<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.6.23 (Ruby 2.6.10) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-core-coap-pubsub-13" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.16.0 -->
  <front>
    <title>A publish-subscribe architecture for the Constrained Application Protocol (CoAP)</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-core-coap-pubsub-13"/>
    <author initials="J." surname="Jimenez" fullname="Jaime Jimenez">
      <organization>Ericsson</organization>
      <address>
        <email>jaime@iki.fi</email>
      </address>
    </author>
    <author initials="M." surname="Koster" fullname="Michael Koster">
      <organization>Dogtiger Labs</organization>
      <address>
        <email>michaeljohnkoster@gmail.com</email>
      </address>
    </author>
    <author initials="A." surname="Keranen" fullname="Ari Keranen">
      <organization>Ericsson</organization>
      <address>
        <email>ari.keranen@ericsson.com</email>
      </address>
    </author>
    <date year="2023" month="October" day="20"/>
    <area>Applications</area>
    <workgroup>CoRE Working Group</workgroup>
    <abstract>
      <t>This document describes a publish-subscribe architecture for the Constrained Application Protocol (CoAP), extending the capabilities of CoAP communications for supporting endpoints with long breaks in connectivity and/or up-time. CoAP clients publish on and subscribe to a topic via a corresponding topic resource at a CoAP server acting as broker.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-core-coap-pubsub/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        core Working Group mailing list (<eref target="mailto:core@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/core/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/core/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/core-wg/coap-pubsub"/>.</t>
    </note>
  </front>
  <middle>
    <section anchor="introduction">
      <name>Introduction</name>
      <t>The Constrained Application Protocol (CoAP) <xref target="RFC7252"/> supports
machine-to-machine communication across networks of constrained
devices and constrained networks. CoAP uses a request/response model where clients make requests to servers in order to request actions on resources. Depending on the situation the same device may act either as a server, a client, or both.</t>
      <t>One important class of constrained devices includes devices that are intended to run for years from a small battery, or by scavenging energy from their environment. These devices have limited up-time because they spend most of their time in a sleeping state with no network connectivity. Another important class of nodes are devices with limited reachability due to middle-boxes like Network Address Translators (NATs) and firewalls.</t>
      <t>For these nodes, the client/server-oriented architecture of REST can be challenging when interactions are not initiated by the devices themselves. A publish/subscribe-oriented architecture where nodes exchange data via topics through a broker entity might fit these nodes better.</t>
      <t>This document applies the idea of broker-based publish-subscribe to Constrained RESTful Environments using CoAP. It defines a broker that allows to create, discover subscribe and publish on topics.</t>
      <section anchor="terminology">
        <name>Terminology</name>
        <t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL
NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED",
"MAY", and "OPTIONAL" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
        <t>This specification requires readers to be familiar with all the terms and
concepts that are discussed in <xref target="RFC8288"/> and <xref target="RFC6690"/>. Readers
should also be familiar with the terms and concepts discussed in
<xref target="RFC7252"/>, <xref target="RFC9176"/> and <xref target="RFC7641"/>. The URI template
format <xref target="RFC6570"/> is used to describe the REST API defined in
this specification.</t>
        <t>This specification makes use of the following terminology:</t>
        <dl newline="true">
          <dt>publish-subscribe (pub/sub):</dt>
          <dd>
            <t>A message communication model where messages associated with specific topics are sent to a broker. Interested parties, i.e. subscribers, receive these topic-based messages from the broker without the original sender knowing the recipients. The broker handles matching and delivering these messages to the appropriate subscribers.</t>
          </dd>
          <dt>publishers and subscribers:</dt>
          <dd>
            <t>CoAP clients can act as publishers or as subscribers. Publishers send CoAP messages (publications) to the broker on specific topics. Subscribers have an ongoing observation relation (subscription) to a topic. Both roles operate without any mutual knowledge, guided by their respective topic interests.</t>
          </dd>
          <dt>topic collection:</dt>
          <dd>
            <t>A set of topic configurations. A topic collection is hosted as one collection resource at the broker, and its representation is the list of links to the topic resources corresponding to each topic configuration.</t>
          </dd>
          <dt>topic-configuration:</dt>
          <dd>
            <t>A set of information concerning a topic, including its configuration and other metadata. A topic configurations is hosted as one topic resource at the broker, and its representation is the set of configuration information concerning the topic. All the topic resources associated with the same topic collection share a common base URI, i.e., the URI of the collection resource. Throughout this document the word "topic" and "topic-configuration" can be used interchangeably.</t>
          </dd>
          <dt>topic-data resource:</dt>
          <dd>
            <t>A resource where clients can publish data and/or subscribe to data for a specific topic. The representation of the topic resource corresponding to such a topic also specifies the URI to the present topic-data resource.</t>
          </dd>
          <dt>broker:</dt>
          <dd>
            <t>A CoAP server that hosts one or more topic collections with their topic-configurations, and possibly also topic-data resources. The broker is responsible for the store-and-forward of state update representations, for the topics for which it hosts the corresponding topic-data resources. The broker is also responsible of handling the topic lifecycle as defined in <xref target="topic-lifecycle"/>. The creation, configuration, and discovery of topics at a broker is specified in <xref target="topics"/>.</t>
          </dd>
        </dl>
      </section>
      <section anchor="coap-publish-subscribe-architecture">
        <name>CoAP Publish-Subscribe Architecture</name>
        <t><xref target="fig-arch"/> shows a simple Publish/Subscribe architecture over CoAP.</t>
        <t>Topics are created by the broker, but the initial configuration can be proposed by a client (e.g., a publisher or a dedicated administrator) over the RESTful interface of a corresponding topic resource hosted by the broker.</t>
        <t>Publishers submit their data over the RESTful interface of a topic-data resource corresponding to the topic, which may be hosted by the broker. Subscribers to a topic are notified of new publications by using Observe <xref target="RFC7641"/> on the corresponding topic-data resource.</t>
        <t>The broker is responsible for the store-and-forward of state update representations between CoAP clients. Subscribers observing a resource will receive notifications, the delivery of which is done on a best-effort basis.</t>
        <figure anchor="fig-arch">
          <name>Publish-subscribe architecture over CoAP</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="272" width="480" viewBox="0 0 480 272" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px" stroke-linecap="round">
                <path d="M 8,64 L 8,128" fill="none" stroke="black"/>
                <path d="M 8,176 L 8,240" fill="none" stroke="black"/>
                <path d="M 104,64 L 104,128" fill="none" stroke="black"/>
                <path d="M 104,176 L 104,240" fill="none" stroke="black"/>
                <path d="M 192,64 L 192,240" fill="none" stroke="black"/>
                <path d="M 280,64 L 280,240" fill="none" stroke="black"/>
                <path d="M 376,64 L 376,128" fill="none" stroke="black"/>
                <path d="M 376,176 L 376,240" fill="none" stroke="black"/>
                <path d="M 472,64 L 472,128" fill="none" stroke="black"/>
                <path d="M 472,176 L 472,240" fill="none" stroke="black"/>
                <path d="M 8,64 L 104,64" fill="none" stroke="black"/>
                <path d="M 192,64 L 280,64" fill="none" stroke="black"/>
                <path d="M 376,64 L 472,64" fill="none" stroke="black"/>
                <path d="M 288,80 L 376,80" fill="none" stroke="black"/>
                <path d="M 104,96 L 184,96" fill="none" stroke="black"/>
                <path d="M 280,96 L 368,96" fill="none" stroke="black"/>
                <path d="M 280,112 L 368,112" fill="none" stroke="black"/>
                <path d="M 8,128 L 104,128" fill="none" stroke="black"/>
                <path d="M 376,128 L 472,128" fill="none" stroke="black"/>
                <path d="M 8,176 L 104,176" fill="none" stroke="black"/>
                <path d="M 376,176 L 472,176" fill="none" stroke="black"/>
                <path d="M 288,192 L 376,192" fill="none" stroke="black"/>
                <path d="M 104,208 L 184,208" fill="none" stroke="black"/>
                <path d="M 280,208 L 368,208" fill="none" stroke="black"/>
                <path d="M 280,224 L 368,224" fill="none" stroke="black"/>
                <path d="M 8,240 L 104,240" fill="none" stroke="black"/>
                <path d="M 192,240 L 280,240" fill="none" stroke="black"/>
                <path d="M 376,240 L 472,240" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="376,224 364,218.4 364,229.6" fill="black" transform="rotate(0,368,224)"/>
                <polygon class="arrowhead" points="376,208 364,202.4 364,213.6" fill="black" transform="rotate(0,368,208)"/>
                <polygon class="arrowhead" points="376,112 364,106.4 364,117.6" fill="black" transform="rotate(0,368,112)"/>
                <polygon class="arrowhead" points="376,96 364,90.4 364,101.6" fill="black" transform="rotate(0,368,96)"/>
                <polygon class="arrowhead" points="296,192 284,186.4 284,197.6" fill="black" transform="rotate(180,288,192)"/>
                <polygon class="arrowhead" points="296,80 284,74.4 284,85.6" fill="black" transform="rotate(180,288,80)"/>
                <polygon class="arrowhead" points="192,208 180,202.4 180,213.6" fill="black" transform="rotate(0,184,208)"/>
                <polygon class="arrowhead" points="192,96 180,90.4 180,101.6" fill="black" transform="rotate(0,184,96)"/>
                <g class="text">
                  <text x="36" y="36">CoAP</text>
                  <text x="244" y="36">CoAP</text>
                  <text x="412" y="36">CoAP</text>
                  <text x="48" y="52">clients</text>
                  <text x="244" y="52">server</text>
                  <text x="424" y="52">clients</text>
                  <text x="328" y="68">observe</text>
                  <text x="144" y="84">publish</text>
                  <text x="56" y="100">publisher</text>
                  <text x="424" y="100">subscribe</text>
                  <text x="56" y="148">...</text>
                  <text x="236" y="148">broker</text>
                  <text x="424" y="148">...</text>
                  <text x="56" y="164">...</text>
                  <text x="424" y="164">...</text>
                  <text x="328" y="180">observe</text>
                  <text x="144" y="196">publish</text>
                  <text x="56" y="212">publisher</text>
                  <text x="424" y="212">subscribe</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
     CoAP                      CoAP                 CoAP
     clients                  server                clients
   .-----------.          .----------.  observe  .-----------.
   |           | publish  |          |<----------+           |
   | publisher +--------->+          +---------->| subscribe |
   |           |          |          +---------->|           |
   '-----------'          |          |           '-----------'
        ...               |  broker  |                ...
        ...               |          |                ...
   .-----------.          |          |  observe  .-----------.
   |           | publish  |          |<----------+           |
   | publisher +--------->|          +---------->| subscribe |
   |           |          |          +---------->|           |
   '-----------'          '----------'           '-----------'
]]></artwork>
          </artset>
        </figure>
        <t>This document describes two sets of interactions, interactions to configure topics and their lifecycle (see <xref target="topic-configuration-interactions"/>) and interactions about the topic-data (see <xref target="topic-data-interactions"/>).</t>
        <t>Topic-configuration interactions are discovery, create, read configuration, update configuration, delete configuration and handle the management of the topics.</t>
        <t>Topic-data interactions are publish, subscribe, unsubscribe, read and delete, these operations are oriented on how data is transferred from a publisher to a subscriber.</t>
        <!--
Throughout the document there is a number of TBDs that need updating, mostly content formats or cbor data representations
-->

</section>
      <section anchor="managing-topics">
        <name>Managing Topics</name>
        <t><xref target="fig-api"/> shows the resources related to a Topic Collection that can be managed at the Broker.</t>
        <figure anchor="fig-api">
          <name>Resources of a Broker</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="176" width="496" viewBox="0 0 496 176" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px" stroke-linecap="round">
                <path d="M 92,56 L 100,72" fill="none" stroke="black"/>
                <path d="M 148,136 L 156,152" fill="none" stroke="black"/>
                <path d="M 136,80 L 156,120" fill="none" stroke="black"/>
                <path d="M 124,40 L 132,56" fill="none" stroke="black"/>
                <path d="M 180,120 L 188,136" fill="none" stroke="black"/>
                <path d="M 212,136 L 220,152" fill="none" stroke="black"/>
                <path d="M 212,104 L 220,120" fill="none" stroke="black"/>
                <path d="M 244,120 L 252,136" fill="none" stroke="black"/>
                <path d="M 308,136 L 316,152" fill="none" stroke="black"/>
                <path d="M 308,104 L 316,120" fill="none" stroke="black"/>
                <path d="M 340,120 L 348,136" fill="none" stroke="black"/>
                <path d="M 92,56 L 100,40" fill="none" stroke="black"/>
                <path d="M 124,72 L 132,56" fill="none" stroke="black"/>
                <path d="M 148,136 L 156,120" fill="none" stroke="black"/>
                <path d="M 180,152 L 188,136" fill="none" stroke="black"/>
                <path d="M 212,136 L 220,120" fill="none" stroke="black"/>
                <path d="M 244,152 L 252,136" fill="none" stroke="black"/>
                <path d="M 308,136 L 316,120" fill="none" stroke="black"/>
                <path d="M 340,152 L 348,136" fill="none" stroke="black"/>
                <path d="M 100,40 L 124,40" fill="none" stroke="black"/>
                <path d="M 100,72 L 124,72" fill="none" stroke="black"/>
                <path d="M 148,104 L 308,104" fill="none" stroke="black"/>
                <path d="M 156,120 L 180,120" fill="none" stroke="black"/>
                <path d="M 220,120 L 244,120" fill="none" stroke="black"/>
                <path d="M 316,120 L 340,120" fill="none" stroke="black"/>
                <path d="M 156,152 L 180,152" fill="none" stroke="black"/>
                <path d="M 220,152 L 244,152" fill="none" stroke="black"/>
                <path d="M 316,152 L 340,152" fill="none" stroke="black"/>
                <g class="text">
                  <text x="40" y="52">topic</text>
                  <text x="44" y="68">collection</text>
                  <text x="44" y="84">resource</text>
                  <text x="280" y="132">...</text>
                  <text x="392" y="132">topic</text>
                  <text x="456" y="132">resources</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
             ___
   topic    /   \
 collection \___/
  resource       \
                  \____________________
                   \___    \___        \___
                   /   \   /   \  ...  /   \   topic resources
                   \___/   \___/       \___/
]]></artwork>
          </artset>
        </figure>
        <t>The Broker exports one or more topic-collection resources, with resource type "core.ps.coll" defined in <xref target="iana"/> of this document. The interfaces for the topic-collection resource is defined in <xref target="topic-collection-interactions"/>.</t>
        <t>A topic-collection resource can have topic resources as its children resources, with resource type "core.ps.conf".</t>
      </section>
    </section>
    <section anchor="topics">
      <name>Pub-Sub Topics</name>
      <t>The configuration side of a "publish/subscribe broker" consists of a collection of topics. These topics as well as the collection itself are exposed by a CoAP server as resources (see <xref target="fig-topic"/>). Each topic is associated with: a topic resource and a a topic-data resource. The topic resource is used by a client creating or administering a topic. The topic-data resource is used by the publishers and the subscribers to a topic.</t>
      <figure anchor="fig-topic">
        <name>Topic and topic-data resources of a topic</name>
        <artset>
          <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="336" width="448" viewBox="0 0 448 336" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px" stroke-linecap="round">
              <path d="M 184,152 L 184,232" fill="none" stroke="black"/>
              <path d="M 272,152 L 272,232" fill="none" stroke="black"/>
              <path d="M 400,152 L 400,232" fill="none" stroke="black"/>
              <path d="M 164,248 L 172,264" fill="none" stroke="black"/>
              <path d="M 92,56 L 100,72" fill="none" stroke="black"/>
              <path d="M 164,168 L 172,184" fill="none" stroke="black"/>
              <path d="M 196,232 L 204,248" fill="none" stroke="black"/>
              <path d="M 228,280 L 236,296" fill="none" stroke="black"/>
              <path d="M 136,80 L 172,152" fill="none" stroke="black"/>
              <path d="M 124,40 L 132,56" fill="none" stroke="black"/>
              <path d="M 196,152 L 204,168" fill="none" stroke="black"/>
              <path d="M 252,248 L 260,264" fill="none" stroke="black"/>
              <path d="M 252,168 L 260,184" fill="none" stroke="black"/>
              <path d="M 284,232 L 292,248" fill="none" stroke="black"/>
              <path d="M 236,104 L 260,152" fill="none" stroke="black"/>
              <path d="M 284,152 L 292,168" fill="none" stroke="black"/>
              <path d="M 380,248 L 388,264" fill="none" stroke="black"/>
              <path d="M 380,168 L 388,184" fill="none" stroke="black"/>
              <path d="M 412,232 L 420,248" fill="none" stroke="black"/>
              <path d="M 364,104 L 388,152" fill="none" stroke="black"/>
              <path d="M 412,152 L 420,168" fill="none" stroke="black"/>
              <path d="M 92,56 L 100,40" fill="none" stroke="black"/>
              <path d="M 124,72 L 132,56" fill="none" stroke="black"/>
              <path d="M 164,168 L 172,152" fill="none" stroke="black"/>
              <path d="M 164,248 L 172,232" fill="none" stroke="black"/>
              <path d="M 196,184 L 204,168" fill="none" stroke="black"/>
              <path d="M 196,264 L 204,248" fill="none" stroke="black"/>
              <path d="M 252,168 L 260,152" fill="none" stroke="black"/>
              <path d="M 220,296 L 228,280" fill="none" stroke="black"/>
              <path d="M 252,248 L 260,232" fill="none" stroke="black"/>
              <path d="M 284,184 L 292,168" fill="none" stroke="black"/>
              <path d="M 284,264 L 292,248" fill="none" stroke="black"/>
              <path d="M 380,168 L 388,152" fill="none" stroke="black"/>
              <path d="M 380,248 L 388,232" fill="none" stroke="black"/>
              <path d="M 412,184 L 420,168" fill="none" stroke="black"/>
              <path d="M 412,264 L 420,248" fill="none" stroke="black"/>
              <path d="M 100,40 L 124,40" fill="none" stroke="black"/>
              <path d="M 100,72 L 124,72" fill="none" stroke="black"/>
              <path d="M 148,104 L 364,104" fill="none" stroke="black"/>
              <path d="M 172,152 L 196,152" fill="none" stroke="black"/>
              <path d="M 260,152 L 284,152" fill="none" stroke="black"/>
              <path d="M 388,152 L 412,152" fill="none" stroke="black"/>
              <path d="M 172,264 L 196,264" fill="none" stroke="black"/>
              <path d="M 260,264 L 284,264" fill="none" stroke="black"/>
              <path d="M 388,264 L 412,264" fill="none" stroke="black"/>
              <path d="M 148,296 L 220,296" fill="none" stroke="black"/>
              <path d="M 236,296 L 308,296" fill="none" stroke="black"/>
              <path d="M 364,296 L 436,296" fill="none" stroke="black"/>
              <circle cx="184" cy="160" r="6" class="closeddot" fill="black"/>
              <circle cx="272" cy="160" r="6" class="closeddot" fill="black"/>
              <circle cx="400" cy="160" r="6" class="closeddot" fill="black"/>
              <g class="text">
                <text x="40" y="52">topic</text>
                <text x="44" y="68">collection</text>
                <text x="44" y="84">resource</text>
                <text x="196" y="132">......</text>
                <text x="284" y="132">......</text>
                <text x="412" y="132">......</text>
                <text x="112" y="148">topic</text>
                <text x="152" y="148">:</text>
                <text x="216" y="148">:</text>
                <text x="240" y="148">:</text>
                <text x="304" y="148">:</text>
                <text x="368" y="148">:</text>
                <text x="432" y="148">:</text>
                <text x="80" y="164">configuration</text>
                <text x="152" y="164">:</text>
                <text x="216" y="164">:</text>
                <text x="240" y="164">:</text>
                <text x="304" y="164">:</text>
                <text x="368" y="164">:</text>
                <text x="432" y="164">:</text>
                <text x="100" y="180">resource</text>
                <text x="152" y="180">:</text>
                <text x="176" y="180">_</text>
                <text x="192" y="180">_</text>
                <text x="216" y="180">:</text>
                <text x="240" y="180">:</text>
                <text x="264" y="180">_</text>
                <text x="280" y="180">_</text>
                <text x="304" y="180">:</text>
                <text x="368" y="180">:</text>
                <text x="392" y="180">_</text>
                <text x="408" y="180">_</text>
                <text x="432" y="180">:</text>
                <text x="164" y="196">....</text>
                <text x="204" y="196">....</text>
                <text x="252" y="196">....</text>
                <text x="292" y="196">....</text>
                <text x="380" y="196">....</text>
                <text x="420" y="196">....</text>
                <text x="164" y="212">....</text>
                <text x="204" y="212">....</text>
                <text x="252" y="212">....</text>
                <text x="292" y="212">....</text>
                <text x="380" y="212">....</text>
                <text x="420" y="212">....</text>
                <text x="152" y="228">:</text>
                <text x="176" y="228">_</text>
                <text x="192" y="228">_</text>
                <text x="216" y="228">:</text>
                <text x="240" y="228">:</text>
                <text x="264" y="228">_</text>
                <text x="280" y="228">_</text>
                <text x="304" y="228">:</text>
                <text x="336" y="228">...</text>
                <text x="368" y="228">:</text>
                <text x="392" y="228">_</text>
                <text x="408" y="228">_</text>
                <text x="432" y="228">:</text>
                <text x="92" y="244">topic-data</text>
                <text x="152" y="244">:</text>
                <text x="216" y="244">:</text>
                <text x="240" y="244">:</text>
                <text x="304" y="244">:</text>
                <text x="368" y="244">:</text>
                <text x="432" y="244">:</text>
                <text x="100" y="260">resource</text>
                <text x="152" y="260">:</text>
                <text x="216" y="260">:</text>
                <text x="240" y="260">:</text>
                <text x="304" y="260">:</text>
                <text x="368" y="260">:</text>
                <text x="432" y="260">:</text>
                <text x="184" y="276">:.......:</text>
                <text x="272" y="276">:.......:</text>
                <text x="400" y="276">:.......:</text>
                <text x="144" y="292">\</text>
                <text x="312" y="292">/</text>
                <text x="336" y="292">...</text>
                <text x="360" y="292">\</text>
                <text x="440" y="292">/</text>
                <text x="176" y="308">topic</text>
                <text x="208" y="308">1</text>
                <text x="264" y="308">topic</text>
                <text x="296" y="308">2</text>
                <text x="392" y="308">topic</text>
                <text x="424" y="308">n</text>
              </g>
            </svg>
          </artwork>
          <artwork type="ascii-art" align="center"><![CDATA[
              ___
    topic    /   \
  collection \___/
   resource       \
                   \___________________________
                    \          \               \
                     \ ......   \ ......        \ ......
             topic  : \___  :  : \___  :       : \___  :
     configuration  : / * \ :  : / * \ :       : / * \ :
          resource  : \_|_/ :  : \_|_/ :       : \_|_/ :
                    ....|....  ....|....       ....|....
                    ....|....  ....|....       ....|....
                    :  _|_  :  :  _|_  :  ...  :  _|_  :
        topic-data  : /   \ :  : /   \ :       : /   \ :
          resource  : \___/ :  : \___/ :       : \___/ :
                    :.......:  :.......:       :.......:
                   \_________/\_________/ ... \_________/
                     topic 1    topic 2         topic n
]]></artwork>
        </artset>
      </figure>
      <section anchor="collection-representation">
        <name>Collection Representation</name>
        <t>Each topic configuration is represented as a link, where the link target is the URI of the corresponding topic resource.</t>
        <t>Publication and subscription to a topic occur at a link, where the link target is the URI of the corresponding topic-data resource. Such a link is specified by the topic-data entry within the topic resource (see <xref target="topic-properties"/>).</t>
        <t>A topic resource with a topic-data link can also be simply called "topic".</t>
        <t>The list of links to the topic resources can be retrieved from the associated topic collection resource, and represented as a Link Format document <xref target="RFC6690"/>where each such link specifies the link target attribute 'rt' (Resource Type), with value "core.ps.conf" defined in this document.</t>
      </section>
      <section anchor="topic-resource-representation">
        <name>Topic-Configuration Representation</name>
        <t>A CoAP client can create a new topic by submitting an initial configuration for the topic (see <xref target="topic-create"/>). It can also read and update the configuration of existing topics and delete them when they are no longer needed (see <xref target="topic-configuration-interactions"/>).</t>
        <t>The configuration of a topic itself consists of a set of properties that can be set by a client or by the broker. The topic-configuration is represented as a CBOR map containing the configuration properties of the topic as top-level elements.</t>
        <t>Unless specified otherwise, these are defined in this document and their CBOR abbreviations are defined in <xref target="pubsub-parameters"/>.</t>
        <section anchor="topic-properties">
          <name>Topic Properties</name>
          <t>The CBOR map includes the following configuration parameters, whose CBOR abbreviations are defined in <xref target="pubsub-parameters"/> of this document.</t>
          <ul spacing="normal">
            <li>'topic-name': A required field used as an application identifier. It encodes the topic name as a CBOR text string. Examples of topic names include human-readable strings (e.g., "room2"), UUIDs, or other values.</li>
            <li>'topic-data': A required field (optional during creation) containing the URI of the topic-data resource for publishing/subscribing to this topic. It encodes the URI as a CBOR text string.</li>
            <li>'resource-type': A required field used to indicate the resource type of the topic-data resource for the topic. It encodes the resource type as a CBOR text string. The value should be "core.ps.conf".</li>
            <li>'media-type': An optional field used to indicate the media type of the topic-data resource for the topic. It encodes the media type as a this information as the integer identifier of the CoAP content-format (e.g., value is "50" for "application/json").</li>
            <li>'topic-type': An optional field used to indicate the attribute or property of the topic-data resource for the topic. It encodes the attribute as a CBOR text string. Example attributes include "temperature".</li>
            <li>'expiration-date': An optional field used to indicate the expiration date of the topic. It encodes the expiration date as a CBOR text string. The value should be a date string in ISO 8601 format (e.g., "2023-03-31T23:59:59Z"). The broker can use this field to automatically remove topics that are no longer valid. If this field is not present, the topic will not expire automatically.</li>
            <li>'max-subscribers': An optional field used to indicate the maximum number of simultaneous subscribers allowed for the topic. It encodes the maximum number as an unsigned CBOR integer. If this field is not present, there is no limit to the number of simultaneous subscribers allowed. The broker can use this field to limit the number of subscribers for the topic.</li>
            <li>'observer-check': An optional field that controls the maximum number of seconds between two consecutive Observe notifications sent as Confirmable messages to each topic subscriber. Encoded as a CBOR unsigned integer greater than 0, it ensures subscribers who have lost interest and silently forgotten the observation do not remain indefinitely on the server's observer list. If another CoAP server hosts the topic-data resource, that server is responsible for applying the observer-check value. The default value for this field is 86400, as defined in <xref target="RFC7641"/>, which corresponds to 24 hours.</li>
          </ul>
        </section>
      </section>
      <section anchor="discovery">
        <name>Discovery</name>
        <t>A client can perform a discovery of: the broker; the topic collection resources and topic resources hosted by the broker; and the topic-data resources associated with those topic resources.</t>
        <section anchor="broker-discovery">
          <name>Broker Discovery</name>
          <t>CoAP clients MAY discover brokers by using CoAP Simple Discovery, via multicast, through a Resource Directory (RD) <xref target="RFC9176"/> or by other means specified in extensions to <xref target="RFC7252"/>. Brokers MAY register with a RD by following the steps on Section 5 of <xref target="RFC9176"/> with the resource type set to "core.ps" as defined in <xref target="iana"/> of this document.</t>
          <t>The following example shows an endpoint discovering a broker using the "core.ps" resource type over a multicast network. Brokers within the multicast scope will answer the query.</t>
          <artwork><![CDATA[
=> 0.01 GET
   Uri-Path: coap://[ff0x::fe]/.well-known/core
   Resource-Type: core.ps

<= 2.05 Content
   Payload:
   Content-Format: 40 (application/link-format)
   <coap://mythinguri.com/broker/v1>; rt=core.ps
]]></artwork>
        </section>
        <section anchor="topic-collection-discovery">
          <name>Topic Collection Discovery</name>
          <t>A Broker SHOULD offer a topic discovery entry point to enable clients to find topics of interest. The resource entry point is the topic collection resource collecting the topic configurations for those topics (see Section 1.2.2 of <xref target="RFC6690"/>) and is identified by the resource type "core.ps.coll".</t>
          <t>The specific resource path is left for implementations, examples in this document use the "/ps" path. The interactions with a topic collection are further defined in <xref target="topic-collection-interactions"/>.</t>
          <t>Since the representation of the topic collection resource includes the links to the associated topic resources, it is not required to locate those links under "/.well-known/core", also in order to limit the size of the Link Format document returned as result of the discovery.</t>
          <t>Example:</t>
          <artwork><![CDATA[
=> 0.01 GET
   Uri-Path: .well-known/core
   Resource-Type: core.ps.coll

   <= 2.05 Content
   Content-Format: 40 (application/link-format)
   </ps1>;rt="core.ps.coll";ct=40,
   </other/path>;rt="core.ps.coll";ct=40
]]></artwork>
        </section>
        <section anchor="topic-discovery">
          <name>Topic-Configuration Discovery</name>
          <t>Each topic collection is associated with a group of topic resources, each detailing the configuration of its respective topic (refer to <xref target="topic-properties"/>). Each topic resource is identified by the resource type "core.ps.conf".</t>
          <t>Below is an example of discovery via /.well-known/core with rt=core.ps.conf that returns a list of topics, as the list of links to the corresponding topic resources.</t>
          <!--
TODO: add the ct part in IANA and add the example here:
- If you want to indicate ct= in one of this links, then it should be ct=X, where is the the Content-Format identifier for application/pubsub+cbor
-->

<artwork><![CDATA[
=> 0.01 GET
   Uri-Path: .well-known/core
   Resource-Type: core.ps.conf

<= 2.05 Content
   Content-Format: 40 (application/link-format)
   </ps1/h9392>;rt="core.ps.conf";ct=TBD,
   </other/path/2e3570>;rt=core.ps.conf;ct=TBD
]]></artwork>
        </section>
        <section anchor="topic-data-discovery">
          <name>Topic-Data Discovery</name>
          <!--
TODO DISCUSS Decide on this section

   Also, as based on Section 1.2.2 of RFC 6690, I'd realistically expect to have located by /.well-known/core certainly the topic collection resources and MAYBE the topic resources (and likely limited only to "perpetual", hence well-known topics).

   Instead, I'd expect to discover the links to the topic resources mostly by GET/FETCH accessing the topic collection resource.

   Practically, you may have to literally *discover* the broker, its collection resource, and a particular topic resource. At that point, you just *learn* the URI of the topic-data resource, from the corresponding parameter within the exact, corresponding topic resource.
-->

<t>Within a topic, there is the topic-data property containing the URI of the topic-data resource that a CoAP client can subscribe and publish to. Resources exposing resources of the topic-data type are expected to use the resource type 'core.ps.data'.</t>
          <t>The topic-data contains the URI of the topic-data resource for publishing and subscribing. So retrieving the topic configuration will also provide the URL of the topic-data (see <xref target="topic-get-resource"/>).</t>
          <t>It is also possible to discover a list of topic-data resources by sending a request to the collection with with rt=core.ps.data resources as shown below.</t>
          <artwork><![CDATA[
=> 0.01 GET
   Uri-Path: /ps
   Resource-Type: core.ps.data

<= 2.05 Content
   Content-Format: 40 (application/link-format)
   </ps/data/62e4f8d>; rt=core.ps.data; obs
]]></artwork>
        </section>
      </section>
      <section anchor="topic-collection-interactions">
        <name>Topic Collection Interactions</name>
        <t>These are the interactions that can happen directly with a specific topic collection.</t>
        <section anchor="topic-get-all">
          <name>Retrieving all topic-configurations</name>
          <t>A client can request a collection of the topics present in the broker by making a GET request to the collection URI.</t>
          <t>On success, the server returns a 2.05 (Content) response, specifying the list of links to topic resources associated with this topic collection (see  <xref target="topic-resource-representation"/>).</t>
          <t>Depending on its granted permissions, a client MAY retrieve a different list of links, corresponding to the topics that the client is authorized to access.</t>
          <t>Example:</t>
          <artwork><![CDATA[
=> 0.01 GET
   Uri-Path: ps

<= 2.05 Content
   Content-Format: 40 (application/link-format)
   </ps/h9392>;rt="core.ps.conf",
   </ps/2e3570>; rt="core.ps.conf"
]]></artwork>
        </section>
        <section anchor="topic-get-properties">
          <name>Getting topic-configurations by Properties</name>
          <!--
FETCH to /topic-collection with filter
retrieve only the topics that match the filter
request is cbor
response is link format
-->

<t>A client can filter a collection of topics by submitting the
representation of a topic filter (see  <xref target="topic-fetch-resource"/>) in a FETCH request to the topic collection URI.</t>
          <t>On success, the server returns a 2.05 (Content) response with a
representation of a list of topics in the collection (see
 <xref target="topic-discovery"/>) that match the filter in CoRE link format <xref target="RFC6690"/>.</t>
          <t>Upon success, the server responds with a 2.05 (Content), providing a list of links to topic resources associated with this topic collection that match the request's filter criteria (refer to  <xref target="topic-discovery"/>). A positive match happens only when each request parameter is present with the indicated value in the topic resource representation.</t>
          <t>Example:</t>
          <artwork><![CDATA[
=> 0.05 FETCH
   Uri-Path: ps
   Content-Format: TBD (application/pubsub+cbor)

   {
     "resource-type" : "core.ps.conf"
     "topic-type" : "temperature"
   }

<= 2.05 Content
   Content-Format: 40 (application/link-format)
   </ps/2e3570>;rt="core.ps.conf"
]]></artwork>
        </section>
        <section anchor="topic-create">
          <name>Creating a Topic</name>
          <!--
POST to /topic-collection
create new topic
request is cbor
response (created) is cbor including the link to new topic-config resource
creator proposes topic name but broker approves
-->

<t>A client can add a new topic-configurations to a collection of topics by submitting an initial representation of the initial topic resource (see  <xref target="topic-resource-representation"/>) in a POST request to the topic collection URI. The request MUST specify at least a subset of the properties in  <xref target="topic-properties"/>, namely: topic-name and resource-type.</t>
          <!--
   TODO Next two paragraphs are thorny
   Also, as above, the topic-data resource may not even hosted at the broker, which only knows the link to that resource. It is up to the actual, responsible host to "assign" a topic-data resource (i.e., associate it with a URI to store within the topic resource at the broker), without even creating the resource yet.

   Removed

A CoAP endpoint creating a topic MAY specify a topic-data URI when the topic-data resource is not hosted by the broker.
-->

<t>Please note that the topic will NOT be fully created until a publisher has published some data to it (See <xref target="topic-lifecycle"/>).</t>
          <t>On success, the server returns a 2.01 (Created) response, indicating the Location-Path of the new topic and the current representation of the topic resource. The response payload includes a CBOR map with key-value pairs. The response must include the required topic properties (see <xref target="topic-properties"/>), namely: "topic-name", "resource-type" and "topic-data". It may also include a number of optional properties too.</t>
          <t>If requirements are defined for the client to create the topic as requested and the broker does not successfully assess that those requirements are met, then the broker MUST respond with a 4.03 (Forbidden) error. The response MUST have Content-Format set to "application/core-pubsub+cbor".</t>
          <t>The broker MUST issue a 4.00 (Bad Request) error if a received parameter is invalid, unrecognized, or if the topic-name is already in use or otherwise invalid.</t>
          <!--
   TODO Regardless, what if the topic-name is already in use or not fine for other reasons? Is the broker going to use and return a new one that fits?
-->

<artwork><![CDATA[
=> 0.02 POST
   Uri-Path: ps
   Content-Format: TBD2 (application/core-pubsub+cbor)
   TBD (this should be a CBOR map with the mandatory parameters)
   {
     "topic-name" : "living-room-sensor"
     "resource-type" : "core.ps.conf"
   }

<= 2.01 Created
   Location-Path: ps/h9392
   Content-Format: TBD2 (application/core-pubsub+cbor)

   TBD (this should be a CBOR map)
   {
     "topic-name" : "living-room-sensor",
     "topic-data" : "ps/data/1bd0d6d"
     "resource-type" : "core.ps.conf"
   }
]]></artwork>
        </section>
      </section>
      <section anchor="topic-configuration-interactions">
        <name>Topic-Configuration Interactions</name>
        <t>These are the interactions that can happen at the topic resource level.</t>
        <section anchor="topic-get-resource">
          <name>Getting a topic-configuration</name>
          <!--
GET to /topic-config
retrieve a topic configuration
response is cbor
-->

<t>A client can read the configuration of a topic by making a GET request to the topic resource URI.</t>
          <t>On success, the server returns a 2.05 (Content) response with a partial representation of the topic resource, as specified in <xref target="topic-resource-representation"/>. The partial representation includes only the configuration parameters such that they are present and have the same value in both the current topic configuration as well as in the FETCH request.</t>
          <t>If requirements are defined for the client to create the topic as requested and the broker does not successfully assess that those requirements are met, then the broker MUST respond with a 4.03 (Forbidden) error.</t>
          <t>The response payload is a CBOR map, whose possible entries are specified in <xref target="topic-resource-representation"/> and use the same abbreviations defined in <xref target="pubsub-parameters"/>.</t>
          <t>For example, below is a request on the topic "ps/h9392":</t>
          <artwork><![CDATA[
=> 0.01 GET
   Uri-Path: ps
   Uri-Path: h9392

<= 2.05 Content
   Content-Format: TBD2 (application/core-pubsub+cbor)
   {
      "topic-name" : "living-room-sensor",
      "topic-data" : "ps/data/1bd0d6d",
      "resource-type": "core.ps.conf",
      "media-type": "application/senml-cbor",
      "topic-type": "temperature",
      "expiration-date": "2023-04-00T23:59:59Z",
      "max-subscribers": 100
   }

]]></artwork>
        </section>
        <section anchor="topic-fetch-resource">
          <name>Getting part of a topic-configuration</name>
          <!--
FETCH to /topic-conf with filter
retrieve only certain parameters from the configuration
request is cbor
response is cbor
-->

<t>A client can read the configuration of a topic by making a FETCH request to the topic resource URI with a filter for specific parameters. This is done in order to retrieve part of the current topic resource.</t>
          <t>The request contains a CBOR map with a configuration filter or 'conf-filter', a CBOR array with CBOR abbreviation. Each element of the array specifies one requested configuration parameter of the current topic resource (see <xref target="topic-resource-representation"/>).</t>
          <t>On success, the server returns a 2.05 (Content) response with a representation of the topic resource. The response has as payload the partial representation of the topic resource as specified in <xref target="topic-resource-representation"/>.</t>
          <t>If requirements are defined for the client to create the topic as requested and the broker does not successfully assess that those requirements are met, then the broker MUST respond with a 4.03 (Forbidden) error.</t>
          <t>The response payload is a CBOR map, whose possible entries are specified in <xref target="topic-resource-representation"/> and use the same abbreviations defined in <xref target="pubsub-parameters"/>.</t>
          <t>Both request and response MUST have Content-Format set to "application/core-pubsub+cbor".</t>
          <t>Example:</t>
          <artwork><![CDATA[
=> 0.05 FETCH
   Uri-Path: ps
   Uri-Path: h9392
   Content-Format: TBD2 (application/core-pubsub+cbor)
   {
     "conf-filter" : [topic-data, media-type]
   }

<= 2.05 Content
   Content-Format: TBD2 (application/core-pubsub+cbor)
   {
     "topic-data" : "ps/data/1bd0d6d",
     "media-type": "application/senml-cbor"
   }

]]></artwork>
        </section>
        <section anchor="topic-update-resource">
          <name>Updating the topic-configuration</name>
          <!--
PUT to /topic-conf
override the whole configuration
request is cbor
response is cbor
-->

<t>A client can update a topic's configuration by submitting the updated topic representation in a PUT request to the topic URI. However, the parameters "topic-name", "topic-data", and "resource-type" are immutable post-creation, and any request attempting to change them will be deemed invalid by the broker.</t>
          <t>On success, the server returns a 2.04 (Changed) response and the current full resource representation. The broker may chose not to overwrite parameters that are not explicitly modified in the request.</t>
          <t>Note that updating the "topic-data" path will automatically cancel all existing observations on it and thus will unsubscribe all subscribers. Similarly, decreasing max-subscribers will also cause that some subscribers get unsubscribed. Unsubscribed endpoints SHOULD receive a final 4.04 (Not Found) response as per <xref target="RFC7641"/> Section 3.2.</t>
          <t>Example:</t>
          <artwork><![CDATA[
=> 0.03 PUT
   Uri-Path: ps
   Uri-Path: h9392
   Content-Format: TBD2 (application/core-pubsub+cbor)

   {
      "topic-name" : "living-room-sensor",
      "topic-data" : "ps/data/1bd0d6d",
      "topic-type": "temperature",
      "expiration-date": "2023-04-28T23:59:59Z",
      "max-subscribers": 2
   }

<= 2.04 Changed
   Content-Format: TBD2 (application/core-pubsub+cbor)

   TBD (this should be a CBOR map)
   {
      "topic-name" : "living-room-sensor",
      "topic-data" : "ps/data/1bd0d6d",
      "resource-type": "core.ps.conf",
      "media-type": "application/senml-cbor",
      "topic-type": "temperature",
      "expiration-date": "2023-04-28T23:59:59Z",
      "max-subscribers": 2
   }
]]></artwork>
          <t>Note that when a topic configuration changes, it may result in disruptions for the subscribers. Some potential issues that may arise include:</t>
          <ul spacing="normal">
            <li>Limiting the number of subscribers will cause to cancel ongoing subscriptions until max-subscribers has been reached.</li>
            <li>Changing the topic-data value will cancel all ongoing subscriptions.</li>
            <li>Changing of the expiration-date may cause to cancel ongoing subscriptions if the topic expires at an earlier data.</li>
          </ul>
        </section>
        <section anchor="topic-delete">
          <name>Deleting a topic-configuration</name>
          <t>A client can delete a topic by making a CoAP DELETE request on the topic resource URI.</t>
          <t>On success, the server returns a 2.02 (Deleted) response.</t>
          <t>When a topic-configuration resource is deleted, the broker MUST also delete the topic-data resource, unsubscribe all subscribers by removing them from the list of observers and returning a final 4.04 (Not Found) response as per section 3.2 of <xref target="RFC7641"/>.</t>
          <t>Example:</t>
          <artwork><![CDATA[
=> 0.04 DELETE
   Uri-Path: ps
   Uri-Path: h9392

<= 2.02 Deleted
]]></artwork>
        </section>
      </section>
    </section>
    <section anchor="pubsub">
      <name>Publish and Subscribe</name>
      <t>The overview of the publish/subscribe mechanism over CoAP is as follows: a publisher publishes to a topic by submitting the data in a PUT request to a topic-data resource and subscribers subscribe to a topic by submitting a GET request with Observe option set to 0 (register) to a topic-data resource. When resource state changes, subscribers observing the resource <xref target="RFC7641"/> at that time will receive a notification.</t>
      <t>A topic-data resource does not exist until some initial data has been published to it. Before initial data publication, a GET request to the topic-data resource URI results in a 4.04 (Not Found) response. If such a "half created" topic is undesired, the creator of the topic can simply immediately publish some initial placeholder data to make the topic "fully created" (see <xref target="topic-lifecycle"/>).</t>
      <!--
* "URIs for topic-data MAY be broker-generated or client-generated."

   See a comment above. I think that only the host of the topic-data resource should be in control of generating this URI (to be provided to the broker if that host is not the broker already).
-->

<t>URIs for topic resources are broker-generated (see <xref target="topic-create"/>). There is no necessary URI pattern dependence between the URI where the topic-data exists and the URI of the topic-configuration resource.</t>
      <section anchor="topic-lifecycle">
        <name>Topic Lifecycle</name>
        <t>When a topic is newly created, it is first placed by the broker into the HALF CREATED state (see <xref target="fig-life"/>). In this state, a client can read and update the configuration of the topic and delete the topic. A publisher can publish to the topic-data resource.  However, a subscriber cannot yet subscribe to the topic-data resource nor read the latest data.</t>
        <!--
TODO I got a comment that mqtt folks my want to pre-subscribe to topics, so they'd like to be able to place an observation even if the resource is not "fully created"

Also, we might want to restrict the discovery part ONLY for FULLY created topics. If so, let's mention it.
-->

<figure anchor="fig-life">
          <name>Lifecycle of a Topic</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="224" width="544" viewBox="0 0 544 224" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px" stroke-linecap="round">
                <path d="M 128,72 L 128,120" fill="none" stroke="black"/>
                <path d="M 128,144 L 128,176" fill="none" stroke="black"/>
                <path d="M 160,144 L 160,176" fill="none" stroke="black"/>
                <path d="M 168,72 L 168,120" fill="none" stroke="black"/>
                <path d="M 248,152 L 248,184" fill="none" stroke="black"/>
                <path d="M 280,152 L 280,184" fill="none" stroke="black"/>
                <path d="M 368,72 L 368,120" fill="none" stroke="black"/>
                <path d="M 368,144 L 368,176" fill="none" stroke="black"/>
                <path d="M 400,144 L 400,176" fill="none" stroke="black"/>
                <path d="M 408,72 L 408,120" fill="none" stroke="black"/>
                <path d="M 8,80 L 104,80" fill="none" stroke="black"/>
                <path d="M 192,80 L 344,80" fill="none" stroke="black"/>
                <path d="M 432,80 L 520,80" fill="none" stroke="black"/>
                <path d="M 192,112 L 344,112" fill="none" stroke="black"/>
                <path d="M 432,112 L 520,112" fill="none" stroke="black"/>
                <path d="M 200,160 L 224,160" fill="none" stroke="black"/>
                <path d="M 304,160 L 328,160" fill="none" stroke="black"/>
                <path d="M 184,128 L 200,160" fill="none" stroke="black"/>
                <path d="M 328,160 L 344,128" fill="none" stroke="black"/>
                <path d="M 520,80 C 528.83064,80 536,87.16936 536,96" fill="none" stroke="black"/>
                <path d="M 520,112 C 528.83064,112 536,104.83064 536,96" fill="none" stroke="black"/>
                <path d="M 144,192 C 135.16936,192 128,184.83064 128,176" fill="none" stroke="black"/>
                <path d="M 144,192 C 152.83064,192 160,184.83064 160,176" fill="none" stroke="black"/>
                <path d="M 384,192 C 375.16936,192 368,184.83064 368,176" fill="none" stroke="black"/>
                <path d="M 384,192 C 392.83064,192 400,184.83064 400,176" fill="none" stroke="black"/>
                <path d="M 128,72 L 168,72" fill="none" stroke="black"/>
                <path d="M 368,72 L 408,72" fill="none" stroke="black"/>
                <path d="M 128,120 L 168,120" fill="none" stroke="black"/>
                <path d="M 368,120 L 408,120" fill="none" stroke="black"/>
                <path d="M 248,152 L 280,152" fill="none" stroke="black"/>
                <path d="M 248,184 L 280,184" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="440,112 428,106.4 428,117.6" fill="black" transform="rotate(180,432,112)"/>
                <polygon class="arrowhead" points="408,144 396,138.4 396,149.6" fill="black" transform="rotate(270,400,144)"/>
                <polygon class="arrowhead" points="352,112 340,106.4 340,117.6" fill="black" transform="rotate(0,344,112)"/>
                <polygon class="arrowhead" points="312,160 300,154.4 300,165.6" fill="black" transform="rotate(180,304,160)"/>
                <polygon class="arrowhead" points="232,160 220,154.4 220,165.6" fill="black" transform="rotate(0,224,160)"/>
                <polygon class="arrowhead" points="200,80 188,74.4 188,85.6" fill="black" transform="rotate(180,192,80)"/>
                <polygon class="arrowhead" points="168,144 156,138.4 156,149.6" fill="black" transform="rotate(270,160,144)"/>
                <polygon class="arrowhead" points="112,80 100,74.4 100,85.6" fill="black" transform="rotate(0,104,80)"/>
                <g class="text">
                  <text x="148" y="36">HALF</text>
                  <text x="392" y="36">FULLY</text>
                  <text x="152" y="52">CREATED</text>
                  <text x="260" y="52">Delete</text>
                  <text x="392" y="52">CREATED</text>
                  <text x="268" y="68">topic-data</text>
                  <text x="472" y="68">Publish</text>
                  <text x="52" y="100">Create</text>
                  <text x="264" y="132">Publish</text>
                  <text x="480" y="132">Subscribe</text>
                  <text x="96" y="164">Read/</text>
                  <text x="432" y="164">Read/</text>
                  <text x="92" y="180">Update</text>
                  <text x="204" y="180">Delete</text>
                  <text x="324" y="180">Delete</text>
                  <text x="436" y="180">Update</text>
                  <text x="200" y="196">Topic</text>
                  <text x="320" y="196">Topic</text>
                  <text x="264" y="212">DELETED</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
                HALF                          FULLY
               CREATED       Delete          CREATED
                ____        topic-data        ____     Publish
------------>  |    |  <-------------------  |    |  ------------.
   Create      |    |                        |    |               |
               |____|  ------------------->  |____|  <-----------'
                      \      Publish      /            Subscribe
               |   ^   \       ___       /   |   ^
         Read/ |   |    '-->  |   |  <--'    |   | Read/
        Update |   |  Delete  |___|  Delete  |   | Update
                '-'   Topic          Topic    '-'
                             DELETED
]]></artwork>
          </artset>
        </figure>
        <t>After a publisher publishes to the topic-data for the first time, the topic is placed into the FULLY CREATED state. In this state, a client can read data by means of a GET request without observe. A publisher can publish to the topic-data resource and a subscriber can observe the topic-data resource.</t>
        <!--
* "When a client deletes a topic-configuration resource, the topic is placed into the DELETED state and shortly after removed from the server."

   Isn't the topic supposed to move back to HALF CREATED (see also Section 3.2.4)? In that case, a follow-up PUT request would bring the topic back to FULLY CREATED (as long as the topic resource at the broker has not been deleted in the first place).

JJ: No, the topic-data sends you to half created but deleting the topic-configuration resource is deleting the topic.

   About "removed from the server", it means simply deleting the topic-data resource, right?

JJ: for topic-data yes.

-->

<t>When a client deletes a topic-configuration resource, the topic is placed into the DELETED state and shortly after removed from the server. In this state, all subscribers are removed from the list of observers of the topic-data resource and no further interactions with the topic are possible.</t>
        <t>When a client deletes a topic-data, the topic is placed into the HALF CREATED state, where clients can read, update and delete the topic-configuration and await for a publisher to begin publication.</t>
      </section>
      <section anchor="topic-data-interactions">
        <name>Topic-Data Interactions</name>
        <!--
TODO: Should we remove this
   See comments above. I'm not sure whether the client should have any say on where the topic-data resource is hosted.

   It'd already be difficult to have some sort of coordination between the broker and the separate server hosting the topic-data resource, let alone involving the client as yet another actor in the process.

JJ: Also note that the broker has no way to know anything about a topic-data hosted elsewhere.
-->

<t>Interactions with the topic-data resource are covered in this section.</t>
        <section anchor="publish">
          <name>Publish</name>
          <t>A topic-configuration with a topic-data resource must have been created in order to publish data to it (See <xref target="topic-create"/>) and be in the half-created or fully-created state in order to the publish operation to work (see <xref target="topic-lifecycle"/>).</t>
          <t>A client can publish data to a topic by submitting the data in a PUT request to the topic-data URI as indicated in its topic resource property. Please note that the topic-data URI is not the same as the topic-configuration URI used for configuring the topic (see <xref target="topic-resource-representation"/>).</t>
          <t>On success, the server returns a 2.04 (Updated) response. However, when data is published to the topic for the first time, the server instead MUST return a 2.01 (Created) response and set the topic in the fully-created state (see <xref target="topic-lifecycle"/>).</t>
          <t>If the request does not have an acceptable content-format, the server returns a 4.15 (Unsupported Content-Format) response.</t>
          <t>If the client is sending publications too fast, the server returns a
4.29 (Too Many Requests) response <xref target="RFC8516"/>.</t>
          <t>Example of first publication:</t>
          <artwork><![CDATA[
=> 0.03 PUT
   Uri-Path: ps
   Uri-Path: data
   Uri-Path: 1bd0d6d
   Content-Format: 110

   {
      "n": "temperature",
      "u": "Cel",
      "t": 1621452122,
      "v": 23.5
   }

<= 2.01 Created
]]></artwork>
          <t>Example of subsequent publication:</t>
          <artwork><![CDATA[
=> 0.03 PUT
   Uri-Path: ps
   Uri-Path: data
   Uri-Path: 1bd0d6d
   Content-Format: 110

   {
      "n": "temperature",
      "u": "Cel",
      "t": 182734122,
      "v": 22.5
   }

<= 2.04 Updated
]]></artwork>
        </section>
        <section anchor="subscribe">
          <name>Subscribe</name>
          <t>A client can subscribe to a topic-data by sending a CoAP GET request with the Observe set to 0 to subscribe to resource updates. <xref target="RFC7641"/>.</t>
          <t>On success, the server hosting the topic-data resource MUST return 2.05 (Content) notifications with the data and the Observe Option. Otherwise, if no Observe Option is present the client should assume that the subscription was not successful.</t>
          <t>If the topic is not yet in the fully created state (see <xref target="topic-lifecycle"/>) the broker SHOULD return a response code 4.04 (Not Found).</t>
          <!--
TODO: After a publisher publishes to the topic-data for the first time, the topic is placed into the FULLY CREATED state.

This is a problem if the topic-data is hosted elsewhere and not in the broker, how does the broker know when to put it in fully created state if the pub/sub mechanism is happening directly btw pub and sub?

Shall I add: The topic-data URI may link to resources that are not hosted directly by the broker as shown in {{fig-external-server}}. Thus subscribers would use the broker for discovery only.
-->

<t>The following response codes are defined for the Subscribe operation:</t>
          <dl>
            <dt>Success:</dt>
            <dd>
              <t>2.05 "Content". Successful subscribe with observe response, current value included in the response.</t>
            </dd>
            <dt>Failure:</dt>
            <dd>
              <t>4.04 "Not Found". The topic-data does not exist.</t>
            </dd>
          </dl>
          <t>If the 'max-subscribers' parameter has been reached, the server must treat that as specified in section 4.1 of <xref target="RFC7641"/>. The response MUST NOT include an Observe Option, the absence of which signals to the subscriber that the subscription failed.</t>
          <!--
TODO Right. However, how can this work when the server hosting the topic-data resource is not the broker? The broker knows the maximum number of subscribers, but that separate server does not. Is it just up to a not-specified-here synchronization protocol between the broker and that server?
-->

<t>Example:</t>
          <artwork><![CDATA[
=> 0.01 GET
   Uri-Path: ps
   Uri-Path: data
   Uri-Path: 1bd0d6d
   Observe: 0

<= 2.05 Content
   Content-Format: 110
   Observe: 10001
   Max-Age: 15

  {
    "bn": "urn:dev:os:193-iot/sparrow/jorvas/",
    "n": "Raitis-lampotila",
    "u": "Cel",
    "t": 1696340182,
    "v": 19.87
  }

<= 2.05 Content
   Content-Format: 110
   Observe: 10002
   Max-Age: 15

  {
    "bn": "urn:dev:os:193-iot/sparrow/jorvas/",
    "n": "Raitis-lampotila",
    "u": "Cel",
    "t": 1696340182,
    "v": 21.87
  }
]]></artwork>
        </section>
        <section anchor="unsubscribe">
          <name>Unsubscribe</name>
          <t>A CoAP client can unsubscribe simply by cancelling the observation as described in Section 3.6 of <xref target="RFC7641"/>. The client MUST either use CoAP GET with the Observe Option set to 1 or send a CoAP Reset message in response to a notification. Also on Section 3.6 of <xref target="RFC7641"/> the client can simply "forget" the observation and the server will remove it from the list of observers after the next notification.</t>
          <t>As per <xref target="RFC7641"/> a server that transmits notifications mostly in non-confirmable messages, but it MUST send a notification in a confirmable message instead of a non-confirmable message at least every 24 hours.</t>
          <t>This value can be modified at the broker by the administrator of a topic by modifying the parameter "observer-check" on <xref target="topic-resource-representation"/>. This would allow to change the rate at which different implementations verify that a subscriber is still interested in observing a topic-data resource.</t>
          <!--
TODO: another item that points to make topic-data a broker thing only.

   Yes, and again, what if the topic-data resource is not hosted at the broker but at a different server? Is it just up to a not-specified-here synchronization protocol between the broker and that server?
-->

</section>
        <section anchor="delete-topic-data">
          <name>Delete topic-data</name>
          <t>A publisher MAY delete a topic by making a CoAP DELETE request on the topic-data URI.</t>
          <t>On success, the server returns a 2.02 (Deleted) response.</t>
          <t>When a topic-data resource is deleted, the broker SHOULD also delete the topic-data parameter in the topic resource, unsubscribe all subscribers by removing them from the list of observers and return a final 4.04 (Not Found) response as per <xref target="RFC7641"/> Section 3.2. The topic is then set back to the half created state as per <xref target="topic-lifecycle"/>.</t>
          <t>Example:</t>
          <artwork><![CDATA[
=> 0.04 DELETE
   Uri-Path: ps
   Uri-Path: data
   Uri-Path: 1bd0d6d

<= 2.02 Deleted
]]></artwork>
        </section>
      </section>
      <section anchor="read-data">
        <name>Read latest data</name>
        <t>A client can get the latest published topic-data by making a GET request to the topic-data URI in the broker. Please note that discovery of the topic-data parameter is a required previous step (see <xref target="topic-get-resource"/>).</t>
        <t>On success, the server MUST return 2.05 (Content) response with the data.</t>
        <t>If the target URI does not match an existing resource or the topic is not in the fully created state (see <xref target="topic-lifecycle"/>), the broker MUST return a response code 4.04 (Not Found).</t>
        <t>Example:</t>
        <artwork><![CDATA[
=> 0.01 GET
   Uri-Path: ps
   Uri-Path: data
   Uri-Path: 1bd0d6d

<= 2.05 Content
   Content-Format: 110
   Max-Age: 15

   {
      "n": "temperature",
      "u": "Cel",
      "t": 1621452122,
      "v": 23.5
   }
]]></artwork>
        <!--
TODO: Do we add wildcards here?
https://github.com/core-wg/coap-pubsub/issues/42

### Subscribe to a subset of topic-data resources  {#wildcard}

Some implementations may want to subscribe to multiple topic-data resources with one single request. That is possible by using FETCH with

-->

</section>
      <section anchor="rate-limit">
        <name>Rate Limiting</name>
        <t>The server hosting the topic-data may have to handle a potentially large number of publishers and subscribers at the same time. This means it could become overwhelmed if it receives too many publications in a short period of time.</t>
        <t>In this situation, if a publisher is sending publications too fast, the server SHOULD return a 4.29 (Too Many Requests) response <xref target="RFC8516"/>.  As described in <xref target="RFC8516"/>, the Max-Age option <xref target="RFC7252"/> in this response indicates the number of seconds after which the client may retry. The broker MAY also stop publishing messages from that publisher for the indicated time.</t>
        <!--
TODO DISCUSS
* "The broker MAY also stop publishing messages from that publisher for the indicated time."

   It's not necessarily the broker, but rather the server hosting the topic-data resource.

   What does "stop publishing" practically mean? Suppose that the client sends a new PUT request right away? What error response does the server send?

   (note that this opens for the server to keep more state about the publishers, which in turn requires pairwise secure association in order to identify them)

   This does not contradict the next, legitimate paragraph on forbidding a client to do so.

-->

<t>When a publisher receives a 4.29 (Too Many Requests) response, it MUST NOT send any new publication requests to the same topic-data resource before the time indicated by the Max-Age option has passed.</t>
      </section>
    </section>
    <section anchor="pubsub-parameters">
      <name>CoAP Pubsub Parameters</name>
      <t>This document defines parameters used in the messages exchanged between a client and the broker during the topic creation and configuration process (see <xref target="topic-resource-representation"/>). The table below summarizes them and specifies the CBOR key to use instead of the full descriptive name.</t>
      <t>Note that the media type application/core-pubsub+cbor MUST be used when these parameters are transported in the respective message fields.</t>
      <figure anchor="fig-CoAP-Pubsub-Parameters">
        <name>CoAP Pubsub Parameters</name>
        <artwork align="center"><![CDATA[
+-----------------+-----------+-----------+------------+
| Name            | CBOR Key  | CBOR Type | Reference  |
|-----------------|-----------|-----------|------------|
| topic-name      | TBD1      | tstr      | [RFC-XXXX] |
| topic-data      | TBD2      | tstr      | [RFC-XXXX] |
| resource-type   | TBD3      | tstr      | [RFC-XXXX] |
| media-type      | TBD4      | uint      | [RFC-XXXX] |
| topic-type      | TBD5      | tstr      | [RFC-XXXX] |
| expiration-date | TBD6      | tstr      | [RFC-XXXX] |
| max-subscribers | TBD7      | uint      | [RFC-XXXX] |
| observer-check  | TBD8      | uint      | [RFC-XXXX] |
+-----------------+-----------+-----------+------------+
]]></artwork>
      </figure>
    </section>
    <section anchor="seccons">
      <name>Security Considerations</name>
      <t>The architecture presented in this document inherits the security considerations from CoAP <xref target="RFC7252"/> and Observe <xref target="RFC7641"/>, as well as from Web Linking <xref target="RFC8288"/>, Link-Format <xref target="RFC6690"/>, and the CoRE Resource Directory <xref target="RFC9176"/>.</t>
      <t>Communications between each client and the broker MUST be secured, e.g., by using OSCORE <xref target="RFC8613"/> or DTLS <xref target="RFC9147"/>. Security considerations for the used secure communication protocols apply too.</t>
      <t>The content published on a topic by a publisher client SHOULD be protected end-to-end between the publisher and all the subscribers to that topic. In such a case, it MUST be possible to assert source authentication of the published data. This can be achieved at the application layer, e.g., by using COSE <xref target="RFC9052"/>, <xref target="RFC9053"/>, <xref target="RFC9338"/>.</t>
      <t>Access control of clients at the broker MAY be enforced for performing discovery operation, and SHOULD be enforced in a fine-grained fashion for operations related to the the creation, update, and deletion of topic resources, as well as for operations on topic-data resources such as publication on and subscription to topics. This prevents rogue clients to, among other things, repeatedly create topics at the broker or publish (large) contents, which may result in Denial of Service against the broker and the active subscribers.</t>
      <t>Building on <xref target="I-D.ietf-ace-key-groupcomm"/>, its application profile for publish-subscribe communication with CoAP <xref target="I-D.ietf-ace-pubsub-profile"/> provides a security model that can be used in the architecture presented in this document, in order to enable secure communication between the different parties as well as secure, authorized operations of publishers and subscribers that fulfill the requirements above.</t>
      <t>In particular, the application profile above relies on the ACE framework for Authentication and Authorization in Constrained Environments (ACE) <xref target="RFC9200"/> and defines a method to: authorize publishers and subscribers to perform operations at the broker, with fine-grained access control; authorize publishers and subscribers to obtain the keying material required to take part to a topic managed by the broker; protect published data end-to-end between its publisher and all the subscribers to the targeted topic, ensuring confidentiality, integrity, and source authentication of the published content end-to-end. That approach can be extended to enforce authorization and fine-grained access control for administrator clients that are intended to create, update, and delete topic configurations at the broker.</t>
    </section>
    <section anchor="iana">
      <name>IANA Considerations</name>
      <t>This document has the following actions for IANA.</t>
      <t>Note to RFC Editor: Please replace all occurrences of "[RFC-XXXX]" with the RFC number of this specification and delete this paragraph.</t>
      <section anchor="media-type">
        <name>Media Type</name>
        <t>IANA is requested to add the following Media-Type to the "Media Types"
registry <xref target="IANA.media-types"/>.</t>
        <table align="left" anchor="new-media-type">
          <name>New Media Type application/pubsub+cbor</name>
          <thead>
            <tr>
              <th align="left">Name</th>
              <th align="left">Template</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">pubsub+cbor</td>
              <td align="left">application/pubsub+cbor</td>
              <td align="left">RFC XXXX, <xref target="media-type"/></td>
            </tr>
          </tbody>
        </table>
        <dl spacing="compact">
          <dt>Type name:</dt>
          <dd>
            <t>application</t>
          </dd>
          <dt>Subtype name:</dt>
          <dd>
            <t>pubsub+cbor</t>
          </dd>
          <dt>Required parameters:</dt>
          <dd>
            <t>N/A</t>
          </dd>
          <dt>Optional parameters:</dt>
          <dd>
            <t>N/A</t>
          </dd>
          <dt>Encoding considerations:</dt>
          <dd>
            <t>binary (CBOR data item)</t>
          </dd>
          <dt>Security considerations:</dt>
          <dd>
            <t><xref target="seccons"/> of RFC XXXX</t>
          </dd>
          <dt>Interoperability considerations:</dt>
          <dd>
            <t>none</t>
          </dd>
          <dt>Published specification:</dt>
          <dd>
            <t><xref target="media-type"/> of RFC XXXX</t>
          </dd>
          <dt>Applications that use this media type:</dt>
          <dd>
            <t>This type is used by clients that create, retrieve, and update topic configurations at servers acting as a pub-sub broker.</t>
          </dd>
          <dt>Fragment identifier considerations:</dt>
          <dd>
            <t>N/A</t>
          </dd>
          <dt>Person &amp; email address to contact for further information:</dt>
          <dd>
            <t>CoRE WG mailing list (core@ietf.org),
or IETF Applications and Real-Time Area (art@ietf.org)</t>
          </dd>
          <dt>Intended usage:</dt>
          <dd>
            <t>COMMON</t>
          </dd>
          <dt>Restrictions on usage:</dt>
          <dd>
            <t>none</t>
          </dd>
          <dt>Author/Change controller:</dt>
          <dd>
            <t>IETF</t>
          </dd>
          <dt>Provisional registration:</dt>
          <dd>
            <t>no</t>
          </dd>
        </dl>
      </section>
      <section anchor="content-format">
        <name>Content-Format</name>
        <t>IANA has added the following Content-Formats to the
<xref section="&quot;CoAP Content-Formats&quot;" relative="#content-formats" sectionFormat="bare" target="IANA.core-parameters"/>
sub-registry, within the "Constrained RESTful Environments (CoRE)
Parameters" Registry <xref target="IANA.core-parameters"/>, as follows:</t>
        <table align="left">
          <name>New Content-Format</name>
          <thead>
            <tr>
              <th align="left">Content Type</th>
              <th align="left">Content Coding</th>
              <th align="left">ID</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">application/pubsub+cbor</td>
              <td align="left">-</td>
              <td align="left">TBD9</td>
              <td align="left">RFC XXXX</td>
            </tr>
          </tbody>
        </table>
        <t>TBD9 is to be assigned from the space 256..999.</t>
      </section>
      <section anchor="iana-coap-pubsub-parameters">
        <name>CoAP Pubsub Parameters</name>
        <t>IANA is asked to register the following entries in the subregistry of the "Constrained RESTful Environments (CoRE) Parameters" registry group.</t>
        <t>This specification establishes the "Pubsub Topic Configuration Parameters" IANA registry within the "Constrained RESTful Environments (CoRE)
Parameters" registry group.</t>
        <t>The columns of this registry are:</t>
        <ul spacing="normal">
          <li>Name: This is a descriptive name that enables easier reference to the item. The name MUST be unique. It is not used in the encoding.</li>
          <li>CBOR Key: This is the value used as CBOR key of the item. These values MUST be unique. The value can be a positive integer, a negative integer, or a text string. Different ranges of values use different registration policies <xref target="RFC8126"/>. Integer values from -256 to 255 as well as text strings of length 1 are designated as "Standards Action With Expert Review". Integer values from -65536 to -257 and from 256 to 65535, as well as text strings of length 2 are designated as "Specification Required". Integer values greater than 65535 as well as text strings of length greater than 2 are designated as "Expert Review". Integer values less than -65536 are marked as "Private Use".</li>
          <li>CBOR Type: This contains the CBOR type of the item, or a pointer to the registry that defines its type, when that depends on another item.</li>
          <li>Reference: This contains a pointer to the public specification for the item.</li>
        </ul>
        <t>The registry is initially populated with the entries in <xref target="fig-CoAP-Pubsub-Parameters"/> of <xref target="pubsub-parameters"/>.</t>
      </section>
      <section anchor="iana-rt">
        <name>Resource Types</name>
        <t>IANA is asked to enter the following values in the "Resource Type (rt=) Link Target Attribute Values" registry within the "Constrained Restful Environments (CoRE) Parameters" registry group.</t>
        <artwork><![CDATA[
Value: core.ps
Description: Publish-Subscribe Broker
Reference: [RFC-XXXX]

Value: core.ps.coll
Description: Topic-collection resource of a Publish-Subscribe Broker
Reference: [RFC-XXXX]

Value: core.ps.conf
Description: Topic-configuration resource of a Publish-Subscribe Broker
Reference: [RFC-XXXX]

Value: core.ps.data
Description: Topic-data resource of a broker
Reference: [RFC-XXXX]
]]></artwork>
      </section>
    </section>
    <section numbered="false" anchor="acknowledgements">
      <name>Acknowledgements</name>
      <t>The current version of this document contains a substantial contribution by Klaus Hartke's proposal <xref target="I-D.hartke-t2trg-coral-pubsub"/>, which defines the topic resource model and structure as well as the topic lifecycle and interactions. It also follows a similar architectural design as that provided by Marco Tiloca's <xref target="I-D.ietf-ace-oscore-gm-admin"/>.</t>
      <t>The authors would like to also thank Carsten Bormann, Hannes Tschofenig, Zach Shelby, Mohit Sethi, Peter van der Stok, Tim Kellogg, Anders Eriksson, Goran Selander, Mikko Majanen, Olaf Bergmann and Oscar Novo for their valuable contributions and reviews.</t>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references>
        <name>Normative References</name>
        <reference anchor="RFC6570">
          <front>
            <title>URI Template</title>
            <author fullname="J. Gregorio" initials="J." surname="Gregorio"/>
            <author fullname="R. Fielding" initials="R." surname="Fielding"/>
            <author fullname="M. Hadley" initials="M." surname="Hadley"/>
            <author fullname="M. Nottingham" initials="M." surname="Nottingham"/>
            <author fullname="D. Orchard" initials="D." surname="Orchard"/>
            <date month="March" year="2012"/>
            <abstract>
              <t>A URI Template is a compact sequence of characters for describing a range of Uniform Resource Identifiers through variable expansion. This specification defines the URI Template syntax and the process for expanding a URI Template into a URI reference, along with guidelines for the use of URI Templates on the Internet. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6570"/>
          <seriesInfo name="DOI" value="10.17487/RFC6570"/>
        </reference>
        <reference anchor="RFC6690">
          <front>
            <title>Constrained RESTful Environments (CoRE) Link Format</title>
            <author fullname="Z. Shelby" initials="Z." surname="Shelby"/>
            <date month="August" year="2012"/>
            <abstract>
              <t>This specification defines Web Linking using a link format for use by constrained web servers to describe hosted resources, their attributes, and other relationships between links. Based on the HTTP Link Header field defined in RFC 5988, the Constrained RESTful Environments (CoRE) Link Format is carried as a payload and is assigned an Internet media type. "RESTful" refers to the Representational State Transfer (REST) architecture. A well-known URI is defined as a default entry point for requesting the links hosted by a server. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6690"/>
          <seriesInfo name="DOI" value="10.17487/RFC6690"/>
        </reference>
        <reference anchor="RFC7252">
          <front>
            <title>The Constrained Application Protocol (CoAP)</title>
            <author fullname="Z. Shelby" initials="Z." surname="Shelby"/>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <date month="June" year="2014"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a specialized web transfer protocol for use with constrained nodes and constrained (e.g., low-power, lossy) networks. The nodes often have 8-bit microcontrollers with small amounts of ROM and RAM, while constrained networks such as IPv6 over Low-Power Wireless Personal Area Networks (6LoWPANs) often have high packet error rates and a typical throughput of 10s of kbit/s. The protocol is designed for machine- to-machine (M2M) applications such as smart energy and building automation.</t>
              <t>CoAP provides a request/response interaction model between application endpoints, supports built-in discovery of services and resources, and includes key concepts of the Web such as URIs and Internet media types. CoAP is designed to easily interface with HTTP for integration with the Web while meeting specialized requirements such as multicast support, very low overhead, and simplicity for constrained environments.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7252"/>
          <seriesInfo name="DOI" value="10.17487/RFC7252"/>
        </reference>
        <reference anchor="RFC8516">
          <front>
            <title>"Too Many Requests" Response Code for the Constrained Application Protocol</title>
            <author fullname="A. Keranen" initials="A." surname="Keranen"/>
            <date month="January" year="2019"/>
            <abstract>
              <t>A Constrained Application Protocol (CoAP) server can experience temporary overload because one or more clients are sending requests to the server at a higher rate than the server is capable or willing to handle. This document defines a new CoAP response code for a server to indicate that a client should reduce the rate of requests.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8516"/>
          <seriesInfo name="DOI" value="10.17487/RFC8516"/>
        </reference>
        <reference anchor="RFC9176">
          <front>
            <title>Constrained RESTful Environments (CoRE) Resource Directory</title>
            <author fullname="C. Amsüss" initials="C." role="editor" surname="Amsüss"/>
            <author fullname="Z. Shelby" initials="Z." surname="Shelby"/>
            <author fullname="M. Koster" initials="M." surname="Koster"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="P. van der Stok" initials="P." surname="van der Stok"/>
            <date month="April" year="2022"/>
            <abstract>
              <t>In many Internet of Things (IoT) applications, direct discovery of resources is not practical due to sleeping nodes or networks where multicast traffic is inefficient. These problems can be solved by employing an entity called a Resource Directory (RD), which contains information about resources held on other servers, allowing lookups to be performed for those resources. The input to an RD is composed of links, and the output is composed of links constructed from the information stored in the RD. This document specifies the web interfaces that an RD supports for web servers to discover the RD and to register, maintain, look up, and remove information on resources. Furthermore, new target attributes useful in conjunction with an RD are defined.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9176"/>
          <seriesInfo name="DOI" value="10.17487/RFC9176"/>
        </reference>
        <reference anchor="RFC8613">
          <front>
            <title>Object Security for Constrained RESTful Environments (OSCORE)</title>
            <author fullname="G. Selander" initials="G." surname="Selander"/>
            <author fullname="J. Mattsson" initials="J." surname="Mattsson"/>
            <author fullname="F. Palombini" initials="F." surname="Palombini"/>
            <author fullname="L. Seitz" initials="L." surname="Seitz"/>
            <date month="July" year="2019"/>
            <abstract>
              <t>This document defines Object Security for Constrained RESTful Environments (OSCORE), a method for application-layer protection of the Constrained Application Protocol (CoAP), using CBOR Object Signing and Encryption (COSE). OSCORE provides end-to-end protection between endpoints communicating using CoAP or CoAP-mappable HTTP. OSCORE is designed for constrained nodes and networks supporting a range of proxy operations, including translation between different transport protocols.</t>
              <t>Although an optional functionality of CoAP, OSCORE alters CoAP options processing and IANA registration. Therefore, this document updates RFC 7252.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8613"/>
          <seriesInfo name="DOI" value="10.17487/RFC8613"/>
        </reference>
        <reference anchor="RFC7641">
          <front>
            <title>Observing Resources in the Constrained Application Protocol (CoAP)</title>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <date month="September" year="2015"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a RESTful application protocol for constrained nodes and networks. The state of a resource on a CoAP server can change over time. This document specifies a simple protocol extension for CoAP that enables CoAP clients to "observe" resources, i.e., to retrieve a representation of a resource and keep this representation updated by the server over a period of time. The protocol follows a best-effort approach for sending new representations to clients and provides eventual consistency between the state observed by each client and the actual resource state at the server.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7641"/>
          <seriesInfo name="DOI" value="10.17487/RFC7641"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
        <reference anchor="IANA.media-types" target="https://www.iana.org/assignments/media-types">
          <front>
            <title>Media Types</title>
            <author>
              <organization>IANA</organization>
            </author>
          </front>
        </reference>
        <reference anchor="IANA.core-parameters" target="https://www.iana.org/assignments/core-parameters">
          <front>
            <title>Constrained RESTful Environments (CoRE) Parameters</title>
            <author>
              <organization>IANA</organization>
            </author>
          </front>
        </reference>
      </references>
      <references>
        <name>Informative References</name>
        <reference anchor="RFC8288">
          <front>
            <title>Web Linking</title>
            <author fullname="M. Nottingham" initials="M." surname="Nottingham"/>
            <date month="October" year="2017"/>
            <abstract>
              <t>This specification defines a model for the relationships between resources on the Web ("links") and the type of those relationships ("link relation types").</t>
              <t>It also defines the serialisation of such links in HTTP headers with the Link header field.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8288"/>
          <seriesInfo name="DOI" value="10.17487/RFC8288"/>
        </reference>
        <reference anchor="RFC8126">
          <front>
            <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
            <author fullname="M. Cotton" initials="M." surname="Cotton"/>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <author fullname="T. Narten" initials="T." surname="Narten"/>
            <date month="June" year="2017"/>
            <abstract>
              <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
              <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
              <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="26"/>
          <seriesInfo name="RFC" value="8126"/>
          <seriesInfo name="DOI" value="10.17487/RFC8126"/>
        </reference>
        <reference anchor="RFC9052">
          <front>
            <title>CBOR Object Signing and Encryption (COSE): Structures and Process</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="August" year="2022"/>
            <abstract>
              <t>Concise Binary Object Representation (CBOR) is a data format designed for small code size and small message size. There is a need to be able to define basic security services for this data format. This document defines the CBOR Object Signing and Encryption (COSE) protocol. This specification describes how to create and process signatures, message authentication codes, and encryption using CBOR for serialization. This specification additionally describes how to represent cryptographic keys using CBOR.</t>
              <t>This document, along with RFC 9053, obsoletes RFC 8152.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="96"/>
          <seriesInfo name="RFC" value="9052"/>
          <seriesInfo name="DOI" value="10.17487/RFC9052"/>
        </reference>
        <reference anchor="RFC9147">
          <front>
            <title>The Datagram Transport Layer Security (DTLS) Protocol Version 1.3</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <author fullname="H. Tschofenig" initials="H." surname="Tschofenig"/>
            <author fullname="N. Modadugu" initials="N." surname="Modadugu"/>
            <date month="April" year="2022"/>
            <abstract>
              <t>This document specifies version 1.3 of the Datagram Transport Layer Security (DTLS) protocol. DTLS 1.3 allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</t>
              <t>The DTLS 1.3 protocol is based on the Transport Layer Security (TLS) 1.3 protocol and provides equivalent security guarantees with the exception of order protection / non-replayability. Datagram semantics of the underlying transport are preserved by the DTLS protocol.</t>
              <t>This document obsoletes RFC 6347.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9147"/>
          <seriesInfo name="DOI" value="10.17487/RFC9147"/>
        </reference>
        <reference anchor="RFC9053">
          <front>
            <title>CBOR Object Signing and Encryption (COSE): Initial Algorithms</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="August" year="2022"/>
            <abstract>
              <t>Concise Binary Object Representation (CBOR) is a data format designed for small code size and small message size. There is a need to be able to define basic security services for this data format. This document defines a set of algorithms that can be used with the CBOR Object Signing and Encryption (COSE) protocol (RFC 9052).</t>
              <t>This document, along with RFC 9052, obsoletes RFC 8152.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9053"/>
          <seriesInfo name="DOI" value="10.17487/RFC9053"/>
        </reference>
        <reference anchor="RFC9200">
          <front>
            <title>Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework (ACE-OAuth)</title>
            <author fullname="L. Seitz" initials="L." surname="Seitz"/>
            <author fullname="G. Selander" initials="G." surname="Selander"/>
            <author fullname="E. Wahlstroem" initials="E." surname="Wahlstroem"/>
            <author fullname="S. Erdtman" initials="S." surname="Erdtman"/>
            <author fullname="H. Tschofenig" initials="H." surname="Tschofenig"/>
            <date month="August" year="2022"/>
            <abstract>
              <t>This specification defines a framework for authentication and authorization in Internet of Things (IoT) environments called ACE-OAuth. The framework is based on a set of building blocks including OAuth 2.0 and the Constrained Application Protocol (CoAP), thus transforming a well-known and widely used authorization solution into a form suitable for IoT devices. Existing specifications are used where possible, but extensions are added and profiles are defined to better serve the IoT use cases.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9200"/>
          <seriesInfo name="DOI" value="10.17487/RFC9200"/>
        </reference>
        <reference anchor="RFC9338">
          <front>
            <title>CBOR Object Signing and Encryption (COSE): Countersignatures</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="December" year="2022"/>
            <abstract>
              <t>Concise Binary Object Representation (CBOR) is a data format designed for small code size and small message size. CBOR Object Signing and Encryption (COSE) defines a set of security services for CBOR. This document defines a countersignature algorithm along with the needed header parameters and CBOR tags for COSE. This document updates RFC 9052.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="96"/>
          <seriesInfo name="RFC" value="9338"/>
          <seriesInfo name="DOI" value="10.17487/RFC9338"/>
        </reference>
        <reference anchor="I-D.hartke-t2trg-coral-pubsub">
          <front>
            <title>Publish/Subscribe over the Constrained Application Protocol (CoAP) using the Constrained RESTful Application Language (CoRAL)</title>
            <author fullname="Klaus Hartke" initials="K." surname="Hartke">
              <organization>Ericsson</organization>
            </author>
            <date day="9" month="May" year="2020"/>
            <abstract>
              <t>   This document explores how the Constrained RESTful Application
   Language (CoRAL) might be used for enabling publish/subscribe-style
   communication over the Constrained Application Protocol (CoAP), which
   allows CoAP nodes with long breaks in connectivity and/or up-time to
   exchange data via a publish/subscribe broker.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-hartke-t2trg-coral-pubsub-01"/>
        </reference>
        <reference anchor="I-D.ietf-ace-oscore-gm-admin">
          <front>
            <title>Admin Interface for the OSCORE Group Manager</title>
            <author fullname="Marco Tiloca" initials="M." surname="Tiloca">
              <organization>RISE AB</organization>
            </author>
            <author fullname="Rikard Höglund" initials="R." surname="Höglund">
              <organization>RISE AB</organization>
            </author>
            <author fullname="Peter Van der Stok" initials="P." surname="Van der Stok">
              <organization>Consultant</organization>
            </author>
            <author fullname="Francesca Palombini" initials="F." surname="Palombini">
              <organization>Ericsson AB</organization>
            </author>
            <date day="1" month="July" year="2023"/>
            <abstract>
              <t>   Group communication for CoAP can be secured using Group Object
   Security for Constrained RESTful Environments (Group OSCORE).  A
   Group Manager is responsible to handle the joining of new group
   members, as well as to manage and distribute the group keying
   material.  This document defines a RESTful admin interface at the
   Group Manager, that allows an Administrator entity to create and
   delete OSCORE groups, as well as to retrieve and update their
   configuration.  The ACE framework for Authentication and
   Authorization is used to enforce authentication and authorization of
   the Administrator at the Group Manager.  Protocol-specific transport
   profiles of ACE are used to achieve communication security, proof-of-
   possession, and server authentication.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-ace-oscore-gm-admin-09"/>
        </reference>
        <reference anchor="I-D.ietf-ace-pubsub-profile">
          <front>
            <title>Publish-Subscribe Profile for Authentication and Authorization for Constrained Environments (ACE)</title>
            <author fullname="Francesca Palombini" initials="F." surname="Palombini">
              <organization>Ericsson</organization>
            </author>
            <author fullname="Cigdem Sengul" initials="C." surname="Sengul">
              <organization>Brunel University</organization>
            </author>
            <author fullname="Marco Tiloca" initials="M." surname="Tiloca">
              <organization>RISE AB</organization>
            </author>
            <date day="13" month="September" year="2023"/>
            <abstract>
              <t>   This document defines an application profile of the Authentication
   and Authorization for Constrained Environments (ACE) framework, to
   enable secure group communication in the Publish-Subscribe (pub/sub)
   architecture for the Constrained Application Protocol (CoAP) [draft-
   ietf-core-coap-pubsub], where Publishers and Subscribers communicate
   through a Broker.  This profile relies on protocol-specific transport
   profiles of ACE to achieve communication security, server
   authentication, and proof-of-possession for a key owned by the Client
   and bound to an OAuth 2.0 Access Token.  This document specifies the
   provisioning and enforcement of authorization information for Clients
   to act as Publishers and/or Subscribers, as well as the provisioning
   of keying material and security parameters that Clients use for
   protecting their communications end-to-end through the Broker.

   Note to RFC Editor: Please replace "[draft-ietf-core-coap-pubsub]"
   with the RFC number of that document and delete this paragraph.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-ace-pubsub-profile-07"/>
        </reference>
        <reference anchor="I-D.ietf-ace-key-groupcomm">
          <front>
            <title>Key Provisioning for Group Communication using ACE</title>
            <author fullname="Francesca Palombini" initials="F." surname="Palombini">
              <organization>Ericsson AB</organization>
            </author>
            <author fullname="Marco Tiloca" initials="M." surname="Tiloca">
              <organization>RISE AB</organization>
            </author>
            <date day="6" month="October" year="2023"/>
            <abstract>
              <t>   This document defines how to use the Authentication and Authorization
   for Constrained Environments (ACE) framework to distribute keying
   material and configuration parameters for secure group communication.
   Candidate group members acting as Clients and authorized to join a
   group can do so by interacting with a Key Distribution Center (KDC)
   acting as Resource Server, from which they obtain the keying material
   to communicate with other group members.  While defining general
   message formats as well as the interface and operations available at
   the KDC, this document supports different approaches and protocols
   for secure group communication.  Therefore, details are delegated to
   separate application profiles of this document, as specialized
   instances that target a particular group communication approach and
   define how communications in the group are protected.  Compliance
   requirements for such application profiles are also specified.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-ace-key-groupcomm-17"/>
        </reference>
      </references>
    </references>
    <section anchor="contributors" numbered="false" toc="include" removeInRFC="false">
      <name>Contributors</name>
      <contact initials="M." surname="Tiloca" fullname="Marco Tiloca">
        <organization>RISE AB</organization>
        <address>
          <email>marco.tiloca@ri.se</email>
        </address>
      </contact>
      <t>Marco offered comprehensive reviews and insightful guidance on the recent iterations of this document. His contributions were particularly notable in the Security Considerations section, among others.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAP93MmUAA+196XYbx9XgfzxFBTrnI2kD4CJKluA4NiVSMRNtQ1Lj5Esy
Pg2gALbZ6Ea6GqQYSvMs8yzzZHO32robICQrmczCk1hAo7qWW7fufm/1+/2O
qZJ88nOSFbkeqlttOp0qrTL43D1Si+UoS81l3yxHZlymI62ScnyZVnpcLUut
pkWpqkutnhe5qcokzfVEHS0WWTpOqrTI1duyqIpxkant58XR251uZ1KM82QO
fU/KZFr1U11N++Oi1PCfZNGH0WCgfpZU2lQd6EPPivJ2qEw16XTSRTlUVbk0
1cHe3tO9g05S6mQYDmc6N0V5NSuL5WIIUzo7UT/B9zSfqd/jsw70PU+NgZbV
7QLmcHpy8aITLx/6151FOlR/gXn3lCnKqtRTA59u5/jhb53Otc6XethRap6k
2VDh7H/AdQyKcgZPZ2l1uRzx8/7NbDdYWKeTLKvLohx2+tAwzc1Q/WGg/pDO
da7/AU8YMn9I4EHwFLodqpMyHRtT5PBd87i/YLMf0qt0ME19f68G6o+FqXTp
unuVji8TnfnH1N9xMavSmS7Vy2RkfKdzbvxLcZlfUfsfZvjDYFzM/RhHMIYu
k1znbpCjMg2erZhxUqaDK270g5ZfqefOGHYEkGtZEWzsxAHTCnWRZsU44U6T
PP0HbfRQnZ2en6ijZ8HMsfWgotY/wEBGw2+uX3qHOyymU10CmsLAi1Jf6tyk
11qV+jrVN0YBKuAi09llNV1marZMJ0k+1gpwGfG81GOdVwrwv2SMg+7gh9Qo
QOwl7Fg1UD/Ct3Bgo25gQLVIyiodL7OkzG5VXlTJKNMwFHV7rsfLMq1u6Ryl
E9e5gWMGH3oqmReAxQW0Lc2g08mLcg5NrgkNz148f/zomz378fFT+/Gbg0cH
8vHJo/3H8vHp/jf245PH+w9t28eH+0M4Y/m01vWTgydP7Mf9A9fJnuv66f7h
N/6p7e8pnFH78eFD6uG0fzy4BCBc6X51UJUzPPdJJkfDNiCCkIx1vzB0gGbz
fjKZp3njdyEVi7KYpplu/Hylb/tECGCb57Aw2BmALzY7P3n5AkjbX2Bm/T/B
39+6nU6/31dwDoCCjatO5yLcTzXRTPgAN74wNewp/b7S+QQJFL42ThbJKM3S
KtWEV9gI0XS+zC2BoyHMcrEAuoSvwduLIs0rwDEgOypDLBkBWbwyiFqAhTli
0DWiFmD2Lry8XPQrIBwD6T1LNb4tC0M0xxPg11cVsOyqWKRjdZ0m8Bl2pdRm
Uci06Rd4UCxLOCVJBS2oY6PLa6AuAE9slhiYVQFnf8CwnqeTSaY7nQfqFM5J
MVkSmqu7B2nw9SPuxMbAVHd3vxGc//jRgsh05gnsTw4YV/TlYwxRmGFZGKNy
XSHvILiP/YidCdCFsWa6EDx37QWOS0P4Ueq/L4Fz7TKEjFbzYgKk9+YSCYCF
9Ty50ralQQAzrGjHihIOPz6T3wmARGZyB2UY81gvBG+ELpm0WvJ66BvQT8Uz
h9FusROlUyQeuBOJDNjD3aQ59WBcNQLqAtvzBiCUzhF4CSD/OEtMHSbKwiTN
x9kSjod7UF0iApRI1hCvoSmuZJkT1t7qBNY4LYs5zmCeZJkaJRUQ0lse/laZ
cQK8dcZ4rcvZLbeGeaclPLlOyyJnEgt4YbQb9hJeU1k6h3M4sfitRnqcwK7g
29Azggs2AwBK9Bo7pFYAcphMpvUCRwVJoNJ8kvLCbnF0igbqKCcq3AajvEBg
4PrtzPhQyszgWAJzpQN+qyZLOlt8EPqj4j20zlJAjNcy6tFkAhtu1AXwSwMC
UQHA2359dGF2CBenaalvAIbIDV4w2YHF0gx6TExoZ3d5q/tFid9gEhG9gjmf
nZxfAOHJAV4KZpdlsgGAsjltY2kxENcFa4eHQKAS7Au2DEfyu6/nRmfXiKBO
cNx1pGTFHPhsMOj0e5hCPoMukyohekP0BbsGUj67hL1iMqKYnAP4gE8DLKpw
/bAURKtBnZAnSDx4ngp4bILL5+76o8TAvJrUHXYoJD8ILJQKTjwuGjj6CC+k
AgN1iuxiCm2NnyofiiwrbuiwjwENKt1TkxQYHJLIgJfkk5AQ89phGQ8eqAtd
AhMssgIOxd2Dyn8TIgnsTgHaTIzqvnp3ftHt8b/q9Rv6fHbyX96dnp0c4+fz
H49evnQfOtLi/Mc3714e+0/+zedvXr06eX3ML8NTFT3qdF8d/Rl+wbl337y9
OH3z+uhll+WaCPglQXPEtKEEyYswwXQse0WxSz17/vZ//o/9Q6HlB/v7T4GW
85cn+98cwhfESx6tyEGO4q94xjuwvUBh6EQDaQFemlZJBocBKJ65LG5yhYgG
0GSsAIowTqeWCSC1hQNl8IxOkBTzVKfJHE4rdErnGLtF3EHoE0NAsXWsF1VA
+HBXl8bwau7uvhcBCiaOU+aVoIT28eNAnfFYHZjdMgNYZKZl0GhA5QYMx+mE
nK8ng6CUF42KAh6Oitjy7uwUOp0vUM/qsMBn5waCJLyWIloz+bb7QzMhanH0
9lSwnEavGuActMIY2R51KyQYmAIeCpIiPD6DqHY3vDYLkOE+dpoHchseIUnZ
GXZA6VBzoJDJrM7SQ6YrLQB8oG2MmW4RYO3kLInB3TOIqSTxiLSC4gn0YvAt
kt+RuqYDkJ7clEp4gloBKhFMhKhDISlueMvJLFXAORRLolvA/VKguUmG4yP7
v8oFLKxwpAuSG3jr5HUgk8A3UJaoUKiZ0UbDqmEWpbxqgsXDmrAzOCJlsSgR
CuECYL8E0oj6kfxXGgR0JCois0CBInFSI75VkGgRdqre+l9xYdyLm9I2vSxi
7Y6doSwPNrG2PwN17vtmjg/zAHG3IClohHzOnuWMP2zLbBb4bSeQZAfqGfBw
VRYIwWKB2pZ2G5LkwFaWIE1ltA+ZnsyAWqMe6DgeCA8o4JFMINvNVA0FOgAm
PwHRNGP1jXHVaBY+5Md8ms6Wouchv6y/hGfwsjBMJWGhOvwtFLg92JguphWS
MSCwiM2J7QpbwW7QFLI0v3I4EUvwpiHfK5Ra2mZtF9qPnkZrddpkkTPpKnPC
Ve6uJwIkPsJJR/0wiSdJa66rBAWCEEoh9JqQamolmwNJph5PZsVCHPxgapY5
1MBZJztOPG/st7lEEpQQLYOvSD+QUDO9YZkO6bYQzxZkQAJBYhLTlZD74hso
HqguDdtldt2yfV0rCy6ZtwBSs0iWjLJbt+MkntlheccdsGNdB3uzIg29JVpo
JGLRD6giJLVTzySvtk8CgNoeN9DWLMeXTnUl3ip9iwRIPJCPgHSvWhYHS2a0
4VWGqi3xfMQ7xjmY/rwom/tq3L6jztGEuGGEXIASmgKMeaotM4npf2qU6Jgp
mpGs4cFUaDOB/vrw5CaBDQdosVazXEzwnxiYMLh9Vdggfr25TAF2qV0do1tD
679nerSOcI4wE+Ja0cEBWjTV49sx/J6YQKoAcYQHcb9b2YXkZ7KJRWBkKFqh
+tZRWsM2CT8viwXhKAY6JzGb9lf4Vt8xHHUUKCwgn9zBsH1UYtDQcIlyPSAu
6IOwCHl397zdQEQCP6kKICJ5uYN1AqdQWUI1EvmANa6sRpPkoCJHLwy/bPV5
ta0Hs0HPG6yQpeLxAh6GLBcpJRrVUtRsAGV2eGJWwkMVh47+NBnTvt1j9RHi
G80eFhjyfzS8V3IICG/uG7AFxZpn3KFRT3AWjR2jFROKBIjArCV6LeMEavH6
RoWyCXbDOt4bkjK0yPUsUFsDzL0HZMCK2hc+v6jr3mhQ1UMRLV4qy0bMdz2V
ToFfWbGVVz+2FIF1ehIl6RwJOUB2kpMhHI4TSDp9PYVJVsioUpR6/jv8qSQx
1+gEgT+aUetf6y/4kF+0vKPxJ4S39ifN8d1B3/8NfItB9LSQXYxb4+sfgl4/
OLYVPv7wW//K12HrTvgKzPFr1+x3QTv/tP+7DwEP/NAcve1j/Hpt9K1gNVv3
9RS37jhADQKo2XcEY6PXbev1b7YNHL65YrviN//V27US3v+S7dpqfVrbLjxp
oCWrB5YPKfLXfrf1dr17wnGfLXhOVsZ+kqWz/LsuOrV02f242vcBzVE0NizW
e7NgLzYSooFLuJQTKZAxM+X3zH7baO14fMTX+mF/Hz/uiEcuNESOrOIckNmo
Q3xS78dy3H5dsq+ZOJ0I0XOmOjQK1aUNIce1p0A2df0pLYD1dZr0PMlBASbw
hqKscROk9TTmJcja83gIk8iDLzRLMQNonDbbAFi/dd04IyxMDEQXZsao+qCZ
eapL9IyKjd4fD+KWXreHmf72N/1+J1I3dKRtoA8AxaJ8OR+h8DFVF8+OxU6W
azLTw8jAlHpklQe5Fz2m+DIrWmRQGI8KkRZqXK8DJ4rktVcIS2RtIkzdPZjL
k74Idk5cW6ROWmO7itXQyF7Atq6E+4Ez4pQrmrGIWrxzE6tPPrOCTp3z2b+f
f/4ZH7CYAX+78P+/dkLV7a/QZBfaOL7Mf3+N++FnP7f8tbSjhuG/9nNbW5qR
/5eouH1W02RXDbUb/Oue1UjUIhUK1T1zYCcpj0HYXUeOLJyVfk8evaay1W/R
hYEukdrlAIsBH6qLLuXBwgzwjW6sbqSwuSjONdz5F5faC6cm1pfahiZJqanI
+JY1ygQIdLSmN8Q9Mnc1LQtsNblMs0mpP2Hp+bSL2g7qKqjj+LPjjgzpWREN
w6AE3rJuw7EjEkKXfISpqYxVGdxinDJmPXeWM2BoBAiiiVUyvfGrMjqbEsXC
fXf6TeRbNgE0hP4julHnSPHViTddpQ1TzNBpAN5QBNQzaVc+GA9q7a2ZPFS9
WD9Fm2TplCy2yTrr40XMutq6I7NEbJMl/aBVhVlDgiwNahChNiq0CRlqp0Nr
yBHRkubH1QNgswH9xR+jn+IXZXFDoXnD6CP9ue+iYkTIDb/uqq+g72H0UV6U
78GIHkzY7QcgfcPooxuRvreuEdfwgRcWfIx/+rIvwrxgPgIc95Hedt/diwF2
EgSUB46qAUetBc7PHjg/14Dz80rgDHmPB8PoY/zTetTcDT7SGoPv7TjHKLTv
Px7UfspjnsYPRe5mqYEOaYtlLDBorBG8yfrkjuRZJPB0OicrjPBsSJC2bABP
yL7fE0Ms2/3zK1Ul5UxX1sodWZJXm3asFWfsJdnQqRKaUYrxeFmyse1Xj18n
vedsy6V+IhOeUMrgJQBDeUv0XULraiQ70hPQdqbJq8cKwlG9Nft9w/5pDuQC
E3ctGf5AfMXQCWdfF2PPZg4XFi5LXYFofm3Fb3LXeYbV8BbY99nu2UCBlzjN
F+zZdXL53Z3zPvPmkGuHDOW0rNhAHu5aUnE0o1ZbZbWltq0Ypy5AttgRgeM6
yZZ1QSOUhGK5isMaCLDPI4yOUd+KJX274H6sC3zEXQuMXwROVtxQ/dA3AjoM
LyIjJMej5SuMqpF0V9NSqVOSK04rjwJO7RKNsGrIToAA+j1ggkNvE6hpFDXD
0TYUqcTWSArkAxEHVSUA3uba8qBNePP0x8pVsaQmLi9/GiKtB38NBRyO1QoN
qxeBOHwfbXr+7M0ZKFIL0veS1LnR4jeDqUTuHhQUi0U/g3OSKYAfReDAmt/l
GcZKecJAnsOb1Dg1mKOy2nExsFDQ9JLRCMOBA605kudt5GlSJnPYwdJ6DwSd
MTDRTt4ib0BoJKjRgsHF0MURETVwuKGQrII0/LnzbKo3nc5XaosniVHXW+zL
o2gYDDLT2YRlUty8nEOohBmARpCT1bykA6HzcWHXIRwT3Zx+0yv9vlKmQlEY
JPP3CfpLjPeIY2sXUqgul6Bs9/FsUZg0v2asX6NbFsX8oAuE592702ND8YPs
KyYaZMJVIdVuW9V2QSwMKMBkSeK5dSzt1FEz4FVtUjuSDBHV4Q2nFjkXRWqs
3F+DEvbbDh6aviN4qL+t3BcYIs3ZqRPZNVjru2fagf+6Nre4mxWbiIjMRF9C
mEYteiasZK4naeKWAfTIQn7NOuidX7mIoA9aAe1F6MoXvRNpKFJbj9F2TInA
JstUXwKlBAd54dBh99FelybSDU7H7i+myLs7ISJ+2vo9x0X0YvJx+/mg8N2t
P5C+oT+LXQwVQyPistSyo6CTp8KAkOltviz/oiJuGS6oMel6409Aw4Tf4CZI
Dk/P36gnj/f2VbyL3YO9g4f9vYf9h/sXBw+Hj57C//4T9i10ZiMf5Ehi2G1e
G8q9y6pANELB7xa2YV5cO7uGCwf0nBwmmE5ghdOwG/iAEbXCInsB7ST/HP5G
MNDxaHKqkvf9wB7wCUcreZ/Ol/PANgsy7DKrklwXyyiGi8NWkeCsP2dxh8wq
lphEg7yINkyO2AYAYMsxAi4llzELzZvPdYOtk57jboOe4tUSsMULVfbHl3p8
1Qprlpkw76fIWuGCo2hoMPFeW/SqoCymx0uKJbMe5sgjy2GJAFWSkwF7kSOG
oX1BhFZgpFcntEWh3OX2xFK8Gcm0FMuSq70exnzo3CwxEjYECMgcEmSPEfQ2
1I3VwTSD2cEJAKDNiqpiOTYKyJsUtMklJmqh3E1CSlppeMnmKxBst6yvWpek
ORGyJBJuHxr+fFhKCyHs8UZI0xY/O1LpW8vb431lMsIYBLNMANGEsjBKhHj7
5PHh3l6vEbXiQ21tTILXb2mzDg5h/stS4rqPrbcJ1ZhAgwF6i4QK6VgQ0jIM
xO5vA2rRZgD35ojgWVtgxLfOuthqvGgGsBWmocSK/CuWercokH8lwN6tAuTf
KJr01dGffSg8Nw4iLqjpOYfWHHvHHGYGIBWAE2KIatjsAKeXHgPRHFcFTGH7
7HgnjolmBcbGFiZ5LSaIcrKM9WaGsdUDWSDPutQzMu1aI8HZMXYbBDVTPIde
UO7OuWzPI6QC0WxcVGAscqHWBcNbcarbQLRV/grWL/w0tDB2CVTKXcqYAzvb
poViMtxxPn7omkxJtncPf5sn46ETWF98KxhrIXEnAPIbif75+xI2VOzXne9+
p/YGwKJ/f3KBRrp3Zdp/m6ChHlNoh7u7f5lO994Ph1P9t90B+g36GKCb7+I8
sb3d/P4FJffK9Dud336nDgZ7j5B8ohyHTd8mt1mRTMiKKI/7bC0ZqsM9tR1K
cmgHEdlvB9v/VmYzv8VVgo6WYg7rLsNv93r/d9+qsvrOjk4LC5TDwMYXnX05
OpJ8QTmqTmn3JICtW7x9SPhz4gX2LMETQJCJlUKsp16bygZSyj6G3aRmPSFx
z6KwvVoELpPHwnt2yGJhkX5/cDA4YMT/3lmgxLFvvNTt6NI6p53gt4sTdW0X
gCnYXaan5ERWRDXmQaSjtjpnQ/+XPDHV3UV0x54Ct18ShnEmTUChnDddlkRO
PtHvd55ianF1T4xrq48xNBtE5sWG0TDwC6aVlbicKoniUCGiIe4f97WkPIRu
45hhog8avcJMRS9NmfQfTqJvNUCWGnSInEUSmBayV2nuUBygIqrI8D6qsDkN
INTp0OFt0oJPPv+AJHDI4YzHmPntuPrucK/HTYi77CImrWxZJw01M2jIRIUx
Bzw08geEKQN1dp0oyoL2dpYAHUhunOgqSbN2MxxSkMo0kx22Sz3lzW+3pIeO
19C7+QlHnY0HzzRwMVpW7hgZTMoTRJQEGlgq/m9HhKk7FgsZA9lJYnw+BqeJ
VatM9utcJMZFw7w5fjNUyYRlqXFFCUOkeh69PmLXsvxmV4LKDpY7ADH3tliq
m4SpulPWAE3opOXasXmaFulJ6CMPFF5o+yfrc7EknQwYIXKHFg4rCls0Z2vh
1xhzw+E1X/Dw5dNWLvxZJ2/38unDpwf1UwXogqfq4tlx4wDuHuiHj77ZozfC
F6R94xgeo/wb8Ga3uer49Pz5u/NzdQy8ZyIlIVJXpIHoyxFQR8IlTv8KJD/H
BIEDKmSBPXW6RUnBiHJiRgBtH5ojEoi6NbZx4U0kH8N5A4Uqu13PKlgRAIH1
2Umr+2kbf8bMY+jIZipTaiVKn3CmFxpzoYDwA8qhR8zNQk4O2rhg4ac5yLrJ
hBfll+FE+wafqs9DwsBgqYBruy9OLp7/qJIx/GLqkkcz8YVm8JZYK8GxR+cJ
g8ElcgaGRtaLIP7KTumrQAfqSQLSCvdaEhTvqHtI1VHFpIXEKR75lyUQka8y
nZT5VxuYkHve5RdTGme6D0VqoB7jqneP25ZO8E/8kku3qiLq4OfhzIufZvhm
K1fD+daez1wVA0cfDMf04DCRk7w2EBtuOQIItoWFFSuqxYxjyx5ssvaLjBh0
JQtr+J7vt+dH6ZBkbjwvrK92jUgsig7KSgDdayQXPPTLlqEj995MV87XyQ69
08rl00iWkI6OVo2X1RV49HxKsQhXoMIzNofxxDPrjLNhC5BU6hHy5XvVNiDX
a9gC9v3F2MIu9rb7+EAfTp9MIg2MxvkWDT2O0jdVsdNQ0Lfy1irJnbBLXIrW
feADoK3n9BLz0XPYJTREZLdWGosT3IINEBPKmUctyjdvulX9BBFVoNHHmu3I
lQ6ph+C5UGOX8SYkRXR/wJR5csWIApu5BlngCFGpEAweQBLdC8x4gYxFO7st
+7ljLXFA7xgKzgrXFLoasY51I5T1qoWzonPkDtKqgAE6U1EBFaT9szIhJ/UC
U9GpRJjx9VHE3sMBGmSToxpS8EM08yZRDmFOmEFw5D7xTFM1MNCa2KNAoPwE
BWiFceOzzs8qqarnWlgxSjXaBCLU73Xl4xzqeAv41eIbRywO/eMkbzH/B6Ds
NiJjCQGmaYbFzNyeFJEcJMCm5Hh2rNvmjNBYoAvlXIuQSiRrcQ4x94zOFHew
Iqq1FlwCA3aa+ry1HEhPMa5ONcw0JPtcmIahUDuGDbT/dYdRCFPrjGMdyVKL
2onr+LQLp6DCAlp3ALugunwBtOOqGJ3Ou0WxailiRRdSGi+oJ4yWydcXoii1
RchObBm7HBAKMLg3CTTiVmhQQRyQeEiH5v6YPxhfxoTVcbvZXvRLPbl2tmKr
Ik6sG7o11i3e0oiwhJTlEeNZg7a0kBLQl2JaEmiNOySF33F4ZTeKXuiqYU23
l1beM05NQkcztvj45ehboASuJF7Pbei2zQNxkgCHfjFpevvm/KKVMnUk7MwF
na2mN9uS8btjfwpKIVhNCcdwXQkpdXvLY0loQGG0xV2KucG8YWHpVPHjWpsW
kobWiKQxgiPWFNq5AbULQunajZj217ZAzA2YNVNCAvomhFAM3dyQSiCJrIGh
qaCRkVyE8rx2tscg2AzGajVp9Qiw2e1Q+VApCbwM0NxaggDnyF7wGqMU0MWL
hxkEjMWlEaGxKPPbyFyQjGCXggCAmk6CqixFA1zr3NW6iKtasLORqAmq5ybC
I7F9WZWVNYrlwtmMx6jj9yJXKY5CNgCglOks767Iyd7m6hSOnKJVSuizVFig
nOY1EbnROiSWFFPKaK0umyLS+W51xTr/GYVdTFwMqPNtjf1R5uFQgnOYEK4E
Z2nDL1tXKBbz9iR3OlZvEa/Iaa+9lBfEcWDRLCzstET7g831X+ZVmkVZdpdB
RR3QOYu51EFDk2Clts8DJTGoirCzIe/fB1ZpiY4XxIWRWAi/LJiGEhOw58MH
0VpH8XhZlmzPv78yh3M9MeVbsOfNOzCCkFDCGyzcyUxtkaSlqb0+X1IAAgcm
WZYsjgwcNTjLqyO9/Wnu+uOM1c1qTCsokoIb0aWDQ/UU2QfCswiTHF1ISBhL
WxSoxE/tVLlqXBitaeNNhDi7InEBNMlhQkRNT9w2CI2fFJpRVHCA8QxOJIbE
Cj6ia6cxPsgXYkoOeiOaKaKWPcmHg72Hahv47SidTHS+o3RZFmVta+hFsrfV
jM7WlR3yaKrtGggP1q8XTgLUsKXm0YHDPwOkOWMQyPgqnZJFg4oYTGKJKc0p
4ApTZKFBMctRyaI40TQ0vxAdJ+MKhpreIv2nAmWlDyC2XdWJ+5meJSXW4KKY
XLStb9YxbhRuO+06ByFAEwMg/F6dmnAnuLSV2LyY2eB5FqZNdY5w3Cmor983
TPYHxDI3lOkOYgGqvjkkRZHox/buIMouPrsc9JRPEoq88IHHO6FkGBw5lPmy
FI0dfYzo7QMpMYALm4uQTkDcV0Lc8GlExXDZrN1+7uLvX/0nrq8XtSTSgi2t
FWt/NNmbPJ58Ehhi01bNlbjCurUyjeCTDFwRu3NMkyL0B7FNIGkTNCMzgFOA
5ayhESqUtPG9TmCHaTG8Rjq9d2bVDGTJpN3babu8xxJWW+wXUcDZxbBSio6H
5KqWLZWMVgvSTK1XDOK4sbOjrEpA4HQhK+VwvopVT7nQAddB5CJnTjvF4sKR
6NBmMw/SgUVUjAwg/5dyUWZ8TQEpFI1s2oez/2METyrFhj8NDzhXyQSbFKeR
bJDqgvWGxYfdY1cAz9aekiKU87uW/HY3sWdG35lqb2IC2JCHCYn+BBp9L5F2
7WIyXafSrpnPhcA24Yxh4HnWJ2GoNrhtHZpHXJNaKD6245j2w/7eXhDT7mcQ
x43DC/t7e8JMm4ZcCmIIKnK1E++a/XKVDTefrrHeij87pDWBWzQm8avNuF+E
5K+xu4ZE3x5sMQZSaX7r3vGrQMKbGlc/Ky7yLgCwUG5SyMDHHVo2nEOzLoIl
9YRGnhtMbQt/6PP3rZ59MSnLRJxTjZwyieORPDs7P37D54riojxVXcE31i8u
1tXWOm5+LZf9DJUV9XJUzYUwV6vZaHtpyk9n1f+f0f17MDouE2zdqWzu+0LK
bquPb40lvs4VfzUT7AbkADnbXzyj6ynPpf62uR3+E8ffjLFuxjAb7OudlJcK
VPJ2zsVZ2w3N4+27uubRQV9OaQM5AEuzL8CWJGfcVoeo10Bu+BXlBR/aW5Pi
0VL+boW6QtbxH4sbTVd/CBWznLZmCAv2Rkr7101jGEg0ny/5FiM4rVXfF2al
kKn81p+cCiUX8QsrueKhorx3NI+OkLQBnZlYU0ujkugmRP8QiD71HNg3GwZL
pHUr/WNh4hha+cZEiZBSwqxx92/Q2xdCLcjzo0w9QM0UYz3mxcTRqcBvCCt5
7WzEyxBDo8NAkewcPxTlGI7xIqqMwkJcPYEgz8pwKIOseWm4i6BEHL0ZVWg/
T+cp3UeFletw/ygmqyYgBqFM9kYVpHNong5bYZmIYLDJQL0LvgUXFUmKgy0+
iuITWkwPaQsBPupFscyjTTQYlRHlVrmoyoeDg1XE9CEehX8iKf1nKxS/TvY/
eLKZ7H8Q0fdDJWfoX2Mr+39FEfvEzWA25kkFuadarV1CTDm1A2mWZFWkGHhm
yuUiTM/RtcOPJ3hR4BajKEvWdhc4g4YdNn6TYWiISbAvMTrYUqz2zFkiFUIl
Ckuw7CUNYeUgI/6vOq1BWXukqZodqB5ARWBcQsmYl/P9QGRckiEdaWwdLepG
pPTafjHJ32jqoaVfErS5zDjGcJQZRtfTfQUsihxjnZf77Z9cDqYeyydFYtqU
VHJ4Hp+8PLk4abe8fIZ9Es43TTdkovDqTwEC1qYfukl5spNeQz8g5uHr3bTH
QK/hVLhuyrAXLJh7y4AN9LGJvCbwlDCcNmQvxnMUn6Mpl+as4DCHAv5PsGId
KIGvHHIuw0gR0jhvXzb+7gHTVakXg+IHXlDpYhYaRRjnGmlBaua+zC/nA0ku
qBlGzmb7KSqF3pQ3pRZtU65sjwao3R3Tfo9gLX4kMrCTBmmz4NmbalWqPQyy
4pTbnZUzGCjCVTchrp3uqGQ4N18XPYotiMSMRGL76a64qGZ6EuXoBzU8Y4A4
ZZskNiF6JDvZsBhq78ie9/+T13+gnulpUdZaB9Xpe2scFLWpoMGK2YPhHV15
JCjxXu7P6F4mWC+KnWtd2cGUMwQNOt7ltjkJR4oTFzEbgMujga6A/JaS/m1K
QASGRZaMNShVEyGeuBK6KDGwJEcBFN3YaFSLiCAl7ivVhUUL+/MQwVAQV7W0
P8OrBkmnworDRHn9s0GXJBoMveCLWcjNgbE6ACOMGcTwGkQQ5ze59HcMtu6C
F4n4fk6sFoHtZUhGR4Av7tY230ImCQQTu7n2CgFJaaMRJUgl+Fk8zzsSoxID
IgyELFtAsarw2UVQnyPXyEuS8pbmuqCrHJFhYWA1pQq5IheSc+ELAgaAoXPh
C5w2cjPauU1QPQ7EEltU3LJSjwsx66KJ6xuPQzYjdpqWGHKJKFhTPtH3yVD/
8ejlC/X87OTo4uRYyEpQcxaH5NJwNimsotLhScMIfV+puMCIFxWJ44fBzYpS
3sQn2KzCuYHyan9YxhtfR6S51VVMqFfhbl6U3pDOd3RbQccnyZ2qWVEFp4UF
yr9XmJSdXRk1v3WJjqB9x3ctcoAh3rpNzsUtTkxTfAwSyXuhbaLLv4IaIxQs
JnJZPXKrRjeAVFPU3Y2W6yPtdOC9qkzHUszcpZiSbf7N65d/puPz4t1L+GSD
uHjCTC+hS9irLVghStSkiw98WEZrcV7FWLXyjwarv2NxkP9YnGj82hjo56Aa
eLC39V9FGOkE9w30fye3GsB/fttv/vlfw6dUhJZjMniID+4/bX+tv36or+ID
zrM2UDBJ+TWc5FYDEPwnlYit7EV/u2EDJ4k15gD//2++B+Xhumt/9a/gFY+7
9JDWtuWAydPcsh1+4JbuxXdMIKSl3eMPvD73lX7lpo1lblHnTCHdn/u6tRIw
8seC7XFc8xaJnC1566ku+dCo5zXVbY+mnD6xQgCtURyrrzJdRuErrI2FAfFM
qh1x5lMZUecNSDGNhSoVFYGhddRlUQxEFdXic0ivZI/GNNddabKKXnvxRbiX
TJyZgblHE7sHVLKzwsJIYL8sSrRaJrRHXMksqELLepVIQqcm3woDfuiebSky
RhXQRsmYIo4jdkmMkpTA0G53uPM97xEFFBnaItZV+stFpG/csMxURkYAN1S8
+dsgStM16ElY2KQ92pjkbmQRJHuL+mqNtoFQgBLlH/4wVK+LRog2plYaSvql
pG0vK1MU/sTq/vcJNE59jq8V5Jxyuu+ku2Jjumz74TpGLGy3jFrTtUtkfN/z
omrS8S1VNOD84X8f7Gsc5pqBAKXYxrtN28AawRznAlKtreTSLP0SCGald1AO
7gMTO9TWAqUpWvZarlEsKb3eeoxaZMPajhDpuUnSSq5WjK5zGYEmnYeKZFiP
mSogtAYNNi/WiYpfnLNyc2P3grbMKlAiEBqnP23NxQ3Nt4AT2AO/tmhKctXr
rTIJ1Ytr1SLCY8SB+lKVoNqauBhc9DOl0ymm8fsSC+zHKEq59LMoJ2kuzrdA
fbE6lb2GQaMTqNJhQbq15y3DGtoZh39cF5mzOshSgQqhEG5r3SVYucySIdD+
JC0UDyuKrrVEg4iUgTBLlRswBQShVnEOO1GQyGAi6Qw6M/qGL8amI3+6Gu3r
5wXREyXkoKCyiVKZrXBFpiz89DG86SROlq+XWfeZLxjwTztFNNoS1zCKJrpf
tCVZwumvtH8jly2H1LpvOwSAk5rgHjCFCscJ7G7+ViX8AUWetdaIuLRfbbqf
YXyr7YkUEvZJgSnnNNdYny3zMFCrE1Z8h4FFwUgh51WUBptTpVEkNPanmFd/
2QCfQ7XNYm9ktHJKLvlL7MVWkUXNT2iViGnrRnI5ExveInH3K9JomI/pUC6y
MkQLSq1DlFOrwfJWO+uhve8aU8QX7HOPqxKvgNXhYP8RwConMa3EOcROvcjK
L4P79HRbNiK6DbMqgElK2cXmiJ3DwcFTtX0BjV4h0ZaMDRMAiw2sTx7tPw4t
60h+ReLyo32yQ5dqSkRPxD3Y5s/c39+Lnbj5St/eEn95rrPAIYhxk48P9g8f
HewfHLjH1+jFezh4tCI5gY3+wZIpExFAlP8fte4nB988PGws+6C27EPRTSdB
XE7o4HDyW93p1eY16FtlzdcyIRdHw3mAWGkdCM5zQPdBB506msjilBnU/T0r
qNA9jD4iF7VAxLikr5vqRC7Fjub9ZsEBKW8qd4tBOkXuHjcIU8ObglNizHIe
0Pfo4pabpB4D6AmAt5WKcTAkZmpDYhaKJi7iQ8ioIwVYn7jhhojrqf1vMBzI
JZgUlwg8E4jtPE7usqylLkOJDlErq9LjexYLHSV3kYDGeacowVRkic5bYZw6
lx+6+wJHH06BknAQJV2hmVFF9xdbXxxoeeeXqC6dYsb3sH75GPJu9HzbTGHv
GIiCm2SpfpDISO7qAlEsJZqKsIhumSdZnw8Op5/UCnazVm8jNKUr3MGg5HGO
1c5JMsV5+6q2EQq1h8d6UuOENaCr54zweJ07HdCuHNAu3TIkZyEgFnRQrcHG
583agDKb4EJREkG8l2OqL5I0W2KZvyEjetcherdxEVzsLPQHslHqPYirrgdM
ROSKhOcKkUl2sxaJbH3eICY0fN4tyZ2Yx+yyXvMaMeKBE3iW8x3enJCOueNJ
5s5qYAlrJ0xTgJeeRB6FMzRWBOIdHidkE6RykOzt8rc3JNMNb9n3YeyfT59v
KeDud8Hez05Bv7E+aDdygBmdcLCpHhyn25PfuO92oU90w9zm48uyyNN/uOtv
qmJcZKt1UFfhXDI/P6Fk0OaCg2zwUO1tFP+LckX41v7e3t4+PnkF6Hs0wyeP
UPBguaM7IrEDOMJwoq+HhRnuP33YT4tq1wAwy+Jm95eivE7MrsgeLKWcJWmV
mn4GqwV+miX2x5qgIuLZ08cPD/dAWpGHKKXsPx08+aazaUhz25IO/t2WdLBv
lxTEPwfBNHcPgtCa1vuywtAbsSGObLypKw0butuoGLkN7UzzwKz7uJ2Q2Dpa
SEZ0SlYOJPxOhGuIbm+i2I991M9R8rNi35nGX+QSBJyBo1T2jPnYDDaaFGtn
GcpPQdhCF2810FW3CQBnCaIDL6EhZPNCg9ua6KRpJWauHKuD1INIWkJdEzsI
E0y8p3mO2n0sUEr5TIBEXuSsn9duimB6ldqqKAzMsBM2NbS86rRhcpGs6N/X
V9HEuoN7DkicYk5pb1K2AdKxDUukCnttamlDSsLwN3zTFY7zfLAb3+TQxf3e
KCc2tYII3R8SB6grIuoUgYm8zJd9q9UWV1hFf3orTDZkcmSxRuSwldjFduVi
j9qjmOKSwmIWTEFFU77UqPEhMr4HV8efDX8sPyGp+DMiAJmEZ0mat5UsWFf1
pLZNaEysojp4woz+ZfzOBVZGs797wDbxvn9G9M4rD3TdxOfHVDqZ+QvGUzbg
3hZGKSrUmkDKoPxFWxDoPyO+8gvE7ge3KnNdWib51rVnzbQ1jcj12tA7f12o
5mppaEX4JhXsBMIYBMMAEqK7wSNfwFVmYiOU5qFpMjRx3Ft6ILDShmelxbAb
3h6zBmNs9jZV0llgkhzdrlTpxX3FaVecgjWGkDgj09pAAvMDXzmKq3MKEZfM
oyLwkvjiDkx0YadQrc8xWDSjlje3V3x56fsThNOaKPpPNGcyzgec6bhAXx8W
kgMBaDJOyomhovbfdy6ramGGu7sz2OPliC5IoWSRm9kuXp8iSSO7nHSwe3hQ
tw4S5wjKtDUppYGVPrDDwkGjdIY6X0bLhg3vigyAdC/NImvlfWKdQ28d5kNl
Pn8LqFVClnGXnupuKuKUcXyxYzmUOkOEc1kTQBcw05BqrEtU93p1NaxfDiLJ
BG/n8wkbWK4dT0qgnNYujI/844EnB81iIvlw2ECK+eQclTpGKFKu26XOKCUP
r4CwUc9s/Z+jYT/yCZDgSI58pMtpQZIiDYMeRfENptVSQpapbpPnyZ/kaajb
Ej/R36DUUU11CX/mkeRA2fDz8AYo5+n0uZ3idGODQfOmN5b3WX4MdAzO1anK
2yjrEKUTYvEG0CAsQu5uexO+nFQB/KzBy/v/BPSNmwswpOifNVzXOtyZBNvo
4DQLLYWsg8A5sL7+zQw2LML+RAwNWUK3NuEu8CxX/J+Q+nugJRSZ5M1M1jpO
ATtcQyt0q1JIDAZM3H7PI3GNMbfRzoArU8Z+vqd5bYd+VMCNguq6upwrUd4K
daWBnc4xml+kGPLKB15lud8XUQXxDBFcmLKhYnhUjgzvCiz9NT+itzkntdzw
QUCfSz4e33UkrJRizpOJjXNFLRTjE4BQp/NE0lupVqXi67Axh5+lEV9vYAIo
U9SihDyCOGKxwensOYUUjYuslEJD3JyAFthN8mZEomMt4vOI0yUIj9J5iKSi
W9YON9VcxNoHaHJ8wPL/W+JN6q3P87XJOGF9AFFr3d1GbH42YXow+cTtRWj2
SOn3rF9OnLLjIFsv1FB3otsMa2rYuDAbz9vGfnaWu0l/5wI+ZjmfJ1iK3LAC
QAwkug+eEjivNIWXLE1kFLDCllDWBZU5xqTOKOOZweCv5F2TSMooAayaQGjN
uyZKvqbqZGgNEc92YHuXy4qsZYLubDT2uoKvG7HDX2/wuf9154N6jWgX/H1g
oPwRgGI/4x0HFM5LivEYw3Q7Hxojftjgcx9eVD4/1o548ex4336uTFXaz38B
JtX/E/z9TfkXfYz3B07fvf/FKH3Wvvhwgxd9Qm0w4qH9vMSqrOumWnvx0QYj
1jM46cXHm0y1lnVKL36zwVRr14Xyi0/uffGzUS4Kv0bi1Gfi1A+IEwdkd9tJ
V3d1SPYDVMSBxFS3qFkYYBz+fglgMmNXCRC6GF+mFRyqpS/2FkR9ORKY5kD+
08qySel8HHdOIgVN9u7Oy1VIbqzpl5/LHapBTTh68yc9orvlSKLGhk8OnjzB
hvjQFmGhH7igfM9RVao7f9a8IJQa82WcA7ycdD5f5k4GtTSaarO3k2lLqpgx
T3qKb5Z2msGb8+dvYGSe7OP9h3wD6fHFy3M79OE3KJmerwKYCBJECoX7j8NZ
OvOZ4bttFVecJbM7q4yBpaHIQ8NXyLZldSJgc95ZxffuAFvuV0Vf55PIQuff
JcMiXlcSufiEXSeVzV06zW1aIcd7W94/0tHNNsiPSywxwYGGSzQLVXaxcQKs
5ih+UWfEugx7hVW1nNky4DSgM92iGFrbo+dvzmWHnu4hPvbcl4f+y8OHTwhF
jsjcESbv2TDd2EwqeYYaL5wfi2Na7vVlh70zzVj/NCOr3wH3aiq2Nt0H0Yy9
3AlIviyh+fdRL8kkMYnlhkutfF0WDnbp+eBhC884JTA+dHH/Rd6uMfO2mkho
E0Elcu+6JC/ZMbQ1EejKYrYMbzKFScwxir8QVQEgZrBA+YKMOc6sI73VIO9v
cFLbpCTv2JPgBOy4WMKxzjEJFWBxjnZ5xDo0k5s4o1LOfcLSRVhModN5tkwz
e5/M3d1p/3iQ6mraT4CRYkVruoQRTy2iE5LIECfhoE3TLLp5KsiLi886V2pj
8hmNYiVU7guIjKSNGnIgCWmZF7DvypVwtQKWiE4b0vlepHDIHbSthCkkFt5X
QMXT+DYpi2X8di+8ECdEurWmDS6CvMymqRCguHAZBZuTGcLf4dZrkAW7BdQc
TxFXtqN2R89PgPcAQ6VYA9yko5gk4YyOZOZOI0OeWslhPcmv07LIeUbb0N+O
kJSDvT1hflZ9SLDM2mWBJ3jowbF2/YW7LTyAWf12AC67GBCQJKJi3248VjGi
Ko3YOSA21wuiO1Ayb0HGU46OKUqdDEKc50mezJr3jwujqdH0Nq6DJ2dDrmMN
yda63uOb7XHCpDpN2IwGp6JHzrlZSR9pxZsxHstc/TzFQEiXbpDAwGeMbhSX
BG4h6Q7cHoPW7A5ncEReUUcpbZQWrsEOwrSxheA7TTK+6yNCFlKE6c7ShlhI
d47XFd9LiQz3wVk2fwBnjR05LbCgyy9PJimsYGidFUDTOaMXi7eMObBKLgTs
3t39x/nJyxcfP3a9twC78HY2ti1K1U0PTOcjS423aHCOyytSQVFPA6qAy0zD
YomIrXJNq18QvULX11nc6vpeTLfDdSlIlvwNLdjrQlxIsKk6Rn+gRuj5InO5
smv+ItUy+gEGCTXoD6tud8UuAISom6Bk46cKlOgDKRu5vukH2pxoDnixdtdq
G6/1TQDIVUOhmnE3BJ6wAJT42KGmqMtiNFzwCkbljarwx/Ay2s6Zc0w5tQbb
vN496nTeuAsXmr+d5ONiIuc9wGP8fZTmWLhgm1R2DuesyFy2QgjHd+7urFb0
0V7jijCUnBkivaM0a383L3LAtrf+co8QYbnzaB+i/o88pOS8c8wk2e+tOQU7
YZGKAJmK9QnDeEJKYSmDrTzbi+oRrKANzvPLt8AnhvUGlFE8zXgBh4y1QH/H
cBMQtDFvoTM4p/+h9DzBO1Amk5JqjxZc1nbMGWs+E49THARSpMb99Hs1l1ur
yUG9jQakH1AWGhTlbAf9V0h7Ti5eqAh6uNgznWT9CzQOHgEw1DbwKP8m7ybR
0SXajmjEN69evXmNeMj1Aawg7Brw7rIEsMsF1CzlznSJLXAmsG6UyAzjq5AM
t6y8IOIU+/iEQFEB2gnR9ogsxY0t3+vc3cW5ISBysHWg1r6781siVmx8Cyqf
dlCQtDStF17d0w2lmrOT8wsMlo2lG9yfnU5ogTirU8fGgL2wTBFSS5kpE5cG
BbS/Pufj/UGdHtcoIxLDVeSP++g3KPCz46cBaVRMC1fRvhiUSOfofbpDjlRQ
ujQpSmRdIJM7ePR4MHj69OlAdnuFuRkZbT9wlMaGZ8u1EnPFHMvWRarhh62d
K5sH/ThGJcLMpvsZWZRcJ6TU2PiumAfDUUlcmD4OJKvkCgTx9RRh37Q0N8Cv
xbyWmdL1hct5bpzw4BolJde5Q1Y9VD4HoG7UZkrKeo9RWDSTnB4W90RCQIbC
ZnZ6xxm08xREDXsFFzpkQg1MC8sa4DysbdnPBZtwHB29BIfGGeXtZWt2VCMt
TWPkC9eJNZf4qwlJEOY6MbmeJfEzyiKuMGoR6SBehXzsdLqSCmzhLGRUZFFe
5QupHYyGdVLxBlAyie0fkGP2lIex79O56cNxQXgePHoUaovBHGjITOczEA73
JQ2AQs4rhk/3vML7aDAw4YijjvBSbHXyHjMhgWBgTbXuisEfP3r0kIaHaXzD
Ijo+lznhr496G0zroHVa0WmxEk5zJjPi1xT7mfOQG4wYvdQ6/D3rz6QUeG6B
QOW/k/JKXn9bptcoMLwzuutRla93ZkNceN82/UhSSYCkgk4UyejTa91Z5OAl
0YnJpAzv96wniH5bkCOX5H0fH0mzcXygPpvGeGyuqtEu5+Dm/i7CedHVUqnE
XyyKxTILrxDVIcnlRJh2oz2LeKvKjlNUmSihpGFYjlBWbdRf503SLxtpiWfU
ndouq+92yGCuLjjY6qiCaY+WsKX/lV7sbkCDgcR/FrdAlwaN4q4C7xxrZyEc
2rTxvg8GekYyZifYVu9d6dT6GuB9kHGHF5Ky7O6J9LFjGIjyq8fLp+3jtdb5
+BJDUthYy5CxK5xGGq3rl0MYgTBixkumJzO2maHcwwq2nny3lRdb4gZyOU+w
r84gEloCgnOG5higvFTaj0RhxK6US5r/MUuWRv0IcveV3jJygym0Y4PmJT3v
VwdVOQMgliCsSyXMj9Z2a+lCM8pVDJxkxKnKJVsyQ4Lp3nChf9Q4LGlBvJnC
YkQixeVwoezQQppkQlS5XwyRsXX6YI2voGWhLtKsGCdbpm6rLQyJwLN5n4w6
dOjJ0UYqhA1It7XPaC5Ija/U86QEOS9Xz1DszPMeQDFHSFyY8WUx1Xk666n/
RMvT+aXORiC7vypgvupcw0b11FsK9rymsrKlOq+Kqx5McQ4yBqxzBq8egeID
w5+U6ZUx6DH4PcAf8yayBH+B7tKrK4zl+CXJNfz8Jkum6pkuZzgZ9uGZMYDp
dXFdWDKaMldxOesWE2wgMXIgM+j8L8hzFSKIygAA

-->

</rfc>
