nss-devel-3.28.4-1.el6_9$>OL<ᬍk'5GJ>8?d   O CIP33 3 3 3 g3 3h3g3f3P(89:OYG3H|3IH3X|Y\3]3^Hbd/e4f7l9tP3u3vwD3x3yCnss-devel3.28.41.el6_9Development libraries for Network Security ServicesHeader and Library files for doing development with Network Security Services.Xc1bl.rdu2.centos.org Development/Librarieshttp://www.mozilla.org/projects/security/pki/nss/linuxi686  YRCyQ - 3.28.4-1Daiki Ueno - 3.28.3-3Daiki Ueno - 3.28.3-2Daiki Ueno - 3.28.3-1Daiki Ueno - 3.27.1-13Daiki Ueno - 3.27.1-12Daiki Ueno - 3.27.1-11Daiki Ueno - 3.27.1-10Daiki Ueno - 3.27.1-9Daiki Ueno - 3.27.1-8Daiki Ueno - 3.27.1-7Kai Engert - 3.27.1-6Kai Engert - 3.27.1-5Kai Engert - 3.27.1-4Kai Engert - 3.27.1-3Daiki Ueno - 3.27.1-2Daiki Ueno - 3.27.1-1Kai Engert - 3.21.0-8Elio Maldonado - 3.21.0-7Elio Maldonado - 3.21.0-6Elio Maldonado - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado - 3.21.0-2Elio Maldonado - 3.21.0-1Elio Maldonado - 3.19.1-9Elio Maldonado - 3.19.1-7Elio Maldonado - 3.19.1-6Elio Maldonado - 3.19.1-5Elio Maldonado - 3.19.1-4Kai Engert - 3.19.1-3Kai Engert - 3.19.1-2Elio Maldonado - 3.19.1-1Kai Engert - 3.18.0-5.3Elio Maldonado - 3.18.0-5Elio Maldonado - 3.18.0-4Elio Maldonado - 3.18.0-3Elio Maldonado - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.16.2.3-4Elio Maldonado - 3.16.2.3-3Elio Maldonado - 3.16.2.3-1Elio Maldonado - 3.16.1-14Elio Maldonado - 3.16.1-13Elio Maldonado - 3.16.1-12Elio Maldonado - 3.16.1-11Elio Maldonado - 3.16.1-10Elio Maldonado - 3.16.1-9Elio Maldonado - 3.16.1-8Elio Maldonado - 3.16.1-7Elio Maldonado - 3.16.1-6Elio Maldonado - 3.16.1-5Elio Maldonado - 3.16.1-4Elio Maldonado - 3.16.1-3Elio Maldonado - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.15.3-11Elio Maldonado - 3.15.3-10Elio Maldonado - 3.15.3-9Elio Maldonado - 3.15.3-8Elio Maldonado - 3.15.3-7Elio Maldonado - 3.15.3-6Elio Maldonado - 3.15.3-5Elio Maldonado - 3.15.3-4Elio Maldonado - 3.15.3-3Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.1-15Elio Maldonado - 3.15.1-14Elio Maldonado - 3.15.1-13Elio Maldonado - 3.15.1-12Elio Maldonado - 3.15.1-11Elio Maldonado - 3.15.1-10Elio Maldonado - 3.15.1-9Elio Maldonado - 3.15.1-8Kai Engert - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.14.3-37Elio Maldonado - 3.14.3-36Elio Maldonado - 3.14.3-35Elio Maldonado - 3.14.3-34Kai Engert - 3.14.3-33Elio Maldonado - 3.14.3-5Elio Maldonado - 3.14.3-4Elio Maldonado - 3.14.3-3Elio Maldonado - 3.14.3-2Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.0.0-12Elio Maldonado - 3.14.0.0-11Elio Maldonado - 3.14.0.0-10Elio Maldonado - 3.14.0.0-9Elio Maldonado - 3.14.0.0-8Elio Maldonado - 3.14.0.0-7Elio Maldonado - 3.14.0.0-6Elio Maldonado - 3.14.0.0-5Elio Maldonado - 3.14.0.0-4Kai Engert - 3.14.0.0-3Bob Relyea - 3.14.0.0-2Elio Maldonado - 3.14.0.0-1Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.3-7Elio Maldonado - 3.13.3-6Elio Maldonado Batiz - 3.13.3-5Elio Maldonado Batiz - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Elio Maldonado Batiz - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado - 3.13.1-4Elio Maldonado - 3.13.1-4Martin Stransky 3.13.1-3Elio Maldonado Batiz - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.12.10-17Elio Maldonado - 3.12.10-16Elio Maldonado - 3.12.10-15Elio Maldonado - 3.12.10-14Elio Maldonado - 3.12.10-13Elio Maldonado - 3.12.10-12Elio Maldonado - 3.12.10-11Elio Maldonado - 3.12.10-10Elio Maldonado - 3.12.10-9Elio Maldonado - 3.12.10-8Elio Maldonado - 3.12.10-7Elio Maldonado - 3.12.10-6Elio Maldonado - 3.12.10-5Elio Maldonado - 3.12.10-4Elio Maldonado - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado Batiz - 3.12.9-9Elio Maldonado - 3.12.9-8Elio Maldonado - 3.12.9-7Elio Maldonado - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Kai Engert - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5.99-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-7.3Elio Maldonado - 3.12.5-7.2Elio Maldonado - 3.12.5-7.1Elio Maldonado - 3.12.5-7Elio Maldonado - 3.12.5-6Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-2Elio Maldonado - 3.12.5-1.14Elio Maldonado - 3.12.5-1.12.1Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.10Elio Maldonado - 3.12.5-1.8Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-1.2Elio Maldonado - 3.12.4-15Elio Maldonado - 3.12.4-14Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Rebase to 3.28.4- Fix crash with tstclnt -W - Adjust gtests to run with our old softoken and downstream patches- Avoid cipher suite ordering change, spotted by Hubert Kario- Rebase to 3.28.3 - Remove upstreamed moz-1282627-rh-1294606.patch, moz-1312141-rh-1387811.patch, moz-1315936.patch, and moz-1318561.patch - Remove no longer necessary nss-duplicate-ciphers.patch - Disable X25519 and exclude tests using it - Catch failed ASN1 decoding of RSA keys, by Kamil Dudka (#1427481)- Update expired PayPalEE.cert- Disable unsupported test cases in ssl_gtests- Adjust the sslstress.txt filename so that it matches with the disableSSL2tests patch ported from RHEL 7 - Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests - Don't add gtests and ssl_gtests to nss_tests, unless gtests are enabled- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release - Add patch to fix bash syntax error in tests/ssl.sh - Add patch to remove duplicate ciphersuites entries in sslinfo.c - Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range - Build with support for SSLKEYLOGFILE- Update fix_multiple_open patch to fix regression in openldap client - Remove pk11_genobj_leak patch, which caused crash with Firefox - Add comment in the policy file to preserve the last empty line - Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not provided by softoken; this superseds check_hash_impl patch- Fix problem in check_hash_impl patch- Add patch to check if hash algorithms are backed by a token - Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256, which have never enabled in the past- Add upstream patch to fix a crash. Mozilla #1315936- Disable the use of RSA-PSS with SSL/TLS. #1390161- Use updated upstream patch for RH bug 1387811- Added upstream patches to fix RH bugs 1057388, 1294606, 1387811- Enable gtests when requested- Rebase to NSS 3.27.1 - Remove nss-646045.patch, which is not necessary - Remove p-disable-md5-590364-reversed.patch, which is no-op here, because the patched code is removed later in %setup - Remove disable_hw_gcm.patch, which is no-op here, because the patched code is removed later in %setup. Also remove NSS_DISABLE_HW_GCM setting, which was only required for RHEL 5 - Add Bug-1001841-disable-sslv2-libssl.patch and Bug-1001841-disable-sslv2-tests.patch, which completedly disable EXPORT ciphersuites. Ported from RHEL 7 - Remove disable-export-suites-tests.patch, which is covered by Bug-1001841-disable-sslv2-tests.patch - Remove nss-ca-2.6-enable-legacy.patch, as we decided to not allow 1024 legacy CA certificates - Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits - Remove nss-init-ss-sec-certs-null.patch, which appears to be no-op, as it clears memory area allocated with PORT_ZAlloc() - Remove nss-disable-sslv2-libssl.patch, nss-disable-sslv2-tests.patch, sslauth-no-v2.patch, and nss-sslstress-txt-ssl3-lower-value-in-range.patch as SSLv2 is already disabled in upstream - Remove fix-nss-test-filtering.patch, which is fixed in upstream - Add nss-check-policy-file.patch from Fedora - Install policy config in /etc/pki/nss-legacy/nss-rhel6.config- Ensure all ssl.sh tests are executed- Update sslauth patch to run more tests- Fix syntax errors in patch that disables sslv2 tests - Resolves: Bug 1297888 - Rebase RHEL 6.8 to NSS 3.21 for Firefox 45- Resolves: Bug 1304812 - Disable support for SSLv2 completely.- Add patches for ABI compatibility- Disable extended master-secret due to older version of softoken- Enable two additional ciphers and keep another one disabled - Prevent enabling extended masker key derive- Rebase to NSS-3.21- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol - Resolves: Bug 1289890- Package listsuites as part of the unsupported tools set - Resolves: Bug 1283655- Resolves: Bug 1272504 - Enable TLS 1.2 as the default in nss- Rebuild against updated NSPR- Sync up with the rhel-6.6 branch - Resolves: Bug 1224450- Additional NULL initialization.- Updated the patch to keep old cipher suite order - Resolves: Bug 1224450- Rebase to nss-3.19.1 - Resolves: Bug 1224450- On RHEL 6.x keep the TLS version defaults unchanged. - Require softokn build 22 to ensure runtime compatibility. - Relax the requirement from pkcs11-devel to nss-softokn-freebl-devel to allow same or newer. - Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1)- Update and reeneable nss-646045.patch on account of the rebase - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Fix shell syntax error in nss/tests/all.sh - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Restore a patch that had been mistakenly disabled - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Replace expired PayPal test certificate that breaks the build - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] - Resolves: Bug 1131311 - rhel65 ns-slapd crash, segfault error 4 in libnss3.so in PK11_DoesMechanism at pk11slot.c:1824 - Temporarily disable some tests until expired PayPalEE.cert is renewed- Keep the same cipher suite order as we had in NSS_3_15_3_RTM - Resolves: Bug 1123092 - openldap-2.4.23-34.el6_5.1.i686 fails after updating nss to nss-3.16.1-4.el6_5.i686- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 - Remove unused indentation pseudo patch - require nss util 3.16.2.3 - Restore patch for certutil man page - supply missing options descriptions to the man page- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Resolves: Bug 1145432 - CVE-2014-1568- Fix pem deadlock caused by previous version of a fix for a race condition - Fixes: Bug 1090681- Add references to bugs filed upstream - Related: Bug 1090681, Bug 1104300- Resolves: Bug 1090681 - RHDS 9.1 389-ds-base-1.2.11.15-31 crash in PK11_DoesMechanism- Replace expired PayPal test certificate that breaks the build - Related: Bug 1099619- Fix defects found by coverity - Resolves: Bug 1104300- Backport nss-3.12.6 upstream fix required by Firefox 31 - Resolves: Bug 1099619- Update nspr-version to 4.10.6- Update pem sources to the same ones used on rhel-7 - Remove no longer needed patches on account of this update - Resolves: Bug 1002205- Move removal of directories to the end of the %prep section - Resolves: Bug 689919 - build without any softoken or util sources in the tree- Remove unused patches rendered obsolete- Fix pem module trashing of private keys on failed login - Resolves: Bug 1002205 - PEM module trashes private keys if login fails- Restore use of indentation patch until another bug is resolved - Resolves: Bug 606022 - nss security tools lack man pages- Update to nss-3.16.1 - Resolves: Bug 1099619 - Rebase nss in RHEL 6.6 to NSS 3.16.1- Resolves: Bug 689919 - build without any softoken or util sources in the tree - Add define-uint32.patch to deal with using older version of nss-softokn - Fix suboptimal test failure detection shell code in the %check section- Prevent users from disabling the internal crypto module - Resolves: Bug 1059176 - nss segfaults with opencryptoki module- Improve support for ECDSA algorithm via pluggable ECC - Document the purpose of the iquote.patch - Resolves: Bug 1057224 - Pluggable ECC in NSS not enabled on RHEL 6 and above- Install man pages for the nss security tools - Resolves: Bug 606022 - nss security tools lack man pages- Fix the numbering and naming of the patches - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- make derEncodingsMatch work with encrypted keys - rename a patch, dropped the experimental moniker from it - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Revoke trust in one mis-issued anssi certificate - Resolves: Bug 1042686 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]- Disable hw gcm on rhel-5 based build environments where OS lacks support - Rollback changes to build nss without softokn until Bug 689919 is approved - Cipher suite was run as part of the nss-softokn build- Build nss without softoken, freebl, or util sources in the build source tree - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Update to NSS_3_15_3_RTM - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 - Resolves: Bug 1031238 - deadlock in trust domain lock and object lock- Using export NSS_DISABLE_HW_GCM=1 to deal with some problemmatic build systems - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add s390x and ia64 to the %define multilib_arches list used for defining alt_ckbi - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add zero default value to DISABLETEST check and fix the TEST_FAILURES check and reporting - Resolves: rhbz#990631 - file permissions of pkcs11.txt/secmod.db must be kept when modified by NSS - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Add a zero default value to the DISABLETEST and TEST_FAILURES checks - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix the test for zero failures in the %check section - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Restore a mistakenly removed patch - Resolves: rhbz#961659 - SQL backend does not reload certificates- Rebuild for the pem module to link with freel from nss-softokn-3.14.3-6.el6 - Related: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] - Related: rhbz#1010224 - NSS 3.15 breaks SSL in OpenLDAP clients- Don't require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Additional syntax fixes in nss-versus-softoken-test.patch - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix all.sh test for which application was last build by updating nss-versus-softoken-test.path - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Disable the cipher suite already run as part of the nss-softokn build - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nspr-4.10.0 - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix relative path in %check section to prevent undetected test failures - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Rebase to NSS_3.15.1_RTM - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) - Update patches on account of the shallow tree with the rebase to 3.15.1 - Update the pem module sources nss-pem-20130405.tar.bz2 with latest patches applied - Remove patches rendered obsolete by the nss rebase and the updated nss-pem sources - Enable the iquote.patch to access newly introduced types- Do not hold issuer certificate handles in the crl cache - Resolves: rhbz#961659 - SQL backend does not reload certificates- Resolves: rhbz#977341 - nss-tools certutil -H does not list all options- Resolves: rhbz#702083 - dont require unique file basenames- Fix race condition in cert code related to smart cards - Resolves: rhbz#903017 - Firefox hang when CAC/PIV smart card certificates are viewed in the certificate manager- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement. Please ensure that older packages that don't use the alternatives system for libnssckbi.so have a smaller n-v-r.- Syncup with uptream changes for aes gcm and ecc suiteb - Enable ecc support for suite b - Apply several upstream AES GCM fixes - Use the pristine nss upstream sources with ecc included - Export NSS_ENABLE_ECC=1 in both the build and the check sections - Make failed requests for unsupoprted ssl pkcs 11 bypass non fatal - Resolves: rhbz#882408 - NSS_NO_PKCS11_BYPASS must preserve ABI - Related: rhbz#918950 - rebase nss to 3.14.3- Revert to accepting MD5 on digital signatures by default - Resolves: rhbz#918136 - nss 3.14 - MD5 hash algorithm disabled- Ensure pem uses system freebl as with this update freebl brings in new API's - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Install sechash.h and secmodt.h which are now provided by nss-devel - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Remove unsafe -r option from commands that remove headers already shipped by nss-util and nss-softoken- Update to NSS_3.14.3_RTM - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Update expired test certificates (fixed in upstream bug 852781) - Sync up pem module's rsawrapr.c with softoken's upstream changes for nss-3.14.3 - Reactivate the aia tests- Recreate the distrust patch by backporting the upstream one - Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Remove a patch that caused a regression - Resolves: rhbz#883620- Fix locking issue causing curl hangs and authenticate to the correct session - Resolves: rhbz#872838- PEM peminit returns CKR_CANT_LOCK when needed to inform caller module isn't thread safe - Resolves: rhbz#555019 - [PEM] invalid writes in multi-threaded libcurl based application- Add dummy sources file to test for and prevent breaking rhpkg commands - Enable testing for 'rhpk upload' and 'rhpk new-sources' breakage such as hangs - Related: rhbz#837089- Update the license to MPLv2.0 - turn off the aia tests - Resolves: rhbz#837089- Resolves: rhbz#702083 - NSS pem module should not require unique base file names- turn on the aia tests - update nss-589636.patch to apply to httpdserv- turn off aia tests for now- turn off ocsp tests for now- Rebase to nss-3.14.0.0-1 - Resolves: rhbz#837089 - Update ssl-cbc-random-iv patch for new sources - Remove patches rendered obsoleted by rebase to 3.14 - Add a patch to enforce no pkcs11 bypass- Resolves: rhbz#830302 - require nspr 4.9.1- Resolves: rhbz#830302 - revert unwanted changes to nss.pc.in- Resolves: rhbz#830302 - Update RHEL 6.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6- Resolves: rhbz#827351 invalid read and free on invalid cert load failure- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity - Require nss-util 3.13.3- Resolves: rhbz#772628 nss_Init leaks memory- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Use completed patch per code review- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV- Update to 3.13.3 - Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave - Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes- Resolves: rhbz#746632 - Adjust the patch for new sources- Resolves: rhbz#746632 - pem_CreateObject() leaks memory given a non-existing file name- Resolves: 784674 - Protect NSS_Shutdown from clients that fail to initialize nss- Add two needed patches - Resolves: rhbz#783315 - Need nss workaround for freebl bug that causes openswan to drop connections - Resolves: rhbz#747387 - Unable to contact LDAP Server during winsync- Rebuild- Resolves: Bug 784490 - CVE-2011-3389 - Activate a patch that was left out in previous build- Resolves: Bug 744070 - Update to 3.13.1 - Resolves: Bug 784674 - nss should protect against being called before nss_Init - Resolves: Bug 784490 - CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)- Resolves: Bug 761086 - Fix nss-735047.patch to not revert the nss-bz689031.patch- Update builtins certs to those from NSSCKBI_1_88_RTM- Bug 747387 - Unable to contact LDAP Server during winsync- Add to the spec file the patch for Bug 671266- More coverity related fixes in the pem module- Coverity related fixes- Add relro support for executables and shared libraries- Add partial RELRO support- Fix the name of the last patch file- Retagging to pick up two missing commits- Update builtins certs to those from NSSCKBI_1_87_RTM- Update builtins certs to those from NSSCKBI_1_86_RTM- Update builtins certs to those from NSSCKBI_1_85_RTM- Fix CMS to verify signed data when SignerInfo indicates signer by subjectKeyID- Fix pem logging to deal with files originally created by root- Retagging for updated patch missing from previous tag- Update to 3.12.10- Resolves: rhbz# 703658 - Fix crmf hard-coded maximum size for wrapped private keys- Resolves: rhbz#688423 - Enable NSS support for pluggable ECC- Add "Conflicts: curl < 7.19.7-26.el6" to fix Bug 694663- Construct private key nickname based on the full pathname of the pem file- Update expired PayPayEE.cert test certificate - Conditionalize some database tests on user not being root- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Fix memory leaks caused by SECKEY_ImportDERPublicKey- Short-term fix for ssl test suites hangs on ipv6 type connections- Add requires for pkcs11-devel on nss-softokn-freebl devel - Run the test suites in check section per packaging guidelines- Prefer user database ca cert trust settings system's ones - Swap internal key slot on fips mode switches- Update to 3.12.9 - Fix libnsspem to test for and reject directories- Add suppport for pkcs8 formatted keys in the pem module - Add verify(not md5 size mtime) to configuration files attributes - Prevent nss-sysinit disabling on package upgrade - Create pkcs11.txt with correct permissions regardless of current umask - Add option to setup-nsssysinit.sh to report nss-sysinit status - Update test certificate which had expired- Update to 3.12.8- Increase release version number, no code changes- Update to 3.12.7- Rebuilt- Appying the changes in previous log - Changing some BuildRequires to >= as well - Temporarily disabling all tests for faster builds- Change some = to >= in Requires to enable a rebase next- Fix SIGSEGV within CreateObject (#596783) - Update expired test certificate- Fix nss.pc to not require nss-softokn- rebuilt using nss-util 3.2.6- rebuilt using nspr-devel 4.8.4- Update to 3.12.6- Update to NSS_3_12_6_RC1- Fix curl related regression and general patch code clean up- Resolves: #551784 rebuilt after nss-softokn and nss-util builds - this will generate the coorect nss.spec- rebuilt for RHEL-6 candidate, Resolves: #551784- Updated to 3.12.5 from CVS import from Fedora 12 - Moved blank legacy databases to the lookaside cache - Reenabled the full test suite - Retagging for a RHEL-6-test-build- Retagged- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- bump release number and rebuild- Fix nsssysinit to allow root to modify the nss system database (#547860)- Temporarily disabling the ssl tests until Bug 539183 is resolved- Fix an error introduced when adapting the patch for 546211- Remove some left over trace statements from nsssysinit patching- Fix nsssysinit to set the default flags on the crypto module (#545779) - Fix nsssysinit to enable apps to use the system cert store, patch contributed by David Woodhouse (#546221) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387) - Sysinit requires coreutils for post install scriplet (#547067) - Remove redundant header from the pem module- Remove unneeded patch- Update to 3.12.5 - CVE-2009-3555 TLS: MITM attacks via session renegotiation- Require nss-softoken of same arch as nss (#527867)- Fix bug where user was prompted for a password when listing keys on an empty system database (#527048) - Fix setup-nsssysinit to handle more general flags formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build  !"#$%&'()*+,-./01233.28.4-1.el6_93.28.43.28.4-1.el6_93.28.4-1.el6_9nss-confignss3cert.hcertdb.hcertt.hcmmf.hcmmft.hcms.hcmsreclist.hcmst.hcrmf.hcrmft.hcryptohi.hcryptoht.hjar-ds.hjar.hjarfile.hkey.hkeyhi.hkeyt.hkeythi.hnss.hnssckbi.hnsspem.hocsp.hocspt.hp12.hp12plcy.hp12t.hpk11func.hpk11pqg.hpk11priv.hpk11pub.hpk11sdr.hpkcs12.hpkcs12t.hpkcs7t.hpreenc.hsechash.hsecmime.hsecmod.hsecmodt.hsecpkcs5.hsecpkcs7.hsmime.hssl.hsslerr.hsslproto.hsslt.hlibcrmf.anss.pc/usr/bin//usr/include//usr/include/nss3//usr/lib//usr/lib/pkgconfig/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnuASCII textPOSIX shell script text executablecurrent ar archivedirectorypkgconfig fileRPRRR?7zXZ !PH6ʇ]"k%nÍdڴ4Yk(`<~>}F}/W1 >#U헱g(#ݢl+Q]Sv:#W"6˝5,%m4)Ǥ%&,Ö3L6+`IKcp% 9ne2ofgQ0X ڒhkΞ Gp78}ĽWxKOP lU.ߖIjQ 979?Izr"4V?9BYTS OYd\eW ONmֶTJ ,I xdT^],3R%͕~B&ַvˀç2#^HSĺо&GQ@Z>9%k0hD$}i4ъT}nWy%G 'nŒZF9&!hy {GCM"V;> |paI-j *7I1/QK2xWb,^Ž+Zg{'//!1UYc)m]ژ]:KpCHCajL7sEuT,FCC6M"zXxFKL:7ۗJ+> MHz-"Րcq^ PWWy}Ơ-m lG6CM1hԆ.ɛB0Ӡ+Ul.J=p, Mh2a[L < bJk)5m#,%VѣWϧ,Z-!+ _K)Jfa$MvCK^{_fS7^.<Nqj}Q;+LT7&wqՕNz#݆K>_JfP뢇tetG8Krd2Y>FM0:Z͋?\nS FGӡ 0<nz9Z#fq(UD^vC`!5ޛː͡_`_ڥ(Sp8q?+y@%[r]کCZ@nh)9^R 7ll6P!,#W?ŤU#K5~s{Phd{Clź^/MD|pvtt>-U[>/ΉvA{M,q :ԺꍰSM|RQ(\+ǭ/5EgXhWٸv(ek L=Kpq#Yj[G~]7jۜn DF7C7xLQx/k#RQ8j̍>c|` êZy6wv&<KLm0U+Ϊ<ATÝz;<`4]`?Θ77'2g-w>SI4\HvVMf.S*B1 p/r!^kWo hG1>yAW+49P14 vJk犧Z`̃Vu94;W¡P4fv{jaL$j:HA^+LjJ6=tO NO~0rO890P/OuVSg\ xZwjӎuPY?/slLzBo'RoVbsaЈcruS0'E+L3 X &<4 O wNҊG I{+Z׷$8u4'D2*ktE*"ϊ)۹k^SBRNq<~W! :N* т<` k7 cwb4[ʆ`?tlՆUrC^ګ\g l^7X9҂9K6x!}up@E#~nIL#-U4nAZ} v#8YC9 4|on>[";sV{ weh^},`;R]} ї\4Ҫ ]`_Liu^CO°>~9ӵoY`6 Rp5H1شAvdW)MƘ> &f@/NVKyJlȆmJ 8]ʕnjh5}[-} $cpsKk lSV4Bjj~jXAtz{F%vΎL|aD?gU?p { GQ?v$49UcxtWfu! ˟,ÏG*\tmF"<^6HY׬B Jv=՜|vZ$:%p݋8k%p`_o<t\X6xisMZyD<Wʴ']z9Ό,W!2t!i7a=%~mRNm:-[T[c%R,9˯ݐ6 ](]+>Dg@A}Јm3}ĭz6F,͂"[͊xP$ v$ewᙶ[è`\ogdlaU5l7}!3П>q:bωbjS.d<:W3'%4 ÄIC[Q[Q7U 2pgZtՂY]I'v!<2xSKnCFX-ƻIZ&k^Y7?F'o܄ڂ mSsV' |v;ZzyӾ5-@l&gڹ}Cal`|Έ&jdY,d̚$v@> 4x(܆Aeڪ B9c-n@<.խEeъSOEmB U L%Q]I.?%U׵ 3AP`Tا_0t jß!|!n+0[NS;ǡ%:p$vt*JH!p{glcb׽#k6f?ZJcnY֌ t ldff F/Ý xBgCfnV-g$/otA^9 >p5ŕ6v80;'#ЅqMs>/g!pIa9EugcgjOޜS˒<ځ=NN'7AFdis:tfN؁?gtS^€E/B*^U Xb5O K 0l)s_47{>>Fl|E?s m",*gt-p?J(6,ux޳8q^/38= $@3mh/v[Z:O9ޟB#l*RKW-N lz 9U܉Jz!2K!j%- )4W& wrz1I;w&Y"G#'HH^1sH' /ʈ于{;b[gӮiy1b:V%(Ę+wj[ I٪@E p2Ts KtNh(:73x3Kg/L{[A)QvجmH$N:ei>$7<'O5iQ敶v4K=UDC %﫵E(E %~U*4)d@pP͈vӹX]1iKo'݄_bQv)a8P!35f" *QǢʩ<狣IgMW-Gqrʼngu6>?6$ 3|wjɒ(? *$&c",)I v6\yGat- G!SwV@ Zk4d'*Pj7ʊ6%N)nG">*#Ų R WH5֚ן YaTm} r4n#/;Hـ^xu{ɻV;[,a={( 8j6%?}j0 ,Ly𙽻9xj D(PQ_!R.aøP̂7IPbCPGѰ6tŧ*;kvEa'l~͕ 0L~i*z@hiB Paf:{4ܽ ^WBv n-/qQ9~ >6kJYH*H./Lw-mBal@5gZPMdX6?;<4p Fw|Մ&ˤ Z]P$;I6 nNc 7viB)x1S~ydo yPdG X0^vp` M8P4e)B= V 퓁LȢ#ݻt׿CrT6!uSV/)f5$6X*t J $C4.BCF[6-:>;NQagŒFu,n rsHՓOH)7vh۬6FXvW^>ݜWs|V[CzL%|Uk/22Uz<\ܝF49o!pӢ^gϣ,4JDd ?"MQ,p@3{]݇ˏbb;OlR;9vu!J+ #W\0K[zTNǶP<++WS-4|;624Q2_mh0;U:J+a]]Vq7w^) N>8 㔅UݔLYh![#5U IC2$doӃ"gqҁYЩzWR;1jf?rzzݭZYtQc \3{EkK à ?ԔFe&2hva>x0V!=_c+D&c↷Gi#i][g,:,O6&HTcgBhy=NțÅcHCfFS>Z(s7c!:":xpRN'Ք A^/%]3g*]5g}:h%m1J$ u3T׍1 :p rTT]%6׿&5̃lW3װ"΍wz{a1\V07Z[6et s3vFK^)ťأdJ2f/x;TQK|y_Йs;Q%94Эm:TR'5DʽR5C2t2"߽F`zAuW$Ϭ;Ik(|_<]y>({L:mG}H5R2G5τ ?4;j~) E;&D=O@{ !ObM0əHcix/`LLKPa[\ rM"p"^,oNEЖqZDwCs<"j!j0 ķ%o&܁y4NZԽi䄽5K+lwU솮lx%"`8~^S&W& &F|nJqRj ȪFQLItC\Υ+kـ|hc{/Պ/lzi$Pl)=LI. L3)Iq>|w.jު a[? ba\cn6f, -'=vryT2þYa,b\ҵZ5Ӊ5cS'8?."lhs~id¯ ot RvTE!E齉K]i(2R&ֹn}0  Hu<ʍX0d.2Q 5zgR_$r@K Z=B>m&{Aѻ;1 NC,Ng).@ΰy9ün"o:8THً5 B2>"e~ӣH|/HfGkT \{èpGe1/C3\SmP$w7;X)L[+Z TV<% ܵօSjߑiپ(:i cC|j<[EDm:[1^;sBHy-Yӵ^~Q8Uhʥ${YcOӢ51VRv?yw|{H G/4i\5_ 'I2-S$q3 [~ +L;̂W%%%YmS6X_j:^:d+:f@3R * n<9h`Ƭy +ae]N{3JDCč8F^ϙrE0>=ެ[5aoav|V-V-Fh~AED>^"s 3N(P.EN⮳ϤT>Q&Ee@Z -U?T0OPMyEn`j)o( 䓤HS֛D)сgckvO k~ku&Aa CIBb!4=ʺVF zRu{`}Vu"ȠvE1? 49yG?C u{7R$)gQ>7(hQ?W-M"' +n7}+.z"3@ 9LhUW!jj* @)cadK {yݑJQIE}:*CǺcʪvxA! p$WGMզ2'6;_ԹU#(vyw!uuIpYNmǦsu 1'2Okqz0|xɺ׀麧#":glKiU@~d_qa$U 2ܳ k.!)fV_V@b)?%PT=nGP g@qlMbZɡlRߡi/S_@$=pܪoڕ\|06ttk7HVOSZcSMGa"C_-h\t(I`܄ƃja\2< ~)H.m e2a-g^QF~M>]+9#,]cʔ *IU=ЩV)0Bލg%1w1LoĂ7́}w(ӁsL*& %&'6n#-!k7% R']l5ҷf2 Џ t &J>l?iK4 H*{w؟+U,=K ;X/ ތ-0MT0EXs%KL|8%wM-gP3 U_lZ$&Plnݣw-T`,^v㞦CX@'+%U?gDVXn@hnWMBcP) A1xWFP?hy 9v.ݦta_rJ(%-ipdDM<8=䐪|PU8,`tdwZNl5Y+ta! 7Hr$8w&Zݴ^IҩFT ZҏYDxu{iֻt_2Yc}R[Rx9q˭,`]4FmdT~:(;ӔTDuG1&KWR L_ޓ ݿ V'7hch"I9M(.PWzMCo'xrmA͉N{Љ z!}p~|C@2~6YU~ӦH*M~[]}"Gs~Qx-qqbܥύiaiXҴ rr|NMnenxH,ު ӹay4ʠ`6\/@rI6l8mC׊[0]a)~kx1IsJKۓ="ꊁ 0\ra%Q^F3 ȭ{P"K#~ ;e@/ȂD!X&'8"r#۔9}ЎPi*1K[QV@9AITZ -^]q݂ (^Qv6rQ!#\W !c5 \ B]gev\ERNzdEhp>8Z7 Ws~.ϤhW4t[!U@Oɬ&Kj>־9\`/{U\m aU%y^yc#W %~yF1cgEC-xz05K?0&WڗYb 岛Z2GP44t՗#\uTA?Z! ZR |wIÍsq:WTҤqɱɠN- .Q"h,orh8","o[0hhN$G9GJH17KW(fZ/h{o;aG)[*MsTp;H`+2iT:zx~Cc.mtpRejIs\^=4ыS>ASxd 8# 7/`6 8>ʗa}ᦈ=~UO][{B7|%vHX OV?7zOwe ;)# Alb˒9ikSj -NƊ+V=}lJxR;-҄8$COY4xP~!("HC,Ucg1c1J7KDl6̒Іׅ)v(ͳ0#(Uܣw;D^V ͹ۣ'l.q}V%J(ðG[\ ~:đS,L7x&&vCm344KCF8߈a) g>$vϑ+[8 |9[bC1eYCM$3x+?nE;cMHp'F(rvq0|+NGc 8N&؆8D8xOrS`h]۬ՔNhļ%[] 6_ڹmJvIۜZ?'͡@/`#ɺ8t2wGgfG?םfSQ X{0DVG45he tmg%T1Ck~;m<Sh ޣ5P )iB1cN2kœH*G`hGqƄ 7nMڴV,łmN:5:fFP( QӴX`>&oIat$.abX#&xujt]ɥзx Vy?"PPCPZȟ-:TEX6e)`irE2&Gh .ЀU_^gE ˥O}0ӻߏo"M)b{}j$"Zw嬝[.F1ab $mƖ}նP(D@6^ vC oc9Kk%nUvEyz^ A' }^0>x;lC8.3/P%s7Q{?q"ć2¬,u}y9:m&88-E^Q-6U&Pp2g]Y¹'q(/'nƧl.~M$#Ǩ\,Pe*{y$&&AM+gef68LW][aJc,;)'fKF&FtiQ>D"Hj>~{4QJ 4 9&%m:=H+WkWK* X{raDXWǮV :x3JwQp>KrݱVPW3H 囎(\Y pQPTc\5S/_AQ,1CfͭB\tOH Fl 10n.8Oب);T <;l3DnE(YR_Gb  `8@|~րL!U3,Ve ΃' ux<0O WoٍP6'V|(5eWTxӫ>%O,[jē'Er6F60XB s8YI"ϯ!,oXv[(uDGl@Lyr!-R&EZmJƜw׾&r.$;놬2KEћoj*-MwtN6v js[ }11,kT(Mg8/7ZmV?^Jg1FxréWmQk <zc酉e̗[<Tk򏕈#=Cô7eKguY~pwՏc׼qu@4tx@ -vEg@] y[&PR}WWYilpqKaYwU\ü?P%S@Egrni>Ak]֡lZ#FS<!tawQ.JZʋ0|E}\mvj!=5#J%a_ ҊKƶaճtٽ^t0뒩<3.ɐm*mAsiC2X; *n |XZA3zK^ױQÜ'0v ܘfne僧bh䒶e#Cuª nҳQLs,鬹5/rXW3̜SC򋶾Q'~e UcxyV2*p9nr-K A}2݂߼U.`:x,R6Kߦ;MUH_[tEڕ:UD…Sf//'(޷YK(?cʓL3I/'ٛ 3I%8R'EvCO<1Nu g7I:Dc@ni3_Q^;߆d-|5\p/]D[J3no YGhʀ3v蒯|q`U酣ڱ/m<0/U$j><腣-6ҩ (e'˝>\ NAp@aPǯlPm2J3XǨINR߇;S'3HӤ U;3@JѰv|NoPK:py ;y,K+,ǫ?<ٶ%ο-˭I )fg +Vr(\ ؽ%_AFs:hXB3җd=ʟgR6:t.# a)Fo uwOīݷf`cS<Õl06;a[hܑؑɯ-#>EhaڎŻVԼO!kXyC/]}9I YB_ *1-̲X]e ̠萀<'X8iίoE>[OduzA}@϶PT\HzzCEWCy>| 1W 9f;H|Ϸh#,G9q@d:>}rb| mw`rδ.@szE 05ҫ}F~y͠Nna??fU@=|Xwh 7.,gu@P0M}gȑ6Y{ߴePO1-eq\p-A%MߎlJmTYClW.Tz?!7xY֙M8Ymdl%]ÄTB).+ɺt9a1-IZeW' "X%CSXAlz,mN.?Wh3$2cS13QO7NK$$w0* _Тkvv- 4$ b95^sİ9xd$ zEeG~Fu8X՚s@gO\bs^s1n<}x02Jx:p+ďbʙ{5;{;brpa>zUkZ~B'7)2V{-nUAaYgNB< x^hqjq`h!+*0d w' o,pmk[{/Wg"KS(k /+ݒn~+~P;c"`#niW0J>B3rb!Ok'ݍr =vip6'2S4Ocx˜9B+ގ& $Id}-}T;ع ANOh2EFX>?$7&Jk;W<"yy]Kv1x!Vr:vfX8 +y`_oӠ}`Gԁ .l_Wa!A<7Wb8 , >VM;;ZkL>&Ya$J |ᆔ8{¢m)fﶴhZ|rqvFyx.VZOG~<+1ZkeŎ@'6R0ȡWޝlds  d%ӹ}Y XxZ"^6ia1AӞ;&CDŽxSlLEW7 #U!+.o"pG sW򿲒ƴOy͆M@1:dǠ E,dzQ#&k#eȻeJRThOCwo;kGpke 0c~s2j=i鑉 B]KzY<-iޛh:7DtH;} r@e{*KTfk<ϓ;Mk*f!*쮰oo(̷"{ǻj|N;{vKyZ"ipHwY|l~%ZfzkĖE"ip2xVll%U/"bn(4/Isv*Wy!=r/M:n[iC 0ikF>L ǨO~&Lhcef }B%l"Hg>ӓ N܇bSicǁ1Ao֭T16uiobJVF>1_RD 6@゜Gr3\t~Pf M7DRqE`"ёyؗJ%2-)N*\)?IZNTԱLWfǽ{THtNN9<<;um36˥l?.}룰MBm]ԻqTJ (tD蝓sݰԬES& rS}>X0BpSehyS [+px(l爜+-I Ù7DtW2X)g `"2d'H˰1& <)[@1'a*z*C4֔Hu'ܐ jZ޺(с'[X:"~S|I ɀY$TD`GoC[?da~몵| #43 Y!$vbY q /M˷-nۇM%8/ae:b nl Qo?ebvZ+D8ɋZL&(釕 x\+&&[#Rh}X 0A~V/Ę&_ӣN" ~5J3(zE)/#+OP`\ ~V@?;nrBz<#pbgͳ!3CsD %`˫8(J^\QbyH|Oǜj9]k83fdZ%RLjV05LB7km6Ylz"WW{1"=强z[O;]MаAʚ@':^U2F^7zn:-+KLo=QUi7wahK&=R.-s4t+,w^Eޥ"Ɖfr|q'_?W Z2-ZNnˢw3(X4]'dy7E@I&eg<}V0Nc)&g/2;<&Q@J(u$cYDu3@Uka.QL) 'T_ܤg#JFX_k:ƶqY/.\閑#&ѝӮ4'۬!]dzO[Gy>?AsdQK2mj4f2ޯU|Ih%/) 0h٬_@nj ^!ߧA;2w>_,N([U!8C?UIitC$r8$>~%6xTς *^|%]a"/̰KCL9y}rD)ѱƬrbZVYűټõ.8`Zm1m.0.X L:Wh3tNˍMpMm"mم T4mUprvYy_FVL dc58֧ʨ9.^1;eRZ)|w6 'H/Cݭ\B*b15ikYϋ)'-vatAi#Z @qۋ\MN|BunsEK ,Y¢+,}}D6zV;o+X>͖CB\pFYrMs2:y>*Z nR3yOxv'B00=m{Cc]5OFqi!IͰ#qBkTu\/P`F0K.k6YQc3~5g-e /Zu&Ђb :#h R,rWiwR|^ĩ%vxmdUړiFJ:JnDYjIfrO~Ml| cjM,ۏSzC`Zй2 c1BRlO G"S ;ppEU{THL ۮ >/ssOhamSŘMȖX==ȋI`}yaP$ {Li(,|{ -%JLR~k%d֍vK&Y[1_L/O-(NБrlx 9^1\1]O.}?mc/IB'kh5s uR ٴ&Q Sn%y$ \ϼ)CrQ-ɏ,_1\џPRoa3eXy:a|/7A$:W3d(ELc)2RU#}NSl,OA:; i[v0W/4 3qQ7N4[Y! ([(L*q|>vsBbcrJ U}a5!Y4ޝjCtXzrnRK8%Zc1~) ҿP]|s'uiUm`\kɾR2H*;"XB?^?YQz7Y%tuiR3ޢs,XIymYQyVXD9),+6vK2ޛt%,W=zTQC@dwS=rEH;jjtd4$tF^eӪ8`o6n"kzm N`}aZ7`L۵cB31lS"h%:fhA߷Qߎ+;]k(򩨗{fwM9u~9Lvyƒ`N+z({co9aM ;Բߧ{.q$BqϴEHw+fSwpFl=(RDj8JxUҋ{ZҞe-DAōknrRu7=IT>tY@0_(p5%hKC1n'Wcgه,/#ESU| id hrXF{Opydzo9oO9& E?쀜';cCZIdi<$BN ̸uIbR$͋ {#`]&Xc'!4r-}<_?n8R:3Pap}Sf*C똋7Z$ύ5DuE; /5#uKZ?!k?Ckx2#ֹPLOjFQYm3t[ZSl@QAecD#c6?]<{Kmi" DD2Fz0ûCUU+@ SS#O#}Ax:ACFmMsy,?Ms)Zg%^ippI2H>MgNcChl=|;v\*kG2t_"lE_.L` s#`:Л?:YaNz6U(q*]e1b "Y!ye $wQKG`wm~wif5q񂏃yrxСJs,']{<k@R=5|O_땀tZ+Lf߃R6bÐ|hD]j#kbT_H2׊v7ުv odž@'rQ;k2T~7v P{;2H8jyIu ^k'UM6Bbh0x_<ǒdak2s~%wL,* ԸsѲL)zFAB F_Q ۤt rQBM~㩕 a(!7e*k~!lTJޠᱜB`oWz95O_̸APa94U;beP]RG3 la?[`gcN)o(4O AVU:-U=>}drLRvD 2 P0]wtL RJ,q"K73P(%c >j g/TB]}j-|0dzS*sѴ(~_,UJG%ꓲL%]x#nA[Yg1oF4٩Cǚj[䁏u {={i)t9O;ORKIM0*>NFX{< ?A[WXCvrxcH I}wz enƳL7aiF XHq/w,o%r\wi*eL.`[:Ztm?Y\\ږZVݱp~_(_Y(.Kp˙"JcLxgΏ3UGP_%BBRɑ?a\.]3+n!@J׹N 8lաsm{Fh8dDQLwZvA>& InĨit3;&Al Bjo Ez]_{dd?g~$K>QlKi]q'iO:L53j3س[@59f(5D [7nLGqHvU{@n-(fgKr{p\P1QyFi/' ĊZKXDPD7"+-"Qr)sKXAԺp8Ƈ3a\D5Ny@cϑ0\5\ <֯#@('2a ף ?Bm:k?Ő Nlv:{cy.H ge#碾xC}d` @E KÒ>'zBL@/mp.an)L(15=)q.f<$}&薥7yl2]d'eNojwY-?P<8WVY x.S J#O51VQ՝яPг"@ɡʆFxڅ=kh@~`=E,Ŀk [nS?WBmo,܌7Q<ټj"WZʣCG<Қ{J.^ЫHF4ΈTT u<2 'b St4OE”Ŀ&E ;A#R*jT2ֆ,Skxf4I?Uy0Ҡ'iDC="XbZ_sZ.ǓHbvH?z[  :v$/-(F=6Pe 􇸗n#ik55H8b%*j:*psuNvJD 6;$vb2?]W2` 냕6Wd\p|O2$b{Ʈ `qY(.TJe zqK7O@ 2L"pzK*y[B3MSZH^kJJG< 5caxP/plLi9@ǵ, NECxY#Mj~'`:ڍi`-ٍ A_%~w>U5zZT27Q~B|q;zDzhtbuGY[)|𢥾y籸M`N7 #M)ˊIlW+7.7#Aop_6"e6ߊp|-}} iWx]9_vEF0xc ZVZo-܃Ogrm)tބx{SjP1t k3oF5PUV Gѿ3ڏ]͕.ٗ0}.(Q ybB6r\/s!N%a]%9ɢF]0iP*Myb;? ou;~A7s's5bv`" J{B2X30O /,pRNVsXC)o]GnmbH+Ls5RΒٺ 609єW\ _,ٵT5"p'Qg5ʱALYˊFV\ ؾ,ge"CqFD!~kA1)@Q+["œ6'+ cBޭ l;a+d ^$SͿy]? dvi|/w[Nrh7O9$-1HD)]_Gn\)0Vڂ M"[HŹShVGhh0r<>$3H$> mѹ2@ÒtAQ G)y@:/Vbf{5`6rV[1s2 +yp.ظ$A[iΊZQA(=Ž>H .٭t_Eβ7n^` 80]XչK!6w̻kx;Nj\r34wYW3eg[;LD}HwԻvRMa~fu~{ Y9Pmt'-抉ݮbo!FBn+Oq `f⣧)w&vtO<4nG朊mᑲѶf:wg*+Bt,( 'ljRWJ1eԗ;t=Ϻ4Z4Df?Bkԇ hJ;@X'u=3uqWk-!%64xZ&4~,~Vr# L1I)q5re,GԘ9UDeĿmf3_gb2&6@6(w@C<\ݖ2Xv,,9ZOLp+ 8S㕁w+t߂܈mF]߼<dVT aBj?Ć1>8 CgE0unnRm/-ߡMn¥;`nnLhwޡǀ6kB):FC&WT0/qW|=9 mP4=PowBqq"һ; :T")&H6 AFu'Xif6L.s^ot^4v1H03W+*907sR-Wjcް ddP%rΓT һN]B>~wм62m~}RSPo+X|i&&̷No*.V`"wt~byO?lDZ5 xV̟)R7N5߆ <9Y+M:feER5R/R|UZ1N)ēcw3]<%ؼHRG!#Rc 4)$yZaK]|' 8SElq$:& ؆Дqhfh'Fr"OuUhC 4zlI21 kX,ꀪBj݅NGyN\7m'E 谙Ct趱`s@`Ŕipb#֪qmg-:ge2eeZ*+J^pbβ0\%AD N}eanvI%am#oOPV$kKG%_SYUN 1ǭ򗐊LiJgwߗ詢[0,QM5AM] P*B YAVY:q@ Pt72/D)JmR!u㋉5E< mu52+f%'\ Q-B6I@{ 7rF\}d V`; mUb\lzf[rZ)6L#HΧ] =~feƒ#~ !թ{X NcH}蕍/M6⹡&6Ra r!NEu28<{}xKҲ #f=wĿy]S_yǸ70JFnEr_.9@r'\{x|a¾%č.F+ >Z;h x 9p2oY=6+^2JR}Rt 4R0W]ka)EV5zEӼC4ˉ&3в P+ U^{feBzHc1I}%36AgԮF2LNo7 ݀ 4ﯱ{^7PJPeK?bSb-7UP,=wgxaͫ?nHPyLGܳZ} A0'+paPg8#y_PHS=G"bi)Z#ffkӥzn+ݞPy ` ό"+Z.4lS&`-8I)v!_[OMz]UҶBQP@%#BL|&L3BVuؗ8LIM+_ bnebw#7 Utvʪs`:övVT"!S1Kf Ms@jG1'o37_jqz3bG=20ƿ^LmX{ZV@8q3yGQ`|:~pσ^n ;L αWA>P]4^(o.uS糁yǎux}ۥ1X>J$ x=|i~Dw8=/bH+t.ϗo! -Z `>߉AiYEYaoA.U伴ݤ+}Ʃ щ +_93 a#:~Ff~tv2 %!JZhF[ 9ZѶ&9ХpqZtzcO51"̀lF<=V-~͑_!Jxvފū{ef] rbb ~nAM'Ґ;EwS 1ؐzE7EUlh' 7TO&x4&p} ,9+Dj.Zϻ i#R%+ť&m`;T"nuPiTΙHsyxnleXY8\.%uG t`!],{0'%wM5pK+L^0Q5b|I M3Xci'ہ8vD]4b=uGAxRl(E$Ɖhye{#>0f򔍖BFT3-Vkq5y&@bg uVE 15Lxw1(%;[v0vOP6SXsfcu,- kU,aC{w .p#` .?lRo,Iq[X ?[ 4Fg͐_PrT'S r Hcf忮<#;DG9 5ZM}Vi Aup+h 1"nr?_6j=?wM;/8QO26]8{g(sZO 1OB|Za%WX~-=m*{&O4f rN_ ёTHpܤF~Z"v3;CcQ[!b,k ǭ># o 9%uq59 W-6+,&=&-'lM:D {H=|oykBf Yf3 }Y& V\ABK%9אG)wDxK8ZǷ{M#g5|+Ihe .@;[4d@YSyY8\i_52J%fqWu3 '_Kp ou"+[NxxB6))n*|_}Apqu}8ؒGZlLR!9,al)ɽ ap3՛=)SB (^ju{o]>>eb_:_]>WgGGkqSIjOGo q02v[G "Š8xy' IA9Zk%}&:K50b\v&$NS,<O![5(=^槾@ ՃڥW>^&(N_gZz*W`:)D "q={z%tJ-[3%؂C̗bamݓ\`Z<@O_c:6N0e>f5ѧ[!PBͶpC2o@ԷTuQ_ada´9=pO¤<(8]8 X34TKsLDS{Df&~2q',}brNh$QZu&&,x94`Å%KB*UҼg|K2]ЪcV=YEʷҜʥ0F~űziLJ[r'jW* a< MB#dcDFisXyt҅@+qWyc<_ݡ{VDrEN]@e[v;?|-TC'g k snA@O^2!$vb9(R !X䤸4+J3K$I~L}#Hz~86Jg?4^-eOu؊ʽ-_Gb*[!L ŵ~%oNv kV)/ß r~ʛ!LzW"K N@,bOđ~4&uZUf"Gz:PLYnP[قB;9%/9^nݺcYHeb= |C*)jI˟fL`UZPA?"g5s4ըJ2JU&&##˾:4}XڣAɾc0<1iDOk?1|gsN}<Xb)UaE;{[r\X%*{e9}Ho|$q"+AwU&en}`kbvjhy"]2W{(Snbf o_jWyoTz10Reo dp9ha%ƎK*5RxpV>!!s5?ǥiiJi:1K ÑЪvűˍg;vdm-k`qo$rHKf3Ov+k wQx.^zTj&*uzIEJR&xx~5;_X+D~M+%YTɈQs,%މk՜ưͻ*5J_g[^+(9G ]7^(TXL=PdV )p' <6-\0eUoW/B"hA{vyΥB7|bn.i}zr:^pVsqw. ȳ~"8sѻM8KЊ"~84)5M%r[֩0h&xP}n'/ N:x10]#͟#.9:6L2a,b JI:G)sON^x2ۚ/Xz8s/ ~SUEwxzLcjz=z"X\CMVzGޝy@+:?f 0onDJ&Ώi-?SĐpdcPD:+/sBճ8!"U-0lz딡 @p~gL/_t%xi]y_VJGH[_",y~ n={ # bK0\n%{2Hl3%*gƜh(׀>hZ(ԭ'q7~ 9BI3:dZF-hU~ʬ@A; $+ĝ{j8nwQ9,ǥvX̠G[܍(CtRm3oa,Q^ۗ[aPZ4"^a>V{Z[jËZM 7BHML?~iGMzeTZx%Zڗ)Srs[+I0R*뤊OI|D/C:㪸eC,ST VZcI@foo *p]l4Yx8>ʗ*X;Rj2*|( `[$kp/}O#WUML@i9_iN7~+T(/ ]ğ!!H!$ vh](Gޞ*sZDsu/ i|0uU_t[ۅ zop %nN%n Y@LKI)KEuIN _y*A2߆(M֪V|PI 'Au*&~D-Wb ?1xj=djBx8ի$&P34hRE̔)^9}B0LT%=beH u C׵*oEVpcL4q˗WW$SZ z"A?Īb8ǏyE#`cH?Wo& 4kR]H͕73xV66OjG֔tG+ө%&75.bt{021Iz+pܴp~T*j kmiXv^ZU!xp$:ygU YZ