nss-util-3.67.0-2.el8_4 >  A `U]"ӫ. f}@J^Q6_TsG{gVzKWxwDVi RX|FyT%~FȍDZM58YccF^#EXer kkŕb 8V0qRSow*P_]0'rqAuo CE\z aTX)v h(vrD$ nkkٖCn*M zaF@dO^?^BfnhjWܸ*ܞNBWW_ {*4!AF3$O#]qUa1w6$5a8cc982f50e0a1824d227386cd056c606b289bc3a13551ed29e7d428c45474183a6a4e775600c8b478d714e8f06ff6478acf3c4 D`U]ooa+\J 3"ل)1Y hRjUȗGpL|ј\i bM1S";a(ս|1L#ވ?}7{\8b$y(GCf" OEęN*"Υ^1_塠eԫJuHlζ ]̀C^i8ޒ_Zod;VFPknF.*uVFͶO&ϝ_-8Kkt_mEEudMQ U]햌`_z(O㦄`׫ jNj4g9Siz%lOmrF9KZ1I7HײǞ/.; ~d' &uvۖ!kyXX+#h#Sp R1XZ1csT}YiHί\/yAؽ 3or^SBNV⅏iDɔFãr@>p<?d   F $,D P \ t  $<Zx(p(J8T9 :ZG H8IPXXY\]^@bde f lt(u@vXwxy,Cnss-util3.67.02.el8_4Network Security Services Utilities LibraryUtilities for Network Security Services and the Softoken module`x86-01.mbox.centos.orgnUnspecifiedhttp://www.mozilla.org/projects/security/pki/nss/linuxx86_64$'FAAA큤````Ԕ``73138fa6a143ada911a37984c09e5972ace993b60642e7cf94d4fbbeaa16cdc2a20c1a32d1f8102432360b42e932869f7c11c7cdbacf9cac554c422132af47f4../../../../usr/lib64/libnssutil3.sorootrootrootrootrootrootrootrootrootrootrootrootnss-3.67.0-2.el8_4.src.rpmlibnssutil3.so()(64bit)libnssutil3.so(NSSUTIL_3.12)(64bit)libnssutil3.so(NSSUTIL_3.12.3)(64bit)libnssutil3.so(NSSUTIL_3.12.5)(64bit)libnssutil3.so(NSSUTIL_3.12.7)(64bit)libnssutil3.so(NSSUTIL_3.13)(64bit)libnssutil3.so(NSSUTIL_3.14)(64bit)libnssutil3.so(NSSUTIL_3.15)(64bit)libnssutil3.so(NSSUTIL_3.17.1)(64bit)libnssutil3.so(NSSUTIL_3.21)(64bit)libnssutil3.so(NSSUTIL_3.24)(64bit)libnssutil3.so(NSSUTIL_3.25)(64bit)libnssutil3.so(NSSUTIL_3.31)(64bit)libnssutil3.so(NSSUTIL_3.33)(64bit)libnssutil3.so(NSSUTIL_3.38)(64bit)libnssutil3.so(NSSUTIL_3.39)(64bit)libnssutil3.so(NSSUTIL_3.59)(64bit)nss-utilnss-util(x86-64)@@@@@@@@@@@@     @libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libdl.so.2()(64bit)libnspr4.so()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)nsprrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)4.25.03.0.4-14.6.0-14.0-15.2-14.14.3`̊`9@`Ȗ@`D`r_@_^@___@__"@_"@_"@_!d_@_ L_ _@^^@@^@^ۅ@^4]N@]]߶]e@]M@]µ]L]]^@\F@\Q\\\\\\@\I\I\U@\ `\l@[[[u[#@[[W[O+[M@[ZZw@Z|;Zo Zo Zg#Z ZZZ@Y+@Y{YY@Yn@YV@Y@YyYm@Yg`YJ_Y1S@XX@XX @XXYX@X@XX~@Xx@XoX>@X*X@WW@Wt@W~Wv[@WrfWoWm WbWQq@WPWJWDB@W4p@W@Wo@W@VV޾V޾V@VяVIVɦV@V@V=@V@V@VO @VHsVEV3[V UYU@UU@U@U>Ua@Ug@U[%UUU @T@Ts@TTء@T@TÉ@TT@T@T?@T:m@T"@S@S<@S@S@S @SSSSpShS(5@S@SRy@RJ@R@RR@RSRR@Rm@Rg@RD!R@RRR|Q@Q*@QQ@QKQ@QQW@Qw@Q]k@QNQ9Q7/Q#@QQ @P!@PՠP @PqP@P@PAPXPd@Pd@PPP@PP5@PPnP;a@P(@P H@O;O;O@OiO@O@O}O~OiOYOX@OOdO&@O!@@OO@O@N>@N>@NNܲ@N`NؽNN@NuN;@Np@Nf @NA!@N*NpM@MWMc@MM@M@MMfH@M^_@MZjMS@MQ0@MQ0@MQ0@MQ0@MK@MGMF@M6@M-MM@Ls@LOLLZ@L6LdL@L*@L@LA@LL@L4Lx@Lx@Li(@Lf@L_L_LT@L0L0L K @KsKsKKCKCKCK]KMKLd@KD{@K<@K5K4@K,@K+nK*@K K@K@K@KJݦ@J - 3.67.0-2Bob Relyea - 3.67.0-1Bob Relyea - 3.66.0-2Bob Relyea - 3.66.0-1.1Bob Relyea - 3.66.0-1Bob Relyea - 3.53.1-17Bob Relyea - 3.53.1-16Bob Relyea - 3.53.1-15Bob Relyea - 3.53.1-14Bob Relyea - 3.53.1-13Bob Relyea - 3.53.1-12Bob Relyea - 3.53.1-11Bob Relyea - 3.53.1-10Daiki Ueno - 3.53.1-9Daiki Ueno - 3.53.1-8Bob Relyea - 3.53.1-7Daiki Ueno - 3.53.1-6Bob Relyea - 3.53.1-5Bob Relyea - 3.53.1-4Daiki Ueno - 3.53.1-3Daiki Ueno - 3.53.1-2Daiki Ueno - 3.53.1-1Daiki Ueno - 3.53.0-1Bob Relyea - 3.44.0-15Bob Relyea - 3.44.0-14Bob Relyea - 3.44.0-13Daiki Ueno - 3.44.0-12Bob Relyea - 3.44.0-11Daiki Ueno - 3.44.0-10Bob Relyea - 3.44.0-9Bob Relyea - 3.44.0-8Daiki Ueno - 3.44.0-7Daiki Ueno - 3.44.0-6Daiki Ueno - 3.44.0-5Bob Relyea - 3.44.0-4.1Bob Relyea - 3.44.0-4Daiki Ueno - 3.44.0-3Bob Relyea - 3.44.0-2Daiki Ueno - 3.44.0-1Daiki Ueno - 3.41.0-5Bob Relyea - 3.41.0-4Daiki Ueno - 3.41.0-3Daiki Ueno - 3.41.0-2Daiki Ueno - 3.41.0-1Daiki Ueno - 3.39.0-1.5Bob Relyea - 3.39.0-1.4Daiki Ueno - 3.39.0-1.3Daiki Ueno - 3.39.0-1.2Daiki Ueno - 3.39.0-1.1Daiki Ueno - 3.39.0-1.0Daiki Ueno - 3.38.0-1.2Daiki Ueno - 3.38.0-1.1Daiki Ueno - 3.38.0-1.0Kai Engert - 3.36.1-1.2Daiki Ueno - 3.36.1-1.1Daiki Ueno - 3.36.1-1.0Daiki Ueno - 3.36.0-1.0Fedora Release Engineering - 3.35.0-5Kai Engert - 3.35.0-4Kai Engert - 3.35.0-3Daiki Ueno - 3.35.0-2Daiki Ueno - 3.34.0-2Daiki Ueno - 3.33.0-6Kai Engert - 3.33.0-5Kai Engert - 3.33.0-4Kai Engert - 3.33.0-3Daiki Ueno - 3.33.0-2Daiki Ueno - 3.32.1-2Daiki Ueno - 3.32.0-4Kai Engert - 3.32.0-3Daiki Ueno - 3.32.0-2Fedora Release Engineering - 3.31.0-6Fedora Release Engineering - 3.31.0-5Daiki Ueno - 3.31.0-4Daiki Ueno - 3.31.0-3Daiki Ueno - 3.31.0-2Daiki Ueno - 3.30.2-3Daiki Ueno - 3.30.2-2Kai Engert - 3.30.0-3Daiki Ueno - 3.30.0-2Kai Engert - 3.29.1-3Daiki Ueno - 3.29.1-2Daiki Ueno - 3.29.0-3Daiki Ueno - 3.29.0-2Daiki Ueno - 3.28.1-6Daiki Ueno - 3.28.1-5Daiki Ueno - 3.28.1-4Daiki Ueno - 3.28.1-3Daiki Ueno - 3.28.1-2Daiki Ueno - 3.27.2-2Daiki Ueno - 3.27.0-5Kai Engert - 3.27.0-4Daiki Ueno - 3.27.0-3Daiki Ueno - 3.27.0-2Daiki Ueno - 3.26.0-2Elio Maldonado - 3.25.0-6Elio Maldonado - 3.25.0-5Elio Maldonado - 3.25.0-4Elio Maldonado - 3.25.0-3Elio Maldonado - 3.25.0-2Kamil Dudka - 3.24.0-3Elio Maldonado - 3.24.0-2.3Elio Maldonado - 3.24.0-2.2Elio Maldonado - 3.24.0-2.1Elio Maldonado - 3.24.0-2.0Elio Maldonado - 3.23.0-9Elio Maldonado - 3.23.0-8Elio Maldonado - 3.23.0-7Elio Maldonado - 3.23.0-6Elio Maldonado - 3.23.0-5Elio Maldonado - 3.23.0-4Elio Maldonado - 3.23.0-3Elio Maldonado - 3.23.0-2Elio Maldonado - 3.22.2-2Elio Maldonado - 3.22.1-3Elio Maldonado - 3.22.1-1Elio Maldonado - 3.22.0-3Elio Maldonado - 3.22.0-2Fedora Release Engineering - 3.21.0-7Elio Maldonado - 3.21.0-6Michal Toman - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado Batiz - 3.21.1-2Elio Maldonado - 3.20.1-2Elio Maldonado - 3.20.0-6Elio Maldonado - 3.20.0-5Elio Maldonado - 3.20.0-4Elio Maldonado - 3.20.0-3Elio Maldonado - 3.20.0-2Elio Maldonado - 3.19.3-2Elio Maldonado - 3.19.2-3Kai Engert - 3.19.2-2Kai Engert - 3.19.1-2Kai Engert - 3.19.0-2Kai Engert - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.17.4-5Till Maas - 3.17.4-4Elio Maldonado - 3.17.4-3Elio Maldonado - 3.17.4-2Elio Maldonado - 3.17.4-1Ville Skyttä - 3.17.3-4Elio Maldonado - 3.17.3-3Elio Maldonado - 3.17.3-2Elio Maldonado - 3.17.3-1Elio Maldonado - 3.17.2-2Elio Maldonado - 3.17.2-1Kai Engert - 3.17.1-1Kevin Fenzi - 3.17.0-2Elio Maldonado - 3.17.0-1Fedora Release Engineering - 3.16.2-4Elio Maldonado - 3.16.2-3Tom Callaway - 3.16.2-2Elio Maldonado - 3.16.2-1Elio Maldonado - 3.16.1-4Fedora Release Engineering - 3.16.1-3Jaromir Capik - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.16.0-1Elio Maldonado - 3.15.5-2Elio Maldonado - 3.15.5-1Elio Maldonado - 3.15.4-5Elio Maldonado - 3.15.4-4Elio Maldonado - 3.15.4-3Peter Robinson 3.15.4-2Elio Maldonado - 3.15.4-1Elio Maldonado - 3.15.3.1-1Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.2-3Elio Maldonado - 3.15.2-2Elio Maldonado - 3.15.2-1Elio Maldonado - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.15-5emaldona - 3.15-4emaldona - 3.15-3Elio Maldonado - 3.15-2Elio Maldonado - 3.15-1Elio Maldonado - 3.15-0.1.beta1.2Elio Maldonado - 3.15-0.1.beta1.1Kai Engert - 3.14.3-12Kai Engert - 3.14.3-10Kai Engert - 3.14.3-9Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.2-2Elio Maldonado - 3.14.2-1Kai Engert - 3.14.1-3Elio Maldonado - 3.14.1-2Elio Maldonado - 3.14.1-1Elio Maldonado - 3.14-12Elio Maldonado - 3.14-11Elio Maldonado - 3.14-10Elio Maldonado - 3.14-9Elio Maldonado - 3.14-8Elio Maldonado - 3.14-7Elio Maldonado - 3.14-6Elio Maldonado - 3.14-5Elio Maldonado - 3.14-4Elio Maldonado - 3.14-3Elio Maldonado - 3.14-2Elio Maldonado - 3.14-1Elio Maldonado - 3.14-0.1.rc.1Kai Engert - 3.13.6-1Elio Maldonado - 3.13.5-8Elio Maldonado - 3.13.5-7Fedora Release Engineering - 3.13.5-6Elio Maldonado - 3.13.5-5Elio Maldonado - 3.13.5-4Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.4-3Elio Maldonado - 3.13.4-2Elio Maldonado - 3.13.4-1Elio Maldonado - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Tom Callaway - 3.13.1-13Elio Maldonado - 3.13.1-12Fedora Release Engineering - 3.13.1-11Elio Maldonado - 3.13.1-11Elio Maldonado - 3.13.1-10elio maldonado - 3.13.1-9Elio Maldonado - 3.13.1-8Elio Maldonado - 3.13.1-7Elio Maldonado - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado Batiz - 3.13.1-4Elio Maldonado - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.13-1Elio Maldonado - 3.13-0.1.rc0.1Elio Maldonado - 3.12.11-3Kai Engert - 3.12.11-2Elio Maldonado - 3.12.11-1Elio Maldonado - 3.12.10-6Michael Schwendt - 3.12.10-5Elio Maldonado - 3.12.10-4Dennis Gilmore - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.10-0.1.beta1Elio Maldonado - 3.12.9-15Elio Maldonado - 3.12.9-14Elio Maldonado - 3.12.9-13Elio Maldonado - 3.12.9-12Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado - 3.12.9-9Fedora Release Engineering - 3.12.9-8Elio Maldonado - 3.12.9-7Christopher Aillon - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.9-0.1.beta2Elio Maldonado - 3.12.8.99.2-1Elio Maldonado - 3.12.8.99.1-1Elio Maldonado - 3.12.8-9Elio Maldonado - 3.12.8-8Elio Maldonado - 3.12.8-7Elio Maldonado - 3.12.8-6Elio Maldonado - 3.12.8-5Elio Maldonado - 3.12.8-4Elio Maldonado - 3.12.8-3Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Elio Maldonado - 3.12.7.99.4-1Elio Maldonado - 3.12.7.99.3-2Elio Maldonado - 3.12.7.99.3-1Elio Maldonado - 3.12.7-3Elio Maldonado - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-12Elio Maldonado - 3.12.6-11Elio Maldonado - 3.12.6-10Elio Maldonado - 3.12.6-9Dennis Gilmore - 3.12.6-8Elio Maldonado - 3.12.6-7Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-5Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1.13.2Elio Maldonado - 3.12.5-1.13.1Elio Maldonado - 3.12.5-1.13Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.9Elio Maldonado - 3.12.5-2.7Elio Maldonado - 3.12.5-1.6Elio Maldonado - 3.12.5-1.5Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1Elio Maldonado - 3.12.4-14.1Elio Maldonado - 3.12.4-13.1Elio Maldonado - 3.12.4-13Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Fix coverity issues- Rebase to NSS 3.67- Restore old pkcs12 defaults.- build nss for older nspr so we can pass gating with the new nspr in the build root- Rebase to NSS 3.66- Fix various corner cases with ike v1 app b support.- Fix the following CVE - CVE-2020-12403 chacha-poly issues - CVE-2020-12400 constant time ECC. - CVE-2020-6829 constant time ECC.- Revert some policy changes the generate ABI runtime issues.- Add support for enable/disable in policy. Now if your policy file has disallow=x enable=y it will act just like our other libraries.- Add OAEP interface so applications can wrap keys with RSA-OAEP rather than RSA-PKCS-1.- fips need to reject small primes even if they are approved - code to autodetect whether or not to use the cache needs to do so in a way that doesn't mess with filesystem negative file caching. - add kdf selftests- Fix issue with upgradedb where upgradedb expects standard to generate dbm databases, not sql databases (default in RHEL8)- Disable dh timing test because it's unreliable on s390- Explicitly enable upgradedb/sharedb test cycles- Disable Delegated Credentials for TLS- Fix attribute decryption issue where the private key components integrity check on private attributes where not being checked.- Update nss-rsa-pkcs1-sigalgs.patch to the upstream version- Include required checks for dh and ecdh key generation in FIPS mode.- Add better checks for dh derive operations in FIPS mode.- Disable NSS_HASH_ALG_SUPPORT as well for MD5 (#1849938) - Adjust for update-crypto-policies packaging change (#1848649) - Fix compilation with -Werror=strict-prototypes (#1843417)- Fix regression in MD5 disablement (#1849938) - Include rsa_pkcs1_* in signature_algorithms extension (#1847945)- Update to NSS 3.53.1- Update to NSS 3.53- Fix swapped CMAC PKCS #11 values. - Fix data alignment crash in CMAC.- Fix coverify scan issue- Fix endian problem in SP-800 108 code.- Install cmac.h required by blapi.h (#1764513) - Fix out-of-bounds write in NSC_EncryptUpdate (#1775913)- Add SP-800 108 Generalized kdf- Check policy against hash algorithms used for ServerKeyExchange (#1730039)- Add CMAC- CKM_NSS_IKE1_APP_B_PRF_DERIVE was missing from the mechanism list, preventing PK11_Derive*() from using it. Add gtests for the PK11_Derive interface for all the CKM_NSS_IKE*_DERIVE mechanism.- Backport fixes from 3.44.1- Add continuous RNG test required by FIPS - fipstest: use CKM_TLS12_MASTER_KEY_DERIVE instead of vendor specific mechanism- Rebuild with the correct build target- rebuild to try to retrigger CI tests- Fix certutil man page - Fix extracting a public key from a private key for dh, ec, and dsa- Disable TLS 1.3 under FIPS mode - Disable RSASSA-PKCS1-v1_5 in TLS 1.3 - Fix post-handshake auth transcript calculation if SSL_ENABLE_SESSION_TICKETS is set - Revert the change to use XDG basedirs (mozilla#818686)- Add ike mechanisms in softokn - Add FIPS checks in softoken- Update to NSS 3.44 - Define NSS_SEED_ONLY_DEV_URANDOM=1 to exclusively use getentropy - Use %autosetup - Clean up manual pages generation - Clean up %check - Remove prelink dependency, which is not available in RHEL-8 - Remove upstreamed patches- Update manual pages to reflect recent changes in commands- Make sure corresponding public keys are created when importing private keys.- Fix the last change - Add --no-reload option to update-crypto-policies to avoid unnecessary restart of daemons- Restore LDFLAGS injection when linking DSO- Update to NSS 3.41 - Consolidate nss-util, nss-softokn, and nss into a single source package- Fix the last commit- Support for IKE/IPsec typical PKIX usage so libreswan can use nss without rejecting certs based on EKU- Backport upstream fixes for rhbz#1649026, rhbz#1608895, rhbz#1644854 - Document PKCS #11 URI - Add warning when adding module with modutil while p11-kit is enabled- Update nss-dsa.patch to not advertise DSA signature algorithm - Update PayPal test certs for testing- Backport "DSA" keyword in crypto-policies- Update to NSS 3.39- Fix LDFLAGS injection when linking DSO- Install crypto-policies configuration file for https://fedoraproject.org/wiki/Changes/NSSLoadP11KitModules - Port enable-fips-when-system-is-in-fips-mode.patch from RHEL-7 - Use %ldconfig_scriptlets - Remove needless use of %defattr, by Jason Tibbitts- Update to NSS 3.38- Backport upstream addition of nss-policy-check utility, rhbz#1428746, includes required fixes for mozbz#1296263 and mozbz#1474875- Switch the default DB type to SQL - Enable SSLKEYLOGFILE- Update to NSS 3.36.1 - Remove nss-3.14.0.0-disble-ocsp-test.patch - Fix partial injection of LDFLAGS - Remove NSS_NO_PKCS11_BYPASS, which is no-op in upstream- Update to NSS 3.36.0 - Add gcc-c++ to BuildRequires (C++ is needed for gtests) - Make test failure detection robuster- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Fix a compiler error with gcc 8, mozbz#1434070 - Set NSS_FORCE_FIPS=1 at %build time, and remove from %check.- Stop pulling in nss-pem automatically, packages that need it should depend on it, rhbz#1539401- Update to NSS 3.35.0- Update to NSS 3.34.0- Make sure 32bit nss-pem always be installed with 32bit nss in multlib environment, patch by Kamil Dudka- Fix test script- Update tests to be compatible with default NSS DB changed to sql (the default was changed in the nss-util package).- rhbz#1505487, backport upstream fixes required for rhbz#1496560- Update to NSS 3.33.0- Update to NSS 3.32.1- Update iquote.patch to really prefer in-tree headers over system headers- NSS libnssckbi.so has already been obsoleted by p11-kit-trust, rhbz#1484449- Update to NSS 3.32.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Backport mozbz#1381784 to avoid deadlock in dnf- Move signtool to %_libdir/nss/unsupported-tools, for: https://fedoraproject.org/wiki/Changes/NSSSigntoolDeprecation- Rebase to NSS 3.31.0- Enable gtests- Rebase to NSS 3.30.2 - Enable TLS 1.3- Backport upstream mozbz#1328318 to support crypto policy FUTURE.- Rebase to NSS 3.30.0 - Remove upstreamed patches- Backport mozbz#1334976 and mozbz#1336487.- Rebase to NSS 3.29.1- Disable TLS 1.3, following the upstream change- Rebase to NSS 3.29.0 - Suppress -Werror=int-in-bool-context warnings with GCC7- Work around pkgconfig -> pkgconf transition issue (releng#6597)- Disable TLS 1.3 - Add "Conflicts" with packages using older Mozilla codebase, which is not compatible with NSS 3.28.1 - Remove NSS_ECC_MORE_THAN_SUITE_B setting, as it was removed in upstream- Add "Conflicts" with older firefox packages which don't have support for smaller curves added in NSS 3.28.1- Fix incorrect version specification in %nss_{util,softokn}_version, pointed by Elio Maldonado- Rebase to NSS 3.28.1 - Remove upstreamed patch for disabling RSA-PSS - Re-enable TLS 1.3- Rebase to NSS 3.27.2- Revert the previous fix for RSA-PSS and use the upstream fix instead- Disable the use of RSA-PSS with SSL/TLS. #1383809- Disable TLS 1.3 for now, to avoid reported regression with TLS to version intolerant servers- Rebase to NSS 3.27.0 - Remove upstreamed ectest patch- Rebase to NSS 3.26.0 - Update check policy file patch to better match what was upstreamed - Remove conditionally ignore system policy patch as it has been upstreamed - Skip ectest as well as ecperf, which are built as part of nss-softokn - Fix rpmlint error regarding %define usage- Incorporate some changes requested in upstream review and commited upstream (#1157720)- Add support for conditionally ignoring the system policy (#1157720) - Remove unneeded test scripts patches in order to run more tests - Remove unneeded test data modifications from the spec file- Remove obsolete patch and spurious lines from the spec file (#1347336)- Cleanup spec file and patches and add references to bugs filed upstream- Rebase to nss 3.25- decouple nss-pem from the nss package (#1347336)- Apply the patch that was last introduced - Renumber and reorder some of the patches - Resolves: Bug 1342158- Allow application requests to disable SSL v2 to succeed - Resolves: Bug 1342158 - nss-3.24 does no longer support ssl V2, installation of IPA fails because nss init fails- Rebase to NSS 3.24.0 - Restore setting the policy file location - Make ssl tests scripts aware of policy - Ajust tests data expected result for policy- Bootstrap build to rebase to NSS 3.24.0 - Temporarily not setting the policy file location- Change POLICY_FILE to "nss.config"- Change POLICY_FILE to "nss.cfg"- Change the POLICY_PATH to "/etc/crypto-policies/back-ends" - Regenerate the check policy patch with hg to provide more context- Fix typo in the last %changelog entry- Load policy file if /etc/pki/nssdb/policy.cfg exists - Resolves: Bug 1157720 - NSS should enforce the system-wide crypto policy- Remove unused patch rendered obsolete by pem update- Update pem sources to latest from nss-pem upstream - Resolves: Bug 1300652 - [PEM] insufficient input validity checking while loading a private key- Rebase to NSS 3.23- Rebase to NSS 3.22.2- Fix ssl2/exp test disabling to run all the required tests- Rebase to NSS 3.22.1- Update .gitignore as part of updating to nss 3.22- Update to NSS 3.22- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Resolves: Bug 1299040 - Enable ssl_gtests upstream test suite - Remove 'export NSS_DISABLE_GTESTS=1' go ssl_gtests are built - Use %define when specifying the nss_tests to run- Add 64-bit MIPS to multilib arches- Update %{nss_util_version} and %{nss_softokn_version} to 3.21.0 - Resolves: Bug 1284095 - all https fails with sec_error_no_token- Add references to bugs filed upstream- Update to NSS 3.21 - Package listsuites as part of the unsupported tools set - Resolves: Bug 1279912 - nss-3.21 is available - Resolves: Bug 1258425 - Use __isa_bits macro instead of list of 64-bit - Resolves: Bug 1280032 - Package listsuites as part of the nss unsupported tools set- Update to NSS 3.20.1- Enable ECC cipher-suites by default [hrbz#1185708] - Split the enabling patch in two for easier maintenance - Remove unused patches rendered obsolete by prior rebase- Enable ECC cipher-suites by default [hrbz#1185708] - Implement corrections requested in code review- Enable ECC cipher-suites by default [hrbz#1185708]- Fix patches that disable ssl2 and export cipher suites support - Fix libssl patch that disable ssl2 & export cipher suites to not disable RSA_WITH_NULL ciphers - Fix syntax errors in patch to skip ssl2 and export cipher suite tests - Turn ssl2 off by default in the tstclnt tool - Disable ssl stress tests containing TLS RC4 128 with MD5- Update to NSS 3.20- Update to NSS 3.19.3- Create on the fly versions of sslcov.txt and sslstress.txt that disable tests for SSL2 and EXPORT ciphers- Update to NSS 3.19.2- Update to NSS 3.19.1- Update to NSS 3.19- Replace expired test certificates, upstream bug 1151037- Update to nss-3.18.0 - Resolves: Bug 1203689 - nss-3.18 is available- Disable export suites and SSL2 support at build time - Fix syntax errors in various shell scripts - Resolves: Bug 1189952 - Disable SSL2 and the export cipher suites- Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code- Commented out the export NSS_NO_SSL2=1 line to not disable ssl2 - Backing out from disabling ssl2 until the patches are fixed- Disable SSL2 support at build time - Fix syntax errors in various shell scripts - Resolves: Bug 1189952 - Disable SSL2 and the export cipher suites- Update to nss-3.17.4- Own the %{_datadir}/doc/nss-tools dir- Resolves: Bug 987189 - nss-tools RPM conflicts with perl-PAR-Packer - Install pp man page in %{_datadir}/doc/nss-tools/pp.1 - Use %{_mandir} instead of /usr/share/man as more generic- Install pp man page in alternative location - Resolves: Bug 987189 - nss-tools RPM conflicts with perl-PAR-Packer- Update to nss-3.17.3 - Resolves: Bug 1171012 - nss-3.17.3 is available- Resolves: Bug 994599 - Enable TLS 1.2 by default- Update to nss-3.17.2- Update to nss-3.17.1 - Add a mechanism to skip test suite execution during development work- Rebuild for rpm bug 1131960- Update to nss-3.17.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Replace expired PayPal test cert with current one to prevent build failure- fix license handling- Update to nss-3.16.2- Remove unwanted source directories at end of %prep so it truly does it - Skip the cipher suite already run as part of the nss-softokn build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Replacing ppc64 and ppc64le with the power64 macro - Related: Bug 1052545 - Trivial change for ppc64le in nss spec- Update to nss-3.16.1 - Update the iquote patch on account of the rebase - Improve error detection in the %section - Resolves: Bug 1094702 - nss-3.16.1 is available- Update to nss-3.16.0 - Cleanup the copying of the tools man pages - Update the iquote.patch on account of the rebase- Restore requiring nss_softokn_version >= 3.15.5- Update to nss-3.15.5 - Temporarily requiring only nss_softokn_version >= 3.15.4 - Fix location of sharedb files and their manpages - Move cert9.db, key4.db, and pkcs11.txt to the main package - Move nss-sysinit manpages tar archives to the main package - Resolves: Bug 1066877 - nss-3.15.5 is available - Resolves: Bug 1067091 - Move sharedb files to the %files section- Revert previous change that moved some sysinit manpages - Restore nss-sysinit manpages tar archives to %files sysinit - Removing spurious wildcard entry was the only change needed- Add explanatory comments for iquote.patch as was done on f20- Update pem sources to latest from nss-pem upstream - Pick up pem fixes verified on RHEL and applied upstream - Fix a problem where same files in two rpms created rpm conflict - Move some nss-sysinit manpages tar archives to the %files the - All man pages are listed by name so there shouldn't be wildcard inclusion - Add support for ppc64le, Resolves: Bug 1052545- ARM tests pass so remove ARM conditional- Update to nss-3.15.4 (hg tag NSS_3_15_4_RTM) - Resolves: Bug 1049229 - nss-3.15.4 is available - Update pem sources to latest from the interim upstream for pem - Remove no longer needed patches - Update pem/rsawrapr.c patch on account of upstream changes to freebl/softoken - Update iquote.patch on account of upstream changes- Update to nss-3.15.3.1 (hg tag NSS_3_15_3_1_RTM) - Resolves: Bug 1040282 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) - Resolves: Bug 1040192 - nss-3.15.3.1 is available- Bump the release tag- Update to NSS_3_15_3_RTM - Resolves: Bug 1031897 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws - Fix option descriptions for setup-nsssysinit manpage - Fix man page of nss-sysinit wrong path and other flaws - Document email option for certutil manpage - Remove unused patches- Revert one change from last commit to preserve full nss pluggable ecc supprt [1019245]- Use the full sources from upstream - Bug 1019245 - ECDHE in openssl available -> NSS needs too for Firefox/Thunderbird- Update to NSS_3_15_2_RTM - Update iquote.patch on account of modified prototype on cert.h installed by nss-devel- Update pem sources to pick up a patch applied upstream which a faulty merge had missed - The pem module should not require unique file basenames- Update pem sources to the latest from interim upstream- Resolves: rhbz#996639 - Minor bugs in nss man pages - Fix some typos and improve description and see also sections- Cleanup spec file to address most rpmlint errors and warnings - Using double percent symbols to fix macro-in-comment warnings - Ignore unversioned-explicit-provides nss-system-init per spec comments - Ignore invalid-url Source0 as it comes from the git lookaside cache - Ignore invalid-url Source12 as it comes from the git lookaside cache- Add man page for pkcs11.txt configuration file and cert and key databases - Resolves: rhbz#985114 - Provide man pages for the nss configuration files- Fix errors in the man pages - Resolves: rhbz#984106 - Add missing option descriptions to man pages for {cert|cms|crl}util - Resolves: rhbz#982856 - Fix path to script in man page for nss-sysinit- Update to NSS_3_15_1_RTM - Enable the iquote.patch to access newly introduced types- Install man pages for nss-tools and the nss-config and setup-nsssysinit scripts - Resolves: rhbz#606020 - nss security tools lack man pages- Build nss without softoken or util sources in the tree - Resolves: rhbz#689918- Update ssl-cbc-random-iv-by-default.patch- Fix generation of NSS_VMAJOR, NSS_VMINOR, and NSS_VPATCH for nss-config- Update to NSS_3_15_RTM- Fix incorrect path that hid failed test from view - Add ocsp to the test suites to run but ... - Temporarily disable the ocsp stapling tests - Do not treat failed attempts at ssl pkcs11 bypass as fatal errors- Update to NSS_3_15_BETA1 - Update spec file, patches, and helper scripts on account of a shallower source tree- Update expired test certificates (fixed in upstream bug 852781)- Fix incorrect post/postun scripts. Fix broken links in posttrans.- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement.- Update to NSS_3_14_3_RTM - sync up pem rsawrapr.c with softoken upstream changes for nss-3.14.3 - Resolves: rhbz#908257 - CVE-2013-1620 nss: TLS CBC padding timing attack - Resolves: rhbz#896651 - PEM module trashes private keys if login fails - Resolves: rhbz#909775 - specfile support for AArch64 - Resolves: rhbz#910584 - certutil -a does not produce ASCII output- Allow building nss against older system sqlite- Update to NSS_3_14_2_RTM- Update to NSS_3_14_1_WITH_CKBI_1_93_RTM- Require nspr >= 4.9.4 - Fix changelog invalid dates- Update to NSS_3_14_1_RTM- Bug 879978 - Install the nssck.api header template where mod_revocator can access it - Install nssck.api in /usr/includes/nss3/templates- Bug 879978 - Install the nssck.api header template in a place where mod_revocator can access it - Install nssck.api in /usr/includes/nss3- Bug 870864 - Add support in NSS for Secure Boot- Disable bypass code at build time and return failure on attempts to enable at runtime - Bug 806588 - Disable SSL PKCS #11 bypass at build time- Fix pk11wrap locking which fixes 'fedpkg new-sources' and 'fedpkg update' hangs - Bug 872124 - nss-3.14 breaks fedpkg new-sources - Fix should be considered preliminary since the patch may change upon upstream approval- Add a dummy source file for testing /preventing fedpkg breakage - Helps test the fedpkg new-sources and upload commands for breakage by nss updates - Related to Bug 872124 - nss 3.14 breaks fedpkg new-sources- Fix a previous unwanted merge from f18 - Update the SS_SSL_CBC_RANDOM_IV patch to match new sources while - Keeping the patch disabled while we are still in rawhide and - State in comment that patch is needed for both stable and beta branches - Update .gitignore to download only the new sources- Fix the spec file so sechash.h gets installed - Resolves: rhbz#871882 - missing header: sechash.h in nss 3.14- Update the license to MPLv2.0- Use only -f when removing unwanted headers- Add secmodt.h to the headers installed by nss-devel - nss-devel must install secmodt.h which moved from softoken to pk11wrap with nss-3.14- Update to NSS_3_14_RTM- Update to NSS_3_14_RC1 - update nss-589636.patch to apply to httpdserv - turn off ocsp tests for now - remove no longer needed patches - remove headers shipped by nss-util- Update to NSS_3_13_6_RTM- Rebase pem sources to fedora-hosted upstream to pick up two fixes from rhel-6.3 - Resolves: rhbz#847460 - Fix invalid read and free on invalid cert load - Resolves: rhbz#847462 - PEM module may attempt to free uninitialized pointer - Remove unneeded fix gcc 4.7 c++ issue in secmodt.h that actually undoes the upstream fix- Fix pluggable ecc support- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Fix checkin comment to prevent unwanted expansions of percents- Resolves: Bug 830410 - Missing Requires %{?_isa} - Use Requires: %{name}%{?_isa} = %{version}-%{release} on tools - Drop zlib requires which rpmlint reports as error E: explicit-lib-dependency zlib - Enable sha224 portion of powerup selftest when running test suites - Require nspr 4.9.1- Resolves: rhbz#833529 - revert unwanted change to nss.pc.in- Resolves: rhbz#833529 - Remove unwanted space from the Libs: line on nss.pc.in- Update to NSS_3_13_5_RTM- Resolves: Bug 812423 - nss_Init leaks memory, fix from RHEL 6.3- Resolves: Bug 805723 - Library needs partial RELRO support added - Patch coreconf/Linux.mk as done on RHEL 6.2- Update to NSS_3_13_4_RTM - Update the nss-pem source archive to the latest version - Remove no longer needed patches - Resolves: Bug 806043 - use pem files interchangeably in a single process - Resolves: Bug 806051 - PEM various flaws detected by Coverity - Resolves: Bug 806058 - PEM pem_CreateObject leaks memory given a non-existing file name- Resolves: Bug 805723 - Library needs partial RELRO support added- Cleanup of the spec file - Add references to the upstream bugs - Fix typo in Summary for sysinit- Pick up fixes from RHEL - Resolves: rhbz#800674 - Unable to contact LDAP Server during winsync - Resolves: rhbz#800682 - Qpid AMQP daemon fails to load after nss update - Resolves: rhbz#800676 - NSS workaround for freebl bug that causes openswan to drop connections- Update to NSS_3_13_3_RTM- fix issue with gcc 4.7 in secmodt.h and C++11 user-defined literals- Resolves: Bug 784672 - nss should protect against being called before nss_Init- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- Deactivate a patch currently meant for stable branches only- Resolves: Bug 770682 - nss update breaks pidgin-sipe connectivity - NSS_SSL_CBC_RANDOM_IV set to 0 by default and changed to 1 on user request- Revert to using current nss_softokn_version - Patch to deal with lack of sha224 is no longer needed- Resolves: Bug 754771 - [PEM] an unregistered callback causes a SIGSEGV- Resolves: Bug 750376 - nss 3.13 breaks sssd TLS - Fix how pem is built so that nss-3.13.x works with nss-softokn-3.12.y - Only patch blapitest for the lack of sha224 on system freebl - Completed the patch to make pem link against system freebl- Removed unwanted /usr/include/nss3 in front of the normal cflags include path - Removed unnecessary patch dealing with CERTDB_TERMINAL_RECORD, it's visible- Statically link the pem module against system freebl found in buildroot - Disabling sha224-related powerup selftest until we update softokn - Disable sha224 and pss tests which nss-softokn 3.12.x doesn't support- Rebuild with nss-softokn from 3.12 in the buildroot - Allows the pem module to statically link against 3.12.x freebl - Required for using nss-3.13.x with nss-softokn-3.12.y for a merge inrto rhel git repo - Build will be temprarily placed on buildroot override but not pushed in bodhi- Fix broken dependencies by updating the nss-util and nss-softokn versions- Update to NSS_3_13_1_RTM - Update builtin certs to those from NSSCKBI_1_88_RTM- Update to NSS_3_13_RTM- Update to NSS_3_13_RC0- Fix attempt to free initilized pointer (#717338) - Fix leak on pem_CreateObject when given non-existing file name (#734760) - Fix pem_Initialize to return CKR_CANT_LOCK on multi-treaded calls (#736410)- Update builtins certs to those from NSSCKBI_1_87_RTM- Update to NSS_3_12_11_RTM- Indicate the provenance of stripped source tarball (#688015)- Provide virtual -static package to meet guidelines (#609612).- Enable pluggable ecc support (#712556) - Disable the nssdb write-access-on-read-only-dir tests when user is root (#646045)- make the testsuite non fatal on arm arches- Fix crmf hard-coded maximum size for wrapped private keys (#703656)- Update to NSS_3_12_10_RTM- Update to NSS_3_12_10_BETA1- Implement PEM logging using NSPR's own (#695011)- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Short-term fix for ssl test suites hangs on ipv6 type connections (#539183)- Add a missing requires for pkcs11-devel (#675196)- Run the test suites in the check section (#677809)- Fix cms headers to not use c++ reserved words (#676036) - Reenabling Bug 499444 patches - Fix to swap internal key slot on fips mode switches- Revert patches for 499444 until all c++ reserved words are found and extirpated- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix cms header to not use c++ reserved word (#676036) - Reenable patches for bug 499444- Revert patches for 499444 as they use a C++ reserved word and cause compilation of Firefox to fail- Fix the earlier infinite recursion patch (#499444) - Remove a header that now nss-softokn-freebl-devel ships- Fix infinite recursion when encoding NSS enveloped/digested data (#499444)- Update the cacert trust patch per upstream review requests (#633043)- Fix to honor the user's cert trust preferences (#633043) - Remove obsoleted patch- Update to 3.12.9- Rebuilt according to fedora pre-release package naming guidelines- Update to NSS_3_12_9_BETA2 - Fix libpnsspem crash when cacert dir contains other directories (#642433)- Update to NSS_3_12_9_BETA1- Update pem source tar with fixes for 614532 and 596674 - Remove no longer needed patches- Update PayPalEE.cert test certificate which had expired- Tell rpm not to verify md5, size, and modtime of configurations file- Fix certificates trust order (#643134) - Apply nss-sysinit-userdb-first.patch last- Move triggerpostun -n nss-sysinit script ahead of the other ones (#639248)- Fix invalid %postun scriptlet (#639248)- Replace posttrans sysinit scriptlet with a triggerpostun one (#636787) - Fix and cleanup the setup-nsssysinit.sh script (#636792, #636801)- Add posttrans scriptlet (#636787)- Update to 3.12.8 - Prevent disabling of nss-sysinit on package upgrade (#636787) - Create pkcs11.txt with correct permissions regardless of umask (#636792) - Setup-nsssysinit.sh reports whether nss-sysinit is turned on or off (#636801) - Added provides pkcs11-devel-static to comply with packaging guidelines (#609612)- NSS 3.12.8 RC0- Fix nss-util_version and nss_softokn_version required to be 3.12.7.99.3- NSS 3.12.8 Beta3 - Fix unclosed comment in renegotiate-transitional.patch- Change BuildRequries to available version of nss-util-devel- Define NSS_USE_SYSTEM_SQLITE and remove unneeded patch - Add comments regarding an unversioned provides which triggers rpmlint warning - Build requires nss-softokn-devel >= 3.12.7- Update to 3.12.7- Apply the patches to fix rhbz#614532- Removed pem sourecs as they are in the cache- Add support for PKCS#8 encoded PEM RSA private key files (#614532)- Fix nsssysinit to return userdb ahead of systemdb (#603313)- Require and BuildRequire >= the listed version not =- Require nss-softoken 3.12.6- Fix SIGSEGV within CreateObject (#596674)- Update pem source tar to pick up the following bug fixes: - PEM - Allow collect objects to search through all objects - PEM - Make CopyObject return a new shallow copy - PEM - Fix memory leak in pem_mdCryptoOperationRSAPriv- Update the test cert in the setup phase- Add sed to sysinit requires as setup-nsssysinit.sh requires it (#576071) - Update PayPalEE test cert with unexpired one (#580207)- Fix ns.spec to not require nss-softokn (#575001)- rebuilt with all tests enabled- Using SSL_RENEGOTIATE_TRANSITIONAL as default while on transition period - Disabling ssl tests suites until bug 539183 is resolved- Update to 3.12.6 - Reactivate all tests - Patch tools to validate command line options arguments- Fix curl related regression and general patch code clean up- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- New version of patch to allow root to modify ystem database (#547860)- Temporarily disabling the ssl tests- Fix nsssysinit to allow root to modify the nss system database (#547860)- Fix an error introduced when adapting the patch for rhbz #546211- Remove left over trace statements from nsssysinit patching- Fix a misconstructed patch- Fix nsssysinit to enable apps to use system cert store, patch contributed by David Woodhouse (#546221) - Fix spec so sysinit requires coreutils for post install scriplet (#547067) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387)- Fix nsssysinit to set the default flags on the crypto module (#545779) - Remove redundant header from the pem module- Remove unneeded patch- Retagging to include missing patch- Update to 3.12.5 - Patch to allow ssl/tls clients to interoperate with servers that require renogiation- Retagging- Require nss-softoken of same architecture as nss (#527867) - Merge setup-nsssysinit.sh improvements from F-12 (#527051)- User no longer prompted for a password when listing keys an empty system db (#527048) - Fix setup-nsssysinit to handle more general formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build3.67.0-2.el8_43.67.0-2.el8_4.build-id43000268b292af89fe0b9bf6b76e551d974ac795libnssutil3.sonss-utilCOPYING/usr/lib//usr/lib/.build-id//usr/lib/.build-id/43//usr/lib64//usr/share/licenses//usr/share/licenses/nss-util/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=43000268b292af89fe0b9bf6b76e551d974ac795, strippedASCII textPPPPPPPPP P P P P PPPPR RRRRRRR RR RRRutf-80c32beec568434b01b51a96747541a3e5c61653986859540a5f34f4fc2a8f414?@7zXZ !#,] b2u jӫ`(y,xۋĻ[ӃuBݷD3vs 5Tc_"H԰v}iW=kB ~hHOo(Yt2>bIGT(wUA:73EqfY`R۾`:)-`:T!s{'! NHpi9y^6,/ӚeоOE-JU\$5^d-aM5% 1ƙ^'XsmzUa(oaNg]m%_A:/! ~L4Ʋ @] ̲ɱ6bf( AIͭ<.ko!3'S< "~łHw$f~>;]^UzHFrfBv?%z' &//NpRVU(IHs IgZƹ%\C:xUog Ҁ\o E aPUѵ"={;A[ Nx}P65Zc)BՔ$ (-ĥ xx.; %%9}=s!Ŷ\>H6)LH"ϨYl'1Dk޷#wj~a/rƂqRbqs gUtҋof#baZajs4AT5Y4aI vɕJ p6S5倮wp+ o_3H9Ay` K2bȊkXZDrqrj+/hS`?LO48sGKjh{KmP3[ V>=A!K5lZCl8 Q/~82j4w3 zcHPݼ$Ǣߊ/)^D-Iޢޝ|/Sr0_rV<)= Ɔ KjSx 60,%p8rJˑ>O%HCSpe2s2x񫻅s1-J p$? njmEm%oύ09[S$}-{᰸|L&@$Pk:=Pf:t`"VĞATA^ߏy (z?IعRh~9syK'3_8cU<@йȽpfŞ:xdn2Շ">+JV~¯^<<*kf)$3HljN gbV^&y^qųd% vEYVMx!wzx;y+8qXVB l62>ca,c"CIlk `n( g_ǰ핥HfdJ+h%㏢i܋C Y&T) _M%LKM|Wr.YP[NVʳ Wi_~7i&σ9@J1Gڕ}.4pPA\jVzt0j{j+sLj$鬯OVRo 2_Q8z7|jÅTbJeok ڑ` M|WFؿO|su}> fQW=P#aw7*큡A J!IVH À`|s7G|kW/yn?Sw>,'vG5޷u{Y2W$eY |M@|\ӀYh.t_7 [)K=,ðmn-@AB1bt JuF!Qد;My Uo*`N֥ kYuz;g<.pA|]9Z !)% s^K?* &lQʡ{==w#J$o S$ ilY-R`9biQ-{G\@X򕆅p "xzn|. UgtwXL[ O2zw %K>x}jz]G)d鹱3:~4]~K̹2'AɈWeXs_iz,kNuP_U?w,VDP{yCj wׇexUC{mA*v5籼ɻ '%ܦP)0&ܕV Z/zooBx7| _"HdP&S_USx.}p%oÎ5e4JHAc 1|rR 3ãILB "YNfAmEVɠ+Y{,t+bq `i#xS_7)r(; kDK`i-^d: ,|2Rv]{K{E,r`K/0B*}M̱-w$@xHAP8h~EC2N;5ӜK޷25J5uYBӡiuRZi$YVhB ӫa4Qm\sXny(^6.·fӘjcEL|kv5_ B9<8ELiV<Y@1]x"še:;/a? ^, ?ְy]-ӓUHL;wPj#^ x`E4BwJLOaZ[-*Vz!d[l:Qf-ao2"ӛVXNox&+^iw~RHS@Jk8PSL-ݼ0udJ-ɥRZuq֎ }e.kd߯=YZ*Vx\vn|t1}+CG 1~GR6+rXGstd6f^ڕ";w%ٽ -8Y9#?et_7oiv>lG -T^EbURjr N .9u_*NAc8h GR5Mo\Tr9rƊ_Wy㟹VRL_SFw?ǧ]=KϡJhof 0kcn҇fB,fDJ0\͜+>EBcr^B9F.SDɲhgtɉH浅2 Wd*D&w'x>GYQaޡePX-Ӆȃϗw$3Q_>IϳOko)Z{q>J+mڽ"vepWq\pջm~`d)-,upK ͛1j!u]3ĸgLK=s[6Veshټ{ l3!J1pvjIIiɍ-a'' ^j)~˒V#w>Ƅ7{ MMN+aD0!yp& syҜj9/S`JS`:c)ec:v JpHZ>bՇr^3jp>KFg WEp|q1|5?vg69b;d=h*r)l[=ө38jvA#{arB,\UmE{b"]76['cɁY=dyBkDpucۅ­g7OuR!zɅ-3Qpr5`[sV=5G!Id@5WnE9"[qc0;O#@1WCt%0]XfM'W0 b2`:|"OT:.k%̫[x+*ž![m}z/YA9 $qJkIg W(ZT_<=x&>^9eRվ64s0v&tIe F光[f ԮȧexСȜl?*Pk|P͜y+XN֤ 9 }R|ׯ D3GK(t0t.9)յB\p Vd~1˶R&>Z8-VA*Ob7_;z?!)_aA@f2)'x J -ԢUsR4w\_@6 $+b?T`Ϲ҂RȨ,Rk+g[GFK9RB6[Q8'R<̗i-5Dj˪iM\Z$_) \T)BS.i*P5<'`KYL()0p Oq1ĩ/# AHǵ yK"(Ŭgi?~%L\|I)GrqyJ:')f]BpFy ^١&'K d*E3f=zjp#̖Eъf"I<[&g{=tur@Ӏ -~IȌSPl"9 ØfK2u-<#Z/+Ȑ[|~DӯMnNSH 7@GetQ\+Zˍ3B1P#TxcS牒[]m/'/X'5WaU"CVfzJt=W 욦A1Um.ykhiA:"n XJF/5@'mX}~nUm@=>D/biqZ:7yC lF>CbɃ,@ CC]jf#:ϣ`B}_?`5q|/&({Ug+\D^\s5vZ^`0S6{~5,,f5qAw0msE \#Xn`5ǔ8jtZ?6 ;ASsf_&&|V?UӪ"/ -iV)nU#D8(7 nL{6C Ln͐3Zb]BJS*͐k}'Uq狆 қ% 4xͿEXLПUX<8)"&?b %ɴ{Ϡ'tiD;$Mw CȀ(X&w{k羆A[o<qfN*Y׉l+9qW@!d~wwJ QO8_??t}D1J\,ZAI.X[nâq EܰnhyOYl+vo: 5u>VOBS) 0A?MiD8ܧA~2\I,PZ_Cz pRrR ?3p(4(EnCb%Mu-Ֆn M+Z ˀ*YT&Kaؐ؈Kk 'AF-Tqdtcawfjb^dIFs7Km拂d@əicbFQ݂)n zd0%ų٧S>'o ,%GyĄsWgl Ɉ oM|N'&$.)ty+52KZ<~zӐiRfӲ>oݒu?g"jfd= ֡z!@h_}v2BC :DV@MLP !W\g,a c(@'jHF_R8n{ȳ4W8$ُ7A#bKaѠr]bY} qMY;!aXa[Pl6HY6^aq{KK:p3q~P]ZsW*%;At1bT4q>bfMφ1_24玶okIRe܏j2ol%vBuqW)#b@۠eb ?3rw>)$dqwRjp*xacKW$kE_l.k( i~ QZ: _^YW%*G2Ƞ! Sděw%s{RTn5GT627Ca[d*g+rڎjvm}]*[P*Ll^iX;v9dJu0iU g(?*'@|7Y=) <2+LL;ޙIُf;QĒ|}>Ux|Rk:ĺ԰A o^Q-1%Z-oK#Z3 <[&E qcKID֯t 6,?a(*]:7m@g}; ؋?9f\˶?2HU̧k=R'$+-Zc*EY!/߮'L7:w(F?@[Ŝp2]״[ 6Ziƈ9~Di$:U´Pl+.⾀՛k >hW.ZN.rOȅ᪸,\dZw+!U%4O?⺒ `48ׇNy$Q5[2l`~b*TY=V_(yz1Q!OzZ=bHR&.o b| Xx~*Cc\d0ӝTW9{A&}c = \cS8@FIfgޔWeGu3ˁUZ:dKuqu3/@-L~\sT . d9 1bפ:m~Az$R"CsOwe>$jtҙ/\8 4*e`n4 Wkf&YٞS4D`@mNsU y ZASsYl꺡,G$ϰEmޜe'[1|O9)5t `xgmiƉyGE>mm_CϼvdQalXp2 \ILBOL&OVg {ʗ?ϐ*k^f/Q2K%7瀰Rs h}v˻_3*H1sS oX6,_M&sp%(p`KUAn{1%-q)-3L$wiE^ uP0Mh}Ņ$ry1OK7m^lALwS`FfoVzc.ڴ##hRW*TmT;:H(.qRɊ{S92خot؄A[Q>e+Z<{x}T^BͳeS%znTJޘ1ev9LǕ} 궯HnҲno+ HhԳX">B{YP0!KhE{1sɥaamkN]%z!9 |Kwߒ|.cOޥQݬH)8y+ ۶t]Q9>Bz1Gz - [!;GRpL1!]gl1)jJE㔆9 4j<ܛUve #Yq}eFuqoSc%愚5jaDq!,4KJN %mE!:-En͖gk1CdWI,;D76jy¼3tlOm1,b[$И *z1۵} >Q(_Iv쭞$~WL<ޅf2$(ƉxY:`e%tDQkŲLBc69FɔO R>bPiUs92 &yeW!nqG6IC:b2C^]Vۯʙ&:@KPehukyA/ D. G ]J-xY'ˠ^/~^fsSx+:D0LBVsG7,AtXUAs`@&0)oChvH<LZxJsWRW|\s b ?Q%0$T;! K`7#~w-M%%qOlG:jW͗X0ԂOƠGOcvvѻ lHu!Bxú|70f$@8¬q˓a cمPVzDC0xyAj~1ha,M^(ƿ$Gc,wh6RT+=w7B} l@:$X T^] Mxw21*zG pPqb FoBu܏9ƖaDfüo55oGT"})19 +_&֣^UЋAOB47ђ Zƅ2庪Aؔ7IcK\KVgl^4ޞ ]bbOW<\V6":,iM?wh@EqAw&k#Z68*c:{_;sٕj ݋r1VvugKRVX35/x |FII6iN0dj5мQ%u5 ~ Agk)[وS]b5۝CSDJ.g7KԼ>Sx1č& x70l.{O i=1 lQ?,%3]42ssX5/ T0D˥d-Z䧉;sLвʼnZp-Em*8wqb-"ςtW $=3K^9.h>Ϯ]aqmTiS sP_]O294)#Y4QCm HߒafP`ޫeE֢uY0~:Q@4m7STo .^`6=5[  +49: :v'|\Pr!7%W 0F Ji cT)-]٬f"QJW#hT5C9֖ʊ^+)q'\SfFdW.N|A$Ks ʷKϐBywgV<Y4ܧ$-9df>DizhX.Suϥ0ecq4dޛKxq\]u SEfeg|QgX[rFsWHM ~Iz?dը4HmFzM /vRR@##7 RCBy6CG KĜDŽlWHviwJT1I()B^Bzm@X7O)d`LMݶ-\3HKБ7x!f@}CTɦU)`*!K=u\x%x07zm=>" :K~Ɠk490YAb}z[zFcR8$=Z$jxUn N㤑lᄂllz1fx[-ѩPChόDnTQҊNf[XŤ,V s"uWQT{UgۄbJD9MEݵX̘RH,YWi kqa)+,[JI|J>Ol\[ |ln3ya[]`$@@ $輹j7/: 3pZ l025_o'G_(U]wW"d9Hϻ25caJ*KnR~;Ycݢ ٠B?6$ƥ QhS@ bb>4k@!=hkA,}oX#\ːY9`U^1\=MviH/]OԚ I \K깕{$Uy},ֲN[e#%C`E Xl!{1 E*5:s]dVo`{֟;ݤPO2 L@P;WGFPΖ'VǺKz6.]4$_sWUDbS8ObسgRjxmI5ܛ{)>wHУumjhgj e ͐?:֣2u2 H\\\ttsn0aH?z*M $+/ޗ\fr`s5 z+Ts(^Ge4l{be*e*Yi x0 B<ӳ!ò[~!nKK$ {V?]}$^!!^AEm+NrfeVw VQ??gk;kh9a(Cv;p? U8HAeO(+0-"ҽɗ0;RˌCJ'Ǥrֳ/[,~m\pbS9k}jGi^睷щscV<ˌQ)J+O #-N q% mpV >싦{pԃ|_"?v8#4'z p2\s ѿO9}8Vΰ __u8uk{4zNؙ?X 'xzr|@JJע%YM8VE`EーrʼnZ5 85 Q{𼺬onMXK􏐆i3cg~?<7),BiEDKJO'D ngJ!Y8.LQD?UZZvU繬ݶf2CWVKM _>/ռ9o,pL'r"M"SvCg7:w|Sma=uQ hEz @&XPzPξ `oPfCybMEγ`]1ҘLV8K{b]9~UaW>{I9q^Q̅cxx-|GDԘw1Ji!*::b-l"[2';Nl 'p.!'-+sC3$dϩ_ҝ,l86T: |8>}S>d_h/ hf'J&UT[#朇bijF߶*Sfx $|:Y"q[5#a*kG VXq$j,N7֭C"Ȧ11`Fx'W!Cuٹa?U.:4(JsVcG ~@E#x,{"D N'rIO D]"탒DK*si[ZEX b/e"^L/Pa8`P[n3}xk  Y"Y!̴tXGF uHA0qch@d Y}_ !; '].:=c_O>N\kOS}*v& w/AVTB3 ɾ[ٍj_W *&VT*.=DuəgK??z|&6ݝT~VOB/yc X{<|+؃Ll)^CQÄlllYp{4)rOm"e#m{7!g87]`Tgd஺5 "мtsV4?ue=@(JCt3UKG:%)΅)c$3˜(?Ndm6vYA%)fU3LfMV̆-) -]I 4OAEf&=ah-q /2Hb`A0 2CFveLĻ+vwv 1i3<1\ŷHI8Ckݻ9ӬNDq g&{c 7r=Glܓȣ f貈;<.2 I>v&X qWSw Sr#.)"Ӎ^3 3:ۓ14#'6Z<r$0O< QKɭamDaIGr:Nf.]`g NQ6<(0Y~ZOCF毊<>cT]tW^r,:MR:8{rfeTq7{ksmĿ6ٹ3;Y?υtZǒK9)qc#Q@D?7/kd&=%A;ѿaYʸ rZ*F9or3ZDq \L}d:-5myM8'}^J2D+C D YԸ M "/\-8$}& "m-Ui֢s[%|i ;v^eGz07i_٘ͯ7 x)d6Ei½p{rY$_̂z) Kٙ|J=a*rYU0s 2tD~@= ImgaL1Dn u:z=T+ju&.̔ KQ㉴toXTtrEm@ _~K(hOOܷRo5#wMw*.-7K"ZRP c1yzjֿY~i8UTr-ȓu(% 3r1nfUE8  j4aS'Q'f'q< ӂm )y!O~]O8*;ㇽ銉<}#PĶ|B8>y.b:h?Aŋ$eNּGOn݊F+h ]K!k'y|yvt>w z|Vmuhnp:Hho+L1(ęIlE3/ ?$fkB`Ѯ]In  Q0p F7RX tLKϾ^;P`aRY J3K+G{lroDnj};t +)Ǯ/W\ִs7]{3#n}5QO,+s/aj3ci1f$"^@{ӸDeD=y(h+uX8?hdFp,W*qᗉv5eϸ!{D띠=wokU0[!V&s䶽H>7&úYq?IMQ,]ܶZ x͡+r}NLL* TZf:%]F>δ.iRM?}q0hR!Kt|4\b`nab I]\6afKRz1No 1O.}=A `0K/ 11y* I>*dLl u:U,؎ FF -'8 2 vFIu%X X /֦?,$WR_޽/=G 8f…Y!/DU -{ .u+O@Te֑hS)\'!]}p:0C[F}@J$}[%IA P0ڂ\GcCzЦV&ErتQi4lB3FP \'oHŜYcSu@ ?n/wjc`xVgM*5X>qYwѝ2 +.Ů mVs}MEf=6ʀ^ W˰ VhcfwlQZZ,&|؁ o{lȅbz0'ߎCg! =Lu8y(kۈfYEF%r_+TFaLA n@uifQb7 w@Q-[Q'K5}`=T'eڭ<È%Eok 3x' ˴@rOS6cJUf_1,ჭ7w 7`&Ȁ]Sq6>JХK-RdX#92Fs6j Ld{PVDP3h:.`荫5 uҪ: 1Xi<T>r.`WF`ssw,zH|=9&2Vq$[?F#PvM͵{uwq#32+M HFTp$[vT5acx^?&CC ʣ嵸H1fYuoc+xӭfNni~!ijqօSTٹՓ0+$һ'vܽV2[? f9[t MV2d e2'&Ѿ׾G74^C h pV\/:Jz%.|zuة0VXԌtkΓ)!/a^+סF!ă _xYCY!~" 1?F _Nί]־ulŷ/C"w-zpL麏(\V9   (Y>/pיּ4ϸ/e[v>!@ Ofʇ Z/Vk#3V2خ6,6%KL%gV# ξԿ20!Ǩuz.L񟥳Z"tp7VtJ"9 9耰]m{ 5NÃ3 -F$cEphY3kuƏ5<.<ʑ0zo+G{fwwVm<9G/.(j86kXb5bI҈^,!TMuQ"[Ajg܎RE!c5Y.Z C0H ~ /|^VT:R QNK6D!C %jI{ iV8yOޣ2uh9v*k\Ɗk6A TUA )لԼU&;AvҼ_թ&u 1Bq8砎Bz=$ۈ )APR,@`)Vo%j0l3vfwQFF{ȃw[1t:i,Ar;sm^HyM2fO0[gQ 6x%^30Kalv[(q>S8R{Xt_)[Mw0AC9tF笘ٔ2ղ*S $5ȯx&w+9mY)OpdT4cz$؁$ڐob&ܚ5u'4Xgh. m77#{Eo&jp /P!oˁNSrوZi?Ӻh{>msOBz#%,FX_OF_ ALTCpI*,Ni;gU7, Kh{;+ݴCrz߇UL^db0AcW '@::wUKN BŃLIN^l}, RnESpksg{anBMMRj6B$N@!RSetG!R+^#t͂.dיI P)P `mc0JDH H+ dꄳDFfPX %pT̵sF Iyc%"^4:U "Z)Rtj5ި&R'BGg][+sC{HG(*E}em51Ҙ|yۧuA9-$LD8 7x  gqpqaOҴ7/dށKR=4zt{pE?34}Uj46s #5:)DG9~w|h4Φ, ?uGNOoN&3-NO +AB7tG j4lڴOnܦz wX.*(}B:'̄CD4h r[*QM0<ko,^ +PZ,k;t9r-xFE7!u6:ftU*q1't*9(k`Z އcpfن2Ct?<{RHE+Rx^mKZ9+-*T+ z;)+mkW͌RNO9/ߏ7,zqFlLAk0fa^腾0fR W)6g;ܙ C3W 4gMpJĩz/&"QdZl7:0o!W]Axinџj 2\pFw|/skyggn2H$6l/dLH2cH6!A/ߎ{m7brcn{tQNWߦt2t bԦuŽ!̞-IZ^]v}TP\/X)?+`r3l[߅m("ǤF.Z|@qf@}G+α}, Uk_b_];:x\kmԕ̪li{: zi/z['kið<}dșLWwFڏ+ujʬT&B=} 5q6@DnNLH< ɇ?J_)CukkKrӋ(8\R"S]; 0]_Oam"f~6Wa~k!Բd, v֏BPïmMԉl SFhNI]S ōXjXIu>ѷDo.xaWEw.Xu'Z[HDָ9 DCI i `{c(̚T-y;rF-Z4Ejʼ}G;GSx?9 PAL?2wm>乥3SpBTũZ0RC=D:]q ( *E=''G6%'$)b].=Bv/RJTsle`Ֆh8pX0"!%@.%k> lZ SyMhl{T}0ae<>1׉N>P\!J%PÅOs0G;Tf韏gHt?po?:|EKx]\m킭AOV,Dɞ#jub 2s֎ ``<tp7IDŽ6c7!Ĝ ВqkGWJB;Wa[y\TA66S[۝I 7 &36oG1bfi_}4֏ÇlXZ~!XY kf؊N0/T(c0漶v#8"E1vva3{.0\ոGi}=Brek dRФjm FzvׅoLH)t1L UkX@bF=g‘޻GY]K.ZW2 @ZU mlrtZY9q$lIОG'nK`y8ls Nj%)}.I>tO]4[T| LJw?cjmN2%Ti*Iv'5#6f~өٳTnZiv+sRUc^+dBi5VKC p4 7i)-Vy .IH3gĮV[,= ƤW5 MRLҦnڕi z%14:=*\xԭkH<'VY^G"h,lbڿ\엳dKCX3\U'FFCcɄ7k= t+zM(ʱ,yHfgVO^fkplWu*T疹M:3hBR;ŏcXrǐ\ XmqV{FCHuA3鄔Kw} !o/xgX*bGN6[OKr*;YW铉\R0'k GuX h(Wʫ7.b.r$MMb%* ll{]p ͭc*oޚ(ž='w:uD"$ SC?$$SOF0-LTgUɉ-hxeo_^ozXvž(tZ 漠Jқ*+'#XfSD*$ lY?)233}l:]q*1ORQ q~" ϦCcWŘwz$/;KۄszeO<)wB{@H/65#TH|IFTSh`LˬGAv5jt(U%VGXP:\4~HZhS+\t!DYjr?1ɫG܁q K7Ǿoe-,pʈ:y7w2 Ù[*',Jm(Ad5 Dȅ]CXX膶mo܎F!wkIH162:W,kr4u cgyx4e 6t=ψJ"߉ p[>tmȬͩF*`N9~K@Eh_OԎiHZ ڌg!"ppNs:N\`G-3%[E8($~0*gS%5- =2.酃rRA|I4LcjC>z4 樅X710]KcD[d`[H'Nf!<7 :'h cB;$KrДZMm'(3i\Uxp6e`bxT~?Y1ҋ߀KjuzjVa QaT$%[kuڪXHiuAm/uDe{ct6 :p18](7]| N=mqb3cTO҅r5LMVI3z^}"_Z=+ ʿP.A5'ꅾPLUϝDh} C1~A j.)f3 c݈j:y%b ehoݓH!m>ķc*|>͔'2N8Д~Hb̸۴"qECG`*O&$4m+LqlS++Hղ0xjh=W%jQ>=u/Y0mЙHDv. كӤeyh&qhT0^XKZpqܴMb xV cB >38iDU?/4*) F+dhWIm `K&}4ӖGB~c\zm Ba(v.w `cX(RJ:%ͧNmj,}o+, a, PT]e@e6od,OHǾ1Ev:Tnu jSí]T% acJ5uqbp 3=ڢIJ7fӸqANuUS2RTjS75DLU>;= %h끟ˣ+]YԶ6ҹ?@my:--/_)zI~'ISWQi`wJSOR?sT=Kؑ{^KTžj츻D']Pvs)w_@،+U(.Q֠m$g0P d&NTkpQ$UY6v{mъBb,S|Qm (+2ukr%:8/^Q?W7#;1*CmȅM9Q ,?? rf߳j@(u2B_anTJn5)Hz$3Ғ*ʹxf7U[{ n tFZMn)"Zq:9evYSFEhdRK#!/EJn\}dG"Fn8 ܂vէ>:h.+W h{ckff~M&4QEqqCL`4B\H/ zenja/ 7]\0y}2iJ:jb%7>"4^J{^50OJZ(At6_|_y]Kg@x]$H_ed*.fu5J #q`vpIwGmI(:Nne__FIL{UE{8k*?;vD`+ҏ0Âu[.&"gΚ6GQƩHU\eEVb9J ŹEwA 5_V%4H{U2p^T 1#!T)} C={v$\El1s#m #|^!5{Xe_SL%G'j 8{[_9V&)|0w 3ͽ {dBr~,Z[R.Vh#yc$S_Pffāj&&6-&K>):oH5ZLu[.ϔ[#GeyAzo1qi!odϸ!R Qu9g=)'Jjo[RE&Ef(AJΜc_l|L:v-ﶻցr!Ǎv ͬW,C 5=_Y % Od5^ JZG%>p ;]x^<h sH8OL}ߩm[$V׭;̵4AMgDD3U?:4-EEy!]phsf4 ,ڧ(dG䆰Ӭj27[Dw5mqdL&GCg|o2m\ʭlzfw:Q 59,Ի֢ȷx{ش NN 䐐'.oG^F}?wYϹ5 RnB['N HG+&oq#%R\_ U4.*\$b(%,sxx9a];  n rRvY '68VaX,\ܠ7Ew&Jx_@?cM%X3a狭cf_g.B&eqɒ7=u:{ 7fOOew,ܐ{|BH MI>`HjQSqj~V{ޥw+0/aVX!޻, ZZ$7+'y=O@bV67xں?5 ӮZABm6Sw @t:R@gq&i2oΪATeI, ?f^շ;%~6ѵbA* ?2/f#-ao)~r54)7YFDDTPrX)9 #*S p4ز'̐H"̫Ѝ͔8}۳} i ^zQ6o'TP7j*q GʽíIpiO4b 좣4=QyQ3s2g |k05 "C{ IzWf%P˚QԘPשW I<,jgCcϡf5}msAFД;z]\BepD>qb.n}E=1'b auDH>K$bO;&[TVf4.7mR^VabJ *Ci//rbz3xX-w{s1jJ5^++WRi%0Bx=;֡_2v!ZRL3I"-0;ROW*n4zdx5Q&.qu0'XxbZ)GtDS.P/X 8= |'L䮶*MM 8b FqQj7R ' *RqRg1[+ޕk8sʘ..1FCAJ]dH=m)]]-"Z*iT|!w\%Uy<='pdpa2 Z\љ9uS2ßn|?Z7q蝅AC:2zُF~1x)XSLn>B/ *6{KV2ѶGlR9{"|:w[O>zqՙzl$2@uȊV+#'VUC\97fӜZ2ijT4 daqnfc0.XFC;oW*V7(09ǶRʆ5#Mc?%_ "@G !(\S@$: 6>F-e;w1Y :q"&oD+~ ::2GinA%ϫܒ} d6/*[9Ybwe L=e\A.87d]SL-OğB5^^%?IeeA?6 x}/)\0m|QU-KZ/T <}DŖӃ!<|&0~{k{))}JS6ϒjg[^}S ;)ZF.P[^k%/m 9`H7G-Hx#]E}c4=s<>f9)|IR޽ӛ<W7. l I΅ao&p4j_@7I,)%`_ ~*Irh'uI/o0yAl2s8Z\uQq~GTN17噽Py..(LZXE#Jz]?C!M<ڇc|39e+I}ک{ׂ Xe޶5ռ;<Or'._{S|!}-+UD lЧ0$_#i;ψd6TmgXq] ~v)ͬh.XcIW3PzdAgEjCý~6E"J_sv\PkV0~2_SXTDc~ZN],15n_]:$WWthe/jf;>I[ճKVF䊀63F]7p( Р'FT'~"GC&,У#Mst6n)G}3k6Rk <`C;* lI%#pcY-$)KJ\ 2 S( Py 6-[oP%( 4]Lj$DϰU<*- `4Ǹ;(.,fdH}!BH҅mP[JzqܲN ARpkL} sn'Cop(O &7!NL }IJ]zq+9 K`+O[nq,FƦ*{!pE:YVq/[<]r3W$لMDvOy@Mb9&-Jp6!:bQz0@?Mしk Ky ڪO0Ed>He~f0 k4+riTAb `K:=I}Zʜxtk-H{o#)6{m$QnvEuPByYM>sDaH۟+X9l=]QԎ$[*1N0y]N3Q"^ j=k7j" t@\{5S%q/xl[y"ۀ`>c7z`,0%!`7EFEUuݺpLܑ nm^E 첶h{w ߏW6CxtX= xZjN.As\q{UHk_Ajv3bWǼ}0 EecVubo^u|~t;Kҙ "kK[( !XT)YƘ>Rd4ow]cd69bp `/{V޹=qڣ7^#m-<>`(JTr>V [?%o%̔ O+Yoހ{ٻ w/@8=\F/XBZZ*=,~)FsB'|S";Q+@foTc#w2xB(Bc{$Kώ"c hROE'v n )KTZbpҫXB-'Q9H,w,vPlbpʱNYm\(G.;):IA71? 6Tm\NGnXMm2z r̛Id[@$Te~)8'W9<23,`íd5`3`qn"o%YqC7jps?D/yQSx|{ ZuҖaw@&׆2g,qx'.FvirlŻfIۅ`1eޕǝ䧗5ȲL(BRgz7!DwZ1O~:g'ot&t>5:NnqPFPJ{YimSڏnEJkp@1 卑C.pf6=HI`Y{dh<3,.zzr7vB,?>L&fE7Mreuq@gna^ p*I2V{`-  |+k naӅ]7\sکw}k~ρW0}zAcbxۊj}+Ps@*¿mLXipîWO:ZfK,5W0d @3_3ϻ~SMئiT 7 zǜD5Nc%,C4Fͬ|<f& D=uGpwꞁ{7WYfۚ*dBND:ǜuM~n|Wo>4*U$)-kRV8B:i6I?={f- 2NS ʌ * XΔz(D$B76U>(^4:~ %6? L? ugȑzE]G`B 2Kuή\Ȓ Ar;'(Z65Rǒ']d< >xl!oϳ;K#ai4!PЉ&Jw Es ,/D.RСpiLP$MA: W* d#irazp1d#yzQ~Ɯ9At $OwgF(;2-vTSbRoNi56Si}Txı.#Z_f u+9wji' kfH#XrңIpC2-ޔNb`kalf+{P (؛#]y)ոZN-VpJ s1k5wOx⣍% 9n?vTs8f niD0ՠiz{ ,cl& h(qabڨB+dE9AEg{1\q1JQyd̟DÈ'< lݳb ~8fD wKFǾ=1Xqp%4jgsJ>)V q| e );Xy{/ .\^$ QE-^h}_l0@ Xk،:Q`mBUbE+i1}d).buŝS߀H=ָaAB͔fuElˁÎfۼ(ILsBK@ͥS_nnA3AEX$:T&:Qิ:EJ U][aGǿ?Έ_0_1,?,el ѻZˮ@}Q\@hBFplvL~2*]6F&*Z@њӂ ňf!tw8ٽn\%B F!AVYp.{6Gyqw )9>, t=&54&Ǟ;/OdU%[PKq~.%.FܫV$,VU]*_Ԁl$ t)(dYjzk\IquJ {z[ ķgyBrDp7ZJgqyck\:@c/]˚B!p)@ɅpzgSxLp6W$- }]CFwdjA6)pgF4,:\WeD'Uu?9-unbKʗv`d=%FI3!E;)::k"/5aK$i3 |#QOv>V'| nӴ/e?yl4 =$3$ǵm{eY{ùvpb|PzS&i0BØ`=O cԛmՍ;%ȹ/<ϴ/EHդ-ۂt8<ԧN$ Q$NrV}!͓L0`'j|;W>l97[r|No0 uC{Bo1C$k(l]6bCnusm_p&i |, FV,,t.vS}Q4ăXg =NV5D-ӌJ_A'{zrsar]Xv,&!h.kY2w< zֺTB)BOպ7Ô|; m!|%kyARK!semAh(ΓAbi]f.E#IϫZ07hVF"rž#!\$$eITnNd5r,Ikw/[Oݳx,vv 2btj+V{h@3/ [jeQj_R~hDJQϟv vJnBo6.e54b壨$IAqa[P#WH B-RDSX}b^7឴ªWсAD!#|sQe\v2ѶP5 gDx:'].ݪx?3.PY c}).þǞsbF8`p8"Ջ ^$tSY`fҊ9c c$0(.B\n@S+jK`ό))P|_ a\94}/9 ި֌-d I;ٻ&}u8$μ$N|r,!%-65UCcj".ru Boyd͖!S\{ҁ<I" (rm1_dB(I8ٽHi *S60r DW o:7KTiK-؍ŗGzE'#2P5*Ѝ[)G+}gC:bJK7+!ʫi\gv8Ol4f}ٗQ#! `4t`ůSPLeg B_jw~ ˞N/In=øm1ς\U_t~>VFLv Lk^WzxQE9,@&,"ڿ RwI$8 >5 #( YB}EŔ^5y1anRqcf5~Pi4qjE)BX$*2 됳`jձ,F{ʀϪ"P`S.YnElIcJ1dSLb vɖL 6tp5J_!m0!l/&j 4+3;Fw5 ?ʆ8q7|Ph}ke:R31EVIl TU;ɑ4iQ^Prz*$ԉ֥!$j\jw1o PQȩ#.Vp{v,X1ӏ+sxA$k*בY@ /j! _Z !-)dVQRjLed}ڊ?mŘ,YL |B9;zh=ݥk,1b"eǜE3<3/ضGkweBoC[#{Fɬ(7' "4;ثo 4h`ᙩA3 Ҹe/]xYõE8GrƺE9x&h(Ѣ"ֽq ɨnL/qQ%ܭ_ЕvX,VsNM-_; n~5jQiNے"gwz,ءR:cd㯯b_Ij( g<>%"& ͍Z^rQ<"]dךiAxA S#i=e5qw`&L6zfA[o7yvi^V|6fZ7SQB]7KY_<+:Kؑ:8+snb.to!y.zFA1T̓1>Zaނš| R6L[}!%ve߲̞B>/ZclKET׸#*=\;p1iؔV_22f2>%4 &:$T dlҰbºk( ो76vrBaF~Uj2H` cfT Tʲ6wlƼC@J*X`\r{D@ta6\'Ν&B A8(`cmG?ԗVE$SHʓ=4H0fKNtf`ܩ@:3e8w~ɲLJ`"RjoO?t'ri)P&,fD>a$nD~v}&<F>oGoS&&jHlKJ%oņ`?H##+rmcH}B9Ti-oi4V{sof̘z_Qg"+  dZjj,Z+< u&I.yf6}v(1 Ѷ:9#4Xm0|84J &$yJN:Q{S*0S<#M~D}LކႩ<1?hG:tarej|-J@,ȄXlYs$ XO>{D!E_{@67);1|5y M@ꨝ|ef*}>[TSDMQ_in ŝ9.C`wSB*ҋ-nG':HE׃Ў@o#Ҽ ﳨM򢱻<6 43Ռ2%ƥDl\5"OÞ0wH8T\r}3v"&u40q@sB9ys,݌Lq|f/f$DoN'W/} 'R'=/ۥeZ1 AVݏ)dӺ=SoTt:]fPx?oVJqY\4'oɹI<,*:͓%"GU+8OѽysE$"*4UĿ`g2 IK#_r3[^#8w[:HɮPI]5ĂqD1a5"`y; 6lSRVO}?6U氱[mbtemNtkʭk G*^J}"GWџ:#x$?gNs|cXA$Ԥӹ VGܐC۴/Nf0Ztl@MEb mƊVwL{]umNZrY5C %aMGi*X{Zьe}uV:=yftZOg+K$Stjmzs/!tE$_đQEs7zź1N!J-5P'96p)ƣd؆C[Vkr?̬qҖ"ħB14:l.͋φ} )ĖsrpSn1\+(&_`VN{:2F,T7>)%ۯNL1|C<8fR?6^}s19Zw̑ "+i$Cc}`yJwҏg{Hલ<]4$۫ :q5]OQPH gyr@tt3SvPT8Q Y(߮ e{WE|D)"ӝȓQVe(Kiޣoj0ڤ4\Xp jBK`ѤFᔲJ|H=1lQ#Dԫ&+ a?z"a&ogM^ [r\vi`Zb|/#(e@]arg39m>=s8gVwSZ$oKD[ i;_RPېVPZr4z5 !b+6US%1Z6]LNZ0Z5p6~HWb 2W\{VIƖmUNAڞZ~IӲزL& KՈ F j'qjI8wi66&ojX˩bYE4B׿z]J;XOPJv52-.tUcѮS*ng]@Qm+Fv 5!Б!xL`!XI3lY}((I1_[S ϘR(-ɠ+>.6c6|D]5S.vG\sYw!S].e3vl ,Hտ߉^>N9]&L-9`Ù*DXNNmAi*/a8JF3jE;5hଽ(\ w62j%/Rfrf(RVdfL%Т;΀ܡ=l˂4\E?9V Ynl4JItS,ϙ1ёY~ 7oG? ՑT8d@v ;Wa# Y{uCI;~' Sa?$߶\R&8oj PnYNu (ҸQ8y{joҳ)eR9 ې;*Uil6/~Bw *R j<1&wSKۡ,͹D/w!"dFCИj%m#j&C{]:~їy❅Ϣ:>4h,N NeY_+oTnH ]ŏIoa @bAt7G~06 "sO<3Z4@&'-dՋ#Nu}SjuCԷd-@*8R1OR .* ٮ}+tvbv`~1nxDMcTOUD%i@7Agt*gF N+gBo Xh/<~Ra6Swןv|n[ϣ7e`j^D"4΍ꥁ :WV!bߗz:^2!L @ZT~%AW$guK}/DqԁFa~{8B @t:r\}3F|j$srsjv SHsC]ՠ~ DPR1FsX"i;_᯾=r݃҂ZxOܿPyxd>&r]غ 6G;0j " Lю ){ t]`cpb&`QZC#Z?_R i}7^  5 a}:rC?!$"q*.glMjP6Xsd=:]*z6`5i-E8+,%[`ڦS7`!ی:1  '>-q: fUc I/*֩>xʽ5M\pTJyQ-I3g:YMhKѪQ-Fbn#z̺)I o78AbDNceE.V'ϚpNXs#?-Wܱ1C׷R3[ɂԓm2?p̆tj̡ $p<^/vy-{]- &Nr\MTKfCt7 KŻ/+6w\`vjcx,m)E,壼IPAp*П2]1҉ Z) ݘz6*6?Apa3)oĠѐ8tN!qe7Y~<4cOOĶ➪b&=K7XۃM^SӃs0l? [IƔnJWں) h住JsJ[ K™>5tq\a-@2_H*5j=Бfv&}([dV*5(:8.mB~湋ԯ콻.Š91$6?*5KFiu(_w)ol/v-戦&*G.сr== 쁩00>˶i$s`s.t#S6lCf={ aMp ;%p8oa꼕Qz{rѧ5 w DǠ8AÏit^HؖQ{ibԠ/23Ɛzuu(c<l:rv% N9gWq.pw8an~%033Up8R4E,$cL)eK[+yi}X(ruIU;Щ_Mz &-MXZs$N4^J*<_@Vx?!f)}L8+(C3΃<2U Q}ce.BYrENY4+ܒ%wZVy3? +RzHbKYb?pCuR&Fף;')ݚ"}Aoa *9k-e"F51 R~4)clCԏydqLs`A.dCW ZVlQ,*۲'CgR1Cy۠t+8E=5F@W'@E٘56k 뚩-&r MWss.9TX J_ $nrD!*OY'PgCFA|:{AquqGd[XTݬ~ )qeH bXq당uqrowK&zBݣ\?jn\jgp}k,W@qK2,H,B4^-e((^%=RwQ뜢6 !f.\&s@K\\=tCcck4(GK>ix)]λWIDth3<^sK7O"q5\xД#6YVlpͷuͻL{o"#Z[g!YǒX H z4w48CXi@O=XyjpR-4+ߢ:pu\vqV@.;~ &3?SzYOH4\~AK+ cAkw$@U,Ba4|G0}?i9 &NX-H i>BS~_ww'׊Ϣ=J?E`1 hp08s?>񊺲Yfkb`E 5Pֽ9MkdZRnlhwȾfrS~T ْBJ5h&5;@S\s!Z^DQ@(n,J8{m6[v4LLf= @$M(mʖɫq>́&0ΰ6b2h5X qZT/od _?٦="O0ee<m6< :gF? u}O -|-,W?;rEt&DZY֤rΘ̐%ѥ 'eB!3>E;s&̲6y@AyQD2BR'.9a֊ +kֆׁdCZ|_ $FvaXn:ZJ{twxBY hrRJ8 ?)4˯&컞G6(`$&S~ G\)ÉS/3n&dhU^x**26%jL|9t΁k,杦7O]mu>H8eD0H@nꏷ9M"rH(dIغₗ~ ) Om qikD { h{7L{krM7S tkV.-2mkĊA({L|-8͹Q3η 8b.g@6p+vd 9lKkA#vsc11x>bH(>$BzBI+ Ԓh rȌkVt;,LC-, kf[Yȍ%mT[%:b9#E'8Oy BD7 sڥ' N(oa]PsJTTB@gn;wߗWoܳ^DhP؅ɯF 03rX1aK['[p>:vp(jK4! aݤCtJXw[2%;o5_>mi2F*dq_T:P6id  RMI[9/ٽ,>0_B{#Wxq|,]#?5]bK),{lKM^VճT't}3=^@5\'xo-2$Zw&{"L}g8x:AudA9 BkQ%QW.';Trvyn6ъEb>MK*jڵglݘ5OD:%5)ڷBd$;|cLBp@GQMCpEʶfvvӘNE9 K,My`Kg\kQ#%O'8΍HEb0t9+6ИDЇJ:q RGn"O(F5TC9=ҭ^D,6g_9 9Cq QEr A 6mZꀼTo(1(B2Cղj}Q3hXD6y"@U|"vLv˖g,2tIgXj]`"۷CXRV{2#ʞʟ0s5$^Hx͉M6K=h,8uKӲNPb< :ْ@4W}>Gړl'@b1T fYy;oGvо%:;JW""1@/%NOxg_y&"Zi`bpIА o((0p-ƫ7ғ@yp:Qx`^gv[򧧆ږ^6c3^f;>8EP2.~\Ny&bE@={[2oDj<A7Ŷ9%|5[/6J`H)ayذ/%Q)m['`+|ss)Ȥy(ߊ_D +nhڑ!vG9+Z3L@)wmT}(s„̯1Zͯ$:O9gR\iN1Ge!@J $?(6X U5@$vuV;Mp(Wڦ:˜N[8dMrFBj vAK.*_zd-ģ&o [^7I;fۑ"kti4?oj16BO#cN~OB4 ˓=/G}y5-7Tm"Lx,/v`;~H*ֳ!̗nsg?[gzYGŖmh_ث^MׯYYʫǣ}͉u[FF̄ӿ#Z""Ԧ7jLx\*:Ȍ/1*]#̎:Ye΃>3M8o]FIזoiT$@?$(fk7grW}`Q +Tn$O Xy\B,9Iv2kIIgpͻ*+Bcqzoſ-~딠p!ǩq'OAcMټkm1e1mBQiؑgVT3EvXxv I&agiqX?=GFHQ}Tep°~gy:Od}V]ۀmе6L"?u%` $ւIn)[ 5L-eE)@j& 1ZwQ.䗬sZn"b!0*QX><"(%ľ+淞b0FpW~։C`A IXsJlNHsa3ywx8'wXպzPaN?7--/lg~]m NTTumcyp]){N8hN.zna)rT%EXud0xp/ʾ`-_>ezm`%Mrw:AF0=6EjyjHiug1.52h=l4$BHD{_LH,`T6YI,i@q$qob}cQ5~{9QRrgtZvʄBCNtλwm HGᚥv 3q5̙f2 n%b# KsTN`-o ^i݌ʱb8z?=#TV켓}]IEcs>-B1LxL9j޳ОEmF@)=4ٰ3g֗%i <k{z`r TƒkI+=v %02 ,Ωہ-kTRXbGF4vw\_Оe3L5(Gb+-"rEDJ qjqV|;W=\D~{1XpcY6V>J="Z hʘu5#tq),2~e} Y*G#Q]FW66oSK^es}*Wzq쳘0?4$@)85Xgglp"[䛅J`푹p7tFqv^tg_0\ӄ>9-Gkj.|1QsmUuNxѨQeV(YW`-cft.m#j0VRLNS/b+tgWlx6RҚ$fm'a13 6pWtz՞4iGqj쿌\1sái.=rЌ'ZiGf]T׏Vը> pC6 ,j#rD+PGY7IyG"DKYf gHu1d?Ԕrpګo;tlF/Ģdm={yI ; uj\b[X´[+v|b( 6?wQ'9^n!Ùڎw@p 3))72?AdC(yK$Nhx`,/'[57q㩶mnMvbVy⶯ƮЧ0j˫4M%fA[f3 MeB@v!釱V`at3$7$H?&̞"qr ć.:!GY( (W%m%cƸ{A{p\qHPG'~J WVJ^.a/}4,2Ij1WpRW6hx]Q #;Iʁnm~'ۺ㺁֩hM?Z^Lxˎ!0+fy\bBxZ}vJ=)O/?dxt5?2|U4uoGHaPW(&aٯvGHWlkGݚA7֖fiD hd@ QnC%?^Z6 wy+} B * Ӆg@.#Hr9juYiYTYkPD(@o9]G*GbǣASvYi(򵭜$U+94^^\ y˺g Zf!m."w^)^]0qŜ F+-[&LݗVF%Wl.,9蓕f۾X.Bgh(T@> yn 3`TK 7/9,Ya6+Aa+H\N]4;1Y7|~}rG|Eah`GQ/+9a:X͚/ k+3ilZ@,=Eo!} ȬD_LqB2 #"֝gQm1E3ӀƮQ4vn%ӯ?1rj.j&bYbd;h Z]!]cKKHma8@OhF-^8 ^MbL?/7^Sqa!_M~* ;@ MKLr}8ΪhѨF;֓H *VS,^V~ijLxV%7pgzo^\Ů:gtQ:lOߍD*\b G`FP5WGFyiٙ@:k{tSU:$5ع6tod~*aKT('i,NI"~qm:Y܌}5nN LkLo-b?kNǦmEԇ}f]ʠC˞J$ }<<Ϙ6{^`YmtG5,RZ%9Y(ddX0x5w>rblIجɜ/*ݮ##J:Ȯ{"#i1n%Q Kv#s״ٕIZ28-Dޖ0gyc2({ t{{Y'W0}`:Pv] @ZJ@(GB"ШMO ^CuhpR[OXUW2l\AًjV6ldyU}6)*)/)'2@ Tk^?08j&'dhcO ̎nD 03\o_MQudJkf.:?cWdLn5ѩ<Gj,ilAM ׍!6$/~/*sez ;[]lق7{d KB0S풋B!{-Pogzhn23 +: c|1C;ʕ;mQ %E g}|Vld"43͛viy=wV]!Y^ &,Ywф}Y@22a0;ȸ;!Sn y\ Sj)+^N`g'/ ~LU-r DQʩ4+o ŀ*AGlVhoqc61cA/<(X{C+pDx;y[H xD~OZTF/+aљC@ /BdgSm d%Mh:h|ʐ LD(ϚfÍunAc|Ϳ{"ifS_,/42Rjty1}U*=NkS`Z԰=FoKxTI/fxMh鋇'NJcZ? k$ Ôpdv>(@L٭=K9ߕdXE( \6k5cxpEWC< ƠO+8A)`n`|y 8!ڬ=X|1W갪O=Bg.+#G,ʇ]R."N\vp(,~wXc>:q b,6uz6{f) !b}h~!sC=B3J-)3W =4>O>Iķ?Vo[j&5H?n'*it>?x%Mc_q1݉ 0N_{pS~Gp{JFQ?!#TI"o[>RtFp%1qLqe 9VQQK ^JJYqz{&X |!et8 <ƪY8 G:#0V=Mg -/45-X@+osWf&r4}DfP>bkq6`‡uc\9=겠 ZڽoWR?Uw[#J8?J:BvS3e)j P EY2Rj>] >@cC42PZ %HMO4ٙX! 7Z^H p0sH ]J["9{F}p}1 Qprxz *&׍܁ aape ~F\LA}5GyeLX@hT*iЭ(h Ipp^ &"G=y"uin?m}@8IZ㳂RMEv-X 5$s2p+ն*Lm=|Cq}c!;I hZ=c`pa&=th1Z-,PfiW|qik; U|"FbxTZO8x kuo~47R|&n>TL Tm!%p-svPGu*41hOH>|sMuT&UВ:`RƆt &ZHߴh_aq <*bA9ٸ9yb? )TNw*cQPW#Dd†[Z8\z=(,uJɉ:k]kf[`W`Z;>$mlSfoWhDP]41A6=pG ^%pyX|ƫ äPXYJqUkOc$]v qsX* XfKy8̘*g̘@%>Pe&`R&V9<`#oS~P>@_ -K}~]^tȠ]P|:4gSu8.W' e$P.i 'pҾn2yV~Ix5oJ:w6[3l皨E!ѬZHxZu + =>#3\@bVb,}-NgQ0MH9ٔ4TӣWL &H:ʍQ [!^l],6^U[O/Xv38lw\Rn=s֎hau۩0gu KG/÷*@5rnY_ޮaրx?#ߘHH"QD%Wu7TeO? 9AlJYI@gxR5g&MD83&`(EOcԣ) fNDV!X,*n=rv'Mo4- 'a bŐ;0Ϊnfj#߯#S*+!8Aʐ q?k$`.X@4@gCE5 g W AևhY6<\}8 (DWm"/B]`ecq(2 5ȄK^F L} Wnsɠo~ Vgyd~H -fH:MQtIHgN'AWԱmIjIRfb~]w↴Iۧ8joXTmNq]ۙ4bAX(kby`giE۰b{Lp4(@6-/KMt m _ A|&/aS%Q\xgk=8Խwz" K~3 !+p}x ٘`l0z$Uƪ:} wRn)]\9i%P va SK\J?#haV.d @ޖoYJb(фH$EK`(EhxiU9 Fȟvs-⁍FN=}4VJ-ް?(5 d3DhL?|j,8=!%<B%@]sG`2HQ6PikiH^SHь*}TpD%,P`HO 9^zy_o_%P6/CgK_ 9hR6]`y "cX UF'RP@n²g$DJkEX?90$t̠ڹ⯥Uu?{V<&Q'hicE+Tfj.4s"C g*4gҽzHikcۧ{@nV$/hp~"%IRx!Vo>?sFr Y|PGIdnN-U{#+< ;'olFdϿOJ=oiU; 5j*0~rsz@I>En4a;jVg`kͰgI僔?:=3_(yV";uCΏ?X}6D$.C#9Ql"kib@_#pzͻO)_FDV5i<4 =k*%zXAlN.YmS=i+fwג%P %Z S"brm|Cco[R&:SaEϔfIBêu:#6.j8I6υHJ.mQ40=(vv!L[K۬t )`$ruJOͩTp8"9qn=j<9t~߿exdrf\LLSk 0W:tw9bt GIM.k\c#W'd6(yG׃qw7($eA"8Dn95WSE.buAJob>uvf\}fZ+=Ni#Q\m; ^)W|> =&Ow*`Z=t>P|Bk)G/26ERliJvzr8]@VidisN܏%UD(Ҿo`hU3ai|x,.,m<B茂y!يiX-V(VlIw)Ãf׈LaU[cT.JWG;R rK2mA;7Zj.̱|T"6G0u邓2֗YX-XT|cHv]dWkoReL>0%^8&6U$Aϯ|lb$ǔO b'F,@ +v 6B% 4Ecp?JOeu)an/xJR٧u9K6.N!K@q$(_].7)(Mջ z]H(~1I~ dG ["qZZO:u`Tuf1(aQQja;Qg&_<| WSbrL BMDp eIPsHs+CG輏z\ ^HEW9Gӹaz}k[e/G13?. \NHmpdt'EAЮ!n))uQG"OB^XՖ%NEn-tpK=^+vA Wp1(;]p7SRG)4 B*u[-F]EXG#IZ.ncFEEBy/= H$&c0͉J ua$:yVct/`3o+MoڈQkIMVS t--"e'Iof]l$lY.WRIK5U#_ЊQ.%O|҈?ogA^CIug*qƇ(U^6vETD.z _?Lkq] ]#*79fwt#jxm(xpm`)SJ`׆- %ks%Wňz8t OEJ޸,5WTKs:GxS(z)#5lrbN++Q <6(KwW\NtE6fl ^_~4#Zh=GsjN|)h0J_V!WG5{ Ø5Bi|FvʅF ~BJrLqbg>KEpV6v$n< b _ݭGDWBu{pN?& o8XMK&~ƾTQ+vqs=ؓM Xū"=}0;MX0?JJTF#m4}.f|y^m  AZޣWw֘3Zؚ34f tKɖ|HlEk[<r!.Ys~슌wa0Rǵ;;2Vmi=qU% n-l&aޠBa !*ۍV#9ιK Ա]Ŷg{!~ o)lLD~ӓ4zOw!t[N@W+ȿ BAOћCsPl +1%dsZ rbcF0n7?kP|p ]OOg V $%>ۤbAC.!cZORݓV P2r1ۛe&O8iMe8nx1QqvvPм~gSIѨVW0=vc`XK4U6^ M'\'߉W3%i"u-ڀ|c3-a"i{эDx!{ɱU+Izǹ~]|u|IB1BDRkofL,o($w8bC,:uh&)EL96?}YԾcnQI(a u^9A'su?|wdlWNCG$}ρČnQc(jQOʤ1&ʹʸa4zwBCQJiS&G7",8@@1Gwa5OJ1ئt+y`ѓqtI,HvTtv:3i M;+)=RIBʗ c~5J7/^tO2%*^4qgi6nfgK_E2$LQّks}_st;c7{Yה_b*r_t]*Eom>zr7UC8muJP }<7'$(Zn~Uinν%ܤX qI3HN |d-ds3$ Ej_;pTY$IgCO.N߮,AS^8Jx{Ձ"ğJ ٯFC?I}Pɥ( STa]v'1@ҧKR2/^tHZIGUmmzx~+4kGDДco.^j*8uigj&${>MŌ`GOەFp/geԂ('3uˈ(44OW]i7˳)"u;? K>m51KJSl_'-Wy ɓ`K#!gpқyq멍1~6BtWë1Xf٣Ui\@ PYԖ h5!A{M 7e7ɰZ~k\jJ(bT;I(i5\Q }z|ĭ_B o^uco~ys7PVz%Yrn1JQ,3hjTL|hǃb1JG%43)S¼t[[5Uc{GTlcEtdc)CGpxnco֬Kc.\Ϧ Ӱ Ƥ ( C$WơN`Y-S*A~\Z 3bM2'CF>N[tlHqKHw4R6Vt,*%$#.*Zl?89's nw*"CII:&_bU%khuy TͨHBO):iK9Olyͳ}eV5{{7Ebt=#+c=? cEIWuCiF_N͓H4]}7M4\8-Bw[`!TNyOP-';`9r9z$ )vlc_OBYSU,A(Fj<$BQ~yK߫aRrk7n&uJ%`][$mv.t˴G O邐dS)n~<<}U DjvY[iF}֩抆#WqҩyMX =JC\0|X"rwh{1JW,h)XjOݑU+1q8PJ2Y{s0:s~:b94"ZxΐK>냈u0 E@K<ݟ~ۤN9e1$hVׇL&DkܥR.ۏMR,Pqbٹ㱙87"I#P:j i["ʣ Fl|v։!:}jxkNuGRNP؀rV@fԽՎigۀPnJ78c 8OwFd f$j:k>ZUq;v3 \j:Ewtco:4$p#x-NON 0>wDԸ3>h770Y9`7u-ְp]"9&O HzSosOxR5ȝ xUhQ/ VZmvJ\&˨JceaAoqiBnѴ8ᕥtbܷWS;ur:T v {? r$W-Mܔ9bÎ@}uyk4#^l,s ]n3rm~MMۇlm2{mw]=.G:#N#oh3# b.QCDAӲ`&+앢АH*~S.?ߌȎe4{OrP90uYJLp8jX G'|1D,2tJ4vM +qcEAΝ*,~&|Su>=]#5G<"?MWo3d䖞5^ ƭ{KZT#܇gY^}0>8i(`\϶WNI) 䯥RaȎa8mAie6bhaɨQp=-yN=NmSv$Cy{8V}Oi <7S [e,HQz&lf!RajN Gʨe}!.NLN% '$-13JB Yᑆo$sorZ2~Ht^P}Hɴ 7~J YZ