<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-48" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-48"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <date year="2026" month="September" day="28"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 330?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 334?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 13 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">3</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">8</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">8.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">8.1*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">7.9*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">6.5*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.6*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">4.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2*</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100835"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
        <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of EarlyAttestationBleed."</t>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="security-researchers">
          <name>Security Researchers</name>
          <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
            </li>
          </ul>
        </section>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100835" target="https://www.cve.org/CVERecord?id=CVE-2026-100835">
          <front>
            <title>Contrast before 1.16.0 Remote Attestation Relay Attack</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87851" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87851">
          <front>
            <title>EUVD-2026-87851</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1108?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y92XLjSLIo+K6vgFVZTad0BJLgzuzpqeJOSqJEkdSado0J
AkESIjZh4aLOvjYv8zBm8wNjM/M4dn+i3/plvuN8ybhHACBAkZCQpczTdU5X
iQDCw8PDw93Dw8Od5/kjR3FU8pn7pSla6oarOg6xHdFRDJ2rG7qtyMQiMndL
rA3XES1t6qrcp/ptk89mskW+ki1lBM6YcvXb4ZCrpIRTLvIue+BdLleslIJ3
pVThlBN1mcvBM2dOLPzQxteuyTkGR9YmkRzAgn4tZFIZeCEZmqLPjn85EicT
iyzfGoCH+y9HkuiQmWFtPnOKPjWOjmRD0kUNCCBb4tThFd2xRH4O2NhzcUH4
qaiofL58ZLsTTbFtgOpsTPi62xy1OO5XTlRtA/pWdJmYBP6lO7+ccr8QWXEM
SxFV/NGt1uA/hgV/DUatX450V5sQ6/ORDJh8PpIAR6Lbrv2ZmwIwcgRDyR0B
YIuIn7nqoFk9WhnWYmYZrvmZGzaro6MF2cAj+fMRx3PVLifOoFcbf3SjyHPi
lhb4mhFo52F0TiJP6Oy+epI9WhLdBcx/5TgPq7s2/mCEuQNkYWK4Nr7CxxpQ
ED/5g6xFzVRJCmYOn4uWNP/MzR3HtD+n06GXaQAHoBVn7k6AtJo7FzVNlHnX
FjWRt0VLFq30vnn6BZqpIo4OmvmA9zZPMegpxdgLKH2YF1JzR4OOjkTXmRsW
TgF0ynHAWipjo196XofcDXbIDWmHv9CvDGsm6soLpf1nbkSkua5Iosrd6MqS
WLbibJDpGxaxgZFoC5+5RzeRxxJ8+jn6xHABW3jYJpYm6hvvoQwYZQShXKK/
CZsLnyRjSpIUI8kfjsvLDGBKJnvGdauI0pzYqrjkGu6EbBbGvkHVDYvcEXFJ
wh3+gq3EP2TWDOf4lz0dnBFR53uipRDuTJSeXeLs6yBKq0tRc60QSUK/fYLU
iDpTXC2CzxN2pWFXqSfW1R+ujk1TE7IPtaGhzyYGV3P3YTQEDpnNRYVru6LO
VXVYhlMDJoGKIDrJhmrMNkCa1Cl34cipKH71uaKLEewmqktkY6ZD/3/M8Nkh
itXnRJ+tFZ3rQM+zfbh1t3Ip0oXoWigErLf76IjGiugcUuCnDH4OnKIL2Uwh
U8jn41E7Fzci17QkBXDYi9tKcaR5iDseXUvxH/gY4EcvxFJhlUfwWADwFGHA
/7AppJQ034dGw+LO3YmiiqB85hpxuPN//fNf/+Nf/1wwnBTdxqWa4s5TXDUV
vNyDb6M/V1Tuag0ElEN8HkFLtlILV3IXfxj0M1F1NV1JAZy9bLtRlyKwBywB
FQBYZC+VkBXmhsNdiBM7Spsz0RT16EKeUFDx89Jcilw9xfVS3J2CX9shQjRT
0Vfv4NkAnUuCxgHOlB1BiixFKaWlVgziH6ZlOIae0vau5DPXdoAijeZw2Ly8
bA65YbV7OWpevrF4UK6ZhgXKhRso9oJaFq7qiD6KlL36IFB2KNiyRF2KykKZ
2KDwdWKPbZgbh+h/aLZ+iJQ9EWwOTVEVUQfxYykzWC+ysg/ZfqfLX/Wa7WoI
oaGIc68TmThgRslE5UYWGDBGFMeuI6pRJjPniqGRmZiy4BNFI/HT3VMWxBLn
3LULw9nohK8bqgqTvQ/LjmjP66ohLoC4ErX5ho4xnQJmyH34cEc+iLooRwWE
xrr7Yw6gJAR1CK8u6EFuKM0tQ1rsw6XZ6150q1wf2UUy1FPsPRXpyiGi9geh
5De9r1Kisq+vKuhTSwQhqO7rqaZYaKyC1uXqqLh21nYw2pvzqJCmQFMzV/1j
IrkpYHIXBnKkM/m6BBOM2zX5UmijfKZQfLt+3xchE56afccwM8BbvE0AL8QQ
XsN69YxpMJ9HF0M2MGq0cmeuTjhsfsq6Eq0ZcbbG3Gq1SoFQIWjizaBBSidO
2nQnKlg7SJF0PlPOChWhnB3vYIfIjaO4jSOY4cuxoo99zMaAGbOUfIOM/sMz
aQNy5iblmWDRN7cp34qJPj/joY1nfhwgL28R0/gZNAZj/TCNPQsW7eV3WcgU
px9IqehgPejRruiy+Ixfsgce9epG3Rh62xJGBk6xuaWr6rDOJyrBLaBFUL3C
N6K0gHeKCJtCGB7dFRJzTjT4VKVNYXNke+D3cKW0JKgs04DDgEigQH9X5L/t
boG2c5Atcj1kYjoP8KJ5c9tgnwrFfLkcN8rmZXdY/S8ZJ3GXcoroig32i2sZ
Jv4nTX+nd/CPG2p0F5hsPiXDxo3p/u2oP3Tc7mmgWpmp+IoSNqG7bR523RPU
ebCl9MkChg/CRnXWuOdwNU0VYnGm6My/d+a9re6WHEKZGxLT2UuN7A+nhgSa
S5QkRKC5VMAAkQgHJuic0xXQU0QznQ31KBia4iAIlEiW0xAdESUKWElctdfg
hs1bfnjZ/9OEycYQZstR5ZxQySdbETuN/wQ7h9q/A83YCXwLzeyfRDOOmu3O
sMpTjuGr3aiK+XjpEVY22Vx09cfqGzB8LXGpGCpxLDstIbppm0guarW0KC8V
24CdtZ2mo1lOZzNeW67XvDablQ4roJst0GDN7FIku0sSb2kpP1/QhIknFLmq
O4ONxcdTL2+uc/zqKbvm1+v8n6Re7gOo9/GC6WcR0ioCG5r5Mv+UtVbfR8im
PCMqcAs/3AB9NDtKzwHRDCfic0Ves10bqaXsW6HhoScYN/HQsDc4apw82zk8
8PnTTOKfpMKSn65K88MD9wfHeYM7NOidNdgmuJRwqk0DzHvolpMN/S8O7DYd
IjmcqKrAQ+KMACUmsPV2XKTMzxm6ln2e8StrveTn5Ur5zw99ZwE11wr6EmZc
j9hzrl5FoUoXiGQZAAx2n8oUWIGbwPZORl8jkAYQhQZ1D3XOJCBOLNC6IFs2
YZqgUiB4TPADyGKtpSVv5kyQyDkp9+fJko+S5dKQCQJwYOoBfxWdwTZd+nMD
hoz4iQowjYx/TpWZa7HFsjIsVYbpUhwqmT9lisXi8SkykLFCoqkGuspNS1kq
KgF+Ijb8pk1/FuFypaLGz3OlFUiT5XMiwuG5De/rHUUF6DwTjbsyhHoRPfWj
6K+MxvDpFmqnOpIQHVQK0KaKB0GKhDLd6zkiXAXYrekxO0r0OqANoIBBqBBn
Sq1CfJDW7BlQRXTS6xy5XreerltnFxIRSVHNjy9n97pmNx7S795bUlr2YR5F
IDtvwdpXd0Sp/5IbVHlUQtIceUmHSdeQuWRF5nQDFhao64i8Jb5KAkmLDIdt
PfUepkQuIZf46KQZrocZ5Kn4vOTzOZC1Vt6z8/YSxAf4ihgz4wAh2gZO9+Lz
vxtFZsZhapSepiu+kLM03pzPv4caxFhGyQEjUUGa8GDOLBXLcUV1D0EkYjlg
p+E5r82tiEUYZVAI/ygqvMbrMFXMwtTkZ5X8DP6lVb6LKtpBqmiKrvzbkQSR
ijHMKs8amLlPYOZmpeJ30MNypCg9QGDCKuUlVcFz8T3kCAx5ZsmC7fLsGkia
H06VKGqHiVJ4tiR+WS7leW29XH8fUXhZPCBM/pRfpsFc14buq6kwYYo/mjAm
boUKKxCz03khZj8USxhHcn8EZUZX9dHVzX8JWWaz8jOvTedzsJ8s6f1k8beG
+X1bwx/HJtlCQoIk8zgUtDLwyBpW0NPM/HN75sKBPfMPYpQfS5jZfLXkl5aZ
5bOVUiExYboNvm4ptoLH2VfdlJBJCUK+kM6VSpVsppzKlcqFHA00CT7cd1JC
jVU8/aBfoI0bsWHrhma6uKv6zLXwnAusWl1UN/ipMT14VnIJGyifZoU3z0vq
9TofMqTTNGBB5W2TSLwi8xLF7N3mbPRNzwAbUZyK0RejFOxyLXxokSngHqJg
ppIe9lPZjFBK0emGt/ygGiUa8IRIz54nrgMMNKPn4BjA5pAZ7p5gd2Tt8T7o
yGv7D5UOEAn9wa5NdGVNjX/coIG1APZjWnSkbCFt4qmex9fpFVH0uaHKhylV
Fy2YLZ27C3/5Djp2Dd39//4vrqeAyoZ9RvTlA4wf9tsN+JcJ649E33ZEPFrn
RrY0N6YwkNlOY9ECygznZAoD25mjuaGJNnCdbcP4dlBVwHogKjcwFOfFpiEk
dVhQpNZvRWeq1x0Nmn+xuUuywrN/jayo1T6kSxKmCY0KbMVdiBtg1wfDtVCc
NGicgc1dRcyMynuEgaQaruwvebBwFAw4oLM3UY1ZGtulgcfg/zXFsQhv8zpZ
8VMfN972UOMBNZ5MzCmvImr8BlDjRYVnIRA2b+gx84w4eIOEpV31sICPKD14
9HcougtLI7zuopQLqOXva70WnOdXCzXccRkGB6UHWZqOnNIExm7zgLMym4M+
DR9JbykibbFlq4qPhEweFAve1O8XZ2zCQXKFd/DRWEmOBWiGPqiphMg7Tqe9
nwDzWoSgTHUwoHB7xnwbcjmgA8oPuf3P//3/5SqpzGHxG9FKwg4jfu+pP6iL
bEWoVMZ7RzGmgxi/GsR4ZxBjYzrGQYwrGYwECOM/DvD/HvEdRPkdhQ78hEym
nCskO/HzvHsTAqxMOCElFIHUr/mYC7t7PBCJD+gYfqy1N12lQ0dfoKFjT3Jj
j76w8X4k33f0tW2/B80jxQ8b9MJa+EZqyiQxj54nniDHhBfi+77iM/ndD9Gg
jnxRfPOLyltfCBn/C2DYF4bLVJRg93mUSqWOjnie58SJTc/ijo5GoARohDEn
KpqNFqFpGeio4ZwgJFgmjqiodMH+/e/RAIV//OMUnu0c5bOH0fPs3Q/pIeme
D7P7PoSHND6LrkJAqK04HXcSEvKBccl9QuvSPuZWc1CTwViov19kYmU7rsAh
BQObGyuO7Makc1M6bhBMJlJLkcgpNAIj4uQED5oMsIDMOdiDCAz377Z9cuJv
12ViKyhjNVGaKzpBa8wi6Fs/5WwFO92K9t1zmhk9x1ABF4s8uxQKUMnT8UCK
v/89TpUhAV+PRJRBpZ+cuGCRIJ6itQEEcG+wBgKenKQ4ZASQmGDE2xjvz01A
DkDHkw0djS9Loe998UVs0pi56E3gPqnqTSMCFNELhFx5ACI11+F7oD1CILwx
pVYBtOOYjQygPGPcMTBirm8Zt+hMOeVcsMTAlDExRpzPgrgDqU90m1BtDnAt
Q3Ylhbm+T/FYGl4GPxFBCziDrNjfc3EJxCAEzxoXurFS0U8footKlsBYiOSC
oF0JO80UV3ctMFUdFeCheUwoRU9OnJURXCfZ3kQxdELjryJXUPAhsjI+BeXI
402T6FPv2/IpXRY6fW6HXuQZ/q+aFFM5jmpCew7jEGcino/QwUwsQ0TKveYe
eihET6NVlaM2Ge2JWpCwJ6MOfu+CDJ1c0/QVbYi1GAOZoklb0xNYm1FG8snF
EYXeuWEzuL3ngse4E4IIgNUP+w9AHOdy+wHrZMtUDDkA73WH8bgAgQMGw8b0
mBgxhTWguTrKkA9imhRXE22CZOfQnkYjjp4bQQt6Uo0sEN2TU2RfkzzEd+wc
RD6laIOwXun0XFuDSaHeQdOwnf03bVJcl+ERrJXY1Xbq8bQGPEF3CO9FFlTK
7kHT1vRA4vRAhfyFeivgU9ZByBGRgl0ZPXrUoCOZg12fRVWRBJOFga3AF0tR
dXHXCQgqMPGsD0+baYosq+To6FfqCsF5otYxwJwqFp5ssp0iY9c1KA3U7MA8
GNJKb25slwNdRGm6Rv2VsUeWMhmGf3C4MHDe/eUQ8DnOPB41ig6nEs+Ja9h4
PGKz1UQQ/V9/5ZoBRsMtRp4A4YbQpWszNc3OIidEBVXlDYmdZXrLhwpK194z
IIrxG4OiS4KegloatAMkLcRw6FvvwDsTn7O/gG02wu7wLBlUHHEsRbL/2yff
CNPBBgOTy0nNjGUap5n3PklLS9s+BkamQpHenlO881jYBeEBNfCyTQMUIgeU
DJ0UiNAWMD76tYAxmDfglOvAYJwJ6hduBZtmX4ai5BnSUSBFhBysF+hzlzLQ
/YagIwOlw3b4SDBfZoDqhCd4mctigSOIMmXbo6NvrLtvXECnb9wlvVOHnfZ3
Otv/jk7Mt6NvwMqR/wFwX/JDS38rAn8K8D+eY++F6Kss/C9HX4FmgL8xytd7
zHuPS9vHQuhxIfpY8B7nt4/LwdeoQr7BmpYVVwtB//tnZqr/7Zfo4NJs9ChI
d+N7PokLkTHjcZgbf/kHXRr7RNXRIQtkuyZE34JCRQQ6DVYjzC8VgS9UgrwX
DbQfgSFF1T4FhpsBr1MJB7MHDEwVFfxrQ1UYLh8vqgh41aQ2JR6041GPhZwD
g9cNJ8W1LEMDDH0vCYfqCa+UggBg+t0TJBjAIRNJsZkdKjmGZfuLRQLEFZk6
4bwoMQ2MWhGWnAY8b2h7ntthLPdjSK0FHBX7lmIb1ar4WFzi0TyuUAAUb7v9
aZU6dS1KZV+oMoEZuHSPqtwJM2KpfrI2J0zdI1r+N2G+oDPv+3ylwOcL73na
3f7gM0+RIiV2DU/4/11yRNzNH0GDyCNPY+yzrY8O29yhhfHadGYOXCb+gcct
dsLIIZDAxvMNw8hpfmD3IZa+VkNNR90/0iv3z3LH/QP0eo9t8Rl0/N5TAASA
oZAYuOftXJDj6TTs7j3DBncMuHAsYCzI7CuQh80f5DA/HG0H5v6gtghsJv/R
tunvMVJQ5P4KooSXLLzmbXP/QJWE7/E1F2inFt4Jt15pGfjWQ8I/Y4K+fdWx
9+7wKff66i3j09c3ZjkGf9dhwPna5qM6eOV9+PAe9s6T10/+UD/cHvJmaSOm
tfc3otfQfN/fPhC57wexj9MiNgaMfYFeblfe/JULpRGAFQn73S1MatG/Nead
qKq3yPW90xKKV/rhXRBj+RP60H54H5Yj/Yw+eFlMskh24yJoW8/UjGn7StYn
Xx2vZHtyEK88m38axvfg8YXFhmazS369mj7xxZykbbdlfyo2Kgr0mKJWPsGd
j4/BKRfNAXAaIydC2GoVs8Ln5muTzz8Vnz4I2yhQhq3wEdiappTnp7NCkV/n
KqUPwjYKFLEtp7IfgW3xKV/iYbqAs6VZ8YOwjQJl2H4IbfOlQoG35kWJL1by
H8UJUaAfiG1xWn7my2VtyUvlpfVRtI0APabCs/IR2D4/P+f4ogQzVyznlx+E
bRQow7bwEdiu11aRX2ULWT4/m60/CNso0A/EdqpZa3769Lzic6WZ+UHYRoEe
U1X4MdhWiiv+6Wla5tfmKvfDsC2kih+C7TMAzq0knLR85aOwjQBFbPOp/Ifo
Mmtm8bm8JPFTaVb+KF0WAcqw/RDtsHqeVvinqabx02L5o2RCFOiHYHtg+5Lz
jMsSdb9OYK+tiDp3tlFFfaHENcyHdrm7qISwfB9WQdjq9+wHC0ltXBZh8aZl
+MqexICHd7TaenBDByEJ/LbMa+c5G4ConyzDnc3xI0x9QtMvUUe1YcnMC+65
49EjwvPMW8FOHjgN9qL+Sd0J9TyaFlEVYD7R2lD/8H73MDrIrrxDmaN3OIud
rV8P/bDsaoI/FDEU7/mG45XRyX+s6HHeRHZ46R2feJlZ6LNI6K6f5sX+jE6d
SyMFE1fb7Rae3eCpDHT4jasGnlpkAAEb1Gm49n/+r/+nTWHqBoYeUHc992VC
J0rYu/Dfn8cj7ViE4IUtPe0BPKbdZ3e6D49/DxrZj0Yjy9DIIRos2yBZ4y03
YLxIx/tV4J/oOMc6zqeoXLKAF+n4WfQZ9etH+s9/dP951n+B0t/Q4CEjOvDw
r1nK1r/moigUPhqFwrF3TnQYBZSTXw56TfcitBsrrRGCvlQbo0snrHsNT+kU
UbXTzJeFrqyUf5uSF+kFBlCkYc++KU+P/8p9CfzAy0wKdl9bBDDszdZtXnHQ
kVWcUVRWJg3NBN5Ou6ZqiLKN0a2FtJBN3xEcrsVX8dge7x1jQOsI2/L1q8tW
t9G8HHWrF8W21zN0Xa9HQvGG3fZ7xn/8F1hUskEvDYGseMIrzl9ipM5emDvU
SPsSiIaVmYaEpNke3rumTO9Xo6TcghOVlAafUHgUjsSDdDVcSyJpvCOL4TuA
IMYd0eBePwCLXyGB6JHN8ZYZ929T/wQzFo+9s8x9zHgKi+F0y5GgL2LD86gO
9RDdv/v/E4jizj+kgl/Jevv01YkJIu4HPm0P6lA9/vf//t8xAsKPgAuOfuAB
DBz+X9GDM0j4hSEqNHRnYixDeu5oj56jbQ/rNtf2gsuPXgVuYaBWCF1d9g5Y
ET1NcZTZVhNi+9ChUoDqzilSirtyUZXCMscAHAIrn8VcKA5YEJsjeouObKMK
8BwYliXB+A8HLJJZOFaJh0FNQf9zn1T4QOVyx8Hw2aDihi2qBkb5jTA6AC/e
TzDWBEQDcLh8xA77QukW/BAITGFBn4BW0gAkntGxG1Z+agtxe3H2aMrOjmVl
SoMfnG1w4ZAFXnlNoX9v4LZrkYAgILF0EBL2EVABD4v8EEWbKqkUZZmjIxqK
Y5uYrngCShMnQTVswsL2olEZb1g5GGhKLzIy++T1UZNi2y68g++8wLEl0WXD
otTB8E12XMZa7ztJCkXMsZPRniGDjQgzdUUPNf0V1AuYl0XSRE+0n12YI26K
oZDIIlMaWiVHDUEcFEKCHrfUjxv7nnUz2XA2rt8NnrjrM3yLXAVdfgUZ4Yhf
ObxZA5LUjzMhnvnEHL10kjhPjiLnt2i0IfdFnM0wOMEhHyePApDHfo4Em0oI
L4ZCDq9ded9YD8YGwKzRPDcqaivMCsSCvtgYXd37lfImcMoCKn0kaHyEb6Xv
iX2gPEDTG1CDL6wsw5HOUSG/P1ibciddfOz8nekLnBOUqCKujNBFuk8sXsiL
zjve28/rOG3oIwhEhJF6uSUw6I7Gx1EuAYngrXpffm/jRWBfADZ+jeoObg5L
jYYLejr6COzvKxN7wkYHIwSR55xtYxbrxMRV5KoJJZ8faMbUlTfJ7yGlbHg3
mk0U0gAhmh1KtL0wWQW/4k5OvDBNkPoWcU5O/OXA+qVBjYCoQvH3JMer0IzD
DIgBsyQUrsx2XtbM1eiGcDXfcJH+KVZB1DSNkN8zCGC+/htUBoW0v+0pu0yH
IYU4lpMTf3QwonCU9luqFxB19SfMKjtViIzLgV7GAelPBSOLImQPMFWDig1Q
SWEOFCpkh0RKgdUusFD/A+uXSSP4MO99to21gS5rZGOgcEBasDAsippKxAVm
3oEWX9EmbJ5/xVXtp8SPnS4aVAWCESYdL/LS2HXR9JUQUhWT3RK2ULARZhH2
89vgfiuEB0w1wSBRc8NMI1zZ8FmK66uig0wU5lyamozFAhrWAs18avVbsFa9
PTr9AEMyceEaqCxBTYBkg+fh0csGrmhMq4/9s/TypzThZigDFQ7ztt48x1kB
qmDILz12h1cYlbhCXUWHCDrf5F1deXaJx6IMSZEb1Wucd9eZ6lCVBHcmWDED
0xvltp0VSFQU67ADGw4u2z7uRP4rouBvoE63c4f9IQE+NevHjU6T8+x8DuN0
CQPrbEy08tWA/mw8tjF16Fi8UFxqV9n0xsncC8H0b4Dd9rbWJDdzMT70aohT
KFkb0zFmlmiCncCrysRCprAAKSAPXvag20lQkSyADCM/TwM6fx00+1eD0bhR
HVW/srxYaANug/pZTywiTPJzLcvsDivlRWWG6yXMKCyBDuffCmGx6ngn1oIF
77yeyL9S5icwg+yWAJBNkbdpzGhqMxcFgkMzZcDU+tqOEjjoiOEQ3OYMcTbR
RRodG+JCajvAsiA0fJysJRWou2TWsRf25fu5DIvZgDKLuWdzC0zN4uC+XjTP
PzFOOP4aXos2IKXKTJjT+2ZYkgLQQiEmwjbfxDAliQUys/g3Qkm7s0gl0bUZ
zWQyxcgpEJje2E7BxjWQ+ticrkMeb6pwjUGtzW6KnGIjpiC3vAZf+6RnsfMi
RmTh3ZuoFPji2ZgFvpiF/4t6AURNZpma9LS/v7XTLILP4QOH+MQFrBw0ojSZ
tyd8KVMo0EoNx/5mjBr5ho4LkGBqLhdtUZgWi113BREGVi+T0J852JGwgiMo
Kh5BQxR8G9CghhHSGwC5Ftritjv16KUGy8FbkUxyEIvaUV8HjWGz2fhK1abt
SQrK7BZ0pm4oi4vUkrZderHJ29kEihw5n7puqYIC2CiAPe4BTPlhn6fsjyqM
ihSaiW+Kka++/Ra4Gl7nKWAKUSYaLBLHoqli2CZGhh0ezwamo98ImMrVTLYX
xkVDkx2zEHnPVqMuVHZn5a9bfvBDm2hUHgxxjqLvCp4Nhxd/sbmvPI8rjPYE
M0vkv1myZLpfuU9fvI+4HOw5Mlz3cjiqXlykNHmv8W3Ax7atBv+ljirvB08h
pLcQjo/9fQ+OBFbAdpqAdvD3oHoJf1MZ3UeKImIwa6YLgllRYTFTUgGJg+0u
mujizDdBwNSkXADGjcwksCcv6EwBExJ668LXdb6CC61MZmFfGCv+gu6Qe7B7
9rZFSG7mxfOMjaMW5lMjXDbWmAgtiVGzyYszHQwHYA5/5ni6FT/yLyzSUFy8
AyByMMfsJccua+1Y0VTGaKJpe24N78IjcivID+r5N2gArp9FAMTFNr8mCv+w
bt7xu9DIfxhfCkZH2Avv7uq3EJB3/vMt0tP7mkD3/J5/uP2P4/75ribQ/clJ
37/62GNeiBM85YNx81QhqD45A5Pj0Oi9kQfNkBqxjVj39Xpgs0HPHqx6/4br
3HH/QekPfOgCvP/YyUQxRVPGcqnIDTdhYiuNk/CJGRDHW8PrP7hBD941b32f
C9gbDI9r16AKmGa8Y5ggGbjrZsx0Q0dcmloEYdw+3fZCXe4fddQ+8kcegk5d
zVyDWpzcp1Hj+E1mwmIRDr0OAPjsGmDxTSlOl8ShyRJs3Mz4FPBhBmbbf1B5
4ttqnskHdDqMTnxTRJZ9sYNOZ9hLj/oR0nxjd4XJzmLdS4z3f0p7oxZx9fxr
qLtvEW8+SlAYDHKExylNdpa+0y+a/ulbsKyo8vW3Lm8S37fII/3feSI8jXtc
Sq1tyuW9UL+nybb7i1G4/2+gIKibH5YvtsQLJ2+Q9HuahDzlO2rIF/beNUFv
r/ta3IME2ZHr6DgfeZdv/KMkNGpXuu+CCGAzoGzrZ7O9X+AXjAA9ov5Duii9
baB/mSSqqyLGYdj8jio6dunM12Lp8NR84waubqdVBZOcUv/y73v5hhttzFfi
Zf+Xg8DUoj0xo/eg+nmvMnm/zjn0JUUBhUKzjrvPKNJdJiD0sFh6NbLLmLeR
D6+GaV/yeHYXY79v283w/v7jJek3rk2FV2CSfhcK1XP/m4ga2jZtedrED+BJ
B5oV53OuwPq2pDkeSQcOkMBA9zvpgR1ubXiAgNtuX6Z940Ia2O+u45mW6UCL
wf5GxAvzu2MKWsJw0ueNFrcla2R/vm1Rt4jvQ2CkG/qk+8bRrN7+FjnmH4yj
CN9sCExgL9MClTVh0XIRLL6dTGq4qvd7eVCI9GEzB1Ou7aUcuulsdifYe7PL
K3/BdLM9WOpHv3INmn0D615Gzl4a7FwGZeRI0fDUg7DTQBZmUN0mK2BuTaBa
1d9K3rJjFpQkTeqNpAQk4etB8ApP1hRdoShtT4SIfyJET5YM78gGIGRK3JUE
OxHcPTPejKKAGAQfC3kYlxT6OFyqzXOzfMG6ltttVXxKYJgCO12cTZ7XmfuH
8t2D1cn11vnlVVnP8u757CGNJ8ws7TDttcji4Dxq4XmZq0sUz9Cen0xSfo/Y
GfymOawy2WxJKMK2Pp+OJCvb3ipLWTZLeeUQwk7S0YUibQCLMBWyJa5FJiF8
giCE7TXl16dm3JeTk+C68d+4Trfdwfo+LBvE8cnJf0PIXg2FMOzb5r4ztG1P
cXALPtziK7g0UU8IDEad7b2V9Z3wv2z5KDo9MVmRMS2HaBM77YgzFoKA90po
ZIdApyDIskmPOmijfcR5B8YVmvPre/GdGYdxLaQEfmYIqWwROnuF9Mz4ToSF
zCuM668soe+LFcELyyo9OfkSUwzkXbE9u7DTpquq6QINfxVKuyO43fa2ZzDU
O/udI/KTbyBvZmO6TXTiR08JcUZZ5itMDIArdgf6q+CoV0Jhz5XEGAbI+2vs
Fcu+LXayr9dvfdAddevVCw9+BVaWx2B+5YxEPeT+ZA/JqZV9Ra5XHbKbkT7d
8q97DZbkq95eX398x9SEkjkn64RefvyRHbCrjz+2B+0H98CuPf75HgKZ8DqL
CuwSPW2Cttg7MvRgfPyf6W1mfFxPsZRjlznfQbzin+mEXfuM9tJrNro3Pa+f
YioX28+OlePfCd32+l4RU34v+OwHgn/TlvIvl/6Ebt4hHt/oZs+c/9QLqkLl
FVrxeP2kq6h78IpF6yfdOU2K1k+6XJoUrZ90izQxtX7OddGkaP2ke6FJ0fpJ
F0CTovWTbnomRuvnXOlMjNbPubuZFK2fdEkzKVo/6TbmAbSSb5/Y9cvsfpsy
Obh8HLi3t4/5NxxMwea38J0dFF530LtqNAfVUfOVabq3k61POfDoRqPpw37V
sEdX3HHlon8ZD10VPwOdl11QZ9cmWD5Bmj5U1DfbSJcNt5qLjm0g/l761XAE
ZiQulIYlf70j4qIj2vOvp+zvRucrDZ76WhPlJvOvfE2dnOBp1obD3LcRzzo9
jDNsjHNMkdSpB3NIb11QqHRw3gMAzcaqqrClMWT/3M/2U9aJ3AwT09OY1uaN
lx38qIkpvomoYxV7Q/+LzX2hL7aLZ2868LmhEVOckWMa9xzNcxSe/9cuTDoG
35/GLpMEc8MSQ0amlDnw8bAOA1T9JJsstH03G/7B7PfcheLgCQPwxTbd1xIW
jndRFrghJkln0tyc9HgxetLAdj1BLrEvfm/vhnkgueWXlWLBSjBpKFDI6x56
mp7COrGDR3hhjh3hIEafvtAAk2iMHoYyqcy3593Pg6dpF0VmICV5iWDAUzrs
9U/ThkEUHx9+xwIChQyfLfOZjOAF8yG7fqn2Gh8RI5jL5DMB2G3HSDp6T/MS
Lz5Qmo2azR16OYSEaUWv0+1QahdIozEwQtaLLOPKoM5ZXB70538lrYt8pswL
wo+jdfmdtG7cy8Yq5AuX1ZQoafQsSDaUdFB1qFgoF/P5VK5YyWRzGXqX8SeS
K4+smQmzJl6+LtCgihUbydARVeKGpMBaEnn/4oJnYCgGXt7Ez/z/jln5nWzR
Z4ZtdGwhX8hUosOLKw3hNWDZIGimOS93LCJXA8WzaFWHo7fQm+CHUyyLGvw1
NsSFCtyxD8eiUCllk+CIDY5pvopdDEV5UO1tQU1E2RI1XCveX9j3tw/kUMGL
GMZb3LmfSC4hKbkEimJlB8WWOAHpvyDyWyhO/Q+3f8UznZB5B4bwMNRgL4b7
olGjkOOrx2TKWaEilLPjHUAIZxw9lRtj+uRtARl4iZVi/Oph49HF8JiLzZPJ
0i+zjB4HMrzG5sHbpodOBiP7fTDel2oyBHBrGO9aSuzOyp7EsZFwCSmwlNTA
UvIDuaQtxCA4DC84bw05VrXg5ATxAluWXtDZ42iXvYql/l1ahYXBa7Q3mkKc
dUWCep0WhqgE9yn24ktjj9jtc7w1HFRBCKWBXhG8FezA0HRWhTlSc4Gaw1hY
hBr9R0fefZdXt+HQzlW3qG1Dz0zD8e3NpKlePm3xZUmOWQGEIB0w28ocf34r
Sfq+9OdHh1Off9omaaf3Q5ZENfBOJLvkX2FJfSK50o8w5Vs06/nRTn70t8BG
0qMXvEeh1OgV7lOBi4WwkzK9FOH75tpkgTmJJyGG8py3BrwaG6HsOXh5Q9Eo
OwP92TbilLLzVMH7GqLt3XDysu6P/CTn0Az2Z+E+KQOGjsG70XjKo6OqHb7G
EXvRj+L/Rn0KWk1B9OqVbNl4l1yv0iRYJHRdl6aU3ma1+NhEFp/3iXI2stf7
ybfCNRDPZDlS9lWRpzh9b8DA0VF3ym0MlyV/Z5epptSzwKRz7H3UnUs9Jo10
4TDttmtzuHPmbIOJ1BW79CbNibTwyqm8zkHwKgWBwm6swGPv8nfVOyxN91g6
CeC4Vyw5SsQ6tER1KJpFjNQEOjnxj2fxdm6oJsvJCZ7EnpzspwzjwH/rvC+f
f0owD1IzTENKFt8X9z//7VUynvhys1tGTxIud/qRK/avMBxNmVFhx4qBxZzI
s0JgMEZQdjjywDfsxRAAAcIBYdlUJt4tzJptqZA8BuU0ytEsvYyHlD+s+EHR
cSgWazIzdseQA7XuB7W9FRq3ZyDvinP5gEFEtVrfv0Y4DGeIs4+q+7VRcOsw
klCOuTJj5eUJ3tE72dFWiOn7GZRKljeyGFXgM87eaBMsS7AvIdBf3xPIxmrg
0VA2JPLUIYH7+RUKhxJDhNDA8XyiKpTHS5cm0Xnqyjz27GXRT2WxJ3/RJ8NS
Zmi6oK5A4xlNKD6TZy5lernbZleRgZZ8pnh8hHU2sS4Sq4By16YJGhRJMbGW
m2mgx0XmDLxY6ekszGLDNNUE9F4SieHnLhGpDc9mc1dGUcDbTCuhL2k2k4hT
mWd3zV+1ogcBOXrlk1hIFGmaAgDUXWxYFiwdEUXAMWtGndUsaDG404tTZU83
KUodWkYmShjbvwzManL51Uv2pgbCi/5YdFFx3OB6uoWVbr0L7JgHwst645fN
mft13XDrws4h4uvLRItrUc5juFfpNT8GyILpo5e7WfEccZu9hA365ERW2KVn
4GI/7QJLuQI2zoFUJD7tWHcnJzcHyipiJ4pjE3UaLvmDd7+JpQerZKdO51ur
k/aJio9a8OEpV6LF3uiH+ys+xiMG0s9PnUTv+dqYZ6bR2UmL8unrbL35eszu
MsAGM/p2QpwVWkjSNoURyzOFiWk6gfjzU27hvYhPX+eOLfkQ6U58e3ECa3QG
rTQc0IzYR7kUV90m8NqBJsZCCyX+wiqw4tFRny11zA7jJUKJv7uMML3aqHQf
FNQj7bMJofVI63iXS2XdtHEJHm9PcYJlyf0D0275p3H0YpOX70nEmyCjoV9t
3vKviCMzs/wah/0hKZofKIwAjCbIMYGnVzipQzZtQ29S28IxzlBMq1BOz+08
jjzKnyPl29ljnJn3wQjPXxRK7njfnOQSzUkPRe+A1TVF1VgNZ7HaVyXLq08a
vYK3p1BRbC64Vwp8J1UQv5uRdE5U0w5S07ELR4KPH36Pl3GChFvb7K/72mXD
7bos7VBMHjwv191bydxofrtt3pFtgqJQCgZ6eNj3pVHsP9+2Sdm4X4XT7Gn+
tBh9mDstnKLXpv961OhQ+czz8T1EOvO+9v8I/guA2gL3OY5VqZSDFv/5//wf
HrD//L//t+gfCCX7BpSFNN+Bwv6KQsm9CeUrdwCK90fkWiyGIzPep5fSdtZS
KSVQfvcSNRTeu7Co9AyyXtESlp7/Klho8RmLQ3mKt2394sP7D4vjkhn/sETG
6eMfCl01Ziln7bw/XfIPS5UcHugPgB4Z6P6EzD8sGXN4aD8AemRosSmff1i6
5/AIfwD0yAjfSir9wxJKhwf5A6BHBvlm2uoflag4PMgfAD0yyHelQ/5hmY7D
I/0B0CMjLafCVgR061d1/bh+fYhsWD8Qfmhge46PQrr+V+r3DlxPMLktpoht
VkP1wEuq5vHete8YARPyjhadprZijC+T2oenQS6tL3R/zEcdQGtTDJ1a4KYL
c2ksiLW90C0bUvpQ0/TxKcuMt2O5hszdSKl5253NaBlTuu2HTT5uROebiaX4
yWtx6/VJii6CWCPYz2y59/Xxe9Ohegdd+7b+LJ2ljF7x/Tv3t7OAhm10THCt
b7Y7/AnRyVSJHlb/V08qrf7uVRyOnjCdnGzLJHu7CvSp42y+msYwY9Av3hqW
nyXba4Tcs3tYOdlQf0rIR+mdp7OslH4m89Norrkdr+8H8IRFaDKn6JYy6oCk
RGRBv+jnpBkgZUaI9yDAZ/IRHN5E1/M/Mc+dP0nww7CIFsQpRD231KWXeqf4
uaieN5n4GSoaJn7AIcHIMf+8BN3RL/eTnPuiwoTzlvhursRHvNcoffxeFHEL
QjF8293OhSKDD3n08Zxd1BfUt8o4yr8dTqd1e2/8bd888vIAGNnZOV5gsdQn
FHjoxNPGnLEbTsZ005bh2qfewRSgiewfRDifeoEvofCUuTKb0yw2GCkgh6Kn
vydoh/vEEjPvRDj/4x/HLOefRWiCJcxqenLSAa50Jhh3BCJhBcLp5ASjNPAc
6OQkxeoftJWll1IZ8WRFvt8sTH2KZ9GgLGgmcvnI85aTUEQHu3ELKxId7/j7
DYHcuxmOjlxrxoJl8Ig4Xux6mfjfYkKa6SdL/83OtP2X27pKXkhJml0QYKFO
NKjmk5cIy4/ICNWQxiMCTHnlhTrFjAtFLr6nhwAsaxmuQVCygUSwFHvhYdvl
xJmXYJugW4Jm3HVNFMd22AkdTude3enNr2bhV0TAaC6X1kigsOmmK4jK8NPB
YipRqsGCVl6aWs8pRp5dKu3p8dwMC07ofvy+l2oSkN3Qgz1gOVibkW+YvGVX
CHBp4PCCixlbrPy686feqqYt0ZoglqbQ3Lu2L+ZFlUXfBLnh8TRKl1kGYuJl
wTwN+gkCJRg6NHoIEztL26yoEzpvlgKUIDIz7/3WGhHxcASkDoOO6YBYygya
yyjwGHo5y3wWi5yCwMf0uEXyNK+fBRvhTGhSYJbmDN8Rf0X6vlf/nCBSWz6Y
Xs8bG1DAz1Ps53pNccPgSCp6tL6biXiCZw0sgZTIRBjNnMqyOnszSkULyCI2
fSLlzG1K3S1adCTw2ufpgFosNIpM/fzDXrZwlok94Et2/4cZ4iPDUNH3j+le
X9VLCQyPYHEEFggtpfLFt0C2mk4hhJYdsTBJEiG+oqO57dOVMuiaQu7Yr7Cy
oze3BQ5Y3bFoTQ0/cCZ0PAdIs3PHL1NljUKfpR5nVTL8H36S/3j/8rviSFjn
NEEZr8ggsDDrfGibhKkLxTTgcsxO8AzqNIdpw0TPNNsbqzSAlLYcFv8IOKFU
nAKN6PKNViZ4wynuLwOEnaL0sTxrhwTHjavQwQ5WpUFmBMIhw2IljLmXqphV
XggORylYyj64akNZsVAvubp3xLrNjv7vNwMeqfEQH6+yRRfWViZ4qf1fY0tn
MFJd4DSQB6HKQPR2ymtr6hiryrCjMsbTHhcEC0gKVAAKNfzapKKVZazfST0d
mR6caACg+bVmpLmhSMQr34N7KxVMk5C0C+T4njHipJ0y6ySwR6IcuKJ4sshL
T0HEzyOs2kuw/D4HhrOfTu3fjkP2r1FqfzH5ooM92x+es0CQrcWaOmq94o3P
R0f/C9XWwbSgeS6kcqeRBRjACF2Uaygg4QnfIaqqAWsiX3He5cop5r9DtUdU
VO7wXFUVE/NTgzxeoq0YpBRlesUrh+BlS8freIQms0ckcGPr6pENLnMQY7D5
ErPb4d5gRyRbu7ms2NnLtkok5a49RELpfcfyujseE4EK1BVm1zP67mnGdh6v
pVhwJuodTJnbI26svqUwQzIQhpxs0LXlezAUNUixCPgELBotxhTMEiu1yRLK
2945+LYaAqWCjpskILgfXhB9jZsUv/YNoOWxQgpvs0mqqGgsIlgTZd+CZLGs
dIcyc60gyTeov+1Z/lHoWD82jNkinr8Gg4n9kjE7TUM1U9hhXPlVMRVOY7aY
TXkbbASimXPRVl7CgUihNUyDZiNldWjhA7A2Z+yglgpPl8kzrDKEE2VH0NUR
XzburbkSvQ06oNFHR9vX0bgfrxAG1k4KWJr5IPYSK4UH1PgxLXbmxWmEbtpg
2+bwatCtD+k9aorbr7uXZ4+C48z4VPOhkq/bXYJ/qEkXUpDel9EQA0okEpR/
3S0+x5DpBZXrfDzeSnkfi8fWCvOOvQPwfoizt16OqpEyZu+gtx84xczUqilK
YGhmYTt4AWJBtwmLmIBdoMjVUQyCcRsEq+hktb1rjBv4zQQYb2uX4vk8NgS8
p8xIF70sWJgIc0Z8P4avtw+EcqPxiQHNUVOHagrmtbA0pNCrKzreQfS+e0lY
BfjAhSWMCPnUhi2YqB9zX+qRIdEBf4reqjreqsDI+Cl1UjJJe1fPvM95mvaZ
yLxX6gbUGdGXimXo9MYpn+HLfDZ9nAyJbDIksjwNjeZFJdxdHVPY2+QYb3N7
XQlC6PCQXl7UYWOsw2Oq572AWjtdymcrOzDOz8GI29jBNiWUtNVMrYiyVvTU
8zO7VpHOCW11/WwVjWlno442lnNpu+L1LlbilAAngm089G2PPaAGTac57Ouz
e6INLSMzf+o+btarHVANBawVYNg7wwIdGMozG4tluZiXV937VqH7kMk/l5RZ
3q2tZrtYgjQlCl7IwHMXMDq+E+SXFphHOqjkbfup94RePZQVPMdIF4Qy+1oV
7TlI/1DwvYSlcOieMzX139KmTpouldBKoT4znkXasks86WKmkKdDOxNN0Rvb
AE3n/4m7w7ouVDQODYmZwzSeGswAI8ouFjTgV/A5DDf1ZFIuRLfA7ppgt5kd
ef1bM/dbWfit2vytWf6tnP+tXPytWfitVv+tJvzWLP5WzvxWLfnf1Ogf2d/K
Zf+PqvdHzX9VbdA/cr9VC/4fVe8PhMy+yWEX1dZvNei0hE0q/qtKFtGo1n+r
1LxOK0FfNbpoaOkXut04KBRE00xheRe8lqrQkad3vj0MJ5sAThbh1LuDOhar
+RLNOSEplqSmVDcGzf0N6OM9+CbrJ/s9/dDxtOERdiNPUjMcOIkbwvYjBi7K
ZO8Cl30vOMDOvwTFXPEg4xx0WenUeJWwmJVn+7JacWhsq8qCWtoTf++Inqgg
nBwMABnvQIlcf4D6+sv3nhTz0ZvL39X8GLcZWOoSU2xvt6u2O6F3i35hFoHk
WQQ0Jm2fOk39wnzWewwPVMH7rSF6EQq3AQMyUzDANSpUqP+OvWBS1L8zj5OT
zpTSmXw6fK7AB+cKNlO+fOBO5hWbn1jGgujUvwY7UF4TQWkaeBCpoHjNFkEQ
FncFYU0FQ7AjOpegXUfGYhMSexN8BaY4VbwOvtuqSUGoVIQCBeabTKqoz1wM
WwaoHXoYpRthNTQPnjGNG741tRJtHuvUoUnIOwY/IXQUKpY1ZwOFfYwOM7zh
FQeGquNZK92JwyZkbsjQem6sePgfFUEYdIvH+bIUuUjoPbBTGBxN2IXCmf80
IUJpRRaKlXJBKBXzud+VvwmZTKZUKhazuWyZEvlLOOd7YIYgmUNqlPgl9CyW
7z2MQvRaRLBkqQeISWxgrEuydtpEx/0Kq8sQ4jDcM8JrdOESLOpDX9NRm65q
gyHlnxWBTl3xW6cT6DB+P9dFjuICRyrFpQH8vvGHOaCKN3xACS995vau1iIe
26wR0eHxEULQbR9Dcq6AXUkTPcEUBqYfo8awzoygndr20gof0u4mlkKmBxeU
RY8U9w6RLiUUjvwUuZDuJBnZaM8ZgbsGW9JxtfDiMWZ2imZ1QpcITm/KXaTB
QvA+5bu6hFMUkla47+XxhIlfEGLyOFav9hyMeXNgTmxGGa+cLuVSPA/mbTqZ
ykx3aEtaWpS6sOiiHbiwiaEWecCaF+Jkh3TeG9h2pSw3jWIgXSjlC/lCypyb
UbueDheEShSC/5TaarEspRDLhR9sqlWXgKh4ZcoreujMG+9y6xJJ2fDflKSn
kcXTLLtOiQexyfabwMrK1JbWTqVSAM4SUjLLPIKzhlTKT5SX6Dk6PvF2BFT3
2WlXF0GPqKrIw1yYKANAusqupIi8TNQDs7JD5O4IyLyTL8cB+gZ0VWxbJbKB
d7BVhdfBxoX/LOgCnRN74W5c3t2IL0tFw3PVZWSB7NDJ1l5kLSz0bCdFn7Gl
nxbLWUOtVDK79MWrZWHhhEiyZ7QhRZNRNZ1Pg6ATMtlsQM0QHGVKwlsFJUUf
sGu56bJ7M91k+j3tuckmwZ3NRB10+E6//mOGMwzhEPugODBUwpuKAwa64utF
XAb0chHVgPhLUg0XyLUy+A3sGWw8iPJUCDqmp0oUncNJ9U38Br5IB9/SAIuQ
D3ivLGMhVNiHbRqKE85WZJsqfcIU0pr+wkQvlWyhIlQzBeDoWp0vZIQCX6vm
GnxNyOVLtVyhUSzTfc0XVVyuuejk0WnD56m567NyekeqsjgyjFMCLQdylMds
HDxezjusAdgIjLm7IyrgCVs1aSGTL5SLhUouPxay2UwmnxGY0dFHTx5dDWwn
D1bmZgdh+iylWIzZDimBqOYHkVqZFrNZgc8WJZEvZSs5vkJIhS8UCqVJTspM
ytPyznK8UHp97rZ/ue1eVTRzaTLLxF+TUYPAVzperROGCk6zJ0xAw6VkstxR
eviI8q+dXnSLfePypb+mDUApAHFDVKS/U/SQRFRSIMwoDv4sAe14PMmJakbE
wWZqg2ZSOai3PWMR3eK0d9w9wG5g7w7BxnuMqFjSvz+7xNr8LcrPtD3aJrDX
SbgXou1/DeBTSBLgZKlgBIdNxdBDOiPZfKZcemXchzU1Rl3wePi4TSSGFz91
tJBFHcw3+NYK3jEjUX8C0R6YZrveIXxJ80xhoZtXVOeDwuLH4avtIbHrPaF2
HYXhhQRE0AbLEmUTQvXO/pktUxfdqA9HYg+AGgwYILP0KUAneE58CFsNN32X
36VY2hHgki3rUUMmhY9oG+b1GeezuVJRqGTTmDZoZlibsZDLVIpg/257N0A1
O3SyQ2QJPfRzxe3jV8bYTDJ5zEtjbSimI9daKPYcMPVLvYINooQ0SOQx7WYu
TjDtHKYLUUB4RFfRARwUCaTgi7hRpvxCVJWNYbG5EReTsJVNf7LdW8jiUvSQ
0gGtBDxIa9gGMww717khca9VLnsReDtXYBkQ3Qbzbgo6kIIDmxl3XEQHSUGA
MDAMlAD01J/+BoU7swCOSAtfM2fsjMA+IF2sFCtCvlRgC6DbQ78ebIXCOWI0
7xlTdp6wIzosOynICmMATyiw0WMnBIEFOdgKq5AnHeOu6NFfEDW1/WwbfBvJ
MXDKPBHb80P/SNAx2PkaJrgBy0jEUz5xESUgKjDoUg9MBzutsW9NcTE+ZERj
LN6rPTWemC9RlpTypUpeKBRypXKuCKyfKeb5Z76aZ3M5MGRLmRlczQIiGW9i
Y1kT+uEYjCsms/zQGybKqVcAmUY3eCQPaGZ6+ZhiUShnQa3misUioFPI8veZ
aoFhUcOYmr4Fe77d1Ix7cJjAx6DK6Md8Pl8Q8kJ2bDCmxURKDjWQDtlcW2zy
lZJQzlbysPfN5zP8aqrk/L2pYdnoRhoCUackBiGwmGz6TZrFsAdUT4PRnfZ4
jG00Nn+xudqwe3S0/dkiMmWzK4xjYqkR9m68P9XwWMgWNYeb/uufFjdEw9qa
E4z51PFmfLiZzc6tFiyF7g73cXXRgk0H11FUB6uxA1E29NTL5sC0WxAbgyjZ
2R7gegqtVPnfzQn0mUWQ1uvRYHEvRYKX4C0oGchCHGXvpCEk5rxQTvxXpOQ4
HmHTI2c83oZpCa1zP1LQrzB4xCoo0hJ6xJFSp+y0D6MOaQa6INHRZMPV616H
gDeNlqVnavvzCrNomkgsgWL75/zEq1i6vbWJmdrq9ICQ+S5Y+BqCZjG5weOD
557IKTRpkkmCoweMmqAprhMc/9Lo63R3MGoFIjSSpMI7QA2+8sLiQzzqpeej
100nm50M0H5aiyBrhfchO19HpP03aISlWKIM/9A2jAftdj9s7/wzhIMXXeyB
ViwOa86Gg+0YAiJLCOGJHiTanviQfUfVETT99AksCoJFGSADAQYr7tPJCVlL
qoum2MlJ9HsMPvGC0mNOuI9ZeqvAhxdbuBFvGKRrpZbQeBpbT3a5mzmf5TZ1
MzcQzcw9aaZDzsA/B+g4IVJi87Yi37QMp3r90tHlRTb3XJNWtVFOtJMhFQco
KVK5zjLTFOzpvb3c1By1WJ09lJ/4YaejrJIhFQcoKVKFi7OiUrGXhqbPzU2/
c9cnT73StKfdXydDKg5QUqRuxw/P7ZuH3LS5Elur1WZarTTsudkhTiYZUnGA
kiJ11hpLK63TaU6ss/Fd4ba4aRLn7k5XlHwypOIAJUWqP64/jDbSLHPeLkmT
c9FtVfnF7ew++2QkQyoOUFKkHs+ezu7Nh9VjQa/fai/ju3zrvHivtJoPCSkV
BygpUnnbyF2sO1dX952hsNKXc9cgd3czUu8skiEVBygpUtfFM00qlJcZSVAb
tzn3qfuQqd6PjWm7mgypOEBJkdLzPVK47teXq/laap7p8h3pb2BPKhkJeSoO
UFKkJmTwcnm5XPWU6WIwPetP10RqGx1z1Ego0eMAJUBKmsKvm8JDR64I6sOT
8lwfOZXa4+a2cdkiN2bv3Ui9CSix7mvVjXytN2gMbzb68rJSvT4Tnf6Tfi/O
Euq+GEBJkVpNxg92pfcoV9yK0cvWFnzZWZamy/t2QqTiACVFyliWp3xJejw/
Lwwe+Z72JBW789thjW8lFAlxgJIilXVvXLEhNDazp8tGL98ejXnrYbIaKWcJ
kYoDlBQps5ariJNL4drq5MfVUW/cLJWX6/7IXSdEKg5QYt23Pq+vex3CD6vK
oOLOr65U1TrPazfVhGomDlBSpEbC2jVvaqvnh2Zt2KmP7mfDzv2jIz+/lJMh
FQcoKVLzwSpfbK1m2q2sVKbPj1p2+nQ+UfVxN6GaiQOUFKmbdmnTHC9UbTBc
X26ynfvi9MVtGXrj6f3C801AiVff3CRdVSatabNoVJ6LF5XbhZPJVOvnCSkV
BygpUjMpqzxllhODzIdjfilk+OGlra7Fx3pCczgOUGLheZXXqtPnQufs0XQa
jUtrqMull4Z8LyRk9DhASZG6d8+k8aZ51q/3uu6DtMxe9Ur3DWM2qN8kQyoO
UGJ76raj6pNWtznnpf416bmN26vndeFheZdwixUHKClS69ubXL30fHOlzyTF
LNXyj1eF3tnNqHKfUCHHAUqKlDCrS/0VX7o0zMbg5aX2Us3Jre7MyA0SGnlx
gJIi5ZRFY/JSy5Xy6p1y8WLdWleDh9Ki/bBJOH1xgJIipeVuNrXi/cX1y1p0
JfLUHBvlvp4X3GE3GVJxgBLLqefOszSZnC/FsdFu8k/NxqObzedmUz6hQo4D
lHiL1Shf14S72wveMS6NZfs6O1oUG5pGmgnVTBygpEgt7y+zpjJ9LLTvpbqw
vlgNpxd1/UZq3SR0msUBSopUr926V/RJuXA/FC8Wz0+15lyrPdZLfSkhT8UB
SorUk1257eb7tfLmQZvPslcT8bEmiNns9CIhT8UBSopUZvByNXi5H9/K6kPh
5nrcu+tp60dVt54Syqk4QEmRusv1OkINNmsTTbi76a/b18pc7ErCyyihjR4H
KLE9NRbbG1VrdYwL7fmyVKtJD7dGh7cuE+9mYgAlRao0fBi6tXLuXLMqz/WJ
cCu0Knm9cpfLJbQS4gAl5qnh3XSWfbhsVq+cs+vSoz0V1mr+iq9eJfS6xAFK
rJC16eWKn6zK57Z8NlHztnhRqbRe8gqREirkGECJvcMbZdouv/QL4sqwJuOh
cDmotJo3zfu7pN7hGEBJkao/rJa9UuGlaI26craae3xcPp5pnfWVktCeigOU
ACl3qsHPbGXderwv1PPGsL0wH6vL+9G49HBxl719//y9DSkprVyhs364q0hn
01tTydWnledMkcxX5kM7ofaLA5QUqWF7XM1khKLIn/f0++qi7fRu1sbiUXtK
yOpxgBIfGa1K/NVdtl69tTL8de2lUiLV3ro21nsJVXIcoMQbd30zkcTp8jrb
4Lvzm+noNpst3123LucJ98hxgJIiZWm3l6Q1eRLX2aKaE/SCqTid7vrqepFQ
0cQBSopUYzY/k9u5jT3pt85716QsvbzwjtTtPSeUVHGAElPq8UKUFDm70puO
eLYaTpRud+rkRplWQp6KA5QUqfGiWbtqXNqju6eZKE8Ka119Khfl5VxKaFHF
AUqK1HM/d1/P9ESr1armhr1Jzby7O3PW1fplQkaPA5QUqcXi6Xqu5DfLs7FS
XT1Y/ZUgWa05r/EJeSoOUOL9TG0hnzvnLyMn36oIt6Y1Pe/q8kwbZRMaL3GA
kiLVcd1xteUKQm1kyevzXLc811bZpyeznHDjHgcoudtMV4z1ojYeXz92l/OW
XtDFu+JT9/4loZ0QBygpUsqdXa9X1fLDI29ejaolW7m8adtTVekkpFQcoKRI
8Z12/2ZQqC/d2zvpqjrLlaThemVUR1pCRo8DlBSpC/3ioVmatK+vtPr69v65
aDvKlXO+koSEcioOUGKeGk+6Z/MruZZ/EmYZXXpZ9x9XrXunbiR1xcYASnzm
sMk/316fXbcH5Sw/sRfX45t2t6gQVXhIeOYQAyixPXWWs8cPLX1a6V6XS6Nl
VhKe89NccX2ekNHjACUOLLk77z08CA9toZlVhuPO5jpvNbQru9FOGBcUByix
lXAu6I0hWVUntxfjFbkyK+WF/vAozYoJGT0OUGIXx5P7kpl2n8rO04Mh3WjK
4+O9NFytWp2ElIoDlHjj8KDc5s8fL61sxiLF60Vb29wNc2bfIQmthDhAiUNw
HmZrTVAmTtHMyxeldUt4uJTVzP3QTLibiQOUFKnixfnsysxmHwbr9uhhwit8
ba302i+9u4S+vDhAiUWC0ZHO+879xbR281B/NC4FXb8qEqHFJ2T0OECJYziG
m0mnosz1y6fL0vBJns8fxvfOet5zEk5fHKCkSMnjdtkqXfTaT9V8odYn68eV
PdW0qnOWUKLHAUrsS+BfxHJx/HCWsc1V7b62Gt1ev6yUq7qV0JcXByhxZEK+
25OX9XVZHTbPrbpy1n2amLX6wMonNPLiACW2p6pXlU3rzJiqt8KqsVpJ83xB
1p4X2iahjR4HKLGNnrl47kxron2tqcXKA195VMf609RulhOuvjhAiUXC/Kqt
Pmyk8UZ3tOUoA0pircrqSlwnPDKKA5TYSpisLiqSrBanSj+zrLVn1eHNTUMT
+5uERl4coMTRLg5ZdSa99nnt+uq8kbWfrdnI0s361SKhLyEOUGL/lN19Khql
1TQ/vx+79YuCMKqPlvyqtU4oEuIAJZboRancKPZrjQHJrPON6vN9L+fkm30p
n1SixwBKHNZl1Qq50tncyS6aF7f1oTUaLByQMKWkgbpxgJIiNejr5w/Tm3pj
3BuscnO9msm8zIrl/KadcPXFAUocw9HrjDP2xcVNoUcWRlN/uTs/07tnmjhM
6F6MA5QUqfZZvZoTtFmVzNVZqz9wx5tOVcio5/2Eqy8OUFKkKlM+K5z1zou2
0JclY1LU+kamaF2utIRbrDhASZEqPz+P261RriJ0m5P24+P1jfPQu7q8r9wk
9CXEAUocgvPiZm/UuvrQW7TLs8vhVV1dt89mK/0q4fTFAUKkmiztwudk0QDT
9Z05cNTRc7+p3peX9/ll2VUui4VRQikaByixYbW4yTzdjdedaksoW4+a83iW
rWbN8aqT0FyIA5Q4ROFRkx/Or9XpnFiTubHqNrXHwSrbaQkJRXscoMTWXuap
eGPajXGdTJ77/d7lonFWf9oMn5sJmSsOUAKkLNGx07bdsB4Hrbu8XawPxQdS
rXS1TqbfvxbevwzfBJQUqat+rTu+k/mBMXp5keeFRubs0bhTL9vd9xtWbwJK
ipQ+tWRLGFX6sllsjBdP2aaTu39c8POr9++13gSUFKlZr7d0+kL33r5vTSeZ
+4Lemw9G4sWF8X4l+CagpEhtxHY7b99O82Z9epbpXPb7g2XufpaR2gmnLw5Q
UqQaYlV4alxftviJfFVY8/LidjJ8UTtS4/2G1ZuAkiJlOovO403jZWg86I3i
oPCi6sWO1BSkZUKk4gAlNqwEXqtd3AlafnSutO3r56v5VXcxuVzfJpTocYAS
R1fWOlKt/DAYZDq30kaZz580Qbh/HszvEgYoxAFKitTLQ24p98ejx/PHrnw+
XpiStbq7dh+mSbfKcYASR1dK921Xnxoj4ercAvHXGtgz89K+X+oJdxBxgJIi
1RrOM85ILM2FS0kkt4/Ny+eX4mqWL9QTbpXjACW+aOsatrA2CuriQrHP+cqg
fXZ3cSZWdS3hDiIOUOLwvNvNJDeXngfGWSvvXCzOrtZ2tu6SSzehQz0OUOId
hNa4fOZbyxxfKWWLz2TskIw+fTjviQk3gHGAkiJ1vnLaQ+mi+7C8qd9lq5nO
ujos2JX7Xi+h9ywOUOKjB/Oi1lQKY71nFYTZUJ8VjOeh4I7UpJ6OOECJb2pm
VfFs4m5a19dW8VrQb+oT81wc9y+T3oCKA5Q4ZpDPXVfLY/leqBY0+Xxt3G54
4WVcHqgJD2niACWOmnjqGrmzeu+pM1MHl+Jw2Lm8en46nzXWCSV6HKDEPqGm
8JQT+/zzUryZjfjrcvmMrJ16V5US7mbiACX28htPTbM8zAotZ5o17Iv62aUx
KK/7L0mvZcUBSrx/7xf768bZvNqpTHQyvXlSz6XMtFIUFwkZPQ5Q4vAga2Td
95TLbn/z8HLbWKr36lktc7NM7KiKA5RY98md2jLX2Nxs8i3TmpcEpZJZF81O
v57w5CgOUFJzuNO07i+u7vqjhnZ1Xhz0bq/KZxm12a5v3i883wSUFKnrZ9tp
CBP73Hq0ptfj2+sb/rFyPn/QExw9vAko8Q55nldr9n1h5ejP/bOeIPWvFo6g
9a+q73fpvQkoKVJyr/rIu9XJY1e9WSuNydU481i7neefKwl9CXGAkiLVGsgv
t1dnhauane8JG7e1GOvO+kEVNu/3urwJKClSz1Z+VWopen3RFp6dbEms15/O
zi23X3j/buZNQIlD07XpuO5MnGGj03/Jub3O4J6oJLtcPVjvl55vQ/IyrPWw
9tq1i/kkDd0+OurSMnaWc8pNATItCMs9+69Z9iea7soSFZul57prRzNEQQOa
Qt1yMJ0SVkLDkkw0e9IdVnjaX//aK339iWX75P4jtiK5VzHVTlYT22v1+xGW
X8bkXliJUNFdWkEvXP/Q9rOg0fJfmHqZVrLE4l1Y+bo+rPKk1m/94x/wo9cd
DZp8PYAULhuHxf2wEqKCdXyxcLlXvGu37vnJCR31ycmBUTy5QP6pQuTfuZsA
D1rRAFMJOor2uoLtZFuTCPNwGbRmeugbC/Pqc4pGyxs5BJMtTh1iYeoznbAi
p034ltbbpUnaRtDLZw5LGX8JKhZHE9pFmBB4J63IXiVqr1YDqCmeTe/S5umk
ZfI0byiWYqJ5UYt89jjl84mXt80v7o6l/egwgH+UmU5rK9uMftaeqtB+Wejd
utCfaNJJgI2FvnVp41PLS8BM5OPfaeV22aszfnLC8kSz1G2sv23/tMoXJq2j
k4Cl3lyNZqFjRRp3YWOBU6yM9kOJmE9lU3lKxg7wXlDeFcv20Un3UsXRRQg4
A2l0wgpkGLRy7NJQl5RdWK16TPqIJWolizgnJ79T7P/+dyx4OKiyotzYDWbd
5USO0opWFY5UF+ZmhBW/wuS+QCqssd7vdhss/Vu90+2P4cfvXs5HV5Exxzs3
AqMYpUbTHwKWnEZ6xowjxbVALuIDeC0bHEyNn49O0Y+ileRe19c8hWfNm9sG
eygU8+Uye4ilpmGRY92BapeNmpaoVWDJUKxYNj5atBd7Do3Tz0rrpUDEJn42
P68SNLFiseZ2sabINOUZyHLb5ocbgKDZ+5CSoFtaeR2oQ7Du27ZCcTI6RYaf
3UOSHOu+ptAabKxzg1YS5yIMZL9jpEc7/fpJlnnM3ajaod6DNzNj31NiLPc/
1vY9thzpwGNeFg+9cSQXR475G0NZcEHpOVh1A6d5m9bxiCYrDGXB9ZjGBL2E
Neto6Rya8dPS/GSMr/Ii7k+E+FbxVK6HyS+VUILUFVZeDar4GKz+M2ZoNC3M
oI/ZmtO0mhZLp8iyV9JEmUFq1bpX2FL0LIcqQPRr/PrFmal8pLUoEWvUc77u
P6z5PokLkZXCO96phVfbcLpBi3vboVLYIHR0GZM3bnM+Rgt5T7alUuGdSjO2
MqHBymGDnGNpS31AQfJJnIa4Ssm2obqsqiYHdhOzglywyrDeqIElxuaGVx9Q
NbCiDCt7spPc0ktYiVYGlleC1UqrKftTrHpo4kixepYPBAaK+VUVb+poWk2s
9slsHSLaWJ10QrggJelks5WXOH9BIcIUSFiw6EDaEqDSMpKymWY/xTrCMFnx
g4BvoIdoAUVkZRR2mBDYq50KLIWY+llA/crFp9tCnjRlrN+zBnIIS8lj+lad
Ds/2irXZ7sRR91av5Jow+RLNChvlUNDrn5QUSZ16laBMmqqWLioRmNdPAspU
YIiN/DV7Ck+8HKLcBHgax0OzJrMErD2vNhUYaaCquSGtTXUKFraliBosQRBf
4lQ85UauoYEVUnUt+HGr4Nq3VXHJNdwJ2SyMU+4Mc9djM8KdiRJY32CNDw19
NjG4mnvK1edEn60BuY4roq3REY0VZlw28Me5uBG5piUpwDOnXANUy7kLxAEy
VsGQc7jzf/3zX//jX/9cAMSNukQBXSMqTKSIdbyaS5Grg7RIcXcKPoRpOUPb
U+cazeGweXnZHHLDavdy1LzEcdk2FmNWRB1zYCuzOaoWeA5MbIlz2FTA0tmA
gVo3VBUWPpviLlYjHkpzy5AWx5TziTdbYckoKkwEvlk604S3LAUwLaJJyxIH
rO7ZXX4V18Oy83XhTbQB6co9OQG8TGSkCVbQVmy2Cjy7ck+tTy8FrskKF/op
cOmgsJwoUBzVIv4O8p57ojfcivWDMgoIgFaFx/XeHoYKPr/M9KuSqn5aX7pv
879F1FB+WaKpYG5iT6b64wTVS7za0eomECihFbrNYmzPWYXykOmU4kYgmBUd
pu0loDtbP1hoUZVpwWraERUCfob3oNe9ys6HQ1MSb1FFCGBLwPJY0kzLCAZL
zYqOyBgjeGRT22g7mayl1yV+tSC0kPG2ajWO0tWwdJz/mGb1ht5pJVbfEsVq
cVgJQg/SE9/u54TqNrHw7VagN1Av2Ucjw9vh2MFWOQBwyi10Y6USMPPYwqHl
bYE9qfm2JSeSgUofrzJFHFuGshyHtAtVkmhtdflGamrYmA2cFkgIV6zIVJgJ
FP6G7kXo0gl/6le0Z9+CGnhhH9KavrBlBp1g415cWbJ9J5qIXsJrjRCa39zT
BSDTcJNmYV7xgGOQC2FbhnPoAAVUEN0cVvbBhz4cOof2G9K6Xq9zob06N+y2
mYDyDbYU1/fLGjIN+wkrt5P1XESRCKSHlYDzdgwsBdpJppj//e9YVnj7ACtn
s8Fw3o7O/8b/CV/QFNWUS6k6x60T1fmL3VmLnyMhg+QF+uBeDmY1JFqYIRQS
p1PXoiaPt8R2jCeGIdai8KxbNG/9IQXFk0PD/sfR0TdqRTjpDhoy32AnorsE
/tuAGfxkH3PftovnG3zLg7lw8N/wnu1quJoBk4YEDKzOXp37Ayv56O4a5sfV
0NwIJ2xHmbTdUqumlCKIlp2m/0lnM2nEpW+JMxcWVv0FS+SJ8KTAXUmgZrE5
/Pril8yOB4V7HEuZMBswnS2UC+ljsMlU9E2dcjheg46mZrT+fbEu5jP7sf7S
rubbHU7IO3NcCjpWfe+xJRp1WszE/GxOvRasD2zBm6wFRXwITUQTrdpvXLYM
k2k6fDaC+p7e+80RX7+6ZCnys585oYh4sMokXNOvTOKVdEdVhwRdMjbe4jed
8SZxUjMFq6qgeNBhuaiOq8/SCJA/UOqEAmQF9HTmc/zGXfzrnxPYRp/6VSno
YPhshY5nZyRsCOEs/1uUbBBBdmpmGDOv3IqspMCsAc0lCinFSRPbsBTJpnUg
sN8B7BtPuS6gjV0KeV4oR7v8wvqMTopvTmEZBVrDJ1SBIJ0X8nmhmC2UxjvJ
7jHX/Tiq28cdMO14KlthAeLLsaKPPdeFPB5dDI/ZaFFycoPqaIjVUuFjzRfo
W8RQRyOHgoW4dXV5X2GhJ2zFuka3Op/Jpf36SPgbiXGrWI4LMh4J8QYVkneG
Dhsw1lU7zWDx+76iBZdE3pOkfhUm+hIEIjM5eLRD+KDSpk88fkcx85kMrLwv
lOm3eG9gv+ymJiS9KYyHgwzfeOlkfnf+li0UGKGxyqoIOkFHmTLoXo24oauB
XttlM/oQNLDh8AYrSBWwVBvEjgHK/5RrWdTX9o1j1CQomrYkdQwTbCJ7oxsm
mIBb2KBLgYUVHYiVmlrprGkaMys7HQ3PXXtgzHKD+0n/+nfcwv1KQWzLc/nm
JNp5kXJMYrjKGZHnhuSx1YeNMMvvHeNroXkILivBZWLJNcs+UIoY5/M7lmOu
Ui7nMsWxr+fGVY9OY2MaWWtjoNP2QbPRuaofR8RmA83gQF3eGdYCa/EQ2IF+
agzvhseHRDce0oxt+mWaVRL1C9KgG4ZaIl/aqjGBtVdVcdPnld1pA501EFdU
TXfA6gYp/YlqjoNdRddxNg9W8uxPCbNcoVgplApMUg19SbVjkqPUalEnybjd
bY0bBN34YxhClL7M2x5v4+5ZtK6dya7IJPViGFrKxQp+Upq6PtM3VT1XFmSi
iLzYu9Se2p1573ltSJLQkTat0sK+UEVCzsl0fZWfDOtZrdN/WfWv+w9tkpX1
x0HqZaqSh7qmOaA3jPGlJ24j9W+qXa7P9i9D9Dt6WhrlAxXKQnjVRI4ZfHEo
eMvmViG6Lp7CjAArUBMjK3BnrrrZzg9ue957DAlgkWywdSF22pBn8nitzZ+u
75XBWLx4kJ+d22XjjLTy37tsMpVCPitUxn1vEzwetMdhwoyDwkBsorEosiKN
q11Gw2GzOvoxREqkixDuK9UDDxn3+QUEvcNSVBsgO8Fwh3eZTMqUp3E6pDUp
dF7mgmYKTdAheaFcCWtr6ISqE5loBvxhmhuuA9vQEB2UhbJFmOgRnOe+IqJ/
IYwD1MmEqYPk2aowGBXWY0/a46871ValpW3zpQKvvDZnkDqI258Z1O56C9jq
xy27VzT77nV3W6mdP56NG+3FY19W9aeaeEM2qjufPF//F627juEMWvUPoZNQ
2aXTxyy9ueFYU8mz9YTCwcroYLV4FdIipbfjDbtWo3M3UJ7W57YBizKXLRf2
LUrKhW8QJuBWO02xDpj3vdT62Svxg2bH751OkLyvM34Hr/gZaQ+eN1aj25w1
VzAjQi6fYTPSbfbb/9Z8qhBz5nFpZi/Rk9FhVn4eu0Jlef+yQHWRz+Q9zkRD
0p4bZpQA4TKlti5Kc4eXQXRgSWPYbgNHzSywkb364bD1VuCLQ8VfhUIB1wEQ
u8FAcENJod6RSywcu2P7v907YYvABwYitQhToJPQFOyohR8zIEq+K9eBp/9/
ddfW27h1hN/3VxAbpNgEK4uk7lssAslX2ZYsS/LKdh6EI/GIpEWRNC+S5TZA
GrToBW3TAG1RJGkKFGiRFEnz0DYIsCnysD+l693NU/9CZ84hJepmW47Tpgsk
u5LI4Tkzc+bMzJn5ODUHi30ZUxSkPTXWVHSsM0OduJMt3K6HL9LEl2UHx+f4
LtrLXp0MdnnSqBFupGMEvF5eUxAPBr9g65sbk/FkE77q0z/rYJ0GP09BXV70
WlFGBp51D9+mCT/zA5xtEANEGpgpYykkYvJITnfb1n3hoJZHLiViED1MMgpr
YqbftXnFbiZlUxBCZJs1zK5DGKefs1+mQ6/53Bgd56yOTqdmkmTRmbdHdwSx
ECj8Kr7gVygTllYeM3hjxL/J6bTNdgffUT0ZRyVEIW87unGJibkWL5K5ZE5u
VlGXcPqoSxg6TSWKmvlLw6HZMCjhaceaW9VjhePt3djm6Yk52DzXMrrZMjx/
p2jYj05OS0bDTjeqSql+nE4fZ+1Y9uiEELrXaWmHK6vWVvqo4HfJjk9Etevh
6SEvBNJ7OJKeLYjiAznzQBSZoCDIEyp8T8NqgQEeHSOzeVaTsSosd5tjW6Zz
mgSvxwWD18dGaYYS5lIh6L0vrBKTKES41+cCwR+lzIREbiYQWUqk05LYrGP5
C3paweXNdRMeZZmYuG/Wq+vNPZuazZoPQeJlBn7HyVlnttRRTMwpSWI2gVc7
FOs1F3EgrOYA/3KGC7Fgh4pxEqHJKMP6rA17sBh1PE4z0eUT6pgKcsNjwdC6
W53I63rhspoFK20q0WO5sb7FxqKCzO04eGfw3dQCkNLT7J6T2llAiQmUp3Dm
eSmR27htjHd0g/LbYmKS/S0mpXSTj/9lWXxZzkovy7kF4dl1hjEnCy49EKTU
bWfBU8tlwXeIY7iOr9FoHlxKx25F2dH6pESZ5WkgiliUBEOO3szOy5lE9irq
LMU2vReABQSlbaIfGEhms17a4Kn9B0LeNFEHwwAwqDRobAp3+bPgF/BWFab7
obLfHY9d9Xodlu9fcfmicHHHYOoRuByvgbOhPqT8HMI/j9WwjgD+7/ep70Rz
nMkYML9EnK+7C6QSGSm13C7Aw+SNatRhTl3pMKf4CZFGzXP4D6tb8C3bE2Y0
d8WErvCcU/M8Z4joOg5arajLdLlvXOzsqK29THLXS4LpTIup5Nws0vWmfI89
+cqpZ76RqbO80mxK/vLpa4cZ8BDXu+UMhkjpTDqYPWY+ejOZj1sR/NfXZDGR
zCQTmcTiTEWYk9jN76z/t8d/M+kZ6Mrz6pz5xyns9OQKaW6fd3btlqkZYh5T
EJKUWZCauRVGpL4RRkzkaAKGjIqIxqWm/NPiSOhyRu15e1ambKm6i2qfSElh
RBzy52a5mtRUruZS9iVjMxy8Wd4mFcnb3Ha0eIPsziK5TmV3lhrp5dJMy/lU
9nRLypWKeKQqZ8QwqpstB4rsz7qn+S12Vg/XxSY3vagHKgobtHWJnkcIzT8+
DMiHXrWLZ44tTPaaEVaFhaaszpSXmfKdOtioNyEQYB6pLPHzge/OMAQVlDGl
xUsQBsRra6/1H+rK6aAlahuG5n4H65seVnZ7ne7BdjuR80vasVve7NlnsdO1
mL9q7Q9LqlG0v4NhRFpyv7kqAOmSKoDcFRxf/lnXKQKQAqPDNHPsPVx1GKMe
VI/SkvJIr7AsI2xNrwiXpVgiDrzlKrQ3Pop2sWHAN2iczW1BagUMi0L7YBB7
eIL7+sZebW29NBVaTRNG7hYg1HSp4d7H2mAVA7jvCwlJ2CZmTJpi92yEtXCk
PI7e3NrcKJRGe5UHbJ5nOKapBDVMjNWsIc2dR4lTictp2PNlHpTJotRMi36O
iuYC6bCPK9MP9JW0LKXmPGSF9KWVAW31btNwyBnk7v/ccHAnCZwixjpJziyw
HiOFrohJb3e7XTvrlF67vrlIJpK3anUT3wrmBUyTElcxrV1zVo/LQyvTVJdg
GkvV3CbX0sIabTOupa7i2hSh+NJ8KvAzbOaF8zNs5FZKkqX0VdwaNEvOSYlu
DSvZJbiVyt0qs+Tr8+qWNYxl9Ub92QHXRPkqrklpsnkcs451ZRkdk3My84e+
90DwdM+gD+9GK97D8mo6rnyfqCVfotr87ht3eFlxPqiCHhUVj6qk4QrepQ1r
2yfOcFzyPqoF5w1tQffAt6K4nTUm8YZHrOYPWxtZr/ZUB4vlBE1OvEDc4h31
AsFeURN71EBXtWjl5Qyf8T5i29i5gj2EtoOd3BNtIPgQ1upEOnTUAKM72M3u
uA+YBF4SplI6K3hoyH96iXtzC8KaV+4IQkx4nWU/GpE1dR1YlwTdP9s42d/Y
3m1TQtNGsllWD82eu3YUkmUe5PXJMhSGtNo6PRMPj7KNI2crUTpL9veyphzz
d9QR2fruMlTRp8gaw9MtLTfMNHf76ZakH2r2wemRY4slMSTKUgfXp4rxe7xu
9T0jM1D754PtRl0uyscDU7OKe+bR/oiz+fz12UqIGj8pHD/qZo6GtYFNNk6H
Sr5z1kgkuuXjymj+FXTWeHPcRKce2ojrPssOacQmuv3iSjrVqJBVsdE6rg7O
6oW2Yda7nUytx14tjY9ndSAyCx1598TrnuZQokjXfTQZE4j7rfOMf7jqxmJH
536tMTwsl91eo9P0avtYsgiLI6Au34T62ZZ2ks8lO+dUSe+Vi/1KVR3U67FG
tZcPeblWK60uxTil57bj+6syUYrto+6ZXjdMfb3dzqhqN5su5EdCmpNQuJzw
OJVQKTrb8l5z/7RdPsibpaLZfKTJcrHXKLVD6tHaoNuvJxpbjuqM5XAmLMfB
Rqm6+WBpFeDIJseNHdEvlXLynjIwKi31sNDfz9trNk3dVPgB3apWzVjSltM4
62yuddTqdqmaTlUL3bX1YNgswb3soDHXHC+3zraKg9xW88yuHbXUzl7TzBiP
ihu04d5wzIzsQepoS8lJxtGJfrpa93KF4+GjtfIGPbBLI00tlqvXNiXgqMWb
2d31RNWXzg6ltKZubg+cYaleHVQtko+IGJyaRWfcQQTKTqn50p90webJHZeS
u7KQjhqPbMRxVlYel6SMLGakRGIR/5ai2cOYXqXxBMQnbND1/OqNBgrxwHiA
uYQs5W4+wAgtWRTT2WxKHEtgb7UyucawQ5wToJGlBpeNjp1gQsE8IzOy2naM
GMYKO4x0+YPhplh408RsMlIaw+iAirw0FZa9a47PkNDh4JPLiako6cStkU5m
E1lM3DIZBNSTt0Y9JSfTiVQgFWEdncaIuhcMShXEgEKLyK3ekjZpf0exxUwl
eUDrvqvlV6XTHC0UPFsMMAxHKbf/t94XHHxUN5eQSLhWYWdKMDoQWjL0k8gh
+7Bnk3GTCvuIvMUzVQZUExzf55DXIv5hQDogx2JHgEiKdeBG4CGwc7hPwHVB
oeFpF3NhGEoQhCYBIAWPSXizdMAl3iDMfO77gs17Sg2KmFLsCQyyYDXak3dn
4lMYT/EeTuyYH1A0EpQl9a4dgU7nzFF5lwhg593+CmvKNsGg61QwId5Zo77n
tjXBtR3aZocZ3SefmSblV2CxnKBSx6TYVS2sx0pAA/grYMnbOvY2+x52r6Kb
gR34EKhopAW/lXRPNXSqYNeOAoSKGpJsUV1AtJkn7zMn1Dv3QSRFDVGZClSH
0aquoFGjA5cGo4DhXvz5rWcfvP/srQ8v3v7L0y/effHp359+/smz3/7431/8
/Kvff3Dx+efPPv7jiy9/CRd89ea7L7788fNf/+Pik1999dZfnz7+7MUPfv38
b4+ff/zxxXvvPf3nL57+8/0Xb/7oX2++9ewn7zx9/PGz93/67Ce/unjndxdv
f/r08Z8ufvH2xc8+ev7l4xefvgPUnr/7w2c/+83zD7+E61HexXw5P4NPUZ+A
TtGIi3An7Erero/oFnewQ7YFCxup5NthkzhLiUIQbbLeUqo8vNuBpUwhzp68
hgM1YSu0SRFWgDgIE4JYHlP4B0WPfauHIGvRELvDy64QIwBMGw6GGVYELfBZ
nh6VveMbDJamxyALAjybGdQPHhQ7HGNB4YBRNsqZRa4hhMtKyJsAz4Uhgrm8
2T/MSmATuMvRwPiBMAbQYd5WgLgP+8EjGC2Ci0soqNQAdUXmYA9UtBWaNWZD
nPzqq3ON+quvIl7UvF/eeIPBFQx0Vwt68x0W0sMaCVq8WcxO2zr3iIIlPkaE
CCJ3PUwSMPi8GqzLobCDCkOEPd0k8N2aQ9yuFfzV19vwVYk4XbAtVV8Zwqco
IAh83Ib1tkMwhQ4fKlQVthFIBrGbqANrBsS4gShr8EWVtmiXaMIe8FexnA58
VbdaOmhlxTcMF7kyL3XAmDLvh4AnKow+QKUiI9Wkc6avw+JQNQ/1aKxZPOsB
y9rG70OUGMtc+EzGuHVHbyNAE2iagUzb9jUL5um4Tz4yZxg2hdeCrHF8hDgx
iAlGzUNBeKB0wo5De9RBtpwQNGFbIGJ+PyKm1DWr51pI/sg3cU7bOmF8rZA+
NYSy3rVMC5YGfLMKO8IQIVf49XnTMoc9RCWM9g+HQD5O8Iy2BRfqYPc8Xbg3
caGrURv2KwW3xTVignaUwMmAxRXoR9Uy1a5PcMBMByhiLOwSX+EzsxF4Ycsy
ekwt8rAVOETY9A384AHTKw7pEldjM4GPtWGfQWQEuhWoSMmnGtbu4oS3Lc2E
u6j/5A8wcM9z+dUF2MdBj7eIgcNoUIbvU4NNoIXjCOFuEF9ujG8jzP5B/k0A
4ozks+tbjJuKQwfIAoMJaz4cDvwQRaZhI7A1HasUtZ5OVcbK/lAR9rpEZ3oA
fEXq6AMQWKYNy1J6bIVtPvnMQUoU9EXh+gFmqkY8i7Go67e4iiEQgGcN3K4+
VpoNRPMAZeXcBR8ATOuar6qMcI06mq4zzTEIXOPjMNdoC/YRy6BDtiBZDIHg
XI4O9pWvxbUY/xQaJeanINQUNzuIM4GGqW3FIjlUZoYn744YpT4xfJZfncAS
YGttdvlE8I7YABhg4m2agXAXYs8vWqbvgbg1iKQoW+wzaEo4Jo2NaYNne+eY
iC2EE3SFOrgzFrgQOmrAEXEwetVop8PkCmuGwzfswn7YgiWGirypO7qiwf5S
giEOSY/pJ3AQQgh0IkGqHl8slkkYsNeWNURNwYUJQgVvSygQB23yHcQe6sDO
xcTI/xnIcB5OyMzmIYzr7zkoCm69PUuhDKeN76WyiP/GrKi0kggqc3WO2Bp5
5sjJZfl3BrFE3KlHhChaIQTcCPR1B1RbA20bwlwLMD+V9Ik5z6qWwUb1hB0L
HDsQMk5/k2LEAFvKnTu1YJtnrrgbdiRj5HNfwMDqPgK68OQ8L/DmuGuhevKe
Ao6exFgUOi4YCTBSzH9YEfLCfJSXMSkGEeaC5w0C+B9077xkQ9jzUMqg8z0X
cQwH10G0IDZlXqM7QieM9BQI9+4G/jpleyEYFFN1VdjT9KABZuXuK3f+A4qk
BrjBhgEA

-->

</rfc>
