nss-devel-3.28.3-3.el6_9$>O328Zn^>8?ôd   O CIP33 3 3 3 g3 3h3g3f3P(89:O,Gp3H<3I3X<YL\3]L3^bQdeflt3u3vw3x3yÜðCnss-devel3.28.33.el6_9Development libraries for Network Security ServicesHeader and Library files for doing development with Network Security Services.XIc1bm.rdu2.centos.org Development/Librarieshttp://www.mozilla.org/projects/security/pki/nss/linuxi686  YRCyQ - 3.28.3-3Daiki Ueno - 3.28.3-2Daiki Ueno - 3.28.3-1Daiki Ueno - 3.27.1-13Daiki Ueno - 3.27.1-12Daiki Ueno - 3.27.1-11Daiki Ueno - 3.27.1-10Daiki Ueno - 3.27.1-9Daiki Ueno - 3.27.1-8Daiki Ueno - 3.27.1-7Kai Engert - 3.27.1-6Kai Engert - 3.27.1-5Kai Engert - 3.27.1-4Kai Engert - 3.27.1-3Daiki Ueno - 3.27.1-2Daiki Ueno - 3.27.1-1Kai Engert - 3.21.0-8Elio Maldonado - 3.21.0-7Elio Maldonado - 3.21.0-6Elio Maldonado - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado - 3.21.0-2Elio Maldonado - 3.21.0-1Elio Maldonado - 3.19.1-9Elio Maldonado - 3.19.1-7Elio Maldonado - 3.19.1-6Elio Maldonado - 3.19.1-5Elio Maldonado - 3.19.1-4Kai Engert - 3.19.1-3Kai Engert - 3.19.1-2Elio Maldonado - 3.19.1-1Kai Engert - 3.18.0-5.3Elio Maldonado - 3.18.0-5Elio Maldonado - 3.18.0-4Elio Maldonado - 3.18.0-3Elio Maldonado - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.16.2.3-4Elio Maldonado - 3.16.2.3-3Elio Maldonado - 3.16.2.3-1Elio Maldonado - 3.16.1-14Elio Maldonado - 3.16.1-13Elio Maldonado - 3.16.1-12Elio Maldonado - 3.16.1-11Elio Maldonado - 3.16.1-10Elio Maldonado - 3.16.1-9Elio Maldonado - 3.16.1-8Elio Maldonado - 3.16.1-7Elio Maldonado - 3.16.1-6Elio Maldonado - 3.16.1-5Elio Maldonado - 3.16.1-4Elio Maldonado - 3.16.1-3Elio Maldonado - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.15.3-11Elio Maldonado - 3.15.3-10Elio Maldonado - 3.15.3-9Elio Maldonado - 3.15.3-8Elio Maldonado - 3.15.3-7Elio Maldonado - 3.15.3-6Elio Maldonado - 3.15.3-5Elio Maldonado - 3.15.3-4Elio Maldonado - 3.15.3-3Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.1-15Elio Maldonado - 3.15.1-14Elio Maldonado - 3.15.1-13Elio Maldonado - 3.15.1-12Elio Maldonado - 3.15.1-11Elio Maldonado - 3.15.1-10Elio Maldonado - 3.15.1-9Elio Maldonado - 3.15.1-8Kai Engert - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.14.3-37Elio Maldonado - 3.14.3-36Elio Maldonado - 3.14.3-35Elio Maldonado - 3.14.3-34Kai Engert - 3.14.3-33Elio Maldonado - 3.14.3-5Elio Maldonado - 3.14.3-4Elio Maldonado - 3.14.3-3Elio Maldonado - 3.14.3-2Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.0.0-12Elio Maldonado - 3.14.0.0-11Elio Maldonado - 3.14.0.0-10Elio Maldonado - 3.14.0.0-9Elio Maldonado - 3.14.0.0-8Elio Maldonado - 3.14.0.0-7Elio Maldonado - 3.14.0.0-6Elio Maldonado - 3.14.0.0-5Elio Maldonado - 3.14.0.0-4Kai Engert - 3.14.0.0-3Bob Relyea - 3.14.0.0-2Elio Maldonado - 3.14.0.0-1Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.3-7Elio Maldonado - 3.13.3-6Elio Maldonado Batiz - 3.13.3-5Elio Maldonado Batiz - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Elio Maldonado Batiz - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado - 3.13.1-4Elio Maldonado - 3.13.1-4Martin Stransky 3.13.1-3Elio Maldonado Batiz - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.12.10-17Elio Maldonado - 3.12.10-16Elio Maldonado - 3.12.10-15Elio Maldonado - 3.12.10-14Elio Maldonado - 3.12.10-13Elio Maldonado - 3.12.10-12Elio Maldonado - 3.12.10-11Elio Maldonado - 3.12.10-10Elio Maldonado - 3.12.10-9Elio Maldonado - 3.12.10-8Elio Maldonado - 3.12.10-7Elio Maldonado - 3.12.10-6Elio Maldonado - 3.12.10-5Elio Maldonado - 3.12.10-4Elio Maldonado - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado Batiz - 3.12.9-9Elio Maldonado - 3.12.9-8Elio Maldonado - 3.12.9-7Elio Maldonado - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Kai Engert - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5.99-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-7.3Elio Maldonado - 3.12.5-7.2Elio Maldonado - 3.12.5-7.1Elio Maldonado - 3.12.5-7Elio Maldonado - 3.12.5-6Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-2Elio Maldonado - 3.12.5-1.14Elio Maldonado - 3.12.5-1.12.1Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.10Elio Maldonado - 3.12.5-1.8Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-1.2Elio Maldonado - 3.12.4-15Elio Maldonado - 3.12.4-14Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Fix crash with tstclnt -W - Adjust gtests to run with our old softoken and downstream patches- Avoid cipher suite ordering change, spotted by Hubert Kario- Rebase to 3.28.3 - Remove upstreamed moz-1282627-rh-1294606.patch, moz-1312141-rh-1387811.patch, moz-1315936.patch, and moz-1318561.patch - Remove no longer necessary nss-duplicate-ciphers.patch - Disable X25519 and exclude tests using it - Catch failed ASN1 decoding of RSA keys, by Kamil Dudka (#1427481)- Update expired PayPalEE.cert- Disable unsupported test cases in ssl_gtests- Adjust the sslstress.txt filename so that it matches with the disableSSL2tests patch ported from RHEL 7 - Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests - Don't add gtests and ssl_gtests to nss_tests, unless gtests are enabled- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release - Add patch to fix bash syntax error in tests/ssl.sh - Add patch to remove duplicate ciphersuites entries in sslinfo.c - Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range - Build with support for SSLKEYLOGFILE- Update fix_multiple_open patch to fix regression in openldap client - Remove pk11_genobj_leak patch, which caused crash with Firefox - Add comment in the policy file to preserve the last empty line - Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not provided by softoken; this superseds check_hash_impl patch- Fix problem in check_hash_impl patch- Add patch to check if hash algorithms are backed by a token - Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256, which have never enabled in the past- Add upstream patch to fix a crash. Mozilla #1315936- Disable the use of RSA-PSS with SSL/TLS. #1390161- Use updated upstream patch for RH bug 1387811- Added upstream patches to fix RH bugs 1057388, 1294606, 1387811- Enable gtests when requested- Rebase to NSS 3.27.1 - Remove nss-646045.patch, which is not necessary - Remove p-disable-md5-590364-reversed.patch, which is no-op here, because the patched code is removed later in %setup - Remove disable_hw_gcm.patch, which is no-op here, because the patched code is removed later in %setup. Also remove NSS_DISABLE_HW_GCM setting, which was only required for RHEL 5 - Add Bug-1001841-disable-sslv2-libssl.patch and Bug-1001841-disable-sslv2-tests.patch, which completedly disable EXPORT ciphersuites. Ported from RHEL 7 - Remove disable-export-suites-tests.patch, which is covered by Bug-1001841-disable-sslv2-tests.patch - Remove nss-ca-2.6-enable-legacy.patch, as we decided to not allow 1024 legacy CA certificates - Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits - Remove nss-init-ss-sec-certs-null.patch, which appears to be no-op, as it clears memory area allocated with PORT_ZAlloc() - Remove nss-disable-sslv2-libssl.patch, nss-disable-sslv2-tests.patch, sslauth-no-v2.patch, and nss-sslstress-txt-ssl3-lower-value-in-range.patch as SSLv2 is already disabled in upstream - Remove fix-nss-test-filtering.patch, which is fixed in upstream - Add nss-check-policy-file.patch from Fedora - Install policy config in /etc/pki/nss-legacy/nss-rhel6.config- Ensure all ssl.sh tests are executed- Update sslauth patch to run more tests- Fix syntax errors in patch that disables sslv2 tests - Resolves: Bug 1297888 - Rebase RHEL 6.8 to NSS 3.21 for Firefox 45- Resolves: Bug 1304812 - Disable support for SSLv2 completely.- Add patches for ABI compatibility- Disable extended master-secret due to older version of softoken- Enable two additional ciphers and keep another one disabled - Prevent enabling extended masker key derive- Rebase to NSS-3.21- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol - Resolves: Bug 1289890- Package listsuites as part of the unsupported tools set - Resolves: Bug 1283655- Resolves: Bug 1272504 - Enable TLS 1.2 as the default in nss- Rebuild against updated NSPR- Sync up with the rhel-6.6 branch - Resolves: Bug 1224450- Additional NULL initialization.- Updated the patch to keep old cipher suite order - Resolves: Bug 1224450- Rebase to nss-3.19.1 - Resolves: Bug 1224450- On RHEL 6.x keep the TLS version defaults unchanged. - Require softokn build 22 to ensure runtime compatibility. - Relax the requirement from pkcs11-devel to nss-softokn-freebl-devel to allow same or newer. - Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1)- Update and reeneable nss-646045.patch on account of the rebase - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Fix shell syntax error in nss/tests/all.sh - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Restore a patch that had been mistakenly disabled - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Replace expired PayPal test certificate that breaks the build - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] - Resolves: Bug 1131311 - rhel65 ns-slapd crash, segfault error 4 in libnss3.so in PK11_DoesMechanism at pk11slot.c:1824 - Temporarily disable some tests until expired PayPalEE.cert is renewed- Keep the same cipher suite order as we had in NSS_3_15_3_RTM - Resolves: Bug 1123092 - openldap-2.4.23-34.el6_5.1.i686 fails after updating nss to nss-3.16.1-4.el6_5.i686- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 - Remove unused indentation pseudo patch - require nss util 3.16.2.3 - Restore patch for certutil man page - supply missing options descriptions to the man page- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Resolves: Bug 1145432 - CVE-2014-1568- Fix pem deadlock caused by previous version of a fix for a race condition - Fixes: Bug 1090681- Add references to bugs filed upstream - Related: Bug 1090681, Bug 1104300- Resolves: Bug 1090681 - RHDS 9.1 389-ds-base-1.2.11.15-31 crash in PK11_DoesMechanism- Replace expired PayPal test certificate that breaks the build - Related: Bug 1099619- Fix defects found by coverity - Resolves: Bug 1104300- Backport nss-3.12.6 upstream fix required by Firefox 31 - Resolves: Bug 1099619- Update nspr-version to 4.10.6- Update pem sources to the same ones used on rhel-7 - Remove no longer needed patches on account of this update - Resolves: Bug 1002205- Move removal of directories to the end of the %prep section - Resolves: Bug 689919 - build without any softoken or util sources in the tree- Remove unused patches rendered obsolete- Fix pem module trashing of private keys on failed login - Resolves: Bug 1002205 - PEM module trashes private keys if login fails- Restore use of indentation patch until another bug is resolved - Resolves: Bug 606022 - nss security tools lack man pages- Update to nss-3.16.1 - Resolves: Bug 1099619 - Rebase nss in RHEL 6.6 to NSS 3.16.1- Resolves: Bug 689919 - build without any softoken or util sources in the tree - Add define-uint32.patch to deal with using older version of nss-softokn - Fix suboptimal test failure detection shell code in the %check section- Prevent users from disabling the internal crypto module - Resolves: Bug 1059176 - nss segfaults with opencryptoki module- Improve support for ECDSA algorithm via pluggable ECC - Document the purpose of the iquote.patch - Resolves: Bug 1057224 - Pluggable ECC in NSS not enabled on RHEL 6 and above- Install man pages for the nss security tools - Resolves: Bug 606022 - nss security tools lack man pages- Fix the numbering and naming of the patches - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- make derEncodingsMatch work with encrypted keys - rename a patch, dropped the experimental moniker from it - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Revoke trust in one mis-issued anssi certificate - Resolves: Bug 1042686 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]- Disable hw gcm on rhel-5 based build environments where OS lacks support - Rollback changes to build nss without softokn until Bug 689919 is approved - Cipher suite was run as part of the nss-softokn build- Build nss without softoken, freebl, or util sources in the build source tree - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Update to NSS_3_15_3_RTM - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 - Resolves: Bug 1031238 - deadlock in trust domain lock and object lock- Using export NSS_DISABLE_HW_GCM=1 to deal with some problemmatic build systems - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add s390x and ia64 to the %define multilib_arches list used for defining alt_ckbi - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add zero default value to DISABLETEST check and fix the TEST_FAILURES check and reporting - Resolves: rhbz#990631 - file permissions of pkcs11.txt/secmod.db must be kept when modified by NSS - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Add a zero default value to the DISABLETEST and TEST_FAILURES checks - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix the test for zero failures in the %check section - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Restore a mistakenly removed patch - Resolves: rhbz#961659 - SQL backend does not reload certificates- Rebuild for the pem module to link with freel from nss-softokn-3.14.3-6.el6 - Related: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] - Related: rhbz#1010224 - NSS 3.15 breaks SSL in OpenLDAP clients- Don't require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Additional syntax fixes in nss-versus-softoken-test.patch - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix all.sh test for which application was last build by updating nss-versus-softoken-test.path - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Disable the cipher suite already run as part of the nss-softokn build - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nspr-4.10.0 - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix relative path in %check section to prevent undetected test failures - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Rebase to NSS_3.15.1_RTM - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) - Update patches on account of the shallow tree with the rebase to 3.15.1 - Update the pem module sources nss-pem-20130405.tar.bz2 with latest patches applied - Remove patches rendered obsolete by the nss rebase and the updated nss-pem sources - Enable the iquote.patch to access newly introduced types- Do not hold issuer certificate handles in the crl cache - Resolves: rhbz#961659 - SQL backend does not reload certificates- Resolves: rhbz#977341 - nss-tools certutil -H does not list all options- Resolves: rhbz#702083 - dont require unique file basenames- Fix race condition in cert code related to smart cards - Resolves: rhbz#903017 - Firefox hang when CAC/PIV smart card certificates are viewed in the certificate manager- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement. Please ensure that older packages that don't use the alternatives system for libnssckbi.so have a smaller n-v-r.- Syncup with uptream changes for aes gcm and ecc suiteb - Enable ecc support for suite b - Apply several upstream AES GCM fixes - Use the pristine nss upstream sources with ecc included - Export NSS_ENABLE_ECC=1 in both the build and the check sections - Make failed requests for unsupoprted ssl pkcs 11 bypass non fatal - Resolves: rhbz#882408 - NSS_NO_PKCS11_BYPASS must preserve ABI - Related: rhbz#918950 - rebase nss to 3.14.3- Revert to accepting MD5 on digital signatures by default - Resolves: rhbz#918136 - nss 3.14 - MD5 hash algorithm disabled- Ensure pem uses system freebl as with this update freebl brings in new API's - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Install sechash.h and secmodt.h which are now provided by nss-devel - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Remove unsafe -r option from commands that remove headers already shipped by nss-util and nss-softoken- Update to NSS_3.14.3_RTM - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Update expired test certificates (fixed in upstream bug 852781) - Sync up pem module's rsawrapr.c with softoken's upstream changes for nss-3.14.3 - Reactivate the aia tests- Recreate the distrust patch by backporting the upstream one - Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Remove a patch that caused a regression - Resolves: rhbz#883620- Fix locking issue causing curl hangs and authenticate to the correct session - Resolves: rhbz#872838- PEM peminit returns CKR_CANT_LOCK when needed to inform caller module isn't thread safe - Resolves: rhbz#555019 - [PEM] invalid writes in multi-threaded libcurl based application- Add dummy sources file to test for and prevent breaking rhpkg commands - Enable testing for 'rhpk upload' and 'rhpk new-sources' breakage such as hangs - Related: rhbz#837089- Update the license to MPLv2.0 - turn off the aia tests - Resolves: rhbz#837089- Resolves: rhbz#702083 - NSS pem module should not require unique base file names- turn on the aia tests - update nss-589636.patch to apply to httpdserv- turn off aia tests for now- turn off ocsp tests for now- Rebase to nss-3.14.0.0-1 - Resolves: rhbz#837089 - Update ssl-cbc-random-iv patch for new sources - Remove patches rendered obsoleted by rebase to 3.14 - Add a patch to enforce no pkcs11 bypass- Resolves: rhbz#830302 - require nspr 4.9.1- Resolves: rhbz#830302 - revert unwanted changes to nss.pc.in- Resolves: rhbz#830302 - Update RHEL 6.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6- Resolves: rhbz#827351 invalid read and free on invalid cert load failure- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity - Require nss-util 3.13.3- Resolves: rhbz#772628 nss_Init leaks memory- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Use completed patch per code review- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV- Update to 3.13.3 - Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave - Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes- Resolves: rhbz#746632 - Adjust the patch for new sources- Resolves: rhbz#746632 - pem_CreateObject() leaks memory given a non-existing file name- Resolves: 784674 - Protect NSS_Shutdown from clients that fail to initialize nss- Add two needed patches - Resolves: rhbz#783315 - Need nss workaround for freebl bug that causes openswan to drop connections - Resolves: rhbz#747387 - Unable to contact LDAP Server during winsync- Rebuild- Resolves: Bug 784490 - CVE-2011-3389 - Activate a patch that was left out in previous build- Resolves: Bug 744070 - Update to 3.13.1 - Resolves: Bug 784674 - nss should protect against being called before nss_Init - Resolves: Bug 784490 - CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)- Resolves: Bug 761086 - Fix nss-735047.patch to not revert the nss-bz689031.patch- Update builtins certs to those from NSSCKBI_1_88_RTM- Bug 747387 - Unable to contact LDAP Server during winsync- Add to the spec file the patch for Bug 671266- More coverity related fixes in the pem module- Coverity related fixes- Add relro support for executables and shared libraries- Add partial RELRO support- Fix the name of the last patch file- Retagging to pick up two missing commits- Update builtins certs to those from NSSCKBI_1_87_RTM- Update builtins certs to those from NSSCKBI_1_86_RTM- Update builtins certs to those from NSSCKBI_1_85_RTM- Fix CMS to verify signed data when SignerInfo indicates signer by subjectKeyID- Fix pem logging to deal with files originally created by root- Retagging for updated patch missing from previous tag- Update to 3.12.10- Resolves: rhbz# 703658 - Fix crmf hard-coded maximum size for wrapped private keys- Resolves: rhbz#688423 - Enable NSS support for pluggable ECC- Add "Conflicts: curl < 7.19.7-26.el6" to fix Bug 694663- Construct private key nickname based on the full pathname of the pem file- Update expired PayPayEE.cert test certificate - Conditionalize some database tests on user not being root- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Fix memory leaks caused by SECKEY_ImportDERPublicKey- Short-term fix for ssl test suites hangs on ipv6 type connections- Add requires for pkcs11-devel on nss-softokn-freebl devel - Run the test suites in check section per packaging guidelines- Prefer user database ca cert trust settings system's ones - Swap internal key slot on fips mode switches- Update to 3.12.9 - Fix libnsspem to test for and reject directories- Add suppport for pkcs8 formatted keys in the pem module - Add verify(not md5 size mtime) to configuration files attributes - Prevent nss-sysinit disabling on package upgrade - Create pkcs11.txt with correct permissions regardless of current umask - Add option to setup-nsssysinit.sh to report nss-sysinit status - Update test certificate which had expired- Update to 3.12.8- Increase release version number, no code changes- Update to 3.12.7- Rebuilt- Appying the changes in previous log - Changing some BuildRequires to >= as well - Temporarily disabling all tests for faster builds- Change some = to >= in Requires to enable a rebase next- Fix SIGSEGV within CreateObject (#596783) - Update expired test certificate- Fix nss.pc to not require nss-softokn- rebuilt using nss-util 3.2.6- rebuilt using nspr-devel 4.8.4- Update to 3.12.6- Update to NSS_3_12_6_RC1- Fix curl related regression and general patch code clean up- Resolves: #551784 rebuilt after nss-softokn and nss-util builds - this will generate the coorect nss.spec- rebuilt for RHEL-6 candidate, Resolves: #551784- Updated to 3.12.5 from CVS import from Fedora 12 - Moved blank legacy databases to the lookaside cache - Reenabled the full test suite - Retagging for a RHEL-6-test-build- Retagged- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- bump release number and rebuild- Fix nsssysinit to allow root to modify the nss system database (#547860)- Temporarily disabling the ssl tests until Bug 539183 is resolved- Fix an error introduced when adapting the patch for 546211- Remove some left over trace statements from nsssysinit patching- Fix nsssysinit to set the default flags on the crypto module (#545779) - Fix nsssysinit to enable apps to use the system cert store, patch contributed by David Woodhouse (#546221) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387) - Sysinit requires coreutils for post install scriplet (#547067) - Remove redundant header from the pem module- Remove unneeded patch- Update to 3.12.5 - CVE-2009-3555 TLS: MITM attacks via session renegotiation- Require nss-softoken of same arch as nss (#527867)- Fix bug where user was prompted for a password when listing keys on an empty system database (#527048) - Fix setup-nsssysinit to handle more general flags formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build  !"#$%&'()*+,-./01233.28.3-3.el6_93.28.33.28.3-3.el6_93.28.3-3.el6_9nss-confignss3cert.hcertdb.hcertt.hcmmf.hcmmft.hcms.hcmsreclist.hcmst.hcrmf.hcrmft.hcryptohi.hcryptoht.hjar-ds.hjar.hjarfile.hkey.hkeyhi.hkeyt.hkeythi.hnss.hnssckbi.hnsspem.hocsp.hocspt.hp12.hp12plcy.hp12t.hpk11func.hpk11pqg.hpk11priv.hpk11pub.hpk11sdr.hpkcs12.hpkcs12t.hpkcs7t.hpreenc.hsechash.hsecmime.hsecmod.hsecmodt.hsecpkcs5.hsecpkcs7.hsmime.hssl.hsslerr.hsslproto.hsslt.hlibcrmf.anss.pc/usr/bin//usr/include//usr/include/nss3//usr/lib//usr/lib/pkgconfig/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnuASCII textPOSIX shell script text executablecurrent ar archivedirectorypkgconfig fileRPRRR?7zXZ !PH6Ȉ7]"k%nÍdڴ4Yk(`<~>}F}/W1 :N9 0JgY):8?ު'j[#0B#WM(xv"@70MHǯYTC;]ƁETCu4>n3Ȱo?]y>@nZbE&اnSX y&lJE )XcqԖ$<0;nOp  `Q~MiwaDveIƒ0KVBՑ4Wi鐮3! cNTؔA3oOnYp]Q"Mx%'L"KRN@&Rm1}%%K+~#Ke}l%'@-?-"8*UD?`y/me2CCDOꢍ A+kLo+Wy@;#U ⚹([ Iǩ,}[zQ)y/hG#3B:sμ_?{҉02DKT1dͣ:J:Vm!ڗcVx-Q:BD]R4H+is?6lhkhOhm:@'7({h.ndٴ99jG>hAz-2) G?Rщi2E^+m$ubk@ۡI-|(] 2[4cm.ʽKP YQ3-1E.CPPSk< ə0 hRy>w*r*vcU|Bdư __UjZ~ e0D^:2yO+\ʬAKlG=zwwH]҃H4q!l?昘t_;ʐyZY[O1cYĩG A.FyC-ח;X~$ 8£-uu@jDYBEa.C~:6(tg5tu:=Zpߦ7<1!KrUlZ5FQ[m=qGD` ?zUIQ#@%ٯ|q rVħCnKQYkByaR/@D|K}MيDJző*n Hӽ8QCeLJL6̺/~FlEI,֫yOD ߙu3#cg?. e<6Dz4iәc3>hP.euӯPt6vmrɇd'R9=a~.I$/! 8 ZI?2&D!FN&B_|hS{P`?J(S|‚:ߧ4'Zo+ Gz2sѸ?L!Λ\yL6 M_yv7&C1zp*а: ӭR)d =CFlB,lZo!d1spg--j]"Œ2Ế~Wqc0?'PzDpX8?!4GF,$W^/3'$Ƨ$֔U#,V!^$'!Jۿy.oݺY1"Ak:VBBP*ڹY$DVGStA0ƣ r!W?ZX_s4p,g.|sk}d{DxK‡;Ӹ̪d}k1R|^h ԇĀtW3g>j9D߻&Л͑PONۮAPRgil6rXInn&$H~tDv1f$iT;9[rL(߃A( f/oUamIXkOp2A8s؛+ ԛ%K"&nNi*jfrHꧪe8d̖G8($ݿt , ʕ gLXÂjl oJ0GJ {,, }0Ƭj'C ׁ͝h s jW2w3DKY'o+tF4] F䶌'bqs/9>b(3j`ί`y0 e K1ZQ6Ӌ Nq'[p**EO:1 H߿}Uh`l嘟Ny6KF"2(-.I b8?|_+(=r!@k;$&7^즄R"Mxu#2q9Hpv H /Z/ي6+ڗ[3-uJSH ,=\i[w=POȃ  ٲE/ Q b1X[%f+g {؝C}lbf;lKKE:e#ٝ$1>z#n6rqvI'FCc-aQYE;@^MY *rXFVҴA铫$#~(7m/U%aa@1І& ZmH/F񀸫$Mp'"::gݖYeSJ0+!OĬu3SSn}։eX{?qqbmSif-E]hCkz8N@y O&,8[OjJ2#HߋѐXw!VҢt' ~Gt'u~Ws\ۗ׊ݒMQ]vZ2]B&x.{[ 3uu]ⴶS]bhu8{ σ\.g,J :;{w ѝ56-銥]כ҇-ol*QM0*M!|tIS oi7ɉ|xNڳ&z,НB/탶Tɀ!uߨGDwW%!c`d`'!*̿wߦC+ץ80W1Jwfhyjw͠HRn}~dE߽zSĔG?[zЋ{ߤiT;Cjd}e?"rQºtfe!ؙ[ 8ڈWہ5~;UKP;W^c& t+n%`=3`.1Gk;pITފ}ej#a9zkN. CG:D:QU;Ȉ;4pxɸ?@+sf3Vsh!Z0C{e.B$tYW]eTn'`m+LI;dKPMz, ύb lB%} :?d C5mZ¾@^5ЯqsEFt>}VvTwU) i ]p(ix*rKgP]&IqgWU/N WPt"WJCe^v sq" [)u3Н/Y~s!_5%yT2DϵpӶͺMjAɟuG{lgӱ%J(@8fDT</zm nOf]])BHo"9Rz,S;iui(u-[ٶ !8cV޼:xp 3nJ)R'Eo~>s @a8@Q~S[$Wœ&4N~/-.&Y\p`zծ.0(OghlڰCu"s`nT`~""%r>䴾ȋ~ JΝU}dF5Ho@ S1Bß%oEKѦudq9Ov9,w.쬕}|Fr"N]_V_şEٚj!i|@Rź^$0V$c6MTL@Ýs@l:n5 _dx-60ww;&8 rϪ Wpi7\-σsf7X6`@iZb!w0J16Ժ3QA.t͎ $Z,4 j > g%ynXg&?Ut'A H)+0{ CXQ<,\ ҈C|-:R<NE}rXp4܀+1p|LJH S;[N[cԦD!4~y꘬B]êMo-1= PxZH=*-?فb'PV[<lr#I8=}wFR_PZXM>/@^'}|| ~M:b9ʍ%=<6Է& 8WG Ʃ.aA sX( hg qӓDFUc F q_.873j".(ioኗV=Ɠ^wKPmABRB7}(JhA9Ѵr=셒Īok*N )[`3mka<1(1̓ pUkϚrQ_ 6rO wv=m$ʐ {8iIwquHY!INcCd9W#xF5Jɏ(J#l m(00g1m;o+,PiR Tk֍SkەaKUtpnc!#EhXnk0Rfj<3O(HiL'wށ&,dvr)?)puҎnPa:μ.4ږ' +\-l/$Ǫwh}uO7*Prgk?K#cF@A(poRB95RgC3un{2TXj̎6v >ۑN2ZpM,̽S`[Q:j_C*f5]os,=>^]eb3HALd,h&OYۆCƪvM GX١=r \5oy̞R*PKs&FsFWU s_sǼ1fltjĽ!%eX1^=:Y4\Q9E F5ߋJSUD9KD@(*ę&+ύkjPRJAgc4EK/mpuCКwe(u{Rv޷YN2 0d.~NM" qJǾ;.DOl[A<",$ [?sP[)b| bSOI ъ H=ipD&X#W kN l jx+Fi3XEN]<< !G-k֪!n@:t <6;dM-tYJ|P)ā^Z WN:>en!Y ݧoIar˅ CIJ U j*>N*=7r iJi:8J 5V,lHH9jȞ.L(8^lʇ{8i(Q>a5A#'acOGQ+U?ZAjp! r23Q#WS1Mz BGcռB(F.O`cݽ&ktxRj8^n2pqlƌS@#SB0'۽T+ Q0W45WG1o\)^=9/|-.rK"'9Zs,g6AfRɼrczb[ށ:A~ݠWv46~ˋ`Y@D+.}~i׫F*YVdg[x+'7x.t2 n`Rz.ɄmS[ n-41=:z9NJIWw]'`8ÙSڂ9x)JO>|cu SJvw[cl[.7U_vm౶ uֽ.Er!җPg|kDrPO=:X3xP"YH(YW"ݘ/|->PMÿİۚ~Շ3[QU[A u8Qf{Wbx&VSK7{k6^y`|U!Y_iJ MX#gQxVVхN nr萨CTa.sYК(0{0trjg#b hb޸F1?|Y"iђJ;u{1+OZ_$@Q[UיiPk(i~|GNR$8[/$|kz%P*L@jEF[7HgR3A())=Fsy"m u)ay' 3 m(A^e߇Ua^2j%iV~y_E73q@]-)叿4:Pa]rAo=~N΁b]'ڎ>g(Z5S%xȿmrns}H6_ni{ 5sF $RUAoX҇94uתhNvչ@u=~7ʍy*혟g)7k!`AR.9PY8?;֪ 8'ݞSJ-{A覊J2.JQ:B\Q?j(%AN|lA14=xp&Vt\^饠7qI&]tL{" `Ud~#F􃀧Wzw$ڂ1-5X m5YB;(5iM30+:yIl.^TԢr*]kYux|֯;H0*=;m6` ٙ"oLOkq,P k,qسK@zt3qI8G#\|;FeFmQ 8K[ƹhDCZ/Jyy0i\\#C+GLrNS*ccm;&^cMgEdhƛO9؝num?|U`bd/K]~m*V C\8 J*c<M@nzY+<B{,o&#Ac5&C\<~`@[svx8q#pc$0V˾>T[J׏Y^69K AvożWVr^C%.ړ?2Bxy> zc}xνg%BY@7@b@$@a,N6 0_*?0ĢbXfJ,n#* [U_T)nBhB⚧]”-}x${r5֑isDP{@w8P=Pc:{+!= orՄI,6&[_>V]aQW!OئFԻr3 y "}x}'!R2P/k;2ޘҳZ0z!!J䷷VDS&`7Ȏ q1A<7ΣKpVPt'sǨlQλ^tɭeuΑ71hGd/Mh,ܔGHc6낼2!%)%$.0:8?Fm3!Zlb"xFuL AkUQ* @X(+J?"~1A-8Z7L!>y`\t- T( 6LR< q &WdDx !=u"K>V=foW ^{\ b:v;PϖP%{rh*|_Uvj9I~NU?.nѣHu˛"o_Poz&>$Cyk̼̇4|"!(VR(TV^S(_Y "ep~]B@V`/".qaE!G$;)t dJ*$ 5+H!]6Cxu^f·MhKqNN$^خȰJ) -cA6^? KՁ2xMQeF*YgK8ǥ%ڕ?Z ,.& 9Lŗ/Z%p<ЀO4 -jOx>xݱfA`u&& U.31mx=2.EBy8eR=ā;01UCs~o}Z+zw<k>N hʕx i3cK2xp{r]gy\0)}r9py̥,H-Z~OdsK 9mM1j+^} h,}֍A?BhϨTi)siLWLHBK;cZH:?fsa uvwI~{ ĶfvjP"gESE澮vI؞^ɐi=X-3zYN Phݽb1cjcr%3Is@ q>Id4c^<tW:(qN2P}(^(va*c0$w$:KA" )~ *EF)8AU;q^2&;Ό!_XS!EHC]=?"el['pAZ_PejE٫hViM DǔcljƋF̦r \ЈƉ&ލ *R[A \plii%\\h YM7DʥfB&JhykPtRآ:G?|8)PpOט]'TP§O\)n"JW|eW`b|Blﯜ NP%3qR(vax(\D*BDQ ntۘҾs8 #: F!q!T >\P ~&k!`7wn\G {/rD#W Ms"|}sFaRb*K75åʭo{CA6XB@;yW@  w> "sK */HYߠ#mkNR4{X8D<H8 ??9[!iz(jenfJBRs,U]T!BW <(8lU~  .uܷtXG"$4̧a' bnu>R= 7w)0D̗Mx. 0h;e8]bUa##(pXs!w%,tj)Ep,5-_f ?dؚ xQXe'a05v4]1`HW* sq%}^[ϨsPkCz9 ?~Ym937AY s!$6F ѯ>gӈ5`g#mOTEP>D S>"%:] i|I{Uiȟ)MHOmC-9_S̵a_Wp HD*ʇ<^^-GT.O7T&bTަӣrQwS'"a({N"Uwiۥd$~|| uc"63X.,f*@fBxb@B*+b$G4cVRI-zb y)cu7zԩF.ZrU2AM @띙b忥𞖪4fy26(O#}~ad(XGj)}:;ka!Ql(70ge0D*f҄ ^P~rs`;Sv74-1e_E};1W`dya>:'‹OJl΋joOי*ͺc&V1U8؀1s`rc(;{Jd! ڂUg5sM]09#t~|J2HnDzՒ?%!His.@Li r%f?TbL11T;Mfr:R pJOi:L0NñQa?vP¤Vs+آ5=QO8 ;s>1u\Tӯ,}!%^L6kV=L=E@1s m\+b0]q6Jޱtk"Ț7ل>B:nn_dȁrl i^'P[wR(:-_r wVmP)kzs?W l*=A!Iϴ̦m.b /mu c |/{ē0^?.oݺ %fR^& ]ogwI#M(6QoS}CuJ`u6x-Z)t[ 4x$ɹ™'2LOPjq7v/pd#%Z&'-w=T)uTŭ$XsQ:KpWHvmp-e:HФDYw5L6DN+oNDKJe6|jF/V[˃C;v⤈u@.ZRchKO4YO0Z8JN#I!+= kAvN<&8[0m$#|?M<.[bTvg'RiICXО׍KaE^ Swi5$y S{;8~3Pҧ(QARnS#g.V3(E/oWn~;ۙ04rH༮$]M26=`jּ?a pCH.VS~e0FJɠz9FWR>Mܻ$b9[}}3(_#XR4MA)A1cqih  hQD#L@XCз_h$ ̞D ڈ%Q8]'¹aZH?ر 4@A^O[ԐsQ;?щǺz zCv}ҵ@] 1e%]!/:.;I /r8X!4l}+@c Aq>};9DGf_NZ dޟ|bdNs d5ʹy^6b,&>/x>T -q^%Ky_UOԀ=6ӏ[H"- -G_.dVWqۏǸ=o'mD@!X,BFqR뷌n.|$ gwao#TKvn8B&f5l??@IbXnIX8Юr8-\6\gC7ljd \r?2rR>BZAGO 5Zgҹy*!=Ba<0P%|6N^m1"uBG$N[F:P. AQ$R S 'Qog4?J65vO;b&n.6r%HxjӅ]UÓVJ.̑ J(2ֻ`dkΦ^;FƃP)PiZ8܈Pٺ搲!03tE¬bfG:aF>h-` lH;Ta~O }bYP tJT)k̀J+SA:Sܿ $=+yKgEnWF%KnW7Gm [ A1bC |[0zL\pZ~L`+a[zc3[Oekz-Lwe7&r9pnГ}1ljX_X%8A"Zb `Q= n8Ѭ5J 옸ߠↅNE){ B}BSWFrHw?8a&39"b]7܂ M ?8CɋpCA;qUIjFĪtD? 힝'V:.vWR5NX:^9 ѻ)x)d&''f>GD䡕m'3.--/uXB/^u#ls[ 1jRQG؋01<:LH;YiЮ:/?QPXEBtL1 '&1:=yLgr3g_bd6,ibp'?Uc\Q],6g_)M@(5ѽDcq6S`iΆ<&%Zmݨ ),"ݶ|z$؅"BW/V鮶{ySC1tpſpIj O-'<5  >Zޒ)mOή5؅yQ[F":P>?/CC;GiH0\kn{b Yߠx 5: V(~ {NNE_7O|#8a0Wux[L5@ܭ*btǥ-Ɏ*z#"A3ӄ"J(aK&_V>"1:`ktD`1JUQWMK&fy‹{&S!SOfI{r!VxSij6I@ʱr윫Y-MUS)UNk3g[K6)*om@\dd4+ 5 ^kxݽ~x x"VN8J/֕c Gh~cNɚ^kx3u*T |%2SԀ+:byH7"1_o'~B>'w¦bq$y2YķS*jOi]r'Մ(}ѣcʛ\[C6'/ Uʟ%xF (P"z#Aױ ;aH\b_-Bq%56.m,+# ,=vQ6Q ]tfb8qu󧂗\{]R[_mwm|6Q36uq5 ߾٭.pXޙ1 Nք*{;E7uVSXOI)U)S!=7 #pnDy mw{D?ҚI|ذZ,]'r)޳V< 0O!E;(.ҋ۞ "z,ýBFi~O. !JVuqM-(Mb4AOz>Ya(:D@Bs+4eX>&l{*MH=6"aL2m>bف$ rf;'(k 3ArwA OXX"/w=UN*=?xNS amV6]Lܿ_2\fVst?@4fO[-ef:B=z47=I1B>wdqX@>݁9ďQµ)W9iebŝFrQtkcȁ#:Vܕ]}hhn#ca_:YCΨtqX'ߞO@l %9Jb3P#X0NC|p g:gXx"Wz5)\_sQ .b*Y ϙ$N3OnaVsB%a&6 (JY \QgC!݌rG;:y j-rAס~`EB֢ztZrtsE $fbQ%p-`W;n0G47HʇëO!Gxͩ?̺R>=a<Ɠgd?_vi㦱1zt>'ym¢"˴O/ӄaer !*Rat"{EۏIjXGP Z3w{\5G^#ջ/A}fp ɏخU0!0(6 Lx5..A,!BW( E ^IxlC>=2jB7@O@(1VUӞzV_䠙Oq~Z@*InP__~y eZDA΄nKIG^"uMQS"pSLJ6lV@Ǵcm No2S:iA̳31܀9m6f]p>ZNԎ5g@G?="z@`i(˚sQ~N~ DThؽd6YIieI{ƕ=l%[puJFr/x%Id '_dфhP(Ԫc>a0n&K 3oŒ};)a"tz̉|_ʰ0zxa[փͣBuv O)WUN _,~$"b 0|hELa+EDzi7DvMoG#A"M72ҌAt>?)tQ T1ijǣ vQzżwCUǑt]IJ;[=d#Eu!~VR+gŚn?x`WsVAb6.6kH;h9kmt!PW^znaا)K7+2cOL+(?W6D<}1=<0&U|^mA1p. ]?5lL~sZ(ԕ5,QO5 6y)&`׎(u7Q(]QQmj<oηL^c>` )-/-C)?t ]^ne*'ZX*KtBݙ~E1dXܫ+3 +Y8:spGܦO#r^'դʍ+bf)x{@xeadux#4Z:][Ĵ9]O*^R5O#`{Eb)\nttK>t꭮C`4Xx j|lPdz.Y'TإLo{{X,wb9ݽ!N4%˝o&f>r}_f2:ۜT`ν̮W :xUzk3(ë2Wu).hY';t5^dx fK-No~`fX䷋8ƀ4E'5Be1,wAGX'yp,wҟߨwkx,QKu:AlYo>:E`c[c<(T2 c["oKPN?1CEdd- +n ^k')e3]* G LGW9JHιdѼ->"s?,tq@ DX+S QqtsZw ԪSg},ցHd&l`:9IeTH&Q'r3DlGbD*c0>/K*Wm\g;~5wלX֛5?o…N«-+elH˱׸<^bqm[g?1:wPw4{0hXH)L4ؑpL午nWRU5PQb+C+4_Q?s^5Ɖv*y9q(kj$LEGI!Nb2~ކy3lWJ_hVd0/ ձl.%50^El_Y?GLJDZ ;G.o=%N½Q/HyδII~y /LHK6Ot$v7t4=@bGT4ש~y t B$vfBM%նu XcM vJCS'Fd.|~o3e7"涹A{TK[6ٙ,(|iN'%ʫ1+"Jd J Ap+ˠKTץu05F&'N2MԐ\xwMDž.0ʷl:P&#꯴v ~EInI\=if m" % Ze^*PEK.T2Uv7})e\/'d>YZBd~^0 #k:?%UF}zmQ\ 7::CeJKLstDd Iz#$K ,L`cEy;G $"Ԍlh5 so;RoC$ gDMG%>O7"1p6G ;# o]壹x%f9KtL=%?{ޣW\KzHP>;^=V*luD2Ąx`GIYhg`Mw^Yݠ1g@."j4zI,0ZR 8&djIZL.(˅u>9ۻ*ӱ?AՉ dy JɈ/'p\e+5JPZ 6Sz)0Ae`v 9`C9d]6 1N8Dwߖ OlxPO2{IE&cPȎHRM}Ӎ+01}&1ΘY/"aGpo2Zpi#PIiWQҗxV(jjȷ"H$s6cJr:CG6=NN  JٳdSOSzfiu";Hlb(;C M |ZVXO.\᧹X&dg쫔"ߝfhU`]ԱoBR~RW4TC+7ݨ8yl]BWHC֘]―sJ۫cܕU~0R芏sqy"ھPnC/` lxqqF?ku]].M|ԕ#Xd]+"ΏGlG_ ) c:'SMQD#+f/<` "7P;|t0D):NS]YƁ^0nHC!qFہ [/.+28^nݜZ|7oVl.~Ͷ):FT P!mUn)|+XvY8upBDٚoAU=L'&/ǝkn[g)쪕̽ݹl3q54c pUwoTCtEyJtus0^GQM\B7Z}ۈ"F^ 6'<*]|"Z,)b[ORt8dh^Ii@|KwTaypo9-C*1r|P<݇w2'{Mu@;nǡGʍDa$!ob7Snj$ 3ڥ%$5{2F.>2Ye٨<- Ҁ^~]FE=`mNF0;٥jQם oKЯǶVL q?: ieHYC>C+A\{"2n?y#p3MqՆy4+# z@^6)<Y%?o}ͬX}oz?9 BD"f BpsiU#۱ z?G]- ˁY{l|&Bce=@,R̉+3y+ķbǜy,J~w^5ٴ-za! zQB†W)*zÏ䵬o*Vr^fI?x-(bBڗ<^À7xW=0'D|K!\&mru$=YPlT@Ob;NPdοx$}I_ԓ݅<)F WLh-1|S<-5 Y*Ձl |#Ki-{VsH[\4dtJӚLڙzA>]7$>/r󖯦O'×5TPm#fȷIrf/PNH -h :P:̕YIZ1^{>)˅yq ךFhedgo#hjIlocV26/%^Ja Tzjzor.]U~@^`h^{o>ufpM0#"*cW] 7nvq!۠]9K϶i!Y3^YNX:vq?DyY<[z׿|z b1eZX,x"ѯ<|p,D5rH Feu;ܪrY\ZXh?Ġ[ ..4}: N߼}Tݍdq9K:)oe'7QRPZ='3Nlʤ/x/ !dwā7zmjJLqHI0%lQӳG4iVPJ ցzh]@ |Ȍe T` 8ᅷ;[>69D&u7QNl2ٛcfDRN\tHo? ZUv2b.uN)g=7; "~A26E`+ԇh̵!Z̿0X)0)Ξ u–AE3Q~:J'UyM`n .C^ tȱ&#Nf8Gi0e0H*Xp o'{nn0c<Ś#o>F-]}}A Op-[c`mQ[IQc\]0a y\8dgMJ([斖(? eL8q/r|Ř^64p@"lboJ/ ͉VxF@ߡ.o2r_lg-~v-.lǜ9O3nia18ПU6!:M-{|ؤI蘸DF㫡Z$msˡnFܟ^6{| V}nsLJ8Avc=R*3oE݉S*љA?a/R9ǣ݇5o%&־+p"13{z&-R&ɜK[yy!=]1걉]aki!U2? lǀ]b@kNnS*rSz 0sPFU/sCWpd`<#yZ.On_Wq֮Rىʈ>- G &_ܬEIͣtx8 P $[o6_脧>#kei2g"ǵ mX,nM털C*7G' 3E PO¬9}]u $ig7iJִ,J i}usþڑnHİ3 uhN݃iūBCBCGWOos͗Z:@r: @]L9&BR\Gh-X+jgh7=Ŵ?b`,4D4W{Cd@f&3*T0` TU̅> 5?jWɪ-By8Rvs $sNcv% J;*5Iz,;"O~N*~<8ғoM|r1Ac/ {m Nn!Z^ȗ\:a‡q2T|Vռ۵ ˓d'D'<ξM/v%o Lo'ЭbKSg_練Pr#ƥuدS4C2wuoa_5ϞLZ PXv?œb/4Fv_<o x67+yHnqxCXC0l1vp}Gx;KP K`,4wT= ~x* w- F0xp=oP1Z=/JEH|$Yתw< ;?`;!a^"߲g ң%`I^ז!aOqF(Kێ5|7bat=\FƱPB_;5etC; )xf9>`U '}qޑӛ8Qw _`nfM']cbRɰX)Jb2r2ҪIu Qb<0R-n㓀pa$ū18ZLlrWfK֠:Q0#w1@!8!rR>W"ڜ1HPJW1Z<ҿP=`KiCrKӡ696WH5륌Ң iB>؞}%ra|ԏpRјd'I~'ʔ0'/E2 L> JeRc //UV-D}u_g&RH'l{!YD65m*#h6˟Xa-s'lO[, =!9 {E z)G <3ٴN$G7 ;y &Nf 9)1U5LYmS"ϯL2KRkj>r 8 !:oSa;H cS[3ڞEȼuCˌ\ċx7M1["Ve ~P`C@7];AlL_D f3@F$^b9o(a(ON;>@ ,Fyk![曯/8)d3%\"!QZu!9 V9sA*t˅1A 6m"wZpp[CQih)@v~HPKˡKypB8u2DK>zv{A\^@ iүOSع޽=~X}ޟ i;j7=Ba>MɝN$-#ȉ 1{󄁓-ѤV$r<27{1W7 ǂ3ԙ ^(tW쏾LnQ>\2䆥f_G߬vPn_~FAu4kg$iBjCB> k7> YZ