<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Segoe UI";
panose-1:2 11 5 2 4 2 4 2 2 3;}
@font-face
{font-family:"Segoe UI Light";
panose-1:2 11 5 2 4 2 4 2 2 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.m-4641350324927119200xhoenzb
{mso-style-name:m_-4641350324927119200x_hoenzb;}
span.m-4641350324927119200xm-6142433305049276458im
{mso-style-name:m_-4641350324927119200x_m_-6142433305049276458im;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks everyone for the feedback…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Concerning LinOTP, I was struggling to find any push notification support. Last year NIST published a “jump ship” on SMS due to intercept/redirect risks. We
have an IT security officer who is not comfortable with SMS solutions. That being said, we are definitely looking definitely need a mobile app 2<sup>nd</sup> factor(for shear popularity, esp. with students) which offers a push notification option, and a back
channel for our campus IdP-MFA to authenticate the additional factor. That is why Duo is a nice solution for us.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I am simply searching for an apples to apples comparable solution to consider, in case we can make a better choice.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks again.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">-Josh<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Greg Haverkamp<br>
<b>Sent:</b> Wednesday, November 15, 2017 11:28 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Duo Alternatives?<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">On Wed, Nov 15, 2017 at 10:16 AM, Michael O Holstein <<a href="mailto:michael.holstein@csuohio.edu" target="_blank">michael.holstein@csuohio.edu</a>> wrote:<o:p></o:p></p>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div id="m_-4641350324927119200divtagdefaultwrapper">
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">2nd on LinOTP.
<o:p></o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">Caveat : AFIK there's no official (as in from-the-authors) commercial support to make your execs happy.<o:p></o:p></span></p>
</div>
</div>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">For LinOTP? There's absolutely paid support from the authors. And if one's willing to pay -- as we are -- you can use their "Smart Virtual Appliance" and get most all of the setup and HA as part of the package. And for Windows, they
license a Credential Provider that integrates with the server, which is what we use for our AD logins.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Greg<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div id="m_-4641350324927119200divtagdefaultwrapper">
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">But LinOTP supports all sorts of stuff .. you can do generic HTOP (eg: Google/Microsoft Authentication with self-enroll or any other one) .. TTOP tokens (RSA like, a company called
Feltian(*) makes them for ~$6/ea in 10 lot, way cheaper in higher qty, and offers a programmer so you can load you own keys) .. plus all sorts of SMS integration (use Twillio).
<o:p></o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">It's a tricky bastard to configure and you've got to work out load balancing on your own (and really question why you'd do this on-prem anyway .. just deploy with docker and let
$IaaS_Provider do GSLB .. and then a pair of Sambas+OpenLDAP (if you need it) as BDCs in a separate VPC to handle the passwords.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">As for backing the thing up, certainly do hot/hot on the MySQL or something similar .. and then call via the API a command to dump the table through a key supplied through the API-to-shell
command, and stick the result on another volume which you then detach (because that is all sorts of sensitive).<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">If you have a VPN I suppose it makes sense to have a local one, you can frontend RADIUS as a protocol. FWIW you can also shim RADIUS into MSGINA if you want to do actual PCs with
MFA also.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">As a bonus, this will also backup your domain authentication bits and LDAP structure in a 2nd way that doesn't involve nearly as long of a restore-to-usable as the Microsoft way.
Just bring up your replica locally and repoint DNS.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">My $0.0000015 BTC anyway.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">Michael Holstein CISSP<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">Mgr. Network & Data Security<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">Cleveland State University<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black">(*) : <a href="http://www.ftsafe.com/product/onlineShop" target="_blank" id="m_-4641350324927119200LPlnk922670">http://www.ftsafe.com</a><o:p></o:p></span></p>
</div>
<div style="margin-bottom:15.0pt;overflow:auto" id="m_-4641350324927119200LPBorder_GT_15107697638210.4680165553625686">
<table class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0" width="90%" style="width:90.0%;background:white;border-top:dotted #C8C8C8 1.0pt;border-left:none;border-bottom:dotted #C8C8C8 1.0pt;border-right:none">
<tbody>
<tr>
<td width="271" valign="top" style="width:187.5pt;border:none;padding:15.0pt 15.0pt 15.0pt .75pt">
<div style="margin-top:5.0pt;margin-bottom:5.0pt;display:table" id="m_-4641350324927119200LPImageContainer_15107697638160.9178840545260616">
<p class="MsoNormal" style="margin-top:15.0pt;background:white"><a href="http://www.ftsafe.com/product/onlineShop" target="_blank"><span style="text-decoration:none"><img border="0" width="250" height="135" id="m_-4641350324927119200LPThumbnailImageID_15107697638170.43287830172320874" src="https://ftsafe.com/files/upload/20161223/20161223175627585cf4cb46931.jpg"></span></a><o:p></o:p></p>
</div>
</td>
<td valign="top" style="border:none;padding:0in 0in 0in 0in;display:table-cell" id="m_-4641350324927119200TextCell_15107697638180.40754172821668555">
<div id="m_-4641350324927119200LPTitle_15107697638180.9837542113512676">
<p class="MsoNormal" style="margin-top:15.0pt;mso-line-height-alt:15.75pt"><span style="font-size:16.0pt;font-family:"Segoe UI Light",sans-serif;color:#006A4D"><a href="http://www.ftsafe.com/product/onlineShop" target="_blank"><span style="text-decoration:none">index
| FEITIAN</span></a><o:p></o:p></span></p>
</div>
<div style="margin-top:7.5pt;margin-bottom:12.0pt" id="m_-4641350324927119200LPMetadata_15107697638190.31647761882558734">
<p class="MsoNormal" style="margin-top:15.0pt;line-height:10.5pt"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#666666"><a href="http://www.ftsafe.com" target="_blank">www.ftsafe.com</a><o:p></o:p></span></p>
</div>
<div id="m_-4641350324927119200LPDescription_15107697638200.3322224662723723">
<p class="MsoNormal" style="margin-top:15.0pt;line-height:15.0pt"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#666666">A professional of security devices and solution provider includes software protection dongle,OTP,PKI ePass token,
Smart Card, Smart card Reader and Mobile banking ...<o:p></o:p></span></p>
</div>
</td>
</tr>
</tbody>
</table>
</div>
<p class="MsoNormal"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
</div>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="m_-4641350324927119200divRplyFwdMsg">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>>
on behalf of Rob Gorrell <<a href="mailto:rwgorrel@uncg.edu" target="_blank">rwgorrel@uncg.edu</a>><br>
<b>Sent:</b> Wednesday, November 15, 2017 12:13:56 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Duo Alternatives?</span> <o:p></o:p></p>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal">SafeNet Authentication Service touted a Shibboleth Agent back when we were looking... IIRC, it was less than impressive looking.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<p class="MsoNormal">-Rob<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">On Wed, Nov 15, 2017 at 12:04 PM, Greg Haverkamp <<a href="mailto:gahaverkamp@lbl.gov" target="_blank">gahaverkamp@lbl.gov</a>> wrote:<o:p></o:p></p>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<div>
<p class="MsoNormal">On Wed, Nov 15, 2017 at 8:48 AM, Manuel Haim <<a href="mailto:haim@hrz.uni-marburg.de" target="_blank">haim@hrz.uni-marburg.de</a>> wrote:<o:p></o:p></p>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal">Hi Josh,<br>
<br>
there seems to be a Shibboleth plugin for use with LinOTP:<br>
<a href="https://github.com/cyber-simon/idp-auth-linotp" target="_blank">https://github.com/cyber-simon/idp-auth-linotp</a><o:p></o:p></p>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">We're using LinOTP with Shibboleth with a heavily modified (essentially unrecognizable) fork of this module. We've been doing so for around 6 months now.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">If distractions would quit getting in the way, I'd have finished at least adding U2F support and "KeyIdentity" Push Token support to the Shibboleth module. (I'm still hoping to have a first pass of that done this week, at least for U2F;
the push tokens are a bit trickier.)<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">I haven't checked InCommon Duo pricing lately; we didn't qualify, and the market price for Duo was considerably higher. That, and we needed MFA for Active Directory desktops, and Duo's solution was ill-suited to our requirements. However,
in general, Duo's solution is quite a bit slicker than LinOTP's. In particular, the LinOTP enrollment apps are sufficiently poor that we decided from the start that we had to do our own. And, of course, the push tokens for LinOTP aren't part of the open
source distro. (Technically, the token code itself is there. What's not there are the push notification servers.)<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">I can't currently distribute my currently module, but I don't foresee it being an issue. I just haven't bothered doing it until I get the last two pieces in.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal">However, we currently plan to implement Shibboleth multi-factor<br>
authentication along with the LinOTP-fork "privacyIDEA" and Yubikey tokens.<br>
<br>
Up to now, we already have an privacyIDEA-LDAP-Proxy running for some<br>
secured applications. Instead of the password alone, the user has to<br>
enter password + Yubikey token into the password field. The LDAP-Proxy<br>
then forwards the password check to our regular LDAP servers, while the<br>
token check is forwarded to the privacyIDEA server.<o:p></o:p></p>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">We have something similar for the LinOTP server. (Not theirs, which is based on an OpenLDAP Perl backend and seemed to have concurrency issues in our testing. We'd had one for our prior solution that we ported over.)<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><span style="color:#888888"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="color:#888888">Greg<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
Kind regards,<br>
Manuel<br>
<br>
Philipps University Marburg, Germany<br>
<br>
<br>
<br>
Am 15.11.2017 um 17:09 schrieb O'Dowd, Josh:<br>
> I am doing due diligence for a likely Duo purchase, which I have demo’d<br>
> on campus using the outstanding Shibboleth native support. I am curious<br>
> if there are any known legitimate alternatives to Duo as a 2^nd factor<br>
> solution WITHOUT sacrificing Shibboleth IdP front-channel password<br>
> authentication as the 1^st factor.<br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> </span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> We are not considering a custom built solution at this time.</span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> </span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> I truly appreciate any feedback from the Shibboleth community.</span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> </span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> Thank You!</span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> </span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> Josh O’Dowd</span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> Software Systems Engineer / Identity Access Management</span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> University of Montana</span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">> </span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><br>
<span class="m-4641350324927119200xm-6142433305049276458im">></span><o:p></o:p></p>
<div>
<div>
<p class="MsoNormal">--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
<p class="MsoNormal"><br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</blockquote>
</div>
<p class="MsoNormal"><br>
<br clear="all">
<br>
-- <o:p></o:p></p>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal">Robert W. Gorrell<br>
IT Manager, Identity and Access Management <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">University of NC at Greensboro<br>
<a href="tel:(336)%20334-5954" target="_blank">336-334-5954</a><br>
PGP Key ID B36DB0CA<o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p class="MsoNormal"><br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</blockquote>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
</div>
</body>
</html>