<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-36" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-36"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Serhii Nikolaichuk">
      <organization>The Capital Index</organization>
      <address>
        <postal>
          <city>Austin, Texas</city>
          <country>USA</country>
        </postal>
        <email>nikolaichuk.s.f@gmail.com</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="20"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 285?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 289?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>. Scores of 13 more GHSAs is yet to be confirmed and will be added later in this table. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing -- CVSS of last 13 GHSAs are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">8.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">7.9</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.6</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">EarlyAttestationBleed</td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">EarlyAttestationBleed</td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>9.1</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 960?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y923bjyI4o+O6v4KpafTrtNnW/5p6aKlmSJdmWLUvyNddZ
KooMSbR4kXnRxbt2r3mZt/mBWTPzPD/Rb/0y39FfMgCCpEhZps0sZ/Wuvasy
RTIQCAQCASAQgCiKB47qaOyr8FNTsrSNUHMcZjuSo5qGUDcNW1WYxRShLVn6
xNWEL/XbppjL5EpiNVfOZAVzItRvBwOhmsoeC5F3uTfe5fOlajl4V04VjwXJ
UIQ8PHNmzMIPbXztLgTHFNh6wWQHEKCvs5lUBl7Ipq4a08OfDqTx2GLLD+L+
04EsOWxqWpuvgmpMzIMDxZQNSYexK5Y0cUTVcCxJnAE29kyaM3EiqZqYLx3Y
7lhXbRugOpsFfN1pDk8F4WdB0mwT+lYNhS0Y/MdwfjoWfmKK6piWKmn4o1M7
gT9MC/7WH57+dGC4+phZXw8UwOTrgQw4MsN27a/CBICxAxhK/gAAW0z6KtT6
zdrByrTmU8t0F1+FQbM2PJizDTxSvh4IolDrCNIUerXxRyeKvCBtaYGvo+Q/
WDLDBQR+FgQP+F0Lf/Dx3UGfQF+hha/wsQ6EwE9+Y2tJX2gsBROAzyVLnn0V
Zo6zsL+m06GXaQAHoFVn5o6BQro7k3RdUkTXlnRJtCVLkaz0PnL/BM00CTGH
Zj7gvc1THHpKNfcCSr89pamZo0NHB5LrzEwLKQmdCgJwiMa54aeu16Fwgx0K
A+rwJ/rKtKaSob4QXb8KQybPDFWWNOHGUJfMslVng7zbsJgN/EAtfB4d3kQe
y/Dp1+gT0wVs4WGLWbpkbLyHCmCUyWYrZfrN+Fz4JBkRSVKcJL85rqhwgCmF
7RnXrSrJM2Zr0lJouGO2mZv7BlU3LXbHpCULd/gTtpJ+U3gznOOf9nRwxiRD
7EqWyoQzSX52mbOvgyitLiXdtUIkCf32CXLCtKnq6hF8nrArHbtKPfGufnMN
bJoas32oDUxjOjaFE3cfRgPgkOlMUoWWKxlCzYDVNDFhEkiS0CSbmjndAGlS
x8KFo6Si+NVnqiFFsBtrLlPMqQH9/zbFZ29RrD5jxnStGkIbep7uw62zFS+R
LiTXwgVuvd9HWzJXzBCQAn/J4GfAKUY2lylmioVCPGrn0kYSmpasAg57cVup
jjwLcceja6n+Ax8D/OiFWRqs8ggecwCeYhz4bzZBSsmzfWg0LOHcHauaBHvI
TGeOcP6f//Gf/+9//sec46QaNi7VlHCeEmqp4OUefBu9maoJV2sgoBLi8wha
ipWau7I7/82kzyTN1Q01BXD2si2zZqoqXKpzU5Ng5O58rxyaMaEuLVQHJBHy
yzpEsZprO6pxDDO5luwo4W4GtQhmxraXlJ2axE/dYKMtJWBcWJwaALDY3vlD
Jp2ZjnAhjXc6P5MWkhEVMWMCFd9tcykJ9ZTQTQl3Kn5th6aomYq++sBqCtC5
ZKh9IA/ZEaTYUpJTemrFIf62sEzHNFL6XhlzRqQWGs3BoHl52RwIg1rncti8
fGdZo8RdmBZse0JfteekuriaI/ko0jT2QNTtUPDUkgw5KqUVZoNGYTB7ZMPc
OMz4TbeNt0jZlUCp0VVNlQwQjJY6hZWsqPuQ7bU74lW32aqFEBpIOPcGU5gD
eprCNGFogYZkRnHsAEtG2X8xU02dTaWUBZ+oOouf7q46Z5Y0E65dGM7GYGLd
1DSY7H1YtiV7VtdMaQ7ElUmpHDjmZAKYIffhwx3JJRmSEhVdOu/utxmAkhHU
W3h1YIcWBvLMMuW9K7LZ7Vx0akIP2UU2tWPsPRXpymGS/hsj8i+8r1ISUP/A
4MJ3CfqZsKvWpVCB+UpwfLV93xchNZ30vUMgDkyvaDMQSLjvwmtYMp7CDCry
8GLAR0GKqXDmGkzA5se8K8maMmer6a1WqxSsa4b63xQapAzmpBfuWANVCIef
LmQquWw1W8mNdrBD5EZR3EYRzPDlSDVGPmYjwIyrUb62Rv+IfMHDUr9JefpZ
9M1tyldxos/PRGjj6SZvkFe02ML8K2gMFsvbNPbUW1SmP6Q+E04/kFLRwXrQ
o13RGviKX/IHHvXqZt0cePYIJ4Og2sLS1QxYamONoZlnMdx74RtJnsM7VQLD
D4ZHlh9bzJgOn2rUFAwg2wO/hyvlJcOdNA049JkMu+uvqvLLju0jbOcgVxK6
yMQ0D/CieXPb4J9mS4VKJW6UzcuOt3v+1eNk7lJJMUO1QblxLXOBf6Tpd3oH
/7ihRu34ZPMpmzYan/tNTn/oaAvqsLtxPfIVJWxGFrUIlvUYtx2wN32ygFaE
sHFHadwLuJomKrOEheTMvnfmaZBhcmQrwoAtnL3UyP1wasiweUiyjAg0lyro
ADITQD+dCYYKWwXTF86GvAamrjoIAiWS5TQkR0KJAoqKUOs2hEHzVhxc9v40
YXIxhNlyVCWfrRaSrYidxn+CnUPtP4Bm7AS+h2buT6IZR81We1ATiWPEWie6
xXy+9AhvNrl8dPXH7jege1rSUjU15lh2WkZ00zaTXdzV0pKyVG0TzG47TaNZ
TqZTUV+u16I+nZbf3oButkCDNbNLkdwuSbylpf71giZMvGwJjKgp6PafT73C
Yp0XV0+5tbheF/4k9fKfQL3PF0x/FSGtErDholARn3LW6vsI2VSmTANuEQcb
oI9uR+nZZ7rpRPyqyGu2ayO11H0rNDz0BONmHhr2BkeNk2c7bw989jSVxSe5
uBQnq/Ls7YH7gxO8wb016J012GK4lHCqFyao99CtoJjGvzpg8DlMdgRJ04CH
pCkDSozB+nVcpMxfM3Q99zwVV9Z6Kc4q1UqioaMvXfTlBJhgzkbkrLw75+QS
8sSFarza5MMnDihNwHSf4LJxVBDENXTOqzKuQa/nyGLIgnZtxFgAaCeizAZL
MKUyZ0K7OD5I6/YUqCI56XWeXa9Pn65Pzy5kJrGSVhhdTu8N3W48pD9sCxAt
e5a6lIDsogVzpe2wvv9S6NdEFBryDKadGTDpuqkwQVEVwTAdAcVrZH0wX4TA
ykDZgG09cRymRJ72SIYnIx/iEh+dNMf1bQZ5Kj0vxUIe1oZV8PblvQTxAb4i
xtR8gxAtE6d7/vWfjSJT821qlJ8mK7GYt3RxMZt9DzWYuYySA0aiSUsmwvaz
VC3HlbQ9BJGZ5cC+imdvtrBiFuOUMV0gzQ+iwmu83qbKojhZiNNqYQr/0avf
RRX9TaroqqH+05EEkYrZSKvPOqglT6CW5OTSd9DDcuQoPUBgwioVZU3Fs8o9
5AgUL655wF7z7JpImh9OlShqbxOl+GzJ4rJSLoj6ern+PqKIivSGMPlTdnSD
nzGYhr9NhQlT+tGEWaDqWlyBmJ3MijH6ayxhHNn9EZQZXtWHVzf/LWSZTivP
oj6ZzUA9seQPkaXTEOuWaqt40nTVSWUzqWy2UEzny+VqLlNJ5cuVYp7OgIMP
9/kpSfVA3yN9gRpLRCOpm/oCFDQDzOBT9DKDjmJI2gY/NSdveiovzWVAq+K7
3sp6vS6G1KI0nSVqor1gsqgqokyYfY+jEt50TdjxpYkUfTFMgY5p4UOLTQD3
EAUz1fSgl8plsuUUTTO8Ffu1KNGAFyQ6fBm7DvDNlA6CMETEYVN4jgajtUf3
N5DF9rt03yASemNcmxnqmlQ5UHAnIPtBG0hLjpwrphfoU/fYOb1iqjEzNeVt
StUlC2bLEO7CX36Ajh3TcP+//0voqiCAQWuMvnyA8dszoQH/WcCyY9G3bQnP
loShLc/MCQxkutNYsoAygxmbwMB25mhm6pINXGfbML4dVFXYC8AI75uq82LT
6W4dFhE76Z1GZ6rbGfab/2oLl2yFh186W5EONqBlCNOEWwS2Ei6kDbDrg+la
qHw36KDNFq4im0b1I0JA1kxX8Zc57FcqnrjR7I01c5rGdmngMfg/GMQWE23R
YCtx4uMm2h5qIqAmsvFiImqImrgB1ERJFfkZoC2aRsw8Iw7eIGFp1zws4COi
B9j/sLgNF5ZGeN1FKRdQy7dSvBaCZ9WGGu4Y7MExxZssTSMnmsDYbRFwVqcz
kI7hA6EtReQttnxViZFIpTfFgjf1+8UZn3CQXGF7LBrGdKD6UQ3ewZrYSE04
N4poS4kMQ8jCyHzsKzFT2P0Qt4jIF6V3v6i+90U2438BTPDCcZlIMuhTB6lU
6uBAFEVBAgMcvYEHBxgPQAFQgqTqNm6GC8tE00NwgoglMODBwCTB//e/R49I
/vGPY3i2c5jAH0Y96rsfkpt2z4e5fR/CQzqkpQMzQKilOm13HGL0YFMVvuCu
ah8KqxmIimAs5HGQOCtsxxWYWDCwmbkSaMYiontC44a9cYHUUmV2DI1AkB4d
oavLhF1gMYM9EYGhRmrbR0e+AqowW0U+0yWwyw2GO5IFZhGzjgVbxU637L3r
KZqSJ0UDXCz27BIUoJIn54AUf/973HJGAr4eiaSAWDs6ckEqI56StQEEUC1a
AwGPjlIUGAK7iqs5NkYVCmNQhaDj8YZG45/hQt/7Tjj5pPEt05srbCWh8YKs
90Yz0kvgeyAw4gk2x4TEH7QTuDIAoDytwzHxbLxnmbdoAxwLoOuDOK4tME5N
zKUyAkgQZtiMxBbAtUzFlVXusTlG7ze8DH4ighZMP1vxv8/A4BHGjKFLc26Y
Kw3dS6HBa2wJ3INIzhluoKBHp4S6a8Ge7GgAD/UARmQ7OnJWZhCZug1qNQ1G
x7yRaFZ8iPyKT6upjIhBq9Gn3reVY+J9g57boRcFjv+rJqVUXiCpas9gHNJU
AtHo0GDGlikh5V6ziIzcSU5vTRNo86GeaKuUTZv8Ul6sLU3uYuEL7RD/cC5Z
SAtqTY5em1NG9sklMJXCd/kMbkNm0Vs8ZogAqDegaAHiOJfbD3gnW6biyAF4
rzuMvAEIAjAYNiZvNGIKjK67BgqKT2KaFJgbAqoMPncee3yiA51xAFGDgzB9
TW+Qw7v+Rtpv0ZVJnXVB7v4rOebhUw48ZLh4olxXFUVjBwc/kwmE+NP2+NY6
FTzVERa5L2dwJoEpYNpgZmlEL4zGs3sc8EWaS3wch5GBQOuFaUsakMFiU9Aj
aUgw5tWMNGQEtiEewCnxvP+2bC5I8qKDFU18y4EvYRrAlE+BzmbqgKGvTwk4
vxjeDVsyXyAeY84BsMJk1ebSWnZM4AOUFjjtgLiqkLruneboIPolQ7V1UHdN
fc9zO4zlfgxpueGo+LeEbZQt8bG0RJcsmpcAKF74/QmeJGQmrkVE9hcf8EUN
xBCX7sSDFgh4vkYQFd8oDPMCzbZvEcqBRQjvRepj/8EQzT4f/a60hv/vkiBi
jCYcNyERGTqO0uDXACIj9cYJC2Mrb14JGngLHyHOuAxQhzTd6ezVIDwew518
Cut9wdeyasSSA1biz8IVSFIUFAcfWIfOlnzI4tzbR1s2eoR3cInhaX5I6T+O
x5ILVtCIwORTvEg0ehZxm/jBZqA5HvwBtn1K+EM42e0Wnt3YDFkE/lYLFsEf
0CKLDerkAfmv/+3/tAmmYaLu8wco638I3xBZZmX/55c/FcqUBqOC4RmIkfYA
HlL3uZ3uw+Pfg0bus9HIcTTyiAa/dcLWeHAEvBjpOP/ZHed5xwXseACMyCwa
P7eySGRG+i98dv8F3n+R6G/q8JATHXj45xyx9c/5KArFz0ahyFEoxaBQwO7f
3ID3IrTrsNIZQ5vSRhN/zLsHs5HhlR473ZWsuWv3XWWT8g8owU5Dn6Ashw22
1EKZHP5N+Bacwi8zqUoqxI1oOdsGmMsOnmKVpoTKakH2MfB22l1ooNLZ6GIo
prO59B3D4VpiDU8E8egVvQpDbCvWry5PO43m5bBTuyi1vJ6h63o9Yg8POq2P
jP8QlBNJMckPD7LiCU95v8VInb0wd6iR9iUQ2bULU0bSbBUhd6HQETNKyi04
SU3p8AnBIzgybDI2KGgySy/QcQqmBSCIhg95WHwLUFwhgWjHONwyY+mzmbHE
mbG8lxmPYTEcbzkS9otY/wDsHAGi5c9GtIyI/v0r9wX98tMrWQ8K3q5mi4j7
RtlWB/rpHwcH//7v/35wxwITXPI3OXgAA4f/g0niq3fwC40OMivGYIZs97mD
PfsctX17b3Ntz8N38MqoRCMyhK6heLoroqerjjrd7oTYXlFtMoqQ4XxUw6EA
KgMz8MrFrRSWORoHDFY+NJUcQXXA9N8c0MEUUAEm1I/8QIcAfAmNLBOtra0d
JcKgJrD/C1/A4GSakD8Mhs8HFTdsSTPRzTCcgbaAwTnQK+w3mgkcrhxwnSoU
cXKMyjkqqob3BHYlHUCiQsQPLfzoHml7Fn0w4Wq5ok7IH+1svRsDbhR6TaF/
b+C2a7GAICCxDBAS9gFQQQUlwfeR2LRJpYhlDpBpYPUu8FbmGDZNnATNRBUD
O4hEYryn5aCni84GuX7y979HoqDQ8WDbLryD7zyjFmxsBUyIY89/xB0ivPUe
31fYmueKX9dUmIYzdUWqqb+CugHzco9b1Fh4dmGOhAn6YpBFcK50U4kqgjgo
hAQ9bqkfN/Y962a8EWxcvxs0ZowpvkWugi5/BxnhSL8LeLwBkhQw96y0uscK
eEOCJknw5Chy/il5QoRv0nSKdp/DPk8eBSAPyU+G7guSEJ55qoTXrrJvrG+a
XTBrFOqn4W6FgZHoHfDH6Brer5Q3gRPu7PGRINPT19L3mJXEAxQxRApfeLMM
u1qjQn6/t5i4kxYfN3v4foFzghJVwpUROsT8gtij3QodrIzDvf28dhRDH4GT
BEaqmSuSnCtTIF8DcQlIBG/V+/J7a4qDXQA6/gntHcIMlhq50Lw9+gD07yuy
mbCRCdrHfkZdoGAOGkuK4vl9rKi/n8jn2XQC3668Sf4IKRXTCxJYoJAGCNEA
Wcn2XHgqfgXWs+dCAqlvMQesZ2858H7J/QOIqoS/JzleWcBvMyA681jYX0qW
lzV1dTIIV7ONEOmfsArctuSi3zMIYL7eO1SGDWl/22N+ojljfJhHR/7oYERh
N/F7Wy8g6hpPeLdtojKFL4fmGrZO5BZh4IIcsGi393ynwgAauiAUB/5VGIAw
lnBNA7Rvl53BEFaXY6myvZUtxlJJwWpzUlNzmcY1IHqfpOWlbR/CXiSbILix
m2weJKnFPLcpwN4wVAJwY8IzVdXSPVHiuw45++G9ck8Eoi+JvG1AlFOYJrRh
Leadxh4LbWA2B16juxGYyN8Mjo5SaDLTT7TBvMGBEU23+hG1XuCd5cjtf0eO
ZFAeRVGM/AvAfYcxKpUAnQ4hwObmhhW9z0Zf5fi/pIlW4O94BynSAhCPPs56
jwvbx+Xga3Qx/wE7m6K6egjMVn2MjiLNh4ms/kG/IiqRP+/SCS8n2NjJz7A2
RFgdCioS/0Bq43t8LQSEP6Xl+oqAB3/sUQV8quy90X8svL4Qz5X21/fYBQ7/
la7g0/ezOnh16PbpPeyN+vX6KbzVj7CHvDlqxBlyfyNSMPx79/tA5L8fxKu4
ZQ9UsHy4pS6gqf43IZSjA7ZYUJm2MMkn/96Yd8Jj3yPX905LKPD0h3fBzOVf
0If+w/uwHPmv6ENUpCSLZDfAjdp6wjWm7e7x+nesjt2D9+8A8epA/0/D+B48
vhEh87ncUlyvJk9iKS/re22R5EGuUaCHhBpuEwECx0I0McdxjJgIIatXF1Ux
P1svxMJT6emTkI0CPQzo+GeRXSzkgjiZFkviOl/d73VKjmwUKCJbSeU+AdnS
U6EswlwBW8vT/b685MhGgXJkP4OyhXKxKFqzkiyWqoXPYoMo0M9DtjSpPIuV
ir4U5crS+izKRoAektysfgKyz8/PebEkw7SVKoXlJyEbBXoYaFx/Ftn12iqJ
q1wxJxam0/UnIRsF+nnITnRrLU6enldivjxdfBKyUaCHtAV+CrLV0kp8eppU
xPVitf+k7TOQLaZKn4HsM8DNr2ScsUL1s5CNAEVkC6SY/OkdzJpaYr4gy+JE
nlY+aweLAOXIfsamsHqeVMWnia6Lk1Lls6RBFOifR3ZrOm9N3SQGMw8H8Wxe
6PMLhTXgR5h9hnJzkSvAtBTuZ/AixNDpJ4rcaIanGsYfZfOeXwId1AuLaaqO
h4obbpQPZxaTHO7tJsecwx/glTYN/Sx48iCpBvecD5icguWc5QGkbzhluYsZ
Pix4n23jVFIHBydsY6LHFx1cPGyJBqwxoMSUgnR+x4O+5vnv6Njx0znG+uAo
CEnS0eeD92IoIlJa+CcL6CrDPEqMez+xESaoEhQeP46H6CE8YI4YRl8tNvy8
C9218FlK6GmSg57BsDuSrtxzr5NpzfHslo5yLVPTvMAL+mDMNDwewoxJKvr+
ZQefh0evmOimxZSQ2D/PqXhMiWRCN6txmLf15jnOClBFXfK4RnyF/q8Vzi8N
UZ6pC9E1VDBtPL8jR1IShvUTwbs6RAcjGgsicXkEzsIb5badFbjJ0cFmC/VB
/7Ll486UvyEK/qn48XbusD8kwJdm/bDRbgre4a2wlDSXcbDOZoFMrAX05+Ox
zYlDY2Hc3UiHZTbFMc88Z58fC37b3R4RClOA6whXA5xC2dosHHNqSYuZKoua
OraQKSxACsiDIcTkP0gJpzziCj2LxwGdf+83e1f94ahRG9Z+5/e98WBvG0XK
e+LRVLKfxkvht0OIF9Uprpcwo/CLxoIfa8yDI/G2iQUr0nk9kX8j5mcwgzws
FcimKtvr+XRl30Uvr0M3CmFq/SMMInDQEcchuCcR4mxmSOT3DHEhHQjBsmB0
3Z+tZQ2ou+RHnswOH1zAqPnBnsKDPPncAlPzGLLfL5rnXzgnHP4eXos2IKUp
3EM/QXcuplMFtNAzLdk2iidFlclNK/DYMUak3VmksuTanGYKm+AFdcPxx3Ys
yHh6qlBzWocixj8Ljf5Ji4cmH2Mjfuqx5TX42ic9DV6X8OI7RnRHpcA3z9Iu
iqUc/C8a2iHpCr/RbqT9oAU7zaPfHDHYe8YuYOXgyZiuiPZYLGeKRUpPeuif
sNPJrWngAmSAieHiASNMi8UvkoAIczVPQn8VpMmEJ8tFUfHIDKHoH+yZdNqF
9AZAroUHrLY78eilBcvBW5FccjCLDsd+7zcGzWbjd4FH1nFJQcxuQWfahlhc
ouNR26Vwee+4OjidQc6nLYlOHQA2CmCPewBTcdATif3xXIJECmWYmGCkqH8o
F8SPvL74x085FKbDInEsulLLT6YVJmkiH5iBwUDAVK7uhfvhoqEkXiiPV/4B
HMXF8SDpv235wfccUvIDGOIMRd8VPBsMLv7VFn4XRVxh1BPMLFN+sRR54f4u
fPnmfSTkU8VURuhcDoa1i4uUruzVVEz42La14E+KPvJ+iAQhvYVweOgfZuNI
YAVspwloB3/v1y7h7ySje0hRRAxmbeGCYFY1WMxEKiBxEMOA567S1D9Xcmac
C2agx3AJ7MkLmilgQkbXSvy9zt/gQiuTnxNdmCvxgsIeutJi4Z11I7m529ZT
Ng5O1SmGFORilYnQkhg2m6I0NUBxAObwZ06k+IoD/xoMhbHi6Y4kwBzzlwK/
HbBzNEoyRpcWther4l2jQW4F+UHhnCYFr/r380BcbPPGoPAP7807wTR0ZgTj
S8HoGH/BbzaBTrkF8sF//oj09LEm0L245x9h/+O4f76rCXR/dNTzL9R0eWjJ
0RHAgnGLtCFoPjkDleOt0XsjD5ohNWIb8e7r9UBng549WPXejdC+E/6N6A98
6AK8f9u54zlBVcZySeSGm3CxlcZJ+MIViMOt4vVvQr8L75q3fiAN6Bscj2vX
pA2YMoNwTJAMwnUzZrqhIyFNGkEYty+33VCX+0cd1Y/8kYegU/yg0CCNU/gy
bBy+y0yYh9Sh8HnAZ1cBi29KOF0yh64h2nhC7VPAhxmobf9G8sTX1TyVD+j0
NjrxTRFZ/sUOOu1BNz3sRUjzB7+BxnYW615ifPxT6o004tr576Hu/oiEaKIE
hcEgR3ic0uRm606/qPqnb0Gzos3XN13eJb6vkUf6v/NEeBoDF4ha21Rie6F+
T5Nt9xfDcP9/wAZBsZuwfLElXtB4h6Tf0yRkhO9sQ76wF7ybUNzWfS3uQYLs
yHW0mYfeZRU/PhiV2pXhx5UEsDlQbvrZ3PYLgr0iQA8oKIwWpWcG+hcxontV
RDkMq9/RjY6HK/i7WDo8NX8Ifdew0xqMzeZBg7/u5RthuFm8Ei/7v+wHqhb1
xJXeN7efj24mH99z3vqSUECh0Kyj9RlFusMFhBEWS69GdhnzNvLh1SDtSx5P
7+Ls98fWGN7ff7wk/UNokfAKVNLvQqF27n8T2Ya2TU+93cT3laWDnRXnc6bC
+rbkGQa8BA6QQEH3O+mCHm5tRICAZrcv0/4QQjuw313bUy3TwS4G9o2ENzR3
xxS0hOGkzxunwpasEft826JuMd+HwEk38En3h0DZ6nwTOeYfvBwTDhwIVGDv
/i7JmrBouQgW305qElzV+708KER6YMzBlOt7KYexVxQlS6YxvtnllX/FtFxd
WOoHPwsNutMNn99GAmobPNgWZeRQ1TGUlfEQb353pLa9Hctj1YBqNd+UvOWx
syhJmhRiRgRk4egbeIXh0qqhEkrbMF/mh/lSuLDpxeEChExZuJLBEkHrmfNm
FAXEIPg4W4BxyaGPw/UJPDfLN6zJsjWr4lOnwRTY6dJ0/LzO3D9U7h6sdr67
LiyvKkZOdM+nD2l0+vL0bNRribucPWphELRryIRnyOZn45TfI3YGvyk7RCaX
K2dLYNYX0pE0INs0hCnL5skkHMb49Qh0ocgbwCJMhVxZOGXjED7BzZLtjeDX
8U/Ct6OjIFDtF6HdabUxbzW/fnx4dPQ/EbKXGzQM+7a5L9hp21Mc3KIPt/QK
LuVeDYHBIIG9QU/fCf/blo+i0xOTPQ7vgUs2s9OONOX3SjBsg67rZGkKgmxE
FL9KjfYR5wMYVymbxvfiOzXfxrWYyopTM5vKlaCzV0hPze9EOJt5hXH9lSb0
fReA8IKvRuGw32KS3H7owtYu7PTC1bR0kQ6asuXdEdxue9szGPLOfueIvPWv
IG/mYrpNFMZNod84ozwtCoaU4ordgf7qxtsrobAn4i+GAQr+GnvFsu+Lndzr
9Vvvd4adeu3Cg1+FleUxmJ8RNlEP+T/ZQ3Jq5V6R61WHPPDQp1vhda/BknzV
2+vowg9MTSjpXbJOKLbwR3bAIwt/bA/6D+6BRxX++R4CmfA6UwRYid5ugrqY
bi65mhdzqeIPofBnepuan9dTLOV4rOQHiFf6M53wqMpoL91mo3PT9foppfKx
/exoOX7I5bbXj4qYykfB5z4R/Lu6lB+7+Rd08wHxGNvN1oYKLJjolcCwHRG2
YKQd0wXtKXQyqn6GEi/eweB3P2lO8FaSZGy25zobYTUDk8BE7L3sNuF4g0gU
BN2s+v2OSXOsNvT7Mf97o/07HRX+fiIpTa5N/J46OkLfDRjOpqZE7EhyPZk2
nuqnWOrYgzmgi6MElYbmPQDQfKSaBgvYVHwvl+0nNJF4CUc8boHJ8cobHDSx
RgGTDCxCZhpgI36jF1vNZm89g5mpswWY4IdEpGjQfHgxvlbYaQy+9sjvwwYz
wy/cRCaUm6vomsJwDKA5tee3826jd3HfTmIpXKgO2tPAFdu7I0vYtG1+Vegf
n3sD6SCkxXGu5Gs8uJjyze/twzDfuAT0baVasA4WdPAVsjFDT9MTWCV28Ajv
/HOHBWL05Rsdp0RPpPHgTuOarJdiAJ6mXYyMCoKhRJnh8V46bOOmqWFwZi2G
3/Hj72xGzFXETCbrHV0ju36rdRufcSKezxQyAdhtx0g6SjVxiXc3iWbDZnOH
XmBQh2lFGQF2KLULpNHom6HgR0XBlUGmCC4P+vnfSeuSmKmI2eyPo3Xlg7Ru
3CvmKmT5KVpKknXyfCimmg6y15aKlVKhkAKLM5PLZygdw19IrgKyZibMmpg/
pkhHCCs+koEjacwNSYG1LIn+3cttiVmbf+b/OeJpXMHa9phhGwtSLBQz1ejw
4irweA14mCFdW/Ku3iFyJ7DxzE9rg+F76I3xwwkWSwj+NjKlOVYz3IdjKVst
55LgiA0O/UDICIaS0q91t6DGEtirOq4V72/Y9x+fyKFZLz4Gg3PzfyG5sknJ
lSUUqzsonkpjkP5zpryH4sT/cPu3eKbLZj6AITwMNdiL4b7Yiyjkv7DyH44y
5tIlv7164CViCrmETujubuyFqu0V2o+3z+1vv9VedxUaHki5fK3QRHz4cqDQ
aIFC458uyluIwYklplLZ6ltHR4AQ6JoULrrH7FO8OgN+ug6VB2Xp1A1dneZ9
sCDLPtYV3kb37UWUTsJ44DMmJgmSsoWS+K0YJh5xYEwGr50SSTlJ6iomT6Vr
xAcHXvTlqwv3qIdqW9S2B6EL0/H1waQB1V92k8jx/I80mq2hcfj1vcve+65x
x1zh/rK9nE7RikummZh24dC72F3ZbYCPK6myEL69vXuhu/j6MndV+FIUYvva
ueRdjvBwc73gJz+J6RpDTMHjZy9raCj0HKMDVZ04FEjKNfdj4tCJigGBWKOW
QmjpVYqbVBSJ7ODt/nCfxFMhP2snemB/cFCzw3GCsZHkhH9sikfgfgdD1b0M
rFvO3CXXq+RKFgsl+QAuE0O5sD43/dXXfdKTj+y1CffeeQDimSyz2r5yToTT
93qkDw46E2FjujwbJ4/WnZAxzyVtbBaLnajRBR2lCFgIzLUFNFYF2+RScsWj
quUZk+degtjXmYteJS5SeUgkPPZSxtQ8b1y6y5NQAce9YslhItahWjGh45Jo
luOjI9//hzk9rK2j7+gIXX1HR/spwznwnzpb3Ne/5LQIqRmmIZHFP4z4X355
lcIvvlbdltGTnMcef+aK/RsMR1enJOx4DvMYly/PXw5jhP0LRx54YT0nNRAg
fOKYS2X2UmLneHVLheSHHMdRjuZJ6Tyk/GHFD4rGoVq8ydTcHUMedmr/1PS9
s9c9A/nQQconDCK6q/klxYVBOK+sfVDbvxsFYe2RNLTcexgrL48wCPxoZ7dC
TD/OoCRZ3sl9WIXPBHujj7G84L40gn/7yEkpT91PZ6VI5InDAn/vKxTeSicV
QgPH84W2UBGj+hfMEMl7eOipwJKfAGtP1sMvpqVOUXXBvQL1YVShxEyBe3Hp
9pDN77oALcVM6fAAi1zgnTyekvquRWmdVFldYHb6hYlODkUwMXLf27Mw9x3f
qcaw7yWRGH7GM4nUcj6buzKKAG/zs4W+fLNq4qtW5HnP050CZiFR5EkKAJCH
1rQsWDoSioBD3oz8w/xUPLg0glNlTzYpog7l9Y4SxvZvm0xcXlOBOw/2JhTE
m2RBdUrv/pOFRUq8G1J40dDLlefnMZ/5merRGuGu//iE3zSQkKUCU8Jxr1Ec
OQdkwfSZPJe8Z5D5Oc/4oI+OFJXfqgEu9u/18URtoOO8kcDMpx3v7ujo5o1q
ENiJ6thMm4RzsOPlImYZwSrZKS/y3uqkPnHjIw0+POVqNJk+fbi/UEU8YiD9
/ISLdJHExux0jfZOMrUvv0/Xm98PebAc2IzRt2PmrFBDkreJD3l2Skxn1w7E
n5+oEwPvvvw+c2zZh0jG9TYyD0uLBK10HNCU2Qf5lFDbpv3cgSbFQgulC8XS
O9LBQY8vdcwp5920jb8cgzC9ki5kBwVlVHp8QqiMSh2DhTXeTQuX4OH24CRY
lsI/MFmnfwBGkbNelkgJQw2HA79QmOXfQUJm5hc43/ZtpCirYBgBGE0zVA5T
wkkd8GkbeJPayh7iDMW0CmUC387j0KP8OVK+lTvEmfkYjPD8RaHkD/fNST7R
nHRR9PZ5ORbcGmvh3Jf7yhZ4FVeiMd57ylDEZpB9tYHvJBgUd/OYz5i2sIOE
tjyiNevjh99jtGeQpnObM35fu1y4XYcnK4zJnutlyH0vBSxlxd1ebN2mNQzd
8aPzup4vjWL/+WObylX4OXucOy4cl6IP88fFY3TE9F6PGh0qX0UxvodIZ97X
/l+CPzHbXVb4GseqJOWgxX/9P/+HB+y//u//PfoXhJJ7B8pcnu1A4X+LQsm/
C+V34Q0o3l8i9y4w3oXzPkU976ylcipL/O7dBCx+dGGR9AxyZVJmSs9/FSy0
+DoHoeoG27Z+zaT957NxJRB+WPmD9OEPha6Z05Szdj5eZOGHFVgID/QHQI8M
dH8Zhx9WwiE8tB8APTK02EIRP6xIRHiEPwB6ZITvlaL4YWUowoP8AdAjg3y3
2MWPKm8QHuQPgB4Z5IeKKPyw+gjhkf4A6JGRVlJhLQK69ctsfV6/PkQ+rB8I
PzSwPcdHob3+Z/J7B64nmNxTvhHbtGO/9ZK2ebzY4ztGQIW8Q1+3RrpijC+T
9MPjIFnDN7KPxagDaL2QQqcWaHThZc05s7Y3hhRTTr/VNH14zFOv7GiuIXU3
UjzPdqdgIzqe2Q9GPhqis83YUv2U92h6fZGjiyBWCfZTJ+19ffjRJOreQdc+
05/nS1KUmBKT7yEZ1tGxLIax2Vr4Y2awiRo9f/7vntQUcphXAi56wnR0tK1b
51kV6FPH2Xw1jWHGoC/eG5ZfW8NrhNyze1g53pA/JeSj9I7IedqjbQ3NSDKT
Ha/vJ/DEq5KFZEJHHJBERDqXIj8npRhSOCE+goCYKURweBddz//EPXf+JMEP
02J6EHoQ9dySSy/1QfFzUTtvcvEzUHW8WYhDgpFj1RoZuqMv95Nc+KbBhIuW
9GGuxEei1yh9+FEU0QQhDN93twuhYNy3PPp4zi4Zc/Ktco7yrx/RtG4vJr3v
m0de7r+un37Ew5ePCHjoxNPGpGQbQcEiFZbp2n5hXUAT2T8IKj72YllCEScz
dTqja9IYKaCEApa/JwBH+MLLOewEFf/jH4c8qUyoXMDR0bZgAIgELBlwdIRR
GngOREUDsAROS116hRgQT16BUfbCPYIgqF1Uj/EsGjYLql+iHHjechaK6OBX
OmBFouPdK+4aJ5C7N4PhgWtNefwLHhHHi12vfs97TEhXyXP0X36m7b/cJiSM
lgzgJWcxluqLl2jBD8gIlQDAEwJMqeAFL8UMCyWu6pVK5VnXaAlieV9fIFiq
PfeQ7QjS1KvKwdArQRnd3AVKYzvsgw7XgKnt9OaXwArqTUtj2ugMDptsrm1V
ai/dGKaqog0saOWlQfN8YuzZJWFPp3NTrFJl+BHzXiojQHZD53rAcbA0I99w
cevVlMdI91Cp1hBWfk3QY29R+6U4gZ28Wpq2L+UljQffBAVl8DDKUHiGO+Zl
WToO+gniJDg6FDyEiQPlbdatMc2bpQIlmMK1e7+1ziQ8GwGhw6HjdXN+JZPu
ygcOQy8nhs9hkUMQ+JhOW2Rv4/WzLCKcMSWd42k08B3zF6TvevWPCcKMtZ1e
zxkbUMDPg+fnEksJg+BEKnqyvpvpboxHDTxBgcQlGGXm4lkDvRklyQKiiE+f
RJy5Tdm2RYtGAq99ng6oxSOj2MTPb+dloyRH9DDgS37fhuvhQ9PU0PWP6cRe
FVkL9I5gcUSKeGO8AFdAthudyhjVKrPwEj5j/j5HBXHS1QpsNcX8oV+WbWfb
3FZF4sVKo4W4/LiZ0OkcIM2PHb9N1DXKfJ7akpfW8n/4lYHi3csfCiPhnVMC
DFFVRF5eN2QlYWocKQ24HPIDPJN85jBtmEiQsonw8kRIacvhEY2AEwrFCdCI
lm+0nNE7PnF/GSDsFNHH8pQdFpw2rkLnOljKDpkRCIcMi+WzZl4qPF4vJzgb
JbDEPrhqQ1kXtiW4YWlts2/+882AR2o8w8erY9GFtZUJXurY19jSDEay1x4H
8iBUTpDug7xWpg4xDy8/KeM87XFBsIDkYAtAoUaFjEm08oyoO6kNI9ODEw0A
dL9AnTwzVZl5Nf/QtNJAMwlJu0CO7xkjTtoxV04CdSTKgSvCkwdeehvEu3WT
L0Hx+xrozX66jn86Dtm/Rkn94vLFAHW2NzjncSBbhTV1cPqKN74eHPyvtFsH
04LaeTaVP44swABG6GpaQwUJz8Q20zQdWBP5SvAuM04wvwpue0zDzR2ea5q6
wPyHII+XjMq0bzUp4Hgv3a6XjRMvwDFKlopIoF3rGhH7lvuHMXw8KPG9I5Kt
3VwJ/OhlW1qauGsPkVB63/G8oY7HRLAFGipX6zl99zTjhsdrKRYciXrnUovt
CTeW7FS5IhkIQ0ExaW35DgxVC1L4AD4Bi0YrOAazxOtz84SltncMvs22S1Qw
0EYCgvvRBdHXaKP4BfMALY8VUnh/TNYk1atOr0uKr0H69c/BQJm6VpBEEra/
7VH+QehUPzaK2WJBJXUnqDO30zSUk5ufxVVeJesWdK6L2cTboCMwfTGTbPUl
HIcUWsMUMxupxUeJdUHbnPJzWhKeLpdnWJoQJ8qOoEuF3/m4t+pK9P5ln4KP
Dravo2E/XqLlSNV67oLYS6wUnk/jx1Qh1QvTCN1twbbNwVW/Ux/QvWXC7efd
66oHwWlmfCrTUJ34rZXgn2nSQgrSx3EaYjyJzIKa8bsVazky3aDcrY/HeylV
Y/HYamHeqXcA3o9w9tbLQS1S+/QD9PbjpriaWltgfSYxl8oIFyAWDJvxgAmw
AiWhjmIQlNsgVsVgq+3tXtQA6TPAcsJVcsnLqYBplabMd1r4u/QbcduoamL0
clSxoX2Buygs/R3bOkWB1ChH+myqYoBM9OIUGQD8BY/q96+5ITelM+V0ppAO
+yXEwC9hi5QUUAzsUVG1xbFlzplBCjpsYaIubUQQcyJbQw/pYq5UyhRLh4DR
lzNpIRkwz4fCtxMNOKktOZdAwaE534RS3YzxFaxlJG7KwXdpL27VTmez1Wq2
SMB8mmuSMXUx7AmgtsmZZZjhbXkWPKOxRqKuV5ItYiJ15CnRMcUxo1FgiQJv
oCAIDQXWv6g6MFQDfbW0lYMUm5kKtAadTYR/EaVvGLSDxwGKHLmI4D2wUxhc
xfiFhKn/NCFCaVXJlqqVYrZcKuR/VX/JZjKZcrlUyuVzFSLyt3BSsiD2Cskc
ykrG/BzvFk9IFkYhGlbpXdTzVMj0ocdYl2zttJiBAo8nDgxxGG468BptQIZZ
Z+k1jXrhajZLB76miSatxK3WKqqGuJ/rIq68wBIjXBqwgjf+MPt0+ybs4ISX
PnN7V3MQj+1Fz+jwxAghaN/gSM5UB+YGczPAFIoUVS9KKqfGoI5pSDUlusRs
eYUPqbuxpbLJmwvKIpfk3iHSUkKRIU6QC2kr4mSjnjNZ4dqVDMfVw4vHnNop
SsSAOhVOb8qdpzNZ0ftU7BgyTtFWcoi4cYroohLnjC1EHKuXHB3GvHljTmxO
Ga+IL3Ep+pNFmyZTnRoOtaTaF6QD06LtuyAXJeMQUxR4rHkhjXdI570BuZ2y
3DSKgXSxXCgWiqnFbEFgWgw4HKHQcEGoRCH4T+lSaCxLqcxy4QefajBjQFRw
ROuYLpkk1UA1Qj5zvAtmyCwFNqaUko00sniaX4gviyA2+YYFrKxObHntVKtF
4KxsSuGXhXHWkEqFsfoS9cPjEy6fMLAYswSAVixOwO6SRJiLBcoAkK6KK6uS
CGrqG7OyQ+TOEMi8c8XdAfoGdFVtW2OKiXe4NFU0JHsGf8xpgc6YPXc3ruhu
pJelqqNfdhlZIDt0svUXRQ8LPdtJ0TO+9NNSJWdq1Wpml74Ymh4WTogkf0YN
CU1O1XQhDYIum8nlAmqG4KgTZkxDPp8UPeDXetIV92ayyfS6+nOTT4I7nUqG
a0s7/fqPOc4whLfYB8WBqTFxoTryDDdBvl3gMqDgZNoB8ZesmS6Qa2WKG7CA
bfRkeVsIWrYTNYrO21nfFvgNfJEOvqUDmpARuVeW8SNY7MNemKoTTjBgLzR6
wjekNf3Cu9nVXLGarWWKwNEndbGYyRbFk1q+IZ5k84XySb7YKFUKBFGTlmsh
Onk0bfg8NXN9Vk7vSFV+Do3nnLDLgRwV8YKuiMH9b+8AfATmzN0RFfCEr5p0
NlMoVkrFar4wyuZymUwhk+VKRw9NAVoNhJyiOpG8KMGzlGpxZntrE4ju/CBS
q5NSLpcVcyVZEsu5al6sMlYVi8VieZyXM+PKpLKzHC/Ubk+47V1uu9fAkF0u
uGbir8moQuBvOl4yTo4KTrMnTGCHSylsubPp4SPiXzs975R65uVLb00NYFMA
4oaoSL9T5GWR1BQIM8LBnyWgnYiuoOjOiDjYfNugy9Vv7tuesoh2NfXewssI
LDSJyjg1xQQBzE3beA8CN5b0r88usza/RPmZ2qNuktJC7aO5fGTVkjV4T4/T
Ue/XzwF8giQDTpYGSnBYVQw9pBnJFTKV8m4USmSnxmMbEb2X29wfeHHEQA1Z
MkB9g2+t4B1XEo0nEO2BaraTjYJeUmoIzMT6iupiUPnqMHw1LiR2vSek1xEM
70whgjZoliibEKp3eMB1mbrkRn1aMn8A1ODAAJmlTwGa4BnzIWx3uAmIJANI
Gdo1vSe0ISsqxp+kS+UdAS7bihFVZFL4iNqsmLpWjVEhly+XstVcGjMJTE1r
M8rmM9US6L/b3k3Ymh2a7BBZQg/99C77+JUzNpdMHvPSYR1hOnStuWrPAFO/
FgnoIGpoB4k8pm5m0hgzxeB1YxWER3QVvYGDKoMUfJE26kScS5q6MS0+N9J8
HNay6Se33kIal2qENh3YlYAHqchKMMOSAtaKLLzecvkLkctDll6BZgDWL6h3
E9gDCRzozGhxMTBHJQaEgWGgBKBjA/oNG+7UAjgSVWaijD3ilIEdkC5VS9Vs
oVzkC6DTdTVHBVMofMdc957xzc4TdsyAZScHt8qpxBwYemTyBwpkfyurtpY4
nduS6zA4dd1+to3diVxRPObm+db/6LsUwSgn/xzejwfFSEIvoTSP0g/3L+jS
CDQHO63zbxfSfPSWDo1H+a9MavS4L1GUlAvlaiFbLObLlXwJOD9TKojPYq3A
p7JvKpY6NYUTC2hkvouNZY3pwxHoVlxk+Ud3XJKTUwB5xjBFJA9szHR3ibAo
VnKwq+ZLpRKgU8yJ95lakWNxgmdyPQtMvt1kSntwGMPHsJPRx2KhUMwWsrmR
yXkW8zA4pB+9pXJtsSlUy9lKrloA07dQyIiriZr3TVPTgikDyxeIOmExCIHC
ZNM3aR4CF1A9DTp3mrMYNzM2/2oLJ4POwcH25ylTiMuu8BiUX6zca3Z/OUGv
ki3pjjD5z/+whAGq1daMYcSIgffqws1s7vaa85x3O8wn1CULTA6hrWoOFgsD
mmzIaWYLoNjNmY0hGNw1CLgeQytN+WdzAX3l8Sf1ejTUzLtg6WV8CTLa8wgJ
2CxA3GhCSMh5gSD4n0hFLPSAk8caveMwLaFl7gca+AnwD3iCf8rwzhw5dcyd
hRi0QClpgjQJ441Qr3sdAt4Ua0NOuv2JAPlhXOQoQrX9YwLmFdTY3vnA1C11
8i9yzwU//UbQPKInePym2xQ5hVIuLBjoGdzFgYculJEygfeYYrfSnf7wNJCg
kSuunv81+MoLqgvxqJevhy6rjDc7KRv9S7HBnVfvQ+6eR6T9N6iCpfg1W9/n
G8aDut0P23OohnDwYpM80KolYEmU8Fm9X4GSW2xc8iDR9hwv7fN0R9D0L1/y
QxR+SIEMRGXdvhwdUeVCVMSOjqLf49mVF9IW4yA/5MkxPlZXAOMT0yfl02zj
aWQ92ZVO5nya39QX+b60yNyzZvqjBQreBXSYECmpeVtVbk5Np3b90jaUeS7/
fCKvToZ5yU6GVBygpEjl28tMM2tP7u3l5sTRSrXpQ+VJHLTb6ioZUnGAkiJV
vDgrqVV7aerGbLHpte967KlbnnT1++tkSMUBSorU7ejhuXXzkJ80V9LparWZ
1KoNe7ZoMyeTDKk4QEmROjsdySu93W6OrbPRXfG2tGky5+7OUNVCMqTiACVF
qjeqPww38jRz3irL43PJPa2J89vpfe7JTIZUHKCkSD2ePZ3dLx5Wj0Wjfqu/
jO4Kp+ele/W0+ZCQUnGAkiJVsM38xbp9dXXfHmRXxnLmmuzubsrq7XkypOIA
JUXqunSmy8XKMiNntcZt3n3qPGRq9yNz0qolQyoOUFKkjEKXFa979eVqtpab
Z4Zyx3obsEhlMyFPxQFKitSY9V8uL5errjqZ9ydnvcmayS2zvRg2Ekr0OEAJ
kJIn8Oum+NBWqlnt4Ul9rg+d6snj5rZxecpuFt0PI/UuoMR732ndLJx0+43B
zcZYXlZr12eS03sy7qVpwr0vBlBSpFbj0YNd7T4qVbdqdnMnc7HiLMuT5X0r
IVJxgJIiZS4rE7EsP56fF/uPYld/kkud2e3gRDxNKBLiACVFKufeuFIj29hM
ny4b3UJrOBKth/FqqJ4lRCoOUFKkFif5qjS+zF5b7cKoNuyOmuXKct0buuuE
SMUBSrz3rc/r626biYOa2q+6s6srTbPOC/pNLeE2EwcoKVLD7Npd3Jysnh+a
J4N2fXg/HbTvHx3l+aWSDKk4QEmRmvVXhdLpaqrfKmp18vyo5yZP52PNGHUS
bjNxgJIiddMqb5qjuab3B+vLTa59X5q8uKem0Xj6uPB8F1Di1TdbsI6msNNJ
s2RWn0sX1du5k8nU6ucJKRUHKClSUzmnPmWWY5PNBiNxmc2Ig0tbW0uP9YTq
cBygxMLzqqDXJs/F9tnjwmk0Lq2BoZRfGsp9NiGjxwFKitS9eyaPNs2zXr3b
cR/kZe6qW75vmNN+/SYZUnGAEutTt23NGJ92mjNR7l2zrtu4vXpeFx+WdwlN
rDhASZFa397k6+XnmytjKquL8knh8arYPbsZVu8TbshxgJIilZ3W5d5KLF+a
i0b/5eXkpZZXTjtTM99PqOTFAUqKlFORzPHLSb5c0O7Uixfr1rrqP5TnrYdN
wumLA5QUKT1/szkp3V9cv6wlV2ZPzZFZ6RmFrDvoJEMqDlBiOfXcfpbH4/Ol
NDJbTfGp2Xh0c4X8dCIm3JDjACU2sRqV65Ps3e2F6JiX5rJ1nRvOSw1dZ82E
20wcoKRILe8vcwt18lhs3cv17PpiNZhc1I0b+fQmodMsDlBSpLqt03vVGFeK
9wPpYv78dNKc6SeP9XJPTshTcYCSIvVkV287hd5JZfOgz6a5q7H0eJKVcrnJ
RUKeigOUFKlM/+Wq/3I/ulW0h+LN9ah719XXj5phPSWUU3GAkiJ1l++2sydg
rI317N1Nb926VmdSR86+DBPq6HGAEutTI6m10fTTtnmhP1+WT07kh1uzLVqX
ia2ZGEBJkSoPHgbuSSV/rlvV5/o4e5s9rRaM6l0+n1BLiAOUmKcGd5Np7uGy
Wbtyzq7Lj/Yku9YKV2LtKqHXJQ5Q4g1Zn1yuxPGqcm4rZ2OtYEsX1erpS0Fl
csINOQZQYu/wRp20Ki+9orQyrfFokL3sV0+bN837u6Te4RhASZGqP6yW3XLx
pWQNO0quln98XD6e6e31lZpQn4oDlAApd6LDz1x1ffp4X6wXzEFrvnisLe+H
o/LDxV3u9uPz9z6kpLRys+31w11VPpvcLtR8fVJ9zpTYbLV4aCXc/eIAJUVq
0BrVMplsSRLPu8Z9bd5yujdrc/6oPyVk9ThAiY+MVmXx6i5Xr91aGfH65KVa
ZrXu+mRkdBNuyXGAEhvuxmYsS5Plda4hdmY3k+FtLle5uz69nCW0keMAJUXK
0m8v2en4SVrnSlo+axQXqtPurK+u5wk3mjhASZFqTGdnSiu/sce90/PuNavI
Ly+iI3e6zwklVRygxJR6vJBkVcmtjKYjna0GY7XTmTj5YeY0IU/FAUqK1Gje
PLlqXNrDu6eppIyLa0N7qpSU5UxOqFHFAUqK1HMvf1/PdCXr9LSWH3THJ4u7
uzNnXatfJmT0OEBJkZrPn65namGzPBuptdWD1VtlZet0JupiQp6KA5TYnjmZ
K+fO+cvQKZxWs7cLa3LeMZSpPswlVF7iACVFqu26o9qpm82eDC1lfZ7vVGb6
Kvf0tKgkNNzjACV3mxmquZ6fjEbXj53l7NQoGtJd6alz/5JQT4gDlBQp9c6u
12ta5eFRXFwNa2Vbvbxp2RNNbSekVBygpEiJ7Vbvpl+sL93bO/mqNs2X5cF6
ZdaGekJGjwOUFKkL4+KhWR63rq/0+vr2/rlkO+qVc76SswnlVBygxDw1GnfO
ZlfKSeEpO80Y8su697g6vXfqZlJXbAygxGcOm8Lz7fXZdatfyYlje349uml1
SirTsg8JzxxiACXWp87y9ujh1JhUO9eV8nCZk7PPhUm+tD5PyOhxgBIHltyd
dx8esg+tbDOnDkbtzXXBauhXdqOVMC4oDlBiLeE8azQGbFUb316MVuxqUa3M
jYdHeVpKyOhxgBK7OJ7cl8yk81Rxnh5M+UZXHx/v5cFqddpOSKk4QIkNhwf1
tnD+eGnlMhYrXc9b+uZukF/0HJZQS4gDlDgE52G61rPq2CktCspFeX2afbhU
tMz9YJHQmokDlBSp0sX59GqRyz30163hw1hUxZO12m29dO8S+vLiACUWCWZb
Pu859xeTk5uH+qN5mTWMqxLLnooJGT0OUOIYjsFm3K6qM+Py6bI8eFJms4fR
vbOedZ2E0xcHKClSyqhVscoX3dZTrVA86bH148qe6HrNOUso0eMAJfYliC9S
pTR6OMvYi9XJ/clqeHv9slKv6lZCX14coMSRCYVOV1nW1xVt0Dy36upZ52m8
OKn3rUJCJS8OUGJ9qnZV3ZyemRPtNrtqrFbyrFBU9Oe5vkmoo8cBSqyjZy6e
25MTyb7WtVL1Qaw+aiPjaWI3KwlXXxygxCJhdtXSHjbyaGM4+nKYgU1irSna
SlonPDKKA5RYSxivLqqyopUmai+zPGlNa4Obm4Yu9TYJlbw4QImjXRy2ao+7
rfOT66vzRs5+tqZDy1jUr+YJfQlxgBL7p+zOU8ksryaF2f3IrV8Us8P6cCmu
TtcJRUIcoMQSvSRXGqXeSaPPMutCo/Z83807hWZPLiSV6DGAEod1WSfFfPls
5uTmzYvb+sAa9ucOSJhy0kDdOEBJker3jPOHyU29Mer2V/mZUctkXqalSmHT
Srj64gAljuHotkcZ++Lipthlc7NpvNydnxmdM10aJHQvxgFKilTrrF7LZ/Vp
jc206Wmv74427Vo2o533Eq6+OEBJkapOxFz2rHtesrM9RTbHJb1nZkrW5UpP
aGLFAUqKVOX5edQ6Hear2U5z3Hp8vL5xHrpXl/fVm4S+hDhAiUNwXtzcjVbX
HrrzVmV6Obiqa+vW2XRlXCWcvjhAiFSTJ134miwaYLK+W/Qdbfjca2r3leV9
YVlx1ctScZhQisYBSqxYzW8yT3ejdbt2mq1Yj7rzeJar5RajVTuhuhAHKHGI
wqOuPJxfa5MZs8Yzc9Vp6o/9Va59mk0o2uMAJdb2Mk+lm4XdGNXZ+LnX617O
G2f1p83guZmQueIAJUDKkhw7bdsN67F/elewS/WB9MBq1Y7ezvR619mPL8N3
ASVF6qp30hndKWLfHL68KLNiI3P2aN5pl63OxxWrdwElRcqYWIqVHVZ7yqLU
GM2fck0nf/84F2dXH7e13gWUFKlpt7t0etnOvX1/Ohln7otGd9YfShcX5sc3
wXcBJUVqI7VaBft2UljUJ2eZ9mWv11/m76cZuZVw+uIAJUWqIdWyT43ry1Nx
rFwV16Iyvx0PXrS23Pi4YvUuoKRILZx5+/Gm8TIwH4xGqV980YxSW25m5WVC
pOIAHXp5GTFX7rWL6Tuo7HuH0g5bzrEwAcCUv1949l+HSrpbkmrz+9C71W+h
AWWssxy8v4qZazGFJl1XvcOMnPvLlXiVSr7w5CrCv8UWkPEy3NvJSph4rX49
wGoZeJsaM0erhksZj8P5qm3/2jmla8VMV5R5HJOtYqGS+qAmspPe6T/+AT+6
nWG/KdYDSOE0v5iMGTNXq1h2IVQLcrdMzdERjfro6I1RPLlA/onKlF+FmwAP
ysSJqRscVX9dcWC8zSqJF59NKnET+sbCNIaCqlOCSodhcgsqTQ0DMRhPSt+E
b6k8At2KH0IvX6ko4regwEQ0g0CEB4F30qriFQ7xajjBJiXy6V1ifXuYtEyB
0rRg6kxKQ1MSc4cpn0+8i/J+LR5MxUzDAP5RpwaVwrA5/aw9RTz8Kh67ZTy+
UJIPgI11WQx541PLy3fFlMNfqdCO4pWFOTriabn4XXne37Z/yspKFbNxEjA1
r6vTtX+eVHsXNiakx0y2P5SIhVQuVSAytoH3gnT8mGaZJt27m0+LEHAG0hhM
C8ohqcbS1JZ+RaRXhZ1/Jez//ndMUN2v8Roq2A1Vx5YEohVVgYhUgxCmjKcv
xVxKQCosidPrdBr8vn293emN4MevXCK1XFXBlHrCkK0dlBpBaU+sEIL0jBlH
SjgFsYgP4LViCrYZJABQjYNo5t/X+dCP95UmP35diRxHTSUFVFgyhBVPf0BF
FrDn0Dj9JEBezgls4qdPOPDLFcdiLexiTcg0lSnToDdxsAEIur0PKRm65UXI
5RnDPL3bihLJ6BQZfm4PSfK8+xNeM5x37hV0jzCQ/YGRHuz06+e0EjFZhmaH
eg/eTM19T5m53P9Y3/fYcuQ3HouK9NYbR3Zx5JgwI5R1CDY9B5Oc4jRv82gc
UHaIUNYhj2kWsC9hjmEFNhmeXNvS/ewXrxJR7M888V6ye6GL2UbUUEaaFWbK
H/sZ+01erwNTYiwsTFiIybHSC4mX8bH8FEjR8t11LxG55GkOWDPar8ngF9Mg
+Ui5wxFr3Of8vf/tne+LNJcEKqZ1uJPD+AQrNFMxFjtUugSEjqFgtoxtko1o
4ZXxNrU9vNMoRQ4XGrx8Ccg5nifGBxRk+6Ci1jGVLWxTc3kWdAH0Jq4FuaCU
YX54E/PZz0wvw7NmYgJfnmX2VZ1syhCCWoamzhnVPtqpjI1o4khBWzJ8IDDQ
bQkqr+YIZmfnug6TbMwmP2ZCkANmvImWIQtSSadAwoJGB9KWAZWWkRRZlG4G
6z7AZMUPAr6BHuTNGHjGb4+sjMIOEzB5ue6BpRBTP+2KX2nieJt4nXL0+D1j
nT8s/YP5cgwaHuo++K3tjh1tb7ZxoQmTL1ManiiHwr7+RU2xFE/fD0oq5Qai
RSVhwXMv6wrfAkNs5K/ZY3jiJW2hekk4HspSxTPedL2alaCkwVYtDKhm5TFo
2JYq6bAEQXxJE+lYGLqmDlpIzbXgx62Ka9/WpKXQcMdsMzePhTNMFYjNmHAm
yaB9gzY+MI3p2BRO3GOhPmPGdA3ItV0JdY22ZK4ww5WJP86ljSQ0LVkFnsG+
bRsLXKiSgXnB1OkMxT8ndgfrOAzkmWXK80PiQebRLSyjJJULo3fTkC/gLc9+
RAnJqaBDwHSeBuTnv/9OKebX7guKOWENEtXmfPlW9nQvB9DCKzYUU58syPvm
icJwK94LygwgA+7yHhd6NgX17pfpeJWS3s9rRHaU/y2ihiO0pIWqeIWoUsSj
3hipDLlCRRyCBR5aMds0Tn4Bs5QwBOmoGjBjLwHJ/SKDIPAVqvJB0Gkl+mnt
gq727jg+HErEtMUPIcCGbmFRSIVkqMUwP7/kSJwngkc2KSjb2eMtvS7xKyz8
DNTYlvrAobk6lvXwH1MuM+idyqj76iBWfcfsl9uipLf7p7+2Tad0u5WqDdwc
7IOh6ZkZdmCvhorchar64RxSTQDgR9KhtuREMpAI8LJxxvFiKLdTSMTTTrVb
BXNfjcTjD5aePI4tlQmC2UaDWF1y4w/1tKBkAaOsbn4ZIYMsJQuzqQUcg6wH
thHOoQMU0EB+CpjNGB/6cGgO7XdEZr1eF8Ll6wadFpdNvtaUEnrEKWR5Ivm+
YLkbtp5JaBNjdVuV5u2QahFavO4ar9S3feDV7CTqc7PK/8b/CV9QYi7iUtpT
0X6hjXe+O2vvF5Yk+viVKLfyhGsjIUk6cS3SO7wltqPBcAwx/6anYqKO6Q8p
qDgRGvY/Dg7+oK3cSbdRm/gDzAHDZfBnA2bwi41Vl4PFgyWfRdiz3/wvvP92
oRruGmbA1XFXDyeiQwMplLV4IaewihMojfRHOpehGs89S5q6sHTqL5j4X4In
RbEsXMmwnyEA+G1r6Mc5FhAtk3faqhVabSFbwIo9GjOwNkyX82TUVJ5KhemM
bGXeJ7YQF7wF9T6AJtICdak/hFwFFNeFI+be6z2cCW/bnw0Ma6empjn1EpIq
agr2P5BzUjalOmlmm5Yq25QrEbvug6p/LHQcENXwK1sQs7z/oOdvvOvoiPx9
F1MNUpbbUJa+dCFbKGRLuWJ5tJMQDvPBjaKW7KgdrpWFL0eqMfKsTWUExjuv
+f2NKrT2a8MB6K+wyFXdX/7h9NF7isJ6X6VV3op3jS5HMZNP+xmE8TcS41a1
HBckAhLiHSok7wxtbNCvNDvNYYn7vqKUxJLorTs/TzG9hOXDNygRdy3xVd1T
cUeMi5nM4bHwjThmi/cGTBw3NWbpTXE06GfExks786vzS65Y5ITGOiQSSBBD
+E341u9cDYWBq4MU3GUzegjy2nREk6dsDliqBQsPS/seC6cWuUf+EDg1GS7O
LUkdc4G1EDeGuQAtYQsbJC+wsGoAsVITK51bLMyplZsMB+eu3Ten+f79uHf9
K2rdPxOIbQJrX+NArSCSsFgK5wFnysyUPbb6tBHmxL1j9AsQvQ+XJ6leYFJy
y36jqjzO53csx3y1UslnSiPfIB7VPDqNzElkrY2ATtsHzUb7qn4YkTkNVJoC
u/oOK4MNsAynLnxpDO4Gh2/JPfSrj2z6Ms1rbfhJW9Fy5vXsWpo5hrUHxrlK
NMWtqQV01kFc0a7YBh0NRO0XErtvdhVdx7kC6FTTPyXM8sVStVguckk18CXV
jgKHUuuU7NpRq3M6ajD0vI5gCFH67iuavqsR7Vm0rp3Jrdg49WKaesrFHPdy
mrxV6Zuaka9kFaZKotS91J9a7Vn3eW3KcrYtb07Lc/tCkxg7Z5P1VWE8qOf0
du9l1bvuPbRYTjEe+6mXicYe6rruwL5hji49cRvJEVvrCD2u7Q7QVeRtcSgf
SChnw6sm4hn2xWHWWza3KjMMsCRroBFZtMnmssKZi6Xf/PlBJfmjB0cAFskG
ii6z06YyVUZrffZ0fa/2R9LFg/Ls3C4bZ+y08L3LJlMtFnLZ6qjn2UmjfmsU
JswoSJ7LJ3pKFetGtQ6n4aBZG/4YIiXaixDuq60HHnLu81PsbwvaoewENQ/e
ZTKphTKJ20NOx8X2yyyrL7JN2EMK2Uo1vFtDJ7SdYPFN+MtisRHaYLSE6KDO
1S3CzIjgPPM3IvobwniDOpkwdZA82y0MRvXEwsL3Yz3+vFOPhGqXl4ui+lqd
Qeogbn9mULvrLWCrH7fsXtHsu9fdbfXk/PFs1GjNH3uKZjydSDdso7mz8fP1
f9O6a5tO/7T+KXTKVnfp9DlLb2Y61kT2dL1s8c3aYaC1eFnEI8Wp4hW700b7
rq8+rc9tExZlPlcp7luUxIXvECbgVjtNWAfM+1Fq/dUr8ZNmx++dJkjZ19lO
cbl3ZqTVf95YjU5z2lzBjGTzhQyfkU6z1/qn5lOVLaYel2b2Ej0ZHaaV55Gb
rS7vX+a4XRQyBY8zUZG0Z+YiSoBwIQ/bkOSZIyogOrDoj8LSwFFTC3Rkr8KW
ZNgqfPFWeZRssYjrAIjd4CCEARaBBzXzEkur7Oj+7/fO+CLwgYFILcEUYFns
YAp2toUfMyAi35XrwNOdMZj0UFQUhL2DazGM6ytUIy1p4c4drDWB5aS8E0+s
1hJXXAjkclSoSVxIixJovfwYOO0h/8bWt9cm454brIbhridU3pJ80cjLb1Xe
IDDQ15dtXefxRjiDaQBLA31F5H+RDG7JYUXHY+FmUEMq5UWwHqKEwjCG3XoU
7+xm2UoRTIjKaIC+WDDj1Bd6s2t67adG4PGvB8cYrzxM4ZHLQQvPFgKGr2MJ
HOFSIifklsCnAf2iw5ENeYJVnKJ2VD4j1BaWqsWImA/RolAtVHOjPvISDh95
CU2nHUfRqBZrDr02g/LO7HFm91Xx5PHsQmw9Pxmr1susrBpjzXHPO9ri9um5
q90tSnd9pTt8LJUeKwux8vAkSexqMp7dp+pmu/Rw4s6lc1fKTOcOHjPx2A1V
R0z0hZDJfM2Vv2YyNFFg5GEpadzT8IB3ReWtf/NdgkQqP0Jpj2zZdQhK+D0u
GPxeDNwMXZhNPJg4FuqSISmS8GXJJwRfZsuRGfm+Ccll86VSNjMaYsQCalre
56OmAV2ZBrp5R8N+c3S1YMZo4IKRGCfgz62quV5kJ4qBPqVsppLHr3kN6bco
4B/Ag375igqit0OJHIQvMi5hfQ42OixGFQ9fDFT5hCG6gmz/EMmX7uYkVNIG
PhuYsNJ2HD2mLS5NwoWKj6ZBO4NnOwsgW9ol9x7XzhuQaEK5C2eflhJqxmVj
eqJiGU1em7NAf2YK2dKI4/8vucy/5CrZf8lV3zDPPoIGJ2SvORTrV5e8mEr2
q5AtoiubV7ASmn4FK692OJ4JIk8vuet/298EzEfmpKYq7hd4pGLAgoF1h5pF
ET3d+0tiEUBeaNXgwZJ/COeSpdmWOwOR65UsItKLn8LsKH2KmRz5acCKeMsJ
hhT9PjmfK+cr70EnF9vuXgASEJh2hHqgNzOtYfeUu/a/CjXDQB70DUDvSPqu
JfzE+4I3VNcRed9n9p+2uE8dfUL+/pTNF4WNOwaxh6dy/IqFqH9hNAMX7os4
wKNm+K+7ZK4V9nEWRCB+V7L+7C5QzJezxWS7ADeTT/thhbn4rsJc5McrM2a8
wL8YkICVqCJitPrOgN7RnIv7NGew6CaWX5vXV5nidePO5Hw6vioXLpwCiM5S
pljY60X62JC/UM/vDr38Q4ZOfqXXLvn44c/uy6AhNueXZTSRSuWSN3r0fOiv
PB+fMvF/npMz+UK5kC/n3/ZU+D6Ji9p586/G//tmT0NV3qsXu/c4hU5P3pnN
s5fJxWJszLRMDV0Q2Wz5DdfMpxCi+EMIEfHReAQJQk620YH819uWUDyhrpwr
s3xpTlUb2T5fzPoWsU+f7/PVFHd8NbHkK4ivKPh9fptiyG/z2dbid3h33prX
He9OIkzjZ7OUqxUrz+1stdvBI9VcOeNbda+DR0L787ZSNnwnRje9sAaaEU7Z
OIbPQ4D2Hx964H2t2sYzxzE6e40QqfzYQAoN5JGBfKf2NuoWGAKkkeay/Hzg
b68IggxKRBnzEISV5MizX5e/qMrzapyZnWoz+39gNMwvvQt9Mr85k/NVtzt7
tC9b+mItPjdEt25eb7pTrbP4H2hGlLL2j4sCyMZEAVTfoXjyvj4SBJD1hA5x
5lZ7eO8wZnrTfyhllVu1R15G2JoOhTgXS0iBN22F6dujaBtjvF2NpWlsb7hW
QLAobAkCUccT3G+nV4NGs7tjWu0CRuqegKlpM80+Fk6YNkUD7g8hnxXOJEPM
7pD7tYX1Jqbcjm61W6cn3WCvcoDM+wTHLhQvIIhITXeI7H2QOJR0rgR7fo4b
ZblMdlTKuFWWMd6YHfqZ2u3QVUq5bHFPJylpmU2t2Fj/TMGRKyN1/9sFB1eS
QCki0mVz5TekR8DQvUzBuTiTB+tJ99ePi4tCvvCpUjf/T0E8j2jZ/HtEkwdW
/fFyY5ZH0wREI1fNZ1KtJDSYTFQrvke1HUDpxHQ64WfYpIXzM2ykVjGby5be
o9Zq1LWeuqy96VUSUKtY/VRi5T5Oq0/mMPLqBVdqPaplcu9RLVuSWo+i+agq
SXgsV82RPvT3r4KjOhr75adwfLQfjMu2cdKRyOMEsck//eOAB6HWvJjZIAQ1
iKmFL/jFWljbrmRttgHSQeQwv4PkxZr/U4RC010SfkcNY7/922h0vXbnqoNp
efdSeDixyS9BCxJe7zPwWhHw6iwcefmKzlReeLHA67Z47Wth4eXbyE0B7IRu
p0gTFtyUUC28gGzZX2kGfuYa2xumy+GBIIjCN/Jw3IXWzUfSk+TZ9fr06fr0
7EJmEitphdHl9N7Q7caDD5a0xI+DpVvopen4eZ25f6jcPVjtfHddWF5VjJzo
nk8DsFgY++NQUW+oaJvn9qy6KY8ulqVxVr2fLW6eH6xFppvxgZJ74ONQ0UZP
D82lo5VX0+XL6uxumOvkHlfGzOxcGQ/XAWVrtY+TVZKm6aeTx9t5+WEzWC2k
0+eNUpus7/L5+eVjLxh/DxUyfmcpcoEK5cBH+1r4MMTIJay0Uire9aR65m78
2F+thyeyZgznk/JApxJL2D3FeuTIPOTx9N+cmcUkJfvRrqUtgLQ7fim793Vb
FB9e3MHd5v7y0tbvJiNncI1hibAAPOi574G+bs+eatXC5IUppavLzrLXn66G
Q/Gur9d8WjYG3Xoiwim6Laev6zlJ6cgP87U61Ay1Kcvl6XReKZ3Ugkna4zSI
B7x1F/Q61lnuanT9LF/e1IxuxxjdznK5jn7XlX3o4fifz48ZCgRH/5XgsCKC
4+a02299TcwBvPbE4915xu12q7krZaX1xtP7k+V1bdFYsOL3zr0Htz/rl81s
27pbT1qNybR/1u2Xiv2TeaPpoU0+7KRIU0XXy/G63VlV26P1YvAwnk6uRkZZ
u+2csjv7O3H+QKFYzqidy/6HJQnoYulR5aKZ77vZ9X22NJu2zlbWpjvsr/qm
VNvOMKgtb51iezYmnUPzhR9VsvZNOy4kO/UmnGk6tNWmKXA8nc2Wc5lyNp9/
i3yJYOpotU9ZOg8WCCE9rNW/C1HQ+LcIVvO5bPX7EQzBymUypUqlmAkm4Kre
i64wvLXL27PQQoPPgnMlGI83zNCATHkhSpqWotNGm/cLjUS/UWQw5WwJ7WQP
Si4xFHLPjbaHRBiGxMdWzRTDoPOfBrpQyVfQM0tT4EEvfBr0Yq5QyhdhUjoT
AVRsusgXuuqNFxCXEux3uOrwGIT2Pcr4ATqrd7mcK6v8oqV3dYTfMyRl7FhY
8KtpGsP8MNQDXT/GABNLHfOb4QeRX76iza+C4Z3bFUPeYuTt+bBpsutMxUEn
sGz2NT+k25VCp3ZZe3Vvehi50j+TbLyGT1/ya6t46/oAL42NYcNDKDXZvzdJ
fh+wFAy6QsaUX36agNnEwJiIfsMTiODtQIPh9VrJwuvreMd8E70D3HHoqeon
/wnbERMeW4J3ZRlTEBliLry865IzEidu4mp00Vinq7tenoVXt9G55m/xm8YK
T2SywCsopJ77qQVSPm28PAP/fzFXsNy2DUTv/QpMckk1iadpDz31YFWxVcuO
M7ZnPDlCJESgpAgNQMrDQ76lx05+oKfc9GN9b0FKtKXcOlNfLEIUCOy+3cWC
2CdMNTHVvw6pF+siY2KpSW+9mCUMm1MKC1+WSI64A1QkHPrX0QHCgHBY6DGu
DpRaRSQDk8kHpjsjNz6tMPPJROp0n1y0fVFqkOwE6U1f2yjph8lccv09KA/1
z30S4oZ8R8ibpiYANpDnBWl4SKIEaHVqQZxodetqjbZZ0LH0/b+ty9B0o0MJ
87hr8w5Xd2ZpSm3VLaST+7BC04NfOmDqU1tVkXN68cL6jPCcTJjAnfjiyxeZ
a4FB9Fwneg8sc2JaDtAubEMUHHCREjNrqg3bB+4BX3/3mSKQD8FlpP0ATirO
/aq1HsIJcfe1Ppr3CxYAyjO0LMpHXp5Z01CeDSCjFsGsTaBY/tQ8WDiH6tLv
EX7Ug/Xr6Nn9ZySlmNOV06KMT0izK/XRlb72ADZafodv6tSjq9L957WvuzW5
rsYljgM9ROifkXnciKS2aZx68+zGaM0GnjMnmdlM11DyDdYrMI1ezXe+LspW
c8AcjjEsGr7WbZ5mtmEl8dxXcPQcDJxS0OqyrXjRQOjIgEodrcwEl/fdVmq+
KVb02UPkpjWWxws54Stva/zKtLu/MPCmienuKWID4DjXFYfxaIQ14r7R7ZLj
GEgUyFp0YE1Qx3+U3zOahb1+rlsv0syDeaIIKlHWokWOrzt1bteIBovdt93f
u28lvhizLMgINtbxIJVdO1OIKLddrm5L7QQHkCt7ZzTSML9H73N0gKbL3T+B
PRngJU/4gJO5140XEZXtMkGM1bqNf4qlO4DmguXpAGuSLqIRHOOsLQrpeGaW
cPi+Mp3Ynqx3yO4SHBxhMrvZu3TV29qTBEdylSTPwRpp+pbMvxvt6Ii/fP7r
kV/Z6qqV3Z5sHB7FrI4tZUSYIQMQxq3/0uKHcCHP/8PXbQPNWqz6jNj1ER0H
x2RlTBdp7+mEN5iTjyqqh5hZvzK1o7I/68CVtjWrlagQ5pHKqa8RuJawJmL2
0gWXWwSCGwyx02uBIiSI9Q5XLlBgk+zC11qYYea+Iyhog9AxQryaasBefGkw
K4QYUWP62OvwVI37kf9Xh9PAqaCfMXLtcyNEPyno/fwTP3P/5v3ZL/05QZco
/0bP3K+sZDdQmEF0fPGIgYZl4BDaswYugGILtHWY6xTzK/RW16cc6Ee4o7Va
+KVxUDKnf2m4/VYxIN738VjWf3Goj+RG2lvFrPgtyQjSVmE6bpqIewZ4phPO
ie5DRDSsMFhBIl1JoD9T5+o0Q8GhK+GYiVjuQQH/Qy3B6w0W2r+9/5UrvpOU
NRzcikwXMuV0YnBPbzU64azevJqZtuHbQgl7mW3rIhYIX64/jn/26scf/gUN
aNbPyVMBAA==

-->

</rfc>
