<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-16" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-16"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="August" day="29"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 123?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 127?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs and finders</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">3 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">2</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of <em>paper</em> authors):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>?</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, and Haowen Song) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">TBA Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 650?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-authors of paper <xref target="Intra-handshake.fail"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8292XLrSJIo+K6vgJ20vn2kEUiCO9WWk8VFXCRRG6n12DUm
CARJiFgoLFxUmW33Zd7mB8bsXpvHsfmBeeq3+pP+knH3AECAIinh9DlVVdad
mQIBDw8PD9/C3UMUxQNXc3V2InzpmK4tixPZVJ2JPGXCV3kqC6eyra8Oharr
MseVXc0yhbplOprKbKYKbdk2Rp4ufK3fn4rZTLYo5nLFSkmwRkL9vtcTSqmC
APAEh82ZLeuC5U6YDT+dOviKNxNcS2DLGVNcAEZfVFJleK5YhmaOD78cyMOh
zeZbkNuP0JcDRXbZ2LJXJ4JmjqyDA9VSTNmAaaq2PHJFLQ5OHMmaLkrFA8cb
GprjAFR3NYO3O6f9piD8Isi6YwEWmqmyGYN/mO6XY+ELUzXXsjVZxz861Rr8
y7Lhv277zS8HpmcMmX1yoAImJwcK4MhMx3NOhBEAYwcwqdwBALaZfCJUb0+r
BwvLno5ty5udCL3Tav9gylbwSD05EESh2hHkMYzq4B+btJDXtMCf42txMGem
Bwj8Igg+8IcW/sHn9wBjAqWFFv6Ejw0gBL7yF7aUjZnOUrAU+Fy2lcmJMHHd
mXOSTkd+TAM4AK25E28IFDK8iWwYsip6jmzIoiPbqmynt5H7C3ymy4g5fBYA
3vp5ikNPadZWQOndS5qauAYMdCB77sSykZIwqCAAh+icG750/QGFOxxQ6NGA
X+gtyx7LpvZGdD0R+ndCw2YOLP2x0GK2IZsreotxioUTHxDmKY75X1xPVPlX
KZV92TL+vSYrE+bo8lxoeEO2mlrbBq9bNntg8pzFhsSv5L+o/DNci20D9Cxz
PLSEmrcNbg/INZ7ImtDyZFOomsBaIwvmRtuqz5SJaenWeAXjp46FC1eFf9Yn
minH0BjqHlOtsQlj/mWMz3ahUp8wc7zUTKENo4234dNZ76/YELJnI4fbH4/R
lq0FMwWc9U+b8ATIbkrZTCFTyOf3o3Mur0CG2ooG427FZ6G5yiQGfQqfpBj/
5C8O/Z5SJtuAd4AJhZ4ysS1lug34abdz0akK17blWoqlH8NklVRsLJfJxl+Y
oemaPPPfSskabBiTE2UOgkPYlDcp3FknBGeH6qA3NpXC4YnQ1sYTkXSB5q5Q
ToFw9iU5yO7+RY/PgiSmcOaZTMDPj/lQsj1m7loELRaLFDAFQ8E0hg9SJnPT
M2+oawpNP53PlLNSRSpnBxvYIXKDOG6DGGb440AzBwFmA8CMcAjFCP1PBOxB
nHdTwl3KFxzxX+5TwZ6OPz8T4ZszWXn1mLuDvKLNZtbfg8b6ag+NfbmLUv5T
cp1w+omUik/Whx4fivbACb7JH/jUq1t1q+crSk4GQXOEuaebYJcMdYaGiM10
eYXvyMoUftNkME1gemSbsNmEGWTC4KegmR0f/BauVOYsBUikAYdbpoAG/01T
f91QysJ6DbJFoYtMTOsAP5ze3Tf4q1IxXy7vm+XpZadX/YfMk3lzNcVMzQFR
5dnWDP+Vpr/TG/jvm2qr3auKdZA6jljtxLn9x08kyvfZXByRvazv6QB0rlk6
c20nrSC6aYcpHm6wtKzONQdsQOakaTbz0XgsGvPlUjTG49LuvXC3BioQBcDE
Cyhyqo6ZzhxH7K1g8oYTp8wtMyw3ZvQhZcCyVNjM1baRJjrzqjf2HPdT82Y+
Gs4KZ4073XF3T3zyMlbEF6UwF0eL0mT3xIPJCf7k4Fe0dsVgaUEXuSsSf7a7
OXGcU9Vfbs18ZwdHfQLQ6ugXjDS0JcBCF6poPmsKWtL+yFGySBKIGXOPKESF
iRwDKjGlMXdEOxwfpA1nDFSR3fQyx26WzZeb5tmFwmRW1PODy/GjaTiNp/Qn
heKBFpgjvuZtiHVbczR4r3HVSUmZlCTlC+lcqVTJZsqpXKlcyJVL0Re3KQ4i
ASoDegMpF6NM3TJmngtewInQxMGBVqasr/BVcNJ2qY5La87QwUGaFT5UH/V6
XYwsT5pmqYsOuH6ipooKYfY9mgN+6VrA0fJIjv/QTwGv2/jQZiPAPULBTCXd
u05lM1IpRbugIzZSI8txADURV1Jk6PSKkR128qm3xEx+80VXd+JvFD98o/LR
G1ImeAM24hvHZQRSD+REKpU6OBBFUZCHDknCg4P+hHGfV5A1w0HZAJbeHBZf
cNHcBWtJF1TmAnvTcn+LK6r//jWhZjskf//bhhJYg/m84jg8FhYTDWQ0STeY
j8zZdY02w2mYCkO8J9ZCODoie+ToaLtvLIxoksD+MySNprBjAAHOwhEY2RPL
c4XZBLgeIcuKAiLqCHnLZsDo9rHgaDgSykHN9IDjNgUwiBdUN2BP2ezV02ym
Hn+IkKyqDrzkmSbD8WR7BQOgY72E7XoEw+PigZELGsjBSIEwBNEHW3G4Elz+
C5m/wl//us04/PNPWgt8U7ZdjVhkx6skNeB9oA3ixkRrJMJ3Inwn8K0KoHyZ
4FroSoBTcQ8m5uhY8MBds4XqDP1YMZvKCGCBM9NhJIIBrm2pnqJxuX5MGIH/
BFNhQHmYjmktdNQ0kVnpDPwrFzGZsomlA3jHZ2tDU1WdHRz8QrIfAVPQY+f8
Z0giE4kXrI8gzwAjwBV3As3pjdGw2u6gCu6YmeXIunMM2I1BCpECA65bTBhF
tOAfK1og5CQgIgJ0FGtGrInqTVAmQEt4E2hiWm5KaNqWAVgF6lSYwSQxDgaC
/1iwTPoQoYDlAttT0RzOwIpr2Q6yG/6mALIaSmNhqMF/mWPBgL0BDqBjgLC0
jC3PnSiW2zHEFaI4HX+XsO3HeAgfw+f7WSkJW9CYYLvB7/4TWO8q7Ay+GwxY
QtgbR0fCTAY64cCBuouuMa1ioOuUUNfB7yINsGeF+Qw3OR3+Dzx90PtoVPEJ
x9TsD5mlyWOisZn68wSGB+6w4RlIFT7SOj6Jv8JLiDOyNypNyxtP3k3C5yOV
OdrYFKwZTpfoso8csMN+Ea5A7s01tkAdAoC4EolR2x8LGVcb+X43zXJz9D2c
6hCpgsf78aJXURGAGaD6YQ56FvMTgkgG6MODP8BOSQl/CLXNYeHZncOQKeC/
qiFr/wFfSPhBXddgmv/5P/4vh2CaFkr/P4RvXVCV/4rG+lqlyVrKgKdk5xCi
CnCHY3m2wtIzW5ujPAWcUMIDCmKov0RQby6jpT5E0EgDZktrwN/lfqddmzE0
V820D/CQZpXdmFWUrMHsxDUa2R+NRpajkUM06FABA/8WSZzYwLkfPXCOD5zH
gXvA0cym+fNQEcnX2Pj5Hz1+no9fIPpbBjzkRIet8UuWdssvuTgKhR+NQoGj
UNyDQh6H3/TN0E8gt28rQps2vcEYehFOeqhbQz48eDIMz0ecNLjbU8+59dRV
KvAlwagFy1ZRlKh1m5qpo8N/AzPU94njBqhjOqLm2mDvF8eEw2ImIjhg6rQ3
0y1ZddLoj6SlbPqB4TxtsYpem4uqFTZfH78V61eXzU7j9LLfqV4UW/6QMGa9
HvMhe53WZyZ+CPJAVkGygjiBff4CQwnf9kixrTA3yJAOJBpZ/zNLiUiI4o9m
jyJnj9JW9jgG9jxe8wjowL3uDejEENHSj0a0hIj+9YR7tr9+eSfUwT7TQjXK
FR0iHtiqaxPmy58HB//+7/9+8MBCb0gOtBk8gInD/4EbGVhn8BeY9tyUHoI/
sFZoB1sUGn27W4l5qAYQ1sE7Wxtt6wi6puqbnoieobnaeK3y8HtVAxNuTgef
IarROIrGnJRw5aHOhI0H9sicwV6ET2VX0FzBkFcHYH6AKS7AGE4QOwJbRoM3
4SPbAkTBYA5i6iJMagSKXvgKJjrThdxhOH0+qX3TlnUwa9HQArMAyIejggbQ
Ldib6gE3lyIxK3T+YGJAA/8J6AkDQKKto5AWIydt5uIbgSN4MOJWtaqNRgzt
JvgEJoPD9ixuiPBPYXx/4o5ns5AgIErAE3OdA6CCBtYAGk2cuKg2UsQyB8g0
oN9neOg8BDWGi6BbaEvgALEw1kfmDDrqDlrY3BD5619jAVH0xxzHg9/gPZfj
D+6qCh5A4Bpz35B/DZ/HXXH4PnIOz226rqUyHVfqiqzOYAd1Q+blAYO4rQ/u
LFhuI3RLkUVwrQxLjVt8OCmEBCOuqb9v7lv2DTiADu7fFfoi5hh/Ra6CIX8H
GeHKv4NdbMtgawHmvpNV91kBMOC6XfAtLeT8JvmOwjd5PEa3zWU/Th6FIA8p
JACPHJIQvkepRveuum2uO/0nWDVYawf0MKgRjGkDjkYwR8/0/0r5Czji7nGA
BHmOgTm+xSskHqBwK5lgUS0WjRTFhfz2YBdxJ20+7tFwfYFrghJVxp0RidZ/
RezR7YQBFubh1nHex7lgDPzG9zV03VqQ5FxYmKZgci4BieDv+kB+rz1pcADA
mK+R7hAmsNUo6ODNUHCrB2ARX1tgDezw+VEeh9/IqgrryKVUFElONd9LE7iW
8tf2MxRULUb7H92qOUKIH2nI5Gaht41vgT8MaPrC3mYu+MP+LuDjwup+NB+Q
+NuHOhaGnouwOMCjI5iwht8BQaMhqY90GyDqmS9gYwEDMhX5TajbmCbjoC+G
4g2Dh2AiNAllcrhEUaT/P/hjmwj7Q9iaonEsvM+c4GbKGZNNEcxNjQUnhwIH
vRFf/KGwNwX3D4a8eSK0ewT6ql+r7vydRGWQExJ5e/0M39gFe218IV5OmlK5
8IMRX080rH4BHW8Dx3NlQxvE5Q8MfIA8goofdjBXXD2mpMA3kZC39kYy6cW8
/9o6AgRcBmM2KIYNEO9jGrjBtTNq+b5moO5j3Cbk7l91HYA0KKwBOqgK6ovO
EO+5skXOPaUt84fQwBhGnGfRvtJMjWLTa7uABXYB2ReWr7gBQqYkXCnuMR2b
EPk3UEAMwpelPMxLibwcTVfxTYJvmKO21mz7D6ps2XXSxfHwdZl5fCo/PNnt
XHeZn1+VzazonY+f0uhn8MMwGrVIo37zqYVWE6ggwjPimLFhKhgRB4O/0Qkr
ZrLZklTMFAr5dNSHixynpmxyFsdplzHu6GC4RFkBFlEqZEtCkw0j+ATOIXfi
nQms1fstKHw7OuoFeRC/Cu1Oq43pEmQNlQ+Pjv47QvbPgaOwQTxtEUPrkfbB
LQRwi+/g0ll9BAxKo61C6Tvhf1vzUXx5IqbONZIXj3PRCwanHEPtMphKaVce
81AV/CjOM6lySqIlCD7gmo8+2kacT2BcoVyT78V3bO3GtZCSxLElpbJFGOwd
0mPrOxGWMu8wxvhA3L/8TldeZYpOivzbnoSGT8VcNmGnZ56upwtl2salzRnc
r0fbMhmMV1vfOSN//6vIm9k9wyay+8hWxBXlZ8JgLAi4YzegvwtavRMKW7Tn
HgbIB3tsg2XXqi9UNXFnLyrwo6pG3tAxqCOPji6ZFhwdkV2EFh7/CyUQGp6y
iUc/PB1SWYHHB7LbQqQFi1tpyjrvOaZgyWb+/YHJ07bsTH4/5v/daP9O6cm/
12T1lC/77ymw6Pp4doXHbEIku5nb8uC8HAtaiqWOfZg9CgkQVJqa/wBA85mC
BzS2LFVguq9O/ZMmmecekz14eufnLR2c4gEw2D3CnQnr/q+O8I1++OCweGIZ
bCaPwfNCIkVwBo8juvTvJSvNIcxLp0hHuDIw20h+UXA6g+YrWL9gljlAc/qe
+1338SjL7pwK4QJ8Z9C6wBXIQb+A6S4qc+BFR7HAWhCAF0JGBASGMvqLMNY3
oEQfPDfX1pSIKDCBIEAPNzW25mnEVvRfSSPQw9RBZLtxruQa7Q8+bxBiwWif
hhk1dyJmz7eFBj6IPCMDLWIMRJ6mR7BLnPARhlkFPJAhjL5+A0uP6fH4roaP
uMjxo7rwNO05aWaGmUeiAs+ZnY4aI2n6UAxfif6GPFAAoSJmy2ImI1FKuJ+l
UO024uPLhspTn8x0cITjpPkhnhtCTw9BxmKoOw2vi85QzGXymRDsemAkHYX1
L9ErJ5r1T0836AWWT5RWdBq0Qal3QBqPqrWI6B5VT8mKQbaXamnpMEuoWCgX
8/kU6LxMNpehCPLfkeZ5pHkmSnM8hAIzVriwFnwmPVfWmRdh76Uii776iyT9
O/y14N8DzwGZsAR979MpyFkpiIV8IVP5fM6K/wHCyKcy6DKBq+oZHLkaSNRp
s9rrf4TeEF8cYXJc+F8DS57qwGLbcCxKlVI2CY74wSFimN3EUFZvq901qKEM
GtNAGen/F479xw9kc6nAVxJPs3J/R3JJScklEYqVDRSb8hDE2pSpH6E4Cl5c
/9d+ppMyn8AQHkY+2IrhNuc3DvnvmPJ+KOwIyJRoF+P3MbNoU1PyxIb5e02p
RDWlEmpKPdSUaCFRXG0N0Y8t8tOXtSI/OgJkwIhBU39n7ADDoFgP5p98bCYV
Y/zNoHGFFXP9QdGmsoIsKzfMY9iOuYMMxOM4eLgR5mxE8ngWDA8vXJikyZNX
8SGwhkMmKRlGmGtGtXEHB03P9sO78WQOtHj0NWrrmOjMcgPLAyMySI59Ybqv
m3kla9v1kLImfGshNE1A/1A5Gz9ROHU2jQL4BCv3/sAcU5dS6MD/EPhjKf44
B6MjGW2D53ypeJRkYdSWH0OWU6WQu3wYUYYTsv6j/OajYkwm0cM1c56uqww/
QZ9Nogg+R+JBnI0RbrDuDTxdXgl47mEQcwFpuFF3TCw10jB4KjuYd4MxW/wp
xa1thAGfgbXMB7IZ5tkQE0R8pU78KPPgoArsAz6wu7H27448bRYJvcNyij8t
beVkm4DAbbDN/P7I6UY83x/770/EJwwSR36OfzTayRIntiXWryfyHd4qUe6f
OXnh5O8S8sAVPDoKQhFHR0CWMBbEg1cnPyFMhrkB/Ijc97goPp045ITIajZH
dmwlRPTz8bEfhe1BZySsLI+EjbzAfyJkc+Vr/b1nRDF5dSzMCHEBK2E8R8BJ
C47FVfWCMi0EZcKUKS3vtoP3d+fuaGZwDWlsytSgFlLoRXMWnV2iNUgljKc4
8rDG3jkezWR3crQhihGpzwseEtwfpNtU4DXBWRlDC8PzWzJX/u0zsbajozDa
BqaUPHJZGIh6h8Kuo8wIGjifr6QfwCdUxRkzRQprHPoWk+yfK25LtPlq2doY
FSeuL5pPqKnFTJ6Hl5BxMQNER/6w4Hnx8AALPqqYFUJJzA8tOujUFG2GKeQz
C51UVbA8N+QzTLfg3DUEXk2iCYJDdpmsOL6am7qHAK9TAiJv7qxyevcVhQRz
lD7AbCSKMkoBAAodWbYNuxko8Oefh/wzd52cGx4n41I5o1WKqEOZ4HHCYEUF
lThgNfEqTFTemsOCWRlYfqG53NglmxjsLleYy7pH+z5Izwgy3/kptW+88pjk
/mRxmkjEsIUl4bhXTcEvicLDNRk8AbJ4fEs+OG/nkz46UjUb9JeO59TwnOLR
PDcA5NKOw/OAdny4o6O7HbUYOIjmOkwfRbP2FUyctc1wl2wU5Hy0O2lMNGjI
fowuOaZyeHZo+NOL28tE9iMG0i/I8blAO9vBhIhGW4jRQvj6+3i5+v0QxC9m
rjgbvw6Zu8AcCGWda8MTojCDoh2KvyA3DDNqv/4+cR0lgIh7mJmKvZoFaYVr
oWnghMbMOcilhOo602wDGkjmPdAiGWpYnCYfHFzzre4wFpwuZ/eeLiNMvwiK
NEYvoOM1XxCUOl/rsPfAWqFhWrgFD9cR3XBbCn9iflgQmScX009MArreVvu9
oKDOjpQ3uasZOUc7feMUJbJEEYDZnAblTxjJxkXt8WXr+Yvakg5xhfZ8FUkH
X69j36f8OVK+lT3ElfkcjOj6xaHkDretSS7RmnRR9N7yYihUjdVoutW2Qhe/
9gnXhqwGdZuz9EE+y3sFHjNYU4DHRjL7hOkzJ8yh5HmSUoAfvo/5AmFm2Loe
Ydt32eh3HZ6+sydh00/K/CjrkBIxhaDmLZLoA76qZ/ACETpIuA6k0d7//bHO
HhR+kY6zx/njYvxh7rhwjD799ftZo99+Ior7R4gN5r8d/Ef4b0wvkoSTfaxK
Ug6++M//9X/6wP7zf/4f8f9AKNkPoEyVyQYU/l9xKLkPofwu7IDi/0ckekG8
7xcCYihicy+VUhLxe1MbY7Si8NmNRdIzYGXMDQzDJOFG219DE6mcWX8bVCxu
PzjaW17zs2pg0j+1wiatW+OUu3Q/X2nz06psohP9CdBjE91ey/PT6niiU/sJ
0GNT21st9NMqhaIz/AnQYzP8qB7pp9UiRSf5E6DHJvlhxdPPqqhJ/9R6nfgk
P1W389NKcqIz/QnQYzMtp6JWBAwbFGb/uHEDiHxaPxF+ZGJbTikiuv4XOggI
Q0+wuE2uiB3S2Lt+JDVP7Qv9wAiYkA9Ydq+TrTjbnSlO9uExRggm6LR84+31
4gGg5UyOhCTR6cJ2E1Nmr3NOVUtJ7/o0fXhMgb1NyzVi7vajDQ4cbww+ouu7
/eDkoyM6WQ1tTV0X5+O5UmwT7DWCsT5jJw0OP5vAz0NFW11/stbBut7T4OEj
JKM2OlZimau1hz9kJhtp8ePKf/SippDD/KYB8ajw0dG604HvVcD0aTXfLWOU
MeiNj6YVlHP5HyH3VLF4y4AtATNw+TkjxlMiMUr/RJXXra27WfgFLFujvj+A
J2xGlStxlzIegCQiUosMinNiNQ3F5eTP1eWImXwMhw/R9eNPPHIXLBL8YdnM
CE+q45FbCumlPil+Lqrnp1z89DQDc9NxSjBzLJRUYDh6czvJhW86dvK05U9z
JT4S/Y/Sh59FEV0QwvDjcPv7LmTvA8h4yiubU4qtco4KElhpWdeprR/H5pGX
tzT8OuJ5lUcEfL0zEDcGMkbFuijb8pygbQ2giewfZjseY7UjtmdYJyhMtPEE
ExTonFqNZFJ+TwKH8BVdUz9kvc52/PNPXBKsomxpc7/UCMfl/TkUP0dg3b1w
Y+hjPA8C4U8lcOqBH/1mkQwCgoM7DAPp+PcHArZ71+sfePaYp0IYmFuyV4z6
JaAfMRX1GsvSPw/2NnrZhxsF8w3MCVHBvKAMVZla0VAtu18FHPYFphBZP2yN
xFOUuYXQtywdg5IeRgw2K45DiRgiGGv0I3wLRON6C2qMUeGujQUmjAU70KOk
wEoZNkEhdxjUKG9s6HWJIG/REa9K5Vk/sXMDQJofiHwbaUvkRiCfD0jVgj/k
dU+4pEfXn2pMFrHfQFSIchpwOeRHCxZF8xgIUc8RsIOzX7SHlLZdnpoDOCFb
jYBGuOU2ivw+iNYFpxQIO0X0sX0xzMJzkEUk4ox13cg0QDjszI21pNgbi6QQ
FTGGpzYElvIPtKEXrSjCDeaZ/tlPWK3+T7gCPqnxdBGz7Y+RNDynHnYKTjtA
HQx0tgVbWsFYLdlxGDaO1NZTuvJ7MX+Iddk8hs952ueCcAMplqerQS4QVXH7
jcf48ebaPnE2lyfFW+4YQbW2MrE0EOO8AB6NPh00OV976mAWVslumSMu2jEX
s6FgjXPggvDkCUm+gfJhf6BLC5sABho9KEX7p+OQ7XuUFAmXLyYo2uveOT+h
XqvSFJfbMd44OTj437FD4npZ0G6QUrnj2AYMYUSy+RvaaKQxsc10HXs2I18J
fv3HCGsHQehpTFcdrM+Ad7QZdqoEeTxn1HLMb7rED+e+ntYPG+1Tv5MC1gww
RUbZvuC2t2fGLG8euQJ+W7ey2hDJ9mYdEA8Kr3Mkibu2EAml98NEQ0Hk+kw0
BNtf4wYHp++Wz7hJ9F6KhYc1fsR8tj57w/4VGq8WDYUhKEjaW4Frpa1b7wE+
IYvG2xmEq8S7UjlEJsc/oPOw/tkN6WKi9QYED8494z+j9TTz7WFAy2eFFCbt
Kzq1WsRFMGSVklbBiQv6fIHpNPb47H31tz5kPIicN+7rEICgg45h1DCMt3WM
fxqpkOWnBOV3pbMCLjoiQrwNNgIzZhPZ0d6iGRKRPUwZOLEKdWQ0G4zbMT9B
IuHpcXmGdfq4UE4MXWpwxue9NlfiJSu3lBZxsP45npDAsybi3dm4c7SVWCk8
OcOXqV2If4AcyZrGb097V7edeo9KvQi3XzYrfA7Cc5Z9Ryux7mjv+2vSRgpa
c/o0xJNuhYWd0jbbt3BkumHvlwCP/efZH+CxtsL887gQPF+Y8FTnoBprBPIJ
eu9sjHfBG+Pxo1ymarJQRzEI1mt4im6yxbogCi1Aeg2wHDFqeYfBAeQwLBke
s8CdCrT0jiww32DeMGxIL3DnyTY+8BJSlEGLcuSWjTU8uo+n5FOLBv4DT6YN
CiiQm9KZUjqTT0c9JjH0mByRelmJ4YmaqDni0LamzCQDHVSYaMgrEcScyJYw
QrqQLRYzheIhYPT1TJ7JJqzzofCtpgMntWX3EijYt6arSBnnEH+CvYzETbn4
W9rPkHTSklSpSAUCFtBcB9fRw4QMgNomN9u0omp5Ej6jucaSMRcyOHrejHhK
dC1xyGgWOvb64hMFQYi9+1aiBq66Y2IUiVQ5SLGJpcLXYLOJ8P+I0jdMJ8BA
parEEmn9B04K0z74FSRsHDxNiFBaU6VipVyQSsV87jftVymTyZRKxWI2ly0T
kb9FC+7DrBAkc6TiHhvSwI7D9adi+ygK8YQvvwTENyHThz5jXbKl22ImCrwO
10+RAjFQOvAzOnkMexnRzzTrmac7LB16zSNdXohrq1XUTHE718WCDKEnRrg0
YAevgmneUlZ6NPQCPwbM7aesIx7rEqL49MQYIUhvcCQnmgtrg+WssIQi5XGL
ssap0avjnTS6Gt9ijrLAhzTc0NbYaOeGsilYsnWKtJVQZIgj5EJSRZxsNHJG
Em482XQ9I7p5rLGTotpVtKlweVPeNJ2RRP9VsWMquESRe2dQcYoK/CpOGZuJ
OFfAwNAcBnNe7VgTh1PG72hDXIqRLtGhxdTGpktfoiLmNjBt2lsP5KJsHmJV
p8+aF/Jwg3T+LyC3U7aXRjGQLpTyhXwhNZvMCAy/zgag0HRBqMQhBE+p3Ggv
S2nM9uAPvtTgxoCo4IjiHSpcUvU0MxLNwxoJU2Ep8DHllGKmkcVJbIqZkghi
kyssYGVt5ChLt1IpAGdJKZWXoeGqIZXyQ+0tHiHEJ1w+YcojFlaCVSyOwO+S
RViLGcoAkK7Ym1UWwUzdsSobRO70gcwbxZMu0Dekq+Y4OlMtLJ3QNdGUnQn8
a0obdMKcqbfyRG8lv801AyNM89gG2aCTY7ypRlToOW6KnvGtn5bLWUuvVDKb
9MWk2ahwQiT5M/qQ0ORUTefTIOikTDYbUjMCRxsxcxyJ+aToAc/2T5e9u9Eq
c901Xk/5InjjsWx6jrwxbvCY4wxT2MU+KA4snYkzvO0GlSBXF7gNKG2SNCD+
peiWB+RaWOIKPGAHI1m+CkHPdqTF0dnd0WCG78Ab6fBdCh1HnMitsowfDuEY
zszS3GjpqkOt7DxOZr+xHVb9VbKFilTNFICja3WxkJEKYq2aa4g1KZcv1XKF
RrGcJ4i6PF8K8cWjZcPnqYkXsHJ6Q6ryEzI8gQEtB3JUxEozEdOOd2sAPgNr
4m2ICnjCd01ayuQL5WKhkssPpGw2k8lnJG50XKMrQLuBkFM1N1ZKHj5LaTZn
tl1KIK75QaRWRsVsVhKzRUUWS9lKTqwwVhELhUJpmFMyw/KovLEdL7TutXB/
fbkeXgdHdj7jlkmwJ+MGQaB0/EYzHBVcZl+YgIZLqWy+ofTwEfGvk552itfW
5dv1kj4ApQDEjVCR/k5RlEXWUiDMCIdglYB2IoaC4poRcXC42qAqwZ162zcW
0a+m0VuYJs0ii6gOU2MsPWVe2sEMberG+turx+zVr3F+pu/RNknpke/j7Q8U
zVZ0+J0ep+PRr19C+ARJAZxsHYzgqKkYeUgrks1nyqV3N7hFNfUCbB0Ro5fr
qnKMgptoIcsmmG/wrh3+xo1E8wVEe2iabdQ5049UdIxdht5RXQz7UBGsEWx+
E5CO6Cf/Cak+VcMz6HSxtCEqFUc14yZDCh/RNwumLTVzkM/mSkWpkk0H1xIO
pFymUgRLc63JLFCCLpE1IgEiD4MS/W2cwVmIywCfTcDDn3Kl0vfsqeZMAFNw
dlS0Y0Dba3LUpo88pmEm8hCr/bEwTYNtGufXHThoCsibN3mljcSprGsry+YW
nTwdRu1Z+pP7SRHbRjMj4h3kP6y2puueE5g632QV/AJFeK/c+A8ilzwsvQAd
DH4mGFIj0DYEDqxT9G0YOH4yA8LANHCvUYCe/gbVNrYBjoxtIx1q3SCOGVjc
6WKlWJHypQJntU7X010NnI5oEaXhP+NqxRcrzAQGV8KySbxTDtzRQ95+MTDV
btdSYe3zKtgtj4J0wWsR4bE+v4+VKR1zR3gd6QuCd9TGlLuvXTBBZIzHydM4
/VBTwJBmqKOdtMHfncnTwS5rFY/z3jmvGNue46Yt5UuVvFQo5ErlXBE4P1PM
i69iNc+X8tZSbW1sCTUbaGR9iI1tD+nFAVgxXDgE7V65zCT3G3nGtEQkD6hA
ql8gLArlLOivXLFYBHQKWfExUy1wLGp4+nVtg3O12RBjCw5DeBl0Br0s5vMF
KS9lBxbnWawEdskS2WXcrLHJV0pSOVvJg5OZz2fExUjLBU6gZcOSgY8JRB2x
PQiBaeLQO2meBhNSPQ3WbZqzmH8/5b86Qq3XOThY/9lkKnHZFebm8+KqrQ7u
1xrGbxzZcIXR3/7DFnpowNoThqfGJtbWRD9zeIBpyhvybDCfUJdtMO6Ftqa7
x9jOyKMUEKyVBRNqyhw8D+VBOMD1GL7S1X+2YMsJP7Ou1+PpJn6Rld8kgALP
vOkRJVhrYG3i3QhrIecfHuM/wrZOGKTCWDPFhjEODcsS2ebhdRYY9pqy1QGs
o+z3CWSukjrmYTnME6EuBjyOx/Nd6nV/QMDbZiOMl2GuydYuRfzYa7Mxgh+Q
x9IevDNsnfeNTQDqFMnjMQJ+zoygse+vwsLHOwOUYWPVGQONzoMJftfcRHFa
yt9I44W7oQSNlbn5kc7wLT+xJsKjbuSKneFqo59UeINHUPcW3MVDgXBEOvgF
jR3/0pUguhrFg4bdDtsPXUZw8PMZfNCaLVgLM3YqzhGQeUmZL3moF/b7g5xt
MeUYmkEBFj+u4McByECAwUL4enTEloruYWrD0VH8ffj+iKo8j4L0lkPeayDB
lWm1UlNqvAzsF6fcyZyPc6v6LHcrzzKP7DT92ZaWHwI6TIiUfHpfUe+allu9
eWub6jSbe60pi1o/JzvJkNoHKClSufY8cyo5o0dnvqq5erE6fiq/iL12W1sk
Q2ofoKRIFS7OilrFmVuGOZmtrtsP1+ylWxp1jcebZEjtA5QUqfvB02vr7ik3
Ol3IzcViNapWGs5k1mZuJhlS+wAlReqsOVAWRrt9OrTPBg+F++LqlLkPD6am
5ZMhtQ9QUqSuB/Wn/koZZ85bJWV4LnvNqji9Hz9mX6xkSO0DlBSp57OXs8fZ
0+K5YNbvjbfBQ755XnzUmqdPCSm1D1BSpPKOlbtYtq+uHts9aWHOJ57FHh7G
rN6eJkNqH6CkSN0UzwylUJ5nFElv3Oe8l85Tpvo4sEatajKk9gFKipSZ77LC
zXV9vpgsldMzU31g1yvwPhUrIU/tA5QUqSG7fbu8nC+62mh6Ozq7Hi2Z0rLa
s34joUTfBygBUsoI/rorPLXViqQ/vWiv9b5bqT2v7huXTXY3634aqQ8BJdZ9
zbqVr3VvG727lTm/rFRvzmT3+sV8lMcJdd8eQEmRWgwHT06l+6xWvIrVzdam
Ytmdl0bzx1ZCpPYBSoqUNS+PxJLyfH5euH0Wu8aLUuxM7ns1sZlQJOwDlBSp
rHfnyQ2psRq/XDa6+VZ/INpPw0VfO0uI1D5ASZGa1XIVeXgp3djt/KDa7w5O
S+X58rrvLRMitQ9QYt23PK8vu20m9qrabcWbXF3pun2eN+6qCdXMPkBJkepL
S292V1u8Pp3Weu16/3Hcaz8+u+rrWzkZUvsAJUVqcrvIF5uLsXGvapXR67OR
Hb2cD3Vz0EmoZvYBSorUXau0Oh1MdeO2t7xcZduPxdGb17TMxsvnheeHgBLv
vsmMdXSVNUenRavyWryo3E/dTKZaP09IqX2AkiI1VrLaS2Y+tNikNxDnUkbs
XTr6Un6uJzSH9wFKLDyv8kZ19Fponz3P3Ebj0u6ZaumtoT5KCRl9H6CkSD16
Z8pgdXp2Xe92vCdlnr3qlh4b1vi2fpcMqX2AEttT923dHDY7pxNRub5hXa9x
f/W6LDzNHxK6WPsAJUVqeX+Xq5de767MsaLNSrX881Whe3bXrzwmVMj7ACVF
ShrXleuFWLq0Zo3bt7faWzWnNjtjK3eb0MjbBygpUm5ZtoZvtVwprz9oF2/2
vX11+1Satp5WCZdvH6CkSBm5u1Wt+Hhx87aUPYW9nA6s8rWZl7xeJxlS+wAl
llOv7VdlODyfywOrdSq+nDaevWw+Nx6JCRXyPkCJXaxG+aYmPdxfiK51ac1b
N9n+tNgwDHaaUM3sA5QUqfnjZXamjZ4LrUelLi0vFr3RRd28U5p3CYNm+wAl
Rarbaj5q5rBceOzJF9PXl9rpxKg910vXSkKe2gcoKVIvTuW+k7+ulVdPxmSc
vRrKzzVJzmZHFwl5ah+gpEhlbt+ubt8eB/eq/lS4uxl0H7rG8lk37ZeEcmof
oKRIPeS6bakGztrQkB7urpetG20idxTprZ/QRt8HKLE9NZBbK91otq0L4/Wy
VKspT/dWW7QvE3szewAlRarUe+p5tXLu3LArr/WhdC81K3mz8pDLJbQS9gFK
zFO9h9E4+3R5Wr1yz25Kz85IWur5K7F6lTDqsg9QYoVsjC4X4nBRPnfUs6Ge
d+SLSqX5lteYklAh7wGUODq80kat8tt1QV5Y9nDQky5vK83Tu9PHh6TR4T2A
kiJVf1rMu6XCW9Hud9RsNff8PH8+M9rLKy2hPbUPUAKkvJEBf2Yry+bzY6Ge
t3qt6ey5On/sD0pPFw/Z+8+v38eQktLKk9rLp4eKcja6n2m5+qjymimyyWL2
1Eqo/fYBSopUrzWoZjJSURbPu+Zjddpyu3dLa/psvCRk9X2AEh8ZLUri1UO2
Xr23M+JN7a1SYtXusjYwuwlV8j5AiR13czVU5NH8JtsQO5O7Uf8+my0/3DQv
Jwl95H2AkiJlG/eXrDl8kZfZop6TzMJMc9ud5dXNNKGi2QcoKVKN8eRMbeVW
zvC6ed69YWXl7U10lU73NaGk2gcoMaWeL2RFU7ML89SVzxa9odbpjNxcP9NM
yFP7ACVFajA9rV01Lp3+w8tYVoeFpam/lIvqfKIktKj2AUqK1Ot17rGe6cp2
s1nN9brD2uzh4cxdVuuXCRl9H6CkSE2nLzcTLb+anw206uLJvl5Iit2ciIaY
kKf2AUrsz9Sm6rl7/tZ3882KdD+zR+cdUx0b/WxC42UfoKRItT1vUG16klTr
2+ryPNcpT4xF9uVlVk7ouO8DlDxsZmrWclobDG6eO/NJ0yyY8kPxpfP4ltBO
2AcoKVLag1OvV/Xy07M4u+pXS452eddyRrrWTkipfYCSIiW2W9d3t4X63Lt/
UK6q41xJ6S0XVrVvJGT0fYCSInVhXjydloatmyujvrx/fC06rnblni8UKaGc
2gcoMU8Nhp2zyZVay79I44ypvC2vnxfNR7duJQ3F7gGU+MxhlX+9vzm7ad2W
s+LQmd4M7lqdosZ06SnhmcMeQIntqbOcM3hqmqNK56Zc6s+zivSaH+WKy/OE
jL4PUOLEkofz7tOT9NSSTrNab9Be3eTthnHlNFoJ84L2AUpsJZxLZqPHFtXh
/cVgwa5mlfLUfHpWxsWEjL4PUOIQx4v3lhl1Xsruy5Ol3Bna8/Oj0lssmu2E
lNoHKLHj8KTd58+fL+1sxmbFm2nLWD30crNrlyW0EvYBSpyC8zReGpI2dIuz
vHpRWjalp0tVzzz2Zgm9mX2AkiJVvDgfX82y2afbZav/NBQ1sbbUuq237kPC
WN4+QId+uT22QLnxsKKRLl7qUDcZ2z0WRgCYGkwJr8HPPLeTklltWXN48u3m
dQvwARUi23SVGDYkwc4IlC/5gI0WtvfH81vjfeU1M8L/trdjITaK09TgkrPP
9szzv/qN2rNh6i42BNJMjxrZRNsQOUGOM3XhwAJGaiiFPTScYwFbDMErR0eR
duKbnQ6PjmgeR0c78HrxgKAjjam/CXcBZP8mOZOJeKVu7HVsEzhcl/9j3qxF
XRIj79hYby5oBnUScBnWRtDtJnULOzLSK6fwLrU6o6RqvCP+hPpqf6Ocacxm
3qj4jHIVcENaU/3ec34bUOAxkS/YHO8ngmXI5KnKB3scUJlTUcwepoKV9/Os
g3aO2DOHpgEcoY1N6qbmcPrZW/rABY3gNjvBfaUaEYCNrf3w9mCfWn5hIlMP
f6NejarfWfDoiNdP8lRrPt56fGqfQZeu4CJgDxXPoKxx3v1oEzZ2DsOWIz+V
iPlUNpUnMraB94KSEOqHQ4vup3bTtgKcgTSmfzUyNmPRzLmlz4Ommu/uBvnN
B0s92GSBaLPCt23gIWrqJWNf/DHjfSWwyI3fAidcdzoNnp5db3euB/DHb5Sn
Hin2wdtosIofabxOXz+gpOxIsY+fqj6DHYpNNFS8HMm/OC9IOn+X/7094fuj
bk785kEtUgiywFZQw6AlFfUs55noMxsrcrEmjV9Vy9PGeZZ+/OaMut9pJ7y8
DiAGTceCbnHEV9QcB7FG+RBIwU9JDBiwhhciCFgdiLeWUAsiIgAzVey3uM5n
j132wuVGeHk23dzmMwq1DlvfYxUAChPr6Q6JPe3aHEv3eGsfAbQG1wEeqKRj
fp027BjLb1uCV1dRcZqNbLvlDj+Ssbo2ZdSacOMiCkQTZ2rh9Uo+EJjouuOj
30gPWw5xSc9kB1skDZkQllsMV/Gun2F/lJRwim3F2BKEh4MqL1KNRpUd2MwM
Fmj/JOAdGEFZDYFPgu+RfbF2AGud/AZOwEaI6eZll8frbkJUDhOMjG11Dc3B
zWCbND3UE3QrjTd09a0tdIRTWHyFKl7iXAky8Cu/4JwI4c2oDIc2El5mHvTt
5OIiwkbBPsUWjn59hDAEPsb5UEEYLy7p+i2iQaGBWBN61CL6GOwLW5MN2Hag
8eSRfCz0PcsAiV31bPjjXsP97ujyXGh4Q7aaWsfCGda/4mdMOJMVsD3AFulZ
5nhoCTXvWKhPmDleAnJtTw6qedqytcCCMnjrkPiJ+TSIyhhZ48Lkwz456wtG
qWMOdRwLGciX/JEr5b5HCgVtb7fd8bazvY9fOuN31NzXCnR9qxsXZdGv1hd9
+jde+hzlW0c0etBH7l3PpKAciCzC4F1EDWdoyzMNa5p8ebWeI93goVKXsXCz
Rq96DaufqAkrVnoLfZB0mgkr9haSPOjPCwJbpTZ0BJ12VVANGg61VWMEcKh+
aY0fQrDxFng2p7IsBIMNpGRXXl+pRY/8C2yF+Jf+kPgW3pmAl9SEvehwap6B
feeCx1QCCKPTDSSBJscLU7A8e93P+3778lf9TRp5A6RAAwW9c9C3fPPKCS3v
SD/ZSENcXENqWgX8SK1c1+REMtB29svF9/GivEYmIq5J62w2kN7WXvj4k12b
j/d2mQYh66BpT5e46nSbmBP21GJUDBn0uTTJQrSxCDHkGGQ9ObgQcSLTzWLY
bgMfBnBoDZ0PxN+WO0lp3NDqSQmRm2yQfF+xHyNbTmT0BbAxvEbrdkhtf23e
YZe3FV4/8NtdE/W5ORm8E/wJb1A9G3Ep6Ue040iJTjdX7RP3JSJ9gibOa3nC
LYuIJB35lzj7W2zDGuEYYtk6dnkmt/M2nFLYEi0y7T/xJh5Uy266jZbBH8I9
Mz28TKYBK/gVb09ebx68LUEE/bvzn3jb+AX4eUtYAbrZ2YnWb2J9ZaStxkxJ
YZtRMProX+lshq5HuLblsQdbp/6GnalkeFIQS8KVAroJAcDfjo4e6bGAaFl8
0FY132oLUh5bSuqMrlDucp6MuwhjOT+ekI/Ax8QvxBn/gkYHd3Usz9Au+kPI
lsHwnLli9qPRowWkkd4twLBOamxZY7+OX9VSoP9AzslSSnPTzLFsTXGoxBiH
vgVT/VjouCCq8Y7qvCjx8TdGpiGpwThd/NYxYaNpRrAFcQE12/XoUux+rboN
Qgz3285VX+h5BmyvTfzpIQgCyxUth4gW4tqCFcV268dCE8voiVpingZjuO7h
iN+CxoQfw6VuGqA9QcHZzo57MA6Pt82hgQok9BEesI1nzwU9YghfG72H3uEu
HsBoycChN9O8MVZQ930o+K1Dv7V0awjEBEdDo4niNm3B5A1YOm4Rgb4CtvtK
LLhzqMPYwmTzoF/GayLxOcW/DQwqLL2mrh+RquV0XsoVipVCqTDAy8rF4Fbd
wYYyG2jmoEn2+qDVaQ4aDL3vAUxh4N8XqA76F73BtrsXNrUDUP4bkXyNpedk
sgs2TL1ZlpHysCGNkiaXN31XNXNlSWWaLMrdS+Ol1Z50X5eWokhtZdUsTZ0L
XWbsnI2WV/lhr5412tdvi+ub66cWy6rm823qbaSzp7phuLCHrMFlj9/UEisz
r3aEa675e+j2+ttd+IvwjTaHFGXlWHTA3ylpyefle42ZJljIVdAONgmcrCSc
edinNVgfNBg+Gw4EsEg2UPrMSVvqWB0sjcnLzaN2O5AvntRX937eOGPNPPLy
9yx8plLIZ6XKILixZnDbGkQJMwjr7/lCj6m97KDa4TSke1t+CpE257L1UoUo
XAxtACzdSfNPRXjIuc+/sUVcd59F65LuAxEzmdRMHW1hxxW4/F5qyNLNYaH9
NpGMmXT6m/trXipX+NTDOQvYgxI7ZcN/zGYroQ0GXIQO2lRbI8zMGM7YqVIG
tW7SfyGMHdTJRKmD5GkHXwY3oicd8ZeN5mF0BUKpIG64P9gLAamDuP1XJrW5
30K2+nnb7h3Nvnvf3Vdq589ng0Zr+nyt6uZLTb5jK92bDF9v/kH7rm25t836
D6GTVNmk04/ZehPLtUeKiO2KZFEq7Gz0aaqi34gk1kkyk9m7KRvth1vtZXnu
WLApc9lyYdumJC78gDAhtzppwjpk3s9S6++9E3/Q6gSj0wKp2wbb6AT7wYq0
bl9XdqNzOj5dwIpIuXzm0Lctr1v/1HyqsdnY59LMVqIno8O4/DrwpMr88W2K
6iKfyfuciYakM7FmcQJEe4E5pqxMXFEF0YEd+lSGN7GNbTBc/XaYsulo8Mau
DmtSoYD7AIjd4CCEnqKRr3RJd6HHDfKPR2d8EwTAQKQWYQnwDotwCTbUws+Z
EJHvynPh6cYcLHooqirC3sC1EMX1HaqxL2njTl1sV4W9H/3G8djwbV8nQJDL
caEmcyEtymD1UsTJSfvI71B9Wx0l7sViQy1vOaJe1BSXQ17e1byLwMBYX9eX
MAxXwhksA3ga6DeTLyqb3L3C9svHwl2vilTKieA9xAmFR1mbLa0+0GZSuQAu
RHnQw7gU+FbaG/0ysEYx12A7NcLoZz0M6b7ztqMzV8IvfF8IGL6OXfSES5kC
MmsCN0P6xaejmMoIWy7G/ahcRqjObE3fI2I+RYt8JV/JDm6Rl3D6yEvoOm20
mRpU97pD792gnDt5nji3mlh7PrsQW68v5qL1Nilp5lB3vfOOPrt/ee3qD7Pi
w63a7T8Xi8/lmVh+epFldjUaTh5TdatdfKp5U/nckzPjqYshd34OqRmIiTET
MpmTbOkkk+H3Q3eaeO8D6jS6qYbuovhLEB4hUgWn1Ftky2ZwRMb3ccPg+2Lo
+3fxch9weo+FumzKqix8nfMFwR+lUmxFvm9BslKuWJQygz52CENLy399cGrC
UJaJIa9B//Z0cDVj5qDngZO4T8Cf2xVrOZNGqplBRZcp5/BtfuHDLgqEV0/J
9jsqiL6GEjmIQGRcwv7srQzYjBoGok00+YS+NcNAgR/eDaS7NYp0xYPXehbs
tI3oi+WIc4twoU7habDO4NnGBpCKm+TeEm/ZAYkWlMdVtlkpkc+4bEyPNOx5
zRtp5+nfmbxUHHD8/yWb+ZdsWfqXbGWHe/YZNDghr0/7Yv3qkvdjk04EqYBh
Pd4EUzgNmmD6F33g+Qjy9JyHQdfjjcB9ZG5qrKG+wPCyCRsG9h1aFgWM+m3v
qkkAeVd0k6fA/CGcy7bu2N4ERK7f9ZBIL/4QZkfpU8hkKU4DXkTVP6p5J4mP
v1fOZ0u58kfQByDj3ukCkIDAtAO0A/2VafW7TR7mPBGqpok8GDiA/vHcQ0v4
wseCX6gJM/J+wOxf1riPXWNEsc+UwzeFgxqD2MM3OX7DWyN+ZbQCF96b2MNj
N/inN2eeHQ085kUgfle2/6taoJArSYVkWoC7yc3bqMFc+NBg5rdV9ybMfIP/
x4NWbGYZE6OVDyb0geVc2GY5g0c3soNG+oHJtN827ozOx8OrUv7CzYPoLGYK
+a1RpM9N+SuN/OHUSz9l6hRXChtABweiH0x/8lgCC/F0ellCF6lYKvqzx8iH
8S7y8UMW/r/OyZlcvpTPlXK7IxVBTIIuUf074/99q0eXr/rN3cO1s0brFtJM
xX7N+1fz7G10MRuaEz1TxRCEJJV2hGZ+CCEKP4UQsRiNT5Dw+H2d6cT/2u0J
7SfUlXtllS6tseYg2+cKUuARB/T5vlhNYSNWs5d8efEdBb8vblOIxG1+tLf4
HdGdXeu6Ed1JhOn+1Sxmq4Xya1uqdDuwmtlsKRN4de8P0iP6eedNiRsWaEZo
suEePv/wbnsffGBVO3gQOMRgrxkhVZDzRClPPOOJa2pfUbfAESCLNCvx84F/
e0cQZFAiypAfxy5kV5n8Nv9VU18Xw8ykqU+c/4aZAb9eXxij6d2Zkqt43cmz
c9kyZkvxtSF6detm1R3rndl/QzeiKDnRbbHtNPaTXKHxr7hzYcsuqCUp7fDr
ydL4d5zklQ8onnysdyy57S1f6BBnrq2Hjw5jxne3T0VJvdeuKcoIqulQ2Bdi
iRjwlqMyY30+7GC+qqezNM1tR2gFBIvK5iAQDTzB/da86jVOuxuu1SZgpG4N
XE2H6c6xUGP6GB24P4ScJJzJpihtkPu9h7UTU+5Ht9qtZq0b6ioXyLxNcGxC
8ZMjiNSUR+5sg8ShpLNF0PlZ7pRlM9KgmPEqLGPuWB36M7U5oKcWs1JhyyAp
eS6lFmxo/EjBkS0hdf/hgoMbSWAUEemkbGmH9AgZ+jqTdy/OlN5y1P3t8+Ii
n8v/UKmb+6cgnk80KfcR0ZSeXX++XFmlwTgB0ShU8yOpVhQaTCGqFT6i2ub1
wInpVONn2IP15atIrYKUlYofUWsx6NovXdZeXZcTUKtQ+aHEyn6eVj+Ywyiq
FxZK+VTLZD+imlSUW8+i9aypSXgsW8mSPfTXE8HVXJ39+iWaKxokJrJ1zmgs
CzNBnuaXPw94Ql7Vzx8M0/HC/EK8pZTy7GFve7K9WieLhlmUvJ7Cz7v9p0gL
pRx5XuiCebDBjQPh5eGRtG/L9vPteWqlxUvbBLpZ2sRyCeDV+JXim3SmGwpm
Myy5whKWmY0FWLGsaRyEX84+YmHWuGZjWZmNFxL/gktAFtsO1+XwQBDwykiM
cDxE9s1nGg/m2M2y+XLTPLtQmMyKen5wOX40DafxFIAlK/HzYNH0ShfHw9dl
5vGp/PBkt3PdZX5+VTazonc+DsHi3Rqfh4p2Q1lfvbYnlVVpcDEvDiXtcTK7
e32yZ5luJgBK4YHPQ0UfPd235q5eWoznb4uzh362k31emBOrc2U+3YSUrVY/
T1ZZHqdfas/309LTqreYyc3XlVodLR9yuenl83U4/2s0yHgtRqwwBOXAZ8ea
BTDEWHFJWi0WHq7leuZh+Hy7WPZrim72p6NSz6DOjTg85XpkyT3kucXf3InN
ZFX67NDyGkDaG76VvMe6I4pPb17vYfV4eekYD6OB27vBtETYAD707PdAX7Yn
L9VKfvTG1OLVZWd+fTte9Pviw61RDWjZ6HXriQinGo6SvqlnZbWjPE2XWl83
tVNFKY3H03KxVg0XaUvQYD/gdbjgumOfZa8GN6/K5V3V7HbMwf0km+0YD10l
gB7N//nxOUOh4Lh9JzjsmOC4a3ZvWyeJOYC3tHp+OM943W4le6Uu9Ovh+LE2
v6nOGjNW+N619+HeTm5LltS2H5ajVmM0vj3r3hYLt7Vp49RHm2LYSZGmRvGX
w2W7s6i0B8tZ72k4Hl0NzJJ+32myB+c7cf5E/3nOqJ3L209LErDF0oPyxWnu
1pOWj1JxMm6dLexVt3+7uLXk6nqFwWzZdYrt+5h0Ds03ftzI2rbsuJHwlr0d
cMbpiKpNu3hamJakUjZTknK5XeRLBNO/WiedAw+EkO5X69+FKFj8awQruaxU
+X4EI7CymUyxXC5kwgW4ql/HdxhWI/LvWWSjwWvhuRLMx59mZEKWMhNlXecX
LTt8XPhIDD6KTaYkFdFP9qFkE0Oh8NxgfUiEaUh8bhW87GsNOvfDQOfLuTJG
ZmkJfOj5Hwa9kM0XcwVYlM5IABObipoiJaxYjDWXQd/hrsNjENJ7VPUNNqtf
NMuNVV50xstX/JorMsaOhRkv09EZVv3TCFSuJXSql9V3RZX9WI0vXvVlWvxN
XgeHJZkHWIUyBK2BUKpKUIhFwRMwt02qSWHqr19G4HswsMjj7/DKbCw3MhnW
68k21rZiAeoqXlTY4ZdiaUFfhKgxPuIJGlh8x5iKyNAKYTWgRxE9nP3I06ly
0aBaQL/w+l2pqn9VGi9dVHmF+AyLK8jGDeqOUwFt/CJkKvl3eEFd4L/Qvca8
3J8fHQl09dn6ZjasuYoUFgtO5DIvfiUg9ZZwNi/zOqHqvoXmTPxSNrqEDx0B
vyKKDHWmaFxI+n7SumrSN9e10DPwy+mwfsxx1/0seuAlroRzZAdZuNJMGZ41
bNmZWv6/5ppycHB0tO1muKMjYdeVcRx7Ylasieb4Yf0W4qBYYsTDItLvBBSZ
yFzWPXLEMO3J1oa8cptm8b4IFx6+r8IlrKg1whjmi8yCDBiyKttCQ82k+1yR
r9acxv2lCdNn+DwodbbMnbMgJE9tTcHOAsB5OpL5zJtYQhOo8Lf/14Q/AdMp
7NZbT13xv6JFx/CkZnuwMWvgLsNUXVw6F5hQOMd7DG34s/8iY75fG/iEfw9a
QehPLMOxEPwT+IowpzNNNsfw5zV4v7pwqU0t04KtAk/qIDJWwoOm8/erpmWu
DGwsEq3CCqrRbRyjAQtqCV2wDmAPEaPApKyJiRd1en/7vwEH13U4tBpIRmCw
tqwzbKXBqBa858reECcSlEZjH4d1HbTw/n+IZqx4OiTDhYdLfu6BRyuvhOrE
ANl3/rf/+Nv/87f/mMIPHUPGHNCJbSlTGnE20TBtaGJobExTma9U4Woqa0Re
kxioirJXBs57sCwVAMCj1t/+PxshMVgGlZMdpEFPdonh5Kk35CuHdXqutXCm
2notmliYCjwwIfIDB4MEa9CF5ogAG4JktnS2ot0W3CRZtzWQWHyjNUT+V6Ld
xdu6UJm/vVrvtTWsz22w9+wYKYL/OdsqkPI0fscyPRdYbQIWD5O3b26RuB1w
avK4y5Yt18a+Io7Qd5SJNWKmhkv/JNtoZU7YaEQLeiF7vKzyAvTNEHgbObal
2Zo6AfndBRRXskGMCBQEXY9aG5bTJT4/s0yZuj20rRWyCDy6xft5bVWoycD0
Dq6uzUagGWhR+X/6K7qt1vWdRBfWmbC8sDe8Z5K60ZCuymbwvzF2IaVyfo6c
xpsYRcYMrQqKhFGHgPCu4mCIoLVC0Ask1BvnwNMT4L0VzLUG8xvLc9ncJqUu
QTgYwrk1ZBosMk6/xTD0BNpjfY8y2T5OUBuIQaRjAT3CYyxK5mEynmrJm3EE
7Mmze3nZP5EoMAyweoJAkX5OCVVhe6XyGhT1jXCEb3hh7T8gj/6XGRiZv0ql
QzA6trahQORGWPFOU+bZcmGbmkh2r/D1S4N5Lp6UkW5RJp45dvASWs1PRU99
OTz4/wH5oQwlSe4AAA==

-->

</rfc>
