<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-46" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-46"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="26"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 314?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 318?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 13 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">8</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">8.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">8.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">7.9*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">6.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.6*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">4.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
        <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of EarlyAttestationBleed."</t>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="security-researchers">
          <name>Security Researchers</name>
          <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
            </li>
          </ul>
        </section>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1090?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y92XLjSLIo+K6vgFVZTad0BJLgzuzpqeJOSqJEkdSado0J
AkESIjZh4aLOvjYv8zBm8wNjM/M4dn+i3/plvuN8ybhHACBAkZCQpczTdU5X
iQDCw8PDw5cID3ee548cxVHJZ+6XpmipG67qOMR2REcxdK5u6LYiE4vI3C2x
NlxHtLSpq3Kf6rdNPpvJFvlKtpQROGPK1W+HQ66SEk65yLvsgXe5XLFSCt6V
UoVTTtRlLgfPnDmx8EMbX7sm5xgcWZtEcgAL+rWQSWXghWRoij47/uVInEws
snxrAB7uvxxJokNmhrX5zCn61Dg6kg1JFzUggGyJU4dXdMcS+TlgY8/FBeGn
oqLy+eKR7U40xbYBqrMx4etuc9TiuF85UbUN6FvRZWIS+Jfu/HLK/UJkxTEs
RVTxR7dag/8YFvw1GLV+OdJdbUKsz0cyYPL5SAIciW679mduCsDIEQwldwSA
LSJ+5qqDZvVoZViLmWW45mdu2KyOjhZkA4/kz0ccz1W7nDiDXm380Y0iz4lb
WuBrRqCdh9E5iTyhs/vqSfZoSXQXMP+V4zys7tr4gxHmDpCFieHa+Aofa0BB
/OQPshY1UyUpmDl8LlrS/DM3dxzT/pxOh16mARyAVpy5OwHSau5c1DRR5l1b
1ETeFi1ZtNL75ukXaKaKODpo5gPe2zzFoKcUYy+g9GFeSM0dDTo6El1nblg4
BdApxwFrqYyNful5HXI32CE3pB3+Qr8yrJmoKy+U9p+5EZHmuiKJKnejK0ti
2YqzQaZvWMQGRqItfOYe3UQeS/Dp5+gTwwVs4WGbWJqob7yHMmCUEYRyif4m
bC58kowpSVKMJH84Li8zgCmZ7BnXrSJKc2Kr4pJruBOyWRj7BlU3LHJHxCUJ
d/gLthL/kFkznONf9nRwRkSd74mWQrgzUXp2ibOvgyitLkXNtUIkCf32CVIj
6kxxtQg+T9iVhl2lnlhXf7g6Nk1NyD7UhoY+mxhczd2H0RA4ZDYXFa7tijpX
1WEZTg2YBCqC6CQbqjHbAGlSp9yFI6ei+NXnii5GsJuoLpGNmQ79/zHDZ4co
Vp8TfbZWdK4DPc/24dbdyqVIF6JroRCw3u6jIxoronNIgZ8y+Dlwii5kM4VM
IZ+PR+1c3Ihc05IUwGEvbivFkeYh7nh0LcV/4GOAH70QS4VVHsFjAcBThAH/
w6aQUtJ8HxoNizt3J4oqgvKZa8Thzv/1z3/9j3/9c8FwUnQbl2qKO09x1VTw
cg++jf5cUbmrNRBQDvF5BC3ZSi1cyV38YdDPRNXVdCUFcPay7UZdisAesARU
AGCRvVRCVpgbDnchTuwobc5EU9SjC3lCQcXPS3MpcvUU10txdwp+bYcI0UxF
X72DZwN0LgkaBzhTdgQpshSllJZaMYh/mJbhGHpK27uSz1zbAYo0msNh8/Ky
OeSG1e7lqHn5xuJBuWYaFigXbqDYC2pZuKoj+ihS9uqDQNmhYMsSdSkqC2Vi
g8LXiT22YW4cov+h2fohUvZEsDk0RVVEHcSPpcxgvcjKPmT7nS5/1Wu2qyGE
hiLOvU5k4oAZJROVG1lgwBhRHLuOqEaZzJwrhkZmYsqCTxSNxE93T1kQS5xz
1y4MZ6MTvm6oKkz2Piw7oj2vq4a4AOJK1OYbOsZ0Cpgh9+HDHfkg6qIcFRAa
6+6POYCSENQhvLqgB7mhNLcMabEPl2ave9Gtcn1kF8lQT7H3VKQrh4jaH4SS
3/S+SolA/SOdibglWEHcrtWVQjPhM4Xjm9b7vghZ0dTyOgbiwPTyNoFlj9oN
XsOS8exZsGBHF0M2Cmo3cmeuTjhsfsq6Eq0Zcbb21Gq1SsG6JmhlzaBBSidO
2nQnKhgcOPx0PlPOChWhnB3vYIfIjaO4jSOY4cuxoo99zMaAGTNWfJuI/sOz
BQ9L/SblWUHRN7cp35CIPj/joY1nARwgL28R0/gZNAZ7+TCNPSMSTdZ3GakU
px9IqehgPejRruga+Ixfsgce9epG3Rh6ngEjA6fY3NJVdVhqE5WgF2YR1HDw
jSgt4J0igl8Gw6OOGTHnRINPVdoU/BPbA7+HK6UlQX2VBhwGRAId9rsi/23X
C9nOQbbI9ZCJ6TzAi+bNbYN9KhTz5XLcKJuX3WH1v2ScxF3KKaIrNpgQrmWY
+J80/Z3ewT9uqFFHLNl8SoaNvuF+j9AfOnpcGmg3Zq29ooRNqMPLg+M7QbUD
Xp1PFrA9EDZqlMY9h6tpqoDfborO/Htn3vM2t+QQytyQmM5eamR/ODUkUB6i
JCECzaUCNoBEOLAC55yugKogmulsqFNvaIqDIFAiWU5DdESUKGCocNVeA/z1
W3542f/ThMnGEGbLUeWcUMknWxE7jf8EO4favwPN2Al8C83sn0QzjprtzrDK
U47hq92oivl46RFWNtlcdPXH6huwPS1xqRgqcSw7LSG6aZtILmq1tCgvFdsA
59ZO09Esp7MZry3Xa16bzUqHFdDNFmiwZnYpkt0libe0lJ8vaMLEE4pc1Z2B
bf/x1Mub6xy/esqu+fU6/yepl/sA6n28YPpZhLSKwIZmvsw/Za3V9xGyKc+I
CtzCDzdAH82O0nNANMOJbHsir9mujdRS9q3Q8NATjJt4aNgbHDVOnu0cHvj8
aSbxT1JhyU9XpfnhgfuD47zBHRr0zhpsE1xKONWmAeY9dMvJhv4XBxw+h0gO
J6oq8JA4I0CJCXi/jouU+TlD17LPM35lrZf8vFwp//mh7yyg5lpBd37G9Yg9
5+pVFKp0gUiWAcDAAVSmwArcBPxJGbf7gDSAKDSoe6hzJgFxYoHWBdmyCdME
lQLBnfofQBZrLS15M2eCRM5JuT9PlnyULJeGTBAAOPYq4K/ifqxNl/7cgCEj
fqICTCPjn1Nl5lpssawMS5VhuhSHSuZPmWKxeHyKDGSskGiqgbvVpqUsFZUA
PxEbftOmP4twuVJR4+e50gqkyfI5EeHw6IT39Q649M6GZ6JxV4bQjTxP/Sj6
K6MxfMCE2qmOJMQ9IgVoU8WzGEVCme71HBGuAnhreoxHifsOaAMoYBAqxJlS
qxAfpDV7BlQRnfQ6R67Xrafr1tmFRERSVPPjy9m9rtmNh/S7fUtKyz7Mowhk
5y1Y++qOKPVfcoMqj0pImiMv6TDpGjKXrMicbsDCAnUdkbfEV0kgaZHhsK2n
3sOUyCXkEh+dNMP1MIM8FZ+XfD4HstbKe3beXoL4AF8RY2YcIETbwOlefP53
o8jMOEyN0tN0xRdylsab8/n3UIMYyyg5YCQqSBMezJmlYjmuqO4hiEQsB+w0
PGq1uRWxCKMMCuEfRYXXeB2milmYmvyskp/Bv7TKd1FFO0gVTdGVfzuSIFIx
hlnlWQMz9wnM3KxU/A56WI4UpQcITFilvKQqeDS9hxyBIc8sWbBdnl0DSfPD
qRJF7TBRCs+WxC/LpTyvrZfr7yMKL4sHhMmf2pdpsJMhQ/fVVJgwxR9NGBNd
ocIKxOx0Xojxh2IJ40juj6DM6Ko+urr5LyHLbFZ+5rXpfA72kyW9nyy+a5jf
5xr+ODbJFhISJNmOQ0ErA4+sYQU9zcw/5zMXDvjMP4hRfixhZvPVkl9aZpbP
VkqFxITpNvi6pdgKnihfdVNCJiUI+UI6VypVsplyKlcqF3I01iP4cN9JCTVW
8fSDfoE2bsSGrRua6aJX9Zlr4TkXWLW6qG7wU2N68KzkEhwon2aFN89L6vU6
HzKk0zRmQOVtk0i8IvMSxezd5mz0Tc8AG1GcitEXoxR4uRY+tMgUcA9RMFNJ
D/upbEYopeh0w1t+UI0SDXhCpMe/E9cBBprRo2iMIXPIDL0n8I6sPbsPOvLa
/kOlA0TC/WDXJrqypsY/OmhgLYD9mBYdKVtIm3iq5/F1ekUUfW6o8mFK1UUL
Zkvn7sJfvoOOXUN3/7//i+spoLLBz4i+fIDxg7/dgH+ZsP5I9G1HxNNtbmRL
c2MKA5ntNBYtoMxwTqYwsJ05mhuaaAPX2TaMbwdVBawHonIDQ3FebBrFUYcF
RWr9VnSmet3RoPkXm7skKzx+18iKWu1DuiRhmtCowFbchbgBdn0wXAvFSYMe
9dvcVcTMqLxHGEiq4cr+kgcLR8Ezfzp7E9WYpbFdGngM/l9THIvwNq+TFT/1
ceNtDzUeUOPJxJzyKqLGbwA1XlR4FoVg84YeM8+IgzdIWNpVDwv4iNKDx/0O
RXdhaYTXXZRyAbV8v9ZrwXn7aqGGO1uGwUHpQZamI6c0gbHbPOCszOagT8NH
0luKSFts2ariI1GLB8WCN/X7xRmbcJBcYQ8+Gq7IsRjJ0Ac1lRB5Z9Np7yfA
vBYhKFMdjOnbnjHfhrYccAPKj3r9z//9/+Uqqcxh8RvRSsIOI37vqT+oi2xF
qFTGe0cxpoMYvxrEeGcQY2M6xkGMKxmMBAjjPw7w/x7xHQTaHR0dKX4kmRdm
wTdSUyYZeNwJ4QmOIMwY7/uKz+R3P0QDL/JF8c0vKm99IWT8L4CALwyXqSiB
N3SUSqWOjnie58SJTc+Gjo5GIJRo0CknKpqNFoppGbhxwDlBlKhMHFFRKQP9
/e/RA/N//OMUnu0cLbOH0fPV3Q/pod2eD7P7PoSHNGSHcgUg1FacjjsJCZ3A
2OE+obVjH3OrOYjtYCx0/1lkbL4dV7BBAgObGyuO7IYpc1M6blgoJlJLkcgp
NAKldnKCBx8GaGRzDvYJAkN/0rZPTnz3USa2gmteE6W5ohO0DiyCe72nnK1g
p1tRs3tuMKP76irgYpFnl0IBKnk6B0jx97/HiVYk4OuRiDKomJMTFzQk4ila
G0AAbdU1EPDkJMUhI8AKBqPSxhBwbgL2KXQ82dDR+Gsb+t4X78ImjZkv3gTu
W+XeNCJAEXclkCsPQKTmI3wPtEcIhDemVEtBO47ZbADKMw4dA4Oo+pZxi879
KQdOPAirqolhw3wWJB1IIaLbhGoXgGsZsispbCv2FI9J4WXwExG0gDPIiv09
F5dADELw7GuhGysV941DdFHJEhgLkVwQtHPA80lxddcC08lRAR6aa4RS9OTE
WRnBDYPt5QRDJzQeKHIrAR8iK+NTENY8Xj6IPvW+LZ/SZaHT53boRZ7h/6pJ
MZXjqGS25zAOcSbifj0dzMQyRKTca+6hhxT0dFRVOWoj0J6oRQM+At1w9u5M
0Mk1TV/wh1iLMZApmrQ1PRG0GWUkn1wcUeg1DDaD26sPeKw4IYgAWKFgDwPi
OJfbD1gnW6ZiyAF4rzsM0QQIHDAYNqbHlogprAHN1VGGfBDTpLiaaBMkO4f2
HRoV9BwDWtCTU2SBqI9IkX1N8hDfsX15+ZSiDcJ6pdNzVg0mhe5WmYbt7L98
kQJnleIRrJXY1Xbq8bQGPEEt1vciCypl9+Bje9CFxOmBCvkL9Z7hU9ZByDFO
gZdAj8I06EjmwAuxqCqSYLIwrhL4YimqLnpBgKACE8/68LSZpsiySo6OfqWu
Oc4TtdYA5lSx8KSNeS6MXdegNFCzA/NoGopBGNB2OdBFlKZr1F8Ze2Qpk2H4
B4cLA+fdXw4Bn+PM49GX6HAq8TYVDRu36222mgii/+uvXDPAaLjFyBMg3BC6
dG2mptnZ2ISooKq8IbGzNW/5UEHp2nsGRDF+Y1B0SdBTOUuDdoCkhRgOfWsS
eGfic/aXy+5whN3h2SaoOOJYimT/t0++Nagv5ZSu2E5qZizTOM2890laWtr2
MTAyFYr0QpXinQ+CVY4HpsDLNj0wjxyYMXRSIEJbwPi4zwKMwbzTU64Dg3Em
qF+4FThxvgxFyTOko0CKCDlYL9DnLmWg+w1Bxxqlw3b4SDBfZoDqhCd4v8di
gQyIMmXbo6NvrLtvXECnb9wlvWaFnfZ3Otv/jk7Mt6NvwMqR/wFwX/JDS980
hj8F+B/PsfdC9FWW/Q9egWaAvzHq1HvMe49L28dC6HEh+ljwHue3j8vB16hC
vsGalhVXC0H/+2fmqvztl+jg0mz0KEh3400+iQuRMeNxmBt/+QddGvtE1dEh
C2S7JkTfgkJFBDoNViPMLxWBL1SCvBcNtB+BIUXVPgWGmwGvUwkHswcMTBUV
/GtDVRguHy/KBXjVpDYlHvzi0YOFnAOD1w0nxbUsQwMMfa+dQ/WEtwxBADD9
7gkSDCiQiaTYzA6VHMOy/cUiAeKKTDeFvKglDYxaEZacBjxvaHue22Es92NI
rQUcFfuWYhvVqvhYXOJRMa5QABRvu/1plTp1LUplX6gygRlsMR5VuRNmxFL9
ZG1OmLpHtPxvwnxBZ97fg5SCPUh4z9Pu9gdDeYoUKbFreML/75Ijsv35ETSI
PPI0xj7b+uiwzR1aGK9NZ7ahyMQ/8LjFTrw4BBLYeL5hGDldDuw+xNLXaqjp
6HaE9Go7YrmzHQH0eo9t8Rl0/N5daQSAoXkYSOZ5LsjxdBp2fc+wwR0DLhyb
Fgsy+wrkYfMHOcwPj9qBuT/IKgKbyX+0bfp7jBQUub+CKOElC2/+2tw/UCXh
e3zNBdqphdeErVdaBr71kPDPPKBvX3XsvU56yr2+jcn49PUlSo7B390w4Hxt
81EdvNp9+PAe9s6T10/+UD/cHvJmaSOmtfc3ojeT/L2ofSBy3w9iH6dFbAwY
+wJ3XV1581cudLMcViT4u1uY1KJ/a8w7UT5vket7pyUUP/PDuyDG8if0of3w
PixH+hl98LKYZJHsntPTtp6pGdP2laxPvjpeyfbkIF7tbP5pGN+DxxcWq5jN
Lvn1avrEF3OStnXL/lSsThToMUWtfIKej4/BKRe9Fn4aIydC2GoVs8Ln5muT
zz8Vnz4I2yhQhq3wEdiappTnp7NCkV/nKqUPwjYKFLEtp7IfgW3xKV/iYbqA
s6VZ8YOwjQJl2H4IbfOlQoG35kWJL1byH8UJUaAfiG1xWn7my2VtyUvlpfVR
tI0APabCs/IR2D4/P+f4ogQzVyznlx+EbRQow7bwEdiu11aRX2ULWT4/m60/
CNso0A/EdqpZa3769Lzic6WZ+UHYRoEeU1X4MdhWiiv+6Wla5tfmKvfDsC2k
ih+C7TMAzq0knLR85aOwjQBFbPOp/IfoMmtm8bm8JPFTaVb+KF0WAcqw/RDt
sHqeVvinqabx02L5o2RCFOiHYHvAfcl5xmWJbr9OwNdWRJ0726iivlDiGuZD
Xu4uKiEs34dVEEb5Pf5g4R027nZXNXQ4kWAvle2keRsAMNBPluHO5vgRZqig
WXLo5rFhyWxn2tsix10Knmc7COw0gNPAP/RPz07obqBpEVUBhhCtDd2z3b9l
i5tWV95BydE7NnCd7V4b7o2y8HV/KGIoJvCNzVBGJ/+xosft8LEDRe9Iw0vV
QZ9Fwjv9bBz2Z9xouTRSMHG13W7h2Q2elECH37hqsHuK8y9ggzoN6f3P//X/
tClM3cBwALqFzn2Z0IkS9i7G9+d6SDsWIXipR097AI9p99md7sPj34NG9qPR
yDI0cogGSwpH1ngTChgv0vF+tfQnOs6xjvMpKiss4EU6fhahRPfaI/3nP7r/
POu/QOlvaPCQER14+NcsZetfc1EUCh+NQuHYO7s5jALKri8HdzL3IrQbT6sR
gvubNkYgTlj3Gp6cKaJqp9n+Em4vpfwbd7xIg9xBuYV32015evxX7kuwN7vM
pMAj2iKA4Wa2bvOKg5tLxRlFZWXS8D3g7bRrqoYo2xgBWUgL2fQdweFafBWP
0vFuKgY9jrAtX7+6bHUbzctRt3pRbHs9Q9f1eiRcb9htv2f8x3+BRSUb9GIJ
yIonvAb7JUbq7IW5Q420L4FoqJdpSEia7YG6a8r0Di5Kyi04UUlp8AmFR+FI
PEhXw7UkksZ7lBhSAwhiLBANAPWDovgVEogeoxxvmXG/6/gnmLF47J0v7mPG
U1gMp1uOBH0RGzJHdaiH6H6P/E8git54SAW/kvX26atTDETcD0baHp6hevzv
//2/Y1SCH5UWHMfAAxg4/L+iB+eC8AvDRmg4zcRYhvTc0R49R9se1m2u7QUg
H70KpsLgqRC6uuwdeiJ6muIos60mxPahg54A1Z2TnRR35aIqhWWOQTEEVj6L
g1AcsCA2R/SmFdme9OPZLCxLgjEZDlgks3D8EA+DmoL+5z6p8IHK5Y6D4bNB
xQ1bVA2MvBvhiT1ezp5g/AeIBuBw+YgdwIWu5PthCZjmgD4BraQBSDw3Y7dw
/PQH4vZy5dGUnefKypQGJDjbgL8hC4bymkL/3sBt1yIBQUBi6SAk7COgAh7g
+GGDNlVSKcoyR0c0PMY2MavsBJQmToJq2ISF0kUjJd6wcjD4k152Y/bJ6+Mf
xbZdeAffecFcS6LLhkWpgyGV7AiLtd53uhOKYmOnlT1DBhsRZuqKHjT6K6gX
MC+LbomeMj+7MEfcFMMTkUWmNNxJjhqCOCiEBD1uqR839j3rZrLhbFy/GzwF
12f4FrkKuvwKMsIRv3J4+wIkqR/7QTzziW2+0kniPDmKnN+iEYDcF3E2w4AB
h3ycPApAHvv36G0qIby4Bjm8duV9Yz14Xg+zRnOhqKitMHMMC8RiY3R171fK
m8ApC3L0kaAxC76VvicegfIAvQJPDb6wsgxHH0eF/P4AasqddPGxM3GmL3BO
UKKKuDJCl60+sRgeL2LueG8/r2OnoY8gOBBG6uUfwEA4GrNGuQQkgrfqffm9
jeEAvwBs/BrVHdwclhoN4fN09BHY31cm9oSNDkbtIc8528Ys/oiJq8h1BEo+
P/iLqStvkt9DStnwbr2aKKQBQjSDkGh7oasKfsWdnHihkyD1LeKcnPjLgfVL
Aw0BUYXi70mOV+EShxkQg1hJKISYeV7WzNWoQ7iab7hI/xSrIJKZRq3vGQQw
X/8NKoNC2t/2lF24wjA/HMvJiT86GFE4cvot1QuIuvoTJv+cKkTG5UAvbID0
p4KRRfaxB3idX8UGqKQwTwYVskMipcBqF1j4/YH1y6QRfJj3PtvGv0CXNbIx
UDggLVhoFEVNJeICs7NAi69oEzbPv+Kq9jOXx04XDXQCwQiTjpc9aTy5aPpK
CKmKOUkJWyjYCJO9+jlQ0N8K4QFTTTBw09ww0whXNnyW4vqq6CAThTmXpq9i
8XmGtUAzn1r9FqxVz0enH2CYJC5cA5UlqAmQbPA8PHrZwBWN2c+xf5YF/JQm
ZQxlKcJh3tab5zgrQBUMw6VH4fAKIwVXqKvoEEHnm7yrK88u8ViUISlyo3qN
8+7DUh2qkuAeA8s5b3qj3LazAomKYh08sOHgsu3jTuS/Igq+A3W6nTvsDwnw
qVk/bnSanGfncxg7SxhYZ2Oila8G9GfjsY2pQ8fihcdSu8qmt0DmXlikf0vo
tre1JrmZizGbV0OcQsnamI4xs0QT7AReVSYWMoUFSAF58AIGdSdBRbKgLozG
PA3o/HXQ7F8NRuNGdVT9ynInoQ24DbRnPbEoLclPiSuze46UF5UZrpcwo7Ak
K5x/U4PFj+O9SQsWvPN6Iv9KmZ/ADLLIfSCbIm9TXdH0Vy4KBIdmU4Cp9bUd
JXDQEcMhuPEX4myiizRiNcSF1HaAZUFoSDdZSypQd8msYy8Uy9/nMixmA8os
Dp7NLTA1i037etE8/8Q44fhreC3agJQqM2E+xRBYrBwAaKEQE8HNNzF0SGLB
xSwmjVDS7ixSSXRtRjOZTDGaCQSmN7ZTsHENpD42p+uQx9sjXGNQa7PbG6fY
iCnILa/B1z7pWTy7iFFSeB8mKgW+eDZmgS9m4f+iuwCiJrNsPnra92/tNIuq
c/hgk3riAlYOGlGazNsTvpQpFGhC/WPfGaNGvqHjAiSYvslFWxSmxWJXIkGE
gdXLJPRnDjwSVhcCRcUjaIiCbwMa1DBCegMg10Jb3HanHr3UYDl4K5JJDmJR
O+rroDFsNhtfqdq0PUlBmd2CztQNZXGRWtK2Sy8beZ5NoMiR8+nWLVVQABsF
sMc9gCk/7POU/VGFUZFCs7VNMRrVt9+CrYbXd9mZQpSJBovEsWg6EebEyODh
8WxgOu4bAVO5msl8YVw0NCEuC1v3bDW6hcrukfx1yw9+uBGNlIMhzlH0XcGz
4fDiLzb3ledxhdGeYGaJ/DdLlkz3K/fpi/cRlwOfI8N1L4ej6sVFSpP3Gt8G
fGzbavBfulHl/eAphPQWwvGx7/fgSGAFbKcJaAd/D6qX8DeV0X2kKCIGs2a6
IJgVFRYzJRWQOHB30UQXZ74JAqYm5QIwbmQmgT15QWcKmJDQmxC+rvMVXGhl
Mgv7wljxF9RD7oH37LlFSG62i+cZG0ctzLlFuGysMRFaEqNmkxdnOhgOwBz+
zPHUFT/yLxHS8FiMyxc5mGP2kmMXqHasaCpjNNG0vW0N7xIicivID7rzb9Cg
WP+mOYiLbQ5GFP5h3byz70Kj8WF8KRgdYS/YDU/uWwjIO//5FunpfU2ge37P
P9z+x3H/fFcT6P7kpO9fR+yxXYgTPHmDcfNUIag+OQOT49DovZEHzZAasY1Y
9/V6YLNBzx6sev+G69xx/0HpD3zoArz/2MlWMEVTxnKpyA03YWIrjZPwiRkQ
x1vD6z+4QQ/eNW/9PRewNxge165BFTDNisYwQTJw182Y6YaOuDS1CMK4fbrt
hbrcP+qofeSPPASdbjVzDWpxcp9GjeM3mQlz+js0RB/w2TXA4ptSnC6JQy/U
2+jM+BTwYQZm239QeeLbap7JB3Q6jE58U0SWfbGDTmfYS4/6EdJ8Y/d3yc5i
3UuM939Ke6MWcfX8a6i7b5HdfJSgMBjkCI9Tmux8e6dfNP3Tt2BZUeXruy5v
Et+3yCP933kiPI0+LqXWNi3vXqjf02Tb/cUo3P83UBB0mx+WL7bESyBvkPR7
moR2ynfUkC/svat7nq/7WtyDBNmR67hxPvIuxPhHSWjUrnR/CyKAzYAy189m
vl+wLxgBekT3D+mi9NxA/4JHVFdFjMOw+R1VdOwimK/F0uGp+cYNXN1Oqwom
wqT7y7/v5RtutDFfiZf9Xw4CU4v2xIzeg+rnvcrk/Trn0JcUBRQKzTp6n1Gk
u0xA6GGx9GpklzFvIx9eDdO+5PHsLsZ+37bO8P7+4yXpN65NhVdgkn4XCtVz
/5uIGto2bXnaxA+qSQeaFedzrsD6tqQ5HkkHGyCBge530gM73NrwAAHdbl+m
feNCGtjvruOZlulAi4F/I+Il9t0xBS1hOOnzRovbkjXin29b1C3i7yEw0g19
0n3jaOZn30WO+QfjKMK3DQIT2Mt+QGVNWLRcBItvJ9sWrur9uzwoRPrgzMGU
a3sph9t0Nrun673Z5ZW/YErSHiz1o1+5Bs2IgeUJI2cvDXYugzJypGh46kHY
aSALM6huEwiwbU2gWtV3JW/ZMQtKkibdjaQEJOErO/AKT9YUXaEobU+EiH8i
RE+WDO/IBiBkStyVBJ4Ies+MN6MoIAbBx0IexiWFPg5X1PK2Wb5g+cGtWxWf
NhamwE4XZ5Pndeb+oXz3YHVyvXV+eVXWs7x7PntI4wkzS01Ley2y2DSPWnhe
5uoSxTPk85NJyu8RO4PfNM9RJpstCUVw6/PpSEKr7U2vlGWztEgOIewkHbdQ
pA1gEaZCtsS1yCSETxCEsL06/PrUjPtychJcAf4b1+m2O1gDhmVoOD45+W8I
2cuzH4Z929x3hrbtKQ5uwYdbfAWX1jEIgcGbBXtvSn0n/C9bPopOT0zmXEyV
IdrETjvijIUg4F0PGtkh0CkIMjHSow7aaB9x3oFxheaF+l58Z8ZhXAspgZ8Z
QipbhM5eIT0zvhNhIfMK4/orS+j7YkXwErFKT06+xBSMeFdszy7stOmqarpA
Q1KF0u4Ibre97RkM3Z39zhH5CTGQN7Mx3SY68aOnhDijLHEUXtbHFbsD/VVw
1CuhsOeaYAwD5P019opl3xY72dfrtz7ojrr16oUHvwIry2Mwv7pCoh5yf7KH
5NTKviLXqw7ZbUWfbvnXvQZL8lVvr68kvmNqQgl/k3VCLyT+yA7YdcQf24P2
g3tgVxH/fA+BTHid2QS8RE+boC32jqw5GLP+Z3qbGR/XUyzl2AXLdxCv+Gc6
YVcxo730mo3uTc/rp5jKxfazY+X49zS3vb5XxJTfCz77geDftKX8C58/oZt3
iMc3utkz5z/10qhQeYVWPF4/6XroHrxi0fpJ90CTovWTLnwmResn3exMTK2f
c4UzKVo/6a5mUrR+0qXMpGj9pNuXidH6OdcsE6P1c+5TJkXrJ12cTIrWT7oh
eQCt5O4TuxKZ3W9TJgeXjwP3tvuYf2ODKXB+C9/ZQeF1B72rRnNQHTVfmaZ7
O9nuKQc7utFo+vC+anhHV9zZysX9ZTx0VfyscF7GP51dm2A5/mhKT1HfbCNd
NtxqLjq2gfh7KVHDEZiRuFAalvz1jogLrGX+9ZT93eh8pcFTX2ui3GT7K19T
Jyd4mrXhMB9tZGedHsYZNsY5pkjq1IM5pLcuKFQ6OO8BgGZjVVVwaQzZP/ez
/TRyIjfD5OU0prV54xVPPWpiBVQi6tyNDh7OX2zuC32xXTx7q6XODY2Y4owc
07jnaO6h8Py/3sKkY/D309hlkmBuWLLGyJSyDXw8rMMAVT/xJQtt382YfjBD
OnehOHjCAHyxTcG1hIXjXZQFbohJnJk0XyY9XoyeNDCvJ8jv9cXv7d0wDySc
/LJSLFgJJg0FCu26h56mp7BO7OARXphjRziI0acvNMAkGqOHoUwq29vz7ufB
07SLIjOQkrxEMOApHd71T9OGQRQfH37HAgKFDJ8t85mM4AXzIbt+qfYaHxEj
mMvkMwHYbcdIOnpP8xIvPlCajZrNHXo5hIRpRa/T7VBqF0ijMTBC1oss48qg
m7O4POjP/0paF/lMmReEH0fr8jtp3biXjVVoL1xWU6Kk0bMg2VDSQWWaYqFc
zOdTuWIlk81l6F3Gn0iuPLJmJsyaePm6QIMqVmwkQ0dUiRuSAmtJ5P2LC56B
oRh4eRM/8/87ZiVaskWfGbbRsYV8IVOJDi+uvrfXgGVooNnfvHyuiFwNFM+i
VR2O3kJvgh9OsXRm8NfYEBcqcMc+HItCpZRNgiM2OKY5JHYxFOVBtbcFNRFl
S9RwrXh/Yd/fPpBDBS9iGG9x534iuYSk5BIoipUdFFviBKT/gshvoTj1P9z+
Fc90QuYdGMLDUIO9GO6LRo1Cjq8wkilnhYpQzo53ACGccfRUbowpjbdFRuAl
VhPxK0yNRxfDYy42dyVLicyyth3Iuhqbm26bsjkZjOz3wXhf+scQwK1hvGsp
sTsre5K5RsIlpMBSUgNLyQ/kkrYQg+AwvOC8NeRYJYGTE8QLbFl6QWfPRrvs
VbX079IqLAxeo73RtN6sKxLUdLQwRCW4T7EXXxp7xG6f463hoDJBKDXziuCt
YAeGprNKvZE6CNQcxmIf1Og/OvLuu7y6DYd2rrpFbRt6ZhqOb28mTfXyaYsv
SzzMihIEKXqZK3P8+a3E5ftSkh8dTkf+aZs4nd4PWRLVwDuR7JJ/hSXaieQv
P8I0bNFM5Ec7OcvfAhtJWV7gXqUrr3CfClwshJ005qUI3zfXJgvMSTwJMZTn
vDXg1b0IZc/ByxuKRtkZ6M/ciFPKzlMF72uItnfDycuEP/ITj0Mz8M/CfVIG
DB2Dd6PxlEdHVTt8jSP2oh/F/42aEbTCgejVENmy8S65XqVJsEjoui5N87zN
avGxiSw+7xPlbGSv/cm3wjUQz2Q5UvZVGqc4fW/AwNFRd8ptDJclZGeXqaZ0
Z4FJ59j7qDuXekwa6cJhKmzX5tBz5myDidQVu/QmzYm08EqcvM5B8CoFgcJu
rMBj7/J31TssTfdYOgnguFcsOUrEOrSMcSiaRYzU6Tk58Y9n8XZuqE7KyQme
xJ6c7KcM48B/67wvn39KMA9SM0xDShZ/L+5//turZDzxJUm3jJ4kXO70I1fs
X2E4mjKjwo4V6Io5kWfFuWCMoOxw5MHesBdDAAQIB4RlU5n4bWHWbEuF5DEo
p1GOZullPKT8YcUPio5DsViTmbE7hhyodT+o7a3QuD0DeVecywcMIqrV+v41
wmE4Q5x9VN2vjYJbh5GEcmwrM1ZenuAdvZMdbYWYvp9BqWR5I4tRBT7j7I02
wVIB+xIC/fU9gWysLh0NZUMiTx0SbD+/QuFQYogQGjieT1SF8njp0iQ6T7cy
jz17WfRTWezJX/TJsJQZmi6oK9B4RhOKz+TZljK93G2zq8hASz5TPD7CWoxY
q4hVJblr0wQNiqSYWF/NNHDHReYMvFjp6SzMYsM01QT0XhKJ4ecuEakNz2Zz
V0ZRwNtMK6EvaTaTyKYyz+6av2pFDwJy9MonsZAo0jQFAOh2sWFZsHREFAHH
rBndrGZBi8GdXpwqe7pJUerQ0i5Rwtj+ZWBWJ8uvKLI3NRBe9MdCiIrjBtfT
LayG6l1gxzwQXtYbv5TN3K+1hq4LO4eIr/kSLXhFOY/hXqXX/BggC6aPXu5m
BW3EbfYSNuiTE1lhl56Bi/20CyzlCtg4B1KR+LRj3Z2c3BwodYidKI5N1Gm4
DA/e/SaWHqySndqZb61O2icqPmrBh6dciRZgox/ur8IYjxhIPz91Er3na2Oe
mUZnJy3Kp6+z9ebrMbvLAA5m9O2EOCu0kKRtCiOWZwoT03QC8een3MJ7EZ++
zh1b8iFST3x7cQLrZgatNBzQjNhHuRRX3Sbw2oEmxkILJf7C+rPi0VGfLXXM
DuMlQom/u4wwvXql1A8KaoT22YTQGqF1vMulsm7auASPt6c4wbLk/oFpt/zT
OHqxycv3JOJNkNHQr0hu+VfEkZlZfo3D+yEpmh8ojACMJsgxgadXOKlDNm1D
b1LbwjHOUEyrUE7P7TyOPMqfI+Xb2WOcmffBCM9fFErueN+c5BLNSQ9F74DV
GkXVWA1nsdpXucqrGRq9greneFBsLrhXCnwnVRC/m5F0TlTTDlLTsQtHgo8f
fo+XcYKEW9vsr/vaZcPtuiztUEwePC/X3VvJ3Gh+u23ekW2ColAKBnp42Pel
Uew/37ZJ2bhfhdPsaf60GH2YOy2c4q5N//WocUPlM8/H9xDpzPva/yP4LwBq
C9znOFalUg5a/Of/8394wP7z//7fon8glOwbUBbSfAcK+ysKJfcmlK/cASje
H5FrsRiOzHifXkrbWUullED53UvUUHjvwqLSM8h6RctKevtXwUKLz1gcylO8
besXBN5/WByXzPiHJTJOH/9Q6KoxSzlr5/3pkn9YquTwQH8A9MhA9ydk/mHJ
mMND+wHQI0OLTfn8w9I9h0f4A6BHRvhWUukfllA6PMgfAD0yyDfTVv+oRMXh
Qf4A6JFBvisd8g/LdBwe6Q+AHhlpORW2IqBbv9Lqx/XrQ2TD+oHwQwPbc3wU
0vW/0n3vYOsJJrfFFLHN6poeeEnVPN679jdGwIS8o4Wgqa0Ys5dJ7cPTIJfW
F+of89ENoLUphk4t0OnCXBoLYm0vdMuGlD7UNH18yjLj7ViuIXM3Uv7ddmcz
WlqUuv3g5KMjOt9MLMVPXouu1ycpughijWA/s+Xe18fvTYfqHXTtc/1ZOksZ
d8X3e+5vZwEN2+iY4FrfbD38CdHJVIkeVv9XTyqtyO5VAY6eMJ2cbEsXe14F
7qnjbL6axjBj0C/eGpafJdtrhNyze1g52dD9lNAepXeezrJS+pnMT6O55nZ2
fT+AJ14VsacudGQDkhKRBf3iPifNACkzQrwHAT6Tj+DwJrre/hPbufMnCX4Y
FtGCOIXozi3d0ku9U/xcVM+bTPwMFQ0TP+CQYOSYf16C7uiX+0nOfVFhwnlL
fDdX4iPea5Q+fi+K6IJQDN/ebudCkcGHdvTxnF3UF3RvlXGUfzucTuv23vjb
e/PIywNgZGfneIHFUp9Q4KETTxtzxm44GdNNW4Zrn3oHU4Amsn8Q4XzqBb6E
wlPmymxOs9hgpIAcip7+nqAd7hNLzLwT4fyPfxyznH8WoQmWMKvpyUkHuNKZ
YNwRiIQVCKeTE4zSwHOgk5MUq3/QVpZeSmXEkxXefrNY9CmeRYOyoJnI5SNv
t5yEIjrYjVtYkbjxjr/fEMi9m+HoyLVmLFgGj4jjxa6Xif8tJqSZfrL03+xM
23+5ravkhZSk2QUBFupEg2o+eYmw/IiMUF1nPCLAlFdeqFPMuFDk4nt6CMCy
luEaBCUbSARLsRcetl1OnHkJtgluS9CMu66J4tgOb0KH07lXd3rzq1n4FREw
msulNRIobOp0BVEZfjpYTCVKNVjQyktT622KkWeXSnt6PDfDghO6H7/vpZoE
ZDf0YA9YDtZm5Bsmb9kVAlwaOLzgYsYWK78W/Km3qmlLtCaIpSk0967ti3lR
ZdE3QW54PI3SZZaBmHhZME+DfoJACYYOjR7CxM7SNivqhM6bpQAliMzMe7+1
RkQ8HAGpw6BjOiCWMoPmMgp2DL2cZT6LRU5B4GN63CJ5mtfPgo1wJjQpMEtz
hu+IvyL9vVf/nCBS7z2YXm83NqCAn6fYz/Wa4obBkVT0aH03E/EEzxpYAimR
iTCaOZVldfZmlIoWkEVs+kTKmduUulu06Ejgtc/TAbVYaBSZ+vmHvWzhLBN7
wJfs/g8zxEeGoeLeP6Z7fVUvJTA8gsURWCC0lMoX3wLZajqFEFp2xMIkSYT4
io7mtk9XyqBrCrljv8LKjt7cFjhgdceiNTX8wJnQ8Rwgzc4dv0yVNQp9lnqc
Vcnwf/hJ/uP3l98VR8I6pwnKeEUGgYVZ50NuEqYuFNOAyzE7wTPopjlMGyZ6
ptneWKUBpLTlsPhHwAml4hRoRJdvtDLBG5vi/jJA2ClKH8uzdkhw3LgKHexg
VRpkRiAcMixWwph7qYpZ5YXgcJSCpeyDqzaUFQv1kqt7R6zb7Oj/fjPgkRoP
8fEqW3RhbWWCl9r/NbZ0BiPVBU4DeRCqDERvp7y2po6xqgw7KmM87XFBsICk
QAWgUMOvTSpaWcb6ndTTkenBiQYAml9rRpobikS88j3oW6lgmoSkXSDH94wR
J+2UWSeBPRLlwBXFk0Veegoifh5h1V6C5fc5MJz9dGr/dhyyf41S+4vJFx3s
2f7wnAWCbC3W1FHrFW98Pjr6X6i2DqYFzXMhlTuNLMAARuiiXEMBCU/4DlFV
DVgT+YrzLldOMf8dqj2ionKH56qqmJifGuTxEm3FIKUo0yteOQQvWzpexyM0
mT0igY6tq0ccXLZBjMHmS8xuh77Bjki2dnNZsbOXbZVIyl17iITS+47ldXc8
JgIVqCvMrmf03dOMeR6vpVhwJuodTJnbI26svqUwQzIQhpxs0LXl72AoapBi
EfAJWDRajCmYJVZqkyWUt71z8G01BEoFHZ0kILgfXhB9jU6KX/sG0PJYIYW3
2SRVVDQWEayJsm9BslhW6qHMXCtI8g3qb3uWfxQ61o8NY7aIt1+DwcR+yZid
pqGaKewwrvyqmAqnMVvMprwNNgLRzLloKy/hQKTQGqZBs5GyOrTwAVibM3ZQ
S4Wny+QZVhnCibIj6OqILxv31lyJ3gYd0Oijo+3raNyPVwgDaycFLM32IPYS
K4UH1PgxLXbmxWmEbtpg2+bwatCtD+k9aorbr7uXZ4+C48z4VPOhkq9bL8E/
1KQLKUjvy2iIASUSCcq/7hafY8j0gsp1Ph5vpbyPxWNrhXnH3gF4P8TZWy9H
1UgZs3fQ2w+cYmZq1RQlMDSz4A5egFjQbcIiJsALFLk6ikEwboNgFZ2stneN
0YHfTIDxtnYpns9jQ8B7yox00cuChYkwZ8Tfx/D19oFQbjQ+MaA5aupQTcF2
LSwNKfTqio53EL3vXhJWAT5wYQkjQj61wQUT9WPuSz0yJDrgT9FbVcdbFRgZ
P6VOSiZp7+qZ9zlP0z4TmfdK3YA6I/pSsQyd3jjlM3yZz6aPkyGRTYZElqeh
0byohLurYwp7mxzjbW6vK0EIHR7Sy4s6OMY6PKZ63guotdOlfLayA+P8HIy4
jR24KaGkrWZqRZS1oqeen9m1inROaKvrZ6toTDsbdbSxnEvbFa93sRKnBDgR
bOOhb3vsATVoOs1hX5/dE21oGZn5U/dxs17tgGooYK0Aw94ZFujAUJ7ZWCzL
xby86t63Ct2HTP65pMzybm0128USpClR8EIGnruA0fGdIL+0wDzSQSVv20+9
J/TqoazgOUa6IJTZ16poz0H6h4LvJSyFQ33O1NR/S5s6abpUQiuF7pnxLNKW
XeJJFzOFPB3amWiK3tgGaDr/T9wd1nWhonFoSMwcpvHUYAYYUXaxoAG/gs9h
uKknk3Ihbgvsrgl2m9mR1781c7+Vhd+qzd+a5d/K+d/Kxd+ahd9q9d9qwm/N
4m/lzG/Vkv9Njf6R/a1c9v+oen/U/FfVBv0j91u14P9R9f5AyOybHHZRbf1W
g05L2KTiv6pkEY1q/bdKzeu0EvRVo4uGln6h7sZBoSCaZgrLu+C1VIWOPL3z
7WE42QRwsgin3h3UsVjNl2jOCUmxJDWlujFo7m9AH+/BN1k/2e/ph46nDY+w
G3mSmuHASdwQth8xcFEmexe47HvBAXb+JSi2FQ8yzsEtK50arxIWs/JsX1Yr
Do1tVVlQS3vi+464ExWEk4MBIOMdKJHrD1Bff/nek2I+enP5u5ofo5uBpS4x
xfbWXbXdCb1b9AuzCCTPIqAxafvUaeoXtme9x/BAFbzfGqIXodANGJCZggGu
UaFC9+/YCyZF/TvzODnpTCmdyafD5wp8cK5gM+XLB9vJvGLzE8tYEJ3ur4EH
ymsiKE0DDyIVFK/ZIgjC4q4grKlgCHZE5xK068hYbEJib4KvwBSnitfBd1s1
KQiVilCgwHyTSRX1mYthywC1Qw+jdCOshubBM6Zxw7emVqLNY506NAl5x+An
hI5CxbLmbKDgx+gwwxtecWCoOp61Uk8cnJC5IUPrubHi4X9UBGHQLR7ny1Lk
IqH3wE5hcDRhFwpn/tOECKUVWShWygWhVMznflf+JmQymVKpWMzmsmVK5C/h
nO+BGYJkDqlR4pfQs1i+9zAK0WsRwZKlO0BMYgNjXZK10yY6+iusLkOIw9Bn
hNe4hUuwqA99TUdtuqoNhpR/VgQ6dcVvN51Ah/H7uS5yFBdspFJcGsDvG3+Y
A6p4wweU8NJnbu9qLeKxzRoRHR4fIQR1+xiScwXsSproCaYwMP0YNYZ1ZgTt
1LaXVviQdjexFDI9uKAseqS4d4h0KaFw5KfIhdSTZGSjPWcE7hpsScfVwovH
mNkpmtUJt0RwelPuIg0Wgvcp39UlnKKQtEK/l8cTJn5BiMnjWL3aczDmzYE5
sRllvHK6lEvxPJi36WQqM92hLWlpUbqFRRftwAUnhlrkAWteiJMd0nlvwO1K
WW4axUC6UMoX8oWUOTejdj0dLgiVKAT/KbXVYllKIZYLP9hUqy4BUfHKlFf0
0Jk33uXWJZKy4b8pSU8ji6dZdp0SD2KT+ZvAysrUltZOpVIAzhJSMss8grOG
VMpPlJfoOTo+8TwCqvvstKuLoEdUVeRhLkyUASBdZVdSRF4m6oFZ2SFydwRk
3smX4wB9A7oqtq0S2cA72KrC62Djwn8WdIHOib1wNy7vbsSXpaLhueoyskB2
6GRrL7IWFnq2k6LP2NJPi+WsoVYqmV364tWysHBCJNkz2pCiyaiazqdB0AmZ
bDagZgiOMiVhV0FJ0QfsWm667N5MN5l+T3tusklwZzNRBx2+06//mOEMQzjE
PigODJXwpuKAga74ehGXAb1cRDUg/pJUwwVyrQx+Az6DjQdRngrBjempEkXn
cFJ9E7+BL9LBtzTAIrQHvFeWsRAq7MM2DcUJZyuyTZU+YQppTX9hopdKtlAR
qpkCcHStzhcyQoGvVXMNvibk8qVartAolqlf80UVl2suOnl02vB5au76rJze
kaosjgzjlEDLgRzlMRsHj5fzDmsANgJj7u6ICnjCVk1ayOQL5WKhksuPhWw2
k8lnBGZ09HEnj64G5smDlbnZQZg+SykWY7ZDSiCq+UGkVqbFbFbgs0VJ5EvZ
So6vEFLhC4VCaZKTMpPytLyzHC+UXp+77V9uu1cVzVyazDLx12TUIPCVjlfr
hKGC0+wJE9BwKZksd5QePqL8a6cX3WLfuHzpr2kDUApA3BAV6e8UPSQRlRQI
M4qDP0tAOx5PcqKaEXGwmdqgmVQO6m3PWMRtcdo7eg/gDez1EGy8x4iKJf37
s0uszd+i/Ezbo20Cvk5CX4i2/zWATyFJgJOlghEcNhVDD+mMZPOZcumVcR/W
1Bh1wePh4zaRGF781NFCFnUw3+BbK3jHjET9CUR7YJrt7g7hS5pnCgvdvKI6
HxQWPw5fbQ+JXe8JtesoDC8kIII2WJYomxCqd/bPbJm66Eb3cCT2AKjBgAEy
S58CdILnxIew1XDTd+27FEs7AlyyZT1qyKTwEW3Ddn3G+WyuVBQq2TSmDZoZ
1mYs5DKVIti/294NUM0OnewQWUIP/Vxx+/iVMTaTTB7z0lgbiunItRaKPQdM
/VKvYIMoIQ0SeUy7mYsTTDuH6UIUEB7RVXQAB0UCKfgibpQpvxBVZWNYbG7E
xSRsZdOfzHsLWVyKHlI6oJWAB2kN22CGwXOdGxL3WuWyF8Fu5wosA6LbYN5N
QQdScGAzo8dFdJAUBAgDw0AJQE/96W9QuDML4Ii08DXbjJ0R8APSxUqxIuRL
BbYAuj3c1wNXKJwjRvOeMWXnCTuiw7KTgqwwBvCEAo4eOyEILMjBVliFdtIx
7ooe/QVRU9vPtsG3kRwDp2wnYnt+6B8JOgY7X8MEN2AZiXjKJy6iBEQFBl3q
gelgpzX2rSkuxoeMaIzFe+VT44n5EmVJKV+q5IVCIVcq54rA+plinn/mq3k2
lwNDtpSZwdUsIJLxJjaWNaEfjsG4YjLLD71hopzuCiDT6AaP5AHNTC8fUywK
5Syo1VyxWAR0Cln+PlMtMCxqGFPTt8Dn203NuAeHCXwMqox+zOfzBSEvZMcG
Y1pMpORQA+mQzbXFJl8pCeVsJQ++bz6f4VdTJef7poZl4zbSEIg6JTEIgcVk
02/SLIY9oHoajO60x2PM0dj8xeZqw+7R0fZni8iUza4wjomlRtjreH+q4bGQ
LWoON/3XPy1uiIa1NScY86njzfhwM5udWy1YCt0d7uPqogVOB9dRVAersQNR
NvTUy+bAtFsQG4Mo2dke4HoKrVT5320T6DOLIK3Xo8HiXooEL8FbUDKQhTjK
3klDSMx5oZz4r0jJcTzCpkfOeLwN0xJa536koF9h8IhVUKQl9IgjpU7ZaR9G
HdIMdEGio8mGq9e9DgFvGi1Lz9T25xVm0TSRWALF9s/5iVexdHtrEzO11ekB
Idu7YOFrCJrF5AaPD557IqfQpEkmCY4eMGqCprhOcPxLo6/T3cGoFYjQSJIK
7wA1+MoLiw/xqJeej143nWx2MkD7aS2CrBXeh+x8HZH236ARlmKJMvxD2zAe
tNv9sL3zzxAOXnSxB1qxOKw5Gw62YwiILCGEJ3qQaHviQ/YdVUfQ9NMnsCgI
FmWADAQYrLhPJydkLakummInJ9HvMfjEC0qPOeE+Zumtgj282MKNeMMgXSu1
hMbT2Hqyy93M+Sy3qZu5gWhm7kkzHdoM/HOAjhMiJTZvK/JNy3Cq1y8dXV5k
c881aVUb5UQ7GVJxgJIilessM03Bnt7by03NUYvV2UP5iR92OsoqGVJxgJIi
Vbg4KyoVe2lo+tzc9Dt3ffLUK0172v11MqTiACVF6nb88Ny+echNmyuxtVpt
ptVKw56bHeJkkiEVBygpUmetsbTSOp3mxDob3xVui5smce7udEXJJ0MqDlBS
pPrj+sNoI80y5+2SNDkX3VaVX9zO7rNPRjKk4gAlRerx7Ons3nxYPRb0+q32
Mr7Lt86L90qr+ZCQUnGAkiKVt43cxbpzdXXfGQorfTl3DXJ3NyP1ziIZUnGA
kiJ1XTzTpEJ5mZEEtXGbc5+6D5nq/diYtqvJkIoDlBQpPd8jhet+fbmar6Xm
mS7fkf4GfFLJSMhTcYCSIjUhg5fLy+Wqp0wXg+lZf7omUtvomKNGQokeBygB
UtIUft0UHjpyRVAfnpTn+sip1B43t43LFrkxe+9G6k1AiXVfq27ka71BY3iz
0ZeXler1mej0n/R7cZZQ98UASorUajJ+sCu9R7niVoxetrbgy86yNF3etxMi
FQcoKVLGsjzlS9Lj+Xlh8Mj3tCep2J3fDmt8K6FIiAOUFKmse+OKDaGxmT1d
Nnr59mjMWw+T1Ug5S4hUHKCkSJm1XEWcXArXVic/ro5642apvFz3R+46IVJx
gBLrvvV5fd3rEH5YVQYVd351parWeV67qSZUM3GAkiI1EtaueVNbPT80a8NO
fXQ/G3buHx35+aWcDKk4QEmRmg9W+WJrNdNuZaUyfX7UstOn84mqj7sJ1Uwc
oKRI3bRLm+Z4oWqD4fpyk+3cF6cvbsvQG0/vF55vAkq8+uYm6aoyaU2bRaPy
XLyo3C6cTKZaP09IqThASZGaSVnlKbOcGGQ+HPNLIcMPL211LT7WE5rDcYAS
C8+rvFadPhc6Z4+m02hcWkNdLr005HshIaPHAUqK1L17Jo03zbN+vdd1H6Rl
9qpXum8Ys0H9JhlScYAS21O3HVWftLrNOS/1r0nPbdxePa8LD8u7hC5WHKCk
SK1vb3L10vPNlT6TFLNUyz9eFXpnN6PKfUKFHAcoKVLCrC71V3zp0jAbg5eX
2ks1J7e6MyM3SGjkxQFKipRTFo3JSy1Xyqt3ysWLdWtdDR5Ki/bDJuH0xQFK
ipSWu9nUivcX1y9r0ZXIU3NslPt6XnCH3WRIxQFKLKeeO8/SZHK+FMdGu8k/
NRuPbjafm035hAo5DlBiF6tRvq4Jd7cXvGNcGsv2dXa0KDY0jTQTqpk4QEmR
Wt5fZk1l+lho30t1YX2xGk4v6vqN1LpJuGkWBygpUr12617RJ+XC/VC8WDw/
1ZpzrfZYL/WlhDwVBygpUk925bab79fKmwdtPsteTcTHmiBms9OLhDwVBygp
UpnBy9Xg5X58K6sPhZvrce+up60fVd16Siin4gAlReou1+sINXDWJppwd9Nf
t6+VudiVhJdRQhs9DlBie2ostjeq1uoYF9rzZalWkx5ujQ5vXSb2ZmIAJUWq
NHwYurVy7lyzKs/1iXArtCp5vXKXyyW0EuIAJeap4d10ln24bFavnLPr0qM9
FdZq/oqvXiXcdYkDlFgha9PLFT9Zlc9t+Wyi5m3xolJpveQVIiVUyDGAEu8O
b5Rpu/zSL4grw5qMh8LloNJq3jTv75LuDscASopU/WG17JUKL0Vr1JWz1dzj
4/LxTOusr5SE9lQcoARIuVMNfmYr69bjfaGeN4bthflYXd6PxqWHi7vs7fvn
721ISWnlCp31w11FOpvemkquPq08Z4pkvjIf2gm1XxygpEgN2+NqJiMURf68
p99XF22nd7M2Fo/aU0JWjwOU+MhoVeKv7rL16q2V4a9rL5USqfbWtbHeS6iS
4wAldtz1zUQSp8vrbIPvzm+mo9tstnx33bqcJ/SR4wAlRcrSbi9Ja/IkrrNF
NSfoBVNxOt311fUioaKJA5QUqcZsfia3cxt70m+d965JWXp54R2p23tOKKni
ACWm1OOFKClydqU3HfFsNZwo3e7UyY0yrYQ8FQcoKVLjRbN21bi0R3dPM1Ge
FNa6+lQuysu5lNCiigOUFKnnfu6+numJVqtVzQ17k5p5d3fmrKv1y4SMHgco
KVKLxdP1XMlvlmdjpbp6sPorQbJac17jE/JUHKDE/kxtIZ875y8jJ9+qCLem
NT3v6vJMG2UTGi9xgJIi1XHdcbXlCkJtZMnr81y3PNdW2acns5zQcY8DlHzb
TFeM9aI2Hl8/dpfzll7QxbviU/f+JaGdEAcoKVLKnV2vV9XywyNvXo2qJVu5
vGnbU1XpJKRUHKCkSPGddv9mUKgv3ds76ao6y5Wk4XplVEdaQkaPA5QUqQv9
4qFZmrSvr7T6+vb+uWg7ypVzvpKEhHIqDlBinhpPumfzK7mWfxJmGV16Wfcf
V617p24k3YqNAZT4zGGTf769PrtuD8pZfmIvrsc37W5RIarwkPDMIQZQYnvq
LGePH1r6tNK9LpdGy6wkPOenueL6PCGjxwFKHFhyd957eBAe2kIzqwzHnc11
3mpoV3ajnTAuKA5QYivhXNAbQ7KqTm4vxityZVbKC/3hUZoVEzJ6HKDEWxxP
7ktm2n0qO08PhnSjKY+P99JwtWp1ElIqDlBix+FBuc2fP15a2YxFiteLtra5
G+bMvkMSWglxgBKH4DzM1pqgTJyimZcvSuuW8HApq5n7oZnQm4kDlBSp4sX5
7MrMZh8G6/boYcIrfG2t9NovvbuEe3lxgBKLBKMjnfed+4tp7eah/mhcCrp+
VSRCi0/I6HGAEsdwDDeTTkWZ65dPl6XhkzyfP4zvnfW85yScvjhASZGSx+2y
VbrotZ+q+UKtT9aPK3uqaVXnLKFEjwOUeC+BfxHLxfHDWcY2V7X72mp0e/2y
Uq7qVsK9vDhAiSMT8t2evKyvy+qweW7VlbPu08Ss1QdWPqGRFwcosT1Vvaps
WmfGVL0VVo3VSprnC7L2vNA2CW30OECJbfTMxXNnWhPta00tVh74yqM61p+m
drOccPXFAUosEuZXbfVhI403uqMtRxlQEmtVVlfiOuGRURygxFbCZHVRkWS1
OFX6mWWtPasOb24amtjfJDTy4gAljnZxyKoz6bXPa9dX542s/WzNRpZu1q8W
CfcS4gAl3p+yu09Fo7Sa5uf3Y7d+URBG9dGSX7XWCUVCHKDEEr0olRvFfq0x
IJl1vlF9vu/lnHyzL+WTSvQYQInDuqxaIVc6mzvZRfPitj60RoOFAxKmlDRQ
Nw5QUqQGff38YXpTb4x7g1VurlczmZdZsZzftBOuvjhAiWM4ep1xxr64uCn0
yMJo6i9352d690wThwm3F+MAJUWqfVav5gRtViVzddbqD9zxplMVMup5P+Hq
iwOUFKnKlM8KZ73zoi30ZcmYFLW+kSlalystoYsVBygpUuXn53G7NcpVhG5z
0n58vL5xHnpXl/eVm4R7CXGAEofgvLjZG7WuPvQW7fLscnhVV9fts9lKv0o4
fXGAEKkmS7vwOVk0wHR9Zw4cdfTcb6r35eV9fll2lctiYZRQisYBSmxYLW4y
T3fjdafaEsrWo+Y8nmWrWXO86iQ0F+IAJQ5ReNTkh/NrdTon1mRurLpN7XGw
ynZaQkLRHgcosbWXeSremHZjXCeT536/d7lonNWfNsPnZkLmigOUAClLdOy0
bTesx0HrLm8X60PxgVQrXa2T6fevhfcvwzcBJUXqql/rju9kfmCMXl7keaGR
OXs07tTLdvf9htWbgJIipU8t2RJGlb5sFhvjxVO26eTuHxf8/Or9vtabgJIi
Nev1lk5f6N7b963pJHNf0HvzwUi8uDDerwTfBJQUqY3Ybuft22nerE/PMp3L
fn+wzN3PMlI74fTFAUqKVEOsCk+N68sWP5GvCmteXtxOhi9qR2q837B6E1BS
pExn0Xm8abwMjQe9URwUXlS92JGagrRMiFQcoMSGlcBrtYs7QcuPzpW2ff18
Nb/qLiaX69uEEj0OUOLoylpHqpUfBoNM51baKPP5kyYI98+D+V3CAIU4QEmR
ennILeX+ePR4/tiVz8cLU7JWd9fuwzSpqxwHKHF0pXTfdvWpMRKuzi0Qf62B
PTMv7fulntCDiAOUFKnWcJ5xRmJpLlxKIrl9bF4+vxRXs3yhntBVjgOU+KKt
a9jC2iioiwvFPucrg/bZ3cWZWNW1hB5EHKDE4Xm3m0luLj0PjLNW3rlYnF2t
7WzdJZduwg31OECJPQitcfnMt5Y5vlLKFp/J2CEZffpw3hMTOoBxgJIidb5y
2kPpovuwvKnfZauZzro6LNiV+14v4e5ZHKDERw/mRa2pFMZ6zyoIs6E+KxjP
Q8EdqUl3OuIAJb6pmVXFs4m7aV1fW8VrQb+pT8xzcdy/THoDKg5Q4phBPndd
LY/le6Fa0OTztXG74YWXcXmgJjykiQOUOGriqWvkzuq9p85MHVyKw2Hn8ur5
6XzWWCeU6HGAEu8JNYWnnNjnn5fizWzEX5fLZ2Tt1LuqlNCbiQOUeJffeGqa
5WFWaDnTrGFf1M8ujUF53X9Jei0rDlBi/71f7K8bZ/NqpzLRyfTmST2XMtNK
UVwkZPQ4QInDg6yRdd9TLrv9zcPLbWOp3qtntczNMvFGVRygxLpP7tSWucbm
ZpNvmda8JCiVzLpodvr1hCdHcYCSmsOdpnV/cXXXHzW0q/PioHd7VT7LqM12
ffN+4fkmoKRIXT/bTkOY2OfWozW9Ht9e3/CPlfP5g57g6OFNQIk95Hlerdn3
hZWjP/fPeoLUv1o4gta/qr5/S+9NQEmRknvVR96tTh676s1aaUyuxpnH2u08
/1xJuJcQBygpUq2B/HJ7dVa4qtn5nrBxW4ux7qwfVGHz/l2XNwElRerZyq9K
LUWvL9rCs5MtifX609m55fYL7/dm3gSUODRdm47rzsQZNjr9l5zb6wzuiUqy
y9WD9X7p+TYkL8NaD2uvXbuYT9LQ7aOjLi1jZzmn3BQg04Kw3LP/mmV/oumu
LFGxWXquu3Y0QxQ0oCnULQfTKWElNCzJRLMn3WGFp/31r73S159Ytk/uP2Ir
knsVU+1kNbG9Vr8fYfllTO6FlQgV3aUV9ML1D20/Cxot/4Wpl2klSyzehZWv
68MqT2r91j/+AT963dGgydcDSOGycVjcDyshKljHFwuXe8W7duuen5zQUZ+c
HBjFkwvknypE/p27CfCgFQ0wlaCjaK8r2E62NYkwD5dBa6aHvrEwrz6naLS8
kUMw2eLUIRamPtMJK3LahG9pvV2apG0EvXzmsJTxl6BicTShXYQJgXfSiuxV
ovZqNYCa4tn0Lm2eTlomT/OGYikmmhe1yGePUz6feHnb/OLuWNqPDgP4R5np
tLayzehn7akK7ZeF3q0L/YkmnQTYWOhblzY+tbwEzEQ+/p1Wbpe9OuMnJyxP
NEvdxvrb9k+rfGHSOjoJWOrN1WgWOlakcRc2FjjFymg/lIj5VDaVp2TsAO8F
5V2xbB+ddC9VHF2EgDOQRiesQIZBK8cuDXVJ2YXVqsekj1iiVrKIc3LyO8X+
73/HgoeDKivKjd1g1l1O5CitaFXhSHVhbkZY8StM7gukwhrr/W63wdK/1Tvd
/hh+/O7lfHQVGXO8cyMwilFqNP0hYMlppGfMOFJcC+QiPoDXssHB1Pj56BT9
KFpJ7nV9zVN41ry5bbCHQjFfLrOHWGoaFjnWHah22ahpiVoFlgzFimXjo0V7
sefQOP2stF4KRGziZ/PzKkETKxZrbhdrikxTnoEst21+uAEImr0PKQm6pZXX
gToE675tKxQno1Nk+Nk9JMmx7msKrcHGOjdoJXEuwkD2O0Z6tNOvn2SZx9yN
qh3qPXgzM/Y9JcZy/2Nt32PLkQ485mXx0BtHcnHkmL8xlAUXlJ6DVTdwmrdp
HY9ossJQFlyPaUzQS1izjpbOoRk/Lc1PxvgqL+L+RIhvFU/lepj8UgklSF1h
5dWgio/B6j9jhkbTwgz6mK05TatpsXSKLHslTZQZpFate4UtRc9yqAJEv8av
X5yZykdaixKxRj3n6/7Dmu+TuBBZKbzjnVp4tQ2nG7S4tx0qhQ1CR5cxeeM2
52O0kPdkWyoV3qk0YysTGqwcNsg5lrbUBxQkn8RpiKuUbBuqy6pqcmA3MSvI
BasM640aWGJsbnj1AVUDK8qwsic7yS29hJVoZWB5JVittJqyP8WqhyaOFKtn
+UBgoJhfVfGmjqbVxGqfzNYhoo3VSSeEC1KSTjZbeYnzFxQiTIGEBYsOpC0B
Ki0jKZtp9lOsIwyTFT8I+AZ6iBZQRFZGYYcJgb3aqcBSiKmfBdSvXHy6LeRJ
U8b6PWsgh7CUPKZv1enwbK9Ym+1OHHVv9UquCZMv0aywUQ4Fvf5JSZHUqVcJ
yqSpaumiEoF5/SSgTAWG2Mhfs6fwxMshyk2Ap3E8NGsyS8Da82pTgZEGqpob
0tpUp2BhW4qowRIE8SVOxVNu5BoaWCFV14IftwqufVsVl1zDnZDNwjjlzjB3
PTYj3JkogfUN1vjQ0GcTg6u5p1x9TvTZGpDruCLaGh3RWGHGZQN/nIsbkWta
kgI8c8o1QLWcu0AcIGMVDDmHO//XP//1P/71zwVA3KhLFNA1osJEiljHq7kU
uTpIixR3p+BDmJYztD11rtEcDpuXl80hN6x2L0fNSxyXbWMxZkXUMQe2Mpuj
aoHnwMSWOAenApbOBgzUuqGqsPDZFHexGvFQmluGtDimnE+82QpLRlFhIvDN
0pkmvGUpgGkRTVqWOGB1z+7yq7gelp2vC2+iDUhX7skJ4GUiI02wgrZis1Xg
2ZV7an16KXBNVrjQT4FLB4XlRIHiqBbxd5D33BO94VasH5RRQAC0Kjyu93wY
Kvj8MtOvSqr6aX2p3+Z/i6ih/LJEU8HcxJ5M9ccJqpd4taPVTSBQQit0m8XY
nrMK5SHTKcWNQDArOkzbS0B3tn6w0KIq04LVtCMqBPwM70Gve5WdD4emJN6i
ihDAloDlsaSZlhEMlpoVHZExRvDIprbRdjJZS69L/GpBaCHjbdVqHKWrYek4
/zHN6g2900qsviWK1eKwEoQepCe+3c8J1W1i4dutQG+gXrKPRobn4diBqxwA
OOUWurFSCZh5bOHQ8rbAntR825ITyUClj1eZIo4tQ1mOQ9qFKkm0trp8IzU1
bMwGTgskhCtWZCrMBAp/Q30RunTCn/oV7dm3oAZe2Ie0pi+4zKATbPTFlSXz
O9FE9BJea4TQ/OaeLgCZhk6ahXnFA45BLgS3DOfQAQqoILo5rOyDD304dA7t
N6R1vV7nQr46N+y2mYDyDbYU1/fLGjIN+wkrt5P1XESRCKSHlYDzdgwsBdpJ
ppj//e9YVnj7ACtns8Fwnkfnf+P/hC9oimrKpVSdo+tEdf5id9bi50jIIHmB
PujLwayGRAszhELidOpa1OTxltiO8cQwxFoUnnWL5q0/pKB4cmjY/zg6+kat
CCfdQUPmG3giukvgvw2YwU/2Mfdtu3i+wbc8mAsH/w3vmVfD1QyYNCRgYHX2
6twfWMlHd9cwP66G5kY4YTvKpK1LrZpSiiBadpr+J53NpBGXviXOXFhY9Rcs
kSfCkwJ3JYGaxebw64tfMjseFPo4ljJhNmA6WygX0sdgk6m4N3XK4XgNOpqa
0fr3xbqYz+zH+ku7mm93OCHvzHEp6Fj1vceWaHTTYibmZ3O6a8H6wBa8yVpQ
xIfQRDTRqv3GZcswmabDZyOo7+m93xzx9atLliI/+5kTiogHq0zCNf3KJF5J
d1R1SNAlY+MtftMZbxInNVOwqgqKBx2Wi+q4+iyNAPkDpU4oQFZAT2d7jt+4
i3/9cwJu9KlflYIOhs9W6Hh2RsKGEM7yv0XJBhFkp2aGMfPKrchKCswa0Fyi
kFKcNLENS5FsWgcC+x2A33jKdQFt7FLI80I52uUX1md0UnxzCsso0Bo+oQoE
6byQzwvFbKE03kl2j7nux1HdPu6AacdT2QoLEF+OFX3sbV3I49HF8JiNFiUn
N6iOhlgtFT7WfIG+RQx1NHIoWIjbrS7vKyz0hK1Y17itzmdyab8+Ev5GYtwq
luOCjEdCvEGF5J3hhg0Y66qdZrD4fV/Rgksi70lSvwoTfQkCkZkcPNohfFBp
0ycev6OY+UwGVt4XyvRbvDfgL7upCUlvCuPhIMM3XjqZ352/ZQsFRmissiqC
TtBRpgy6VyNu6Gqg13bZjD4EDWw4vMEKUgUs1QaxY4DyP+VaFt1r+8YxahIU
TVuSOoYJNpG90Q0TTMAtbNClwMKKDsRKTa101jSNmZWdjobnrj0wZrnB/aR/
/Tu6cL9SENvyXL45iXZepByTGK5yRuS5IXls9WEjzPJ7x/haaB6Cy0pwmVhy
zbIPlCLG+fyO5ZirlMu5THHs67lx1aPT2JhG1toY6LR90Gx0rurHEbHZQDM4
UJd3hrXAWjwEPNBPjeHd8PiQ6MZDmrFNv0yzSqJ+QRrchqGWyJe2akxg7VVV
dPq8sjttoLMG4oqq6Q5Y3SClP1HNcbCr6DrO5sFKnv0pYZYrFCuFUoFJqqEv
qXZMcpRaLbpJMm53W+MGwW38MQwhSl+22x5v4+5ZtK6dya7IJPViGFrKxQp+
UppufaZvqnquLMhEEXmxd6k9tTvz3vPakCShI21apYV9oYqEnJPp+io/Gdaz
Wqf/supf9x/aJCvrj4PUy1QlD3VNc0BvGONLT9xG6t9Uu1yf+S9D3Hf0tDTK
ByqUhfCqiRwz+OJQ8JbNrUJ0XTyFGQFWoCZGVuDOXHWznR90e957DAlgkWzg
uhA7bcgzebzW5k/X98pgLF48yM/O7bJxRlr57102mUohnxUq477nBI8H7XGY
MOOgMBCbaCyKrEjjapfRcNisjn4MkRLpIoT7SvXAQ8Z9fgFB77AU1QbITjDc
4V0mkzLlaZwOaU0KnZe5oJlCE3RIXihXwtoaOqHqRCaaAX+Y5obrgBsaooOy
ULYIEz2C89xXRPQvhHGAOpkwdZA8WxUGo8J67El7/HWn2qq0tG2+VOCV1+YM
Ugdx+zOD2l1vAVv9uGX3imbfve5uK7Xzx7Nxo7147Muq/lQTb8hGdeeT5+v/
onXXMZxBq/4hdBIqu3T6mKU3NxxrKnm2nlA4WBkdrBavQlqk9Ha8YddqdO4G
ytP63DZgUeay5cK+RUm58A3CBNxqpynWAfO+l1o/eyV+0Oz4vdMJkvd1xu/g
FT8j7cHzxmp0m7PmCmZEyOUzbEa6zX7735pPFWLOPC7N7CV6MjrMys9jV6gs
718WqC7ymbzHmWhI2nPDjBIgXKbU1kVp7vAyiA4saQzuNnDUzAIb2asfDq63
Al8cKv4qFAq4DoDYDQaCG0oK3R25xMKxO7b/270Ttgh8YCBSizAFOglNwY5a
+DEDouS7ch14ujMGgz7kZRlh7+BaCOP6CtVIS7pwFw4W0sRi2d7xOdaijSud
DHI5KtREJqR5EaxeFlOQ9pA/oPr2+mRsswlLfbrrKcZpsPMU5OVDZUUpGOjr
E1bThNfsAOcMpgE8Ddwpo1tIos48OcWWjFPuZlhFKuV48B6ihMKYmN1am29o
M6Fc+P+ru7rftq0r/p6/gkjRIgkim6S+MwSFZFu2bOvDkhzZ7oNAiVckLYqk
+SFZ3gp0wYZ2xbq2QDcMbdYBAza0Q7o+bCsKpEMe8qcsdtKn/Qs7515Sor5s
y3XXLkCbUCIP7z3n3HPPOfecnyCESDWqmF2HME47od9Mhl6zuTE8zlkZnk5N
JcnCM28Nn/BjIVD4FfyBX64o0bTyiMG5If/Gp9MyWm38jerxOCrKcxnL1vRz
TMyleBFLx9Jio4K6hNNHXcLQaSJR1MicGw5Nh0FRVz1QnYoWyR5sbkfWjw6N
/vqJmtSMpu56W3ndenB4VNDrVqJekQu1g0TiIGVFUvuHkkRK7aa6t7RibiT2
s15H2vIkXum4eHrICoG0Lo6ka3E8f09M3uN5KigI8rgy29OwWqCPR8fIbJbV
pKwKyt1m2JbJnKaE9+OCwfsjwzRDAXOpEPTe5VYkQ5Il7laPCQS/FJJjErma
QEQhmkgIfKOG5S/oafm3N9YMeJVpYOK+UausNUoWMRpVD4LE8wz8lp02jy2h
LRuYUxL4VBTvtgnWa87jQFDNAf7lFBci/g4VYSQCk1GE9VkddGExanicZqDL
x9UwFeQEx4KBdTfboZ/rhduqJqy0iUSP6UR6Jh2LAjK3lsE7g88mFoCQmGT3
jNTOHEpUoCyFM8tLCT3GbONyW9MJeyzCx+jffExINNj4XxX5V8WU8KqYnhOe
XWYYM7Lgwj1OiF93Fjy+WBZ8S7J1x/ZUEs6DC4nItSg7Wp84L9I8DUQR85Jg
yNGr2XkxGU1dRJ2m2Cb3ArCAoLQN9AN9yazXCjmW2r/HZQwDdTAIAP1Kg/o6
d5O9C74Bb1Wmuh8o+83R2BW326b5/iWHLQoHdwyqHr7L8To4G8p9ws4hvJNI
FesI4P9ej3h2OMcZiwDzC5L9XXeBeDQpxBfbBViYnKuEHeb4hQ5znJ0QqcQ4
gf+wugV/ZXvMjKYvmNAFnnN8lucMEV3bRqsVdpnO943z7S2lWUrGtt0YmM4E
H4/NzCJdbsq36JsvnHrye5k6zStNp+TPn766lwQPca1TTGKIlEgm/Nlj5qM7
lfm4FsF/d03mo7FkLJqMzs9UBDmJ7czW2v96/FeTno6uPKvOmX2cQk9PLpDm
5kl722oaqs5nMAUhCMk5qZlrYUT8e2HEWI7GZ8iwiGhUasqu5kdC5zOq5JbM
ZNFUNAfVPhoXgog44M/VcjXxiVzNueyLRaY4eLW8TTyUt7nuaPEK2Z15cp3I
7iw00vOlmRAz8dTRhpAu5PFIVUzyQVQ3XQ4U2p81V/Wa9Kwe7ouMb3phD5Tn
cqR5jp6HCM0+PvTJB161g2eOTUz2GiFWBYWmtM6UlZmyndrfqNchEKAeqSiw
84GfTDEEFZQypclKEPqS21Jf793X5KN+k1dzuuq8hvVN98vb3XZnd7MVTXsF
9cAprnet48jRasRbMXcGBUXPW69hGJEQnO+vCkA4pwogfQHHF3/XZYoABN/o
UM0ceQ8XHcYou5X9hCA/0Mo0ywhb023uvBRLyIE3HZl0R0fRDjYMeDpZpnOb
k1oBwyKTHhjELp7gvpErVVfXChOh1SRh5G4WQk2H6M5drA1WMID7GRcVuE3J
iAgT7J6OsOaOlMXR6xvruWxhuFe5wOZZhmOSil/DRFlNG9KcWZQYlWUxAXu+
yIIykRcaCd5LE96YIx16uTT5Qk9OiEJ8xkuWpJ6w1CfN7nUaDjGJ3P3BDQdz
ksApoqwTxOQc6zFU6DIfc7c3W9XjduH1y5uLWDR2rVY3+qNgns80IXoR01pV
e+WgODCTDWUBptFUzXVyLcGtkhblWvwirk0QWl6YT1l2hk29cHaGjdyKC6KQ
uIhb/UbBPiyQjUE5tQC34ulrZZZ4eV5ds4bRrN6wP9vnGi9exDUhIa0fRMwD
TV5Ex8S0SP2hn97jXM3Vyf2b4Yr3oLyajCrfx2rJF6g2v/nmDVZWnPGroIdF
xcMqabiDdWnD2vYkezAqeR/WgrOGNr974EdR3E4bk1jDI1bzB62NtFd7ooPF
tP0mJ1YgbrKOek7CXlEDe9RAV9Vw5eUUn/E5ybKwcwV7CC0bO7nH2kDwJbTV
SWqTYQOMZmM3u+3coxJ4hZtI6SzhoSH76hXmzc0Ja27f4LgI9wbNftRDa+oy
sC5RsnOcO9zJbW63iEQSeqxRVPaMrrO6H5ClHuTlyVIUhoTSPDrm9/ZT9X17
I1o4jvVKKUOMeFvKkGxtexGq6FOk9MHRhpoeJBvbvURT0PZUa/do37b4Ah8Q
pamDy1PF+H25ZvZcPdlXeif9zXpNzIsHfUM18yVjf2fI2Uzm8myVJGX5MHvw
oJPcH1T7lpQ7GsiZ9nE9Gu0UD8rD+ZfRWWPNcWOdemgjLvsuK6ARGev2W5YT
8XpZWuHrzYNK/7iWbelGrdNOVrv0p6Xx9bQORKShI+ueeMNVbSLJwmVfLY0I
LHvNk6S3t+JEIvsnXrU+2CsWnW693XCrO1iyCIvDpy5ehfrxhnqYScfaJ0RO
lIr5Xrmi9Gu1SL3SzQS8XK0WVhZinNx1Wss7K6Ik51v7nWOtphvaWquVVJRO
KpHNDIU0I6FwPuFRKqGctzfFUmPnqFXczRiFvNF4oIpivlsvtALq4dqg668n
GlmOypTlsMcsx26uUFm/t7AKMGSTg/oW7xUKabEk9/VyU9nL9nYy1qpF4lcV
vk+3olaSprBh14/b66ttpbJZqCTilWxndc0fNk1wLzpozDUvF5vHG/l+eqNx
bFX3m0q71DCS+oN8jtSdK46Zkt2N72/IaUHfP9SOVmpuOnsweLBazJFdqzDU
1HyxcmlTAo7aciO1vRateMLxnpBQlfXNvj0o1Cr9iillQiIGp2beGbcfgdJT
arb0x12wWXLHpeQszaWjLIc24mVaVr4sCEmRTwrR6Dz+LUSzizG9QpajEJ/Q
QdcyK1caKMQDowGmo6KQvvoAQ7REnk+kUnF+JIHSSnl8jWGHOCNAQksNbhse
O8GE/HmGZmS2rIik60v0MNJhL4aHIsFDY7NJCgkMo30q4sJUaPauMTpDQoeD
TS7Nx8Oko9dGOpaKpjBxS2XgU49dG/W4GEtE475UuDV0GkPqntUJkREDCi0i
s3oL2qSdLdnik+XYLql5jppZEY7SJJt1Ld7HMBym3P7fel9w8GHdXEAiwVqF
nSlK6UBoSdFPQofsg64ljZpU6CXyFs9UKVCNf3yfRl7z+IcC6YAc820OIina
gRuCh8DO4Z4ErgsKDU+7qAtDUYIgNPEBKVhMwpqlfS6xBmHqc9/lLNZTqhPE
lKJvoJAFK+GevBtjV0E8xXo4sWO+T9BIEJrUu3QEOpkzR+VdIICd9fht2pRt
gEHXCGdAvLNKPNdpqZxj2aRFDzM6z74yDMLuwGI5TiG2QbCrmluLFIAG8JfD
krc17G32XOxeRTcDO/AhUFGlJnxX0FxF14iMXTsyEMqrSLJJNA7RZp49ok6o
e+KBSPIqojJliQajVRxOJXobbvVHAcM9/cvDs08fnT387PT9vz7/5uOXX/7j
+ddfnP3u7f988+tv//Dp6ddfnz3+08unv4Ebvn3r45dP337x0T9Pv/jg24d/
e/7kq5c//+jF35+8ePz49JNPnv/rvef/evTyrV/++62HZ+98+PzJ47NHvzp7
54PTD39/+v6Xz5/8+fS990/f/fzF0ycvv/wQqL34+Bdn7/72xWdP4X6Udz5T
zEzhU9TGoFNUyUG4E3ona9dHdIsb2CHbhIWNVDKtoEmcpkQhiDZobymR799s
w1ImEGeP38OAmrAV2iAIKyDZCBOCWB4T+Ad5l36qBSBr4RC7zcquECMATBsO
hhpWBC3waJ4elb3t6RSWpkshC3w8mynUDxYU2wxjQWaAURbKmUauAYTLUsAb
H8+FIoI5rNk/yEpgE7jD0MDYgTAG0EHeloO4D/vBQxgtnINLyK/UAHVF5mAP
VLgVmjZmQ5x8585Mo37nDuJFzfrmzTcpXEFfc1S/N9+mIT2sEb/Fm8bspKUx
j8hf4iNECD9y14IkAYXPq8K6HHBbqDASV9IMCT5btSWnY/p/9bQWfFSQ7A7Y
loonD+AqDAgCl5uw3rYkTKHDRZko3CYCySB2E7FhzYAYc4iyBh9USJN0JJUr
AX9l027DRzWzqYFWlj1dd5Ars1IHlCmzvvB5osDofVQqaaiaZMb0NVgciuqi
Ho00i2U9YFlb+HmAEmMac99JGbdmay0EaAJN05Fpm55qwjxt59nnxhTDJvBa
kDW2hxAnumSAUXNREC4oHbdlky6xkS2HEpqwDRAxex4RU2qq2XVMJL/vGTin
TU2ifC1LPaJzRa1jGiYsDfhkBXaEAUKusPszhmkMuohKGO4fDoB8bP8dLRNu
1MDuuRp3a+xGRyUW7FcybourkgHaUQAnAxaXrx8V01A6noQDpjpAEGNhW/Jk
NjMLgRc2TL1L1SIDW4EtceuejhcuML1sSx3JUelM4LI66FGIDF+3fBUpeETF
2l2c8KapGvAU8Z79EQbuug67Owv7OOjxhqTjMOqE4vtUYRNo4jgCuBvElxvh
23DTf5B/Y4A4Q/lseyblpmyTPrJAp8KaDYcDX4SRaegILFXDKkW1qxGFsrI3
kLlSR9KoHgBfkTr6ABIs07ppyl26wtaffWUjJQL6IjP9ADNVlVyTsqjjNZmK
IRCAa/adjjZSmhyieYCyMu6CDwCmddVTFEq4SmxV06jm6BLc4+EwV0kT9hFT
JwO6IGkMgeBctgb2la3F1Qi7CowS9VMQaoqZHcSZQMPUMiOhHCo1w+NPh4xS
T9I9ml8dwxKga216+YTwjugAKGDidZqBYBei78+bhueCuFWIpAhd7FNoSjgm
lY4px7K9M0zEBsIJOlwN3BkTXAgNNWBfsjF6VUm7TeUKa4bBN2zDftiEJYaK
vK7ZmqzC/lKAIQ6kLtVP4CCEEOhEglRdtlhMQ6LAXhvmADUFFyYIFbwtLivZ
aJNvIPZQG3YuKkb2T1+Gs3BCpjYPblR/z0BRcOvtmjKhOG1sLxV5/DdmRYWl
qF+ZqzHE1tA7h04uzb9TiCXJmXhFgKIVQMANQV+3QLVV0LYBzDUL81OknmTM
sqpFsFFdbssExw6EjNNfJxgxwJZy40bV3+apK+4EHckY+dzlMLC6i4AuLDnP
CrwZ7lqgnqyngKEnURYFjgtGApQU9R+WuAw3G+VlRIpChDngeYMAfoDunVcs
CHvuC0l0vmcijuHg2ogWRKfManSH6IShngLu1k3fXyd0LwSDYiiOAnua5jfA
LN28feO/FEHyumiEAQA=

-->

</rfc>
