<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-westerbaan-dnssec-mldsa-03" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="ML-DSA for DNSSEC">Module-Lattice Digital Signature Algorithm for DNSSEC</title>
    <seriesInfo name="Internet-Draft" value="draft-westerbaan-dnssec-mldsa-03"/>
    <author initials="B. E." surname="Westerbaan" fullname="Bas Westerbaan">
      <organization>Cloudflare</organization>
      <address>
        <email>bas@cloudflare.com</email>
      </address>
    </author>
    <author fullname="Sophie Schmieg">
      <organization>Google</organization>
      <address>
        <email>sschmieg@google.com</email>
      </address>
    </author>
    <date year="2026" month="August" day="04"/>
    <area>Security</area>
    <workgroup>Domain Name System Operations</workgroup>
    <keyword>DNSSEC</keyword>
    <keyword>ML-DSA</keyword>
    <keyword>post-quantum</keyword>
    <keyword>FIPS 204</keyword>
    <keyword>signatures</keyword>
    <abstract>
      <?line 58?>

<t>This document describes how to specify Module-Lattice-Based Digital
Signature Algorithm (ML-DSA) keys and signatures in DNS Security
(DNSSEC).  It uses the ML-DSA-44 parameter set defined in FIPS 204.
ML-DSA-44 is believed to be secure even against adversaries in possession
of a cryptographically relevant quantum computer.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://bwesterb.github.io/draft-westerbaan-dnssec-mldsa/draft-westerbaan-dnssec-mldsa.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-westerbaan-dnssec-mldsa/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Domain Name System Operations Working Group mailing list (<eref target="mailto:dnsop@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/dnsop/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/dnsop/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/bwesterb/draft-westerbaan-dnssec-mldsa"/>.</t>
    </note>
  </front>
  <middle>
    <?line 66?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>DNSSEC, which is broadly defined in <xref target="RFC4033"/>, <xref target="RFC4034"/>, and
<xref target="RFC4035"/>, uses cryptographic keys and digital signatures to provide
authentication of DNS data.  Currently the most popular signature
algorithms in use are RSA and the NIST-specified elliptic curve
signature algorithm ECDSA <xref target="RFC6605"/>.</t>
      <t>All currently specified algorithms rely for their security on the hardness of the
integer factorization problem or the (elliptic curve) discrete
logarithm problem.  A cryptographically relevant quantum computer when built
would be able to solve both of these problems efficiently, and
would therefore be able to forge DNSSEC signatures created with any of
these algorithms.</t>
      <t><xref target="FIPS204"/> specifies the Module-Lattice-Based Digital Signature
Algorithm (ML-DSA), a signature scheme whose security is based on the
hardness of lattice problems over module lattices.  ML-DSA is believed
to be secure even against adversaries in possession of a
cryptographically relevant quantum computer.  <xref target="FIPS204"/> defines three
parameter sets: ML-DSA-44, ML-DSA-65, and ML-DSA-87.</t>
      <t>This document defines the use of DNSSEC's DS, DNSKEY, and RRSIG resource
records (RRs) with the ML-DSA-44 parameter set.  ML-DSA-44 targets NIST
security category 2, which is defined as the (quantum) collision resistance
of SHA-256.  ML-DSA-44 has the smallest keys and signatures of the three
ML-DSA parameter sets, which makes it the most suitable for use in the DNS.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="dnskey-resource-records">
      <name>DNSKEY Resource Records</name>
      <t>An ML-DSA-44 public key consists of a 1312-octet value as produced by
the key generation algorithm ML-DSA.KeyGen defined in Section 5.1 of
<xref target="FIPS204"/>.  It is encoded into the Public Key field of a DNSKEY
resource record as a simple bit string, using the byte encoding of the
public key described in Section 7.2 of <xref target="FIPS204"/>.</t>
    </section>
    <section anchor="rrsig-resource-records">
      <name>RRSIG Resource Records</name>
      <t>An ML-DSA-44 signature consists of a 2420-octet value as produced by the
signing algorithm ML-DSA.Sign defined in Section 5.2 of <xref target="FIPS204"/>.  It
is encoded into the Signature field of an RRSIG resource record as a
simple bit string, using the byte encoding of the signature described in
Section 7.2 of <xref target="FIPS204"/>.</t>
      <t>Signatures are generated and verified using the "pure" ML-DSA variant
(i.e., not the pre-hash variant HashML-DSA) with an empty context string
(ctx of zero length), as described in Sections 5.2 and 5.3 of
<xref target="FIPS204"/>.  The message signed is the data to be signed as described
in Section 3.1.8.1 of <xref target="RFC4034"/>.</t>
    </section>
    <section anchor="algorithm-number-for-ds-dnskey-and-rrsig-resource-records">
      <name>Algorithm Number for DS, DNSKEY, and RRSIG Resource Records</name>
      <t>The algorithm number associated with the use of ML-DSA-44 in DS, DNSKEY,
and RRSIG resource records is TBD1.  This registration is fully defined
in the IANA Considerations section.</t>
    </section>
    <section anchor="examples">
      <name>Examples</name>
      <t>The following example, in the style of Section 6 of <xref target="RFC6605"/>, shows an
ML-DSA-44 DNSKEY, its corresponding DS record, and an RRSIG over an MX
RRset.  The key was generated deterministically from the 32-octet seed
shown in the PrivateKey field, and the signature was produced using the
deterministic variant of ML-DSA (rnd set to all zeroes) so that the
example is byte-for-byte reproducible.  Because of the size of ML-DSA-44
keys and signatures, the base64-encoded values are wrapped.</t>
      <aside>
        <t><em>Warning</em>: Test vectors provisionally use 18 for the algorithm number. Will
be updated with the number IANA allocates.</t>
      </aside>
      <artwork><![CDATA[
Private-key-format: v1.3
Algorithm: 18 (MLDSA44)
PrivateKey: AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8=

example.com. 3600 IN DNSKEY 257 3 18 (
             17K0clSq4NtF55MNSpjSyX2PE5fReJ2voXAksxbpvslPyZRtQvGbeadBO7qj
             PnFJy0LtURVpOsBB+suYit61/g4dhjEYSZW1ksOX0ilOLhT5CqQUujgmiZrE
             P0zMrLwm6agyuVEY1ctDPL75ZgsAE44IF/YediyidMNq1VTrIqrBFi5KsBrL
             oeOMTv2PgLZbMz0PcuVd/nHOnB67mInnxWEGwP1zgDoq7P6v3teqPLLO2lTR
             K9jNNqeM+XWUO0er0l6ICsRS5XQu0ejRqCr6huWQx1jBWuTShA2SvKGlCQ9A
             SWWX/KfYuVE/GhvabpUKqpjeRnUH1KT1pPBZkhZYLDVy9i7aiQWrNYFnDEoC
             d3oz4Mpylf2PT/bRoKOnaD1l9fX3/GDaAj6CbF+SFEwC99G6EHWYdVPqk2f8
             122ZC3+pnNRa/biDbUPkWfUYffBYR5cJoB6mg1k1+nBGCZDNPcG6QBupS6sd
             3kGsZ6szGdysoGBI1MTu8n7hOpwX0FOPQw8tZC3CQVZg3niHfY2KvHJSOXjA
             QuQoX0MZhGxEEmJCl2hEwQ5Va6IVtacZ5Z0MayqW05hZBx/cws3nUkp77a5U
             6FsxjoVOj+Ky8+36yXGRKCcKr9HlBEw6T9r9n/MfkHhLjo5FlhRKDa9YZRHT
             2ZYrnqla8Ze05fxg8rHtFd46W+9fib3HnZEFHZsoFudPpUUx79wcvnTUSIV/
             R2vNWPIcC2U7O3ak4HamVZowJxhVXMY/dIWaq6uSXwI4YcqM0Pe62yhx9n1V
             Mm10URNa1F9KG6aRGPuyyKMO7JOS7z+XcGbJrdXHEMxkexUU0hfZWMcBfD6Q
             /SDATmdLkEhuk3CjGgAdMvRzl55JBnSefkd/oLdFCPil8jeDErg8Jb04jKCw
             //dHi69CtxZn7arJfEaxKWQ+WG5bBVoMIRlG1PNuZ1vtWGD6BCoxXZgmFk1q
             kjfDWl+/SVSQpb1N8ki5XEqud4S2BWcxZqxCRbW0sIKgnpMj5i8geMW3Z4NE
             be/XNq06NwLUmwiYRJAKYYMzl7xEGbMNepegs4fBkRR0xNQbU+Mql3rLbw6n
             XbZbs55Z5wHnaVfe9vLURVnDGncSK1IE47XCGfFoixTtC8C4AbPm6C3NQ+nA
             6fQXRM2YFb0byIINi7Ej8E+s0bG2hd1aKxuNu/PtkzZw8JWhgLTxktCLELj6
             u9/MKyRRjjLuoKXgyQTKhEeACD87DNLQuLavZ7w1W5SUAl3HsKePqA46Lb/r
             UTKIUdYHgZjpSTZRrnh+wCUfkiujDp9R32Km1yeEzz3SBTkxdt+jJKUSvZSX
             CjbdNKUUqGeR8Os28BRbCatkZRtKAxOymWEaKhxIiRYnWYdooxFAYLpEQ0ht
             9RUioc6IswmFwhb45u0XjdVnswSg1Mr7qIKig0LxepqiauWNtjAIPSw1j99W
             bD9dYqQoVnvJ6ozpXKoPNUdLC/qPM5olCrTfzyCDvo7vvBBV4Y/hU3DuyyYF
             Ztg/8GshGq7EPKKbVMzQD4gVokZe8LRlFcx+QfMSTwnv/3OTCatYspoUWaAL
             zlA46TjJZ49y6w5O5f2q5m2fhXP8l/xCtJWfS/i2HXhDPoawM11ukZHE2L9I
             ezkFwQjP1qwksM633LfPUfhNDtaHuV6uscUzwG8NlwI9kqcIJYN7Wbpst9Tl
             awqHwgOGKujzFbpZJejt76Z5NpoiAnZhUfFqll+fgeznbMBwtVhp5NuXhM8F
             yDCzJCyDEg== )

example.com. 3600 IN DS 59829 18 2 (
             812cb1a22af04380e2f72d91c06c14eb1a918cf30037a8a9c67497e9264b
             4bfa )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 18 2 3600 (
             1440021600 1438207200 59829 example.com.
             kdySHzwB7NftjQSAF7snCeKau3NoqpLNg16h/eHZV8L3Zpi30lkRyiS4FLMM
             ZqTjzbf1A/bShg4qZpYlnfqXN8uqFWF9GEEJOgte1CFdF4GC05gEBU88Kryf
             nGAcpXKafw9htDxZrqmqVSWN+1guW7HyUUFo1IuWTnZKuhZptDJkq+Ml+5ZH
             y4p+2Tdwk8MH7tJlTYk/UVaM1wIXPB2YgJ++kD0zhys5c38rztcaOmMXt6ej
             yAEY37Dc1Z/KsrRQZWv+XZ/CTliuh+dGJHoGuTm5KwS0us884ukWNC/wIU/S
             dlGoBDVXsT163Tr6lTf8pJ4xixcKIN8nsKSFxP9j+AbaN5SofIAvp4LGIFLg
             MKsRV/cqeYo8PegVD2EhAQ2/HVTO3uO8vlqLK7nWVVK2+2aYKIL2EqzjhRYK
             U5DhMwS9ZgbG0niszGXpvZcNcOyABXysdVuaDjnUuamYVACOUrV786LNmt8I
             WDnXWoPPMErPk5vNyHq6+ZHg79UeZpSzx0Ae/1aIfi2WEta9Or5sGItBn6vF
             Wi9kJRuhuoMIXf9CLBV/LHL/PIenBxXSnr2Owg54AuSN2tmk2lDy8BfKzzvx
             TOoKXx4edo96Xv6QWASAxO9JmyEvhnF3SBI6HG3fn2+k8rgJLIHpsr4pZhMh
             4/SQWaojxt51nEIFi1bl7P6sAmCdMP81LSNx05hIkKcPeO33hA2VSDO7GzOE
             snBOzbhUX9gbFr3aNV/Wrbs/cZMAL1I0IKG20jkmEfZ9PeKN0hXCxHJo4hPF
             L2mm9ciGpuXS7oN8f7YublNTwRY8b4plScVICpyBT5UDOgezR9/+DnklL0fz
             IORMTRnpD1hq4BqZMgNMwvczFg3DrSLQP/cBiKLn3toJrkSuU9aXodEqW3lh
             RdMvDUqTtHgMKas5velmabpENAbixiB8n5zoENnMLV6w/13a+yOTT2WUvESg
             HqF92FfQMdQl36noyewmjUFZopirCGV6AkebdVsTY27DtYkGWamLXcm3w2d6
             AYV/LssvyK/Jlnw/E7YRJWkO+8PvHA2tvfQSr8fNC4ll/KHdwr8d0Q8spPcO
             HMMui20XDYeprPmp64hSt4IBuiQusdm3SQsWjQvaUsg8sykZd24S/wNQiGsw
             XaoG6oWYYCZupfvGc0sgb+9qxZU5fSAYKwx5LjYajruvQ5flebAtrUdLuPbG
             Mb2I7Z8c4IvDmbA6ljqMK60w1XI+wU7jSWzoEaiIeAUR1aT925KFMEhmFG3k
             Tr5ZPI57wM7pEI9jBME80lu7D3f4z++icSHSJ5YNa/+kp7eSIT94m4Tj7nel
             mN0WnKFgzGZKnuiDGJew5FFnfB0qfvqUNUPt1rVaIr7rzBBL4j8WQHqOo17A
             +0pnIqKTe1Z8MxFnPwP1eWHa3T/7JeEPSD5JFOpEWxs12twxTC42BrTCckSm
             rfmksfxmJa0mfflaOPHkjahTprrItJzG1efHYCu5nP5rsclZF0hDOR1OZrgK
             2IhnG1VotIPB4+/+70+uD0qcqY3L2yonxFlQS8sEmMcXi9xQTxdFG4NOk/TQ
             G50Oly1tRp9UoLjwTDtlIjh71Lz9lajbAabV4WtIvd7cwaREO0kFAtzIgfJR
             VMasWvUo6e93qQBThzvkCNs8ngsa0jXJL1HrERP+qkiULCDMr19FVimWmIzL
             CkR9pg9WWjruY5krgdVbINUqjsyyGriPEhy2JneNWdOdFoAwkWtGbIpQhHs2
             bLHpG9xPPF+ElqLmjNa76BhXv4caurHYn7K0m4NMVgDywGXoh0OGe/PoXQ4g
             Ht7EbHgbCQO9V8+/1+MWw9ZrU6btOGJ2JVXeyRXYyJarn+cnPL1nWOlq7bMD
             3mazOTNZPc5UENSvDL51hmd3WD71i2u9btqIzjnmSxggPHRsVcOaGXHM3aUJ
             nrDtwi1EY7THlJatS+ItjWQMCDh8g/4LF9S2UWGFc21MimswWvgh1jB/4hYI
             9C8PSCpAeV26dXoANntR/lLms42488dVJ1wyNGjaNNX1itiqFYsNUn3LyT3T
             dVUgBwkfzO1I4UnhDIbsHJWbs7Dl/52Ei4MbpPJXnL1gMNc6SD1EkT1CeY9f
             esHF20wr8tb7V+qPO2TCE26syB9lZ41OSOYgqPYK/OHyoLedQmTOFls0QMj2
             F0bks3pJm/TDDMEuUdhulPatnZBNIXexqNImQUFyipcJ9W5KnD6Wr5+jyULy
             VBQRpWPzipfPFACb5d5lWPtrvh4kurYt3sSdUy+WJKuYb1roxXTZJqP0QDgn
             VEYL5nJnxqSRD9fx7HMRHXODkVioBFmSUgwP5XBljn/YpIgG8Ix42hyKMCti
             yv1gIY3/m8cfHyj5I6xcDHUTZHyM9+KSZeipf6wUnngoZuYzP9N3Nozo8LI+
             w3Mo6s/VjhmsALOYcus720s0MQY5prhkcZYUvgv9YL9R+1Fm7Kxy3cjpnGqy
             WwxN6YmNw/f6C+21Dlex7+09o2ygi0M1NEZZ0FhdaBmxVxtSjbBm3uKu9taW
             0zO534HXlifFkxf6GhboxbGdm1yekVIjDLnC+iodQyLwIi0vvc435Xk4GRBs
             8D5Pxf3vT3tgPy5sDXbJ3lT58MekKdT/HobugDOdu0ltGenFjnKFhdJudvQ/
             FFjqJk1HYnjxxdP3QYKlSHOv2ADtRqgI0VHLJmECOifYr90uWml1uzaUzK0X
             Tulm8fn6lfpF3EWJYSsq1iXQWuiRw9u6dxiS02+c4Z8Nzumoh48W+z0GFy+q
             ClyhqdedA6k3WZIJi919e5b24mj5rqzcgrA6KMqnTJDKh2cuoKC1fI88w774
             co0XPDyg+v/RD2ET1fquDGHjeVyVBsknNZQ5lwvLeAy/uH+Ql5qECQ9WCIJP
             ydZZhB906hkHZ+vch1fG+vhgMtoXhtZ4UXzQwbJBL/4wxtOau3IgWGkJEImJ
             PK3KE+7phfn5YmGSjVCp8o1t2QxpwJ1ZPBuTrUWy15gruIP8e415f0UPUZjF
             G+p6JqsUzaBzgZvAg9nY/vHEC0sXuC7lnqmDxr8LU9JMD77XrBccXMP199d/
             10bJW8TH+yzqE4syjdUPEalQnwP/fh9us92eSdv50vr0/KPhzfWzcRwWFxof
             S15zlJe3xNj+BAURHCApKjBkh5emuLy+w9zn6vn6/QsbXWp6hZWcoLO6ytLf
             6/H+DhguNzs/VFVbg5SXo62wztPoAAAAAAAAAAAAAA0jNEY= )
]]></artwork>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <section anchor="ml-dsa">
        <name>ML-DSA</name>
        <t>The security considerations of <xref target="FIPS204"/> apply.</t>
        <t>In particular sections 3.4 and 3.6 of <xref target="FIPS204"/> discuss additional
considerations for implementing ML-DSA, including guidance on the
choice of hedged vs deterministic variants. These considerations
apply when ML-DSA is used for DNSSEC and especially during online signing.</t>
      </section>
      <section anchor="downgrades">
        <name>Downgrades</name>
        <t>Section 5.11 of <xref target="RFC6840"/> recommends validators to accept any single
valid path. Such lenient validators are vulnerable to a downgrade attack:
if a zone is signed by ML-DSA-44 and a quantum-vulnerable algorithm,
then a quantum attacker can strip the ML-DSA-44 signatures, and have the
lenient validator accept the forged quantum-vulnerable signature.</t>
        <t>This does not apply if the lenient validator does not accept any
quantum-vulnerable algorithms or if the zone is only signed by ML-DSA-44.
A validator that insists on the presence of a valid ML-DSA-44 RRSIG
when the availability is advertised in the zones DS, also evades the
downgrade.</t>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document updates the IANA registry "Domain Name System Security
(DNSSEC) Algorithm Numbers".  The following entry is to be added to the
registry:</t>
      <table>
        <name>New DNSSEC Algorithm Number entry</name>
        <thead>
          <tr>
            <th align="left">Field</th>
            <th align="left">Value</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Number</td>
            <td align="left">TBD1</td>
          </tr>
          <tr>
            <td align="left">Description</td>
            <td align="left">ML-DSA-44</td>
          </tr>
          <tr>
            <td align="left">Mnemonic</td>
            <td align="left">MLDSA44</td>
          </tr>
          <tr>
            <td align="left">Zone Signing</td>
            <td align="left">Y</td>
          </tr>
          <tr>
            <td align="left">Trans. Sec.</td>
            <td align="left">*</td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Reference</td>
            <td align="left">(this document)</td>
          </tr>
        </tbody>
      </table>
      <t>* There has been no determination of standardization of the use of this
algorithm with Transaction Security.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC4033">
          <front>
            <title>DNS Security Introduction and Requirements</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>The Domain Name System Security Extensions (DNSSEC) add data origin authentication and data integrity to the Domain Name System. This document introduces these extensions and describes their capabilities and limitations. This document also discusses the services that the DNS security extensions do and do not provide. Last, this document describes the interrelationships between the documents that collectively describe DNSSEC. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4033"/>
          <seriesInfo name="DOI" value="10.17487/RFC4033"/>
        </reference>
        <reference anchor="RFC4034">
          <front>
            <title>Resource Records for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of resource records and protocol modifications that provide source authentication for the DNS. This document defines the public key (DNSKEY), delegation signer (DS), resource record digital signature (RRSIG), and authenticated denial of existence (NSEC) resource records. The purpose and format of each resource record is described in detail, and an example of each resource record is given.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4034"/>
          <seriesInfo name="DOI" value="10.17487/RFC4034"/>
        </reference>
        <reference anchor="RFC4035">
          <front>
            <title>Protocol Modifications for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of new resource records and protocol modifications that add data origin authentication and data integrity to the DNS. This document describes the DNSSEC protocol modifications. This document defines the concept of a signed zone, along with the requirements for serving and resolving by using DNSSEC. These techniques allow a security-aware resolver to authenticate both DNS resource records and authoritative DNS error indications.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4035"/>
          <seriesInfo name="DOI" value="10.17487/RFC4035"/>
        </reference>
        <reference anchor="FIPS204" target="https://doi.org/10.6028/NIST.FIPS.204">
          <front>
            <title>Module-Lattice-Based Digital Signature Standard</title>
            <author>
              <organization>National Institute of Standards and Technology (NIST)</organization>
            </author>
            <date year="2024" month="August"/>
          </front>
          <seriesInfo name="FIPS" value="PUB 204"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC6605">
          <front>
            <title>Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="W.C.A. Wijngaards" initials="W.C.A." surname="Wijngaards"/>
            <date month="April" year="2012"/>
            <abstract>
              <t>This document describes how to specify Elliptic Curve Digital Signature Algorithm (DSA) keys and signatures in DNS Security (DNSSEC). It lists curves of different sizes and uses the SHA-2 family of hashes for signatures. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6605"/>
          <seriesInfo name="DOI" value="10.17487/RFC6605"/>
        </reference>
        <reference anchor="RFC6840">
          <front>
            <title>Clarifications and Implementation Notes for DNS Security (DNSSEC)</title>
            <author fullname="S. Weiler" initials="S." role="editor" surname="Weiler"/>
            <author fullname="D. Blacka" initials="D." role="editor" surname="Blacka"/>
            <date month="February" year="2013"/>
            <abstract>
              <t>This document is a collection of technical clarifications to the DNS Security (DNSSEC) document set. It is meant to serve as a resource to implementors as well as a collection of DNSSEC errata that existed at the time of writing.</t>
              <t>This document updates the core DNSSEC documents (RFC 4033, RFC 4034, and RFC 4035) as well as the NSEC3 specification (RFC 5155). It also defines NSEC3 and SHA-2 (RFC 4509 and RFC 5702) as core parts of the DNSSEC specification.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6840"/>
          <seriesInfo name="DOI" value="10.17487/RFC6840"/>
        </reference>
      </references>
    </references>
    <?line 308?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>TODO</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA517256qSLrnvU/BrL6YWu3KFBBQ8rerd6sgooAoIsrMXHAG
5SQHEaurn2U/yzzZRIBmpq6s6t3jTUJAfId/fKcgvnx5eekUQRE6b8g3MbHL
0HkRjKIILAdhAi8ojBBRAi82ijJzkFHoJVlQ+BHiJhnCSIrCTr51DNPMnDOc
L7wwyujhmWUUDphTvyF5YXc6dmLFRgR42ZnhFi+VkxdOZhpG/GLHee5YL1Fo
58YL2u/kpRkFeR4kcVGnYALPbqaduIxMJ3vr2IDqW8dK4tyJ8zJ/Q4qsdDpA
hH7HyBwDiKI4Vgkkrb91qiQ7ellSpmCUSSIjiBEJiIAoNeAdIcvUyYwCsMm/
dY5ODd623zrIy00BeNVqBa/SJC9eTqURF2UE76e8rCA4SsDr/A5S3jk7cQnE
Q5D/JlsEaVX8pgFRg9hDODgPjoNpIRgH2CTp3wOncF+TzIMPjMzywQO/KNL8
rdeD78Gh4Oy83l/rwYGemSVV7vQaCj04EyypX5pgrnkDv/enSwGnhADtvPjE
7j71tSX2GiR/TuTPn776RRR+63SMsvCTDIIPeCJIEIN1Hb+yr4j2Pq954JZh
2BrR2MifHwLFjTi4NtC+IZMwKW0XQOM0D50WT9PI/269P3m1kujO84P0NyVJ
/QAsl+VHgdNg/kycSxIvfCCc5+3bf/eaRw3lTpxkEZhxbixiPZ0QaL//cUl8
XJLwEpoUsKi3huzXfvkC1HbsL7xTKYzYNjK7FfYdzub3AoUHpKRGeDCNj3NA
viwcJHHfZ+YI+ItsHMuPkzDxauQXiVc231uCjdMBc8eJF3TYjOROFjh5ELvJ
nQ0U/w2R1XHrFlAHI/McYDx327GToLFODH2lUHzYgwxe4bRXOKMDiT3iRVEo
eb8cEuhbp/P6+trpvLy8IIaZF5lhFZ3Oxg9yBASXMnLiArGd3MoC08kRP6mQ
IkHy1LECt0b+DMjOV2Hul9b5vyMgNLTgfPg5sFAYJZB7qOn80saM768IwhdI
mYNXCt+5xY8XgkBSIwPGBcwVIAeldIMY8Adk7oHktfPxMlDIdMLAOYNXgAqm
AyZZUDowEiOGByJKXiCGfXay3IDrAAmBCAXYwqjZActqIFZWp0XiZQYwZssI
wxrJnNA5gwiG3OIYAow0BWaQ3TCNAtsGVt35C7CQIgN4WdBgOp1Wtx9IBQj5
jXBZYtiA4Cc1fvvtZt+///7j/YaANwC5zn2AhAMNOg/SfUBs3yz7E9QAgDRL
zoHtNGECLDJQBwoGrRcuAjBOA+A+KbMMPARiQeQjEK8BJGkJ/PyDWse4L28D
GZAEhFMHWYPMBbnDidAoX1qjCYBqThgGKeCIAPzPTuedEvJOCWEnMPM1KkKD
/f13AOcoDOGMm0Af5D7xB6tRN/kScA2ydoWBKSFAMSiHD3wyBusJtQT3wDtA
NgXm4wKjByTaSASRMUOQU1oyyC+P4n4HeAJ3AGbXAS5ttOLepgDERv+OjYDV
B7ZnlkFYgLxahjY0SwNQapwsCc8OYiaFfxMXAHvjkyOO6wZW0CDRWkM7HbyV
OUB/5zMhcO85twT82QiAEiAE2UgFVAA0AEpup2XzgSiA/bffbkH099/fQb95
4n8rjnZ+dn8g8ocgCIjyDsjklZ/kzseSQZdoCLZr1/m8duGtonqHIwFeC8wT
inN/mIPFuBVQn1y/8//h+pCj0fl3XB9BPoPWejSELHOczkPQAin5PUL9uF9S
ZLOk99vh4PXngHyn6DT+1jotWN7/mSOM8gPeLNh9S2W9VngOyJonZWY5ncyx
EpiYflmv8+/t0v9JUH3HED5pU0/eeHPnfZ3uFSmCfwpm9yBmtDL+ckPoO4AI
OFMDKpAoyEGeBDLBjDkbveAk9cDPv83OIwA3KEu+TBqta9ywva33I8R3sSLj
CFe2+AhleQksFToJjBgQx6ANEwC+VxixJ0l8hqERVJUNWwZqFTT3cEUcKBBS
NXB+E1Vl8+1H+xeRls31ml2p/Jpl4DVQUBDeLzq3N5TZUhWYj6uPmZOlKLIS
004Go8jDUOebONp/axf421Le8EtpJHxr5f9sKDAQtxYPQ12WwrAFV6VzT+lN
nhlP5P/7XxgBjPZ/gHiLYxgNrLa9GWIDaMIwTrXckhhYfnsLoKo7Rpo6IBsA
KgYMz0YKnR9gDtYuB9VCjMCIBND86/+CyPyfN+Q/TCvFiL/dBqDCD4N3zB4G
G8x+HvlpcgviF0NfsHlH82H8CelHeUf7h/s77p8G/+M/Q2D3yAs2/M+/daAJ
tZ6IrG/uBy4a9wPJLP7sc6UZthkbgZsw4BeNYRsI1sfwl8QqQHlzNsLSgbCm
TRUBVs6sYbhuZnlOfNv/fMqhLf3XhVNzIMx9qitAhdW8Sr5iMOZ/ilVtqQUs
yImtxG7eBuYDucitiIAYAuI/SDWNfK16nXt0QdroAqWEAT5KgW+ZwONAWQn2
YbBKgdsxSM6sQaXcMIEjt3T8CYYH+7zLO3jF4auf5YUYtxHuX0D8kW4eEcYJ
HP0ThBu54Fwo5k/Qwhz3NbA/CQqB7XwF7EeZ/IFr/BS1P+Pa+bdx/aT7Z1g7
fwqr8hFiYRC5GRgMHiAIgETZll4fjL+l4N1v94x7BmkURPzOL8Gr8/oDiZM2
6oL48wKiun9/jszAzX1LcCtDwOYvLRo/KJzLXcXOL1ZxgUJenSxBQif2Cv97
E2S+MpS8WQAoKPna/9nCYeSOQGo3vBYaOLfNNLDqvW8O2gefOXQ+rXD/FXsd
Nu7zuTBvzPGj3JGazyvt95svs/LPNgtl+zCz9vsMECJPrOCjVvuU9j/tb+LP
TDo/p37knvqBspsxgzVIBLBm9gK472v0Avdw0/6+DencUiI/kkYwH+Zgy3D7
0AKLKHjRKM1eDGiVNw1ckOWTCpqG047/uKfWvKjDdot8A5J6h7Ct8380aQPm
2097tztyAfBaoAPQKE3ixsIZ5aZWC+u75zQFIbgTdx1Q6DSFzHvCBmv6Yc42
rBMikNbz4lbWuVkSNbL276E3dwAQbTa7qSFnwRlMf4+GP963Oh++Vn2OJO+O
0nlg+O4I70uJ/JLBAgdwBXYIUyq0eAeUajkMF0bjR50bqk1hCxz+BVjYS+P5
mdNyDEBVA1QeO5ZxM5RWtuuj0XS+qKh+tHEElN4U8XKPVk1obCNBlcGUb8ON
wZsBzeH3zt+Qv2pGBkPkX9+QDazUzg7cUOXtJjNvvpAAZKEo2PC+P/vJzl8R
LQhDQA24X5naj/Z+c4XGDgGxBJadcHfyz3/+s3NbjRegzUv7ueMNOWOv/Y+d
xxvkC3YfQG2C+N75WL43ZDRiJ6NqNR17Fj9ZJQIzQpfMZbRmfVGdrvc7bnw0
uEtlz/zhr5078vBT1CvSp1AU4aV7ksfJAdJvGN2+3tx+2GCBWqFyIqRiSpKi
pKQHpd7hMku6a2eOn5Pd6JhfzPSch3Ktr4vVmTMdwx4vB6fDIyU5ns5rVCjU
9TZd5uNxNy/3QUFhPY+w/QO7V3QNO+bLHRqES8HfkJPTSi0PXhToGftECb2K
mVBFlOHV5ZbdY1bByMKA1L18xBIEP+3tHTuoA1uUTth2k/GnbDwNyEU+zoRH
SomzFDdnXPYE3RSvqGyVW7sXz5bxmBpEfBxfNJarZOzqMclpIFPnfuGcZEFY
4uFm/UhpQR8k6eSI3Z2mLlEnQ0OKn+RrhdytStQ5rE+TjPJLbXXBDmOt3Cj+
CFfOCy6crOjRIyVF03a9hbsHmvU4/2yYqbo4pQdnHaszbLHBUnmsH319LzDb
mg4GRrDSMmk/jRk2mTxSsvvJlRDTOnRxedMz18liGRsMFtLurt/jGGN0oCbm
tKtM2WpC0xzFzrS9vZVPR9wdPlkBjuuTfjeNpbXRMwPGVOWj5qp71x3v16Q1
T8ZU5GFHrBuPuYnOSLLFUatxmSpUbj9S6h+5XKfyK2fXecKNeUzclMN44C/T
aodOl/KqGhaA1WS11b1+HMzcPb44z+bKcnd4wmlVrpIdKuo+d2HZaD4JcZ+t
VuTWoPhtYVg6qaOiUZ80lPT18aVnVXk/Vo/pYGCQ6iMlappfDsl2eegu6mG3
T9U7br2YWIuMnoVjtqI2dEbHPdE9znzhkJDT0F8vGIPe6+vZ5pESru+z+BQa
Q91BSffiDbNZMbUJSuvSbmD2Z7HOTmd6nkxLW05V9TKgK+scb1SF3/YeKa3x
s6TJvDXB1cGybxyJmRFt9aSaX/ztTtz3bF4zTlSp7Cqe2FsnEZUdCq/9Cx1j
20dKYoSh6loysCm94ChjzcllXS/E5WC+VAbX7s7izHlm72aseDk6F1VFfVfX
RGvsMtTqkVJPYUabyBaOrF8e+5MD541s8by+hiQ5H8eK4x7tXiLY04kchMOD
w7CZN5ybKHFYTKonSj17FlD0pLjo8cDI5i5rXBbaqqtxpDneJiK/DjlMlkod
Oxcax1DjSXLZ6V40PWKnR0rHg8toYbenbJVVamLS8BiQO/ZU2oSCjzXrop8u
k7WpoTm/8OJUPJDB0HNEra8T0lNUMZ3eTjqhlFQJalQF+/V8tNjvxWs4uLCc
KUpO6ng54Y6P6zV6kVam2hVPYT8TzIqKHyntTN3MSVInq1lsbF2HPgsg6MUM
F1vKAuNZYrCbcO40CS6bYjKcECNTjqhJX1p14ycbp9zVbi3i+6mJmjXPS8GA
PQzZbo6aHO7bmLG4lFLZk4vjVa+Gc833hM3lWEwEVjhQj5RKuicu6vX6cBDK
ZLHz6tVm4bPOaMIMB4wkrErBOOuDCtNIRR2F/Vm+cOTTiKAEs5c9UlI3C161
9zNPP6TKRl9nsd+tJqp7DMoDk9LrPr6IsNphr9e+Mt4cL3bRPcwXqnLWld0j
pcnBtKWFqp44Zz1c5vhwvDYnRnEEaWQxuizrSGONhX/hg/U+BpEpSS7T0V5I
2RXqF4+U6LUaJBbF51U0rXyTIEt0d7C3cV4pHiZmgxO/CDxUuDjpKTBKTSoO
I1BTV9iBprUnK2Boe39aJdv4PKeSa7pbJLKk2sKkd5JFMgkn2ca91hPmnAzO
5/F4S+x7vtpngEvtp4+U9MLrDbnc504DVl4szK14XTGEt02OujMU1uHUunRX
rqhsqvjc6y83QPM9KA1VzRg9ZalrCBZic5jrBF1TFbkkXfxERrjr7+Rh2LtM
irnmKr0An+18Rk6MSsSw8qjPWFyg+UdKzvU4rVYHGTtVx1yk+n3BlVXXl5jC
mJVbqswt9VpxQymsePp4svj5XhpoZpoX9CZ8pGRUp1nlLblFebhOzVSfO4di
QOmklCbBKNZ91Z2ewrDres41NsVxVWz9lJTKnS8On3Cqmcl1PqkZ1vv1V+T7
H1UpCkLSQ5yGFQr+XKMMMdwyMQPHDRcl+kPUwd0BbtOYhVIWRjjgEY0NLbeP
ov2BMTRoixoQ9MChcYowHykRpmv8oQziDsHQ5hj29fPzP3i7LeXhHChxM/pc
WhEEiuIYfIIBsXF0gIPLVs0HBg+zjnatzK7VeCC5xWGljKaDPJ44C6PsS8kp
FSQPo/yeM9O3Q6Gvp0EfDY/rOlCIqSCKTwZ62hyupouNeqbie8RJT/dh7J52
0rA8TbUpzbHsfOkVDjaZ2lOCm6Ckx47V4XCR1e4jpZgbWcBTDLei/YK56Nkp
Om0VTepiXqkNZrWqThOML7VNrC9KX08LZn48dcWwS+qzJ2Mg0i6+savjUJwN
inm42R976tYQsYrfyWN878273SODXv06J63+MLsWlrGMxF1BOU/lZj1i9/0B
Y2F6b5Fn65Wunbs7vTfZhEHpd21uPku4chORi0pBy3w4JMqjJk16Fa/2lKcy
KuSSMbPd5RuM6m8yKty4w3ROXIKLteClYZwvlOlFpg/dkWlIpJK4/OicEgLH
TwXvKRUv8vW2Z52cfTKUHW/L4Kw/WuG92Xaz7JfL4Tk8CYtBrG23C7yLG/sF
L+Ds6Xrw1/vFUxAmGV+sFFr3TA4F27Ert0vPuiVZy3o03tW5vS0N5hCrpRHt
t6PJUs22gyElSFExfAoJGhPvtESWRTaTj+RZqmcnqqvPvAGtOnqqXC/oyOlh
Bu8GuMYWBr3MyJzji3FMnZ8cWQvo43xd+iXI3zuXngjjbU+YCT2Zd+LxZafE
Gb6sPJIYlYqEF9ERD5l6OHYX1+v58khpswQp6kI4dkJTuzO10kYKyAf0PKrZ
sx9PQV7hqRnXd2O8exxm3lzgZ2meEanui/6TQ/eUlWYkh0tBYjHLTwPMDEEh
n4+iiS3KQ0xQpAsoEPnjwpKdZb8PyvKtwiwH3HX5VB7k8Xh5NX11R3vmNOsb
0ranZWbes3RxJGA8yi84HD0cI9bVadlZSKi/m1xm84Tw5SecBDyKaCvg0nKn
DBJp6A72pRlKm2q9H5pEGirWlp+k9XhDqswSxM813esy8TEUUPf6SIlfrsXN
Ok4ZzD8R45MuepJYna3r1OszmSKs5J41DhZC3C+SeXZUSpU2donNnrR++ITT
GhRyjHraFDNPXBg5eXbCCOw8WGlkBpdgPIzJa8JKsShsqaqH9Y1uvdxscE09
s8qTjc9OUxqfuivRXoV9Kk5qp4oO6lRP0iCbcFtqdHRMe5tv9viAKfZHTjMi
YWdF/Qq3n0qW0R7YT56f60VvHsZVjx2Amkw7LrtD+Twb4cXZXSnZ0JUmRBj2
FjO7yoY2uhrmqWwtn2QSxTLA0R2zd9JMjlKK8JWC4MdlsCpzO+orq1w7rM6G
mnvDvD7qNk4ovUpaBVz+VLjujISjEm2/n+hl6p45C809s0ufLrpKuspov6gu
pHDYG4esPK9IN3TMUZGB8qGUTe4pFpg4P9CHFsGfmcgcUeHhJC4otMJ2fLdS
BwdFA4gbAe+M1DVmbGicXExF1o+mXP/45C0Zqcs8OajEQcry9GEsskM0LAdM
3yWu3W5gKTNlTu4lo9cF2x9H4Tc0ERGbwyB2npJ6JKFavJh6V05fxGXAcHOn
IqfT2B2jJ/d8UiVVLrBsa/DZILuOxwJxGGqr2WmZYIOnwrWLpjF/WmwcTB+K
l2ksg120o82M/qY3mDusrDDkfLpMWe2SY3hRXTYTAh9nm4l1VKJHSpkbHXP3
Es0NNHLd0FjKs+PB8DdplvHF/MphjjvbT0oylskst0J9ivrMco0t9cx7ipk4
78cctk0KXh4T3V53gHZLBj1Zp31fwOskvkzDlTLM2Ui0dgF9WW0u9pQjpOWx
t3naCHEkugxrrFintJoIh2rDFCF/8AeYcKVD42CODHNLaAV/tgdWZazZJXqc
joor77nzp88GW9HItbOaUA7dP63GG/96Pk6kfBh7uYEednMBm2XsWu6ejoEq
TBgxw+jpNoi0iL8+FYmT45pOPVrTgOntyWPm2VuTl9TTIa9rLgtk1q/xeexI
mr20p8moOmoFZ/Lpyp/l+FMJLMxSjr7I8rTLgoQUHSRjQI393ZmwjDKb7ePB
Ao0ISdx6TF1xu8RHl5zTk5PdiniOBcWANWeeOVkt6e2w28O6olbReqZSZrHk
5vh8u3Pq9W5fz40s7lqxLGCxtgxPA1Nknj4bRMZ1uZF02SJVVlLOjEBifmT3
NWaABXhJm8WJvx7iSLl4njxb51traXC7mdg31PlTrZIxRRVg7H6wmYVzo1C6
fHHQVuKE8YdejxCmtIKrGje1cEwMorzSzp6PHcY9wt8/ZU56MpSVSTpytjhl
75KRFBfrXihEOYETw6G9nWNVLXEHQ5J2WFAEp+k+l9S4L9Sb/tNnA3ureuPq
6F6XGE+osc/wZj6ba2Y+YMIeibMBIZqpPN/FAuaJkkUpDMYeN9jE2dNPlZiT
z6Y4CiJhYQ623ZO8xDcTFqfyekyHOoEtleXeO8n7RW85qxPBsVfRZjkNc3Ql
Hp6sYIqax7yfzqPehmFEtlRtvwxlo4j1scTvnMtJ4qOVOq2D1JrTGrmIGUrL
yO6hVoX6ycbHq3WqydcgdeXpaGKSNhlqcpGdfeJYZvuinyu2Wne1+aLcm1gG
dvobfX6S0RXjPW2st+xeION5fDkpa4Z2L4OZuJ7tlsxxGyTjaaSoXiWTu3F4
iHv7lPe4IX8hcL9eiJMieKoOz5jH7/u9COwLZvWB5KmLxczUjT6rRbq7UHQH
SEtVahx7iV7urzItgfr6mgwFvvtIqeqLCZX3tgc/ykfCcm+VOajjc1Rc7ck0
84+WvlfP3pneC/S6i02jweJS961DGnOnJ5y06iJR+0iqei416eIYEzqXQRel
E7z2AlTEJFbX0alvG+Posr0UysEcR/1yUdKF8bSJRa9Lsk/MdmHgTo8Xl+J8
M7mYnA335cctf2CEeNINEntVCxUfoOezRfTJ3ZHg1uP8aWvFkPLF7Z83/cKT
azJndua8H27IoegcF/amN0vM0mOWdomGBefE0wNIH749L+3z6umD1nR6OM2P
GAgfh8vFlvur/SJUZsszPmKK9cnj0e1MmEfsZBm4+4xGSy0KsfJqqNcF+vTZ
YFOG0dCNqdBNp31Wm++V/IQFu5VWBuuKLin7Eigo3rUIfShdyyjxiaHWvaLc
tO4+fTyahLV/sh17RB37ms7PAxqjHdLEiehAZqer5WUjaiGe4s2cWfi4VSaL
Cebyw2E1GBCPlKwE3clM7XXPvTWo6jeYeyoZbnZwtvV2nB9jSV+RYXUWnFHd
K2fdVUie2MmK1ib8XH6yTFvX/TGNUv5xpnfPlo+5XPfse2KR7PxCJ9TddVWZ
87HQI6pLsQT7Pt7TuOOc5aOnSCcv+gu2O0h9Nyb3EacctpN0mGAFvrqk1RzT
5XG5yVStxkgvK3l56BAY6aKqrOqHp4qV66bU/JSrV2N89fTzyKPjfe88Yydo
visngzA+RcwlGwoqPReZwWCXjS1rJ8oYTdtPVoCh5lwbbmbd+npiibw+2KrM
GuEqruSe69NlTuOOYp9J9JyhvYXsX13taq0rbXpJniKdgpHXcO70L9KhOwY1
0mwySheH8dEnnagU6m5FX8EWJaZ6q9zcaSnl65qVCEuqLoQnSlRv1mV8r5Su
wI2nW9MjlV1C4dW1kJPRww89SOwefqSABzedv7x3ez4dLoJHf7l3isODu492
o8czyMdza8RI07B+7XT4GDYBFYHVtirej4X7r0Rz2tV/pZ5nwqa+Ms8Rw7aD
tqW388QKHls1R++wswae5rXiwaNNKyyb00ivDGzY0XTvWbP8BLapAVa+Y3vw
HC1Hvjz/y1/h8WTuPKnXafRpuwQ/etlK2BX38U8BjUZO05nXnLLZZdac/cdN
K8qtd+G1AZRJqtjLDBue035qAvk4xoYdwQAMeKQaATXtHJ78AZ2awzx4IGlZ
Tlo0zYLwQDN0Os1zAHbhvyJKafnwcB72JX6eCI8Nz2UIj1xvLYkGYt9FQYyi
MKzjWyeA7RjXJG6ONW/H72b96YS7OeC9N9u9fCL4fpD4AzbExB8v3Wg7GWIZ
cdNKkD51u30+94T0fePsNEv3kxp33YvmfDuDq/mFKO/0Pnr2nLzpf2iXMmhP
Yn+m/vHeO8SdP1M1h+2pN2p30JrerC+Qe+2MPnFqTpGDew9MfG/MyJ24NVWj
ffcTSM13uE5jhc257Rn+e4QZhLc2zaZxsgjytgfjLlDbiWiEeYI4Z2hy7en3
fdmbroEvugqeWx3bg+D8ownh1q5Qf/lvID/1jv/UjZF/u7UCfOpRiCG5IL91
foAI0LaIQ3nv3N46nX8g06ZB5w9//0C2TQfRp5HOP17+xe/nF8Cke+fIH3OC
DRwPI2AS0zSqpI1XfznpY0U/JomxEyUxiER/xOl2aP7ASYcGp9y6or6atH8e
AZM2mRGDOAeW6PVrTv/7rz9PUnPnc6h75gnEG+3/1aRta/rvsHw9ib+H9q/5
/RuTPvh9PWntuE7WeNuXv38gvzw0cX4Hk357a/955ddvklPd+fzUaNQY8rff
Ox2A5Ab2XTYttKYD/DZO3hPPe59/fvsvlXvf+61L5L1hJMg/WvvbRoxmCY02
b9xd7fZ/DiaIs033k3WMkyoE6Q7KngPJ284Nx/71mwuigQPl2yyZZef/AQwE
mxIqNwAA

-->

</rfc>
