<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-51" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-51"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Stevens Institute of Technology</organization>
      <address>
        <postal>
          <city>New York</city>
          <country>USA</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <date year="2026" month="September" day="30"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 331?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 335?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against implementations of early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 13 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.8</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">8</td>
              <td align="left">3</td>
            </tr>
            <tr>
              <td align="left">8.2</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">3</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">4</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.5</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">3</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">5.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.4</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.2</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">3.7</td>
              <td align="left">Low</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <t>The vulnerabilities cover the broader ecosystem, including but not limited to attestation, authentication, authorization, key storage, parsing and resource handling inside the runtime. Any vulnerability in the whole system, and not just attestation, breaks security of the overall system. The key take away is that early attestation adds unnecessary complexity to an already complex system.</t>
      <table>
        <name>GHSAs/CVEs for implementations of early attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">7.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">6.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">7.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-f96w-jjf8-xpw3">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">3.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100835"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.ritz-seat-facts"/> archived</td>
            <td align="left">2 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100835"/> published  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87851"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">CVE-2024-21944</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity; draft <strong>archived</strong>
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of CVE-2026-100835/EarlyAttestationBleed/Intra-handshake.fail."</t>
      <section anchor="edgeless-systems-cve-2026-100835">
        <name>Edgeless Systems (CVE-2026-100835)</name>
        <ul spacing="normal">
          <li>
            <t><eref target="https://radar.offseq.com/threat/contrast-before-1160-is-susceptible-to-remote-attestation-relay-attacks-cve-2026-100835-3833ee713219f7e3">Threat radar</eref></t>
          </li>
          <li>
            <t><eref target="https://buttondown.com/vulnfeed/archive/vulnfeed-2-critical-cves-2026-09-27-0400-utc/">vulnfeed</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ervik.as/cves/CVE-2026-100835">ervik</eref></t>
          </li>
          <li>
            <t><eref target="https://securityvulnerability.io/vulnerability/CVE-2026-100835">securityvulnerability.io</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/cve-2026-100835">vulnerability</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode 518</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/571">Freenode 571</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="security-researchers">
          <name>Security Researchers</name>
          <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
            </li>
          </ul>
        </section>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.
We also sincerely thank the author of <xref target="I-D.ritz-seat-facts"/> for archiving the draft.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414897198_Presentation_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.confidentialcomputing.io/g/attestation/topic/121496347">Confidential Computing Consortium (CCC)</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.aaif.io/g/wg-security-privacy/topic/contribution/121504323">Agentic AI Foundation (AAIF) Security &amp; Privacy</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100835" target="https://www.cve.org/CVERecord?id=CVE-2026-100835">
          <front>
            <title>Contrast before 1.16.0 Remote Attestation Relay Attack</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87851" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87851">
          <front>
            <title>EUVD-2026-87851</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1133?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y9WXPrSLIw9q5fgeiO9hxpBJLgzjMed3MnJVGiSGo98QUP
CBRJiFgoLFw0p2/4xQ+O8B9w2I7wi+P7E/PkefHvuL/EmVVYKRISznan751u
EUBlZWVlZWZVZmXyPH9kK7ZKPnK/NEVT3XJV2yaWLdqKoXN1Q7cUmZhE5m6J
ueU6oqlNHZX7UL9t8tlMtshXsqWMwBlTrn47HHKVlHDKRd5lD7zL5YqVkv+u
lCqccqIuczl4Zs+JiR9a+NpZcrbBkc2SSDZgQb8WMqkMvJAMTdFnx78ciZOJ
SVZvDcDF/ZcjSbTJzDC3HzlFnxpHR7Ih6aIGBJBNcWrzim6bIj8HbKy5uCD8
VFRUviAcWc5EUywLoNrbJXzdbY5aHPcrJ6qWAX0rukyWBP6l27+ccr8QWbEN
UxFV/NGt1uA/hgl/DUatX450R5sQ8+ORDJh8PJIAR6JbjvWRmwIwcgRDyR0B
YJOIH7nqoFk9WhvmYmYazvIjN2xWR0cLsoVH8scjjueqXU6cQa8W/uhGkefE
gBb4mhFo52F0TiJP6Oy+epI9WhHdAcx/5TgXq7s2/mCEuQNkYWK4Nr7CxxpQ
ED/5g2xEbamSFMwcPhdNaf6Rm9v20vqYTodepgEcgFbsuTMB0mrOXNQ0UeYd
S9RE3hJNWTTT++bpF2imijg6aOYB3ts8xaCnFGMvoPRhXkjNbQ06OhIde26Y
OAXQKccBa6mMjX7puR1yN9ghN6Qd/kK/MsyZqCsvlPYfuRGR5roiiSp3oysr
YlqKvUWmb5jEAkaiLTzmHt1EHkvw6cfoE8MBbOFhm5iaqG/dhzJglBGEcon+
JmwuPJKMKUlSjCR/2A4vM4ApmewZ160iSnNiqeKKazgTsl0Y+wZVN0xyR8QV
CXf4C7YS/5BZM5zjX/Z0cEZEne+JpkK4M1F6doi9r4MorS5FzTFDJAn99ghS
I+pMcbQIPk/YlYZdpZ5YV384OjZNTcg+1IaGPpsYXM3Zh9HQJrAiLFh9FshS
xyaIGJ1cQzVm2zB2ZM09wPqIIngzrEaQm6gOkY2ZDt3/McNnhwhWnxN9tlF0
ruOI+mwfat1ALEW6EB0TZYD5dh8d0VgTnUMC7B07rI7ZXFS4NqDAVXXocWoA
A1LxG9AA2CJ1yl3Ycio69Ppc0cUIZnNgFF3IZgqZQj4fj9q5uBW5pikpgMNe
3NaKLc1D5H90TMV74GGAH70QU4VFHsFjAcBThAH/w6KQUtJ8HxoNkzt3Jooq
gu6Za8Tmzv/1z3/993/9c8FwUnQLV2qKO09x1ZT/cg++jf5cUbmrDRBQDrF5
BC3ZTC0cyVn8YdDPRNXRdCUFcPZy7VZdicAesAJUAGCSvVRCVpgbNnchTqwo
bc7EpahH1/GEgoqfl+ZK5Ooprpfi7hT82goRopmKvnoHz/roXBK0DXCmrAhS
ZCVKKS21ZhD/WJqGbegpbe9CPnNgjepcozkcNi8vm0NuWO1ejpqXbyweFGtL
wwTdwg0Ua0ENC0e1RQ9Fyl59kCc7FGyZoi5FRaFMLND3OrHGFsyNTfQ/NEs/
RMqeCCaHpqiKqIP0MZUZrBdZ2Ydsv9Plr3rNdjWE0FDEudeJTGywomSiciMT
7BcjimPXFtUoky3niqGRmZgy4RNFI/HT3VMWxBTn3LUDw9nqhK8bqgqTvQ/L
jmjN66ohLoC4EjX5hrYxnQJmyH34cEc+iLooRwWExrr7Yw6gJAR1CK8uqEFu
KM1NQ1rsw6XZ6150q1wf2UUy1FPsPRXpyiai9geh5F+6X6VEZV9fVVCnpghC
UN3XU00x0VYFpcvVUW/trO1AEZxHhTQFmpo56h8TyUkBkzswkCOdydcVWGDc
rsWXQhPlI4XimfX7vghZ8NTqO4aZAd7iLVBkJmIIr2G9urY0WM+jiyEbGLVZ
uTNHJxw2P2VdieaM2IEtt16vUyBUCFp4M2iQ0omdXjoTFYwdpEg6nylnhYpQ
zo53sEPkxlHcxhHM8OVY0cceZmPAjBlKnj1G/+GZtAE5c5NyLbDom9uUZ8RE
n5/x0Ma1Pg6QlzfJ0vgZNAZb/TCNXQMWzeV3GcgUpx9IqehgXejRruiy+Ihf
sgcu9epG3Ri6uxJGBk6xuJWj6rDOJyrBHaBJUL3CN6K0gHeKCHtCGB7dFJLl
nGjwqUqbwt7IcsHv4UppRVBZpgGHAZFAgf6uyH/f3QEFc5Atcj1kYjoP8KJ5
c9tgnwrFfLkcN8rmZdc16372OImzklNEVyywXxzTWOJ/0vR3egf/uKFGN4HJ
5lMyLNyX7t+NekPH3Z4GqpWZiq8oYRG62eZh0z1BnQc7So8sYPggbFRnjXsO
V9NUISa3FO351868u9MNyCGUuSFZ2nupkf3h1JBAc4mShAg0VwoYIBLhwASd
c7oCeopoS3tLDxQMTbERBEok026ItogSBawkrtprcMPmLT+87H8zYbIxhAk4
qpwTKvlkK2Kn8Tewc6j9O9CMncC30Mx+I5px1Gx3hlWecgxf7UZVzPeXHmFl
k81FV3+svgHD1xRXiqES27TSEqKbtojkoFZLi/JKsQzYWFtpOprVdDbjtdVm
w2uzWemwAroJgPprZpci2V2SuEtL+fmCJkw8ochVnRlsLL4/9fLLTY5fP2U3
/GaT/0bq5b4D9b6/YPpZhDSLwIbLfJl/yprrryNkU54RFbiFH26BPpoVpeeA
aIYdOXJFXrMcC6ml7Fuh4aEnGDdx0bC2OGqcPMs+PPD500zin6TCip+uS/PD
A/cGx7mDOzTonTXYJriUcKqXBpj30C0nG/pfbNht2kSyOVFVgYfEGQFKTNjx
GFDm5wxdyz7P+LW5WfHzcqX87UPfWUDNjYJnCTOuR6w5V6+iUKULRDINAAa7
T2UKrMBNYHsn41EjkAYQhQZ1F3VuSUCcmKB1QbZswzRBpUDQS/ADyGJupBW/
zC1BIuek3LeTJR8ly6UhEwRgw9QD/iqeBVt06c8NGDLiJyrANDL+OVVmjskW
y9owVRmmS7GpZP6QKRaLx6fIQMYaiaYaeFK+NJWVohLgJ2LBb9r0ZxEuVypq
/DxXWoM0WT0nIhy6bXhP7ygqQOeZaNyVIfQU0VU/iv7KaAw7t1A71ZGEeECl
AG2q6AdSJJTpbs8R4SrAbk2P2VHiqQPaAAoYhAqxp9QqxAdpzZoBVUQ7vcmR
603r6bp1diERkRTV/Phydq9rVuMh/e69JaVlH+ZRBLLzJqx9dUeUei+5QZVH
JSTNkZd0mHQNmUtWZE43YGGBuo7IW+KpJJC0yHDY1lXvYUrkEnKJh06a4XqY
QZ6Kzys+nwNZa+ZdO28vQTyAr4gxMw4Qom3gdC8+/rtRZGYcpkbpabrmCzlT
45fz+ddQgxirKDlgJCpIEx7MmZVi2o6o7iGIREwb7DR081rcmpiEUQaF8I+i
wmu8DlNlWZgu+VklP4N/aZWvoop2kCqaoiv/diRBpGIMs8qzBmbuE5i5Wan4
FfQwbSlKDxCYsEp5SVXQLb6HHL4hzyxZsF2eHQNJ88OpEkXtMFEKz6bEr8ql
PK9tVpuvIwoviweEyTedyzTY0bWhe2oqTJjijybMErdChTWI2em8ELMfiiWM
LTk/gjKjq/ro6ua/hCyzWfmZ16bzOdhPpvR+snhbw/y+reGPY5NsISFBkp04
FLQy8MgGVtDTbPlte+bCgT3zD2KUH0uY2Xy94lfmMstnK6VCYsJ0G3zdVCwF
3dlX3ZSQSQlCvpDOlUqVbKacypXKhRyNM/E/3OcpocYqej/oF2jjRmzYuqEt
HdxVfeRa6OcCq1YX1S1+akwP+kouYQPl0azwpr+kXq/zIUM6TQMWVN5aEolX
ZF6imL3bnI2+6RlgI4pTMfpilIJdrokPTTIF3EMUzFTSw34qmxFKKTrd8JYf
VKNEA54Qqe954tjAQDPqB8f4NZvMcPcEuyNzz+mDjry236l0gEh4HuxYRFc2
1PjHDRpYC2A/pkVbyhbSS/TquXydXhNFnxuqfJhSddGE2dK5u/CX76Bj19Cd
/+//4HoKqGzYZ0RfPsD4Yb/dgH8tYf2R6NuOiK51bmRJc2MKA5ntNBZNoMxw
TqYwsJ05mhuaaAHXWRaMbwdVBawHonIDQ7FfLBpCUocFRWr9VnSmet3RoPkX
iwb6tExRI2tqtQ/pkoRpQqMCW3EX4hbY9cFwTBQnDRpnYHFXETOj8h5hIKmG
I3tLHiwcBQMO6OxNVGOWxnZp4DH4f02xTcJbvE7W/NTDjbdc1HhAjSeT5ZRX
ETV+C6jxosKzEAiLN/SYeUYc3EHC0q66WMBHlB48nncougNLI7zuopTzqeXt
a90WnHuuFmq4c2ToO0oPsjQdOaUJjN3iAWdlNgd9GnZJBxSRAmzZquIjEZMH
xYI79fvFGZtwkFzhHXw0VJJj8ZmhD2oqIfLOodPeT4B5TUJQptoYTxj4mG9D
Rw54AOVF3P7n//r/cJVU5rD4jWglYYcRv9brD+oiWxEqlfHeUYzpIMavBjHe
GcTYmI5xEONKBiMBwviPffy/Rnz7QX5HIYefkMmUc4VkHj/3dG9CgJUJJ6SE
IpD6NR9z4eMeF0RiBx3Dj7V2p6t0yPUFGjrWkxvr+sLG+5F8n+sraL8HzSPF
Cxt0w1r4RmrKJDGPJ088QY4JL8T3fcVn8rsfokEd+aL45heVt74QMt4XwLAv
DJepKMHu8yiVSh0d8TzPiROL+uKOjkagBGiAMScqmoUW4dI08KCGs/2IYJnY
oqLSBfuPf0QDFP788xSe7bjy2cOoP3v3Q+ok3fNhdt+H8JDGZ9FVCAi1Fbvj
TEJC3jcuuQ9oXVrH3HoOatIfCz3vF5lYCcblH0jBwObGmiO7IenclI4bBNMS
qaVI5JTD8Fru5AQdTQZYQMs52IMIDPfvlnVy4m3XZWIpKGM1UZorOkFrzCR4
tn7KWQp2Goj2XT/NjPoxVMDFJM8OhQJUcnU8kOIf/4hTZUjA1yMRZVDpJycO
WCSIp2huAQHcG2yAgCcnKQ4ZASQmGPEWhvtzE5AD0PFkS0fjyVLoe198EZs0
Zi66E7hPqrrTiABFPAVCrjwAkZrr8D3QHiEQ3phSqwDaccxGBlCuMW4bGDHX
N41bPEw55RywxMCUWWKIOJ8FcQdSn+gWodoc4JqG7EgKO/o+Rbc0vPR/IoIm
cAZZs7/n4gqIQQj6Ghe6sVbxnD5EF5WsgLEQyQVBuxJ2mimu7phgqtoqwEPz
mFCKnpzYa8O/TRJcRDF0QuOvIjdQ8CGyMj4F5cjjRZPoU/fb8ildFjp9boVe
5Bn+r5oUUzmOakJrDuMQZyL6R+hgJqYhIuVecw91ClFvtKpy1CajPVELEvZk
9IDfvR9DJ3e59BRtiLUYAy3FJW1NPbAWo4zkkYsjCr1yw2YwuOaCbtwJQQTA
6of9ByCOcxl8wDoJmIohB+Dd7jAeFyBwwGDYmLqJEVNYA5qjowz5TkyT4mqi
RZDsHNrTaMRRvxG0oJ5qZIHonpwi+5rkIb5jfhD5lKINwnqtU7+2BpNCTweX
hmXvv2iT4roMD3+txK62U5enNeAJukN4L7KgUnYdTYHpgcTpgQr5Cz2tgE9Z
B6GDiBTsyqjrUYOOZA52fSZVRRJMFga2Al+sRNXBXScgqMDEsz5cbaYpsqyS
o6Nf6VEIzhO1jgHmVDHRs8l2ioxdN6A0ULMD82BIK724ESwHuojSdI16K2OP
LGUyDP/gcGHgvHvLwedznHl0NYo2pxL3ENew0D1isdVEEP1ff+WaPkbDACNX
gHBD6NKxmJpmvsgJUUFVuUNivkx3+VBB6Vh7BkQxjgzqXbNKVwl1jJoagAK8
TUR66Bn0wE4Tj9k/gbk2QgzQvQxaj9imIln/7YNnl+lgloEVZqdmxiqNM8+7
n6SllWUdA29TOUnv0ymuixY2RuizBva2aMxCxGfJ0EmBVG3BWsCjLuAVdkBw
ynVgMPYEVQ63hn20J1ZRGA3pKHDAQg6WEPS5SyzofkvwbAMFRjB8pKEnRkCb
whO83mWyWBJEmXLy0dEX1t0XzqfTF+6S3rLDTvs7ne1/R+fqy9EX4O7I/wC4
pwygpbc7gT8F+B/Psfflw6+E6Cv8MkdflVNZ+BtjgiMtShSY+zgbelza/7gQ
PM4xQPRxPnic978u0q97RFYcLdIpKqjQi5z/ohB9EbTI0x72vsjuf5GjI7iA
lRQ8/cdHttP4+y/RiUizmUI9sBue9EFciGzhHIdXzi9/0pW9T9IeHTKggiUt
egYg6lFQySBMgBepBH+hAvC9aKD5C4tHVK1TWBwzWJdUQAOnwWKjehb+taUa
GJe6GxQF62pJTWKME0BPlYlcDoPXDTvFtUxDAwy9Qx4OtSteiAX5xcwTVw5i
/IlMJMViZrRkG6blLWwJEFdkeoboBrlpYJOLIB40WJ+Gtue5FcZyP4bU2MFR
sW8ptlGjAB+LK4wsQGkCgOJNz2+2CKaOSans6QQm7/0T6aMqd8JscCqIze0J
s1YQLe+bMF/QmfeOrCX/yBre87S7/bFzrh2AlNi1m+H/d8kROS3/HjSIPHIV
3r6twdHhLUNoYby2/Nn5M1NVwOMmc5ByCMQ3UT27NhKM4JutiKWnlFFR09Mr
6dXp1Wrn9Aro9R4l+hFMlL1ODASAkZwYd+huvJDj6TTsbp3D+4UYcOFQxliQ
2VcgD1tvyGFeNN0OzP0xeRHYTFehadbfY2OhyP0VRAkvmXhJ3eL+ZJbOLq3p
3ES3KN70nQIqkupQaYEeCXSbq4qm2MzmCs3EKT1nolFJod+G6d6MOqUiywI5
Jc5AlMEmw6IbHmrZW2BDw5Yd15bKhm/RIxI0+Ni1tBRX1bc7FoorUNewLSSc
hy4CRCSfMM4wgt7EJCKYjL5odbnXoGceqguArWRE1aZrfC1umVgV91qquOvf
v+dnOgW2JtCr7L/wekEzBucJp4nzLZoWZhYwX1km8K3LDJ6rEnjAMx723kA/
5V5f4GakeX3vmmPwd8+dOM/e+F4dvDrE+u497F0vbj/5Q/1we8ibpY2YObe/
Eb3N6B0h7wOR+3oQ+1Z8xC6FsS/QWeLI279xoWQUwJyTbQgm3Ri+Nead4Ly3
0N4/La+n5PTw+EIRcD+zN2Ksfm532s/szrSln9wdL4tJ1tZuVA5t625FYtq+
UtXJF9Ur1ZwcxKtz9W+G8TV4fGKRydnsit+sp098MSdpwQnAN0XmRYEec94+
10fglIsmoDiNkS4hZLXKssLn5psln38qPn0nZKNAj306fiuyy6WU56ezQpHf
5Cql74RsFOgx523MvxXZ4lO+xMNcAVtLs+J3QjYKFJFlBxffimy+VCjw5rwo
8cVK/nuxQRTosS+Kvpmy0/IzXy5rK14qr8zvRdkI0GNf9n0rss/Pzzm+KMG0
Fcv51XdCNgr02DfUvhXZzcYs8utsIcvnZ7PNd0I2CvT7ITvVzA0/fXpe87nS
bPmdkI0CZciWvgeyleKaf3qalvnNcp37XshGgCKyhe/Cs9NnIEJuLeGM5Svf
C9kIUEQ2/12kgWbOTD6XlyR+Ks3K30uDRYAisrnvwgbr52mFf5pqGj8tlr+X
NIgCZZT9NqVwYKOTc+1JSgkyES1bgR302VYV9YUS1zAf2g/vohLC8n1Y+XHS
X7NzLCQ1a1lIz5vG4CsTEiNs3tEqOHMPed7oSft7HFT0kNU9kwCKfjANZzbH
Q3BMtEOTfVFHh2HKzMHienrwBIfn2aEGc2pxGmxZPb/wCT0oXpoEz5F00dzS
4/z9p/l4nnnlugCP3nG2bwfHsHhszi7CeEMRQ9HFb5yTMyJ5jxU97vCXucpd
z5x72kWfRQLFvaRC1kc8+7k0UjBrtd1u4dkNOvygwy9c1T9Yx9kXsEGdXg74
z//5f7coTN3AQBfqXeE+TehECXsX/fuzxqRtkxC8HqinXYDHtPvsTvfh8e9B
I/u90cgeu34l6IOltiQbvFMJjBfpeL/u+4aOc8eup4sKJRN4kY6fxTrSg8JI
//nv3X/+2PXNIf0NDR4yogMP/5qlbP1rLopC4XujUDh2/YaHUUAh+engIfde
hHYj8zVC8OjbwljmCeteQwewIqpWmh154YlXyru7y4v0ugzo0LAjZilPj//G
ffKP7VeZFGxhAgQwyNLSLV6x8byrOKOorJc0EBh4O+0sVUOULYylLqSFbPqO
4HBNvopBInjLHcOnR9iWr19dtrqN5uWoW70ott2eoet6PRL4Oey23zP+47/A
opINekUNZMUTXqj/FCN19sLcoUbak0A0iHFpSEiaIFTEWcr0Nj9KygCcqKQ0
+ITCo3Ak3jugT+ONbAwWAwTxxJuGknvhfvwaCUQ9bMcBM+7fmX4DMxaPXaf3
PmY8hcVwGnAk6IvYYFCqQF1E9+/3vwFR3OuH9O8rWW+dvlLCiLgXZhf4VVE9
/sd//AfG23jxlr6nDh7AwOH/FT3s10B/Bg0UmxirkJ472qPnaNvDus2x3KsM
R6/CBDEsMISuLrv+cERPU2xlFmhCbB/yAfqo7jiiUtyVg6oUljmGexFY+czz
othgQWyP6J1NEgSsoIsFliXBaCMbLJJZODKOh0FNQf9zH1T4QOVyx/7w2aDi
hi2qBsaUjjDwBNM8TDCyCUQD+r2OmG82lNzDi65Bfw99AlpJA5DoUmX3+bxE
KmJwTftoylz9sjKlcTV2EMo6ZGF+blPo3x245ZjEJwhILB2EhHUEVEDfnhcQ
a1EllaIsc3REA7+sJebGnoDSxElQDYuwINFX7rQ4kmBYM702y+yT1x4pxbIc
eAffuWGKK6LLhkmpg8HCzLvJWu9zOIXiM5kju2fIhLoDr6gP2ltBPZ95mTcz
GoDw7MAccVN0wiGLTGkgnxw1BHFQCAl6DKgfN/Y962ay5Sxcv1sMkNBn+Ba5
Crr8DDLCFj+ji1MESeqFMBHXfGIHu3SSOFeOIue3aGwr90mczTCWxCbfTx75
II+9jBwWlRBuyIscXrvyvrEeDOWAWaNZlVTUVpiDioUYsjE6uvsr5U7glIXv
ekjQcBbPSt8TqkJ5gCbToAZfWFmG4+qjQn7/1QDKnXTxsXAJpi9wTlCiirgy
Qtc2P7BQNDcW9HhvP69vBUAfftgrjNTNZIIhnjQak3IJSAR31XvyOwjvgX0B
2Pg1qju4OSw1Gpzq6ugjsL+vltgTNjoYj4o8ZweNWRgdE1eRi02UfF5YI1NX
7iS/h5Sy4d6fX6KQBgjRXGSi5QZlK/gVd3LiBgWD1DeJfXLiLQfWLw2hBUQV
ir8rOV5F0hxmQAzPJqHgeLbzMmeORjeE6/mWi/RPsfL99fQ+xp5BAPP136Ay
KKT9bU/Z1U0MYMWxnJx4o4MRhe8EvKV6FQwtwDAGTGAg43KgV79A+lPByGJW
2QNMDKJiA1RSmHGHCtkhkVJgtQvsYsmB9cukEXyYdz8LQqOgyxrZGigckBYs
ao6iphJxgXmeoMVntAmb559xVXv1F2Kni8bAgWCEScdr4zRqQlx6SgipiqmV
CVso2AhzVnvZlHC/FcIDpppgSPJyy0wjXNnwWYrrq6KNTBTmXJoIj4WZGuYC
zXxq9ZuwVt09Ov0AA4Bx4RqoLEFNgGSD5+HRywauaKzhgP2zWganNL1rKN8Z
DvO23jzHWQGqYIA59c7DKwx4XaOuokMEnb/kHV15dojLogxJkRvVa5x7s57q
UIxycW/osMoZS3eUQTvTl6go1mEHNhxctj3cifw3RMHbQJ0Gc4f9IQE+NOvH
jU6Tc+18DqPCCQNrb5do5as+/dl4LGNq07G4gd/R4B0pfN/wthdYk9zMwdDj
qyFOoWRul7YxM8Ul2Am8qkxMZAoTkALy4NUiNzKnxeL9MKj41Kfz50GzfzUY
jRvVUfUzy8KGNmBwhYT1xAL4JC+zt8xuTFNeVGa4XsKMwtI1cd4dJHYzAm9g
m7Dg7dcT+TfK/ARmkN1JAbIpcpA0jybSC2Kj0D72tB0lsN8Rw8G/OxzibKKL
NPA6xIXUdoBlQehlBbKRVKDuilnHbpSed85lmMwGlNkNDza3wNQs2OnzRfP8
A+OE48/htWgBUqrMhDm93Yj1TwAtFGIibPOXGFUmsbB5Fq5IKGl3FqkkOhaj
mUymGOgGAtMd2ynYuAZSH5vTdcjjvSiuMai12b2kU2zEFGTAa/C1R3p2U0PE
ADq86RWVAp9cG7PAF7Pwf9FTAFGTWV4wPe3tb600C7i0ef8wfOIAVjYaUZrM
WxO+lCkUaFmQY28zRo18Q8cFSDARnIO2KEyLyS5XgwgDq5dJ6I8c7EhYdRsU
FY+gIQqeDWhQwwjpDYAcE21xy5m69FL95eCuSCY5iEntqM+DxrDZbHymatNy
JQVldhM6U7eUxUVqSVsOvUbn7mx8RY6cT49uqYIC2CiAXe4BTPlhn6fsjyqM
ihSa93GKgcqe/eYfNbzOisEUokw0WCS2SRMTsU2MDDs8ng1Mx3MjYCpHW7K9
MC4amlqbXchwbTV6hMpuSP0t4AcvAooGUcIQ5yj6ruDZcHjxF4v7zPO4wmhP
MLNE/rspS0vnM/fhk/sRl4M9R4brXg5H1YuLlCbvNb4N+NiyVP+/9KDK/cFT
COkAwvGxt+/BkcAKCKYJaAd/D6qX8DeV0X2kKCIGs7Z0QDArKixmSiogsb/d
RRNdnHkmCJialAvAuJGZBHblBZ0pYEJC7/h4us5TcKGVySzsC2PNX9Adcg92
z+62CMnNTvFcY+Oohdn7CJeNNSZCS2LUbPLiTAfDAZjDmzmebsWPvOuxNHIa
r5eIHMwxe8mxq4E7VjSVMZq4tNxjDfd6LXIryA968m/QeGkvZwWIiyCbKwr/
sG7eOXeh0ZgwvhSMjrAX7k3pLyEg7/znS6Sn9zWB7vk9/3D7H8f981VNoPuT
k7530bbHTiHAPv2C4+apQlA9cvomx6HRuyP3myE1Yhux7ut132aDnl1Y9f4N
17nj/krpD3zoALy/7uQ9maIpYzpU5IabMLGVxkn4wAyI48Dw+is36MG75q13
5gL2BsPj2jGoAqb5FRkmSAbuuhkz3dARl6YWQRi3D7e9UJf7Rx21j7yRh6DT
o2auQS1O7sOocfwmM2FpEpve3gB8dg2w+KYUp0ti09QcFm5mPAp4MH2z7a9U
nni2mmvyAZ0OoxPfFJFlX+yg0xn20qN+hDRf2M10srNY9xLj/Z/S3qhFXD3/
HOruS+Q0HyUoVnwCjnA5pcn86Dv9oumfvgXLiipfb+vyJvE9izzS/50rwtO4
x6XUChJ874X6NU2C7i9G4f7xFhc95ofliy3xftAbJP2aJqGT8h015Al7N3Te
3eu+FvcgQXbk+i/udQfEwXMloVG71r0jCB82A8q2fhbb+/nnghGgR/T8kC5K
dxvo3f2J6qqIcRg2v6OKjt1n9LRYOjw1X7iBo1tpVcGUuvR8+fe9fMONtstX
4mX/lwPf1KI9ubcuDqmf9yqT9+ucQ19SFFAoNOu4+4wi3WUCQg+LpVcju4x5
G/nwapj2JI9rdzH2+xJshvf3Hy9Jv3BtKrx8k/SrUKiee99E1FDQtOVqEy94
J+1rVpzPuQLr25Tm6JL2D0B8A93rpAd2uLnlAQJuuz2Z9oULaWCvu45rWqZ9
LQb7GxHTM+yOyW8Jw0mfN1pcQNbI/jxoUTeJd4bASDf0SPeFoznkvS1yzD8Y
RxG+AOGbwG5eDyprwqLlwl98O3n7cFXvP+VBIdKHzRxMubaXcnhMZ7HbUO6b
XV75CyY37sFSP/qVa9BcL1hkNeJ7aTC/DMrIkaKh14MwbyALM6gGqTHYsSZQ
reptJW+ZmwUlSZOeRlICkvAtIniFnjVFVyhKgUeIeB4h6lkyXJcNQMiUuCsJ
diK4e2a8GUUBMfA/FvIwLin0cbgwoHvM8gmLqAbbqvgE1DAFVro4mzxvMvcP
5bsHs5PrbfKrq7Ke5Z3z2UMaPcwsyTXttchi4Fxqob/M0SWKZ2jPTyYpr0fs
DH7TjGmZbLYkFGFbn09HUuMFlwBTpsUSrNmEME86HqFIW8AiTIVsiWuRSQgf
PwghuAH/2mvGfTo58W+y/53rdNsdrCbFco8cn5z8N4TsVuwIw75t7vOhBT3F
wS14cIuv4NK0UCEwGHK29/LWV8L/FPBRdHpicnBjEhjRIlbaFmcsBAHvkdDI
DoFOgZ/Tlbo6aKN9xHkHxhWaYe5r8Z0Zh3EtpAR+ZgipbBE6e4X0zPhKhIXM
K4zrryyhr4sVwfvlKvWcfIopPfOu2J5d2Omlo6rpAo18FUq7I7gNetszGHo6
+5Uj8lK9IG9mY7pN5PGjXkKcUXbfFXNO4Irdgf4qOOqVUNhzczGGAfLeGnvF
sm+Lnezr9VsfdEfdevXChV+BleUymFenJVEPuW/sITm1sq/I9apDdoHSo1v+
da9swnfSuqGPLMQ2QXrEUEN/Lb9C8/X1ynfMae5rO6E3Kn9kB+wS5Y/tQfvB
PbCrkt/eg88VrwOnYXvpqiE04t6RSAqD6r+lt5nx/XqKpRy79fkO4hW/pRN2
PzTaS6/Z6N703H6KqVxsPzvmkXd5NOj1vbKp/F7w2e8I/k0jzLuF+hO6eYdc
faObPXP+U2+yCpVXaMXj9ZMure7BKxatn3Q9NSlaP+kialK0ftKV08TU+jmX
S5Oi9ZOukSZF6yddGE2K1k+6GpoYrR9yCfTb0fo51z2TovWTLnYmResnXeE8
gFbyfRe7tJndb1MmB5ePA/f2vjP/xsmUv2sufGUHhdcd9K4azUF11Hxlmh7q
JGo8+jdA/T7/3//7vRaXm1c9uWHHro9+Y0fBubp/qh29URA+Ww6faos7x9l4
xo6OZ8VLmugm79TZ1RGWrpMm7BX1bRDts+XWc9G2DMTfTXgcjkKNxMbS0OzP
d0RcdERr/vmU/d3ofKYBZJ9rotxkZ0yfUycn6NHbcphtOuJdoA5Jw8JYzxRJ
nbowh/TmCYVKB+c+ANBsrKoKuzND9nyflpdlUeRmWAqCxvU2b9x8/EdNTKpP
RJ270WGz9heL+0RfBHJgbwL+uaGRpTgjxzT2O5oSKszKr49x6Ri8M0V2ocaf
G5Z3NTKlzImBDksM0vVy2LLw/t36EwfrTXAXio1eFuCLIEPdCmSAe1kYuCEm
B27S1LfUxRr1trA16Kdd++T19m6YuxnaXB/Lp7ViwkpY0nCokOch9DQ9hXVi
+Y/w0iBzYyFGHz7RIJtonCKGc6nsfNO9owhP0w5Kf1/g8xLBoK902PORpg39
SEY+/I4FRQoZPlvmMxnBDWhEdv1U7TW+R5xkLpPP+GCDjpF09K7qJV7+oDQb
NZs79LIJCdOKXincodQukEZjYIQMMVnGlUEPqHF50J//lbQu8pkyLwg/jtbl
d9K6cS8b65A/QFZToqRRf5hsKGm/zlexUC7m86lcsZLJ5jL0PudPJFceWTMT
Zk28gF7g3IzCOJKhLarECUmBjSTy3uUN11ZSDLzAip95/x2zglfZoscMQYRw
IV/IVKLDiyvG4jZg2TBoUj43CTIiV8NMk63qcPQWejQl5RQLEft/jQ1xoQJ3
7MOxKFRK2SQ4YoPj3TTNFENRHlR7AaiJKJuihmvF/Qv7DrrO81mhks9/H2YV
3ADq3YTTP5pyQlLKCRTFyg6KLXECimBB5LdQnHofBn/F85+QeQeG8DDUYC+G
+4Jzo5DjSzdlyjDbQjk73gGEcMZRJ+UY044H1ZvgJZZp8kr3jUcXw2MuNrso
S1vOspscyE8cmwYwyLaeDEb262C8L0FnCGBgI+8aTewKz560x5HoEck3mlTf
aPLi2qQAoh8rh/e9A5uOlQw5OUG8wKyl95X2uA9kt1ywd7VYYbcCNNobTdbP
uiJ+sVwTI3b86yV78aWhWOwyPl6i9kuQhJKYrwleksaEwjorgR4peEItY6zq
Q+3/oyP3+s+ry4Fo8qoBakEk3tKwPdPTT3vzzszuHwJ8WYpuVn3ET2bNdjXH
H98qR7Cv0MDR4SIDH4JyCPS6zIqoBl4RZTkP9pUeOMIUfaFqAV5JgHL4UTzY
SFmBgvsoVFKgwn0ocLEQdioKlCJ839wsWZxS4kmIoTznrgG3wE0omRDeZVE0
ys5Af7ajOKXsPFXw+opouRe+3PoWIy9FPzSDrVq4T8qAoaiAbjS89OioaoVv
tcTee6T4v1EchpYyEd1iQQEb75LrVdYIk4RuL9OE6EGSj++b1+PjPlHORvZ6
a/lW9ArimSxlDHG/xrMv7xYjxelr4yeOjrpTbms4rHQBu1s2pYcMTDrHXs/d
ueO0pIE/HCaNdywON9GcZTCRumZ3AKU5kRZexvNXKRleZWRQ2AUeeOzeha+6
LuB0j2XXAI57xZKjRKxD68OHgnvESEGukxPP6YyXlUMFkU5O0L98crKfMowD
/63T4Hz8KbFNSM0wDSlZvBPG//Hvr3ITxdd6Dhg9SfTg6fdcsX+D4WjKjAo7
VokvJs6AVeGDMYKyw5H7J95uZAQQIBwfl01l4g+7WbOACskja06jHM2y7bhI
ecOKHxQdh2KyJjNjdww5UOtejN9bkYJ7BvKu6J3vMIioVut7tyqH4YR51lF1
vzbyL2FG8uuxU81YeXmCVxZPdrQVYvp+BqWS5Y2kThX4jLO22gSLauzLj/S3
98T1sQKUNLIPiTy1iX8S7aPwKk7srX5ZVGFEImA9Wlzm1F5p5+gVT2KyZDzh
unL0wwOFJjA/hm0RdRquG4Q3kompv6LXoaQeIdyR+B+ovufxwuyS6Dw9gj12
jXvRS0OyJ/fUB8NUZmhnoWJDSx/tPT6TZ0fh9GK+xa6Rw8TzmeIxHRhWUGPF
hu7aNLmGIilLrPq4NPCkSAZS2L6CxQxETK1OQEknEW9e3hmRbjgY6+0KVAo4
yJIT+pJmookchvMsT8CrVtSBEZrLD9I0BQDoMbdhmrDORZRXx6wZPWRnrOHf
x8apsqbbFKUOrdgUJYzlXeRm1fu8QkF70zphkgYsz6rYjp9awMSa2G7yAczh
4WYs8ipUzb0KkLjPYv6T+FJO0TJ8dJkw3Kv0iiYDZML00Yv5fkEVL/MMG/TJ
iaywC+uw5LyUGSxdDhhkB9LIeLRj3Z2c3BwowBq/SkAietml6FVoC1PxNDo7
mWM+fJ5ttp+P2XUP2HRG306IvUarSQqyPLFUXJi7p+OLRC8rGV4d+fB5bluS
B5HuzoO7JVg012+l4ZBmxDrKpbhqkONsB5oYCy2UGw3LMotHR322ojCBjpsr
Jv56N8J0ixXTvZFfILjPWJ0WCK7jdTeVddNGTj8OnDw+93N/YmYyz1lH7365
KbFEvCwzGrq2I3ob2S165BmWguTwGUmKplAKIwCj8dNwoHMLJ3XIpm3oTmpb
OMYZimkVSnsazOPIpfw5Ur6dPcaZeR+M8PxFoeSO981JLtGc9FDCDVihYVSX
1XCir31139yCwdFbinvSA8emy3ul1HeyKfG7SVvnRF1afvY+didL8PDD7/G+
kp+TLEiQu69dNtyuyzIzxaQKdNMBvpXvjqYADFKzBDmcQlkqqG+x78n52H++
BHnruF+F0+xp/rQYfZg7LZziSU7/9ajxkOUjz8f3EOnM/dr7w/8vAGoL3Mc4
VqVSDlr85//1v7nA/vP//F+ifyCU7BtQFtJ8Bwr7Kwol9yaUz9wBKO4fkZvD
GHjNeJ/e29tZS6WUQPndzWVReO/CotLTTwxGa8q6Z1r+QotP6hxK5Ry09aqB
7/clx+V7/mG5ntPHPxS6asxS9sZ+f0bpH5ZNOjzQHwA9MtD9Oat/WL7q8NB+
APTI0GKzYv+wjNjhEf4A6JERvpV3+4fl3A4P8gdAjwzyzczePyqXc3iQPwB6
ZJDvyhj9w5JBh0f6A6BHRlpOha0I6NarU/z9+vUgsmH9QPihge1xKYV0/a/0
LNw/joLJbTFFbLGqwAdeUjWPV9O98wcwIe9oFXhqK8acb1L78NRPN/aJbkP5
6DnLZimGPBm46cJ0IwtiBnfeZUNKH2qaPj5lyQN3LNeQuTtizljqzQdcZjNa
mJfurmEvjRvR+XZiKl5+X9x6fZCiiyDWCPaSf+59ffzejLGu82vv5Uqa8VPG
k/L951tvJ0oN2+i0pOw22OFPiE6mStSB/V89qSnkMLeGdtTrdHISFP52dxV4
zo6z+Woaw4xBv3hrWF4icbcRcs+uA3OypaeOoaNA18fOEnd6yd5Po+n4dk6C
vwNPmITmu4puKaPnfJSILCYYjxNpkkyZEeI9CPCZfASHN9F1T2nZAZk3SfDD
MInmxy5ED0jpyVnqneLnonreZOJnqGiYGwOHBCPHFP0SdEe/3E9y7pMKE86b
4ru5Eh/xbqP08XtRxC0IxfDtI3guFDh86JQffe+ivqBHmIyjvAv0dFqDq/Vv
n9cjLw+Ake0dlwMLtT6hwENeUAvT6m45GTNym4ZjnbrOKkAT2d8PgD51g2FC
IStzZTaniX4wekAOBVd/TSAP94Hlrt4JgP7zz2OWFtEkNAcVJn49OekAV9oT
jEUCkbAG4XRygpEb6Bs6OUmxEhFtZeVmnUY8Wdn6N0utn6J/GpQFTdYuH7mH
0iQU5cHuFsOKxPNt/P2GQO7dDEdHjjljATToNo4Xu26xgreYkCZDytJ/Mz+3
9zIoPeWGmaTZ/QEW/kQDbT64ucK8KI1QVXQ8icesYG74U8y4UOTie3rWzhK7
4RoEJetLBFOxFi62XU6cuTnICR5L0KTEzhLFsRU+hA5nvK/u9OYV/PCKRmCE
l0PLSFDYdNPlR2p4GXMx2yrVYH4rN5OveyhGnh0q7anLboY1OXQvvN/NxgnI
bqmzD1gO1mbkGyZv2Q0DXBo4PP/eRoAVY3xs7ZaBx5ZoTRBTU2h6YssT86LK
InL89Pno9NFllqSZuIlCT/1+/OAJhg6NKMLc11KQOHZC581UgBJEZua911oj
IvogQOow6JgxiWUVoeme/BNDN62bx2IRZwN8TL0akqt5vUThCGdC8yazTHC0
aLy3Ir2zV89PEGasYHrd01ifAl4qZy8dboob+p6fqLt9N1nzBH0NLMeWyEQY
TS7LEl+7M0pFC8giNn0i5cwg63CAFh0JvPZ42qcWC5ciUy9Fs5tQnSWr9/mS
XQ9ihvjIMFQ8+8eMuK9KyviGh784fAuEVpv55FkggaZTCKGVWUzMI0WIp+ho
+v90pQy6ppA79orQ7OjNoAYEK80WLTviBdOEvGCANHPvfZoqGxT6LDs7KyTi
/fDqIMSfL78rtoR1TnO48YoMAgsT84e2SZjdUUwDLsfMUWbQQ3OYNsyFTRPi
sWIMSGnTZjGRgBNKxSnQiC7faPGGNw7FvWWAsFOUPqZr7RDfq7cOOXawcA8y
IxAOGRaLhczdbM6sOIXvg6RgKfvgqg0lDkO95OiuJzNIIP/vNwMuqdFXjjfd
ogsrkAlu9YPX2NIZjBRgOPXlQah4Er288tqaOsbCO8xVxnja5QJ/AUm+CkCh
hl8vqWhlSf13snNHpgcnGgBoXjkeaW4oEnErHOHeSgXTJCTtfDm+Z4w4aafM
OvHtkSgHrimeLBrTVRDx8wir9hIsv4++4exlnPu345D9a5TaX0y+6GDP9ofn
LN4isFhTR61XvPHx6Oh/otranxY0z4VU7jSyAH0YoXt0DQUkPOE7RFU1YE3k
K869eznFFIGo9oiKyh2eq6qyxBTeII9XaCv6WVeZXnErRrgJ5fG2HqH5/hEJ
3Ng6emSDyw6IMQB9hQkAcW+wI5J3S5O6vpegkCblrj1EQul9x1Lf2y4TgQrU
FWbXM/ruacZ2Hq+lmO8TdR1Ty8DFjQXKFGZI+sKQkw26trwTDEX1s1ACPj6L
RutV+bPEqpGynPuW6wcPCkZQKui4SQKCe+EF0de4SfHKAwFaLiuk8LKbpIqK
xqKENVH2LEgW30p3KDPH9POgg/oLfPlHIbd+bGizSdzzGgww9qrq7DQNlZVh
zrjyq3oznMZsMYvyNtgIRFvORUt5Ccf7hNYwDaSNVB6itSHA2pwxRy0Vng6T
Z1iICSfKiqCrI75s3IG5Er0sOqBBPkfB62h4jVsrBMtL+SzNziD2EiuFDmr8
mNaDc+M0QrdvsG1zeDXo1of0mjXF7dfdu7VHvjszPht/qCpusEvwnJp0IfkZ
kBkNMaBEIn6F3N36fAyZnl/cz8PjraoAsXgEVpjr9vbBe2HP7no5qkYqvb2D
3l58EjNTq0tRAkMzC9vBCxALukVYxATsAkWujmIQjFs/WEUn6+AqMm7gtxNg
vMAuRf88NgS8p8xIF918X5grdEa8cwxPbx8I70bjE4Oco6YO1RTs1MLU9hZn
Tvmx6+y0BLCycVehU/kiYUkWVzyxikcoD1VlQYXhxFPvuFnwA+tgjmQMXRe5
/gBJ+ulrD/P56IWzr2p+jJoAC7ZhotjAorCcCQ0J/4VNmuROmnvVJpxQIb33
Gld6H5ekfmFO/d27CB92QB7TwHa3BpcpAurBIOnPlDGdWuSZDpVlH/CvKfAT
uivjBaGY4RWLtxwLBQDuNHnbAD7Fw6vIuRYVbd61Qt699uehwudgZ0NISchl
hcq0RHLHiBqy15SEbyaCKW0bOt75pUh5H6TdEFT/AZ/l/XMi6MpyLy1X+GyJ
z+QzGd6xpTTtA2txL6K3CemjlIh34wktMR4lGjTylk00l4ASSuN56It05ME+
4PXuoI5VXj5FvgwgRyFKiimpKdWhj9M7VD1mfLCPcbD4+IGLgcgVH9oErED9
mPtUj4gJKkQ+RG8vHge4RWQKlTgpmQRY0c95mm0epsitsAWsQfSVYho6veTN
Z/gyn6VzkwCJbDIkgDtoiKyohLurY+UMixxjAgW3K0HYvSSsPzuiDo8p/7ls
Z6VL+WxlB8b5OWyMtpa/9Q/lil6m1kTZKHrqma0tK50T2urm2Swa085WHW1N
+9JyxOtdrMQpAekO+82hZ8/vATVo2s1hX5/dE21oGpn5U/dxu1nvgGooIMVA
CdwZJsjRUHrrWCzLxby87t63Ct2HTP65pMzyTm0928USLBSi4MUn9GWCIf+V
ID+1YMuhg5nLFYRQOqOp+5Re85UV9A+m4YOdFuHL0XtblATWQhWtOdhhoasx
Etbtoqc/qan3lja101RphWQaPb3mWWg5u2KXLmYKeUqQM3EpuhQZ4Cb2f+Du
sAgVlfxDQ2IbU3rbAQxyI8pkJjTg1/A5ECn1tKS8iwd0uyuJpR2w5c1vzdxv
ZeG3avO3Zvm3cv63cvG3ZuG3Wv23mvBbs/hbOfNbteR9U6N/ZH8rl70/qu4f
Ne9VtUH/yP1WLXh/VN0/EDL7JoddVFu/1aDTEjapeK8qWUSjWv+tUnM7rfh9
1ZjUxTpVdON/UJSIy2UKa1HhpXGFjjy98+1hONkEcLKHZa4vXGPQjJPGr/FN
1k/2a/qh42nDI+xGnqRmOHASN4Tgox0l4qP9Jrjse8FlmUraZ7WgRtpvcLtm
CoGty0zBGOroaqFHxOwFEypeqgbsNZ0ppTP5dNh1xfuuK4vpIt73WKAlMzGN
BdHpEe5U2fAaGC2wEQZtpaDcyBZhhRd3V3hNBaOmI9qXoGxGxmIbWs8TfAW7
PaqHbHwXaA1BqFQEqvQ/eFa5KuozByPjAWqH+jt1IyyV5/4zpoDCl/XWItph
S7rrQCNsQugoVDTX2EBhq6yDXbflFRuGqqM7nx72wD53bsjQem6sefgfXVsY
140RI7IUub/qPrBSGH9P2D3Wmfc0IUJpRRaKlXJBKBXzud+Vv4PZkimVisVs
LlumRP4Urrzga2Ukc0irEK+QpcmqLoRRiF5w8XmRHjIyUQSMdUk2dpvouCVm
1VFCHIbHEvAavQQES2vR13TUS0e1wK7wzExQFms+ONcE4czv57qIVeyf1VNc
GsDvW2+YA6pRwj5weOkxt3ujG/EIkpVEh8dHCMHMb4rkXAEzi6Yagyn0LSFG
jWGd2QTRJWZJa3xIu5uYCpkeXFB7DH+/WB4uJdzc8VPkQnpYwchGe84I3DWY
VrajhRePMbNSNK8Ynrrh9KacRRpUn/sp39UlnKLQbguPVnh0YvILQpY8jtWt
AAlj3h6YE4tRxi1qTbkUQw54i06mMtNt2pIW+KWnpHTRDhzYJ1MD1WfNC3Gy
Qzr3DezsU6aTRjEA1ke+kC+klvNl1MylwwWhEoXgPaVGSCxLKcR04AebatUh
ICpeWbaKHgqrwBQCukRSFvw3JelpZPE02yrhPinNjjSAlZWpJW3sSqUAnCWk
ZJbwBmcNqZSfKC/RUA184hrIdO9upR1dhH2wqoo8zMUSZQBIV9mRFJGXiXpg
VnaI3B0BmXcyNtlAX5+uimWpRDbw6r+q8DoYb/CfBV2gc2ItnK3DO1vxZaVo
6LpfRRbIDp0s7UXWwkLPslP0GVv6abGcNdRKJbNLX7wkGBZOiCR7RhtSNBlV
0/k0CDohk8361AzBUaYkbDkrKfqA3QZPl52b6TbT72nPTTYJzmwm6o4l7vTr
PWY4wxAOsQ+KAwN27kvFBstT8fQiLgN6K5JqQPwlqYYD5Fob/BaMYQt9na4K
Qd/HVImic7i0xRK/gS/S/rc0hifkZtgry1iUHt2BLw3FDufLspYqfcIU0ob+
wvxClWyhIlQzBeDoWp0vZIQCX6vmGnxNyOVLtVyhUSxTg/2TKq42XHTy6LTh
89Tc8Vg5vSNVWagihsKBlgM5ymMSGB6vWR7WAGwExtzZERXwhK2atJDJF8rF
QiWXHwvZbCaTzwjM6OjjYTFdDWxjq9iRNH/+s5RiMmY7pASimh9EamVazGYF
PluURL6UreT4CiEVvlAolCY5KTMpT8s7y/FC6fW52/5l0L2qaMvVklkm3pqM
GgSe0nErDjFUcJpdYQIaDjbrqx2lh48o/1rpRbfYNy5f+hvaAJQCEDdERfo7
Rf1wopICYUZx8GYJaMejszCqGREHi6kNmsDnoN52jUX0vNDe0SwGM3ev6Wvh
jVRULOnfnx1ibv8e5Wf/eAuM+IRGPm3/qw+fQpIAJ1MFIzhsKoYe0hnJ5jPl
0qvDybCmxsAeHv3bQSo7vMKro4Us6mC+wbem/44ZifoTiHbfNNs9LMGXNL0Z
lpt6RXVcNSqGYMnH4YwKIbHrPqF2HYXhRp1E0AbLEmUTQnXDS5gtUxed6JGG
xB4ANRgwQGblUYBO8Jx4EAIN5x0fxB8oFEs7AlyyZD1qyKTwEW3DDkHG+Wyu
VBQq2TRmq5oZ5nYs5DKVIti/Qe8GqGabTnaILKGHXrbCffzKGJtJJpd5aTgX
xXTkmAvFmgOmXsFlsEGUkAaJPKbdzMUJJj7E418FhEd0FR3AQZFACr6IW2XK
L0RV2RommxtxMQlb2fQn272FLC5FDykd0ErAg7SStD/Dogy7FYl7rXLZC//w
bw2WAdEtMO+moAMpOLCZccdFdJAUBAgDw0AJQANL6G9QuDMT4Ii0/Dw7m5wR
2Aeki5ViRciX2FFwtdvDYy7YCoVTE2nuM6bsXGFHdFh2kp+MyACeUGCjx5xQ
vgU5CIRVyFmDoX3Uu+wH5gWfBfHdkdQWp8yTErioPa+zbTAXLuZVAstIREey
uHMGjgoMutR908FKa+zbpbgYHzKiMdzz1Z4agzJWKEtK+VIlLxQKuVI5VwTW
zxTz/DNfzbO5HBiyqcwMrmYCkYw3sTHNCf1wDMYVk1ledBcT5fRUAJlGN3gk
D2hmer+dYlEoZ0Gt5orFIqBTyPL3mWqBYVHDsK2+CXu+3eSge3CYwMegyujH
fD5fEPJCdmwwpsX8XTY1kA7ZXAE2+UpJKGcredj75vMZfj1Vct7e1DAtdIMN
gahTEoMQWEwW/SbNrkn4VE+D0Z12eYxtNLZ/sbjasHt0FPxsEZmy2RWGyrEk
F3s33h9q6Hm0RM3mpv/6p8kN0bA25wTDinXMcRBuZjHX6IIlcd7hPq4umrDp
4DqKap9i9KVD7wiguwpMuwWxME6XuY8B11Nopcr/bodAH1mQcr0evY/gJrtw
8wr6hTtZFK3sHryHxJwbLYz/8lOBozMVoyRoVANGUMC0hNa5F4zq1fk8YnVM
aSFLYkupU+ZQxsBWmvjQz6812XL1utsh4E0Dsqnbdn9maxawFQlXUSwvlIS4
dYODi8HotaxTHzQ7u2ARkgiahX37jw+61pFTaK6uJfHP1DEwhyZZTxBhQAP8
093BqOWL0Ei6EddH73/l3rwI8aibFZLeaJ5sd3KQewlK/Pwj7ocshAOR9t6g
EZZiKU+8uIAwHrTb/bBdF3sIBzeA3QWtmBxWfg7HczIERJbJxhU9SLQ9IUj7
oiEiaHoZOligDQtkQQYCDNbch5MTspFUB02xk5Po9xjf5N57iAmiOGZZ1fwz
vNjyqXiJJV0rtYTG09h8ssrdzPkst60vcwNxmbknzXToMPDbAB0nREps3lbk
m5ZhV69fOrq8yOaea9K6NsqJVjKk4gAlRSrXWWWagjW9t1bbmq0Wq7OH8hM/
7HSUdTKk4gAlRapwcVZUKtbK0PT5ctvv3PXJU6807Wn318mQigOUFKnb8cNz
++YhN22uxdZ6vZ1WKw1rvuwQO5MMqThASZE6a42ltdbpNCfm2fiucFvcNol9
d6crSj4ZUnGAkiLVH9cfRltpljlvl6TJuei0qvzidnaffTKSIRUHKClSj2dP
Z/fLh/VjQa/fai/ju3zrvHivtJoPCSkVBygpUnnLyF1sOldX952hsNZXc8cg
d3czUu8skiEVBygpUtfFM00qlFcZSVAbtznnqfuQqd6PjWm7mgypOEBJkdLz
PVK47tdX6/lGap7p8h3pb2FPKhkJeSoOUFKkJmTwcnm5WveU6WIwPetPN0Rq
G53lqJFQoscBSoCUNIVfN4WHjlwR1Icn5bk+siu1x+1t47JFbpa9dyP1JqDE
uq9VN/K13qAxvNnqq8tK9fpMtPtP+r04S6j7YgAlRWo9GT9Yld6jXHEqRi9b
W/Ble1Waru7bCZGKA5QUKWNVnvIl6fH8vDB45Hvak1Tszm+HNb6VUCTEAUqK
VNa5ccSG0NjOni4bvXx7NObNh8l6pJwlRCoOUFKklrVcRZxcCtdmJz+ujnrj
Zqm82vRHziYhUnGAEuu+zXl90+sQflhVBhVnfnWlquZ5XrupJlQzcYCSIjUS
Ns7yprZ+fmjWhp366H427Nw/2vLzSzkZUnGAkiI1H6zzxdZ6pt3KSmX6/Khl
p0/nE1UfdxOqmThASZG6aZe2zfFC1QbDzeU227kvTl+clqE3nt4vPN8ElHj1
zZekq8qkNW0Wjcpz8aJyu7AzmWr9PCGl4gAlRWomZZWnzGpikPlwzK+EDD+8
tNSN+FhPaA7HAUosPK/yWnX6XOicPS7tRuPSHOpy6aUh3wsJGT0OUFKk7p0z
abxtnvXrva7zIK2yV73SfcOYDeo3yZCKA5TYnrrtqPqk1W3Oeal/TXpO4/bq
eVN4WN0l3GLFAUqK1Ob2JlcvPd9c6TNJWZZq+cerQu/sZlS5T6iQ4wAlRUqY
1aX+mi9dGsvG4OWl9lLNya3uzMgNEhp5cYCSImWXRWPyUsuV8uqdcvFi3ppX
g4fSov2wTTh9cYCSIqXlbra14v3F9ctGdCTy1Bwb5b6eF5xhNxlScYASy6nn
zrM0mZyvxLHRbvJPzcajk83nZlM+oUKOA5R4i9UoX9eEu9sL3jYujVX7Ojta
FBuaRpoJ1UwcoKRIre4vs0tl+lho30t1YXOxHk4v6vqN1LpJeGgWBygpUr12
617RJ+XC/VC8WDw/1ZpzrfZYL/WlhDwVBygpUk9W5bab79fK2wdtPsteTcTH
miBms9OLhDwVBygpUpnBy9Xg5X58K6sPhZvrce+up20eVd18Siin4gAlReou
1+sINdisTTTh7qa/aV8rc7ErCS+jhDZ6HKDE9tRYbG9VrdUxLrTny1KtJj3c
Gh3evEy8m4kBlBSp0vBh6NTKuXPNrDzXJ8Kt0Krk9cpdLpfQSogDlJinhnfT
Wfbhslm9ss+uS4/WVNio+Su+epXw1CUOUGKFrE0v1/xkXT635LOJmrfEi0ql
9ZJXiJRQIccASnw6vFWm7fJLvyCuDXMyHgqXg0qredO8v0t6OhwDKClS9Yf1
qlcqvBTNUVfOVnOPj6vHM62zuVIS2lNxgBIg5Uw1+JmtbFqP94V63hi2F8vH
6up+NC49XNxlb98/f29DSkorR+hsHu4q0tn0dqnk6tPKc6ZI5uvlQzuh9osD
lBSpYXtczWSEosif9/T76qJt9242xuJRe0rI6nGAEruM1iX+6i5br96aGf66
9lIpkWpvUxvrvYQqOQ5Q4o27vp1I4nR1nW3w3fnNdHSbzZbvrluX84R75DhA
SZEytdtL0po8iZtsUc0JemGp2J3u5up6kVDRxAFKilRjNj+T27mtNem3znvX
pCy9vPC21O09J5RUcYASU+rxQpQUObvWm7Z4th5OlG53audGmVZCnooDlBSp
8aJZu2pcWqO7p5koTwobXX0qF+XVXEpoUcUBSorUcz93X8/0RLPVquaGvUlt
eXd3Zm+q9cuEjB4HKClSi8XT9VzJb1dnY6W6fjD7a0EyW3Ne4xPyVBygxPuZ
2kI+t89fRna+VRFul+b0vKvLM22UTWi8xAFKilTHccbVliMItZEpb85z3fJc
W2efnpblhBv3OEDJj810xdgsauPx9WN3NW/pBV28Kz51718S2glxgJIipdxZ
9XpVLT888surUbVkKZc3bWuqKp2ElIoDlBQpvtPu3wwK9ZVzeyddVWe5kjTc
rI3qSEvI6HGAkiJ1oV88NEuT9vWVVt/c3j8XLVu5ss/XkpBQTsUBSsxT40n3
bH4l1/JPwiyjSy+b/uO6dW/XjaRHsTGAEvsctvnn2+uz6/agnOUn1uJ6fNPu
FhWiCg8JfQ4xgBLbU2c5a/zQ0qeV7nW5NFplJeE5P80VN+cJGT0OUOLAkrvz
3sOD8NAWmlllOO5sr/NmQ7uyGu2EcUFxgBJbCeeC3hiSdXVyezFek6tlpbzQ
Hx6lWTEho8cBSnzE8eS8ZKbdp7L99GBIN5ry+HgvDdfrVichpeIAJd44PCi3
+fPHSzObMUnxetHWtnfD3LJvk4RWQhygxCE4D7ONJigTu7jMyxelTUt4uJTV
zP1wmXA3EwcoKVLFi/PZ1TKbfRhs2qOHCa/wtY3Sa7/07hKe5cUBSiwSjI50
3rfvL6a1m4f6o3Ep6PpVkQgtPiGjxwFKHMMx3E46FWWuXz5dloZP8nz+ML63
N/OenXD64gAlRUoet8tm6aLXfqrmC7U+2TyurammVe2zhBI9DlDiswT+RSwX
xw9nGWu5rt3X1qPb65e1clU3E57lxQFKHJmQ7/bkVX1TVofNc7OunHWfJsta
fWDmExp5cYAS21PVq8q2dWZM1Vth3VivpXm+IGvPC22b0EaPA5TYRs9cPHem
NdG61tRi5YGvPKpj/WlqNcsJV18coMQiYX7VVh+20nir29pqlAElsVFldS1u
ErqM4gAlthIm64uKJKvFqdLPrGrtWXV4c9PQxP42oZEXByhxtItN1p1Jr31e
u746b2StZ3M2MvVl/WqR8CwhDlDi8ymr+1Q0Sutpfn4/duoXBWFUH634dWuT
UCTEAUos0YtSuVHs1xoDktnkG9Xn+17Ozjf7Uj6pRI8BlDisy6wVcqWzuZ1d
NC9u60NzNFjYIGFKSQN14wAlRWrQ188fpjf1xrg3WOfmejWTeZkVy/ltO+Hq
iwOUOIaj1xlnrIuLm0KPLIym/nJ3fqZ3zzRxmPB4MQ5QUqTaZ/VqTtBmVTJX
Z63+wBlvO1Uho573E66+OEBJkapM+axw1jsvWkJfloxJUesbmaJ5udYSbrHi
ACVFqvz8PG63RrmK0G1O2o+P1zf2Q+/q8r5yk/AsIQ5Q4hCcFyd7o9bVh96i
XZ5dDq/q6qZ9NlvrVwmnLw4QItVkaRc+JosGmG7ulgNbHT33m+p9eXWfX5Ud
5bJYGCWUonGAEhtWi5vM091406m2hLL5qNmPZ9lqdjledxKaC3GAEocoPGry
w/m1Op0TczI31t2m9jhYZzstIaFojwOU2NrLPBVvllZjXCeT536/d7lonNWf
tsPnZkLmigOUAClTtK20ZTXMx0HrLm8V60PxgVQrXa2T6fevhfcvwzcBJUXq
ql/rju9kfmCMXl7keaGROXs07tTLdvf9htWbgJIipU9N2RRGlb68LDbGi6ds
087dPy74+dX791pvAkqK1KzXW9l9oXtv3bemk8x9Qe/NByPx4sJ4vxJ8E1BS
pLZiu523bqf5ZX16lulc9vuDVe5+lpHaCacvDlBSpBpiVXhqXF+2+Il8Vdjw
8uJ2MnxRO1Lj/YbVm4CSIrW0F53Hm8bL0HjQG8VB4UXVix2pKUirhEjFAUps
WAm8Vru4E7T86FxpW9fPV/Or7mJyublNKNHjACWOrqx1pFr5YTDIdG6lrTKf
P2mCcP88mN8lDFCIA5QUqZeH3Eruj0eP549d+Xy8WErm+u7aeZgm3SrHAUoc
XSndtx19aoyEq3MTxF9rYM2Wl9b9Sk+4g4gDlBSp1nCesUdiaS5cSiK5fWxe
Pr8U17N8oZ5wqxwHKPFFW8ewhI1RUBcXinXOVwbts7uLM7Gqawl3EHGAEofn
3W4nubn0PDDOWnn7YnF2tbGydYdcOgkP1OMAJd5BaI3LZ761yvGVUrb4TMY2
yejTh/OemHADGAcoKVLna7s9lC66D6ub+l22mulsqsOCVbnv9RKensUBSux6
WF7UmkphrPfMgjAb6rOC8TwUnJGa9KQjDlDim5pZVTybONvW9bVZvBb0m/pk
eS6O+5dJb0DFAUocM8jnrqvlsXwvVAuafL4xbre88DIuD9SETpo4QImjJp66
Ru6s3nvqzNTBpTgcdi6vnp/OZ41NQokeByjxmVBTeMqJff55Jd7MRvx1uXxG
Nna9q0oJdzNxgBKf8htPzWV5mBVa9jRrWBf1s0tjUN70X5Jey4oDlHj/3i/2
N42zebVTmehkevOknkuZaaUoLhIyehygxOFB5si87ymX3f724eW2sVLv1bNa
5maV+KAqDlBi3Sd3aqtcY3uzzbeW5rwkKJXMprjs9OsJPUdxgJKaw52meX9x
ddcfNbSr8+Kgd3tVPsuozXZ9+37h+SagpEhdP1t2Q5hY5+ajOb0e317f8I+V
8/mDnsD18CagxDvkeV6tWfeFta0/9896gtS/WtiC1r+qvv9I701ASZGSe9VH
3qlOHrvqzUZpTK7Gmcfa7Tz/XEl4lhAHKClSrYH8cnt1VriqWfmesHVai7Fu
bx5UYfv+U5c3ASVF6tnMr0stRa8v2sKznS2J9frT2bnp9Avv3828CShxaLo2
HdftiT1sdPovOafXGdwTlWRX6wfz/dLzbUhuhrUelve7djCfpKFbR0ddWinR
tE+5KUCmNYe5Z+81y/5E012ZomKx9Fx37WiGKGhAU6ibNqZTwmJ7WPWLZk+6
wyJi+0usu9XVP7Bsn9xfY4veu0V5rWRl191Wvx9hhW9M7oWlgRTdoUUawyU2
LS8LGq0wh6mXabFUrA+HxdXrwypPav3Wn3/Cj153NGjydR9SuDIh1o/EYpsK
looWZVlx68Ox2mcbhQ4caHRyQkd9cnJgFE8OkH+qEPl37sbHg9blwFSCtqK9
LpI8CcpeYR4uA1Nwhb8xMa8+p2i0gpZNMNni1CYmpj7TCauj24RvaUlnmqRt
BL185LBa9ie/KHY0oV2ECYF30orsFjt3a02BmuLZ9K4snk5aJk/zhmK1L5oX
tchnj1Men7h52yYEFL9CeYkNA/hHmem0fLfF6GfuKTzuVR7fLT3+gSadBNhY
S16Xth613ATMRD7+HQvfwWwx5jo5YXmiWeo21l/QPy0kh0nr6CRgNUFHo1no
WB3QXdhYQxeL7/1QIuZT2VSekrEDvOdXEMbKkHTS3VRxdBECzkAanbACXwYt
Trwy1BVlF32LtMakj1gFWTKJfXLyO8X+H//AmpqDKqv7jt1g1l1O5CitaOHq
SAFrbkZYfTVM7gukAtJz/W63wdK/1Tvd/hh+/O7mfHQUGXO8cyMwilFqNL0h
YFVzpGfMOFJcC+QiPoDXssHB1Hj56BT9KFqs8HUJ11N41ry5bbglqYr5cpk9
xGrmsMix7kC1y0ZNqyArsGQoViwbH60LjT2HxullpXVTIGITL5ufW2ycmLFY
c7tYU2S8Wmm8WyttH1ISdDt1sLisNCdYWjAogp2MTpHhZ/eQJMe6rym0zB/r
3KDF6rkIA1nvGOnRTr9ekmUeczeqVqh3/83M2PeUGKv9j7V9j01bOvCYl8VD
b2zJwZFj/sZQFlxQejZW3cBpDtI6HtFkhaEsuC7TLEEvYVlEWvqPZvw0NS8Z
46u8iPsTIb5Vn5frYfJLJZQgdY3Fff0qhAYrMY4ZGpcmZtDHbM1pWiaKpVNk
2Stpokw/tWrdrZ0qupZDFSB6ZaS9+t9UPtJyp4g16jlP9x/WfB/EhciqLR7v
lFusbTndoPXjrVC1dRA6uozJG4Ocj9Fa8ZOgGi+8owUGXaHBKq6DnGNpSz1A
fvJJnIa4YtyWoTqscCsHdhOzghywyrCkrYG1s+aGW4JSNbCiDCt7spPc0k1Y
iVYGloeE1UoLdntTrLpo4kixLJQHBAaK+VUVd+poWk0sKMtsHSJaWAB3Qjg/
JelkG8hLnD+/1mUKJCxYdCBtCVBpFUnZTLOfYqlqmKz4QcA30EO0RieyMgo7
TAjslucFlkJMvSygXnHs06BWLE0Z6/WsgRzSFAsXhqnT4VluFTLLmdjq3gKp
XBMmX6JZYaMcCnr9g5IiqVO3kuWSpqqli0oE5vWSgDIVGGIjb82ewhM3hyg3
AZ7G8dCsySwBa8+trQlGGqhqbkhra56ChW0qogZLEMSXOBVPuZFjaGCFVB0T
ftwquPYtVVxxDWdCtgvjlDvD3PXYjHBnogTWN1jjQ0OfTQyu5pxy9TnRZxtA
ruOIaGt0RGONGZcN/HEubkWuaUoK8Mwp1wDVcu4AcYCMVTDkbO78X//813//
1z8XAHGrrlBA14gKEyliHdLmSuTqIC1S3J2CD2FaztD21LlGczhsXl42h9yw
2r0cNS9xXJaF9b4VUccc2MpsjqoFngMTm+IcNhWwdLZgoNYNVYWFz6a4iwWv
h9LcNKTFMeV84s5WWDKKChOBb1ZnXcJblgKY1mmlla99VnftLq9Q8GHZ+bq2
K9qAdOWenABeS2SkCRZpVyy2Cly7ck85WTcF7pJV5PNS4NJBYcVaoDiqRfzt
5z13RW+4FesHZRQQAK0Kl+vdPQwVfF4l81dVe720vnTf5n2LqKH8MsWlgrmJ
XZnqjRNUL3HLk6tbX6CEVmiQxdhCXRU1nVLcCASzosO0vfh0Z+sHKwiqMq2J
TjuiQsDL8O73ulfZeXBoSuIAVYQAtgQsjxXNtIxgsJqxaIuMMfxHFrWNgslk
Ld0u8asFobWyg8LoOEpHw9K33mOa1Rt6p4VJPUsUWAlDh4A2Xnri2/2cUA0S
C98GAr2Besk6GhnuDsfyt8o+gFNuoRtrlYCZxxYOraAM7EnNt4CcSAYqfdzK
FHFsGcpyHNIuVEmitdXlG6mpYWE2cFogIVyxIlNhJlD4G7oXoUsn/Cl+h/iy
b0ENvLAPadlo2DKDTrBwL66s2L4TTUQ34bVGCM1v7uoCkGm4STMxr7jPMciF
sC3DObSBAiqIbg4r++BDDw6dQ+sNaV2v17nQXp0bdttMQHkGW4rre2WZmYb9
oGPl181cRJEIpIeVgPN2DCwF2kmmmP/jH1i5OniAxdnZYDh3R+d94/2EL2iK
asqlVJ3j1onq/MXurMXPkZBB8gJ9cC8HsxoSLcwQConTqWNSk8ddYjvGE8MQ
a1GgdXvnJmY/jFyA2575xgmjY/WMWoqMW8l84FPKL/sdouafR0dfqHFipzto
H32BDY7uEPhvAxjjg3XMfQnW5Bf4lgcr5OC/4T3bLHE1A3gB58U3Znt17g8s
EKQ7G5h2R0MrJpwHHkVdsFNXl1KKIFpWmv4nnc2kEZe+Kc4cWK/1F6y8J8KT
AnclgfbG5vDrk1fsPR4ULVmtTJhpmc4WyoX0MZh6Kh55nXI4XoOOpma0/n2x
LuYz+7H+1K7m2x1OyNtzXGG6aAL52cqPnoXMxPxsTg9DWB/Ygl+yFhTxITQR
l2gsf+GyZZjMpc1nI6jv6b3fHPH1q0uWeT/7kROKiAcreMI1vYIn3IiWgkAN
igRdsdUR4Ded8Utip2YKFmtBqaPDKlRtR5+lESB/oIIKBcjq8unsKPMLd/Gv
f05gd37qFbugg+GzFTqeYBLYUKIU8kwmLJVA6/SEqgyk80K+XCkJlfK4j9+5
hvp4bw3tMdZUJ+O6VxqSSlJYF+MdtTY2puP67XA4rmTGij4O12AY+zUYjhmh
wyUOArQtkL9WamYYM7fWjKykwKYDtS0KKcVOE8swFcmiRTCQOgPYNJ9yXSAu
EkbI80L5OxAmLxSzhdJ4J9M/JvofRw2bcQfs2oAc8BLH7Z7bANkuhu5oUW1w
g+poiKVi4WPN02YBYmig4DoC8zg453O/wipX2Ip1jT4FPpNLe8Wh8DcS41Yx
bQcUHBLiDSok7wxPq2CnolppBovf9xWtNiXyrhrxSlDRlyC2mb3FoxEWVLP3
iMfvWCV8JgPy4RNdmgHeW8OxndSEpLeF8XCQ4Rsvnczv9t+zhQIjNJaYFUHn
6Cj5Bt2rETd0NFDqu2xGH4I6MmzeYNW4fJZqg3A0wPI55VomPWj8wjFqEhSg
AUltYwkGobXVjSXYvwFsMCSAhRUdiJWamunscmnMzOx0NDx3rIExyw3uJ/3r
33H/+isFEdQm82xpNHIjtajEcIk3Is8NyWWr7zbCLL93jK9F+yG4rP7YEuvN
mVZac/e63rE03euivP+a5ZirlMu5THHsaeNx1aUTipvwWhsDnYIHzUbnqn4c
Ee4N3AP4Sv3OMBdYiIjA9vtDY3g3PD6kYNBDNbbol2lWRtWrxoNnUNRq+dRW
jQmsvaqKO1635lAb6KyBuKLGRAe2HKBLPlD9drCr6DrO5mGLMPsmYZYrFCuF
UoFJquEhwQ1Sq0VPiMbtbmvcIOjDGMMQovRlroZ4A3/PonWsTHZNJqkXw9BS
DpYvlNL03Dd9U9VzZUEmisiLvUvtqd2Z9543hiQJHWnbKi2sC1Uk5JxMN1f5
ybCe1Tr9l3X/uv/QJllZfxykXqYqeahrmg16wxhfuuI2Uvyn2uX6bPM2xENX
15ZA+UCFshBeNREfiycOBXfZ3CpE18VTmBFgBWoIZQXuzFG3wfzgnu+9PlgA
i2SDfRux0oY8k8cbbf50fa8MxuLFg/xs364aZ+T/r+5Zexs5jvyuXzFYw8au
sRRnhm8dFgYpig9JpCiSWkryB2LIac6MOJwZzYMUlTPgM+6QXHA5x0ASHBxf
DjjggiRw4g9JDAObwB/2p2S1u/50f+GqumfI4UsSZW3sW8DeJTlT3V1VXa+u
qi7E77pt+EwiLgoZUO8sAtCuF1doZEZovBFa67azZYbDxk62+WaQtJYuQrgL
qge+ZNwX3J7onxSj2gDZCV4L/Mbzm5bcu06HFDqJ0qUqDCxhB3RIXEhnwtoa
BqHqRCYDE/5hWWOuBD54CA9aX5tOmBgzc1YDRUT/hTBWYIcPYwfRM1VhsKoz
Eha+txvxrbmrZrtDx4mkEhFt0ZxB7ODcvs2i5vfbhK3e3LZbwNmd993TTG7v
dLedL/ZPa7JunOWkIzLWPbVzfvgd7buS6dYL2/eCJyEzj6f72Xqq6dq9rm/r
CYmV18KD1eJfDzdz7/j1hl0hX2rVtbOLPceETRkT04llm5Jy4Q2ImXCrE6Wz
njDvbbH1996J90SdYHRKIHnZYJG5eV1PkWL9fGznyzvKzggoIsTiPKNIeadW
/F7zqUYsxedSfinS18ODkj5ve0JmeHzZR3UR5+M+Z6Ih6aimNYuA8B2tjiF1
VTcig+jA+5xlEgWOUmywkf3L0yXD0eCJVTffCokE7gNAdp6B4BpdjcZwqnhr
7pztf/PohG2CABiI1CSQwCAhEsyphTezIIq+A8+Fb+fWYNIvI7KMsOfmmgjP
dWGqM2/Sjdt38RZRvCnczx3Ai3ivuzca5PKsUJOYkI5IYPWyhIqoP/kVqm+p
T8ZCYnjPqXfRwyQVdpiEvLzqTlUKBsZ6aLEgDTu92gUygKeB8Twa6JIM5slp
Ttd8zB01soilWAS8h1lEYULQ/EWjN2gzIZ0AFyLdbuDRArhx2iWLE825Xsux
MTnL2p4czS2E8sIr707e8H0hYPhtvN2Yq0o0pj5FcGGCv9nldI1uDy/onvWj
YjyXtWxNv0bE3AoX8Uw8I7bryEu4fOQldJ3mAkXt7LXu0KIbFHPVU9Wpa5Hc
6e5+pHh+ZoyKl2pKMzq66+2Vdevp2XlFb1nJVl2uNE+TydO0FUmfnEkSOeh1
1OPNbbOUPMl5fWnPk3il7+LRKcuC0gY4k4HF8fyWmNrieUoocPK4GtNpmCox
wnNzRDaLvVJUBbl+S2TLfORVwudxw+DzkUmYoYIRX3B6H3PbkiHJEvdwyAiC
PwqpGYrcjSCiEEsmBb7dxNwftLT8x9s7BgxlGnhq0W7Wd9oHFjHaDQ+cxOsE
/J6dMS8soScbGFMS+HQMn7YJJquuwkCQygL25QIWIr6GijAQgciowv5sjAew
GTU8SzTQ5OOaGApygjPRQLqbvdBdxfBYw4SdNhfoMZ3I0KRzUYDmVhSsM/hu
bgMIyXl0LwntrIBECcpCOMuslNBrTDZGe5pO2GsRPk7/5uNCss3m/7bIvy2m
hbfFzAr37DbTWBKrF7Y4IXHfsfrEerH6PcnWHdtTSThaLyQj98LsKH0SvEjj
NOBFrAqCIUbvJufFVCx9E3QaYpvXBSABgWnbaAf6lCk2KwUW2t/isoaBPBg4
gH6aRavIPWBjwS9grcqU9wNmfzCdu+IOejTev+mwTeGgxqDs4Zsc74GxoTwh
7LTEu4w0MIkC/u8NiWeHY5zxCCC/ItnfVgskYikhsZ4WYG5yoR42mBM3GswJ
do6lEuMS/sPUHrxifEaMZm5Y0A2Wc2KZ5QweXc9GqRU2ma63jcu9PaVzkIrv
u3EQnUk+EV8aRbrdkh/SkW9ceuqNLJ3GlRZD8tcvXz1OgYW406+m0EVKppL+
6jHyMViIfNwL4b89J/OxeCoeS8VWRyqCmMR+dm/n7z3/u1FPR1OepSYtP06h
pyc3UHP3srdvdQxV57MYghCE1IrQzL0gIvFGEDETo/ERMsmgmubZsk+rPaHr
EXXgHpipqqloDrJ9LCEEHnGAn7vFahJzsZpr0RePLGDwbnGbRChuc9/e4h2i
O6voOhfdWWum11MzKWYT6fOSkKmU8UhVTPGBV7eYCxXSz5qreh16Vg/PRWaV
XtgC5bkC6VzD5yFAy48PffCBVe3gmWMHg71GCFVBli1NsmU5tkxT+4q6CI4A
tUhFgZ0P/MMCQpBBKVI6LAVhJLld9b3hE00+H3V4taCrzjuY3PWktj/o9Y92
u7GMV1FPnWpxYF1EzvMRb9s8HFcUvWy9g25EUnDeXBaAcE0WQOYGjK8/1m2S
AARf6FDOnFoPNx3GKEf1k6QgP9VqNMoIqukRd12IJWTAm45MBtOjaAerJTyd
ROnaVoRWQLDIZAgCcYAnuO8XDhr5ncqcazUPGLGbA1fTIbrzGBOjFXTg/pGL
CdyuZESEOXQvelgrZ8r86GKpWMhVJrrKBTQvExzzUPxMK4pqWo3nLIPEoETF
JOh8kTllIi+0k7yXIbyxgjr04+b8gJ6cFIXEkkE2paGwOSKdwX0KDjGF2P3O
BQczksAooqgTxNQK6TFh6Bofd/d3u42LXuW924uLeCx+r1I39r1Ano80IXYT
0roNe/u0OjZTbWUNpNFQzX1iLcnlSZdiLXET1uYARdfGU46dYVMrnJ1hI7YS
gigkb8LWqF2xzyqkNK6l18BWInOvyBJvj6t75jAa1ZsUp/tY48WbsCYkpeJp
xDzV5HV4TMyI1B76wRbnaq5OnjwIp/sHueVkmvY/k0i/Rqr9gw82WPJz1k8B
n6Q+T1LE4QlWog5725Ps8TTff5IIz6r5/NKJ70VmP63KYtWeWMoQ1HXSQvW5
8h3T9iu8WHa8ydoJcBIWyhpYoAe8qoYzLxfwjO9JloVlO1hAadlYxj5TA4OD
0DovqUcm1T+ajaX8trNFKfAWNxfS2cRDQ/bTW8yaW+HWPNrguAj3Po1+tEJ7
6jY9bWLk8KJwdljY3e8SiST1eLuqHBsDJ38SgKUW5O3B0hYUSaVzfsEfn6Rb
J3YpVrmIDw/Shhjx9pQJ2Ob+OlDRpkjr4/OSmhmn2vvDZEfQjlXr6PzEtvgK
HwCloYPbQ0X/Pdo0h66eGinDy9FuqymWxdORoZrlA+PkcILZbPb2aJUkJXqW
O33aT52MGyNLKpyP5WzvohWL9auntcn6a2isscrAmTJFlBG3HcsKYERmSh2j
cjLRqknbfKtzWh9dNHNd3Wj2e6nGgN6rjcPTPBCRuo6sdOR9V7WJJAu3HVqa
Aoh6ncuUd7ztRCInl16jNT6uVp1Bq9d2G4eYsgibw4cu3gX6RUk9y2bivUsi
Jw+q5WGtroyazUirPsgGuMw3KttrIU4eON3o4bYoyeXuSf9Ca+qGttPtphSl
n07mshMiLQkoXA94Gkqole1d8aB9eN6tHmWNStloP1VFsTxoVboB9HBu0P3n
E00lR31BctgzkuOoUKkXt9ZmAdbW5bS1x3uVSkY8kEd6raMc54aHWStvkcRd
ie/Drav1lCmU7NZFr5jvKfXdSj2ZqOf6+R1/2jTAve6kMdYcrXYuSuVRptS+
sBonHaV30DZS+tNygbScO86Zgj1KnJTkjKCfnGnn2003kzsdP81XC+TIqkw4
tVyt31qUgKEWbaf3d2J1T7g4FpKqUtwd2eNKsz6qm1I2RGIwaladcfseKD2l
Zlt/1gRbRnfcSs7mSjhKNKSIozStPCoIKZFPCbHYKvytBXOAPr1CojHwT+ik
m9ntO00U/IHpBDMxUcjcfYIhWCLPJ9PpBD+lwMF2bXaPYXk8A0BCWw0emxw7
wYL8dYZWZHatiKTrm/Qw0mEDw0uR4KWZ1aSEJLrRPhRxbSg0eteeniGhwcEW
l+ETYdCxewMdT8fSGLilNPChx+8NekKMJ2MJnyrc0uoibICFEpFJvTVl0uGe
bPGpWvyIND1HzW4L5xmSy7kW7zdwnITc/r/VvuDkVyQXYeMCEzxFb8A9BDnz
6NuJCVGIZ5KxeIqO6GejYtL8NMOGe5jNlguPpqkI7wSn7PMjS5LWYwONlOkh
mn+C7g8YLgTE0RN8PCbG6OjhvbgGBwayCTQxgwOuNG11E0oqGA8saVqUQz8i
L+EZMu1K5KcrZJC3ePxDuyYB35Z7HHiOtNw61AsEy8SHEphqyKRIE2qy0ZZQ
4Ir53UeYD8Yq432uYNXg1Md4zFmsgFgn2ECMjkD7U2yHKyU3Zj4F/iMr2MX2
CCOCJCY0iHlrj3v+jAA36xoO+7LXH9EKfAMUmEY4A/y7PPFcp6tyjmWTLj28
6T//0jAIewKTAzmF2AbBEnpuJ1IBGIBfDlP8drCQ3XOxVBnNKmy3AI6ZKnXg
t4rmKrpGZKxSkgFQWUWQHaJx2Fro+WfU6HYvPSBJWcUWXDmiwWwVh1OJ3oNH
/VnAdK9+/dHLX3328qPfXH38uxd/+fT1F3968dXvX/7ih//7l3/75j9/dfXV
Vy8//+/XX/87PPDNh5++/vqHr37256vf//Sbj/7w4tmXr//pZ6/++OzV559f
/fKXL/76kxd//ez1h//ytw8/evmjT148+/zlZ//68kc/vfrkP64+/uLFs/+5
+snHVz/+7auvn73+4hOA9urTf37545+/+s3X8DzSu5ytZheakTRn+uSokoO9
beiTrDcDtjLZwLrlDggyhJLtBh0BaAh44wdbBq34JfKTBz0QXeTBBxuzz7Cu
XFj3bhDsISHZ2BMGG7fMNbsou/RbLeioFw4p9FiaGTaEAFGOk6GKBDtUePRc
Apm95+m0B9GA9qfw67wXWrywIIDNGmrIrDuYhXSmnnrQr2czwI3fvIe2f3NY
Z4cgCoMV/w5r/cYOwDFgEMSpOfBzsfg/1JCHc3AL+ZkpwK6IHKz5Cte90yr8
rY2Nd99dqsTefRebgy375YMPaG+KkeaofiMGm4YwYI/4JfM0RkG6GhO2/haf
tv/wIxVaEBShvRIbsC/H3B4yjMQdaIYE3+Vtyemb/l9DrQtfVSS7D7Kl7slj
+BTu/gIfd2G/7Ul4ZAAfakThdrFrEDbqIjbsGSBjAVvqwRd10iF9SeUOAL+y
affgq6bZ0YAra56uO4iVZaESipRlP/g4UWD2fgsyacKaZMnyNdgciuoiH005
i0V5YFtb+H3QEsg0Vo5JEbdjg3qrYxaRrSPSdj3VhHXazvPfGgsIm2vOg6ix
Pexno0sGCDUXCeEC03F7NhkQG9FyJqEIKwGJ2fvYHqepmgPHRPAnnoFr2tUk
iteaNCQ6V9X6pmHC1oBvtkEjjLG/Dns+a5jGeIAtKMP10kHXJtsfo2vCgxrI
PVfjHs486KjEAn0lo1rMSwZwRwWMKthcPn/UTUPpexJOmPIAwYYa+5Ins5VZ
2GWjZOoDyhZZUAW2xBU9HT+4gPSaLfUlR6UrgY+N8ZD2Q/F5y2eRikdUzFXG
Be+aqgFvEe/5f8HEXddhT+dAjwMflyQdp9EitJlTA5RAB+cR9DbCZoLTZkbc
4h/E30z3owl99j2TYlO2yQhRoFNiLe99BD+E2xDRGViqhlmZ6kAjCkXlcCxz
B31Jo3wAeEXoaANIsE1bpikP6A4rPv/SRkgE+EVm/AFiqiG5JkVR3+swFsP2
DK45cvralGkK2LoFmJVhF2wAEK15T1Eo4AaxVU2jnKNL8IyH08yTDugRUydj
uiGpBYid2GwN5Cvbi/kI+xQIJWqnYF8xJnawbwcKpq4ZCcWMqRiefTsklIaS
7tF48kyHB7rXFrdPqLnVxqRzyH2KgUAL0fHLpuG5QG4V7GBCN/tC6yyck0rn
VGDR7SUiooS9Ix2uCeaMCSaEhhxwItnorauk16N0hT3Dmmrsgz7swBZDRi5q
tiaroF8qMMWxNKD8CRgEQxiNSKCqyzaLaUi0i1vJHCOn4MYEooK1xeUkG2Xy
Bjaa6oHmomRk//RpuKzvyoLy4Kb1BqwDDqregSkT2pSP6VKRx39jFFjYjPmZ
yBprzxsac2Lk0vMG2k9LcuaGCFqmBf3+Jh1+94C1VeC2Maw1B+tTpKFkLJOq
VZBRA27PBMMOiIzLLxL0kEClbGw0fDVPTXEnqMBGT+8xh47kY+zeww4jWEI7
a7IXsCeroWCtsiiKAsMFPQEKitoPm1yWW97SZwqK9oNzwPIGAnwH1UpvWeD2
PBFSaHwvbS+Hk+thayi6ZJaTPGlFOePhPfDtdUJ1IQgUQ3EU0GmaX/Cz+eDR
xv8Bvxs9SKGOAQA=

-->

</rfc>
