<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.7 (Ruby 3.2.2) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-core-comi-17" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.20.0 -->
  <front>
    <title abbrev="CORECONF">CoAP Management Interface (CORECONF)</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-core-comi-17"/>
    <author initials="M. V." surname="Veillette" fullname="Michel Veillette" role="editor">
      <organization>Trilliant Networks Inc.</organization>
      <address>
        <postal>
          <street>610 Rue du Luxembourg</street>
          <city>Granby</city>
          <region>Quebec</region>
          <code>J2J 2V2</code>
          <country>Canada</country>
        </postal>
        <email>michel.veillette@trilliant.com</email>
      </address>
    </author>
    <author initials="P." surname="van der Stok" fullname="Peter van der Stok" role="editor">
      <organization>consultant</organization>
      <address>
        <phone>+31625097806</phone>
        <email>stokcons@kpnmail.nl</email>
        <uri>https://vanderstok.tech</uri>
      </address>
    </author>
    <author initials="A." surname="Pelov" fullname="Alexander Pelov" role="editor">
      <organization>IMT Atlantique</organization>
      <address>
        <postal>
          <street>2 rue de la Châtaigneraie</street>
          <city>Cesson-Sevigne</city>
          <region>Bretagne</region>
          <code>35510</code>
          <country>France</country>
        </postal>
        <email>alexander.pelov@imt-atlantique.fr</email>
      </address>
    </author>
    <author initials="A." surname="Bierman" fullname="Andy Bierman">
      <organization>YumaWorks</organization>
      <address>
        <postal>
          <street>685 Cochran St.</street>
          <street>Suite #160</street>
          <city>Simi Valley</city>
          <region>CA</region>
          <code>93065</code>
          <country>USA</country>
        </postal>
        <email>andy@yumaworks.com</email>
      </address>
    </author>
    <author initials="C." surname="Bormann" fullname="Carsten Bormann" role="editor">
      <organization>Universität Bremen TZI</organization>
      <address>
        <postal>
          <street>Postfach 330440</street>
          <city>Bremen</city>
          <code>D-28359</code>
          <country>Germany</country>
        </postal>
        <phone>+49-421-218-63921</phone>
        <email>cabo@tzi.org</email>
      </address>
    </author>
    <date year="2024" month="March" day="04"/>
    <area>Applications</area>
    <workgroup>CoRE</workgroup>
    <abstract>
      <?line 97?>

<t>This document describes a network management interface for constrained devices
and networks, called CoAP Management Interface (CORECONF). The Constrained Application
Protocol (CoAP) is used to access datastore and data node resources specified
in YANG, or SMIv2 converted to YANG. CORECONF uses the YANG to CBOR mapping and converts
YANG identifier strings to numeric identifiers for payload size reduction.
CORECONF extends the set of YANG based
protocols, NETCONF and RESTCONF, with the capability to manage constrained devices
and networks.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://core-wg.github.io/comi/draft-ietf-core-comi.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-core-comi/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        core Working Group mailing list (<eref target="mailto:core@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/core/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/core/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/core-wg/comi"/>.</t>
    </note>
  </front>
  <middle>
    <?line 108?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>The Constrained Application Protocol (CoAP) <xref target="RFC7252"/> is designed for
Machine to Machine (M2M) applications such as smart energy, smart city, and building control.
Constrained devices need to be managed in an automatic fashion to handle
the large quantities of devices that are expected in
future installations. Messages between devices need to be as small and
infrequent as possible. The implementation
complexity and runtime resources need to be as small as possible.</t>
      <t>This specification describes the CoAP Management Interface (CORECONF) which uses CoAP methods
to access structured data defined in YANG <xref target="RFC7950"/>. This specification is
complementary to <xref target="RFC8040"/> which describes a REST-like interface
called RESTCONF, which uses HTTP methods to access structured data
defined in YANG.</t>
      <t>The use of standardized data models specified in a standardized language, such
as YANG, promotes interoperability between devices and applications from
different manufacturers.</t>
      <t>CORECONF and RESTCONF are intended to work in a stateless client-server fashion.
They use a single round-trip to complete a single editing transaction, where
NETCONF needs multiple round trips.</t>
      <t>To promote small messages, CORECONF uses a YANG to CBOR mapping
<xref target="RFC9254"/> and numeric identifiers <xref target="I-D.ietf-core-sid"/>
to minimize CBOR payloads and URI length.</t>
      <section anchor="terminology">
        <name>Terminology</name>
        <t>The following terms are defined in the YANG data modeling language <xref target="RFC7950"/>: action, anydata, anyxml, client, container, data model, data node, identity, instance identifier, leaf, leaf-list, list, module, RPC, schema node, server, submodule.</t>
        <t>The following terms are defined in <xref target="RFC6241"/>: configuration data, datastore, state data.</t>
        <t>The following term is defined in <xref target="I-D.ietf-core-sid"/>: YANG schema item identifier (YANG SID, often shortened to simply SID).</t>
        <t>The following terms are defined in the CoAP protocol <xref target="RFC7252"/>: Confirmable Message, Content-Format, Endpoint.</t>
        <t>The following terms are defined in this document:</t>
        <dl>
          <dt>data node resource:</dt>
          <dd>
            <t>a CoAP resource that models a YANG data node.</t>
          </dd>
          <dt>datastore resource:</dt>
          <dd>
            <t>a CoAP resource that models a YANG datastore.</t>
          </dd>
          <dt>event stream resource:</dt>
          <dd>
            <t>a CoAP resource used by clients to observe YANG notifications.</t>
          </dd>
          <dt>notification instance:</dt>
          <dd>
            <t>An instance of a schema node of type notification, specified in a YANG module
implemented by the server. The instance is generated in the server at the occurrence
of the corresponding event and reported by an event stream resource.</t>
          </dd>
          <dt>list instance identifier:</dt>
          <dd>
            <t>Handle used to identify a YANG data node that is an instance of a YANG "list",
specified with the values of the key leaves of the list.</t>
          </dd>
          <dt>single instance identifier:</dt>
          <dd>
            <t>Handle used to identify a specific data node which can be instantiated only
once. This includes data nodes defined at the root of a YANG module and
data nodes defined within a container. This excludes data nodes defined
within a list or any children of these data nodes.</t>
          </dd>
          <dt>instance-identifier:</dt>
          <dd>
            <t>List instance identifier or single instance identifier.</t>
          </dd>
          <dt>instance-value:</dt>
          <dd>
            <t>The value assigned to a data node instance. Instance-values are serialized into
the payload according to the rules defined in <xref section="4" sectionFormat="of" target="RFC9254"/>.
In a yang-instances data item, the reference SID applying to the
instance-value is provided by the SID in the corresponding instance-identifier.</t>
          </dd>
        </dl>
        <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
        <?line -18?>

</section>
      <section anchor="example-syntax">
        <name>Example syntax</name>
        <t>CBOR is used to encode CORECONF request and response payloads. The CBOR syntax
of the YANG payloads is specified in <xref target="RFC9254"/>, based on <xref target="RFC8949"/>
and <xref target="RFC8742"/>.
The payload examples are
notated in Diagnostic notation (defined in <xref section="8" sectionFormat="of" target="RFC8949"/> and
<xref section="G" sectionFormat="of" target="RFC8610"/>), which
can be automatically converted to CBOR.</t>
      </section>
    </section>
    <section anchor="comi-architecture">
      <name>CORECONF Architecture</name>
      <t>This section describes the CORECONF architecture to use CoAP for reading and
modifying the content of datastore(s) used for the management of the instrumented
node.</t>
      <figure anchor="archit">
        <name>Abstract CORECONF architecture</name>
        <artset>
          <artwork type="svg" align="left"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="384" width="536" viewBox="0 0 536 384" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
              <path d="M 8,32 L 8,64" fill="none" stroke="black"/>
              <path d="M 8,112 L 8,144" fill="none" stroke="black"/>
              <path d="M 8,192 L 8,272" fill="none" stroke="black"/>
              <path d="M 80,144 L 80,184" fill="none" stroke="black"/>
              <path d="M 128,192 L 128,272" fill="none" stroke="black"/>
              <path d="M 256,64 L 256,104" fill="none" stroke="black"/>
              <path d="M 320,192 L 320,368" fill="none" stroke="black"/>
              <path d="M 336,256 L 336,288" fill="none" stroke="black"/>
              <path d="M 336,320 L 336,352" fill="none" stroke="black"/>
              <path d="M 440,144 L 440,184" fill="none" stroke="black"/>
              <path d="M 512,256 L 512,288" fill="none" stroke="black"/>
              <path d="M 512,320 L 512,352" fill="none" stroke="black"/>
              <path d="M 528,32 L 528,64" fill="none" stroke="black"/>
              <path d="M 528,112 L 528,144" fill="none" stroke="black"/>
              <path d="M 528,192 L 528,368" fill="none" stroke="black"/>
              <path d="M 8,32 L 528,32" fill="none" stroke="black"/>
              <path d="M 8,64 L 528,64" fill="none" stroke="black"/>
              <path d="M 8,112 L 528,112" fill="none" stroke="black"/>
              <path d="M 8,144 L 528,144" fill="none" stroke="black"/>
              <path d="M 8,192 L 128,192" fill="none" stroke="black"/>
              <path d="M 320,192 L 528,192" fill="none" stroke="black"/>
              <path d="M 128,208 L 152,208" fill="none" stroke="black"/>
              <path d="M 296,208 L 312,208" fill="none" stroke="black"/>
              <path d="M 136,224 L 152,224" fill="none" stroke="black"/>
              <path d="M 296,224 L 320,224" fill="none" stroke="black"/>
              <path d="M 136,254 L 168,254" fill="none" stroke="black"/>
              <path d="M 136,258 L 168,258" fill="none" stroke="black"/>
              <path d="M 288,254 L 312,254" fill="none" stroke="black"/>
              <path d="M 288,258 L 312,258" fill="none" stroke="black"/>
              <path d="M 336,256 L 512,256" fill="none" stroke="black"/>
              <path d="M 8,272 L 128,272" fill="none" stroke="black"/>
              <path d="M 336,288 L 512,288" fill="none" stroke="black"/>
              <path d="M 336,320 L 512,320" fill="none" stroke="black"/>
              <path d="M 336,352 L 512,352" fill="none" stroke="black"/>
              <path d="M 320,368 L 528,368" fill="none" stroke="black"/>
              <polygon class="arrowhead" points="448,184 436,178.4 436,189.6 " fill="black" transform="rotate(90,440,184)"/>
              <polygon class="arrowhead" points="320,256 308,250.4 308,261.6 " fill="black" transform="rotate(0,312,256)"/>
              <polygon class="arrowhead" points="320,208 308,202.4 308,213.6 " fill="black" transform="rotate(0,312,208)"/>
              <polygon class="arrowhead" points="304,224 292,218.4 292,229.6 " fill="black" transform="rotate(180,296,224)"/>
              <polygon class="arrowhead" points="264,104 252,98.4 252,109.6 " fill="black" transform="rotate(90,256,104)"/>
              <polygon class="arrowhead" points="160,208 148,202.4 148,213.6 " fill="black" transform="rotate(0,152,208)"/>
              <polygon class="arrowhead" points="144,256 132,250.4 132,261.6 " fill="black" transform="rotate(180,136,256)"/>
              <polygon class="arrowhead" points="144,224 132,218.4 132,229.6 " fill="black" transform="rotate(180,136,224)"/>
              <polygon class="arrowhead" points="88,184 76,178.4 76,189.6 " fill="black" transform="rotate(90,80,184)"/>
              <g class="text">
                <text x="160" y="52">SMIv2</text>
                <text x="240" y="52">specification</text>
                <text x="340" y="52">(optional)</text>
                <text x="400" y="52">(2)</text>
                <text x="196" y="132">YANG</text>
                <text x="272" y="132">specification</text>
                <text x="352" y="132">(1)</text>
                <text x="36" y="180">Client</text>
                <text x="348" y="180">Server</text>
                <text x="88" y="212">Request</text>
                <text x="180" y="212">CoAP</text>
                <text x="244" y="212">request(3)</text>
                <text x="380" y="212">Indication</text>
                <text x="88" y="228">Confirm</text>
                <text x="180" y="228">CoAP</text>
                <text x="248" y="228">response(3)</text>
                <text x="372" y="228">Response</text>
                <text x="488" y="228">(4)</text>
                <text x="212" y="260">Security</text>
                <text x="264" y="260">(7)</text>
                <text x="396" y="276">Datastore(s)</text>
                <text x="488" y="276">(5)</text>
                <text x="368" y="340">Event</text>
                <text x="432" y="340">stream(s)</text>
                <text x="488" y="340">(6)</text>
              </g>
            </svg>
          </artwork>
          <artwork type="ascii-art" align="left"><![CDATA[
+----------------------------------------------------------------+
|                SMIv2 specification (optional) (2)              |
+------------------------------+---------------------------------+
                               |
                               v
+----------------------------------------------------------------+
|                     YANG specification  (1)                    |
+--------+--------------------------------------------+----------+
         |                                            |
 Client  v                              Server        v
+--------------+                       +-------------------------+
|      Request +--> CoAP request(3) -->|  Indication             |
|      Confirm |<-- CoAP response(3)<--+  Response         (4)   |
|              |                       |                         |
|              |<==== Security (7) ===>| +---------------------+ |
+--------------+                       | | Datastore(s)    (5) | |
                                       | +---------------------+ |
                                       |                         |
                                       | +---------------------+ |
                                       | | Event stream(s) (6) | |
                                       | +---------------------+ |
                                       +-------------------------+
]]></artwork>
        </artset>
      </figure>
      <t><xref target="archit"/> is a high-level representation of the main elements of the CORECONF management
architecture. The different numbered components of <xref target="archit"/> are discussed according to the component number.</t>
      <dl>
        <dt>(1) YANG specification:</dt>
        <dd>
          <t>contains a set of named and versioned modules.</t>
        </dd>
        <dt>(2) SMIv2 specification:</dt>
        <dd>
          <t>Optional part that consists of a named module which, specifies a set of variables and "conceptual tables". There
is an algorithm to translate SMIv2 specifications to YANG specifications.</t>
        </dd>
        <dt>(3) CoAP request/response messages:</dt>
        <dd>
          <t>The CORECONF client sends request messages to and receives response messages
from the CORECONF server.</t>
        </dd>
        <dt>(4) Request, Indication, Response, Confirm:</dt>
        <dd>
          <t>Processes performed by the CORECONF clients and servers.</t>
        </dd>
        <dt>(5) Datastore:</dt>
        <dd>
          <t>A resource used to access configuration data, state data, RPCs, and
 actions. A CORECONF server supports a single unified datastore.
 Multiple datastores, for instance as those defined by Network
 Management Datastore Architecture (NMDA) <xref target="RFC8342"/>, are out of scope
 of this specification.</t>
        </dd>
        <dt>(6) Event stream:</dt>
        <dd>
          <t>A resource used to get real-time notifications. A CORECONF server may support multiple Event streams serving different purposes such as normal monitoring, diagnostic, syslog, security monitoring.</t>
        </dd>
        <dt>(7) Security:</dt>
        <dd>
          <t>The server <bcp14>MUST</bcp14> prevent unauthorized users from reading or writing any CORECONF
resources. CORECONF relies on security protocols such as DTLS <xref target="RFC6347"/><xref target="RFC9147"/> or OSCORE <xref target="RFC8613"/> to secure CoAP communications.</t>
        </dd>
      </dl>
      <section anchor="major-differences">
        <name>Major differences between RESTCONF and CORECONF</name>
        <t>CORECONF is a RESTful protocol for small devices where saving bytes to
transport a message is very important. Contrary to RESTCONF, many design
decisions are motivated by the
saving of bytes. Consequently, CORECONF is not a RESTCONF over CoAP protocol,
but differs more significantly from RESTCONF.</t>
        <section anchor="major-differences-coap">
          <name>Differences due to CoAP and its efficient usage</name>
          <ul spacing="normal">
            <li>
              <t>CORECONF uses CoAP/UDP as transport protocol and CBOR as payload format
<xref target="RFC9254"/>. RESTCONF uses HTTP/TCP as transport
protocol and JSON or XML as payload formats.</t>
            </li>
            <li>
              <t>CORECONF uses the methods FETCH and iPATCH to access data nodes.
RESTCONF uses instead the HTTP method PATCH and the HTTP method GET with the "fields" Query parameter.</t>
            </li>
            <li>
              <t>RESTCONF uses the HTTP methods HEAD, and OPTIONS, which are not supported by CoAP.</t>
            </li>
            <li>
              <t>CORECONF does not support "insert" query parameter (first, last, before, after)
and the "point" query parameter which are supported by RESTCONF.</t>
            </li>
            <li>
              <t>CORECONF does not support the "start-time" and "stop-time" query parameters
to retrieve past notifications.</t>
            </li>
          </ul>
        </section>
        <section anchor="major-differences-cbor">
          <name>Differences due to the use of CBOR</name>
          <ul spacing="normal">
            <li>
              <t>CORECONF encodes YANG identifier strings as numbers, where RESTCONF does not.</t>
            </li>
            <li>
              <t>CORECONF also differs in the handling of default values, only 'report-all' and 'trim' options are supported.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="id-compression">
        <name>Compression of YANG identifiers</name>
        <t>In the YANG specification, items are identified with a name string. In order
to significantly reduce the size of identifiers used in CORECONF, numeric
 identifiers called YANG Schema Item iDentifier (YANG SID or simply SID) are used instead.</t>
        <section anchor="instance-identifier">
          <name>Instance-identifiers</name>
          <t>Instance-identifiers are used to uniquely identify data node instances within a datastore. This YANG built-in type is defined in <xref section="9.13" sectionFormat="of" target="RFC7950"/>. An instance-identifier is composed of the data node identifier (i.e., a SID) and, for data nodes within list(s), the keys used to index within these list(s).</t>
          <t>In CORECONF, instance-identifiers are carried in the payload of FETCH
and PATCH requests.
They are encoded in CBOR
based on the rules defined in <xref section="6.13.1" sectionFormat="of" target="RFC9254"/>.</t>
        </section>
      </section>
      <section anchor="media-type">
        <name>Media-Types</name>
        <t>CORECONF uses Media-Types based on the YANG to CBOR mapping specified
in <xref target="RFC9254"/>.</t>
        <t>The following new Media-Types based on CBOR sequences <xref target="RFC8742"/> are defined in this document:</t>
        <dl>
          <dt>application/yang-identifiers+cbor-seq:</dt>
          <dd>
            <t>This Media-Type represents a CBOR YANG document containing a list of instance-identifiers used to target specific data node instances within a datastore.</t>
          </dd>
          <dt/>
          <dd>
            <t>FORMAT: CBOR sequence of instance-identifiers</t>
          </dd>
          <dt/>
          <dd>
            <t>The message payload of Media-Type 'application/yang-identifiers+cbor-seq' is encoded using a CBOR sequence.
Each item of this CBOR sequence contains an instance-identifier encoded as defined in <xref section="6.13.1" sectionFormat="of" target="RFC9254"/>.</t>
          </dd>
          <dt>application/yang-instances+cbor-seq:</dt>
          <dd>
            <t>This Media-Type represents a CBOR YANG document containing a list of data node instances.
Each data node instance is identified by its associated instance-identifier.</t>
          </dd>
          <dt/>
          <dd>
            <t>FORMAT: CBOR sequence of CBOR maps of instance-identifier, instance-value</t>
          </dd>
          <dt/>
          <dd>
            <t>The message payload of Media-Type 'application/yang-instances+cbor-seq' is encoded using a CBOR sequence.
Each item within this CBOR sequence contains a CBOR map carrying an instance-identifier and associated instance-value.
Instance-identifiers are encoded using the rules defined in <xref section="6.13.1" sectionFormat="of" target="RFC9254"/>, instance-values are encoded using the rules
defined in <xref section="4" sectionFormat="of" target="RFC9254"/>.
The reference SID applying to the instance-value is provided by the
SID in the instance-identifier.</t>
          </dd>
          <dt/>
          <dd>
            <t>When present in an iPATCH request payload, this Media-Type carry a list of data node instances to be replaced, created, or deleted.
For each data node instance D, for which the instance-identifier is the same as a data node instance I, in the targeted datastore resource: the value of D replaces the value of I.  When the value of D is null, the data node instance I is removed.  When the targeted datastore resource does not contain a data node instance with the same instance-identifier as D, a new instance is created with the same instance-identifier and value as D (unless the value of D is null).</t>
          </dd>
        </dl>
        <t>The different Media-Type usages are summarized in the table below:</t>
        <table align="left">
          <name>Summary of Media-Type Usages</name>
          <thead>
            <tr>
              <th align="left">Method</th>
              <th align="left">Resource</th>
              <th align="left">Media-Type</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">FETCH request</td>
              <td align="left">datastore</td>
              <td align="left">application/yang-identifiers+cbor-seq</td>
            </tr>
            <tr>
              <td align="left">FETCH response</td>
              <td align="left">datastore</td>
              <td align="left">application/yang-instances+cbor-seq</td>
            </tr>
            <tr>
              <td align="left">iPATCH request</td>
              <td align="left">datastore</td>
              <td align="left">application/yang-instances+cbor-seq</td>
            </tr>
            <tr>
              <td align="left">GET response</td>
              <td align="left">event stream</td>
              <td align="left">application/yang-instances+cbor-seq</td>
            </tr>
            <tr>
              <td align="left">POST request</td>
              <td align="left">rpc, action</td>
              <td align="left">application/yang-instances+cbor-seq</td>
            </tr>
            <tr>
              <td align="left">POST response</td>
              <td align="left">rpc, action</td>
              <td align="left">application/yang-instances+cbor-seq</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="unified-datastore">
        <name>Unified datastore</name>
        <t>CORECONF supports a simple datastore model consisting of a single unified datastore. This datastore provides access to both configuration and operational data. Configuration updates performed on this datastore are reflected immediately or with a minimal delay as operational data.</t>
        <t>More complex datastore models such as the Network Management Datastore
Architecture (NMDA) as defined by <xref target="RFC8342"/> are out of scope of the
present specification.</t>
        <t>Characteristics of the unified datastore are summarized in the table below:</t>
        <table align="left">
          <name>Characteristics of the Unified Datastore</name>
          <thead>
            <tr>
              <th align="left">Name</th>
              <th align="left">Value</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">Name</td>
              <td align="left">unified</td>
            </tr>
            <tr>
              <td align="left">YANG modules</td>
              <td align="left">all modules</td>
            </tr>
            <tr>
              <td align="left">YANG nodes</td>
              <td align="left">all data nodes ("config true" and "config false")</td>
            </tr>
            <tr>
              <td align="left">Access</td>
              <td align="left">read-write</td>
            </tr>
            <tr>
              <td align="left">How applied</td>
              <td align="left">changes applied in place immediately or with a minimal delay</td>
            </tr>
            <tr>
              <td align="left">Protocols</td>
              <td align="left">CORECONF</td>
            </tr>
            <tr>
              <td align="left">Defined in</td>
              <td align="left">"ietf-coreconf"</td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="coap-interface">
      <name>CoAP Interface</name>
      <t>This document specifies a Management Interface. CoAP endpoints that
implement the CORECONF management protocol, support
at least one discoverable management resource of resource type (rt): core.c.ds.
The path of the discoverable management resource is left to implementers to
select (see <xref target="discovery"/>).</t>
      <t>YANG data node instances are accessible by performing FETCH and iPATCH
operations on the datastore resource.</t>
      <t>CORECONF also supports event stream resources used to observe notification instances.
Event stream resources can be discovered using resource type (rt): core.c.ev.</t>
      <t>The description of the CORECONF management interface is shown in the table below:</t>
      <table align="left" anchor="tbl-resources">
        <name>Resources, example paths, and resource types (rt)</name>
        <thead>
          <tr>
            <th align="left">CoAP resource</th>
            <th align="left">Example path</th>
            <th align="left">rt</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Datastore resource</td>
            <td align="left">/c</td>
            <td align="left">core.c.ds</td>
          </tr>
          <tr>
            <td align="left">Default event stream resource</td>
            <td align="left">/s</td>
            <td align="left">core.c.ev</td>
          </tr>
        </tbody>
      </table>
      <t>The path values in the table are example ones. On discovery, the server makes
the actual path values known for these resources.</t>
      <t>The methods used by CORECONF are:</t>
      <table align="left" anchor="tbl-methods">
        <name>CoAP Methods in CORECONF</name>
        <thead>
          <tr>
            <th align="left">Operation</th>
            <th align="left">Description</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">FETCH</td>
            <td align="left">Retrieve specific data nodes within a datastore resource or event stream resource</td>
          </tr>
          <tr>
            <td align="left">iPATCH</td>
            <td align="left">Idempotently create, replace, and delete data node(s) within a datastore resource</td>
          </tr>
          <tr>
            <td align="left">POST</td>
            <td align="left">Invoke an RPC or action</td>
          </tr>
          <tr>
            <td align="left">GET</td>
            <td align="left">Retrieve the datastore resource or event stream resource</td>
          </tr>
          <tr>
            <td align="left">PUT</td>
            <td align="left">Create or replace a datastore resource</td>
          </tr>
          <tr>
            <td align="left">DELETE</td>
            <td align="left">Delete a datastore resource</td>
          </tr>
        </tbody>
      </table>
      <section anchor="data-retrieval">
        <name>Data Retrieval</name>
        <t>One or more data nodes can be retrieved by the client.
The operation is mapped to the FETCH method defined in <xref section="2" sectionFormat="of" target="RFC8132"/>.</t>
        <t>There are two additional query parameters for the FETCH method:</t>
        <table align="left" anchor="tbl-query-fetch">
          <thead>
            <tr>
              <th align="left">query parameters</th>
              <th align="left">Description</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">c</td>
              <td align="left">Control selection of configuration and non-configuration data nodes (GET and FETCH)</td>
            </tr>
            <tr>
              <td align="left">d</td>
              <td align="left">Control retrieval of default values.</td>
            </tr>
          </tbody>
        </table>
        <section anchor="content">
          <name>Using the 'c' query parameter</name>
          <t>The 'c' (content) option controls how descendant nodes of the
requested data nodes will be processed in the reply.</t>
          <t>The allowed values are:</t>
          <table align="left" anchor="tbl-c-values">
            <name>Values for the 'c' query parameter</name>
            <thead>
              <tr>
                <th align="left">Value</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">c</td>
                <td align="left">Return only configuration descendant data nodes</td>
              </tr>
              <tr>
                <td align="left">n</td>
                <td align="left">Return only non-configuration descendant data nodes</td>
              </tr>
              <tr>
                <td align="left">a</td>
                <td align="left">Return all descendant data nodes</td>
              </tr>
            </tbody>
          </table>
          <t>This option is only allowed for GET and FETCH methods on datastore and
data node resources.  A 4.02 (Bad Option) error is returned if used for other
methods or resource types.</t>
          <t>If this query parameter is not present, the default value is "a" (the quotes
are added for readability, but they are not part of the payload).</t>
        </section>
        <section anchor="dquery">
          <name>Using the 'd' query parameter</name>
          <t>The 'd' (with-defaults) option controls how the default values of the
descendant nodes of the requested data nodes will be processed.</t>
          <t>The allowed values are:</t>
          <table align="left" anchor="tbl-d-values">
            <name>Values for the 'd' query parameter</name>
            <thead>
              <tr>
                <th align="left">Value</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">a</td>
                <td align="left">All data nodes are reported. Defined as 'report-all' in <xref section="3.1" sectionFormat="of" target="RFC6243"/>.</td>
              </tr>
              <tr>
                <td align="left">t</td>
                <td align="left">Data nodes set to the YANG default are not reported. Defined as 'trim' in <xref section="3.2" sectionFormat="of" target="RFC6243"/>.</td>
              </tr>
            </tbody>
          </table>
          <t>If the target of a GET or FETCH method is a data node that represents a leaf
that has a default value, and the leaf has not been given a value by any
client yet, the server <bcp14>MUST</bcp14> return the default value of the leaf.</t>
          <t>If the target of a GET method is a data node that represents a
container or list that has child resources with default values,
and these have not been given a value yet,</t>
          <ul empty="true">
            <li>
              <t>The server <bcp14>MUST NOT</bcp14> return the child resource if <tt>d</tt>=<tt>t</tt>.</t>
            </li>
          </ul>
          <ul empty="true">
            <li>
              <t>The server <bcp14>MUST</bcp14> return the child resource if <tt>d</tt>=<tt>a</tt>.</t>
            </li>
          </ul>
          <t>If this query parameter is not present, the default value is "t" (the quotes are
added for readability, but they are not part of the payload).</t>
        </section>
        <section anchor="fetch">
          <name>FETCH</name>
          <t>The FETCH method is used to retrieve one or more instance-values.
The FETCH request payload contains the list of instance-identifiers of the data node instances requested.</t>
          <t>The return response payload contains a list of data node instance-values in the same order as requested.
A CBOR null is returned for each data node requested by the client, not supported by the server or not currently instantiated.</t>
          <t>For compactness, indexes of the list instance identifiers returned by the FETCH response <bcp14>SHOULD</bcp14> be elided, only the SID is provided.
That means that the client is responsible for remembering the full
instance-identifiers in its request since no key values will be in the
response.
This approach may also help reduce implementation complexity since the format of each entry within the CBOR sequence of the FETCH response is identical to the format of the corresponding GET response.</t>
          <artwork><![CDATA[
FORMAT:
  FETCH <datastore resource>
        (Content-Format: application/yang-identifiers+cbor-seq)
  CBOR sequence of instance-identifiers

  2.05 Content (Content-Format: application/yang-instances+cbor-seq)
  CBOR sequence of CBOR maps of SID, instance-value
]]></artwork>
          <section anchor="fetch-example">
            <name>FETCH examples</name>
            <t>This example uses the current-datetime leaf from module ietf-system <xref target="RFC7317"/>
and the interface list from module ietf-interfaces <xref target="RFC8343"/>.
In this example the value of current-datetime (SID 1723) and the interface
list (SID 1533) instance identified with name="eth0" are queried.</t>
            <artwork><![CDATA[
REQ: FETCH </c>
     (Content-Format: application/yang-identifiers+cbor-seq)
1723,            / current-datetime (SID 1723) /
[1533, "eth0"]   / interface (SID 1533) with name = "eth0" /

RES: 2.05 Content
     (Content-Format: application/yang-instances+cbor-seq)

{
  1723 : "2014-10-26T12:16:31Z" / current-datetime (SID 1723) /
},
{
  1533 : {
     4 : "eth0",              / name (SID 1537) /
     1 : "Ethernet adaptor",  / description (SID 1534) /
     5 : 1880,                / type (SID 1538), identity /
                              / ethernetCsmacd (SID 1880) /
     2 : true,                / enabled (SID 1535) /
    11 : 3             / oper-status (SID 1544), value is testing /
  }
}

]]></artwork>
          </section>
        </section>
      </section>
      <section anchor="data-editing">
        <name>Data Editing</name>
        <t>CORECONF allows datastore contents to be created, modified and deleted using
CoAP methods.</t>
        <section anchor="DataOrdering">
          <name>Data Ordering</name>
          <t>A CORECONF server <bcp14>MUST</bcp14> preserve the relative order of all user-ordered list
and leaf-list entries that are received in a single edit request.
As per <xref target="RFC9254"/>, these YANG data node types are encoded as CBOR
arrays, so messages will preserve their order.</t>
        </section>
        <section anchor="post-operation">
          <name>POST</name>
          <t>The CoAP POST operation is used in CORECONF for the
invocation of "ACTION" and "RPC" resources.
Refer to <xref target="rpc"/> for details on "ACTION" and "RPC" resources.</t>
        </section>
        <section anchor="ipatch-operation">
          <name>iPATCH</name>
          <t>One or multiple data node instances are replaced with the idempotent
CoAP iPATCH method <xref target="RFC8132"/>.</t>
          <t>There are no query parameters for the iPATCH method.</t>
          <t>The processing of the iPATCH command is specified by Media-Type application/yang-instances+cbor-seq.
In summary, if the CBOR patch payload contains a data node instance that is not present
in the target, this instance is added. If the target contains the specified instance,
the content of this instance is replaced with the value of the payload.
A null value indicates the removal of an existing data node instance.</t>
          <artwork><![CDATA[
FORMAT:
  iPATCH <datastore resource>
         (Content-Format: application/yang-instances+cbor-seq)
  CBOR sequence of CBOR maps of instance-identifier, instance-value

  2.04 Changed
]]></artwork>
          <section anchor="ipatch-example">
            <name>iPATCH example</name>
            <t>In this example, a CORECONF client requests the following operations:</t>
            <ul spacing="normal">
              <li>
                <t>Set "/ietf-system:system/ntp/enabled" (SID 1755) to true.</t>
              </li>
              <li>
                <t>Remove the server "tac.nrc.ca" from the "/ietf-system:system/ntp/server" (SID 1756) list.</t>
              </li>
              <li>
                <t>Add/set the server "NTP Pool server 2" to the list "/ietf-system:system/ntp/server" (SID 1756).</t>
              </li>
            </ul>
            <artwork><![CDATA[
REQ: iPATCH </c>
     (Content-Format: application/yang-instances+cbor-seq)
{
  1755 : true                   / enabled (SID 1755) /
},
{
  [1756, "tac.nrc.ca"] : null   / server (SID 1756) /
},
{
  1756 : {                      / server (SID 1756) /
    3 : "tic.nrc.ca",           / name (SID 1759) /
    4 : true,                   / prefer (SID 1760) /
    5 : {                       / udp (SID 1761) /
      1 : "132.246.11.231"      / address (SID 1762) /
    }
  }
}

RES: 2.04 Changed
]]></artwork>
            <t>A data node resource is deleted using an iPATCH with a null value, as seen in this example.</t>
          </section>
        </section>
      </section>
      <section anchor="datastore-access">
        <name>Full datastore access</name>
        <t>The methods GET, PUT, POST, and DELETE can be used to request, replace, create,
and delete a whole datastore respectively.</t>
        <artwork><![CDATA[
FORMAT:
  GET <datastore resource>

  2.05 Content (Content-Format: application/yang-data+cbor; id=sid)
  CBOR map of SID, instance-value
]]></artwork>
        <artwork><![CDATA[
FORMAT:
  PUT <datastore resource>
      (Content-Format: application/yang-data+cbor; id=sid)
  CBOR map of SID, instance-value

  2.04 Changed
]]></artwork>
        <artwork><![CDATA[
FORMAT:
  POST <datastore resource>
       (Content-Format: application/yang-data+cbor; id=sid)
  CBOR map of SID, instance-value

  2.01 Created
]]></artwork>
        <artwork><![CDATA[
FORMAT:
  DELETE <datastore resource>

  2.02 Deleted
]]></artwork>
        <t>The content of the CBOR map represents the complete datastore of the server
at the GET indication of after a successful processing of a PUT or POST request.</t>
        <section anchor="datastore-example">
          <name>Full datastore examples</name>
          <t>The example uses the interface list from module ietf-interfaces <xref target="RFC8343"/> and
the clock container from module ietf-system <xref target="RFC7317"/>.
We assume that the datastore contains two modules ietf-system (SID 1700) and
ietf-interfaces (SID 1500); they contain the 'interface' list (SID 1533) with
one instance and the 'clock' container (SID 1721). After invocation of GET, a
CBOR map with data nodes from these two modules is returned:</t>
          <artwork><![CDATA[
REQ:  GET </c>

RES: 2.05 Content
     (Content-Format: application/yang-data+cbor; id=sid)
{
  1721 : {                      / Clock (SID 1721) /
    2: "2016-10-26T12:16:31Z",  / current-datetime (SID 1723) /
    1: "2014-10-05T09:00:00Z"   / boot-datetime (SID 1722) /
  },
  1533 : [
    {                           / interface (SID 1533) /
       4 : "eth0",              / name (SID 1537) /
       1 : "Ethernet adaptor",  / description (SID 1534) /
       5 : 1880,                / type (SID 1538), identity: /
                                / ethernetCsmacd (SID 1880) /
       2 : true,                / enabled (SID 1535) /
      11 : 3             / oper-status (SID 1544), value is testing /
    }
  ]
}
]]></artwork>
        </section>
      </section>
      <section anchor="event-stream">
        <name>Event stream</name>
        <t>Event notification is an essential function for the management of servers.
CORECONF allows notifications specified in YANG <xref target="RFC5277"/> to be reported to a list
of clients. The path for the default event stream can be discovered as
described in <xref target="coap-interface"/>. The server <bcp14>MAY</bcp14> support additional event
stream resources to address different notification needs.</t>
        <t>Reception of notification instances is enabled with the CoAP Observe
<xref target="RFC7641"/> function. Clients subscribe to the notifications by sending a
GET request with an "Observe" option to the stream resource.</t>
        <t>Each response payload carries one or multiple notifications. The number of
notifications reported, and the conditions used to remove notifications
from the reported list are left to implementers.
When multiple notifications are reported, they <bcp14>MUST</bcp14> be ordered starting from
the newest notification at index zero. Note that this could lead to
notifications being sent multiple times, which increases the probability for
the client to receive them, but it might potentially lead to messages that
exceed the MTU of a single CoAP packet. If such cases could arise, implementers
should make sure appropriate fragmentation is available - for example the one
described in <xref target="block"/>.</t>
        <t>The format of notifications is a CBOR sequence, where each item in
the sequence is a single notification as described in <xref section="4.2.1" sectionFormat="of" target="RFC9254"/>.
(Accordingly, a notification without any content is an empty CBOR
sequence, i.e., zero bytes.)</t>
        <artwork><![CDATA[
FORMAT:
  GET <stream-resource> Observe(0)

  2.05 Content (Content-Format: application/yang-instances+cbor-seq)
  CBOR sequence of CBOR maps of instance-identifier, instance-value
]]></artwork>
        <t>The sequence of data node instances may contain identical items which have
been generated at different times.</t>
        <t>An example implementation is:</t>
        <ul empty="true">
          <li>
            <t>Every time an event is generated, the generated notification instance is
appended to the chosen stream(s). After an aggregation period, which may be
limited by the maximum number of notifications supported,
the content of the instance is sent to all clients observing the modified stream.</t>
          </li>
        </ul>
        <section anchor="filtering-notifications">
          <name>Filtering Notifications</name>
          <t>If only a subset of all possible notifications is of interest, a FETCH
operation can be performed with a request payload of type
application/yang-identifiers+cbor-seq that indicates which subset.</t>
          <artwork><![CDATA[
FORMAT:
  FETCH <stream-resource> Observe(0)
        (Content-Format: application/yang-identifiers+cbor-seq)
  CBOR sequence of instance-identifiers

  2.05 Content (Content-Format: application/yang-instances+cbor-seq)
  CBOR sequence of CBOR maps of instance-identifier, instance-value
]]></artwork>
          <t>When filtering is not supported by a CORECONF server, the request
payload can be ignored: all event notifications are then reported
independently of the presence and content of the request payload.</t>
        </section>
        <section anchor="event-stream-example">
          <name>Notify Examples</name>
          <t>Let suppose the server generates the example-port-fault event as defined below.</t>
          <sourcecode type="yang"><![CDATA[
module example-port {
  yang-version 1.1;
  namespace "https://example.com/ns/example-port";
  prefix "port";

  notification example-port-fault {   // SID 60010
    description
      "Event generated if a hardware fault is detected";
    leaf port-name {                  // SID 60011
      type string;
    }
    leaf port-fault {                 // SID 60012
      type string;
    }
  }
}
]]></sourcecode>
          <t>In this example the default event stream resource path /s is an example
location discovered with a request similar to <xref target="discovery-ex-es"/>. By executing a
GET with Observe 0 on the default event stream resource the client receives the
following response:</t>
          <artwork><![CDATA[
REQ:  GET </s> Observe(0)

RES:  2.05 Content
      (Content-Format: application/yang-instances+cbor-seq)
      Observe(12)

{
  60010 : {             / example-port-fault (SID 60010) /
    1 : "0/4/21",       / port-name (SID 60011) /
    2 : "Open pin 2"    / port-fault (SID 60012) /
  }
},
{
  60010 : {             / example-port-fault (SID 60010) /
    1 : "1/4/21",       / port-name (SID 60011) /
    2 : "Open pin 5"    / port-fault (SID 60012) /
  }
}

]]></artwork>
          <t>In the example, the request returns a success response with the contents
of the last two generated events. Consecutively the server will regularly
notify the client when a new event is generated.</t>
          <t>A client that wants to filter notifications can use a FETCH payload:</t>
          <artwork><![CDATA[
REQ:  FETCH </s> Observe(0)
      (Content-Format: application/yang-identifiers+cbor-seq)

60010, 60020 /CBOR sequence with two notification identifiers/

RES:  2.05 Content
      (Content-Format: application/yang-instances+cbor-seq)
      Observe(12)

{
  60010 : {             / example-port-fault (SID 60010) /
    1 : "0/4/21",       / port-name (SID 60011) /
    2 : "Open pin 2"    / port-fault (SID 60012) /
  }
},
{
  60010 : {             / example-port-fault (SID 60010) /
    1 : "1/4/21",       / port-name (SID 60011) /
    2 : "Open pin 5"    / port-fault (SID 60012) /
  }
}

]]></artwork>
          <t>Note that the notifications in this example are identical to the
unfiltered example as they are all using identifier SID 60010 and this
is included in the filter.</t>
        </section>
      </section>
      <section anchor="rpc">
        <name>RPC and Action statements</name>
        <t>The YANG "action" and "RPC" statements specify the execution of a Remote
Procedure Call (RPC) in the server.  It is invoked using a POST method to
an "Action" or "RPC" resource instance.</t>
        <t>The request payload contains the values assigned to the input container when specified.
The response payload contains the values of the output container when specified.
Both the input and output containers are encoded in CBOR using the rules defined in
<xref section="4.2.1" sectionFormat="of" target="RFC9254"/>.</t>
        <t>The returned success response code is 2.04 Changed.</t>
        <artwork><![CDATA[
FORMAT:
  POST <datastore resource>
         (Content-Format: application/yang-instances+cbor-seq)
  CBOR sequence of CBOR maps of instance-identifier, instance-value

  2.04 (Content-Format: application/yang-instances+cbor-seq)
  CBOR sequence of CBOR maps of instance-identifier, instance-value
]]></artwork>
        <section anchor="rpc-example">
          <name>RPC Example</name>
          <t>This example is based on <xref section="3.6.1" sectionFormat="of" target="RFC8040"/>, abbreviated and
annotated with SIDs as follows:</t>
          <sourcecode type="yang"><![CDATA[
module example-ops {
  yang-version 1.1;
  namespace "https://example.com/ns/example-ops";
  prefix "ops";

  rpc reboot {                          // SID 61000
    description "Reboot operation.";
    input {                             // SID 61009
      leaf delay {                      // SID 61001
        type uint32;
        units "seconds";
        default 0;
        description
          "Number of seconds to wait before initiating the
           reboot operation.";
      }
    }
  }
}
]]></sourcecode>
          <t>This example invokes the 'reboot' RPC  (SID 61000).</t>
          <artwork><![CDATA[
REQ:  POST </c>
      (Content-Format: application/yang-instances+cbor-seq)

{ 61000:
  {
    1 : 77
  }
}
RES:  2.04 Changed
      (Content-Format: application/yang-instances+cbor-seq)

{ 61000:
  null
}
]]></artwork>
          <!--
We now believe this is the correct empty return for an RPC without output.
    Note that we always have to send a yang-instances (or at least a
    yang-identifiers) for the input side to find the right RPC.
 -->

</section>
        <section anchor="action-example">
          <name>Action Example</name>
          <t>The example is based on the YANG action "reset" as defined in <xref section="7.15.3" sectionFormat="of" target="RFC7950"/>
and annotated below with SIDs.</t>
          <sourcecode type="yang"><![CDATA[
module example-server-farm {
  yang-version 1.1;
  namespace "urn:example:server-farm";
  prefix "sfarm";

  import ietf-yang-types {
    prefix "yang";
  }

  list server {                        // SID 60000
    key name;
    leaf name {                        // SID 60001
      type string;
    }
    action reset {                     // SID 60002
      input {                          // SID 60008
        leaf reset-at {                // SID 60003
          type yang:date-and-time;
          mandatory true;
        }
      }
      output {                         // SID 60009
        leaf reset-finished-at {       // SID 60004
          type yang:date-and-time;
          mandatory true;
        }
      }
    }
  }
}
]]></sourcecode>
          <t>This example invokes the 'reset' action  (SID 60002),
of the server instance with name equal to "myserver".</t>
          <artwork><![CDATA[
REQ:  POST </c>
      (Content-Format: application/yang-instances+cbor-seq)

{ [60002, "myserver"]:
  {
    1 : "2016-02-08T14:10:08Z" / reset-at (SID 60003) /
  }
}
RES:  2.04 Changed
         (Content-Format: application/yang-instances+cbor-seq)

{ [60002, "myserver"]:
  {
    2 : "2016-02-08T14:10:11Z" / reset-finished-at (SID 60004)/
  }
}
]]></artwork>
        </section>
      </section>
    </section>
    <section anchor="block">
      <name>Use of Block-wise Transfers</name>
      <t>The CoAP protocol provides reliability by acknowledging the UDP datagrams.
However, when large pieces of data need to be transported, datagrams get
fragmented, thus creating constraints on the resources in the client, server
and intermediate routers. The block option <xref target="RFC7959"/> allows the transport
of the total payload in individual blocks of which the
size can be adapted to the underlying transport sizes such as: (UDP datagram
size ~64KiB, IPv6 MTU of 1280, IEEE 802.15.4 payload of 60-80 bytes). Each
block is individually acknowledged to guarantee reliability.</t>
      <t>Notice that the Block mechanism splits the data at fixed positions,
such that individual data fields may become fragmented. Therefore, assembly
of multiple blocks may be required to process complete data fields.</t>
      <t>Beware of race conditions. In case blocks are filled one at a time, care should
be taken that the whole and consistent data representation is sent in multiple blocks sequentially
without interruption. On the server, values might change, lists might get re-ordered,
extended or reduced. When these actions happen during the serialization of
the contents of the resource, the transported results do not correspond with
a state having occurred in the server; or worse the returned values are inconsistent.
For example: array length does not correspond with the actual number of items.
It may be advisable to use Indefinite-length CBOR arrays and maps,
which are foreseen for data streaming purposes.
(Note that the outer structure of yang-identifiers and yang-instances
is a CBOR sequence, which already behaves similar to an
indefinite-length encoded array.)</t>
    </section>
    <section anchor="discovery">
      <name>Application Discovery</name>
      <t>Two application discovery mechanisms are supported by CORECONF, the YANG library
data model as defined by <xref target="I-D.ietf-core-yang-library"/> and
the CORE resource discovery <xref target="RFC6690"/>.
Implementers may choose to implement one or the other or both.</t>
      <section anchor="yang-library">
        <name>YANG library</name>
        <t>The YANG library data model <xref target="I-D.ietf-core-yang-library"/> provides a high-level description of the resources available. The YANG library contains the
list of modules, features, and deviations supported by the CORECONF server.
From this information, CORECONF clients can infer the list of data nodes supported
and the interaction model to be used to access them. This module also contains
the list of datastores implemented.</t>
        <t>As described in <xref target="RFC6690"/>, the location of the YANG library can be found by
sending a GET request to
"/.well-known/core" including a resource type (RT) parameter with the value
"core.c.yl". Upon success, the return payload will contain the root resource
of the YANG library module.</t>
        <t>The following example assumes that the SID of the YANG library is 2351 (<tt>kv</tt> after
encoding as specified in <xref target="id-compression"/>) and that the server uses /c as
datastore resource path.</t>
        <artwork><![CDATA[
REQ: GET </.well-known/core?rt=core.c.yl>

RES: 2.05 Content (Content-Format: application/link-format)
</c/kv>;rt="core.c.yl"
]]></artwork>
      </section>
      <section anchor="resource-discovery">
        <name>Resource Discovery</name>
        <t>As some CoAP interfaces and services might not support the YANG library
interface and still be interested to discover resources that are available,
implementations <bcp14>MAY</bcp14> choose to support discovery of all available
resources using "/.well-known/core" as defined by <xref target="RFC6690"/>.</t>
        <section anchor="datastore-resource-discovery">
          <name>Datastore Resource Discovery</name>
          <t>The presence and location of (path to) each datastore implemented by the CORECONF server
can be discovered by sending a GET request to "/.well-known/core" including a
resource type (RT) parameter with the value "core.c.ds".</t>
          <t>Upon success, the return payload contains the list of datastore resources.</t>
          <t>Each datastore returned is further qualified using the "ds" Link-Format attribute.
This attribute is set to the SID assigned to the datastore identity.
When a unified datastore is implemented, the ds attribute is set to 1029 as
specified in <xref target="ietf-coreconf-sid"/>.
For other examples of datastores, see the Network Management Datastore Architecture (NMDA) <xref target="RFC7950"/>.</t>
          <sourcecode type="abnf"><![CDATA[
link-extension    = ( "ds" "=" sid )
                    ; SID assigned to the datastore identity
sid               = 1*DIGIT
]]></sourcecode>
          <t>The following example assumes that the server uses /c as datastore resource
path.</t>
          <figure anchor="discovery-ex-ds">
            <artwork align="left"><![CDATA[
REQ: GET </.well-known/core?rt=core.c.ds>

RES: 2.05 Content (Content-Format: application/link-format)
</c>; rt="core.c.ds";ds=1029
]]></artwork>
          </figure>
        </section>
        <section anchor="data-node-resource-discovery">
          <name>Data node Resource Discovery</name>
          <t>If implemented, the presence and location of (path to) each data node
implemented by the CORECONF server are discovered by sending a GET request to
"/.well-known/core" including a resource type (RT) parameter with the value
"core.c.dn".</t>
          <t>Upon success, the return payload contains the SID assigned to each data node
and their location.</t>
          <t>The example below shows the discovery of the presence and location of
data nodes. Data nodes '/ietf-system:system-state/clock/boot-datetime' (SID 1722)
and '/ietf-system:system-state/clock/current-datetime' (SID 1723) are returned.
The example assumes that the server uses /c as datastore resource path.</t>
          <artwork><![CDATA[
REQ: GET </.well-known/core?rt=core.c.dn>

RES: 2.05 Content (Content-Format: application/link-format)
</c/a6>;rt="core.c.dn",
</c/a7>;rt="core.c.dn"
]]></artwork>
          <t>Without additional filtering, the list of data nodes may become prohibitively
long. If this is the case implementations <bcp14>SHOULD</bcp14> support a way to obtain all
links using multiple GET requests (for example through some form of
pagination).</t>
        </section>
        <section anchor="event-stream-resource-discovery">
          <name>Event stream Resource Discovery</name>
          <t>The presence and location of (path to) each event stream implemented by the CORECONF server are
discovered by sending a GET request to "/.well-known/core" including a resource type (RT)
parameter with the value "core.c.es".</t>
          <t>Upon success, the return payload contains the list of event stream resources.</t>
          <t>The following example assumes that the server uses /s as the default event stream
resource.</t>
          <figure anchor="discovery-ex-es">
            <artwork align="left"><![CDATA[
REQ: GET </.well-known/core?rt=core.c.es>

RES: 2.05 Content (Content-Format: application/link-format)
</s>;rt="core.c.es"
]]></artwork>
          </figure>
        </section>
      </section>
    </section>
    <section anchor="error-handling">
      <name>Error Handling</name>
      <t>In case a request is received which cannot be processed properly, the CORECONF server <bcp14>MUST</bcp14> return an error response. This error response <bcp14>MUST</bcp14> contain a CoAP 4.xx or 5.xx response code.
Requests that result in an error response <bcp14>MUST NOT</bcp14> have an effect on
the datastore.</t>
      <t>Errors returned by a CORECONF server can be broken into two categories, those associated with the CoAP protocol itself and those generated during the validation of the YANG data model constraints as described in <xref section="8" sectionFormat="of" target="RFC7950"/>.</t>
      <t>The following list of common CoAP errors should be implemented by CORECONF servers. This list is not exhaustive, other errors defined by CoAP and associated RFCs may be applicable.</t>
      <ul spacing="normal">
        <li>
          <t>Error 4.01 (Unauthorized) is returned by the CORECONF server when the CORECONF client is not authorized to perform the requested action on the targeted resource (i.e., data node, datastore, rpc, action or event stream).</t>
        </li>
        <li>
          <t>Error 4.02 (Bad Option) is returned by the CORECONF server when one or more CoAP options are unknown or malformed.</t>
        </li>
        <li>
          <t>Error 4.04 (Not Found) is returned by the CORECONF server when the CORECONF client is requesting a non-instantiated resource (i.e., data node, datastore, rpc, action or event stream).</t>
        </li>
        <li>
          <t>Error 4.05 (Method Not Allowed) is returned by the CORECONF server when the CORECONF client is requesting a method not supported on the targeted resource. (e.g., GET on an rpc, PUT or POST on a data node with "config" set to false).</t>
        </li>
        <li>
          <t>Error 4.08 (Request Entity Incomplete) is returned by the CORECONF server if one or multiple blocks of a block transfer request is missing, see <xref target="RFC7959"/> for more details.</t>
        </li>
        <li>
          <t>Error 4.13 (Request Entity Too Large) may be returned by the CORECONF server during a block transfer request, see <xref target="RFC7959"/> for more details.</t>
        </li>
        <li>
          <t>Error 4.15 (Unsupported Content-Format) is returned by the CORECONF server when the Content-Format used in the request does not match those specified in <xref target="media-type"/>.</t>
        </li>
      </ul>
      <t>The CORECONF server <bcp14>MUST</bcp14> also enforce the different constraints associated with the YANG data models implemented. These constraints are described in <xref section="8" sectionFormat="of" target="RFC7950"/>. These errors are reported using the CoAP error code 4.00 (Bad Request) and may have the following error container as payload. The YANG definition and associated .sid file are available in <xref target="ietf-coreconf-yang"/> and <xref target="ietf-coreconf-sid"/>. The error container is encoded using the encoding rules of a YANG data template as defined in <xref section="5" sectionFormat="of" target="RFC9254"/>.</t>
      <artwork><![CDATA[
+--rw error!
   +--rw error-tag             identityref
   +--rw error-app-tag?        identityref
   +--rw error-data-node?      instance-identifier
   +--rw error-message?        string
]]></artwork>
      <t>The following 'error-tag' and 'error-app-tag' are defined by the ietf-coreconf YANG module, these tags are implemented as YANG identity and can be extended as needed.</t>
      <ul spacing="normal">
        <li>
          <t>error-tag 'operation-failed' is returned by the CORECONF server when the operation request cannot be processed successfully.  </t>
          <ul spacing="normal">
            <li>
              <t>error-app-tag 'malformed-message' is returned by the CORECONF server when the payload received from the CORECONF client does not contain a well-formed CBOR content as defined in <xref target="RFC8949"/> or does not comply with the CBOR structure defined within this document.</t>
            </li>
            <li>
              <t>error-app-tag 'data-not-unique' is returned by the CORECONF server when the validation of the 'unique' constraint of a list or leaf-list fails.</t>
            </li>
            <li>
              <t>error-app-tag 'too-many-elements' is returned by the CORECONF server when the validation of the 'max-elements' constraint of a list or leaf-list fails.</t>
            </li>
            <li>
              <t>error-app-tag 'too-few-elements' is returned by the CORECONF server when the validation of the 'min-elements' constraint of a list or leaf-list fails.</t>
            </li>
            <li>
              <t>error-app-tag 'must-violation' is returned by the CORECONF server when the restrictions imposed by a 'must' statement are violated.</t>
            </li>
            <li>
              <t>error-app-tag 'duplicate' is returned by the CORECONF server when a client tries to create a duplicate list or leaf-list entry.</t>
            </li>
          </ul>
        </li>
        <li>
          <t>error-tag 'invalid-value' is returned by the CORECONF server when the CORECONF client tries to update or create a leaf with a value encoded using an invalid CBOR datatype or if the 'range', 'length', 'pattern' or 'require-instance' constrain is not fulfilled.  </t>
          <ul spacing="normal">
            <li>
              <t>error-app-tag 'invalid-datatype' is returned by the CORECONF server when CBOR encoding does not follow the rules set by the YANG Build-In type or when the value is incompatible with it (e.g., a value greater than 127 for an int8, undefined enumeration).</t>
            </li>
            <li>
              <t>error-app-tag 'not-in-range' is returned by the CORECONF server when the validation of the 'range' property fails.</t>
            </li>
            <li>
              <t>error-app-tag 'invalid-length' is returned by the CORECONF server when the validation of the 'length' property fails.</t>
            </li>
            <li>
              <t>error-app-tag 'pattern-test-failed' is returned by the CORECONF server when the validation of the 'pattern' property fails.</t>
            </li>
          </ul>
        </li>
        <li>
          <t>error-tag 'missing-element' is returned by the CORECONF server when the operation requested by a CORECONF client fails to comply with the 'mandatory' constraint defined. The 'mandatory' constraint is enforced for leafs and choices, unless the node or any of its ancestors have a 'when' condition or 'if-feature' expression that evaluates to 'false'.  </t>
          <ul spacing="normal">
            <li>
              <t>error-app-tag 'missing-key' is returned by the CORECONF server to further qualify a missing-element error. This error is returned when the CORECONF client tries to create or list instance, without all the 'key' specified or when the CORECONF client tries to delete a leaf listed as a 'key'.</t>
            </li>
            <li>
              <t>error-app-tag 'missing-input-parameter' is returned by the CORECONF server when the input parameters of an RPC or action are incomplete.</t>
            </li>
          </ul>
        </li>
        <li>
          <t>error-tag 'unknown-element' is returned by the CORECONF server when the CORECONF client tries to access a data node of a YANG module not supported, of a data node associated with an 'if-feature' expression evaluated to 'false' or to a 'when' condition evaluated to 'false'.</t>
        </li>
        <li>
          <t>error-tag 'bad-element' is returned by the CORECONF server when the CORECONF client tries to create data nodes for more than one case in a choice.</t>
        </li>
        <li>
          <t>error-tag 'data-missing' is returned by the CORECONF server when a data node required to accept the request is not present.  </t>
          <ul spacing="normal">
            <li>
              <t>error-app-tag 'instance-required' is returned by the CORECONF server when a leaf of type 'instance-identifier' or 'leafref' marked with require-instance set to 'true' refers to an instance that does not exist.</t>
            </li>
            <li>
              <t>error-app-tag 'missing-choice' is returned by the CORECONF server when no nodes exist in a mandatory choice.</t>
            </li>
          </ul>
        </li>
        <li>
          <t>error-tag 'error' is returned by the CORECONF server when an unspecified error has occurred.</t>
        </li>
      </ul>
      <t>For example, the CORECONF server might return the following error.</t>
      <artwork><![CDATA[
RES:  4.00 Bad Request
     (Content-Format: application/yang-data+cbor; id=sid)
{
  1024 : {
    4 : 1011,        / error-tag (SID 1028) /
                     /   = invalid-value (SID 1011) /
    1 : 1018,        / error-app-tag (SID 1025) /
                     /   = not-in-range (SID 1018) /
    2 : 1740,        / error-data-node (SID 1026) /
                     /   = timezone-utc-offset (SID 1740) /
    3 : "maximum value exceeded" / error-message (SID 1027) /
  }
}
]]></artwork>
      <!-- Note that we do not
use application/yang-instances+cbor-seq here, as we don't have an instance.
-->

</section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>For secure network management, it is important to restrict access to configuration variables
only to authorized parties. CORECONF re-uses the security mechanisms already available to CoAP,
this includes DTLS <xref target="RFC6347"/><xref target="RFC9147"/> and OSCORE <xref target="RFC8613"/> for protected access to
resources, as well as suitable authentication and authorization mechanisms, for
example those defined in ACE OAuth <xref target="RFC9200"/>.</t>
      <t>All the security considerations of <xref target="RFC7252"/>, <xref target="RFC7959"/>, <xref target="RFC8132"/> and
<xref target="RFC7641"/> apply to this document as well. The use of NoSec (<xref section="9" sectionFormat="of" target="RFC7252"/>), when OSCORE
is not used, is <bcp14>NOT RECOMMENDED</bcp14>.</t>
      <t>In addition, mechanisms for authentication and authorization may need to be
selected if not provided with the CoAP security mode.</t>
      <t>As <xref target="RFC9254"/> and <xref target="RFC4648"/> are used for payload and SID
encoding, the security considerations of those documents also need to be
well-understood.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <section anchor="resource-type-rt-link-target-attribute-values-registry">
        <name>Resource Type (rt=) Link Target Attribute Values Registry</name>
        <t>This document adds the following resource type to the "Resource Type (rt=) Link Target Attribute Values", within the "Constrained RESTful Environments (CoRE) Parameters" registry.</t>
        <table align="left">
          <thead>
            <tr>
              <th align="left">Value</th>
              <th align="left">Description</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">core.c.ds</td>
              <td align="left">YANG datastore</td>
              <td align="left">RFC XXXX</td>
            </tr>
            <tr>
              <td align="left">core.c.dn</td>
              <td align="left">YANG data node</td>
              <td align="left">RFC XXXX</td>
            </tr>
            <tr>
              <td align="left">core.c.yl</td>
              <td align="left">YANG module library</td>
              <td align="left">RFC XXXX</td>
            </tr>
            <tr>
              <td align="left">core.c.es</td>
              <td align="left">YANG event stream</td>
              <td align="left">RFC XXXX</td>
            </tr>
          </tbody>
        </table>
        <t>// RFC Ed.: replace RFC XXXX with this RFC number and remove this note.</t>
      </section>
      <section anchor="coap-content-formats-registry">
        <name>CoAP Content-Formats Registry</name>
        <t>This document adds the following Content-Format to the "CoAP Content-Formats", within the "Constrained RESTful Environments (CoRE) Parameters" registry.</t>
        <table align="left">
          <thead>
            <tr>
              <th align="left">Media Type</th>
              <th align="left">Content Coding</th>
              <th align="left">ID</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">application/yang-identifiers+cbor-seq</td>
              <td align="left"> </td>
              <td align="left">TBD2</td>
              <td align="left">RFC XXXX</td>
            </tr>
            <tr>
              <td align="left">application/yang-instances+cbor-seq</td>
              <td align="left"> </td>
              <td align="left">TBD3</td>
              <td align="left">RFC XXXX</td>
            </tr>
          </tbody>
        </table>
        <t>// RFC Ed.: replace TBD1, TBD2 and TBD3 with assigned IDs and remove this note.
// RFC Ed.: replace RFC XXXX with this RFC number and remove this note.</t>
      </section>
      <section anchor="media-types-registry">
        <name>Media Types Registry</name>
        <t>This document adds the following media types to the "Media Types" registry.</t>
        <table align="left">
          <thead>
            <tr>
              <th align="left">Name</th>
              <th align="left">Template</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">yang-identifiers+cbor-seq</td>
              <td align="left">application/yang-identifiers+cbor-seq</td>
              <td align="left">RFC XXXX</td>
            </tr>
            <tr>
              <td align="left">yang-instances+cbor-seq</td>
              <td align="left">application/yang-instances+cbor-seq</td>
              <td align="left">RFC XXXX</td>
            </tr>
          </tbody>
        </table>
        <t>Each of these media types share the following information:</t>
        <ul spacing="normal">
          <li>
            <t>Subtype name: &lt;as listed in table&gt;</t>
          </li>
          <li>
            <t>Required parameters: N/A</t>
          </li>
          <li>
            <t>Optional parameters: N/A</t>
          </li>
          <li>
            <t>Encoding considerations: binary</t>
          </li>
          <li>
            <t>Security considerations: See the Security Considerations section of RFC XXXX</t>
          </li>
          <li>
            <t>Interoperability considerations: N/A</t>
          </li>
          <li>
            <t>Published specification: RFC XXXX</t>
          </li>
          <li>
            <t>Applications that use this media type: CORECONF</t>
          </li>
          <li>
            <t>Fragment identifier considerations: N/A</t>
          </li>
          <li>
            <t>Additional information:</t>
          </li>
        </ul>
        <artwork><![CDATA[
*  Deprecated alias names for this type: N/A

*  Magic number(s): N/A

*  File extension(s): N/A

*  Macintosh file type code(s): N/A
]]></artwork>
        <ul spacing="normal">
          <li>
            <t>Person &amp; email address to contact for further information: iesg&amp;ietf.org</t>
          </li>
          <li>
            <t>Intended usage: COMMON</t>
          </li>
          <li>
            <t>Restrictions on usage: N/A</t>
          </li>
          <li>
            <t>Author: Michel Veillette</t>
          </li>
          <li>
            <t>Change Controller: IETF</t>
          </li>
          <li>
            <t>Provisional registration?  No</t>
          </li>
        </ul>
        <t>// RFC Ed.: replace RFC XXXX with this RFC number and remove this note.</t>
      </section>
      <section anchor="yang-namespace-and-module-name-registration">
        <name>YANG Namespace and Module Name Registration</name>
        <t>This document registers the following XML namespace URN in the "IETF XML
Registry", following the format defined in <xref target="RFC3688"/>:</t>
        <t>URI: please assign urn:ietf:params:xml:ns:yang:ietf-coreconf</t>
        <t>Registrant Contact: The IESG.</t>
        <t>XML: N/A, the requested URI is an XML namespace.</t>
        <t>Reference:    RFC XXXX</t>
        <t>IANA is requested to register the following YANG module in the "YANG Module Names" registry <xref target="RFC6020"/>:</t>
        <t>Name: ietf-coreconf</t>
        <t>Namespace: urn:ietf:params:xml:ns:yang:ietf-coreconf</t>
        <t>Prefix: coreconf</t>
        <t>Reference: RFC XXXX</t>
        <t>// RFC Ed.: please replace XXXX with RFC number and remove this note</t>
        <t>The YANG module and SID file are in <xref target="ietf-coreconf-yang"/> and
<xref target="ietf-coreconf-sid"/>, respectively.</t>
      </section>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC3688">
          <front>
            <title>The IETF XML Registry</title>
            <author fullname="M. Mealling" initials="M." surname="Mealling"/>
            <date month="January" year="2004"/>
            <abstract>
              <t>This document describes an IANA maintained registry for IETF standards which use Extensible Markup Language (XML) related items such as Namespaces, Document Type Declarations (DTDs), Schemas, and Resource Description Framework (RDF) Schemas.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="81"/>
          <seriesInfo name="RFC" value="3688"/>
          <seriesInfo name="DOI" value="10.17487/RFC3688"/>
        </reference>
        <reference anchor="RFC6020">
          <front>
            <title>YANG - A Data Modeling Language for the Network Configuration Protocol (NETCONF)</title>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <date month="October" year="2010"/>
            <abstract>
              <t>YANG is a data modeling language used to model configuration and state data manipulated by the Network Configuration Protocol (NETCONF), NETCONF remote procedure calls, and NETCONF notifications. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6020"/>
          <seriesInfo name="DOI" value="10.17487/RFC6020"/>
        </reference>
        <reference anchor="RFC4648">
          <front>
            <title>The Base16, Base32, and Base64 Data Encodings</title>
            <author fullname="S. Josefsson" initials="S." surname="Josefsson"/>
            <date month="October" year="2006"/>
            <abstract>
              <t>This document describes the commonly used base 64, base 32, and base 16 encoding schemes. It also discusses the use of line-feeds in encoded data, use of padding in encoded data, use of non-alphabet characters in encoded data, use of different encoding alphabets, and canonical encodings. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4648"/>
          <seriesInfo name="DOI" value="10.17487/RFC4648"/>
        </reference>
        <reference anchor="RFC5277">
          <front>
            <title>NETCONF Event Notifications</title>
            <author fullname="S. Chisholm" initials="S." surname="Chisholm"/>
            <author fullname="H. Trevino" initials="H." surname="Trevino"/>
            <date month="July" year="2008"/>
            <abstract>
              <t>This document defines mechanisms that provide an asynchronous message notification delivery service for the Network Configuration protocol (NETCONF). This is an optional capability built on top of the base NETCONF definition. This document defines the capabilities and operations necessary to support this service. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5277"/>
          <seriesInfo name="DOI" value="10.17487/RFC5277"/>
        </reference>
        <reference anchor="RFC6241">
          <front>
            <title>Network Configuration Protocol (NETCONF)</title>
            <author fullname="R. Enns" initials="R." role="editor" surname="Enns"/>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <author fullname="J. Schoenwaelder" initials="J." role="editor" surname="Schoenwaelder"/>
            <author fullname="A. Bierman" initials="A." role="editor" surname="Bierman"/>
            <date month="June" year="2011"/>
            <abstract>
              <t>The Network Configuration Protocol (NETCONF) defined in this document provides mechanisms to install, manipulate, and delete the configuration of network devices. It uses an Extensible Markup Language (XML)-based data encoding for the configuration data as well as the protocol messages. The NETCONF protocol operations are realized as remote procedure calls (RPCs). This document obsoletes RFC 4741. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6241"/>
          <seriesInfo name="DOI" value="10.17487/RFC6241"/>
        </reference>
        <reference anchor="RFC6243">
          <front>
            <title>With-defaults Capability for NETCONF</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="B. Lengyel" initials="B." surname="Lengyel"/>
            <date month="June" year="2011"/>
            <abstract>
              <t>The Network Configuration Protocol (NETCONF) defines ways to read and edit configuration data from a NETCONF server. In some cases, part of this data may not be set by the NETCONF client, but rather a default value known to the server is used instead. In many situations the NETCONF client has a priori knowledge about default data, so the NETCONF server does not need to save it in a NETCONF configuration datastore or send it to the client in a retrieval operation reply. In other situations the NETCONF client will need this data from the server. Not all server implementations treat this default data the same way. This document defines a capability-based extension to the NETCONF protocol that allows the NETCONF client to identify how defaults are processed by the server, and also defines new mechanisms for client control of server processing of default data. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6243"/>
          <seriesInfo name="DOI" value="10.17487/RFC6243"/>
        </reference>
        <reference anchor="RFC8949">
          <front>
            <title>Concise Binary Object Representation (CBOR)</title>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <date month="December" year="2020"/>
            <abstract>
              <t>The Concise Binary Object Representation (CBOR) is a data format whose design goals include the possibility of extremely small code size, fairly small message size, and extensibility without the need for version negotiation. These design goals make it different from earlier binary serializations such as ASN.1 and MessagePack.</t>
              <t>This document obsoletes RFC 7049, providing editorial improvements, new details, and errata fixes while keeping full compatibility with the interchange format of RFC 7049. It does not create a new version of the format.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="94"/>
          <seriesInfo name="RFC" value="8949"/>
          <seriesInfo name="DOI" value="10.17487/RFC8949"/>
        </reference>
        <reference anchor="RFC8610">
          <front>
            <title>Concise Data Definition Language (CDDL): A Notational Convention to Express Concise Binary Object Representation (CBOR) and JSON Data Structures</title>
            <author fullname="H. Birkholz" initials="H." surname="Birkholz"/>
            <author fullname="C. Vigano" initials="C." surname="Vigano"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <date month="June" year="2019"/>
            <abstract>
              <t>This document proposes a notational convention to express Concise Binary Object Representation (CBOR) data structures (RFC 7049). Its main goal is to provide an easy and unambiguous way to express structures for protocol messages and data formats that use CBOR or JSON.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8610"/>
          <seriesInfo name="DOI" value="10.17487/RFC8610"/>
        </reference>
        <reference anchor="RFC8742">
          <front>
            <title>Concise Binary Object Representation (CBOR) Sequences</title>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <date month="February" year="2020"/>
            <abstract>
              <t>This document describes the Concise Binary Object Representation (CBOR) Sequence format and associated media type "application/cbor-seq". A CBOR Sequence consists of any number of encoded CBOR data items, simply concatenated in sequence.</t>
              <t>Structured syntax suffixes for media types allow other media types to build on them and make it explicit that they are built on an existing media type as their foundation. This specification defines and registers "+cbor-seq" as a structured syntax suffix for CBOR Sequences.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8742"/>
          <seriesInfo name="DOI" value="10.17487/RFC8742"/>
        </reference>
        <reference anchor="RFC7252">
          <front>
            <title>The Constrained Application Protocol (CoAP)</title>
            <author fullname="Z. Shelby" initials="Z." surname="Shelby"/>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <date month="June" year="2014"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a specialized web transfer protocol for use with constrained nodes and constrained (e.g., low-power, lossy) networks. The nodes often have 8-bit microcontrollers with small amounts of ROM and RAM, while constrained networks such as IPv6 over Low-Power Wireless Personal Area Networks (6LoWPANs) often have high packet error rates and a typical throughput of 10s of kbit/s. The protocol is designed for machine- to-machine (M2M) applications such as smart energy and building automation.</t>
              <t>CoAP provides a request/response interaction model between application endpoints, supports built-in discovery of services and resources, and includes key concepts of the Web such as URIs and Internet media types. CoAP is designed to easily interface with HTTP for integration with the Web while meeting specialized requirements such as multicast support, very low overhead, and simplicity for constrained environments.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7252"/>
          <seriesInfo name="DOI" value="10.17487/RFC7252"/>
        </reference>
        <reference anchor="RFC7950">
          <front>
            <title>The YANG 1.1 Data Modeling Language</title>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <date month="August" year="2016"/>
            <abstract>
              <t>YANG is a data modeling language used to model configuration data, state data, Remote Procedure Calls, and notifications for network management protocols. This document describes the syntax and semantics of version 1.1 of the YANG language. YANG version 1.1 is a maintenance release of the YANG language, addressing ambiguities and defects in the original specification. There are a small number of backward incompatibilities from YANG version 1. This document also specifies the YANG mappings to the Network Configuration Protocol (NETCONF).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7950"/>
          <seriesInfo name="DOI" value="10.17487/RFC7950"/>
        </reference>
        <reference anchor="RFC7959">
          <front>
            <title>Block-Wise Transfers in the Constrained Application Protocol (CoAP)</title>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="Z. Shelby" initials="Z." role="editor" surname="Shelby"/>
            <date month="August" year="2016"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a RESTful transfer protocol for constrained nodes and networks. Basic CoAP messages work well for small payloads from sensors and actuators; however, applications will need to transfer larger payloads occasionally -- for instance, for firmware updates. In contrast to HTTP, where TCP does the grunt work of segmenting and resequencing, CoAP is based on datagram transports such as UDP or Datagram Transport Layer Security (DTLS). These transports only offer fragmentation, which is even more problematic in constrained nodes and networks, limiting the maximum size of resource representations that can practically be transferred.</t>
              <t>Instead of relying on IP fragmentation, this specification extends basic CoAP with a pair of "Block" options for transferring multiple blocks of information from a resource representation in multiple request-response pairs. In many important cases, the Block options enable a server to be truly stateless: the server can handle each block transfer separately, with no need for a connection setup or other server-side memory of previous block transfers. Essentially, the Block options provide a minimal way to transfer larger representations in a block-wise fashion.</t>
              <t>A CoAP implementation that does not support these options generally is limited in the size of the representations that can be exchanged, so there is an expectation that the Block options will be widely used in CoAP implementations. Therefore, this specification updates RFC 7252.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7959"/>
          <seriesInfo name="DOI" value="10.17487/RFC7959"/>
        </reference>
        <reference anchor="RFC7641">
          <front>
            <title>Observing Resources in the Constrained Application Protocol (CoAP)</title>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <date month="September" year="2015"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a RESTful application protocol for constrained nodes and networks. The state of a resource on a CoAP server can change over time. This document specifies a simple protocol extension for CoAP that enables CoAP clients to "observe" resources, i.e., to retrieve a representation of a resource and keep this representation updated by the server over a period of time. The protocol follows a best-effort approach for sending new representations to clients and provides eventual consistency between the state observed by each client and the actual resource state at the server.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7641"/>
          <seriesInfo name="DOI" value="10.17487/RFC7641"/>
        </reference>
        <reference anchor="RFC8132">
          <front>
            <title>PATCH and FETCH Methods for the Constrained Application Protocol (CoAP)</title>
            <author fullname="P. van der Stok" initials="P." surname="van der Stok"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="A. Sehgal" initials="A." surname="Sehgal"/>
            <date month="April" year="2017"/>
            <abstract>
              <t>The methods defined in RFC 7252 for the Constrained Application Protocol (CoAP) only allow access to a complete resource, not to parts of a resource. In case of resources with larger or complex data, or in situations where resource continuity is required, replacing or requesting the whole resource is undesirable. Several applications using CoAP need to access parts of the resources.</t>
              <t>This specification defines the new CoAP methods, FETCH, PATCH, and iPATCH, which are used to access and update parts of a resource.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8132"/>
          <seriesInfo name="DOI" value="10.17487/RFC8132"/>
        </reference>
        <reference anchor="RFC8040">
          <front>
            <title>RESTCONF Protocol</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <author fullname="K. Watsen" initials="K." surname="Watsen"/>
            <date month="January" year="2017"/>
            <abstract>
              <t>This document describes an HTTP-based protocol that provides a programmatic interface for accessing data defined in YANG, using the datastore concepts defined in the Network Configuration Protocol (NETCONF).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8040"/>
          <seriesInfo name="DOI" value="10.17487/RFC8040"/>
        </reference>
        <reference anchor="RFC9254">
          <front>
            <title>Encoding of Data Modeled with YANG in the Concise Binary Object Representation (CBOR)</title>
            <author fullname="M. Veillette" initials="M." role="editor" surname="Veillette"/>
            <author fullname="I. Petrov" initials="I." role="editor" surname="Petrov"/>
            <author fullname="A. Pelov" initials="A." surname="Pelov"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="M. Richardson" initials="M." surname="Richardson"/>
            <date month="July" year="2022"/>
            <abstract>
              <t>YANG (RFC 7950) is a data modeling language used to model configuration data, state data, parameters and results of Remote Procedure Call (RPC) operations or actions, and notifications.</t>
              <t>This document defines encoding rules for YANG in the Concise Binary Object Representation (CBOR) (RFC 8949).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9254"/>
          <seriesInfo name="DOI" value="10.17487/RFC9254"/>
        </reference>
        <reference anchor="I-D.ietf-core-sid">
          <front>
            <title>YANG Schema Item iDentifier (YANG SID)</title>
            <author fullname="Michel Veillette" initials="M." surname="Veillette">
              <organization>Trilliant Networks Inc.</organization>
            </author>
            <author fullname="Alexander Pelov" initials="A." surname="Pelov">
              <organization>IMT Atlantique</organization>
            </author>
            <author fullname="Ivaylo Petrov" initials="I." surname="Petrov">
              <organization>Google Switzerland GmbH</organization>
            </author>
            <author fullname="Carsten Bormann" initials="C." surname="Bormann">
              <organization>Universität Bremen TZI</organization>
            </author>
            <author fullname="Michael Richardson" initials="M." surname="Richardson">
              <organization>Sandelman Software Works</organization>
            </author>
            <date day="22" month="December" year="2023"/>
            <abstract>
              <t>   YANG Schema Item iDentifiers (YANG SID) are globally unique 63-bit
   unsigned integers used to identify YANG items, as a more compact
   method to identify YANG items that can be used for efficiency and in
   constrained environments (RFC 7228).  This document defines the
   semantics, the registration, and assignment processes of YANG SIDs
   for IETF managed YANG modules.  To enable the implementation of these
   processes, this document also defines a file format used to persist
   and publish assigned YANG SIDs.


   // The present version (–24) is intended to address the remaining
   // IESG comments.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-core-sid-24"/>
        </reference>
        <reference anchor="I-D.ietf-core-yang-library">
          <front>
            <title>Constrained YANG Module Library</title>
            <author fullname="Michel Veillette" initials="M." surname="Veillette">
              <organization>Trilliant Networks Inc.</organization>
            </author>
            <author fullname="Ivaylo Petrov" initials="I." surname="Petrov">
              <organization>Acklio</organization>
            </author>
            <date day="11" month="January" year="2021"/>
            <abstract>
              <t>   This document describes a constrained version of the YANG library
   that provides information about the YANG modules, datastores, and
   datastore schemas used by a constrained network management server
   (e.g., a CORECONF server).

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-core-yang-library-03"/>
        </reference>
        <reference anchor="RFC8342">
          <front>
            <title>Network Management Datastore Architecture (NMDA)</title>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <author fullname="J. Schoenwaelder" initials="J." surname="Schoenwaelder"/>
            <author fullname="P. Shafer" initials="P." surname="Shafer"/>
            <author fullname="K. Watsen" initials="K." surname="Watsen"/>
            <author fullname="R. Wilton" initials="R." surname="Wilton"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>Datastores are a fundamental concept binding the data models written in the YANG data modeling language to network management protocols such as the Network Configuration Protocol (NETCONF) and RESTCONF. This document defines an architectural framework for datastores based on the experience gained with the initial simpler model, addressing requirements that were not well supported in the initial model. This document updates RFC 7950.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8342"/>
          <seriesInfo name="DOI" value="10.17487/RFC8342"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC6347">
          <front>
            <title>Datagram Transport Layer Security Version 1.2</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <author fullname="N. Modadugu" initials="N." surname="Modadugu"/>
            <date month="January" year="2012"/>
            <abstract>
              <t>This document specifies version 1.2 of the Datagram Transport Layer Security (DTLS) protocol. The DTLS protocol provides communications privacy for datagram protocols. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery. The DTLS protocol is based on the Transport Layer Security (TLS) protocol and provides equivalent security guarantees. Datagram semantics of the underlying transport are preserved by the DTLS protocol. This document updates DTLS 1.0 to work with TLS version 1.2. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6347"/>
          <seriesInfo name="DOI" value="10.17487/RFC6347"/>
        </reference>
        <reference anchor="RFC6690">
          <front>
            <title>Constrained RESTful Environments (CoRE) Link Format</title>
            <author fullname="Z. Shelby" initials="Z." surname="Shelby"/>
            <date month="August" year="2012"/>
            <abstract>
              <t>This specification defines Web Linking using a link format for use by constrained web servers to describe hosted resources, their attributes, and other relationships between links. Based on the HTTP Link Header field defined in RFC 5988, the Constrained RESTful Environments (CoRE) Link Format is carried as a payload and is assigned an Internet media type. "RESTful" refers to the Representational State Transfer (REST) architecture. A well-known URI is defined as a default entry point for requesting the links hosted by a server. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6690"/>
          <seriesInfo name="DOI" value="10.17487/RFC6690"/>
        </reference>
        <reference anchor="RFC8343">
          <front>
            <title>A YANG Data Model for Interface Management</title>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <date month="March" year="2018"/>
            <abstract>
              <t>This document defines a YANG data model for the management of network interfaces. It is expected that interface-type-specific data models augment the generic interfaces data model defined in this document. The data model includes definitions for configuration and system state (status information and counters for the collection of statistics).</t>
              <t>The YANG data model in this document conforms to the Network Management Datastore Architecture (NMDA) defined in RFC 8342.</t>
              <t>This document obsoletes RFC 7223.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8343"/>
          <seriesInfo name="DOI" value="10.17487/RFC8343"/>
        </reference>
        <reference anchor="RFC7317">
          <front>
            <title>A YANG Data Model for System Management</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <author fullname="M. Bjorklund" initials="M." surname="Bjorklund"/>
            <date month="August" year="2014"/>
            <abstract>
              <t>This document defines a YANG data model for the configuration and identification of some common system properties within a device containing a Network Configuration Protocol (NETCONF) server. This document also includes data node definitions for system identification, time-of-day management, user management, DNS resolver configuration, and some protocol operations for system management.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7317"/>
          <seriesInfo name="DOI" value="10.17487/RFC7317"/>
        </reference>
        <reference anchor="RFC8613">
          <front>
            <title>Object Security for Constrained RESTful Environments (OSCORE)</title>
            <author fullname="G. Selander" initials="G." surname="Selander"/>
            <author fullname="J. Mattsson" initials="J." surname="Mattsson"/>
            <author fullname="F. Palombini" initials="F." surname="Palombini"/>
            <author fullname="L. Seitz" initials="L." surname="Seitz"/>
            <date month="July" year="2019"/>
            <abstract>
              <t>This document defines Object Security for Constrained RESTful Environments (OSCORE), a method for application-layer protection of the Constrained Application Protocol (CoAP), using CBOR Object Signing and Encryption (COSE). OSCORE provides end-to-end protection between endpoints communicating using CoAP or CoAP-mappable HTTP. OSCORE is designed for constrained nodes and networks supporting a range of proxy operations, including translation between different transport protocols.</t>
              <t>Although an optional functionality of CoAP, OSCORE alters CoAP options processing and IANA registration. Therefore, this document updates RFC 7252.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8613"/>
          <seriesInfo name="DOI" value="10.17487/RFC8613"/>
        </reference>
        <reference anchor="RFC9147">
          <front>
            <title>The Datagram Transport Layer Security (DTLS) Protocol Version 1.3</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <author fullname="H. Tschofenig" initials="H." surname="Tschofenig"/>
            <author fullname="N. Modadugu" initials="N." surname="Modadugu"/>
            <date month="April" year="2022"/>
            <abstract>
              <t>This document specifies version 1.3 of the Datagram Transport Layer Security (DTLS) protocol. DTLS 1.3 allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</t>
              <t>The DTLS 1.3 protocol is based on the Transport Layer Security (TLS) 1.3 protocol and provides equivalent security guarantees with the exception of order protection / non-replayability. Datagram semantics of the underlying transport are preserved by the DTLS protocol.</t>
              <t>This document obsoletes RFC 6347.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9147"/>
          <seriesInfo name="DOI" value="10.17487/RFC9147"/>
        </reference>
        <reference anchor="RFC9200">
          <front>
            <title>Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework (ACE-OAuth)</title>
            <author fullname="L. Seitz" initials="L." surname="Seitz"/>
            <author fullname="G. Selander" initials="G." surname="Selander"/>
            <author fullname="E. Wahlstroem" initials="E." surname="Wahlstroem"/>
            <author fullname="S. Erdtman" initials="S." surname="Erdtman"/>
            <author fullname="H. Tschofenig" initials="H." surname="Tschofenig"/>
            <date month="August" year="2022"/>
            <abstract>
              <t>This specification defines a framework for authentication and authorization in Internet of Things (IoT) environments called ACE-OAuth. The framework is based on a set of building blocks including OAuth 2.0 and the Constrained Application Protocol (CoAP), thus transforming a well-known and widely used authorization solution into a form suitable for IoT devices. Existing specifications are used where possible, but extensions are added and profiles are defined to better serve the IoT use cases.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9200"/>
          <seriesInfo name="DOI" value="10.17487/RFC9200"/>
        </reference>
      </references>
    </references>
    <?line 1383?>

<section anchor="ietf-coreconf-yang">
      <name>ietf-coreconf YANG module</name>
      <t>This appendix is normative.</t>
      <figure anchor="yang-ietf-coreconf">
        <name>ietf-coreconf YANG module</name>
        <sourcecode type="yang" name="ietf-coreconf@2024-03-04.yang" markers="true"><![CDATA[
module ietf-coreconf {
  yang-version 1.1;

  namespace "urn:ietf:params:xml:ns:yang:ietf-coreconf";
  prefix coreconf;

  import ietf-datastores {
    prefix ds;
    reference
      "RFC 8342: Network Management Datastore Architecture (NMDA)";
  }

  import ietf-restconf {
    prefix rc;
    description
      "This import statement is required to access
       the yang-data extension defined in RFC 8040.";
    reference "RFC 8040: RESTCONF Protocol";
  }

  organization
    "IETF Core Working Group";

  contact
    "WG Web:   <https://datatracker.ietf.org/wg/core/>
     WG List:  <mailto:core@ietf.org>

     Michel Veillette
     <mailto:michel.veillette@trilliantinc.com>

     Alexander Pelov
     <mailto:alexander.pelov@imt-atlantique.fr>

     Peter van der Stok
     <mailto:stokcons@kpnmail.nl>

     Andy Bierman
     <mailto:andy@yumaworks.com>";

  description
    "This module contains the different definitions required
     by the CORECONF protocol.

     Copyright (c) 2024 IETF Trust and the persons identified as
     authors of the code.  All rights reserved.

     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject
     to the license terms contained in, the Revised BSD License
     set forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
     (https://trustee.ietf.org/license-info).

     This version of this YANG module is part of RFC XXXX;
     see the RFC itself for full legal notices.";

  revision 2024-03-04 {
     description
      "Initial revision.";
    reference
      "[I-D.ietf-core-comi] CoAP Management Interface";
  }

  identity unified {
    base ds:datastore;
    description
      "Identifier of the unified configuration and operational
       state datastore.";
  }

  identity error-tag {
    description
      "Base identity for error-tag.";
  }

  identity operation-failed {
    base error-tag;
    description
      "Returned by the CORECONF server when the operation request
       can't be processed successfully.";
  }

  identity invalid-value {
    base error-tag;
    description
      "Returned by the CORECONF server when the CORECONF client tries
       to update or create a leaf with a value encoded using an
       invalid CBOR datatype or if the 'range', 'length',
       'pattern' or 'require-instance' constrain is not
       fulfilled.";
  }

  identity missing-element {
    base error-tag;
    description
      "Returned by the CORECONF server when the operation requested
       by a CORECONF client fails to comply with the 'mandatory'
       constraint defined. The 'mandatory' constraint is
       enforced for leafs and choices, unless the node or any of
       its ancestors have a 'when' condition or 'if-feature'
       expression that evaluates to 'false'.";
  }

  identity unknown-element {
    base error-tag;
    description
      "Returned by the CORECONF server when the CORECONF client tries
       to access a data node of a YANG module not supported, of a
       data node associated with an 'if-feature' expression
       evaluated to 'false' or to a 'when' condition evaluated
       to 'false'.";
  }

  identity bad-element {
    base error-tag;
    description
      "Returned by the CORECONF server when the CORECONF client tries
       to create data nodes for more than one case in a choice.";
  }

  identity data-missing {
    base error-tag;
    description
      "Returned by the CORECONF server when a data node required to
       accept the request is not present.";
  }

  identity error {
    base error-tag;
    description
      "Returned by the CORECONF server when an unspecified error has
      occurred.";
  }

  identity error-app-tag {
    description
      "Base identity for error-app-tag.";
  }

  identity malformed-message {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the payload received
       from the CORECONF client don't contain a well-formed CBOR
       content as defined in [RFC8949] or don't
       comply with the CBOR structure defined within this
       document.";
  }

  identity data-not-unique {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the validation of the
       'unique' constraint of a list or leaf-list fails.";
  }

  identity too-many-elements {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the validation of the
       'max-elements' constraint of a list or leaf-list fails.";
  }

  identity too-few-elements {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the validation of the
       'min-elements' constraint of a list or leaf-list fails.";
  }

  identity must-violation {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the restrictions
       imposed by a 'must' statement are violated.";
  }

  identity duplicate {
    base error-app-tag;
    description
      "Returned by the CORECONF server when a client tries to create
       a duplicate list or leaf-list entry.";
  }

  identity invalid-datatype {
    base error-app-tag;
    description
      "Returned by the CORECONF server when CBOR encoding is
       incorect or when the value encoded is incompatible with
       the YANG Built-In type. (e.g., value greater than 127
       for an int8, undefined enumeration).";
  }

  identity not-in-range {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the validation of the
       'range' property fails.";
  }

  identity invalid-length {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the validation of the
       'length' property fails.";
  }

  identity pattern-test-failed {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the validation of the
       'pattern' property fails.";
  }

  identity missing-key {
    base error-app-tag;
    description
      "Returned by the CORECONF server to further qualify a
       missing-element error. This error is returned when the
       CORECONF client tries to create a list instance, without all
       the 'key' specified or when the CORECONF client tries to
       delete a leaf listed as a 'key'.";
  }

  identity missing-input-parameter {
    base error-app-tag;
    description
      "Returned by the CORECONF server when the input parameters
       of a RPC or action are incomplete.";
  }

  identity instance-required {
    base error-app-tag;
    description
      "Returned by the CORECONF server when a leaf of type
       'instance-identifier' or 'leafref' marked with
       require-instance set to 'true' refers to an instance
       that does not exist.";
  }

  identity missing-choice {
    base error-app-tag;
    description
      "Returned by the CORECONF server when no nodes exist in a
       mandatory choice.";
  }

  rc:yang-data coreconf-error {
    container error {
      description
        "Optional payload of a 4.00 Bad Request CoAP error.";

      leaf error-tag {
        type identityref {
          base error-tag;
        }
        mandatory true;
        description
          "The enumerated error-tag.";
      }

      leaf error-app-tag {
        type identityref {
          base error-app-tag;
        }
        description
          "The application-specific error-tag.";
      }

      leaf error-data-node {
        type instance-identifier;
        description
          "When the error reported is caused by a specific data node,
           this leaf identifies the data node in error.";
      }

      leaf error-message {
        type string;
        description
          "A message describing the error.";
      }
    }
  }
}
]]></sourcecode>
      </figure>
    </section>
    <section anchor="ietf-coreconf-sid">
      <name>ietf-coreconf .sid file</name>
      <t>This appendix is normative.</t>
      <figure anchor="yang-ietf-coreconf-sid">
        <name>ietf-coreconf SID file</name>
        <sourcecode type="yang" name="ietf-coreconf@2024-03-04.sid" markers="true"><![CDATA[
{
  "ietf-sid-file:sid-file": {
    "module-name": "ietf-coreconf",
    "module-revision": "2024-03-04",
    "assignment-range": [
      {
        "entry-point": "1000",
        "size": "100"
      }
    ],
    "item": [
      {
        "namespace": "module",
        "identifier": "ietf-coreconf",
        "sid": "1000"
      },
      {
        "namespace": "identity",
        "identifier": "bad-element",
        "sid": "1001"
      },
      {
        "namespace": "identity",
        "identifier": "data-missing",
        "sid": "1002"
      },
      {
        "namespace": "identity",
        "identifier": "data-not-unique",
        "sid": "1003"
      },
      {
        "namespace": "identity",
        "identifier": "duplicate",
        "sid": "1004"
      },
      {
        "namespace": "identity",
        "identifier": "error",
        "sid": "1005"
      },
      {
        "namespace": "identity",
        "identifier": "error-app-tag",
        "sid": "1006"
      },
      {
        "namespace": "identity",
        "identifier": "error-tag",
        "sid": "1007"
      },
      {
        "namespace": "identity",
        "identifier": "instance-required",
        "sid": "1008"
      },
      {
        "namespace": "identity",
        "identifier": "invalid-datatype",
        "sid": "1009"
      },
      {
        "namespace": "identity",
        "identifier": "invalid-length",
        "sid": "1010"
      },
      {
        "namespace": "identity",
        "identifier": "invalid-value",
        "sid": "1011"
      },
      {
        "namespace": "identity",
        "identifier": "malformed-message",
        "sid": "1012"
      },
      {
        "namespace": "identity",
        "identifier": "missing-choice",
        "sid": "1013"
      },
      {
        "namespace": "identity",
        "identifier": "missing-element",
        "sid": "1014"
      },
      {
        "namespace": "identity",
        "identifier": "missing-input-parameter",
        "sid": "1015"
      },
      {
        "namespace": "identity",
        "identifier": "missing-key",
        "sid": "1016"
      },
      {
        "namespace": "identity",
        "identifier": "must-violation",
        "sid": "1017"
      },
      {
        "namespace": "identity",
        "identifier": "not-in-range",
        "sid": "1018"
      },
      {
        "namespace": "identity",
        "identifier": "operation-failed",
        "sid": "1019"
      },
      {
        "namespace": "identity",
        "identifier": "pattern-test-failed",
        "sid": "1020"
      },
      {
        "namespace": "identity",
        "identifier": "too-few-elements",
        "sid": "1021"
      },
      {
        "namespace": "identity",
        "identifier": "too-many-elements",
        "sid": "1022"
      },
      {
        "namespace": "identity",
        "identifier": "unified",
        "sid": "1029"
      },
      {
        "namespace": "identity",
        "identifier": "unknown-element",
        "sid": "1023"
      },
      {
        "namespace": "data",
        "identifier": "/ietf-coreconf:error",
        "sid": "1024"
      },
      {
        "namespace": "data",
        "identifier": "/ietf-coreconf:error/error-app-tag",
        "sid": "1025"
      },
      {
        "namespace": "data",
        "identifier": "/ietf-coreconf:error/error-data-node",
        "sid": "1026"
      },
      {
        "namespace": "data",
        "identifier": "/ietf-coreconf:error/error-message",
        "sid": "1027"
      },
      {
        "namespace": "data",
        "identifier": "/ietf-coreconf:error/error-tag",
        "sid": "1028"
      }
    ]
  }
}
]]></sourcecode>
      </figure>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>We are very grateful to <contact fullname="Bert Greevenbosch"/> who was one of the original authors
of the CORECONF specification.</t>
      <t><contact fullname="Mehmet Ersue"/> and <contact fullname="Bert Wijnen"/> explained the encoding aspects of PDUs transported
under SNMP.
<contact fullname="Koen Zandberg"/>'s implementation input motivated massively simplifying
(and fixing) the URI construction for GET/PUT/POST requests.</t>
      <t>The specification has further benefited from comments (alphabetical order) by
<contact fullname="Rodney Cummings"/>,
<contact fullname="Dee Denteneer"/>,
<contact fullname="Esko Dijk"/>,
<contact fullname="Klaus Hartke"/>,
<contact fullname="Michael van Hartskamp"/>,
<contact fullname="Tanguy Ropitault"/>,
<contact fullname="Jürgen Schönwälder"/>,
<contact fullname="Anuj Sehgal"/>,
<contact fullname="Zach Shelby"/>,
<contact fullname="Hannes Tschofenig"/>,
<contact fullname="Michael Verschoor"/>,
and
<contact fullname="Thomas Watteyne"/>.</t>
    </section>
    <section anchor="contributors" numbered="false" toc="include" removeInRFC="false">
      <name>Contributors</name>
      <contact initials="I. I." surname="Petrov" fullname="Ivaylo Petrov">
        <organization/>
        <address>
          <email>ivaylopetrov@google.com</email>
        </address>
      </contact>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+1923LbSJbgO74ih45YSV0kJVIXy6xydcmSXKUey/ZIctd0
11ZEgyQkoQ0CbACUzJY137KxMd+wT/u0/WN7bnkDQImS5a7djeX0lEUQmXny
5MmT556dTie4GqjNIBhnozScRAM1zsPzshNH5XlnlOUR/GcSd5KwjIoyGIXl
QBXlOBhlaRGlxawYqHlUBEWZR+FkoI4Oz14HZVwm0M9+tvdeHYdpeBFNorRU
R2kZ5efhKFKr++9ODvffvX29FoTDYR4BAPpJEEJHA7U3nSYxDBbDMMH1BXZ2
chhcReksGgRKTcI4GSiE7geEs5vlF/D0Ii4vZ0N+3rm+WEfA4TGDPlCty7Kc
FoP1dfm9y+9344zeXG+ad/eynCStIAhn5WWWD4KOilOY8nFX/RH+F8VJEpVl
BIPkGU45GsdllsNXxuRxPLqMEu89gHSgznJ4EIeAk7dReZ3lHwtAzqgLPyMe
I4B1p7ehTmaRGs/Um9mnaDLMZjTFUVzOB+rHPEyHcxw1ugAMDdS/zaJhNMLf
szGM+4f+H1T/j336PkvLHJrswzqMQ3gSMe4mBFr3SoP2Q6lh6sK8YZ6NE3of
wRKqz+oqTNUY/jots496UkgRs6SEHuDJ9DJL4f3WN5u9nf72xovnuxs7LTt6
Ae3w/R8+TlN80k0T+HGWxwOlFwmGgBHwxW4ZjS4XQbSXRJ/oTYAtya40MEfH
Z2qvTACY+G+zyEFsX+WI1gioQu1f/uO/l2F8kUZ5GEcGeyub29u9jRWD7f2o
KLK0cxpd4asO1l/lURnyI4Pn17A0o8jONNTwdacI3w/xpOyEBrDueQ4Tk5mk
47l6FUf5JEz1NP40m4Q/I33YGcBfHbWzuw07YnQJg8EadOnZyuksLiP1rLfj
wH4aT2L1xxDW2CWX/T072RebGzvbK+4UPpzuOfADVD/MAQwiU6ENBng/hOWJ
UvUqQ5DT+iagKXxI4ytYx7j8x3+WiDFgBersz0fOkrzPihLYwqXa3NzY2tow
sPPLBtKDTn93c/uFC+mPhKy5pbdvtl50tvq9Tr+329nZfNHv2YmMwmH2Q/n3
mHgFsi8g+OGsdDb1URf/BySeEx3xJI+uwnmS2afSW0yPp/T0h4ssu0giwk2Q
IjJKmDIu1Mnr/c2d3d2B+jRJAPf8ZGejvwFMM0wvehv8ZGtnC94ZhkXE37f7
z58PVDrqpFkZn0ur/lYPnkUlQG4fbdJr12N+sPti6wVMdEjIx+/AReD7eJzI
9+dbfdh70d/46/P+dh+3bTiV7y+2BTDzHbobJtno43WsYXu+g3BkwyLKr+TR
bm8T+gHILuX7xhb0kwPPtbC+6G9vcd8dge+oc9C1vLaIx4PaQ3o9iYd5CIst
fW/iFNIJsLI4Pa/gemdzC/A2LpOi15cnOy82bMtN+fP5Zu/5wKAIcJgVOJ5A
2jOdbGrYN2A+cG51MjwGgqDT6ahwCOQbjsogOLuMCwWH54wOuXFUjICwokKF
uFq4a+C0MmdgbM5AAJ5YJvQSp9EYGl7FIzhJYcPphkUbqBa27nipo7Srzi4j
eNN26Ryiwfs8K7NRlkAD6GtNAcyzAt4pM5gZjAtTCMsQ2G0e4Z6nbyqFjYcL
CYcPvKKKaTSKz+NoDLhXf9p7+2Mbtrg6PT666uNUYJuX3CP+1jVHOg5UqBKA
w+f4+/6rdyeAlek0Ti9oNGldBPRGPIY54kA58gh4p8BGKSA4j0fOrwUhcYo7
MRyrIv47AjuejXDC3cAMH30CLjVmCIqoVNk5A4IbbhxMBTGA7LeHZ9QAITo5
PKUvbXUNUgK1HYXTcBgnwJsQHF7Ue5ewy+QyiWEXRkHwDJcuzwRIdfMsdr7e
IjEtXEJVXcKbG9nEt7e4nEB5eD6NESnBMfBT6AAB1X+uHveP11ToCFaqmAHX
DeHfSZiXKoJz8GLelm/Ig9uEiuEsTsa4UsQ0swRQW580TJjXfhgJasZA7NBe
wZ7JcJuO1HlYXOJE4K1L6BjwgWhNwhzw+LcZHollDD3B+uhOy8uwVCARwhoC
7ZXUZ3A+K2fwCHh2CbuDp9JVx0DDMGoBAJTXUZQ2AcZTTRKcFvKPPIIzGLYT
PJ9mRREPgYvTLoon04R2Gm8e4Ozw/ROuPCIkh+Mnnrg7o3EMp1PhErKBZD0t
qyhp1e/f4ur6EsQ23k/0/iQCsXRcBHYXw7oAMQF+ZAuPo3NaJtmxQjTA6W9v
cao1oOJCZkuzz4nUqQ1ydSA0hsDlcrhTgEt/jCxzC4RtOZvIAv7T2ZkBXC0E
PKgA3uW9AT0gfcDKp+MwH8OWl3lOgFUlDosi4vPfA6HrYgbobRPdB7A+zMOA
A0wyUBEYfjjUc73Nq6SEi+9toHNoGozj8/MoxzUDwp/B/HEWOe58w4JcjkL0
jEOBVEhEQ2eEBreMEsTGKImhww6dsrneOF1EwZxwAO/CjkyABkEWGneAS06x
K1660vkdhTHcu7Bd0yIkNoOrAfAGmt0h8RZqArJ7PNU9KuwRp3CWafwIWU9k
n7Ur/D1s5O7BzU3HnPpAPsQaGxj5zU1NHri9RbKexCmIsMDZqVfh9bwSH06O
VBKlF+UlwPnsmToDaTBOsyS7mANjLe034avnWZJk14QM+K2gdXCozBxQlp7w
XU017s5BaYAxCdInvk5/gJDXloVrE69EBpm3nf7a9lhty/SRyRInA63BwUgb
Zhae839hcxXQI/8X+pkl0Prk/T7QMehwE90f0woS95Bf6i41bZoWSpc4LRTY
4otZLgyKZmbkgjbTJz1o7JtPIafnhjUdMI4FclBYJu5xv0o/nh4dgGRxjrpF
AVo3/MsbpUC2PMef15abm+Gr+pB3z0y0KcBsQYQEDq2PjzY+LHHrvSbhsq0O
0/E0g+267IiOMDgIgroYNQiAehgq/YiPOeFgoUOE2LDLnbBk9ohOqCF0El0h
h2I7zZ39kFg4nAslE4sWcZ87JaVEc8Auajylc3wIKWPHe/Yr8uzQJVd8UM6n
kddbu8q+aTwmZhDFzaHM8LE4hzQvZ7bZRYW6QFkmLC0VCCMFDOG3bDSa5cCx
SVFHSFC6y+BJMc1SEnUYW3TYR9MslyFBmmlEI2ABd2fTRkZE/ETCjpG35cd5
bal5CWPkbhXM0XstHKPVRs3ZoMkIp1dhMmPZCb99hGMCWMeVfYJtAcxAjoUH
Q6qlBAdaPtNHAOxQd1jGhPQsTVApz2AAETLidJTMQGqwzS2rkEXJs6x0ZsvL
TpKaamqFMyciMZxWhoo+LRwKejLNaMFAfQDGrUBATsZAD4KsInLaAtI0sjo+
st4sWHLsdTGa3f5o0bCrM72CIDWKFI+SkYNs3aYLgqHbmjkQkHccJiTlAKvK
YJ6IUa0ZgYSV5UTW0CmhGjBbYdWnEWskW4gD98hG49IRIoyeaTAEu8i/29xl
RDIQTBXYMwlJczsgbl4PaiRy4MlX8djuZWwnu9Xfiw3oR0o+EzoH8QkEgtbx
h9OzVpv/VW/f0d8nh//24ejk8AD/Pv1p780b80cgb5z+9O7DmwP7l225/+74
+PDtATeGp8p7FLSO9/7UYv2o9e792dG7t3tvWrUTgBaH9QISLqd5hPsjLAIt
QRP6X+2//1//rbcFy/AvcDz1e70XICrxl93e8y0Su6OUR8O9JV8BVfMAUB2F
OfFLkM5AR41BKwLpDPWQy+w6VSjrAb5+9wti5teB+m44mva2vpcHOGHvocaZ
95BwVn9Sa8xIbHjUMIzBpve8gmkf3r0/ed813p2H3/0+QV2309v9/fcBSYWH
n0I8N1QxBzbxCQTDiB90+AHIhiRZOvYQoGLccUa8JS2x0KcBkmVh9lYhVhfs
gjsMhOESEzPyalxRTXyxuM22CJWJOIaGPBB/cUB4sYj+htvwzNnRMgfa/HgA
66PuIA4v0qxAZZue4o5ebdznu7jPzVDEZm9u9oCWYM99Uj/qX3d6IO6uif4W
CK83Gj1Q3Ny3/CAicHMGzyz+9nLgr2VEahHgn9xJofPsVmvHAlpFLzY6lNsN
DIVqEEkuaASC43gsxqQATg44s4j7EC8heY6sClocWi3WeLWxKb7kWOhk+ZDp
5DOWNgKRw4L/gI8Kw+LqIvim84Wfb4LPqvJhS5qvj69mU/w3TNbUan/Nf//z
fVDcD+Q3QRUIVR3jnheuvgoq6MOagocOtdpba3rVQcWDwHFedlDRDM5iDO2T
qAy4uPvNUxZCFyHumwXNFk/IIO5EWBS8+r0W5+nJ6uaagmef8QwfGyR60EsX
ogypz991OkYjIF4HfXxH0J1o5qc/q1trbhemz0WYWoiZehffvYQPYAwEdbTE
rD5fU/AAJtKMjW/qm2EROj/D/x24nAAnsr2Gz++jddvFYiiW7mLhL/9UKD6r
Q0ejQXSs7vyzcXEXgSPLDW4G6hmzf0WxBS9X9sT90nw8rMA3Mr93QCi+SF+2
kui8bME5Awcgv8cm81BdxheXnQSUugQVPaB4bfPV58AEVAsVsd5plCkzqD03
And8FgqsXTCdTYYRWjbRPpeluisHGDIjxMVoVuCxVBPYTTvpCg8j5IR1Dona
hGhEOD/xd6Avc0wCDPliMxQHWMEqqCs4WRoOH+zrnRw/IHrkJSuo6PIA1adg
ZY27Fm2NxASrxjsQXIWgoQwTMaK2RqgbTssZdFzS4xbhjJxwrACHyUUGW/9y
QjhA6yXGcTSBWWiXU+UxzQz4n8sP140Ap+2YWv0ya8p2D4AbfUZa9tNvk1pG
cuAoilG9rvUHE0CrsE8nYqdAgIBlCrduOzy5bZhrW3NiBOx9nqFxHMaZRjm6
O626VIGX8crj8MyBpRk2R+aYionHmt6brH7W1Ee2xqLNmjjbPUHq3atOThWz
KVpKCmt7nqUs7zpmKHWszczmIXSNYphRlUOU+7LCmtVgwhImE7gOEjM5X8Bc
fXt8sCfOMfQWo3SNuyubER0Wo2wKREYbuer8ALQh83MZ4gLEXQBRw89Jh/xA
vkWsATWTcK7RY+3s7jAFvYkb3jKN6SyfZrj02ktHoQUJbLUU4yvg5Ta8reV9
WLF5kWQXaAeWM9O+SPQAJ6g+TjXNC3ikBwLzI4BmKcc6kTEB5puzl8NI2LBU
1zn7FNB0YuK2lHWHdV3dKSGXXmrBMg5XM7GDszenYofe3Hp+ews6D/vfgTHC
cO9OsTtZ0R16isZg7E80AGCPEyA2Z9+D4ncc/hUaa3yOHM+g9cTAljGg3jyb
YIuO0+LWceHE2td1PkusPRkpl/0i2kdEvhVVhLSaw3lJPCMgBkbrH2pOgT0C
9udo14QfMPKKjM+5eN2s8wxjXMS9G4yBXgtiekjUE6C8q9AaRAMZF8ibhqYe
C/ZyJnPHZRMjOZUyI3qSISV4xvJ2MIQ9w+goYCicFoBApI7dMV3oDsgH8ww0
UIvv8YwUNeoUUR0Dc4jOoTkx2BkhoQHrHQxJAdT/ruJhwn7WPxy8Jw5h8GmW
ghYT9XB0vIqezBEiQJu+vt210zYuyfWzfb9njCpy+/7D6bu3SI7/fvymPgQS
XRVeEh/Ez/n68Gz/J0bC+z3804+70KZGVQEMmSLsO+rK8Zsq7gO7q/7y4+GZ
NQq3gP0m46KF8YFAVHCEw2Fd0kH0u8pIlX4AJ4d7B2xxYjPLqXbiIt0h7QhD
Y9rDtfFRMM6iwn1PtWAyUV621N98YNQqnHbk4Arxv8PonHxN4Tn8tgYY0bNs
kRum3txC5UHk0OVdUFHPcPLkJfHyFosncK5M5XtlODzfYe3yqMxjYJjwA0gH
VZfIgo1QWgc2EWoj7SOBeiCzOYqd1U2hMXgykFBYiGPXrqyerY+DMCkys63F
4krxGMI54NwN4ZASl0KbLY4r7AcBgTpZIRytwPCTFcXmicLHP/tj90FohTOh
EGm6An+BwS9jDLLVL8G0jxw3rHc0t8nUzMOYPsT9wTKo4APt47BLx1EekMfQ
5VcUHBSxPwhdygCUCw8d7oAPjai29lQH3msS28CeSvZoHZEb86DuxmRXgPFa
EvgyDG1soZWjuoWb0FN/TDhqeNl0jIaxFENLYUjjvqm7EQrrCLHSGftPODZq
FidlB4kDnXRVv642Ir7o9jbFUqhDShynnwMg9kA6DFk5WYlygHIcwHE36sLm
F3SlYxYOHVeOwI3uG9BW29rdZc23cTqOPunX2JsjL3eJwOzyNgDKmByFeR5b
56Fm9QA48XEyzDILFv2gkNAMClWi/cqUBLs8MKbdezwvO4DMbq/ufmFhJgJR
r3MGi4GEMaFvuDSuhEJ83H3RG7kx9s6L6KuckVV/dxpdN/fOxm8SMpCwtMX6
Pte4E0izzr4luwrfIAzYDbw3YLK0Q1tNHUUyGp39qNrpIvoviaji5ztvXmxN
MyXGoJVNTs47NwwC9/rdyfHe2cDHwqIBAxG8tQjoUJYzv5WlULOCm0oT26zg
2XpQoDxxiIHVFGahVR4fUGsraN64eoDwoVRbn4PG5FdY3Ib1MpOv/4aIcw4R
EBZQMg2LIhvF4klp8jjesdZ6UxULFt7hNXSqPpoOajh8KBUYvngHJZjpECOc
s6rXSB0UENeAN5oke44XsFgf5LtZI/TTTGZVtN7ZNYYRLO3xPrvPpX2/Qxt6
cVzai0jq50tQSIXiJWA29o4WTRttXjOHPGhx7t4E4nuGPZWEowj6GIEaX+If
eKhGGCo4xum+hq/Rgs1ywEcwi9kLpoLTJ7EKBbGwaIxcUEdtjQxmt65lyEYk
2WgWnNOBhr3wnx91FaOu8jbqtbMkaVclDAMDvpFHE9B2x24Xd0BkdQbZIc2z
M0oX4aBxsxSIy5AOUpcVyZos0wMacCVMBCa7OkspWLQZB2s6SMKalBzimbE5
k8X2ySTMJXhEsIEhccMITn7g0Z+hHemW1uR/onHDX51+73AUQEesBmvKhpYW
3dTRUgef15NYX5foqcY6BabKdvuCnlD3zq2P7LMfLPaQnt6/Oz2zaIKm+XTU
FuPrw2CSnjRQj+7pBlPZrC9F/DCtU6KdeeXg+kDEhQ4XEF0/VK3AIMCKZbhj
nrlyrGdInni2Yo5v1B4I0VfvsDezdGGbC4sutO0F2WMGu863gFOYDYaBi+uD
Al7ZLG/emU3HmFbq2OUzLeLaPBriIueJZC5MSGwvUTNDfsqqK8U34xhREs5x
W9cGDoJj7ExyEKq4sFZU3LhiJ280kwdNZnJHrINTyzGa12zmorYF+qyqWs73
L0N0yIG+jOZo4yqrrcmSLOct8kCH4/yR+NtDPp8betHQPKwXJx6xoD2DYfD6
68N6YR1W6V4cvXa1xUSoynymzVDy5DxMiqi1Rr3sMeGaGaFZvoMG+aWRg738
lF3zzidcfFajS9j6uC3kGSwKnbpLES3zGWPVZ7jMbn7QB3s6sEIa9dQyEeSI
jtbSPS3gWAvoVHMps12Ie7Ht2qbiYPRSOO2YRJfbavqf6/lsSubpco+RBJVz
hlNgIpsXeZetTV5zxyAsMcIXJb+UXcdowKdN5DQzMgzM0gaKI4tezcs1zpTv
jrrjQoeXwfJq88x9XcK0EbFkcjGR2Tl5O4oIeZ5aLSJMm9A9zW9vUSapxDxb
WRUZA/PlmHjBXDNX5PNVA3pg+GShLRx10c1LwUGrpzlaGsO4rT1AB7w3xrYD
sg6bm0t8nJ6w0UHuQH10JYYWjnqburEHTYRgE0hjHeC5gIP6Uf3V7WHiImnN
kZGUlW1YF4Td5usjvztDSXYXkxG5EdHYvmhsH13pvfusHCYdi9qmrayl0KKt
AyJpNuyr9pFeENZbkglEcxaN0cMepxpyV7Cviq56l5rlnLfdVIJJ+BF0SnyA
CV8UIGE7/Zjiwkh0YeFkCspiayeLzrVwolgiWrx3mroxWMmhjKf5WAGakX+i
vRl1A1iT3cthK/miBbaCNY1wNI4m06wkN6QoPG2t2vFysTZqB8ZQpLuGNsKt
zOEovco+Yr4AhitQYP/oCzGmRXo9gsFSM7NZjIw7R3j/wY6wT4hRFM/K52/j
1B84h4PDN4dnhzzCQSTpgV/WrTeC3qyaqBtPXcpulRccHwvuSFQSkNtoBMNe
unmG8HVy/QDeepcSYsgN7VCnsFztjzPhMRwVw8eaOSqQZ6LpW4y+8BPvAvGd
NpqH+joUurfZ11ZxkWJB1lbhGBMsSVqvegpNdLE7CO3u2ptfY5Pz4o9qDznI
IEsUn9Jy3tQ1oDRLO/XIIC2t4sbAt2huLJrWxGo7lFnIun+x+/BZaYIjNHbO
sfKEqgT6oVftg7H/rYxWam5jFOUoMlzOBHxnVR6tiVtTZ7wXCg5aOqFBcMOy
PYwE0YhET4/GPtcE8X5IGidFcBlFB3f2XI6BEH0r0VhZ4yWRB+s6Pk1QhOyI
sYobZZan7JitLJGF0QGGGqcNjRvWuLED7iH0e+ColwWv6zUaGctsA1f4I/+k
90nDMrW0hC0Lgn8h4Bpz2NQjRXO0Cr2aihYNqZhIe3tqq7vRV6uvwrHEOq6p
KM+znA2FOFFcu3ObL5ABqHlghskrggY6GcXTUiU5CboRDVpslO5mwDdaYUut
4i9/m2FSekBS8Xgsg6O6J9npbYXhOaV2O1LPGKMpwqOYjdfYgejthnHTbhjT
I70Z4JVVPH07Al/RvCVqMzCbYsFmUcttlofvj6/3QdIP+S+15+vsbOCRmAej
uIaFHy3hHSfixZDyPegxbx6xlBEP7GgYSSvHFutQgni9+s2QcJhGBYZ+Awx2
z44fsmfrxIR79ujcMauzkQ63KTTyTtzYdxVQeLHnAMT894AeX7JbwSW2tokN
wtfoDcTDEGP8LmIQxaAB7yvK3Z0HEto7j0pPlKf4R97rDXtSJ9DCEN2FE1ty
PoFJVkVUkOPGTI6SUB1lkmwtlVicQCZcYMQO66dN08UJBsH3tRhPTK5z5umP
iEzuL+O/vPxL+ZduU+P7G4Z/+WLmV3rMj9LbvpD5Ie9jmrt5RqKCsLgqHWrV
30R2ZY7AWXEzdp0eKm4660YtJet6YfBBPQ7GmEIMlxRGKLivZh+6PtvFXsCO
r+mSd4kipJA/OCPtsd8XfUfe4Xdedw5aLu6J2+16YKCzzaAb8qJR6j3qgW7O
OEz0NVXEmkxBcQPVu2hzJI+fwt6UUe2AKgNWnEOSggoHTJSgg1ZC2kqddGxd
t7iwWEUhClMpPmQnxzihLsk+xRQ5iTD0Th+t54C7pnRxQj4GGWhqgcN4hGRL
GcyyPvoU5HUKNPhdFoBAbckzXAUMJidj1mWUTHVMm1+wSDkFi3gkAo4iVRGb
tJoR1tBz4qTqUQ0NqDSREyPM3Mgq/Za13G3XJdblBMpAoijQ7Uydf1fXRb83
qUOrfj2OwXIuQowbXTIgR6l+d2Nbl/1YZryag6xxNC8khCqaVEJACBfEnzSD
Mlm9wqk68kDLwNoyZQJ2ZSuhGy2iTAQ6ByksWxJyyHZezAsM/eDaJ5u955Ja
zL58bU6k3VVran4vjHMIBQYO1HRA8lzQNbBWcZv1nvc311RtYK6cwW9sb8Ib
9R0urnGM8nzZAoa90SKmjydMTJyDcXly+G8DTVLrIyGhx9IPQtt2hbL1O6e1
HvyC0LcVw/crNbDIdaZnpqJeysvQGGA/HXiEuDT0DdQY3EBrhEsNVKu/0dvq
9DY6/Z2zXn/Q2xls9v7cunc2t23uBECGTm4Ymi3sj0D2MINTpQnpWT7HHuiH
HrY4RIUpBWkJTu8pbHNsve7Zu3XDLdNwGxr2dnc3KgNhQ7ahS4vdNVtISbdd
+FlXkYCyX0zC0Vh6gWHMuH0YFx1wDeNGKZqIx2bobd2oh7PcrLyNNqcOJlHN
Ct1iawuANaIO1iRGDol93Aa3geUHLPMfSuEuMYVJHa9bz6MB2pHrbxbrhY76
MbE+lBAfSwKgRP2wZyJwq8jpwHUc/R3KBzw8ftdfYfh6dpNOH2KXCSt5CdXl
FDEDpWQ42jCZqENPsBgb7HriQqbCFR1IsVv0T5LsdC03W9BMH6Mgs5AHvlZO
gUXkanUd8gO4EWIhx8CBjp2HcxA44FA1iX50GruzinOejqCJbM83z6ZZUXaM
gdFUcASs0gue6bEaYK6VKJAYrrKRSTtt7e1jwoX4gE/e77dc/8EJRqVxVb58
Orq95fjoCMTAhIwed7dm2MUyf/MsnoZ4zrjwazurm6fX5KnTMWU2bCk2Nn4m
KxlFRGw+PupGVJCBFhpOvR5EFBYbgcR+OG9hEhj5B91SGyAQOnEpS3BPOto4
PAErs51byYhQ1SR5NwSD6UJOjsYTeLFvEs3nhoGRntNVvoLpaRNuBRFu1w5Y
5DIlLmq91pfJ02plOij8k9wv7InzUkXKoHA5Nt1iAaxPEnnTUJsoqEl4sjZ3
inhfSeZaKgyXpL8ttU/xD2Phwc+cPaIFHLNXrExWkYEwtK+aRKzTA0RO1qH0
1nc9QBB+p05hqVvrjrA24H/W03K6LgdPS5/Q23DyUE40hthS8xMKaHR1rVYZ
jrppPuqOwpbNR144BLeyI+ys6YJh2P3eeLxOxien/7dnwOEy8iLQg35LqwPE
yx8wUtcV3zS9PER+a6ANFoC2t+U0b5YFvPOcsGrknl8QsraHxV+hL9oi2FYm
7aDLikzwFUWmRSJIU1P8hYQ10Kv0eG2vlSNfPd9+odtsLZJWqM2UAph1qx0j
5GwvBg9azcZT06Rn5CKW5IB7d/tbO91er9vf7LV0E+BcmMJlmvV1s1st22jx
trrTgO3UzfKcbuRIKU5QtE74MryKC12hCSz2tyNXIQLVaiY2W/EEcPwUS1X0
qMOPbn3PPCiubfTNtukcZ0ujOFLF5WgNRpLNb9zZ4t8OHLd2qK4vs6TiNsaS
xiDfkDuoyjhRcW7kmg9XWLEX2hvfwhH9sojHhndiiP+d2mkFKPRV38HKvxIo
zUy6ChpKW3cdM18VuJ647hcAJ4Rzx3r2xTOvOzirHuuRhcQxKPPpLzV/be/S
gllNIFYspKjYFgHC0xxTbFGyntEOkMR2R7oKacVBGHPjkbUQWdlYjvHCbi3X
gBHV7RePsz6QN4/tctnoo63/uIzhoxv8TDUWZ5PI2vd8DYrFrevMhHi6XQmL
29hY4xriFShF04Ofv2XjtE4ZIFeJeXFFVY0eyNcCtDjbMhhiKFmhWa4409SK
em+tq/ZoCX39gVhXGBh6YUeC9SNpcaCI/GlaO+rAM6kwL8IT+fFmioa9JUaK
3l2H5T6tsJ2wnCt9tmvs1Owa7fvtNHSYOXaRje2zjReDjQ34359bNOgwyxoa
y6F227ZmkV+os0VHKc+g0QZkDBUPt6h8gU3lcVaVwb1mlaUMK48zrTyFcYXF
kF9BDLEWFi9+8+YZhW11+CvwKv7Vj/2kBEn0TaO/IlHns5R9qc0VBE0dnqqx
xqsU4JeEtOX58f4XLnIytP5lLghLZhM0sXLRHy40RZGHGpBxU+BlPTC1WoL0
5qYS2Xzb9TyAe38yJROckCcaJKjFwZaZkQmdIlguPqnmPJwkJxGWgRLG1Rxt
ywmOTCBGiSUDwzu5hYb5+w6WMDcL05WifJgfMeR5agXFX4PhnEo9kZgZsLuC
XTQsaqaqJcO0dASEdFOvAU1ZlnUfHSWTF8afqA0rlapBiGyu4wCoCHwYNQ1Y
h/cI/Sv8o5VDSQn0WgZG9TNkRCcPGl6agrfheMSMuGYYvXAHrj7Ltr+hGPqg
d6qkgbikmxEI29F1VCmRgRWfOUv/71GeddVbvF1ATmMqFDBLyC6I06pgYhhR
2jrSkwES2XShq5PEKUrfWsAAcWaoL3PAa1Ecbx5hjOyL+OaEHcoxdBtfXJaK
7VgxFTgVSJwaYBizH30a0aUf0OPx2QcvD4mr6ISjj1FJ9hzK0BkRUDy3MI+x
0JeL+aC4pJ8wrBga5BE7/KY5ekcBm+GF9e4hM7oK44RCljvsn3X8MEBo1b1N
lzg5Of3aYecjNza5v9qooiuKRCZ/OE4DFi3F6hI79b78NS5UBQiTcNvtd3tB
Lel2dU9XvcNKRaHfG25GzEaiat0iFwtPnkxhccmMa6HmKhJIXVIHaa1ZweI9
bMLMv9csZXVj7Z/kGVzGSmVVArebJsMs+oa1yGn9tFw6hfcHho0EHDJiauSH
pcOmaTcBoeylhqgqzuUYrVbf4xmKhapQRjJ18d3S+xziYUdp5O5438z3iElz
GwrHl2QFXv6ga1JqORfLAl5c5NEFdwJSQJyN9c7HuQ8j6C2JJ7ETfTAJP8WT
2cQy1+ohrMMV2tC2Zk71qwYUwjmo1LacL5wroiMAjK+FgdcBKHFSsj/lrcee
MVqG4xnpmJKIInQ8yM1B9R1KNAOdkckhlIIk1s0gJ71NSxSLSTVMJeP7F5ar
wiH2bGMVZoQzxAu9+nftLS3K/b/h3V9+D9Ppem6IIS7qATNh1b+m6+vT+gVW
quBrFy5S0FvHAyKaqCa38pld4qj64A7w5KXtRjE42g9AFgVROysboEI6Wv8n
Sp7rPKKiIkY7qv+bSKZYeCZqzRn4pNZV2Sls0pVg3QxVzG0SeuN7CkXZdxuT
s5qWUkqdql63923A9zkWU9TEzEWw2lQ4yibrabHudtP6luq/wcifsPIYPcBO
XCbWADMqg+vrFFa0s7FBFzwqVy0Tym+xiuFcU4Liw2WYj69xwbgvMoOWlDxM
0CgO76DRSDts0DydsXsyFml2XBzrW6MOuX1ZyBf21b+rr1ujWjVFhTTqI8bU
S6rLeqHPcm4XJNqa4SgsFT5WAJNPQnGEmgwtoLpOVKDu8moOvUWjWWkFe+pB
mJDaMFmDd8LnCIym5Ct6bK0vR8v7gwaTSeELFGQ9aTCfPJot4UcP0OtL4AfR
Xc2ost5ErauGTo1lBI0LG+tb6/2eMUmsOyRnWlhbDLZ4N8UqJiB09FtOi8og
2oKiPSVfDmjv8YBuLwVo4BJ2ZD19Lltko1lh7ahWBbRXR0pkhr4cAksdkvHN
cgCiP12wE+kWHQMuv6SABJB9ZkD2yZz1Ijf4ki4FkfIidWkMJTqj+uBpfh1K
pAgfR5VjA48XvmeOT3Ph/T6R61irouFsf+zJHtAqt3Ed+htq3T94GZ+ANl+W
tB2t//9N9n/vJnPNADXBt3Ky2DqQNhA1mKVMy9HYvlfYIHGOQSK5y5bUMXMW
0wroI/a6KpO0xf1KLT7ML8WX91idpUrZXB7+5hmG5LCqxld2cRKqG4zjvM7m
v7mwFtr04pghj34ZBVT/e0x1jhH6VehhzcRxy91n6oh2ekz5r7YGGLlsJPam
zAI0ZO0JMFleCQxyIzjO6hKfH4Wic0Oci6pYTZrOSsdLQdzIGDi70u+i+HWn
Y2GRoO3f3eGrTMcd0chUtKXSpmgqyHhHybGgYqRoKGtno/FRx6syfLo4CBbD
9Vc2OHfvdVb+nxAT81vrSqRk4F47NCE4sLsWxUTHhXuHks102pFV1NeRUzn4
4TCPrrhkHXrxwlRfoUQHDLAEqqrLMl6hnWGNGkcGs/pyhQN68fQN/o4l1acj
IA50SN3lZtKCem9jo6ZwwE7n9sZE0BVlgrfNXd4rr+cXQpukN3Dhl0VuO9uo
ZwiaNIdZnJab/W/Nw1mKORGtAiu7jIuW/UEL5Rvuo6oShZ/WW2PVkV7oRt0w
LqWQNEwzxgwT2fKuKytfgBitIfm6jU9txGyZba1wPytEq3K+4Uqs+YHpsulN
YNOjY7u5d2QjN+aQfv5cYDXSjw2XeKrRMObGYOO7f+l00JWeZteolktZhLjQ
hQApC2RUinVW0pfO6bpFwpO25zLH7hKQ9vy/xsP6OpwXnOVG1f6x0mT1DsLV
jK705Do4IXVSFS3XbDAp0XsRjyOWesWTkpO9H2ACIDqd75ntyNFuOQ+f4wvi
GeKmUrtSfqKFhpWytbB+6vNub7vrF1GmuCHLk8jqYTnTXfYPFglA0sony3Al
WJOBNB04TT1WVMiTQMk9BRwOQT1zQDVToX4ff6AO8LYddjaJ/rKQ01g7g7Av
zIlCMB2jxyJ7R62He6wesiq0KAv6czrTZo97WaXTZtewGAKcRuqEDa2dNpsO
WyLAEYsDDEHohHi7d6xxwR8Mcw5BcJiTP93+chv4/4o4tBhuB4QXTWADvcbF
ZTR24XfabH0NsJfnugDhiqnysmrWbK2ttWwhPL9EJ1ESSCesNrQmc4lI/Vrc
+hcCqu2M9KvPuzmSZaPf2dg9620NehuDjV3K0DGkY+a2aXWmhYz+q8Hab4S1
13NgdenFAL21tu4tKZYiILnwFTolO9cxfDvDSzfOueo9+yqdRApzC4ep3oi3
ymi3LprMR1hvKYnGF1qwx1tCULy+yMMJcMyfsuuILOmkQyQYWg/6aTRibYMd
aRGrMhgmoG8AQR+W6QXv/Am0H5a9WzOp3YqjYklKaEg13XStdxMPoa+1lSRZ
HZeXjtmVIyX2VA4bFp3wFAtAaNAhB/ruebqqkyNJKEnA3FUiFF/CmZEY7Qqd
gOk4BpwhtVOHNGFTyjegaxD0rZ4YSWT1uVk6jnKpeGwuW8H3TcXJgVp18cyd
/cfO1r/Gr9rq6P3VjnaM9/oYcnR0eHiodjf6eOBtuX6onY3O7gb7ade6VKo6
4MmTVqvhT9x1lluYZiFAVkaRSxBdMiTEI8eUQIQGujBWOYyLCSiRSSzBk7T2
8BqcXdDnNCs4qKId0ByN20tQSG/znSribgRB3nrnMX2DElvkBpOiiCbDZI6L
Y4IVZBW4NSnacc6zkdBLP55TRoNJvYrINYCF/MKRGwBCN15gdIHumzwIMV1S
gTEnmExFbto2hqJEigMNAiT08COVPxY0cYSyOICwvmqkq7pUrsbTjtA4rc1L
7hqiwIlAC3lE5PlsynE571zzRVtr/Rx2wXUo2yQ36Gd815ZOHGsH0aeSncWU
f43Zz4B2Xci5iPQVZSA6oldZjWcmO1vfkq0jJd3kGadACe/atr/DIqp3gJVQ
1DiTatA60ZmjN0O5M+1SrmDiO+YrN9B/S1U0s7zQiXJiSXDKl8epRX+XkuK1
jKYoTw0O6PQCIzptWWoPEOpYatJZnzfFAHSDo1KTXji+iguKIJG7dI9SElDh
xY6MwLcpUW4ckQXq8O3A3reDZE6h9+aKDnaf4PT17WXdYNW36xGPwxdnXIgW
YKvK7DSYf04FzbEpBEmCdSFwTpd04b3jGQpT8nb6szLJfzgxDAyBE2nPHpDq
QDuTMJLZlK6E8wirfTnvmd8sZ6lcg+NW9mtbzSCJh3jHFxck4oLG1TK8R52D
ril7ysK2tHLCn+lWNFul3IJNN6ntvNigRG23NCeFh1xm5Ih1Ar90aBotDwZy
4hesi8z3+HhAW9umPFHONO4B3FZfdu/dbCh86ZR91HFOfCh6A7vGw0CXv5Bo
5rY6h4N5RrcLchoG2nv8eI/aTYr6lsbXHDRHxw/HSsV4A1HtxsUR3YpA6ZiX
Ub0AhzOUn28vMivjjGWOyo2MGJEmxatFxaOKD3rGQXU8vkjRCSgjf08tAsvQ
BVNj4gSNV6lTSwXnGQgCgKnABEkqN0iyzILWevc6SpIO1bxcx3Vvif2cX68U
Pz05W3Mv7/KyEoOWlAGdJ62u+jBF6zqbWNsOuzSyA3nE3Aj7PMtsgdqgaVaM
zdrdNtZdgJkBTukPusOpoR+08W5u99TqXz5e/YUTKQJiLDTn2mXvlYuubnUd
hNBLqqO8iPURxebWyzOiq9zLlWMfcxX5v8/LlwaLTSH7d6sHSZx+7DDRrwWg
/6x/vPr+W+jSWRmTJWmvATA8k6iuQKGIU4BtaoS+npQuSeSTvXoPm8dobOA8
tSxNcRSOfeLtopmeG3uss8cN62gHfgBbQdHMlg9qECwHlSAs00PgVgjGFW6i
+YZS6poJm7x6XtImtJ1Vg3DczblKYRJltmbr8HBPzoZfwM2Ceui3G/Fc2cyN
E3M2c/CAzaxapiYwKtf37ubGwkn1fVDoQGv3J12mr1Dns5xOMFTweQNad08L
r0J8gwTOlA+icQncEQQSXWNHf2cR15Rbo/tfKv4uZxEkU0KCp8OGmvexx5ul
+FXzeL2N/gvkAFUO4hZB7xTxGOnqtS5HaLOvvAMBVU0WNO+6GGDx/blyqZtY
HMNheh4QfyARvJCyey/VKmO29bKF5lW15th87OfbJbEYYBf+56Xq/e7g6Mej
M+0ZWpJ519hqAzkFD2er4+LL2er33yqHqaLvY1y8xKW3F557QU1ILM1XmpuS
HRQK3MRajs7rxPcQVkM9B/ezGnOJ+f185qsIDeP04XymSpOVSYvYFucGR13f
9M/GeazDLvYE9wy5C9G2HCko8E6Rx5WGxHlKdYrWKRFw3ctOW3HS0wjYe5tX
k+NW3Oy40GGmXW+ej9pbWmR50OZKn0BmCXc8mQUIo83Pn1ef67hcnV5gU5tM
lG57kXTvWIBAs7mMhzEHbQVJRveQ6moc4hFDC01VEJHKdCazSl2Hc75/gC+a
ShJiuFrsMNYWZzcVatVPAMmz2cUly2CIE6S1aXgRpzSkrojoJcB9qTzihU4u
xyeCp5FHGvhEcK88En2BPNJ8b8Ty+oS3bQp9bU9TDKoRtR52OEVffjgV3iYB
bC04k6KFZ1IABEY1lH/S1wrfPKOiyh19zzCXT6E9YWN6KQNZSj6xbWdEblC/
jjZmRaFlut1IW26pUowoJjBMBUJWqf2H3MTe7UaKy1b30ye0gmzjv154D1Zg
MkVdqLxrQcHaDcPZoqvkxsbfz8/RK55xEpV7kSjhy69kWcsE0Dr5MM8+UsEL
FKKuM4VJGRcZJhkiTlCrce5k9FMmjS8lLosoORc1FJvYSFTHYgobJx7XbQSO
ycf1eyxO+dr1bwmubhe9u7CEE14oS1fkMEIkLW5Y03UquClkbblIKBtGo0+X
4axAptzWYjJ36uhp5nJ6B2UAqLHQyz4ZktHgd0LWW1jxYfVDGs4Ad3SN1ZpX
MXUB37vWtw1WywQJvLY78gdwCo8ba4xWS6nYX7m20PBBuUDZHFNtS2Vt7+63
ym0Va/70KhXRl52cWzOXMOteDz5L+VoUfCFMOD3JH3VLobFYvUab0xdjVHDG
5wQWunfLzT45wrbVqtySiDPY48LlTzsHCeb0M4YWEUJXrUbdC5gYld0m5kST
cQt6ZP5VlsQp5M6xllZH6e6xylx34aAVln3IlRePUu21WmrK8XktG9p6J0Nx
fZbiE3aPh0lMtUlYr3WdoufmahCuhOcB3NusAXyWZeoN4mzNuuLuhlm44iLo
HgrSNvIPu4z+8fxAuvHamiqDDt+wvqIJFbFjjl+xMDiXit/qq0MbT1cyRUdo
GZcEGZs86p8G9TOocnr4Fmu08NMh6/SRR0seKdJYGLybqe4YgOzBwpG6QMsb
zOiEPNbEzzWXwDNfqJOGOiAZjjudEmedE+JtiuUSFQcJXTRsgFYR+dbJJvMO
+k3Y0bPA8kPjVeGpXQSN4BujNMc60/6yqwDa4TRBp+Wi8LTthhBokga/6XTy
awbhX9De43zvlOGFZ7/Rpp08Oq++Cscrvv77JV6lMqjIqOTlhkjiahPJ2De9
czyYk09tF3fFgL5CeF/x4FvxLrOXDektjHtJpK4/Cg3FpeuILoBpetVUrSWH
Owt2xrWNNxlE0VjOR4vVFROs2jkH+onGKw/iFDZNWDOGJgHbloOiymRYAdBD
hloxx7fG8MPA0BqWEfZNlYrqEdhw9TKpPpLbTP5gna1aJWGsF/ViCzkxeqdt
R7AWc0cqJpey8UbrHtxr0vXljs24ELIsO7M0Bpw+DBN1+XpFd2PZIG9alpFz
p17uuZwqDUCVWdaZhCmoaUx3xReDNQk/OZ19MXDn0fUTwhanTwXbBPSFzlWc
JTTCwyBDt1QeS/QJBssWWo+jblds6g8xBR6FtngTWc1YP38AQYUmv4/LKGdS
iBCFPN1bAzYivAegymfilPDMCRkPQ0N1Dxto+MpkHNzARbGmktnLRhr/BCMH
O0HCGxU3G1l6slzX5l3JMWRopa1WOL4D/5qGZRnlsHzw2orEWJlYEodCtOIF
rI4DpprXQiNDj748PghocwQbJsTHDhMNHcsobEs/dDi8msXJuINZpzLZa/+u
e05Rw7sySqoSQSiMSy3za2ReEJ4xPAEQ2es/1xH4sDd22xThx9wuSoHB5cZA
2IACZHCwyxjXX7pfpRc25GBlnsX7UaNe1vZLR9bdLDO0EFEHa4k96rRtGN8Q
Zg0Ab/eJmqOZ2hce8jVrkmxMGprYROVMXDGR2h43FWph4XPBOySDkmbA98bg
Bmff/+gyi+mq1lmaSIgLq51EknOOUcNX4aUSZXi2makVnNiKjXekPR2fdyS+
ZwWEJh1XwQY5vGZwxnUlMrVC+uvKAmYvaP4YzZdCMarDnnt5Tndhe2vFY3iG
Rrfn+7nkyNwB6t1307YlkJKEV4nAtkpctgwPNuVoifPiCCxthtzd3XiiNIiO
sa8/jCw5h8Ip8s7lxP3LWnX8I9sSqttCDEiP2xYLUSIhV64lxGpJEn3l2Vza
/Lt9varpwrQWUagmzrFDnBR6lzWRetPbVaQMw/ETI0Qo0K0Yqk0ZdJCg6Ya9
WSRz0L6uQkVSsdDNQyQY/4opHRqNSzQtPYuGX1x/0eEhGqLu6yGQ0AaRKklO
V1bZZOkCXwNldUVNwvyjJoCqyKGNaSuY+LKiqC43055TCYuYlxERqMz+3duR
Mb/8nNJMlpP65tWzOTnN60h/PgBtKbB3y5KY/+HldjoaWq758gppVHvi4DDn
urmKCcY6xDAFhmw4jgknWDIFZlFF2o3+lrnxBv/qbfR6pmTpuoMb9ptv9HfX
FlVIXafYFU+U1q1sxYQej7FbG0Ovtx5n+55xXBHNDLPrFmboPd/aqA1jzCpm
oJ17BsKwgb8DE+jMylEnOz9H4pYggi1TOoLK2evSayLaU8VEvMhg3bfPmJGf
2/wmm2bq54Vy8H1AtUnuz2pSmI1BJeKpabpSGlecLXnAWZ/qNAISRYMMVmCB
bZ7rGm1IsFiSBS8rkTAqW+21jWI3h3fB4RDqwpKsCZpw3qxyTe9VmMdo/CsC
vokuc30/eJFhjGEhZmMAKzE1swsNpht1LiHw1qgIPaKxE+8HseUsCnVw9uZU
QhM3t57f3t7cdMZlUvSkqrZ6d0pB5Ww82aHHyPvRa0h1qOyEbEikoDehKPZi
FpcEAM6Hy3NYW6hMkZ9Y8NtUmtMGMKBt2rHk7O0fqnd70JbBetHfYBfinshB
BiEjb92Qd7M5vr/dx4hnxzbfdm+joXh6t4Qs0tWcA9Qc64+eJYu/M05he5sB
1ahVay99oa3SNOiaZJwxWgM5s9BA30aaQc8wrvDx8eHbg8ODLvnEdQhK211g
0tvuxWg4d9LYAr7em2uL8VHJdxxWPMKWnsi5jfG7/m1KYoaGSW3tbO3i9zyy
tyFrWx6+BLvYBEG371sbWWfBbsFeBQd8svNREhqoA3T7zzN1tPd2r7Y93Thk
uuVnNS9frlGcpzrjW3T2TJyl3F57El3AEchxLt4aj8fVu1r8CBMJW2w9dMRW
271psbWvNSb0Nh+enmHp/cP0Ks6zlLEB59fJ4Zp6b8RlLNbCMHftFcj8ab4I
+bOim6IofocugtehhvSbcQFwxJZu8Xpf/Tt8lNci9VuweHZXi3liW4gArePm
F7SIHKi8EJvqGDeD6k3v6+v0wuG4O1ByA4dtIaQOS4yPJBsKSTXXN+bwnow4
04U2hC85PIhWKp44TSxN3T41QdAtV0yNiz+fTTzQPlukPis4eOu0slxR0M/1
7s9eHfRra7zMOa0W9Lb5qPWHhiCzETC42NQPa2Y61JNKvDTSwVPSk12UB5ER
eWLlujpNQ05XlZV/iwntzat9pt17d32qi3/Xgi9LGD4B3LXoyxLH3URACQFs
ZCsiD3/FpVRAdfDrZHXJ/VvqdDYk/o7VAQbqv34XFto4gjsUJZrv5c0TrZda
U8ZAvV3fk585YoaSsJt+PtS2YP9AHKhhnFJ6HUPTfGwO4AeeywJZFc9bbW/U
CJMujzBvhkyDkjdf7drC+H42TCiNXxuXeHkG1S6dpEmJhZsVsgXsCgyMFCut
XkuytFuEbTEsezYgt7pq9PsBZiaPuJJTEqPbFMubSM0XjLwlEKQ/anEcXsQj
2bqrxZr/4+s4ES8sWmtqPx+HIwy6Ky7Zj08Ug+4K90VEICw6LMJ/UdEE5HFz
FUIpCXyjkuDTpkR3Xgrk/ov/go7lbpZfOEuXsk8ElA5E6PHxu7eGHB2nU5bq
dxwMkow4UMfx6DJK1B8jdHSUZSQ/c/EIOhdy2CARvHl0eKYX6z3KjAXjX5gO
Afp7rNbztGcvnf1vTXEafPGYZQdicCfO6FUWypCRScXb5/9+/MYpd/Ph5K0O
i2nhFPHnQHPlVttpx73QEV71KG/u7IIIDPT34eRooKZYeSiSU0VhOR1cugFt
/WLwaZIMgJqpKIoXKxDoYUM6iYkkBqRWHB2e/gjoAMhoCb1CowAFDCqVcr2p
0T0awsIHSKp2o5LEbAPJIrkpgvFVQZcrr2lE0TNnHZzDR/TIjf4GIeQtcc7K
PM16Dh6CnfdUS2igXHyZ6dm5udQnK6GJ0BLgPbTn5DPrRFtWZGykzp3xOUFj
fE5bVW5363Q6ahiOPqISszBsBO+YrA8TmOvfMUb+Exs+iV9c6dBwrxaU331z
Fah6GailVsYtDKWf1SpDOenIXmWoccEVf3K9lGJiauEK7W5u9QcPTlKzdaZc
AHSlP3/4fMTDN9TiJvxKD9ZFL5vGNUEXhTaL4d4wVkR7YLjsgqa1sbWhq8qZ
ecuM4acBifpk4Xkvcdl2SsD/Qfln1Z46YKa1j7j4GbCEO/bHPJtNuTiXnCz8
5s8/qp+jIbKC73TlQfJd53gnSd7V58v69QWlD6xLkSNo9ga2NrT7Dg+uMhvg
rz/o17/nc7B+ktBT3WRCv3av9K8/wPGUwNEMZ306wsKHupu9JPoUon4P52WS
Xfm9hPrH7hR//CGeYCWkBHsBRtY9z3Uv7ynT4ypE3OfqtMw++h0B8XxE8eKH
j9MUH3XTxACQjufqFcgfkzCtjA6//DCfTUIkx4KAZixXqaflpuh7CSM2JtJG
BFqK4uGqlnQdnN8VAPez6ZzL062O1lQfLdNEA2f5rCjNVUBTkjYKK0/R5U7U
AduHTGkTSl9AxCdc9Y4Kl6LNfaxHPAG5rWDLhbYxzdjRI+YOfMKiKp2QBWux
QKzcXvso+RaMkRROiOmS7klc4vkzneXFjO2kXJqhmA3/Ggnl2jtkRxEmUGBx
pMKEOOK+4iPxJAKxBL6/Oj0AkqV3uT3aogEwjIZIla3lOtIosPhbKdSb6ALk
GiPjFBoHiZSLzPj1A22jEteC3lIldhNFdjsJ1B2U6NY0SolCNPfNJCfMO2oL
svi6Mvu3ejIs7eNjyddgwREWMCHYU6p0VHSlWmjEEyFS6Wxsdja2hAk2sb0j
KoyZmFY1RqVf/MUv6gG7If6VTSUOoz7S6foOU9YRjjofmmHBUolwGgzMQbGQ
MR9ZDUGWT/fkW9Op9K+OeggTzaS5HI9NsmmAzHpzbhYB8Yo8nboBpdrpRk09
VgM03UmbhgtnfPLoIA896VGITo7F8ZwNIPsOqq8Db6Oz2Zymj4wN0+0fHiKm
Wz40Uky3swFjDfisRoT8kyjAVgB8dLSPIaKHBv3oho+O/TFL+ZgQIDP6MpFA
jfzJiyv5jbbAI+NQdA+PCUcxiHtcVIoD/B3YdQJUfiPMPiqgpWEmblDLV5jK
gugXPZH7g2AWHXBfA9YFgR7SiQn3WHjm6uiGB5+70rCR8VbTEuoTl9ZfTnPV
HAZzMixOZcCDeXEeg8N7G9IZfpFshl85mQG6su8/NKHBcAyd17CI1G1Ww1dE
ZC1K1pzND82EaJhGLQ/iN5nI43InFkzHzZz4bWbzqGyLpu3q5Vp8xbm4iRlG
0Fg+P6Npe5h8iq8D9aJUDnMWLJHRcYekb2TkrwO9n/VgGQ5G9tKtAPWEBnNH
S0NigznJ3eyIUmdHmETn5pQHw5eXyHxowJgXVPdb7LbmXIk71laqnP4WsC7I
rmgAtiG34jeBeFE+xh1aHV5O8OSgNmUWaCAfl2CgW98X5R3ekWbgbrzHZBsY
QeOepIM7sF1JOfiKRFLNT9DA06l2Z5ZC42asRJ5/tXPCDVM3ZP2gaHXd6jFB
65ZC6rHrd6wqq1hfCScNYe5mK1Wj3S2M+WhgHTrGA+eqTzbR3n3afDFRywkD
MXXuw1qsulOQQEy4+KElrVomCct4ZDsZ8s5Pzdodfm7NX4vu31hwsxIafPTx
qFU8q3lx13WIfb3uIVB7i+9DfgeETvxQR4erLAurDX2vQlvfP/eiS1egNzWg
pPpEjHWiZ0bUNDDagjNOL+wdIBDN0M5FBXLbu6WYxXPzNWAzM/dGnDsms6d0
e6m+YcpJVEfW/zUx+1gmjAO5PEc0+49QyKOrI1+2vJ9/sB6LLt0gFDjvE6/K
i5ctJNuWAjJKqu1dI5kUIPN/t8U3qk52dNgv7WNHbPLI0KyD/Q30Hy2dNNJi
MGia8NAHtNX23tG+lxZdraJRoF/iuBI89FkAhbd+EcTbZW2RtN+ZZiDaYjd4
XVfL0lQLb+WQ5y1v1X6VUfBmgOaeTYwAthfkOj3bzbFomgLA2MClAWjfM5hm
F4uHc6yKzYP1nnAw1/DXPFr/qUeztpfmATefckCtSzYPtfWEQxH/aB5m+6mH
0SdK83A7Tz7cwqGeP+FQNcmyecjdJx3Stxo0j/jiK4zICmXjeL2nZCaeB7R5
uKdkJzU7dfOQT8lTfMm7ebynZCkVpbV5wKdkLAsUxuaBn5LVOHaB5sGektH4
JtPm8Z6S27jmr+bRnpLRVGMnmkd8SkbTYIdqHLT/lNymasVvHvEpGU7NDdI8
5FMyHInUaR7oKZew4rxvHnB51oaH3OLB1j0pd7BYmukvz9sePuL6/eJNf3kW
9+jxjfrcDMHyfO/RENx1fPaX54OPHn8h9ncrqlZwr4KMCuUDlGQc6qE6so5q
FwV5z9ymyMGNN4NZypHyEWrEP3P0O91lcIEmIExJLDN1c3PzKspL9WMeYabm
MCtGl7e3t3h7oLrGSg9ppKP1sjzGuvOJjkPVNzJZs52bXwSKNvR9HF3Cwa0O
82IW3ZrkYx7y5/ivaZTi0+jTNOGIUDJK2IuXMOie4l3fH3wo3Nv7AkolVqdv
j993cZx/zaJU/Rl6h/leQJcrRaU4vxiEJ1kZX5EBbILqOMbz4w1zU7TRYy3J
VQTwPP4Ef68RMJijwU7RGVuL0fP04+HZ+vsP8P/vTm3hfimD7SGBimVoV8Aw
SqPzuNQFErE6Nnl9V8NkehkOI8wFTxRdjLiGV3TBtE6ycRrN1f5sgrfwFTCx
Nj4+iCJ1EGFgQRTl+uFh8TFTB/FfP+oH/5qEs0L9FOblx0g/w2DvMEoowhp/
KT6Gk6n+8QzIeDZXJ9k0LrGAvX7+h3/8z/wC8Hs6uvzH/0iv//GfydgOu5fO
/qpOo8uLMNGP/ozpe6eXUTKc60c/hWkaFeoMqCs7j9L4ogrQH4Hc8Q4n7pdT
MW7OLjNYJvUzHuvzFCfRDf43+r3dhuICAQA=

-->

</rfc>
