<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-27" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-27"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="09"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 208?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>, <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how <strong>intra</strong>-handshake (aka early) attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader intra-handshake (aka early) attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 212?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published CVEs/GHSAs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">4</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 850?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA829yXLrSLIouNdXwDLtvnukEjiPpzo7kyIpkpKoidR47BkP
CARJiBgoDBxUmdfepnf9A23dbb1s6x/o1d3Vpr/jfkm7ewAgwAESTp2TVfXe
zUyBgIeHh4eHu4cPoigeOKqjsc/CTx3DsSRxIhmKPZGmTPgkTSWhKVna6lCo
OQ6zHclRTUOom4atKsxiitCWLH3kasKn+n1TzGVyJTGfL1XLgjkS6ve9nlBO
FQWAJ9hszixJE0xnwiz4qWnjK+5McEyBLWdMdgAYfZHNpDLwg2zqqjE+/OlA
Gg4tNt+BXTxGPx3IksPGprX6LKjGyDw4UEzZkHSYp2JJI0dUo+DEkaRqYq58
YLtDXbVtgOqsZvB2p9k/FYSfBUmzTcBCNRQ2Y/APw/npWPiJKapjWqqk4R+d
2gn8y7Tgv277pz8dGK4+ZNbnAwUw+XwgA47MsF37szACYOwAJpU/AMAWkz4L
tdtm7WBhWtOxZbqzz0KvWesfTNkKHimfDwRRqHUEaQyj2vjHJi2kNS3w5+hi
HMyZ4QICPwuCB/yhhX/w+T3AmEBpoYU/4WMdCIGv/MaWkj7TWAqWAp9Lljz5
LEwcZ2Z/TqdDP6YBHIBWnYk7BArp7kTSdUkRXVvSJdGWLEWy0rvI/RN8pkmI
OXzmA975eYpDT6nmTkDp/Uuamjg6DHQguc7EtJCSMKggAIdonBt+6noDCnc4
oNCjAX+it0xrLBnqG9H1s9C/ExoWs2Hpj4UWs3TJWNFbjFMsmPiAME9xzH9z
XFHhX6UU9tOO8e9VSZ4wW5PmQsMdstXU3DV43bTYA5PmLDIkfiX9pvDPcC12
DdAzjfHQFE7cXXB7QK7xRFKFlisZQs0A1hqZMDfaVn0mTwxTM8crGD91LFw4
CvyzPlENKYLGUHOZYo4NGPO3MT7bh0p9wozxUjWENow23oVPZ72/IkNIroUc
br0/RlsyF8wQcNY/bMITILuRzWWKmWKhEI/OubQCIWrJKoy7E5+F6siTCPQp
fJJi/JPfbPo9JU92AW+mhHpK6KaEB1XTmG6/Q9Fj4ZKhANZwi0SGZHNJTump
BQfz28wyHdNI6TsZtiuBeNRVTZUM4CpLHQN5FHXX0NftjnjVbbZqkbFmE9XU
2VhKWa7hqDqLp19XncLJMRFuXNjeK4OJdVPTVGPnVNuSPalrpjSFSct07vQc
czRimnAhDW18CIspGZISXU2dD/HbBD6X8fN9uHRgzws9eWKZ8nTX+M1u56JT
E66RerKpHeOIqchQDpP03xgRb+a9lZKAdgcG58E5yGlhU7ynUJB9Jjh7jmp6
Y/MQPgSCwOKIdPaqzgqPBTgLvYMTjsr+RY/Pgg4o4cw1mICfH/OhJGvMnLXE
XywWKdiDDM+BMXyQMpiTnrlDTZVp+ulCppLLVrOV3GADO0RuEMVtEMEMfxyo
xsDHbACYEQ6B1Kb/iYA9nJ7A7ncpT05Hf7lP+SI0+vxMhG/OJPnVZc4e8ooW
m5l/Bo21VQyNvWMOD9UPHaOE0w+kVHSyHvToULQHPuOb/IFHvbpZN3ueXsLJ
IKi2MHc1A7baUGOo+FlMk1b4jiRP4TdVAlUQpke6IJtNmE4qI34KipDtgd/B
lfKcpQCJNOBwy2RQmH5VlV82dCBhvQa5ktBFJqZ1gB+ad/cN/mq2VKhU4mbZ
vOz0av+UeTJ3rqSYodpwMriWOcN/penv9Ab+cVNttXs1EKCyaYu1TpTbv/9E
wnyfy0cRiWV9VwOgc9XUmGPZaRnRTdtMdnGDpSVlrtqgcjM7TbOZj8ZjUZ8v
l6I+Hpf374W7NVCBKAAa9SZFcpsk4a8J6k5126cS6sE6nK5chdgims3ImhDB
qhjiQQm6tk9BUDxQGMH51G88CihBRiqYRzPJmYSJly0JNXfs2s73p15htsyL
i5fcUlwuC/8g9fLfgXoyHLCSLLOZIzTnYNEZMhNAAZoIhgrHKdNnzoosLLAO
HQSBUttyGpIjodQF3UaodRtgPN2LvcvrP5WQVgnYcFaoiC85a/FthGwqY6YB
t4i9FdBHt6P0vGW66URMPeQ1sCeRWuquHRqeeoJ5Mw8Ne4WzxsWznf0Tn7yM
ZfFFLs7F0aI82T9xf3KCN7l9k97Ygy2GWwmXemaCpgHDCopp/LsjKMxhsgNm
uQY8BJYxUGJow1cuUubPmbqeex2LC2s5FyeVaiXR1NG8F305AdqgsxI5K2+u
OS5nzRMXqrFl+IedIChN6qYxwm3jqCCIa+gvUGXcg97Ikc2QhYPeiFFGUGVF
mQ1KaUplzojOWHyQ1u0xUEVy0ss8u1mevtycnl3ITGIlrTC4HD8aut14Sn9Y
LSFaXlvqXAKyixaslbbB+v6Pwm1NRKEhT2DZwZJkgm4qTFBURTBMR0DxGtkf
zBchsDNQNuC3njgOUyIv9GALMXTWfIhLfHTSHNf9DPJSep2LhTzsDatQze0n
iA9wixhjcw8hWiYu9/TzvxpFxuZ+apRfRguxmLd0cTaZfAs1mDmPkgNmoklz
JsLxM1ctx5W0HQSRmeXAuYruQFtYMItxypgukOYHUWEbr/1UmRVHM3FcLYzh
H3r1m6ii76WKrhrqvxxJEKmYg7T6qoNa8gJqSU4ufQM9LEeO0gMEJuxSUdZU
dJ/uIEegeHHNA86aV9dE0vxwqkRR20+U4qsli/NKuSDqy/ny24giKtIeYbLb
m/xB9bYBx4OFBPGPqTBhSj+aMDNUXYsLELOjSTFGf40ljCO7P4Iy/at6/+ru
n0KW8bjyKuqjyQTUE0v+EFk6DbFuqbYKTxtXnVQ2k8pmC8V0vlyu5jKVVL5c
KeYr5fCLu1wmpHqgG4TeQI0lopHUTX0GCpoBpvQpOrxARzEkbYWvmqO9TpNL
cx7Qqviu46Rer4shtShN3l1NtGdMFlVFlAmzb/GZwC9dE058aSRFf+inQMe0
8KHFRoB7iIKZarp3ncplsuUULTP8Kt7WokQDXpBQxRWGrgN8MyYXLd5aOWwM
z9FgtHbo/gay2G7v0h4ioa/EtZmhLkmVAwV3BLIftIG05Mi5YnqG7j2PndML
phoTU1P2U6ouWbBahvAQfvMDdOyYhvv//e9CVwUBDFpj9McnmL89ERrwjxls
Oxb9tS0ZBsjlvi1PzBFMZLzxsWQBZXoTNoKJbazRxNQlG7jOtmF+G6iqcBaA
EX5rqs4bgD44UP07Ac8fKzZSI/6liHqvyPBSVAwtx8feEjOFzRdxO0feKL37
RvW9N7IZ/w0QDm8cl5Ekw9l3kEqlDg5EURQkMJbQc3Nw0Idzje7PBEnVbRRc
M8tENVFw8DYEtAQNjS0wBmiTfok61v77p4SeuMNj4cuGx2oN4+NeLgATvldu
qU7bHYJY5QJRqAUCUfiEEtE+FBYTWOZgbmQtSlwqrecZqMcw0Ym5EI6OyHlx
dLR5K874rXh4Q46IQiDxZkhXVWbHAA62xxH6L0zY2rMJCDocBdUM2z5CcWKB
TsusY8FWcVQ0OVXDBSGzaeaPyQzWYHtb7NVVLaYc70Qu/JmkKDa85MKWwfEk
awUD4Jm1BAodwfC48rDlXc2x8RZaGMI5BdJ3uCJdx/f1C3/72y5P+B9/HMMv
XJ798QctBn4loWaJvLbnMzo04H2gE+IJCuFIhO9E+E7gkhpAeUeCY+IdyrVl
3qOCdiyAIgaHQG2G96ViLpURNKCyYTOyfAGuZSqurHJzmhCyYD3ZgnPKBLRP
YcgY+pemhrnQ0NYPTVZjc2AHRGrKUJqBUpMS6q4FAtLRVsf4lsWITEdHzsIM
Yhj8MIdjwTQYKRf4tJrKiBjJAN/Bu8SBwcvVVDb6sgeickzsbGy8Xk4V+Ay2
Piml8gJdwNgTmIk0lkCaOTSdoWVKSKtN19s+3pWRC8kzqWmCJq1g8jgKgoJt
bJPzwIvWoEWezfxbnxAfcW6ZSTP6mrxxNqeY7JNRYCoFgPCVXIdaoEtvyBAB
OIPgNITp4JquX+CDrJmLIwfgveHw4hIgCDBN/JhchogpMLzuGsgP38g8KdAB
BdO1Aq489vhFB2ojwlEtkDAjAkfoCwJ30wmEihH5l2iwLgjYfydvKbzKgYe0
SU9m66qiaOzg4GfSSxFfCvjYtz8F7zyHze3LD1w5YA1YJlhJmtEbo/l8lFHg
65lpSxqQwWJjONxpSjDnxYTUFgS2ojXHJfBcsrZszkikotcL7S7LgTeB7GBf
pYRTy9QBQ1+XFXA9MSAIzl6+TTxGnAJghcmqzYWt7Jiw7iglcJkBcVUhHcpz
sesg0yU4OHTQQUx9x3M7jOVuDGnT4az4u4RtlA3xsTRHPxnq/AAoXugl4cFj
vFuBH8MsOXItIrK/2YAvaiCOuFQnHrRAsPM9gaj4mnqYF2i1fTVdDtR0+F2k
MXZ762n1+ew3pTT8/00SRCyEhPMmJCJTx1kaPHAsMlNvnrAx1vJlS7DAr/AS
4ozbALVY0x1Ptibh8ZjCbHUM+33G97JqxJIDduLPwhVIThQUBx/Yh86afMji
3AVDRzW66TZwieFpfnPkP47HkgtSUHVAD1e8SAV6FrFl/WAEUBEPfgeDKyX8
LpxsDgvP7myGLAL/VQs2we/wRRY/qJNZ+l//43+zCaZhok7zO2jZvwtfEFlm
Zdeq3jdddacdizF0TBtpD+AhDZ/bGD48/x1o5L43GjmORh7RoIBJDGo0SYhE
Bs5/74HzfOACDtwDRmQWzZ+HZZDIjIxf+N7jF/j4RaK/qcNDTnTg4Z9zxNY/
56MoFL83CkWOQikGhQIOv/cA3onQphdBZwwtcTs91MwhHx7sQ4ahn3a6K1lT
1751lVXKvzUCgwwdNbIctsxSM2V0+Fcwofyr0XkmVUnlojaUbdii6uDVQmlM
qCxmIkIF3k67Mw0UOzuNNn46m0s/MJyuJdbwmgbvwwBFsY/fivWry9NOo3nZ
79QuSi1vZBi6Xo9cGvU6rY/M/xCUE0kxyTkKsuIFr96+xEidnTA3qJH2JRAZ
sDNTRtKsFSF3ptC9H0rKNThJTenwCsEjODIcMjYoaDJLz9CbBSYFIIgGD9Ii
MO3EBRKITozDNTOWvjczljgzlncy4zFshuM1R8J5EesIgJMjQLT8vREtI6J/
+8ydUL/8tCXrQcHb1GwRcd8YW+tAP/1xcPAf//EfBw8ssK0l/5CDBzBx+P9g
mPjqHfyFRgaZEUMwO9bn3MGOc46+3X+2ubjICOtgy5hE4zGErqF4uiuip6uO
Ol6fhPi9otpkBCHD+aiG72dVBubglYtHKWxzNA4Y7Hz4VHIE1RF0aXVAtwVA
BVhQ/zoeFB4V3oSPLBOtq7XdJMKkRnD+C5/A8GSakD8Mps8nFTdtSQO9GLUx
0BYwYgJGhfNGM4HDlQOuU4XCAI5ROUdF1fCewKmkA0hUiLgn2Q+5kNYXhAcj
rpYr6oichDhFmAwO2+NGoPcpjO9N3HYtFhAEJJYBQsI+ACqooCSgZsWJi4dU
iljmAJkGdu8Mo/eHcGjiImgmqhg4QOR6/D0tB11adGHD9ZO//S0SmoIOB9t2
4Td4zzNiwdJWwIQ49hxD3BHCv4bPo04r+D5k6nPFr2sqTMOVuiLV1N9B3YB5
uWstaiy8urBGwgh9MMgiuFa6qUQVQZwUQoIR19SPm/uOfTNcCTbu3xUaM8YY
f0WugiG/goxwpK8C+pxBkpKTgOhR91gBo2ZpkQRPjiLnn5JHRPgijcdo9zns
+8mjAOQh+b/QiUESwjNPlfDeVXbNda/ZBatG8VcanlYYrYbeAH+OruH9lfIW
cMSdPj4SZHr6WvoOs5J4gMI4SOELH5Zhn2pUyO92CxN30ubjZg8/L3BNUKJK
uDNCN0ufEHu0W2GAhXG4c5xtjzCMEThFYKaauSDJuTAF8jUQl4BE8Ha9L7/X
pjjYBaDjn9DZIUxgq5ErzTujD0D/vjZB6djNnzOUx8E3kqJ47h0wOaVNqnmm
nMBPKW9tP0JBxfQubGcomwFCNFhRsj0PnopvgdHseYpA2FvMAaPZ2wV8XPL6
AKIq4e8JjC3Ddz/foSePhd2jZHBZY1cnO3AxWQmR8QmrwEtLLvgdkwCee4/K
cA7t/vaY3y5NGJ/m0ZE/O5hR2Cv83okLiLrGCyiYeGOu8F3QXMKJiUwi9FzY
/hYd8p7rVOjBhy7Iwp4fIQ0QhhJuZYD25bLT68OmcixVttcixZgrKdhkTmps
ztPI+qL3Slqe2/ZhCm1UEsZo9HhgwWqldCsc+zpwiqKXNs39qaCXiaIY/B+A
8J20qKsBDPLNgykr8N+y0cc5T7GrwH9jyHfwJqa4BY/8twrrR2XPPEE7qMsU
1dW9T9fa1058kWU+6JZDHezo6BQ+QLvbYt613rHQhncdEBroEoUd4B9gR0e4
cDA7TF+zEZGfgQ9Fmf8t/IH0RSTwHkcISH1KW2MXIbdPW59SO5OrjoXtnCeu
F58xyRDBmlKZH4QucPhbx7FP9+81wMb10g8YYWe0ozdOYd84wg7y5ugjzqC7
P6Iz3M/62gUi/+0gtuI1PVDBVuLGsIDW8F+FULoknGKglaxhktv7vTlvhAW+
R65vXZZQwN0PH4KZ8z9hDP2Hj2E58p8xhqhISTbJZmAPfesJ3z3fruUwCd40
3ewlkL7cNe8JR1AKPpGLGV/CTDFKJ6QzxLQUfjx5d3aggKHg/hnsOAu0Gm5Q
kBLk8AcYyqnheYnGHWhp3DjpMTkFM8oipL16L9fi4cWC99r6KgBE/wlbmahU
ozLBb4ZoHhqDCY7pHuQr+lKa519RG/Yzq2P1HbrnAYMCtCaMB6PLZmnmG2+o
lsBio8cfFUz8CPM5BcWlW0f0U4bwANIzvOCarbhLATVieA10TE1yUAsLq36U
akLzxexpdI+Rt8wCHdfzbdMLQ6ahBQ6qFRiZYF6BRQDPw7NXTNSEMTsbx+fp
zceUyxXKKMBp3teb57gqQBXQeegKGX8aqZa+QBuPpgi28kx0DRVY29PxOJKS
0K+fCF7IHNmeGtvIjp95s1x/ZwWWCJpDcI73bi9bPu5M+Sui4Dsej9drh+Mh
AT4164eNdlPw/GPCXNJcxsE6qxnyphbQn8/HNkcOzYVx1Y78ETbFhNClaiik
67679sIIY4DrCFc9XELZWs0cc2xJM7CvRU0dWsgUFiAF5MHwCzo/wLTkl1q6
aQG5fTp/vW1eX932B41av/aV5zmg72R9Yc9H4hdWsmnNTI47RUURL6pj3C9h
RuEB9oIfjsHvmzHKygKN2dleyL8S8zNYQR4BAGRTlXVaCqWquKhROxRJC0vr
W4lE4GAgjoNPojBnM0MiNS3EhWRzw7ZglObClrIG1J1zrxKzw7YhzJr7ThR+
b87XFpiaX9N9vWief+KccPg1vBdtQEpTuDUEbMaosgGghVaAZNtoPiiq7JCt
ya/nGJF2Y5PKkmtzmilshIkZoOt7czsWZHRQKfQ57UMRQ0uExu1Ji0d9HONH
3LBc8xq87ZOeJg/GFsDFYJioFPAjkIpiKQf/L+o9l3SFZ3IYad8vbKf5BaMj
BvGSQxewctD5oCuiPRTLmWKRKgUc+k5Mco6ZBm5ABpgYLvpwYFkskcIjQIS5
miehPwvSaMQrWKCoeAYTq+j7TkxyKCC9AZBroQ/LdkcevbRgO3g7kksOZpH/
4etto9dsNr4K/PKSSwpidgsG01bE4hJ5oGyXIoo8j2BgCSPn00lDFh7ARgHs
cQ9gKvauRWJ/tAFJpFBm1Qgv432/R+Ci3w545RalwnTYJI5FoeTc+acwSRP5
xAy8bwGmcnXvRhU3DeXRojxe+D4OunrkcSd/XfODrzlS0g9McYKi7wqe9XoX
/24LX0URdxiNBCvLlF8sRZ65X4VPX7yXhHyqCCpp57LXr11cpHRlp9PKhJdt
Wwv+TRc83h8iQUivIRwe+v5CnAnsgPUyAe3gv29rl/DfJKOvkaKIGKzazAXB
rGqwmYlUQOLATYyuLWns2/DOhHPBBLQTLoE9eUErBUzIKETPP+v8Ay60M7lN
fmEuxAvyLHel2cxzJyK5udruKRsHp+oYvba5WGUitCX6zaYojQ1QHIA5/JUT
yYV94IcUUqQAGqOSAGvMfxR4INaG94lkjC7NbO86wAtJRG4F+UE35ibFB/hx
qSAu1vmSKPzDZ/PGfQV5CWB+KZgd4z/wqE9QBddAPvi/3yMjfewTGF7c8T9h
9+O4/33TJzD80dG1H3PY5d77oyOABfMW6UDQfHIGKse+2XszDz5DasR+xIev
1wOdDUb2YNWv74T2g/AXoj/woQvw/rIR2zxCVcZySeSGP+FiK42L8IkrEIdr
xesvwm0Xfmve+3cVoG9wPG5ckw5gyojjmCAZhJtmzHLDQEKaNIIwbp/uu6Eh
d886qh/5Mw9BpytaoUEap/Cp3zh8l5mEa3TvYYQS4LOpgMV/SjhdMgdlBh6/
8tSngA8zUNv+QvLE19U8lQ/otB+d+E8RWf7GBjrtXjfdv46Q5ncevcs2NutO
Ynz8VRqNNOLa+dfQcL9HbsFRgsJkkCM8TmnyfKWNcVH1T9+DZkWHr2+6vEt8
XyOPjP/gifA0OomJWusU+p1Qv+WT9fAX/fD4v8MBQdfjsH3xS4yBe4ek3/JJ
yLbeOIZ8YS94waXc1t0W9yBBNuQ62sx9Lx7QD8FApXZh+D78ADYHyk0/m9t+
wX1aBOgB3bvRpvTMQD/WLXpWRZTDsPodPei4g9o/xdLhpflduHUNO63B3Gx+
L/vrTr4R+qvZlnjZ/eZtoGrRSFzp3Xv8fPQw+fiZs+9NQgGFQrOO1mcU6Q4X
EEZYLG3N7DLm18iLV720L3k8vYuz3+9rY3j3+PGS9HehRcIrUEm/CYXauf9O
5Bhaf3rqnSZ+kmQ6OFlxPScq7G9LnuAVR+AACRR0f5Au6OHWSgQIaHb7Mu13
IXQC+8O1PdUyHZxiYN9IGAy/OafgS5hO+rxxKqzJGrHP11/ULeb7EDjpej7p
fheoSoNvIsf8D+MPw47jQAX2Uh9I1oRFy0Ww+TZS8nBX7/byoBC5BmMOllzf
STm856JABDKN8ZdNXvl3TEfvwlY/+FloUH4MvH4fiVlo8HgGlJF9VcdoAcaj
aHh4Xm2diMDvBYFqNd+UvOfhCShJmnSdRwRk4dsX+AkjUlRDJZTWkRTMj6Sg
iAzTC3UACJmycCWDJYLWM+fNKAqIQfBytgDzkkMvhyuleW6WL1gecW1WxZcM
gCWw06Xx8HWZeXyqPDxZ7Xx3WZhfVYyc6J6Pn9IYmcXLEtCoJRr1i0ctjDNx
DZnwDNn8bJjyR8TB4G+MjitlcrlytgRmfSEdSX9bl99IWRTMN047jPEINHSh
yCvAIkyFXFk4ZcMQPkHw3jr1Yvv+S/hydBRcTf4itDutNpaO4nkeh0dH/x0h
ezVxwrDvm7suu9YjxcEt+nBLW3CpblEIDN527bz0+kb4X9Z8FF2emKoJmHIj
2cxOO9KYh+6h254iIrO0BEEWLsUK0Ee7iPMBjKuUGfmt+I7N/bgWU1lxbGZT
uRIMtoX02PxGhLOZLYzrW5rQt8VYYg6FRqEHX2KKO30oJnYTdnrmalq6WKFt
XN6cwf16tB2TIe/sN87I2/8K8mYuZthEkTIUXYMrynNfbbQ6YMduQN8KKt4S
CjtufGMYoODvsS2WfV/s5Lb3b/220+/Uaxce/CrsLI/B/EpIiUbI/4MjJKdW
botcWwPyi2efboXtUYMtuTXa9u3yB5YmVOwh2SB0t/wjB+A3yz92BP0Hj8Bv
lf/xEQKZsJ2MB1aid5qgLqabc67mzfaHVv0uFP6R0cbm9xsplnL8rvwDxCv9
I4PwW/XoKN1mo3PX9cYppfIx46z19kBrjkb6hnXXsNYsbajLPOrp0kspRW2U
B04ZPKSblCmMOpSM1fouYQVGN6ihJqLuJamG77gjN+8UMPn1gUlTLCz79Zj/
d6P9la6nvp5ISpOfYF9TR0foLwBjzdSUiO1C7g7TxpvkFEsdezB7FA9OUGlq
3gMAzWeqacA0puJ7Vmw/T1HiFbwpeqt555WjPGhiqjyTDOHOAB4Cu+QL/fBO
Wv3E1NkMzL5DIlI0UCfMANtKIs0hKO9OYe7BysBsQ4VQ/Pw9DDbD60VLtYHm
9D0Pur2PhtjvLxgiXKgO2nDAFet4tTkcFLZsYiTBH98/wjBqy3HlPAiG++KP
9mGYm3FzngX3ZQEmrSPN6LIlZNeEnoKhDmdi8AhTebiRjBh9+kIu/OgtKF4W
aVx78jKH4GnaxTJMQdEYUWZ4pZQO21Vp+jC4JxXDv/Er12xGzFXETCbrXZci
u36pdRvf4xY2nylkArDrgZF0lEF2iSHZRLN+s7lBLzDiwrSiRJ8NSm0BaTwq
5iKkRitaSpJ1MiMVU00HJXBKxUqpUEiB+p7J5TOUPvQn0ryANM+EaY75jkXy
xy74THqOpDE3xN5LWRL9oOF16Xybv+b/e8BrwYDp4tFpfbFeLBQz1Y+X9vA+
QBgFHgPoxbkicicgUaentV7/PfSG+OIIKy4G/zUwpSkWK9+FYylbLeeS4Igf
HCKGuU0MJeW21l2DGkqg/OsoI73/wrF//45snvWCDTBxMv8nkiublFxZQrG6
geKpNASxNmXKeyiO/BfX/xXPdNnMBzCEh6EPdmK46yI7CvlPrGSOs4yJYOZh
4iG1aPOk5FFh8+2TMuKQlIOTUgtOSv+qRF5DDK5fMPVufZAfHVFYOHkt9sYB
oOtWXgd6bNaKxpATncYVVszxBmVB7Tzs37COXdqJOfn5eYAoZrYFWf2hKhAL
hplrDkzS4BVRIzVKSDHCqjoUSH9w4MWWbaVuoMajrVFbX/PMTMfXPJJGgX7a
rELAC4jQbNYq7eHn95IXaOCPJyt8Ilpauh+LNWeaiXk7h14aQ2Xzgz3ZDfFw
KqmyEJf3UNzOe6gKn4pCLNCNnIhCZBc0112BEi5EDPUFb0d4dWlmFlgXOmZQ
rzBYStWJuWENuFJ5TCw9UjE+CnteUEQh/ZTi2j4FZjpYeiY8JjFhyO3Uid5f
HhzU7HDYVGxgLeEfW1QEtouDkbte5Z81K2+Sayud12KhtDJgSzGUff19E64/
75J/fGbb1sV77lHEM1ku/66qzoTTtzroDg46I2Flurz+Cw9eHJGdyWV1bALV
RhDdjDzLAtYDd20B7SjBNrmAXfAgU3nC5KlXkmg7V3YrVVblEWLw2EtSrHnO
iXSXpz0Dx22xZD8R61DJ2JD3OFpf6+jId4dgOpm19nscHaHnY1+9Ms6B/9L1
CT7/Kc5zpGaYhkQW3zf7P/2yVTQivmT9mtGTXE8df88d+1eYjq6OSdgBS8R7
wHglPJgjHHg488Ap5fnsgADhC5hcKvOR26Y1FZL7fI+jHM3LIHhI+dOKnxTN
Q7X4J2Nzcw55ONr9S6T3rqJ2TORDfuXvMInoqeY3ORJ64UpG9kFt92kURPlG
Ch9xx1asvDzCmNijjdMKMf04g5JkeafaRhVeE+yVPsQuA7sKV/z1IxdHR0fB
1RESeeSwwBW5hcK+TOYQGjifT3SEihjkPGOGSI6tQ09nlrwE3l11Nj6ZljpG
1QXPClSgUYUSMwXuYKRkCpuH/gMtxUzp8ADrodYwtImKoD20KKNYldUZ1kWc
meimUAQTA5m9MwurLfCTagjnXhKJ4efYS6TH89XclFEEeF0RIPTm3uYJW1+R
UzhPIdbMQqLIoxQAIOehaVmwdSQUAYf8M3Jd8kvCIIYel8oerVJEHaokFyWM
7QffY5uwVVDMbGcJC0ysCZpUeOkg2D7N8RJGMO/Kq87gV86b+LUQ0XzhXun4
EnM0kZBpA0vCca9RWC0HZMHymbx6oWfL+en2fNJHR4rKkwyAi/00J14aAHSc
PbnzPu34cEdHd3vqjuIgqmMzbRSu+oe5Fswygl2yUbn2vd1JY+LBRxp8eMnV
aPlGenF3SdR4xED6+SU+KK7exnoIjfZGHv+nr+Pl6ushjx0CIzP665A5C9SQ
5HWpDV4PBQsotAPx55eGwTikT18nji37ECk1bR2ohFVqg690nNCY2Qf5lFBb
F5rZgCbFQgsVqMGS0tLBwTXf6ljOwEs8jM8VQJhetWCyg4KKvNd8Qagibx1j
JzU+TAu34OHapx9sS+EPLA/j382Qk8GrSyJh5FW/59cLt/yUDGRmns+23zuS
ojoWYQRgNs1QVwwJF7XHl63nLWore4grFPNVqPbceh37HuXPkfKt3CGuzMdg
hNcvCiV/uGtN8onWpIui95YX/sWjsRautrKrUKZX2zca8rqj8GlszaKtA3yj
toW4WTlvwrSZHZRQ4gF+WR8/fB+D34LCMOsqhbu+y4W/6/A6GTH1mryaTO8V
HaI6TOs8v3VFjVDKE10lXfvSKPZ/v6+LBwk/Z49zx4XjUvRh/rh4jI6Y6+1Z
o0PlsyjGjxAZzHvb/4/g31j8ISt8jmNVknLwxX/9n/+rB+y//o//JfofCCX3
DpSpPNmAwv8rCiX/LpSvwh4o3n9EwtDx+p/zPgWBbuylcipL/O4lRhU/urFI
egZlWqgoiue/CjZafGXNUD3N9bd+de7dV4dxRTd/WMHN9OEPha6Z45SzdD5e
1vOHlfQMT/QHQI9MdHfh0B9WNDQ8tR8APTK12NKkP6wsaXiGPwB6ZIbvFT/9
YYVPw5P8AdAjk3y3vOqPKqiZ/qHlOqOT/FDZzh9WkTM80x8APTLTSiqsRcCw
fmH37zeuD5FP6wfCD01sx/VR6Kz/mfzegesJFveUH8Q2ndj7fuRtWpv9U98x
AirkA/q6NdIVY3yZpB8eB7nrX8g+FqMOoOVMCt1aoNGFuWtTZq0TKBRTTu/7
NH147DVNjWquIXU30p7BdsdgIzqe2Q9GPhqik9XQUv0ii2h6fZKjmyBWCfYr
yez8+fCj9fu8i65dpj8vH6MoMc1M3kMyrKNjIVZjtbbwh8xgIzV6Yf3PXtQU
cpjXdCB6w3R0tO6U4FkV6FPH1dxaxjBj0BvvTcuv5up9hNyzeVk5XJE/JeSj
9O7UeRWYdbeWSG2HDa/vd+CJrSYZZEJHHJBERLqXIj8nVVxROCE+goCYKURw
eBddz//EPXf+IsEfpsX0IFYh6rkll17qg+Lnonbe5OKnp+qYaIVTgpljnWQZ
hqM3d5Nc+KLBgouW9GGuxEei91H68KMooglCGL7vbt9umLftQMZ7dsmYkm+V
c5SfjUHLus7TeN83j7y8o4XyEY+sPSLgoRtPG2s0rQQFy6Japmv7LZoATWT/
IN71GIsdY9OGdYjKRB1PKGsUIwWUUCztt4TwCJ94JdGNeNc//jjkNTZCxR6P
jtblHkEkYMFHCuuhaBMq+YhFl1vq3KsBinjynh+yFwgShDFtonqMd9FwWFDF
XOXA85azUEQHj3CHHYmOd699UJxA7t71+geuNeYBM3hFHC92vYrR7zEhZdbm
6J/8Ttv/cV12LVplkzc1wniYT17euR+QEaqIiTcEmGHuFbiJmRZKXNVrzsOL
UNEWxMZSvkCwVNtr/V7rCNLYKwjL0CtBBa7cGUpjO+yDDlcdrm2M5hddD1qX
SUM66AwOm2yudYMzr/oSVu6hAyz4yqsK5fnE2KtLwp5u58ZYF93wg7m9yi6A
7Iru9YDjYGtG3uHilseTUyeoUHOgEFZ+F5pjb1P7zV+AnbzuLbYv5SWNB98E
JYzxMspQeMEv5hWdOQ7GCeIkODoUPIR11OR1EaIhrZulAiWwlxrVj/O+1pmE
dyMgdDh0zL7lGWqUOhw4DL0SAT6HRS5B4GW6bZG9g9cvOkfluqkGF68qgL8x
f0P6rlf/mmBn42bfGRtQwC8L5pdWSgm94EYqerO+WfhriFcNPF9b4hKMChXx
ImreipJkAVHEl08izlxXsAr1k6aIQCPg6YBaPDKKjfxyX15xPnJE9wO+5Kkg
XA/vm6aGrn+srrRV1j/QO4LNEWkXh/ECXAFZH3QqY1Qd38KcZMb8c45qMaer
FThqivlDvxHAxrG5rsPN2+NES7/7cTOh2zlAml87fhmpS5T5XnNcKubu/yGt
G7onjVH5UHfTkJWElUKkNOByyC/wTPKZw7JhXTUqrsArYyOlLYeHQAJOKBRH
QCPavtFK2u/4xP1tgLBTRB/LU3ZYcNu4CN3rYPMEZEYgHDIsFmyfeJXBeKXw
4G6UwBL74K4NJaGvm7zB1loXI/zXWwGP1HiHj1lN0Y21lgleJc1tbGkFI8U8
jwN5EGpgQWkh28rUITY/4DdlnKc9Lgg2kBwcASjUqHUWb2XJgwiild4iy4ML
DQB0vyWCPDFVmXldJtC00kAzCUm7QI7vmCMu2jFXTgJ1JMqBC8KTB156B8S7
nbouTWyQ6+vNfvWCfzkO2b1HSf3i8sUAdfa6d87jQNYKa+rgdIs3Ph8c/M90
WgfLgtp5NpU/jmzAAEYoa6qhgoRnYptpmg6siXzlt24cYbkJPPaYhoc7PNc0
dYbl4EAezxk1BlxrUsDxXvVRrzgh5mYxqh2JSKBd6xoR+5b7hzGJMmgqtyGS
rc3UcX71so5FJ+7aQSSU3g+8jKLjMREcgYbK1XpO3x2feR0ft6RYcCWqBaU7
/RtubBKjckUyEIaCYtLe8h0Y6rqZK+ATsGi0Z0iwSrwjHK/faHvX4Ovio0QF
A20kILgfXRD9GW2UmWd1AloeK6QwOUrWqPMvrwSj+Bqk33EPDJSxawU19eD4
W1/lH4Ru9WOjmC0W9O5zghYHG5+GShTzu7jKVu1iQee6mE28DToC02cTyVbf
wnFIoT1MMbORNhBUZxS0zTG/pyXh6XJ5hs0wcKHsCLrUapDPe62uRFMDbyn4
6GD9czTsx6s7G+mTyF0QO4mVwvtpfJl68nhhGqHsFPy22bu67dR7lFJLuP28
mUl5ENxmxld2DHUm3G73TBspqKbFaYjxJDILuhRu9kjiyHSDBks+Hu9VmIzF
Y62FebfeAXg/wtnbLwe1Pa0599J7b4vKC96ikgdMgBUoCXUUg6DcBrEqBlus
E09RA6TXAMsRV8klL8Ucq8yMme+08E/pPXHbqGpi9HJUsaFzgbsoLP0d2zpF
gdQoR27ZWMUAmWjqExkA/Ace1e8nqiE3pTPldKaQDvslxMAvYYtUI00M7FFR
tcWhZU6ZQQo6HGGiLq1EEHMiW8II6WKuVMoUS4eA0aczaSYZsM6HwpcTDTip
LTmXQMG+OV2FKn8M8SfYy0jclIO/pb24VTudzVar2SIB82muScbYxbAngNom
Z5Zhho/lSfCM5hqJul5Itoh1pZGnRMcUh4xmoWH7Pj5REITYN3Mlqg5M1UBf
LR3lIMUmpgJfg84mwv8hSl8waAevAxQ5kojgPbBTGFzFeELC2H+aEKG0qmRL
1UoxWy4V8r+qv2QzmUy5XCrl8rkKEflLuEZTEHuFZA4VaWJ+yWuL12cKoxAN
q/RS7TwVMn3oMdYlWzotZqDA43XUQhyGhw78jDYgwyKc9DPNeuZqNksHvqaR
Ji3EtdYqqoa4m+sirrzAEiNcGrCDV/40byn7JuzghB995vZScxCPdapmdHpi
hBB0bnAkJ6oDa4NlA2AJRYqqFyWVU6NXx6qMmhLdYra8wIc03NBS2WjvhrLI
JblzirSVUGSII+RCOoo42WjkTFa4cSXDcfXw5jHHdopqBKBOhcubcqfpTFb0
XhU7hoxLtJYcIh6cIrqoxCljMxHn6tWKhjmv9qyJzSnjtY0iLkV/smjTYqpj
w6EvqRUA6cC0aW9dkIuScYjZ8x5rXkjDDdJ5v4DcTlluGsVAulguFAvF1Gwy
IzAtBhyOUGi6IFSiEPynlNYZy1Iqs1z4gy81mDEgKjiidaweS5Kqpxohnznm
ghkyS4GNKaVkI40sTmJTzJRFEJv8wAJWVke2vHSq1SJwVjal8HRfXDWkUmGo
vkX98PiEyycMLMYEdtCKxRHYXZIIazFDGQDSFbskSyKoqXtWZYPInX4v3DqT
ktQdoG9AV9W2NaaYmMOlqaIh2RP415Q26ITZU3fliu5KepurOvpl55ENskEn
W39T9LDQs50UPeNbPy1VcqZWrWY26Yuh6WHhhEjyZ/Qhocmpmi6kQdBlM7lc
QM0QHHXEjHHI55OiBzytJ11x70arzHVXf23yRXDHY8lwbWljXP8xxxmmsI99
UByYGhNnqiNP8BDkxwVuAwpOphMQ/5I10wVyLUxxBRawjZ4s7whBy3akRtHZ
XwRrhu/AG+ngXbqgCRmRO2UZv4LFMeyZqTrhEgE29Yt0OZm97pGYXV3NFavZ
WqYIHH1SF4uZbFE8qeUb4kk2Xyif5IuNUqVAEDVpvhSii0fLhs9TE9dn5fSG
VOX30HjPCaccyFERM3pFDO7ffwLwGZgTd0NUwBO+a9LZTKFYKRWr+cIgm8tl
MoVMlisd12gK0G4g5BTViZTsCJ6lVIsz275DIHryg0itjkq5XFbMlWRJLOeq
ebHKWFUsFovlYV7ODCujysZ2vFC718L99eV6eA0M2fmMayb+nowqBP6h49Um
5KjgMnvCBE64lMLmG4cePiL+tdPTTunavHy7XtIHcCgAcUNUpL9T5GWR1BQI
M8LBXyWgnYiuoOjJiDjY/NigbOy957anLKJdTaO3MBmBhRZRGabGmOLP3LSN
eRDUYPnXV5dZq1+i/Ezfo26S0kLfR8vMyKola/A7PU5HvV8/B/AJkgw4WRoo
wWFVMfSQViRXyFTKm1EokZMar21E9F6uq3dg4oiBGrJkgPoG71rBb1xJNF5A
tAeq2UY9CfqRijtgYcotqotBI6DDcGpcSOx6T0ivIxjenUIEbdAsUTYhVO/y
gOsydcmN+rRk/gCowYEBMnOfArTAE+ZDWJ9wIxBJBpAydGp6T+hAVlSMP0mX
yhsCXLYVI6rIpPARfbNg6lI1BoVcvlzKVnNpLEIwNq3VIJvPVEug/65HN+Fo
dmixQ2QJPfQLtOziV87YXDJ5zEuXdYRp37Wmqj0BTP3WDKCDqKETJPKYhplI
Q6z1gunGKgiP6C7ag4MqgxR8k1bqSJxKmroyLb420nQY1rLpT269hTQu1Qgd
OnAqAQ9Sz4lghSUFrBVZ2D5y+Q8il4csvQDNAKxfUO9GcAYSONCZ0eJiYI5K
DAgD00AJQNcG9DccuGML4EjUqIYK94hjBnZAulQtVbOFcpFvgE7X1RwVTKFw
jrnuPeOHnSfsmAHbTg6yyqmRFhh6vPOqr0DermXV2hKne1tyHQa3ruvX1rE7
kRTFY26er/2PvkuROhhzo7oLipGEXkJpGqUfnl8wpBFoDnZa5+/OpOlgnw6N
V/lbJjV63OcoSsqFcrWQLRbz5Uq+BJyfKRXEV7FW4Et5ayqWOjaFEwtoZL6L
jWUN6cUB6FZcZPlXd1ySk1MAecYwRSQPHMyUu0RYFCs5OFXzpVIJ0CnmxMdM
rcixOME7uWsLTL7Nckg7cBjCy3CS0ctioVDMFrK5gcl5FuswOKQf7VO51tgU
quVsJVctgOlbKGTExUjN+6apacGSgeULRB2xGIRAYbLpnTQPgQuongadO81Z
jJsZq3+3hZNe5+Bg/ecpU4jLrvAalCdW7jS7P52gV8mWdEcY/f0/LaGHarU1
YRgxYmBeXfgzm7u9prwc2wbzCXXJApNDaKuag72TgCbU59W2BVDspszGEAzu
GgRcj+ErTflXcwF95vEn9Xo01MxLsPRKxAQFvnmEBBwWIG40ISTkvEAQ/Eek
QRB6wMljjd5xWJbQNvcDDfx64Ae83jkVvGaOnDrmzkIMWqAaNkGZhOFKqNe9
AQFvirUhJ93uGnX8Mm6zLI53TcC8/gLrnA+s9VIn/yL3XPDbbwTNI3qCx3vd
pkFP5RkDPYO7OLyG2Ym8xxS7le7c9k8DCRpJcfX8r8FbXlBdiEe9Aj+UrDJc
bVQT9JNig5xX70Xunkek/V9QBUvxNFvf5xvGg4bdDdtzqIZw8GKTPNCqJWCH
iPBdvd+Qj1tsXPIg0XZcL+3ydEfQ9JMv+SUKv6RABqIuV5+OjqiRGypiR0fR
9/Huygtpi3GQH/LiGB8rs47xiemT8mm28TKwXuxKJ3M+zq/qs/ytNMs8smb6
o/Xa3wV0mBApqXlfVe5OTad289Y2lGku/3oiL076eclOhlQcoKRI5dvzTDNr
jx7t+erE0Uq18VPlRey12+oiGVJxgJIiVbw4K6lVe27qxmS2um4/XLOXbnnU
1R9vkiEVBygpUveDp9fW3VN+1FxIp4vFalSrNuzJrM2cTDKk4gAlRersdCAv
9Ha7ObTOBg/F+9KqyZyHB0NVC8mQigOUFKnrQf2pv5LHmfNWWR6eS+5pTZze
jx9zL2YypOIAJUXq+ezl7HH2tHguGvV7/W3wUDg9Lz2qp82nhJSKA5QUqYJt
5i+W7aurx3YvuzDmE9dkDw9jVm9PkyEVBygpUjelM10uVuYZOas17vPuS+cp
U3scmKNWLRlScYCSImUUuqx4c12fLyZLuXlmKA/segUWqWwm5Kk4QEmRGrLb
t8vL+aKrjqa3o7Pr0ZLJLbM96zcSSvQ4QAmQkkfw113xqa1Us9rTi/pa7zvV
k+fVfePylN3Nuh9G6l1Aic++07pZOOneNnp3K2N+Wa3dnEnO9YvxKI0Tnn0x
gJIitRgOnuxq91mpulWzmzuZihVnXh7NH1sJkYoDlBQpc14ZiWX5+fy8ePss
dvUXudSZ3PdOxNOEIiEOUFKkcu6dKzWyjdX45bLRLbT6A9F6Gi766llCpOIA
JUVqdpKvSsPL7I3VLgxq/e6gWa7Ml9d9d5kQqThAic++5Xl92W0zsVdTb6vu
5OpK06zzgn5XS3jMxAFKilQ/u3RndyeL16fmSa9d7z+Oe+3HZ0d5faskQyoO
UFKkJreLQul0MdbvFbU6en3Wc6OX86FmDDoJj5k4QEmRumuVV83BVNNve8vL
Va79WBq9uaem0Xj5uPB8F1Di3TeZsY6msNNRs2RWX0sX1fupk8nU6ucJKRUH
KClSYzmnvmTmQ5NNegNxns2IvUtbW0rP9YTqcBygxMLzqqDXRq/F9tnzzGk0
Lq2eoZTfGspjNiGjxwFKitSjeyYPVs2z63q34z7J89xVt/zYMMe39btkSMUB
SqxP3bc1Y3jaaU5E+fqGdd3G/dXrsvg0f0hoYsUBSorU8v4uXy+/3l0ZY1md
lU8Kz1fF7tldv/qY8ECOA5QUqey4Ll8vxPKlOWvcvr2dvNXyymlnbOZvEyp5
cYCSIuVUJHP4dpIvF7QH9eLNureubp/K09bTKuHyxQFKipSev1udlB4vbt6W
kiuzl+bArFwbhazb6yRDKg5QYjn12n6Vh8PzuTQwW03xpdl4dnOF/HgkJjyQ
4wAlNrEalZuT7MP9heiYl+a8dZPrT0sNXWfNhMdMHKCkSM0fL3MzdfRcbD3K
9ezyYtEbXdSNO/n0LqHTLA5QUqS6rdNH1RhWio896WL6+nLSnOgnz/XytZyQ
p+IAJUXqxa7edwrXJ5XVkz4Z566G0vNJVsrlRhcJeSoOUFKkMrdvV7dvj4N7
RXsq3t0Mug9dffmsGdZLQjkVBygpUg/5bjt7AsbaUM8+3F0vWzfqROrI2bd+
Qh09DlBifWogtVaafto2L/TXy/LJifx0b7ZF6zKxNRMDKClS5d5Tzz2p5M91
q/paH2bvs6fVglF9yOcTaglxgBLzVO9hNM49XTZrV87ZTfnZHmWXWuFKrF0l
9LrEAUp8IOujy4U4XFTObeVsqBVs6aJaPX0rqExOeCDHAErsHV6po1bl7boo
LUxrOOhlL2+rp8275uNDUu9wDKCkSNWfFvNuufhWsvodJVfLPz/Pn8/09vJK
TahPxQFKgJQ70uHPXHV5+vxYrBfMXms6e67NH/uD8tPFQ+7+4+v3PqSktHKz
7eXTQ1U+G93P1Hx9VH3NlNhkMXtqJTz94gAlRarXGtQymWxJEs+7xmNt2nK6
d0tz+qy/JGT1OECJr4wWZfHqIVev3VsZ8ebkrVpmte7yZGB0Ex7JcYASG+7G
aihLo/lNriF2Jnej/n0uV3m4Ob2cJLSR4wAlRcrS7y/Z6fBFWuZKWj5rFGeq
0+4sr26mCQ+aOEBJkWqMJ2dKK7+yh9en590bVpHf3kRH7nRfE0qqOECJKfV8
IcmqklsYTUc6W/SGaqczcvL9zGlCnooDlBSpwbR5ctW4tPsPL2NJGRaXhvZS
KSnziZxQo4oDlBSp1+v8Yz3TlazT01q+1x2ezB4ezpxlrX6ZkNHjACVFajp9
uZmohdX8bKDWFk/W9SIrW6cTURcT8lQcoMT2zMlUOXfO3/pO4bSavZ9Zo/OO
oYz1fi6h8hIHKClSbdcd1E7dbPakbynL83ynMtEXuZeXWSWh4R4HKLnbzFDN
5fRkMLh57swnp0bRkB5KL53Ht4R6QhygpEipD3a9XtMqT8/i7KpfK9vq5V3L
HmlqOyGl4gAlRUpst67vbov1uXv/IF/Vxvmy3FsuzFpfT8jocYCSInVhXDw1
y8PWzZVeX94/vpZsR71yzhdyNqGcigOUmKcGw87Z5Eo5KbxkxxlDfltePy9O
H526mdQVGwMo8Z3DqvB6f3N207qt5MShPb0Z3LU6JZVp2aeEdw4xgBLrU2d5
e/B0aoyqnZtKuT/PydnXwihfWp4nZPQ4QIkDSx7Ou09P2adWtplTe4P26qZg
NfQru9FKGBcUByixlnCeNRo9tqgN7y8GC3Y1q1amxtOzPC4lZPQ4QIldHC/u
W2bUeak4L0+mfKerz8+Pcm+xOG0npFQcoMSGw5N6Xzh/vrRyGYuVbqYtffXQ
y8+uHZZQS4gDlDgE52m81LPq0CnNCspFeXmafbpUtMxjb5bQmokDlBSp0sX5
+GqWyz3dLlv9p6GoiidLtdt66z4k9OXFAUosEsy2fH7tPF6MTu6e6s/mZdYw
rkoseyomZPQ4QIljOHqrYbuqTozLl8ty70WZTJ4Gj85y0nUSLl8coKRIKYNW
xSpfdFsvtULx5Jotnxf2SNdrzllCiR4HKLEvQXyTKqXB01nGni1OHk8W/fub
t4V6VbcS+vLiACWOTCh0usq8vqxovea5VVfPOi/D2Un91iokVPLiACXWp2pX
1dXpmTnS7rOLxmIhTwpFRX+d6quEOnocoMQ6eubitT06kewbXStVn8TqszYw
XkZ2s5Jw98UBSiwSJlct7WklD1aGo8/7GTgklpqiLaRlwiujOECJtYTh4qIq
K1pppF5n5ietca13d9fQpetVQiUvDlDiaBeHLdrDbuv85ObqvJGzX61x3zJm
9atpQl9CHKDE/im781Iyy4tRYfI4cOsXxWy/3p+Li9NlQpEQByixRC/JlUbp
+qRxyzLLQqP2+tjNO4XmtVxIKtFjACUO67JOivny2cTJTZsX9/We1b+dOiBh
ykkDdeMAJUXq9to4fxrd1RuD7u0iPzFqmczbuFQprFoJd18coMQxHN32IGNf
XNwVu2xqNo23h/Mzo3OmS72E7sU4QEmRap3Va/msPq6xiTY+vb51B6t2LZvR
zq8T7r44QEmRqo7EXPase16ys9eKbA5L+rWZKVmXCz2hiRUHKClSldfXQeu0
n69mO81h6/n55s556l5dPlbvEvoS4gAdeiWpsEzgjYuZy9TxtkMVFy3nWBgB
YCpdLLz6P4e62VqSavNUsM3Gf/ABFeuxqK05Fu3D6mGUqfOAxch2V2r3irR/
4nnlwl9ia+d7xX3tZNXbva9+PcBC4ZhIhkUzVcOlYo/hUp22n3FHleqwyAcV
XcU6c/axgGU4VawhHWpstVlz/+iI5rGvp6/w4gJBRypTfhXufMheV3uDiY6q
b5dPHq5LZGEWl0n1+kPvWFiTSVB1qrblMMzUpT6bdRN7A9ArTXiXaj1Til8f
RvlMHZ6+BNWyN6qihLkKuCGtKl4VdK8hBfCYyBdsjs16YRkyBco5xzpglFNf
EnOHKX/lvaw/v7EA1pWkaQBHqGOD6nrbnH7WjorkfknyzZrknyhjGWBjkXlD
XvnU8op3MOXwV+oaoHg17o+OeI0RnvjHx1uPTyXmqP0nLgLWGXR1ymHkFUI3
YWN1XSzL90OJWEjlUgUiYxt4L6gtjDUjadG9REPaVoAzkMZgWtDbQTXmpjb3
2ztsdan8lbD/29+w2uZtjReEx2Go1ackEK2opHWktLUwZrwWGxaG4B3ihetO
p8GTB+vtzvUA/viVy5iWqypYH0jos6WDciDoU4blzpGeMfNICacg6PAB/KyY
2AXcz2ZUjYNoGcPt4q7Hu/qsHm+3VcVZU31kFbYMYcVzOaliNI4cmqdf0cBL
oMVP/FzQA7/3YizWwibWexqubyMlw7C8oyrvfh4qj52MTpHp53aQJM+HP+EN
UPngXnfaCAPZH5jpwca4W72mj7d+webN20+ZOd/9WN/12HLkPY9FRdr3iyO7
OHPM/g2VUMD+vlixDZd5nRR8QKmuoRIKHtPM4KTBgokKtq6nfHFL91N5t7Jq
d6fRvle5V+hi6rQaSq9fYNnfoV9+2OTFxzG/d2Zh9SWs9JGmnsk8GZfnPkd7
kda9qqpey+oDbIDpF5j2K4OTfKRCqIg1nnP+ab7/5PskTSWBOoMcbhRkPMF2
k1RZ3g7VYQehYyiY+rvOGI5WkR+u6/TCbxrl+3OhwWuxg5zjSe8+oCB1mTp0
xpTptk3N5SVdBdCEuF7jgpqFxW5NLM47Mb1ylZqJ1Qh5ybytpp+U7ox6g6ZO
GTVy2GjziWjiTE1sXu0BgYmu+2l4BdSx1CzXXphkY2ncIROChPbhKtpTJaiL
mQIJCzoaSFsGVJpH6n1Q7jwWsYbFip8EvAMjyKsh8Iz/PbIyCjusJuEV7gWW
Qkz9HHK/bPbxuoosFRzwR8amRdjHAJP/DZoe6j7U89cdOtrO0qlCExZfppoC
UQ6Fc/2TmmIpXosY1E4qdECbSsLurV4KOT8CQ2zk79ljeOJloFPzB5wPldzg
6ftdrwEXKGlwVAs9asB1DDqzpUo6bEEQX9JIOhb6rqmDFlJzLfjjXsW9b2vS
XGi4Q7aamsfCGdY9ws+YcCbJoE+Dft0zjfHQFE7cY6E+YcZ4Cci1XQl1jbZk
LrBch4l/nEsrSWhasgo8g2PbNlbrViUDi5yo4wmKf07sDhal7skTy5Snh8SD
zKNbWEZJKhdG79ZUncGvvJQDVVel6tQB03kakF/M9xulmN+IKOhMgQXVVZvz
5b5SsF5Bg5nXOSGm2UpQxMYTheGv+CgoM4AMeMp7XOhZCTS6X3N8q76uX6SB
LCP/XUQNZ2hJM1XxumqkiEe9OVJPVYUqUgcbPLRj1jUp/G4sKaEP0lE1YMXe
ApL7HZNA4CtUspyg0070a/QEQ+08cXw4VFVijR9CgAPdwg5XCslQi2GxYcmR
1k3O6ZFNCsp69fiX3pD4FnaxxLbBQd1ynJqrY41y/zEVZoHRqSesrw5iC1ss
5bXusHa/e/lr69oQ92up2sDDwT7om56ZYQcWaKhjT6hFEa4hFTgGfiQdak1O
JAOJAK+0WBwvhgpVhEQ8nVSbLb12NXw6/mAfrePYvl8gmG00cdU5N/5QTwvq
LzMqUeP3RDDIUrKwNEzAMch6YBvhGjpAAer1jqUZ8aEPh9bQfkdk1ut1IdyL
p9dpcdnka00pIdRbGMn3CWv3s+VEQpsYW/WptG6H1FjJ4k1keNuh9QOvARlR
n5tV/jv+n/AGVRkhLqUzFe0XOninm6v2fpcsoo/fVmstT7g2EpKkI9civcPb
YhsaDMcQi4l5KibqmP6UgvLZoWn/gb2R8Sh30m3UJn4Hc8Bwsb1vA1bwk40t
JIPNg/0rRTiz9/4Tfv9yoRruElbA1fFUD1fVQQMpVIJxJqewJQUojfSvdC5D
DSuvLWnswtapv2EVYwmeFMWycCXDeYYA4G9bQ8/MsYBomXzQVq3QagvZArYf
0JiBhe67nCejpvJYKownZCvzMfELcca/oNF78Ik0Q13qdyFXAcV15oi590YP
l/UJ1fkEhrVTY9Mce9XVFDUF5x/IOSmbUp00s01LlW0q/IRD34Kqfyx0HBDV
8Fe2IGb5+Bsj05DU8u221u+BDgkbTdX9LYgLqFqOC5sJYewCEEYdC3dLwKWG
8Jvw5bZz1Rd6rg47bXMq9BBkgumIJq9xGKDdgsXFXnjHwqkl8c7QfFiGDBCM
/cUxZ9g8aGWYMziJQpVATSSTaoDCkxpZ6dxsZo6t3KjfO3ftW3Ocv30cXt/8
iprdzwRiXfHRP9Xw5IlU+JPChTOZMjFl3nv1+80wJ+6co1+x/324vKrjDKt4
WvaeNqyHx8IXvmRRJvZVLSyVRVUaQ1Wm0oVsvlqp5DOlgW90DWoenQbmaOB5
D5RB/6I3ADqtHzQb7av6YYSvG3gwB7bbA7bS6GHfKl341Og99A737S30xg5s
ejPNi1P7Vc7QOuMNYFqaOQQmBQNQJZqi+GsBnXXYEiR526AHwHb+RFt771CH
EYbPFeDcHq/X41uoVyxVi+XioI1tcHpeG5zBhpIwUI3BKdlOg1bndNBg6N0b
wBSi9N3VZXTz1MVFJpKvsXTtTG7Bhqk309RTLhaFldPkEUnf1Yx8JaswVRKl
7qX+0mpPuq9LU5azbXl1Wp7aF5rE2DkbLa8Kw149p7ev3xbXN9dPLZZTjOfb
1NtIY091XXdANpmDyx7fF5GiarWOcM01qh66IzwxivKBhE42vGsi3kdPAqWz
3ra5V5lhgLVSg1PXIkGeywpnLvZK8dcHFbGPXjcAWCQbKFPMTpvKWBks9cnL
zaN6O5AunpRX537eOGOnhW/dNplqsZDLVgd+b+bBbWsQJswgqDbHF3pMLV4G
tQ6nIXUo/iFE2pzLzvahYbjoQgRYmp3mn4rwkHOfX5N23QEGZSd1vhUzmdRM
Ge1gx5XpOm5qyNKnw2L7bZLVZ9nmr84vhWyl6olVf850nGC3KviP2WwltEEx
DtFBnaprhJkRwXniH0T0XwhjD3UyYeogedZHGMzqhYWF78dG/HmjgDc1+ywX
xQ2zEuvBIXUQt39kUpv7LWCrH7fttmj2zfvuvnpy/nw2aLSmz9eKZrycSHds
pbmT4evNP2nftU3n9rT+XeiUrW7S6ftsvYnpWCOZ6jVLYra4t9kGaC1e2c1I
N4dMJnZTNtoPt+rL8tw2YVPmc5Xirk1JXPgOYQJutdOEdcC8H6XWn70Tv9Pq
+KPTAim7BtvoxvLOirRuX1dWo9McNxewItl8IXPo6ezXrX9pPlXZbOxxaWYn
0ZPRYVx5HbjZ6vzxbYrHRSFT8DgTFUl7Ys6iBAhXvrYNSZ44ogKiA6vkKywN
HDW2QEf2WlJIhq3CG/vqiWeLRdwHQOwGByH0sGsqqJmXWIt8Q/d/f3TGN4EP
DERqCZYA+0gGS7BxLPyYCRH5rlwHe8VG52DSQ1FREPYGrsUwrluoRr6kjTt1
sDgz9l/wbtWwvHlcNX6Qy1GhJnEhLUqg9fKrxrSH/J6jb6dNxr0DWD7aXY6o
HxT5O5GX95WqJjAwVqil9HAlnMEygKWB/giy8SWDW3LYAulYuOvVkEp5EayH
KKHwqnyzgPM7p1m2UgQTojLoob8PzDj1jX7ZNL12UyPwKtcDV/mWFyM8czn4
wrOFgOHrWDNeuJTI0bUm8GlAv+h0ZEMeYduDqB2Vzwi1maVqMSLmQ7QoVAvV
3OAWeQmnj7yEptNGqd1BLdYc2jaD8s7keWLfquLJ89mF2Hp9MRatt0lZNYaa
4553tNn9y2tXe5iVHm6Vbv+5VHquzMTK04sksavRcPKYqpvt0tOJO5XOXSkz
njp4lcHjA1QdMdFnQibzOVf+nMnQQoGRh70X8UyjbrHUD/I33+1EpPKjYHbI
lk2nk4Tv44bB98XAzdDFBrtg9B4LdcmQFEn4NOcLgj9my5EV+bYFyWXzpVI2
M+jjrThqWt7rg6YBQ5kGuhIH/dvm4GrGjEHPBSMxTsCfW1VzOcuOFCODB12m
kse3edPFfRQI2j9L1hYVRO+EEjkIX2Rcwv7srXTYjCo6+A1U+YQ+uoJs/6LC
l+7mKFQDHl7rmbDTNhw9pi3OTcKFunWlQTuDZxsbIFvaJPcO184eSLSg3IWz
S0sJfcZlY3qkYt8p3syqQP/OFLKlAcf/33KZf8tVsv+Wq+4xzz6CBifkdbMv
1q8uefXx7GchW0R3KW/5IDT9lg9es028d0Ke9nqwr8cbgfnInNRYxfMC3fYG
bBjYd6hZFNGburuHBAHknckMHmL3u3AuWZptuRMQuV6NfyK9+F2YHaVPMZMj
Pw1YEfucYEjRb5PzuXK+8h50crFtngUgAYFpB6gHeivT6ndPufv4s1AzDORB
3wD0rj0fWsJPfCz4hRohIe/7zP7TGvexo4/Ip5yy+aaw8cQg9vBUjl+xc+Mv
jFbgwn0Te3idCf9058y1wj7OggjE70rWP3oKFPPlbDHZKcDN5NPbsMJcfFdh
LnIX/oQZb/B/eOmNrRsiYrT6zoTe0ZyLuzRnsOhGlt/MzleZ4nXjzuh8PLwq
Fy6cAojOUqZY2OlF+tiUP9HI7069/EOmTn6lbZd8/PQnj2XQEJvTyzKaSKVy
yZs9ej70Lc/Hd1n4f5yTM/lCuZAv5/d7KnyfxEXtvPln4/9tq6ehKu81WNt5
nUK3J++s5tnb6GI2NCZapoYuiGy2vMc1810IUfwhhIj4aDyCBGEN6wg0/td+
SyieUFfOlVm+NMeqjWyfL2Z9i9inz7f5aoobvppY8hXELQp+m9+mGPLbfG9r
8Ru8O/vWdcO7kwjT+NUs5WrFyms7W+12YDVzuXLGt+q2AxRC5/O6tSS8J0YP
vbAGmhFO2TCGz0OAdl8feuB9rdrGO8chOnuNEKn8+DMKP+PRZ/yk9g7qFhgC
pJHmsvx+4K9bBEEGJaIM+TX3QnLkya/zX1TldTHMTE61if3fMOLil+sLfTS9
O5PzVbc7ebYvW/psKb42RLdu3qy6Y60z+29oRpSydnhb7Lrl/iBXqPwrblxY
kgPHUjbtN97Dv6Mkr75D8eRjbbHkrrc8oUOcudYe3ruMGd/dPpWyyr16TV5G
OJoOhTgXS0iBN22F6euraBvjiF2NpWlue1wrIFgUNgeBqOMN7pfTq16j2d0w
rTYBI3VPwNS0mWYfCydMG6MB97uQzwpnkiFmN8i9bWHtxZTb0a126/SkG5xV
DpB5l+DYhOIFnRCpKU/F3gWJQ0nnSnDm57hRlstkB6WMW2UZY8/q0J+pzQFd
pZTLFncMkpLm2dSCDfXvKThyZaTuP11wcCUJlCIiXTZX3iM9Aoa+zhScizO5
txx1f/24uCjkC99V6ub/JYjnES2bf49ocs+qP1+uzPJgnIBo5Kr5nlQrCQ0m
E9WK71FtA1A6MZ1O+B02aeH8DhupVczmsqX3qLUYdK2XLmuvrisJqFWsfldi
5T5Oq+/MYeTVCxIxPaplcu9RLVuSWs+i+awqSXgsV82RPvS3z4KjOhr75adw
DK4f8MnWsbiR6NYE8a8//XHAAx1rXlxmEOYYxG3CGzwdE/a2K1mrdRBuEJ3K
81y8eOZ/iXBbylfgeVAYX+xnPFEK50Y4vWl5uQ88ZNXkqbOChClkBqauAK9O
MJ7J9uKZtuhM/fhmM0zpxNSimYUJnpFodByEMiCkEQui8VUL01Yt+zOtwM9c
Y9tjuhweCIIofCEPx0No33wgyXiZZzfL05eb07MLmUmspBUGl+NHQ7cbTz5Y
0hI/DhZVr3RpPHxdZh6fKg9PVjvfXRbmVxUjJ7rn4wAsdpL8OFTUGyra6rU9
qa7Kg4t5aZhVHyezu9cna5bpZnyg5B74OFS00dN9c+5o5cV4/rY4e+jnOrnn
hTExO1fG001A2Vrt42SVpHH65eT5flp+WvUWM+n0daXURsuHfH56+XwdzP8a
FTKeFxNJ0kE58NGxZj4MMZLok1ZKxYdrqZ55GD7fLpb9E1kz+tNRuadTTwIc
nmI9cmQe8pjtL87EYpKS/ejQ0hpA2h2+ld3Hui2KT29u72H1eHlp6w+jgdO7
wbBE2AAe9Ny3QF+2Jy+1amH0xpTS1WVnfn07XvT74sOtXvNp2eh164kIp+i2
nL6p5ySlIz9Nl2pfM9SmLJfH42mldFILFmmH0yAe8NpdcN2xznJXg5tX+fKu
ZnQ7xuB+kst19Ieu7EMPx/98/5ihQHDcbgkOKyI47k67t63PiTmAF2t+fjjP
uN1uNXelLLTr4fjxZH5TmzVmrPita+/BvZ3cls1s23pYjlqN0fj2rHtbKt6e
TBtND23yYSdFmlqgXQ6X7c6i2h4sZ72n4Xh0NTDK2n3nlD3Y34jzBzqrcUbt
XN5+WJKALpYeVC6a+Vs3u3zMlibj1tnCWnX7t4tbU6qtVxjUln232J6NSffQ
fONHlaxdy44bCXvK74EzToeO2jQFjqez2XIuU87m8/vIlwim10g2nQcLhJDu
1+rfhCho/GsEq/lctvrtCIZg5TKZUqVSzAQLcFW/ju4wzAzl37PQRoPXgnsl
mI83zdCETHkmSpqWottGm48LH4n+R5HJlLMltJM9KLnEUMg9N1hfEmEYEp9b
FVtbr0HnvxvoQiVfQc8sLYEHvfDdoBdzhVK+CIvSGQmgYlOyWCidGJPc5hKc
d7jr8BqEzj2qKgE6q5fAzJVVnszH04K8XDZSxo6FGU9/0hhWFaERKMUVA0ws
dcizjw8if/mKNk83wrzOBUPeYuTt+bBpsulMxUknsGx2fX5IGXxCp3ZZ28rN
7UfSxrEnt2HyN3lqJGb2HmBi0hAOPIRSk/3cPPL7gKVgUJoSU375aQRmEwNj
IvoOL1KBGWgGwxROycIUacxjXkXzTDu8e7Xql4wJ2xEjHluC+ZiMKYgMMRcm
iLrkjMSFG7kaJbPqlB7q5fJvZTx7Pc15NqvCi2XMMAWF1HM/fT3l08bLZadq
KDbPsfRNL8y9s3klFH7rJVCP8nULdUzDC+WnC3ao67YFxADiYKKHvdl1+zMl
fC5Ue+JlN1pkgoAN4yXJkY3BZJXLd4/z1om0nqWhBkaNl2GJKYW2sy71cwLW
v4V0PMUSL1hyB1hqJZwjf0jClWpI8KxhSfbU9P41V2V41JWsKWyLW1dZwV+3
bMim0kS4AqoopjWCR31zqAIvXbuaBkx2dLSrM/jR0d6W4Xz6tFExN59PEHMC
cRKyKXKuwFnR0u2FQ4TAVZxLmksWqBzeskSD7axvGp3Ky4yBDl4pDyngabaD
2CrsqvHEQQZcsyS3CSdMm+FzP7XeNPaiS/g0LVXGqhbAohqS/8ydmLA+lv33
/8fYIv1GkjsuqeVizrkmGfIEpgJL6gC3CucW05mFK/MiYUxjGxiKfw8nn9Cf
mLptIvgnsIdhTmeqRPxwDRa+JlyqU9MwYU/BkzqIxZXwoGr8/ZphGisdizOF
M/j86gcWjtGAhTOFLmhAsNk8BjozJ4ZwbTH37/8X4OA4Nod2AtIfGK8taQzL
ETGqPdBzJHeIE/FT8bH2zTr3Xtj+H6IZSdYPyHDhmoS0YsGmAJQ0osm5C1a8
tBJqEx3k/fnf//Pv//ff/3MKP4Rz9QmD2UTFUKmJrrIxTW2+UoSrqaQSuWGe
CB3PGwn23oNpKgAAHrX+/v9aCInBsih8GUCM9CQH3z+Tpu6QryTmfDrmwp6q
67U5xSRn4IkJLQcwL4i+hjseE+AGG4JINzW2ol1GGg3WCLFUEHV8gzVE/tdH
dxUJNF4qi8pMWKv1JlvDComYmL21zZ6hIgw/Zpv5xwON3zEN14F1noCWx6Td
m10k7gecTrmvaccWbGONI1vo2/LEHDFDxaV/kizUrCdsNKIFvZBcnqJ7AQfV
EHgdObilWqoyAcHfBRRXkk6MCRQE/QY1FVhOh/j+zDQkqjbSNlfIIihUYcXh
SBdOJNgEJEMtNoIjhRaV/6e3orvypreOAmEd/cuTxPFM1E2FUfEYfsjlMvjf
6K/JpvJeXKDKC8OFxgw0KfL+UbUJyd4Ywi/t4delCQ6cc+DpCfDeCuZ6AvMb
S3PJ2CW1LkFY6MK5OWQqLDJOv8XQ3QanxsFBzzt/Sd+z/XxIdJwdC2gFH2OC
O3cN8vBSXgzGZ08e0cxLSBCJfI0CM0YIFB3sKaEm7M56X4OiuiU2qHewAP+E
3IGfZ6BY/5Ito4a3swwKIjfC6gk0ZR4hGJRMCkU0C59+ajDXwdtBOmvkiWuM
7TFIANULv0/9dHjw/wPz0SAscDMBAA==

-->

</rfc>
