<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-02" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-02"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <date year="2026" month="August" day="04"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 60?>

<t>The draft aims to provide technical details of CVE-2026-33697 and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without phyical access</em>. Moreover, since continuous attestation is required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the ProVerif artifacts  <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 65?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
      <table>
        <name>Binding mechanisms, implementations and ProVerif artifacts</name>
        <thead>
          <tr>
            <th align="left">No.</th>
            <th align="left">Binding mechanism</th>
            <th align="left">Used in</th>
            <th align="left">Artifacts</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1.</td>
            <td align="left">Client’s TLS nonce</td>
            <td align="left">
              <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
          </tr>
          <tr>
            <td align="left">2.</td>
            <td align="left">Client’s attestation nonce</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
          </tr>
          <tr>
            <td align="left">3.</td>
            <td align="left">Early exporter</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
          </tr>
          <tr>
            <td align="left">4.</td>
            <td align="left">Server’s public key</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
          </tr>
          <tr>
            <td align="left">5.</td>
            <td align="left">Combination of #2 and #3</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
          </tr>
          <tr>
            <td align="left">6.</td>
            <td align="left">Combination of #2 and #4</td>
            <td align="left">
              <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  CCC Attestation SIG's adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
          </tr>
          <tr>
            <td align="left">7.</td>
            <td align="left">Combination of #2, #3, and #4</td>
            <td align="left">
              <eref target="https://www.ietf.org/archive/id/draft-fossati-tls-attestation-06.html">draft-fossati-tls-attestation-06</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
          </tr>
        </tbody>
      </table>
      <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
      <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="credits">
      <name>Credits</name>
      <t>We discovered the vulnerability jointly with <strong>Viacheslav Dubeyko</strong> and <strong>Jean-Marie Jacquet</strong>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE (<eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>) published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft-fossati-tls-attestation</eref> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
      <t>Further formal analysis of <strong>production</strong> implementation of intra-handshake attestation has led to discovery of another class of attacks and will potentially lead to three CVEs (currently under <em>responsible</em> disclosure) each with an expected <strong>CVSS 9.1</strong>.</t>
    </section>
    <section anchor="affected-implementations">
      <name>Affected Implementations</name>
      <t>At least the following implementations are affected:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>] and <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t>CCC Attestation SIG's adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>] <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref></t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>] <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref></t>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
    </section>
    <section anchor="correlation-goals">
      <name>Correlation Goals</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/04/">draft-fossati-seat-early-attestation</eref> and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any security property that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high-severity vulnerabilities, we recommend that the
developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <eref target="https://dl.acm.org/doi/10.1145/3779208.3785387">ID-Crisis paper</eref>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <eref target="https://dl.acm.org/doi/10.1145/3779208.3785387">ID-Crisis paper</eref>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
      </section>
      <section anchor="technical-report">
        <name>Technical Report</name>
        <t>Technical report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="media-coverage">
      <name>Media Coverage</name>
      <t>Several media enthusiasts have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <t>If you have written an article on this and would like to be added here, please send us a PR or an email with the subject "media coverage of intra-handshake.fail"</t>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently verifying the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
        </ul>
        <t>Three main questions have been raised in support of our work:</t>
        <ul spacing="normal">
          <li>
            <t>What security property hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
          </li>
          <li>
            <t>Since continuous attestation is required, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified?</t>
          </li>
          <li>
            <t>What is the benefit of doing signatures of remote attestation within the handshake (as this latency can be exploited)?</t>
          </li>
        </ul>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 377?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>We would like to thank our co-authors of paper for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We gratefully acknowledge the following for insightful discussions on this work:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Nathanael Ritz</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following who gave feedback on <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis">previous state-of-the-art</eref> that we utilize as the basis:</t>
      <ul spacing="normal">
        <li>
          <t>Tuomas Aura</t>
        </li>
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t>Several others at the IETF, IRTF, and CCC have contributed by providing feedback.</t>
      <t>We sincerely thank Karthikeyan Bhargavan, Bruno Blanchet, and Nadim Kobeissi for the foundational formal model of draft 20 of TLS 1.3 in their <eref target="https://ieeexplore.ieee.org/document/7958594">work</eref>.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9V923LjSLLYO7+irHk4LVkAeKcon9k51F1qSa2R1FKrFRva
IlAkq4kLGwWQYs/Mxnk5b/4BR9hhvzn8D/vk+ZP9EmdmASBAUZQ4O907npju
JoqorKysvFdW0TCMUiQjV2yztWM/Crkx4L6jBnwoWCeKhIp4JAOf7Qa+ko4I
hcOOeOj1Ype92b3ZN6rlatOo1ZrtFgt6bPfm6oq1zMb6Wol3u6EYrwx1rWTz
SPSDcLrNpN8LSiUnsH3uAX5OyHuRIYvgjB6XrlGullTc9aRSADWajuDt4/3r
A8a+Y9xVAWAhfUeMBPzlR2ubbE04MgpCyV18OO7swD9BCJ8urw/WSn7sdUW4
XXIAk+2SDTgKX8Vqm0VhLEowp1oJ4IaCb7PO5X6nNAnCYT8M4tE2u9rvXJeG
YgpNznaJGaxzzHgfBlX4ME8KPiMFfl2kZ2ks/BjG/46xBPjtIT7o6d3CmNLv
s0P8Cps9oAO+8m/ikXsjV5h24GE7D+3BNhtE0UhtW1buSwvAAWgZDeIuEMiL
B9zzuGPEinvcUDx0eGgtovYadHM5Yg7dUsALu5sauimDhYCs51fUHEQeDFTi
cTQIQqQkDMoYMIirmWHtLBmQvccB2RUNuEZvBWGf+/IL0XWbXb9ne6FQsPKb
7FCEHven9JbQFMsm/kCYmxrzf4tiw9G9TEcAIn4APSM5hgUpIV9mT2x+VU3E
f5uGeEaw6I158VnfZkeyPzCUGItQRlPkBpCARFxAQK5Pr/T0iC3ZSewLht03
9VA87ItottCTycQE/AUufx86mL6IrFHcdaVNdLHq5a1qpV3Zqj7MYYfIPRRx
eyhghl8+SP8hxewBMCMcssWi/wzAHmTmzGTvzWR5it/cmGwv7orpMCi2nxjQ
54Tbn2MRPUNeIxSj4FvQ2J0uoXHC3ShLr5IewukrUqo42QR6cSgSjm18Uzck
1NsNdoOrRB1pMjCp2Dh2fRHyritYFLBQuHyK73B7CN9JzsQjTM/GDmI0EB68
6lJX0H8qAb+AK+2xMAEJC3C4FDboyR+k8/2c6mOzNThDDqZFKJVM0yyVDMNg
vKto6FLpeiC0YWBcegrxHIXBGGwKi4Q98IHbXeaICAivtIEqmCxYGXa///5m
TzdWmvWtrT+/yZRlPHZM4UvFTRGHwQj/sejZmuuzvskmAwl4AtXAEIFO9yMw
LjkcBOLk2wKRGAQTtrFBzLGxsdgcsB5hDLw5wnlKW2wCCOGzjQkwXRBHbDSY
EmBu20KpDZOdBaEIgK83mZI4ENitSPpxEKsCYMAwFJ9jCTZ380UsuOMoeCn2
fYGj8HAKYNGAPIL0bMCgSH5QM7EbKbSIrAvMAfzQnbJIf0MKiP300yLx/OUX
WgB88yIMbkAkewAkkj2YsWLPdCLRh54x2PKQdUbcHgijapYZaDYw04KBboaB
gQuc2JZd6QKmmzTOgI8BQQFEBCT9YOIKp5/H1RVjWDYGcx+KQeACeAXsRvzm
ScdxRQnsKaKEkMlmA/cBOTX7jXCyYOcJGNkHl6mRsGUv0biEA/e5O1WSeBFf
tKFRIqOzLngoaNA9YBmwXgqYGWeSNgMnyOe9B3oVuQ5Uh5NYPmoriDTQJArs
wFVgw35m54HJfmY788NC23sFHWDAn1knW42foUcFO+y6Eqb593//b4pg+gHy
2s/s/gyE7F8U+Dsz+eHS9KCVFCQhasPiqSAObWGNQjmGaRuAE3IWoGBkwmKA
LEVixEciXEfQSAMRVmaAf5PitaJQCAuMvm8lANdpVtW5WeXJms7OmKFR/b3R
qGo0aojGPg/B4ojHURBGwN2FgWu/98A1PXAdB74SIagOmr92ElCJF8ev/97j
1/X4DaJ/4EGjJjqIxndVkpbvakUUGr83Cg2NQnMJCnUcfh80hQtsyq6mIE0g
mhC4AHgVLURod3fXyEU5licEaOK+srpu0NXDg/coMPxQFti3YawuY2dq2glQ
g0euMmzbNnK8aI6c3vp/Yfe7IMFFMUOjqnxlSAhPVNTsEw6TkYHggKmteOQG
3FEWmKuGValatwLnGRod0MwgZzbiZlxjX2P33fnB8d7++fVx57R5mAzJYD6F
qO3q+BAknTvBCDULSPAnAMLul+inhWSam6CV6ioDZz8K7JzsN3/vhW/qhW8t
XPhNYLzN3OrrMKUXgAGMJGGXQ9soN4tLIUXUIwcHLR+ECJZ0rJcgULiTm2/r
955vC+f707b2975fe6L11SaTaNc9YBhCStH8n5rltV9Kpb/+9a+lW5E5Wjw1
d9AA9IP/wTkVdkweNjxx1yVbx7vgnswsXmmBxaO+z1u5GO0EwiphizCCngEP
BiAHjl/g5tD1iS9HgUL0PBnJ/swmYn9HKhudJeDfDNXU3UWXQQplsncxGlWQ
THAOxgKEFbryiMkIgu0pRIQReBMMxlAycZHBF5HwJnQKA0CUj0ZpuGXApHrg
CbA34GUIl9XWs+nrSS2bNncDX6CvBX4DkA9HBRPhBiC8Tkm7OznXHF1RmBjQ
IGkBQ+IBSFhRZpOZI59xFOEbqVta6oWBBy84steDzj5OESaDw14F2lPRXWH8
ZOIqhkFSgoCuARcxUiWgggR3wRFKauKiXTGJZUrINOAAjDDp0wU7h4vgBuhs
4AB58k9f8ncwBlBgniPtqdxni8idsVRBOF0oQOCmhnwsA1dEobJs1KRW2tNK
esLKW4dHVx1j3Ov3DW/8+Gh4/T7Ij1QqhtFg5EhTBNxxJwhV6vprN1jjA75r
MdIAhzWXHjPRkwQTAhBmsrYnetKX9KzDGrTAmEdSbO3s/dU1ZqrwX3b+jj5f
7v/4/vhyfw8/Xx11Tk+zD6Xkjaujd+9P92afZj13352d7Z/v6c7QygpNpbWz
zt2a1oBr7y6uj9+dd07XcF4R+buBHXvERiFxPfACLJUIwQPG6XNVgtW3Q9nV
tNjZvfi//6tSB5L8p8uD3Wql0gZi6IetSqsOD8Cvvh4t8IEt9CNQeFoCCYIA
AqGgErH5SEYghpu49gqiKJ8hpwM1N+6RMn/eZv/atUeV+p+SBpxwoTGlWaGR
aPa05UlnTcQFTQuGyahZaJ+jdBHfzl3hOaV7rvFff3BBIplR2frhTyBNyEMh
JjIVClZOoz2Vpk8BrBCSFmQB4rkbiVGTcvk4zStsbBD9NzZOBPcN8EmkSBML
EObhUHsURAP0mwLkPS3DqAuupScIQYTUmYVYHoVFEGZ1QLdQuuBGSw5GIfso
A2D49jAGApMM0Rb9ga9Q/ZJEgGmZqQ2Rqo1Yc5+WQoBQbrF3drSJqYIGGfc5
FBCD7GXgxz1h514+TnN6oFwS+b7HFPJMj2C6MDHpRRtveapvhTxSVrPf/fxY
/nC3dXsXHtXOHuvjd1t+1Yjf9u8stO6VChDVp1GbNOr9hXa2UanGoIYRz5w3
IbpmOiIOBs/oxDXL1Wqr0iw3GnUr73jktJsZkrPZtyIhtDuF4ZY9BSzyVKi2
2IHo5vBJnUsdBKgBrNW3UK3sfmPjKs3Jfc+Ojg+PMHVHynJrfWPjz4hrTaeC
8tje7LM390VFW/TFXpFrWl/PTXYZIo0UkeYTRO5nrFZcwRyBLnAF1FRZ6GiD
34/5Bq6AIhHv62gYvjTGZXPLrNAqpR10QoM6sX94sq+ZYJvynr91ev3g+ak1
zIrRDypmtQmDPZljP/g286uUn0wQI5yi//sbIxZH2KAkUGyWJE9fFTTOw7ZG
setajS3SI635GdzMRlswGcyHBb9xRokCcpDzq0uG1Vmw5bHSDAUIADhmcME5
nSlTcCyWR0pWpQwaDI0YvAbWHzhIp7cVYIcaYg69J2H7ympNJBCQs9Pw/Hm9
NvjUt41PdmNs9CatwXK9Vk/VyZy4zYK0zOIWbXne/OUtLp+zuBipoZfpjcCa
K2ACMv7vwLKFBRsO2KODBe5oD2MBMrfYK8a8ADuFIANsG4yGmH0HUzfssVIG
OBtgkxmMkU0QXMMuR28exro/Pwb3ywNjIO0cv/tjx4RILzL7wdjCaRnJKxYC
XTdLOZ7Ss9Va/mftOoOkpqO9Gmbeqcg5F/cTiE8iPqJwOadncq1WD6ivsiZM
hjBMmyZ25xh8Xncu9McmLVdJ7gVarVhZws+YxrAFOstW3uRb1NHIXsl/h9qt
YVTKRnXLKJcrSaaANi46Z3v/vPFnbyCNKUt3DmGq1qfX+/tzhAVHJE9USu7O
kfQJkL0PDvj4OaXhmtz2ElUhQRmYlUq9YdWaja1mvW6CAShXa2VKo3zDxakj
ccp54mBOGbxKdhpM9EyuIGoRcU4OHm1uJMYgt0eu9Gvpvw+xEr58BGOZ0Cm1
jg2jUW+U26+3jkkHhFE3y/D3GYQNsaeR2wkFHx50IHx6Ab0uvthDBZh9egj4
0AVeXIRjs9JuVVfBETusI4bVeQy5c9k5m4HqclD/Hm7GJZ9w7J8XyAP3HK3F
fSvdeADW0/s32YJaXTCsmKC14HVDdY1audLQK4nJ6do3JFdlVXJVCMX2HIoH
vAv6byicl1DspS/OPi1nukr5FRhCY67DQgwXbewVIX/D2oX8LH+744nJZBR6
HK5gxuctcEAWePzUAtt5C2xnFtjNLDBadEwM2TOIyTaiTq0SeDKUGxuADMT0
6FY/u/eK+UcstkrSmvO7/5jm82hcNhVRMihmF4J0bzfKdjEXY66Q33RiBzOX
cYiJRXfKUMMnPScCM5MRTNIfKp1hEgxorMhhA3/gIA6JXkmKOb9/urExyrZi
Ya5zLu8LqeQBV8zVs0kzJzpZ7ev1ATde0ShpwQPOYiJdl42CSM8UZgJxTkKQ
UAg0Yoq9mc1Tb1Fv5HIXGznvbZ0Jbg/0omEm9nGkkyMbG7SEbbNCmRfw4bK8
yXExRV8qdSJEAeinN51dN5hQMnk+lY/p4ATIdqlkfLXd2u1vEMEh+k83wZan
IhCxP0Qeg/y2b0Ki1bYsF8U5ryfaV46SYDr/rC3I7W8S0evUaxppb2zAhLPM
iM78fAvB+v3TWDgPGep59IM/3hxenatCLZzumZ7iBp4qVUy2d8SAzZI9RAgS
2Zu/9B+nf1lnsaJ9kLlvuyKaYPVRugnnp9tjparJjjKeTXcKcfvnzV8GkbJT
iGjNhW+H01Fq4Wac7mF5Vl+oUs1kndm+4xw0kMsl0HL7lVh8x3X+IEROp7bD
gLu012AnZdvkKujSEZzuZef6Kq2lDHMVcdF0RKVqz/o4YOaAnPmhAJv9tGIO
N1aR1leamlcJrQ+Bv6pLe+WKembkvU4I8hYJclhdR4K9DkaerEUoNWKQMw4T
vNTFcGhkO27ir3zBKrOnm91p7ZuNo6OL4Cyy3S/4MWjalygmE/CYKyoaCHek
sq1qvR1dSfHD93HfJdk8d3J1YYv6VfP9jmlfnC3ZF0/2vl/a3KX9bpYWOnLH
oV1R9P6Uij1iV0WpogvAUoSgCpb+h6FHOonvKpvVzfpms9hY22xstpiGNzdr
DFe2DWP5CIXBkrfTD9m/AOiwwraXMRupD+jx9//xXxNgf//v/1H8gFCqL0AZ
2oM5KPpTEUrtRSh/Yc9AST7kghzi/aQQFMOU0nffsf3Uo81kYnnZYa7YcNY3
LS5dnMVbWpH4tcoGra9alGi5Qd+MHqPXFyd+tcLE/ES/AvTCRBeXP3610sf8
1L4C9MLUlhZYfrXiyvwMvwL0wgxfKuH8auWb+Ul+BeiFSb5YJPq1ShWtr1oI
WZzk6woiv1aRovVVSyCLM90y8wYfhtUuD3d/v3FTiHpaXxF+bmIzkzxvQvV+
IKaQEieWfMsDbYgVWeznvqRYgQ5U4vlGPIdosFs8S+GSWwdIRMtcuU2mYogE
IEKY2x5WgkcGqHuei9NeuTM862qtb1JV5LyTmfNMr/NnUVTchzgpSrKeocAt
HzaYdkOZ1oxipecbuygES/1VrDZ9lgbri2eNpu4f2htfDMYqo+anNJN+HULl
L/pd8q1ePcxcP6uMW+/o34M/vuRI0Eu0ynv1WCLrT2cFuF3hi54sppr/2bxl
IqNjkIVhDZ/gJ8oS59AepVEIMdQTTsrzJr3x0pTSGtukk/lK0TztvN3Xonkl
PSxVQxwgAMOyahtQpTfvXTxhG/JX0wSbjKSTtf5aXNAPJ1QuhRdExTnSCTbp
b1DsOyMDnjfEHLzD/b4Ig1il59iACQLAPitu2MR6Y9wBmO0iDGR/gLsIVJTg
/Ka9FfZGCcF++mmuwOGXX3DOWL18KPH4XTra7Ajp3GCbbIK6BoaAGN7RC04F
56iVkE903I/6O4I/+PyCxGAhaykO+3pPwcONnqVykRRbv7ROHQRYpb9LB7r4
e8bRgBYaD5jy5lLcnADI6wGhYNk83icG9+mcmbCzevvsCDzVkV5nRyJ1fYu2
PNdB4GJmKVZYPT9X26+mXjdAl3mWjU63gajs/z6t+59xtRSCSuRDrNUUImVq
qlu22lu1WrNRW09PA8yd00uYKjstp5n+LHCw1qavt+CS7SgPGxFpfezvvicf
kf+AfAkgR6YP6T7S8tzHqxLJenADsTakY9ihBFLk/AKQPoNbgAvMEFc2oISO
GEs8C4qXFaC6pHlHeK4D5GCE9cHIVj2gEYrW3GnfFxI2aWU4wjaJPiHXKRuS
axKCSS5tiCcokGmAcHiRBIyL1dx6J9NxkILcjRPpxp1D3FKQ3ThfnIsCFvtk
NaazcyF/wBVISI2VUViqtYmkwQ1GkhScdoo6OH5iAba0gvfHe8YuDcJoo+3l
mphWq10tb5m11lajttVa38yyjbk6capjenpSYR3POOjkrZaDhHMyobOD2HXI
IPZAo+DbySFl2hN1QOX7eDw7SqQit6SmPjHrJbLE7EEgQcXr4ylo+V0s9yd+
odPOtDmqsX5CF1zozTllXOTaCeGpIty1DfG6B/+FtQdJPw/w0HlqQdNK8D8c
Vy2WazI+Wif5gW9cXL01dEXeLITQuv4f5qftUulP7ADUZ7aUaPIrZm2zIOjZ
uLnSwD3Z60lhHAnX9UAEkBeZkHqTH8v9QblK4ToKL2SBd+QIGAuLB8ZoXPFg
N52z1hssb/Z31/eO9pOzUViAKGyONmSinbbYL7hsOvMCPMrHWMyP2ek51R8u
KCMoFEYQRy4gLFqJ24FEhRcljNcFp1FqB0avyYJum7qW4om2zPYFkuRs4mOi
N4Mn0qQ+WpMpXTDEJI+pTy7daXrKH/AxdT52ZnkvBWbYSrOGkBpw9BllAIvn
SkdMzPXjy3SOLNlLyhXoYN/9q3eXx7tXVNaqLWiW3y3NMr1UmfDykM8e+j/V
h/7Js8ACI852kaHA30gKU9FIUzus6ADsBMfIj24CeO60DNJYXyOBTsycsSG5
045r6L3guZlUaYHW8FL0Je6JFTc8keWTL3TRRbphjiSzyi0M5fJ+q5H5rcqg
o75Glj03pDK6YTAUPjlNoCIMCNUMYAmIY2AEq1FtNsuNJu7IvjnhI+6DEEFg
uuOC7jri0bmYqOtgOM0ViXfxK2BFH74yI/wuPdCqrEql3a40CFhKZBfc9hg3
IAHqEUUTfpBXe4OsjeZa2AufcHC34xFlYowoMLqCZuHiUWg90W4Q49UGU0NC
RKJ8DNVIVXoCokkHeoMdNeAPonSP+3SYlHDsQrVD0qBM3ObUNyCJftq6IkKW
dCrN9laj0mrWaz/I7yvlcrnVajarteoWEfk+f57oKnVbkcy5A0UiPTQX6rNE
eRQKNd9GUlKXmGhrPWGsc/EYHQof5fhYa9xcwe0AounHCB1vgSc56Wua9Sh2
lbDAupDFNnounxgzr8CQvrGY6wpnljPvmHDZAxmdptO8BIskJvkIE75MmTuk
LwmPWUlmcXpGgRBk0jWSAxnB2gBPKlhCg2pzDC41Na528Uos1ymKmLIn2EjD
QVgues8KVEiB6sIpkiihyjB6yIVkGzTZaORyhf0Ycz+KvbzwBH1l0rVdaH9w
ec14aJUrRvKqcezbuES5a69Q7xsQ+kfGUIiRgXMFDDypBMx5+syaKE0ZVAMg
e8SlGNAbihZT9v2IeqKzon0MEtrLWIEmxMxUxpqnvDtHuuQb0MxmGFuoBqxG
q96oN8zRYERg9G1aAIWmC0qlCCFtpfLNpSwlRRjDg15qcBNBVWhEd/EIMmmq
K+nnkhbgKHDfFib4/dy0fQtZnNSmUW4ZoDb1jT/AyrKn7Meo3W4AZ1VMR5f1
4qohlepd+aWYCMEWrZ/AQtlYqA4ehNEDv5YbsBYj1AGgXfFmGW6ASX9mVeaI
fHwNZJ4rRo+AvhldpVKucAIssXOl4XM1gH+GJKADoYbxNDbiKf8ylh5G/eOC
gMzRSXlfHC+v9FRkUpsWfYtvVQO33S7P09cJ/IJyQiR1G3UkNDVVrboFiq5S
rlYzaubgyJ7w+7k43KQGXWxlbcXve9PyxZn3eV8vQtzvcz9WfG7ctFnjDFN4
jn1QHQSuMEYysgdoBLW5QDGgywjIAuKT7QYxkGsSGFOIMBRmFxITgpFDTxbR
ef681AjfgTes7F3KkOWc9IW6TCeCcQwFoXaUPwqg6CB/rMmcHOvHyqd2tdGu
dMoN4OidXaNRrjSMnU5tz9ip1OqtnVpjr7lVJ4guHz+y4uLRsmG7OYhTVrbm
tKrOhmOaE6wc6FEDS3ENrMN93gLoGQSDeE5VQIuWGogX6o2tZqNdqz9UqtVy
uV6uaKfjAsMlkgZCzpFR4QxP1mbKUDPbc0agaPlBpbZ7zWq1YlSbNjda1XbN
aAvRNhqNRqtbs8vdrd7WnDieyrMLdnNxPhveBad/PNKeSSqTRYcgNTrJOVqN
Ci5zokzAwpmOGM8ZPWwi/lXW8Lh5EZx/uXikDmAUgLg5KtKzSVEslyYoM8Ih
XSWgnYGhdtEyIg5Kmw0qo37WbifOIsYgNPohRPymyC2i0zX7WH4nYktBPK0v
q/nhcyzC6fdFfqb+NkAKXXBd8w5erpHoWK2Xt1pPrn3M21c8529gHmh2tgbz
iT76tdwHpwveDbPvaOQeiJkPA+UsQdJCRsaRuLNjNVtzSslWjl80ziY2UZ+J
kI/Sf6hXa61mpV210utHHyq1crsJPt3MZgRgbiIiUE7Wco3p4aJFa6AXS0tb
siAQfw+1+r6Ow6FUA8AUwgoHPQawq5LnvedcMw0z4F08p4SVthIEosgZz+Ag
bZDsL3wqe8aQu3IahNp34sNu3nOkRx2R5LwI6ecUKWhaWCHpurFKnYp77oAH
brOnZkR/YWgZF9YErB3EbOCy9ECvEzjwAzGKEBBicQGEgWkgV1N6kp7BiPRD
gMOhq1J06MzoC/BtrWa72a7UWw3t+R+fxW4kwb3Pl7V7SZtW4IkACx+Y0s4K
2QPgCQj81kul4x6bBrEOESfAeBHeF+ezRItiAoOibjoOQGG+K4fpNRg604Vh
3SYbUV0pU7gLgMkzdnGJ6QWs9MebBGapLRV3qXh5TcepdhK/LgguTX37KsbS
md92OVMRpRJdB0FZjfTrnAaZ7ZQVDgts6qnOUiNptoNuctEx7Bn4IRwTGHxY
XFo0FzCknxlqZXn63REfPjznsuLOypMIFhOIY9QBrXqrXa80GrXWVq0JQllu
1o3PRqeuuewycELZD9hOCMsXvIhNGHbpxQdwZbSuSW+80YqTYnBkZz8wkDxg
B6lol7BobFXBiNWazSag06gaH8qdhsZiB7clLkKIsOZPGS7AoQsvg+Ggl416
vVGpV6oPgRYnsDzo6IM78pyHM8Om3m5VtqrtOkSa9XrZmPRkLY0Eg1Ahn14B
UXtiCULgnyh6x9L73hnVLXBxrXVireSO3H9RbOfquFSaPR4Ih0L9d1j5qu9Z
XBjlvtnBNI3iXsR6v/4tZFfoxYYDgdt2PsMETq6b0udIhut0ImeO+dguD8HD
Z0fSjTahJ9BkShctKgZ+1FAo3KjS6SbAdRN6gTz+wTIu23r7cHe3uLmL4Zjq
pVdPUqZO35OCZAU7hhfdsJz+TXb18K/0ImsbM1WYoqTcKZaSw7LkxFzPgnbL
HKw2K8E68uQuFBHZ5qbOvrlK5w6TW7L0jZi7u+k2ItPhvN6mw0PieD2ULbLm
Z4+X4XrSbZsjAWZcx/2YtaWj6qvkDXFH2cKbubOM3oi0sYTYMspu0sze0vos
z0lR7pLSLl4tlV0F7uJlKOD/T9NNGPRi8MorL9tbLoxFoIv906tGk0xibpxk
yzcBLUOGFxblNw61FeH63rREB9DFXE9z0AuSlEU00/p/WlNP3yuFSwkYTPSR
r9fdY4O1D1Yw3uoZLfvj27eNy4/GmffJbh4Pbq52jIOh9doLcV4EtL4iUpPu
w51qn3102nE7OKvuDI2taNzqjT8c9ldDahmgVZGqxu9jvlfZm/Y/ne+d1Q+v
H4zwrju5licrUmoZoJWReuCHU9c7OApOvc/nrZ0d++4mODLC85WRWgJoVaRu
wO083Ppy0eCTIOw+XFXOL9sH++/3P9yWV0NqGaBVkbp42L27ntr98tvDlt19
y+ODjjG86X+ofgpWQ2oZoFWR2r2bjM9ajS/N8PrYqXZqHz+OP554R4/v5IqM
vgzQqkjxg92gvnN2uXf1fuqPz9udH094dPHJ/8BXRGoZoFWR+rF54tmNrXHZ
rrh7N7X40/FdufPhIegddlZDahmgFZCye/D0vnF35LQr7t0n+Xn3OmrvfJze
7J0fiPejs1cj9SKgVSkVV44e727b9knvZiRru73253JTDCaju8P91Si1DNCq
SHXF5Zfz8/HkTPaGl72Ti96jsA+Do9H1nloNqWWAVkXq6vChUy5Xmtx4e+Z/
6AwPo7P3j8HwI9iu1ZBaBmhVpGqTlvHutrrbuQnLxo87X9ot0Tl73Hnwz45X
Q2oZoBWQinsePFbbjwcfPzR268HV4XD0sTP+cP3Quju9rd68nlQvQ/r/XSkQ
rI8nn04+jO4mHxv+7o335eG2fvC2+UEe7N/VV0NqGaBVkWqcnjRlW40Dzx+M
phdHtxfi01mrd+Z9+HE1pJYBWhWpk4MHe+IdHe13w5OH28ZNc7ovottbX8oV
KbUM0MrWb/+m7bw/CKLOj1+OfGdYrX3esSc71zW+oqZaBmhlpXA0Lu9XVO+D
Gk93IrfZ6d9tfTKujo7kZEWlsATQOtY74uUWVD71OcbdOiwnnf2YQshl8nsB
tGUe0q0gWJqEhSkUetxiRcvTcumkUvqNznKx/7y0hj65bFqtVkKd9PqBiqJf
+6MYWIoo8WcvcidP50vcX/rhjE8x0KknhfNDOn+Z1AEmNe5YQxbQJSkQ3lMF
MkWy4dN6aV0uPVct/YbSeAATf4jJt6dP7oVe/4Fi51x6ENYkwiIAHGYWUpco
iMylCZPweQSkwyobSl5STiT00iD5Sby6OEB9qdiOfrGEyVwKie5XyfKodLxR
R86jEDf0MNGubw7TYa7OHFDtT5Z8Sn9RLLshBSCmdaTZxcWYv+3iKQTEGpcy
Zc5XLa6+lOW4c955Mtp1YZgBXVGt3+R2emyZflAEfyeFrnYp3FagSj9t6x8f
E873az3uKrrz51bMpZqxdnRIMmYHRnoDIiBOtEmrmoFsWHNJhVX5ClpFMvn0
CmBofHr5Lw3ex1pO/Omtaf6Swbk7Z3BUrDLpDyKs6cWCkph+jk1lOfNMIeyH
0kbWtIPQ5ThuPAiwmlD9+n98eNQ/icDwNxH0k+QeMAuIFO/h6zthDGTdcbkP
U4hQtiM8XPEWU2ghHvf5xB1QTEdCKd0fRJ5dDwJPBQj+LvYR4RPJ/T7eUMHx
vNC5HAZ+AOoCLxvhSkzZrXT1+3tA7ICdgRp1pA/6xMYRA7/fBRxixD4Y+JgM
jn/9nzBYFCnd7VaEIA2AG4+78HjEgwmmaAMadHcg/P4joHUUayz0FE5jXIa3
MYgQn7LOwBMRe/vr337937/+bUio4sWGQ1gx3HyGhnOOrICp+UsZfaHFonze
q1ZsAkTvo7D3hHCQIenixqygdL4M/7eXsK5nFeDAgK78InJF0VKz43UceNDY
iUNc4OPAB+E8kwPu2oLTAS76+kAf0CFq+j5omGtlD4Ke8CWS8I6HmIYeCLzC
Hp5PeaxTlaex73Rh9QQ0HkqwOQMewkr5zpR7tBaAZRSMMIsKFI5o9U5A7VOJ
9lEwxSvb8CwL7myEDtvhsLBqVl9I+Ve0J1kecpOhbtU113hzTVJvmMigzrBq
00SSk5DfpPWjQy+hcKeJlL8F0g9A7qeAyw6MDyuGV0gXZUAPdQ4M6rG3QVfg
DyFmpxt6VDyXGLLCwQU0QnRta7WMn5MS3uQaLtAf9yixrzxUgdsljXZ93Sz9
PyVfTLNTcgAA

-->

</rfc>
