<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-17" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-17"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="August" day="30"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 127?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 131?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs and finders</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">3 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">2</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of <em>paper</em> authors):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>?</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, and Haowen Song) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">TBA Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 654?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-authors of paper <xref target="Intra-handshake.fail"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8292XLrSJIo+K6vgJ20vn2kEUiCO9WWk8VFXCRRG6n12DUm
CARJiFgoLFxUmW33Zd7mB8bsXpvHsfmBeeq3+pP+knH3AECAIinh9DlVVdad
mQIBDw8PD9/C3UMUxQNXc3V2InzpmK4tixPZVJ2JPGXCV3kqC6eyra8Oharr
MseVXc0yhbplOprKbKYKbdk2Rp4ufK3fn4rZTLYo5nLFSkmwRkL9vtcTSqmC
APAEh82ZLeuC5U6YDT+dOviKNxNcS2DLGVNcAEZfVFJleK5YhmaOD78cyMOh
zeZbkNuP0JcDRXbZ2LJXJ4JmjqyDA9VSTNmAaaq2PHJFLQ5OHMmaLkqlA8cb
GprjAFR3NYO3O6f9piD8Isi6YwEWmqmyGYN/mO6XY+ELUzXXsjVZxz861Rr8
y7Lhv277zS8HpmcMmX1yoAImJwcK4MhMx3NOhBEAYwcwqdwBALaZfCJUb0+r
BwvLno5ty5udCL3Tav9gylbwSD05EESh2hHkMYzq4B+btJDXtMCf42txMGem
Bwj8Igg+8IcW/sHn9wBjAqWFFv6Ejw0gBL7yF7aUjZnOUrAU+Fy2lcmJMHHd
mXOSTkd+TAM4AK25E28IFDK8iWwYsip6jmzIoiPbqmynt5H7C3ymy4g5fBYA
3vp5ikNPadZWQOndS5qauAYMdCB77sSykZIwqCAAh+icG750/QGFOxxQ6NGA
X+gtyx7LpvZGdD0R+ndCw2YOLP2x0GK2IZsreotxioUTHxDmKY75X1xPVPlX
KZV92TL+vSYrE+bo8lxoeEO2mlrbBq9bNntg8pzFhsSv5L+o/DNci20D9Cxz
PLSEmrcNbg/INZ7ImtDyZFOomsBaIwvmRtuqz5SJaenWeAXjp46FC1eFf9Yn
minH0BjqHlOtsQlj/mWMz3ahUp8wc7zUTKENo4234dNZ76/YELJnI4fbH4/R
lq0FMwWc9U+b8ATIbkrZTCFTyOf3o3Mur0CG2ooG427FZ6G5yiQGfQqfpBj/
5C8O/Z5SJtuAd2WQVIama7IJC2xrY8BU1bYNc93uiFfd01Y1NtJsolkGG8sp
2zNdzWD7p9IBlhd6ysS2lOm2MU67nYtOVbi2LddSLP0YSKukYuO5TDb+wgjh
mf9WSgZ8D0y+BHMQU8KmdEvhPj4hODsUFb2xqYIOT4Q2EEQkzaO5K5SKoAp8
vQGaon/R47Mg+SyceSYT8PNjPpRsj5m7FniLxSIFLMhQDI7hg5TJ3PTMG+qa
QtNP5zPlrFSRytnBBnaI3CCO2yCGGf440MxBgNkAMCMcQqFF/xMBe1Ae3ZRw
l/LFVPyX+1QgQeLPz0T45kxWXj3m7iCvaLOZ9fegsb7aQ2NfyqNO+ZQWIZx+
IqXik/Whx4eiPXCCb/IHPvXqVt3q+WqZk0HQHGHu6SZYQUOdodljM11e4Tuy
MoXfNBkMIZgeWUJsNmEGGUz4KdgBjg9+C1cqc5YCJNKAwy1TwF74TVN/3TAB
hPUaZItCF5mY1gF+OL27b/BXpWK+XN43y9PLTq/6D5kn8+ZqipmaA4LRs60Z
/itNf6c38N831Va7VxXrIHUcsdqJc/uPn0iU77O5OCJ7Wd/TAehcs3Tm2k5a
QXTTDlM83GBpWZ1rDliczEnTbOaj8Vg05sulaIzHpd174W4NVCAKgEEZUORU
HTOdOY7YW8HkDSdOmVtmWG7MxETKgB2rsJmrbSNNdOZVb+w57qfmzXw0nBXO
Gne64+6e+ORlrIgvSmEujhalye6JB5MT/MnBr2hbi8HSgi5yVyT+bHdz4jin
qr/cmvnO6o56IGBDoBcy0tByAX9AqKKxrilot/sjR8kiSSBmzD2iEBUmcgyo
xJTG3BHtcHyQNpwxUEV208scu1k2X26aZxcKk1lRzw8ux4+m4TSe0p8Uigda
YPz4mrch1m3N0eC9xlUnJWVSkpQvpHOlUiWbKadypXIhVy5FX9ymOIgEqAzo
DaRcjDJ1y5h5LvgcJ0ITBwdambK+wlfBJdylOi6tOUN3CmlW+FB91Ot1MbI8
aZqlLjrgaIqaKiqE2fdoDvilawFHyyM5/kM/Bbxu40ObjQD3CAUzlXTvOpXN
SKUU7YKO2EiNLMcB1ERcSZGhiy1GdtjJp94SM/nNF13dib9R/PCNykdvSJng
DdiIbxyXEUg9kBOpVOrgQBRFQR46JAkPDvoTxj1sQdYMB2UDWHpzWHzBReMa
rCVdUJkL7E3L/S2uqP7714Sa7ZCiC982lMAazOcVx+GxsJhoIKNJusF8ZM6u
a7QZTsNUGOI9sRbC0RHZI0dH2z1xYUSTBPafIWk0hR0DCHBNjsCkn1ieK8wm
wPUIWVYUEFFHyFs2A0a3jwVHw5FQDmqmBxy3KYBBvKC6AXvKZq+eZjP1+EOE
ZFV14CXPNBmOJ9srGADd+CVs1yMYHhcPjFzQQA7GJYQhiD7YisOV4PJfyPwV
/vrXbcbhn3/SWuCbsu1qxCI7XiWpAe8DbRA3JlojEb4T4TuBb1UA5csE10JX
ApyKezAxR8eCB86hLVRn6DWL2VRGAAucmQ4jEQxwbUv1FI3L9WPCCLw1mAoD
ysN0TGuho6aJzEpn4M25iMmUTSwdwDs+Wxuaqurs4OAXkv0ImEIsO+c/QxKZ
SLxgfQR5BhgBrrgTaE5vjIbVdodwcMfMLEfWnWPAbgxSiBQYcN1iwih+Bv9Y
0QIhJwEREaCjWDNiTVRvgjIBWsKbQBPTclNC07YMwCpQp8IMJolRNxD8x4Jl
0ocIBSwX2J6K5nAGVlzLdpDd8DcFkNVQGgtDdDPNsWDA3gAH0DFAWIIj+f65
E8VyO4a4QhQV5O8Stv0YD+Fj+Hw/KyVhCxoTbDf43X8C612FncF3gwFLCHvj
6EiYyUAnHDhQd9E1plUMdJ0S6jr4XaQB9qwwn+Emp8P/yXPU+2hU8QnH1OwP
maXJI7CxmfrzBIYH7rDhGUgVPtI6Goq/wkuIM7I3Kk3LG0/eTcLnI5U52tgU
rBlOl+iyjxyww34RrkDuzTW2QB0CgLgSiVHbHwsZVxv5fjfNcnP0PZzqEKmC
x/vxoldREYAZoPphDnoW8xOCSAbow4M/wE5JCX8Itc1h4dmdw5Ap4L+qIWv/
AV9I+EFd12Ca//k//i+HYJoWSv8/hG9dUJX/isb6WqXJWsqAp2TnEKIKcIdj
ebbC0jNbm6M8BZxQwgMKYqi/RFBvLqOlPkTQSANmS2vA3+V+p12bMTRXzbQP
8JBmld2YVZSswezENRrZH41GlqORQzToCAOPGSySOLGBcz964BwfOI8D94Cj
mU3z56Eikq+x8fM/evw8H79A9LcMeMiJDlvjlyztll9ycRQKPxqFAkehuAeF
PA6/6Zuhn0Bu31aENm16gzH0Ipz0ULeGfHjwZBiexjhpcLennnPrqatU4EuC
UQuWraIoUes2NVNHh/8GZqjvE8cNUMd0RM21wd4vjgmHxUxEcMDUaW+mW7Lq
pNEfSUvZ9APDedpiFb02F1UrbL4+fivWry6bncbpZb9TvSi2/CFhzHo95kP2
Oq3PTPwQ5IGsgmQFcQL7/AWGEr7tkWJbYW6QIR1INLL+Z5YSkRDFH80eRc4e
pa3scQzsebzmEdCBe90b0IkhoqUfjWgJEf3rCfdsf/3yTqiDfaaFapQrOkQ8
sFXXJsyXPw8O/v3f//3ggYXekBxoM3gAE4f/AzcysM7gLzDtuSk9BH9grdAO
tig0+na3EvNQDSCsg3e2NtrWEXRN1Tc9ET1Dc7XxWuXh96oGJtycjllDVKNx
FI05KeHKQ50JGw/skTmDvQifyq6guYIhrw7A/ABTXIAxnCB2BLaMBm/CR7YF
iILBHMTURZjUCBS98BVMdKYLucNw+nxS+6Yt62DWoqEFZgGQD0cFDaBbsDfV
A24uRWJW6PzBxIAG/hPQEwaARFtHIS1GTtrMxTcCR/BgxK1qVRuNGNpN8AlM
BoftWdwQ4Z/C+P7EHc9mIUFAlIAn5joHQAUNrAE0mjhxUW2kiGUOkGlAv8/w
iHsIagwXQbfQlsABYmGsj8wZdNQdtLC5IfLXv8YCouiPOY4Hv8F7Lscf3FUV
PIDANea+If8aPo+74vB95NSf23RdS2U6rtQVWZ3BDuqGzMsDBnFbH9xZsNxG
6JYii+BaGZYat/hwUggJRlxTf9/ct+wbcAAd3L8r9EXMMf6KXAVD/g4ywpV/
B7vYlsHWAsx9J6vuswJgwHW74FtayPlN8h2Fb/J4jG6by36cPApBHlJIAB45
JCF8j1KN7l1121x3+k+warDWDuhhUCMY0wYcjWCOnun/lfIXcMTd4wAJ8hwD
c3yLV0g8QOFWMsGiWiwaKYoL+e3BLuJO2nzco+H6AtcEJaqMOyMSrf+K2KPb
CQMszMOt47yPc8EY+I3va+i6tSDJubAwKcLkXAISwd/1gfxee9LgAIAxXyPd
IUxgq1HQwZuh4FYPwCK+tsAa2OHzozwOv5FVFdaRS6kokpxqvpcmcC3lr+1n
KKhajPY/ulVzhBA/0pDJzUJvG98CfxjQ9IW9zVzwh/1dwMeF1f1oPiDxtw91
LAw9F2FxgEdHMGENvwOCRkNSH+k2QNQzX8DGAgZkKvKbULcxKcdBXwzFGwYP
wURoEsrkcImiSP9/8Mc2EfaHsDUh5Fh4n6fBzZQzJpsimJsaC04OBQ56I774
Q2FvCu4fDHnzRGj3CPRVv1bd+TuJyiADJfL2+hm+sQv22vhCvJw0JY7hByO+
nmhY/QI63gaO58qGNojLHxj4AHkEFT/sYK64ekxJgW8iIW/tjWTSi3n/tXUE
CLgMxmxQDBsg3sc0cINrZ9Tyfc1A3ce4Tcjdv+o6AGlQWAN0UBXUF50h3nNl
i5x7SlvmD6GBMYw4z6J9pZkaxabXdgEL7AKyLyxfcQOETEm4UtxjOjYh8m+g
gBiEL0t5mJcSeTmaHOObBN8wI26t2fYfVNmy66SL4+HrMvP4VH54stu57jI/
vyqbWdE7Hz+l0c/gh2E0apFG/eZTC60mUEGEZ8QxY8NUMCIOBn+jE1bMZLMl
qZgpFPLpqA8XOU5N2eQsjtMuY9zRwXCJsgIsolTIloQmG0bwCZxD7sQ7E1ir
91tQ+HZ01AvyIH4V2p1WG9MlyBoqHx4d/XeE7J8DR2GDeNoihtYj7YNbCOAW
38Gls/oIGJRGW4XSd8L/tuaj+PJETJ1rJC8e56IXDE45htplMJXSrjzmoSr4
UZxnUuWUREsQfMA1H320jTifwLhCuSbfi+/Y2o1rISWJY0tKZYsw2Dukx9Z3
Iixl3mGM8YG4f/mdrrzKFJ0U+bc9CQ2firlswk7PPF1PF8q0jUubM7hfj7Zl
Mhivtr5zRv7+V5E3s3uGTWT3ka2IK8rPhMFYEHDHbkB/F7R6JxS2aM89DJAP
9tgGy65VX6hq4s5eVOBHVY28oWNQRx4dXTItODoiuwgtPP4XSiA0PGUTj354
8qWyAo8PZLeFSAsWt9KUdZZ1TMGSzfz7A5OnbdmZ/H7M/7vR/p2SoX+vyeop
X/bfU2DR9fHsCo/ZhEguNbflwXk5FrQUSx37MHsUEiCoNDX/AYDmMwUPaGxZ
qsB0X536J00yz3Qme/D0zs9bOjjFA2Cwe4Q7E9b9Xx3hG/3wwWHxxDLYTB6D
54VEiuAMHkd06d9LVppDmAVPkY5wZWC2kfyi4HQGzVewfsEsc4Dm9D33u+7j
UZbdORXCBfjOoHWBK5CDfgHTXVTmwIuOYoG1IAAvhIwICAxl9BdhrG9AiT54
bq6tKRFRYAJBgB5uamzN04it6L+SRqCHqYPIduNcyTXaH3zeIMSC0T4NM2ru
RMyebwsNfBB5RgZaxBiIPE2PYJc44SMMswp4IEMYff0Glh7T4/FdDR9xkeNH
deFp2nPSzAwzj0QFnjM7HTVG0vShGL4S/Q15oABCRcyWxUxGogR0P0uh2m3E
x5cNlac+mengCMdJ80M8N4SeHoKMxVB3Gl4XnaGYy+QzIdj1wEg6CutfoldO
NOufnm7QCyyfKK3oNGiDUu+ANB5VaxHRPaqekhWDbC/V0tJhllCxUC7m8ynQ
eZlsLkMR5L8jzfNI80yU5ngIBWascGEt+Ex6rqwzL8LeS0UWffUXKTFw+GvB
vweeAzJhCfrep1OQs1IQC/lCpvL5nBX/A4SRT2XQZQJX1TM4cjWQqNNmtdf/
CL0hvjjC5LjwvwaWPNWBxbbhWJQqpWwSHPGDQ8Qwu4mhrN5Wu2tQQxk0poEy
0v8vHPuPH8jmUoGvJJ5m5f6O5JKSkksiFCsbKDblIYi1KVM/QnEUvLj+r/1M
J2U+gSE8jHywFcNtzm8c8t8x5f1Q2BGQKdEuxu9jZtGmpuSJDfP3mlKJakol
1JR6qCnRQqK42hqiH1vkpy9rRX50BMiAEYOm/s7YAYZBsfrMP/nYTCrG+JtB
4wor5vqDok1lBVlWbpjHsB1zBxmIx3HwcCPM2Yjk8SwYHl64MEmTJ6/iQ2AN
h0xSMoww14wq8Q4Omp7th3fjyRxo8ehr1NYx0ZnlBpYHRmSQHPvCdF8380rW
tushZU341kJomoD+oeI5fqJw6mwaBfAJ1gn+gTmmLqXQgf8h8MdS/HEORkcy
2gbP+VLxKMnCqC0/hiynSiF3+TCiDCdk/Uf5zUfFmEyih2vmPF3XNH6CPptE
EXyOxIM4GyPcYN0beLq8EvDcwyDmAtJwo+6YWGqkYfAUC4LGGOiin1Lc2kYY
8BlYy3wgm2GeDTFBxFfqxI8yDw6qwD7gA7sba//uyNNmkdA7LKf409JWTrYJ
CNwG28zvj5xuxPP9sf/+RHzCIHHk5/hHo50scWJbYv16It/hrRLl/pmTF07+
LiEPXMGjoyAUcXQEZAljQTx4dfITwmSYG8CPyH2Pi+LTiUNOiKxmc2THVkJE
Px8f+1HYHnRGwsrySNjIC/wnQjZXvtbfe0YUk1fHwowQF7ASxnMEnLTgWFxV
LyjTQlAmTJnS8m47eH937o5mBteQxqZMDWohhV40Z9HZJVqDVMJ4iiMPa+yd
49FMdidHG6IYkfq84CHB/UG6TQVeE5yVMbQwPL8lc+XfPhNrOzoKo21gSskj
l4WBqHco7DrKjKCB8/lK+gF8QlWcMVOksMahbzHJ/rnitkSbr5atjVFx4vqi
+YSaWszkeXgJGRczQHTkDwueFw8PsOCjilkhlMT80KKDTk3RZphCPrPQSVUF
y3NDPsN0C85dQ+DVJJogOGSXyYrjq7mpewjwOiUg8ubOKqd3X1FIMEfpA8xG
oiijFACg0JFl27CbgQJ//nnIP3PXybnhcTIulTNapYg6lAkeJwxWVFCJA1YT
r8JE5a05LJiVgeUXmsuNXbKJwe5yhbmse7Tvg/SMIPOdn1L7xiuPSe5PFqeJ
RAxbWBKOe9UU/JIoPFyTwRMgi8e35IPzdj7poyNVs0F/6XhODc8pHs1zA0Au
7Tg8D2jHhzs6uttRi4GDaK7D9FE0a1/BxFnbDHfJRkHOR7uTxkSDhuzH6JJj
Kodnh4Y/vbi9TGQ/YiD9ghyfC7SzHUyIaLSFGC2Er7+Pl6vfD0H8YuaKs/Hr
kLkLzIFQ1rk2PCEKMyjaofgLcsMwo/br7xPXUQKIuIeZqdirWZBWuBaaBk5o
zJyDXEqorjPNNqCBZN4DLZKhhsVp8sHBNd/qDmPB6XJ27+kywvSLoEhj9AI6
XvMFQanztQ57D6wVGqaFW/BwHdENt6XwJ+aHBZF5cjH9xCSg62213wsK6uxI
eZO7mpFztNM3TlEiSxQBmM1pUP6EkWxc1B5ftp6/qC3pEFdoz1eRdPD1OvZ9
yp8j5VvZQ1yZz8GIrl8cSu5w25rkEq1JF0XvLS+GQtVYjaZbbSt08WufcG3I
alC3OUsf5LO8V+AxgzUFeGwks0+YPnPCHEqeJykF+OH7mC8QZoat6xG2fZeN
ftfh6Tt7Ejb9pMyPsg4pEVMIat4iiT7gq3oGLxChg4TrQBrt/d8f6+xB4Rfp
OHucPy7GH+aOC8fo01+/nzX67SeiuH+E2GD+28F/hP/G9CJJONnHqiTl4Iv/
/F//pw/sP//n/xH/D4SS/QDKVJlsQOH/FYeS+xDK78IOKP5/RKIXxPt+ISCG
Ijb3UiklEb83tTFGKwqf3VgkPQNWxtzAMEwSbrT9NTSRypn1t0HF4vaDo73l
NT+rBib9Uyts0ro1TrlL9/OVNj+tyiY60Z8APTbR7bU8P62OJzq1nwA9NrW9
1UI/rVIoOsOfAD02w4/qkX5aLVJ0kj8BemySH1Y8/ayKmvRPrdeJT/JTdTs/
rSQnOtOfAD0203IqakXAsEFh9o8bN4DIp/UT4UcmtuWUIqLrf6GDgDD0BIvb
5IrYIY2960dS89Qs0Q+MgAn5gGX3OtmKs92Z4mQfHmOEYIJOyzfezC8eAFrO
5EhIEp0ubDcxZfY651S1lPSuT9OHxxTY27RcI+ZuP9rgwPHG4CO6vtsPTj46
opPV0NbUdXE+nivFNsFeIxjrM3bS4PCzCfw8VLTV9SdrHazrPQ0ePkIyaqNj
JZa5Wnv4Q2aykRY/rvxHL2oKOcxvGhCPCh8drTsd+F4FTJ9W890yRhmD3vho
WkE5l/8Rck8Vi7cM2BIwA5efM2I8JRKj9E9Ued3aupuFX8CyNer7A3jCZlS5
Encp4wFIIiK1yKA4J1bTUFxO/lxdjpjJx3D4EF0//sQjd8EiwR+WzYzwpDoe
uaWQXuqT4ueien7KxU8PWyPK5P3CzLFQUoHh6M3tJBe+6dg31JY/zZX4SPQ/
Sh9+FkV0QQjDj8Pt77uQvQ8g4ymvbE4ptso5KkhgpWVdp7Z+HJtHXt7S8OuI
51UeEfD1zkDcGMgYFeuibMtzgrY1gCayf5jteIzVjtieYZ2gMNHGE0xQoHNq
NZJJ+T0JHMJXdE39kPU62/HPP3FJsIqypc39UiMcl/fnUPwcgXX3wo2hj/E8
CIQ/lcCpB370m0UyCAgO7jAMpOPfHwjY7l2vf+DZY54KYWBuyV4x6peAfsRU
1GssS/882NvoZR9uFMw3MCdEBfOCMlRlakVDtex+FXDYhZhCZP2wNRJPUeYW
Qt+ydAxKehgx2Kw4DiViiGCs0Y/wLRCN6y2oMUaFuzYWmDAW7ECPkgIrZdgE
hdxhUKO8saHXJYK8RUe8KpVn/cTODQBpfiDybaQtkRuBfD4gVQv+kNc94ZIe
XX+qMVnEfgNRIcppwOWQHy1YFM1jIEQ9R8B+0X7RHlLadnlqDuCEbDUCGuGW
2yjy+yBaF5xSIOwU0cf2xTALz0EWkYgz1nUj0wDhsA841pJibyySQlTEGJ7a
EFjKP9CGXrSiCDeYZ/pnP2G1+j/hCvikxtNFzLY/RtLwnHrYKTjtAHUw0NkW
bGkFY7Vkx2HYOFJbT+nK78X8IdZl8xg+52mfC8INpFierga5QFTF7Tce48eb
a/vE2VyeFG+5YwTV2srE0kCM8wJ4NPp00OR87amDWVglu2WOuGjHXMyGgjXO
gQvCkyck+QbKh/2BLi1sAhho9KAU7Z+OQ7bvUVIkXL6YoGive+f8hHqtSlNc
bsd44+Tg4H/HDonrZUG7QUrljmMbMIQRyeZvaKORxsQ203Xs2Yx8Jfj1HyOs
HQShpzFddbA+A97RZtipEuTxnFHLMb/pEj+c+3paP2y0T/1OClgzwBQZZfuC
296eGbO8eeQK+G3dympDJNubdUA8KLzOkSTu2kIklN4PEw0Fkesz0RBsf40b
HJy+Wz7jJtF7KRYe1vgR89n67A37V2i8WjQUhqAgaW8FrpW2br0H+IQsGm9n
EK4S70rlEJkc/4DOw/pnN6SLidYbEDw494z/jNbTzLeHAS2fFVKYtK/o1GoR
F8GQVUpaBScu6PMFptPY47P31d/6kPEgct64r0MAgg46hlHDMN7WMf5ppEKW
nxKU35XOCrjoiAjxNtgIzJhNZEd7i2ZIRPYwZeDEKtSR0Wwwbsf8BImEp8fl
Gdbp40I5MXSpwRmf99pciZes3FJaxMH653hCAs+aiHdn487RVmKl8OQMX6Z2
If4BciRrGr897V3dduo9KvUi3H7ZrPA5CM9Z9h2txLqjve+vSRspaM3p0xBP
uhUWdkrbbN/CkemGvV8CPPafZ3+Ax9oK88/jQvB8YcJTnYNqrBHIJ+i9szHe
BW+Mx49ymarJQh3FIFiv4Sm6yRbrgii0AOk1wHLEqOUdBgeQw7BkeMwCdyrQ
0juywHyDecOwIb3AnSfb+MBLSFEGLcqRWzbW8Og+npJPLRr4DzyZNiigQG5K
Z0rpTD4d9ZjE0GNyROplJYYnaqLmiEPbmjKTDHRQYaIhr0QQcyJbwgjpQrZY
zBSKh4DR1zN5JpuwzofCt5oOnNSW3UugYN+ariJlnEP8CfYyEjfl4m9pP0PS
SUtSpSIVCFhAcx1cRw8TMgBqm9xs04qq5Un4jOYaS8ZcyODoeTPiKdG1xCGj
WejY64tPFAQh9u5biRq46o6JUSRS5SDFJpYKX4PNJsL/I0rfMJ0AA5WqEkuk
9R84KUz74BeesHHwNCFCaU2VipVyQSoV87nftF+lTCZTKhWL2Vy2TET+Fi24
D7NCkMyRintsSAM7Dtefiu2jKMQTvvwSEN+ETB/6jHXJlm6LmSjwOlw/RQrE
QOnAz+jkMexlRD/TrGee7rB06DWPdHkhrq1WUTPF7VwXCzKEnhjh0oAdvAqm
eUtZ6dHQC/wYMLefso54rEuI4tMTY4QgvcGRnGgurA2Ws8ISipTHLcoap0av
jjfg6Gp8iznKAh/ScENbY6OdG8qmYMnWKdJWQpEhjpALSRVxstHIGUm48WTT
9Yzo5rHGTopqV9GmwuVNedN0RhL9V8WOqeASRW65QcUpKvCrOGVsJuJcAQND
cxjMebVjTRxOGb+jDXEpRrpEhxZTG5sufYmKmNvAtGlvPZCLsnmIVZ0+a17I
ww3S+b+A3E7ZXhrFQLpQyhfyhdRsMiMw/PIcgELTBaEShxA8pXKjvSylMduD
P/hSgxsDooIjije2cEnV08xINA9rJEyFpcDHlFOKmUYWJ7EpZkoiiE2usICV
tZGjLN1KpQCcJaVUXoaGq4ZUyg+1t3iEEJ9w+YQpj1hYCVaxOAK/SxZhLWYo
A0C6Ym9WWQQzdceqbBC50wcybxRPukDfkK6a4+hMtbB0QtdEU3Ym8K8pbdAJ
c6beyhO9lfw21wyMMM1jG2SDTo7xphpRoee4KXrGt35aLmctvVLJbNIXk2aj
wgmR5M/oQ0KTUzWdT4OgkzLZbEjNCBxtxMxxJOaTogc82z9d9u5Gq8x113g9
5Yvgjcey6TnyxrjBY44zTGEX+6A4sHQmzvBuHVSCXF3gNqC0SdKA+JeiWx6Q
a2GJK/CAHYxk+SoEPduRFkdnd0eDGb4Db6TDdyl0HHEit8oyfjiEYzgzS3Oj
pasOtbLzOJn9xnZY9VfJFipSNVMAjq7VxUJGKoi1aq4h1qRcvlTLFRrFcp4g
6vJ8KcQXj5YNn6cmXsDK6Q2pyk/I8AQGtBzIURErzURMO96tAfgMrIm3ISrg
Cd81aSmTL5SLhUouP5Cy2Uwmn5G40XGNrgDtBkJO1dxYKXn4LKXZnNl2KYG4
5geRWhkVs1lJzBYVWSxlKzmxwlhFLBQKpWFOyQzLo/LGdrzQutfC/fXlengd
HNn5jFsmwZ6MGwSB0vEbzXBUcJl9YQIaLqWy+YbSw0fEv0562ileW5dv10v6
AJQCEDdCRfo7RVEWWUuBMCMcglUC2okYCoprRsTB4WqDqgR36m3fWES/mkZv
YZo0iyyiOkyNsfSUeWkHM7SpG+tvrx6zV7/G+Zm+R9skpUe+j7c/UDRb0eF3
epyOR79+CeETJAVwsnUwgqOmYuQhrUg2nymX3t0XF9XUC7B1RIxerqvKMQpu
ooUsm2C+wbt2+Bs3Es0XEO2habZR50w/UtExdhl6R3Ux7ENFsEaw+U1AOqKf
/Cek+lQNz6DTxdKGqFQc1YybDCl8RN8smLbUzEE+mysVpUo2HVyCOJBymUoR
LM21JrNACbpE1ogEiDwMSvS3cQZnIS4DfDYBD3/KlUrfs6eaMwFMwdlR0Y4B
ba/JUZs+8piGmchDrPbHwjQNtmmcX3fgoCkgb97klTYSp7KurSybW3TydBi1
Z+lP7idFbBvNjIh3kP+w2pque05g6nyTVfALFOG9cuM/iFzysPQCdDD4mWBI
jUDbEDiwTtG3YeD4yQwIA9PAvUYBevobVNvYBjgyto10qHWDOGZgcaeLlWJF
ypcKnNU6XU93NXA6okWUhv+MqxVfrDATGFwJyybxBjtwRw95+8XAVLtdS4W1
z6tgtzwK0gWvRYTH+vw+VqZ0zB3hdaQvCN5RG1PuvnbBBJExHidP4/RDTQFD
mqGOdtIGf3cmTwe7rFU8znvnvGJse46btpQvVfJSoZArlXNF4PxMMS++itU8
X8pbS7W1Md6PBzSyPsTGtof04gCsGC4cgnavXGaS+408Y1oikgdUINUvEBaF
chb0V65YLAI6haz4mKkWOBY1PP26tsG52myIsQWHIbwMOoNeFvP5gpSXsgOL
8yxWArtkiewybtbY5CslqZyt5MHJzOcz4mKk5QIn0LJhycDHBKKO2B6EwDRx
6J00T4MJqZ4G6zbNWcy/DfNfHaHW6xwcrP9sMpW47Apz83lx1VYH92sN4zeO
bLjC6G//YQs9NGDtCcNTYxNra6KfOTzANOUNeTaYT6jLNhj3QlvT3WNsZ+RR
CgjWyoIJNWUOnofyIBzgegxf6eo/W7DlhJ9Z1+vxdBO/yMpvEkCBZ970iBKs
NbA28W6EtZDzD4/xH2FbJwxSYayZYsMYh4ZliWzz8DoLDHtN2eoA1lH2+wQy
V0kd87Ac5olQFwMex+P5LvW6PyDgbbMRxssw12RrlyJ+7LXZGMEPyGNpD94Z
ts77xiYAdYrk8RgBP2dG0Nj3V2Hh450ByrCx6oyBRufBBL9rbqI4LeVvpPF6
31CCxsrc/Ehn+JafWBPhUTdyxc5wtdFPKrzBI6h7C+7ioUA4Ih38gsaOf+lK
EF2N4kHDbofthy4jOPj5DD5ozRashRk7FecIyLykzJc81Av7/UHOtphyDM2g
AIsfV/DjAGQgwGAhfD06YktF9zC14ego/j58f0RVnkdBessh7zWQ4Mq0Wqkp
NV4G9otT7mTOx7lVfZa7lWeZR3aa/mxLyw8BHSZESj69r6h3Tcut3ry1TXWa
zb3WlEWtn5OdZEjtA5QUqVx7njmVnNGjM1/VXL1YHT+VX8Reu60tkiG1D1BS
pAoXZ0Wt4swtw5zMVtfth2v20i2NusbjTTKk9gFKitT94Om1dfeUG50u5OZi
sRpVKw1nMmszN5MMqX2AkiJ11hwoC6PdPh3aZ4OHwn1xdcrchwdT0/LJkNoH
KClS14P6U3+ljDPnrZIyPJe9ZlWc3o8fsy9WMqT2AUqK1PPZy9nj7GnxXDDr
98bb4CHfPC8+as3Tp4SU2gcoKVJ5x8pdLNtXV4/tnrQw5xPPYg8PY1ZvT5Mh
tQ9QUqRuimeGUijPM4qkN+5z3kvnKVN9HFijVjUZUvsAJUXKzHdZ4ea6Pl9M
lsrpmak+sOsVeJ+KlZCn9gFKitSQ3b5dXs4XXW00vR2dXY+WTGlZ7Vm/kVCi
7wOUACllBH/dFZ7aakXSn16013rfrdSeV/eNyya7m3U/jdSHgBLrvmbdyte6
t43e3cqcX1aqN2eye/1iPsrjhLpvD6CkSC2Ggyen0n1WK17F6mZrU7Hszkuj
+WMrIVL7ACVFypqXR2JJeT4/L9w+i13jRSl2Jve9mthMKBL2AUqKVNa78+SG
1FiNXy4b3XyrPxDtp+Gir50lRGofoKRIzWq5ijy8lG7sdn5Q7XcHp6XyfHnd
95YJkdoHKLHuW57Xl902E3tV7bbiTa6udN0+zxt31YRqZh+gpEj1paU3u6st
Xp9Oa712vf847rUfn1319a2cDKl9gJIiNbld5IvNxdi4V7XK6PXZyI5ezoe6
OegkVDP7ACVF6q5VWp0Oprpx21terrLtx+LozWtaZuPl88LzQ0CJd99kxjq6
ypqj06JVeS1eVO6nbiZTrZ8npNQ+QEmRGitZ7SUzH1ps0huIcykj9i4dfSk/
1xOaw/sAJRaeV3mjOnottM+eZ26jcWn3TLX01lAfpYSMvg9QUqQevTNlsDo9
u653O96TMs9edUuPDWt8W79LhtQ+QIntqfu2bg6bndOJqFzfsK7XuL96XRae
5g8JXax9gJIitby/y9VLr3dX5ljRZqVa/vmq0D2761ceEyrkfYCSIiWN68r1
QixdWrPG7dtb7a2aU5udsZW7TWjk7QOUFCm3LFvDt1qulNcftIs3+96+un0q
TVtPq4TLtw9QUqSM3N2qVny8uHlbyp7CXk4HVvnazEter5MMqX2AEsup1/ar
Mhyez+WB1ToVX04bz142nxuPxIQKeR+gxC5Wo3xTkx7uL0TXurTmrZtsf1ps
GAY7Tahm9gFKitT88TI700bPhdajUpeWF4ve6KJu3inNu4RBs32AkiLVbTUf
NXNYLjz25Ivp60vtdGLUnuulayUhT+0DlBSpF6dy38lf18qrJ2Myzl4N5eea
JGezo4uEPLUPUFKkMrdvV7dvj4N7VX8q3N0Mug9dY/msm/ZLQjm1D1BSpB5y
3bZUA2dtaEgPd9fL1o02kTuK9NZPaKPvA5TYnhrIrZVuNNvWhfF6WarVlKd7
qy3al4m9mT2AkiJV6j31vFo5d27Yldf6ULqXmpW8WXnI5RJaCfsAJeap3sNo
nH26PK1euWc3pWdnJC31/JVYvUoYddkHKLFCNkaXC3G4KJ876tlQzzvyRaXS
fMtrTEmokPcAShwdXmmjVvntuiAvLHs46EmXt5Xm6d3p40PS6PAeQEmRqj8t
5t1S4a1o9ztqtpp7fp4/nxnt5ZWW0J7aBygBUt7IgD+zlWXz+bFQz1u91nT2
XJ0/9gelp4uH7P3n1+9jSElp5Unt5dNDRTkb3c+0XH1Uec0U2WQxe2ol1H77
ACVFqtcaVDMZqSiL513zsTptud27pTV9Nl4Ssvo+QImPjBYl8eohW6/e2xnx
pvZWKbFqd1kbmN2EKnkfoMSOu7kaKvJofpNtiJ3J3ah/n82WH26al5OEPvI+
QEmRso37S9YcvsjLbFHPSWZhprntzvLqZppQ0ewDlBSpxnhyprZyK2d43Tzv
3rCy8vYmukqn+5pQUu0DlJhSzxeyoqnZhXnqymeL3lDrdEZurp9pJuSpfYCS
IjWYntauGpdO/+FlLKvDwtLUX8pFdT5RElpU+wAlRer1OvdYz3Rlu9ms5nrd
YW328HDmLqv1y4SMvg9QUqSm05ebiZZfzc8GWnXxZF8vJMVuTkRDTMhT+wAl
9mdqU/XcPX/ru/lmRbqf2aPzjqmOjX42ofGyD1BSpNqeN6g2PUmq9W11eZ7r
lCfGIvvyMisndNz3AUoeNjM1azmtDQY3z535pGkWTPmh+NJ5fEtoJ+wDlBQp
7cGp16t6+elZnF31qyVHu7xrOSNdayek1D5ASZES263ru9tCfe7dPyhX1XGu
pPSWC6vaNxIy+j5ASZG6MC+eTkvD1s2VUV/eP74WHVe7cs8XipRQTu0DlJin
BsPO2eRKreVfpHHGVN6W18+L5qNbt5KGYvcASnzmsMq/3t+c3bRuy1lx6Exv
BnetTlFjuvSU8MxhD6DE9tRZzhk8Nc1RpXNTLvXnWUV6zY9yxeV5QkbfByhx
YsnDeffpSXpqSadZrTdor27ydsO4chqthHlB+wAlthLOJbPRY4vq8P5isGBX
s0p5aj49K+NiQkbfByhxiOPFe8uMOi9l9+XJUu4M7fn5UektFs12QkrtA5TY
cXjS7vPnz5d2NmOz4s20ZaweernZtcsSWgn7ACVOwXkaLw1JG7rFWV69KC2b
0tOlqmcee7OE3sw+QEmRKl6cj69m2ezT7bLVfxqKmlhbat3WW/chYSxvH6BD
v9weW6DceFjRSBcvdaibjO0eCyMATA2mhNfgZ57bScmstqw5PPl287oF+IAK
kW26SgwbkmBnBMqXfMBGC9v74/mt8b7ymhnhf9vbsRAbxWlqcMnZZ3vm+V/9
Ru3ZMHUXGwJppkeNbKJtiJwgx5m6cGABIzWUwh4azrGALYbglaOjSDvxzU6H
R0c0j6OjHXi9eEDQkcbU34S7ALJ/k5zJRLxSN/Y6tgkcrsv/MW/Woi6JkXds
rDcXNIM6CbgMayPodpO6hR0Z6ZVTeJdanVFSNd4Rf0J9tb9RzjRmM29UfEa5
Crghral+7zm/DSjwmMgXbI73E8EyZPJU5YM9DqjMqShmD1PByvt51kE7R+yZ
Q9MAjtDGJnVTczj97C194IJGcJud4L5SjQjAxtZ+eHuwTy2/MJGph79Rr0bV
7yx4dMTrJ3mqNR9vPT61z6BLV3ARsIeKZ1DWOO9+tAkbO4dhy5GfSsR8KpvK
ExnbwHtBSQj1w6FF91O7aVsBzkAa078aGZuxaObc0udBU813d4P85oOlHmyy
QLRZ4ds28BA19ZKxL/6Y8b4SWOTGb4ETrjudBk/Prrc71wP44zfKU48U++Bt
NFjFjzRep68fUFJ2pNjHT1WfwQ7FJhoqXo7kX5wXJJ2/y//envD9UTcnfvOg
FikEWWArqGHQkop6lvNM9JmNFblYk8avquVp4zxLP35zRt3vtBNeXgcQg6Zj
Qbc44itqjoNYo3wIpOCnJAYMWMMLEQSsDsRbS6gFERGAmSr2W1zns8cue+Fy
I7w8m25u8xmFWoet77EKAIWJ9XSHxJ52bY6le7y1jwBag+sAD1TSMb9OG3aM
5bctwaurqDjNRrbdcocfyVhdmzJqTbhxEQWiiTO18HolHwhMdN3x0W+khy2H
uKRnsoMtkoZMCMsthqt418+wP0pKOMW2YmwJwsNBlRepRqPKDmxmBgu0fxLw
DoygrIbAJ8H3yL5YO4C1Tn4DJ2AjxHTzssvjdTchKocJRsa2uobm4GawTZoe
6gm6lcYbuvrWFjrCKSy+QhUvca4EGfiVX3BOhPBmVIZDGwkvMw/6dnJxEWGj
YJ9iC0e/PkIYAh/jfKggjBeXdP0W0aDQQKwJPWoRfQz2ha3JBmw70HjySD4W
+p5lgMSuejb8ca/hfnd0eS40vCFbTa1j4QzrX/EzJpzJCtgeYIv0LHM8tISa
dyzUJ8wcLwG5ticH1Txt2VpgQRm8dUj8xHwaRGWMrHFh8mGfnPUFo9QxhzqO
hQzkS/7IlXLfI4WCtrfb7njb2d7HL53xO2ruawW6vtWNi7LoV+uLPv0bL32O
8q0jGj3oI/euZ1JQDkQWYfAuooYztOWZhjVNvrxaz5Fu8FCpy1i4WaNXvYbV
T9SEFSu9hT5IOs2EFXsLSR705wWBrVIbOoJOuyqoBg2H2qoxAjhUv7TGDyHY
eAs8m1NZFoLBBlKyK6+v1KJH/gW2QvxLf0h8C+9MwEtqwl50ODXPwL5zwWMq
AYTR6QaSQJPjhSlYnr3u532/ffmr/iaNvAFSoIGC3jnoW7555YSWd6SfbKQh
Lq4hNa0CfqRWrmtyIhloO/vl4vt4UV4jExHXpHU2G0hvay98/Mmuzcd7u0yD
kHXQtKdLXHW6TcwJe2oxKoYM+lyaZCHaWIQYcgyynhxciDiR6WYxbLeBDwM4
tIbOB+Jvy52kNG5o9aSEyE02SL6v2I+RLScy+gLYGF6jdTuktr8277DL2wqv
H/jtron63JwM3gn+hDeono24lPQj2nGkRKebq/aJ+xKRPkET57U84ZZFRJKO
/Euc/S22YY1wDLFsHbs8k9t5G04pbIkWmfafeBMPqmU33UbL4A/hnpkeXibT
gBX8ircnrzcP3pYggv7d+U+8bfwC/LwlrADd7OxE6zexvjLSVmOmpLDNKBh9
9K90NkPXI1zb8tiDrVN/w85UMjwpiCXhSgHdhADgb0dHj/RYQLQsPmirmm+1
BSmPLSV1RlcodzlPxl2EsZwfT8hH4GPiF+KMf0Gjg7s6lmdoF/0hZMtgeM5c
MfvR6NEC0kjvFmBYJzW2rLFfx69qKdB/IOdkKaW5aeZYtqY4VGKMQ9+CqX4s
dFwQ1XhHdV6U+PgbI9OQ1GCcLn7rmLDRNCPYgriAmu16dCl2v1bdBiGG+23n
qi/0PAO21yb+9BAEgeWKlkNEC3FtwYpiu/VjoYll9EQtMU+DMVz3cMRvQWPC
j+FSNw3QnqDgbGfHPRiHx9vm0EAFEvoID9jGs+eCHjGEr43eQ+9wFw9gtGTg
0Jtp3hgrqPs+FPzWod9aujUEYoKjodFEcZu2YPIGLB23iEBfAdt9JRbcOdRh
bGGyedAv4zWR+Jzi3wYGFZZeU9ePSNVyOi/lCsVKoVQY4GXlYnCr7mBDmQ00
c9Ake33Q6jQHDYbe9wCmMPDvC1QH/YveYNvdC5vaASj/jUi+xtJzMtkFG6be
LMtIediQRkmTy5u+q5q5sqQyTRbl7qXx0mpPuq9LS1GktrJqlqbOhS4zds5G
y6v8sFfPGu3rt8X1zfVTi2VV8/k29TbS2VPdMFzYQ9bgssdvaomVmVc7wjXX
/D10e/3tLvxF+EabQ4qyciw64O+UtOTz8r3GTBMs5CpoB5sETlYSzjzs0xqs
DxoMnw0HAlgkGyh95qQtdawOlsbk5eZRux3IF0/qq3s/b5yxZh55+XsWPlMp
5LNSZRDcWDO4bQ2ihBmE9fd8ocfUXnZQ7XAa0r0tP4VIm3PZeqlCFC6GNgCW
7qT5pyI85Nzn39girrvPonVJ94GImUxqpo62sOMKXH4vNWTp5rDQfptIxkw6
/c39NS+VK3zq4ZwF7EGJnbLhP2azldAGAy5CB22qrRFmZgxn7FQpg1o36b8Q
xg7qZKLUQfK0gy+DG9GTjvjLRvMwugKhVBA33B/shYDUQdz+K5Pa3G8hW/28
bfeOZt+97+4rtfPns0GjNX2+VnXzpSbfsZXuTYavN/+gfde23Ntm/YfQSaps
0unHbL2J5dojRcR2RbIoFXY2+jRV0W9EEuskmcns3ZSN9sOt9rI8dyzYlLls
ubBtUxIXfkCYkFudNGEdMu9nqfX33ok/aHWC0WmB1G2DbXSC/WBFWrevK7vR
OR2fLmBFpFw+c+jbltetf2o+1dhs7HNpZivRk9FhXH4deFJl/vg2RXWRz+R9
zkRD0plYszgBor3AHFNWJq6ogujADn0qw5vYxjYYrn47TNl0NHhjV4c1qVDA
fQDEbnAQQk/RyFe6pLvQ4wb5x6MzvgkCYCBSi7AEeIdFuAQbauHnTIjId+W5
8HRjDhY9FFUVYW/gWoji+g7V2Je0cacutqvC3o9+43hs+LavEyDI5bhQk7mQ
FmWweini5KR95Heovq2OEvdisaGWtxxRL2qKyyEv72reRWBgrK/rSxiGK+EM
lgE8DfSbyReVTe5eYfvlY+GuV0Uq5UTwHuKEwqOszZZWH2gzqVwAF6I86GFc
Cnwr7Y1+GVijmGuwnRph9LMehnTfedvRmSvhF74vBAxfxy56wqVMAZk1gZsh
/eLTUUxlhC0X435ULiNUZ7am7xExn6JFvpKvZAe3yEs4feQldJ022kwNqnvd
ofduUM6dPE+cW02sPZ9diK3XF3PRepuUNHOou955R5/dv7x29YdZ8eFW7faf
i8Xn8kwsP73IMrsaDSePqbrVLj7VvKl87smZ8dTFkDs/h9QMxMSYCZnMSbZ0
ksnw+6E7Tbz3AXUa3VRDd1H8JQiPEKmCU+otsmUzOCLj+7hh8H0x9P27eLkP
OL3HQl02ZVUWvs75guCPUim2It+3IFkpVyxKmUEfO4ShpeW/Pjg1YSjLxJDX
oH97OriaMXPQ88BJ3Cfgz+2KtZxJI9XMoKLLlHP4Nr/wYRcFwqunZPsdFURf
Q4kcRCAyLmF/9lYGbEYNA9EmmnxC35phoMAP7wbS3RpFuuLBaz0LdtpG9MVy
xLlFuFCn8DRYZ/BsYwNIxU1yb4m37IBEC8rjKtuslMhnXDamRxr2vOaNtPP0
70xeKg44/v+SzfxLtiz9S7aywz37DBqckNenfbF+dcn7sUknglTAsB5vgimc
Bk0w/Ys+8HwEeXrOw6Dr8UbgPjI3NdZQX2B42YQNA/sOLYsCRv22d9UkgLwr
uslTYP4QzmVbd2xvAiLX73pIpBd/CLOj9ClkshSnAS+i6h/VvJPEx98r57Ol
XPkj6AOQce90AUhAYNoB2oH+yrT63SYPc54IVdNEHgwcQP947qElfOFjwS/U
hBl5P2D2L2vcx64xothnyuGbwkGNQezhmxy/4a0RvzJagQvvTezhsRv805sz
z44GHvMiEL8r2/9VLVDIlaRCMi3A3eTmbdRgLnxoMPPbqnsTZr7B/+NBKzaz
jInRygcT+sByLmyznMGjG9lBI/3AZNpvG3dG5+PhVSl/4eZBdBYzhfzWKNLn
pvyVRv5w6qWfMnWKK4UNoIMD0Q+mP3ksgYV4Or0soYtULBX92WPkw3gX+fgh
C/9f5+RMLl/K50q53ZGKICZBl6j+nfH/vtWjy1f95u7h2lmjdQtppmK/5v2r
efY2upgNzYmeqWIIQpJKO0IzP4QQhZ9CiFiMxidIePy+znTif+32hPYT6sq9
skqX1lhzkO1zBSnwiAP6fF+sprARq9lLvrz4joLfF7cpROI2P9pb/I7ozq51
3YjuJMJ0/2oWs9VC+bUtVbodWM1stpQJvLr3B+kR/bzzpsQNCzQjNNlwD59/
eLe9Dz6wqh08CBxisNeMkCrIeaKUJ57xxDW1r6hb4AiQRZqV+PnAv70jCDIo
EWXIj2MXsqtMfpv/qqmvi2Fm0tQnzn/DzIBfry+M0fTuTMlVvO7k2blsGbOl
+NoQvbp1s+qO9c7sv6EbUZSc6LbYdhr7Sa7Q+FfcubBlF9SSlHb49WRp/DtO
8soHFE8+1juW3PaWL3SIM9fWw0eHMeO726eipN5r1xRlBNV0KOwLsUQMeMtR
mbE+H3YwX9XTWZrmtiO0AoJFZXMQiAae4H5rXvUap90N12oTMFK3Bq6mw3Tn
WKgxfYwO3B9CThLOZFOUNsj93sPaiSn3o1vtVrPWDXWVC2TeJjg2ofjJEURq
yiN3tkHiUNLZIuj8LHfKshlpUMx4FZYxd6wO/ZnaHNBTi1mpsGWQlDyXUgs2
NH6k4MiWkLr/cMHBjSQwioh0Ura0Q3qEDH2dybsXZ0pvOer+9nlxkc/lf6jU
zf1TEM8nmpT7iGhKz64/X66s0mCcgGgUqvmRVCsKDaYQ1QofUW3zeuDEdKrx
M+zB+vJVpFZBykrFj6i1GHTtly5rr67LCahVqPxQYmU/T6sfzGEU1QsLpXyq
ZbIfUU0qyq1n0XrW1CQ8lq1kyR7664ngaq7Ofv0SzRUNEhPZOmc0loWZIE/z
y58HPCGv6ucPhul4YX4h3lJKefawtz3ZXq2TRcMsSl5P4efd/lOkhVKOPC90
wTzY4MaB8PLwSNq3Zfv59jy10uKlbQLdLG1iuQTwavxK8U060w0FsxmWXGEJ
y8zGAqxY1jQOwi9nH7Ewa1yzsazMxguJf8ElIItth+tyeCAIeGUkRjgeIvvm
M40Hc+xm2Xy5aZ5dKExmRT0/uBw/mobTeArAkpX4ebBoeqWL4+HrMvP4VH54
stu57jI/vyqbWdE7H4dg8W6Nz0NFu6Gsr17bk8qqNLiYF4eS9jiZ3b0+2bNM
NxMApfDA56Gij57uW3NXLy3G87fF2UM/28k+L8yJ1bkyn25CylarnyerLI/T
L7Xn+2npadVbzOTm60qtjpYPudz08vk6nP81GmS8FiNWGIJy4LNjzQIYYqy4
JK0WCw/Xcj3zMHy+XSz7NUU3+9NRqWdQ50YcnnI9suQe8tzib+7EZrIqfXZo
eQ0g7Q3fSt5j3RHFpzev97B6vLx0jIfRwO3dYFoibAAfevZ7oC/bk5dqJT96
Y2rx6rIzv74dL/p98eHWqAa0bPS69USEUw1HSd/Us7LaUZ6mS62vm9qpopTG
42m5WKuGi7QlaLAf8DpccN2xz7JXg5tX5fKuanY75uB+ks12jIeuEkCP5v/8
+JyhUHDcvhMcdkxw3DW7t62TxBzAW1o9P5xnvG63kr1SF/r1cPxYm99UZ40Z
K3zv2vtwbye3JUtq2w/LUasxGt+edW+LhdvatHHqo00x7KRIU6P4y+Gy3VlU
2oPlrPc0HI+uBmZJv+802YPznTh/ov88Z9TO5e2nJQnYYulB+eI0d+tJy0ep
OBm3zhb2qtu/XdxacnW9wmC27DrF9n1MOofmGz9uZG1bdtxIeMveDjjjdETV
pl08LUxLUimbKUm53C7yJYLpX62TzoEHQkj3q/XvQhQs/jWClVxWqnw/ghFY
2UymWC4XMuECXNWv4zsMqxH59yyy0eC18FwJ5uNPMzIhS5mJsq7zi5YdPi58
JAYfxSZTkoroJ/tQsomhUHhusD4kwjQkPrcKXva1Bp37YaDz5VwZI7O0BD70
/A+DXsjmi7kCLEpnJICJTUVNkRJWLMaay6DvcNfhMQjpPar6BpvVL5rlxiov
OuPlK37NFRljx8KMl+noDKv+aQQq1xI61cvqu6LKfqzGF6/6Mi3+Jq+Dw5LM
A6xCGYLWQChVJSjEouAJmNsm1aQw9dcvI/A9GFjk8Xd4ZTaWG5kM6/VkG2tb
sQB1FS8q7PBLsbSgL0LUGB/xBA0svmNMRWRohbAa0KOIHs5+5OlUuWhQLaBf
eP2uVNW/Ko2XLqq8QnyGxRVk4wZ1x6mANn4RMpX8O7ygLvBf6F5jXu7Pj44E
uvpsfTMb1lxFCosFJ3KZF78SkHpLOJuXeZ1Qdd9CcyZ+KRtdwoeOgF8RRYY6
UzQuJH0/aV016ZvrWugZ+OV0WD/muOt+Fj3wElfCObKDLFxppgzPGrbsTC3/
X3NNOTg4Otp2M9zRkbDryjiOPTEr1kRz/LB+C3FQLDHiYRHpdwKKTGQu6x45
Ypj2ZGtDXrlNs3hfhAsP31fhElbUGmEM80VmQQYMWZVtoaFm0n2uyFdrTuP+
0oTpM3welDpb5s5ZEJKntqZgZwHgPB3JfOZNLKEJVPjb/2vCn4DpFHbrraeu
+F/RomN4UrM92Jg1cJdhqi4unQtMKJzjPYY2/Nl/kTHfrw18wr8HrSD0J5bh
WAj+CXxFmNOZJptj+PMavF9duNSmlmnBVoEndRAZK+FB0/n7VdMyVwY2FolW
YQXV6DaO0YAFtYQuWAewh4hRYFLWxMSLOr2//d+Ag+s6HFoNJCMwWFvWGbbS
YFQL3nNlb4gTCUqjsY/Dug5aeP8/RDNWPB2S4cLDJT/3wKOVV0J1YoDsO//b
f/zt//nbf0zhh44hYw7oxLaUKY04m2iYNjQxNDamqcxXqnA1lTUir0kMVEXZ
KwPnPViWCgDgUetv/5+NkBgsg8rJDtKgJ7vEcPLUG/KVwzo911o4U229Fk0s
TAUemBD5gYNBgjXoQnNEgA1BMls6W9FuC26SrNsaSCy+0Roi/yvR7uJtXajM
316t99oa1uc22Ht2jBTB/5xtFUh5Gr9jmZ4LrDYBi4fJ2ze3SNwOODV53GXL
lmtjXxFH6DvKxBoxU8Olf5JttDInbDSiBb2QPV5WeQH6Zgi8jRzb0mxNnYD8
7gKKK9kgRgQKgq5HrQ3L6RKfn1mmTN0e2tYKWQQe3eL9vLYq1GRgegdX12Yj
0Ay0qPw//RXdVuv6TqIL60xYXtgb3jNJ3WhIV2Uz+N8Yu5BSOT9HTuNNjCJj
hlYFRcKoQ0B4V3EwRNBaIegFEuqNc+DpCfDeCuZag/mN5blsbpNSlyAcDOHc
GjINFhmn32IYegLtsb5HmWwfJ6gNxCDSsYAe4TEWJfMwGU+15M04Avbk2b28
7J9IFBgGWD1BoEg/p4SqsL1SeQ2K+kY4wje8sPYfkEf/ywyMzF+l0iEYHVvb
UCByI6x4pynzbLmwTU0ku1f4+qXBPBdPyki3KBPPHDt4Ca3mp6Knvhwe/P/L
rOFNt+4AAA==

-->

</rfc>
