
From nobody Wed Sep 13 07:47:13 2017
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E21A132DFB for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 07:47:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.4
X-Spam-Level: 
X-Spam-Status: No, score=-5.4 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k3GoUiuEXGuC for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 07:46:58 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DFBE0132949 for <fud@ietf.org>; Wed, 13 Sep 2017 07:46:57 -0700 (PDT)
Received: from [192.168.91.203] ([131.111.5.143]) by mail.gmx.com (mrgmx001 [212.227.17.190]) with ESMTPSA (Nemesis) id 0McmFl-1e9Oo835Hd-00HyjZ; Wed, 13 Sep 2017 16:46:53 +0200
To: Russ Housley <housley@vigilsec.com>
Cc: fud@ietf.org
References: <8f8528da-d1eb-08c7-b3fe-b1f4febed595@gmx.net> <C2FC414A-7DF9-4293-91D4-C050CB591440@vigilsec.com>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <4666e022-7b57-29e8-28b9-21a7f193f26f@gmx.net>
Date: Wed, 13 Sep 2017 16:46:52 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <C2FC414A-7DF9-4293-91D4-C050CB591440@vigilsec.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:oXvmrvZuqp554DHWYuG9taGE+nZGdcxj95+SZTql6qpW88E5LrL XQpEgCRSgjuAm/S/eC39KTfaXSJ+5AbukZZa1YhENn3KmxcKXB87sP0LxRv1UJdO8b8xgvw eLuHA42NTDBAcZb/BxB2/UFsxQyxJ8mSN5PGHBlSJAbtutllJSK7urQOSSY6TxMoWp0DurK lnApMzWfMORkjAnbJe2Ng==
X-UI-Out-Filterresults: notjunk:1;V01:K0:okH3xaIxLHk=:EKg4hyGWCcIsNPfey2uRCq /Hj8+n53zK9rLyKT1IZnhLelXeb9j/Ye+MLumQBVyOlz5w2VcEhi9Vh3Q78U7Gz/NMBr90H2C NJQTzbfZ04M3J5fMFy0GxOGafr7+fiJ8jDVg2hPV3wN32aT8geOc1hQgarD1Aft1RYaTognSN 1F8ZOnN9zdpSMSVX9Cfn/UYIotxTmoQVgDCjr1+04iweYC1q/2kFdDVBfRFJU/7vRD7OefgGl kI7bkC/OHkItlfnxt7dSO9gbAf9tcK6TEdJx+3wbl+0HzioX+zpibgFCLGLsChmAPEzb/H6Ba L2bksJDC9AM6uaawbj8pyT/M6knBKCtC3UuAtU/d1mz/9qRqtcXsmv9MGKt44WukM9QmlLRRC y/0DqMOVFte2oBAK7faCuP2AiUehWWCGWxpCjOekbP6oaLSosyd9RG7eM74aeNvRY9++0dXqz hE0bHQkmyc7aS+i9xeyAQFfmwAPaoHkrq2By9mXTC3ovNPrzjtrlUsDa2MUEMeCNQeHjy3lAw d/nJ6r/cZp3Kp2INJ0seEngHI6yN0/mEWw4cRuNf6b7jShIIi3t+vHJGnAZhIIz1t26YZ2JzT WYlrTSl3tgN6Ci+3jQxhhdH5wrtuh475+bhhupfVFKlPYuQUmchhT4UjGtOhvYgFH5nWZFgEk zeJ/iW6Ocq5XuiJcB5+LRTD3BeCaPPA9tnsDfNbtfqSWl58ybZ4pP2mC9rdXcyTp7Mgv/URny H8jgycIu4DM0tM3uje8SFkQK8GwtY/DZV3wUXvJ6Nf/d8vhSZ0DOK27qpDzmZQVB0d+Z4NO6u Fl6N/wxhFlIHrp1oUdks0JiOb/fP2UxuuHZqOto2ZhB9OzlT5w=
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/jlXfaoSV4nbt579sdyRrLa8Tmkg>
Subject: Re: [Fud] Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Sep 2017 14:47:00 -0000

Hi Russ,

thanks for your feedback.

A few remarks below:

On 08/14/2017 03:05 PM, Russ Housley wrote:
> I'm jumping into this conversation after vacation.  I have read the whole thread to date before composing this note.
> 
> 
>> Firmware Updating Description (FUD)
> 
> The page that Kathleen set up call this group Firmware UpDate (FUD).
> 
> 
>> Vulnerabilities with Internet of Things (IoT) devices have raised the
>> need for a secure firmware update mechanism that is also suitable for
>> constrained devices. Security experts, researchers and regulators
>> recommend that all IoT devices are equipped with such a mechanism. While
>> there are many proprietary firmware update mechanisms in use today there
>> is a lack of an modern interoperable approach of securely updating IoT
>> devices.
>>
>> A firmware update solution consists of several components, including a
>> mechanism to transport firmware images to IoT devices and a manifest
>> that provides meta-data about the firmware image as well as
>> cryptographic information for protecting the firmware image in an
>> end-to-end fashion. With RFC 4018 the IETF standardized a manifest
>> format that uses the Cryptographic Message Syntax (CMS) to protect
>> firmware packages.
> 
> There are some vital pieces of information that need to be conveyed, but from the above text, it is not clear to me whether they are expected to be in the manifest and meta-data.  The vital data includes:
> 
>    - a firmware package identifier;
>    - whether the package is a patch or upgrade;
>    - the hardware the package needs to run;
>    - dependencies on other firmware packages; and
>    - if the package is encrypted to protect intellectual property, the key needed to decrypt it.
> 
-----

The above-listed information is expected to be included in the manifest.
Maybe the paragraph should be expanded in the following way:

A firmware update solution consists of several components, including
* a mechanism to transport firmware images to IoT devices,
* a manifest that provides meta-data about the firmware image (such as a
firmware package identifier, the hardware the package needs to run,
dependencies on other firmware packages, etc.) as well as
cryptographic information for protecting the firmware image in an
end-to-end fashion, and
* the firmware image itself.
With RFC 4018 the IETF standardized a manifest format that uses the
Cryptographic Message Syntax (CMS) to protect firmware packages.

-----
Do you think that this is better text?

> 
>> Since the publication of RFC 4108 more than 10 years have passed and
>> more experience with IoT deployments have lead to additional
>> functionality requiring the work done with RFC 4108 to be revisited. The
>> purpose of this group is to standardize a version 2 of RFC 4108 that
>> reflects best current practices. This group will not define any
>> transport mechanism.
>>
>> In 2016 the Internet Architecture Board organized a workshop on
>> 'Internet of Things (IoT) Software Update (IOTSU)', which took place at
>> Trinity College Dublin, Ireland on the 13th and 14th of June, 2016. The
> 
> 13-14 June 2016
OK.


> 
>> main goal of the workshop was to foster a discussion on requirements,
>> challenges and solutions for bringing software and firmware updates to
>> IoT devices. This workshop also made clear that there are challenges
>> with lack of regulatory requirements, and misaligned incentives. It is
>> nevertheless seen as important to standardize the building blocks that
>> help interested parties to implement and deploy a solid firmware update
>> mechanism.
>>
>> In particular this group aims to publish two documents, namely
>> * an IoT firmware update architecture that includes a description of
>> the involved entities, security threats and assumptions, and
>> * the manifest format itself.
> 
> The text a few paragraphs ago made me think that rfc4108bis was an output.  Why is it not here?
> 
>> This group does not aim to standardize a generic software update
>> mechanism used by rich operating systems, like Linux, but instead
>> focuses on software development practices in the embedded industry.
> 
> This should be expanded to make it clear that JavaScript is not a goal either.
> 

Good point.

-----

This group does not aim to standardize a generic software update
mechanism used by rich operating systems, like Linux, but instead
focuses on software development practices in the embedded industry.
Software update solutions that aim to take the features of scripting
languages, such as JavaScript variants like JerryScript, into account
are also outside the scope of this group.

-----

>> This group will aim to develop a close relationship with silicon vendors
>> and OEMs that develop IoT operating systems.
>>
>> Milestones
>>
>> Dec 2017     Submit "Architecture" document as WG item.
>>
>> Dec 2017     Submit "Manifest Format" specification as WG item.
>>
>> Jul 2018    Submit "Architecture" to the IESG for publication as an
>> Informational RFC.
>>
>> Nov 2018     Submit "Manifest Format" to the IESG for publication as a
>> Proposed Standard.
> 
> The text a few paragraphs ago made me think that rfc4108bis was an output.  Why is it not here?
I didn't use the term "rfc4108bis" but instead called it "manifest format".

Ciao
Hannes

> Russ
> 


From nobody Wed Sep 13 07:51:26 2017
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16FA2132DFB for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 07:51:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.119
X-Spam-Level: 
X-Spam-Status: No, score=-2.119 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NXPE0QMuV017 for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 07:51:17 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2377132949 for <fud@ietf.org>; Wed, 13 Sep 2017 07:51:16 -0700 (PDT)
Received: from [192.168.91.203] ([131.111.5.143]) by mail.gmx.com (mrgmx002 [212.227.17.190]) with ESMTPSA (Nemesis) id 0M9Jss-1dipsX2cyU-00Cm7h; Wed, 13 Sep 2017 16:51:11 +0200
To: Michael Richardson <mcr+ietf@sandelman.ca>, fud@ietf.org
References: <C64FB690-1EB9-46A0-989F-DAC57E1CA819@riot-os.org> <eb247364-e4d6-1c22-c882-0e53df6c2902@gmx.net> <525.1503422326@dooku.sandelman.ca>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <3d78ce15-553e-2423-3185-95e789fca3d5@gmx.net>
Date: Wed, 13 Sep 2017 16:51:10 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <525.1503422326@dooku.sandelman.ca>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:FCQ4WhQE+EmuVJP4kBwnYExhXe7ilMcIBVHzpIKlBWnSBcdOVaa 9DwiZJl04Pn56Vo0z7r9d47YG2JNfU9Snf1toOCsN7rrbRimmsugt3FLclYc8l3lJABmGSp ju5WGjf1DpGXjjxPRZaxBwc0z/YyvKgMerEyl/pss0OJ83+PD5JRw/7s6PxCckHvQopcE4T wJ1lotq4PgPBWVF2Ya4kA==
X-UI-Out-Filterresults: notjunk:1;V01:K0:ofsMZusZHpM=:lKPcTjwrON5g0OZZHPwJ6i THH7ljA0DFLVYyojSo90KzVc8eFUHXXmPSleD41t4W2YkVC5Ntq5zwy+MCFcR4+lree2sToVP IUKi7BYSwXC05N7kDnJM5mV/NLgKP47lg6mT4NDhUsBTn6caEBWHZfbg70WNVrVJzl/ZI2E59 0EL97O5BUjSCKU3W/MdbLTEU55G45+O1zbqROqRXEnQkek0sinb1rnonl8bgtHQAdtrf+tMPO lWohy5NQv1bt/HJpY3OuPbpMVfrLBAMivDVi/JcAsw+LlqdY7/528me6okq5bKpKXtFfnd/K6 VCiLTHbTyZ6Lt3qo8/HzxM3xROx1iw7iSZHuCdAOqCnTEd6LHCgtmklkROg8GRAZro6/33xm0 yXROsRGTthBzm04Lrz0Yod107D3zKXMLjoQSlHwRldIxdcHhTUXZ7nPA3/RbPOsJj6DHSzFPL 9HShwIEnnKz+k5yTHwropxULWux8RQQK9ofjCsBqdIGBG/v2FjiHZH/KYXKemQAM+33KtT4oR /MpFkoMiu2Ujp30/sUxhL/7vtgDha10JnNIWeDJmzEJCv28MmMa9fLAVNeiQe3AXldQ6tksOF Rwlr9+lqmt8Mq8u0mBpObBGKgGeA0tyj8wCNtssipOCvqD3vtf7qfV+d/217i5CNkIRF8PklQ JYtFBmLA/AQHirnysWRve5TAY3tu9BjCgFLg5VKa8+CM7MrB9xb78E65EHG0WYXV3zhNWrRAq 5C2QUITVl/9p/T9VZLy05FIl3Uk3gL8dAJnXRXk+q4dk2I3YwskLQR+pS3K6buHVSXxqQdTj9 KpWg6Z95kR1yy6EHt3H/I4Xw3Ju6yGiRvYFoUiR4ig44om9BQg=
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/rYF2_l_wtxQejRwj2C9_GakRFHw>
Subject: Re: [Fud] Comment on draft-moran-fud-manifest-00
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Sep 2017 14:51:24 -0000

Hi Michael,

here is my take on this issue: I don't think that the idea of having
multiple parties sign the manifest so that the device can check all the
signatures in order to decide whether the vendor, enterprise operator,
and regulator "agreed" on deploying a specific firmware update for a
medical device. I think that this is a too heavy for an IoT device and
too much policy for the device to consider. While this is not impossible
to do (even with the proposed manifest format) I believe it is more
likely that the party providing the firmware update to the IoT device
will make that policy decision (which will typically involve humans).

Hence, I think we need to make sure that the common case works well. If
someone wants to do research on the other option that's fine for me as
well.

Ciao
Hannes


On 08/22/2017 07:18 PM, Michael Richardson wrote:
> 
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     > Hi Thomas,
> 
>     > interesting idea.
> 
>     > As an optional feature I don't see a problem with it.
> 
>     > How exactly the approval process for applying a firmware update in a
>     > particular product looks like will of course vary a lot. At the IOTSU
>     > workshop we had people describing a healthcare setting where any code
>     > changes need to go through certification first. In smart home
>     > environments the firmware updates are most likely facing fewer
>     > regulatory restrictions.
> 
> I think that the regulated (e.g. health-care) situation is different than
> the security vs feature update situation.
> 
> In the regulated situation, I can see two ways to go about the process:
>   a) devices have a built-in policy that requires signatures from X,Y and Z
>      before they will apply them.
> 
>   b) devices have a built-in policy that will accept updates on from Z
>      (the regulator)
>      Z has a policy where it only reviews things once X and Y
>      have signed.  Applying the signature from Z may remove the signature
>      from X and Y (that's a space optimization only).
>      As the device does not recognize X or Y, it would ignore those signatures.
> 
> Whereas, Thomas is suggesting that when any of X, Y or Z signs, it would
> include some kind of flag (probably an OID?) saying the reason for the
> update.
> (Maybe we'd want to also have optional space for a URL pointing at update notes)
> 
>     > On 08/11/2017 12:37 AM, Thomas Eichinger wrote:
>     >> Hi,
>     >>
>     >> reading draft-moran-fud-manifest-00 I am wondering what people think
>     >> about adding a component to the manifest classifying the described
>     >> update as a security and/or feature update (others are imaginable) in
>     >> a machine-readable manner.
>     >>
>     >> The use case I see is that users then can define rules to deploy
>     >> security only updates in an automated timely fashion while being able
>     >> to review others before. Similar to Directive.applyImmediately but not
>     >> forced by the Author of the update.
>     >>
>     >> Any opinions on that?
>     >>
>     >> Best, Thomas
>     >>
>     >> _______________________________________________ Fud mailing list
>     >> Fud@ietf.org https://www.ietf.org/mailman/listinfo/fud
>     >>
> 
>     > _______________________________________________ Fud mailing list
>     > Fud@ietf.org https://www.ietf.org/mailman/listinfo/fud
> 
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting =-
> 
> 
> 
> 
> 
> _______________________________________________
> Fud mailing list
> Fud@ietf.org
> https://www.ietf.org/mailman/listinfo/fud
> 


From nobody Wed Sep 13 07:52:11 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A47C7133055 for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 07:52:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HdqwnmcewnL8 for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 07:52:07 -0700 (PDT)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 447AE132DFB for <fud@ietf.org>; Wed, 13 Sep 2017 07:52:07 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 830A0300564 for <fud@ietf.org>; Wed, 13 Sep 2017 10:52:06 -0400 (EDT)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id Sysd4lVmt4E9 for <fud@ietf.org>; Wed, 13 Sep 2017 10:52:04 -0400 (EDT)
Received: from [5.5.33.84] (vpn.snozzages.com [204.42.252.17]) by mail.smeinc.net (Postfix) with ESMTPSA id 4BCE630044B; Wed, 13 Sep 2017 10:52:04 -0400 (EDT)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <4666e022-7b57-29e8-28b9-21a7f193f26f@gmx.net>
Date: Wed, 13 Sep 2017 10:52:08 -0400
Cc: fud@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <991B3FD8-E317-44C0-9A10-44311083B5DD@vigilsec.com>
References: <8f8528da-d1eb-08c7-b3fe-b1f4febed595@gmx.net> <C2FC414A-7DF9-4293-91D4-C050CB591440@vigilsec.com> <4666e022-7b57-29e8-28b9-21a7f193f26f@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/hHAHlMdS1EowZN6Kzic2SFjHONI>
Subject: Re: [Fud] Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Sep 2017 14:52:09 -0000

Thanks for addressing my comments.

Russ


> On Sep 13, 2017, at 10:46 AM, Hannes Tschofenig =
<hannes.tschofenig@gmx.net> wrote:
>=20
> Hi Russ,
>=20
> thanks for your feedback.
>=20
> A few remarks below:
>=20
> On 08/14/2017 03:05 PM, Russ Housley wrote:
>> I'm jumping into this conversation after vacation.  I have read the =
whole thread to date before composing this note.
>>=20
>>=20
>>> Firmware Updating Description (FUD)
>>=20
>> The page that Kathleen set up call this group Firmware UpDate (FUD).
>>=20
>>=20
>>> Vulnerabilities with Internet of Things (IoT) devices have raised =
the
>>> need for a secure firmware update mechanism that is also suitable =
for
>>> constrained devices. Security experts, researchers and regulators
>>> recommend that all IoT devices are equipped with such a mechanism. =
While
>>> there are many proprietary firmware update mechanisms in use today =
there
>>> is a lack of an modern interoperable approach of securely updating =
IoT
>>> devices.
>>>=20
>>> A firmware update solution consists of several components, including =
a
>>> mechanism to transport firmware images to IoT devices and a manifest
>>> that provides meta-data about the firmware image as well as
>>> cryptographic information for protecting the firmware image in an
>>> end-to-end fashion. With RFC 4018 the IETF standardized a manifest
>>> format that uses the Cryptographic Message Syntax (CMS) to protect
>>> firmware packages.
>>=20
>> There are some vital pieces of information that need to be conveyed, =
but from the above text, it is not clear to me whether they are expected =
to be in the manifest and meta-data.  The vital data includes:
>>=20
>>   - a firmware package identifier;
>>   - whether the package is a patch or upgrade;
>>   - the hardware the package needs to run;
>>   - dependencies on other firmware packages; and
>>   - if the package is encrypted to protect intellectual property, the =
key needed to decrypt it.
>>=20
> -----
>=20
> The above-listed information is expected to be included in the =
manifest.
> Maybe the paragraph should be expanded in the following way:
>=20
> A firmware update solution consists of several components, including
> * a mechanism to transport firmware images to IoT devices,
> * a manifest that provides meta-data about the firmware image (such as =
a
> firmware package identifier, the hardware the package needs to run,
> dependencies on other firmware packages, etc.) as well as
> cryptographic information for protecting the firmware image in an
> end-to-end fashion, and
> * the firmware image itself.
> With RFC 4018 the IETF standardized a manifest format that uses the
> Cryptographic Message Syntax (CMS) to protect firmware packages.
>=20
> -----
> Do you think that this is better text?
>=20
>>=20
>>> Since the publication of RFC 4108 more than 10 years have passed and
>>> more experience with IoT deployments have lead to additional
>>> functionality requiring the work done with RFC 4108 to be revisited. =
The
>>> purpose of this group is to standardize a version 2 of RFC 4108 that
>>> reflects best current practices. This group will not define any
>>> transport mechanism.
>>>=20
>>> In 2016 the Internet Architecture Board organized a workshop on
>>> 'Internet of Things (IoT) Software Update (IOTSU)', which took place =
at
>>> Trinity College Dublin, Ireland on the 13th and 14th of June, 2016. =
The
>>=20
>> 13-14 June 2016
> OK.
>=20
>=20
>>=20
>>> main goal of the workshop was to foster a discussion on =
requirements,
>>> challenges and solutions for bringing software and firmware updates =
to
>>> IoT devices. This workshop also made clear that there are challenges
>>> with lack of regulatory requirements, and misaligned incentives. It =
is
>>> nevertheless seen as important to standardize the building blocks =
that
>>> help interested parties to implement and deploy a solid firmware =
update
>>> mechanism.
>>>=20
>>> In particular this group aims to publish two documents, namely
>>> * an IoT firmware update architecture that includes a description of
>>> the involved entities, security threats and assumptions, and
>>> * the manifest format itself.
>>=20
>> The text a few paragraphs ago made me think that rfc4108bis was an =
output.  Why is it not here?
>>=20
>>> This group does not aim to standardize a generic software update
>>> mechanism used by rich operating systems, like Linux, but instead
>>> focuses on software development practices in the embedded industry.
>>=20
>> This should be expanded to make it clear that JavaScript is not a =
goal either.
>>=20
>=20
> Good point.
>=20
> -----
>=20
> This group does not aim to standardize a generic software update
> mechanism used by rich operating systems, like Linux, but instead
> focuses on software development practices in the embedded industry.
> Software update solutions that aim to take the features of scripting
> languages, such as JavaScript variants like JerryScript, into account
> are also outside the scope of this group.
>=20
> -----
>=20
>>> This group will aim to develop a close relationship with silicon =
vendors
>>> and OEMs that develop IoT operating systems.
>>>=20
>>> Milestones
>>>=20
>>> Dec 2017     Submit "Architecture" document as WG item.
>>>=20
>>> Dec 2017     Submit "Manifest Format" specification as WG item.
>>>=20
>>> Jul 2018    Submit "Architecture" to the IESG for publication as an
>>> Informational RFC.
>>>=20
>>> Nov 2018     Submit "Manifest Format" to the IESG for publication as =
a
>>> Proposed Standard.
>>=20
>> The text a few paragraphs ago made me think that rfc4108bis was an =
output.  Why is it not here?
> I didn't use the term "rfc4108bis" but instead called it "manifest =
format".
>=20
> Ciao
> Hannes
>=20
>> Russ
>>=20
>=20
> _______________________________________________
> Fud mailing list
> Fud@ietf.org
> https://www.ietf.org/mailman/listinfo/fud


From nobody Wed Sep 13 12:59:06 2017
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E30A132EE2 for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 12:59:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T4esNiLWntuR for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 12:59:02 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 966E0132ED1 for <fud@ietf.org>; Wed, 13 Sep 2017 12:59:02 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 66F9BE1D3; Wed, 13 Sep 2017 16:03:16 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 7F67480CFA; Wed, 13 Sep 2017 15:59:01 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
cc: fud@ietf.org
In-Reply-To: <3d78ce15-553e-2423-3185-95e789fca3d5@gmx.net>
References: <C64FB690-1EB9-46A0-989F-DAC57E1CA819@riot-os.org> <eb247364-e4d6-1c22-c882-0e53df6c2902@gmx.net> <525.1503422326@dooku.sandelman.ca> <3d78ce15-553e-2423-3185-95e789fca3d5@gmx.net>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature"
Date: Wed, 13 Sep 2017 15:59:01 -0400
Message-ID: <28070.1505332741@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/kYv2hg38_o590SWr20P-WrV3IdU>
Subject: Re: [Fud] Comment on draft-moran-fud-manifest-00
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Sep 2017 19:59:04 -0000

--=-=-=
Content-Type: text/plain


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > and regulator "agreed" on deploying a specific firmware update for a
    > medical device. I think that this is a too heavy for an IoT device and
    > too much policy for the device to consider. While this is not
    > impossible

I agree with you, and that's situation (b) that I described.

    > to do (even with the proposed manifest format) I believe it is more
    > likely that the party providing the firmware update to the IoT device
    > will make that policy decision (which will typically involve humans).

    >> b) devices have a built-in policy that will accept updates on from Z
    >> (the regulator)
    >> Z has a policy where it only reviews things once X and Y
    >> have signed.  Applying the signature from Z may remove the signature
    >> from X and Y (that's a space optimization only).
    >> As the device does not recognize X or Y, it would ignore those
    >> signatures.

The question is, can the signatures from X and Y *remain* for the purposes
of auditing?  Removing them then becomes an option, rather than a requirement.


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAlm5jgUACgkQgItw+93Q
3WVnOQf8CvmwV02+wg6hHl/sP3QLm5+QmOUiqJj1BYutuxubnVbnWw/YrewwFQGH
u+zkfSm9za/i1YOq8z8YoRR45Cqh46k8ZFi0UTZDpVXSO5+VKS9Obf+cHAzqb00U
F3IZPRkrAb5CViAfUaX0FEL+X4W8ciQZW1h3KsQDsJnNhfajOyMJmUhQHFhV/Xc3
bOVbh8JgDvIbL95Vg2bS2z7U56b41jJYVcD1ddWtKnSon6BdV+MJF/kYBBZZ0CiN
6nHQNFve8tCgJJwYHDamjdKrz53wSzhw7JBBlQiEtcW7tz7/JSw5JaIq07hPRlI5
+p5Uv73fOL3fwqvCIKxYEpWT2AwTSQ==
=wTyD
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Sep 13 14:02:10 2017
Return-Path: <Brendan.Moran@arm.com>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA21513305C for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 14:02:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.699
X-Spam-Level: 
X-Spam-Status: No, score=-4.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0xS_4WUgUMbd for <fud@ietfa.amsl.com>; Wed, 13 Sep 2017 14:02:06 -0700 (PDT)
Received: from EUR02-HE1-obe.outbound.protection.outlook.com (mail-eopbgr10045.outbound.protection.outlook.com [40.107.1.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DDAF413293A for <fud@ietf.org>; Wed, 13 Sep 2017 14:02:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com;  s=selector1-arm-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=NEIhSkLT+1EakWnKEJkKpR7I4uIqO0Kwr+Gtnzbhpkg=; b=Dpl9ucamcmlcGZUuMP0ROEb1ByzQHgYsq7rteV3z47FZd92m/31hqRdYZgF9V0nHkN9Ak6WEsZE7/xZZteHzYF0yFilZXPLBVAScGNIDiXuA6jIuKz1GPWCUEpNNNvdutGnnoYVKHC+G0E1MsUowVoz8V0V4L8aCvHgddHr597M=
Received: from AM4PR08MB2836.eurprd08.prod.outlook.com (10.171.191.30) by AM4PR08MB1171.eurprd08.prod.outlook.com (10.167.92.15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.35.12; Wed, 13 Sep 2017 21:02:02 +0000
Received: from AM4PR08MB2836.eurprd08.prod.outlook.com ([fe80::a9dd:f699:8eb0:48da]) by AM4PR08MB2836.eurprd08.prod.outlook.com ([fe80::a9dd:f699:8eb0:48da%13]) with mapi id 15.20.0013.012; Wed, 13 Sep 2017 21:02:03 +0000
From: Brendan Moran <Brendan.Moran@arm.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, Hannes Tschofenig <hannes.tschofenig@gmx.net>
CC: "fud@ietf.org" <fud@ietf.org>
Thread-Topic: [Fud] Comment on draft-moran-fud-manifest-00
Thread-Index: AQHTGzpw87DvXLX1n0OjsiyXTL7otqKQnvcAgCJqDQCAAFYDgIAAEJec
Date: Wed, 13 Sep 2017 21:02:03 +0000
Message-ID: <AM4PR08MB2836AC6C1608244AE937346AEA6E0@AM4PR08MB2836.eurprd08.prod.outlook.com>
References: <C64FB690-1EB9-46A0-989F-DAC57E1CA819@riot-os.org> <eb247364-e4d6-1c22-c882-0e53df6c2902@gmx.net> <525.1503422326@dooku.sandelman.ca> <3d78ce15-553e-2423-3185-95e789fca3d5@gmx.net>, <28070.1505332741@obiwan.sandelman.ca>
In-Reply-To: <28070.1505332741@obiwan.sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Brendan.Moran@arm.com; 
x-originating-ip: [217.140.96.140]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; AM4PR08MB1171; 6:utuHtpyiK1JP0wfjDmnUDOUogYzaA5osX04ovJBFT2oJ7pzfVoThMBHfzhuWCxH/wGKmotQOkBqYZFowxBnUhbLv3esDnlwdrLCI26CXEIpe/O0zYuuU5Yy5lSeZIMNYk7V8Y4mNoNSGOWPmT62Zb1f0gJPShkSbzh6Jqi4AG+wx+6Lgj4nlJ6/i7nshRu7U37eSK4vxePWpBf8JWwQmsXu0aFVTJO6tTJzMvn70iZuPItxeFw3tUON97fy91XRxe4cKtjNl4kVhp3SXf/fTD4lYZfTtFxNRz53YILyZzD9s+3WnaBikEK8cr8Qe2ugV7CoI7Fr7A5ykcM1O0DjjuQ==; 5:IwFS5GyRtUahLfEls99BVNKha6ljcMugtmnq3zJVBLC92yGOnQ75LIbx6QPO+4x3MiLmC9p37V9w7wun2eGCzy4Co3blY2TedLj4tPkpAodCMxC9kEjIF2QwTY9CO5SzklS79XQ0GU9sip/QFJPnwA==; 24:qxqWOevojk0wM1jPkClc5ajDfICMZpZiEM7gSZYOdnxpL0QvwSxknoNlW7PO7X5uJ6b6sghTMLwq1BRV+H+RbEWkuLD3995qcGX88ouHpqM=; 7:RLwku1yjmmdsP3viIXKwLVeaHVi1djRt+l/+eRMcYsXeG/untpEpx3Jxht1qkFitTkDRdbXQrt+8K177GSLJxs6OdmuPAvQ1SuWxeVMyZgjLh49XY3TBQaxMeqm6Pxszqn5SqouusamkJ7WrTnnaSE4tiGwPYH6HWPBl3GyqtfJJdoWqUZgVZqzjV+WtRC6SIurTboJvbcoaSq99NvjijtwzLikZzeU6oFcPERVRpM4=
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 6a12ab31-3086-4866-0f66-08d4faeaaf00
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(300000502095)(300135100095)(22001)(2017030254152)(48565401081)(300000503095)(300135400095)(2017052603199)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:AM4PR08MB1171; 
x-ms-traffictypediagnostic: AM4PR08MB1171:
x-exchange-antispam-report-test: UriScan:(158342451672863)(248736688235697);
x-microsoft-antispam-prvs: <AM4PR08MB117170DC1B8FA18FB5DEED82EA6E0@AM4PR08MB1171.eurprd08.prod.outlook.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(93006095)(93001095)(100000703101)(100105400095)(3002001)(10201501046)(6055026)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123560025)(20161123564025)(20161123562025)(20161123558100)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:AM4PR08MB1171; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:AM4PR08MB1171; 
x-forefront-prvs: 042957ACD7
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(39860400002)(346002)(376002)(199003)(377454003)(189002)(24454002)(51444003)(40434004)(97736004)(6436002)(2906002)(106356001)(6246003)(54356999)(76176999)(50986999)(2950100002)(189998001)(105586002)(5890100001)(54896002)(5250100002)(53936002)(93886005)(9686003)(6116002)(230783001)(3846002)(102836003)(6506006)(101416001)(99286003)(55016002)(68736007)(66066001)(14454004)(478600001)(8676002)(3660700001)(7736002)(7696004)(8936002)(229853002)(81166006)(81156014)(74316002)(5660300001)(4326008)(72206003)(86362001)(33656002)(53546010)(3280700002)(2900100001)(25786009)(316002); DIR:OUT; SFP:1101; SCL:1; SRVR:AM4PR08MB1171; H:AM4PR08MB2836.eurprd08.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_AM4PR08MB2836AC6C1608244AE937346AEA6E0AM4PR08MB2836eurp_"
MIME-Version: 1.0
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Sep 2017 21:02:03.0921 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR08MB1171
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/l8xsdEJextyLy-tJqKmt6xJCHm8>
Subject: Re: [Fud] Comment on draft-moran-fud-manifest-00
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Sep 2017 21:02:09 -0000

--_000_AM4PR08MB2836AC6C1608244AE937346AEA6E0AM4PR08MB2836eurp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

I think this comes down to a matter of configuration. Devices need to be co=
nfigured to either:

  1.  require at least one signature to match
  2.  require all signatures to match


I don't see a reason not to support both modes of operation.


Brendan

________________________________
From: Fud <fud-bounces@ietf.org> on behalf of Michael Richardson <mcr+ietf@=
sandelman.ca>
Sent: Wednesday, September 13, 2017 8:59:01 PM
To: Hannes Tschofenig
Cc: fud@ietf.org
Subject: Re: [Fud] Comment on draft-moran-fud-manifest-00


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > and regulator "agreed" on deploying a specific firmware update for a
    > medical device. I think that this is a too heavy for an IoT device an=
d
    > too much policy for the device to consider. While this is not
    > impossible

I agree with you, and that's situation (b) that I described.

    > to do (even with the proposed manifest format) I believe it is more
    > likely that the party providing the firmware update to the IoT device
    > will make that policy decision (which will typically involve humans).

    >> b) devices have a built-in policy that will accept updates on from Z
    >> (the regulator)
    >> Z has a policy where it only reviews things once X and Y
    >> have signed.  Applying the signature from Z may remove the signature
    >> from X and Y (that's a space optimization only).
    >> As the device does not recognize X or Y, it would ignore those
    >> signatures.

The question is, can the signatures from X and Y *remain* for the purposes
of auditing?  Removing them then becomes an option, rather than a requireme=
nt.


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-



IMPORTANT NOTICE: The contents of this email and any attachments are confid=
ential and may also be privileged. If you are not the intended recipient, p=
lease notify the sender immediately and do not disclose the contents to any=
 other person, use it for any purpose, or store or copy the information in =
any medium. Thank you.

--_000_AM4PR08MB2836AC6C1608244AE937346AEA6E0AM4PR08MB2836eurp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; pad=
ding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content=3D"text/html; charset=3DUTF-8">
<style type=3D"text/css" style=3D"">
<!--
p
	{margin-top:0;
	margin-bottom:0}
-->
</style>
<div dir=3D"ltr">
<div id=3D"x_divtagdefaultwrapper" dir=3D"ltr" style=3D"font-size:12pt; col=
or:#000000; font-family:Calibri,Helvetica,sans-serif">
<p>I think this comes down to a matter of configuration. Devices need to be=
 configured to either:</p>
<p></p>
<ol style=3D"margin-bottom:0px; margin-top:0px">
<li><span style=3D"font-size:12pt"></span><span style=3D"font-size:12pt">re=
quire at least one signature to match</span><br>
</li><li><span style=3D"font-size:12pt">require all signatures to match</sp=
an></li></ol>
<p></p>
<p><br>
</p>
<p>I don't see a reason not to support both modes of operation.</p>
<p><br>
</p>
<p>Brendan</p>
</div>
<hr tabindex=3D"-1" style=3D"display:inline-block; width:98%">
<div id=3D"x_divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" =
color=3D"#000000" style=3D"font-size:11pt"><b>From:</b> Fud &lt;fud-bounces=
@ietf.org&gt; on behalf of Michael Richardson &lt;mcr&#43;ietf@sandelman.ca=
&gt;<br>
<b>Sent:</b> Wednesday, September 13, 2017 8:59:01 PM<br>
<b>To:</b> Hannes Tschofenig<br>
<b>Cc:</b> fud@ietf.org<br>
<b>Subject:</b> Re: [Fud] Comment on draft-moran-fud-manifest-00</font>
<div>&nbsp;</div>
</div>
</div>
<font size=3D"2"><span style=3D"font-size:10pt;">
<div class=3D"PlainText"><br>
Hannes Tschofenig &lt;hannes.tschofenig@gmx.net&gt; wrote:<br>
&nbsp;&nbsp;&nbsp; &gt; and regulator &quot;agreed&quot; on deploying a spe=
cific firmware update for a<br>
&nbsp;&nbsp;&nbsp; &gt; medical device. I think that this is a too heavy fo=
r an IoT device and<br>
&nbsp;&nbsp;&nbsp; &gt; too much policy for the device to consider. While t=
his is not<br>
&nbsp;&nbsp;&nbsp; &gt; impossible<br>
<br>
I agree with you, and that's situation (b) that I described.<br>
<br>
&nbsp;&nbsp;&nbsp; &gt; to do (even with the proposed manifest format) I be=
lieve it is more<br>
&nbsp;&nbsp;&nbsp; &gt; likely that the party providing the firmware update=
 to the IoT device<br>
&nbsp;&nbsp;&nbsp; &gt; will make that policy decision (which will typicall=
y involve humans).<br>
<br>
&nbsp;&nbsp;&nbsp; &gt;&gt; b) devices have a built-in policy that will acc=
ept updates on from Z<br>
&nbsp;&nbsp;&nbsp; &gt;&gt; (the regulator)<br>
&nbsp;&nbsp;&nbsp; &gt;&gt; Z has a policy where it only reviews things onc=
e X and Y<br>
&nbsp;&nbsp;&nbsp; &gt;&gt; have signed.&nbsp; Applying the signature from =
Z may remove the signature<br>
&nbsp;&nbsp;&nbsp; &gt;&gt; from X and Y (that's a space optimization only)=
.<br>
&nbsp;&nbsp;&nbsp; &gt;&gt; As the device does not recognize X or Y, it wou=
ld ignore those<br>
&nbsp;&nbsp;&nbsp; &gt;&gt; signatures.<br>
<br>
The question is, can the signatures from X and Y *remain* for the purposes<=
br>
of auditing?&nbsp; Removing them then becomes an option, rather than a requ=
irement.<br>
<br>
<br>
--<br>
Michael Richardson &lt;mcr&#43;IETF@sandelman.ca&gt;, Sandelman Software Wo=
rks<br>
&nbsp;-=3D IPv6 IoT consulting =3D-<br>
<br>
<br>
<br>
</div>
</span></font>IMPORTANT NOTICE: The contents of this email and any attachme=
nts are confidential and may also be privileged. If you are not the intende=
d recipient, please notify the sender immediately and do not disclose the c=
ontents to any other person, use
 it for any purpose, or store or copy the information in any medium. Thank =
you.
</body>
</html>

--_000_AM4PR08MB2836AC6C1608244AE937346AEA6E0AM4PR08MB2836eurp_--


From nobody Fri Sep 15 08:29:51 2017
Return-Path: <ned.smith@intel.com>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0197E132713 for <fud@ietfa.amsl.com>; Fri, 15 Sep 2017 08:29:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.92
X-Spam-Level: 
X-Spam-Status: No, score=-6.92 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i5mNmSLMKXu2 for <fud@ietfa.amsl.com>; Fri, 15 Sep 2017 08:29:48 -0700 (PDT)
Received: from mga01.intel.com (mga01.intel.com [192.55.52.88]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5FE20132153 for <Fud@ietf.org>; Fri, 15 Sep 2017 08:29:45 -0700 (PDT)
Received: from fmsmga001.fm.intel.com ([10.253.24.23]) by fmsmga101.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 15 Sep 2017 08:29:31 -0700
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="5.42,397,1500966000";  d="scan'208,217";a="1195481079"
Received: from orsmsx102.amr.corp.intel.com ([10.22.225.129]) by fmsmga001.fm.intel.com with ESMTP; 15 Sep 2017 08:29:31 -0700
Received: from orsmsx109.amr.corp.intel.com ([169.254.11.66]) by ORSMSX102.amr.corp.intel.com ([169.254.3.17]) with mapi id 14.03.0319.002; Fri, 15 Sep 2017 08:29:31 -0700
From: "Smith, Ned" <ned.smith@intel.com>
To: "Fud@ietf.org" <Fud@ietf.org>
Thread-Topic: A few questions / observations
Thread-Index: AQHTLjdsLe1oeSwl+Em8FCdFITDsKg==
Date: Fri, 15 Sep 2017 15:29:30 +0000
Message-ID: <D531874E-95BF-4A12-8049-15794BCD1039@intel.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/f.21.0.170409
x-originating-ip: [10.24.10.81]
Content-Type: multipart/alternative; boundary="_000_D531874E95BF4A12804915794BCD1039intelcom_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/ML2v6c5Xe949Hl9DASVjj8e_r_w>
Subject: [Fud] A few questions / observations
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Sep 2017 15:29:50 -0000

--_000_D531874E95BF4A12804915794BCD1039intelcom_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

wrcgICAgICAgICBJcyBpdCBwb3NzaWJsZSBmb3IgdGhlIGltYWdlIHR5cGUgdG8gYmUgYW4gZXhp
c3Rpbmcg4oCcbWFuaWZlc3TigJ0gc3VjaCBhcyDigJxwYWNrYWdlc+KAnSBvciDigJxidW5kbGVz
4oCdPw0KDQrCtyAgICAgICAgIElzIHRoZSBwdXNoIG1vZGVsIHN1cHBvcnRlZCAoY2xvdWQgc3Rv
cmFnZSBwdXNoZXMgdXBkYXRlIGZpbGUgcHJvYWN0aXZlbHkpPw0KDQrCtyAgICAgICAgIFdoeSB3
YXMgQVNOLjEgc2VsZWN0ZWQgYXMgdGhlIGVuY29kaW5nIGZvcm1hdD8gKFdoeSBub3QgQ09TRT8p
DQoNCsK3ICAgICAgICAgSXQgaXNu4oCZdCBjbGVhciBob3cgdGhlIG1hbmlmZXN0IGFuZCB0aGUg
aW1hZ2UgKHBhY2thZ2UgLyBidW5kbGUpIHdpbGwgc2hhcmUgdGhlIGF2YWlsYWJsZSBBIC9CIHN0
b3JhZ2UgYXJlYS4gUG9zc2libHkgaXQgaXMgYXNzdW1lZCB0aGUgbWFuaWZlc3QgcmVsYXRlZCBv
cGVyYXRpb25zIGFyZSB0byBiZSBpbnRlZ3JhdGVkIGludG8gYW4gZXhpc3RpbmcgU1cgdXBkYXRl
IGNhcGFiaWxpdHkgYW5kIGJlIHRhdWdodCB0byB1bmRlcnN0YW5kIHRoZSBtYW5pZmVzdCBzdHJ1
Y3R1cmUuIENvbnNpZGVyIHRoZSBjYXNlIHdoZXJlIHZlcnNpb24gMSBvZiBhIFNXIHVwZGF0ZSB0
b29sIHVuZGVyc3RhbmRzIGJ1bmRsZXMgYnV0IGl0IHJlY2VpdmVzIGEgZmlsZSB0aGF0IGNvbnRh
aW5zIGEgbWFuaWZlc3QuIElzIGl0IGV4cGVjdGVkIHRoYXQgdGhlIHYxIHRvb2wgd2lsbCBiZSBh
YmxlIHRvIHByb2Nlc3MgdGhlIHVwZGF0ZSBuZXZlcnRoZWxlc3MgKGlnbm9yaW5nIHRoZSBtYW5p
ZmVzdCkuIFRoaXMgYXNzdW1lcyB0aGUgZW5jcnlwdGlvbiBvcHRpb24gaXNu4oCZdCBiZWluZyBh
cHBsaWVkIG9mIGNvdXJzZS4NCg0KwrcgICAgICAgICBUaGUgYXJjaCBkaWRu4oCZdCBtZW50aW9u
IGludGVncml0eSBhcyBhIHJlcXVpcmVtZW50LiBNYXliZSBpdCBpcyBpbXBsaWVkIGJ1dCBpdCBz
ZWVtcyBwb3NzaWJsZSBmb3IgYSBjbGV2ZXIgYXR0YWNrZXIgdG8gcmVwbGFjZSBvbmUgY2lwaGVy
IHRleHQgd2l0aCBhIGRpZmZlcmVudCBjaXBoZXIgdGV4dCB1bmxlc3MgaW50ZWdyaXR5IHdlcmUg
bWVudGlvbmVkIGFzIGEgZ29hbCBhbmQgc3RlcHMgdGFrZW4gdG8gYWxsb3cgb25seSBjaXBoZXIg
c3VpdGVzIHRoYXQgYWNoaWV2ZSBib3RoIG9iamVjdGl2ZXMuDQoNCsK3ICAgICAgICAgVGhlcmUg
aXMgbm8gbWVudGlvbiBvZiB3aGljaCBjcnlwdG8gYWxnb3JpdGhtcyB3aWxsIGJlIHN1cHBvcnRl
ZC4NCg0KwrcgICAgICAgICBUaGVyZSBhcmUgc3RpbGwgYSBmZXcgdHlwb3MuDQoNCg==

--_000_D531874E95BF4A12804915794BCD1039intelcom_
Content-Type: text/html; charset="utf-8"
Content-ID: <1EF0BD84A8BFA541ADD3E58633DDDBB0@intel.com>
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6bz0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6b2ZmaWNlIiB4
bWxuczp3PSJ1cm46c2NoZW1hcy1taWNyb3NvZnQtY29tOm9mZmljZTp3b3JkIiB4bWxuczptPSJo
dHRwOi8vc2NoZW1hcy5taWNyb3NvZnQuY29tL29mZmljZS8yMDA0LzEyL29tbWwiIHhtbG5zPSJo
dHRwOi8vd3d3LnczLm9yZy9UUi9SRUMtaHRtbDQwIj4NCjxoZWFkPg0KPG1ldGEgaHR0cC1lcXVp
dj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWw7IGNoYXJzZXQ9dXRmLTgiPg0KPG1l
dGEgbmFtZT0iVGl0bGUiIGNvbnRlbnQ9IiI+DQo8bWV0YSBuYW1lPSJLZXl3b3JkcyIgY29udGVu
dD0iIj4NCjxtZXRhIG5hbWU9IkdlbmVyYXRvciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUg
KGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxlPjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8N
CkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IkNvdXJpZXIgTmV3IjsNCglwYW5vc2UtMToyIDcg
MyA5IDIgMiA1IDIgNCA0O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6V2luZ2RpbmdzOw0K
CXBhbm9zZS0xOjUgMCAwIDAgMCAwIDAgMCAwIDA7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWls
eToiQ2FtYnJpYSBNYXRoIjsNCglwYW5vc2UtMToyIDQgNSAzIDUgNCA2IDMgMiA0O30NCkBmb250
LWZhY2UNCgl7Zm9udC1mYW1pbHk6RGVuZ1hpYW47DQoJcGFub3NlLTE6MiAxIDYgMCAzIDEgMSAx
IDEgMTt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAx
NSA1IDIgMiAyIDQgMyAyIDQ7fQ0KLyogU3R5bGUgRGVmaW5pdGlvbnMgKi8NCnAuTXNvTm9ybWFs
LCBsaS5Nc29Ob3JtYWwsIGRpdi5Nc29Ob3JtYWwNCgl7bWFyZ2luOjBpbjsNCgltYXJnaW4tYm90
dG9tOi4wMDAxcHQ7DQoJZm9udC1zaXplOjEyLjBwdDsNCglmb250LWZhbWlseTpDYWxpYnJpO30N
CmE6bGluaywgc3Bhbi5Nc29IeXBlcmxpbmsNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCWNv
bG9yOiMwNTYzQzE7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQphOnZpc2l0ZWQsIHNw
YW4uTXNvSHlwZXJsaW5rRm9sbG93ZWQNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCWNvbG9y
OiM5NTRGNzI7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQpwLk1zb0xpc3RQYXJhZ3Jh
cGgsIGxpLk1zb0xpc3RQYXJhZ3JhcGgsIGRpdi5Nc29MaXN0UGFyYWdyYXBoDQoJe21zby1zdHls
ZS1wcmlvcml0eTozNDsNCgltYXJnaW4tdG9wOjBpbjsNCgltYXJnaW4tcmlnaHQ6MGluOw0KCW1h
cmdpbi1ib3R0b206MGluOw0KCW1hcmdpbi1sZWZ0Oi41aW47DQoJbWFyZ2luLWJvdHRvbTouMDAw
MXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6Q2FsaWJyaTt9DQpzcGFuLkVt
YWlsU3R5bGUxNw0KCXttc28tc3R5bGUtdHlwZTpwZXJzb25hbC1jb21wb3NlOw0KCWZvbnQtZmFt
aWx5OkNhbGlicmk7DQoJY29sb3I6d2luZG93dGV4dDt9DQpzcGFuLm1zb0lucw0KCXttc28tc3R5
bGUtdHlwZTpleHBvcnQtb25seTsNCgltc28tc3R5bGUtbmFtZToiIjsNCgl0ZXh0LWRlY29yYXRp
b246dW5kZXJsaW5lOw0KCWNvbG9yOnRlYWw7fQ0KLk1zb0NocERlZmF1bHQNCgl7bXNvLXN0eWxl
LXR5cGU6ZXhwb3J0LW9ubHk7DQoJZm9udC1mYW1pbHk6Q2FsaWJyaTt9DQpAcGFnZSBXb3JkU2Vj
dGlvbjENCgl7c2l6ZTo4LjVpbiAxMS4waW47DQoJbWFyZ2luOjEuMGluIDEuMGluIDEuMGluIDEu
MGluO30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7cGFnZTpXb3JkU2VjdGlvbjE7fQ0KLyogTGlzdCBE
ZWZpbml0aW9ucyAqLw0KQGxpc3QgbDANCgl7bXNvLWxpc3QtaWQ6MTMxOTQ2NzE5Ow0KCW1zby1s
aXN0LXR5cGU6aHlicmlkOw0KCW1zby1saXN0LXRlbXBsYXRlLWlkczoxNzIyNTU4OTU4IDY3Njk4
Njg5IDY3Njk4NjkxIDY3Njk4NjkzIDY3Njk4Njg5IDY3Njk4NjkxIDY3Njk4NjkzIDY3Njk4Njg5
IDY3Njk4NjkxIDY3Njk4NjkzO30NCkBsaXN0IGwwOmxldmVsMQ0KCXttc28tbGV2ZWwtbnVtYmVy
LWZvcm1hdDpidWxsZXQ7DQoJbXNvLWxldmVsLXRleHQ674K3Ow0KCW1zby1sZXZlbC10YWItc3Rv
cDpub25lOw0KCW1zby1sZXZlbC1udW1iZXItcG9zaXRpb246bGVmdDsNCgl0ZXh0LWluZGVudDot
LjI1aW47DQoJZm9udC1mYW1pbHk6U3ltYm9sO30NCkBsaXN0IGwwOmxldmVsMg0KCXttc28tbGV2
ZWwtbnVtYmVyLWZvcm1hdDpidWxsZXQ7DQoJbXNvLWxldmVsLXRleHQ6bzsNCgltc28tbGV2ZWwt
dGFiLXN0b3A6bm9uZTsNCgltc28tbGV2ZWwtbnVtYmVyLXBvc2l0aW9uOmxlZnQ7DQoJdGV4dC1p
bmRlbnQ6LS4yNWluOw0KCWZvbnQtZmFtaWx5OiJDb3VyaWVyIE5ldyI7fQ0KQGxpc3QgbDA6bGV2
ZWwzDQoJe21zby1sZXZlbC1udW1iZXItZm9ybWF0OmJ1bGxldDsNCgltc28tbGV2ZWwtdGV4dDrv
gqc7DQoJbXNvLWxldmVsLXRhYi1zdG9wOm5vbmU7DQoJbXNvLWxldmVsLW51bWJlci1wb3NpdGlv
bjpsZWZ0Ow0KCXRleHQtaW5kZW50Oi0uMjVpbjsNCglmb250LWZhbWlseTpXaW5nZGluZ3M7fQ0K
QGxpc3QgbDA6bGV2ZWw0DQoJe21zby1sZXZlbC1udW1iZXItZm9ybWF0OmJ1bGxldDsNCgltc28t
bGV2ZWwtdGV4dDrvgrc7DQoJbXNvLWxldmVsLXRhYi1zdG9wOm5vbmU7DQoJbXNvLWxldmVsLW51
bWJlci1wb3NpdGlvbjpsZWZ0Ow0KCXRleHQtaW5kZW50Oi0uMjVpbjsNCglmb250LWZhbWlseTpT
eW1ib2w7fQ0KQGxpc3QgbDA6bGV2ZWw1DQoJe21zby1sZXZlbC1udW1iZXItZm9ybWF0OmJ1bGxl
dDsNCgltc28tbGV2ZWwtdGV4dDpvOw0KCW1zby1sZXZlbC10YWItc3RvcDpub25lOw0KCW1zby1s
ZXZlbC1udW1iZXItcG9zaXRpb246bGVmdDsNCgl0ZXh0LWluZGVudDotLjI1aW47DQoJZm9udC1m
YW1pbHk6IkNvdXJpZXIgTmV3Ijt9DQpAbGlzdCBsMDpsZXZlbDYNCgl7bXNvLWxldmVsLW51bWJl
ci1mb3JtYXQ6YnVsbGV0Ow0KCW1zby1sZXZlbC10ZXh0Ou+CpzsNCgltc28tbGV2ZWwtdGFiLXN0
b3A6bm9uZTsNCgltc28tbGV2ZWwtbnVtYmVyLXBvc2l0aW9uOmxlZnQ7DQoJdGV4dC1pbmRlbnQ6
LS4yNWluOw0KCWZvbnQtZmFtaWx5OldpbmdkaW5nczt9DQpAbGlzdCBsMDpsZXZlbDcNCgl7bXNv
LWxldmVsLW51bWJlci1mb3JtYXQ6YnVsbGV0Ow0KCW1zby1sZXZlbC10ZXh0Ou+CtzsNCgltc28t
bGV2ZWwtdGFiLXN0b3A6bm9uZTsNCgltc28tbGV2ZWwtbnVtYmVyLXBvc2l0aW9uOmxlZnQ7DQoJ
dGV4dC1pbmRlbnQ6LS4yNWluOw0KCWZvbnQtZmFtaWx5OlN5bWJvbDt9DQpAbGlzdCBsMDpsZXZl
bDgNCgl7bXNvLWxldmVsLW51bWJlci1mb3JtYXQ6YnVsbGV0Ow0KCW1zby1sZXZlbC10ZXh0Om87
DQoJbXNvLWxldmVsLXRhYi1zdG9wOm5vbmU7DQoJbXNvLWxldmVsLW51bWJlci1wb3NpdGlvbjps
ZWZ0Ow0KCXRleHQtaW5kZW50Oi0uMjVpbjsNCglmb250LWZhbWlseToiQ291cmllciBOZXciO30N
CkBsaXN0IGwwOmxldmVsOQ0KCXttc28tbGV2ZWwtbnVtYmVyLWZvcm1hdDpidWxsZXQ7DQoJbXNv
LWxldmVsLXRleHQ674KnOw0KCW1zby1sZXZlbC10YWItc3RvcDpub25lOw0KCW1zby1sZXZlbC1u
dW1iZXItcG9zaXRpb246bGVmdDsNCgl0ZXh0LWluZGVudDotLjI1aW47DQoJZm9udC1mYW1pbHk6
V2luZ2RpbmdzO30NCm9sDQoJe21hcmdpbi1ib3R0b206MGluO30NCnVsDQoJe21hcmdpbi1ib3R0
b206MGluO30NCi0tPjwvc3R5bGU+DQo8L2hlYWQ+DQo8Ym9keSBiZ2NvbG9yPSJ3aGl0ZSIgbGFu
Zz0iRU4tVVMiIGxpbms9IiMwNTYzQzEiIHZsaW5rPSIjOTU0RjcyIj4NCjxkaXYgY2xhc3M9Ildv
cmRTZWN0aW9uMSI+DQo8cCBjbGFzcz0iTXNvTGlzdFBhcmFncmFwaCIgc3R5bGU9InRleHQtaW5k
ZW50Oi0uMjVpbjttc28tbGlzdDpsMCBsZXZlbDEgbGZvMSI+PCFbaWYgIXN1cHBvcnRMaXN0c10+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6U3ltYm9sIj48c3BhbiBz
dHlsZT0ibXNvLWxpc3Q6SWdub3JlIj7CtzxzcGFuIHN0eWxlPSJmb250OjcuMHB0ICZxdW90O1Rp
bWVzIE5ldyBSb21hbiZxdW90OyI+Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7
Jm5ic3A7Jm5ic3A7DQo8L3NwYW4+PC9zcGFuPjwvc3Bhbj48IVtlbmRpZl0+PHNwYW4gc3R5bGU9
ImZvbnQtc2l6ZToxMS4wcHQiPklzIGl0IHBvc3NpYmxlIGZvciB0aGUgaW1hZ2UgdHlwZSB0byBi
ZSBhbiBleGlzdGluZyDigJxtYW5pZmVzdOKAnSBzdWNoIGFzIOKAnHBhY2thZ2Vz4oCdIG9yIOKA
nGJ1bmRsZXPigJ0/PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb0xpc3RQYXJh
Z3JhcGgiIHN0eWxlPSJ0ZXh0LWluZGVudDotLjI1aW47bXNvLWxpc3Q6bDAgbGV2ZWwxIGxmbzEi
PjwhW2lmICFzdXBwb3J0TGlzdHNdPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQt
ZmFtaWx5OlN5bWJvbCI+PHNwYW4gc3R5bGU9Im1zby1saXN0Oklnbm9yZSI+wrc8c3BhbiBzdHls
ZT0iZm9udDo3LjBwdCAmcXVvdDtUaW1lcyBOZXcgUm9tYW4mcXVvdDsiPiZuYnNwOyZuYnNwOyZu
YnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOw0KPC9zcGFuPjwvc3Bhbj48L3NwYW4+
PCFbZW5kaWZdPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0Ij5JcyB0aGUgcHVzaCBtb2Rl
bCBzdXBwb3J0ZWQgKGNsb3VkIHN0b3JhZ2UgcHVzaGVzIHVwZGF0ZSBmaWxlIHByb2FjdGl2ZWx5
KT88bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTGlzdFBhcmFncmFwaCIgc3R5
bGU9InRleHQtaW5kZW50Oi0uMjVpbjttc28tbGlzdDpsMCBsZXZlbDEgbGZvMSI+PCFbaWYgIXN1
cHBvcnRMaXN0c10+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6U3lt
Ym9sIj48c3BhbiBzdHlsZT0ibXNvLWxpc3Q6SWdub3JlIj7CtzxzcGFuIHN0eWxlPSJmb250Ojcu
MHB0ICZxdW90O1RpbWVzIE5ldyBSb21hbiZxdW90OyI+Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7
Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7DQo8L3NwYW4+PC9zcGFuPjwvc3Bhbj48IVtlbmRpZl0+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQiPldoeSB3YXMgQVNOLjEgc2VsZWN0ZWQgYXMg
dGhlIGVuY29kaW5nIGZvcm1hdD8gKFdoeSBub3QgQ09TRT8pPG86cD48L286cD48L3NwYW4+PC9w
Pg0KPHAgY2xhc3M9Ik1zb0xpc3RQYXJhZ3JhcGgiIHN0eWxlPSJ0ZXh0LWluZGVudDotLjI1aW47
bXNvLWxpc3Q6bDAgbGV2ZWwxIGxmbzEiPjwhW2lmICFzdXBwb3J0TGlzdHNdPjxzcGFuIHN0eWxl
PSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OlN5bWJvbCI+PHNwYW4gc3R5bGU9Im1zby1s
aXN0Oklnbm9yZSI+wrc8c3BhbiBzdHlsZT0iZm9udDo3LjBwdCAmcXVvdDtUaW1lcyBOZXcgUm9t
YW4mcXVvdDsiPiZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNw
Ow0KPC9zcGFuPjwvc3Bhbj48L3NwYW4+PCFbZW5kaWZdPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
MTEuMHB0Ij5JdCBpc27igJl0IGNsZWFyIGhvdyB0aGUgbWFuaWZlc3QgYW5kIHRoZSBpbWFnZSAo
cGFja2FnZSAvIGJ1bmRsZSkgd2lsbCBzaGFyZSB0aGUgYXZhaWxhYmxlIEEgL0Igc3RvcmFnZSBh
cmVhLiBQb3NzaWJseSBpdCBpcyBhc3N1bWVkIHRoZSBtYW5pZmVzdCByZWxhdGVkIG9wZXJhdGlv
bnMgYXJlIHRvIGJlIGludGVncmF0ZWQgaW50byBhbiBleGlzdGluZw0KIFNXIHVwZGF0ZSBjYXBh
YmlsaXR5IGFuZCBiZSB0YXVnaHQgdG8gdW5kZXJzdGFuZCB0aGUgbWFuaWZlc3Qgc3RydWN0dXJl
LiBDb25zaWRlciB0aGUgY2FzZSB3aGVyZSB2ZXJzaW9uIDEgb2YgYSBTVyB1cGRhdGUgdG9vbCB1
bmRlcnN0YW5kcyBidW5kbGVzIGJ1dCBpdCByZWNlaXZlcyBhIGZpbGUgdGhhdCBjb250YWlucyBh
IG1hbmlmZXN0LiBJcyBpdCBleHBlY3RlZCB0aGF0IHRoZSB2MSB0b29sIHdpbGwgYmUgYWJsZSB0
byBwcm9jZXNzIHRoZQ0KIHVwZGF0ZSBuZXZlcnRoZWxlc3MgKGlnbm9yaW5nIHRoZSBtYW5pZmVz
dCkuIFRoaXMgYXNzdW1lcyB0aGUgZW5jcnlwdGlvbiBvcHRpb24gaXNu4oCZdCBiZWluZyBhcHBs
aWVkIG9mIGNvdXJzZS48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTGlzdFBh
cmFncmFwaCIgc3R5bGU9InRleHQtaW5kZW50Oi0uMjVpbjttc28tbGlzdDpsMCBsZXZlbDEgbGZv
MSI+PCFbaWYgIXN1cHBvcnRMaXN0c10+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6U3ltYm9sIj48c3BhbiBzdHlsZT0ibXNvLWxpc3Q6SWdub3JlIj7CtzxzcGFuIHN0
eWxlPSJmb250OjcuMHB0ICZxdW90O1RpbWVzIE5ldyBSb21hbiZxdW90OyI+Jm5ic3A7Jm5ic3A7
Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7DQo8L3NwYW4+PC9zcGFuPjwvc3Bh
bj48IVtlbmRpZl0+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQiPlRoZSBhcmNoIGRpZG7i
gJl0IG1lbnRpb24gaW50ZWdyaXR5IGFzIGEgcmVxdWlyZW1lbnQuIE1heWJlIGl0IGlzIGltcGxp
ZWQgYnV0IGl0IHNlZW1zIHBvc3NpYmxlIGZvciBhIGNsZXZlciBhdHRhY2tlciB0byByZXBsYWNl
IG9uZSBjaXBoZXIgdGV4dCB3aXRoIGEgZGlmZmVyZW50IGNpcGhlciB0ZXh0IHVubGVzcyBpbnRl
Z3JpdHkgd2VyZSBtZW50aW9uZWQNCiBhcyBhIGdvYWwgYW5kIHN0ZXBzIHRha2VuIHRvIGFsbG93
IG9ubHkgY2lwaGVyIHN1aXRlcyB0aGF0IGFjaGlldmUgYm90aCBvYmplY3RpdmVzLjxvOnA+PC9v
OnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29MaXN0UGFyYWdyYXBoIiBzdHlsZT0idGV4dC1p
bmRlbnQ6LS4yNWluO21zby1saXN0OmwwIGxldmVsMSBsZm8xIj48IVtpZiAhc3VwcG9ydExpc3Rz
XT48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTpTeW1ib2wiPjxzcGFu
IHN0eWxlPSJtc28tbGlzdDpJZ25vcmUiPsK3PHNwYW4gc3R5bGU9ImZvbnQ6Ny4wcHQgJnF1b3Q7
VGltZXMgTmV3IFJvbWFuJnF1b3Q7Ij4mbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJz
cDsmbmJzcDsmbmJzcDsNCjwvc3Bhbj48L3NwYW4+PC9zcGFuPjwhW2VuZGlmXT48c3BhbiBzdHls
ZT0iZm9udC1zaXplOjExLjBwdCI+VGhlcmUgaXMgbm8gbWVudGlvbiBvZiB3aGljaCBjcnlwdG8g
YWxnb3JpdGhtcyB3aWxsIGJlIHN1cHBvcnRlZC48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBj
bGFzcz0iTXNvTGlzdFBhcmFncmFwaCIgc3R5bGU9InRleHQtaW5kZW50Oi0uMjVpbjttc28tbGlz
dDpsMCBsZXZlbDEgbGZvMSI+PCFbaWYgIXN1cHBvcnRMaXN0c10+PHNwYW4gc3R5bGU9ImZvbnQt
c2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6U3ltYm9sIj48c3BhbiBzdHlsZT0ibXNvLWxpc3Q6SWdu
b3JlIj7CtzxzcGFuIHN0eWxlPSJmb250OjcuMHB0ICZxdW90O1RpbWVzIE5ldyBSb21hbiZxdW90
OyI+Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7DQo8L3Nw
YW4+PC9zcGFuPjwvc3Bhbj48IVtlbmRpZl0+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQi
PlRoZXJlIGFyZSBzdGlsbCBhIGZldyB0eXBvcy48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdCI+PG86cD4mbmJz
cDs8L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2JvZHk+DQo8L2h0bWw+DQo=

--_000_D531874E95BF4A12804915794BCD1039intelcom_--


From nobody Tue Sep 19 16:59:58 2017
Return-Path: <thomas@riot-os.org>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E3FA7133011 for <fud@ietfa.amsl.com>; Tue, 19 Sep 2017 16:59:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JdKspuVannjJ for <fud@ietfa.amsl.com>; Tue, 19 Sep 2017 16:59:55 -0700 (PDT)
Received: from mail.stillroot.org (mail.stillroot.org [176.9.132.253]) by ietfa.amsl.com (Postfix) with ESMTP id F417C132944 for <fud@ietf.org>; Tue, 19 Sep 2017 16:59:54 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.stillroot.org (Postfix) with ESMTP id D1E5D42F6C; Wed, 20 Sep 2017 01:59:23 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at ba.stillroot.org
Received: from mail.stillroot.org ([127.0.0.1]) by localhost (mail.stillroot.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JIHVY9ruyIfx; Wed, 20 Sep 2017 01:59:17 +0200 (CEST)
Received: from [192.168.1.66] (unknown [IPv6:2602:306:36e3:3580:1d7a:6a27:c0ff:e24f]) by mail.stillroot.org (Postfix) with ESMTPSA id A94084269D; Wed, 20 Sep 2017 01:59:16 +0200 (CEST)
From: "Thomas Eichinger" <thomas@riot-os.org>
To: "Hannes Tschofenig" <hannes.tschofenig@gmx.net>
Cc: fud@ietf.org
Date: Tue, 19 Sep 2017 16:59:14 -0700
Message-ID: <9A771B0B-A182-4C29-B283-99B8282560FA@riot-os.org>
In-Reply-To: <eb247364-e4d6-1c22-c882-0e53df6c2902@gmx.net>
References: <C64FB690-1EB9-46A0-989F-DAC57E1CA819@riot-os.org> <eb247364-e4d6-1c22-c882-0e53df6c2902@gmx.net>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (2.0BETAr6090)
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/uOEnxjoe5rM82N7ip2edDd11M0I>
Subject: Re: [Fud] Comment on draft-moran-fud-manifest-00
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Sep 2017 23:59:57 -0000

Hi Hannes,

First, I'm sorry for the massive latency.

I'd be ok with having it as an optional feature but maybe bound to an 
optional textual description.
Meaning if you provide a textual description also provide a machine 
readable classification or only a classification one or neither. What do 
you think?

Totally agree with you regarding certification and regulation. The 
proposed addition in my opinion just allows for a wider variety of 
update strategies while some others might just ignore it.

Best,
Thomas


On 22 Aug 2017, at 4:33 PDT(-0700), Hannes Tschofenig wrote:

> Hi Thomas,
>
> interesting idea.
>
> As an optional feature I don't see a problem with it.
>
> How exactly the approval process for applying a firmware update in a
> particular product looks like will of course vary a lot. At the IOTSU
> workshop we had people describing a healthcare setting where any code
> changes need to go through certification first. In smart home
> environments the firmware updates are most likely facing fewer
> regulatory restrictions.
>
> Ciao
> Hannes
>
>
>
> On 08/11/2017 12:37 AM, Thomas Eichinger wrote:
>> Hi,
>>
>> reading draft-moran-fud-manifest-00 I am wondering what people think 
>> about
>> adding a component to the manifest classifying the described update 
>> as a
>> security and/or feature update (others are imaginable) in a 
>> machine-readable
>> manner.
>>
>> The use case I see is that users then can define rules to deploy 
>> security
>> only updates in an automated timely fashion while being able to 
>> review
>> others before. Similar to Directive.applyImmediately but not forced 
>> by the
>> Author of the update.
>>
>> Any opinions on that?
>>
>> Best,
>> Thomas
>>
>> _______________________________________________
>> Fud mailing list
>> Fud@ietf.org
>> https://www.ietf.org/mailman/listinfo/fud
>>


From nobody Mon Sep 25 11:07:25 2017
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C1CA413451F for <fud@ietfa.amsl.com>; Mon, 25 Sep 2017 11:07:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level: 
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eM3_2BZp8QYb for <fud@ietfa.amsl.com>; Mon, 25 Sep 2017 11:07:23 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B34AE1330B2 for <fud@ietf.org>; Mon, 25 Sep 2017 11:07:22 -0700 (PDT)
Received: from [192.168.91.203] ([80.92.122.248]) by mail.gmx.com (mrgmx001 [212.227.17.190]) with ESMTPSA (Nemesis) id 0Lkwc9-1dOIph1LgD-00ajnQ for <fud@ietf.org>; Mon, 25 Sep 2017 20:07:20 +0200
To: fud@ietf.org
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net>
Date: Mon, 25 Sep 2017 20:07:19 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:FI/0TPaq4b3SO9mWNBpfPaDHnP+9VJx/8AwpZ9e8xOH0bw+x94O UPGYQDRtrNfE/BgcwBk6IDxOEDNYZeac1DAkGSD/+sHlA173w1xlNQssw/8TSvuQnKrad3d /uyQMCAaFSE+1FBX2l/xDtQh2jw8mBNrURG+QTASjec38gAtUShHvwPBINEDCa+0QGwJr9c 2GhxIvOG1ylHi/rkNCP7A==
X-UI-Out-Filterresults: notjunk:1;V01:K0:X+s44UFeSfE=:NsTwYZr4GeFKlulQI+1/Ot c/n/a3ohaxU6fWdg7Wppcu+zKYaZXP0Sn7G/Y0z22S4YlPKez/sfaXisojRmGEui0yPcewqnO ObUAzHXOkdlOyO62EWW0XYY8G67lYMLcOQCv989flyM81ILfw81+Fpxp6x1UqPMKH0aEvkUO8 xVqwOt8bPKPP2LBYJa7U5VqHUbmNwb6qAc5r8LrpsQ/pxmyPHrSeCaiq1oXKCWFu4ohSrV+cs 7w37aPx02LrW/udCNA3/Xwcf/aDqzvozTZq62anuorULAqW3cWU7HOk2al31D0QkfIRCmn2Lx VLqTiG7Ff8zF2zwlvN9eHRSS0UxsUA2qc2G3VVgg0WwR0QizANZzg5DAPopsxoP8S866NhgRO mbJUuOB64d0uzm0Usa8MDpQkIRRFOYzpX+1neDJKqWO7P7cm2ZOBai4flLqJ+yloybPUfY7i2 0jU3tsE0bE6kntP+rXYrrBlDdOKPxoswiAsIhGRuTHhptFpIwdqzUjn/8CEcjXGrW8HtS+v3g arE+n9QnN/7eMKD/6qYxiX8SUC0NP7F1mnx1rwiLL77Ev9wobIrhVoQubra51lfrtCZIjdpwN 8+9B0dw5iA4+OUin+dmTeGAiu06YYUm1psZlPqMCr/OfYrpAoCzlaLWunFQjqXSZ6aNo+pHJx 3zAwuQGbCC/KOye885ZY6ry7KC++WfMP2i1jSth5nlY0nUbtaG88JK0fHe+eRyWG05/BkYEMq lwa7g6dSmHoUCax4XCPp6IXzwZBEibVlIA1DfWG51vDEcezrqlT44IcFJRKE7fdSa4SFPIUx1 YAKAaP5EGeYTuXL/pPk81B3P5bDgqUyhi65LUqSWVGa4CiXeEM=
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/ldoLD2yf6gdBEemTKB7kpYW-z9I>
Subject: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Sep 2017 18:07:25 -0000

Based on the feedback following the IETF meeting in Prague I have
updated the charter text.

Ciao
Hannes

----

Firmware Updating Description (FUD)
[Alternative proposal: SUIT (Software Updates for Internet of Things).]

Vulnerabilities with Internet of Things (IoT) devices have raised the
need for a secure firmware update mechanism that is also suitable for
constrained devices. Security experts, researchers and regulators
recommend that all IoT devices are equipped with such a mechanism. While
there are many proprietary firmware update mechanisms in use today there
is a lack of a modern interoperable approach of securely updating IoT
devices.

A firmware update solution consists of several components, including
* a mechanism to transport firmware images to IoT devices,
* a manifest that provides meta-data about the firmware image
  (such as a firmware package identifier, the hardware the package
   needs to run, dependencies on other firmware packages, etc.) as
   well as cryptographic information for protecting the firmware
   image in an end-to-end fashion, and
* the firmware image itself.

With RFC 4108 the IETF standardized a manifest format that uses the
Cryptographic Message Syntax (CMS) to protect firmware packages.

Since the publication of RFC 4108 more than 10 years have passed and
more experience with IoT deployments have lead to additional
functionality requiring the work done with RFC 4108 to be revisited. The
purpose of this group is to standardize a version 2 of RFC 4108 that
reflects best current practices. This group focuses on defining a
firmware update solution for Class 1 devices, as defined in RFC 7228,
i.e., IoT devices with ~10 KiB RAM and ~100 KiB flash. This group
will not define any transport mechanism.

In 2016 the Internet Architecture Board organized a workshop on
'Internet of Things (IoT) Software Update (IOTSU)', which took place at
Trinity College Dublin, Ireland on the 13-14 June 2016. The
main goal of the workshop was to foster a discussion on requirements,
challenges and solutions for bringing software and firmware updates to
IoT devices. This workshop also made clear that there are challenges
with lack of regulatory requirements, and misaligned incentives. It is
nevertheless seen as important to standardize the building blocks that
help interested parties to implement and deploy a solid firmware update
mechanism.

In particular this group aims to publish two documents, namely
 * an IoT firmware update architecture that includes a description of
the involved entities, security threats and assumptions, and
 * the manifest format itself.

This group does not aim to standardize a generic software update
mechanism used by rich operating systems, like Linux, but instead
focuses on software development practices in the embedded industry.
Software update solutions that aim to take the features of scripting
languages, such as JavaScript variants like JerryScript, into account
are also outside the scope of this group.

This group will aim to develop a close relationship with silicon vendors
and OEMs that develop IoT operating systems.

Milestones

Dec 2017     Submit "Architecture" document as WG item.

Dec 2017     Submit "Manifest Format" specification as WG item.

Jul 2018    Submit "Architecture" to the IESG for publication as an
Informational RFC.

Nov 2018     Submit "Manifest Format" to the IESG for publication as a
Proposed Standard.


Additional calendar items:

Mar 2018     Release initial version of the manifest creation tools as
open source.

Apr 2018     Release first version of manifest test tool suite as open
source.

Jun 2018     Release first IoT OS implementation of firmware update
mechanisms as open source.


From nobody Tue Sep 26 04:23:39 2017
Return-Path: <cabo@tzi.org>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A4A5E13293A for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 04:23:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L7i6MPZ3v7Wl for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 04:23:35 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C6EE120720 for <fud@ietf.org>; Tue, 26 Sep 2017 04:23:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id v8QBNWmd028393; Tue, 26 Sep 2017 13:23:32 +0200 (CEST)
Received: from [172.20.10.9] (ip-109-45-0-30.web.vodafone.de [109.45.0.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3y1dql6SKMzDLJD; Tue, 26 Sep 2017 13:23:31 +0200 (CEST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net>
Date: Tue, 26 Sep 2017 13:23:30 +0200
Cc: fud@ietf.org
X-Mao-Original-Outgoing-Id: 528117810.150504-a651ecf62de196421fd28acabb86fb8e
Content-Transfer-Encoding: quoted-printable
Message-Id: <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org>
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/02uYNHhp6wFi8d4dSZw6xpIGl3I>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 11:23:36 -0000

> Firmware Updating Description (FUD)
> [Alternative proposal: SUIT (Software Updates for Internet of =
Things).]

SUIT is so much better than FUD.

(When we created the DICE working group, which was about =E2=80=9CImprovem=
ents to DTLS for the Internet of Things=E2=80=9D, we got some strong =
feedback that people weren=E2=80=99t going to install =E2=80=9CIDIOT=E2=80=
=9D modifications into their systems.
I think the same applies for =E2=80=9CFUD=E2=80=9D.  And the suits will =
quickly agree with installing SUIT :-))

> The
> purpose of this group is to standardize a version 2 of RFC 4108

I think this (part of the) sentence can be misunderstood, and it does =
not mesh with the rest of the charter.

The possible misunderstanding of this sentence is that this is going to =
be a =E2=80=9Clet=E2=80=99s fix the bugs in and make some tweaks to RFC =
4108=E2=80=9D WG.

The rest of the charter does not say this, but misunderstanding that =
sentence may make people read that rest under the presumption that =
bugfixing/tweaking RFC 4108 is all that is going to happen.

Gr=C3=BC=C3=9Fe, Carsten


From nobody Tue Sep 26 09:42:10 2017
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DD58C1330B3 for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:42:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level: 
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y57PBozt_uuj for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:42:07 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BDFD3132025 for <fud@ietf.org>; Tue, 26 Sep 2017 09:42:06 -0700 (PDT)
Received: from [192.168.91.203] ([80.92.122.248]) by mail.gmx.com (mrgmx101 [212.227.17.168]) with ESMTPSA (Nemesis) id 0MTfZc-1doBkb23QO-00QOwP; Tue, 26 Sep 2017 18:41:57 +0200
To: Carsten Bormann <cabo@tzi.org>
Cc: fud@ietf.org
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net> <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <5578ca84-bd41-3864-db3a-bbc7f8cd9177@gmx.net>
Date: Tue, 26 Sep 2017 18:41:56 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0
MIME-Version: 1.0
In-Reply-To: <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Provags-ID: V03:K0:32TcnvR24z1d7pWoit2NpmvBfYZX4u5u4jaAND1Q/4jYbepHiVn c1AmY09OdZPndhjLWxDhSytKA26IY1sPWGOZoaplFAboVEiAAGAfyXMvDYDIFLuk0Rr65Ey c99mFwa1RQbB1biYJJYe7tNSRZoSy9bt08pihEr/rTbXP4WhvbU8vwwMYb2y9Gf4vQSn4SU X/1zhdCxsmfWkj89YnhUg==
X-UI-Out-Filterresults: notjunk:1;V01:K0:l19gE5QUsi4=:9h+0ACR8gTp/+GEuRCFZ09 I2ptjLQUjiidmS3A+RusXltxPQC87hBCYYm1uV2VXSuG6pvnvMazHZII7GQyd9upyns5oQuC7 Wghv4inv0K0HiRXKbbIgrQ1SwRDRK1Gj8A9NJTvidrufL6o/L4WXuVmzBvRwi0yqZ0UduAiG6 LGHzZU9UzhydAE9Lr6EL646YoMzxR6ZDQCFK7+ofZGSjdIFgBz0thrdQRcoTvG6i9NGjmYppN 0ERqHSedZEwUZ6GPJP1ofY+L40wqkCu+TRkUzL1FkDoxEc+eSS4RRDNH+EIlaIRpegp17ngg4 kcVQV7fGwSrk8v/3CSfqH/Vblo5IGCgVBZg4UP9Syao/2EBlDEpbn/ImIzwBUKZ+AAtQpyDFe 1erZQqJ2QZocwyRQ+HiZ/jEsk2ejIlQCwZKZnFNFtfnarFZIH06EcSLHYBzoPvJx6Zd7psZR5 yip6ZZz60bV2jJXhZB7gSFr9ebJrWtcYNs7DMLJpLmkkGW5w2O/+HNsVtJRPrnboTJAPTMKmB c8DjXdKbm3zw0NC56oCCzPr08lwdyR3MtXYVezkpS/cU7PE/zoyoGpW0Jg21At+VivntS7V9J GfuJ/05SouzQAU3I9IVBTCREeuQm21oun3qKZuGYN+sHHU9b3JNLsJ/ahZAY1CtW4BgTztfKi iAwDvDnxfGcy3LTDtLpCLdqyRvYtvE8oVcoAmWvQpl0d4jbPXIALWHx5/cThAgILvkPyPdxQ0 NPFs36A+03ZQj+PEu5+tnJxQb/LZwtsmAUzkhPOWi/oyEE1f7O4SaOYlBDVKgvb+SA3QRgBD5 hU6rKbWhFJI0rjdPxuDRP6LBLs/9Z2EwHqEKEODthZAyoLPJZI=
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/VS5miqLrJJd2NT1Ot0u-X67d8HQ>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 16:42:09 -0000

Hi Carsten

for us RFC 4108 served as a great starting point since it contains a lot
of well thought components. But that's just us.

So, the question is what updated sentence would you suggest?

Ciao
Hannes

On 09/26/2017 01:23 PM, Carsten Bormann wrote:
>> Firmware Updating Description (FUD)
>> [Alternative proposal: SUIT (Software Updates for Internet of Things).]
> 
> SUIT is so much better than FUD.
> 
> (When we created the DICE working group, which was about “Improvements to DTLS for the Internet of Things”, we got some strong feedback that people weren’t going to install “IDIOT” modifications into their systems.
> I think the same applies for “FUD”.  And the suits will quickly agree with installing SUIT :-))
> 
>> The
>> purpose of this group is to standardize a version 2 of RFC 4108
> 
> I think this (part of the) sentence can be misunderstood, and it does not mesh with the rest of the charter.
> 
> The possible misunderstanding of this sentence is that this is going to be a “let’s fix the bugs in and make some tweaks to RFC 4108” WG.
> 
> The rest of the charter does not say this, but misunderstanding that sentence may make people read that rest under the presumption that bugfixing/tweaking RFC 4108 is all that is going to happen.
> 
> Grüße, Carsten
> 
> _______________________________________________
> Fud mailing list
> Fud@ietf.org
> https://www.ietf.org/mailman/listinfo/fud
> 


From nobody Tue Sep 26 09:45:31 2017
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 069A51342DB for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:45:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7VfMALXqBVhD for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:45:28 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D30C21330AE for <fud@ietf.org>; Tue, 26 Sep 2017 09:45:27 -0700 (PDT)
Received: from [192.168.91.203] ([80.92.122.248]) by mail.gmx.com (mrgmx103 [212.227.17.168]) with ESMTPSA (Nemesis) id 0Lj25i-1dLuKn0jmw-00dJoP; Tue, 26 Sep 2017 18:45:19 +0200
To: Carsten Bormann <cabo@tzi.org>
Cc: fud@ietf.org
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net> <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <88205e11-2b12-d88a-5613-4a52e865afc5@gmx.net>
Date: Tue, 26 Sep 2017 18:45:17 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0
MIME-Version: 1.0
In-Reply-To: <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Provags-ID: V03:K0:TVvKMx/nhEICtrse3lLaRlMz7P/KpdtxTuSKSW18doPVOaNoq5y IeN6PJxK1XhpPfXPfPZUjgTJaNFfIyl4yhqbh8XaD9VffSx/HGGrZoWX1Kskr8QnMCB1I/P uoCCl9EB0iM1ycFzxqlknDmfWyksJi5yaC4HK7xQoHO9G0uvwgPjbVJ0RaOVOFWMUUu5l4p foOIf8+mIfD3z8lDQrqQQ==
X-UI-Out-Filterresults: notjunk:1;V01:K0:DWqh5Af7nyo=:2S1APZji1VhWKyhM3XvW6C PUTFMbEqz6P0GfX8+3kI155DaHidb9pg8onH2jBGVQuLW/8xiLmO+viIqgjjaBBOPKeZWI+e0 zPqdMuyJYxU9DWnxVKfZfO9pftq+C7g6cC4gps+UjpZWa6hMKG/rLI6JizeQHtC00KjyYSFTw YIhhCasG3igw69Xm1B1FZzw90XQun0NZIxJQrpSy4K1VlbTauAMK/qG4LXnoGiVT++xqdprGI jBkFXnXgX0smLNlaaWZ23v+JMpTRXISc3qDGLmPyLTKiYS3fY5YlrvkIEoS8KOhr70WjmINte AaLsaEQ7r20deYNu5tCcpN9KOqfl5Tuz6AG9um02WMYzXlIHvam95OkER5fUPvlLVVCyE8RzP I06HYe3V3YBDDKESu/iquiQM5tLzA/srSlFANgsSIXlqn5R+YQQuBCum2TcotFW4NRParnVjl 2fH4yo3WHVaCjBpgpRdIHBKPpGQk+O2F8QJQFqxo4ynMM7tkCM2kHpsI0y8gI4AmGTeEkDdSB P+6OD3v8UDUdbxrlrIf4ezh+Rjl2zkoias3BWdq0S/eohk49GrV6Z19yY2X4Q2b9bjzenT8Cy MtYLprwkB9zU5THDchilwYa9RtIYK1HpqJDozyxj3rP9fsFGMNMHUFnLoDmaqQ8moVVr2gGUp x+13fNsW5+cpk2cdFEBDIgfzuEqBw2RDJfXa1j9qW6Umf4zIxHN+GTmwe9UgTZA4+hsJxShmP wLiPsnOejmAM//20cb5HWVwm5yahJIGsXdToSG6fGxF+Hc/eSxnSNk/TMaYiTX7+NfGSK6y0r YF380oQMUyoaJSeJKSqUAYWMbDrTWmzh7mXOS3nHmnxlLXitmg=
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/plWJcthXUBXXOaLZUCxaesHlS5o>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 16:45:30 -0000

FWIW: SUIT (Software Updates for Internet of Things) is totally fine for
me. Finding the right name for a group or a protocol is always tricky.

On 09/26/2017 01:23 PM, Carsten Bormann wrote:
>> Firmware Updating Description (FUD)
>> [Alternative proposal: SUIT (Software Updates for Internet of Things).]
> SUIT is so much better than FUD.
> 
> (When we created the DICE working group, which was about “Improvements to DTLS for the Internet of Things”, we got some strong feedback that people weren’t going to install “IDIOT” modifications into their systems.
> I think the same applies for “FUD”.  And the suits will quickly agree with installing SUIT :-))
> 


From nobody Tue Sep 26 09:54:00 2017
Return-Path: <david.waltermire@nist.gov>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 54BF81342F7 for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:53:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nistgov.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 54FlhlFuGGh6 for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:53:54 -0700 (PDT)
Received: from gcc01-CY1-obe.outbound.protection.outlook.com (mail-cy1gcc01on0131.outbound.protection.outlook.com [23.103.200.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0B3211342DB for <fud@ietf.org>; Tue, 26 Sep 2017 09:53:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nistgov.onmicrosoft.com; s=selector1-nist-gov; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=tH0d5gAtgieLaOr7l6iw5kZbGGm8lXcbzRomjG1gI88=; b=sF7LCfAKmBwj9jvhalybrVlJuV57hLqPnMPlEE+fFv53QEI9Y+WzCv+oYZQ1pDLBAT7fyAAm46OcxgGRQd90m6eL8uiWjiVHaPP0usH7273Lm6EqE2L+BpZPlot4j+dXBANt7cDo/b+j0PP8DzevIHs7U3wcBz+SFjefzSXxiTU=
Received: from CY4PR09MB1495.namprd09.prod.outlook.com (10.173.191.141) by CY4PR09MB1494.namprd09.prod.outlook.com (10.173.191.140) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.77.7; Tue, 26 Sep 2017 16:53:52 +0000
Received: from CY4PR09MB1495.namprd09.prod.outlook.com ([10.173.191.141]) by CY4PR09MB1495.namprd09.prod.outlook.com ([10.173.191.141]) with mapi id 15.20.0077.011; Tue, 26 Sep 2017 16:53:52 +0000
From: "Waltermire, David A. (Fed)" <david.waltermire@nist.gov>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, Carsten Bormann <cabo@tzi.org>
CC: "fud@ietf.org" <fud@ietf.org>
Thread-Topic: [Fud] Revised Charter Text
Thread-Index: AQHTNikt7Pq4Bg4OrEyBBc9r7k3jU6LHB3AAgABZ54CAAAEPMA==
Date: Tue, 26 Sep 2017 16:53:51 +0000
Message-ID: <CY4PR09MB1495CB8351B12B4C7D1A1859F07B0@CY4PR09MB1495.namprd09.prod.outlook.com>
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net> <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org> <88205e11-2b12-d88a-5613-4a52e865afc5@gmx.net>
In-Reply-To: <88205e11-2b12-d88a-5613-4a52e865afc5@gmx.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=david.waltermire@nist.gov; 
x-originating-ip: [129.6.224.58]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; CY4PR09MB1494; 6:Ensec5hwfYewgEutrbQuLU7MSuCS++Rx0Q2pH+cFuv+qnEpCU9Bjq2fbjHaVGYL6ESWRu5aOJsoIHazI+EjTtiCz5fsdr7ZaNv4AHXyDX5a7+R/tAbnI6X3lmMyFLEb6BsuY1ARs/g1aYVHEMp58OY2TVBTypSxRZWopFMxDL/DdQOUxIgIR5zcGulJICVRkxbN/oa1Vb+npV2ndApTWgWFKKGvylWLKVGyzpP96v23GxBUzDwyrDjl2zkenyg8T+WwB29U7AzSV1iFHuswU+QGaSWVQJRF1QPFacjyi5SXfIc0W7cTa0HTUlB06m/yyMFpbfRf5GXhjUMiE3Jj1ag==; 5:SSo4P6pMWhowi+OHjIIPJeeRu+jjEWEcS7HZLIFljJTrFtixXTQ+RYwNYiLYG49bL2/MH03dPaEmbi04y9qdDE5Ja7U9rJYh/qo2XLYf27moWTavj4RC44009bJvSI+nbgILhnjBVAhtDx2GqrLnVg==; 24:LyBwmIhmwcN1Gcbp2YMJ3nKCKvtAB2z5kUMIwfq6dMvWIMAvjUnBrXJWlklOjo2zIYvTvkVvt75Ol/I8BBzuC7sXNiQrf43O11xu9Vqzr8s=; 7:uch6MQCz4O9n2n9PqLvZCsyulUtdD5oGJKBAMOI9eNQXbQcHELT1bz4b3FJqY7Q/JamHR8GVsaxTSEOLQD94PGQpM0TGuYaLLGwLI5Uc79ZHZWet1wyiZX35wmJl1YBxn5/s6kmdgiseE9l2VPQPlKs/63FnLM7XAtnKGQ+HbWTW1b/x1RfdqRmj9bAbwKyoEBEp7j+WoMtLrMWQAkuyxTWa7bIKYdbgPVSIu43m2qg=
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 1beab78c-9d47-4ed7-55aa-08d504ff2a98
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254152)(48565401081)(2017052603199)(201703131423075)(201703031133081)(201702281549075); SRVR:CY4PR09MB1494; 
x-ms-traffictypediagnostic: CY4PR09MB1494:
x-exchange-antispam-report-test: UriScan:;
x-microsoft-antispam-prvs: <CY4PR09MB1494015B3614693CAA0E3C58F07B0@CY4PR09MB1494.namprd09.prod.outlook.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(10201501046)(3002001)(100000703101)(100105400095)(93006095)(93001095)(6055026)(6041248)(20161123564025)(20161123555025)(20161123558100)(20161123560025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:CY4PR09MB1494; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:CY4PR09MB1494; 
x-forefront-prvs: 0442E569BC
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(376002)(346002)(39860400002)(199003)(24454002)(13464003)(377454003)(189002)(106356001)(305945005)(966005)(86362001)(6116002)(33656002)(6306002)(6506006)(77096006)(102836003)(3846002)(99286003)(2900100001)(229853002)(14454004)(105586002)(6246003)(478600001)(5660300001)(53546010)(2906002)(53936002)(3660700001)(55016002)(9686003)(97736004)(74316002)(189998001)(68736007)(4326008)(7736002)(81166006)(6436002)(54356999)(50986999)(561944003)(66066001)(316002)(8936002)(7696004)(2950100002)(81156014)(25786009)(3280700002)(8676002)(110136005)(76176999)(101416001); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR09MB1494; H:CY4PR09MB1495.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Sep 2017 16:53:51.9966 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR09MB1494
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/4BFAkRcRQgmlJ1kx3UJEAY-uuCA>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 16:53:56 -0000

SWYgd2UgZG8gbWFrZSB0aGUgY2hhbmdlIHRvIFNVSVQsIHdlIHdpbGwgbmVlZCB0byByZXF1ZXN0
IGEgbmV3IERhdGF0cmFja2VyIHBhZ2UuIENoYW5naW5nIHRoZSBuYW1lIHRvICJGaXJtd2FyZSBV
cGRhdGluZyBEZXNjcmlwdGlvbiIgZG9lcyBub3QgcmVxdWlyZSBhIG5ldyBEYXRhdHJhY2tlciBw
YWdlLg0KDQpGV0lXLCBvbmNlIHRoZSBSRkNzIHdlIHByb2R1Y2UgYXJlIHB1Ymxpc2hlZCwgdGhl
IG5hbWUgRlVELCBTVUlULCBvciBhbnl0aGluZyBlbHNlIHdpbGwgYmUgbGVzcyByZWxldmFudCBh
bmQgZG9lcyBub3QgbmVlZCB0byBiZSBtZW50aW9uZWQgaW4gYW55IG9mIHRoZSBwcm9kdWNlZCBk
b2N1bWVudHMuIFRoaXMgbWFrZXMgbWUgbGVzcyBjb25jZXJuZWQgYWJvdXQgd2hhdCB3ZSBjYWxs
IHRoZSBXRy4NCg0KUmVnYXJkcywNCkRhdmUNCg0KPiAtLS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0t
LQ0KPiBGcm9tOiBGdWQgW21haWx0bzpmdWQtYm91bmNlc0BpZXRmLm9yZ10gT24gQmVoYWxmIE9m
IEhhbm5lcyBUc2Nob2ZlbmlnDQo+IFNlbnQ6IFR1ZXNkYXksIFNlcHRlbWJlciAyNiwgMjAxNyAx
Mjo0NSBQTQ0KPiBUbzogQ2Fyc3RlbiBCb3JtYW5uIDxjYWJvQHR6aS5vcmc+DQo+IENjOiBmdWRA
aWV0Zi5vcmcNCj4gU3ViamVjdDogUmU6IFtGdWRdIFJldmlzZWQgQ2hhcnRlciBUZXh0DQo+IA0K
PiBGV0lXOiBTVUlUIChTb2Z0d2FyZSBVcGRhdGVzIGZvciBJbnRlcm5ldCBvZiBUaGluZ3MpIGlz
IHRvdGFsbHkgZmluZSBmb3IgbWUuDQo+IEZpbmRpbmcgdGhlIHJpZ2h0IG5hbWUgZm9yIGEgZ3Jv
dXAgb3IgYSBwcm90b2NvbCBpcyBhbHdheXMgdHJpY2t5Lg0KPiANCj4gT24gMDkvMjYvMjAxNyAw
MToyMyBQTSwgQ2Fyc3RlbiBCb3JtYW5uIHdyb3RlOg0KPiA+PiBGaXJtd2FyZSBVcGRhdGluZyBE
ZXNjcmlwdGlvbiAoRlVEKQ0KPiA+PiBbQWx0ZXJuYXRpdmUgcHJvcG9zYWw6IFNVSVQgKFNvZnR3
YXJlIFVwZGF0ZXMgZm9yIEludGVybmV0IG9mDQo+ID4+IFRoaW5ncykuXQ0KPiA+IFNVSVQgaXMg
c28gbXVjaCBiZXR0ZXIgdGhhbiBGVUQuDQo+ID4NCj4gPiAoV2hlbiB3ZSBjcmVhdGVkIHRoZSBE
SUNFIHdvcmtpbmcgZ3JvdXAsIHdoaWNoIHdhcyBhYm91dA0KPiDigJxJbXByb3ZlbWVudHMgdG8g
RFRMUyBmb3IgdGhlIEludGVybmV0IG9mIFRoaW5nc+KAnSwgd2UgZ290IHNvbWUgc3Ryb25nDQo+
IGZlZWRiYWNrIHRoYXQgcGVvcGxlIHdlcmVu4oCZdCBnb2luZyB0byBpbnN0YWxsIOKAnElESU9U
4oCdIG1vZGlmaWNhdGlvbnMgaW50byB0aGVpcg0KPiBzeXN0ZW1zLg0KPiA+IEkgdGhpbmsgdGhl
IHNhbWUgYXBwbGllcyBmb3Ig4oCcRlVE4oCdLiAgQW5kIHRoZSBzdWl0cyB3aWxsIHF1aWNrbHkg
YWdyZWUNCj4gPiB3aXRoIGluc3RhbGxpbmcgU1VJVCA6LSkpDQo+ID4NCj4gDQo+IF9fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fDQo+IEZ1ZCBtYWlsaW5nIGxp
c3QNCj4gRnVkQGlldGYub3JnDQo+IGh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGlu
Zm8vZnVkDQo=


From nobody Tue Sep 26 09:59:56 2017
Return-Path: <cabo@tzi.org>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 074191342DB for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:59:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level: 
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cFDsA7oI-OQx for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 09:59:52 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 892BB1330AE for <fud@ietf.org>; Tue, 26 Sep 2017 09:59:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id v8QGxm6O001674; Tue, 26 Sep 2017 18:59:48 +0200 (CEST)
Received: from [172.27.22.22] (unknown [195.37.142.75]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3y1nHm18KrzDLRt; Tue, 26 Sep 2017 18:59:48 +0200 (CEST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <5578ca84-bd41-3864-db3a-bbc7f8cd9177@gmx.net>
Date: Tue, 26 Sep 2017 18:59:46 +0200
Cc: fud@ietf.org
X-Mao-Original-Outgoing-Id: 528137986.615691-5015d66d4d643d58bc7f03edee824267
Content-Transfer-Encoding: quoted-printable
Message-Id: <946B5D4B-C81A-44B3-9337-E9A7AB3F737D@tzi.org>
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net> <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org> <5578ca84-bd41-3864-db3a-bbc7f8cd9177@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/Zd-yCL__05bxPjJebZ7ULxPEHeQ>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 16:59:55 -0000

> On Sep 26, 2017, at 18:41, Hannes Tschofenig =
<hannes.tschofenig@gmx.net> wrote:
>=20
> Hi Carsten
>=20
> for us RFC 4108 served as a great starting point since it contains a =
lot
> of well thought components. But that's just us.

There is no doubt about RFC 4108 being a good input.

Let me try explain my point in an analogy: if the QUIC WG had said it =
wants to do TLS 1.4, there might have been about the same =
misunderstanding (and QUIC certainly does use TLS as a great starting =
point).

Gr=C3=BC=C3=9Fe, Carsten


>=20
> So, the question is what updated sentence would you suggest?
>=20
> Ciao
> Hannes
>=20
> On 09/26/2017 01:23 PM, Carsten Bormann wrote:
>>> Firmware Updating Description (FUD)
>>> [Alternative proposal: SUIT (Software Updates for Internet of =
Things).]
>>=20
>> SUIT is so much better than FUD.
>>=20
>> (When we created the DICE working group, which was about =
=E2=80=9CImprovements to DTLS for the Internet of Things=E2=80=9D, we =
got some strong feedback that people weren=E2=80=99t going to install =
=E2=80=9CIDIOT=E2=80=9D modifications into their systems.
>> I think the same applies for =E2=80=9CFUD=E2=80=9D.  And the suits =
will quickly agree with installing SUIT :-))
>>=20
>>> The
>>> purpose of this group is to standardize a version 2 of RFC 4108
>>=20
>> I think this (part of the) sentence can be misunderstood, and it does =
not mesh with the rest of the charter.
>>=20
>> The possible misunderstanding of this sentence is that this is going =
to be a =E2=80=9Clet=E2=80=99s fix the bugs in and make some tweaks to =
RFC 4108=E2=80=9D WG.
>>=20
>> The rest of the charter does not say this, but misunderstanding that =
sentence may make people read that rest under the presumption that =
bugfixing/tweaking RFC 4108 is all that is going to happen.
>>=20
>> Gr=C3=BC=C3=9Fe, Carsten
>>=20
>> _______________________________________________
>> Fud mailing list
>> Fud@ietf.org
>> https://www.ietf.org/mailman/listinfo/fud
>>=20
>=20


From nobody Tue Sep 26 10:09:35 2017
Return-Path: <cabo@tzi.org>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 337B11342EE for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 10:09:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level: 
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m5m86GOW89kM for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 10:09:33 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F299413428A for <fud@ietf.org>; Tue, 26 Sep 2017 10:09:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id v8QH9T9w009549; Tue, 26 Sep 2017 19:09:29 +0200 (CEST)
Received: from [172.27.22.22] (unknown [195.37.142.75]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3y1nVx5dWczDLRy; Tue, 26 Sep 2017 19:09:29 +0200 (CEST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <CY4PR09MB1495CB8351B12B4C7D1A1859F07B0@CY4PR09MB1495.namprd09.prod.outlook.com>
Date: Tue, 26 Sep 2017 19:09:28 +0200
Cc: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "fud@ietf.org" <fud@ietf.org>
X-Mao-Original-Outgoing-Id: 528138568.25437-1fc0613419e333653772edc3ba812018
Content-Transfer-Encoding: quoted-printable
Message-Id: <B129FDEA-CF31-4EFB-93D9-669F0543CCD9@tzi.org>
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net> <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org> <88205e11-2b12-d88a-5613-4a52e865afc5@gmx.net> <CY4PR09MB1495CB8351B12B4C7D1A1859F07B0@CY4PR09MB1495.namprd09.prod.outlook.com>
To: "Waltermire, David A. (Fed)" <david.waltermire@nist.gov>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/_KEQzbfAOUyzKRN2_R0EBWC1vWI>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 17:09:34 -0000

On Sep 26, 2017, at 18:53, Waltermire, David A. (Fed) =
<david.waltermire@nist.gov> wrote:
>=20
> FWIW, once the RFCs we produce are published, the name FUD, SUIT, or =
anything else will be less relevant and does not need to be mentioned in =
any of the produced documents. This makes me less concerned about what =
we call the WG.

While that is theoretically true, that is not the way things work out in =
practice =E2=80=94 people still call TLS =E2=80=9CSSL=E2=80=9D because =
that was the name the technology was referred to before 1999 (1996, =
actually).  We will need to do marketing for the WG's output *before* it =
has an RFC number, and being able to call it SUIT in that marketing does =
help.
(A new data tracker page is relatively low effort compared to fixing up =
marketing material.)

(And no, we shouldn=E2=80=99t have a FUD WG producing the SUIT protocol, =
just as we shouldn=E2=80=99t have suits producing FUD :-)

Gr=C3=BC=C3=9Fe, Carsten

(Says someone who is not innocent for calling a WG CoRE that then went =
on producing the CoAP protocol.)


From nobody Tue Sep 26 13:55:01 2017
Return-Path: <Brendan.Moran@arm.com>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 66B9013445D for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 13:55:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.909
X-Spam-Level: 
X-Spam-Status: No, score=-2.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=-1, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4SM5tG53Kgmg for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 13:54:57 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0077.outbound.protection.outlook.com [104.47.2.77]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E1FA513445E for <Fud@ietf.org>; Tue, 26 Sep 2017 13:54:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com;  s=selector1-arm-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=KNygTNQNHjrZHqHcn3aTZy+O/TK6zhAQcht8+jdQfkU=; b=HpCniIEE0bSnW/y7lDVHpPcP/7/eJnKDlfRI3LY0Dl6E1nInkwcZpNcGqiQD54X4i60/gJ8zHJr5ueXBSB77mw0qcUY4HV50aIQiphN1YgnchUaOk08htUtyJQgZP7vWoE30PuqU4hsmlxEEbUWB9Lq0qQ3HdEHRFXUm+7RPcbg=
Received: from AM4PR08MB2836.eurprd08.prod.outlook.com (10.171.191.30) by AM4PR08MB2836.eurprd08.prod.outlook.com (10.171.191.30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.77.7; Tue, 26 Sep 2017 20:54:54 +0000
Received: from AM4PR08MB2836.eurprd08.prod.outlook.com ([fe80::d4a2:963:ba6f:fef4]) by AM4PR08MB2836.eurprd08.prod.outlook.com ([fe80::d4a2:963:ba6f:fef4%13]) with mapi id 15.20.0077.011; Tue, 26 Sep 2017 20:54:54 +0000
From: Brendan Moran <Brendan.Moran@arm.com>
To: "Smith, Ned" <ned.smith@intel.com>
CC: "Fud@ietf.org" <Fud@ietf.org>
Thread-Topic: [Fud] A few questions / observations
Thread-Index: AQHTLjdsLe1oeSwl+Em8FCdFITDsKqLHtvcA
Date: Tue, 26 Sep 2017 20:54:54 +0000
Message-ID: <2BF4654C-4260-4C7C-8DD5-CF892628711B@arm.com>
References: <D531874E-95BF-4A12-8049-15794BCD1039@intel.com>
In-Reply-To: <D531874E-95BF-4A12-8049-15794BCD1039@intel.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-mailer: Apple Mail (2.3273)
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Brendan.Moran@arm.com; 
x-originating-ip: [217.140.96.140]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; AM4PR08MB2836; 6:KvkDzCfu61s5ECXeTtvQ+CpZmqLRDwx3W45nTT3EsCuY+YrCelB0re7NJbeFQxHQBrI4/zyxvlA3g/zPqFgBOuJHJCEJ+XuMR8PpEI+omhqR/3AMv3QGE8zxTLBwgRK40mCwMqXhQkMp6/dxPtNRH2W/BK3j+A2eV+JLtMW5on+0Br6BHll22ST+AKMRmobBssylgmRJWyISsDzXTg+8EQJVwm2fy7DLnQZ/3VhZzmwyYuUFji9xzA3i48d/2iyMEyGqIurCEIvp8arewz3IOqwLIWkBdWLBTdU4sj1preRWDXAPpUA+U0BF0v6XcVgc+FYayv9w/hPXaFivmXZ7fQ==; 5:rmcvQ/jk3sD4y3Xjk/+EulBda9kODZ7u8SxcQJbUgusVjA4IUE2gt4nGVrXktChf8KzxwNxFkIUPRfuYVcKS/G3+2vcKvGy5a5e0s3wwQpxTJcpO4JSoVcFyre8M0+hWeSwn8PU8YmmMtRF+wh6Oow==; 24:AHon9MJQ4m8laZutxAQrWklYJBMjpW+pa7K+cVdCuaC0QI9+XkQoOYu2Rx6ZLGmkkoyVnnTSZg+vcONwaYZ0rcmgMhQYPv5xh1uw5LOTeeY=; 7:Z0LZJFoMlC/7sN4fx1KcwbY30pWpYLfK4fQDMIwbuqg7M8hlMYnP3ECKw+vPLvh0phAXJc0kIaRfjsIZxYG6/OYEhNr5PwEsY1tKGDb92KWwILuHIweGeDHHvZHv1NNnP/BHa2Uv1z/j/4a7ln8lgFm29rYn+r4wi5mWW8FHQk4QNhVDG3J3QptDL8RgO+RRfIdYmj/qdi4JRoDpROL5Q37MK0ywyiAjfER10FCUuyg=
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 31eb80a3-711a-47db-d825-08d50520d6d6
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254152)(48565401081)(2017052603199)(201703131423075)(201703031133081)(201702281549075); SRVR:AM4PR08MB2836; 
x-ms-traffictypediagnostic: AM4PR08MB2836:
x-exchange-antispam-report-test: UriScan:(131327999870524)(788757137089)(228905959029699); 
x-microsoft-antispam-prvs: <AM4PR08MB2836EB3106467AE5E0E777DFEA7B0@AM4PR08MB2836.eurprd08.prod.outlook.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(10201501046)(3002001)(100000703101)(100105400095)(93006095)(93001095)(6055026)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123560025)(20161123555025)(20161123558100)(20161123564025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:AM4PR08MB2836; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:AM4PR08MB2836; 
x-forefront-prvs: 0442E569BC
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(39860400002)(346002)(376002)(40434004)(199003)(24454002)(51444003)(189002)(102836003)(2950100002)(6916009)(6246003)(966005)(66066001)(478600001)(189998001)(14454004)(33656002)(57306001)(53936002)(83716003)(25786009)(86362001)(6436002)(229853002)(6486002)(2900100001)(82746002)(316002)(6512007)(5250100002)(236005)(5890100001)(99286003)(8676002)(4326008)(6306002)(6116002)(7736002)(6506006)(36756003)(54896002)(606006)(5660300001)(2906002)(3660700001)(101416001)(8936002)(50986999)(97736004)(3280700002)(105586002)(81166006)(106356001)(81156014)(50226002)(76176999)(53546010)(3846002)(72206003)(68736007); DIR:OUT; SFP:1101; SCL:1; SRVR:AM4PR08MB2836; H:AM4PR08MB2836.eurprd08.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_2BF4654C42604C7C8DD5CF892628711Barmcom_"
MIME-Version: 1.0
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Sep 2017 20:54:54.3664 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR08MB2836
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/zaagTSKTKmbbA_-v8C6b1v8bMMg>
Subject: Re: [Fud] A few questions / observations
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 20:55:00 -0000

--_000_2BF4654C42604C7C8DD5CF892628711Barmcom_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SGkgTmVkLA0KSeKAmXZlIHBsYWNlZCBteSBjb21tZW50cyBpbmxpbmUuDQoNClRoYW5rcyBmb3Ig
eW91ciBmZWVkYmFjayENCg0KQmVzdCBSZWdhcmRzLA0KQnJlbmRhbg0KDQoNCk9uIDE1IFNlcCAy
MDE3LCBhdCAxNjoyOSwgU21pdGgsIE5lZCA8bmVkLnNtaXRoQGludGVsLmNvbTxtYWlsdG86bmVk
LnNtaXRoQGludGVsLmNvbT4+IHdyb3RlOg0KDQrigKIgICAgICAgICBJcyBpdCBwb3NzaWJsZSBm
b3IgdGhlIGltYWdlIHR5cGUgdG8gYmUgYW4gZXhpc3Rpbmcg4oCcbWFuaWZlc3TigJ0gc3VjaCBh
cyDigJxwYWNrYWdlc+KAnSBvciDigJxidW5kbGVz4oCdPw0KDQpJIGRvbuKAmXQgc2VlIHdoeSBu
b3QuIFRoZSBtYW5pZmVzdCBpcyBhIHByZXR0eSBnZW5lcmljIHdyYXBwZXIuDQoNCuKAoiAgICAg
ICAgIElzIHRoZSBwdXNoIG1vZGVsIHN1cHBvcnRlZCAoY2xvdWQgc3RvcmFnZSBwdXNoZXMgdXBk
YXRlIGZpbGUgcHJvYWN0aXZlbHkpPw0KDQpDZXJ0YWlubHkuIFRoaXMgaXMgb25lIG9mIHRoZSBl
eHBlY3RlZCB1c2UtY2FzZXMsIGhvd2V2ZXIgbWFuaWZlc3QgbXVzdCBwcmVjZWRlIHBheWxvYWQu
DQoNCuKAoiAgICAgICAgIFdoeSB3YXMgQVNOLjEgc2VsZWN0ZWQgYXMgdGhlIGVuY29kaW5nIGZv
cm1hdD8gKFdoeSBub3QgQ09TRT8pDQoNCkFTTi4xIHdhcyB1c2VkIGZvciBhIGZldyByZWFzb25z
Lg0KDQogIDEuICBJdCBpcyB0aGUgZGVmYXVsdCBmb3JtYXQgZm9yIGNlcnRpZmljYXRlcy4gTW9z
dCB0b29scyB1c2UgREVSIHJhdGhlciB0aGFuIENPU0UgZm9yIHBhY2tpbmcgY2VydGlmaWNhdGVz
LCBzbyB0aGlzIHJlZHVjZXMgdGhlIG51bWJlciBvZiBwYXJzZXJzIGluIHRoZSB0YXJnZXQuIFdo
ZXJlIGludGVyd29yayB3aXRoIEhTTXMgaXMgaW52b2x2ZWQsIHVzaW5nIGEgZm9ybWF0IHRoZSBI
U00gc3VwcG9ydHMgaXMgYmVuZWZpY2lhbC4NCiAgMi4gIFBDS1M3IC8gQ01TIC8gUkZDNTY1MiBh
cmUgd2lkZWx5IHN1cHBvcnRlZC4gRm9yIGV4YW1wbGUsIE9wZW5TU0zigJlzIHNtaW1lIGNvbW1h
bmQgaGFuZGxlcyBDTVMgc2lnbmluZy92YWxpZGF0aW9uIGRpcmVjdGx5LiBUaGlzIG1ha2VzIHRo
ZSBjdXN0b20gdG9vbGluZyByZXF1aXJlZCBzaW1wbGVyLiBUaGlzIHdpbGwgYWxzbywgaG9wZWZ1
bGx5LCBpbXByb3ZlIGNvbXBhdGliaWxpdHkgd2l0aCBleGlzdGluZyBIU01zDQogIDMuICBEaXJl
Y3QgY29kZSBnZW5lcmF0aW9uLiBJbiBhIHNjZW5hcmlvIHdoZXJlIHRoZSBwYXJzZXIgZG9lcyBu
b3QgY3JlYXRlIGEgZG9jdW1lbnQgb2JqZWN0IG1vZGVsLCBidXQgZXh0cmFjdHMgb3IgdmFsaWRh
dGVzIHNwZWNpZmljIGZpZWxkcywgQVNOLjEgcHJvdmlkZXMgYSBncmFtbWFyIHRoYXQgbWFrZXMg
aXQgcG9zc2libGUgdG8gZ2VuZXJhdGUgYSBwYXJzZXIgcHJvZ3JhbWF0aWNhbGx5Lg0KICA0LiAg
VGhlIG1lYW5pbmcgb2Yg4oCcbGVuZ3Ro4oCdIGZvciBjb21wb3NpdGUgdHlwZXMuIEluIERFUiwg
dGhlIGxlbmd0aCBvZiBhIGZpZWxkIGlzIHVuYW1iaWd1b3VzLiBJdCBpcyBhbHdheXMgdGhlIGxl
bmd0aCwgaW4gYnl0ZXMsIG9mIHRoZSBjb250YWluZWQgb2JqZWN0LiBUaGlzIGFsbG93cyBhIHBh
cnNlciB0aGF0IHVuZGVyc3RhbmRzIHRoZSBkb2N1bWVudCBiZWluZyBwYXJzZWQgdG8gc2tpcCBs
YXJnZSBjaHVua3Mgb2YgYSBkZWVwbHkgbmVzdGVkIHRyZWUuIEluIENCT1IsIHRoZSDigJxsZW5n
dGjigJ0gb2YgYW4gYXJyYXkgb3IgbWFwIGlzIHRoZSBudW1iZXIgb2YgZWxlbWVudHMgaXQgY29u
dGFpbnMuIFRoaXMgbWFrZXMgaXQgaW1wb3NzaWJsZSBmb3IgdGhlIHBhcnNlciB0byDigJxza2lw
4oCdIGFueXRoaW5nLiBJdCBoYXMgdG8gcGFyc2UgdGhlIGVudGlyZSBzdHJ1Y3R1cmUuIEl0IGlz
IHBvc3NpYmxlIHRvIGNpcmN1bXZlbnQgc29tZSBvZiB0aGVzZSBsaW1pdGF0aW9ucyB1c2luZyB0
YWdnaW5nLCBpbiBwYXJ0aWN1bGFyIHRhZyAyNCAoZW5jb2RlZCBDQk9SIGRhdGEgaXRlbSksIGJ1
dCB0aGlzIGhhcyB0aGUgZG93bnNpZGUgb2YgYnJlYWtpbmcgdHJhbnNsYXRhYmlsaXR5IHRvIEpT
T04sIHdoaWNoIGlzIGEga2V5IGFkdmFudGFnZSBvZiBDQk9SLiBDb25zaXN0ZW50IFRMViByZXBy
ZXNlbnRhdGlvbiBtYWtlcyBwYXJzaW5nIGluIGEgY29uc3RyYWluZWQgZW52aXJvbm1lbnQgb2Zm
ZXJzIGEgbm90aW9uYWwgcGVyZm9ybWFuY2UgaW1wcm92ZW1lbnQsIGJ1dCB0aGlzIGlzIG1pbm9y
IGFuZCBtYXkgbm90IHBsYXkgb3V0IGluIHByYWN0aWNlLg0KDQpOZXZlciB0aGUgbGVzcywgSSB0
aGluayB0aGF0IENCT1IvQ09TRSB3b3VsZCBiZSBwZXJmZWN0bHkgc2VydmljZWFibGUgZm9yIHRo
aXMgdXNlLiBJ4oCZbSBub3QgZXZlbiBjZXJ0YWluIHRoYXQgQVNOLjEgY2Fu4oCZdCBiZSB1c2Vk
IGFzIGEgc2NoZW1hIGZvciBDQk9SIChzZWUgMyBhYm92ZSkuIFRoYXQgYmVpbmcgdGhlIGNhc2Us
IEkgY2FuIHNlZSBhIGNhc2UgZm9yIERFUiBtYW5pZmVzdHMgd2l0aCBDTVMsIGFuZCBDQk9SIG1h
bmlmZXN0cyB3aXRoIENPU0UuDQoNCg0K4oCiICAgICAgICAgSXQgaXNu4oCZdCBjbGVhciBob3cg
dGhlIG1hbmlmZXN0IGFuZCB0aGUgaW1hZ2UgKHBhY2thZ2UgLyBidW5kbGUpIHdpbGwgc2hhcmUg
dGhlIGF2YWlsYWJsZSBBIC9CIHN0b3JhZ2UgYXJlYS4gUG9zc2libHkgaXQgaXMgYXNzdW1lZCB0
aGUgbWFuaWZlc3QgcmVsYXRlZCBvcGVyYXRpb25zIGFyZSB0byBiZSBpbnRlZ3JhdGVkIGludG8g
YW4gZXhpc3RpbmcgU1cgdXBkYXRlIGNhcGFiaWxpdHkgYW5kIGJlIHRhdWdodCB0byB1bmRlcnN0
YW5kIHRoZSBtYW5pZmVzdCBzdHJ1Y3R1cmUuIENvbnNpZGVyIHRoZSBjYXNlIHdoZXJlIHZlcnNp
b24gMSBvZiBhIFNXIHVwZGF0ZSB0b29sIHVuZGVyc3RhbmRzIGJ1bmRsZXMgYnV0IGl0IHJlY2Vp
dmVzIGEgZmlsZSB0aGF0IGNvbnRhaW5zIGEgbWFuaWZlc3QuIElzIGl0IGV4cGVjdGVkIHRoYXQg
dGhlIHYxIHRvb2wgd2lsbCBiZSBhYmxlIHRvIHByb2Nlc3MgdGhlIHVwZGF0ZSBuZXZlcnRoZWxl
c3MgKGlnbm9yaW5nIHRoZSBtYW5pZmVzdCkuIFRoaXMgYXNzdW1lcyB0aGUgZW5jcnlwdGlvbiBv
cHRpb24gaXNu4oCZdCBiZWluZyBhcHBsaWVkIG9mIGNvdXJzZS4NCg0KVGhlIGV4cGVjdGF0aW9u
IHdhcyB0aGF0IG1hbmlmZXN0IHdvdWxkIGJlIHN0b3JlZCBpbnRvIGEgc2VwYXJhdGUga2V5L3Zh
bHVlIHN0b3JlLg0KDQrigKIgICAgICAgICBUaGUgYXJjaCBkaWRu4oCZdCBtZW50aW9uIGludGVn
cml0eSBhcyBhIHJlcXVpcmVtZW50LiBNYXliZSBpdCBpcyBpbXBsaWVkIGJ1dCBpdCBzZWVtcyBw
b3NzaWJsZSBmb3IgYSBjbGV2ZXIgYXR0YWNrZXIgdG8gcmVwbGFjZSBvbmUgY2lwaGVyIHRleHQg
d2l0aCBhIGRpZmZlcmVudCBjaXBoZXIgdGV4dCB1bmxlc3MgaW50ZWdyaXR5IHdlcmUgbWVudGlv
bmVkIGFzIGEgZ29hbCBhbmQgc3RlcHMgdGFrZW4gdG8gYWxsb3cgb25seSBjaXBoZXIgc3VpdGVz
IHRoYXQgYWNoaWV2ZSBib3RoIG9iamVjdGl2ZXMuDQoNClRoaXMgaXMgYW4gaW50ZXJlc3Rpbmcg
cG9pbnQuIFdlIG1heSBoYXZlIGRyYWZ0ZWQgaXQgYXMgYW4gaW1wbGljaXQgcmVxdWlyZW1lbnQu
IEkgaGF2ZSBtYWRlIHRoZSBhc3N1bXB0aW9uIHRoYXQgaW50ZWdyaXR5IGlzIGEgcHJlcmVxdWlz
aXRlIGZvciBhdXRoZW50aWNpdHkgYW5kIGF1dGhlbnRpY2l0eSBpcyBhbiBleHByZXNzbHkgc3Rh
dGVkIGdvYWwuIEhvd2V2ZXIsIHlvdSBhcmUgY29ycmVjdCwgdGhpcyBzaG91bGQgYmUgbWFkZSBl
eHBsaWNpdC4NCg0K4oCiICAgICAgICAgVGhlcmUgaXMgbm8gbWVudGlvbiBvZiB3aGljaCBjcnlw
dG8gYWxnb3JpdGhtcyB3aWxsIGJlIHN1cHBvcnRlZC4NCg0KVGhlIGN1cnJlbnQgZXhwZWN0YXRp
b24gaXMgU0hBMjU2LCBBRVMxMjgtQ1RSLCBhbmQgRUNDIHNlY3AyNTZyMS4gVGhlcmUgaXMgYW4g
YXJndW1lbnQgdG8gYmUgbWFkZSBmb3IgU0hBNTEyLCBBRVMyNTYtQ1RSLCBhbmQgYW4gZXF1aXZh
bGVudCBFQ0MgYWxnb3JpdGhtLiBXZSBoYXZlIGFsc28gZGlzY3Vzc2VkIHVzaW5nIGVkMjU1MTku
DQoNCuKAoiAgICAgICAgIFRoZXJlIGFyZSBzdGlsbCBhIGZldyB0eXBvcy4NCg0KSSBoYXZlIGEg
ZmV3IHVwZGF0ZXMgY29taW5nLCBzbyBJIHdpbGwgcmV2aWV3IHRoZSBkcmFmdCBhdCB0aGUgc2Ft
ZSB0aW1lLg0KDQoNCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fDQpGdWQgbWFpbGluZyBsaXN0DQpGdWRAaWV0Zi5vcmc8bWFpbHRvOkZ1ZEBpZXRmLm9yZz4N
Cmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vZnVkDQoNCklNUE9SVEFOVCBO
T1RJQ0U6IFRoZSBjb250ZW50cyBvZiB0aGlzIGVtYWlsIGFuZCBhbnkgYXR0YWNobWVudHMgYXJl
IGNvbmZpZGVudGlhbCBhbmQgbWF5IGFsc28gYmUgcHJpdmlsZWdlZC4gSWYgeW91IGFyZSBub3Qg
dGhlIGludGVuZGVkIHJlY2lwaWVudCwgcGxlYXNlIG5vdGlmeSB0aGUgc2VuZGVyIGltbWVkaWF0
ZWx5IGFuZCBkbyBub3QgZGlzY2xvc2UgdGhlIGNvbnRlbnRzIHRvIGFueSBvdGhlciBwZXJzb24s
IHVzZSBpdCBmb3IgYW55IHB1cnBvc2UsIG9yIHN0b3JlIG9yIGNvcHkgdGhlIGluZm9ybWF0aW9u
IGluIGFueSBtZWRpdW0uIFRoYW5rIHlvdS4NCg==

--_000_2BF4654C42604C7C8DD5CF892628711Barmcom_
Content-Type: text/html; charset="utf-8"
Content-ID: <4CC9ECD7EF3D9A4B889F6550CE4E536C@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64

PGh0bWw+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIgY29udGVudD0i
dGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjwvaGVhZD4NCjxib2R5IHN0eWxlPSJ3b3JkLXdy
YXA6IGJyZWFrLXdvcmQ7IC13ZWJraXQtbmJzcC1tb2RlOiBzcGFjZTsgLXdlYmtpdC1saW5lLWJy
ZWFrOiBhZnRlci13aGl0ZS1zcGFjZTsiIGNsYXNzPSIiPg0KPGRpdiBjbGFzcz0iIj5IaSBOZWQs
PC9kaXY+DQo8ZGl2IGNsYXNzPSIiPknigJl2ZSBwbGFjZWQgbXkgY29tbWVudHMgaW5saW5lLjwv
ZGl2Pg0KPGRpdiBjbGFzcz0iIj48YnIgY2xhc3M9IiI+DQo8L2Rpdj4NCjxkaXYgY2xhc3M9IiI+
VGhhbmtzIGZvciB5b3VyIGZlZWRiYWNrITwvZGl2Pg0KPGRpdiBjbGFzcz0iIj48YnIgY2xhc3M9
IiI+DQo8L2Rpdj4NCjxkaXYgY2xhc3M9IiI+QmVzdCBSZWdhcmRzLDwvZGl2Pg0KPGRpdiBjbGFz
cz0iIj5CcmVuZGFuPC9kaXY+DQo8ZGl2IGNsYXNzPSIiPjxiciBjbGFzcz0iIj4NCjwvZGl2Pg0K
PGJyIGNsYXNzPSIiPg0KPGRpdj4NCjxibG9ja3F1b3RlIHR5cGU9ImNpdGUiIGNsYXNzPSIiPg0K
PGRpdiBjbGFzcz0iIj5PbiAxNSBTZXAgMjAxNywgYXQgMTY6MjksIFNtaXRoLCBOZWQgJmx0Ozxh
IGhyZWY9Im1haWx0bzpuZWQuc21pdGhAaW50ZWwuY29tIiBjbGFzcz0iIj5uZWQuc21pdGhAaW50
ZWwuY29tPC9hPiZndDsgd3JvdGU6PC9kaXY+DQo8YnIgY2xhc3M9IkFwcGxlLWludGVyY2hhbmdl
LW5ld2xpbmUiPg0KPGRpdiBjbGFzcz0iIj4NCjxkaXYgY2xhc3M9IldvcmRTZWN0aW9uMSIgc3R5
bGU9InBhZ2U6IFdvcmRTZWN0aW9uMTsgZm9udC1mYW1pbHk6IEhlbHZldGljYTsgZm9udC1zaXpl
OiAxMnB4OyBmb250LXN0eWxlOiBub3JtYWw7IGZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7IGZv
bnQtd2VpZ2h0OiBub3JtYWw7IGxldHRlci1zcGFjaW5nOiBub3JtYWw7IHRleHQtYWxpZ246IHN0
YXJ0OyB0ZXh0LWluZGVudDogMHB4OyB0ZXh0LXRyYW5zZm9ybTogbm9uZTsgd2hpdGUtc3BhY2U6
IG5vcm1hbDsgd29yZC1zcGFjaW5nOiAwcHg7IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBw
eDsgYmFja2dyb3VuZC1jb2xvcjogcmdiKDI1NSwgMjU1LCAyNTUpOyI+DQo8ZGl2IHN0eWxlPSJt
YXJnaW46IDBpbiAwaW4gMC4wMDAxcHQgMC41aW47IGZvbnQtc2l6ZTogMTJwdDsgZm9udC1mYW1p
bHk6IENhbGlicmk7IHRleHQtaW5kZW50OiAtMC4yNWluOyIgY2xhc3M9IiI+DQo8c3BhbiBzdHls
ZT0iZm9udC1zaXplOiAxMXB0OyBmb250LWZhbWlseTogU3ltYm9sOyIgY2xhc3M9IiI+PHNwYW4g
Y2xhc3M9IiI+wrc8c3BhbiBzdHlsZT0iZm9udC1zdHlsZTogbm9ybWFsOyBmb250LXZhcmlhbnQt
Y2Fwczogbm9ybWFsOyBmb250LXdlaWdodDogbm9ybWFsOyBmb250LXNpemU6IDdwdDsgbGluZS1o
ZWlnaHQ6IG5vcm1hbDsgZm9udC1mYW1pbHk6ICdUaW1lcyBOZXcgUm9tYW4nOyIgY2xhc3M9IiI+
Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7PHNwYW4gY2xh
c3M9IkFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48L3NwYW4+PC9z
cGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6IDExcHQ7IiBjbGFzcz0iIj5Jcw0KIGl0IHBvc3Np
YmxlIGZvciB0aGUgaW1hZ2UgdHlwZSB0byBiZSBhbiBleGlzdGluZyDigJxtYW5pZmVzdOKAnSBz
dWNoIGFzIOKAnHBhY2thZ2Vz4oCdIG9yIOKAnGJ1bmRsZXPigJ0/PC9zcGFuPjwvZGl2Pg0KPC9k
aXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90ZT4NCjxiciBjbGFzcz0iIj4NCkkgZG9u4oCZdCBzZWUg
d2h5IG5vdC4gVGhlIG1hbmlmZXN0IGlzIGEgcHJldHR5IGdlbmVyaWMgd3JhcHBlci48L2Rpdj4N
CjxkaXY+PGJyIGNsYXNzPSIiPg0KPGJsb2NrcXVvdGUgdHlwZT0iY2l0ZSIgY2xhc3M9IiI+DQo8
ZGl2IGNsYXNzPSIiPg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIiBzdHlsZT0icGFnZTogV29y
ZFNlY3Rpb24xOyBmb250LWZhbWlseTogSGVsdmV0aWNhOyBmb250LXNpemU6IDEycHg7IGZvbnQt
c3R5bGU6IG5vcm1hbDsgZm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IG5v
cm1hbDsgbGV0dGVyLXNwYWNpbmc6IG5vcm1hbDsgdGV4dC1hbGlnbjogc3RhcnQ7IHRleHQtaW5k
ZW50OiAwcHg7IHRleHQtdHJhbnNmb3JtOiBub25lOyB3aGl0ZS1zcGFjZTogbm9ybWFsOyB3b3Jk
LXNwYWNpbmc6IDBweDsgLXdlYmtpdC10ZXh0LXN0cm9rZS13aWR0aDogMHB4OyBiYWNrZ3JvdW5k
LWNvbG9yOiByZ2IoMjU1LCAyNTUsIDI1NSk7Ij4NCjxkaXYgc3R5bGU9Im1hcmdpbjogMGluIDBp
biAwLjAwMDFwdCAwLjVpbjsgZm9udC1zaXplOiAxMnB0OyBmb250LWZhbWlseTogQ2FsaWJyaTsg
dGV4dC1pbmRlbnQ6IC0wLjI1aW47IiBjbGFzcz0iIj4NCjxzcGFuIHN0eWxlPSJmb250LXNpemU6
IDExcHQ7IiBjbGFzcz0iIj48bzpwIGNsYXNzPSIiPjwvbzpwPjwvc3Bhbj48L2Rpdj4NCjxkaXYg
c3R5bGU9Im1hcmdpbjogMGluIDBpbiAwLjAwMDFwdCAwLjVpbjsgZm9udC1zaXplOiAxMnB0OyBm
b250LWZhbWlseTogQ2FsaWJyaTsgdGV4dC1pbmRlbnQ6IC0wLjI1aW47IiBjbGFzcz0iIj4NCjxz
cGFuIHN0eWxlPSJmb250LXNpemU6IDExcHQ7IGZvbnQtZmFtaWx5OiBTeW1ib2w7IiBjbGFzcz0i
Ij48c3BhbiBjbGFzcz0iIj7CtzxzcGFuIHN0eWxlPSJmb250LXN0eWxlOiBub3JtYWw7IGZvbnQt
dmFyaWFudC1jYXBzOiBub3JtYWw7IGZvbnQtd2VpZ2h0OiBub3JtYWw7IGZvbnQtc2l6ZTogN3B0
OyBsaW5lLWhlaWdodDogbm9ybWFsOyBmb250LWZhbWlseTogJ1RpbWVzIE5ldyBSb21hbic7IiBj
bGFzcz0iIj4mbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDs8
c3BhbiBjbGFzcz0iQXBwbGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PC9zcGFuPjwv
c3Bhbj48L3NwYW4+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTogMTFwdDsiIGNsYXNzPSIiPklzDQog
dGhlIHB1c2ggbW9kZWwgc3VwcG9ydGVkIChjbG91ZCBzdG9yYWdlIHB1c2hlcyB1cGRhdGUgZmls
ZSBwcm9hY3RpdmVseSk/PC9zcGFuPjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90
ZT4NCjxkaXY+PGJyIGNsYXNzPSIiPg0KPC9kaXY+DQo8ZGl2PkNlcnRhaW5seS4gVGhpcyBpcyBv
bmUgb2YgdGhlIGV4cGVjdGVkIHVzZS1jYXNlcywgaG93ZXZlciBtYW5pZmVzdCBtdXN0IHByZWNl
ZGUgcGF5bG9hZC48L2Rpdj4NCjxiciBjbGFzcz0iIj4NCjxibG9ja3F1b3RlIHR5cGU9ImNpdGUi
IGNsYXNzPSIiPg0KPGRpdiBjbGFzcz0iIj4NCjxkaXYgY2xhc3M9IldvcmRTZWN0aW9uMSIgc3R5
bGU9InBhZ2U6IFdvcmRTZWN0aW9uMTsgZm9udC1mYW1pbHk6IEhlbHZldGljYTsgZm9udC1zaXpl
OiAxMnB4OyBmb250LXN0eWxlOiBub3JtYWw7IGZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7IGZv
bnQtd2VpZ2h0OiBub3JtYWw7IGxldHRlci1zcGFjaW5nOiBub3JtYWw7IHRleHQtYWxpZ246IHN0
YXJ0OyB0ZXh0LWluZGVudDogMHB4OyB0ZXh0LXRyYW5zZm9ybTogbm9uZTsgd2hpdGUtc3BhY2U6
IG5vcm1hbDsgd29yZC1zcGFjaW5nOiAwcHg7IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBw
eDsgYmFja2dyb3VuZC1jb2xvcjogcmdiKDI1NSwgMjU1LCAyNTUpOyI+DQo8ZGl2IHN0eWxlPSJt
YXJnaW46IDBpbiAwaW4gMC4wMDAxcHQgMC41aW47IGZvbnQtc2l6ZTogMTJwdDsgZm9udC1mYW1p
bHk6IENhbGlicmk7IHRleHQtaW5kZW50OiAtMC4yNWluOyIgY2xhc3M9IiI+DQo8c3BhbiBzdHls
ZT0iZm9udC1zaXplOiAxMXB0OyIgY2xhc3M9IiI+PG86cCBjbGFzcz0iIj48L286cD48L3NwYW4+
PC9kaXY+DQo8ZGl2IHN0eWxlPSJtYXJnaW46IDBpbiAwaW4gMC4wMDAxcHQgMC41aW47IGZvbnQt
c2l6ZTogMTJwdDsgZm9udC1mYW1pbHk6IENhbGlicmk7IHRleHQtaW5kZW50OiAtMC4yNWluOyIg
Y2xhc3M9IiI+DQo8c3BhbiBzdHlsZT0iZm9udC1zaXplOiAxMXB0OyBmb250LWZhbWlseTogU3lt
Ym9sOyIgY2xhc3M9IiI+PHNwYW4gY2xhc3M9IiI+wrc8c3BhbiBzdHlsZT0iZm9udC1zdHlsZTog
bm9ybWFsOyBmb250LXZhcmlhbnQtY2Fwczogbm9ybWFsOyBmb250LXdlaWdodDogbm9ybWFsOyBm
b250LXNpemU6IDdwdDsgbGluZS1oZWlnaHQ6IG5vcm1hbDsgZm9udC1mYW1pbHk6ICdUaW1lcyBO
ZXcgUm9tYW4nOyIgY2xhc3M9IiI+Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7
Jm5ic3A7Jm5ic3A7PHNwYW4gY2xhc3M9IkFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9z
cGFuPjwvc3Bhbj48L3NwYW4+PC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6IDExcHQ7IiBj
bGFzcz0iIj5XaHkNCiB3YXMgQVNOLjEgc2VsZWN0ZWQgYXMgdGhlIGVuY29kaW5nIGZvcm1hdD8g
KFdoeSBub3QgQ09TRT8pPC9zcGFuPjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90
ZT4NCjxkaXY+PGJyIGNsYXNzPSIiPg0KPC9kaXY+DQo8ZGl2PkFTTi4xIHdhcyB1c2VkIGZvciBh
IGZldyByZWFzb25zLjwvZGl2Pg0KPGRpdj4NCjxvbCBjbGFzcz0iTWFpbE91dGxpbmUiPg0KPGxp
IGNsYXNzPSIiPkl0IGlzIHRoZSBkZWZhdWx0IGZvcm1hdCBmb3IgY2VydGlmaWNhdGVzLiBNb3N0
IHRvb2xzIHVzZSBERVIgcmF0aGVyIHRoYW4gQ09TRSBmb3IgcGFja2luZyBjZXJ0aWZpY2F0ZXMs
IHNvIHRoaXMgcmVkdWNlcyB0aGUgbnVtYmVyIG9mIHBhcnNlcnMgaW4gdGhlIHRhcmdldC4gV2hl
cmUgaW50ZXJ3b3JrIHdpdGggSFNNcyBpcyBpbnZvbHZlZCwgdXNpbmcgYSBmb3JtYXQgdGhlIEhT
TSBzdXBwb3J0cyBpcyBiZW5lZmljaWFsLjwvbGk+PGxpIGNsYXNzPSIiPlBDS1M3IC8gQ01TIC8g
UkZDNTY1MiBhcmUgd2lkZWx5IHN1cHBvcnRlZC4gRm9yIGV4YW1wbGUsIE9wZW5TU0zigJlzIHNt
aW1lIGNvbW1hbmQgaGFuZGxlcyBDTVMgc2lnbmluZy92YWxpZGF0aW9uIGRpcmVjdGx5LiBUaGlz
IG1ha2VzIHRoZSBjdXN0b20gdG9vbGluZyByZXF1aXJlZCBzaW1wbGVyLiBUaGlzIHdpbGwgYWxz
bywgaG9wZWZ1bGx5LCBpbXByb3ZlIGNvbXBhdGliaWxpdHkgd2l0aCBleGlzdGluZyBIU01zPC9s
aT48bGkgY2xhc3M9IiI+RGlyZWN0IGNvZGUgZ2VuZXJhdGlvbi4gSW4gYSBzY2VuYXJpbyB3aGVy
ZSB0aGUgcGFyc2VyIGRvZXMgbm90IGNyZWF0ZSBhIGRvY3VtZW50IG9iamVjdCBtb2RlbCwgYnV0
IGV4dHJhY3RzIG9yIHZhbGlkYXRlcyBzcGVjaWZpYyBmaWVsZHMsIEFTTi4xIHByb3ZpZGVzIGEg
Z3JhbW1hciB0aGF0IG1ha2VzIGl0IHBvc3NpYmxlIHRvIGdlbmVyYXRlIGEgcGFyc2VyIHByb2dy
YW1hdGljYWxseS48L2xpPjxsaSBjbGFzcz0iIj5UaGUgbWVhbmluZyBvZiDigJxsZW5ndGjigJ0g
Zm9yIGNvbXBvc2l0ZSB0eXBlcy4gSW4gREVSLCB0aGUgbGVuZ3RoIG9mIGEgZmllbGQgaXMgdW5h
bWJpZ3VvdXMuIEl0IGlzIGFsd2F5cyB0aGUgbGVuZ3RoLCBpbiBieXRlcywgb2YgdGhlIGNvbnRh
aW5lZCBvYmplY3QuIFRoaXMgYWxsb3dzIGEgcGFyc2VyIHRoYXQgdW5kZXJzdGFuZHMgdGhlIGRv
Y3VtZW50IGJlaW5nIHBhcnNlZCB0byBza2lwIGxhcmdlIGNodW5rcyBvZiBhIGRlZXBseQ0KIG5l
c3RlZCB0cmVlLiBJbiBDQk9SLCB0aGUg4oCcbGVuZ3Ro4oCdIG9mIGFuIGFycmF5IG9yIG1hcCBp
cyB0aGUgbnVtYmVyIG9mIGVsZW1lbnRzIGl0IGNvbnRhaW5zLiBUaGlzIG1ha2VzIGl0IGltcG9z
c2libGUgZm9yIHRoZSBwYXJzZXIgdG8g4oCcc2tpcOKAnSBhbnl0aGluZy4gSXQgaGFzIHRvIHBh
cnNlIHRoZSBlbnRpcmUgc3RydWN0dXJlLiBJdCBpcyBwb3NzaWJsZSB0byBjaXJjdW12ZW50IHNv
bWUgb2YgdGhlc2UgbGltaXRhdGlvbnMgdXNpbmcgdGFnZ2luZywNCiBpbiBwYXJ0aWN1bGFyIHRh
ZyAyNCAoZW5jb2RlZCBDQk9SIGRhdGEgaXRlbSksIGJ1dCB0aGlzIGhhcyB0aGUgZG93bnNpZGUg
b2YgYnJlYWtpbmcgdHJhbnNsYXRhYmlsaXR5IHRvIEpTT04sIHdoaWNoIGlzIGEga2V5IGFkdmFu
dGFnZSBvZiBDQk9SLiBDb25zaXN0ZW50IFRMViByZXByZXNlbnRhdGlvbiBtYWtlcyBwYXJzaW5n
IGluIGEgY29uc3RyYWluZWQgZW52aXJvbm1lbnQgb2ZmZXJzIGEgbm90aW9uYWwgcGVyZm9ybWFu
Y2UgaW1wcm92ZW1lbnQsDQogYnV0IHRoaXMgaXMgbWlub3IgYW5kIG1heSBub3QgcGxheSBvdXQg
aW4gcHJhY3RpY2UuPC9saT48L29sPg0KPGRpdiBjbGFzcz0iIj48YnIgY2xhc3M9IiI+DQo8L2Rp
dj4NCjxkaXYgY2xhc3M9IiI+TmV2ZXIgdGhlIGxlc3MsIEkgdGhpbmsgdGhhdCBDQk9SL0NPU0Ug
d291bGQgYmUgcGVyZmVjdGx5IHNlcnZpY2VhYmxlIGZvciB0aGlzIHVzZS4gSeKAmW0gbm90IGV2
ZW4gY2VydGFpbiB0aGF0IEFTTi4xIGNhbuKAmXQgYmUgdXNlZCBhcyBhIHNjaGVtYSBmb3IgQ0JP
UiAoc2VlIDMgYWJvdmUpLiBUaGF0IGJlaW5nIHRoZSBjYXNlLCBJIGNhbiBzZWUgYSBjYXNlIGZv
ciBERVIgbWFuaWZlc3RzIHdpdGggQ01TLCBhbmQgQ0JPUiBtYW5pZmVzdHMNCiB3aXRoIENPU0Uu
PC9kaXY+DQo8ZGl2IGNsYXNzPSIiPjxiciBjbGFzcz0iIj4NCjwvZGl2Pg0KPC9kaXY+DQo8YnIg
Y2xhc3M9IiI+DQo8YmxvY2txdW90ZSB0eXBlPSJjaXRlIiBjbGFzcz0iIj4NCjxkaXYgY2xhc3M9
IiI+DQo8ZGl2IGNsYXNzPSJXb3JkU2VjdGlvbjEiIHN0eWxlPSJwYWdlOiBXb3JkU2VjdGlvbjE7
IGZvbnQtZmFtaWx5OiBIZWx2ZXRpY2E7IGZvbnQtc2l6ZTogMTJweDsgZm9udC1zdHlsZTogbm9y
bWFsOyBmb250LXZhcmlhbnQtY2Fwczogbm9ybWFsOyBmb250LXdlaWdodDogbm9ybWFsOyBsZXR0
ZXItc3BhY2luZzogbm9ybWFsOyB0ZXh0LWFsaWduOiBzdGFydDsgdGV4dC1pbmRlbnQ6IDBweDsg
dGV4dC10cmFuc2Zvcm06IG5vbmU7IHdoaXRlLXNwYWNlOiBub3JtYWw7IHdvcmQtc3BhY2luZzog
MHB4OyAtd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRoOiAwcHg7IGJhY2tncm91bmQtY29sb3I6IHJn
YigyNTUsIDI1NSwgMjU1KTsiPg0KPGRpdiBzdHlsZT0ibWFyZ2luOiAwaW4gMGluIDAuMDAwMXB0
IDAuNWluOyBmb250LXNpemU6IDEycHQ7IGZvbnQtZmFtaWx5OiBDYWxpYnJpOyB0ZXh0LWluZGVu
dDogLTAuMjVpbjsiIGNsYXNzPSIiPg0KPHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTogMTFwdDsiIGNs
YXNzPSIiPjxvOnAgY2xhc3M9IiI+PC9vOnA+PC9zcGFuPjwvZGl2Pg0KPGRpdiBzdHlsZT0ibWFy
Z2luOiAwaW4gMGluIDAuMDAwMXB0IDAuNWluOyBmb250LXNpemU6IDEycHQ7IGZvbnQtZmFtaWx5
OiBDYWxpYnJpOyB0ZXh0LWluZGVudDogLTAuMjVpbjsiIGNsYXNzPSIiPg0KPHNwYW4gc3R5bGU9
ImZvbnQtc2l6ZTogMTFwdDsgZm9udC1mYW1pbHk6IFN5bWJvbDsiIGNsYXNzPSIiPjxzcGFuIGNs
YXNzPSIiPsK3PHNwYW4gc3R5bGU9ImZvbnQtc3R5bGU6IG5vcm1hbDsgZm9udC12YXJpYW50LWNh
cHM6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IG5vcm1hbDsgZm9udC1zaXplOiA3cHQ7IGxpbmUtaGVp
Z2h0OiBub3JtYWw7IGZvbnQtZmFtaWx5OiAnVGltZXMgTmV3IFJvbWFuJzsiIGNsYXNzPSIiPiZu
YnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOzxzcGFuIGNsYXNz
PSJBcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48L3NwYW4+PC9zcGFuPjwvc3Bh
bj48c3BhbiBzdHlsZT0iZm9udC1zaXplOiAxMXB0OyIgY2xhc3M9IiI+SXQNCiBpc27igJl0IGNs
ZWFyIGhvdyB0aGUgbWFuaWZlc3QgYW5kIHRoZSBpbWFnZSAocGFja2FnZSAvIGJ1bmRsZSkgd2ls
bCBzaGFyZSB0aGUgYXZhaWxhYmxlIEEgL0Igc3RvcmFnZSBhcmVhLiBQb3NzaWJseSBpdCBpcyBh
c3N1bWVkIHRoZSBtYW5pZmVzdCByZWxhdGVkIG9wZXJhdGlvbnMgYXJlIHRvIGJlIGludGVncmF0
ZWQgaW50byBhbiBleGlzdGluZyBTVyB1cGRhdGUgY2FwYWJpbGl0eSBhbmQgYmUgdGF1Z2h0IHRv
IHVuZGVyc3RhbmQgdGhlIG1hbmlmZXN0DQogc3RydWN0dXJlLiBDb25zaWRlciB0aGUgY2FzZSB3
aGVyZSB2ZXJzaW9uIDEgb2YgYSBTVyB1cGRhdGUgdG9vbCB1bmRlcnN0YW5kcyBidW5kbGVzIGJ1
dCBpdCByZWNlaXZlcyBhIGZpbGUgdGhhdCBjb250YWlucyBhIG1hbmlmZXN0LiBJcyBpdCBleHBl
Y3RlZCB0aGF0IHRoZSB2MSB0b29sIHdpbGwgYmUgYWJsZSB0byBwcm9jZXNzIHRoZSB1cGRhdGUg
bmV2ZXJ0aGVsZXNzIChpZ25vcmluZyB0aGUgbWFuaWZlc3QpLiBUaGlzIGFzc3VtZXMgdGhlDQog
ZW5jcnlwdGlvbiBvcHRpb24gaXNu4oCZdCBiZWluZyBhcHBsaWVkIG9mIGNvdXJzZS48L3NwYW4+
PC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9ibG9ja3F1b3RlPg0KPGRpdj48YnIgY2xhc3M9IiI+
DQo8L2Rpdj4NCjxkaXY+VGhlIGV4cGVjdGF0aW9uIHdhcyB0aGF0IG1hbmlmZXN0IHdvdWxkIGJl
IHN0b3JlZCBpbnRvIGEgc2VwYXJhdGUga2V5L3ZhbHVlIHN0b3JlLiZuYnNwOzwvZGl2Pg0KPGJy
IGNsYXNzPSIiPg0KPGJsb2NrcXVvdGUgdHlwZT0iY2l0ZSIgY2xhc3M9IiI+DQo8ZGl2IGNsYXNz
PSIiPg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIiBzdHlsZT0icGFnZTogV29yZFNlY3Rpb24x
OyBmb250LWZhbWlseTogSGVsdmV0aWNhOyBmb250LXNpemU6IDEycHg7IGZvbnQtc3R5bGU6IG5v
cm1hbDsgZm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IG5vcm1hbDsgbGV0
dGVyLXNwYWNpbmc6IG5vcm1hbDsgdGV4dC1hbGlnbjogc3RhcnQ7IHRleHQtaW5kZW50OiAwcHg7
IHRleHQtdHJhbnNmb3JtOiBub25lOyB3aGl0ZS1zcGFjZTogbm9ybWFsOyB3b3JkLXNwYWNpbmc6
IDBweDsgLXdlYmtpdC10ZXh0LXN0cm9rZS13aWR0aDogMHB4OyBiYWNrZ3JvdW5kLWNvbG9yOiBy
Z2IoMjU1LCAyNTUsIDI1NSk7Ij4NCjxkaXYgc3R5bGU9Im1hcmdpbjogMGluIDBpbiAwLjAwMDFw
dCAwLjVpbjsgZm9udC1zaXplOiAxMnB0OyBmb250LWZhbWlseTogQ2FsaWJyaTsgdGV4dC1pbmRl
bnQ6IC0wLjI1aW47IiBjbGFzcz0iIj4NCjxzcGFuIHN0eWxlPSJmb250LXNpemU6IDExcHQ7IiBj
bGFzcz0iIj48bzpwIGNsYXNzPSIiPjwvbzpwPjwvc3Bhbj48L2Rpdj4NCjxkaXYgc3R5bGU9Im1h
cmdpbjogMGluIDBpbiAwLjAwMDFwdCAwLjVpbjsgZm9udC1zaXplOiAxMnB0OyBmb250LWZhbWls
eTogQ2FsaWJyaTsgdGV4dC1pbmRlbnQ6IC0wLjI1aW47IiBjbGFzcz0iIj4NCjxzcGFuIHN0eWxl
PSJmb250LXNpemU6IDExcHQ7IGZvbnQtZmFtaWx5OiBTeW1ib2w7IiBjbGFzcz0iIj48c3BhbiBj
bGFzcz0iIj7CtzxzcGFuIHN0eWxlPSJmb250LXN0eWxlOiBub3JtYWw7IGZvbnQtdmFyaWFudC1j
YXBzOiBub3JtYWw7IGZvbnQtd2VpZ2h0OiBub3JtYWw7IGZvbnQtc2l6ZTogN3B0OyBsaW5lLWhl
aWdodDogbm9ybWFsOyBmb250LWZhbWlseTogJ1RpbWVzIE5ldyBSb21hbic7IiBjbGFzcz0iIj4m
bmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDs8c3BhbiBjbGFz
cz0iQXBwbGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PC9zcGFuPjwvc3Bhbj48L3Nw
YW4+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTogMTFwdDsiIGNsYXNzPSIiPlRoZQ0KIGFyY2ggZGlk
buKAmXQgbWVudGlvbiBpbnRlZ3JpdHkgYXMgYSByZXF1aXJlbWVudC4gTWF5YmUgaXQgaXMgaW1w
bGllZCBidXQgaXQgc2VlbXMgcG9zc2libGUgZm9yIGEgY2xldmVyIGF0dGFja2VyIHRvIHJlcGxh
Y2Ugb25lIGNpcGhlciB0ZXh0IHdpdGggYSBkaWZmZXJlbnQgY2lwaGVyIHRleHQgdW5sZXNzIGlu
dGVncml0eSB3ZXJlIG1lbnRpb25lZCBhcyBhIGdvYWwgYW5kIHN0ZXBzIHRha2VuIHRvIGFsbG93
IG9ubHkgY2lwaGVyIHN1aXRlcyB0aGF0DQogYWNoaWV2ZSBib3RoIG9iamVjdGl2ZXMuPC9zcGFu
PjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90ZT4NCjxkaXY+PGJyIGNsYXNzPSIi
Pg0KPC9kaXY+DQo8ZGl2PlRoaXMgaXMgYW4gaW50ZXJlc3RpbmcgcG9pbnQuIFdlIG1heSBoYXZl
IGRyYWZ0ZWQgaXQgYXMgYW4gaW1wbGljaXQgcmVxdWlyZW1lbnQuIEkgaGF2ZSBtYWRlIHRoZSBh
c3N1bXB0aW9uIHRoYXQgaW50ZWdyaXR5IGlzIGEgcHJlcmVxdWlzaXRlIGZvciBhdXRoZW50aWNp
dHkgYW5kIGF1dGhlbnRpY2l0eSBpcyBhbiBleHByZXNzbHkgc3RhdGVkIGdvYWwuIEhvd2V2ZXIs
IHlvdSBhcmUgY29ycmVjdCwgdGhpcyBzaG91bGQgYmUgbWFkZSBleHBsaWNpdC48L2Rpdj4NCjxi
ciBjbGFzcz0iIj4NCjxibG9ja3F1b3RlIHR5cGU9ImNpdGUiIGNsYXNzPSIiPg0KPGRpdiBjbGFz
cz0iIj4NCjxkaXYgY2xhc3M9IldvcmRTZWN0aW9uMSIgc3R5bGU9InBhZ2U6IFdvcmRTZWN0aW9u
MTsgZm9udC1mYW1pbHk6IEhlbHZldGljYTsgZm9udC1zaXplOiAxMnB4OyBmb250LXN0eWxlOiBu
b3JtYWw7IGZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7IGZvbnQtd2VpZ2h0OiBub3JtYWw7IGxl
dHRlci1zcGFjaW5nOiBub3JtYWw7IHRleHQtYWxpZ246IHN0YXJ0OyB0ZXh0LWluZGVudDogMHB4
OyB0ZXh0LXRyYW5zZm9ybTogbm9uZTsgd2hpdGUtc3BhY2U6IG5vcm1hbDsgd29yZC1zcGFjaW5n
OiAwcHg7IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBweDsgYmFja2dyb3VuZC1jb2xvcjog
cmdiKDI1NSwgMjU1LCAyNTUpOyI+DQo8ZGl2IHN0eWxlPSJtYXJnaW46IDBpbiAwaW4gMC4wMDAx
cHQgMC41aW47IGZvbnQtc2l6ZTogMTJwdDsgZm9udC1mYW1pbHk6IENhbGlicmk7IHRleHQtaW5k
ZW50OiAtMC4yNWluOyIgY2xhc3M9IiI+DQo8c3BhbiBzdHlsZT0iZm9udC1zaXplOiAxMXB0OyIg
Y2xhc3M9IiI+PG86cCBjbGFzcz0iIj48L286cD48L3NwYW4+PC9kaXY+DQo8ZGl2IHN0eWxlPSJt
YXJnaW46IDBpbiAwaW4gMC4wMDAxcHQgMC41aW47IGZvbnQtc2l6ZTogMTJwdDsgZm9udC1mYW1p
bHk6IENhbGlicmk7IHRleHQtaW5kZW50OiAtMC4yNWluOyIgY2xhc3M9IiI+DQo8c3BhbiBzdHls
ZT0iZm9udC1zaXplOiAxMXB0OyBmb250LWZhbWlseTogU3ltYm9sOyIgY2xhc3M9IiI+PHNwYW4g
Y2xhc3M9IiI+wrc8c3BhbiBzdHlsZT0iZm9udC1zdHlsZTogbm9ybWFsOyBmb250LXZhcmlhbnQt
Y2Fwczogbm9ybWFsOyBmb250LXdlaWdodDogbm9ybWFsOyBmb250LXNpemU6IDdwdDsgbGluZS1o
ZWlnaHQ6IG5vcm1hbDsgZm9udC1mYW1pbHk6ICdUaW1lcyBOZXcgUm9tYW4nOyIgY2xhc3M9IiI+
Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7PHNwYW4gY2xh
c3M9IkFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48L3NwYW4+PC9z
cGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6IDExcHQ7IiBjbGFzcz0iIj5UaGVyZQ0KIGlzIG5v
IG1lbnRpb24gb2Ygd2hpY2ggY3J5cHRvIGFsZ29yaXRobXMgd2lsbCBiZSBzdXBwb3J0ZWQuPC9z
cGFuPjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90ZT4NCjxkaXY+PGJyIGNsYXNz
PSIiPg0KPC9kaXY+DQo8ZGl2PlRoZSBjdXJyZW50IGV4cGVjdGF0aW9uIGlzIFNIQTI1NiwgQUVT
MTI4LUNUUiwgYW5kIEVDQyBzZWNwMjU2cjEuIFRoZXJlIGlzIGFuIGFyZ3VtZW50IHRvIGJlIG1h
ZGUgZm9yIFNIQTUxMiwgQUVTMjU2LUNUUiwgYW5kIGFuIGVxdWl2YWxlbnQgRUNDIGFsZ29yaXRo
bS4gV2UgaGF2ZSBhbHNvIGRpc2N1c3NlZCB1c2luZyBlZDI1NTE5LjwvZGl2Pg0KPGJyIGNsYXNz
PSIiPg0KPGJsb2NrcXVvdGUgdHlwZT0iY2l0ZSIgY2xhc3M9IiI+DQo8ZGl2IGNsYXNzPSIiPg0K
PGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIiBzdHlsZT0icGFnZTogV29yZFNlY3Rpb24xOyBmb250
LWZhbWlseTogSGVsdmV0aWNhOyBmb250LXNpemU6IDEycHg7IGZvbnQtc3R5bGU6IG5vcm1hbDsg
Zm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IG5vcm1hbDsgbGV0dGVyLXNw
YWNpbmc6IG5vcm1hbDsgdGV4dC1hbGlnbjogc3RhcnQ7IHRleHQtaW5kZW50OiAwcHg7IHRleHQt
dHJhbnNmb3JtOiBub25lOyB3aGl0ZS1zcGFjZTogbm9ybWFsOyB3b3JkLXNwYWNpbmc6IDBweDsg
LXdlYmtpdC10ZXh0LXN0cm9rZS13aWR0aDogMHB4OyBiYWNrZ3JvdW5kLWNvbG9yOiByZ2IoMjU1
LCAyNTUsIDI1NSk7Ij4NCjxkaXYgc3R5bGU9Im1hcmdpbjogMGluIDBpbiAwLjAwMDFwdCAwLjVp
bjsgZm9udC1zaXplOiAxMnB0OyBmb250LWZhbWlseTogQ2FsaWJyaTsgdGV4dC1pbmRlbnQ6IC0w
LjI1aW47IiBjbGFzcz0iIj4NCjxzcGFuIHN0eWxlPSJmb250LXNpemU6IDExcHQ7IiBjbGFzcz0i
Ij48bzpwIGNsYXNzPSIiPjwvbzpwPjwvc3Bhbj48L2Rpdj4NCjxkaXYgc3R5bGU9Im1hcmdpbjog
MGluIDBpbiAwLjAwMDFwdCAwLjVpbjsgZm9udC1zaXplOiAxMnB0OyBmb250LWZhbWlseTogQ2Fs
aWJyaTsgdGV4dC1pbmRlbnQ6IC0wLjI1aW47IiBjbGFzcz0iIj4NCjxzcGFuIHN0eWxlPSJmb250
LXNpemU6IDExcHQ7IGZvbnQtZmFtaWx5OiBTeW1ib2w7IiBjbGFzcz0iIj48c3BhbiBjbGFzcz0i
Ij7CtzxzcGFuIHN0eWxlPSJmb250LXN0eWxlOiBub3JtYWw7IGZvbnQtdmFyaWFudC1jYXBzOiBu
b3JtYWw7IGZvbnQtd2VpZ2h0OiBub3JtYWw7IGZvbnQtc2l6ZTogN3B0OyBsaW5lLWhlaWdodDog
bm9ybWFsOyBmb250LWZhbWlseTogJ1RpbWVzIE5ldyBSb21hbic7IiBjbGFzcz0iIj4mbmJzcDsm
bmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDsmbmJzcDs8c3BhbiBjbGFzcz0iQXBw
bGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PC9zcGFuPjwvc3Bhbj48L3NwYW4+PHNw
YW4gc3R5bGU9ImZvbnQtc2l6ZTogMTFwdDsiIGNsYXNzPSIiPlRoZXJlDQogYXJlIHN0aWxsIGEg
ZmV3IHR5cG9zLjwvc3Bhbj48L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Jsb2NrcXVvdGU+DQo8
ZGl2PjxiciBjbGFzcz0iIj4NCjwvZGl2Pg0KSSBoYXZlIGEgZmV3IHVwZGF0ZXMgY29taW5nLCBz
byBJIHdpbGwgcmV2aWV3IHRoZSBkcmFmdCBhdCB0aGUgc2FtZSB0aW1lLjwvZGl2Pg0KPGRpdj48
YnIgY2xhc3M9IiI+DQo8YmxvY2txdW90ZSB0eXBlPSJjaXRlIiBjbGFzcz0iIj4NCjxkaXYgY2xh
c3M9IiI+DQo8ZGl2IGNsYXNzPSJXb3JkU2VjdGlvbjEiIHN0eWxlPSJwYWdlOiBXb3JkU2VjdGlv
bjE7IGZvbnQtZmFtaWx5OiBIZWx2ZXRpY2E7IGZvbnQtc2l6ZTogMTJweDsgZm9udC1zdHlsZTog
bm9ybWFsOyBmb250LXZhcmlhbnQtY2Fwczogbm9ybWFsOyBmb250LXdlaWdodDogbm9ybWFsOyBs
ZXR0ZXItc3BhY2luZzogbm9ybWFsOyB0ZXh0LWFsaWduOiBzdGFydDsgdGV4dC1pbmRlbnQ6IDBw
eDsgdGV4dC10cmFuc2Zvcm06IG5vbmU7IHdoaXRlLXNwYWNlOiBub3JtYWw7IHdvcmQtc3BhY2lu
ZzogMHB4OyAtd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRoOiAwcHg7IGJhY2tncm91bmQtY29sb3I6
IHJnYigyNTUsIDI1NSwgMjU1KTsiPg0KPGRpdiBzdHlsZT0ibWFyZ2luOiAwaW4gMGluIDAuMDAw
MXB0IDAuNWluOyBmb250LXNpemU6IDEycHQ7IGZvbnQtZmFtaWx5OiBDYWxpYnJpOyB0ZXh0LWlu
ZGVudDogLTAuMjVpbjsiIGNsYXNzPSIiPg0KPHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTogMTFwdDsi
IGNsYXNzPSIiPjxvOnAgY2xhc3M9IiI+PC9vOnA+PC9zcGFuPjwvZGl2Pg0KPGRpdiBzdHlsZT0i
bWFyZ2luOiAwaW4gMGluIDAuMDAwMXB0OyBmb250LXNpemU6IDEycHQ7IGZvbnQtZmFtaWx5OiBD
YWxpYnJpOyIgY2xhc3M9IiI+DQo8c3BhbiBzdHlsZT0iZm9udC1zaXplOiAxMXB0OyIgY2xhc3M9
IiI+PG86cCBjbGFzcz0iIj4mbmJzcDs8L286cD48L3NwYW4+PC9kaXY+DQo8L2Rpdj4NCjxzcGFu
IHN0eWxlPSJmb250LWZhbWlseTogSGVsdmV0aWNhOyBmb250LXNpemU6IDEycHg7IGZvbnQtc3R5
bGU6IG5vcm1hbDsgZm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IG5vcm1h
bDsgbGV0dGVyLXNwYWNpbmc6IG5vcm1hbDsgdGV4dC1hbGlnbjogc3RhcnQ7IHRleHQtaW5kZW50
OiAwcHg7IHRleHQtdHJhbnNmb3JtOiBub25lOyB3aGl0ZS1zcGFjZTogbm9ybWFsOyB3b3JkLXNw
YWNpbmc6IDBweDsgLXdlYmtpdC10ZXh0LXN0cm9rZS13aWR0aDogMHB4OyBiYWNrZ3JvdW5kLWNv
bG9yOiByZ2IoMjU1LCAyNTUsIDI1NSk7IGZsb2F0OiBub25lOyBkaXNwbGF5OiBpbmxpbmUgIWlt
cG9ydGFudDsiIGNsYXNzPSIiPl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fPC9zcGFuPjxiciBzdHlsZT0iZm9udC1mYW1pbHk6IEhlbHZldGljYTsgZm9udC1z
aXplOiAxMnB4OyBmb250LXN0eWxlOiBub3JtYWw7IGZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7
IGZvbnQtd2VpZ2h0OiBub3JtYWw7IGxldHRlci1zcGFjaW5nOiBub3JtYWw7IHRleHQtYWxpZ246
IHN0YXJ0OyB0ZXh0LWluZGVudDogMHB4OyB0ZXh0LXRyYW5zZm9ybTogbm9uZTsgd2hpdGUtc3Bh
Y2U6IG5vcm1hbDsgd29yZC1zcGFjaW5nOiAwcHg7IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6
IDBweDsgYmFja2dyb3VuZC1jb2xvcjogcmdiKDI1NSwgMjU1LCAyNTUpOyIgY2xhc3M9IiI+DQo8
c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6IEhlbHZldGljYTsgZm9udC1zaXplOiAxMnB4OyBmb250
LXN0eWxlOiBub3JtYWw7IGZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7IGZvbnQtd2VpZ2h0OiBu
b3JtYWw7IGxldHRlci1zcGFjaW5nOiBub3JtYWw7IHRleHQtYWxpZ246IHN0YXJ0OyB0ZXh0LWlu
ZGVudDogMHB4OyB0ZXh0LXRyYW5zZm9ybTogbm9uZTsgd2hpdGUtc3BhY2U6IG5vcm1hbDsgd29y
ZC1zcGFjaW5nOiAwcHg7IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBweDsgYmFja2dyb3Vu
ZC1jb2xvcjogcmdiKDI1NSwgMjU1LCAyNTUpOyBmbG9hdDogbm9uZTsgZGlzcGxheTogaW5saW5l
ICFpbXBvcnRhbnQ7IiBjbGFzcz0iIj5GdWQNCiBtYWlsaW5nIGxpc3Q8L3NwYW4+PGJyIHN0eWxl
PSJmb250LWZhbWlseTogSGVsdmV0aWNhOyBmb250LXNpemU6IDEycHg7IGZvbnQtc3R5bGU6IG5v
cm1hbDsgZm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IG5vcm1hbDsgbGV0
dGVyLXNwYWNpbmc6IG5vcm1hbDsgdGV4dC1hbGlnbjogc3RhcnQ7IHRleHQtaW5kZW50OiAwcHg7
IHRleHQtdHJhbnNmb3JtOiBub25lOyB3aGl0ZS1zcGFjZTogbm9ybWFsOyB3b3JkLXNwYWNpbmc6
IDBweDsgLXdlYmtpdC10ZXh0LXN0cm9rZS13aWR0aDogMHB4OyBiYWNrZ3JvdW5kLWNvbG9yOiBy
Z2IoMjU1LCAyNTUsIDI1NSk7IiBjbGFzcz0iIj4NCjxhIGhyZWY9Im1haWx0bzpGdWRAaWV0Zi5v
cmciIHN0eWxlPSJjb2xvcjogcmdiKDE0OSwgNzksIDExNCk7IHRleHQtZGVjb3JhdGlvbjogdW5k
ZXJsaW5lOyBmb250LWZhbWlseTogSGVsdmV0aWNhOyBmb250LXNpemU6IDEycHg7IGZvbnQtc3R5
bGU6IG5vcm1hbDsgZm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IG5vcm1h
bDsgbGV0dGVyLXNwYWNpbmc6IG5vcm1hbDsgb3JwaGFuczogYXV0bzsgdGV4dC1hbGlnbjogc3Rh
cnQ7IHRleHQtaW5kZW50OiAwcHg7IHRleHQtdHJhbnNmb3JtOiBub25lOyB3aGl0ZS1zcGFjZTog
bm9ybWFsOyB3aWRvd3M6IGF1dG87IHdvcmQtc3BhY2luZzogMHB4OyAtd2Via2l0LXRleHQtc2l6
ZS1hZGp1c3Q6IGF1dG87IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBweDsgYmFja2dyb3Vu
ZC1jb2xvcjogcmdiKDI1NSwgMjU1LCAyNTUpOyIgY2xhc3M9IiI+RnVkQGlldGYub3JnPC9hPjxi
ciBzdHlsZT0iZm9udC1mYW1pbHk6IEhlbHZldGljYTsgZm9udC1zaXplOiAxMnB4OyBmb250LXN0
eWxlOiBub3JtYWw7IGZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7IGZvbnQtd2VpZ2h0OiBub3Jt
YWw7IGxldHRlci1zcGFjaW5nOiBub3JtYWw7IHRleHQtYWxpZ246IHN0YXJ0OyB0ZXh0LWluZGVu
dDogMHB4OyB0ZXh0LXRyYW5zZm9ybTogbm9uZTsgd2hpdGUtc3BhY2U6IG5vcm1hbDsgd29yZC1z
cGFjaW5nOiAwcHg7IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBweDsgYmFja2dyb3VuZC1j
b2xvcjogcmdiKDI1NSwgMjU1LCAyNTUpOyIgY2xhc3M9IiI+DQo8YSBocmVmPSJodHRwczovL3d3
dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2Z1ZCIgc3R5bGU9ImNvbG9yOiByZ2IoMTQ5LCA3
OSwgMTE0KTsgdGV4dC1kZWNvcmF0aW9uOiB1bmRlcmxpbmU7IGZvbnQtZmFtaWx5OiBIZWx2ZXRp
Y2E7IGZvbnQtc2l6ZTogMTJweDsgZm9udC1zdHlsZTogbm9ybWFsOyBmb250LXZhcmlhbnQtY2Fw
czogbm9ybWFsOyBmb250LXdlaWdodDogbm9ybWFsOyBsZXR0ZXItc3BhY2luZzogbm9ybWFsOyBv
cnBoYW5zOiBhdXRvOyB0ZXh0LWFsaWduOiBzdGFydDsgdGV4dC1pbmRlbnQ6IDBweDsgdGV4dC10
cmFuc2Zvcm06IG5vbmU7IHdoaXRlLXNwYWNlOiBub3JtYWw7IHdpZG93czogYXV0bzsgd29yZC1z
cGFjaW5nOiAwcHg7IC13ZWJraXQtdGV4dC1zaXplLWFkanVzdDogYXV0bzsgLXdlYmtpdC10ZXh0
LXN0cm9rZS13aWR0aDogMHB4OyBiYWNrZ3JvdW5kLWNvbG9yOiByZ2IoMjU1LCAyNTUsIDI1NSk7
IiBjbGFzcz0iIj5odHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2Z1ZDwvYT48
YnIgc3R5bGU9ImZvbnQtZmFtaWx5OiBIZWx2ZXRpY2E7IGZvbnQtc2l6ZTogMTJweDsgZm9udC1z
dHlsZTogbm9ybWFsOyBmb250LXZhcmlhbnQtY2Fwczogbm9ybWFsOyBmb250LXdlaWdodDogbm9y
bWFsOyBsZXR0ZXItc3BhY2luZzogbm9ybWFsOyB0ZXh0LWFsaWduOiBzdGFydDsgdGV4dC1pbmRl
bnQ6IDBweDsgdGV4dC10cmFuc2Zvcm06IG5vbmU7IHdoaXRlLXNwYWNlOiBub3JtYWw7IHdvcmQt
c3BhY2luZzogMHB4OyAtd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRoOiAwcHg7IGJhY2tncm91bmQt
Y29sb3I6IHJnYigyNTUsIDI1NSwgMjU1KTsiIGNsYXNzPSIiPg0KPC9kaXY+DQo8L2Jsb2NrcXVv
dGU+DQo8L2Rpdj4NCjxiciBjbGFzcz0iIj4NCklNUE9SVEFOVCBOT1RJQ0U6IFRoZSBjb250ZW50
cyBvZiB0aGlzIGVtYWlsIGFuZCBhbnkgYXR0YWNobWVudHMgYXJlIGNvbmZpZGVudGlhbCBhbmQg
bWF5IGFsc28gYmUgcHJpdmlsZWdlZC4gSWYgeW91IGFyZSBub3QgdGhlIGludGVuZGVkIHJlY2lw
aWVudCwgcGxlYXNlIG5vdGlmeSB0aGUgc2VuZGVyIGltbWVkaWF0ZWx5IGFuZCBkbyBub3QgZGlz
Y2xvc2UgdGhlIGNvbnRlbnRzIHRvIGFueSBvdGhlciBwZXJzb24sIHVzZSBpdCBmb3IgYW55IHB1
cnBvc2UsDQogb3Igc3RvcmUgb3IgY29weSB0aGUgaW5mb3JtYXRpb24gaW4gYW55IG1lZGl1bS4g
VGhhbmsgeW91Lg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_2BF4654C42604C7C8DD5CF892628711Barmcom_--


From nobody Tue Sep 26 16:05:39 2017
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C9254134499 for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 16:05:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id olNb72Nqv9-i for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 16:05:37 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 35FA813202D for <fud@ietf.org>; Tue, 26 Sep 2017 16:05:36 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 21BA02009E for <fud@ietf.org>; Tue, 26 Sep 2017 19:10:34 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 170878189F for <fud@ietf.org>; Tue, 26 Sep 2017 19:05:35 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: fud@ietf.org
In-Reply-To: <88205e11-2b12-d88a-5613-4a52e865afc5@gmx.net>
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net> <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org> <88205e11-2b12-d88a-5613-4a52e865afc5@gmx.net>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature"
Date: Tue, 26 Sep 2017 19:05:35 -0400
Message-ID: <19725.1506467135@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/AgvF1pgbPy-wxUJmp0u00a3Iz0s>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2017 23:05:39 -0000

--=-=-=
Content-Type: text/plain


> FWIW: SUIT (Software Updates for Internet of Things) is totally fine for
> me. Finding the right name for a group or a protocol is always tricky.

It's really an awesome name.
My koodos to whomever came up with it.


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAlnK3T4ACgkQgItw+93Q
3WVBxQgAoaYFNL6iAuDHeh+6J46ATaa45zuJFTMhCI9GRqdlFQtqQrKTiBBtE7rs
Bxx1nWMgPTyj2AhHctdXOQii5vBNArgl69sjbXlvnWGYYpWvFunv29+4LeFq1qKI
9txjOJTLyMikkdMXeDr6hNqTQppMHMGKFXDCg8lw+iA2FklNlHM81XwhpyWPFdxM
RblAVj3KQZTu1lhbnJsVwK9JjiD8W6SbC+LiwLB8lIXKm04vkw9qBMOlLj3/tzRO
Xqt405xJzupcfpEFrbRuA00nWUo5Q6HpNjJxvbakUVssBtssvkAiCFckFX+iZJpE
WbeIUFv8xygSgBLjC5IxSkvoEQGJdA==
=Dw7l
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Sep 26 17:01:48 2017
Return-Path: <ned.smith@intel.com>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4ECB913306F for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 17:01:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UFO1ZNo82vbh for <fud@ietfa.amsl.com>; Tue, 26 Sep 2017 17:01:44 -0700 (PDT)
Received: from mga14.intel.com (mga14.intel.com [192.55.52.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B4F64133032 for <Fud@ietf.org>; Tue, 26 Sep 2017 17:01:44 -0700 (PDT)
Received: from fmsmga004.fm.intel.com ([10.253.24.48]) by fmsmga103.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 26 Sep 2017 17:01:44 -0700
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="5.42,442,1500966000";  d="scan'208,217";a="316584716"
Received: from orsmsx105.amr.corp.intel.com ([10.22.225.132]) by fmsmga004.fm.intel.com with ESMTP; 26 Sep 2017 17:01:44 -0700
Received: from orsmsx109.amr.corp.intel.com ([169.254.11.116]) by ORSMSX105.amr.corp.intel.com ([169.254.2.45]) with mapi id 14.03.0319.002; Tue, 26 Sep 2017 17:01:43 -0700
From: "Smith, Ned" <ned.smith@intel.com>
To: Brendan Moran <Brendan.Moran@arm.com>
CC: "Fud@ietf.org" <Fud@ietf.org>
Thread-Topic: [Fud] A few questions / observations
Thread-Index: AQHTLjdsLe1oeSwl+Em8FCdFITDsKqLHtvcAgAA0MwA=
Date: Wed, 27 Sep 2017 00:01:43 +0000
Message-ID: <88B5ACDC-AEB9-4611-B3D5-8A3C720E2795@intel.com>
References: <D531874E-95BF-4A12-8049-15794BCD1039@intel.com> <2BF4654C-4260-4C7C-8DD5-CF892628711B@arm.com>
In-Reply-To: <2BF4654C-4260-4C7C-8DD5-CF892628711B@arm.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/f.21.0.170409
x-originating-ip: [10.241.231.84]
Content-Type: multipart/alternative; boundary="_000_88B5ACDCAEB94611B3D58A3C720E2795intelcom_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/YqvKKI-Eb2KrpBWJ1CI0mTTkiWk>
Subject: Re: [Fud] A few questions / observations
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Sep 2017 00:01:47 -0000

--_000_88B5ACDCAEB94611B3D58A3C720E2795intelcom_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

U2VlIGFkZGl0aW9uYWwgY29tbWVudHMgaW5saW5lIGJlbG93Lg0KLU5lZA0KDQpGcm9tOiBCcmVu
ZGFuIE1vcmFuIDxCcmVuZGFuLk1vcmFuQGFybS5jb20+DQpEYXRlOiBUdWVzZGF5LCBTZXB0ZW1i
ZXIgMjYsIDIwMTcgYXQgMTo1NCBQTQ0KVG86ICJTbWl0aCwgTmVkIiA8bmVkLnNtaXRoQGludGVs
LmNvbT4NCkNjOiAiRnVkQGlldGYub3JnIiA8RnVkQGlldGYub3JnPg0KU3ViamVjdDogUmU6IFtG
dWRdIEEgZmV3IHF1ZXN0aW9ucyAvIG9ic2VydmF0aW9ucw0KDQpIaSBOZWQsDQpJ4oCZdmUgcGxh
Y2VkIG15IGNvbW1lbnRzIGlubGluZS4NCg0KVGhhbmtzIGZvciB5b3VyIGZlZWRiYWNrIQ0KDQpC
ZXN0IFJlZ2FyZHMsDQpCcmVuZGFuDQoNCg0KT24gMTUgU2VwIDIwMTcsIGF0IDE2OjI5LCBTbWl0
aCwgTmVkIDxuZWQuc21pdGhAaW50ZWwuY29tPG1haWx0bzpuZWQuc21pdGhAaW50ZWwuY29tPj4g
d3JvdGU6DQpbc3R1ZmYgZGVsZXRlZF0NCuKAoiAgICAgICAgIFdoeSB3YXMgQVNOLjEgc2VsZWN0
ZWQgYXMgdGhlIGVuY29kaW5nIGZvcm1hdD8gKFdoeSBub3QgQ09TRT8pDQoNCkFTTi4xIHdhcyB1
c2VkIGZvciBhIGZldyByZWFzb25zLg0KDQogIDEuICBJdCBpcyB0aGUgZGVmYXVsdCBmb3JtYXQg
Zm9yIGNlcnRpZmljYXRlcy4gTW9zdCB0b29scyB1c2UgREVSIHJhdGhlciB0aGFuIENPU0UgZm9y
IHBhY2tpbmcgY2VydGlmaWNhdGVzLCBzbyB0aGlzIHJlZHVjZXMgdGhlIG51bWJlciBvZiBwYXJz
ZXJzIGluIHRoZSB0YXJnZXQuIFdoZXJlIGludGVyd29yayB3aXRoIEhTTXMgaXMgaW52b2x2ZWQs
IHVzaW5nIGEgZm9ybWF0IHRoZSBIU00gc3VwcG9ydHMgaXMgYmVuZWZpY2lhbC4NCltubXNdIEhT
TXMgYXJlIGEgY29tcHV0aW5nIGVudmlyb25tZW50IHRoYXQgaXMgY29uc3RyYWluZWQgdG8gb3Bl
cmF0aW9ucyBpbnZvbHZpbmcgbW9zdGx5IGNyeXB0b2dyYXBoaWMgYW5kIGtleSBleGNoYW5nZSBv
cGVyYXRpb25zLiBZb3VyIG9ic2VydmF0aW9uIGlzIHRoYXQgQVNOLjEgaXMgdGhlIGRhdGEgbW9k
ZWwgbGFuZ3VhZ2Ugb2YgY2hvaWNlIGJ5IHRoZSBIU00gY29tbXVuaXR5LiBJIGFncmVlIHRoYXQg
aXMgdGhlIGNvcnJlY3QgY2hvaWNlIGZvciB0aGF0IGNvbnN0cmFpbmVkIGVudmlyb25tZW50LiBI
b3dldmVyLCBpdCBpcyBhbHNvIHRoZSBjYXNlIHRoYXQgdGhlcmUgYXJlIG90aGVyIGVudmlyb25t
ZW50cyB0aGF0IGhhdmUgY2hvc2VuIGRpZmZlcmVudCBkYXRhIG1vZGVsIGxhbmd1YWdlcyBhbmQg
b3BlcmF0ZSBpbiBhIGNvbnN0cmFpbmVkIGVudmlyb25tZW50LiBDT1NFLCBKU09OIGFuZCBYTUwg
YXJlIGNvbW1vbmx5IGF2YWlsYWJsZSBwYXJzZXJzIGluIHRoZXNlIG90aGVyIGVudmlyb25tZW50
cy4gVGhlIGxvZ2ljIHRoYXQgYXJndWVzIGZvciBwcm9wYWdhdGlvbiBvZiBBU04uMSBiZWNhdXNl
IHRoZSBIU00g4oCcY29uc3RyYWluZWQgZW52aXJvbm1lbnQgYWxyZWFkeSBzdXBwb3J0cyBpdCBh
bmQgdGhlcmVmb3JlIGF2b2lkcyDigJhibG9hdOKAmSBvZiBhbiBhZGRpdGlvbmFsIHBhcnNlcuKA
nSBjYW4gYmUgdXNlZCB0byBhcmd1ZSB0aGUgb3RoZXIgc2lkZSBhcyB3ZWxsLiBTaW5jZSB0aGUg
Y29uc3RyYWluZWQgZGV2aWNlIGFscmVhZHkgc3VwcG9ydHMgYW4gYWx0ZXJuYXRpdmUgKGUuZy4g
Q09TRSwgSlNPTiwgWE1M4oCmKSBhbmQgdGhlIGRlcGVuZGVuY2Ugb24gQVNOLjEgcmVwcmVzZW50
cyBhZGRpdGlvbmFsIG92ZXJoZWFkIHRvIHRoZSBjb25zdHJhaW5lZCBlbnZpcm9ubWVudC4gSW4g
Y2FzZXMgd2hlcmUgYm90aCBhbiBhcHBsaWNhdGlvbiBwcm9jZXNzb3IgYW5kIEhTTSBlbnZpcm9u
bWVudHMgZXhpc3QgaXQgbWFrZXMgc2Vuc2UgdG8gdXNlIG9uZSBvciB0aGUgb3RoZXIgb3IgYm90
aCwgYnV0IG5vdCBpbnRyb2R1Y2UgYSB0aGlyZC4gSeKAmW0gbm90IHRha2luZyBhIHN0cm9uZyBw
b3NpdGlvbiBvbiBBU04uMSB2cy4gQ09TRSAob3Igc29tZSBvdGhlciBhbHRlcm5hdGl2ZSkgZXhj
ZXB0IHRvIG9ic2VydmUgdGhhdCBpdCBzaG91bGRu4oCZdCBiZSB0aGUgb2JqZWN0aXZlIG9mIEZV
RCB0byBhZHZvY2F0ZSBhIHBhcnRpY3VsYXIgZGF0YSBtb2RlbCBsYW5ndWFnZSBvdmVyIGFub3Ro
ZXIsIGJ1dCByYXRoZXIgc2hvdWxkIHRyeSB0byBhY2NvbW1vZGF0ZSB0aGUgZGF0YSBtb2RlbCBs
YW5ndWFnZSBjaG9pY2VzIG9mIHRoZSBjb25zdHJhaW5lZCBlbnZpcm9ubWVudHMgZm9yIHdoaWNo
IHRoaXMgUkZDIGhvcGVzIHRvIGJlIHJlbGV2YW50LiBJdCBzaG91bGQgYmUgbm90ZWQgdGhhdCBt
b3N0IGRhdGEgbW9kZWwgbGFuZ3VhZ2VzIHRoYXQgZW1icmFjZSBzZWN1cml0eSB0eXBpY2FsbHkg
bWFrZSBhY2NvbW1vZGF0aW9uIGZvciBhIHNlY3VyaXR5IERNTCBieSBlbmNhcHN1bGF0aW5nIFBL
Q1MgYW5kIFguNTA5IC0gaW1wbHlpbmcgQVNOLjEvQkVSL0RFUiBzdXBwb3J0IGV4aXN0cyBzb21l
d2hlcmUgaW4gdGhlIHBsYXRmb3JtLiBIb3dldmVyLCBzdXBwb3J0IGZvciBQS0NTL1guNTA5IHNo
b3VsZCB0cmFuc2xhdGUgdG8gZ2VuZXJhbCBhbmQgYnJvYWQgc3VwcG9ydCBmb3IgYW55dGhpbmcg
QVNOLjEgYXMgdGhlIHJhbmdlIG9mIG9iamVjdHMga25vd24gdG8gUEtDUyBhbmQgWC41MDkgaXMg
dHlwaWNhbGx5IHJhdGhlciBzbWFsbC4NCk15IG9waW5pb24gaXMgdGhlIGVudmlyb25tZW50IHRo
YXQgZ2VuZXJhdGVzLCBkaXN0cmlidXRlcyBhbmQgaW5zdGFsbHMgc29mdHdhcmUgdXBkYXRlcyBp
c27igJl0IGVudGlyZWx5IEhTTSBvciBhcHBsaWNhdGlvbiBmcmFtZXdvcmsgKGUuZy4gTFdNMk0p
LiBUaGVyZWZvcmUsIGl0IGlzIHJlYXNvbmFibGUgdG8gZXhwZWN0IG11bHRpcGxlIGVuY29kaW5n
cyBtYXkgYmUgcmVxdWlyZWQuDQoNCiAgMS4gIFBDS1M3IC8gQ01TIC8gUkZDNTY1MiBhcmUgd2lk
ZWx5IHN1cHBvcnRlZC4gRm9yIGV4YW1wbGUsIE9wZW5TU0zigJlzIHNtaW1lIGNvbW1hbmQgaGFu
ZGxlcyBDTVMgc2lnbmluZy92YWxpZGF0aW9uIGRpcmVjdGx5LiBUaGlzIG1ha2VzIHRoZSBjdXN0
b20gdG9vbGluZyByZXF1aXJlZCBzaW1wbGVyLiBUaGlzIHdpbGwgYWxzbywgaG9wZWZ1bGx5LCBp
bXByb3ZlIGNvbXBhdGliaWxpdHkgd2l0aCBleGlzdGluZyBIU01zDQpbbm1zXSBJdCBpcyBhbHNv
IHRoZSBjYXNlIHRoYXQgY29uc3RyYWluZWQgZW52aXJvbm1lbnRzIG1heSBub3QgaGF2ZSBjaG9z
ZW4gT3BlblNTTCwgYnV0IGluc3RlYWQgcmVseSBvbiBlbWJlZFRMUywgdGlueURUTFMgb3Igb3Ro
ZXIgbGlicmFyeSB0aGF0IGRvZXNu4oCZdCBoYXZlIHRoZSBzYW1lIGRlcGVuZGVuY3kgb24gU01J
TUUuIENvbXBhdGliaWxpdHkgd2l0aCBIU01zIGlzIGltcG9ydGFudCwgYnV0IHRoZSBxdWVzdGlv
biBmb3IgRlVEIHBvdGVudGlhbGx5IGlzIHRvIHVuZGVyc3RhbmQgaG93IG11Y2ggb2YgdGhlIFJG
Q+KAmXMgc29sdXRpb24gc2hvdWxkIGJlIGNvbXB1dGVkIHdpdGhpbiB0aGUgSFNNIHZzLiB0aGUg
aG9zdCBwcm9jZXNzaW5nIGVudmlyb25tZW50IG9yIGFuIGF2YWlsYWJsZSBURUUuDQoNCiAgMS4g
IERpcmVjdCBjb2RlIGdlbmVyYXRpb24uIEluIGEgc2NlbmFyaW8gd2hlcmUgdGhlIHBhcnNlciBk
b2VzIG5vdCBjcmVhdGUgYSBkb2N1bWVudCBvYmplY3QgbW9kZWwsIGJ1dCBleHRyYWN0cyBvciB2
YWxpZGF0ZXMgc3BlY2lmaWMgZmllbGRzLCBBU04uMSBwcm92aWRlcyBhIGdyYW1tYXIgdGhhdCBt
YWtlcyBpdCBwb3NzaWJsZSB0byBnZW5lcmF0ZSBhIHBhcnNlciBwcm9ncmFtbWF0aWNhbGx5Lg0K
W25tc10gSXQgaXMgdHJ1ZSB0aGF0IHRoZSBBU04uMSB0b29scyBlY29zeXN0ZW0gaXMgbWF0dXJl
LiBBU04uMSBoYXMgYmVlbiBhcm91bmQgZm9yIGEgd2hpbGUuIFRoYXQgaG93ZXZlciBoYXMgbm90
IHByZXZlbnRlZCB0aGUgaW52ZW50aW9uIGFuZCBwcm9saWZlcmF0aW9uIG9mIGFsdGVybmF0aXZl
IGRhdGEgbW9kZWwgbGFuZ3VhZ2VzLiBJZiB0aGUgYXJndW1lbnQgaXMgdGhhdCBBU04uMSB3aWxs
IGV2ZW50dWFsbHkgd2luLCB3ZSBqdXN0IG5lZWQgdG8gd2FpdCBsb25nZXIsIHRoZW4gSSByZXNw
ZWN0ZnVsbHkgZGlzYWdyZWUuIFRoZSBlY29zeXN0ZW1zIHN1cHBvcnRpbmcgYWx0ZXJuYXRpdmUg
RE1McyBtYXkgYmUgbGVzcyBtYXR1cmUsIGJ1dCB0aGV5IGFyZSBldm9sdmluZyBxdWlja2x5Lg0K
DQogIDEuICBUaGUgbWVhbmluZyBvZiDigJxsZW5ndGjigJ0gZm9yIGNvbXBvc2l0ZSB0eXBlcy4g
SW4gREVSLCB0aGUgbGVuZ3RoIG9mIGEgZmllbGQgaXMgdW5hbWJpZ3VvdXMuIEl0IGlzIGFsd2F5
cyB0aGUgbGVuZ3RoLCBpbiBieXRlcywgb2YgdGhlIGNvbnRhaW5lZCBvYmplY3QuIFRoaXMgYWxs
b3dzIGEgcGFyc2VyIHRoYXQgdW5kZXJzdGFuZHMgdGhlIGRvY3VtZW50IGJlaW5nIHBhcnNlZCB0
byBza2lwIGxhcmdlIGNodW5rcyBvZiBhIGRlZXBseSBuZXN0ZWQgdHJlZS4gSW4gQ0JPUiwgdGhl
IOKAnGxlbmd0aOKAnSBvZiBhbiBhcnJheSBvciBtYXAgaXMgdGhlIG51bWJlciBvZiBlbGVtZW50
cyBpdCBjb250YWlucy4gVGhpcyBtYWtlcyBpdCBpbXBvc3NpYmxlIGZvciB0aGUgcGFyc2VyIHRv
IOKAnHNraXDigJ0gYW55dGhpbmcuIEl0IGhhcyB0byBwYXJzZSB0aGUgZW50aXJlIHN0cnVjdHVy
ZS4gSXQgaXMgcG9zc2libGUgdG8gY2lyY3VtdmVudCBzb21lIG9mIHRoZXNlIGxpbWl0YXRpb25z
IHVzaW5nIHRhZ2dpbmcsIGluIHBhcnRpY3VsYXIgdGFnIDI0IChlbmNvZGVkIENCT1IgZGF0YSBp
dGVtKSwgYnV0IHRoaXMgaGFzIHRoZSBkb3duc2lkZSBvZiBicmVha2luZyB0cmFuc2xhdGFiaWxp
dHkgdG8gSlNPTiwgd2hpY2ggaXMgYSBrZXkgYWR2YW50YWdlIG9mIENCT1IuIENvbnNpc3RlbnQg
VExWIHJlcHJlc2VudGF0aW9uIG1ha2VzIHBhcnNpbmcgaW4gYSBjb25zdHJhaW5lZCBlbnZpcm9u
bWVudCBvZmZlcnMgYSBub3Rpb25hbCBwZXJmb3JtYW5jZSBpbXByb3ZlbWVudCwgYnV0IHRoaXMg
aXMgbWlub3IgYW5kIG1heSBub3QgcGxheSBvdXQgaW4gcHJhY3RpY2UuDQpbbm1zXSBUaGUgcXVl
c3Rpb24gdG8gYXNrIGlzIHdoZXRoZXIgdGhpcyBzb3J0IG9mIHBhcnNpbmcgaW5lZmZpY2llbmN5
IGlzIGEgbGFyZ2VyIHBhaW4gcG9pbnQgdGhhbiBoYXZpbmcgdG8gZG8gc2VtYW50aWMgbWFwcGlu
ZyBvZiBzdHJ1Y3R1cmVzIHRoYXQgYWxyZWFkeSBhcmUgbWVhbmluZ2Z1bCBpbiB0aGUgY29udGV4
dCBvZiB0aGUgYXBwbGljYXRpb24gZW52aXJvbm1lbnQgdGhhdCBpcyBwZXJmb3JtaW5nIHRoZSB1
cGRhdGUuIEluIHN1Y2ggYSBjYXNlLCBBU04uMSBtYXkgYmUgdGhlIGdyZWF0ZXIgcGFpbiBwb2lu
dC4NCg0KTmV2ZXIgdGhlIGxlc3MsIEkgdGhpbmsgdGhhdCBDQk9SL0NPU0Ugd291bGQgYmUgcGVy
ZmVjdGx5IHNlcnZpY2VhYmxlIGZvciB0aGlzIHVzZS4gSeKAmW0gbm90IGV2ZW4gY2VydGFpbiB0
aGF0IEFTTi4xIGNhbuKAmXQgYmUgdXNlZCBhcyBhIHNjaGVtYSBmb3IgQ0JPUiAoc2VlIDMgYWJv
dmUpLiBUaGF0IGJlaW5nIHRoZSBjYXNlLCBJIGNhbiBzZWUgYSBjYXNlIGZvciBERVIgbWFuaWZl
c3RzIHdpdGggQ01TLCBhbmQgQ0JPUiBtYW5pZmVzdHMgd2l0aCBDT1NFLg0KDQogICAgICAgICAg
ICBbbm1zXSBHaXZlbiBDT1NFIGVuY29kZXMgWC41MDkgYW5kIFBLQ1Mgc3RydWN0dXJlcyBpdCB3
b3VsZCBzZWVtIHRoZSBkZXNpZ25lcnMgYW50aWNpcGF0ZWQgaW50ZXJvcGVyYXRpb24gd2l0aCBI
U01zLCBhdCBsZWFzdCBhdCB0aGUga2V5IGFuZCBjZXJ0aWZpY2F0ZSBsZXZlbHMgb2YgYWJzdHJh
Y3Rpb24uIEJ1dCBnaXZlbiBDT1NFIGRlZmluZXMgYSBjcnlwdG9ncmFwaGljIG1lc3NhZ2Ugc3lu
dGF4IG9mIGl0cyBvd24sIGl0IGFudGljaXBhdGVzIHJlbGV2YW5jZSBpbiBtZXNzYWdpbmcgcHJv
Y2Vzc29yIGVudmlyb25tZW50cy4gTXkgdW5kZXJzdGFuZGluZyBvZiBIU01zIGFyZSB0aGF0IHRo
ZXkgZG9u4oCZdCBhbnRpY2lwYXRlIGJlaW5nIHVzZWQgYXMgbWVzc2FnZSBwcm9jZXNzb3JzLiBN
eSBxdWVzdGlvbiBtYXkgYmUgYSBiaXQgbW9yZSBwaGlsb3NvcGhpY2FsLiBEbyB0aGUgYXV0aG9y
cyBvZiB0aGUgUkZDIHJlZ2FyZCB0aGUgZXhjaGFuZ2Ugb2YgU1cgdXBkYXRlcyBhbmQgdGhlaXIg
bWFuaWZlc3RzIGFzIGJlaW5nIGZ1bmRhbWVudGFsbHkgYW4gSFNNIHdvcmtsb2FkIG9yIHNvbWV0
aGluZyBlbHNlOyBzdWNoIGFzIGRldmljZSBtYW5hZ2VtZW50IG9yIHBvc3NpYmx5IGEgZGlzdHJp
YnV0ZWQgY29tcHV0ZT8NCg0KVGh4LA0KTmVkDQoNCg0KX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX18NCkZ1ZCBtYWlsaW5nIGxpc3QNCkZ1ZEBpZXRmLm9yZzxt
YWlsdG86RnVkQGlldGYub3JnPg0KaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5m
by9mdWQNCg0KSU1QT1JUQU5UIE5PVElDRTogVGhlIGNvbnRlbnRzIG9mIHRoaXMgZW1haWwgYW5k
IGFueSBhdHRhY2htZW50cyBhcmUgY29uZmlkZW50aWFsIGFuZCBtYXkgYWxzbyBiZSBwcml2aWxl
Z2VkLiBJZiB5b3UgYXJlIG5vdCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50LCBwbGVhc2Ugbm90aWZ5
IHRoZSBzZW5kZXIgaW1tZWRpYXRlbHkgYW5kIGRvIG5vdCBkaXNjbG9zZSB0aGUgY29udGVudHMg
dG8gYW55IG90aGVyIHBlcnNvbiwgdXNlIGl0IGZvciBhbnkgcHVycG9zZSwgb3Igc3RvcmUgb3Ig
Y29weSB0aGUgaW5mb3JtYXRpb24gaW4gYW55IG1lZGl1bS4gVGhhbmsgeW91Lg0K

--_000_88B5ACDCAEB94611B3D58A3C720E2795intelcom_
Content-Type: text/html; charset="utf-8"
Content-ID: <2907C79BC517BB4E95F67D3F27219DAF@intel.com>
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6bz0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6b2ZmaWNlIiB4
bWxuczp3PSJ1cm46c2NoZW1hcy1taWNyb3NvZnQtY29tOm9mZmljZTp3b3JkIiB4bWxuczptPSJo
dHRwOi8vc2NoZW1hcy5taWNyb3NvZnQuY29tL29mZmljZS8yMDA0LzEyL29tbWwiIHhtbG5zPSJo
dHRwOi8vd3d3LnczLm9yZy9UUi9SRUMtaHRtbDQwIj4NCjxoZWFkPg0KPG1ldGEgaHR0cC1lcXVp
dj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWw7IGNoYXJzZXQ9dXRmLTgiPg0KPG1l
dGEgbmFtZT0iVGl0bGUiIGNvbnRlbnQ9IiI+DQo8bWV0YSBuYW1lPSJLZXl3b3JkcyIgY29udGVu
dD0iIj4NCjxtZXRhIG5hbWU9IkdlbmVyYXRvciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUg
KGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxlPjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8N
CkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0
IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OkRlbmdYaWFuOw0K
CXBhbm9zZS0xOjIgMSA2IDAgMyAxIDEgMSAxIDE7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWls
eTpDYWxpYnJpOw0KCXBhbm9zZS0xOjIgMTUgNSAyIDIgMiA0IDMgMiA0O30NCi8qIFN0eWxlIERl
ZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwgbGkuTXNvTm9ybWFsLCBkaXYuTXNvTm9ybWFsDQoJ
e21hcmdpbjowaW47DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7
DQoJZm9udC1mYW1pbHk6IlRpbWVzIE5ldyBSb21hbiI7fQ0KYTpsaW5rLCBzcGFuLk1zb0h5cGVy
bGluaw0KCXttc28tc3R5bGUtcHJpb3JpdHk6OTk7DQoJY29sb3I6Ymx1ZTsNCgl0ZXh0LWRlY29y
YXRpb246dW5kZXJsaW5lO30NCmE6dmlzaXRlZCwgc3Bhbi5Nc29IeXBlcmxpbmtGb2xsb3dlZA0K
CXttc28tc3R5bGUtcHJpb3JpdHk6OTk7DQoJY29sb3I6cHVycGxlOw0KCXRleHQtZGVjb3JhdGlv
bjp1bmRlcmxpbmU7fQ0Kc3Bhbi5hcHBsZS1jb252ZXJ0ZWQtc3BhY2UNCgl7bXNvLXN0eWxlLW5h
bWU6YXBwbGUtY29udmVydGVkLXNwYWNlO30NCnNwYW4uRW1haWxTdHlsZTE4DQoJe21zby1zdHls
ZS10eXBlOnBlcnNvbmFsLXJlcGx5Ow0KCWZvbnQtZmFtaWx5OkNhbGlicmk7DQoJY29sb3I6d2lu
ZG93dGV4dDt9DQpzcGFuLm1zb0lucw0KCXttc28tc3R5bGUtdHlwZTpleHBvcnQtb25seTsNCglt
c28tc3R5bGUtbmFtZToiIjsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lOw0KCWNvbG9yOnRl
YWw7fQ0KLk1zb0NocERlZmF1bHQNCgl7bXNvLXN0eWxlLXR5cGU6ZXhwb3J0LW9ubHk7DQoJZm9u
dC1zaXplOjEwLjBwdDt9DQpAcGFnZSBXb3JkU2VjdGlvbjENCgl7c2l6ZTo4LjVpbiAxMS4waW47
DQoJbWFyZ2luOjEuMGluIDEuMGluIDEuMGluIDEuMGluO30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7
cGFnZTpXb3JkU2VjdGlvbjE7fQ0KLyogTGlzdCBEZWZpbml0aW9ucyAqLw0KQGxpc3QgbDANCgl7
bXNvLWxpc3QtaWQ6Njg0MzMwMTcwOw0KCW1zby1saXN0LXRlbXBsYXRlLWlkczotNTQ4MTI1NzY0
O30NCm9sDQoJe21hcmdpbi1ib3R0b206MGluO30NCnVsDQoJe21hcmdpbi1ib3R0b206MGluO30N
Ci0tPjwvc3R5bGU+DQo8L2hlYWQ+DQo8Ym9keSBiZ2NvbG9yPSJ3aGl0ZSIgbGFuZz0iRU4tVVMi
IGxpbms9ImJsdWUiIHZsaW5rPSJwdXJwbGUiPg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQt
ZmFtaWx5OkNhbGlicmkiPlNlZSBhZGRpdGlvbmFsIGNvbW1lbnRzIGlubGluZSBiZWxvdy48bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9u
dC1zaXplOjExLjBwdDtmb250LWZhbWlseTpDYWxpYnJpIj4tTmVkPG86cD48L286cD48L3NwYW4+
PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7
Zm9udC1mYW1pbHk6Q2FsaWJyaSI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPGRpdiBz
dHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLXRvcDpzb2xpZCAjQjVDNERGIDEuMHB0O3BhZGRpbmc6
My4wcHQgMGluIDBpbiAwaW4iPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PGI+PHNwYW4gc3R5bGU9
ImZvbnQtZmFtaWx5OkNhbGlicmk7Y29sb3I6YmxhY2siPkZyb206IDwvc3Bhbj4NCjwvYj48c3Bh
biBzdHlsZT0iZm9udC1mYW1pbHk6Q2FsaWJyaTtjb2xvcjpibGFjayI+QnJlbmRhbiBNb3JhbiAm
bHQ7QnJlbmRhbi5Nb3JhbkBhcm0uY29tJmd0Ozxicj4NCjxiPkRhdGU6IDwvYj5UdWVzZGF5LCBT
ZXB0ZW1iZXIgMjYsIDIwMTcgYXQgMTo1NCBQTTxicj4NCjxiPlRvOiA8L2I+JnF1b3Q7U21pdGgs
IE5lZCZxdW90OyAmbHQ7bmVkLnNtaXRoQGludGVsLmNvbSZndDs8YnI+DQo8Yj5DYzogPC9iPiZx
dW90O0Z1ZEBpZXRmLm9yZyZxdW90OyAmbHQ7RnVkQGlldGYub3JnJmd0Ozxicj4NCjxiPlN1Ympl
Y3Q6IDwvYj5SZTogW0Z1ZF0gQSBmZXcgcXVlc3Rpb25zIC8gb2JzZXJ2YXRpb25zPG86cD48L286
cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4m
bmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5IaSBO
ZWQsPG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5J
4oCZdmUgcGxhY2VkIG15IGNvbW1lbnRzIGlubGluZS48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0K
PGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+
DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+VGhhbmtzIGZvciB5b3VyIGZlZWRiYWNrITxv
OnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4m
bmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5CZXN0
IFJlZ2FyZHMsPG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIj5CcmVuZGFuPG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8ZGl2Pg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdp
bi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCI+T24gMTUgU2VwIDIwMTcsIGF0IDE2OjI5LCBTbWl0aCwgTmVkICZsdDs8YSBocmVmPSJt
YWlsdG86bmVkLnNtaXRoQGludGVsLmNvbSI+bmVkLnNtaXRoQGludGVsLmNvbTwvYT4mZ3Q7IHdy
b3RlOjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Jsb2NrcXVvdGU+DQo8L2Rpdj4NCjxkaXY+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5bc3R1ZmYgZGVsZXRlZF08bzpwPjwvbzpwPjwvcD4NCjxi
bG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0K
PGRpdj4NCjxkaXYgc3R5bGU9Im1hcmdpbi1sZWZ0Oi41aW4iPg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCIgc3R5bGU9InRleHQtaW5kZW50Oi0uMjVpbjtiYWNrZ3JvdW5kOndoaXRlIj48c3BhbiBzdHls
ZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTpTeW1ib2wiPsK3PC9zcGFuPjxzcGFuIHN0
eWxlPSJmb250LXNpemU6Ny4wcHQiPiZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNw
OyZuYnNwOyZuYnNwOzxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwv
c3Bhbj48L3NwYW4+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6Q2Fs
aWJyaSI+V2h5DQogd2FzIEFTTi4xIHNlbGVjdGVkIGFzIHRoZSBlbmNvZGluZyBmb3JtYXQ/IChX
aHkgbm90IENPU0U/KTwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6Q2FsaWJyaSI+PG86
cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvYmxvY2txdW90ZT4NCjxkaXY+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPkFTTi4xIHdhcyB1c2VkIGZvciBhIGZldyByZWFzb25z
LjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPG9sIHN0YXJ0PSIxIiB0eXBlPSIxIj4N
CjxsaSBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNv
LW1hcmdpbi1ib3R0b20tYWx0OmF1dG87bXNvLWxpc3Q6bDAgbGV2ZWwxIGxmbzEiPg0KSXQgaXMg
dGhlIGRlZmF1bHQgZm9ybWF0IGZvciBjZXJ0aWZpY2F0ZXMuIE1vc3QgdG9vbHMgdXNlIERFUiBy
YXRoZXIgdGhhbiBDT1NFIGZvciBwYWNraW5nIGNlcnRpZmljYXRlcywgc28gdGhpcyByZWR1Y2Vz
IHRoZSBudW1iZXIgb2YgcGFyc2VycyBpbiB0aGUgdGFyZ2V0LiBXaGVyZSBpbnRlcndvcmsgd2l0
aCBIU01zIGlzIGludm9sdmVkLCB1c2luZyBhIGZvcm1hdCB0aGUgSFNNIHN1cHBvcnRzIGlzIGJl
bmVmaWNpYWwuPG86cD48L286cD48L2xpPjwvb2w+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHls
ZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG87bWFy
Z2luLWxlZnQ6LjVpbiI+DQpbbm1zXSBIU01zIGFyZSBhIGNvbXB1dGluZyBlbnZpcm9ubWVudCB0
aGF0IGlzIGNvbnN0cmFpbmVkIHRvIG9wZXJhdGlvbnMgaW52b2x2aW5nIG1vc3RseSBjcnlwdG9n
cmFwaGljIGFuZCBrZXkgZXhjaGFuZ2Ugb3BlcmF0aW9ucy4gWW91ciBvYnNlcnZhdGlvbiBpcyB0
aGF0IEFTTi4xIGlzIHRoZSBkYXRhIG1vZGVsIGxhbmd1YWdlIG9mIGNob2ljZSBieSB0aGUgSFNN
IGNvbW11bml0eS4gSSBhZ3JlZSB0aGF0IGlzIHRoZSBjb3JyZWN0IGNob2ljZQ0KIGZvciB0aGF0
IGNvbnN0cmFpbmVkIGVudmlyb25tZW50LiBIb3dldmVyLCBpdCBpcyBhbHNvIHRoZSBjYXNlIHRo
YXQgdGhlcmUgYXJlIG90aGVyIGVudmlyb25tZW50cyB0aGF0IGhhdmUgY2hvc2VuIGRpZmZlcmVu
dCBkYXRhIG1vZGVsIGxhbmd1YWdlcyBhbmQgb3BlcmF0ZSBpbiBhIGNvbnN0cmFpbmVkIGVudmly
b25tZW50LiBDT1NFLCBKU09OIGFuZCBYTUwgYXJlIGNvbW1vbmx5IGF2YWlsYWJsZSBwYXJzZXJz
IGluIHRoZXNlIG90aGVyIGVudmlyb25tZW50cy4NCiBUaGUgbG9naWMgdGhhdCBhcmd1ZXMgZm9y
IHByb3BhZ2F0aW9uIG9mIEFTTi4xIGJlY2F1c2UgdGhlIEhTTSDigJxjb25zdHJhaW5lZCBlbnZp
cm9ubWVudCBhbHJlYWR5IHN1cHBvcnRzIGl0IGFuZCB0aGVyZWZvcmUgYXZvaWRzIOKAmGJsb2F0
4oCZIG9mIGFuIGFkZGl0aW9uYWwgcGFyc2Vy4oCdIGNhbiBiZSB1c2VkIHRvIGFyZ3VlIHRoZSBv
dGhlciBzaWRlIGFzIHdlbGwuIFNpbmNlIHRoZSBjb25zdHJhaW5lZCBkZXZpY2UgYWxyZWFkeSBz
dXBwb3J0cyBhbg0KIGFsdGVybmF0aXZlIChlLmcuIENPU0UsIEpTT04sIFhNTOKApikgYW5kIHRo
ZSBkZXBlbmRlbmNlIG9uIEFTTi4xIHJlcHJlc2VudHMgYWRkaXRpb25hbCBvdmVyaGVhZCB0byB0
aGUgY29uc3RyYWluZWQgZW52aXJvbm1lbnQuIEluIGNhc2VzIHdoZXJlIGJvdGggYW4gYXBwbGlj
YXRpb24gcHJvY2Vzc29yIGFuZCBIU00gZW52aXJvbm1lbnRzIGV4aXN0IGl0IG1ha2VzIHNlbnNl
IHRvIHVzZSBvbmUgb3IgdGhlIG90aGVyIG9yIGJvdGgsIGJ1dCBub3QgaW50cm9kdWNlDQogYSB0
aGlyZC4gSeKAmW0gbm90IHRha2luZyBhIHN0cm9uZyBwb3NpdGlvbiBvbiBBU04uMSB2cy4gQ09T
RSAob3Igc29tZSBvdGhlciBhbHRlcm5hdGl2ZSkgZXhjZXB0IHRvIG9ic2VydmUgdGhhdCBpdCBz
aG91bGRu4oCZdCBiZSB0aGUgb2JqZWN0aXZlIG9mIEZVRCB0byBhZHZvY2F0ZSBhIHBhcnRpY3Vs
YXIgZGF0YSBtb2RlbCBsYW5ndWFnZSBvdmVyIGFub3RoZXIsIGJ1dCByYXRoZXIgc2hvdWxkIHRy
eSB0byBhY2NvbW1vZGF0ZSB0aGUgZGF0YSBtb2RlbA0KIGxhbmd1YWdlIGNob2ljZXMgb2YgdGhl
IGNvbnN0cmFpbmVkIGVudmlyb25tZW50cyBmb3Igd2hpY2ggdGhpcyBSRkMgaG9wZXMgdG8gYmUg
cmVsZXZhbnQuIEl0IHNob3VsZCBiZSBub3RlZCB0aGF0IG1vc3QgZGF0YSBtb2RlbCBsYW5ndWFn
ZXMgdGhhdCBlbWJyYWNlIHNlY3VyaXR5IHR5cGljYWxseSBtYWtlIGFjY29tbW9kYXRpb24gZm9y
IGEgc2VjdXJpdHkgRE1MIGJ5IGVuY2Fwc3VsYXRpbmcgUEtDUyBhbmQgWC41MDkgLSBpbXBseWlu
ZyBBU04uMS9CRVIvREVSDQogc3VwcG9ydCBleGlzdHMgc29tZXdoZXJlIGluIHRoZSBwbGF0Zm9y
bS4gSG93ZXZlciwgc3VwcG9ydCBmb3IgUEtDUy9YLjUwOSBzaG91bGQgdHJhbnNsYXRlIHRvIGdl
bmVyYWwgYW5kIGJyb2FkIHN1cHBvcnQgZm9yIGFueXRoaW5nIEFTTi4xIGFzIHRoZSByYW5nZSBv
ZiBvYmplY3RzIGtub3duIHRvIFBLQ1MgYW5kIFguNTA5IGlzIHR5cGljYWxseSByYXRoZXIgc21h
bGwuPG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdp
bi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG87bWFyZ2luLWxlZnQ6LjVp
biI+DQpNeSBvcGluaW9uIGlzIHRoZSBlbnZpcm9ubWVudCB0aGF0IGdlbmVyYXRlcywgZGlzdHJp
YnV0ZXMgYW5kIGluc3RhbGxzIHNvZnR3YXJlIHVwZGF0ZXMgaXNu4oCZdCBlbnRpcmVseSBIU00g
b3IgYXBwbGljYXRpb24gZnJhbWV3b3JrIChlLmcuIExXTTJNKS4gVGhlcmVmb3JlLCBpdCBpcyBy
ZWFzb25hYmxlIHRvIGV4cGVjdCBtdWx0aXBsZSBlbmNvZGluZ3MgbWF5IGJlIHJlcXVpcmVkLjxv
OnA+PC9vOnA+PC9wPg0KPG9sIHN0YXJ0PSIyIiB0eXBlPSIxIj4NCjxsaSBjbGFzcz0iTXNvTm9y
bWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0
OmF1dG87bXNvLWxpc3Q6bDAgbGV2ZWwxIGxmbzEiPg0KUENLUzcgLyBDTVMgLyBSRkM1NjUyIGFy
ZSB3aWRlbHkgc3VwcG9ydGVkLiBGb3IgZXhhbXBsZSwgT3BlblNTTOKAmXMgc21pbWUgY29tbWFu
ZCBoYW5kbGVzIENNUyBzaWduaW5nL3ZhbGlkYXRpb24gZGlyZWN0bHkuIFRoaXMgbWFrZXMgdGhl
IGN1c3RvbSB0b29saW5nIHJlcXVpcmVkIHNpbXBsZXIuIFRoaXMgd2lsbCBhbHNvLCBob3BlZnVs
bHksIGltcHJvdmUgY29tcGF0aWJpbGl0eSB3aXRoIGV4aXN0aW5nIEhTTXM8bzpwPjwvbzpwPjwv
bGk+PC9vbD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6
YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0bzttYXJnaW4tbGVmdDouNWluIj4NCltubXNd
IEl0IGlzIGFsc28gdGhlIGNhc2UgdGhhdCBjb25zdHJhaW5lZCBlbnZpcm9ubWVudHMgbWF5IG5v
dCBoYXZlIGNob3NlbiBPcGVuU1NMLCBidXQgaW5zdGVhZCByZWx5IG9uIGVtYmVkVExTLCB0aW55
RFRMUyBvciBvdGhlciBsaWJyYXJ5IHRoYXQgZG9lc27igJl0IGhhdmUgdGhlIHNhbWUgZGVwZW5k
ZW5jeSBvbiBTTUlNRS4gQ29tcGF0aWJpbGl0eSB3aXRoIEhTTXMgaXMgaW1wb3J0YW50LCBidXQg
dGhlIHF1ZXN0aW9uIGZvciBGVUQgcG90ZW50aWFsbHkNCiBpcyB0byB1bmRlcnN0YW5kIGhvdyBt
dWNoIG9mIHRoZSBSRkPigJlzIHNvbHV0aW9uIHNob3VsZCBiZSBjb21wdXRlZCB3aXRoaW4gdGhl
IEhTTSB2cy4gdGhlIGhvc3QgcHJvY2Vzc2luZyBlbnZpcm9ubWVudCBvciBhbiBhdmFpbGFibGUg
VEVFLjxvOnA+PC9vOnA+PC9wPg0KPG9sIHN0YXJ0PSIzIiB0eXBlPSIxIj4NCjxsaSBjbGFzcz0i
TXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0
b20tYWx0OmF1dG87bXNvLWxpc3Q6bDAgbGV2ZWwxIGxmbzEiPg0KRGlyZWN0IGNvZGUgZ2VuZXJh
dGlvbi4gSW4gYSBzY2VuYXJpbyB3aGVyZSB0aGUgcGFyc2VyIGRvZXMgbm90IGNyZWF0ZSBhIGRv
Y3VtZW50IG9iamVjdCBtb2RlbCwgYnV0IGV4dHJhY3RzIG9yIHZhbGlkYXRlcyBzcGVjaWZpYyBm
aWVsZHMsIEFTTi4xIHByb3ZpZGVzIGEgZ3JhbW1hciB0aGF0IG1ha2VzIGl0IHBvc3NpYmxlIHRv
IGdlbmVyYXRlIGEgcGFyc2VyIHByb2dyYW1tYXRpY2FsbHkuPG86cD48L286cD48L2xpPjwvb2w+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNv
LW1hcmdpbi1ib3R0b20tYWx0OmF1dG87bWFyZ2luLWxlZnQ6LjVpbiI+DQpbbm1zXSBJdCBpcyB0
cnVlIHRoYXQgdGhlIEFTTi4xIHRvb2xzIGVjb3N5c3RlbSBpcyBtYXR1cmUuIEFTTi4xIGhhcyBi
ZWVuIGFyb3VuZCBmb3IgYSB3aGlsZS4gVGhhdCBob3dldmVyIGhhcyBub3QgcHJldmVudGVkIHRo
ZSBpbnZlbnRpb24gYW5kIHByb2xpZmVyYXRpb24gb2YgYWx0ZXJuYXRpdmUgZGF0YSBtb2RlbCBs
YW5ndWFnZXMuIElmIHRoZSBhcmd1bWVudCBpcyB0aGF0IEFTTi4xIHdpbGwgZXZlbnR1YWxseSB3
aW4sIHdlIGp1c3QgbmVlZA0KIHRvIHdhaXQgbG9uZ2VyLCB0aGVuIEkgcmVzcGVjdGZ1bGx5IGRp
c2FncmVlLiBUaGUgZWNvc3lzdGVtcyBzdXBwb3J0aW5nIGFsdGVybmF0aXZlIERNTHMgbWF5IGJl
IGxlc3MgbWF0dXJlLCBidXQgdGhleSBhcmUgZXZvbHZpbmcgcXVpY2tseS4NCjxvOnA+PC9vOnA+
PC9wPg0KPG9sIHN0YXJ0PSI0IiB0eXBlPSIxIj4NCjxsaSBjbGFzcz0iTXNvTm9ybWFsIiBzdHls
ZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG87bXNv
LWxpc3Q6bDAgbGV2ZWwxIGxmbzEiPg0KVGhlIG1lYW5pbmcgb2Yg4oCcbGVuZ3Ro4oCdIGZvciBj
b21wb3NpdGUgdHlwZXMuIEluIERFUiwgdGhlIGxlbmd0aCBvZiBhIGZpZWxkIGlzIHVuYW1iaWd1
b3VzLiBJdCBpcyBhbHdheXMgdGhlIGxlbmd0aCwgaW4gYnl0ZXMsIG9mIHRoZSBjb250YWluZWQg
b2JqZWN0LiBUaGlzIGFsbG93cyBhIHBhcnNlciB0aGF0IHVuZGVyc3RhbmRzIHRoZSBkb2N1bWVu
dCBiZWluZyBwYXJzZWQgdG8gc2tpcCBsYXJnZSBjaHVua3Mgb2YgYSBkZWVwbHkgbmVzdGVkIHRy
ZWUuDQogSW4gQ0JPUiwgdGhlIOKAnGxlbmd0aOKAnSBvZiBhbiBhcnJheSBvciBtYXAgaXMgdGhl
IG51bWJlciBvZiBlbGVtZW50cyBpdCBjb250YWlucy4gVGhpcyBtYWtlcyBpdCBpbXBvc3NpYmxl
IGZvciB0aGUgcGFyc2VyIHRvIOKAnHNraXDigJ0gYW55dGhpbmcuIEl0IGhhcyB0byBwYXJzZSB0
aGUgZW50aXJlIHN0cnVjdHVyZS4gSXQgaXMgcG9zc2libGUgdG8gY2lyY3VtdmVudCBzb21lIG9m
IHRoZXNlIGxpbWl0YXRpb25zIHVzaW5nIHRhZ2dpbmcsIGluIHBhcnRpY3VsYXINCiB0YWcgMjQg
KGVuY29kZWQgQ0JPUiBkYXRhIGl0ZW0pLCBidXQgdGhpcyBoYXMgdGhlIGRvd25zaWRlIG9mIGJy
ZWFraW5nIHRyYW5zbGF0YWJpbGl0eSB0byBKU09OLCB3aGljaCBpcyBhIGtleSBhZHZhbnRhZ2Ug
b2YgQ0JPUi4gQ29uc2lzdGVudCBUTFYgcmVwcmVzZW50YXRpb24gbWFrZXMgcGFyc2luZyBpbiBh
IGNvbnN0cmFpbmVkIGVudmlyb25tZW50IG9mZmVycyBhIG5vdGlvbmFsIHBlcmZvcm1hbmNlIGlt
cHJvdmVtZW50LCBidXQgdGhpcyBpcw0KIG1pbm9yIGFuZCBtYXkgbm90IHBsYXkgb3V0IGluIHBy
YWN0aWNlLjxvOnA+PC9vOnA+PC9saT48L29sPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9
Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvO21hcmdp
bi1sZWZ0Oi4yNWluO3RleHQtaW5kZW50Oi4yNWluIj4NCltubXNdIFRoZSBxdWVzdGlvbiB0byBh
c2sgaXMgd2hldGhlciB0aGlzIHNvcnQgb2YgcGFyc2luZyBpbmVmZmljaWVuY3kgaXMgYSBsYXJn
ZXIgcGFpbiBwb2ludCB0aGFuIGhhdmluZyB0byBkbyBzZW1hbnRpYyBtYXBwaW5nIG9mIHN0cnVj
dHVyZXMgdGhhdCBhbHJlYWR5IGFyZSBtZWFuaW5nZnVsIGluIHRoZSBjb250ZXh0IG9mIHRoZSBh
cHBsaWNhdGlvbiBlbnZpcm9ubWVudCB0aGF0IGlzIHBlcmZvcm1pbmcgdGhlIHVwZGF0ZS4gSW4g
c3VjaCBhDQogY2FzZSwgQVNOLjEgbWF5IGJlIHRoZSBncmVhdGVyIHBhaW4gcG9pbnQuPG86cD48
L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48
L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5OZXZlciB0aGUgbGVzcywg
SSB0aGluayB0aGF0IENCT1IvQ09TRSB3b3VsZCBiZSBwZXJmZWN0bHkgc2VydmljZWFibGUgZm9y
IHRoaXMgdXNlLiBJ4oCZbSBub3QgZXZlbiBjZXJ0YWluIHRoYXQgQVNOLjEgY2Fu4oCZdCBiZSB1
c2VkIGFzIGEgc2NoZW1hIGZvciBDQk9SIChzZWUgMyBhYm92ZSkuIFRoYXQgYmVpbmcgdGhlIGNh
c2UsIEkgY2FuIHNlZSBhIGNhc2UgZm9yIERFUiBtYW5pZmVzdHMgd2l0aCBDTVMsIGFuZA0KIENC
T1IgbWFuaWZlc3RzIHdpdGggQ09TRS48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+Jm5ic3A7Jm5i
c3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7
IFtubXNdIEdpdmVuIENPU0UgZW5jb2RlcyBYLjUwOSBhbmQgUEtDUyBzdHJ1Y3R1cmVzIGl0IHdv
dWxkIHNlZW0gdGhlIGRlc2lnbmVycyBhbnRpY2lwYXRlZCBpbnRlcm9wZXJhdGlvbiB3aXRoIEhT
TXMsIGF0IGxlYXN0IGF0IHRoZSBrZXkgYW5kIGNlcnRpZmljYXRlIGxldmVscyBvZiBhYnN0cmFj
dGlvbi4gQnV0IGdpdmVuIENPU0UgZGVmaW5lcyBhIGNyeXB0b2dyYXBoaWMgbWVzc2FnZSBzeW50
YXgNCiBvZiBpdHMgb3duLCBpdCBhbnRpY2lwYXRlcyByZWxldmFuY2UgaW4gbWVzc2FnaW5nIHBy
b2Nlc3NvciBlbnZpcm9ubWVudHMuIE15IHVuZGVyc3RhbmRpbmcgb2YgSFNNcyBhcmUgdGhhdCB0
aGV5IGRvbuKAmXQgYW50aWNpcGF0ZSBiZWluZyB1c2VkIGFzIG1lc3NhZ2UgcHJvY2Vzc29ycy4g
TXkgcXVlc3Rpb24gbWF5IGJlIGEgYml0IG1vcmUgcGhpbG9zb3BoaWNhbC4gRG8gdGhlIGF1dGhv
cnMgb2YgdGhlIFJGQyByZWdhcmQgdGhlIGV4Y2hhbmdlIG9mDQogU1cgdXBkYXRlcyBhbmQgdGhl
aXIgbWFuaWZlc3RzIGFzIGJlaW5nIGZ1bmRhbWVudGFsbHkgYW4gSFNNIHdvcmtsb2FkIG9yIHNv
bWV0aGluZyBlbHNlOyBzdWNoIGFzIGRldmljZSBtYW5hZ2VtZW50IG9yIHBvc3NpYmx5IGEgZGlz
dHJpYnV0ZWQgY29tcHV0ZT88bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48YnI+DQpUaHgsPG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIj5OZWQ8YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxibG9j
a3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPGRp
dj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0iYmFja2dyb3VuZDp3aGl0ZSI+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6Q2FsaWJyaSI+Jm5ic3A7
PC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTpDYWxpYnJpIj48bzpwPjwvbzpwPjwvc3Bh
bj48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNp
emU6OS4wcHQ7Zm9udC1mYW1pbHk6SGVsdmV0aWNhO2JhY2tncm91bmQ6d2hpdGUiPl9fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPC9zcGFuPjxzcGFuIHN0eWxl
PSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6SGVsdmV0aWNhIj48YnI+DQo8c3BhbiBzdHls
ZT0iYmFja2dyb3VuZDp3aGl0ZSI+RnVkIG1haWxpbmcgbGlzdDwvc3Bhbj48YnI+DQo8L3NwYW4+
PGEgaHJlZj0ibWFpbHRvOkZ1ZEBpZXRmLm9yZyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBw
dDtmb250LWZhbWlseTpIZWx2ZXRpY2E7Y29sb3I6Izk1NEY3MjtiYWNrZ3JvdW5kOndoaXRlIj5G
dWRAaWV0Zi5vcmc8L3NwYW4+PC9hPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1m
YW1pbHk6SGVsdmV0aWNhIj48YnI+DQo8L3NwYW4+PGEgaHJlZj0iaHR0cHM6Ly93d3cuaWV0Zi5v
cmcvbWFpbG1hbi9saXN0aW5mby9mdWQiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9u
dC1mYW1pbHk6SGVsdmV0aWNhO2NvbG9yOiM5NTRGNzI7YmFja2dyb3VuZDp3aGl0ZSI+aHR0cHM6
Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9mdWQ8L3NwYW4+PC9hPjxvOnA+PC9vOnA+
PC9wPg0KPC9kaXY+DQo8L2Jsb2NrcXVvdGU+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
Pjxicj4NCklNUE9SVEFOVCBOT1RJQ0U6IFRoZSBjb250ZW50cyBvZiB0aGlzIGVtYWlsIGFuZCBh
bnkgYXR0YWNobWVudHMgYXJlIGNvbmZpZGVudGlhbCBhbmQgbWF5IGFsc28gYmUgcHJpdmlsZWdl
ZC4gSWYgeW91IGFyZSBub3QgdGhlIGludGVuZGVkIHJlY2lwaWVudCwgcGxlYXNlIG5vdGlmeSB0
aGUgc2VuZGVyIGltbWVkaWF0ZWx5IGFuZCBkbyBub3QgZGlzY2xvc2UgdGhlIGNvbnRlbnRzIHRv
IGFueSBvdGhlciBwZXJzb24sIHVzZSBpdCBmb3IgYW55IHB1cnBvc2UsDQogb3Igc3RvcmUgb3Ig
Y29weSB0aGUgaW5mb3JtYXRpb24gaW4gYW55IG1lZGl1bS4gVGhhbmsgeW91LiA8bzpwPjwvbzpw
PjwvcD4NCjwvZGl2Pg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_88B5ACDCAEB94611B3D58A3C720E2795intelcom_--


From nobody Wed Sep 27 02:43:59 2017
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 28AC0134904 for <fud@ietfa.amsl.com>; Wed, 27 Sep 2017 02:43:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level: 
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GYyiRN_SW5WC for <fud@ietfa.amsl.com>; Wed, 27 Sep 2017 02:43:56 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 914B0134902 for <Fud@ietf.org>; Wed, 27 Sep 2017 02:43:55 -0700 (PDT)
Received: from [192.168.91.203] ([80.92.122.248]) by mail.gmx.com (mrgmx101 [212.227.17.168]) with ESMTPSA (Nemesis) id 0MCggg-1e5M5g0hxi-009Q1i; Wed, 27 Sep 2017 11:43:46 +0200
To: Brendan Moran <Brendan.Moran@arm.com>, "Smith, Ned" <ned.smith@intel.com>
Cc: "Fud@ietf.org" <Fud@ietf.org>
References: <D531874E-95BF-4A12-8049-15794BCD1039@intel.com> <2BF4654C-4260-4C7C-8DD5-CF892628711B@arm.com>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <d462ce27-f1b2-fbc3-21e6-d5007990ce10@gmx.net>
Date: Wed, 27 Sep 2017 11:43:45 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0
MIME-Version: 1.0
In-Reply-To: <2BF4654C-4260-4C7C-8DD5-CF892628711B@arm.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Provags-ID: V03:K0:V+bh82s7MgKatoAqlCTkUowTGs0ARFsPQkmroBHOiv8jPr07H21 KN0Gvgwyu0nR5UnAGHKtK3Q461IPkmkruebY9RD8J2ed8DZxvBbRuPlHF7zwFc1h4YBTzpW mtll6Tjs2h5Civfd2+Hb/0s1vxxSH9snDsYakrsq5KMQJZ9UQ2umH3oUvvUF2hJcox8crPk lxjvtUNbaTZcDJTDKgBZw==
X-UI-Out-Filterresults: notjunk:1;V01:K0:RFUBex+hQHw=:M0kRpfpolMKqEnDmBrdnKy l4eZ4NzaZw2iBnBiQ2FOhAFafgirH4qup6z3zj7Wau2f3fF9qGOgwMaoBsrm4LVPY2VivsMgy myFc32lvSZFJ555YjIrSYQ6DWik0ctc10PSNzQFsXk4wSB5brfnzFnW/sihjM+cvQufuasoRz LgAXqD4x+vmEGrOgJWf+4WSmUf163j1WDZC3T2oQfsACXNdgBHEgOugNkmBWlqRtp6AhyYPgY GO/U1mtBR/vjylti2tCbVLayMDU690SM3TMm+KKJ+dq3BMbu7MNe3ksjC0zYiH0LqvKF33FwL Z6v0elzo7lJatAqXcWr94oCHLGtbkjNhC3p9bEPGIsKvzKT1ULHOt6i8WM8cncZhJS0ycuVG1 WpSXFF2lcS5wPZBM9OKjHbdwataImS2sQfs2cYV16EXBJ0Y7vWCmN89IF38luPvoSgmmOlY6k aR+RgtlX9JsnmA6DmWQ8d8+IIBxPsSZj0kbqBDQiJGkATb7YPcGfPQe54qwlCzntgHxuJsWiF pqxX7lo6HTiLbfeGPGqlA5uL7wqketkrFTdUYi9tMM0nE0+i7m/DHa9uOFcDaCFcyq84RhWbj kMYVCY4J6p0lD+sBwRUYkF7njduatLWFXM/1yEJCxuE6/dTDQPNkZpmCo74VHK4AAFMcAwA0l gXBa0zR2z4aiWcB3hSO3Y3tBAxc+XN1Ybdu1Ylns2dQ5nMUMcQgzLnJDPq4XPoMvGO49yPboV nr++6rox+w+x9YKba7TkBqHcSDKsNxsR3W3CD7cpXdxVfF7VxxEDQvoCaa+qSi13RUn5LMjTU x0JcNZElCtzRuLq63rrJx77ZCFCWRTe/nWZKSGFZKjc1tdpbkQ=
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/l754ZFr2JO9QnpkJH8ki6Jl54Uw>
Subject: Re: [Fud] A few questions / observations
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Sep 2017 09:43:57 -0000

One minor remark:

On 09/26/2017 10:54 PM, Brendan Moran wrote:
>> ·         Is the push model supported (cloud storage pushes update
>> file proactively)?
> 
> Certainly. This is one of the expected use-cases, however manifest must
> precede payload.


The way to convey manifests and firmware images is actually independent
from the manifest format itself. This group aims to standardize the
manifest format. The different ways to transport the manifest/firmware
image to the devices can happen using a variety of protocols and in
different flavors, including push and pull approaches. We are using
LwM2M as a way to transport the firmware/manifest, for example.

Ciao
Hannes


From nobody Wed Sep 27 14:17:20 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8915D1350D9 for <fud@ietfa.amsl.com>; Wed, 27 Sep 2017 14:17:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CeSQRPFUb0rs for <fud@ietfa.amsl.com>; Wed, 27 Sep 2017 14:17:18 -0700 (PDT)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 233601350D3 for <fud@ietf.org>; Wed, 27 Sep 2017 14:17:18 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 7EA8430058D for <fud@ietf.org>; Wed, 27 Sep 2017 17:17:17 -0400 (EDT)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 55_A-t3E-Avh for <fud@ietf.org>; Wed, 27 Sep 2017 17:17:16 -0400 (EDT)
Received: from [172.20.1.237] (h60.74.129.40.static.ip.windstream.net [40.129.74.60]) by mail.smeinc.net (Postfix) with ESMTPSA id 244893002A3; Wed, 27 Sep 2017 17:17:15 -0400 (EDT)
From: Russ Housley <housley@vigilsec.com>
Message-Id: <FAC5CB2C-2BCB-400D-8432-1A9C5B9A2072@vigilsec.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_169ABCC2-F08E-41A9-96FE-9DFDCFBA2516"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Wed, 27 Sep 2017 17:17:15 -0400
In-Reply-To: <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org>
Cc: fud@ietf.org
To: Carsten Bormann <cabo@tzi.org>
References: <598d9373-4a4a-01c3-33e8-34ed1beceaa2@gmx.net> <B7D00C27-E186-4455-AEE4-02066F5D430F@tzi.org>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/DrJBeYLRNtMIXhoY-jLzMmBBgWo>
Subject: Re: [Fud] Revised Charter Text
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Sep 2017 21:17:19 -0000

--Apple-Mail=_169ABCC2-F08E-41A9-96FE-9DFDCFBA2516
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8


>> Firmware Updating Description (FUD)
>> [Alternative proposal: SUIT (Software Updates for Internet of =
Things).]
>=20
> SUIT is so much better than FUD.
>=20
> (When we created the DICE working group, which was about =
=E2=80=9CImprovements to DTLS for the Internet of Things=E2=80=9D, we =
got some strong feedback that people weren=E2=80=99t going to install =
=E2=80=9CIDIOT=E2=80=9D modifications into their systems.
> I think the same applies for =E2=80=9CFUD=E2=80=9D.  And the suits =
will quickly agree with installing SUIT :-))

I am chairing two groups where the WG got a different name than the BoF. =
 In both cases, the mail list continues to have the BoF name, and it =
causes confusion.  If the WG gets called something other than FUD, I =
strongly recommend closing this mail list and opening one that is named =
the same as the WG.

Russ



--Apple-Mail=_169ABCC2-F08E-41A9-96FE-9DFDCFBA2516
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><br class=3D""><div><blockquote type=3D"cite" class=3D""><div =
class=3D""><div class=3D"Singleton"><blockquote type=3D"cite" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" =
class=3D"">Firmware Updating Description (FUD)<br class=3D"">[Alternative =
proposal: SUIT (Software Updates for Internet of Things).]<br =
class=3D""></blockquote><br style=3D"font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><span style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">SUIT is so much better than =
FUD.</span><br style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">(When we created the DICE =
working group, which was about =E2=80=9CImprovements to DTLS for the =
Internet of Things=E2=80=9D, we got some strong feedback that people =
weren=E2=80=99t going to install =E2=80=9CIDIOT=E2=80=9D modifications =
into their systems.</span><br style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">I think the same applies for =
=E2=80=9CFUD=E2=80=9D. &nbsp;And the suits will quickly agree with =
installing SUIT :-))</span></div></div></blockquote><br =
class=3D""></div><div>I am chairing two groups where the WG got a =
different name than the BoF. &nbsp;In both cases, the mail list =
continues to have the BoF name, and it causes confusion. &nbsp;If the WG =
gets called something other than FUD, I strongly recommend closing this =
mail list and opening one that is named the same as the =
WG.</div><div><br class=3D""></div><div>Russ</div><div><br =
class=3D""></div><br class=3D""></body></html>=

--Apple-Mail=_169ABCC2-F08E-41A9-96FE-9DFDCFBA2516--


From nobody Fri Sep 29 04:00:34 2017
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: fud@ietfa.amsl.com
Delivered-To: fud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41EEA134290 for <fud@ietfa.amsl.com>; Fri, 29 Sep 2017 04:00:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.4
X-Spam-Level: 
X-Spam-Status: No, score=-5.4 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 38rtHztxrexi for <fud@ietfa.amsl.com>; Fri, 29 Sep 2017 04:00:29 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A6E3132D49 for <fud@ietf.org>; Fri, 29 Sep 2017 04:00:28 -0700 (PDT)
Received: from [192.168.91.203] ([80.92.122.248]) by mail.gmx.com (mrgmx001 [212.227.17.190]) with ESMTPSA (Nemesis) id 0M4nt7-1d8gtD41Wv-00yvV3 for <fud@ietf.org>; Fri, 29 Sep 2017 13:00:27 +0200
To: "Fud@ietf.org" <fud@ietf.org>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <c14c92bf-cf99-efdb-6693-0e33519fbb0a@gmx.net>
Date: Fri, 29 Sep 2017 13:00:26 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:yUBNJpNOw5Q3W+rCRFsiyCBEhBSdwcsU6bscqits382TCAvakfM qIvlAno7KrLRkg48XDxvfF7xunpcYQX7rB+aoea8W4q7a1rh9Xy2ajSgXo/Zolwv5eZq3pn AMlWLAAIzoyFsngw74iPazCLJB7XgB2ht4Gnxti8vWZ1Q/Xn/lCt1QLFASTXgVD/FdH6Tjt MNUYPbed6mVVjDaYaBRcg==
X-UI-Out-Filterresults: notjunk:1;V01:K0:GczvObEPbP8=:beLLX1nQSAPW+hxkipuAAj uDzkpc7Gjn4I4N+zBZNROvRzcrYSpd0fXjpVQdjAjB2seG0DSlgrXDQMPUKStT2uZQFjvyQsb Q65T9RloQHdNfvlUpgmBxczSGmBsKnelD+QNc0WDzUgdcAMuJkMVQnEu6/K1dq+VEfbOOkRta hSghHzzXA0ELMdC88VVgGb/5t6k5fQ5g0hm2aLkzHn4OodTAvz+Z/DLOLcLJFBY66gpxKaItM ZV0GvmStUM/RJtOPYTs0gCjQaEWVyaKzz12xPm8MoyEzS2hYCBAWJseyQRODT0ALGGWHkazl3 lBRmt7FJdyEetuoTKZU0ifN0EA8wXKDdxZ/xAhCSVk33QF8Wf3b9O8XxPJeh86RMv7Ng3J6+0 3cn58nrP/Uzf1k2QuuAet0fLCh4yL6Ci04ECs4huMRFz36nF1xBstURPGDhKNjIwWEFbEqnDx 59Q+EOag8i96HxfifeZQTZrtflzMtwOL2+CwDUTvsU7BXzWPs/NMRWZAUZo/c4SuKQiWAB6h/ UmlDOmqQOX5VVhBd2zvcC2ZU5+AT/J9Avjk4NcYQ37zMRusD45M7UuuxqXWbAuLA0Pc578yMd FY67Tl0sZO45x8ppXkA7476gjXfI0UIbsHE6sAR82brKYXRMQL/DddRS+4W6iKO5Gib3R1vx2 hK6APZfXSC1KzHbnrohDt/5bUol33Sxyx6DImU3C2XW2vyjI0toCOqOTtHJXp4C9ZLB1Cf3lt 9Ha9365s0gjSpJK/ssLaqkH930fkx3CImXAdI8umQa+rQikQRTi4nkHE8PbLGo8z9H7sXykvs 2e5MKoqoY1h46LMRRVWWrzlzHM6cUJJSkgeQmVnJZyxRFot5kw=
Archived-At: <https://mailarchive.ietf.org/arch/msg/fud/uvqbCtWTh2KAHa4Lu8qR_u236Pw>
Subject: [Fud] Editorial Charter Update
X-BeenThere: fud@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FUD - Firmware Updating Description <fud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/fud>, <mailto:fud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/fud/>
List-Post: <mailto:fud@ietf.org>
List-Help: <mailto:fud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/fud>, <mailto:fud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Sep 2017 11:00:32 -0000

Irit Arkin, my co-worker, helped to improve readability of the charter
text. Below is the updated charter text:

-----

Firmware Updating Description (FUD)
[Alternative proposal: SUIT (Software Updates for Internet of Things).]

Vulnerabilities in Internet of Things (IoT) devices have raised the
need for a secure firmware update mechanism that is also suitable for
constrained devices. Security experts, researchers and regulators
recommend that all IoT devices be equipped with such a mechanism. While
there are many proprietary firmware update mechanisms in use today, there
is a lack of a modern interoperable approach of securely updating IoT
devices.

A firmware update solution consists of several components, including:
* A mechanism to transport firmware images to IoT devices.
* A manifest that provides meta-data about the firmware image
  (such as a firmware package identifier, the hardware the package
   needs to run, and dependencies on other firmware packages), as
   well as cryptographic information for protecting the firmware
   image in an end-to-end fashion.
* The firmware image itself.

With RFC 4108 the IETF standardized a manifest format that uses the
Cryptographic Message Syntax (CMS) to protect firmware packages.

More than ten years have passed since the publication of RFC 4108, and
greater experience with IoT deployments has lead to additional
functionality, requiring the work done with RFC 4108 to be revisited. The
purpose of this group is to standardize a second version of RFC 4108 that
reflects the current best practices. This group focuses on defining a
firmware update solution for Class 1 devices, as defined in RFC 7228,
that is - IoT devices with ~10 KiB RAM and ~100 KiB flash. This group
will not define any transport mechanisms.

In June of 2016 the Internet Architecture Board organized a workshop on
'Internet of Things (IoT) Software Update (IOTSU)', which took place at
Trinity College Dublin, Ireland. The main goal of the workshop was to
foster a discussion on requirements,
challenges and solutions for bringing software and firmware updates to
IoT devices. This workshop also made clear that there are challenges
with lack of regulatory requirements and misaligned incentives. It is
nevertheless seen as important to standardize the building blocks that
help interested parties implement and deploy a solid firmware update
mechanism.

In particular this group aims to publish two documents, namely:
* An IoT firmware update architecture that includes a description of
the involved entities, security threats and assumptions.
* The manifest format itself.

This group does not aim to standardize a generic software update
mechanism used by rich operating systems, like Linux, but instead
focuses on software development practices in the embedded industry. Also
out of scope are
software update solutions that aim to take the features of scripting
languages, such as JavaScript variants like JerryScript, into account.

This group will aim to develop a close relationship with silicon vendors
and OEMs that develop IoT operating systems.

Milestones

Dec 2017     Submit "Architecture" document as WG item.

Dec 2017     Submit "Manifest Format" specification as WG item.

Jul 2018    Submit "Architecture" to the IESG for publication as an
Informational RFC.

Nov 2018     Submit "Manifest Format" to the IESG for publication as a
Proposed Standard.


Additional calendar items:

Mar 2018     Release initial version of the manifest creation tools as
open source.

Apr 2018     Release first version of manifest test tool suite as open
source.

Jun 2018     Release first IoT OS implementation of firmware update
mechanisms as open source.

