<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-54" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-100835 of CVSS 9.1, CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-100833 of CVSS 8.2, CVE-2026-33697 of CVSS 7.5, and 36 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-54"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Stevens Institute of Technology</organization>
      <address>
        <postal>
          <city>New York</city>
          <country>USA</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <author fullname="Islam Aboubakarov">
      <organization abbrev="ESILV">Ecole Superieure Ingénieurs Léonard de Vinci Paris</organization>
      <address>
        <postal>
          <city>Paris</city>
          <code>92000</code>
          <country>France</country>
        </postal>
        <email>islam.aboubakarov@edu.devinci.fr</email>
      </address>
    </author>
    <author fullname="Ammara Gul">
      <organization>Birmingham City University</organization>
      <address>
        <postal>
          <country>UK</country>
        </postal>
        <email>ammara.gul@bcu.ac.uk</email>
      </address>
    </author>
    <author fullname="Venkat Malladi">
      <organization>Verily</organization>
      <address>
        <postal>
          <city>Dallas, TX</city>
          <code>75019</code>
          <country>United States of America</country>
        </postal>
        <email>vmalladi@verily.com</email>
      </address>
    </author>
    <date year="2026" month="October" day="03"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <keyword>CVE-2026-100833</keyword>
    <keyword>CVE-2026-100835</keyword>
    <abstract>
      <?line 378?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/>, <xref target="CVE-2026-100833"/>, <xref target="EUVD-2026-87851"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. Based on our work, all except two implementations of early attestation have been archived, withdrawn, or moved to post-handshake attestation. In our analysis <xref target="Intra-handshake.fail-repo"/>, the remaining two implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable. We recommend users to carefully evaluate their systems.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 382?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>We first present the executive summary of published GHSAs/CVEs against early attestation and then an overview of the research works that led to those discoveries.</t>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>The table below presents the current status of published GHSAs and CVEs against implementations of early attestation with confirmed scores.
Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST standard metrics</eref>, where 10.0 is the highest possible vulnerability score. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>. Scores of 20 more published GHSAs is yet to be confirmed and will be added later in this table.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.8</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">8</td>
              <td align="left">3</td>
            </tr>
            <tr>
              <td align="left">8.2</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.7</td>
              <td align="left">High</td>
              <td align="left">2</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">3</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">4</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.5</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">3</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">5.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.4</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">4.2</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">3.7</td>
              <td align="left">Low</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility, and further research.</t>
        <ul spacing="normal">
          <li>
            <t>This work resulted in <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
          </li>
        </ul>
      </section>
      <section anchor="id-crisis">
        <name>ID-Crisis</name>
        <t>A <em>complementary</em> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility, extensibility, and extensibility.</t>
      </section>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/> presents a formal analysis together with regression tests of the broader attestation ecosystem and discovered three critical-severity vulnerabilities in implementations of early attestation:</t>
        <ul spacing="normal">
          <li>
            <t>Ultraviolet Cocos AI in TDX path resulting in <xref target="CVE-2026-92701"/> of CVSS 9.1.</t>
          </li>
          <li>
            <t>Ultraviolet Cocos AI in SEV-SNP path resulting in <xref target="CVE-2026-92702"/> of CVSS 9.1.</t>
          </li>
          <li>
            <t>Edgeless Systems Contrast in policies resulting in <xref target="GHSA-Edgeless-Systems2"/> of CVSS 9.0-10.0 and <xref target="CVE-2026-100833"/> of CVSS 8.2.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <t>The vulnerabilities cover the broader ecosystem, including but not limited to attestation, authentication, authorization, key storage, parsing and resource handling inside the runtime. Any vulnerability in the whole system, and not just attestation, breaks security of the overall system. The key take away is that early attestation adds unnecessary complexity to an already complex system.</t>
      <table>
        <name>GHSAs/CVEs for implementations of early attestation and finders in (roughly) chronological order of publishing -- CVSS scores marked with * are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, Jean-Marie Jacquet, and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">7.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">6.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">7.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-f96w-jjf8-xpw3">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">3.7</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">7.7</td>
            <td align="left">Sebastian Jylanki</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI4"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI5"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems6"/></td>
            <td align="left">7.6</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100833"/></td>
            <td align="left">8.2</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87853"/></td>
            <td align="left">7.6</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-100835"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-q46g-34w4-vhmp">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">Moderate</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar; independently by XOR</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-jj9v-7353-35cv">GHSA-jj9v-7353-35cv</eref></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar; independently by XOR</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-9rfg-55gm-hwvw">GHSA-9rfg-55gm-hwvw</eref></td>
            <td align="left">7.5</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-ccfw-q8vr-cww3">GHSA-ccfw-q8vr-cww3</eref></td>
            <td align="left">5.5</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-ffg7-hfjp-rj7v">GHSA-ffg7-hfjp-rj7v</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-cxxj-pvvx-6xcv">GHSA-cxxj-pvvx-6xcv</eref></td>
            <td align="left">4.3</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/veraison/services/security/advisories/GHSA-pv6g-4385-q8c8">GHSA-pv6g-4385-q8c8</eref></td>
            <td align="left">6.5</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="intra-handshakefail-1">
      <name>Intra-handshake.fail</name>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.ritz-seat-facts"/> archived</td>
            <td align="left">2 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems3"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems4"/></td>
            <td align="left">24 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI4"/>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI5"/>  [<strong>Severity = MODERATE (CVSS 6.3)</strong>]</td>
            <td align="left">25 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100835"/> published  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87851"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-100833"/> published  [<strong>Severity = HIGH (CVSS 8.2)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-87853"/>  [<strong>Severity = HIGH (CVSS 7.6)</strong>]</td>
            <td align="left">27 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published the following EUVDs to acknowledge the vulnerabilities.</t>
      <table>
        <name>ENISA's issued EUVDs</name>
        <thead>
          <tr>
            <th align="left">EUVD</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87851"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-87853"/></td>
            <td align="left">7.6</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">CVE-2024-21944</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="Intra-handshake.fail"/></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS up to <strong>10.0</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>Both violate the fundamental requirement in SEAT charter of binding to connection.</t>
      <t>While <xref target="CVE-2026-100835"/> and <xref target="GHSA-Edgeless-Systems5"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>] are patched in Contrast v1.16.0, users of Edgeless Systems Contrast need to trust Edgeless Systems for the provided hardware identifiers. This keeps Edgeless Systems within the TCB.</t>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Privasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity; draft <strong>archived</strong>
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06 and -07)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
      <table>
        <name>Summary of vulnerable early attestation drafts</name>
        <thead>
          <tr>
            <th align="left">Spec</th>
            <th align="left">Status</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="I-D.fossati-tls-attestation-10"/></td>
            <td align="left">Withdrawn</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.ritz-seat-facts"/></td>
            <td align="left">Archived</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="I-D.fossati-seat-early-attestation"/></td>
            <td align="left">Vulnerable</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 10.0 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of CVE-2026-100835/EarlyAttestationBleed/Intra-handshake.fail."</t>
      <section anchor="earlyattestationtschss-eat-cve-2026-100835">
        <name>EarlyAttestationTschüss (EAT) (CVE-2026-100835)</name>
        <ul spacing="normal">
          <li>
            <t><eref target="https://radar.offseq.com/threat/contrast-before-1160-is-susceptible-to-remote-attestation-relay-attacks-cve-2026-100835-3833ee713219f7e3">Threat radar</eref></t>
          </li>
          <li>
            <t><eref target="https://buttondown.com/vulnfeed/archive/vulnfeed-2-critical-cves-2026-09-27-0400-utc/">vulnfeed</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ervik.as/cves/CVE-2026-100835">ervik</eref></t>
          </li>
          <li>
            <t><eref target="https://securityvulnerability.io/vulnerability/CVE-2026-100835">securityvulnerability.io</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/cve-2026-100835">vulnerability</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="earlyattestationbleed-1">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode 518</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/571">Freenode 571</eref></t>
          </li>
          <li>
            <t><eref target="https://collective.flashbots.net/t/earlyattestationbleed-paper-review/6054">Flashbots</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://www.rich-wise.co.jp/cve-info/cve-2026-92701-intel-tdx%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%E3%81%AB%E3%82%88%E3%82%8A%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%AF%BE%E7%AD%96%E3%82%92%E8%AC%9B%E3%81%98%E3%82%8B/">Rich &amp; Wise with Socrates and Plato</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92701">OpenCVE (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t><eref target="https://app.opencve.io/cve/CVE-2026-92702">OpenCVE (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92702">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="intra-handshakefail-2">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/">https://mailarchive.ietf.org/arch/msg/seat/n1-mBLW1m4TKiGsQqOhOIkbNxVs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/">https://mailarchive.ietf.org/arch/msg/seat/mBHcB8YRR0HVcyihhjm11XqRhWE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/">https://mailarchive.ietf.org/arch/msg/seat/zY3vdP_TZKZIdK_kpcrwWQuYf8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/">https://mailarchive.ietf.org/arch/msg/seat/QcXGunfoT1OKrBI_FRsgpNsXvn4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/">https://mailarchive.ietf.org/arch/msg/seat/FSh0tTa7h1NcaeVZENqz6wg45C8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/">https://mailarchive.ietf.org/arch/msg/seat/5uos1xo5lkLisK-9RGJWLJaAnmk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/">https://mailarchive.ietf.org/arch/msg/seat/2Vyb3hcqRoJF4tLkJOxs2CueNuw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/">https://mailarchive.ietf.org/arch/msg/seat/9mDNq-Fv3-9726qe_te0nfYKMaM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/">https://mailarchive.ietf.org/arch/msg/seat/KwtGScLIYvUCW2A0HxAS5s9XMMo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/">https://mailarchive.ietf.org/arch/msg/seat/SpLBEi5_nMr51gSng5oqS1uTlxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/">https://mailarchive.ietf.org/arch/msg/seat/b2laJbuyFQQr6Q1nUCbpKa_PNz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/">https://mailarchive.ietf.org/arch/msg/seat/V-3QA8_dX1A5mdKxoVy-1z_8RlA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/">https://mailarchive.ietf.org/arch/msg/seat/vjIo3JCMjHglRNaSSHNOqjKgDxs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/">https://mailarchive.ietf.org/arch/msg/seat/pE1j3aP-qvaUgT-Q88JextCIlcc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/">https://mailarchive.ietf.org/arch/msg/seat/uojEp8S21Ftf2osLCJNoR8xPzKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/">https://mailarchive.ietf.org/arch/msg/seat/xP6PxDJhAH9bnefUjlKc0f96ak8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/">https://mailarchive.ietf.org/arch/msg/seat/krTrXMiNIPyYzVDvlXlJB0UvaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/">https://mailarchive.ietf.org/arch/msg/seat/5dHBv3DyUy4Fprh71i90x6pHPCY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/">https://mailarchive.ietf.org/arch/msg/rats/HErXLOWPTDmOK6RMVO8J0lEGCyU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/">https://mailarchive.ietf.org/arch/msg/rats/QqstD1bsKrZrfQ_VQU-Z9KhYnxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/">https://mailarchive.ietf.org/arch/msg/rats/Oh4lBsX5wtnqPJM1cPOkt1mPOAQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/">https://mailarchive.ietf.org/arch/msg/rats/dMAZ-uAbZIlUxiDbO_0ZBVh4q90/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/">https://mailarchive.ietf.org/arch/msg/rats/FRdzVOJ5OBs4M1yuFk_ntxYl1yI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/">https://mailarchive.ietf.org/arch/msg/rats/qr4w7FinCkG1qt27aCCjJKruP5E/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/">https://mailarchive.ietf.org/arch/msg/ufmrg/mf_CtbtSDHPz3uMHRXele2vwYr8/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Dr. Kubilay Ahmet Küçük, Sylvain Bellemare, Eva C. M. Willems, Justin DESSENNES SAINTEN, Massimiliano Brighindi, Mikerah Quintyne-Collins, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in early attestation. We have <strong>responsibly disclosed</strong> the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.
We also sincerely thank the author of <xref target="I-D.ritz-seat-facts"/> for archiving the draft.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/415074362_Presentation_Safeguarding_GA4GH_Ecosystem_from_High-and_Critical-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414897198_Presentation_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-3">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
            </section>
          </section>
          <section anchor="earlyattestationbleed-2">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.confidentialcomputing.io/g/attestation/topic/121496347">Confidential Computing Consortium (CCC)</eref></t>
              </li>
              <li>
                <t><eref target="https://lists.aaif.io/g/wg-security-privacy/topic/contribution/121504323">Agentic AI Foundation (AAIF) Security &amp; Privacy</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems3" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-rxcv-p3px-m3c3">
          <front>
            <title>Existing Mesh CA key can cross manifest boundaries during Contrast peer recovery</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems4" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-376m-h37w-4rvq">
          <front>
            <title>Node installer leaves the host containerd configuration world-writable (0666), allowing local privilege escalation</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems5" target="https://github.com/advisories/GHSA-jw33-f4wc-8736">
          <front>
            <title>Contrast before 1.16.0 is susceptible to remote attestation relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI4" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-v5m8-5wxc-vjgp">
          <front>
            <title>Cocos Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI5" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-ghwv-vrp2-2975">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100835" target="https://www.cve.org/CVERecord?id=CVE-2026-100835">
          <front>
            <title>Contrast before 1.16.0 Remote Attestation Relay Attack</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87851" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87851">
          <front>
            <title>EUVD-2026-87851</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-100833" target="https://www.cve.org/CVERecord?id=CVE-2026-100833">
          <front>
            <title>Contrast before 1.23.1 Image Substitution via Policy Generation</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems6" target="https://github.com/advisories/GHSA-MJJ6-PX65-JQ92">
          <front>
            <title>Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions.</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-87853" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-87853">
          <front>
            <title>EUVD-2026-87853</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1204?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Kaya Ercihan</t>
        </li>
        <li>
          <t>Jan Kahmen</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Serhii Nikolaichuk</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9S92XIjSbIo9s6vSOu21hR5mNjXGo2msRIgCRIEwLXsGjqR
GQCSyAXMBQun5phe9CAz/YBMkpleZNfuP8yT5kXfcb5E7hG5Aokks4pVZ26f
M91EZoaHh4eHLxEe7jzPH1mypZDP3C8twVC2XM2yiGkJlqxrXEPXTFkiBpG4
O2JsuY5gqFNb4T417lp8LpMr8dlMppIvcvqUa9wNh1w1lT3lvJfVXDmTjXmX
O/COAs17LyupXOBlPl+qlr135VTxlBM0icuXON2aEwM/NPG1veQsnSObJREt
wJ9+nc2kMvBC1FVZmx3/ciRMJgZZvTV0Z9S/HImCRWa6sf3MydpUPzqSdFET
VCCdZAhTi5c1yxD4OWBjzoUF4aeCrPDFwpFpT1TZNAGqtV3C193WqM1xv3KC
YurQt6xJZEngX5r1yyn3C5FkSzdkQcEf3Vod/qMb8Ndg1P7lSLPVCTE+H0mA
yecjEXAkmmmbn7kpACNHMJT8EQA2iPCZqw1ataO1bixmhm4vP3PDVm10tCBb
eCR9PuJ4rtblhBn0auKPbhh5TvBpga8ZgXYehuck9IRO/d6TXOgJm+b9R8Wj
FdFsGN+vHOfgfn+GPxj57mFIMH3cGb7CxyrQGT/5nWwEdamQFMwvPhcMcf6Z
m1vW0vycTgdepgEcgJatuT2BCVDtuaCqgsTbpqAKvCkYkmCko2bzF2imCEgD
aOYCjmyeYtBTsh4JKH2YY1JzS4WOjgTbmusGThR0ynHAgApjtl96TofcLXbI
DWmHv9CvdGMmaPIrnaHP3IiIc00WBYW71eQVMUzZ2uLSaBrEBHajLdwlMLoN
PRbh08/hJ7oN2MLDM2KogrZ1HkqAUSabrZTpb8LmwiXJmJIkxUjyu2XzEgOY
kkjEuO5kQZwTUxFWXNOekO1CjxpUQzfIPRFWJNjhL9hK+F1izXCOf4no4JwI
Gt8TDJlw54L4YhMrqoMwra4E1TYCJAn8dglSJ8pMttUQPs/YlYpdpZ5ZV7/b
GjZNTUgUakNdm010rm5HYTS0CKwIE9aoCbLatggiRidXV/TZNogdWXOPsD7C
CN4OayHkJopNJH2mQfe/z/DZIYI15kSbbWSN69iCNotCresLr1AXgm2gpDDe
7qMj6GuicUiAyLHD6pjNBZk7AxS4mgY9TnVgQCqkfRoAW6ROuUtLSoWH3pjL
mhDCbA6MomVzmWKmWCjEo3YhbAWuZYgy4BCJ21q2xHmA/E+2IbsPXAzwo1di
KLDIQ3gsAHiKMOC/mxRSSpxHodE0uAt7IisCaKi5Sizu4p//+Od//ec/Fgwn
WTNxpaa4ixRXS3kvI/Bt9ueywl1vgIBSgM1DaElGamGL9uJ3nX4mKLaqySmA
E8m1W2UlAHvAClAAgEEiqYSsMNct7lKYmGHanAtLQQuv4wkFFT8vrZXANVJc
L8Xdy/i1GSBEKxV+9Q6e9dC5ImhB4EyZIaTIShBTamrNIP6+NHRL11Jq5EI+
t2GNalyzNRy2rq5aQ25Y616NWldvLB4Ua0vdAN3CDWRzQc0PW7EEF0XKXn2Q
JzsUbBuCJoZFoURMsAo0Yo5NmBuLaL+rpnaIlD0BDBNVVmRBA+ljyDNYL5Ic
hWy/0+Wve62zWgChoYBzrxGJWGBrSUThRgZYOXoYx64lKGEmW85lXSUzIWXA
J7JK4qe7Jy+IIcy5GxuGs9UI39AVBSY7CsuOYM4bii4sgLgiNQyHlj6dAmbI
ffhwRz4ImiCFBYTKuvt9DqBEBHUIry6oQW4ozg1dXETh0up1L7s1ro/sIurK
KfaeCnVlEUH9nVDyL52vUoIc2RcoOJWrTXR7IiwEQ19FdgjtCay3JQG9A6sO
Opz9879p+LfJXf7zv+kaKGKYJu5O1kQ5wE6uEdAadi/v3s1wTPlXc5lMJjgq
GVFNCT6qvxPJBo2/wk5TUyNidDUwFgwBRLwSNay6bKC9DiYF10CtvCO5fDV3
EVZBFGhqZiu/T0Q7BUvYXkSR9o5oC8HieoKiCNGsD76PrATVbBO/NU+50cMO
BpqMvsbQQhsRlXRNhaaiECBXuZjJVoN4rlTW8e8r2gs1Xo80puJWYARzu6Z5
Cq3EzxSE67lFfRFw0qh5fgyLA5Y3bxLsCMgIr0FkOk4PYD26HLLBU+eCO7c1
wmHzU9aVYMyI5ZvT6/U6BXKdoJE9gwYpjVjppT1RYLhItXQhU8llq9lKbryD
HSI3DuM2DmGGL8eyNnYxGwNmjE1dk5j+wzOBD6L+NuUYweE3dynXjgw/P+eh
jWMAHiAvb5Cl/jNoDE7VYRo7PgR6LO/yUShOP5BS4cE60MNd0aXzGb9kDxzq
NfSGPnTcR0YGEBPcylY0ELUTEFqgPgyCFg58I4gLeCcL4LzD8Kj3TpZzAksJ
PBlsCk6s6YCP4EpxRdBeSQMOAyKCDfNXWfrLrqvqz0GuBEsfmJjOA7xo3d41
HWe0VKhU4kbZuuo6lvXPHiexV1KKaLIJJqRt6Ev8T5r+Tu/gHzfUsLeebD5F
3cQNhOhtA3fo6HCrYN0wa32PEiahuyK8KpsTNDvAqXfJArYnwkaLovnA4Wqa
ysTgloI1/9aZd7YkfHJkK9yQLK1IauR+ODVEMB4EUUQEWisZbECRcOAFzDlN
BlOBqEtrS3d+dFW2EARKJMNqCpaAEgUMVa7Wa3LD1h0/vOp/N2FyMYTxOaqS
z1YLyVbETuPvYOdA+3egGTuBb6GZ+04046h51hnWeMoxfK0bVjEfLz2CyiaX
D6/+WH0DvochrGSwJy3DTIuIbtokoo1aLS1IK9nUwcY003Q0q+lsxqurzYZX
Z7PyYQV06wP11swuRXK7JHGWlvzzBU2QeNkSV7Nn4Nt9PPUKy02eXz/nNvxm
U/hO6uU/gHofL5h+FiGNErDhslDhn3PG+tsI2ZJmRAFu4YdboI9qhuk5IKpu
hfbGkddM20RqyVErNDj0BOMmDhrmFkeNk2dahwc+f56J/LNYXPHTdXl+eODu
4DhncIcGvbMGzwguJZzqpQ7mPXTLSbr2Jws8SYuIFgf+C/CQMCNAiQnboQTK
/Jyhq7mXGb82Nit+XqlWvn/oOwuotZFxO2fG9Yg55xo1FKp0gYiGDsBUcBKn
wAocOLuahLu9QBpAFBo0HNS5JQFxYoDWBdmyDdIElQLB45wfQBZjI674ZX4J
Ejkv5r+fLIUwWa7AlUUAFkw94K/gdrxJl/5chyEjfoIMTCPhn1N5Zhtssax1
Q5FgumSLSuZPmVKpdHyKDKSvkWiKjocVS0NeyQoBfiIm/KZNfxbh8uWSys/z
5TVIk9XL9xOuuCuQHa6YEFA8hMumsqVUJlKI7Emaj5Aru8N9Xufz/LSwFvlK
OV9KNFw8TuRdNSsrQEyeaYJdkUn3rR1tK2t7NnLw0BWVcQM5BrdEZWCFGp5P
yiKqMKfnkC7JgnOqxTjQuMOCJo8M9q9MrCk1gvFBWjVnwASCld7kyc2m/XzT
Pr8UiUBKSmF8NXvQVLP5mH63K01p2Qe2FYDLeANmQ9nRHO5LblDjUeeKc1w6
GvC4imtJkiVO04EtwDoJTTpxNTDwBK4vbOtYM0FK5BMuChedNMP18Hp4Lr2s
+EIeVItRcMzaSIK4APeIMdMPEOJMx+lefP5Xo8hMP0yN8vN0zRfzhsov5/Nv
oQbRV2FywEgUEJ48WG8r2bBsQYkgiEgMC8xSke4qrgnIDUoZ1Dk/igr7eB2m
yrI4XfKzamEG/1Kr30QV9SBVVFmT/+VIgkjF2KHVFxWs+mew6nNijFA9SA/D
EsP0AIEJq5QXFRnDNSLI4fktzHAHU+3F1pE0P5wqYdQOE6X4Yoj8qlIu8Opm
tfk2ovCScECYfNc2VJMdJ+iaq6aChCn9aMIs0fMrrkHMTufFGPcvljCWaP8I
yoyuG6Pr2/8UssxmlRdenc7nYC4a4vvJ4nrChShP+MexSa6YkCDJNliKagV4
ZAMr6Hm2/L4tgj2L9CN2cg8zyo8lzGy+XvErY5njc9VyMTFhuk2+YcimjAEU
191UNpPKZgvFdL5cruYylVS+XCnmaWST92HUwRA1VvGwh36BNm7Ihm3o6tJG
J/Iz18ZjPbBqNUHZ4qd4QnjgaOgK/EWXZsU3j4cajQYfMKTTNERG4c0lEXlZ
4kWK2bvN2fCbng42ojAVwi9GKfA7DHxokCngHqBgppoe9lO5TLacotMNb/lB
LUw04AmBRjtMbAsYaEYjLzCu0iIzdBbBGYxwgeC1fugM7QCRcPvbNokmb6jx
j/4oWAtgP6YFS8wV00s8xHT4Or0msjbXFekwpRqCAbOlcffBL99Bx66u2f/f
/8H1ZFDZ4GeEXz7C+M0514R/LWH9kfDbjoDBHNzIFOf6FAYy22ksGECZ4ZxM
YWA7czTXVcEErjNNGN8OqjJYD0ThBrpsvZo0aKkBC4rU++3wTPW6o0HrTyYN
LWsbgkrW1Gof0iUJ04RGBbbiLoUtsOujbhsoTpo0ssXkrkNmRvU9wkBUdFty
lzxYODJGHNDZmyj6LI3t0sBj8P+qbBmEN3mNrPmpixtvOqjxgBpPJsspryBq
/BZQ4wWZZ0E3Jq9rMfOMODiDhKVdc7CAjyg9eHTkZc2GpRFcd2HKedRy/Vqn
BedsIwYa7uyQeufCB1majpzSBMZu8oCzPJuDPg2ewPsUEX1s2ariQ5G8B8WC
M/XR4oxNOEiuoAcfDs7lWNxw4IO6Qoi0s8cW+Qkwr0EIylQLI1j9I/W7wJaD
zKIsaGz3f/yv/w9Xxb2UQ+I3pJWyO4z4rUEOoC5y1Wy1Oo4cxZgOYrw3iPHO
IMb6dIyDGFczGPgQxH/s4f8t4tsLKz3idoOskx1wRm5b7fMxF9zucUAkPo90
gsC5wHSVD530gYaOPbiOPenDxtFIvu+kz28fieZOoPv3ETyXT2W5Lt1lHwZ2
2ekJYB+35becs0/vLulvpXz+v3/KR27Flg5sxX6K2iE+5hxj30RmLwCzh2di
5pyJcE4Eo380Ys0Fi6PBQTQk0jsh8TbFo85KUiHhFB5Mog3d3vl5ie8/lIr8
+U3cfl3Ehm6YvLHs+tbc5r9zbg+z4JHshn87sXF8MzVl9g2P+7k8QTkcVG/v
+4rPFHY/RDc19EXpzS+qb32RzbhfgBp4ZbhMBdEyPx+lUqmjI57nOQH4Ag/0
j45GYFrRiyKcIKsm8tPS0HH7k7O8mx3AYcBrVA3+7W/hKKe///0Unu3EA7GH
4aCY3Q9ppEXEh7moD3M7HzIZsvclrti//51G5FItCKifyVbHngSMLI+XuU/I
zOYxt56DmeqNmi4Zgal1nwLehjCQYK6vObJ7VYmuRuqXLZGuskhOObxQwZ2c
4Lm2Dh7Icg7+GALD/TPTPDlxt8skYspo46iCOIfFi96QQfAo75QzZezUN612
j4WZiFAAF4O82BQKkMmxsYEUf/tbnCmJBNwfiSCBSX1yYoNHgHgKxhYQQN98
AwQ8OUlxyDJgsYATbeI1MG4Cehg6nmzpaFxbBvqOCmdkk8bcNWcCo6waZxoR
oIC7sMi/ByBSdxm+B9ojBMLrU2qVQzuO+agAynGGLR1jpPuGjuG201POBk8I
XIklXgricyCBQcASzSTUmga4hi7ZosyOnk4xCgZeej8RQQM4g6zZ33NhBcQg
BEMbFpq+VlDoB+iikBUwFiK5IOjXgfBPcQ3bAFfRUgAeuqeEUvTkxFrr3i1D
//airhEa7hm6mYgPkZXxKRinPF5ADD91vq2c0mWh0edm4EWB4b/XpJTKc9QS
NecwDmEm4HEsHczE0AWk3D730DNoGvwC+oj6RLQn6sGJukk1gXNvkk7ucuka
ugHWYgy0FJa0NQ34MBllRJdcHJHpVUw2g/71R4wamRBEALxu8P8BcZxL/wPW
ic9UDDkA73SHNzAAAgcMho1pVApiCmtAtTWUIR/ENCmuLpgEyc6hP4tOFD2m
hhY0MAZZILwnRpHdJ3mA79g5pHRK0QaxvtZoGI0Kk0J355e6aUVfwExxXYaH
t1ZiV9upw9Mq8AT10N+LLCifXbvAt0SROD1QNn+iu4XwKesgsBGY4u4JjXRQ
oSOJs02cMhiYCJOF8fbAFytBsdFqAgRlmHjWh6P3VFmSFHJ09CvdisR5oqYs
wJzKBgZSsJ0axq4bUBpoAwDzYJg/varnLwe6iNJ0jborI0KWMhmGf3C4MHDe
3eXg8TnOvGPTKcQ5RNFNPJ402WoiiP6vv3ItD6Ohj5EjQOiFANtkCp2FPkyI
AqrKGRILnXCWDxWUthkxIIpxaFDvmlW6SmgchqECKMDbQKSHrkMN7DRxmf0L
GHYjxACjWUDrEcuQRfO/fHItOA0MOLDXrNRMX6Vx5nnnk7S4Ms1j4G0qJ+k9
a9mJCJFncwyRAfY2aXRDKGaAoZMCqdqGtYBbzcArbIPulOvAYKwJqhxuLZie
WEVhNKSjwAHnMrCEoM9dYkH3W4J7iygw/OEjDV0xAtoUnuCFXoOFriHKlJOP
jr6y7r5yHp2+clf09jV22t/pLPodnauvR1+Bu0P/A+CuMoCW7u4A/JmF//Ec
e185/CobfoVf5umrSioHf+MVBKdFlj4uU2DO45wHqJwqRz8u+o/zASAF/3HB
+7pEv+4RSbbVEJqooAIv8t6LYviF36JAe4h8kYt+kacjuISV5D/922fmk/zl
l/BEpNlMoR7YjYb8JCwEtnCOgyvnl7/TlR0laY8OGVD+khZcAxD1KKhkECbA
i1SCv1IB+F400PyFxSMo5iksjhmsSyqggdNgsVE9C//aUg2MS92JwYR1taQm
Mcbp4EmxgVwOg9d0K8W1DV0FDN1NVg61KyZKAPnFzBNHDmK4m0RE2WRmtGjp
hukubBEQlyW6h+/E1KpgkwsgHlRYn7oa8dwMYhmNITV2cFTsW4pt2CjAx8IK
I3tQmgCgeNPzuy2CqW1QKrs6AdUVoARUoHu7zNoGJqOY7HpgQXOQKQrvKOmo
xp0w451KcGN7wswcHI/7TZChKMu4Z02id9YE73mKZ3SMr2NAIAl3DW74/106
ho65PoJ4oUeOpozyKY4O+xqBFbXvMrCDI6bjYHEYLLKBQyCebesaxKEoIs/e
RSxdbY4anm47i3vbzqudbWeg13u072dklqjTRwSAEecYH+3wEC6VMBM53nnQ
0UjFwAvGXMfCzO3DPGz4IY+5m1s7QKOjh0PAHTWHVI7YJAjmeEHu2FWs1IZD
kf4riCpeNDA5isn9nVlSu1NCpzDsArmzfAr4iopNpRGeOGJYjCKr9LYmSmV/
wk7pjheNOgz81g3nMugpFYkmyEFhBqISnBiTOlTUczDBRhfB4oFfCqORSTdr
5t42YYqradsdC8gR2Os5Xt510UWAiOQzRnaG0JsYRACT1BPdDpPrdE9FcQCw
BY+oWlQUrIUtE9tCpCWMuwrRewpMZ4HrA71K3gu3FzSTcJ5wmjjPYmpjRhtj
z/KBbx2OcUMRYP5d4yQyp8kpt58ShJFmP5MHx+DvyV/XnvmoDva20z68h8hF
5fRTONQPF0HeHG3EzMXoRvR+vHtEFAUi/+0gosRCyO6FsS/wMNSWtn/mAkmQ
gDkn2wBM6ni+Nead4Nu30I6elv0pOT08vkCE68/sjeirn9ud+jO7MyzxJ3fH
S0KStbUbdUfbOq5OTNs9jZ58Ue0p8OQg9nb4vxvGt+DxhV20yOVW/GY9feZL
eVH1dxi+K/I2DPSYc/1oD4FTLpzS6DRGugSQVavLKp+fb5Z84bn0/EHIhoEe
e3T8XmSXS7HAT2fFEr/JV8sfhGwY6DHnOv7fi2zpuVDmYa6ArcVZ6YOQDQNF
ZNnGyPciWygXi7wxL4l8qVr4KDYIAz32RNF3U3ZaeeErFXXFi5WV8VGUDQE9
9mTf9yL78vKS50siTFupUlh9ELJhoMeeofa9yG42Rolf54o5vjCbbT4I2TDQ
j0N2qhobfvr8subz5dnyg5ANA2XIlj8C2WppzT8/Tyv8ZrnOfxSyIaCIbPFD
eHb6AkTIr0WcsUL1o5ANAUVkCx8iDVRjZvD5gijyU3FW+SgNFgKKyOY/hA3W
L9Mq/zxVVX5aqnyUNAgDZZT9PqVwwNHJO/YkpQSZCKYlgwd9vlUEbSHHNSwE
/OFdVAJYvg8r7x7Et3iOxXeatdFxVk6PpQ/08fY3jlyd/lE97AQg/fAxFN+0
nKPwett1SLSKcM8IFokGq8ZYySKJuWnxUijNYK2vC/xqrlKR39MlFgL3bdwa
QcuH60FQDDw/V1d8OV/M8/mi+N0DCEM7Du9F/JgBVI3pjC8WZyo/X6/W3zuA
MDTfQvh2UcGwFMXpmn8Bc44X1weUbgIsw9CYtv0ILKfTWZmfT5+XvPFc/m5m
CEP7OHdG3Gye+eVqteFLm+9n2TA0prI+wnJZrmAtF/KVIkyUGG0MJMAyDM2n
5bfOuH+AGwjjoMe274l2oCd2zgY09P3J0O3ZHE9UMU8nzRVMT811Q2Kn9U7Y
AG7X8zzbwWYREpwKct8NMjqhp45Lg+ChgSYYW3o2HH00jGdc1048ydE7Doot
/2gOz2DZrWZ3KELgqtgbh66MSO5jWYs7EGRxV06Yh3O0QZ+Fbv25OUnNz7jR
f6WnYFbru93Cs1uTHX9+5WreKS1yWxYbNOhNz//4n/93k8LUdIyapEf13JcJ
nahsJAe+P+Nh2jIIwVwPWtoBeEy7z+10Hxx/BBq5j0Yjd+wEKUAfLH8+2WCC
DGC8UMfRMvc7Os4fO2ET1AI1gBfp+NnFFXoqFOq/8NH9F46dQA+kv67CQ0Z0
4OFfc5Stf82HUSh+NArFYycI5TAKaBF/OXjsGYnQ7jVLlRA8DDXxYtqEda9i
NJEsKGaa2Y1oNqbcWwW8QO8+g8MUPJxfStPjP3NfvJPcVSYFtq2PAN7bMDWT
ly083CjNKCrrJb3VBbydtpeKLkgmXowrprO59D3B4Rp8DSMO8f4B3oUbYVu+
cX3V7jZbV6Nu7bJ05vQMXTcaoVs8w+7Ze8Z//CdYVJJO8w2ArHjGqw5fYqRO
JMwdaqRdCURj55e6iKTx4w7tpUQzUaGk9MEJckqFTyg8Ckfk3dPYNGYTwshj
QBCPN+m9QDd2nF8jgWjUxbHPjNHbkN/BjKVjJ4IqihlPYTGc+hwJ+iL2DgJ1
ABxEozd3vwNR3NgN6N89WW+e7ilhRNyN2faDdFA9/vu//zsGb7rB+170BjyA
gcP/y1rwEBsPr2nU8URfBfTcUYSeo20P6zbbdO6lHu3FnGOMeQBdTXKCqxA9
Vbbkma8JsX0gLsRDdSfqIMVd26hKYZlj7DCBlc+O2WULLIjtEU3AQfzoRzxP
h2VJMHTVAotkFgyz5mFQU9D/3CcFPlC4/LE3fDaouGELio4XFGhkEqYom2CY
LIgGDHI4YvE6gQRSbqgmHu7TJ6CVVACJYTYsOYObBFDwc+4cTVncmCRPaZCm
5d+LGLKYcacp9O8M3MQ85C5BQGJpICTMI6ACBnK4tytMqqRSlGWOjmgUsbnE
AjwTUJo4CYpuEnbjYC92Io4keJuG5kBxw7N2ww9k07ThHXznxLyvwJ3TDUod
vHkSDO56V3QXOsU09uOaxiW5K6jnMS8LXQlHs73YMEfcFCMukEWmNCpcChuC
OCiEBD361I8be8S6AQ/VxPW7xWg7bYZvkaugyz9ARljCHxjPIoAkdeNhiWM+
sVM8OkmcI0eR89v0ogT3RZjNMDDRIh8njzyQx+7FOZNKCCd+UgquXSlqrAfj
AmHWaEZQBbUV3p5k8epsjLbm/Eo5Ezhld0FcJGhspGulR8Q9Uh6gmdGowRdU
lsHrXGEhH30jjXInXXwshI7pC5wTlKgCroxADo5PLK7ZuVhwHNnP/mU06MO7
QwEjdbLw4X0BGtpPuQQkgrPqXfntx4qCXwA2fp3qDm4OS43edHB09BHY39dL
7AkbHbzcgDxn+Y1ZTDYTV6Fb6pR8bow8U1fOJL+HlJLuJENaopAGCOE8uoLp
3PCR8Svu5MS5YQJS3yDWyYm7HFi/9D4GICpT/B3JsRddeZgB8a4PCdy0Yp6X
MbNV6hCu51su1D/FygvOotcAIwYBzNd/g8qgkKLbnrI8HHgbAsdycuKOTlBC
F8zeUr0yxpFhzBpmo5JoRB9egcfyCigY2QUI9gCzvCnYAJUUXoylQnZIxBRY
7Vl2n/HA+mXSCD4sOJ/54bLQZZ1sdRQOSIuZdyUak1Qu8N4ttPgDbcLWxR+4
qt0ib7HTRQOqQTDCpOO1YBoiJyxdJYRUxUIZhC0UbIQlb9xMoOhvBfCAqSZ4
v2W5ZaYRrmz4LMX1FcFCJgpyLk3izO4s6MYCzXxq9RuwVh0fnX6At0lw4eqo
LEFNgGSD58HRSzquaCwUh/2zUmintDRBIFcvDvOu0brAWQGq4G0lusUNr/D2
xBp1FR0i6Pwlb2vyi00cFmVICtyoUXdvTlMdiiGNznVPVp5v6YzSb2d4EhXF
Onhgw8HVmYs7kf6MKLgO1Kk/d9gfEuBTq3Hc7LQ4x87n8IoRYWCt7RKtfMWj
PxuPqU8tOhbnFlE4UlMMJo+46/nWJDez8R7L9RCnUDS2S0ufGcIS7ARekScG
MoUBSAF58J6qE4bZZsHjeEPl1KPzH4NW/3owGjdro9ofLPkn2oD+fUTWEwvq
Ft3CQBJLf0N5UZ7heglnB8WtBc690Mqu2WE6HQMWvLU/kX+mzE9gBtkFRyCb
LPkJn2kSaD8QFu1jV9tRAnsdMRy8RDABziaaQG/xBLiQ2g6wLAi9+UY2ogLU
XTHr2Incdve5dIPZgBK7LsjmFpiaRbb+cdm6+MQ44fiP4Fo0ASlFYsKc3tfH
IouAFgoxAdz8JYYQi+wOFgthJ5S0O4tUFGyT0UwiUwx9BoHpjO0UbFwdqY/N
6Trk8ZIt1xzUz9gl11NsxBSkz2vwtUt6du1PwJBqvDYclgJfHBuzyJdy8H/h
XQBBlVhOWy3t+rdmmgXhW7y3QTuxASsLjShV4s0JX84Ui7Sq4LHrjFEjX9dw
ARJMYmyjLQrTYrBMOSDCwOplEvozBx4JK6GJouIJNETRtQF1ahghvQGQbaAt
btpTh16KtxycFckkBzGoHfXHoDlstZp/ULVpOpKCMrsBnSlbyuICtaRNm97J
djwbT5Ej59OtW6qgADYKYId7AFN+2Ocp+6MKoyKF5iyf4q0X137zthr2U5wx
hSgRFRaJZdAsk8yJkcDD49nANNw3Aqay1SXzhXHR0MwP7HafY6vRLVR23fbP
Pj+4J0c0rB6GOEfRdw3PhsPLP5ncHzyPK4z2BDNLpL8Ykri0/+A+fXE+4vLg
c2S47tVwVLu8TKlSpPGtw8emqXj/pRtVzg+eQkj7EI6PXb8HRwIrwJ8moB38
Pahdwd9URveRoogYzNrSBsEsK7CYKamAxJ67iya6MHNNEDA1KReAcSMxCezI
CzpTwISEXhh1dZ2r4AIrk1nYl/qav6Qecg+8Z8ctQnKzXTzH2DhqY+ZpwuVi
jYnAkhi1Wrww08BwAOZwZ46nrviRm5WB3qbBu4oCB3PMXnLsnvmOFU1ljCos
TWdbw8nqgNwK8oPu/Ov0Do2bgGxFApUIUPgHdfPOvgsNvYfxpWB0hL1wEnR8
DQB55z9fQz29rwl0z0f8w0U/jvvnm5pA9ycnfTdrQ4/tQoB9+hXHzVOFoLjk
9EyOQ6N3Ru41Q2rENmLdNxqezQY9O7Aa/Vuuc8/9G6U/8KEN8P5tJ4ndFE0Z
w6YiN9iEia00TsInZkAc+4bXv3GDHrxr3bl7LmBvMDxubJ0qYJosm2GCZOBu
WjHTDR1xaWoRBHH7dNcLdBk96rB95I48AJ1uNXNNanFyn0bN4zeZCQvNWfQq
IOCza4DFN6U4XRGL3sUz0ZlxKeDC9My2f6PyxLXVHJMP6HQYnfimiCz7Yged
zrCXHvVDpPnK0pyQncUaSYz3f0p7oxZx7eKPQHdfQ7v5KEGxYCxwhMMpLRY0
tdMvmv7pO7CsqPJ1XZc3ie9a5KH+7x0RnkYfl1LLL04TCfVbmvjdX46C/eOV
YLrND8sXW+Jl0zdI+i1NAjvlO2rIFfbOPSnH190X9yBBduT6L87dNsTBPUpC
o3atuVsQHmwGlLl+JvP9vH3BENAjun9IF6XjBrr3QcO6KmQcBs3vsKJjl+Nd
LZYOTs1XbmBrZlqRsRwE3V/+ayTfcKPtck+8RH858Ewt2pNzxe6Q+nmvMnm/
zjn0JUUBhUKrgd5nGOkuExBaUCztjewq5m3ow+th2pU8jt3F2O+r7wxH9x8v
Sb9yZ1R4eSbpN6FQu3C/Cakhv2nb0SZupGba06w4n3MZ1rchzvFI2tsA8Qx0
t5Me2OHGlgcI6Ha7Mu0rF9DAbncdx7RMe1oM/BsBc/3sjslrCcNJXzTbnE/W
kH/ut2gYxN1DYKQbuqT7ytH6R66LHPMPxlEEA8c8E9hJEkVlTVC0XHqLbycJ
M67q6F0eFCJ9cOZgytVIyuE2ncmuvjpvdnnlT1ipogdL/ehXrklTjMHnd6Gz
lyY7l0EZOZJVPPUg7DSQhRnU/DxLbFsTqFZzXck7dsyCkqRFdyMpAUnwyii8
wpM1WZMpSv6JEHFPhOjJku4c2QCETJm7FsETQe+Z8WYYBcTA+zhbgHGJgY+D
dcWdbZYv3dao7btV8dVEYArMdGk2edlkHh4r949GJ9/bFFbXFS3H2xezxzSe
MLOKJbTXEgvIcqiF52W2JlI8Az4/maTcHrEz+E3T32ZyuXK2BG59IR3Kc+zf
C08ZJsuWaxHCTtJxC0XcAhZBKuTKXJtMAvh4QQh+OpX9UzPuy8mJlxblL1yn
e9bBSqgskdXxycl/QchOtbkg7LtW1Bma31Mc3KILt7QHl2YjDIDBkNnIm7rf
CP+Lz0fh6YkpqIIZxQSTmGlLmLEQBLw0SCM7snQKvAT99KiDNooizjswrtJ0
wd+K70w/jGsxleVnejaVK0Fne0jP9G9EOJvZw7ixZwl9W6wIJitR6MnJl5iy
ie+K7dmFnV7aipIu0gDHbHl3BHd+bxGDobuz3zgiN28Y8mYupttEJ370lBBn
lCU3wARGuGJ3oO8FR+0JhYhr6jEMUHDX2B7Lvi12cvvrtzHojrqN2qUDvwor
y2Ewt8Zgoh7y39lDcmrl9si11yGLUHfpVtjvlU34TjZRPCMLsI2f6zrQ0FvL
e2ju36V/x5zmv7UTen3+R3bAbsz/2B7UH9wDuxf//T14XLEfOA3upaOG0Ih7
R1ZCDEf/nt5m+sf1FEs5dsX/HcQrfU8nLBlAuJdeq9m97Tn9lFL52H52zCM3
U4Df63tlU+W94HMfCP5NI8xNOfATunmHXH2jm4g5/6lpC7LVPbTi8fpJGQoi
8IpF6yflIkiK1k/KOpAUrZ+UXyAxtX5OJoGkaP2knAFJ0fpJ2QGSovWT8gAk
RuuH3Pj/frR+zt3+pGj9pFv8SdH6Sff1D6CV3O9it7tz0TZlcnCFOHBv+52F
N3amPK+5+I0dFPc76F03W4PaqLVnmh7qJGw8ejfYvT7/3//7vRaXU84juWHH
rr9/d0dRQ8nHDiUwG5VU7gOGkY8YRmjKS3Gd+EcD3sZ8+FJEcHs8uDEv7OzI
4zEBnp3LbhJhJ5m1xm6/sPTVNIG9oG39gKUtt54Llqkj7k4BgGAgbSi8l0aX
/3FPhEVHMOd/nLK/m50/aAzcH3VBarFtsj9SJyd4KLnlsPpC6ICEnqnqJoar
pkjq1IE5pJdnKFQ6OOcBgGZjVRRwMHXJPb413azDAjfD0mQ0NLl161SyOWph
ORoiaNytBv7mn0zuC33hi7LI0jVzXSVLYUaOafh6OBuAzwLhsCDkBJPdAvJm
Y+9iC8sq/5Vxj5dX84vLLu/Oxx6ZgvNwBkuW3PuNVHF+4vE38sEd/nAnkUXs
h8FMHA5+/gKgk/Qn073GQ2nLbmbj+TTGZLv579ltjt3acQdrxXGXsoWHarCG
/OyzQFHeuRsOfcTkz0+aNp/OdfhwjcmpD5x6Z/q/rGUDpMaSRr8FDpoCT9NT
kCmm9wjviLJTS8To0xcaUxUOS8XoPYVtZztXUuFp2kZl7+l3XiQY45cOHnSl
aUMvcJUPvmMxsNkMn6vwmUzWiV/Fpf2l1mt+RFhsPlPIeGD9jpF09GryFd71
oTQbtVo79LIICdKK3iDdodQukGZzoAfsbklCKULPI1CU0J//mbQu8ZkKn83+
OFpX3knr5oOkrwPHP5KSEkSVHn9Kupz2avSWipVSoZDKl6qZXD5Dr+/+RHIV
kDUzQdbEfANFzqlGgCMZWoJC7IAU2IgC797VcUxjWcf7yviZ+98xK1abK7nM
4AeEFwvFTDU8vLhyfk4DljaEJtx1CiggcnXMIt2uDUdvoUfTTU8F0/L/GuvC
QgHuiMKxlK2Wc0lwxAbHuyUeKIaCNKj1fFATQTIEFdeK8xf27Xdd4HOgpwof
w6xZJ15+t1jFj6ZcNinlshTF6g6KbWECimBBpLdQnLof+n/F81828w4M4WGg
QRSGB4OxY1N4B82TA7UCYnPt7toZ74URZ9TEwHhfFuwAQN+u2bVe2NWpiBIE
oagd0bNeFM96ceMJRR+iF6OI9+wpeGpksLpfJyeIF9ji9J5YxLGNRK8D+Xfc
ZXYbQ6W90Yo7rCu3WBK9y23513oi8aUhcCwJAl5e9+qIBSqRrAleTses/drC
dGMhvfz+1JzH0nzUaTk6cq5d7V3KRDtd8VHzzfKlbrk2oJdu6J3lWT75+LJy
GayEmFdYgrlix5/fqikUVS3o6HCloE9+TSN6TWlFFB2v5rJcE1H1g44wZ16g
5E9EcaC3wIZqAxWdR4G6QFXuU5GLhbBTFqgctuc3SxYflngSYijPOWvAqVIX
SOKEd4hklbIz0J+Z9qeUnacyXhsSTOeinVOkauTW2YFm4F8G+6QMGIjG6IbD
eo+OambwNlHsfVOnWEZshTdaj0xwKv75bLxLrr1sHQYJ3BqnxUn85Cofm0/l
c5QoZyPb90DfihpCPJOl6oks6vuxOB3VQS5zGG/nlLTjpsASAiW3EornpLVZ
gmWYpl6oKNbHY1kx2O2me3oTLmqvjeEZqVWK7z3wpAtAsMQ540CvxsuKVfQ+
dYr2AX6H68FoxBGgNKJ87zsnd4obTS75l72Y4J/KtLYmvcy3IGRp7oMIlLEa
NepAlO6U2+o2q/zEblNO6Z4U04uxF9J3bvUtaagbh5VzbOhfA2Pd1JkyW7Nb
r0AbceEWdNlLQhK1VeNoEyf7Q80Jekj3WD4ZoMCeMBglWrRrElq1O/VMT07c
MAu8nh+oJ3lyghEVJyfRlGFr/1868dPnnxLNh9QM0pCSxd1T/x//speNK9BJ
IN7WQCkDjaiISRwve/qRcunPMBxVnlE1wwoZx0TWsCLGMEYwM3Dk3hmPEwsE
BAhGhOZSmfjjHdbMp0LyWLLTMEez/FIOUu6w4gcVGsdM3x1DHgwqN6r1rdjY
iIG8K17tAwYRtif67j3iYTBFpHlUi7YDvGvHoYySTLLGyssTvKR7smMnIKbv
Z1AqWd5IY1aFzzhzq06wsFhURrA/vyeSldXvprGsSOSpRbyDCw+FvcjIt/pl
cbQhicBxvKvmTe4sTy81E4OlnwqW5aUfHqijhRlhLJMo02DZRbyDTwxtj16H
0tgEcEfif6KWFo9XxJdE4+ku9LHjVglu4p2IbGufdEOeoYWLig19LNTZfKbA
Tk5oKgqTJU6AieczJfqcz5SP6QCxEC0zZ+7PaFoZWZSXWDx7qeOmmQQksTxF
i7m3mHqdoLGUQMy5GZcE6vIxFtwVrBSwnx8q8CXNwRQ6FuNZhoy9VvTcKzCn
n8RpCgDQHX/dMGC9Cyi3jlkzWiOWsYiXiQCnzJxuU5Q6tPBlmDCmm8KAFUF2
yyZGJjTD9CRY5V62bC+pBkzW3HLSbmD2GidXl1voc+4W0kZPlx27xVfEDFcz
psuF4V6jl5MZIAOmj6ak8OrGuTmX2KBPTiSZpWqApecmi2GJosAwO5BAyaUd
6+7k5PZAHfv41QJeJEpB9KNZqeTwraF3CI6v3L0XBB8XRP3Vs+a4fcgHc02F
wvKD7m2gMnRAuO7vslAaOQdZbgY5mu7AxHRbzc5OdqhPf8w22z+O2ZUuwdx5
OyHWGu1E0c/kxtLtYX6ujqcE3MyDeD3s0x9zyxRdiHQnyL8/Bsj7qkPFyZsR
8yif4mp+HsMdaEIstED+Qw45++ioz2QHJsly8kHFp3BAmBI9C6fFuNn9aeSY
PlvUKM4+NfBKq8K6OcM1feyf7HnrnPs7Zh90T7Pp/U4n7Z2AF+JGQ8daxuN4
likDVwdLM3R4Py5F06QFEUAHy021g2fBOKlDNm1DZ1LPssc4QzGtAqmN/Xkc
OZS/QMqf5Y5xZt4HIzh/YSj546g5ySeakx7K8gFNp2iigVALJvOLKhTMqrPv
3ESOSAEemxJzz4zZyZjG7yZmnhMFPFI3Qye7d5l18cPv8U6il3fQT4Id1S4X
bNdl2ddi0oE6KT/fymlJ03z66Zf8PG2BTDT0QLnvarTYf776uSm5X7OnudPC
aSn8MH9aPMVdw/7+qFEofub5+B5CnTlfu394/wVAZ1nucxyrUikHLf7j//rf
HGD/8X/+L+E/EEruDSgLcb4Dhf0VhpJ/E8of3AEozh+h7AB4uYLxPr2bu7OW
yqks5XcnX03xvQuLSk8v+R+WVnb3T72FFp+4PZCu3W/rIHoggCAup/sPy+ee
Pv6h0BV9lrI21vuzxv+wjPHBgf4A6KGBRuel/2E56YND+wHQQ0OLzXz/w7Le
B0f4A6CHRvhWbv0fllc/OMgfAD00yDez9/+ofO3BQf4A6KFBvisr/A9L+B4c
6Q+AHhppJRW0IqBbZkcJysf160Jkw/qB8AMDizi+DOj6X+nuv7cBB5PbZorY
pBr70Euq5jH9hLvTAibkPe74K9RWjNnRpfbhqZdS8At1Jvmw07pZCoFTM3S6
MKXQghh+XgtJF9OHmqaPT1mC0B3LNWDujtjBP8FdNMBlBj6i5ewjGATjrbj5
dmLIbg5vdL0+ieFFEGsEuwl+I18fv9dTdw5aI31/mtVXwrOB6B29t5MhB210
zPOvbf29jAnRyFQOB0v8Z09qCjkMXSZ0UkLnbCcnHuLuPhmeLOBs7k1jkDHo
F28Nyy0W4DRC7tk9LJ9s6T5rYPPTiedgyXndgg6n4ZSbO3vfH8ATBqE57cIu
ZXhHkxKRBc3jBipNhCsxQrwHAT5TCOHwJrrB42dvkuCHbhDVi5MJbwnTPcLU
O8XPZe2ixcTPUFYx/w0OCUaOZThE6I5+GU1y7osCE84bwru5Eh/xTqP08XtR
RBeEYvj2oQNu17x1roFn04K2oJu1jKPcJBl0Wv30GW9vNCIvD4CRrZ1DFnbA
fUKBB859TUydveUkzLpv6LZ56hzPAZrI/t59gVMn8CoQHjWXZ3OazAsjVaTA
7YNvCRrjPrH89DtR73//+zFLfWoQmmcOkzufnHSAK60Jxr2BSFiDcDo5wSgh
PA07OUmxMjBn8srJLI948pS/RSc2iTfdg7QdVE/xRB6UBS3IIB052+8kEFHE
8gfAisSdfCduIU4g926HoyPbmLFgLTwojxe7TkGSt5iQJjzL0X+zk333pV9e
zglpSrMLNizUjgZ1fXLyAboRQZTkmKPaomcOmPnPCbWLGReKXHxPTxVY8kZc
g6BkPYlgyObCwbbLCTOnzgDBbQmaeNxeojg2g9vtwaoWtZ3e3KI+bmEYjCa0
aakYCps6XV5UkJsVGzMqUw3mtXKydTubYuTFptKeHlLOsO6O5hyLuBl3Adkt
Pd4EloO1GfqGyVt2BQeXBg7Pu9jkY8UYH1uzVU1bojVBDFWmKchNV8wLCov+
8kpk4PGWJrFE7MRJBnzq9eOFizB0aPQa5rcX/eTQEzpvhgyUIBIz793WKhHw
tAWkDoOOWdFY5iCa0s3bMXRSN7osFjpWgY/p+Y3oaF63GADCmdDc6CzbI74j
7op0917dc4IgY/nT6+zGehRw07W7Ka9T3NA74woHGOwmZJ/gWQPLoycwEUYT
SLPk9s6MUtECsohNn0A5088s7qNFRwKvXZ72qMVC88jUTcPuFE1gBSk8vmT3
55ghPtJ1Bff+Mev1Xtkoz/DwFodngdCKUl9cC8TXdDIhtPqSgbniCHEVHS3x
ka5WQNcU88desFRYb/p1Xlj5xXBpITd8KHDeB0izg8wvU3mDQp9VYGDFgtwf
bq2T+P3ld0XTsM5pnkZelkBgYfGNgJuEGVyFNOByzI4EdbppDtOG+e5p0ktW
cAUpbVgs/hZwQqk4BRrR5Rsu0PLGpri7DBB2itLHcKwd4p1frgMHO1icC5kR
CIcMiwWB5k7GdlaAxjttpWAp++CqDSQHRL1ka86ZrV8k4l9vBhxSY3QAXgUN
LyxfJjgVTvaxpTMYKrJy6smDQIE0emNp35o6xuJa7KiM8bTDBd4CEj0VgEIN
v15S0coKd+xk4A9ND040AFDdklviXJdF4lQxQ99KAdMkIO08OR4xRpy0U2ad
ePZImAPXFE8W+esoiPh5hFV7BZbfZ89wdrNK/stxSPQapfYXky8a2LP94QWL
MPEt1tRRe483Ph8d/U9UW3vTguZ5NpU/DS1AD0bg8mRTBglP+A5RFBVYE/mK
cy4nTzENKKo9oqByh+eKIi8xTT/I4xXail5mZaZXnKowTpwpXtEktKYHIoGO
ra2FHFy2QYzH8CtM8om+wY5I3i0/7Jy9+MVyKXdFEMn0gnqBJRkTgQrUZGbX
M/pGNGOex74U885EnYOppX/EjUUIZWZIesKQk3S6ttwdDFnxMs0CPh6LhmvS
ebPEKg6zuhqmcw7uF4WhVNDQSQKCu+EF4dfopLglwAAthxVSeMNRVARZZRHp
qiC5FiSL6KUeysxmo3fUn3+WfxQ41o8NozeIs1+Dwexu5aydpoHSUewwrrJX
U4pTmS1mUt4GG4Goy7lgyq/ByKbAGqahw6HqYrT+C1ibM3ZQS4WnzeQZFlvD
iTJD6GqILxu3b66EbwgPaDjTkf86HEjk1APCEnIeS7M9iEhipfCAGj+mNR+d
OA22KpytGotrDa8H3caQ5iGguP26e6H6yDvOjK+4Eah87XsJ7qEmXUhelnNG
QwwoEYlXBXv/rjwi0/MKeLp4vFX5IxYP3wpzjr098G6gt7Nejmqhao7voLcb
icXM1NpSEMHQzIE7eAliQTMJi5gAL1DgGigGwbj1glU0svbvn6MDv50A4/l2
KZ7PY0PAe8qMdMHJ6Yf5gGfE3cdw9faBgHY0PjGsO2zqUE3Bdi0MNbIAux+t
z3ZLACsLvQqNyhcRyy454olVNUN5qMgLKgwnrnpHZ8ELIYQ5kjBYX+D6AyTp
l2/dzOfDd7i/qfkxagIsyojJoH2LwrQnNAj+FzZpojNpzrWu4EWOdOSVwXQU
l6R+YYf6Ow1Gpjj/5z9M1HG10THGHYc6OKaB/U7VPUOAgfhDpj9T+nRqkhc6
cJasw7sgw0+oj8Zns6UML5u8aZsoDtDv5C0duBa3skK7XFTQuTdLeefmp4sK
nwc/h5ByNp/LVqdlkj9G1JDZpiR4ORUMa0vX8No3Rcr9IO2E4HoP+Bzv7RpB
V6Zzb73K58p8ppDJ8LYlpmkfoKvkRfiqKn2UEjA9AjHTe0SDRu4iCgnSlBxI
3Hvoi3ToQRTwRnfQwLpOX0Jf+pDDEEXZEJWUYtPH6R2qHkdyBWWjo6ODV1KR
Kz6dEbAJtWPuSyMkNKhI+RS+N3vs4xaSMFT+pCTiY0U/5+ltIJgip6YesAbR
VrKha/SeP5/hK3yOzk0CJHLJkADuoKHBghzsroG1ckxyjDk0nK6y2d174tqL
LWjwmPKfw3ZmulzIVXdgXFyAm7Q1vY2AQHb4ZWpN5I2spV7Y2jLT+eyZsnkx
Svq0s1VGW8O6Mm3hZhcrYUpA1oP3OXSt+whQg5bVGva12QNRh4aemT93n7ab
9Q6opgwyDVTCvW6AVA0ktI/FslIqSOvuQ7vYfcwUXsryrGDX17NdLMFeITJe
AsOTTTDrvxHklzY4IBoYvVwxG0hgNnWepjRipSUZTwvT8MFOi+D9+MgW5Sxr
oQjmHKyywNUgESv10b2g1NR9S5taaarCAjKN7mXzLLSeXe5MlzLFAiXIubAU
HIoM0KX9H7h7LDtH9cBQF5mbSm97gHmuh5nMgAb8Gj4HIqWel5R3cbtudyWx
zBOWtPmtlf+tkv2t1vqtVfmtUvitUvqtVfyt3vitnv2tVfqtkvmtVna/qdM/
cr9VKu4fNeePuvuq1qR/5H+rFd0/as4fCJl9k8cuau3f6tBpGZtU3VfVHKJR
a/xWrTudVr2+6kzqYmU6ug1wUJQIy2UKq89h3gCZjjy98+1hOLkEcHKHZa4n
XGPQjJPG+/gm6yf3Lf3Q8ZzBI+xGmqRmOHASNwT/ox0l4qH9Jrjce8HlmEqK
smFQI0Wb346ZQsCRmckYUR1eLXTDmL1gQsXN1oG9pjPldKaQDh5k8d5Blsl0
Ee+dX6AlMzH0BdHohu5U3vAqGC3gFoO2klFu5Eqwwku7K7yugFHTEawrUDYj
fbENrOcJvgLfj+ohC9/5WiObrVazVOl/cm10RdBmNsbJA9QOPf3U9KBUnnvP
mAIKXlZcC2iHLakPgkbYhNBRKGiusYGC46yBXbflZQuGquHhPt36Aa93rkvQ
eq6vefgfXVsY5Y3xI5IYujntPDBTGI1P2A3qmfs0IUJpWcqWqpVitlwq5P8q
/wXMlky5XCrl8rkKJfKXYK0VTysjmQNahbilaw1WZyWIQvhij8eLdMuRiSJg
rCuysc6Ihg4yq4cU4DDcpIDXeGZAsJgefU1HvbQVE+wK18wEZbHm/V1OEM58
NNeFrGJv557i0gR+37rDHFCNEjwRh5cuczu5BBAPP19NeHh8iBDM/KZIzmUw
s2hmPphCzxJi1Bg2mE0QXmKmuMaHtLuJIZPpwQUVYfh75TFxKaGrxwcuv1OM
aM+ZLHcDppVlq8HFo8/MFE3Dh3twOL0pe5EG1ed8ync1Eaco4HvhRguPR5o8
3hnncaxOzVcY8/bAnJiMMk4Ze8qlGIDAm3Qy5Zlm0Za0pDfdM6WLdmCD10wN
VI81L4XJDumcN+Dnpww7jWIArI9CsVBMLefLsJlLhwtCJQzBfUqNkFiWkolh
ww821YpNQFTsWbayFgiywOQVmkhSJvw3JWppZPE0c5XQT0qzDQ5gZXlqihur
Wi0CZ2VTEst5hLOGVCpM5Ndw4AY+cQxk6smbaVsTwCtWFIGHuViiDADpKtmi
LPASUQ7Myg6RuyMg807SLgvo69FVNk2FSDomnVBkXgPjDf6zoAt0TsyFvbV5
eyu8rmQVD/JXoQWyQydTfZXUoNAzrRR9xpZ+WqjkdKVazezSFy9JBoUTIsme
0YYUTUbVdCENgi6byeU8agbgyFMStJzlFH3AbsOnK/btdJvp99SXFpsEezYT
NNsUdvp1HzOcYQiH2AfFgQ6e+1K2wPKUXb2Iy4DeCqUaEH+Jim4DudY6vwVj
2MSTT0eF4EnIVA6jc7iYzRK/gS/S3rc0oidw6BApy1jMHvXAl7psBVOmmUuF
PmEKaUN/YYqpaq5YzdYyReDoeoMvZrJFvl7LN/l6Nl8o1/PFZqlCDfYvirDa
cOHJo9OGz1Nz22Xl9I5UZYGLGBgHWg7kKI/ph3i8XnpYA7AR6HN7R1TAE7Zq
0tlMoVgpFav5wjiby2UyhUyWGR193Dqmq4E5trIVyvToPUvJBmO2Q0ogrPlB
pFanpVwuy+dKosCXc9U8XyWkyheLxfIkL2YmlWllZzleyr0+d9e/8rtXZHW5
WjLLxF2TYYPAVTpOjTGGCk6zI0xAw4GzvtpReviI8q+ZXnRLff3qtb+hDUAp
AHEDVKS/U/RUTpBTIMwoDu4sAe14PDoMa0bEwWRqg6aOOqi3HWMRz2Fo72gW
g5kbafqaeBMXFUv6ry82MbZ/CfOzt70FRnxCI5+2/9WDTyGJgJOhgBEcNBUD
D+mM5AqZSnlvqzKoqTHMh8fTbj+bIV5d1tBCFjQw3+Bbw3vHjETtGUS7Z5rt
bpbgS5rhDgvM7VEdV42CAVnScTATQ0DsOk+oXUdhODEoIbTBskTZhFCdYBNm
yzQEO7ylIbIHQA0GDJBZuRSgEzwnLgRfw7nbB/EbCqXyjgAXTUkLGzIpfETb
sE2QcSGXL5ey1Vwa86TNdGM7zuYz1RLYv37vOqhmi052gCyBh27Cyih+ZYzN
JJPDvDS4i2I6so2FbM4BUzfrDtggckCDhB7TbubCBHNf4vavDMIjvIoO4CCL
IAVfha085ReCIm91g82NsJgErWz6k3lvAYtL1gJKB7QS8CCtHe/NsCCBtyJy
+yqXvfA2/9ZgGRDNBPNuCjqQggObGT0uooGkIEAYGAZKABpmQn+Dwp0ZAEcw
kSXY3uSMgB+QLlVL1WyhzLaCa90ebnOBKxRMiqU6z5iyc4Qd0WDZiV4aLB14
QgZHjx1JMSNwC252fdg9OvJ/tolEPcNrDGpiCRginaJPdTwjMgXV4qb//IfB
DdHoMeZEpkml8PQo0Mxkh1gLlo/aO522dDzq5RqCAQYh15EV6xTj5GwazY15
l0DtLoiJEZXsoA9wPYVWivSv5qB/ZuGkjUY4ctxJwOBkG/TSbrF4R8nZFA2w
oBPXif/ysprjsReeZ9PzZzzrhmkx/Yh7N2zQrbp6xKrK0uxexBJTp+zoD0MQ
aTpEL/fTZMs1Gk6HgDcNnaUHbNGJp1loTSiwQDbdQ3/i5Nzyr3Di+VKDnhYy
v5LFsiFoFqDrPT54CIqcQvNILYm334khFDRffIKzYBqKne4ORm3vZDKUAsM5
TfW+cmLkAzzq5Iqkd08n25106m7SDC8nhvMhO2xHpN03qCBTLA2He4IbxIN2
Gw3bOQwN4OCEGjugZYPDOtzByDuGgMCyrKDdTHNULHcrcB86tw6h6eZSYCER
LOQAGQgwWHOfTk7IRlRsVJMnJ+HvMRLFiVCPOe4+Zhm/vP2V2GK2eN0gXS+3
s83nsfFsVrqZi1l+21jmB8Iy80Ba6cBGzfcBOk6IlNC6q0q3bd2q3bx2NGmR
y7/UxXV9lBfMZEjFAUqKVL6zyrSy5vTBXG3rllKqzR4rz/yw05HXyZCKA5QU
qeLleUmumitd1ebLbb9z3yfPvfK0pz7cJEMqDlBSpO7Gjy9nt4/5aWsttNfr
7bRWbZrzZYdYmWRIxQFKitR5eyyu1U6nNTHOx/fFu9K2Raz7e02WC8mQigOU
FKn+uPE42oqzzMVZWZxcCHa7xi/uZg+5Zz0ZUnGAkiL1dP58/rB8XD8Vtcad
+jq+L7QvSg9yu/WYkFJxgJIiVTD1/OWmc3390Blm19pqbuvk/n5GGp1FMqTi
ACVF6qZ0rorFyiojZpXmXd5+7j5mag9jfXpWS4ZUHKCkSGmFHine9Bur9Xwj
ts416Z70t+AviHpCnooDlBSpCRm8Xl2t1j15uhhMz/vTDRHP9M5y1Ewo0eMA
JUBKnMKv2+JjR6pmlcdn+aUxsqr1p+1d86pNbpe9dyP1JqDEuq/d0Av13qA5
vN1qq6tq7eZcsPrP2oMwS6j7YgAlRWo9GT+a1d6TVLWrei9XX/AVa1Werh7O
EiIVBygpUvqqMuXL4tPFRXHwxPfUZ7HUnd8N63w7oUiIA5QUqZx9awvNbHM7
e75q9gpnozFvPE7WI/k8IVJxgJIitaznq8LkKntjdArj2qg3bpUrq01/ZG8S
IhUHKLHu21w0Nr0O4Yc1eVC159fXimJcFNTbWkI1EwcoKVKj7MZe3tbXL4+t
+rDTGD3Mhp2HJ0t6ea0kQyoOUFKk5oN1odRez9Q7Sa5OX57U3PT5YqJo425C
NRMHKClSt2flbWu8UNTBcHO1zXUeStNXu61rzef3C883ASVeffMl6SoSaU9b
Jb36Urqs3i2sTKbWuEhIqThASZGaiTn5ObOa6GQ+HPOrbIYfXpnKRnhqJDSH
4wAlFp7XBbU2fSl2zp+WVrN5ZQw1qfzalB6yCRk9DlBSpB7sc3G8bZ33G72u
/Siucte98kNTnw0at8mQigOU2J666yjapN1tzXmxf0N6dvPu+mVTfFzdJ3Sx
4gAlRWpzd5tvlF9ur7WZKC/L9cLTdbF3fjuqPiRUyHGAkiKVnTXE/povX+nL
5uD1tf5ay0vt7kzPDxIaeXGAkiJlVQR98lrPlwvKvXz5atwZ14PH8uLscZtw
+uIAJUVKzd9u66WHy5vXjWCL5Lk11it9rZC1h91kSMUBSiynXjov4mRysRLG
+lmLf241n+xcIT+b8gkVchygxC5Ws3JTz97fXfKWfqWvzm5yo0WpqaqklVDN
xAFKitTq4Sq3lKdPxbMHsZHdXK6H08uGdiu2bxNumsUBSopU76z9IGuTSvFh
KFwuXp7rrblaf2qU+2JCnooDlBSpZ7N61y3065Xtozqf5a4nwlM9K+Ry08uE
PBUHKClSmcHr9eD1YXwnKY/F25tx776nbp4UzXhOKKfiACVF6j7f62Tr4KxN
1Oz9bX9zdiPPha6YfR0ltNHjACW2p8bC2VZR2x39Un25Ktfr4uOd3uGNq8Te
TAygpEiVh49Du17JX6hG9aUxyd5l29WCVr3P5xNaCXGAEvPU8H46yz1etWrX
1vlN+cmcZjdK4ZqvXSfcdYkDlFghq9OrNT9ZVy5M6XyiFEzhslptvxZkIiZU
yDGAEu8Ob+XpWeW1XxTWujEZD7NXg2q7ddt6uE+6OxwDKClSjcf1qlcuvpaM
UVfK1fJPT6unc7WzuZYT2lNxgBIgZU9V+JmrbtpPD8VGQR+eLZZPtdXDaFx+
vLzP3b1//t6GlJRWdrazebyviufTu6Wcb0yrL5kSma+Xj2cJtV8coKRIDc/G
tUwmWxL4i572UFucWb3bjb54Up8TsnocoMRHRusyf32fa9TujAx/U3+tlkmt
t6mPtV5ClRwHKLHjrm0nojBd3eSafHd+Ox3d5XKV+5v21TyhjxwHKClShnp3
RdqTZ2GTKyn5rFZcylanu7m+WSRUNHGAkiLVnM3PpbP81pz02xe9G1IRX195
S+z2XhJKqjhAiSn1dCmIspRbay1LOF8PJ3K3O7Xyo0w7IU/FAUqK1HjRql83
r8zR/fNMkCbFjaY8V0rSai4mtKjiACVF6qWff2hkeoLRbtfyw96kvry/P7c2
tcZVQkaPA5QUqcXi+WYuF7ar87FcWz8a/XVWNNpzXuUT8lQcoMT+TH0hXVgX
ryOr0K5m75bG9KKrSTN1lEtovMQBSopUx7bHtbadzdZHhrS5yHcrc3Wde35e
VhI67nGAkm+babK+WdTH45un7mre1oqacF967j68JrQT4gAlRUq+NxuNmlJ5
fOKX16Na2ZSvbs/MqSJ3ElIqDlBSpPjOWf92UGys7Lt78bo2y5fF4Wat10Zq
QkaPA5QUqUvt8rFVnpzdXKuNzd3DS8m05GvrYi1mE8qpOECJeWo86Z7Pr6V6
4Tk7y2ji66b/tG4/WA096VZsDKDEZw7bwsvdzfnN2aCS4yfm4mZ8e9YtyUTJ
PiY8c4gBlNieOs+b48e2Nq12byrl0SonZl8K03xpc5GQ0eMAJQ4sub/oPT5m
H8+yrZw8HHe2NwWjqV6bzbOEcUFxgBJbCRdZrTkk69rk7nK8JtfLamWhPT6J
s1JCRo8DlHiL49l+zUy7zxXr+VEXb1X56elBHK7X7U5CSsUBSuw4PMp3hYun
KyOXMUjpZnGmbu+H+WXfIgmthDhAiUNwHmcbNStPrNKyIF2WN+3s45WkZB6G
y4TeTBygpEiVLi9m18tc7nGwORs9TniZr2/k3tlr7z7hXl4coMQiQe+IF33r
4XJav31sPOlXWU27LpFsm0/I6HGAEsdwDLeTTlWea1fPV+XhszSfP44frM28
ZyWcvjhASZGSxmcVo3zZO3uuFYr1Ptk8rc2pqtas84QSPQ5Q4r0E/lWolMaP
5xlzua4/1Neju5vXtXzdMBLu5cUBShyZUOj2pFVjU1GGrQujIZ93nyfLemNg
FBIaeXGAEttTtevqtn2uT5W77Lq5XovzQlFSXxbqNqGNHgcosY2euXzpTOuC
eaMqpeojX31Sxtrz1GxVEq6+OECJRcL8+kx53IrjrWapq1EGlMRGkZS1sEl4
ZBQHKLGVMFlfVkVJKU3lfmZVP5vVhre3TVXobxMaeXGAEke7WGTdmfTOLuo3
1xfNnPlizEaGtmxcLxLuJcQBSrw/ZXafS3p5PS3MH8Z247KYHTVGK37d3iQU
CXGAEkv0klhplvr15oBkNoVm7eWhl7cKrb5YSCrRYwAlDusy6sV8+Xxu5Rat
y7vG0BgNFhZImHLSQN04QEmRGvS1i8fpbaM57g3W+blWy2ReZ6VKYXuWcPXF
AUocw9HrjDPm5eVtsUcWekt7vb8417rnqjBMuL0YBygpUmfnjVo+q85qZK7M
2v2BPd52atmMctFPuPriACVFqjrlc9nz3kXJzPYlUZ+U1L6eKRlXazWhixUH
KClSlZeX8Vl7lK9mu63J2dPTza312Lu+eqjeJtxLiAOUOATn1c7dKg3lsbc4
q8yuhtcNZXN2Pltr1wmnLw4QItViV+I/J4sGmG7ulwNLGb30W8pDZfVQWFVs
+apUHCWUonGAEhtWi9vM8/1406m1sxXjSbWeznO13HK87iQ0F+IAJQ5ReFKl
x4sbZTonxmSur7st9WmwznXa2YSiPQ5QYmsv81y6XZrNcYNMXvr93tWied54
3g5fWgmZKw5QAqQMwTLTptk0ngbt+4JZagyFR1KrdtVOpt+/yb5/Gb4JKClS
1/16d3wv8QN99PoqzYvNzPmTfq9cnXXfb1i9CSgpUtrUkIzsqNqXlqXmePGc
a1n5h6cFP79+v6/1JqCkSM16vZXVz3YfzIf2dJJ5KGq9+WAkXF7q71eCbwJK
itRWODsrmHfTwrIxPc90rvr9wSr/MMuIZwmnLw5QUqSaQi373Ly5avMT6bq4
4aXF3WT4qnTE5vsNqzcBJUVqaS06T7fN16H+qDVLg+KropU6YisrrhIiFQco
sWGV5dX65X1WLYwu5DPz5uV6ft1dTK42dwklehygxNGV9Y5YrzwOBpnOnbiV
5/NnNZt9eBnM7xMGKMQBSorU62N+JfXHo6eLp650MV4sRWN9f2M/TpO6ynGA
EkdXig9ntjbVR9nrCwPEX3tgzpZX5sNKS+hBxAFKilR7OM9YI6E8z16JArl7
al29vJbWs0KxkdBVjgOU+KKtrZvZjV5UFpeyecFXB2fn95fnQk1TE3oQcYAS
h+fdbSf5ufgy0M/bBetycX69MXMNm1zZCTfU4wAl9iDU5tUL317l+Wo5V3oh
Y4tktOnjRU9I6ADGAUqK1MXaOhuKl93H1W3jPlfLdDa1YdGsPvR6CXfP4gAl
PnpYXtZbcnGs9YxidjbUZkX9ZZi1R0rSnY44QIlvauYU4Xxib9s3N0bpJqvd
NibLC2Hcv0p6AyoOUOKYQT5/U6uMpYdsrahKFxv9bstnX8eVgZLwkCYOUOKo
ieeunj9v9J47M2VwJQyHnavrl+eLWXOTUKLHAUq8J9TKPueFPv+yEm5nI/6m
UjknG6vRVcSE3kwcoMS7/Ppza1kZ5rJta5rTzcvG+ZU+qGz6r0mvZcUBSuy/
90v9TfN8XutUJxqZ3j4rF2JmWi0Ji4SMHgcocXiQMTIeevJVt799fL1rrpQH
5byeuV0l3qiKA5RY90md+irf3N5uC+2lMS9n5WpmU1p2+o2EJ0dxgJKaw52W
8XB5fd8fNdXri9Kgd3ddOc8orbPG9v3C801ASZG6eTGtZnZiXhhPxvRmfHdz
yz9VL+aPWoKjhzcBJfaQ5wWlbj4U15b20j/vZcX+9cLKqv3r2vu39N4ElBQp
qVd74u3a5Kmr3G7k5uR6nHmq380LL9WEewlxgJIi1R5Ir3fX58XrulnoZbd2
ezHWrM2jkt2+f9flTUBJkXoxCutyW9Yai7Psi5UrC43G8/mFYfeL7/dm3gSU
ODRdnY4b1sQaNjv917zd6wweiEJyq/Wj8X7p+TYkJ8NaDwux3diY60/XzKOj
Lq1pZ1in3BQg0+qw3Iv7mmV/oumuDEE2WXqu+7NwhihoQNNbGxamU8KyaFif
iWZPusdyT9HFsJ062J9YJkbu32LLkzvlU81kBbKdVn89wlrMmNwLy7bImk3L
6QWLIZpuFjRaCwzT4tKylljJC8tgN4Y1ntT77b//HX70uqNBi294kII15LDS
H5ZFlLGoL1Yxdyp57RZBPzmhoz45OTCKZxvIP5WJ9Ffu1sOD1kyA0fGWrO6X
s534BYowD5dOC6gHvjEw5zknq7TWkUWwBtHUIgamPtMIq3jagm9p8V2apG0E
vXzmsK7xF698cTihXYgJgXfSsuSUpXaqAoGa4tn0rkyeTlqmQHM6Yl0mmrOy
xOeOUy6fOHnb3ErvWOePDgP4R55ptNCyyehnRJSIdmtE7xaJ/kTLOQJsrPqt
iVuXWk5yXCId/5WWcZecouMnJyyHL0vdxvrz+6clvzBpHZ0ErPtmqzQLHavY
uAsbq51imbQfSsRCKpcqUDJ2gPe8Wq9Yw49OupMqji5CwBlIoxFWikmnZWRX
urKi7MIK188Fg9arFQ1inZz8lWL/t79h9cNBjVXoxm4wIyoncJRWtMRwqNQw
NyOsEhYmXgVSYcH1frfbZOnfGp1ufww//urkfLRlCfNvcyMwilFqtNwhYP1p
pGfMOFJcG+QiPoDXks7B1Lj56GTtKFxWbr/Y5ik8a93eNZ1yQaVCpcIeYt1p
WOSYE77WZaOm9WplWDIUK5aNj1bwxZ4D43QzhjopELGJm83PKQtNjFisuV2s
KTItaQay3DT54RYgqGYUUiJ0S8uwA3UIFoHzyxUno1No+LkIkuRZ93WZFmRj
neu0rDgXYiDzHSM92unXTYDLY+5GxQz07r2Z6VFPib6KfqxGPTYs8cBjXhIO
vbFEG0eO+RsHfjplUHoWVkTAafbTOh7RZIWBrMsO0yxBL2EBO1qkjWb8NFQ3
GeNeXsToRIhvVVLlepj8Ug4kSF1jGVavXpzOikFjhsalgdnNMZNumpbwYekU
WfZKmijTS63acKpcCo7lUAOIbsFft1IzlY+0MCVijXrO1f2HNd8nYSGwunjH
O4Xx6ltO02mlbzNQFxuEjiZh8kY/52O4qvfEr5sK7xSasZUJDVYbG+QcS1vq
AvKST+I0xJVNNnXFZiU2ObCbmBVkg1WGxUd1rGs0151igYqO1T5YSYqd5JZO
wkq0MrCQH6xWWlrZnWLFQRNHiiV7XCAwUMyvKjtTR9NqYulPZusQwcRSpRPC
eSlJJ1tfXuL8eVUJUyBhwaIDaUuASqvAJ6ytiUWFYbLiBwHfQA/haorIyijs
sIKhU0gVWAoxdbOAumWMT/2qnjRlrNuzCnII68pj+laNDs90KkSZ9sRSIktZ
ci2YfJFmhQ1zKOj1T3KKpE6dmoNLmqqWLioBmNdNAspUYICN3DV7Ck+cHKLc
BHgax6PIqqPZuZ5TBRGMNFDV3JBWQTwFC9uQBRWWIIgvYSqcciNbV8EKqdkG
/LiTce2birDimvaEbBf6KXeOecWxGeHOBRGsb7DGh7o2m+hc3T7lGnOizTaA
XMcW0NboCPoaCIxfnHIXwlbgWoYoA8+cck1QLRc2EAfIWANDzuIu/vmPf/7X
f/5jARC3ygoFdJ0oMJECVoxsrQSuAdIixd3L+BCm5RxtT41rtobD1tVVa8gN
a92rUesKx2WaWJlZFmBR1g15NkfVAs+BiQ1hDk4FLJ0tGKgNXVFg4bMp7mJp
4qE4N3RxcUw5nzizFZSMgsxE4Jt1NJfwlqUAphU1aY1ij9Udu8st6XpYdu5X
4UQbkK7ckxPAa4mMNMFy2rLJVoFjV0YU/nRS4C5ZtTQ3BS4dFNYWBYqjWsTf
U6CLVz0cRG+wFesHZRQQAK0Kh+sdH4YKPrfm9F59VTetL/Xb3G8RNZRfhrCU
MTexI1PdcYLqJU4haWXrCZTACvWzGJtzVq48YDqluBEIZlmDaXv16M7WD1Z3
UyRavZp2RIWAWy7a6zVS2blwaEpiH1WEALYELI8VzbSMYLDurGAJjDG8Rya1
jfzJZC2dLvGrBaFVjf0S1jhKW8Uipe5jmtUbeqdFI11LFFgJQ4eANm564rto
Tqj5iYXvfIHeRL1kHo10x8MxPVfZA3DKLTR9rRAw89jCobVugT2p+eaTE8lA
pY9TNSCOLQNZjgPahSpJtLa6fDM11U3MBk6T1werCWSqzAQKfkN9Ebp0gp+6
5e3Zt6AGXtmHtMAvuMygE0z0xeUV8zvRRHQSXquE0Pzmji4AmYZOmoF5xT2O
QS4Etwzn0AIKKCC6Oay6gg9dOHQOzTekdaPR4AK+OjfsnjEB5RpsKa7vFtBl
GvYTlnEnm7mAIhFIDysB5+0YWAq0k0Qx/9vfsMaw/wDLaLPBcI5H537j/oQv
aIpqyqVUnaPrRHX+YnfW4ucom0HyAn3Ql4NZDYgWZggFxOnUNqjJ4yyxHeOJ
YYh1AtC6vXcSsx9GzsctYr5xwuhYXaOWIuPUnB54lPIKNAeo+fejo6/UOLHS
HbSPvoKDo9kE/tsExvhkHnNf/TX5Fb7lwQo5+G94z5wlrq4DL+C8eMZsr8H9
jsVbNHsD026raMUE88CjqPM9dWUppgiiZabpf9K5TBpx6RvCzIb12njFqmgC
PCly1yJob2wOv764ZbnjQdFywvKEmZbpXLFSTB+Dqafgltcph+PV6Wjqevtf
F+tSIRON9ZezWuGsw2UL1hxXmIaV5Xts5Yf3QmZCYTanmyGsD2zBL1kLivgQ
mghLNJa/crkKTObS4nNh1Fn3YbiuoYEFBmjlkUBu/nQhW8yUC/lSbtxn5c3p
4zFWmZ3ZAuXLMR3AuAWuL2WnMSqdcQcMIB54atxwa9/RPP7AXOMd3TCWtXGb
Wuvjs2573CS4nzSGdTJ29gOk8ehyOGbbPvHC9jhE2H5rxDeur1hRgdxnLltC
ErM6G1zLrbPBsZL3aBwgr6zYwvdJNJ3xS2KlZjLWCEGBqkFnimVrszQC5A8U
7qAAWTk4je3SfuUu//mPCRHB1nQKd9B54nNVOlXfNUmFSrWcrVbCkxRZunmM
pbyJPyvmoVnRp+PG3XA4rmZwgoLlJcZeeYljRuhg9QYfbRNUi5ma6frMKXEi
ySkwV4E5hGxKttLE1A1ZNGl9D6TOQFdh1XWBuEiYbIHPVj6AMIVsKVcsj3eK
GGANg3HYZmMc65EDXuK4gyzojBY1IjeojYZYoRQ+Vl1F7SOGtheKCLD8/S1M
5yssroStWNd4XMJn8mm3JhH+RmLcyYZlg+5GQrxBheSd4UYcOGGKmWaw+Kiv
aJEjgXc0pFv5iL4k7lLncan7RdRd4vE7BhefycDK/EKXpo/3VrctOzUh6W1x
PBxk+OZrJ/NX6y+5YpERGiubCqBONRTqg+71iBvaKtgru2xGH4Km1f//6p5t
t5Eju3d9RWMGNmaModjdvE8wMChRvEgiRZHUUJIfiCa72N1i39QXUtSuAa+x
wW4W2XgNbILA62yAAAl2A2/8kMQw4F34YT4lc/NTfiHnVHWTzZskajS2M4A9
w2bzVNWpc69zTnkxi10CNSGpEsh9C4y6R1zRoTHUn3IMmwR1wxSlnmWDreuO
TcsG034KG2wkIGHNBGRt9p24aNuW4oj9VnPPdxuWkmgcd+uH76Nrfp+CmF6J
FboJaL/PXIEkRW8WI7Jq9QKyurMVirGla1zUWqvgsmuvbLzmzHHjRuDGhxF3
6sajKrsNOyZy2WyCT3dCQ6OTD/CE4mZG3KPqmDzYKZQPtmeFewHdm4m90rac
Adf0wMsxuAeFZrv5cJXuxMO3jkvfjLPbO8OLhjC8Rg2yD0q61QXey+vozAfX
KZUAzwaIK2onlcGbAl3ygGq+lUPN8rGYBO9HeSNhlkilc6lMikmq70edzjOt
7/LiiHQ3Ly3L2PTx1rxenIa040d5M5EVZKJJMalaM85KZbV6fmH1ekK5Ny5m
Bu6+LhGyR/oXB8luc1s0yvXLUf2wflIiomyeNjYv+zo52TYMD/SG1akF4nbm
XqN8haszv7SJ8eTATEL5QIWyEOWameOjUBwKAds81YhpSo9gR4AUqI0nCtyu
r4+n+4Pu7E2PlwEsog1cUuLGLVmROxeGenZ4rDU60v6JfO49HRZ2STF5W7bh
c6mkKORAvbPgRqdRWqGR2UbjRcRar5OvMBw2d/Ktt4OktXQRwl1QPfCQUV94
aV9wCI5qA2QnOGTwHc9v2nL/Kh1S7KbKl6pg2MIO6JCkkM1FtTUMQtWJTAwL
/mHbY65s+dEbyLSBNp0wMWfmrIaKiP4LYazADh/FDqJnqsJgVWckKnxvNuL9
uRtOe0PXjWVSMW3RnEHs4NzeZFHz/DYhq7fHdgs4uzXfPc1t7Z3udgqlwWld
1s2zLemIjHVf7Z4f/kB8V7a8RnH7TvAk5ObxdDesp1qe0+8Ftp6QWnkbOVgt
wc13M9ddX23YFQvldkM7u9hzLWDKhJhNLWNKSoXXIGZCrW6cznpCvDfF1vfN
iXe0O+HodIPkZYPNXVd/zY6UGudjp1DZUXZGsCNCIsmzHans1Es/ajrViK0E
VMovRfp6eFCy5x1fyA2PLweoLpJ8MqBMNCRd1bJnERC9GtQ1pZ7qxWQQHXiN
sEziQFGKAzZycGe3ZLoavLHqwlUhlUI+AGQXGAiu2dNoeKqGl7XO2f7Xj04Y
E4TAQKSmYQtMEtmCObXwdhZE0Xfge/B0bg0WfRiTZYQ9N9dUdK4LU535JWXc
gUfi7ILqIC0C73+96rpikMuzQk1iQjomgdXLckXiweRXqL6lPhmL9m3qGGvs
Y/4NOydDWl51fToFA2M9sFmQhh3M7cI2gKeBoUoaw5NM5slpbs96xB0184il
RAy8h1lEYa7T/B2q12gzIZsCFyLbaeKpCcbuLlmcaM71Wo6NyTHd9uTUcSFK
GV15b/KLwBcCgt/GS3W5mkSPC6YILk7wN7ucntnr473Qs35UgufytqPpV4iY
G+EimUvmxE4DaQmXj7SErtNcoKiTv9IdWnSDEp56qroNLbZ1ursfK52fmaPS
pZrRzK7u+XsV3X56dl7V23a63ZCrrdN0+jRrx7InZ5JEDvpd9Xhz2yqnT7b8
gbTnS7wy8PBUmCV4aQbOxLA5nn8sZh7zPN0ocPK4OtNpmAUywpQARDYLK1NU
hWmMS2TLfFBZwveRYfD92CTMUMVgNji9j7htyZRkiXswZBuCXwqZmR253YaI
QiKdFvhOC9Oa0NIKXu/smDCUZeKBTKfV2Okc2MTsNH1wEq8S8HtOzrqwhb5s
YkxJ4LMJfNshmIe7CgNhlg7YlwtYiAUaKsZAhCKjBvzZHBvAjBoek5po8nEt
DAW54XFvKN2tfuQaZnitaQGnzQV6LDc2tOhcFNhzOw7WGTybYwAhPY/uJaGd
FZDohrIQzjIrJfIzJhvjfU0n7GcxPkn/5pNCusPm/47IvyNmhXfE3Ar37CbT
WBKrFx5zQuquY/Wp9WL1e5Kju46vkmi0XkjH7oTYUfqkeJHGacCLWBUEQ4ze
Ts6LmUT2Oug0xDavC0ACAtF20A4MdqbUqhZZaP8xlzdNpMHQAQwySNol7h4b
C74Ba1WmtB8S+73p3BXP6NN4/6bLmMJFjUHJIzA53gdjQ3lC2GmJfxlrYn4I
/N8fEt+JxjiTMUB+VXLeVAukEhkhtZ4WYG5ysRE1mFPXGswpdkSnEvMS/sOs
Jbw9fUaM5q5Z0DWWc2qZ5QweXd9BqRU1ma62jSv9PaV7kEnue0kQnWk+lVwa
RbrZkh/Qka9deuatLJ3GlRZD8lcvXz3OgIW4M6hl0EVKZ9LB6jHyYSxEPu5k
49+ckvlEMpNMZBKrIxVhTGI/v7fzfc//drunoynPsq6WH6fQ05NrdnP3sr9v
d01V5/MYghCEzIrQzJ0gIvVWEDETowkQMkkOm6YQs0+rPaGrEXXgHViZmqVo
LpJ9IiWEHnGIn9vFalJzsZor0ZeMLWDwdnGbVCRuc9fe4i2iO6v2dS66s9ZM
r97NtJhPZc/LQq5awSNVMcOHXt1imldEP2ue6nfpWT28F5tVelELlOeKpHsF
nUcALT8+DMCHVrWLZ45dDPaaEVSFCcQ0f5ilDzNNHSjqEjgC1CIVBXY+8FcL
CEECpUjpshSEkeT11PeHTzT5fNTl1aKuuu9i3tqT+r7RHxzt9hI5v6qeurWS
YV/Ezgsxf9s6HFcVvWK/i25EWnDfXhaAcEUWQO4ajK8/1k2SAIRA6FDKnFoP
1x3GKEeNk7QgP9XqNMoIqukhd1WIJWLAW65MjOlRtIuFIL5O4nRtK0IrIFhk
MgSBaOAJ7gfFg2ZhpzrnWs0DRuxugavpEt19hDnfCjpwP+USArcrmTFhDt2L
HtbKmTI/ulQuFbeqE13lAZqXCY55KEESGUU1LTR0l0FiUOJiGnS+yJwykRc6
ad7PEd5csTv04+b8gL6cFoXUkkE2paGwOSJd4y4Fh5hB7P7ggoMZSWAUUdQJ
YmaF9JgQdJ1Pevu7veZFv/r+zcVFMpG8U6mb+FEgL0CakLgOab2ms31aG1uZ
jrIG0mio5i6xluYKpEexlroOa3OA4mvjaYudYVMrnJ1hI7ZSgiikr8PWqFN1
zqqkPK5n18BWKnenyBJvjqs7pjAa1ZvU3QdY48XrsCakpdJpzDrV5HVoTMyJ
1B76yWPO0zydPLkXrWQI0+bJtKJhpkZgjSqCex9usLzufJDdPsnqnmS/wxus
+h5425ec8bSUYZLjzwoVg6qQH0XRAi04Y4WsWKURlqzSGvy5yiTLCYrXWOK/
xTolcBLWAJtYewi0qkYzLxfwjL+TbBsrkrA21HawQn+mvAcHoSVsUp9MCps0
B7sUOO5jugP3ubmQziYeGrKv7jNrboVb83CD42LcBzT60Y7w1E3a9STI4UXx
7LC4u98jEknryU5NOTYNt3ASgqUW5M3B0u4aaaV7fsEfn2TbJ045Ub1IDg+y
phjz95QJ2Nb+OlDRpsjq4/OymhtnOvvDdFfQjlX76PzEsfkqHwKloYObQ0X/
Pd6yhp6eGSnDy9FuuyVWxNORqVqVA/PkcILZfP7maJUkJX62dfp0kDkZN0e2
VDwfy/n+RTuRGNRO65P119FYY0WPMxWYKCNuOpYdwojNVHHG5XSqXZe2+Xb3
tDG6aG31dLM16GeaBr0yHIeneSAidR1ZVcwHnuoQSRZuOrQ0BRD3u5cZ/3jb
jcVOLv1me3xcq7lGu9/xmoeYsgjMEUAXbwP9oqye5XPJ/iWR0we1yrDeUEat
VqzdMPIhLgvN6vZaiJMNtxc/3BYludI7GVxoLd3Udnq9jKIMsumt/GSTlgQU
rgY8DSXUK86ueNA5PO/VjvJmtWJ2nqqiWDHa1V4IPZobdPf5RFPJ0ViQHM6M
5DgqVhulx2uTAOtYc9re4/1qNSceyCO93lWOt4aHebtgk9RtNz+A21AbGUso
O+2LfqnQVxq71UY61dgaFHaCadMA97qTxlhzvNa9KFdGuXLnwm6edJX+QcfM
6E8rRdJ2bzlnCvYodVKWc4J+cqadb7e83Nbp+GmhViRHdnVCqZVa48aiBAy1
eCe7v5No+MLFsZBWldLuyBlXW41Rw5LykS0Go2bVGXfggdJTasb6sybYsn1H
VnI3V8JR4hFFHKdp5XFByIh8RkgkVuFvLZgG+vQKiSfAP6GTbuW3bzVR8Aem
E8wlRCF3+wlGYIk8n85mU/x0Bw6267M8hpX/DACJsBq8Njl2ggUF64ysyOrZ
MUnXN+lhpMsGhh/Fwh/NrCYjpNGNDqCIa0Oh0bvO9AwJDQ62uByfioJO3Bno
ZDaRxcAt3YMAevLOoKfEZDqRCnaFW1pdhL29UCIyqbemTDrck20+U08ekZbv
qvlt4TxHtrY8mw96U05Cbv/fal9w8iuSi7AngwWeom9wD0DOPHwzMSEKyVw6
kczQEYNsVEyan2bYcA/y+Urx4TQV4d3wlH1+ZEnS+mygkTI9RAtO0IMBozWO
OHqKTybEBB09yotrUGAom0ATMzjgStMuPpGkgrFhS9OiHPoRaQnPkGnDpSBd
IYe0xeMf2hAK6LbS58BzpJXkkTYnWAE/lMBUQyLFPaEmG+12Ba5Y0FiF+WCs
6D+gClboTn2MR5zNaqN1gr3R6Ai09cZ2tAh0Y+ZT6D+yWmTs/DAiuMWEBjFv
7HHPnxEgs67hsC/7+UPaXMAEBaYRzgT/rkB8z+2pnGs7pEcPbwbPvjJNwt7A
5EBOIY5JsDsAtxOrAgzAL4cpfjtYo+97WIWNZhV2kgDHTJW68F1V8xRdIzJW
KckAqKIiyC7ROOya9OxzanR7lz5sSUXF7mJbRIPZKi6nEr0PrwazgOm++LeP
X/7+85cf/+HFJ//+/M+fvf7yv55//aeX//CL//3z3373T79/8fXXL7/4l9ff
/h288N1Hn73+9hevfvvfL/70m+8+/o/n33z1+me/ffWf37z64osXv/vd87/8
+vlfPn/90V//z0cfv/zlp8+/+eLl53/z8pe/efHpP7745Mvn3/zri19/8uJX
f3z17Tevv/wUoL367Ocvf/X3r/7wLbyP+13J1/ILfVZaMy2AVMnFtj30TdZ2
Aru0bGBJdhcEGULJ98JmBzQEvPGTxyYtZibyk3t9EF3k3ocbs++whmNY0m8S
bI8hOdjuBnvSzPXxqHj0qRY2C4yGFPoszQx7XYAox8lQRYLNN3x6LoHE3vd1
2l7JoK03ghL2he41LAjgsF4hMmt8ZuM+U089bEW0GeIm6EtEO9u5rGlFGIXB
ZgYu62rHDsAxYBDGqTnwc7GvQaTXEOciCwWZKUCuiBys+YqW9NMGA483Nt57
b6kSe+897Hu27JsPP6RtN0aaqwY9JhwawgAeCboB0BgF6WlM2AYsPu1sEkQq
tDAoQttANoEvx9weEozEHWimBM8KjuQOrOCvodaDR1XJGYBsafjyGD5FG9vA
x13gtz0JjwzgQ50o3C42RMIeZMQBnoFtLGK3QHjQIF0ykFTuAPArW04fHrWs
rgZUWfd13UWsLAuVUKQs+yLAiQKzD7qrSRPSJEuWrwFzKKqHdDSlLBblAba2
8XnY7cgyV45JEbfjgHprYBaRoyPSdn3VgnU67rM/mgsIm+s7hKhxfGzVo0sm
CDUPN8IDouP2HGIQB9FyJqEIK8MWs99j55+WahmuheBPfBPXtKtJFK91aUh0
rqYNLNMC1oAn26ARxtg6iL2fNy1zbGB3zWi9dNiQygnG6FnwogZyz9O4BzMv
uiqxQV/JqBYLkgnUUQWjCpgroI+GZSoDX8IJUxog2CtkX/JltjIbG4iULd2g
ZJEHVeBIXMnX8YMHSK870kByVboS+NgcD2mrl4C2AhKp+kTFXGVc8K6lmvAr
4j/7Z5i457ns7S3Q40DHZUnHabQJ7VPVBCXQxXmEbZuwT+K0TxO3+AfxN9PY
abI/+75FsSk7ZIQo0OlmLW/rBF9EOyzRGdiqhlmZqqERhaJyOJa5g4GkUToA
vCJ0tAEkYNO2ZckG5bDSs68chESAXmRGHyCmmpJnURQN/C4jMew84Vkjd6BN
iaaIXWmAWBl2wQYA0VrwFYUCbhJH1TRKOboE7/g4zQLpgh6xdDKmDEktQGwy
52ggXxkvFmLsUyiUqJ2CLdOY2MGWJCiYelYsEjOmYnj21xGhNJR0n8aTZ5pX
UF5bZJ9I366NSVOUuxQDoRai41cs0/dgu1Wwgwll9oWuYDgnlc6pyKLbS0RE
GdtiulwLzBkLTAgNKeBEctBbV0m/T/cVeIb1C9kHfdgFFkNCLmmOJqugX6ow
xbFkUPoEDIIhjEYk7KrHmMUyJdqgrmyNkVKQMWFTwdritiQHZfIG9tDqg+ai
28j+GezhspYyC8qDm9YbsOY+qHoNSya03yDTpSKP/8YosLCZCDKRNdZ5ODLm
xMil5w20VZjkzg0RdoMLWxlOmhfvAWmrQG1jWOsWrE+RhpK5TKrWQEYZ3J4F
hh1sMi6/RNBDApWysdEM1Dw1xd2wAhs9vUccOpKPsDERO4xgCe2sf2BInqyG
gnUBoygKDRf0BCgoaj9scnluebeiKSja6s4Fyxs24AeoVrpvg9vzRMig8b20
cx5Oro9dr+iSWU7ypMvmjId3L7DXCdWFIFBMxVVAp2lBwc/mvYcb/wd5AUoj
qZ0BAA==

-->

</rfc>
