<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-49" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-49"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <date year="2026" month="September" day="28"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 330?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 334?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against implementations of early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 13 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.8</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">3</td>
              <td align="left">3</td>
            </tr>
            <tr>
              <td align="left">8.2</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">3</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">9</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.5</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">3</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">5.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.4</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.2</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">3.7</td>
              <td align="left">Low</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <t>The vulnerabilities cover the broader ecosystem, including but not limited to attestation, authentication, authorization, key storage, parsing and resource handling inside the runtime. Any vulnerability in the whole system, and not just attestation, breaks security of the overall system. The key take away is that early attestation adds unnecessary complexity to the complexity of an already complex system.</t>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">7.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">6.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">7.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-f96w-jjf8-xpw3">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">3.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100835"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100835"/> published  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87851"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
        <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of EarlyAttestationBleed."</t>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="security-researchers">
          <name>Security Researchers</name>
          <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
            </li>
          </ul>
        </section>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100835" target="https://www.cve.org/CVERecord?id=CVE-2026-100835">
          <front>
            <title>Contrast before 1.16.0 Remote Attestation Relay Attack</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87851" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87851">
          <front>
            <title>EUVD-2026-87851</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1119?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y9WXPrSLIw9q5fgeiO9hzpCiTBnWc87uZOSqJEkdR64gse
ECiSELFQWLhoTt/wix8c4T/gsB3hF8f3J+bJ8+LfcX+JM6uwUiQknG2m751u
EUBlZWVlZWZVZmXyPH9kK7ZKPnK/NEVT3XJV2yaWLdqKoXN1Q7cUmZhE5m6J
ueU6oqlNHZX7UL9t8tlMtshXsqWMwBlTrn47HHKVlHDKRd5lD7zL5YqVkv+u
lCqccqIuczl4Zs+JiR9a+NpZcrbBkc2SSDZgQb8WMqkMvJAMTdFnx78ciZOJ
SVZvDcDF/ZcjSbTJzDC3HzlFnxpHR7Ih6aIGBJBNcWrzim6bIj8HbKy5uCD8
VFRUPl85spyJplgWQLW3S/i62xy1OO5XTlQtA/pWdJksCfxLt3855X4hsmIb
piKq+KNbrcF/DBP+GoxavxzpjjYh5scjGTD5eCQBjkS3HOsjNwVg5AiGkjsC
wCYRP3LVQbN6tDbMxcw0nOVHbtisjo4WZAuP5I9HHM9Vu5w4g14t/NGNIs+J
AS3wNSPQzsPonESe0Nl99SR7tCK6A5j/ynEuVndt/MEIcwfIwsRwbXyFjzWg
IH7yB9mI2lIlKZg5fC6a0vwjN7ftpfUxnQ69TAM4AK3Yc2cCpNWcuahposw7
lqiJvCWasmim983TL9BMFXF00MwDvLd5ikFPKcZeQOnDvJCa2xp0dCQ69tww
cQqgU44D1lIZG/3SczvkbrBDbkg7/IV+ZZgzUVdeKO0/ciMizXVFElXuRldW
xLQUe4tM3zCJBYxEW3jMPbqJPJbg04/RJ4YD2MLDNjE1Ud+6D2XAKCMI5RL9
TdhceCQZU5KkGEn+sB1eZgBTMtkzrltFlObEUsUV13AmZLsw9g2qbpjkjogr
Eu7wF2wl/iGzZjjHv+zp4IyIOt8TTYVwZ6L07BB7XwdRWl2KmmOGSBL67RGk
RtSZ4mgRfJ6wKw27Sj2xrv5wdGyampB9qA0NfTYxuJqzD6MhcMhsLipc2xF1
rqrDMpwaMAlUBNFJNlRjtgXSpE65C1tORfGrzxVdjGA3UR0iGzMd+v9jhs8O
Uaw+J/pso+hcB3qe7cOtG8ilSBeiY6IQMN/uoyMaa6JzSIGfMvg5cIouZDOF
TCGfj0ftXNyKXNOUFMBhL25rxZbmIe54dEzFe+BhgB+9EFOFVR7BYwHAU4QB
/8OikFLSfB8aDZM7dyaKKoLymWvE5s7/+Y9//vd//mPBcFJ0C5dqijtPcdWU
/3IPvo3+XFG5qw0QUA7xeQQt2UwtHMlZ/GHQz0TV0XQlBXD2su1WXYnAHrAE
VABgkr1UQlaYGzZ3IU6sKG3OxKWoRxfyhIKKn5fmSuTqKa6X4u4U/NoKEaKZ
ir56B8/66FwSNA5wpqwIUmQlSikttWYQ/1iahm3oKW3vSj5zLBso0mgOh83L
y+aQG1a7l6Pm5RuLB+Xa0jBBuXADxVpQy8JRbdFDkbJXHwTKDgVbpqhLUVko
EwsUvk6ssQVzYxP9D83SD5GyJ4LNoSmqIuogfkxlButFVvYh2+90+ates10N
ITQUce51IhMbzCiZqNzIBAPGiOLYtUU1ymTLuWJoZCamTPhE0Uj8dPeUBTHF
OXftwHC2OuHrhqrCZO/DsiNa87pqiAsgrkRtvqFtTKeAGXIfPtyRD6IuylEB
obHu/pgDKAlBHcKrC3qQG0pz05AW+3Bp9roX3SrXR3aRDPUUe09FurKJqP1B
KPmX7lcpUdnXVxX0qSmCEFT39VRTTDRWQetydVRcO2vbH+3NeVRIU6CpmaP+
MZGcFDC5AwM50pl8XYEJxu2afCm0UT5SKJ5dv++LkAlPzb5jmBngLd4igBdi
CK9hvbrGNJjPo4shGxg1WrkzRyccNj9lXYnmjNiBMbder1MgVAiaeDNokNKJ
nV46ExWsHaRIOp8pZ4WKUM6Od7BD5MZR3MYRzPDlWNHHHmZjwIxZSp5BRv/h
mbQBOXOTck2w6JvblGfFRJ+f8dDGNT8OkJc3ydL4GTQGY/0wjV0LFu3ld1nI
FKcfSKnoYF3o0a7osviIX7IHLvXqRt0YutsSRgZOsbiVo+qwzicqwS2gSVC9
wjeitIB3igibQhge3RWS5Zxo8KlKm8LmyHLB7+FKaUVQWaYBhwGRQIH+rsh/
290CBXOQLXI9ZGI6D/CieXPbYJ8KxXy5HDfK5mV3WP2XjJM4KzlFdMUC+8Ux
jSX+J01/p3fwjxtqdBeYbD4lw8KN6f7tqDd03O5poFqZqfiKEhahu20edt0T
1HmwpfTIAoYPwkZ11rjncDVNFWJyS9Gef+3Mu1vdgBxCmRuSpb2XGtkfTg0J
NJcoSYhAc6WAASIRDkzQOacroKeItrS39ETB0BQbQaBEMu2GaIsoUcBK4qq9
Bjds3vLDy/43EyYbQ5iAo8o5oZJPtiJ2Gn8DO4favwPN2Al8C83sN6IZR812
Z1jlKcfw1W5UxXx/6RFWNtlcdPXH6hswfE1xpRgqsU0rLSG6aYtIDmq1tCiv
FMuAnbWVpqNZTWczXlttNrw2m5UOK6CbAKi/ZnYpkt0libu0lJ8vaMLEE4pc
1ZnBxuL7Uy+/3OT49VN2w282+W+kXu47UO/7C6afRUizCGy4zJf5p6y5/jpC
NuUZUYFb+OEW6KNZUXoOiGbYkTNX5DXLsZBayr4VGh56gnETFw1ri6PGybPs
wwOfP80k/kkqrPjpujQ/PHBvcJw7uEOD3lmDbYJLCad6aYB5D91ysqH/xYbd
pk0kmxNVFXhInBGgxAS23raDlPk5Q9eyzzN+bW5W/LxcKX/70HcWUHOj4FnC
jOsRa87VqyhU6QKRTAOAwe5TmQIrcBPY3sl41gikAUShQd1FnVsSECcmaF2Q
LdswTVApEHQT/ACymBtpxS9zS5DIOSn37WTJR8lyacgEAdgw9YC/iofBFl36
cwOGjPiJCjCNjH9OlZljssWyNkxVhulSbCqZP2SKxeLxKTKQsUaiqQYelS9N
ZaWoBPiJWPCbNv1ZhMuViho/z5XWIE1Wz4kIh34b3tM7igrQeSYad2UIPUV0
1Y+ivzIaw94t1E51JCEeUClAmyo6ghQJZbrbc0S4CrBb02N2lHjqgDaAAgah
QuwptQrxQVqzZkAV0U5vcuR603q6bp1dSEQkRTU/vpzd65rVeEi/e29JadmH
eRSB7LwJa1/dEaXeS25Q5VEJSXPkJR0mXUPmkhWZ0w1YWKCuI/KWeCoJJC0y
HLZ11XuYErmEXOKhk2a4HmaQp+Lzis/nQNaaedfO20sQD+ArYsyMA4RoGzjd
i4//bhSZGYepUXqarvlCztT45Xz+NdQgxipKDhiJCtKEB3NmpZi2I6p7CCIR
0wY7Df28FrcmJmGUQSH8o6jwGq/DVFkWpkt+VsnP4F9a5auooh2kiqboyr8d
SRCpGMOs8qyBmfsEZm5WKn4FPUxbitIDBCasUl5SFfSL7yGHb8gzSxZsl2fH
QNL8cKpEUTtMlMKzKfGrcinPa5vV5uuIwsviAWHyTecyDXZ0beiemgoTpvij
CbPErVBhDWJ2Oi/E7IdiCWNLzo+gzOiqPrq6+ZeQZTYrP/PadD4H+8mU3k8W
b2uY37c1/HFski0kJEiyE4eCVgYe2cAKepotv23PXDiwZ/5BjPJjCTObr1f8
ylxm+WylVEhMmG6Dr5uKpaA7+6qbEjIpQcgX0rlSqZLNlFO5UrmQo4Em/of7
PCXUWEXvB/0CbdyIDVs3tKWDu6qPXAv9XGDV6qK6xU+N6UFfySVsoDyaFd70
l9TrdT5kSKdpwILKW0si8YrMSxSzd5uz0Tc9A2xEcSpGX4xSsMs18aFJpoB7
iIKZSnrYT2UzQilFpxve8oNqlGjAEyL1PU8cGxhoRv3gGMBmkxnunmB3ZO45
fdCR1/Y7lQ4QCc+DHYvoyoYa/7hBA2sB7Me0aEvZQnqJXj2Xr9NrouhzQ5UP
U6oumjBbOncX/vIddOwauvP//R9cTwGVDfuM6MsHGD/stxvwryWsPxJ92xHR
tc6NLGluTGEgs53GogmUGc7JFAa2M0dzQxMt4DrLgvHtoKqA9UBUbmAo9otF
Q0jqsKBIrd+KzlSvOxo0/2Jxl2SNvn+NrKnVPqRLEqYJjQpsxV2IW2DXB8Mx
UZw0aJyBxV1FzIzKe4SBpBqO7C15sHAUDDigszdRjVka26WBx+D/NcU2CW/x
OlnzUw833nJR4wE1nkyWU15F1PgtoMaLCs9CICze0GPmGXFwBwlLu+piAR9R
evB43qHoDiyN8LqLUs6nlrevdVtw7rlaqOHOkaHvKD3I0nTklCYwdosHnJXZ
HPRp2CUdUEQKsGWrio+ETB4UC+7U7xdnbMJBcoV38NFYSY4FaIY+qKmEyDuH
Tns/AeY1CUGZamNAYeBjvg0dOeABlBdy+1//6//DVVKZw+I3opWEHUb8Wq8/
qItsRahUxntHMaaDGL8axHhnEGNjOsZBjCsZjAQI4z/28f8a8e1H+R2FHH5C
JlPOFZJ5/NzTvQkBViackBKKQOrXfMyFj3tcEIkddAw/1tqdrtIh1xdo6FhP
bqzrCxvvR/J9rq+g/R40jxQvbNANa+EbqSmTxDyePPEEOSa8EN/3FZ/J736I
BnXki+KbX1Te+kLIeF8Aw74wXKaiBLvPo1QqdXTE8zwnTizqizs6GoESoBHG
nKhoFlqES9PAgxrO9kOCZWKLikoX7N//Hg1Q+PPPU3i248pnD6P+7N0PqZN0
z4fZfR/CQxqfRVchINRW7I4zCQl537jkPqB1aR1z6zmoSX8s9LxfZGIlGJd/
IAUDmxtrjuzGpHNTOm4QTEukliKRU2gERsTJCTqaDLCAlnOwBxEY7t8t6+TE
267LxFJQxmqiNFd0gtaYSfBs/ZSzFOw0EO27fpoZ9WOogItJnh0KBajk6ngg
xd//HqfKkICvRyLKoNJPThywSBBP0dwCArg32AABT05SHDICSEww4i2M9+cm
IAeg48mWjsaTpdD3vvgiNmnMXHQncJ9UdacRAYp4CoRceQAiNdfhe6A9QiC8
MaVWAbTjmI0MoFxj3DYwYq5vGrd4mHLKOWCJgSmzxBhxPgviDqQ+0S1CtTnA
NQ3ZkRR29H2Kbml46f9EBE3gDLJmf8/FFRCDEPQ1LnRjreI5fYguKlkBYyGS
C4J2Jew0U1zdMcFUtVWAh+YxoRQ9ObHXhn+dJLiJYuiExl9FrqDgQ2RlfArK
kcebJtGn7rflU7osdPrcCr3IM/xfNSmmchzVhNYcxiHORPSP0MFMTENEyr3m
HuoUot5oVeWoTUZ7ohYk7MnoAb97QYZO7nLpKdoQazEGWopL2pp6YC1GGckj
F0cUeueGzWBwzwXduBOCCIDVD/sPQBznMviAdRIwFUMOwLvdYTwuQOCAwbAx
dRMjprAGNEdHGfKdmCbF1USLINk5tKfRiKN+I2hBPdXIAtE9OUX2NclDfMf8
IPIpRRuE9Vqnfm0NJoWeDi4Ny95/0ybFdRke/lqJXW2nLk9rwBN0h/BeZEGl
7DqaAtMDidMDFfIXeloBn7IOQgcRKdiVUdejBh3JHOz6TKqKJJgsDGwFvliJ
qoO7TkBQgYlnfbjaTFNkWSVHR7/SoxCcJ2odA8ypYqJnk+0UGbtuQGmgZgfm
wZBWenMjWA50EaXpGvVWxh5ZymQY/sHhwsB595aDz+c48+hqFG1OJe4hrmGh
e8Riq4kg+r/+yjV9jIYBRq4A4YbQpWMxNc18kROigqpyh8R8me7yoYLSsfYM
iGIcGdS7ZpWuEuoYNTUABXibiPTQM+iBnSYes38Cc22EGKB7GbQesU1Fsv7b
B88u08EsAyvMTs2MVRpnnnc/SUsryzoG3qZykl6oU1wXLWyM0GcN7G3RmIWI
z5KhkwKp2oK1gEddwCvsgOCU68Bg7AmqHG4N+2hPrKIwGtJR4ICFHCwh6HOX
WND9luDZBgqMYPhIQ0+MgDaFJ3i/y2SxJIgy5eSjoy+suy+cT6cv3CW9Zoed
9nc62/+OztWXoy/A3ZH/AXBPGUBLb3cCfwrwP55j78uHXwnRVzn2P3hVTmXh
b4wJjrQoUWDu42zocWn/40LwOMcA0cf54HHF/7pIv+4RWXG0SKeooEIvcv6L
QvRF0CJPe9j7Irv/RY6O4AJWUvD07x/ZTuNvv0QnIs1mCvXAbnjSB3EhsoVz
HF45v/xJV/Y+SXt0yIAKlrToGYCoR0ElgzABXqQS/IUKwPeigeYvLB5RtU5h
ccxgXVIBDZwGi43qWfjXlmpgXOpuUBSsqyU1iTFOAD1VJnI5DF437BTXMg0N
MPQOeTjUrngjFuQXM09cOYjxJzKRFIuZ0ZJtmJa3sCVAXJHpGaIb5KaBTS6C
eNBgfRranudWGMv9GFJjB0fFvqXYRo0CfCyuMLIApQkAijc9v9kimDompbKn
E5i890+kj6rcCbPBqSA2tyfMWkG0vG/CfEFn3juylvwja3jP0+72x865dgBS
Ytduhv/fJUfktPx70CDyyFV4+7YGR4e3DKGF8dryZ+fPTFUBj5vMQcohEN9E
9ezaSDCCb7Yilp5SRkVNT6+kV6dXq53TK6DXe5ToRzBR9joxEABGcmLcobvx
Qo6n07C7dQ7vF2LAhUMZY0FmX4E8bL0hh3nRdDsw98fkRWAzXYWmWX+PjYUi
91cQJbxk4i11i/uTWTq7tKZzE92ieNN3CqhIqkOlBXok0G2uKppiM5srNBOn
9JyJRiWFfhumezPqlIosC+SUOANRBpsMi254qGVvgQ0NW3ZcWyobvkWPSNDg
Y9fSUlxV3+5YKK5AXcO2kHAeuggQkXzCOMMIehOTiGAy+qLV5V6DnnmoLgC2
khFVm67xtbhlYlXca6nirn//nt/bq4WeQIcYUqsCHrL/qdcvGjY4czhxnG/j
tDDZgPnKVoFvXfbwnJfAFZ45sfdS+in3+k43I9brq9gcg797EsV5Fsj36uDV
sdZ372HvCnL7yR/qh9tD3ixtxAy8/Y3o/UbvUHkfiNzXg9gnAyKWKox9ge4T
R97+lQvlpwB2nWxDMOlW8a0x74TrvUWu/dPyekpOD48vFBP3M3sjxurndqf9
zO5MW/rJ3fGymGRt7cbp0Lbu5iSm7SvlnXxRvVLWyUG8Omn/Zhhfg8cnFquc
za74zXr6xBdzkhacCXxTrF4U6DHn7Xx9BE65aEqK0xjpEkJWqywrfG6+WfL5
p+LTd0I2CvTYp+O3IrtcSnl+OisU+U2uUvpOyEaBHnPeVv1bkS0+5Us8zBWw
tTQrfidko0ARWXaU8a3I5kuFAm/OixJfrOS/FxtEgR77ouibKTstP/Plsrbi
pfLK/F6UjQA99mXftyL7/Pyc44sSTFuxnF99J2SjQI99Q+1bkd1szCK/zhay
fH4223wnZKNAvx+yU83c8NOn5zWfK82W3wnZKFCGbOl7IFsprvmnp2mZ3yzX
ue+FbAQoIlv4Ljw7fQYi5NYSzli+8r2QjQBFZPPfRRpo5szkc3lJ4qfSrPy9
NFgEKCKb+y5ssH6eVvinqabx02L5e0mDKFBG2W9TCgc2OjnXnqSUIBPRshXY
QZ9tVVFfKHEN86H98C4qISzfh5UfOf01O8dCUrOWBfm8aQy+MiEx5uYdrYJT
+JAvLsHZOzt5dY8lgKgfTMOZzfEjzL5DM4BR74dhyszr4rp/8FiH59m5BvN0
cRrsWj1n8Qk9PV6aBA+XdNHc0jP+/Uf8eMh55foFj95x4G8HZ7N4ls5ux3hD
EUMhx28cnjM6eY8VPe5EmPnPXXedewRGn0Wix71MQ9ZHPP65NFIwcbXdbuHZ
DXoBocMvXNU/bUcGELBBnd4Y+K//+X+3KEzdwOgX6nLhPk3oRAl71/37U8mk
bZMQvDOop12Ax7T77E734fHvQSP7vdHIHrvOJuiDJbwkG7xoCYwX6Xi/+vuG
jnPHrvuLyiUTeJGOnwVA0tPDSP/5791//th12CH9DQ0eMqIDD/+apWz9ay6K
QuF7o1A4dp2Jh1FAOfnp4Mn3XoR2w/U1QvA83MIA5wnrXkOvsCKqVpqdeuGh
V8q70MuL9A4NqNGwd2YpT4//yn3yz/JXmRTsYgIEMPLS0i1esfHIqzijqKyX
NDoYeDvtLFVDlC0MsC6khWz6juBwTb6KkSN49R1jqkfYlq9fXba6jeblqFu9
KLbdnqHrej0SDTrstt8z/uO/wKKSDXpvDWTFE96y/xQjdfbC3KFG2pNANLJx
aUhImiB+xFnK9Io/SsoAnKikNPiEwqNwJN47tU/jNW2MIAME8Ricxpd7MYD8
GglE3W7HATPu35x+AzMWj11P+D5mPIXFcBpwJOiL2AhRqkNdRPdv+b8BUdzu
h1TwK1lvnb7yeiHiXuxd4GxF9fif//mfGITjBWH67jt4AAOH/1f0sLMDnRw0
emxirEJ67miPnqNtD+s2x3LvNxy9ih3EWMEQurrsOskRPU2xlVmgCbF9yDHo
o7rjnUpxVw6qUljmGANGYOUzd4xigwWxPaIXOUkQxYJeKViWBEOQbLBIZuFw
OR4GNQX9z31Q4QOVyx37w2eDihu2qBoYaDrCaBTM/TDBcCcQDegMO2IO21DG
Dy/kBl0+9AloJQ1Aop+VXfLzsquIwd3toynz/8vKlAbb2EF869D1J7Gm0L87
cMsxiU8QkFg6CAnrCKiADj8vStaiSipFWeboiEaDWUvMmD0BpYmToBoWYZGj
r3xscSTBWGd6l5bZJ6+dUoplOfAOvnP9YSuiy4ZJqYMRxMzlyVrv8zmFgjaZ
d7tnyIT6CK+oY9pbQT2feZmLMxqV8OzAHHFT9MMhi0xpdJ8cNQRxUAgJegyo
Hzf2PetmsuUsXL9bjJrQZ/gWuQq6/AwywhY/o99TBEnqxTUR13xiZ7t0kjhX
jiLnt2jAK/dJnM0wwMQm308e+SCPvTQdFpUQbhyMHF678r6xHozvgFmjqZZU
1FaYmIrFHbIxOrr7K+VO4JTF9HpI0BgXz0rfE79CeYBm2KAGX1hZhoPto0J+
/30Byp108bEYCqYvcE5Qooq4MkJ3OT+w+DQ3QPR4bz+vrwpAH34sLIzUTW+C
cZ80RJNyCUgEd9V78juI+YF9Adj4Nao7uDksNRqx6uroI7C/r5bYEzY6GKSK
PGcHjVlsHRNXkdtOlHxerCNTV+4kv4eUsuFeql+ikAYI0QRlouVGaiv4FXdy
4kYKg9Q3iX1y4i0H1i+NqwVEFYq/KzlehdccZkCM2SahiHm28zJnjkY3hOv5
lov0T7Hynfj0ksaeQQDz9d+gMiik/W1P2X1OjGrFsZyceKODEYUvCrylehWM
N8DYBsxqIONyoPfBQPpTwcgCWdkDzBaiYgNUUpiGhwrZIZFSYLUL7LbJgfXL
pBF8mHc/C+KloMsa2RooHJAWLJSOoqYScYHJn6DFZ7QJm+efcVV7VRlip4sG
xoFghEnHu+Q0lEJcekoIqYr5lglbKNgIE1l7KZZwvxXCA6aaYJzycstMI1zZ
8FmK66uijUwU5lyaHY/FnhrmAs18avWbsFbdPTr9AKOCceEaqCxBTYBkg+fh
0csGrmis7ID9swoHpzTnaygJGg7ztt48x1kBqmDUOXXQwyuMgl2jrqJDBJ2/
5B1deXaIy6IMSZEb1Wuce92e6lAMfXGv7bB6Gkt3lEE705eoKNZhBzYcXLY9
3In8V0TB20CdBnOH/SEBPjTrx41Ok3PtfA5DxQkDa2+XaOWrPv3ZeCxjatOx
uNHg0YgeKXwJ8bYXWJPczMF45KshTqFkbpe2MTPFJdgJvKpMTGQKE5AC8uB9
Izdcp8WCADHS+NSn8+dBs381GI0b1VH1M0vNhjZgcK+E9cSi+iQv3bfMrlFT
XlRmuF7CjMJyOHHexSR2XQKvZZuw4O3XE/lXyvwEZpBdVAGyKXKQSY9m1wsC
ptA+9rQdJbDfEcPBv1Ac4myiizQaO8SF1HaAZUHoDQaykVSg7opZx27onnfO
ZZjMBpTZtQ82t8DULALq80Xz/APjhOPP4bVoAVKqzIQ5vfKIVVEALRRiImzz
lxhqJrFYehbDSChpdxapJDoWo5lMphj9BgLTHdsp2LgGUh+b03XI42UprjGo
tdllpVNsxBRkwGvwtUd6dn1DxKg6vP4VlQKfXBuzwBez8H/RUwBRk1myMD3t
7W+tNIvCtHn/PHziAFY2GlGazFsTvpQpFGixkGNvM0aNfEPHBUgwO5yDtihM
i8luXIMIA6uXSeiPHOxIWM0bFBWPoCEKng1oUMMI6Q2AHBNtccuZuvRS/eXg
rkgmOYhJ7ajPg8aw2Wx8pmrTciUFZXYTOlO3lMVFaklbDr1b5+5sfEWOnE+P
bqmCAtgogF3uAUz5YZ+n7I8qjIoUmgxyitHLnv3mHzW8TpXBFKJMNFgktkmz
FbFNjAw7PJ4NTMdzI2AqR1uyvTAuGppvm93ScG01eoTKrk39NeAHLwiKRlbC
EOco+q7g2XB48ReL+8zzuMJoTzCzRP6bKUtL5zP34ZP7EZeDPUeG614OR9WL
i5Qm7zW+DfjYslT/v/Sgyv3BUwjpAMLxsbfvwZHACgimCWgHfw+ql/A3ldF9
pCgiBrO2dEAwKyosZkoqILG/3UUTXZx5JgiYmpQLwLiRmQR25QWdKWBCQi/+
eLrOU3Chlcks7AtjzV/QHXIPds/utgjJzU7xXGPjqIUp/QiXjTUmQkti1Gzy
4kwHwwGYw5s5nm7Fj7w7szScGu+ciBzMMXvJsfuCO1Y0lTGauLTcYw33zi1y
K8gPevJv0CBqL5EFiIsgxSsK/7Bu3jl3oQGZML4UjI6wF+716S8hIO/850uk
p/c1ge75Pf9w+x/H/fNVTaD7k5O+d/u2x04hwD79guPmqUJQPXL6Jseh0bsj
95shNWIbse7rdd9mg55dWPX+Dde54/6D0h/40AF4/7GTDGWKpozpUJEbbsLE
Vhon4QMzII4Dw+s/uEEP3jVvvTMXsDcYHteOQRUwTbrIMEEycNfNmOmGjrg0
tQjCuH247YW63D/qqH3kjTwEnR41cw1qcXIfRo3jN5kJ65XY9EoH4LNrgMU3
pThdEpvm67BwM+NRwIPpm23/QeWJZ6u5Jh/Q6TA68U0RWfbFDjqdYS896kdI
84VdVyc7i3UvMd7/Ke2NWsTV88+h7r5ETvNRgsJgkCNcTmkyV/pOv2j6p2/B
sqLK19u6vEl8zyKP9H/nivA07nEptYKs33uhfk2ToPuLUbh/vNpFj/lh+WJL
vDT0Bkm/pknopHxHDXnC3o2ed/e6r8U9SJAduf6LewcCcfBcSWjUrnXvCMKH
zYCyrZ/F9n7+uWAE6BE9P6SL0t0GeheCoroqYhyGze+oomOXHD0tlg5PzRdu
4OhWWlUwzy49X/59L99wo+3ylXjZ/+XAN7VoT+5VjEPq573K5P0659CXFAUU
Cs067j6jSHeZgNDDYunVyC5j3kY+vBqmPcnj2l2M/b4Em+H9/cdL0i9cmwov
3yT9KhSq5943ETUUNG252sSL30n7mhXnc67A+jalObqk/QMQ30D3OumBHW5u
eYCA225Ppn3hQhrY667jmpZpX4vB/kbEnA27Y/JbwnDS540WF5A1sj8PWtRN
4p0hMNINPdJ94WhieW+LHPMPxlGE70D4JrCb7IPKmrBoufAX304yP1zV+095
UIj0YTMHU67tpRwe01nsipT7ZpdX/oIZj3uw1I9+5Ro0AQyWXo34XhrML4My
cqRo6PUgzBvIwgyqQb4MdqwJVKt6W8lb5mZBSdKkp5GUgCR8kQheoWdN0RWK
UuARIp5HiHqWDNdlAxAyJe5Kgp0I7p4Zb0ZRQAz8j4U8jEsKfRyuFuges3zC
0qrBtio+KzVMgZUuzibPm8z9Q/nuwezkepv86qqsZ3nnfPaQRg8zy3xNey2y
MDiXWugvc3SJ4hna85NJyusRO4PfNI1aJpstCUXY1ufTkXx5wc3AlGmxrGs2
IcyTjkco0hawCFMhW+JaZBLCxw9CCK7Fv/aacZ9OTvzr7X/jOt12B0tMsYQk
xycn/w0hu2U8wrBvm/t8aEFPcXALHtziK7g0V1QIDEad7b2/9ZXwPwV8FJ2e
mMTcmBlGtIiVtsUZC0HAqyQ0skOgU+AneqWuDtpoH3HegXGFpp37WnxnxmFc
CymBnxlCKluEzl4hPTO+EmEh8wrj+itL6OtiRfDSuUo9J59i6tG8K7ZnF3Z6
6ahqukCDX4XS7ghug972DIaezn7liLz8L8ib2ZhuE3n8qJcQZ5RdgsVEFLhi
d6C/Co56JRT2XF6MYYC8t8ZesezbYif7ev3WB91Rt169cOFXYGW5DOYVb0nU
Q+4be0hOrewrcr3qkN2h9OiWf92rvyRf9fb6ouQ7piaUTzxZJ/Ru5I/sgF2H
/LE9aD+4B3bp8dt78GXC6zvfsEt0tQnaYu9IEoXh8d/S28z4fj3FUo7d33wH
8Yrf0gm76RntpddsdG96bj/FVC62nx0rx7sGGvT6XhFTfi/47HcE/6Yt5d0n
/QndvEM8vtHNnjn/qXdShcortOLx+knXT/fgFYvWT7pomhStn3SlNClaP+ny
aGJq/ZxroknR+kkXQpOi9ZOufiZF6ydd8kyM1g+5zvntaP2ci5tJ0fpJVzST
ovWTLmMeQCv59oldv8zutymTg8vHgXt7+5h/44DJ3/wWvrKDwusOeleN5qA6
ar4yTQ91EjUe/bucfp//7//9XovLzZme3LBjF0G/saPgeNw/nI5eDAgfEYcP
p8WdU2k8Kkf/seIlRHQTc+rsBghLxUmT8Yr6Ngja2XLruWhbBuLvJjMOB5NG
QlxphPXnOyIuOqI1/3zK/m50PtM4sM81UW6yo6LPqZMTdMxtOcwkHXESUL+i
YWHIZoqkTl2YQ3qBhEKlg3MfAGg2VlWF3Zkhey5My8ugKHIzLPNAw3ObN26u
/aMmJswnos7d6LBZ+4vFfaIvAjmwN7n+3NDIUpyRYxrCHU3uFGbl16exdAze
0SC7F+PPDcupGplS5otAvyPG2nr5aVmU/m5tiYO1JLgLxUZnCfBFkH1uBTLA
vfML3BCT3zZpWlvqKY06Tdga9BOoffJ6ezfMA3lhP60VE1bCkkY1hRwIoafp
KawTy3+Ed/+YNwox+vCJxspEww0xKktlx5TuVUN4mnZQ+vsCn5cIxm6lww6M
NG3oByTy4XcstlHI8Nkyn8kIblwisuunaq/xPcIdc5l8xgcbdIyko1dOL/EO
B6XZqNncoZdNSJhW9GbgDqV2gTQaAyNkiMkyrgx6zozLg/78V9K6yGfKvCD8
OFqX30nrxr1srEPH+rKaEiWNurVkQ0n7NbyKhXIxn0/lipVMNpeh1zJ/Irny
yJqZMGviPfIC52YLxpEMbVElTkgKbCSR9+5guLaSYuA9VPzM+++YFbPKFj1m
CAJ9C/lCphIdXlyhFbcBy2tB0+u5CY4RuRpmkWxVh6O30KPpJqdYZNj/a2yI
CxW4Yx+ORaFSyibBERsc76ZgphiK8qDaC0BNRNkUNVwr7l/Y95fvyKGCG/y8
m0H6R5NLSEougaJY2UGxJU5A+i+I/BaKU+/D4K94phMy78AQHoYa7MVwX2Bt
FHJ8LaZMOStUhHJ2vAMI4YyjDsYx5hEPyjHBS6y75NXiG48uhsdcbHJQloec
JSc5kHA4NotfkD49GYzs18F4X37NEMDAMN61lNj1mz15jCORH5JvKam+peTF
pEkBRD/ODe9qB4YcqwFycoJ4gS1L7xrt8RnIbv1f71qwwiL6Ndobzb7PuiJ+
9VsTo238qyF78aVhVOwiPV6A9muKhLKSrwlecMYMwTqraR6pYELNYSzTQ43+
oyP36s6ri31o56oBakEU3dKwPXszadaaDwG+LOc2KyfiZ6dmW5njj2/VF9hX
OeDocNWAD0F9A3rVZUVUA693snwF+2oJHGGGvVD6fy/Hfzn8KB5spE5AwX0U
qRHwocDFQtgpEVCK8H1zs2QxRoknIYbynLsG3Io1oURAeA9F0Sg7A/3ZNuKU
svNUwasnouVe1nILVoy8nPvQDPZn4T4pA4Y8+t1oaOjRUdUK30iJvbNI8X+j
2gutTSK61X8CNt4l16uMDyYJ3TymGc6DBB3fNyfHx32inI3s9X7yrcgTxDNZ
uhfifo0HXt4NRIrT18Y+HB11p9zWcFgtAnYvbEpPFph0jr1au3M/aUmDdjjM
Au9YHO6cOctgInXN7u9JcyItvBTmr9IpvMqmoLDLN/DYvcdedf2+6R7LjAEc
94olR4lYhxZ8DwXmiJEKWycnnqcZLxqHKhydnKBT+eRkP2UYB/5bp7D5+FPi
kpCaYRpSsnjHiv/j317lFYov3hwwepLIv9PvuWL/CsPRlBkVdqy0XkxwASur
B2MEZYcj94+53XAIIEA4ti2bysSfcLNmARWSh9OcRjmaZcpxkfKGFT8oOg7F
ZE1mxu4YcqDWvfi8t6L89gzkXSE732EQUa3W925EDsPJ7qyj6n5t5F+gjOTG
Y0eZsfLyBK8bnuxoK8T0/QxKJcsbCZkq8BlnbbUJVsnYl9vor++JyWMVJWlU
HhJ5ahP/+PkVCodyXITQwPF8oCqUx/ujS6Lz9Cjz2LWXRS8rx55UTB8MU5mh
6YK6Ao1nNKH4TJ4dKdN76ha7VQ205DPF4yOsWotVxlhBnrs2zTWhSMoSKyMu
DTxxkTkD74i6OgsT8jBNNQG9l0RieGlYRGrDs9nclVEUcJA0JvQlTcwSOVTm
2bX5V62oIyBHb68SE4kiTVMAgB4XG6YJS0dEEXDMmtHDahZ/6V9PxqmyptsU
pQ6tahQljOXda2YV7rxiOnuzHGHOAixhqtiOf9PexLrR7l18TGnhJvDxqjjN
vSqJuHVhfoj4ckfRUnWU8xjuVXpjkQEyYfroPXW/6IiXiIUN+uREVtj9beBi
L4MEyx4DNs6BrCoe7Vh3Jyc3B4qUYieKbRF1Gq5AhdfYian7q2Sn6u1bq5P2
iYqPWvDhKVeipRPphwdqqcQiBtLPywJFryxbmDKn0dnJ8PLh82yz/XzMrmXA
BjP6dkLsNVpIUpCNiaXMwhw7HV/8ednD8IrHh89z25I8iHQnHtwBwYq3fisN
BzQj1lEuxVWDXGQ70MRYaKEcZlhTWTw66rOljolu3Jwu8dewEaZbaZjug/zq
vn02IbS6bx2vpamsmzYuwePAi+MvS+5PzCDmeePoHS03dZWIl1pGQ9dORHci
u+2OzMxShRw+D0nRVEdhBGA0froM9F7hpA7ZtA3dSW0LxzhDMa1C6UmDeRy5
lD9Hyrezxzgz74MRnr8olNzxvjnJJZqTHoreAasSjKqxGk7Ita9om1vtN3qb
cE/drNi0dq8U+E7WI343ueqcqEvLz7LH7k4JHn74Pd4r8nOHBYls97XLhtt1
WQalmJR+btq+t/LS0VR9QQqVINdSKJsEdR72PWkU+8+XIL8c96twmj3Nnxaj
D3OnhVM8tem/HjUeqHzk+fgeIp25X3t/+P8FQG2B+xjHqlTKQYv/+r/+NxfY
f/2f/0v0D4SSfQPKQprvQGF/RaHk3oTymTsAxf0jcsMXI6sZ79P7dTtrqZQS
KL+7OScK711YVHr6CbxoQVj3/MpfaPHJl0Mpl4O2Xinv/c7iuLzMPywnc/r4
h0JXjVnK3tjvz/z8w7I+hwf6A6BHBro/t/QPyysdHtoPgB4ZWmz26h+WuTo8
wh8APTLCt/Jj/7Dc2OFB/gDokUG+mYH7R+VcDg/yB0CPDPJdmZ1/WNLm8Eh/
APTISMupsBUB3XpFhr9fvx5ENqwfCD80sD3uo5Cu/5Wee/tHTzC5LaaILVbS
98BLqubxCrl3MAIm5B0t4U5txZizTGofnvppwT7R/TEfPQDaLMWQ1wI3XZgW
ZEHM4G66bEjpQ03Tx6csyd+O5Royd0fhgvaWM5vRqrp02w+bfNyIzrcTU/Hy
8OLW64MUXQSxRrCXpHPv6+P3ZnZ1HV37tv4sM6eMp+L7d+5vJzQN2+i0Huw2
2OFPiE6mStRZ/a+e1BRymFsAO+phOjkJqna7uwo8U8fZfDWNYcagX7w1LC/h
t9sIuWfXWTnZ0vOU0Bml609nCTa9pOyn0bR5O6e+34EnTELzUkW3lNEDSEpE
FvSL55w0maXMCPEeBPhMPoLDm+i650/s5M6bJPhhmETz4xSiJ7f0SC/1TvFz
UT1vMvEzVDTMYYFDgpFjKn0JuqNf7ic590mFCedN8d1ciY94t1H6+L0o4haE
Yvj2cTsXigw+dKKPfnZRX9CzVcZR3kV3Oq3BFfi3z+aRlwfAyPaOe4HFUp9Q
4CGPp4Xpb7ecjJmzTcOxTl3HFKCJ7O9HOJ+6gS+h8JS5MpvThDwYKSCHoqe/
JmiH+8ByTO9EOP/55zFLX2gSmisKE7SenHSAK+0Jxh2BSFiDcDo5wSgN9AOd
nKRYKYe2snKzQyOerOb8m3XST9EXDcqCJlWXj9zTchKK6GCXh2FF4sE7/n5D
IPduhqMjx5yxYBl0EceLXbeowFtMSJMWZem/mU/bexmUiHJDStLsggALdaJB
NR/cnF5eREaopDm6CDB7lxvqFDMuFLn4njoBWAI2XIOgZH2JYCrWwsW2y4kz
N1c4wWMJmjzYWaI4tsKH0OHM9NWd3rzCHF5xB4zmcmi5Bwqbbrr8qAwvsy1m
RaUazG/lZtx1D8XIs0OlPXXPzbB2hu7F77tZMwHZLXXsAcvB2ox8w+Qtu0KA
SwOH51/MCLBijI+t3Rru2BKtCWJqCk0jbHliXlRZ9I2f5h69UbrMkikTN6Hn
qd+PHyjB0KHRQ5ijWgoSvE7ovJkKUILIzLz3WmtEROcISB0GHTMbsewfNC2T
f2Lopl/zWCziBYGPqbtFcjWvl9Ab4UxofmOWsY1WfPdWpHf26vkJwowVTK97
GutTwEu57KWtTXFD3yUVda3vJlWeoK+B5cISmQijSWBZgmp3RqloAVnEpk+k
nBlkBw7QoiOB1x5P+9RioVFk6qVSdhOfs6TyPl+y+z/MEB8Zhopn/5i59lXp
F9/w8BeHb4HQqjCfPAsk0HQKIbSCion5ngjxFB1N05+ulEHXFHLHXrGYHb0Z
1GpgJdSi5UG8wJmQew6QZn7HT1Nlg0KfZVFnBT+8H169gvjz5XfFkbDOaa41
XpFBYGEC/dA2CbMwimnA5Zh58Ax6aA7ThjmraeI6VjQBKW3aLP4RcEKpOAUa
0eUbLbLwxqG4twwQdorSx3StHeK7G9chxw4W2EFmBMIhw2JRj7mbdZkVkfCd
oxQsZR9ctaEEX6iXHN11sQaJ3v/9ZsAlNTrx8SpbdGEFMsGtUvAaWzqDkUIJ
p748CBU5ordTXltTx1ggh7nKGE+7XOAvIMlXASjU8OslFa0s+f5OFu3I9OBE
AwDNK5sjzQ1FIm4lItxbqWCahKSdL8f3jBEn7ZRZJ749EuXANcWTRV66CiJ+
HmHVXoLl99E3nL3McP92HLJ/jVL7i8kXHezZ/vCcBYIEFmvqqPWKNz4eHf1P
VFv704LmuZDKnUYWoA8jdFGuoYCEJ3yHqKoGrIl8xbmXK6eYyg/VHlFRucNz
VVWWmGob5PEKbUU/OyrTK25lBzfxO17HIzQvPyKBG1tHj2xw2QExBpuvMFEf
7g12RLK5m5aL+V6CgpeUu/YQCaX3HUtRb7tMBCpQV5hdz+i7pxnbebyWYr5P
1HVMLQMXNxYSU5gh6QtDTjbo2vJOMBTVzxYJ+PgsGq0r5c8SqxrKcuNbrh88
KOxAqaDjJgkI7oUXRF/jJsUr4wNouayQwttskioqGosI1kTZsyBZLCvdocwc
089XDuov8OUfhdz6sWHMJnHPazCY2Kt+s9M0VP6FOePKr+rCcBqzxSzK22Aj
EG05Fy3lJRyIFFrDNGg2UiGI1nAAa3PGHLVUeDpMnmHBJJwoK4KujviycQfm
SvQ26IBGHx0Fr6NxP25NDywD5bM0O4PYS6wUOqjxY1q3zY3TCN20wbbN4dWg
Wx/Se9QUt193L88e+e7M+Kz5oeq1wS7Bc2rSheRnKmY0xIASifiVbHfr6DFk
en4RPg+Pt7L3x+IRWGGu29sH74U4u+vlqBqpyPYOenuBU8xMrS5FCQzNLGwH
L0As6BZhEROwCxS5OopBMG79YBWdrIO7xriB306A8QK7FP3z2BDwnjIjXXQT
emFOzxnxzjE8vX0glBuNTwxojpo6VFOwUwtTQwq9uqLjOqL33UvCgsYHLixh
RMiHNmzBRP2Y+1SPDIkO+EP0VtVxoAIj46fUSckk7V49cz/naQZrIvNu1R5Q
Z0RfKaah0xunfIYv89n0cTIkssmQyPI0NJoXlXB3dczGb5FjvM3tdiUIIech
vbyow8ZYh8dUz7sBtVa6lM9WdmCcn4MRt7X8bUoo/+wytSbKRtFTz8/sWkU6
J7TVzbNZNKadrTramval5YjXu1iJUwKcCLbx0LM99oAaNO3msK/P7ok2NI3M
/Kn7uN2sd0A1FLBWgGHvDBN0YChlbiyW5WJeXnfvW4XuQyb/XFJmeae2nu1i
CdKUKHghA/0uYHR8JchPLTCPdFDJQfup+4RePZQV9GOkC0KZfa2K1hykfyj4
XsKqPnTPmZp6b2lTO02XSmil0DMznkXasks86WKmkKdDOxOXoju2AZrO/wN3
hyVqqGgcGhIzh2k8NZgBRpRdTGjAr+FzGG7qaUm5EI8FdtcEu81sy5vfmrnf
ysJv1eZvzfJv5fxv5eJvzcJvtfpvNeG3ZvG3cua3asn7pkb/yP5WLnt/VN0/
at6raoP+kfutWvD+qLp/IGT2TQ67qLZ+q0GnJWxS8V5VsohGtf5bpeZ2WvH7
qtFFQ6vY0O3GQaEgLpcprFSD11IVOvL0zreH4WQTwMkinHp3UMe6O5+iOSck
xZTUlOrEoLm/AX28B99k/WS/ph86njY8wm7kSWqGAydxQwg+YuCiTPYucNn3
ggPsvEtQ7CgeZJyNR1Y6NV4lrMvl2r6s7B0a26qyoJb2xNs74kmUH04OBoCM
d6BErj9Aff3paz3FfPTm8lc1P8ZtBlbtxGzhwXbVcib0btEvzCKQXIuAxqTt
U6epX9iZ9R7DA1XwfmuIXoTCbcCAzBQMcI0KFXp+x14wKerdmcfJSWdK6Uw+
HfYr8L5fwWLKl/ePk3nF4iemsSA6PV+DHSiviaA0DXREKihes0UQhMVdQVhT
wRDsiPYlaNeRsdiGxN4EX4EpThWvje8CNSkIlYpQoMA8k0kV9ZmDYcsAtUOd
UboRVkNz/xnTuOFbU2vR4rHkHpqEvG3wE0JHoWKFdjZQ2MfoMMNbXrFhqDr6
WulOHDYhc0OG1nNjzcP/qAjCoFt058tS5CKh+8BKYXA0YRcKZ97ThAilFVko
VsoFoVTM535X/iZkMplSqVjM5rJlSuRP4fT1vhmCZA6pUeJVAzRZ6vowCtFr
Ef6SpSdATGIDY12Sjd0mOu5XWImJEIfhnhFe4xEuwfpE9DUd9dJRLTCkPF8R
6NQ1Hxw6gQ7j93NdxBXnH6RSXBrA71tvmAOqeMMOSnjpMbd7tRbxCLJGRIfH
RwhBt30MybkCdiVN9ART6Jt+jBrDOjOCokvMktb4kHY3MRUyPbigTOpS3DtE
upRQOPJT5EK6k2Rkoz1nBO4abEnb0cKLx5hZKZrVCY9EcHpTziINFoL7Kd/V
JZyikLTCfS+PHiZ+QciSx7G6ZfRgzNsDc2IxyriVgSmXoj+Yt+hkKjPdpi1p
lVR6hEUX7cCBTQy1yH3WvBAnO6Rz38C2K2U6aRQD6UIpX8gXUsv5MmrX0+GC
UIlC8J5SWy2WpRRiOvCDTbXqEBAVr0x5RQ/5vPEuty6RlAX/TUl6Glk8zbLr
lHgQm2y/CaysTC1pY1cqBeAsISWzzCM4a0il/ER5ifrR8Ym7I6C6z0o7ugh6
RFVFHuZiiTIApKvsSIrIy0Q9MCs7RO6OgMw7+XJsoK9PV8WyVCIbeAdbVXgd
bFz4z4Iu0DmxFs7W4Z2t+LJSNPSrriILZIdOlvYia2GhZ9kp+owt/bRYzhpq
pZLZpS9eLQsLJ0SSPaMNKZqMqul8GgSdkMlmfWqG4ChTEt4qKCn6gF3LTZed
m+k20+9pz002Cc5sJuqgw3f69R4znGEIh9gHxYGhEn6p2GCgK55exGVALxdR
DYi/JNVwgFxrg9/CnsFCR5SrQvBgeqpE0TlcH2CJ38AXaf9bGmAROgPeK8tY
CBX2YS0NxQ5nK7KWKn3CFNKG/sJEL5VsoSJUMwXg6FqdL2SEAl+r5hp8Tcjl
S7VcoVEs033NJ1Vcbbjo5NFpw+epueOxcnpHqrI4MoxTAi0HcpTHbBw8Xs47
rAHYCIy5syMq4AlbNWkhky+Ui4VKLj8WstlMJp8RmNHRx5M8uhrYTh6szO0O
wvRZSjEZsx1SAlHNDyK1Mi1mswKfLUoiX8pWcnyFkApfKBRKk5yUmZSn5Z3l
eKH0+txt/zLoXlW05WrJLBNvTUYNAk/puGVbGCo4za4wAQ2XkslqR+nhI8q/
VnrRLfaNy5f+hjYApQDEDVGR/k5RJ4mopECYURy8WQLa8ejJiWpGxMFiaoNm
Ujmot11jEY/Fae+4e4DdwN4dgoX3GFGxpH9/doi5/VuUn2l7tE1gr5NwL0Tb
/+rDp5AkwMlUwQgOm4qhh3RGsvlMufTKuA9raoy64NH5GCQSw4ufOlrIog7m
G3xr+u+Ykag/gWj3TbPd0yF8SfNMYc2eV1Tn/Rrpx+Gr7SGx6z6hdh2F4YYE
RNAGyxJlE0J1ff/MlqmLTvQMR2IPgBoMGCCz8ihAJ3hOPAiBhpu+69ylWNoR
4JIl61FDJoWPaBt26jPOZ3OlolDJpjFt0Mwwt2Mhl6kUwf4NejdANdt0skNk
CT30csXt41fG2EwyucxLY20opiPHXCjWHDD1qtaCDaKENEjkMe1mLk4w7Rym
C1FAeERX0QEcFAmk4Iu4Vab8QlSVrWGyuREXk7CVTX+y3VvI4lL0kNIBrQQ8
SMvx+jMMO9e5IXGvVS574Z92rsEyILoF5t0UdCAFBzYz7riIDpKCAGFgGCgB
qNef/gaFOzMBjkhreLPD2BmBfUC6WClWhHypwBZAt4fnerAVCueI0dxnTNm5
wo7osOwkPyuMATyhwEaPeQh8C3IQCKvQSTrGXVHXnx81FXwWBN9GcgycspOI
wH/ouQRtg/nXMMENWEYievnERZSAqMCgS903Hay0xr5diovxISMaY/Fe7anR
Y75CWVLKlyp5oVDIlcq5IrB+ppjnn/lqns3lwJBNZWZwNROIZLyJjWlO6Idj
MK6YzPJCb5gop6cCyDS6wSN5QDPTy8cUi0I5C2o1VywWAZ1Clr/PVAsMixrG
1PRN2PPtpmbcg8MEPgZVRj/m8/mCkBeyY4MxLSZSsqmBdMjmCrDJV0pCOVvJ
w943n8/w66mS8/amhmnhMdIQiDolMQiBxWTRb9Isht2nehqM7rTLY2yjsf2L
xdWG3aOj4GeLyJTNrjCOiaVG2Lvx/lBDt5AlajY3/ec/TG6IhrU5JxjzqePN
+HAzi/mtFiyF7g73cXXRhE0H11FUGwvLA1G21OtlcWDaLYiFQZTMtwe4nkIr
Vf53OwT6yCJI6/VosLibIsFN8OZXP2QhjrLraQiJOTeUE/8VqZ6OLmzqckb3
NkxLaJ17kYJescQjVgySVgMktpQ6Zd4+jDqkGej8REeTLVevux0C3jRalvrU
9ucVZtE0kVgCxfL8/MQtvhrc2sRMbXXqIGRnFyx8DUGzmFz/8UG/J3IKTZq0
JL7rAaMmaIrrBO5fGn2d7g5GLV+ERpJUuA5U/ys3LD7Eo256PnrddLLdyQDt
pbXws1a4HzL/OiLtvUEjLMUSZXhO2zAetNv9sF3/ZwgHN7rYBa2YHJbPDQfb
MQRElhDCFT1ItD3xIftc1RE0vfQJLAqCRRkgAwEGa+7DyQnZSKqDptjJSfR7
DD5xg9JjPNzHLL2Vf4YXW4MSbxika6WW0Hgam09WuZs5n+W29WVuIC4z96SZ
Dh0Gfhug44RIic3binzTMuzq9UtHlxfZ3HNNWtdGOdFKhlQcoKRI5TqrTFOw
pvfWaluz1WJ19lB+4oedjrJOhlQcoKRIFS7OikrFWhmaPl9u+527PnnqlaY9
7f46GVJxgJIidTt+eG7fPOSmzbXYWq+302qlYc2XHWJnkiEVBygpUmetsbTW
Op3mxDwb3xVui9smse/udEXJJ0MqDlBSpPrj+sNoK80y5+2SNDkXnVaVX9zO
7rNPRjKk4gAlRerx7Onsfvmwfizo9VvtZXyXb50X75VW8yEhpeIAJUUqbxm5
i03n6uq+MxTW+mruGOTubkbqnUUypOIAJUXqunimSYXyKiMJauM25zx1HzLV
+7ExbVeTIRUHKClSer5HCtf9+mo930jNM12+I/0t7EklIyFPxQFKitSEDF4u
L1frnjJdDKZn/emGSG2jsxw1Ekr0OEAJkJKm8Oum8NCRK4L68KQ810d2pfa4
vW1ctsjNsvdupN4ElFj3tepGvtYbNIY3W311Walen4l2/0m/F2cJdV8MoKRI
rSfjB6vSe5QrTsXoZWsLvmyvStPVfTshUnGAkiJlrMpTviQ9np8XBo98T3uS
it357bDGtxKKhDhASZHKOjeO2BAa29nTZaOXb4/GvPkwWY+Us4RIxQFKitSy
lquIk0vh2uzkx9VRb9wslVeb/sjZJEQqDlBi3bc5r296HcIPq8qg4syvrlTV
PM9rN9WEaiYOUFKkRsLGWd7U1s8PzdqwUx/dz4ad+0dbfn4pJ0MqDlBSpOaD
db7YWs+0W1mpTJ8ftez06Xyi6uNuQjUTBygpUjft0rY5XqjaYLi53GY798Xp
i9My9MbT+4Xnm4ASr775knRVmbSmzaJReS5eVG4XdiZTrZ8npFQcoKRIzaSs
8pRZTQwyH475lZDhh5eWuhEf6wnN4ThAiYXnVV6rTp8LnbPHpd1oXJpDXS69
NOR7ISGjxwFKitS9cyaNt82zfr3XdR6kVfaqV7pvGLNB/SYZUnGAEttTtx1V
n7S6zTkv9a9Jz2ncXj1vCg+ru4RbrDhASZHa3N7k6qXnmyt9JinLUi3/eFXo
nd2MKvcJFXIcoKRICbO61F/zpUtj2Ri8vNReqjm51Z0ZuUFCIy8OUFKk7LJo
TF5quVJevVMuXsxb82rwUFq0H7YJpy8OUFKktNzNtla8v7h+2YiORJ6aY6Pc
1/OCM+wmQyoOUGI59dx5liaT85U4NtpN/qnZeHSy+dxsyidUyHGAEm+xGuXr
mnB3e8HbxqWxal9nR4tiQ9NIM6GaiQOUFKnV/WV2qUwfC+17qS5sLtbD6UVd
v5FaNwkPzeIAJUWq127dK/qkXLgfiheL56dac67VHuulvpSQp+IAJUXqyarc
dvP9Wnn7oM1n2auJ+FgTxGx2epGQp+IAJUUqM3i5Grzcj29l9aFwcz3u3fW0
zaOqm08J5VQcoKRI3eV6HaEGm7WJJtzd9Dfta2UudiXhZZTQRo8DlNieGovt
raq1OsaF9nxZqtWkh1ujw5uXiXczMYCSIlUaPgydWjl3rpmV5/pEuBValbxe
ucvlEloJcYAS89TwbjrLPlw2q1f22XXp0ZoKGzV/xVevEp66xAFKrJC16eWa
n6zL55Z8NlHzlnhRqbRe8gqREirkGECJT4e3yrRdfukXxLVhTsZD4XJQaTVv
mvd3SU+HYwAlRar+sF71SoWXojnqytlq7vFx9XimdTZXSkJ7Kg5QAqScqQY/
s5VN6/G+UM8bw/Zi+Vhd3Y/GpYeLu+zt++fvbUhJaeUInc3DXUU6m94ulVx9
WnnOFMl8vXxoJ9R+cYCSIjVsj6uZjFAU+fOefl9dtO3ezcZYPGpPCVk9DlBi
l9G6xF/dZevVWzPDX9deKiVS7W1qY72XUCXHAUq8cde3E0mcrq6zDb47v5mO
brPZ8t1163KecI8cBygpUqZ2e0lakydxky2qOUEvLBW7091cXS8SKpo4QEmR
aszmZ3I7t7Um/dZ575qUpZcX3pa6veeEkioOUGJKPV6IkiJn13rTFs/Ww4nS
7U7t3CjTSshTcYCSIjVeNGtXjUtrdPc0E+VJYaOrT+WivJpLCS2qOEBJkXru
5+7rmZ5otlrV3LA3qS3v7s7sTbV+mZDR4wAlRWqxeLqeK/nt6mysVNcPZn8t
SGZrzmt8Qp6KA5R4P1NbyOf2+cvIzrcqwu3SnJ53dXmmjbIJjZc4QEmR6jjO
uNpyBKE2MuXNea5bnmvr7NPTspxw4x4HKPmxma4Ym0VtPL5+7K7mLb2gi3fF
p+79S0I7IQ5QUqSUO6ter6rlh0d+eTWqlizl8qZtTVWlk5BScYCSIsV32v2b
QaG+cm7vpKvqLFeShpu1UR1pCRk9DlBSpC70i4dmadK+vtLqm9v756JlK1f2
+VoSEsqpOECJeWo86Z7Nr+Ra/kmYZXTpZdN/XLfu7bqR9Cg2BlBin8M2/3x7
fXbdHpSz/MRaXI9v2t2iQlThIaHPIQZQYnvqLGeNH1r6tNK9LpdGq6wkPOen
ueLmPCGjxwFKHFhyd957eBAe2kIzqwzHne113mxoV1ajnTAuKA5QYivhXNAb
Q7KuTm4vxmtytayUF/rDozQrJmT0OECJjzienJfMtPtUtp8eDOlGUx4f76Xh
et3qJKRUHKDEG4cH5TZ//nhpZjMmKV4v2tr2bphb9m2S0EqIA5Q4BOdhttEE
ZWIXl3n5orRpCQ+Xspq5Hy4T7mbiACVFqnhxPrtaZrMPg0179DDhFb62UXrt
l95dwrO8OECJRYLRkc779v3FtHbzUH80LgVdvyoSocUnZPQ4QIljOIbbSaei
zPXLp8vS8Emezx/G9/Zm3rMTTl8coKRIyeN22Sxd9NpP1Xyh1iebx7U11bSq
fZZQoscBSnyWwL+I5eL44SxjLde1+9p6dHv9slau6mbCs7w4QIkjE/Ldnryq
b8rqsHlu1pWz7tNkWasPzHxCIy8OUGJ7qnpV2bbOjKl6K6wb67U0zxdk7Xmh
bRPa6HGAEtvomYvnzrQmWteaWqw88JVHdaw/Ta1mOeHqiwOUWCTMr9rqw1Ya
b3VbW40yoCQ2qqyuxU1Cl1EcoMRWwmR9UZFktThV+plVrT2rDm9uGprY3yY0
8uIAJY52scm6M+m1z2vXV+eNrPVszkamvqxfLRKeJcQBSnw+ZXWfikZpPc3P
78dO/aIgjOqjFb9ubRKKhDhAiSV6USo3iv1aY0Aym3yj+nzfy9n5Zl/KJ5Xo
MYASh3WZtUKudDa3s4vmxW19aI4GCxskTClpoG4coKRIDfr6+cP0pt4Y9wbr
3FyvZjIvs2I5v20nXH1xgBLHcPQ644x1cXFT6JGF0dRf7s7P9O6ZJg4THi/G
AUqKVPusXs0J2qxK5uqs1R84422nKmTU837C1RcHKClSlSmfFc5650VL6MuS
MSlqfSNTNC/XWsItVhygpEiVn5/H7dYoVxG6zUn78fH6xn7oXV3eV24SniXE
AUocgvPiZG/UuvrQW7TLs8vhVV3dtM9ma/0q4fTFAUKkmiztwsdk0QDTzd1y
YKuj535TvS+v7vOrsqNcFgujhFI0DlBiw2pxk3m6G2861ZZQNh81+/EsW80u
x+tOQnMhDlDiEIVHTX44v1anc2JO5sa629QeB+tspyUkFO1xgBJbe5mn4s3S
aozrZPLc7/cuF42z+tN2+NxMyFxxgBIgZYq2lbashvk4aN3lrWJ9KD6QaqWr
dTL9/rXw/mX4JqCkSF31a93xncwPjNHLizwvNDJnj8adetnuvt+wehNQUqT0
qSmbwqjSl5fFxnjxlG3aufvHBT+/ev9e601ASZGa9Xoruy9076371nSSuS/o
vflgJF5cGO9Xgm8CSorUVmy389btNL+sT88ynct+f7DK3c8yUjvh9MUBSopU
Q6wKT43ryxY/ka8KG15e3E6GL2pHarzfsHoTUFKklvai83jTeBkaD3qjOCi8
qHqxIzUFaZUQqThAiQ0rgddqF3eClh+dK23r+vlqftVdTC43twklehygxNGV
tY5UKz8MBpnOrbRV5vMnTRDunwfzu4QBCnGAkiL18pBbyf3x6PH8sSufjxdL
yVzfXTsP06Rb5ThAiaMrpfu2o0+NkXB1boL4aw2s2fLSul/pCXcQcYCSItUa
zjP2SCzNhUtJJLePzcvnl+J6li/UE26V4wAlvmjrGJawMQrq4kKxzvnKoH12
d3EmVnUt4Q4iDlDi8Lzb7SQ3l54Hxlkrb18szq42VrbukEsn4YF6HKDEOwit
cfnMt1Y5vlLKFp/J2CYZffpw3hMTbgDjACVF6nxtt4fSRfdhdVO/y1YznU11
WLAq971ewtOzOECJXQ/Li1pTKYz1nlkQZkN9VjCeh4IzUpOedMQBSnxTM6uK
ZxNn27q+NovXgn5TnyzPxXH/MukNqDhAiWMG+dx1tTyW74VqQZPPN8btlhde
xuWBmtBJEwcocdTEU9fIndV7T52ZOrgUh8PO5dXz0/mssUko0eMAJT4TagpP
ObHPP6/Em9mIvy6Xz8jGrndVKeFuJg5Q4lN+46m5LA+zQsueZg3ron52aQzK
m/5L0mtZcYAS79/7xf6mcTavdioTnUxvntRzKTOtFMVFQkaPA5Q4PMgcmfc9
5bLb3z683DZW6r16VsvcrBIfVMUBSqz75E5tlWtsb7b51tKclwSlktkUl51+
PaHnKA5QUnO40zTvL67u+qOGdnVeHPRur8pnGbXZrm/fLzzfBJQUqetny24I
E+vcfDSn1+Pb6xv+sXI+f9ATuB7eBJR4hzzPqzXrvrC29ef+WU+Q+lcLW9D6
V9X3H+m9CSgpUnKv+sg71cljV73ZKI3J1TjzWLud558rCc8S4gAlRao1kF9u
r84KVzUr3xO2Tmsx1u3Ngyps33/q8iagpEg9m/l1qaXo9UVbeLazJbFefzo7
N51+4f27mTcBJQ5N16bjuj2xh41O/yXn9DqDe6KS7Gr9YL5fer4Nyc2w1sPa
a9cO5pM0dOvoqEvL2Jn2KTcFyLQgLPfsvWbZn2i6K1NULJae664dzRAFDWgK
ddPGdEpYCQ1LMtHsSXdY4Wl//Wu39PUHlu2T+4/YiuRuxVQrWU1st9XvR1h+
GZN7YSVCRXdoBb1w/UPLy4JGy39h6mVayRKLd2Hl6/qwypNav/Xnn/Cj1x0N
mnzdhxQuG4fF/bASooJ1fLFwuVu8a7fu+ckJHfXJyYFRPDlA/qlC5N+5Gx8P
WtEAUwnaiva6gu0kqEmEebgMWjM99I2JefU5RaPljWyCyRanNjEx9ZlOWJHT
JnxL6+3SJG0j6OUjh6WMP/kVi6MJ7SJMCLyTVmS3ErVbqwHUFM+md2XxdNIy
eZo3FEsx0byoRT57nPL4xM3b5hV3x9J+dBjAP8pMp7WVLUY/c09VaK8s9G5d
6A806STAxkLfurT1qOUmYCby8e+0crvs1hk/OWF5olnqNtZf0D+t8oVJ6+gk
YKk3R6NZ6FiRxl3YWOAUK6P9UCLmU9lUnpKxA7znl3fFsn100t1UcXQRAs5A
Gp2wAhkGrRy7MtQVZRdWqx6TPmKJWskk9snJ7xT7v/8dCx4OqqwoN3aDWXc5
kaO0olWFI9WFuRlhxa8wuS+QCmus97vdBkv/Vu90+2P48bub89FRZMzxzo3A
KEap0fSGgCWnkZ4x40hxLZCL+ABeywYHU+Plo1P0o2gludf1NU/hWfPmtsEe
CsV8ucweYqlpWORYd6DaZaOmJWoVWDIUK5aNjxbtxZ5D4/Sy0ropELGJl83P
rQRNzFisuV2sKTJNeQay3LL44RYgaNY+pCTollZeB+oQrPsWVChORqfI8LN7
SJJj3dcUWoONdW7QSuJchIGsd4z0aKdfL8kyj7kbVSvUu/9mZux7SozV/sfa
vsemLR14zMvioTe25ODIMX9jKAsuKD0bq27gNAdpHY9ossJQFlyXaZagl7Bm
HS2dQzN+mpqXjPFVXsT9iRDfKp7K9TD5pRJKkLrGyqt+FR+D1X/GDI1LEzPo
Y7bmNK2mxdIpsuyVNFGmn1q17ha2FF3LoQoQvRq/XnFmKh9pLUrEGvWcp/sP
a74P4kJkpfCOd2rh1bacbtDi3laoFDYIHV3G5I1BzsdoIe9JUCoV3qk0YysT
GqwcNsg5lrbUA+Qnn8RpiKuUbBmqw6pqcmA3MSvIAasM640aWGJsbrj1AVUD
K8qwsic7yS3dhJVoZWB5JVittJqyN8WqiyaOFKtneUBgoJhfVXGnjqbVxGqf
zNYhooXVSSeE81OSTraBvMT58wsRpkDCgkUH0pYAlVaRlM00+ynWEYbJih8E
fAM9RAsoIiujsMOEwG7tVGApxNTLAupVLj4NCnnSlLFezxrIISwlj+lbdTo8
yy3WZjkTW91bvZJrwuRLNCtslENBr39QUiR16laCWtJUtXRRicC8XhJQpgJD
bOSt2VN44uYQ5SbA0zgemjWZJWDtubWpwEgDVc0NaW2qU7CwTUXUYAmC+BKn
4ik3cgwNrJCqY8KPWwXXvqWKK67hTMh2YZxyZ5i7HpsR7kyUwPoGa3xo6LOJ
wdWcU64+J/psA8h1HBFtjY5orDHjsoE/zsWtyDVNSQGeOeUaoFrOHSAOkLEK
hpzNnf/zH//87//8xwIgbtUVCugaUWEiRazj1VyJXB2kRYq7U/AhTMsZ2p46
12gOh83Ly+aQG1a7l6PmJY7LsrAYsyLqmANbmc1RtcBzYGJTnMOmApbOFgzU
uqGqsPDZFHexGvFQmpuGtDimnE/c2QpLRlFhIvDN0plLeMtSANMimrQssc/q
rt3lVXE9LDtfF95EG5Cu3JMTwGuJjDTBCtqKxVaBa1fuqfXppsBdssKFXgpc
OigsJwoUR7WIv/28567oDbdi/aCMAgKgVeFyvbuHoYLPKzP9qqSql9aX7tu8
bxE1lF+muFQwN7ErU71xguolbu1odesLlNAKDbIYW3NWoTxkOqW4EQhmRYdp
e/HpztYPFlpUZVqwmnZEhYCX4d3vda+y8+DQlMQBqggBbAlYHiuaaRnBYKlZ
0RYZY/iPLGobBZPJWrpd4lcLQgsZB1WrcZSOhqXjvMc0qzf0TiuxepYoVovD
ShC6n574dj8nVIPEwreBQG+gXrKORoa7w7H8rbIP4JRb6MZaJWDmsYVDy9sC
e1LzLSAnkoFKH7cyRRxbhrIch7QLVZJobXX5RmpqWJgNnBZICFesyFSYCRT+
hu5F6NIJf+pVtGffghp4YR/Smr6wZQadYOFeXFmxfSeaiG7Ca40Qmt/c1QUg
03CTZmJecZ9jkAthW4ZzaAMFVBDdHFb2wYceHDqH1hvSul6vc6G9OjfstpmA
8gy2FNf3yhoyDfsBK7eTzVxEkQikh5WA83YMLAXaSaaY//3vWFY4eICVs9lg
OHdH533j/YQvaIpqyqVUnePWier8xe6sxc+RkEHyAn1wLwezGhItzBAKidOp
Y1KTx11iO8YTwxBrUbjWLZq33pD84smhYf95dPSFWhF2uoOGzBfYiegOgf82
YAY/WMfcl2DxfIFveTAXDv4b3rNdDVczYNKQgL7V2atzf2AlH93ZwPw4Gpob
4YTtKJOCLbW6lFIE0bLS9D/pbCaNuPRNcebAwqq/YIk8EZ4UuCsJ1Cw2h1+f
vJLZ8aBwj2MqE2YDprOFciF9DDaZimdTpxyO16CjqRmtf1+si/nMfqw/tav5
docT8vYcl4KOVd97bIlGDy1mYn42p6cWrA9swS9ZC4r4EJqIS7Rqv3DZMkzm
0uazEdT39N5vjvj61SVLkZ/9yAlFxINVJuGaXmUSt6Q7qjok6IqxcYDfdMYv
iZ2aKVhVBcWDDstFtR19lkaA/IFSJxQgK6CnszPHL9zFP/8xgW30qVeVgg6G
z1boeHZGwoYQzvIfoGSBCLJSM8OYueVWZCUFZg1oLlFIKXaaWIapSBatA4H9
DmDfeMp1AW3sUsjzQjna5SfWZ3RSPHMKyyjQGj6hCgTpvJDPC8VsoTTeSXaP
ue7HUd0+7oBpx1PZCgsQX44VfeweXcjj0cXwmI0WJSc3qI6GWC0VPtY8gR4g
hjoaORQsxOCoy/0KCz1hK9Y1HqvzmVzaq4+Ev5EYt4ppOyDjkRBvUCF5Z3hg
A8a6aqUZLH7fV7Tgksi7ktSrwkRfgkBkJgePdgjvV9r0iMfvKGY+k4GV94ky
fYD3FvbLTmpC0tvCeDjI8I2XTuZ3+2/ZQoERGqusiqATdJQpg+7ViBs6Gui1
XTajD0EDGzZvsIJUPku1QewYoPxPuZZJz9q+cIyaBEVTQFLbWIJNZG11Ywkm
YAAbdCmwsKIDsVJTM51dLo2ZmZ2OhueONTBmucH9pH/9O27hfqUggvJcnjmJ
dl6kHJMYrnJG5LkhuWz13UaY5feO8bXQPASXleBaYsk10zpQihjn8yuWY65S
LucyxbGn58ZVl05jYxpZa2OgU/Cg2ehc1Y8jYrOBZrCvLu8Mc4G1eAjsQD80
hnfD40OiG500Y4t+mWaVRL2CNHgMQy2RT23VmMDaq6q46XPL7rSBzhqIK6qm
O2B1g5T+QDXHwa6i6zibByt59k3CLFcoVgqlApNUQ09S7ZjkKLVa9JBk3O62
xg2Cx/hjGEKUvuy0Pd7G3bNoHSuTXZNJ6sUwtJSDFfykND36TN9U9VxZkIki
8mLvUntqd+a9540hSUJH2rZKC+tCFQk5J9PNVX4yrGe1Tv9l3b/uP7RJVtYf
B6mXqUoe6ppmg94wxpeuuI3Uv6l2uT7bvwzx3NHV0igfqFAWwqsm4mbwxKHg
Lptbhei6eAozAqxATYyswJ056jaYH9z2vNcNCWCRbLB1IVbakGfyeKPNn67v
lcFYvHiQn+3bVeOMtPJfu2wylUI+K1TGfXcTPB60x2HCjP3CQGyisSiyIo2r
XUbDYbM6+jFESqSLEO4r1QMPGfd5BQRdZymqDZCdYLjDu0wmtZSncTqkNSl0
XuaCthSaoEPyQrkS1tbQCVUnMtEM+GO53HId2IaG6KAslABhokdwnnuKiP6F
MA5QJxOmDpInUGEwKqzHnrTHX3eqrUory+JLBV55bc4gdRC3bxnU7nrz2erH
LbtXNPvqdXdbqZ0/no0b7cVjX1b1p5p4Q7aqM588X/+L1l3HsAet+nehk1DZ
pdP3WXpzwzankmvrCYWDldHBanErpEVKb8cbdq1G526gPG3OLQMWZS5bLuxb
lJQL3yCMz61WmmLtM+97qfWzV+J3mh2v9/+/uqv7beQ48u/7VwzWcLA2ltLM
8HsPC4MUJYqS+CGSWkryA9HkNGdGHM6M5oMUdWfAZ9whueByjoHc4eA4CRAg
h+TgxA9JDAObwA/7p2S1u366f+GqumfI4ZckKvLFt4C9S3Kmpruqurqquuo3
TEDKsofF5sZ1vUSK9fOxUyhtq9sjkIgUT4hcIqXtWvE7rac6tdVAS8WlTF+P
D2rmvO1L2eHxZR+3i4SYCDQTHUlXs+xZBkRfU+qapKt5MQVMB77SGMJt0CjV
AR85eH84hN46XLHq5a9SMonrAJhd4CSERldn2ZEKvjh2zve/+emUL4KQGJjU
FIjApBERzG0L386EGPuqvgffzs3BYl/GFAVpz401GR3rwlBn7mQLt+/hizTx
ZdnB8Tm+i/a6VyeDXZ41aoQb6RgBr5fXFGwGg1+x9S2NyXiyCV/16V/0sE6D
n6egLq96rSgjA896hG/ThJ/5Ac4eiAEiDcyUsRQSMXkkp7td67Fw1Mghl+Ix
iB5mGYU1MfPv2rxhN5MySQghMu0GZtchjNMv2S/zoddybkyOc7Ymp1MLSbLo
zLuTO4JYCBR+C1/wK1QISytPGbwz4d/sdLpmt4fvqJ6No+KikLMd3bjGxNyK
F4lsIiu366hLOH3UJQyd5hJF7dy14dBiGBT3tFPNreux/OneQax4fmaOipda
Wjc7hufvlwz72dl52WjZqVZdKTdPU6nTjB3LnJwRQqu9jna8sWXtpk7yfp/s
+0RU+x6eHvJCIH2AIxnYgig+kdNPRJEJCoI8ocb3NKwWGOHRMTKbZzUZq8Jy
tyW2ZT6nSfB6XDB4fWySZihjLhWC3sfCFjGJQoRHQy4Q/FFKz0jkbgKRpXgq
JYntJpa/oKcVXN7eNuFRlomJ+3azvt2u2tRsN3wIEq8z8PtO1rqwpZ5iYk5J
EjNxvNqhWK+5igNhNQf4lwtciAU7VIyTCE1GBdZnYzyAxajjcZqJLp/QxFSQ
Gx4Lhtbd6kVe1wuXNSxYaXOJHsuNDS02FhVkbm+CdwbfzS0AKTXP7iWpnRWU
mEB5CmeZlxK5jdvGzZ5uUH5bTEywv8WElGrz8b8ti2/LGeltObsiPLvNMJZk
waUngpS87yx4cr0s+D5xDNfxNRrNg0up2L0oO1qfpCizPA1EEauSYMjRu9l5
OR3P3ESdpdjm9wKwgKC0bfQDA8kUm+Udntp/IuRME3UwDACDSoNWUXjInwW/
gLeqMN0Plf3hdOyqN+ixfP+GyxeFizsGU4/A5XgPnA31KeXnEP5lrIF1BPB/
f0h9J5rjTMSA+WXi/LW7QDKelpLr7QI8TN6pRx3m5I0Oc5KfEGnUvIT/sLoF
37I9Y0azN0zoBs85ucxzhoiu56DVirpM1/vGpd6+2qmmEwdeAkxnSkwmlmaR
bjflR+zJN049/a1MneWVFlPy109fO06Dh7jdr6QxREqlU8HsMfMxWMh83Ivg
/3pNFuOJdCKejq/OVIQ5iYPc/vb/9fjvJj0DXXlenbP8OIWdntwgzb3L3oHd
MTVDzGEKQpLSK1Iz98KI5LfCiJkcTcCQSRHRtNSUf1odCV3PqKpXtdIVS9Vd
VPt4Ugoj4pA/d8vVJOdyNdeyLxFb4ODd8jbJSN7mvqPFO2R3Vsl1Lruz1kiv
l2ZKziUz57tStlzCI1U5LYZR3WI5UGR/1j3N77CzerguNrvpRT1QUdihnWv0
PEJo+fFhQD70ql08c+xgsteMsCosNGV1przMlO/UwUZdhECAeaSyxM8H/m6B
IaigjCkdXoIwIl5Xe2/4VFfORx1R2zE093tY3/S0djDo9Y/2uvGsX9ZO3Upx
YF/Ezgsxf8s6HJdVo2R/D8OIlOR+e1UA0jVVANkbOL7+s25TBCAFRodp5tR7
uOkwRj2qn6Qk5ZleY1lG2JreEa5LsUQceMtV6GB6FO1iw4Bv0E02txWpFTAs
Ch2CQRzgCe77O9VGYbs8F1rNE0bu5iHUdKnhPsbaYBUDuH8Q4pKwR8yYNMfu
xQhr5Uh5HF3cLe7ky5O9ygM2LzMc81SCGibGataQ5i6jxKlsyinY82UelMmi
1E6JfpaK5grpsI8b8w/0lZQsJZc8ZIMMpY0R7Qzu03DIaeTu39xwcCcJnCLG
OklOr7AeE4WuiQnvYK/buOiV37u9uUjEE/dqdePfCeYFTJPiNzGt23C2Titj
K91W12AaS9XcJ9dSQoF2GdeSN3FtjtDm2nzK8zNs5oXzM2zkVlKSpdRN3Bq1
y85Zme6Oa5k1uJXM3iuz5Nvz6p41jGX1Jv3ZAddE+SauSSlSPI1Zp7qyjo7J
WZn5Q3//RPB0z6BPH0Yr3sPyajqtfJ+pJV+j2vzhBw94WXEuqIKeFBVPqqTh
Ct6lDWvbJ854WvI+qQXnDW1B98B3oridNSbxhkes5g9bG1mv9lwHi+UETU68
QNziHfUCwV5RE3vUQFe1aOXlAp/xPmLb2LmCPYS2g53cM20g+BDW6kR6dNIA
ozvYze64T5gE3hLmUjobeGjIf3qLe3Mrwpp3HghCTHifZT9akTV1G1iXOD28
2Dk73Nk76FJCU0aiXVGPzYFbOAnJMg/y9mQZCkNK7ZxfiMcnmdaJsxsvXySG
1Ywpx/x9dUK2ebAOVfQpMsb4fFfLjtPtg2GqI+nHmn10fuLYYlkMibLUwe2p
Yvy+2bSGnpEeqcPL0V6rKZfk05GpWaWqeXI44Wwud3u2EqJunuVPn/XTJ+PG
yCY752Ml17toxeP9ymltMv8aOmu8OW6mUw9txG2fZYc0YjPdfptKKtmqkS2x
1Tmtjy6a+a5hNvu9dGPAXi2Nj2d1IDILHXn3xPue5lCiSLd9NJkS2PQ7l2n/
eMuNxU4u/UZrfFypuINWr+01DrFkERZHQF2+C/WLXe0sl030LqmSqlZKw1pd
HTWbsVZ9kAt5WWiUt9ZinDJwu5uHWzJRSt2T/oXeNEx9u9tNq2o/k8rnJkJa
klC4nvA0lVArOXtytX143q0c5cxyyWw/02S5NGiVuyH1aG3Q/dcTTS1HfcFy
ODOW42inXC8+WVsFOLLJaWtf9MvlrFxVRkatox7nh4c5u2DT5F2FH9Cta/W0
Je06rYtesdBT63vleipZz/cL28GwWYJ73UFjrnmz0rnYLY2yu+0Lu3HSUXvV
tpk2npV2aMu945gZ2aPkya6SlYyTM/18q+ll86fjZ4XKDj2yyxNNLVXqtzYl
4KhttjMH2/G6L10cSylNLe6NnHG5WR/VLZKLiBicmlVn3EEEyk6p+dKfdcGW
yR2Xkruxko66GdmIN1lZ+aYkpWUxLcXjq/i3Fs0BxvQq3YxDfMIG3cxt3Wmg
EA9MB5iNy1L27gOM0JJFMZXJJMWpBKpbtdk1hh3inACNLDW4bHLsBBMK5hmZ
kdW1Y8QwNthhpMsfDDfFwptmZpOWUhhGB1Tktamw7F17eoaEDgefXFZMRknH
7410IhPPYOKWySCgnrg36kk5kYonA6kI2+g0RtQ9b1CqIAYUWkRu9da0SYf7
ii2ma4kj2vRdLbclnWdpPu/ZYoBhOEm5/X/rfcHBR3VzDYmEaxV2pjijA6El
Qz+JHLKPBzaZNqmwj8hbPFNlQDXB8X0WeS3iHwakA3Is9QSIpFgHbgQeAjuH
hwRcFxQannYxF4ahBEFoEgBS8JiEN0sHXOINwsznfizYvKfUoIgpxZ7AIAu2
oj15D2Y+hfEU7+HEjvkRRSNBWVLv1hHofM4clXeNAHbZ7e+wpmwTDLpOBRPi
nQL1PberCa7t0C47zOi/+NI0Kb8Ci+UElTomxa5qYTtWBhrAXwFL3raxt9n3
sHsV3QzswIdARSMd+K2se6qhUwW7dhQgVNKQZIfqAqLNvPiMOaHepQ8iKWmI
ypSnOoxWdQWNGj24NBgFDPfqvz569fPPXn3066uP//vlnz5988UfXn7121f/
8f3/+dO/fvOzn1999dWrz3/55ut/gwu++fDTN19///VP/nj12x9/89HvXj7/
8s0//uT175+//vzzq5/+9OWff/Tyz5+9+fCf//LhR69+8MnL55+/+uxfXv3g
x1ef/OfVx1+8fP6rqx99fPXD37z++vmbLz4Baq8//adXP/z317/+Gq5HeZdy
ldwCPkVzBjpFIy7CnbArebs+ols8wA7ZDixspJLrhk3iLCUKQbTJekup8vRh
D5YyhTh79hoO1ISt0CZFWAHiIEwIYnnM4R+UPPatHoKsRUPsHi+7QowAMG04
GGZYEbTAZ3l6VPaebzBYmgGDLAjwbBZQP3hQ7HCMBYUDRtkoZxa5hhAuGyFv
AjwXhgjm8mb/MCuBTeAuRwPjB8IYQId5WwHiPuwHj2C0CC4uoaBSA9QVmYM9
UNFWaNaYDXHyu+8uNervvot4Uct++eADBlcw0l0t6M13WEgPayRo8WYxO+3q
3CMKlvgUESKI3PUwScDg8xqwLsfCPioMEaq6SeC7gkPcvhX8NdS78FWZOH2w
LXVfGcOnKCAIfNyD9bZPMIUOH2pUFfYQSAaxm6gDawbEuIMoa/BFnXZon2hC
FfirWE4PvmpaHR20suYbhotcWZY6YExZ9kPAExVGH6BSkYlq0iXT12FxqJqH
ejTVLJ71gGVt4/chSoxlrnwmY9y2o3cRoAk0zUCm7fmaBfN03Be/MRcYNofX
gqxxfIQ4MYgJRs1DQXigdMK+QwfUQbacETRhuyBifj8ipjQ1a+BaSP7EN3FO
ezphfK2RITWEit63TAuWBnyzBTvCGCFX+PU50zLHA0QljPYPh0A+TvCMrgUX
6mD3PF14NHOhq1Eb9isFt8UCMUE7yuBkwOIK9KNumWrfJzhgpgMUMRYOiK/w
mdkIvLBrGQOmFjnYChwiFH0DP3jA9JpD+sTV2EzgY2M8ZBAZgW4FKlL2qYa1
uzjhPUsz4S7qv/gFDNzzXH51HvZx0ONdYuAwWpTh+zRgE+jgOEK4G8SXm+Lb
CIt/kH8zgDgT+Rz4FuOm4tARssBgwloOhwM/RJFp2AhsTccqRW2gU5WxcjhW
hGqf6EwPgK9IHX0AAsu0ZVnKgK2w4osvHaREQV8Urh9gphrEsxiL+n6HqxgC
AXjWyO3rU6XZQTQPUFbOXfABwLQWfFVlhBvU0XSdaY5B4Bofh1mgHdhHLIOO
2YJkMQSCczk62Fe+Fgsx/ik0SsxPQagpbnYQZwINU9eKRXKozAzP3h0xSkNi
+Cy/OoMlwNba4vKJ4B2xATDAxPs0A+EuxJ5fskzfA3FrEElRttgX0JRwTBob
0w7P9i4xEbsIJ+gKTXBnLHAhdNSAE+Jg9KrRXo/JFdYMh284gP2wA0sMFbmo
O7qiwf5ShiGOyYDpJ3AQQgh0IkGqHl8slkkYsNeuNUZNwYUJQgVvS8gTB23y
A8Qe6sHOxcTI/xnIcBlOyMLmIUzr7zkoCm69A0uhDKeN76WyiP/GrKi0EQ8q
c3WO2Bp55sTJZfl3BrFE3LlHhChaIQTcBPR1H1RbA20bw1zzMD+VDIm5zKpW
wEYNhH0LHDsQMk6/SDFigC3lwYNGsM0zV9wNO5Ix8nksYGD1GAFdeHKeF3hz
3LVQPXlPAUdPYiwKHReMBBgp5j9sCDlhOcrLlBSDCHPB8wYB/A26d96yIex5
KqXR+V6KOIaD6yFaEJsyr9GdoBNGegqERw8Df52yvRAMiqm6KuxpetAAs/Hw
nQf/C2TJeuEPigEA

-->

</rfc>
