<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-westerbaan-dnssec-mldsa-01" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="ML-DSA for DNSSEC">Module-Lattice Digital Signature Algorithm for DNSSEC</title>
    <seriesInfo name="Internet-Draft" value="draft-westerbaan-dnssec-mldsa-01"/>
    <author initials="B. E." surname="Westerbaan" fullname="Bas Westerbaan">
      <organization>Cloudflare</organization>
      <address>
        <email>bas@cloudflare.com</email>
      </address>
    </author>
    <author fullname="Sophie Schmieg">
      <organization>Google</organization>
      <address>
        <email>sschmieg@google.com</email>
      </address>
    </author>
    <date year="2026" month="July" day="21"/>
    <area>Security</area>
    <workgroup>Domain Name System Operations</workgroup>
    <keyword>DNSSEC</keyword>
    <keyword>ML-DSA</keyword>
    <keyword>post-quantum</keyword>
    <keyword>FIPS 204</keyword>
    <keyword>signatures</keyword>
    <abstract>
      <?line 58?>

<t>This document describes how to specify Module-Lattice-Based Digital
Signature Algorithm (ML-DSA) keys and signatures in DNS Security
(DNSSEC).  It uses the ML-DSA-44 parameter set defined in FIPS 204.
ML-DSA-44 is believed to be secure even against adversaries in possession
of a cryptographically relevant quantum computer.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://bwesterb.github.io/draft-westerbaan-dnssec-mldsa/draft-westerbaan-dnssec-mldsa.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-westerbaan-dnssec-mldsa/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Domain Name System Operations Working Group mailing list (<eref target="mailto:dnsop@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/dnsop/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/dnsop/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/bwesterb/draft-westerbaan-dnssec-mldsa"/>.</t>
    </note>
  </front>
  <middle>
    <?line 66?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>DNSSEC, which is broadly defined in <xref target="RFC4033"/>, <xref target="RFC4034"/>, and
<xref target="RFC4035"/>, uses cryptographic keys and digital signatures to provide
authentication of DNS data.  Currently the most popular signature
algorithms in use are RSA and the NIST-specified elliptic curve
signature algorithm ECDSA <xref target="RFC6605"/>.</t>
      <t>All currently specified algorithms rely for their security on the hardness of the
integer factorization problem or the (elliptic curve) discrete
logarithm problem.  A cryptographically relevant quantum computer when built
would be able to solve both of these problems efficiently, and
would therefore be able to forge DNSSEC signatures created with any of
these algorithms.</t>
      <t><xref target="FIPS204"/> specifies the Module-Lattice-Based Digital Signature
Algorithm (ML-DSA), a signature scheme whose security is based on the
hardness of lattice problems over module lattices.  ML-DSA is believed
to be secure even against adversaries in possession of a
cryptographically relevant quantum computer.  <xref target="FIPS204"/> defines three
parameter sets: ML-DSA-44, ML-DSA-65, and ML-DSA-87.</t>
      <t>This document defines the use of DNSSEC's DS, DNSKEY, and RRSIG resource
records (RRs) with the ML-DSA-44 parameter set.  ML-DSA-44 targets NIST
security category 2, which equates to 160 bits of security classical
and post-quantum security. ML-DSA-44 has the smallest keys and signatures
of the three ML-DSA parameter sets, which makes it the most suitable
for use in the DNS.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="dnskey-resource-records">
      <name>DNSKEY Resource Records</name>
      <t>An ML-DSA-44 public key consists of a 1312-octet value as produced by
the key generation algorithm ML-DSA.KeyGen defined in Section 5.1 of
<xref target="FIPS204"/>.  It is encoded into the Public Key field of a DNSKEY
resource record as a simple bit string, using the byte encoding of the
public key described in Section 7.2 of <xref target="FIPS204"/>.</t>
    </section>
    <section anchor="rrsig-resource-records">
      <name>RRSIG Resource Records</name>
      <t>An ML-DSA-44 signature consists of a 2420-octet value as produced by the
signing algorithm ML-DSA.Sign defined in Section 5.2 of <xref target="FIPS204"/>.  It
is encoded into the Signature field of an RRSIG resource record as a
simple bit string, using the byte encoding of the signature described in
Section 7.2 of <xref target="FIPS204"/>.</t>
      <t>Signatures are generated and verified using the "pure" ML-DSA variant
(i.e., not the pre-hash variant HashML-DSA) with an empty context string
(ctx of zero length), as described in Sections 5.2 and 5.3 of
<xref target="FIPS204"/>.  The message signed is the data to be signed as described
in Section 3.1.8.1 of <xref target="RFC4034"/>.</t>
    </section>
    <section anchor="algorithm-number-for-ds-dnskey-and-rrsig-resource-records">
      <name>Algorithm Number for DS, DNSKEY, and RRSIG Resource Records</name>
      <t>The algorithm number associated with the use of ML-DSA-44 in DS, DNSKEY,
and RRSIG resource records is 18 (please).  This registration is fully defined
in the IANA Considerations section.</t>
    </section>
    <section anchor="examples">
      <name>Examples</name>
      <t>The following example, in the style of Section 6 of <xref target="RFC6605"/>, shows an
ML-DSA-44 DNSKEY, its corresponding DS record, and an RRSIG over an MX
RRset.  The key was generated deterministically from the 32-octet seed
shown in the PrivateKey field, and the signature was produced using the
deterministic variant of ML-DSA (rnd set to all zeroes) so that the
example is byte-for-byte reproducible.  Because of the size of ML-DSA-44
keys and signatures, the base64-encoded values are wrapped.</t>
      <artwork><![CDATA[
Private-key-format: v1.3
Algorithm: 18 (MLDSA44)
PrivateKey: AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8=

example.com. 3600 IN DNSKEY 257 3 18 (
             17K0clSq4NtF55MNSpjSyX2PE5fReJ2voXAksxbpvslPyZRtQvGbeadBO7qj
             PnFJy0LtURVpOsBB+suYit61/g4dhjEYSZW1ksOX0ilOLhT5CqQUujgmiZrE
             P0zMrLwm6agyuVEY1ctDPL75ZgsAE44IF/YediyidMNq1VTrIqrBFi5KsBrL
             oeOMTv2PgLZbMz0PcuVd/nHOnB67mInnxWEGwP1zgDoq7P6v3teqPLLO2lTR
             K9jNNqeM+XWUO0er0l6ICsRS5XQu0ejRqCr6huWQx1jBWuTShA2SvKGlCQ9A
             SWWX/KfYuVE/GhvabpUKqpjeRnUH1KT1pPBZkhZYLDVy9i7aiQWrNYFnDEoC
             d3oz4Mpylf2PT/bRoKOnaD1l9fX3/GDaAj6CbF+SFEwC99G6EHWYdVPqk2f8
             122ZC3+pnNRa/biDbUPkWfUYffBYR5cJoB6mg1k1+nBGCZDNPcG6QBupS6sd
             3kGsZ6szGdysoGBI1MTu8n7hOpwX0FOPQw8tZC3CQVZg3niHfY2KvHJSOXjA
             QuQoX0MZhGxEEmJCl2hEwQ5Va6IVtacZ5Z0MayqW05hZBx/cws3nUkp77a5U
             6FsxjoVOj+Ky8+36yXGRKCcKr9HlBEw6T9r9n/MfkHhLjo5FlhRKDa9YZRHT
             2ZYrnqla8Ze05fxg8rHtFd46W+9fib3HnZEFHZsoFudPpUUx79wcvnTUSIV/
             R2vNWPIcC2U7O3ak4HamVZowJxhVXMY/dIWaq6uSXwI4YcqM0Pe62yhx9n1V
             Mm10URNa1F9KG6aRGPuyyKMO7JOS7z+XcGbJrdXHEMxkexUU0hfZWMcBfD6Q
             /SDATmdLkEhuk3CjGgAdMvRzl55JBnSefkd/oLdFCPil8jeDErg8Jb04jKCw
             //dHi69CtxZn7arJfEaxKWQ+WG5bBVoMIRlG1PNuZ1vtWGD6BCoxXZgmFk1q
             kjfDWl+/SVSQpb1N8ki5XEqud4S2BWcxZqxCRbW0sIKgnpMj5i8geMW3Z4NE
             be/XNq06NwLUmwiYRJAKYYMzl7xEGbMNepegs4fBkRR0xNQbU+Mql3rLbw6n
             XbZbs55Z5wHnaVfe9vLURVnDGncSK1IE47XCGfFoixTtC8C4AbPm6C3NQ+nA
             6fQXRM2YFb0byIINi7Ej8E+s0bG2hd1aKxuNu/PtkzZw8JWhgLTxktCLELj6
             u9/MKyRRjjLuoKXgyQTKhEeACD87DNLQuLavZ7w1W5SUAl3HsKePqA46Lb/r
             UTKIUdYHgZjpSTZRrnh+wCUfkiujDp9R32Km1yeEzz3SBTkxdt+jJKUSvZSX
             CjbdNKUUqGeR8Os28BRbCatkZRtKAxOymWEaKhxIiRYnWYdooxFAYLpEQ0ht
             9RUioc6IswmFwhb45u0XjdVnswSg1Mr7qIKig0LxepqiauWNtjAIPSw1j99W
             bD9dYqQoVnvJ6ozpXKoPNUdLC/qPM5olCrTfzyCDvo7vvBBV4Y/hU3DuyyYF
             Ztg/8GshGq7EPKKbVMzQD4gVokZe8LRlFcx+QfMSTwnv/3OTCatYspoUWaAL
             zlA46TjJZ49y6w5O5f2q5m2fhXP8l/xCtJWfS/i2HXhDPoawM11ukZHE2L9I
             ezkFwQjP1qwksM633LfPUfhNDtaHuV6uscUzwG8NlwI9kqcIJYN7Wbpst9Tl
             awqHwgOGKujzFbpZJejt76Z5NpoiAnZhUfFqll+fgeznbMBwtVhp5NuXhM8F
             yDCzJCyDEg== )

example.com. 3600 IN DS 59829 18 2 (
             812cb1a22af04380e2f72d91c06c14eb1a918cf30037a8a9c67497e9264b
             4bfa )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 18 3 3600 (
             1440021600 1438207200 59829 example.com. (
             kdySHzwB7NftjQSAF7snCeKau3NoqpLNg16h/eHZV8L3Zpi30lkRyiS4FLMM
             ZqTjzbf1A/bShg4qZpYlnfqXN8uqFWF9GEEJOgte1CFdF4GC05gEBU88Kryf
             nGAcpXKafw9htDxZrqmqVSWN+1guW7HyUUFo1IuWTnZKuhZptDJkq+Ml+5ZH
             y4p+2Tdwk8MH7tJlTYk/UVaM1wIXPB2YgJ++kD0zhys5c38rztcaOmMXt6ej
             yAEY37Dc1Z/KsrRQZWv+XZ/CTliuh+dGJHoGuTm5KwS0us884ukWNC/wIU/S
             dlGoBDVXsT163Tr6lTf8pJ4xixcKIN8nsKSFxP9j+AbaN5SofIAvp4LGIFLg
             MKsRV/cqeYo8PegVD2EhAQ2/HVTO3uO8vlqLK7nWVVK2+2aYKIL2EqzjhRYK
             U5DhMwS9ZgbG0niszGXpvZcNcOyABXysdVuaDjnUuamYVACOUrV786LNmt8I
             WDnXWoPPMErPk5vNyHq6+ZHg79UeZpSzx0Ae/1aIfi2WEta9Or5sGItBn6vF
             Wi9kJRuhuoMIXf9CLBV/LHL/PIenBxXSnr2Owg54AuSN2tmk2lDy8BfKzzvx
             TOoKXx4edo96Xv6QWASAxO9JmyEvhnF3SBI6HG3fn2+k8rgJLIHpsr4pZhMh
             4/SQWaojxt51nEIFi1bl7P6sAmCdMP81LSNx05hIkKcPeO33hA2VSDO7GzOE
             snBOzbhUX9gbFr3aNV/Wrbs/cZMAL1I0IKG20jkmEfZ9PeKN0hXCxHJo4hPF
             L2mm9ciGpuXS7oN8f7YublNTwRY8b4plScVICpyBT5UDOgezR9/+DnklL0fz
             IORMTRnpD1hq4BqZMgNMwvczFg3DrSLQP/cBiKLn3toJrkSuU9aXodEqW3lh
             RdMvDUqTtHgMKas5velmabpENAbixiB8n5zoENnMLV6w/13a+yOTT2WUvESg
             HqF92FfQMdQl36noyewmjUFZopirCGV6AkebdVsTY27DtYkGWamLXcm3w2d6
             AYV/LssvyK/Jlnw/E7YRJWkO+8PvHA2tvfQSr8fNC4ll/KHdwr8d0Q8spPcO
             HMMui20XDYeprPmp64hSt4IBuiQusdm3SQsWjQvaUsg8sykZd24S/wNQiGsw
             XaoG6oWYYCZupfvGc0sgb+9qxZU5fSAYKwx5LjYajruvQ5flebAtrUdLuPbG
             Mb2I7Z8c4IvDmbA6ljqMK60w1XI+wU7jSWzoEaiIeAUR1aT925KFMEhmFG3k
             Tr5ZPI57wM7pEI9jBME80lu7D3f4z++icSHSJ5YNa/+kp7eSIT94m4Tj7nel
             mN0WnKFgzGZKnuiDGJew5FFnfB0qfvqUNUPt1rVaIr7rzBBL4j8WQHqOo17A
             +0pnIqKTe1Z8MxFnPwP1eWHa3T/7JeEPSD5JFOpEWxs12twxTC42BrTCckSm
             rfmksfxmJa0mfflaOPHkjahTprrItJzG1efHYCu5nP5rsclZF0hDOR1OZrgK
             2IhnG1VotIPB4+/+70+uD0qcqY3L2yonxFlQS8sEmMcXi9xQTxdFG4NOk/TQ
             G50Oly1tRp9UoLjwTDtlIjh71Lz9lajbAabV4WtIvd7cwaREO0kFAtzIgfJR
             VMasWvUo6e93qQBThzvkCNs8ngsa0jXJL1HrERP+qkiULCDMr19FVimWmIzL
             CkR9pg9WWjruY5krgdVbINUqjsyyGriPEhy2JneNWdOdFoAwkWtGbIpQhHs2
             bLHpG9xPPF+ElqLmjNa76BhXv4caurHYn7K0m4NMVgDywGXoh0OGe/PoXQ4g
             Ht7EbHgbCQO9V8+/1+MWw9ZrU6btOGJ2JVXeyRXYyJarn+cnPL1nWOlq7bMD
             3mazOTNZPc5UENSvDL51hmd3WD71i2u9btqIzjnmSxggPHRsVcOaGXHM3aUJ
             nrDtwi1EY7THlJatS+ItjWQMCDh8g/4LF9S2UWGFc21MimswWvgh1jB/4hYI
             9C8PSCpAeV26dXoANntR/lLms42488dVJ1wyNGjaNNX1itiqFYsNUn3LyT3T
             dVUgBwkfzO1I4UnhDIbsHJWbs7Dl/52Ei4MbpPJXnL1gMNc6SD1EkT1CeY9f
             esHF20wr8tb7V+qPO2TCE26syB9lZ41OSOYgqPYK/OHyoLedQmTOFls0QMj2
             F0bks3pJm/TDDMEuUdhulPatnZBNIXexqNImQUFyipcJ9W5KnD6Wr5+jyULy
             VBQRpWPzipfPFACb5d5lWPtrvh4kurYt3sSdUy+WJKuYb1roxXTZJqP0QDgn
             VEYL5nJnxqSRD9fx7HMRHXODkVioBFmSUgwP5XBljn/YpIgG8Ix42hyKMCti
             yv1gIY3/m8cfHyj5I6xcDHUTZHyM9+KSZeipf6wUnngoZuYzP9N3Nozo8LI+
             w3Mo6s/VjhmsALOYcus720s0MQY5prhkcZYUvgv9YL9R+1Fm7Kxy3cjpnGqy
             WwxN6YmNw/f6C+21Dlex7+09o2ygi0M1NEZZ0FhdaBmxVxtSjbBm3uKu9taW
             0zO534HXlifFkxf6GhboxbGdm1yekVIjDLnC+iodQyLwIi0vvc435Xk4GRBs
             8D5Pxf3vT3tgPy5sDXbJ3lT58MekKdT/HobugDOdu0ltGenFjnKFhdJudvQ/
             FFjqJk1HYnjxxdP3QYKlSHOv2ADtRqgI0VHLJmECOifYr90uWml1uzaUzK0X
             Tulm8fn6lfpF3EWJYSsq1iXQWuiRw9u6dxiS02+c4Z8Nzumoh48W+z0GFy+q
             ClyhqdedA6k3WZIJi919e5b24mj5rqzcgrA6KMqnTJDKh2cuoKC1fI88w774
             co0XPDyg+v/RD2ET1fquDGHjeVyVBsknNZQ5lwvLeAy/uH+Ql5qECQ9WCIJP
             ydZZhB906hkHZ+vch1fG+vhgMtoXhtZ4UXzQwbJBL/4wxtOau3IgWGkJEImJ
             PK3KE+7phfn5YmGSjVCp8o1t2QxpwJ1ZPBuTrUWy15gruIP8e415f0UPUZjF
             G+p6JqsUzaBzgZvAg9nY/vHEC0sXuC7lnqmDxr8LU9JMD77XrBccXMP199d/
             10bJW8TH+yzqE4syjdUPEalQnwP/fh9us92eSdv50vr0/KPhzfWzcRwWFxof
             S15zlJe3xNj+BAURHCApKjBkh5emuLy+w9zn6vn6/QsbXWp6hZWcoLO6ytLf
             6/H+DhguNzs/VFVbg5SXo62wztPoAAAAAAAAAAAAAA0jNEY= )
]]></artwork>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <section anchor="ml-dsa">
        <name>ML-DSA</name>
        <t>The security considerations of <xref target="FIPS204"/> apply.</t>
        <t>In particular sections 3.4 and 3.6 of <xref target="FIPS204"/> discuss additional
considerations for implementing ML-DSA, including guidance on the
choice of hedged vs deterministic variants. These considerations
apply when ML-DSA is used for DNSSEC and especially during online signing.</t>
      </section>
      <section anchor="downgrades">
        <name>Downgrades</name>
        <t>Section 5.11 of <xref target="RFC6840"/> recommends validators to accept any single
valid path. Such lenient validators are vulnerable to a downgrade attack:
if a zone is signed by ML-DSA-44 and a quantum-vulnerable algorithm,
then a quantum attacker can strip the ML-DSA-44 signatures, and have the
lenient validator accept the forged quantum-vulnerable signature.</t>
        <t>This does not apply if the validator does not accept any quantum-vulnerable
algorithms or if the zone is only signed by ML-DSA-44.</t>
        <aside>
          <t><em>Note to editor</em>: remove this remark before publication. Remark: Ideally
we update RFC6840 in a different document to recommend validators to
insist on PQ RRSIGs if there there is a DS that indicated they should be available.</t>
        </aside>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document updates the IANA registry "Domain Name System Security
(DNSSEC) Algorithm Numbers".  The following entry is to be added to the
registry:</t>
      <table>
        <name>New DNSSEC Algorithm Number entry</name>
        <thead>
          <tr>
            <th align="left">Field</th>
            <th align="left">Value</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Number</td>
            <td align="left">18 (please)</td>
          </tr>
          <tr>
            <td align="left">Description</td>
            <td align="left">ML-DSA-44</td>
          </tr>
          <tr>
            <td align="left">Mnemonic</td>
            <td align="left">MLDSA44</td>
          </tr>
          <tr>
            <td align="left">Zone Signing</td>
            <td align="left">Y</td>
          </tr>
          <tr>
            <td align="left">Trans. Sec.</td>
            <td align="left">*</td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Use for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Signing</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Implement for DNSSEC Validation</td>
            <td align="left">
              <bcp14>MAY</bcp14></td>
          </tr>
          <tr>
            <td align="left">Reference</td>
            <td align="left">(this document)</td>
          </tr>
        </tbody>
      </table>
      <t>* There has been no determination of standardization of the use of this
algorithm with Transaction Security.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC4033">
          <front>
            <title>DNS Security Introduction and Requirements</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>The Domain Name System Security Extensions (DNSSEC) add data origin authentication and data integrity to the Domain Name System. This document introduces these extensions and describes their capabilities and limitations. This document also discusses the services that the DNS security extensions do and do not provide. Last, this document describes the interrelationships between the documents that collectively describe DNSSEC. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4033"/>
          <seriesInfo name="DOI" value="10.17487/RFC4033"/>
        </reference>
        <reference anchor="RFC4034">
          <front>
            <title>Resource Records for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of resource records and protocol modifications that provide source authentication for the DNS. This document defines the public key (DNSKEY), delegation signer (DS), resource record digital signature (RRSIG), and authenticated denial of existence (NSEC) resource records. The purpose and format of each resource record is described in detail, and an example of each resource record is given.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4034"/>
          <seriesInfo name="DOI" value="10.17487/RFC4034"/>
        </reference>
        <reference anchor="RFC4035">
          <front>
            <title>Protocol Modifications for the DNS Security Extensions</title>
            <author fullname="R. Arends" initials="R." surname="Arends"/>
            <author fullname="R. Austein" initials="R." surname="Austein"/>
            <author fullname="M. Larson" initials="M." surname="Larson"/>
            <author fullname="D. Massey" initials="D." surname="Massey"/>
            <author fullname="S. Rose" initials="S." surname="Rose"/>
            <date month="March" year="2005"/>
            <abstract>
              <t>This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of new resource records and protocol modifications that add data origin authentication and data integrity to the DNS. This document describes the DNSSEC protocol modifications. This document defines the concept of a signed zone, along with the requirements for serving and resolving by using DNSSEC. These techniques allow a security-aware resolver to authenticate both DNS resource records and authoritative DNS error indications.</t>
              <t>This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4035"/>
          <seriesInfo name="DOI" value="10.17487/RFC4035"/>
        </reference>
        <reference anchor="FIPS204" target="https://doi.org/10.6028/NIST.FIPS.204">
          <front>
            <title>Module-Lattice-Based Digital Signature Standard</title>
            <author>
              <organization>National Institute of Standards and Technology (NIST)</organization>
            </author>
            <date year="2024" month="August"/>
          </front>
          <seriesInfo name="FIPS" value="PUB 204"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC6605">
          <front>
            <title>Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="W.C.A. Wijngaards" initials="W.C.A." surname="Wijngaards"/>
            <date month="April" year="2012"/>
            <abstract>
              <t>This document describes how to specify Elliptic Curve Digital Signature Algorithm (DSA) keys and signatures in DNS Security (DNSSEC). It lists curves of different sizes and uses the SHA-2 family of hashes for signatures. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6605"/>
          <seriesInfo name="DOI" value="10.17487/RFC6605"/>
        </reference>
        <reference anchor="RFC6840">
          <front>
            <title>Clarifications and Implementation Notes for DNS Security (DNSSEC)</title>
            <author fullname="S. Weiler" initials="S." role="editor" surname="Weiler"/>
            <author fullname="D. Blacka" initials="D." role="editor" surname="Blacka"/>
            <date month="February" year="2013"/>
            <abstract>
              <t>This document is a collection of technical clarifications to the DNS Security (DNSSEC) document set. It is meant to serve as a resource to implementors as well as a collection of DNSSEC errata that existed at the time of writing.</t>
              <t>This document updates the core DNSSEC documents (RFC 4033, RFC 4034, and RFC 4035) as well as the NSEC3 specification (RFC 5155). It also defines NSEC3 and SHA-2 (RFC 4509 and RFC 5702) as core parts of the DNSSEC specification.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6840"/>
          <seriesInfo name="DOI" value="10.17487/RFC6840"/>
        </reference>
      </references>
    </references>
    <?line 307?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>TODO</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA51727qqSrLmvU9Bz7rotco5hoCAML9dtUsFFQVEEVG6+4JD
clBOchCxatWz7GfpJ+sEdAx1jrVqV3sxJyRkZOSfEX9EkjHe3t46uZ8H4Afy
TYztIgBvgpHnvgUQ1nf93AgQxXcjIy9SgAwDN0793AsRJ04RVlIUbvytY5hm
Cs51f+GNVYZPzywjB7BP9QPJcrvTsWMrMkI4lp0aTv5WgiwHqWkY0ZsdZRmw
3sLAzow3FOtkhRn6WebHUV4lsAPPbSadqAhNkP7o2FDqj44VRxmIsiL7geRp
ATpQhX7HSIEBVVGAVUBNq2+dMk6PbhoXCWxl49DwI0SCKiBKBccOkWUCUiOH
w2TfOkdQwbftHx3k7TaB+qqdVX2VxFn+diqMKC/C+n7CywqCo0R9nd1Byjpn
EBVQPQT5bw6LIO0Uv2lQVT9ykWndr26H3QLYDrGJk7/5IHfe49StHxip5cEH
Xp4n2Y9er36vbvLP4P3+Wq9u6JlpXGag10jo1T3hknqFCfuaN/B7f7gUdZcA
op3lD8Pdu763wt79+I+F/PHTdy8Pg2+djlHkXpzW4MMxEcSP4LqO3rl3RPvo
1zxwiiBojWhkZK8P4cSNyL820P5AxkFc2A6EBjQPQYunaWR/sz6evFtxeB/z
U/Q3JU48Hy6X5YU+aDB/FT6NYzd4Epxl7dt/c5tHjeROFKch7HFuLGI9GRNo
v/95SXxekvVlbVLQon40Yr/2yzc4bWB/4Z1KbkS2kdqtsh9wNr+3WnkoSmqU
h934KIPiixwgsfPRM0Pg/8gGWF4UB7FbIb9IvLL5tRXYOB00d5x4Q+mmJQOp
DzI/cuL7MLX6PxBZHbVuUc/BSF0AjeduO3bsN9aJoe8UitO9eoD3utt73aNT
C3vGi6JQ8n5JE+iPTuf9/b3TeXt7Qwwzy1PDyjudjednCCSXIgRRjtggs1Lf
BBnixSWSx0iWAMt3KuSPgOx8RXO/tM7/KwKpoQXn08+hhdYsgdyppvNLyxm/
viMInyNFBl/JPXDjjzeCQBIjhcYFzRUiV2vp+BEcH4q5E8l75/NlOCETBD44
w1fgFEwAO1m1drAlQgwXMkqWI4Z9Bmlm1OtQC4IMBYetWbMDl9VArLRK8thN
DWjMlhEEFZKCAJwhgyE3HkOgkSbQDNIbpqFv29CqO3+CFpKnEC+rNphOp53b
d6SEgrxGuTQ2bCjwYRp///vNvn/77fvHDVHfQOQ69waybmjQedLuE2L7ZtkP
UEMAkjQ++zZoaAIuMpxOrVhtvfUiQOM0IO7jIk3hQ6hWjXwI+RpCkhTQzz+l
dYz78jaQQU0gnQJkDSNXPXrdsTbKt9ZofDg1EAR+AkdEIP5n0PmQhHxIQrhx
HfmaKdYG+9tvEM5hENQ9bgp9insYH65G1cRLOKqftisMTQmBE6v18KBPRnA9
61nCe+gdMJpC83Gg0UMRLRPVyJgBjCmtGOSXZ3V/hXhCd4Bm14EubbTq3rpA
xIb/jo3A1Ye2ZxZ+kMO4WgR2bZYGlNQ4WRycAWLGuXdTFwJ7GydDgOP4lt8g
0VpD2x2+lQI4f/AoCN674BaAH40ATgJSkI2UcApQBkTJ6bTDfCIKYf/7328k
+ttvH6DfPPG/xaOdn90fqvypCAJZHsBIXnpxBj6XrHaJRmC7dp3HtQtuGdUH
HDH0WmietTr3hxlcjFsC9eD6nf8P169HNDr/jusjyCNorUfXkKUAdJ5IC4bk
D4b6fr+kyGZJ77f04P1nQr5LBI2/tU4Ll/d/ZgirfK9vFty+lbJeK/wU6prF
RWqBTgqsuA5Mv6zX2a/t0v8BqX5gWD9pQ0/WeHPnY53uGSmC38kMQDzylmQw
CkVMP28W7bNHYEBcIYadWr/HJPDjnfeHYT2jnWgWQtRhdvJV7Oi0HtJCfF/2
Z6Tv2oXGsV7g/JPRsgIaLLSjTk0cNZx+yxYQxfeauMdxdK4ZEiaXzbBsjb7f
3NcLA2qFkLJB9ZuoKptv39v/EWnZXK+5lcqvOba+VmZDQfi46NzeUGZLVWA/
rz57jpeiyEls2xm2Ik9NnW/icP+tXedvS3nDL6Wh8K3V/9Feaj5uDb9mvDSp
2QvyZta5R/Ym3IzG8v/9L4yAtvs/IO3iGMZA421vaGxQW3JNV+1ocQQdoL2F
UFUdI0kADApQilGztJHUHAAxh2uXwaQhQmpigmj++X/VyPyfH8h/mFaCEX+9
NdQTfmq8Y/bU2GD2c8tPnVsQv2j6YpgPNJ/aX5B+1ne4f7q/4/7Q+B//GUD/
RN4w+j//2qlNqHVIZH3zQnjReCGMadGj6xVm0AZupN6L+VnrOAaC9TH8LbZy
mOWcjaAANaxJk0zAlTOrmrWbXi6Ibtugh1Dayn9fgGoK2e4hvYCJVvMq+Y7V
1P9AWW3GBS0IRFZsN29D86lHkVsVoTAEhgEYcRr92ul17iSDtCRTa1nzfJhA
VoYsALesKdyO1clKvSurxZkVTJibQeqWW1R+gOHJPu/6Dt7x+tVHfWuMW6L7
FxB/Rp1nhHECR/8A4Uavum+t5k/Q1qHua2B/UrQGtvMVsJ/Z8ieu0Qt5P+La
+bdxfZj7I6ydP4RV+UwXahK5GVhNHpAEYLxsM7DPgb8l8N1vdwY+w2gKib3z
i/8O3r8jUdyyLuSfN8jq3v05MoM3953BLRuBe8Akb/wgB5f7FDu/WPmlVvIK
0hgJQOTm3q8NyXxlKFmzALWi5Hv/ZwuvmTuEEd5wW2jqvm2kqZPf+x6hffA4
Qudhhfvv2DvduM9jft6Y42fWIzVfWdrPOF8G559tttbt08zazzRQiSy2/M+U
7SH6P2xzosdBOj9nAMg9A4CTxWjkF2hEMM36tQHErzNo1693gc304H29hf/Y
lHRukZEfSsM6LGZwA3H77FKH7vqimTt3MWrjvE3EiYMgLmsLAW3793uEzfIq
aDfMNzypDyTbrP97Ez3qsPuwk7sDWOcVcCpwYkkcNYbOKrfZteh+OFCTHsI7
cdeBaU+T1nzEbbi0n1Zt1+lCCKN7lt+SPCeNw0bX/p2BMwCBaIPabRpy6p9h
9w9S/P6x8fl0ufKRUD78pfM04Ic/fKwo8kta5zlwVGiOdWStDR/AxC2rWcNo
3KlzQ7VJc6Hfv0FDe2sIIAXtiD5MbuCUR8AybvbS6nZ9tp3OF4nV95ZOoIVQ
xNudtBqGbAmhTOvIb8NV/+c//9m5AfEGBb213x1+IGfsvf+5BfjR2JwowBEJ
4tfOJ3I/kOGQGw/L1WTkWvx4FQvsEF2yl+Ga80R1st7vpqOjMb2U9syj/9K5
T7r+JvSO9CkURXjpHmZxcoD0m4Fun1FuP2ywQK1AORFSPiFJUVKSg1LtcJkj
nTWY4+d4NzxmFzM5Z4Fc6et8dZ6awLBHy8Hp8CxJjibzChVydb1Nltlo1M2K
vZ9TWM8lbO/A7RVdw47Zcof6wVLwNuT4tFKLgxv6esq9SEKvYiqUIWW4VbHl
9piVs7IwIHU3G3IEwU96e2D7lW+L0gnbblL+lI4mPrnIRqnwLCkGS3FzxmVX
0E3xispWsbV70WwZjahByEfRReOmpYxdXTY+DWTq3M/BSRaEJR5s1s+SFsxB
kk5A7O40dYmCFA0ofpytFXK3KlBwWJ/GKeUV2uqCHUZasVG8Ia6cF9NgvGKG
z5IUTdv1Fs4ezqw39c6GmaiLU3IA60idYYsNlsgj/ejpe4HdVow/MPyVlkr7
ScRy8fhZkt2Pr4SYVIGDy5ueuY4Xy8hgsYBxdv3elDWGB2psTrrKhCvHDDOl
uJm2t7fy6Yg79IsV4Lg+7neTSFobPdNnTVU+ao66d5zRfk1a83hEhS52xLrR
aDrWWUm2ptRqVCQKldnPkvrHaaZT2XVqV1k8HfGYuCnoaOAtk3KHTpbyqqRz
ONR4tdXdfuTPnD2+OM/mynJ3eMFpVaziHSrq3vTCceF8HOAeV67IrUHx29yw
dFJHRaM6aSjp6aNLzyqzfqQek8HAINVnSdQkuxzi7fLQXVR0t09Vu+l6MbYW
KTMLRlxJbZiUiXqic5x5wiEmJ4G3XrAGs9fXs82zJFzfp9EpMGgdoKRzcel0
lk9sgtK6jOOb/Vmkc5OZnsWTwpYTVb0MmNI6RxtV4be9Z0lr/CxpMm+NcXWw
7BtHYmaEWz0u5xdvuxP3PZvXjBNVKLuSJ/bWSURlQOGVd2EibPssSQwxVF1L
BjZhFlPKWE/loqoW4nIwXyqDa3dnTc15au9mnHg5gouqop6ja6I1clhq9Syp
p7DDTWgLR84rjv3xYeoObfG8vgYkOR9FCnCOdi8W7MlY9gP6AFgudem5iRKH
xbh8kdSzZz7FjPOLHg2MdO5wxmWhrbralDRH21jk18EUk6VCx865NmWp0Ti+
7HQ3nByx07Ok48FhtaDbU7bKKjExiT765I47FTah4CPNuuiny3htamjGL9wo
EQ+kT7tA1Po6Ib2wigl6O+mEUlIpqGHp79fz4WK/F6/B4MJNTVECCXAzwhkd
12v0Iq1MtSuegn4qmCUVPUvambqZkaROlrPI2DqAOQuQ9CJ2GlnKAuM5YrAb
T51J7F82+ZgeE0NTDqlxX1p1oxcbp5zVbi3i+4mJmhXPS/6AO9BcN0PNKe7Z
mLG4FFLRk/PjVS/puea5wuZyzMcCJxyoZ0kF0xMX1Xp9OAhFvNi51Wqz8Dgw
HLP0gJWEVSEYZ31QYhqpqMOgP8sWQD4NCUowe+mzJHWz4FV7P3P1Q6Js9HUa
ed1yrDpHvziwCbPu44sQqwB3vfaV0eZ4sfPuYb5QlbOu7J4ljQ+mLS1U9TQF
a3qZ4fRobY6N/AjDyGJ4WVahxhkL78L7630EmSmOL5PhXki4Ferlz5KYterH
FsVnZTgpPZMgC3R3sLdRViouJqaDE7/wXVS4gOTkG4Um5YchzGpL7MAw2osV
sIy9P63ibXSeU/E12S1iWVJtYdw7ySIZB+N041yrMXuOB+fzaLQl9j1P7bPQ
pfaTZ0l67vboaeZNTwNOXizMrXhdsYS7jY86oIV1MLEu3ZUjKpsyOvf6yw2c
+R5mZapmDF+i1DWAC7E5zHWCqaiSXJIOfiJD3PF2Mh30LuN8rjlKz8dnO4+V
Y6MUMaw46jMOFxj+WRK4Hifl6iBjp/KYiVS/Lziy6ngSmxuzYksVmaVeyykt
BSXPHE8WP99LA81MspzZBM+SjPI0K93ldFEcrhMz0efgkA8onZSS2B9Guqc6
k1MQdB0XXCNTHJX51ktIqdh5Iv2CU8WOr/NxxXLuX/6C/Pp7WYqCkAyNM3WG
gr/mKDSGWyZm4LjhoESfRgHuDHCbwSyUsjACwEcMRltOH0X7A4M2GIsaEMwA
MDhFmM+SCNMxflcHcYdgaHMe+v74/HfebrPoug8NE6um9TW1IggUxbH6CQbV
xtEBDi/baT6JfOl3tCtldi1HA8nJDytlOBlk0RgsjKIvxadEkFyM8npgpm9p
oa8nfh8NjuvKV4iJIIovJnraHK6mgw17puK5xElP9kHknHYSXZwm2oSZctx8
6eYAG0/sCTEdo6TLjVSaXqSV8ywpmg4t6CuGUzJezl709BSetoomdTG30Aaz
SlUnMcYX2ibSF4WnJzk7P566YtAl9dmLORBJF9/Y5ZEWZ4N8Hmz2x566NUSs
5HfyCN+78273yKJXr8pIq0+n19wylqG4yynwknBWQ27fH7AWpvcWWbpe6dq5
u9N7403gF17Xns5n8bTYhOSiVNAio2miOGrSuFfyak95SaSCaTxit7tsg1H9
TUoFG4dO5sTFv1gLXqKjbKFMLjJz6A5NQyKV2OGH54QQpvxEcF+C8SJbb3vW
CexjWgbulsU5b7jCe7PtZtkvlvQ5OAmLQaRttwu8ixv7BS/g3Ol68Nb7xQsN
k6wnlgqju+YUhXuh63SXnHVLspbVcLSrMntbGOwhUgsj3G+H46Wabgc0JUhh
Tr+QgsZGOy2WZZFL5SN5lqrZierqM3fAqEBPlOsFHYIeZvCOj2tcbjDLlMym
fD6KqPOLK2s+c5yvC6+AEXznMGNhtO0JM6En8yAaXXZKlOLL0iWJYaFIeB4e
8YCt6JGzuF7Pl2dJmyUMUhcC2DFD7c7UShsqMCIw87Dizl40gZGFp2bTvhPh
3SOdunOBnyVZSiS6J3ovLt1TVpoRHy45iUUcP/ExM4CpfDYMx7Yo05igSBeY
IvLHhSWDZb8PE/Otwi4H0+vyJUHIotHyanrqjnHNSdo3pG1PS82sZ+niUMB4
lF9McfRwDDlHZ2SwkFBvN77M5jHhyS84CXgYMpY/TYqdMogl2hnsCzOQNuV6
T5tEEijWlh8n1WhDquwSMuia6XXZ6BgIqHN9lsQv1+JmHSUs5p2I0UkXXUks
z9Z14vbZVBFWcs8a+Qsh6ufxPD0qhcoYu9jmTlo/eMFpDVM5Vj1t8pkrLoyM
PIMghHsPThqa/sUf0RF5jTkpEoUtVfawvtGtlpsNrqlnTnmx8dlpwuATZyXa
q6BPRXEFyvCgTvQ48dPxdEsNj8C0t9lmjw/YfH+cakYo7KywX+L2S9Iy3EP7
ybJztejNg6jscQOYlWnHZZeWz7Mhnp+dlZLSjjQmgqC3mNllStvois4S2Vq+
6CSKhY+jO3YP9/dymFCEp+QEPyr8VZHZYV9ZZdphdTbUzKWz6qjbOKH0Smnl
T7OX1HVnxFMq1vb7sV4kznlqoZlrdpnTRVdJRxnuF+WFFA5745AW5xXpBMAc
5ilMIArZnL5wgYnzA522CP7MhuaQCg4ncUGhJbbju6U6OCgaRNzweTBU15ix
YXByMRE5L5xM+8cXb0lJXebJQSkOEo5nDiORo9GgGLB9h7h2u76lzJQ5uZeM
XhdugIDCbxgiJDaHQQRewnoooVq0mLjXqb6ICp+dzkFJTiaRM0JPzvmkSqqc
Y+nW4NNBeh2NBOJAa6vZaRljg5fUtYsmEX9abACm0+JlEslwHw20mdHf9AZz
wMkKS84ny4TTLhmG5+VlMybwUboZW0clfJaUOuExcy7h3EBDxwmMpTw7Hgxv
k6Qpn8+vUww4s/24ICOZTDMr0Ceoxy7X2FJP3RfOxHkvmmLbOOflEdHtdQdo
t2DRk3Xa9wW8iqPLJFgpdMaForXzmctqc7EnU0JaHnubl63QlESXQYXl64RR
Y+FQbtg84A/eABOuTGAczKFhbgkt58/2wCqNNbdEj5NhfuVdZ/7y4WArGpl2
VmMKMP3TarTxrufjWMroyM0M9LCbC9gs5dZy93T0VWHMiinGTLZ+qIX89SVN
HB/XTOIymgZNb08eU9femrykng5ZVU1TX+a8Cp9HQNLspT2Jh+VRy6cmn6y8
WYa/JMHCLJkyF1medDkYkMKDZAyokbc7E5ZRpLN9NFigISGJW5etyuku9tDl
FPTkeLciXrkgH3DmzDXHqyWzpbs9rCtqJaOnKmXmy+kcn293oFrv9tXcSKOu
FckCFmnL4DQwRfblw0FoXJcbSZctUuUk5cwKJOaFdl9jB5iPF4yZn/jrIQqV
i+vKs3W2tZbGdDcT+4Y6f8lVUjYvfYzbDzazYG7kSpfPD9pKHLMe7fYIYcIo
uKpNJxaOiX6YldrZ9bDDqEd4+5fIyYxpWRknQ7DFKXsXD6UoX/cCIcwInKBp
ezvHykqaHgxJ2mF+7p8m+0xSo75QbfovHw7sreqOyqNzXWI8oUYey5vZbK6Z
2YANeiTO+YRoJvJ8FwmYK0oWpbAYd9xgY7BnXjIxkM0mOAqZMDcH2+5JXuKb
MYdTWTViAp3Alspy757k/aK3nFWxAOxVuFlOggxdiYcXK5ig5jHrJ/Owt2FZ
kStU2ysC2cgjfSTxO3A5SXy4UieVn1hzRiMXEUtpKdk9VKpQvdj4aLVONPnq
J448GY5N0iYDTc7Ts0cci3Sf9zPFVquuNl8UexNL4V5/o89PMrpi3Zet9Zbb
C2Q0jy4nZc0yzmUwE9ez3ZI9bv14NAkV1S1lcjcKDlFvn/DulOYvBO5VC3Gc
+y/Z4Rlz+X2/F8Kdwaw6kDx1sdiZutFnlch0F4oOoLZUqUaRG+vF/iozEsyv
rzEt8N1nSWVfjKmstz14YTYUlnuryGAmn6Hiak8mqXe09L16ds/MXmDWXWwS
DhaXqm8dkmh6esFJKy8StQ+lsudQ4y6OsQG4DLooE+OV66MiJnG6jk482xiF
l+0lVw7mKOwXi4LJjZdtLHpdkn1itgt8Z3K8ONTUM+OLObXrnflxyx9YIRp3
/dheVULJ++j5bBF9cnckputR9rK5Ykn54vTPm37uyhWZsTtz3g82JC2C48Le
9GaxWbjs0i7QIJ+CaHKA4cOz54V9Xr180ppMDqf5EYP0cbhcbLm/2i8CZbY8
40M2X59cHt3OhHnIjZe+s08ZtNDCACuuhnpdoC8fDjZFENJORAVOMulz2nyv
ZCfM3620wl+XTEHZF19B8a5F6LR0LcLYI2ite0Wnk6r78vloHFTeyQb2kDr2
NZ2f+wzGANLEifBApqer5aZDaiGeos2cXXi4VcSLMebwNF0OBsSzJCtGdzJb
ud1zbw2z+g3mnAp2OjuAbbUdZcdI0ldkUJ4FMKx6xay7CsgTN14x2pifyy+W
aeu6N2JQyjvO9O7Z8jBn2j17rpjHOy/XCXV3XZXmfCT0iPKSL+G+j3e16XHO
8eEL08mL/oLrDhLPich9OFUO23FCx1iOry5JOcd0eVRsUlWrMNJNC16mAYGR
DqrKqn54yVin3YSanzL1aoyurn4euky0751n3BjNdsV4EESnkL2ktKAyc5Ed
DHbpyLJ2oowxjP1iBRhqzjV6M+tW1xNHZNXBVmXOCFZRKfccjykyBgeKfSbR
c4r2FrJ3dbSrtS61ySV+YToFI6/BHPQv0qE7gjnSbDxMFofR0SNBWAhVt2Su
cIsSUb1VZu60hPJ0zYqFJVXlwoskqjfrsp5bSFfoxpOt6ZLKLqbw8prL8fDp
hx4kbl9/pqiPbjp/+ii8fDnZg4/+dC/ark/NPut4ng8An8+OESNJguq90+Gj
uhAn9622avB+NNt/J5qjpv479dqzrq8rsgwxbNtvq2s7L0PVR6nN8Xdd3VIf
pbXq1eeKVlA0R4Fu4dtGZIF7+ZjlxXXFGBzKA7ZbH2JlyJeHb9l7fTaYgZfp
dZr5tAV7n2VlRV2g9lmf38wINEVyzeGhXaTN+XvUlIPc6gfeG0DZuIzc1LDr
Q9KHQozPo+S6OBeCUZ9nhnCadlYfu8E55XHalFYZlgWSvKnbq08TA9BpnkOw
c+8dUQrLqw/I6xLBx471md25COrzzlt1oIHYd1UQI88N6/ij49clEdc4as4U
b0fgZvVwytycrt7r3t4eBH4cWn+vi1Kiz5duskGKWEbUHOcnL4Vnj4eOtXzP
OINm6X6axn3ueXO4nNar+YUqH/I+y+dA1tQgtEvpt8egn1I/n39C+7Pcx3LX
2gxbKXewmrqoLxCr6yh/GLU9/db5K/JnKc4b8AG08Dj98w+4zGHcTLc5gg+N
9IiYbSFnWw3TGOE7sm4e/UB4G9QGBkWVACmSupT8XtDd1GBBH3IckDa1gvci
MDjchzE92xIU4zfFMLWzyKv2c192m1oKbv/6dTUPq7Tnzn5k10qB5pi7qk/p
79Wr5/pvJ+oD56bm+edCgddaxlb77LOu4FaBUH35dx4/FYf/VGeRfbud7j+U
HUS1OD+71XRAXmlrwGvjuo/2o9P5BzJpSm9+9/cPZNvUBj20dP7x9i9+P78A
O91rQn5/pIfSjPtICNuUoCQNV3zZ6dOZPtRDxAiaVgT57fdGuh3GP84J0Wtz
Vm71Tl912r+2wE6b1Igge8Ilev96pP/95587qRl4JNDXMaF6w/2/6rRtjfkD
lq878feA8fV4/0anz/G+7rQGje9ZAPny9w/kl6fyzF9hp7//aP865S/fJFDe
x/mphKgx5G+/dToQyU3jlHVxrAkg0UbxRzj7KOTPbn+Gci9svxV+fNSA+Nkn
mbUlRc0SGm00urva7Q8ZTMjeTV2TdYziMoBBtNY9g5q35UnA/ss3xwgyUOu3
WbLLzv8DdkEmgAs3AAA=

-->

</rfc>
