<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-34" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 24 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-34"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur, Belgium</organization>
      <address>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch, Zurich, Switzerland</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Serhii Nikolaichuk">
      <organization>The Capital Index, Austin, Texas</organization>
      <address>
        <email>nikolaichuk.s.f@gmail.com</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant, Paris, France</organization>
      <address>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA, San Benedetto del Tronto, Italy</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="19"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 260?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, two CVEs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 264?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">EarlyAttestationBleed</td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">EarlyAttestationBleed</td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>9.1</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 924?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y923LjyLIo9q6vQMzEPrulLfB+7eXxDEVSIiVRokjq2nGC
AwJFEiIuFC68aPXs8Ivf/AMO2+FHh/9hv60Xf8f5EmdmASBAUpDQ0z1rzVoz
3QRQWVlZWVmZWVmZoigeOKqjsc/CT03J0tZCzXGY7UiOahpC3TRsVWEWU4SW
ZOljVxM+1e+aYi6TK4nVXDmTFcyxUL/r94VqKnssRN7l3niXz5eq5eBdOVU8
FiRDEXIFwXSmzMIPbXztzgXHFNhqzmQHEKCvs5lUBl7Ipq4ak8OfDqTRyGKL
D+L+04EsOWxiWuvPgmqMzYMDxZQNSYexK5Y0dkTVcCxJnAI29lSaMXEsqZqY
LxzY7khXbRugOus5fN1uDk4F4WdB0mwT+lYNhc0Z/MdwfjoWfmKK6piWKmn4
o107gT9MC/7WG5z+dGC4+ohZnw8UwOTzgQw4MsN27c/CGICxAxhK/gAAW0z6
LNR6zdrB0rRmE8t055+FfrM2OJixNTxSPh8IolBrC9IEerXxRzuKvCBtaIGv
o+Q/WDDDBQR+FgQP+P0Z/uDju4c+gb7CGb7CxzoQAj/5ja0kfa6xFEwAPpcs
efpZmDrO3P6cTodepgEcgFadqTsCCunuVNJ1SRFdW9Il0ZYsRbLS+8j9EzTT
JMQcmvmA9zZPcegp1dwLKP32lKamjg4dHUiuMzUtpCR0KgjAIRrnhp86XofC
LXYo9KnDn+gr05pIhvpKdP0sDG6FhsVsmPpj4YxZumSs6SvGKRYMfEiYpzjm
vzmuqPBWKYX9tKf/O1WSp8zWpIXQcEdsPTP3dV43LXbPpAWLdImtpN8U3gzn
Yl8H50wyxI5kqUw4l+QXlzn7Org11AWzbNVZ43q8knTXOhZOmDZRXT3S5zOC
0xFc6pmD+8018PPUaO/4+qYxGZnCibuv1z7M1mQqqcKZKxlCzQDOHptAWlrV
AyZPDVMzJ2sYfupYuHQU+G99qhpSBKOR5jLFnBjQ528TfPYWJepTZkxWqiG0
oLfJPnzam+Ud6UJyLVxg1vt9tCRzyQwBR/3DBjyFWTeyuUwxUywU4tG5kNaS
0LRkFfrdi89SdeTpsfDkWir+ib9fmaXBIop0OQM4Kcbh/GZTo5Q83ddjwxIu
3JGqSSCipzpzhIt//Nc//p9//NdsX/eN7lTVhOsV0EAJsWCka8VKzVzZnf1m
0meS5uqGmgI4e7mNWVNVFa7UmalJMCJ3b7eDKRPq0lx1JI2mfHUs1FzbUWFl
D0Cy2ZH+jQ2slJ0ax9O7mRLqKaGTEu5VTWO6/Q6THQtXDDdCpHe0V7aQ5JSe
WnIwv80t0zGNlL53iZ0T7kKj2e83r66afaFfa18NmlfvdI5CZW5aIIGFnmrP
aBd1NUdCtLqwwO1j4dSSDDkqcxRmwz5mMHtoSyBxmfGbbhtvkaMjwVaqq5oq
GSACLHUCvKyo+/Dqttridad5VgMehJVxwgymMAeUAoVpwsCC7dg8FtowYVHm
mE9VU2cTKWW5hqPqLH52OuqMWdJUuHEB87XBxLqpaaqxd5Zakj2ta6Y0A5LJ
pLX0HXM8BmwupZGND2FpSoakRNemzrv4bQrNZWz+Fi5t2ECEvjy1THkvjzY7
7ct2TejixMumdow9piJdOUzSf2NE3bn3VUoC4h4YXKIsYNMXtnWFFO6KnwmO
rwvu+yKk+5EScQgEgdkTbQZLFDcJeA2KlaeFgd41uOzzUZC2I5y7BhOw+THv
SrImzNmoD8vlMgUSlaFSMYEGKYM56bk70lSZhp8uZCq5bDVbyQ23sEPkhlHc
hhHM8OVQNYY+ZkPAjHAIVAD6RwTsQRWDlXqb8jb96Ju7lL8fR5+fi9DG20jf
IK9osbn5V9AY1OC3aezpTKihfUgnI5x+IKWig/WgR7uiNfAZv+QPPOrVzbrZ
95RcTgZBtYWFqxmw1EYaQ9vBYrjjwDeSPIN3qgTWBAyPzAk2nzIdPtWoKWjV
tgd+D1fKC4Z7Sxpw6DEZ9ptfVeWXLYVa2MxBriR0kIlpHuBF8/auwT/NlgqV
Stwom1ftfu2fMk7mLpQUM1QbtnTXMuf4R5p+p7fwjxtq1DhMNp+yaaNFs9+O
8YeOBoYO+xRXjnYoYTMy00Qw10a4q4AR45MF9ASEjTtH40HA1TRWwdqcS870
W2eeBhkmR7Yi9Nnc2UuN3A+nhgybhyTLiEBzAaYv7NICaGVTwVBhq2D63FmT
KQrGs4MgUCJZTkNyJJQooHIItU4DrMw7sX/V/dOEycUQZsNRlXy2Wki2IrYa
/wl2DrX/AJqxE/gemrk/iWYcNc9a/ZpIHCPW2tEt5vtLj/Bmk8tHV3/sfgNa
pCUtVFNjjmWnZUQ3bTPZxV0tLSkL1TbBfrTTNJrFeDIR9cVqJeqTSfntDeh2
AzRYM9sUyW2TxFta6l8vaMLEy5bAvpiAlv79qVeYr/Li8jm3Elerwp+kXv47
UO/7C6a/ipBWCdhwXqiIzzlr+W2EbCoTpgG3iP010Ee3o/TsMd10Is465DXb
tZFa6r4VGh56gnEzDw17jaPGybOdtwc+fZ7I4rNcXIjjZXn69sD9wQne4N4a
9NYaPGO4lHCq5yao99CtoJjGvztg2DlMdgRJ04CHpAkDSozAjnVcpMxfM3Q9
9zIRl9ZqIU4r1UqioaODVvTlBJhgzlrkrLw95+QI8cSFauxs8mE3NkoTMMLH
uGwcFQRxDT2+qoxr0Os5shiyoF0bMRYA2okos8ESTKnMGdMujg/Suj0BqkhO
epVnN6vT55vT80uZSaykFYZXkwdDtxuP6Q/bAkTLrqUuJCC7aMFcaVus778U
ejURhYY8hWlnBky6bipMUFRFMExHQPEaWR/MFyGwMlA2YFtPHIcpkac9kqG7
/UNc4qOT5ri+zSDPpZeFWMjD2rAK3r68lyA+wB1iTMw3CHFm4nTPPv+rUWRi
vk2N8vN4KRbzli7Op9NvoQYzF1FywEg0acFE2H4WquW4kraHIDKzHNhX8UDH
FpbMYpwypguk+UFU2MXrbarMi+O5OKkWJvAfvfpNVNHfpIquGuq/HEkQqZiN
tPqig1ryDGpJTi59Az0sR47SAwQmrFJR1lQ8ANtDjkDx4poH7DUvromk+eFU
iaL2NlGKL5YsLirlgqivFqtvI4qoSG8Ikz9lRze41900/G0qTJjSjybMHFXX
4hLE7HhajNFfYwnjyO6PoMzguj64vv2nkGUyqbyI+ng6BfXEkj9ElnZDrFuq
rcLTxnU7lc2kstlCMZ0vl6u5TCWVL1eK+Uo5/OE+PyWpHuh7pC9QY4loJHVT
n4OCZoAZfIpeZtBRDElb46fm+E1P5ZW5CGhVfNdbWa/XxZBalKYDMk2050wW
VUWUCbNvcVTCm44JO740lqIvBinQMS18aLEx4B6iYKaa7ndTuUy2nKJphrdi
rxYlGvCCRMcoI9cBvpnQkQ7GHThsAs/RYLT26P4Gsth+l+4bREJvjGszQ12R
KgcK7hhkP2gDacmRc8X0HH3qHjunl0w1pqamvE2pumTBbBnCffjLD9CxbRru
//d/CB0VBDBojdGXjzB+eyo04D9zWHYs+rYl4dGRMLDlqTmGgUy2GksWUKY/
ZWMY2NYcTU1dsoHrbBvGt4WqCnsBGOE9U3VeATT642ARsZPuaXSmOu1Br/nv
tnDFlni2pbMl6WB9WoYwTbhFYCvhUloDuz6aroXKd4OOzGzhOrJpVD8iBGTN
dBV/mcN+peKBGs3eSDMnaWyXBh6D/4NBbDHRFg22FMc+bqLtoSYCaiIbzcei
hqiJa0BNlFSRn+bZIkZ+vDnPiIM3SFjaNQ8L+IjoAfY/LG7DhaURXndRygXU
8q0Ur4XgWbWhhlsGe3BM8SZL08iJJjB2WwSc1ckUpGP4QGhDEXmDLV9VYiT8
5U2x4E39fnHGJxwkV9gei8bGHKj+Ub13sCY2UmPOjSLaUiLDuKQwMh/7SswU
tj/ELSLyRendL6rvfZHN+F8AE7xyXMaSDPrUQSqVOjgQRVGQwABHb+DBAZ6Q
U1SNIKm6jZvh3DLR9BAcDFKAWdHQgAcDkwT/3/8ePSL5449jeLZ1mMAfRj3q
2x+Sm3bPh7l9H8JDOpilAzNA6Ex1Wu4oxOjBpip8wl3VPhSWUxAVwVjI4yBx
VtiMKzCxYGBTcynQjEVE95jGDXvjHKmlyuwYGoEgPUJPlwmbwHwKWyLCQoXU
to9w47HA+mHWsWCrCHvDxdsOoQk5TDTo0mIvropMCcTwxBmM+O9/j1u1SKdd
hCUFpNfRkQvCF/GRrDUggNrPCuh0BOjhfMPm4WqOjRFpwgg0Huh4tCaR6B/V
Qt/7DjL53PCd0ZsSbCWhjYIc9kYzUj/ge6Aj4gmmxZikHLQT+J4PoDzlwjHx
CLxrmXeo6h8LoNKD1K3NMXZKzKUyAggKZtiMpBPAtUzFlVXumCGELJhVtuTh
h1OwY4QRY+ipnBnmUkOvUWiwGlsAUyBSM4b7IqjHKaHuWrDVOtr6GL+yGJHp
6MhZmkEU4ybI0TQYqan4tJrKiBjLCO3gW+LDaLTkDgh6GgbhAa4cE6sbW0DK
qQIf106TUiovkBC1pzA+aSKBJHRokCPLlJCCu6wiI5eSj1vTBNprqCfaGWXT
JjeUF69Jkzyf+zI6xEecW+bSnFqTX9fmFJN9MgpMpRBQPpObsEt0Do8YIgDa
DOhVgDjO6eYD3smGuThyAN7rDkNmAIIAjIaNyfmMmALD666B/PCNzJMCa0JA
jcDnymOPX3SgKyIctScIs136gpjddifSdoqeSuqsA2L138nvDp9y4CG7xJPU
uqooGjs4+JksHMSXdr+31qfgaYawuH35gjMHTADTBDNJI3plNJ5tb/8naSbx
cRxGBgKt56YtaUAGi01ATaQhwZiXU1KAEdia5hynwHPu27I5J8GK/lO04C0H
vgSyg6WeApXM1AFDX10ScD4xJBh2XL4gPEacAWCFyarNhbHsmDDvKCVwmgFx
VSFt3Dus0UGyS4Zq66DNmvqe53YYy/0Y0vLCUfFvCdsoG+JjaYEeV7QeAVC8
0EvCg8d4Sgcvwyw5di0isr/YgC9qII64VCcetECw8zWBqPg2X5gXaLZ9g08O
DD54L1If+899aPb56LelNPx/mwQRWzPhuAmJyNBxlAYPHY+M1BsnLIyNfNkR
LPAWPkKccRmgimi6k+nOIDweUxhoobDe53wtq0YsOWAl/ixcg+REQXHwgXXo
bMiHLM6debRVo8N3C5cYnuZnkP7jeCy5IAWFByw6xQs0o2cRr4gfSwaK4cFX
MN1TwlfhZLtbeHZrM2QR+FstWARfoUUWG9TJwfE//pf/3SaYhok6z1fQxb8K
XxBZZmX/+6c/FamUBpuB4RGHkfYAHlL3ua3uw+Pfg0bue6OR42jkEQ1+U4Gt
8FwIeDHScf57d5znHRew4z4wIrNo/NyIIpEZ6b/wvfsv8P6LRH9Th4ec6MDD
P+eIrX/OR1Eofm8UihyFUgwKBez+zQ14L0Lb/iidMTQZbbTgR7x7sAoZXgOx
0x3Jmrl2z1XWKf/8EcwwdPnJctgeS82V8eHfhC/BIfsik6qkQtyIhrFtgDXs
4CFVaUKoLOdk/gJvp925BiqcjR6EYjqbS98zHK4l1vDAD09W0WkwwLZi/frq
tN1oXg3atcvSmdczdF2vR8zdfvvsI+M/BOVEUkxys4OseMZD3C8xUmcvzC1q
pH0JRGbr3JSRNBtFyJ0rdIKMknIDTlJTOnxC8AiODJuMDQqazNJz9IuCSQEI
osFDDhTfwBOXSCDaMQ43zFj63sxY4sxY3suMx7AYjjccCftFrPkPO0eAaPl7
I1pGRP/+mbt6fvlpR9aDgret2SLivjG20YF++uPg4D//8z8P7llgYUv+JgcP
YODwfzBBfPUOfqGRQWbECMyOzT53sGefo7Zv722u7TnwDnaMSTQeQ+gaiqe7
Inq66qiTzU6I7RXVJiMIGc5HNXzSrzIwB69d3EphmaNxwGDlQ1PJEVRH0KX1
AZ07ARVgQv3ADlB4VPgSGlkmWlcbu0mEQY1h/xc+geHJNCF/GAyfDypu2JIG
ejFqY6AtYOwN9Ar7jWYChysHXKcKBZQco3KOiqrhPYFdSQeQqBDxMwk/eEfa
HDUfjLlarqhjcjfjEGEw2G2fG4FeU+jfG7jtWiwgCEgsA4SEfQBUUEFJQM2K
Exc3qRSxzAEyDazeOd7kG8GmiZOgmahiYAeRQIv3tBx0ZNHRH9dP/v73SJAT
Ohxs24V38J1nxIJNrYAJcey5h7gjhLfe49oKm/pc8euYCtNwpq5JNfVXUCdg
Xu5QixoLLy7MkTBGHwyyCM6VbipRRRAHhZCgxw3148a+Z92M1oKN63eNxowx
wbfIVdDl7yAjHOl3AU8vQJIC5p6VVvdYAS890CQJnhxFzj8lj4jwRZpM0O5z
2PeTRwHIQ/KPobuCJIRnnirhtavsG+ubZhfMGkXyabhbYdwjegP8MbqG9yvl
TeCYO318JMj09LX0PWYl8QAFBJHCF94sw57UqJDf7wwm7qTFx80evl/gnKBE
lXBlhM4oPyH2aLdCB0vjcG8/u35g6CNwisBINXNJknNpCuRrIC4BieCtel9+
b0xxsAtAxz+hvUOYwlIjV5q3Rx+A/n1NNhM2MkH72M+ocxTMQWNJUTw/jxV1
5xP5PJtO4NuVN8kfIaViejEAcxTSACEa/yrZnitPxa/AevZcRiD1LeaA9ewt
B94vuX8AUZXw9yTHjgX8NgOi846F/aRkeVkTVyeDcDldC5H+CavAXUse+D2D
AObrvkNl2JD2tz3mB5ZTxod5dOSPDkYUdg+/t/UCoq7xjJfQxipT+HJormDr
RG4R+i7IAYt2e8+HKvShoQtCse/fdAEIIwnXNED7ctXuD2B1OZYq2xvZYiyU
FKw2JzUxF2lcA6L3SVpe2PZhCo1Vkspo/XhgwXylO9jYdzfwg3Lv6f535IcF
tU0Uxci/ANz346I6B9DJvQ/WLjdp6H02+irH/yUdsAJ/x8s9kRawf0QfZ73H
hc3jcvA1OnO/wp6iqK4eArNR3KKjSPNhIpN90KOH6tvR0Sk0QJPdYt7Z8rHQ
gm8dkDfoTYU14+99R0c41duExWsCNmL1M7CxCIys4J7/B04PvsfXQjBTp7Sy
dih+8HXPru2Tce+F7WNh9x411693rz8LHP7Otu5PyPfqYOf467v3sDf+1uun
8FY/wh7y5qgR5+D9jUgX8K9y7wOR/3YQOxHEHqhgvXGjWkCr+m9CKAUD7Iag
3Wxgkvv8vTFvBaq+R65vnZZQCOgP74KZi7+gD/2H92E58l/Rh6hISRbJdqgZ
tfWkcUzb7YPub1gd20fg3wBi52j9T8NIjsdmi9rsEEk2Jn7g4W0VoGF9Isc9
foTXpyljAm25pqXw/dw78wS1Fve0n8E6tkBF5GYaaZQOf4Ch1hoqH2gyg+7L
Tb4+k1Mwv1ke2PCGNcFtI/iw4H22OWCBXfGErU00VVAz4+dtNA6NwQAndLr0
O3qomhe/o43h566JVR7p9AzMNFBBMV6TjvCluW8So46HV/YZV9uxEaasEBQe
14Te3xAeQHqGx4bzNXfUoJ0Bn6WEriY5qNKG9Wi6CkbjxfAbdDqSD9ICy8E7
MaAPRkxDvwbe2FfRaAU7C56HR6+YaF9g/hvsnyeQOaYLzqEbPzjMu3rzAmcF
qAIKJB3M46uxaulLtJxpiPJUnYuuocJC9xRmjqQkDOonghfSSha9xoIIEX50
NPdGuWlnBfYdGpmg4vR7V2c+7kz5G6Lgu3OPN3OH/SEBPjXrh41WU/C8jsJC
0lzGwTrrOfKmFtCfj8c2xw6NhXE9mbw8NsXX0FF1KEbprrPxbQkTgOsI132c
Qtlazx1zYknzqSqLmjqykCksQArIg6EttJuCwc6PCnXTAnL7dP691+xe9wbD
Rm1Q+53fQ0KP1CYMgvfEjwFlP1GEwqMWiRfVCa6XMKPwCzCCHwTDT/ExCtIC
88PZnci/EfMzmEEeVwFkU5XNtTG6SuaieeJQpDtMrW97E4GDjjgOQfxeiLOZ
IZEGG+JC8mTAsmB0DY2tZA2ou+C+OmaHLW4YNfdIKTwagc8tMDU//Pz9snnx
iXPC4e/htWgDUprCTUtgM0a5owAtNKkk20ZbTFFlhyx4fujJiLRbi1SWXJvT
TGFjvDgFhpM3tmNBRrefQs1pHYoYsCM0eidnPJbmGBtxc33Da/C1T3oaPFiu
ABdDkKJS4Iu37xTFUg7+Fz2TkHSF37Qy0r633U7zY1tHDOKZRy5g5aBLR1dE
eySWM8Ui5WI69F3D5HI0DVyADDAxXPSMwbRYPMARRJireRL6syCNxzwzGIqK
J7BXi75HyiQ3DdIbALkWegZtd+zRSwuWg7ciueRgFnl1fu81+s1m43eBHwlz
SUHMbkFn2ppYXCK/nu1SHJfnZw3cCsj5tNOQuQywUQB73AOYiv2uSOyPBjWJ
FLr5OMYQB9+bFBx87Aakc/NcYTosEseiqx7cpaowSRP5wAw8xQKmcnXvnBoX
DSWXQHm89D1HdKDLo3n+tuEHX4+mS3kwxCmKvmt41u9f/rst/C6KuMKoJ5hZ
pvxiKfLc/V349MX7SMiniqCgt6/6g9rlZUpX9roCTfjYtrXgTzo2836IBCG9
gXB46HthcSSwAjbTBLSDv/dqV/B3ktFdpCgiBrM2d0EwqxosZiIVkDhwvqPD
UJr4DhFnyrlgCroKl8CevKCZAiZkFO7o73X+BhdamdzBcWkuxUvy13ek+dxz
0iK5uRHjKRsHp+oEfeG5WGUitCQGzaYoTQxQHIA5/JkT6WDgwA/PpPgLtNMl
AeaYvxR4eNuWT49kjC7Nbe+QxQvvRG4F+UFxCCZFXfhx4yAuNveZUfiH9+at
UyByucD4UjA6xl/wiFtQDDdAPvjP10hPH2sC3Yt7/hH2P47755uaQPdHR10/
0rPDz0SOjgAWjFukDUHzyRmoHG+N3ht50AypEduId1+vBzob9OzBqndvhda9
8B9Ef+BDF+D9x9bdgzGqMpZLIjfchIutNE7CJ65AHG4Ur/8Qeh1417zzT4BA
3+B43LgmbcB0Y5VjgmQQbpox0w0dCWnSCMK4fbrrhLrcP+qofuSPPASdDr6F
BmmcwqdB4/BdZsKUVw7FfQE+2wpYfFPC6Yo5FB5vo2vVp4APM1Db/oPkia+r
eSof0OltdOKbIrL8iy10Wv1OetCNkOYrj4xmW4t1LzE+/in1Rhpx7eL3UHdf
I7EFKEFhMMgRHqc0+X3CrX5R9U/fgWZFm69vurxLfF8jj/R/74nwNHrciVqb
FBd7oX5Lk033l4Nw/19hg6CgA1i+2BIjC98h6bc0CdnWW9uQL+wFL2SX27q7
4h4kyJZcR5t54EVZ+oEtqNQuDf9AJIDNgXLTz+a2X3BKGQF6QKeZtCg9M9CP
IIzuVRHlMKx+Rzc67u33d7F0eGq+Cj3XsNMajM3mp92/7uUbYbCe74iX/V/2
AlWLeuJK75vbz0c3k4/vOW99SSigUGjW0fqMIt3mAsIIi6WdkV3FvI18eN1P
+5LH07s4+33dGMP7+4+XpF+FMxJegUr6TSjULvxvItvQpumpt5v4l5jTwc6K
8zlVYX1b8hTPiwIHSKCg+510QA+31iJAQLPbl2lfhdAO7HfX8lTLdLCLgX0j
4RWD7TEFLWE46YvGqbAha8Q+37SoW8z3IXDS9X3SfRUoi4pvIsf8g1GdYTd6
oAJ7F05I1oRFy2Ww+LauzOKq3u/lQSHSBWMOplzfSzk8NKTwDjKN8c02r/w7
povowFI/+Flo0F0j+PwuEgnS4FEiKCMHqo4xGIzHJvGgx9rmegc/ZAWq1XxT
8o4HfaAkadLZKBGQhc+i4BXG+aiGSiht4lOYH59CcS6mF0ACEDJl4VoGSwSt
Z86bURQQg+DjbAHGJYc+DieD9dwsXzAB9casik/pAVNgp0uT0csq8/BYuX+0
WvnOqrC4rhg50b2YPKYx3o2nDaFeS9TrF49aGL3jGjLhGbL52Sjl94idwW+6
tZjJ5crZEpj1hXTkeuomPU7KsvklR4cxHteHLhR5DViEqZArC6dsFMInCInc
XF3ZPQ0UvhwdBee8vwit9lkL8ynyezKHR0f/HSF7OavCsO+a+47+Nj3FwS36
cEs7cCknWAgMusz3HgF+I/wvGz6KTk9MVhO8yCTZzE470oQHROIhBsWZZmkK
glvyFHhBjfYR5wMYV+mW57fiOzHfxrWYyooTM5vKlaCzHaQn5jcinM3sYFzf
0YS+LXIVb6ZoFMfxJSb52ocijbdhp+eupqWLFVrG5e0R3G162zMY8s5+44i8
9a8gb+Ziuk0Uf0QxSzij/LouRmTgit2CvhOqvSMU9px/xzBAwV9jOyz7vtjJ
7a7feq89aNdrlx78Kqwsj8H8TGWJesj/yR6SUyu3Q66dDvkxvE+3wm6vwZLc
6W33rP0DUxNKxpKsEzpp/5Ed8HP2H9uD/oN74Gfsf76HQCbsXnEEK9HbTVAX
080FV/NiogG/CoU/09vE/H49xVKORw58gHilP9MJjzGI9tJpNtq3Ha+fUiof
28+WluMHIGx6/aiIqXwUfO47gn9Xl/IjGf6Cbj4gHmO72dhQgQUTjWUP2xFh
C0baMl14cN6Vd2kaLQMe32fwSws0JxhOKxnrzbnOWlhOwSQwEXvvGnY43iAS
BUEhwb/fM2mGme9/P+Z/b7R+p6PC308kpcm1id9TR0fouwHD2dSUiB1JrifT
xlP9FEsdezD7dOOBoNLQvAcAmo9U02ABm4rv5bL9m7gSr1dDQYbNWy/t7kET
c+cyycByEaYBNuIXerHRbPbm2Z2aOpuDCX5IRIqGkIUX467CTmPwtUd+kSOY
GRhtKGmUf0MV0EXXFIZjAM2pPQ8rv4teInk7uZJwqTpoTwNXbCIpF7Bp27KJ
UR1/fP/Q2ahdzdd4EKb5xe/twzDfiKH9slQtWAdzOvgK2Zihp+kxrBI7eISX
1bjDAjH69IWOU6In0nhwp3FN1rsbB0/TLqasCxJsiTLD47102MZNU8PgzFoM
v+PH39mMmKuImUzWO7pGdv1S6zS+x4l4PlPIBGA3HSPp6I7kFV46IJoNms0t
eoFBHaYVXWXbotQ2kEajZ843EBQFVwaZIrg86Oc/k9YlMVMRs9kfR+vKB2nd
eFDMZcjyU7SUJOvk+VBMNR1kVSsVK6VCIQUWZyaXz9A9wr+QXAVkzUyYNfHi
c5GOEJZ8JH1H0pgbkgIrWRL9SwObelo2/8z/c8jTi4G17THDJhakWChmqtHh
xWWG9xogjAIP4vUi1xG5E9h4Zqe1/uA99Eb44RiT+AZ/G5rSDOvl7MOxlK2W
c0lwxAaHiGFuG0NJ6dU6G1AjCexVHdeK9zfs++t35NCsFx+DN6jzfyG5sknJ
lSUUq1sonkojkP4zpryH4tj/cPO3eKbLZj6AITwMNdiL4b7Yiyjkv7AiDY4y
5goCv/xx4GUQCLmETugWRmx48eYGysfb5/a332iv2woND6Rc7Co0ER++HCg0
WqDQ+KeL8gZicGKJd4A3+tbRESAEuiaFi+4x+xQv/61/z1TlQVk6dSOsmeP1
wYLsr1jEbRPdtxdROgnjAeV4ozbIJhLKPrNkeGPWgTEZPKd3JDcSqauY7Ytu
4RwceNGXOzfFUA/VNqhtDkLnpuPrg0njpD9tZz/hiYtoNBtD4/Dze3el9t2C
irkB9Yloael+tOKCaSbeFzz07kVVthvg40qqLIQvP23fhyru3oWqCp+KQmxf
W3ekyhEebm7KiyakawwxBY+fvfRWcwtMOB0TMawxOlDViUOBpFxzPyYOHasY
EIil0SiEll6luElFkcgOZrAK90k8FfKztqMH9gcHNTscJxgbSU74x+YmAu53
MFTdSxW24cxtcu1kBbBY6HYqcJkYSuLwffM2fN4nPfnIdk24984DEM9kKUH2
lRkgnL7VI31w0B4La9PlaaR4tO6YjHkuaWOvX25Fjc7pKEXAAhWuLaCxKtgm
l5JLHlUtT5k88zKb7V6537lxr/KQSHjs3XWued64dIdnTwCO22HJQSLWoRzm
oeOSaJq+oyPf/4eXUa2No+/oCF19R0f7KcM58F86zcnnv+S0CKkZpiGRxT+M
+J9+2ck9E19DZcPoSc5jj7/niv0bDEdXJyTsgCXiXb484SaMEfYvHHnghfWc
1ECA8IljLpXZS4mt49UNFZIfchxHOZpnU/GQ8ocVPygah2rxJhNzewx52Kn9
U9P3zl73DORDBynfYRDRXc0vdSn0wwnR7IPa/t0oCGuP5E/j3sNYeXmEQeBH
W7sVYvpxBiXJ8k7Snip8JthrfYRlb/blv/nbR05Kj46Cs1Ik8thhgb93B4W3
8iCE0MDxfKItVMSo/jkzRPIeHnoqsORnbtiTrueTaakTVF1wr0B9GFUoMVPg
Xly6PWTzuy5ASzFTOjzA5Ms1jOWjXIr3Z5SPQJXVOaZXnZvo5FAEEyP3vT0L
k7bwnWoE+14SieGn6pBILeezuS2jCPAmsUjoyzer+ey0Is97nu4UMAuJIo9T
AIA8tKZlwdKRUAQc8mbkH+an4sGlEZwqe7xOEXUoIWWUMLZ/2wSLxa6DnIh7
M+HgTbKgapJ3/wmr7DreDSm8aOglefETcE79lKpojXDXf3ymShpIyFKBKeG4
1yiOnAOyYPpMngTVM8j8ZB180EdHispv1QAX+/f6eIYR0HHeyLzh0453d3R0
+0b6YuxEdWymjcPJQ/FyEbOMYJVspb1+b3VSn7jxkQYfnnI1mgWWPtyfWTke
MZB+fqYgukhiY1qVRmsrC8in3yer9e+HPFgObMbo2xFzlqghyZuMPTytEuZh
aQXiz88whYF3n36fOrbsQyTjehOZhymvg1Y6DmjC7IN8Sqht8lVtQZNioYXy
XGFKeOngoMuXOiZD8W7axl+OQZheqnGyg4L03l0+IZTeu47Bwhrv5gyX4OHm
4CRYlsIfmGXKPwCjyFkvvZGEoYaDvl/AwvLvICEz8wucb/s2UpQOJ4wAjKYZ
KtMk4aT2+bT1vUk9yx7iDMW0CqWw3MzjwKP8BVL+LHeIM/MxGOH5i0LJH+6b
k3yiOemg6O3x/OG4NdbCSZv25dv1UoRHY7z35E+OTX22s4FvZcYRtxNwTpk2
t4NMbDyiNevjh99jtGeQX2qT7HRfu1y4XZtn2YlJ++aldnsvdxmlc9tcbN3k
4wnd8aPzuq4vjWL/+brJQSb8nD3OHReOS9GH+ePiMTpiurujRofKZ1GM7yHS
mfe1/5fgT8z9khU+x7EqSTlo8T/+r//NA/Y//s//NfoXhJJ7B8pMnm5B4X+L
Qsm/C+V34Q0o3l8i9y4w3oXzPkU9b62lcipL/O7dBCx+dGGR9AySPFFKJc9/
FSy0+AS9obS8m7Z+kv/957NxuXt/WN7e9OEPha6Zk5Szcj6eHfiHZQYOD/QH
QI8MdH/+4R+Wezg8tB8APTK02AzHPyy7cXiEPwB6ZITv5VD+YfmTw4P8AdAj
g3w3S/OPysub/qFZf6OD/FD23x+W2Dc80h8APTLSSiqsRUC3fn2I79evD5EP
6wfCDw1sz/FRaK//mfzegesJJveUb8Q27dhvveR1w5uDU98xAirkPfq6NdIV
Y3yZpB8eB8kavpB9LEYdQKu5FDq1QKMLL2vOmLW5MaSYcvqtpunDY6+Kd1Rz
Dam7kSovtjsBG9HxzH4w8tEQna5HlurnakXT65McXQSxSrCfOmnv68OPZv/0
Drr2mf48X5KixNREeg/JsI6O+ZyN9cbCHzGDjdXo+fM/e1JTyGFe7ZLoCdPR
0abgimdVoE8dZ3NnGsOMQV+8Nyw/KbTXCLln+7BytCZ/SshH6R2R87RHm6JP
kWQmW17f78ATO7V2yISOOCCJiHQuRX5OSjGkcEJ8BAExU4jg8C66nv+Je+78
SYIfpsX0IPQg6rkll17qg+LnsnbR5OKnr+p4sxCHBCPHdOsydEdf7ie58EWD
CRct6cNciY9Er1H68KMooglCGL7vbt+t4LrrQMZzdsmYkW+Vc5R//YimdXMx
6X3fPPJyb7eu5xEPXz4i4KETTxuTkq0FBbMrW6Zr+5XgAE1k/yCo+NiLZQlF
nEzVyZSuSWOkgBIKWP6WABzhE89DvBVU/McfhzypTCjx69HRJvUriARM/np0
hFEaeA5E6V8xd/uZuvAyCCOevHSQ7IV7BEFQ26ge41k0bBaUeFs58LzlLBTR
wa90wIpEx7tXhSxOIHdu+4MD15rw+Bc8Io4Xu17i+feYkK6S5+i//Ezbf7nJ
MxjNuMtro2Es1Scv0YIfkBFKiIsnBJhSwQteihkWSlzVq/HFs67REsT6dL5A
sFR75iHbFqSJl06aoVeCMrq5c5TGdtgHHU5eXtvqza/dENRBlEa00RkcNtlc
m2qJXroxTFVFG1jQykuD5vnE2ItLwp5O5yZYXsHwI+a9VEaA7JrO9YDjYGlG
vuHi1qt1ipHuoRpjIaz8YlbH3qL2a0gBO3lFoGxfyksaD74JMqHjYZSh8Ax3
zMuydBz0E8RJcHQoeAgTB8qbrFsjmjdLBUowhWv3fmudSXg2AkKHQ8fr5vxK
Jt2VDxyGXk4Mn8MihyDwMZ22yN7G62dZRDgjSjrH02jgO+YvSN/16h8ThBlr
M72eMzaggJ8Hz88llhL6wYlU9GR9O9PdCI8aeIICiUswyszFswZ6M0qSBUQR
nz6JOHOTsm2DFo0EXvs8HVCLR0axsZ/fzstGSY7oQcCX/L4N18MHpqmh6x/T
ie1UBwn0jmBxRKpOYrwAV0A2G53KGBXZsPASPmP+PkeZ3NPVCmw1xfyhX09k
a9vcpPPnVbaiFST8uJnQ6RwgzY8dv4zVFcp8r1o71YTwf/gp7ePdyx8KI9lb
bjtkJWFqHCkNuBzyAzyTfOYwbZhIkLKJ8Lz6SGnL4RGNgBMKxTHQiJZvNA//
Oz5xfxkg7BTRx/KUHRacNi5D5zpYgwWZEQiHDIt1H6ZeKjxeZyA4GyWwxD64
akNZFza1ImFpbbJv/uvNgEdqPMPHq2PRhbWRCV7q2F1saQYj2WuPA3kQqoND
90F2lalDrKHCT8o4T3tcECwgOdgCUKhRBT5eMZcHEURTG0amBycaAOh+ZRV5
aqoy84rVoGmlgWYSknaBHN8zRpy0Y66cBOpIlAOXhCcPvPQ2iHcL/l2ZWODa
15v9dB3/chyyf42S+sXliwHqbLd/weNANgpr6uB0hzc+Hxz8z7RbB9OC2nk2
lT+OLMAARuhqWkMFCc/EFtM0HVgT+cqvADvG/Cq47TENN3d4rmnqHPMfgjxe
MKovutGkgOO9dLteNk68AMcoWSoigXata0TsW+4fxvDxoDbllki2tnMl8KOX
TU1E4q49RELpfc/zhjoeE8EWaKhcref03dPMKxy7I8WCI1HvXGq+OeHGWlMq
VyQDYSgoJq0t34GhbmpGAz4Bi0ZLDwWzxAtL8oSltncMvsm2S1Qw0EYCgvvR
BdHXaKP4lV4ALY8VUnh/TNaobDhPfaT4GqRfuBMMlIlrBUkkYfvbHOUfhE71
Y6OYLRaUAHWCAilbTUM5uflZXGUnWbegc13MJt4GHYHp86lkq6/hOKTQGqaY
2UgRGUqsC9rmhJ/TkvB0uTzDmjo4UXYEXapYyse9UVei9y97FHx0sHkdDfvx
Ei1Hyq1yF8ReYqXwfBo/ptJeXphG6G4Ltm32r3vtep/uLRNuP29fVz0ITjPj
U5mGCpzu1oqnhRSkj+M0xHgSmQXFTrdLrXFkOkGdNh+P91KqxuKx0cK8U+8A
vB/h7K2Xg9obFX7fpPeblW4veaVbHjABVqAk1FEMgnIbxKoYbLm53YsaIH0G
WI65Si55ORUwrdKE+U4Lf5d+I24bVU2MXo4qNrQvcBeFpb9jW6cokBrlSI9N
VAyQiV6cIgOAv+BR/f41N+SmdKaczhTSYb+EGPglbJGSAoqBPSqqtjiyzBkz
SEGHLUzUpbUIYk5kK+ghXcyVSpli6RAw+nQuzSUD5vlQ+HKiASe1JOcKKDgw
Z+tQqpsRvoK1jMRNOfgu7cWt2ulstlrNFgmYT3NNMiYuhj0B1BY5swwzvC1P
g2c01kjU9VKyRUykjjwlOqY4YjQKDauA8oGCIMTyu2tRdWCoBvpqaSsHKTY1
FWgNOpsI/yJKXzBoB48DFDlyEcF7YKcwuIrxCwkT/2lChNKqki1VK8VsuVTI
/6r+ks1kMuVyqZTL5ypE5C/hpGRB7BWSOZSVjPk53i2ekCyMQjSs0ruo56mQ
6UOPsa7YyjljBgo8njgwxGG46cBrtAEZZp2l1zTquavZLB34msaatBQ3Wquo
GuJ+rou48gJLjHBpwApe+8Ps0e2bsIMTXvrM7V3NQTw2Fz2jwxMjhKB9gyM5
VR2YG8zNAFMoUlS9KKmcGv06piHVlOgSs+UlPqTuRpbKxm8uKItcknuHSEsJ
RYY4Ri6krYiTjXrOZIUbVzIcVw8vHnNipygRA+pUOL0pd5bOZEXvU7FtyDhF
G8kh4sYpootKnDE2F3GsXnJ0GPP6jTmxOWW86nPEpehPFm2aTHViONSSal+Q
DkyLtueCXJSMQ0xR4LHmpTTaIp33BuR2ynLTKAbSxXKhWCim5tM5gTljwOEI
hYYLQiUKwX9Kl0JjWUpllgs/+FSDGQOigiNax3TJJKn6qhHymeNdMENmKbAx
pZRspJHF0/xCfFkEsck3LGBldWzLK6daLQJnZVMKvyyMs4ZUKozU16gfHp9w
+YSBxZglALRicQx2lyTCXMxRBoB0xWLrkghq6huzskXk9qAfrsBLV9wdoG9A
V9W2NaaYeIdLU0VDsqfwx4wW6JTZM3ftiu5ael2oOvplF5EFskUnW39V9LDQ
s50UPeNLPy1VcqZWrWa26Yuh6WHhhEjyZ9SQ0ORUTRfSIOiymVwuoGYIjjpm
xiTk80nRA36tJ11xb8frTLejvzT5JLiTiWS4trTVr/+Y4wxDeIt9UByYGhPn
qiNPcRPk2wUuAwpOph0Qf8ma6QK5lqa4BgvYRk+Wt4WgZTtWo+i8nfVtjt/A
F+ngWzqgCRmRe2UZP4LFPuy5qTrhBAM2lZ11OZm9IrR4N7uaK1aztUwROPqk
LhYz2aJ4Uss3xJNsvlA+yRcbpUqBIGrSYiVEJ4+mDZ+npq7PyuktqcrPofGc
E3Y5kKMiXtAVMbj/7R2Aj8CculuiAp7wVZPOZgrFSqlYzReG2Vwukylkslzp
6KIpQKuBkFNUJ5IXJXiWUi3ObG9tAtGdH0RqdVzK5bJiriRLYjlXzYtVxqpi
sVgsj/JyZlQZV7aW46Xa6Qp33atN9xoYsos510z8NRlVCPxNx0vGyVHBafaE
CexwKYUttjY9fET8a6dn7VLXvHrtrqgBbApA3BAV6XeKvCySmgJhRjj4swS0
E9EVFN0ZEQebbxt0ufrNfdtTFtGupt7P8DICC02iMkpNMEEAc9M23oOgOu2/
vrjMWv8S5Wdqj7pJSgu1j+bykVVL1uA9PU5HvV8/B/AJkgw4WRoowWFVMfSQ
ZiRXyFTK21EokZ0aj21E9F5ucn/gxREDNWTJAPUNvrWCd1xJNJ5BtAeq2VY2
CnpJqSEwE+sO1cWg8tVh+GpcSOx6T0ivIxjemUIEbdAsUTYhVO/wgOsydcmN
+rRk/gCowYEBMgufAjTBU+ZD2OxwYxBJBpAytGt6T2hDVlSMP0mXylsCXLYV
I6rIpPARtVkydaUaw0IuXy5lq7k0ZhKYmNZ6mM1nqiXQfze9m7A1OzTZIbKE
HvrpXfbxK2dsLpk85qXDOsJ04Foz1Z4Cpn4tEtBB1NAOEnlM3UylEWaKwevG
KgiP6Cp6AwdVBin4Kq3VsTiTNHVtWnxupNkorGXTT269hTQu1QhtOrArAQ9S
kZVghiUFrBVZ2N1y+QuRy0OWXoJmANYvqHdj2AMJHOjMaHExMEclBoSBYaAE
oGMD+g0b7sQCOBJVZqKMPeKEgR2QLlVL1WyhXOQLoN1xNUcFUyh8x1z3nvHN
zhN2zIBlJwe3yqlyHBh6vICzr0D2NrJqY4nTuS25DoNT181nm9idyBXFY26e
b/yPvkuRCqFzo7oDipGEXkJpFqUf7l/QpRFoDnZa59/OpdnwLR0aj/J3TGr0
uC9QlJQL5WohWyzmy5V8CTg/UyqIL2KtwKeyZyqWOjGFEwtoZL6LjWWN6MMh
6FZcZPlHd1ySk1MAecYwRSQPbMx0d4mwKFZysKvmS6USoFPMiQ+ZWpFjcYJn
cl0LTL7tZEp7cBjBx7CT0cdioVDMFrK5ocl5FvMwOKQfvaVybbApVMvZSq5a
ANO3UMiIy7Ga901T04IpA8sXiDpmMQiBwmTTN2keAhdQPQ06d5qzGDcz1v9u
Cyf99sHB5ucpU4jLrvEYlF+s3Gt2fzpBr5It6Y4w/sd/WUIf1WpryjBixMB7
deFmNnd7zXjOuy3mE+qSBSaH0FI1B4uFAU2oSrRtC6DYzZiNIRjcNQi4HkMr
TflXcwF95vEn9Xo01My7YOllfAky2vMICdgsQNxoQkjIeYEg+J9IRSz0gJPH
Gr3jMC2hZe4HGvgJ8A94gn/K8M4cOXXMnYUYtEApaYI0CaO1UK97HQLeFGtD
Trr9iQD5YVzkKEK1/WMC5hXU2Nz5wNQtdfIvcs8FP/1G0DyiJ3j8pts0qMg+
Z6BncBcHHrpQRsoE3mOK3Uq3e4PTQIJGrrh6/tfgKy+oLsSjXr4euqwyWm+l
bPQvxQZ3Xr0PuXsekfbfoAqW4tdsfZ9vGA/qdj9sz6EawsGLTfJAq5aAJVHC
Z/V+BUpusXHJg0Tbc7y0z9MdQdO/fMkPUfghBTIQlXX7dHRElQtRETs6in6P
Z1deSFuMg/yQJ8f4WF0BjE9Mn5RPs43nofVsV9qZi0l+XZ/ne9I888Ca6Y8W
KHgX0GFCpKTmXVW5PTWd2s1ry1BmufzLibw8GeQlOxlScYCSIpVvLTLNrD1+
sBfrE0cr1SaPlWex32qpy2RIxQFKilTx8rykVu2FqRvT+brbuu+y50553NEf
bpIhFQcoKVJ3w8eXs9vH/Li5lE6Xy/W4Vm3Y03mLOZlkSMUBSorU+elQXuqt
VnNknQ/vi3eldZM59/eGqhaSIRUHKClS3WH9cbCWJ5mLs7I8upDc05o4u5s8
5J7NZEjFAUqK1NP58/nD/HH5VDTqd/rr8L5welF6UE+bjwkpFQcoKVIF28xf
rlrX1w+tfnZpLKauye7vJ6zemiVDKg5QUqRuSue6XKwsMnJWa9zl3ef2Y6b2
MDTHZ7VkSMUBSoqUUeiw4k23vlhOV3Lz3FDuWXcNFqlsJuSpOEBJkRqx3uvV
1WLZUcez3vi8O14x+cxszQeNhBI9DlACpOQx/LotPraUalZ7fFZf6gOnevK0
vmtcnbLbeefDSL0LKPHed1o3CyedXqN/uzYWV9XazbnkdJ+NB2mScO+LAZQU
qeVo+GhXO09K1a2andzJTKw4i/J48XCWEKk4QEmRMheVsViWny4uir0nsaM/
y6X29K5/Ip4mFAlxgJIilXNvXamRbawnz1eNTuFsMBStx9FyoJ4nRCoOUFKk
5if5qjS6yt5YrcKwNugMm+XKYtUduKuESMUBSrz3rS7qq06Lif2a2qu60+tr
TbMuCvptLeE2EwcoKVKD7Mqd354sXx6bJ/1WffAw6bcenhzl5bWSDKk4QEmR
mvaWhdLpcqLfKWp1/PKk58bPFyPNGLYTbjNxgJIidXtWXjeHM03v9VdX61zr
oTR+dU9No/H8ceH5LqDEq286Z21NYafjZsmsvpQuq3czJ5Op1S8SUioOUFKk
JnJOfc4sRiab9ofiIpsR+1e2tpKe6gnV4ThAiYXndUGvjV+KrfOnudNoXFl9
Qym/NpSHbEJGjwOUFKkH91werpvn3Xqn7T7Ki9x1p/zQMCe9+m0ypOIAJdan
7lqaMTptN6ei3L1hHbdxd/2yKj4u7hOaWHGAkiK1urvN18svt9fGRFbn5ZPC
03Wxc347qD4k3JDjACVFKjupy92lWL4y543e6+vJay2vnLYnZr6XUMmLA5QU
KacimaPXk3y5oN2rl6/WnXXdeyzPzh7XCacvDlBSpPT87fqk9HB587qSXJk9
N4dmpWsUsm6/nQypOECJ5dRL60UejS4W0tA8a4rPzcaTmyvkJ2Mx4YYcByix
idWo3Jxk7+8uRce8MhdnN7nBrNTQddZMuM3EAUqK1OLhKjdXx0/Fswe5nl1d
Lvvjy7pxK5/eJnSaxQFKilTn7PRBNUaV4kNfupy9PJ80p/rJU73clRPyVByg
pEg929W7dqF7Ulk/6tNJ7nokPZ1kpVxufJmQp+IAJUUq03u97r0+DO8U7bF4
ezPs3Hf01ZNmWM8J5VQcoKRI3ec7rewJGGsjPXt/212d3ahTqS1nXwcJdfQ4
QIn1qaF0ttb005Z5qb9clU9O5Mc7syVaV4mtmRhASZEq9x/77kklf6Fb1Zf6
KHuXPa0WjOp9Pp9QS4gDlJin+vfjSe7xqlm7ds5vyk/2OLvSCtdi7Tqh1yUO
UOINWR9fLcXRsnJhK+cjrWBLl9Xq6WtBZXLCDTkGUGLv8Fodn1Veu0VpaVqj
YT971aueNm+bD/dJvcMxgJIiVX9cLjrl4mvJGrSVXC3/9LR4Otdbq2s1oT4V
BygBUu5Yh5+56ur06aFYL5j9s9n8qbZ4GAzLj5f3ubuPz9/7kJLSys22Vo/3
Vfl8fDdX8/Vx9SVTYtPl/PEs4e4XBygpUv2zYS2TyZYk8aJjPNRmZ07ndmXO
nvTnhKweByjxkdGyLF7f5+q1Oysj3py8Vsus1lmdDI1Owi05DlBiw91Yj2Rp
vLjJNcT29HY8uMvlKvc3p1fThDZyHKCkSFn63RU7HT1Lq1xJy2eN4lx1Wu3V
9c0s4UYTBygpUo3J9Fw5y6/tUff0onPDKvLrq+jI7c5LQkkVBygxpZ4uJVlV
ckuj6Ujny/5IbbfHTn6QOU3IU3GAkiI1nDVPrhtX9uD+eSIpo+LK0J4rJWUx
lRNqVHGAkiL10s0/1DMdyTo9reX7ndHJ/P7+3FnV6lcJGT0OUFKkZrPnm6la
WC/Oh2pt+Wh1l1nZOp2KupiQp+IAJbZnTmbKhXPxOnAKp9Xs3dwaX7QNZaIP
cgmVlzhASZFque6wdupmsycDS1ld5NuVqb7MPT/PKwkN9zhAyd1mhmquZifD
4c1TezE9NYqGdF96bj+8JtQT4gAlRUq9t+v1mlZ5fBLn14Na2Vavbs/ssaa2
ElIqDlBSpMTWWfe2V6wv3Lt7+bo2yZfl/mpp1gZ6QkaPA5QUqUvj8rFZHp3d
XOv11d3DS8l21GvnYilnE8qpOECJeWo4ap9Pr5WTwnN2kjHk11X3aXn64NTN
pK7YGECJzxzWhZe7m/Obs14lJ47s2c3w9qxdUpmWfUx45hADKLE+dZ63h4+n
xrjavqmUB4ucnH0pjPOl1UVCRo8DlDiw5P6i8/iYfTzLNnNqf9ha3xSshn5t
N84SxgXFAUqsJVxkjUafLWuju8vhkl3Pq5WZ8fgkT0oJGT0OUGIXx7P7mhm3
nyvO86Mp3+rq09OD3F8uT1sJKRUHKLHh8KjeFS6erqxcxmKlm9mZvr7v5+dd
hyXUEuIAJQ7BeZys9Kw6ckrzgnJZXp1mH68ULfPQnye0ZuIAJUWqdHkxuZ7n
co+91dngcSSq4slK7Zy9du4T+vLiACUWCWZLvug6D5fjk9vH+pN5lTWM6xLL
nooJGT0OUOIYjv561KqqU+Pq+arcf1am08fhg7OadpyE0xcHKClSyvCsYpUv
O2fPtULxpMtWT0t7rOs15zyhRI8DlNiXIL5KldLw8Txjz5cnDyfLwd3N61K9
rlsJfXlxgBJHJhTaHWVRX1W0fvPCqqvn7efR/KTeswoJlbw4QIn1qdp1dX16
bo61u+yysVzK00JR0V9m+jqhjh4HKLGOnrl8aY1PJPtG10rVR7H6pA2N57Hd
rCRcfXGAEouE6fWZ9riWh2vD0ReDDGwSK03RltIq4ZFRHKDEWsJoeVmVFa00
VruZxcnZpNa/vW3oUnedUMmLA5Q42sVhy9aoc3ZxcnN90cjZL9ZkYBnz+vUs
oS8hDlBi/5Tdfi6Z5eW4MH0YuvXLYnZQHyzE5ekqoUiIA5RYopfkSqPUPWn0
WGZVaNReHjp5p9DsyoWkEj0GUOKwLuukmC+fT53crHl5V+9bg97MAQlTThqo
GwcoKVK9rnHxOL6tN4ad3jI/NWqZzOukVCmszxKuvjhAiWM4Oq1hxr68vC12
2MxsGq/3F+dG+1yX+gndi3GAkiJ1dl6v5bP6pMam2uS023OH61Ytm9EuuglX
XxygpEhVx2Iue965KNnZriKbo5LeNTMl62qpJzSx4gAlRary8jI8Ox3kq9l2
c3T29HRz6zx2rq8eqrcJfQlxgBKH4Ly6uVutrj12ZmeVyVX/uq6tzs4nS+M6
4fTFAUKkmjzpwudk0QDj1f2852iDl25Te6gsHgqLiqtelYqDhFI0DlBixWp2
m3m+H65atdNsxXrSnafzXC03Hy5bCdWFOECJQxSedOXx4kYbT5k1mprLdlN/
6i1zrdNsQtEeByixtpd5Lt3O7cawzkYv3W7natY4rz+v+y/NhMwVBygBUpbk
2GnbblhPvdP7gl2q96VHVqu29Vam273JfnwZvgsoKVLX3ZP28F4Re+bg9VWZ
FhuZ8yfzXrs6a39csXoXUFKkjLGlWNlBtavMS43h7DnXdPIPTzNxev1xW+td
QEmRmnQ6C6ebbT/YD6fjUeahaHSmvYF0eWl+fBN8F1BSpNbS2VnBvhsX5vXx
eaZ11e32FvmHSUY+Szh9cYCSItWQatnnxs3VqThSrosrUZndjfqvWktufFyx
ehdQUqTmzqz1dNt47ZuPRqPUK75qRqklN7PyIiFScYAOvbyMmCv3xsX0HVT2
vU1phy3nWBgDYMrfL7z4r0Ml3S1Jtfl96O3qt9CAMtZZDt5fxcy1mEKTrqve
Y0bO/eVKvEoln3hyFeE/YgvIeBnu7WQlTLxWvx5gtQy8TY2Zo1XDpYzH4XzV
tn/tnNK1YqYryjyOyVaxUEm9XxPZSff0jz/gR6c96DXFegApnOYXkzFj5moV
yy6EakFul6k5OqJRHx29MYpnF8g/Vpnyq3Ab4EGZODF1g6PquxUHRpusknjx
2aQSN6FvLExjKKg6Jah0GCa3oNLUMBCD8aT0TfiWyiPQrfgB9PKZiiJ+CQpM
RDMIRHgQeCetKl7hEK+GE2xSIp/eBda3h0nLFChNC6bOpDQ0JTF3mPL5xLso
79fiwVTMNAzgH3ViUCkMm9PP2lPEw6/isV3G4xMl+QDYWJfFkNc+tbx8V0w5
/JUK7SheWZijI56Wi9+V5/1t+qesrFQxGycBU/O6Ol3750m1t2FjQnrMZPtD
iVhI5VIFImMLeC9Ix49plmnSvbv5tAgBZyCNwbSgHJJqLExt4VdE2ins/Cth
//e/Y4LqXo3XUMFuqDq2JBCtqApEpBqEMGE8fSnmUgJSYUmcbrvd4Pft6612
dwg/fuUS6cxVFUypJwzYykGpEZT2xAohSM+YcaSEUxCL+ABeK6Zgm0ECANU4
iGb+3c2HfryvNPnxbiVyHDWVFFBhyRBWPP0BFVnAnkPj9JMAeTknsImfPuHA
L1cci7WwjTUh01QmTIPexP4aIOj2PqRk6JYXIZenDPP0bipKJKNTZPi5PSTJ
8+5PeM1w3rlX0D3CQPYHRnqw1a+f00rEZBmaHeo9eDMx9z1l5mL/Y33fY8uR
33gsKtJbbxzZxZFjwoxQ1iHY9BxMcorTvMmjcUDZIUJZhzymmcO+hDmGFdhk
eHJtS/ezX+wkotifeeK9ZPdCB7ONqKGMNEvMlD/yM/abvF4HpsSYW5iwEJNj
pecSL+Nj+SmQouW7614icsnTHLBmtF+TwS+mQfKRcocj1rjP+Xv/2zvfJ2km
CVRM63Arh/EJVmimYix2qHQJCB1DwWwZmyQb0cIro01qe3inUYocLjR4+RKQ
czxPjA8oyPZBRa1jKlvYpubyLOgC6E1cC3JBKcP88Cbms5+aXoZnzcQEvjzL
7E6dbMoQglqGps4Y1T7aqoyNaOJIQVsyfCAw0E0JKq/mCGZn57oOk2zMJj9i
QpADZrSOliELUkmnQMKCRgfSlgGVFpEUWZRuBus+wGTFDwK+gR7k9Qh4xm+P
rIzCDhMwebnugaUQUz/til9p4niTeJ1y9Pg9Y50/LP2D+XIMGh7qPvit7Y4c
bW+2caEJky9TGp4oh8K+/klNsRRP3w9KKuUGokUlYcFzL+sK3wJDbOSv2WN4
4iVtoXpJOB7KUsUz3nS8mpWgpMFWLfSpZuUxaNiWKumwBEF8SWPpWBi4pg5a
SM214Medimvf1qSF0HBHbD0zj4VzTBWIzZhwLsmgfYM23jeNycgUTtxjoT5l
xmQFyLVcCXWNlmQuMcOViT8upLUkNC1ZBZ7Bvm0bC1yokoF5wdTJFMU/J3Yb
6zj05allyrND4kHm0S0soySVC6N305DP4S3PfkQJyamgQ8B0ngbk57//Rinm
1+4LijlhDRLV5nz5VvZ0LwfQ3Cs2FFOfLMj75onCcCveC8oMIAPu8h4XejYF
9e6X6dhJSe/nNSI7yv8WUcMRWtJcVbxCVCniUW+MVIZcoSIOwQIPrZhNGie/
gFlKGIB0VA2YsdeA5H6RQRD4ClX5IOi0Ev20dkFXe3ccHw4lYtrghxBgQ7ew
KKRCMtRimJ9fciTOE8EjmxSUzezxll6X+BUWfgZqbEp94NBcHct6+I8plxn0
TmXUfXUQq75j9stNUdK7/dNf26RTuttI1QZuDvbBwPTMDDuwV0NF7kJV/XAO
qSYA8CPpUBtyIhlIBHjZOON4MZTbKSTiaafaroK5r0bi8QdLTx7HlsoEwWyj
QawuuPGHelpQsoBRVje/jJBBlpKF2dQCjkHWA9sI59ABCmggPwXMZowPfTg0
h/Y7IrNerwvh8nX99hmXTb7WlBK6xClkeSL5PmG5G7aaSmgTY3VblebtkGoR
WrzuGq/Ut3ng1ewk6nOzyv/G/wlfUGIu4lLaU9F+oY13tj1r7xeWJPr4lSg3
8oRrIyFJOnYt0ju8JbalwXAMMf+mp2KijukPKag4ERr2HwcHX2krd9It1Ca+
gjlguAz+bMAMfrKx6nKweLDkswh79pv/hfdfLlXDXcEMuDru6uFEdGgghbIW
z+UUVnECpZH+SOcyVOO5a0kTF5ZO/RUT/0vwpCiWhWsZ9jMEAL9tDf04xwKi
ZfJOz2qFs5aQLWDFHo0ZWBumw3kyaipPpMJkSrYy7xNbiHPegnrvQxNpjrrU
VyFXAcV17oi593oPZ8Lb9GcDw9qpiWlOvISkipqC/Q/knJRNqU6a2aalyjbl
SsSue6DqHwttB0Q1/MoWxCzvP+j5C+86OiJ/38VUg5TlNpSlL13IFgrZUq5Y
Hm4lhMN8cMOoJTtshWtl4cuhagw9a1MZgvHOa35/oQqtvdqgD/orLHJV95d/
OH30nqKw3ldplbfiXaPLUczk034GYfyNxLhTLccFiYCEeIcKyTtDGxv0K81O
c1jivq8oJbEkeuvOz1NML2H58A1KxF1L3Kl7Km6JcTGTOTwWvhDHbPBeg4nj
pkYsvS4O+72M2HhtZX51fskVi5zQWIdEAgliCL8JX3rt64HQd3WQgttsRg9B
XpuOaPKUzQFLncHCw9K+x8KpRe6RrwKnJsPFuSGpY86xFuLaMOegJWxgg+QF
FlYNIFZqbKVz87k5sXLjQf/CtXvmJN97GHVvfkWt+2cCsUlg7WscqBVEEhZL
4TzgTJmassdW322EOXHvGP0CRO/D5Umq55iU3LLfqCqP8/kNyzFfrVTymdLQ
N4iHNY9OQ3McWWtDoNPmQbPRuq4fRmROA5WmwK6+x8pgfSzDqQufGv37/uFb
cg/96kObvkzzWht+0la0nHk9uzPNHMHaA+NcJZri1nQGdNZBXNGu2AIdDUTt
JxK7b3YVXce5AuhUkz8lzPLFUrVYLnJJ1fcl1ZYCh1LrlOza4Vn7dNhg6Hkd
whCi9N1XNH1bI9qzaF07k1uyUerVNPWUiznu5TR5q9K3NSNfySpMlUSpc6U/
n7WmnZeVKcvZlrw+Lc/sS01i7IKNV9eFUb+e01vd12X3pvt4xnKK8dRLvY41
9ljXdQf2DXN45YnbSI7YWlvocm23j64ib4tD+UBCORteNRHPsC8Os96yuVOZ
YYAlWQONyKJNNpcVzl0s/ebPDyrJHz04ArBINlB0mZ02lYkyXOnT55sHtTeU
Lh+VF+du0Thnp4VvXTaZarGQy1aHXc9OGvbOhmHCDIPkuXyiJ1Sxblhrcxr2
m7XBjyFSor0I4e5sPfCQc5+fYn9T0A5lJ6h58C6TSc2Vcdwecjoqtl6nWX2e
bcIeUshWquHdGjqh7QSLb8Jf5vO10AKjJUQHdaZuEGZGBOepvxHR3xDGG9TJ
hKmD5NlsYTCqZxYWvh/r8eeteiRUu7xcFNVddQapg7j9mUFtr7eArX7cstuh
2Tevu7vqycXT+bBxNnvqKprxfCLdsrXmTkcvN/+kddcynd5p/bvQKVvdptP3
WXpT07HGsqfrZYtv1g4DrcXLIh4pThWv2J02Wvc99Xl1YZuwKPO5SnHfoiQu
fIcwAbfaacI6YN6PUuuvXonfaXb83mmClH2dbRWXe2dGznova6vRbk6aS5iR
bL6Q4TPSbnbP/qX5VGXzicelmb1ET0aHSeVl6Gari4fXGW4XhUzB40xUJO2p
OY8SIFzIwzYkeeqICogOLPqjsDRw1MQCHdmrsCUZtgpfvFUeJVss4joAYjc4
CKGPReBBzbzC0ipbuv/7vTO+CHxgIFJLMAVYFjuYgq1t4ccMiMh37TrwdGsM
Jj0UFQVhb+FaDOO6g2qkJS3cmYO1JrCclHfiidVa4ooLgVyOCjWJC2lRAq2X
HwOnPeTf2Pr22mTcc4PVMNzVmMpbki8aefmtyhsEBvr6tKnrPFoL5zANYGmg
r4j8L5LBLTms6Hgs3PZrSKW8CNZDlFAYxrBdj+Kd3SxbKYIJURn20RcLZpz6
Sm+2Ta/91Ag8/vXgGGPHwxQeuRy08GwhYPg6lsARriRyQm4IfBrQLzoc2ZDH
WMUpakflM0JtbqlajIj5EC0K1UI1N+whL+HwkZfQdNpyFA1rsebQrhmUd6ZP
U7uniidP55fi2cuzsTx7nZZVY6Q57kVbm989v3S0+3npvqd0Bk+l0lNlLlYe
nyWJXY9H04dU3WyVHk/cmXThSpnJzMFjJh67oeqIiT4XMpnPufLnTIYmCow8
LCWNexoe8C6pvPVvvkuQSOVHKO2RLdsOQQm/xwWD34uBm6EDs4kHE8dCXTIk
RRI+LfiE4MtsOTIj3zYhuWy+VMpmhgOMWEBNy/t82DSgK9NAN+9w0GsOr+fM
GPZdMBLjBPyFVTVX8+xYMdCnlM1U8vg1ryH9FgX8A3jQL3eoIHo7lMhB+CLj
CtZnf63DYlTx8MVAlU8YoCvI9g+RfOlujkMlbeCzvgkrbcvRY9riwiRcqPho
GrQzeLa1ALKlbXLvce28AYkmlLtw9mkpoWZcNqbHKpbR5LU5C/RnppAtDTn+
/5bL/Fuukv23XPUN8+wjaHBCdpsDsX59xYupZD8L2SK6snkFK6HpV7Dyaofj
mSDy9IK7/jf9jcF8ZE5qouJ+gUcqBiwYWHeoWRTR072/JBYB5IVWDR4s+VW4
kCzNttwpiFyvZBGRXvwuzI7Sp5jJkZ8GrIi3nGBI0W+T87lyvvIedHKxbe8F
IAGBaYeoB3ozczbonHLX/mehZhjIg74B6B1J358JP/G+4A3VdUTe95n9pw3u
E0cfk78/ZfNFYeOOQezhqRy/YiHqXxjNwKX7KvbxqBn+6y6Ya4V9nAURiN+R
rD+7CxTz5Wwx2S7AzeTTXlhhLr6rMBf58cqUGa/wLwYkYCWqiBitvjOgdzTn
4j7NGSy6seXX5vVVpnjduD2+mIyuy4VLpwCis5QpFvZ6kT425E/U87tDL/+Q
oZNfadclHz/86UMZNMTm7KqMJlKpXPJGj54Pfcfz8V0m/s9zciZfKBfy5fzb
ngrfJ3FZu2j+1fh/2+xpqMp79WL3HqfQ6ck7s3n+Or6cj4yplqmhCyKbLb/h
mvkuhCj+EEJEfDQeQYKQk010IP/1tiUUT6hr59osX5kT1Ua2zxezvkXs0+fb
fDXFLV9NLPkK4g4Fv81vUwz5bb63tfgN3p235nXLu5MI0/jZLOVqxcpLK1vt
tPFINVfO+FbdbvBIaH/eVMqG78TophfWQDPCKRvF8HkI0P7jQw+8r1XbeOY4
QmevESKVHxtIoYE8MpDv1N5GfQaGAGmkuSw/H/jbDkGQQYkoIx6CsJQcefrr
4hdVeVmOMtNTbWr/N4yG+aV7qY9nt+dyvup2pk/21Zk+X4kvDdGtmzfrzkRr
z/8bmhGlrP3jogCyMVEA1XconryvjwQBZD2hQ5y50R7eO4yZ3PYeS1nlTu2S
lxG2pkMhzsUSUuBNW2H65ijaxhhvV2NpGtsbrhUQLApbgEDU8QT3y+l1v9Hs
bJlW24CRuidgatpMs4+FE6ZN0ID7KuSzwrlkiNktcu9aWG9iyu3os9bZ6Ukn
2KscIPM+wbENxQsIIlLTHSJ7HyQOJZ0rwZ6f40ZZLpMdljJulWWMN2aHfqa2
O3SVUi5b3NNJSlpkU0s20r+n4MiVkbr/dMHBlSRQioh02Vz5DekRMHQ3U3Au
z+X+atz59ePiopAvfFepm/+XIJ5HtGz+PaLJfav+dLU2y8NJAqKRq+Z7Uq0k
NJhMVCu+R7UtQOnEdDrhZ9ikhfMzbKRWMZvLlt6j1nLYsZ47rLXuVhJQq1j9
rsTKfZxW35nDyKsXXKn1qJbJvUe1bEk6exLNJ1VJwmO5ao70ob9/FhzV0dgv
P4Xjo/1gXLaJk45EHieITf7pjwMehFrzYmaDENQgpha+4BdrYW27krXeBEgH
kcP8DpIXa/4vEQpNd0n4HTWM/fZvo9H12q2rDqbl3Uvh4cQmvwQtSHi9z8Br
RcCr03Dk5Q6dqbzwfI7XbfHa19zCy7eRmwLYCd1OkcYsuCmhWngB2bI/0wz8
zDW2N0yXwwNBEIUv5OG4D62bj6QnybOb1enzzen5pcwkVtIKw6vJg6HbjUcf
LGmJHwdLt9BLk9HLKvPwWLl/tFr5zqqwuK4YOdG9mARgsTD2x6Gi3lDR1i+t
aXVdHl4uSqOs+jCd3748WvNMJ+MDJffAx6GijZ4emAtHKy8ni9fl+f0g1849
LY2p2b42Hm8CytZqHyerJE3SzydPd7Py47q/nEunL2ulNl7d5/Ozq6duMP4u
KmT8zlLkAhXKgY/2NfdhiJFLWGmlVLzvSvXM/eipt1wNTmTNGMzG5b5OJZaw
e4r1yJF5yOPpvzhTi0lK9qNdSxsAaXf0WnYf6rYoPr66/fv1w9WVrd+Ph07/
BsMSYQF40HPfAn3Vmj7XqoXxK1NK11ftRbc3WQ4G4n1Pr/m0bPQ79USEU3Rb
Tt/Uc5LSlh9nK3WgGWpTlsuTyaxSOqkFk7THaRAPeOMu6Lat89z18OZFvrqt
GZ22Mbyb5nJt/b4j+9DD8T/fP2YoEBy9HcFhRQTH7Wmnd/Y5MQfw2hNP9xcZ
t9Op5q6VpdYdTR5OFje1eWPOit869x7c3rRXNrMt6341PmuMJ73zTq9U7J3M
Gk0PbfJhJ0WaKrpejVat9rLaGq7m/cfRZHw9NMraXfuU3dvfiPMHCsVyRm1f
9T4sSUAXSw8rl818z82uHrKl6eTsfGmtO4PesmdKtc0Mg9ry1im2Z2PSOTRf
+FEla9+040KyU2/CmaRDW22aAsfT2Ww5lyln8/m3yJcIpo5W+4Sl82CBENKD
Wv2bEAWNf4NgNZ/LVr8dwRCsXCZTqlSKmWACruvd6ArDW7u8PQstNPgsOFeC
8XjDDA3IlOeipGkpOm20eb/QSPQbRQZTzpbQTvag5BJDIffccHNIhGFIfGzV
TDEMOv/dQBcq+Qp6ZmkKPOiF7wa9mCuU8kWYlPZYABWbLvKFrnrjBcSFBPsd
rjo8BqF9jzJ+gM7qXS7nyiq/aOldHeH3DEkZOxbm/GqaxjA/DPVA148xwMRS
R/xm+EHkl69o86tgeOd2yZC3GHl7PmyabDtTcdAJLJt9zQ/pdqXQrl3Vdu5N
DyJX+qeSjdfw6Ut+bRVvXR/gpbERbHgIpSb79ybJ7wOWgkFXyJjyy09jMJsY
GBPRb3gCEbwdaDC8XitZeH0d75ivo3eA2w49Vf3kP2E7YsxjS/CuLGMKIkPM
hZd3XXJG4sSNXY0uGut0ddfLs7BzG51r/ha/aazwRCZzvIJC6rmfWiDl08bL
M0CZamx+/9U3vfBepM2z1PBTL7QSfOeUAIovXpEM5Q4QbGQH7zjaAmIAcfCi
R/h2IN1V/EyXcZeqPfVunlpkgoAN411gJBuDySqX7x7nbS45e5aGGhg13u1X
vO5pO5ukTSdg/VtIx1NMv4PJk4Cl1sIF8ockXKuGBM8almTPTO+PhSrDo45k
zWBZ9FxlDb96bMRm0lS4BqoopjWGRwNzpAIvdV1NAyY7Oto6qE4hWx4doeG2
58Uff/Dh00LFvAl8gHhfEwchmyLnChwVTd2bcIgQOIsLSXPJApXDS5ZosHsj
n3qn1D8ToIOXZkUKeJrtIbYKq2oydZABNyzJbcIp0+b43E97YBpvokv4NC1V
xowjwKIakv/cnZowP5b9j//X2CH9VgICnFLLxXwAmmTIUxgKTKkD3CpcWExn
Fs7Ms4QxjS1gKN4edj5hMDV120Twj2APw5jOVYn4oQsWviZcqTPTMGFNwZM6
iMW1cK9q/PuaYRprHdNshW9X+pkpLOyjARNnCh3QgGCxeQzUM43JzJUQD+yF
MbyGfCm5Ckd4jneTW6YGWwf2AWLOkoQzV8MfDtASbKqZZE8JQfjZXy/oFjlS
C2B6zNdx2RQDFnEc5+bUgFbM/cf/DWN2HJt/fQK7DTB6S9IQjXtGeSj6juSO
EA8/LQPmQdrkYRB2/0GyRBI3BGS/dE0ikmLBIgQSaDQHF+5IxSw8tan+/xdz
NT0JA0H0zq/Y4EUTIaIHTx4kBDD4ccDEeFzott3Udkk/MP1F/gNP3Phjvplp
aSON8WK88ZFMd3fmzRuWmQd+Wex3+4/9LsIXbd0GXsEmtNSaFcbWBHyU29JT
T5G27F6cK1knftPA+otzHgzgo9n+MyVLBmHgiduRtpY6d3xEUbGSyKH539y9
Z5FtYmFKA++IQTldgAWpdlIEARuemBUoxL2ZklHNFRTpxaQWqVUAPRnIu9+i
mBOoyKax5EhaNqBubLVS2g9YPoZDS5Djb2Bd0xE//84lRQ4/h6gqje5OLgNG
G9Y0lbutDsjPSe8qU8/ZOnS+SSy5/lWnVMmHxvfZoQCLjGvfgxhXwBZF8Mym
1gtBNA9YYqljDkycIOopqozgzlxQ4hLNyjNzV1KIECLhcZQQaqwBAs7ZqfFB
YexUeVl5tGuG/oh6VNNtLIIBxMGx8wwLCQmpXl7Qa7ofGg2vqj5EK5KCrWce
Kje+bWTlEZ19e0Qt81JrFB0IboGYDhF7JfY6xv4CvdVJV5Z8RHKK1cKtjIWT
afszQ9d7YKleb1nxPdeXWT1/SRd154p+dZ+T2IFcRUo7qwgD1eEpHdQiJ8JH
VFcwNKHCpriQGKpb1a2A0JhiDZsM5SQc8A+zCicbFPI3o2uqKDslcWhxPilp
8JalI/Egn9XqoFan/Ykpcvo3krltHRZJkAXIALZq9x/2z3pfeTt8ZxZJAQA=

-->

</rfc>
