<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-15" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-15"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="August" day="28"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 123?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 127?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs and finders</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">2</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of <em>paper</em> authors):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>?</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, and Haowen Song) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">TBA Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 649?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-authors of paper <xref target="Intra-handshake.fail"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8292XLrSJIo+K6vgJ20vn2kEUiCO9WWk8VFXCRRG6n12DUm
CARJiFgoLFxUmW33Zd7mB8bsXpvHsfmBeeq3+pP+knH3AECAIinh9DlVVdad
mQIBDw8PD9/C3UMUxQNXc3V2InzpmK4tixPZVJ2JPGXCV3kqC6eyra8Oharr
MseVXc0yhbplOprKbKYKbdk2Rp4ufK3fn4rZTLYo5nLFSkmwRkL9vtcTSqmC
APAEh82ZLeuC5U6YDT+dOviKNxNcS2DLGVNcAEZfVFJleK5YhmaOD78cyMOh
zeZbkNuP0JcDRXbZ2LJXJ4JmjqyDA9VSTNmAaaq2PHJFLQ5OHMmaLkqFA8cb
GprjAFR3NYO3O6f9piD8Isi6YwEWmqmyGYN/mO6XY+ELUzXXsjVZxz861Rr8
y7Lhv277zS8HpmcMmX1yoAImJwcK4MhMx3NOhBEAYwcwqdwBALaZfCJUb0+r
BwvLno5ty5udCL3Tav9gylbwSD05EESh2hHkMYzq4B+btJDXtMCf42txMGem
Bwj8Igg+8IcW/sHn9wBjAqWFFv6Ejw0gBL7yF7aUjZnOUrAU+Fy2lcmJMHHd
mXOSTkd+TAM4AK25E28IFDK8iWwYsip6jmzIoiPbqmynt5H7C3ymy4g5fBYA
3vp5ikNPadZWQOndS5qauAYMdCB77sSykZIwqCAAh+icG750/QGFOxxQ6NGA
X+gtyx7LpvZGdD0R+ndCw2YOLP2x0GK2IZsreotxioUTHxDmKY75X1xPVPlX
KZV92TL+vSYrE+bo8lxoeEO2mlrbBq9bNntg8pzFhsSv5L+o/DNci20D9Cxz
PLSEmrcNbg/INZ7ImtDyZFOomsBaIwvmRtuqz5SJaenWeAXjp46FC1eFf9Yn
minH0BjqHlOtsQlj/mWMz3ahUp8wc7zUTKENo4234dNZ76/YELJnI4fbH4/R
lq0FMwWc9U+b8ATIbkrZTCFTyOf3o3Mur0CG2ooG427FZ6G5yiQGfQqfpBj/
5C8O/Z5SJtuAd4AJhZ4ysS1lug34abdz0akK17blWoqlH8NklVRsLJfJxl+Y
oemaPPPfSskabBiTE2UOgkPYlDcp3FknBGeH6qA3NpXC4YnQ1sYTkXSB5q5Q
ToFw9iU5yO7+RY/PgiSmcOaZTMDPj/lQsj1m7loELRaLFDAFQ8E0hg9SJnPT
M2+oawpNP53PlLNSRSpnBxvYIXKDOG6DGGb440AzBwFmA8CMcAjFCP1PBOxB
nHdTwl3KFxzxX+5TwZ6OPz8T4ZszWXn1mLuDvKLNZtbfg8b6ag+NfbmLUv5T
cp1w+omUik/Whx4fivbACb7JH/jUq1t1q+crSk4GQXOEuaebYJcMdYaGiM10
eYXvyMoUftNkME1gemSbsNmEGWTC4KegmR0f/BauVOYsBUikAYdbpoAG/01T
f91QysJ6DbJFoYtMTOsAP5ze3Tf4q1IxXy7vm+XpZadX/YfMk3lzNcVMzQFR
5dnWDP+Vpr/TG/jvm2qr3auKdZA6jljtxLn9x08kyvfZXByRvazv6QB0rlk6
c20nrSC6aYcpHm6wtKzONQdsQOakaTbz0XgsGvPlUjTG49LuvXC3BioQBcDE
Cyhyqo6ZzhxH7K1g8oYTp8wtMyw3ZvQhZcCyVNjM1baRJjrzqjf2HPdT82Y+
Gs4KZ4073XF3T3zyMlbEF6UwF0eL0mT3xIPJCf7k4Fe0dsVgaUEXuSsSf7a7
OXGcU9Vfbs18ZwdHfQLQ6ugXjDS0JcBCF6poPmsKWtL+yFGySBKIGXOPKESF
iRwDKjGlMXdEOxwfpA1nDFSR3fQyx26WzZeb5tmFwmRW1PODy/GjaTiNp/Qn
heKBFpgjvuZtiHVbczR4r3HVSUmZlCTlC+lcqVTJZsqpXKlcyJVL0Re3KQ4i
ASoDegMpF6NM3TJmngtewInQxMGBVqasr/BVcNJ2qY5La87QwUGaFT5UH/V6
XYwsT5pmqYsOuH6ipooKYfY9mgN+6VrA0fJIjv/QTwGv2/jQZiPAPULBTCXd
u05lM1IpRbugIzZSI8txADURV1Jk6PSKkR128qm3xEx+80VXd+JvFD98o/LR
G1ImeAM24hvHZQRSD+REKpU6OBBFUZCHDknCg4P+hHGfV5A1w0HZAJbeHBZf
cNHcBWtJF1TmAnvTcn+LK6r//jWhZjskf//bhhJYg/m84jg8FhYTDWQ0STeY
j8zZdY02w2mYCkO8J9ZCODoie+ToaLtvLIxoksD+MySNprBjAAHOwhEY2RPL
c4XZBLgeIcuKAiLqCHnLZsDo9rHgaDgSykHN9IDjNgUwiBdUN2BP2ezV02ym
Hn+IkKyqDrzkmSbD8WR7BQOgY72E7XoEw+PigZELGsjBSIEwBNEHW3G4Elz+
C5m/wl//us04/PNPWgt8U7ZdjVhkx6skNeB9oA3ixkRrJMJ3Inwn8K0KoHyZ
4FroSoBTcQ8m5uhY8MBds4XqDP1YMZvKCGCBM9NhJIIBrm2pnqJxuX5MGIH/
BFNhQHmYjmktdNQ0kVnpDPwrFzGZsomlA3jHZ2tDU1WdHRz8QrIfAVPQY+f8
Z0giE4kXrI8gzwAjwBV3As3pjdGw2u6gCu6YmeXIunMM2I1BCpECA65bTBhF
tOAfK1og5CQgIgJ0FGtGrInqTVAmQEt4E2hiWm5KaNqWAVgF6lSYwSQxDgaC
/1iwTPoQoYDlAttT0RzOwIpr2Q6yG/6mALIaSmNhqMF/mWPBgL0BDqBjgLC0
jC3PnSiW2zHEFaI4HX+XsO3HeAgfw+f7WSkJW9CYYLvB7/4TWO8q7Ay+GwxY
QtgbR0fCTAY64cCBuouuMa1ioOuUUNfB7yINsGeF+Qw3OR3+Dzx90PtoVPEJ
x9TsD5mlyWOisZn68wSGB+6w4RlIFT7SOj6Jv8JLiDOyNypNyxtP3k3C5yOV
OdrYFKwZTpfoso8csMN+Ea5A7s01tkAdAoC4EolR2x8LGVcb+X43zXJz9D2c
6hCpgsf78aJXURGAGaD6YQ56FvMTgkgG6MODP8BOSQl/CLXNYeHZncOQKeC/
qiFr/wFfSPhBXddgmv/5P/4vh2CaFkr/P4RvXVCV/4rG+lqlyVrKgKdk5xCi
CnCHY3m2wtIzW5ujPAWcUMIDCmKov0RQby6jpT5E0EgDZktrwN/lfqddmzE0
V820D/CQZpXdmFWUrMHsxDUa2R+NRpajkUM06FABA/8WSZzYwLkfPXCOD5zH
gXvA0cym+fNQEcnX2Pj5Hz1+no9fIPpbBjzkRIet8UuWdssvuTgKhR+NQoGj
UNyDQh6H3/TN0E8gt28rQps2vcEYehFOeqhbQz48eDIMz0ecNLjbU8+59dRV
KvAlwagFy1ZRlKh1m5qpo8N/AzPU94njBqhjOqLm2mDvF8eEw2ImIjhg6rQ3
0y1ZddLoj6SlbPqB4TxtsYpem4uqFTZfH78V61eXzU7j9LLfqV4UW/6QMGa9
HvMhe53WZyZ+CPJAVkGygjiBff4CQwnf9kixrTA3yJAOJBpZ/zNLiUiI4o9m
jyJnj9JW9jgG9jxe8wjowL3uDejEENHSj0a0hIj+9YR7tr9+eSfUwT7TQjXK
FR0iHtiqaxPmy58HB//+7/9+8MBCb0gOtBk8gInD/4EbGVhn8BeY9tyUHoI/
sFZoB1sUGn27W4l5qAYQ1sE7Wxtt6wi6puqbnoieobnaeK3y8HtVAxNuTgef
IarROIrGnJRw5aHOhI0H9sicwV6ET2VX0FzBkFcHYH6AKS7AGE4QOwJbRoM3
4SPbAkTBYA5i6iJMagSKXvgKJjrThdxhOH0+qX3TlnUwa9HQArMAyIejggbQ
Ldib6gE3lyIxK3T+YGJAA/8J6AkDQKKto5AWIydt5uIbgSN4MOJWtaqNRgzt
JvgEJoPD9ixuiPBPYXx/4o5ns5AgIErAE3OdA6CCBtYAGk2cuKg2UsQyB8g0
oN9neOg8BDWGi6BbaEvgALEw1kfmDDrqDlrY3BD5619jAVH0xxzHg9/gPZfj
D+6qCh5A4Bpz35B/DZ/HXXH4PnIOz226rqUyHVfqiqzOYAd1Q+blAYO4rQ/u
LFhuI3RLkUVwrQxLjVt8OCmEBCOuqb9v7lv2DTiADu7fFfoi5hh/Ra6CIX8H
GeHKv4NdbMtgawHmvpNV91kBMOC6XfAtLeT8JvmOwjd5PEa3zWU/Th6FIA8p
JACPHJIQvkepRveuum2uO/0nWDVYawf0MKgRjGkDjkYwR8/0/0r5Czji7nGA
BHmOgTm+xSskHqBwK5lgUS0WjRTFhfz2YBdxJ20+7tFwfYFrghJVxp0RidZ/
RezR7YQBFubh1nHex7lgDPzG9zV03VqQ5FxYmKZgci4BieDv+kB+rz1pcADA
mK+R7hAmsNUo6ODNUHCrB2ARX1tgDezw+VEeh9/IqgrryKVUFElONd9LE7iW
8tf2MxRULUb7H92qOUKIH2nI5Gaht41vgT8MaPrC3mYu+MP+LuDjwup+NB+Q
+NuHOhaGnouwOMCjI5iwht8BQaMhqY90GyDqmS9gYwEDMhX5TajbmCbjoC+G
4g2Dh2AiNAllcrhEUaT/P/hjmwj7Q9iaonEsvM+c4GbKGZNNEcxNjQUnhwIH
vRFf/KGwNwX3D4a8eSK0ewT6ql+r7vydRGWQExIzp3AkJ03JWfjSiK8Qmkq/
gNa2gYe5+iCWd/kDAx/gqqMqhz3JVVGPKSnwNiTklr2xSXox77+2jukA38CY
DYpKA8T7mE5tcH2LeruvGajNGLfyuENXXYcUDQpUgFapgkKiU8F7rj6RF09p
E/whNDAqEedCtJg0U6No81rTs0DTk8Vg+aoYIGRKwpXiHtNBCJF/AwXEIHxZ
ysO8lMjL0QQUX8l/w6yzta7af/Rky66TLo6Hr8vM41P54clu57rL/PyqbGZF
73z8lEbPgR9v0ahFGvWbTy20g0CpEJ4RV4sNU8GIOBj8jW5VMZPNlqRiplDI
p6NeWeSANGWT+zdOu4xx1wUDIMoKsIhSIVsSmmwYwSdw97hb7kxgrd5vKuHb
0VEvyGz4VWh3Wm1MgCD7pnx4dPTfEbJ/shuFDQJni2BZj7QPbiGAW3wHl07f
I2BQvmwVM98J/9uaj+LLEzFerpG8eECLfi242Rg8l8H4SbvymAef4EdxnkmV
UxItQfAB12X00TbifALjCmWPfC++Y2s3roWUJI4tKZUtwmDvkB5b34mwlHmH
MXr8cY/xO51zlSk6qeZve1IUPhVF2YSdnnm6ni6UaRuXNmdwvx5ty2QwAm19
54z8/a8ib2b3DJvIkiPrD1eUn/KC+hdwx25AfxeGeicUtujDPQyQD/bYBsuu
VV+oauLuW1TgR1WNvKFjUEceHV0yLTgMIksHbTb+F0ogNCVlEw9zeIKjsgIf
DmS3hUgLFre7lHUmc0zBkhX8+wOTp23Zmfx+zP+70f6dEo5/r8nqKV/231Ng
o/XxNAoPzoRIvjK3zsEdORa0FEsd+zB75OQTVJqa/wBA85mCTzO2LFVguq9O
/bMjmWcTk4V3eudnIh2c4pEuWDLCnQnr/q+O8I1++OD4d2IZbCaPwZdCIkVw
Bh8iuvTvJSvNIcw0p9hFuDIw20jGUHDeggYp2LNgaDlAc/qee1L38bjJ7iwJ
4QK8YdC6wBXIQb+AMS4qc+BFR7HAWhCAF0JGBASGMnqAMNY3oEQffDHX1pSI
KDCBIEAPNzW25mnEVvRfSSPQw9RBZLtxruQa7Q8+bxBiwWifhhk1dyJmz7eF
Bl6FPCMDLWIMRJ6mR7BLnPARBk4FPGIhjL5+A0uP6fGIrYaPuMjx47TwNO05
aWaGuUSiAs+ZnY4aI2n6UAxfif6GPFAAoSJmy2ImI1GSt593UO024uPLhsqT
mcx0cCjjpPmxnBtCTw9BxmLwOg2vi85QzGXymRDsemAkHQXqL9HPJpr1T083
6AWWT5RWdL6zQal3QBqPqrWI6B5VT8mKQbaXamnpMO+nWCgX8/kU6LxMNpeh
mPDfkeZ5pHkmSnM8VgIzVriwFnwmPVfWmRdh76Uii776i6TxO/y14N8DzwGZ
sAR979MpyEIpiIV8IVP5fBaK/wHCyKcy6ASB8+kZHLkaSNRps9rrf4TeEF8c
Ybpb+F8DS57qwGLbcCxKlVI2CY74wSFimN3EUFZvq901qKEMGtNAGen/F479
xw9kc6nAVxLPp3J/R3JJScklEYqVDRSb8hDE2pSpH6E4Cl5c/9d+ppMyn8AQ
HkY+2IrhNuc3DvnvmMR+KOwIsZRoF+P3MbNoU1PyVIX5e02pRDWlEmpKPdSU
aCFRpGwN0Y8W8vOUtSI/OgJkwIhBU39n7AADm1jh5Z9lbKYJY0TNoHGFFXP9
QdGmsoK8KTfMTNiOuYMMxCMzeFwRZmFEMnMWDI8jXJikydNR8SGwhkMmKRlG
mD1G1W4HB03P9gO28fQMtHj0NWrrKOfMcgPLAyMySI59gbevm5kia9v1kPIg
fGshNE1A/1CBGj8jOHU2jQL4BGvx/sCsUZeS4sD/EPhjKf44S4/LqVLIQ/6b
Ubby3wJrfPNRMSZ56OGaBU/X1YGfoMLm1AWf7/AAzcbINNjwBp4KrwQ8rzCI
hYAA3HQ7JsYZaRj0lB3Ml8FYK/6U4jY1woDPwCbmA9kM82NoqSMeUSd+BHlw
UAUmAU/X3Vjhd0eVNouEzGHRxJ+WbnKyTQwgs28zsj9yrRHP98f1+xPoCYPE
8Z3jH412soSHbQnx64l8h09KlPtnTjo4+bsENnAFj46CgMPREZAljPjwENXJ
TwiG4Zk+P9r2/SqKQicOLCGyms2RHVsJEf18FOxHYXvQGQkryyNhIy/wnwjZ
XPm6fe/ZTkxeHQszQlzAChbPEXDSgmNxhbygDAlBmTBlSsu77cD83Xk5GhNc
DxqbMjWoYRR60VxDZ5doDVIA46mJPHixd45HM9mdHG2IYkTq84KHBPcHaTIV
eE1wVsbQwiD8loyTf/tMRO3oKIypgcEkj1wWhpveobDrCDKCBs7nK+kH8PxU
ccZMkYIXh75dJPvngdsSZL5atjZGxYnri0YSamoxk+dBJGRczNzQkT8seF48
PMBCjSpmc1Dy8UOLDig1RZth6vfMQldUFSzPDfkM0yQ4dw2BV5NoguBwXCZb
ja/mpu4hwOuj/MibO6uT3n1Fgb8cHfszG4mijFIAgAJElm3DbgYK/PnnIf/M
XSfVhsfAuFTOaJUi6lAGd5wwWAlBpQlYBbwKE4y35p5gNgWWTWguN2nJ8gW7
yxXmsu7Rvg/SKoKMdX667JuoPPK4P8mbJhIxX2FJOO5VU/BLmfAITQZ7nywe
314Pzsn5pI+OVM0G/aXj+TI8p6gzP9MHubTj0DugHR/u6OhuRw0FDqK5DtNH
0Wx7BRNebTPcJRuFNB/tThoTDRqyH6NLjikYnh2a9/Ti9vKO/YiB9Atycy4w
1crBRIZGW4jRQvj6+3i5+v0QxC9mnDgbvw6Zu8DcBWWdI8MTmTDzoR2KvyCn
CzNhv/4+cR0lgIh7mJmKvZoF6YBroWnghMbMOcilhOo6Q2wDGkjmPdAimWVY
VCYfHFzzre4wFpwhZ/eeISNMv3iJNEYvoOM1XxCUOl/rsPfAWqFhWrgFD9dx
23BbCn9iXlcQfydH0k8oArreVvu9oBDOjpQluasZuUA7PeAUJaBEEYDZnAZl
SxivxkXt8WXr+Yvakg5xhfZ8FUnjXq9j36f8OVK+lT3ElfkcjOj6xaHkDret
SS7RmnRR9N7yIiZUjdVomtS2AhW/ZgnXhqwGdZuz9EEeynsFHjNYU4DHRhL6
hOkzJ8x95PmNUoAfvo9ZAWFG17qOYNt32eh3HZ52syfR0k+m/ChbkBIohaBW
LZKgA76qZ/DCDjouuA6k0d7//bHO+hN+kY6zx/njYvxh7rhwjD799ftZo99+
Ior7R4gN5r8d/Ef4b0wLkoSTfaxKUg6++M//9X/6wP7zf/4f8f9AKNkPoEyV
yQYU/l9xKLkPofwu7IDi/0ckekG87xfwYShicy+VUhLxe1MbY7Si8NmNRdIz
YGXM6QvDJOFG21/7Eql4WX8bVBpuPx7aWxbzs2pX0j+1MiatW+OUu3Q/XyHz
06pjohP9CdBjE91eg/PT6m+iU/sJ0GNT21vl89MqfKIz/AnQYzP8qI7op9UQ
RSf5E6DHJvlhpdLPqoRJ/9Q6m/gkP1Vv89NKaaIz/QnQYzMtp6JWBAwbFFT/
uHEDiHxaPxF+ZGJbTikiuv4XOggIQ0+wuE2uiB3S2Lt+JDVPbQf9wAiYkA9Y
Lq+TrTjbneFN9uExRggm6LR8423x4gGg5UyOhCTR6cI2EVNmrzNLVUtJ7/o0
fXhMgb1NyzVi7vajjQkcbww+ouu7/eDkoyM6WQ1tTV0X1Qtflfgm2GsEY13F
ThocfjbxnoeKtrr+ZK2Ddb2nMcNHSEZtdKygMldrD3/ITDbS4oeS/+hFTSGH
+cX+8ajw0dG6Q4HvVcD0aTXfLWOUMeiNj6YVlGH5HyH3VLHoyoAtATNweU8I
jKdEYpT+uSmvN1t3ofALT7ZGfX8AT9iMKk7iLmU8AElEpNYWFOfEKhiKy8mf
q6cRM/kYDh+i68efeOQuWCT4w7KZEZ5HxyO3FNJLfVL8XFTPT7n46WkGZqDj
lGDmWOCowHD05naSC9907MBpy5/mSnwk+h+lDz+LIroghOHH4fb33cPeB5Dx
lFc2pxRb5RwVpKnSsq4TWD+OzSMvb2nUdcSzJ48I+HpnIG4MZIyK9Uy25TlB
uxlAE9k/zGk8xipFbKuwTkOYaOMJpiHQObUayZf8njQN4Su6pn7Iep3T+Oef
uCRY/djS5n6JEI7L+2oofibAuuvgxtDHeB4Ewp9K19QDP/qNPSlAe6BQ4UEf
3GEYSMe/PxCw3bte/8CzxzzhwcAMkr1i1C/d/IipqEdYlv55sLdByz7cKJhv
YOaHCuYF5aHK1EKGatD96t2wny+FyPphSyOeiMwthL5l6RiU9DBisFkpHErE
EMFYgx7hWyAa11tQY4wKbm0sI2Es2IEepf5VyrAJCrnDoLZ4Y0OvS/t4a414
NSnP7YmdGwDS/EDk20hbIjcC+XxAqhb8Ia97uSU9uv5UQ7GI/QaiQpTTgMsh
P1qwKJrHQIh6joCdl/1iO6S07fIEHMAJ2WoENMItt1Gc90G0LjilQNgpoo/t
i2EWnoMsIhFnrMdGpgHCYUdtrAHFnlYkhaj4MDy1IbCUf6ANvWjdEG4wz/TP
fsIq83/CFfBJjaeLmFN/jKThmfOwU3DaAepgoLMt2NIKxirGjsOwcaQmnpKS
34v5Q6yn5jF8ztM+F4QbSLE8XQ1ygaj62m8Yxo831/aJs7k8Kd4qxwiqrJWJ
pYEY54XraPTpoMn52lPnsbC6dcsccdGOuZgNBWucAxeEJ09I8g2UD/v6XFrY
vC/Q6EHB2T8dh2zfo6RIuHwxQdFe9875CfValaa43I7xxsnBwf+OnQ3Xy4J2
g5TKHcc2YAgjkrPf0EYjjYltpuvYaxn5SvCrPEZYIQhCT2O66mAVBryjzbDD
JMjjOaNWYX6zJH449/W0fthon/odELAygCkyyvYFt709M2Z588gV8Nu6BdWG
SLY3q314UHidCUnctYVIKL0fJhoKItdnoiHY/ho3ODh9t3zGTaL3Uiw8rPEj
5rP12Rv2ndB4TWgoDEFB0t4KXCtt3TIP8AlZNN6GIFwl3k3KITI5/gGdh3XL
bkgXE603IHhw7hn/Ga2nmW8PA1o+K6QwNV/RqUUiLoIhq5SaCk5c0J8LTKex
x2fvq7/1IeNB5LxxX2U/gg46fVGjL96OMf5ppA6WnxKU3xXICrjoiAjxNtgI
zJhNZEd7i2ZIRPYwZeDEKsuR0Wwwbsf8BImEp8flGdbX40I5MXSpMRmf99pc
iRem3FJaxMH653hCAs+aiHdV487RVmKl8OQMX6Y2H/4BciQ3Gr897V3dduo9
Kugi3H7ZrOM5CM9Z9h2txLqave+LSRspaKnp0xBPuhUWdjjbbLvCkemGPVsC
PPafZ3+Ax9oK88/jQvB8YcJTnYNqrIHHJ+i9s6HdBW9ox49ymarJQh3FIFiv
4Sm6yRbrsie0AOk1wHLEqFUdBgeQw7AweMwCdyrQ0juywHyDecOwIb3AnSfb
+MBLSFEGLcqRWzbW8Og+nnhPrRX4DzyZNiiTQG5KZ0rpTD4d9ZjE0GNyROpB
JYYnaqLmiEPbmjKTDHRQYaIhr0QQcyJbwgjpQrZYzBSKh4DR1zN5JpuwzofC
t5oOnNSW3UugYN+ariLFmkP8CfYyEjfl4m9pP0PSSUtSpSIVCFhAcx1cRw8T
MgBqm9xs04qq5Un4jOYaS8ZcyODoeTPiKdG1xCGjWejYo4tPFAQh9txbiRq4
6o6JUSRS5SDFJpYKX4PNJsL/I0rfMJ0AA5WqEkuk9R84KUz74FeHsHHwNCFC
aU2VipVyQSoV87nftF+lTCZTKhWL2Vy2TET+Fi2rD7NCkMyRunpsJAM7Dtef
SuqjKMQTvvxCD9+ETB/6jHXJlm6LmSjwOlw/RcrAQOnAz+jkMexBRD/TrGee
7rB06DWPdHkhrq1WUTPF7VwXCzKEnhjh0oAdvAqmeUtZ6dHQC/wYMLefso54
rAuF4tMTY4QgvcGRnGgurA0WrcISipTHLcoap0avjnfJ6Gp8iznKAh/ScENb
Y6OdG8qmYMnWKdJWQpEhjpALSRVxstHIGUm48WTT9Yzo5rHGTooqVNGmwuVN
edN0RhL9V8WOqeASRe6LQcUpKvCrOGVsJuJcAQNDcxjMebVjTRxOGb8TDXEp
RrpEhxZTG5sufYmKmNvAtGlvPZCLsnmItZs+a17Iww3S+b+A3E7ZXhrFQLpQ
yhfyhdRsMiMw/BoagELTBaEShxA8paKivSylMduDP/hSgxsDooIjinefcEnV
08xINA9rJEyFpcDHlFOKmUYWJ7EpZkoiiE2usICVtZGjLN1KpQCcJaVUXmyG
q4ZUyg+1t3iEEJ9w+YQpj1g+CVaxOAK/SxZhLWYoA0C6Yk9VWQQzdceqbBC5
0wcyb5RIukDfkK6a4+hMtbB0QtdEU3Ym8K8pbdAJc6beyhO9lfw21wyMMM1j
G2SDTo7xphpRoee4KXrGt35aLmctvVLJbNIXk2ajwgmR5M/oQ0KTUzWdT4Og
kzLZbEjNCBxtxMxxJOaTogc82z9d9u5Gq8x113g95Yvgjcey6TnyxrjBY44z
TGEX+6A4sHQmzvCWGlSCXF3gNqC0SdKA+JeiWx6Qa2GJK/CAHYxk+SoEPduR
Fkdnd9+CGb4Db6TDdyl0HHEit8oyfjiEYzgzS3OjBaoOtaDzOJn9hnRY21fJ
FipSNVMAjq7VxUJGKoi1aq4h1qRcvlTLFRrFcp4g6vJ8KcQXj5YNn6cmXsDK
6Q2pyk/I8AQGtBzIURHryURMO96tAfgMrIm3ISrgCd81aSmTL5SLhUouP5Cy
2Uwmn5G40XGNrgDtBkJO1dxYwXj4LKXZnNl2KYG45geRWhkVs1lJzBYVWSxl
KzmxwlhFLBQKpWFOyQzLo/LGdrzQutfC/fXlengdHNn5jFsmwZ6MGwSB0vHb
yXBUcJl9YQIaLqWy+YbSw0fEv0562ileW5dv10v6AJQCEDdCRfo7RVEWWUuB
MCMcglUC2okYCoprRsTB4WqDagF36m3fWES/mkZvYZo0iyyiOkyNscCUeWkH
M7Spi+pvrx6zV7/G+Zm+R9skpUe+jzc5UDRb0eF3epyOR79+CeETJAVwsnUw
gqOmYuQhrUg2nymX3t28FtXUC7B1RIxermvHMQpuooUsm2C+wbt2+Bs3Es0X
EO2habZRzUw/Umkx9hJ6R3Ux7DZFsEaw+U1AOqKf/Cek+lQNz6DTxdKGqFQc
1YybDCl8RN8smLbUzEE+mysVpUo2HVwnOJBymUoRLM21JrNACbpE1ogEiDwM
CvG3cQZnIS4DfDYBD3/KlUrfs6eaMwFMwdlR0Y4Bba/JUZs+8piGmchDrOnH
wjQNtmmcX3fgoCkgb97klTYSp7KurSybW3TydBi1Z+lP7idFbBvNjIh3kP+w
2pque05g6nyTVfALFOG9cuM/iFzysPQCdDD4mWBIjUDbEDiwTtG3YeD4yQwI
A9PAvUYBevobVNvYBjgytnt0qEGDOGZgcaeLlWJFypcKnNU6XU93NXA6okWU
hv+MqxVfrDATGFwJyybxLjhwRw9528TAVLtdS4W1z6tglzsK0gWvRYTH+vw+
VqZ0zB3hdaQvCN5R+1HuvnbBBJExHidP4/RDTQFDmqGOdtIGf3cmTwe7rFU8
znvnvGJse46btpQvVfJSoZArlXNF4PxMMS++itU8X8pbS7W1sSXUbKCR9SE2
tj2kFwdgxXDhELRp5TKT3G/kGdMSkTygAql+gbAolLOgv3LFYhHQKWTFx0y1
wLGo4enXtQ3O1Wbbiy04DOFl0Bn0spjPF6S8lB1YnGexEtglS2SXcbPGJl8p
SeVsJQ9OZj6fERcjLRc4gZYNSwY+JhB1xPYgBKaJQ++keRpMSPU0WLdpzmL+
vZL/6gi1XufgYP1nk6nEZVeYm8+Lq7Y6uF9rGL9xZMMVRn/7D1vooQFrTxie
GptYWxP9zOEBpilvu7PBfEJdtsG4F9qa7h5j0yKPUkCwVhZMqClz8DyUB+EA
12P4Slf/2YItJ/zMul6Pp5v4RVZ+KwAKPPPWRpRgrYG1iXcarIWcf3iM/wib
N2GQCmPNFBvGODQsS2Sbh9dQYNhrylYHsI6y3w2QuUrqmIflME+EehXwOB7P
d6nX/QEBb5uNMF6GuSZbexHxY6/N9gd+QB5Le/Cur3XeN5b61ymSx2ME/JwZ
QWO/XoWFj3cGKMOGqDMGGp0HE/xut4nitJS/kcaLckMJGitz8yOd4Vt+Yk2E
R93I1TjD1UbXqPDmjaDuLbhDhwLhiHTwCxo7/mUpQXQ1igcNux22H7qM4ODn
M/igNVuwFmbsVJwjIPOSMl/yUA/r9wc522LKMTSDAix+XMGPA5CBAIOF8PXo
iC0V3cPUhqOj+Pvw/RFVeR4F6S2HvNdAgqvOaqWm1HgZ2C9OuZM5H+dW9Vnu
Vp5lHtlp+rONKz8EdJgQKfn0vqLeNS23evPWNtVpNvdaUxa1fk52kiG1D1BS
pHLteeZUckaPznxVc/VidfxUfhF77ba2SIbUPkBJkSpcnBW1ijO3DHMyW123
H67ZS7c06hqPN8mQ2gcoKVL3g6fX1t1TbnS6kJuLxWpUrTScyazN3EwypPYB
SorUWXOgLIx2+3Ronw0eCvfF1SlzHx5MTcsnQ2ofoKRIXQ/qT/2VMs6ct0rK
8Fz2mlVxej9+zL5YyZDaBygpUs9nL2ePs6fFc8Gs3xtvg4d887z4qDVPnxJS
ah+gpEjlHSt3sWxfXT22e9LCnE88iz08jFm9PU2G1D5ASZG6KZ4ZSqE8zyiS
3rjPeS+dp0z1cWCNWtVkSO0DlBQpM99lhZvr+nwxWSqnZ6b6wK5X4H0qVkKe
2gcoKVJDdvt2eTlfdLXR9HZ0dj1aMqVltWf9RkKJvg9QAqSUEfx1V3hqqxVJ
f3rRXut9t1J7Xt03Lpvsbtb9NFIfAkqs+5p1K1/r3jZ6dytzflmp3pzJ7vWL
+SiPE+q+PYCSIrUYDp6cSvdZrXgVq5utTcWyOy+N5o+thEjtA5QUKWteHokl
5fn8vHD7LHaNF6XYmdz3amIzoUjYBygpUlnvzpMbUmM1frlsdPOt/kC0n4aL
vnaWEKl9gJIiNavlKvLwUrqx2/lBtd8dnJbK8+V131smRGofoMS6b3leX3bb
TOxVtduKN7m60nX7PG/cVROqmX2AkiLVl5be7K62eH06rfXa9f7juNd+fHbV
17dyMqT2AUqK1OR2kS82F2PjXtUqo9dnIzt6OR/q5qCTUM3sA5QUqbtWaXU6
mOrGbW95ucq2H4ujN69pmY2XzwvPDwEl3n2TGevoKmuOTotW5bV4UbmfuplM
tX6ekFL7ACVFaqxktZfMfGixSW8gzqWM2Lt09KX8XE9oDu8DlFh4XuWN6ui1
0D57nrmNxqXdM9XSW0N9lBIy+j5ASZF69M6Uwer07Lre7XhPyjx71S09Nqzx
bf0uGVL7ACW2p+7bujlsdk4nonJ9w7pe4/7qdVl4mj8kdLH2AUqK1PL+Llcv
vd5dmWNFm5Vq+eerQvfsrl95TKiQ9wFKipQ0rivXC7F0ac0at29vtbdqTm12
xlbuNqGRtw9QUqTcsmwN32q5Ul5/0C7e7Hv76vapNG09rRIu3z5ASZEycner
WvHx4uZtKXsKezkdWOVrMy95vU4ypPYBSiynXtuvynB4PpcHVutUfDltPHvZ
fG48EhMq5H2AErtYjfJNTXq4vxBd69Kat26y/WmxYRjsNKGa2QcoKVLzx8vs
TBs9F1qPSl1aXix6o4u6eac07xIGzfYBSopUt9V81MxhufDYky+mry+104lR
e66XrpWEPLUPUFKkXpzKfSd/XSuvnozJOHs1lJ9rkpzNji4S8tQ+QEmRyty+
Xd2+PQ7uVf2pcHcz6D50jeWzbtovCeXUPkBJkXrIddtSDZy1oSE93F0vWzfa
RO4o0ls/oY2+D1Bie2ogt1a60WxbF8brZalWU57urbZoXyb2ZvYASopUqffU
82rl3LlhV17rQ+lealbyZuUhl0toJewDlJineg+jcfbp8rR65Z7dlJ6dkbTU
81di9Sph1GUfoMQK2RhdLsThonzuqGdDPe/IF5VK8y2vMSWhQt4DKHF0eKWN
WuW364K8sOzhoCdd3laap3enjw9Jo8N7ACVFqv60mHdLhbei3e+o2Wru+Xn+
fGa0l1daQntqH6AESHkjA/7MVpbN58dCPW/1WtPZc3X+2B+Uni4esvefX7+P
ISWllSe1l08PFeVsdD/TcvVR5TVTZJPF7KmVUPvtA5QUqV5rUM1kpKIsnnfN
x+q05Xbvltb02XhJyOr7ACU+MlqUxKuHbL16b2fEm9pbpcSq3WVtYHYTquR9
gBI77uZqqMij+U22IXYmd6P+fTZbfrhpXk4S+sj7ACVFyjbuL1lz+CIvs0U9
J5mFmea2O8urm2lCRbMPUFKkGuPJmdrKrZzhdfO8e8PKytub6Cqd7mtCSbUP
UGJKPV/IiqZmF+apK58tekOt0xm5uX6mmZCn9gFKitRgelq7alw6/YeXsawO
C0tTfykX1flESWhR7QOUFKnX69xjPdOV7Wazmut1h7XZw8OZu6zWLxMy+j5A
SZGaTl9uJlp+NT8baNXFk329kBS7ORENMSFP7QOU2J+pTdVz9/yt7+abFel+
Zo/OO6Y6NvrZhMbLPkBJkWp73qDa9CSp1rfV5XmuU54Yi+zLy6yc0HHfByh5
2MzUrOW0NhjcPHfmk6ZZMOWH4kvn8S2hnbAPUFKktAenXq/q5adncXbVr5Yc
7fKu5Yx0rZ2QUvsAJUVKbLeu724L9bl3/6BcVce5ktJbLqxq30jI6PsAJUXq
wrx4Oi0NWzdXRn15//hadFztyj1fKFJCObUPUGKeGgw7Z5MrtZZ/kcYZU3lb
Xj8vmo9u3Uoait0DKPGZwyr/en9zdtO6LWfFoTO9Gdy1OkWN6dJTwjOHPYAS
21NnOWfw1DRHlc5NudSfZxXpNT/KFZfnCRl9H6DEiSUP592nJ+mpJZ1mtd6g
vbrJ2w3jymm0EuYF7QOU2Eo4l8xGjy2qw/uLwYJdzSrlqfn0rIyLCRl9H6DE
IY4X7y0z6ryU3ZcnS7kztOfnR6W3WDTbCSm1D1Bix+FJu8+fP1/a2YzNijfT
lrF66OVm1y5LaCXsA5Q4BedpvDQkbegWZ3n1orRsSk+Xqp557M0SejP7ACVF
qnhxPr6aZbNPt8tW/2koamJtqXVbb92HhLG8fYAO/XJ7bIFy42FFI1281KFu
MrZ7LIwAMDWYEl6Dn3luJyWz2rLm8OTbzesW4AMqRLbpwjBsSIKdEShf8gEb
LWzvj+e3xvvKa2aE/21vx0JsFKepwVVmn+2Z53/1G7Vnw9RdbAikmR41som2
IXKCHGfqwoEFjNRQCntoOMcCthiCV46OIu3ENzsdHh3RPI6OduD14gFBRxpT
fxPuAsj+fXEmE/Hi3Njr2CZwuC7/x7xZi7okRt6xsd5c0AzqJOAyrI2g203q
FnZkpFdO4V1qdUZJ1XgT/An11f5GOdOYzbxR8RnlKuCGtKb6vef8NqDAYyJf
sDneTwTLkMlTlQ/2OKAyp6KYPUwFK+/nWQftHLFnDk0DOEIbm9RNzeH0s7f0
gQsawW12gvtKNSIAG1v74R3BPrX8wkSmHv5GvRpVv7Pg0RGvn+Sp1ny89fjU
PoMuXcFFwB4qnkFZ47z70SZs7ByGLUd+KhHzqWwqT2RsA+8FJSHUD4cW3U/t
pm0FOANpTP8CZGzGoplzS58HTTXf3Q3ymw+WerDJAtFmhW/bwEPU1EvGvvhj
xvtKYJEbvwVOuO50Gjw9u97uXA/gj98oTz1S7IO30WAVP9J4nb5+QEnZkWIf
P1V9BjsUm2ioeDkSVTbYRpB0/i7/e3vC90fdnPj9glqkEGSBraCGQUsq6lnO
M9FnNlbkYk0av5CWp43zLP34zRl1v9NOeHkdQAyajgXd4oivqDkOYo3yIZCC
n5IYMGANL0QQsDoQby2hFkREAGaq2G9xnc8eu+yFy43wimy6uc1nFGodtr7H
KgAUJtbTHRJ72rU5lu7x1j4CaA2uAzxQScf80mzYMZbftgSvrqLiNBvZdssd
fiRjdW3KqDXhxkUUiCbO1MLrlXwgMNF1x0e/kR62HOKSnskOtkgaMiEstxiu
4l0/w/4oKeEU24qxJQgPB1VepBqNKjuwmRks0P5JwDswgrIaAp8E3yP7Yu0A
1jr5DZyAjRDTzSstj9fdhKgcJhgZ2+oamoObwTZpeqgn6FYab+jqW1voCKew
+ApVvMS5EmTgV36NORHCm1EZDm0kvLI86NvJxUWEjYJ9ii0c/foIYQh8jPOh
gjBeXNL1W0SDQgOxJvSoRfQx2Be2Jhuw7UDjySP5WOh7lgESu+rZ8Me9hvvd
0eW50PCGbDW1joUzrH/Fz5hwJitge4At0rPM8dASat6xUJ8wc7wE5NqeHFTz
tGVrgQVl8NYh8RPzaRCVMbLGhcmHfXLW14hSxxzqOBYykC/5I1fKfY8UCtre
brvjbWd7H790xu+oua8V6PpWNy7Kol+tL/r0b7z0Ocq3jmj0oI/cu55JQTkQ
WYTBu4gaztCWZxrWNPnyaj1HusFDpS5j4WaNXugaVj9RE1as9Bb6IOk0E1bs
LSR50J8XBLZKbegIOu2qoBo0HGqrxgjgUP3SGj+EYONd72xOZVkIBhtIya68
vlKLHvnX1ArxL/0h8S28MwEvqQl70eHUPAP7zgWPqQQQRqcbSAJNjhemYHn2
up/3/fblr/qbNPIGSIEGCnrnoG/55pUTWt6RfrKRhri4htS0CviRWrmuyYlk
oO3sl4vv40V5jUxEXJPW2Wwgva298PEnuzYf7+0yDULWQdOeLnHV6TYxJ+yp
xagYMuhzaZKFaGMRYsgxyHpycCHiRKabxbDdBj4M4NAaOh+Ivy13ktK4odWT
EiI32SD5vmI/RracyOgLYGN4jdbtkNr+2rzDLm8rvH7gt7sm6nNzMngn+BPe
oHo24lLSj2jHkRKdbq7aJ+5LRPoETZzX8oRbFhFJOvKvava32IY1wjHEsnXs
8kxu5204pbAlWmTaf+JNPKiW3XQbLYM/hHtmeniZTANW8KuDFxaEmwdvSxBB
/+78J94pfgF+3hJWgO5vdqL1m1hfGWmrMVNS2GYUjD76VzqboesRrm157MHW
qb9hZyoZnhTEknClgG5CAPC3o6NHeiwgWhYftFXNt9qClMeWkjqjK5S7nCfj
LsJYzo8n5CPwMfELcca/oNHBXR3LM7SL/hCyZTA8Z66Y/Wj0aAFppHcLMKyT
GlvW2K/jV7UU6D+Qc7KU0tw0cyxbUxwqMcahb8FUPxY6LohqvKM6L0p8/I2R
aUhqME4Xv3VM2GiaEWxBXEDNdj26+rpfq26DEMP9tnPVF3qeAdtrE396CILA
ckXLIaKFuLZgRbHd+rHQxDJ6opaYp8EYrns44regMeHHcKmbBmhPUHC2s+Me
jMPjbXNooAIJfYQHbOPZc0GPGMLXRu+hd7iLBzBaMnDozTRvjBXUfR8KfuvQ
by3dGgIxwdHQaKK4TVsweQOWjltEoK+A7b4SC+4c6jC2MNk86Jfxmkh8TvFv
A4MKS6+p60ekajmdl3KFYqVQKgzwsnIxuFV3sKHMBpo5aJK9Pmh1moMGQ+97
AFMY+PcFqoP+RW+w7e6FTe0AlP9GJF9j6TmZ7IINU2+WZaQ8bEijpMnlTd9V
zVxZUpkmi3L30nhptSfd16WlKFJbWTVLU+dClxk7Z6PlVX7Yq2eN9vXb4vrm
+qnFsqr5fJt6G+nsqW4YLuwha3DZ4ze1xMrMqx3hmmv+Hrq9/nYX/iJ8o80h
RVk5Fh3wd0pa8nn5XmOmCRZyFbSDTQInKwlnHvZpDdYHDYbPhgMBLJINlD5z
0pY6VgdLY/Jy86jdDuSLJ/XVvZ83zlgzj7z8PQufqRTyWakyCG6sGdy2BlHC
DML6e77QY2ovO6h2OA3p3pafQqTNuWy9VCEKF0MbAEt30vxTER5y7vNvbBHX
3WfRuqT7QMRMJjVTR1vYcQUuv5casnRzWGi/TSRjJp3+5v6al8oVPvVwzgL2
oMRO2fAfs9lKaIMBF6GDNtXWCDMzhjN2qpRBrZv0XwhjB3UyUeogedrBl8GN
6ElH/GWjeRhdgVAqiBvuD/ZCQOogbv+VSW3ut5Ctft62e0ez795395Xa+fPZ
oNGaPl+ruvlSk+/YSvcmw9ebf9C+a1vubbP+Q+gkVTbp9GO23sRy7ZEiYrsi
WZQKOxt9mqroNyKJdZLMZPZuykb74VZ7WZ47FmzKXLZc2LYpiQs/IEzIrU6a
sA6Z97PU+nvvxB+0OsHotEDqtsE2OsF+sCKt29eV3eicjk8XsCJSLp859G3L
69Y/NZ9qbDb2uTSzlejJ6DAuvw48qTJ/fJuiushn8j5noiHpTKxZnADRXmCO
KSsTV1RBdGCHPpXhTWxjGwxXvx2mbDoavLGrw5pUKOA+AGI3OAihp2jkK13S
Xehxg/zj0RnfBAEwEKlFWAK8wyJcgg218HMmROS78lx4ujEHix6KqoqwN3At
RHF9h2rsS9q4UxfbVWHvR79xPDZ829cJEORyXKjJXEiLMli9FHFy0j7yO1Tf
VkeJe7HYUMtbjqgXNcXlkJd3Ne8iMDDW1/UlDMOVcAbLAJ4G+s3ki8omd6+w
/fKxcNerIpVyIngPcULhUdZmS6sPtJlULoALUR70MC4FvpX2Rr8MrFHMNdhO
jTD6WQ9Duu+87ejMlfAL3xcChq9jFz3hUqaAzJrAzZB+8ekopjLClotxPyqX
EaozW9P3iJhP0SJfyVeyg1vkJZw+8hK6ThttpgbVve7Qezco506eJ86tJtae
zy7E1uuLuWi9TUqaOdRd77yjz+5fXrv6w6z4cKt2+8/F4nN5JpafXmSZXY2G
k8dU3WoXn2reVD735Mx46mLInZ9DagZiYsyETOYkWzrJZPj90J0m3vuAOo1u
qqG7KP4ShEeIVMEp9RbZshkckfF93DD4vhj6/l283Aec3mOhLpuyKgtf53xB
8EepFFuR71uQrJQrFqXMoI8dwtDS8l8fnJowlGViyGvQvz0dXM2YOeh54CTu
E/DndsVazqSRamZQ0WXKOXybX/iwiwLh1VOy/Y4Koq+hRA4iEBmXsD97KwM2
o4aBaBNNPqFvzTBQ4Id3A+lujSJd8eC1ngU7bSP6Yjni3CJcqFN4GqwzeLax
AaTiJrm3xFt2QKIF5XGVbVZK5DMuG9MjDXte80baefp3Ji8VBxz/f8lm/iVb
lv4lW9nhnn0GDU7I69O+WL+65P3YpBNBKmBYjzfBFE6DJpj+RR94PoI8Pedh
0PV4I3AfmZsaa6gvMLxswoaBfYeWRQGjftu7ahJA3hXd5Ckwfwjnsq07tjcB
ket3PSTSiz+E2VH6FDJZitOAF1H1j2reSeLj75Xz2VKu/BH0Aci4d7oAJCAw
7QDtQH9lWv1uk4c5T4SqaSIPBg6gfzz30BK+8LHgF2rCjLwfMPuXNe5j1xhR
7DPl8E3hoMYg9vBNjt/w1ohfGa3Ahfcm9vDYDf7pzZlnRwOPeRGI35Xt/6oW
KORKUiGZFuBucvM2ajAXPjSY+W3VvQkz3+D/8aAVm1nGxGjlgwl9YDkXtlnO
4NGN7KCRfmAy7beNO6Pz8fCqlL9w8yA6i5lCfmsU6XNT/kojfzj10k+ZOsWV
wgbQwYHoB9OfPJbAQjydXpbQRSqWiv7sMfJhvIt8/JCF/69zciaXL+Vzpdzu
SEUQk6BLVP/O+H/f6tHlq35z93DtrNG6hTRTsV/z/tU8extdzIbmRM9UMQQh
SaUdoZkfQojCTyFELEbjEyQ8fl9nOvG/dntC+wl15V5ZpUtrrDnI9rmCFHjE
AX2+L1ZT2IjV7CVfXnxHwe+L2xQicZsf7S1+R3Rn17puRHcSYbp/NYvZaqH8
2pYq3Q6sZjZbygRe3fuD9Ih+3nlT4oYFmhGabLiHzz+8294HH1jVDh4EDjHY
a0ZIFeQ8UcoTz3jimtpX1C1wBMgizUr8fODf3hEEGZSIMuTHsQvZVSa/zX/V
1NfFMDNp6hPnv2FmwK/XF8Zoenem5Cped/LsXLaM2VJ8bYhe3bpZdcd6Z/bf
0I0oSk50W2w7jf0kV2j8K+5c2LILaklKO/x6sjT+HSd55QOKJx/rHUtue8sX
OsSZa+vho8OY8d3tU1FS77VrijKCajoU9oVYIga85ajMWJ8PO5iv6uksTXPb
EVoBwaKyOQhEA09wvzWveo3T7oZrtQkYqVsDV9NhunMs1Jg+RgfuDyEnCWey
KUob5H7vYe3ElPvRrXarWeuGusoFMm8THJtQ/OQIIjXlkTvbIHEo6WwRdH6W
O2XZjDQoZrwKy5g7Vof+TG0O6KnFrFTYMkhKnkupBRsaP1JwZEtI3X+44OBG
EhhFRDopW9ohPUKGvs7k3YszpbccdX/7vLjI5/I/VOrm/imI5xNNyn1ENKVn
158vV1ZpME5ANArV/EiqFYUGU4hqhY+otnk9cGI61fgZ9mB9+SpSqyBlpeJH
1FoMuvZLl7VX1+UE1CpUfiixsp+n1Q/mMIrqhYVSPtUy2Y+oJhXl1rNoPWtq
Eh7LVrJkD/31RHA1V2e/fonmigaJiWydMxrLwkyQp/nlzwOekFf18wfDdLww
vxBvKaU8e9jbnmyv1smiYRYlr6fw827/KdJCKUeeF7pgHmxw40B4eXgk7duy
/Xx7nlpp8dI2gW6WNrFcAng1fqX4Jp3phoLZDEuusIRlZmMBVixrGgfhl7OP
WJg1rtlYVmbjhcS/4BKQxbbDdTk8EAS8MhIjHA+RffOZxoM5drNsvtw0zy4U
JrOinh9cjh9Nw2k8BWDJSvw8WDS90sXx8HWZeXwqPzzZ7Vx3mZ9flc2s6J2P
Q7B4t8bnoaLdUNZXr+1JZVUaXMyLQ0l7nMzuXp/sWaabCYBSeODzUNFHT/et
uauXFuP52+LsoZ/tZJ8X5sTqXJlPNyFlq9XPk1WWx+mX2vP9tPS06i1mcvN1
pVZHy4dcbnr5fB3O/xoNMl6LESsMQTnw2bFmAQwxVlySVouFh2u5nnkYPt8u
lv2aopv96ajUM6hzIw5PuR5Zcg95bvE3d2IzWZU+O7S8BpD2hm8l77HuiOLT
m9d7WD1eXjrGw2jg9m4wLRE2gA89+z3Ql+3JS7WSH70xtXh12Zlf344X/b74
cGtUA1o2et16IsKphqOkb+pZWe0oT9Ol1tdN7VRRSuPxtFysVcNF2hI02A94
HS647thn2avBzatyeVc1ux1zcD/JZjvGQ1cJoEfzf358zlAoOG7fCQ47Jjju
mt3b1kliDuAtrZ4fzjNet1vJXqkL/Xo4fqzNb6qzxowVvnftfbi3k9uSJbXt
h+Wo1RiNb8+6t8XCbW3aOPXRphh2UqSpUfzlcNnuLCrtwXLWexqOR1cDs6Tf
d5rswflOnD/Rf54zaufy9tOSBGyx9KB8cZq79aTlo1ScjFtnC3vV7d8ubi25
ul5hMFt2nWL7PiadQ/ONHzeyti07biS8ZW8HnHE6omrTLp4WpiWplM2UpFxu
F/kSwfSv1knnwAMhpPvV+nchChb/GsFKLitVvh/BCKxsJlMslwuZcAGu6tfx
HYbViPx7Ftlo8Fp4rgTz8acZmZClzERZ1/lFyw4fFz4Sg49ikylJRfSTfSjZ
xFAoPDdYHxJhGhKfWwUv+1qDzv0w0PlyroyRWVoCH3r+h0EvZPPFXAEWpTMS
wMSmoqZICSsWY81l0He46/AYhPQeVX2DzeoXzXJjlRed8fIVv+aKjLFjYcbL
dHSGVf80ApVrCZ3qZfVdUWU/VuOLV32ZFn+T18FhSeYBVqEMQWsglKoSFGJR
8ATMbZNqUpj665cR+B4MLPL4O7wyG8uNTIb1erKNta1YgLqKFxV2+KVYWtAX
IWqMj3iCBhbfMaYiMrRCWA3oUUQPZz/ydKpcNKgW0C+8fleq6l+VxksXVV4h
PsPiCrJxg7rjVEAbvwiZSv4dXlAX+C90rzEv9+dHRwJdfba+mQ1rriKFxYIT
ucyLXwlIvSWczcu8Tqi6b6E5E7+UjS7hQ0fAr4giQ50pGheSvp+0rpr0zXUt
9Az8cjqsH3PcdT+LHniJK+Ec2UEWrjRThmcNW3amlv+vuaYcHBwdbbsZ7uhI
2HVlHMeemBVrojl+WL+FOCiWGPGwiPQ7AUUmMpd1jxwxTHuytSGv3KZZvC/C
hYfvq3AJK2qNMIb5IrMgA4asyrbQUDPpPlfkqzWncX9pwvQZPg9KnS1z5ywI
yVNbU7CzAHCejmQ+8yaW0AQq/O3/NeFPwHQKu/XWU1f8r2jRMTyp2R5szBq4
yzBVF5fOBSYUzvEeQxv+7L/ImO/XBj7h34NWEPoTy3AsBP8EviLM6UyTzTH8
eQ3ery5calPLtGCrwJM6iIyV8KDp/P2qaZkrAxuLRKuwgmp0G8dowIJaQhes
A9hDxCgwKWti4kWd3t/+b8DBdR0OrQaSERisLesMW2kwqgXvubI3xIkEpdHY
x2FdBy28/x+iGSueDslw4eGSn3vg0coroToxQPad/+0//vb//O0/pvBDx5Ax
B3RiW8qURpxNNEwbmhgaG9NU5itVuJrKGpHXJAaqouyVgfMeLEsFAPCo9bf/
z0ZIDJZB5WQHadCTXWI4eeoN+cphnZ5rLZyptl6LJhamAg9MiPzAwSDBGnSh
OSLAhiCZLZ2taLcFN0nWbQ0kFt9oDZH/lWh38bYuVOZvr9Z7bQ3rcxvsPTtG
iuB/zrYKpDyN37FMzwVWm4DFw+Ttm1skbgecmjzusmXLtbGviCP0HWVijZip
4dI/yTZamRM2GtGCXsgeL6u8AH0zBN5Gjm1ptqZOQH53AcWVbBAjAgVB16PW
huV0ic/PLFOmbg9ta4UsAo9u8X5eWxVqMjC9g6trsxFoBlpU/p/+im6rdX0n
0YV1Jiwv7A3vmaRuNKSrshn8b4xdSKmcnyOn8SZGkTFDq4IiYdQhILyrOBgi
aK0Q9AIJ9cY58PQEeG8Fc63B/MbyXDa3SalLEA6GcG4NmQaLjNNvMQw9gfZY
36NMto8T1AZiEOlYQI/wGIuSeZiMp1ryZhwBe/LsXl72TyQKDAOsniBQpJ9T
QlXYXqm8BkV9IxzhG15Y+w/Io/9lBkbmr1LpEIyOrW0oELkRVrzTlHm2XNim
JpLdK3z90mCeiydlpFuUiWeOHbyEVvNT0VNfDg/+f/AhVbQB7gAA

-->

</rfc>
