<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-55" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-100835 of CVSS 9.1, CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-100833 of CVSS 8.2, CVE-2026-33697 of CVSS 7.5, and 36 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-55"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Stevens Institute of Technology</organization>
      <address>
        <postal>
          <city>New York</city>
          <country>USA</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Islam Aboubakarov">
      <organization abbrev="ESILV">Ecole Superieure Ingénieurs Léonard de Vinci Paris</organization>
      <address>
        <postal>
          <city>Paris</city>
          <code>92000</code>
          <country>France</country>
        </postal>
        <email>islam.aboubakarov@edu.devinci.fr</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <author fullname="Venkat Malladi">
      <organization>Verily</organization>
      <address>
        <postal>
          <city>Dallas, TX</city>
          <code>75019</code>
          <country>United States of America</country>
        </postal>
        <email>vmalladi@verily.com</email>
      </address>
    </author>
    <date year="2026" month="October" day="04"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <keyword>CVE-2026-100833</keyword>
    <keyword>CVE-2026-100835</keyword>
    <abstract>
      <?line 378?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/>, <xref target="CVE-2026-100833"/>, <xref target="EUVD-2026-87851"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>three CVEs of CVSS 9.1, one CVE of CVSS 8.2, one CVE of CVSS 7.5, several GHSAs published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/> and <xref target="ID-Crisis-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users of these two implementations to carefully evaluate their systems and understand the risks.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 382?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against implementations of early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0–10.0</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">9.8</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">8</td>
              <td align="left">3</td>
            </tr>
            <tr>
              <td align="left">8.2</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">7.6</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">3</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">4</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">6.5</td>
              <td align="left">Medium</td>
              <td align="left">3</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">3</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">5.5</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">5.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">4.4</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">4.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">4.2</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
            <tr>
              <td align="left">3.7</td>
              <td align="left">Low</td>
              <td align="left">1</td>
              <td align="left">—</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
        <ul spacing="normal">
          <li>
            <t>This work resulted in <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
          </li>
        </ul>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1.</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1.</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0 and <xref target="CVE-2026-100833"/> of CVSS 8.2.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <t>The vulnerabilities cover the broader ecosystem, including but not limited to attestation, authentication, authorization, key storage, parsing and resource handling inside the runtime. Any vulnerability in the whole system, and not just attestation, breaks security of the overall system. The key take away is that early attestation adds unnecessary complexity to an already complex system.</t>
      <table>
        <name>GHSAs/CVEs for implementations of early attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">7.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">6.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">7.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-f96w-jjf8-xpw3">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">3.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems6"/></td>
            <td align="left">7.6</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100833"/></td>
            <td align="left">8.2</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87853"/></td>
            <td align="left">7.6</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100835"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-q46g-34w4-vhmp">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">Moderate</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar; independently by XOR</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-jj9v-7353-35cv">GHSA-jj9v-7353-35cv</eref></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar; independently by XOR</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-9rfg-55gm-hwvw">GHSA-9rfg-55gm-hwvw</eref></td>
            <td align="left">7.5</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-ccfw-q8vr-cww3">GHSA-ccfw-q8vr-cww3</eref></td>
            <td align="left">5.5</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-ffg7-hfjp-rj7v">GHSA-ffg7-hfjp-rj7v</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-cxxj-pvvx-6xcv">GHSA-cxxj-pvvx-6xcv</eref></td>
            <td align="left">4.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-pv6g-4385-q8c8">GHSA-pv6g-4385-q8c8</eref></td>
            <td align="left">6.5</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.ritz-seat-facts"/> archived</td>
            <td align="left">2 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100835"/> published  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87851"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100833"/> published  [<strong>Severity = HIGH (CVSS 8.2)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87853"/>  [<strong>Severity = HIGH (CVSS 7.6)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published the following EUVDs to acknowledge the vulnerabilities.</t>
      <table>
        <name>ENISA's issued EUVDs</name>
        <thead>
          <tr>
            <th align="left">EUVD</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87853"/></td>
            <td align="left">7.6</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">CVE-2024-21944</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="Intra-handshake.fail"/></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further code review and formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0–10.0</td>
            <td align="left">Critical</td>
            <td align="left">3</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">3</td>
          </tr>
          <tr>
            <td align="left">7.7</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.6</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">6</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">13</td>
          </tr>
          <tr>
            <td align="left">6.5</td>
            <td align="left">Medium</td>
            <td align="left">10</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">10</td>
          </tr>
          <tr>
            <td align="left">5.5</td>
            <td align="left">Medium</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">4.4</td>
            <td align="left">Medium</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">4.3</td>
            <td align="left">Medium</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">3.7</td>
            <td align="left">Low</td>
            <td align="left">1</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>Both violate the fundamental requirement in SEAT charter of binding to connection.</t>
      <t>While <xref target="CVE-2026-100835"/> and <xref target="GHSA-Edgeless-Systems5"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>] are patched in Contrast v1.16.0, <strong>users of Edgeless Systems Contrast need to trust Edgeless Systems for the provided hardware identifiers</strong>. This keeps Edgeless Systems within the TCB.</t>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Privasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity; draft <strong>archived</strong>
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06 and -07)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
      <table>
        <name>Summary of vulnerable early attestation drafts</name>
        <thead>
          <tr>
            <th align="left">Spec</th>
            <th align="left">Status</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="I-D.fossati-tls-attestation-10"/></td>
            <td align="left">Withdrawn</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.ritz-seat-facts"/></td>
            <td align="left">Archived</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.fossati-seat-early-attestation"/></td>
            <td align="left">Vulnerable</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of CVE-2026-100835/EarlyAttestationBleed/Intra-handshake.fail."</t>
      <section anchor="earlyattestationtschss-eat">
        <name>EarlyAttestationTschüss (EAT)</name>
        <t><xref target="CVE-2026-100835"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://radar.offseq.com/threat/contrast-before-1160-is-susceptible-to-remote-attestation-relay-attacks-cve-2026-100835-3833ee713219f7e3">Threat radar</eref></t>
          </li>
          <li>
            <t><eref target="https://buttondown.com/vulnfeed/archive/vulnfeed-2-critical-cves-2026-09-27-0400-utc/">vulnfeed</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ervik.as/cves/CVE-2026-100835">ervik</eref></t>
          </li>
          <li>
            <t><eref target="https://securityvulnerability.io/vulnerability/CVE-2026-100835">securityvulnerability.io</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/cve-2026-100835">vulnerability</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode 518</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/571">Freenode 571</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
        <section anchor="cve-2026-100833">
          <name>CVE-2026-100833</name>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.cisa.gov/news-events/bulletins/sb26-271">America's Cyber Defense Agency (CISA)</eref></t>
            </li>
            <li>
              <t><eref target="https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-09-27/TIER_3_CVE-2026-100833.md">Alan Turing Institute</eref></t>
            </li>
            <li>
              <t><eref target="https://radar.offseq.com/threat/contrast-edgelesssyscontrast-versions-1140-before-1231-generate-runtime-policies-that-fail-to-detect-d602b2a9f5df6321">Offseq</eref></t>
            </li>
            <li>
              <t><eref target="https://www.thehackerwire.com/vulnerability/CVE-2026-100833/">The Hacker wire</eref></t>
            </li>
            <li>
              <t><eref target="https://cvebrief.com/cve/cve-2026-100833/">CVE Brief</eref></t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures within the handshake is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.
We also sincerely thank the author of <xref target="I-D.ritz-seat-facts"/> for archiving the draft.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/415074362_Presentation_Safeguarding_GA4GH_Ecosystem_from_High-and_Critical-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414897198_Presentation_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.confidentialcomputing.io/g/attestation/topic/121496347">Confidential Computing Consortium (CCC)</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.aaif.io/g/wg-security-privacy/topic/contribution/121504323">Agentic AI Foundation (AAIF) Security &amp; Privacy</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems5" target="https://github.com/advisories/GHSA-jw33-f4wc-8736">
          <front>
            <title>Contrast before 1.16.0 is susceptible to remote attestation relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100835" target="https://www.cve.org/CVERecord?id=CVE-2026-100835">
          <front>
            <title>Contrast before 1.16.0 Remote Attestation Relay Attack</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87851" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87851">
          <front>
            <title>EUVD-2026-87851</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100833" target="https://www.cve.org/CVERecord?id=CVE-2026-100833">
          <front>
            <title>Contrast before 1.23.1 Image Substitution via Policy Generation</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems6" target="https://github.com/advisories/GHSA-MJJ6-PX65-JQ92">
          <front>
            <title>Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions.</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87853" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87853">
          <front>
            <title>EUVD-2026-87853</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1227?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9S923LrSLIo9q6vQHRHe5a0Bd6vazye5k0iJVGiROq64gQb
BIokRFwoXHjRrDlxXvzgCL/ZLw7bEX5xnDj/ME+eF3/H/hJnVhVAgAQhYS2t
tce993SLACorKysrL1VZmaIoHjiqo5HPwi8tydLWQs1xiO1IjmoaQsM0bFUh
FlGEO2KthbZk6WNXEz417lpiLpMridlMppIvCuZYaNz1+0I1lT0W/JfVXDmT
jXmX2/OOAs37LyupXOBlPl+qlv135VTxWJAMRciXBNOZEgs/tPG1OxccUyCr
OZEdwJ9+nc2kMvBCNnXVmBz+ciCNRhZZvDV0PupfDmTJIRPTWn8WVGNsHhwo
pmxIOpBOsaSxI6qGY0niFLCxp9KMiGNJ1cRi8cB2R7pq2wDVWc/h605rcCII
vwqSZpvQt2ooZE7gX4bzy7HwC1FUx7RUScMfnVod/mNa8NfN4OSXA8PVR8T6
fKAAJp8PZMCRGLZrfxbGAIwcwFDyBwDYItJnoXbTqh0sTWs2sUx3/lnot2qD
gxlZwyPl84EgCrWOIE2gVxt/dMLIC9KGFviaEWjrYXhOQk/o1O88yYWesGne
fVQ8WBDDhfH9Kggc9/tT/MHIdw9DgukTTvEVPtaBzvjJ72Ql6XONpGB+8blk
ydPPwtRx5vbndDrwMg3gALTqTN0RTIDuTiVdlxTRtSVdEm3JUiQrHTWbv0Az
TUIaQDMPcGTzFIOeUs1IQOn9HJOaOjp0dCC5ztS0cKKgU0EABtQYs/3S5R0K
t9ih0Kcd/kK/Mq2JZKivdIY+CwMiTw1VljTh1lAXxLJVZ41Lo2kRG9iNtvCW
wOA29FiGTz+Hn5guYAsPT4mlS8aaP1QAo0w2WynT34TNhUeSISVJipHkd8cV
FQYwpZCIcd2pkjwltiYthKY7IuuZGTWohmmReyItSLDDX7CV9LvCmuEc/xLR
wRmRDLErWSoRziT5xSVOVAdhWl1KumsFSBL47RGkTrSJ6uohfJ6xKx27Sj2z
rn53DWyaGpEo1PqmMRmZQt2NwqjvEFgRNqxRG2S16xBEjE6uqZmTdRA7shQe
YX2EEbzt10LIjTSXKObEgO5/n+CzfQRrTIkxWamG0HYlYxKFWmcjvEJdSK6F
ksJ6u4+2ZC6JISABIscOq2MylVThFFAQagb0ODaBAamQ3tAA2CJ1LFw4Sio8
9MZUNaQQZlNgFCObyxQzxUIhHrVzaS0JLUtWAYdI3JaqI08D5H9yLdV74GGA
H70SS4NFHsJjBsBThAH/3aaQUvI0Co2mJZy7I1WTQENNdeII5//8xz//6z//
MWM4qYaNKzUlnKeEWsp/GYFvszdVNeFqBQRUAmweQkuxUjNXdme/m/QzSXN1
Q00BnEiuXWsLCdgDVoAGACwSSSVkhanpCBfSyA7T5kyaS0Z4HY8oqPh5aS0k
oZESuinhXsWv7QAhWqnwq3fwrI/OJUELAmfKDiFFFpKc0lNLBvH3uWU6ppHS
IxfymQtr1BCarX6/dXnZ6gv9Wudy0Lp8Y/GgWJubFugW4Ua1Z9T8cDVH8lCk
7NUDebJFwRNLMuSwKFSIDVaBQeyhDXPjEON33Tb2kbIrgWGiq5oqGSB9LHUC
60VRo5DttTviVbd1Wgsg1Jdw7g2iEAdsLYVowsACK8cM49hxJC3MZPOpaupk
IqUs+ETVSfx0d9UZsaSpcO3CcNYGERumpsFkR2HZluxpQzOlGRBXpoZh3zHH
Y8AMuQ8fbskHyZCUsIDQWXe/TwGUjKD24dUBNSj05allyrMoXFrdzkWnJvSQ
XWRTO8beU6GuHCLpvxNK/jn/KiWpkX2BgtOF2sh0R9JMssxFZIfQnsB6mxPQ
O7DqoMPJP/+bgX/bwsU//5tpgCKGaRLuVENWA+zkGQGtfufi7t0Mx5R/NZfJ
ZIKjUhHVlLRB9XeiuKDxF9hpamxFjK4GxoIlgYjXooZVVy2018GkEBqolbck
10bNnYdVEAWamrja7yPZTcESdmdRpL0jxkxyhK6kaVI064Pvo2pBNdvEb+1j
YfCwhYGhoq/Rd9BGRCVd06GpLAXIVS5mstUgnguddfz7gvZCjdcDg6m4BRjB
wrZpnkIr8TMF4XluUV8EnDRqnh/C4oDlLdoEOwIywmsQmdzpAawHF302eOpc
CGeuQQRsfsy6kqwJcTbm9HK5TIFcJ2hkT6BByiBOeu6ONBguUi1dyFRy2Wq2
khtuYYfIDcO4DUOY4cuhagw9zIaAGWNTzySm/4hM4IOov01xIzj85i7l2ZHh
52citOEG4B7yihaZmz+DxuBU7acx9yHQY3mXj0Jx+oGUCg+WQw93RZfOZ/yS
PeDUa5gNs8/dR0YGEBPCwtUMELUjEFqgPiyCFg58I8kzeKdK4LzD8Kj3TuZT
AksJPBlsCk6szcFHcKW8IGivpAGHGyKDDfNXVfnLtqu6mYNcCZY+MDGdB3jR
ur1rcme0VKhU4kbZuuxwy/pnj5O4CyVFDNUGE9K1zDn+J01/p7fwjxtq2FtP
Np+yaeMGQvS2gTd0dLh1sG6Ytb5DCZvQXRFRV+0Rmh3g1HtkAdsTYaNF0XwQ
cDWNVWIJc8mZfuvM8y2JDTmyFaFP5k4kNXI/nBoyGA+SLCMCrYUKNqBMBPAC
poKhgqlA9Lmzpjs/pq46CAIlkuU0JUdCiQKGqlDrNoV+607sX/a+mzC5GMJs
OKqSz1YLyVbEVuPvYOdA+3egGTuBb6GZ+04046h52u7XRMoxYq0TVjEfLz2C
yiaXD6/+WH0DvoclLVSwJx3LTsuIbtomsotaLS0pC9U2wca003Q0i/FkIuqL
1UrUJ5PyfgV0uwHqr5ltiuS2ScKXlvrzBU2QeNmSUHMn4Nt9PPUK81VeXD7n
VuJqVfhO6uU/gHofL5h+FiGtErDhvFARn3PW8tsI2VImRANuEftroI9uh+l5
Q3TTCe2NI6/Zro3UUqNWaHDoCcZNOBr2GkeNk2c7+wc+fZ7I4rNcXIjjZXm6
f+De4AQ+uH2D3lqDpwSXEk713ATzHroVFNP4kwOepENkRwD/BXhImhCgxIjt
UAJlfs7Q9dzLRFxaq4U4rVQr3z/0rQXUWqm4nTMRusSeCo0aClW6QGTLBGA6
OIljYAUBnF1Dwd1eIA0gCg0aHHVhTkCcWKB1QbasgzRBpUDwOOcHkMVayQtx
np+DRM7L+e8nSyFMlktwZRGAA1MP+Gu4HW/TpT81YciIn6QC0yj451iduBZb
LEvT0hSYLtWhkvlTplQqHR4jA5lLJJpm4mHF3FIXqkaAn4gNv2nTn0W4fLmk
i9N8eQnSZPHy/YQrbgtkzhUjAoqHCNlUtpTKRAqRHUnzEXJle7jPy3xeHBeW
slgp50uJhovHiaKnZlUNiCkyTbAtMum+Nde2qrFjIwcPXVEZN5BjcEtUBVao
4fmkKqMK4z2HdEkWnFMjxoHGHRY0eVSwf1XijKkRjA/Suj0BJpCc9CpPrlcn
z9cnZxcykUhJKwwvJw+Gbjcf0+92pSkte8C2EnCZaMFsaFuaw3sp3NRE1Lny
FJeOATyu41pSVEUwTGALsE5Ck048DQw8gesL23JrJkiJfMJF4aGTZrjuXw/P
pZeFWMiDarEK3KyNJIgHcIcYE3MPIU5NnO7Z5381ikzM/dQoP4+XYjFv6eJ8
Ov0WahBzESYHjEQD4SmC9bZQLceVtAiCyMRywCyV6a7ikoDcoJRBnfOjqLCL
136qzIvjuTipFibwL736TVTR91JFVw31X44kiFSMHVp90cGqfwarPifHCNW9
9LAcOUwPEJiwSkVZUzFcI4Icvt/CDHcw1V5cE0nzw6kSRm0/UYovliwuKuWC
qK8Wq28jiqhIe4TJd21DNdlxgml4aipImNKPJswcPb/iEsTseFqMcf9iCePI
7o+gzOCqMbi6/Q8hy2RSeRH18XQK5qIlv58snidciPKEfxyb5IoJCZJsg6Wo
V4BHVrCCnifz79si2LFIP2Indz+j/FjCTKbLhbiw5jkxVy0XExOm0xQblmqr
GEBx1UllM6lstlBM58vlai5TSeXLlWKeRjb5H0YdDFFjFQ976Bdo44Zs2Iap
z110Ij8LJ3isB1atIWlr/BRPCPccDV2Cv+jRrPjm8VCj0RADhnSahshooj0n
sqgqokwxe7c5G37TNcFGlMZS+MUgBX6HhQ8tMgbcAxTMVNP9XiqXyZZTdLrh
rXhTCxMNeEKi0Q4j1wEGmtDIC4yrdMgEnUVwBiNcIHht7jtD20Mk3P52bWKo
K2r8oz8K1gLYj2nJkXPF9BwPMTlfp5dENaampuynVEOyYLYM4T745Tvo2DEN
9//934WuCiob/Izwy0cYvz0VmvCvOaw/En7bljCYQxjY8tQcw0AmW40lCyjT
n5IxDGxrjqamLtnAdbYN49tCVQXrgWjCjak6rzYNWmrAgiL13kl4prqdwU3r
TzYNLTuxJJ0sqdXep0sSpgmNCmwlXEhrYNdH07VQnDRpZIstXIXMjOp7hIGs
ma7iLXmwcFSMOKCzN9LMSRrbpYHH4P911bGIaIsGWYpjDzfR5qiJgJpIRvOx
qCFq4hpQEyVVZEE3tmgaMfOMOPBBwtKucSzgI0oPER151XBhaQTXXZhyPrU8
v5a3EPg2YqDh1g6pfy68l6XpyClNYOy2CDirkyno0+AJ/IYi8gZbtqrEUCTv
XrHApz5anLEJB8kV9ODDwbkCixsOfFDXCFG29tgiPwHmtQhBmepgBOvmSP0u
sOWgsigLGtv97//T/y1UcS9ln/gNaaXsFiN+a5ADqItcNVutDiNHMaSDGO4M
Yrg1iKE5HuIghtUMBj4E8R/6+H+L+PbDSg+E7SDrZAeckdtWu3wsBLd7OIjE
55E8CFwITFd530kfaOjYg+vYkz5sHI3k+076Nu0j0dwKdP8+gufyqazQobvs
/cAuOz0B7OG2/Frg+/Tekv5Wyuf//0/5yK3Y0p6t2E9RO8SHAjf2bWT2AjB7
eCYm/ExE4BGMm6MRZyo5Ag0OoiGR/gmJvykedVaSCgmn8GASbeh2z85KYu+h
VBTPruP26yI2dMPkjWXXt+Y2/51zu58FD1Qv/JvHxonN1JjZNyLu54oE5XBQ
vb3vKzFT2P4Q3dTQF6U3v6i+9UU2430BauCV4TKWZMf+fJBKpQ4ORFEUJOAL
PNA/OBiAaUUvigiSqtvIT3PLxO1PwfFvdgCHAa9RNfi3v4WjnP7+92N4thUP
xB6Gg2K2P6SRFhEf5qI+zG19yGTIzpe4Yv/+dxqRS7UgoH6qOm13FDCyfF4W
PiEz24fCcgpmqj9qumQkptY3FPA3hIEEU3MpkO2rSnQ1Ur9sjnRVZXIs4IUK
4egIz7VN8EDmU/DHEBjun9n20ZG3XaYQW0UbR5fkKSxe9IYsgkd5x4KtYqcb
02r7WJiJCA1wsciLS6EAmbiNDaT429/iTEkk4O5IJAVM6qMjFzwCxFOy1oAA
+uYrIODRUUpAlgGLBZxoG6+BCSPQw9DxaE1H49ky0HdUOCObNOau8QmMsmr4
NCJACXdhkX/3QKTuMnwPtEcIRDTH1CqHdgLzUQEUd4YdE2Oke5aJ4bbjY8EF
TwhciTleChJzIIFBwBLDJtSaBriWqbiyyo6ejjEKBl76PxFBCziDLNnfU2kB
xCAEQxtmhrnUUOgH6KKRBTAWIjkj6NeB8E8JDdcCV9HRAB66p4RS9OjIYZYp
v2e4ub9oGvRp+N7i9kN6YdFfAcjlAjUo7SmgI00kPFWlOI0sU0IC7DIBPUqm
MSygVqhrQxGhjphs2lSg8+uPdI7mc89eDXAI44O5NKetadyGzQYoe6MWiEpv
VLKJ2NxixOCPEUEEwHkGNx4QxynZfMA62fAGQw7A8+7wIgVAEIBPsDENLkFM
gZV110BR8EFznxLqkg09IM7glqIvRE+boQWNb3GW5tbWFkV2l+QB9mHHicox
RRuk89Kg0TA6TArdZJ+bthN9jzIldBgePsvHLxocB3wR2nrCZck4VgdWof73
e8cAqmVb62/sTOyrC6rkT3QvED5lHQS2+VLCPaFxDDp0pAiuvWE7mJcoLIAY
MkwwhtoDLy0kzUWDCb5XgVk4AtgvnWwU7EymwGBnNteFuqooGjk4+JVuT+Kk
U/MWMBmrFgZXsN0bxvsrUCRoFwAnYug/vb63WVt0raXpqvWWWYR8ZTjgHwKu
MmQib235iwbZiNt5GuEHK6aNR5Y2W5oE0f/1V6HlY9TfYMSFCr0k4NpMybNw
iBHRQH3xIbFwCr4WqfB07YgBUYxDg3oXL9AlR2MzLB1AAd4WIt33nGzgzZG3
cr6AsTcQ6Pzg9RGdOJYq2//pk2fVGWDUgQ3npCbmIo38IvJP0vLCtg9hoVDZ
Se9eqzxKRJ1MMWwG1opNIx5CcQQMnRRI2hNYWLj9DEzENu2OhTYMxhmhGhKW
ku3LVJBsBwdf2c+vgj+Or8IlvTGNVOhtUS76HaXl14OvwH2h/wHwairz7//l
f6Hj+OpvTMCfOfjfv/+X/1Vg31TCL7Ohl9nwS/w2T1+BroC/8fIAb5Olj8sU
HH8c7KecKu97UQoD2rwobl7kAz0UNo8Lge9L9PsuUVRX5y02r/L7XhXDrbKh
V/l9rwoUiT2vYlrl9r3KU/JcwHIKPv/bZ+au/OWX8HynGUOgbtkOlPwkzSS2
fg6DC+iXv9MFHiW9D/bZVpuVLXm2IepmUPMgU0CIUK3wSgXke9FAyxjWkKTZ
x7BGJrA8qXQHhoY1R3U3/GtNtTqueB6eCctrTq1lDOHBQ2TLwVVg4WFxSjix
TB0w9PZfBdTYmEMBxBizZrg4xEg4hciqzSxs2TFBH/D1LQPiqkK393m4rQ7m
ugRSQk8JfVOPeG4HsYzGEEUdzfHAvqXYhg0NfCwtMOgHhQoAilew321ljF2L
UtlTDai1ACWgAt32ZYY4MBnFZNs5C5qETF/4qv6gJhwxu54Kcmt9xEynoDkQ
ZCjKMt4xlOwfQ8F7keIZHf7LjRIk4bYtDv+/TcctM+T7iRd6xBVmlLtxsN8N
CayoXW+CnSkxVQeLw2JBDwIC8e1lz8gOBRj5NjRi6Sl1VPTU7pd3dqQXWzvS
QK/3KOHPyCxRB5MIAIPRMXSa8xAulTATccc96IGkYuAFw7FjYeZ2Ye63GpHH
vH2vLaDRgcUh4BmR6lJm5u7sHwTdKOSObf1NTTkU6b+CqBJlC/Om2MLfmUG1
PSV0CsNulTfLx4CvrLlUGuFhJEbMaKpOL3KiVN5M2DHdDKMBiYHfpsXviR5T
kWiDHJQmICrBMbKpk0a9ERvsfhkMH/ilMRrZdB9n6u8gpoSasd4yhLjAXk7x
Xq+HLgJEJJ8x6DOE3sgiElimvujmTG5SZ1PjANiCR1QdKgqW0pqJbSnSIMYN
h+jtBqazwJ2CXhX/hdcLWmM4TzhNgm+YnajU1t82sOBbzjFelALMv2f9RKY7
ORZ2s4Uw0uwm+RAY/B3569lEH9XBzk7bh/cQuah4P4V9/QgR5M3RRswejW5E
r857p0dRIPLfDiJKLHzdCISveE9phuekrrL+sxDIjwTMOVoHYFKv9a0xb8Xl
voV29LTsTsnx/vEFgl9/Zm/EXPzc7vSf2Z3lyD+5O1GRkqyt7YA82pa7SjFt
dzR68kW1o8CTg9jZ/P9uGN+Cxxd2ByOXW4ir5fhZLOVlfbPR8F1BuWGgh4Ln
qvsIHAvhbEfHMdIlgKxenVfF/HQ1FwvPpecPQjYM9NCn4/ciO5/LBXE8KZbE
Vb5a/iBkw0APBW/r4HuRLT0XyiLMFbC1PCl9ELJhoIgs23n5XmQL5WJRtKYl
WSxVCx/FBmGgh74o+m7KjisvYqWiL0S5srA+irIhoIe+7PteZF9eXvJiSYZp
K1UKiw9CNgz00DfUvhfZ1coqictcMScWJpPVByEbBvpxyI51ayWOn1+WYr48
mX8QsmGgDNnyRyBbLS3F5+dxRVzNl/mPQjYEFJEtfgjPjl+ACPmljDNWqH4U
siGgiGzhQ6SBbk0sMV+QZXEsTyofpcFCQBHZ/IewwfJlXBWfx7oujkuVj5IG
YaCMst+nFPY4OnluT1JKkJFkOyp40GdrTTJmalzDQsAf3kYlgOX7sPKvSHyL
51h8p1kbHYLFeyx9oI+3u3Hk6fSP6mErNumHj6H4puUchdfbrkOiVYR7RrBI
DFg11kKVScwljJdCaQJrfVkQF1OdivyuqbDouG/j1ghaPlzdBMXA83N1IZbz
xbyYL8rfPYAwtMPwXsSPGUDVGk/EYnGii9PlYvm9AwhD21gI3y4qGJayPF6K
L2DOifJyj9JNgGUYGtO2H4HleDwpi9Px81y0nsvfzQxhaB/nzsir1bM4XyxW
Ymn1/SwbhsZU1kdYLvMFrOVCvlKEiZKjjYEEWIahbWj5rTO+OcANRHPQY9v3
BD3QEzu+AQ19f7JMdzLFE1VM4UnTCNNjedNSWFAAD7XA7XpRZDvYLFBC0EHu
e4FLR/TUcW4RPDQwJGtNz4ajj4bxjOuKh5UcvOOg2NkczeEZLLvw7A1FCtwi
e+PQlRHJe6wacQeCLJaLR3vwow36LHQh0EtXan/Gjf5LMwWzWt/uFp7d2uz4
86tQ809pkduy2KBBL4H++3/532wK0zAxoPKrIML/vozoRGUjOfD9yRDTjkUI
poEw0hzgIe0+t9V9cPwRaOQ+Go3cIQ9TgD5Yan2ywtwZwHihjqNl7nd0nD/k
oRPUArWAF+n42Z0WeioU6r/w0f0XDnksCNLf1OEhIzrw8K85yta/5sMoFD8a
heIhD2LZjwJaxF/2HntGIrR9A1MnBA9DbbyzNmLd67A2sbCDnWZ2I5qNKe/C
gSjRa9HgMAUP5+fK+PDPwhf/JHeRSYFtu0EAr3TYhi2qDh5ulCYUleWcXvgC
3k67c82UFBvvzBXT2Vz6nuBwLbGGUYx4NQGvyQ2wrdi4ujzpNFuXg07tonTK
e4auG43QBZ9+5/Q94z/8EywqxaSpCEBWPOMtiC8xUicS5hY10p4EomH1c1NG
0myCFt25QpNUoaTcgJPUlA6fUHgUjix6p7FpTDSEQcmAIB5v0iuDXli5uEQC
0aiLww0zRm9Dfgczlg55FFYUMx7DYjjecCToi9jrCdQB4IhGb+5+B6K4sRvQ
vzuy3j7eUcKIuBfOvQnSQfX4n//zf8YYTi+u34/egAcwcPh/1QgeYuPhNY1k
HpmLgJ47iNBztO1+3eba/MrqwU44OoafB9A1FB5chejpqqNONpoQ2wfiQnxU
t6IOUsKVi6oUljnGIxNY+eyYXXXAglgf0NwcZBMEiefpsCwJRrA6YJFMgqHb
IgxqDPpf+KTBB5qQP/SHzwYVN2xJM/HuAo1MwuxlI4yWBdGAQQ4HLF4nkFvK
i9jEw336BLSSDiAxzIblbfDyA0qbdDwHYxY3pqhjGqvpbK5M9FkcOm8K/fOB
25ii3CMISCwDhIR9AFTAQA7v4oVNlVSKsszBAQ1BtudYm2cEShMnQTNtwgKH
d2In4kiCF21oehQvPGs7/EC1bRfewXc8jn4B7pxpUergpZRgcNe7orvQKaax
H1c0LslbQV2feVnoSjia7cWFORLGGHGBLDKmkeZK2BDEQSEk6HFD/bixR6wb
8FBtXL9rjLYzJvgWuQq6/ANkhCP9gfEsEkhSvL/GolIanBXwFI9OksDlKHL+
Cb1DIXyRJhMMTHTIx8kjH+Shd6fOphKCx08qwbWrRI11b1wgzBpNFqqhtsKL
lSzY3eFR6vxXik/gmF0T8ZCgsZGelR4R90h5gCZNowZfUFkGb3qFhXz0ZTXK
nXTxsRA6pi9wTlCiSrgyAuk5PiH2/mWFw8h+du+pQR/+vQwYKU/Qh2H+9F4A
5RKQCHzVe/J7EysKfgHY+HWqO4QpLDV6e4Lr6AOwv6/m2BM22nthAnnO2TSW
FIVfNbHCF9gp+bxQeaau+CS/h5SKyfMkzVFIA4Rwil3J5pd/VPxKODrit1ZA
6lvEOTrylgPrl97xAERVij+XHDvRlfsZEO8GkcAlLOZ5WRNXpw7hcroWQv1T
rPzgLHpDMGIQwHy9N6gMCim67TFL0YGXInAsR0fe6CQtdPfsLdWrYhwZxqxh
oiqFRvTh7XisvICCkd2DYA8wAZyGDVBJ4Z1ZKmT7RE6B1Z5lVx33rF8mjeDD
Av9sEy4LXdbJ2kThgLSY+LelMX/lDK/kQos/0CZsnf+Bq9qr/xY7XTSgGgQj
TDreGKYhctLcU0JIVayhQdhCwUZYDcdLEor+VgAPmGqC11zma2Ya4cqGz1JC
T5McZKIg59L8znS8GGuMZj61+i1Yq9xHpx/gpRJcuCYqS1ATINngeXD0iokr
GmvIYf+sStoxrVoQSOOLw7xrtM5xVoAqeAOKbnHDK7xDskRdRYcIOn8uuob6
4hLOogxJSRg06t6laqpDMaSR34NjlfvmfJSbdpYvUVGsgwfWv7k89XAnyp8R
Bc+BOt7MHfaHBPjUahw22y2B2/kCXkEiDKyznqOVr/n0Z+OxzbFDx8IvE4Uj
NeVgXom77saaFCYuXme56uMUytZ67pgTS5qDnSBq6shCprAAKSAPXmHlYZgn
LHhcNy0gt0fnP25avaubwbBZG9T+YHlB0QbcXFVkPbGgbtmrGaSwzDiUF9UJ
rpdw4lDcWhC8u67s6h5m2rFgwTu7E/lnyvwEZpDdfQSyqcomFzTND70JhEX7
2NN2lMB+RwwHP0dMgLOJIdHLPAEupLYDLAtCb9ORlawBdRfMOuaR294+l2kx
G1BhVxDZ3AJTs8jWPy5a558YJxz+EVyLNiClKUyY06v8WH8R0EIhJoGbP8cQ
YpldxWIh7ISSdmuRypJrM5opZIyhzyAw+diOwcY1kfrYnK5DEe/fCs2b+im7
/3qMjZiC3PAafO2Rnl0llDCkGm8Uh6XAF25jFsVSDv4vvAsg6QpLd2ukPf/W
TrMgfEf0N2hHLmDloBGlK6I9EsuZYpEWHDz0nDFq5JsGLkCC+Y1dtEVhWiyW
RAdEGFi9TEJ/FsAjYdU1UVQ8gYYoejagSQ0jpDcAci20xW13zOml+cuBr0gm
OYhF7ag/bpr9Vqv5B1WbNpcUlNkt6ExbUxaXqCVtu/S6NvdsfEWOnE+3bqmC
AtgogDn3AKZivydS9kcVRkUKTWc+xlsvnv3mbzXsZj9jClEhOiwSx6IJKJkT
o4CHJ7KBGbhvBEzl6nPmC+OioUkh2CU/bqvRLVR2hffPG37wTo5oWD0McYqi
7wqe9fsXf7KFP0QRVxjtCWaWKH+xFHnu/iF8+sI/EvLgc2SEzmV/ULu4SOlK
pPFtwse2rfn/pRtV/IdIIaQ3EA4PPb8HRwIrYDNNQDv4+6Z2CX9TGd1DiiJi
MGtzFwSzqsFipqQCEvvuLpro0sQzQcDUpFwAxo3CJDCXF3SmgAkJvVDq6TpP
wQVWJrOwL8yleEE95C54z9wtQnKzXTxubBycYFJqIuRijYnAkhi0WqI0McBw
AObwZk6krviBl7CB3qbBK4uSAHPMXgrsCvqWFU1ljC7Nbb6twRM+ILeC/KA7
/ya9Q+PlJluQQJECFP5B3by170JD72F8KRgdYS947o6vASDv/OdrqKf3NYHu
xYh/hOjHcf98UxPo/uio5yV06LJdCLBPv+K4RaoQNI+cvsmxb/R85H4zpEZs
I9Z9o+HbbNAzh9Xo3Qrte+HfKP2BD12A929b+e3GaMpYLhW5wSZMbKVxEj4x
A+JwY3j9m3DThXetO2/PBewNhse1a1IFTPNoM0yQDMJ1K2a6oSMhTS2CIG6f
7rqBLqNHHbaPvJEHoNOtZqFJLU7h06B5+CYzYQ06h14FBHy2DbD4phSnS+LQ
u3g2OjMeBTyYvtn2b1SeeLYaN/mATvvRiW+KyLIvttBp97vpQS9Emq8sAwrZ
WqyRxHj/p7Q3ahHXzv8IdPc1tJuPEhRryQJHcE5psaCprX7R9E/fgWVFla/n
urxJfM8iD/V/z0V4Gn1cSq1N3ZpIqN/SZNP9xSDYP14Kptv8sHyxJV42fYOk
39IksFO+pYY8Yc/vSXFfd1fcgwTZkuu/8LttiIN3lIRG7dLwtiB82Awoc/1s
5vv5+4IhoAd0/5AuSu4GevdBw7oqZBwGze+womN38D0tlg5OzVfhxjXstKZi
pQi6v/zXSL4RBuv5jniJ/vLGN7VoT/yK3T71815l8n6ds+9LigIKhVYDvc8w
0h0mIIygWNoZ2WXM29CHV/20J3m43cXY7+vGGY7uP16SfhVOqfDyTdJvQqF2
7n0TUkObpidcm3iRmmlfs+J8TlVY35Y8xSNpfwPEN9C9Trpgh1trESCg2+3J
tK9CQAN73bW5aZn2tRj4NxKmAdoek98ShpM+b54IG7KG/PNNi4ZFvD0ERrq+
R7qvAi2N5LnIMf9gHEUwcMw3gXn+KCprgqLlwl98W/mZcVVH7/KgEOmBMwdT
rkdSDrfpbHb1lb/Z5pU/YRGLLiz1g1+FJs0+Bp/fhc5emuxcBmXkQNXx1IOw
00AWZlDbpGBi25pAtZrnSt6xYxaUJC26G0kJSIJXRuEVnqyphkpR2pwIEe9E
iJ4smfzIBiBkysKVDJ4Ies+MN8MoIAb+x9kCjEsOfBwsOc63Wb50WoOTjVsV
X2gEpsBOlyajl1Xm4bFy/2i1891VYXFVMXKiez55TOMJMytmQnstsYAsTi08
L3MNmeIZ8PnJKOX1iJ3Bb5oZN5PLlbMlcOsL6VAK5M298JRls0S6DiHsJB23
UOQ1YBGkQq4snJBRAB8/CGGTgmb31Ez4cnTkZ1/5i9DunLaxSCo9B6scHh39
J4TMC9EFYd+1os7QNj3FwS16cEs7cGmiwgAYDJmNvKn7jfC/bPgoPD0xtVYw
2ZhkEzvtSBMWgoCXBmlkR5ZOgZ+7nx510EZRxHkHxlWaSfhb8Z2Y+3EtprLi
xMymciXobAfpifmNCGczOxg3diyhb4sVwWQlGj05+RJTUfFdsT3bsNNzV9PS
RRrgmC1vj+Bu01vEYOju7DeOyMtFhryZi+k20YkfPSXEGWXJDTBPEq7YLeg7
wVE7QiHimnoMAxS8NbbDsm+Lndzu+m3cdAadRu2Cw6/CyuIM5pUfTNRD/jt7
SE6t3A65djpkEeoe3Qq7vbIJ30o0imdkAbbZpMEONPTX8g6au3fp3zGn+W/t
hF6f/5EdsBvzP7YH/Qf3wO7Ff38PPlfsBk6De8nVEBpx78h0iOHo39PbxPy4
nmIpx674v4N4pe/phCUDCPfSbTU7t13eTymVj+1nyzzyMgVsen2vbKq8F3zu
A8G/aYR5KQd+QjfvkKtvdBMx5z81bUG2uoNWPF4/KUNBBF6xaP2kXARJ0fpJ
WQeSovWT8gskptbPySSQFK2flDMgKVo/KTtAUrR+Uh6AxGj9kBv/34/Wz7nb
nxStn3SLPylaP+m+/h60kvtd7HZ3LtqmTA6uEAfubb+z8MbOlO81F7+xg+Ju
B92rZuumNmjtmKb7Ogkbj/4Ndr/P/+f/eq/FxSt9JDfs2PX37+4oaij52KEE
ZqOSyn3AMPIRwwhNeSmuk83RgL8xH74UEdweD27MS1s78nhMgGfnqpdEmOfM
NtjtF5YlmybFl4z1JmBpLSynkmObiDsvKhAMpA2F99Lo8j/uiTRrS/b0j2P2
d7P9B42B+6MuKS22TfZH6ugIDyXXAhZmCB2Q0DNV08Zw1RRJHXOYfXp5hkKl
g+MPADQbq6aBg2kq3vGt7WUdloQJVi2jocmtW17k5qCFlWqIZAi3Bvibf7KF
L/TFRpRFVrWZmjqZSxNySMPXw9kANiwQDgtCTrDZLSB/NnYutrDk8l8Z9/h5
Nb947PLutOyRKTj3Z7BkCcLfSBW3yWz+Rj64/R9uJbKI/TCYiYPjt1kAdJL+
ZHvXeCht2c1sPJ/GmGwvDT67zbFdVm5vGTnhQnXwUA3W0Cb7LFBU5HfDoY+Y
NPpJs+fTuQ4frjE59YFTz6f/y1K1QGrMafRb4KAp8DQ9Bpli+4/wjig7tUSM
Pn2hMVXhsFSM3tPYdja/kgpP0y4qe1+/izLBGL908KArTRv6gati8B2Lgc1m
xFxFzGSyPH4Vl/aXWrf5EWGx+Uwh44PddIyko1eTL/GuD6XZoNXaopdDSJBW
9AbpFqW2gTSbN2bA7lYUlCL0PAJFCf35H0nrkpipiNnsj6N15Z20bj4o5jJw
/KNoKUnW6fGnYqppv3xvqVgpFQqpfKmayeUz9PruTyRXAVkzE2RNzDdQFHg9
AhxJ35E04gakwEqWRO+uDjeNVRPvK+Nn3n+HrI5truQxwyYgvFgoZqrh4cVV
+uMNWNoQmnCXF1FA5OqYRfqk1h+8hR5NNz2WbGfz19CUZhpwRxSOpWy1nEuC
IzY43C7zQDGUlJtadwNqJCmWpONa4X9h35uuC2IO9FThY5g1y+Plt+tZ/GjK
ZZNSLktRrG6heCKNQBHMiPIWimPvw81f8fyXzbwDQ3gYaBCF4d5g7NgU3kHz
ZE+tgNhcu9t2xnthxBk1MTDelwU7AHBj12xbL+zqVEQJglDUjuxbL5pvvXjx
hPIGoh+jiPfsKXhqZLBaYkdHiBfY4vSeWMSxjUKvA23uuKvsNoZOexPWxOFd
eTWT6F1uZ3OtJxJfGgLHkiDg5XW/NlmgEsmS4OV0zNpvzGwvFtLP70/Neaza
R52WgwN+7Qq6UAgvE8YyA21d0kS7XdugujHT56bj2YR++qF3lmv5tMGflc8I
9L9xzQ4/v1XKKKpI0cH+AkWsxNBOaaIcf7xVlIjFPFWCBYYiihHl+aNwGaKD
3QJEB1ulh0r8UaDsUDbPM7KEawdl+NN8xNPdOkMHURWGDqJqCx1EVRU6iKon
dLBTSSjoYazmLGItMRsE556vQl57L5BGCm8xqTpdUDDjzLk4pgtqrOLFJcnm
V/14tayBV+kHmoGHG+yDLoFAPEgnHFh8cFCzg/eZYm+8elXp9pfVgcWKhdEk
Xsdws3C2ybOTL8QigXvrtDzKJr3Lx2Z0+RylTNjIdn3gt+KWEM9kyYIiKw5/
LE4HddAMAkb88aJ7whhYQqLk1kIRpbQ6TLAQ1NgPVsUKfiwvB7tfdU/v4kXt
9jE8I/Va8b1HrnQBSI48ZRzoV5lZsHLjx1j41Ks6uL8mjUG40KZR7Tvf8fwt
XkS7srlwxpTPWIUeWJ1MUAIzQub2LpBAMa1Bow6E6YyFtemy+lPsTueY7owx
7Rx7LX7rbuGcBtwJWL/Hhf4NEDy2yVTqkt29BfrIM6+szE4qlKgNI67DeA6K
Gg+9SHdZVhugwY5AGCRauEsSWrlbBVePjrxgD0wSEKiUeXSEcR1HR9GUYev/
Xzr91OefElOI1AzSkJLF29n/7/+ykxMs0Ekg6tdCSQONqJhJHLV7/JGy6c8w
HF2dUFXDKi3HxPewKsswRjBucOT+SROPSAICBONSc6lM/CETa7ahQvKItuMw
R7MsVxwpb1jxgwqNY2JujyEPLoAXW/tWhG7EQN4VNfcBgwjbFD3vNnM/mKjS
PqhF2wL+5edQXksmWWPl5RFeFT7ashUQ0/czKJUsbyRTq8Jngr3WR1jeLCov
2Z/fE0/LCozTiFok8tgh/vGJj8JOfOZb/bJo3pBEEATRU/W2cJqnV6uJxZJg
BQsO0w/3VPPCvDSOTbRxsPgjZgIglrFDr33JdAK4I/E/UWtLxIvqc2KIdC/8
kDt3kpf+JyLn2yfTUido5aJiQ08PtbaYKbDzG5oQw2bpG2DixUyJPhcz5UM6
QKyKy0ya+1Oa3EaV1TlW956buHWnAEkcX9FiBjCmXkdoMCUQc17eJ4k6nowF
twUrBbzJUhX4kmaCCh3OiSxPx04revoWmNNP8jgFAOi5g2lZsN4llFuHrJlD
MyFQFvHzIeCU2eN1ilKHlt8ME8b2EimwUs1e8cbItGqYJMUdgY/huH5qD5is
qcOTf2AOHZ4xzCs3OvVKhKN/zQ7/4utyhksr0+XCcK/RK9IMkAXTRxNj+NXr
vMxPbNBHR4rKEkbA0vNS1rB0VWCY7Unj5NGOdXd0dBu5VvDruNUCbiNKQfTe
Wd3m8N2ldwiOr8K9H4ofF8r91bfmhF3IezNehS4HBF3aQJnqgHDd3euhNOLH
aV4eO5p0wcakX832Vo6qT39MVus/DtnFMsneejsizhLtRHmTT44l/cMsYW1f
CXj5D/GS2qc/po4texDpftTmFhsgv1EdOk7ehNgH+ZRQ22RT3IImxUILZGEU
kLMPDnpMdmCqLp6VKj6RBMJU6Ik8rQzObnEjx/TYokZx9qmBF2s11s0prunD
zfmiv86Fv2MORO9Mnd4y5cn3JLyWN+hzaxmDAli+DlwdLNnR/l3BFE3WFkQA
XSwv4Q+eSOOk9tm09fmknmYPcYZiWgUSLG/mccApf46UP80d4sy8D0Zw/sJQ
8odRc5JPNCddlOU3NKmjjQZCLZhSMKpcMS9XH74PHZGIPDYx544Zs5W3TdxO
Dz0lGnikXp5Qdvsz6+GH3+PNSD/74SYVd1S7XLBdh+WAi0lKyhOPvpVZkyYb
3SSB2mSLC+TDocfaPU+jxf7zdZMhU/g1e5w7LhyXwg/zx8Vj3KTr7Y4aheJn
UYzvIdQZ/9r7w/8vADrNCp/jWJVKOWjx7//n/8yB/fv/8T+G/0AouTegzOTp
FhT2VxhK/k0ofwh7oPA/QjkK8IoH4316Q3hrLZVTWcrvPGtO8b0Li0pPPwUh
Fnj29kz9hRafPj6QNH7TliO6J4whLrP8D8sqnz78odA1c5JyVs77c9f/sLz1
wYH+AOihgUZnx/9hmfGDQ/sB0ENDi82//8Ny7wdH+AOgh0b4Vob/H5bdPzjI
HwA9NMg3awj8qKzxwUH+AOihQb4rN/0PSzsfHOkPgB4aaSUVtCKgW2ZHSdrH
9etBZMP6gfADA4s4sgzo+l/p7r+/AQeTe8IUsU019r6XVM1jEgxvpwVMyHvc
8deorRizo0vtw2M/seEX6kyKYad1NZcCJ2fodGFioxmxNtk1FFNO72uaPjxm
aUq3LNeAuTtg4QcEd9EAlwn4iA7fR7AIRn0J0/XIUr1M4uh6fZLDiyDWCPbS
DEe+Pnyvp84PWyN9f5pbWMGzgegdvbdTMgdtdKw2YKw3exkjYpCxGg7Z+I+e
1BRyGLpM6KSEztmOjnzEvX0yPFnA2dyZxiBj0C/eGpZXsoA3Qu7ZPjAfrek+
a2Dzk0eRsBTBXlmJ43Diz6297w/gCYvQzHphlzK8o0mJyEL3cQOVpuNVGCHe
g4CYKYRweBPd4BG0P0nww7SI7kfrhLeE6R5h6p3i56J23mLip6/qmIUHhwQj
x2IgMnRHv4wmufBFgwkXLendXImPRN4offheFNEFoRi+feiA2zVvnWvg2bRk
zOhmLeMoL1UHndZNEo+3NxqRl2+AkZ2tQxZ2wH1EgQfOfW1M4L0WFMz9b5mu
fcyP5wBNZH//1sIxD/8KBGlN1cmUphTDaBUlcAfiW0LXhE8sS/5W7P3f/37I
ErBahGa7wxTTR0dt4EpnhNF3IBKWIJyOjjAgCU/Djo5SrBjNqbrg+e0RT5Hy
t8xDokTbO0jbQvUYT+RBWdCyEMoB337H/L2gbVAI8XwJsCJxJ59HLsQJ5O5t
f3DgWhMWIoYH5fFil5dFeYsJadq1HP03O9n3Xm6K3PEwpjS75sMC/mgg2See
ldCLCqIkx0zZDj1zwPyDPOAvZlwocvE9PVVgKSRxDYKS9SWCpdozjm1HkCa8
2gHBbQma/tydozi2g9vtwdoata3evNJCXnkajGl0acEaCps6XX5kkJebG/M6
Uw3mt+I5w/mmGHlxqbSnh5QTrP5j8GMRL+8vILumx5vAcrA2Q98wecsuAuHS
wOH516s2WDHGx9ZsVdOWaE0QS1dpInTbE/OSxiLA/EIdeLxlKCwdPOEpiY/9
fvxwEYYOjVjDLPvyJkX1iM6bpQIliMLMe6+1TiQ8bQGpw6BjbjaWv4gmlvN3
DHkCSY/FQscq8DE9v5G55vVKEiCcEc3QznJO4jvirUhv79U7Jwgy1mZ6+W6s
TwEvabyXeDsl9P0zrnCAwXZa+BGeNbBsfhITYTSNNUuxz2eUihaQRWz6JMqZ
m/zmG7ToSOC1x9M+tVh4Hhl7yeB56QZWFsPnS3aLjxniA9PUcO8fc2/vFK/y
DQ9/cfgWCK1r9cWzQDaaTiWE1oCyMGMdIZ6io4VG0tUK6Jpi/tAPlwrrzU21
GVYEMlzgyAsfCpz3AdLsIPPLWF2h0Gd1IFjJIu+HV3Elfn/5XdE0rHOaLVJU
FRBYWAIk4CZhHlkpDbgcsiNBk26aw7Rh1n2aepOVfUFKWw6L+gWcUCqOgUZ0
+YbLxLyxKe4tA4SdovSxuLVD/PPLZeBgB0uEITMC4ZBhsSzRlOeNZ2Vw/NNW
CpayD67aQIpC1Euuwc9sN6Uq/vVmgJMaowPwQmp4YW1kAq+zsostncFQqZdj
Xx4EyrTRe1O71tQhlvhiR2WMpzkX+AtI9lUACjX8ek5FKysfslUHIDQ9ONEA
QPcKf8lTU5UJr6WGvpUGpklA2vlyPGKMOGnHzDrx7ZEwBy4pniz6lyuI+HmE
VXsJlt9n33D2clv+y3FI9Bql9heTLwbYs73+OYsw2VisqYOTHd74fHDwP1Bt
7U8LmufZVP44tAB9GIErnE0VJDwR20TTdGBN5CuBX5EeYzJSVHtEQ+UOzzVN
nWOxAJDHC7QV/fzOTK/w2jQ8zhQvihJaWQSRQMfWNUIOLtsgxmP4BaYaRd9g
SyRvF0HmZy+bkr2UuyKIZPuBvcCSjIlABRoqs+sZfSOaMc9jV4r5Z6L8YGq+
OeLGUogqMyR9YSgoJl1b3g6Gqvn5bgEfn0XDlfH8WWJ1j1l1D5ufg29K01Aq
GOgkAcG98ILwa3RSvEJkgBZnhRTes5Q1SdVZVLouKZ4FafLLI+ChTFw2eq7+
Nmf5B4Fj/dhQeovw/RoMaPfqd201DRSwYodxlZ3KVoLObDGb8jbYCESfTyVb
fQ1GNgXWMA0dDtU4o1VowNqcsINaKjxdJs+w5BtOlB1C10B82bg35kr4nvIN
DWc62LwOBxLxqkRYyM5nabYHEUmsFB5Q48e08iSP02Crgm/VOEKrf3XTafRp
NgSK26/b17oP/OPM+LofgfrbGy/BO9SkC8nPtc5oiAElMvFrce/e2Edkun4Z
UQ+Pt+qPxOKxscL4sbcP3gv05uvloBaqKfkOenuRWMxMrc0lGQzNHLiDFyAW
DJuwiAnwAiWhgWIQjFs/WMUgy80teHTg1yNgvI1diufz2BDwHjMjXeKZBTEr
8YR4+xie3t4T0I7GJ4Z1h00dqinYroWlR5aB30Trs90SwMpBr8Kg8kXG4k9c
PLHaaigPNXVGheHIU+/oLPghhDBHCgbrS0LvBkn65Vs388XwTfJvan6ImgBL
Q2JK6o1FYbsjGgT/C5s0mU8av0wWvMyRjry4mI7iktQv7FB/q8HAlqf//IeN
Oq42OMQ69zv3RWhsPy//Z0kwls2o6c+UOR7b5IWOnWUN8e/JiCPqponZbCkj
qrZouzZKBHQ9RccExsXdrNBGF5V13hVXkV9B9XAR8+DqEFLO5nPZ6rhM8oeI
GvLbmARvyYJt7ZgG3j+nSHkfpHkUrv9AzIn+xhF0ZfML9FUxVxYzhUxGdB05
TfsAdaXOwndm6aOUhHkaiJ3eohpt5K2jkCxNqYEMwvu+SIceRAFvdG4aWGDq
S+jLDeQwRFm1ZC2lufRxeouqh5GMQTkJ+WHP3Vjkik+nBMxC41D40gjJDSpV
PoUv8B5ucAsJGSqCUgrZYEU/F+mVIJgiXtwPWIMYC9UyDZpwQMyIFTFH5yYB
ErlkSAB30OhgSQ1218CiPTY5xGQevKtsdvvCuvHiSgY8pvzH2c5Olwu56haM
83PwlNa2vxcQSFM/Ty2JulKN1AtbW3Y6nz3VVi9WyRy319pgbTmXtitdb2Ml
jQmIe3BA+56BHwHqpuW0+j1j8kD0vmVmps+dp/VquQWqqYJYA61wb1ogWAOZ
9WOxrJQKyrLzcFLsPGYKL2V1UnDry8k2lmCyEBVvguHhJlj23wjyywn4IAZe
Dy5mA5nUxvxpyiBOWlHxwDANH2y1CF7Uj2xRzrIWmmRPwTAL3A6SsWQg3Q5K
jb23tKmTplosINPodrbIouvZHc90KVMsUIKcSXOJU+QGvdr/TrjH+ndUFfRN
mXmq9MIHWOhmmMksaCAu4XMgUup5TnkXd+y2VxJLgeEoq99a+d8q2d9qrd9a
ld8qhd8qpd9axd/qjd/q2d9apd8qmd9qZe+bOv0j91ul4v1R43/UvVe1Jv0j
/1ut6P1R438gZPZNHruonfxWh07L2KTqvarmEI1a47dqnXda9fuqM6mLJfLo
TsBeUSLN5yksg4cJDFQ68vTWt/vh5BLAye2Xub5wjUEzThrv4pusn9y39EPH
cwqPsBtllJrgwEncEDYfbSkRH+03weXeCy53yGzwrexu1BCp6QQYH+8ZU3Ev
NMkYjVx6biKvocdOv3YYXigypvvC9Eoo5UVaNtn2s4XYaXsEPeT4Uq9pYI8N
WMXfjsGuTkTXQ5fgS9GhX8IS418ytSIyM0g0R+jnwsK11qxiI90rYc6Und4Y
G+lBp3UzzA+3xoulHCn7UvsqgdUVuLLsP+MOpQ22WCHj22W5fNYv0StaroGJ
5sQ57k6D5S6iQ0oNVTTWwJMBgScqpUxulJOq46IyLoEddsisQyK06UGsgPmm
wuQHk3ZK3+Er3yDbZ93k2dLH5Vq3VBLYBAcWGeETdt9zQbbsGGxIT9cijF+0
Y6L9tgMP/RsyUTEUfwd3i79gqshLNoP9pjPldKaQDp6Aiv4JqM0sGNE/+EL7
d2SZM2LQk4CxuhJ1MHUNE0MmVNQ2uRLohdK2XqhrQLy25FwC8w7M2TqgBUb4
CuaIWi8OvtvYGtlstZqlpuInz7kDhp24eMECoLLZMsygLp/6zxiDB2+5LiW0
3ufUeUVuGBE6Cg1Ziw10ZOKddWstqg4M1cCoELpnqBNnairQemouRfgfW2bz
OVYqMxU5dO2eP7BTeI2D8QqZeE8TIpRWlWypWilmy6VC/q/qX4BJMuVyqZTL
5yqUyF+CpYJ8Ww7JHLBFiFd52WJlgoIohG+E+dxI96rT3rq4JCvnlBi4s8LK
eQU4DHe34DUeNhGsBUlf01HPXc0GBvecEzAxluJmexzkjRjNdSFfyj/yobg0
gd/X3jBvqB0SDKWAlx5z80QUiMcm3VJ4eGKIEMxpo0hOVTDOaWJJmELffmbU
6DeYJRleYra8xIe0O7q+9y6oCHfRr+6KSwn3CMRA5gSKEe05kxWuwSB3XD24
eMyJnaJZJHHzFqc35c7SYDDxT8WOIeMUBZx2KhDxLFzEZAMijpWXLIYxr/fM
ic0og2JgQoUqETFyRbTpZKoTw6EtaUV6utlOF+2Na9sqdWt81ryQRluk4280
aZSyXKrewGYtFAvF1Hw6DztHdLggVMIQvKfUdI1lKZWAepjwqdZcAqJixx9S
jUB0DmY+MWSSsuG/KdlII4tznYfedZrtjAErq2NbXjnVahE4K5tSWMounDWk
UmGkvoYjfvAJd6voFpCddg0JtJSmSSLMxRxlAEhXxZVVCZSWtmdWtojcGQCZ
t3LOOUBfn66qbWtEMTFjiaaKBpj88J8ZXaBTYs/ctSu6a+l1oeoYAbIILZAt
Otn6q6IHhZ7tpOgztvTTUiVnatVqZpu+eLs2KJwQSfaMNqRoMqqmC2kQdNlM
LudTMwBHBYsp4G+pKfqAqdV0xb0drzO9rv7SYpPgTiaS4drSVr/eY4YzDGEf
+6A4MDWwKlQH/BXV04u4DOh1YqoB8ZesmS6Qa2mKa3ChbDwy5yoEj9DGahid
/bWY5vgNfJH2v6WhYIHTqkhZxoI96b7N3ARjLkBoe67RJ0whregvzJBWzRWr
2VqmCBxdb4jFTLYo1mv5pljP5gvler7YLFWom/dFkxYrITx5dNrweWrqeqyc
3pKqLOIVIypBy4EcFTF7loj3kvdrADYCc+puiQp4wlZNOpspFCulYjVfGGZz
uUymkMkyo6OHJiJdDWw7RHVCiUr9ZynVYsy2TwmENT+I1Oq4lMtlxVxJlsRy
rpoXq4RUxWKxWB7l5cyoMq5sLccLtdsT7nqXm+41VZ8v5swy8dZk2CDwlA4v
kcdQwWnmwgQ0XEohiy2lh48o/9rpWafUMy9feyvaAJQCEDdARfo7RY9zJTUF
wozi4M0S0E7EM+ewZkQcuB1NM5/t1dvcWMQDPNo7OlPgHEU6TDZe4UbFkv7r
i0us9V/C/OxvioLrl9A1pO1/9eFTSJh7zdLACA6aioGHdEZyhUylvLPHHdTU
GB8mYpjEJhkn3nk30EIGR2pE4FvLf8eMROMZRLtvmm1vseFLmqAR6yPuUB1X
jYaRfMyH8hJmBMQuf0LtOgqDBy+F0AbLEmUTQuVRStw/kdzwRpjMHgA1GDBA
ZuFRgE7wlHgQNhrO23SK34YqlbcEuGwrRtiQSeEj2oZtnQ0LuXy5lK3m0pjm
bwIO6DCbz1RLYP9uejdBNTt0sgNkCTz08q1G8StjbCaZOPPSqECKKfjPM9We
AqZewiawQdSABgk9pt1MpRGmbkVXVQXhEV5Fe3AAJ9UQX6W1OhZnkqauTYvN
jTQbBa1s+pN5bwGLSzUCSge0EvCgqmnuZoYlBbwVWdhVueyFv2W8BMuAGDaY
d2PQgRQc2MzocREDJAUBwsAwUALQ+CT6GxTuBLx4UbKRJdiO9oSAH5AuVUvV
bKHMDhBqnS5ujoIrFMyopvNnTNlxYUcMWHayn0PNBJ4AD57vozAjcP0nW6j3
OwcHm58nRKGe4RVGw7HMHZFO0ac6Hi7aku4I43/+wxL6aPRYU6LSjGR47Bho
ZrPTzxlLp+6HNTgmxggIDckCg1Boq5pzjAGWLr0GgAm7QO3OiI2huOyEGHA9
hlaa8q/moH9mcciNRvjKAc/cwZNl+jnbWKCswrfSAyzIA4LxX35SfjwvxUAI
GriAm0cwLfbmqoYXb+oVDT5gRZFpajjiyKljdmaMsas0m6efNGy0FhoN3iHg
TWOu6clsdN50FpMVikhRbS9ahPB0bZu7v3gw2aDHzMyvZEGQCJpFdvuP956e
I6fQBGRz4u+SY+wNLXeQIIiAxvCnOzeDE/9IO5Q7hR/D+1/xyxUBHuWpTuml
5dF6qxqAl23FT6bCP2RRGoi09wYVZIrlb/GO/oN40G6jYfNT9AAOPEadg1Yt
AcvIB0M2GQISS8+DdjNNbjLfLiC/L+AhhKaXhIPF0rBYFWQgwGApfDo6IitZ
c1FNHh2Fv8cQJn61ISZO4pClivP3V2JrMeM9lXS9fJJtPg+tZ7vSyZxP8uvG
PH8jzTMPpJUObNR8H6DDhEhJrbuqcntiOrXr17ahzHL5l7q8rA/ykp0MqThA
SZHKtxeZVtYeP9iLdd3RSrXJY+VZ7Lfb6jIZUnGAkiJVvDgrqVV7YerGdL7u
te975LlbHnf1h+tkSMUBSorU3fDx5fT2MT9uLaWT5XI9rlWb9nTeJk4mGVJx
gJIidXYylJd6u90aWWfD++Jdad0izv29oaqFZEjFAUqKVG/YeBys5Unm/LQs
j84l96Qmzu4mD7lnMxlScYCSIvV09nz2MH9cPhWNxp3+OrwvnJyXHtST1mNC
SsUBSopUwTbzF6v21dVDu59dGoupa5L7+wlptGfJkIoDlBSp69KZLhcri4yc
1Zp3efe585ipPQzN8WktGVJxgJIiZRS6pHjdayyW05XcOjOUe9Jbg78gmwl5
Kg5QUqRG5Ob18nKx7Krj2c34rDdeEfnUbM8HzYQSPQ5QAqTkMfy6LT62lWpW
e3xWXxoDp1p/Wt81L0/I7bz7bqTeBJRY9500zEK9e9Ps366NxWW1dn0mOb1n
40GaJNR9MYCSIrUcDR/tavdJqbpVs5urz8SKsyiPFw+nCZGKA5QUKXNRGYtl
+en8vHjzJHb1Z7nUmd716+JJQpEQBygpUjn31pWa2eZ68nzZ7BZOB0PRehwt
B+pZQqTiACVFal7PV6XRZfbaaheGtUF32CpXFqvewF0lRCoOUGLdtzpvrLpt
IvZr6k3VnV5daZp1XtBvawnVTBygpEgNsit3fltfvjy26v12Y/Aw6bcfnhzl
5bWSDKk4QEmRmt4sC6WT5US/U9Tq+OVJz42fz0eaMewkVDNxgJIidXtaXreG
M02/6a8u17n2Q2n86p6YRvP5/cLzTUCJV990TjqaQk7GrZJZfSldVO9mTiZT
a5wnpFQcoKRITeSc+pxZjEwy7Q/FRTYj9i9tbSU9NRKaw3GAEgvPq4JeG78U
22dPc6fZvLT6hlJ+bSoP2YSMHgcoKVIP7pk8XLfOeo1ux32UF7mrbvmhaU5u
GrfJkIoDlNieumtrxuik05qKcu+adN3m3dXLqvi4uE/oYsUBSorU6u423yi/
3F4ZE1mdl+uFp6ti9+x2UH1IqJDjACVFKjtpyL2lWL40582b19f6ay2vnHQm
Zv4moZEXBygpUk5FMkev9Xy5oN2rF6/WnXV181ienT6uE05fHKCkSOn523W9
9HBx/bqSXJk8t4ZmpWcUsm6/kwypOECJ5dRL+0Uejc4X0tA8bYnPreaTmyvk
J2MxoUKOA5TYxWpWruvZ+7sL0TEvzcXpdW4wKzV1nbQSqpk4QEmRWjxc5ubq
+Kl4+iA3squLZX980TBu5ZPbhJtmcYCSItU9PXlQjVGl+NCXLmYvz/XWVK8/
Nco9OSFPxQFKitSzXb3rFHr1yvpRn05yVyPpqZ6VcrnxRUKeigOUFKnMzevV
zevD8E7RHou318PufVdfPWmG9ZxQTsUBSorUfb7bztbBWRvp2fvb3ur0Wp1K
HTn7Okhoo8cBSmxPDaXTtaaftM0L/eWyXK/Lj3dmW7QuE3szMYCSIlXuP/bd
eiV/rlvVl8Yoe5c9qRaM6n0+n9BKiAOUmKf69+NJ7vGyVbtyzq7LT/Y4u9IK
V2LtKuGuSxygxApZH18uxdGycm4rZyOtYEsX1erJa0ElckKFHAMo8e7wWh2f
Vl57RWlpWqNhP3t5Uz1p3bYe7pPuDscASopU43G56JaLryVr0FFytfzT0+Lp
TG+vrtSE9lQcoARIuWMdfuaqq5Onh2KjYPZPZ/On2uJhMCw/Xtzn7t4/f29D
SkorN9tePd5X5bPx3VzNN8bVl0yJTJfzx9OE2i8OUFKk+qfDWiaTLUniedd4
qM1One7typw96c8JWT0OUOIjo2VZvLrPNWp3Vka8rr9Wy6TWXdWHRjehSo4D
lNhxN9YjWRovrnNNsTO9HQ/ucrnK/fXJ5TShjxwHKClSln53SU5Gz9IqV9Ly
WaM4V512Z3V1PUuoaOIAJUWqOZmeKaf5tT3qnZx3r0lFfn0VHbnTfUkoqeIA
JabU04Ukq0puabQc6WzZH6mdztjJDzInCXkqDlBSpIazVv2qeWkP7p8nkjIq
rgztuVJSFlM5oUUVBygpUi+9/EMj05Wsk5Navt8d1ef392fOqta4TMjocYCS
IjWbPV9P1cJ6cTZUa8tHq7fMytbJVNTFhDwVByixP1OfKefO+evAKZxUs3dz
a3zeMZSJPsglNF7iACVFqu26w9qJm83WB5ayOs93KlN9mXt+nlcSOu5xgJJv
mxmquZrVh8Prp85iemIUDem+9Nx5eE1oJ8QBSoqUem83GjWt8vgkzq8GtbKt
Xt6e2mNNbSekVBygpEiJ7dPe7U2xsXDv7uWr2iRflvurpVkb6AkZPQ5QUqQu
jIvHVnl0en2lN1Z3Dy8l21GvnPOlnE0op+IAJeap4ahzNr1S6oXn7CRjyK+r
3tPy5MFpmEm3YmMAJT5zWBde7q7Prk9vKjlxZM+uh7ennZJKtOxjwjOHGECJ
7amzvD18PDHG1c51pTxY5OTsS2GcL63OEzJ6HKDEgSX3593Hx+zjabaVU/vD
9vq6YDX1K7t5mjAuKA5QYivhPGs0+2RZG91dDJfkal6tzIzHJ3lSSsjocYAS
b3E8u6+Zcee54jw/mvKtrj49Pcj95fKknZBScYASOw6P6l3h/OnSymUsUrqe
nerr+35+3nNIQishDlDiEJzHyUrPqiOnNC8oF+XVSfbxUtEyD/15Qm8mDlBS
pEoX55OreS73eLM6HTyORFWsr9Tu6Wv3PuFeXhygxCLBbMvnPefhYly/fWw8
mZdZw7gqkeyJmJDR4wAljuHor0ftqjo1Lp8vy/1nZTp9HD44q2nXSTh9cYCS
IqUMTytW+aJ7+lwrFOs9snpa2mNdrzlnCSV6HKDEewniq1QpDR/PMvZ8WX+o
Lwd3169L9aphJdzLiwOUODKh0Okqi8aqovVb51ZDPes8j+b1xo1VSGjkxQFK
bE/VrqrrkzNzrN1ll83lUp4Wior+MtPXCW30OECJbfTMxUt7XJfsa10rVR/F
6pM2NJ7HdquScPXFAUosEqZXp9rjWh6uDUdfDDKgJFaaoi2lVcIjozhAia2E
0fKiKitaaaz2Mov66aTWv71t6lJvndDIiwOUONrFIcv2qHt6Xr++Om/m7Bdr
MrCMeeNqlnAvIQ5Q4v0pu/NcMsvLcWH6MHQbF8XsoDFYiMuTVUKREAcosUQv
yZVmqVdv3pDMqtCsvTx0806h1ZMLSSV6DKDEYV1WvZgvn02d3Kx1cdfoW4Ob
mQMSppw0UDcOUFKkbnrG+eP4ttEcdm+W+alRy2ReJ6VKYX2acPXFAUocw9Ft
DzP2xcVtsUtmZst4vT8/MzpnutRPuL0YBygpUqdnjVo+q09qZKpNTno37nDd
rmUz2nkv4eqLA5QUqepYzGXPuuclO9tTZHNU0ntmpmRdLvWELlYcoKRIVV5e
hqcng3w122mNTp+erm+dx+7V5UP1NuFeQhygxCE4r27uVmtoj93ZaWVy2b9q
aKvTs8nSuEo4fXGAEKkWuxL/OVk0wHh1P79xtMFLr6U9VBYPhUXFVS9LxUFC
KRoHKLFhNbvNPN8PV+3aSbZiPenO01mulpsPl+2E5kIcoMQhCk+68nh+rY2n
xBpNzWWnpT/dLHPtk2xC0R4HKLG1l3ku3c7t5rBBRi+9Xvdy1jxrPK/7L62E
zBUHKAFSluTYadtuWk83J/cFu9ToS4+kVu3o7Uyvd519/zJ8E1BSpK569c7w
XhFvzMHrqzItNjNnT+a9dnnaeb9h9SagpEgZY0uxsoNqT5mXmsPZc67l5B+e
ZuL06v2+1puAkiI16XYXTi/bebAfTsajzEPR6E5vBtLFhfl+JfgmoKRIraXT
04J9Ny7MG+OzTPuy17tZ5B8mGfk04fTFAUqKVFOqZZ+b15cn4ki5Kq5EZXY3
6r9qbbn5fsPqTUBJkZo7s/bTbfO1bz4azdJN8VUzSm25lZUXCZGKA5TYsMqK
ev3iPqsXBufqqX39cjW96sxGl6u7hBI9DlDi6Mp6W65XHm9uMu07ea1Op896
NvvwcjO9TxigEAcoKVKvj/mF0hsOns6fOsr5cDaXreX9tfs4TuoqxwFKHF0p
P5y6xtgcZK/OLRB/Jzf2ZH5pPyyMhB5EHKCkSJ30pxlnIJWn2UtZIndPrcuX
19JyUig2ErrKcYASX7R1TTu7Mova7EK1z8XqzenZ/cWZVDP0hB5EHKDE4Xl3
61F+Kr/cmGcnBedidna1snMNl1y6CTfU4wAl9iD05uWLeLLIi9VyrvRChg7J
GOPH866U0AGMA5QUqfOlc9qXLzqPi9vGfa6Waa9q/aJdfeh2E+6exQFKfPQw
v6i31OLQ6FrF7KRvTIrmSz/rDrSkOx1xgBLf1Mxp0tnIXZ9cX1ul66xx2xjN
z6Vh7zLpDag4QIljBsX8da0yVB6ytaKunK/Mu7WYfR1WbrSEhzRxgBJHTTx3
zPxZo/vcnmg3l1K/3768enk+nzRXCSV6HKDEe0Kt7HNe6okvC+l2MhCvK5Uz
snIaHU1O6M3EAUq8y28+t+aVfi574oxzpn3ROLs0byqr3mvSa1lxgBL7771S
b9U8m9ba1ZFBxrfP2rmcGVdL0iwho8cBShweZA2sh6562emtH1/vmgvtQTur
Z24XiTeq4gAl1n1Ku77IN9e368LJ3JqWs2o1syrN271GwpOjOEBJzeF2y3q4
uLrvDZr61Xnppnt3VTnLaK3Txvr9wvNNQEmRun6xnWZ2ZJ9bT9b4enh3fSs+
Vc+nj0aCo4c3ASX2kKcFrW4/FJeO8dI762bl3tXMyeq9q9r7t/TeBJQUKaVb
exLd2uipo92u1Oboaph5qt9NCy/VhHsJcYCSInVyo7zeXZ0Vr+p2oZtduyez
oeGsHrXs+v27Lm8CSorUi1VYlk9UozE7zb44ubLUaDyfnVtur/h+b+ZNQIlD
0/XxsOGMnH6z3XvNu932zQPRSG6xfLTeLz3fhsQzrHWxgt+1i7n+TMM+OOjQ
YoiWcyyMATItKyy8eK9Z9iea7sqSVJul57o/DWeIggY0vbXlYDolrKeHhb1o
9qR7rBMWXUWdF1D/xDIxCv8WW9ee1921k1VW563+eoBFvDG5F6aYVw2X1mEM
VtG0vSxotIgcpsWl9VCxBBzWT2/0ayKp907+/nf40e0Mblpiw4cULD6IJSKx
nqaK1aAlRVF5CThW3myl0oEDjY6O6KiPjvaM4tkF8o9VovxVuPXxoJU2YHQi
Zr7fqYM82lS2wjxcJqbgCn5jYc5zQdVpkSyHYPGqsUMsTH1mEFYqtwXf0qrN
NEnbAHr5LGBB7C9+3etwQrsQEwLvpFWF1zPn5aRATYlsehe2SCctU6A5HbGg
F81ZWRJzhymPT3jethEBxa9SXmLDAP5RJwat0G0z+lkRtcW94uLb1cU/0Tqg
ABvLxWPdBU4tnhyXKId/xdp2MFuMuY6OWA5flrqN9bfpX2C97FYwp5ns6Mxg
FUFXp6npWP3P7Q6xdi4W3fuhlC2kcqkCpW0bGNKvHIwVISkn8PxxdGUCzjAW
g7DCXiYtSrwwtQXlIWONEzCVLFr9WLaIc3T0V4r93/6GtTRvaqzeO3aDaVIF
SaAEpAWrQ4WrhQlhddUwGyuQCuZD6HU6TZYTrtHu9Ibw4688EaSrKpiUWxiA
pYyipOUNAauZIz1jxpESTkBY4gN4rZgCTI2XpE41DsJFCndLtx7Ds9btXZNX
bCgVKhX2EKuYw8rHRPG1Dhs1rX6swjqiWLEUfbQeNPYcGKeXRpTnRcQmXoo/
XmScWLFYC9tYU2RavHyG2F8DBN2OQkqGbscuFpWVpwRLCm6KXyejU2j4uQiS
5Fn3dZWW92Odm7RIvRBiIPsdIz3Y6tfLiitiQkfNDvTuv5mYUU+JuYh+rEc9
thx5z2NRkfa9cWQXR45JHW82OZZBEzpYJgGneZPr8YBmMAykYuZMMwdlheUQ
ack/mgbU0r0MjTvJEqOzI75Vl1foYkZMNZA1dYlFff3qgyYrLY5pG+cWpjzH
9LppWg2K5VhkKS1p9kw/32qD10yVuDlRA4he+Wiv7jeVj7TMKWKNys8zCPar
w0/STGJVFg+3yizW14Jh0rrxdqDKOggdQ8GMjptEkOEa8aNNFV54p9E0rkxo
sErrIOdYLlMPkJ+REqchrgi3bWouK9gqgDHFTCMXTDUsZWtiiaypyUtPaiaW
AGF1KrYyXvIslmh6YFlIWK20ULc3xRpHE0eK1Z88IDBQTLqq8qmjuTaxkCwz
gIhkY+HbERH8PKWj9UZe4vz5NS5TIGHBzANpS4BKi8AnrK2NJaphsuIHAd9A
D+HanMjKKOywHiYvywsshZh6qUG9otjHmxqxNI+s17MOckhXbVwYlkGHZ/Ni
Y7Y7crTIwqhCCyZfpqliwxwKyv6TmiKpY17Bck7z19JFJQHzeplBmQoMsJG3
Zo/hCU8sKoyAp3E8mqpzzS50eU1NsNxAVQt9WlPzGMxuS5V0WIIgvqSxdCwM
XFMH06TmWvDjTsW1b2vSQmi6I7KemcfCGSYbx2ZEOJNkMMnBRO+bxmRkCnX3
WGhMiTFZAXJtV0Jboy2ZSyAwfnEsnEtrSWhZsgo8cyw0QbWcu0AcIGMNrDtH
OP/nP/75X//5jxlAXGsLFNB1osFESlh/tLWQhAZIi5Rwr+JDmJYzNEgNodnq
91uXl62+0K91LgetSxyXbWOdb1WCRVm31MkUVQs8Bya2pCl4GrB01mC1NkxN
g4XPpriDha778tQy5dkh5XzCZysoGSWVicA3q7LO4S3LC0zrs9KK1z6rc7vL
KxC8X3bu1nRFw5Cu3KMjwGuOjDTC4uyqzVYBNzYjysjyvLhzVnjPy4tLB4WV
aoHiqBbx9xjo4teiB9EbbMX6QRkFBECrgnM9d2yo4PMqmO9U6/Vy/VJnzvsW
UUP5ZUlzFRMWc5nqjRNUL+FlybW1L1ACK3ST2thGXRU2nVLCAASzasC0vfp0
F7i1DLpGobXQaUdUCHjFx/1eI5WdB4fmKd6gihDAloDlsaDplxEMVjGWHIkx
hv/IprbRZjJZS94lfjUjtEb2piA6jtLVseSt95im+obeaf1RzxIFVsJ4IqCN
l7P4LpoTaptsw3cbgd5EvWQfDEzu9ti+/+wDOBZmhrnUsEoaWzi0cjKwJzXf
NuREMlDpw0sJxLFlIPVxQLtQJYnWVkdspsamjSnCaUb7YImBTJWZQMFvqC9C
l07wU/wO8WXfghp4ZR/SctHgR4NOsNFBVxfMGUUTkWfB1gmhSc+5LgCZhp6b
hcnGfY5BLgRfDefQAQpoILoFLMWCDz04dA7tN6R1o9EQAg680O+cMgHlGWwp
oeeVY2Ya9pOBBV5XUwlFIpAeVgLO2yGwFGgnhWL+t79hxerNAyzKzgYjcI/O
+8b7CV/QvNWUS6k6R9eJ6vzZ9qzFz1E2g+Q1LerLwawGRAszhALidOxa1OTh
S2zLeGIYYvEAtG7vebb2/chtcIuYb5wwOlbPqKXI8ArmNz6l/HLfAWr+/eDg
KzVOnHQb7aOv4OAYLoH/NoExPtmHwtfNmvwK34pghez9N7xnzpJQN4EXcF58
Y7bbEH7Hii6Gu4Jpd3W0YoLJ4VHUbTx1bS6neIlG+p90LpNGXHqWNHFhvTZe
sVSaBE+KwpUM2hubw68vXpH3eFC0HqI6YqZlOlesFNOHYOppuA92LOB4TTqa
unnyr4t1qZCJxvrLaa1w2hayBWeKK8yQLCA/W/nhvZCJVJhM6WYI6wNbiHPW
giLehybSHI3lr0KuApM5d8RcGHXWfRiuZ2hg1QFajiSQsD9dyBYz5UK+lBv2
8Dtu3g6xYPHElShfDukAhi1wfSk7DVHpDNtgAInAU8OGVxCPJvcH5hpu6Yah
agxPqLU+PO2cDJsEN5mGsE6GfD9AGQ4u+kO27RMvbA9DhO21BmLj6pJVGsh9
FrIlJDErviG0vOIbwoCWvkDjAHllwRb+hkTjiTgnTmqiYuEQFKgGdKY5rjFJ
I0BxTzUPCpDViDPY1u1X4eKf/xgRGWxNXs2DzpOYq9Kp+q5JKlSq5Wy1Ep6k
yCrgQ6wKTzazYu+bFXM8bNz1+8P/r7pn223kyO5dX9EYw8aMMU12N+8TDAxK
FC+SKFEkNbr4gWiyi90t9k19IUXtGnCMBLtZZOM1sAkCr7MBAiTYDbzxQxJj
Ae/CD/6UzM1P+YWcU9VNNm+SKGtsZwB7hs3mqapT517nnCoIuEHxOyc6kzsn
HjFEx690mE7bA9XiJVTbVsN7TxQ9AeYqEIcsJnQ/STzb1XsevfQDsdO0TeC6
GiAXESOmeTF/D4hJi1kpk+vM3WyAFxt0Zm02RrETdMCXuO44CYarRY3INYvt
Fl5bCi+bkaKeTgxtLxQRYPlPQ5jhW3jjEv6KDY1nKLyQSkYXFeFnRMYz3fUD
0N2IiBuwsP5gGIgDJ8zwkgwWv+wtevORzIcaMroOiX5JIlbnkdX53jwt8XMG
Fy8IwJnvU9aczntsB36Q6JLkONNpNQW+dFUV3vOfSpkMQzRedyqDOrVQqDdr
B22uFZhgr8yTGX0Imtb2eZvdDDUhqQrIfRuMusdc2aUx1J9yDJsEdcMUpb7t
gK3rjS3bAdN+ChtsJCBh3QJkJfpuUnIcW3Wlfru1G3hNW001T7qNw/fQNX+L
gpjekxW5CWi/z9yLJMevGyOKZvdCsrq3FUr80jUuaq1VcNldWA7efeZ6STN0
46OIO3XjUZXdhR1ThXw+JWQ7kaHRKYZ4QnEzI+5RdUwebJeqB1uzwr2E7s3E
Xjm23QHX8sHLMbmHpdZx69Eq3Yknch2PvplkV3pGtw9heI0aZO9XDLsLvFc0
0JkP71iqAJ5NEFfUTqqCNwW65CHVfCuHmuVjKQ3ej/qdhFkqky1kchkmqb4f
dTrPtIEnSCPSTVzZtpkI8Cq9XpKGtJNHRSuVFxWiy7xc3zfPK1WtfnFp93pi
tTcu5wbeniETskv6lwfpbmtLMquNq1HjsHFaIZJinTUTV32DnG6Zpg96w+7s
h+J25rKjYo1rML+0hfHk0ExC+UCFshjnmpnjo0gciiHbPNOJZcmPYUeAFKiN
J4ncTmCMp/uD7uxtz5wBLKINXFLiJW1FVTqXpnZ+eKI3O/LeqXLhPxuWdkg5
fVe2EQqZtCQWQL2z4EanWVmhkdlG4+3Eeq9TrDEctraL7TeDpLV0EcJdUD3w
kFFfdJNfeDKOagNkJzhk8J0gJBylf50OKXcz1StNNB1xG3RIWswX4toaBqHq
RCGmDf9wnDFXtYP4tWT6QJ9OmFgzc9YiRUT/hTBWYEeIYwfRM1VhsKpzEhe+
txvxrblrT3tDz+NzGV5fNGcQOzi377KoeX6bkNWbY7sFnN2Z754VNnfPdjql
yuCsoRjW+aZ8RMZGoHUvDn8gvqvafrO8dS94EgvzeLof1tNs3+33QltPzKy8
ohyslvA6vJk7sK837Mql6nFTP7/c9WxgypSUzyxjSkqFNyBmQq1eks56Qry3
xdb3zYn3tDvR6HSDlGWDzd1hf8OOVJoXY7dU21a3R7AjYiotsB2pbTcqP2o6
1YmjhlQqLEX6enhQ8xedQCwMT64GqC7SQjqkTDQkPc12ZhEQvy/Us+Se5vMK
iA68W1ghSaAo1QUbObzIW7Y8Hd5YdQurmMkgHwCySwwE1+rpNDy1jze4ztn+
N49OGBNEwECkZmELLBLbgjm18GYWRNF3EPjwdG4NNn3IKwrCnptrJj7XhanO
/JIy7sAnSXZrdZgWgZfCXneHMcjlWaEmMyHNy2D1slyRZDj5FapvqU/Gon0J
A2ONfcy/YedkSMur7lSnYGCshw4L0rCDuR3YBvA0MFRJY3iyxTw53evZj7mj
VhGxlOLBe5hFFOY6zV+seoM2E/MZcCHynRaemmDs7orFieZcr+XYmBzTbU1O
HReilPGV9ya/CH0hIPgtvGmX25fpccEUweUJ/maX07N6fbwsetaPSglc0XF1
4xoRcytcpAvpgtRpIi3h8pGW0HWaCxR1ite6Q4tuUMrXzjSvqfObZzt7fOXi
3BpVrrScbnUNP9itGc6z84u6cexkj5tKvX2WzZ7lHT5/ei7L5KDf1U4SW3Y1
e7oZDOTdQBbUgY+nwizBSzdxJqbDCcITKfdEEOhGgZPHNZhOwyyQEaYEILJZ
WJmiKsptXCJb5oPKMr6PDIPv85MwQx2D2eD0Pua2ZEtWZO7hkG0IfinmZnbk
bhsiialsVhQ6bUxrQksrfL2zbcFQtoUHMp12c7tz4BCr0wrASbxOwO+6BfvS
EfuKhTElUcin8G2XYHLuKgxEWTpgXy5ggQ81FM9ARCJjH/izNTaBGXU8JrXQ
5OPaGAryouPeSLrb/djdzPBaywZOmwv02B4/tOlcVNhzJwnWGTybYwAxO4/u
JaGdFZDohrIQzjIrJfYzJhuTfd0g7Ge8kKZ/C2kx22Hzf1sS3pby4ttSYYV7
dptpLInVi084MXPfsfrMerH6Xdk1PDfQSDxaL2b5eyF2lD4ZQaJxGvAiVgXB
EKN3k/NSLpW/CToNsc3rApCAQLQdtAPDnam062UW2n/CFS0LaTByAMMMkuMK
94CNBd+AtapQ2o+I/cF07qpv9mm8P+ExpvBQY1DyCE2O98DYUJ8SdloSXPEt
zA+B/wdDErjxGGeaB+TXZfe7aoFMKidm1tMCzE0uN+MGc+ZGgznDjug0Yl3B
f5i1hFeqz4jRwg0LusFyziyznMGj67soteIm0/W2ca2/q3YPcuk9Pw2iMytk
0kujSLdb8kM68o1Lz72RpdO40mJI/vrlayc5sBC3B/s5dJGyuWy4eox8mAuR
j3vZ+O9OyUIqnUuncqnVkYooJrFX3N3+vud/t90z0JRnWVfLj1Po6ckNu7lz
1d9zupZmCEUMQYhibkVo5l4QkXkjiJiJ0YQImSSHTVOI2afVntD1iDrwD+zc
vq3qHpJ9KiNGHnGEn7vFajJzsZpr0ZfmFzB4t7hNJha3uW9v8Q7RnVX7Ohfd
WWum1+9mVipm8hdVsVCv4ZGqlBMir24xzSumn3VfC7r0rB7e42eVXtwCFbgy
6V5D5zFAy48PQ/CRVe3hmWMXg71WDFVRAjHNH2bpw0xTh4q6Ao4AtUglkZ0P
/MUCQpBAKVK6LAVhJPs97b3hU125GHUFrWxo3juYt/a0sWf2B0c7vVQhqGtn
3n7FdC75ixIfbNmH47pq1Jx30I3Iit6bywIQr8kCKNyA8fXHuk0SgBgKHUqZ
U+vhpsMY9ah5mhWVZ3qDRhlBNT3irguxxAx421OIOT2K9rAQJDBIkq5tRWgF
BItChiAQTTzBfb980Cpt1+dcq3nAiN1NcDU9YniPMedbRQfup1xK5HZkixfn
0L3oYa2cKfOjK9VKebM+0VU+oHmZ4JiHEiaRUVTT6kNvGSQGJSllQedLzCmT
BLGTFYICEawVu0M/JuYHDJSsJGaWDJKQh2JiRLrmfQoOKYfY/cEFBzOSwCii
qBOl3ArpMSHohpD293Z6rct+/b3bi4t0Kn2vUjf1o0BeiDQxdRPSei1362x/
bOc66hpIo6Ga+8RaliuRHsVa5iaszQFKro2nTXaGTa1wdoaN2MqIkpi9CVuj
Tt09r5PquJFfA1uZwr0iS7o9ru6ZwmhUb1KMH2JNkG7CmpiVK2e8faYr69CY
VJCoPfSTJ5yv+wZ5+iBeyRClzZNpRcNMjcAaVQQPPthged3FMLt9ktU9yX6H
N1hJPvB2ILvjaSnDJMefFSqGVSE/iqIFWnDGClmxSiMqWaWF+XOVSbYbFq+x
xH+btU/gZKwBtrD2EGhVi2deLuAZfyc7DlYkYW2o42LZ/kx5Dw5CS9jkPpkU
Nukuti5wvSd0B97i5kI6CTw0ZF+9xay5FW7Now2O47n3afTjOMZTt+nhkyKH
l+Xzw/LOXo/IJGukO/vqiWV6pdMILLUgbw+WttzIqt2LS+HkNH986lZT9cv0
8CBvSXywq07AtvfWgYo2Rd4YX1S1wjjX2Rtmu6J+ojlHF6euI9SFCCgNHdwe
KvrvybY99I3cSB1ejXaO21JNOhtZml07sE4PJ5gtFm+PVllWk+ebZ88GudNx
a+TI5YuxUuxfHqdSg/2zxmT9DTTWWNHjTAUmyojbjuVEMPiZKs6kks0cN+Qt
4bh71hxdtjd7htUe9HMtk94jjsPTPBCJuo6sKuZ9X3OJrIi3HVqeAkgG3atc
cLLl8fzpVdA6Hp/s73vmcb/jtw4xZRGYI4Qu3QX6ZVU7LxbS/SuiZA/2a8NG
Ux212/xx0yxGuCy16ltrIU4xvV7ycEuSlVrvdHCptw1L3+71cqo6yGc3i5NN
WhJQuB7wNJTQqLk70kHn8KK3f1S06jWr80yTpJp5XO9F0OO5QfefTzSVHM0F
yeHOSI6jcr1ZebI2CbA2NmfHu0JQrxekA2VkNLrqyebwsOiUHJK56+aHcJta
M2eLVff4sl8p9dXmTr2ZzTQ3B6XtcNo0wL3upDHWnNzvXlZro0K1c+m0Trtq
/6Bj5YxntTI59u44Zwr2KHNaVQqicXquX2y1/cLm2fhZab9Mjpz6hFJr+81b
ixIw1JKd/N52qhmIlydiVlMrOyN3XG83R01bLsa2GIyaVWfcoQdKT6kZ68+a
YMv2HVnJS6yEoyZjijhJ08qTopiThJyYSq3C31owTfTpVZJMgX9CJ90ubt1p
ouAPTCdYSEli4e4TjMGSBCGbz2eE6Q4cbDVmeQwr/xkAEmM1eG1y7AQLCtcZ
W5Hdc3jZMBL0MNJjA8OP+OhHM6vJiVl0o0Mo0tpQaPSuMz1DQoODLa4gZOKg
U/cGOp1P5TFwS/cghJ6+N+gZKZ1NZcJd4ZZWF2HDL5SITOqtKZMOdxVHyDXS
R6QdeFpxS7wokM1N3xHChpWTkNv/t9oXnPyK5CLsyWCDpxiY3EOQM4++m5iQ
xHQhm0rn6IhhNiomzU8zbLiHxWKt/GiaivBOdMo+P7Is63020EidHqKFJ+jh
gPEaRxw9I6RTUoqOHufFNSgwkk2giRkccKVpF59YUsHYdORpUQ79iLSEZ8i0
4VKYrlBA2hLwD20IBXRb63PgOdJK8libE6yAH8pgqiGR4p5Qk422wAJXLGys
wnwwVvQfUgUrdKc+xmPOYbXRBsGGaXQE2npjK14EujHzKfIfWS0ydn4YEdxi
QoOYt/a4588IkFnXcNiX/fwRbS5ggQLTCWeBf1cige/1NM5zXNKjhzeDb760
LMLewORATiWuRbA7ALfN1wEG4JfDFL9trNEPfKzCRrMKO0mAY6bJXfiurvuq
oRMFq5QUAFTTEGSX6Bx2TfrmM2p0+1cBbElNw5Zjm0SH2aoepxGjD6+Gs4Dp
vvi3j17+9rOXH/3uxcf//vxPn77+4r+e//EPL//hZ//7p7/99p9+++KPf3z5
+b+8/vrv4IVvP/z09dc/e/Xr/37xh199+9F/PP/qy9d/+etX//nVq88/f/Gb
3zz/8y+f//mz1x/+9f98+NHLn3/y/KvPX372Ny9//qsXn/zji4+/eP7Vv774
5ccvfvH7V19/9fqLTwDaq0//6uUv/v7V776G93G/a8X94kKflfZMCyBN9rBt
D32TtZ3ALi0bWJLdBUGGUIq9qNkBDQFv/OSJRYuZifL0QR9EF3nwwcbsO6zh
GJb0WwTbY8gutrvBnjRzfTxqPn2qRx0E4yGFPkszw14XIMpxMlSRYPONgJ5L
ILH3A4O2VzJp642whH2hew0LArisV4jCGp85uM/UU49aESUi3IR9iWi7O481
rYiiMNjMwGOt7tgBOAYMojg1B34u9jWI9RriPGShMDMFyBWRgzVf8ZJ+2mDg
ycbGu+8uVWLvvot9z5Z988EHtO3GSPe0sMeES0MYwCNhNwAaoyA9nQnbkMWn
nU3CSIUeBUVob8gW8OWY20WCkbkD3ZLhWcmVvYEd/jXUe/CoLrsDkC3NQBnD
p3hjG/i4A/y2K+ORAXxoEJXbwYZI2IOMuMAzsI1lbCEID5qkSwayxh0AfhXb
7cOjtt3VgSobgWF4iJVloRKKlGVfhDhRYfZhdzV5QppkyfJ1YA5V85GOppTF
ojzA1g4+j7od2dbKMSnitl1Qb03MInINRNpOoNmwTtf75vfWAsLm+g4hatwA
W/UYsgVCzceN8IHouF2XmMRFtJzLKMKqsMXs99j5p63Zpmcj+NPAwjXt6DLF
a0MeEoPb1we2ZQNrwJMt0AhjbB3E3i9atjU2seVmvF46akjlhmP0bHhRB7nn
69zDmRc9jTigrxRUiyXZAuqog1EFzBXSR9O21EEg44QpDRDsFbInBwpbmYMN
RKq2YVKyKIIqcGWuEhj4wQekN1x5IHsaXQl8bI2HtNVLSFshidQDomGuMi54
x9Ys+BUJvvlnmLjve+ztTdDjQMdV2cBpHBPap6oFSqCL84jaNmGfxGmfJm7x
D+JvprHTZH/2AptiU3HJCFFg0M1a3tYJvoh3WKIzcDQdszI1UycqReVwrHAH
A1mndAB4RehoA8jApse2rZiUwyrffOkiJAL0ojD6ADHVkn2bomgQdBmJYecJ
3x55A31KNGXsSgPEyrALNgCI1lKgqhRwi7iarlPKMWR4J8BplkgX9IhtkDFl
SGoBYpM5Vwf5ynixxLNPkVCidgq2TGNiB1uSoGDq2XwsZkzF8OyvY0JpKBsB
jSfPNK+gvLbIPrG+XRuTpij3KQYiLUTHr9lW4MN2a2AHE8rsC13BcE4anVOZ
RbeXiIgqtsX0uDaYMzaYEDpSwKnsoreukX6f7ivwDOsXsgf6sAsshoRc0V1d
0UC/1GGKY9mk9AkYBEMYjUjYVZ8xi23JtEFd1R4jpSBjwqaCtcVtyi7K5A3s
odUHzUW3kf0z3MNlLWUWlAc3rTdgzX1Q9Zq2Qmi/QaZLJQH/jVFgMZEKM5F1
1o44NubEyKXnDbRVmOzNDRF1g4taGU46Gu8CaWtAbWNY6yasT5WHsrVMqu6D
jDK5XRsMO9hkXH6FoIcEKmVjoxWqeWqKe1EFNnp6jzl0JB9jYyJ2GMES2ln/
wIg8WQ0F6wJGURQZLugJUFDUfkhwRW55t6IpKNrqzgPLGzbgB6hWessBt+ep
mEPje2nnPJxcH7te0SWznORJl80ZD+9BaK8TqgtBoFiqp4JO08OCn8SDRxv/
B/5FM/6YoAEA

-->

</rfc>
