<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-28" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-28"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="09"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 208?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>, <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how <strong>intra</strong>-handshake (aka early) attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader intra-handshake (aka early) attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 212?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published CVEs/GHSAs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 850?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8292XLjSLIo+K6vgFXZuSelFriv2VNTRZEUSUnURmpNu8YE
gSAJEQuFhYu66th9mbf5gbGZsXkcmx+Yp/PWL/Md50vG3QMAAS6QkJ1Z3XVO
V2WCgIeHh4eHu4cvoigeOKqjsc/CTx3DsSRxIhmKPZGmTPgkTSWhKVna6lCo
OQ6zHclRTUOom4atKsxiitCWLH3kasKn+n1TzGVyJTGfL1XLgjkS6ve9nlBO
FQWAJ9hszixJE0xnwiz4qWnjK+5McEyBLWdMdgAYfZHNpDLwg2zqqjE+/OlA
Gg4tNt+BXTxGPx3IksPGprX6LKjGyDw4UEzZkHSYp2JJI0dUo+DEkaRqYq5y
YLtDXbVtgOqsZvB2p9k/FYSfBUmzTcBCNRQ2Y/Avw/npWPiJKapjWqqk4V86
tRP4j2nBn277pz8dGK4+ZNbnAwUw+XwgA47MsF37szACYOwAJpU/AMAWkz4L
tdtm7WBhWtOxZbqzz0KvWesfTNkKHimfDwRRqHUEaQyj2viXTVpIa1rgz9HF
OJgzwwUEfhYED/hDC//C5/cAYwKlhRb+hI91IAS+8htbSvpMYylYCnwuWfLk
szBxnJn9OZ0O/ZgGcABadSbuECikuxNJ1yVFdG1Jl0RbshTJSu8i90/wmSYh
5vCZD3jn5ykOPaWaOwGl9y9pauLoMNCB5DoT00JKwqCCAByicW74qesNKNzh
gEKPBvyJ3jKtsWSob0TXz0L/TmhYzIalPxZazNIlY0VvMU6xYOIDwjzFMf/N
cUWFf5VS2E87xr9XJXnCbE2aCw13yFZTc9fgddNiD0yas8iQ+JX0m8I/w7XY
NUDPNMZDUzhxd8HtAbnGE0kVWq5kCDUDWGtkwtxoW/WZPDFMzRyvYPzUsXDh
KPDv+kQ1pAgaQ81lijk2YMzfxvhsHyr1CTPGS9UQ2jDaeBc+nfX+igwhuRZy
uPX+GG3JXDBDwFn/sAlPgOxGNpcpZoqFQjw659IKhKglqzDuTnwWqiNPItCn
8EmK8U9+s+n3lDzZBbyZEuopoZsSHlRNY7r9DkWPhUuGAljDLRIZks0lOaWn
FhzMbzPLdEwjpe9k2K4E4lFXNVUygKssdQzkUdRdQ1+3O+JVt9mqRcaaTVRT
Z2MpZbmGo+osnn5ddQonx0S4cWF7rwwm1k1NU42dU21L9qSumdIUJi3TudNz
zNGIacKFNLTxISymZEhKdDV1PsRvE/hcxs/34dKBPS/05IllytNd4ze7nYtO
TbhG6smmdowjpiJDOUzSf2NEvJn3VkoC2h0YnAfnIKeFTfGeQkH2meDsOarp
jc1D+BAIAosj0tmrOis8FuAs9A5OOCr7Fz0+CzqghDPXYAJ+fsyHkqwxc9YS
f7FYpGAPMjwHxvBBymBOeuYONVWm6acLmUouW81WcoMN7BC5QRS3QQQz/HGg
GgMfswFgRjgEUpv+EQF7OD2B3e9SnpyO/nKf8kVo9PmZCN+cSfKry5w95BUt
NjP/DBprqxgae8ccHqofOkYJpx9IqehkPejRoWgPfMY3+QOPenWzbvY8vYST
QVBtYe5qBmy1ocZQ8bOYJq3wHUmewm+qBKogTI90QTabMJ1URvwUFCHbA7+D
K+U5SwESacDhlsmgMP2qKr9s6EDCeg1yJaGLTEzrAD807+4b/NVsqVCpxM2y
ednp1f4p82TuXEkxQ7XhZHAtc4b/SdPf0xv4x0211e7VQIDKpi3WOlFu//4T
CfN9Lh9FJJb1XQ2AzlVTY45lp2VEN20z2cUNlpaUuWqDys3sNM1mPhqPRX2+
XIr6eFzevxfu1kAFogBo1JsUyW2ShL8mqDvVbZ9KqAfrcLpyFWKLaDYja0IE
q2KIByXo2j4FQfFAYQTnU7/xKKAEGalgHs0kZxImXrYk1Nyxazvfn3qF2TIv
Ll5yS3G5LPyD1Mt/B+rJcMBKssxmjtCcg0VnyEwABWgiGCocp0yfOSuysMA6
dBAESm3LaUiOhFIXdBuh1m2A8XQv9i6v/1RCWiVgw1mhIr7krMW3EbKpjJkG
3CL2VkAf3Y7S85bpphMx9ZDXwJ5Eaqm7dmh46gnmzTw07BXOGhfPdvZPfPIy
lsUXuTgXR4vyZP/E/ckJ3uT2TXpjD7YYbiVc6pkJmgYMKyim8e+OoDCHyQ6Y
5RrwEFjGQImhDV+5SJk/Z+p67nUsLqzlXJxUqpVEU0fzXvTlBGiDzkrkrLy5
5ricNU9cqMaW4R92gqA0qZvGCLeNo4IgrqG/QJVxD3ojRzZDFg56I0YZQZUV
ZTYopSmVOSM6Y/FBWrfHQBXJSS/z7GZ5+nJzenYhM4mVtMLgcvxo6HbjKf1h
tYRoeW2pcwnILlqwVtoG6/s/Crc1EYWGPIFlB0uSCbqpMEFRFcEwHQHFa2R/
MF+EwM5A2YDfeuI4TIm80IMtxNBZ8yEu8dFJc1z3M8hL6XUuFvKwN6xCNbef
ID7ALWKMzT2EaJm43NPP/2oUGZv7qVF+GS3EYt7Sxdlk8i3UYOY8Sg6YiSbN
mQjHz1y1HFfSdhBEZpYD5yq6A21hwSzGKWO6QJofRIVtvPZTZVYczcRxtTCG
f+nVb6KKvpcqumqo/3IkQaRiDtLqqw5qyQuoJTm59A30sBw5Sg8QmLBLRVlT
0X26gxyB4sU1DzhrXl0TSfPDqRJFbT9Riq+WLM4r5YKoL+fLbyOKqEh7hMlu
b/IH1dsGHA8WEsQ/psKEKf1owsxQdS0uQMyOJsUY/TWWMI7s/gjK9K/q/au7
fwpZxuPKq6iPJhNQTyz5Q2TpNMS6pdoqPG1cdVLZTCqbLRTT+XK5mstUUvly
pZivlMMv7nKZkOqBbhB6AzWWiEZSN/UZKGgGmNKn6PACHcWQtBW+ao72Ok0u
zXlAq+K7jpN6vS6G1KI0eXc10Z4xWVQVUSbMvsVnAr90TTjxpZEU/aGfAh3T
wocWGwHuIQpmqunedSqXyZZTtMzwq3hbixINeEFCFVcYug7wzZhctHhr5bAx
PEeD0dqh+xvIYru9S3uIhL4S12aGuiRVDhTcEch+0AbSkiPniukZuvc8dk4v
mGpMTE3ZT6m6ZMFqGcJD+M0P0LFjGu7/978LXRUEMGiN0R+fYP72RGjAv2aw
7Vj017ZkGCCX+7Y8MUcwkfHGx5IFlOlN2AgmtrFGE1OXbOA624b5baCqwlkA
RvitqTpvAPrgQPXvBDx/rNhIjfiXIuq9IsNLUTG0HB97S8wUNl/E7Rx5o/Tu
G9X33shm/DdAOLxxXEaSDGffQSqVOjgQRVGQwFhCz83BQR/ONbo/EyRVt1Fw
zSwT1UTBwdsQ0BI0NLbAGKBN+iXqWPvvnxJ64g6PhS8bHqs1jI97uQBM+F65
pTptdwhilQtEoRYIROETSkT7UFhMYJmDuZG1KHGptJ5noB7DRCfmQjg6IufF
0dHmrTjjt+LhDTkiCoHEmyFdVZkdAzjYHkfovzBha88mIOhwFFQzbPsIxYkF
Oi2zjgVbxVHR5FQNF4TMppk/JjNYg+1tsVdXtZhyvBO58GeSotjwkgtbBseT
rBUMgGfWEih0BMPjysOWdzXHxltoYQjnFEjf4Yp0Hd/XL/ztb7s84X/8cQy/
cHn2xx+0GPiVhJol8tqez+jQgPeBTognKIQjEb4T4TuBS2oA5R0Jjol3KNeW
eY8K2rEAihgcArUZ3peKuVRG0IDKhs3I8gW4lqm4ssrNaULIgvVkC84pE9A+
hSFj6F+aGuZCQ1s/NFmNzYEdEKkpQ2kGSk1KqLsWCEhHWx3jWxYjMh0dOQsz
iGHwwxyOBdNgpFzg02oqI2IkA3wH7xIHBi9XU9noyx6IyjGxs7HxejlV4DPY
+qSUygt0AWNPYCbSWAJp5tB0hpYpIa02XW/7eFdGLiTPpKYJmrSCyeMoCAq2
sU3OAy9agxZ5NvNvfUJ8xLllJs3oa/LG2Zxisk9GgakUAMJXch1qgS69IUME
4AyC0xCmg2u6foEPsmYujhyA94bDi0uAIMA08WNyGSKmwPC6ayA/fCPzpEAH
FEzXCrjy2OMXHaiNCEe1QMKMCByhLwjcTScQKkbkX6LBuiBg/528pfAqBx7S
Jj2ZrauKorGDg59JL0V8KeBj3/4UvPMcNrcvP3DlgDVgmWAlaUZvjObzUUaB
r2emLWlABouN4XCnKcGcFxNSWxDYitYcl8BzydqyOSORil4vtLssB94EsoN9
lRJOLVMHDH1dVsD1xIAgOHv5NvEYcQqAFSarNhe2smPCuqOUwGUGxFWFdCjP
xa6DTJfg4NBBBzH1Hc/tMJa7MaRNh7Pi7xK2UTbEx9Ic/WSo8wOgeKGXhAeP
8W4Ffgyz5Mi1iMj+ZgO+qIE44lKdeNACwc73BKLia+phXqDV9tV0OVDT4XeR
xtjtrafV57PflNLw/5skiFgICedNSESmjrM0eOBYZKbePGFjrOXLlmCBX+El
xBm3AWqxpjuebE3C4zGF2eoY9vuM72XViCUH7MSfhSuQnCgoDj6wD501+ZDF
uQuGjmp0023gEsPT/ObIfxyPJRekoOqAHq54kQr0LGLL+sEIoCIe/A4GV0r4
XTjZHBae3dkMWQT+VAs2we/wRRY/qJNZ+l//43+zCaZhok7zO2jZvwtfEFlm
Zdeq3jdddacdizF0TBtpD+AhDZ/bGD48/x1o5L43GjmORh7RoIBJDGo0SYhE
Bs5/74HzfOACDtwDRmQWzZ+HZZDIjIxf+N7jF/j4RaK/qcNDTnTg4Z9zxNY/
56MoFL83CkWOQikGhQIOv/cA3onQphdBZwwtcTs91MwhHx7sQ4ahn3a6K1lT
1751lVXKvzUCgwwdNbIctsxSM2V0+Fcwofyr0XkmVUnlojaUbdii6uDVQmlM
qCxmIkIF3k67Mw0UOzuNNn46m0s/MJyuJdbwmgbvwwBFsY/fivWry9NOo3nZ
79QuSi1vZBi6Xo9cGvU6rY/M/xCUE0kxyTkKsuIFr96+xEidnTA3qJH2JRAZ
sDNTRtKsFSF3ptC9H0rKNThJTenwCsEjODIcMjYoaDJLz9CbBSYFIIgGD9Ii
MO3EBRKITozDNTOWvjczljgzlncy4zFshuM1R8J5EesIgJMjQLT8vREtI6J/
+8ydUL/8tCXrQcHb1GwRcd8YW+tAP/1xcPAf//EfBw8ssK0l/5CDBzBx+H8w
THz1Dv6GRgaZEUMwO9bn3MGOc46+3X+2ubjICOtgy5hE4zGErqF4uiuip6uO
Ol6fhPi9otpkBCHD+aiG72dVBubglYtHKWxzNA4Y7Hz4VHIE1RF0aXVAtwVA
BVhQ/zoeFB4V3oSPLBOtq7XdJMKkRnD+C5/A8GSakD8Mps8nFTdtSQO9GLUx
0BYwYgJGhfNGM4HDlQOuU4XCAI5ROUdF1fCewKmkA0hUiLgn2Q+5kNYXhAcj
rpYr6oichDhFmAwO2+NGoPcpjO9N3HYtFhAEJJYBQsI+ACqooCSgZsWJi4dU
iljmAJkGdu8Mo/eHcGjiImgmqhg4QOR6/D0tB11adGHD9ZO//S0SmoIOB9t2
4Td4zzNiwdJWwIQ49hxD3BHCv4bPo04r+D5k6nPFr2sqTMOVuiLV1N9B3YB5
uWstaiy8urBGwgh9MMgiuFa6qUQVQZwUQoIR19SPm/uOfTNcCTbu3xUaM8YY
f0WugiG/goxwpK8C+pxBkpKTgOhR91gBo2ZpkQRPjiLnn5JHRPgijcdo9zns
+8mjAOQh+b/QiUESwjNPlfDeVXbNda/ZBatG8VcanlYYrYbeAH+OruH9LeUt
4Ig7fXwkyPT0tfQdZiXxAIVxkMIXPizDPtWokN/tFibupM3HzR5+XuCaoESV
cGeEbpY+IfZot8IAC+Nw5zjbHmEYI3CKwEw1c0GSc2EK5GsgLgGJ4O16X36v
TXGwC0DHP6GzQ5jAViNXmndGH4D+fW2C0rGbP2coj4NvJEXx3DtgckqbVPNM
OYGfUt7afoSCiuld2M5QNgOEaLCiZHsePBXfAqPZ8xSBsLeYA0aztwv4uOT1
AURVwt8TGFuG736+Q08eC7tHyeCyxq5OduBishIi4xNWgZeWXPA7JgE89x6V
4Rza/e0xv12aMD7NoyN/djCjsFf4vRMXEHWNF1Aw8cZc4buguYQTE5lE6Lmw
/S065D3XqdCDD12QhT0/QhogDCXcygDty2Wn14dN5ViqbK9FijFXUrDJnNTY
nKeR9UXvlbQ8t+3DFNqoJIzR6PHAgtVK6VY49nXgFEUvbZr7U0EvE0Ux+B+A
8J20qKsBDPLNgykr8N+y0cc5T7GrwJ8x5Dt4E1Pcgkf+W4X1o7JnnqAd1GWK
6urep2vtaye+yDIfdMuhDnZ0dAofoN1tMe9a71how7sOCA10icIO8A+woyNc
uBCZaES8tbERq5+BKUVgSwUP7j+Q2Pg7/iwEdD+lfbKLqttHr0+2nZlWx8J2
AhRXks+YZIhgWqnMj0gXOPyts9lfhO81wMZd0w8YYWfoozdOYd84wg7y5ugj
zq27P6ID3U8B2wUi/+0gtoI3PVDBvuKWsYCm8V+FUO4kHGmgoqxhkg/8vTlv
xAi+R65vXZZQ9N0PH4KZ8z9hDP2Hj2E58p8xhqhISTbJZpQPfetJ4j3froXy
WiYmEcXcT+8JR9AQPpG/GV/CtDHKLaQDxbQUflZ5F3igjaEU/xmMOgtUHG5d
kEbk8AcY16nh4YmWHqhs3FLpMTkFM8oipL1KMFfp4cWC99r6XgDOgRO2MlHD
Rs2CXxPRPDQGExzTpchXdKw0z7+iauynWccqP3TpA9YFqFAYHEY3z9LMt+RQ
R4HFRvc/apv4ESZ3CopLV5DotAzhAaRneNs1W3H/AqrH8BoonJrkoEoW1gMp
74Tmi6nU6Csj15kFCq/n6KYXhkxDcxz0LLA4wdYC8wCeh2evmKgWY6o2js9z
nY8psSuUXoDTvK83z3FVgCqgANF9Mv40Ui19gQYfTREM55noGiqwtqfwcSQl
oV8/Ebz4OTJENbaRKj/zZrn+zgrMErSN4FDv3V62fNyZ8ldEwfdCHq/XDsdD
Anxq1g8b7abgOcuEuaS5jIN1VjPkTS2gP5+PbY4cmgvjeh45J2wKEKEb1lB8
13137ZIRxgDXEa56uISytZo55tiSZmBsi5o6tJApLEAKyIOxGHR+gJ3Jb7h0
0wJy+3T+etu8vrrtDxq1fu0rT3pAR8r69p6PxG+vZNOamRx3CpEiXlTHuF/C
jMKj7QU/NoNfPmPIlQXqs7O9kH8l5mewgjwcAMimKuscFcpbcVG9diisFpbW
NxmJwMFAHAefRGHOZoZEOluIC8kAh23BKOeFLWUNqDvnLiZmhw1FmDV3pCj8
Ep2vLTA1v7P7etE8/8Q54fBreC/agJSmcNMI2IxRmQNAC00CybbRllBU2SHD
k9/VMSLtxiaVJdfmNFPYCLM0QPH35nYsyOitUuhz2ocixpkIjduTFg8BOcaP
uJW55jV42yc9TR4sL4CLkTFRKeCHIxXFUg7+L+pKl3SFp3UYad9JbKf5baMj
BsGTQxewctAToSuiPRTLmWKRygYc+h5N8pSZBm5ABpgYLjp0YFkskWIlQIS5
miehPwvSaMTLWaCoeAZ7q+g7UkzyLiC9AZBroUPLdkcevbRgO3g7kksOZpEz
4utto9dsNr4K/CaTSwpidgsG01bE4hK5o2yXwos892BgFiPn00lD5h7ARgHs
cQ9gKvauRWJ/NAhJpFCa1Qhv5n0nSOCv345+5ealwnTYJI5FceXcE6gwSRP5
xAy8fAGmcnXvehU3DSXVojxe+A4PuofkQSh/XfODrzlSBhBMcYKi7wqe9XoX
/24LX0URdxiNBCvLlF8sRZ65X4VPX7yXhHyqCCpp57LXr11cpHRlpwfLhJdt
Wwv+S7c93l9EgpBeQzg89J2HOBPYAetlAtrBn29rl/BnktHXSFFEDFZt5oJg
VjXYzEQqIHHgM0Y/lzT2DXpnwrlgAtoJl8CevKCVAiZkFK/nn3X+ARfamdxA
vzAX4gW5mbvSbOb5FpHcXG33lI2DU3WMLtxcrDIR2hL9ZlOUxgYoDsAc/sqJ
5M8+8OMLKWwALVNJgDXmPwo8KmvDFUUyRpdmtnc34MUnIreC/KDrc5OCBfwg
VRAX6+RJFP7hs3nj8oJcBjC/FMyO8R94CCiogmsgH/zn98hIH/sEhhd3/CPs
fhz3zzd9AsMfHV37AYhd7so/OgJYMG+RDgTNJ2egcuybvTfz4DOkRuxHfPh6
PdDZYGQPVv36Tmg/CH8h+gMfugDvLxuBziNUZSyXRG74Ey620rgIn7gCcbhW
vP4i3Hbht+a9f3EB+gbH48Y16QCm9DiOCZJBuGnGLDcMJKRJIwjj9um+Gxpy
96yj+pE/8xB0uq8VGqRxCp/6jcN3mUm4Rl8fhisBPpsKWPynhNMlc1Bm4PEr
T30K+DADte0vJE98Xc1T+YBO+9GJ/xSR5W9soNPuddP96whpfuehvGxjs+4k
xsdfpdFII66dfw0N93vkShwlKEwGOcLjlCZPXtoYF1X/9D1oVnT4+qbLu8T3
NfLI+A+eCE+jx5iotc6n3wn1Wz5ZD3/RD4//OxwQdFcO2xe/xIC4d0j6LZ+E
bOuNY8gX9oIXacpt3W1xDxJkQ66jzdz3ggP9eAxUaheG79APYHOg3PSzue0X
XK5FgB7QJRxtSs8M9APfomdVRDkMq9/Rg457q/1TLB1emt+FW9ew0xrMzeaX
tL/u5Buhv5ptiZfdb94GqhaNxJXevcfPRw+Tj585+94kFFAoNOtofUaR7nAB
YYTF0tbMLmN+jbx41Uv7ksfTuzj7/b42hnePHy9JfxdaJLwClfSbUKid++9E
jqH1p6feaeJnTKaDkxXXc6LC/rbkCd53BA6QQEH3B+mCHm6tRICAZrcv034X
QiewP1zbUy3TwSkG9o2EkfGbcwq+hOmkzxunwpqsEft8/UXdYr4PgZOu55Pu
d4FKNvgmcsw/GIwYdhwHKrCXB0GyJixaLoLNt5Gfh7t6t5cHhcg1GHOw5PpO
yuGlF0UlkGmMv2zyyr9jbnoXtvrBz0KDkmXg9ftIAEODBzegjOyrOoYOMB5S
w2P1auusBH5JCFSr+abkPY9VQEnSpLs9IiAL377ATxieohoqobQOq2B+WAWF
Z5he3ANAyJSFKxksEbSeOW9GUUAMgpezBZiXHHo5XDbNc7N8wVqJa7Mqvn4A
LIGdLo2Hr8vM41Pl4clq57vLwvyqYuRE93z8lMYwLV6jgEYt0ahfPGph0Ilr
yIRnyOZnw5Q/Ig4Gf8dQuVImlytnS2DWF9KRXLh1LY6URZF947TDGA9HQxeK
vAIswlTIlYVTNgzhE0TyrfMwtu+/hC9HR8E95S9Cu9NqYx0pnvRxeHT03xGy
VyAnDPu+ueuyaz1SHNyiD7e0BZeKGIXA4G3Xzkuvb4T/Zc1H0eWJKaGA+TeS
zey0I415HB+67Sk8MktLEKTkUuAAfbSLOB/AuEppkt+K79jcj2sxlRXHZjaV
K8FgW0iPzW9EOJvZwri+pQl9W8AlJlRoFIfwJabS04cCZDdhp2eupqWLFdrG
5c0Z3K9H2zEZ8s5+44y8/a8gb+Zihk0UNkOhNriiPBHWRqsDduwG9K0I4y2h
sOPGN4YBCv4e22LZ98VObnv/1m87/U69duHBr8LO8hjML4uUaIT8PzhCcmrl
tsi1NSC/ePbpVtgeNdiSW6Nt3y5/YGlClR+SDUJ3yz9yAH6z/GNH0H/wCPxW
+R8fIZAJ25l5YCV6pwnqYro552rebH+c1e9C4R8ZbWx+v5FiKcfvyj9AvNI/
Mgi/VY+O0m02Onddb5xSKh8zzlpvD7TmaNhvWHcNa83ShrrMQ6AuvfxS1EZ5
FJXB47tJmcIQRMlYre8SVmB0gxpqIupexmr4jjty807Rk18fmDTFKrNfj/mf
G+2vdD319URSmvwE+5o6OkJ/ARhrpqZEbBdyd5g23iSnWOrYg9mj4HCCSlPz
HgBoPlNNA6YxFd+zYvtJixIv502hXM07rzblQRPz5plkCHcG8BDYJV/oh3dy
7CemzmZg9h0SkaKBOmEG2FYSaQ5BrXeKeQ9WBmYbqoriJ/MBuugOwRAAoDl9
zyNw76Px9vurhwgXqoM2HHDFOl5tDgeFLZsYSfDH9w83jNpyXDkPguG++KN9
GOZm3JxnwX1ZgEnrSDO6bAnZNaGnYKjDmRg8wrwebiQjRp++kAs/eguKl0Ua
1568NCJ4mnaxJlNQQUaUGV4ppcN2VZo+DO5JxfBv/Mo1mxFzFTGTyXrXpciu
X2rdxve4hc1nCpkA7HpgJB2lk11ifDbRrN9sbtALjLgwrSjrZ4NSW0Aaj4q5
CKnRipaSZJ3MSMVU00E9nFKxUioUUqC+Z3L5DOUS/Yk0LyDNM2GaY/Jjkfyx
Cz6TniNpzA2x91KWRD+CeF1H3+av+f8d8MIwYLp4dFpfrBcLxUz143U+vA8Q
RoHHAHpBr4jcCUjU6Wmt138PvSG+OMLyi8GfBqY0xcrlu3AsZavlXBIc8YND
xDC3iaGk3Na6a1BDCZR/HWWk9ycc+/fvyOZZL9gAsyjzfyK5sknJlSUUqxso
nkpDEGtTpryH4sh/cf2neKbLZj6AITwMfbATw10X2VHIf2JZc5xlTAQzjxkP
qUWbJyWPCptvn5QRh6QcnJRacFL6VyXyGmJw/YJ5eOuD/OiIYsTJa7E3DgBd
t/I60GOzcDSGnOg0rrBijjcoCwrpYTOHdezSTszJz88DRDHNLUjxD5WEWDBM
Y3NgkgYvjxopWEKKEZbYoaj6gwMvtmwrjwM1Hm2N2vqaZ2Y6vuaRNAr002ZJ
Al5NhGazVmkPP7+XyUADfzxz4RPR0tL9WKw500xM4jn0choqmx/sSXWIh1NJ
lYW4JIjidhJEVfhUFGKBbiRIlCO7oLluEZRwIWKoL3g7witSM7PAutAxnXqF
wVKqTswNa8CVymNi6ZGK8VHYAIMiCumnFNf2KTDTwTo04TGJCUNup070/vLg
oGaHw6ZiA2sJ/9gKI7BdHIzc9coArVl5k1xbub0WC+WYAVuKoVTs75t9/XmX
/OMz27Yu3nOPIp7JEvt3lXgmnL7VQXdw0BkJK9PlxWB48OKI7Ewuq2OzqTaC
6GbkWRawOLhrC2hHCbbJBeyCB5nKEyZPvfpE24mzW3mzKo8Qg8dexmLNc06k
uzwHGjhuiyX7iViH6seGvMfRYltHR747BHPLrLXf4+gIPR/7ipdxDvyXLlbw
+U9xniM1wzQksvi+2f/pl60KEvH169eMnuR66vh77ti/wnR0dUzCDlgi3gPG
y+LBHOHAw5kHTinPZwcECF/A5FKZj9w2ramQ3Od7HOVoXhPBQ8qfVvykaB6q
xT8Zm5tzyMPR7l8ivXcVtWMiH/Irf4dJRE81v+OR0AuXNbIPartPoyDKN1IF
iTu2YuXlEcbEHm2cVojpxxmUJMs7pTeq8Jpgr/QhthzYVcXirx+5ODo6Cq6O
kMgjhwWuyC0U9qU1h9DA+XyiI1TEIOcZM0RybB16OrPkZfPuKrrxybTUMaou
eFagAo0qlJgpcAcjJVPYPPQfaClmSocHWBy1hqFNVBHtoUXpxaqszrBI4sxE
N4UimBjI7J1ZWHqBn1RDOPeSSAw/4V4iPZ6v5qaMIsDr8gChN/d2Utj6ipzC
eQqxZhYSRR6lAAA5D03Lgq0joQg45J+R65JfEgYx9LhU9miVIupQWbkoYWw/
+B57hq2CymY761lgYk3QscJLB8Feao6XMIJ5V16pBr+M3sQvjIjmC/dKx9eb
o4mETBtYEo57jcJqOSALls/kpQw9W87PveeTPjpSVJ5kAFzspznxOgGg4+xJ
pPdpx4c7OrrbU4QUB1Edm2mjcAlAzLVglhHsko0ytu/tThoTDz7S4MNLrkZr
OdKLu+ujxiMG0s+v90Fx9TYWR2i0N5L6P30dL1dfD3nsEBiZ0V+HzFmghiSv
627w4ihYTaEdiD+/TgzGIX36OnFs2YdIqWnrQCUsWRt8peOExsw+yKeE2rrq
zAY0KRZaqFoN1peWDg6u+VbH2gZe4mF8rgDC9EoHkx0UlOe95gtC5XnrGDup
8WFauAUP1z79YFsKf2CtGP9uhpwMXpESCSOv+j2/eLjlp2QgM/N8tv3ekRQV
tQgjALNphlpkSLioPb5sPW9RW9lDXKGYr0KF6Nbr2Pcof46Ub+UOcWU+BiO8
flEo+cNda5JPtCZdFL23vAowHo21cOmVXVUzvUK/0ZDXHVVQYwsYbR3gG4Uu
xM0yehOmzeygnhIP8Mv6+OH7GPwWVIlZlyzc9V0u/F2HF82IKd7kFWh6rwIR
FWVa5/mty2uEUp7oKunal0ax//y+riQk/Jw9zh0XjkvRh/nj4jE6Yq63Z40O
lc+iGD9CZDDvbf8PwX+x+ENW+BzHqiTl4Iv/+j//Vw/Yf/0f/0v0Dwgl9w6U
qTzZgML/FIWSfxfKV2EPFO8PkTB0vP7nvE9BoBt7qZzKEr97iVHFj24skp5B
zRaqkOL5r4KNFl9mM1Rcc/2tX6p799VhXAXOH1Z9M334Q6Fr5jjlLJ2P1/j8
YfU9wxP9AdAjE91dRfSHVRANT+0HQI9MLbZO6Q+rURqe4Q+AHpnhe5VQf1gV
1PAkfwD0yCTfrbX6o6prpn9o7c7oJD9Uw/OHlecMz/QHQI/MtJIKaxEwrF/l
/fuN60Pk0/qB8EMT23F9FDrrfya/d+B6gsU95QexTSf2vh95z9Zm/9R3jIAK
+YC+bo10xRhfJumHx0Hu+heyj8WoA2g5k0K3Fmh0Ye7alFnrBArFlNP7Pk0f
HnsdVKOaa0jdjfRqsN0x2IiOZ/aDkY+G6GQ1tFS/4iKaXp/k6CaIVYL9SjI7
fz78aDE/76Jrl+nPy8coSkxnk/eQDOvoWJXVWK0t/CEz2EiNXlj/sxc1hRzm
dSCI3jAdHa3bJnhWBfrUcTW3ljHMGPTGe9PyS7t6HyH3bF5WDlfkTwn5KL07
dV4FZt26JVLbYcPr+x14YqtjBpnQEQckEZHupcjPSRVXFE6IjyAgZgoRHN5F
1/M/cc+dv0jwF9NiehCrEPXckksv9UHxc1E7b3Lx01N1TLTCKcHMsWiyDMPR
m7tJLnzRYMFFS/owV+Ij0fsoffhRFNEEIQzfd7dvd8/bdiDjPbtkTMm3yjnK
z8agZV3nabzvm0de3tFP+YhH1h4R8NCNp401mlaCgjVSLdO1/X5NgCayfxDv
eoyVj7GDwzpEZaKOJ5Q1ipECSiiW9ltCeIRPvKzoRrzrH38c8hobocqPR0fr
2o8gErD6I4X1ULQJ1X/ECswtde4VBEU8eQMQ2QsECcKYNlE9xrtoOCyofK5y
4HnLWSiig0e4w45Ex7vXSyhOIHfvev0D1xrzgBm8Io4Xu1756PeYkDJrc/Rv
fqft/7guuxYtuck7HGE8zCcv79wPyAhVxMQbAsww9wrcxEwLJa7qderhRaho
C2KXKV8gWKrt9YGvdQRp7FWHZeiVoAJX7gylsR32QYdLENc2RvMrsAd9zKQh
HXQGh00217rbmVd9CSv30AEWfOVVhfJ8YuzVJWFPt3NjLJJu+MHcXmUXQHZF
93rAcbA1I+9wccvjyaktVKhTUAgrvyXNsbep/U4wwE5eKxfbl/KSxoNvgnrG
eBllKLzgF/OKzhwH4wRxEhwdCh7COmryugjRkNbNUoES2FiN6sd5X+tMwrsR
EDocOmbf8gw1Sh0OHIZeiQCfwyKXIPAy3bbI3sHrF52j2t1Ug4tXFcDfmL8h
fderf02ws4uz74wNKOCXBfNLK6WEXnAjFb1Z3yz8NcSrBp6vLXEJRoWKeBE1
b0VJsoAo4ssnEWeuK1iFmktTRKAR8HRALR4ZxUZ+uS+vOB85ovsBX/JUEK6H
901TQ9c/VlfaqvEf6B3B5oj0jsN4Aa6ArA86lTEqlW9hTjJj/jlHhZnT1Qoc
NcX8od8VYOPYXBfl5r1yonXg/biZ0O0cIM2vHb+M1CXKfK9TLlV29/8irbu7
J41R+VCr05CVhJVCpDTgcsgv8EzymcOyYV01Kq7Ay2QjpS2Hh0ACTigUR0Aj
2r7Rstrv+MT9bYCwU0Qfy1N2WHDbuAjd62AnBWRGIBwyLFZvn3iVwXjZ8OBu
lMAS++CuDSWhrzu+wdZaFyP811sBj9R4h49ZTdGNtZYJXiXNbWxpBSPFPI8D
eRDqZkFpIdvK1CF2QuA3ZZynPS4INpAcHAEo1KiPFu9ryYMIopXeIsuDCw0A
dL8/gjwxVZl5LSfQtNJAMwlJu0CO75gjLtoxV04CdSTKgQvCkwdeegfEu227
Lk3sluvrzX71gn85Dtm9R0n94vLFAHX2unfO40DWCmvq4HSLNz4fHPzPdFoH
y4LaeTaVP45swABGKGuqoYKEZ2KbaZoOrIl85fdxHGG5CTz2mIaHOzzXNHWG
5eBAHs8ZdQlca1LA8V71Ua84IeZmMaodiUigXesaEfuW+4cxiTLoMLchkq3N
1HF+9bKORSfu2kEklN4PvIyi4zERHIGGytV6Tt8dn3ntH7ekWHAlqgWlO/0b
buwYo3JFMhCGgmLS3vIdGOq6syvgE7BotIFIsEq8PRyv32h71+Dr4qNEBQNt
JCC4H10Q/RltlJlndQJaHiukMDlK1qgNMK8Eo/gapN9+DwyUsWsFNfXg+Ftf
5R+EbvVjo5gtFjTyc4J+BxufhkoU87u4ylbtYkHnuphNvA06AtNnE8lW38Jx
SKE9TDGzkZ4QVGcUtM0xv6cl4elyeYadMXCh7Ai61HeQz3utrkRTA28p+Ohg
/XM07MerOxtpmshdEDuJlcL7aXyZGvR4YRqh7BT8ttm7uu3Ue5RSS7j9vJlJ
eRDcZsZXdgy1Kdzu/UwbKaimxWmI8SQyC1oWbjZM4sh0g25LPh7vVZiMxWOt
hXm33gF4P8LZ2y8HtT19OvfSe2+/ygver5IHTIAVKAl1FIOg3AaxKgZbrBNP
UQOk1wDLEVfJJS/FHKvMjJnvtPBP6T1x26hqYvRyVLGhc4G7KCz9Hds6RYHU
KEdu2VjFAJlo6hMZAPwHHtXvJ6ohN6Uz5XSmkA77JcTAL2GLVCNNDOxRUbXF
oWVOmUEKOhxhoi6tRBBzIlvCCOlirlTKFEuHgNGnM2kmGbDOh8KXEw04qS05
l0DBvjldhSp/DPEn2MtI3JSDv6W9uFU7nc1Wq9kiAfNprknG2MWwJ4DaJmeW
YYaP5UnwjOYaibpeSLaIdaWRp0THFIeMZqFhLz8+URCE2ERzJaoOTNVAXy0d
5SDFJqYCX4POJsL/EKUvGLSD1wGKHElE8B7YKQyuYjwhYew/TYhQWlWypWql
mC2XCvlf1V+ymUymXC6VcvlchYj8JVyjKYi9QjKHijQxv+S1xeszhVGIhlV6
qXaeCpk+9Bjrki2dFjNQ4PE6aiEOw0MHfkYbkGERTvqZZj1zNZulA1/TSJMW
4lprFVVD3M11EVdeYIkRLg3YwSt/mreUfRN2cMKPPnN7qTmIxzpVMzo9MUII
Ojc4khPVgbXBsgGwhCJF1YuSyqnRq2NVRk2JbjFbXuBDGm5oqWy0d0NZ5JLc
OUXaSigyxBFyIR1FnGw0ciYr3LiS4bh6ePOYYztFNQJQp8LlTbnTdCYreq+K
HUPGJVpLDhEPThFdVOKUsZmIc/VqRcOcV3vWxOaU8XpIEZeiP1m0aTHVseHQ
l9QKgHRg2rS3LshFyTjE7HmPNS+k4QbpvF9AbqcsN41iIF0sF4qFYmo2mRGY
FgMORyg0XRAqUQj+U0rrjGUplVku/IUvNZgxICo4onWsHkuSqqcaIZ855oIZ
MkuBjSmlZCONLE5iU8yURRCb/MACVlZHtrx0qtUicFY2pfB0X1w1pFJhqL5F
/fD4hMsnDCzGBHbQisUR2F2SCGsxQxkA0hVbJksiqKl7VmWDyJ1+L9xHk5LU
HaBvQFfVtjWmmJjDpamiIdkT+M+UNuiE2VN35YruSnqbqzr6ZeeRDbJBJ1t/
U/Sw0LOdFD3jWz8tVXKmVq1mNumLoelh4YRI8mf0IaHJqZoupEHQZTO5XEDN
EBx1xIxxyOeTogc8rSddce9Gq8x1V39t8kVwx2PJcG1pY1z/MccZprCPfVAc
mBoTZ6ojT/AQ5McFbgMKTqYTEP8ma6YL5FqY4gosYBs9Wd4RgpbtSI2is78I
1gzfgTfSwbt0QRMyInfKMn4Fi2PYM1N1wiUCbGoe6XIye60kMbu6mitWs7VM
ETj6pC4WM9mieFLLN8STbL5QPskXG6VKgSBq0nwpRBePlg2fpyauz8rpDanK
76HxnhNOOZCjImb0ihjcv/8E4DMwJ+6GqIAnfNeks5lCsVIqVvOFQTaXy2QK
mSxXOq7RFKDdQMgpqhMp2RE8S6kWZ7Z9h0D05AeRWh2VcrmsmCvJkljOVfNi
lbGqWCwWy8O8nBlWRpWN7Xihdq+F++vL9fAaGLLzGddM/D0ZVQj8Q8erTchR
wWX2hAmccCmFzTcOPXxE/Gunp53StXn5dr2kD+BQAOKGqEh/T5GXRVJTIMwI
B3+VgHYiuoKiJyPiYPNjg7Kx957bnrKIdjWN3sJkBBZaRGWYGmOKP3PTNuZB
ULflX19dZq1+ifIzfY+6SUoLfR8tMyOrlqzB7/Q4HfV+/RzAJ0gy4GRpoASH
VcXQQ1qRXCFTKW9GoUROary2EdF7ua7egYkjBmrIkgHqG7xrBb9xJdF4AdEe
qGYb9SToRyrugIUpt6guBo2ADsOpcSGx6z0hvY5geHcKEbRBs0TZhFC9ywOu
y9QlN+rTkvkDoAYHBsjMfQrQAk+YD2F9wo1AJBlAytCp6T2hA1lRMf4kXSpv
CHDZVoyoIpPCR/TNgqlL1RgUcvlyKVvNpbEIwdi0VoNsPlMtgf67Ht2Eo9mh
xQ6RJfTQL9Cyi185Y3PJ5DEvXdYRpn3Xmqr2BDD1WzOADqKGTpDIYxpmIg2x
1gumG6sgPKK7aA8OqgxS8E1aqSNxKmnqyrT42kjTYVjLpr9y6y2kcalG6NCB
Uwl4kHpOBCssKWCtyML2kct/ELk8ZOkFaAZg/YJ6N4IzkMCBzowWFwNzVGJA
GJgGSgC6NqC/w4E7tgCORI1qqHCPOGZgB6RL1VI1WygX+QbodF3NUcEUCueY
694zfth5wo4ZsO3kIKucGmmBocfbsPoK5O1aVq0tcbq3JddhcOu6fm0duxNJ
UTzm5vna/+i7FKmdMTequ6AYSegllKZR+uH5BUMageZgp3X+7kyaDvbp0HiV
v2VSo8d9jqKkXChXC9liMV+u5EvA+ZlSQXwVawW+lLemYqljUzixgEbmu9hY
1pBeHIBuxUWWf3XHJTk5BZBnDFNE8sDBTLlLhEWxkoNTNV8qlQCdYk58zNSK
HIsTvJO7tsDk2yyHtAOHIbwMJxm9LBYKxWwhmxuYnGexDoND+tE+lWuNTaFa
zlZy1QKYvoVCRlyM1LxvmpoWLBlYvkDUEYtBCBQmm95J8xC4gOpp0LnTnMW4
mbH6d1s46XUODtZ/PWUKcdkVXoPyxMqdZvenE/Qq2ZLuCKO//6cl9FCttiYM
I0YMzKsLf2Zzt9eUl2PbYD6hLllgcghtVXOwdxLQhJq+2rYAit2U2RiCwV2D
gOsxfKUp/2ouoM88/qRej4aaeQmWXomYoMA3j5CAwwLEjSaEhJwXCIL/ijQI
Qg84eazROw7LEtrmfqCBXw/8gNc7p4LXzJFTx9xZiEELVMMmKJMwXAn1ujcg
4E2xNuSk212jjl/GbZbF8a4JmNdfYJ3zgbVe6uRf5J4LfvuNoHlET/B4r9s0
aLA8Y6BncBeH1z07kfeYYrfSndv+aSBBIymunv81eMsLqgvxqFfgh5JVhquN
aoJ+UmyQ8+q9yN3ziLT/C6pgKZ5m6/t8w3jQsLthew7VEA5ebJIHWrUE7BAR
vqv3G/Jxi41LHiTajuulXZ7uCJp+8iW/ROGXFMhA1OXq09ERNXJDRezoKPo+
3l15IW0xDvJDXhzjY2XWMT4xfVI+zTZeBtaLXelkzsf5VX2Wv5VmmUfWTH+0
Xvu7gA4TIiU176vK3anp1G7e2oYyzeVfT+TFST8v2cmQigOUFKl8e55pZu3R
oz1fnThaqTZ+qryIvXZbXSRDKg5QUqSKF2cltWrPTd2YzFbX7Ydr9tItj7r6
400ypOIAJUXqfvD02rp7yo+aC+l0sViNatWGPZm1mZNJhlQcoKRInZ0O5IXe
bjeH1tngoXhfWjWZ8/BgqGohGVJxgJIidT2oP/VX8jhz3irLw3PJPa2J0/vx
Y+7FTIZUHKCkSD2fvZw9zp4Wz0Wjfq+/DR4Kp+elR/W0+ZSQUnGAkiJVsM38
xbJ9dfXY7mUXxnzimuzhYczq7WkypOIAJUXqpnSmy8XKPCNntcZ93n3pPGVq
jwNz1KolQyoOUFKkjEKXFW+u6/PFZCk3zwzlgV2vwCKVzYQ8FQcoKVJDdvt2
eTlfdNXR9HZ0dj1aMrlltmf9RkKJHgcoAVLyCP52V3xqK9Ws9vSivtb7TvXk
eXXfuDxld7Puh5F6F1Dis++0bhZOureN3t3KmF9WazdnknP9YjxK44RnXwyg
pEgthoMnu9p9Vqpu1ezmTqZixZmXR/PHVkKk4gAlRcqcV0ZiWX4+Py/ePotd
/UUudSb3vRPxNKFIiAOUFKmce+dKjWxjNX65bHQLrf5AtJ6Gi756lhCpOEBJ
kZqd5KvS8DJ7Y7ULg1q/O2iWK/Pldd9dJkQqDlDis295Xl9220zs1dTbqju5
utI067yg39USHjNxgJIi1c8u3dndyeL1qXnSa9f7j+Ne+/HZUV7fKsmQigOU
FKnJ7aJQOl2M9XtFrY5en/Xc6OV8qBmDTsJjJg5QUqTuWuVVczDV9Nve8nKV
az+WRm/uqWk0Xj4uPN8FlHj3TWasoynsdNQsmdXX0kX1fupkMrX6eUJKxQFK
itRYzqkvmfnQZJPeQJxnM2Lv0taW0nM9oTocByix8Lwq6LXRa7F99jxzGo1L
q2co5beG8phNyOhxgJIi9eieyYNV8+y63u24T/I8d9UtPzbM8W39LhlScYAS
61P3bc0YnnaaE1G+vmFdt3F/9bosPs0fEppYcYCSIrW8v8vXy693V8ZYVmfl
k8LzVbF7dtevPiY8kOMAJUUqO67L1wuxfGnOGrdvbydvtbxy2hmb+duESl4c
oKRIORXJHL6d5MsF7UG9eLPuravbp/K09bRKuHxxgJIipefvVielx4ubt6Xk
yuylOTAr10Yh6/Y6yZCKA5RYTr22X+Xh8HwuDcxWU3xpNp7dXCE/HokJD+Q4
QIlNrEbl5iT7cH8hOualOW/d5PrTUkPXWTPhMRMHKClS88fL3EwdPRdbj3I9
u7xY9EYXdeNOPr1L6DSLA5QUqW7r9FE1hpXiY0+6mL6+nDQn+slzvXwtJ+Sp
OEBJkXqxq/edwvVJZfWkT8a5q6H0fJKVcrnRRUKeigOUFKnM7dvV7dvj4F7R
nop3N4PuQ1dfPmuG9ZJQTsUBSorUQ77bzp6AsTbUsw9318vWjTqROnL2rZ9Q
R48DlFifGkitlaafts0L/fWyfHIiP92bbdG6TGzNxABKilS599RzTyr5c92q
vtaH2fvsabVgVB/y+YRaQhygxDzVexiNc0+XzdqVc3ZTfrZH2aVWuBJrVwm9
LnGAEh/I+uhyIQ4XlXNbORtqBVu6qFZP3woqkxMeyDGAEnuHV+qoVXm7LkoL
0xoOetnL2+pp8675+JDUOxwDKClS9afFvFsuvpWsfkfJ1fLPz/PnM729vFIT
6lNxgBIg5Y50+Guuujx9fizWC2avNZ091+aP/UH56eIhd//x9XsfUlJaudn2
8umhKp+N7mdqvj6qvmZKbLKYPbUSnn5xgJIi1WsNaplMtiSJ513jsTZtOd27
pTl91l8SsnocoMRXRouyePWQq9furYx4c/JWLbNad3kyMLoJj+Q4QIkNd2M1
lKXR/CbXEDuTu1H/PperPNycXk4S2shxgJIiZen3l+x0+CItcyUtnzWKM9Vp
d5ZXN9OEB00coKRINcaTM6WVX9nD69Pz7g2ryG9voiN3uq8JJVUcoMSUer6Q
ZFXJLYymI50tekO10xk5+X7mNCFPxQFKitRg2jy5alza/YeXsaQMi0tDe6mU
lPlETqhRxQFKitTrdf6xnulK1ulpLd/rDk9mDw9nzrJWv0zI6HGAkiI1nb7c
TNTCan42UGuLJ+t6kZWt04moiwl5Kg5QYnvmZKqcO+dvfadwWs3ez6zRecdQ
xno/l1B5iQOUFKm26w5qp242e9K3lOV5vlOZ6Ivcy8usktBwjwOU3G1mqOZy
ejIY3Dx35pNTo2hID6WXzuNbQj0hDlBSpNQHu16vaZWnZ3F21a+VbfXyrmWP
NLWdkFJxgJIiJbZb13e3xfrcvX+Qr2rjfFnuLRdmra8nZPQ4QEmRujAunprl
YevmSq8v7x9fS7ajXjnnCzmbUE7FAUrMU4Nh52xypZwUXrLjjCG/La+fF6eP
Tt1M6oqNAZT4zmFVeL2/Obtp3VZy4tCe3gzuWp2SyrTsU8I7hxhAifWps7w9
eDo1RtXOTaXcn+fk7GthlC8tzxMyehygxIElD+fdp6fsUyvbzKm9QXt1U7Aa
+pXdaCWMC4oDlFhLOM8ajR5b1Ib3F4MFu5pVK1Pj6VkelxIyehygxC6OF/ct
M+q8VJyXJ1O+09Xn50e5t1icthNSKg5QYsPhSb0vnD9fWrmMxUo305a+eujl
Z9cOS6glxAFKHILzNF7qWXXolGYF5aK8PM0+XSpa5rE3S2jNxAFKilTp4nx8
Ncvlnm6Xrf7TUFTFk6Xabb11HxL68uIAJRYJZls+v3YeL0Ynd0/1Z/MyaxhX
JZY9FRMyehygxDEcvdWwXVUnxuXLZbn3okwmT4NHZznpOgmXLw5QUqSUQati
lS+6rZdaoXhyzZbPC3uk6zXnLKFEjwOU2JcgvkmV0uDpLGPPFiePJ4v+/c3b
Qr2qWwl9eXGAEkcmFDpdZV5fVrRe89yqq2edl+HspH5rFRIqeXGAEutTtavq
6vTMHGn32UVjsZAnhaKiv071VUIdPQ5QYh09c/HaHp1I9o2ulapPYvVZGxgv
I7tZSbj74gAlFgmTq5b2tJIHK8PR5/0MHBJLTdEW0jLhlVEcoMRawnBxUZUV
rTRSrzPzk9a41ru7a+jS9SqhkhcHKHG0i8MW7WG3dX5yc3XeyNmv1rhvGbP6
1TShLyEOUGL/lN15KZnlxagweRy49Ytitl/vz8XF6TKhSIgDlFiil+RKo3R9
0rhlmWWhUXt97OadQvNaLiSV6DGAEod1WSfFfPls4uSmzYv7es/q304dkDDl
pIG6cYCSInV7bZw/je7qjUH3dpGfGLVM5m1cqhRWrYS7Lw5Q4hiObnuQsS8u
7opdNjWbxtvD+ZnROdOlXkL3YhygpEi1zuq1fFYf19hEG59e37qDVbuWzWjn
1wl3XxygpEhVR2Iue9Y9L9nZa0U2hyX92syUrMuFntDEigOUFKnK6+ugddrP
V7Od5rD1/Hxz5zx1ry4fq3cJfQlxgA69klRYJvDGxcxl6njboYqLlnMsjAAw
lS4WXv2fQ91sLUm1eSrYZuM/+ICK9VjU1hyL9mH1MMrUecBiZLsrtXtF2j/x
vHLhL7G1873ivnay6u3eV78eYKFwTCTDopmq4VKxx3CpTtvPuKNKdVjkg4qu
Yp05+1jAMpwq1pAONbbarLl/dETz2NfTV3hxgaAjlSm/Cnc+ZK+rvcFER9W3
yycP1yWyMIvLpHr9oXcsrMkkqDpV23IYZupSn826ib0B6JUmvEu1ninFrw+j
fKYOT1+CatkbVVHCXAXckFYVrwq615ACeEzkCzbHZr2wDJkC5ZxjHTDKqS+J
ucOUv/Je1p/fWADrStI0gCPUsUF1vW1OP2tHRXK/JPlmTfJPlLEMsLHIvCGv
fGp5xTuYcvgrdQ1QvBr3R0e8xghP/OPjrcenEnPU/hMXAesMujrlMPIKoZuw
sbouluX7oUQspHKpApGxDbwX1BbGmpG06F6iIW0rwBlIYzAt6O2gGnNTm/vt
Hba6VP5K2P/tb1ht87bGC8LjMNTqUxKIVlTSOlLaWhgzXosNC0PwDvHCdafT
4MmD9XbnegB/+ZXLmJarKlgfSOizpYNyIOhThuXOkZ4x80gJpyDo8AH8rJjY
BdzPZlSNg2gZw+3irse7+qweb7dVxVlTfWQVtgxhxXM5qWI0jhyap1/RwEug
xU/8XNADv/diLNbCJtZ7Gq5vIyXDsLyjKu9+HiqPnYxOkenndpAkz4c/4Q1Q
+eBed9oIA9kfmOnBxrhbvaaPt37B5s3bT5k53/1Y3/XYcuQ9j0VF2veLI7s4
c8z+DZVQwP6+WLENl3mdFHxAqa6hEgoe08zgpMGCiQq2rqd8cUv3U3m3smp3
p9G+V7lX6GLqtBpKr19g2d+hX37Y5MXHMb93ZmH1Jaz0kaaeyTwZl+c+R3uR
1r2qql7L6gNsgOkXmPYrg5N8pEKoiDWec/5pvv/k+yRNJYE6gxxuFGQ8wXaT
VFneDtVhB6FjKJj6u84YjlaRH67r9MJvGuX7c6HBa7GDnONJ7z6gIHWZOnTG
lOm2Tc3lJV0F0IS4XuOCmoXFbk0szjsxvXKVmonVCHnJvK2mn5TujHqDpk4Z
NXLYaPOJaOJMTWxe7QGBia77aXgF1LHULNdemGRjadwhE4KE9uEq2lMlqIuZ
AgkLOhpIWwZUmkfqfVDuPBaxhsWKnwS8AyPIqyHwjP89sjIKO6wm4RXuBZZC
TP0ccr9s9vG6iiwVHPBHxqZF2McAk/8Nmh7qPtTz1x062s7SqUITFl+mmgJR
DoVz/ZOaYileixjUTip0QJtKwu6tXgo5PwJDbOTv2WN44mWgU/MHnA+V3ODp
+12vARcoaXBUCz1qwHUMOrOlSjpsQRBf0kg6FvquqYMWUnMt+Mu9invf1qS5
0HCHbDU1j4UzrHuEnzHhTJJBnwb9umca46EpnLjHQn3CjPESkGu7Euoabclc
YLkOE/9yLq0koWnJKvAMjm3bWK1blQwscqKOJyj+ObE7WJS6J08sU54eEg8y
j25hGSWpXBi9W1N1Br/yUg5UXZWqUwdM52lAfjHfb5RifiOioDMFFlRXbc6X
+0rBegUNZl7nhJhmK0ERG08Uhr/io6DMADLgKe9xoWcl0Oh+zfGt+rp+kQay
jPx3ETWcoSXNVMXrqpEiHvXmSD1VFapIHWzw0I5Z16Twu7GkhD5IR9WAFXsL
SO53TAKBr1DJcoJOO9Gv0RMMtfPE8eFQVYk1fggBDnQLO1wpJEMthsWGJUda
NzmnRzYpKOvV4196Q+Jb2MUS2wYHdctxaq6ONcr9x1SYBUannrC+OogtbLGU
17rD2v3u5a+ta0Pcr6VqAw8H+6BvemaGHVigoY49oRZFuIZU4Bj4kXSoNTmR
DCQCvNJicbwYKlQREvF0Um229NrV8On4g320jmP7foFgttHEVefc+EM9Lai/
zKhEjd8TwSBLycLSMAHHIOuBbYRr6AAFqNc7lmbEhz4cWkP7HZFZr9eFcC+e
XqfFZZOvNaWEUG9hJN8nrN3PlhMJbWJs1afSuh1SYyWLN5HhbYfWD7wGZER9
blb57/h/hTeoyghxKZ2paL/QwTvdXLX3u2QRffy2Wmt5wrWRkCQduRbpHd4W
29BgOIZYTMxTMVHH9KcUlM8OTfsP7I2MR7mTbqM28TuYA4aL7X0bsIKfbGwh
GWwe7F8pwpm999/w+5cL1XCXsAKujqd6uKoOGkihEowzOYUtKUBppP+kcxlq
WHltSWMXtk79DasYS/CkKJaFKxnOMwQAf7c19MwcC4iWyQdt1QqttpAtYPsB
jRlY6L7LeTJqKo+lwnhCtjIfE78QZ/wLGr0Hn0gz1KV+F3IVUFxnjph7b/Rw
WZ9QnU9gWDs1Ns2xV11NUVNw/oGck7Ip1Ukz27RU2abCTzj0Laj6x0LHAVEN
f8sWxCwff2NkGpJavt3W+j3QIWGjqbq/BXEBVctxYTMhjF0Awqhj4W4JuNQQ
fhO+3Hau+kLP1WGnbU6FHoJMMB3R5DUOA7RbsLjYC+9YOLUk3hmaD8uQAYKx
vzjmDJsHrQxzBidRqBKoiWRSDVB4UiMrnZvNzLGVG/V75659a47zt4/D65tf
UbP7mUCsKz76pxqePJEKf1K4cCZTJqbMe69+vxnmxJ1z9Cv2vw+XV3WcYRVP
y97ThvXwWPjClyzKxL6qhaWyqEpjqMpUupDNVyuVfKY08I2uQc2j08AcDTzv
gTLoX/QGQKf1g2ajfVU/jPB1Aw/mwHZ7wFYaPexbpQufGr2H3uG+vYXe2IFN
b6Z5cWq/yhlaZ7wBTEszh8CkYACqRFMUfy2gsw5bgiRvG/QA2M6faGvvHeow
wvC5Apzb4/V6fAv1iqVqsVwctLENTs9rgzPYUBIGqjE4Jdtp0OqcDhoMvXsD
mEKUvru6jG6eurjIRPI1lq6dyS3YMPVmmnrKxaKwcpo8Ium7mpGvZBWmSqLU
vdRfWu1J93VpynK2La9Oy1P7QpMYO2ej5VVh2Kvn9Pb12+L65vqpxXKK8Xyb
ehtp7Kmu6w7IJnNw2eP7IlJUrdYRrrlG1UN3hCdGUT6Q0MmGd03E++hJoHTW
2zb3KjMMsFZqcOpaJMhzWeHMxV4p/vqgIvbR6wYAi2QDZYrZaVMZK4OlPnm5
eVRvB9LFk/Lq3M8bZ+y08K3bJlMtFnLZ6sDvzTy4bQ3ChBkE1eb4Qo+pxcug
1uE0pA7FP4RIm3PZ2T40DBddiABLs9P8UxEecu7za9KuO8Cg7KTOt2Imk5op
ox3suDJdx00NWfp0WGy/TbL6LNv81fmlkK1UPbHqz5mOE+xWBX+YzVZCGxTj
EB3UqbpGmBkRnCf+QUR/Qhh7qJMJUwfJsz7CYFYvLCx8PzbizxsFvKnZZ7ko
bpiVWA8OqYO4/SOT2txvAVv9uG23RbNv3nf31ZPz57NBozV9vlY04+VEumMr
zZ0MX2/+SfuubTq3p/XvQqdsdZNO32frTUzHGslUr1kSs8W9zTZAa/HKbka6
OWQysZuy0X64VV+W57YJmzKfqxR3bUriwncIE3CrnSasA+b9KLX+7J34nVbH
H50WSNk12EY3lndWpHX7urIanea4uYAVyeYLmUNPZ79u/UvzqcpmY49LMzuJ
nowO48rrwM1W549vUzwuCpmCx5moSNoTcxYlQLjytW1I8sQRFRAdWCVfYWng
qLEFOrLXkkIybBXe2FdPPFss4j4AYjc4CKGHXVNBzbzEWuQbuv/7ozO+CXxg
IFJLsATYRzJYgo1j4cdMiMh35TrYKzY6B5MeioqCsDdwLYZx3UI18iVt3KmD
xZmx/4J3q4blzeOq8YNcjgo1iQtpUQKtl181pj3k9xx9O20y7h3A8tHuckT9
oMjfiby8r1Q1gYGxQi2lhyvhDJYBLA30R5CNLxncksMWSMfCXa+GVMqLYD1E
CYVX5ZsFnN85zbKVIpgQlUEP/X1gxqlv9Mum6bWbGoFXuR64yre8GOGZy8EX
ni0EDF/HmvHCpUSOrjWBTwP6RacjG/II2x5E7ah8RqjNLFWLETEfokWhWqjm
BrfISzh95CU0nTZK7Q5qsebQthmUdybPE/tWFU+ezy7E1uuLsWi9TcqqMdQc
97yjze5fXrvaw6z0cKt0+8+l0nNlJlaeXiSJXY2Gk8dU3WyXnk7cqXTuSpnx
1MGrDB4foOqIiT4TMpnPufLnTIYWCow87L2IZxp1i6V+kL/5bicilR8Fs0O2
bDqdJHwfNwy+LwZuhi422AWj91ioS4akSMKnOV8Q/DFbjqzIty1ILpsvlbKZ
QR9vxVHT8l4fNA0YyjTQlTjo3zYHVzNmDHouGIlxAv7cqprLWXakGBk86DKV
PL7Nmy7uo0DQ/lmytqggeieUyEH4IuMS9mdvpcNmVNHBb6DKJ/TRFWT7FxW+
dDdHoRrw8FrPhJ224egxbXFuEi7UrSsN2hk829gA2dImuXe4dvZAogXlLpxd
WkroMy4b0yMV+07xZlYF+m+mkC0NOP7/lsv8W66S/bdcdY959hE0OCGvm32x
fnXJq49nPwvZIrpLecsHoem3fPCabeK9E/K014N9Pd4IzEfmpMYqnhfotjdg
w8C+Q82iiN7U3T0kCCDvTGbwELvfhXPJ0mzLnYDI9Wr8E+nF78LsKH2KmRz5
acCK2OcEQ4p+m5zPlfOV96CTi23zLAAJCEw7QD3QW5lWv3vK3cefhZphIA/6
BqB37fnQEn7iY8Ev1AgJed9n9p/WuI8dfUQ+5ZTNN4WNJwaxh6dy/IqdG39h
tAIX7pvYw+tM+Lc7Z64V9nEWRCB+V7L+0VOgmC9ni8lOAW4mn96GFebiuwpz
kbvwJ8x4g//hpTe2boiI0eo7E3pHcy7u0pzBohtZfjM7X2WK1407o/Px8Kpc
uHAKIDpLmWJhpxfpY1P+RCO/O/XyD5k6+ZW2XfLx0588lkFDbE4vy2gilcol
b/bo+dC3PB/fZeH/cU7O5AvlQr6c3++p8H0SF7Xz5p+N/7etnoaqvNdgbed1
Ct2evLOaZ2+ji9nQmGiZGrogstnyHtfMdyFE8YcQIuKj8QgShDWsI9D43/Zb
QvGEunKuzPKlOVZtZPt8MetbxD59vs1XU9zw1cSSryBuUfDb/DbFkN/me1uL
3+Dd2beuG96dRJjGr2YpVytWXtvZarcDq5nLlTO+VbcdoBA6n9etJeE9MXro
hTXQjHDKhjF8HgK0+/rQA+9r1TbeOQ7R2WuESOXHn1H4GY8+4ye1d1C3wBAg
jTSX5fcDf90iCDIoEWXIr7kXkiNPfp3/oiqvi2FmcqpN7P+GERe/XF/oo+nd
mZyvut3Js33Z0mdL8bUhunXzZtUda53Zf0MzopS1w9ti1y33B7lC5V9x48KS
HDiWsmm/8R7+PUry6jsUTz7WFkvuessTOsSZa+3hvcuY8d3tUymr3KvX5GWE
o+lQiHOxhBR401aYvr6KtjGO2NVYmua2x7UCgkVhcxCIOt7gfjm96jWa3Q3T
ahMwUvcETE2bafaxcMK0MRpwvwv5rHAmGWJ2g9zbFtZeTLkd3Wq3Tk+6wVnl
AJl3CY5NKF7QCZGa8lTsXZA4lHSuBGd+jhtluUx2UMq4VZYx9qwO/TW1OaCr
lHLZ4o5BUtI8m1qwof49BUeujNT9pwsOriSBUkSky+bKe6RHwNDXmYJzcSb3
lqPurx8XF4V84btK3fy/BPE8omXz7xFN7ln158uVWR6MExCNXDXfk2olocFk
olrxPaptAEonptMJv8MmLZzfYSO1itlctvQetRaDrvXSZe3VdSUBtYrV70qs
3Mdp9Z05jLx6QSKmR7VM7j2qZUtS61k0n1UlCY/lqjnSh/72WXBUR2O//BSO
wfUDPtk6FjcS3Zog/vWnPw54oGPNi8sMwhyDuE14g6djwt52JWu1DsINolN5
nosXz/wvEW5L+Qo8Dwrji/2MJ0rh3AinNy0v94GHrJo8dVaQMIXMwNQV4NUJ
xjPZXjzTFp2pH99shimdmFo0szDBMxKNjoNQBoQ0YkE0vmph2qplf6YV+Jlr
bHtMl8MDQRCFL+TheAjtmw8kGS/z7GZ5+nJzenYhM4mVtMLgcvxo6HbjyQdL
WuLHwaLqlS6Nh6/LzONT5eHJaue7y8L8qmLkRPd8HIDFTpIfh4p6Q0VbvbYn
1VV5cDEvDbPq42R29/pkzTLdjA+U3AMfh4o2erpvzh2tvBjP3xZnD/1cJ/e8
MCZm58p4ugkoW6t9nKySNE6/nDzfT8tPq95iJp2+rpTaaPmQz08vn6+D+V+j
QsbzYiJJOigHPjrWzIchRhJ90kqp+HAt1TMPw+fbxbJ/ImtGfzoq93TqSYDD
U6xHjsxDHrP9xZlYTFKyHx1aWgNIu8O3svtYt0Xx6c3tPaweLy9t/WE0cHo3
GJYIG8CDnvsW6Mv25KVWLYzemFK6uuzMr2/Hi35ffLjVaz4tG71uPRHhFN2W
0zf1nKR05KfpUu1rhtqU5fJ4PK2UTmrBIu1wGsQDXrsLrjvWWe5qcPMqX97V
jG7HGNxPcrmO/tCVfejh+J/vHzMUCI7bLcFhRQTH3Wn3tvU5MQfwYs3PD+cZ
t9ut5q6UhXY9HD+ezG9qs8aMFb917T24t5PbspltWw/LUasxGt+edW9LxduT
aaPpoU0+7KRIUwu0y+Gy3VlU24PlrPc0HI+uBkZZu++csgf7G3H+QGc1zqid
y9sPSxLQxdKDykUzf+tml4/Z0mTcOltYq27/dnFrSrX1CoPasu8W27Mx6R6a
b/yokrVr2XEjYU/5PXDG6dBRm6bA8XQ2W85lytl8fh/5EsH0Gsmm82CBENL9
Wv2bEAWNf41gNZ/LVr8dwRCsXCZTqlSKmWABrurX0R2GmaH8exbaaPBacK8E
8/GmGZqQKc9ESdNSdNto83HhI9H/KDKZcraEdrIHJZcYCrnnButLIgxD4nOr
YmvrNej8dwNdqOQr6JmlJfCgF74b9GKuUMoXYVE6IwFUbEoWC6UTY5LbXILz
DncdXoPQuUdVJUBn9RKYubLKk/l4WpCXy0bK2LEw4+lPGsOqIjQCpbhigIml
Dnn28UHkb76izdONMK9zwZC3GHl7PmyabDpTcdIJLJtdnx9SBp/QqV3WtnJz
+5G0cezJbZj8TZ4aiZm9B5iYNIQDD6HUZD83j/w+YCkYlKbElF9+GoHZxMCY
iL7Di1RgBprBMIVTsjBFGvOYV9E80w7vXq36JWPCdsSIx5ZgPiZjCiJDzIUJ
oi45I3HhRq5Gyaw6pYd6ufxbGc9eT3OezarwYhkzTEEh9dxPX0/5tPFy2aka
is1zLH3TC3PvbF4Jhd96CdSjfN1CHdPwQvnpgh3qum0BMYA4mOhhb3bd/kwJ
nwvVnnjZjRaZIGDDeElyZGMwWeXy3eO8dSKtZ2mogVHjZVhiSqHtrEv9nID1
byEdT7HEC5bcAZZaCefIH5JwpRoSPGtYkj01vf/MVRkedSVrCtvi1lVW8Ldb
NmRTaSJcAVUU0xrBo745VIGXrl1NAyY7OtrVGfzoaG/LcD592qiYm88niDmB
OAnZFDlX4Kxo6fbCIULgKs4lzSULVA5vWaLBdtY3jU7lZcZAB6+UhxTwNNtB
bBV21XjiIAOuWZLbhBOmzfC5n1pvGnvRJXyalipjVQtgUQ3Jf+ZOTFgfy/77
/2NskX4jyR2X1HIx51yTDHkCU4EldYBbhXOL6czClXmRMKaxDQzFv4eTT+hP
TN02EfwT2MMwpzNVIn64BgtfEy7VqWmYsKfgSR3E4kp4UDX+fs0wjZWOxZnC
GXx+9QMLx2jAwplCFzQg2GweA52ZE0O4tpj79/8LcHAcm0M7AekPjNeWNIbl
iBjVHug5kjvEifip+Fj7Zp17L2z/g2hGkvUDMly4JiGtWLApACWNaHLughUv
rYTaRAd5f/73//z7//33/5zCD+FcfcJgNlExVGqiq2xMU5uvFOFqKqlEbpgn
QsfzRoK992CaCgCAR62//78WQmKwLApfBhAjPcnB98+kqTvkK4k5n465sKfq
em1OMckZeGJCywHMC6Kv4Y7HBLjBhiDSTY2taJeRRoM1QiwVRB3fYA2R/+2j
u4oEGi+VRWUmrNV6k61hhURMzN7aZs9QEYYfs83844HG75iG68A6T0DLY9Lu
zS4S9wNOp9zXtGMLtrHGkS30bXlijpih4tI/SRZq1hM2GtGCXkguT9G9gINq
CLyOHNxSLVWZgODvAoorSSfGBAqCfoOaCiynQ3x/ZhoSVRtpmytkERSqsOJw
pAsnEmwCkqEWG8GRQovK/+it6K686a2jQFhH//IkcTwTdVNhVDyGH3K5DP4Z
/TXZVN6LC1R5YbjQmIEmRd4/qjYh2RtD+KU9/Lo0wYFzDjw9Ad5bwVxPYH5j
aS4Zu6TWJQgLXTg3h0yFRcbptxi62+DUODjoeecv6Xu2nw+JjrNjAa3gY0xw
565BHl7Ki8H47MkjmnkJCSKRr1FgxgiBooM9JdSE3Vnva1BUt8QG9Q4W4J+Q
O/DzDBTrX7Jl1PB2lkFB5EZYPYGmzCMEg5JJoYhm4dNPDeY6eDtIZ408cY2x
PQYJoHrh96mfDg/+f3LkwJF9MwEA

-->

</rfc>
