<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-47" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-47"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <date year="2026" month="September" day="27"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 319?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 323?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 13 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">8</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">8.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">8.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">7.9*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">6.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.6*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">4.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
        <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of EarlyAttestationBleed."</t>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="security-researchers">
          <name>Security Researchers</name>
          <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
            </li>
          </ul>
        </section>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1095?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y92XLjSLIo+K6vgFVZTad0BJLgzuzpqeJOSqJEkdSado0J
AkESIjZh4aLOvjYv8zBm8wNjM/M4dn+i3/plvuN8ybhHACBAkZCQpczTdU5X
iQDCw8PDw93Dw8Od5/kjR3FU8pn7pSla6oarOg6xHdFRDJ2rG7qtyMQiMndL
rA3XES1t6qrcp/ptk89mskW+ki1lBM6YcvXb4ZCrpIRTLvIue+BdLleslIJ3
pVThlBN1mcvBM2dOLPzQxteuyTkGR9YmkRzAgn4tZFIZeCEZmqLPjn85EicT
iyzfGoCH+y9HkuiQmWFtPnOKPjWOjmRD0kUNCCBb4tThFd2xRH4O2NhzcUH4
qaiofL50ZLsTTbFtgOpsTPi62xy1OO5XTlRtA/pWdJmYBP6lO7+ccr8QWXEM
SxFV/NGt1uA/hgV/DUatX450V5sQ6/ORDJh8PpIAR6Lbrv2ZmwIwcgRDyR0B
YIuIn7nqoFk9WhnWYmYZrvmZGzaro6MF2cAj+fMRx3PVLifOoFcbf3SjyHPi
lhb4mhFo52F0TiJP6Oy+epI9WhLdBcx/5TgPq7s2/mCEuQNkYWK4Nr7CxxpQ
ED/5g6xFzVRJCmYOn4uWNP/MzR3HtD+n06GXaQAHoBVn7k6AtJo7FzVNlHnX
FjWRt0VLFq30vnn6BZqpIo4OmvmA9zZPMegpxdgLKH2YF1JzR4OOjkTXmRsW
TgF0ynHAWipjo196XofcDXbIDWmHv9CvDGsm6soLpf1nbkSkua5Iosrd6MqS
WLbibJDpGxaxgZFoC5+5RzeRxxJ8+jn6xHABW3jYJpYm6hvvoQwYZQShXKK/
CZsLnyRjSpIUI8kfjsvLDGBKJnvGdauI0pzYqrjkGu6EbBbGvkHVDYvcEXFJ
wh3+gq3EP2TWDOf4lz0dnBFR53uipRDuTJSeXeLs6yBKq0tRc60QSUK/fYLU
iDpTXC2CzxN2pWFXqSfW1R+ujk1TE7IPtaGhzyYGV3P3YTQEDpnNRYVru6LO
VXVYhlMDJoGKIDrJhmrMNkCa1Cl34cipKH71uaKLEewmqktkY6ZD/3/M8Nkh
itXnRJ+tFZ3rQM+zfbh1t3Ip0oXoWigErLf76IjGiugcUuCnDH4OnKIL2Uwh
U8jn41E7Fzci17QkBXDYi9tKcaR5iDseXUvxH/gY4EcvxFJhlUfwWADwFGHA
/7AppJQ034dGw+LO3YmiiqB85hpxuPN//fNf/+Nf/1wwnBTdxqWa4s5TXDUV
vNyDb6M/V1Tuag0ElEN8HkFLtlILV3IXfxj0M1F1NV1JAZy9bLtRlyKwBywB
FQBYZC+VkBXmhsNdiBM7Spsz0RT16EKeUFDx89Jcilw9xfVS3J2CX9shQjRT
0Vfv4NkAnUuCxgHOlB1BiixFKaWlVgziH6ZlOIae0vau5DPXdoAijeZw2Ly8
bA65YbV7OWpevrF4UK6ZhgXKhRso9oJaFq7qiD6KlL36IFB2KNiyRF2KykKZ
2KDwdWKPbZgbh+h/aLZ+iJQ9EWwOTVEVUQfxYykzWC+ysg/ZfqfLX/Wa7WoI
oaGIc68TmThgRslE5UYWGDBGFMeuI6pRJjPniqGRmZiy4BNFI/HT3VMWxBLn
3LULw9nohK8bqgqTvQ/LjmjP66ohLoC4ErX5ho4xnQJmyH34cEc+iLooRwWE
xrr7Yw6gJAR1CK8u6EFuKM0tQ1rsw6XZ6150q1wf2UUy1FPsPRXpyiGi9geh
5De9r1Kisq+vKuhTSwQhqO7rqaZYaKyC1uXqqLh21nYw2pvzqJCmQFMzV/1j
IrkpYHIXBnKkM/m6BBOM2zX5UmijfKZQfLt+3xchE56afccwM8BbvE0AL8QQ
XsN69YxpMJ9HF0M2MGq0cmeuTjhsfsq6Eq0ZcbbG3Gq1SoFQIWjizaBBSidO
2nQnKlg7SJF0PlPOChWhnB3vYIfIjaO4jSOY4cuxoo99zMaAGbOUfIOM/sMz
aQNy5iblmWDRN7cp34qJPj/joY1nfhwgL28R0/gZNAZj/TCNPQsW7eV3WcgU
px9IqehgPejRruiy+Ixfsgce9epG3Rh62xJGBk6xuaWr6rDOJyrBLaBFUL3C
N6K0gHeKCJtCGB7dFRJzTjT4VKVNYXNke+D3cKW0JKgs04DDgEigQH9X5L/t
boG2c5Atcj1kYjoP8KJ5c9tgnwrFfLkcN8rmZXdY/S8ZJ3GXcoroig32i2sZ
Jv4nTX+nd/CPG2p0F5hsPiXDxo3p/u2oP3Tc7mmgWpmp+IoSNqG7bR523RPU
ebCl9MkChg/CRnXWuOdwNU0VYnGm6My/d+a9re6WHEKZGxLT2UuN7A+nhgSa
S5QkRKC5VMAAkQgHJuic0xXQU0QznQ31KBia4iAIlEiW0xAdESUKWElctdfg
hs1bfnjZ/9OEycYQZstR5ZxQySdbETuN/wQ7h9q/A83YCXwLzeyfRDOOmu3O
sMpTjuGr3aiK+XjpEVY22Vx09cfqGzB8LXGpGCpxLDstIbppm0guarW0KC8V
24CdtZ2mo1lOZzNeW67XvDablQ4roJst0GDN7FIku0sSb2kpP1/QhIknFLmq
O4ONxcdTL2+uc/zqKbvm1+v8n6Re7gOo9/GC6WcR0ioCG5r5Mv+UtVbfR8im
PCMqcAs/3AB9NDtKzwHRDCfic0Ves10bqaXsW6HhoScYN/HQsDc4apw82zk8
8PnTTOKfpMKSn65K88MD9wfHeYM7NOidNdgmuJRwqk0DzHvolpMN/S8O7DYd
IjmcqKrAQ+KMACUmsPV2XKTMzxm6ln2e8StrveTn5Ur5zw99ZwE11wr6EmZc
j9hzrl5FoUoXiGQZAAx2n8oUWIGbwPZORl8jkAYQhQZ1D3XOJCBOLNC6IFs2
YZqgUiB4TPADyGKtpSVv5kyQyDkp9+fJko+S5dKQCQJwYOoBfxWdwTZd+nMD
hoz4iQowjYx/TpWZa7HFsjIsVYbpUhwqmT9lisXi8SkykLFCoqkGuspNS1kq
KgF+Ijb8pk1/FuFypaLGz3OlFUiT5XMiwuG5De/rHUUF6DwTjbsyhHoRPfWj
6K+MxvDpFmqnOpIQHVQK0KaKB0GKhDLd6zkiXAXYrekxO0r0OqANoIBBqBBn
Sq1CfJDW7BlQRXTS6xy5XreerltnFxIRSVHNjy9n97pmNx7S795bUlr2YR5F
IDtvwdpXd0Sp/5IbVHlUQtIceUmHSdeQuWRF5nQDFhao64i8Jb5KAkmLDIdt
PfUepkQuIZf46KQZrocZ5Kn4vOTzOZC1Vt6z8/YSxAf4ihgz4wAh2gZO9+Lz
vxtFZsZhapSepiu+kLM03pzPv4caxFhGyQEjUUGa8GDOLBXLcUV1D0EkYjlg
p+E5r82tiEUYZVAI/ygqvMbrMFXMwtTkZ5X8DP6lVb6LKtpBqmiKrvzbkQSR
ijHMKs8amLlPYOZmpeJ30MNypCg9QGDCKuUlVcFz8T3kCAx5ZsmC7fLsGkia
H06VKGqHiVJ4tiR+WS7leW29XH8fUXhZPCBM/pRfpsFc14buq6kwYYo/mjAm
boUKKxCz03khZj8USxhHcn8EZUZX9dHVzX8JWWaz8jOvTedzsJ8s6f1k8beG
+X1bwx/HJtlCQoIk8zgUtDLwyBpW0NPM/HN75sKBPfMPYpQfS5jZfLXkl5aZ
5bOVUiExYboNvm4ptoLH2VfdlJBJCUK+kM6VSpVsppzKlcqFHA00CT7cd1JC
jVU8/aBfoI0bsWHrhma6uKv6zLXwnAusWl1UN/ipMT14VnIJGyifZoU3z0vq
9TofMqTTNGBB5W2TSLwi8xLF7N3mbPRNzwAbUZyK0RejFOxyLXxokSngHqJg
ppIe9lPZjFBK0emGt/ygGiUa8IRIz54nrgMMNKPn4BjA5pAZ7p5gd2Tt8T7o
yGv7D5UOEAn9wa5NdGVNjX/coIG1APZjWnSkbCFt4qmex9fpFVH0uaHKhylV
Fy2YLZ27C3/5Djp2Dd39//4vrqeAyoZ9RvTlA4wf9tsN+JcJ649E33ZEPFrn
RrY0N6YwkNlOY9ECygznZAoD25mjuaGJNnCdbcP4dlBVwHogKjcwFOfFpiEk
dVhQpNZvRWeq1x0Nmn+xuUuywrN/jayo1T6kSxKmCY0KbMVdiBtg1wfDtVCc
NGicgc1dRcyMynuEgaQaruwvebBwFAw4oLM3UY1ZGtulgcfg/zXFsQhv8zpZ
8VMfN972UOMBNZ5MzCmvImr8BlDjRYVnIRA2b+gx84w4eIOEpV31sICPKD14
9HcougtLI7zuopQLqOXva70WnOdXCzXccRkGB6UHWZqOnNIExm7zgLMym4M+
DR9JbykibbFlq4qPhEweFAve1O8XZ2zCQXKFd/DRWEmOBWiGPqiphMg7Tqe9
nwDzWoSgTHUwoHB7xnwbcjmgA8oPuf3P//3/5SqpzGHxG9FKwg4jfu+pP6iL
bEWoVMZ7RzGmgxi/GsR4ZxBjYzrGQYwrGYwECOM/DvD/HvEdRPkdHR0pfhib
F2bBN1JTJhl49ITwBEcQZoz3fcVn8rsfooEX+aL45heVt74QMv4XQMAXhstU
lGA3dJRKpY6OeJ7nxIlNz4aOjkYglGjEKycqmo0WimkZ6DjgnCBEVSaOqKiU
gf7+9+iB+T/+cQrPdo6W2cPo+eruh/TQbs+H2X0fwkMaL0S5AhBqK07HnYSE
TmDscJ/Q2rGPudUcxHYwFup/Fhmbb8cVOEhgYHNjxZHdGGluSscNC8VEaikS
OYVGoNROTvDgwwCNbM7BPkFguJ+07ZMTf/soE1vBNa+J0lzRCVoHFkFf7yln
K9jpVtTsnhvMqF9dBVws8uxSKEAlT+cAKf7+9zjRigR8PRJRBhVzcuKChkQ8
RWsDCKCtugYCnpykOGQEWMFgVNoYf85NwD6FjicbOhp/bUPf++Jd2KQx88Wb
wH2r3JtGBCiiVwK58gBEaj7C90B7hEB4Y0q1FLTjmM0GoDzj0DEwgqtvGbe4
uT/lYBMPwqpqYswynwVJB1KI6Dah2gXgWobsSgpzxZ7iMSm8DH4ighZwBlmx
v+fiEohBCJ59LXRjpaLfOEQXlSyBsRDJBUE7B3Y+Ka7uWmA6OSrAQ3ONUIqe
nDgrI7jesL0ZYeiExgNFrkTgQ2RlfArCmsebD9Gn3rflU7osdPrcDr3IM/xf
NSmmchyVzPYcxiHORPTX08FMLENEyr3mHnpIQU9HVZWjNgLtiVo0sEegDmfv
wgadXNP0BX+ItRgDmaJJW9MTQZtRRvLJxRGF3gFhM7i9d4HHihOCCIAVCvYw
II5zuf2AdbJlKoYcgPe6w/hQgMABg2FjemyJmMIa0FwdZcgHMU2Kq4k2QbJz
aN+hUUHPMaAFPTlFFojuESmyr0ke4jvml5dPKdogrFc6PWfVYFKot8o0bGf/
zY8UbFYpHsFaiV1tpx5Pa8AT1GJ9L7KgUnYPPrYHXUicHqiQv9DdM3zKOght
jFOwS6BHYRp0JHOwC7GoKpJgsjDQEvhiKaou7oIAQQUmnvXhaTNNkWWVHB39
SrfmOE/UWgOYU8XCkza2c2HsugalgZodmAdDLOlNgu1yoIsoTdeovzL2yFIm
w/APDhcGzru/HAI+x5nHoy/R4VTiORUNG931NltNBNH/9VeuGWA03GLkCRBu
CF26NlPT7GxsQlRQVd6Q2Nmat3yooHTtPQOiGL8xKLok6KmcpUE7QNJCDIe+
NQm8M/E5+8tldzjC7vBsE1QccSxFsv/bJ98a1JdySldsJzUzlmmcZt77JC0t
bfsYGJkKRXqbS/HOB8EqxwNT4GWbHphHDswYOikQoS1gfPSzAGOw3ekp14HB
OBPUL9wKNnG+DEXJM6SjQIoIOVgv0OcuZaD7DcGNNUqH7fCRYL7MANUJT/By
kcUCGRBlyrZHR99Yd9+4gE7fuEt6xws77e90tv8dnZhvR9+AlSP/A+C+5IeW
vmkMfwrwP55j74Xoqyz7H7wCzQB/Y9Sp95j3Hpe2j4XQ40L0seA9zm8fl4Ov
UYV8gzUtK64Wgv73z2yr8rdfooNLs9GjIN2NN/kkLkTGjMdhbvzlH3Rp7BNV
R4cskO2aEH0LChUR6DRYjTC/VAS+UAnyXjTQfgSGFFX7FBhuBrxOJRzMHjAw
VVTwrw1VYbh8vCgX4FWT2pR48ItHDxZyDgxeN5wU17IMDTD0d+0cqie84ggC
gOl3T5BgQIFMJMVmdqjkGJbtLxYJEFdk6hTyopY0MGpFWHIa8Lyh7Xluh7Hc
jyG1FnBU7FuKbVSr4mNxiUfFuEIBULzt9qdV6tS1KJV9ocoEZuBiPKpyJ8yI
pfrJ2pwwdY9o+d+E+YLOvO+DlAIfJLznaXf7g6E8RYqU2DU84f93yRFxf34E
DSKPPI2xz7Y+OmxzhxbGa9OZORSZ+Acet9iJF4dAAhvPNwwjp8uB3YdY+loN
NR11R0iv3BHLHXcE0Os9tsVn0PF7vdIIAEPzMJDM27kgx9Np2N17hg3uGHDh
2LRYkNlXIA+bP8hhfnjUDsz9QVYR2Ez+o23T32OkoMj9FUQJL1l47djm/oEq
Cd/jay7QTi28o2y90jLwrYeEf+YBffuqY+9d1lPu9VVQxqevb3ByDP6uw4Dz
tc1HdfDK+/DhPeydJ6+f/KF+uD3kzdJGTGvvb0SvRfm+qH0gct8PYh+nRWwM
GPsCva6uvPkrF7rWDisS9rtbmNSif2vMO1E+b5Hre6clFD/zw7sgxvIn9KH9
8D4sR/oZffCymGSR7J7T07aeqRnT9pWsT746Xsn25CBeeTb/NIzvweMLi1XM
Zpf8ejV94os5Sdtuy/5UrE4U6DFFrXyCOx8fg1Mueif9NEZOhLDVKmaFz83X
Jp9/Kj59ELZRoAxb4SOwNU0pz09nhSK/zlVKH4RtFChiW05lPwLb4lO+xMN0
AWdLs+IHYRsFyrD9ENrmS4UCb82LEl+s5D+KE6JAPxDb4rT8zJfL2pKXykvr
o2gbAXpMhWflI7B9fn7O8UUJZq5Yzi8/CNsoUIZt4SOwXa+tIr/KFrJ8fjZb
fxC2UaAfiO1Us9b89Ol5xedKM/ODsI0CPaaq8GOwrRRX/NPTtMyvzVXuh2Fb
SBU/BNtnAJxbSThp+cpHYRsBitjmU/kP0WXWzOJzeUnip9Ks/FG6LAKUYfsh
2mH1PK3wT1NN46fF8kfJhCjQD8H2wPYl5xmXJep+ncBeWxF17myjivpCiWuY
D+1yd1EJYfk+rIIwyu/ZDxbeYeNuvaqhw4kEvlTmSfMcADDQT5bhzub4EabH
oCl6qPPYsGTmmfZc5Oil4HnmQWCnAZwG+0P/9OyEegNNi6gKMIRobajPdr/L
Fp1WV95BydE7HLjO1teGvlEWvu4PRQzFBL7hDGV08h8repyHjx0oekcaXvYO
+iwS3umnArE/o6Pl0kjBxNV2u4VnN3hSAh1+46qB9xTnX8AGdRrS+5//6/9p
U5i6geEA1IXOfZnQiRL2Lsb353pIOxYheKlHT3sAj2n32Z3uw+Pfg0b2o9HI
MjRyiAbLSEfWeBMKGC/S8X619Cc6zrGO8ykqKyzgRTp+FqFEfe2R/vMf3X+e
9V+g9Dc0eMiIDjz8a5ay9a+5KAqFj0ahcOyd3RxGAWXXl4OezL0I7cbTaoSg
f9PGCMQJ617DkzNFVO008y+heynl37jjRRrkDsot7G035enxX7kvgW92mUnB
jmiLAIab2brNKw46l4ozisrKpOF7wNtp11QNUbYxArKQFrLpO4LDtfgqHqXj
3VQMehxhW75+ddnqNpqXo271otj2eoau6/VIuN6w237P+I//AotKNujFEpAV
T3gN9kuM1NkLc4caaV8C0VAv05CQNNsDddeU6R1clJRbcKKS0uATCo/CkXiQ
roZrSSSN9ygxpAYQxFggGgDqB0XxKyQQPUY53jLj/q3jn2DG4rF3vriPGU9h
MZxuORL0RWzIHNWhHqL7d+R/AlHcjYdU8CtZb5++OsVAxP1gpO3hGarH//7f
/ztGJfhRacFxDDyAgcP/K3pwLgi/MGyEhtNMjGVIzx3t0XO07WHd5tpeAPLR
q2AqDJ4KoavL3qEnoqcpjjLbakJsHzroCVDdOdlJcVcuqlJY5hgUQ2DlszgI
xQELYnNEb1qR7Uk/ns3CsiQYk+GARTILxw/xMKgp6H/ukwofqFzuOBg+G1Tc
sEXVwMi7EZ7Y4+XsCcZ/gGgADpeP2AFc6Eq+H5aAaQ7oE9BKGoDEczN2C8dP
fyBuL1ceTdl5rqxMaUCCsw34G7JgKK8p9O8N3HYtEhAEJJYOQsI+AirgAY4f
NmhTJZWiLHN0RMNjbBNT2k5AaeIkqIZNWChdNFLiDSsHgz/pZTdmn7w+/lFs
24V38J0XzLUkumxYlDoYUsmOsFjrfac7oSg2dlrZM2SwEWGmruhBo7+CegHz
suiW6CnzswtzxE0xPBFZZErDneSoIYiDQkjQ45b6cWPfs24mG87G9bvBU3B9
hm+Rq6DLryAjHPErh7cvQJL6sR/EM5+Y85VOEufJUeT8Fo0A5L6IsxkGDDjk
4+RRAPLYv0dvUwnhxTXI4bUr7xvrwfN6mDWaC0VFbYWZY1ggFhujq3u/Ut4E
TlmQo48EjVnwrfQ98QiUB+gVeGrwhZVlOPo4KuT3B1BT7qSLj52JM32Bc4IS
VcSVEbps9YnF8HgRc8d7+3kdOw19BMGBMFIv/wAGwtGYNcolIBG8Ve/L720M
B+wLwMavUd3BzWGp0RA+T0cfgf19ZWJP2Ohg1B7ynLNtzOKPmLiKXEeg5POD
v5i68ib5PaSUDe/Wq4lCGiBEMwiJthe6quBX3MmJFzoJUt8izsmJvxxYvzTQ
EBBVKP6e5HgVLnGYATGIlYRCiNnOy5q5Gt0QruYbLtI/xSqIZKZR63sGAczX
f4PKoJD2tz1lF64wzA/HcnLijw5GFI6cfkv1AqKu/oSZR6cKkXE50AsbIP2p
YGSRfewBXudXsQEqKcyTQYXskEgpsNoFFn5/YP0yaQQf5r3PtvEv0GWNbAwU
DkgLFhpFUVOJuMDsLNDiK9qEzfOvuKr9tOmx00UDnUAwwqTjZU8aTy6avhJC
qmJCVMIWCjbCTLN+DhTcb4XwgKkmGLhpbphphCsbPktxfVV0kInCnEvTV7H4
PMNaoJlPrX4L1qq3R6cfYJgkLlwDlSWoCZBs8Dw8etnAFY2p17F/loL8lCZl
DGUpwmHe1pvnOCtAFQzDpUfh8AojBVeoq+gQQeebvKsrzy7xWJQhKXKjeo3z
7sNSHaqS4B4DS3hveqPctrMCiYpiHXZgw8Fl28edyH9FFPwN1Ol27rA/JMCn
Zv240Wlynp3PYewsYWCdjYlWvhrQn43HNqYOHYsXHkvtKpveApl7YZH+LaHb
3taa5GYuxmxeDXEKJWtjOsbMEk2wE3hVmVjIFBYgBeTBCxh0OwkqkgV1YTTm
aUDnr4Nm/2owGjeqo+pXljsJbcBtoD3riUVpSX4+Xpndc6S8qMxwvYQZhSVZ
4fybGix+HO9NWrDgndcT+VfK/ARmkEXuA9kUeZvqiqa/clEgODSbAkytr+0o
gYOOGA7Bjb8QZxNdpBGrIS6ktgMsC0JDuslaUoG6S2Yde6FYvp/LsJgNKLM4
eDa3wNQsNu3rRfP8E+OE46/htWgDUqrMhPkUQ2CxbAGghUJMhG2+iaFDEgsu
ZjFphJJ2Z5FKomszmslkitFMIDC9sZ2CjWsg9bE5XYc83h7hGoNam93eOMVG
TEFueQ2+9knP4tlFjJLC+zBRKfDFszELfDEL/xf1AoiazLL56Gl/f2unWVSd
wwdO6okLWDloRGkyb0/4UqZQoNn8j/3NGDXyDR0XIMH0TS7aojAtFrsSCSIM
rF4moT9zsCNhRSlQVDyChij4NqBBDSOkNwByLbTFbXfq0UsNloO3IpnkIBa1
o74OGsNms/GVqk3bkxSU2S3oTN1QFhepJW279LKRt7MJFDlyPnXdUgUFsFEA
e9wDmPLDPk/ZH1UYFSk0W9sUo1F9+y1wNby+y84Uokw0WCSORdOJsE2MDDs8
ng1MR78RMJWrmWwvjIuGJsRlYeuerUZdqOweyV+3/OCHG9FIORjiHEXfFTwb
Di/+YnNfeR5XGO0JZpbIf7NkyXS/cp++eB9xOdhzZLju5XBUvbhIafJe49uA
j21bDf5LHVXeD55CSG8hHB/7+x4cCayA7TQB7eDvQfUS/qYyuo8URcRg1kwX
BLOiwmKmpAISB9tdNNHFmW+CgKlJuQCMG5lJYE9e0JkCJiT0JoSv63wFF1qZ
zMK+MFb8Bd0h92D37G2LkNzMi+cZG0ctzLlFuGysMRFaEqNmkxdnOhgOwBz+
zPF0K37kXyKk4bEYly9yMMfsJccuUO1Y0VTGaKJpe24N7xIicivID+r5N2hQ
rH/THMTFNgcjCv+wbt7xu9BofBhfCkZH2At2w5P7FgLyzn++RXp6XxPont/z
D7f/cdw/39UEuj856fvXEXvMC3GCJ28wbp4qBNUnZ2ByHBq9N/KgGVIjthHr
vl4PbDbo2YNV799wnTvuPyj9gQ9dgPcfO9kKpmjKWC4VueEmTGylcRI+MQPi
eGt4/Qc36MG75q3vcwF7g+Fx7RpUAdOsaAwTJAN33YyZbuiIS1OLIIzbp9te
qMv9o47aR/7IQ9Cpq5lrUIuT+zRqHL/JTFhQwKEh+oDPrgEW35TidEkceqHe
xs2MTwEfZmC2/QeVJ76t5pl8QKfD6MQ3RWTZFzvodIa99KgfIc03dn+X7CzW
vcR4/6e0N2oRV8+/hrr7FvHmowSFwSBHeJzSZOfbO/2i6Z++BcuKKl9/6/Im
8X2LPNL/nSfC07jHpdTapuXdC/V7mmy7vxiF+/8GCoK6+WH5Yku8BPIGSb+n
SchTvqOGfGHvXd3z9rqvxT1IkB25jo7zkXchxj9KQqN2pfsuiAA2A8q2fjbb
+wV+wQjQI+o/pIvS2wb6FzyiuipiHIbN76iiYxfBfC2WDk/NN27g6nZaVTAR
JvUv/76Xb7jRxnwlXvZ/OQhMLdoTM3oPqp/3KpP365xDX1IUUCg067j7jCLd
ZQJCD4ulVyO7jHkb+fBqmPYlj2d3Mfb7tt0M7+8/XpJ+49pUeAUm6XehUD33
v4mooW3TlqdN/KCadKBZcT7nCqxvS5rjkXTgAAkMdL+THtjh1oYHCLjt9mXa
Ny6kgf3uOp5pmQ60GOxvRLzEvjumoCUMJ33eaHFbskb259sWdYv4PgRGuqFP
um8czfzsb5Fj/sE4ivBtg8AE9rIfUFkTFi0XweLbybaFq3q/lweFSB82czDl
2l7KoZvOZvd0vTe7vPIXTEnag6V+9CvXoBkxsDZi5Oylwc5lUEaOFA1PPQg7
DWRhBtVtAgHm1gSqVf2t5C07ZkFJ0qTeSEpAEr6yA6/wZE3RFYrS9kSI+CdC
9GTJ8I5sAEKmxF1JsBPB3TPjzSgKiEHwsZCHcUmhj8PlvDw3yxesfbjdVsWn
jYUpsNPF2eR5nbl/KN89WJ1cb51fXpX1LO+ezx7SeMLMUtPSXossNs2jFp6X
ubpE8Qzt+ckk5feIncFvmucok82WhCJs6/PpSEKr7U2vlGWztEgOIewkHV0o
0gawCFMhW+JaZBLCJwhC2F4dfn1qxn05OQmuAP+N63TbHawBwzI0HJ+c/DeE
7OXZD8O+be47Q9v2FAe34MMtvoJL6xiEwODNgr03pb4T/pctH0WnJyZzLqbK
EG1ipx1xxkIQ8K4HjewQ6BQEmRjpUQdttI8478C4QvNCfS++M+MwroWUwM8M
IZUtQmevkJ4Z34mwkHmFcf2VJfR9sSJ4iVilJydfYgpGvCu2Zxd22nRVNV2g
IalCaXcEt9ve9gyGeme/c0R+QgzkzWxMt4lO/OgpIc4oSxyFl/Vxxe5AfxUc
9Uoo7LkmGMMAeX+NvWLZt8VO9vX6rQ+6o269euHBr8DK8hjMr66QqIfcn+wh
ObWyr8j1qkN2W9GnW/51r8GSfNXb6yuJ75iaUMLfZJ3QC4k/sgN2HfHH9qD9
4B7YVcQ/30MgE15nNoFdoqdN0BZ7R9YcjFn/M73NjI/rKZZy7ILlO4hX/DOd
sKuY0V56zUb3puf1U0zlYvvZsXL8e5rbXt8rYsrvBZ/9QPBv2lL+hc+f0M07
xOMb3eyZ8596aVSovEIrHq+fdD10D16xaP2ke6BJ0fpJFz6TovWTbnYmptbP
ucKZFK2fdFczKVo/6VJmUrR+0u3LxGj9nGuWidH6Ofcpk6L1ky5OJkXrJ92Q
PIBW8u0TuxKZ3W9TJgeXjwP39vYx/4aDKdj8Fr6zg8LrDnpXjeagOmq+Mk33
drL1KQce3Wg0fdivGvboijuuXPQv46Gr4meF8zL+6ezaBMvxR1N6ivpmG+my
4VZz0bENxN9LiRqOwIzEhdKw5K93RFxgIfWvp+zvRucrDZ76WhPlJvOvfE2d
nOBp1obDfLQRzzo9jDNsjHNMkdSpB3NIb11QqHRw3gMAzcaqqrClMWT/3M/2
08iJ3AyTl9OY1uaNVzz1qIkVUImoY6VzQ/+LzX2hL7aLZ2+11LmhEVOckWMa
9xzNPRSe/9cuTDoG35/GLpMEc8OSNUamlDnw8bAOA1T9xJcstH03Y/rBDOnc
heLgCQPwxTYF1xIWjndRFrghJnFm0nyZ9HgxetLAdj1Bfq8vfm/vhnkg4eSX
lWLBSjBpKFDI6x56mp7COrGDR3hhjh3hIEafvtAAk2iMHoYyqcy3593Pg6dp
F0VmICV5iWDAUzrs9U/ThkEUHx9+xwIChQyfLfOZjOAF8yG7fqn2Gh8RI5jL
5DMB2G3HSDp6T/MSLz5Qmo2azR16OYSEaUWv0+1QahdIozEwQtaLLOPKoM5Z
XB70538lrYt8pswLwo+jdfmdtG7cy8Yq5AuX1ZQoafQsSDaUdFCZplgoF/P5
VK5YyWRzGXqX8SeSK4+smQmzJl6+LtCgihUbydARVeKGpMBaEnn/4oJnYCgG
Xt7Ez/z/jlmJlmzRZ4ZtdGwhX8hUosOLq+/tNWAZGmj2Ny+fKyJXA8WzaFWH
o7fQm+CHUyydGfw1NsSFCtyxD8eiUCllk+CIDY5pDoldDEV5UO1tQU1E2RI1
XCveX9j3tw/kUMGLGMZb3LmfSC4hKbkEimJlB8WWOAHpvyDyWyhO/Q+3f8Uz
nZB5B4bwMNRgL4b7olGjkOMrjGTKWaEilLPjHUAIZxw9lRtjSuNtkRF4idVE
/ApT49HF8JiLzV3JUiKzrG0Hsq7G5qbbpmxOBiP7fTDel/4xBHBrGO9aSuzO
yp5krpFwCSmwlNTAUvIDuaQtxCA4DC84bw05Vkng5ATxAluWXtDZ42iXvaqW
/l1ahYXBa7Q3mtabdUWCmo4WhqgE9yn24ktjj9jtc7w1HFQmCKVmXhG8FezA
0HRWqTdSB4Gaw1jsgxr9R0fefZdXt+HQzlW3qG1Dz0zD8e3NpKlePm3xZYmH
WVGCIEUv28ocf34rcfm+lORHh9ORf9omTqf3Q5ZENfBOJLvkX2GJdiL5y48w
DVs0E/nRTs7yt8BGUpYXuFfpyivcpwIXC2EnjXkpwvfNtckCcxJPQgzlOW8N
eHUvQtlz8PKGolF2BvqzbcQpZeepgvc1RNu74eRlwh/5icehGezPwn1SBgwd
g3ej8ZRHR1U7fI0j9qIfxf+NmhG0woHo1RDZsvEuuV6lSbBI6LouTfO8zWrx
sYksPu8T5Wxkr/eTb4VrIJ7JcqTsqzROcfregIGjo+6U2xguS8jOLlNNqWeB
SefY+6g7l3pMGunCYSps1+Zw58zZBhOpK3bpTZoTaeGVOHmdg+BVCgKF3ViB
x97l76p3WJrusXQSwHGvWHKUiHVoGeNQNIsYqdNzcuIfz+Lt3FCdlJMTPIk9
OdlPGcaB/9Z5Xz7/lGAepGaYhpQsvi/uf/7bq2Q88SVJt4yeJFzu9CNX7F9h
OJoyo8KOFeiKOZFnxblgjKDscOSBb9iLIQAChAPCsqlMvFuYNdtSIXkMymmU
o1l6GQ8pf1jxg6LjUCzWZGbsjiEHat0PansrNG7PQN4V5/IBg4hqtb5/jXAY
zhBnH1X3a6Pg1mEkoRxzZcbKyxO8o3eyo60Q0/czKJUsb2QxqsBnnL3RJlgq
YF9CoL++J5CN1aWjoWxI5KlDAvfzKxQOJYYIoYHj+URVKI+XLk2i89SVeezZ
y6KfymJP/qJPhqXM0HRBXYHGM5pQfCbPXMr0crfNriIDLflM8fgIazFirSJW
leSuTRM0KJJiYn0100CPi8wZeLHS01mYxYZpqgnovSQSw89dIlIbns3mroyi
gLeZVkJf0mwmEacyz+6av2pFDwJy9MonsZAo0jQFAKi72LAsWDoiioBj1ow6
q1nQYnCnF6fKnm5SlDq0tEuUMLZ/GZjVyfIriuxNDYQX/bEQouK4wfV0C6uh
ehfYMQ+El/XGL2Uz92ut4daFnUPE13yJFryinMdwr9JrfgyQBdNHL3ezgjbi
NnsJG/TJiaywS8/AxX7aBZZyBWycA6lIfNqx7k5Obg6UOsROFMcm6jRchgfv
fhNLD1bJTu3Mt1Yn7RMVH7Xgw1OuRAuw0Q/3V2GMRwykn586id7ztTHPTKOz
kxbl09fZevP1mN1lgA1m9O2EOCu0kKRtCiOWZwoT03QC8een3MJ7EZ++zh1b
8iHSnfj24gTWzQxaaTigGbGPcimuuk3gtQNNjIUWSvyF9WfFo6M+W+qYHcZL
hBJ/dxlhevVK6T4oqBHaZxNCa4TW8S6Xyrpp4xI83p7iBMuS+wem3fJP4+jF
Ji/fk4g3QUZDvyK55V8RR2Zm+TUO+0NSND9QGAEYTZBjAk+vcFKHbNqG3qS2
hWOcoZhWoZye23kceZQ/R8q3s8c4M++DEZ6/KJTc8b45ySWakx6K3gGrNYqq
sRrOYrWvcpVXMzR6BW9P8aDYXHCvFPhOqiB+NyPpnKimHaSmYxeOBB8//B4v
4wQJt7bZX/e1y4bbdVnaoZg8eF6uu7eSudH8dtu8I9sERaEUDPTwsO9Lo9h/
vm2TsnG/CqfZ0/xpMfowd1o4Ra9N//Wo0aHymefje4h05n3t/xH8FwC1Be5z
HKtSKQct/vP/+T88YP/5f/9v0T8QSvYNKAtpvgOF/RWFknsTylfuABTvj8i1
WAxHZrxPL6XtrKVSSqD87iVqKLx3YVHpGWS9omUlPf9VsNDiMxaH8hRv2/oF
gfcfFsclM/5hiYzTxz8UumrMUs7aeX+65B+WKjk80B8APTLQ/QmZf1gy5vDQ
fgD0yNBiUz7/sHTP4RH+AOiREb6VVPqHJZQOD/IHQI8M8s201T8qUXF4kD8A
emSQ70qH/MMyHYdH+gOgR0ZaToWtCOjWr7T6cf36ENmwfiD80MD2HB+FdP2v
1O8duJ5gcltMEdusrumBl1TN471r3zECJuQdLQRNbcUYXya1D0+DXFpf6P6Y
jzqA1qYYOrXATRfm0lgQa3uhWzak9KGm6eNTlhlvx3INmbuR8u+2O5vR0qJ0
2w+bfNyIzjcTS/GT1+LW65MUXQSxRrCf2XLv6+P3pkP1Drr2bf1ZOksZveL7
d+5vZwEN2+iY4FrfbHf4E6KTqRI9rP6vnlRakd2rAhw9YTo52ZYu9nYV6FPH
2Xw1jWHGoF+8NSw/S7bXCLln97BysqH+lJCP0jtPZ1kp/Uzmp9Fcczte3w/g
iVdF7OkWOuKApERkQb/o56QZIGVGiPcgwGfyERzeRNfzPzHPnT9J8MOwiBbE
KUQ9t9Sll3qn+LmonjeZ+BkqGiZ+wCHByDH/vATd0S/3k5z7osKE85b4bq7E
R7zXKH38XhRxC0IxfNvdzoUigw959PGcXdQX1LfKOMq/HU6ndXtv/G3fPPLy
ABjZ2TleYLHUJxR46MTTxpyxG07GdNOW4dqn3sEUoInsH0Q4n3qBL6HwlLky
m9MsNhgpIIeip78naIf7xBIz70Q4/+Mfxyznn0VogiXManpy0gGudCYYdwQi
YQXC6eQEozTwHOjkJMXqH7SVpZdSGfFkhbffLBZ9imfRoCxoJnL5yPOWk1BE
B7txCysSHe/4+w2B3LsZjo5ca8aCZfCIOF7sepn432JCmuknS//NzrT9l9u6
Sl5ISZpdEGChTjSo5pOXCMuPyAjVdcYjAkx55YU6xYwLRS6+p4cALGsZrkFQ
soFEsBR74WHb5cSZl2CboFuCZtx1TRTHdtgJHU7nXt3pza9m4VdEwGgul9ZI
oLDppiuIyvDTwWIqUarBglZemlrPKUaeXSrt6fHcDAtO6H78vpdqEpDd0IM9
YDlYm5FvmLxlVwhwaeDwgosZW6z8WvCn3qqmLdGaIJam0Ny7ti/mRZVF3wS5
4fE0SpdZBmLiZcE8DfoJAiUYOjR6CBM7S9usqBM6b5YClCAyM+/91hoR8XAE
pA6DjumAWMoMmsso8Bh6Oct8FoucgsDH9LhF8jSvnwUb4UxoUmCW5gzfEX9F
+r5X/5wgUu89mF7PGxtQwM9T7Od6TXHD4EgqerS+m4l4gmcNLIGUyEQYzZzK
sjp7M0pFC8giNn0i5cxtSt0tWnQk8Nrn6YBaLDSKTP38w162cJaJPeBLdv+H
GeIjw1DR94/pXl/VSwkMj2BxBBYILaXyxbdAtppOIYSWHbEwSRIhvqKjue3T
lTLomkLu2K+wsqM3twUOWN2xaE0NP3AmdDwHSLNzxy9TZY1Cn6UeZ1Uy/B9+
kv94//K74khY5zRBGa/IILAw63xom4SpC8U04HLMTvAM6jSHacNEzzTbG6s0
gJS2HBb/CDihVJwCjejyjVYmeMMp7i8DhJ2i9LE8a4cEx42r0MEOVqVBZgTC
IcNiJYy5l6qYVV4IDkcpWMo+uGpDWbFQL7m6d8S6zY7+7zcDHqnxEB+vskUX
1lYmeKn9X2NLZzBSXeA0kAehykD0dspra+oYq8qwozLG0x4XBAtIClQACjX8
2qSilWWs30k9HZkenGgAoPm1ZqS5oUjEK9+DeysVTJOQtAvk+J4x4qSdMusk
sEeiHLiieLLIS09BxM8jrNpLsPw+B4azn07t345D9q9Ran8x+aKDPdsfnrNA
kK3FmjpqveKNz0dH/wvV1sG0oHkupHKnkQUYwAhdlGsoIOEJ3yGqqgFrIl9x
3uXKKea/Q7VHVFTu8FxVFRPzU4M8XqKtGKQUZXrFK4fgZUvH63iEJrNHJHBj
6+qRDS5zEGOw+RKz2+HeYEckW7u5rNjZy7ZKJOWuPURC6X3H8ro7HhOBCtQV
Ztcz+u5pxnYer6VYcCbqHUyZ2yNurL6lMEMyEIacbNC15XswFDVIsQj4BCwa
LcYUzBIrtckSytveOfi2GgKlgo6bJCC4H14QfY2bFL/2DaDlsUIKb7NJqqho
LCJYE2XfgmSxrHSHMnOtIMk3qL/tWf5R6Fg/NozZIp6/BoOJ/ZIxO01DNVPY
YVz5VTEVTmO2mE15G2wEoplz0VZewoFIoTVMg2YjZXVo4QOwNmfsoJYKT5fJ
M6wyhBNlR9DVEV827q25Er0NOqDRR0fb19G4H68QBtZOClia+SD2EiuFB9T4
MS125sVphG7aYNvm8GrQrQ/pPWqK26+7l2ePguPM+FTzoZKv212Cf6hJF1KQ
3pfREANKJBKUf90tPseQ6QWV63w83kp5H4vH1grzjr0D8H6Is7dejqqRMmbv
oLcfOMXM1KopSmBoZmE7eAFiQbcJi5iAXaDI1VEMgnEbBKvoZLW9a4wb+M0E
GG9rl+L5PDYEvKfMSBe9LFiYCHNGfD+Gr7cPhHKj8YkBzVFTh2oK5rWwNKTQ
qys63kH0vntJWAX4wIUljAj51IYtmKgfc1/qkSHRAX+K3qo63qrAyPgpdVIy
SXtXz7zPeZr2mci8V+oG1BnRl4pl6PTGKZ/hy3w2fZwMiWwyJLI8DY3mRSXc
XR1T2NvkGG9ze10JQujwkF5e1GFjrMNjque9gFo7XcpnKzswzs/BiNvYwTYl
lLTVTK2Islb01PMzu1aRzgltdf1sFY1pZ6OONpZzabvi9S5W4pQAJ4JtPPRt
jz2gBk2nOezrs3uiDS0jM3/qPm7Wqx1QDQWsFWDYO8MCHRjKMxuLZbmYl1fd
+1ah+5DJP5eUWd6trWa7WII0JQpeyMBzFzA6vhPklxaYRzqo5G37qfeEXj2U
FTzHSBeEMvtaFe05SP9Q8L2EpXDonjM19d/Spk6aLpXQSqE+M55F2rJLPOli
ppCnQzsTTdEb2wBN5/+Ju8O6LlQ0Dg2JmcM0nhrMACPKLhY04FfwOQw39WRS
LkS3wO6aYLeZHXn9WzP3W1n4rdr8rVn+rZz/rVz8rVn4rVb/rSb81iz+Vs78
Vi3539ToH9nfymX/j6r3R81/VW3QP3K/VQv+H1XvD4TMvslhF9XWbzXotIRN
Kv6rShbRqNZ/q9S8TitBXzW6aGjpF7rdOCgURNNMYXkXvJaq0JGnd749DCeb
AE4W4dS7gzoWq/kSzTkhKZakplQ3Bs39DejjPfgm6yf7Pf3Q8bThEXYjT1Iz
HDiJG8L2IwYuymTvApd9LzjAzr8ExVzxIOMcdFnp1HiVsJiVZ/uyWnFobKvK
glraE3/viJ6oIJwcDAAZ70CJXH+A+vrL954U89Gby9/V/Bi3GVjqElNsb7er
tjuhd4t+YRaB5FkENCZtnzpN/cJ81nsMD1TB+60hehEKtwEDMlMwwDUqVKj/
jr1gUtS/M4+Tk86U0pl8OnyuwAfnCjZTvnzgTuYVm59YxoLo1L8GO1BeE0Fp
GngQqaB4zRZBEBZ3BWFNBUOwIzqXoF1HxmITEnsTfAWmOFW8Dr7bqklBqFSE
AgXmm0yqqM9cDFsGqB16GKUbYTU0D54xjRu+NbUSbR7r1KFJyDsGPyF0FCqW
NWcDhX2MDjO84RUHhqrjWSvdicMmZG7I0HpurHj4HxVBGHSLx/myFLlI6D2w
UxgcTdiFwpn/NCFCaUUWipVyQSgV87nflb8JmUymVCoWs7lsmRL5Szjne2CG
IJlDapT4JfQslu89jEL0WkSwZKkHiElsYKxLsnbaRMf9CqvLEOIw3DPCa3Th
EizqQ1/TUZuuaoMh5Z8VgU5d8VunE+gwfj/XRY7iAkcqxaUB/L7xhzmgijd8
QAkvfeb2rtYiHtusEdHh8RFC0G0fQ3KugF1JEz3BFAamH6PGsM6MoJ3a9tIK
H9LuJpZCpgcXlEWPFPcOkS4lFI78FLmQ7iQZ2WjPGYG7BlvScbXw4jFmdopm
dUKXCE5vyl2kwULwPuW7uoRTFJJWuO/l8YSJXxBi8jhWr/YcjHlzYE5sRhmv
nC7lUjwP5m06mcpMd2hLWlqUurDooh24sImhFnnAmhfiZId03hvYdqUsN41i
IF0o5Qv5Qsqcm1G7ng4XhEoUgv+U2mqxLKUQy4UfbKpVl4CoeGXKK3rozBvv
cusSSdnw35Skp5HF0yy7TokHscn2m8DKytSW1k6lUgDOElIyyzyCs4ZUyk+U
l+g5Oj7xdgRU99lpVxdBj6iqyMNcmCgDQLrKrqSIvEzUA7OyQ+TuCMi8ky/H
AfoGdFVsWyWygXewVYXXwcaF/yzoAp0Te+FuXN7diC9LRcNz1WVkgezQydZe
ZC0s9GwnRZ+xpZ8Wy1lDrVQyu/TFq2Vh4YRIsme0IUWTUTWdT4OgEzLZbEDN
EBxlSsJbBSVFH7BruemyezPdZPo97bnJJsGdzUQddPhOv/5jhjMM4RD7oDgw
VMKbigMGuuLrRVwG9HIR1YD4S1INF8i1MvgN7BlsPIjyVAg6pqdKFJ3DSfVN
/Aa+SAff0gCLkA94ryxjIVTYh20aihPOVmSbKn3CFNKa/sJEL5VsoSJUMwXg
6FqdL2SEAl+r5hp8TcjlS7VcoVEs033NF1Vcrrno5NFpw+epueuzcnpHqrI4
MoxTAi0HcpTHbBw8Xs47rAHYCIy5uyMq4AlbNWkhky+Ui4VKLj8WstlMJp8R
mNHRR08eXQ1sJw9W5mYHYfospViM2Q4pgajmB5FamRazWYHPFiWRL2UrOb5C
SIUvFAqlSU7KTMrT8s5yvFB6fe62f7ntXlU0c2kyy8Rfk1GDwFc6Xq0ThgpO
sydMQMOlZLLcUXr4iPKvnV50i33j8qW/pg1AKQBxQ1Skv1P0kERUUiDMKA7+
LAHteDzJiWpGxMFmaoNmUjmotz1jEd3itHfcPcBuYO8OwcZ7jKhY0r8/u8Ta
/C3Kz7Q92iaw10m4F6Ltfw3gU0gS4GSpYASHTcXQQzoj2XymXHpl3Ic1NUZd
8Hj4uE0khhc/dbSQRR3MN/jWCt4xI1F/AtEemGa73iF8SfNMYaGbV1Tng8Li
x+Gr7SGx6z2hdh2F4YUERNAGyxJlE0L1zv6ZLVMX3agPR2IPgBoMGCCz9ClA
J3hOfAhbDTd9l9+lWNoR4JIt61FDJoWPaBvm9Rnns7lSUahk05g2aGZYm7GQ
y1SKYP9uezdANTt0skNkCT30c8Xt41fG2EwyecxLY20opiPXWij2HDD1S72C
DaKENEjkMe1mLk4w7RymC1FAeERX0QEcFAmk4Iu4Uab8QlSVjWGxuREXk7CV
TX+y3VvI4lL0kNIBrQQ8SGvYBjMMO9e5IXGvVS57EXg7V2AZEN0G824KOpCC
A5sZd1xEB0lBgDAwDJQA9NSf/gaFO7MAjkgLXzNn7IzAPiBdrBQrQr5UYAug
20O/HmyFwjliNO8ZU3aesCM6LDspyApjAE8osNFjJwSBBTnYCquQJx3jrujR
XxA1tf1sG3wbyTFwyjwR2/ND/0jQMdj5Gia4ActIxFM+cRElICow6FIPTAc7
rbFvTXExPmREYyzeqz01npgvUZaU8qVKXigUcqVyrgisnynm+We+mmdzOTBk
S5kZXM0CIhlvYmNZE/rhGIwrJrP80BsmyqlXAJlGN3gkD2hmevmYYlEoZ0Gt
5orFIqBTyPL3mWqBYVHDmJq+BXu+3dSMe3CYwMegyujHfD5fEPJCdmwwpsVE
Sg41kA7ZXFts8pWSUM5W8rD3zecz/Gqq5Py9qWHZ6EYaAlGnJAYhsJhs+k2a
xbAHVE+D0Z32eIxtNDZ/sbnasHt0tP3ZIjJlsyuMY2KpEfZuvD/V8FjIFjWH
m/7rnxY3RMPamhOM+dTxZny4mc3OrRYshe4O93F10YJNB9dRVAersQNRNvTU
y+bAtFsQG4Mo2dke4HoKrVT5380J9JlFkNbr0WBxL0WCl+AtKBnIQhxl76Qh
JOa8UE78V6TkOB5h0yNnPN6GaQmtcz9S0K8weMQqKNISesSRUqfstA+jDmkG
uiDR0WTD1eteh4A3jZalZ2r78wqzaJpILIFi++f8xKtYur21iZna6vSAkPku
WPgagmYxucHjg+eeyCk0aZJJgqMHjJqgKa4THP/S6Ot0dzBqBSI0kqTCO0AN
vvLC4kM86qXno9dNJ5udDNB+Wosga4X3ITtfR6T9N2iEpViiDP/QNowH7XY/
bO/8M4SDF13sgVYsDmvOhoPtGAIiSwjhiR4k2p74kH1H1RE0/fQJLAqCRRkg
AwEGK+7TyQlZS6qLptjJSfR7DD7xgtJjTriPWXqrwIcXW7gRbxika6WW0Hga
W092uZs5n+U2dTM3EM3MPWmmQ87APwfoOCFSYvO2It+0DKd6/dLR5UU291yT
VrVRTrSTIRUHKClSuc4y0xTs6b293NQctVidPZSf+GGno6ySIRUHKClShYuz
olKxl4amz81Nv3PXJ0+90rSn3V8nQyoOUFKkbscPz+2bh9y0uRJbq9VmWq00
7LnZIU4mGVJxgJIiddYaSyut02lOrLPxXeG2uGkS5+5OV5R8MqTiACVFqj+u
P4w20ixz3i5Jk3PRbVX5xe3sPvtkJEMqDlBSpB7Pns7uzYfVY0Gv32ov47t8
67x4r7SaDwkpFQcoKVJ528hdrDtXV/edobDSl3PXIHd3M1LvLJIhFQcoKVLX
xTNNKpSXGUlQG7c596n7kKnej41pu5oMqThASZHS8z1SuO7Xl6v5Wmqe6fId
6W9gTyoZCXkqDlBSpCZk8HJ5uVz1lOliMD3rT9dEahsdc9RIKNHjACVASprC
r5vCQ0euCOrDk/JcHzmV2uPmtnHZIjdm791IvQkose5r1Y18rTdoDG82+vKy
Ur0+E53+k34vzhLqvhhASZFaTcYPdqX3KFfcitHL1hZ82VmWpsv7dkKk4gAl
RcpYlqd8SXo8Py8MHvme9iQVu/PbYY1vJRQJcYCSIpV1b1yxITQ2s6fLRi/f
Ho1562GyGilnCZGKA5QUKbOWq4iTS+Ha6uTH1VFv3CyVl+v+yF0nRCoOUGLd
tz6vr3sdwg+ryqDizq+uVNU6z2s31YRqJg5QUqRGwto1b2qr54dmbdipj+5n
w879oyM/v5STIRUHKClS88EqX2ytZtqtrFSmz49advp0PlH1cTehmokDlBSp
m3Zp0xwvVG0wXF9usp374vTFbRl64+n9wvNNQIlX39wkXVUmrWmzaFSeixeV
24WTyVTr5wkpFQcoKVIzKas8ZZYTg8yHY34pZPjhpa2uxcd6QnM4DlBi4XmV
16rT50Ln7NF0Go1La6jLpZeGfC8kZPQ4QEmRunfPpPGmedav97rug7TMXvVK
9w1jNqjfJEMqDlBie+q2o+qTVrc556X+Nem5jdur53XhYXmXcIsVBygpUuvb
m1y99Hxzpc8kxSzV8o9Xhd7Zzahyn1AhxwFKipQwq0v9FV+6NMzG4OWl9lLN
ya3uzMgNEhp5cYCSIuWURWPyUsuV8uqdcvFi3VpXg4fSov2wSTh9cYCSIqXl
bja14v3F9ctadCXy1Bwb5b6eF9xhNxlScYASy6nnzrM0mZwvxbHRbvJPzcaj
m83nZlM+oUKOA5R4i9UoX9eEu9sL3jEujWX7OjtaFBuaRpoJ1UwcoKRILe8v
s6YyfSy076W6sL5YDacXdf1Gat0kdJrFAUqKVK/dulf0SblwPxQvFs9PteZc
qz3WS30pIU/FAUqK1JNdue3m+7Xy5kGbz7JXE/GxJojZ7PQiIU/FAUqKVGbw
cjV4uR/fyupD4eZ63LvraetHVbeeEsqpOEBJkbrL9TpCDTZrE024u+mv29fK
XOxKwssooY0eByixPTUW2xtVa3WMC+35slSrSQ+3Roe3LhPvZmIAJUWqNHwY
urVy7lyzKs/1iXArtCp5vXKXyyW0EuIAJeap4d10ln24bFavnLPr0qM9FdZq
/oqvXiX0usQBSqyQtenlip+syue2fDZR87Z4Uam0XvIKkRIq5BhAib3DG2Xa
Lr/0C+LKsCbjoXA5qLSaN837u6Te4RhASZGqP6yWvVLhpWiNunK2mnt8XD6e
aZ31lZLQnooDlAApd6rBz2xl3Xq8L9TzxrC9MB+ry/vRuPRwcZe9ff/8vQ0p
Ka1cobN+uKtIZ9NbU8nVp5XnTJHMV+ZDO6H2iwOUFKlhe1zNZISiyJ/39Pvq
ou30btbG4lF7SsjqcYASHxmtSvzVXbZevbUy/HXtpVIi1d66NtZ7CVVyHKDE
G3d9M5HE6fI62+C785vp6DabLd9dty7nCffIcYCSImVpt5ekNXkS19mimhP0
gqk4ne766nqRUNHEAUqKVGM2P5PbuY096bfOe9ekLL288I7U7T0nlFRxgBJT
6vFClBQ5u9Kbjni2Gk6Ubnfq5EaZVkKeigOUFKnxolm7alzao7unmShPCmtd
fSoX5eVcSmhRxQFKitRzP3dfz/REq9Wq5oa9Sc28uztz1tX6ZUJGjwOUFKnF
4ul6ruQ3y7OxUl09WP2VIFmtOa/xCXkqDlDi/UxtIZ875y8jJ9+qCLemNT3v
6vJMG2UTGi9xgJIi1XHdcbXlCkJtZMnr81y3PNdW2acns5xw4x4HKLnbTFeM
9aI2Hl8/dpfzll7QxbviU/f+JaGdEAcoKVLKnV2vV9XywyNvXo2qJVu5vGnb
U1XpJKRUHKCkSPGddv9mUKgv3ds76ao6y5Wk4XplVEdaQkaPA5QUqQv94qFZ
mrSvr7T6+vb+uWg7ypVzvpKEhHIqDlBinhpPumfzK7mWfxJmGV16WfcfV617
p24kdcXGAEp85rDJP99en123B+UsP7EX1+ObdreoEFV4SHjmEAMosT11lrPH
Dy19Wulel0ujZVYSnvPTXHF9npDR4wAlDiy5O+89PAgPbaGZVYbjzuY6bzW0
K7vRThgXFAcosZVwLuiNIVlVJ7cX4xW5Mivlhf7wKM2KCRk9DlBiF8eT+5KZ
dp/KztODId1oyuPjvTRcrVqdhJSKA5R44/Cg3ObPHy+tbMYixetFW9vcDXNm
3yEJrYQ4QIlDcB5ma01QJk7RzMsXpXVLeLiU1cz90Ey4m4kDlBSp4sX57MrM
Zh8G6/boYcIrfG2t9NovvbuEvrw4QIlFgtGRzvvO/cW0dvNQfzQuBV2/KhKh
xSdk9DhAiWM4hptJp6LM9cuny9LwSZ7PH8b3znrecxJOXxygpEjJ43bZKl30
2k/VfKHWJ+vHlT3VtKpzllCixwFK7EvgX8RycfxwlrHNVe2+thrdXr+slKu6
ldCXFwcocWRCvtuTl/V1WR02z626ctZ9mpi1+sDKJzTy4gAltqeqV5VN68yY
qrfCqrFaSfN8QdaeF9omoY0eByixjZ65eO5Ma6J9ranFygNfeVTH+tPUbpYT
rr44QIlFwvyqrT5spPFGd7TlKANKYq3K6kpcJzwyigOU2EqYrC4qkqwWp0o/
s6y1Z9XhzU1DE/ubhEZeHKDE0S4OWXUmvfZ57frqvJG1n63ZyNLN+tUioS8h
DlBi/5TdfSoapdU0P78fu/WLgjCqj5b8qrVOKBLiACWW6EWp3Cj2a40Byazz
jerzfS/n5Jt9KZ9UoscAShzWZdUKudLZ3Mkumhe39aE1GiwckDClpIG6cYCS
IjXo6+cP05t6Y9wbrHJzvZrJvMyK5fymnXD1xQFKHMPR64wz9sXFTaFHFkZT
f7k7P9O7Z5o4TOhejAOUFKn2Wb2aE7RZlczVWas/cMebTlXIqOf9hKsvDlBS
pCpTPiuc9c6LttCXJWNS1PpGpmhdrrSEW6w4QEmRKj8/j9utUa4idJuT9uPj
9Y3z0Lu6vK/cJPQlxAFKHILz4mZv1Lr60Fu0y7PL4VVdXbfPZiv9KuH0xQFC
pJos7cLnZNEA0/WdOXDU0XO/qd6Xl/f5ZdlVLouFUUIpGgcosWG1uMk83Y3X
nWpLKFuPmvN4lq1mzfGqk9BciAOUOEThUZMfzq/V6ZxYk7mx6ja1x8Eq22kJ
CUV7HKDE1l7mqXhj2o1xnUye+/3e5aJxVn/aDJ+bCZkrDlACpCzRsdO23bAe
B627vF2sD8UHUq10tU6m378W3r8M3wSUFKmrfq07vpP5gTF6eZHnhUbm7NG4
Uy/b3fcbVm8CSoqUPrVkSxhV+rJZbIwXT9mmk7t/XPDzq/fvtd4ElBSpWa+3
dPpC996+b00nmfuC3psPRuLFhfF+JfgmoKRIbcR2O2/fTvNmfXqW6Vz2+4Nl
7n6WkdoJpy8OUFKkGmJVeGpcX7b4iXxVWPPy4nYyfFE7UuP9htWbgJIiZTqL
zuNN42VoPOiN4qDwourFjtQUpGVCpOIAJTasBF6rXdwJWn50rrTt6+er+VV3
Mblc3yaU6HGAEkdX1jpSrfwwGGQ6t9JGmc+fNEG4fx7M7xIGKMQBSorUy0Nu
KffHo8fzx658Pl6YkrW6u3Yfpkm3ynGAEkdXSvdtV58aI+Hq3ALx1xrYM/PS
vl/qCXcQcYCSItUazjPOSCzNhUtJJLePzcvnl+Jqli/UE26V4wAlvmjrGraw
Ngrq4kKxz/nKoH12d3EmVnUt4Q4iDlDi8LzbzSQ3l54Hxlkr71wszq7Wdrbu
kks3oUM9DlDiHYTWuHzmW8scXylli89k7JCMPn0474kJN4BxgJIidb5y2kPp
ovuwvKnfZauZzro6LNiV+14vofcsDlDiowfzotZUCmO9ZxWE2VCfFYznoeCO
1KSejjhAiW9qZlXxbOJuWtfXVvFa0G/qE/NcHPcvk96AigOUOGaQz11Xy2P5
XqgWNPl8bdxueOFlXB6oCQ9p4gAljpp46hq5s3rvqTNTB5ficNi5vHp+Op81
1gklehygxD6hpvCUE/v881K8mY3463L5jKydeleVEu5m4gAl9vIbT02zPMwK
LWeaNeyL+tmlMSiv+y9Jr2XFAUq8f+8X++vG2bzaqUx0Mr15Us+lzLRSFBcJ
GT0OUOLwIGtk3feUy25/8/By21iq9+pZLXOzTOyoigOUWPfJndoy19jcbPIt
05qXBKWSWRfNTr+e8OQoDlBSc7jTtO4vru76o4Z2dV4c9G6vymcZtdmub94v
PN8ElBSp62fbaQgT+9x6tKbX49vrG/6xcj5/0BMcPbwJKPEOeZ5Xa/Z9YeXo
z/2zniD1rxaOoPWvqu936b0JKClScq/6yLvVyWNXvVkrjcnVOPNYu53nnysJ
fQlxgJIi1RrIL7dXZ4Wrmp3vCRu3tRjrzvpBFTbv97q8CSgpUs9WflVqKXp9
0RaenWxJrNefzs4tt194/27mTUCJQ9O16bjuTJxho9N/ybm9zuCeqCS7XD1Y
75eeb0PyMqz1sPbatYv5JA3dPjrq0jJ2lnPKTQEyLQjLPfuvWfYnmu7KEhWb
pee6a0czREEDmkLdcjCdElZCw5JMNHvSHVZ42l//2it9/Yll++T+I7YiuVcx
1U5WE9tr9fsRll/G5F5YiVDRXVpBL1z/0PazoNHyX5h6mVayxOJdWPm6Pqzy
pNZv/eMf8KPXHQ2afD2AFC4bh8X9sBKignV8sXC5V7xrt+75yQkd9cnJgVE8
uUD+qULk37mbAA9a0QBTCTqK9rqC7WRbkwjzcBm0ZnroGwvz6nOKRssbOQST
LU4dYmHqM52wIqdN+JbW26VJ2kbQy2cOSxl/CSoWRxPaRZgQeCetyF4laq9W
A6gpnk3v0ubppGXyNG8olmKieVGLfPY45fOJl7fNL+6Opf3oMIB/lJlOayvb
jH7WnqrQflno3brQn2jSSYCNhb51aeNTy0vATOTj32nldtmrM35ywvJEs9Rt
rL9t/7TKFyato5OApd5cjWahY0Uad2FjgVOsjPZDiZhPZVN5SsYO8F5Q3hXL
9tFJ91LF0UUIOANpdMIKZBi0cuzSUJeUXVitekz6iCVqJYs4Jye/U+z//ncs
eDiosqLc2A1m3eVEjtKKVhWOVBfmZoQVv8LkvkAqrLHe73YbLP1bvdPtj+HH
717OR1eRMcc7NwKjGKVG0x8ClpxGesaMI8W1QC7iA3gtGxxMjZ+PTtGPopXk
XtfXPIVnzZvbBnsoFPPlMnuIpaZhkWPdgWqXjZqWqFVgyVCsWDY+WrQXew6N
089K66VAxCZ+Nj+vEjSxYrHmdrGmyDTlGchy2+aHG4Cg2fuQkqBbWnkdqEOw
7tu2QnEyOkWGn91DkhzrvqbQGmysc4NWEuciDGS/Y6RHO/36SZZ5zN2o2qHe
gzczY99TYiz3P9b2PbYc6cBjXhYPvXEkF0eO+RtDWXBB6TlYdQOneZvW8Ygm
KwxlwfWYxgS9hDXraOkcmvHT0vxkjK/yIu5PhPhW8VSuh8kvlVCC1BVWXg2q
+Bis/jNmaDQtzKCP2ZrTtJoWS6fIslfSRJlBatW6V9hS9CyHKkD0a/z6xZmp
fKS1KBFr1HO+7j+s+T6JC5GVwjveqYVX23C6QYt726FS2CB0dBmTN25zPkYL
eU+2pVLhnUoztjKhwcphg5xjaUt9QEHySZyGuErJtqG6rKomB3YTs4JcsMqw
3qiBJcbmhlcfUDWwogwre7KT3NJLWIlWBpZXgtVKqyn7U6x6aOJIsXqWDwQG
ivlVFW/qaFpNrPbJbB0i2liddEK4ICXpZLOVlzh/QSHCFEhYsOhA2hKg0jKS
splmP8U6wjBZ8YOAb6CHaAFFZGUUdpgQ2KudCiyFmPpZQP3KxafbQp40Zazf
swZyCEvJY/pWnQ7P9oq12e7EUfdWr+SaMPkSzQob5VDQ65+UFEmdepWgTJqq
li4qEZjXTwLKVGCIjfw1ewpPvByi3AR4GsdDsyazBKw9rzYVGGmgqrkhrU11
Cha2pYgaLEEQX+JUPOVGrqGBFVJ1Lfhxq+Dat1VxyTXcCdksjFPuDHPXYzPC
nYkSWN9gjQ8NfTYxuJp7ytXnRJ+tAbmOK6Kt0RGNFWZcNvDHubgRuaYlKcAz
p1wDVMu5C8QBMlbBkHO483/981//41//XADEjbpEAV0jKkykiHW8mkuRq4O0
SHF3Cj6EaTlD21PnGs3hsHl52Rxyw2r3ctS8xHHZNhZjVkQdc2ArszmqFngO
TGyJc9hUwNLZgIFaN1QVFj6b4i5WIx5Kc8uQFseU84k3W2HJKCpMBL5ZOtOE
tywFMC2iScsSB6zu2V1+FdfDsvN14U20AenKPTkBvExkpAlW0FZstgo8u3JP
rU8vBa7JChf6KXDpoLCcKFAc1SL+DvKee6I33Ir1gzIKCIBWhcf13h6GCj6/
zPSrkqp+Wl+6b/O/RdRQflmiqWBuYk+m+uME1Uu82tHqJhAooRW6zWJsz1mF
8pDplOJGIJgVHabtJaA7Wz9YaFGVacFq2hEVAn6G96DXvcrOh0NTEm9RRQhg
S8DyWNJMywgGS82KjsgYI3hkU9toO5mspdclfrUgtJDxtmo1jtLVsHSc/5hm
9YbeaSVW3xLFanFYCUIP0hPf7ueE6jax8O1WoDdQL9lHI8Pb4djBVjkAcMot
dGOlEjDz2MKh5W2BPan5tiUnkoFKH68yRRxbhrIch7QLVZJobXX5Rmpq2JgN
nBZICFesyFSYCRT+hu5F6NIJf+pXtGffghp4YR/Smr6wZQadYONeXFmyfSea
iF7Ca40Qmt/c0wUg03CTZmFe8YBjkAthW4Zz6AAFVBDdHFb2wYc+HDqH9hvS
ul6vc6G9OjfstpmA8g22FNf3yxoyDfsJK7eT9VxEkQikh5WA83YMLAXaSaaY
//3vWFZ4+wArZ7PBcN6Ozv/G/wlf0BTVlEupOsetE9X5i91Zi58jIYPkBfrg
Xg5mNSRamCEUEqdT16Imj7fEdownhiHWovCsWzRv/SEFxZNDw/7H0dE3akU4
6Q4aMt9gJ6K7BP7bgBn8ZB9z37aL5xt8y4O5cPDf8J7tariaAZOGBAyszl6d
+wMr+ejuGubH1dDcCCdsR5m03VKrppQiiJadpv9JZzNpxKVviTMXFlb9BUvk
ifCkwF1JoGaxOfz64pfMjgeFexxLmTAbMJ0tlAvpY7DJVPRNnXI4XoOOpma0
/n2xLuYz+7H+0q7m2x1OyDtzXAo6Vn3vsSUadVrMxPxsTr0WrA9swZusBUV8
CE1EE63ab1y2DJNpOnw2gvqe3vvNEV+/umQp8rOfOaGIeLDKJFzTr0zilXRH
VYcEXTI23uI3nfEmcVIzBauqoHjQYbmojqvP0giQP1DqhAJkBfR05nP8xl38
658T2Eaf+lUp6GD4bIWOZ2ckbAjhLP9blGwQQXZqZhgzr9yKrKTArAHNJQop
xUkT27AUyaZ1ILDfAewbT7kuoI1dCnleKEe7/ML6jE6Kb05hGQVawydUgSCd
F/J5oZgtlMY7ye4x1/04qtvHHTDteCpbYQHiy7Gijz3XhTweXQyP2WhRcnKD
6miI1VLhY80X6FvEUEcjh4KFuHV1eV9hoSdsxbpGtzqfyaX9+kj4G4lxq1iO
CzIeCfEGFZJ3hg4bMNZVO81g8fu+ogWXRN6TpH4VJvoSBCIzOXi0Q/ig0qZP
PH5HMfOZDKy8L5Tpt3hvYL/spiYkvSmMh4MM33jpZH53/pYtFBihscqqCDpB
R5ky6F6NuKGrgV7bZTP6EDSw4fAGK0gVsFQbxI4Byv+Ua1nU1/aNY9QkKJq2
JHUME2wie6MbJpiAW9igS4GFFR2IlZpa6axpGjMrOx0Nz117YMxyg/tJ//p3
3ML9SkFsy3P55iTaeZFyTGK4yhmR54bksdWHjTDL7x3ja6F5CC4rwWViyTXL
PlCKGOfzO5ZjrlIu5zLFsa/nxlWPTmNjGllrY6DT9kGz0bmqH0fEZgPN4EBd
3hnWAmvxENiBfmoM74bHh0Q3HtKMbfplmlUS9QvSoBuGWiJf2qoxgbVXVXHT
55XdaQOdNRBXVE13wOoGKf2Jao6DXUXXcTYPVvLsTwmzXKFYKZQKTFINfUm1
Y5Kj1GpRJ8m43W2NGwTd+GMYQpS+zNseb+PuWbSuncmuyCT1YhhaysUKflKa
uj7TN1U9VxZkooi82LvUntqdee95bUiS0JE2rdLCvlBFQs7JdH2VnwzrWa3T
f1n1r/sPbZKV9cdB6mWqkoe6pjmgN4zxpSduI/Vvql2uz/YvQ/Q7eloa5QMV
ykJ41USOGXxxKHjL5lYhui6ewowAK1ATIytwZ6662c4PbnveewwJYJFssHUh
dtqQZ/J4rc2fru+VwVi8eJCfndtl44y08t+7bDKVQj4rVMZ9bxM8HrTHYcKM
g8JAbKKxKLIijatdRsNhszr6MURKpIsQ7ivVAw8Z9/kFBL3DUlQbIDvBcId3
mUzKlKdxOqQ1KXRe5oJmCk3QIXmhXAlra+iEqhOZaAb8YZobrgPb0BAdlIWy
RZjoEZznviKifyGMA9TJhKmD5NmqMBgV1mNP2uOvO9VWpaVt86UCr7w2Z5A6
iNufGdTuegvY6sctu1c0++51d1upnT+ejRvtxWNfVvWnmnhDNqo7nzxf/xet
u47hDFr1D6GTUNml08csvbnhWFPJs/WEwsHK6GC1eBXSIqW34w27VqNzN1Ce
1ue2AYsyly0X9i1KyoVvECbgVjtNsQ6Y973U+tkr8YNmx++dTpC8rzN+B6/4
GWkPnjdWo9ucNVcwI0Iun2Ez0m322//WfKoQc+ZxaWYv0ZPRYVZ+HrtCZXn/
skB1kc/kPc5EQ9KeG2aUAOEypbYuSnOHl0F0YElj2G4DR80ssJG9+uGw9Vbg
i0PFX4VCAdcBELvBQHBDSaHekUssHLtj+7/dO2GLwAcGIrUIU6CT0BTsqIUf
MyBKvivXgac7YzDoQ16WEfYOroUwrq9QjbSkC3fhYCFNLJbtHZ9jLdq40skg
l6NCTWRCmhfB6mUxBWkP+QOqb++ejDmbsNSnu55inAY7T0Fe/v+ru7rfxo0j
/n5/BXFBgktwsknq+4pDIPlTtiXLknyynQdhJa5IWhRJ80Oy3AZIgxZJg6ZJ
gLQokjQFCrRIiqR5aBsEuBR5uD+l57vLU/+FzuySEvVlW47TpAckd5TI4e7M
7OzM7MxP835WlJGBd93BX9OEr/kBzhaIASINzJSxFBIxeSSnuy3rrrBfzSGX
4jGIHsYZhTUxk7+1ecluJmWSEEJkGlXMrkMYp5+xbyZDr9ncGB7nrAxPp6aS
ZNGZt4ZPBLEQKPwK/sCvUCIsrTxi8PqQf+PTaZmtNv5G9XgcFReFnO3oxgUm
5kq8SGQTWblRQV3C6aMuYeg0kShq5C4Mh6bDoLinHWluRY/lj7Z2Yhsnx2Z/
40xL62bT8PztgmE/OD4pGnU7Va8oxdpRKnWUsWOZw2NC6G67qR0srVibqcO8
3yHbPhHVjoenh7wQSO/iSLq2IIr35PQ9UWSCgiBPKPM9DasF+nh0jMzmWU3G
qrDcbYZtmcxpErwfFwzeHxumGYqYS4Wg966wQkyiEOFOjwsEv5TSYxK5nkBk
KZ5KSWKjhuUv6GkFtzfWTHiVZWLivlGrrDV2bWo2qj4EiRcZ+G0na53aUlsx
MackiZk43u1QrNecx4GwmgP8yykuxIIdKsZJhCajBOuzOujCYtTxOM1El0+o
YSrIDY8FQ+tutSM/1wu3VS1YaROJHsuN9Sw2FhVkbi+DdwafTSwAKTXJ7hmp
nTmUmEB5CmeWlxJ5jNvG5bZuUP5YTEywv8WElGrw8T8vi8/LGel5OTsnPLvK
MGZkwaV7gpS86Sx4crEs+DZxDNfxNRrNg0up2I0oO1qfpCizPA1EEfOSYMjR
69l5OR3PXEadpdgm9wKwgKC0DfQDA8ls1IrrPLV/T8iZJupgGAAGlQb1DeE2
fxd8A96qwnQ/VPbbo7GrXrfN8v1LLl8ULu4YTD0Cl+NlcDbU+5SfQ/hnsSrW
EcD//R71nWiOMxED5heJ8113gWQ8LSUX2wV4mLxeiTrMyUsd5iQ/IdKoeQb/
YXUL/sr2mBnNXjKhSzzn5CzPGSK6toNWK+oyXewbF9rbanM3ndjxEmA6U2Iy
MTOLdLUp32FvvnTq6e9l6iyvNJ2Sv3j62kEaPMS1TimNIVIqnQpmj5mP7lTm
40YE/901WYwn0ol4Oj4/UxHmJHZy22v/6/FfT3oGuvK8Omf2cQo7PblEmltn
7R27aWqGmMMUhCSl56RmboQRye+FEWM5moAhwyKiUakpv5ofCV3MqF1v10qX
LFV3Ue3jSSmMiEP+XC9Xk5zI1VzIvkRsioPXy9skI3mbm44Wr5HdmSfXiezO
QiO9WJopOZfMnGxK2WIBj1TltBhGddPlQJH9Wfc0v8nO6uG+2PimF/VARWGd
Ni/Q8wih2ceHAfnQq3bxzLGJyV4zwqqw0JTVmfIyU75TBxv1BgQCzCOVJX4+
8JMphqCCMqY0eQlCn3gt7eXefV056TdFbd3Q3Bewvul+eafb7uxvteJZv6gd
uaWNrn0aO1mN+SvW3qCoGgX7BQwjUpL7/VUBSBdUAWQv4fji77pKEYAUGB2m
mSPv4bLDGHW/cpiSlAd6mWUZYWt6UbgoxRJx4C1Xod3RUbSLDQO+QZfZ3Oak
VsCwKLQHBrGLJ7ivrO9WV9eKE6HVJGHkbh5CTZca7l2sDVYxgPuZEJeELWLG
pAl2T0dYc0fK4+iNzY31fHG4V3nA5lmGY5JKUMPEWM0a0txZlDiVZTkFe77M
gzJZlBop0c9S0ZwjHXa5NPlCX0nJUnLGS5ZIT1rq02b3Jg2HnEbu/uCGgztJ
4BQx1klyeo71GCp0WUx4O1ut6mm7+PLVzUUinrhRqxv/UTAvYJoUv4xpraqz
clQaWOmGugDTWKrmJrmWElZpi3EteRnXJggtL8ynPD/DZl44P8NGbiUlWUpd
xq1+o+gcF+nmoJxZgFvJ7I0yS746r25Yw1hWb9ifHXBNlC/jmpQiG0cx60hX
FtExOSszf+in9wRP9wx6/3a04j0sr6ajyvexWvIFqs1vv3qLlxXngiroYVHx
sEoa7uBd2rC2feIMRiXvw1pw3tAWdA/8KIrbWWMSb3jEav6wtZH1ak90sFhO
0OTEC8Qt3lEvEOwVNbFHDXRVi1ZeTvEZnyO2jZ0r2ENoO9jJPdYGgi9hrU6k
TYcNMLqD3eyOe49J4DlhIqWzhIeG/KvnuDc3J6x58ZYgxIRXWPajHllTV4F1
idO90/XjvfWtnRYlNGUkGiX1wOy6q4chWeZBXp0sQ2FIqc2TU/HgMFM/dDbj
xdNEbzdjyjF/Wx2Sre0sQhV9iowxONnUsoN0Y6eXakr6gWbvnxw6tlgUQ6Is
dXB1qhi/L9esnmek+2rvrL9Vr8kF+ahvalZh1zzcG3I2l7s6WwlRl4/zRw86
6cNBtW+T9ZOBkmuf1uPxTumoPJx/GZ013hw31qmHNuKq77JDGrGxbr9lJZWs
l8mKWG8eVfqntXzLMGuddrraZT8tja9ndSAyCx1598QrnuZQokhXfTUZEVj2
m2dp/2DFjcUOz/xqfXBQKrndervhVfewZBEWR0Bdvg71003tOJdNtM+oktot
FXrlitqv1WL1SjcX8nK1WlxZiHFK120t763IRCm0Djunes0w9bVWK62qnUwq
nxsKaUZC4WLCo1RCueBsybuNvZNWaT9nFgtm44Emy4VuvdgKqUdrg26+nmhk
OSpTlsMZsxz768XKxr2FVYAjmxzVt0W/WMzKu0rfKDfVg3xvL2ev2jR5XeEH
dCtaJW1Jm079tL2x2lYrW8VKKlnJd1bXgmGzBPeig8Zc83KpebpZ6Gc3G6d2
9bCptncbZtp4UFindfeaY2Zk95OHm0pWMg6P9ZOVmpfNHw0erJbW6b5dHGpq
oVS5sikBR225kdlZi1d86fRASmnqxlbfGRRrlX7FIrmIiMGpmXfGHUSg7JSa
L/1xF2yW3HEpuUtz6ajLkY14mZWVL0tSWhbTUjw+j38L0exiTK/S5TjEJ2zQ
tdzKtQYK8cBogNm4LGWvP8AILVkUU5lMUhxJYHelPL7GsEOcE6CRpQa3DY+d
YELBPCMzslp2jBjGEjuMdPmL4aFY+NDYbNJSCsPogIq8MBWWvWuMzpDQ4eCT
y4rJKOn4jZFOZOIZTNwyGQTUEzdGPSknUvFkIBVhDZ3GiLrnDUoVxIBCi8it
3oI2aW9bscV0ObFPa76r5VakkyzN5z1bDDAMhym3/7feFxx8VDcXkEi4VmFn
ijM6EFoy9JPIIfuga5NRkwq7RN7imSoDqgmO77PIaxH/MCAdkGOhLUAkxTpw
I/AQ2DncI+C6oNDwtIu5MAwlCEKTAJCCxyS8WTrgEm8QZj73XcHmPaUGRUwp
9gYGWbAS7cm7NXYVxlO8hxM75vsUjQRlSb0rR6CTOXNU3gUC2FmPv8iask0w
6DoVTIh3VqnvuS1NcG2HtthhRufRl6ZJ+R1YLCeo1DEpdlULa7Ei0AD+Cljy
toa9zb6H3avoZmAHPgQqGmnCd0XdUw2dKti1owChgoYkm1QXEG3m0UfMCfXO
fBBJQUNUpjzVYbSqK2jUaMOtwShguOd/ef3Jxx89ef2T83f++vjrD5598Y/H
X33+5Hdv/OfrX3/7h4/Pv/rqyWd/evbNb+CGb1/74Nk3bzx9/5/nn7/77et/
e/zwy2c/f//p3x8+/eyz8w8/fPyvtx//66Nnr/3y36+9/uTN9x4//OzJR796
8ua75+/9/vydLx4//PP52++cv/Xp028ePvviPaD29INfPHnrt08/+QbuR3kX
cqXcFD5FbQw6RSMuwp2wO3m7PqJb3MIO2SYsbKSSa4VN4iwlCkG0yXpLqXL/
dhuWMoU4e/weDtSErdAmRVgB4iBMCGJ5TOAfFDz2qR6CrEVD7DYvu0KMADBt
OBhmWBG0wGd5elT2tm8wWJougywI8GymUD94UOxwjAWFA0bZKGcWuYYQLksh
bwI8F4YI5vJm/zArgU3gLkcD4wfCGECHeVsB4j7sB49gtAguLqGgUgPUFZmD
PVDRVmjWmA1x8ksvzTTqL72EeFGzvnn1VQZX0NddLejNd1hID2skaPFmMTtt
6dwjCpb4CBEiiNz1MEnA4POqsC4HwjYqDBF2dZPAZ6sOcTtW8FdPb8FHReJ0
wLZUfGUAV1FAELjcgvW2TTCFDhdlqgpbCCSD2E3UgTUDYlxHlDX4oEKbtEM0
YRf4q1hOGz6qWU0dtLLsG4aLXJmVOmBMmfVFwBMVRh+gUpGhatIZ09dhcaia
h3o00iye9YBlbePnIUqMZc59J2PcmqO3EKAJNM1Apm35mgXzdNxHn5pTDJvA
a0HWOD5CnBjEBKPmoSA8UDph26Fd6iBbjgmasE0QMX8eEVNqmtV1LSR/6Js4
py2dML6WSY8aQknvWKYFSwM+WYEdYYCQK/z+nGmZgy6iEkb7h0MgHyd4R8uC
G3Wwe54u3Bm70dWoDfuVgtviKjFBO4rgZMDiCvSjYplqxyc4YKYDFDEWdoiv
8JnZCLywaRldphY52AocImz4Bl54wPSyQzrE1dhM4LI66DGIjEC3AhUp+lTD
2l2c8JalmfAU9R/9EQbueS6/Ow/7OOjxJjFwGHXK8H2qsAk0cRwh3A3iy43w
bYTpP8i/MUCcoXx2fItxU3FoH1lgMGHNhsOBL6LINGwEtqZjlaLW1anKWNkb
KMJuh+hMD4CvSB19AALLtG5ZSpetsI1HXzpIiYK+KFw/wExViWcxFnX8Jlcx
BALwrL7b0UdKs45oHqCsnLvgA4BpXfVVlRGuUkfTdaY5BoF7fBzmKm3CPmIZ
dMAWJIshEJzL0cG+8rW4GuNXoVFifgpCTXGzgzgTaJhaViySQ2VmePzpiFHq
EcNn+dUxLAG21qaXTwTviA2AASbepBkIdyH2/oJl+h6IW4NIirLFPoWmhGPS
2JjWebZ3honYRDhBV6iBO2OBC6GjBhwSB6NXjbbbTK6wZjh8ww7sh01YYqjI
G7qjKxrsL0UY4oB0mX4CByGEQCcSpOrxxWKZhAF7bVoD1BRcmCBU8LaEPHHQ
Jt9C7KE27FxMjPyfgQxn4YRMbR7CqP6eg6Lg1tu1FMpw2vheKov4b8yKSkvx
oDJX54itkXcOnVyWf2cQS8SdeEWIohVCwA1BX7dBtTXQtgHMNQ/zU0mPmLOs
aglsVFfYtsCxAyHj9DcoRgywpdy6VQ22eeaKu2FHMkY+dwUMrO4ioAtPzvMC
b467Fqon7yng6EmMRaHjgpEAI8X8hyUhJ8xGeRmRYhBhLnjeIIAfoHvnORvC
nvtSGp3vmYhjOLg2ogWxKfMa3SE6YaSnQLhzO/DXKdsLwaCYqqvCnqYHDTBL
t1+89V/ig5um5YQBAA==

-->

</rfc>
