attachment
<div dir="ltr"><div><div><div><div><div><div><div><div><div>Hi Pete,<br><br></div>Yes, please send out a Stable draft that I can send out for PWG Last Call <br>with Mike's proposed text (note that PWG Last Calls are supposed to be <br>
started by a WG chair or a PWG officer).<br></div></div><div><br></div>Please keep in Mike's editor's note about reservations on X.509 Certificates. <br>Besides the ambiguities about private key management, there is the issue <br>
about Certification Revocation List (CRL) handling - which is a cumbersome <br>and nowhere near real-time band-aid for the inherent concerns about X.509 <br>certificates.<br></div></div></div></div><br></div>Cheers,<br></div>
- Ira<br><br></div><div class="gmail_extra"><br clear="all"><div><div dir="ltr">Ira McDonald (Musician / Software Architect)<br>Co-Chair - TCG Trusted Mobility Solutions WG<br>Chair - Linux Foundation Open Printing WG<br>
Secretary - IEEE-ISTO Printer Working Group<br>Co-Chair - IEEE-ISTO PWG Internet Printing Protocol WG<br>IETF Designated Expert - IPP & Printer MIB<br>Blue Roof Music / High North Inc<br><a style="color:rgb(51,51,255)" href="http://sites.google.com/site/blueroofmusic" target="_blank">http://sites.google.com/site/blueroofmusic</a><br>
<a style="color:rgb(102,0,204)" href="http://sites.google.com/site/highnorthinc" target="_blank">http://sites.google.com/site/highnorthinc</a><br>mailto: <a href="mailto:blueroofmusic@gmail.com" target="_blank">blueroofmusic@gmail.com</a><br>
Winter 579 Park Place Saline, MI 48176 734-944-0094<br>Summer PO Box 221 Grand Marais, MI 49839 906-494-2434<br><br><div style="display:inline"></div><div style="display:inline"></div><div style="display:inline"></div>
<div></div><div></div><div></div><div></div></div></div>
<br><br><div class="gmail_quote">On Fri, Jun 20, 2014 at 1:14 PM, Zehler, Peter <span dir="ltr"><<a href="mailto:Peter.Zehler@xerox.com" target="_blank">Peter.Zehler@xerox.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div link="blue" vlink="purple" lang="EN-US">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">All,<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">I’ve seen no objections to Mike’s note. I will assume that these are the additions we will use. I can send out a PWG wide Last Call version later today.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">Pete<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Impact","sans-serif";color:navy">Peter Zehler</span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
<br>
</span><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:navy"><img src="cid:image001.png@01CF8C89.7A16DA80" alt="parc" height="54" width="113"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">Email:
</span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><a href="mailto:Peter.Zehler@Xerox.com" target="_blank"><span style="font-size:10.0pt;font-family:"Arial","sans-serif"">Peter.Zehler@Xerox.com</span></a></span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">Office: <a href="tel:%2B1%20%28585%29%20265-8755" value="+15852658755" target="_blank">+1 (585) 265-8755</a><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">Mobile: <a href="tel:%2B1%20%28585%29%20329-9508" value="+15853299508" target="_blank">+1 (585) 329-9508</a></span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">FAX: <a href="tel:%2B1%20%28585%29%20265-7441" value="+15852657441" target="_blank">+1 (585) 265-7441</a></span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">US Mail: Peter Zehler</span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">Palo Alto Research Center Incorporated</span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">800 Phillips Rd.</span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">M/S 128-25E</span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><br>
</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:navy">Webster NY, 14580-9701</span><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">
</span><span style="color:#1f497d"><u></u><u></u></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<div>
<div style="border:none;border-top:solid #b5c4df 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> Michael Sweet [mailto:<a href="mailto:msweet@apple.com" target="_blank">msweet@apple.com</a>]
<br>
<b>Sent:</b> Monday, June 16, 2014 8:33 PM<br>
<b>To:</b> Ira McDonald<br>
<b>Cc:</b> <a href="mailto:ipp@pwg.org" target="_blank">ipp@pwg.org</a>; Zehler, Peter<br>
<b>Subject:</b> Re: [IPP] Fwd: IPP Scan operational attribute<u></u><u></u></span></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Based on discussions in the conference call, here is a summary of the proposed additions to IPP Scan:<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">8.1.1 destination-accesses (1setOf collection | no-value)<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">The "destination-accesses" operation attribute allows the Client to provide authentication information for each of the "destination-uris" values. If provided, this attribute MUST have the same cardinality (have the same number of values)
as the "destinations-uris" Job Template attribute. The ith value of the "destination-accesses" attribute corresponds to the ith value of the "destination-uris" attribute.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Each collection value contains zero of more member attribute which provide the authentication information required for the corresponding destination. A Client MAY also provide the no-value out-of-band value for a given destination to specify
that no authentication information is supplied.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Printers specify which member attributes are supported using the "destination-accesses-supported" Printer attribute (section 8.4.1). Printers specify which member attributes are required for a given destination in the "destination-mandatory-access-attributes"
member attribute (section 8.4.2.7) of the "destination-uri-ready" Printer attribute (section 8.4.2).<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">8.1.1.1 <span style="font-family:"Menlo-Regular","serif"">access-oauth-token (1setOf octetString(MAX))</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">The "access-oauth-token" member attribute provides a Base64-encoded OAuth Access Token as defined in The OAuth 2.0 Authorization Framework [RFC6749]. When the size of the access token exceeds
1023 octets (the maximum size of an octetString value), the Client separates the token into multiple octetString values and sends the result as an ordered set to the Printer. The Printer reassembles each octetString to produce the complete access token value
to be used with the destination.</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">Printers that support this attribute MUST list 'access-oauth-token' in the "destination-accesses-supported" Printer attribute (section 8.4.1).</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">8.1.1.2 access-password (text(MAX))</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">The "access-password" member attribute provides a password string, typically for HTTP Basic or Digest authentication [RFC2617]. Clients MUST provide the password using the UTF-8 encoding
[STD63] in Unicode Normalization Form C as required for Network Unicode [RFC5198]. Printers MUST convert the password, as needed, to whatever encoding is required by the destination URI.</span><u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">Printers that support this attribute MUST list 'access-password' in the "destination-accesses-supported" Printer attribute (section 8.4.1).</span><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">8.1.1.3 access-pin (text(MAX))</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">The "access-pin" member attribute provides a Personal Identification Number string. Clients MUST restrict the characters to the US ASCII digits '0' (code 48) through '9' (code 57) and Printers
MUST reject values containing characters other than the digits '0' through '9'.</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">Printers that support this attribute MUST list 'access-pin' in the "destination-accesses-supported" Printer attribute (section 8.4.1).</span><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">8.1.1.4 access-user-name (text(MAX))<u></u><u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">The "access-user-name" member attribute provides a user name string, typically for HTTP Basic or Digest authentication [RFC2617]. Clients MUST provide the user name using the UTF-8 encoding
[STD63] in Unicode Normalization Form C as required for Network Unicode [RFC5198]. Printers MUST convert the user name, as needed, to whatever encoding is required by the destination URI.</span><span style="font-family:"Menlo","serif""><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">Printers that support this attribute MUST list 'access-user-name' in the "destination-accesses-supported" Printer attribute (section 8.4.1).</span><span style="font-family:"Menlo","serif""><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo","serif""><u></u> <u></u></span></p>
</div>
</div>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">[Editor's note: I am really not happy with the following, and would be happy to punt X.509 certificate passing for now since we don't have a good plan for management of private keys associated
with x.509 certs...]</span><span style="font-family:"Menlo","serif""><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo","serif""><u></u> <u></u></span></p>
</div>
</div>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">8.1.1.5 access-x509-certificate (1setOf octetString(MAX))<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">The "access-x509-certificate" member attribute provides a PEM-encoded X.509 certificate identifying the User or Client that is making the request. When the size of the certificate exceeds
1023 octets (the maximum size of an octetString value), the Client separates the certificate into multiple octetString values and sends the result as an ordered set to the Printer. The Printer reassembles each octetString to produce the complete X.509 certificate to
be used with the destination.</span><span style="font-family:"Menlo","serif""><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">Printers that support this attribute MUST list 'access-x509-certificate' in the "destination-accesses-supported" Printer attribute (section 8.4.1) and MUST provide a method for loading the
corresponding private key that is used for authenticating the holder of the X.509 certificate.</span><span style="font-family:"Menlo","serif""><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo","serif""><u></u> <u></u></span></p>
</div>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">8.4.1 destination-accesses-supported (1setOf type2 keyword)<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">The "destination-accesses-supported" Printer attribute lists the supported member attributes of the "destination-accesses" operation attribute (section 8.1.1). This attribute MUST be supported
if the "destination-accesses" attribute is supported.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">8.4.2.7 destination-mandatory-access-attributes (1setOf type2 keyword)<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">The "destination-mandatory-access-atributes" member attribute lists the member attributes that MUST be supplied in a Job Creation request when using this destination.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif"">... plus the corresponding registrations in section 14 and normative references in section 15.1 (add RFC2617 and RFC6749)<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Menlo-Regular","serif""><u></u> <u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal">On Jun 16, 2014, at 11:24 AM, Ira McDonald <<a href="mailto:blueroofmusic@gmail.com" target="_blank">blueroofmusic@gmail.com</a>> wrote:<u></u><u></u></p>
</div>
<p class="MsoNormal"><br>
<br>
<u></u><u></u></p>
<div>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">Hi Mike,<u></u><u></u></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt">Agreed.<u></u><u></u></p>
</div>
<p class="MsoNormal">It shouldn't be an opaque blob - the "access-type" should be sufficiently fine-grained<u></u><u></u></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt">to allow explicit multi-factor scenarios.<u></u><u></u></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt">And Pete and I want to state that binary data MUST be sent as straight "octetString"
<br>
and and text data (e.g., password) MUST be sent as UTF-8 (with no trailing '\0').<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">The only downside (potentially pretty large for explicit multi-factor "access-type"<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">values is rapid loss of interoperability when vendors roll their own name values<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">for combinations we didn't anticipate.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Cheers,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">- Ira<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><br clear="all">
<u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">Ira McDonald (Musician / Software Architect)<br>
Co-Chair - TCG Trusted Mobility Solutions WG<br>
Chair - Linux Foundation Open Printing WG<br>
Secretary - IEEE-ISTO Printer Working Group<br>
Co-Chair - IEEE-ISTO PWG Internet Printing Protocol WG<br>
IETF Designated Expert - IPP & Printer MIB<br>
Blue Roof Music / High North Inc<br>
<a href="http://sites.google.com/site/blueroofmusic" target="_blank"><span style="color:#3333ff">http://sites.google.com/site/blueroofmusic</span></a><br>
<a href="http://sites.google.com/site/highnorthinc" target="_blank"><span style="color:#6600cc">http://sites.google.com/site/highnorthinc</span></a><br>
mailto: <a href="mailto:blueroofmusic@gmail.com" target="_blank">blueroofmusic@gmail.com</a><br>
Winter 579 Park Place Saline, MI 48176 <a href="tel:734-944-0094" target="_blank">
734-944-0094</a><br>
Summer PO Box 221 Grand Marais, MI 49839 <a href="tel:906-494-2434" target="_blank">
906-494-2434</a><u></u><u></u></p>
</div>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><u></u> <u></u></p>
<div>
<p class="MsoNormal">On Mon, Jun 16, 2014 at 11:19 AM, Michael Sweet <<a href="mailto:msweet@apple.com" target="_blank">msweet@apple.com</a>> wrote:<u></u><u></u></p>
<div>
<p class="MsoNormal">Ira,<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<div>
<p class="MsoNormal">On Jun 16, 2014, at 11:02 AM, Ira McDonald <<a href="mailto:blueroofmusic@gmail.com" target="_blank">blueroofmusic@gmail.com</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">Hi Mike,<u></u><u></u></p>
</div>
<p class="MsoNormal">The reason for some sparse syntax was to support Pete's use case (over the phone)<u></u><u></u></p>
</div>
<p class="MsoNormal">of wanting two or more credentials for the *same* destination (i.e., multi-factor auth is<u></u><u></u></p>
</div>
<p class="MsoNormal">in use). This is a critically important real-world use case.<u></u><u></u></p>
</div>
</blockquote>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
<p class="MsoNormal">Then we need to define it and its requirements.<u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal"><br>
<br>
<u></u><u></u></p>
<div>
<div>
<p class="MsoNormal">With the straight parallel 1setOf approach, there has to be a nested collection to hold<br>
the auth-type, auth-data, etc. for each credential for one destination - ugly and fragile.<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
<p class="MsoNormal">If the auth type defines multiple credentials then those can be provided via separate data values in the 1setOf, or using type-specific member attributes. In short, we need to define what the attributes contain, not provide a BLOB holder
that will become an interoperability nightmare.<u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal"><br>
<br>
<u></u><u></u></p>
<div>
<p class="MsoNormal">Pete and I particularly liked the use of the simple (1setOf octetString(MAX)) with auto<br>
concatenation to support large credentials (X.509 certificates, etc.).<u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
<p class="MsoNormal">That is indeed a simple solution, but let's not make it an opaque blob.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Andale Mono","serif"">_________________________________________________________<br>
Michael Sweet, Senior Printing System Engineer, PWG Chair<u></u><u></u></span></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Andale Mono","serif";color:black">_________________________________________________________<br>
Michael Sweet, Senior Printing System Engineer, PWG Chair<u></u><u></u></span></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
</blockquote></div><br></div>