<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.29 (Ruby 3.4.4) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-webtrans-overview-10" category="std" consensus="true" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.29.0 -->
  <front>
    <title abbrev="WebTransport">The WebTransport Protocol Framework</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-webtrans-overview-10"/>
    <author initials="E." surname="Kinnear" fullname="Eric Kinnear">
      <organization>Apple Inc.</organization>
      <address>
        <email>ekinnear@apple.com</email>
      </address>
    </author>
    <author initials="V." surname="Vasiliev" fullname="Victor Vasiliev">
      <organization>Google</organization>
      <address>
        <email>vasilvv@google.com</email>
      </address>
    </author>
    <date/>
    <area>Applications and Real-Time</area>
    <workgroup>WEBTRANS</workgroup>
    <abstract>
      <?line 36?>

<t>The WebTransport Protocol Framework enables clients constrained by the Web
security model to communicate with a remote server using a secure multiplexed
transport.  It consists of a set of individual protocols that are safe to expose
to untrusted applications, combined with an abstract model that allows them
to be used interchangeably.</t>
      <t>This document defines the overall requirements on the protocols used in
WebTransport, as well as the common features of the protocols, support for some
of which may be optional.</t>
    </abstract>
    <note>
      <name>Note to Readers</name>
      <?line 48?>

<t>Discussion of this draft takes place on the WebTransport mailing list
(webtransport@ietf.org), which is archived at
&lt;https://mailarchive.ietf.org/arch/search/?email_list=webtransport&gt;.</t>
      <t>The repository tracking the issues for this draft can be found at
&lt;https://github.com/ietf-wg-webtrans/draft-ietf-webtrans-overview/issues&gt;.
The web API draft corresponding to this document can be found at
&lt;https://wicg.github.io/web-transport/&gt;.</t>
    </note>
  </front>
  <middle>
    <?line 59?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>The WebTransport Protocol Framework enables clients constrained by the Web
security model to communicate with a remote server using a secure multiplexed
transport.  It consists of a set of individual protocols that are safe to expose
to untrusted applications, combined with an abstract model that allows them
to be used interchangeably.</t>
      <t>This document defines the overall requirements on the protocols used in
WebTransport, as well as the common features of the protocols, support for some
of which may be optional.</t>
      <section anchor="background">
        <name>Background</name>
        <t>Historically, web applications that needed a bidirectional data stream between a
client and a server could rely on WebSockets <xref target="RFC6455"/>, a message-based
protocol compatible with the Web security model.  However, since the
abstraction it provides is a single ordered reliable stream of messages, it
suffers from head-of-line blocking, meaning that all messages must be sent and
received in order even if they could be processed independently of each other,
and some messages may no longer be relevant.  This makes it a poor fit for
latency-sensitive applications which rely on partial reliability and stream
independence for performance.</t>
        <t>One existing option available to Web developers are WebRTC data channels
<xref target="RFC8831"/>, which provide a WebSocket-like API for a peer-to-peer SCTP
channel protected by DTLS.  In theory, it is possible to use it for the use
cases addressed by this specification. However, in practice, it has not seen
wide adoption outside of browser-to-browser settings due to its dependency on
ICE (which fits poorly with the Web model) and userspace SCTP (which has a
limited number of implementations available due to not being used in other
contexts).</t>
        <t>An alternative design would be to open multiple WebSocket connections over
HTTP/3 <xref target="RFC9220"/>.  That would avoid head-of-line blocking and provide an
ability to cancel a stream by closing the corresponding WebSocket session.
However, this approach has a number of drawbacks, which all stem primarily from
the fact that semantically each WebSocket is a completely independent entity:</t>
        <ul spacing="normal">
          <li>
            <t>Each new stream would require a WebSocket handshake to agree on application
protocol used, meaning that it would take at least one RTT to establish each
new stream before the client can write to it.</t>
          </li>
          <li>
            <t>Only clients can initiate streams.  Server-initiated streams and other
alternative modes of communication (such as the QUIC DATAGRAM frame
<xref target="RFC9221"/>) are not available.</t>
          </li>
          <li>
            <t>While the streams would normally be pooled by the user agent, this is not
guaranteed, and the general process of mapping a WebSocket to a server is
opaque to the client.  This introduces unpredictable performance properties
into the system, and prevents optimizations which rely on the streams being on
the same connection (for instance, it might be possible for the client to
request different retransmission priorities for different streams, but that
would be much more complex unless they are all on the same connection).</t>
          </li>
        </ul>
        <t>WebTransport avoids all of those issues by letting applications create a single
transport object that can contain multiple streams multiplexed together in a
single context (similar to SCTP, HTTP/2, QUIC and others), and can also be used
to send unreliable datagrams (similar to UDP).</t>
      </section>
      <section anchor="conventions-and-definitions">
        <name>Conventions and Definitions</name>
        <t>The keywords "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD",
"SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this
document are to be interpreted as described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/>
when, and only when, they appear in all capitals, as shown here.</t>
        <t>WebTransport is a framework that aims to abstract away the underlying transport
protocol while still exposing a few key transport-layer aspects to application
developers.  It is structured around the following concepts:</t>
        <dl>
          <dt>WebTransport session:</dt>
          <dd>
            <t>A WebTransport session is a single communication context established between a
client and a server.  It may correspond to a specific transport-layer
connection, or it may be a logical entity within an existing multiplexed
transport-layer connection.  WebTransport sessions are logically independent
from one another even if some sessions can share an underlying
transport-layer connection.</t>
          </dd>
          <dt>WebTransport protocol:</dt>
          <dd>
            <t>A WebTransport protocol is a specific protocol that can be used to establish
a WebTransport session.</t>
          </dd>
          <dt>Datagram:</dt>
          <dd>
            <t>A datagram is a unit of transmission that is limited in size (typically to
the path MTU), does not have an expectation of being delivered reliably, and
is treated atomically by the transport.</t>
          </dd>
          <dt>Stream:</dt>
          <dd>
            <t>A stream is a sequence of bytes that is reliably delivered to the receiving
application in the same order as it was transmitted by the sender.  Streams
can be of arbitrary length, and therefore cannot always be buffered entirely
in memory. WebTransport protocols and APIs are expected to provide partial
stream data to the application before the stream has been entirely received.</t>
          </dd>
          <dt>Message:</dt>
          <dd>
            <t>A message is a stream that is sufficiently small that it can be fully buffered
before being passed to the application.  WebTransport does not define messages
as a primitive, since from the transport perspective they can be simulated
by fully buffering a stream before passing it to the application.  However,
this distinction is important to highlight since some of the similar protocols
and APIs (notably WebSocket <xref target="RFC6455"/>) use messages as a core abstraction.</t>
          </dd>
          <dt>Application:</dt>
          <dd>
            <t>A WebTransport application refers to executable code that is provided by a
developer to perform some, often user-visible, function, such as sending and
receiving data. For example, a JavaScript application using WebTransport that
is running inside a browser or code running within an executable that makes
outgoing or accepts incoming WebTransport sessions.</t>
          </dd>
          <dt>Server:</dt>
          <dd>
            <t>A WebTransport server is an application that accepts incoming WebTransport
sessions.  In cases when WebTransport is served over a multiplexed protocol
(such as HTTP/2 or HTTP/3), "WebTransport server" refers to a handler for a
specific multiplexed endpoint (e.g. an application handling specific HTTP
resource), rather than the application listening on a given TCP or UDP
socket.</t>
          </dd>
          <dt>Client:</dt>
          <dd>
            <t>A WebTransport client is an application that initiates the transport
session and may be running in a constrained security context, for instance,
a JavaScript application running inside a browser.</t>
          </dd>
          <dt>Endpoint:</dt>
          <dd>
            <t>An endpoint refers to either a Server or a Client.</t>
          </dd>
          <dt>User agent:</dt>
          <dd>
            <t>A WebTransport user agent is a software system that has an unrestricted
access to the host network stack and can create transports on behalf
of the client.</t>
          </dd>
          <dt>Event:</dt>
          <dd>
            <t>An event is a notification, callback, or signal that a WebTransport endpoint
can provide to a WebTransport application to notify it that some change of
interest to the application has occurred.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="common-requirements">
      <name>Common Transport Requirements</name>
      <t>Since clients are not necessarily trusted and have to be constrained by the
Web security model, WebTransport imposes certain requirements on any specific
protocol used.</t>
      <t>All WebTransport protocols MUST use TLS <xref target="RFC8446"/> or a semantically
equivalent security protocol (for instance, DTLS <xref target="RFC9147"/>).
The protocols SHOULD use TLS version 1.3 or later, unless they aim for
backwards compatibility with legacy systems.</t>
      <t>All WebTransport protocols MUST require the user agent to obtain and maintain
explicit consent from the server to send data.  For connection-oriented
protocols (such as TCP or QUIC), the connection establishment and keep-alive
mechanisms suffice.  STUN Consent Freshness <xref target="RFC7675"/> is another example of
a mechanism satisfying this requirement.</t>
      <t>All WebTransport protocols MUST limit the rate at which the client sends data.
This SHOULD be accomplished via a feedback-based congestion control mechanism
(such as <xref target="RFC5681"/> or <xref target="RFC9002"/>).</t>
      <t>All WebTransport protocols MUST support simultaneously establishing multiple
sessions between the same client and server.</t>
      <t>All WebTransport protocols MUST prevent clients from establishing transport
sessions to network endpoints that are not WebTransport servers.</t>
      <t>All WebTransport protocols MUST provide a way for the user agent to indicate
the origin <xref target="RFC6454"/> of the client to the server.</t>
      <t>All WebTransport protocols MUST provide a way for a server endpoint location to
be described using a URI <xref target="RFC3986"/>.  This enables integration with various
Web platform features that represent resources as URIs, such as Content
Security Policy <xref target="CSP"/>.</t>
      <t>All WebTransport protocols MUST provide a way for the session initiator to
negotiate a subprotocol with the peer when establishing a WebTransport session.
The session initiator provides an optional list of subprotocols to the peer.
The peer selects one and responds indicating the selected subprotocol or
rejects the session establishment request if none of the subprotocols are
supported. Note that the semantics of individual subprotocol token values is
determined by the WebTransport resource in question and are not registered in
IANA's "ALPN Protocol IDs" registry.</t>
    </section>
    <section anchor="session-establishment">
      <name>Session Establishment</name>
      <t>WebTransport session establishment is an asynchronous process.  A session is
considered <em>ready</em> from the client's perspective when the server has confirmed
that it is willing to accept the session with the provided origin and URI.
WebTransport protocols MAY allow clients to send data before the session is
ready; however, they MUST NOT use mechanisms that are unsafe against replay
attacks without an explicit indication from the client.</t>
      <section anchor="application-protocol-negotiation">
        <name>Application Protocol Negotiation</name>
        <t>WebTransport sessions offer a protocol negotiation mechanism, similar to
TLS Application-Layer Protocol Negotiation Extension (ALPN) <xref target="RFC7301"/>.</t>
        <t>When establishing a session, a WebTransport client can offer the server a list
of protocols that it would like to use on that session, in preference order.
When the server receives such a list, it selects a single choice from that list
and communicates that choice to the client.  A server that does not wish to use
any of the protocols offered by the client can reject the WebTransport session
establishment attempt.</t>
      </section>
    </section>
    <section anchor="transport-features">
      <name>Transport Features</name>
      <t>All transport protocols MUST provide datagrams, unidirectional and
bidirectional streams in order to make the transport protocols interchangeable.</t>
      <section anchor="features-session">
        <name>Session-Wide Features</name>
        <t>Any WebTransport protocol SHALL provide the following operations on the
session:</t>
        <dl>
          <dt>establish a session</dt>
          <dd>
            <t>Create a new WebTransport session given a URI <xref target="RFC3986"/> of the requester.
An origin <xref target="RFC6454"/> MUST be given if the WebTransport session is coming
from a browser client; otherwise, it is OPTIONAL.</t>
          </dd>
          <dt>terminate a session</dt>
          <dd>
            <t>Terminate the session while communicating to the peer an unsigned 32-bit
error code and an error reason string of at most 1024 bytes.  As soon as the
session is terminated, no further application data will be exchanged on it.
The error code and string are optional; the default values are 0 and "".  The
delivery of the error code and string MAY be best-effort.</t>
          </dd>
          <dt>drain a session</dt>
          <dd>
            <t>Indicate to the peer that it expects the session to be gracefully terminated
as soon as possible.  Either endpoint MAY continue using the session and MAY
open new streams.  This signal is intended to allow intermediaries and endpoints
to request a session be drained of traffic without enforcement.</t>
          </dd>
        </dl>
        <t>Any WebTransport protocol SHALL provide the following events:</t>
        <dl>
          <dt>session terminated event</dt>
          <dd>
            <t>Indicates that the WebTransport session has been terminated, either by the
peer or by the local networking stack, and no user data can be exchanged on
it any further.  If the session has been terminated as a result of the peer
performing the "terminate a session" operation above, a corresponding error
code and an error string can be provided.</t>
          </dd>
          <dt>session draining event</dt>
          <dd>
            <t>Indicates that the WebTransport session has been asked to drain as soon as
possible.  Continued use of the session, including opening new streams is
discouraged, but allowed.</t>
          </dd>
        </dl>
      </section>
      <section anchor="features-datagrams">
        <name>Datagrams</name>
        <t>A datagram is a sequence of bytes that is limited in size (generally to the path
MTU) and is not expected to be transmitted reliably.  The general goal for
WebTransport datagrams is to be similar in behavior to UDP while being subject
to common requirements expressed in <xref target="common-requirements"/>.</t>
        <t>A WebTransport sender is not expected to retransmit datagrams, though it may
end up doing so if it is using TCP or some other underlying protocol that only
provides reliable delivery.  WebTransport datagrams are not expected to be flow
controlled, meaning that the receiver might drop datagrams if the application
is not consuming them fast enough.</t>
        <t>The application MUST be provided with the maximum datagram size that it can
send.  The size SHOULD be derived from the result of performing path MTU
discovery.</t>
        <t>In the WebTransport model, all of the outgoing and incoming datagrams are
placed into a size-bound queue (similar to a network interface card queue).</t>
        <t>Any WebTransport protocol SHALL provide the following operations on the
session:</t>
        <dl>
          <dt>send a datagram</dt>
          <dd>
            <t>Enqueues a datagram to be sent to the peer.  This can potentially result in
the datagram being dropped if the queue is full.</t>
          </dd>
          <dt>receive a datagram</dt>
          <dd>
            <t>Dequeues an incoming datagram, if one is available.</t>
          </dd>
          <dt>get maxiumum datagram size</dt>
          <dd>
            <t>Returns the largest size of the datagram that a WebTransport session is
expected to be able to send.</t>
          </dd>
        </dl>
      </section>
      <section anchor="features-streams">
        <name>Streams</name>
        <t>A unidirectional stream is a one-way reliable in-order stream of bytes where the
initiator is the only endpoint that can send data.  A bidirectional stream
allows both endpoints to send data and can be conceptually represented as a pair
of unidirectional streams.</t>
        <t>The streams are in general expected to follow the semantics and the state
machine of QUIC streams (<xref target="RFC9000"/>, Sections 2 and 3).
TODO: describe the stream state machine explicitly.</t>
        <t>A WebTransport stream can be reset, indicating that the endpoint is not
interested in either sending or receiving any data related to the stream. The
sender of a stream can indicate an offset in the stream (possibly zero) after
which data that was already sent will not be retransmitted.</t>
        <t>Streams SHOULD be sufficiently lightweight that they can be used as messages.</t>
        <t>Data sent on a stream is flow controlled by the transport protocol.  In addition
to flow controlling stream data, the creation of new streams is flow controlled
as well: an endpoint may only open a limited number of streams until the peer
explicitly allows creating more streams.  From the perspective of the client,
this is presented as a size-bounded queue of incoming streams.</t>
        <t>Any WebTransport protocol SHALL provide the following operations on the
session:</t>
        <dl>
          <dt>create a unidirectional stream</dt>
          <dd>
            <t>Creates an outgoing unidirectional stream; this operation may block until the
flow control of the underlying protocol allows for it to be completed.</t>
          </dd>
          <dt>create a bidirectional stream</dt>
          <dd>
            <t>Creates an outgoing bidirectional stream; this operation may block until the
flow control of the underlying protocol allows for it to be completed.</t>
          </dd>
          <dt>receive a unidirectional stream</dt>
          <dd>
            <t>Removes a stream from the queue of incoming unidirectional streams, if one is
available.</t>
          </dd>
          <dt>receive a bidirectional stream</dt>
          <dd>
            <t>Removes a stream from the queue of incoming bidirectional streams, if one is
available.</t>
          </dd>
        </dl>
        <t>Any WebTransport protocol SHALL provide the following operations on an
individual stream:</t>
        <dl>
          <dt>send bytes</dt>
          <dd>
            <t>Add bytes into the stream send buffer.  The sender can also indicate a FIN,
signalling the fact that no new data will be send on the stream.  Not
applicable for incoming unidirectional streams.</t>
          </dd>
          <dt>receive bytes</dt>
          <dd>
            <t>Removes bytes from the stream receive buffer.  FIN can be received together
with the stream data.  Not applicable for outgoing unidirectional streams.</t>
          </dd>
          <dt>abort send side</dt>
          <dd>
            <t>Sends a signal to the peer that the write side of the stream has been aborted.
Discards the send buffer; if possible, no currently outstanding data is
transmitted or retransmitted.  An unsigned 32-bit error code can be supplied
as a part of the signal to the peer; if omitted, the error code is presumed
to be 0.</t>
          </dd>
          <dt>abort receive side</dt>
          <dd>
            <t>Sends a signal to the peer that the read side of the stream has been aborted.
Discards the receive buffer; the peer is typically expected to abort the
corresponding send side in response.  An unsigned 32-bit error code can be
supplied as a part of the signal to the peer.</t>
          </dd>
        </dl>
        <t>Any WebTransport protocol SHALL provide the following events for an individual
stream:</t>
        <dl>
          <dt>send side aborted</dt>
          <dd>
            <t>Indicates that the peer has aborted the corresponding receive side of the
stream.  An unsigned 32-bit error code from the peer may be available.</t>
          </dd>
          <dt>receive side aborted</dt>
          <dd>
            <t>Indicates that the peer has aborted the corresponding send side of the
stream.  An unsigned 32-bit error code from the peer may be available.</t>
          </dd>
          <dt>all data committed</dt>
          <dd>
            <t>Indicates that all of the outgoing data on the stream, including the end
stream indication, is in the state where aborting the send side would have no
further effect on any data being delivered.</t>
          </dd>
          <dt/>
          <dd>
            <t>For protocols, like HTTP/2, stream data might be passed to another
component (like a kernel) for transmission. Once data is passed to that
component it might not be possible to abort the sending of stream data
without also aborting the entire connection.
For these protocols, data is considered committed once it passes to the
other component.</t>
          </dd>
          <dt/>
          <dd>
            <t>A protocol, like HTTP/3, that uses a more integrated stack might be able to
retract data further into the process. For these protocols, sending on a
stream might be aborted at any time until all data has been received and
acknowledged by the peer, corresponding to the "Data Recvd" state in QUIC;
see <xref section="3.1" sectionFormat="of" target="QUIC"/>.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="transport-properties">
      <name>Transport Properties</name>
      <t>WebTransport defines common semantics for multiple protocols to allow them to
be used interchangeably.  Nevertheless, those protocols still have
substantially different performance properties that an application may want to
query.</t>
      <t>The most notable property is support for unreliable data delivery.  The
protocol is defined to support unreliable delivery if:</t>
      <ul spacing="normal">
        <li>
          <t>Resetting a stream results in the lost stream data no longer being
retransmitted, and</t>
        </li>
        <li>
          <t>The datagrams are never retransmitted.</t>
        </li>
      </ul>
      <t>Another important property is pooling support.  Pooling means that multiple
transport sessions may end up sharing the same transport layer connection, and
thus share a congestion controller and other contexts.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>Providing untrusted clients with a reasonably low-level access to the network
comes with risks.  This document mitigates those risks by imposing a set of
common requirements described in <xref target="common-requirements"/>.</t>
      <t>WebTransport mandates the use of TLS for all protocols implementing it.  This
provides confidentiality and integrity for the transport, protecting it from
both potential attackers and ossification by intermediaries in the network.</t>
      <t>One potential concern is that even when a transport cannot be created, the
connection error would reveal enough information to allow an attacker to scan
the network addresses that would normally be inaccessible.  Because of that, the
user agent that runs untrusted clients MUST NOT provide any detailed error
information until the server has confirmed that it is a WebTransport endpoint.
For example, the client must not be able to distinguish between a network
address that is unreachable and one that is reachable but is not a WebTransport
server.</t>
      <t>Since WebTransport requires TLS, individual transport protocols MAY expose
TLS-based authentication capabilities such as client certificates.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>There are no requests to IANA in this document.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
        <reference anchor="RFC8446">
          <front>
            <title>The Transport Layer Security (TLS) Protocol Version 1.3</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>This document specifies version 1.3 of the Transport Layer Security (TLS) protocol. TLS allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</t>
              <t>This document updates RFCs 5705 and 6066, and obsoletes RFCs 5077, 5246, and 6961. This document also specifies new requirements for TLS 1.2 implementations.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8446"/>
          <seriesInfo name="DOI" value="10.17487/RFC8446"/>
        </reference>
        <reference anchor="RFC6454">
          <front>
            <title>The Web Origin Concept</title>
            <author fullname="A. Barth" initials="A." surname="Barth"/>
            <date month="December" year="2011"/>
            <abstract>
              <t>This document defines the concept of an "origin", which is often used as the scope of authority or privilege by user agents. Typically, user agents isolate content retrieved from different origins to prevent malicious web site operators from interfering with the operation of benign web sites. In addition to outlining the principles that underlie the concept of origin, this document details how to determine the origin of a URI and how to serialize an origin into a string. It also defines an HTTP header field, named "Origin", that indicates which origins are associated with an HTTP request. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6454"/>
          <seriesInfo name="DOI" value="10.17487/RFC6454"/>
        </reference>
        <reference anchor="RFC3986">
          <front>
            <title>Uniform Resource Identifier (URI): Generic Syntax</title>
            <author fullname="T. Berners-Lee" initials="T." surname="Berners-Lee"/>
            <author fullname="R. Fielding" initials="R." surname="Fielding"/>
            <author fullname="L. Masinter" initials="L." surname="Masinter"/>
            <date month="January" year="2005"/>
            <abstract>
              <t>A Uniform Resource Identifier (URI) is a compact sequence of characters that identifies an abstract or physical resource. This specification defines the generic URI syntax and a process for resolving URI references that might be in relative form, along with guidelines and security considerations for the use of URIs on the Internet. The URI syntax defines a grammar that is a superset of all valid URIs, allowing an implementation to parse the common components of a URI reference without knowing the scheme-specific requirements of every possible identifier. This specification does not define a generative grammar for URIs; that task is performed by the individual specifications of each URI scheme. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="66"/>
          <seriesInfo name="RFC" value="3986"/>
          <seriesInfo name="DOI" value="10.17487/RFC3986"/>
        </reference>
        <reference anchor="QUIC">
          <front>
            <title>QUIC: A UDP-Based Multiplexed and Secure Transport</title>
            <author fullname="J. Iyengar" initials="J." role="editor" surname="Iyengar"/>
            <author fullname="M. Thomson" initials="M." role="editor" surname="Thomson"/>
            <date month="May" year="2021"/>
            <abstract>
              <t>This document defines the core of the QUIC transport protocol. QUIC provides applications with flow-controlled streams for structured communication, low-latency connection establishment, and network path migration. QUIC includes security measures that ensure confidentiality, integrity, and availability in a range of deployment circumstances. Accompanying documents describe the integration of TLS for key negotiation, loss detection, and an exemplary congestion control algorithm.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9000"/>
          <seriesInfo name="DOI" value="10.17487/RFC9000"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="CSP" target="https://www.w3.org/TR/CSP/">
          <front>
            <title>Content Security Policy Level 3</title>
            <author>
              <organization>W3C</organization>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="RFC6455">
          <front>
            <title>The WebSocket Protocol</title>
            <author fullname="I. Fette" initials="I." surname="Fette"/>
            <author fullname="A. Melnikov" initials="A." surname="Melnikov"/>
            <date month="December" year="2011"/>
            <abstract>
              <t>The WebSocket Protocol enables two-way communication between a client running untrusted code in a controlled environment to a remote host that has opted-in to communications from that code. The security model used for this is the origin-based security model commonly used by web browsers. The protocol consists of an opening handshake followed by basic message framing, layered over TCP. The goal of this technology is to provide a mechanism for browser-based applications that need two-way communication with servers that does not rely on opening multiple HTTP connections (e.g., using XMLHttpRequest or s and long polling). [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6455"/>
          <seriesInfo name="DOI" value="10.17487/RFC6455"/>
        </reference>
        <reference anchor="RFC8831">
          <front>
            <title>WebRTC Data Channels</title>
            <author fullname="R. Jesup" initials="R." surname="Jesup"/>
            <author fullname="S. Loreto" initials="S." surname="Loreto"/>
            <author fullname="M. Tüxen" initials="M." surname="Tüxen"/>
            <date month="January" year="2021"/>
            <abstract>
              <t>The WebRTC framework specifies protocol support for direct, interactive, rich communication using audio, video, and data between two peers' web browsers. This document specifies the non-media data transport aspects of the WebRTC framework. It provides an architectural overview of how the Stream Control Transmission Protocol (SCTP) is used in the WebRTC context as a generic transport service that allows web browsers to exchange generic data from peer to peer.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8831"/>
          <seriesInfo name="DOI" value="10.17487/RFC8831"/>
        </reference>
        <reference anchor="RFC9220">
          <front>
            <title>Bootstrapping WebSockets with HTTP/3</title>
            <author fullname="R. Hamilton" initials="R." surname="Hamilton"/>
            <date month="June" year="2022"/>
            <abstract>
              <t>The mechanism for running the WebSocket Protocol over a single stream of an HTTP/2 connection is equally applicable to HTTP/3, but the HTTP-version-specific details need to be specified. This document describes how the mechanism is adapted for HTTP/3.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9220"/>
          <seriesInfo name="DOI" value="10.17487/RFC9220"/>
        </reference>
        <reference anchor="RFC9221">
          <front>
            <title>An Unreliable Datagram Extension to QUIC</title>
            <author fullname="T. Pauly" initials="T." surname="Pauly"/>
            <author fullname="E. Kinnear" initials="E." surname="Kinnear"/>
            <author fullname="D. Schinazi" initials="D." surname="Schinazi"/>
            <date month="March" year="2022"/>
            <abstract>
              <t>This document defines an extension to the QUIC transport protocol to add support for sending and receiving unreliable datagrams over a QUIC connection.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9221"/>
          <seriesInfo name="DOI" value="10.17487/RFC9221"/>
        </reference>
        <reference anchor="RFC9147">
          <front>
            <title>The Datagram Transport Layer Security (DTLS) Protocol Version 1.3</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <author fullname="H. Tschofenig" initials="H." surname="Tschofenig"/>
            <author fullname="N. Modadugu" initials="N." surname="Modadugu"/>
            <date month="April" year="2022"/>
            <abstract>
              <t>This document specifies version 1.3 of the Datagram Transport Layer Security (DTLS) protocol. DTLS 1.3 allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</t>
              <t>The DTLS 1.3 protocol is based on the Transport Layer Security (TLS) 1.3 protocol and provides equivalent security guarantees with the exception of order protection / non-replayability. Datagram semantics of the underlying transport are preserved by the DTLS protocol.</t>
              <t>This document obsoletes RFC 6347.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9147"/>
          <seriesInfo name="DOI" value="10.17487/RFC9147"/>
        </reference>
        <reference anchor="RFC7675">
          <front>
            <title>Session Traversal Utilities for NAT (STUN) Usage for Consent Freshness</title>
            <author fullname="M. Perumal" initials="M." surname="Perumal"/>
            <author fullname="D. Wing" initials="D." surname="Wing"/>
            <author fullname="R. Ravindranath" initials="R." surname="Ravindranath"/>
            <author fullname="T. Reddy" initials="T." surname="Reddy"/>
            <author fullname="M. Thomson" initials="M." surname="Thomson"/>
            <date month="October" year="2015"/>
            <abstract>
              <t>To prevent WebRTC applications, such as browsers, from launching attacks by sending traffic to unwilling victims, periodic consent to send needs to be obtained from remote endpoints.</t>
              <t>This document describes a consent mechanism using a new Session Traversal Utilities for NAT (STUN) usage.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7675"/>
          <seriesInfo name="DOI" value="10.17487/RFC7675"/>
        </reference>
        <reference anchor="RFC5681">
          <front>
            <title>TCP Congestion Control</title>
            <author fullname="M. Allman" initials="M." surname="Allman"/>
            <author fullname="V. Paxson" initials="V." surname="Paxson"/>
            <author fullname="E. Blanton" initials="E." surname="Blanton"/>
            <date month="September" year="2009"/>
            <abstract>
              <t>This document defines TCP's four intertwined congestion control algorithms: slow start, congestion avoidance, fast retransmit, and fast recovery. In addition, the document specifies how TCP should begin transmission after a relatively long idle period, as well as discussing various acknowledgment generation methods. This document obsoletes RFC 2581. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5681"/>
          <seriesInfo name="DOI" value="10.17487/RFC5681"/>
        </reference>
        <reference anchor="RFC9002">
          <front>
            <title>QUIC Loss Detection and Congestion Control</title>
            <author fullname="J. Iyengar" initials="J." role="editor" surname="Iyengar"/>
            <author fullname="I. Swett" initials="I." role="editor" surname="Swett"/>
            <date month="May" year="2021"/>
            <abstract>
              <t>This document describes loss detection and congestion control mechanisms for QUIC.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9002"/>
          <seriesInfo name="DOI" value="10.17487/RFC9002"/>
        </reference>
        <reference anchor="RFC7301">
          <front>
            <title>Transport Layer Security (TLS) Application-Layer Protocol Negotiation Extension</title>
            <author fullname="S. Friedl" initials="S." surname="Friedl"/>
            <author fullname="A. Popov" initials="A." surname="Popov"/>
            <author fullname="A. Langley" initials="A." surname="Langley"/>
            <author fullname="E. Stephan" initials="E." surname="Stephan"/>
            <date month="July" year="2014"/>
            <abstract>
              <t>This document describes a Transport Layer Security (TLS) extension for application-layer protocol negotiation within the TLS handshake. For instances in which multiple application protocols are supported on the same TCP or UDP port, this extension allows the application layer to negotiate which protocol will be used within the TLS connection.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7301"/>
          <seriesInfo name="DOI" value="10.17487/RFC7301"/>
        </reference>
        <reference anchor="RFC9000">
          <front>
            <title>QUIC: A UDP-Based Multiplexed and Secure Transport</title>
            <author fullname="J. Iyengar" initials="J." role="editor" surname="Iyengar"/>
            <author fullname="M. Thomson" initials="M." role="editor" surname="Thomson"/>
            <date month="May" year="2021"/>
            <abstract>
              <t>This document defines the core of the QUIC transport protocol. QUIC provides applications with flow-controlled streams for structured communication, low-latency connection establishment, and network path migration. QUIC includes security measures that ensure confidentiality, integrity, and availability in a range of deployment circumstances. Accompanying documents describe the integration of TLS for key negotiation, loss detection, and an exemplary congestion control algorithm.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9000"/>
          <seriesInfo name="DOI" value="10.17487/RFC9000"/>
        </reference>
      </references>
    </references>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+1cWXMjx5F+719Rph52xgFgTuvgrNemSI413jm4JMcKh+1Q
FBoFsDyNbri7QQysmP+++WVmHQ02JVmr2CfrQUOCjaqsPL88qqfTadH7vnLH
5vrGmW/d/Lq1dbdp2t5ctE3flE1lXrZ27XZN+6Gw83nrbo8HzxWLpqzpgWOz
aO2yn3rXL6c7N+/xwLS5de2td7vpk8fFwvb01PdnJ9fnn4qSflk17f7YdP2i
wOqrttluaO3zr68vT95eFYXftMemb7dd//Tx468ePy1s6+yxOdlsKk9f903d
GVsvzKWz1fTar11RdD198J2tmpp22ruu2Phj8xc6xsR0RGvrlh39tF/jh78V
hd32N017XJhpYeg/X3fH5nxm/tvXtbMtfyZHO299Ofi4aVdCiTOv6nLGn7m1
9dWxcR/kud9b/HlWNutisMGfZuZPtvOVd7fZDn/yZd+0w7/QJrb2/+SjHps/
NM2qcvlOt3j49vb3K/6L7OTrZdOu6Su3js5lTq8ujvkrvW1Xrj82N32/6Y4f
PdrtdrPdsxlt8ej68hE99kgeE2U4Om3q3tW9uXLltvX93lw0xPS9ee1uXWWe
HfHDkX0msuTbZ6f8q8j6WxKrr1fmDJpRFNPp1Nh5R5pR0m8/QeGMq+28cp0p
iSd1T/+SzOnrvnYLM9+bXpYoukDlulkQeX1DD67X2xpq4szO9zfGmtatG/qt
I4V0rdl2IMwa/qoz623VexLXR7co+kDRzJhXPe/pO9q8WfLzPX7w9cLf+sXW
VmajZHdEju0NKanp7NKBCvdx03SuoJ+2NSsykW0z9Z2AzjmfRoisI3/CUXjJ
qmp2WN6tsdbcEfX0FU8iassbW68ccWk/A0t9Z8get2vIbuGWtDR/z8AOaRli
wj+2njjB3Gxq/ls6gC5b5GKZGNuZnaPvWlkKrKVvLp3tiXPMlsEqZGDbDQuU
NJHMjuySHtnd+PLGrO0e5DcbHN9WM9GJmuTy3Vv8r2++I2teuLYrijPflduu
owdlCxwNekSq/IG23VS2dOEIAz2CcUC4FUmteBBcEf70ezgn6PzDiRJEi1ri
IVkLSaYv/vqfwT6wiP5lFr71CB886hz/8zs2wu+wyW/zPf76XzPR7daR8D0Z
NekpSZQNAbT6rtsS/WBOdqiSZE+cWTbb+oCSFWnGdg7rfiS+dRXd66MfcrmP
ZCPQA3Lo7+bk4lXYrmlJdpuG1BhkNUpKUJ37qdn5cjVTknzziFadxqM/4rND
omu/WJCvKj4j79i3zWJbQuD/tvl/2zxs/rPPzNdkEAj49aIoviFONxRgidb9
hPU055ewo3ZuAUaauV/QWUpZC2GGxENx3a5pj37nHHGzEM1hbGCD7MtmWy2I
FdUeLKDDXjXlB0cM+f77312+PP38+W9+8+kTndusXdfZlZvOLTGmCCcEBzZE
EGmmiE3V0AzVkLTnm2ZHMbIljviaHBQ9VwT5wpX5HlwjNSIuwvngMQreFD3J
6zmm0EP/w6mIjUoRMdn3RbddLsk9mmXbrM0N+cpps5ySu3NmXjXsZCb0BYIN
7G1EkeIKpPJdD2F0yp+CWOnY+flaSDBEPFHJ8t0r1+Ys6ZIW4QcXbuPof3UP
Xi6NsyTkhh5vJwVYDulnO5L068YQIlvR4nO4xcrd2hqGxqq7Zm9ObLFm05Dy
LD0rUVGRGdflfkqkkhclGodaIboV5Lmxbe9tpdwj908CYVqYiUWiuXSsoRvX
Mkyi30kf3xH33EfSQjBN9NTYWwQACIKsD4JeAPk0G/Ae5k4fXV6figLCHmtX
dYXo0pdfPnsCXRISVdp0vKh0JK8Pjp0xaKFzO9dO+2aKf83V6fVFoSuygZGy
i+c7u359BffEFkxhBfoAHSJ/03mllKzZCANZQ+lXQtodMdguFq0IkH0ofa3b
uNIvlaGzpLekCRvW1tLxDjfkAyhCk864utjxURbKpGbbd/iAtGDekruSY+iP
cJvgKHmnLdPmydqiHCC24tXpuXkgbFrir1AAEujAwNiuHrI06TRtt0HYB5PC
N0GfLSq/9uBTvV3PaW+46zX5dji9kCpEiSo9ONTcQebqA0WLixLY92PfPSTV
OCFNqMjl1oyoifzOr2qzC2ZBq5BK1DGUJBkjhNTipzr2xMU319cXj56pv/nq
6dPHnz6xDZCNynr2tvGLcZvm40dNqoug44h6UOLKJDdIVls1XUAbw0CfyCOd
ALSaFVHurBRkY21jA1czbhJs2M3JaXdBr+FXKLitiSy/tq0nucEnFdh0iWDG
3qcjlFT34tvFUyQS2P3Br1auhx1nnoVAAGUi++Oi+LU5x7dqtwsH3Kkn56CW
mxXRXC+6G/In4ItdtY7xYeY2KDWJDh0yP3CVPkgCCJNgj6mcJX9JyaS5vL7m
4E4J5pwg3w2fhZbL6Jo7sjonTJcABBS1o+Cg2j+jw7yrq31CNvR3X5NzA2KR
VTpSiSuOWNPwl+DFJNkVFTUDrYSJcExOCAjW+aDbQk4Swf/n/atTQ6n3yR8u
T96QpAht0SpRGclhPWS/BqOIlgKKv73xlZwqkCE8quE/IVVEh6apEjqDmRL7
6YiqVJ4dCG232lqCGL0D53EYPE3PAaaECMMBj0QmSC3JFhINsdx3tFazsf8Q
O04cDzHFK+gkrmzrDYVVSq7Z8jO/jw3p1947rEbfkIW6PZR6ogaHYAjQRO5u
rYn4YejJOSPehPWMPyYmZ37APIBb9jWKFOpb13510wsH1YcHz60q1De0FnSd
NM8sPGI/Pm4dA9a1l/yITJAAFI7C30/PKWETM9+KQdJq0XmtoR5r6KwY4Udi
VgURcOiHMsDGwxGHZ4FvHAB5dl6dfAPgoelipkNqUUkoGIbwkmjrXYRACYOb
Zv53FzwIjAQemRKA5GYDwzMIT6xaORgHHLktFFapLydbIAFSQgd9QfCYGHbH
TydiGNGyuocieuxqqy4Cb2BwQiIUg+qI0BD7Vy3IyFd/f3bxUDDuaVNDfWKd
6gzY3PPvkgl9cHvKeIhrR2/eX10fTeRf8/Yd/3x5TqRdnp/h56tvTl6/jj+E
J66+eff+Nf290J/SN0/fvXlz/vZMvkyfmoOP3pz8+UgOevTu4vrVu7cnr4/A
N5hrEZMJqIDkHpx2kDlwMoMo3pWtn0vQ/Pr0wjx5Tq7kV+RKnj558tWnT/rL
l0++eP7pU7G7cbVs1sD7ya+iY5sNJdMsMNKb0m58b5FM0BbdTbOrKRi27lDT
OGwsY7ooINeTFOAiQiZld1adEcUTwhTs42PJMgaBHTs3An60PSdu4naW5NVJ
OOkb08ru4dSAmXrZKYsqCRpK9ghwRalfiVyJ+MVpDhOzbJDVYQ/Sy9Jt+u74
4HAalunjY3Nixv40yBqGDj8oe4xS8MkxKzJmJC8SggHSE1BQX6vw8JAJWCe6
gYmBR+tDjmcJ568Q7DV+M5KDdOuEr/Os29zhcFqaKBs7vqBv3WYIGmg5zooQ
r23N5hyzGU5K4hKwbgIK8HB1piE/TM+BpIIOsagOZRUVTIQVWBk/jp4t5PU5
tkAB1Y4enmg4U6ejGhJ8kGxEqsCVikFwEGjTmYCQSR6d/6czD/r9RpnIUYYT
ekvI+831e/KCi8YJ7r+xt04kCOUXTQPg51hH2JwQSJa47tnSEVHJTNjBo4DU
rHUnhQip3FIUV+zL9TyKpYRtCHuI1Nht37suHiXslW2v4VvyWZFlZqLi2zSK
SZ5rOencAR4Jt/o+QRi4ejYOIQ4IQaWFglA79/SdFmGtXvU3Ecu0ggDpSUZR
FfkgYAIKvhyPF2wVwA0MOAh7UvDdz8Y1R0IG5Yii8MJ8OWfIAzTppcWUa5yM
KiPyw2fIVJ8Eup/DLQSKTCgEkEDeSO6uEtFMXkUiXw9yQDHCl15KAR3gYATS
oYK4ZakrA4hUpUW0Z2O7LskuI/nQ+KMySn0rlhcgZdCFHISLBKHswo5goGnA
fuy+gZiluCEkUuzeotjA1O0HFGu5cIDvQTM+9/043SGfYotCaY79nhZ/OmSl
RIxlaGduCP5VDAGFavZSWlsLkCIqBM4aVOIB8YINIAHkvI71kOsAsQZjJdGC
u0uVKCS3ifCxgJOrEKk2Kh9c33TlVtB0SXlH1AXVSjYhBJsYFFllBXfzASlm
LHtSPaQJ01vPsHdCbK81ooSsBTaoqS9jYDVs1vKZeUmBx320wK2o2v2RcpYr
wiSbIdlS8R2cSlEwvMi25tyPELkUaELhomnlaOGBPIrFw/O5uXiFZGTbrxrG
/uRYSo7stCxF5zvbhxgEx8cReDzUa57D1eHsPAJ2fmgDeIOwBdeKpPwD0GUO
YRRvs+DqBAqfGZYOSkerxSxSADNOKJUMihFHI1QfZbpiOSWvaHkudIG2EArz
3UjQG+IeoXQ3W80Oz8xL4Jjxu9ifVaJrtm3piJDWcrQn9tR3vB86NK6WxIwo
WnlAgmsCrUQSgXUQxRZEEjllgDQmEYVO90gkpOrd0OUkWbDlKkhKasdWmZob
sZSsOG5iBvki7P8+Pb9PlelM58pcOVWdmJ2ZtGfuWa08sBIb4QUt8D6m82OM
Scm+Rggy7h33QziRFv5wManm3IlO60txttDjrgtelDJGlPl7BvV05PJDTMQ0
UYx85S7G3N3YagnbW+YVADrwrctOexspI5cZy50TAziCehYjWBT1bGi8DM8X
2KUIIMReVu57vaUUF/1yz1GC62Dw7NK3IYKl4ODAjbF4DXY1JSlDy/EYmSS3
X9Jml3lLx3z/mfRnpnmn5xM5GA4qodoUqjuEZxEYuGIXG1TEacZ5ku7dbbkV
d3sdkwN/skbfi7C1azlXP+w62XofLbgYVOEQiQg53AODOCVGOLt+fRXyyufP
P6ckk9U0LzAW2PLWVlz5CLTGrQ6qL2eyHte/njz/goKm9EnTzppUh73JMtiU
n8yeYWtAhnYyLJn4NbcuoFdkA4sudo2kWst17cqtbLlX8+h+wtlDpXNYWuPS
85w5Lb7Fc4mkIKBIeuSlhYnnIhLSoBIKGRJGOY6mJGfatFCWrPHVpQCgPhMF
k4cTLS7H2lbMXtYhxfzg3GZqgc+LtYPq+24dIKMDtL5+/xY1EqbyJdnCTQ1O
iki++PwLwjHibzWTk2AP60GTThckRN/7bin5/Q2nBlHtfgJvOSeSxIFLUb0W
97IKHJjVCbek16pqgXS35MKZJNq33nLlwC0gfmkfgkEEwGJy3jZVIr2IjJUj
/+bzL5+IVqtWPn78lLXyR08Req+MZEm9XbPtUG4PIsnT7iImwaEykKp7qTyg
xYEf31pLpNHJsLYNNk7RMO4M96iOPrjXrJEOHzWCK36KqaReG8o/WRMsMxp0
8TEiwI0KUvcVWZC4FcLOzyGAPJ4E9/wvMOSQhFi2jpG3amKcKOYuq6aFAYX3
l6+Upmdfffm59olI9cJoBIIHZf28BjuVW3LnJHT20hvyTAy2Y7eeWds6klUn
xWPBTZwY0FZdwtw69lUcjn395fTq4m8/WwCxciUwCZ82Re1WjXQ+iEHbeSrJ
heYfd0MZtw706b7KyPXoRrHXTrE7TCAwIoSYs20jDMGuGggc9zArrvhJTQlV
Di6RdUGNQptNngOIy45CoaB1f5eKYUbd0FWG4r5fkubXKf3LaSOzKNTIKVwa
jEqJUGVZiYDdwYxKTknffCA+Umjc8thBsXAUvNYHIzWJqUFDgFGZugBhg322
bgVU3croyKuTtyf/0Zmjk9cXb9NEz6uz7kgfbPcMY66UAec5A8YLoAdMUtzd
7evypm1qUvXQL5qh9pZKowVP7sgoxXcEGxf771IEFJMmSvNSAGtYFh8BvmiR
pW/XKPtrOYMI2Pmq0mEpycAGQk1qG/Jg9S1gGxnZbLx6SHZz8mcZ9ok+NI/Q
g9pNOiWf7AVh5ti7JfgRmgea/MeQGz3rtuYhJbuygEHwCJXdF7YH2O74BJTH
aqlPQETQcsz+DLkoLY6sgpAE/1Ytmye+xmu4DaorXLfR79TpO4n0iUl9lQIQ
LNtu+prrs2ObmvOPPYZG0HGDSj4MmOLZYwqwqOOOOBUlbXLoX7JWrhCdqYqV
EUMyu4N5sNhI5kEPHcsIyWLciQctHHfqSq1KzoS2bA+ty3XqonlHbh0Gz5R6
ATeNT5UvdK9BHOdQaTBOCdRnD5unJxEk4qFYdNuh4S2nKADjD6e/hDPJl2Q8
E/9318MoE4oD2NgTJt6wbmXJzkuNYxJ++h+LPbEtB3A+mBZDJWk4Pxb6iHH6
iU655gGCYekw7jScv3NiBerXpt9i+0At0rIQgad63E8YKNnf0yqQ1l5MMAft
ItTRtGsq/dgiNYrSTELUYsp9T0NzFRMKox5WCiF3wUYQrwYmKKVBKj2GlZjx
BGFkLZkau7drJdWq0KVJ5TZRlxfSgCVdc2GwKbQmicsSrhQtxENex08Hrpib
ellrLEy4akznSgRSftLYZ0+nc4/k3rVtKPtxoKv1E2JjR2uibAE5LJEjrFGq
ePL46XNpS8BwyD4bxEiO9FndB12QQORigkm45baVakvmOtnTI76Al+6j6Bfa
pTw1YvhuxgGBShDcesA1L/iIC7e0hPVDsMcDj6XTe8Qw0nFtltsm0ZLH10Zk
QveClGDqlkvp1ixaTjkzIbxSQD3gcXCD0rcY4h+pMZCJlk6K7YlDUs8PrAxD
EUT3uZSoIoQGbciofL11CpvzLXAKeoTHREgx05ROF6C0lnxkWATdHml7ciBm
I6fo7wlVO2nExDwFZf0mgrbIB5xooRUTacAhzY0x1eFWRhmz0p/lA2QWhQw+
8jGyTf6WyaJL8HDUGmP/J1dOLQNqwceIIJvwAWctVUjcuB7bc/0M7KkbybJk
HFL6Krkeo+DVcwlI1R+16eVAZCMkSeOC/Cf0OQQdxy1obSgEuR+N+Iej5DWN
nTe33CcYjsOx3nND+9Ds1QT0KAHTzRLzWdhRLD+H9bb7IEqnJhX1HsdLmn+q
Wr4QEDFgGjBEWW0XGiKYnkzXZVBq4buS0DwlwAuZA2Ill8riZ+YsDrHk8SrG
UESsgybz/W3ZOx1mne3iDnPsLxfoLzO3ZS5s0Nucu0E7NjR6xXPFWbFVQ/9D
pW3YJIxH8Z2uFfCjl3rxrW/CjI5GCelDUqoEmFLoJYLmoHpJBLZh+Jni31ix
FbDyThMHPeSxQ8bprT4HK/AUqxudpih41mhDGIzpaxBbJSiKs9NanDQM2Wyz
QZfhmAGGboqYB6fpJY0Bd1qtkYsh2TuQz5K0p9BqVnVnhjI14YkmGW9btM0m
F87ysOBdKI+Qu22DTa/NEsOXrgZX9EpNHjMD9Ij5VszA1vajX2/XSW1ZGbPG
dAHRqErx31JJj3jI4/Ax20neJ3M5YUyiYNtiLhbFq7GrSFIoj1NxLnUK2QBC
B2/A9IKvNi1kJtEyhdM5zxCR4VG4y6fNbKykcdBaYji6tK0++vBnB5sfApyc
nNpIM/m+85q367JPgwFmNTQurWj45V5Kg1qTZ/+gbPZhdDIuo2MmpEIbsESY
KHygZYAf6IyqcEOizlwgqr7L6AmWQrnFd/m4a7FyPevP9o4C0YqXjrxjLWCm
wn3Krhf9Udmms480krLs3RyaVLhnwHopKYV68EESIZ+xSz7IbPKxGTrVFNW3
aOkeZX24onSlRPz2DiMrLNxUMPN6dwiTehFtxXGlvHNwYsZyqUIvLs3JK+XV
3bymEfp60mlCKWWrSqAlyhD6N9a3SK9HT9upU4jT0S3Xq0KMyFksen1QLQsD
yARjelesbXnjpfzGE6Fh1QexGP8Ydzquwkj/U/7+MzSN3p29O45F3HzKhlc2
YeVQVOFbW4exQr6gTAETkOTnJUZ1rVEkOlMd2ogSmxTBhcmJps3GJgC+mPuk
F7ZPUzey9YwzAw1ZcuktkRRK5kaKILgO5/PBZ/NA8cre/NO1DQX3JVFVSCtF
hpL4lgNkWnHpSvwCZzxyCyOLiT1Dk2AAyTUPho14ambnOL4E5uwHE3W0WRiA
0bE52ZSHAJK9LLnyFqPZnQG16C5lmsIuFjzBC6gw+KoA4jiGpf0xJOE6LzfE
ZYf7Fnrh7pghaBAyJgbYEjmLsebuJZew4pZ0ukoAOelauEgopKARhHJiSoZe
hkCX10QHLZBJEYb4D6wzBSYXQhNXoNXVJiv95UNQHB0f9Qyx/CFl/xBxR599
IW3DlCrwlAau3SSeomSRiSuwZwxxKbeXMhYbuulyxQVqHQkf9Z3jdI89+v9M
dgqw9zH80q2bW5fNCEYEdVczxt15FpJRBsiCctr9Hq79K5uPFgDv3/uX0F1C
nHlfJsy7ckDkSIxZlYX+nF1F0SjCj/E8YsCs4qbjHYXkn83LV28xKCTVjSqk
x+k+Vt2wIxoUnHiDwU0W2uctX9hRwB0upvyIBDNRhWMFycjR0iyCHC0+HU5H
5KcgqDdTw70OXF0JED/ztELrIaU/bPSg1M5DkmbQMCJar7jTb+M00GE5C7/J
da5w6TEjJaX1c+nSEbl4gwGPgfQqND3oC2hbSPG5KMizPnKhdtvzS0wCWBWN
zHNijup5sOTq7EFFMy/phTnXLVgUamyWx4fTsOnhkZnGRnaYHBYJNRZs1zLD
z+7iceRpkOq/wFaAgp/F1aEGvUhLA8fG+fYcCwqN4h6H1aCoC4bHl/B5534i
d2Fzyt+fwt3/YxFQ5grqrNtbDL2KTAEKz8ZrU8wknsuTpyTgD/iRy1GPEmfN
f5Qty4QrUAjQ+yEjTv0XITUd+henE7m7lDWbtZjDXSrH8nv+zsCr5tU6xfJp
dj91WidSlE65ieZpfPpU6A4HlkYjD+/VuMYR+guODKLsw+Sd9pIHVzZmmJF8
2WQj5hNpWIarcfm1gnRTMc7s62QW29GaJAF0/YAXsOaDa2tc2+YRkOw2ysy8
Q+lQPdvgAgCPZaeV4u1ITRDyW+7RhlOqs8yp1VDB3WwEyAHr5MrD4GaPjMHR
H7vBOy0CldlMQVQCg8SV3+aAI4TxETQcmPvxHDOZmQ2r5hx+NhHt2fL9fAHm
YbKHb/1iBjbyXWsEPPcsd9yYvCDuiBriXMTokSK/5EaY8izbRCzMSrG+92un
eDKaQXTJMUDLgD4RWzc7SmVWKYuCTU3G3jXjzBFnZJeuvF0cqZqTziP1fsHt
M2e+/16TbfNs9gQC/hX++tuYjB90iS/Sdd6DsrC+EkUru6kAAN2MN0oHg0A2
lAvWOqI1+u4VAh6YvqDHMALKBdyc2XqtEJZZdNs5oroWu9L93PH7yOpUhoPm
cE07uTdSEKpt91r+4GakXAeJa+zlck56I8vBrdW8+Iu8P7+uJuximwwr5N8O
nUO/5Mv5l64LV3sTqEMpL7qwCvTlniR/G4j0gwdwRu6P/ZqB7kEt2slAxLBQ
cKLzoeliTc4E3EyXCv9G3+5zoZ+gaq2cjrOR/WG1Tt5forV43BiM/hcDk+nx
w8uCcoj+ZtuFe4Yjo6AV96IX0WPIWyd0Ukrn707V9Vi9NnzBqECAbRjeDnND
8Z1H6Fjz7SDS4mnFb2wbztprzbggk3D6vdZ3H2JzNN4AxqWqlcY5KDc/Bevm
ae8wOQOgU4w1Tgb3hO9vnBy8vatexKsU2vLC7A9Dnip/9VJ8wYdcx1LiU6uD
p7gWUmIOL4QR/4rfwnBiFOIkvG1Fb3fx2yy4jBkL1UZmpfgdMBAc6Ui4UcBM
GfaN1QCU2fqembQWlz5bGRGAFvJVVZ5Gs5lm6WXCuRaTFIwX+eQ1g5nwVoxb
x7dvpZUU3gUoTXfxanAregq2cfRDMjLji2KUqrsve/C1KJP2J792pY2dSdsL
efnILQ+fEgIb0dg4sZZebYI7nT2hLzS1uTubHyJVucaG9WKLh8vgo7c4ZsXg
3lgqcsmbkZTToRwvV/dWW8zWxHvU0XiUUbH7CS9pKTzgy3LZPV2OS39BA1bb
XUMaizhiLNc2DgYy2WQ6WMIkH/IcnYY6+XN4Cxk9rpPoeFej44sS4oLsRt4h
4+NoWRfnthCFloJv2RthvvOOJ7oWUMo9wjAPwQ6Gn9Z3CURPou+Fw2h88b8n
nbiSdVQAAA==

-->

</rfc>
