<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-53" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-53"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Stevens Institute of Technology</organization>
      <address>
        <postal>
          <city>New York</city>
          <country>USA</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Islam Aboubakarov">
      <organization abbrev="ESILV">Ecole Superieure Ingénieurs Léonard de Vinci Paris</organization>
      <address>
        <postal>
          <city>Paris</city>
          <code>92000</code>
          <country>France</country>
        </postal>
        <email>islam.aboubakarov@edu.devinci.fr</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <author fullname="Venkat Malladi">
      <organization>Verily</organization>
      <address>
        <postal>
          <city>Dallas, TX</city>
          <code>75019</code>
          <country>United States of America</country>
        </postal>
        <email>vmalladi@verily.com</email>
      </address>
    </author>
    <date year="2026" month="October" day="02"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 346?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 350?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against implementations of early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 13 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.8</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">8</td>
              <td align="left">3</td>
            </tr>
            <tr>
              <td align="left">8.2</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">3</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">4</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.5</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">3</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">5.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.4</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.2</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">3.7</td>
              <td align="left">Low</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
        <ul spacing="normal">
          <li>
            <t>This work resulted in <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
          </li>
        </ul>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <t>The vulnerabilities cover the broader ecosystem, including but not limited to attestation, authentication, authorization, key storage, parsing and resource handling inside the runtime. Any vulnerability in the whole system, and not just attestation, breaks security of the overall system. The key take away is that early attestation adds unnecessary complexity to an already complex system.</t>
      <table>
        <name>GHSAs/CVEs for implementations of early attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">7.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">6.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">7.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-f96w-jjf8-xpw3">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">3.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100835"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.ritz-seat-facts"/> archived</td>
            <td align="left">2 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100835"/> published  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87851"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">CVE-2024-21944</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="CVE-2026-100835"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Privasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity; draft <strong>archived</strong>
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of CVE-2026-100835/EarlyAttestationBleed/Intra-handshake.fail."</t>
      <section anchor="edgeless-systems-cve-2026-100835">
        <name>Edgeless Systems (CVE-2026-100835)</name>
        <ul spacing="normal">
          <li>
            <t><eref target="https://radar.offseq.com/threat/contrast-before-1160-is-susceptible-to-remote-attestation-relay-attacks-cve-2026-100835-3833ee713219f7e3">Threat radar</eref></t>
          </li>
          <li>
            <t><eref target="https://buttondown.com/vulnfeed/archive/vulnfeed-2-critical-cves-2026-09-27-0400-utc/">vulnfeed</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ervik.as/cves/CVE-2026-100835">ervik</eref></t>
          </li>
          <li>
            <t><eref target="https://securityvulnerability.io/vulnerability/CVE-2026-100835">securityvulnerability.io</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/cve-2026-100835">vulnerability</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode 518</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/571">Freenode 571</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.
We also sincerely thank the author of <xref target="I-D.ritz-seat-facts"/> for archiving the draft.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/415074362_Presentation_Safeguarding_GA4GH_Ecosystem_from_High-and_Critical-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414897198_Presentation_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.confidentialcomputing.io/g/attestation/topic/121496347">Confidential Computing Consortium (CCC)</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.aaif.io/g/wg-security-privacy/topic/contribution/121504323">Agentic AI Foundation (AAIF) Security &amp; Privacy</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100835" target="https://www.cve.org/CVERecord?id=CVE-2026-100835">
          <front>
            <title>Contrast before 1.16.0 Remote Attestation Relay Attack</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87851" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87851">
          <front>
            <title>EUVD-2026-87851</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1141?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y92XLrSJIo+K6vgGVaTh2pBe7rqanJpLiIlESJEqn12DUe
EAiSELFQWLioTrbNyzxcs/sDYzNjNi9j1+4/1NPUy3xHf8m4ewAgQFGQcLau
7K5MEUB4eHh4uHuEe7iLorjnqI7GPgq/NCVLWws1x2G2IzmqaQh107BVhVlM
EW6YtRbakqWPXU34UL9pirlMriRWc+VMVjDHQv2m3xeqqeyhEHmXe+VdPl+q
loN35VTxUJAMRcjDM2fKLPzQxtfuXHBMga3mTHYAC/o6m0ll4IVs6qox2f9l
TxqNLLZ4awAe7r/syZLDJqa1/iioxtjc21NM2ZB0IIBiSWNHVA3HksQpYGNP
pRkTx5KqicX8nu2OdNW2AaqznsPXneagJQi/CpJmm9C3aihszuBfhvPLofAL
U1THtFRJwx+d2hH8x7Tgr6tB65c9w9VHzPq4pwAmH/dkwJEZtmt/FMYAjO3B
UPJ7ANhi0kehdtWs7S1NazaxTHf+Ueg3a4O9GVvDI+XjniAKtY4gTaBXG390
osgL0oYW+JoTaOthdE4iT2h2XzzJ7S2Y4QLmvwqCh9XtMf7ghLkFZGFihGN8
hY91oCB+8gdbSfpcYymYOXwuWfL0ozB1nLn9MZ0OvUwDOACtOlN3BKTV3amk
65IiurakS6ItWYpkpXfN0y/QTJNwdNDMB7yzeYpDT6nmTkDp13khNXV06GhP
cp2paeEUQKeCAKylcTb6pet1KFxjh0KfOvyFvjKtiWSoz0T7j8KAyVNDlSVN
uDbUBbNs1Vkj0zcsZgMjUQufuQfXkccyfPox+sR0AVt4eMwsXTLW3kMFMMpk
s5Uy/WZ8LnySDIkkKU6SPxxXVDjAlMJ2jOtGleQpszVpITTcEVvPzF2DqpsW
u2XSgoU7/AVbSX8ovBnO8S87OjhhkiF2JUtlwokkP7nM2dVBlFbnku5aIZKE
fvsEOWLaRHX1CD6P2JWOXaUeeVd/uAY2TY3YLtT6pjEZmcKRuwujvsNgRdiw
+myQpa7DEDGaXFMzJ+swdmwp3MP6iCJ43a9FkBtpLlPMiQHd/zHBZ68RrD5l
xmSlGkLblYzJLtQ6G7EU6UJyLZQB1tt9tCVzyQwBCbBz7LA6JlNJFY4BBaFm
QI9jExiQxO+GBsAWqUPhzFFS0aHXp6ohRTCbAqMY2VymmCkWCvGonUprSWha
sgo47MRtqTryNET+B9dS/Qc+BvjRM7M0WOQRPGYAPMU48D9sgpSSp7vQaFjC
qTtSNQl0z1RnjnD6z3/887//8x8zjpNq2LhSU8JpSqilgpc78G30pqomXKyA
gEqIzSNoKVZq5sru7A+TPpM0VzfUFMDZybVrbSEBe8AK0ACAxXZSCVlhajrC
mTSyo7Q5keaSEV3HIwIVPy/NhSTUU0I3Jdyq+LUdIkQzFX31Dp4N0DlnaBvg
TNkRpNhCklN6askh/jG3TMc0UvrOhXziwho1hEaz32+enzf7Qr/WOR80z99Y
PCjW5qYFukW4Uu0ZGRau5kg+isRePZAnWxRsWZIhR0WhwmzQ9wazhzbMjcOM
P3TbeI2UXQlMDl3VVMkA6WOpE1gviroL2V67I150m8e1EEJ9CefeYApzwIpS
mCYMLLBfzCiOHUfSokw2n6qmziZSyoJPVJ3FT3dXnTFLmgqXLgxnbTCxbmoa
TPYuLNuSPa1rpjQD4spk8vUdczwGzJD78OGWfJAMSYkKCJ1398cUQMkI6jW8
OqAGhb48tUx5tguXZrdz1qkJPWQX2dQOsfdUpCuHSfofjMg/975KSerOvkDB
6UJtZLojaSZZ5mJnh9CewXqbM9A7sOqgw8k//4eBf9vC2T//h2mAIoZpEm5U
Q1ZD7OQbAc1+5+zm3QzHlX81l8lkwqNSEdWUtEH1D6a4oPEX2GlqbO0YXQ2M
BUsCEa/tGtaRaqElDiaFUEetvCW5NmruNKqCCGhq4mp/jGQ3BUvYne0i7Q0z
ZpIjdCVNk3azPuxNVC2sZhv4rX0oDO62MDBU3EX0HbQRUUnXdGgqSyFylYuZ
bDWM50LnHf+xoF7IeN0zuIpbgBEsbBvdKbQSPxIIf2e164vQJooM731YHLC8
RZthR0BGeA0i09vOANaDsz4fPG0bhBPXYAI2P+RdSdaEORtzerlcpkCuMzSy
J9AgZTAnPXdHGgwXqZYuZCq5bDVbyQ23sEPkhlHchhHM8OVQNYY+ZkPAjLOp
bxLTPyIX+CDqr1OeERx9c5Py7cjo8xMR2ngG4CvkFS02N38GjWG79DqNvT0E
7ljetUchnH4gpaKD9aBHu6Kl8xG/5A886tXNutn3NoacDCAmhIWrGSBqRyC0
QH1YDC0c+EaSZ/BOlWBbDsOjfTmbTxksJdjJYFPYntoe+B1cKS8Y2itpwOGK
yWDD/K4qf9vehG7mIFeCpQ9MTPMAL5rXNw3+abZUqFTiRtk873iW9c8eJ3MX
SooZqg0mpGuZc/xPmn6nt/CPG2p0H55sPmXTxqOB3QcC/tBxw62DdcOt9ReU
sBmdd4i6ao/Q7IBNvU8WsD0RNloUjTsBV9NYZZYwl5zp1868d9iwIUe2IvTZ
3NlJjdwPp4YMxoMky4hAc6GCDSgzAXYBU8FQwVRg+txZ05mOqasOgkCJZDkN
yZFQooChKtS6DaHfvBH7571vJkwuhjAbjqrks9VCshWx1fgb2DnU/h1oxk7g
W2jmvhHNOGoet/s1kThGrHWiKub7S4+wssnlo6s/Vt/A3sOSFirYk45lp2VE
N20z2UWtlpaUhWqbYGPaaRrNYjyZiPpitRL1yaT8ugK63gAN1sw2RXLbJPGW
lvrzBU2YeNmSUHMnsLf7/tQrzFd5cfmYW4mrVeEbqZf/DtT7/oLpZxHSKgEb
zgsV8TFnLb+OkE1lwjTgFrG/BvrodpSeV0w3ncipN/Ka7dpILXXXCg0PPcG4
mYeGvcZR4+TZzusDnz5OZPFRLi7E8bI8fX3g/uAEb3CvDXprDR4zXEo41XMT
zHvoVlBM4y8O7CQdJjsC7F+Ah6QJA0qM+AklUObnDF3PPU3EpbVaiNNKtfLt
Q99aQM2Visc5E6HL7KlQr6FQpQUiWyYA02GTOAZWEGCzayh42gukAUShQd1D
XZgzECcWaF2QLeswTVApMHTU/ACyWCt5Ic7zc5DIeTn/7WQpRMlyDltZBODA
1AP+Gh7H27T0pyYMGfGTVGAaBf8cqxPX4otlaVqaAtOlOiSZP2RKpdL+ITKQ
uUSiaSY6K+aWulA1BvzEbPhNTX8W4fLlki5O8+UlSJPFUyLCoedM9PWOqgF0
kYvGbRlCB7me+lGNF0Zj2L+I2qmOJMQzQhVoU0NXnCqjTPd6jgjXLOzWjJgd
JR45oA2ggkGoMmdMViE+SOv2BKgiOelVnl2uWo+XrZMzmUmspBWG55M7Q7cb
9+l37y2Jlj2YRwnILlqw9rUtUeq/FK5qIioheYq8ZMCk68hciqoIhgkLC9R1
RN4yXyWBpEWGw7aeeg9TIp+QS3x00hzX1xnksfS0EAt5kLVWwbPzdhLEB/iC
GBPzFUIcmzjds4//ahSZmK9To/w4XorFvKWL8+n0a6jBzEWUHDASDaSJCObM
QrUcV9J2EERmlgN2mkzHbEtmMU4ZFMI/igov8XqdKvPieC5OqoUJ/EuvfhVV
9FepoquG+i9HEkQqxjCrPulg5j6CmZuTS19BD8uRo/QAgQmrVJQ1FSMTdpAj
MOS5JQu2y5NrIml+OFWiqL1OlOKTJYuLSrkg6qvF6uuIIirSK8Lkm85lGvx8
3TR8NRUmTOlHE2aOW6HiEsTseFqM2Q/FEsaR3R9BmcFFfXBx/Z9Clsmk8iTq
4+kU7CdLfj9Z/K1hYdfW8MexSa6YkCDJThyKegV4ZAUr6HEy/7Y9c/GVPfMP
YpQfS5jJdLkQF9Y8J+aq5WJiwnQaYt1SbRUjCi46qWwmlc0Wiul8uVzNZSqp
fLlSzFOoT/DhLk8JGavo/aAv0MaN2LB1U5+7uKv6KLTQzwVWrSFpa/wUXWav
+ErOYQPl06z4pr+kXq+LIUM6TTEjmmjPmSyqiigTZu82Z6NvuibYiNJYir4Y
pGCXa+FDi40B9xAFM9V0v5fKZbLlFE03vBWvalGiAU9I5P4fuQ4w0IRCETCE
0GET3D3B7sjacfpgIK/tdiq9QiQ8D3ZtZqgrMv5xgwbWAtiPacmRc8X0HL16
Hl+nl0w1pqamvE6pumTBbBnCbfjLd9CxYxru//d/CF0VVDbsM6Iv72H8sN9u
wL/msP5Y9G1bwugGYWDLU3MMA5lsNZYsoEx/ysYwsK05mpq6ZAPX2TaMbwtV
FawHpglXpuo82xTFU4cFxY56rehMdTuDq+ZfbIq1almSzpZktfdpScI0oVGB
rYQzaQ3sem+6FoqTBoV62MJFxMyovkcYyJrpKv6SBwtHRRc8zd5IMydpbJcG
HoP/11XHYqItGmwpjn3cRNtDTQTURDaaj0UNURPXgJooqSKPQrFF04iZZ8TB
GyQs7ZqHBXxE9BDxvEM1XFga4XUXpVxALX9f67UQvHO1UMOtI8PAUfoqS9PI
iSYwdlsEnNXJFPRp2CW9oYi8wZavKjEStPqqWPCmfrc44xMOkiu8g49Gqwo8
RDb0wZHGmLJ16LTzE2BeizGUqQ6GdG58zDehIweVhx1QGPN//Nf/R6imMq+L
34hWym4x4td6/UFd5KrZanW4cxRDGsTwxSCGW4MYmuMhDmJYzWAkQBj/YYD/
14jvIM5yL+Twy2YylXwxmcfPO90bMWBlJmRT2RKQ+iUfC+HjHg9EYgcdx4+3
9qar/JrrCzR0rCc31vWFjXcj+T7X16b9DjT3VD9y0wtrERupMZfEIp48iQw5
JrwQ3/eVmClsf4gGdeSL0ptfVN/6IpvxvwCGfea4jCUZdp97qVRqb08URUEa
2eSL29sbgBKgGG9BUnUbLcK5ZeJBjeAEQdkKcyRVowX7979HAxT+/PMQnm25
8vnDqD97+0Nyku74MLfrQ3hIIXK0CgGhY9Vpu6OQkA+MS+EDWpf2vrCcgpoM
xkLn/RIXK5txBQdSMLCpuRTY9q0AYUzjBsE0R2qpMjsUMMJZODhAR5MJFtB8
CvYgAsP9u20fHPjbdYXZKspYXZKnqsHQGrMYnq0fCraKnW5E+7afZkJ+DA1w
sdiTS1CASp6OB1L8/e9xqgwJ+HIkkgIq/eDABYsE8ZSsNSCAe4MVEPDgICUg
I4DEBCPexhsXwgjkAHQ8WtNofFkKfe+KL+KTxs1FbwJ3SVVvGhGghKdAyJWv
QCRzHb4H2iMEJppjsgqgncBtZADlGeOOiUGLPcvE+LfxoeCCJQamzByj9MUc
iDuQ+sywGWlzgGuZiiur/Oj7EN3S8DL4iQhawBlsyf+eSgsgBmPoa5wZ5lLD
c/oQXTS2AMZCJGcM7UrYaaaEumuBqepoAA/NY0YUPThwlmZwoWdzF8g0GMVf
RS4B4UNkZXwKylHEuz7Rp963lUNaFgY9t0MvChz/F01KqbxAmtCewjikiYT+
ERrMyDIlpNxL7iGnEHmjNU0gm4x6IgsS9mR0wO9dUaLJnc99RRtiLc5Ac2lO
rckDa3PKyD65BKbSrSc+g5ubRujGHTFEAKx+2H8A4jiXmw94Jxum4sgBeK87
DIkGCAIwGDYmNzFiCmtAdw2UId+JaVLCkWQzJLuA9jQaceQ3ghbkqUYWiO7J
CdmXJA/xHfeDKIeENgjrpUF+bR0mhU4H56bt7L7rlBI6HI9grcSutkOPp3Xg
CdohvBdZUCnbjqaN6YHE6YIK+QudVsCnvIPQQUQKdmXketShI0WAXZ9FqkiG
ycIAWOCLhaS5uOsEBFWYeN6Hp810VVE0trf3Kx2F4DyRdQwwx6qFnk2+U+Ts
ugKlgZodmAfjbunuzGY50CJK0xr1V8YOWcplGP4h4MLAefeXQ8DnOPPoapQc
QWPeIa5po3vE5quJIfq//io0A4z6G4w8AUIRuq7N1TT3RY6YBqrKGxL3ZXrL
hwSla+8YEGEcGdS7ZpVWCTlGLR1AAd4WIt33DXpgp5HP7J/AXBsgBuheBq3H
HEuV7f/ywbfLDDDLwApzUhNzkcaZF71P0vLCtveBt0lO0pVG1XPRwsYIfdbA
3jbFLER8lhydFEjVFqwFPOoCXuEHBIdCGwbjjFDlCEvYR/tiFYVRn0aBA87m
YQlBn9vEgu7XDM82UGBsho809MUIaFN4gjfsLB5LgigTJ+/tfeHdfRECOn0R
zumiI3ba2+ps9zuaqy97X4C7I/8D4L4ygJb+7gT+zML/RIG/r7z+Kht9hV/m
6VUllYO/MSY40qJMwLzHudDj8u7Hxc3jPAdEjwubx4Xg6xJ93WWK6uqRTlFB
hV7kgxfF6ItNiwL1sPNFbveLPI3gDFbS5unfP/Kdxt9+iU5Ems8U6oHt8KQP
0kziC2c/vHJ++ZNW9i5Ju/eaAbVZ0pJvAKIeBZUMwgR4kST4MwnA96KB5i8s
HkmzD2FxTGBdkoAGToPFRnoW/rUmDYxL3QuKgnU1J5MY4wTQU2Uhl8PgDdNJ
CS3L1AFD/5BHQO2Kd5JBfnHzxJODGH+iMFm1uRktO6Zl+wtbBsRVhc4QvSA3
HWxyCcSDDuvT1Hc8t8NY7saQjB0cFf+WsI0aBfhYWmBkAUoTABRven6zRTB2
LaKyrxNQXQFKQAU6W+LWNjAZYbK9rwqbg1xRBEfZezXhgBvvJMGt9QE3c3A8
/jdhhiKW8c+65eCsG96LhOfuoDvPgEASbhvc8P/bdIwcs38P4kUeeZpy155i
7/W9RmhFvdwy8INrruNgcVjcsyogkMC29Q3iSBRDYO8ilr42Rw1Px17yi2Ov
xdaxF9DrPdr3IzLLLu8HAsAQUAxY9HgIl0qUibw9d3ijEQMuHAMZCzL3AuTr
Zh9ymB+GtwVzdzBfBDZXcmjT9XYYZyirfwUZJMoWJhiwhT+5ibRNa5qb6N7G
n75DQEXWXBIz6MpAf7um6nQvCsXtZiYO6YCKwplCv03Lu3Z1SLLOBgEnTUAG
wu7Epp0SbQlsML5hr49rS+PDt+lsBS1FfqUwJdSM9ZZp40ni5RSvyfnoIkBE
8hEDFCPojSwmga0ZyGSPe006LNE8AHwlI6oOrfGltObyWNpp4uJxwe7DAq6M
YE8DvSrBC78XtH9wnnCahMAUamFWCOuFSQPfeszg+ziBB3yrY2f2gEPh5eV7
TpqXd+YFDv+FYPUNle/VwYvTr+/ew8714vVTeK0fYQd5c9SI24G7G9FNVP/s
eReI/NeD2LXiIwYtjH2GXhZXWf9VCCUSAeYcrUMwaUf51pi3ovreQnv3tLyc
ksPXxxcKnfuZvTFz8XO7039md5Yj/+TuREVKsra2w3morbeHiWn7QlUnX1Qv
VHNyEC8O5L8Zxtfg8YmHNOdyC3G1HD+Kpbysb44OvimkLwp0X/A3yAECh0I0
echhjHQJIatX51UxP13NxcJj6fE7IRsFuh/Q8VuRnc/lgjieFEviKl8tfydk
o0D3BX9H/63Ilh4LZRHmCthanpS+E7JRoIgsP/H4VmQL5WJRtKYlWSxVC9+L
DaJA9wNR9M2UHVeexEpFX4hyZWF9L8pGgO4Hsu9bkX16esqLJRmmrVQpLL4T
slGg+4Gh9q3IrlZWSVzmijmxMJmsvhOyUaDfD9mxbq3E8ePTUsyXJ/PvhGwU
KEe2/D2QrZaW4uPjuCKu5sv890I2AhSRLX4Xnh0/ARHySxlnrFD9XshGgCKy
he8iDXRrYon5giyLY3lS+V4aLAIUkc1/FzZYPo2r4uNY18VxqfK9pEEUKKfs
tymFVzY6ec+eJEqwkWQ7KuygT9aaZMzUuIaF0H54G5UQlu/DKgiw/pqdYzGp
Wctjgd40Bl+YkBia845Wm8P6kMuOjujf49mi01nvTAIo+sEy3ckUT88xSRIl
aiMPiWkp3DPjuYjwBEcU+aEG94YJOmxZfYfyAZ0wzy2G50iGZK3JD7DbDYDn
mRee73DvHU4BZ3MMi+ft/AaNPxQpFJb8xgE7J5L/WDXiDn+5j91z6XmnXfQs
EmHuJ4SyP+LZz7mZglk72u4Wnl3b/Kj7i1ALTuRx9rPYoE63Cv7jf/3fbYJp
mBghQ24Z4dOIJiq7c9G/P91M2rEYw3uFRtoDuE/d57a6D49/Bxq5741Gbt9z
SEEfPC0pW+FlTGC8SMe7dd83dJzf91xkJJQs4EUaPw+SpIPCSP+F791/Yd9z
6iH9TR0ecqIDD/+aI7b+NR9Fofi9USjuew7H11FAIfnp1UPunQhth/TrjOHR
t41B0CPevY6eY1XS7DQ/8sITr5R/6VeU6J4N6NCwI2aujPf/KnwKju0XmRRs
YTYIYHSmbdii6uB5V2lCqCznFEEMvJ1255opKTYGYRfT2Vz6luFwLbGG0SV4
PR7jrgfYVqxfnLc6jeb5oFM7Kx17PUPX9XokYrTfOX7P+Pf/AotKMeluG8iK
R7yJ/ylG6uyEuUWNtC+BKPpxbspImk2MiTtXKA0ASsoNOElN6fAJwSM4sugf
0KfxKjdGmQGCeOJNMeh+nKC4RAKRh21/w4y7d6bfwIylfc9bvosZD2ExHG44
EvRFbBQpKVAP0d37/W9AFPf6If37Qtbbhy+UMCLux+dtHLKoHv/93/8dA3X8
QM3AUwcPYODw/6oR9mugP4MizEbmIqTn9nboOWr7um5zbe8OxN6L+EKMJwyh
ayieIx3R01VHnWw0IbYP+QADVLccUSnhwkVVCssc48QYrHzueVEdsCDWe3TZ
k20iXdDFAsuSYZiSAxbJJBxSJ8KgxqD/hQ8afKAJ+f1g+HxQccOWNBODUckL
jfkhRhgSBaIB/V573Dcbygrih+Wgv4eegFbSASS6VPlFQD8Di7S537035jEC
ijqmgBxnEwPb5/GBXlPo3xu4jUkgfYKAxDJASNh7QAX07fmRtDYpqRSxzN4e
RYzZc8xrPgKliZOgmTbj0aUv3GlxJMF4aLpv67vitz1Sqm278A6+8+IbF8xQ
TIuog1HGYUf+uzz5XVNh5A68IB+0v4K6AfNyb2Y0cuHJhTkSxuiEQxYZUwSg
EjUEcVAICXrcUD9u7DvWzWgt2Lh+1xhZYUzwLXIVdPkZZIQjfUYXpwSS1I99
Yp75xA92aZIET44i57coKFb4JE0mGITisO8njwKQ+34qD5skhBcro4TXrrJr
rK/GgMCsUTomDbUVJq/isYl8jK7h/Up5Ezjmcb8+EhQH41vpO2JciAcoCwcZ
fGFlGQ7Ijwr53XcKiDtp8fFwCa4vcE5Qokq4MkL3PT/wGDYviHR/Zz8vrxNA
H0G8LIzUS4GCsaEUxklcAhLBW/W+/N7EBcG+AGz8I9IdwhSWGkW1ejp6D+zv
izn2hI1eDWRFnnM2jXn8HRdXkRtRRD4/HpKrK2+S30NKxfQu3s9RSAOEaBIz
yfaiuVX8Sjg48KKJQepbzDk48JcD75dibwFRlfD3JMeLSJrXGRDjulkoqp7v
vKyJq9OGcDldC5H+CavAX08XOXYMApiv9waVQSHtbnvI73xi5CuO5eDAHx2M
KHyZ4C3Vq2JoAYYxYOYDBZcD3RnD3LYoGHmwK3+AGUU0bIBKClP1kJDtMzkF
VnuW30h5Zf1yaQQfFrzPNqFR0OURW5soHJAWPNyOUNOYNMMEUdDiM9qEzdPP
uKr92hmx00XBcyAYYdLxvjlFTUhzXwkhVTFLMeMLBRthvnE/DRPut0J4wFQz
jGWer7lphCsbPksJPU1ykInCnEsZ9Hh8qmnN0Mwnq9+Ctert0ekDjBzGhWui
sgQ1AZINnodHr5i4orH+BvbP61AcUl7YUKI0HOZNvXmKswJUwch08s7DK4yU
XaKuoiGCzp+LrqE+ucxjUY6kJAzqR4J3JZ90KEa5eFd7eNWTuTfKTTsrkKgo
1mEH1r86P/ZxZ8pfEQV/A3W4mTvsDwnwoVnfb7SbgmfnCxhOzjhYZz1HK18L
6M/HY5tjh8biRYxHg3fk8EXFm+7GmhQmLsYsX/RxCmVrPXfMiSXNwU4QNXVk
IVNYgBSQB+8keZE5LR4oiNHIhwGdP181exdXg2GjNqh95unb0Abc3D3hPfEA
PtnPyq7wq9bEi+oE10uYUXieJ8G/vMSvVODVbQsWvPNyIv9KzM9gBvllFiCb
qmyy7VEGvk1sFNrHvrYjAgcdcRyCS8chzmaGRBHbIS4k2wGWBaNbDmwla0Dd
BbeOvSg9/5zLtLgNqPCrIXxugal5sNPns+bpB84J+5/Da9EGpDSFC3O6Fom1
awAtFGISbPPnGFUm83h7Hq7IiLRbi1SWXJvTTGFjDHQDgemN7RBsXBOpj81p
HYp4oUpoXB0d8wtNh9iIK8gNr8HXPun5FQ8JA+jwilhUCnzybMyiWMrB/0VP
ASRd4QnFjLS/v7XTPODSEYPD8JELWDloROmKaI/EcqZYpJIu+/5mjIx808AF
yDCDnIu2KEyLxW9lgwgDq5dL6I8C7Eh4ZSIUFQ+gIYq+DWiSYYT0BkCuhba4
7Y49emnBcvBWJJcczCI76vNVo99sNj6T2rQ9SUHMbkFn2ppYXCJL2nbp/p23
swkUOXI+Hd2SggLYKIA97gFMxX5PJPZHFUYihRJGjjHC2bffgqOGl+k0uEJU
mA6LxLEooxHfxCiwwxP5wAw8NwKmcvU53wvjoqGc3Pwmh2er0REqv1r11w0/
+BFQFEQJQ5yi6LuAZ/3+2V9s4bMo4gqjnmBmmfI3S5Hn7mfhwyfvIyEPe46M
0DnvD2pnZyld2Wl8m/CxbWvBf+mgyvshEoT0BsL+vr/vwZHACthME9AO/r6q
ncPfJKN7SFFEDGZt7oJgVjVYzEQqIHGw3UUTXZr4JgiYmsQFYNwoXAJ78oJm
CpiQ0eUgX9f5Ci60MrmFfWYuxTPaIXdh9+xti5Dc/BTPMzb2Wpj2jwm5WGMi
tCQGzaYoTQwwHIA5/JkTaSu+59+rpchpvJciCTDH/KXA7xRuWdEkY3RpbnvH
Gt69XORWkB908m9SvLSf7GLBQmlgUfiHdfPWuQtFY8L4UjA6xl94V6y/hIC8
858vkZ7e1wS6F3f8I+x+HPfPVzWB7g8Oev4N3S4/hQD79AuOWySFoPnkDEyO
10bvjTxohtSIbcS7r9cDmw169mDVe9dC+1b4N6I/8KEL8P5tK2HKGE0ZyyWR
G27CxVYaJ+EDNyD2N4bXvwlXXXjXvPHPXMDe4HhcuiYpYErMyDFBMgiXzZjp
ho6ENFkEYdw+3HRDXe4eddQ+8kcegk5HzUKDLE7hw6Cx/yYzYZUPh659AD7b
Blh8U8LpnDl078LGzYxPAR9mYLb9G8kT31bzTD6g0+voxDdFZPkXW+i0+930
oBchzRd+pZ1tLdadxHj/p9QbWcS108+h7r5ETvNRgmK1LuAIj1Oa3I++1S+a
/ukbsKxI+fpblzeJ71vkkf5vPRGexj0uUWuTGXwn1K9psun+bBDuH69/0TE/
LF9siReL3iDp1zQJnZRvqSFf2Huh895e96W4BwmyJdd/8a47IA6+KwmN2qXh
H0EEsDlQvvWz+d4vOBeMAN2j80NalN420L/7E9VVEeMwbH5HFR2/COlrsXR4
ar4IV65hpzUVc/HS+fLvO/lGGKznL8TL7i+vAlOLevJuXbymft6rTN6vc177
klBAodCs4+4zinSHCwgjLJZejOw85m3kw4t+2pc8nt3F2e/LZjO8u/94SfpF
OCbhFZikX4VC7dT/JqKGNk1bnjbxg3fSgWbF+ZyqsL4teYou6eAAJDDQ/U66
YIdbaxEg4Lbbl2lfhJAG9rtre6ZlOtBisL+RMK/D9piCljCc9GmjJWzIGtmf
b1rULeafIXDS9X3SfREo+by/RY75B+MowhcgAhPYSwhCsiYsWs6CxbeV8A9X
9e5THhQiPdjMwZTrOymHx3Q2vw3lvdnmlb9gVuQuLPW9X4UGJYnBArkR30uD
+2VQRg5UHb0ejHsDeZhBbZNTgx9rAtVq/lbyhrtZUJI06TSSCMjCt4jgFXrW
VEMllDYeIeZ7hMizZHouG4CQKQsXMuxEcPfMeTOKAmIQfJwtwLjk0Mfhoo7e
McsnLIC72VbFZ66GKbDTpcnoaZW5u6/c3lvtfHdVWFxUjJzonk7u0+hh5tmx
qdcSj4HzqIX+MteQCc/Qnp+NUn6P2Bn8plRrmVyunC3Btr6QjuTU21wCTFk2
z8zmMMY96XiEIq8BizAVcmWhxUYhfIIghM3V+ZdeM+HTwUFwBf5vQrtz3MYy
VDxpyf7BwX9ByF6pjzDsm+YuH9qmpzi4RR9u6QVcyicVAoMhZzsvb30l/E8b
PopOT0zybsweI9nMTjvShIcg4D0SiuzI0hQEyWDJ1UGNdhHnHRhXKTXd1+I7
MV/HtZjKihMzm8qVoLMXSE/Mr0Q4m3mBcf2FJfR1sSJ4MV0jz8mnmJo174rt
2Yadnruali5S5Gu2vD2Cm01vOwZDp7NfOSI/RwzyZi6m20QeP/IS4ozy+66Y
rAJX7Bb0F8FRL4TCjpuLMQxQ8NfYC5Z9W+zkXq7f+lVn0KnXzjz4VVhZHoP5
BV4S9ZD/xh6SUyv3glwvOuQXKH26FV72yid8Kx8c+shCbLPJqxhqGKzlF2i+
vF75jjnNf20ndKPyR3bAL1H+2B70H9wDvyr57T0EXPEycBq2l54aQiPuHRmo
MKj+W3qbmN+vp1jK8Vuf7yBe6Vs64fdDo710m43Oddfrp5TKx/azZR75l0c3
vb5XNlXeCz73HcG/aYT5t1B/QjfvkKtvdLNjzn/qTdZs9QVa8Xj9pEurO/CK
ResnXU9NitZPuoiaFK2fdOU0MbV+zuXSpGj9pGukSdH6SRdGk6L1k66GJkbr
h1wC/Xa0fs51z6Ro/aSLnUnR+klXOF9BK/m+i1/azO22KZODK8SBe3vfWXjj
ZCrYNRe/soPiyw66F43mVW3QfGGavtZJ1HgMboAGff6///d7LS4vIXtyw45f
H/3Gjjbn6sGpdvRGQfhsOXyqLW0dZ+MZOzqeVT/bopf10+BXR3ieT8r0Kxnr
TbTPWlhOJcc2EX8vU3I4CjUSG0uh2Z9vmTRrS/b08yH/u9H+TAFkn48kpcnP
mD6nDg7Qo7cWME11xLtADknTxljPFEsdejD7dPOEoNLgvAcAmo9V02B3Ziq+
79P20zNKwgRrSFBcb/PaS+S/18Rs/EwyhGsDNmt/sYVP9GIjB3Zm7p+aOptL
E7ZPsd/RlFBhVn55jEtj8M8U+YWaYG54wtbIlHInBjosMUjXT37Lw/u3C1e8
WqhCOFMd9LIAX2wy1C1ABniXhYEbYpLnJs2ZSy7WqLeFr8Eg7donv7d3w9zO
0Ob5WD4tVQtWwpzCoUKeh9DT9BjWiR08wkuD3I2FGH34REE20ThFDOfS+Pmm
d0cRnqZdlP6BwBdlhkFf6bDnI00Ng0hGMfyOB0VmM2KuImYyWS+gEdn1U63b
+B5xkvlMIROA3XSMpKO7qud4+YNoNmg2t+jlMBamFV0p3KLUNpBG48oMGWKK
giuDDqhxedDP/0xal8RMRcxmfxytK++kdeNOMZchf4CipSRZJ3+YYqrpoEBY
qVgpFQqpfKmayeUzdJ/zJ5KrgKyZCbMmXkAvCl4qYhxJ35E05oakwEqWRP/y
hmcrqSZeYMXP/P8OeaWsXMlnhk2EcLFQzFSjw4ur4uI14NkwKCmflz0ZkTvC
TJOtWn/wFnqUknKMFYyDv4amNNOAO3bhWMpWy7kkOGKD/e38zoShpFzVuhtQ
I0mxJB3XivcX9r3puiDmstVC4fswa9YLoN7OVP2jKZdNSrksoVjdQrEljUAR
zJjyFopj/8PNX/H8l828A0N4GGqwE8NdwblRyPE1nzIVmO1sJTfcAoRwhlEn
5RDzlW/KPsFLrO/k1/wbDs76+0JsdlGe75xnN3klP3FsGsBNmvZkMHJfB+N9
CTpDADc28rbRxK/w7Eh7HIkekQOjSQuMJj+uTd5ADGLl8L73xqbjtUYODhAv
MGvpvtIO94Hi1Rn2rxar/FaATr1Rln/eFQuq7FoYsRNcL9mJL4Vi8cv4eIk6
qF0Syn6+ZHhJGhMKG7x2eqRSClnGWA6I7P+9Pe/6z4vLgWjyahvUNpF4c9Px
Tc8g7c07U8J/2ODLU3TzsiVBMmu+q9n/+FYdg10VCvZer07wYVNHga7LLJhm
4hVRnvNgV82CPUzRFyoz4NcSqIQfxYON1CMoeo9CtQiqwoeiEAthqxRBOcL3
zdWcxyklnoQYygveGvAq44SSCeFdFlUndgb68x3FIbHzWMXrK5LtXfjyCmMM
/Nz+0Ay2auE+iQFDUQGdaHjp3l7NDt9qib33SPi/UVWGaqBIXpWhDRtvk+tF
1giLhW4vU0L0TZKP75vX4+MuUc5H9nJr+Vb0CuKZLGUM877Gsy//FmMUp+Aw
5T3nGnt7nbGwNl1e8YDfLBvTEQOXzbGXc7duOM0p7EfAlPGuLeAWWrBNLlCX
/AagPGXyzM93/iIhw4t8DCq/vgOPvZvwNc8BnO7y3BrAby8YcpCIcaisfCi0
R4rU8To48F3OeFU5VEfp4AC9ywcHuynD+e9fOgnOx58S2YTUDNOQyOKfL/7P
f3uRmSi+RDSxeeLYwcPvuV7/CsPR1QmJOl7ALybKgBfvgzGCqsORB+fdXlwE
ECAcHZdLZeKPunmzDRWSx9UcRjma59rxkPKHFT+oyDgm5vYY8qDU/Qi/t+IE
dwzkXbE732EQUZ3W8+9U9sPp8uy92m5dFFzBjGTX42easfLyAC8sHmzpKsT0
/QxKkuWNlE5V+Eyw1/oIS2rsyo701/dE9fG6lRTXh0QeOyw4hw5QeBEl9la/
PKYwIhGwjC0uc7JWjvN0wZNZPBVPuBwdffhKmQnMjuHYTBuHyw3hfWRmGS/o
9VpKjxDuSPwPpO1FvC47Z4ZIB7D7nmkv+UlIdmSe+mBa6gStLFRsaOejtSdm
CvwgnK7l2/wSOUy8mCnt08Cw8BqvUXR7TKk1VFmdY7HIuYnnRAqQwgkULOYf
4mp1BEo6iXjzs85ItN3grLctUAnwJkdO6EvKQxM5Chd5loAXrch9EZrLD/I4
BQDokNu0LFjnEsqrfd6Mjtg5awS3sXGq7PE6RdShQk9Rwtj+NW5e9M8vE7Qz
qROmaMCqrqrjBokFLCyl7aUewAweXr4iv7DV1C8cibss7j2JrwAVrd5Hy4Tj
XqMLmhyQBdNH1/KDcip+3hk+6IMDReXX1WHJ+QkzeLIcMMheSSLj0453d3Bw
/Urd1vhVAhLRzy1FF6FtTMTTaG/ljfnwebJaf97nlz1gyxl9O2LOEq0meZPj
iSfiwsw97UAk+jnJ8OLIh89Tx5Z9iLQ339wswVq7QSsdhzRh9l4+JdQ2Gc62
oEmx0EKZ0bCas7S31+MrCtPneJli4i93I0yvxjHtjIK6wj3O6lRXuI6X3TTe
zTFy+v7GxRNwv/An5iXzXXV088tLiCXhVZlB37Md0dfI79Ajz/AEJK+fkKQo
gVIYARhNkIQDXVs4qX0+bX1vUo+z+zhDMa1CSU838zjwKH+KlD/O7ePMvA9G
eP6iUPL7u+Ykn2hOuijhrnh9YlSXtXCar13l4rw6w9E7ijuSA8cmy3uh1Ldy
KYnbKVunTJvbQe4+fiMr6+OH3+NtpSAj2SY97q52uXC7Ds/LFJMo0EsG+Fa2
O0oAuEnMssngFMpRQZ7Fni/nY//5sslaJ/yaPcwdFg5L0Yf5w+IhnuP0Xo4a
j1g+imJ8D5HOvK/9P4L/AqDjrPAxjlVJykGL//i//psH7D/+z/8t+gdCyb0B
ZSZPt6Dwv6JQ8m9C+Sy8AsX7I3JvGMOuOe/Trb2ttVROZYnfvUwWxfcuLJKe
QVowKkXrnWgFCy0+pXMokfOmrV9EfLcnOS7b8w/L9Jze/6HQNXOSclbO+/NJ
/7Bc0uGB/gDokYHuzlj9w7JVh4f2A6BHhhabE/uH5cMOj/AHQI+M8K2s2z8s
43Z4kD8AemSQb+b1/lGZnMOD/AHQI4N8V77oH5YKOjzSHwA9MtJKKmxFQLd+
eePv168PkQ/rB8IPDWyHQymk63+ls/DgOAomt8UVsc1rAr/yktQ8Xkz3zx/A
hLyl4vFkK8acb5J9eBgkG/tE21Axes6ymkshPwZuujDZyIxZmxvviimnX2ua
3j/kqQO3LNeQuTvgrljy5QMukwmV5aXdNeylcSM6XY8s1c/ui1uvD3J0EcQa
wX7qz52v99+bL9Zzfe28Wkn5PhU8Kd99vvV2mtSwjU4FZdebHf6IGWysRt3X
/9mTmkIO80pvR71OBwebeuHergLP2XE2X0xjmDHoi7eG5acR9xoh92y7L0dr
OnUMHQV6HnaettNP9X4YTca3dRL8HXjCYpTtKrqljJ7zERF5RDAeJ1KKTIUT
4j0IiJlCBIc30fVOafkBmT9J8MO0mB5ELkQPSOnkLPVO8XNWO21y8dNXdcyM
gUOCkWOCfhm6oy93k1z4pMGEi5b0bq7ER6LXKL3/XhRxC0IYvn0EL4TChl87
5UfPu2TM6AiTc5R/fZ6mdXOx/u3zeuTlK2BkZ8vlwAOtDwh4yAtqY1LdtaBg
Pm7LdO1Dz1kFaCL7B+HPh14oTChgZapOppTmB2MHlFBo9deE8QgfeObqrfDn
P//c50kRLUYZqDDt68FBG7jSGWEkEoiEJQingwOM20Df0MFBiheIOFYXXs5p
xJMXrX+z0Poh+qdBWVCqdmXPO5RmoRgPfrMYViSeb+PvNwRy97o/2HOtCQ+f
QbdxvNj1ShW8xYSUCilH/+Z+bv/lpvCUF2SS5rcHePAThdl88DKF+TEaoZro
eBKPOcG84KeYcaHIxfd01s7TuuEaBCUbSARLtWceth1BmngZyBkeS1BKYneO
4tgOH0KH893Xtnrzy334JSMwvsulIhIEmzZdQZyGny8Xc62SBgtaeXl8vUMx
9uSStCeX3QQrchh+cL+XixOQXZOzD1gO1mbkGy5v+f0CXBo4vODWxgYrzvjY
2isCjy3RmmCWrlJyYtsX85LG43GC5Pno9DEUnqKZeWlCD4N+guAJjg7FE2Hm
a3mTNnZE82apQAmmcPPeb60zCX0QIHU4dMyXxHOKULKn4MTQS+rms1jE2QAf
k1dD9jSvnyYc4YwoazLPA0cl4/0V6Z+9+n6CMGNtptc7jQ0o4Cdy9pPhpoR+
4PmJutu3UzWP0NfAM2xJXIRRalme9tqbURItIIv49EnEmZucwxu0aCTw2ufp
gFo8WIqN/QTNXjp1nqo+4Et+OYgb4gPT1PDsH/PhvigoExgeweIILBCqNfPJ
t0A2mk5ljOqyWJhFijFf0VHy/3S1ArqmmN/3S9Bs6c1NBQhemC1adMQPpgl5
wQBp7t77NFZXKPR5bnZeRsT/4VdBiD9ffldsCe+cMriJqgICC9Pyh7ZJmNtR
SgMu+9xRZtKhOUwbZsKmdHi8FANS2nJ4RCTghFJxDDSi5Rst3fDGobi/DBB2
iuhjedYOC7x6y5BjB8v2IDMC4ZBhsVTI1MvlzEtTBD5IAkvsg6s2lDYM9ZJr
eJ7MTfr4f70Z8EiNvnK85xZdWBuZ4NU+eIktzWCk/MJhIA9CpZPo6spLa2of
y+5wVxnnaY8LggUkByoAhRp+PSfRylP6b+XmjkwPTjQA0P1iPPLUVGXm1TfC
vZUGpklI2gVyfMcYcdIOuXUS2CNRDlwSnjwW01MQ8fMIq/YcLL+PgeHs55v7
l+OQ3WuU7C8uXwywZ3v9Ux5vsbFYU3utF7zxcW/vfyFtHUwLmufZVP4wsgAD
GKFbdA0VJDwT20zTdGBN5CvBu3k5xgSBqPaYhsodnmuaOscE3iCPF2grBjlX
uV7x6kV46eTxrh6jbP+IBG5sXSOyweUHxBh+vsD0f7g32BLJ24VJPd/Lpowm
cdcOIqH0vuWJ7x2PiUAFGiq36zl9dzTjO4+XUizwiXqOqfnGxY3lyVRuSAbC
UFBMWlv+CYaqBTkoAZ+ARaPVqoJZ4rVIecZ92/ODb8pFEBUM3CQBwf3wguhr
3KT4xYEALY8VUnjVTdYkVecxwrqk+BYkj2+lHcrEtYIs6KD+Nr78vZBbPzaw
2WLeeQ2GF/s1dbaahorKcGdc5UW1GUHntphNvA02AtPnU8lWn8PxPqE1TIG0
kbpDVBkCrM0Jd9SS8HS5PMMyTDhRdgRdA/Hl496YK9GrolcU5LO3eR0Nr/Eq
hWBxqYCl+RnETmKl0EGNH1M1OC9OI3T3Bts2+xdXnXqfLlkTbr9u36zdC9yZ
8bn4QzVxN7sE36lJCynIf8xpiAElMgvq425X5+PIdIPSfj4eb9UEiMVjY4V5
bu8AvB/27K2XvVqkzts76O3HJ3EztTaXZDA0c7AdPAOxYNiMR0zALlAS6igG
wbgNglUMttxcRMYN/HoEjLexS9E/jw0B7zE30iUv2xdmCp0w/xzD19uvhHej
8YlBzlFThzQFP7Ww9J2lmVNB7Do/LQGsHNxVGCRfZCzI4oknXu8I5aGmzkgY
jnz1jpuFILAO5kjB0HVJ6F0hST997WG+GL1u9lXN91ETYLk2TBO7sShsd0Qh
4b/wSZO9SfMu2oRvAKR3XuJK7+KS1C/cqb99E+HDFsh9Cmz3KnBZEqC+GST9
TJnjsc2eaKg890BwSUEc0a5MzGZLGVG1Rdu1UQDgTlN0TOBTPLyKnGuRaPMv
FYrepT8fFTEPOxvGytl8Llsdl1l+H1FD9hqz8L1EMKUd08Abv4SU/0HaC0EN
Hog5MTgngq5s78pyVcyVxUwhkxFdR05TH1iJexa9S0iPUhLejGdUYDxKNGjk
L5toJgE1lMTztS/SkQe7gNc7V3Ws8fIp8uUGchSirFqyltJcepzeouo+54Nd
jIOlx1+5Fohc8eGYgRVo7Auf6hExQULkQ/Tu4v4Gt4hMIYmTUtgGK/pcpFzz
MEVefS1gDWYsVMs06Iq3mBErYo7mJgESuWRIAHdQiKykhrurY90Mm+1j+gSv
q2x2+4qw8eRKBjwm/vPYzk6XC7nqFozTU9gYre1g6x/KFD1PLZm6Uo3UE19b
djqfPdZWT1bJHLfX2mBtOee2K11uYyWNGUh32G/2fXt+B6irptPs94zJHdP7
lpmZPnYe1qvlFqiGClIMlMCtaYEcDSW3jsWyUiooy85dq9i5zxSeyuqk4B4t
J9tYgoXCVLz2hL5MMOS/EuSnFmw5DDBzhWI2lMxo7D2lS76Kiv7BNHyw1SJ8
NXpni3KWt9Akewp2WOhqjIxVu+j0JzX231JTJ01KKyTT6PRa5KHl/IJdupQp
FoggJ9Jc8ihyhZvY/0m4xRJUJPn7psw3pnTbAQxyM8pkFjQQl/A5ECn1OCfe
xQO67ZXEkw44yuq3Zv63Sva3WvO3ZuW3SuG3Sum3ZvG3o/pvR9nfmqXfKpnf
amX/myP6I/dbpeL/UfP+OPJf1Rr0R/63WtH/o+b9gZD5N3nsotb67Qg6LWOT
qv+qmkM0avXfqkdep9WgryMudbFKFW38XxUl0nyewkpUeGVcpZGnt759HU4u
AZzc6zI3EK4xaMZJ45f4Jusn9zX90HiO4RF2o4xSExw4ixvC5qMtJRKg/Sa4
3HvB5bhK2mW1oEbabXB7ZgqDrctExRjq6GqhI2L+ggsVP1ED9prOlNOZQjrs
uhID15XNdZEYeCzQkhlZ5owZdIQ7VleiDkYLbIRBW6koN3IlWOGl7RV+pIFR
05acc1A2A3O2Dq3nEb6C3R7pIQffbbRGNlutZknpf/Ctck0yJi5GxgPUNvk7
DTMslafBM66Awpf1lhLaYXPadaARNmI0Cg3NNT5Q2CobYNetRdWBoRrozqfD
HtjnTk0FWk/NpQj/o7WFcd0YMaLIkdur3gM7hfH3jN9infhPEyKUVpVsqVop
ZsulQv539W9gtmTK5VIpl89ViMifwnUXAq2MZA5pFeaXsbR4zYUwCtELLgEv
0iEjF0XAWOds5RwzA7fEvDZKiMPwWAJeo5eAYWEtek2jnruaDXaFb2aCsliK
m3NNEM7ibq6LWMXBWT3h0gB+X/vDvCKNEvaBw0ufub373IjHJlVJdHhihBDc
/CYkpyqYWZRoDKYwsIQ4Nfp1bhNEl5gtL/EhdTeyVDZ+dUHtMPyDUnm4lHBz
J46RC+mwgpONes5khUswrRxXDy8ec2KnKKsYnrrh9KbcWRpUn/ep2DFknKLQ
bguPVkR0YoozxuYijtWr/whjXr8yJzanjFfSmrgUQw5EmyZTnRgOtaTyvnRK
Sov2yoV9MhmoAWueSaMt0nlvYGefstw0igGwPgrFQjE1n86jZi4NF4RKFIL/
lIyQWJZSmeXCDz7VmstAVLywbFUjFFaBCQQMmaVs+G9KNtLI4mm+VcJ9Upof
aQArq2NbXjnVahE4K5tSeLobnDWkUmGkPkdDNfCJZyDT3t1Ou4YE+2BNk0SY
iznKAJCuiiurkqgw7ZVZ2SJyZwBk3srX5AB9A7qqtq0xxcSL/5oqGmC8wX9m
tECnzJ65a1d019LzQtXRdb+ILJAtOtn6s6KHhZ7tpOgZX/ppqZIztWo1s01f
vCQYFk6IJH9GDQlNTtV0IQ2CLpvJ5QJqhuCoYxa2nNUUPeC3wdMV93q8zvS6
+lOTT4I7mUiGa0tb/fqPOc4whNfYB8WBCTv3ueqA5an6ehGXAd2KJA2Iv2TN
dIFcS1NcgzFso6/TUyHo+xirUXReL2wxx2/gi3TwLcXwhNwMO2UZj9KjHfjc
VJ1wtix7rtETrpBW9AuzC1VzxWq2likCRx/VxWImWxSPavmGeJTNF8pH+WKj
VCGD/ZMmLVZCdPJo2vB5aur6rJzekqo8VBFD4UDLgRwVMQWMiNcsX9cAfATm
1N0SFfCEr5p0NlMoVkrFar4wzOZymUwhk+VGRw8Pi2k18I2t6kSS/AXPUqrF
me01JRDV/CBSq+NSLpcVcyVZEsu5al6sMlYVi8VieZSXM6PKuLK1HM/Ubk+4
6Z1vutdUfb6Yc8vEX5NRg8BXOl69IY4KTrMnTEDDwWZ9saX08BHxr52edUo9
8/y5t6IGoBSAuCEq0u8U+eEkNQXCjHDwZwloJ6KzMKoZEQebqw1K3/Oq3vaM
RfS8UO9oFoOZu9P0tfFGKiqW9O9PLrPWf4vyc3C8BUZ8QiOf2v8awCdIMuBk
aWAEh03F0EOakVwhUym/OJwMa2oM7BHRv71JZIdXeA20kCUDzDf41grecSPR
eATRHphm24cl+JKSm2GxqRdUx1WjYQiWsh/ORBASu94TsusIhhd1EkEbLEuU
TQjVCy/htkxdcqNHGjJ/ANTgwACZhU8BmuAp8yFsNJx/fBB/oFAqbwlw2VaM
qCGTwkfUhh+CDAu5fLmUrebSmKtqYlrrYTafqZbA/t30boJqdmiyQ2QJPfRz
Fe7iV87YXDJ5zEvhXITpwLVmqj0FTP1yy2CDqCENEnlM3UylEaY9xONfFYRH
dBW9goMqgxR8ltbqWJxJmro2LT430mwUtrLpJ9+9hSwu1QgpHdBKwINURzqY
YUmB3YosvFS5/EVw+LcEy4AZNph3Y9CBBA5sZtxxMQMkBQPCwDBQAlBgCf0G
hTuxAI5Exef52eSEwT4gXaqWqtlCmR8F1zpdPOaCrVA4MZHuPePKzhN2zIBl
JwepiEzgCRU2etwJxY3ANWyzj/qdvb3NzxZTaGd4gWFMPAHBzk3RhyP0CtmS
7gjjf/7DEvpo9FhThiGfBt4/DzezudtqxtPrBv5ox0TnrlCXLDAIhbaqOVit
HqZyTU4vWwC1O2M2xlBy1x7gegitNOVfbYP+kQeQ1uvRWHEvEYGX8S0oqcgj
HBXvUDTEgl4kJ/4rUpIdPdjkcUbvNkyLvYmx9wMF/QqMe7zCJJUYZI6cOuTO
Pgw6pJR0Qe6j0Vqo170OAW8KliWX2u6cwzyYJhJKoNq+m595FV03lzbRo1Qn
/yDfV/LoNQTNQ3KDx6+6PZFTKI/SnAXnnRg0QemvE3h/Kfg63bkatAJfZCQV
hOc/Db7youJDPOrl66PbpqP1VnZoP3lEkBvC+5C71xFp/w0qyBRPR+H7bMN4
ULe7YXvuzxAOXnCxB1q1BKzJG4614whIPMsI2s2Uq2G+XY33NU91BE0/ewIP
guBBBshAgMFS+HBwwFay5qKaPDiIfo+xJ15MeoyDe59nvArOV2ILW+IFg/RR
uZVtPA6tR7vSyZxO8uv6PH8lzTN3rJkOHdR8G6D9hEhJzZuqct0yndrlc9tQ
Zrn805G8PBrkJTsZUnGAkiKVby8yzaw9vrMX6yNHK9Um95VHsd9uq8tkSMUB
SopU8eykpFbthakb0/m6177tscduedzV7y6TIRUHKClSN8P7p+Pr+/y4uZRa
y+V6XKs27Om8zZxMMqTiACVF6qQ1lJd6u90cWSfD2+JNad1kzu2toaqFZEjF
AUqKVG9Yvx+s5Unm9Lgsj04lt1UTZzeTu9yjmQypOEBJkXo4eTy5m98vH4pG
/UZ/Ht4WWqelO7XVvE9IqThASZEq2Gb+bNW+uLhr97NLYzF1TXZ7O2H19iwZ
UnGAkiJ1WTrR5WJlkZGzWuMm7z527jO1u6E5Pq4lQyoOUFKkjEKXFS979cVy
upKbJ4Zyy3pr2C/IZkKeigOUFKkRu3o+P18su+p4djU+6Y1XTD422/NBI6FE
jwOUACl5DL+ui/dtpZrV7h/Vp/rAqR49rG8a5y12Pe++G6k3ASXWfa26WTjq
XjX612tjcV6tXZ5ITu/RuJMmCXVfDKCkSC1Hw3u72n1Qqm7V7OaOZmLFWZTH
i7vjhEjFAUqKlLmojMWy/HB6Wrx6ELv6o1zqTG/6R2IroUiIA5QUqZx77UqN
bGM9eTxvdAvHg6Fo3Y+WA/UkIVJxgJIiNT/KV6XRefbSaheGtUF32CxXFqve
wF0lRCoOUGLdtzqtr7ptJvZr6lXVnV5caJp1WtCvawnVTBygpEgNsit3fn20
fLpvHvXb9cHdpN++e3CUp+dKMqTiACVFanq1LJRay4l+o6jV8dODnhs/no40
Y9hJqGbiACVF6vq4vG4OZ5p+1V+dr3Ptu9L42W2ZRuPx/cLzTUCJV990zjqa
wlrjZsmsPpXOqjczJ5Op1U8TUioOUFKkJnJOfcwsRiab9ofiIpsR++e2tpIe
6gnN4ThAiYXnRUGvjZ+K7ZOHudNonFt9Qyk/N5S7bEJGjwOUFKk790Qerpsn
vXq3497Li9xFt3zXMCdX9etkSMUBSmxP3bQ1Y9TqNKei3LtkXbdxc/G0Kt4v
bhNuseIAJUVqdXOdr5efri+MiazOy0eFh4ti9+R6UL1LqJDjACVFKjupy72l
WD43542r5+ej51peaXUmZv4qoZEXBygpUk5FMkfPR/lyQbtVz56tG+vi6r48
O75fJ5y+OEBJkdLz1+uj0t3Z5fNKcmX22ByalZ5RyLr9TjKk4gAlllNP7Sd5
NDpdSEPzuCk+NhsPbq6Qn4zFhAo5DlDiLVajcnmUvb05Ex3z3FwcX+YGs1JD
11kzoZqJA5QUqcXdeW6ujh+Kx3dyPbs6W/bHZ3XjWm5dJzw0iwOUFKnucetO
NUaV4l1fOps9PR41p/rRQ73ckxPyVBygpEg92tWbTqF3VFnf69NJ7mIkPRxl
pVxufJaQp+IAJUUqc/V8cfV8N7xRtPvi9eWwe9vVVw+aYT0mlFNxgJIidZvv
trNHsFkb6dnb697q+FKdSh05+zxIaKPHAUpsTw2l47Wmt9rmmf50Xj46ku9v
zLZonSfezcQASopUuX/fd48q+VPdqj7VR9mbbKtaMKq3+XxCKyEOUGKe6t+O
J7n782btwjm5LD/Y4+xKK1yItYuEpy5xgBIrZH18vhRHy8qprZyMtIItnVWr
reeCyuSECjkGUOLT4bU6Pq4894rS0rRGw372/Kraal43726Tng7HAEqKVP1+
ueiWi88la9BRcrX8w8Pi4URvry7UhPZUHKAESLljHX7mqqvWw12xXjD7x7P5
Q21xNxiW789uczfvn7+3ISWllZttr+5vq/LJ+Gau5uvj6lOmxKbL+f1xQu0X
BygpUv3jYS2TyZYk8bRr3NVmx073emXOHvTHhKweByixy2hZFi9uc/XajZUR
L4+eq2VW666OhkY3oUqOA5R4426sR7I0XlzmGmJnej0e3ORyldvL1vk04R45
DlBSpCz95py1Ro/SKlfS8lmjOFeddmd1cTlLqGjiACVFqjGZnijH+bU96rVO
u5esIj8/i47c6T4llFRxgBJT6uFMklUltzSajnSy7I/UTmfs5AeZVkKeigOU
FKnhrHl00Ti3B7ePE0kZFVeG9lgpKYupnNCiigOUFKmnXv6unulKVqtVy/e7
o6P57e2Js6rVzxMyehygpEjNZo+XU7WwXpwM1dry3uots7LVmoq6mJCn4gAl
3s8czZRT5/R54BRa1ezN3Bqfdgxlog9yCY2XOEBJkWq77rDWcrPZo4GlrE7z
ncpUX+YeH+eVhBv3OEDJj80M1VzNjobDy4fOYtoyioZ0W3rs3D0ntBPiACVF
Sr216/WaVrl/EOcXg1rZVs+vj+2xprYTUioOUFKkxPZx7/qqWF+4N7fyRW2S
L8v91dKsDfSEjB4HKClSZ8bZfbM8Or680Ourm7unku2oF87pUs4mlFNxgBLz
1HDUOZleKEeFx+wkY8jPq97DsnXn1M2kR7ExgBL7HNaFp5vLk8vjq0pOHNmz
y+H1caekMi17n9DnEAMosT11kreH9y1jXO1cVsqDRU7OPhXG+dLqNCGjxwFK
HFhye9q9v8/eH2ebObU/bK8vC1ZDv7AbxwnjguIAJbYSTrNGo8+WtdHN2XDJ
LubVysy4f5AnpYSMHgco8RHHo/ucGXceK87jvSlf6+rDw53cXy5b7YSUigOU
eONwr94UTh/OrVzGYqXL2bG+vu3n5z2HJbQS4gAlDsG5n6z0rDpySvOCclZe
tbL354qWuevPE+5m4gAlRap0djq5mOdy91er48H9SFTFo5XaPX7u3iY8y4sD
lFgkmG35tOfcnY2Pru/rD+Z51jAuSizbEhMyehygxDEc/fWoXVWnxvnjebn/
qEyn98M7ZzXtOgmnLw5QUqSU4XHFKp91jx9rheJRj60elvZY12vOSUKJHgco
8VmC+CxVSsP7k4w9Xx7dHS0HN5fPS/WibiU8y4sDlDgyodDpKov6qqL1m6dW
XT3pPI7mR/Urq5DQyIsDlNieql1U160Tc6zdZJeN5VKeFoqK/jTT1wlt9DhA
iW30zNlTe3wk2Ze6Vqrei9UHbWg8ju1mJeHqiwOUWCRML461+7U8XBuOvhhk
QEmsNEVbSquELqM4QImthNHyrCorWmms9jKLo+NJrX993dCl3jqhkRcHKHG0
i8OW7VH3+PTo8uK0kbOfrMnAMub1i1nCs4Q4QInPp+zOY8ksL8eF6d3QrZ8V
s4P6YCEuW6uEIiEOUGKJXpIrjVLvqHHFMqtCo/Z01807hWZPLiSV6DGAEod1
WUfFfPlk6uRmzbObet8aXM0ckDDlpIG6cYCSInXVM07vx9f1xrB7tcxPjVom
8zwpVQrr44SrLw5Q4hiObnuYsc/OrotdNjObxvPt6YnROdGlfsLjxThASZE6
PqnX8ll9UmNTbdLqXbnDdbuWzWinvYSrLw5QUqSqYzGXPemeluxsT5HNUUnv
mZmSdb7UE26x4gAlRary9DQ8bg3y1WynOTp+eLi8du67F+d31euEZwlxgBKH
4Dy7uWutrt13Z8eVyXn/oq6tjk8mS+Mi4fTFAUKkmvxK/Mdk0QDj1e38ytEG
T72mdldZ3BUWFVc9LxUHCaVoHKDEhtXsOvN4O1y1a61sxXrQnYeTXC03Hy7b
Cc2FOECJQxQedOX+9FIbT5k1mprLTlN/uFrm2q1sQtEeByixtZd5LF3P7caw
zkZPvV73fNY4qT+u+0/NhMwVBygBUpbk2GnbblgPV63bgl2q96V7Vqt29Ham
17vMvn8ZvgkoKVIXvaPO8FYRr8zB87MyLTYyJw/mrXZ+3Hm/YfUmoKRIGWNL
sbKDak+ZlxrD2WOu6eTvHmbi9OL9e603ASVFatLtLpxetnNn37XGo8xd0ehO
rwbS2Zn5fiX4JqCkSK2l4+OCfTMuzOvjk0z7vNe7WuTvJhn5OOH0xQFKilRD
qmUfG5fnLXGkXBRXojK7GfWftbbceL9h9SagpEjNnVn74brx3DfvjUbpqvis
GaW23MzKi4RIxQFKbFhlRf3o7DarFwan6rF9+XQxvejMRuerm4QSPQ5Q4ujK
o7Z8VLm/usq0b+S1Op0+6tns3dPV9DZhgEIcoKRIPd/nF0pvOHg4fegop8PZ
XLaWt5fu/TjpVjkOUOLoSvnu2DXG5iB7cWqB+Gtd2ZP5uX23MBLuIOIAJUWq
1Z9mnIFUnmbPZYndPDTPn55Ly0mhWE+4VY4DlPiirWva2ZVZ1GZnqn0qVq+O
T27PTqSaoSfcQcQBShyed7Me5afy05V50io4Z7OTi5Wdq7vs3E14oB4HKPEO
Qm+cP4mtRV6slnOlJzZ0WMYY3592pYQbwDhASZE6XTrHffmsc7+4rt/mapn2
qtYv2tW7bjfh6VkcoMSuh/nZUVMtDo2uVcxO+sakaD71s+5AS3rSEQco8U3N
nCadjNx16/LSKl1mjev6aH4qDXvnSW9AxQFKHDMo5i9rlaFyl60VdeV0Zd6s
xezzsHKlJXTSxAFKHDXx2DHzJ/XuY3uiXZ1L/X77/OLp8XTSWCWU6HGAEp8J
NbOPeaknPi2k68lAvKxUTtjKqXc0OeFuJg5Q4lN+87E5r/Rz2ZYzzpn2Wf3k
3LyqrHrPSa9lxQFKvH/vlXqrxsm01q6ODDa+ftRO5cy4WpJmCRk9DlDi8CBr
YN111fNOb33/fNNYaHfayVHmepH4oCoOUGLdp7SPFvnG+npdaM2taTmrVjOr
0rzdqyf0HMUBSmoOt5vW3dnFbW/Q0C9OS1fdm4vKSUZrHtfX7xeebwJKitTl
k+00siP71HqwxpfDm8tr8aF6Or03Erge3gSUeIc8LWhH9l1x6RhPvZNuVu5d
zJys3ruovf9I701ASZFSurUH0a2NHjra9UptjC6GmYejm2nhqZrwLCEOUFKk
WlfK883FSfHiyC50s2u3NRsazupey67ff+ryJqCkSD1ZhWW5pRr12XH2ycmV
pXr98eTUcnvF9+9m3gSUODRdHw/rzsjpN9q957zbbV/dMY3lFst76/3S821I
Xoa1LpZeu3Qx159p2Ht7HapiZzmHwhggUz1Y4cl/zbM/UborS1Jtnp7r9jia
IQoaUHpry8F0SlgIDSsyUfakWyzwtLv8tVf5+gPPxCj8W2xBcq9gqp2sJLbX
6vc9rL6Myb2wbItquFRAL1z+0PazoFH1L0yLS4UssXYXFr6u92siO+q1/vwT
fnQ7g6umWA8ghavGYW0/LISoYhlfrFvu1e7aLnt+cECjPjh4ZRSPLpB/rDLl
d+E6wINqJsDoREfVXxawHW1KEmEeLpNKpoe+sTDnuaDqVN3IYVh1aOwwC1Of
GYzXOG3Ct1Rul5K0DaCXjwJWMv4UFCyOJrSLMCHwTlpVvELUXh0gUFMin96F
LdKkZQqU0xErMVHOypKY20/5fOLlbfNru2NlPxoG8I86Mai0ss3pZ+0oCu1X
hd4uC/2BCjgCbKzzbchrn1peclym7P9OhdsVr8z4wQHP4ctTt/H+Nv1TkS9M
WkeTgJXeXJ2y0PEajduwsb4pFkb7oUQspHKpApGxDbwXVHfFqn006V6qOFqE
gDOQxmC8+JJJhWMXprYgduGl6qeSRRVqZYs5Bwe/E/Z//zvWO7yq8Zrc2A1m
RBUkgWhFRYUjxYWFCeO1rzDxKpAKS6z3Op0GT/9Wb3d6Q/jxu5fz0VUVzL8t
DMAoRqnR9IeAFaeRnjHjSAktkIv4AF4rpgBT4+ejU429aCG5l+U1D+FZ8/qm
4ZULKhUqFf4QK03DIsec8LUOHzVVqFVhyRBWPBsf1ezFnkPj9DOGeikQsYmf
zc8rBM2sWKyFbawJGb+OlejVsdqFlAzdUuF1oA7Dsm+bAsXJ6BQZfm4HSfK8
+yOVSrDxzk0qJC5EGMh+x0j3tvr1E+CKmLtRs0O9B28m5q6nzFzsfqzvemw5
8iuPRUV67Y0juzhyzN94tUmnDErPwYoIOM2btI57lKwwlHXZY5o56CUsWUdl
2Sjjp6X7yRhf5EXcnQjxrdqpQheTX6qhBKlLLLwaVIgzeflnzNA4tzC7OWbS
TVMJH55OkWevpESZQWrVulfXUvIshxpA9Ev8+rWZST5SKUrEGvWcr/tf13wf
pJnEK+Htb5XCO1oLhkm1ve1QJWwQOoaCyRs3OR+jdbxHm0qp8I6Kv3lCg1fD
BjnH05b6gILkkzgNcYWSbVNzeVFNAewmbgW5YJVhuVET6xpNTa88oGZitQ9e
kmIruaWXsBKtDCzdB6uViin7U6x5aOJIsWSPDwQGivlVVW/qKK0mFvvktg6T
bCxOOmJCkJJ0tN7IS5y/oA5hCiQsWHQgbRlQaRH6hLe1sYwwTFb8IOAb6CFa
PxFZGYUd1iz0SqcCSyGmfhZQv3Dx4aaOJ6WM9XvWQQ5hJXlM32rQ8GyvQpTt
jhxtZ/FKoQmTL1NW2CiHgl7/oKZY6tCrMjinVLW0qCRgXj8JKFeBITby1+wh
PPFyiAoj4Gkcj6bqnmYXul7dQzDSQFULfap7eAgWtqVKOixBEF/SWDoUBq6p
gxVScy34caPi2rc1aSE03BFbz8xD4QTzimMzJpxIMljfYI33TWMyMoUj91Co
T5kxWQFybVdCW6MtmUsgMH5xKJxKa0loWrIKPHMoNEC1nLpAHCBjDQw5Rzj9
5z/++d//+Y8ZQFxrCxTQR0yDiZSwRmRzIQl1kBYp4VbFhzAtJ2h7GkKj2e83
z8+bfaFf65wPmuc4LtvGWsyqBIvyyFInU1Qt8ByY2JKmsKmApbMGA7Vuahos
fD7FHSxG3JenlinP9onzmTdbYckoqVwEvlk5cw5veQpgqqFJVYkDVvfsLr+I
6+uy82XdTbQBaeUeHABec2SkERbQVm2+Cjy7ckepTy8F7pxXS/NT4NKgsJoo
UBzVIv4eA12CeuEgesOteD8oo4AAaFV4XO/tYUjw+VWmX1RU9dP60r7N/xZR
Q/llSXMVcxN7MtUfJ6he5pWO1taBQAmt0E0WY3vKC5SHTKeUMADBrBowbc8B
3fn6wepumkL1qqkjEgJ+geig153KzodDKYk3qCIEsCVgeSwo0zKCwUqzkiNx
xgge2WQbbSaTt/S6xK9mjOoYb4pW4yhdHcuS+o8pqzf0TkUjfUsUWAlDh4A2
fnrim92cUNskFr7ZCPQG6iV7b2B6Oxw72CoHAA6FmWEuNQZmHl84VN0W2JPM
tw05kQwkfbyqAXFsGcpyHNIupCTR2uqIjdTYtDEbOCWvD1cTyFS5CRT+hvYi
tHTCn/oF7fm3oAae+YdU0he2zKATbNyLqwu+70QT0Ut4rTNG+c09XQAyDTdp
FuYVDzgGuRC2ZTiHDlBAA9EtYNUVfOjDoTm035DW9XpdCO3VhX7nmAso32BL
CT2/ZC7XsB+wcDtbTSUUiUB6WAk4b/vAUqCdFML873/HqsKbB1g4mw9G8HZ0
/jf+T/iCUlQTl5I6x60T6fzZ9qzFz1E2g+QF+uBeDmY1JFq4IRQSp2PXIpPH
W2JbxhPHEOsEoHV76yVmfx25DW475hsnjMbqG7WEjFdl+iqgVFCSOUTNP/f2
vpBx4qTbaB99gQ2O4TL4bwMY44O9L3zZrMkv8K0IVsir/4b3fLMkHJnACzgv
gTHbrQt/YPEWw13BtLs6WjHhPPAo6jY7dW0upxiiZafpP+lcJo249Cxp4sJ6
rT9jVTQJnhSFCxm0NzaHX5/8QtzxoKicsDripmU6V6wU0/tg6ml45HUo4HhN
Gs2R2frXxbpUyOzG+tNxrXDcFrIFZ4orzMBa8l2+8qNnIROpMJnSYQjvA1uI
c96CEO9DE2mOxvIXIVeByZw7Yi6KOu8+Ctc3NLDAAFUeCeXmTxeyxUy5kC/l
hj1e0JweD7HK7MSViC+HNIBhE7a+xE5DVDrDNhhAIvDUsO7XvqM8/sBcwy3d
MFSNYYus9eFxpzVsMDxPGsI6GXrnAcpwcNYf8mOfeGG7HyFsrzkQ6xfnvKhA
7qOQLSGJeZ0NoenX2RB4kXs0DpBXFnzhb0g0nohz5qQmKtYIQYFqQGea4xqT
NAIUXyncQQB5OTiDn9J+Ec7++Y8Rk8HW9Ap30DyJuSpN1TdNUqFSLWerlegk
7SzdPMRS3mwzK/Zrs2KOh/Wbfn9YzeAEhctLDIPyEvuc0OHqDRu0bVAtdmpi
mhOvxImipsBcBeaQsinVSTPbtFTZpvoeSJ0rU4dV1wHiImGyBTFb+Q6EKWRL
uWJ5uFXEAGsYDKM2G+fYgBzwEscdZkFvtKgRhavaoI8VSuFj3VfUG8TQ9kIR
AZb/5gjT+wqLK2Er3jW6S8RMPu3XJMLfSIwb1XJc0N1IiDeokLwzPIiDTZhm
pzkscddXVORIEj0N6Vc+opfMX+oiLvVNEXWfeOKWwSVmMrAyP9HS3OC9Nl3H
TY1Yel0c9q8yYuO5nfnd+VuuWOSExsqmEqhTA4X6VediIPRdHeyVbTajh6Bp
TUc0eRGogKWOQe6bYNQdCi2LzlC/CJyaDHXDhqSOOQdb114b5hxM+w1ssJGA
hVUDiJUaW+ncfG5OrNx40D917Stzkr+6G/Uuf8et+a8EYlMSy98moP0eKYEk
hSuLMWVqyh5bfbcR5sSdY3yptV6Dy8tezbHMmWWndW8b75+40zYeVdnXLMd8
tVLJZ0pD39AY1jw6obiJiHtUHcGDZqN9UY8K9wZubwJ75da0ZkLfgV2OLnxo
9G/7+6/pTnS+DW36Ms2rd/qFhvB4jQyyT8eaOYK1V9NwM++VUzoGOusgrshO
asNuCnTJB9J8r3YVXce5Aux+Jt8kzPLFUrVYLnJJ9XPU6faide1MbslGqWfT
1FMuVs2T03Sknb6uGflKVmGqJErdc/3xuD3tPq1MWc625XWrPLPPNImxUzZe
XRRG/XpOb/eel73L3v0xyynGw1Xqeayx+7quO6A3zOG5J24jdY1qHaHH96V9
PE/2zCSUDySUs+FVE3Ef+eIw6y2bG5UZhnQIMwKsQDZeLiucuNp6Mz+4nX2v
exnAItlgS8rstKlMlOFKnz5e3qlXQ+nsXnlybhaNE9YqfO2yyVSLhVy2Cuqd
H24Mr45f0ch8orEQsSoPax1Ow36zNvgxREqkixDuC9UDDzn3+UX7PCc4qo3/
v7qr+23kOPLv+isGa9jYNZbizPBbh4VBiuKHJFIUSS0l+YEYcpozIw5nRvNB
isoZ8Bl3SC64nGMgCQ6OLwcccEESOPFDEsPAJvDD/ilZ7a6f7l+4qu4Zcvgl
ibI29i1g75Kcqe6urq6uqq76NehOcMjgN57ftOTedXtIoZMoXarCwBJ2YA+J
C+lMeLeGRuh2IpOBCf+wrDFXMr3wDWRaX5t2mBgzfVaDjYj+C2ms4A4f5g6y
Z7qFwajOSFj53q7Ft+ZuOO0OHSeSSkS0RXMGuYN9+zaDml9vE7F6c8tugWd3
XndPM7m90912vtg/rcm6cZaTjshY99TO+eF3tO5KplsvbN8Ln4TMPJ/uZ+mp
pmv3ur6tJyRW3kYOVot/893MddfXG3aFfKlV184u9hwTFmVMTCeWLUoqhTcw
ZiKtTpT2eiK8t+XW33sl3tPsBK3TCZKXNTZ3Xf0NM1Ksn4/tfHlH2RnBjAix
OM9mpLxTK36v5VQjluJLKb+U6evxQUmftz0hMzy+7ON2EefjvmSiIemopjXL
gPDVoI4hdVU3IoPqwGuEZRIFiVJssJH9O7slw9HgiVUXrgqJBK4DYHaekeAa
XY2Gp6p4Weuc7X9z64QtgoAYqNQkTIFBQlMwty28mQFR9h14Lnw7NwaTfhmR
ZaQ919dEuK8LXZ15ky7cvkui7IJqPy0C73+97rpi0MuzSk1iSjoigdXLckWi
fudXbH1LfTIW7dvUMdbYw/wbdk6Gsrzq+nRKBtp6aLEgDTuY24VpAE8DQ5U0
hicZzJPTnK75mDtqZJFLsQh4D7OMwlyn+TtUb9jNhHQCXIh0u4GnJhi7u2Rx
ojnXazk3Jsd025NTx4UoZXjk3ckbvi8EAr+Nl+pyVYkeF0wZXJjwb3Y4XaPb
w3uhZ/2oGM9lLVvTr1Ext+JFPBPPiO06yhIOH2UJXae5QFE7e607tOgGxVz1
VHXqWiR3ursfKZ6fGaPipZrSjI7uentl3Xp6dl7RW1ayVZcrzdNk8jRtRdIn
Z5JEDnod9Xhz2ywlT3JeX9rzJF7pu3gqzBK8tAH2ZGBxPL8lprZ4nk4UOHlc
je1pmAUywpQAZDYLK1NWBWmMS3TLfFBZwudxweDzkUmYoYLBbHB6H3PbkiHJ
EvdwyCYEfxRSMzNytwkRhVgyKfDtJqY1oaXlP97eMaAp08ADmXazvtM+sIjR
bnjgJF6n4PfsjHlhCT3ZwJiSwKdj+LRNMA93FQeCLB2wLxe4EPF3qAgjEaiM
KqzPxngAi1HDY1IDTT6uiaEgJzjuDbS72QtdwwyPNUxYaXOBHtOJDE3aFwXm
3IqCdQbfzS0AITnP7iWhnRWU6ISyEM4yKyX0GtON0Z6mE/ZahI/Tv/m4kGyz
/r8t8m+LaeFtMbPCPbtNN5bE6oUtTkjcd6w+sV6sfk+ydcf2VBKO1gvJyL0I
O2qfBC/SOA14EauCYMjRu+l5MRVL30Sdhtjm9wLQgCC0bbQD/ZkpNisFFtrf
4rKGgTIYOIB+BkmryD1gbcEvYK3KVPYDYX8w7bviDno03r/psEXh4I5BxcM3
Od4DY0N5QthpiXcZaWB+CPzfGxLPDsc44xFgfkWyv+0ukIilhMR6uwBzkwv1
sMGcuNFgTrAjOpUYl/AfZi3h7ekzajRzw4BusJwTyyxn8Oh6NmqtsMl0vW1c
7u0pnYNUfN+Ng+pM8on40ijS7Yb8kLZ849BTb2ToNK60GJK/fvjqcQosxJ1+
NYUuUjKV9EePkY/BQuTjXib+20syH4un4rFUbHWkIohJ7Gf3dv7e/b/b7Olo
yrOsq+XHKfT05IbZ3L3s7VsdQ9X5LIYgBCG1IjRzL4xIvBFGzMRofIZMksOm
KcTs02pP6HpGHbgHZqpqKpqDYh9LCIFHHPDnbrGaxFys5lr2xSMLHLxb3CYR
itvct7d4h+jOqnmdi+6s1dPrZzMpZhPp85KQqZTxSFVM8YFXt5jmFdqfNVf1
OvSsHp6LzG56YQuU5wqkc42chwgtPz70yQdWtYNnjh0M9hohVgUJxDR/mKUP
s53a36iL4AhQi1QU2PnAPywwBAWUMqXDUhBGkttV3xs+0eTzUYdXC7rqvIN5
a09q+4Ne/2i3G8t4FfXUqRYH1kXkPB/xts3DcUXRy9Y76EYkBefNZQEI12QB
ZG7g+Ppt3SYJQPCVDpXMqfVw02GMclQ/SQryU61Go4ywNT3irguxhAx405HJ
YHoU7WAhiKeTKB3bitAKKBaZDEEhDvAE9/3CQSO/U5lzreYJI3dz4Go6RHce
Y863gg7cP3IxgduVjIgwx+5FD2tlT5kfXSwVC7nKZK9ygc3LFMc8FT+JjLKa
Fho6yygxKlExCXu+yJwykRfaSd7LEN5YMTv04+Z8g56cFIXEkkY2paGwOSKd
wX0qDjGF3P3OFQczksAooqwTxNQK7TER6Bofd/d3u42LXuW926uLeCx+r1o3
9r1gns80IXYT07oNe/u0OjZTbWUNptFQzX1yLcnlSZdyLXET1+YIRdfmU46d
YVMrnJ1hI7cSgigkb+LWqF2xzyqkNK6l1+BWInOvzBJvz6t7ljAa1ZvU3ftc
48WbuCYkpeJpxDzV5HVkTMyI1B76wRbnaq5OnjwIVzIEafNkWtEwUyOwRhXB
gw82WF531s9un2R1T7Lf4QlWfQ9r25Ps8bSUYZLjzwoV/aqQ70XRAi04Y4Ws
WKURlKzSGvy5yiTT9ovXWOK/yZASOAlrgA2sPQRZVcOZlwt8xvcky8KKJKwN
tWys0J8p78FGaAmb1COTwibNRpQC29miM/AWNxfS2cRDQ/bTW8yaW+HWPNrg
uAj3Po1+tEJr6jZwPTFyeFE4Oyzs7neJRJJ6vF1Vjo2Bkz8JyFIL8vZkKbpG
UumcX/DHJ+nWiV2KVS7iw4O0IUa8PWVCtrm/DlW0KdL6+LykZsap9v4w2RG0
Y9U6Oj+xLb7CB0Rp6OD2VNF/jzbNoaunRsrwcrTbaopl8XRkqGb5wDg5nHA2
m709WyVJiZ7lTp/2UyfjxsiSCudjOdu7aMVi/eppbTL+GhprrOhxpgITdcRt
27ICGpGZKs6onEy0atI23+qc1kcXzVxXN5r9XqoxoFeGY/M0D0SkriOrinnf
VW0iycJtm5amBKJe5zLlHW87kcjJpddojY+rVWfQ6rXdxiGmLMLi8KmLd6F+
UVLPspl475LIyYNqeVirK6NmM9KqD7IBL/ONyvZajJMHTjd6uC1Kcrl70r/Q
mrqh7XS7KUXpp5O57GSSlgQUric8DSXUyvaueNA+PO9Wj7JGpWy0n6qiWB60
Kt2Aejg36P7ziaaao76gOewZzXFUqNSLW2uLAEOsOW3t8V6lkhEP5JFe6yjH
ueFh1spbJHHXyffp1tV6yhRKduuiV8z3lPpupZ5M1HP9/I7fbRrgXrfTGGuO
VjsXpfIoU2pfWI2TjtI7aBsp/Wm5QFrOHftMyR4lTkpyRtBPzrTz7aabyZ2O
n+arBXJkVSaSWq7Wb61KwFCLttP7O7G6J1wcC0lVKe6O7HGlWR/VTSkbmmIw
aladcfseKD2lZkt/1gRbNu+4lJzNlXSUaGgjjtK08qggpEQ+JcRiq/i3Fs0B
+vQKicbAP6Gdbma379RR8AemHczERCFz9w6GaIk8n0ynE/x0Bg62a7NrDCv/
GQESWmrw2OTYCQbkjzM0IrNrRSRd36SHkQ5rGF6KBC/NjCYlJNGN9qmIa1Oh
0bv29AwJDQ42uAyfCJOO3RvpeDqWxsAtnQOfevzeqCfEeDKW8GeFW1pdhNhe
qBGZ1ltTJx3uyRafqsWPSNNz1Oy2cJ4huZxr8T425STk9v+t9gU7vyK5CDEZ
TPAUvQH3EPTMo2+nJkQhnknG4inaop+Niknz0wwb7mE2Wy48mqYivBOcss+3
LElajzU0UqaHaP4Jut9guMYRW0/w8ZgYo62H1+IaEhjoJtiJGR1wpSmKTyip
YDywpGlRDv2IsoRnyBRwyU9XyKBs8fiHAkKB3JZ7HHiOtJI8BHOCFfBDCUw1
FFKcE2qyUbQrcMV8YBXmg7Gif18qWKE79TEecxarjdYJYqPRFij0xna4CHRj
5lPgP7JaZER+GBGcYkKDmLf2uOfPCHCxruGwL3v9EQUXMGAD0whngH+XJ57r
dFXOsWzSpYc3/edfGgZhT2ByIKcQ2yCIDsDtRCpAA/jLYYrfDtboey5WYaNZ
hUgS4JipUgd+q2iuomtExiolGQiVVSTZIRqHqEnPP6NGt3vpwZSUVUQXyxEN
eqs4nEr0Hjzq9wK6e/Xrj17+6rOXH/3m6uPfvfjLp6+/+NOLr37/8hc//N+/
/Ns3//mrq6++evn5f7/++t/hgW8+/PT11z989bM/X/3+p9989IcXz758/U8/
e/XHZ68+//zql7988defvPjrZ68//Je/ffjRyx998uLZ5y8/+9eXP/rp1Sf/
cfXxFy+e/c/VTz6++vFvX3397PUXnwC1V5/+88sf//zVb76G53G+y9lqdgFn
pTkDAaRKDsL20CcZ7ASitGxgSXYHFBlSyXYDsAMaAt74wZZBi5mJ/ORBD1QX
efDBxuwzDHAMS/oNgvAYko1wN4hJM4fjUXbpt1oAFhgOKfRYmhliXYAqx87Q
jQTBNzx6LoHC3vN0Cq80oNAbfgn7AnoNCwLYDCtEZsBnFs4z9dQDKKLNgDc+
LhFFtnMYaEUQhUEwA4eh2rEDcAwYBHFqDvxcxDUIYQ1xDi4hPzMFxBWZgzVf
4ZJ+CjCwtbHx7rtLN7F330Xcs2W/fPABhd0YaY7qY0zYNIQBa8RHA6AxCtLV
mLL1l/gU2cSPVGhBUITCQDZgXY65PRQYiTvQDAm+y9uS0zf9v4ZaF76qSHYf
dEvdk8fwKQxsAx93Yb3tSXhkAB9qROF2ERAJMciIDWsGprGAaIHwRZ10SF9S
uQPgr2zaPfiqaXY0kMqap+sOcmVZqIQyZdkPPk8U6L2PriZNRJMsGb4Gi0NR
XZSjqWSxKA8sawu/D9COTGNlm5RxOzZsb3XMIrJ1ZNqup5owTtt5/ltjgWFz
uEPIGttDqB5dMkCpuTgRLggdt2eTAbGRLWcSqrASTDF7H5F/mqo5cEwkf+IZ
OKZdTaJ8rUlDonNVrW8aJiwN+GYbdoQxQgex57OGaYwHiK4ZrpcOAKlsv42u
CQ9qoPdcjXs486CjEgv2Kxm3xbxkgHRUwKiCxeXLR900lL4nYYepDBDECtmX
PJmNzEIAkZKpD6hYZGErsCWu6On4wQWm12ypLzkqHQl8bIyHFOrFly1fRCoe
UTFXGQe8a6oGvEW85/8FHXddhz2dg30c5Lgk6diNFqE4VQ3YBDrYjwC2CXES
pzhN3OIf5N8MsNNkfvY9k3JTtskIWaDTyVoO6wQ/hBGWaA8sVcOsTHWgEYWy
cjiWuYO+pFE5AL4idbQBJFimLdOUB3SFFZ9/aSMlAvIiM/kANdWQXJOyqO91
mIgh8oRrjpy+NhWaAqLSgLAy7oINAKo17ykKJdwgtqppVHJ0CZ7xsJt50oF9
xNTJmC5IagEiyJytgX5lazEfYZ8CpUTtFIRMY2oHIUlQMXXNSChmTNXw7Nsh
pTSUdI/Gk2fAK+haW1w+IdyujQkoyn2qgWAXou2XTcNzYbpVsIMJXewLqGDY
J5X2qcCi20tURAlhMR2uCeaMCSaEhhJwItnorauk16PzCmuG4YXsw37YgSWG
glzUbE1WYX+pQBfH0oDKJ3AQDGE0ImFWXbZYTEOiAHUlc4ySggsTJhWsLS4n
2aiTNxBDqwc7F51G9k9/DpdByixsHty03oCB++DWOzBlQvEG2V4q8vhvjAIL
mzE/E1ljyMOhNidGLj1voFBhkjPXRIAGF0AZTsCL90C0VZC2MYw1B+NTpKFk
LNOqVdBRA27PBMMOJhmHXyToIcGWsrHR8Ld5aoo7QQU2enqPOXQkHyMwETuM
YAntDD8wEE9WQ8FQwCiLAsMFPQFKitoPm1yWW45WNCVFoe4csLxhAr6DaqW3
LHB7nggpNL6XIudh53qIekWHzHKSJyibMx7eA99eJ3QvBIViKI4Ce5rmF/xs
Pni08X/1Vmqk0o4BAA==

-->

</rfc>
