<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-18" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-18"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="01"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 139?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 143?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs and finders</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">3 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">2</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of <em>paper</em> authors):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>?</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, and Haowen Song) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">TBA Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 669?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8192XLryJLYu74CcTpm5kgWSII7z0S7m4u4SKI2UusJBxsE
iiRELBQWLrrdE37xm3/AEXb40eEf8NO83T+ZL3FmFgACFEkJ557T996Y6W6B
QFZWVlZulZkliuKBq7k6+yJ86piuLYsT2VSdiTxlwmd5Kgsnsq2vDoWq6zLH
lV3NMoW6ZTqaymymCm3ZNkaeLnyu352I2Uy2KOZyxUpJsEZC/a7XE0qpggDw
BIfNmS3rguVOmA0/nTj4ijcTXEtgyxlTXABGX1RSZXiuWIZmjg8/HcjDoc3m
W5Dbj9CnA0V22diyV18EzRxZBweqpZiyAdNUbXnkilocnDiSNV2UygeONzQ0
xwGo7moGb3dO+k1B+EmQdccCLDRTZTMG/zDdT8fCJ6ZqrmVrso5/dKo1+Jdl
w3/d9JufDkzPGDL7y4EKmHw5UABHZjqe80UYATB2AJPKHQBgm8lfhOrNSfVg
YdnTsW15sy9C76TaP5iyFTxSvxwIolDtCPIYRnXwj01ayGta4M/xtTiYM9MD
BH4SBB/4fQv/4PO7hzGB0kILf8LHBhACX/mVLWVjprMULAU+l21l8kWYuO7M
+ZJOR35MAzgArbkTbwgUMryJbBiyKnqObMiiI9uqbKe3kfsTfKbLiDl8FgDe
+nmKQ09p1lZA6d1Lmpq4Bgx0IHvuxLKRkjCoIACH6JwbPnX9AYVbHFDo0YCf
6C3LHsum9kp0/SL0b4WGzRxY+mOhxWxDNlf0FuMUCyc+IMxTHPNfXU9U+Vcp
lX3aMv6dJisT5ujyXGh4Q7aaWtsGr1s2u2fynMWGxK/kX1X+Ga7FtgF6ljke
WkLN2wa3B+QaT2RNaHmyKVRNYK2RBXOjbdVnysS0dGu8gvFTx8K5q8I/6xPN
lGNoDHWPqdbYhDF/HeOzXajUJ8wcLzVTaMNo4234dNb7KzaE7NnI4fb7Y7Rl
a8FMAWf9wyY8AbKbUjZTyBTy+f3onMkrkKG2osG4W/FZaK4yiUGfwicpxj/5
1aHfU8pkG/CuDJLK0HRNNmGBbW0MmKratmGu2h3xsnvSqsZGmk00y2BjOWV7
pqsZbP9UOsDyQk+Z2JYy3TbGSbdz3qkKV7blWoqlHwNplVRsPJfJxq+MEJ75
b6VkwPfA5EswBzElbEq3FO7jLwRnh6KiNzZV0OEXoQ0EEUnzaO4KpSKoAl9v
gKbon/f4LEg+C6eeyQT8/JgPJdtj5q4F3mKxSAELMhSDY/ggZTI3PfOGuqbQ
9NP5TDkrVaRydrCBHSI3iOM2iGGGPw40cxBgNgDMCIdQaNH/RMAelEc3Jdym
fDEV/+UuFUiQ+PNTEb45lZUXj7k7yCvabGb9GTTWV3to7Et51Ckf0iKE0w+k
VHyyPvT4ULQHvuCb/IFPvbpVt3q+WuZkEDRHmHu6CVbQUGdo9thMl1f4jqxM
4TdNBkMIpkeWEJtNmEEGE34KdoDjg9/ClcqcpQCJNOBwwxSwF37R1J83TABh
vQbZotBFJqZ1gB9Obu8a/FWpmC+X983y5KLTq/5d5sm8uZpipuaAYPRsa4b/
StPf6Q3890211e5VxTpIHUesduLc/v0nEuX7bC6OyF7W93QAOtcsnbm2k1YQ
3bTDFA83WFpW55oDFidz0jSb+Wg8Fo35cika43Fp9164XQMViAJgUG5SJLtJ
Ev6aoG21NgMqoRlogLrmGvQN0RxGxrQIRvUQlROYmgEFQe+iMGJAs8aDgBJk
pIFzMJPdSZR4UlGoemPPcb8/9fKzZU5cPGeX4nKZ/xupl/sO1FNAwcqKwmau
cDIHh8ZUmAD6fyKYGqhTZszcFTkY4By5CAKltu02ZFdGqQuulVDtNsB3uBN7
F1d/KiHtIrDhLF8Wn7P24tsIeaKOmQ7cIvZWQB/DidPzhhmWG/N0kNfAnUJq
adt2aHTqCebNfDScFc4aF89xd0988jxWxGelMBdHi9Jk98SDyQn+5OBXdPHE
YLOASeSuRL6emxPHOVX9PaOZb5y/qCOMWwqc4RHyjgtuqVBFn1FTkBH9kWMc
IYG2M/doZLTbUHCBZZbSmDsiRYMP0oYzBqrIbnqZY9fL5vN18/RcYTIr6vnB
xfjBNJzGY/qDuvlAC2xw3wBsiHVbczR4r3HZSUmZlCTlC+lcqVTJZsqpXKlc
yJVL0Re32S9EArRJ6A2kXIwydcuYeS7Ioy9CEwcHWpmyvsJXrdFOC+bCmjP0
6pFmhXetmHq9LkaWJ02z1EVnxhRRU0WFMPsWAwZ+6VrA0fJIjv/QTwGv2/jQ
ZiPAPULBTCXdu0plM1IpRbugIzZSI8txADURV1JkGOkRIzvsy4feEjP5zRdd
3Ym/UXz3jcp7b0iZ4A3YiK8clxEoX5ATqVTq4EAURUEeOqSQDw76IAspKiDI
muGgbACHA0Wq4KKPB0a7LqjMBfam5f4at5f+y+eEBtYhBbm+btgiazAft18O
j4XFRANTgaQbzEfm7LpGmwWaAfCeWAvh6IhUzNHR9oCQMKJJAvvPkDSawkCT
zMFDPkLNYnmuMJsA1yNkVD2Oc4S8ZTNgdPtYcDQcCeWgZnrAcZsCGMQLWj1g
1tvsxdNsph6/i5Csqg685Jkmw/FkewUDoCJcwnY9guFx8cDXAg3kYHhMGILo
g604XJGKC7ww4S9/2eaj/PEHrQW+KduuRiyy41WSGvA+0AZxY6I1EuE7Eb4T
+FYFUL5McC30aMG3vUM75VjwTBWkQHWGwRsxm8oI4Agy02EkggGubameonG5
fkwYTeQ5TIUxVPFT01roqGkis9LZHNYaMZmyiaUDeMdna0NTVZ0dHPxEsh8B
U6Rv5/xnSCITiResjyDPACPAFXcCzemV0bDbrRO+TvDFzHJk3TkG7MYghUiB
AdctJozCuPCPFS0QcpJvgDiKNSPWRPUmKBOgJbwJNDEtNyU0bcsArAJ1Ksxg
khj8BcEPho1JHyIUMKBheyqawxlYcS3bQXbD38BIUjWUxkJgUBqwN2TYTAYI
S8vY8tyJYrkdQ1whCk7zdwnbfoyH8DF8vp+VkrAFjQkuBPzuP4H1rsLO4LuB
zEIbNgQYckAnHDhQd9E1plUMdJ0S6jr4XaQB9qwwn+Emp8P/yXPU+2hU8QnH
1Ox3maXJDwJiM/XnCQwP3GHDM5AqfKR1UB5/hZcQZ2RvVJqWN568mYTPRypz
tLEpWDOcLtFlHzlgh/0kXILcm2tsgToEAHElEqO2PxYyLngsii/UYJabo+/h
VO79BI/340WvoiIAM0D1o230LOZKBAE10IcHv4OdkhJ+F2qbw8KzW4chU8B/
VUPW/h2+kPCDuq7BNP/jv/4Ph2CaFkr/34WvXVCV/4LG+lqlyVrKgKdk5xCi
CnCHY3m2wtIzW5ujPAWcUMIDCmKov0RQby6jpT5E0EgDZktrwN8UBUq7NmNo
rpppH+AhzSq7MasoWYPZiWs0st8bjSxHI4do0EkannZZJHFiA+e+98A5PnAe
B+4BRzOb5s8jliRfY+Pnv/f4eT5+gehvGfCQEx22xk9Z2i0/5eIoFL43CgWO
QnEPCnkcftM3Qz+B3L6tCG3a9AZj6EU46aFuDfnw4MkwPBR00l3ZnnrOjaeu
UoEvCUYtWLaKokSt29RMHR3+K5ihvk8cN0Ad0xE11wZ7vzgmHBYzEcEBU6e9
mW7JqpNGfyQtZdP3DOdpi1X02lxUrbD5+vitWL+8aHYaJxf9TvW82PKHhDHr
9ZgP2eu0PjLxQ5AHsgqSFcQJ7PNnGEr4ukeKbYW5QYZ0INHI+p9ZSkRCFL83
exQ5e5S2sscxsOfxmkdAB+51b0AnhoiWvjeiJUT0L1+4Z/vzpzdCHeyzeBzJ
IcQDW3Vtwnz64+Dg3/7t3w7uWegNyYE2gwcwcfg/cCMD6wz+AtOem9JD8AfW
Cu1gi0Kjb3crMQ/VAMI6eGNro20dQddUfdMT0TM0VxuvVR5+r2pgws3ptD9E
NRpH0ZiTEi491Jmw8cAemTPYi/Cp7AqaKxjy6gDMDzDFBRjDCWJHYMto8CZ8
ZFsYpJzNgqMdESY1AkUvfAYTnelC7jCcPp/UvmnLOpi1aGiBWYDhPRgVNIBu
wd5UD7i5FIlZofMHExMwDkhPQE8YABJtHYW0WBAfhDcCR/BgxK1qVRuNGNpN
8AlMBoftWdwQ4Z/C+P7EHc9mIUFAlIAn5joHQAUNrAE0mjhxUW2kiGUOkGlA
v88w02IIagwXQbfQlsABYmGs98wZdNQdtLC5IfKXv8TiqOiPOY4Hv8F7Lscf
3FUVPIDANea+If8aPo+74vB9JPmE23RdS2U6rtQlWZ3BDuqGzMsDBnFbH9xZ
sNxG6JYii+BaGZYat/hwUggJRlxTf9/ct+wbcAAd3L8r9EXMMf6KXAVD/gYy
wpV/A7vYlsHWAsx9J6vuswJgwHW74FtayPlN8h2Fr/J4jG6by76fPApBHlJI
AB45JCF8j1KN7l1121x3+k+wanRYoKMawaMVwNEI5uiZ/l8pfwFH3D0OkCDP
MTDHt3iFxAMUbiUTLKrFopGiuJDfHuwi7qTNxz0ari9wTVCiyrgzIucfnxF7
dDthgIV5uHWct3EuGIOC/tzX0HVrQZJzYWFujsm5BCSCv+sD+b32pMEBAGO+
RrpDmMBWo6CDN0PBrR6ARXxlgTWww+dHeRx+I6sqrCOXUlEkOdV8L03gWspf
249QULUY7X90q+YIIX6yJpObhd42vgX+MKDpC3ubueAP+7uAjwur+958QOJv
H+pYGHouwuIAj45gwhp+BwSNhqTe022AqGc+g42FJ1gq8ptQtzE3zEFfDMUb
Bg/BRGgSyuRwiaJI/3/w+zYR9ruwNS/pWHibLsTNlFMmmyKYmxoLDrAFDnoj
vvhdYW8K7u8MefNEaPcI2/DJ7nmdJGeQF7Xt41yij/u1KrpZ4TN8Yxeea0MO
B3TSlAuJH4w4b6CR9hPYCzbsHq64aLO5/IGBD5Df0IgAacCVYI8pKfBzJOTT
vVFRejHvv7aOJgHHwpgNiocDxLuYNm9wTY8WQ18zUI8ybl9yV7K6DmYaFCIB
fVYFVUjH4ndcceMuOKHt97vQwHhInP/RVtNMjeLcaxuDBTYG2SqWbwQAhExJ
uFTcYzqCIfJvoIAYhC9LeZiXEnk5mu/lmxdfMclzrSX3H3rZsuuki+PhyzLz
8Fi+f7Tbue4yP78sm1nROxs/ptFn4QdrNGqRRv3qUwstMFBnhGfEyWPDVDAi
DgZ/o0NXzGSzJamYKRTy6ag/GDmaTdnkeI7TLmPcacLQi7ICLKJUyJaEJhtG
8AmPpykg4Exgrd5uZ+Hr0VEvSO35WWh3Wm3MACLLqnx4dPRfELKf2hCFDaJu
i0hbj7QPbiGAW3wDl9JPImBQsm0VcN8I/+uaj+LLEzGbrpC8eDSMHjU4+Bi2
l8HsSrvymIe94EdxnkmVUxItQfAB16L00TbifADjCqVPfSu+Y2s3roWUJI4t
KZUtwmBvkB5b34iwlHmDMcYa4r7qN4YFVKboZBR83ZOj86H4zSbs9MzT9XSh
TNu4tDmDu/VoWyZDCRnfOCN//6vIm9k9wyayIcnuxBXl58tgeAi4YzegvwmA
vREKWzTxHgbIB3vsDcu+L3ayb/dv/abT79Sr5z78Cuwsn8GChJZEI+T+phHW
6jtUl3HnN6q0oupS3tCTqOePji6YFhylkZ2IFi//C6UoGuKyiUdhPCdaWYEH
DPrHQtQFi1utyrr4IWYkkA/x2z2Tp23Zmfx2zP+70f6NUoh+q8nqCWfd31Jg
4fbxLA+PHYVIiQP3bcCZOxa0FEsd+zB7FCIhqDQ1/wGA5jMFj3BsWarAdN8k
8E/eZF6AQPbxya2fTnhwggfiYAcKtybw7r84wlf64Z3D84llsJk8Bk8UiRTB
GTyw6NK/1Q40h7A4hSI/4crAbCMZbMFpFZrz4A2AmeoAzel77ofexaNOu3NM
hHMN3HfZBa5ADvoJXBlRmcN+chQLLB4BeCFkR0BgKKP/DGN9BUr0wZN1bU2J
iDMTCAL0cFNja55GbEX/lTQCPUwdREQG50qulX/n8wZBHIz2YZhRky1iun1d
aOCTyTMyMiMGTeRpegS7xAkfYdhZwAMqwujzV8oAjMe7NXzExaYf5Yanac9J
MzPMxBIVeM7sdNSgStOHYvhK9DfkgQIIRjFbFjMZiepC/KyNarcRH182VJ4K
ZqaDIy0nzQ813RB6egh6AkP/aXhddIZiLpPPhGDXAyPp6JjjAqMURLP+yckG
vcB6i9KKTsc2KPUGSONBtRYR/anqKVkxyH5ULS0dZk0VC+ViPp8CvZ3J5jIU
Uf8TaZ5HmmeiNMdDOTDFhXNrwWfSc2WdeRH2Xiqy6KvwSOWPw18L/j3wHJAJ
S7BZfDoFOTwFsZAvZCofz+HxP0AY+VQG3T5w3T2DI1cDiTptVnv999Ab4osj
TBYM/2tgyVMdWGwbjkWpUsomwRE/OEQMs5sYyupNtbsGNZRB6xsoI/3/wrF/
/45sLhX4SuLpXu5PJJeUlFwSoVjZQLEpD0GsTZn6Hoqj4MX1f+1nOinzAQzh
YeSDrRhuc+DjkP/ESpRDYUeAqkS7GL+PmUWbmpIneszfakolqimVUFPqoaZE
C4nijGuIfqyVn0atFfnRESADRgy6KzvjHxgWxqJQ/yRoM9cf45EGjSusmOsP
ijaVFWSduWFex3bMHWQgHtfCw54whyWS17RgeJjjwiRNnsyLD4E1HDKryTDC
3DsqkD04aHq2H+6OJ7egxaOvUVvHiGeWG1geGFVCcuwLW37ezLNZ266HlEXi
WwuhaQL6h2pa+QnLibNpFMAnWL77O+bcupRSCCa0wB9L8cc5GB3JaBs8B07F
ozULo9j8WLacKoXc5cOIMpyQ9R/lNx8VYzKJHq6Z82RdavwB+mwSRfA5Eg8m
bYz4g3Vv4Gn7SsBzIIOYC0jDjbpjYqmRhsFkrNMbY7COfkpxaxthwGdgLfOB
bIZ5R8QEEX+vEz/aPTioAvuAH+9urP2bI2CbRY4iYDnFH5bG82WbgMBtsM38
fi9wgHi+TYPYX5hAGCSOXh1/b7STJZJsKzRYT+QbPG6i3D9yMseXPyVsgyt4
dBSEU46OgCxhPIsH4L78gFAf5krwlAHf46IYe+KwGSKr2RzZsZUQ0Y/H+L4X
tgedkbCyPBI28gL/iZDNla/1956ZxeTVsTAjxAWsDPIcASctOBZX1QvKPBGU
CVOmtLzbEhHe5CGgmcE1pLEpU4MSZaEXzeF0donWILUynvLJwxp753iEJVhH
G6IYkfq44CHB/U76UQVeE5yVMbTwiGFLJs+/fiReeHQURgzBlJJHLgsDUW9Q
2HW0G0ED5/OZ9AP4hKo4Y6ZIYY1D32KS/XPWbYlHny1bG6PixPVF8wk1tZjJ
8/ASMi5mxOjIHxY8Lx4eYAFMFbNkKKn7vkUHv5qizTClfmahk6oKlueGfIbp
J5y7hsCrSTRBkHQgkxXHV3NT9xDgdYpE5M2dVV9vvqKQYI7SKZiNRFFGKQBA
oSPLtmE3AwX++OOQf+auk5XD43VcKme0ShF1KDM+ThisMKGSDyzyX4WJ21tz
ejBLBctRNJcbu2QTg93lCnNZ92jfB+kqQSUAP7X3jVcek9yfPE8TiRi2sCQc
96op+CVieEAogydAFo9vyQf5B3zSR0eqZoP+0vHcHp5TTJ3nSoBc2pFMENCO
D3d0dLujNgUH0VyH6aNoFYOCicS2Ge6SjQKl93YnjYkGDdmP0SXH1BbPDg1/
enF72cx+xED6BTlP52hnO5gg0mgLMVoIn38bL1e/HYL4xUweZ+PXIXMXmBOi
rHOPeIIYZpS0Q/EX5MphhvHn3yauowQQcQ8zU7FXsyDNci00DZzQmDkHuZRQ
XWfebUCT90KLZOxhsZ58cHDFt7rDWHBCnt17Qo4w/aIw0hi9gI5XfEFQ6nyu
w94Da4WGaeEWPFxHdMNtKfyB+XJBZJ5cTD9RC+h6U+33ggJDO1Lu5a5m5Bzt
9I1TlNgTRQBmExYKYyQbF7XHl63nL2pLOsQV2vNVJD1+vY59n/JnSPlW9hBX
5mMwousXh5I73LYmuURr0kXRe8OLw1A1VqPpZ9sKf/xaMFwbshrUbc7SO/k9
bxV4zGBNAR4byf0Tps+cMKeU541KAX74PuY8hJly6/qMbd9lo991eDrTngRW
P0n1vSxMSkwVghrASOIT+KqewQtm6CDhKpBGe//3+zqbUvhJOs4e54+L8Ye5
48Ix+vRXb2eNfvsXUdw/Qmww/+3gP8J/Y7qVJHzZx6ok5eCL//hf/90H9h//
87/F/wOhZN+BMlUmG1D4f8Wh5N6F8puwA4r/H5HoBfG+XxiJoYjNvVRKScTv
TW2M0YrCRzcWSc+AlTFXMgyThBttf01RpJJo/W1Qwbn94GhvudGPqglK/9CK
o7RujVPu0v145dEPqzqKTvQHQI9NdHtt0w+ra4pO7QdAj01tb/XUD6ucis7w
B0CPzfC9+qwfVpsVneQPgB6b5LsVYD+qwij9Q+uX4pP8UB3TDytRis70B0CP
zbSciloRMGxQqP79xg0g8mn9QPiRiW05pYjo+p/oICAMPcHiNrkidkhj7/qR
N1nCHqZ+YARMyHtsQ6CTrTjbnTlP9uExRggm6LR85T024wGg5UyOhCTR6cL2
G1Nmr/NmVUtJ7/o0fXjstzyKW64Rc7cfbfjgeGPwEV3f7QcnHx3RyWpoa+q6
WQGeK8U2wV4jGOtVdtLg8KMFDTxUtNX1J2sdrOs9DS/eQzJqo2Nlmrlae/hD
ZrKRFj+u/Hsvago5zG+iEI8KHx2tOz/4XgVMn1bzzTJGGYPeeG9aQXmb/xFy
TxWL2QzYEjADl58zYjwlEqP0T1R5Hd+6u4df0LM16vsdeMJmVMkTdynjAUgi
IrUMoTgnVhdRXE7+WJ2SmMnHcHgXXT/+xCN3wSLBH5bNjPCkOh65pZBe6oPi
57x6dsLFTw87lsrk/cLMsXBUgeHoze0kF77q2M7Xlj/MlfhI9D9KH34URXRB
CMP3w+1v+9y9DSDjKa9sTim2yjkqSMKlZV2n574fm0de3tIA7YjnVR4R8PXO
QNwYyBgV68Rsy3OCNj6AJrJ/mO14jNWf2K5inaAw0cYTTFCgc2o1kkn5LQkc
wmd0Tf2Q9Trb8Y8/cEmwqrSlzf3SKxyX9ytR/ByBdVPRjaGP8TwIhD+VBKoH
fvSbRTIICA7uMAyk49/vCNjuba9/4NljngphYG7JXjHql8S+x1TUey1L/zzY
2/hmH24UzDcwJ0QF84IyVGVqzUO1/X5VdNgcnEJk/bBVFE9R5hZC37J0DEp6
GDHYrMAOJWKIYKzxkfA1EI3rLagxRoXMNhbJMBbsQI+SAitl2ASF3GFQs72x
odclk7xlSbxKl2f9xM4NAGl+IPJ1pC2RG4F8PiBVC/6Q1z3ykh5df6hRW8R+
A1EhymnA5ZAfLVgUzWMgRD1HwDbufhEjUtp2eWoO4IRsNQIa4ZbbKHp8J1oX
nFIg7BTRx/bFMAvPQRaRiDPWuSPTAOGwPT/W1mKvMJJCVNQZntoQWMo/0IZe
tCoKN5hn+mc/YfX+P+AK+KTG00XMtj9G0vCcetgpOO0AdTDQ2RZsaQVj9XDH
Ydg40muA0pXfivlDrFPnMXzO0z4XhBtIsTxdDXKBqKrdb8TGjzfX9omzuTwp
3oLICKrXlYmlgRjnDQHQ6NNBk/O1p45uYdXwljnioh1zMRsK1jgHLghPnpDk
Gyjv9ku6sLApYqDRg3K6fzgO2b5HSZFw+WKCor3qnfET6rUqTXG5HeONLwcH
/xk7Rq6XBe0GKZU7jm3AEEYkm7+hjUYaE9tM17GVOvKV4Nd/jLD+EYSexnTV
wfoMeEebYedOkMdzRi3Y/CZU/HDu80n9sNE+8TtLYM0AU2SU7Qtue3tmzPLm
kSvgt3Vrrw2RbG/WMvGg8DpHkrhrC5FQet9PNBRErs9EQ7D9NW5wcPpu+Yyb
RG+lWHhY40fMZ+uzN+znofGK11AYgoKkvRW4Vtq6FSHgE7JovL1DuEq8S5dD
ZHL8AzoP68HdkC4mWm9A8ODcM/4zWk8z3x4GtHxWSGHSvqJT60lcBENWKWkV
nLig7xmYTmOPz95Xf+tDxoPIeeO+jgkIOuigRg3UeJvL+KeRKl9+SlB+U/4r
4KIjIsTbYCMwYzaRHe01miER2cOUgROr2EdGs8G4HfMTJBKeHpdn2LcAF8qJ
oUsN3/i81+ZKvGTlhtIiDtY/xxMSeNZEvFsdd462EiuFJ2f4MrVP8Q+QI1nT
+O1J7/KmU+9RqRfh9tNmhc9BeM6y72gl1i3ubb9R2khBq1KfhnjSrbCwc9xm
OxuOTDfshRPgsf88+x081laYfx4XgucLE57qHFRjjVE+QO+djQLPeaNAfpTL
VE0W6igGwXoNT9FNtlgXRKEFSK8BliPeShyDA8hhWPY8ZoE7FWjpHVlgvsG8
YdiQXuDOk2284yWkKIMW5cgNG2t4dB9PyaeWFfwHnkwbFFAgN6UzpXQmn456
TGLoMTki9fYSwxM1UXPEoW1NmUkGOqgw0ZBXIog5kS1hhHQhWyxmCsVDwOjz
qTyTTVjnQ+FrTQdOasvuBVCwb01XkVLUIf4EexmJm3Lxt7SfIemkJalSkQoE
LKC5Dq6jhwkZALVNbrZpRdXyJHxGc40lYy5kcPS8GfGU6FrikNEsdOx9xicK
ghB7Ga5EDVx1x8QoEqlykGITS4WvwWYT4f8Rpa+YToCBSlWJJdL6D5wUpn3w
e4jYOHiaEKG0pkrFSrkglYr53C/az1ImkymVisVsLlsmIn+NNg0Is0KQzJGu
AdigB3Ycrj81DIiiEE/48ktAfBMyfegz1gVbui1mosDrcP0UKRADpQM/o5PH
sLcT/Uyznnm6w9Kh1zzS5YW4tlpFzRS3c10syBB6YoRLA3bwKpjmDWWlR0Mv
8GPA3H7KOuKxLiGKT0+MEYL0BkdyormwNljOCksoUh63KGucGr06Xkylq/Et
5igLfEjDDW2NjXZuKJuCJVunSFsJRYY4Qi4kVcTJRiNnJOHak03XM6Kbxxo7
KapdRZsKlzflTdMZSfRfFTumgksUuXwKFaeowK/ilLGZiHMFDAzNYTDn1Y41
cThl/A4/xKUY6RIdWkxtbLr0JSpibgPTpr3xQC7K5iFWdfqseS4PN0jn/wJy
O2V7aRQD6UIpX8gXUrPJjMDwO60ACk0XhEocQvCUyo32spTGbA/+4EsNbgyI
Co4oXqTEJVVPMyPRPKyRMBWWAh9TTilmGlmcxKaYKYkgNrnCAlbWRo6ydCuV
AnCWlFJ5GRquGlIpP9Re4xFCfMLlE6Y8YmElWMXiCPwuWYS1mKEMAOmKvWpl
EczUHauyQeROH8i8UTzpAn1DumqOozPVwtIJXRNN2ZnAv6a0QSfMmXorT/RW
8utcMzDCNI9tkA06OcarakSFnuOm6Bnf+mm5nLX0SiWzSV9Mmo0KJ0SSP6MP
CU1O1XQ+DYJOymSzITUjcLQRM8eRmE+KHvBs/3TZux2tMldd4+WEL4I3Hsum
58gb4waPOc4whV3sg+LA0pk4wyuvUAlydYHbgNImSQPiX4pueUCuhSWuwAN2
MJLlqxB+i0gcnd1dGWb4DryRDt+l0HHEidwqy/jhEI7hzCzNjZauOtTaz+Nk
9hv9YdVfJVuoSNVMATi6VhcLGakg1qq5hliTcvlSLVdoFMt5gqjL86UQXzxa
NnyemngBK6c3pCo/IcMTGNByIEdFrDQTMe14twbgM7Am3oaogCd816SlTL5Q
LhYqufxAymYzmXxG4kbHFboCtBsIOVVzY6Xk4bOUZnNm26UE4pofRGplVMxm
JTFbVGSxlK3kxApjFbFQKJSGOSUzLI/KG9vxXOteCXdXF+vhdXBk5zNumQR7
Mm4QBErHb5bDUcFl9oUJaLiUyuYbSg8fEf866WmneGVdvF4t6QNQCkDcCBXp
7xRFWWQtBcKMcAhWCWgnYigorhkRB4erDaoS3Km3fWMR/WoavYVp0iyyiOow
NcbSU+alHczQpu60v7x4zF79HOdn+h5tk5Qe+T7e/kDRbEWH3+lxOh79+imE
T5AUwMnWwQiOmoqRh7Qi2XymXHpzjWNUUy/A1hExermuKscouIkWsmyC+Qbv
2uFv3Eg0n0G0h6bZRp0z/UhFx9gp6Q3VxbCXFsEaweY3AemIfvKfkOpTNTyD
ThdLG6JScVQzbjKk8BF9s2DaUjMH+WyuVJQq2XRwN+lAymUqRbA015rMAiXo
ElkjEiDyMCjR38YZnIW4DPDZBDz8KVcqfc+eas4EMAVnR0U7BrS9Jkdt+shj
GmYiD7HaHwvTNNimcX7dgYOmgLx5lVfaSJzKuraybG7RydNh1J6lP7mfFLFt
NDMi3kH+w2pruu45ganzVVbBL1CEt8qN/yByycPSC9DB4GeCITUCbUPgwDpF
34aB4yczIAxMA/caBejpb1BtYxvgyNhG06HWDeKYgcWdLlaKFSlfKnBW63Q9
3dXA6YgWURr+M65WfLHCTGBwJSybxIslwR095O0oA1PtZi0V1j6vgt0DKUgX
vBYRHuvz+1iZ0jF3hNeRviB4R21dufvaBRNExnicPI3TDzUFDGmGOtpJG/zd
mTwd7LJW8TjvjfOKse05btpSvlTJS4VCrlTOFYHzM8W8+CJW83wpbyzV1sZ4
bSXQyHoXG9se0osDsGK4cAja33KZSe438oxpiUgeUIFUv0BYFMpZ0F+5YrEI
6BSy4kOmWuBY1PD068oG52qzIcYWHIbwMugMelnM5wtSXsoOLM6zWAnskiWy
y7hZY5OvlKRytpIHJzOfz4iLkZYLnEDLhiUDHxOIOmJ7EALTxKF30jwNJqR6
GqzbNGcx/5Laf3GEWq9zcLD+s8lU4rJLzM1n/j1sWxzczzWM3ziy4Qqjv/67
LfTQgLUnDE+NTaytiX7m8ADTlDfk2WA+oS7bYNwLbU13j7GdkUcpIFgrCybU
lDl4HsqDcIDrMXylq/9owZYv/My6Xo+nm/hFVn6TAAo886ZHlGCtgbWJd0Ws
hZx/eIz/CNs6YZAKY80UG8Y4NCxLZJuH13tg2GvKVgewjrLf65C5SuqYh+Uw
T4S6GPA4Hs93qdf9AQFvm40wXoa5Jlu7FPFjr83GCH5AHkt78A61dd43NgGo
UySPxwj4OTOCxj7ICgsf7wxQho1mZww0Og8m+F2EE8VpKX8jjbduhxI0Vubm
RzrDt/zEmgiPupErh4arjX5S4Y0mQd1bcDcRBcIR6eAXNHb8S2iC6GoUDxp2
O2w/dBnBwc9n8EFrtmAtzNipOEdA5iVlvuSh3uBvD3K2xZRjaAYFWPy4gh8H
IAMBBgvh89ERWyq6h6kNR0fx9+H7I6ryPArSWw55r4EEV8jVSk2p8Tywn51y
J3M2zq3qs9yNPMs8sJP0R9tyvgvoMCFS8sldRb1tWm71+rVtqtNs7qWmLGr9
nOwkQ2ofoKRI5drzzInkjB6c+arm6sXq+LH8LPbabW2RDKl9gJIiVTg/LWoV
Z24Z5mS2umrfX7HnbmnUNR6ukyG1D1BSpO4Gjy+t28fc6GQhNxeL1ahaaTiT
WZu5mWRI7QOUFKnT5kBZGO32ydA+HdwX7oqrE+be35ualk+G1D5ASZG6GtQf
+ytlnDlrlZThmew1q+L0bvyQfbaSIbUPUFKknk6fTx9mj4unglm/M14H9/nm
WfFBa548JqTUPkBJkco7Vu582b68fGj3pIU5n3gWu78fs3p7mgypfYCSInVd
PDWUQnmeUSS9cZfznjuPmerDwBq1qsmQ2gcoKVJmvssK11f1+WKyVE5OTfWe
Xa3A+1SshDy1D1BSpIbs5vXiYr7oaqPpzej0arRkSstqz/qNhBJ9H6AESCkj
+Ou28NhWK5L++Ky91Ptupfa0umtcNNntrPthpN4FlFj3NetWvta9afRuV+b8
olK9PpXdq2fzQR4n1H17ACVFajEcPDqV7pNa8SpWN1ubimV3XhrNH1oJkdoH
KClS1rw8EkvK09lZ4eZJ7BrPSrEzuevVxGZCkbAPUFKkst6tJzekxmr8fNHo
5lv9gWg/Dhd97TQhUvsAJUVqVstV5OGFdG2384Nqvzs4KZXny6u+t0yI1D5A
iXXf8qy+7LaZ2KtqNxVvcnmp6/ZZ3ritJlQz+wAlRaovLb3ZbW3x8nhS67Xr
/Ydxr/3w5Kovr+VkSO0DlBSpyc0iX2wuxsadqlVGL09GdvR8NtTNQSehmtkH
KClSt63S6mQw1Y2b3vJilW0/FEevXtMyG88fF57vAkq8+yYz1tFV1hydFK3K
S/G8cjd1M5lq/SwhpfYBSorUWMlqz5n50GKT3kCcSxmxd+HoS/mpntAc3gco
sfC8zBvV0Uuhffo0cxuNC7tnqqXXhvogJWT0fYCSIvXgnSqD1cnpVb3b8R6V
efayW3poWOOb+m0ypPYBSmxP3bV1c9jsnExE5eqadb3G3eXLsvA4v0/oYu0D
lBSp5d1trl56ub00x4o2K9XyT5eF7ultv/KQUCHvA5QUKWlcV64WYunCmjVu
Xl9rr9Wc2uyMrdxNQiNvH6CkSLll2Rq+1nKlvH6vnb/ad/blzWNp2npcJVy+
fYCSImXkble14sP59etS9hT2fDKwyldmXvJ6nWRI7QOUWE69tF+U4fBsLg+s
1on4fNJ48rL53HgkJlTI+wAldrEa5euadH93LrrWhTVvXWf702LDMNhJQjWz
D1BSpOYPF9mZNnoqtB6UurQ8X/RG53XzVmneJgya7QOUFKluq/mgmcNy4aEn
n09fnmsnE6P2VC9dKQl5ah+gpEg9O5W7Tv6qVl49GpNx9nIoP9UkOZsdnSfk
qX2AkiKVuXm9vHl9GNyp+mPh9nrQve8ayyfdtJ8Tyql9gJIidZ/rtqUaOGtD
Q7q/vVq2rrWJ3FGk135CG30foMT21EBurXSj2bbOjZeLUq2mPN5ZbdG+SOzN
7AGUFKlS77Hn1cq5M8OuvNSH0p3UrOTNyn0ul9BK2AcoMU/17kfj7OPFSfXS
Pb0uPTkjaannL8XqZcKoyz5AiRWyMbpYiMNF+cxRT4d63pHPK5Xma15jSkKF
vAdQ4ujwShu1yq9XBXlh2cNBT7q4qTRPbk8e7pNGh/cASopU/XEx75YKr0W7
31Gz1dzT0/zp1GgvL7WE9tQ+QAmQ8kYG/JmtLJtPD4V63uq1prOn6vyhPyg9
nt9n7z6+fu9DSkorT2ovH+8ryunobqbl6qPKS6bIJovZYyuh9tsHKClSvdag
mslIRVk865oP1WnL7d4uremT8ZyQ1fcBSnxktCiJl/fZevXOzojXtddKiVW7
y9rA7CZUyfsAJXbczdVQkUfz62xD7ExuR/27bLZ8f928mCT0kfcBSoqUbdxd
sObwWV5mi3pOMgszzW13lpfX04SKZh+gpEg1xpNTtZVbOcOr5ln3mpWV11fR
VTrdl4SSah+gxJR6OpcVTc0uzBNXPl30hlqnM3Jz/UwzIU/tA5QUqcH0pHbZ
uHD6989jWR0Wlqb+XC6q84mS0KLaBygpUi9XuYd6pivbzWY11+sOa7P7+1N3
Wa1fJGT0fYCSIjWdPl9PtPxqfjrQqotH+2ohKXZzIhpiQp7aByixP1Obqmfu
2WvfzTcr0t3MHp11THVs9LMJjZd9gJIi1fa8QbXpSVKtb6vLs1ynPDEW2efn
WTmh474PUPKwmalZy2ltMLh+6swnTbNgyvfF587Da0I7YR+gpEhp9069XtXL
j0/i7LJfLTnaxW3LGelaOyGl9gFKipTYbl3d3hTqc+/uXrmsjnMlpbdcWNW+
kZDR9wFKitS5ef54Uhq2ri+N+vLu4aXouNqle7ZQpIRyah+gxDw1GHZOJ5dq
Lf8sjTOm8rq8elo0H9y6lTQUuwdQ4jOHVf7l7vr0unVTzopDZ3o9uG11ihrT
pceEZw57ACW2p05zzuCxaY4qnetyqT/PKtJLfpQrLs8SMvo+QIkTS+7Puo+P
0mNLOslqvUF7dZ23G8al02glzAvaByixlXAmmY0eW1SHd+eDBbucVcpT8/FJ
GRcTMvo+QIlDHM/ea2bUeS67z4+WcmtoT08PSm+xaLYTUmofoMSOw6N2lz97
urCzGZsVr6ctY3Xfy82uXJbQStgHKHEKzuN4aUja0C3O8up5admUHi9UPfPQ
myX0ZvYBSopU8fxsfDnLZh9vlq3+41DUxNpS67Zeu/cJY3n7AB365fbYAuXa
w4pGunipQ91kbPdYGAFgajAlvAQ/89xOSma1Zc3hybeb1y3AB1SIbNNVYtiQ
BDsjUL7kPTZa2N4fz2+N95nXzAj/aW/HQmwUp6nBJWcf7Znnf/ULtWfD1F1s
CKSZHjWyibYhcoIcZ+rCgQWM1FAKe2g4xwK2GIJXjo4i7cQ3Ox0eHdE8jo52
4PXsAUFHGlN/EW4DyP5NciYT8Urd2OvYJnC4Lv/HvFmLuiRG3rGx3lzQDOok
4DKsjaDbTeoWdmSkV07gXWp1RknVeM/9F+qr/ZVypjGbeaPiM8pVwA1pTfV7
z/ltQIHHRL5gc7yfCJYhk6cqH+xxQGVORTF7mApW3s+zDto5Ys8cmgZwhDY2
qZuaw+lnb+kDFzSC2+wE95lqRAA2tvbD24N9avmFiUw9/IV6Nap+Z8GjI14/
yVOt+Xjr8al9Bl26gouAPVQ8g7LGefejTdjYOQxbjvxQIuZT2VSeyNgG3gtK
QqgfDi26n9pN2wpwBtKY/tXI2IxFM+eWPg+aar65G+QXHyz1YJMFos0K37aB
h6ipl4x98ceM95XAIjd+C5xw1ek0eHp2vd25GsAfv1CeeqTYB2+jwSp+pPE6
ff2AkrIjxT5+qvoMdig20VDxciT/4rwg6fxN/vf2hO/3ujnxmwe1SCHIAltB
DYOWVNSznGeiz2ysyMWaNH5VLU8b51n68Zsz6n6nnfDyOoAYNB0LusURX1Fz
HMQa5UMgBT8kMWDAGl6IIGB1IN5aQi2IiADMVLHf4jqfPXbZC5cb4eXZdHOb
zyjUOmx9j1UAKEyspzsk9rRrcyzd4619BNAaXAd4oJKO+XXasGMsv20JXl1F
xWk2su2WO/xIxuralFFrwo2LKBBNnKmF1yv5QGCi646PfiM9bDnEJT2THWyR
NGRCWG4xXMW7fob9UVLCCbYVY0sQHg6qvEg1GlV2YDMzWKD9k4B3YARlNQQ+
Cb5H9sXaAax18hs4ARshppuXXR6vuwlROUwwMrbVNTQHN4Nt0vRQT9CtNN7Q
1be20BFOYPEVqniJcyXIwM/8gnMihDejMhzaSHiZedC3k4uLCBsF+xRbOPr1
EcIQ+BjnQwVhvLik67eIBoUGYk3oUYvoY7AvbE02YNuBxpNH8rHQ9ywDJHbV
s+GPOw33u6PLc6HhDdlqah0Lp1j/ip8x4VRWwPYAW6RnmeOhJdS8Y6E+YeZ4
Cci1PTmo5mnL1gILyuCtQ+In5tMgKmNkjQuTd/vkrC8YpY451HEsZCBf8keu
lPsWKRS0vd12x9vO9j5+6YzfUXNfK9D1rW5clEW/Wl/06d946XOUbx3R6EEf
uTc9k4JyILIIg3cRNZyhLc80rGny5dV6jnSDh0pdxsLNGr3qNax+oiasWOkt
9EHSaSas2GtI8qA/LwhsldrQEXTaVUE1aDjUVo0RwKH6pTV+CMHGW+DZnMqy
EAw2kJJdeX2lFj3yL7AV4l/6Q+JbeGcCXlIT9qLDqXkG9p0LHlMJIIxON5AE
mhwvTMHy7HU/77vty1/1N2nkDZACDRT0zkHf8s0rJ7S8I/1kIw1xcQ2paRXw
I7VyXZMTyUDb2S8X38eL8hqZiLgmrbPZQHpbe+HjD3ZtPt7bZRqErIOmPV3i
qtNtYk7YU4tRMWTQ59IkC9HGIsSQY5D15OBCxIlMN4thuw18GMChNXTeEX9b
7iSlcUOrJyVEbrJB8n3GfoxsOZHRF8DG8Bqt2yG1/bV5h13eVnj9wG93TdTn
5mTwTvAnvEH1bMSlpB/RjiMlOt1ctQ/cl4j0CZo4r+UJtywiknTkX+Lsb7EN
a4RjiGXr2OWZ3M6bcEphS7TItP/Am3hQLbvpNloGvwt3zPTwMpkGrOBnvD15
vXnwtgQR9O/Of+Jt4+fg5y1hBehmZydav4n1lZG2GjMlhW1Gweijf6WzGboe
4cqWxx5snfordqaS4UlBLAmXCugmBAB/Ozp6pMcComXxQVvVfKstSHlsKakz
ukK5y3ky7iKM5fx4Qj4CHxO/EGf8Cxod3NWxPEO76HchWwbDc+aK2fdGjxaQ
Rnq3AMM6qbFljf06flVLgf4DOSdLKc1NM8eyNcWhEmMc+gZM9WOh44Koxjuq
86LEx98YmYakBuN08VvHhI2mGcEWxAXUbNejS7H7teo2CDHcbzqXfaHnGbC9
NvGnhyAILFe0HCJaiGsLVhTbrR8LTSyjJ2qJeRqM4bqHI34NGhO+D5e6aYD2
BAVnOzvuwTg83jaHBiqQ0Ee4xzaePRf0iCF8bvTue4e7eACjJQOH3kzzxlhB
3feh4LcO/drSrSEQExwNjSaK27QFkzdg6bhFBPoK2O4zseDOoQ5jC5PNg34Z
r4nE5xT/NjCosPSaun5EqpbTeSlXKFYKpcIALysXg1t1BxvKbKCZgybZ64NW
pzloMPS+BzCFgX9foDron/cG2+5e2NQOQPmvRPI1lp6TyS7YMPVqWUbKw4Y0
Sppc3vRt1cyVJZVpsih3L4znVnvSfVlaiiK1lVWzNHXOdZmxMzZaXuaHvXrW
aF+9Lq6urx5bLKuaTzep15HOHuuG4cIesgYXPX5TS6zMvNoRrrjm76Hb6293
4VfhK20OKcrKseiAv1PSks/LdxozTbCQq6AdbBI4WUk49bBPa7A+aDB8NBwI
YJFsoPSZk7bUsTpYGpPn6wftZiCfP6ov7t28ccqaeeTlb1n4TKWQz0qVQXBj
zeCmNYgSZhDW3/OFHlN72UG1w2lI97b8ECJtzmXrpQpRuBjaAFi6k+afivCQ
c59/Y4u47j6L1iXdByJmMqmZOtrCjitw+b3UkKWbw0L7dSIZM+nkF/fnvFSu
8KmHcxawByV2yob/mM1WQhsMuAgdtKm2RpiZMZyxU6UMat2k/0IYO6iTiVIH
ydMOvgxuRE864k8bzcPoCoRSQdxwf7AXAlIHcftbJrW530K2+nHb7g3Nvnnf
3VVqZ0+ng0Zr+nSl6uZzTb5lK92bDF+u/077rm25N836d6GTVNmk0/fZehPL
tUeKiO2KZFEq7Gz0aaqi34gk1kkyk9m7KRvt+xvteXnmWLApc9lyYdumJC58
hzAhtzppwjpk3o9S68/eid9pdYLRaYHUbYNtdIJ9Z0VaNy8ru9E5GZ8sYEWk
XD5z6NuWV61/aD7V2Gzsc2lmK9GT0WFcfhl4UmX+8DpFdZHP5H3OREPSmViz
OAGivcAcU1YmrqiC6MAOfSrDm9jGNhiufjtM2XQ0eGNXhzWpUMB9AMRucBBC
T9HIV7qgu9DjBvn7ozO+CQJgIFKLsAR4h0W4BBtq4cdMiMh36bnwdGMOFj0U
VRVhb+BaiOL6BtXYl7Rxpy62q8Lej37jeGz4tq8TIMjluFCTuZAWZbB6KeLk
pH3kd6i+rY4S92KxoZa3HFEvaorLIS/vat5FYGCsz+tLGIYr4RSWATwN9JvJ
F5VN7l5h++Vj4bZXRSrlRPAe4oTCo6zNllbvaDOpXAAXojzoYVwKfCvtlX4Z
WKOYa7CdGmH0sx6GdN9429GZK+EXvi8EDF/HLnrChUwBmTWBmyH94tNRTGWE
LRfjflQuI1RntqbvETEfokW+kq9kBzfISzh95CV0nTbaTA2qe92ht25Qzp08
TZwbTaw9nZ6LrZdnc9F6nZQ0c6i73llHn909v3T1+1nx/kbt9p+KxafyTCw/
PssyuxwNJw+putUuPta8qXzmyZnx1MWQOz+H1AzExJgJmcyXbOlLJsPvh+40
8d4H1Gl0Uw3dRfFrEB4hUgWn1Ftky2ZwRMb3ccPg+2Lo+3fxch9weo+FumzK
qix8nvMFwR+lUmxFvm1BslKuWJQygz52CENLy399cGLCUJaJIa9B/+ZkcDlj
5qDngZO4T8Cf2RVrOZNGqplBRZcp5/BtfuHDLgqEV0/J9hsqiL6GEjmIQGRc
wP7srQzYjBoGok00+YS+NcNAgR/eDaS7NYp0xYPXehbstI3oi+WIc4twoU7h
abDO4NnGBpCKm+TeEm/ZAYkWlMdVtlkpkc+4bEyPNOx5zRtp5+nfmbxUHHD8
/ymb+adsWfqnbGWHe/YRNDghr076Yv3ygvdjk74IUgHDerwJpnASNMH0L/rA
8xHk6TkPg67HG4H7yNzUWEN9geFlEzYM7Du0LAoY9dveVZMA8q7oJk+B+V04
k23dsb0JiFy/6yGRXvwuzI7Sp5DJUpwGvIiqf1TzRhIff6ucz5Zy5fegD0DG
vdEFIAGBaQdoB/or0+p3mzzM+UWomibyYOAA+sdz9y3hEx8LfqEmzMj7AbN/
WuM+do0RxT5TDt8UDmoMYg/f5PgFb434mdEKnHuvYg+P3eCf3px5djTwmBeB
+F3Z/lu1QCFXkgrJtAB3k5s3UYO58K7BzG+r7k2Y+Qr/jwet2MwyJkYr70zo
Hcu5sM1yBo9uZAeN9AOTab9t3BmdjYeXpfy5mwfRWcwU8lujSB+b8mca+d2p
l37I1CmuFDaADg5E35n+5KEEFuLJ9KKELlKxVPRnj5EP403k47ss/N/OyZlc
vpTPlXK7IxVBTIIuUf2T8f+21aPLV/3m7uHaWaN1C2mmYr/m/at5+jo6nw3N
iZ6pYghCkko7QjPfhRCFH0KIWIzGJ0h4/L7OdOJ/7faE9hPq0r20ShfWWHOQ
7XMFKfCIA/p8W6ymsBGr2Uu+vPiGgt8WtylE4jbf21v8hujOrnXdiO4kwnT/
ahaz1UL5pS1Vuh1YzWy2lAm8urcH6RH9vPOmxA0LNCM02XAPn797t70PPrCq
HTwIHGKw14yQKsh5opQnnvHENbWvqFvgCJBFmpX4+cC/viEIMigRZciPYxey
q0x+mf+sqS+LYWbS1CfOP2NmwM9X58Zoenuq5Cped/LkXLSM2VJ8aYhe3bpe
dcd6Z/bP6EYUJSe6Lbadxn6QKzT+FXcubNkFtSSlHX49WRr/jpO88g7Fk4/1
hiW3veULHeLMtfXw3mHM+PbmsSipd9oVRRlBNR0K+0IsEQPeclRmrM+HHcxX
9XSWprntCK2AYFHZHASigSe4X5uXvcZJd8O12gSM1K2Bq+kw3TkWakwfowP3
u5CThFPZFKUNcr/1sHZiyv3oVrvVrHVDXeUCmbcJjk0ofnIEkZryyJ1tkDiU
dLYIOj/LnbJsRhoUM16FZcwdq0N/pjYH9NRiVipsGSQlz6XUgg2N7yk4siWk
7t9dcHAjCYwiIp2ULe2QHiFDX2Xy7vmp0luOur98XFzkc/nvKnVz/xDE84km
5d4jmtKz608XK6s0GCcgGoVqvifVikKDKUS1wntU27weODGdavwMe7C+fBWp
VZCyUvE9ai0GXfu5y9qrq3ICahUq35VY2Y/T6jtzGEX1wkIpn2qZ7HtUk4py
60m0njQ1CY9lK1myh/7yRXA1V2c/f4rmigaJiWydMxrLwkyQp/npjwOekFf1
8wfDdLwwvxBvKaU8e9jbnmyv1smiYRYlr6fw827/IdJCKUeeF7pgHmxw40B4
eXgk7duy/Xx7nlpp8dI2gW6WNrFcAng1fqX4Jp3phoLZDEuusIRlZmMBVixr
Ggfhl7OPWJg1rtlYVmbjhcQ/4RKQxbbDdTk8EAS8MhIjHPeRffORxoM5dr1s
Pl83T88VJrOinh9cjB9Mw2k8BmDJSvw4WDS90sXx8GWZeXgs3z/a7Vx3mZ9f
ls2s6J2NQ7B4t8bHoaLdUNZXL+1JZVUanM+LQ0l7mMxuXx7tWaabCYBSeODj
UNFHT/etuauXFuP56+L0vp/tZJ8W5sTqXJqP1yFlq9WPk1WWx+nn2tPdtPS4
6i1mcvNlpVZHy/tcbnrxdBXO/woNMl6LESsMQTnw0bFmAQwxVlySVouF+yu5
nrkfPt0slv2aopv96ajUM6hzIw5PuR5Zcg95bvFXd2IzWZU+OrS8BpD2hq8l
76HuiOLjq9e7Xz1cXDjG/Wjg9q4xLRE2gA89+y3Ql+3Jc7WSH70ytXh50Zlf
3YwX/b54f2NUA1o2et16IsKphqOkr+tZWe0oj9Ol1tdN7URRSuPxtFysVcNF
2hI02A94HS646tin2cvB9YtycVs1ux1zcDfJZjvGfVcJoEfzf75/zlAoOG7e
CA47Jjhum92b1pfEHMBbWj3dn2W8breSvVQX+tVw/FCbX1dnjRkrfOva+3Bv
JjclS2rb98tRqzEa35x2b4qFm9q0ceKjTTHspEhTo/iL4bLdWVTag+Ws9zgc
jy4HZkm/6zTZvfONOH+g/zxn1M7FzYclCdhi6UH5/CR340nLB6k4GbdOF/aq
279Z3Fhydb3CYLbsOsX2fUw6h+YbP25kbVt23Eh4y94OOON0RNWmXTwtTEtS
KZspSbncLvIlgulfrZPOgQdCSPer9W9CFCz+NYKVXFaqfDuCEVjZTKZYLhcy
4QJc1q/iOwyrEfn3LLLR4LXwXAnm408zMiFLmYmyrvOLlh0+LnwkBh/FJlOS
iugn+1CyiaFQeG6wPiTCNCQ+twpe9rUGnftuoPPlXBkjs7QEPvT8d4NeyOaL
uQIsSmckgIlNRU2RElYsxprLoO9w1+ExCOk9qvoGm9UvmuXGKi864+Urfs0V
GWPHwoyX6egMq/5pBCrXEjrVi+qbosp+rMYXr/oyLf4mr4PDkswDrEIZgtZA
KFUlKMSi4AmY2ybVpDD1508j8D0YWOTxd3hlNpYbmQzr9WQba1uxAHUVLyrs
8EuxtKAvQtQYH/EEDSy+Y0xFZGiFsBrQo4gezn7k6VS5aFAtoF94/aZU1b8q
jZcuqrxCfIbFFWTjBnXHqYA2fhEylfw7vKAu8F/oXmNe7s+PjgS6+mx9MxvW
XEUKiwUncpkXvxKQeks4m5d5faHqvoXmTPxSNrqEDx0BvyKKDHWmaFxI+n7S
umrSN9e10DPwy+mwfsxx1/0seuAlroQzZAdZuNRMGZ41bNmZWv6/5ppycHB0
tO1muKMjYdeVcRx7Ylasieb4Yf0W4qBYIl9URIoovxMOzQMXYS7rHnlhmPNk
a0Netk1TeFttS6NTC4QxzAuZAhktZEm2hVaaSfe2Iv+sOYr7RROmz/B5UNJs
mTvRJXxObE3BDgLAYTqS89SbWEITWPiv/9eEPwHTKezKG09d8b+ixcXwpGZ7
sAFr4BYrE5gKLJELzCac4X2FNvzZf5Yxr68N/MC/B+kv9CeW4VgI/hF8QpjT
qSabY/jzCrxcXbjQppZpwZaAJ3UQDSvhXtP5+1XTMlcGNhCJVlsFVec2jtGA
hbOELlgBsFeIIWBS1sTECzm9v/5vwMF1HQ6tBhIQGKkt6wxbZjCq+e65sjfE
iQQl0NivYV3vLLz9H6IZK5IOyXDuWfDfZx54rvJKqE4MkHFnf/33v/6fv/77
FH7oGDLmek5sS5nSiLOJhulBE0NjY5rKfKUKl1NZI/LCvJAEKGNl2Cr3lqUC
AHjU+uv/sxESg2VQOdlh1/dkF98/lafekK8c1uO51sKZauu1aGIBKvDAhMgP
zAqSqkEXlyMCbAgS2NLZinZVcGNk3dZAMvEN1RD5Xx/dRSR/ePsWKue3V+tN
tYYVkQh79tJbdowUu/+YbRVIcxq/Y5meC6w2AcuGyds3t0jcDjg1eXxly5Zr
Y/8QR+g7ysQaMVPDpX+UbbQmJ2w0ogU9lz1ePnkOemUIvI0c29JsTZ2AnO4C
iivZIEYECoJOR+0My+kSn59apkxdHdrWClkEHt3gPby2KtRkYHoHV9dmI9AA
tKj8P/0V3VbT+kZyC+uMV17AG94nSV1nSCdlM/jfGKOQUjk/F07jzYoiY4bW
A0W8qBNAeCdxMETQQiHo+RHqhzPg6Qnw3grmWoP5jeW5bG6TUhcgHAzhzBoy
DRYZp99iGGICLbG+L5lsHCeoAcRg0bGAnt8xFh/zcBhPqeRNNwL25Fm8vLyf
SBQYAFglQaBID6eEqrC9InkNivpDOMJXvJj275Av/9MMjMmfpdIhGBdb200g
ciOsbKcp86y4sB1NJItX+PypwTwXT8RItygTzxw7eNms5qecpz4dHvx/gl7K
dDbyAAA=

-->

</rfc>
