<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-23" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-23"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Eva Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="06"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 198?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>, <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how <strong>intra</strong>-handshake (aka early) attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, two GHSAs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against intra-handshake (aka early) attestation</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 202?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published CVEs/GHSAs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TDQE / quote-generation path</td>
              <td align="left">AMD-SP / SNP attestation firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK / VCEK / VLEK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest OS</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">3 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">7 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">2</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>] and <strong>archived</strong></t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>] and <strong>archived</strong></t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.
Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 807?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8292XLjyJIo+K6vgGVZ306pBZLgzmyrqUNxl0RtpNa0aywQ
CJIQsVBYuOhktc3LvM0PjN07No9j8wPz1G/nZb6jv2TcPQAQoEhKyJNZ5xzr
riqBgIeHh4dv4e4hiuKBq7k6+yJ86piuLYsT2VSdiTxlwmd5KgsN2dZXh0LV
dZnjyq5mmULNMh1NZTZThbZsGyNPFz7X7hpiNpMtirlcsVISrJFQu+v1hFKq
IAA8wWFzZsu6YLkTZsNPDQdf8WaCawlsOWOKC8Doi0qqDM8Vy9DM8eGnA3k4
tNl8C3L7Efp0oMguG1v26ougmSPr4EC1FFM2YJqqLY9cUYuDE0eypovZ3IHj
DQ3NcQCqu5rB251GvykIvwiy7liAhWaqbMbgH6b76Vj4xFTNtWxN1vGPTvUE
/mXZ8F83/eanA9Mzhsz+cqACJl8OFMCRmY7nfBFGAIwdwKRyBwDYZvIXoXrT
qB4sLHs6ti1v9kXoNar9gylbwSP1y4EgCtWOII9hVAf/2KSFvKYF/hxfi4M5
Mz1A4BdB8IHft/APPr97GBMoLbTwJ3xsACHwlb+wpWzMdJaCpcDnsq1MvggT
1505X9LpyI9pAAegNXfiDYFChjeRDUNWRc+RDVl0ZFuV7fQ2cn+Cz3QZMYfP
AsBbP09x6CnN2goovXtJUxPXgIEOZM+dWDZSEgYVBOAQnXPDp64/oHCLAwo9
GvATvWXZY9nUXomuX4T+rVC3mQNLfyy0mG3I5oreYpxi4cQHhHmKY/4X1xNV
/lVKZZ+2jH+nycqEObo8F+rekK2m1rbBa5bN7pk8Z7Eh8Sv5Lyr/DNdi2wA9
yxwPLeHE2wa3B+QaT2RNaHmyKVRNYK2RBXOjbdVnysS0dGu8gvFTx8K5q8I/
axPNlGNoDHWPqdbYhDH/MsZnu1CpTZg5Xmqm0IbRxtvw6az3V2wI2bORw+33
x2jL1oKZAs76p014AmQ3pWymkCnk8/vROZNXIENtRYNxt+Kz0FxlEoM+hU9S
jH/yF4d+TymTbcAbc1m413SdGc47xDwWLhiKXh13R2w0NpeVlJFacDB/mdmW
a5kpYyuvdmWQjIama7IJDGVrY6CMqm0b+qrdES+7jVY1NtZsolkGG8sp2zNd
zWD7SdeBLSb0lIltKdNtYzS6nfNOVbhCjBVLP4b5KqnYeC6Tjb8wQnjmv5WS
Ad8Dky/5HMSisClNUyg3vhCcHYqR3thUeYdfhDYQRCRNp7krlMKgenw9BZqp
f97jsyB9IJx6JhPw82M+lGyPmbsWsIvFIgUsz1DsjuGDlMnc9Mwb6ppC00/n
M+WsVJHK2cEGdojcII7bIIYZ/jjQzEGA2QAwIxxCIUn/EwF7UFbdlHCb8sVi
/Je7VCCx4s9PRfjmVFZePObuIK9os5n1Z9BYX+2hsa9VUId9SGsRTj+RUvHJ
+tDjQ9Ee+IJv8gc+9WpWzer5ZgAng6A5wtzTTbC6hjpDM8tmurzCd2RlCr9p
MhheMD2yvNhswgwy0PBTsDscH/wWrlTmLAVIpAGHG6aAffKbpv66YXII6zXI
FoUuMjGtA/zQuL2r81elYr5c3jfLxkWnV/2HzJN5czXFTM0BQezZ1gz/laa/
0xv475tqq92rijWQOo5Y7cS5/cdPJMr32Vwckb2s7+kAdK5ZOnNtJ60gummH
KR5usLSszjUHLFzmpGk289F4LBrz5VI0xuPS7r1wuwYqEAXAgN2kSHaTJPw1
Qdtq3QZUQrPTAI3GNfYbojmMjHcRjPghKicwbQMKgp5HYcSAZvUHASXISANn
ZCa7kyjxpKJQ9cae4/546uVny5y4eM4uxeUy/3dSL/cDqKeAgpUVhc1coTEH
B8pUmAD2xkQwNVCnzJi5K3JowBlzEQRKbduty66MUhfsCaHarYOvcif2Lq7+
VELaRWDDWb4sPmftxfcRsqGOmQ7cIvZWQB/DidPzhhmWG/OskNfAfUNqadt2
aHTqCebNfDScFc4aF89xd0988jxWxGelMBdHi9Jk98SDyQn+5OBXdCnFYLOA
SeSuRL6emxPHOVX9PaOZb5zNqOONWwqc7xHyjgtusFBFH1VTkBH9kWMcIYG2
M/doZLTbUHCBZZbSmDsiRYMP0oYzBqrIbnqZY9fL5vN18/RcYTIr6vnBxfjB
NJz6Y/rDuploeWVrcxnILtqwVvrG+gc/CjdVEXeOMpHBQDbHTDAslQmqpgqm
5QooY2JMwoJ9BOyBGwS/9WVSlBI5oQd8xDBA8CEuCdBJc1x3M8hz8WUu5nPA
IHa+kt1NkADgG2KMrR2EaFm43NMv/2wUGVu7qVF6Hi3EQs42xNlk8j3UYNY8
Tg6YCTjdTAQZPNds15P1LQRRmO2CcsEQlCMsmM04ZSwPSPOTqPAWr91UmRVG
M3FcyY/hH0blu6hi7KSKoZnaPx1JEKk92qTyYoBufgbdnFWK30EP21Xi9ACB
CbtUVHQNQ3ZbyBFaH1z9gm598SwkzU+nShy13UQpvNiKOC+X8qKxnC+/jyii
Ku8QJtsjmB+08eqgHmwkSKCmooQp/mzCzNB+KyxAzI4mhT1G3F7CuIr3MyjT
v6z1L2//IWQZj8svojGaTMSFbSsfIkunLtZszdHgaf2yk5IyKUnKF9K5UqmS
zZRTuVK5kCuXoi9uixuQ6YGxAHoDLZaYRVKzjJnngh/wRWhi1AdsFFPWV/iq
NdoZObiw5iGtCu9GD2q1mhgxi9IUUdRFZ8YUUVNFhTD7nsAB/NK1QOPLIzn+
Qz8FNqaND202AtwjFMxU0r2rVDYjlVK0zPCreFONEw14QbZhosLQc4FvxhQb
xJMSl43hOXpN9hYD2EQW2x5i2UEkDBh4DnjOSzLlwMAdgewHayAtu0q2kJ5h
jMtn5/SCaebE0tXdlKrJNqyWKdxH3/wAHTuW6f1//0PoaiCAwWqM//gI83cm
Qh3+MYNtx+K/tmXTBLncd5SJNYKJjDc+lm2gTG/CRjCxjTWaWIbsANc5Dsxv
A1UNdAF4ojeW5r4C6IMDLYhD+0FJsZ4a8S9FtHtFhudwYmQ5PvaWmMlvvojb
OfZG8d03Ku+9IWWCN0A4vHJcRrICuu8glUodHIiiKMhDh8IXBwd90Gt0ZiPI
muGg4JrZFpqJgosReLASdEFlLjgDtEm/xqNL//1zwnDU4bHwdSNss4bx8VAP
gIkeZbY0t+0NQaxygShUQ4EofEaJ6BwKiwksczg3xwMCyFwqrecZmscw0Ym1
EI6OyIM/Oto8iGX8IDa6IUdEIZB4M6SrpjBw2uewPY7Qibdga88mIOhwFDQz
HOcIxYkNNi2zjwVHw1HR5dRMD4TMpq8LnhzOE7a3zV48zWbq8Vbkop/JqurA
Sx5sGRxPtlcwAOqsJVDoCIbHlYctD86+gyefwhD0FEjf4YpsnSDgLfz1r9vC
wX/8cQy/cHn2xx+0GPiVjJYl8tqOz0hpwPtAJ8QTDMKRCN+J8J3AJTWA8lWC
a+FBwpVt3aGBdiyAIQZKoDrDMzoxm8oIOlDZdBh5vgDXtlRP0bg7TQjZsJ5s
wTllAtanMGQMgyxT01ro6OtHJquzObADIjVlKM3AqEkJNc8GAenqq2N8y2ZE
pqMjd2GFx+bByTq8AU+J18LHlZR0LFgmo8eRl8vHxLjmxuulVJ7j+uaTYion
0HmDMwGc5bEMcst9E13awZmRpeYLOpNnMDsYBSfl8EkpwUwFplFaACf2+gQe
Q09DhsoI1AQoLMADyb5+gQ+yXn/AnYP3h8NDLYAgAK74MYW2kPTAk4Zn4pJ9
5/r6Es3QVFVnBwe/kNWGr9IR/C7uFXxtB6wf7C5BnsEYMDoKQeLCV0YofpDQ
KFxmliPrzjGgNgbVR1EfIMRiQkodga2I3Dh7P2rnKNaMBA7GhNArsV14E2YM
3kdKaNqWARgGlp6ApMQMDdBMnLU4mTHqDFJa0RwuihTXApLjHkIKA+KaShaG
H4U1QOLJIFYN0NCWseW5E8VyO4bEqDgr/i5hG+cAfCzPMYqEFjEA2i8Skiz/
MYbf4ccoN4w8m4gc8DnwRRU2K5d5ZKfbIPY4OyIqgR0b5QVa7cCIVUIjFn4X
aYztAV1afT77TRkG/7dJgpj9nHDehERs6jhLk2fyxGbqzxM2xnprv9nT8Cu8
hDjjNkAbz/LGkzeT8HlMZY42BkEww+kSXfaRA3biL8IlaDfcowcf2IfumnzI
4jxAQYoMg1gbuOzhaX64EDzejyWXYWAIgJWq+ofZ9Czm6QXn1WBAHXwDdyQl
fBNONoeFZ7cOQxaB/6qGm+AbfCHhBzVy2v7rf/0/HIJpWqjxv4EN+k34isgy
W1obQt91Gpp2bcYwbGumfYCHNHx2Y/jo/Legkf3RaGQ5GjlEgzLYMMvMIiES
Gzj3owfO8YHzOHAPGJHZNH9+ck8iMzZ+/kePn+fjF4j+lgEPOdGBh3/JElv/
koujUPjRKBQ4CsU9KORx+M0zCvTb6fhjK0KbPrbBGPqpTnqoW0M+PHhPDJPx
nHRXtqeec+Opq1RwpgLuCoYxFCXqt6Rm6ujw38HBCE7P5plUOZWNexiO6Yia
i4H34phQWcxEhAq8nfZmuiWrTho94LSUTd8znK4tVvEQw0WlaY7FPn4r1i4v
mp1646LfqZ4XW/7IMHStFjtS6XVaH5n/4b/CplItCh2CrHiGoYSve6TOVpgb
1EgHEojcu5mlIGm64If9K9HGm6HwU0lSrsHJWsqAVwgewVFAyTiWZ4OPP8NY
DxjcgCC6A0iL0PERF0gg0hiHa2Ys/mhmLHJmLG1lxmPYDMdrjgR9sddNBs0R
Ilr60YiWENG/fuEhml8/vZH1YODFo38OIR64Kmsb6NMfBwf/8R//cXDPQs9T
DpQcPICJw/+BMR+Yd/AXeHnckxqCa7jWcwdb9Bx9u1u3ebjICOvgjauFrlUE
XVP1bVdEz9BcbbzWhPi9qoENOKec3hDV6Okl+Nkp4dJDVQrbHO1yBjsfPpXB
S3EFQ14dUCwdqAALGpzYgsGjwZvwkW1hasBsFiRUiTCpEeh/4TO4ZUwXcofh
9Pmk9k1b1sEuRmsMrAU8VIdRQd/oFnC4esBtqshJ8TEa52iomv4T0EoGgESD
iMdZg1N5eX18djDiZrmqjSiEhlOEyeCwPX5S4H8K4/sTdzybhQQBiQVOuesc
ABU0MBLQsuLERSWVIpY5QKaB3TvDfOohKE1cBN1CEwMHiB0ev2flYMCHjjO4
ffLXv8ayF9AddxwPfoP3/JMO8E5VcCGO/bAJDxPwr+HzeEgHvo84wtzw61oq
03GlLsk0DXZQN2ReHniKOwsvHqyRMMIIBbIIrpVhqXFDECeFkGDENfX3zX3L
vgGn38H9u0Jnxhzjr8hVMOTvICNc+XcBI7IgSQFz30ur+awAGHBLQvDlKHJ+
k+IFwld5PEa/z2U/Th6FIA8pOoSOP0kI3z1Vo3tX3TbXnW4XrBql6OiorTCh
CR3xYI6e6f+V8hdwxEMiARLkegZW+ha3kniAkhzI4Isqy2jEMS7ktwdNiTtp
83G3h+sLXBOUqDLujMi5y2fEHv1WGGBhHm4d5228FMYI4xEwU91akORcWJiB
b3IuAYng7/pAfq9dcfALwMY/Id0hTGCrUaDJ19EHYH9fWWB0bOfPGcrj8BtZ
Vf3ICric8ibVfFdO4FrKX9uPUFC1/OPMGcpmgBDPZ5MdP76l4VvgNPtBGhD2
NnPBafZ3AR83JXQIUY3w9wXGG8d3N99h9ItFg4fkcNljzyA/cDFZCbHxCasw
hkkB6i2TAJ57j8qgh7Z/e8zPXiaMT/PoKJgdzCgaM31P4wKinvkMBiaeJ6t8
FzSWoDGRSYSeB9vfJiXvBxaFHnzogSzsBUm0AGEo41YGaF8vOr0+bCrX1hRn
LVLMuZqCTeamxtY8jawv+q+klbnjHKbQRyVhjE6PDxa8ViqAwbGvwkAixjDT
PAYJdpkoiuH/A4hKSkIzDT6noDW4kb7xVob/xsxf+JfkPyqsHwVv5dePSr4L
gr5Ol6maZ/ifri2srTghW3ww9IZ21tFREz5A39pm/sHWsdCGd10QDBhxBC4P
lNTRES4OzA6LhhykGA6J5xZCSLwmMfs20rzVnwFdthawHAtv60q4pXvKZFME
/0hjQeaxwOG/UbABlX/UABvHKT9hhK15ff44+V3jCFvIm6WPODtu/4i0clBZ
sw1E7vtBbCSmvTeB7yVUJOXrpw/BrPmfMIbx08ewXeXPGENU5SRsu5laQt/6
wm/nt/2TasigazZEPHd9s5adJCzTdB6VQGLykLkv4kBZf6bQL76ERT5UeEVy
37JVrjb88ycwjFDY/gL+lQ3WBjf0yThx+QNMQNRRj6HTBdYTdxp6TEkBFSSE
tNMe5dY1vJj3X1uH6LkuPbcW4jl5hF3wFn03ADU2Fy8+MgdNbYzeVnbvYL4/
jn5ev9EQ5bEJ1gMYs0GwVyTX8yA4KKcIPyoYWQDzkP8o8OPFDauR7FBDnjm+
G+8ftKMdAVYzRbotiusH2RZgGqxT4ZEG0UTujTgDaXeYXwpmx/gPPJcBGGcN
5IP/+xYb6WOfwPDilv8J2x/v+993fQLDHx1dBSfpXe51g2H2DectKvKMqM8p
Aeznolm6c/b+zMPPkBp7P+LD12rClf8WjOzDql3dCu174d+I/sCHHsD7t42M
nRHGPm1PcZE7I5/AuGLvKo2LMNJsY4G+8L8JN1141LgLQgtgOPLh77rBqJGp
UFhTqFvkr3zu1w/fX3scTolmZ91131/7o6NrzyIHnLLLOSZI/OuGkOZ5kyI/
TvXNbvCqtg/PJw0fIR6xI5mABFuHv2AulmbjoY0yDYa/QuseNvvYAyjCZQ+X
AexAXRvaaHBrVJEOSG5B42OfIo78jQ102r1uun8VW5FvPA2FbezPrUT4+Ks0
2u8YxK2e/R4Z7lssYI1nGjAZmGmwTA2eeLsx7l2tcZa+O2+cCXikh+/hl3v+
Fxm/sTE+Vq1j4D2N/hxRa10QtRXq93yyHv68Hx3/G+gEimTDjsUv8bj6HZJ+
zycRdbuheQL5LjhcBXH191bCg9DYEOWoRvv+0X1wWgKOr7UwA3c7hM2BDpkO
iJP6iIS+YkAPKERGskAlWeAEx9Jx9RRRfopl8ygjhXDiuo37koHiSkeX5ptw
45lOWoe5OTyE+ttWvhH6q9mbrbz9zRtA3jJMcBdoJH5usVPjfFR/fFzN7HqT
UAhYfxPpDhcQ+wUpuJckPBxr5G4TbdE3L3vpQPjUelc3Fy2fA7+RXGrU6u3G
96EQk5zfh0H1DOQ1yg78F0oP/4uYTlgDavqSPMj+T4fKFdd3osF+t5UJRicC
fSqGMcVgyC4zLHslAgR7NQtl3DchooSD4dpgG9NwoQYxZFPGLK/NGYZfwuTS
Z/WmEA73+03j6vKmP6hX+9XfI1/U0Lbl+WKtQFN8E6j6Loh+7vkfJg0IkXYl
AsMUpVmYzUdSJypkzsNtuJFljvsbCBDVsf5GR3ECZnmdUjUB07vYAUGdHx6g
lOtrBobmGT+y4mfh1XVOHA/CwTyrIGKovvWOnwWgLGhQ7IwmzqKBEfgJj380
UyPuWx9bsODYgo4/LP9cASBkSsKl4h5TujLnrTgKiEH4spSHeSmRl6ONIvwA
5FfsDrOOku2vXgPSOeniePiyzDw8lu8f7Xauu8zPL8tmVvTOxo9pPAblFXI0
apFG/epTCw91PFMhPCPH02yYCkbEweBvPIouZrLZklTMFAr5dCwTe10OmbLp
5Hycdhnjx73oQyorwCJKhWxJaLJhBJ/wpHydG/g2NCV8PToK44C/Cu1Oq42l
/DwR8fDo6L8jZL9GOQr7rrEtDrUeaR/cQgC3+AYu1ZFHwGAgams86jvhf13z
UXx59hTwYfan7DAn7cpjfk6O/julH0i0BGFBCAXm6aNtxPkAxhVK0v9efMfW
blwLKUkcW1IqW4TB3iA9tr4TYSnzBuPaG1vm+xIaMGFRpzj/1z3F9h9KQNmE
nZ55up4ulGkblzZncLcebctkqLL6O2fk738VeTO7Z9hEx1J0lIUrysswHPQb
YMduQH+TwfNGKGwJxu5hgHywx96w7PtiJ/t2/9ZuOv1OrXruw6/AzvIZLKhM
TzRC7u8cIdwcb0Z4G/D9AJEiFYDJBqFw788cgAd7f+4Ixk8egQd6//4Rwt1J
4dCN4Ewg19EqMix8C08ad58ofhPyf89oY+vHjbSXcjx8/QHiFf+eQXigOz5K
t1Hv3Hb9cYqp3J5x1pZvaL/GE1yiVmTUfpU3DFd+EHjhFzGgXcjPEk2eyURm
DR62yybmy3NzXFmBAwsGoYWo+2UR6E0FbQxjgW3KE/j9nsnTtuxMfj/m/11v
/07NOX4/kdUG1yW/p46O0PcGR8fS1Zj1T6EDy2HHgpZiqWMfZo/SoAgqTc1/
AKD5THUdmMZSgyiFE6Tny7yVIB1oNm79Rj0HDayfYrIp3JrAQ//qCF/ph3dq
rSaWwWbgMh0SkSI4AwNHGeCtuUZzCNtMUnZXuDIw20h1bJC2juevljGTbc0B
mtP3PNfkLp5ZtruKVDjXXPSCgCuQg35xmCLiGbjoKBa4IMIfP/5gPe5VcTM5
PDH+Goz2YZibh8u+L/V1AU6hK8/orCLiYUSegpMLujx8hBms3M1EjD5/pQh4
PHUWC0p1bsf4CbPwNO1hbX5YSSwq8JzZ6aiHk6YPxfCV6G/IAwWwVMRsWcxk
JOrweEjs+rXarcfHlw2VN1kx00FSqpPm1Q1uCD09BMMNk4nT8LroDMVcJp8J
wa4HRtJR4vQFZiIRzfqNxga9wJ2K0oryWzco9QZI/UG1FhGDVtVTsmKQQ6da
Wjqsiy4WysV8PgWGdCaby1DW7J9I8zzSPBOlOab5Fyi2ueAz6bmyzrwIey8V
WQxyZdY9PB3+WvDvAS8QBifCp1NQ71kQC/lCpvLxek//A4SRT2UiqR+I3AlI
1Gmz2uu/h94QXxxhG57wvwaWPMXWidtwLEqVUjYJjvjBIWKY3cRQVm+q3TWo
oQxmuIEy0v8vHPvbD2RzqcBXEusFcn8iuaSk5JIIxcoGik15CGJtytT3UBwF
L67/az/TSZkPYAgPIx9sxXDbOXAc8p/Y4xFnuSfNh2dORcyiTU3JK77mbzVl
LAqshJpSDzVlcOygrCGGRxmYcb5W5EdHlClF8YOdx+gY/OSNZCi5ebOLHuYc
GjSusGKuPygLG6pgI9mwpGs75hSu5jkbmNAdFrNFih8XDBO2XZikydtk4UNg
DX4kQ4YRllpTbtnBQdOvE9zMWESLR1+jtj4ymVluYHnsSrKImuufNwvueJkq
zWBtxh5+eS9PjwbblpdXFmJ5eTwJ7026Xg4QQYraBg9bqxhOtjBplVdhlFMl
IXEi3+eCsBfoRpJfNsbDjXVv8Q+QkdMuYvf7jOsXLM9scAIMrO9ZCZgSbhAP
Atm47XdMnDfSMIMTG+WOMQ+FfkpxoxxhwGdgVEcXiXglEqfpxI/sDg6qwGUM
pOoGi7ypBrFZJCsZllqMFO/82HqdL9vkCPLaNiv9vYAf4hkEX7aGwLZ0BiQM
Ekedj3802skq2LZ1+ltP5DsiZUS5f+bysS9/SrgVV/DoKAh9HB0BWcIIgt/a
7yeE6LFsilcP+Y4ZJX4lD3dvw16zOfZjKyHmHw/W/zT0DzojYWV5vBKfTkRx
KHPlmw97U9ljEu1YmNFMBGze6TkCUkFwLK7zF1SmJigTpkz9vgxvq5beFC2h
vcJVrbEpdYMu4kIvWgfu7BK+QcZevGycx0f2zvEI05OONoQ1IvVx0USi/Z1a
xQq8JjgrY2jpPL9ws+zv3z9yEnB0FJ4FgE0mj1wWRrTeoLCrDiSCBs7nM2kQ
cC5VccZMkeIjh77pJfvlD9uqFD9btjZG1Yrri3YY6nIxk+dxKuRkzCzRkT8s
eF48PMBeS1XMNqEWEvctqsfQFG2GPVdmFnq7qmB5bshnWKvGuWsIvJpEVwQV
SjKZg3w1N7UTAV7XU0Xe3NmY9c1XFFvMUe0Vs5EoyigFACgGZdk2bG8ZTw8O
+WcUAeOnPmEtDi6VM1qliDrUhyNOGGxxS62CsA//KmwFsbUAEEvasKWR5nKr
mYxrsNpcYS7rHu37oLYt6DsyCZq4oBXMg5v7G3TQRCIWMiwJx71KyY0cELid
4FKQTeS7BEGxEp/00ZGq2aDhdCyngecUIeeFVSCXdlQeBbTjwx0d3e7oaYSD
aK7D9FG0Z4qCPQ5sM9wlG12x3tudNCaaPGRhRpcc6+A8O/Qg6MXt7Zb2IwbS
LyiQpOxmB6vJ6u2NKqjPv4+Xq98PQfxi2Z+z8euQuQssIFPWhYq8mhTLz9qh
+AsKazGJ5vPvE9dRAoi4hyNZNtgBK/zKwAmNmXOQSwnVdZnuBjR5L7RIeS+2
q5MPDq74VsdiMD89fH/GNsL0O5GRxgi7fV3xBaFuXzVMZ9P5MC3cgofr0HC4
LYU/sLg2CPGTr+pXdcrYZLjfC3oR2kEBLDLzakau1U4nO0VVgFEEYDaNSMdd
GRe1x5et5y9qSzrEFdrzVaRzx3od+z7lz5DyrewhrszHYETXLw4ld7htTXKJ
1qSLoveGNxVD1ViN1qpuazPk9w2LZyFuulPvlN29VeAblYHiZt+RCdNnTliA
zjOtpAA/fB+zmcKy2nWPl23fZaPfdXiV4Z5qd7+i/b2SbapiF4LecZF6RPBm
PWO2Lga4CqTR3v99W5deC79Ix9nj/HEx/jB3XDjGiMDV21mjZ/9FFPePEBvM
fzv4j/DfWGgnCV/2sSpJOfjiv/7P/90H9l//83+L/wdCyb4DZapMNqDw/4pD
yb0L5XdhBxT/P2KZwXiKzHkfgxWbe6mUkojf/fKUwkc3FknPsMiVSkr9QEq4
0fb3JYp0I1p/G3T+234Cta9l0U9rV5Q+/KnQdWuccpfux5si/bSGSNGJ/gTo
sYlub7v001ouRaf2E6DHpra3sdNPa+oUneFPgB6b4Xuto35a26joJH8C9Ngk
321O9bPaEaV/arOj+CQ/1PTop/Uzis70J0CPzbSciloRMGzQFvPHjRtA5NP6
ifAjE9tyjhHR9b/QUUEYeoLFbXJF7JDG3vUjvwcJrzX1AyNgQt5jn1qdbMU9
SWFkHx5jhGCCTstXfu1mPAC0nMmRGCU6XVhONGX2OiNetZT0rk/Th8f+rURx
yzVi7sb6yjreGHxE13f7wclHR3SyGtqaum6NiqdSsU2w1wjG5jY7aXD40e4n
PFS01fUnax2s6z2Nkt9DMmqjYxsrc7X28IfMZCMtfu75j17UFHKY37I1HhU+
Olr3mfW9Cpg+reabZYwyBr3x3rSCXlj+R8g9Vex8ZcCWcO2guAbjKZEYpX80
y5t+rTtB+91/tkZ9fwBP2IzKaOMuZTwASUSkntIU58R6OorLyR9raiRm8jEc
3kXXjz/xyF2wSPCHZTMjPPKOR24ppJf6oPg5r541uPjp4aWiMnm/Q7yFVLAU
GI7e3E5y4auON/za8oe5Eh+J/kfpw4+iiC4IYfh+uP3tZRxvA8h4DiybU4qt
co4K0utpWdeJ9+/H5pGXt9xRdsQTNI8I+HpnIG5Yza1iUynb8pyg/Tugiewf
pk0eY6s4bHm7znSYaOMJFRLiSbYaScn8nkwQ4TPvw7SRNvnHH4e800Gkjc7R
0bqRDogEbKVD2SGUwEDNdLBlXUub+x2UEE/eMVnxMxLW94RuoHqM50egLKjf
mHrgR8tZJLWAJ0rDjsTAO3Uu3y+Qu7e9/oFnj3kOBmZY7xe7fr+995iQihuz
9M+DvW259+FGwX8Dk1FUMEcoNVamxuHUn9RvuRjeL546iB4nK/xN6iIZ3lQg
D0n3mPwLcoPW9xlQ30fe3Ip0SviVAxpLV4MwFXvxSP7SgdkYGz2aQZqu3/LC
ZvqKjtqACWC3xN7hEpBnClNX+Ui38whWQVvtY3+fBd2sgXR+O2onELyyzvM1
wp5seD5kqtRJBJlX4UeSwTjhcSNHhxJLsKOgwtfR7wEJq2BrQAm8OoGaxPlf
G0zG4wqQAxw6VjjyKiAqqwxjeH4hdcARsXMJeJkOQBRfF6oaNinkC4onMxO/
9hp/Y8EeCaKhQeR+6z1tQXw0pIB//RTNii5VF3rhIVEMhL/E1NdthAw3xOg/
r2KVuVDRTJAJ/CYZf0Vps4N04MuHXIWHUBgjplOF9fVxlOtlhpwaUosn0zAq
HcWyd8qtsEgN8Ru9iS95kj83jfuWpWM03sNQ2Waf0tAUCHda7HYI4WtgE6x1
j8YYtfu0se6TsUD1UHO5dKUM0r+QOww6m25osnVjQd7vO97LkufNxQ7MAGl+
Evh1pC1RDPt3YVF3yuAPeX1/Y9Ksjg9dZhRxXLCfgpwGXA75mZpFYWxYNrxT
hKq/eas/pLTt8uQ2wAnl4whoRNs33hrwnTB1sA0QdoroY/v2BwsPABeRoxbs
BovMCIRDhsUOlHjRCokKan0YHlcSWGIf3LWRQt/1hRGwtcIet/+EK+CTGo/V
sV4lvrHWMgEWQzbYFmxpBWNdkI5DeRDpyEsJ/2/tm0Ps5soPrzhP+1wQbiAl
VAEo1OguAH5zDT/XXxvmzuby4EJrDt8COAdlYmkK89vmorejg7EQkXahHN8y
R1y0Y24vhBZCnAMXhCfP1fMVxLtXD1xYeB9WYMoGFeL/dByyfY+SRcTliwkW
5lXvjKdmrG3IFDdAYrzx5eDgfyFtHS4LGsxSKncc24AhjEg9TF0DCc/ENtN1
A1gT+Sq4BmaEJf2o9piOyh2e67o2wz5ZII/njG468fuccL3yuVE7rLcbfv9l
rLphioyyfcGdTs+MuZw8ZIvlceEtGRsi2d4sz+WnIessY+KuLURC6X0/0VAQ
uT4TgQo0NW5pc/pu+Yz7Am+lWHhK6R8VzdaHztj1WuN9zkJhCJYe7a0gpqCt
724CfEIWjTdBDleJX3HhEJkc/2Taw/6kbkgXE90WIHhw4B//Gd2Gme8IAlo+
K6Sw7EXR6aIv3h9DDSzI4AoR8BnGnh02GwP1tz5dP4gctO/rK0wXCvmXkbhh
z9aNTyO93fjxWPlN0zfB4LaYQ7wNNgIzZhPZ0V6jqUGRPUypZ7G+tshoNlib
Y350SsLT4/IMu/viQjkxdOnuFD7vtbkSL/q6oXygg/XP8Uwcni4Uv/iFRwW2
EiuFR8b4cnD3KDna67oD/LbRu7zp1HpULEm4/bJZI3cQHjDub3kXuWrl7e1u
tJHCnkOchpjiobDw2pXNpu8cmW7YMT7A473We3vxWFth/kF0CJ4vTHiceVDd
cdfQTnrvvHPnnN+5w3MYmKrJQg3FIBi3YfqIyRbrkkK0AOk1wHLETXLZLx7G
Th5jFsQRAi29I/3R9/w2DBvSCzxqYBvvuLspSi5HOXLDxhrmrMSLWsgB4D/w
PPOgBAm5KZ0ppTP5dDRUIIahAkekTlJieJQsao44tK0pM8lABxUmGvJKBDEn
siWMkC5ki8VMoXgIGH0+lWeyCet8KHw90YGT2rJ7ARTsW9NVpLvCEH+CvYzE
Tbn4W9rPX3XSklSpSAUCFtBcl82xh5lIALVN8SXTiqrlSfiM5hrLU17Ijuh4
M+Ip0bXEIaNZ6HgfCZ8o3fUL+1/UXJiqieFTUuUgxSaWCl+DzSbC/yNKXzGP
BiP0qhLLMfcfOCnMd2I813wcPE2IUFpTpWKlXJBKxXzuN+1XKZPJlErFYjaX
LRORv0b74ITpUEjmSCMcbGMPOw7Xn3rgRFGIZzr6RVS+CZk+9Bnrgi3dFjNR
4PFWUxEOQ6UDP6MPyLBNIf1Ms555usPSYfhnpMsLcW21ipopbue6WHQt9MQI
lzrs4FUwzRsq2IjGHOHHgLn9ag7EY12EF5+eGCME6Q2O5ERzYW2wIByWUKQS
B1HWODV6Nexdp6vxLeYoC3xIww1tjY12bih+kevWKdJWQpEhjpALSRVxstHI
GUm49mTT9Yzo5rHGToqqv9GmwuVNedN0RhL9V8WOqeASrSWHiIpTVOBXccrY
TMS5AgaG5jCY82rHmjicMn4ffOJSDPGKDi2mNjZd+hIVMbeBadPeeCAXZfMQ
66J91jyXhxuk838BuZ2yvTSKgXShlC/kC6nZZEZgWgw4HKHQdEGoxCEET6lg
by9Lacz24A++1ODGgKjgiNawvyZJqp5mRsLYWD5kKiwFPqacUsw0sjiJTTFT
EkFscoUFrKyNHGXpVioF4CwppfJCTlw1pFJ+qL3GQ+P4hMsnzPXF0mSwisUR
+F2yCGsxQxkA0hWvfZNFMFN3rMoGkTv9XvQuICo/doG+IV01x9GZamFVka6J
puxM4F9T2qAT5ky9lSd6K/l1rhkYKp3HNsgGnRzjVTWiQs9xU/SMb/20XM5a
eqWS2aQvZotHhRMiyZ/Rh4Qmp2o6nwZBJ2Wy2ZCaETjaiJnjSMwnRQ94IUy6
7N2OVpmrrvHS4Ivgjcey6TnyxrjBY44zTGEX+6A4sHQmzjRXmaAS5OoCtwHl
C5MGxL8U3fKAXAtLXIEH7GAky1ch/I75ODq7Gw3N8B14Ix2+S2cmESdyqyzj
p6I4hjOzNDda/O3QBTgeJ7N/HQ7WzVayhYpUzRSAo09qYiEjFcSTaq4unki5
fOkkV6gXy3mCqMvzpRBfPFo2fJ6aeAErpzekKj8axqNH0HIgR0Ws1RQx3363
BuAzsCbehqiAJ3zXpKVMvlAuFiq5/EDKZjOZfEbiRscVugK0Gwg5VXNjzRjC
ZynN5sy2SwnENT+I1MqomM1KYraoyGIpW8mJFcYqYqFQKA1zSmZYHpU3tuO5
1r0S7q4u1sPr4MjOZ9wyCfZk3CAIlI7f/42jgsvsCxPQcCmVzTeUHj4i/nXS
007xyrp4vVrSB6AUgLgRKtLfKYqyyFoKhBnhEKwS0E7EUFBcMyIODlcbVGe7
U2/7xiL61TR6C+sDWGQR1WFqjMXbzEs7WJpAN8b99uIxe/VrnJ/pe7RNUnrk
+3gDEUWzFR1+p8fpePTrlxA+QVIAJ1sHIzhqKkYe0opk85lyaTMxJKapF2Dr
iBi9XPdlwOMcEy1k2QTzDd61w9+4kWg+g2gPTbONTgH0I5XtY/O/N1QXww7q
BCsoLIuIXf8J2XUEwz9TiKENliXKJoTqHx5wW2YEwsQEIkT0nf+EVKmqYTJH
uljaEL2Ko5pxEySFj+ibBdOWmjnIZ3OlolTJprEwfGzZq4GUy1SKYLmuNaMF
StWlZYpMKPIwaJqxjdM4S3KZ4rOdrTlTrqT6nj3VnAlgOvH7gYL1oMlRHyHy
mIaZyEPsv4E1oBps+zj/78BBU0B+vcorbSROZV1bWTanqjwdRu1j+pP7XRFb
STMj6gL0CXCPpuveem1kFfwMRXirLPkPIpdkLL0AnQ5+KxhmI9BeBA6sXfSV
GDiSMgPCwDRw71LAn/4GVTm2AY6Ml1c51ExFHDOw4NPFSrEi5UsFzrqdrqe7
Gjgx0Xplw3/G1ZQvppgJG0YJK5Tp7gBw0fglUIHpd7OWMmsfWsELWCjoF7wW
EUbrRJhYvd8xd6zXkcMgGEiXqXF3uAsmjYzxPXkapx9qHhjSDHW+kzb4uzN5
Othl/eK5+BtnGGPlcxQCpXypkpcKhVypnCsC52eKefFFrOb5Ut5Yqq2NLeHE
BhpZ72Jj20N6cQBWERc2waEbl8HkziPPmJaI5AGVSoVAhEWhnAV9mCsWi4BO
ISs+ZKoFjsUJnqZd2eCsbbao2YLDEF4GHUQvi/l8QcpL2YHFeRaL7l2ybHYZ
S2ts8pWSVM5W8uC05vMZcTHScoFTadmwZOCzAlFHbA9CYOo49E6a55OFVE+D
tZzmLMYdhNW/OsJJr3NwsP6zyVTisks8wORVilsd5s8nGA9yZMMVRn/7T1vo
oUFsTximX5hYpBb9zOEBqylvkbXBfEJNtsFZENqa7h7jmbhHuVRYlg4m2ZQ5
mCjAg3qA6zF8pav/bMGbLzyZo1aL52351Yp+246wbTHPjQBlAeJGFyJCzs+q
wH+EjdYw6IWxa4o1Y1wbliWyzcObt/0uxwe8fzO1A2aukjrmYT5MN6C+Ijwu
yBPHajV/QMCbElcovLa9bxg/RttsVeIH+JnfP31dQIG9OGoUGeQxB35ujaB5
ekz4eGfAM7zebcbAQuDBCf/uvkRxX0qESndu+s1QgsbqRf3IafiWn6EW4VG/
6QpVfgxXGx3ewsvGgwJS/0UeWEekg1/QePLvjg+itVE8aNjtsP1QaAQHP9HH
B63ZAnbAj56ycwRkXpvpSx66kfPtwdC2GHUMzaCSkR9/8OMFZCDAYCF8Pjpi
S0X30IQ6Ooq/j6dOfn7YntD2IW/18bEm1Jjslz4pNaX688B+dsqdzNk4t6rN
cjfyLPPAGumPdrN+F9BhQqTkxl1FvW1abvX6tW2q02zu5URZnPRzspMMqX2A
kiKVa88zDckZPTjz1YmrF6vjx/Kz2Gu3tUUypPYBSopU4fy0qFWcuWWYk9nq
qn1/xZ67pVHXeLhOhtQ+QEmRuhs8vrRuH3OjxkJuLharUbVSdyazNnMzyZDa
BygpUqfNgbIw2u3G0D4d3BfuiqsGc+/vTU3LJ0NqH6CkSF0Nao/9lTLOnLVK
yvBM9ppVcXo3fsg+W8mQ2gcoKVJPp8+nD7PHxVPBrN0Zr4P7fPOs+KA1G48J
KbUPUFKk8o6VO1+2Ly8f2j1pYc4nnsXu78es1p4mQ2ofoKRIXRdPDaVQnmcU
Sa/f5bznzmOm+jCwRq1qMqT2AUqKlJnvssL1VW2+mCyVxqmp3rOrFXikipWQ
p/YBSorUkN28XlzMF11tNL0ZnV6NlkxpWe1Zv55Qou8DlAApZQR/3RYe22pF
0h+ftZda362cPK3u6hdNdjvrfhipdwEl1n3NmpU/6d7Ue7crc35RqV6fyu7V
s/kgjxPqvj2AkiK1GA4enUr3Sa14FaubPZmKZXdeGs0fWgmR2gcoKVLWvDwS
S8rT2Vnh5knsGs9KsTO5652IzYQiYR+gpEhlvVtPrkv11fj5ot7Nt/oD0X4c
LvraaUKk9gFKitTsJFeRhxfStd3OD6r97qBRKs+XV31vmRCpfYAS677lWW3Z
bTOxV9VuKt7k8lLX7bO8cVtNqGb2AUqKVF9aerPbk8XLY+Ok1671H8a99sOT
q768lpMhtQ9QUqQmN4t8sbkYG3eqVhm9PBnZ0fPZUDcHnYRqZh+gpEjdtkqr
xmCqGze95cUq234ojl69pmXWnz8uPN8FlHj3TWaso6usOWoUrcpL8bxyN3Uz
mWrtLCGl9gFKitRYyWrPmfnQYpPeQJxLGbF34ehL+amW0BzeByix8LzMG9XR
S6F9+jRz6/ULu2eqpde6+iAlZPR9gJIi9eCdKoNV4/Sq1u14j8o8e9ktPdSt
8U3tNhlS+wAltqfu2ro5bHYaE1G5umZdr353+bIsPM7vE7pY+wAlRWp5d5ur
lV5uL82xos1KJ/mny0L39LZfeUiokPcBSoqUNK4pVwuxdGHN6jevryev1Zza
7Iyt3E1CI28foKRIuWXZGr6e5Ep5/V47f7Xv7Mubx9K09bhKuHz7ACVFysjd
rk6KD+fXr0vZU9hzY2CVr8y85PU6yZDaByixnHppvyjD4dlcHlithvjcqD95
2XxuPBITKuR9gBK7WPXy9Yl0f3cuutaFNW9dZ/vTYt0wWCOhmtkHKClS84eL
7EwbPRVaD0pNWp4veqPzmnmrNG8TBs32AUqKVLfVfNDMYbnw0JPPpy/PJ42J
cfJUK10pCXlqH6CkSD07lbtO/uqkvHo0JuPs5VB+OpHkbHZ0npCn9gFKilTm
5vXy5vVhcKfqj4Xb60H3vmssn3TTfk4op/YBSorUfa7blk7AWRsa0v3t1bJ1
rU3kjiK99hPa6PsAJbanBnJrpRvNtnVuvFyUTk6UxzurLdoXib2ZPYCSIlXq
Pfa8k3LuzLArL7WhdCc1K3mzcp/LJbQS9gFKzFO9+9E4+3jRqF66p9elJ2ck
LfX8pVi9TBh12QcosUI2RhcLcbgonznq6VDPO/J5pdJ8zWtMSaiQ9wBKHB1e
aaNW+fWqIC8sezjoSRc3lWbjtvFwnzQ6vAdQUqRqj4t5t1R4Ldr9jpqt5p6e
5k+nRnt5qSW0p/YBSoCUNzLgz2xl2Xx6KNTyVq81nT1V5w/9Qenx/D579/H1
ex9SUlp5Unv5eF9RTkd3My1XG1VeMkU2WcweWwm13z5ASZHqtQbVTEYqyuJZ
13yoTltu93ZpTZ+M54Ssvg9Q4iOjRUm8vM/Wqnd2Rrw+ea2UWLW7PBmY3YQq
eR+gxI67uRoq8mh+na2LncntqH+XzZbvr5sXk4Q+8j5ASZGyjbsL1hw+y8ts
Uc9JZmGmue3O8vJ6mlDR7AOUFKn6eHKqtnIrZ3jVPOtes7Ly+iq6Sqf7klBS
7QOUmFJP57KiqdmF2XDl00VvqHU6IzfXzzQT8tQ+QEmRGkwbJ5f1C6d//zyW
1WFhaerP5aI6nygJLap9gJIi9XKVe6hlurLdbFZzve7wZHZ/f+ouq7WLhIy+
D1BSpKbT5+uJll/NTwdadfFoXy0kxW5ORENMyFP7ACX2Z06m6pl79tp3882K
dDezR2cdUx0b/WxC42UfoKRItT1vUG16knTSt9XlWa5TnhiL7PPzrJzQcd8H
KHnYzNSs5fRkMLh+6swnTbNgyvfF587Da0I7YR+gpEhp906tVtXLj0/i7LJf
LTnaxW3LGelaOyGl9gFKipTYbl3d3hRqc+/uXrmsjnMlpbdcWNW+kZDR9wFK
itS5ef7YKA1b15dGbXn38FJ0XO3SPVsoUkI5tQ9QYp4aDDunk0v1JP8sjTOm
8rq8elo0H9yalTQUuwdQ4jOHVf7l7vr0unVTzopDZ3o9uG11ihrTpceEZw57
ACW2p05zzuCxaY4qnetyqT/PKtJLfpQrLs8SMvo+QIkTS+7Puo+P0mNLamS1
3qC9us7bdePSqbcS5gXtA5TYSjiTzHqPLarDu/PBgl3OKuWp+fikjIsJGX0f
oMQhjmfvNTPqPJfd50dLuTW0p6cHpbdYNNsJKbUPUGLH4VG7y589XdjZjM2K
19OWsbrv5WZXLktoJewDlDgF53G8NCRt6BZnefW8tGxKjxeqnnnozRJ6M/sA
JUWqeH42vpxls483y1b/cShq4slS67Zeu/cJY3n7ACUWCVZbObtyH85HJ7eP
tSfrQjLNyyKTmmJCRt8HKHEOR281bFe0iXnxfFHqPauTyePgwV1Oum7C5dsH
KClS6qBVtkvn3dZzNV84uWLLp4UzMoyqe5pQou8DlDiWIL7K5eLg8TTjzBYn
DyeL/t3160K7rNkJY3n7ACXOTMh3uuq8tizrvcaZXdNOO8/D2Untxs4nNPL2
AUpsT1UvK6vmqTXS76RFfbFQJvmCarxMjVVCG30foMQ2eub8pT06kZ1rQy9W
HsXKkz4wn0dOo5xw9+0DlFgkTC5b+uNKGaxM15j3M6AklrqqL+RlwiOjfYAS
WwnDxXlFUfXiSLvKzE9a42rv9rZuyFerhEbePkCJs11ctmgPu62zk+vLs3rW
ebHHfduc1S6nCWMJ+wAljk85neeiVVqM8pOHgVc7L0j9Wn8uLprLhCJhH6BD
v3MMdvO69rA4n67X7FBjNNs9FkYAmJp+Ci/Bz7ysgOoobFlzeN3H5pVZ8AH1
1LDpXlnsrYVNfigt/x57Bm3vcey3N/7Myz+Ff9vbddrvwekk63vsf/UbtdjF
qhHsbaeZHvVki3bUc4LyGmoohbX41BsR20E5xwJ2y9Ow+2rkSpjNbtVHRzSP
o6MdeD17QNCRxtTfhNsAsn+tsMlEVzPir/sNNINONliyYVGn68g7NrZOETSD
muK4DMvy6Ia6moVdtemVBrxL7WqpnqcPo3yhu1G+hn1mN5oXRLkKuCGtqX7/
YL+VO/CYyBdsjrdQwjJk8lRgiu16qPS1KGYPU8HK+yU+QUtubP9G0wCO0MYm
dcR1OP3sLb18g2a+m918P1N5IsDG9symsgqo5dfYM/XwN+q3rfrdoY+OeCsA
XuXDx1uPT52g6OI8XARsB+YZVLDEG/ltwsYmmNg966cSMZ/KpvJExjbwXtgC
FFu70aL7VUW0rQBnII3J9LArumbOLX0eNEZ/c7/bb4T9X/+KTfFuqryVMg5D
fXJlgWhFnWdjHWiFMeMtk7B+m9/9K1x1OnVeKVRrd64G8MdvVDIVqTvFGwax
QQ3SfF1JdUD1QZG6U79qagY7FvtDqXjhpX/rcVD/9KYUaXvt0XuNCvm11Fqk
JnGBXQ6HQbdFi/daxaKomY3NJrA8Ok23NvIKJl4wFr8NreY3kQuvLAaIQT/N
oBEq8Rn1fUOsUV4EUnG3BPksT2WBepMfbvSfOsELr6iRrhNpOwuLZ6pYL7Uu
s4o3zR2u2xLCb3R3r89EvPVseE9pACis96I7wvZ0JXUs3eMd7ATQKFw/eKCu
sLefhb0IJ5bfnQuvJqWaaezdu+0WZ5K/ujZl1Ep646IxRBNnauH1mT4QmOi6
o7ffLxY763EtwGQHOwEOmRBWAQ5X8a7uYRuwlNDA7plsCYLFQXUYKZKmgkPs
2QmLtX8S8A6MoKyGwDPB98jKWMeGJbh+n0JgKcR081b043XTPKrSDEbGaxOw
bTNWTJo0PdQhdOugN3T1rZ3ihAYsvkKFmHEOBfn4WUuxFG+9COqbqkNpU8l4
f5xfd8dFSYSNgj2LLbf9sj3qdY3zoTplXvPY9a8AAWUHIk/o0RUgx2B72Jps
wBYEbSiP5GOh71kGSPOqZ8MfdxrufUeX50LdG7LV1DoWTrHNA37GhFNZAbsE
7JSeZY6HlnDiHQu1CTPHS0Cu7ckos9uytcAaZwv/OJNXstCwFQ14Bsd2HGxO
qskmVoZr4wk2buDE7mAPzp4ysS1lekg8yHy6RWWUrHFh9G4LufXt9dRMjppx
hkzna5LIvcPfI8WCqxC23fu7s/OdXwXqd03f1+59fdMvF4XRr9bXw/v3pPtc
6FtbNHrQYvVNO8GgspUszOBdRA1naMszTfWbiKeIR/050q1uKjXgDDd4ZMes
C3mpMT82QRH6IB01E1bsNSR5cGcDCHyVOrQSdNqJQWODcKitGieAQ6W4a/wQ
AmhWG+/YUEmG2gx7K8quvL5mlR45dLf5evX4l/6Q+Bbeo4UXF4ZtWnFqnoEt
WYPHVM0Oo9OtdIFlgJfoYeeS9R0vd9uXv7ouqI3c/lxH5eAc9C3fXHNCSz5y
Z0DkkgRcQ+rnCPxI3U/W5EQykAjwO6ns48VIdW9ExJOm2rxUZNuVE8cfvMnj
eO/NIyCYHXQVtDk3otGbCdtNMqrrD1pAm2Rx2lhPH3IMsp4cXJI9kem2WexE
hQ8DOLSGzjsic8tN9lw2BVZTSojcbojk+4ytitlyIqNvgZcFabRuh3S1g817
5vOrJtYP/CtQiPrcPA3eCf6EN6g0m7iUdCragaR4p5ur9oE7tJE+wcUea3nC
rZGIJB15Ntkd/hbbsGA4htiBBc1VcmNvwimF3UIj0/4Db2dEVe6m22hNfBPu
mOnhBYN1WMHPDl5iFW4evEFLBJ2985/w+9dz8BuXsAKegVo92ooAWwVEOk7N
lBR24Aajkf6VzmboyqwrWx57sHVqr9i0UYYnBbEkXCqgzxAA/O3o6OEeC4iW
xQdtVfOttiDlsduyzkzs69vlPBl3OcZyfjwhn4OPiV+IM/4FjQ7u71ieoS31
TciWwXCduWL2vdGjvRAibc2AYZ3U2LLGfksaVUuB/gM5J0spzU0zx7I1xaFu
GTj0DZj6x0LHBVENf0l5UeLjb4xMQ9KlM3QZcAfvhdCMYAviAmq268FmQhjb
AERRxz6lMnCpKfxF+HrTuewLPc+AnbY5FXoIMsFyRYu3dArRbsHi4m08x0IT
m8Mg4fiwDBkgHPura83wroSVac1AE0Uan1lIJs0Egyc1stPZ2cwa29lRv3fm
OTfWOHfzMLy6/g0tu18IxLrBVaDVUPPE2iLJ0T5hTJ1YCr/97cfNMCtunWPQ
oPh9uNQRC0wF0Oa2s+MiuMNj4StfsjgTB6YW9heh1laR1hzpvJSrlMu5THEQ
OF2Dqk+ngTUa+HdHqwNwagdAp/WDRr19WTuM8XUdFXPou91j5/AeXtNhCJ/r
vfve4a69hVGtgUNvpnkvzqA1DHpnvN99S7eGwKTgAGpEUxR/LaCzAVuCJG8b
7ADYzp9pa+8c6jDG8Nk86O3xej2+h3qFYqVQKgza2PW/53f9H2wYCQPNHDTJ
dxq0Os1BnWGUZABTiNN32z1nm1oXF5lIvsbSczLZBRumXi3LSHnYA09JU2gi
fVs1c2VJZZosyt0L47nVnnRflpaiSG1l1SxNnXNdZuyMjZaX+WGvljXaV6+L
q+urxxbLqubTTep1pLPHmmG4IJuswUWP74tYJ5pqR7jiFlUPwxG+GEX5QEJH
iu6aWBTHl0Bpyd82dxozTfBWqqB1bRLkWUk49bA1fLA+aIh9NGwLYJFsYEwx
J22pY3WwNCbP1w/azUA+f1Rf3Lt5/ZQ189+7bTKVQj4rVQbB7ZCDm9YgSphB
2KKHL/SYOtoPqh1OQ7oj8acQaXMuWy8wi8LFkBPA0p00/1SEh5z7ghZ864b3
KDvp7j0xk0nN1NEWdlxZnuulhizdHBbarxPJmEmN39xf81K54ovVYM6kTvBy
DviP2WwltMEwjtBBm2prhJkZw3kSKCL6L4SxgzqZKHWQPGsVBrN6ZlHh+7ER
f9noV0rXjZUK4oZbiU10kDqI298zqc39FrLVz9t2b2j23fvurnJy9nQ6qLem
T1eqbj6fyLdspXuT4cv1P2jftS33pln7IXSSKpt0+jFbb2K59kihBpeyKBV2
9hYHq8XvVRZrXp3J7N2U9fb9jfa8PHMs2JS5bLmwbVMSF75DmJBbnTRhHTLv
R6n1Z+/EH7Q6wei0QOq2wTaaz7+zIq2bl5Vd7zTGjQWsiJTLZw59m/2q9U/N
pxqbjX0uzWwlejI6jMsvA0+qzB9ep6gu8pm8z5loSDoTaxYnQLRdqGPKysQV
VRAd2BRYZXjr8dgGG9nvwC2bjgZv7GrCKhUKuA+A2HUOQujhJXFgZl5gA9cN
2//90RnfBAEwEKlFWAK8Nitcgg218HMmROS79Fy8Gi8+B4seiqqKsDdwLURx
fYNq7EvauFMXO1piu2n/rhrsCbuv+TDI5bhQk7mQFmWweimS56R95Heovq0+
GY8OYM9Nbzmi6y8o3om8vKu/J4GBsT6v730aroRTWAbwNDAeQT6+bHJPDm98
OBZue1WkUk4E7yFOKDxy3Ox6+Y42k8oFcCHKgx7G+8CN017pl03Xazs1wqhy
LQyVv4liRGeuhF/4vhAwfA0b7QoXMgW61gRuhvSLT0cxlRF2eY77UbmMUJ3Z
mr5HxHyIFvlKvpId3CAv4fSRl9B12uhPOKjudYfeukE5d/I0cW408eTp9Fxs
vTybi9brpKSZQ931zjr67O75pavfz4r3N2q3/1QsPpVnYvnxWZbZ5Wg4eUjV
rHbx8cSbymeenBlPXTzK4OfFmoGYGDMhk/mSLX3JZGihwMnDq6ZQp9HleHT9
1V+CsBORKsgm2CJbNoNOMr6PGwbfF8MwQxfvEwSn91ioyaasysLnOV8Q/FEq
xVbk+xYkK+WKRSkz6GMTUbS0/NcHDROGskwMJQ76N43B5YyZg54HTuI+AX9m
V6zlTBqpZgYVXaacw7f5HVO7KBDedinbb6gg+hpK5CACkXEB+7O3MmAzahjg
N9HkE/oYCgovlw6kuzWKNM6F13oW7LSNQI/liHOLcKHLSdJgncGzjQ0gFTfJ
vSW0swMSLSgP4WyzUiKfcdmYHml4zQa/uyNP/87kpeKA4/8v2cy/ZMvSv2Qr
O9yzj6DBCXnV6Iu1ywveslX6IkgFDJfyPtlCI+iT7d8thudOyNP+lbPr8Ubg
PjI3NdZQX2DY3oQNA/sOLYsCRlO3N94mgPwiFpOnKn0TzmRbd2xvAiLXb4xM
pBd/CLOj9ClkshSnAS9iVxAMKfp9cj5bypXfg04htk1dABIQmHaAdqC/Mq1+
t8nDx1+EqmkiDwYOoH/sed8SPvGx4Be69wF5P2D2T2vcx64xophyyuGbwkGN
Qezhmxy/4UVVvzJagXPvVezhcSb805szz47GOPMiEL8r23+vFijkSlIhmRbg
bnLzJmowF941mAs8hD9h5iv8Px56Y7/rmBitvDOhdyznwjbLGTy6kR3c3ROY
TPtt487obDy8LOXP3TyIzmKmkN8aRfrYlD/TyO9OvfRTpk5xpbch+f3TnzyU
wEJsTC9K6CIVS0V/9hj5MN5EPn7Iwv/9nJzJ5Uv5XCm3O1IRxCTOq2eNPxv/
71s9HU15/z6ZrccpdHryzmqevo7OZ0NzomeqGIKQpNKO0MwPIUThpxAiFqPx
CRKmNawz0Phfuz2h/YS6dC+t0oU11hxk+1xBCjzigD7fF6spbMRq9pIvL76h
4PfFbQqRuM2P9ha/I7qza103ojuJMN2/msVstVB+aUuVbgdWM5stZQKv7m2C
QkQ/77ycecMCzQhNNtzD5xFA248PffCBVe3gmeMQg71mhFRB/hmln/HsM66p
fUXdAkeALNKsxM8H/v0NQZBBiShDfsy9kF1l8tv8V019WQwzk6Y+cf4bZlz8
enVujKa3p0qu4nUnT85Fy5gtxZe66NWs61V3rHdm/w3diKLkRLfFtlPuD3KF
xr/izoUtu6CWpHRwzxD+HSd55R2KJx/rDUtue8sXOsSZa+vhvcOY8e3NY1FS
77QrijKCajoU9oVYIga85ajMWB9FO5hH7OksTXPbEVoBwaKyOQhEA09wvzYv
e/VGd8O12gSM1D0BV9NhunMsnDB9jA7cNyEnCaeyKUob5H7rYe3ElPvRrXar
edINdZULZN4mODah+EknRGrK93e2QeJQ0tki6Pwsd8qyGWlQzHgVljF3rA79
mdoc0FOLWamwZZCUPJdSCzY0fqTgyJaQuv9wwcGNJDCKiHRStrRDeoQMfZXJ
u+enSm856v72cXGRz+V/qNTN/VMQzyealHuPaErPrj1drKzSYJyAaBSq+ZFU
Kwp1phDVCu9RbQNQOjGdTvgZ9mB93ztSqyBlpeJ71FoMuvZzl7VXV+UE1CpU
fiixsh+n1Q/mMIrqhQVtPtUy2feoJhXl1pNoPWlqEh7LVrJkD/31i+Bqrs5+
/RTNwQ0SPtk6FzeW3Zog//XTHwc80bHq52WGaY5h3iZejE41D7C3PdlerZNw
w+xUXufi5zP/U6TbUr0CL0jC/OLgUiIqhdtIp7dsv/aBp6xavARRkPEmQRNL
V4BXJ5jP5Pj5TG/oTJcYzWZYGoelRTMbC+Vi2eg4CFVAyCMWZuNrNpb/2c4X
WoFfuMW2w3U5PBAEvKUaIxz3kX3zkT7EOXa9bD5fN0/PFSazop4fXIwfTMOp
PwZgyUr8OFg0vdLF8fBlmXl4LN8/2u1cd5mfX5bNrOidjUOweP3Wx6Gi3VDW
Vy/tSWVVGpzPi0NJe5jMbl8e7VmmmwmAUnjg41DRR0/3rbmrlxbj+evi9L6f
7WSfFubE6lyaj9chZavVj5NVlsfp55Onu2npcdVbzOTmy0qtjpb3udz04ukq
nP8VGmS8LiZWpINy4KNjzQIYYqzQJ60WC/dXci1zP3y6WSz7J4pu9qejUs+g
Rs44POV6ZMk95DnbX92JzWRV+ujQ8hpA2hu+lryHmiOKj69e7371cHHhGPej
gdu7xrRE2AA+9Oz3QF+2J8/VSn70ytTi5UVnfnUzXvT74v2NUQ1oWe91a4kI
pxqOkr6uZWW1ozxOl1pfN7WGopTG42m5eFINF2lL0GA/4HW44Kpjn2YvB9cv
ysVt1ex2zMHdJJvtGPddJYAezf/58TlDoeC4eSM47JjguG12b1pfEnMA73D5
dH+W8brdSvZSXehXw/HDyfy6OqvPWOF7196HezO5KVlS275fjlr10fjmtHtT
LNycTOsNH22KYSdFmu6NuRgu251FpT1YznqPw/HocmCW9LtOk90734nzB66j
4Yzaubj5sCQBWyw9KJ83cjeetHyQipNx63Rhr7r9m8WNJVfXKwxmy65TbN/H
pHNovvHjRta2ZceNhBfx7oAzTkdUbZoSx9OSVMpmSlIut4t8iWD6t++lc+CB
ENL9au27EAWLf41gJZeVKt+PYARWNpMplsuFTLgAl7Wr+A7DylD+PYtsNHgt
PFeC+fjTjEzIUmairOspOm10+LjwkRh8FJtMSSqin+xDySaGQuG5wfqQCNOQ
+NwqeB/oGnTuh4HOl3NljMzSEvjQ8z8MeiGbL+YKsCidkQAmNhWLRcqJscht
LoO+w12HxyCk96g6H2xWv4CZG6u8mI+XBfm1bGSMHQszXv6kM+zOQCNQiSsm
mNjakFcfH8T+CgxtXm6EdZ0LhrzFKNrzYddkM5iKk07g2Wz7/JAq+IRO9aL6
pja3Hysbx4tMTYu/yUsjsbL3AAuThqDwEEpVCWrzKO4DnoJJZUpM/fXTCNwm
Bs5E/B1e7I8VaCbDEk7ZxhJprGNexetMO/zKTy1ovRH1I0Y8twTrMRlTERli
LiwQ9SgYiQs38nQqZjWoPNSv5X9T8exfBMurWVXedGCGJShkngfl66mANn4t
O3WVcHiNZeB6Ye2dwztK8FMvgS52Xd87i2V4kfp0wYlcVcovPKb2Jc7mVaVf
qOBzoTkTv7qRrhhGH8YvkiMfgykal+8+560LaX1PQwudGr/CEksKHXfdMuUE
vH8b6djEVhnYugRYaiWcIX/IwqVmyvCsbsvO1PL/NdeUg4Ojo23Xox4d7bw3
lU+HNh7W2nOEscYPkVIska8yYklLsRMOTQxXZS7rHnmUSnQL0pzeVnHT6NR2
YwzzQi5Bzgt5lG0hnmbSNfXIUGsW4z7ehOkzfB6UylvmTnQJn4atKdilAlhO
R3KeehML6G07f/t/TPgTMJ2ChLnx1BX/K1q0jktke1hDDi6+MoGpwBK5wH3C
GV7PbMOf/WcZcxTbwCD8e9BkQn9iGY6F4B/Bv4U5nWoyre8VeOy6cKFNLdOC
PQJPaiDmVsK9pvP3q6ZlrgxsWhOtyAu6Gdg4Rh0WzhK6YNHA5iGGgElZExPv
H/f+9n8BDq7rcGgnIM2BkdqyzrBNC6NeAj1X9oY4kaC0HnuCrGvphbf/QzRj
xfchGc49i5BWbWByQEknmpx54JXLK6E6MUB+n/3tP//2f//tP6fwQ7T2njCY
TTRMfZoYGhvT1OYrVbicyhqRG+aJ0FF/yLCX7i1LBQDwqPW3/9dGSAyWReXL
AGKhJ7v4/qk89YZ8JbGG07UWzlRbr00Ti5aBJya0HMC8IMrq3nhMgOtsCCLa
0tmKdllwYXbN1kB08Q1WF/lfH91VJKB4CyFqG2Gv1ptsDSsiMvbsrbfsGWmq
8HO2WSDuafyOZXourPMErDYmb9/sInE/4NTksaMtW7CNPWwcoe8oE2vETA2X
/lG20VKesNGIFvRc9njJ7TkoniHwOnJwS7M1dQKCvAsormSDGBMoCPYKWh6w
nC7x/allytQ9pG2tkEXg0Q2sOKho4USGTeDg6tpsBCqCFpX/p7+i2+qg34h2
YZ3Ny4u+w+u0qfMRKa1sBv8b4y9SKufn+Wm8YVZkzNAyomgedY+QnY0hglYd
QZ+ZUIGcAU9PgPdWMNcTmN9YnsvmNql1AcLCEM6sIdNgkXH6LYbhM9AaB+Fl
52S/OUF9IwbCjgX0ao+xYJ2H+ni6KG/uErAnz1DmLSGIRIGFgBUgBIoUdUqo
Ctur2NegqA+JA+YaLMA/oBbglxkYyr9KJbTYtrY1QeRG2A2Bpswz/sIWSJEM
ZeHzpzrzXDztI12jTDxz7IxBAmh+On3q0+HB/w83HLBikR4BAA==

-->

</rfc>
