nss-devel-3.28.4-3.el6_9$>R4x$XuD>8?d   O CIP33 3 3 3 g3 3h3g3f3P(89:OG3HT3I 3XTYd\3]d3^ bide flt(3u3vw3x3yĴCnss-devel3.28.43.el6_9Development libraries for Network Security ServicesHeader and Library files for doing development with Network Security Services.Y- c1bl.rdu2.centos.org =CentOSMPLv2.0CentOS BuildSystem Development/Librarieshttp://www.mozilla.org/projects/security/pki/nss/linuxi686  YRCyQ - 3.28.4-3Kai Engert - 3.28.4-2Daiki Ueno - 3.28.4-1Daiki Ueno - 3.28.3-3Daiki Ueno - 3.28.3-2Daiki Ueno - 3.28.3-1Daiki Ueno - 3.27.1-13Daiki Ueno - 3.27.1-12Daiki Ueno - 3.27.1-11Daiki Ueno - 3.27.1-10Daiki Ueno - 3.27.1-9Daiki Ueno - 3.27.1-8Daiki Ueno - 3.27.1-7Kai Engert - 3.27.1-6Kai Engert - 3.27.1-5Kai Engert - 3.27.1-4Kai Engert - 3.27.1-3Daiki Ueno - 3.27.1-2Daiki Ueno - 3.27.1-1Kai Engert - 3.21.0-8Elio Maldonado - 3.21.0-7Elio Maldonado - 3.21.0-6Elio Maldonado - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado - 3.21.0-2Elio Maldonado - 3.21.0-1Elio Maldonado - 3.19.1-9Elio Maldonado - 3.19.1-7Elio Maldonado - 3.19.1-6Elio Maldonado - 3.19.1-5Elio Maldonado - 3.19.1-4Kai Engert - 3.19.1-3Kai Engert - 3.19.1-2Elio Maldonado - 3.19.1-1Kai Engert - 3.18.0-5.3Elio Maldonado - 3.18.0-5Elio Maldonado - 3.18.0-4Elio Maldonado - 3.18.0-3Elio Maldonado - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.16.2.3-4Elio Maldonado - 3.16.2.3-3Elio Maldonado - 3.16.2.3-1Elio Maldonado - 3.16.1-14Elio Maldonado - 3.16.1-13Elio Maldonado - 3.16.1-12Elio Maldonado - 3.16.1-11Elio Maldonado - 3.16.1-10Elio Maldonado - 3.16.1-9Elio Maldonado - 3.16.1-8Elio Maldonado - 3.16.1-7Elio Maldonado - 3.16.1-6Elio Maldonado - 3.16.1-5Elio Maldonado - 3.16.1-4Elio Maldonado - 3.16.1-3Elio Maldonado - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.15.3-11Elio Maldonado - 3.15.3-10Elio Maldonado - 3.15.3-9Elio Maldonado - 3.15.3-8Elio Maldonado - 3.15.3-7Elio Maldonado - 3.15.3-6Elio Maldonado - 3.15.3-5Elio Maldonado - 3.15.3-4Elio Maldonado - 3.15.3-3Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.1-15Elio Maldonado - 3.15.1-14Elio Maldonado - 3.15.1-13Elio Maldonado - 3.15.1-12Elio Maldonado - 3.15.1-11Elio Maldonado - 3.15.1-10Elio Maldonado - 3.15.1-9Elio Maldonado - 3.15.1-8Kai Engert - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.14.3-37Elio Maldonado - 3.14.3-36Elio Maldonado - 3.14.3-35Elio Maldonado - 3.14.3-34Kai Engert - 3.14.3-33Elio Maldonado - 3.14.3-5Elio Maldonado - 3.14.3-4Elio Maldonado - 3.14.3-3Elio Maldonado - 3.14.3-2Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.0.0-12Elio Maldonado - 3.14.0.0-11Elio Maldonado - 3.14.0.0-10Elio Maldonado - 3.14.0.0-9Elio Maldonado - 3.14.0.0-8Elio Maldonado - 3.14.0.0-7Elio Maldonado - 3.14.0.0-6Elio Maldonado - 3.14.0.0-5Elio Maldonado - 3.14.0.0-4Kai Engert - 3.14.0.0-3Bob Relyea - 3.14.0.0-2Elio Maldonado - 3.14.0.0-1Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.3-7Elio Maldonado - 3.13.3-6Elio Maldonado Batiz - 3.13.3-5Elio Maldonado Batiz - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Elio Maldonado Batiz - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado - 3.13.1-4Elio Maldonado - 3.13.1-4Martin Stransky 3.13.1-3Elio Maldonado Batiz - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.12.10-17Elio Maldonado - 3.12.10-16Elio Maldonado - 3.12.10-15Elio Maldonado - 3.12.10-14Elio Maldonado - 3.12.10-13Elio Maldonado - 3.12.10-12Elio Maldonado - 3.12.10-11Elio Maldonado - 3.12.10-10Elio Maldonado - 3.12.10-9Elio Maldonado - 3.12.10-8Elio Maldonado - 3.12.10-7Elio Maldonado - 3.12.10-6Elio Maldonado - 3.12.10-5Elio Maldonado - 3.12.10-4Elio Maldonado - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado Batiz - 3.12.9-9Elio Maldonado - 3.12.9-8Elio Maldonado - 3.12.9-7Elio Maldonado - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Kai Engert - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5.99-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-7.3Elio Maldonado - 3.12.5-7.2Elio Maldonado - 3.12.5-7.1Elio Maldonado - 3.12.5-7Elio Maldonado - 3.12.5-6Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-2Elio Maldonado - 3.12.5-1.14Elio Maldonado - 3.12.5-1.12.1Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.10Elio Maldonado - 3.12.5-1.8Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-1.2Elio Maldonado - 3.12.4-15Elio Maldonado - 3.12.4-14Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Fix zero-length record treatment for stream ciphers and SSLv2- Include CKBI 2.14 and updated CA constraints from NSS 3.28.5- Rebase to 3.28.4- Fix crash with tstclnt -W - Adjust gtests to run with our old softoken and downstream patches- Avoid cipher suite ordering change, spotted by Hubert Kario- Rebase to 3.28.3 - Remove upstreamed moz-1282627-rh-1294606.patch, moz-1312141-rh-1387811.patch, moz-1315936.patch, and moz-1318561.patch - Remove no longer necessary nss-duplicate-ciphers.patch - Disable X25519 and exclude tests using it - Catch failed ASN1 decoding of RSA keys, by Kamil Dudka (#1427481)- Update expired PayPalEE.cert- Disable unsupported test cases in ssl_gtests- Adjust the sslstress.txt filename so that it matches with the disableSSL2tests patch ported from RHEL 7 - Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests - Don't add gtests and ssl_gtests to nss_tests, unless gtests are enabled- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release - Add patch to fix bash syntax error in tests/ssl.sh - Add patch to remove duplicate ciphersuites entries in sslinfo.c - Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range - Build with support for SSLKEYLOGFILE- Update fix_multiple_open patch to fix regression in openldap client - Remove pk11_genobj_leak patch, which caused crash with Firefox - Add comment in the policy file to preserve the last empty line - Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not provided by softoken; this superseds check_hash_impl patch- Fix problem in check_hash_impl patch- Add patch to check if hash algorithms are backed by a token - Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256, which have never enabled in the past- Add upstream patch to fix a crash. Mozilla #1315936- Disable the use of RSA-PSS with SSL/TLS. #1390161- Use updated upstream patch for RH bug 1387811- Added upstream patches to fix RH bugs 1057388, 1294606, 1387811- Enable gtests when requested- Rebase to NSS 3.27.1 - Remove nss-646045.patch, which is not necessary - Remove p-disable-md5-590364-reversed.patch, which is no-op here, because the patched code is removed later in %setup - Remove disable_hw_gcm.patch, which is no-op here, because the patched code is removed later in %setup. Also remove NSS_DISABLE_HW_GCM setting, which was only required for RHEL 5 - Add Bug-1001841-disable-sslv2-libssl.patch and Bug-1001841-disable-sslv2-tests.patch, which completedly disable EXPORT ciphersuites. Ported from RHEL 7 - Remove disable-export-suites-tests.patch, which is covered by Bug-1001841-disable-sslv2-tests.patch - Remove nss-ca-2.6-enable-legacy.patch, as we decided to not allow 1024 legacy CA certificates - Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits - Remove nss-init-ss-sec-certs-null.patch, which appears to be no-op, as it clears memory area allocated with PORT_ZAlloc() - Remove nss-disable-sslv2-libssl.patch, nss-disable-sslv2-tests.patch, sslauth-no-v2.patch, and nss-sslstress-txt-ssl3-lower-value-in-range.patch as SSLv2 is already disabled in upstream - Remove fix-nss-test-filtering.patch, which is fixed in upstream - Add nss-check-policy-file.patch from Fedora - Install policy config in /etc/pki/nss-legacy/nss-rhel6.config- Ensure all ssl.sh tests are executed- Update sslauth patch to run more tests- Fix syntax errors in patch that disables sslv2 tests - Resolves: Bug 1297888 - Rebase RHEL 6.8 to NSS 3.21 for Firefox 45- Resolves: Bug 1304812 - Disable support for SSLv2 completely.- Add patches for ABI compatibility- Disable extended master-secret due to older version of softoken- Enable two additional ciphers and keep another one disabled - Prevent enabling extended masker key derive- Rebase to NSS-3.21- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol - Resolves: Bug 1289890- Package listsuites as part of the unsupported tools set - Resolves: Bug 1283655- Resolves: Bug 1272504 - Enable TLS 1.2 as the default in nss- Rebuild against updated NSPR- Sync up with the rhel-6.6 branch - Resolves: Bug 1224450- Additional NULL initialization.- Updated the patch to keep old cipher suite order - Resolves: Bug 1224450- Rebase to nss-3.19.1 - Resolves: Bug 1224450- On RHEL 6.x keep the TLS version defaults unchanged. - Require softokn build 22 to ensure runtime compatibility. - Relax the requirement from pkcs11-devel to nss-softokn-freebl-devel to allow same or newer. - Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1)- Update and reeneable nss-646045.patch on account of the rebase - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Fix shell syntax error in nss/tests/all.sh - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Restore a patch that had been mistakenly disabled - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Replace expired PayPal test certificate that breaks the build - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] - Resolves: Bug 1131311 - rhel65 ns-slapd crash, segfault error 4 in libnss3.so in PK11_DoesMechanism at pk11slot.c:1824 - Temporarily disable some tests until expired PayPalEE.cert is renewed- Keep the same cipher suite order as we had in NSS_3_15_3_RTM - Resolves: Bug 1123092 - openldap-2.4.23-34.el6_5.1.i686 fails after updating nss to nss-3.16.1-4.el6_5.i686- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 - Remove unused indentation pseudo patch - require nss util 3.16.2.3 - Restore patch for certutil man page - supply missing options descriptions to the man page- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Resolves: Bug 1145432 - CVE-2014-1568- Fix pem deadlock caused by previous version of a fix for a race condition - Fixes: Bug 1090681- Add references to bugs filed upstream - Related: Bug 1090681, Bug 1104300- Resolves: Bug 1090681 - RHDS 9.1 389-ds-base-1.2.11.15-31 crash in PK11_DoesMechanism- Replace expired PayPal test certificate that breaks the build - Related: Bug 1099619- Fix defects found by coverity - Resolves: Bug 1104300- Backport nss-3.12.6 upstream fix required by Firefox 31 - Resolves: Bug 1099619- Update nspr-version to 4.10.6- Update pem sources to the same ones used on rhel-7 - Remove no longer needed patches on account of this update - Resolves: Bug 1002205- Move removal of directories to the end of the %prep section - Resolves: Bug 689919 - build without any softoken or util sources in the tree- Remove unused patches rendered obsolete- Fix pem module trashing of private keys on failed login - Resolves: Bug 1002205 - PEM module trashes private keys if login fails- Restore use of indentation patch until another bug is resolved - Resolves: Bug 606022 - nss security tools lack man pages- Update to nss-3.16.1 - Resolves: Bug 1099619 - Rebase nss in RHEL 6.6 to NSS 3.16.1- Resolves: Bug 689919 - build without any softoken or util sources in the tree - Add define-uint32.patch to deal with using older version of nss-softokn - Fix suboptimal test failure detection shell code in the %check section- Prevent users from disabling the internal crypto module - Resolves: Bug 1059176 - nss segfaults with opencryptoki module- Improve support for ECDSA algorithm via pluggable ECC - Document the purpose of the iquote.patch - Resolves: Bug 1057224 - Pluggable ECC in NSS not enabled on RHEL 6 and above- Install man pages for the nss security tools - Resolves: Bug 606022 - nss security tools lack man pages- Fix the numbering and naming of the patches - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- make derEncodingsMatch work with encrypted keys - rename a patch, dropped the experimental moniker from it - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Revoke trust in one mis-issued anssi certificate - Resolves: Bug 1042686 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]- Disable hw gcm on rhel-5 based build environments where OS lacks support - Rollback changes to build nss without softokn until Bug 689919 is approved - Cipher suite was run as part of the nss-softokn build- Build nss without softoken, freebl, or util sources in the build source tree - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Update to NSS_3_15_3_RTM - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 - Resolves: Bug 1031238 - deadlock in trust domain lock and object lock- Using export NSS_DISABLE_HW_GCM=1 to deal with some problemmatic build systems - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add s390x and ia64 to the %define multilib_arches list used for defining alt_ckbi - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add zero default value to DISABLETEST check and fix the TEST_FAILURES check and reporting - Resolves: rhbz#990631 - file permissions of pkcs11.txt/secmod.db must be kept when modified by NSS - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Add a zero default value to the DISABLETEST and TEST_FAILURES checks - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix the test for zero failures in the %check section - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Restore a mistakenly removed patch - Resolves: rhbz#961659 - SQL backend does not reload certificates- Rebuild for the pem module to link with freel from nss-softokn-3.14.3-6.el6 - Related: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] - Related: rhbz#1010224 - NSS 3.15 breaks SSL in OpenLDAP clients- Don't require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Additional syntax fixes in nss-versus-softoken-test.patch - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix all.sh test for which application was last build by updating nss-versus-softoken-test.path - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Disable the cipher suite already run as part of the nss-softokn build - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nspr-4.10.0 - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix relative path in %check section to prevent undetected test failures - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Rebase to NSS_3.15.1_RTM - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) - Update patches on account of the shallow tree with the rebase to 3.15.1 - Update the pem module sources nss-pem-20130405.tar.bz2 with latest patches applied - Remove patches rendered obsolete by the nss rebase and the updated nss-pem sources - Enable the iquote.patch to access newly introduced types- Do not hold issuer certificate handles in the crl cache - Resolves: rhbz#961659 - SQL backend does not reload certificates- Resolves: rhbz#977341 - nss-tools certutil -H does not list all options- Resolves: rhbz#702083 - dont require unique file basenames- Fix race condition in cert code related to smart cards - Resolves: rhbz#903017 - Firefox hang when CAC/PIV smart card certificates are viewed in the certificate manager- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement. Please ensure that older packages that don't use the alternatives system for libnssckbi.so have a smaller n-v-r.- Syncup with uptream changes for aes gcm and ecc suiteb - Enable ecc support for suite b - Apply several upstream AES GCM fixes - Use the pristine nss upstream sources with ecc included - Export NSS_ENABLE_ECC=1 in both the build and the check sections - Make failed requests for unsupoprted ssl pkcs 11 bypass non fatal - Resolves: rhbz#882408 - NSS_NO_PKCS11_BYPASS must preserve ABI - Related: rhbz#918950 - rebase nss to 3.14.3- Revert to accepting MD5 on digital signatures by default - Resolves: rhbz#918136 - nss 3.14 - MD5 hash algorithm disabled- Ensure pem uses system freebl as with this update freebl brings in new API's - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Install sechash.h and secmodt.h which are now provided by nss-devel - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Remove unsafe -r option from commands that remove headers already shipped by nss-util and nss-softoken- Update to NSS_3.14.3_RTM - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Update expired test certificates (fixed in upstream bug 852781) - Sync up pem module's rsawrapr.c with softoken's upstream changes for nss-3.14.3 - Reactivate the aia tests- Recreate the distrust patch by backporting the upstream one - Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Remove a patch that caused a regression - Resolves: rhbz#883620- Fix locking issue causing curl hangs and authenticate to the correct session - Resolves: rhbz#872838- PEM peminit returns CKR_CANT_LOCK when needed to inform caller module isn't thread safe - Resolves: rhbz#555019 - [PEM] invalid writes in multi-threaded libcurl based application- Add dummy sources file to test for and prevent breaking rhpkg commands - Enable testing for 'rhpk upload' and 'rhpk new-sources' breakage such as hangs - Related: rhbz#837089- Update the license to MPLv2.0 - turn off the aia tests - Resolves: rhbz#837089- Resolves: rhbz#702083 - NSS pem module should not require unique base file names- turn on the aia tests - update nss-589636.patch to apply to httpdserv- turn off aia tests for now- turn off ocsp tests for now- Rebase to nss-3.14.0.0-1 - Resolves: rhbz#837089 - Update ssl-cbc-random-iv patch for new sources - Remove patches rendered obsoleted by rebase to 3.14 - Add a patch to enforce no pkcs11 bypass- Resolves: rhbz#830302 - require nspr 4.9.1- Resolves: rhbz#830302 - revert unwanted changes to nss.pc.in- Resolves: rhbz#830302 - Update RHEL 6.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6- Resolves: rhbz#827351 invalid read and free on invalid cert load failure- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity - Require nss-util 3.13.3- Resolves: rhbz#772628 nss_Init leaks memory- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Use completed patch per code review- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV- Update to 3.13.3 - Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave - Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes- Resolves: rhbz#746632 - Adjust the patch for new sources- Resolves: rhbz#746632 - pem_CreateObject() leaks memory given a non-existing file name- Resolves: 784674 - Protect NSS_Shutdown from clients that fail to initialize nss- Add two needed patches - Resolves: rhbz#783315 - Need nss workaround for freebl bug that causes openswan to drop connections - Resolves: rhbz#747387 - Unable to contact LDAP Server during winsync- Rebuild- Resolves: Bug 784490 - CVE-2011-3389 - Activate a patch that was left out in previous build- Resolves: Bug 744070 - Update to 3.13.1 - Resolves: Bug 784674 - nss should protect against being called before nss_Init - Resolves: Bug 784490 - CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)- Resolves: Bug 761086 - Fix nss-735047.patch to not revert the nss-bz689031.patch- Update builtins certs to those from NSSCKBI_1_88_RTM- Bug 747387 - Unable to contact LDAP Server during winsync- Add to the spec file the patch for Bug 671266- More coverity related fixes in the pem module- Coverity related fixes- Add relro support for executables and shared libraries- Add partial RELRO support- Fix the name of the last patch file- Retagging to pick up two missing commits- Update builtins certs to those from NSSCKBI_1_87_RTM- Update builtins certs to those from NSSCKBI_1_86_RTM- Update builtins certs to those from NSSCKBI_1_85_RTM- Fix CMS to verify signed data when SignerInfo indicates signer by subjectKeyID- Fix pem logging to deal with files originally created by root- Retagging for updated patch missing from previous tag- Update to 3.12.10- Resolves: rhbz# 703658 - Fix crmf hard-coded maximum size for wrapped private keys- Resolves: rhbz#688423 - Enable NSS support for pluggable ECC- Add "Conflicts: curl < 7.19.7-26.el6" to fix Bug 694663- Construct private key nickname based on the full pathname of the pem file- Update expired PayPayEE.cert test certificate - Conditionalize some database tests on user not being root- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Fix memory leaks caused by SECKEY_ImportDERPublicKey- Short-term fix for ssl test suites hangs on ipv6 type connections- Add requires for pkcs11-devel on nss-softokn-freebl devel - Run the test suites in check section per packaging guidelines- Prefer user database ca cert trust settings system's ones - Swap internal key slot on fips mode switches- Update to 3.12.9 - Fix libnsspem to test for and reject directories- Add suppport for pkcs8 formatted keys in the pem module - Add verify(not md5 size mtime) to configuration files attributes - Prevent nss-sysinit disabling on package upgrade - Create pkcs11.txt with correct permissions regardless of current umask - Add option to setup-nsssysinit.sh to report nss-sysinit status - Update test certificate which had expired- Update to 3.12.8- Increase release version number, no code changes- Update to 3.12.7- Rebuilt- Appying the changes in previous log - Changing some BuildRequires to >= as well - Temporarily disabling all tests for faster builds- Change some = to >= in Requires to enable a rebase next- Fix SIGSEGV within CreateObject (#596783) - Update expired test certificate- Fix nss.pc to not require nss-softokn- rebuilt using nss-util 3.2.6- rebuilt using nspr-devel 4.8.4- Update to 3.12.6- Update to NSS_3_12_6_RC1- Fix curl related regression and general patch code clean up- Resolves: #551784 rebuilt after nss-softokn and nss-util builds - this will generate the coorect nss.spec- rebuilt for RHEL-6 candidate, Resolves: #551784- Updated to 3.12.5 from CVS import from Fedora 12 - Moved blank legacy databases to the lookaside cache - Reenabled the full test suite - Retagging for a RHEL-6-test-build- Retagged- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- bump release number and rebuild- Fix nsssysinit to allow root to modify the nss system database (#547860)- Temporarily disabling the ssl tests until Bug 539183 is resolved- Fix an error introduced when adapting the patch for 546211- Remove some left over trace statements from nsssysinit patching- Fix nsssysinit to set the default flags on the crypto module (#545779) - Fix nsssysinit to enable apps to use the system cert store, patch contributed by David Woodhouse (#546221) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387) - Sysinit requires coreutils for post install scriplet (#547067) - Remove redundant header from the pem module- Remove unneeded patch- Update to 3.12.5 - CVE-2009-3555 TLS: MITM attacks via session renegotiation- Require nss-softoken of same arch as nss (#527867)- Fix bug where user was prompted for a password when listing keys on an empty system database (#527048) - Fix setup-nsssysinit to handle more general flags formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build  !"#$%&'()*+,-./01233.28.4-3.el6_93.28.43.28.4-3.el6_93.28.4-3.el6_9nss-confignss3cert.hcertdb.hcertt.hcmmf.hcmmft.hcms.hcmsreclist.hcmst.hcrmf.hcrmft.hcryptohi.hcryptoht.hjar-ds.hjar.hjarfile.hkey.hkeyhi.hkeyt.hkeythi.hnss.hnssckbi.hnsspem.hocsp.hocspt.hp12.hp12plcy.hp12t.hpk11func.hpk11pqg.hpk11priv.hpk11pub.hpk11sdr.hpkcs12.hpkcs12t.hpkcs7t.hpreenc.hsechash.hsecmime.hsecmod.hsecmodt.hsecpkcs5.hsecpkcs7.hsmime.hssl.hsslerr.hsslproto.hsslt.hlibcrmf.anss.pc/usr/bin//usr/include//usr/include/nss3//usr/lib//usr/lib/pkgconfig/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnuASCII textPOSIX shell script text executablecurrent ar archivedirectorypkgconfig fileRPRRR?7zXZ !PH6fm]"k%nÍdڴ4Yk(`<~>}F}/W1 :(6+.3˾ J>Vi7ޟCM0=ʪ:e{}PMPhslߒUʜX4!Nśl.4BUsCx+_슻PmQ EjNwA[zȏl]k"9Q:XfTI}#7]oa_CoLC4 *jVoDT޾D ς2(/ ^y०qgPxtn?kדX`Ib8[=*{j- yfRQA.%~$YnAQSu)D A!d/Η.bi<;ф0y}fѩS2~>-Q1eX~N'w_r,H` q[7^\JixqAN!ѭmْ~zwnԍiX`G[݁6vޤN! ҫ:FX"V|O95=_y-W 鵶Ku$! d>Aeg,E.ba"4X(\$.o7yke>'hQ]QӸ}/rł"{K8l Tx$ͧuϓ|KB=hֆϻO]E_WCt>d+.*-)OA<.#9FtD.Vz1d?!x|/׽F&\&m3XM02ڒ9szK88?n7vWB?c5!B dˆ <*vKé RѬdo@k+XQ߭^|;G9ojpJBa}$X}R4zyzۆR/V xwЭ 0A{ȧ~kE󉣱̈́W1j$b4ej9X{XԴ7tu Ԇ h8GF=p[V9]!$"Ů(Kg[JdϘn혦)DC*^rI9Q5BcV&FO-ՇSh* _ޘZޫ"@"LEXN~Ny I7|S:&*=Cb'0V%fm8Js,1UV)⤊ fBY'dj<]ZYU1 TA*őcW# r ԮW5w2У8G Cao2]ޞ0@X%v: Q ~2Xr,hIMhLMߵpȈ؟`a *v,*<5r`U/?:7[Ӽ?6~THJjA_]eUN{_뜾ۉz3KJﶹ8[aNϯ1j2?YU-Mf?Pii6O7O9J՜|Vmdַl =8:^lѿP+@)뻰vi!jdgx*G @I:Q{Bk8cj\z ȵ qVc(k% dV0Гµ_U8}rm.G2չDe|{eEIVl=Ufd!^GF9DyԔF7A-G> 2d0XD=[{=hn[(z~in6ADv_Ҳ02gP`2;.Jŧ-^e@fﺀ%Au)H ` Vx+×7nɘoe>:7:Zo1犉|& UҧؽP.̱` ]W,$+"ҡ$>,3ixG 8,*{nzo3St  #^LC6˰U@֐:};ʩ{VV Լ㕬xGӜ7:| LȽj/z)' OK<0p;O6X -LQumܳbYdm@-oK.i39t8B8;w\M2Oy\u*),myS3yEG يS?ZC׵n8pCj-Mk*jbfp0;ռhU%k>vGs'/kKVg)?td/X9ImQ< }av^/ê2Y5l]HmllތlH̴jqҋAMʋbl?s~y,$D_dua$xEP Hg&eĎ7M5MZ͑b筼o*q|\\r%9x+&=N ᗻ)Vb*@ݟ0>}~v޷eb.,X߹ZGfgLNs=vd91^{ U&܆L02zr}ut` œ6 6!AoSY\P$M7e1].z87~IF;LlAbpE ?Aa8bKx 4J%C^!ARƙ`r4EgY31t.`#Fj8B=h.2צ|CJ%D6 _1tyыg7i_vMӧl0 ^/jc;=J](]=-CH.ĤM(>)xgK im$.dZj;൨-R$JB'`!-4 ma‰޳ݱ[' % ̋%؄ٽML3T53@ڥf/%6p>o+țq[ѹϼ߶uCs}(}(ޮ8ϖ$Y|Zft "rO ?퀴4\<5 Ocj Tw004=sϙmj[w;% ޞBM[ewΒBճDBIeCDX-^}ϤGm/+8L\^,J\g;#"R:ƒc&_-P^i̙p kjsXJ1'pʰ6,%!->Aľ<:Nx<;5O=!9@QOB81ߣ>`WMXP׼\F!#\5<̦\h;56 ,o$2 eGΦQE1s&UYZ/I!& L)ieuG-`wP6hew x y31t' 'LtXHݯiڑZʔ' A:C§m iix{Ltg8?:.Q5o0䊈_Ri%4 y'ه8w??iv&K4@Ǒ= vUE9~ kN%[JEٗ8HAB[]- gKzFOe@ꓽ'Uu G;w#7/+܇)i!AvƇ0y $ T',E=< Ud2ݙ ?$ԄL2P4%Tx{ @xu }n"9,L*ˣqcA^ڕ]pG.2BNGx4gfL2/~be`FE=K:܂V,y(pEznܚ}PG_i\&ԇ{Y2ǑFʇ%ƦQ- 2757{]B8 ˈ G@wEĒ"ź8q6Lw`E39l%Eo hc ](C(w7!݄CW5/msg/KnBdbOD7oCc[7 m8*4hءpiVSa:HP.(:p?[z۫KrcU p"+ӂ]l~|p)Mؼ@p"Jj%^]0Ӊq|J]-ES( 921>vKϥ,1;[AyQO"P]S~TS?&ǀ@@8)^《fR: \…I,oj6{ybxHHp97kJuR_iӠ%7v{#&V>L1wqu!'Eyɳ&e pz~j>B0 r&OI5?K9Jt)7@.H ^}X,)©M.9%wg #e6kkX'=NF1:f(ۜ)ZG5wyɆX`M37aDE fi DpZt4zȞ=ED8n!zaBAU)_S@]+1h0GcAۄY 4#fٝ\hHk%-|!gFC(u*{d$VOK\ <E$sswUV){őB-BrW DBL؀m8ٜj3cRKA$CL~vCyݗsx\; Qbzk,MV:0rl9( ~d3nBNf j'hfXO+B40*C;gU9\ĞLBL ognpz~0p'誅Ju׍s*¿kd(tLiSY/N2 ; iN},l.`>LP?>vr3cxV׾tB!N:Ps( >5^\5'@]=/*+X lDJ N,X 95TW9+e;p\>Y (u!!%S -xpytDI #F\Tlj4=m "W M oO`p2]/t<|.s'p*pg>~j3\Y7"'䣛Ùk T>Z {2y\cb#[5Xf/l`4bVpշV 0OX5h)J9>z r>s_5Q}6^$F1mHifWbB;~YYJ{[9p&n1\ẻON`F&iQ*ѕx=ls2i zX0Yfp0))p +SuW$ sts#z>M7oOwq a?t8zeT 3Hp-U}=ɃD谠ވDL t%WM(Ȳ>,O ibEk+ad62>f6@:;CRkx kHnβpA|&J¡jOb1C<׊frT */PZ`w o/HK_e􊚖iWGϵ.2 zuR+B>9 4Q*6mG2WpL a7t0>wk<`h*ԒKɽ`=)f$ַ‰heSѨ`q-ryp8H&@Utn1ɇ׌N"lQND}=gOq@`/xyg殫U@7{G^q1 8mf8l\L)3܄IsQ=l(ZAY!|]/%|½3P[ 7;+3[tm#p>?`Ffs\5;8~5Ըѓ/AHO چrq-j]o_R {ӹ@kPɔtyRxVkQl} :^BQBg6 Jr244 <07 "@!;d?#x 'd{ukdBYnZ  f)r5 C ._}g=)[㜩0lL j̣V5΍m(shxQ)AN1$OB/nA|G} r4?^;hE7w1FSR?ZJqIFؒ)GHAe!@ }s`V7_kj2[̨=붖@ܢ?gh3%H`ĥ|þ"΃bY5)2p2 Õ#%xEN,/sMS@<]}zW7V(|Y{Ȗ*euFv͐˝^M1wfâyGa1}q}S]GRc>qMj~y]()HLBsjnFgE #o[vp2g`A(l(]HD dGTY"2p|s \u^h^ԣ16pMT `+-T.u<]7\+?S9=-5:GkUOi̇q|zT^1Y# kXoy5Odi(V}J}iz=cR/?6%/A_!e|z n.`j2aSuqbj7[BXezqִ_Eʷg1?C_PuN}%$ƓR?ʍ U4bebUߗW\+!ڶ3_AJ]4N}kq"pn .`V_2eTuϜJLt;5.8|IB˧F4+hkAčK7p;STs/8#("_{ :M܃&̵@ oqK 0)]lYܧ=Uy/ظ-?B?jm/K/鄈OTmZq4oӝ=۩Y3hm^_r t򈓃hg;^ 39vp|NG=v8SN{,"ո3 )`Eg';&}4\LndMj~ R]VnsAMYW됇NJ3f&;Hƽ%|7q]l|{qGt1H)uTvoP`~9H܊0ކ2e}(k`D}E:gh7>id ]-s_ 9ٯ1݇Gm<^wkO/;ÏՃuel_7, aA$`xJOh fEaVb_`%H#ج.f~F}"q8JdpIP>ا߻ k(K+vmGHA{h6ʎP-D YfA?IH̶U$Q}Q&GZ@(`LJ_f;Bv H *1m7t#)p[MV¨cbْD-H*,%3gU&)ǞC 8.x*? RzQ>@dw 9wmZjD1Kܻvrи%: 3!FTo$>tvդlm/:Jm$b=5:U‰"{G.*HL_m;b[Dy]0;0D'D\2)1_^"qFws:IJ];2p8#MftvRikLzO<4Zqc'^bQgD!nz7 u%˖я{^F'>;w(D/V EW뀣G~ȵw5 E[ ݹ>1ft{!@ʩYFlȓ=̢)twwQߵȗ,; DrP[4>K˸gI=M8ʷʓDIM o(ݱ mX4UuvF ^sT6ܼզќ0p)riK X %/QlNTbKAv)H?v$<6z =׺U3~_g˱ӣ+l}Ĩp{ڝ~qWڵmH*4X܄uwɬEzV56Cv5a"c/30:B< {f9)U~5!6%³ PaL*Y_,Cl}vuֵ4$_$O\:abUdFqjK4hcJȽ\DF䥄v2p~<$oOJ2z>)`:^nwE`Qe $@_ -[;5xLWs H3 F~:kvz+=>MPfMO?2BͶ*Bw u-v<騣Kv;lof8"g%-f,'9֠<5s*  4=rXy~W>r zGk!/\茒\ /X f5AĞ64tl-D<7n[.r9&lUyoa3`\ȉLNuI %UrCqҧ9ѯo`Km' DOH}*t-PfE~tCQVZ"ڄTRI7m:_6i;o;F#eپ[ q|ceUUo >N ,$5t}FҸ5 "}uwrJ3UA^Fԛ{0Egc5ϲz+ĩ*;F~5[SB׏AS}t,Γ͸̆U  ̻S= uCuJbj[oI2@Ҹek H1 ,j M[W{:,vb[z@, ᳛7_R2ZHGM< $kLC[5n<L TqaZ8S#)(΂ޖO >X$vj{89|_T"({g"Q?yaUJzV#wݾ|3w5CR Jz*,{Z57$H)HWNr\tc8!nG6}pLœҜ ܩHt}022}VS vE ^/&6y_J]GB>@܂O61z$XQ{9< }L(+o.>(EKFU|g"ZS8y!Ies0_&0N $JȵC+=Qgi)p(je~Fv?4ѼkhzG F-[j7 =eTn@iNm4@Mt`^oGսIՇP83؆M>iL: F@XOX$W j%:'9&تcmD@\VT$C//zb##QFPT6s5g]>TZ˾Rx_iqnMjd1Ocr<auD5z{Һ ka.-sPb I&f}zF،e]mIAρ@ԥ|7 M̵ī/ݦ= elS%4/beãm- [Wg'Co`=ʝ0Ϫ9Nko<έ42ygS51"٬ zaoh z,jѵjuS &ڗW[%I9 }9Ѥ+ig_EV̱+FrMO~^!?/@6P5CX!] $A D\:@֕=-wU!Dtqm>QeE{W']MɭWk5iW.YWWğg7Yq=2֏Jw;6rNMej<2P0tu#|4hZ\ý`R#6yk7qDîL zr_B c"#f Y5 1 L7͉?R ]ǭxž?53GFfw&sVa߶"3M;)?1zߘ>%N} s\5=WXw-zY\Ňp*?=xB}k1'p;^ݯ5/eY\ǠJgIu*Ô^./&Yvr~\Ԟj0 szB;ޛr XJȘsd25+`4//@RRٲqb$aN)+Յw]*U n#᪤V48z?Gi +мT j{ϒt8HoA -_΂3k~DthL3 L,"@\lQt _99JJb>j qX*g]Ui6z3; _pt,'լsM𣗃bf+mVb%`L볓'bG j%h1ư63SJH{*J"9G*3xLo!?e|8~@4D&bB2{Wǭ80JrغX& _Q2 "D"wQ\5^y 2i'@}U L&,8h`\ 1م^:D{5L"N/\-$ql\+f&WhsH;gF?z r+2F?^^ma1J&JaX("AӨRe@6_[:-J5%N@i-+ތKt=w6|؇MYiC;E<d:jK6DET\20xop(Xt&ФBk#`mi-0x`# ={T̰>ؤBtDlg{!q?_Tu Q7:D[Z]#BSC-%PLOeux8rNC%U@T׋LItDsI"Ra$Ĥ]Rr:/]L|-a.+G0lK ,1+H/R=<:3{]}Z7Vt4ss gû"4ћHDPm}.Ix!~+R8sx9!e`oI@=%J^&28hųG Zd5$ion>Q&uYy?8_^">x)Gtl~hBxx<]@ p%΃\]\<1_KƗ̕"oh~->Xi3LmO{As5#g!xbfu@ߗ,C,Bx%LzP#ߍDģ^"zp3+"ۉx6eA 1ŜBSCY5ԯ#7zwsC~-k~6(htĩDbcrm6;!x'"< [ݶfNe {@ݺv߫m]-{;p`xT{(w@;xԓ4ģ!r֪b6oR>ꎎdz&%^/:]ĪI;3#hfsA.9GT@zɔܙW^UG8i?FD2,D|twW{zĆ3EпC1G{FIIșF HpA]O{S#Y0Lm^?1 *GZG~N:uP<{[¬*gգjuI_šUn!2%F%VR$3cKe}şͥrWH;-IS8jƵeK^"ivʳ5w֡M,^ ' :)lbɃ2ZM8 %,U8jF,tqIhe<-ugK`ۦwL[e\*q$8u2\Wc ("79{U~iXh9oiZ}ifPK5.B5\?\2TNrd*JqYy ߄.Li?!I},Nw~Jv5T U^6^|cG22^s(fMqh/JWPG nYa%#:g'pg07#=€a?g=$l}6kxDn#ɚ-2NnbBюTgAW׆ҝ "r'{(kX< o3/:k738F T$ d\ęZ:^eg/:GH/ ~K‰ar4 6PxENI_@̷JUS(rTx|| 3 ATDE(\Mr6wI'{OS;`?%&N\x3 6|:_?\Mj8-7 D&Ճ q5zErq FdxWnjQqS%RpX`Qrp}hKj{g)2@ `2G aԑM[D#L~@ҫMa$]p}܅= n A}~eaos:kȜ)*|%tvKj|!wقak Tۂ踽6qBe7\*lrbrh-{Wٰv?cBxdY2tK. J XjKnڡH^sY-U-xmz ε8M-\hP!+]bufJvFnR]1 u7xx|\&O~k|IJU 1>OCT7Q>_V O{^+$|;erM< }Tl~lBVRzޥY3nf4꤯OU”WVIxCKsG$M?BYc0=l(Vto;1?4T[jw@dU-:bfPԋbu5_)f-x}G':IC/gLy'g>lHxw$2sHy}ZO}PLI>y,Zr_kU3fb@tHbu‘bμ0|z)"]*w '10 ,h+% ]p/Y;t헅v=h6EIAqi' 9uP ̦󞆓T_y86Sg` \qDԭZQvW!k6>=*3jaZѓzkţCHȰwtq̑\jd80bǻmpԛw3? V$km㋑0 MW mUFu笠 $$\ü^Z|.#bWAm$thMV/&QJiz֙aџOƱLȋ^pCnOf 9F/zpXeͬλ[G!h"u>CXp3GηZs|sWpI~N%Xe9s!Rn$2y{ry5.Z!Dn%da)Fk}nEȃDȄfi93/6105ESBE&ǡ{.ױY04 e @j' NTtM&E;-v.ɐ,sd19<E~A?ք7(%- f뽋(ے z+XE~sx+ Ӳ]Rtr rԡÆP%'~f)4B:+vԊKKrqYnS s{p%=Tg/m7b?ngeƔ8?ע!3YcU+zI5sS|oa=WhSF4K|)muXuɫtduǗt9ǃMH;%r]I<\K(08x*ѢBIaՌ|I"6|[ {)KjRaGP̿nʰg//="Jh+żUhjf0>!5 /˜ٺg_*ꋀNE<=ca#2tG0S\yxS}~hEۻEkscѼcGQfZ%o3HG4ԆCCʆ/I6Y2BN kƪQnDbxr|8=j.@);K}HxUtt T"ef+N$>"\)B=$mxg֍(!{fXM1 A8]Cu`*o28jgo7ܨq.l;h¹[|T_0-5 KK.eOMy65"+c&uC7/;۷I$τf=+_>I%>?z% 6`MBǦSN79eq&N=toXrw}mkLQ 7=*_q]wXܯ)¤ 2w%7fұꊦYީen:@хG](-D-;BNTQtH9Z * I]^"Wڮ+^'MiGy ?sYGSFilW:Ɍ־`o"2ʢ+\"aE/I[ʩ֖ I FpGɹsAc\4W~{@4qU%ܔsoon#z?M?ڂTLU} (b{#Ê.FȚE,OQe~ `UH1>! gŬܮfՕzA%& _E G+uDhE gaO{u`1.vLuPk3/-ٺ{q^;FC;8 P!v%ץ3Oadc }}sŇocupFDhoW(μ25^gk1ލ/|١E=e5-G jD砛W *b9Q(*x{Ux ,$CghvcnsdIЖ'Z.a[,sࣆd1Z0YykJwpq +O~r)f%͹j&Fu .WOg6 Rdg*_A!;<u:CH/;d%Mm7#3a`[8;qFZ䩘;sI->JI>kapRj$[(ذٿ' g"4T+wos«i/XvC #<3,jUo_6H1ú 2<9tΥޑnvuQ\kN> QT#RI4L˺hXL:[qzY]qiH9 9Qk a?ؤL 6BfP|.َݎCyGŞ,i˜{x#q;ˢZu5 0/[1192%f*+e|)gt+Y3zZw"LyR>5Ih7u!Ǥ&] ؠlG[ &؆_nJk9.a¤K!J@8Ҧ(*gP1] Cu7-H+s#A] qnQy ZXæhzWwlazh#*ω6@wPSn-ʻ ǣ*Umei;s~uؖd!M8ڍZw5eL%qU X̆,>XLSTfSpv{EK AX]td|'5ƫ܅-їXáLVX>zx]#S_R{`݇s ⑿pU&˅l!Jmhuja@] _a&5=Y;p(>k:Y vIy4*F;H3K"4.h۵JfU=SHfKVG,է71T*P 0sP`ڼ;jz&xvZx sÛZ)sɰ5ސM)%M}g}뿘P]@%^e;P`a^+@ 3IRp hEвwjv4oRnJxh|2%$!/{֍0:\apԀr6om!vŇ̴! "m42奼cдuМH2V_y yrS9ˉ2wE\ԕ!A`tafII:M5T^:>]>OZ/yY䟆:zYȡae9f^?=ӑbxsY&#U="N*2]=vh͟{t[F,~ђJ#V+Y/F&GH#`ub|c|&vsIbdJf$KEqq"}ye#>|"f t|[2_ :_eZWRq%QԂ2([5-$6ҠQc'*>)V51tA@<{P3@dS,}``_AyT,c(Ht 1V<[5!he^u)rMY~8A5sN>^a)wfUC+&@T*e 'zy, ΋S}|o4oHw;I6O{ū럨6R<+N/erF8cZ8lHy77\qDd_"X0k$S̱=ޘM!CaΫ!4[5Zg7-:t6` xY&``eCXA*P'Vn7 5;_gVNHAF%J.f2%4Oa4G /%e/`[E iS6&0#/9h3?^V+?,G(5>W Es-&CH4.ĬQ?S| ݫ.fza"1bGvzԘm l/{!YZp_(GUڸ:K²a04:Tn9JAQc6 ҝ رېU'~N 9iuzx>dqhzF<7/l6w`2B܃T5?&xz$&`FM1nd7YRv8,`ijeZC>L ~&9@ fSϦVpx *,>c=Dq/ͨH̘=f l7`$"B92͂$9[9k ޅo.3y3"D; ~}K^;IC| ɝRRd1_kM&L %iD - -4'iꈗLmsQ`'Mҧ.&[3[SkIMNBP81"̠1(u=o27g[b&B{E 㚀y5j3 3 cRdd3lcӄkp$+!^{# #c%gйݼqCޞwZH߳ҪC+50wZ7ug'RQaJU3xZh$ ɡBj [Iʋ48&g+yK!$WdC0Czsħ 䳣D*A)>(f~ |cq _}wSU_41fyQ|1N//+^|I'@:*oM">EJ1hZX/mbº&tv͵B@bnRNjPڅ5IAܬd|ذjލg=ʋ% _Νlo[(iasp+;L3yG}uBa@^VH6Me:=2Nȥ…< tKL/MBwe1J'_̖es9<@O}{,oWy-n Kb`2)oRpZp3: J5RT},i/6eU@}X7n'odvYBsc<).C.Qb]`ޒb0#Yv u}NYwot|*mROq+.a^dC\6 "FnAoYNX\6WSn!^ !zgE?Em iVp$ avV^rS(_=nNFgτR; F;m# ^Ub$% 6^PcSeV^Rhe)g~񦜔J!32x{d4h@7QS<9Qā兇p8ǣT[0%˵ebuO̻l^ƚ(>z*fb*Cs4f.&a՝j3*iٰNjF/RrA?(ok5~XdPȊvo_آ[o/Wty-$~/sHn{tQt)b-[~Tyk&m)WSɭ{},'%n  w(ږzī\V?f,Jdb'p=!~bY`TdDLEüh-ZC֍;\^ PosZ0R&A-kcW g @qUޚώSQMul-S@3:(~۩Ԍ/t<[tuk)0xg5ZBU[:o: kQ3_2ϽO:Jc:'0}CHP4pp2[2?wj2;Ǘ.Y˦="~Փp5WAWHWCW9bkt; ޼*M:=Ҙ,wqahXFg*&b{jQ7a`:{͕[Ll8[f&$:h3:LeUzg{JJk''uADEv_|3lUo|i ,Hlnu8wix"aQ1>PSi0ȫ*SGO{s^)j=:eϘmĬd~{5<<}hs+'Њ$uru4_ah& !5#dKel D=2 kvƞHTjr%L~գ8؊83t_)؛5$ &tr! \?`xЀGLUdnX⪰jOv`0N~?ʐzu"E71<iۚ %6XjJzwAm2g)B0´tp!ɿ"xNQY1DLDkAN~kQ챹h29`}W% a2r=y=fw+x\8+>sIECS;jO q7I WT*D^'J1v:4¨}i?uOl&kN23V7#.(HZbd\Q$ |@j#/bm1PO H'k? }D1c$|`▴HB4߱/kmKVGg^&)YP{k% 0$k+%+a,+ جٹ;,B#0T9[0>W| A,ECCV|o;+vy6Z8b& \!fq'q Z28C[>!VAZf'И=j 樏|ҌTo .`s)0isۙ6Cu?u 2~E:!cՒ ;.QlhmpK1tV0=RvHKܦ 7TWtQ>)wT D`V<15NvFBրQrN$Dq _sqrm^~ - w)>]l`yaPJ o ɋ'ĹLtTDwXvfˈp| @E]ߨxc zyF /6' XBǶĵb"|4@џoR6k4E-*urޝ^5"wBBjs[̠̔ź_G֠#VSp>U]o-uc\6Tp/U yú׃N=t`)ipt= (KU7|bl&>Py*Eb}-*__}VkC&R$!I-=X0ha 8@7#lኜ)Ʊ\bꌲ]Fk6Μ-{6t/ ӟ2"Wn`<[_$WeyfLI۳dVW)/#nRakQxUefeODYN! 6 YZ