nss-util-3.67.0-4.el8_4 >  A `AU]݀ Deui %BV]lДTޝl瓾]Mg7) TXz 1JwCmh( yEga-(!KiK ѣkbZ&ŧ۴^9 `d P4.4}*tEQ.R7A 52\Íe/hwOs6W19$^O^䧌b Y:V1$q'qz0~P.x(v 6dffe413333253b7cf2b70255a67db10842064d891fca2b44c3204754efeb34d36019a2a1f38c1c325036e1efc71b2fceed723575ԉ`AU]J< 0).VwF?ƍ5X KO# r/[ݬ؆ۆbE 77Ƹ?jMrjxrFSp8¡Ej&1(__s!{Ƭ> y)iLzih;ӋJbm(#N9~b k[b8>4 ^[VO2v E Zę:nZs46 9(p|R_?RTRXxm*?`>-smљPnõK\ a?ޖmVx+ " RT3 Y%j#6nlShLq,ZaZL3w0T*\_}a TFS02XhxbwQ6"(v*C6~*b>{CBXG՘a$6t}1@f!/pz.{Daysjud32` ]PQss$2P>p<l?\d   F $,D P \ t  $<ZxX(89 (:ZGdH|IXY\]0^bdfekfnlptuvw`xxy XCnss-util3.67.04.el8_4Network Security Services Utilities LibraryUtilities for Network Security Services and the Softoken module`A(x86-01.mbox.centos.org PCentOSCentOSMPLv2.0CentOS Buildsys Unspecifiedhttp://www.mozilla.org/projects/security/pki/nss/linuxi686"ĜFAAA큤`A%`A%`A%``A%`607d739820ce0e5b7547179c21e2e18e8348ea79c343549d1ed0a9d6d9621c4ea20c1a32d1f8102432360b42e932869f7c11c7cdbacf9cac554c422132af47f4../../../../usr/lib/libnssutil3.sorootrootrootrootrootrootrootrootrootrootrootrootnss-3.67.0-4.el8_4.src.rpmlibnssutil3.solibnssutil3.so(NSSUTIL_3.12)libnssutil3.so(NSSUTIL_3.12.3)libnssutil3.so(NSSUTIL_3.12.5)libnssutil3.so(NSSUTIL_3.12.7)libnssutil3.so(NSSUTIL_3.13)libnssutil3.so(NSSUTIL_3.14)libnssutil3.so(NSSUTIL_3.15)libnssutil3.so(NSSUTIL_3.17.1)libnssutil3.so(NSSUTIL_3.21)libnssutil3.so(NSSUTIL_3.24)libnssutil3.so(NSSUTIL_3.25)libnssutil3.so(NSSUTIL_3.31)libnssutil3.so(NSSUTIL_3.33)libnssutil3.so(NSSUTIL_3.38)libnssutil3.so(NSSUTIL_3.39)libnssutil3.so(NSSUTIL_3.59)nss-utilnss-util(x86-32)@@@@@@@@@@@@@     @libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libdl.so.2libnspr4.solibplc4.solibplds4.solibpthread.so.0libpthread.so.0(GLIBC_2.0)nsprrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)4.25.03.0.4-14.6.0-14.0-15.2-14.14.3` @`ٹ`̊`9@`Ȗ@`D`r_@_^@___@__"@_"@_"@_!d_@_ L_ _@^^@@^@^ۅ@^4]N@]]߶]e@]M@]µ]L]]^@\F@\Q\\\\\\@\I\I\U@\ `\l@[[[u[#@[[W[O+[M@[ZZw@Z|;Zo Zo Zg#Z ZZZ@Y+@Y{YY@Yn@YV@Y@YyYm@Yg`YJ_Y1S@XX@XX @XXYX@X@XX~@Xx@XoX>@X*X@WW@Wt@W~Wv[@WrfWoWm WbWQq@WPWJWDB@W4p@W@Wo@W@VV޾V޾V@VяVIVɦV@V@V=@V@V@VO @VHsVEV3[V UYU@UU@U@U>Ua@Ug@U[%UUU @T@Ts@TTء@T@TÉ@TT@T@T?@T:m@T"@S@S<@S@S@S @SSSSpShS(5@S@SRy@RJ@R@RR@RSRR@Rm@Rg@RD!R@RRR|Q@Q*@QQ@QKQ@QQW@Qw@Q]k@QNQ9Q7/Q#@QQ @P!@PՠP @PqP@P@PAPXPd@Pd@PPP@PP5@PPnP;a@P(@P H@O;O;O@OiO@O@O}O~OiOYOX@OOdO&@O!@@OO@O@N>@N>@NNܲ@N`NؽNN@NuN;@Np@Nf @NA!@N*NpM@MWMc@MM@M@MMfH@M^_@MZjMS@MQ0@MQ0@MQ0@MQ0@MK@MGMF@M6@M-MM@Ls@LOLLZ@L6LdL@L*@L@LA@LL@L4Lx@Lx@Li(@Lf@L_L_LT@L0L0L K @KsKsKKCKCKCK]KMKLd@KD{@K<@K5K4@K,@K+nK*@K K@K@K@KJݦ@J - 3.67.0-4Bob Relyea - 3.67.0-3Bob Relyea - 3.67.0-2Bob Relyea - 3.67.0-1Bob Relyea - 3.66.0-2Bob Relyea - 3.66.0-1.1Bob Relyea - 3.66.0-1Bob Relyea - 3.53.1-17Bob Relyea - 3.53.1-16Bob Relyea - 3.53.1-15Bob Relyea - 3.53.1-14Bob Relyea - 3.53.1-13Bob Relyea - 3.53.1-12Bob Relyea - 3.53.1-11Bob Relyea - 3.53.1-10Daiki Ueno - 3.53.1-9Daiki Ueno - 3.53.1-8Bob Relyea - 3.53.1-7Daiki Ueno - 3.53.1-6Bob Relyea - 3.53.1-5Bob Relyea - 3.53.1-4Daiki Ueno - 3.53.1-3Daiki Ueno - 3.53.1-2Daiki Ueno - 3.53.1-1Daiki Ueno - 3.53.0-1Bob Relyea - 3.44.0-15Bob Relyea - 3.44.0-14Bob Relyea - 3.44.0-13Daiki Ueno - 3.44.0-12Bob Relyea - 3.44.0-11Daiki Ueno - 3.44.0-10Bob Relyea - 3.44.0-9Bob Relyea - 3.44.0-8Daiki Ueno - 3.44.0-7Daiki Ueno - 3.44.0-6Daiki Ueno - 3.44.0-5Bob Relyea - 3.44.0-4.1Bob Relyea - 3.44.0-4Daiki Ueno - 3.44.0-3Bob Relyea - 3.44.0-2Daiki Ueno - 3.44.0-1Daiki Ueno - 3.41.0-5Bob Relyea - 3.41.0-4Daiki Ueno - 3.41.0-3Daiki Ueno - 3.41.0-2Daiki Ueno - 3.41.0-1Daiki Ueno - 3.39.0-1.5Bob Relyea - 3.39.0-1.4Daiki Ueno - 3.39.0-1.3Daiki Ueno - 3.39.0-1.2Daiki Ueno - 3.39.0-1.1Daiki Ueno - 3.39.0-1.0Daiki Ueno - 3.38.0-1.2Daiki Ueno - 3.38.0-1.1Daiki Ueno - 3.38.0-1.0Kai Engert - 3.36.1-1.2Daiki Ueno - 3.36.1-1.1Daiki Ueno - 3.36.1-1.0Daiki Ueno - 3.36.0-1.0Fedora Release Engineering - 3.35.0-5Kai Engert - 3.35.0-4Kai Engert - 3.35.0-3Daiki Ueno - 3.35.0-2Daiki Ueno - 3.34.0-2Daiki Ueno - 3.33.0-6Kai Engert - 3.33.0-5Kai Engert - 3.33.0-4Kai Engert - 3.33.0-3Daiki Ueno - 3.33.0-2Daiki Ueno - 3.32.1-2Daiki Ueno - 3.32.0-4Kai Engert - 3.32.0-3Daiki Ueno - 3.32.0-2Fedora Release Engineering - 3.31.0-6Fedora Release Engineering - 3.31.0-5Daiki Ueno - 3.31.0-4Daiki Ueno - 3.31.0-3Daiki Ueno - 3.31.0-2Daiki Ueno - 3.30.2-3Daiki Ueno - 3.30.2-2Kai Engert - 3.30.0-3Daiki Ueno - 3.30.0-2Kai Engert - 3.29.1-3Daiki Ueno - 3.29.1-2Daiki Ueno - 3.29.0-3Daiki Ueno - 3.29.0-2Daiki Ueno - 3.28.1-6Daiki Ueno - 3.28.1-5Daiki Ueno - 3.28.1-4Daiki Ueno - 3.28.1-3Daiki Ueno - 3.28.1-2Daiki Ueno - 3.27.2-2Daiki Ueno - 3.27.0-5Kai Engert - 3.27.0-4Daiki Ueno - 3.27.0-3Daiki Ueno - 3.27.0-2Daiki Ueno - 3.26.0-2Elio Maldonado - 3.25.0-6Elio Maldonado - 3.25.0-5Elio Maldonado - 3.25.0-4Elio Maldonado - 3.25.0-3Elio Maldonado - 3.25.0-2Kamil Dudka - 3.24.0-3Elio Maldonado - 3.24.0-2.3Elio Maldonado - 3.24.0-2.2Elio Maldonado - 3.24.0-2.1Elio Maldonado - 3.24.0-2.0Elio Maldonado - 3.23.0-9Elio Maldonado - 3.23.0-8Elio Maldonado - 3.23.0-7Elio Maldonado - 3.23.0-6Elio Maldonado - 3.23.0-5Elio Maldonado - 3.23.0-4Elio Maldonado - 3.23.0-3Elio Maldonado - 3.23.0-2Elio Maldonado - 3.22.2-2Elio Maldonado - 3.22.1-3Elio Maldonado - 3.22.1-1Elio Maldonado - 3.22.0-3Elio Maldonado - 3.22.0-2Fedora Release Engineering - 3.21.0-7Elio Maldonado - 3.21.0-6Michal Toman - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado Batiz - 3.21.1-2Elio Maldonado - 3.20.1-2Elio Maldonado - 3.20.0-6Elio Maldonado - 3.20.0-5Elio Maldonado - 3.20.0-4Elio Maldonado - 3.20.0-3Elio Maldonado - 3.20.0-2Elio Maldonado - 3.19.3-2Elio Maldonado - 3.19.2-3Kai Engert - 3.19.2-2Kai Engert - 3.19.1-2Kai Engert - 3.19.0-2Kai Engert - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.17.4-5Till Maas - 3.17.4-4Elio Maldonado - 3.17.4-3Elio Maldonado - 3.17.4-2Elio Maldonado - 3.17.4-1Ville Skyttä - 3.17.3-4Elio Maldonado - 3.17.3-3Elio Maldonado - 3.17.3-2Elio Maldonado - 3.17.3-1Elio Maldonado - 3.17.2-2Elio Maldonado - 3.17.2-1Kai Engert - 3.17.1-1Kevin Fenzi - 3.17.0-2Elio Maldonado - 3.17.0-1Fedora Release Engineering - 3.16.2-4Elio Maldonado - 3.16.2-3Tom Callaway - 3.16.2-2Elio Maldonado - 3.16.2-1Elio Maldonado - 3.16.1-4Fedora Release Engineering - 3.16.1-3Jaromir Capik - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.16.0-1Elio Maldonado - 3.15.5-2Elio Maldonado - 3.15.5-1Elio Maldonado - 3.15.4-5Elio Maldonado - 3.15.4-4Elio Maldonado - 3.15.4-3Peter Robinson 3.15.4-2Elio Maldonado - 3.15.4-1Elio Maldonado - 3.15.3.1-1Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.2-3Elio Maldonado - 3.15.2-2Elio Maldonado - 3.15.2-1Elio Maldonado - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.15-5emaldona - 3.15-4emaldona - 3.15-3Elio Maldonado - 3.15-2Elio Maldonado - 3.15-1Elio Maldonado - 3.15-0.1.beta1.2Elio Maldonado - 3.15-0.1.beta1.1Kai Engert - 3.14.3-12Kai Engert - 3.14.3-10Kai Engert - 3.14.3-9Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.2-2Elio Maldonado - 3.14.2-1Kai Engert - 3.14.1-3Elio Maldonado - 3.14.1-2Elio Maldonado - 3.14.1-1Elio Maldonado - 3.14-12Elio Maldonado - 3.14-11Elio Maldonado - 3.14-10Elio Maldonado - 3.14-9Elio Maldonado - 3.14-8Elio Maldonado - 3.14-7Elio Maldonado - 3.14-6Elio Maldonado - 3.14-5Elio Maldonado - 3.14-4Elio Maldonado - 3.14-3Elio Maldonado - 3.14-2Elio Maldonado - 3.14-1Elio Maldonado - 3.14-0.1.rc.1Kai Engert - 3.13.6-1Elio Maldonado - 3.13.5-8Elio Maldonado - 3.13.5-7Fedora Release Engineering - 3.13.5-6Elio Maldonado - 3.13.5-5Elio Maldonado - 3.13.5-4Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.4-3Elio Maldonado - 3.13.4-2Elio Maldonado - 3.13.4-1Elio Maldonado - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Tom Callaway - 3.13.1-13Elio Maldonado - 3.13.1-12Fedora Release Engineering - 3.13.1-11Elio Maldonado - 3.13.1-11Elio Maldonado - 3.13.1-10elio maldonado - 3.13.1-9Elio Maldonado - 3.13.1-8Elio Maldonado - 3.13.1-7Elio Maldonado - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado Batiz - 3.13.1-4Elio Maldonado - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.13-1Elio Maldonado - 3.13-0.1.rc0.1Elio Maldonado - 3.12.11-3Kai Engert - 3.12.11-2Elio Maldonado - 3.12.11-1Elio Maldonado - 3.12.10-6Michael Schwendt - 3.12.10-5Elio Maldonado - 3.12.10-4Dennis Gilmore - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.10-0.1.beta1Elio Maldonado - 3.12.9-15Elio Maldonado - 3.12.9-14Elio Maldonado - 3.12.9-13Elio Maldonado - 3.12.9-12Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado - 3.12.9-9Fedora Release Engineering - 3.12.9-8Elio Maldonado - 3.12.9-7Christopher Aillon - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.9-0.1.beta2Elio Maldonado - 3.12.8.99.2-1Elio Maldonado - 3.12.8.99.1-1Elio Maldonado - 3.12.8-9Elio Maldonado - 3.12.8-8Elio Maldonado - 3.12.8-7Elio Maldonado - 3.12.8-6Elio Maldonado - 3.12.8-5Elio Maldonado - 3.12.8-4Elio Maldonado - 3.12.8-3Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Elio Maldonado - 3.12.7.99.4-1Elio Maldonado - 3.12.7.99.3-2Elio Maldonado - 3.12.7.99.3-1Elio Maldonado - 3.12.7-3Elio Maldonado - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-12Elio Maldonado - 3.12.6-11Elio Maldonado - 3.12.6-10Elio Maldonado - 3.12.6-9Dennis Gilmore - 3.12.6-8Elio Maldonado - 3.12.6-7Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-5Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1.13.2Elio Maldonado - 3.12.5-1.13.1Elio Maldonado - 3.12.5-1.13Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.9Elio Maldonado - 3.12.5-2.7Elio Maldonado - 3.12.5-1.6Elio Maldonado - 3.12.5-1.5Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1Elio Maldonado - 3.12.4-14.1Elio Maldonado - 3.12.4-13.1Elio Maldonado - 3.12.4-13Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Better fix for the sdb timeout. The issue wasn't a race, it was the sqlite timeout waiting to begin a transaction under heavy thread usage.- Fix sdb race condition- Fix coverity issues- Rebase to NSS 3.67- Restore old pkcs12 defaults.- build nss for older nspr so we can pass gating with the new nspr in the build root- Rebase to NSS 3.66- Fix various corner cases with ike v1 app b support.- Fix the following CVE - CVE-2020-12403 chacha-poly issues - CVE-2020-12400 constant time ECC. - CVE-2020-6829 constant time ECC.- Revert some policy changes the generate ABI runtime issues.- Add support for enable/disable in policy. Now if your policy file has disallow=x enable=y it will act just like our other libraries.- Add OAEP interface so applications can wrap keys with RSA-OAEP rather than RSA-PKCS-1.- fips need to reject small primes even if they are approved - code to autodetect whether or not to use the cache needs to do so in a way that doesn't mess with filesystem negative file caching. - add kdf selftests- Fix issue with upgradedb where upgradedb expects standard to generate dbm databases, not sql databases (default in RHEL8)- Disable dh timing test because it's unreliable on s390- Explicitly enable upgradedb/sharedb test cycles- Disable Delegated Credentials for TLS- Fix attribute decryption issue where the private key components integrity check on private attributes where not being checked.- Update nss-rsa-pkcs1-sigalgs.patch to the upstream version- Include required checks for dh and ecdh key generation in FIPS mode.- Add better checks for dh derive operations in FIPS mode.- Disable NSS_HASH_ALG_SUPPORT as well for MD5 (#1849938) - Adjust for update-crypto-policies packaging change (#1848649) - Fix compilation with -Werror=strict-prototypes (#1843417)- Fix regression in MD5 disablement (#1849938) - Include rsa_pkcs1_* in signature_algorithms extension (#1847945)- Update to NSS 3.53.1- Update to NSS 3.53- Fix swapped CMAC PKCS #11 values. - Fix data alignment crash in CMAC.- Fix coverify scan issue- Fix endian problem in SP-800 108 code.- Install cmac.h required by blapi.h (#1764513) - Fix out-of-bounds write in NSC_EncryptUpdate (#1775913)- Add SP-800 108 Generalized kdf- Check policy against hash algorithms used for ServerKeyExchange (#1730039)- Add CMAC- CKM_NSS_IKE1_APP_B_PRF_DERIVE was missing from the mechanism list, preventing PK11_Derive*() from using it. Add gtests for the PK11_Derive interface for all the CKM_NSS_IKE*_DERIVE mechanism.- Backport fixes from 3.44.1- Add continuous RNG test required by FIPS - fipstest: use CKM_TLS12_MASTER_KEY_DERIVE instead of vendor specific mechanism- Rebuild with the correct build target- rebuild to try to retrigger CI tests- Fix certutil man page - Fix extracting a public key from a private key for dh, ec, and dsa- Disable TLS 1.3 under FIPS mode - Disable RSASSA-PKCS1-v1_5 in TLS 1.3 - Fix post-handshake auth transcript calculation if SSL_ENABLE_SESSION_TICKETS is set - Revert the change to use XDG basedirs (mozilla#818686)- Add ike mechanisms in softokn - Add FIPS checks in softoken- Update to NSS 3.44 - Define NSS_SEED_ONLY_DEV_URANDOM=1 to exclusively use getentropy - Use %autosetup - Clean up manual pages generation - Clean up %check - Remove prelink dependency, which is not available in RHEL-8 - Remove upstreamed patches- Update manual pages to reflect recent changes in commands- Make sure corresponding public keys are created when importing private keys.- Fix the last change - Add --no-reload option to update-crypto-policies to avoid unnecessary restart of daemons- Restore LDFLAGS injection when linking DSO- Update to NSS 3.41 - Consolidate nss-util, nss-softokn, and nss into a single source package- Fix the last commit- Support for IKE/IPsec typical PKIX usage so libreswan can use nss without rejecting certs based on EKU- Backport upstream fixes for rhbz#1649026, rhbz#1608895, rhbz#1644854 - Document PKCS #11 URI - Add warning when adding module with modutil while p11-kit is enabled- Update nss-dsa.patch to not advertise DSA signature algorithm - Update PayPal test certs for testing- Backport "DSA" keyword in crypto-policies- Update to NSS 3.39- Fix LDFLAGS injection when linking DSO- Install crypto-policies configuration file for https://fedoraproject.org/wiki/Changes/NSSLoadP11KitModules - Port enable-fips-when-system-is-in-fips-mode.patch from RHEL-7 - Use %ldconfig_scriptlets - Remove needless use of %defattr, by Jason Tibbitts- Update to NSS 3.38- Backport upstream addition of nss-policy-check utility, rhbz#1428746, includes required fixes for mozbz#1296263 and mozbz#1474875- Switch the default DB type to SQL - Enable SSLKEYLOGFILE- Update to NSS 3.36.1 - Remove nss-3.14.0.0-disble-ocsp-test.patch - Fix partial injection of LDFLAGS - Remove NSS_NO_PKCS11_BYPASS, which is no-op in upstream- Update to NSS 3.36.0 - Add gcc-c++ to BuildRequires (C++ is needed for gtests) - Make test failure detection robuster- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Fix a compiler error with gcc 8, mozbz#1434070 - Set NSS_FORCE_FIPS=1 at %build time, and remove from %check.- Stop pulling in nss-pem automatically, packages that need it should depend on it, rhbz#1539401- Update to NSS 3.35.0- Update to NSS 3.34.0- Make sure 32bit nss-pem always be installed with 32bit nss in multlib environment, patch by Kamil Dudka- Fix test script- Update tests to be compatible with default NSS DB changed to sql (the default was changed in the nss-util package).- rhbz#1505487, backport upstream fixes required for rhbz#1496560- Update to NSS 3.33.0- Update to NSS 3.32.1- Update iquote.patch to really prefer in-tree headers over system headers- NSS libnssckbi.so has already been obsoleted by p11-kit-trust, rhbz#1484449- Update to NSS 3.32.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Backport mozbz#1381784 to avoid deadlock in dnf- Move signtool to %_libdir/nss/unsupported-tools, for: https://fedoraproject.org/wiki/Changes/NSSSigntoolDeprecation- Rebase to NSS 3.31.0- Enable gtests- Rebase to NSS 3.30.2 - Enable TLS 1.3- Backport upstream mozbz#1328318 to support crypto policy FUTURE.- Rebase to NSS 3.30.0 - Remove upstreamed patches- Backport mozbz#1334976 and mozbz#1336487.- Rebase to NSS 3.29.1- Disable TLS 1.3, following the upstream change- Rebase to NSS 3.29.0 - Suppress -Werror=int-in-bool-context warnings with GCC7- Work around pkgconfig -> pkgconf transition issue (releng#6597)- Disable TLS 1.3 - Add "Conflicts" with packages using older Mozilla codebase, which is not compatible with NSS 3.28.1 - Remove NSS_ECC_MORE_THAN_SUITE_B setting, as it was removed in upstream- Add "Conflicts" with older firefox packages which don't have support for smaller curves added in NSS 3.28.1- Fix incorrect version specification in %nss_{util,softokn}_version, pointed by Elio Maldonado- Rebase to NSS 3.28.1 - Remove upstreamed patch for disabling RSA-PSS - Re-enable TLS 1.3- Rebase to NSS 3.27.2- Revert the previous fix for RSA-PSS and use the upstream fix instead- Disable the use of RSA-PSS with SSL/TLS. #1383809- Disable TLS 1.3 for now, to avoid reported regression with TLS to version intolerant servers- Rebase to NSS 3.27.0 - Remove upstreamed ectest patch- Rebase to NSS 3.26.0 - Update check policy file patch to better match what was upstreamed - Remove conditionally ignore system policy patch as it has been upstreamed - Skip ectest as well as ecperf, which are built as part of nss-softokn - Fix rpmlint error regarding %define usage- Incorporate some changes requested in upstream review and commited upstream (#1157720)- Add support for conditionally ignoring the system policy (#1157720) - Remove unneeded test scripts patches in order to run more tests - Remove unneeded test data modifications from the spec file- Remove obsolete patch and spurious lines from the spec file (#1347336)- Cleanup spec file and patches and add references to bugs filed upstream- Rebase to nss 3.25- decouple nss-pem from the nss package (#1347336)- Apply the patch that was last introduced - Renumber and reorder some of the patches - Resolves: Bug 1342158- Allow application requests to disable SSL v2 to succeed - Resolves: Bug 1342158 - nss-3.24 does no longer support ssl V2, installation of IPA fails because nss init fails- Rebase to NSS 3.24.0 - Restore setting the policy file location - Make ssl tests scripts aware of policy - Ajust tests data expected result for policy- Bootstrap build to rebase to NSS 3.24.0 - Temporarily not setting the policy file location- Change POLICY_FILE to "nss.config"- Change POLICY_FILE to "nss.cfg"- Change the POLICY_PATH to "/etc/crypto-policies/back-ends" - Regenerate the check policy patch with hg to provide more context- Fix typo in the last %changelog entry- Load policy file if /etc/pki/nssdb/policy.cfg exists - Resolves: Bug 1157720 - NSS should enforce the system-wide crypto policy- Remove unused patch rendered obsolete by pem update- Update pem sources to latest from nss-pem upstream - Resolves: Bug 1300652 - [PEM] insufficient input validity checking while loading a private key- Rebase to NSS 3.23- Rebase to NSS 3.22.2- Fix ssl2/exp test disabling to run all the required tests- Rebase to NSS 3.22.1- Update .gitignore as part of updating to nss 3.22- Update to NSS 3.22- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Resolves: Bug 1299040 - Enable ssl_gtests upstream test suite - Remove 'export NSS_DISABLE_GTESTS=1' go ssl_gtests are built - Use %define when specifying the nss_tests to run- Add 64-bit MIPS to multilib arches- Update %{nss_util_version} and %{nss_softokn_version} to 3.21.0 - Resolves: Bug 1284095 - all https fails with sec_error_no_token- Add references to bugs filed upstream- Update to NSS 3.21 - Package listsuites as part of the unsupported tools set - Resolves: Bug 1279912 - nss-3.21 is available - Resolves: Bug 1258425 - Use __isa_bits macro instead of list of 64-bit - Resolves: Bug 1280032 - Package listsuites as part of the nss unsupported tools set- Update to NSS 3.20.1- Enable ECC cipher-suites by default [hrbz#1185708] - Split the enabling patch in two for easier maintenance - Remove unused patches rendered obsolete by prior rebase- Enable ECC cipher-suites by default [hrbz#1185708] - Implement corrections requested in code review- Enable ECC cipher-suites by default [hrbz#1185708]- Fix patches that disable ssl2 and export cipher suites support - Fix libssl patch that disable ssl2 & export cipher suites to not disable RSA_WITH_NULL ciphers - Fix syntax errors in patch to skip ssl2 and export cipher suite tests - Turn ssl2 off by default in the tstclnt tool - Disable ssl stress tests containing TLS RC4 128 with MD5- Update to NSS 3.20- Update to NSS 3.19.3- Create on the fly versions of sslcov.txt and sslstress.txt that disable tests for SSL2 and EXPORT ciphers- Update to NSS 3.19.2- Update to NSS 3.19.1- Update to NSS 3.19- Replace expired test certificates, upstream bug 1151037- Update to nss-3.18.0 - Resolves: Bug 1203689 - nss-3.18 is available- Disable export suites and SSL2 support at build time - Fix syntax errors in various shell scripts - Resolves: Bug 1189952 - Disable SSL2 and the export cipher suites- Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code- Commented out the export NSS_NO_SSL2=1 line to not disable ssl2 - Backing out from disabling ssl2 until the patches are fixed- Disable SSL2 support at build time - Fix syntax errors in various shell scripts - Resolves: Bug 1189952 - Disable SSL2 and the export cipher suites- Update to nss-3.17.4- Own the %{_datadir}/doc/nss-tools dir- Resolves: Bug 987189 - nss-tools RPM conflicts with perl-PAR-Packer - Install pp man page in %{_datadir}/doc/nss-tools/pp.1 - Use %{_mandir} instead of /usr/share/man as more generic- Install pp man page in alternative location - Resolves: Bug 987189 - nss-tools RPM conflicts with perl-PAR-Packer- Update to nss-3.17.3 - Resolves: Bug 1171012 - nss-3.17.3 is available- Resolves: Bug 994599 - Enable TLS 1.2 by default- Update to nss-3.17.2- Update to nss-3.17.1 - Add a mechanism to skip test suite execution during development work- Rebuild for rpm bug 1131960- Update to nss-3.17.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Replace expired PayPal test cert with current one to prevent build failure- fix license handling- Update to nss-3.16.2- Remove unwanted source directories at end of %prep so it truly does it - Skip the cipher suite already run as part of the nss-softokn build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Replacing ppc64 and ppc64le with the power64 macro - Related: Bug 1052545 - Trivial change for ppc64le in nss spec- Update to nss-3.16.1 - Update the iquote patch on account of the rebase - Improve error detection in the %section - Resolves: Bug 1094702 - nss-3.16.1 is available- Update to nss-3.16.0 - Cleanup the copying of the tools man pages - Update the iquote.patch on account of the rebase- Restore requiring nss_softokn_version >= 3.15.5- Update to nss-3.15.5 - Temporarily requiring only nss_softokn_version >= 3.15.4 - Fix location of sharedb files and their manpages - Move cert9.db, key4.db, and pkcs11.txt to the main package - Move nss-sysinit manpages tar archives to the main package - Resolves: Bug 1066877 - nss-3.15.5 is available - Resolves: Bug 1067091 - Move sharedb files to the %files section- Revert previous change that moved some sysinit manpages - Restore nss-sysinit manpages tar archives to %files sysinit - Removing spurious wildcard entry was the only change needed- Add explanatory comments for iquote.patch as was done on f20- Update pem sources to latest from nss-pem upstream - Pick up pem fixes verified on RHEL and applied upstream - Fix a problem where same files in two rpms created rpm conflict - Move some nss-sysinit manpages tar archives to the %files the - All man pages are listed by name so there shouldn't be wildcard inclusion - Add support for ppc64le, Resolves: Bug 1052545- ARM tests pass so remove ARM conditional- Update to nss-3.15.4 (hg tag NSS_3_15_4_RTM) - Resolves: Bug 1049229 - nss-3.15.4 is available - Update pem sources to latest from the interim upstream for pem - Remove no longer needed patches - Update pem/rsawrapr.c patch on account of upstream changes to freebl/softoken - Update iquote.patch on account of upstream changes- Update to nss-3.15.3.1 (hg tag NSS_3_15_3_1_RTM) - Resolves: Bug 1040282 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) - Resolves: Bug 1040192 - nss-3.15.3.1 is available- Bump the release tag- Update to NSS_3_15_3_RTM - Resolves: Bug 1031897 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws - Fix option descriptions for setup-nsssysinit manpage - Fix man page of nss-sysinit wrong path and other flaws - Document email option for certutil manpage - Remove unused patches- Revert one change from last commit to preserve full nss pluggable ecc supprt [1019245]- Use the full sources from upstream - Bug 1019245 - ECDHE in openssl available -> NSS needs too for Firefox/Thunderbird- Update to NSS_3_15_2_RTM - Update iquote.patch on account of modified prototype on cert.h installed by nss-devel- Update pem sources to pick up a patch applied upstream which a faulty merge had missed - The pem module should not require unique file basenames- Update pem sources to the latest from interim upstream- Resolves: rhbz#996639 - Minor bugs in nss man pages - Fix some typos and improve description and see also sections- Cleanup spec file to address most rpmlint errors and warnings - Using double percent symbols to fix macro-in-comment warnings - Ignore unversioned-explicit-provides nss-system-init per spec comments - Ignore invalid-url Source0 as it comes from the git lookaside cache - Ignore invalid-url Source12 as it comes from the git lookaside cache- Add man page for pkcs11.txt configuration file and cert and key databases - Resolves: rhbz#985114 - Provide man pages for the nss configuration files- Fix errors in the man pages - Resolves: rhbz#984106 - Add missing option descriptions to man pages for {cert|cms|crl}util - Resolves: rhbz#982856 - Fix path to script in man page for nss-sysinit- Update to NSS_3_15_1_RTM - Enable the iquote.patch to access newly introduced types- Install man pages for nss-tools and the nss-config and setup-nsssysinit scripts - Resolves: rhbz#606020 - nss security tools lack man pages- Build nss without softoken or util sources in the tree - Resolves: rhbz#689918- Update ssl-cbc-random-iv-by-default.patch- Fix generation of NSS_VMAJOR, NSS_VMINOR, and NSS_VPATCH for nss-config- Update to NSS_3_15_RTM- Fix incorrect path that hid failed test from view - Add ocsp to the test suites to run but ... - Temporarily disable the ocsp stapling tests - Do not treat failed attempts at ssl pkcs11 bypass as fatal errors- Update to NSS_3_15_BETA1 - Update spec file, patches, and helper scripts on account of a shallower source tree- Update expired test certificates (fixed in upstream bug 852781)- Fix incorrect post/postun scripts. Fix broken links in posttrans.- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement.- Update to NSS_3_14_3_RTM - sync up pem rsawrapr.c with softoken upstream changes for nss-3.14.3 - Resolves: rhbz#908257 - CVE-2013-1620 nss: TLS CBC padding timing attack - Resolves: rhbz#896651 - PEM module trashes private keys if login fails - Resolves: rhbz#909775 - specfile support for AArch64 - Resolves: rhbz#910584 - certutil -a does not produce ASCII output- Allow building nss against older system sqlite- Update to NSS_3_14_2_RTM- Update to NSS_3_14_1_WITH_CKBI_1_93_RTM- Require nspr >= 4.9.4 - Fix changelog invalid dates- Update to NSS_3_14_1_RTM- Bug 879978 - Install the nssck.api header template where mod_revocator can access it - Install nssck.api in /usr/includes/nss3/templates- Bug 879978 - Install the nssck.api header template in a place where mod_revocator can access it - Install nssck.api in /usr/includes/nss3- Bug 870864 - Add support in NSS for Secure Boot- Disable bypass code at build time and return failure on attempts to enable at runtime - Bug 806588 - Disable SSL PKCS #11 bypass at build time- Fix pk11wrap locking which fixes 'fedpkg new-sources' and 'fedpkg update' hangs - Bug 872124 - nss-3.14 breaks fedpkg new-sources - Fix should be considered preliminary since the patch may change upon upstream approval- Add a dummy source file for testing /preventing fedpkg breakage - Helps test the fedpkg new-sources and upload commands for breakage by nss updates - Related to Bug 872124 - nss 3.14 breaks fedpkg new-sources- Fix a previous unwanted merge from f18 - Update the SS_SSL_CBC_RANDOM_IV patch to match new sources while - Keeping the patch disabled while we are still in rawhide and - State in comment that patch is needed for both stable and beta branches - Update .gitignore to download only the new sources- Fix the spec file so sechash.h gets installed - Resolves: rhbz#871882 - missing header: sechash.h in nss 3.14- Update the license to MPLv2.0- Use only -f when removing unwanted headers- Add secmodt.h to the headers installed by nss-devel - nss-devel must install secmodt.h which moved from softoken to pk11wrap with nss-3.14- Update to NSS_3_14_RTM- Update to NSS_3_14_RC1 - update nss-589636.patch to apply to httpdserv - turn off ocsp tests for now - remove no longer needed patches - remove headers shipped by nss-util- Update to NSS_3_13_6_RTM- Rebase pem sources to fedora-hosted upstream to pick up two fixes from rhel-6.3 - Resolves: rhbz#847460 - Fix invalid read and free on invalid cert load - Resolves: rhbz#847462 - PEM module may attempt to free uninitialized pointer - Remove unneeded fix gcc 4.7 c++ issue in secmodt.h that actually undoes the upstream fix- Fix pluggable ecc support- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Fix checkin comment to prevent unwanted expansions of percents- Resolves: Bug 830410 - Missing Requires %{?_isa} - Use Requires: %{name}%{?_isa} = %{version}-%{release} on tools - Drop zlib requires which rpmlint reports as error E: explicit-lib-dependency zlib - Enable sha224 portion of powerup selftest when running test suites - Require nspr 4.9.1- Resolves: rhbz#833529 - revert unwanted change to nss.pc.in- Resolves: rhbz#833529 - Remove unwanted space from the Libs: line on nss.pc.in- Update to NSS_3_13_5_RTM- Resolves: Bug 812423 - nss_Init leaks memory, fix from RHEL 6.3- Resolves: Bug 805723 - Library needs partial RELRO support added - Patch coreconf/Linux.mk as done on RHEL 6.2- Update to NSS_3_13_4_RTM - Update the nss-pem source archive to the latest version - Remove no longer needed patches - Resolves: Bug 806043 - use pem files interchangeably in a single process - Resolves: Bug 806051 - PEM various flaws detected by Coverity - Resolves: Bug 806058 - PEM pem_CreateObject leaks memory given a non-existing file name- Resolves: Bug 805723 - Library needs partial RELRO support added- Cleanup of the spec file - Add references to the upstream bugs - Fix typo in Summary for sysinit- Pick up fixes from RHEL - Resolves: rhbz#800674 - Unable to contact LDAP Server during winsync - Resolves: rhbz#800682 - Qpid AMQP daemon fails to load after nss update - Resolves: rhbz#800676 - NSS workaround for freebl bug that causes openswan to drop connections- Update to NSS_3_13_3_RTM- fix issue with gcc 4.7 in secmodt.h and C++11 user-defined literals- Resolves: Bug 784672 - nss should protect against being called before nss_Init- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- Deactivate a patch currently meant for stable branches only- Resolves: Bug 770682 - nss update breaks pidgin-sipe connectivity - NSS_SSL_CBC_RANDOM_IV set to 0 by default and changed to 1 on user request- Revert to using current nss_softokn_version - Patch to deal with lack of sha224 is no longer needed- Resolves: Bug 754771 - [PEM] an unregistered callback causes a SIGSEGV- Resolves: Bug 750376 - nss 3.13 breaks sssd TLS - Fix how pem is built so that nss-3.13.x works with nss-softokn-3.12.y - Only patch blapitest for the lack of sha224 on system freebl - Completed the patch to make pem link against system freebl- Removed unwanted /usr/include/nss3 in front of the normal cflags include path - Removed unnecessary patch dealing with CERTDB_TERMINAL_RECORD, it's visible- Statically link the pem module against system freebl found in buildroot - Disabling sha224-related powerup selftest until we update softokn - Disable sha224 and pss tests which nss-softokn 3.12.x doesn't support- Rebuild with nss-softokn from 3.12 in the buildroot - Allows the pem module to statically link against 3.12.x freebl - Required for using nss-3.13.x with nss-softokn-3.12.y for a merge inrto rhel git repo - Build will be temprarily placed on buildroot override but not pushed in bodhi- Fix broken dependencies by updating the nss-util and nss-softokn versions- Update to NSS_3_13_1_RTM - Update builtin certs to those from NSSCKBI_1_88_RTM- Update to NSS_3_13_RTM- Update to NSS_3_13_RC0- Fix attempt to free initilized pointer (#717338) - Fix leak on pem_CreateObject when given non-existing file name (#734760) - Fix pem_Initialize to return CKR_CANT_LOCK on multi-treaded calls (#736410)- Update builtins certs to those from NSSCKBI_1_87_RTM- Update to NSS_3_12_11_RTM- Indicate the provenance of stripped source tarball (#688015)- Provide virtual -static package to meet guidelines (#609612).- Enable pluggable ecc support (#712556) - Disable the nssdb write-access-on-read-only-dir tests when user is root (#646045)- make the testsuite non fatal on arm arches- Fix crmf hard-coded maximum size for wrapped private keys (#703656)- Update to NSS_3_12_10_RTM- Update to NSS_3_12_10_BETA1- Implement PEM logging using NSPR's own (#695011)- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Short-term fix for ssl test suites hangs on ipv6 type connections (#539183)- Add a missing requires for pkcs11-devel (#675196)- Run the test suites in the check section (#677809)- Fix cms headers to not use c++ reserved words (#676036) - Reenabling Bug 499444 patches - Fix to swap internal key slot on fips mode switches- Revert patches for 499444 until all c++ reserved words are found and extirpated- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix cms header to not use c++ reserved word (#676036) - Reenable patches for bug 499444- Revert patches for 499444 as they use a C++ reserved word and cause compilation of Firefox to fail- Fix the earlier infinite recursion patch (#499444) - Remove a header that now nss-softokn-freebl-devel ships- Fix infinite recursion when encoding NSS enveloped/digested data (#499444)- Update the cacert trust patch per upstream review requests (#633043)- Fix to honor the user's cert trust preferences (#633043) - Remove obsoleted patch- Update to 3.12.9- Rebuilt according to fedora pre-release package naming guidelines- Update to NSS_3_12_9_BETA2 - Fix libpnsspem crash when cacert dir contains other directories (#642433)- Update to NSS_3_12_9_BETA1- Update pem source tar with fixes for 614532 and 596674 - Remove no longer needed patches- Update PayPalEE.cert test certificate which had expired- Tell rpm not to verify md5, size, and modtime of configurations file- Fix certificates trust order (#643134) - Apply nss-sysinit-userdb-first.patch last- Move triggerpostun -n nss-sysinit script ahead of the other ones (#639248)- Fix invalid %postun scriptlet (#639248)- Replace posttrans sysinit scriptlet with a triggerpostun one (#636787) - Fix and cleanup the setup-nsssysinit.sh script (#636792, #636801)- Add posttrans scriptlet (#636787)- Update to 3.12.8 - Prevent disabling of nss-sysinit on package upgrade (#636787) - Create pkcs11.txt with correct permissions regardless of umask (#636792) - Setup-nsssysinit.sh reports whether nss-sysinit is turned on or off (#636801) - Added provides pkcs11-devel-static to comply with packaging guidelines (#609612)- NSS 3.12.8 RC0- Fix nss-util_version and nss_softokn_version required to be 3.12.7.99.3- NSS 3.12.8 Beta3 - Fix unclosed comment in renegotiate-transitional.patch- Change BuildRequries to available version of nss-util-devel- Define NSS_USE_SYSTEM_SQLITE and remove unneeded patch - Add comments regarding an unversioned provides which triggers rpmlint warning - Build requires nss-softokn-devel >= 3.12.7- Update to 3.12.7- Apply the patches to fix rhbz#614532- Removed pem sourecs as they are in the cache- Add support for PKCS#8 encoded PEM RSA private key files (#614532)- Fix nsssysinit to return userdb ahead of systemdb (#603313)- Require and BuildRequire >= the listed version not =- Require nss-softoken 3.12.6- Fix SIGSEGV within CreateObject (#596674)- Update pem source tar to pick up the following bug fixes: - PEM - Allow collect objects to search through all objects - PEM - Make CopyObject return a new shallow copy - PEM - Fix memory leak in pem_mdCryptoOperationRSAPriv- Update the test cert in the setup phase- Add sed to sysinit requires as setup-nsssysinit.sh requires it (#576071) - Update PayPalEE test cert with unexpired one (#580207)- Fix ns.spec to not require nss-softokn (#575001)- rebuilt with all tests enabled- Using SSL_RENEGOTIATE_TRANSITIONAL as default while on transition period - Disabling ssl tests suites until bug 539183 is resolved- Update to 3.12.6 - Reactivate all tests - Patch tools to validate command line options arguments- Fix curl related regression and general patch code clean up- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- New version of patch to allow root to modify ystem database (#547860)- Temporarily disabling the ssl tests- Fix nsssysinit to allow root to modify the nss system database (#547860)- Fix an error introduced when adapting the patch for rhbz #546211- Remove left over trace statements from nsssysinit patching- Fix a misconstructed patch- Fix nsssysinit to enable apps to use system cert store, patch contributed by David Woodhouse (#546221) - Fix spec so sysinit requires coreutils for post install scriplet (#547067) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387)- Fix nsssysinit to set the default flags on the crypto module (#545779) - Remove redundant header from the pem module- Remove unneeded patch- Retagging to include missing patch- Update to 3.12.5 - Patch to allow ssl/tls clients to interoperate with servers that require renogiation- Retagging- Require nss-softoken of same architecture as nss (#527867) - Merge setup-nsssysinit.sh improvements from F-12 (#527051)- User no longer prompted for a password when listing keys an empty system db (#527048) - Fix setup-nsssysinit to handle more general formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build3.67.0-4.el8_43.67.0-4.el8_4.build-id0c252c107685680e7a5daee460c6fee496c22b6elibnssutil3.sonss-utilCOPYING/usr/lib//usr/lib/.build-id//usr/lib/.build-id/0c//usr/share/licenses//usr/share/licenses/nss-util/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=0c252c107685680e7a5daee460c6fee496c22b6e, strippedASCII textPPPPPPPPP P P P P PPPPR RRRRRRR R RR RRRutf-8f00d8dcc8113ec2b7aed0b4a903f81b685ae5bf19141bbd12305b97e3d5104a1?@7zXZ !#,n] b2u jӫ`(y,xݦ#Ѳ-gιbUWYUVF^,lQY{ct 1I[(hw}G*Zc'RDrr clAt4ë`4#@Hv^3 ĸdK!G ` e~]+$^*fT׭0SČS]|\R /).)LV9 u;72=_@MlBDt1VF mjԟ[7r rlP\AB?uVdFa쐕y+Jv!Y~ŵˍKm'o`$[H^.zPu(OwB<`n}p[{4d2BI_fq OOHlg*Bj|-ESq vY82;-n8 3!м @xObX=ٶFz Dk~+! a+g_^q^$1J-%,S$5<.̞~3P&t 'ԁwX3NR]&cdPsڰ ]Q`HQxjE+ab_e{Ŭs.o;pksfG:xqk5@%Q`X_߮PAwt05Cǂp]{\?K5k VRyՉ yn'ZU/g ͠0Kb@gK;?կ^] ]&:BouNtAouUmorA9qL{ʇ+u8f tO@L Ĵ yPo%J l?Wg Ŵ^HFǼЫX,lbqRjE;$C&dZ(9*s '*D2 M'i< EX|'.s*<dB.I, -tFyD@P >?դ:H4^5X7Q'E%&J57#2bt7*];K]ﺬ{? 5\UW|Ӯa==*_)~ )SG繼#EӋABԼ$ڡ+$SxH*Fīzu\1<}xH^_Tol 6",:/R6;eǠ*2gy{L Oz |gh.K< Z@)_I3)05mrt;(;6 1VNYp27])B WX{XؾdV-߀WUd(W+jCd"es_3Ucna$?\z61f,Ba )n므0:_d`!5[N7ؐX@+f^I:p;.Tiu)k"hQ;ϭ)/Lz&S%lRyƃ֥E&̭F>vMbv7J$#;cK_/㣪sPGOiV#tL8T but߳""z)7 mE֪Uiw.\bJJÎx)xLbK=7 *EdLR?M\ѽ|,BOQż\4v]cF&'wRqA9.o@rJ:P%q6Io B ͉yKg&+W~f|L稧'IQC/XN6T{{+q~xnnu]qX?m & FVCwf4p)65xyfFs5!uD7  ~HH5T3*L&ŇIJJ]a y]LbQbOA.HjwqbCFR 窳@oZU`4!M Я33Qbppx&2rE[Bs7ǐ~i *kk)#ɛ_y@qDlx*`@>TV%Yo3K8{{x}Ů fݶAk'f"E!vKCbf1A-ɓ*p %?n)ʥ\Q!fz.x:g3. ﰏT^gn66kJ^*R tLZcrXzawSdWiUzO;êZ %ƓDYC# i-B F`Lܣ_ȉQ-!BЛYZp\x롣S'rIjh:gKydkDMF$$ (:ɇC4%@֜ v>Ŵ4ۮ?]u '>< CkmȀ~R@wOYQ@=wژ:o& sK'ֱPr\ĊUZ---!jSN>Fq``SwA% iYtP\Ue s?BQ!/ޔM!Q2Eqe/*d^Vvx[ۨq%$ ̛@'e]@ф|y?m}}@=ۡ\o( lFFˏ@*K)Hn6c6 [1%^=W4po1@emdj:MY[*~#/b]1W(! 1;懐Ag@<Alh5`pdWչ ² YPSmru$MRL '1Kls؅f\ u0"#fvkLДRTlOڟ2FS{I ѪCj0z*;LC2n%BLsV47ռb{f_93qnqJƚT(&7>FX x< X/h*&)j4۲DDU.e;f4Y&b6UThABF eCB*[fO{}h.K[s~˾ AY` HFa)]!mFm^)W9SzE!bItۀH,;R5ʽ@$p*Ig/2L,PO]cxm7cL5YX0IɖCYqP E!xN&re%ixnMuR=xJE 줎ʧd:/! {i^$U-CxTBD>þѥ1lDnZ=hZk>qfLOH~'0?}VAHև%7 Fr `'QzІg%9:{F l3@_ bwϞiYQy3oBԊmit3eެ.g_َDQU-sݷ{39":wVn0HvmPK'.b#M#6N}t636+ǘi8T`ƞF\xR\T1!cgTҊъ 49w1OZx2Gj?3.'viVawFGGOX~1ZbMSG[7vgy}}(z+?MpSX4Um(Q--k"fdy嫙d,g{* M:aC:/uTČگ] ;/>ͅ &к%kb,㿣4p/ۼ OʃS &r6!'Bӑa!8N B5"S_6>2AJ-ׅCgW9T,Q^ ~ՒHZ" 5;e\I 'q.]y)\sx"BCۼB*,OǼ/'LRmt Ƒ\c&٣$QAʴu2(R*!dSFƧj{UI:%4vω@W7I2<҄: we2)CWs]sjSM<ܡLuJ%i2FOAНxR®&`sAi==J ՃΏ;lTtA4=:JgM]m}%tEJmZE@$ KBZܫ.EVgIODTd|HGUS!> l}hklg 0=?Ŧ1P 3['7 BP'j9ٌ_0kXr`c1%+Jjם }uDDTf]t(HfyMa)N,򫎨 [sE%eŦYVV9 T V deM2]gfCn}h h HA4\}ٔ5z 4E nH4)De*=_n2u) ΌM dg888VS8m=? %h1"fݦEGu5!$X&+_)x`idU$o(1HѬ ~C, #> D>ػwP,co)={I0Ȱek|w fJ˿Д5+O9n wpwƃJ Phcz*H[#ݏt${uJI?&1<ߖ4?0Ä rݵl` Ѿ8NrJ/X> YLuY~ĚR~ '=rw=wΉ'22v쪂Ȥy4.t$ 9$!IO*Pc4G=uQN,m;+0`&΀8;`+/}cI_1()2;TYPSyƊZXLǫ_jTd9RhM,\/r>yΙYZm8 O>t6ӗW{.yjr ?q=WΏd}q8әSo2YSAbKP^Z Q}śX͵>гH! QuCmS'ǜDxaZo^`u_\VCiR9W2YwT17z]-mZ- R+B7+qSn%4hpl WAAXx.yJu3ʬy`uTSgyӎTn 1mQd3N,׷du"Fi`w?EaZ]jbq֙`C9φA_pvx<u:C.`[>֐@7kv<<,>t!(6goyB9SbfuY^:]8N[v;-vt 謸ay=9}_ϐ_J)W&Q}d>)L]o&yDzTo3(n:@|sV{=^ `C=*\g>L1.VJ݌_ AW_mFr_NZ#J}1bTWFyS湻WjnE1[u (_t`,i2d.y=G pP99tYzoی 16cEGYx䕌ܝ!J͢C?`TgW)BP:Xr!d@׽_85ڟ0(Hz+zq#hhΏT"?E{? p4+s+"ۯ2MCڹ9-Sodp|j0˲FaDBzbXqId fմ!\4(,Qd[.FL>k2'lH7%\Z}pDxeIPʝ45'eΑڇExT}{f8sg ")O0llOE=t4sP hYGE3 / |_ʼnͮ0'@#2+BBtCJGxOZ~|->-,yt"k //sc(sw-)1,{RBԫ[R8A#`Ȇ63:r+_V'<4ݰ ۿ8+ѷoR-ۤ|ݳp Sv0Ln@XT*p{}K8C*gU_2F Ǐ"r&BkD8qwWjy,ၽROYo?YԆᮙQG{6]A{vOwMXFEoK5uGL@WWPVG%ƃఒ7A.s}E={%B72ċz1ijbZ#*~2p{\LާKn\[<9 ,U\YL3~B5 <$ҳ5}yщ ](i dKIw|"^~:38qm/N~`0>FM ͷj:^À{,-/W{Ő7G޿HO|SE4X44݁l&(ʕ|1Dz3vj$]U cybvdź*q tT/S6yg"W{c9+\f gnALW,2#o7R) *;u 8O5iڇŧǮsI 0A^2Ckg%XH6iuQl]tg1Nj+iF{k]f ! kߺ̦.;@z+fOθ,k,O kMF _{{>)q#yXypzIafZq66)lTe OqMR Vk6}o6Ϗ|rY|8lræ`ꩆTtdΉKޑF Іu>u5;[S<2#^N4W?Od:4<:p @hzmJ/IKΰ3NtG~OWJGE,8sU^XeWLf_*TzX伌e(T7vƢє22knMڍ+tȝ#hûkBm^F#61ζ_yz7\*|F?8(3Ha`hoYEJUv_8 aLjFbXɡkpʇwwfEP2PyD&7_Qg "$3|MIKIk)˅/Q> [)WMK@wM54ˀu\cPHK 88_9"wőcԚ f!; TXU:D$&c/("gj> },,B04TIrDs|HW񺸻:;o%-U!Bv*w@);؍3lDc+]Q ;q CPЇ &h? zΔ47)UM>?4ǝx()y .7Tq[?JIvbTqMƇRU:ʼn*/1&6vJj`Ȕ:A +M.]#*ZzW.H sfեz8DS͆u5ݙ\|I`ߍ$D Bw?>l, Ay%j f'?V.SFcQˍ'q6QWbD7;>L_>rƢm$.VVF] 5=F9)39/pf %Cά+W- n8}R8Uu ,kNV ²&`ay0Q8fK<脕uuP3 ʼnq'Ϳ&ѐbLXGZsGr )l I=fD 3=hnAI_Ou|1vq4y#b:]0hpgUUpՏtuL^ĎZ&  EJkDI}MBmrYb%ġʓ5n Hp?B\̯mQW[6^Hyex&4n@q2 `KI)v|mh{XGCD45iBLShNXLUiJtoߎ4gpgzpRk$0+M0g>Pؿ]1`gA5BX# "qq\Jk8F jΌofBV(o(dkA!%0^jeVY 5 8ې0Fup闝ﳳ[gTn/EZPY򾒹^Jh)5~ ^h\"o5\e(5l.avj6B!FF oP΂T@7]>~Ы,,]iR`ԛ*Hhw%' Zr \hmHYTǥ>)'H ߮md"_d\N T(F!"NJ0ؐԵp"/_FxoWy0 `E>^W.qy4"O Rg KZݪljZM#$D(v!DDNQ AJhBhl֒P}!qؖ:ZZ:wޞ#f}n%VTU?r Λ{c9o֯2r?7ni-K')$[d+*~n"y^)L` ?jE sdW |by12KlE8y&o0 /)<(AL& F:~ŅE{ms?߉Gv֝ j/ nhmGN/b!@ۿ}:! m$3ݧ[܉lK('&a9_&&I$8~pқtDwSf̪/J"[3VP |\i x )*ư3)Yr8] &xSRuy@R/sM/ĮHg͟CJyHJƓ`a$Lr} ̰kiDZX wl3Z5>~ :{v6"{׶N1EȋqLh-̏orc WnPIT :vtf\BɅJ$.|6ELz~aذ5TeF8Z5jYOǜ{#- 9o5@QK~И 2F[ĩ]BfVlW/1s>}Y-߈|GY 6b-ـsެ^]5߂ASR~ 1y 0:bcW!ѣper#PAF٘H2PE~ԜpҟLe,6ZGC?tq0»QR->DSäBqAJjS_sGF RYI̋5sXC&edi ^TdywmvZ#Ӱ1@~6QOA kٖXZ-qv{*n_ճe7V]kͮ؝ב=߮Эo,e:z?!\F>7MDΩ]*;(,nB)D?ͲE\W8yߺI#ih@$Mg*ϏDyŞz{ŵyDSy 4`iG]!n؜{V.[+ý|,@Qݶ+<럺<OK@n"Bn]u/5ɉ!i{t]pb0 Lҙ=䔫! O Ht T==WxfTJT@줏ab s I?)ZύfZ\kD I{4'[4{ *\Q{^" &қ$01+dYA t`d$HuyR8 b풷L*՟Rg(`Y @A=|xJ#QV@T`E2{p{U8فO9ذ("\G9Myr"dh(opVi>9I'N;Xm_@2> f"R? +z .<)b͢hS>BM كh7*;6k_fRkp$p!8땢#JbhڕD?^7;>b6<avm+'[Y.+%0$`z5j1|P_ !'^iSm:M?}>:YPܳ~3uOWF l0UX]0"MpcSXQ+B˩God~*ք^LyRg3w[ nMSv/Hݻ..D*pٙ6 pH(.0 o,Oo0G",xIҩͧnjp峔2Nw,XqO*w=e]6 H LIu o)N7@$g'#rŪC82q|E,V4;f f||[٘qc~Bn+v6WLJzvf6┫{"=ziRfȷM;yp=\:N#gIT\NtZ䧙t3$rJfS"w@ZҤ_ D}{,IĚX %p<|OYeW((3YT:j%AX127jzv:"-\&˰\  뾴Y,|U1+s' #LkKVK%xDZ{\'a3'eoQJdvӔ" H([0`Z.ڼ:\# i@˥dQ\;HThkQ`r rD7mVuK=V> >Pt -"gà#%u`h٬"k"<'V8)>8"/*s?1fAJDz@)ȔDpL[.^Gc?w4ርS5ɭ |C#;}z!nM;l |&q,i0K2<M I}*Isop9b]G;Kڐܟ[zMx„Qg3f:!jg}SKfƈ8PDfG:vbq^X#ܧ-=C'tdX} BlgO⭺QayunpvdQ;.58\I3#nRB{^,r)pcxiGR 틶wx~RXJmҮ7B;$ ;*Boߏj X'AuשїzkՈ +\O0g!."XtԖWc.ox} ڠ`TK1sRPԳ8 VjCYNf˵ | &$ BBstpS^>JB'3{rtKtTd"ELwvX[g=?9C[ө"S36"{&<2H}kaAЯ,cXݳչg!EE4,WNĒEyz"8IԒ-ּ& ~McQٖ rX,Z66 !Tw)َ-fnҕZYǏCFO] FwRYʴF<7+`9Y @b-}o5igh #+:|g$~Ċ•+hOV-$/ s\d-<>XA/2 a,xs_!GJC̊pfusK 1q6 +;Y!*$Ox;V+ΑCz@ӄե h T>Maj.yq$rV6{hKhrɄ ܅oeϟ&n`f\SSqwe?]-ҧ%D-ht qJ\zc,ԩ tUhoNݿix+N~26/*-TNb?_oWx&8., a@/8dDޣعR@aԁ Z~h yJ̳>uip1;k.k&ׅhJ;ӯ z #j&W+)Zp>#!,"ؾ9yܷe(279LfQԇBX-;|Yw2lRN#q Q'}{٤kޒxGj2N| &|8J鵤Z3a ⎏xdZ˽G{̵@wm:vĞ\x,$$~q}| 9>[.scχeÏmkK^eIyiBdXEUjyxH$(4@S+XirNkl 5//!ئnQL G,)v{y%cjWý/-_"l?OeK(WJ"jL{'vs3Mk'm֭CeJ6T||\L4X.ŸTᠴQ(Dݯu6[gN@+ۻ ^F!'g]R ##}~/F;0J<4ܾi dWj_JM)lkvndQΰu ƧSWV%L]OߠSpuͫԫ$9 jIwice΃jd,x44=ISPD^[©Oތ'aA0ns"LUR:Hr?xVV+x4ٌ)pΊpYN`@hp;lteZV| yФV VkhD߆*E\T%ۚ\!а/5NxD*\W#Ѐ $Y1Ђ xB C3sjRo&Z6QDGezyXi,*pJGEM#yB_AeYjp0ºr|uzwWf06Ɓ>7M7ߌ~b 9_p/0T eh3\Lyqh'$u[BQ+ jBBtwnH~%Zx鿘B˧[tIX_sZ:TS_Ht\kId6[zSQ^v>RwX;(p-'ŵ[vM2dC˝ԱZ th k,nMz 0C/5}NJXF72B\K,7+ Gz"YiCMP 4YO&J%S8EV`` 3S5b0~{}~+ cLOއ1M/"'6ĸt*L .i?W\M9M͛+[6>S>{K!D >vL[񅥘oو%o"Ֆ&@aTh" 6'yZLCwCA,&Yl-hp#R~ =?oїY#v(2g #MV*vw8H8[9 $iB&Ar)HB\￿q59 i ƦM"VsaRp\Ф@6-AN|K nRu|W }LL&,>w>.WIĎ!>0fd;%mq'T/='\fnzמMS+9CŕfvH}"W7/`#FIGK0QmLL&RA@:"?/ aW?2.IwoXS~ 6vŪp.9S ~Mz4`Ceo$0ԝn"tv2Iy)bJ ?LG,\+)b0$w*Y1-MjM)j}/spѮسN^a5Hդ` C.5H ,rTbnp~ppQqwCԶ0䦇`;j]xO1yql=^ĬӉzߝU?T'*LUq0c=O^g&L4Y;":rEr#U.#@'n'y"*&J^%ƒYP+CRaU'an~Æ֎AIi> "GJRPu_ yoQk BMFaU9"+ݸP'&XƗ%o%NЕxuAl0o4=#D-Ve͒>{6+yӎd v9( ov@f*5y.m:'g%= rEXW&͚ v}wC)m~]ZKR5cʁsDȇ0N Zޠ^%4^]g(!?r&>C\p.Vg <6^@^L.cpܐ;U}噂ǟUbr!G`}Z( ضT.Ov.I%<|zzJRH3γi8mƕ[xL,"ҳ6@9%ЖP9M]C&2UJMf#L0i}: &kZLh^{$.}NqIf!Tީil{z$ @@eeg|v2l3OI&$/X]>)_ a""I"}`rQg`-x͟.r*`m H+JqWïEFu> Zڸ1.-߬4L,GܗyH&:;,WޅgH'H~4jl_4@Mh™x=B{9b87So (`حDa;1_H[:h+/Ţ5%J&aR4r+fe431ZSε%}AV)5aQnO-OYIb|n}(kxz2 `W $|?1Ѡ%kpqt8Y#58Y,_G39(BVG!b~~/;EANsIN[40L#,) 3:n;gzQLD[sR2t&U$>sMHѕY8l諹{%v"oC1q,Wiu2>o")%HچKr4^TgҌ:g2@XM+ Fӂ4\BkYQCw0kX=d2\ji,O/|E"Gך`ݕʟ(8|Q8b{zNX+%BXBPUuSUd,Jr$L*Gje~q@3%NBz B'Jzjr'K =%N*1E?߃ `-~F~GT.4eʀژǞ4t(Χ@xtUkBs)#ISSǴW0gCIldPkܞYg%`2aɓվX&A7Ӳ|5T(A-JEz>~a<씱:-TTSџm6k)],G1|>-DE|&Mms C{5 >Sgy"=y;'g2 ^b? qbp. |1ߣfmBOYRE !/^$$; Yl|Is-"I7=2};z߬ @&\PkAxPYtӁЌ.#|0t uJIki;例J;]HȸAS"`|hbnre)2,c ɡ7v/c-_57|<1X.Ʀ'K}Z1})eauU˦FI`*MS_4\8& 'Zs sʅ֞t}FXDR$Ý>8fT H fZL y~zȍ6A-d&*`Ӱpojve%oQO2ZUJd4-v靲Lm"1ͮjvQ%} fSb' TbqO n+07Ϸ C!i,sAXC`k3sނjS0Vkrw` lF+?'1vِ`ikV7*ɒ>طiKqbF@ ݴAKb8^2vk{9{,l8Z s8T^+Pg$˴vI./^i P{7x}%=, ;UUv:M=1{BhP7l֢j_\Nj,g ysa-fK=U*BjXKJxDSL"~ux*ix#?MRGFՔ]ygtxB.!P8&}.W8_,:455 JO+ny͘?rBD7yl#U47 .}q L kj Zٽ6ρCSXӖiSWkb/EQBLKa# GX2ywJ6qv}7kX[\O.Sz*bCZhՃeq`[ݔ3HF@H㉹4~ߚ6,g7d6S}Jňsy)Ԁ:Z9 7]?FILRv ?ojXzBR6-hr]mN;5/őLbH];dDIG5+Ɍ/;NThbvQS XtEUEV%qK!)o{%GLtTY [BE*R ܣ` Sj$ט z>s#c.zȪ@i .x3P.c%+lF4KJ TX;R}I4 B퀓U[A8? g˯$}dj|?#1tkQ~Ǧdoz'@mIn Sų1ێKYA+ $Mm<ƈR؛'tkw+F>$8J 1 bZXJǦK>􂑓rz-|0^˩:$CSOo[!{;$,$mhJJCz/=n])p y8M ʊon3VND`p`M,TjHdJ5o IgR.`Sg6Jظj[0H|/,1n0PUNُ퉕;o КO}͟G>KTI׃L=@OJg%C˭0&W޴惉p t*ȿ,UR+.K4IZN@Ss"ؾ8sם2M}K^9@5{c.7%F,jHz4ByJƀR@b/5ܒAb%]_: ju϶ʈAGBLf7jx'bT{3a /݅乥rUr)n,S!;n+`D gznOae26hh|YGK6c5a/:rHB"|}=(kXUHu fRJkDh;Om.@d? 4a^r׃<}BZlPQ޴?.]>Uӂ&, jAK0ňj  BRZnyBQbرVWҬ,"\k\y;B`iBV8BN DzOPb4H*?[:N [nQcbRj&<lvk !i4 LE4SIFMoqP&sӭS6`Eh;)0& 0'v"Gg2!ʑ)Fuqb*cM(F(PQIw7U\EK=Py..U:eRxW 3Rk~֜_ߣa[99wv~ՁaXt͕- O#7lIN]E $N+ 6e !wLv-]]`j.@`1$|"Q1YfU@JA,zB‚{ś@a"W3b;Ʃ<)u݈gL5{Ifa쮹4yOK6cU܏_UWG28Ū>!BmxJVBeiƜ/yxE<U菣Cd*D"FV#ھAXqE]s<Ės!n3(R—Z(+&}N|_ Uc-Zp"ґeUgT*W׻ྥ GQ`[憛 nL7հ{l,mι2r[v*@m/Yĩcg .(E}\2 Œp Fa@nZF18 PԌЪC͓M= YN<_#1+W%Sr5}u(z;:?zt}3jP95hݞ`#ISySpZi7jjt5[Pu55d<#z TT6k:!)0S'pk~٭esf9~n@*|,o^$ДVE:M.W"IG*aX8t^_ォNы)1B/*iOG|a3l,Hm8c*\==ic]2>tTUJ( n6d3W!TWzh\wNV%O4ti -^34`<%^r"Qٲx0yp.eaPi ixBXYt^ pcщT޲2КPi_y_z[eg3&<,28 +fLD]fOם w(`Nnd"b@6_-(徻Cj 5pSX԰{Ii<,<.˽.̝6 (gvtR\YvD pV7B5j8=?DP'DK%xxvc9嶰ހ\siRɦii5e΢5 vasy0)D[UBcnOiݿr(ZT{\C`cèX\6M'H8 M/c=53yDuwĩ-ɒZx⩆-fu:.ptK%{ Cpط#og@3[b ~DT>n2L.Bҷq/\gLw&·R\%{[ZMDbgN*}w/~v[$ [3x_:QZ/3' á$Lw_nZ c߉qMnj 4Vh65M2!X&`Z*{ba 0O =Q:4%5@'ܦO {1Bn|֤8.5b6 R~ v} E Q`)1|ޝ$mDM3pG4ȗIC%FL\ 3)jm KbJ:xJ%=NpF%L"c48' |'z([JϺ.f%x>jnShQo'9plWMًDŽy]DnHv7"$\rx]@շ1OE{f+j*8To4֕SOifcת)r^cAջ\FSR$l?~1Q㪪qv"nvtpiKq)yd~OoP< j3 %){h|1 D1xT@7C_A(o?topϗs~cT  񟾯Oh&vN"-O"Ƒ/ & 9^Z񏸮M,-B;G$M¿r5=^b 7r3jӶVFwVbQFoBMLi&.T{GB`^6\ON4 .iR Ѣ73؟0aBK?(8A)_6h'3d ;c IsiDF Ӵ aGњSL#wX3B+ iXJvgE{( x#} qS`6ɝk&nNFnb\~1ibxT?9ԆD5/Sc oaJ'YPsK2_ %,z'HSfmTy^RsXqaX}SM$Gy]L Ԕ p".vG>n_<-~vrBO >-1IyPwH=!|3|I"2<D+}{a3g=*'ZdbvPT+UƥuͲvPt*qzˠ~?$M!$c]GF2+Ay]-TPػES>/[H9_-wNO e+/&iX]J} Ζbt_, m.:]4 ץ?t۶X1Dʖ2]eJ)-iR.lw?f/z $8(@6*cI zԊ՗ru/c=G*S'! *\86PmvIc.FNeHVJKt-eW7&YYj r1lQPoł'c&CvEE*(WՇF5 !0mlB|}M$!Y\o80-'d6O:a'D(B7ap[vSpq U,HdV)NGj^\BYV:,#Ȑql*u'vĄ*r3v:XvB}n6[DX$Qݹǽ"w?qD! Ao߭'0XYQto˹][_(=>I50C7S@*;-$[fT%}as,b9ɓEq3vnUև# 4+[JAT1r2v0y4.q6|YPDȝ%GBqV@i0K#a09EՠT}FGMlFwi?PU(7GR@ F}M+}hFhIW3.M^ʦ,f*zgΧ꘾Xx%r7_n 98H"=Ml!f)#Q^;}.Uy0] %Qpx !)=Ub{ҷ8!^۾+(ʋrwo˭p I1#U?mA"\ÉΙk(4A2Ԡ@kuZ\2y"_joַC|5OE\"˛Uk%!Tč-T7tF5EhJv1;S4&+wWvn| Ϸdl IY)R2qSm=hP 9T "jX@M~4DT;CdZtoO\zxͮUZZٙ^0RO{/Pdgt"MMj 3`SYU;ȉ vāPANl8K/!2Eڎnen0TPK~]\&AKɥ[^&aŤ֠B$?@ʾ b [w'<V5HpY91&u9o/+l5"s\XU-9LM#` 0 LXp#M PҳbZ0˙E #Uw<N>X;$ϟvIR hۙ`sAoW!n_ r[əWSlZ~3I_l/~Uj0b"-Ż  2w;?lm8ӵ/`; 朿JGv.WmO:xDY ]蝲a:5{xC٥>s˶O+JM|]%!Y8 êC|j1o6XoC$A/I~N99<=dqjnPQFg2Ǣ >X4u92=b!͹nGΌS"0\pM꺋: AF>fxtyrN!Ji;h28~|Q!ll\m jepmCM6;i )i2!8ҳ lb7}5om L)jΫRH.G%  ļU!#%"W(LDifz.[ #[vvl6jncE[{4i(Qnu[&B8Oꡠܴ !dt!zͻQ&ֶ;f=h* N| Z25;lPU.7 <:U@F*e8<ȮW ?Kl( Vv},F'&8ŚD[дS~HƵRj_eW4ZE5acŚ  f̋2(rtWXg*;Q!eF 6_E%<+ӂ`y^ ̻pxb-ch[E;0R# ?DANnœIo9Yas/ )|&~D@"8-u,4Q G!'l?V3#vj{YS;Ӥc A+աYlW.o=^q7M.OézVDa})- gOmWt$"gjN,`3?G៴*H1 bQ&yS ^ 2~Ax9p1k?`IW0+U[z/wŭa@Hq$ߧ#NRy:PM;X5Dmu݁k&xi߯*% CZNӎ)ph5k,p[_L)JBR>F{?DS)jJ5_C}PNw!`L*Ld1X7`kBoN(iP[BnFKW^ V~; e5x6}S56 ۵5+L6E#>: H DECL#̮«%@[jo‚-1ϲ6lb/%H#lYb@[Zk]^Dr^F|=r1>bץ9Pk{L:&@dY}z 5xzT6+*X.XCR~0uCZVG}lT7^}vTeV,gGB5ؚa%N2+xt Waag/,J,ۍL^7Y.9rIc^܅5 NY"rzP|֔6tJ4T8 Ggs5U‰؍Z?Ykm"sW%G"i D`)964m8퇮csˁ⃀mtIbp7+fpR{x.'w+.Xsn*w|!8\f#!?1҇N<~EF`%m-*话;pUc7/;-T3J*X;ewXJjkH[ޫ+7Jj#3?0@1x-ח~7=]lf8VMՓ%E#˹ /ӿ`3ǫlS^88XL#2"+%c vwkku ͘w}d$ڧA:jjH}g;{6wWRك(np`+AM=]"֡B>R d]=_ѠőuV@bV w&N#o@o=~(Կ==㗐O|RAwk3.Cs)U'S@b݀H$ +=S[ZW wa}ǡq<2͸8ȈL9Wp6T528G H\ܧ1?b:`PhKR1ͮ\9$>8DzeFk{3a0Ӯun hA*~o2ULţBdsdČT$6m3Q!CPs:Hm tGH;Ès&ϿgkJ pF6Uy WKVNPQ26UvH4[ ty ^#.Pt\0bwH; |%) P"0@ χ+*5ӎ|ڼDw. ~7HJwj'M|l+Rh\84%y22sL/ ڈ&#ܙY[s])o[ { ;zoT7rA&I\&Lv6ȋ6ό2T Ȣ ΩJm?6ʯA닮.3ޞZCdXԓ͋΅@&6 H4]APK\W..7bpUPQSjQ2r3V +dUM(; 4*cPK/ &PwP1X}Hp|cOn+/9Щ7Ô}Rʜj`dυsC?,4Dtvd=KB~\)' fJa&DZ؟ Gt0Nt9'lSCͷ jrlDL`ao>M;v֑iE@M0/r+]{S^~b#Ht7$ID"i/G"uq(LDjV[$V85ZW̄$i:Mq,4b@C(|=֠`&4a^@806v&`6%=E}vQ'#;<Ĵ #C`,͸ND HD yie)*{5Q] 4Q8݁b1Dܟ`cwʞ\o: h{nZKZ(#+FET-AMB *F}^A-c3p>yszUso0~KUe';di &DM]nY&,iH\ 6(C񭰩,vBIiŨUYy({fD>7.oi_@ay 5;Ud&#i-_o}g~WDL\ bTWR,4H4㡂#!Pdfopxb !H 1^TD^| a:YN<8=-d'4wuP;qqU fhl!\=(uS2?j37Dvzx-iko {z ƒ@U DfٕT+땯E2[̮ ]ϩ7|y_y kTE;w{#D vE? g5zZk4(yg~OKMR_%hI7e8cw|5#'.䷝cP)|av;5jShNإ"n,C4\'P4v241hjIDf ߡw/dчeE p6}*nT7Q.R5;"W7t ۺlڂ{!ܷ͏Zbm Ͼ< D n!!jV/=%hS? x`UGlwy?3bɇj<4[u7CGJN EԱ|ua:4fz7)AR 9 L%+vJTzK\n/n3|]h6"|^Uz!'i{EMO'reVb|(8ٿ5{]@eo4kS_j(MyjdbTf+uX!vaD7Np.!e(ܒ`r2uD XNyBy|RR! _U.8a|)]|~ԊSt*&LOrti&ɜn/fc`%SJ{Lq1y ޣ(Vs!9nXr gC$>CJ~ɹt LCs.˺1Ks4`|SoE F[7qM:gywxO6x_|E*ACp Nj k.DXZ'Բl9:.nlPBmllK=/K e^xBT k Fw*V5ݫPljC,SqR?Fmt"z|&61M7&ei8bY 'f9EalQ`&W>;X'4kWʅ]{lu٥JB6˘s3AK1dLw&,edUhݑ }|k~PT4il ;Y{U[>3 *`r׋g Vgw%N̜^"ʐXAyq sp\ŕbO>s`lt,NwUA'MGC[.Y5 v;]c8=8V8ykY/S!,6"3:B!{>y+^?[%lZL&/=BN`s짐gl'EyCj6{cbC G& ?KW w`w`sјnq)V j4oKiz9/ӱj19y8?tw;/|iY- vԣSpF}Fa$~SIkdIOF钆/>,>OZZ5v #)`s1oA/<'õdep7ߛc[-p,T&RPk' Ѱf46~ͺ[e £t9ƽŕqR[k( * X.Qj,fO@JOoLv"Ѕf(v9b0AHT;]kը:x쒃dɹW[}cnkonAtim P#Ӄbb,0vx7$',$Z cCq0H֌#c:R2zW*;SkxzO<8~ȽbASyl_{_`dI.'*2%i&4-_O yo˒rXqV69#LLσ-xF4zMuI:O\ = mJ\/Qy`B\!ŸW)2"7@:$g6'x15wŊ+,&LeyAJ<4:FTXz=Tvkvb]L~UEye:Hxw8>ўx2Fr"\ Rs=/UHrOR b FՉ7+lV!:4I]?ꛜfYG((@*ś|L;_ Igأk&=e]]mȒq9N0CaHN l`']MDʻ s$W6^gKA**Jih` #1ީ/.%M{5#E-\{#+.gtN@V>G` ~'xtz67A~IO ",b8<P`\ ʹ\Rt0\6#'L1Mx:g-`~N3T$*E +6i *Y})&rk:7S50yfz@RC܉gPm_HC5CeKRqr)ºϻϋU$xaAu2ӗ0-K?ϕ]utQ:?I"aVF EWA vWX& #J7Y/S>y6cјj? p5IE:,:‡B<>nȵX&Q9s!d>=r"ihP8pme! fQCYveks}jNA :k94%aNo#BY39OkN9P?8pr̚X=d9&L$L@ea5־{mZcqNYzsjj\%3,$dۖig(߇4g4<ⲞxaΡ[;@ry|܌AxjHҪ/bH)>0s[4}&o`_ADMbkAzA'"Se/?*G-,{ujt-yx,v 0 f΄#T\G*jvlKi L~U{skyג,XbU;5_m$+0YsQrmak*hJ4H!r2,ீ`N?/fAK]k7FGy"5hߵIUBv݌wߠa0. *y"]1ֆAҳɫ\L4q5@/X曘UIV1GYto8$:2{~ΖAV5ՅnOTHi;+?k7%Uy16,ыo 'KD[=@T뽎 a֔ sߠ GT .[5dZK|6pP_LN ;5?.&_=qI;0@=|RO|(Nط qڎQl_(yHȲMPGE#yp^.ԓe]޴8戅[]F-|XE)8E0ϊ扥4]-yiHX(XE )[zla$1.j0'zO{?WD>|N^*Czs jV7KZ(58 Z!,sC$Rj̾e%|SFyX!4X@Lt&Vx1GZF}I!b\٪E#ɏq1LL^$9iY!88"_4jZo YkFu&3Ml12.!. !) Ԡ:\-1zw\Fbv9 ? ,MR^ʎIkn3\L:y MJvL7 |gDHXt.H9JLj?fK2kG(uP;ݬs2YX}%[(s\~f]Rxb~zJo)# TR?O[%U}}IE|nv@( psGMo a0vi)RYC~Rq#vCXO"=Թ֯"$y%;m懠A!A38s"5)9 t/u7Zt2qtSNqLKv6jdV>C@7Mo8WpWSg+r:PN@56$k o%e0TַаƹB)ƒv*l[+v)$Zf4@K4퓽l9 ebZXB6k \JS4M40`|b,xDZU^g,-bcIVC&3nRc47kUy>yvZ.pxAme1PN|!:faSW߶@Q>ETK.i\?4y9V LT#,n{TR6XFJY!mĘaƮ39wEWk=h=iўuA9m9̸7Y%]Aw(? (jrqp(C^L3ϝuaOb~G6PdltL9k._"J՚_JrʶG^Nf5J>&eAڠQiѮ߅c렆"LQ[7뫚h1*Ж9*c҇AX)^Q5F мb ś/31 ޔ.e"TMκuIL樳ym(j#>9]w`go)bVlHυ}?%ģ3"k=},.^aZSk0o,sQ?Hk$§|Q?MĮC [%)ӑ5.Z z0i? ÜbG,#.u1_ _ u ^n,\avv]v:6S5aFO(lcu;q"hp&~Ze]0* ·ڈT)R\Iݼmj#X{##PAxrSF[WCqE-%< Fцx'i;3ř!~ OUs$ojD7O\3xPIik) Tdo[!oKfN'߇@}?ZgSױ<3pۚRzRRBzbh3/YZDc˺6w dl]k/a 1i4xb峌ce+NͿ*l 2f` 坋^Lq؛Es`qGR><|ަNJ,OLHl bMjj xyx؇4pHγ4'E% GoBh K%9>Hbj O 2K"/i{Tm%z(58lA3Rg0lOn:(ND>.ѶhhO[f طH1֡to/;e/QC7B,V>sx5wWofS,o"C|4[*?ج28"ii<X@s!N,xd(;Sc L$dyuKUHѢ!z)ת_oٴ'ϗ;c&L9`} 2qb[kG:e᳑z&rp`S47˽s:pܻHeʶ X74==Ŵ]rB<~PaSLTH/()tMM_sږɸAj\)D#up^vED$zR-b54UR-InbUP j_o*| ·ן>^nⴡ98ΊW'!َ4=-@^>xİMkAF}߼T#Yv拶ip͸5U˲.7qI:5jq#a.5L}7*~LBf<)`lh0cj| HCQS:vNBЬOyrqZ6}Y)A+G^t/0lԋ>{pSy0;|RmD3\w6 ojMY2F=eX7闵MwSpzח]3a^ztDS:/Vɷ04&ïfe<50/VBk>x y Ĭ_&07ᐻ#y鷽=늹%zJքXq@.,Sv1^k)p%ak&dN%CY[) ~׶п7̘.Nɧv9<)Ҩ%0 L_%#0֔&yБ94"Hk=(X?Be'yYBW) ^'X&/^fxĝM1䬐 (JGêVݣ]H頰 MG`n|7ޯ٥!-[ BEc(g<ͨO c4gO"oSV)'PՋ }9`Jdb훉l${Se韱 ZM \nN}yzH-wR؄rz+h6uaM"w;2˸'`oE[ZBq!S>1NJ@}P }R/v]I9 յ&r, ~[Q6;fW9.''dG&mɹӘs:IUAA3TRP-9ec!V\gG@Do@7}cȖupB=R6X`r^aaǟ|4GFnZV@}J/,U𷶳=E\p=B7 sM]|b;`% òhQvˉnD[(G-K&OȱiA*Y} _^rdIr5)0髿 NV\2RJ_+mZwOΣF )د`+B671zvFc:F<<'/`.01T:$]V` bhSLt[}m.dŚ)uGj|)nLv kܐm29ќ ؁"MIȆ#,{bйK͉iBvkNޟ@4e=|7)!dpKC@r0Nk:-hCֽtzpj#o,E !*"IGD"ҿw2ROR\h-qtq}h4!6oGY,-$Jl{rV glT) 5+JG˭ zA"ȱ nq@f7i&LaoGXUm.Yf4-)*auu,h6>uƈId8-%/Iql'!f<*:XK!\2E WK}Ogc )JtCP`j~]sI`jעM}yhq?(|ҪzSk ̑{w;?h;=`+&VǼdip{)Wj%]~wj>vV (5Ee({a +5X#n7 >BKU3P P kH>2=9'np_THw,P* f%&٥e@Ow@,oMlBK k X*Ob$Qa'xѭ{c֯(-`ֹp;xAUdUBHioh*ԑV;MBnqݩ੺Ys=,*dyY-$29 }_W b,k#ȈC Ĥdz,i%cwkeRaAqs-njϬ lϺfBao䚘-K6OEZ:ąD "_{ݰ@\mG}D,KY,W?'L3YQ+>+| lp%)L}@<Ʋ17} a#.ekMޡ-b/p%e巋?sDP|c'L5rW>/>@1pfz!8Q )U_YI.!OW41K<{*e16ʗFc;L'ztgL}2> C@#C3nW0ӱSRmCM5>.FZˢna/I X?N.rU)n (!st T;\p\[ G)"6p҉˟w >g؝6\I>,xP)dVwPb~2-ժc@ ,'DdOIp;x5Uo.v>|PiJC$X[m6cN{Sr%9y r%M;Q=X:a]=}7=Nuu" K@NHM7eͦ[NFR4 zgt[mzLYcp1M*mG6VcQN U#ĚރYZ |^15A1ti3/~c>r3OiµVYyi6.OXerc6I7316 hY,+kW,E* 0k2B3 _u LjVW:سJsp5qh8 WZA5NfKo0&`I?" @ ˹ ;.y2=\Ff#Nޯbvy"cĪ .p:?2XoI0yڔP]c,'o ǐg/FH5288+:l*J#B谖3rDpMQ{_زu[K ¤ TK?y.xygmr"Txb>-VchNyºj4r$ _2g+>z0=:!i1ROn-c?x>/IFJKa)Cŵ3iM7my4՝!U3V '}1ci +e*1X/xw|wܥApiXI 9Hr~í"/ɭ.̴ԝW"n 6켔Y*Kr{Tk -1Wt#s"4`gt ᬮn apmxAnR+Xxcxw1s3$_?oqAfQP}s{FiԀwKNSM)Ȏr|A锏#6Za(+}L)u|''E#nϝYɖ .$1ʮC3 O%w4}S>h3qj4p Ew*cJ|i R?i8*Qrux'DL=Ͷ& b6Ґ֮DV|SX29_g}q{mQ/"G?70 jPP#Qɐ~Z!VqAU!'ͥBhY>n`2{GgY~PdԸO/l;\$mYLOYcOMU= f1`6ڱ a[P3Fz[F2ۑlpD8L=\$Ϭz81yZ#>aXM[2KJ=xp j9n)tC75&*v*3ݡ}K䜥j܊KsAR #ϛin˟{w6ҳ-Q@߉8Q&$W8|! ϣ_<_qp_]u61Q.Mݚuϡ 7gBhF.ՉB[3vM .ysxVWWţ˷p8@jAeG+Ud8mCTr^ !.?H{J?I,6>c}`XfԖ< C;ɧXm` XReHnR~3F^R f/Vt{\ۺ#rb7X]а ^Ժ;[jpH>KnKE*7% 4)D2a*K䲞c)] =~,LA8\5;8tD,r뗗5gT2VD)L% PO0 T&|3z]9X$ъJc-kS6V8 fk @g_sqJ6IHvQMz-7a2My=Fzsg eںi="ɸ߱C (˻rksҖP/Q; iYESDsԤB+:R)͋23vҶKdJ4)-n1;eH \tSR@4G#Ga$ϻ5LY`6|'Q"Џn؆]i<#`mVEj^;HJ|fL='8',=Cp-Ce^?[-urO:ՁH 6R[׬ `᏷kAݘ@#+Y>Cljb@xj2oyB*8JavS=y:nw 13֡[v>Š$]} $҉=igbΚ)7*cgvh~|~:]",u(GZi>خIbP|si=8aws`{ )tme#<\3_BTy~a߷G{!9rS f7Cw'kqqMR_Q{1 W!6V![> uqIYcU>BH^]c7dP0 ^;]<:zۚʏ /[y`vnG^/lv&j>w5W. Sy"$=tS[xMu*<t#ߖwDP~wgWV 7F'ABȕ|̱2fD]cu+ʄLpk7laX5^/1ǡ[ܟ04Ux^)1 ьaiۿ:fFֶT{slėֺŧ́ќ@h6tq'' ,W.\ag _^|3}F-G٬iiȽTk6(hI^Cz(7y_t?ryxi~Q+Xi)YjtV.+lO+x&ir\Ns˒IPi͆|m%Ϟ<۴ DB]ˆV-ՁU^> Yf~&C@2xޡ?ް?74iHFqC9XXǐ`c b&v@ D5.[2];:o|Y9h@QЃ~](^O 89}yFokq άZx'~Q/忦7(xe75M`=%#HqS }X察J& XçhF1 [ zKܝvDv5"4kr)/8}>t '>s#=JdFˮ w@^@NJꮮJ#&նEZ(h=gC'jWԾyt~Qe* Y׿]gn')+%[l#k9 >qk7M5XD $tdqQAJ԰8X q7{:n)fA'¹1GCt}0|{ilᱴ:[4XݹzG SFĖ.{ *2 y L }v`lm⥄5oĝ/X:dTzdpu+8iFNVB=Q¢Vь U_$;+ȔDhZ9#|/E]Mua/f9ݭ"9g(o`Xn6t̎PKTNmgQ,ty95 Y!UےsY^'90ʸxC ĂK9LUNwK-BZeH)fbHyo֦|=^p {\P7ړaSz5!";ģɆ\24Z .HB4 {~Jzw[{ĝzK0]m7(|YEPn*ŷϮe'ŏo/BA9ih߈^.Ry h4秫{3Jt'+F v3dsvzOOtcSW2lU|o/e @37asC \螀Z[GtP2LQRN>3BkX9[E\g)mхPd;d\̅-.lHes7#Z\%WIHxU_\Vh9dB1nB"mf"1lDr}A%7ۄ}FoӦHrڱHAm7dғ/ZEe{uG7Cֳ~ⵗ4_ɉtς~q:?u$~׍*.9& `~&u%-BbJLsJŲPLcde! tԡdXQt͞~f>o1a93nֶQ UN/^bڲ{I1=HJRnu,auJ[֑ Ny۵`>ju"Yп҉@b,Ɉ;&pEmpPi=,D k@ŔgͬFd'2]?7IօjihSWxq`{9tF{ /#!ޔݭa5Ȋ$oĥb=m+;`U~L`t˜, xB^iw x"H$HwZ뵬"-:׎j; nʏVXXp=1A_`C0\qAk|7{c5eۖ_ >rVNxEЊϷ]7dT&ƫ§l {B 2}殔6\P41vu'>e>W#=/h?t˽j #:"u6]e4F#o L(.v !NNq)?n6&ľpPػQ A9s7F鹑Rv5Kzr!*j70Q<ڦOBCBIa):!8q1 :BOm1/@WaM:='u{T'J>#;ɉDD$X=zģ/o vj:C]H ߟ"%P?BGU1r30,l٦Mc\Ƞe{#t3b fٵ+R#q(ϋt2ٙξMS6Qͪ?̆ ~/@a`Q@mhy9 G[jȧ2a3یlOw b7n *%vRl (}iz~+3V{n̰`|Ә> ݴAlY\vp+3&>z4q[^`Qo8̤MG \H;UCq96%ZhtpRU0H?HT1`&~`2k9Vj"&KGt>^|Tj4c_:Z]ipBKD<8 ^Ƕ*)S"y3&c3ΨXԼK釦@xUgRdOmdcblOFQ<9;Hm-gvuw?7kNR)߹#ҳUNASkLeSq`3q[*˿zS-ݸ3]9.KZ~Ӂ#/Xy/^=sQlUˬֵ~%r12<؎J}Be= f eYª,){,;PYr+ޯ# zQq:(׻mtDsr7KMm`4Y?WwQNs;<4ֺ4K#iIs%&hkm`b ;T?V2Y.<_ _(/t-xASU駒 k,k \+d<3E"8S({wo7Iօu_.92B-mT \\ZL!Rᅀ7TZ}2.qtiXH6=( ?/h<} W=^:0?F 2FcgS-PO(t՗exq 8-ʿ.$ј-;wRqba{@Cŝj'FmEMCGLma*Rp<a^|x$)&]L`U Nx.`}6!GͨB9(S z, `&J 5jCkє1.76`kz&r(X(Vᙥ+jv+|=૔[ݠ #S̪sMꆔ >{G%+SWK@4&dKոic WDg pUJ,7}`W7@>~uN5%@1N߭25b^;HF7 R832bk@ LzdjAW4<:'tAMtrJvu=B_߭ *kw˱gU4^- B<`u-Hr7&jd̠쿋{0ܱͤhc&00Ck ٖڵ!,ehj3G`ESjBHQ֪kfah\&#~[;c*0K.Jo1R= &|%c'@mt`L + Hs6.B+Di_!I?\nVWίu%~hB_&L[> , 슮s$E6;U QsWfe]"+ [}a4U["BGD޲wݠTB k#YJh@·K斚ǣ8BX]i\pUHs#yCŠ.O{b-)\]ܟ?aҀQ5:&:w@R՗&e UHJ`- 'XrAޛwi&i^P[X'J˨'ԍTW/l~ ;/T]AxѺ'V6>s<. |A8־̘`em̈ L2Ak@f;u%$t k,S2nɝ9c[cS;hr~:̮(6>k}V,Xֱny"#l)6˫PVCD\op$ؗ܉h%JC3/vb[-:ֵH*`v^֮E#m;#ANT53tv? (X#tOE* ζʡt8R^wjyR ^GPBwv|QT6PHhy7#(V0ԙ)4ԓJaT$ pxX&LF>j-3lpD NSh~c6m{bhkY#C uԔ%r^2-Z?s/3oiR}ōH)! U0m xQy q1ƈTJ^=?UY2HW}M,<<i_o%[(WddsIpC9XŠ1!)! T̵Z2/`?P:p9–jX3)-6FMh3qϛv!ȝ?X\e9%wK*Dt`0R#ښkW둲XQ-?f>Kv:[4l.  بqq:&c@H _FG"KmTCd]=3MqƐuFlaZiCL|(aNl2r=ʽWݪ/Q&jV@s@Tf}*9Wܯs+V0Y`ju#Ћ/&-[ oߔLK7S>΀HXw e̟$֧DIZv2T˝qSR_*,|gBSJc+Fb ͼ<%C@N3((w-'^ୀfnmYHD/Kj`tiգ*+c55F_{ #1$"RL0úCRu٨a&JS ĥ߳js(iA B\TK*:ۤ2 gӼ5tF ҁ@p sWS'^ā؇}\ $^=$8H,,[sWW_E:^n^4CsğL3 KgDGL#~]9%ֲ$pgqi"m ^񛣉F78C*u/ ^(7@aDuf&`szu7t X `:"yr#cy"uuuyb.μOA\?`sMߒA'8:af!M-_$C=:z?,.ntȎ x'g>XWnf<9O": ~D&u# Y¸P0-D wqVuzಅd7-(Q,jآ%Xm%|٪ɍu83@T.1g*v9~r⦅]L`.ʘD쮲ed*K~*>Bk4/eirlҮFw$ 7zKQpi*ϋӎF\7h<JEQʚfA?yhIN,<Е&tp %PWtCoqMtElูK!] f.tqü:p_zENH~iBV@k.(pRiXf}H:x_& R/ѵ ԜuK^RVDAA| ngIlZsO#h,XB"e8y^BQ/ʉ IJ? " ]]ʙy{Z#RǨRb);{ Ƅ5]4-ZV|%) GFw#s:";U,$N+̐WYkbe Rer:D*TCjbE {@EdzWGLur0slC [uTZbgbV|f,XyH{f`i-)up$,^)qX-RUY~%,"jz^;_8`ΑR{-7 aL ,x)2@fjznHѶ2^܂\pº^+f-!ج͠5Ӣh*EoSP!M T X{=u@MC5+\3qh6o(`2X!hWƞ#Ip5ۉ17ؚsi|_Y^TA+,ŃD 9ݝ!Vx[ <vj+-:"Lʻ1K}`bΜHawb8|9e};^;$ =hם\3/ľ:%gK (h)%$1bΊy J"g9`S7cHdҼ8m7PH1&zqJ78V¿k+U;-_[^WDq Mwl0=%9~V^d[L+ ?a[2WY뒇룥@sxf Nü@/]<)LQ8KDXMDXQ3 GW o vҒ[`)H~gbLL@m _XD-[ DDsa);MSCDf힩˷sxUf 19h"]߇貓vơ,y)jÐzRTVO``4)= ]ХZ9^( > ,QL:Ǭnh Iin>g`?l3ᑮ$gόsRu#uթTK4T Yɸ$^ZX}⾗z`7)<\fb|[5y"*cg/ӪV#YGWM~4ٳAil_&Ðᡸ΀i) s n:* xv8KpԢ UYf.džj?Ryf_)u(LӮAT2kHA7Ʌ16?Œ٠:1(NԌJs:ŗyYpG5C h;(~%I1M뢈h{ -`>qrPS>< ԭJwnsP+#j`է"ir, xtj[4JEBSiGYS:.itGux@;o8Xim{WI/ǻ9J@#mHct DFIސJ9G˛[%&r[lxgn.GS}PJS^ҋE}0ǖRi2($c}:_AϤG& V@uWp:>?y)u)O $U.E:S6Buɡt|hhkR4A¡VZyy!)2b?6+ƫcQ><m/\F) [MT{vty R:csQ-3[{l+Ü? b[ّ&-\ƽe놟nw Mx\E){j j*'t0TgىWa78M}nŒQҼO K7ĊMhI1tU!Tޓ^^#۰fd뛯@? 먧A~㖹랼(2F˙3D>-qS/~ mqoˏ743*Pt#SUM'P]w0ۉ/x* 0:&>xȱ4z 9S!|rN0p͟2VvƔ[ܳ2)'QB{]6z/E1.%14BΙe 1%2~T45X/n:B g寲 % c y:$h>4 Il2> އhpzk54W1 tl`^B@:ZVtTLmp m3Mk N]]D@K>rW ( 02x-16Xk\HYp8tU1*O?LOد}}͝SLgXv-DFԜPw*|H6A+E DQP(MM-z6ka?ϸ)]UK1փ/|ZtGVh+[fQ q=u+IbXgVCqCBf W'|#fMymN=/輧&<*1﹝\tӈ18'z֦r]QπX}DC#G*p[hsY`UÛHU!S<˄掏,nu(̼R5AgWd(!zW >e(yJ7e>X}Kܳ6IH |g2 xӦ5"\)k#f8aedsY-L5Ordu8C}/kurDJ|wH{Ah%Dr/3?$kԳW;67)pvC_\ߌ,2SrksCMX[y'¸£:0yuZ䝴ꜜئE}kK{ldϛazitxwUՀj[2F/#dD#˰v;#:'Z%4f?ݯWo_ ]('/jzq$kZ>YdhuQ/rs1~^C]Ag}8p0˝-oDycgU!QTpfϩP`nG( =_/u^nk[ێ)ji5%*]8>oG >0УoOJw}B>{} T(1H#1ՙd F&"-,cT)΃e}8Dy]K+BjzЌg\mGD""QNF3ŽϬ1C>To0N]yU `Ўj"4'!ILFv7SCǏK_Zꡊ3ʘ~>Ik` \'Xؐ8Ur >*XsN 8I7f-G*MPro ))s߫N`a!A!v!?[GF8v2/PxUThLMa.L~ ίZVap٩&*oG=ڝ[6kl@ `n,M-?_S%'/ɿΠ27_{|Mc >]+ Q_Ez`p uݛUJ̹QeQK{DWU|&wvI6ը^2ܤ<ӡ ,97]MMG{ǷK*)4`t876Dwn  .3^+8cO}tIZ6oxN'V4BbhQֳǖ+8?qP9+7޵|?qI$މV#ELQ]oaN"Թ]PI!aoX A+rR # 汿 >ą_Fp?RN9v UjHw|M0xx[4hi -~E;D,jûyctw/~+~O$b`N)߳r)l **DRn88cp'TkC$W\MqkulVrpo|F zH7cO.XUxYJtj%#ӡUڦ73Xa9"8wXJ:d0sE` w+j%3"?= 7 - d8Ӌ<45\[kV?<~# 3RK / A0mzfcgl(s^Z?KՃ_NCzk@l6jt()x.6K.5:DLSͽGYM#.Waփ ʷr旪O6b:*9>*67~ٷ8^vLʽX"[2{J9.]Cܿ"9wCZs_b%THR+;15QTe OAi@A5ߡ&Q3DQ e^?YbDTk.Ԣ{F*kdcRHƁI;rxD^I͇ VyXI$4=t伈dvHR̄wp@ ̈́*D^#5Pp(/ J4oȍ%tCygnd󕍞}0}H( >)% eWK]ւnYRL- ƽ%!Sx,>1So)ɽ1}8kÔ vUoSTXd߯3'ԣVFG&E@IJP~mE3G Z$D ʹ Ƃ"c<,)`), \-ґiTsW4c]`/Cf))D5x4'|:Iô,g#ϵheB -M yQ2rtD) ~%qN M¬rHݢM!tw%@_A{e[,։Qiع#uD2fmD-)vg "<Ɣ?e o< RydzpwacvqMxmeW׊l1aQ6W䔏7d͠4SCM/kY̾?=2R{[iS xziӺQ:zV lv{L ޞѸ%F,yF ^"82vWwLQCh~;@ zԩ=||!642BG @ 4a(\7cuN+&YQY⅑O5YB ؇]za_C-gg:ru-q 7 X闇nX[4F jZ=ѦӒv,,4+ys\R[ q+(GLyH<#rT0=W(;sʨ= N,m>_vi^6)R.[73?V4/s,)O9CmM?XS'%;  \e](GTQp9BP_e-/|ScS|*nAϦnR˹ZнaΑ`~1[?=2+ =vt S*|eVeBI2Wi~n$dJJP}DU}41@:ic3Ƈ!u=7hG͎G1p41fS%%jQ?ޕfl)0`w {?WL(~m{>O-5l=\o_+pO)JNҋ1ڗ%uve&I9=ggҰ{qrl3=q^POEbvPQ Ry]9l>Ŝ NfS$U!:%; PB az/x N^f-'!څ j_P_PEqC \<>X"S* B.t>?E.>9Y]e:#ٕpD Փ*sm6! |ʬ;G:CY85ʏ&\ @"[=#>*Lh5S]0iu|YIqO?YF\3)Uщ<4Z/y!6a, ׭'I9b^0/yr8u{+M}s#aTJ`lރuto !QX7Wt!ZYnӒ.өr;h5`6wы }A6EYnޱjX525D֭R9pSz݅zЌ- Ӽ]'ț{CĮN=pwͻPdm_Nہ$JrOKN^"-a-bR 022&-Dh^HlLpR_6?jdq(@:8f98"O[og UBd {eQ{?\qkyϲhpg߲[<5ex_g:|FxX\)"Xc$_(̧.;´T2`9" /k enAnB_C?ұHveS1Ko}N>U$QUA<ήYH[8gֳs ) V0]|?} m XA&]|O,~[A|94vG׭|wYiH{ɾsp|V>~Z:KCA>x2`uE'[fD(n0 hXOOʹf,]Oŵ#z)MCt<ΈE x2Z#81T&RvvWP]PZ%Wao@is0GԮ)e- J7I,bqVpa0 EQFrPAcJO1Ԟ`SХYu_ab%~kqN]"2T-7x8L͆+yG%;Y0lx }-WG`Olߌ(\SoUL B mHrV6WYo.~@cTH\+/N/]yʼn^;)yZ+{6f3 %4vfXJ7 JW0WᢧԄpkfn+S2JfH|"B)VI1 ,p䞴b˺~;4 k\5`+L?'jP0FZBԉ\zc74&c|8-!WXiJNy/ƋLKCi#G ~q^(廒d51ǫeLwCWV^DyBa^b}7\;p0(闱׈2wH"Љ,wX2:*3^-jiX( *c u0NWwD i!G,IcSW50X*zDb{3εT ?%]JdG\WmǺM%GiTPJ< e}n"k+s Z:ir U,Bor8>:Pn fZZE# 'fvZZr"V~v>О p6l  YZ