<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-50" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-50"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Stevens Institute of Technology</organization>
      <address>
        <postal>
          <city>New York</city>
          <country>USA</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <date year="2026" month="September" day="29"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 331?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 335?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against implementations of early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 13 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.8</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">8</td>
              <td align="left">3</td>
            </tr>
            <tr>
              <td align="left">8.2</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">3</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">4</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.5</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">3</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">5.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.4</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.2</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">3.7</td>
              <td align="left">Low</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <t>The vulnerabilities cover the broader ecosystem, including but not limited to attestation, authentication, authorization, key storage, parsing and resource handling inside the runtime. Any vulnerability in the whole system, and not just attestation, breaks security of the overall system. The key take away is that early attestation adds unnecessary complexity to the complexity of an already complex system.</t>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">7.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">6.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">7.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-f96w-jjf8-xpw3">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">3.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100835"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.ritz-seat-facts"/> archived</td>
            <td align="left">2 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100835"/> published  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87851"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <section anchor="edgeless-systems-cve-2026-100835">
        <name>Edgeless Systems (CVE-2026-100835)</name>
        <ul spacing="normal">
          <li>
            <t><eref target="https://radar.offseq.com/threat/contrast-before-1160-is-susceptible-to-remote-attestation-relay-attacks-cve-2026-100835-3833ee713219f7e3">Threat radar</eref></t>
          </li>
          <li>
            <t><eref target="https://buttondown.com/vulnfeed/archive/vulnfeed-2-critical-cves-2026-09-27-0400-utc/">vulnfeed</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ervik.as/cves/CVE-2026-100835">ervik</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
        <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of EarlyAttestationBleed."</t>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="security-researchers">
          <name>Security Researchers</name>
          <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
            </li>
          </ul>
        </section>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.
We also sincerely thank the author of <xref target="I-D.ritz-seat-facts"/> for archiving the draft.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414897198_Presentation_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100835" target="https://www.cve.org/CVERecord?id=CVE-2026-100835">
          <front>
            <title>Contrast before 1.16.0 Remote Attestation Relay Attack</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87851" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87851">
          <front>
            <title>EUVD-2026-87851</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1129?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y9WXPrSLIw9q5fgeiO9hxpBO7rGY+7uUmkJEqUSK0nvuAB
gSIJEQuFhYvm9A2/+MER/gMO2xF+cXx/Yp48L/4d95c4MwsAAYqChLPd6Xun
WwRQWVlZWZlZlVmZoijuOaqjsY/CLy3J0tZCzXGY7UiOahpCwzRsVWEWU4Qb
Zq2FtmTpY1cTPjRuWmIukyuJ1Vw5kxXMsdC46feFaip7KETe5V55l8+XquXg
XTlVPBQkQxHy8MyZMgs/tPG1OxccU2CrOZMdwIK+zmZSGXghm7pqTPZ/2ZNG
I4st3hqAh/sve7LksIlprT8KqjE29/YUUzYkHQigWNLYEVXDsSRxCtjYU2nG
xLGkamIxs2e7I121bYDqrOfwdac1OBKEXwVJs03oWzUUNmfwL8P55VD4hSmq
Y1qqpOGPTq0O/zEt+OtqcPTLnuHqI2Z93FMAk497MuDIDNu1PwpjAMb2YCj5
PQBsMemjULtq1faWpjWbWKY7/yj0W7XB3oyt4ZHycU8QhVpHkCbQq40/OlHk
BWlDC3zNCbT1MDonkSc0uy+e5PYWzHAB818FwcPq9hh/cMLcArIwMcIxvsLH
OlAQP/mDrSR9rrEUzBw+lyx5+lGYOs7c/phOh16mARyAVp2pOwLS6u5U0nVJ
EV1b0iXRlixFstK75ukXaKZJODpo5gPe2TzFoadUcyeg9Ou8kJo6OnS0J7nO
1LRwCqBTQQDW0jgb/dL1OhSusUOhTx3+Ql+Z1kQy1Gei/UdhwOSpocqSJlwb
6oJZtuqskembFrOBkaiFz9yD68hjGT79GH1iuoAtPDxmli4Za++hAhhlstlK
mX4zPhc+SYZEkhQnyR+OKyocYEphO8Z1o0rylNmatBCa7oitZ+auQTVMi90y
acHCHf6CraQ/FN4M5/iXHR2cMMkQu5KlMuFEkp9c5uzqIEqrc0l3rRBJQr99
gtSZNlFdPYLPI3alY1epR97VH66BTVMjtgu1vmlMRqZQd3dh1HcYrAgbVp8N
stR1GCJGk2tq5mQdxo4thXtYH1EEr/u1CHIjzWWKOTGg+z8m+Ow1gjWmzJis
VENou5Ix2YVaZyOWIl1IroUywHq7j7ZkLpkhIAF2jh1Wx2QqqcIxoCDUDOhx
bAIDkvjd0ADYInUonDlKKjr0xlQ1pAhmU2AUI5vLFDPFQiEetVNpLQktS1YB
h524LVVHnobI/+Baqv/AxwA/emaWBos8gscMgKcYB/6HTZBS8nQXGk1LOHVH
qiaB7pnqzBFO//XPf/33f/1zxnFSDRtXako4TQm1VPByB77N3lTVhIsVEFAJ
sXkELcVKzVzZnf1h0meS5uqGmgI4O7l2rS0kYA9YARoAsNhOKiErTE1HOJNG
dpQ2J9JcMqLreESg4ueltZCERkropoRbFb+2Q4RopaKv3sGzATrnDG0DnCk7
ghRbSHJKTy05xD/mlumYRkrfuZBPXFijhtBs9fut8/NWX+jXOueD1vkbiwfF
2ty0QLcIV6o9I8PC1RzJR5HYqwfyZIuCR5ZkyFFRqDAb9L3B7KENc+Mw4w/d
Nl4jZVcCk0NXNVUyQPpY6gTWi6LuQrbX7ogX3dZxLYRQX8K5N5jCHLCiFKYJ
AwvsFzOKY8eRtCiTzaeqqbOJlLLgE1Vn8dPdVWfMkqbCpQvDWRtMbJiaBpO9
C8u2ZE8bminNgLgymXx9xxyPATPkPny4JR8kQ1KiAkLn3f0xBVAygnoNrw6o
QaEvTy1Tnu3CpdXtnHVqQg/ZRTa1Q+w9FenKYZL+ByPyz72vUpK6q68aqFNL
AiGo7eqprlpoq4LSFRqot7bW9kYRnEaFNAFNTVztj5HspoDJXRjInsHl6wIs
MGHb4kuhifKRoPhm/a4vQhY8WX37MDPAW6INisxCDOE1rFfPlgbreXDW5wMj
m1U4cQ0mYPND3pVkTZizseWWy2UKhApDC28CDVIGc9Jzd6SBsYMUSRcylVy2
mq3khlvYIXLDKG7DCGb4cqgaQx+zIWDGDSXfHqN/RC5tQM5cpzwLLPrmJuUb
MdHnJyK08ayPV8grWmxu/gwag63+Oo09AxbN5XcZyITTD6RUdLAe9GhXtCw+
4pf8gUe9htkw+96uhJNBUG1h4WoGrPORxnAHaDFUr/CNJM/gnSrBnhCGR5tC
Np8yHT7VqCnsjWwP/A6ulBcMlWUacLhiMijQ31Xl79s7oM0c5EpCF5mY5gFe
tK5vmvzTbKlQqcSNsnXe8cy6nz1O5i6UFDNUG+wX1zLn+J80/U5v4R831Ogm
MNl8yqaN+9Ldu1F/6Ljb00G1clPxBSVsRpttETbdI9R5sKP0yQKGD8JGdda8
E3A1jVVmCXPJmX7tzHs73Q05shWhz+bOTmrkfjg1ZNBckiwjAq2FCgaIzAQw
QaeCoYKeYvrcWdOBgqmrDoJAiWQ5TcmRUKKAlSTUuk2h37oR++e9byZMLoYw
G46q5LPVQrIVsdX4G9g51P4daMZO4Fto5r4RzThqHrf7NZE4Rqx1oirm+0uP
sLLJ5aOrP1bfgOFrSQvV1Jhj2WkZ0U3bTHZRq6UlZaHaJmys7TSNZjGeTER9
sVqJ+mRSfl0BXW+ABmtmmyK5bZJ4S0v9+YImTLxsSai5E9hYfH/qFearvLh8
zK3E1arwjdTLfwfqfX/B9LMIaZWADeeFiviYs5ZfR8iWMmEacIvYXwN9dDtK
zyumm07kyBV5zXZtpJa6a4WGh55g3MxDw17jqHHybOf1gU8fJ7L4KBcX4nhZ
nr4+cH9wgje41wa9tQaPGS4lnOq5CeY9dCsopvEXB3abDpMdQdI04CFpwoAS
I348BpT5OUPXc08TcWmtFuK0Uq18+9C3FlBrpeJZwkToMnsqNGooVGmByJYJ
wGD3qY6BFYQRbO8UPGoE0gCi0KDhoS7MGYgTC7QuyJZ1mCaoFBh6CX4AWayV
vBDn+TlI5Lyc/3ayFKJkOTcVhgAcmHrAX8OzYJuW/tSEISN+kgpMo+CfY3Xi
WnyxLE1LU2C6VIck84dMqVTaP0QGMpdINM3Ek/K5pS5UjQE/MRt+U9OfRbh8
uaSL03x5CdJk8ZSIcOi2EX29o2oAXeSicVuG0Cmip35U44XRGHZuoXZqIAnx
gEoF2tTQD6TKKNO9niPCNQu7NSNmR4mnDmgDqGAQqswZk1WID9K6PQGqSE56
lWeXq6PHy6OTM5lJrKQVhueTO0O3m/fpd+8tiZY9mEcJyC5asPa1LVHqvxSu
aiIqIXmKvGTApOvIXIqqCIYJCwvUdUTeMl8lgaRFhsO2nnoPUyKfkEt8dNIc
19cZ5LH0tBALeZC1VsGz83YSxAf4ghgT8xVCHJs43bOP/24UmZivU6P8OF6K
xbyli/Pp9GuowcxFlBwwEg2kiQjmzEK1HFfSdhBEZpYDdhq6eW1hySzGKYNC
+EdR4SVer1NlXhzPxUm1MIF/6dWvoor+KlV01VD/7UiCSMUYZtUnHczcRzBz
c3LpK+hhOXKUHiAwYZWKsqaiW3wHOQJDnluyYLs8uSaS5odTJYra60QpPlmy
uKiUC6K+Wqy+jiiiIr0iTL7pXKbJj65Nw1dTYcKUfjRh5rgVKi5BzI6nxZj9
UCxhHNn9EZQZXDQGF9f/JWSZTCpPoj6eTsF+suT3k8XfGhZ2bQ1/HJvkigkJ
kuzEoahXgEdWsIIeJ/Nv2zMXX9kz/yBG+bGEmUyXC3FhzXNirlouJiZMpyk2
LNVW0Z190UllM6lstlBM58vlai5TSeXLlWKe4kyCD3d5SshYRe8HfYE2bsSG
bZj63MVd1UfhCP1cYNUakrbGT83xq76Sc9hA+TQrvukvaTQaYsiQTlPAgiba
cyaLqiLKhNm7zdnom64JNqI0lqIvBinY5Vr40GJjwD1EwUw13e+lcplsOUXT
DW/Fq1qUaMATEvmeR64DDDQhPzjGrzlsgrsn2B1ZO04fDOS13U6lV4iE58Gu
zQx1RcY/btDAWgD7MS05cq6YnqNXz+Pr9JKpxtTUlNcp1ZAsmC1DuA1/+Q46
dkzD/f/+D6GrgsqGfUb05T2MH/bbTfjXHNYfi75tS+haFwa2PDXHMJDJVmPJ
Asr0p2wMA9uao6mpSzZwnW3D+LZQVcF6YJpwZarOs00hJA1YUKzeO4rOVLcz
uGr9xaZAnyNL0tmSrPY+LUmYJjQqsJVwJq2BXe9N10Jx0qQ4A1u4iJgZ1fcI
A1kzXcVf8mDhqBhwQLM30sxJGtulgcfg/3XVsZhoiwZbimMfN9H2UBMBNZGN
5mNRQ9TENaAmSqrIQyBs0TRi5hlx8AYJS7vmYQEfET1EPO9QDReWRnjdRSkX
UMvf13otBO9cLdRw68gwcJS+ytI0cqIJjN0WAWd1MgV9GnZJbygib7Dlq0qM
REy+Kha8qd8tzviEg+QK7+CjoZICj88MfVDXGFO2Dp12fgLMazGGMtXBeMKN
j/kmdOSAB1B+xO1//q//j1BNZV4XvxGtlN1ixK/1+oO6yFWz1epw5yiGNIjh
i0EMtwYxNMdDHMSwmsFIgDD+wwD/rxHfQZDfXsjhl81kKvliMo+fd7o3YsDK
TMimsiUg9Us+FsLHPR6IxA46jh9v7U1X+TXXF2joWE9urOsLG+9G8n2ur037
HWjuqX7YoBfWIjZTYy6JRTx5EhlyTHghvu8rMVPY/hAN6sgXpTe/qL71RTbj
fwEM+8xxGUsy7D73UqnU3p4oioI0sskXt7c3ACVAAcaCpOo2WoRzy8SDGsEJ
IoIV5kiqRgv2H/+IBij8+echPNty5fOHUX/29ofkJN3xYW7Xh/CQ4rNoFQJC
x6rTdkchIR8Yl8IHtC7tfWE5BTUZjIXO+yUuVjbjCg6kYGBTcymw7ZB0YUzj
BsE0R2qpMjsUMLxWODhAR5MJFtB8CvYgAsP9u20fHPjbdYXZKspYXZKnqsHQ
GrMYnq0fCraKnW5E+7afZkJ+DA1wsdiTS1CASp6OB1L84x9xqgwJ+HIkkgIq
/eDABYsE8ZSsNSCAe4MVEPDgICUgI4DEBCPexnB/YQRyADoerWk0viyFvnfF
F/FJ4+aiN4G7pKo3jQhQwlMg5MpXIJK5Dt8D7RECE80xWQXQTuA2MoDyjHHH
xIi5nmXe4GHKoeCCJQamzBxDxMUciDuQ+sywGWlzgGuZiiur/Oj7EN3S8DL4
iQhawBlsyf+eSgsgBmPoa5wZ5lLDc/oQXTS2AMZCJGcM7UrYaaaEhmuBqepo
AA/NY0YUPThwlmZwm2RzEcU0GMVfRW6g4ENkZXwKylHEiybRp963lUNaFgY9
t0MvChz/F01KqbxAmtCewjikiYT+ERrMyDIlpNxL7iGnEHmjNU0gm4x6IgsS
9mR0wO/dj6HJnc99RRtiLc5Ac2lOrckDa3PKyD65BKbSlRs+g5trLujGHTFE
AKx+2H8A4jiXmw94Jxum4sgBeK87jMcFCAIwGDYmNzFiCmtAdw2UId+JaVJC
XbIZkl1AexqNOPIbQQvyVCMLRPfkhOxLkof4jvtBlENCG4T10iC/tg6TQqeD
c9N2dl+0SQkdjkewVmJX26HH0zrwBO0Q3ossqJRtR9PG9EDidEGF/IVOK+BT
3kHoICIFuzJyPerQkSLArs8iVSTDZGFgK/DFQtJc3HUCgipMPO/D02a6qiga
29v7lY5CcJ7IOgaYY9VCzybfKXJ2XYHSQM0OzIMhrXRxY7McaBGlaY36K2OH
LOUyDP8QcGHgvPvLIeBznHl0NUqOoDHvENe00T1i89XEEP1ffxVaAUb9DUae
ABH60KVrczXNfZEjpoGq8obEfZne8iFB6do7BkQYRwb1rlmlVUKOUUsHUIC3
hUj3fYMe2GnkM/snMNcGiAG6l0HrMcdSZfu/ffDtMgPMMrDCnNTEXKRx5kXv
k7S8sO194G2Sk3SfTvVctLAxQp81sLdNMQsRnyVHJwVS9QjWAh51Aa/wA4JD
oQ2DcUaocoQl7KN9sYrCqE+jwAFn87CEoM9tYkH3a4ZnGygwNsNHGvpiBLQp
PMHrXRaPJUGUiZP39r7w7r4IAZ2+COd0yw477W11tvsdzdWXvS/A3ZH/AXBf
GUBLf3cCf2bhf6LA31def5WNvsIv8/SqksrB3xgTHGlRJmDe41zocXn34+Lm
cZ4DoseFzeNC8HWJvu4yRXX1SKeooEIv8sGLYvTFpkWBetj5Irf7RZ5GcAYr
afP0Hx/5TuPvv0QnIs1nCvXAdnjSB2km8YWzH145v/xJK3uXpN17zYDaLGnJ
NwBRj4JKBmECvEgS/JkE4HvRQPMXFo+k2YewOCawLklAA6fBYiM9C/9akwbG
pe4FRcG6mpNJjHEC6KmykMth8IbppIQjy9QBQ/+QR0DtihdiQX5x88STgxh/
ojBZtbkZLTumZfsLWwbEVYXOEL0gNx1scgnEgw7r09R3PLfDWO7GkIwdHBX/
lrCNGgX4WFpgZAFKEwAUb3p+s0Uwdi2isq8TuLwPTqT3asIBt8FJEFvrA26t
IFr+N2G+oJn3j6zl4Mga3ovU3e7YOc8OQEps283w/9vkiJyWfw8aRB55Cm/X
1mDv9S1DaGG8tPz5+TNXVcDjFneQCggkMFF9uzYSjBCYrYilr5RRUdPplfzi
9GqxdXoF9HqPEv0IJspOJwYCwEhOjDv0Nl7I8TQN21vn8H4hBlw4lDEWZO4F
yNetN+QwP5puC+bumLwIbK6r0DTr7bCxUOT+CqJElC28pG4Lf3JLZ5vWNDfR
LYo/fYeAiqy5JC3QI4Fuc03VVYfbXKGZOKRzJopKCv02Le9m1CGJLBvklDQB
UQabDJs2PGTZ22BDw5Yd15bGh2/TEQkafPxaWkqoGestC8UTqEvYFjLBRxcB
IpKPGGcYQW9kMQlMxkC0etxr0pmH5gHgKxlRdWiNL6U1F6vSTksVd/279/z+
Xi30BDrEkFoN8FCCT/1+0bDBmcOJEwIb5whzDVgvbBX41mMP33kJXOGbEzvv
pB8KL690c2K9vIktcPjbJ1GCb4F8rw5eHGt99x52riCvn8Jr/Qg7yJujRtzA
292I7jf6h8q7QOS/HsQuGRCxVGHsM3SfuMr6b0IoPQWw62gdgklbxbfGvBWu
9xbau6fl5ZQcvj6+UEzcz+yNmYuf253+M7uzHPkndycqUpK1tR2nQ229zUlM
2xfKO/mieqGsk4N4cdL+zTC+Bo9PPFY5l1uIq+X4USzlZX1zJvBNsXpRoPuC
v/MNEDgUoikpDmOkSwhZvTqvivnpai4WHkuP3wnZKND9gI7fiux8LhfE8aRY
Elf5avk7IRsFui/4W/VvRbb0WCiLMFfA1vKk9J2QjQJFZPlRxrciWygXi6I1
LcliqVr4XmwQBbofiKJvpuy48iRWKvpClCsL63tRNgJ0P5B934rs09NTXizJ
MG2lSmHxnZCNAt0PDLVvRXa1skriMlfMiYXJZPWdkI0C/X7IjnVrJY4fn5Zi
vjyZfydko0A5suXvgWy1tBQfH8cVcTVf5r8XshGgiGzxu/Ds+AmIkF/KOGOF
6vdCNgIUkS18F2mgWxNLzBdkWRzLk8r30mARoIhs/ruwwfJpXBUfx7oujkuV
7yUNokA5Zb9NKbyy0cl79iRRgo0k21FhB32y1iRjpsY1LIT2w9uohLB8H1ZB
5PTX7ByLSc1aHuTzpjH4woTEmJt3tNqcwod8cQnO3vnJq3csAUT9YJnuZIof
YfYdygBG3g/TUrjXxXP/4LGOKPJzDe7pEnTYtfrO4gM6PZ5bDA+XDMla0xn/
7iN+POS88PyCe+848Hc2Z7N4ls5vx/hDkUIhx28cnnM6+Y9VI+5EmPvPPXed
dwRGzyLR436mIfsjHv+cmymYuPp2t/DsGr2A0OEXoRactiMDZLFBg24M/Of/
/L/bBNMwMfqFXC7CpxFNVHbnun9/Kpm0YzGGdwaNtAdwn7rPbXUfHv8ONHLf
G43cvudsgj54vku2wouWwHiRjnerv2/oOL/vub9ILlnAizR+HgBJp4eR/gvf
u//CvuewQ/qbOjzkRAce/jVHbP1rPopC8XujUNz3nImvo4By8tOrJ987EdoO
19cZw/NwGwOcR7x7Hb3CqqTZaX7qhYdeKf9CryjRHRpQo2HvzFwZ7/9N+BSc
5S8yKdjFbBDAyEvbsEXVwSOv0oRQWc4pOhh4O+3ONVNSbAywLqazufQtw+Fa
Yg0jR/DqO8ZUD7Ct2Lg4P+o0W+eDTu2sdOz1DF03GpFo0H7n+D3j3/8LLCrF
pHtrICse8Zb9pxipsxPmFjXSvgSiyMa5KSNpNvEj7lyhK/4oKTfgJDWlwycE
j+DIon9qn8Zr2hhBBgjiMTjFl/sxgOISCURut/0NM+7enH4DM5b2PU/4LmY8
hMVwuOFI0BexEaKkQz1Ed2/5vwFR3O6HVPALWW8fvvB6IeJ+7N3G2Yrq8T/+
4z8wCMcPwgzcd/AABg7/rxphZwc6OSh6bGQuQnpub4eeo7av6zbX9u437L2I
HcRYwRC6huI5yRE9XXXUyUYTYvuQYzBAdcs7lRIuXFSlsMwxBozByufuGNUB
C2K9Rxc52SaKBb1SsCwZhiA5YJFMwuFyIgxqDPpf+KDBB5qQ3w+GzwcVN2xJ
MzHQdIDRKJj7YYThTiAa0Bm2xx22oYwffsgNunzoCWglHUCin5Vf8vOzq0ib
u9t7Y+7/V9QxBds4m/jWvudP4k2hf2/gtmuxgCAgsQwQEvYeUAEdfn6UrE1K
KkUss7dH0WD2HBNmj0Bp4iRops145OgLH1scSTDWme7ScvvkpVNKtW0X3sF3
nj9swQzFtIg6GEHMXZ689S6fUyhok3u3u6bCyEd4QY5pfwV1A+blLs5oVMKT
C3MkjNEPhywypug+JWoI4qAQEvS4oX7c2Hesm9FasHH9rjFqwpjgW+Qq6PIz
yAhH+ox+TwkkqR/XxDzziZ/t0iQJnhxFzj+igFfhkzSZYICJw76fPApA7vtp
OmySEF4cjBJeu8qusb4a3wGzRqmWNNRWmJiKxx3yMbqG9yvlTeCYx/T6SFCM
i2+l74hfIR6gDBtk8IWVZTjYPirkd98XIO6kxcdjKLi+wDlBiSrhygjd5fzA
49O8ANH9nf28vCoAfQSxsDBSL70Jxn1SiCZxCUgEb9X78nsT8wP7ArDx66Q7
hCksNYpY9XT0HtjfF3PsCRu9GqSKPOdsGvPYOi6uIrediHx+rCNXV94kv4eU
iuldqp+jkAYI0QRlku1Faqv4lXBw4EUKg9S3mHNw4C8H3i/F1QKiKuHvSY4X
4TWvMyDGbLNQxDzfeVkTV6cN4XK6FiL9E1aBE58uaewYBDBf7w0qg0La3faQ
3+fEqFYcy8GBPzoYUfiiwFuqV8V4A4xtwKwGCi4Hug8G0p8EIw9k5Q8wW4iG
DVBJYRoeErJ9JqfAas/y2yavrF8ujeDDgvfZJl4KuqyztYnCAWnBQ+kINY1J
M0z+BC0+o03YOv2Mq9ovyhA7XRQYB4IRJh3vklMohTT3lRBSFfMtM75QsBEm
svZTLOF+K4QHTDXDOOX5mptGuLLhs5TQ0yQHmSjMuZQdj8eemtYMzXyy+i1Y
q94enT7AqGBcuCYqS1ATINngeXj0iokrGgs7YP+8wMEh5XwNJUHDYd40Wqc4
K0AVjDonBz28wijYJeoqGiLo/LnoGuqTyzwW5UhKwqBRF7zr9qRDMfTFu7bD
y2nMvVFu2lmBREWxDjuw/tX5sY87U/6GKPgbqMPN3GF/SIAPrcZ+s90SPDtf
wFBxxsE66zla+VpAfz4e2xw7NBYvGjwa0SOHLyHedDfWpDBxMR75oo9TKFvr
uWNOLGkOdoKoqSMLmcICpIA8eN/IC9c54kGAGGl8GND581Wrd3E1GDZrg9pn
npoNbcDNvRLeE4/qk/103wq/Rk28qE5wvYQZhedwEvyLSfy6BF7LtmDBOy8n
8m/E/AxmkF9UAbKpyiaTHmXX2wRMoX3sazsicNARxyG4UBzibGZIFI0d4kKy
HWBZMLrBwFayBtRdcOvYC93zz7lMi9uACr/2wecWmJpHQH0+a51+4Jyw/zm8
Fm1ASlO4MKcrj1gUBdBCISbBNn+OoWYyj6XnMYyMSLu1SGXJtTnNFDbG6DcQ
mN7YDsHGNZH62JzWoYiXpYTmVf2YX1Y6xEZcQW54Db72Sc+vb0gYVYfXv6JS
4JNnYxbFUg7+L3oKIOkKTxZmpP39rZ3mUZiOGJyHj1zAykEjSldEeySWM8Ui
1QrZ9zdjZOSbBi5AhtnhXLRFYVosfuMaRBhYvVxCfxRgR8JL3qCoeAANUfRt
QJMMI6Q3AHIttMVtd+zRSwuWg7ciueRgFtlRn6+a/Var+ZnUpu1JCmJ2CzrT
1sTiElnStkt367ydTaDIkfPp6JYUFMBGAexxD2Aq9nsisT+qMBIplAxyjNHL
vv0WHDW8TJXBFaLCdFgkjkXZivgmRoEdnsgHZuC5ETCVq8/5XhgXDeXb5rc0
PFuNjlD5tam/bfjBD4KiyEoY4hRF3wU86/fP/mILn0URVxj1BDPLlL9bijx3
PwsfPnkfCXnYc2SEznl/UDs7S+nKTuPbhI9tWwv+SwdV3g+RIKQ3EPb3/X0P
jgRWwGaagHbw91XtHP4mGd1DiiJiMGtzFwSzqsFiJlIBiYPtLpro0sQ3QcDU
JC4A40bhEtiTFzRTwISMLv74us5XcKGVyS3sM3MpntEOuQu7Z29bhOTmp3ie
sbF3hCn9mJCLNSZCS2LQaonSxADDAZjDnzmRtuJ7/p1ZCqfGOyeSAHPMXwr8
vuCWFU0yRpfmtnes4d25RW4F+UEn/yYFUfuJLEBcbFK8ovAP6+atcxcKyITx
pWB0jL/wrk9/CQF55z9fIj29rwl0L+74R9j9OO6fr2oC3R8c9Pzbt11+CgH2
6Rcct0gKQfPJGZgcr43eG3nQDKkR24h332gENhv07MFq9K6F9q3wV6I/8KEL
8P66lQxljKaM5ZLIDTfhYiuNk/CBGxD7G8Prr8JVF961bvwzF7A3OB6XrkkK
mJIuckyQDMJlK2a6oSMhTRZBGLcPN91Ql7tHHbWP/JGHoNNRs9Aki1P4MGju
v8lMWK/EoSsdgM+2ARbflHA6Zw7l67BxM+NTwIcZmG1/JXni22qeyQd0eh2d
+KaILP9iC512v5se9CKk+cKvq7OtxbqTGO//lHoji7h2+jnU3ZfIaT5KUCwD
BRzhcUqLu9K3+kXTP30DlhUpX3/r8ibxfYs80v+tJ8LTuMclam2yfu+E+jVN
Nt2fDcL949UuOuaH5Yst8dLQGyT9miahk/ItNeQLey963tvrvhT3IEG25Pov
3h0IxMF3JaFRuzT8I4gANgfKt3423/sF54IRoHt0fkiL0tsG+heCoroqYhyG
ze+oouOXHH0tlg5PzRfhyjXstKZinl06X/59J98Ig/X8hXjZ/eVVYGpRT95V
jNfUz3uVyft1zmtfEgooFFoN3H1Gke5wAWGExdKLkZ3HvI18eNFP+5LHs7s4
+33ZbIZ39x8vSb8IxyS8ApP0q1ConfrfRNTQpumRp038+J10oFlxPqcqrG9L
nqJLOjgACQx0v5Mu2OHWWgQIuO32ZdoXIaSB/e7anmmZDrQY7G8kzNmwPaag
JQwnfdo8EjZkjezPNy0aFvPPEDjp+j7pvgiUWN7fIsf8g3EU4TsQgQnsJfsg
WRMWLWfB4ttK5oerevcpDwqRHmzmYMr1nZTDYzqbX5Hy3mzzyl8w43EXlvre
r0KTEsBg5dWI76XJ/TIoIweqjl4Pxr2BPMygtsmXwY81gWo1fyt5w90sKEla
dBpJBGThi0TwCj1rqqESShuPEPM9QuRZMj2XDUDIlIULGXYiuHvmvBlFATEI
Ps4WYFxy6ONwtUDvmOUTVlbdbKvis1LDFNjp0mT0tMrc3Vdu7612vrsqLC4q
Rk50Tyf3afQw88zX1GuJh8F51EJ/mWvIhGdoz89GKb9H7Ax+Uxq1TC5XzpZg
W19IR/LlbW4GpiybZ11zGOOedDxCkdeARZgKubJwxEYhfIIghM21+JdeM+HT
wUFwvf3vQrtz3MYSUzwhyf7BwX9DyF4ZjzDsm9YuH9qmpzi4RR9u6QVcyhUV
AoNRZzvvb30l/E8bPopOT0xibswMI9nMTjvShIcg4FUSiuzI0hQEiV7J1UGN
dhHnHRhXKe3c1+I7MV/HtZjKihMzm8qVoLMXSE/Mr0Q4m3mBceOFJfR1sSJ4
6Vwjz8mnmHo074rt2Yadnruali5S8Gu2vD2Cm01vOwZDp7NfOSI//wvyZi6m
20QeP/IS4ozyS7CYiAJX7Bb0F8FRL4TCjsuLMQxQ8NfYC5Z9W+zkXq7fxlVn
0GnUzjz4VVhZHoP5xVsS9ZD/xh6SUyv3glwvOuR3KH26FV72yid8K9cb+shC
bLPJmRhqGKzlF2i+vGH5jjnNf20ndKnyR3bA71H+2B70H9wDvy357T0EXPHy
sjhsLz01hEbcO7JLYVz9t/Q2Mb9fT7GU4xc/30G80rd0wq+IRnvptpqd667X
TymVj+1nyzzy749uen2vbKq8F3zuO4J/0wjzL6L+hG7eIVff6GbHnP/Uy6zZ
6gu04vH6SfdWd+AVi9ZPuqGaFK2fdBc1KVo/6dZpYmr9nPulSdH6STdJk6L1
k+6MJkXrJ90OTYzWD7kH+u1o/Zwbn0nR+kl3O5Oi9ZNucb6CVvJ9F7+3mdtt
UyYHV4gD9/a+s/DGyVSway5+ZQfFlx10L5qtq9qg9cI0fa2TqPEYXAIN+vx/
/+/3WlxesvXkhh2/QfqNHW3O1YNT7eiNgvDZcvhUW9o6zsYzdnQ8q34mRS+j
p8GvjvAcnpTFVzLWm2iftbCcSo5tIv5eFuRwFGokNpZCsz/fMmnWluzp50P+
d7P9mQLIPtclpcXPmD6nDg7Qo7cWMAV1xLtADknTxljPFEsdejD7dPOEoNLg
vAcAmo9V02B3Ziq+79P2Uy9KwgTrQ1Bcb+vaS9K/18JM+0wyhGsDNmt/sYVP
9GIjB3Zm5Z+aOptLE7ZPsd/RrFBhVn55jEtj8M8U+YWaYG54MtbIlHInBjos
MUjXT2zLw/u3i1K8WoRCOFMd9LIAX2zS1i1ABniXhYEbYhLjJs2HSy7WqLeF
r8Eg89onv7d3w9xO0ub5WD4tVQtWwpzCoUKeh9DT9BjWiR08wkuD3I2FGH34
REE20ThFDOfS+Pmmd0cRnqZdlP6BwBdlhkFf6bDnI00Ng0hGMfyOB0VmM2Ku
ImYyWS+gEdn1U63b/B5xkvlMIROA3XSMpKO7qud4+YNoNmi1tujlMBamFV0p
3KLUNpBm88oMGWKKgiuDDqhxedDP/0pal8RMRcxmfxytK++kdfNOMZchf4Ci
pSRZJ3+YYqrpoPhXqVgpFQqpfKmayeUzdJ/zJ5KrgKyZCbMmXkAvCl6aYRxJ
35E05oakwEqWRP/yhmcrqSZeYMXP/P8OeRWsXMlnhk2EcLFQzFSjw4ur0OI1
4AkxKC+flxkZkatj+smjWn/wFnqUp3KM1YmDv4amNNOAO3bhWMpWy7kkOGKD
/e3czYShpFzVuhtQI0mxJB3XivcX9v3lO3Jo1oua3k49/aPJlU1KriyhWN1C
8UgagfSfMeUtFMf+h5u/4pkum3kHhvAw1GAnhrsicqOQ44s4ZSq5bDVbyQ23
ACGcYdQzOcQE5Js6TvASCzb5RfyGg7P+vhCbVZQnMOdZTV7JVByb/m+Tdz0Z
jNzXwXhfYs4QwI1hvG0p8Xs7OxIgR0JG5MBS0gJLyQ9mkzcQgwA5vOS9MeR4
8ZCDA8QLbFm6pLTDZ6B4hYP9+8QqvwqgU2+Utp93xYKyuRaG6QR3SnbiS/FX
/AY+3pwOipGE0pkvGd6MxtTCBi+GHil9QuYw1vcho39vz7vz8+JGINq52ga1
Tfjd3HR8ezNpupsPG3x5sm5ehyRIa823Mvsf3ypMsKvkwN7r5QY+bAoj0B2Z
BdNMvBfKEx3sKkKwh6n5QnUD/OIAlfCjeLCRAgNF71GouEBV+FAUYiFs1RYo
R/i+tZrz4KTEkxBDecFbA16pm1AGIbzAourEzkB/vo04JHYeq3hnRbK9W15e
pYuBn6wfmsH+LNwnMWAoFKATjSnd26vZ4asssZcdCf83ysRQURPJKxu0YeNt
cr1IFWGx0JVlSo2+yezxfZN5fNwlyvnIXu4n3wpZQTyT5Ylh3td44OVfXSSc
vjZoYm+vMxbWpsuLGPALZWM6WeDSOfZO7tbFpjlF+wiYPt61Bdw5C7bJReqS
X/yTp0ye+bnPX+RheJGGQeW3duCxdwG+5vl9012eUgM47gVLDhKxDlWKD0X0
SJHSXAcHvqcZbyiHSiMdHKBT+eBgN2U4B/5b5775+FMCmpCaYRoSWfxjxf/x
7y8SEsVXfd4wepKQwcPvuWL/BsPR1QkJO16TLya4gNfjgzGCssORB8fcXjgE
ECAcFJdLZeJPuHmzDRWSh9McRjmap9jxkPKHFT8oGodq8SYTc3sMeVDrfmDf
W+GBOwbyrpCd7zCIqFbr+Vcp++EsefZebbc2Cm5eRpLq8aPMWHl5gPcUD7a0
FWL6fgYlyfJGJqcqfCbYa32E5TV2JUX623uC+XgpSgrnQyKPHRYcP79A4bXk
GCE0cDwfSIWKePF0zgyRjjL3PXtZ8tN57Mjh9MG01AmaLqgr0HhGE0rMFPiR
Ml1wt/l1bKClmCnt72G5WyxPxiv53B5TkgpVVudYUnFu4omLIph4udTTWZjJ
h2uqEei9JBLDz98ikQ3PZ3NbRhHgTbaZ0JeU0SVyqCzy+/YvWpEjIE/XXpmF
RJHHKQBAx8WmZcHSkVAE7PNmdFjNAzeDe804VfZ4nSLqUDmkKGFs/0I0L43n
V+HZmR4Jkx1g7VPVcYMr+hYWnPYu8WMuDC/zj1/+aeqXV8StC/dDxNdJita4
I87juNfoqiMHZMH00QX3oFqJn8GFD/rgQFH5xW/gYj/1BE87AzbOK+lYfNrx
7g4Orl+pboqdqI7NtHG4dBXef2eWEaySFyGU8auT+kTFRxZ8eMrVaM1F+vCV
IiyxiIH089NH0V1nG3PtNNtbqWE+fJ6s1p/3+X0O2GBG346Ys0QLSd6kceK5
tjA5TzsQf37aMbwb8uHz1LFlHyLtxDeXR7BUbtBKxwFNmL2XTwm1TRKzLWhS
LLRQ8jMsxizt7fX4UscMOV4ymPj72wjTK1FM+6CgLHCPTwiVBW7gfTaNd3OM
S3B/48UJlqXwJ6Ye871xdLnLy3kl4W2YQd+zE9GdyK/JIzPzHCOvn4ekKEdS
GAEYTZBnA71XOKl9Pm19b1KPs/s4QzGtQnlNN/M48Ch/ipQ/zu3jzLwPRnj+
olDy+7vmJJ9oTrooeq94eWFUjbVwJq9d1d68MsHRa4g7Cm7F5sN7ocC30iWJ
21lZp0yb20F6Pn7pKuvjh9/jhaQg6dgmA+6udrlwuw5PvRSTC9DL9/dWQjvK
8bfJvbJJ0hRKQ0HOw54vjWL/+bJJTCf8mj3MHRYOS9GH+cPiIZ7a9F6OGg9U
PopifA+Rzryv/T+C/wKg46zwMY5VScpBi//8v/43D9h//p//S/QPhJJ7A8pM
nm5B4X9FoeTfhPJZeAWK90fkajBGVnPep4t5W2upnMoSv3vJKorvXVgkPYPM
X1RJ1ju/ChZafNbmUK7mTVu/BvhuZ3FcQucflsw5vf9DoWvmJOWsnPenjP5h
6aLDA/0B0CMD3Z2U+oclpA4P7QdAjwwtNu31D0t5HR7hD4AeGeFbibV/WFLt
8CB/APTIIN9M3f2jkjWHB/kDoEcG+a6U0D8s23N4pD8AemSklVTYioBu/erE
369fHyIf1g+EHxrYDvdRSNf/SufewdETTO4RV8Q2rwX8yktS83j33D8YARPy
lmq/k60Yc5ZJ9uFhkE/sE+2PxegB0GouhbwWuOnCfCIzZm0utSumnH6taXr/
kGcH3LJcQ+bugDteyXMPuEwmVI6Xtv2wyceN6HQ9slQ/gS9uvT7I0UUQawT7
2T13vt5/b0pYz9G18/YkpfRU8FR898797UyoYRudCsmuNzv8ETPYWI06q/+r
JzWFHOZVzo56mA4ONuW+vV0FnqnjbL6YxjBj0BdvDcvPFO41Qu7ZdlaO1nSe
Ejqj9PzpPDOnn839MJpvb+vU9zvwhMUooVV0Sxk9gCQi8qBfPOekLJgKJ8R7
EBAzhQgOb6LrnT/xkzt/kuCHaTE9iFOIntzSkV7qneLnrHba4uKnr+qY/AKH
BCPHHPwydEdf7ia58EmDCRct6d1ciY9Er1F6/70o4haEMHz7uF0IRQa/dqKP
fnbJmNHZKuco/4Y8Tevm7vzbZ/PIy1fAyM6We4HHUh8Q8JDH08a8uWtBwZTb
lunah55jCtBE9g8inA+9wJdQeMpUnUwpkw9GCiih6OmvCdoRPvDk1FsRzn/+
uc/zHlqMkkxhZteDgzZwpTPCuCMQCUsQTgcHGKWBfqCDgxSvAXGsLry00ogn
L1b/ZoH1Q/RFg7KgbOzKnndazkIRHfzyMKxIPHjH328I5O51f7DnWhMeLIMu
4nix61UjeIsJKdtRjv7Nfdr+y01tKS+kJM0vCPBQJwqq+eAlA/MjMkK10NFF
gGm/vFCnmHGhyMX35ATgmdtwDYKSDSSCpdozD9uOIE28JOMMjyUo67A7R3Fs
hw+hwynta1u9+RU9/KoQGM3lUp0Igk2briAqw0+Ji+lUSYMFrbxUvd6hGHty
SdqTe26CRTcMP37fS7cJyK7JsQcsB2sz8g2Xt/wKAS4NHF5wMWODFWd8bO0V
f8eWaE0wS1cp/7Dti3lJ49E3QX589EYZCs/CzLxMoIdBP0GgBEeHoocwubW8
yQw7onmzVKAEU7h577fWmYTOEZA6HDqmROJpQyifU3Bi6OVt81ks4gWBj8nd
Inua188EjnBGlBiZp3qjUvH+ivTPXn0/QZixNtPrncYGFPBzNfv5blNCP3BJ
RV3r29mYR+hr4Em0JC7CKHssz2ztzSiJFpBFfPok4sxNWuENWjQSeO3zdEAt
HhrFxn4OZi9jOs9GH/Alv//DDfGBaWp49o8pb1/UjAkMj2BxBBYIlZP55Fsg
G02nMkalVyxMFMWYr+gov3+6WgFdU8zv+1VmtvTmpsgDr70WrSviB86E3HOA
NPc7fhqrKxT6PP06rxTi//ALHcSfL78rjoR3TknaRFUBgYWZ90PbJEzfKKUB
l33uwTPp0BymDZNdU8Y7Xm0BKW05PP4RcEKpOAYa0fKNVmd441DcXwYIO0X0
sTxrhwXuxmXIsYOVeZAZgXDIsFgNZOqla+bVJwLnKIEl9sFVG8oMhnrJNTwX
6yZD/L/fDHikRic+XmWLLqyNTPDKG7zElmYwUmHhMJAHoepIdDvlpTW1j5V1
uKuM87THBcECkgMVgEINv56TaOVZ+7fSb0emBycaAOh+vR15aqoy80oY4d5K
A9MkJO0COb5jjDhph9w6CeyRKAcuCU8eeekpiPh5hFV7Dpbfx8Bw9lPK/dtx
yO41SvYXly8G2LO9/ikPBNlYrKm9oxe88XFv738ibR1MC5rn2VT+MLIAAxih
i3JNFSQ8E9tM03RgTeQrwbtcOcYcgKj2mIbKHZ5rmjrHHN0gjxdoKwZpVble
8UpCeBnj8Toeo4T+iARubF0jssHlB8QYbL7ADH+4N9gSydZ2Pi/ue9lUyiTu
2kEklN63PLe94zERqEBD5XY9p++OZnzn8VKKBT5RzzE137i4sQKZyg3JQBgK
iklryz/BULUgzSTgE7BotCBVMEu83ChPqm97fvBNRQiigoGbJCC4H14QfY2b
FL/+D6DlsUIKb7PJmqTqPCJYlxTfguSxrLRDmbhWkOgc1N/Gl78XcuvHhjFb
zDuvwWBiv2zOVtNQ3RjujKu8KCgj6NwWs4m3wUZg+nwq2epzOBAptIYpaDZS
WoiKP4C1OeGOWhKeLpdnWGkJJ8qOoGsgvnzcG3Mlehv0iqKP9javo3E/XjEQ
rB8VsDQ/g9hJrBQ6qPFjKvjmxWmEbtpg21b/4qrT6NM9asLt1+3Ls3uBOzM+
3X6o7O1ml+A7NWkhBSmOOQ0xoERmQQnc7QJ8HJluUL3Px+OttP+xeGysMM/t
HYD3Q5y99bJXi5Ryewe9/cApbqbW5pIMhmYOtoNnIBYMm/GICdgFSkIDxSAY
t0GwisGWm7vGuIFfj4DxNnYp+uexIeA95ka65CX0wmSgE+afY/h6+5VQbjQ+
MaA5auqQpuCnFpaOFHpxRcdzRG/Hyn/YShywT4HXXmEoS1KkUFIZ+pkyx2Ob
PZFq41figzB6cUQ7CTGbLWVE1RZt10amxd2R6JhAWzxwiZzF0HL0r72J3rU0
HxUxD9Y4Y+VsPpetjsssv4+oIUnGLHxzDsw/xzTwIioh5X+Q9iJcgwdiTgzO
NqAr27tJWxVzZTFTyGRE15HT1AcWiJ5Fb7vRo5SEF7YZlb7eIhoRd9elLywz
/cptMCT1h2PY30rGvvCpEeEX4qYP0Str+xuUIsxFrJdSWDogIH0uUl5xGLdX
SwnozYyFapkGXecVM2JFzNGAEyCRS4YEkJyCOCU13F0DayTYbB+vyntdZbOF
KMEl48mVDHhMk+rNpZ0uF3LVLRinp2Ahr+1gDxjKCjxPLZm6Uo3UE2dYO53P
HmurJ6tkjttrbbC2nHPblS63sZLGDJY5bDz6vmG3A9RVy2n1e8bkjul9y8xM
HzsP69VyC1RTBVMQpMGtaYGBEUpkHItlpVRQlp27o2LnPlN4KquTgltfTrax
BFXFVLztgk4tsOi+EuSnI7A9DbB3Nu3H3hO616mo6CRKF7MV/rUm2VNQraGb
DTLWWqINfWrsv6WmTprkUGjJ04GkyMOY+Q2pdClTLNDQTqS55I3tCvcl/4Nw
i4WDSO/0TZnvNShYHWwsM8ouFjQQl/A5DDf1OCcuxDOX7TXBr4o7yuq3Vv63
Sva3Wuu3VuW3SuG3Sum3VvG3euO3eva3Vum3Sua3Wtn/pk5/5H6rVPw/at4f
df9VrUl/5H+rFf0/at4fCJl/k8cuake/1aHTMjap+q+qOUSj1vitWvc6rQZ9
1blQwtpCtJd7VShI83kK6wfhnV+VRp7e+vZ1OLkEcHIIp9G5amA1pE/RhB6y
aslaSnNj0NzdgB7vwDdZP7mv6YfGcwyPsBtllJrgwFncEDYfcXBRJnsXuNx7
wQF2/g0z7ucAGefgeaBBOwMZq6V5GwtejBB3Mpo6o23MyN+Y4zFfEKsP1pWC
F8wkoXeFxtCnr3XDi9Fr4V/VfB/3cFhLFXO4b84CbHdEF7d+4eaW7JlbFPC3
S52mfuEOgR1WHarg3aamZ+wwMNonKkYPR4UKHY7yF1yK+gkJcHLSmXI6U0iH
nTZi4LSxufIVg7N6tIdGljljBh1ewvZe1MH0gS0gqGcVxWuuBIKwtC0I6xqY
Rm3JOQftOjBn65DYG+Er2OeQ4nXw3UZNZrPVarZIwHx7VJOMiYsx4QC1TZ4+
wwyroWnwjGvc8JW0pYTW3JzsbTTlRoxGoaHRxwcKm0QDZngtqg4M1UBHNh1z
wA5vairQemouRfgfiSCMaMZYCUWO3NL0HtgpjDxn/LbmxH+aEKG0qmRL1Uox
Wy4V8r+rfwdDLVMul0q5fK5CRP4ULioQmCFI5pAaZX6NRosXFAijEL1zEixZ
Ol7jEhsY65ytnGNm4GaQF/4IcRhuyOE1no8zrBpFr2nUc1ezwZDyjVXQqUtx
c6IHOkzczXUR2zo4pSZcmsDva3+YV6R4w95feOkzt3dvGfHYpOSIDk+MEIIb
8YTkVAW7krJowRQGph+nRr/BjaDoErPlJT6k7kaWysavLqgd24egDhwuJRSO
4hi5kLbpnGzUcyYrXIIt6bh6ePGYEztFKbPwvAmnN+XO0mAheJ+KHUPGKQpJ
KzxUENF9J84Ym4s4Vq+4IYx5/cqc2JwyXr1m4lJ0tos2TaY6MRxqSbVr6XyQ
Fu2VCztEssgD1jyTRluk897AnjZluWkUA+liuVAsFFPz6Txq19NwQahEIfhP
yVaLZSmVWS784FOtuQxExQtTXjVCAQV4Ud6QWcqG/6ZkI40snuYbLtxtpflm
HlhZHdvyyqlWi8BZ2ZTC07rgrCGVCiP1ORqkgE+8HQHpPjvtGhLoEU2TRJiL
OcoAkK6KK6uSqDDtlVnZInJnAGTeSkbkAH0Duqq2rTHFxAvumioaYOPCf2a0
QKfMnrlrV3TX0vNC1dFpvYgskC062fqzooeFnu2k6Blf+mmpkjO1ajWzTV+8
txcWTogkf0YNCU1O1XQhDYIum8nlAmqG4KhjFt4qqCl6wO88pyvu9Xid6XX1
pxafBHcykQzQ4Vv9+o85zjCE19gHxYEJ+/+56oCBrvp6EZcB3dwiDYi/ZM10
gVxLU1zDnsFGL5+nQvDUf6xG0Xm9asMcv4Ev0sG3FL0SOmDfKct4fBr2Yc9N
1QmngrLnGj3hCmlFvzCLTjVXrGZrmSJwdL0hFjPZoliv5ZtiPZsvlOv5YrNU
oX3NJ01arITo5NG04fPU1PVZOb0lVXmQHgaBgZYDOSpiqhMRbz6+rgH4CMyp
uyUq4AlfNelsplCslIrVfGGYzeUymUImy42OHh6T0mrgO3mwMtdbCNOzlGpx
ZntNCUQ1P4jU6riUy2XFXEmWxHKumherjFXFYrFYHuXlzKgyrmwtxzO12xNu
eueb7jVVny/m3DLx12TUIPCVjldMh6OC0+wJE9BwKYUttpQePiL+tdOzTqln
nj/3VtQAlAIQN0RF+p0iD5SkpkCYEQ7+LAHtRHSTRTUj4mBztUFpal7V256x
iD4H6h13D7Ab2LlDsPGSKCqW9O9PLrPWf4/yc3BIBnudhHshav9rAJ8gyYCT
pYERHDYVQw9pRnKFTKX8wrgPa2oMaRHRs7vJ0oa3ag20kCUDzDf41grecSPR
eATRHphm26dD+JKSeGElpRdUF4PK9fvhvAEhses9IbuOYHjxFhG0wbJE2YRQ
vcAKbss0JDd6hiPzB0ANDgyQWfgUoAmeMh/CRsON33XuUipvCXDZVoyoIZPC
R9SGn/oMC7l8uZSt5tKYk2liWuthNp+plsD+3fRugmp2aLJDZAk99BPx7eJX
zthcMnnMS4FMhOnAtWaqPQVM/VrCYIOoIQ0SeUzdTKUR5vTDQ2QVhEd0Fb2C
gyqDFHyW1upYnEmaujYtPjfSbBS2sukn372FLC7VCCkd0ErAg1QkOZhh2LlO
TVl4qXL5i+C0cwmWATNsMO/GoAMJHNjMuONiBkgKBoSBYaAEoJAK+g0Kd2IB
HIkqq/PD2AmDfUC6VC1Vs4VykS+AThfP9WArFE7Ao3vPuLLzhB0zYNnJQcod
E3hChY0ed78EFuTVRliF3BQY1EZ+1SAkbfPZJrI5ksDhkJ9EbJyzvr/VMbnz
ErMHgWUkoQtV2jpJRwUGXRqB6WCndf7tXJoNXzOiMdDxxZ4awxEWKEvKhXK1
kC0W8+VKvgSsnykVxCexVuBzeWUqljoxhboFRDLfxMayRvThEIwrLrP8uCYu
yulUAJnGMEUkD2hmutlNWBQrOVCr+VKpBOgUc+JdplbkWNQxYKlnwZ5vO+/l
DhxG8DGoMvpYLBSK2UI2NzQ502KWKocMpNdsrg02hWo5W8lVC7D3LRQy4nKs
5v29qWnZeIzUB6KOWQxCYDHZ9E2aXxAIqJ4Gozvt8RjfaKz/Ygv1fmdvb/Pz
iCnEZhcYJMbzTuzceH+oo8/NlnRHGP/rn5bQR8PamjIMqDUw7UC4mc2dgjOe
n3iL+4SGZMGmQ2irmnOIcYcuRcej0wtMuxmzMUKVO04B10NopSn/bodAH3l4
bqMRjcT38k942fOCmpQ8flTxPA0hMefFyeK/IjXtMT6A/PkYOwDTElrnfhim
X8Jyj5fopBqNzJFTh9yViiGdlN4vyCI1WguNhtch4E2hyOSw3J20mYcqRQI1
VNsPomBeSdzNlVhMg9cg7ys/u+CxgQiaBzwHj191KiOnUEaqOQtcDxiSQvnD
E/jWKbQ93bkaHAUiNJIBxPNOB195dw5CPOrlPqS7vKP1VnptP2dIkBLE+5AH
LyDS/hs0wlI8C4nvEQ/jQd3uhu05l0M4eKHbHmjVErCocTiSkSMg8WwbnuhB
ou0IvtkVBxBB089NwUNMeAgHMhBgsBQ+HBywlay5aIodHES/x8geL+I/Jnxg
n+cOC87wYiuD4vWNdL18lG0+Dq1Hu9LJnE7y68Y8fyXNM3eslQ4dBn4boP2E
SEmtm6pyfWQ6tcvntqHMcvmnurysD/KSnQypOEBJkcq3F5lW1h7f2Yt13dFK
tcl95VHst9vqMhlScYCSIlU8OympVXth6sZ0vu61b3vssVsed/W7y2RIxQFK
itTN8P7p+Po+P24tpaPlcj2uVZv2dN5mTiYZUnGAkiJ1cjSUl3q73RpZJ8Pb
4k1p3WLO7a2hqoVkSMUBSopUb9i4H6zlSeb0uCyPTiX3qCbObiZ3uUczGVJx
gJIi9XDyeHI3v18+FI3Gjf48vC0cnZbu1KPWfUJKxQFKilTBNvNnq/bFxV27
n10ai6lrstvbCWu0Z8mQigOUFKnL0okuFyuLjJzVmjd597Fzn6ndDc3xcS0Z
UnGAkiJlFLqseNlrLJbTldw6MZRb1lvDnlQ2E/JUHKCkSI3Y1fP5+WLZVcez
q/FJb7xi8rHZng+aCSV6HKAESMlj+HVdvG8r1ax2/6g+NQZOtf6wvmmeH7Hr
effdSL0JKLHuO2qYhXr3qtm/XhuL82rt8kRyeo/GnTRJqPtiACVFajka3tvV
7oNSdatmN1efiRVnUR4v7o4TIhUHKClS5qIyFsvyw+lp8epB7OqPcqkzvenX
xaOEIiEOUFKkcu61KzWzzfXk8bzZLRwPhqJ1P1oO1JOESMUBSorUvJ6vSqPz
7KXVLgxrg+6wVa4sVr2Bu0qIVBygxLpvddpYddtM7NfUq6o7vbjQNOu0oF/X
EqqZOEBJkRpkV+78ur58um/V++3G4G7Sb989OMrTcyUZUnGAkiI1vVoWSkfL
iX6jqNXx04OeGz+ejjRj2EmoZuIAJUXq+ri8bg1nmn7VX52vc+270vjZPTKN
5uP7heebgBKvvumcdTSFHY1bJbP6VDqr3sycTKbWOE1IqThASZGayDn1MbMY
mWzaH4qLbEbsn9vaSnpoJDSH4wAlFp4XBb02fiq2Tx7mTrN5bvUNpfzcVO6y
CRk9DlBSpO7cE3m4bp30Gt2Oey8vchfd8l3TnFw1rpMhFQcosT1109aM0VGn
NRXl3iXrus2bi6dV8X5xm3CLFQcoKVKrm+t8o/x0fWFMZHVerhceLordk+tB
9S6hQo4DlBSp7KQh95Zi+dycN6+en+vPtbxy1JmY+auERl4coKRIORXJHD3X
8+WCdquePVs31sXVfXl2fL9OOH1xgJIipeev1/XS3dnl80pyZfbYGpqVnlHI
uv1OMqTiACWWU0/tJ3k0Ol1IQ/O4JT62mg9urpCfjMWECjkOUOItVrNyWc/e
3pyJjnluLo4vc4NZqanrrJVQzcQBSorU4u48N1fHD8XjO7mRXZ0t++OzhnEt
H10nPDSLA5QUqe7x0Z1qjCrFu750Nnt6rLemev2hUe7JCXkqDlBSpB7t6k2n
0KtX1vf6dJK7GEkP9ayUy43PEvJUHKCkSGWuni+unu+GN4p2X7y+HHZvu/rq
QTOsx4RyKg5QUqRu8912tg6btZGevb3urY4v1anUkbPPg4Q2ehygxPbUUDpe
a/pR2zzTn87L9bp8f2O2Res88W4mBlBSpMr9+75br+RPdav61Bhlb7JH1YJR
vc3nE1oJcYAS81T/djzJ3Z+3ahfOyWX5wR5nV1rhQqxdJDx1iQOUWCHr4/Ol
OFpWTm3lZKQVbOmsWj16LqhMTqiQYwAlPh1eq+PjynOvKC1NazTsZ8+vqket
69bdbdLT4RhASZFq3C8X3XLxuWQNOkquln94WDyc6O3VhZrQnooDlAApd6zD
z1x1dfRwV2wUzP7xbP5QW9wNhuX7s9vczfvn721ISWnlZtur+9uqfDK+mav5
xrj6lCmx6XJ+f5xQ+8UBSopU/3hYy2SyJUk87Rp3tdmx071embMH/TEhq8cB
SuwyWpbFi9tco3ZjZcTL+nO1zGrdVX1odBOq5DhAiTfuxnokS+PFZa4pdqbX
48FNLle5vTw6nybcI8cBSoqUpd+cs6PRo7TKlbR81ijOVafdWV1czhIqmjhA
SZFqTqYnynF+bY96R6fdS1aRn59FR+50nxJKqjhAiSn1cCbJqpJbGi1HOln2
R2qnM3byg8xRQp6KA5QUqeGsVb9ontuD28eJpIyKK0N7rJSUxVROaFHFAUqK
1FMvf9fIdCXr6KiW73dH9fnt7YmzqjXOEzJ6HKCkSM1mj5dTtbBenAzV2vLe
6i2zsnU0FXUxIU/FAUq8n6nPlFPn9HngFI6q2Zu5NT7tGMpEH+QSGi9xgJIi
1XbdYe3IzWbrA0tZneY7lam+zD0+zisJN+5xgJIfmxmquZrVh8PLh85iemQU
Dem29Ni5e05oJ8QBSoqUems3GjWtcv8gzi8GtbKtnl8f22NNbSekVBygpEiJ
7ePe9VWxsXBvbuWL2iRflvurpVkb6AkZPQ5QUqTOjLP7Vnl0fHmhN1Y3d08l
21EvnNOlnE0op+IAJeap4ahzMr1Q6oXH7CRjyM+r3sPy6M5pmEmPYmMAJfY5
rAtPN5cnl8dXlZw4smeXw+vjTkllWvY+oc8hBlBie+okbw/vj4xxtXNZKQ8W
OTn7VBjnS6vThIweByhxYMntaff+Pnt/nG3l1P6wvb4sWE39wm4eJ4wLigOU
2Eo4zRrNPlvWRjdnwyW7mFcrM+P+QZ6UEjJ6HKDERxyP7nNm3HmsOI/3pnyt
qw8Pd3J/uTxqJ6RUHKDEG4d79aZw+nBu5TIWK13OjvX1bT8/7zksoZUQByhx
CM79ZKVn1ZFTmheUs/LqKHt/rmiZu/484W4mDlBSpEpnp5OLeS53f7U6HtyP
RFWsr9Tu8XP3NuFZXhygxCLBbMunPefubFy/vm88mOdZw7goseyRmJDR4wAl
juHor0ftqjo1zh/Py/1HZTq9H945q2nXSTh9cYCSIqUMjytW+ax7/FgrFOs9
tnpY2mNdrzknCSV6HKDEZwnis1QpDe9PMvZ8Wb+rLwc3l89L9aJhJTzLiwOU
ODKh0Okqi8aqovVbp1ZDPek8jub1xpVVSGjkxQFKbE/VLqrroxNzrN1kl83l
Up4Wior+NNPXCW30OECJbfTM2VN7XJfsS10rVe/F6oM2NB7HdquScPXFAUos
EqYXx9r9Wh6uDUdfDDKgJFaaoi2lVUKXURygxFbCaHlWlRWtNFZ7mUX9eFLr
X183dam3TmjkxQFKHO3isGV71D0+rV9enDZz9pM1GVjGvHExS3iWEAco8fmU
3XksmeXluDC9G7qNs2J20BgsxOXRKqFIiAOUWKKX5Eqz1Ks3r1hmVWjWnu66
eafQ6smFpBI9BlDisC6rXsyXT6ZObtY6u2n0rcHVzAEJU04aqBsHKClSVz3j
9H583WgOu1fL/NSoZTLPk1KlsD5OuPriACWO4ei2hxn77Oy62GUzs2U8356e
GJ0TXeonPF6MA5QUqeOTRi2f1Sc1NtUmR70rd7hu17IZ7bSXcPXFAUqKVHUs
5rIn3dOSne0psjkq6T0zU7LOl3rCLVYcoKRIVZ6ehsdHg3w122mNjh8eLq+d
++7F+V31OuFZQhygxCE4z27uWmto993ZcWVy3r9oaKvjk8nSuEg4fXGAEKkW
T7vwMVk0wHh1O79ytMFTr6XdVRZ3hUXFVc9LxUFCKRoHKLFhNbvOPN4OV+3a
UbZiPejOw0mulpsPl+2E5kIcoMQhCg+6cn96qY2nzBpNzWWnpT9cLXPto2xC
0R4HKLG1l3ksXc/t5rDBRk+9Xvd81jxpPK77T62EzBUHKAFSluTYadtuWg9X
R7cFu9ToS/esVu3o7Uyvd5l9/zJ8E1BSpC569c7wVhGvzMHzszItNjMnD+at
dn7ceb9h9SagpEgZY0uxsoNqT5mXmsPZY67l5O8eZuL04v17rTcBJUVq0u0u
nF62c2ffHY1Hmbui0Z1eDaSzM/P9SvBNQEmRWkvHxwX7ZlyYN8YnmfZ5r3e1
yN9NMvJxwumLA5QUqaZUyz42L8+PxJFyUVyJyuxm1H/W2nLz/YbVm4CSIjV3
Zu2H6+Zz37w3mqWr4rNmlNpyKysvEiIVByixYZUV9frZbVYvDE7VY/vy6WJ6
0ZmNzlc3CSV6HKDE0ZX1tlyv3F9dZdo38lqdTh/1bPbu6Wp6mzBAIQ5QUqSe
7/MLpTccPJw+dJTT4WwuW8vbS/d+nHSrHAcocXSlfHfsGmNzkL04tUD8HV3Z
k/m5fbcwEu4g4gAlReqoP804A6k8zZ7LErt5aJ0/PZeWk0KxkXCrHAco8UVb
17SzK7Oozc5U+1SsXh2f3J6dSDVDT7iDiAOUODzvZj3KT+WnK/PkqOCczU4u
Vnau4bJzN+GBehygxDsIvXn+JB4t8mK1nCs9saHDMsb4/rQrJdwAxgFKitTp
0jnuy2ed+8V14zZXy7RXtX7Rrt51uwlPz+IAJXY9zM/qLbU4NLpWMTvpG5Oi
+dTPugMt6UlHHKDENzVzmnQyctdHl5dW6TJrXDdG81Np2DtPegMqDlDimEEx
f1mrDJW7bK2oK6cr82YtZp+HlSstoZMmDlDiqInHjpk/aXQf2xPt6lzq99vn
F0+Pp5PmKqFEjwOU+EyolX3MSz3xaSFdTwbiZaVywlZOo6PJCXczcYASn/Kb
j615pZ/LHjnjnGmfNU7OzavKqvec9FpWHKDE+/deqbdqnkxr7erIYOPrR+1U
zoyrJWmWkNHjACUOD7IG1l1XPe/01vfPN82Fdqed1DPXi8QHVXGAEus+pV1f
5Jvr63XhaG5Ny1m1mlmV5u1eI6HnKA5QUnO43bLuzi5ue4OmfnFauureXFRO
MlrruLF+v/B8E1BSpC6fbKeZHdmn1oM1vhzeXF6LD9XT6b2RwPXwJqDEO+Rp
Qavbd8WlYzz1TrpZuXcxc7J676L2/iO9NwElRUrp1h5EtzZ66GjXK7U5uhhm
Huo308JTNeFZQhygpEgdXSnPNxcnxYu6Xehm1+7RbGg4q3stu37/qcubgJIi
9WQVluUj1WjMjrNPTq4sNRqPJ6eW2yu+fzfzJqDEoen6eNhwRk6/2e49591u
++qOaSy3WN5b75eeb0PyMqx1sbDdpYv5JE3D3tvrUI1AyzkUxgCZqu0KT/5r
nv2J0l1Zkmrz9Fy3x9EMUdCAUqhbDqZTwjJzWO+KsifdYvms3cXFvbriH3i2
T+GvseXevXK0drKC416r3/ewtjUm98ICQ6rhUnnCcHFJ28+CRrXVMPUylQnF
ymhYVrzRr4ms3jv680/40e0MrlpiI4AUrsmHlROxzKSKRZKxKrxXGW27qPzB
AY364OCVUTy6QP6xypTfhesAD6pogKkEHVV/WR54tCn4hHm4TCpIH/rGwrz6
gqpT7SiHYbLFscMsTH1mMF5BtgXfUjFjStI2gF4+Clgn+lNQDjqa0C7ChMA7
aVXxynx7tRpATYl8ehe2SJOWKVDeUKxzRXlRS2JuP+XziZe3bcRA8avES3wY
wD/qxKDC1Tann7Wj5LZfc3u76PYHSjoJsLGKuiGvfWp5CZiZsv87lnyD2eLM
dXDA80Tz1G28v03/VEINk9bRJGAdPVenLHS8AuY2bKwei2XnfigRC6lcqkBk
bAPvBbVzsSYiTbqXKo4WIeAMpDEYL5BhUlnehaktiF2MNdIakz5i/V/ZYs7B
we+E/T/+gdUkr2q84jl2g1l3BUkgWlHJ5kjpZmHCeGUxTO4LpMIC9r1Op8nT
vzXand4Qfvzu5Xx0VQVzvAsDMIpRarT8IWA9b6RnzDhSwhHIRXwArxVTgKnx
89Gpxl60TN/L4qWH8Kx1fdP0inCVCpUKf4h1vGGRY92BWoePmur/qrBkCCue
jY8qImPPoXH6WWm9FIjYxM/m55XZZlYs1sI21oSMX3FN9Cqu7UJKhm6prD1Q
h2FRvU3552R0igw/t4Mked59XaUCd7xzk8q0CxEGst8x0r2tfv0kyyLmbtTs
UO/Bm4m56ykzF7sf67seW478ymNRkV5748gujhzzN4ay4ILSc7DqBk7zJq3j
HiUrDGXB9ZhmDnoJCwJS6RzK+GnpfjLGF3kRdydCfKsyrdDF5JdqKEHqEsva
BlV8TF5cGzM0zi3MoI/ZmtNUTYunU+TZKylRZpBateFVDZU8y6EGEP0Cyn7l
a5KPVOgTsUY95+v+1zXfB2km8TqD+1uFButrwTCpcrodqjMOQsdQMHnjJudj
tEr6aFOHFt5RmUJPaPBa4yDneNpSH1CQfBKnIa4MtW1qLi9ZKoDdxK0gF6wy
LOZqYomxqekVX9RMrCjDy55sJbf0ElailYHllWC1Uqlqf4o1D00cKVbP8oHA
QDG/qupNHaXVxFKq3NZhko2lX0dMCFKSjtYbeYnzF1R5TIGEBYsOpC0DKi0i
KZsp+ykWaYbJih8EfAM9RKtTIiujsMOEwF5hWmApxNTPAuqXhT7cVEmllLF+
zzrIIV21cWFYBg3P9oq12e7I0XaWBhVaMPkyZYWNcijo9Q9qiqUOvUpQc0pV
S4tKAub1k4ByFRhiI3/NHsITL4eoMAKexvFQ1mSegLXr1aYCIw1UtdCn2lSH
YGFbqqTDEgTxJY2lQ2HgmjpYITXXgh83Kq59W5MWQtMdsfXMPBROMHc9NmPC
iSSD9Q3WeN80JiNTqLuHQmPKjMkKkGu7EtoabclcYsZlE3+cSmtJaFmyCjxz
KDRBtZy6QBwgYw0MOUc4/dc///Xf//XPGUBcawsU0HWmwURKWMertZCEBkiL
lHCr4kOYlhO0PQ2h2er3W+fnrb7Qr3XOB61zHJdtY6VrVTIwB7Y6maJqgefA
xJY0hU0FLJ01GKgNU9Ng4fMp7mCp5748tUx5tk+cz7zZCktGSeUi8M26pHN4
y1MAU4VSqvkcsLpnd/klcl+XnS+rmqINSCv34ADwmiMjjbA8uWrzVeDZlTsK
qXopcOe8cKGfApcGhbVageKoFvF3kPfcE73hVrwflFFAALQqPK739jAk+Pwa
3i/q1fppfWnf5n+LqKH8sqS5irmJPZnqjxNUL/MKc2vrQKCEVugmi7E95eXf
Q6ZTShiAYFYNmLbngO58/WChRU2hauDUEQkBP8N70OtOZefDoZTEG1QRAtgS
sDwWlGkZwWAdX8mROGMEj2yyjTaTyVt6XeJXM0ZVojclwXGUro6l4/zHlNU7
5VVi9S1RrBaHlSCMID3xzW5OqG0SC99sBHoT9ZK9NzC9HY4dbJUDAIfCzDCX
GgMzjy8cqh0M7Enm24acSAaSPl5liji2DGU5DmkXUpJobXXEZmps2pgNnAok
hCtWZKrcBAp/Q3sRWjrhT/E7xJd/C2rgmX9IBZNhyww6wca9uLrg+040Eb2E
1zpjlN/c0wUg03CTZmFe8YBjkAthW4Zz6AAFNBDdAlb2wYc+HJpD+w1p3Wg0
hNBeXeh3jrmA8g22lNDzyxpyDfvBwFK3q6mEIhFIDysB520fWAq0k0KY/+Mf
WLN58wDLkvPBCN6Ozv/G/wlfUIpq4lJS57h1Ip0/2561+DnKZpC8QB/cy8Gs
hkQLN4RC4nTsWmTyeEtsy3jiGGItCrRub73E7K8jt8Ftx3zjhNFYfaOWkPFq
eF8FlAoKXoeo+efe3hcyTpx0G+2jL7DBMVwG/20CY3yw94UvmzX5Bb4VwQp5
9d/wnm+WhLoJvIDzEhiz3YbwBxYIMtwVTLuroxUTzgOPom6zU9fmcoohWnaa
/pPOZdKIS8+SJi6s18YzVt6T4ElRuJBBe2Nz+PXJL3MeD4oKX6sjblqmc8VK
Mb0Ppp6GR16HAo7XpNHUzaN/X6xLhcxurD8d1wrHbSFbcKa4wgzJAvLzlR89
C5lIhcmUDkN4H9hCnPMWhHgfmkhzNJa/CLkKTObcEXMR1Hf03msNxMbFOc+8
n/soZEuIBy94IrT8gifCgEpBoAZFgi746tjgN56Ic+akJioWa0GpY8Aq1BzX
mKQRoPhKBRUCyOvyGfwo84tw9q9/jmB3fugXu6DBiLkqjWczCXwoUQr5JhOW
SqA6PaEqA+lCtlCplrPVyrDHC9/T4+HOKqdDrMzOhg2/NCRJUlgXwy21NjTH
w8ZNvz+sZoaqMQzXYBgGNRj2OaHDJQ42aNsgf+3UxDQnXq0ZRU2BTQdqW8qm
VCfNbNNSZZuKYCB1rmDTfCh0gLhImGxBzFa+A2EK2VKuWB5uZfrHRP/DqGEz
bINduyEHvMRxe+c2QLazvjdaVBvCVW3Qx1Kx8LHua7MNYmig4DoC83hzzud9
hVWusBXvGn0KYiaf9otD4W8kxo1qOS4oOCTEG1RI3hmeVsFORbPTHJa46yuq
NiWJnhrxS1DRSxDb3N4S0QgT5W1eEresEjGTAfnwiZbmBu+16TpuasTS6+Kw
f5URm8/tzO/O33PFIic0lpiVQOcYKPmuOhcDoe/qoNS32YwegjoyHdHk1bgC
ljoG4WiC5XMoHFl00PhF4NRkKEA3JHXMORiE9tow52D/bmCDIQEsrBpArNTY
Sufmc3Ni5caD/qlrX5mT/NXdqHf5O+5ffyUQm9pkvi2NRm6kFpUULvHGlKkp
e2z13UaYE3eO8aVofw0urz82x3pzlv1KHWacz69YjvlqpZLPlIa+Nh7WPDqh
uAmvtSHQafOg1WxfNPYjwr2Je4BAqd+a1gwLETHYfn9o9m/7+68pGPRQDW36
Ms3LqPrVePAMiqyWT8eaOYK1V9Nwx+vVHDoGOusgrsiYaMOWA3TJB9Jvr3YV
Xce5AmwRJt8kzPLFUrVYLnJJ1X9NcIPUOqITouFx52jYZOjDGMIQovTlroZ4
A3/HonXtTG7JRqln09RTLpYvlNN07pu+rhn5SlZhqiRK3XP98bg97T6tTFnO
tuX1UXlmn2kSY6dsvLoojPqNnN7uPS97l737Y5ZTjIer1PNYY/cNXXdAb5jD
c0/cRor/1DpCj2/e+njo6tkSKB9IKGfDqybiY/HFYdZbNjcqMwzpEGYEWIEM
oVxWOHG19WZ+cM/3Xh8sgEWywb6N2WlTmSjDlT59vLxTr4bS2b3y5Nwsmifs
qPC1yyZTLRZy2Sqod34CMLw6fkUj84nGitCqPKx1OA37rdrgxxApkS5CuC9U
Dzzk3OdXT/Q8xag2QHbCruX/r+7qfhu3svv7/BXEBFlMgqFFUt9TDALJsj5s
S5YleWQ7DwIlXpG0KJLmh2S5DZAGLXa76DYbYFsU2XQLFGixW2Sbh7ZBgNlF
HuZP6Xhm8tR/oefcS0rUl205nk06QDIjiTy895xzzz3n3HN+hN8EYctW+tft
IcVusnypiUNb3IE9JCFmstHdGh5CtxOFDC34h21PuDLE4BE+6AN9NmBizo1Z
Czci+i+ksYY7QpQ7yJ7ZFgazwpfRb/rEdxZeNdsbuS6fTvL6sjuD3MGxfZ9J
La63qVq9vWW3xLM7r7tn2fze6W6nUBqc1hXDPMvLR2Ri+Fr3/PAHWndly2sU
t++FT2J2kU/3s/Q0y3P6vcDXE5NrXwsPXkvweri5945f79gVC+V2Qz+72HMt
WJRxKZNctSipFt7AmKm2ujE66qny3pZbf+qVeE/SCZ9OBaSsehi/MK7rJVJq
nE+cQmVH3RmDRMR4QmASqezUSz9qPdWJrQZaKqxk+mZ8UDPnHV/Mjo4vB7hd
JIREoJnoSLqaZc8zIPqOVteUe5rHK2A68H3OComBRqkO+MjBy9Nl09XhinVv
vhWTSVwHwOwCI8E1ezrN4dTwrbkLvv/NTydsEYTEwKSmQAQmiYhgYVt4OxOi
7DvwPfh2YQ4W/ZJXFKS9MNZkdKxLQ527ky7cgYdvEcU3hQe1A/gi3uveGw12
ed6oycxI8zJ4vaygIhYMfs3WtzImYykxfM+pf9HHIhV2mIS6vO6dqpQMPOuR
zZI07PRqF8QAkQbm82iiSzZZJKe7Pesxd9TMIZfiPEQP84zCgqDFF43esJuJ
mSSEEJlOE48WIIzTL1meaCH0Ws2N6VnW9vRobimVF515b3pHEAuBwm/j2425
mkxz6jMGF6f8m59Oz+z18QXd83FUXOBytqMb15iYW/EikU1kpU4DdQmnj7qE
odNCoqiTuzYcWg6D4p52qrkNnc+f7u7zpfMzc1y61NK62TU8f69i2M/OzqtG
2061G0q1dZpKnWZsPnNyJsvkoN/Vjre2rXLqJO8P5D1fFtSBh0enrApKH+JI
hjYnCE+k9BNBoIKCII+rsz0NSyXGeG6OzGa5V8qqsNZvhW1ZzLzKeD0uGLye
n6YZqpjxhaD3Mbctm7Iic49GTCD4o5iek8jdBCKJ8VRKFDotrP1BTyu4vLNj
wqMsE08tOq3GTufAJman6UOQeJ2B33Oy1oUt9hUTc0qikInj1Q7BYtV1HAhL
WcC/XOICH+xQPCMRmowarM/mZAiLUcezRBNdPq6FqSA3PBMNrbvVj7yrGC5r
WrDSFhI9lsuPLDoWFWRux8A7g+8WFoCYWmT3itTOGkpUoCyFs8pLidzGbGOs
rxuE3cYLCfq3kBBTHTb+dyXhXSkjvitl14RntxnGily9+IQTk/edq09ulqvf
kx3DdXyNRLP1Yoq/F2VH65MUJJqngShiXRIMOXo3Oy+l45mbqNMU2+JeABYQ
lLaDfmAgmVKrWmSp/SdczjRRB8MAMCizaJe4h+xZ8At4qwrV/VDZH87GrnrD
Ps33b7lsUbi4Y1D1CFyOD8DZUJ8SdlriX/JNLKKA//sj4jvRHGeCB+ZXZef7
7gLJeFpMbrYLsDC52Ig6zMkbHeYkO8fSiHkJ/2FpD75ifM6MZm+Y0A2ec3KV
5wwRXd9BqxV1ma73jSv9PbV7kE7sewkwnSkhmViZRbrdlB/RJ9849fRbmTrN
Ky2n5K+fvnacBg9xZ1BLY4iUSqeC2WPmY7iU+bgXwX9/TRbiiXQino6vz1SE
OYn93N7On3r8d5Oega48K01afZxCT09ukObuZX/f7pqaIeQwBSGK6TWpmXth
RPKtMGIuRxMwZFpBNauzZZ/WR0LXM+rAO7DSNUvVXVT7eFIMI+KQP3fL1SQX
cjXXsi/BL3HwbnmbZCRvc9/R4h2yO+vkupDd2Wik10szJeWSmfOymK1W8EhV
SgthVLdcCxXZn3VP87v0rB6u4+c3vagHKnBF0r1GzyOEVh8fBuRDr9rFM8cu
JnvNCKvCKltaZMtqbNlOHWzUJQgEqEcqiex84M+WGIIKSpnSZSUIY9nraR+M
nurK+bgraEVDc3+CxV1P6/vD/uBotxfP+lXt1K2VhvYFf17g/W3rcFJVjYr9
EwwjUqL79qoAxGuqALI3cHzzZ92mCEAMjA7VzJn3cNNhjHrUOEmJyjO9TrOM
sDW9x12XYok48JarkOHsKNrFbgnfIDE6tzWpFTAsChmBQRziCe6HxYNmYae6
EFotEkbu5iHUdInhPsbCaBUDuL/g4iK3K5u8uMDu5Qhr7UhZHF0ql4r56nSv
8oDNqwzHIpWg0oqymnbjuasoMSoxKQV7vsSCMkkQOynBzxLBXCMd+nFr8YG+
kpLE5IqHbMkjcWtMusP7NBxSGrn7gxsO5iSBU0RZJ0rpNdZjqtB1IeHt7/aa
F/3qB7c3F4l44l6tbvxHwbyAaWL8Jqb1ms72aW1ipTvqBkyjqZr75FqKK5Ae
5VryJq4tEIptzKc8O8OmXjg7w0ZuJUVJTN3ErXGn6pxVSXlSz2zArWT2Xpkl
3Z5X96xhNKs3bU4PuCZIN3FNTMmlU9461ZVNdEzKStQf+vMnnKd7Bnn6MFru
H9aWk1nZ/1wh/Qal9g8/esCKn3NBCfi09HlaIg5XsBZ1WNu+7Exm9f7TQnjW
zRe0TvwoKvtpVxbr9sRWhrCvkzaqL7TvWE7Q4cWq4y0GJ8DJ2ChrYoMe6KoW
rbxc4jPeJ9s2tu1gA6XtYBv7XA8MPoT2ecl9Mu3+0R1s5XfcJ1QC73ALKZ0t
PDRkP73DvLk1Yc17DziO5z6k2Y92ZE3dBtMmTg4vimeHxd39HpFJykh0auqx
OXQLJyFZ6kHeniyFoEip3fML4fgk0z5xyvHqRWJ0kDEl3t9Tp2Rb+5tQRZ8i
Y0zOy1p2ku7sj1JdUT/W7KPzE8cWqkJIlKYObk8V4/dYyxp5Rnqsji7Hu+2W
VJFOx6ZmVQ7Mk8MpZ3O527NVltXYWf702SB9MmmObbl4PlFy/Yt2PD6ondan
86+js8Y6A+faFNFG3PZZdkiDn2t1jCmpZLsubwvt7mljfNHK9wyzNeinm0P6
Xm18PK0DkWjoyFpHPvQ0h8iKeNtHyzMCMb97mfaPt12eP7n0m+3Jca3mDtv9
jtc8xJJFWBwBdeku1C/K2lkum+hfEiV1UKuM6g113Grx7cYwF/Ky0Kxub8Q4
Zej2YofbkqxUeieDC71lmPpOr5dW1UEmlc9NhbQioXA94VkqoV5xdqWDzuF5
r3aUM6sVs/NMk6TKsF3thdSjtUH3X080sxyNJcvhzFmOo2K1UXqysQowWJfT
9p7gV6tZ6UAZG/WuepwfHebsgk2SdxV+QLehNdKWWHbaF/1Soa82dquNVLKR
HxR2gmHTBPemg8Zcc6zWvShXxtly58JunnTV/kHHTBvPKkXSdu84Zkr2KHlS
VrKicXKmn2+3vGz+dPKsUCuSI7s61dRKrXFrUwKOWqyT2d+JN3zx4lhMaWpp
d+xMqq3GuGHJuYiIwalZd8YdRKD0lJot/XkXbJXccSm5W2vpqLHIRhyjZeUx
UUxLQlqMx9fxbyOaQ4zpVRKLQ3xCB93Kbd9poBAPzAaYjUti9u4DjNCSBCGV
ySSFmQQOtuvzawzb4xkBEllqcNn02AkmFMwzMiOrZ/OyYWzRw0iXPRhu4sOb
5maTFlMYRgdUpI2p0OxdZ3aGhA4Hm1xWSEZJx++NdCITz2DilsogoJ64N+pJ
KZGKJwOpcCu7ixAACy0is3ob2qTDPcUW0vXEEWn5rpbbFs+zJJ/3bCEAcJym
3P6/9b7g4KO6uYFEwrUKO1Oc0oHQkkK/RA7ZJ0NbnjWp0I/IWzxTpSg9wfF9
Fnkt4B+KIgRyrPQ5iKRo+3EEGwPbpkcyuC4oNDztoi4MhUiC0CRA42AxCesU
D7jEuqOpz/2Ys1lDrUEQUIs+geI1bEc7Bx/MfQrjKdbAinABY4JGgtCk3q0j
0MWcOSrvBgHsqtvfox3pJhh0nXAmxDsF4ntuT+Nc2yE9epgxePG1aRJ2BRbL
cSpxTIIt5dwOXwUawF8OS952sLHb97B1F90MhB+AQEWTu/BbVfdUQycKdu0o
QKiiIcku0TmE2nnxBXVCvUsfRFLREJIqT3QYrepyGjH6cGkwChju1b998uo3
X7z65LdXn/77yz98/uar/3r5ze9f/cNP//cPf/vdP/3m6ptvXn35L2++/Tu4
4LuPP3/z7U9f/+q/r37/y+8++Y+Xz79+85e/ev2fz19/+eXVr3/98o+/ePnH
L958/Nf/8/Enr3722cvnX7764m9e/eyXV5/949WnX718/q9Xv/j06ue/e/3t
8zdffQbUXn/+V69+/vevf/stXI/yruRquSVwjtYcbowmu4j1Qq9kWAUI7fEA
+3i7sLCRSq4XdsjTlCgE0SbtgCXK04d9WMoE4uz5axhKFfaBmwQxFWQHMVIQ
yGQB/KHi0W/1EGEuGmL3WdkVAiSAacPBUMOKiA0+zdOjsvd9g2LyDCleQ9D3
vAR5woJihwFMKAwty0Y508g1xK/ZCnkTgNlQODSXIR2EWQnsgHcZFBo7EMYA
OszbchD3YTN8BKCGc3EJBZUaoK7IHOyBivaB0650iJPff3+lUX//fQTLWvXL
Rx9RrIax7moBMIFDQ3pYI0ELOY3ZSU9nHlGwxGdwGEHkrodJAood2IR1OeH2
UGFk7kA3Zfiu4MjuwAr+Guk9+KoqOwOwLQ1fmcCnKBoKfNyF9bYnYwodPtSJ
yu0iig4CVxEH1gyIsYgQc/BFg3TJQNa4A+CvYjl9+KpldXXQyrpvGC5yZVXq
gDJl1Q8BT1QYfQDJJU9Vk6yYvg6LQ9U81KOZZrGsByxrG78PIXIsc+0zKeN2
HL2H6FSgaQYybdfXLJin4774nbnEsAWwGmSN4yO+iyGbYNQ8FIQHSsftOWRI
HGTLmYwmrAwiZvcjXExLs4auheRPfBPntKvLlK91eUQMrqYPLNOCpQHfbMOO
MEG8GXZ9zrTMyRAhGaP9wyGKkRM8o2fBhTrYPU/nHs1d6GrEhv1KwW2xIJug
HVVwMmBxBfrRsEx14Ms4YKoDBAEm9mVfYTOzEXWibBlDqhY52AocmSv5Bn7w
gOl1Rx7IrkZnAh+bkxHFBwl0K1CRqk80rN3FCe9amgl3Ef/FP8PAPc9lV+dh
Hwc9LssGDqNNKLhREzaBLo4jxPpBcL0ZuA+3/Af5N4cGNJXPvm9RbioOGSML
DCqs1VhA8EMUloeOwNZ0rFLUhjpRKStHE4U7GMg61QPgK1JHH0CGZdq2LGVI
V1jpxdcOUiKgLwrTDzBTTdmzKIsGfpepGMIVeNbYHegzpSkilAkoK+Mu+ABg
Wgu+qlLCTeJouk41x5DhGh+HWSBd2Ecsg0zogqQxBCKTOTrYV7YWCzz7FBol
6qcgzhYzO4hjgYapZ/GRHCo1w/N3R4zSSDZ8ml+dQzyga215+UTAnh5MkTTu
0wyEuxB9fsUyfQ/ErUEkRehiX4KSwjFpdExFlu1dYSLKiKXoci1wZyxwIXTU
gBPZwehVI/0+lSusGQYysQ/7YReWGCpySXd0RYP9pQpDnMhDqp/AQQgh0IkE
qXpssVimTFHNytYENQUXJggVvC0uLztokx8g8FIfdi4qRvbPQIarcEiWNg9u
Vn/PEGFw6x1aCqEgdWwvlQT8N2ZFxa14UJmrM7jayDOnTi7Nv1N8KdldeEQI
IRbi300Rb/dAtTXQtgnMNQ/zU+WRbK6yqjWwUUNuzwLHDoSM0y8RjBhgS3nw
oBls89QVd8OOZIx8HnMYWD1GNBuWnGcF3gx0LlRP1lPAoKMoi0LHBSMBSor6
D1tcjlsNcTMjRfHRXPC8QQA/QPfOOzaEPU/FNDrfK+HWcHB9hEqiU2Y1ulNo
xkhPAffoYeCvE7oXgkExVVeFPU0PGmC2Hr734P8AfPVxRKGMAQA=

-->

</rfc>
