knot-devel-3.0.0-2.el7> 6 6`d63!}|J^>j/5,d_m j/5,dgS.rcl= nwi)]Edׅ%D>{?פQ[Ю"OBfVjg.m$sJfbqt.6E_Hv`*0AʥuQLcZţ]1XEPAv#-'[VS\tA|LQf_>}E>\qXI =:V `@jTSkQ_H!ak`R5T1ZahȤs>g*+ڲk+>ߦѿHwVBgYAkٹb~{q@fPx8hڮh~:!qb `4&)~JR2"|~/y#6"\EpS \d'CBq`\nv? SD[FX ʠfw׬j/5,d_m j/5,dVJ *5#Y}e8z⚥IGg? Fd elb~mDu梃,SdKPyd{5TI6 Y(i4f|3]! 4^7\)W.8n=O枖9r/4'w2h|\JmI- 'k~&qy wio>vtS؍]5 |B+Ϟퟆ[u'6ie%ytnUp!/?3+*\ds;:^WS x/Ősf8=0?Q2]S^cH\vfю,8r?O+lq|9 0\#p5 2'k!"+"h!8QWYo{[-K%FT(: * im"9,Az}MGAmr>K aY}<C|jwITL%_! {? M?Fb'/$R#q+4C @'>:?d   M &2JPXMM &M M M M M<MM>XM ( ! (W8`+9 +:&$+GzhMH{MI|MX} Y}8\}hM]~M^Q bkd0e5f8l:tTMuMvwMx,My` Cknot-devel3.0.02.el7Development header files for the Knot DNS librariesThe package contains development header files for the Knot DNS libraries included in knot-libs package._mGbuildvm-x86-13.iad2.fedoraproject.orgAFedora ProjectFedora ProjectGPL-3.0-or-laterFedora ProjectUnspecifiedhttps://www.knot-dns.czlinuxx86_64Er %~ zR c ^4 J 0&d'K@D , tgj  GEO& r L >""7 +:%A큤A큤A큤A큤A큤A큤A큤A큤A큤_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_m_mb7d9c808eb375b11fa79bab2cd342ce71b8964f54342357ea6fb9e6f282e278db4fbe48c632018c0e15b531c25797c3b380cb0ec35f0a597a1f1c94008220b58f676aed7ec38307f1d7282f86ec4f894dd4875c2429109cab92b9621525966dabc13139bb264cedbb87f2c05521f7485d1933527c92e8a7a212c6f8ef2464203364324e616dcffd84443431a4d05b8f69363665df33a0384e51bf51365adc424d7ea4016beeafa78da5c93e4a0aab3caac4eafef217e3e32c4c17881172e6e278e9c208cedc89ed277c48b97086e1455d2534705619218a1229e97234bfb0b9e85dc895d1c2610cef7f07c2ed8f7ff2636a55034385513452f53e85c2754a05492ea22cde12acc55b67f797071c03119cac1d0ecacb187646052b5ec9bf692e8f6cdd36b572a22aea68204f86f208c5f2a052cccfe73a5430b0dc4dbe6a9db0bb9fa74795774ffc71a964f8b7132997957fc0ff8ea37b1f21d1f49c112b28d7419ae51ecd71495a5c3010c371169857d9c66a7a6a6af98b030b6ea5be85ec1a5919f3837757036c1766ffddfe13b4756a180dd56c94acd798fed6d1d35454f28c3e7b2c6cc75abeb22f94d2eb7162ccfaefa2a224dfd135c8186472796d057e91e096b8b7839195eba6caef7bf94d3bf1fd92c9554420c212969a571718311bb068794bba3e89a38dda175a6952a812eace59e96b20203054f68ffaa6a860eb5599c23167095d105229e366197352e4d4b3ddc39745ce54e4b386fd69dbc9924ad79e3e1ea4a4dd6c3646eb57a5145cea6bddd6144c24ffbcde3ffcaafc8b4fd8f8df55d86daf9841241e346b2e6bc17f15091d367132c5456d64e2c3565a20767af608031639b271fecd0b35ab0054e67bace684a983d9c96599ea7ac28049709e7cc98c3de9f322e232b419b010057a85ae809040bfd1d4f7980d352ae3a6573aeabfe39a9aab4f6bcdbf0693805d8fbdd906c78ab0e955f39e7eea5977a041757fd765e25974c4b01ba40214d4cab0626fc506a1ad7a0e8577b3aef19a925a2e7e584a3b3fcb95e283786e674532f67549c00841bc95832f32904bd73abc971e99b1da5eec117e8a341735d9a97a37ab02ec9377bcfb81e1c5dd368d8b08a45c1a06bae79ef63c42672bc930378393ca1581c00d473c52452f2175a51ec44a886bfde1981d7734d3838d18f18e2271744e71bd78026dc4714e7f21b9e7b667191d36950be3a402aac76dcf9f532c6dfbb60228158cd280701096ce5420acb9eaa10775bed967650d289df9057585a7a4e9fedf4a5ed8150cd8db260fec71ea554f47b5e1b3c0d5a226d9720bb3cbf391fee27b1a70850972b4469ce0948db81b62373ec7b7f48dc28d3b26cacca029b46cfe7d4815c72d5253618e526d5f9a68f1993f6d90e0428b4585ca5be835eeceab21017198d81b3819c40046ea8ea9156c5acc89c8272ed367a5e39697095241155a9b48283f7e206fdc4345c99e734245ed008a00c55b022308f1e325cdd2ccd6476828068ee18c484d9aa5d85a9d55ee1bcd8a6c512fbaab8e00b5a31d025c978aecbda25a32caccf45d637996cff1cded7df7fe32ed047aabdbfbc878e4a090daddf8cbcf961b104eef29eee38761e4d542ee9df287a6e20403a08a75476d01eb55697b3903695fc4e8ff5dfb39fe9b4c0f6fcac6f57d1fabd5792d97708c868ffa8985c98f69b4b0062de6517423284635714ee1a820a82bc17197d1334667b6b06ef1258a93c21649c8a8b4b91b4063489f544e810bc10ffcf7834cef2549c53a9b6b81cdb937c0bd08f121aba302841a71120e7dd3194c3f3e51dd2b2db50acaa6e0adf5a10b15d83dfcc30161dcdbfe3e0ec3bcd4ecd1b35415214c84ec3728b93cde1d58ef253337548c27d48246cdfa95df787ca6e01968b1165e23e9f213a3e8092e3d55141db8a229a257e33b5b78d6e416ca902cf8a68b2a28e1e3e89a775b91a6df6110fd6a82ec30fecd5f27716fb25bd2f32491a381a61b4864685d60c8d14c3ee0e1e6b27e0aa5c14f71a87b37c84e0ab07f1a7a62a475a45f9b759420314f72544c842974443d5fda756c4efca40cd701630d5b70efa38e8858ddc6237adf9676eb48ef1be78d484dc095525cf47421ac58917ea5c09e68bacb516577967c3a2ffd12022371430ab2a2e74d275401c78b36c467a06a1e2ced136266ed33508ea1410b3054429eabfee04ff1f14beb1df7ee29fd647dbd56960a62b25caf376211b0be3034b5504b6fafbaf42aafeda061486f3a0cd57ee6661cbb3472354758d8f194182e0e372d1c5b0c964f5b0e272006722d7b9cea85bc01a4a7b2691463264f07587df64c29a37d54dd4feaa4b278612b0010e5590988870be0b13237c6cde1cf49092b22631003298e74a56c98121799d00246d344841cb4a4e1cb60499185a8bf7068cfad12e59fe2b5c332c6e971c6ee71a317a56253e05e712dd37186e9d1fbf2460d537ac1bc5636d5fdb8a6cc17007197f83ca431b327084bca54022011cb92d30b44fc417912d2af87f0a8a0027d7b857395c8566c5c6773fb43be48a6b25855cd7495e9907dc46930b276cf7b2ec1c5c2b3032312fc404f217416a54005443f8bd7821040a1280a52fa02ce842b4007a1c81da28000d3c840eb4477853b2d336a7cc14a8cab9041b5f72a00026fbb7b6f97fd93aff54b07847560732279f9d239ed2a65dd31d26b72c031ed855777fbb19b6a0359a0cf3e3f25d0161d462c53aa3a2e8e23112706d9a1364dc27b43ffb8640d23e55f7e0ba9ff96d6a41e0801e99cf64594257e326177f185f84bba1a340f1bd6c6cdba7e392d089e3e43c9f46e6f53d90e559399b60335d8e9a6561b2246f93d84f2ce24fec9871a035876cd88af930534a33a12434d466509fcc980bd47a850561e2ad456f0ebaf534172b28libdnssec.so.8.0.0libknot.so.11.0.0libzscanner.so.3.0.0rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootknot-3.0.0-2.el7.src.rpmknot-develknot-devel(x86-64)pkgconfig(knotd)pkgconfig(libdnssec)pkgconfig(libknot)pkgconfig(libzscanner)@@@@@ @    /usr/bin/pkg-configknot-libs(x86-64)libdnssec.so.8()(64bit)libknot.so.11()(64bit)libzscanner.so.3()(64bit)pkgconfig(gnutls)pkgconfig(libdnssec)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.0-2.el73.33.0.03.0.4-14.6.0-14.0-15.2-14.11.3_m_Z@_O@^˳@^U@^^F]}@]ʞ]@]]2@]'$[ @[H@[E@ZnZZZZ}@Zz@Ze@ZNYYYXƉXX@XAXJX-W#WhWWV&@VUUUUa@UG_@T@T@Jakub Ružička 3.0.0-2Jakub Ružička 3.0.0-1Jakub Ružička 2.9.6-1Tomas Krizek - 2.9.5-1Tomas Krizek - 2.9.4-1Tomas Krizek - 2.9.3-1Tomas Krizek - 2.9.2-1Tomas Krizek - 2.9.1-1Tomas Krizek - 2.8.4-1Tomas Krizek - 2.8.3-1Tomas Krizek - 2.8.2-1Tomas Krizek - 2.6.9-1Fedora Release Engineering - 2.6.8-2Tomas Krizek - 2.6.8-1Tomas Krizek - 2.6.7-1Tomas Krizek - 2.6.6-1Iryna Shcherbina - 2.6.5-2Tomas Krizek - 2.6.5-1Igor Gnatenko - 2.6.4-3Fedora Release Engineering - 2.6.4-2Tomas Krizek - 2.6.4-1Petr Špaček - 2.6.1-1Petr Spacek - 2.5.3-1Petr Spacek - 2.5.3-2Petr Spacek - 2.5.3-1Petr Spacek - 2.4.1-2Petr Spacek - 2.4.1-1Fedora Release Engineering - 2.4.0-2Petr Spacek - 2.4.0-1Jan Vcelak - 2.3.3-1Jan Vcelak - 2.3.2-1Jan Vcelak - 2.3.0-3Jan Vcelak - 2.3.0-2Jan Vcelak - 2.3.0-1Jan Vcelak - 1.6.8-1Jan Vcelak 1.6.7-1Jan Vcelak 1.6.6-1Jan Vcelak 1.6.5-1Jan Vcelak 1.6.4-1Fedora Release Engineering - 1.99.1-4Kalev Lember - 1.99.1-3Jan Vcelak 1.99.1-2Jan Vcelak 1.99.1-1- Rebuild- New major upstream release 3.0.0 - Sync packaging from upstream- Update to 2.9.6- new upstream release 2.9.5- new upstream release 2.9.4- new upstream release 2.9.3- new upstream release 2.9.2- New upstream release 2.9.1 - add EPEL8 compatibility - fix unsafe PGP keyring permissions- new upstream release 2.8.4- new upstream release 2.8.3- rebase to latest upstream version 2.8.2Knot DNS 2.6.9 (2018-08-14) =========================== Improvements: ------------- - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation Bugfixes: --------- - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_RebuildKnot DNS 2.6.8 (2018-07-10) =========================== Features: --------- - New 'import-pkcs11' command in keymgr Improvements: ------------- - Unixtime serial policy mimics Bind – increment if lower #593 Bugfixes: --------- - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy #589Knot DNS 2.6.7 (2018-05-17) =========================== Features: --------- - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) Improvements: ------------- - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination Bugfixes: --------- - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback modeKnot DNS 2.6.6 (2018-04-11) =========================== Features: --------- - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation Improvements: ------------- - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination Bugfixes: --------- - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)- New upstream release 2.6.5 Knot DNS 2.6.5 (2018-02-12) =========================== Features: --------- - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set Improvements: ------------- - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates Bugfixes: --------- - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations - Failed to generate documentation on OpenBSD- Escape macros in %changelog- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Added PGP signature verification - Added integration test - New upstream release 2.6.4 Knot DNS 2.6.4 (2018-01-02) =========================== Features: --------- - Module synthrecord allows multiple 'network' specification - New CSK handling support in keymgr Improvements: ------------- - Allowed configuration for infinite zsk lifetime - Increased performance and security of the module synthrecord - Signing changeset is stored into journal even if 'zonefile-load' is whole Bugfixes: --------- - Unintentional zone re-sign during reload if empty NSEC3 salt - Inconsistent zone names in journald structured logs - Malformed outgoing transfer for big zone with TSIG - Some minor DNSSEC-related issues Knot DNS 2.6.3 (2017-11-24) =========================== Bugfixes: --------- - Wrong detection of signing scheme rollover Knot DNS 2.6.2 (2017-11-23) =========================== Features: --------- - CSK algorithm rollover and (KSK, ZSK) <-> CSK rollover support Improvements: ------------- - Allowed explicit configuration for infinite ksk lifetime - Proper error messages instead of unclear error codes in server log - Better support for old compilers Bugfixes: --------- - Unexpected reply for DS query with an owner below a delegation point - Old dependencies in the pkg-config file- New upstream release 2.6.1 Knot DNS 2.6.1 (2017-11-02) =========================== Features: --------- - NSEC3 Opt-Out support in the DNSSEC signing - New CDS/CDNSKEY publish configuration option Improvements: ------------- - Simplified DNSSEC log message with DNSKEY details - +tls-hostname in kdig implies +tls-ca if neither +tls-ca nor +tls-pin is given - New documentation sections for DNSSEC key rollovers and shared keys - Keymgr no longer prints useless algorithm number for generated key - Kdig prints unknown RCODE in a numeric format - Better support for LLVM libFuzzer Bugfixes: --------- - Faulty DNAME semantic check if present in the zone apex and NSEC3 is used - Immediate zone flush not scheduled during the zone load event - Server crashes upon dynamic zone addition if a query module is loaded - Kdig fails to connect over TLS due to SNI is set to server IP address - Possible out-of-bounds memory access at the end of the input - TCP Fast Open enabled by default in kdig breaks TLS connection Knot DNS 2.6.0 (2017-09-29) =========================== Features: --------- - On-slave (inline) signing support - Automatic DNSSEC key algorithm rollover - Ed25519 algorithm support in DNSSEC (requires GnuTLS 3.6.0) - New 'journal-content' and 'zonefile-load' configuration options - keymgr tries to run as user/group set in the configuration - Public-only DNSSEC key import into KASP DB via keymgr - NSEC3 resalt and parent DS query events are persistent in timer DB - New processing state for a response suppression within a query module - Enabled server side TCP Fast Open if supported - TCP Fast Open support in kdig Improvements: ------------- - Better record owner compression if related to the previous rdata dname - NSEC(3) chain is no longer recomputed whole on every update - Remove inconsistent and unnecessary quoting in log files - Avoiding of overlapping key rollovers at a time - More DNSSSEC-related semantic checks - Extended timestamp format in keymgr Bugfixes: --------- - Incorrect journal free space computation causing inefficient space handling - Interface-automatic broken on Linux in the presence of asymmetric routing Knot DNS 2.5.5 (2017-09-29) =========================== Improvements: ------------- - Constant time memory comparison in the TSIG processing - Proper use of the ctype functions - Generated RRSIG records have inception time 90 minutes in the past Bugfixes: --------- - Incorrect online signature for NSEC in the case of a CNAME record - Incorrect timestamps in dnstap records - EDNS Subnet Client validation rejects valid payloads - Module configuration semantic checks are not executed - Kzonecheck segfaults with unusual inputs Knot DNS 2.5.4 (2017-08-31) =========================== Improvements: ------------- - New minimum and maximum refresh interval config options (Thanks to Manabu Sonoda) - New warning when unforced flush with disabled zone file synchronization - New 'dnskey' keymgr command - Linking with libatomic on architectures that require it (Thanks to Pierre-Olivier Mercier) - Removed 'OK' from listing keymgr command outputs - Extended journal and keymgr documentation and logging Bugfixes: --------- - Incorrect handling of specific corner-cases with zone-in-journal - The 'share' keymgr command doesn't work - Server crashes if configured with query-size and reply-size statistics options - Malformed big integer configuration values on some 32-bit platforms - Keymgr uses local time when parsing date inputs - Memory leak in kdig upon IXFR query- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble).- disable dnstap on RHEL (depedencies are missing)- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble). Knot DNS 2.5.3 (2017-07-14) =========================== Features: --------- - CSK rollover support for Single-Type Signing Scheme Improvements: ------------- - Allowed binding to non-local adresses for TCP (Thanks to Julian Brost!) - New documentation section for manual DNSSEC key algorithm rollover - Initial KSK also generated in the submission state - The 'ds' keymgr command with no parameter uses all KSK keys - New debug mode in kjournalprint - Updated keymgr documentation Bugfixes: --------- - Sometimes missing RRSIG by KSK in submission state. - Minor DNSSEC-related issues Knot DNS 2.5.2 (2017-06-23) =========================== Security: --------- - CVE-2017-11104: Improper TSIG validity period check can allow TSIG forgery (Thanks to Synacktiv!) Improvements: ------------- - Extended debug logging for TSIG errors - Better error message for unknown module section in the configuration - Module documentation compilation no longer depends on module configuration - Extended policy section configuration semantic checks - Improved python version compatibility in pykeymgr - Extended migration section in the documentation - Improved DNSSEC event timing on 32-bit systems - New KSK rollover start log info message - NULL qtype support in kdig Bugfixes: --------- - Failed to process included configuration - dnskey_ttl policy option in the configuration has no effect on DNSKEY TTL - Corner case journal fixes (huge changesets, OpenWRT operation) - Confusing event timestamps in knotc zone-status output - NSEC/NSEC3 bitmap not updated for CDS/CDNSKEY - CDS/CDNSKEY RRSIG not updated Knot DNS 2.5.1 (2017-06-07) =========================== Bugfixes: --------- - pykeymgr no longer crash on empty json files in the KASP DB directory - pykeymgr no longer imports keys in the "removed" state - Imported keys in the "removed" state no longer makes knotd to crash - Including an empty configuration directory no longer makes knotd to crash - pykeymgr is distributed and installed to the distribution tarball Knot DNS 2.5.0 (2017-06-05) =========================== Features: --------- - KASP database switched from JSON files to LMDB database - KSK rollover support using CDNSKEY and CDS in the automatic DNSSEC signing - Dynamic module loading support with proper module API - Journal can store full zone contents (not only differences) - Zone freeze/thaw support - Updated knotc zone-status output with optional column filters - New '[no]crypto' option in kdig - New keymgr implementation reflecting KASP database changes - New pykeymgr for JSON-based KASP database migration - Removed obsolete knot1to2 utility Improvements: ------------- - Added libidn2 support to kdig (with libidn fallback) - Maximum timer database switched from configure to the server configuration Knot DNS 2.4.4 (2017-06-05) =========================== Improvements: ------------- - Improved error handling in kjournalprint Bugfixes: --------- - Zone flush not replanned upon unsuccessful flush - Journal inconsistency after deleting deleted zone - Zone events not rescheduled upon server reload (Thanks to Mark Warren) - Unreliable LMDB mapsize detection in kjournalprint - Some minor issues found by AddressSanitizer Knot DNS 2.4.3 (2017-04-11) =========================== Improvements: ------------- - New 'journal-db-mode' optimization configuration option - The default TSIG algorithm for utilities input is HMAC-SHA256 - Implemented sensible default EDNS(0) padding policy (Thanks to D. K. Gillmor) - Added some more semantic checks on the knotc configuration operations Bugfixes: --------- - Missing 'zone' keyword in the YAML output - Missing trailing dot in the keymgr DS owner output - Journal logs 'invalid parameter' in several cases - Some minor journal-related problems Knot DNS 2.4.2 (2017-03-23) =========================== Features: --------- - Zscanner can store record comments placed on the same line - Knotc status extension with version, configure, and workers parameters Improvements: ------------- - Significant incoming XFR speed-up in the case of many zones Bugfixes: --------- - Double OPT RR insertion when a global module returns KNOT_STATE_FAIL - User-driven zscanner parsing logic inconsistency - Lower serial at master doesn't trigger any errors - Queries with too long DNAME substitution do not return YXDOMAIN response - Incorrect elapsed time in the DDNS log - Failed to process forwarded DDNS request with TSIG- configuration checking was fixed to be compatible with Knot 2.4.x- new upstream release 2.4.1 replaces old 1.6.x series which is not supported - configuration should be upgraded automatically using knot1to2 tool - make sure you reviewed the new configuration in /etc/knot directory!- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- new upstream release: + fix: False positive semantic-check warning about invalid bitmap in NSEC + fix: Unnecessary SOA queries upon notify with up to date serial + fix: Timers for expired zones are reset on reload + fix: Zone doesn't expire when the server is down + fix: Failed to handle keys with duplicate keytags + fix: Per zone module and global module insconsistency + fix: Obsolete online signing module configuration + fix: Malformed output from kjournalprint + fix: Redundant SO_REUSEPORT activation on the TCP socket + fix: Failed to use higher number of background workers + improvement: Lower memory consumption with qp-trie + improvement: Zone events and zone timers improvements + improvement: Print all zone names in the FQDN format + improvement: Simplified query module interface + improvement: Shared TCP connection between SOA query and transfer + improvement: Response Rate Limiting as a module with statistics support + improvement: Key filters in keymgr + features: New unified LMDB-based zone journal + features: Server statistics support + features: New statistics module for traffic measuring + features: Automatic deletion of retired DNSSEC keys + features: New control logging category- new upstream release: + fix: double free when failed to apply zone journal + fix: zone bootstrap retry interval not preserved upon zone reload + fix: DNSSEC related records not flushed if not signed + fix: false semantic checks warning about incorrect type in NSEC bitmap + fix: memory leak in kzonecheck + improvement: all zone names are fully-qualified in log + features: new kjournalprint utility- new upstream release: + fix: missing glue in some responses + fix: knsupdate prompt printing on non-terminal + fix: configuration policy item names in documentation + fix: segfault on OS X Sierra + fix: incorrect %s expansion for the root zone + fix: refresh not existing slave zone after restart + fix: immediate zone refresh upon restart if refresh already scheduled + fix: early zone transfer after restart if transfer already scheduled + fix: not ignoring empty non-terminal parents during delegation lookup + fix: CD bit clearing in responses + fix: compilation error on GNU/kFreeBSD + fix: server crash after double zone-commit if journal error + improvement: significant speed-up of conf-commit and conf-diff operations + improvement: new EDNS Client Subnet API + improvement: better semantic-checks error messages + improvement: speed-up of knotc if control operation and known socket + improvement: zone purge operation purges also zone timers + feature: print TLS certificate hierarchy in kdig verbose mode + feature: new +subnet alias for +client + feature: new mod-whoami and mod-noudp modules + feature: new zone-purge control command + feature: new log-queries and log-responses options for mod-dnstap + feature: simple modules don't require empty configuration section + feature: new zone journal path configuration option + feature: new timeout configuration option for module dnsproxy- fix post-installation scriptlet (RHBZ #1370939)- endian independent DNS cookies (fixes build on ppc64 and s390x)- new upstream release: + fix: No wildcard expansion below empty non-terminal for NSEC signed zone + fix: Don't ignore non-existing records to be removed in IXFR + fix: Fix kdig IXFR response processing if the transfer content is empty + fix: Avoid multiple loads of the same PKCS #11 module + improvement: Refactored semantic checks and better error messages + improvement: Set TC flag in delegation only if mandatory glue doesn't fit the response + improvement: Separate EDNS(0) payload size configuration for IPv4 and IPv6 + feature: Zone size limit restriction for DDNS, AXFR, and IXFR (CVE-2016-6171)- new upstream release: + fix: Transfer of a huge rrset goes into an infinite loop + fix: Huge response over TCP contains useless TC bit instead of SERVFAIL + fix: Failed to build utilities with disabled daemon + fix: Memory leaks during keys removal + fix: Rough TSIG packet reservation causes early truncation + fix: Minor out-of-bounds string termination write in rrset dump + fix: Server crash during stop if failed to open timers DB + fix: Failed to compile on OS X older than Sierra + fix: Poor minimum UDP-max-size configuration check + fix: Failed to receive one-record-per-message IXFR-style AXFR + fix: Kdig timeouts when receiving RCODE != NOERROR on subsequent transfer message + improvement: Speed-up of rdata addition into a huge rrset + improvement: Introduce check of minumum timeout for next refresh + improvement: Dnsproxy module can forward all queries without local resolving- new upstream release: + improvement: Log change of the zone serial number after IXFR transfer + improvement: Document operational impact of various RRL settings + improvement: Add support for rate-limit-slip zero + improvement: Add 'timer-db' configuration option- new upstream release: + security fix: out-of-bound read in packet parser for malformed NAPTR record + fix: systemd startup notifications- new upstream release: + fix: don't load expired zones on reload and startup + fix: remove race condition in scheduling causing delaying of events + fix: NSEC proof construction in zones with many delegations + fix: TC flag setting in RRL slipped answers + fix: disable domain name compression for root label + fix: check if executed under systemd before using journald log sink + feature: write persistent timers on server shutdown for better performance + feature: support time unit specification for 'max-conn-idle', 'max-conn-handshake', 'max-conn-reply', and 'notify-timeout' config options + feature: add 'request-edns-config' config option- new upstream release: + fix: lost NOTIFY message if received during zone transfer + fix: kdig, record correct dnstap SocketProtocol when retrying over TCP + fix: kdig, hide TSIG section with +noall + fix: do not set AA flag for AXFR/IXFR queries + feature: new configuration format in YAML, binary store im LMDB + feature: DNSSEC, separate library, switch to GnuTLS, new utilities + feature: DNSSEC, basic KASP support (generate initial keys, ZSK rollover) + feature: zone parser, split long TXT/SPF strings into multiple strings + feature: kdig, add generic dump style option (+generic) + feature: try all master servers on failure in multi-master environment + feature: improved remotes and ACLs (multiple addresses, multiple keys) + feature: basic support for zone file patterns (%s to substitute zone name) + improvement: do not write class for SOA record (unified with other RR types) + improvement: do not write master server address into the zone file + documentation: manual pages also in HTML and PDF format- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for nettle soname bump- fix BuildRequires for systemd integration- new upstream pre-release version: + DNSSEC: switch from OpenSSL to GnuTLS + DNSSEC: initial support for KASP - split package into subpackages - add documentation building - restart daemon on updated  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLM3.0.0-2.el73.0.0-2.el73.0.03.0.03.0.03.0.0 knotmodule.hlibdnssecbinary.hcrypto.hdnssec.herror.hkey.hkeyid.hkeystore.hkeytag.hnsec.hpem.hrandom.hsign.htsig.hversion.hlibknotattribute.hcodes.hconsts.hcontrolcontrol.hcookies.hdbdb.hdb_lmdb.hdb_trie.hdescriptor.hdname.hendian.herrcode.herror.hlibknot.hlookup.hmm_ctx.hpacketcompr.hpkt.hrrset-wire.hwire.hrdata.hrdataset.hrrset-dump.hrrset.hrrtypednskey.hds.hnaptr.hnsec.hnsec3.hnsec3param.hopt.hrdname.hrrsig.hsoa.htsig.htsig-op.htsig.hversion.hwire.hyparseryparser.hypformat.hypschema.hyptrafo.hlibzscannererror.hscanner.hversion.hlibdnssec.solibknot.solibzscanner.soknotd.pclibdnssec.pclibknot.pclibzscanner.pc/usr/include//usr/include/knot//usr/include/libdnssec//usr/include/libknot//usr/include/libknot/control//usr/include/libknot/db//usr/include/libknot/packet//usr/include/libknot/rrtype//usr/include/libknot/yparser//usr/include/libzscanner//usr/lib64//usr/lib64/pkgconfig/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnudirectoryC source, ASCII textASCII textpkgconfig file RRRPRPRRPRRPRhttps://bugz.fedoraproject.org/knot?`7zXZ !#,'n] b2u jӫ`(}ӛ6Mh詍FQF$$E @eo083tb@P!mUFDz[z G潻NtȌfgud ȻH_;T$j_M̀/οԾ˭Iss#C)hwzI ⚔$F&vȤj]|eqm{*jgh ArGԳ}_6t4~+(εW@M{? @rZ(3Q*pAB\^_4l_dZ=Ǥ(QQԦfSm/D\̅$n3}6Ҿt-RĆ-&[.r4A'}Rh$tbʕ4>Y줃qpYytm~ Ss|N4$-{lN=jX=!C&aSzì?GUɖRQXv\4ȵ?ޠ:ހl"%0vԶ c ML%E6Qx }KP}6^yI@wm o pP]\ ;})3↘zf!WB%B&d= +9QP;za@@H*8Xu(>ĔUA\"ifgӮR73,LGH3%}}v˄6~b$!ٮ1 ·441 vEF/4gx\ඪ{He=/M5!FUP&4 M2Y >FF.f0vL'[@AT;3rDqԡcnb߳A 5&1#c:ڵ-O QַtrӰWϘ]kWEHtYb4LrCC?k/;NزAdk>` &}%0qGMIƝrށ>KkX<- 46֗*H ̇Kǭv% U8A<O8͂zPigD=+qM,Bwۥm;pૄ-Q&z荡l?^cp2)@6!'τ"'H&XqGTm4~%<na9?f ?[ JOr@a͑rs%jN񺤊 嶇h}m9 \Q_he,)A֍*G_9TpY^hF AtoRV~70$ 2N>) MY^z-˥2vTkc8NhGQ>q3ԔSELz+Aq wVR ;>KG`)H1i33#~ץXat[ɱ"}9-hRevAb""p6^G•h]_ԜCvňv6'W뿓y1ͻ)S[Ȥe{O:dV*4ť{{$Ǩ##gxϧ;S'DC#PM$|F2䬦) O_{}iRۙ(zLL֊5 ]Bb4v @i9еGIO> f}^(1P"E5O!;]wa31,:aDJbih,mgg ~]`u #[7@H©Oq:|/\&{%e4}GeQU ޒfASʉEG ={=H0h=0D_k:!in2Eo^`J!LFkf1TGW}(Sf4w ˡI1/{0 Zp pNiE5x ^ϷB 6>r0A_ PJ2m~5ZtR %b(FZa?{HJ sd$ipI>X4|*XNfw=I ]؊됕Nw-Jz:oT1Dby;($c'\ē1,.͸0҄Ұ˻7~w+8C@XeZ:W a)Rm1>IŐuH] ?O⟙Էʉv6I#zKa)}nה b󙖸/4-C൶Rȭ3nx}$N}^P)yw4Qãxtϭ`Bjf 14= WfA+jو!3nZ[-(kE)F+W'q,Ӫl-.=zn^xRe2i3cy3׽}k`^I-@62%e/jWt:X͸v[G3 !q)6"yAa>{槲s,?d6U@Z_?$akkdY CEȝ. bm/7]ט\*8M; +-)@4#$2)ʼ2&6T8g2 R`ZM-(f»r_k (S9SO#n{l60K?~P,޻鰦}\M8%/%pK#E$U9}/ t~p9}鋒bD<\|ldHkQiiI 4\~)QeEdxm{6戻sr2M2B'!4%_SL GJ(C%aA/_IECKr.=r;ǍO>UWǵ9GyA(c|X@ - | L"@jθ?Cx9ŭ s{)vSXBS+Q'7<ȌZ`yv@ed.r^Sp%0U,ZE6ʘmH+Zkz3r+AVcG?u$Vi鎐>LUJuۃ2u8wsrωVa!==EHhn_ e~5CcQzx"Lgk+%k1ğU,18ȊQZT-oWx,M?V\e1d %;x|=iMo&"X7a{[ YiD=?,К=YX&h LËXh wbTuj&'aAn&sIu.}:15\XuD*S2gn/r]JlQeS6zJ};kK;,,1.j إvo ,$1>^Ȣ܎.6DIYn: ï{X(DZ~_G" VeQY96!zP?і"6 LwiC&DbN۩)Í `>RmZx(tVxGP*KnIQkevD-e6Wښ;aLׁIc%+]D!A?RdFmt]r'rV)6Zd@Lcٷj2%m5J9l"b{|qƥU9(.I3Nu7KTV}6(J3 ܪ9SZwϩ!3 wsZQ[|<.vLqwzo$Ws ^$:w_s>s4gu/Pݸ?X-ܩޖ7֝Ns%@R_Φ~ KPzcOoϝ VU EO#3'Erṣ8{4̲t:2nߵ5^WzcI3Q1SN`24f^Gޢ7[0ųnZbiѷՃL\$a #&q0S82]ne* ϗxKwDFxguvC$c?OƶQ _+{$yGgNP QIodyjpAejJ]b4U}ڔ@jiY}c|_+N)"@<ho *ؖwɗvkSRG[BsOjos459!$e `(mh_o&̹.}0pT*1lSz4~kKƤ.V&/"St4Z0h"?1`#yA|Ἒl#$:Ub$v %uNfwdz8G{cTlݡ~4!C`~kh *qw:;N@FϷӖ藆Suf5l$Um}&Ƭ "?LU0غ=m9d##cˤ|S RLGo2!#9[ɪi^} òC@HaY: ?v.bl/R]')1IߴyU_ojO^x!ǥҩ lASXsT{*/LrK $c=Xr^S;əzn| 9VoBs~9l[mۂY!/] H2q YJa=3 lowQ;e髇u6PY'hI`Ƴ>`>NW (\zҮenm!#a \EjgrOelo2_?|CE$2q輇y4-7icsXB}|KJɒA)vOM_Mn i)+;Z [0&^R{3%v'ޔl:){vc4~ESa)K<멱Gº |̇Tȕ*W$QW`{[ x+47nD͈,SYs.wPA씌 2g]2[c _c޶2&NW21fm[_6}Mr ~5x3sS70&@z øڢ>] JI^_$^_ě@1Á T2]7ؙLnv Mqqѭ~ɣ2 $(鬒9rF68-H2!W,iCe 4]n|6l9(~лw<;&!ym3DF; [EZ*r[ ö9"+Yx5ee&Q2!v\/E @DnQ?g-lfd#ă#9 1zDn=֌ ӮmGͨ:\.ge+lݲ z BJkZIuKrPԂ'VHBH}Pv=,`JZ̊.*'2vG"bV7`C"9,kx$xߐYvR^%lc3_h&ecp8ƗV Z_*C#"9j1i\HDWKJnTig/lֺ(7cKCWWTI Goх"t)-6l>XbwڹųQN8Q)S{F6ƞz3dnSm\zi.mq-Ɉ񿒨hxZwS?#XIVA 7*~ّ]Y"6\dl8pzs$ď5-|1Gv$ Y7&61s3[!@Zz Ps daKko)5ӛ;Hgax(!2xmlDzs!ǂsv-%&`zo"^Eq4Ynh3hlхwafGqkaq/u "}OQDUȾ)?Tz%r4SFγ($ŴIVyxI\B)pSuT­3(V~_q}jd#.rZW2FB`tFKȿq0`)N(J74UTltWZû]LJtXCNC8O?iSan7i0\$׉"PEUB51mC 4pDq(|m)жK߫;uX{MaքB9|^Hu1qE@x3)PUl0($1vG3e"oڟ*1ʶ?-CjIRbAFemŞiIx5XZ,=mD9޵eeN}!"KRdW₄i&ڪҬ>M͏-K8]Y ygmw(!jJ3@TS'ЫF,|ϝLǁwq\>.c ۇO#~wv8 }j cS;g@,nG[נ LP2/xN.Geh)p%3 nʡ8Q<]X 'O3/ ^~+sH@FymA &iELBC8m%diC-$"|Aw:]ԲH6Ѷ'z_1Ԑχ n6W^~;aCЗ*_ڐ S}J$Rх$%"߻n@BNŽKT&SbL)$ S+n ]3|4t:]sҞ49oV6 ྱoj~>IޣS^n|CĞ_ +P5ziT=w%zAcRLy^ed&p~$HQaKj{{QyJo' Qɪ(g 9mH!S+ްԞ'-oŶN.Uc$߽\lLÆp'"wBWk&ҿb~NEyŻx>Q*Tuy ܟזϣz_QhdBr%\Q4pA;Zx~ ;v(zʁ#]~cfOv[opIQ$0O/N0 hdj-~k1(zx#˰ٌwf0tCdz K~` d:3HR#)t-]&t:8Eܤ-_s^ FM} ?\vşMŮ/CgP:܁WGZ+Mv(Zv쟧ld(ΧiK}Xӷ.,16B 9j'MdRnr4kjcO9ƥfL֌2+\CZBMRfV .P;7ܓ>7e3=z]BԻ}lMx!O,kУd 7CwxCR.ReZ<=%/EOtBAQ ( _1s-| a}xϼ*2ڰ*K`{́(Vɥ;4[_$ :xˆD >PcZUcT.4#Jڲ;%S{Ye.ݾ7EIT'sRQX5@UOhW5QB$NcDnB"oBF,y`»/K x;gY0boeuZ_o15iw3`p9<+ $|1sYBiHw+a5}{@Q}mVC$] e_\z(C.b+ɻ5G c YD>IRB^ɻe[ݘd⏭/[tDbtqGm?5nUis mW]Ȭ;P\"-%J406 H}&=ɭ g Dhv@15tm=/WDeB ?1(~#Ÿ57\(KݣysH$A/>J?FWoW|ʟ/!cQvC6[9fLFFb20]7n<89 3؝~Tb'0&"M hsF/ctIh.t')XiR*xhGiYe}T2[B8Z zh>!i 8g 7"s/7:&X 99%2=*I2?2"<6_aa>uvZPU/CTbIk3JLGh\?LLe8cAs}v:ؒnuЀiɃ%<q)=HfSd5tC_og=s8XJ%(}q|Lh3>taViK+DfvGQ_e"A)idig?4jd]t_[ƕ⋭9DKm:vWIekp™TrNvK~$*+Jw涯Yʃu2֖g!S3zSi |`qla;BN-z#YTͯ0/܌g_S2r4Ջ凿*hq~cye< p-Ӑ%c+Q{.ގ4e7fu맼G[P/ !@Q0)B&8Q['zˊYnhN?zp5lO*A: ;@zJ"??srs+bI>t<:d Go e6{uΝbCib?lNd}s溊vG8[bў i{E{(:݀;ۥQAz]<+ΩwU 5xq2蔑)]:Ji>PO팠}~s \j]Q34" +8Q<O +;Ovո=uns)QrUnMEB.լgf.fll5mM}NP YMfoml_Dqә۟f)CZը~"|'`Z&" ]ڣaXrn8ڤ6Bl)QH:? .GTxKC5LH&`ƿA3Obk5`*tVʓ3˄ɖPxkmb}L~px#2#Ӟ3ķ@ҮpGT\5Yz/z摉z''v0ݜ>Di(Kj_ͿEW#+JHx,)r)k5GvJk z ?m!f;YRȳ2& ԙB ] U3Ca.K -Esmb0IIRE4_0P-y#)CmP$WcDxt#A S|"{`Ȓ5;Y}#V$Xa&~qswkbŴq|v}L:Јҋ)ҝ."J<<ѽ&#ƼcrGPTj\']3x^{ r^񖦸pbXFUgŲ)ZwG*Nc^1m ŃD;~"RZC𿂎5/'0 ǹ#N5A~\v8@OspF|%gXptgaѣ .e۷?~V%\BP.^ R?CŔ9"&oҕ"kB"{ߣ+Z 6![}OX"Pєx򥈥ߕ[t/Y}i5uў7gWGPS}V8>V-v*!GR_vīVk$+Pg!$Ƨn/h-5'ȲX:J&-wb\jaLVeI>RH/$Z@/El͎],:Z))@֢j6ik&'- .)T?+X5` gpE\ <<~5OX4EĄ]:T/'u,{Q3MܬӁ\Q@E-߰~D/vyqpJHry7RX '9x[ԗ39;jB\M%j1U>V&2 cϿRϭHAVX&q |gR}*̫I?{aƱIOM`f 9=ٵ 9Fw@"AfcBbz0!}F6? ǝL5EFq2LS#`=ʎU_ч鏲>"pzחh9N6.H!Ӷf]=d# a Ҋ:ޑxc G\=`^,I'? xM'YDă< swA # VZS;~NΊi.V!zRK0e;F‡/D)bמ;!ө4OF)ܪa}.OvDsk/{Zjo3isԆ,\²mv`eKJ [5}_5$b@ZcCNg)e\$OF!/<ᤡ3h#76㡡pDpx(ID-k״aȋ?!SH.\vfHОZJd^&(n:@)ǶzC:_܊8A"eH`*9K|Qg68);9g{An'M qL@5EBYVf D%2)dgn) XTBj,6"=bDGqGTKj }2z5Ku\ z6JA3!WJM» $zӏ΋(Ô߄VȆ$86nOCD_g $Ha»W|oi;7Z&UyHQ\}xƀx_LGB z <,K ¢9lJ8*2 ߢˌ BI6khmeQ|_g 9xÝU} N-2WQL7"^oUB+Pԑ]k)0C7dAueFR7q -J>樅Y[*à֫D-jyO׽FV4GpZ(`G&`"n4f}V ^ P/Oā~TI"|aTC+NOl7N k %D}OSDlsT]>,0xLEa-'Xi=iS7-) {uEOǺ U#{מ WvF3c?s "3 䑊[hSKdm١ɤ M!X^A!L+l^ (VI.IE$ 7glpW "@ĴŨw htb׬_3H8/58ܪ[#@tFX$\ ޮa5yP+sBnH߶Jkr.\}~ B1xk !;\) -vjwL I;IX*I9Kuv5Uq 8.)0a9?d;]䢲VD2.p:3/h=!mxP={Ӄ_krٝ3LRm@9;PCD".ɕNj0٦d$l4",E&D\t,/ztl!_8 _#5sj&`&1s$YFyϗaF]3>LnL[9{G׶ C[W {󞥬AXk~!R)/{6%Z6 >Lyދ*,QCm,|J68L[XtQ2e(_θ$`S8@8 dCƝK)EZozV?LSbjPz @_ z ~SICM濇oJàV†cprtmg&+٬4 yic>G't|):&7f-)[cV|zڋlw.ڋ|te3a(j'ژs8XeFH[,Z`5ox݂J d-]lr UOꀜBU 3:^Q~l ">zUdHϗ_|(w4Ϣh'>VMĎT!'ݥy]}R:-+]m[C2yP9jI<OwBT4= .SV 1h=g^-k'#-@"i EwKGRF2 ̃ML J [\ z.le6W`Nb73lkX]D_+&HAu1`[hZV#J ;їGVcwz3?Dภlpe'sZ4};!7- SI{Q1b: \dR+|ЗJ-k3_H+ϭ~۾De$6yC̫6eœZj(R.5W1tj࿆YOelϿ՜wf U,\A(>Sܯb( -TQn[UO,oPF7{H&7OWpn5b#r%029Yݵ!5]+N+ͬ LT,?G]TN.}<5l\}X!B;;i0eCjඃZ.@i V %.L]R ]d3sjmeDTDΰ!l t>]^3aSPnk$(3q~؁I gb+N$m͹ iB1긓 HӢ/*LN&=S{UY;xfb4Futh TSg7$َȘbyg09de:β/pmԨ:)ׁ6}>aC+dmJs63:e`${ nBSP5Tr;-[ y7u$":>ՊqR!b۷3~d ;'}FY|SԢ&LFd1ǯgN8:*7"j̚ef W,. )խT(MbEJT;ż]m % ޵o]n L@MlPcFQ:?4nNNyjݎ~ Ds@OmT]n!ebaT wٞ-i3qV!Ml"r{s APqC!6~HW#yq׌t}&;^&!i9m9xu4N8Ysr{;OI_F6%/skcu9Eqe]ǪVLM0xG^AL!_vucdWWxT-ˍrv!ePH^k^Œ">,R?MNƼ'ME ErtiFob>YlӉ;-X զ 3o1B V)c%!jZT݈-+u/V<Л/j[el (i i$Xa\_$7O<%U%=kBni>ǚm${tAGgqH>.ePAQi)!4":|הy%7;A.9vɭ`^&IE!i: b~[}롦AhLN 0E"ku!ّsihHc: |gin@ > (ʘz~tb~p +"C#HĒq xڵk}=OV\6dՏkYbGp^\b89f3ѢK ΥqVRY_5^nHH" IP=B 0lroXl%},;YiDF\_P!ZȌwrD\kyBv5-c PbFrQV|`4tz=2CljSZK6k(7AKyy ˉ>b<:4FjX(Pr߃6vJBEeHO"W~'atWsnY KA=~ߛFjٸsȱPz{3f.UrMŞD]1K;̪~kR7|}Y~wUSgfrI)@eCp^ogU)eo)s~ZGob&h1Lm@?^Ж[;-hcc {@DD 9~9ڶT t-fvtT@*_(޴chXZ?t?13q"I.J9HS0[,DCzӞ!F%3 N^sVRUo!Fql)F6ҁsv)IG z(u>a=[ -c}+ z`<76Hmax42h)cf^m2\5g\#-rav)~TL lY|JkZP0"JסcTWd=j|6pj ߇`m!C '*̬msQz}h}1u-:#n1|F&YmkQ΃̑Xծh䝘!z't&6֙8.pfGCOngA8I"*Yb/"EE Adf U?cS\R m(kxJ T~׻dnÈI1Mh]WJ^M/C :a;ʳ5| ZZkAIVl1[vO>G_¡ jltl/:MtJ?nw4#?!JNGB3|!q,GhuZ c}H??Ɗ'>S_k沕ʼ%[E)J" m%2{F{QPM/ȵaWUvgb)?nh!p+ 3nur^ 7;(Gr .D=0[e?f%-J !.ip2%FlF☱Hc%Zg(( >$m8 3Mwи*BNTJDÍCrҚl_rXW VM'%68K᜷l2X˓=(h|@Ur5:^6GLzwFlogi ==B)w֯/MY.Ԁ3uiAIgbȲ\oe»~{_AzUJ#J{40XX!¦5K: $$*˄@!n3q;"u{Moq?@x3?PQ'Z^t1dɞ;>4(Pӈfcb놏gDZL SI>7Xw˜^(d NtnmPBHuh/Ni/Ҹeѕ(T#V7'ae˥71^݂ v>kEnMFmv%ߕg->vS+]PUfV]pYn!.B5Ü:F5C\70Cu=ЪFM.2*AȔ|z7 笁P%.3EXgb&o c9~Cfi L$c6Vl#3k9$Ui],{mi-$Z(V$GKet<>/ROlqU20m ̱&B)Dٽ-kcneYR=Yڙ?-1tI3f/pI{MaLrWohx=lӱ,c lgP5DfKJOXT3 k?ɣ|gZ *#8/ZQW4.,5pRMf@50X#?a*=1<W^`!şU|OT zJ =f&'Q^ Y,o;Qke/,w'b}$3x[D6  1gX  Th>9vrTwH=z}MZȣ*崈>VWzDem'%+gDZVxٹTOd\R8@t h"A*arK8j \71Y6_z$O&qdXr5B" y@s~B*i&ϫsMr!ByB_#ѺQVRtZĤ_E0p?WՌj`zʾJm{lHlG5*ds51Ѭ@ɃP)Zj4+(6^zIbr$DU0V`*Ovx͖^+=WRǕqg1HŋhA1ݲU`>ѕX`8fZ-sN/)jŠFm~4 QOuTmG H`4wA/<)=<|٬~@ԥz"Oq8y?a"PWͱW^Y!1[z>vkhC{do/^0Y@*w~7. ʪ&fXN TOMJhA٤;oAAҿ(_NS. EA%^CɃ/1#qphe~0{\D]3)xZ~,B2{Gg<^!Ė:7bmcލCu_0QgX_\C)qūIABئr^?AGMg7[1z}v|@Iay4%+GIn/Kx 2j;8T\̑2})tDj#[*G?+ / |J>3zc'd(wq?_;!N|6̉ 2۫GQWHrkoJ20d <&q<\f\"ie]( xeߢG#+ĕVY}~ϋ _)T_]-X' ^c%Z5^;NMɕǥṄ7ЋaڿaZ%R HdLTBRx43}3 ż86Iw̷(+>dWubA!iJصvE' J{1.p_'{+2@1G\kAs˸F6iB pۋ8 O;ʐU*9V@Y'zŅўqk}sCX#C:PGC=b>JT2=jdY3yⴧ7)feKp`:5RMr:XWp<ձKX+ Ҭ~_SaCb/L^L/UX8V_p-h9k%:+yw ۚs[q#ևтsR{R/Gb#7qY_`A#~$qP \ |uе~(;)AkFCb披5 P1'-YpC!֎zkLH$غ6, дoEt >Ɍ3٤23$%dE7 ;mU786uL`G&ρѱ"_5pk|RI]Δ1XVylMX.-<_$WØwy~^_jZroxϭ09k:מ,XU 1ߝoXnSKEc9SOFv))"x7[&fw)ovhb.WB@;sAVxLHl9RUq3X!/&|!IYg͎h`ĩsRUZҹ~gf rF=w|Wy Ƈs@FWݘB?ɶzMNGqN2Zcp:3;2[^i $2LIYw F ɑR#T8Ψ?-TL:'Ac+y;Wn #.i! K =4(Nr0MoNg ,(eDMeXt4#,#oX f;\Oey/C2(_k|5oxɷf.BM=J@g%"=9mR];89~/Ktj.5SIIoFnP&u[ 瞚֣ D˼3RZqd^O TL"-P̉\@8u8SG{b/e^gmtx$N$2,";6_I*dn n/IS/EC#b~`<op)If)4ED5aAOB;saʶknjQ~mO8<8ƔK8sd'S=DؔQ:ߨ+&ʛ4)aOcYYQԆ*sQz:z7嶡_RcL|Ȕ>Jz!]?U옕9,E2YWS6}{ar+0~N-5Pfx4#Gc.n= g}}$OHH+j Ɵ\ItE-C@5<a;PI]М+DS(a^mqx}fEYæXS<"9D`x[X5U4cD4TƜR۬䧶gʲzl/P5Df*"{#[9 [a+%M.1l#)\fvNX,#m)~hM%ƑZzkBM(Xol'ԷTh7wkfi;Z݉/矦bP(ճgJD:W%#ӁO3XR^#ldK'ʹ"TfVnӦew\G-]6 iF8Z\Y|Mpu #Wq2i+2B]a6γ[FSYMːI\2!qqG9L'h8+} N l*Q3h+ PUC&>|%mzCױ'(4 O@=X$`bDK0d7: G׋flYg{5g2>- -T[oAБs_8M9;b.aƏ;Ƈ`:b\4}nA[d1Qq%܅M.~Yp@֥3*Q$V] ꌭrԫt5 V6\In NI3lw*(+vk$Wt!>f!ǿ[1r\OSmo iI}_n^lkOW,OO# dː!X=}ucS):?*dMT5WA6ԌepR¼l4'Me,M;2Qk3% YFҦ(xňN`k7B&Ss8D4ଞCQ5_3@U::衱xxx]4|Q:!Z5T Y f'Ue0Dhs)>d=`pTEz苀'@ay]UghYqfFL1V}I^W:ٵs\>y&'_@&Wq+ !=ف-9jk u b݌[&HZg/v#5@a6k}k0xq TE(cu5 P(mǵ; u|bh\:ׁ*b|38L2[ǾNjޛŃ>a[W&u}fs\Uovvc}[B/gsM?F؁hglҬrK脊q:{}~~Zrέ}MAwE_5z+b<!FgTxb7):F1>3y.roA+㻅 h&X-HCyiSUA. /"6s|'OǺ>{KB¨[GcӠtHP [ܽ8/E?C,@F(NIjj#+bjȡ|,1W4ށ AAKV?2=3QqMiaP*t0V.Nh6 &nhTw7AJ Z Kee6dH6s=٣Q ;k5ū'1K7+S8k}4 "wo 샒b9*Mgw}'N.:y$O8raB~sJվAŨVGq<=bv)og9ZM37Y|Lͼ=]%:6̀,>1fDmLtI&G}>MzӨ:HC54@@ k"~֓/) a=AT)D *vÍ1L>׮0uE`P\Nqq*Y{f pje a^}4Ֆ{&T턂,q6 ğq@q,ݥCFrb|_u\ o-?iuEbO9 nW c$aҠ]OswstHd2hk8Ԑ^]O7T}b=+gq#2UG)Q{ecϕ AI!zLz2X.@eh2yd1T to !1@xOH@Ym"^=Z~E$gp@ ?FXI${( V{$cة<>VEi(kU MEDVb:=4}~nbdyo6~i,JWlGxsC Z7Fn401 y,_} |5Fʔ';Ic@8T>Aa_?Fב LY"yQ *B Dgcr`$kPJ >=w%4F^0"5{; {3jhL)D`(@)s 0 ³(hYE(?[s}0.}o5h9B.,0kt|Ł+bx}W>!?!-k ֣ aa7׀cIZŶ׻ GHgs>lu|7.HkO_<:vy蚞Oay(ջ qt0\mKn;RR[[něZ+0 h9ף L1ǎGX`*>Arҭb~%z !!b+=?EtbKm4&[}-I~mf%]ƐIoI|W=zZ _0 +dy K)bHm)1!Zu\4ͱFH,Ftb 'RO\xpY0KyucW"˵jrzyѻc@4M/!o߳,L'h?oI$hS<~Sl_j0*Q8ır̤l=KGi)s﫺j ڷ2?ZaRVKūuXEj* 0 Yfm)'{o شwרNarN 6Jgξ9Z`ܡ3l HnuۼjGR<7{Ô1CZa17nA4:sS,a\Xq;<p0y4LskK.K4 zjẸF6gz6Srwc*I˘f`c=iiHoѸYB˲:#ğָ;4+5[Y?gas ɀB\YG8m?V-WUItPk"%.IIǀl-y>2Wlհsnڝ@_\OD&Xh0$M&1ZLy^ޑ"Y oکm1rgQJqD_鍴8'D E A!J][&"ji h.!ep#ݫc]@FƞڶH˯5{`izGgEshPHT.mU=D ɂ2/e-(@yxc4UB`,d_N+. }!'" (X:;,W؜X-^BI[GS4cԂEC w\t _تNZhN7O,}kj4Nter֚>_<ԼK/:#֒ȬMNTgpa3Y~Dz9y34FnGzrGkԹ$ %#XEZRT%A&ƣs ]pƤ]-6/`9"*8&7"!8BZy7LEb'IrJgƄA3{jke Џ$YvdR 'R\dNO'~ܒ|Uf5wZ*m\1WU0ab>4 m 5,u=F ˢW|Xf?vOA $cV(nʵpN?b@=Ǹ +J9]8-%jz'M$ @ݙ?YapboKKQt> GPF\Q&{yQ% Q̠k1~t() Z-M?^%aJ49<p8: GRhX}ǴdX01aa,*[KR!x_Vܟ3G4[o{=aI36Y'dOԫ4/~a/&oŭ\?f5JPL|hUog(Is .I$`΍h25ujg,q#cAqK[}Kһg>T6޼z7 4T]uG7NMwO^Y~(JךT sXLet7/n=;S/!n@)r=Ki/<4gn@q$Sșoe|m"K7CPoLs{ɪHMz <t~@kJb@{ظ*䅑j~9b峍}NJf8ՌLxh[.P9FVI6!X5Q/N=8"͔G.!Iro[ĊgUqs7n1#^@}Ĥ4u^@[@}J+35,l`\ܛx} v j]}FUgXS/4+ 'E+Mvv= vӐX u@+LHxB-",(#iWfm+9Ś!Dk~$bUn@b-> 5| ^g k|?P%ڀ|GJ v 42۴Y2=!N@^wRˢbLÍ sg%tXHhiɼFVYGp1@W_ @*;i=CPYҴVɋ%tǦ0 a1R1lwShG5^9nL/Rdi(~9.a'dkfU!8!}"; [E_0 >Pn;s,*(g خgo:{s[ H4w'2Ev)ys?O]f݂d='Kr7b囋eҠ/j]Nw2u]Gbr( Xj"Q(p˸ڼ; :GUIK\.*h_qB`Fx>'_^LK;K.v!78:oPi)r#<(BZ-QsTKicAT{oڏmt;=ᶙt(jMсӶ3Vy"6'Ȥn0 e]vP꼶Y5+e Ovj}:F.s.Wr^\Q3Aٱ5ky|mi,$P:1׮O ?h3o@_cO!8C@KisUC cz9<%= (%~ خ)JКJcmp0'cjw+Kv`TnTc'[ X@F~ x X?N \ `Dx=W]'ai|/}qvU+nsng9HI fI}[ eNͨ<[Ecf$[q;EB/Fѿ(sY@Q>Jts?Lj%֮{52KDiDl=~ŭnrA~> v-@+n8Dk %B0 ӁHy_W90xFQu48!M..@+C1 a i- R;)ĵd0P "ҁZҢ5cIZ׮QboF8%ʸ服WA>tGxwfkTL>ҁĻ4~ϦS4r$\*LF4XP(Lsa8IM@VЇ%e; xD'FȚLWxEP"4t<{ =s(ӏqpo 9,;61ܸN1rn*bh8-wUGgI 9*KN\b#cS+&w壻GFb,K.ɶw鿯 ]5[~+Mf\I+Q="rR[撠u;ֺ“vTؑF,"Pg&]y7vi` Yjʀ!p=d[ߌ ܔF ʠlcm/boUO$ vsr{;9I@`1D?&;BU HLXֶI8DqЛG*i.ղvłv.Y踱ѩ;IZ5/wk1{uTVT?T4wm.nwBS"E>]_2I,= *Ur0>]>WbҜbOvWRE "pG.Hbeb. d[j{N/sfKWom!+ѱ^D2.#jF*hjp\R4sCqpPo3"$`n\gb]vc[b^෾@huU}Ew}M?:]t*V/˴뽕X1x i BZX2"9S\AK"0uI[PzćOkmkmSm+ߤt,[6P6>kfkG5,?.@ۧsq0&yD@ʚ*.eE#D.lFj¹ePZ*eUY 4I2F7H5ѽu$m_ e4лSϦF9 $ `_X ]J֪!d 7#>% -@$xzh1D,dtw)"f9rrK֎˚ ] &SfiFȵ(KO&,veBPY'*hml9 d>铯ޗI(vn(| H4UԚjBI8IC+H6ܒ3O,.V+AC3SڱvƗcxp&h%Mĵ}zq;u*GnSHl%ap q<0c)*Tq\z"Ko<2 tU{=H!ekpW+Wx?'+@9 s"+ڦ7 ,_XpCXKP{*AT?JJB{zo o"'zW7 -U$xI6& d j[e%&Ϯ66.$.er0Ȁߘ{q 5:djw*1!TFN /iI! &}hh_t΢#~xiO_J̄7z~Nt9::[.Ǜd;JP+ozhTvٗFchY;.i#Ta#UoV9.?յhaH150!@i߁wx/5kl- VFN%=@9[2*wpqy qrwGp #%0a}O+M! y5O+OZ%gg'EgD8Sl>9W2+B<58*MaluKbR=-0m1?w4^5XOZ* >Ofoxl9-_aC% [ AfZX=XRV>32r=_&0P #1 tF|͑/EmntM&^fjG@Yg+ﴃN`f Bmkp9#S!9O (/X;yې,Ck#"'}: oHΊ6>ޓ ?{/]m:~'ʵ9쌺đw|--.vEpENRb}'i ^0=ʼ Q_^&+CMа_RI9)3|Ꙁ|K,C=;2dd m ~O[g- ו_r0&']aд1mp%,Ĺ#,bv*U'@o(@5A1#=jxer5">5\Z}+' 3qFnasyԱ0q G~G3Z/#yY,B(cnsts^mr_<ң (KAWT6Wp3Pǩ-Nʳ 7P6S򜳋j>0g<ϖQ MtWT,>8)Pe~;3W=3"ۂC,}DOuZ|;\53O6np4dYY[6q˴cW\U8'Ki,ӵsDK_ >r7z_63JҠ~/X~*S2/ #Q2."FE[AvOr4IP5 LK-oБ26I&S(Q5`j碥D+ ~h=%)h[<сO{ mXM!P%sYː>>yFb2D2^݌ ~8դ{U92ya)AiLB~TYɝ1``wr=R{HNѳJ )y#PwYir;8Բ9S5V~ sˁb*RŤa4zcd -Z'4DSc0e9^ ;Ʒ3C[: GX37iNs )ɻ-v[OҌB۴ormw Lg_˨Z5VpRCqܧ-y{Fw63B#NdH.NGB&]赊`GSM%rS> I^рth^qw{Yڠ(ZqyuYiE%owX m0^+yrdx}MHm@ٗFLLԡ9ں!WC 2K6LcURݭ[._qV8^=GՃ#& :,wvg_G+}rG(Nxו6AZ_3EE2 z,t߃9dhCT+h[oFDo,j_\?!n,!WTi/ߦ阌m cׁ. V_)ɸ2 7NJ~!YAZ%E+j%A 7X8@ckzH\5;pSJo U0fi:KNm KP <x عP|;`ag.)c )>#2g3h_1x:Jxْ B2,"B࢜T]YG:TN-UӐ:Yjԝ0q> >>Tƒ=™"ƿCT?@Due'F7~>WaS{1l[skC&8{D )6d  Bwc|G  g%ot%KYjr(^D#62NW!'%$`+.k";Y֞,Ļ\-D^.I@h;­7Xз7?\@3gX(r_sg4[d?,2,ΰrU#ۓ,;y `2`^:PھcdG !I17]\DPUBCe NCSv܆`b4tO2T7QOcs{&Ś8a>Мc9elv+7d6'}dQ>ۦ# db(g12"yBW%x- u朧?T!~G߅vToo`B!;~܊p!.iwЋ=# W'r͂4gu\=*&@pup(Xus1GWcCM d9kM7LwV\ޘ"La%+5,BѱRɌTp1)P4jӸsH4ѲJH^ؕ BRA{juBV2DKaM#P2u=+'ĬC] ++DOP>䯭:]F5N빴MpthJŶgRORvf>^}]>Ǟś6?4l=;g?L.DuǼ8[#CkN\JtiZn* IF9pġR%"}y@jЁrZJhLOwTqkv)Q;)&J98ŔxIs=҅tӑi1M#/ ^醒`̕q[:NYaӅI+I(x4B࿙pLȖ(([c9:A֪pXOUA)O}CҴzoB,Ѹ$lL$5ОV}%7:`S+n.MmPdDK^" uYp"rs*lN L*K!So3[Q/J٨ !3oF܎xZq.[r:{—:p3S07 }ЪB hnY`WaOnqypa$4:FxwQ/l^t>9^i̵7U44۔f&x7tDҬ8${'`]]+94oVy/I0bH3h#N{ ?3/ +&#\=>OQf)U.t 1Q^*c]uh}*2w3l]viވׁURz BZD?-0Mo!5(VP<Xs)HЀMq 3BIE<iR=|-%.~ VW}5>|O?M$ŷ'; 2*攥n:  -]~Ԩn>CkͺHӔ>YU"h \ .b ,w#NmsBv1-g}-#?T1  QSr/8DBp Viz/ ־o .Rg5~i?~4μ2|<0kko1|Na@~1b?z q2VMC>K0!")ۯgn,Vyackzi )!ܦ=a _xRRl@?sʂ]U'ie _|4>E:6ɉ'EN~fby *mR@wZIwy=ӷށ2OqF&yo-?)j)y궳aIfup^ۉ/X{ ފX/u(?Bް'E'8L" ý:prg$fەD+5g)51X>icK*^@0 B#SC౨{#>07tgлk{3;o^j WR"mq$P JaAjOu`< cll@?#ƾ6uҏlo_V]a% مޭF,4mqhef4ջDrfP2Ŧ9YqR?;*FG/H^R _/a|R.m 컈;gCeu'@| 􆎟HE(AҵA .\856i)tx ^ 9 }1LZsOVg*_;Ҵ;c쾖Nĥ-AR,Smt\f#OT6e)1Zwa<<;" m pPLpnI[Avn8IgxL,]dkU O߮0/{A"5dCp!U4LY^p=?ckԕ~%D@R5H&E ND&XX2>t~flD-5]yJixtH5}Nl `4 P|H:`bVY[0"5mcBLțkhb2,n(uWQ ]~2J"S `GTr`.&j[p9|%!iI>G3/wӶD]&>"A_#D(4KeGK4DD{KT}:?$9N>S!듳3ԟ&BܢW=шPs+R[wNxg2]䖦uvtA$Iꐵ1,UISd=V œӫ@^Tڭxm՚S|5·ψ\X=7E8в,F#LyRN"Y7OVH$q"bMZ}b:zb Lr㕽#wo:Vvu?(h=6-uqiM%8qÚX?0X3—K 767O7@&<eXnit>c_)d(-00bgw Z!h橲s k 6e뉸Mnҏ [a_S,$L`xJveƛmtJ16 $ک1Lxح+[0/5N{7$`{qa:l+-Mw5=yL(RA3|ȑ67>7iڧH$ CM⻐HTJhHErS,.c2#,S~J1'];AR.JE|KThany c񿓐||[U14P 4UR*>5 K]u0͂ంʫY~{KfOf 6wXeuۇLv$k;5<>"8 %߽qK v)ҿ!7c}gJ"E$׮Ïl;@DX?W(2%D͗Rݳv,#+,}$a VdW@H|\B]r~fU4#N 7T9z $ { ?Wa9~% kWFOrb]SN;uܸ%V_Fc=׬{4dLZ?V0m#hqT?XգN ła0#'R-9O=ʽq:^u"ɔ x3x|ɋ8 \ &3]S&4:RS18:l5㖲4eV{is'74 \y,ւe]X)}7J0$)`˱>Y :BU}Mxw@(VW~QA/ͺ;l5M(αa,_0hQOUE3?IfkBS\58RV