OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

imi message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [imi] Token profile issue with AppliesTo and AudienceRestriction


--Apple-Mail-211--854969967
Content-Type: multipart/alternative;
	boundary=Apple-Mail-210--854971257


--Apple-Mail-210--854971257
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

I think the IDP has enough control with the three options in the card.  =
See 3.3.3

I should point out I just noticed that 11.7 Auditing-Optional Card: is =
wrong.  It dos not mention the <AppliesTo> element in the RP policy and =
implies the default is the opposite to what it is.    Sorry I should =
have cought that.

The problem is that the RP largely has no control, unless they are using =
a RP/STS.

Auditing optional cards are not useful at the moment because they always =
default to non-auditing.

We need a way for the RP to select Auditing vs non-Auditing for Auditing =
optional cards without a RP STS.

I agree with Scott that the URL of the page the object tag is on is a =
bit crude.

Having a way to specify the identity of the RP via WS-Security Policy or =
object tag etc is also a requirement.

While we are at it giving the user the ability to tell if the card is =
disclosing information about the RP to the issuer would be nice.  That =
is probably an implementation issue.

The audience restriction issue could be mitigated if we had a way to do =
HoK through the browser.=20

(Scott can take over on the HoK rant)

John B.

On 2009-12-15, at 7:55 PM, Mike Jones wrote:

> (adding Arun to the thread, so he can see this)
>=20
> -----Original Message-----
> From: Scott Cantor [mailto:cantor.2@osu.edu]=20
> Sent: Tuesday, December 15, 2009 2:54 PM
> To: 'John Bradley'; Mike Jones
> Cc: imi@lists.oasis-open.org
> Subject: RE: [imi] Token profile issue with AppliesTo and =
AudienceRestriction
>=20
> John Bradley wrote on 2009-12-15:
>> Thank Arun for me.
>=20
> And me. ;-)
>=20
> One of my major outstanding issues, related to this topic, is how to =
get
> AppliesTo in there as the default/common case. Either we need expanded =
use
> of WS-SP for non-STS RPs or we fix the tag, but we need something.
>=20
> The problem with the IdP-only approach that bakes "require AppliesTo" =
into
> the card is that the selector then mis-applies the delivery location =
as the
> identifier of the RP, which are not at all the same thing.
>=20
> -- Scott
>=20
>=20
>=20
> ---------------------------------------------------------------------
> To unsubscribe from this mail list, you must leave the OASIS TC that
> generates this mail.  Follow this link to all your TCs in OASIS at:
> https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php=20=

>=20
>=20
>=20
> ---------------------------------------------------------------------
> To unsubscribe from this mail list, you must leave the OASIS TC that
> generates this mail.  Follow this link to all your TCs in OASIS at:
> https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
>=20


--Apple-Mail-210--854971257
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">I =
think the IDP has enough control with the three options in the card. =
&nbsp;See 3.3.3<div><br></div><div>I should point out I just noticed =
that 11.7&nbsp;<span class=3D"Apple-style-span" style=3D"font-size: =
10px; font-weight: bold; ">Auditing-Optional Card: </span><font =
class=3D"Apple-style-span" color=3D"#000000" size=3D"3"><span =
class=3D"Apple-style-span" style=3D"background-color: transparent; =
font-size: 12px;">is wrong. &nbsp;It dos not mention the =
&lt;AppliesTo&gt; element in the RP policy and implies the default is =
the opposite to what it is. &nbsp; &nbsp;Sorry I should have cought =
that.</span></font></div><div><div><br></div><div>The problem is that =
the RP largely has no control, unless they are using a =
RP/STS.</div><div><br></div><div>Auditing optional cards are not useful =
at the moment because they always default to =
non-auditing.</div><div><br></div><div>We need a way for the RP to =
select Auditing vs non-Auditing for Auditing optional cards without a RP =
STS.</div><div><br></div><div>I agree with Scott that the URL of the =
page the object tag is on is a bit =
crude.</div><div><br></div><div>Having a way to specify the identity of =
the RP via WS-Security Policy or object tag etc is also a =
requirement.</div><div><br></div><div>While we are at it giving the user =
the ability to tell if the card is disclosing information about the RP =
to the issuer would be nice. &nbsp;That is probably an implementation =
issue.</div><div><br></div><div>The audience restriction issue could be =
mitigated if we had a way to do HoK through the =
browser.&nbsp;</div><div><br></div><div>(Scott can take over on the HoK =
rant)</div><div><br></div><div>John =
B.</div><div><br></div><div><div><div>On 2009-12-15, at 7:55 PM, Mike =
Jones wrote:</div><br class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><div>(adding Arun to the thread, so he can see =
this)<br><br>-----Original Message-----<br>From: Scott Cantor =
[mailto:cantor.2@osu.edu] <br>Sent: Tuesday, December 15, 2009 2:54 =
PM<br>To: 'John Bradley'; Mike Jones<br>Cc: <a =
href=3D"mailto:imi@lists.oasis-open.org";>imi@lists.oasis-open.org</a><br>S=
ubject: RE: [imi] Token profile issue with AppliesTo and =
AudienceRestriction<br><br>John Bradley wrote on =
2009-12-15:<br><blockquote type=3D"cite">Thank Arun for =
me.<br></blockquote><br>And me. ;-)<br><br>One of my major outstanding =
issues, related to this topic, is how to get<br>AppliesTo in there as =
the default/common case. Either we need expanded use<br>of WS-SP for =
non-STS RPs or we fix the tag, but we need something.<br><br>The problem =
with the IdP-only approach that bakes "require AppliesTo" into<br>the =
card is that the selector then mis-applies the delivery location as =
the<br>identifier of the RP, which are not at all the same =
thing.<br><br>-- =
Scott<br><br><br><br>-----------------------------------------------------=
----------------<br>To unsubscribe from this mail list, you must leave =
the OASIS TC that<br>generates this mail. &nbsp;Follow this link to all =
your TCs in OASIS at:<br><a =
href=3D"https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups=
.php">https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.p=
hp</a> =
<br><br><br><br>----------------------------------------------------------=
-----------<br>To unsubscribe from this mail list, you must leave the =
OASIS TC that<br>generates this mail. &nbsp;Follow this link to all your =
TCs in OASIS at:<br><a =
href=3D"https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups=
.php">https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.p=
hp</a><br><br></div></blockquote></div><br></div></div></body></html>=

--Apple-Mail-210--854971257--

--Apple-Mail-211--854969967
Content-Disposition: attachment;
	filename=smime.p7s
Content-Type: application/pkcs7-signature;
	name=smime.p7s
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIWJDCCBv8w
ggXnoAMCAQICAnEPMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4
MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0Ew
HhcNMDkwMzE5MDA1MzU2WhcNMTAwMzE5MDA1MzU2WjBsMR4wHAYDVQQKExVQZXJzb25hIE5vdCBW
YWxpZGF0ZWQxKTAnBgNVBAMTIFN0YXJ0Q29tIEZyZWUgQ2VydGlmaWNhdGUgTWVtYmVyMR8wHQYJ
KoZIhvcNAQkBFhBqYnJhZGxleUBtYWMuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
AQEAz3okuJxE7OE652aGLbj/c3BSDEN948QVbCpKaE1HcsIdvGCIzgJWujkMj5Q+QJNXb6VYPR8W
xIaIjqlZIhqXzis9YEzc6z3MsdhYpeDTEbJg/hXpW1NFHX+CIGDO2TD2v6V7SbJYNm6MDJhHQEEn
/fGBtWrdDXwTHUQBQNJX1N4pUWaTqgcPBiW2V/M1/ZuFZlo0RBJRfHpHkYqTBDx2VkA+KYl6ULTy
TnKsYzGQFqAqp5T/nnOqyEV6iItSAuczHf6DTe5gyDzbBE+BLx3bzdDXn2uE27DFAERJaVzu1G34
wW23M7PQyFzoo5bvGbBjGCSLYQ7/EFulChKwxA7EDQIDAQABo4IDiDCCA4QwCQYDVR0TBAIwADAL
BgNVHQ8EBAMCBLAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRIzl+k
PHLfEqIfyQAbdLvRd9ELHDAbBgNVHREEFDASgRBqYnJhZGxleUBtYWMuY29tMIGoBgNVHSMEgaAw
gZ2AFFNy7ZKc4NrLAVx8fpY1TvLUuFGCoYGBpH8wfTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0
YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcx
KTAnBgNVBAMTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5ggENMIIBRwYDVR0gBIIB
PjCCATowggE2BgsrBgEEAYG1NwECADCCASUwLgYIKwYBBQUHAgEWImh0dHA6Ly93d3cuc3RhcnRz
c2wuY29tL3BvbGljeS5wZGYwNAYIKwYBBQUHAgEWKGh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL2lu
dGVybWVkaWF0ZS5wZGYwgbwGCCsGAQUFBwICMIGvMBQWDVN0YXJ0Q29tIEx0ZC4wAwIBARqBlkxp
bWl0ZWQgTGlhYmlsaXR5LCByZWFkIHRoZSBzZWN0aW9uICpMZWdhbCBMaW1pdGF0aW9ucyogb2Yg
dGhlIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5IFBvbGljeSBhdmFpbGFibGUgYXQg
aHR0cDovL3d3dy5zdGFydHNzbC5jb20vcG9saWN5LnBkZjBjBgNVHR8EXDBaMCugKaAnhiVodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMCugKaAnhiVodHRwOi8vY3JsLnN0YXJ0
c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzABhi1odHRw
Oi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYBBQUHMAKGNmh0
dHA6Ly93d3cuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50LmNhLmNydDAjBgNV
HRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcNAQEFBQADggEBAJseTTEK
i3xbLVWJPJF/oArTkB1LAr8TxR1JKoxQBgBrZwmWU4MNnU525gR59/ZlgYCp2HBBF8EG9iYFNShu
hkRxfT3PpgiQ9/hdPS5lyE+l5cAhYnkJHicpqoIsWwAAcR6aG08kU3Jx7O++RLOvRthYZIGY5aG5
PIogRS844AlQTNAeFtSSpAlYZT6MJjE55eQb0pXIUr+8QJEdmPax5DMV+iBASElHir4knWLDfCEc
m2+OK0CajHxTg1tU7H/d58BIfB8Szml3SUxbek98OOKZP4URdFbZA4+o27lEJSJFb9JvMjABimt9
YpmvU4oKmNKYLBM1UP6iC4ZtdkX2HZ8wggc3MIIGH6ADAgECAgIA3jANBgkqhkiG9w0BAQUFADCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBE
aWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDIgUHJp
bWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBMB4XDTA5MDMyMDE5NTYyMloXDTEwMDMyMDE5NTYy
MlowgaMxCzAJBgNVBAYTAkNBMRkwFwYDVQQIExBCcml0aXNoIENvbHVtYmlhMRIwEAYDVQQHEwlW
YW5jb3V2ZXIxLTArBgNVBAsTJFN0YXJ0Q29tIFZlcmlmaWVkIENlcnRpZmljYXRlIE1lbWJlcjEV
MBMGA1UEAxMMSm9obiBCcmFkbGV5MR8wHQYJKoZIhvcNAQkBFhBqYnJhZGxleUBtYWMuY29tMIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6eBS+r9t09H9KUSW4W/YvlZxSKjNR1pa017l
TwoaP7ydmJjdFyN8i0CMbW3qUidZP/gZcrACAtF7c4GPf+o0sxMIHC1pVUANhCS4HMwTA2KRIBqu
5LJ2IIni5HWN1mv2Q8kN+GgvX0v2SzQraZZ1yRSpJcqI2q9oV2XsUlQ0f4icnMAD/o3FtBk2p2OV
+R0IGrDiRYPsL3tyf7IjO+3zYJJS2iFkIRgYy+egI4AhWrd9t6EqnoHMplt4n5/xgoxPXRQ8T4ST
03wVsTXbeAmWECTud8RLiqvU6s9qvm1QlNuXfqjnGDy4Zgok3epFsTNP9rtIHdI36bYp6c/+6GQF
HQIDAQABo4IDiDCCA4QwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYDVR0lBBYwFAYIKwYBBQUH
AwIGCCsGAQUFBwMEMB0GA1UdDgQWBBSJ3y3+LbYfMZEALd2djXgavtvAZzAbBgNVHREEFDASgRBq
YnJhZGxleUBtYWMuY29tMIGoBgNVHSMEgaAwgZ2AFK5Vg2/sMcq59x36r2sx88gd46y7oYGBpH8w
fTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBE
aWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxKTAnBgNVBAMTIFN0YXJ0Q29tIENlcnRpZmljYXRp
b24gQXV0aG9yaXR5ggEOMIIBRwYDVR0gBIIBPjCCATowggE2BgsrBgEEAYG1NwECADCCASUwLgYI
KwYBBQUHAgEWImh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwNAYIKwYBBQUHAgEW
KGh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL2ludGVybWVkaWF0ZS5wZGYwgbwGCCsGAQUFBwICMIGv
MBQWDVN0YXJ0Q29tIEx0ZC4wAwIBARqBlkxpbWl0ZWQgTGlhYmlsaXR5LCByZWFkIHRoZSBzZWN0
aW9uICpMZWdhbCBMaW1pdGF0aW9ucyogb2YgdGhlIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0
aG9yaXR5IFBvbGljeSBhdmFpbGFibGUgYXQgaHR0cDovL3d3dy5zdGFydHNzbC5jb20vcG9saWN5
LnBkZjBjBgNVHR8EXDBaMCugKaAnhiVodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9jcnR1Mi1jcmwu
Y3JsMCugKaAnhiVodHRwOi8vY3JsLnN0YXJ0c3NsLmNvbS9jcnR1Mi1jcmwuY3JsMIGOBggrBgEF
BQcBAQSBgTB/MDkGCCsGAQUFBzABhi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNz
Mi9jbGllbnQvY2EwQgYIKwYBBQUHMAKGNmh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL2NlcnRzL3N1
Yi5jbGFzczIuY2xpZW50LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNv
bS8wDQYJKoZIhvcNAQEFBQADggEBAKsZIOrdqVshNdrUw80Zr2RiHFnzPjKxqG6tFKG/hISfJ7WF
xAlnATxZNytnMFiNfLDS7O4P3idfwx8HnE8H5DBT0k8FYxcip6MDVMxZ/23DVhhKq7pTmj4DrPNB
2KZKwSwXKdUblksjNalfzs9ymozBRcK2H6S6y5bSE0b9aOVN5aGGOQBL+fp/Xh12+SrAl9M1RA5X
oFSTvMoVI3txCqFPpJdFL0jzKujaJBdg+OeUDSQCSbwFd7X9vcLdWdsfnHLECZE6C+KXfA9IoK7f
YloBd2HEo51VkJa10FRAdZglMapXaAtl7Agdgegw8fveQ86d2v2A8e4ptZaaVhBjE8YwggfiMIIF
yqADAgECAgEOMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENv
bSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMSkwJwYD
VQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEwMjQyMTAyNTRaFw0x
MjEwMjIyMTAyNTRaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkG
A1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRD
b20gQ2xhc3MgMiBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0EwggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQDLKIVFnAEs+xnyq6UzjCqgDcvQVe1dIoFnRsQPCFO+y92k8RK0Pn3M
bQ2Gd+mehh9GBZ+36uUQA7Xj9AGM6wgPhEE34vKtfpAN5tJ8LcFxveDObCKrL7O5UT9WsnAZHv7O
YPYSR68mdmnEnJ83M4wQgKO19b+Rt8sPDAz9ptkQsntCn4GeJzg3q2SVc4QJTg/WHo7wF2ah5LMO
eh8xJVSKGEmd6uPkSbj113yKMm8vmNptRPmM1+YgmVwcdOYJOjCgFtb2sOP79jji8uhWR91xx7Tp
M1K3hv/wrBZwffrmmEpUeuXHRs07JqCCvFh9coKF4UQZvfEg+x3/69xRCzb1AgMBAAGjggNbMIID
VzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIBpjAdBgNVHQ4EFgQUrlWDb+wxyrn3HfqvazHzyB3j
rLswgagGA1UdIwSBoDCBnYAUTgvvGqRAW6UXaYcwyjRoQ9BBrvKhgYGkfzB9MQswCQYDVQQGEwJJ
TDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzEpMCcGA1UEAxMgU3RhcnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHmC
AQEwCQYDVR0SBAIwADA9BggrBgEFBQcBAQQxMC8wLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cuc3Rh
cnRzc2wuY29tL3Nmc2NhLmNydDBgBgNVHR8EWTBXMCygKqAohiZodHRwOi8vY2VydC5zdGFydGNv
bS5vcmcvc2ZzY2EtY3JsLmNybDAnoCWgI4YhaHR0cDovL2NybC5zdGFydHNzbC5jb20vc2ZzY2Eu
Y3JsMIIBXQYDVR0gBIIBVDCCAVAwggFMBgsrBgEEAYG1NwEBBDCCATswLwYIKwYBBQUHAgEWI2h0
dHA6Ly9jZXJ0LnN0YXJ0Y29tLm9yZy9wb2xpY3kucGRmMDUGCCsGAQUFBwIBFilodHRwOi8vY2Vy
dC5zdGFydGNvbS5vcmcvaW50ZXJtZWRpYXRlLnBkZjCB0AYIKwYBBQUHAgIwgcMwJxYgU3RhcnQg
Q29tbWVyY2lhbCAoU3RhcnRDb20pIEx0ZC4wAwIBARqBl0xpbWl0ZWQgTGlhYmlsaXR5LCByZWFk
IHRoZSBzZWN0aW9uICpMZWdhbCBMaW1pdGF0aW9ucyogb2YgdGhlIFN0YXJ0Q29tIENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5IFBvbGljeSBhdmFpbGFibGUgYXQgaHR0cDovL2NlcnQuc3RhcnRjb20u
b3JnL3BvbGljeS5wZGYwEQYJYIZIAYb4QgEBBAQDAgAHMFAGCWCGSAGG+EIBDQRDFkFTdGFydENv
bSBDbGFzcyAyIFByaW1hcnkgSW50ZXJtZWRpYXRlIEZyZWUgU1NMIEVtYWlsIENlcnRpZmljYXRl
czANBgkqhkiG9w0BAQUFAAOCAgEAHvcQF/726YR5L5A3Ta7JV1nTu3w9yWqp00945pg7uea+1KVt
R/7/yeNFAV7MPQylPE8pROEcGU+RwwDFuNn9cePfAMzOBTpy/6VE076+gYkZa4n8uWaL5A2FVo8t
RmEyfoT4gRL9B5h5w8Y4ZySCJBLyfp4jByyxHaTTIWZ8TIkxUQLSBeFnmHKYFwYwMbBA0Sgb8ONC
vq9zeJcpMkkDadhJSCfB9c9gZocbaaVHVqTlSeENRr5/Y31dapzIRQg2Pl9V/A65Cq03KQxMXBpX
n8HkLO/g2FCt7KYkJCaTe6qT2JX8thmB3nb+5RmtWQIITCP+PPNkFQCts6ujOtJx6TlDLWA+tV7Q
LN2Q+S98p/SwnXito+GW0N7kXcL8QDBVsF8lCvwCz+JQrvUIcW5xEzpAVk9xSbpePxVIMzNEUQhB
obkFojhUqGt+VyU3GH/+BP2brzl4StOJ1KXuw2EzFs0ai9OMsqCUFRyhykm6MrbnsnSrqhWSnSQP
YIu+zpzwWC/8sZFxoJCwvbbIu+6E+AIGa8tP+pYF+empPn/7pkIoTT4LSkkEIxGKvUvDJTh86VDN
L8bIIQE2LHVDwcOq+mcQx416FAA9Nw1DBGyrFr6hQe5yTVXrJ4G7vJosNRGCwPnx302gonaFdwi+
+YyqjPyhPO6q4fRarYvWyqp5L6UxggNsMIIDaAIBATCBkzCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNp
Z25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDIgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xp
ZW50IENBAgIA3jAJBgUrDgMCGgUAoIIBrTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqG
SIb3DQEJBTEPFw0wOTEyMTUyMzM0MzFaMCMGCSqGSIb3DQEJBDEWBBTExD9r1WMwSciRmq7k2NF6
zpV6hzCBpAYJKwYBBAGCNxAEMYGWMIGTMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRD
b20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYG
A1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0ECAnEP
MIGmBgsqhkiG9w0BCRACCzGBlqCBkzCBjDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29t
IEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNV
BAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgJxDzAN
BgkqhkiG9w0BAQEFAASCAQBqJ04TGthMf2d7fXXjotCkYDnPMqv/9rg+p8DdWF/ukYU1Ff3SY0To
nXiogQfgTuLv/M8/o3EOPmMUI6pgMJoLQTGvHzw7/Yx17s90treQGP3IHeaL1+GZpuT6el8CDJQa
C4PCdUnz1bMKE/lyab7q8AaJKgyTO15RZ6LRez5/x25iVLYisySf+75DLRw2L7LgxuviZkOFPpaq
lP8HTGINH8f0l0/SrJ2m4O+ZjMi61tMMRz2HR0rN7ZEB9hWzpcekG9khcXDHjb5AjW0iprWBAP/8
lbTM6Z9MMV62XOFeYoxbqZ47gfjTr3G6w97Vn4WDtxpKBb21GXRAK9uCy61DAAAAAAAA

--Apple-Mail-211--854969967--


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]