knot-module-geoip-3.2.5-1.el7> 6 6`d63!}|J^>j/5,dc` j/5,d妊4_8Gm!ŻÐ!ݧWFJxT[Lf~whc(AqK<2}8wZ-b={͗,_\e&S?p>Ar?xKSLj\>KuZǡ%dk7A^Z$&z^Ǟ3Qi0-'i C`jb6F^Oǟ| vYç}߰Cy#i:\i_mw" zÁt0mмUgm_xs)̻3ya\/hfABbxWO xON\܆bD~B PޘR6d10cf561c0b380c92da0b6cf9facf4cb48074b4 t3!}|J^>j/5,dc` j/5,diNMU(̙~ARt 2CrK;Fpĺ~dPبiqf\uYpF$&:BvDS9oj ~msZb#Ll*9 WWqk= ϸY1'R88 7tvj.x"}UR!2v[T'vmnL753_0,%~v`9FȐ3+”)R39DIQӭHN(A%$7E&ϗb.ȣqjC}aҧi= .}5bG%i8PC=s-۸lt>qZӌUYP '47txT %)7ap2е4qbئ%0/-,~Lh7r=Q,X㤶lEƢ@=IjL-^pa'RYie.E-N;34T'am{j>:n?ntd  : $( * , 0 q tx}((8C9C:CGl$Hl(Il,Xl0Yl8\lP]lT^l]blzdm?emDfmGlmItmdumhvmlwmxnynnLnPCknot-module-geoip3.2.51.el7geoip module for Knot DNSThe package contains geoip Knot DNS module for geography-based responses.cbuildvm-x86-10.iad2.fedoraproject.orgiFedora ProjectFedora ProjectGPL-3.0-or-laterFedora ProjectUnspecifiedhttps://www.knot-dns.czlinuxx86_64icrb8d1437c6f95ad777a029aec734470c37b05a0b98bd3e295097b1bc785289971rootrootknot-3.2.5-1.el7.src.rpmknot-module-geoipknot-module-geoip(x86-64)@@@@@@@@@@@@@@@@@   @ knotlibc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libgcc_s.so.1(GCC_3.3.1)(64bit)libmaxminddb.so.0()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.2.5-1.el73.0.4-14.6.0-14.0-15.2-14.11.3cۥcc{h@ca @c*cobjbDF@b@aՈ@a@an@a9@aj@a @a@`t`9@`f@`c`@_H@_@_E@_m_Z@_O@^˳@^U@^^F]}@]ʞ]@]]2@]'$[ @[H@[E@ZnZZZZ}@Zz@Ze@ZNYYYXƉXX@XAXJX-W#WhWWV&@VUUUUa@UG_@T@T@Jakub Ružička - 3.2.5-1Jakub Ružička - 3.2.4-1Jakub Ružička - 3.2.3-1Jakub Ružička - 3.2.2-1Jakub Ružička - 3.2.1-1Jakub Ružička - 3.2.0-1Jakub Ružička - 3.1.8-1Jakub Ružička - 3.1.7-1Jakub Ružička - 3.1.6-1Jakub Ružička - 3.1.5-1Jakub Ružička - 3.1.4-1Jakub Ružička - 3.1.3-1Jakub Ružička - 3.1.2-1Jakub Ružička - 3.1.1-1Jakub Ružička 3.1.0-2Jakub Ružička - 3.1.0-1Jakub Ružička - 3.0.8-1Jakub Ružička - 3.0.7-1Jakub Ružička - 3.0.6-1Jakub Ružička 3.0.5-1Jakub Ružička - 3.0.4-1Jakub Ružička - 3.0.3-1Jakub Ružička - 3.0.2-1Jakub Ružička - 3.0.1-1Jakub Ružička 3.0.0-2Jakub Ružička 3.0.0-1Jakub Ružička 2.9.6-1Tomas Krizek - 2.9.5-1Tomas Krizek - 2.9.4-1Tomas Krizek - 2.9.3-1Tomas Krizek - 2.9.2-1Tomas Krizek - 2.9.1-1Tomas Krizek - 2.8.4-1Tomas Krizek - 2.8.3-1Tomas Krizek - 2.8.2-1Tomas Krizek - 2.6.9-1Fedora Release Engineering - 2.6.8-2Tomas Krizek - 2.6.8-1Tomas Krizek - 2.6.7-1Tomas Krizek - 2.6.6-1Iryna Shcherbina - 2.6.5-2Tomas Krizek - 2.6.5-1Igor Gnatenko - 2.6.4-3Fedora Release Engineering - 2.6.4-2Tomas Krizek - 2.6.4-1Petr Špaček - 2.6.1-1Petr Spacek - 2.5.3-1Petr Spacek - 2.5.3-2Petr Spacek - 2.5.3-1Petr Spacek - 2.4.1-2Petr Spacek - 2.4.1-1Fedora Release Engineering - 2.4.0-2Petr Spacek - 2.4.0-1Jan Vcelak - 2.3.3-1Jan Vcelak - 2.3.2-1Jan Vcelak - 2.3.0-3Jan Vcelak - 2.3.0-2Jan Vcelak - 2.3.0-1Jan Vcelak - 1.6.8-1Jan Vcelak 1.6.7-1Jan Vcelak 1.6.6-1Jan Vcelak 1.6.5-1Jan Vcelak 1.6.4-1Fedora Release Engineering - 1.99.1-4Kalev Lember - 1.99.1-3Jan Vcelak 1.99.1-2Jan Vcelak 1.99.1-1- Update to 3.2.5- Update to 3.2.4 - Use devtoolset-12-gcc on EPEL 7- Update to 3.2.3- Update to 3.2.2- Update to 3.2.1 - Remove patches included upstream - Update Conflicts and move to knot-libs- Update to 3.2.0 - Patch: fix tests on 32-bit platforms - Patch: revert problematic hardening of service file - Patch: revert config improvement to support EL 7 - New knot-dnssecutils subpackage - Debian compat (knot-utils vs knot-dnsutils) - Remove bundled(jquery) version as it differes between distros- Update to 3.1.8- Update to 3.1.7- Update to 3.1.6 - Use _sharedstatedir for home- Update to 3.1.5- Update to 3.1.4- Update to 3.1.3- Update to 3.1.2- Update to 3.1.1 - Enable XDP on ARM and improve XDP config macros - Remove patch included upstream- Introduce a patch to fix tests on ppc64le - Use autosetup macro to apply patches- Update to 3.1.0 - Add missing BuildRequires including new libmnl for kxdpgun - Temporarily disable XDP on ARM until issues are resolved- Update to 3.0.8 - Print failed tests during check- Update to 3.0.7- Update to 3.0.6- Update to 3.0.5 - Properly escape BASE_VERSION macro - Include module dirs in main package- Update to 3.0.4 - Move dnstap module to subpackage - Move geoip module to subpackage - Remove redundant VERSION macro- Update to 3.0.3- Update to 3.0.2- Update to 3.0.1 - Sync packaging from upstream- Rebuild- New major upstream release 3.0.0 - Sync packaging from upstream- Update to 2.9.6- new upstream release 2.9.5- new upstream release 2.9.4- new upstream release 2.9.3- new upstream release 2.9.2- New upstream release 2.9.1 - add EPEL8 compatibility - fix unsafe PGP keyring permissions- new upstream release 2.8.4- new upstream release 2.8.3- rebase to latest upstream version 2.8.2Knot DNS 2.6.9 (2018-08-14) =========================== Improvements: ------------- - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation Bugfixes: --------- - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_RebuildKnot DNS 2.6.8 (2018-07-10) =========================== Features: --------- - New 'import-pkcs11' command in keymgr Improvements: ------------- - Unixtime serial policy mimics Bind – increment if lower #593 Bugfixes: --------- - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy #589Knot DNS 2.6.7 (2018-05-17) =========================== Features: --------- - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) Improvements: ------------- - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination Bugfixes: --------- - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback modeKnot DNS 2.6.6 (2018-04-11) =========================== Features: --------- - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation Improvements: ------------- - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination Bugfixes: --------- - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)- New upstream release 2.6.5 Knot DNS 2.6.5 (2018-02-12) =========================== Features: --------- - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set Improvements: ------------- - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates Bugfixes: --------- - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations - Failed to generate documentation on OpenBSD- Escape macros in %changelog- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Added PGP signature verification - Added integration test - New upstream release 2.6.4 Knot DNS 2.6.4 (2018-01-02) =========================== Features: --------- - Module synthrecord allows multiple 'network' specification - New CSK handling support in keymgr Improvements: ------------- - Allowed configuration for infinite zsk lifetime - Increased performance and security of the module synthrecord - Signing changeset is stored into journal even if 'zonefile-load' is whole Bugfixes: --------- - Unintentional zone re-sign during reload if empty NSEC3 salt - Inconsistent zone names in journald structured logs - Malformed outgoing transfer for big zone with TSIG - Some minor DNSSEC-related issues Knot DNS 2.6.3 (2017-11-24) =========================== Bugfixes: --------- - Wrong detection of signing scheme rollover Knot DNS 2.6.2 (2017-11-23) =========================== Features: --------- - CSK algorithm rollover and (KSK, ZSK) <-> CSK rollover support Improvements: ------------- - Allowed explicit configuration for infinite ksk lifetime - Proper error messages instead of unclear error codes in server log - Better support for old compilers Bugfixes: --------- - Unexpected reply for DS query with an owner below a delegation point - Old dependencies in the pkg-config file- New upstream release 2.6.1 Knot DNS 2.6.1 (2017-11-02) =========================== Features: --------- - NSEC3 Opt-Out support in the DNSSEC signing - New CDS/CDNSKEY publish configuration option Improvements: ------------- - Simplified DNSSEC log message with DNSKEY details - +tls-hostname in kdig implies +tls-ca if neither +tls-ca nor +tls-pin is given - New documentation sections for DNSSEC key rollovers and shared keys - Keymgr no longer prints useless algorithm number for generated key - Kdig prints unknown RCODE in a numeric format - Better support for LLVM libFuzzer Bugfixes: --------- - Faulty DNAME semantic check if present in the zone apex and NSEC3 is used - Immediate zone flush not scheduled during the zone load event - Server crashes upon dynamic zone addition if a query module is loaded - Kdig fails to connect over TLS due to SNI is set to server IP address - Possible out-of-bounds memory access at the end of the input - TCP Fast Open enabled by default in kdig breaks TLS connection Knot DNS 2.6.0 (2017-09-29) =========================== Features: --------- - On-slave (inline) signing support - Automatic DNSSEC key algorithm rollover - Ed25519 algorithm support in DNSSEC (requires GnuTLS 3.6.0) - New 'journal-content' and 'zonefile-load' configuration options - keymgr tries to run as user/group set in the configuration - Public-only DNSSEC key import into KASP DB via keymgr - NSEC3 resalt and parent DS query events are persistent in timer DB - New processing state for a response suppression within a query module - Enabled server side TCP Fast Open if supported - TCP Fast Open support in kdig Improvements: ------------- - Better record owner compression if related to the previous rdata dname - NSEC(3) chain is no longer recomputed whole on every update - Remove inconsistent and unnecessary quoting in log files - Avoiding of overlapping key rollovers at a time - More DNSSSEC-related semantic checks - Extended timestamp format in keymgr Bugfixes: --------- - Incorrect journal free space computation causing inefficient space handling - Interface-automatic broken on Linux in the presence of asymmetric routing Knot DNS 2.5.5 (2017-09-29) =========================== Improvements: ------------- - Constant time memory comparison in the TSIG processing - Proper use of the ctype functions - Generated RRSIG records have inception time 90 minutes in the past Bugfixes: --------- - Incorrect online signature for NSEC in the case of a CNAME record - Incorrect timestamps in dnstap records - EDNS Subnet Client validation rejects valid payloads - Module configuration semantic checks are not executed - Kzonecheck segfaults with unusual inputs Knot DNS 2.5.4 (2017-08-31) =========================== Improvements: ------------- - New minimum and maximum refresh interval config options (Thanks to Manabu Sonoda) - New warning when unforced flush with disabled zone file synchronization - New 'dnskey' keymgr command - Linking with libatomic on architectures that require it (Thanks to Pierre-Olivier Mercier) - Removed 'OK' from listing keymgr command outputs - Extended journal and keymgr documentation and logging Bugfixes: --------- - Incorrect handling of specific corner-cases with zone-in-journal - The 'share' keymgr command doesn't work - Server crashes if configured with query-size and reply-size statistics options - Malformed big integer configuration values on some 32-bit platforms - Keymgr uses local time when parsing date inputs - Memory leak in kdig upon IXFR query- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble).- disable dnstap on RHEL (depedencies are missing)- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble). Knot DNS 2.5.3 (2017-07-14) =========================== Features: --------- - CSK rollover support for Single-Type Signing Scheme Improvements: ------------- - Allowed binding to non-local adresses for TCP (Thanks to Julian Brost!) - New documentation section for manual DNSSEC key algorithm rollover - Initial KSK also generated in the submission state - The 'ds' keymgr command with no parameter uses all KSK keys - New debug mode in kjournalprint - Updated keymgr documentation Bugfixes: --------- - Sometimes missing RRSIG by KSK in submission state. - Minor DNSSEC-related issues Knot DNS 2.5.2 (2017-06-23) =========================== Security: --------- - CVE-2017-11104: Improper TSIG validity period check can allow TSIG forgery (Thanks to Synacktiv!) Improvements: ------------- - Extended debug logging for TSIG errors - Better error message for unknown module section in the configuration - Module documentation compilation no longer depends on module configuration - Extended policy section configuration semantic checks - Improved python version compatibility in pykeymgr - Extended migration section in the documentation - Improved DNSSEC event timing on 32-bit systems - New KSK rollover start log info message - NULL qtype support in kdig Bugfixes: --------- - Failed to process included configuration - dnskey_ttl policy option in the configuration has no effect on DNSKEY TTL - Corner case journal fixes (huge changesets, OpenWRT operation) - Confusing event timestamps in knotc zone-status output - NSEC/NSEC3 bitmap not updated for CDS/CDNSKEY - CDS/CDNSKEY RRSIG not updated Knot DNS 2.5.1 (2017-06-07) =========================== Bugfixes: --------- - pykeymgr no longer crash on empty json files in the KASP DB directory - pykeymgr no longer imports keys in the "removed" state - Imported keys in the "removed" state no longer makes knotd to crash - Including an empty configuration directory no longer makes knotd to crash - pykeymgr is distributed and installed to the distribution tarball Knot DNS 2.5.0 (2017-06-05) =========================== Features: --------- - KASP database switched from JSON files to LMDB database - KSK rollover support using CDNSKEY and CDS in the automatic DNSSEC signing - Dynamic module loading support with proper module API - Journal can store full zone contents (not only differences) - Zone freeze/thaw support - Updated knotc zone-status output with optional column filters - New '[no]crypto' option in kdig - New keymgr implementation reflecting KASP database changes - New pykeymgr for JSON-based KASP database migration - Removed obsolete knot1to2 utility Improvements: ------------- - Added libidn2 support to kdig (with libidn fallback) - Maximum timer database switched from configure to the server configuration Knot DNS 2.4.4 (2017-06-05) =========================== Improvements: ------------- - Improved error handling in kjournalprint Bugfixes: --------- - Zone flush not replanned upon unsuccessful flush - Journal inconsistency after deleting deleted zone - Zone events not rescheduled upon server reload (Thanks to Mark Warren) - Unreliable LMDB mapsize detection in kjournalprint - Some minor issues found by AddressSanitizer Knot DNS 2.4.3 (2017-04-11) =========================== Improvements: ------------- - New 'journal-db-mode' optimization configuration option - The default TSIG algorithm for utilities input is HMAC-SHA256 - Implemented sensible default EDNS(0) padding policy (Thanks to D. K. Gillmor) - Added some more semantic checks on the knotc configuration operations Bugfixes: --------- - Missing 'zone' keyword in the YAML output - Missing trailing dot in the keymgr DS owner output - Journal logs 'invalid parameter' in several cases - Some minor journal-related problems Knot DNS 2.4.2 (2017-03-23) =========================== Features: --------- - Zscanner can store record comments placed on the same line - Knotc status extension with version, configure, and workers parameters Improvements: ------------- - Significant incoming XFR speed-up in the case of many zones Bugfixes: --------- - Double OPT RR insertion when a global module returns KNOT_STATE_FAIL - User-driven zscanner parsing logic inconsistency - Lower serial at master doesn't trigger any errors - Queries with too long DNAME substitution do not return YXDOMAIN response - Incorrect elapsed time in the DDNS log - Failed to process forwarded DDNS request with TSIG- configuration checking was fixed to be compatible with Knot 2.4.x- new upstream release 2.4.1 replaces old 1.6.x series which is not supported - configuration should be upgraded automatically using knot1to2 tool - make sure you reviewed the new configuration in /etc/knot directory!- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- new upstream release: + fix: False positive semantic-check warning about invalid bitmap in NSEC + fix: Unnecessary SOA queries upon notify with up to date serial + fix: Timers for expired zones are reset on reload + fix: Zone doesn't expire when the server is down + fix: Failed to handle keys with duplicate keytags + fix: Per zone module and global module insconsistency + fix: Obsolete online signing module configuration + fix: Malformed output from kjournalprint + fix: Redundant SO_REUSEPORT activation on the TCP socket + fix: Failed to use higher number of background workers + improvement: Lower memory consumption with qp-trie + improvement: Zone events and zone timers improvements + improvement: Print all zone names in the FQDN format + improvement: Simplified query module interface + improvement: Shared TCP connection between SOA query and transfer + improvement: Response Rate Limiting as a module with statistics support + improvement: Key filters in keymgr + features: New unified LMDB-based zone journal + features: Server statistics support + features: New statistics module for traffic measuring + features: Automatic deletion of retired DNSSEC keys + features: New control logging category- new upstream release: + fix: double free when failed to apply zone journal + fix: zone bootstrap retry interval not preserved upon zone reload + fix: DNSSEC related records not flushed if not signed + fix: false semantic checks warning about incorrect type in NSEC bitmap + fix: memory leak in kzonecheck + improvement: all zone names are fully-qualified in log + features: new kjournalprint utility- new upstream release: + fix: missing glue in some responses + fix: knsupdate prompt printing on non-terminal + fix: configuration policy item names in documentation + fix: segfault on OS X Sierra + fix: incorrect %s expansion for the root zone + fix: refresh not existing slave zone after restart + fix: immediate zone refresh upon restart if refresh already scheduled + fix: early zone transfer after restart if transfer already scheduled + fix: not ignoring empty non-terminal parents during delegation lookup + fix: CD bit clearing in responses + fix: compilation error on GNU/kFreeBSD + fix: server crash after double zone-commit if journal error + improvement: significant speed-up of conf-commit and conf-diff operations + improvement: new EDNS Client Subnet API + improvement: better semantic-checks error messages + improvement: speed-up of knotc if control operation and known socket + improvement: zone purge operation purges also zone timers + feature: print TLS certificate hierarchy in kdig verbose mode + feature: new +subnet alias for +client + feature: new mod-whoami and mod-noudp modules + feature: new zone-purge control command + feature: new log-queries and log-responses options for mod-dnstap + feature: simple modules don't require empty configuration section + feature: new zone journal path configuration option + feature: new timeout configuration option for module dnsproxy- fix post-installation scriptlet (RHBZ #1370939)- endian independent DNS cookies (fixes build on ppc64 and s390x)- new upstream release: + fix: No wildcard expansion below empty non-terminal for NSEC signed zone + fix: Don't ignore non-existing records to be removed in IXFR + fix: Fix kdig IXFR response processing if the transfer content is empty + fix: Avoid multiple loads of the same PKCS #11 module + improvement: Refactored semantic checks and better error messages + improvement: Set TC flag in delegation only if mandatory glue doesn't fit the response + improvement: Separate EDNS(0) payload size configuration for IPv4 and IPv6 + feature: Zone size limit restriction for DDNS, AXFR, and IXFR (CVE-2016-6171)- new upstream release: + fix: Transfer of a huge rrset goes into an infinite loop + fix: Huge response over TCP contains useless TC bit instead of SERVFAIL + fix: Failed to build utilities with disabled daemon + fix: Memory leaks during keys removal + fix: Rough TSIG packet reservation causes early truncation + fix: Minor out-of-bounds string termination write in rrset dump + fix: Server crash during stop if failed to open timers DB + fix: Failed to compile on OS X older than Sierra + fix: Poor minimum UDP-max-size configuration check + fix: Failed to receive one-record-per-message IXFR-style AXFR + fix: Kdig timeouts when receiving RCODE != NOERROR on subsequent transfer message + improvement: Speed-up of rdata addition into a huge rrset + improvement: Introduce check of minumum timeout for next refresh + improvement: Dnsproxy module can forward all queries without local resolving- new upstream release: + improvement: Log change of the zone serial number after IXFR transfer + improvement: Document operational impact of various RRL settings + improvement: Add support for rate-limit-slip zero + improvement: Add 'timer-db' configuration option- new upstream release: + security fix: out-of-bound read in packet parser for malformed NAPTR record + fix: systemd startup notifications- new upstream release: + fix: don't load expired zones on reload and startup + fix: remove race condition in scheduling causing delaying of events + fix: NSEC proof construction in zones with many delegations + fix: TC flag setting in RRL slipped answers + fix: disable domain name compression for root label + fix: check if executed under systemd before using journald log sink + feature: write persistent timers on server shutdown for better performance + feature: support time unit specification for 'max-conn-idle', 'max-conn-handshake', 'max-conn-reply', and 'notify-timeout' config options + feature: add 'request-edns-config' config option- new upstream release: + fix: lost NOTIFY message if received during zone transfer + fix: kdig, record correct dnstap SocketProtocol when retrying over TCP + fix: kdig, hide TSIG section with +noall + fix: do not set AA flag for AXFR/IXFR queries + feature: new configuration format in YAML, binary store im LMDB + feature: DNSSEC, separate library, switch to GnuTLS, new utilities + feature: DNSSEC, basic KASP support (generate initial keys, ZSK rollover) + feature: zone parser, split long TXT/SPF strings into multiple strings + feature: kdig, add generic dump style option (+generic) + feature: try all master servers on failure in multi-master environment + feature: improved remotes and ACLs (multiple addresses, multiple keys) + feature: basic support for zone file patterns (%s to substitute zone name) + improvement: do not write class for SOA record (unified with other RR types) + improvement: do not write master server address into the zone file + documentation: manual pages also in HTML and PDF format- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for nettle soname bump- fix BuildRequires for systemd integration- new upstream pre-release version: + DNSSEC: switch from OpenSSL to GnuTLS + DNSSEC: initial support for KASP - split package into subpackages - add documentation building - restart daemon on updated3.2.5-1.el73.2.5-1.el7geoip.so/usr/lib64/knot/modules-3.2/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=88c849da177213da53861ad72c296d54dec46aa6, strippedR R RRR RRR RRRRRRRR RRhttps://bugz.fedoraproject.org/knot?`7zXZ !#,j] b2u y-iSqk@I OKjNMW&J| hPnGMJ'3L'7R|uz;"D9}7(ҏ.C-7Gcۇulh`A`̆I N,e[H_)پ0ҕRv͏ :'<ު%1mɂg6m`1ĉwv0VbQQaK7r`jzC!y ~NjH@$oHgW4,Wj6-afuC3rnX+sjCnߗIgR0%] ٯ~h\G&@TSj!Ob@m;V`QJxpPcsҮ42gʀ/H^G!O0ˊ俜P[] ܊MjԴrf1iZ c[sdWM?MɈơZµ ؃a\f,kkޙ$6L{o0 g̡~>__{(K޳q i -?>)#jןįr´֨ԄYf_-=xK#(eCn>zQS\ϾT0L :*H~a[- -ôD3Qa·}&D!fauiJ$cG)_"U%Y;wf|c&?@z#Eາ{}p~x/d5Cbn Di{b|7>,Q%`qZ]+s?N/*f~Z׋z3£O3VN1~˓,?Ucd Py H/qBOu<:(_n C* lNPJU~tumJ2srt UFDN K,@eMr˂^moUqiEκʠWFc.gᩗ]c޴O5%Fb}zvf1?gg9ϵaB`CyyjoV@5cT>obf0n5zKe 253یP5z2+F* _]2AԸ'gi7h|6ie PӬs )7|%a!+T"x^c;,N2-$ƱX멧 MW('7n0PH|Wf[e9.w+$IBTbYzCKEu B@lK!|DDSe#\ PJ!Y0xrJ8SL8Ԓ$ ?.՝?7;i$ҋۓ;to! pʋVZ1M=SܪY8TH]qnh8M'Bs@2c.M ;Q^SS QۥFK+Fva RlPC&P@Z9?6rR,#۸7׽04tX1wp)P|_@-&0fkRwCEHx;GLUEBt}S .Kuo$,BӋzXtT63pK+xs 7eAɞbUbM$a<)W(p7(Gz~+cQrERpz6I>JD;U|7I뱏ueIr{쿐B @jc~MMS010a_P 4{M{< b2SQ>"6AxQHOBMi}F&Q>!{(vǓFlP[F }f/R A-֓pWf}(B#VYtD?yxUcTa=/ɝ4s&2pOV ,wɑgSZZՆI{6%ϹpJǡ7&.]Sn=_tMʮf[pU9ҽ 1rYLE_|[N4~5/mP/*ԥX.[p=݊P+Fpe2s<*g#β-iG):ʴ= BU=vT;PlD; p3=ſek,!rgݪG1*ttyՔᲒ,z P5w'7"Umj-yK\F=s/Om>UX^pUTT{yi5^b0c<޸yB4N}LFg]j$]|J{7 "X5Ʒ"`L[l߿ jޣ ͉K@yyLg&<P=[蹴E["3vru^m豏*FnZ5k2,(y=ΟYI%r9隣.86=aRǿ[h, 'RpLM$3@Bjc?WP;K&Sϱ\_@_ق$; V]xw1(sߠ8#0iVѸ(~Z`oeFZ嬳, eE\j!@<]Q\#w&m7ٗ-.NMOmO+OYoa[iF`eVQY_v<=DUYv *fXqD+ےLʮ=]7Ӂ9"xe #\`v-Qt"91BxP2c8 # 4hsrMg#4%2̝OϠħ`yG2UHEIKDManX^˼& 5#d!jrc(0p 4 +Gf 9C&`(CO$VoJ{ mJ%C(1FƌT7O7p*\@C ҤetQƂԟi H:9!9ΦhXc`Fp >rAa:y$E]GPxRg(sl7JA[שƱV4//n.mSH@lzv*KX|̸?-nT1>t28nPkk,3 ڐ>^y43 b߂\XueX81F1\b 9!U[:r#r8zAgiAM( 4_O 9>7W!k:;FtW%rIdi^Ax+ܴ]$iH:b^ ZcM6NC,9>{iVܮOp}ȩ0j;\T!)4+sN#3Zo Pj'z IkI1i9;,SDiv |tyy Wi10&4d0A\\b ^_UO!zjy!ːM5xgD iXx#d5-NOYN8ĄM/S)h ^x|!/WƎ̶xU⢚FTGO0˖Ce' uP3'b%?Of'krrFD/\քJIJxK1;9q脬{8,]]IS9P6mglVR6X͵ 4Vr]Nq<{MIP}^MK|qƉNgPR r8AƖTeFpmvy3$ :7}KE@drMh)}E@<rK~#Q4tPuZ0V=ٵ\bp?{zU>.46yinұ%rB6Ec'5]T)7Vϊɿ%VrY,{|2TU~]r?t{#%]PݙIBݩMaˌ"iY*EyZ>8RdT37<+D WN~K+< mxUEBMHE*YwւR[n.,W}ے2dsD>w5ښLп@$|6Sy1+e3,QUҸbbo5hǐR&ds١SW>̆ߨA7?]7*$_Cȝy,uFx*X\xc)ÊwDb>bGg.Bz\tUa& :M ,p&!ޖ>vrY,'c%"f IŏtZE" _>a߇ig9V%81*eλ?vrzz}0ʮ0f`hURI!?_Y&$*P7w=hcٰS.T `W,-r…GcGx.4r,K*Q nR $Z"ɹ|It-* 6ro?UШ0KLCj<屿 |˾r>h dnO#Ui\BvD6gN0|u$+jdhylֆ9ٕgpK͙/]! k.93lgn u$!'lF4ĉYR2 E[:zZ0vZ8vܴCͿ#n7n*Xۡ5M_܍?[b k{wmeS$X;ǭ]?O$U;X+|xY5lglhgdRR'8t}4r~OW_Wߴ]ڵN\ -d"aW`$%k/;ww t&])U c4aTvۯ2@ڱZ~1hUTcɎbp4us6f 6~fot]8@2Rں_lY7m3~4XɰQ̝1Kr;i;wݼ섢ݑO~(Q_d{Ԥ]BzVdY*ǘe$5W, `u [BlNJB9Q%-!*В_Ser*" vy92o[4/C&p`2HN{<&d#׊ 8f<&h.'\I F]y3I957!EƿVMP`ƈoTXN1׮BANȎGP) 2%w=R^󊁀硢'Ό|uZ(,uJ0&gVm_~g#Sr BlJy"Q(<  ϒTRK{'.6GW $/J˿\}t $!䴕0?Bv.c_G.ַgX~k|%?9W,JO*Szm15C:'v2bG;JS{ab+qޞFONq:8Ir<IL$uҳ9Y/øuo  Ϛzi,&9f^vM[ kk/dic!Z,Q{Xj2 >UXBj%2r"hVۼ0q/(?a)>nmHD~nDaUZVk~tAv6HyWJRR!G "QW b+y9&C$4,~C^š_bdIJJ$9qF\ޘcgy1ߣ/^! Z!tޢ{E9H.ЏX(,Yȵ_Y+m,~Vh1*% YooFSgZ!ҧ7X\w-cK/W)NJ_Q^r,SM v]xY D|PEB &+6Bʚ+*QLBJ#om]_ 3.ĸ՚=dzϹRc@vNs[Ci t@%;LU](@a+!3<*3Z̟˄(kRhߟԶzF(Ҵ0%EFD'-x,oh M{-#R0 u9l\g'>!zQ @Snl7#/7nyЎt6~x~_󂓍Ӏ7U072sq- pH E`sm-i,s\;? ^466*m{zB=A#Ǡi>A zeBړj3?ؑql@a?NE+$b3SgC-oQIp@J{X^w@TG͙ W>aؘE/h;Fz`v:fgA{weZTK/ $3UQ6H0胫{0ig!쏪hN*zC""+&0/'R="ǗS3Q;p˥0Wa;ƶR]zO]#|ֽX#׮ۊHC ։C˯l2[Ir͉>S(MqH_b,H %_}țDyfYFG kZ.ng B OǏN!NT,^0bD0v<Xw6,ȸv2WY~nWd.Uʍb~ˌ0MF\ʑrKp@ҨZ#<恂qZRC>WퟣCY^ Tsdnؠ{7teb_cPqe"n? vAw ՞H8+rxᅘz.7Sd4APAQ7CQBWrZ_h调nmey_^PuAVJnwfOkcrVgXy d\IIUl< m=0#ċ8 $Ax/``k~N_[5 1 Gb;Ĝ|a *gHqU\^ $5ER j9&-6g?Q=s/ ]%!N4/0a`K­Ar1qw`h1@~ynnOhM[_2ذ &\II&<vڮ]c<:r5Q`I281Itί]M Glo^v Ut`>WJAtZ=o!ٻmCs7z4@HΗ/EЖȈ= ޽*hF]@A~G.tkDu(mےy},k=_r&ې)\j 3*`uη}y5`FYPf:=_0ݵ-X #~w@>o mVkܾq~r adkA9"Ղg7,v&I-(Lxg1%m/"H=B;o 9(R䘟Ѻ,yEݞ>1n W*3ÚЋj"Y=63||P+|c)HV:a@E5:ң5W(VS4I8^{vi_uŧ[<9wt]6W̽:OBx2(\PS] 0fbmU7>P $FNn|WHl.yدkoktɾ/}UѰ^X^كcVe*. RAY)HJ@s󊺎<( )=s#C.\AA@P"?EѽJץTY%ڑ$EFm$wN F2h,4>p5!~oXۅٕՏ3MEAyB(ǡOx瞧vYٵʻ- 쳊?-!<A}l1翣 "LsQhwƹL[=&6P;s-W8j[x? WGT(oRZMc͆eyZ߮<b(8YRYK\sfU2䭃|=քUF2%*$eH-Hu֔JXSbT˒ړg>9_04ޝ-Umz+u˓ :{Z@di'T|Q;K&9lv"ޑq6tdK4;B#~NAҳ{oCr趨'NdKFh+^ghb%MEIRuI^t D6}ǰݦN[8ijyXS|OCv]:n vO`v#F4TF-j'g@^(UT$ %|u!~Zz$tAeh{OA,u_#/W%af4>YB2)z;X07!;ހeP?T0}뼳tH\Үk*MpZ^Jz%p% iUh zELaT`7S?錮c^5/ ;=nzpԾq>uţ9Dq$!qJXy+ R+D(R~6fmggJ)sviJ@Xd=@uC WT+N+sZke3eb0*:ZI:FZC[Yj UI }ˎ (#5ΤX"j}Lؼ!`yyGXqS)bDy* B^#jv lkF>RץMZ" 9it3"-"AcLŔu}!X) ]?Ur;78?Zˢwyb&b8ɒOQ-3jR,͇4D~}DUW%]/UdE)(gZ[Q&,L0\F^X luu<[edDEXcSĔ*ٓ=+[95m͊3b͎.Fx2NP3 ZrMEJ*kͯfC-F6I\mG/=9$*xw@bn)$RLfQ*[vWcFe-ݔw8dν@t nA))L HIQ+ )mS[b 5aSc`u(xDHfP)եAu_qL%J %),o+~s{tźqMUG P ޿8ɶat\#.;GI7<{3S5gˉ|Rvk>Ww^?^,4p.:O"h_j>B`*zҗ=QRG^gaEL8Z "{?BI \l,TB O`#s!X?<;8sOߙ.Kzmؐr›4&mN] 1=ᡂ}qvi x7-i1hW )VZs3usԈ -3*nrƍYs,=Kp>jW#[ö<`^c ."J!2|ҏۜ j9#P\B(w _@eZykbaL@*ɘiev?=uC4%zlq6'1krL.ʢV<'޶D%znq-W.p74ངCY !SW.>1xW!X5R{47)88[҅/ #8Cbv\b$ͼ`&ٷ-O&uW!D .zMhn&@"a3 L.'aK+mI^[I'iJ#U#F8IwD ŨYKQ%&X8I*PRtX 3*\"1h ۀQ?DHF9Ϫcͫ\9sA}?~'Fx߇Jd_Ȗ_[FdJ_?!]*VDS!?1L;3F &P}O 1Yч4]F{N|9R9M,ظA7* ?IG"IH=miJs7ٟu_c|#.M|#įU@оk)Ièx* =\|W&X^j*0lNӐ*u4WKl<]'8IJ/ʯ,O6B*Q{S=M*Qُ%_ ^ ~bb[VJ٫B^Vӵ>}suFVZspWBo 5kjgDD?7s3?@oM0bT L GC3$U/i[E-%Ujȶ?ܤ?RSsZRh1PfjL~:CZqOTavt^D\fH' h#kȵ!:1=SnuD{pPmZo.7!Ӳ2kJ$b=ՓjҎYCH)= T+7G!$>)QsiUc2N +Y]P8+^qu[lM۰|(+w։ֱkse :蔞VKK]J62zn: 8EvytH㽢ih@U|4"˱np\S'݌!-6_lJdgGKV]ǁ+2rbkClMp Ȳo_ q338AIu,:_#˴a۞uqcѺ*rSJW{kapeR]8GٳQ:G o.[N卦 {MPSTY)0M SFl膒_Nw3uBg68̧mϮ]S[~I{t%8WL#@|$ ټ[C-c/ {lq&ojZ{OϫW\C- >_lB1.D{j٪c srK81F-r?,wRd{\|s_?`A @c3ܣ Ok /-Bqo 9Dc*,>m)16 [NAj_I/XvK[g7 n4}LPT=u@6]6זS2n=.n,gݯx f6 rܞMCͼpD}ZG.J^הF1 ߛ Z`K֐_Q?+Zxݴ?7DjQ: Q;zy}B^ ܺ9K5~:y)<#8&GOd rvhvh6cIhHkXmc{t6wM9{GWޏmmRiivBY +kb-] m_۹>o%"SaIu8ܼpcthUb#!:Zn@XTO7|U͑+DbA8hcc),ݱG2K@Fi&9X5/"O_^F̺)6l=5Y?== 8~TZf򿳥#򫮦}7~ Zb󪦪ͿL:~-Ż@EgLʜuƘĞ]e RtIde@uG}Qx0bN- DYj] ,EBK{>E-W'܁\s[E%YnY:Vp2j#oƬ+s8Eu hp69iw3v3"yX1 ;lHJ}ΛԳj6j`J@%rD$FVIByLkP-@lc;"ꦽ-'d.Z-TL%քJj1W:Gfs&-㚟xJO>N]/ K6%u8[T~ZWwPvB XRv"-}ˌ(ܑq<1':'d[TLVa.a𘔨UF}n=&>F.0,>+t8=B3AS.deГeiבNa^z(bHƯ-N4 JGf-UJE@Tljg_q%ݫ١A GK;*B5B@zLϡC0~ $ŚcPy (w"9hul.sa70A@>;i3[ OPZHhO*SGƨðYg{ͲQq&%ڤϔ 50$!$ oB(i[F7^~ l"!cx4*)ZJgNթLAvw?B OfHeIhxz6/.1CkFD`DA@Yz" *'o[>3znÛ#7QM V7E ..͌vJ{jnR' ".; G0T/`˟T?VbůI%@q#qOH*Q9=BZSL67YHY^.OjԂq lnx6&=5H_|8fGK6]56B- ܌ }#}3鿭\/έL`y|Ia DiZ m9PȣρX{A-x:ڨt.2h{N~Fl{| ֛fsPboSqfiUfυׁ_%!nAD". I'']T/\63;|Xs*2펷y͇u "7{QL PtYB?)pwixKOa.ԩas?I*ǠưLQgpKpe]{5]l*㰹)=qTĆ{hD3Q+Pɩn:PPqW9bkzAC{`T^Ÿ ͚PR囱~L,7U$r֊/$= P1+2l/ M,?齨??/ E=G+24u}ʮR!6󔫩@PZWOf$6b+\sDVT^şI_5Pi=[әx|]09sY$z=x*Ì:㎋,U>EOULafAvdl͠'Z:5154hͯv>4]Kr%7HTeF0Zjfrz9ُc.E_ȯ w> {yTceEM'БU+咮 wa v ZCOJBԁx]U$'_!p؆aUDؼQ2B?/P߹:8ܼ|b n* 8mU&ƅO@Ju\BS4K\G'n{g8z?шn\opݤ3 Jr`@5]sg2ľ >I~Uէw)(taC|0imLZiIWIZ?:O!ERyoaa4fJЀgadxf_OKax1 Nf,oǘpu!!k88҉eM$+ tapqS?{%KE'z}EXzKA#fl(iXv R aDBU6+M ZؔOx}+s9e3x j.*tDgMW1e¿gI">~|L߽~t-P"`Ֆʋ4PWMLVIM1#֭ =G#[:`uDu< 4W.KdX\H7jn206/ew5rUŸD԰a?n6 riܫfuAp:ִN<DeLGII.~9zcs_a9B ]1v,R,~ɹKZ1w(]K:\bDEEaS{*tLl`hJ 5Ւ~&MnOz;pp,k{*"IG-aJi97&öNz͂H&9`i b/9 J sV+.ՠA2@`HI$!'$`gȝP=RtR#`>PB*HrWR3JsPF[%x=$+5 ?\՘ě/{Ee8\p?+Ǒ @"TyS+ 3dHBW(di%OW< d-A6/AM;"Woo,>`PSHIqi^Tڅap>R,FO|ͱ=:?d%@굽c$kwXL{ӣ_J뗤JUV׬wXx~o!6 iz&Q:ŔKЅPrhw:i񩏫VhaD?{Q6,~MIǖOQAelCx}-g[Nt V H|M08"D2Mees _۟'x&:a&v??ehԧ 0J]I"ƱMę4pȬcYH֐xg}b(]~O*3 Pq_{n4}U*.CY`.#7/Y5,j1ݵ;Dc6+@4RG8 JPxz2/J!U3S5˟%>ԂTK* r_S h{e_F--cB30c c]^峈!^Aq)TE~?tiust9cm_k>ɕ,ɍ`uPuaS^ & njyܓo{ڄqb:>eiǢp8)n, V"4=4(SN#yĤy8d)[ofx;aכxhg #ߞ+| 5@>Q$d$?z2 (`ʗ& Ըx`!Yԉ~5_˩s| :>;[{{HGJk~dY$p1oq:v@40-l@eL+O38{SH&=Q[ -{a}!ՓRqʮR-Qe)%?6x?@!' sm,;HCQX" huA/A{ |M PCo2mlV1r,3)_V|5WܤUC:67x(U 5qR!dDOa뽵Dt}+mgrb\W#Vǡ?Ovdz\IÉeoR,5'FRr)e:w{-M֘WI^z| Z%7 uu9a7\`"6NHl[rĤvVIGTkn e&_rصǢ.y}6p$~ Lq&g7D,Z\q&1F8۾~N\o|BY_t/ [WRˊLd]A&}h~Nsp.юЈI/ ˻} ѣ.7118/N<=Xl=X@6E])q"%7>b"|s8 r6+zUQӘliWqd AA(K !@80## 1sm{ڠg%T1,A:3vnmXRÆY e5:žӎ\ɬq/B@s =|7=A )+8 OPZk-#'x깕O}RB"iYZ 0Nk/CF\QX&35Md@C ]z3z^:jȒyKKd&BiM2' ӜnxXX#6rɎ(*эK* ZYьK"%ƕ@P^4Hv'fP.<*,Q[MPX01V5|*Ñyo/DuN-;/GK 7ZU93ɤYN]{,=]Myy)^Uje AIPCpkvmx4)yF64Iu!eHJtOsXJPQwJx4a,2.m'1h>;ykĵd@(a6~V3o_R-r|v%0 U0oGXDnBjOWĖBfT nS_CЊv5|HhjP)hNT1Y.]Xa#+Po-6qޘd󕛠ѥ_q; S չ3Wo%sO3aBG 0:jg]Z[Az{!UrҧdyL>O5b&5mjVxwFuߙXEsZ:`2R_Hz ܃%W:T;x5pe`o=\-WKCwm=X{۝is"jN :id† 2jWh È9`E .]p)Mls&w_I=,ګ@ 5* 3 hLr8+hr2+Mz@90Ee#7E*h& єݗsU$[!>06 A2F.cXty N_3/Uo U%c[e f$?xz-UM_W+֪w0:wBCuӢƈc+bg%2V$NIofs s pl4"O~"'H1{PAP#I^r3hΉя)kWǧ` 470x2<֡/E#̻)6et)bيX'>fnؕ-"~7$3 w֡H)֣rUQu I1,n%2x0lɭV}Uxq'7,fZضh 㶵 S.Qd5rO zy$|L%k@xʭ9[Q;{H

eW}.DGbWGچzCўyn{9̻ "u0R3 P!̔0 |TQI!7_rR{7V<&hЀ`vȈ_ !_ Ą>9E/r+w}U3:r(Yes0 GGw+̠_J^G#ΩA30y&eJ& hϱ`jKpO!ӞT̾:PP1ȫ~=U.j"&0|ZY)&Y|hI~MH2DT/hP˶&́w]#_:kduF fm8|H^>#)c^l'. *oY6ڇGo4?`E";"#Jwg&-]LNUyR kb3pu%A)Z^b߳lb\Rz{b3jKz*4t7v&"|b t2+`b/ mXp Yoz 3WLzCVv)KoJOUׁGS7 !MVIRQaU5>І+%!b*f\AWrTȶ 2TnI*/#~k|[P߫ a%e`ɉ-3nXȳ&*"|N9ɳדfgLW0hG"#vs+nbM0gPڗ+ :x#`5gqB-k0]G/A|s'8>65 f&M @#{I}f^M/EDwFEnh^FuZ`<.+W5ֺ B1iwmP5vəi.9>0e2`CnB:)v>9#L^' U r-Қ1_lUbStm)a5c)ejJ.5NVJ:),5VCA/1&@|!H_WivK%Ȅ ~f}hWxCˆspo[^`nWrIj̹7?_yLuX_rd,,A$?R̼ H?24·)cH4YH9`(1vp¾'=8̍. >.z(MjpWn emM$ o2-.:j*&#ԥm'*eL2L+S9y]𵝠V$T W)|w!I~\?+V Zv[ 4Oa-uXVM^B/"3@#۠\DMQXBly h|b F2QF@}%,1Gq@춲0֐PgS$I1;'|Rzڇ+Ѷp2F,/eLt9)4}pvT PD$o4k녢hOJGD%8a;ȃ,ҪͯAf49"clEBTm:!fW>$EYglsme+=c +v0' fRivYF\%d+=Z/ZͰ,iUPk(CHLv.PiT2񝕣Oi5`g_ &)+'W{hb;|eTHE% 1͘Fm5o3?%^D[ [Yr]²՗豹ܝ ؎kJ@`qD=0 P] Gg@'ZNA76.;'r4!fJUuьrCS5G2ﴈxӣ*AᑑSVFv3zSy+ K[Ϯۮ-)CaN LnU?ڄ&(b}>4eԋroҵKZo Un֟(%E)-Y.N3e'Ij:BxхpIO,&i%>9Kܒ;#LVsm~ԙ#;'T$zyY”~  ./ҳk7YXebW+س,6΅"[)[k噺} |uaj& R{ӦvwACiZ=lZN/LaCb Ǻ.pzj8Q 5̼EP_)L Cf h;+U$o@0~`) CtCf(^,e?Ilǜ;0j|r AG!$^džۭr<}#4PJѮE6r4v_th[ ARn`N=lcKk}TQ8LkbryW:BW;/3k+/ȦE+3q|QkL[ވ_W)8p(ڭޣm\;S wV'R96•AKIՓ w0F֜2@N׋-8\n:5V4TY;(iסﴄ>Nfk-zX3:ؓ: nx I䥊0܋Qv_]8e +Rre8/swR8&PHA 6E*a܍Qi3Q|.Ȝ{;+9dEI#N#Q؂)ߗo؆)ljKo{w2 B%W6Z6#951|jwtY޹ ƞ~2є@`=v,OCZ䈯/~s&ĚEL_`Q{9V,Xh]ZUJ0:Bݴ`i]R3heRnT]U9|OU?ɠcb ̳ǿ|Xds,!7-kmݱͥ9#:d[+/~ bҵBHQy_ϋNǁ؍Gz5AGdXZcKn]!tt"\GG*R"(v.ut]ƭ M@o{ziW+'o* A&X҅-K:q" g'Ea@ę!5RI݄ w-8:N<^8ƏGRd])45ʌ6ZG L34X0 BnVI!՗;ЪMKg_%*HκHDԯ+ӽ`w=w+<+QN]!TI#"s=t< (R0Gy4ҫ,R*ۗB)7$`r _s):w"dZW/ f|=9_ԌV?=Rז' a#բ$粑פ#;9mQNI[xX]I͌&R3&g[-d2{9Җek^[o }hH!&ښ6Zܣ8?ltic+HU7ݕ%1sa~dڰu {od I_F´Z)Q|/j֛~:}R 檹l#9~pq!v[k(YI<Q$!T0 Y+e`6zBB+bJnf8"I}U4+;n!\Ms+쫻pxcebaogı =ϊ XTgߢxmd?b²ʃEeWPN 6B͑ kcQql"5ǻKkgxc} N`Y?hxDیg -9귩L>#!ymEm@iYj{[C e^4 M+&Dyj<$!GMB$8ADK-؊D߷QnR؂S`ﮇ3qrڿZ${qc *sB91 YMݗp Oby9"if1?Ra7Gkz}CR2F˝! 1\u"\C Cꊘ"iI{dҢZnE^@  C һ~qhV@3x-Rӫp*]c,1v~^ |, 9#S)+F|a!𪿁J.ǐIH0‡~齄\9jjy}f `ZrPh3 W:x۠'ۆQ{ZT"ٷNz[Q"cu; ! &=PENWBVXdƈ֦TѺIq 7$㌺t%ljb!U*4âTn97T٠4O[/_vV*($X9ݵO x# H"-2@cUua‰Cp(g+58[lv 'LW={d:Jut_p$z(ɩ#ƳKHA0"_;vs#3t{|s䒀mQ'G{?-p;Xb/ ^'ûN![xe1 Nit%mm7yF(\WyqÌQ: )CHqN/$hVte#+/Mu72 Xdzqo$߇J!PTr%U棦6Q ul6/fGwkUC'}3eiHG<^+KdyTW]j$Ls92 X@iY\9(`piBF^oa(mU^6t!έ)(ו~:2d(*:q ZpLG ETP#c猉SwȁxpnL 4J@|'j:v(nW- K[w{])2Qr!s^5/: ʊsw+{$e: 87jGLS߫!b{!\DJfcS?Ruf7/ò4oPoUHS.w8VnWCFۦɗBf.[s ވ œct`EXy*sv}V>܃ޣo |2O" :4 A\[l_$2!74-4\*J>O0ʧOc€{wLo_|tŪ GED Nw۾S^VާH ;.FAfX^f\>Isu׊HcOk?$r=LVCdO¬?НCՒb(S9rcH:)XG",-C7$2>i 7K#Kb.Lx qY՜~}=)&$d S%{,(4:V(8t;vcCw^9 =c;=yʔtYh!f0휘IQIxһ!l[#7*>[%FDP" d!{k)psoZ\?$K+/4} kRNɠaC/MٮA hс0B&c,=fj(FpX-y#Fx!P^Ǿ{ kf1m-K<9<-\D5?~ ZZ.7WS;d"#ZSӮ$ҺxDXdIAIB.[Wr:BMDߪIL6yԤf[XZ$"EZ=NYz2_ WUmLkت #샅ëuU\RGd$_~#e"XByXY%iɍ{uJXt60r:BP/3ef.E念нW$[nlXZdJ<fCA;z̪˼I*͙i?>ɾx~}T7br5~Ī@ABM`@V#+r9=17)= w"zzv:m9|J?jX#} &=SLR2w V6j i;g{nṾ5U1W=Nݑ#B2_O*]VFpJhw܅nՑ=AQԂhU A1 moS'm ͣ5EL1&O梕3}v7PyX*Yk3k6K>Kga|`[ c|yt+H=#~PX>h[LkQ3wȲ9m>mX}s zUYdC9L Da[ݳW[0r4EXGţ 6#Bs1WY̖~, 4Gs(hǁO8j{5^950s'0ش*A>Te0II$#)웓2jȚb-Jԛ̕ߧ6(+\bf%-ŭSfsW;_`R ȈF_Smdex R j0!g,]$\tFqByF'?xR}C53#ґW62~ZOt'>\!&:ڪ&=~u^uN$e{ΰ"9 3Ԝ4VOӐcz2V&j&&frSuKoD^u{(.knY[7@rjsoiy֗/2>ϴBv>C| .Ef^_m3kj\׎1_sG !PR5inU61\!-jL#T ޥjr; ZL{CT1ěMY d6sc+ yD7, tV۠lw4b4d9Rk(eJ'VPyć]xA}c߃i^_uj5:#0hiL"EqnBG*}1\%QϺ/|>1cɳI\g76^zK+u~ÆgCW*;B1mў5~:X-g/q#b4 X#C +F'o-;MNyMJ0О&ty;K%YeA؊:u@NêƝ#)fA^&IOf'륗 Tc+uRD=MMPnjK=zv6 e˛z5KKIlkJH#9}bUE^*Ñ?d/Dq1 `0YTb9C3K,2aGaoH[4-cuZ-%tKct{jsFXɔES܍P=`ȜC-a#l85.3\N%3Z6RgD?[En߉ߤJn`؅= >sQRvqq \Ũbԕ|| ͽcأJT&k{7IutHc%ZN`0"cΠr[Io6?:~fU0$ _=- ( Y02~b`,3/"E/JY%#_=?#AS.bܞ3uZ}6 /SCYS,CU״$%=xNﱆ*̨ [0>fF@ 14 hKĥ|Acqh;!峣JI .m|bTׄ“m[esV#3ݎ. i&AwF1>5I*uh~u?(y+gẀ|ɢne.±iw$"Q# g_KeWR3QNCo{ó 1/ߖ+hb(S%tuݣ8!{5-lkGa˦"Ǐ"KF9zwIdpqѨ{b JЪ31sE9-[1YڻbdҐy;"h 1t5KGj WJu?Ht(8e.9ypl4t=*j 34R*_`|ƥV.8ʍ;Sݝi@k`7+! \$7v^.))1}W?dQ ._A+{Pc:w2U*lIjiր 6]\m;CH}zwW"i޵M4[&n!LK?/ Q57N9h*H5fΰ th f.~Q'1_ swPNhw0͋TwU(Uݟ$zs kMUnc ? rMOmMzP|Ӱ')DS؂r7m0{#v[X&o( (n0|ǓXhF|2IvԸ'mp24Фyi X9)~3 B'ss!fdkD9,Xwy;w` 6ljlCw!]l)%WNSsJX~4P`on(k\n_݉5̳Tq.Qjg jYvjEXf" fCς 6:lJp6t9Tل;Yb:S27zz {~Z~{ƫ6 ׍$!q3m/OǢ}\&G3 36з7H]nC[Rz@B{3%NܰtqLެ"[s#nr3\@ h^pY.,HOHр'b@AƼhs.ĹU,.]MS/>ĉy>ix:ar։hjCl$Ϯ'UY[3Е*t&] sq_gqeh֖Ҙ݀[ꒇM WcOk KFcZD]/́@`GANh\*7'ۣ1Bɶ7S:kҴNn0YmD ߚE@LFt47z<9*7樍 lXA?|? H}f}zmF?`Ojz fSNi#vΣŧ& kܰ5TN%Ho[e p28xX}I @w"^h]C?0!ߝdO {-pQރk!4{V3`&E*̩O%\5ʈ_fбffgͤ;p%6u9l[;,+$FDXI^8?T}[%|Hz\<+gSӭ}-0e',_Oadm cxsȪܮ_U|lů,p`E*:Wf Ȋ;ד,ʅ]_8&]@VR_Ĉ\_D!6<g\oo`RP`{Ig| SFR BJ-{i:K- @r# y6VzW$U}=*jD{$`vaS :F2\D^x 8GIBa,,{yݒ*;գP bj[g!D㈠ ܹ2X!f*X\Y+N5`_clDPsḧkwңh4!Zɂ?g29SZ^4 ؀(#茠IdԦaӋiyp.zrv9亂MX 1ے&8HTIj%o?E1L?uމ>] N&˛W })lƌm&\Q,h.ec&:eFR>Cvո'f|$dȪu k,;ǝ:fR#s]cSA[* W [GrlGVy P=i~>`bZv;c earWЈi(25Pd_:}A!B'g0Ҙɰ~=H簤//0dIV:}w(yc?/"9|ISeyhYu&uƼNє$ɺ"glh-bCP[4dt& [-ղeS.Qk'~%ԛtdό2k)Ɨ\I!M%EGdupq  YZ