<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-westerbaan-dnssec-mldsa-04" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="ML-DSA for DNSSEC">Module-Lattice Digital Signature Algorithm for DNSSEC</title>
    <seriesInfo name="Internet-Draft" value="draft-westerbaan-dnssec-mldsa-04"/>
    <author initials="B. E." surname="Westerbaan" fullname="Bas Westerbaan">
      <organization>Cloudflare</organization>
      <address>
        <email>bas@cloudflare.com</email>
      </address>
    </author>
    <author fullname="Sophie Schmieg">
      <organization>Google</organization>
      <address>
        <email>sschmieg@google.com</email>
      </address>
    </author>
    <date year="2026" month="August" day="11"/>
    <area>Security</area>
    <workgroup>Domain Name System Operations</workgroup>
    <keyword>DNSSEC</keyword>
    <keyword>ML-DSA</keyword>
    <keyword>post-quantum</keyword>
    <keyword>FIPS 204</keyword>
    <keyword>signatures</keyword>
    <abstract>
      <?line 58?>

<t>This document describes how to specify Module-Lattice-Based Digital
Signature Algorithm (ML-DSA) keys and signatures in DNS Security
(DNSSEC).  It uses the ML-DSA-44 parameter set defined in FIPS 204.
ML-DSA-44 is believed to be secure even against adversaries in possession
of a cryptographically relevant quantum computer.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://bwesterb.github.io/draft-westerbaan-dnssec-mldsa/draft-westerbaan-dnssec-mldsa.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-westerbaan-dnssec-mldsa/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Domain Name System Operations Working Group mailing list (<eref target="mailto:dnsop@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/dnsop/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/dnsop/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/bwesterb/draft-westerbaan-dnssec-mldsa"/>.</t>
    </note>
  </front>
  <middle>
    <?line 66?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>DNSSEC, which is broadly defined in <xref target="RFC4033"/>, <xref target="RFC4034"/>, and
<xref target="RFC4035"/>, uses cryptographic keys and digital signatures to provide
authentication of DNS data.  Currently the most popular signature
algorithms in use are RSA and the NIST-specified elliptic curve
signature algorithm ECDSA <xref target="RFC6605"/>.</t>
      <t>All currently specified algorithms rely for their security on the hardness of the
integer factorization problem or the (elliptic curve) discrete
logarithm problem.  A cryptographically relevant quantum computer when built
would be able to solve both of these problems efficiently, and
would therefore be able to forge DNSSEC signatures created with any of
these algorithms.</t>
      <t><xref target="FIPS204"/> specifies the Module-Lattice-Based Digital Signature
Algorithm (ML-DSA), a signature scheme whose security is based on the
hardness of lattice problems over module lattices.  ML-DSA is believed
to be secure even against adversaries in possession of a
cryptographically relevant quantum computer.  <xref target="FIPS204"/> defines three
parameter sets: ML-DSA-44, ML-DSA-65, and ML-DSA-87.</t>
      <t>This document defines the use of DNSSEC's DS, DNSKEY, and RRSIG resource
records (RRs) with the ML-DSA-44 parameter set.  ML-DSA-44 targets NIST
security category 2, which is defined as the (quantum) collision resistance
of SHA-256.  ML-DSA-44 has the smallest keys and signatures of the three
ML-DSA parameter sets, which makes it the most suitable for use in the DNS.</t>
      <aside>
        <t><em>Note</em>: The codepoint assigned by IANA refers to version 03 of this document.
The present version of the document is compatible: it defines
the same codepoint.</t>
      </aside>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="dnskey-resource-records">
      <name>DNSKEY Resource Records</name>
      <t>An ML-DSA-44 public key consists of a 1312-octet value as produced by
the key generation algorithm ML-DSA.KeyGen defined in Section 5.1 of
<xref target="FIPS204"/>.  It is encoded into the Public Key field of a DNSKEY
resource record as a simple bit string, using the byte encoding of the
public key described in Section 7.2 of <xref target="FIPS204"/>.</t>
    </section>
    <section anchor="rrsig-resource-records">
      <name>RRSIG Resource Records</name>
      <t>An ML-DSA-44 signature consists of a 2420-octet value as produced by the
signing algorithm ML-DSA.Sign defined in Section 5.2 of <xref target="FIPS204"/>.  It
is encoded into the Signature field of an RRSIG resource record as a
simple bit string, using the byte encoding of the signature described in
Section 7.2 of <xref target="FIPS204"/>.</t>
      <t>Signatures are generated and verified using the "pure" ML-DSA variant
(i.e., not the pre-hash variant HashML-DSA) with an empty context string
(ctx of zero length), as described in Sections 5.2 and 5.3 of
<xref target="FIPS204"/>.  The message signed is the data to be signed as described
in Section 3.1.8.1 of <xref target="RFC4034"/>.</t>
    </section>
    <section anchor="algorithm-number-for-ds-dnskey-and-rrsig-resource-records">
      <name>Algorithm Number for DS, DNSKEY, and RRSIG Resource Records</name>
      <t>The algorithm number associated with the use of ML-DSA-44 in DS, DNSKEY,
and RRSIG resource records is 18.  This registration is fully defined
in the IANA Considerations section.</t>
    </section>
    <section anchor="examples">
      <name>Examples</name>
      <t>The following example, in the style of Section 6 of <xref target="RFC6605"/>, shows an
ML-DSA-44 DNSKEY, its corresponding DS record, and an RRSIG over an MX
RRset.  The key was generated deterministically from the 32-octet seed
shown in the PrivateKey field, and the signature was produced using the
deterministic variant of ML-DSA (rnd set to all zeroes) so that the
example is byte-for-byte reproducible.  Because of the size of ML-DSA-44
keys and signatures, the base64-encoded values are wrapped.</t>
      <artwork><![CDATA[
Private-key-format: v1.3
Algorithm: 18 (MLDSA44)
PrivateKey: AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8=

example.com. 3600 IN DNSKEY 257 3 18 (
             17K0clSq4NtF55MNSpjSyX2PE5fReJ2voXAksxbpvslPyZRtQvGbeadBO7qj
             PnFJy0LtURVpOsBB+suYit61/g4dhjEYSZW1ksOX0ilOLhT5CqQUujgmiZrE
             P0zMrLwm6agyuVEY1ctDPL75ZgsAE44IF/YediyidMNq1VTrIqrBFi5KsBrL
             oeOMTv2PgLZbMz0PcuVd/nHOnB67mInnxWEGwP1zgDoq7P6v3teqPLLO2lTR
             K9jNNqeM+XWUO0er0l6ICsRS5XQu0ejRqCr6huWQx1jBWuTShA2SvKGlCQ9A
             SWWX/KfYuVE/GhvabpUKqpjeRnUH1KT1pPBZkhZYLDVy9i7aiQWrNYFnDEoC
             d3oz4Mpylf2PT/bRoKOnaD1l9fX3/GDaAj6CbF+SFEwC99G6EHWYdVPqk2f8
             122ZC3+pnNRa/biDbUPkWfUYffBYR5cJoB6mg1k1+nBGCZDNPcG6QBupS6sd
             3kGsZ6szGdysoGBI1MTu8n7hOpwX0FOPQw8tZC3CQVZg3niHfY2KvHJSOXjA
             QuQoX0MZhGxEEmJCl2hEwQ5Va6IVtacZ5Z0MayqW05hZBx/cws3nUkp77a5U
             6FsxjoVOj+Ky8+36yXGRKCcKr9HlBEw6T9r9n/MfkHhLjo5FlhRKDa9YZRHT
             2ZYrnqla8Ze05fxg8rHtFd46W+9fib3HnZEFHZsoFudPpUUx79wcvnTUSIV/
             R2vNWPIcC2U7O3ak4HamVZowJxhVXMY/dIWaq6uSXwI4YcqM0Pe62yhx9n1V
             Mm10URNa1F9KG6aRGPuyyKMO7JOS7z+XcGbJrdXHEMxkexUU0hfZWMcBfD6Q
             /SDATmdLkEhuk3CjGgAdMvRzl55JBnSefkd/oLdFCPil8jeDErg8Jb04jKCw
             //dHi69CtxZn7arJfEaxKWQ+WG5bBVoMIRlG1PNuZ1vtWGD6BCoxXZgmFk1q
             kjfDWl+/SVSQpb1N8ki5XEqud4S2BWcxZqxCRbW0sIKgnpMj5i8geMW3Z4NE
             be/XNq06NwLUmwiYRJAKYYMzl7xEGbMNepegs4fBkRR0xNQbU+Mql3rLbw6n
             XbZbs55Z5wHnaVfe9vLURVnDGncSK1IE47XCGfFoixTtC8C4AbPm6C3NQ+nA
             6fQXRM2YFb0byIINi7Ej8E+s0bG2hd1aKxuNu/PtkzZw8JWhgLTxktCLELj6
             u9/MKyRRjjLuoKXgyQTKhEeACD87DNLQuLavZ7w1W5SUAl3HsKePqA46Lb/r
             UTKIUdYHgZjpSTZRrnh+wCUfkiujDp9R32Km1yeEzz3SBTkxdt+jJKUSvZSX
             CjbdNKUUqGeR8Os28BRbCatkZRtKAxOymWEaKhxIiRYnWYdooxFAYLpEQ0ht
             9RUioc6IswmFwhb45u0XjdVnswSg1Mr7qIKig0LxepqiauWNtjAIPSw1j99W
             bD9dYqQoVnvJ6ozpXKoPNUdLC/qPM5olCrTfzyCDvo7vvBBV4Y/hU3DuyyYF
             Ztg/8GshGq7EPKKbVMzQD4gVokZe8LRlFcx+QfMSTwnv/3OTCatYspoUWaAL
             zlA46TjJZ49y6w5O5f2q5m2fhXP8l/xCtJWfS/i2HXhDPoawM11ukZHE2L9I
             ezkFwQjP1qwksM633LfPUfhNDtaHuV6uscUzwG8NlwI9kqcIJYN7Wbpst9Tl
             awqHwgOGKujzFbpZJejt76Z5NpoiAnZhUfFqll+fgeznbMBwtVhp5NuXhM8F
             yDCzJCyDEg== )

example.com. 3600 IN DS 59829 18 2 (
             812cb1a22af04380e2f72d91c06c14eb1a918cf30037a8a9c67497e9264b
             4bfa )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 18 2 3600 (
             1440021600 1438207200 59829 example.com.
             kdySHzwB7NftjQSAF7snCeKau3NoqpLNg16h/eHZV8L3Zpi30lkRyiS4FLMM
             ZqTjzbf1A/bShg4qZpYlnfqXN8uqFWF9GEEJOgte1CFdF4GC05gEBU88Kryf
             nGAcpXKafw9htDxZrqmqVSWN+1guW7HyUUFo1IuWTnZKuhZptDJkq+Ml+5ZH
             y4p+2Tdwk8MH7tJlTYk/UVaM1wIXPB2YgJ++kD0zhys5c38rztcaOmMXt6ej
             yAEY37Dc1Z/KsrRQZWv+XZ/CTliuh+dGJHoGuTm5KwS0us884ukWNC/wIU/S
             dlGoBDVXsT163Tr6lTf8pJ4xixcKIN8nsKSFxP9j+AbaN5SofIAvp4LGIFLg
             MKsRV/cqeYo8PegVD2EhAQ2/HVTO3uO8vlqLK7nWVVK2+2aYKIL2EqzjhRYK
             U5DhMwS9ZgbG0niszGXpvZcNcOyABXysdVuaDjnUuamYVACOUrV786LNmt8I
             WDnXWoPPMErPk5vNyHq6+ZHg79UeZpSzx0Ae/1aIfi2WEta9Or5sGItBn6vF
             Wi9kJRuhuoMIXf9CLBV/LHL/PIenBxXSnr2Owg54AuSN2tmk2lDy8BfKzzvx
             TOoKXx4edo96Xv6QWASAxO9JmyEvhnF3SBI6HG3fn2+k8rgJLIHpsr4pZhMh
             4/SQWaojxt51nEIFi1bl7P6sAmCdMP81LSNx05hIkKcPeO33hA2VSDO7GzOE
             snBOzbhUX9gbFr3aNV/Wrbs/cZMAL1I0IKG20jkmEfZ9PeKN0hXCxHJo4hPF
             L2mm9ciGpuXS7oN8f7YublNTwRY8b4plScVICpyBT5UDOgezR9/+DnklL0fz
             IORMTRnpD1hq4BqZMgNMwvczFg3DrSLQP/cBiKLn3toJrkSuU9aXodEqW3lh
             RdMvDUqTtHgMKas5velmabpENAbixiB8n5zoENnMLV6w/13a+yOTT2WUvESg
             HqF92FfQMdQl36noyewmjUFZopirCGV6AkebdVsTY27DtYkGWamLXcm3w2d6
             AYV/LssvyK/Jlnw/E7YRJWkO+8PvHA2tvfQSr8fNC4ll/KHdwr8d0Q8spPcO
             HMMui20XDYeprPmp64hSt4IBuiQusdm3SQsWjQvaUsg8sykZd24S/wNQiGsw
             XaoG6oWYYCZupfvGc0sgb+9qxZU5fSAYKwx5LjYajruvQ5flebAtrUdLuPbG
             Mb2I7Z8c4IvDmbA6ljqMK60w1XI+wU7jSWzoEaiIeAUR1aT925KFMEhmFG3k
             Tr5ZPI57wM7pEI9jBME80lu7D3f4z++icSHSJ5YNa/+kp7eSIT94m4Tj7nel
             mN0WnKFgzGZKnuiDGJew5FFnfB0qfvqUNUPt1rVaIr7rzBBL4j8WQHqOo17A
             +0pnIqKTe1Z8MxFnPwP1eWHa3T/7JeEPSD5JFOpEWxs12twxTC42BrTCckSm
             rfmksfxmJa0mfflaOPHkjahTprrItJzG1efHYCu5nP5rsclZF0hDOR1OZrgK
             2IhnG1VotIPB4+/+70+uD0qcqY3L2yonxFlQS8sEmMcXi9xQTxdFG4NOk/TQ
             G50Oly1tRp9UoLjwTDtlIjh71Lz9lajbAabV4WtIvd7cwaREO0kFAtzIgfJR
             VMasWvUo6e93qQBThzvkCNs8ngsa0jXJL1HrERP+qkiULCDMr19FVimWmIzL
             CkR9pg9WWjruY5krgdVbINUqjsyyGriPEhy2JneNWdOdFoAwkWtGbIpQhHs2
             bLHpG9xPPF+ElqLmjNa76BhXv4caurHYn7K0m4NMVgDywGXoh0OGe/PoXQ4g
             Ht7EbHgbCQO9V8+/1+MWw9ZrU6btOGJ2JVXeyRXYyJarn+cnPL1nWOlq7bMD
             3mazOTNZPc5UENSvDL51hmd3WD71i2u9btqIzjnmSxggPHRsVcOaGXHM3aUJ
             nrDtwi1EY7THlJatS+ItjWQMCDh8g/4LF9S2UWGFc21MimswWvgh1jB/4hYI
             9C8PSCpAeV26dXoANntR/lLms42488dVJ1wyNGjaNNX1itiqFYsNUn3LyT3T
             dVUgBwkfzO1I4UnhDIbsHJWbs7Dl/52Ei4MbpPJXnL1gMNc6SD1EkT1CeY9f
             esHF20wr8tb7V+qPO2TCE26syB9lZ41OSOYgqPYK/OHyoLedQmTOFls0QMj2
             F0bks3pJm/TDDMEuUdhulPatnZBNIXexqNImQUFyipcJ9W5KnD6Wr5+jyULy
             VBQRpWPzipfPFACb5d5lWPtrvh4kurYt3sSdUy+WJKuYb1roxXTZJqP0QDgn
             VEYL5nJnxqSRD9fx7HMRHXODkVioBFmSUgwP5XBljn/YpIgG8Ix42hyKMCti
             yv1gIY3/m8cfHyj5I6xcDHUTZHyM9+KSZeipf6wUnngoZuYzP9N3Nozo8LI+
             w3Mo6s/VjhmsALOYcus720s0MQY5prhkcZYUvgv9YL9R+1Fm7Kxy3cjpnGqy
             WwxN6YmNw/f6C+21Dlex7+09o2ygi0M1NEZZ0FhdaBmxVxtSjbBm3uKu9taW
             0zO534HXlifFkxf6GhboxbGdm1yekVIjDLnC+iodQyLwIi0vvc435Xk4GRBs
             8D5Pxf3vT3tgPy5sDXbJ3lT58MekKdT/HobugDOdu0ltGenFjnKFhdJudvQ/
             FFjqJk1HYnjxxdP3QYKlSHOv2ADtRqgI0VHLJmECOifYr90uWml1uzaUzK0X
             Tulm8fn6lfpF3EWJYSsq1iXQWuiRw9u6dxiS02+c4Z8Nzumoh48W+z0GFy+q
             ClyhqdedA6k3WZIJi919e5b24mj5rqzcgrA6KMqnTJDKh2cuoKC1fI88w774
             co0XPDyg+v/RD2ET1fquDGHjeVyVBsknNZQ5lwvLeAy/uH+Ql5qECQ9WCIJP
             ydZZhB906hkHZ+vch1fG+vhgMtoXhtZ4UXzQwbJBL/4wxtOau3IgWGkJEImJ
             PK3KE+7phfn5YmGSjVCp8o1t2QxpwJ1ZPBuTrUWy15gruIP8e415f0UPUZjF
             G+p6JqsUzaBzgZvAg9nY/vHEC0sXuC7lnqmDxr8LU9JMD77XrBccXMP199d/
             10bJW8TH+yzqE4syjdUPEalQnwP/fh9us92eSdv50vr0/KPhzfWzcRwWFxof
             S15zlJe3xNj+BAURHCApKjBkh5emuLy+w9zn6vn6/QsbXWp6hZWcoLO6ytLf
             6/H+DhguNzs/VFVbg5SXo62wztPoAAAAAAAAAAAAAA0jNEY= )
]]></artwork>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <section anchor="ml-dsa">
        <name>ML-DSA</name>
        <t>The security considerations of <xref target="FIPS204"/> apply.</t>
        <t>In particular sections 3.4 and 3.6 of <xref target="FIPS204"/> discuss additional
considerations for implementing ML-DSA, including guidance on the
choice of hedged vs deterministic variants. These considerations
apply when ML-DSA is used for DNSSEC and especially during online signing.</t>
      </section>
      <section anchor="downgrades">
        <name>Downgrades</name>
        <t>Section 5.11 of <xref target="RFC6840"/> recommends validators to accept any single
valid path. Such lenient validators are vulnerable to a downgrade attack:
if a zone is signed by ML-DSA-44 and a quantum-vulnerable algorithm,
then a quantum attacker can strip the ML-DSA-44 signatures, and have the
lenient validator accept the forged quantum-vulnerable signature.</t>
        <t>This does not apply if the lenient validator does not accept any
quantum-vulnerable algorithms or if the zone is only signed by ML-DSA-44.
A validator that insists on the presence of a valid ML-DSA-44 RRSIG
when the availability is advertised in the zones DS, also evades the
downgrade.</t>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>IANA has added the following entry to the "Domain Name System Security (DNSSEC)
Algorithm Numbers" registry.</t>
      <table>
        <name>New DNSSEC Algorithm Number entry</name>
        <thead>
          <tr>
            <th align="left">Field</th>
            <th align="left">Value</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Number</td>
            <td align="left">18</td>
          </tr>
          <tr>
            <td align="left">Description</td>
            <td align="left">ML-DSA-44</td>
          </tr>
          <tr>
            <td align="left">Mnemonic</td>
            <td align="left">MLDSA44</td>
          </tr>
          <tr>
            <td align="left">Zone Signing</td>
            <td align="left">Y</td>
          </tr>
          <tr>
            <td align="left">Trans. Sec.</td>
            <td align="left">*</td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Reference</td>
            <td align="left">draft-westerbaan-dnssec-mldsa-03</td>
          </tr>
        </tbody>
      </table>
      <t>* There has been no determination of standardization of the use of this
algorithm with Transaction Security.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC4033">
          <front>
            <title>DNS Security Introduction and Requirements</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>The Domain Name System Security Extensions (DNSSEC) add data origin authentication and data integrity to the Domain Name System. This document introduces these extensions and describes their capabilities and limitations. This document also discusses the services that the DNS security extensions do and do not provide. Last, this document describes the interrelationships between the documents that collectively describe DNSSEC. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4033"/>
          <seriesInfo name="DOI" value="10.17487/RFC4033"/>
        </reference>
        <reference anchor="RFC4034">
          <front>
            <title>Resource Records for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of resource records and protocol modifications that provide source authentication for the DNS. This document defines the public key (DNSKEY), delegation signer (DS), resource record digital signature (RRSIG), and authenticated denial of existence (NSEC) resource records. The purpose and format of each resource record is described in detail, and an example of each resource record is given.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4034"/>
          <seriesInfo name="DOI" value="10.17487/RFC4034"/>
        </reference>
        <reference anchor="RFC4035">
          <front>
            <title>Protocol Modifications for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of new resource records and protocol modifications that add data origin authentication and data integrity to the DNS. This document describes the DNSSEC protocol modifications. This document defines the concept of a signed zone, along with the requirements for serving and resolving by using DNSSEC. These techniques allow a security-aware resolver to authenticate both DNS resource records and authoritative DNS error indications.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4035"/>
          <seriesInfo name="DOI" value="10.17487/RFC4035"/>
        </reference>
        <reference anchor="FIPS204" target="https://doi.org/10.6028/NIST.FIPS.204">
          <front>
            <title>Module-Lattice-Based Digital Signature Standard</title>
            <author>
              <organization>National Institute of Standards and Technology (NIST)</organization>
            </author>
            <date year="2024" month="August"/>
          </front>
          <seriesInfo name="FIPS" value="PUB 204"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC6605">
          <front>
            <title>Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="W.C.A. Wijngaards" initials="W.C.A." surname="Wijngaards"/>
            <date month="April" year="2012"/>
            <abstract>
              <t>This document describes how to specify Elliptic Curve Digital Signature Algorithm (DSA) keys and signatures in DNS Security (DNSSEC). It lists curves of different sizes and uses the SHA-2 family of hashes for signatures. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6605"/>
          <seriesInfo name="DOI" value="10.17487/RFC6605"/>
        </reference>
        <reference anchor="RFC6840">
          <front>
            <title>Clarifications and Implementation Notes for DNS Security (DNSSEC)</title>
            <author fullname="S. Weiler" initials="S." role="editor" surname="Weiler"/>
            <author fullname="D. Blacka" initials="D." role="editor" surname="Blacka"/>
            <date month="February" year="2013"/>
            <abstract>
              <t>This document is a collection of technical clarifications to the DNS Security (DNSSEC) document set. It is meant to serve as a resource to implementors as well as a collection of DNSSEC errata that existed at the time of writing.</t>
              <t>This document updates the core DNSSEC documents (RFC 4033, RFC 4034, and RFC 4035) as well as the NSEC3 specification (RFC 5155). It also defines NSEC3 and SHA-2 (RFC 4509 and RFC 5702) as core parts of the DNSSEC specification.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6840"/>
          <seriesInfo name="DOI" value="10.17487/RFC6840"/>
        </reference>
      </references>
    </references>
    <?line 308?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>TODO</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA6V7W5+qSJbvu5+Cs/vhVLU7U0BA2L+pnlZBRQFRRJSZ88Ad
lJtcRKyu/izzWeaTTQRoZurO2lU9J18S4rJirX+sWxDLl5eXThEUofMN+SIm
dhk6L4JRFIHlIGzgBYURIkrgxUZRZg4yDL0kCwo/QtwkQ1hJUbjxl45hmplz
hvOFF1YZPvRZRuGAOfU3JC/sTsdOrNiIwFp2ZrjFS+XkhZOZhhG/2HGeO9ZL
FNq58YISnbw0oyDPgyQu6hRM4LnNpBOXkelk3zo2oPqtYyVx7sR5mX9Diqx0
OoCFfsfIHAOwojhWCTitv3SqJDt6WVKmoJVNIiOIEQmwgCg1WDtClqmTGQVY
Jv/SOTo1GG1/6yAvNwHgUysVfEqTvHg5lUZclBF8n/CyguCAWfCc30HKO2cn
LgF7CPInl0WQVsQvGmA1iD1kCufBdjAtBO0AmyT9e+AU7muSebDDyCwfdPhF
kebfej04DjYFZ+f1PqwHG3pmllS502so9OBMsKV+aYK55g383g+3Ak4JAdp5
8WG5+9TXlthrkPyYyI97X/0iCr90OkZZ+EkGwQdrIkgQg30dvXKviPY2r+lw
yzBslWhk5M+dQHAjDq4NtN+QcZiUtgugcZpOp8XTNPK/W289r1YS3dd8J/1F
SVI/ANtl+VHgNJg/E58miRc+EM7zdvTfvaarodyJkywCM86NRqwnYwLt998f
ifdHEj5ClQIa9a0h+7ldvgCxHfsT61QKI7aNzG6ZfYOz+XuBzANSUsM8mMbH
OSBfFg6SuG8zcwT8RzaO5cdJmHg18pPEK5ufW4KN0QF1x4kXlG5acicLnDyI
3eS+DGT/GyKro9YsoAxG5jlAee66YydBo50Y+kqhON2DC7zCaa9wRgcSe8SL
olDy/kgT6LdO5/X1tdN5eXlBDDMvMsMqOp2NH+QIcC5l5MQFYju5lQWmkyN+
UiFFguSpYwVujfwIyM5nbu6n1vh/RoBraMF5t3OgodBLIHdX0/mp9Rk/vyII
XyBlDoYUvnPzHy8EgaRGBpQLqCtADnLpBjFYH5C5O5LXzvtgIJDphIFzBkOA
CKYDJlmQO9ASI4YHPEpeIIZ9drLcgPsACQEPBZaFXrMDttVArKxOi8TLDKDM
lhGGNZI5oXMGHgy5+TEEKGkK1CC7YRoFtg20uvMXoCFFBvCyoMJ0Oq1sX5EK
EPIb5rLEsAHBD2L8+utNv3/77evbCwFfAHKdewMJGxp0Hrh7h9i+afYHqAEA
aZacA9tp3ATYZCAOZAxqL9wEoJwGwH1cZhnoBGxB5CPgrwEkaQns/J1ax7hv
bwMZ4AS4UwdZg8gFV4cToVK+tEoTANGcMAxSsCIC8D87nTdKyBslhBvDyNeI
CBX2t98AnMMwhDNuDL2T+7A+2I26iZdg1SBrdxioEgIEg3z4wCZjsJ9QSvAO
rANEU6A+LlB6QKL1RBAZMwQxpSWD/PTI7s8AT2AOQO06wKSNlt3bFIDY8F/R
EbD7QPfMMggLEFfL0IZqaQBKjZEl4dlBzKTwb+wCYG/r5IjjuoEVNEi02tBO
B6MyB8jvfCQE3j3nFoA/KgEQArggG6mACIAGQMnttMu8Iwpg//XXmxP97bc3
0G+W+Kf8aOd78wcsvzOCAC/vgEhe+UnuvG8ZNImGYLt3nY97F94yqjc4EmC1
QD0hO/fOHGzGLYH6YPqd/4XpwxWNzr9i+gjyEbTWoiFkmeN0HpwWCMlvHurr
/ZEimy29v9KD1+8d8p2i09hba7Rge/9vjrDKV/iy4PYtlfVa4aeA1zwpM8vp
ZI6VwMD003qd/9xu/Q+c6huGsKcNPXljzZ23fbpnpAj+wZndnZjR8vjTDaGf
AUTAmBpQAUdBDuIk4AlGzNnwBSeph/X82+w8AnCDtOTToNGaxg3b234/Qnxn
KzKOcGeLd1eWl0BToZFAjwFxDFo3AeCDev/NyIGD/K3zN+SvUlI4f/2GbECn
ldhOmgDPAYSDfAApzRrhh9IQiOQCDYImBzUJCon2WwY/bN4roAfppIB7uJf3
oTdB3vYYTIH6BFySCZOW4G3XwfwGFZj9vjHzCiPMOInP0JWDLLiBiYUTguYd
apADAUSqZvu/iKqy+fK1/Y9Iy+Z5za1Ufs2x8BlsiCC8PXRuI5TZUhXY96f3
meOlKHIS204GrchDU+eLONx/aRXyy1Le8EtpKHxp8f6o2DBwtBYKXXOWQjcL
tahzT0GauDgay//9XxgBjOz/gPiAYxgDrKx9obEBNDnoV9vVkhhYavsKUKs7
Rpo6IHoBKgYMJ0YKnRXQEaBrOchuYgR6UIDmX/8DIvP/viH/ZlopRvzt1gAF
fmi8Y/bQ2GD2fct3k1sQP2n6ZJk3NB/an5B+5He4f3i/4/6h8d/+PQQqhbxg
9L//rQNVqPUcyPrmLsBD4y5A8I0/+ojSDNsMA4GHRmDHjSEaCNbH8JfEKkA6
djbC0oGwpk3W05gJDC/NLM+Jb+e1DzG/pf+6cOopcMsf8iCQETZDyVcMxqgP
vrVNDYEGOTE0BTgaqA9cRW5ZBMQQEK9AaGz4a8Xr3L0h0npDyCUMSFEKfIEJ
LA2kweDcCLMqeHyE5MwaZPbNIrDllj58gOFBP+/8Dl5xOPQjvxDj1iP/AcTv
4fERYZzA0R8g3PAF50I2v4MWxuTPgf2OUQhs5zNg39P6d1zjpyjzEdfOv4zr
B9k/wtr5IazKe0iATuSmYNB5ACcAfGybKr4v/CUFY7/cM4QzCPsgQnV+Cl6d
169InLRRAvifFxCF/Hs/MgMv9yPMLW0Ch9W0aOygcC53ETs/WcUFMnl1sgQJ
ndgr/J8bJ/OZouTNBkBGydf+9xoOPXcEUhHDa6GBc9vICLP0+2Gm7fi4QufD
DvdfsVe6MZ+PB4lGHd/TM6n5HNR+b/o0i/heZyFv72rWfk+CgTGxgvfc8kOa
8uE8Fn9cpPN9qoLcUxUgLEY3OAQww/cCeEptpALv8BPD26GpcwvgTTQeQ7ux
75+FYMoHHxqRuYsBdfLGvwtykqSCiuG07V/viUBe1GF7oL/BSL0B2J5KvjZB
A0bbDyfNO25BAUM4OK/kaRI3+s0qN6FaUN/spklfwZu464C0rEm73sI12NF3
ZbZhVhOBoJ4XtyTUzZKo4bV/d7y5A4BoY9lNDDkLzmD6my/8+nYwe7e06qMf
eTOTzsOCb2bwtpHITxlMx8CqQAthQIX67oDEMofOwmisqHNDtUnDgbm/AP16
aew+c9oVYYYDRB45lnFTk5a366PKdD7J/762XgQcFCji5e6rGsfY+oEqgwHf
Brv+z3/+s3MD4gUQemm/i3xDzthr//2I8g2oGjymgBUJ4ufOO3LfkOGQGw+r
1WTkWfx4lQjsEF2yl+Ga80V1st7vpqOjMb1U9synf+nchYbfrF6RPoWiCC/d
oytODpB+s9DtM8/tDxssUCtUToRUTEhSlJT0oNQ7XOZId+3M8XOyGx7zi5me
81Cu9XWxOk9Nx7BHy8Hp8EhJjifzGhUKdb1Nl/lo1M3LfVBQWM8jbP/A7RVd
w475cocG4VLwN+T4tFLLgxcFesY9UUKvYiZUEWV4dbnl9phVsLIwIHUvH3IE
wU96e8cO6sAWpRO23WT8KRtNAnKRjzLhkVLiLMXNGZc9QTfFKypb5dbuxbNl
PKIGER/HF42bVjJ29djkNJCpc79wTrIgLPFws36ktGAOknRyxO5OU5eok6Eh
xY/ztULuViXqHNancUb5pba6YIeRVm4Uf4gr58U0HK+Y4SMlRdN2vYW7B5L1
pv7ZMFN1cUoPzjpWZ9hig6XySD/6+l5gtzUTDIxgpWXSfhKzXDJ+pGT3kysh
pnXo4vKmZ66TxTI2WCxk3F2/N2WN4YEam5OuMuGqMcNMKW6m7e2tfDriLv2k
BTiuj/vdNJbWRs8MWFOVj5qr7l13tF+T1jwZUZGHHbFuPJqOdVaSrSm1GpWp
QuX2I6X+cZrrVH6d2nWeTEc8Jm5KOh74y7TaoZOlvKroAiw1Xm11rx8HM3eP
L86zubLcHZ5wWpWrZIeKuj+9cFw0H4e4z1UrcmtQ/LYwLJ3UUdGoTxpK+vro
0rOqvB+rx3QwMEj1kRI1yS+HZLs8dBc13e1T9W66XoytRcbMwhFXURsmY+Ke
6B5nvnBIyEnorxeswez19WzzSAnX91l8Cg1ad1DSvXh0NismNkFpXcYNzP4s
1rnJTM+TSWnLqapeBkxlneONqvDb3iOlNX6WNJm3xrg6WPaNIzEzoq2eVPOL
v92J+57Na8aJKpVdxRN76ySiskPhtX9hYmz7SEmMMFRdSwY2YRZTylhP5bKu
F+JyMF8qg2t3Z03NeWbvZpx4OToXVUV9V9dEa+Sy1OqRUk9hh5vIFo6cXx77
48PUG9rieX0NSXI+ihXHPdq9RLAnYzkI6YPDcplHz02UOCzG1ROlnj0LKGZc
XPR4YGRzlzMuC23V1aakOdomIr8Op5gslTp2LrQpS43GyWWne9HkiJ0eKR0P
LquF3Z6yVVapiUn0MSB33Km0CQUfadZFP13Ga1NDc37hxal4IAPac0StrxPS
k1cxnd5OOqGUVAlqVAX79Xy42O/Fazi4cFNTlJzU8XLCHR3Xa/QirUy1K57C
fiaYFRU/UtqZupmTpE5Ws9jYug5zFoDTi9lpbCkLjOeIwW48dSdJcNkUY3pM
DE05osZ9adWNn3Sccle7tYjvJyZq1jwvBQPuQHPdHDWnuG9jxuJSSmVPLo5X
vaLnmu8Jm8uxGAuccKAeKZVMT1zU6/XhIJTJYufVq83C55zhmKUHrCSsSsE4
64MK00hFHYb9Wb5w5NOQoASzlz1SUjcLXrX3M08/pMpGX2ex363GqnsMygOb
Mus+voiw2uGu174y2hwvdtE9zBeqctaV3SOl8cG0pYWqnqbOml7mOD1am2Oj
OIIwshhelnWkccbCv/DBeh8Dz5Qkl8lwL6TcCvWLR0rMWg0Si+LzKppUvkmQ
Jbo72Ns4rxQPE7PBiV8EHipcnPQUGKUmFYchSGYr7MAw2pMWsIy9P62SbXye
U8k13S0SWVJtYdw7ySKZhONs417rMXtOBufzaLQl9j1f7bPApPaTR0p64fXo
ae5PTwNOXizMrXhdsYS3TY66QwvrcGJduitXVDZVfO71lxsg+R5kZapmDJ+i
1DUEG7E5zHWCqamKXJIufiIj3PV3Mh32LuNirrlKL8BnO5+VE6MSMaw86jMO
Fxj+kZJzPU6q1UHGTtUxF6l+X3Bl1fUltjBm5ZYqc0u9VlNaCiueOZ4sfr6X
BpqZ5gWzCR8pGdVpVnnL6aI8XCdmqs+dQzGgdFJKk2AY677qTk5h2HU95xqb
4qgqtn5KSuXOF+knnGp2fJ2Pa5bzfvkF+fn3shQFIRkaZ2CGgj/nKDSGWyZm
4LjhokSfRh3cHeA2g1koZWGEA7oYjLbcPor2BwZtMBY1IJiBw+AUYT5SIkzX
+F0exB2Coc197evH/t8Z3WbRcA7kuGl9Tq0IAkVxDPZggG0cHeDgsRXzYYGH
WUe7VmbXajSQ3OKwUoaTQR6PnYVR9qXklAqSh1F+z5npW1ro62nQR8Pjug4U
YiKI4pOCnjaHq+liw56p+B5x0tN9GLunnUSXp4k2YaYcN196hYONJ/aEmI5R
0uNGKk0vstp9pBRPhxawFMOtGL9gL3p2ik5bRZO6mFdqg1mtqpME40ttE+uL
0tfTgp0fT10x7JL67EkZiLSLb+zqSIuzQTEPN/tjT90aIlbxO3mE7715t3tk
0atf56TVp7NrYRnLSNwVlPOUbtZDbt8fsBam9xZ5tl7p2rm703vjTRiUftee
zmfJtNxE5KJS0DKnaaI8atK4V/FqT3lKo8JpMmK3u3yDUf1NRoUbl07nxCW4
WAteouN8oUwuMnPoDk1DIpXE5YfnlBCm/ETwnkLxIl9ve9bJ2Se07HhbFuf8
4QrvzbabZb9c0ufwJCwGsbbdLvAubuwXvIBzp+vBX+8XT06YZH2xUhjdM6co
OAldp7v0rFuStayHo12d29vSYA+xWhrRfjscL9VsO6ApQYoK+sklaGy80xJZ
FrlMPpJnqZ6dqK4+8waM6uipcr2gQ6eHGbwb4BpXGMwyI/MpX4xi6vxkyFrA
HOfr0i9B/N65zFgYbXvCTOjJvBOPLjslzvBl5ZHEsFQkvIiOeMjW9MhdXK/n
yyOlzRKEqAvh2AlD7c7UShsqIB4w86jmzn48AXGFp2bTvhvj3SOdeXOBn6V5
RqS6L/pPBt1TVpqRHC4FicUcPwkwMwSJfD6MxrYo05igSBeQIPLHhSU7y34f
pOVbhV0OptflU3qQx6Pl1fTVHeOZk6xvSNuelpl5z9LFoYDxKL+Y4ujhGHGu
zsjOQkL93fgymyeELz/hJOBRxFjBNC13yiCRaHewL81Q2lTrPW0SaahYW36c
1qMNqbJL4D/XTK/LxsdQQN3rIyV+uRY36zhlMf9EjE666ElidbauE6/PZoqw
knvWKFgIcb9I5tlRKVXG2CU2d9L64RNOa5DIseppU8w8cWHk5NkJI3Dy4KSh
GVyCER2T14STYlHYUlUP6xvdernZ4Jp65pQnHZ+dJgw+cVeivQr7VJzUThUd
1ImepEE2nm6p4dEx7W2+2eMDttgfp5oRCTsr6le4/ZSyDPdAf/L8XC968zCu
etwA5GTacdml5fNsiBdnd6VktCuNiTDsLWZ2ldE2uqLzVLaWTzyJYhng6I7d
g9O9HKUU4SsFwY/KYFXmdtRXVrl2WJ0NNffovD7qNk4ovUpaBdP8KXHdGcmU
SrT9fqyXqXueWmjumV3mdNFV0lWG+0V1IYXD3jhk5XlFuqFjDosMpA+lbE6f
fIGJ8wOdtgj+zEbmkAoPJ3FBoRW247uVOjgoGkDcCHhnqK4xY8Pg5GIicn40
mfaPT9aSkbrMk4NKHKQczxxGIkejYTlg+y5x7XYDS5kpc3IvGb0uOP44Cr9h
iIjYHAax8xTUIwnV4sXEu071RVwG7HTuVORkErsj9OSeT6qkygWWbQ0+G2TX
0UggDrS2mp2WCTZ4Sly7aBrzp8XGwXRavExiGZyiHW1m9De9wdzhZIUl55Nl
ymmXHMOL6rIZE/go24ytoxI9Usrc6Ji7l2huoJHrhsZSnh0Phr9Js4wv5tcp
5riz/bgkY5nMcivUJ6jPLtfYUs+8J5+J8348xbZJwcsjotvrDtBuyaIn67Tv
C3idxJdJuFLonItEaxcwl9XmYk+mhLQ89jZPB6EpiS7DGivWKaMmwqHasEXI
H/wBJlyZ0DiYQ8PcElrBn+2BVRlrbokeJ8Piynvu/OmzwVY0cu2sJpTD9E+r
0ca/no9jKadjLzfQw24uYLOMW8vd0zFQhTErZhgz2QaRFvHXpyRxfFwzqcdo
GlC9PXnMPHtr8pJ6OuR1Pc0CmfNrfB47kmYv7UkyrI5aMTX5dOXPcvwpBRZm
6ZS5yPKky4GAFB0kY0CN/N2ZsIwym+3jwQKNCEncemxdTXeJjy6nTk9Odivi
2RcUA86ceeZ4tWS2dLeHdUWtYvRMpcxiOZ3j8+3Oqde7fT03srhrxbKAxdoy
PA1MkX36bBAZ1+VG0mWLVDlJObMCifmR3dfYARbgJWMWJ/56iCPl4nnybJ1v
raUx3c3EvqHOn3KVjC2qAOP2g80snBuF0uWLg7YSx6xPez1CmDAKrmrTiYVj
YhDllXb2fOww6hH+/ilyMmNaVsbp0NnilL1LhlJcrHuhEOUETtC0vZ1jVS1N
D4Yk7bCgCE6TfS6pcV+oN/2nzwb2VvVG1dG9LjGeUGOf5c18NtfMfMCGPRLn
AkI0U3m+iwXMEyWLUliMO26wsbNnnjIxJ59NcBR4wsIcbLsneYlvxhxO5fWI
CXUCWyrLvXeS94veclYngmOvos1yEuboSjw8acEENY95P51HvQ3Lilyp2n4Z
ykYR6yOJ3zmXk8RHK3VSB6k1ZzRyEbOUlpHdQ60K9ZOOj1brVJOvQerKk+HY
JG0y1OQiO/vEscz2RT9XbLXuavNFuTexDJz0N/r8JKMr1ns6WG+5vUDG8/hy
UtYs414GM3E92y3Z4zZIRpNIUb1KJnej8BD39invTWn+QuB+vRDHRfCUHZ4x
j9/3exE4F8zqA8lTF4udqRt9VotMd6HoDuCWqtQ49hK93F9lRgL59TWhBb77
SKnqiwmV97YHP8qHwnJvlTnI43NUXO3JNPOPlr5Xz96Z2QvMuotNosHiUvet
QxpPT084adVFovaRVPVcatzFMTZ0LoMuyiR47QWoiEmcrqMT3zZG0WV7KZSD
OYr65aJkCuPpEItel2SfmO3CwJ0cLy419c3kYk5teC4/bvkDK8TjbpDYq1qo
+AA9ny2iT+6OxHQ9yp+OViwpX9z+edMvPLkmc3ZnzvvhhqRF57iwN71ZYpYe
u7RLNCymTjw5gPDh2/PSPq+ePmhNJofT/IgB93G4XGy5v9ovQmW2PONDtlif
PB7dzoR5xI2XgbvPGLTUohArr4Z6XaBPnw02ZRjRbkyFbjrpc9p8r+QnLNit
tDJYV0xJ2ZdAQfGuRei0dC2jxCdorXtFp5O6+/TxaBzW/sl27CF17Gs6Pw8Y
jHFIEyeiA5mdrpaXDamFeIo3c3bh41aZLMaYy9N0NRgQj5SsBN3JbO11z701
yOo3mHsq2ens4Gzr7Sg/xpK+IsPqLDjDulfOuquQPHHjFaON+bn8pJm2rvsj
BqX840zvni0fc6fds++JRbLzC51Qd9dVZc5HQo+oLsUSnPt4T5se5xwfPXk6
edFfcN1B6rsxuY+mymE7TukEK/DVJa3mmC6Pyk2majVGelnJy7RDYKSLqrKq
H54y1mk3peanXL0ao6unn4ceE+975xk3RvNdOR6E8SliLxktqMxcZAeDXTay
rJ0oYwxjP2kBhppzjd7MuvX1xBF5fbBVmTPCVVzJPddnypzBHcU+k+g5Q3sL
2b+62tVaV9rkkjx5OgUjr+Hc6V+kQ3cEcqTZeJguDqOjTzpRKdTdirmCI0pM
9Va5udNSytc1KxGWVF0IT5So3qzL+l4pXYEZT7amRyq7hMKrayEnw4c/9CBx
e/iRAl7cdP7yVhb6dK8Huv5yLymHd2bvdUmP13+PF8aIkaZh/drp8DGsFioC
q61pvN/H9l+J5qKp/0o9z4TVf2WeI4ZtB23tb+dpKXh/2tx5w5IWeJHWsgdv
Fa2wbC4CvTKwYenTvbjN8hNYzwaW8h3bg1dYOfLp1Vv+Cm8Gc+dJvE4jT1tO
+F70VsLyufdfDzQSOU0JX3N1aJdZc+keNzUgt6KB1wZQNqliLzNseEX6ofri
/f4Ylg4DMOBtZgTEtHN46QZkKpK2AMqwLCctmqpCeJcYOp2mH4Bd+K+IUlo+
vBUPmgKo94nwxu5chvC281a7aCD2nRXEKArDOn7rBLAO4prEzY3iewnW+wVs
c7d6r8p7+UDw7ab6K6xEid8H3Wg7GWIZcXOHnz6VxX28coT0fePsNFv3nRh3
2YvmajmDu/kJK2/03ov7nLwpPGi3MmgvQb+n/j7uDeLOj0TNYR3rjdodtKYo
6hPkXjvDDys1F7jBvfgkvldE5E7cqqrRjv0AUvMdrtNoIRxsnOHvKMwgvNVz
NhWWRZC3xQ93htqSRSPME8Q5Q5VrL57v295c2H9yoQ9sFzbCIkFgio59w/vt
Kj8ushq51ax89ouRN39yLzPvPBdC5F/u1QbQU/wDmTT1Lr/79w9k2xTk/ODv
H51/vPzB3x8OAEMAL7dSjd/nBaN/xEjLC8I2pSJpY96fUnnf2h9QEWMnSmLg
o36Pl9t1+o950aFuKrfKpc+o7H8kzZ3KJjNi4CPB5r5+zst//vVPUFFz56Pf
fOYKSDT8A24+obJtDesN6z9Jhb9Hks85+v+h8s7Rn6SyhgWujfl/PuSPfobW
B1R+/db+DueXL5JT3Tn5rgapMd8vv3U6YL82sCSzMXTTAZ4lTt5C49tPFvLb
D27uJfy3EpK3apIgf/+VQluT1CiK0Ua2uyu4/WTDBJGgKYyyjnFShSAgQ+By
wHlb3+TYv3xxgb9yIH+bJbvs/A9f0OGt9TcAAA==

-->

</rfc>
