity, and availability in a range of deployment circumstances. Accompanying documents describe the integration of TLS for key negotiation, loss detection, and an exemplary congestion control algorithm.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9000"/>
          <seriesInfo name="DOI" value="10.17487/RFC9000"/>
        </reference>
        <reference anchor="RFC9846">
          <front>
            <title>The Transport Layer Security (TLS) Protocol Version 1.3</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <date month="July" year="2026"/>
            <abstract>
              <t>This document specifies version 1.3 of the Transport Layer Security (TLS) protocol. TLS allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</t>
              <t>This document obsoletes RFC 8446, which specified TLS 1.3. This document obsoletes RFC 5246 (specifying TLS 1.2) and RFCs 5077, 6961, 7627, and 8422, all of which pertain to TLS 1.2 or earlier, and updates RFCs 5705 and 6066. This document also specifies new requirements for TLS 1.2 implementations.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9846"/>
          <seriesInfo name="DOI" value="10.17487/RFC9846"/>
        </reference>
        <reference anchor="RFC9849">
          <front>
            <title>TLS Encrypted Client Hello</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <author fullname="K. Oku" initials="K." surname="Oku"/>
            <author fullname="N. Sullivan" initials="N." surname="Sullivan"/>
            <author fullname="C. A. Wood" initials="C. A." surname="Wood"/>
            <date month="March" year="2026"/>
            <abstract>
              <t>This document describes a mechanism in Transport Layer Security (TLS) for encrypting a message under a server public key.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9849"/>
          <seriesInfo name="DOI" value="10.17487/RFC9849"/>
        </reference>
        <reference anchor="RFC8484">
          <front>
            <title>DNS Queries over HTTPS (DoH)</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="P. McManus" initials="P." surname="McManus"/>
            <date month="October" year="2018"/>
            <abstract>
              <t>This document defines a protocol for sending DNS queries and getting DNS responses over HTTPS. Each DNS query-response pair is mapped into an HTTP exchange.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8484"/>
          <seriesInfo name="DOI" value="10.17487/RFC8484"/>
        </reference>
        <reference anchor="I-D.parsons-opsawg-security-operations">
          <front>
            <title>Security Operations Fundamentals and Guidance</title>
            <author fullname="Michael P" initials="M." surname="P">
              <organization>UK National Cyber Security Centre</organization>
            </author>
            <author fullname="Flo D" initials="F." surname="D">
              <organization>UK National Cyber Security Centre</organization>
            </author>
            <date day="20" month="May" year="2026"/>
            <abstract>
              <t>   Security operators are responsible for detecting malicious activity,
   responding to threats and defending their networks and systems from
   cyber attacks.  Security operations are commonly entwined with other
   operational and management priorities to ensure that both security
   and operational priorities are considered holistically.

   With security operators being a crucial part of operation, management
   and security of the network, it is valuable to give consideration to
   them during the design of new protocols.  This document builds upon
   draft-ietf-opsawg-rfc5706bis, describing the fundamentals of security
   operations to provide a foundation for considerations for protocol
   design and guidance.  This document also describes how security
   operations considerations can be most usefully included in other IETF
   documents.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-parsons-opsawg-security-operations-01"/>
        </reference>
        <referencegroup anchor="BCP47" target="https://www.rfc-editor.org/info/bcp47">
          <reference anchor="RFC4647" target="https://www.rfc-editor.org/info/rfc4647">
            <front>
              <title>Matching of Language Tags</title>
              <author fullname="A. Phillips" initials="A." role="editor" surname="Phillips"/>
              <author fullname="M. Davis" initials="M." role="editor" surname="Davis"/>
              <date month="September" year="2006"/>
              <abstract>
                <t>This document describes a syntax, called a "language-range", for specifying items in a user's list of language preferences. It also describes different mechanisms for comparing and matching these to language tags. Two kinds of matching mechanisms, filtering and lookup, are defined. Filtering produces a (potentially empty) set of language tags, whereas lookup produces a single language tag. Possible applications include language negotiation or content selection. This document, in combination with RFC 4646, replaces RFC 3066, which replaced RFC 1766. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="47"/>
            <seriesInfo name="RFC" value="4647"/>
            <seriesInfo name="DOI" value="10.17487/RFC4647"/>
          </reference>
          <reference anchor="RFC5646" target="https://www.rfc-editor.org/info/rfc5646">
            <front>
              <title>Tags for Identifying Languages</title>
              <author fullname="A. Phillips" initials="A." role="editor" surname="Phillips"/>
              <author fullname="M. Davis" initials="M." role="editor" surname="Davis"/>
              <date month="September" year="2009"/>
              <abstract>
                <t>This document describes the structure, content, construction, and semantics of language tags for use in cases where it is desirable to indicate the language used in an information object. It also describes how to register values for use in language tags and the creation of user-defined extensions for private interchange. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="47"/>
            <seriesInfo name="RFC" value="5646"/>
            <seriesInfo name="DOI" value="10.17487/RFC5646"/>
          </reference>
        </referencegroup>
        <referencegroup anchor="BCP166" target="https://www.rfc-editor.org/info/bcp166">
          <reference anchor="RFC6365" target="https://www.rfc-editor.org/info/rfc6365">
            <front>
              <title>Terminology Used in Internationalization in the IETF</title>
              <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
              <author fullname="J. Klensin" initials="J." surname="Klensin"/>
              <date month="September" year="2011"/>
              <abstract>
                <t>This document provides a list of terms used in the IETF when discussing internationalization. The purpose is to help frame discussions of internationalization in the various areas of the IETF and to help introduce the main concepts to IETF participants. This memo documents an Internet Best Current Practice.</t>
              </abstract>
            </front>
            <seriesInfo name="BCP" value="166"/>
            <seriesInfo name="RFC" value="6365"/>
            <seriesInfo name="DOI" value="10.17487/RFC6365"/>
          </reference>
        </referencegroup>
        <reference anchor="RFC6241">
          <front>
            <title>Network Configuration Protocol (NETCONF)</title>
            <author fullname="R. Enns" initials="R." role="editor" surname="Enns"/>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <author fullname="J. Schoenwaelder" initials="J." role="editor" surname="Schoenwaelder"/>
            <author fullname="A. Bierman" initials="A." role="editor" surname="Bierman"/>
            <date month="June" year="2011"/>
            <abstract>
              <t>The Network Configuration Protocol (NETCONF) defined in this document provides mechanisms to install, manipulate, and delete the configuration of network devices. It uses an Extensible Markup Language (XML)-based data encoding for the configuration data as well as the protocol messages. The NETCONF protocol operations are realized as remote procedure calls (RPCs). This document obsoletes RFC 4741. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6241"/>
          <seriesInfo name="DOI" value="10.17487/RFC6241"/>
        </reference>
        <reference anchor="RFC6632">
          <front>
            <title>An Overview of the IETF Network Management Standards</title>
            <author fullname="M. Ersue" initials="M." role="editor" surname="Ersue"/>
            <author fullname="B. Claise" initials="B." surname="Claise"/>
            <date month="June" year="2012"/>
            <abstract>
              <t>This document gives an overview of the IETF network management standards and summarizes existing and ongoing development of IETF Standards Track network management protocols and data models. The document refers to other overview documents, where they exist and classifies the standards for easy orientation. The purpose of this document is, on the one hand, to help system developers and users to select appropriate standard management protocols and data models to address relevant management needs. On the other hand, the document can be used as an overview and guideline by other Standard Development Organizations or bodies planning to use IETF management technologies and data models. This document does not cover Operations, Administration, and Maintenance (OAM) technologies on the data-path, e.g., OAM of tunnels, MPLS Transport Profile (MPLS-TP) OAM, and pseudowire as well as the corresponding management models. This document is not an Internet Standards Track specification; it is published for informational purposes.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6632"/>
          <seriesInfo name="DOI" value="10.17487/RFC6632"/>
        </reference>
        <reference anchor="RFC7854">
          <front>
            <title>BGP Monitoring Protocol (BMP)</title>
            <author fullname="J. Scudder" initials="J." role="editor" surname="Scudder"/>
            <author fullname="R. Fernando" initials="R." surname="Fernando"/>
            <author fullname="S. Stuart" initials="S." surname="Stuart"/>
            <date month="June" year="2016"/>
            <abstract>
              <t>This document defines the BGP Monitoring Protocol (BMP), which can be used to monitor BGP sessions. BMP is intended to provide a convenient interface for obtaining route views. Prior to the introduction of BMP, screen scraping was the most commonly used approach to obtaining such views. The design goals are to keep BMP simple, useful, easily implemented, and minimally service affecting. BMP is not suitable for use as a routing protocol.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7854"/>
          <seriesInfo name="DOI" value="10.17487/RFC7854"/>
        </reference>
        <reference anchor="RFC8639">
          <front>
            <title>Subscription to YANG Notifications</title>
            <author fullname="E. Voit" initials="E." surname="Voit"/>
            <author fullname="A. Clemm" initials="A." surname="Clemm"/>
            <author fullname="A. Gonzalez Prieto" initials="A." surname="Gonzalez Prieto"/>
            <author fullname="E. Nilsen-Nygaard" initials="E." surname="Nilsen-Nygaard"/>
            <author fullname="A. Tripathy" initials="A." surname="Tripathy"/>
            <date month="September" year="2019"/>
            <abstract>
              <t>This document defines a YANG data model and associated mechanisms enabling subscriber-specific subscriptions to a publisher's event streams. Applying these elements allows a subscriber to request and receive a continuous, customized feed of publisher-generated information.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8639"/>
          <seriesInfo name="DOI" value="10.17487/RFC8639"/>
        </reference>
        <reference anchor="RFC8641">
          <front>
            <title>Subscription to YANG Notifications for Datastore Updates</title>
            <author fullname="A. Clemm" initials="A." surname="Clemm"/>
            <author fullname="E. Voit" initials="E." surname="Voit"/>
            <date month="September" year="2019"/>
            <abstract>
              <t>This document describes a mechanism that allows subscriber applications to request a continuous and customized stream of updates from a YANG datastore. Providing such visibility into updates enables new capabilities based on the remote mirroring and monitoring of configuration and operational state.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8641"/>
          <seriesInfo name="DOI" value="10.17487/RFC8641"/>
        </reference>
        <reference anchor="RFC8632">
          <front>
            <title>A YANG Data Model for Alarm Management</title>
            <author fullname="S. Vallin" initials="S." surname="Vallin"/>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <date month="September" year="2019"/>
            <abstract>
              <t>This document defines a YANG module for alarm management. It includes functions for alarm-list management, alarm shelving, and notifications to inform management systems. There are also operations to manage the operator state of an alarm and administrative alarm procedures. The module carefully maps to relevant alarm standards.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8632"/>
          <seriesInfo name="DOI" value="10.17487/RFC8632"/>
        </reference>
        <reference anchor="RFC9232">
          <front>
            <title>Network Telemetry Framework</title>
            <author fullname="H. Song" initials="H." surname="Song"/>
            <author fullname="F. Qin" initials="F." surname="Qin"/>
            <author fullname="P. Martinez-Julia" initials="P." surname="Martinez-Julia"/>
            <author fullname="L. Ciavaglia" initials="L." surname="Ciavaglia"/>
            <author fullname="A. Wang" initials="A." surname="Wang"/>
            <date month="May" year="2022"/>
            <abstract>
              <t>Network telemetry is a technology for gaining network insight and facilitating efficient and automated network management. It encompasses various techniques for remote data generation, collection, correlation, and consumption. This document describes an architectural framework for network telemetry, motivated by challenges that are encountered as part of the operation of networks and by the requirements that ensue. This document clarifies the terminology and classifies the modules and components of a network telemetry system from different perspectives. The framework and taxonomy help to set a common ground for the collection of related work and provide guidance for related technique and standard developments.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9232"/>
          <seriesInfo name="DOI" value="10.17487/RFC9232"/>
        </reference>
        <reference anchor="RFC7950">
          <front>
            <title>The YANG 1.1 Data Modeling Language</title>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <date month="August" year="2016"/>
            <abstract>
              <t>YANG is a data modeling language used to model configuration data, state data, Remote Procedure Calls, and notifications for network management protocols. This document describes the syntax and semantics of version 1.1 of the YANG language. YANG version 1.1 is a maintenance release of the YANG language, addressing ambiguities and defects in the original specification. There are a small number of backward incompatibilities from YANG version 1. This document also specifies the YANG mappings to the Network Configuration Protocol (NETCONF).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7950"/>
          <seriesInfo name="DOI" value="10.17487/RFC7950"/>
        </reference>
        <reference anchor="RFC8040">
          <front>
            <title>RESTCONF Protocol</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <author fullname="K. Watsen" initials="K." surname="Watsen"/>
            <date month="January" year="2017"/>
            <abstract>
              <t>This document describes an HTTP-based protocol that provides a programmatic interface for accessing data defined in YANG, using the datastore concepts defined in the Network Configuration Protocol (NETCONF).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8040"/>
          <seriesInfo name="DOI" value="10.17487/RFC8040"/>
        </reference>
        <reference anchor="RFC7011">
          <front>
            <title>Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of Flow Information</title>
            <author fullname="B. Claise" initials="B." role="editor" surname="Claise"/>
            <author fullname="B. Trammell" initials="B." role="editor" surname="Trammell"/>
            <author fullname="P. Aitken" initials="P." surname="Aitken"/>
            <date month="September" year="2013"/>
            <abstract>
              <t>This document specifies the IP Flow Information Export (IPFIX) protocol, which serves as a means for transmitting Traffic Flow information over the network. In order to transmit Traffic Flow information from an Exporting Process to a Collecting Process, a common representation of flow data and a standard means of communicating them are required. This document describes how the IPFIX Data and Template Records are carried over a number of transport protocols from an IPFIX Exporting Process to an IPFIX Collecting Process. This document obsoletes RFC 5101.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="77"/>
          <seriesInfo name="RFC" value="7011"/>
          <seriesInfo name="DOI" value="10.17487/RFC7011"/>
        </reference>
        <reference anchor="RFC5424">
          <front>
            <title>The Syslog Protocol</title>
            <author fullname="R. Gerhards" initials="R." surname="Gerhards"/>
            <date month="March" year="2009"/>
            <abstract>
              <t>This document describes the syslog protocol, which is used to convey event notification messages. This protocol utilizes a layered architecture, which allows the use of any number of transport protocols for transmission of syslog messages. It also provides a message format that allows vendor-specific extensions to be provided in a structured way.</t>
              <t>This document has been written with the original design goals for traditional syslog in mind. The need for a new layered specification has arisen because standardization efforts for reliable and secure syslog extensions suffer from the lack of a Standards-Track and transport-independent RFC. Without this document, each other standard needs to define its own syslog packet format and transport mechanism, which over time will introduce subtle compatibility issues. This document tries to provide a foundation that syslog extensions can build on. This layered architecture approach also provides a solid basis that allows code to be written once for each syslog feature rather than once for each transport. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5424"/>
          <seriesInfo name="DOI" value="10.17487/RFC5424"/>
        </reference>
        <reference anchor="RFC6020">
          <front>
            <title>YANG - A Data Modeling Language for the Network Configuration Protocol (NETCONF)</title>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <date month="October" year="2010"/>
            <abstract>
              <t>YANG is a data modeling language used to model configuration and state data manipulated by the Network Configuration Protocol (NETCONF), NETCONF remote procedure calls, and NETCONF notifications. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6020"/>
          <seriesInfo name="DOI" value="10.17487/RFC6020"/>
        </reference>
        <reference anchor="RFC9907">
          <front>
            <title>Guidelines for Authors and Reviewers of Documents Containing YANG Data Models</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Boucadair" initials="M." role="editor" surname="Boucadair"/>
            <author fullname="Q. Wu" initials="Q." surname="Wu"/>
            <date month="March" year="2026"/>
            <abstract>
              <t>This document provides guidelines for authors and reviewers of specifications containing YANG data models, including IANA-maintained YANG modules. Recommendations and procedures are defined, which are intended to increase interoperability and usability of Network Configuration Protocol (NETCONF) and RESTCONF protocol implementations that utilize YANG modules.</t>
              <t>This document obsoletes RFC 8407; it also updates RFC 8126 by providing additional guidelines for writing the IANA considerations for RFCs that specify IANA-maintained YANG modules.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="216"/>
          <seriesInfo name="RFC" value="9907"/>
          <seriesInfo name="DOI" value="10.17487/RFC9907"/>
        </reference>
        <reference anchor="RFC8199">
          <front>
            <title>YANG Module Classification</title>
            <author fullname="D. Bogdanovic" initials="D." surname="Bogdanovic"/>
            <author fullname="B. Claise" initials="B." surname="Claise"/>
            <author fullname="C. Moberg" initials="C." surname="Moberg"/>
            <date month="July" year="2017"/>
            <abstract>
              <t>The YANG data modeling language is currently being considered for a wide variety of applications throughout the networking industry at large. Many standards development organizations (SDOs), open-source software projects, vendors, and users are using YANG to develop and publish YANG modules for a wide variety of applications. At the same time, there is currently no well-known terminology to categorize various types of YANG modules.</t>
              <t>A consistent terminology would help with the categorization of YANG modules, assist in the analysis of the YANG data modeling efforts in the IETF and other organizations, and bring clarity to the YANG- related discussions between the different groups.</t>
              <t>This document describes a set of concepts and associated terms to support consistent classification of YANG modules.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8199"/>
          <seriesInfo name="DOI" value="10.17487/RFC8199"/>
        </reference>
        <reference anchor="RFC9182">
          <front>
            <title>A YANG Network Data Model for Layer 3 VPNs</title>
            <author fullname="S. Barguil" initials="S." surname="Barguil"/>
            <author fullname="O. Gonzalez de Dios" initials="O." role="editor" surname="Gonzalez de Dios"/>
            <author fullname="M. Boucadair" initials="M." role="editor" surname="Boucadair"/>
            <author fullname="L. Munoz" initials="L." surname="Munoz"/>
            <author fullname="A. Aguado" initials="A." surname="Aguado"/>
            <date month="February" year="2022"/>
            <abstract>
              <t>As a complement to the Layer 3 Virtual Private Network Service Model (L3SM), which is used for communication between customers and service providers, this document defines an L3VPN Network Model (L3NM) that can be used for the provisioning of Layer 3 Virtual Private Network (L3VPN) services within a service provider network. The model provides a network-centric view of L3VPN services.</t>
              <t>The L3NM is meant to be used by a network controller to derive the configuration information that will be sent to relevant network devices. The model can also facilitate communication between a service orchestrator and a network controller/orchestrator.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9182"/>
          <seriesInfo name="DOI" value="10.17487/RFC9182"/>
        </reference>
        <reference anchor="RFC9291">
          <front>
            <title>A YANG Network Data Model for Layer 2 VPNs</title>
            <author fullname="M. Boucadair" initials="M." role="editor" surname="Boucadair"/>
            <author fullname="O. Gonzalez de Dios" initials="O." role="editor" surname="Gonzalez de Dios"/>
            <author fullname="S. Barguil" initials="S." surname="Barguil"/>
            <author fullname="L. Munoz" initials="L." surname="Munoz"/>
            <date month="September" year="2022"/>
            <abstract>
              <t>This document defines an L2VPN Network Model (L2NM) that can be used to manage the provisioning of Layer 2 Virtual Private Network (L2VPN) services within a network (e.g., a service provider network). The L2NM complements the L2VPN Service Model (L2SM) by providing a network-centric view of the service that is internal to a service provider. The L2NM is particularly meant to be used by a network controller to derive the configuration information that will be sent to relevant network devices.</t>
              <t>Also, this document defines a YANG module to manage Ethernet segments and the initial versions of two IANA-maintained modules that include a set of identities of BGP Layer 2 encapsulation types and pseudowire types.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9291"/>
          <seriesInfo name="DOI" value="10.17487/RFC9291"/>
        </reference>
        <reference anchor="RFC8309">
          <front>
            <title>Service Models Explained</title>
            <author fullname="Q. Wu" initials="Q." surname="Wu"/>
            <author fullname="W. Liu" initials="W." surname="Liu"/>
            <author fullname="A. Farrel" initials="A." surname="Farrel"/>
            <date month="January" year="2018"/>
            <abstract>
              <t>The IETF has produced many modules in the YANG modeling language. The majority of these modules are used to construct data models to model devices or monolithic functions.</t>
              <t>A small number of YANG modules have been defined to model services (for example, the Layer 3 Virtual Private Network Service Model (L3SM) produced by the L3SM working group and documented in RFC 8049).</t>
              <t>This document describes service models as used within the IETF and also shows where a service model might fit into a software-defined networking architecture. Note that service models do not make any assumption of how a service is actually engineered and delivered for a customer; details of how network protocols and devices are engineered to deliver a service are captured in other modules that are not exposed through the interface between the customer and the provider.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8309"/>
          <seriesInfo name="DOI" value="10.17487/RFC8309"/>
        </reference>
        <reference anchor="RFC8299">
          <front>
            <title>YANG Data Model for L3VPN Service Delivery</title>
            <author fullname="Q. Wu" initials="Q." role="editor" surname="Wu"/>
            <author fullname="S. Litkowski" initials="S." surname="Litkowski"/>
            <author fullname="L. Tomotaki" initials="L." surname="Tomotaki"/>
            <author fullname="K. Ogaki" initials="K." surname="Ogaki"/>
            <date month="January" year="2018"/>
            <abstract>
              <t>This document defines a YANG data model that can be used for communication between customers and network operators and to deliver a Layer 3 provider-provisioned VPN service. This document is limited to BGP PE-based VPNs as described in RFCs 4026, 4110, and 4364. This model is intended to be instantiated at the management system to deliver the overall service. It is not a configuration model to be used directly on network elements. This model provides an abstracted view of the Layer 3 IP VPN service configuration components. It will be up to the management system to take this model as input and use specific configuration models to configure the different network elements to deliver the service. How the configuration of network elements is done is out of scope for this document.</t>
              <t>This document obsoletes RFC 8049; it replaces the unimplementable module in that RFC with a new module with the same name that is not backward compatible. The changes are a series of small fixes to the YANG module and some clarifications to the text.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8299"/>
          <seriesInfo name="DOI" value="10.17487/RFC8299"/>
        </reference>
        <reference anchor="RFC8466">
          <front>
            <title>A YANG Data Model for Layer 2 Virtual Private Network (L2VPN) Service Delivery</title>
            <author fullname="B. Wen" initials="B." surname="Wen"/>
            <author fullname="G. Fioccola" initials="G." role="editor" surname="Fioccola"/>
            <author fullname="C. Xie" initials="C." surname="Xie"/>
            <author fullname="L. Jalil" initials="L." surname="Jalil"/>
            <date month="October" year="2018"/>
            <abstract>
              <t>This document defines a YANG data model that can be used to configure a Layer 2 provider-provisioned VPN service. It is up to a management system to take this as an input and generate specific configuration models to configure the different network elements to deliver the service. How this configuration of network elements is done is out of scope for this document.</t>
              <t>The YANG data model defined in this document includes support for point-to-point Virtual Private Wire Services (VPWSs) and multipoint Virtual Private LAN Services (VPLSs) that use Pseudowires signaled using the Label Distribution Protocol (LDP) and the Border Gateway Protocol (BGP) as described in RFCs 4761 and 6624.</t>
              <t>The YANG data model defined in this document conforms to the Network Management Datastore Architecture defined in RFC 8342.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8466"/>
          <seriesInfo name="DOI" value="10.17487/RFC8466"/>
        </reference>
        <reference anchor="RFC3139">
          <front>
            <title>Requirements for Configuration Management of IP-based Networks</title>
            <author fullname="L. Sanchez" initials="L." surname="Sanchez"/>
            <author fullname="K. McCloghrie" initials="K." surname="McCloghrie"/>
            <author fullname="J. Saperia" initials="J." surname="Saperia"/>
            <date month="June" year="2001"/>
            <abstract>
              <t>This memo discusses different approaches to configure networks and identifies a set of configuration management requirements for IP-based networks. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3139"/>
          <seriesInfo name="DOI" value="10.17487/RFC3139"/>
        </reference>
        <reference anchor="RFC3198">
          <front>
            <title>Terminology for Policy-Based Management</title>
            <author fullname="A. Westerinen" initials="A." surname="Westerinen"/>
            <author fullname="J. Schnizlein" initials="J." surname="Schnizlein"/>
            <author fullname="J. Strassner" initials="J." surname="Strassner"/>
            <author fullname="M. Scherling" initials="M." surname="Scherling"/>
            <author fullname="B. Quinn" initials="B." surname="Quinn"/>
            <author fullname="S. Herzog" initials="S." surname="Herzog"/>
            <author fullname="A. Huynh" initials="A." surname="Huynh"/>
            <author fullname="M. Carlson" initials="M." surname="Carlson"/>
            <author fullname="J. Perry" initials="J." surname="Perry"/>
            <author fullname="S. Waldbusser" initials="S." surname="Waldbusser"/>
            <date month="November" year="2001"/>
            <abstract>
              <t>This document is a glossary of policy-related terms. It provides abbreviations, explanations, and recommendations for use of these terms. The intent is to improve the comprehensibility and consistency of writing that deals with network policy, particularly Internet Standards documents (ISDs). This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3198"/>
          <seriesInfo name="DOI" value="10.17487/RFC3198"/>
        </reference>
        <reference anchor="RFC3535">
          <front>
            <title>Overview of the 2002 IAB Network Management Workshop</title>
            <author fullname="J. Schoenwaelder" initials="J." surname="Schoenwaelder"/>
            <date month="May" year="2003"/>
            <abstract>
              <t>This document provides an overview of a workshop held by the Internet Architecture Board (IAB) on Network Management. The workshop was hosted by CNRI in Reston, VA, USA on June 4 thru June 6, 2002. The goal of the workshop was to continue the important dialog started between network operators and protocol developers, and to guide the IETFs focus on future work regarding network management. This report summarizes the discussions and lists the conclusions and recommendations to the Internet Engineering Task Force (IETF) community. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3535"/>
          <seriesInfo name="DOI" value="10.17487/RFC3535"/>
        </reference>
        <reference anchor="RFC5198">
          <front>
            <title>Unicode Format for Network Interchange</title>
            <author fullname="J. Klensin" initials="J." surname="Klensin"/>
            <author fullname="M. Padlipsky" initials="M." surname="Padlipsky"/>
            <date month="March" year="2008"/>
            <abstract>
              <t>The Internet today is in need of a standardized form for the transmission of internationalized "text" information, paralleling the specifications for the use of ASCII that date from the early days of the ARPANET. This document specifies that format, using UTF-8 with normalization and specific line-ending sequences. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5198"/>
          <seriesInfo name="DOI" value="10.17487/RFC5198"/>
        </reference>
        <reference anchor="RFC2975">
          <front>
            <title>Introduction to Accounting Management</title>
            <author fullname="B. Aboba" initials="B." surname="Aboba"/>
            <author fullname="J. Arkko" initials="J." surname="Arkko"/>
            <author fullname="D. Harrington" initials="D." surname="Harrington"/>
            <date month="October" year="2000"/>
            <abstract>
              <t>This document describes and discusses the issues involved in the design of the modern accounting systems. The field of Accounting Management is concerned with the collection the collection of resource consumption data for the purposes of capacity and trend analysis, cost allocation, auditing, and billing. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2975"/>
          <seriesInfo name="DOI" value="10.17487/RFC2975"/>
        </reference>
        <reference anchor="RFC2544">
          <front>
            <title>Benchmarking Methodology for Network Interconnect Devices</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <author fullname="J. McQuaid" initials="J." surname="McQuaid"/>
            <date month="March" year="1999"/>
            <abstract>
              <t>This document is a republication of RFC 1944 correcting the values for the IP addresses which were assigned to be used as the default addresses for networking test equipment. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2544"/>
          <seriesInfo name="DOI" value="10.17487/RFC2544"/>
        </reference>
        <reference anchor="RFC2330">
          <front>
            <title>Framework for IP Performance Metrics</title>
            <author fullname="V. Paxson" initials="V." surname="Paxson"/>
            <author fullname="G. Almes" initials="G." surname="Almes"/>
            <author fullname="J. Mahdavi" initials="J." surname="Mahdavi"/>
            <author fullname="M. Mathis" initials="M." surname="Mathis"/>
            <date month="May" year="1998"/>
            <abstract>
              <t>The purpose of this memo is to define a general framework for particular metrics to be developed by the IETF's IP Performance Metrics effort. This memo provides information for the Internet community. It does not specify an Internet standard of any kind.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="2330"/>
          <seriesInfo name="DOI" value="10.17487/RFC2330"/>
        </reference>
        <reference anchor="RFC5415">
          <front>
            <title>Control And Provisioning of Wireless Access Points (CAPWAP) Protocol Specification</title>
            <author fullname="P. Calhoun" initials="P." role="editor" surname="Calhoun"/>
            <author fullname="M. Montemurro" initials="M." role="editor" surname="Montemurro"/>
            <author fullname="D. Stanley" initials="D." role="editor" surname="Stanley"/>
            <date month="March" year="2009"/>
            <abstract>
              <t>This specification defines the Control And Provisioning of Wireless Access Points (CAPWAP) Protocol, meeting the objectives defined by the CAPWAP Working Group in RFC 4564. The CAPWAP protocol is designed to be flexible, allowing it to be used for a variety of wireless technologies. This document describes the base CAPWAP protocol, while separate binding extensions will enable its use with additional wireless technologies. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5415"/>
          <seriesInfo name="DOI" value="10.17487/RFC5415"/>
        </reference>
        <reference anchor="RFC4251">
          <front>
            <title>The Secure Shell (SSH) Protocol Architecture</title>
            <author fullname="T. Ylonen" initials="T." surname="Ylonen"/>
            <author fullname="C. Lonvick" initials="C." role="editor" surname="Lonvick"/>
            <date month="January" year="2006"/>
            <abstract>
              <t>The Secure Shell (SSH) Protocol is a protocol for secure remote login and other secure network services over an insecure network. This document describes the architecture of the SSH protocol, as well as the notation and terminology used in SSH protocol documents. It also discusses the SSH algorithm naming system that allows local extensions. The SSH protocol consists of three major components: The Transport Layer Protocol provides server authentication, confidentiality, and integrity with perfect forward secrecy. The User Authentication Protocol authenticates the client to the server. The Connection Protocol multiplexes the encrypted tunnel into several logical channels. Details of these protocols are described in separate documents. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4251"/>
          <seriesInfo name="DOI" value="10.17487/RFC4251"/>
        </reference>
        <reference anchor="RFC8341">
          <front>
            <title>Network Configuration Access Control Model</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>The standardization of network configuration interfaces for use with the Network Configuration Protocol (NETCONF) or the RESTCONF protocol requires a structured and secure operating environment that promotes human usability and multi-vendor interoperability. There is a need for standard mechanisms to restrict NETCONF or RESTCONF protocol access for particular users to a preconfigured subset of all available NETCONF or RESTCONF protocol operations and content. This document defines such an access control model.</t>
              <t>This document obsoletes RFC 6536.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="91"/>
          <seriesInfo name="RFC" value="8341"/>
          <seriesInfo name="DOI" value="10.17487/RFC8341"/>
        </reference>
        <reference anchor="NEMOPS">
          <front>
            <title>Report from the IAB Workshop on the Next Era of Network Management Operations (NEMOPS)</title>
            <author fullname="W. Hardaker" initials="W." surname="Hardaker"/>
            <author fullname="D. Dhody" initials="D." surname="Dhody"/>
            <date month="May" year="2026"/>
            <abstract>
              <t>The "Next Era of Network Management Operations (NEMOPS)" workshop was convened by the Internet Architecture Board (IAB) from December 3-5, 2024 as a three-day online meeting. It builds on a previous 2002 workshop, the outcome of which was documented in RFC 3535, identifying 14 operator requirements for consideration in future network management protocol design and related data models, along with some recommendations for the IETF. Much has changed in the Internet's operation and technological foundations since then. The NEMOPS workshop reviewed the past outcomes and discussed any operational barriers that prevented these technologies from being widely implemented. With the industry, network operators and protocol engineers working in collaboration, the workshop developed a suggested plan of action and network management recommendations for the IETF and IRTF. Building on RFC 3535, this document provides the report of the follow-up IAB workshop on network management.</t>
              <t>Note that this document is a report on the proceedings of the workshop. The views and positions documented in this report are those of the workshop participants and do not necessarily reflect IAB views and positions.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9968"/>
          <seriesInfo name="DOI" value="10.17487/RFC9968"/>
        </reference>
      </references>
    </references>
    <?line 1648?>

<section anchor="sec-checklist">
      <name>Operational Considerations Checklist</name>
      <t>This appendix provides a concise checklist of key questions that Protocol Designers should address in the "Operational Considerations" section of their specifications. Each item references the relevant section of this document for detailed guidance.</t>
      <t>This checklist is intended for use by document authors and the working groups that develop protocol documents. A separate list
of guidelines and a checklist of questions to consider when reviewing a document to evaluate whether the document address common
operations and management needs is provided in <xref target="CHECKLIST"/>.</t>
      <t>The decision to incorporate all or part of these items into their work remains with Protocol Designers and WGs themselves.</t>
      <section anchor="documentation-requirements">
        <name>Documentation Requirements</name>
        <ul spacing="normal">
          <li>
            <t>Does the specification include an "Operational Considerations" section, placed immediately before the Security Considerations section? (<xref target="sec-oper-manag-considerations"/>, <xref target="sec-placement-sec"/>)</t>
          </li>
          <li>
            <t>If one or more of the topics raised in this document is not relevant, does the section briefly explain why? (<xref target="sec-oper-manag-considerations"/>)</t>
          </li>
          <li>
            <t>If there are no new operational considerations, does the section include the appropriate boilerplate with explanation? (<xref target="sec-null-sec"/>)</t>
          </li>
          <li>
            <t>If the considerations are described elsewhere in the same document, does the section summarize them and point to those sections? (<xref target="sec-oper-manag-considerations"/>)</t>
          </li>
          <li>
            <t>If the considerations are documented separately, does the section give a short overview and a normative reference to that document? (<xref target="sec-this-doc"/>)</t>
          </li>
        </ul>
      </section>
      <section anchor="operational-fit">
        <name>Operational Fit</name>
        <ul spacing="normal">
          <li>
            <t>How does this protocol operate "out of the box"? (<xref target="sec-install"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What are the default values, modes, timers, and states? (<xref target="sec-install"/>)</t>
              </li>
              <li>
                <t>What is the rationale for chosen default values, especially if they affect operations or are expected to change over time? (<xref target="sec-install"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>What is the migration path for existing deployments? (<xref target="sec-migration"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>How will deployments transition from older versions or technologies? (<xref target="sec-migration"/>)</t>
              </li>
              <li>
                <t>Does the protocol require infrastructure changes, and how can these be introduced? (<xref target="sec-migration"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>What are the requirements or dependencies on other protocols and functional components? (<xref target="sec-other"/>)</t>
          </li>
          <li>
            <t>What is the impact on network operation? (<xref target="sec-impact"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What are the scaling implications and interactions with other protocols? (<xref target="sec-impact"/>)</t>
              </li>
              <li>
                <t>What are the impacts on traffic patterns or performance (e.g., delay or jitter)? (<xref target="sec-impact"/>)</t>
              </li>
              <li>
                <t>Does management traffic account for MTU constraints and avoid reliance on IP fragmentation? (<xref target="sec-impact"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>What is the impact on Security Operations? (<xref target="sec-impact-secops"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>How does deployment affect Indicators of Compromise or their availability? (<xref target="sec-impact-secops"/>)</t>
              </li>
              <li>
                <t>What logging is needed for digital forensics? (<xref target="sec-impact-secops"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>How can correct operation be verified? (<xref target="sec-oper-verify"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What status and health indicators does the protocol provide? (<xref target="sec-oper-verify"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>How are human-readable messages handled? (<xref target="sec-messages"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>Do messages contain codes that enable local language mapping for internationalization? (<xref target="sec-messages"/>)</t>
              </li>
            </ul>
          </li>
        </ul>
      </section>
      <section anchor="management-information">
        <name>Management Information</name>
        <ul spacing="normal">
          <li>
            <t>What needs to be managed? (<xref target="sec-mgmt-consid"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What are the manageable entities (e.g., protocol endpoints, network elements, and services)? (<xref target="sec-mgmt-consid"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>Which standardized management technologies are applicable? (<xref target="sec-mgmt-tech"/>)</t>
          </li>
          <li>
            <t>What essential information is required? (<xref target="sec-interop"/>, <xref target="sec-mgmt-info"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What configuration and operational (state, statistical, etc.) information is needed? (<xref target="sec-interop"/>)</t>
              </li>
              <li>
                <t>Is an Information Model needed, especially if multiple Data Model representations are required? (<xref target="sec-interop"/>)</t>
              </li>
              <li>
                <t>Is the model kept minimal, with each object serving a distinct purpose and no data that can be derived from other objects? (<xref target="sec-im-design"/>)</t>
              </li>
              <li>
                <t>What is manageable, what needs configuration, and what protocol-specific events might occur? (<xref target="sec-mgmt-info"/>)</t>
              </li>
              <li>
                <t>How are configuration data, operational state, and statistics distinguished? (<xref target="sec-mgmt-info"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>If YANG Data Models are defined, what type is appropriate? (<xref target="sec-yang-dm"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>Should Device Models, Network Models, or Service Models be specified? (<xref target="sec-yang-dm"/>)</t>
              </li>
            </ul>
          </li>
        </ul>
      </section>
      <section anchor="fault-management">
        <name>Fault Management</name>
        <ul spacing="normal">
          <li>
            <t>What Faults and events should be reported? (<xref target="sec-fm-mgmt"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What essential Faults, health indicators, alarms, and events should be exposed? (<xref target="sec-fm-mgmt"/>)</t>
              </li>
              <li>
                <t>How will Fault information be propagated? (<xref target="sec-fm-mgmt"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>How is liveness monitored? (<xref target="sec-monitor"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What testing and liveness detection features are built into the protocol? (<xref target="sec-monitor"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>How are Faults determined? (<xref target="sec-fault-determ"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What error counters or diagnostics help pinpoint Faults? (<xref target="sec-fault-determ"/>)</t>
              </li>
              <li>
                <t>What distinguishes faulty from correct messages? (<xref target="sec-fault-determ"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>How are Faults localized and contained? (<xref target="sec-cause-analysis"/>, <xref target="sec-fault-isol"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>Can the Probable Root Cause of a Fault be identified using management information? (<xref target="sec-cause-analysis"/>)</t>
              </li>
              <li>
                <t>Can Faults be isolated or quarantined to prevent them from propagating? (<xref target="sec-fault-isol"/>)</t>
              </li>
            </ul>
          </li>
        </ul>
      </section>
      <section anchor="configuration-management">
        <name>Configuration Management</name>
        <ul spacing="normal">
          <li>
            <t>What configuration parameters are defined? (<xref target="sec-config-mgmt"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What parameters need to be configurable, including their valid ranges? (<xref target="sec-config-mgmt"/>)</t>
              </li>
              <li>
                <t>What information persists across reboots? (<xref target="sec-config-mgmt"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>How is configuration managed across multiple devices? (<xref target="sec-config-mgmt"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>Can configuration changes be applied across several devices as a coordinated operation, with a way to back out on failure? (<xref target="sec-config-mgmt"/>)</t>
              </li>
              <li>
                <t>Is there a way to dump and restore configuration? (<xref target="sec-config-mgmt"/>)</t>
              </li>
            </ul>
          </li>
        </ul>
      </section>
      <section anchor="accounting-management">
        <name>Accounting Management</name>
        <ul spacing="normal">
          <li>
            <t>Is it appropriate to collect usage information for this protocol, and if so, what information should be collected? (<xref target="sec-acc-mgmt"/>)</t>
          </li>
        </ul>
      </section>
      <section anchor="performance-management">
        <name>Performance Management</name>
        <ul spacing="normal">
          <li>
            <t>What are the performance implications? (<xref target="sec-perf-mgmt"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What are the hardware/software performance impacts (e.g., CPU, memory, and forwarding)? (<xref target="sec-perf-mgmt"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>What performance information should be available? (<xref target="sec-monitor-proto"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What protocol counters are defined (e.g., packets received, sent, or dropped)? (<xref target="sec-monitor-proto"/>)</t>
              </li>
              <li>
                <t>What is the counter behavior at maximum values? (<xref target="sec-monitor-proto"/>)</t>
              </li>
              <li>
                <t>What are the protocol limitations and behavior when limits are exceeded? (<xref target="sec-monitor-proto"/>)</t>
              </li>
            </ul>
          </li>
        </ul>
      </section>
      <section anchor="security-management">
        <name>Security Management</name>
        <ul spacing="normal">
          <li>
            <t>What security-related monitoring is needed? (<xref target="sec-security-mgmt"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>What security events should be logged, and do any log entries contain privacy-sensitive information that must be controlled? (<xref target="sec-security-mgmt"/>)</t>
              </li>
              <li>
                <t>What statistics help detect attacks, and what threats do management operations themselves introduce? (<xref target="sec-security-mgmt"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>What access controls are needed on management interfaces? (<xref target="sec-security-mgmt"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>Do management interfaces support role-based access control and the principle of least privilege? (<xref target="sec-security-mgmt"/>)</t>
              </li>
              <li>
                <t>How are ACLs maintained, updated, and verified for consistency across devices? (<xref target="sec-security-mgmt"/>)</t>
              </li>
            </ul>
          </li>
          <li>
            <t>How are secure transport, authentication, identity, and key/credential management addressed for management operations? (<xref target="sec-security-mgmt"/>)</t>
          </li>
        </ul>
      </section>
      <section anchor="operational-and-management-tooling">
        <name>Operational and Management Tooling</name>
        <ul spacing="normal">
          <li>
            <t>Can existing tooling be adapted or extended to deploy, monitor, and manage this specification before new tools are considered? (<xref target="sec-oper-mgmt-tooling"/>)
            </t>
            <ul spacing="normal">
              <li>
                <t>Where new tooling is required, are its requirements limited to functions that adaptation or extension cannot provide? (<xref target="sec-oper-mgmt-tooling"/>)</t>
              </li>
              <li>
                <t>Is the management interface designed to remain stable under high-frequency automated query patterns, including those from AI-driven tools? (<xref target="sec-ai-tooling"/>)</t>
              </li>
            </ul>
          </li>
        </ul>
      </section>
    </section>
    <section numbered="false" anchor="sec-ack">
      <name>Acknowledgements</name>
      <t>The authors thank the following individuals and groups,
whose efforts have helped to improve this document:</t>
      <dl>
        <dt>The IETF Ops Directorate (OpsDir):</dt>
        <dd>
          <t>The IETF OpsDir <xref target="IETF-OPS-Dir"/> reviewer team, which has been providing document reviews for more than a decade, and its Chairs past and present: Gunter Van de Velde, Carlos Pignataro, Bo Wu, and Daniele Ceccarelli.</t>
        </dd>
        <dt>The Area Director (AD) championing the update:</dt>
        <dd>
          <t>Med Boucadair, who initiated and championed the effort to refresh RFC 5706, 15 years after its publication, building on an idea originally suggested by Carlos Pignataro.</t>
        </dd>
        <dt>Reviewers of this document, in roughly chronological order:</dt>
        <dd>
          <t>Mahesh Jethanandani, Chongfeng Xie, Alvaro Retana, Michael P., Scott Hollenbeck, Ron Bonica, Italo Busi, Brian Trammell, Aijun Wang, Richard Shockey, Tina Tsou, Lars Eggert, Joel Halpern, Johan Stenstam, Dave Thaler, Harald Alvestrand, Greg Mirsky, Marco Tiloca, Jacqueline McCall, Tim Winters, Eliot Lear, Giuseppe Fioccola, Bo Wu, Qin Wu, Saumya Dikshit, and Paul Aitken.</t>
        </dd>
        <dt>The document shepherd who has gone beyond normal shepherding duties to improve this document:</dt>
        <dd>
          <t>Alvaro Retana</t>
        </dd>
      </dl>
      <t>Claude Opus was used to distill document content into <xref target="sec-checklist"/>.</t>
      <dl>
        <dt>The author of RFC 5706:</dt>
        <dd>
          <t>David Harrington</t>
        </dd>
        <dt>Acknowledgments from RFC 5706:</dt>
        <dd>
          <t>The following acknowledgments apply to RFC 5706, the predecessor of this document. Some individuals listed below as reviewers of RFC 5706 are now authors or contributors of this document.</t>
        </dd>
        <dt/>
        <dd>
          <t>This document started from an earlier document edited by Adrian
Farrel, which itself was based on work exploring the need for
Manageability Considerations sections in all Internet-Drafts produced
within the Routing Area of the IETF. That earlier work was produced
by Avri Doria, Loa Andersson, and Adrian Farrel, with valuable
feedback provided by Pekka Savola and Bert Wijnen.</t>
        </dd>
        <dt/>
        <dd>
          <t>Some of the discussion about designing for manageability came from
private discussions between Dan Romascanu, Bert Wijnen, Jürgen Schönwälder, Andy Bierman, and David Harrington.</t>
        </dd>
        <dt/>
        <dd>
          <t>Thanks to reviewers who helped fashion RFC 5706, including
Harald Alvestrand, Ron Bonica, Brian Carpenter, Benoît Claise, Adrian
Farrel, David Kessens, Dan Romascanu, Pekka Savola, Jürgen Schönwälder, Bert Wijnen, Ralf Wolter, and Lixia Zhang.</t>
        </dd>
      </dl>
    </section>
    <section anchor="contributors" numbered="false" toc="include" removeInRFC="false">
      <name>Contributors</name>
      <contact fullname="Thomas Graf">
        <organization>Swisscom</organization>
        <address>
          <email>thomas.graf@swisscom.com</email>
        </address>
      </contact>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8S9+3PjVpIm+rv+Cqw6YkaaJVlP2+XqWbtVKj+04yrrWnJ7
9m5sbEAkJKGLJDgAKBXb4/3bb+aXj5MHhMryzL1xO/bhEoGD88yTjy+/nE6n
B33dL6vXxXfbelEt63XVFddNW5w2647+0Nbrm+LHTdWWfU1/Kcr1onhXrsub
alWt+6JeF2ffXH5bXGyqeX1dz+Wpg/Lqqq3uXscX/yG+Zo3r44tmvi5X1IdF
W17307rqr6fNpivvb6bt9fyzL55+flV306dfHBx0PXXgf5fLZk1P9+22Oqg3
Lf6r658/ffrl0+cHZVuVr4vDB/t8eHB/8/oTQzqh94tfmvYDj/y7ttluDj7c
vz4oimmx8qfwz8bbGPwTTe493BXzfNg0W6+Lq/nmoLnqmmXVV93rggd7sN0s
Svzr+YvPnx5026tV3XX0Sr/b0LB5wg8O5s2COvi62NJcvTrY1K+L/9k380nR
NW3fVtcd/dduxf/xvw4O1k27om/eVTyM4s3p+fPn+K+fvj199cWXz/y/X7x8
+vrgoF5fx+dPv//m9F9+OLu4xGOF7paH5++n6q6u7ovT22r+YVl3Pd7i8dBw
nj7/TBop25uKBn/b95vu9ZMnN3V/u72azZvVEx7d9Mfzi+nbs5+eSFvTy2q1
WVILT2hk1ZNVWa8PqJn0ZN0O+tYV9Ldq3jfUx6o4orlf1O3xY3pCP5d9W84/
VO2M9+GsaW+e3PAueCKtPCmvmm3/hDtw/s1P37775vIn6mn2/fOqxQyu51Xx
rurbej7oD83d9Yp+2O/U53+0U6Gp0DNMzfcnp/9ycvn9j+8vXo+2en9/n1pb
VVVP++nJLX2l7G9pXZ/EIeGQf++/4adyS/+tM0/7u73RrZnP8vQp/Z9n3KmL
b05ptcb7sq7n8242r7tydtPcPWmrrtm286p7crNsuq5sd7Ez789OTy+K7+Iv
8Xuv+GO0yZ+9+px2s/dyigevt8ulyJo31bqpSRQty7qr8BsNoVzXf8e2fl18
c1e1u/4W8u/8guTXSdvOtzL0ivbgks4umvhL5U+y1Jqtq37/a/+9qfhT7Yex
T53W3byJDf9tjkf/Mucf+FjsN3iyaOtyXXxbtm21HGnzx+WieNvcQNRul7y2
8QMl3v5Ls1wsmhv6wGz7Yf8TF+WqrtriDa3Vth77xvvmQ13GZju8MbuSN/73
Td2Wy0XzlzU/Nz6M07KldSzO65s1bfK2GfnKm+W2Kr6t2vUDY5mjib9c0WPX
9NRsnj+1beu0z0YfGvbpJ5pXEl/rkb7835ffZJ+mp2YtTeTf+4rHN5uvWTKv
6cxfbfvRbXd526zKji6W8nqk/Yt7kvSYqPSRHm/MbuiNv3T6OybzYDqdFuVV
x6Kh501fvCfBe942dBE0SxHM9q/im499te5EYLcVbd2uLxZVR/NeLYp7kr/F
You9mV1SRXNN36+o/+s5/7tc1v2uWFfVgt7qG73zqnDh8eOrGW4UEkvNdd3z
JD98OQ4uxaLuCrrwmk1fr8ol2rmk72+27abpKukOPUIaw1YUkI67sWmbO2qj
oF23gNilv8nBx+e4lRZXSUV/oFHd35Z96lK5HPap7Eif6aknt82WztEVJqZc
LEgudTxdtOzFfVtjZNaVjpUhnitRiOiqKlf0b/qQd7YsuqgnQc/Kl4z+MLZi
9GdaqzntKsxv3RbbrpodyOzE6XBNgu9zKBMTGjldnnPuas2zTVcpPbDcYczQ
NPSk0K/YB2vq0Sfmpq/mt+v637aVriT9kzZwt+pmxRkNcdnhDKsKg26wFoPN
op3j1ujXpt0V787eFHOaKf7UrPi2pu8tdxPuSk2HqFls5/wZWb9/29IdKl1o
6Of5crvgjRdUPepsrlkeFl2Ffctrw+Oi7vA6cYPjS1Vdkwb8n1iU4kh6xtNN
grm6K6m//+Pk/Xf8yXcNadjd8YQ2UL2sdNfykzQKaqncVAUJfm6lvi7WDXo8
OB58dumf6552UbWYiQxY1YvFsjo4+FNxprOGMf/6Jxr9FBP5G/bKj9fU+Yls
30cNkb+2oOttSfthMaEuQZujW297czsQFLQLb0hjXPPi3Db3PCM72k/LJZ0e
amOzbHbUBL+uMoPaSztrMXukuOAG0pbjrzY8qOK2bBd4tGzntzXt0X7b8l4q
tmva72VHyyDfm1dtX8oO2NiIRQ6SNG9q3m+rckf/94N1mz87CT2amEgJh2JT
tn0939KtTZ9c1NfX/I+ep7Ve0yJs20pEWUOT121ba7q8qlmgTrAZ45mr1nd1
26xFavgE6OP4Nhk8PLO2CCSVFlsYazKYMeGgUrKDmFRTj1erWm7S6r+VO0EE
p9lB3BZMoa44+uW77tg/m3d8T7bn1waJOz14dS73xrdfUfY4GJjTzW3Jx0Ik
rAxRl5BWrPu0KPz116/p3LMw/O23JPXoh7qHTdbrvnqM9MuPYybyosT6D4or
bmZcYv0hccXN/L8jsd6SUmZiayYTbP3DDpw3pPsWVw1N3OMnDYt1sljU8vQS
+z8una3Pr79e6Meez5695MufZoNvk7/AhqXVpJ8O4bjAXUrSj3S7qqc54hum
XXTFL3RL02bGzMYrqGU1sFrP5QhkF5LsYjq3fVUuqF1S+vk71juep9uGLdt6
np9LvBemYU+bopY7XwH+BI2QRTQ1PaUNI44PVhF++20GtUcmgqWcnt3wEs/D
VB6gx/lb325bWtV2OJu0C2mVaAzbnh9WbciHD6G5pPPUyQEgYdWKtCCtkuXh
xAVlEn1QApplc1NTC9tO+qVDx32m6y8C6U6aoZW5J3mSWumqFj+x8L9mYdLo
2Fi+31TdtKOtWU315PIKrxrITpLgS95Hf/qT7Mm3Nla58nj8PKm/fUoIkjJG
O4X21E3u+LIVU7H3sHCjEZfq/hKdaE47P1PwXKiwGNuxVnrP19RVxdNyvaw+
1lekBogywFKkIFW+vsOPcohr3tDogewwOTrf0CZsWYPLzz1fWyp2CpaP6Mbw
9PGAq4+s3cpGeHB4pqSMyRFaJ+p7x0tNj/Hs4U6yWz7tF/TptryrSL3pyys6
NLd8UdFppb3VDD4+vFJt/4moY1WkXJLoW5BaUZFasV3TmLq+aRazwRIvmgpm
OqkrerLpVWi+bXXLY7jjm4R0FZx4mhCSQZn4GsorautMxAFUU2yYzg0MGogL
iQ+k9Jjx4N1mo4GWjBpON2A6Qbt/7IbagPfFVCTeB2s2bGQDXGxrns3qkybM
hlahJANVFuGubHEBQzmpcMDZUUpnke5zqGX8flq4cOOMTS/mlqZTRBleL67r
j7S4JF+3stHaQvyI3NaiIhFD+xqn4eFeoyGdPloXnC3v06z4vrlnXwvUJbq4
Rq20oBDxcMv17hGqhl5JNBeYrAWd4UUlC8g6QlIUbehsAcfTuayyw7S/HNyV
otNrqf47vZ2u1klxte1FaPtQxOhhuXSVLGxbApyhed1hh3B3eKloMaByXheN
uosHC6f6kki/rllVQ8lH27mrRi/ry8GFMm9IvPwdQnQBOSC39BUJ+IqU8bgN
f+9KpC2+pA+zQYFjcd/gzMyX1JclCzR2/C7C2qvRHHWch020NezcR5qInYnP
xcwHHX7EIVS/h/oCRPN5eLi2RdHejw9KmGIjRgm3LPqt2R1o0LRoGEbX6UDY
9cIXkV2ubO7f0BZbcu/oYbL1WCegBzLRqlOFURUsZ0kkwqXAVuqDvhkXc9zJ
rbhjhp4BVQomRbed08XX7Un16J1KyvygqaB3zoo3PMl9s2E/uhwQbhRmpalS
Og3c3mPWWnb1GdxHm4YOCwtTHPehITaYARi0Y5dsuWq2a5FaffVR1g1Cgpb0
qoKolIMrpicrH2Qz8sG2Y2XqdXmHK69KqzRwGrXNipqk6wz7gc4ErfFyRU3T
IbhaNnJcztYiUOZsNlFrww2YT0xS6kn6sUXEm/FvrOCXPONtj+8griNzvonO
QZLxpC6pzCuTbkljh1TEBkxuMsyzfUR2APQ5E4MshIJ+apauB7FE7zshiwUf
EZWv1H+aypcJNzhNwum9wu693i6DnxCHSV164zPfmTdyx6o0tyx+RGrDzWEW
TtFTEPUpSPDgUYCXpMnEswxehYa8oU/pBoJ3FWdWvtn1MLMxNejeQFQPxFbD
dz9f1aZ7igrML/J0ydhJmtebJU/bZrOkseNsNKxB1A0d/3ndUuN8lUFzP8tU
6uu2XFUshzATpFqo3aVej37odx3xbpVrdPmmpZ/ZrWK7bOitUdPfjQm+qFkm
6RXK1yKtM12FuKZp/vj0kf1Vr+jE80jZur7dQlTCJ8y9ZitG5CUrRyImRlwj
+g1fdlKV57efdlqxMJABupEt0p6scBvaJC2cuNB4N8iL8yD23BEtO6Tb3tyw
N/9og1ND67VzTeN4VPaauhekrJ1K1T5g0oV7LnRF5VSNVrp6VS9LWG4la092
tjEtnc4LHGBsH/e37Ordm4XkFNqfiI7dE6rfyN1cXFhz4zIMyiytxBDQ8Ise
bvZIX7KIpjV/qKlff/36zen5F89/+w3xWVkM6XvS0FbU3k1yZPbsVdW16ET9
prPEEt4WI/ocswm3lkQDkg/FK8pUPBxlSF6xLR66InwXpc7SFcF+r+K+lFnI
BdVQWzUlnk6XqPE0sM2G7gF+lUyuJSw/kaTuH54VtjNydyj3HNcQ/M6h05V7
+sTBwRGehd0CVXHF70RVBWpt7hxml8BIt6krri/WEiTy6ZO548Of9pid56U4
G633uiIPzxNEk7YG+cG2IKsIbHZAAbopN9SbC9a2h9aBzmMKWpEiIRorZpWE
Ft3wfAxvW6jHQStkC77FfYebHl/iKWZpqFapDsm3Aq4qqLhlR11gIUHrSpdK
BQFfWjSw6OtVZfbQnN0tfiM8FH2jfjTblmN/mL4p78C6I1VRlHAa9C08xeVa
zXFxEe181/rCzXTPu50FYV2FwNnApopzao1AANCL2Ho4Jrgfl0Hc4VAhiIkN
Hh7eYoeNfi8LGfB2NKfhLMGfRpyZPhZTG/XA8Hd8w0KAzkmnWzXsrsAIPMrz
aYXUFV//IgaiAxBPSPkYdztdoNXyWuXO9di1R98WN7arysmLgd0rJriGdHh0
bMJd7XRWzyERSdlrd+KqvS5ZwYPlCUs789xAe8Yu6dsth3NEw33Qhsasr+qb
W9z77BfHRmBpIiKgdKNZZ8iFIx0nUnRqc+l9YrrTvua2p1ObCRF7GvdKuwTm
QjADLPSVRb4+rWOUd03NeiPd7O2DkTFzQOMaZrkFN5PETFR90l2XxFaVXxqy
7r+IiKabPF3ifyC8I16LdItn2zIpTdD8NYroaDONh7OHr2pNb1QnnyvCe5Mb
g4sPRRbZGhhA79i30qRtJquTewi5ierjbUnmB/3zz2r8pk2Te/vkK78gaKLP
iJs1V4nckP7U7UtGmGmMZq3Azb8wr9z1lo8DjfK6Z5tD3P5DN0u6IwraB9QK
rexNyTfKzG2kPaQc/YH+fYzDvIXlGEUZAlm8XKquCaaCxn5ScDxk4EyHNQiH
j0EB+QEGDrjIs2mZqKZYOkwj9YDul7tyueXumTMj2waq/lsnZSeZ3gqJuv7E
XEOlnexHWBz1yLEV+FxF011qsPb3MH6//hrQgb/9Nj6hE9nlNzIq+Eb73HJF
Xzh6+fmLL5/+9tskLIFOvptHoUP7SBbY4dePugfGPH4sPTk+QU3AmmJzQ31V
V23DBxYzvV3DfX1/25CeCVM/nuBJ4cgoXlZ3OstAPHg3fcsgYFqTvvyQCbx9
aUx9kWtzu+7ZK0B6PetMch9pKIj+0v12cPCAC9vDocNISwzg8gbvoGRN7JLC
y7KerLdt6p5kIN9IJBJIEVx0GprV3cTWxLOXtpUyx6I810GWoLNqe4nS16gu
HI+g2tIMEbSgo/sC5jtVNqUp4Dfa8l69Rha0kaAyvwgP+97MS+QHhrBhQGQw
9IdKXcWOyer21MIZXyNsyScbaJJFHNsqnTZuzSQYy34seatqbN3D4yPfr80h
/U/FKYNkXpP5xgftv9Bovvzy5VNML/32w9lrsudWrJ4VP7CXxnUNFlS3W/ph
2rBk7M2Hz7/RftttRIODH4WVplGFBWeQ4Sb3PA7WSJrr/l6RMhyv0tePqtnN
jL08HU8prSbHoSdBaWX9b0eLtpLQOu4f7nQ3UfHa7UicfZxYd9RfSlcUaTHs
uqGHe5Y7JgFKdr7wV1LExw/MlQ/LnPQpEHRXrRcN981+2giGqJNdA1WBWtb3
5Wm5YisG/Iw12DrggO38UncJqdU06qW1pJ+ZFe/pFPc0EZue7ZCk4fEU0XJ2
6QJbkaxhhdJjU7ziSQt8TQusUd0AEhK1Qj1osFwVdIn/7khi83+EaaYXFzDN
GHidXOzJquW9As0KD3ALlYyVXUswCbQ1HPVttwUUCfpF3cFRRiJ3qRIgNaN6
bme+c9yqkIRkonXWQ4RExDiv+jltsWFr4bYT5QOaubjzRKVQhzDrKvsfbfk6
4zt3onoH+/JXKw1I6ifh6c0+qw2K7w4SdLu04K3iVHjVltUN22o9AB5Hulh8
wVfdMc+hhv5Tg3iUMfzJ6F/bC3ygg1XH2x4KYUtCY8H7ZEWDhs/CB6x4H9mP
azrWSf2URuBS2GWejaK8KkT+zAxkoa0le4Dbi/40nfRrupsW6Rp/8fLlS77G
Beaglw79IWw++Wl1s+qnfNOrVPu23C77ByQefgthm9cCmRX/qN/Z7AHlqZCn
6f5Kjm0JW4nfc1m1fRe6U9J2X0FDapZlaqDj27yVrSjzuzIPN51p/hMu/uXO
YNiFCG12hmAMPMjrFcYZsR3BHMDY9taHjvjaQc9Q9aBC6OmOoGX9LJ/5vhZd
qnTbNADsTNxucP/3CF6ROBJFJU7FAAKI7Xxf7twatmglLumSHcI8pSLbV+p2
8FNCVgu75cUaGzhD9D7ZdtTVhL6xTUJTxdkwUALjrpKZVcQU+zD/Odtjurnk
j6upeHtk6rVhu4bzTb23AnIFv5d4IxmsfOmx4JXrT215RhmLb61ZQzZidTVI
meR/iAWKdK03gsxb27Nh1tXzzKqNry3L1LITmQpVtGhZfmDXWx9szRLOjYTA
nXhSxVaCtdVrBOC6LV0qFqwFitGs97le5OJ5p6uBERbHJBbFCikKu/Adi0Y9
ueTcEJJ2Z83lcYJD0Qbs6WLwL5s1rbtL7WSSZX+vrG1+bkmD7FKAz20J9cfQ
pqhVh7yp+G2oNAC5VeXad/MunISepbXPlh7nZGDhIOeqt+6AYEqM5xpAEnVR
GzWsWD9EJsASMqfXDr0CxoldqwF/xv9M6sW1q7TDLaX6SYZZSkgSv50rC3KZ
3HhcBgWH7UzbsWtqXq05QpZkg8IrgX5Z0oUE941B3iYinxd8806CshIOeegZ
PXJNy5i5+7p5swkuWdeQsTY/nryLOXqT4mRBhlHNUjPhit4lXJFZmc+/fPbb
b9oF+dOzp0/ZcjEfOjaYA73jtbq6qtc2ja9h5zybpS4IyEAEsQOjsLPIzJPG
PlTVJrRox6LdroF8KFMocyZRWAPVkoVfixJnqrC+K+bW89lg9Ht9kS9zgh03
4Mln6m4Z9Cf4ona+pQc9gmHcNB+4YQk18lVsyWrY6fI5bVSwt/pZ6fWLWbY+
octwRLEzdM0wOrZW5Q6mS7CsVTJtNzctqcpxp+/EhK/Xd83yrpLbW4Afgvyq
IBHpnyQnOiiEAMZ+qMIcmMwIayOCvaLDgMaWu+RdSq4BGsEGkvDwQU/MoV4c
nX2u2179jf1ne0GHKPRpn09wsSuaGEFu088GuByYnJ3iaDj40pmc5d4N4ppk
Q3MghOzydUPmM22+Q/rWMJWYj+nhj//w7lCBLuxILoPZ70dKDiXG3rR8WdJ/
dgKSiwlgvAk2LGg5JAO0HnybQ0itiRyxHidBqNArhrKV+eQVEitsxxsmRN/y
6zEzWHQbKyJDA5DLelX3MB8mgxPR6LhYJ1w224X1h1bFjx1+pfvPtITrZVX1
2a7iB27ZdeEHbfA2ItbvL568vzzHF1wJzx8UfQty6tB6duh3YuZX2b+C7GYS
VYI0yo6l1FJC4JUYDx97Dxgs3U/E+gfJ/7a5925BQGPhR5yFUZX/4osvv9Qt
QpfNFeJxPzU05Zmb4+uz6Vvk607Xq2Yz1VmacmyOL83pjvSe0Aqt7QPmwqhX
A2q1O0MUE88hPUeWFdWyipe1nlbeGjEmE3xlihJro5NFfRrmteVpcj+GO2DE
dxHgVYiJipdhoNXZvv3mY7kCaEUAcj7AOsWZTDif/nA2yXaexEerq4Ij3Bqc
fUMryV3/mf8fn6Xi6M3PZ8f29ndtubkF6nv41Hf8FNoRb8nUlftwqSeVhWT1
CmiutABHJ+dnx7ZceWhIl2pB98Fiy1Z6WSAXPJnMm6qhuYA0MIT6L9+Z5Pco
QowIQZsdQteLYl8jGgdaoqOXDoI3OP7rMaEC5TOPVZoXtgtXjdgnk7xXk8Hy
TwqXkRbYKqEiftrFjdQB76VI3p+Cv1eSSfZ5LdSnvJ+uAUTaJ4GHlsgiLbBc
mmLzTXOXtsDXTpbLoVO2GGaSPpByIFG4bNEORJ0cifiO5wMJOkfBNn881RKx
6+s92IWHXbPEwHJxx1JR3MCb7ZWr4nThYgHYU60A/NH5EC++76bxSUlo1IQa
2zT0rZ2ckaAd3lUjH5tgTkIMP5sXaTqHlp4gMqeBK7OoYiTjSDwg2AiyBX77
7XgkonsU3EHhuYSRL4dg6PG1nhQJIy4wP8uu8PzosP9TlDNBzg/kenwsmjpZ
KtCnslBzccF5PdH+jwDNLDhaLgdo6IFip59pq2RId4b5sTwXDfcDJLMXBrad
qA6kCLuCvsxg99VKEZQPp43beu1/IAL2NJlRBfADiMYZ5pSWo+KLbyLvyBKJ
/iq5EYPzwFN4W9/cLncJj/Op48sNfhIdffLIhda94p/J3UeK7XsQI98ZsLtl
Go5918DMUQnRjyRmHqLDeLk2hI1gCrEB7gP0bXO9XSqiIPXzinSEa3EvG6iK
lXekqdzudA9pyrOjFZNdbio6j+4xUdWC868Z8Nd2HLr39MfQ9id3lgw14AsQ
tcRggGvlpKgZMFtrxIeyqDtHF1PkXWyc/ZRCfyVFKquYAVEu78td50eF1kVg
O+qqQh4TnRRPEWBImrgC/qnQmODjZkt2QzeckUxrGz9xIuc8uCpbUQH1NtFu
hH9642X93tt9zSd2X+iCBd14r/HRlD3GyNjdbG9m2kovmjwLOcAcx6LTRWkj
It05H78vDP7oO90XfL1dLqcd55tyXs1ySdaLTfLVzo+ILUG13+NRALdm6WWJ
rhJdYB9vl7vnObI4cGK6ZOGoU4s8I8DeYcQ3tQILRla0M993hBy2tCfTHWy5
Cr8/lLEsD0/tkBB2ntNRjKZ1PLAge3kVjpZhw9pSHbJcilwFnAxzid1rl2XA
ykH+tnlUwn2uNDlySfkSYnRLneGcJn4cokcdSZBVCfwsZ3jSc//94sf3+md+
/N0Pk+L07dsfJI54bHqZPX9QWOwN/DxIatk6Xg2ohQBuRBh4lYMzgHD1G/ug
GLmzVXcSRTlED49gBCmg3bt0zGt9UARFCGpkSEzQ0I6gJ4uLfTUjT0ngtrZi
BCZbjF0HsuLW8pArRuxts6HyaaM15hWuxAYmifsVmTOA0WlSsCZXAzuGYw6n
ZLOeJoCbILiuUzM4p0M1Gvn+/LJlg0gSKX1Q8pwXdGji7ne/+sMonhiXyYTc
a/WgffnlZy84RPpV5gTptnU/XfW1RFPluRdfpH998dkXL8Nvr77AbxIDw18+
++w5n46viu/Em01z44O6K2kTIO+lLdcduwU4S5H0LaxRN8l6Fm6ZeTNFQAIn
lmeEmtecHvY0MmKHIbmSfcl3ctRtLZvVw/AL4MmgvNO6cOo4z9GyaTburjVX
ftW2tHKGW+BRnZDyOslmrN5sVtO6KVdTj9Gr0wh3+9oWXnZfbqHLrukwHBrM
FW2DhFu/Svb8ELBlgxocGZYbfG629LUAO+ZNHPhb0jaC9+/RWZyu9wNMf+8C
Pms6sHUMKT9GINZBJLMHwkUkfLTN/boTUo6BRt/NRHU1NQ0SSoVB4pUQGW4X
lJtBEe4fg9VlR4Jxo9ctM/6NRErZvO0155z6C1HcrBP+K4428DzgDlrvYEdM
l+weyhUN2QoAn+4N1fHKYuvMQupKssMazfVLwW6a6+v6ZquBmQBhyjM7ghsv
uWN3bjciWUwFXL7KKpXPrvd/20cD+p74nS0hd3r1sZJ1+LRmpbgbpat4lJPo
TVMvqxaUl7KB3je4vgdZSt/wcqpHyb8X3A/lvu8QSKqQIp9Ms8AtlK35I1Gj
E1kQyZ7X1BXZL+tmYLLnqPGBsc+8dFPbkiYx50m75LYkcwM7bGjkaTaZk71N
VPwyJJX7poQq9FHO9awGAeLMKE/OC4dbI67LzaWwTHwFyECOF4lualozmlBD
0TIQ3ESyd/+xG3LJ9PZ5jkMBz9B3GbmT7OncZsjbyJ2jY3v4sQ49JftJObtJ
jejgkk1nIFkS0YaA4ePxYThebncx5AdjkQb2f+h/9PPh5X/YHPJTLKYM0IJ7
hl3xP9/ktk1xw1KAP/q/DqUTZgCLnj/HGsjlfJBsDd2B7I6fK/RHDJNS2LFY
Yx/jVUyQfIulf4JKqAvJGXuJG5LaMnYiDaOUJdIdwE4UC838Url5/Gk/xN5Q
3N2WjmA0W/YNq7CtVB1AB8P6kJw8X5Kwj8kqf8C7vrF3k0A8G1oG7ov2hZTc
JbxL60mPLRi4jMgTJ8rh2d9JPVXaSyOaNKh88C4k7+hyyTlKC5470qBrdvTJ
eqlzxscvKaI4ZWry7OXyIJYtlytHzOte/Tuyb2VCTxVXKa5XY4fUGRvhW/Lt
n066QTNB6JPguLrlQ9YCHPmg+qFxZ/RrZJtMtStJ02HRsVWwcUCbyZX+hnMN
TpWT6lwvBmrkzE+cZ2Dt8Yc5+SQUm8Ui3+aWVMNGPTX4jnXa391pyauGq/5k
ww6v+mNxwgsRaOaQieUc2HlCiRD6OE7gu7r/fnvFE3OyEFStOPA+0Y/U8iGr
F9KFoz0n3rHorrnzb5D7lnzT9foh4oPUt0hrJ/Q6j6bfLJEKdx+s+P9QNOsP
hbL2efOYbqYxIiLXQt2UkTRIAwkzvWbxs6gMwwDOnmCcKlVNzo0mwnAJIAtT
5T37rNhVZSt6lQS/cGvxcZvywO6EzI6NA4HTghuDO8ZG05RF5cID7iR76YIn
o5Vz2wGXZ0LVdzCs5NKwhTuEyRW8HQ9d9ngnjPnwxI3hQAxzGcZ4WCw5a4Hp
S32jDLZFDpspLjXz+cE+kLyyLjTpFIusirx3o+REEJ2diAQ47CBYfpdLUBzV
v76mo9Jw0/SPr+TKTY5doHpt8pWZAVhAOACMqyMRIUsjfqqE+M0ycz1hPqdo
AGg7o7T6CpkDNElgi7MsMePp082tfRqhe5hxPFPasagDYwZ4pxi3iuX3RHih
tQgOU+VPK9d6cX8Vkn1wS8TWhr21nl44qlY0wK/inogw46OLd2fHBgruJEHd
ErP5sovcQl8V9PDp+mZmrtwh6Rb3rDbWLoXh5Zex9SYbdkriXJrOK6nzKTA0
ZPLIV1t0Nl8uv0b//9hnTq/IZ+lf6X8QrI9nsfxqlBXsK7JLk8rLTX+zqIFv
O0fOj53F9FWfDf7Leru6kl7xNdQpFTlay9X1PzGZQ/ELq0yPDB99KwTS0jFT
Hr5JXpSvIw5Dw+oYUkq/fqTd61nNZKkwyXuKRw1vDCjeKW7PEevpfdMuo6en
s0RYzh4R95+EfsWJg7uJ9r5EiS/kEEiL6mKSID2pneU8OK/c7xN4PRQhOrAR
6dzeCgZZ/HyeVr6orrYgRmJgGWceaWp55r/xlM5Ss3ZIhWZs08AJL0HMvry+
lrRYzxBVCGb1sWrnWpQBSdDK5aMXKfvGdGr0gq/bEBZhyKLozCA2vqs5+6r+
e8WnRmPA7JHZjVn70dPWqecQtOh5pjn0fFVrnz97RRpdoEAKFKXoaQqGK+88
Y2ot/KCLyWZTLjfes9+M60o87IZKKUag8VgPOTwkEXQvqsX/4uGyEBkGGerO
s8QSW1W1yOJp9agNCj+b5d3vjMZkzj2gFkscwAYaVmS5fjhFvQCvCQYgvCaZ
6p60WQPmIBNRsLqAA0OzmhUn/zE2FD417FnlQW4lxUm5lvZT+z/hOeaZCFn8
gt/QCNIomwsnM29XYJ5RGZvHdSB033x3Xlwvy02xoD/zqZad+Pzliy9pJ96X
5iXS7y6b+Qfx6F63AJXMd5LEgkaMnIYbHUAri3tcpxVt6B2EZN+KzYKAg55E
UBM1Rg8kotscfLPixx4pxJIEB8vmelnPez1ZLGxwwTa+oYHRvS6XXZUPMQGX
aHW58IuKUDJJlRmXo4ClPjfJX+YpEZZ47BRe7oRhnzJ/raamQzNoctCap9eS
jn1TCx5J7wgVV1cVGcQ1r9Oqam8s7ACl84HNzgYY2TrqUqTu9xxqYlWVvZL9
3lFWJxPsbjHCxZSlVeQTJgY+KGrJyFL8HCd3c0IIffmi6rcbrwaAh9RNvNYC
NzFN1CR6tbC/rLgKjf1RZZ8p0y9mr8zyffblZywKjw5PIgU/3ZlOKKczadCl
w2O9CLjW1ZhWdMLcJ/ATWbxDVEKLETChFAtJ53Cc8ZAeeDpHzoRRAjN/0/Q1
rLfFbl2uFIY8YC5CFm8CxjxeOWD9Rln0rGDKYYhrXzUfD608gPt58ov1YYKY
hK7bJWkGjV7TNFN0Vf+GgLXj/tIEzaKwmahNwI/Ye5J0q7maSA/gzdnCCJUn
5NanYbFlOBeB2LfidOTgquQx++MeXdXYEzNMrH+PdC9q5Ffl/ANjn1ljlbmc
s39+bV+Q7y6tVone0rl7XtGlvMA7J9ES/plAbiSur5zRhnaLNi60Q0iWQXAK
x5r+QxzF666ycFjwkQZqG+M1sUWTCj2lJPkIhpDd7wNidgeixPiadJQvmOiG
gF4mdyIQr4FIRfm5VW/ZrjlRraOVw8gyZ5FC4a6SDFrysOlI5BtHPJSywgnQ
Tnu0WshEwYUs/YRPBCKu7DyOiUeh0vKGrlyrnLe7Tc9geUbdF+Xyht0et6vA
+rQ/E5Ae8SPNcoE0Z3+ZZ/Dwqm0+VOvDmRoB2X7X4SObEmLhurzTcA7filV7
J4FhKFbyLbHIDlHFSPwygZ7lUJ5UCI1cNiKof+KdPL1s601xyd09+uny8tgO
6vDHv/J54tuEn/rryU/H1l9YLpen59y7tTnGLReJJPRx0iyCLPUrALkX2jms
xNRTlY8nXhaBPqIWuQUEeliunNAfN4BsoxLcoKoWBPyXyQRxkyHyqr+0dfdB
czlgcZhuwNGcdCyDB82Bu/BCKFKRcb1G76vuSksJkk+C6UDRAXNk40qHa7D1
KD/PMKIJQ2FZGTOOJyiyIxMqaBCanlUGKruWJ0mCgSS1WBjeNo1ql9tFnfRM
cLxoplcgenVVo5y3rATtJcM8oDKKZySyu2sSYHaiPlS77nduGjduWZOCnsPO
ZTkarnfQFNYL+Wdg4WC7DIhqi6o6ObyYvJu2vuPbg3uBQwlajcVEbokV60VK
7MUxlcZUkb37wS5DFucuDwJBjrjwIRItpZvtlM22t0pMHzcl4hI8tMSAQifh
WNZf7EpS5q41GoZMyrUJfkfXzAZFTtzLnNQCif6JkAcJCNPUKq5HhinziOQ7
SwzPFk1QNG73Rwoj8G3KtuPSjjQuZfAMU50AkbEGh0CmXj1TZoYcG8SG4wiY
XsEYNBsbUGAtVC19V9/oIM5Z3xc1dGV//C2Esh9FUthpho8mgSuNR0K2rOWG
swwUQQNYAbRyLTjFJEKUzWsPJzFg+OVmeNzBVWOPYHt68umnhsGNJEC40kDl
6Pl5k+PHAPRiTNpy59a4xPZCivoTluT6XJYc3ytzT0AoZOSlsmvMXcubhkMW
lmlnLekJVMNi71e/nTPfBItuhyDhvpMUYZDFxYAUrRHSxE7YLYy7OY2NxuXD
WdQd7DZJ+WpEddHpyhytj9lECroUfeNrbMF3LC/Sp69IpF3XvbGti+U5l8gX
lAAr2UFnYjoVG0WzYBUEwz+LByPL1glO2uumDVASLEaPSpGSlhSaYcOBhS2a
W0N9j6T/1hb8WpLdLOE2ezKMVpkjUOkheVY+4cRIwl9K1Kh4jVx8jwH0e5rs
2rXpRP2czm9OvzHZZxL21H4RGwxyzBx5uV/K/D4hNFisS41ByDQkbRTeVwUL
7rI0uEDFjm0ndnECmjirPx2vteE+PDm/it4eI0czvWQCI4bBndMQN0nVW3Kz
VSi+YbXe4RZeT8deJynIOW+1IjB2IbXWbCABsawaEYguj8Upg8PEGB5O3u8E
8q4u6AgjDNJQSRINHxHAOhqWltcZkdFsOuSwtVXQiSJHPKIwIRjh/OG0ZJbj
NSu+a5r4kxNNpMy2QPCaMqJwKepw9aQ8Jn0nN3FokuZwnBzVs2omWjHNrrHK
u9ASdYHtKy6OI6azd/luu1zbZV0z+5W4zhalyJj84SH3kLlm2IW/4suYQSQV
7r1x4l5R2wKNN22ucoO2rksBd5mxwDDiaXN93am2lX6KQKSRz6BwS5Pqxv+n
b8yIZjIcK5t2agmHUqRcIRyu6qtdkMRjeYzioxbGdSxSQufeD05mpzkXQQMf
WZAhpajRrdEOIdtiMdMoGSwHHzlPj12l3mbQls0Zd0vbqlrfwDBIVMZKXVm3
ZjwxiQr0INkFJj54O+DDywplRaBiOskxUBPsppiy9JSSYBq3kVKSvDSpy4pu
ypTEV8++eGpK4kNBj7DcfDC4hETSclRJzLKv6UE4jgdEPN86bpTpHTck4/hh
DeTx8789tlyDxBKGwGbdiFkb4lnYbCH3NIcp61QCsyLsrZ1Sk90g0XxvBjz9
4OPiKd5vW6CnY80nsYKQScDzgmwIGUu6fIMBufdyr9DTvpuj5frTpCwtl1vL
jYa4NKes1O0V5zxzWjg20/wF81opSVwTXO70GAdOPrdpA5tT5HECe4l+QAel
qF1DuUKPHUygJHYzVB5WwWB2hZe7UZ+RwtDkDtf6sEzs1gE3/qnRSYcV+5xh
NnCOFi4uWTl7jJoUEijNVtmEN3wPoNCA+VPUABVqYkQOtIc7NZc8d0Ep7naj
DODYz1cVw6OgNHKwGTvgqlnkvnDoon+g3FKSpO6wMAq1JKtZ4jn9l6MiBxdv
fW2jDTd+WzG+XuYMETR42OHwE0ql4siSapg7RgO3Xz79jNSQycg8mCOhd3hh
OK8JVktfqjZSh4+p1SRfilrorndSbHsSeGIsp1rWdOCeubyNZbCAj1AyKPqP
i6r9q9rPthOOfrr46/lxCkI/f85jSeQEgI8IUR1vlGXTfFA8ecFvFucnl99T
n7sOBC9rKctcy5f1tVRdEa8gYRk7AmxIVhVGbm9rSdR5ia8xgW/Du25e9FtS
H5ZydqWSBaut6IiS6c2KN1t4ghgUwRTSsNqVaI/2BeiHdBClyuF7hkiupbDD
2TlpZPMPlfI8JWkD84KvxprNXS1lz9oOa7n/BfNuvtdFQn7QLcVfM5BwKTiE
++JwUVWbqX6JVL6N7O7DDBV5j0A2ZJjcGubuGpXkMAllpMJbdKjzDx7OQw1l
wVelS/3s2YuU1vb8i2fPAPOkj15L8fTAWspxWbj5EJVVT+pEfW+yE1LqZhKO
ccfHLWFqBhuhEjniieiyiZ2GRDWe41nxPyo6Bz9JCyc8KIT6dSepK0M8vPU6
XA76zchqHk2BEW8VjoCSWTIoskqkfgg6nt99nvfjx41DTPdY//Ig50sJcnJW
4bPnnzNg8Nkrq0jrNY0AMQa3lQNBG/7qy+yrFqt1Y8p4NBNTngZq8USCYdex
svtjwUlaSUAiPOtgwmU2f3bzhiK9wimAoIlvY2W3dBJLLIrwkA0kfLorh7ku
UCRPvJiGMRAEfKaFlD//4umXwke4Kv+Ge8DTdbyyLKnIbPGRxdGBRWqpJOKw
7DSMkPwzDsWybTfL3HN7OqNVesMFEr0kZo4cifda05bB/0w3rXBEpdArh/tF
5YdbqZPLnHZ1awbdPmprcC5/p05I5uJwMsrkXh/TbtlP2ndxVofhRKONFroL
OVwyhjl8xvvMTo7RGc9fFH+h+a36ZuP1IsF2WzjOpI8s2MI8t2hYHenSvfcK
xGlQ9bbmz5JdyLULWY+QaZYW6XiKOJ0NoiSTxx0mxawjbCOOJAEw8mEE96Fc
WwJKWVYhuybz1YlJga27l0qqh4x3i+dwKX0za8hcI4wJhwcsp5gn249ZgUyr
nLFAlQSIZVapzqnX2Xn7bAQPPfnjjAHB5vF6z5gprKAlbxl9aSnhhK1mR0uI
w35OJJyg14xRggdcfe5hTN5FZuUViRWIEeVg5l7GlJbriVzm3+zK6+pmi1ry
kJFGJEuTh0nm2qTpM4KauzNiJQEpKA2m8/yyvedKigWomdZ3Vrxr2qpB2bLN
cI0+/901QlOPIXbIU3VxbD1MuqjU+YawNbLMk49f9NyrXZApvhqMLNSZZpfR
HYBfGj1biRoPNxkwCMCC3WgEQEEiKSiPGK6E1lCZC+JQq2i8eCHZNZoBn7ez
ZERblSKoVRQ27lS06mbedU2x4mXUWriBUtbVHNmY97THZsUvChBU2G8MjSpg
Z78hOfjqFgIiT42VuWV7irNV63FqTNVikgwT5QaT0Nnv46PrVWLhBhni4ZKP
JvlQO8yjCaJArs1TdM3JNEgc9xqT9tcNV3hozScqcyEnNUKUPCOHCyxYEQBt
IpG4rRgLSNK+nynNQTYwQ1yqU5ZVd9tL0X8CqprFwgsipCElICEQzipOxD2g
qI8IzbJeCSdpZzorVo6MoGn2eKaJ/O6CwXOUDS6tVS7DMN2BMNp7xS+9fX/h
bM4vwIphKIvqhnnvzE8DucxQaQZXNhIQl9oTDyILLt4li/rFcw4Y2zRArjPm
lf4hXWCjarvRGolao6yB4afFjIMPGlBVEievxWH/pmo/kGKxs0XlGw02Wbcp
V9pcoQX8qsXIVw3TXnNcjQkI0EvGGGzYVIoltq8qYE2w+VUwmxFB7WErcWQG
VxRZV+2MqwullXkcY2ZyI8hO6w4Q3LhnRmNN6EyGnKoGZLulFBt3+UE4Mm8w
EMnNgR04JR3f7dlQJDCbPbIVCOiD5GfpQ93lvlo8GO6bjPnqD6i/aRwym4bm
4vtxWUIz+xtjOlqz+6dw2GjvD3Lyc9wd9r5yJKuHh96eL2tJ9gUncHzTy3VM
zL0ReNdsohKyyPt8gHucneWhxIncEioYVAzGdKtlua68MPdBKMyN46YJwL6A
solp+5sOV5sryWMAtJjwZEEzwufQQe32/lYgxc5lumFgVTd/nfufgz42scqr
nhwi1ORH3bEJ5kriBTptqUuoI1uVSqey70jrrLimlPD8Ay+OEBodPTvmyPWb
2llxqC/fJm/DW+Q+c/eP3nz79hhn5t35Dyb4Pnv1Ciz2wIR8FYq+NwkKXOC4
tOWmXhTUhgGPtIzpkePAF7h/qZUXK65Zw8o93lyW7U28oBldR6u8LH4or+j/
vZBqEQvgYKi9Hy7Ou2NjTkqSIAUjYmVbNbFFs1loZF+MToaAUzOxEjwKU9Ye
RfLwDhgZDCSgCjftsq8G5gz3TO9pMWt7yWIvJYdjdvAVL8jzY45sBbWSo0nN
jWp91uMjc/ohAZV1Cgk4sybJo08hOt4fU7P1zGEMz7rSvF4v2R0pMzWv6js+
Zl9ls2Rc5ujfi+OxAg9ds7mFpwBmUbUGmqqWDGK5R+B+4gRaasRT73KZq5sW
+Fe7G4Jk0SxO6V9vvCh6EFRb8gpiA4+ZogNxxukYsKxdaX1BXYzIQQsW/C4p
WUnUz8bUiowNLBYWxFdv8oLZMZKLKhyxwqB0iTr4CeVFCvPJSbz8OTPtcamn
SNXA+UhadbuLC2vja1qrTiDEPSSho/Yo/gdzknGNUStLQFO7w0UO9SYANxhP
Cv80t027geyHrSKd+EDdVmyVqbfhFXsbUmFdWS4eGTuyGogA8EFRryTrbQBv
T+bc58nF9erLpzz/DAQMBBXBJxCIlkQfaCXUwWE4ib4ta8tdPzunw1feBFZ/
9jYmZ6PjM1JpkMzdaPCMHMwRHj6iP/64EayCXI7lVaOxQQ86a8ycC4JUXYpu
D/JKSaiUuOT4YLRGvhDcHik0lEzuEGvPdPZQf0JkJG+XGgS6PO3fnP54fiEV
krLwPTeupBmrkiM1YH+TUhs7w5qSsqE2QvD0IqA3J+WbL1ujNuMqvWvZiZzG
xsCZvqe7tBPSgc5yDx4iwx0tX/JIc85pvh7pGn5gN6TCSyEq7ltwmAhJj48C
f3he1auIJUH5ie2Gd6j4VxrJsOU4Pl0WHMo5OmtOaV+pN//lcxS0ksBYTu/+
OLe3JRjAMCVbckJXU9RKlOLPNxt/fVRkjvmBMw8TQEt5GNNKJ6wXuiXU8ki+
dS/dER1GCWbC8cLTuLre/j/uUXAs6pta4UI8/Hmo2ujEcCzaFkqdKin5TBjB
CTp5+WWtVce3+Kz4obm5ST4g5/akRxzInKi6c7RNNE9ySf84T+vIvMJhio0e
eoy7le/oWcZ0SBM0n/4bjWLKDuOp9HyM5tCABOCv8irjSxk47WwUWoDdgUvQ
FaTHVYlS5YIvyxLGBA7UPVjoHdUbuCZJypXi5EnBxeRe+L9+Pju14/H0KYoB
X5J6+2z2wkNgLz/nv34jn6WBnMIwKr6vlssUJ3v5pRFhsnUMGOH3l5fnF8XR
2+Z7O4CvXr7SA8haJMs95DbbAhlySYRDfccurJumXHbOkZWjZPg5zn21fHJk
Fe2LDKwxa2eNlS1DaH8B0fGp00kydt3ck0F1o8FO6ygHtz3bVOY29AMJwNAD
ggspEH0if33dCEdCKtHlS2KHSllZeiSF9O1ONWFBbWGw4GIi8zQe5Cy73i+3
kQvHspERk1/Vju0J3HG2CA1qJrEuwV4JpVkRvjxWdUbm/FGH1nPBH3uEZ17s
yJROCSezHtlrt6DM0cgWmlKoxY1ScEiVvnodTP4meG33pHDA6WXyHaiAoL1m
ONJQ2BusMjbgcntjjKYeHDUZq56NUFRCVTQyFlECvMt4SDGdg2mrO79FBdnH
LlcJW8LrXfVycV5t66WGeGziJBv4hjfHchfyppIWtNbCn/vrDSiO9zcHUo1t
BbmDy6ucAc96IlDECW8tZwAwmhRsa/b0xLIeY7ij2UApmLtSkJxkEnhIJwVZ
47UVgekrOTCVZDUBnlTm7PHjOfay0J2raZLBPeM4sEIZfcXREx22338rVP+k
eQL8Pi8Ze90PK9VzuodxskjMtxsGW1sl4kkpi0ddVYkfOFQMQTkQ7Y0k9LG7
xOp3xhvSom0jsNUB/i+Lxkd+nElmMvIly6w89Ar1pSvvb6bW+DQ1Dt5xIB3+
ijwpYXsS4NYQ6YARSTqVpaXHZDlDuQ14yzZevaDL6LuEGwfJhWhSPfZDzFiW
i8E5KXuXi6AO6FRsb25Q774SGRBAxyy2/o3ZRa69RBv9Ewg2p/N1r3C2FRoP
JgxSOATfi6wHXIBY1mXI/slwGeN9QoRTkXQOmZTsmxGdPsSjm0FsB1sYYCYF
1Sj7yWPNknymvLMSe5Ae5X1haNBt6RGlQS1WXGBiX7E6JTMozqVaLakrlJ4D
+i4QMxzh/HglPwnNYX09hHb8KfXCR6QZILafBO62oJM4rcbsuEeouuqhEwcb
gjjRjFWdxcghB5/HLEyxRdyHNIUbOgLOoOcCC271vyx3Vb+Nc1K7CNJ6lCGz
0SKwjxvSo7eHslj1OFxhVGlGs2CZ3x1aXDBF9CfWlJ74sDoh20r2gkykB/f5
MpPxBwYcBe5LrrFXl43f9rnV7DvA35IfL0w9tgjP/qCK3syo33aSK4A7Xzgz
bU/LnMTC7kqUaehyvv66fTPuBkhdvrvYDlTjUlble9ExlLI3ASm83eK2Iv33
1mAQjfiabOeIFBBjtZYoaSJU9Ssa+bX7Ild8Ue8UK/otumveJ0WQsuMpT1Ue
IhdS9MVeSdhecODDC03rwHprd6xITPYn1kK7A5YVDnkyyJmt123POE3zdyqz
Oi/97XYV0sW7SX5f7uXwSrFUET150vmQVse9yUZAEnzdaVh2OJlLNjmcG15s
OuE325L1FOZIgkNCMvn2eHgtdToQPTlad94wCYHkL5Vq2x5HdswM2kvTptpY
LKFkPSn68oakbF6QRBEbL79ghCqUdJi5tjH0horg85Z3UqssP/2tuhTJtkHk
yEd9/sDmCGU2gPyvyBS+AQZJ4+BGSuBNkd70QM1ztQHBUv53Ew3d1oMuyVmi
uJTPP4fOQxpPRlbnfX1j/JkLI5+LNd0c5jlQyhjmkZHzJWx6q8mpg5te7iQt
eS9bTav2ZpqDXSVW0TcoqZAtnCfW+Z3gUfdJ2LfK9iVXqKkFA55aN+w0QDPA
KoKGK6THQsbCNSboBDEaB+7SgQfVy6bLIUp8Wz6Otq8WQ6hinDUOG8SqChE0
2GsGeSJ6HFYlKK1oe0RcGHwlFi4QxSw5RiyOM/tkPg78/CmlA0qa5G76gU4d
Cr5SqUoTOMs0nSfBORUAQnfWUs3F+yGBpocdW5E9vdAlxfLXorPMQSGcuJFC
G9IRS/0DGJ+ZGT06VIq9rLMXyoWxRNxJifPQnO9t80W7WnNEj4BCMQD9imJk
OMdfZx9R/nmX2VmRiKMMXGD58+0U37JCsBu6paeLVrgcWnGY6r8nIxggMljv
G6mvYbuCkdU1LT1/mkT8oIdluxc3iAm2lsIw+IgyWWnzgx/LZdlKRS2Glm0U
c6O5oZPkvQpuE5tP15mzX+PbIIvk99M4WCjqMLoq9l6b4PXD7ca6Lm3Vphet
t2/SEPwtOmskPzY9rSR4A7AXU0ORvJ1d/fqEtiJ5QRyI3xqdgCAJSSkgS48O
5Nd/SIN9nJ6vu/WgSEXUOVevvgZRfnZygYyVAipObNSZm5qJoyRnvVRtYKxK
Ss4O+8hwUMkJ4zfLKml5mnK6xk0PbIMp3LJC8dvGzzuvmEiPCTdFSRWclerJ
8tACmDNqulqMCXKpC5IotcRQaytj0jrZO1AWacHlHjiNbPogd6NKBh6FRxY2
LopIU/wAIMDpcDz2wnHajQaf2dkwnFWYpA89HdGVanOknSPmw4kbI75JMkxm
8H1lEyv9YNm0SJ/PVdTg7/0jYTctcdlD6MUK1UPbB8XY1yXQDwOjLjgbgF7z
FMrvHrQfE3wHsFA2bDQB58m8MZeUNZqQ2fo2sycgg6m+lhqPVtsx22CkyAgL
eyvwvy0SDYTCaeYpPKfZnkzZeu+/uTz98f23x87C9fKZJLXE+hu1pgkA9yu3
ujqhGLNjJRgGBFbg9tyDpPJhtrkIw3ZxPfJGV/U8Sd0TZ8IQK84xOOguzfGP
/1IckeLb8HzRpj92Fy3z+Hp3MqPzMncD+eUQyXdD7kueLCEgN0k3S/XD/Oeg
+rgCP2PAQ9zOkkkgDo1FZF+SrrClL843cEmKyejI4DIJvQ5uRYbctAoDEHLU
YkGqY2coJclJBP0tbKl6nXVTHVfQikjI071YQbFI09KspzTGKQPNBzPTBZ8l
nHxskTBCtl5Wo9YjaIHZbbamiwZXs1ZG5k4i/oicLjUY64yfZpATK4p0Z7g9
x4d90C3mvU/SK+u8JBeLE6ZTngJovojbpJQVJD52MjRj67BRCSULQ79ED73X
gjhaKAgJuwoYV8YBx6tnvg6+uJi/owrzDylkDejPPFWJODZuwLhG1vSfx9vw
kq+mLSQ0BVAWZv1Lfp5lR/MKysTOwU8rpA25nJ5GE2DNg1ChxjlIsFVK0fF1
xqDmaCoNGP2h2j7RK9q6JeBfMXJx7WYkLWwJtgCSRp9YBYDBgOAIqeIQNRKG
rjgW65w0ONJ5TC60JneaOs/RC0E8WpsjbwcXh3wwlDDeXnlpWC0GwQb49Qo2
OOeTqMtN/u7xDP0V91R7U65ZqUlE/jYB35agHD7NFewTsW9w6M5TT0VeOlzm
6NvTk/OL4xGBBhcuazKKBOJYyu+W4oieBfa+J78CqkRsjKW84z1fLr3EAAY2
UjqiS7hkjStYicysguC2ZWdBN4nlQxGAE9CMuUn47vv8BapuFkVgRbl4/+5c
QokFS8yqzfyK6poLl9URV6+aooDb8SCfoijeVACV0wgYgycZ6LF2J1bTY13i
KLewWaoj9es/C1kyGPUcCOEY6muT8ZZorBmBqVZSjuSzXfepUiP/iYocg9pm
bwfAdSeM5fBKpdYynwk+1BJmkmMZ14hxKjhlVstp9nvpKQG5nsKgaHiQDMuD
Yb7xdymBKSlLb96dm6L0xavPkKzCXYW9J9ggbgxg4nWGPlbgyudgQbd/sKYV
GBtg9OZnTNwT/jKN/M8GlXmOedgkan8/j6Jh6lg6Yz5g/VFZO2QhrAgvXcPw
DIs4XTOhan8rS1y7yylUyMt0XaUxFtizllVbOG1j5+TfA/JHo/uWHTw0Y/a4
IgHzUUwYTjE7a5WQzSML1cdEqpsZGZ0Rki5qSbwxeRY17ujGi9kd+34ouqcW
HKrB2sBC7+gavpfrH6VFYB1HgjWeHjWMcZPU7WLKF/Yuz4pCr7e9aIRZl9QC
cYYrVqmCCSMDiS/c1ai6t2nrqmfK3LPk6dO0+27L+BW1OFle5JU+YFJPJQ/W
MZcAP9Qwk9k9uElXQbNKBo5MUKcFbTAFAfwyMfKNbIRK3yTYf3AxcRtTdeLS
RCd1Ijgtr1PW/V2V9V9GKC7PWzIJWjaMae6vSPniXHmMnd2ifNdUwvxT4fIJ
2c0CtBGmEC8JmFenBZS+6mZai7Fe8WQz2GzgGBzb0hkjSa9Zx8qPngovI/n4
uprv5svcxyYZWZ63a45m2/62ZSaqgRtpL1SrqmwDxbdqxgID3acRsBb7pocf
D1mgTJBBr9/WG01YRVySW0os3eVNW2lnkwMnd3mSsvjR2M+jiz9Qiw3UYOgK
fFcA/8USFjhquzk4tJ6w3pjhffWFD++dZNPtGM4Waz89UPZJMRtwRz1HDai7
51IFihWEGeqWtWvpXRyh1bTRzVGLUbOEinOjtab1QvnyM8t1SJXQDLmhVnpm
pKvB/9M3F5dsID1k4PPv0cJ/9fSlfScz14I95PSv9TVqOrsWUimifl9rmjDJ
HS0LKWtaQccRq2k0TnSftJ9wmhGFu5VMQD91Fk8eHiAt3xHZBuy8n50X35Ki
kxXt+gb0wtzQ0dn5t2f/6rf402fGI3zN75SuGBt5COmutNzwzRvoODpgraHP
AApHQ+6e5tTxer0VYCCDzVyGtc3Sk3YhVKtbFWL7m9VsooEAESZxTZJHoj9O
07xXOFhXrViBmlsEa6bXRnoK/OZJZoySdsNWFyuT6xhTw8sAAigX5caouzSn
aJI+bP5jXlvJsuPvABnIJqSe8GpiYSmO0asoEipAqZZbM8INemBfp3xo81Mj
4rKzOUoLrvvt6Oxdd+ysT4MqC4iSGrq8TR3f32sndLLfqdrbmYkHipQNeNn3
ZGlyo3uX2Ex2snoAJmw3bKKfV24+bPkBf7ocSnjbQg6UIErRZdpGwUeKULZl
C+mUuiKknn1XyG26BGWxzpUJ799xOmRlMazZiKIufLbyg7dUIkEllDEVm5mf
cf3B7B8SMGC6eesFGxD+A8AouK2F6qbC6rldg3/d7zjxWegPwo+tmwyM07bT
DGmj5giXzCC9yWStqL0I0OLvGNyjAURqZahf9OzdRN1FpiWFmTt6++5Y9Eyp
imtnTxngMdEao1DhldP/JowxFx9KpT10O6/oPsQ9SmdBcoPYMkpEObqXeLd9
BHCJrLWWzei37zpULnKSRRP7dM9M69V0sRL7BWfvnXhHOtkc4WxcLbdcBdQS
QhIfayTYm4gOqfXlGk5rIK3xrXZYQwJQNSNmBexsIn9fvHz5MtpDdmNF9OVC
gNJbshh5WXg68FUe54EU9y7Ksru70WAc/kcDy/83nX4VhvekvOKpmWsoOb75
78XI//I5+Ic0Awf/der/S//5Xw/+fazBfz94m7qV/lP/y3rIc/jEeU/3+vfQ
/4ZTrGXPf31d/MkXnmRxv6z+2+GDIhcpHFGy0CQfH9JqSl2rckkz8N8O5/jC
4YPcqLjknHcRUNGu8yRyV1QnxSCADD+n5q4nIJroEanDnqsKO8KzMWMMWdlf
1ErPy2I8lk1BqidlAA+xriU/UrAbKTA4GctlnajkS9C3SG3PACjYgfCtaN6f
pF9Zikj3oCWhnkiXIcPbbzJ2FQzWN9X8DTUDrNaC2Bum6mg+6HyJONXEKNsd
CmyQcyAQBNMP574VbBgvyhpci7zCsqF+UCSV0DQJQF+xPSySh1tXSD7X18tt
FdzAkZC9kkM0K37WeHIigJe5X5nObiAuuTAlMgNBPklf6FKLGjl3fldH6Lga
Lf5L3JhGgxExGbQ3K36G602xsO+sGMm2E/OSG5yZc2pSjKDhWJV/+pxNA0kH
TjbJJLiZuKZNz3NqwpgWrBXVL4RWMqXHPGtidnYVb/UAQM3dp6KmDGLEepyt
jp/pPpavrSZCzuwr6JGYQYLespkoBy+RHLO/prOMJ7izmnQXF6ZEsa1rHFqB
ZBfOzmDtqMeC9wQ3xYxoUlMTKPAgZua3jflfXBxkHoPM9tSQXPD/jG5hdis4
m362woY2REF5auRIkQaMOJGd+PNakNZueNr5KY5+fvfD8bEcoGupNFSFOzCP
/mdTK1JK61xK5mvTSKqUbhyeF0FeJIUy2eMhYfHXX4VUz8LTeztYMsWncruy
W1yPKdpVlpoHTr1FCpXZV5lp6/WHwq93HW6nUX1RUCRxEodV/eDQupEkB94P
l5ATi2XKMtO+5XMeK/9Y2iKqYYr0U9pdsVtgtJXRTWdUYatxmfguYtsSLDYH
k2qt0bSEJcjlRREbgB9d+IeyoRFxyW3h+Jj0ii5Y6J1ctUEf9NaSZ09zeb0M
W8MEZNYX/dHrQKrKD5pzRFvDQwGIAE3YY+rilA9YwLZylLuPysQMjOrTH85M
D1f5O9ACRNUpH/BqhHeT31POs4cX+P3TUpgGy+WONsSx+BNPzs9E4HAnEnUi
GyVdlVt/adVDxNbBGBpk7TLLi8HbeysrAegh8LJGgoYNqTbaw4IRtbCwYrgA
4eB0MU7C9G/X5eqKdkuT8gRiWrnHldRMxQLsg1VDmYffEZyGKMiCxBwQYyq/
vws2QIoOBKiOvjly/2TqJN0a7HFbliEFo6vUxpj3LhWA0lDXp0GM/EJgQ5yn
qc+T1fUOCvaKS4dywTm2RnnPwbGqj1UkAXARbKUXvLQITcoou3TFIy1OuMOk
Qo8gAkBdKjNmmG2xp8UVFHwaxiPuuNV0Efkw6X1JnzUPUlsNLlgdKES8yV5J
HOZ7elEJCHP08rvf45oVq3qkecFJSLOmRYt4rz27a+/6VS9TZ6gOKePHbK6I
rpn/QmM8nbYPxHZpUBBFWZoXwN7pvi7eNga10vcEKCZXZYlEJ2DAuB1IRzzl
xZjq+IK1/7Uck7rL8j5CJc7hBAm69G3jc+MJLN5TcDAwmeYxbR5wBNFHv95j
whe3gM+JvsS3Fc+XsJVaZSgnpd57/I0KfIgKeA7t+rgtN7TvnOZ95E3jjN9v
Gy546Q0ynTmfeeEroAWfLKf4we1pU7RPYM0zgsmh0/s19I9/7Pb1SBN/psby
SFG9zzQj4dOiKZobNDlrAxbRn0bcnmpAO3mOqUQHbog6VsCRAF3xoao2ZoXt
N4mAi0InEHm3zRRJu3KUAYdsOQwsgIJnpI9dIDEE+TulBh1ZfHEOYDLrw6FE
zVqjruosddp8GObi8TfaStkEJilHyDkH+CtxiCRcODZjwPHAn+HtddrHskvD
lWAayWUETAEDDbktRVEEr4JXGv9mf3SAfTed9Rgid93dp/qs/L9kvu95OIYm
Uio6n93ntc9WzOVWDefP3h3nHJWsWJHakjghi7ztFUFozQlhhOzKlOQSilp9
lLpFhqKLOlix2HrU29ozuaw98kzIFvXCik1dyWmMqo7qghEwbM0pMSy/1Q1e
i4TKjJwTbgDJb1ebT7LxSu+cdErE//OZpY3LrCF/UiW2eUCTFhBdJwJEktsG
ZSPS2HPQc5Nv6yUjirykiXogfhysXNp9Cw5qCMO91Ye6xr3gl45xu8fLnxak
T+kepKnUpGekKjEvZil7irTsemHS0apdKSfpWNZWgrjQflW037ZPTFo2zkh3
uyeApBsvZ1ykUiyZbO+ObAWZxs4JA9LgZH73XZfyjc9mhdR253TTu10AFXos
JTjopg5MAXx3A/bE9KlQpkX5FCTMR8OkE9vurG4OCSJGzTvJneADhAXR2hp2
BHUXzRRCNYoYEw8xOe7FTRUnIAiOKwTBhIm1WJY7gwd9PlMdOzh4RrWuP2q8
M+kiHeurnYtj9oyYqgfmiRxI6iw3wjqevP3Hk1SWTzNU97snmWV2e03MN6OF
6uCSutqFWwt3AxwWRqahrIPuJfvyy6dfIJ2SZukLm6VUiCrdLzKivS5NcFgw
YZdtVRVvazDy2SS9QHheuGSkGKL3PSIiJ2NTta62nN9iur2thGoKw4jdIB1S
1IUdKYYc2eHhYWSRaXHQQqe11YTrOCCyJ6LtHggs3wWP23KxiUjlmfL/cG8c
pMQzI7xL+k9U5Ttru869QgexUMqL2WeJ2VAXkc7cXucPiowVqGnzeqtQwluB
y4nEs9UMU6v+1gOkl70VeJaOdwpacOPYtfQMjZPqQ5q7l5yQe0kRDxqoOe5Q
jL9iHyzWWWLnSoEZrVV5Uk95sj0Psgs6zraHlcERLF4TiDVzaxhnkTQhX07+
nhTzmOV7cSR/XVqQmo1oRTxk2ntBZPMSQfEbFjVQZbvwTJ6w/2yRbCE+uUoX
+r6ukrlD7awblqLIOaN48VJx9ME2ljRqOyG6ONJIot8DylTTXRV066kfCNGO
OPNfPUP9EWmqH661RUQ0EU/bmt6zwHG0oW6ROLyka1ALmsjvTH7OqgWXWIQ2
yg3oLiSsUpYJq4G2JTbDN2JHdjFfQ/tufkye0x9e/PX8fb5w0tjRDy/ev3O6
xmevnmtQAy8933uJnuc/+gvP+ZqyfZEv+WBfnJLMb1a00wYbw/b7dQ4wf/Xi
qfDbDQ6b3xU45tamT5cdYXElyZewNrsEN7C3pkhxzA6XYTakGevpDzg/Jw7R
O7r44UR8mcEBvWloCXfmxIypM+v+eCYNficnFPVnPGM03wrp79bNUCKJt9xy
N70r251LiitWKtgEdoTlJN/CKiCuyY4FCQhbsYx7icWsQ26iVuCmWeakJ5w2
BeDyBLISMdh1nr6Y7To/S7r1slXnXXfhu+7Vc/Dx5rtu+PzzCwF+eMmgl0rU
wF59HZLjpHgbDa8ZBZlgAZcajXKfqBiS4+4v33H7hDXqk9iaES7NAOEkVr6h
jTVJ7NIoxiZDZr73Sfza0A8UHQ8trAq8JZ6AFOhe9sRkcgiyKhszdUOf1RSg
PimmR/gPm3U8Ek5seVCYYRV5bS9TR+JWsqrnoWzY3i18UGQCfZBdCq0+1aex
dmtleUMmg/KmHBSxBvpw5YHUAth1LpkWsjTq10GPjlPMAHpuiAhitvXjetR1
uFCgghGV1v3AkbT6Rn4t+F2lvwaLO6MxFI98QB95VPGgsPjNka6+0lpY6nuu
2xxbXRpLXPZUSLnubW6VykBvIC2glOqmsFETNrdqUpZhIAeoVlS2kfiPwOts
MkuJ70q9EAepIZ5xYNew9IgX2ivLsIQOKSpKOi3OnLYhcdgra+KBQGFvYnln
dhp2IzSTSeew7w8hhbzXh3VTviLZo0c8HFXd+qLuZAthk5pwd6y2G4G8F7aJ
0EFYuHN6ZAJc3jUASjOl1gsdpIb06imjdFJFwc1qT9bWbtdr3kZNuzvWREVb
K2VILvOdmg3GHYcBmMzVsxC10zMva8wYFRuHCcq6lXQ+UoI5nZYp3fRcKTsk
M6RW2AgAKCLEHMqex/ThLOcsAzsJtIGdSWxgDULO+RnNxmYsCLnyo7KG1oG1
pkxpmhU/1B+qeyW7HCbiZ/qtnzb2IOxNu5LfPNgzn3WfWmtPzrKU68mvT9tO
fOvml67AN9gYKZMcmC740Cws09QcTaaQTJzIVuy+dIHa+5zQgzQpxetoGDbb
SgK2w7G6MCsnuBD6kJAmtKvuaGCaHyOU4WN3UNgdadriUL93NwRZ9sjyjNgo
seUth/Tgd0CrjrCDFNc7BKFmd1zjC3QX7VGwKVuLIW5EgItNH9Lj22ZT3ljd
0QdyrQxw20WEOe48bkK8gJxZBRB012R5mBHbZZrEPhTvAIoge/QTvaPT58ow
9mzo5EVRa58bYZUiVBlS6jGjYYerc6+AGSkFXIkhEjcginT9QGcfXzCNByw7
IHrHA6lLmv6ZkH/VksbJrgwVCt1uPac5X3NofuBCEGYoErmKedzbAl9bAcT8
xWhmInE+L5pgWLd0T1oZrPUnBq3olbwSEbZL3wuhRN6J8WJ82OfbuPWuZevu
NTBztjTh0C2DR4pesmOBaIU+yG3IcjjrkM/21U4CBrZcWHtvEcFcNMOhLgvb
M2iGTpK8cmVcRpVfOjDY2Hkrig578+lGAXfH4mtu5ELprXwMNzeM8ICYVa0v
MSq6tsxRAnpmHZPfwjmWkYuSWKqbRmqgSm1dlopfe4b3MLl1JLPVAx2JeGTF
UtF8bNyUR7mywipoO2fs08w+wFfbpum1zpclE+FISrUuJFsqtoMUKYADkQ2i
c0iN/RkeahY5wSsmThr5tnj5U2WDfAdKxWrcR3U/xuTKDQ3PNCM31Tcei9u7
cYfcv/AdtOFgUREdeQEk1aSQz056u2IZRWJI0Ydlc4MduI/MSqcNKpUe5wgx
kutMYBtS7e3xNLNGX8M1CSSYIaUQgHjmzCz6XasIurCY5RtbL/V04Mx5ztVR
yYiogCriepaM2rPicwkaI6/n4lPdbLK1j/iQHdOObG/qtRCBkyRHGAxn7FTp
JMDc3ds9qAf8qvko9ZfZafS1hu1/MCr0t5ldEfLOFdQsf3gQI2++UlCx0wfp
ADMHvPIZGyMKv6w74OyUdgAtaDMpfn57jpPdFpen8reQN4qbcEvC6Cfh0zpn
X8yCL8LTcik1NI9+Oj/tGBkaYnAm8jEPyIfTgcaofEyX1+wswNU7S4ZdKblV
EvNwqabJwWQHNvks7K2owAM44Xo1yFRiMTot1VaVmo5SUQf31VbocWg24bBs
9P7UMtcwzpmfS03zcA2Z+BJoi24fR+tEZkWUC3C6LwODAjZOor6dqg4d+yZL
h2vWVu9YqLqUAoZLYNn6dFl+UCCm14OUyp+6ooy6cgBWJY4I8NQti3Ju0UbG
VJUfqrWjJ7uwBLGWbOBaENqhBAXTXqEHqSZZuBjm5UaQ2HUVGYi0SoE4wXU8
neCXlOJErjcnxSmzWjTQvFFjWvCNWhFLxiZCQBTOT+imtMU5vb+XaeOK1QJ4
Ye2uNuEngoQkqcbc5NZ+q6ZfTFYAIdxUjEI53Gd+hgJLbqbW6ha2ynn1GhU+
OJ7eqe90HAg5y+FZLmUlbqKDcYSXXvbDXLtZccE7X/vgxG5WHibv0NVOxDXd
tH5chc5YkMFrs5xci6F39UelqTDHDjfEdVLtZqafuR5W9cmSSMHOKrVas47Z
H9hy4uHZdYJneiTd2PtJW5N0zOLEm+ALnaO2HgEbTtMkUF5lpnnoxdgn3lj7
rLmsP9H+gcdzfEyCJxFgNM94tciKjqHiojCiGoYnZPmkkRsRN0fZmmLXbEch
qNi4u0B8xUWXuPih/UXUvl+EC5i3DM8YTftyobVogoDAhWFbCOi36CbZG7xQ
auYKFvYEXVN65xoETMS/8msyAol7cmgh9MMxLW3uQGVWnYsfnejKfZE+436d
swtCPvn1Q2WI9f4MN/vRT+9+fH+sPX6ilmeK9z84Xwb5o31/hUn7iXVbAY+f
KHhcxQsU3qkhyl172HvNnoBZfcUOEOXYR/VjQWD1WbK0JHyIYBOFjppcuUBg
b68kXKqsgOuQtaiirSX1ww64tWF9o2bY1TfWzbrTgMhyh/TdPpONkC5tTapZ
KZkWotarNBaMzZWJX1be6na+XRmg1fyI+TAhiZZLXf5g8zxYbppkSSi4gMi4
q5q1uDmx+KKGuRnHCMqh3Xk8+fRiOVaUzAG7hpDlyR5FVemYlEzgwXU35PgN
zE2hy4xesi0ma3PWNcv9S6umv/qV5RdBCgjXeAsq3b+J/l3bZhgV2mMGkFrI
/v2oaQXidXXjpaQY0Sjv6rZZKxdpn7lVYSVPBBKmRG7C0ez4ChXV6+pjP71t
Nk4TxBuOvrsn/4KLgRVXxyGasSzXXyqbkCgbDVotg4RvVi9FgRZyCVy51JfK
Hpw+aohNYdlhAFeu46Ry5ZAsGw5wwGjS+WCntk3G6CwDVK7Rdg3DhtWcqDXG
mmsFK42mHEmoiZ5QG50k1V7GSPtRQhMy0QmsmvuXzSFLr7bbjWTcQmyYieL1
gzSjReZOshta4Nv5CIfNMjrOe4HyalAPLkIXerE6kpeVNIUlzwzFftUk1ZyK
Zc8tKxvNXLPF8PmhCipbrBRUSxrYg1s+c47Qt3hnipo9IL4iU7C5tB13vawq
zdfzZQXzHr/B1Wk5WLtstouphEMGhuIt364B0eH8UMY7Al9OZSH2QRUn8XG3
5b2S0YWG9ritJroyNMYabQF+zh8UkpAGvvQwH7KeZumPLeljy+vo5IS1QpUU
Z8wWcZoWIqPml/CQg2KhnHhlQCxV5eTUg6/kOwLcRlUXbEIBZKiyADOZGbOU
89145Y3sKNsRXN1KZjg3Hiy1cG9e3A8bK7aLyyHrMw52ircPqh8ELKum3z+G
w9lrRIiXyUm1Q/rTCkScMfUw5iTFNDlHmJn9nfLO2uqKrlz3KgQzBLl0KG/h
v+4x+IsaePhTyILFCB8UClzS41wXT0Nz3eFBQoW8eAbWQKOF7KJh60Qwo7sl
CAK0l6d+JlSOsf1fZ+8OcUCcVo1mMrDYfvp2rBs7FRr47CHnpEZj+fvI2F50
tlc15UQAOyoJNluyRdhLya6pwK6J1s7UUat3ejeghNmDUXbKqMyNVgsHtxl3
CiQKTKpeqi8of04gDvR2pfqPOPs17q7oSzZOvBBEqqdrpmHIYeolmmUNzDTZ
TFoBQGQlgX3HYq5CBm7qKaeKSfokz+bXsZmzi+nZhdJK+O0JFyZZEJyAIpPF
oc2UU2IwX7k+4MZrEOhqyHhbp0FJyUXVXspuZ/WXhdCVTFKwNAP2JTlWLjZB
nAaVHogmRZ7JqdgXu5Fr/vAS5iKTzEqO/7m8+gYHKp0zHCk7UV++EhLRgola
e6mQFLmGuEt9aFcX3gMROhTNCBxwZsVSP+1VTUKded9YNkkBsOGBES/EqHvX
OadWuSN0oM4z8FXlmWhUzMVpVvVwXKQiSqKTY5IyMqm5+cX3qxggG8487Dol
xvYIyKfJT9BgCkUEX+f6jEYlHpQeXr6oQ80e3hp6J2KarqxN4WIp152V1FgL
rfTCuIBRvCv6pPV4y/4SpaWqoUuKnwq89qKCC3hD04Y48ZrNzpJPqbMk9VJy
ajsUbGSMLaWHrp3vfdjyoQTdoRg/G52VsVbXdYC85NVR+NypMaEARTjd2ZeU
MSBrKnEpPOBsTbK3qWVGXeCxLJwe0CWghg/YLGz2j8B5TfzS91TobF/pYDbh
duxyZPH+rhqMvBstdhly34f1FX6vD8Gms2hUPGfmq2MP6M26/rtfFLareUPi
QoHM2iRG1RTosrHWg1NpwmE/A90CHlk0nHOy1iDZUrNmf7IG9QWaNqFkGFV1
f9uwczeGCxPsP6nS7MfNiVTCJ3CsHNMnx1n5uEML6ijLGThxV7OAG922A/VS
C/emGtOO5RyKhJDNHHoAm5J/UpnKzHuLcv/tUGzCX3URgpAC+0gFokR3qeLq
y3ZKo6H3ynXFp0kY7K0YabXczB6IxbG4ybaoC2aksqJGjFGR1FlcaL/wns7+
sPuzXJGEtKlo5kE0LD1UfjeLIqTaZwA62zZ6/vTp8+Ls5E2CgyWV9BfWQdn3
offlZy8+0/tS1B2Rfvs7FAIw6NZ2BalFKV5nK13HIEyWK/A7q0cNdQ2nLsut
FqLVSAyxO9oCyrwpl7lRFEGcB9K3XriXedQ/X347fSXay/tvT7UWhhXQywkV
xaSeN8bn+PO6Rn4fj/zPoUS1o3rdHdP0SY9TOS7FGkGXrRUcJb9oJVNSnFyc
np3Nij2LQcxJ70Ta/mNatc4990FuMxTo3fadsV1280bgZaxqCVzAZGe64dPS
GcFD8J8sd96th/1txklj+gpON417Su1N2Xhq2r1TqrVDONlRa9+mwqqpPrzL
yxknkivd2LVaApZxxBeux1ryIjmkiTxJFzFmik2c7MaT7ktKQz69J0YTEf72
JuYSX1WRYSFoFVUOFO9yl91NpXllJ/yvN7I9meNjJQdMsCWGVwbGTqslY3JC
KSax82cjNw6ELzdp16Ri0hAjwNzm49Kv/a4TwEVdZlfxBNRIVRI7gBV9qIKN
P8gIXt6KXouW+TUz74yfrEE6X/7UoFR7FuTMya0i1bHazybM6pWJ7lwAX+3C
wsl1IxhrLIsnsQVDJVl++m7u0bR8KvlicHpDuRh4M7Syd7KQxgdtlxlLFBT4
ST4WOEsZvJstjVXrSETHe/7Jcj4PzsnHrL8RqQY7JAoOrBvfAqBZ5YDfTcaw
4gEWGMJ1lwE5wCbSNRPxzJZjr499M3xQ9vHhGW+7xdbhDKNTcKi3yvMvv/gs
c7pYFVoNjltlyKz4ZgrwSR8FMae4D5FUUozELKySjqExzfdcYNYjPBykZ4Ln
JSpbit6/5SAos1Ly46Q7sdBTcskqOeQMqKb9RqYHO2cd6Jq6FBA74YB2lffT
dqzXwXRRZ0uvZZDkbrLEn1Bn5x6eBJkO0U7CDvXyrFYvSU6nwnoHLbHobrSl
RNOt2zkUsdnfz5yuHzb0twJZzEvXAreA8g51dT/KG+VxafMES7Xa4FTnK9EM
jU3wZPZWBCcxXNWu4vu6gZZFeHrXaqPLkPlETHLN3y0Hnkw/XXoY48mAhLsP
YW1Hldhg+v16Ra6XCdGVpEB5+EMhOAJPhJ+ES0VkBc1TcSPWNSYu3d+QNnO7
KiW8/I5ERrOQafnlO66t8st3x5IQorOU7YYQ7IfdW5Usis2B2gu7RKwGOjIK
s45FDZXJxChilaJaS9gq1T2XUAv6TYytQKvSrNwmhKUiJ4cAyQwa2lXZtyaC
2qul5sUwys5OOpsh8fKbbPqM2Q9mxTeMJL6Kc5rPlh5KXJ9yC86XpaDlPDwz
0RFMojnpVeYERPzng+Q7tuv0E9slOT8q9hR5soXicLgLf/aMNIPtQsIqGZBy
3mpDdXZaqlRsJ1VDzDvwZ7shjWHVp7GuunD/L+Kd1PF39MN/Fq7csusZEacp
+O5B3fO+J7/DJGO4S64yLjwSlkla6RKW4Hyf8NdcYXpk62DHZhGmiHR0f37A
K+4fwrPzXFqmg8SNHJ2dn787pgNpJ9FqJfnqeKUnpyYebGJx+1kxor0k6Ocv
XoBTNvjnoMQg1OkEMBzNA3p7MyxPJvl4Th9zpmfZixc65GKYxm4zm2VfIwbv
hSRDf1LF3qvdvuCdoKQcLU4rrohI7a/QW1gATMerq+D3r6+wI+ic9cJGvxY3
VSLsu6g4QQDb7VDePzS9kKaUhoqf+4afVYiqKBhAqTI61L4arl9dGlgMwzui
9lwXv8my5NJ0cDUYXmkgDxMaPgitfHjDZCGqPoE290v6KT4V90y9MtV73Rvv
LuCcweMFNj6cSCUmwiM0getyQ9oL+JQawZYBGubAVNpKILyE+m2s8l98gYQy
yCwRKPHeEcEijPeA2k0k6tkxxQ+2xe3uqq1pgoV1zZqxvMm9+HCgTBomtZqe
nxLTE39oCgl76bjEiKsPTtE0n7v8z/QdJYnI/07fteJk+Q/d3dzIby5TcUuN
8LjfdXyxo5ryOttbkXPd88sTXC7YrFL3CDImVg5+4q5QcejVUmk2xW+PE39B
+NgnpnXw0QfbD57641nxfQVBpdyDA0RLSiB7RFbELSjIdhmnk6XVPvGSY3Gi
4YCdp9QyBZrVTFYM8/T0/Gdh3vq7mhRaIja4prBtqcV7dgwpPid8QpIoDaLW
x8S1feSEXPFRC1EdSGbV0yMG1EElKtMKS+BaYcSeSo1U7ZRBv8M9CaJgcf+Y
B4ZdSTcxM4Y5TOvKSRPf5ZkEPoos50IPjfhPNV1NsFSMTs/NO812U/1aGxDJ
79SC2ZanKfhQASMinGiq4jsNof3eecAl/a5GqD3CsLSNhK89gwFXYMCRJ++Z
qBx4FW9Gsy6xJiAzT8DKKBREk3rElJ90swQ8TQqx1etOCQanUwk9ez6UlSzN
jSxLxvLHhuUVsqfNib1HN/wQvbBAWRXZqTi26EPC4JRlUB4S160/mJ5KDnR3
djmbYqoaLA5khQfTHFiznIhQds1a2SZow36sV9uVXDRGoS+Nwbj9OqQ17TgU
uilSTareBEjeiuhF4mIXStgutMHp8pzvgCj/d+Yb1ye0AjD8BPag6Ug9uhVN
nhiKwamT+k6DGTJ3kKusD2VVAHsnLLKlHHTM35/V5SMhmrXw3I23EYMNQi+u
5jBr7aIJyBTRn/5etY3X+K316ybh0eHYOd9xS0trTohNUiSm3b3U1WFk3rJc
VKKRkC3Sifum1IqPC2T9ciEw5LSEgxU5f4XqdL0LVbN0s1bc/9LpAfYKC5tA
ScmW457CgVh2Moc1wzxvvRwUKAcDuYSL7r0tbxWuG6QBGVaV17L6OIfX3jRv
u/PL4YldybwFCmmVbLj4QgHpvfojzUMVN+AQO9PMKwYvLlA6Q3mC7q0ueJcH
41LDsH1TtJJ2vyBawiNwmjvDlwY0kUiS6HxhsItM8XEAxTkyGN3nWShhWV33
upMzvh+7Y6FKBBb9PQ8V8ikQw+Gs04cg63/94eR9UuWp3SP85extd6wyQKw3
9We77ccHDEBUSO9n/O+XT798ad5IIwTSKmGHd7Q603pxGAR3IrcL/LnPnk+v
aBq0DzLRKonxt8vyhtPPWcZsxSnrcNjDZ7MZd+HwgRteSfjy+52133HRZWCz
cNo0oT5xVOikjF/vPDCcd3GmSHJVX8PNnSmmsXRxY7zZv1vHISO0DUy9nGvM
l8VKjBG5BgWnKBdGUjASo/c+twdqrwlKYOI3plpUIy0k/eRBKSH2qDaRPi2i
Qto3b3gzrjw7NfLwQZ3H8XW36Ha+8GzejC+8GQmPX3lTxh5YeQcZ72sRnuu4
E0C3HF9PlwvUUqUmgmb1hHJ90VMD6rWvhv+NdsFkf7Oa6pmea6u/yQgXcmXK
JrPknJF1ho/TdSDN0tzLVxBbVz4WALmlw+wB5hY8ss+6BR2G2OEUepCQEPsN
YJWPTdzedWnrK45Zz5uMAh54SXZLREeEGv7sBdtu4IsQJ5DmzqiZ4hm7E5LB
m+nVDhkk+Q+Bak3TQjbb/uvx3WuUN/nuZRv8//NZ3Js5s4CT5z9OGC68B+Ys
qFWJUyCNnRMLagawgz9b0va6rplrddI4zZnq5z5Cp1FjrQq5IpYn2eCiEBW7
raFVHf38r8dfGz+CZtpEb0ryBbArKQtxG2u1emu45ZHibpbgbVnv3YoMmlsk
SR+VV50xZ/+NgactrGifCHNHiPJyqAOEw94HcGhLqqGvC7Ou9uJeZneF2Ncj
2WSSBavBZZCEWnuyQBun6b/bLtdWLk7tYpG8v+fjwOQliqlHdg7RzACnUDeH
lt09FrCDJHZZ9lJ9V853U9b4gDDJb09xJvAS9OlsCMeYGRMl+MDlmmXhT5am
MDdxrobJ+0fz9dhV4+nsVu4Ynkj4kxqNiaRInzDUcDBKchrd+IqZEAl5Hgsf
uabvzU1Nr/NMU0NptYjZVuv9lMSiFl+EZNh4U7836pJjRl0aMwxunvBUScfE
ktwlFpJhf4ZrLwkPNLa55AyrO51bUUeM1FYz/gcA6D/4fumB2ac7aSNBJ7uz
sH/0PpxkNyjySjgwK1mV9gs8VfWazLRa9gvfDT2p2VzH6exajMYwWqHF0zGy
oZiVRwDDgm47Nf2qiK/YK2cEP0bP6EUtrac4LdiOHCHsqrUGk5ExmpXT1DxZ
lu8yO4bYV8nBVX+Qo5NHy/tmYzEqO2Rt3X3QUgvdlsv91GpQRtduW91slxJT
rbtua5O3qpVfnhEOjEGtGd7HlbdN1XPLVFUQdymBMAycF/U6YwSLXEOOnX/0
EfX2+YA4mlxichKLFSyJ6ILhWzEh5QGb61SPGY/jnFGLLAo1TPhLzSEBOi8n
kDXobYPqMEenJ+e/nJyneuPPGJ9yRb37oHW9Ik8ZTXqz5BzfubakzcAtfHJO
1h1A8/rbaSJfRq+8F5eBtcL68cslvQ7J/WbnlIImOqJ9PmrpKgJ0rxarABW4
0kpL2nyz7ZaCZwqmDczpe6eIa1RViMAIJTV5yN1kQKkr3icg1rftD9PNKduG
q5/wDDdkb3L5AL2V9Uaw0StWMc/YS0SSEimoJOGHxs23TlBV8dOsuJSQVB5n
LqVMUrOsUkrM4OMrr8IdlMFlJYEtpi3ha7BeVjeVQqkQvBH1SH24QnWEHHtY
DwwZJJNRPxRhiyEukJhW6Mtl90ElSLqkYRig9CTgLDHRZH5bzUVq5DuRlIKO
99rJ6Q/dsYw1Jl49Kl/zLK/gZdUGUFcBfAxKTtIFqHtM7Brkt/iYSQhJv00L
zjNn0uYZywZ4vP4Vqj9wg5VA890gZ/2jQoqaZgBBqve7ifY92xrOvs60sVXK
oYTw9bj0h0qAaHNaST0IOZtMW6aKEkbEiCg3k39QB0rNyLAaT5GJWo+S7tKh
180VXw0GMJd4ReKVXzY/um2yPzSRvIEMihMTPa02gTU3SpUmlGh+0R+nypQZ
19PEKrylkPrkAc7D3tM6LJ4Vwujq6HJ9flCew+ZskMLygGYtFNYyANPEjDSz
dYc2lET1aRuBRENadCfcUrWTeOomXDx4qdH/TpbLlCzFWkM7wG3bJLGmTj8x
IEV7mPa7bISoCXA5nmyzuzc+hSWs0/T/M+R94rGlMCbWcKrVpodvXinCeS6M
PSlNPv1/t4ztO7q4+P44m2u5e18+/+wZB8dJOemTvZxUKWhdiX9B5uyto3NG
7kUkcAUADynNGo/VSFZQSpOAKZVlZJof9weSqAyAFUq+ybhHcEPjdlcw/9wj
pqgdxD6uyiV7CxaWLzPMYEkDVxVK78WZkBKqSUUD03xkCeiiAgF80TxUU0j1
DuPkLU7S+713LSqq+9ObgT5Uzyq2B+ju8r8fs1d2oyBUddeGdTPogXLNGNA8
6yEclrHNCNRAuAdoF4QhHsonGi4D4qr5V3Dhx8/Y7fDAdHCeyTUvDksDOndW
meIll2a6tsI2QmSMkMnwLgEvFQKOzE7MTojix+ipXMek2+KyaRCeGQgzcVCw
ZJCi7b089psrWlEx4kXbkhGx+8cu5oxFhqty0Wx6O/VbpB0OqvogyyTPWPNK
7O7Q1bIAXggcd+mCjnlw0+YYc3QbmCuE8XiWqo90JRzyT91hgUxcK+jqqI2A
GhWfUl2lHM59lC9iO+xFNnoOSVGYmG01yWLnk+iz0ca66HX0Yy7HkOPTyyn9
ssxLCkacobF49JKmnnD06lPFlZSHGxcc24QKH70b3K+F5cTE8hUsN0nEk+Eh
HpDqHrPbiYHM1nwWRfSLyQoEQUS5LoNXA5pvCYDSjZxKIRmosmLPgwOelVeM
yaz7Aw3WAZ2l99+8+/H84r+Bn/tzJJlbKh1yjViB4EOr62hM/Wy+ZzhA5T9w
xNLIlfHatIlDBvdwH2kDHY5u2cG0wAFhZevUmYjbUuB7fNx5vnGmTJdIEb29
k2VSKtzgzvMiN4x9f2L5uXpuoDm12/VamGoWlal+K4mjSuaIKcRqbrCaGrcp
Cz9zW1i3UCNY8NRe100+ObVUE3NgjqY01PvFPYYx7CpdACQMWNha+nCl829b
J599UZj+qUABnlYI9L+xJ1Ravi7eSGVc+6gx/uqJyH1q3B7mPHwGk2uaXfBu
q+Bxb2nBiaPCAKzNPMg846/SDnsCFyPfZL1lHxrg19UrbQ9zsX/W9nbRTLzo
4lISQi4VD8ZeQhO93Iqe5+Vj2MHHNDcW4NDUajmtstuZj4xVDUZ5sFmibY13
Qos+QY9e7C0Nnbkzp8pnVI9a0Q+KnSKTNWbSyafNmGb/jx5VzTCU7Lg7DTqo
zCk+mexWqxhOVmJGdJTcVbrMe75oH8I+SDIbVRyQNMXcAB9QimYzAmNvRj6R
3Ct70xV2CzKh/l6hZfrGtVSM45jJOhRtu7eF+ZG9FvdSsHJP2rlEuZLbha+9
csGUUX2VkByWQ6rHXg+zZyJ6+v1+vcDkax+51vzg5kLGC/0oSlsXRi67hM+J
AMnR3ANVdlQ0AOniJ8aySgJStq4SNYZyhjJhW3UXqy4E+dWGfdwNJRpKKPsd
SAsCGpfvaUOUpICq0foucx1fCjr+tTQ7fP7XX/kv0+9PTv/l5PL7H99f/Pab
POjuEI488P6GQug808NR7iaR4RRf1glOulG4IGM0oRu3qD2NQGlG9Th04cqR
DyRVgzexSOrhZXIUEHWxL8d7GF5BQz0GL4wqpnM1ZUs449dy2WBlTnhN42X8
gHh8SDBaO29dKJv0yS4JZOd0SkKG8iWCcLTch8wEVKGuN1D6hu6RfXDwP3Yp
xCVI4JzwxK9qoyz2Jk1uC7DUHL16VRY3RocvUp27rCWYJKfdWjllH1Yc+jVp
F/ImGx04yAEZpqtqh4PMpHVxIW4Cfshv+7MoJEReMft2uiQkx+Q62i9BXiam
jBHRZ26zSVJTsBfX5rAI0kraxC5wm8tuY0G5/RhelG+AshwrdQWSBs2T7ls7
cCD15wOBoJck1dVWwtyOdfQU6x68XtJokrUnhXqo8+kYy1Uk3kXby6tKUJ9c
icmkpjjWES0/Ofu0RVrWuSn6SyoHBRC95MU1noB20sJvyHuJE5GWpOALyODk
7Fitq9ycE0DDOAXqPuAgSAO5KlKpda+fSD9l4svs1lERdnImIbmF8L1xzo3V
uVUJfydoYgt0CMoSV02rJPVWRGOtONVJKJlUWeSPtE+SiayMhYBdFUJxZnD0
uF95u5hO6uxCfZ7lrTFTKD+f5JAFdVu98cJTJ2fTDe/SPCooWwbcxMrTgC61
WrxLPCYqKNjDwEVTkNmTStyaOhKoGLiNGEWYx7qmwY7ac7VdhaQ0nIGs8JHG
rkKFuHXUKxUTQBcPM3VqURYxu6uFO9uU1ycZBlyrzNMpqSGANXNebK/Q8qXc
xPbvl/CASiQfJcRVq8D3w8nulEzCKfU6TdeS0F0JHGgltWgsRctYmeCiSqne
2C60ln6uo0NyaJ7pCLF7JfJhCjbPvLGO3nBpcPHoL9iI4ESHpQMFHorjjcOa
0UpbmZs9JXY9kJt+ZHWpf/31n/Ms9d+O7QyPYXuG7+Uon9+O4ZErzk7en4yL
uJqaMj8bcs41/9z9NZAqDMBGG0YGFcIvucPvdzx7Mknu2NOEsXWDGy+geIaX
Zq7rJgOG24G3LvRdiUoSL1ocF5QiIQsOn9tXA400CBmJPhle8jDKWCUp36Mn
BVyq4FTMmreYVF4/iBit0cmyFRxbFT9GoYzcdVQAk7NYMR/RZ5CPMHNqKVGM
zWunSwIxGiKYc5hbo77pqkIINJIt+V5UL4uE3VJtj/2I1mM07yxMFeEkuWs6
u2hStDSwx8EZK07vkZNDazXl3CU6+7+zx085/LvkMi9K6Gz/phXE8pUbxA4+
puUDRGIOMhZ/mfQHdmYlmk1I0E9AqSQh37xThw/38NCJlZ2bbuCzFPIApumR
WamUCb9KoitrIj9RrQYISGrb8s906Gl4dbilrgWIySc3EZUgSOFFhr3ugCRN
mytQ6UCHScgIchngqeDvHVA/wyGBNp9PdpjoYSFGBp1U94JlSdTGIwisPqNa
0QURr+bBqHjBg4L6qL3Gg+bnnn7/zem//HB2cYnNdwnXwRxwIDHL5k27aTBA
ppBl/hiOrbs3WkiWAOSRNYaeKbxiqkiPbCYAfL7DWq+6iklyRTV+m6V3RzIy
OheWqTSwxxz9RWLvMdtxwtYex1vqFaoLAat2Jb7OT8W+9fWviyM5uXK98PxO
c5mSEpzxoZWgiud8pU7ZzOJEMotxqT9HsWyk3Xq2SdzsmsRjp2IiV0MvaY2Y
gyuyeq6XO8+ku7/dPaaj2qP+wTtxz+k88m2bf3idQ2DqqqHD2YIV0FAe9A9B
cnnnuLhXNjuOZkkznxcfJUVUsj89dbdcVYEWdK9/3Xa1KlulHVupUl1bwjtn
jumT3R+bstFuajfATW9IyJE+oRRJyUK1FZ3ZslH/n8aupSeOIwjf91eMyMVI
g5MckkhIOfAwNo6RCWAT5da7O0B7Z2dWOwN4FfFvcs4xp9z4Y6lnd/U81pwi
k51+V3VVV9X3EbExeRsPRdSKCl4S2g8jxYOyB3/FgaEEWQE48S2KDVPpaJFf
zI5bMTDcjmSVkvtcf90JTVOBTFmyKbiX5vmnQGE5Y57ngipmnKdma2vCd6ID
5heJGW5J1euhIKEnN4gL2zfKoJoacFz7JwVAqGPZ9OenbBje0IAm6XiWXqit
iYwkfTyKoINxauH3OjlccaV00F+zNeAlUAG+UV3S2xGslw7dwvKMNx60YNhJ
9Z7T9ChF0FNuhEd6LmStPS2MNTvc1aSz44kpTJcv10vOvNi1dDWZWnTMpAqv
oVng4DZChl8MLL9Www48W8TNo98MHk30+anabdnJurT+p+CHp2N+SesKG8A4
tUlAgC5H42dJBhcYAwgPsNZii5FeaFvt04C0Lr4nv2JffTLlnWJfUFkAAdKI
AXx6jpGw23CPDnQ4uuLh8gt6pLsqqKzrVWOPOimXeNRVLk8joSvCWNf4mLlE
61OxZ5NUh+3dXLNfz/FCr2xXbAX6W986yudDW322ZcCiDBkhd71OlAfKBLK1
Yhpceg/QXzfJSISylgSry0QclX2EWWCLa6xZGRaBgabYsyG/X5BQo6jK/4in
J/5WgW5nxENhQ5IM2apVynDauHicnpotKq5gcwz2hpeMeQmwGa56qkJ+8VTf
5c3AjT8+JF/qLRLGlNQwiiCZ4sY5XeBNhFPRAJn6X4y6tDvWLY1UCkAUuzt9
mLNobG5t8yLSNvGHVqIiW7l9NjSpo+b+odiQgcPB9vCrZGEGEPBtEIdu2TyW
djhwQYt29nq327/ww/V6565OqQC3X/GrRHbp7Ruy6UxZeCilNtbQ+JxDr7Tn
1MCiWLUKOis0rZTEWE+/EDga7in7RnQVw58EIZIWBQxXemezcCD4AIEhRb5u
SddzY1ZF7PGLZ9cuiecw5+xfPtRdGHyF7tCzGR8GJUTHFUFUKZUeHLvRKv19
XPo82W3ZbLWupJbHEkLPhzthm5WeVuOWNba6XmaJmXWZT+jNQosb0Bt786UO
WhBCpKadW8wjkLf8G1SL1o9KpzFgaUZr2p4ExtKoZoJ4CfEnRV54gS1uDJPZ
hUZvluYtsyefSpveU+A5M2qLLul1I7UfY70E20/p1aNITQtDXj70vVwEsP5d
Slu7scLFbGelTMuEGaifzgOnsxIw04ZHWuFO/Wy/fXMxycIHeAczfsshmyy1
8GYKHA1d1e62qvnUUh2YkrVK899uMyE/VxY8km+90AMB6Fhb/UnRtUg3gEZL
XDLDDo1lUNiGiFDGqAzc5wO8iRRDP5ESSZtzz+HyYdLc0THE/mQSU6WW4/zC
yJKXhGdaJQe0zICdpdIJoSAmOP9DApmqLMO2ZXRLnIQhnbO7aj5Lq8MDYnQH
8tRj0L30wkTXfLMDK4Ur9Liwsidl2hprI8rkUFbaKEXCtiEduS6wu0Krm2z2
lPgixvP4GVcpFo01IHemyx4dBavxDZkrRisl3d42KL6LqRxLGkDEfEF1GkDM
H10vjHAPoVrTJUSYBsMI2QOY2pxdZB4tWCULMNPjOJ9aKG0Nowx44jLE4YBY
z+sdg7YL7XYiZp3Pv4mVR76k2LdH558UDS9XTFWBwNsd7k9HmzQ6uCDiaVnr
NcVktNIYmelFdVsUHjXGe8hxjBFHyZCEBLf7gq7E/1SQt5BXQ3WuBlyseUFb
EYJCht9FkUrRYLiSN4GKGu8ET8xAHDRsQDfmZDMX+7Z3N1pq/MpQUty1Orhe
SWjtmF4Si5YwycUbn28rzIAUEEvSegQYeMnAorkZCLJBZCVKbQxhrVWeJxWw
5okuPvnHJ6jxAQR5TKuLhHV2a6Xr9lkd18NfhQThWOfarT55SXnr9s7V/qDK
wFgSmGs9IK+nvkb0qNHSQtGti6c99SOS24s3F8Xm++EazIDI3UEfM3u8ZUTf
vaRQBweOd2Q3m5wUmSTndkoopDQlFqOY8hMmeU1CRhLuSRPeYlpsJw5gi4OC
UBTmexHzmOaGzfm2w5JJGoeHG1OoGF/c5rqaNFdJjx18PhoalfrTAwc7JvYQ
LiHR/oBQo43KSYzEtCmZR3jGNHOHM43CI2dqiKH3zcQxp0r1SusZr11vxzgh
0g/lm5VlUb6PxdPkr32Ghirmv+7cuLIpdp44JKlhWkzWWXSKKiK/WCNZYxi6
zSfM+pDwPaLq4hWQzMo0zrbPnVE+8MdVkx179Cg4+PkK/gD/3t2f7Gf2R/A3
TRj+eH65B/98epJILgYcCrfUDCXE0p0iYyZvJwUTNMDHHzSx9o2ykpDwYObm
4vHjeTq6cx6WYYW6hvOI6MllP3vLF+hnh4GT7HNR4ldHbl3WTXYO+w5O/xpM
psM6u77n5o5d5QusXCxmmO9dll7CvwegwMPUs1cHx7toni5Xvg511KymcCnO
YDkP63sYJQwMZ4ohYy8Qc+RNyaeCr8bbwWfwBmFfCDr8p19++DnPfvwp2xQO
zY2blnBGYKL30zJoKAvx7iou9oYr9tYzZWAkq5luelOHuV3IpjS9ZIKcCtAw
bQerM+/WNb/84VspQa3QRN0djvZ9gTuDb4aVhwW+q6vbmwKG9IeH9T4oH6Cr
7KJo4Sd5dga77ooyOwdz6XJWty1oY7huq2kxW+TgGVawchX0kmenrSvr7BAc
QdgisIur7AocoiVsCjTqv9xX2bXDXJMLbHE9x6cXsL5A3V3B3LOrpoY9/YAr
9waWAJX7+xr6fefgtK8r/BeepkvUKi2ex2OUhas7rA3P4VfgXsxx7FRIg1w3
b9cFGO5w0BbQxZlbz2roCJ1kaMrNQB9gdkN2NjtyOMArv8yuSc+AcnhTelBY
H2AboRkPLitYgtmJr8EhKF04f7/DeuN/L939coOHbdHceakZPAcfFCbdLopK
8xFUSsDnX4HendMxQ3G6xVC6lqkRk1r4DYnXfSvE5SPivp9u2WRyVDqMZH9c
3TcEBELlkEINSPE8HQrVWFbyjCJ+UEjA0UQK1lp43PSQY5ew+uC4vsNE5eq2
xWfzqBKlqAI1avxENE7UeK7zeyYfh4FEWWL7BO5vtFx4DGm2GoNjWN1ZMhfu
tCjRZmiCEmvsBCRJ4DFoZDZNmDexHpCt1zx8m81A6Az6LIvXPMgq5myHHxRz
L2J8MEdpmJzAYhWlKlJQDEV5Q/sjbOMVZ51gfkGErVM2gEla+zGc1cGIhWUZ
qBz2jteghsjz5JQ/dK6V7QC8auyFNKVEzvEGwJxMIh3m+TBPsTNt4Iwe1h6M
T5gWiGztsgO8fGGL5DGZJ5yFCaNHT+k/CNx8AzMirz5k8ECD58Vi4UCSHkDA
qIlDRHy49l8qEqB9QUERlMpIvs24VpEvqVcxANbHkm/3CXkVrf28CfzPcI/A
gixdA8YKiLTpHbTF83/rW6w3mN09/1s9Pv9dEnAVzHmTHcISQX96GaUyIacG
LvuG7wo9iiT5fIvfOFAamCUUDn0kGh9Qalbfso6FO2JFEBE46qp+/qfNQP4J
Ba5z7nh4v9HbcZN3p2x3YHTOybpcODi/13VJfeP8P/iv3mV/4ivQ68n/SfpV
m3OUAQA=

-->

</rfc>
