<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-26" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-26"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="08"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 208?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>, <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how <strong>intra</strong>-handshake (aka early) attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader intra-handshake (aka early) attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 212?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published CVEs/GHSAs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">4</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">8 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">3</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="mitigated-implementations">
        <name>Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 850?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA829yXLrSLIouNdXwDLtvnukEjiPpzo7kyIpkpKoidR47BkP
CARJiBgoDBxUmdfepnf9A23dbb1s6x/o1d3Vpr/jfkm7ewAgwAESTp2TVfXe
zUyBgIeHh4eHu4cPoigeOKqjsc/CTx3DsSRxIhmKPZGmTPgkTSWhKVna6lCo
OQ6zHclRTUOom4atKsxiitCWLH3kasKn+n1TzGVyJTGfL1XLgjkS6ve9nlBO
FQWAJ9hszixJE0xnwiz4qWnjK+5McEyBLWdMdgAYfZHNpDLwg2zqqjE+/OlA
Gg4tNt+BXTxGPx3IksPGprX6LKjGyDw4UEzZkHSYp2JJI0dUo+DEkaRqYq50
YLtDXbVtgOqsZvB2p9k/FYSfBUmzTcBCNRQ2Y/APw/npWPiJKapjWqqk4R+d
2gn8y7Tgv277pz8dGK4+ZNbnAwUw+XwgA47MsF37szACYOwAJpU/AMAWkz4L
tdtm7WBhWtOxZbqzz0KvWesfTNkKHimfDwRRqHUEaQyj2vjHJi2kNS3w5+hi
HMyZ4QICPwuCB/yhhX/w+T3AmEBpoYU/4WMdCIGv/MaWkj7TWAqWAp9Lljz5
LEwcZ2Z/TqdDP6YBHIBWnYk7BArp7kTSdUkRXVvSJdGWLEWy0rvI/RN8pkmI
OXzmA975eYpDT6nmTkDp/Uuamjg6DHQguc7EtJCSMKggAIdonBt+6noDCnc4
oNCjAX+it0xrLBnqG9H1s9C/ExoWs2Hpj4UWs3TJWNFbjFMsmPiAME9xzH9z
XFHhX6UU9tOO8e9VSZ4wW5PmQsMdstXU3DV43bTYA5PmLDIkfiX9pvDPcC12
DdAzjfHQFE7cXXB7QK7xRFKFlisZQs0A1hqZMDfaVn0mTwxTM8crGD91LFw4
CvyzPlENKYLGUHOZYo4NGPO3MT7bh0p9wozxUjWENow23oVPZ72/IkNIroUc
br0/RlsyF8wQcNY/bMITILuRzWWKmWKhEI/OubQCIWrJKoy7E5+F6siTCPQp
fJJi/JPfbPo9JU92AW+mhHpK6KaEB1XTmG6/Q9Fj4ZKhANZwi0SGZHNJTump
BQfz28wyHdNI6TsZtiuBeNRVTZUM4CpLHQN5FHXX0NftjnjVbbZqkbFmE9XU
2VhKWa7hqDqLp19XncLJMRFuXNjeK4OJdVPTVGPnVNuSPalrpjSFSct07vQc
czRimnAhDW18CIspGZISXU2dD/HbBD6X8fN9uHRgzws9eWKZ8nTX+M1u56JT
E66RerKpHeOIqchQDpP03xgRb+a9lZKAdgcG58E5yGlhU7ynUJB9Jjh7jmp6
Y/MQPgSCwOKIdPaqzgqPBTgLvYMTjsr+RY/Pgg4o4cw1mICfH/OhJGvMnLXE
XywWKdiDDM+BMXyQMpiTnrlDTZVp+ulCppLLVrOV3GADO0RuEMVtEMEMfxyo
xsDHbACYEQ6B1Kb/iYA9nJ7A7ncpT05Hf7lP+SI0+vxMhG/OJPnVZc4e8ooW
m5l/Bo21VQyNvWMOD9UPHaOE0w+kVHSyHvToULQHPuOb/IFHvbpZN3ueXsLJ
IKi2MHc1A7baUGOo+FlMk1b4jiRP4TdVAlUQpke6IJtNmE4qI34KipDtgd/B
lfKcpQCJNOBwy2RQmH5VlV82dCBhvQa5ktBFJqZ1gB+ad/cN/mq2VKhU4mbZ
vOz0av+UeTJ3rqSYodpwMriWOcN/penv9Ab+cVNttXs1EKCyaYu1TpTbv/9E
wnyfy0cRiWV9VwOgc9XUmGPZaRnRTdtMdnGDpSVlrtqgcjM7TbOZj8ZjUZ8v
l6I+Hpf374W7NVCBKAAa9SZFcpsk4a8J6k5126cS6sE6nK5chdgims3ImhDB
qhjiQQm6tk9BUDxQGMH51G88CihBRiqYRzPJmYSJly0JNXfs2s73p15htsyL
i5fcUlwuC/8g9fLfgXoyHLCSLLOZIzTnYNEZMhNAAZoIhgrHKdNnzoosLLAO
HQSBUttyGpIjodQF3UaodRtgPN2LvcvrP5WQVgnYcFaoiC85a/FthGwqY6YB
t4i9FdBHt6P0vGW66URMPeQ1sCeRWuquHRqeeoJ5Mw8Ne4WzxsWznf0Tn7yM
ZfFFLs7F0aI82T9xf3KCN7l9k97Ygy2GWwmXemaCpgHDCopp/LsjKMxhsgNm
uQY8BJYxUGJow1cuUubPmbqeex2LC2s5FyeVaiXR1NG8F305AdqgsxI5K2+u
OS5nzRMXqrFl+IedIChN6qYxwm3jqCCIa+gvUGXcg97Ikc2QhYPeiFFGUGVF
mQ1KaUplzojOWHyQ1u0xUEVy0ss8u1mevtycnl3ITGIlrTC4HD8aut14Sn9Y
LSFaXlvqXAKyixaslbbB+v6Pwm1NRKEhT2DZwZJkgm4qTFBURTBMR0DxGtkf
zBchsDNQNuC3njgOUyIv9GALMXTWfIhLfHTSHNf9DPJSep2LhTzsDatQze0n
iA9wixhjcw8hWiYu9/TzvxpFxuZ+apRfRguxmLd0cTaZfAs1mDmPkgNmoklz
JsLxM1ctx5W0HQSRmeXAuYruQFtYMItxypgukOYHUWEbr/1UmRVHM3FcLYzh
H3r1m6ii76WKrhrqvxxJEKmYg7T6qoNa8gJqSU4ufQM9LEeO0gMEJuxSUdZU
dJ/uIEegeHHNA86aV9dE0vxwqkRR20+U4qsli/NKuSDqy/ny24giKtIeYbLb
m/xB9bYBx4OFBPGPqTBhSj+aMDNUXYsLELOjSTFGf40ljCO7P4Iy/at6/+ru
n0KW8bjyKuqjyQTUE0v+EFk6DbFuqbYKTxtXnVQ2k8pmC8V0vlyu5jKVVL5c
KeYr5fCLu1wmpHqgG4TeQI0lopHUTX0GCpoBpvQpOrxARzEkbYWvmqO9TpNL
cx7Qqviu46Rer4shtShN3l1NtGdMFlVFlAmzb/GZwC9dE058aSRFf+inQMe0
8KHFRoB7iIKZarp3ncplsuUULTP8Kt7WokQDXpBQxRWGrgN8MyYXLd5aOWwM
z9FgtHbo/gay2G7v0h4ioa/EtZmhLkmVAwV3BLIftIG05Mi5YnqG7j2PndML
phoTU1P2U6ouWbBahvAQfvMDdOyYhvv//e9CVwUBDFpj9McnmL89ERrwjxls
Oxb9tS0ZBsjlvi1PzBFMZLzxsWQBZXoTNoKJbazRxNQlG7jOtmF+G6iqcBaA
EX5rqs4bgD44UP07Ac8fKzZSI/6liHqvyPBSVAwtx8feEjOFzRdxO0feKL37
RvW9N7IZ/w0QDm8cl5Ekw9l3kEqlDg5EURQkMJbQc3Nw0Idzje7PBEnVbRRc
M8tENVFw8DYEtAQNjS0wBmiTfok61v77p4SeuMNj4cuGx2oN4+NeLgATvldu
qU7bHYJY5QJRqAUCUfiEEtE+FBYTWOZgbmQtSlwqrecZqMcw0Ym5EI6OyHlx
dLR5K874rXh4Q46IQiDxZkhXVWbHAA62xxH6L0zY2rMJCDocBdUM2z5CcWKB
TsusY8FWcVQ0OVXDBSGzaeaPyQzWYHtb7NVVLaYc70Qu/JmkKDa85MKWwfEk
awUD4Jm1BAodwfC48rDlXc2x8RZaGMI5BdJ3uCJdx/f1C3/72y5P+B9/HMMv
XJ798QctBn4loWaJvLbnMzo04H2gE+IJCuFIhO9E+E7gkhpAeUeCY+IdyrVl
3qOCdiyAIgaHQG2G96ViLpURNKCyYTOyfAGuZSqurHJzmhCyYD3ZgnPKBLRP
YcgY+pemhrnQ0NYPTVZjc2AHRGrKUJqBUpMS6q4FAtLRVsf4lsWITEdHzsIM
Yhj8MIdjwTQYKRf4tJrKiBjJAN/Bu8SBwcvVVDb6sgeickzsbGy8Xk4V+Ay2
Piml8gJdwNgTmIk0lkCaOTSdoWVKSKtN19s+3pWRC8kzqWmCJq1g8jgKgoJt
bJPzwIvWoEWezfxbnxAfcW6ZSTP6mrxxNqeY7JNRYCoFgPCVXIdaoEtvyBAB
OIPgNITp4JquX+CDrJmLIwfgveHw4hIgCDBN/JhchogpMLzuGsgP38g8KdAB
BdO1Aq489vhFB2ojwlEtkDAjAkfoCwJ30wmEihH5l2iwLgjYfydvKbzKgYe0
SU9m66qiaOzg4GfSSxFfCvjYtz8F7zyHze3LD1w5YA1YJlhJmtEbo/l8lFHg
65lpSxqQwWJjONxpSjDnxYTUFgS2ojXHJfBcsrZszkikotcL7S7LgTeB7GBf
pYRTy9QBQ1+XFXA9MSAIzl6+TTxGnAJghcmqzYWt7Jiw7iglcJkBcVUhHcpz
sesg0yU4OHTQQUx9x3M7jOVuDGnT4az4u4RtlA3xsTRHPxnq/AAoXugl4cFj
vFuBH8MsOXItIrK/2YAvaiCOuFQnHrRAsPM9gaj4mnqYF2i1fTVdDtR0+F2k
MXZ762n1+ew3pTT8/00SRCyEhPMmJCJTx1kaPHAsMlNvnrAx1vJlS7DAr/AS
4ozbALVY0x1Ptibh8ZjCbHUM+33G97JqxJIDduLPwhVIThQUBx/Yh86afMji
3AVDRzW66TZwieFpfnPkP47HkgtSUHVAD1e8SAV6FrFl/WAEUBEPfgeDKyX8
LpxsDgvP7myGLAL/VQs2we/wRRY/qJNZ+l//43+zCaZhok7zO2jZvwtfEFlm
Zdeq3jdddacdizF0TBtpD+AhDZ/bGD48/x1o5L43GjmORh7RoIBJDGo0SYhE
Bs5/74HzfOACDtwDRmQWzZ+HZZDIjIxf+N7jF/j4RaK/qcNDTnTg4Z9zxNY/
56MoFL83CkWOQikGhQIOv/cA3onQphdBZwwtcTs91MwhHx7sQ4ahn3a6K1lT
1751lVXKvzUCgwwdNbIctsxSM2V0+Fcwofyr0XkmVUnlojaUbdii6uDVQmlM
qCxmIkIF3k67Mw0UOzuNNn46m0s/MJyuJdbwmgbvwwBFsY/fivWry9NOo3nZ
79QuSi1vZBi6Xo9cGvU6rY/M/xCUE0kxyTkKsuIFr96+xEidnTA3qJH2JRAZ
sDNTRtKsFSF3ptC9H0rKNThJTenwCsEjODIcMjYoaDJLz9CbBSYFIIgGD9Ii
MO3EBRKITozDNTOWvjczljgzlncy4zFshuM1R8J5EesIgJMjQLT8vREtI6J/
+8ydUL/8tCXrQcHb1GwRcd8YW+tAP/1xcPAf//EfBw8ssK0l/5CDBzBx+P9g
mPjqHfyFRgaZEUMwO9bn3MGOc46+3X+2ubjICOtgy5hE4zGErqF4uiuip6uO
Ol6fhPi9otpkBCHD+aiG72dVBubglYtHKWxzNA4Y7Hz4VHIE1RF0aXVAtwVA
BVhQ/zoeFB4V3oSPLBOtq7XdJMKkRnD+C5/A8GSakD8Mps8nFTdtSQO9GLUx
0BYwYgJGhfNGM4HDlQOuU4XCAI5ROUdF1fCewKmkA0hUiLgn2Q+5kNYXhAcj
rpYr6oichDhFmAwO2+NGoPcpjO9N3HYtFhAEJJYBQsI+ACqooCSgZsWJi4dU
iljmAJkGdu8Mo/eHcGjiImgmqhg4QOR6/D0tB11adGHD9ZO//S0SmoIOB9t2
4Td4zzNiwdJWwIQ49hxD3BHCv4bPo04r+D5k6nPFr2sqTMOVuiLV1N9B3YB5
uWstaiy8urBGwgh9MMgiuFa6qUQVQZwUQoIR19SPm/uOfTNcCTbu3xUaM8YY
f0WugiG/goxwpK8C+pxBkpKTgOhR91gBo2ZpkQRPjiLnn5JHRPgijcdo9zns
+8mjAOQh+b/QiUESwjNPlfDeVXbNda/ZBatG8VcanlYYrYbeAH+OruH9lfIW
cMSdPj4SZHr6WvoOs5J4gMI4SOELH5Zhn2pUyO92CxN30ubjZg8/L3BNUKJK
uDNCN0ufEHu0W2GAhXG4c5xtjzCMEThFYKaauSDJuTAF8jUQl4BE8Ha9L7/X
pjjYBaDjn9DZIUxgq5ErzTujD0D/vjZB6djNnzOUx8E3kqJ47h0wOaVNqnmm
nMBPKW9tP0JBxfQubGcomwFCNFhRsj0PnopvgdHseYpA2FvMAaPZ2wV8XPL6
AKIq4e8JjC3Ddz/foSePhd2jZHBZY1cnO3AxWQmR8QmrwEtLLvgdkwCee4/K
cA7t/vaY3y5NGJ/m0ZE/O5hR2Cv83okLiLrGCyiYeGOu8F3QXMKJiUwi9FzY
/hYd8p7rVOjBhy7Iwp4fIQ0QhhJuZYD25bLT68OmcixVttcixZgrKdhkTmps
ztPI+qL3Slqe2/ZhCm1UEsZo9HhgwWqldCsc+zpwiqKXNs39qaCXiaIY/B+A
8J20qKsBDPLNgykr8N+y0cc5T7GrwH9jyHfwJqa4BY/8twrrR2XPPEE7qMsU
1dW9T9fa1058kWU+6JZDHezo6BQ+QLvbYt613rHQhncdEBroEoUd4B9gR0e4
cDA7TF+zEZGfgQ9Fmf8t/IH0RSTwHkcISH1KW2MXIbdPW59SO5OrjoXtnCeu
F58xyRDBmlKZH4QucPhbx7FP9+81wMb10g8YYWe0ozdOYd84wg7y5ugjzqC7
P6Iz3M/62gUi/+0gtuI1PVDBVuLGsIDW8F+FULoknGKglaxhktv7vTlvhAW+
R65vXZZQwN0PH4KZ8z9hDP2Hj2E58p8xhqhISTbJZmAPfesJ3z3fruUwCd40
3ewlkL7cNe8JR1AKPpGLGV/CTDFKJ6QzxLQUfjx5d3aggKHg/hnsOAu0Gm5Q
kBLk8AcYyqnheYnGHWhp3DjpMTkFM8oipL16L9fi4cWC99r6KgBE/wlbmahU
ozLBb4ZoHhqDCY7pHuQr+lKa519RG/Yzq2P1HbrnAYMCtCaMB6PLZmnmG2+o
lsBio8cfFUz8CPM5BcWlW0f0U4bwANIzvOCarbhLATVieA10TE1yUAsLq36U
akLzxexpdI+Rt8wCHdfzbdMLQ6ahBQ6qFRiZYF6BRQDPw7NXTNSEMTsbx+fp
zceUyxXKKMBp3teb57gqQBXQeegKGX8aqZa+QBuPpgi28kx0DRVY29PxOJKS
0K+fCF7IHNmeGtvIjp95s1x/ZwWWCJpDcI73bi9bPu5M+Sui4Dsej9drh+Mh
AT4164eNdlPw/GPCXNJcxsE6qxnyphbQn8/HNkcOzYVx1Y78ETbFhNClaiik
67679sIIY4DrCFc9XELZWs0cc2xJM7CvRU0dWsgUFiAF5MHwCzo/wLTkl1q6
aQG5fTp/vW1eX932B41av/aV5zmg72R9Yc9H4hdWsmnNTI47RUURL6pj3C9h
RuEB9oIfjsHvmzHKygKN2dleyL8S8zNYQR4BAGRTlXVaCqWquKhROxRJC0vr
W4lE4GAgjoNPojBnM0MiNS3EhWRzw7ZglObClrIG1J1zrxKzw7YhzJr7ThR+
b87XFpiaX9N9vWief+KccPg1vBdtQEpTuDUEbMaosgGghVaAZNtoPiiq7JCt
ya/nGJF2Y5PKkmtzmilshIkZoOt7czsWZHRQKfQ57UMRQ0uExu1Ji0d9HONH
3LBc8xq87ZOeJg/GFsDFYJioFPAjkIpiKQf/L+o9l3SFZ3IYad8vbKf5BaMj
BvGSQxewctD5oCuiPRTLmWKRKgUc+k5Mco6ZBm5ABpgYLvpwYFkskcIjQIS5
miehPwvSaMQrWKCoeAYTq+j7TkxyKCC9AZBroQ/LdkcevbRgO3g7kksOZpH/
4etto9dsNr4K/PKSSwpidgsG01bE4hJ5oGyXIoo8j2BgCSPn00lDFh7ARgHs
cQ9gKvauRWJ/tAFJpFBm1Qgv432/R+Ci3w545RalwnTYJI5FoeTc+acwSRP5
xAy8bwGmcnXvRhU3DeXRojxe+D4OunrkcSd/XfODrzlS0g9McYKi7wqe9XoX
/24LX0URdxiNBCvLlF8sRZ65X4VPX7yXhHyqCCpp57LXr11cpHRlp9PKhJdt
Wwv+TRc83h8iQUivIRwe+v5CnAnsgPUyAe3gv29rl/DfJKOvkaKIGKzazAXB
rGqwmYlUQOLATYyuLWns2/DOhHPBBLQTLoE9eUErBUzIKETPP+v8Ay60M7lN
fmEuxAvyLHel2cxzJyK5udruKRsHp+oYvba5WGUitCX6zaYojQ1QHIA5/JUT
yYV94IcUUqQAGqOSAGvMfxR4INaG94lkjC7NbO86wAtJRG4F+UE35ibFB/hx
qSAu1vmSKPzDZ/PGfQV5CWB+KZgd4z/wqE9QBddAPvi/3yMjfewTGF7c8T9h
9+O4/33TJzD80dG1H3PY5d77oyOABfMW6UDQfHIGKse+2XszDz5DasR+xIev
1wOdDUb2YNWv74T2g/AXoj/woQvw/rIR2zxCVcZySeSGP+FiK42L8IkrEIdr
xesvwm0Xfmve+3cVoG9wPG5ckw5gyojjmCAZhJtmzHLDQEKaNIIwbp/uu6Eh
d886qh/5Mw9BpytaoUEap/Cp3zh8l5mEa3TvYYQS4LOpgMV/SjhdMgdlBh6/
8tSngA8zUNv+QvLE19U8lQ/otB+d+E8RWf7GBjrtXjfdv46Q5ncevcs2NutO
Ynz8VRqNNOLa+dfQcL9HbsFRgsJkkCM8TmnyfKWNcVH1T9+DZkWHr2+6vEt8
XyOPjP/gifA0OomJWusU+p1Qv+WT9fAX/fD4v8MBQdfjsH3xS4yBe4ek3/JJ
yLbeOIZ8YS94waXc1t0W9yBBNuQ62sx9Lx7QD8FApXZh+D78ADYHyk0/m9t+
wX1aBOgB3bvRpvTMQD/WLXpWRZTDsPodPei4g9o/xdLhpflduHUNO63B3Gx+
L/vrTr4R+qvZlnjZ/eZtoGrRSFzp3Xv8fPQw+fiZs+9NQgGFQrOO1mcU6Q4X
EEZYLG3N7DLm18iLV720L3k8vYuz3+9rY3j3+PGS9HehRcIrUEm/CYXauf9O
5Bhaf3rqnSZ+kmQ6OFlxPScq7G9LnuAVR+AACRR0f5Au6OHWSgQIaHb7Mu13
IXQC+8O1PdUyHZxiYN9IGAy/OafgS5hO+rxxKqzJGrHP11/ULeb7EDjpej7p
fheoSoNvIsf8D+MPw47jQAX2Uh9I1oRFy0Ww+TZS8nBX7/byoBC5BmMOllzf
STm856JABDKN8ZdNXvl3TEfvwlY/+FloUH4MvH4fiVlo8HgGlJF9VcdoAcaj
aHh4Xm2diMDvBYFqNd+UvOfhCShJmnSdRwRk4dsX+AkjUlRDJZTWkRTMj6Sg
iAzTC3UACJmycCWDJYLWM+fNKAqIQfBytgDzkkMvhyuleW6WL1gecW1WxZcM
gCWw06Xx8HWZeXyqPDxZ7Xx3WZhfVYyc6J6Pn9IYmcXLEtCoJRr1i0ctjDNx
DZnwDNn8bJjyR8TB4G+MjitlcrlytgRmfSEdSX9bl99IWRTMN047jPEINHSh
yCvAIkyFXFk4ZcMQPkHw3jr1Yvv+S/hydBRcTf4itDutNpaO4nkeh0dH/x0h
ezVxwrDvm7suu9YjxcEt+nBLW3CpblEIDN527bz0+kb4X9Z8FF2emKoJmHIj
2cxOO9KYh+6h254iIrO0BEEWLsUK0Ee7iPMBjKuUGfmt+I7N/bgWU1lxbGZT
uRIMtoX02PxGhLOZLYzrW5rQt8VYYg6FRqEHX2KKO30oJnYTdnrmalq6WKFt
XN6cwf16tB2TIe/sN87I2/8K8mYuZthEkTIUXYMrynNfbbQ6YMduQN8KKt4S
CjtufGMYoODvsS2WfV/s5Lb3b/220+/Uaxce/CrsLI/B/EpIiUbI/4MjJKdW
botcWwPyi2efboXtUYMtuTXa9u3yB5YmVOwh2SB0t/wjB+A3yz92BP0Hj8Bv
lf/xEQKZsJ2MB1aid5qgLqabc67mzfaHVv0uFP6R0cbm9xsplnL8rvwDxCv9
I4PwW/XoKN1mo3PX9cYppfIx46z19kBrjkb6hnXXsNYsbajLPOrp0kspRW2U
B04ZPKSblCmMOpSM1fouYQVGN6ihJqLuJamG77gjN+8UMPn1gUlTLCz79Zj/
d6P9la6nvp5ISpOfYF9TR0foLwBjzdSUiO1C7g7TxpvkFEsdezB7FA9OUGlq
3gMAzWeqacA0puJ7Vmw/T1HiFbwpeqt555WjPGhiqjyTDOHOAB4Cu+QL/fBO
Wv3E1NkMzL5DIlI0UCfMANtKIs0hKO9OYe7BysBsQ4VQ/Pw9DDbD60VLtYHm
9D0Pur2PhtjvLxgiXKgO2nDAFet4tTkcFLZsYiTBH98/wjBqy3HlPAiG++KP
9mGYm3FzngX3ZQEmrSPN6LIlZNeEnoKhDmdi8AhTebiRjBh9+kIu/OgtKF4W
aVx78jKH4GnaxTJMQdEYUWZ4pZQO21Vp+jC4JxXDv/Er12xGzFXETCbrXZci
u36pdRvf4xY2nylkArDrgZF0lEF2iSHZRLN+s7lBLzDiwrSiRJ8NSm0BaTwq
5iKkRitaSpJ1MiMVU00HJXBKxUqpUEiB+p7J5TOUPvQn0ryANM+EaY75jkXy
xy74THqOpDE3xN5LWRL9oOF16Xybv+b/e8BrwYDp4tFpfbFeLBQz1Y+X9vA+
QBgFHgPoxbkicicgUaentV7/PfSG+OIIKy4G/zUwpSkWK9+FYylbLeeS4Igf
HCKGuU0MJeW21l2DGkqg/OsoI73/wrF//45snvWCDTBxMv8nkiublFxZQrG6
geKpNASxNmXKeyiO/BfX/xXPdNnMBzCEh6EPdmK46yI7CvlPrGSOs4yJYOZh
4iG1aPOk5FFh8+2TMuKQlIOTUgtOSv+qRF5DDK5fMPVufZAfHVFYOHkt9sYB
oOtWXgd6bNaKxpATncYVVszxBmVB7Tzs37COXdqJOfn5eYAoZrYFWf2hKhAL
hplrDkzS4BVRIzVKSDHCqjoUSH9w4MWWbaVuoMajrVFbX/PMTMfXPPZFgUYu
gzcrD/CiITSDtRp7+Pm9hAUa7OMJCp+Ifpbux1/NmWZirs6hl7pQ2fxgT0ZD
PJxKqizE5ToUtnMdKsKnohALdCMPIh/h/Oa6E9AHiM8pHrIWPHb3is7MLDAd
dEyPXmEklKoT5wKxucZ4TPw6UjH4CRtaULgg/ZTiqjxFXTpYVya8tMRhIZ9S
J3o5eXBQs8MxUbFRs8QmsRVDYC84GJbrlfVZ8+kmXbZydS0WyhkD/hNDqdXf
N5v68y7hxme2bTq85/tEPJMl6u8q2Uw4fav37eCgMxJWpsuLu/DIxBEZkVwQ
x2ZHbUTIzchtLGCxb9cW0EgSbJNLzwWPIJUnTJ569Ya2E2G38mBVHv4Fj70M
xC5PZQZG2+LEfiKOoTKwIY9wtGbW0ZHv4sAUMWvtyzg6Qm/GvhpknPH+pWsO
fP5THOJIzTANiSy+v/V/+mWrEER8Gfo1fye5cjr+nhv1rzAdXR2TjAOWiPdq
8ep2MEc40HDmgaPJ88MBAcKXKrlU5iM3SGsqJPfjHkc5mpc28JDypxU/KZqH
avFPxubmHPJwdPsXQ+9dL+2YyId8xd9hEtHDzG9cJPTC1Ynsg9ruQyiI3I0U
M+LOqlgxeYRxrkcbhxRi+nEGJcnyTgWNKrwm2Ct9iJ0DdhWj+OtHLoOOjoLr
ICTyyGGBe3ELhX3ZySE0cD6f6OQUMXB5xgyRnFWHnh4seUm5u2pnfDItdYwa
Cx4RqBSjiiRmCtxpSAkSNg/nB1qKmdLhAdY4rWG4EhU2e2hRlrAqqzOsdTgz
0fWgCCYGJ3tHFVZQ4AfUEI67JBLDz5uXSDfnq7kpowjwOss/9ObehghbX5Gj
N09h08xCosijFAAgh6BpWbB1JBQBh/wzckfyi78gLh6Xyh6tUkQdqg4XJYzt
B9Rj669VUKBsZ1kKTJYJGk94KR7YEs3xkkAwl8qruOBXw5v49Q3RJOGe5viy
cTSRkLkCS8Jxr1GoLAdkwfKZvCKhZ5/5KfR80kdHisoTB4CL/dQlnu4Pqs2e
fHifdny4o6O7PbVEcRDVsZk2Clfyw/wJZhnBLtmoRvve7qQx8eAjxT285Gq0
JCO9uLvMaTxiIP38sh0UK29jjYNGeyM3/9PX8XL19ZDHA4HhGP11yJwFakjy
unwGr3GCRRHagfjzy71gbNGnrxPHln2IlG62Dj7CyrPBVzpOaMzsg3xKqK2L
x2xAk2KhhYrOYJlo6eDgmm91LFHgJRPGx/8jTK8CMJk/QZXda74gVGW3jvGQ
Gh+mhVvwcO2nD7al8AeWfPHvW8hx4NUakTCaqt/za4BbfpoFMjPPUdvv8UhR
bYowAjCbZqjThYSL2uPL1vMWtZU9xBWK+SpUT269jn2P8udI+VbuEFfmYzDC
6xeFkj/ctSb5RGvSRdF7y4v54tFYC1dQ2VX80qvXGw1j3VHMNLYO0dYBvlGv
Qtyshjdh2swOyiLxoL2sjx++jwFtQbGXdeXBXd/lwt91eO2LmBpMXp2l9woJ
UW2lde7eukpGKI2JroeufWkU+7/f1wWBhJ+zx7njwnEp+jB/XDxGR8v19qzR
YfJZFONHiAzmve3/R/BvLOiQFT7HsSpJOfjiv/7P/9UD9l//x/8S/Q+EknsH
ylSebEDh/xWFkn8XyldhDxTvPyKh5Xilz3mfAjs39lI5lSV+95Kdih/dWCQ9
g9IrVOjE808FGy2+WmaoRub6W7/i9u7rwLhCmj+siGb68IdC18xxylk6Hy/V
+cPKdIYn+gOgRya6uxjoDysEGp7aD4AemVpsudEfVmo0PMMfAD0yw/cKmv6w
YqbhSf4A6JFJvlsy9UcVyUz/0BKc0Ul+qBTnD6uyGZ7pD4AemWklFdYiYFi/
WPv3G9eHyKf1A+GHJrbjeih01v9Mfu/A9QSLe8oPYptO7H0/8tarzf6p7xgB
FfIBfd0a6YoxvkzSD4+DfPQvZB+LUQfQciaFLivQ6MJ8tCmz1kkRiimn932a
Pjz2GqFGNdeQuhtpuWC7Y7ARHc/sByMfDdHJamipfuFENL0+ydFNEKsE+9Vh
dv58+NGafN791i7Tn5eEUZSYBiXvIRnW0bG4qrFaW/hDZrCRGr2E/mcvago5
zGskEL1YOjpadz/wrAr0qeNqbi1jmDHojfem5Vdo9T5C7tm8oxyuyJ8S8lF6
9+S8ssu6A0ukXsOG1/c78MRW4wsyoSMOSCIi3UuRn5OqqCicEB9BQMwUIji8
i67nf+KeO3+R4A/TYnoQfxD13JJLL/VB8XNRO29y8dNTdUyewinBzLH2sQzD
0Zu7SS580WDBRUv6MFfiI9H7KH34URTRBCEM33e3bzfB23Yg4/W6ZEzJt8o5
ys+woGVd516875tHXt7RFvmIR8seEfDQjaeNdZdWgoKlTi3Ttf22S4Amsn8Q
w3qMBYyxEcM67GSijieUCYoBAkooPvZbwnKET7w66EYM6x9/HPK6GaECjkdH
6xKOIBKwiCOF6lA0CZVxxELKLXXu1fVEPHkfD9kL9AhCkzZRPcYraDgsqAqu
cuB5y1koYoNHrcOORMe71xIoTiB373r9A9ca84AYvCKOF7teFej3mJCyZXP0
T36n7f+4LqUWrZzJGxVhvMsnL5fcj8MIVbnEGwLMGveK1sRMCyWu6jXc4YWl
aAtisyhfIFiq7bVzr3UEaewVeWXolaCiVe4MpbEd9kGHKwnXNkbzC6kH7cik
IR10BodNNte6aZlXUQmr8dABFnzlVXryfGLs1SVhT7dzY6x1bvgB2l61FkB2
Rfd6wHGwNSPvcHHLY8Spu1Oo4U8IK7+zzLG3qf2GLsBOXkcW25fyksZjboKy
xHgZZSi8iBfzCskcB+ME4REcHQoOwtpo8rqw0JDWzVKBEtgfjWrCeV/rTMK7
ERA6HDpm1PKsM0oHDhyGXtq/z2GRSxB4mW5bZO/g9QvJUQluqqvFKwXgb8zf
kL7r1b8m2NmM2XfGBhTwS3355ZJSQi+4kYrerG8W8xriVQPPwZa4BKPiQ7ww
mreiJFlAFPHlk4gz11WpQj2iKcrPCHg6oBYPiGIjv4SXV3CPHNH9gC95egfX
w/umqaHrHysmbZXqD/SOYHNEWsBhvABXQNYHncoYVby3MM+YMf+co/rK6WoF
jppi/tAv7r9xbK5ra/OWN9Fy7n7cTOh2DpDm145fRuoSZb7X8JYKtPt/SOsm
7UljVD7UsTRkJWH1DykNuBzyCzyTfOawbFgrjQom8GrXSGnL4WGNgBMKxRHQ
iLZvtDr2Oz5xfxsg7BTRx/KUHRbcNi5C9zrYEAGZEQiHDItF2CdetS9e/Tu4
GyWwxD64a0OJ5evGbbC11gUG//VWwCM13uFjplJ0Y61lglcdcxtbWsFIgc7j
QB6EmlJQqse2MnWIDQ34TRnnaY8Lgg0kB0cACjVqh8XbU/Iggmj1tsjy4EID
AN1vcyBPTFVmXucINK000ExC0i6Q4zvmiIt2zJWTQB2JcuCC8OTxlt4B8W73
rUsTm976erNfkeBfjkN271FSv7h8MUCdve6d8ziQtcKaOjjd4o3PBwf/M53W
wbKgdp5N5Y8jGzCAEcqEaqgg4ZnYZpqmA2siX/ntGEdYQgKPPabh4Q7PNU2d
YYk3kMdzRs3+1poUcLxXUdQrOIj5VozqQSISaNe6RsS+5f5hTIwMGsVtiGRr
Mx2cX72s48uJu3YQCaX3Ay+N6HhMBEegoXK1ntN3x2deF8ctKRZciWpBOU7/
hhsbv6hckQyEoaCYtLd8B4a6btAK+AQsGu0DEqwS7/LGazLa3jX4uqAoUcFA
GwkI7kcXRH9GG2XmWZ2AlscKKUx4kjXq5suruyi+Bul30QMDZexaQZ08OP7W
V/kHoVv92OBliwX9+JygbcHGp6Gyw/wurrJVj1jQuS5mE2+DjsD02USy1bdw
HFJoD1OobKS1A9UOBW1zzO9pSXi6XJ5hgwtcKDuCLrUP5PNeqyvRdL9bCj46
WP8cDfvxaslGeh9yF8ROYqXwfhpfpj47XphGKOMEv232rm479R6lyRJuP29m
Rx4Et5nx1RpD3Qa3WzjTRgoqZHEaYjyJzILOg5t9jzgy3aBpko/He1UjY/FY
a2HerXcAni9McHd6UNvTbnMvvfe2nbzgbSd5wARYgZJQRzEIym0Qq2KwxTqZ
FDVAeg2wHHGVXPLSxrFyzJj5Tgv/lN4Tro2qJkYvRxUbOhe4i8LS37GtUxRI
jXLklo1VDJCJpjORAcB/4MH8fvIZclM6U05nCumwX0IM/BK2SHXPxMAeFVVb
HFrmlBmkoMMRJurSSgQxJ7IljJAu5kqlTLF0CBh9OpNmkgHrfCh8OdGAk9qS
cwkU7JvTVaiaxxB/gr2MxE05+Fvai1u109lstZotEjCf5ppkjF0MewKobXJm
GWb4WJ4Ez2iukajrhWSLWCsaeUp0THHIaBYatuTjEwVBiL0wV6LqwFQN9NXS
UQ5SbGIq8DXobCL8H6L0BYN28DpAkSP5B94DO4XBVYznIYz9pwkRSqtKtlSt
FLPlUiH/q/pLNpPJlMulUi6fqxCRv4TrLgWxV0jmUOEl5pextnjNpTAK0bBK
L33OUyHThx5jXbKl02IGCjxeGy3EYXjowM9oAzIsrEk/06xnrmazdOBrGmnS
QlxrraJqiLu5LuLKCywxwqUBO3jlT/OWkm7CDk740WduLyMH8VinX0anJ0YI
QecGR3KiOrA2WAoAllCkqHpRUjk1enWstKgp0S1mywt8SMMNLZWN9m4oi1yS
O6dIWwlFhjhCLqSjiJONRs5khRtXMhxXD28ec2ynKO8fdSpc3pQ7TWeyoveq
2DFkXKK15BDx4BTRRSVOGZuJOFev/jPMebVnTWxOGa8VFHEp+pNFmxZTHRsO
fUnl/UkHpk1764JclIxDzIj3WPNCGm6QzvsF5HbKctMoBtLFcqFYKKZmkxmB
aTHgcIRC0wWhEoXgP6VUzViWUpnlwh98qcGMAVHBEa1jRViSVD3VCPnMMQXM
kFkKbEwpJRtpZHESm2KmLILY5AcWsLI6suWlU60WgbOyKYWn8OKqIZUKQ/Ut
6ofHJ1w+YWAxJqWDViyOwO6SRFiLGcoAkK7Y+VgSQU3dsyobRO70e+F2mJR4
7gB9A7qqtq0xxcTULU0VDcmewL+mtEEnzJ66K1d0V9LbXNXRLzuPbJANOtn6
m6KHhZ7tpOgZ3/ppqZIztWo1s0lfDE0PCydEkj+jDwlNTtV0IQ2CLpvJ5QJq
huCoI2aMQz6fFD3gaT3pins3WmWuu/prky+COx5LhmtLG+P6jznOMIV97IPi
wNSYOFMdeYKHID8ucBtQcDKdgPiXrJkukGthiiuwgG30ZHlHCFq2IzWKzv7C
VjN8B95IB+/SBU3IiNwpy/gVLI5hz0zVCaf929QD0uVk9jpCYsZ0NVesZmuZ
InD0SV0sZrJF8aSWb4gn2XyhfJIvNkqVAkHUpPlSiC4eLRs+T01cn5XTG1KV
30PjPSecciBHRczSFTG4f/8JwGdgTtwNUQFP+K5JZzOFYqVUrOYLg2wul8kU
MlmudFyjKUC7gZBTVCdShiN4llItzmz7DoHoyQ8itToq5XJZMVeSJbGcq+bF
KmNVsVgslod5OTOsjCob2/FC7V4L99eX6+E1MGTnM66Z+HsyqhD4h45Xb5Cj
gsvsCRM44VIKm28ceviI+NdOTzula/Py7XpJH8ChAMQNUZH+TpGXRVJTIMwI
B3+VgHYiuoKiJyPiYPNjgzKs957bnrKIdjWN3sJkBBZaRGWYGmPaPnPTNuZB
UNPkX19dZq1+ifIzfY+6SUoLfR8tHSOrlqzB7/Q4HfV+/RzAJ0gy4GRpoASH
VcXQQ1qRXCFTKW9GoUROary2EdF7ua7IgYkjBmrIkgHqG7xrBb9xJdF4AdEe
qGYbNSLoRyrYgMUmt6guBs19DsOpcSGx6z0hvY5geHcKEbRBs0TZhFC9ywOu
y9QlN+rTkvkDoAYHBsjMfQrQAk+YD2F9wo1AJBlAytCp6T2hA1lRMf4kXSpv
CHDZVoyoIpPCR/TNgqlL1RgUcvlyKVvNpbGwwNi0VoNsPlMtgf67Ht2Eo9mh
xQ6RJfTQL7qyi185Y3PJ5DEvXdYRpn3Xmqr2BDD12y2ADqKGTpDIYxpmIg2x
fgtmGasgPKK7aA8OqgxS8E1aqSNxKmnqyrT42kjTYVjLpj+59RbSuFQjdOjA
qQQ8SH0kghWWFLBWZGH7yOU/iFwesvQCNAOwfkG9G8EZSOBAZ0aLi4E5KjEg
DEwDJQBdG9DfcOCOLYAjUfMZKsYjjhnYAelStVTNFspFvgE6XVdzVDCFwqnl
uveMH3aesGMGbDs5SCan5lhg6PFuqr4CebuWVWtLnO5tyXUY3LquX1vH7kRS
FI+5eb72P/ouRepKzI3qLihGEnoJpWmUfnh+wZBGoDnYaZ2/O5Omg306NF7l
b5nU6HGfoygpF8rVQrZYzJcr+RJwfqZUEF/FWoEv5a2pWOrYFE4soJH5LjaW
NaQXB6BbcZHlX91xSU5OAeQZwxSRPHAwU+4SYVGs5OBUzZdKJUCnmBMfM7Ui
x+IE7+SuLTD5Nksc7cBhCC/DSUYvi4VCMVvI5gYm51ksv+CQfrRP5VpjU6iW
s5VctQCmb6GQERcjNe+bpqYFSwaWLxB1xGIQAoXJpnfSPAQuoHoadO40ZzFu
Zqz+3RZOep2Dg/Wfp0whLrvCa1CeWLnT7P50gl4lW9IdYfT3/7SEHqrV1oRh
xIiBeXXhz2zu9pryEmsbzCfUJQtMDqGtag72QwKaUO9W2xZAsZsyG0MwuGsQ
cD2GrzTlX80F9JnHn9Tr0VAzL8HSK/sSFO3mERJwWIC40YSQkPMCQfAfkaY/
6AEnjzV6x2FZQtvcDzTwa3wf8BrmVMSaOXLqmDsLMWiB6tIEZRKGK6Fe9wYE
vCnWhpx0u+vO8cu4zVI33jUB83oGrHM+sJZLnfyL3HPBb78RNI/oCR7vdZsG
fZJnDPQM7uLwmmAn8h5T7Fa6c9s/DSRoJMXV878Gb3lBdSEe9Yr2ULLKcLVR
IdBPig1yXr0XuXsekfZ/QRUsxdNsfZ9vGA8adjdsz6EawsGLTfJAq5aAXR/C
d/V+kz1usXHJQ63tt6+Xdnm6I2j6yZf8EoVfUiADUeeqT0dH1JwNFbGjo+j7
eHflhbTFOMgPeXGMj5VOx/jE9En5NNt4GVgvdqWTOR/nV/VZ/laaZR5ZM/3R
GuzvAjpMiJTUvK8qd6emU7t5axvKNJd/PZEXJ/28ZCdDKg5QUqTy7XmmmbVH
j/Z8deJopdr4qfIi9tptdZEMqThASZEqXpyV1Ko9N3VjMltdtx+u2Uu3POrq
jzfJkIoDlBSp+8HTa+vuKT9qLqTTxWI1qlUb9mTWZk4mGVJxgJIidXY6kBd6
u90cWmeDh+J9adVkzsODoaqFZEjFAUqK1PWg/tRfyePMeassD88l97QmTu/H
j7kXMxlScYCSIvV89nL2OHtaPBeN+r3+NngonJ6XHtXT5lNCSsUBSopUwTbz
F8v21dVju5ddGPOJa7KHhzGrt6fJkIoDlBSpm9KZLhcr84yc1Rr3efel85Sp
PQ7MUauWDKk4QEmRMgpdVry5rs8Xk6XcPDOUB3a9AotUNhPyVBygpEgN2e3b
5eV80VVH09vR2fVoyeSW2Z71GwklehygBEjJI/jrrvjUVqpZ7elFfa33nerJ
8+q+cXnK7mbdDyP1LqDEZ99p3SycdG8bvbuVMb+s1m7OJOf6xXiUxgnPvhhA
SZFaDAdPdrX7rFTdqtnNnUzFijMvj+aPrYRIxQFKipQ5r4zEsvx8fl68fRa7
+otc6kzueyfiaUKREAcoKVI5986VGtnGavxy2egWWv2BaD0NF331LCFScYCS
IjU7yVel4WX2xmoXBrV+d9AsV+bL6767TIhUHKDEZ9/yvL7stpnYq6m3VXdy
daVp1nlBv6slPGbiACVFqp9durO7k8XrU/Ok1673H8e99uOzo7y+VZIhFQco
KVKT20WhdLoY6/eKWh29Puu50cv5UDMGnYTHTBygpEjdtcqr5mCq6be95eUq
134sjd7cU9NovHxceL4LKPHum8xYR1PY6ahZMquvpYvq/dTJZGr184SUigOU
FKmxnFNfMvOhySa9gTjPZsTepa0tped6QnU4DlBi4XlV0Guj12L77HnmNBqX
Vs9Qym8N5TGbkNHjACVF6tE9kwer5tl1vdtxn+R57qpbfmyY49v6XTKk4gAl
1qfu25oxPO00J6J8fcO6buP+6nVZfJo/JDSx4gAlRWp5f5evl1/vroyxrM7K
J4Xnq2L37K5ffUx4IMcBSopUdlyXrxdi+dKcNW7f3k7eannltDM287cJlbw4
QEmRciqSOXw7yZcL2oN68WbdW1e3T+Vp62mVcPniACVFSs/frU5Kjxc3b0vJ
ldlLc2BWro1C1u11kiEVByixnHptv8rD4flcGpitpvjSbDy7uUJ+PBITHshx
gBKbWI3KzUn24f5CdMxLc966yfWnpYaus2bCYyYOUFKk5o+XuZk6ei62HuV6
dnmx6I0u6sadfHqX0GkWBygpUt3W6aNqDCvFx550MX19OWlO9JPnevlaTshT
cYCSIvViV+87heuTyupJn4xzV0Pp+SQr5XKji4Q8FQcoKVKZ27er27fHwb2i
PRXvbgbdh66+fNYM6yWhnIoDlBSph3y3nT0BY22oZx/urpetG3UideTsWz+h
jh4HKLE+NZBaK00/bZsX+utl+eREfro326J1mdiaiQGUFKly76nnnlTy57pV
fa0Ps/fZ02rBqD7k8wm1hDhAiXmq9zAa554um7Ur5+ym/GyPskutcCXWrhJ6
XeIAJT6Q9dHlQhwuKue2cjbUCrZ0Ua2evhVUJic8kGMAJfYOr9RRq/J2XZQW
pjUc9LKXt9XT5l3z8SGpdzgGUFKk6k+LebdcfCtZ/Y6Sq+Wfn+fPZ3p7eaUm
1KfiACVAyh3p8Geuujx9fizWC2avNZ091+aP/UH56eIhd//x9XsfUlJaudn2
8umhKp+N7mdqvj6qvmZKbLKYPbUSnn5xgJIi1WsNaplMtiSJ513jsTZtOd27
pTl91l8SsnocoMRXRouyePWQq9furYx4c/JWLbNad3kyMLoJj+Q4QIkNd2M1
lKXR/CbXEDuTu1H/PperPNycXk4S2shxgJIiZen3l+x0+CItcyUtnzWKM9Vp
d5ZXN9OEB00coKRINcaTM6WVX9nD69Pz7g2ryG9voiN3uq8JJVUcoMSUer6Q
ZFXJLYymI50tekO10xk5+X7mNCFPxQFKitRg2jy5alza/YeXsaQMi0tDe6mU
lPlETqhRxQFKitTrdf6xnulK1ulpLd/rDk9mDw9nzrJWv0zI6HGAkiI1nb7c
TNTCan42UGuLJ+t6kZWt04moiwl5Kg5QYnvmZKqcO+dvfadwWs3ez6zRecdQ
xno/l1B5iQOUFKm26w5qp242e9K3lOV5vlOZ6Ivcy8usktBwjwOU3G1mqOZy
ejIY3Dx35pNTo2hID6WXzuNbQj0hDlBSpNQHu16vaZWnZ3F21a+VbfXyrmWP
NLWdkFJxgJIiJbZb13e3xfrcvX+Qr2rjfFnuLRdmra8nZPQ4QEmRujAunprl
YevmSq8v7x9fS7ajXjnnCzmbUE7FAUrMU4Nh52xypZwUXrLjjCG/La+fF6eP
Tt1M6oqNAZT4zmFVeL2/Obtp3VZy4tCe3gzuWp2SyrTsU8I7hxhAifWps7w9
eDo1RtXOTaXcn+fk7GthlC8tzxMyehygxIElD+fdp6fsUyvbzKm9QXt1U7Aa
+pXdaCWMC4oDlFhLOM8ajR5b1Ib3F4MFu5pVK1Pj6VkelxIyehygxC6OF/ct
M+q8VJyXJ1O+09Xn50e5t1icthNSKg5QYsPhSb0vnD9fWrmMxUo305a+eujl
Z9cOS6glxAFKHILzNF7qWXXolGYF5aK8PM0+XSpa5rE3S2jNxAFKilTp4nx8
Ncvlnm6Xrf7TUFTFk6Xabb11HxL68uIAJRYJZls+v3YeL0Ynd0/1Z/MyaxhX
JZY9FRMyehygxDEcvdWwXVUnxuXLZbn3okwmT4NHZznpOgmXLw5QUqSUQati
lS+6rZdaoXhyzZbPC3uk6zXnLKFEjwOU2JcgvkmV0uDpLGPPFiePJ4v+/c3b
Qr2qWwl9eXGAEkcmFDpdZV5fVrRe89yqq2edl+HspH5rFRIqeXGAEutTtavq
6vTMHGn32UVjsZAnhaKiv071VUIdPQ5QYh09c/HaHp1I9o2ulapPYvVZGxgv
I7tZSbj74gAlFgmTq5b2tJIHK8PR5/0MHBJLTdEW0jLhlVEcoMRawnBxUZUV
rTRSrzPzk9a41ru7a+jS9SqhkhcHKHG0i8MW7WG3dX5yc3XeyNmv1rhvGbP6
1TShLyEOUGL/lN15KZnlxagweRy49Ytitl/vz8XF6TKhSIgDlFiil+RKo3R9
0rhlmWWhUXt97OadQvNaLiSV6DGAEod1WSfFfPls4uSmzYv7es/q304dkDDl
pIG6cYCSInV7bZw/je7qjUH3dpGfGLVM5m1cqhRWrYS7Lw5Q4hiObnuQsS8u
7opdNjWbxtvD+ZnROdOlXkL3YhygpEi1zuq1fFYf19hEG59e37qDVbuWzWjn
1wl3XxygpEhVR2Iue9Y9L9nZa0U2hyX92syUrMuFntDEigOUFKnK6+ugddrP
V7Od5rD1/Hxz5zx1ry4fq3cJfQlxgA69klRYJvDGxcxl6njboYqLlnMsjAAw
lS4WXv2fQ91sLUm1eSrYZuM/+ICK9VjUqhyL9mH1MMrUecBiZLsrtXtF2j/x
vHLhL7G1873ivnay6u3eV78eYKFwTCTDopmq4VKxx3CpTtvPuKNKdVjkg4qu
Yp05+1jAMpwq1pAONbbarLl/dETz2NfTV3hxgaAjlSm/Cnc+ZK9TvcFER9W3
yycP1yWyMIvLpHr9oXcsrMkkqDpV23IYZupSn826ib0B6JUmvEu1ninFrw+j
fKYOT1+CatkbVVHCXAXckFYVrwq615ACeEzkCzbHZr2wDJkC5ZxjHTDKqS+J
ucOUv/Je1p/fWADrStI0gCPUsUF1vW1OP2tHRXK/JPlmTfJPlLEMsLHIvCGv
fGp5xTuYcvgrdQ1QvBr3R0e8xghP/OPjrcenEnPU/hMXAesMujrlMPIKoZuw
sbouluX7oUQspHKpApGxDbwX1BbGmpG06F6iIW0rwBlIYzAt6O2gGnNTm/vt
Hba6VP5K2P/tb1ht87bGC8LjMNTqUxKIVlTSOlLaWhgzXosNC0PwxvDCdafT
4MmD9XbnegB//MplTMtVFawPJPTZ0kE5EPQpw3LnSM+YeaSEUxB0+AB+Vkxs
/u1nM6rGQbSM4XZx1+NdfVaPt9uq4qypPrIKW4aw4rmcVDEaRw7N069o4CXQ
4id+LuiB33sxFmthE+s9fda3kZJhWN5RlTc9D5XHTkanyPRzO0iS58Of8Aao
fHCvO22EgewPzPRgY9ytXtPHW79g8+btp8yc736s73psOfKex6Ii7fvFkV2c
OWb/hkooYH9frNiGy7xOCj6gVNdQCQWPaWZw0mDBRAU71lO+uKX7qbxbWbW7
02jfq9wrdDF1Wg2l1y+w7O/QLz9s8uLjmN87s7D6Elb6SFPPZJ6My3Ofo71I
615VVa9l9QE2wPQLTPuVwUk+UiFUxBrPOf8033/yfZKmkkCdQQ43CjKeYLtJ
qixvh+qwg9AxFEz9XWcMR6vID9d1euE3jfL9udDgtdhBzvGkdx9QkLpMHTpj
ynTbpubykq4CaEJcr3FBzcJityYW552YXrlKzcRqhLxk3lbTT0p3Rr1BU6eM
GjlstPlENHGmJjav9oDARNf9NLwC6lhqlmsvTLKxNO6QCUFC+3AV7akS1MVM
gYQFHQ2kLQMqzSP1Pih3HotYw2LFTwLegRHk1RB4xv8eWRmFHVaT8Ar3Aksh
pn4OuV82+3hdRZYKDvgjY9Mi7GOAyf8GTQ91H+r56w4dbWfpVKEJiy9TTYEo
h8K5/klNsRSvRQxqJxU6oE0lYfdWL4WcH4EhNvL37DE88TLQqfkDzodKbvD0
/a7XgAuUNDiqhR414DoGndlSJR22IIgvaSQdC33X1EELqbkW/HGv4t63NWku
NNwhW03NY+EM6x7hZ0w4k2TQp0G/7pnGeGgKJ+6xUJ8wY7wE5NquhLpGWzIX
WK7DxD/OpZUkNC1ZBZ7BsW0bq3WrkoFFTtTxBMU/J3YHi1L35IllytND4kHm
0S0soySVC6N3a6rO4FdeyoGqq1J16oDpPA3IL+b7jVLMb0QUdKbAguqqzfly
XylYr6DBzOucENNsJShi44nC8Fd8FJQZQAY85T0u9KwEGt2vOb5VX9cv0kCW
kf8uooYztKSZqnhdNVLEo94cqaeqQhWpgw0e2jHrmhR+N5aU0AfpqBqwYm8B
yf2OSSDwFSpZTtBpJ/o1eoKhdp44PhyqKrHGDyHAgW5hhyuFZKjFsNiw5Ejr
Juf0yCYFZb16/EtvSHwLu1hi2+CgbjlOzdWxRrn/mAqzwOjUE9ZXB7GFLZby
WndYu9+9/LV1bYj7tVRt4OFgH/RNz8ywAws01LEn1KII15AKHAM/kg61JieS
gUSAV1osjhdDhSpCIp5Oqs2WXrsaPh1/sI/WcWzfLxDMNpq46pwbf6inBfWX
GZWo8XsiGGQpWVgaJuAYZD2wjXANHaAA9XrH0oz40IdDa2i/IzLr9boQ7sXT
67S4bPK1ppQQ6i2M5PuEtfvZciKhTYyt+lRat0NqrGTxJjK87dD6gdeAjKjP
zSr/Hf9PeIOqjBCX0pmK9gsdvNPNVXu/SxbRx2+rtZYnXBsJSdKRa5He4W2x
DQ2GY4jFxDwVE3VMf0pB+ezQtP/A3sh4lDvpNmoTv4M5YLjY3rcBK/jJxhaS
webB/pUinNl7/wm/f7lQDXcJK+DqeKqHq+qggRQqwTiTU9iSApRG+lc6l6GG
ldeWNHZh69TfsIqxBE+KYlm4kuE8QwDwt62hZ+ZYQLRMPmirVmi1hWwB2w9o
zMBC913Ok1FTeSwVxhOylfmY+IU441/Q6D34RJqhLvW7kKuA4jpzxNx7o4fL
+oTqfALD2qmxaY696mqKmoLzD+SclE2pTprZpqXKNhV+wqFvQdU/FjoOiGr4
K1sQs3z8jZFpSGr5dlvr90CHhI2m6v4WxAVULceFzYQwdgEIo46FuyXgUkP4
Tfhy27nqCz1Xh522ORV6CDLBdEST1zgM0G7B4mIvvGPh1JJ4Z2g+LEMGCMb+
4pgzbB60MswZnEShSqAmkkk1QOFJjax0bjYzx1Zu1O+du/atOc7fPg6vb35F
ze5nArGu+OifanjyRCr8SeHCmUyZmDLvvfr9ZpgTd87Rr9j/Plxe1XGGVTwt
e08b1sNj4QtfsigT+6oWlsqiKo2hKlPpQjZfrVTymdLAN7oGNY9OA3M08LwH
yqB/0RsAndYPmo32Vf0wwtcNPJgD2+0BW2n0sG+VLnxq9B56h/v2FnpjBza9
mebFqf0qZ2id8QYwLc0cApOCAagSTVH8tYDOOmwJkrxt0ANgO3+irb13qMMI
w+cKcG6P1+vxLdQrlqrFcnHQxjY4Pa8NzmBDSRioxuCUbKdBq3M6aDD07g1g
ClH67uoyunnq4iITyddYunYmt2DD1Jtp6ikXi8LKafKIpO9qRr6SVZgqiVL3
Un9ptSfd16Upy9m2vDotT+0LTWLsnI2WV4Vhr57T29dvi+ub66cWyynG823q
baSxp7quOyCbzMFlj++LSFG1Wke45hpVD90RnhhF+UBCJxveNRHvoyeB0llv
29yrzDDAWqnBqWuRIM9lhTMXe6X464OK2EevGwAskg2UKWanTWWsDJb65OXm
Ub0dSBdPyqtzP2+csdPCt26bTLVYyGWrA7838+C2NQgTZhBUm+MLPaYWL4Na
h9OQOhT/ECJtzmVn+9AwXHQhAizNTvNPRXjIuc+vSbvuAIOykzrfiplMaqaM
drDjynQdNzVk6dNhsf02yeqzbPNX55dCtlL1xKo/ZzpOsFsV/MdsthLaoBiH
6KBO1TXCzIjgPPEPIvovhLGHOpkwdZA86yMMZvXCwsL3YyP+vFHAm5p9lovi
hlmJ9eCQOojbPzKpzf0WsNWP23ZbNPvmfXdfPTl/Phs0WtPna0UzXk6kO7bS
3Mnw9eaftO/apnN7Wv8udMpWN+n0fbbexHSskUz1miUxW9zbbAO0Fq/sZqSb
QyYTuykb7Ydb9WV5bpuwKfO5SnHXpiQufIcwAbfaacI6YN6PUuvP3onfaXX8
0WmBlF2DbXRjeWdFWrevK6vRaY6bC1iRbL6QOfR09uvWvzSfqmw29rg0s5Po
yegwrrwO3Gx1/vg2xeOikCl4nImKpD0xZ1EChCtf24YkTxxRAdGBVfIVlgaO
GlugI3stKSTDVuGNffXEs8Ui7gMgdoODEHrYNRXUzEusRb6h+78/OuObwAcG
IrUES4B9JIMl2DgWfsyEiHxXroO9YqNzMOmhqCgIewPXYhjXLVQjX9LGnTpY
nBn7L3i3aljePK4aP8jlqFCTuJAWJdB6+VVj2kN+z9G30ybj3gEsH+0uR9QP
ivydyMv7SlUTGBgr1FJ6uBLOYBnA0kB/BNn4ksEtOWyBdCzc9WpIpbwI1kOU
UHhVvlnA+Z3TLFspgglRGfTQ3wdmnPpGv2yaXrupEXiV64GrfMuLEZ65HHzh
2ULA8HWsGS9cSuToWhP4NKBfdDqyIY+w7UHUjspnhNrMUrUYEfMhWhSqhWpu
cIu8hNNHXkLTaaPU7qAWaw5tm0F5Z/I8sW9V8eT57EJsvb4Yi9bbpKwaQ81x
zzva7P7ltas9zEoPt0q3/1wqPVdmYuXpRZLY1Wg4eUzVzXbp6cSdSueulBlP
HbzK4PEBqo6Y6DMhk/mcK3/OZGihwMjD3ot4plG3WOoH+ZvvdiJS+VEwO2TL
ptNJwvdxw+D7YuBm6GKDXTB6j4W6ZEiKJHya8wXBH7PlyIp824LksvlSKZsZ
9PFWHDUt7/VB04ChTANdiYP+bXNwNWPGoOeCkRgn4M+tqrmcZUeKkcGDLlPJ
49u86eI+CgTtnyVriwqid0KJHIQvMi5hf/ZWOmxGFR38Bqp8Qh9dQbZ/UeFL
d3MUqgEPr/VM2Gkbjh7TFucm4ULdutKgncGzjQ2QLW2Se4drZw8kWlDuwtml
pYQ+47IxPVKx7xRvZlWgf2cK2dKA4/9vucy/5SrZf8tV95hnH0GDE/K62Rfr
V5e8+nj2s5AtoruUt3wQmn7LB6/ZJt47IU97PdjX443AfGROaqzieYFuewM2
DOw71CyK6E3d3UOCAPLOZAYPsftdOJcszbbcCYhcr8Y/kV78LsyO0qeYyZGf
BqyIfU4wpOi3yflcOV95Dzq52DbPApCAwLQD1AO9lWn1u6fcffxZqBkG8qBv
AHrXng8t4Sc+FvxCjZCQ931m/2mN+9jRR+RTTtl8U9h4YhB7eCrHr9i58RdG
K3Dhvok9vM6Ef7pz5lphH2dBBOJ3JesfPQWK+XK2mOwU4Gby6W1YYS6+qzAX
uQt/wow3+D+89MbWDRExWn1nQu9ozsVdmjNYdCPLb2bnq0zxunFndD4eXpUL
F04BRGcpUyzs9CJ9bMqfaOR3p17+IVMnv9K2Sz5++pPHMmiIzellGU2kUrnk
zR49H/qW5+O7LPw/zsmZfKFcyJfz+z0Vvk/ionbe/LPx/7bV01CV9xqs7bxO
oduTd1bz7G10MRsaEy1TQxdENlve45r5LoQo/hBCRHw0HkGCsIZ1BBr/a78l
FE+oK+fKLF+aY9VGts8Xs75F7NPn23w1xQ1fTSz5CuIWBb/Nb1MM+W2+t7X4
Dd6dfeu64d1JhGn8apZytWLltZ2tdjuwmrlcOeNbddsBCqHzed1aEt4To4de
WAPNCKdsGMPnIUC7rw898L5WbeOd4xCdvUaIVH78GYWf8egzflJ7B3ULDAHS
SHNZfj/w1y2CIIMSUYb8mnshOfLk1/kvqvK6GGYmp9rE/m8YcfHL9YU+mt6d
yfmq250825ctfbYUXxuiWzdvVt2x1pn9NzQjSlk7vC123XJ/kCtU/hU3LizJ
gWMpm/Yb7+HfUZJX36F48rG2WHLXW57QIc5caw/vXcaM726fSlnlXr0mLyMc
TYdCnIslpMCbtsL09VW0jXHErsbSNLc9rhUQLAqbg0DU8Qb3y+lVr9HsbphW
m4CRuidgatpMs4+FE6aN0YD7XchnhTPJELMb5N62sPZiyu3oVrt1etINzioH
yLxLcGxC8YJOiNSUp2LvgsShpHMlOPNz3CjLZbKDUsatsoyxZ3Xoz9TmgK5S
ymWLOwZJSfNsasGG+vcUHLkyUvefLji4kgRKEZEumyvvkR4BQ19nCs7Fmdxb
jrq/flxcFPKF7yp18/8SxPOIls2/RzS5Z9WfL1dmeTBOQDRy1XxPqpWEBpOJ
asX3qLYBKJ2YTif8Dpu0cH6HjdQqZnPZ0nvUWgy61kuXtVfXlQTUKla/K7Fy
H6fVd+Yw8uoFiZge1TK596iWLUmtZ9F8VpUkPJar5kgf+ttnwVEdjf3yUzgG
1w/4ZOtY3Eh0a4L415/+OOCBjjUvLjMIcwziNuENno4Je9uVrNU6CDeITuV5
Ll48879EuC3lK/A8KIwv9jOeKIVzI5zetLzcBx6yavLUWUHCFDIDU1eAVycY
z2R78UxbdKZ+fLMZpnRiatHMwgTPSDQ6DkIZENKIBdH4qoVpq5b9mVbgZ66x
7TFdDg8EQRS+kIfjIbRvPpBkvMyzm+Xpy83p2YXMJFbSCoPL8aOh240nHyxp
iR8Hi6pXujQevi4zj0+Vhyerne8uC/OripET3fNxABY7SX4cKuoNFW312p5U
V+XBxbw0zKqPk9nd65M1y3QzPlByD3wcKtro6b45d7TyYjx/W5w99HOd3PPC
mJidK+PpJqBsrfZxskrSOP1y8nw/LT+teouZdPq6Umqj5UM+P718vg7mf40K
Gc+LiSTpoBz46FgzH4YYSfRJK6Xiw7VUzzwMn28Xy/6JrBn96ajc06knAQ5P
sR45Mg95zPYXZ2IxScl+dGhpDSDtDt/K7mPdFsWnN7f3sHq8vLT1h9HA6d1g
WCJsAA967lugL9uTl1q1MHpjSunqsjO/vh0v+n3x4Vav+bRs9Lr1RIRTdFtO
39RzktKRn6ZLta8ZalOWy+PxtFI6qQWLtMNpEA947S647lhnuavBzat8eVcz
uh1jcD/J5Tr6Q1f2oYfjf75/zFAgOG63BIcVERx3p93b1ufEHMCLNT8/nGfc
breau1IW2vVw/Hgyv6nNGjNW/Na19+DeTm7LZrZtPSxHrcZofHvWvS0Vb0+m
jaaHNvmwkyJNLdAuh8t2Z1FtD5az3tNwPLoaGGXtvnPKHuxvxPkDndU4o3Yu
bz8sSUAXSw8qF838rZtdPmZLk3HrbGGtuv3bxa0p1dYrDGrLvltsz8ake2i+
8aNK1q5lx42EPeX3wBmnQ0dtmgLH09lsOZcpZ/P5feRLBNNrJJvOgwVCSPdr
9W9CFDT+NYLVfC5b/XYEQ7BymUypUilmggW4ql9HdxhmhvLvWWijwWvBvRLM
x5tmaEKmPBMlTUvRbaPNx4WPRP+jyGTK2RLayR6UXGIo5J4brC+JMAyJz62K
ra3XoPPfDXShkq+gZ5aWwINe+G7Qi7lCKV+ERemMBFCxKVkslE6MSW5zCc47
3HV4DULnHlWVAJ3VS2DmyipP5uNpQV4uGyljx8KMpz9pDKuK0AiU4ooBJpY6
5NnHB5G/fEWbpxthXueCIW8x8vZ82DTZdKbipBNYNrs+P6QMPqFTu6xt5eb2
I2nj2JPbMPmbPDUSM3sPMDFpCAceQqnJfm4e+X3AUjAoTYkpv/w0ArOJgTER
fYcXqcAMNINhCqdkYYo05jGvonmmHd69WvVLxoTtiBGPLcF8TMYURIaYCxNE
XXJG4sKNXI2SWXVKD/Vy+bcynr2e5jybVeHFMmaYgkLquZ++nvJp4+WyUzUU
m+dY+qYX5t7ZvBIKv/USqEf5uoU6puGF8tMFO9R12wJiAHEw0cPe7Lr9mRI+
F6o98bIbLTJBwIbxkuTIxmCyyuW7x3nrRFrP0lADo8bLsMSUQttZl/o5Aevf
QjqeYokXLLkDLLUSzpE/JOFKNSR41rAke2p6/5qrMjzqStYUtsWtq6zgr1s2
ZFNpIlwBVRTTGsGjvjlUgZeuXU0DJjs62tUZ/Ohob8twPn3aqJibzyeIOYE4
CdkUOVfgrGjp9sIhQuAqziXNJQtUDm9ZosF21jeNTuVlxkAHr5SHFPA020Fs
FXbVeOIgA65ZktuEE6bN8LmfWm8ae9ElfJqWKmNVC2BRDcl/5k5MWB/L/vv/
Y2yRfiPJHZfUcjHnXJMMeQJTgSV1gFuFc4vpzMKVeZEwprENDMW/h5NP6E9M
3TYR/BPYwzCnM1UifrgGC18TLtWpaZiwp+BJHcTiSnhQNf5+zTCNlY7FmcIZ
fH71AwvHaMDCmUIXNCDYbB4DnZkTQ7i2mPv3/wtwcBybQzsB6Q+M15Y0huWI
GNUe6DmSO8SJ+Kn4WPtmnXsvbP8P0Ywk6wdkuHBNQlqxYFMAShrR5NwFK15a
CbWJDvL+/O//+ff/++//OYUfwrn6hMFsomKo1ERX2ZimNl8pwtVUUoncME+E
jueNBHvvwTQVAACPWn//fy2ExGBZFL4MIEZ6koPvn0lTd8hXEnM+HXNhT9X1
2pxikjPwxISWA5gXRF/DHY8JcIMNQaSbGlvRLiONBmuEWCqIOr7BGiL/66O7
igQaL5VFZSas1XqTrWGFREzM3tpmz1ARhh+zzfzjgcbvmIbrwDpPQMtj0u7N
LhL3A06n3Ne0Ywu2scaRLfRteWKOmKHi0j9JFmrWEzYa0YJeSC5P0b2Ag2oI
vI4c3FItVZmA4O8CiitJJ8YECoJ+g5oKLKdDfH9mGhJVG2mbK2QRFKqw4nCk
CycSbAKSoRYbwZFCi8r/01vRXXnTW0eBsI7+5UnieCbqpsKoeAw/5HIZ/G/0
12RTeS8uUOWF4UJjBpoUef+o2oRkbwzhl/bw69IEB8458PQEeG8Fcz2B+Y2l
uWTsklqXICx04dwcMhUWGaffYuhug1Pj4KDnnb+k79l+PiQ6zo4FtIKPMcGd
uwZ5eCkvBuOzJ49o5iUkiES+RoEZIwSKDvaUUBN2Z72vQVHdEhvUO1iAf0Lu
wM8zUKx/yZZRw9tZBgWRG2H1BJoyjxAMSiaFIpqFTz81mOvg7SCdNfLENcb2
GCSA6oXfp346PPj/AdgBBJ5EMwEA

-->

</rfc>
