<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.7) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

]>


<rfc ipr="trust200902" docName="draft-kavian-aep-basic-session-credential-04" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true">
  <front>
    <title abbrev="AEP Basic">Basic Session Credential Grant Type for the Agent Enrollment Protocol</title>

    <author initials="N." surname="Kavian" fullname="N. Kavian">
      <organization>Jarwin, Inc. (InFlow)</organization>
      <address>
        <email>nas@inflowpay.ai</email>
      </address>
    </author>

    <date year="2026" month="September" day="04"/>

    
    
    

    <abstract>


<?line 39?>

<t>This document defines the Basic session-credential grant type for the Agent Enrollment Protocol (AEP).  The grant type lets an AEP Service issue an HTTP Basic credential through the AEP Grant command for deployments that already integrate with Basic authentication middleware.</t>



    </abstract>



  </front>

  <middle>


<?line 43?>

<section anchor="introduction"><name>Introduction</name>

<t>AEP session credentials allow a Service to issue a stateful credential after an Agent authenticates with a baseline AEP client assertion <xref target="AEP-CORE"/>.  This document defines the <spanx style="verb">basic</spanx> grant type for Services that want to reuse HTTP Basic authentication <xref target="RFC7617"/> while preserving AEP key possession as the issuance root.  Grant type request and response bodies are JSON objects <xref target="RFC8259"/> carried over HTTP semantics <xref target="RFC9110"/> as defined by AEP.</t>

<t>This grant type does not replace baseline AEP authentication.  Services that implement this grant type <bcp14>MUST</bcp14> continue to accept baseline AEP authentication on authenticated AEP commands.</t>

</section>
<section anchor="requirements-language"><name>Requirements Language</name>

<t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>

<?line -18?>

</section>
<section anchor="grant-type"><name>Grant Type</name>

<t>The grant type identifier is:</t>

<figure><sourcecode type="text"><![CDATA[
basic
]]></sourcecode></figure>

<t>A Service that enables this grant type lists <spanx style="verb">basic</spanx> in <spanx style="verb">commands.grant_types</spanx> and lists <spanx style="verb">grant</spanx> and <spanx style="verb">revoke</spanx> in <spanx style="verb">commands.supported</spanx> in its AEP Inspect document.</t>

</section>
<section anchor="inspect-configuration"><name>Inspect Configuration</name>

<t>A Service <bcp14>MAY</bcp14> publish configuration under <spanx style="verb">commands.grant_types_config.basic</spanx>:</t>

<figure><sourcecode type="json"><![CDATA[
{
  "commands": {
    "grant_types": ["basic"],
    "grant_types_config": {
      "basic": {
        "default_lifetime_seconds": "86400",
        "realm": "api.example.com",
        "scopes_supported": ["read", "write"],
        "supports_per_credential_revoke": "true"
      }
    },
    "supported": ["enroll", "grant", "inspect", "revoke", "status"]
  }
}
]]></sourcecode></figure>

<t><spanx style="verb">default_lifetime_seconds</spanx> is an AEP-owned numeric value and is therefore represented as a JSON string.</t>

<t><spanx style="verb">realm</spanx>, when present, identifies the HTTP Basic realm associated with credentials issued by this grant type.</t>

<t><spanx style="verb">scopes_supported</spanx>, when present, lists Service-defined scope strings an Agent can request.</t>

<t><spanx style="verb">supports_per_credential_revoke</spanx> is a string boolean.  If absent, the default is <spanx style="verb">"false"</spanx>.  Every successful Grant response includes <spanx style="verb">credential_id</spanx>.  When this value is <spanx style="verb">"true"</spanx>, the Service <bcp14>MUST</bcp14> support a Revoke request containing both <spanx style="verb">grant_type</spanx> and that <spanx style="verb">credential_id</spanx>.  When this value is <spanx style="verb">"false"</spanx> or absent, the Agent <bcp14>MUST</bcp14> use grant-type or all-grant-types Revoke instead.</t>

</section>
<section anchor="grant-request"><name>Grant Request</name>

<t>The Agent invokes AEP Grant using baseline <spanx style="verb">Authorization: AEP &lt;jwt&gt;</spanx> authentication with <spanx style="verb">op</spanx> equal to <spanx style="verb">grant</spanx>.</t>

<figure><sourcecode type="json"><![CDATA[
{
  "grant_type": "basic",
  "label": "legacy-basic-prod",
  "requested_scopes": ["read"]
}
]]></sourcecode></figure>

<t><spanx style="verb">grant_type</spanx> <bcp14>MUST</bcp14> be <spanx style="verb">basic</spanx>.</t>

<t><spanx style="verb">label</spanx> is <bcp14>OPTIONAL</bcp14> and is an Agent-provided display label.  Services <bcp14>MAY</bcp14> ignore it.</t>

<t><spanx style="verb">requested_scopes</spanx> is <bcp14>OPTIONAL</bcp14>.  A Service <bcp14>MAY</bcp14> grant fewer scopes than requested.  Unsupported requested scopes <bcp14>MAY</bcp14> be omitted from the response <spanx style="verb">scopes</spanx> array.  If the Service cannot issue a useful credential for the requested scopes, it <bcp14>MUST</bcp14> return <spanx style="verb">invalid_request</spanx>.</t>

<t>The Agent does not submit a password.  The Service generates the username and password, or generates the password for a Service-owned username, and returns the credential in the Grant response.</t>

</section>
<section anchor="grant-response"><name>Grant Response</name>

<t>A successful Grant response is a JSON object:</t>

<figure><sourcecode type="json"><![CDATA[
{
  "credential_id": "bas_01HZY8W7Q2F8J7D3P9G9Z1N6TT",
  "expires_at": "2026-12-01T00:00:00Z",
  "password": "s3cr3tExample",
  "realm": "api.example.com",
  "scopes": ["read"],
  "username": "aep_agent_abc123"
}
]]></sourcecode></figure>

<t><spanx style="verb">username</spanx> and <spanx style="verb">password</spanx> are <bcp14>REQUIRED</bcp14>.  Agents <bcp14>MUST</bcp14> treat <spanx style="verb">password</spanx> as an opaque secret. Services <bcp14>MUST</bcp14> generate values that can be encoded according to RFC 7617 without lossy transformation. Generated passwords <bcp14>MUST</bcp14> contain at least 128 bits of entropy. Generated usernames and passwords <bcp14>MUST NOT</bcp14> contain control characters.</t>

<t><spanx style="verb">expires_at</spanx> is <bcp14>REQUIRED</bcp14> and is an RFC 3339 <xref target="RFC3339"/> timestamp for credential expiry.</t>

<t><spanx style="verb">realm</spanx>, when present, identifies the associated HTTP Basic realm.</t>

<t><spanx style="verb">scopes</spanx> is <bcp14>OPTIONAL</bcp14> and contains the granted scope strings when present.  A missing or <spanx style="verb">null</spanx> value means the Basic credential has no scope-limited authorization.  The Service <bcp14>MAY</bcp14> return an empty array with the same meaning.</t>

<t><spanx style="verb">credential_id</spanx> is <bcp14>REQUIRED</bcp14> and is a stable Service-issued identifier for the issued Basic credential. It follows the Service-wide uniqueness and non-reassignment requirements in the Core Grant command. It is not the username or password and is not used for credential presentation. The Agent stores it with the credential and sends it only when targeting that credential in a Revoke request supported by the Service.</t>

<t>The response does not include the base64-encoded <spanx style="verb">Authorization</spanx> value.  Agents construct that value locally from <spanx style="verb">username ":" password</spanx> according to RFC 7617.</t>

</section>
<section anchor="credential-presentation"><name>Credential Presentation</name>

<t>On later HTTP requests, the Agent presents the credential using HTTP Basic authentication:</t>

<figure><sourcecode type="http-message"><![CDATA[
Authorization: Basic YWVwX2FnZW50X2FiYzEyMzpzM2NyM3RFeGFtcGxl
]]></sourcecode></figure>

<t>On protected resources, the Agent <bcp14>MAY</bcp14> instead use the dedicated AEP carrier while preserving the Basic field value:</t>

<figure><sourcecode type="http-message"><![CDATA[
AEP-Authorization: Basic YWVwX2FnZW50X2FiYzEyMzpzM2NyM3RFeGFtcGxl
]]></sourcecode></figure>

<t>Services implementing this grant type <bcp14>MUST</bcp14> accept both carriers on protected resources. Agents <bcp14>MUST</bcp14> use only one AEP carrier per request, and the ambiguity and precedence rules are defined by AEP core.</t>

<t>The encoded value is standard base64 of <spanx style="verb">username ":" password</spanx> as defined by RFC 7617.  This encoding is not AEP's base64url binary convention.</t>

<t>Authenticated AEP command endpoints <bcp14>MUST</bcp14> continue to accept baseline AEP authentication.</t>

</section>
<section anchor="revoke"><name>Revoke</name>

<t>The Agent invokes AEP Revoke using baseline <spanx style="verb">Authorization: AEP &lt;jwt&gt;</spanx> authentication with <spanx style="verb">op</spanx> equal to <spanx style="verb">revoke</spanx>.</t>

<t>To revoke all Basic credentials of this type for the authenticated Agent:</t>

<figure><sourcecode type="json"><![CDATA[
{
  "grant_type": "basic"
}
]]></sourcecode></figure>

<t>When the Service advertises per-credential Revoke, the Agent can revoke one Basic credential:</t>

<figure><sourcecode type="json"><![CDATA[
{
  "credential_id": "bas_01HZY8W7Q2F8J7D3P9G9Z1N6TT",
  "grant_type": "basic"
}
]]></sourcecode></figure>

<t>Revoke returns an empty JSON object on success.  The Service <bcp14>MUST</bcp14> return success regardless of whether a matching credential existed.</t>

<t>To revoke all session credentials of every grant type, Agents use the core <spanx style="verb">all_grant_types</spanx> Revoke request.</t>

</section>
<section anchor="error-handling"><name>Error Handling</name>

<t>This grant type uses the AEP error vocabulary defined by the core protocol.  A Basic credential that is expired, malformed, revoked, unknown, or bound to a different Agent fails as <spanx style="verb">not_recognized</spanx>.</t>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>

<t>This document requests registration of <spanx style="verb">basic</spanx> in the AEP Grant Types registry.</t>

<texttable>
      <ttcol align='left'>Field</ttcol>
      <ttcol align='left'>Value</ttcol>
      <c>Grant Type</c>
      <c><spanx style="verb">basic</spanx></c>
      <c>Description</c>
      <c>HTTP Basic credential issued through AEP Grant</c>
      <c>Reference</c>
      <c>This document</c>
</texttable>

</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<t>Basic credentials are bearer secrets once encoded into the Authorization header.  Services <bcp14>MUST</bcp14> store passwords using strong password-storage controls.  Services <bcp14>MUST NOT</bcp14> log raw passwords or Authorization header values, and Services <bcp14>MUST</bcp14> support AEP Revoke for every advertised grant type.  Agents that suspect credential disclosure <bcp14>SHOULD</bcp14> call AEP Revoke using baseline AEP authentication and then fall back to per-request signed client assertions until a new credential is issued.</t>

<t>Services <bcp14>SHOULD</bcp14> use a distinct realm or credential store for AEP-issued Basic credentials when the Service also supports human-facing Basic credentials.</t>

</section>
<section anchor="privacy-considerations"><name>Privacy Considerations</name>

<t>Basic credentials can become correlation handles if reused outside the issuing Service.  Agents <bcp14>MUST NOT</bcp14> present AEP-issued Basic credentials to other Services.  Services <bcp14>MUST NOT</bcp14> log raw passwords or Authorization header values in ordinary logs or telemetry.</t>

</section>


  </middle>

  <back>



    <references title='Normative References' anchor="sec-normative-references">



<reference anchor="RFC3339">
  <front>
    <title>Date and Time on the Internet: Timestamps</title>
    <author fullname="G. Klyne" initials="G." surname="Klyne"/>
    <author fullname="C. Newman" initials="C." surname="Newman"/>
    <date month="July" year="2002"/>
    <abstract>
      <t>This document defines a date and time format for use in Internet protocols that is a profile of the ISO 8601 standard for representation of dates and times using the Gregorian calendar.</t>
    </abstract>
  </front>
  <seriesInfo name="RFC" value="3339"/>
  <seriesInfo name="DOI" value="10.17487/RFC3339"/>
</reference>
<reference anchor="RFC7617">
  <front>
    <title>The 'Basic' HTTP Authentication Scheme</title>
    <author fullname="J. Reschke" initials="J." surname="Reschke"/>
    <date month="September" year="2015"/>
    <abstract>
      <t>This document defines the "Basic" Hypertext Transfer Protocol (HTTP) authentication scheme, which transmits credentials as user-id/ password pairs, encoded using Base64.</t>
    </abstract>
  </front>
  <seriesInfo name="RFC" value="7617"/>
  <seriesInfo name="DOI" value="10.17487/RFC7617"/>
</reference>
<reference anchor="RFC8259">
  <front>
    <title>The JavaScript Object Notation (JSON) Data Interchange Format</title>
    <author fullname="T. Bray" initials="T." role="editor" surname="Bray"/>
    <date month="December" year="2017"/>
    <abstract>
      <t>JavaScript Object Notation (JSON) is a lightweight, text-based, language-independent data interchange format. It was derived from the ECMAScript Programming Language Standard. JSON defines a small set of formatting rules for the portable representation of structured data.</t>
      <t>This document removes inconsistencies with other specifications of JSON, repairs specification errors, and offers experience-based interoperability guidance.</t>
    </abstract>
  </front>
  <seriesInfo name="STD" value="90"/>
  <seriesInfo name="RFC" value="8259"/>
  <seriesInfo name="DOI" value="10.17487/RFC8259"/>
</reference>
<reference anchor="RFC9110">
  <front>
    <title>HTTP Semantics</title>
    <author fullname="R. Fielding" initials="R." role="editor" surname="Fielding"/>
    <author fullname="M. Nottingham" initials="M." role="editor" surname="Nottingham"/>
    <author fullname="J. Reschke" initials="J." role="editor" surname="Reschke"/>
    <date month="June" year="2022"/>
    <abstract>
      <t>The Hypertext Transfer Protocol (HTTP) is a stateless application-level protocol for distributed, collaborative, hypertext information systems. This document describes the overall architecture of HTTP, establishes common terminology, and defines aspects of the protocol that are shared by all versions. In this definition are core protocol elements, extensibility mechanisms, and the "http" and "https" Uniform Resource Identifier (URI) schemes.</t>
      <t>This document updates RFC 3864 and obsoletes RFCs 2818, 7231, 7232, 7233, 7235, 7538, 7615, 7694, and portions of 7230.</t>
    </abstract>
  </front>
  <seriesInfo name="STD" value="97"/>
  <seriesInfo name="RFC" value="9110"/>
  <seriesInfo name="DOI" value="10.17487/RFC9110"/>
</reference>

<reference anchor="AEP-CORE" target="https://datatracker.ietf.org/doc/draft-kavian-agent-enrollment-protocol/">
  <front>
    <title>The Agent Enrollment Protocol</title>
    <author initials="N." surname="Kavian" fullname="N. Kavian">
      <organization></organization>
    </author>
    <date year="2026" month="August" day="27"/>
  </front>
  <seriesInfo name="Internet-Draft" value="draft-kavian-agent-enrollment-protocol-04"/>
</reference>


<reference anchor="RFC2119">
  <front>
    <title>Key words for use in RFCs to Indicate Requirement Levels</title>
    <author fullname="S. Bradner" initials="S." surname="Bradner"/>
    <date month="March" year="1997"/>
    <abstract>
      <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
    </abstract>
  </front>
  <seriesInfo name="BCP" value="14"/>
  <seriesInfo name="RFC" value="2119"/>
  <seriesInfo name="DOI" value="10.17487/RFC2119"/>
</reference>
<reference anchor="RFC8174">
  <front>
    <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
    <author fullname="B. Leiba" initials="B." surname="Leiba"/>
    <date month="May" year="2017"/>
    <abstract>
      <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
    </abstract>
  </front>
  <seriesInfo name="BCP" value="14"/>
  <seriesInfo name="RFC" value="8174"/>
  <seriesInfo name="DOI" value="10.17487/RFC8174"/>
</reference>



    </references>





  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA61Z6XIbNxL+P0+B5f7YZEtD63BsmZVKVrElW1lbcmQ5Xjvl
EsEZkJx4OJgAGNH0kWfZZ9kn268bmIukVE6VVYk5BIHuRh9fHxPHceQyl6uR
GPwkbZaIF8raTBfioVGpKlwmc/HYyMKJy1WpxFQb4eZKHM3wmzgujM7zBT0+
N9rpROeDSE4mRl2D3tHxc8E0B1Gqk0IuwCQ1curid/I6k0UsVRlPaENsPdM4
aZjGu3ejVDoc2d/dvxfvPqCFBAszbVYjYV0aZaUZCWcq6/Z3dx/s7ke2miwy
JuQg60icHl+eRNbJIr2SuS4U71ZRmY0iISDtSKyUxaPVxhk1tc331aL9Kis3
14ZOxPhfiKzAD2dD8W++Ay/5q/XXtJnJIvsgHaQZiZ+lWWbFjjgtkqH45rQ4
yfXyW96nFjLLRyBh/5UVUyyXcjWUWRQV2ixw+loR64uThwcHBw/C4/17e/fD
4+H+d/Xqg729XXqE2uOH5xfHI6ZfG/fydqPxVmlmyo3E3LnSju7cgfqlMzJ5
p8wwU246xJ3uwJJ3+kYkorFqiMZlIHqHiXZteBjv3+dFq0ymLO6rvZACinHK
FMrFj4j2up/cxIJ8gk63NqK/eJuNttkpIgkaLQ+HwyiK41jIiaVruyi6nGdW
4MYVaytV06xQlv3fx8qm24oZx4r7olgR38BW3w6FION0DubKWSELsiTC0Vxn
iRLw60rR4pPLyxBWosPWzY2uZnPPD8d8yCZ6sYD3sySpKnO9Iv50A+mEzI2S
6QrKQlAZmEksMzcPpEmjRDphBxaLLE1ztZRGBR35hSj6O1nO6LRKaF8UEe+g
lY54uE0O1xayuY7T9Y0QyuA9rfLudWB8ZVgFrLuONNA/iykFkEPlMAjfN8kz
3mjhWizxx491HHz+zBq+yZJjRqDxuuGCoEFXS/5NC6Mqq7omWNPTx48hPD9/
Fst5litRGmWJVDFjOd+plSi1rVUkvQykCllALUZrB2kft7IY9UelLG4GM4JU
qQsIMNEp4kfAHOLnF+dnQk9+VwnsyuwJEsA+kQZBlgp9DU2yxBZYQ6KGfYQX
2AcRvDpSMVmRjMPg9x2FpBrcCu0gQZlLyNnTfV8HEL+vu2xR5orV7tbIPnv5
4hI+iqNFxS4hk0SV7jbqgpTW8YbUW9/7uR2SQ15AY5lR3tOfymJWAT/oToq1
v9QmtWJAvAc7/lOcnfPzxfEvL08vjh/R84snR0+fNg9R2PHiyfnLp4/ap/bk
w/Nnz47PHvnDWBW9pWjw7Og1fiErDs6fX56enx09HSD0vE4axySLQg8TxVFp
4Dx0RWmjVNnEZBN8wZmfHj7/33/37sKMf4Md9/f2yN7+y+He/bvse6rw3HSR
r8JXaG0VybJU0hAVhCScpMwc4nOH3MDO9bIQc8VB/s/fSDNvR+L7SVLu3f0h
LNCFe4u1znqLrLPNlY3DXolblrawabTZW1/TdF/eo9e977XeO4vf/8h+Fu8d
/vhDRM7TljreYzremjE4TTOEU2ZHUfTnn38Kp967iAGEvgL+WoAj11eFnOQc
B33HzzML36yRB7YYNx7Mu65olx2zAcNeXvcrY5RX+p1aO2irskQdo1Jez3CG
IuO0sCWgofGwoYdsv/hQF9NsVhkZsLsRHpoTZTUB6znFZ7tJVEWK+28V98rv
HPpbBQX9bkH5IzLwoD4yGImPnJEHnbNY/G3ABwdvdzZ+DZSbk/jV720XsAQU
k1XurvJsqly2UFdW4RwzHBzeu7u7O9hpNyP15Qv6BQEwVO8lYdQQInb32EQT
80axLCTlTArxpcmcqoX12/0+e1Uqc9XmsitvLeJF1ecgHPjMn5/DZfs8fKVD
XFgJ9JB5k9FjoIcnypyVHbyNiNxn74Hjm9QAt6iLihhxDiQp4BEGOexa5lxa
pLTDUfwjAVLm4dxVeARCwuVUg9IIuQxuNGYVjncYXETYutNGic9snVTJ+ylD
6yRj5OY83i0SuCLgNLQWMMRu3RobnH2gBBeO65zGx4LUtq0oEjyF1MrEb7Wd
V10gguSrcyUpz51OqVZk5nTXoHnaPB5McSE1GGPXMRLwStgKuc1aqnM8xjTJ
PCuSvAK+I6paxllKR1/RBVkX3kZMmb1o7Fk2AUvQHC4BSS9Y7KZ2oBQrs8IL
D52P29jyiMJg9YXsw8XQ4PQu79XKclCJxBxiBjvamOdxu2Jr+eDUDuE0bIH3
wkvssdeTzAraaztVbWX5JnWRMD7i6r/ptWjj978v3Q/j9dqBHW6sy7EAGyqa
dY2rw3W0ajVEgevRhmJ1kMuJymktVzOZrEL/ioYk9b8Hnav0yjtsCxpvmxDt
qp81NmnKUHJGZsE+V2esOjhr9yV+14i0VKSZRUW2EnymW3oRhGezggI5cz5c
+4L1GOBkH/197E3VEmjv95OTNDGjUpx4WTTB2K7Xu4kIrqUXmaPVqdEL9pPG
7ce1GKhT0fJyNHVdGhFKFWfdJcCp1nqEur1aZw0MCo6I6qkyyJFwIZln6VXY
OR52/aupbXl6QNFTAqOoSgyNWS0QdivDDQhxhTyG+kk2TX1ih5y9v6/+icVt
+p+AwDWRnVDek7j+WOeeXCSqNdToxYxfogR+C8o0CO6bhc383I3+4PRXu3tP
3rw+fHX/l/2Tw5/vPzp4/uDxgzd7Z/cuL723q/clSm17JR2d4C5/bz/e3bvc
3R3xf2/8vloLtMseJObAHfucWwfNLdl4sBFIvFrrjo+p8oqHBFdykuztHwya
UKt3hcqplmPMlXZdu5L3z7hdYLdx4OJ6eznydCnhPuiioCk0aW2k0Zna6B4p
Q+dDSQYxoIpEU6yiuwE5wi4AD2p1QY0ig5KunMjRFSLxwWo2DCWol3oc6LY+
Ztu2SVIVj5NKAuT39g/FhMo+PQVH9OTlqnu8VoTtOWwgRlV0TZA+UX6IZC5p
CKIMdVXj1tCMG7XmOsBEF6IZlW8u6Ql9CBUgqFIWJbt/x6mZ3uqLy4hO1bBe
UbS1wSZkhjt5GgxpGxVBly2jIE8QYSPIOy6qHEDsk98COb87++lcZi4JQTzh
OM+AImTtblZagxICxwBO0JxalG7lYdCnKGJiCVuIZ6i2+sl5qw1okoJ2o8GY
UE51+pYaMsMv6xcZilNgvqZRje1icbwEDZT+Gfy/ALwwx0IXMQwAZc0K7l1N
t+8OoPWQ8k9vFsU8Mo+4PRyFaA1WhhvRHvyerjtPMFfQbAvl1oGdJfhv1Nid
KYEojqW8oWmLw9STo5Jjtge8G6VUm/G4Sm1UFFJKA7dNVgnVHe+lkuXe3bjG
g37hEvysxSI4L5y0SpwXzHthrhMUUyufTxt0E4PRQHTwahvQcMboDPWfd5QY
RecFSghXT4rCbW23tAtK30hPvhq7cSQW8gzNlGNggaVZzFrB5o+9fvXr8j/7
J8WbV9/t4jN7/eF49exD+eHZ/tnq2cHFiXp84pLH73MP7OcUtNohkXHxYXVl
EtWTlwsgX2ByReor9LQ7NeIJmdkc1LVBjqjJU6/6rRdBL/UVLtOkkmZU5qXY
Mi2rJ2RUxgf5Lc3Etihj2EtqpAJ2el1PTMPt0fHU9t4JzQDwdjFBz58RLFG2
MCohe9OAssrD4LE/NIS3mjoIav9umgZ+BSMR1z4AKEPd6Lq9aWTju2GAy5RJ
NwEcwPgfNlCtTI78V0j0Woica1Ii0CFiZ9s6LQS1tNRZo6G/NogMo0YCh5u6
lQAdX7VdCQ0paZqm0cyABnnrUM5lAHtQ71XE2uiURN4oBLe1PnU9FTrCNpPJ
9JoG7hZXhiN1X4T423cj0vfcLDI54brIX6civU36Bst9nd2k3k5ZTLEUiuj1
nN3pKMIOfJ3BrXN6hLqRTmh6gqSB6i2Zk9V7FU/GfdO65ba9LaESjqcGbfjv
1NFcYxkFnBiDwlVvZNjPV+ylx8bA/E/g8nDA2eZ0v7KhyiJXVLz5GmlmUuUU
TJ1wbNjW79+4YNryLkpyivc1I5qihcyppKVHf3E8VMW7Ak0Qd0wTXRHuIOzQ
z06nypC3eJ+ZyozeHlnUYtqhgUv0rMg+qHTsB5lHZ0c0xbSoT/yA0q6/tKtT
Gdkqo/d6/i3CtDt97b80u+QRRdhOJeonccJpwP99Er8yrn3x3ycQiNs/0fv2
BX9MoPMKHgRq2f+CBI/4BULJt/90w0vEUBbW7xJblRCBC8WGSRTroK/kL5AA
1nqhkspQTlm32CZ4UYKZKPxrQr9FSS5pUwtQW3uzdcFUzJHslemNQXgw5thp
m57HIzKsq/FRL8e0C0m9boDsBhnqknI9E0YuO8Tgv9uECI2gT6lr4oQ5XSdH
ED77iG8ANe3OP5uikGPLVn5+3zFdmtkEHWSFe4Y3KFQn3pKGtrxaC8m/QNDh
6EQm7ygmCdab6he1PgRbf9kKjYIKKmxRqGXfoYJPDTtFTpCPcIzi3SLpJi5M
h/t1vrcb6YYKrRualtDC9ZJSbnWtZSvmFbJ9PJUJ3X/jNOPIc5Ndy+RLHNO3
9KggGAmNyoPNCVypgJv6V8SpQEtPpJp2i5jXvUJ/3EBuFYrr2+8JY2hOMLUq
v4qHEgByt0Bgj8O83ymqQxn+/g8crID1IiQAAA==

-->

</rfc>

