nss-devel-3.28.4-1.el6_9$>OȒ kazw+>8?d   O CIP33 3 3 3 g3 3h3g3f3P(89:OYG3H|3IH3X|Y\3]3^Hbd eflt03u3vw$3x3yüCnss-devel3.28.41.el6_9Development libraries for Network Security ServicesHeader and Library files for doing development with Network Security Services.X c1bl.rdu2.centos.org CentOSMPLv2.0CentOS BuildSystem Development/Librarieshttp://www.mozilla.org/projects/security/pki/nss/linuxx86_64  YRCyQ - 3.28.4-1Daiki Ueno - 3.28.3-3Daiki Ueno - 3.28.3-2Daiki Ueno - 3.28.3-1Daiki Ueno - 3.27.1-13Daiki Ueno - 3.27.1-12Daiki Ueno - 3.27.1-11Daiki Ueno - 3.27.1-10Daiki Ueno - 3.27.1-9Daiki Ueno - 3.27.1-8Daiki Ueno - 3.27.1-7Kai Engert - 3.27.1-6Kai Engert - 3.27.1-5Kai Engert - 3.27.1-4Kai Engert - 3.27.1-3Daiki Ueno - 3.27.1-2Daiki Ueno - 3.27.1-1Kai Engert - 3.21.0-8Elio Maldonado - 3.21.0-7Elio Maldonado - 3.21.0-6Elio Maldonado - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado - 3.21.0-2Elio Maldonado - 3.21.0-1Elio Maldonado - 3.19.1-9Elio Maldonado - 3.19.1-7Elio Maldonado - 3.19.1-6Elio Maldonado - 3.19.1-5Elio Maldonado - 3.19.1-4Kai Engert - 3.19.1-3Kai Engert - 3.19.1-2Elio Maldonado - 3.19.1-1Kai Engert - 3.18.0-5.3Elio Maldonado - 3.18.0-5Elio Maldonado - 3.18.0-4Elio Maldonado - 3.18.0-3Elio Maldonado - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.16.2.3-4Elio Maldonado - 3.16.2.3-3Elio Maldonado - 3.16.2.3-1Elio Maldonado - 3.16.1-14Elio Maldonado - 3.16.1-13Elio Maldonado - 3.16.1-12Elio Maldonado - 3.16.1-11Elio Maldonado - 3.16.1-10Elio Maldonado - 3.16.1-9Elio Maldonado - 3.16.1-8Elio Maldonado - 3.16.1-7Elio Maldonado - 3.16.1-6Elio Maldonado - 3.16.1-5Elio Maldonado - 3.16.1-4Elio Maldonado - 3.16.1-3Elio Maldonado - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.15.3-11Elio Maldonado - 3.15.3-10Elio Maldonado - 3.15.3-9Elio Maldonado - 3.15.3-8Elio Maldonado - 3.15.3-7Elio Maldonado - 3.15.3-6Elio Maldonado - 3.15.3-5Elio Maldonado - 3.15.3-4Elio Maldonado - 3.15.3-3Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.1-15Elio Maldonado - 3.15.1-14Elio Maldonado - 3.15.1-13Elio Maldonado - 3.15.1-12Elio Maldonado - 3.15.1-11Elio Maldonado - 3.15.1-10Elio Maldonado - 3.15.1-9Elio Maldonado - 3.15.1-8Kai Engert - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.14.3-37Elio Maldonado - 3.14.3-36Elio Maldonado - 3.14.3-35Elio Maldonado - 3.14.3-34Kai Engert - 3.14.3-33Elio Maldonado - 3.14.3-5Elio Maldonado - 3.14.3-4Elio Maldonado - 3.14.3-3Elio Maldonado - 3.14.3-2Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.0.0-12Elio Maldonado - 3.14.0.0-11Elio Maldonado - 3.14.0.0-10Elio Maldonado - 3.14.0.0-9Elio Maldonado - 3.14.0.0-8Elio Maldonado - 3.14.0.0-7Elio Maldonado - 3.14.0.0-6Elio Maldonado - 3.14.0.0-5Elio Maldonado - 3.14.0.0-4Kai Engert - 3.14.0.0-3Bob Relyea - 3.14.0.0-2Elio Maldonado - 3.14.0.0-1Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.3-7Elio Maldonado - 3.13.3-6Elio Maldonado Batiz - 3.13.3-5Elio Maldonado Batiz - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Elio Maldonado Batiz - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado - 3.13.1-4Elio Maldonado - 3.13.1-4Martin Stransky 3.13.1-3Elio Maldonado Batiz - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.12.10-17Elio Maldonado - 3.12.10-16Elio Maldonado - 3.12.10-15Elio Maldonado - 3.12.10-14Elio Maldonado - 3.12.10-13Elio Maldonado - 3.12.10-12Elio Maldonado - 3.12.10-11Elio Maldonado - 3.12.10-10Elio Maldonado - 3.12.10-9Elio Maldonado - 3.12.10-8Elio Maldonado - 3.12.10-7Elio Maldonado - 3.12.10-6Elio Maldonado - 3.12.10-5Elio Maldonado - 3.12.10-4Elio Maldonado - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado Batiz - 3.12.9-9Elio Maldonado - 3.12.9-8Elio Maldonado - 3.12.9-7Elio Maldonado - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Kai Engert - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5.99-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-7.3Elio Maldonado - 3.12.5-7.2Elio Maldonado - 3.12.5-7.1Elio Maldonado - 3.12.5-7Elio Maldonado - 3.12.5-6Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-2Elio Maldonado - 3.12.5-1.14Elio Maldonado - 3.12.5-1.12.1Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.10Elio Maldonado - 3.12.5-1.8Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-1.2Elio Maldonado - 3.12.4-15Elio Maldonado - 3.12.4-14Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Rebase to 3.28.4- Fix crash with tstclnt -W - Adjust gtests to run with our old softoken and downstream patches- Avoid cipher suite ordering change, spotted by Hubert Kario- Rebase to 3.28.3 - Remove upstreamed moz-1282627-rh-1294606.patch, moz-1312141-rh-1387811.patch, moz-1315936.patch, and moz-1318561.patch - Remove no longer necessary nss-duplicate-ciphers.patch - Disable X25519 and exclude tests using it - Catch failed ASN1 decoding of RSA keys, by Kamil Dudka (#1427481)- Update expired PayPalEE.cert- Disable unsupported test cases in ssl_gtests- Adjust the sslstress.txt filename so that it matches with the disableSSL2tests patch ported from RHEL 7 - Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests - Don't add gtests and ssl_gtests to nss_tests, unless gtests are enabled- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release - Add patch to fix bash syntax error in tests/ssl.sh - Add patch to remove duplicate ciphersuites entries in sslinfo.c - Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range - Build with support for SSLKEYLOGFILE- Update fix_multiple_open patch to fix regression in openldap client - Remove pk11_genobj_leak patch, which caused crash with Firefox - Add comment in the policy file to preserve the last empty line - Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not provided by softoken; this superseds check_hash_impl patch- Fix problem in check_hash_impl patch- Add patch to check if hash algorithms are backed by a token - Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256, which have never enabled in the past- Add upstream patch to fix a crash. Mozilla #1315936- Disable the use of RSA-PSS with SSL/TLS. #1390161- Use updated upstream patch for RH bug 1387811- Added upstream patches to fix RH bugs 1057388, 1294606, 1387811- Enable gtests when requested- Rebase to NSS 3.27.1 - Remove nss-646045.patch, which is not necessary - Remove p-disable-md5-590364-reversed.patch, which is no-op here, because the patched code is removed later in %setup - Remove disable_hw_gcm.patch, which is no-op here, because the patched code is removed later in %setup. Also remove NSS_DISABLE_HW_GCM setting, which was only required for RHEL 5 - Add Bug-1001841-disable-sslv2-libssl.patch and Bug-1001841-disable-sslv2-tests.patch, which completedly disable EXPORT ciphersuites. Ported from RHEL 7 - Remove disable-export-suites-tests.patch, which is covered by Bug-1001841-disable-sslv2-tests.patch - Remove nss-ca-2.6-enable-legacy.patch, as we decided to not allow 1024 legacy CA certificates - Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits - Remove nss-init-ss-sec-certs-null.patch, which appears to be no-op, as it clears memory area allocated with PORT_ZAlloc() - Remove nss-disable-sslv2-libssl.patch, nss-disable-sslv2-tests.patch, sslauth-no-v2.patch, and nss-sslstress-txt-ssl3-lower-value-in-range.patch as SSLv2 is already disabled in upstream - Remove fix-nss-test-filtering.patch, which is fixed in upstream - Add nss-check-policy-file.patch from Fedora - Install policy config in /etc/pki/nss-legacy/nss-rhel6.config- Ensure all ssl.sh tests are executed- Update sslauth patch to run more tests- Fix syntax errors in patch that disables sslv2 tests - Resolves: Bug 1297888 - Rebase RHEL 6.8 to NSS 3.21 for Firefox 45- Resolves: Bug 1304812 - Disable support for SSLv2 completely.- Add patches for ABI compatibility- Disable extended master-secret due to older version of softoken- Enable two additional ciphers and keep another one disabled - Prevent enabling extended masker key derive- Rebase to NSS-3.21- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol - Resolves: Bug 1289890- Package listsuites as part of the unsupported tools set - Resolves: Bug 1283655- Resolves: Bug 1272504 - Enable TLS 1.2 as the default in nss- Rebuild against updated NSPR- Sync up with the rhel-6.6 branch - Resolves: Bug 1224450- Additional NULL initialization.- Updated the patch to keep old cipher suite order - Resolves: Bug 1224450- Rebase to nss-3.19.1 - Resolves: Bug 1224450- On RHEL 6.x keep the TLS version defaults unchanged. - Require softokn build 22 to ensure runtime compatibility. - Relax the requirement from pkcs11-devel to nss-softokn-freebl-devel to allow same or newer. - Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1)- Update and reeneable nss-646045.patch on account of the rebase - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Fix shell syntax error in nss/tests/all.sh - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Restore a patch that had been mistakenly disabled - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Replace expired PayPal test certificate that breaks the build - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] - Resolves: Bug 1131311 - rhel65 ns-slapd crash, segfault error 4 in libnss3.so in PK11_DoesMechanism at pk11slot.c:1824 - Temporarily disable some tests until expired PayPalEE.cert is renewed- Keep the same cipher suite order as we had in NSS_3_15_3_RTM - Resolves: Bug 1123092 - openldap-2.4.23-34.el6_5.1.i686 fails after updating nss to nss-3.16.1-4.el6_5.i686- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 - Remove unused indentation pseudo patch - require nss util 3.16.2.3 - Restore patch for certutil man page - supply missing options descriptions to the man page- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Resolves: Bug 1145432 - CVE-2014-1568- Fix pem deadlock caused by previous version of a fix for a race condition - Fixes: Bug 1090681- Add references to bugs filed upstream - Related: Bug 1090681, Bug 1104300- Resolves: Bug 1090681 - RHDS 9.1 389-ds-base-1.2.11.15-31 crash in PK11_DoesMechanism- Replace expired PayPal test certificate that breaks the build - Related: Bug 1099619- Fix defects found by coverity - Resolves: Bug 1104300- Backport nss-3.12.6 upstream fix required by Firefox 31 - Resolves: Bug 1099619- Update nspr-version to 4.10.6- Update pem sources to the same ones used on rhel-7 - Remove no longer needed patches on account of this update - Resolves: Bug 1002205- Move removal of directories to the end of the %prep section - Resolves: Bug 689919 - build without any softoken or util sources in the tree- Remove unused patches rendered obsolete- Fix pem module trashing of private keys on failed login - Resolves: Bug 1002205 - PEM module trashes private keys if login fails- Restore use of indentation patch until another bug is resolved - Resolves: Bug 606022 - nss security tools lack man pages- Update to nss-3.16.1 - Resolves: Bug 1099619 - Rebase nss in RHEL 6.6 to NSS 3.16.1- Resolves: Bug 689919 - build without any softoken or util sources in the tree - Add define-uint32.patch to deal with using older version of nss-softokn - Fix suboptimal test failure detection shell code in the %check section- Prevent users from disabling the internal crypto module - Resolves: Bug 1059176 - nss segfaults with opencryptoki module- Improve support for ECDSA algorithm via pluggable ECC - Document the purpose of the iquote.patch - Resolves: Bug 1057224 - Pluggable ECC in NSS not enabled on RHEL 6 and above- Install man pages for the nss security tools - Resolves: Bug 606022 - nss security tools lack man pages- Fix the numbering and naming of the patches - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- make derEncodingsMatch work with encrypted keys - rename a patch, dropped the experimental moniker from it - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Revoke trust in one mis-issued anssi certificate - Resolves: Bug 1042686 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]- Disable hw gcm on rhel-5 based build environments where OS lacks support - Rollback changes to build nss without softokn until Bug 689919 is approved - Cipher suite was run as part of the nss-softokn build- Build nss without softoken, freebl, or util sources in the build source tree - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Update to NSS_3_15_3_RTM - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 - Resolves: Bug 1031238 - deadlock in trust domain lock and object lock- Using export NSS_DISABLE_HW_GCM=1 to deal with some problemmatic build systems - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add s390x and ia64 to the %define multilib_arches list used for defining alt_ckbi - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add zero default value to DISABLETEST check and fix the TEST_FAILURES check and reporting - Resolves: rhbz#990631 - file permissions of pkcs11.txt/secmod.db must be kept when modified by NSS - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Add a zero default value to the DISABLETEST and TEST_FAILURES checks - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix the test for zero failures in the %check section - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Restore a mistakenly removed patch - Resolves: rhbz#961659 - SQL backend does not reload certificates- Rebuild for the pem module to link with freel from nss-softokn-3.14.3-6.el6 - Related: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] - Related: rhbz#1010224 - NSS 3.15 breaks SSL in OpenLDAP clients- Don't require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Additional syntax fixes in nss-versus-softoken-test.patch - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix all.sh test for which application was last build by updating nss-versus-softoken-test.path - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Disable the cipher suite already run as part of the nss-softokn build - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nspr-4.10.0 - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix relative path in %check section to prevent undetected test failures - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Rebase to NSS_3.15.1_RTM - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) - Update patches on account of the shallow tree with the rebase to 3.15.1 - Update the pem module sources nss-pem-20130405.tar.bz2 with latest patches applied - Remove patches rendered obsolete by the nss rebase and the updated nss-pem sources - Enable the iquote.patch to access newly introduced types- Do not hold issuer certificate handles in the crl cache - Resolves: rhbz#961659 - SQL backend does not reload certificates- Resolves: rhbz#977341 - nss-tools certutil -H does not list all options- Resolves: rhbz#702083 - dont require unique file basenames- Fix race condition in cert code related to smart cards - Resolves: rhbz#903017 - Firefox hang when CAC/PIV smart card certificates are viewed in the certificate manager- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement. Please ensure that older packages that don't use the alternatives system for libnssckbi.so have a smaller n-v-r.- Syncup with uptream changes for aes gcm and ecc suiteb - Enable ecc support for suite b - Apply several upstream AES GCM fixes - Use the pristine nss upstream sources with ecc included - Export NSS_ENABLE_ECC=1 in both the build and the check sections - Make failed requests for unsupoprted ssl pkcs 11 bypass non fatal - Resolves: rhbz#882408 - NSS_NO_PKCS11_BYPASS must preserve ABI - Related: rhbz#918950 - rebase nss to 3.14.3- Revert to accepting MD5 on digital signatures by default - Resolves: rhbz#918136 - nss 3.14 - MD5 hash algorithm disabled- Ensure pem uses system freebl as with this update freebl brings in new API's - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Install sechash.h and secmodt.h which are now provided by nss-devel - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Remove unsafe -r option from commands that remove headers already shipped by nss-util and nss-softoken- Update to NSS_3.14.3_RTM - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Update expired test certificates (fixed in upstream bug 852781) - Sync up pem module's rsawrapr.c with softoken's upstream changes for nss-3.14.3 - Reactivate the aia tests- Recreate the distrust patch by backporting the upstream one - Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Remove a patch that caused a regression - Resolves: rhbz#883620- Fix locking issue causing curl hangs and authenticate to the correct session - Resolves: rhbz#872838- PEM peminit returns CKR_CANT_LOCK when needed to inform caller module isn't thread safe - Resolves: rhbz#555019 - [PEM] invalid writes in multi-threaded libcurl based application- Add dummy sources file to test for and prevent breaking rhpkg commands - Enable testing for 'rhpk upload' and 'rhpk new-sources' breakage such as hangs - Related: rhbz#837089- Update the license to MPLv2.0 - turn off the aia tests - Resolves: rhbz#837089- Resolves: rhbz#702083 - NSS pem module should not require unique base file names- turn on the aia tests - update nss-589636.patch to apply to httpdserv- turn off aia tests for now- turn off ocsp tests for now- Rebase to nss-3.14.0.0-1 - Resolves: rhbz#837089 - Update ssl-cbc-random-iv patch for new sources - Remove patches rendered obsoleted by rebase to 3.14 - Add a patch to enforce no pkcs11 bypass- Resolves: rhbz#830302 - require nspr 4.9.1- Resolves: rhbz#830302 - revert unwanted changes to nss.pc.in- Resolves: rhbz#830302 - Update RHEL 6.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6- Resolves: rhbz#827351 invalid read and free on invalid cert load failure- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity - Require nss-util 3.13.3- Resolves: rhbz#772628 nss_Init leaks memory- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Use completed patch per code review- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV- Update to 3.13.3 - Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave - Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes- Resolves: rhbz#746632 - Adjust the patch for new sources- Resolves: rhbz#746632 - pem_CreateObject() leaks memory given a non-existing file name- Resolves: 784674 - Protect NSS_Shutdown from clients that fail to initialize nss- Add two needed patches - Resolves: rhbz#783315 - Need nss workaround for freebl bug that causes openswan to drop connections - Resolves: rhbz#747387 - Unable to contact LDAP Server during winsync- Rebuild- Resolves: Bug 784490 - CVE-2011-3389 - Activate a patch that was left out in previous build- Resolves: Bug 744070 - Update to 3.13.1 - Resolves: Bug 784674 - nss should protect against being called before nss_Init - Resolves: Bug 784490 - CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)- Resolves: Bug 761086 - Fix nss-735047.patch to not revert the nss-bz689031.patch- Update builtins certs to those from NSSCKBI_1_88_RTM- Bug 747387 - Unable to contact LDAP Server during winsync- Add to the spec file the patch for Bug 671266- More coverity related fixes in the pem module- Coverity related fixes- Add relro support for executables and shared libraries- Add partial RELRO support- Fix the name of the last patch file- Retagging to pick up two missing commits- Update builtins certs to those from NSSCKBI_1_87_RTM- Update builtins certs to those from NSSCKBI_1_86_RTM- Update builtins certs to those from NSSCKBI_1_85_RTM- Fix CMS to verify signed data when SignerInfo indicates signer by subjectKeyID- Fix pem logging to deal with files originally created by root- Retagging for updated patch missing from previous tag- Update to 3.12.10- Resolves: rhbz# 703658 - Fix crmf hard-coded maximum size for wrapped private keys- Resolves: rhbz#688423 - Enable NSS support for pluggable ECC- Add "Conflicts: curl < 7.19.7-26.el6" to fix Bug 694663- Construct private key nickname based on the full pathname of the pem file- Update expired PayPayEE.cert test certificate - Conditionalize some database tests on user not being root- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Fix memory leaks caused by SECKEY_ImportDERPublicKey- Short-term fix for ssl test suites hangs on ipv6 type connections- Add requires for pkcs11-devel on nss-softokn-freebl devel - Run the test suites in check section per packaging guidelines- Prefer user database ca cert trust settings system's ones - Swap internal key slot on fips mode switches- Update to 3.12.9 - Fix libnsspem to test for and reject directories- Add suppport for pkcs8 formatted keys in the pem module - Add verify(not md5 size mtime) to configuration files attributes - Prevent nss-sysinit disabling on package upgrade - Create pkcs11.txt with correct permissions regardless of current umask - Add option to setup-nsssysinit.sh to report nss-sysinit status - Update test certificate which had expired- Update to 3.12.8- Increase release version number, no code changes- Update to 3.12.7- Rebuilt- Appying the changes in previous log - Changing some BuildRequires to >= as well - Temporarily disabling all tests for faster builds- Change some = to >= in Requires to enable a rebase next- Fix SIGSEGV within CreateObject (#596783) - Update expired test certificate- Fix nss.pc to not require nss-softokn- rebuilt using nss-util 3.2.6- rebuilt using nspr-devel 4.8.4- Update to 3.12.6- Update to NSS_3_12_6_RC1- Fix curl related regression and general patch code clean up- Resolves: #551784 rebuilt after nss-softokn and nss-util builds - this will generate the coorect nss.spec- rebuilt for RHEL-6 candidate, Resolves: #551784- Updated to 3.12.5 from CVS import from Fedora 12 - Moved blank legacy databases to the lookaside cache - Reenabled the full test suite - Retagging for a RHEL-6-test-build- Retagged- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- bump release number and rebuild- Fix nsssysinit to allow root to modify the nss system database (#547860)- Temporarily disabling the ssl tests until Bug 539183 is resolved- Fix an error introduced when adapting the patch for 546211- Remove some left over trace statements from nsssysinit patching- Fix nsssysinit to set the default flags on the crypto module (#545779) - Fix nsssysinit to enable apps to use the system cert store, patch contributed by David Woodhouse (#546221) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387) - Sysinit requires coreutils for post install scriplet (#547067) - Remove redundant header from the pem module- Remove unneeded patch- Update to 3.12.5 - CVE-2009-3555 TLS: MITM attacks via session renegotiation- Require nss-softoken of same arch as nss (#527867)- Fix bug where user was prompted for a password when listing keys on an empty system database (#527048) - Fix setup-nsssysinit to handle more general flags formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build  !"#$%&'()*+,-./01233.28.4-1.el6_93.28.43.28.4-1.el6_93.28.4-1.el6_9nss-confignss3cert.hcertdb.hcertt.hcmmf.hcmmft.hcms.hcmsreclist.hcmst.hcrmf.hcrmft.hcryptohi.hcryptoht.hjar-ds.hjar.hjarfile.hkey.hkeyhi.hkeyt.hkeythi.hnss.hnssckbi.hnsspem.hocsp.hocspt.hp12.hp12plcy.hp12t.hpk11func.hpk11pqg.hpk11priv.hpk11pub.hpk11sdr.hpkcs12.hpkcs12t.hpkcs7t.hpreenc.hsechash.hsecmime.hsecmod.hsecmodt.hsecpkcs5.hsecpkcs7.hsmime.hssl.hsslerr.hsslproto.hsslt.hlibcrmf.anss.pc/usr/bin//usr/include//usr/include/nss3//usr/lib64//usr/lib64/pkgconfig/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuASCII textPOSIX shell script text executablecurrent ar archivedirectorypkgconfig fileRPRRR?7zXZ !PH6n]"k%nÍdڴ4Yk(`<͓%BRJI!)Epe`rXlmstS-QJ]Q+9`;C+,]//W[\c+jdnBfp*+9|*ä 8)sSUT-)AiU3n ëŪr|\2_ȸg>6/T>TG l.e85ގ[a.ඖra7̥8(85xv-sWQ@%l`$Cd=Y] ގfQ9vB,QJթXU!Ta .0s00p 2Δ,/ Ǚ$$}HWN"6\ 256!`c1W5m z!7Hn6H0.^kSK@Z$T,%hHq NMjrh86@d@dLkP?MI%ˆTFqݡJod\f-3,7fQiBv^B+ ._'AB0C$d6=+uu1dǜq:Wv{埀b2]T7 J[貸ߒ8m@{B ֫UӤ"-7?D &gmieG#[X?9vs} 4Av) C/C9bBO `, k=r,'Q&li31Ú[DDVKNWq8O-8\l#3!Ze n e0b YQBUSl6MV9{`qx$ӧ>h @]}hݲ~[p/!!>fs+hIPBʃ]`Vo|;Gn"V_ݴԤnoiEzgrWzެ( a/5m[c3۷~j⚂k9.K2#0eGj&5LdJdl+5m;b*STe2^o7]$ΫЫE<][;>+l70WCQ"#]~NK<۸z~4v -̚#dO43NivWm IMGn<զPC:V݁$y ~_7Hh V\3hd+;F14\9ew@kq1TWj䢡/CU"@FM~}̃`/Y q;!t6bːY9{7""2&m؅76*T+`FS! U}/-}Js"u-Qfh9d{30Oz| uΏ/ڭ1 Ęw/p uÊL2曝ߏ8f)l-<傥K n޲m>?[o=D4g P9__{6mr"9kILxu. gZ'wpG,[ok r[G )|)3XAάNOu#yodQ/7 g{;B(W5VL%GP0weX}fl?;븻u;נIӐ 8cx7m.HRdRDj1zAʟnWi< Wz-A0H].J/>eNF2M9ڞ Ώ^|r9.(GЧ`78H48cdcXҽ6YfUEYʓ 0, -8$obHb0N6lR}b$ehH4- aڙ;9/Ǘ# (<F17r^5̒ý(CἛuG~~)oYyIB0$r4lM5zzPS?q9_U& 1EXFGi Zx)6#3[9mٱ6.p6]c%7Ua#/Dza( V\ij  -Idf$ߠ1ŭ+“ii!3ڮ-J:A!p$ oEDYݒ\u~v UPBF's18?a`Hɶbi/Fq<Ŧ"(Z%! 㚼=2ZnEKCJ0y{hkms?dBG811!+emնuE>q:.X}5z¥@1STJA˞Z\CoHTYٗyn yJH*A^t_c!-_!(uWms,2o8v~Ɔi{x7MY chiG.Oq~D^ziALOU|;,}QsO1NyO6ۈ)oX6>3=3d$iMǰ .&Ӿ#PpÀa@۴ŀץH5$?Ov:M O+n̜ :n8ר%3[{Ljy ΙM铞^Z-v7!dHhNdʙ|[]*DdrVF45X*s;7@ KFl1eUQ]RF1Ԅӡ,kg!UFök d05dINlmEoǍ2DSw~2WD> AO[2PpD}O֚r%sIWt en 2WH)>gUA':,NUA."g|tV Uo3f ۆ70~(IM++f2Ka#Ti#'M].HuӇxý$mt8QJF̣ʓ4+V@â4vOry̦56Kp3gõerwVt?P1C3 F7yA>!?bʘ+d\ƕlQ9vA ^zYK1T|x߬%([VLEh P˚(̰C$ƏM/[/a; 3^GH6Hq qbwoE=&& _m*•")WHUDܹ87`K'6iOX&=+:Okw\)J;w^zv1xɎ*i67iAuJca\C]iZwA=  Q g&^W4dw`0aʌ*FĒa cr0g; ؇K\e~}=irFUjs9 o8qȷ|\JUwJP-b?Âf卵ߌ6x(Hh[Z[ԇbt~fS↢4 4?0>jZM1 ɶ~BP")wOf)aze. i3ChԣxJ=|^:S% RYxFļtӞJKўbI6CjW<5v"*T R8FX8)+8&O:Cyz" Ї( xͯX/OwEf ] $ 6QZrg[TQK[ <̠NIrsnTXw!&tW~5GՄCo=h}ӢmA7>JMD9܄Gʍ`z]n422 19vg"s;w5e#\U̇O5ܡ蛓Z_DPvN-^:Ķ+iCeFHo?I0Th;qk7f`-b՝Vx0PQC%n姓o}]Yӽ9<vZ&hnsVshE6'>`?OMj%dתV6fN_T63pR]$=ݬGj]!T؟v/43Nߏ:k*lJGG6bFF?o2L[{pιK<iLx6"3"ޑ&_U#0`G ̿lA]&\4+{FpO%$ΣҸ$*ܖyT@uO Ճ\}y=8Jn߬?3k7 ,aŗEjV>>5ö@\Qϙm8ٰ8VW\9:nC`R]jwOR4ѷxyulUIob/ 3 v H|,tE˙$sU_h'$ȤN-K#ԉc`sޒ:_+g+2 ABƆV]O=2|I} S; ֧f!H6!n]w_#)v42OrÉ@xT^I!Gt9)V6*X"KwfIAlX#P_/ăIXUb3-ѣjh:[PIX-{nsZ4NA /$ה `=z72XDr~ĻKLdI^WofWH=UmuÂcmg?Ig+{|800/:f-$m PRq%Kjwy__dGĶ!twyo#47}0 #DcmZsv qK!u^;%Oၣk#xבKo˨έ=j @L/ >1F$-l~ǮO;$v'"),o<;KN"-Ӻ( RV Oc[yo0(f'"B؄02A[,U-c-%!E{ֆuLʯ{<̗l3ˤM 7UT=Н.#_f<`*Y ^0!צ¼kW\%TAw& \)k!OtS)Pg(^C{zfXJ:B3啴D-U eq%sJNUnBP y}'u5&Ńٗ@QJwXۤ)?_`xȕO: ul}! 5|!=02PPCx2;%y5uAlqсɪGVWY8n… "l2.[ǻXF }'ሉxKܞw2֙ LqA12"6FSrl5v{s42\;-xsQԸi<3֫Ͻ"OJN 7jT!xtT?fqc WrRZqEQ]u)z\vΓ6dSaQ'D+QF)M3NJV΋#-X#2Vfހu~7|ϏFԇUZ>Ǩ!HnkL44a3ҙdlj cHT`l!-Ubfo9^b u~em̹99}s̹U ("XL.uc.#~NЛm_&VAӼ#ϰO,$G`ouYd J :?n8JRs>]4'4@\Fֈ/meO@ouIhjUft6NqGPɖaPU\[LMΊ'm>}K$D5i ? +\Y;Coޓ _H?IvAv#nFu$6,:LElʁXw-X$ ߲]QNDR,gOdoarGʺk6 %gy*ʄPfԊ3;矅ָ'KG!oz|Ԯn :ĥ8)"|VGifB|v*7d=<KI5L!@1aQc7fƣ'Q4PtԌ"h8n5LMW\fd]~GRPu[Z=b$'~:ڈX09x.lB+P)8=p >NVjhbHn5"҉,֛j|Ď1]iofGl7p{ErB{Z'*18uȅIu.Zg.iJ"gq;\ۏڬ,OBTw^մDREDA%Π!sश#*fLcD}8`x7j8}FâZǁpS.ءyh`((vWJb]ULAwW-P:K+Rdށ"ḓRrVĔq ;gjWm \.w-O:0T.lEr_&}Y!^ Wʉ*dK7į  =|ξAlYA=?/cݾ/W'Xc*[p9액kS4\֮YUN^L C}Eմ!tJbaYG ĩpolUdI)/1WqLYW s l s^tz&) Dg16\4ʛ[X&$\4UgqD& Jޥ 7t0djl$% C|,OċRY=VLIY-NWD.WZ,Qq<K P,]gjslBL^!}ՔhaH*~cP([f:,(MQǷͩgSH{@*i:e M8IE`?O|ӄwve-VUsѣ,Q$@V3Wl)$cN:L}|ɤ( \Pݜzb_y Ri[f4%IEG(m N&~\xeI- /PCZ.7e&¿}rLwfr ,jih|cUJHW)(d1 Y b8)-,!a1\5iS>GOɤ/݅f,5mu7fƲL 11[[9zut4=/̥}qjFnP"Y؆ty%WKǢW Uylts[3roW12YWh}|yI&.pOѝpL@),BI`.uJ@_4N2GAE^;6SCx's4 J-ØI;1΂9Ȋ".YbSX>8;WYJ=49`lmuWLGb7Jrab4^!'U4W-() RWV'm[_RZS᧷148r+5۠.JB6JYxV4t/HV>_I0F=Z﷐Ƨ~> E6sxz<^tWFˆ#R`dYaa;9k#r.VV+zN҈Jz@,k3\&EVLRtpTB76adStޘt1 4r]$7%|ELU[>+>&i -eXvkQ'2?J:Vr|Os=?J3C/Z0,.&c?)UEB|S΁X`4g aNi.'ׂ-t6ZfVI_xgE 66Jg،Oqtssbw:)z{@S4(B";GQUrh8O3ïdUBh!cAidU6ϫ⬤^29I @ K-l$fcMYۃ XJoqg F IM 7W] WfywXw fʜb!,,1Y|훡cjpVr 71Q#݇S5Re"60s)1<6/5% f)/ Gi- ~|lR}Ho u D1_Rl`9_[?%H*8 O0" eBԩжYn?LԐ*|TTeŇ' GnfU:Ђ}wdT~6z}GiO YcJVK8Qu+uFm`Hٗ_R}mЬ5zk>6Sp=B{^ ^@@s?.w24$S쿸];}Ina  J\4HSmr &v Δx23"Lj<Ր-:_=z24:Z|8y:v= &}p @Y mV"lmʍ/>H=m<AMZuAэ@Y"'Ńz'l}6A|LBȍC~~lm3aBaR=y)Qcs$eɇN߸G+pIw$&ӦxUe:zfC R {D#4~=&, lcO xS?{oZmDt唳E N)REuzw顟-4t55zS]=]!'LW0({j0g!f?]ܑRSJfMCoP”// N D:k.֮Tqz5(s;;-iCC&!+sȬ bL%QSHhOqeDwa낀ȉSX]Uqȓ-=M+Ӂk#.QOײw_jXc!]%N=JD G⼶]C+֋$(D-)T y?H8_" m+& \eR ISx̅T n7fF>6?WHݺ /-eYmx1H,WzLf߫YjIͺ@1SDA9 ?ɧe}m[v^O.V+\ɲ  tqYTq &(TM't̆$\O%^0.x!׼]-T"5O4#VH"LV`ޝFklTIi66M.齛=t:KoTY~=mQ | cvuBkwzv̓NYϺm޺ &ӢwVz M^CQ@[oOMwٸkF~e(UcBV44)b|uU.S)ͮ kOxZLJ-S*L>T?Q9}PH{ So(?^V͌#9 QB]5yw1*hL WG؋Z{X댮7;&*V3_;d3X x l9(&K `S"OZޚ\N|[OۧQ8MG>^@Ul@')|BpZ~t _$QT DH=hb*} PfʊT_cnEYn8ѰLu?<0Tu.L<:-t2+s5 -4@7m 2?>)= rd7ӽP@xvE9fvI7ڇݍgϦgy*¨}xl3 !aؓٙ 9rksVpҕ/煙~PITf= yj$β(?pS%*vjOu[ʷ>@d ;@sƟEl}{I16A0Y>2Dwixi$@`)pfq+e]U<$aft=hh-vIZ,A]  4E[ִzS=>0/a>+1ɶI3ayCKz1}eT:V&#9#bASu1hAAr:xS+'^#^n5ZBu #A4yJ ] <=F`w{s }P"{iCBV .j^$B6$Z+ dJaq 2Lq5@grA IS~;'lP"\`PDE´ARґqrJ7}% lֆMAVZDuCwYbZaw|wGUaPNɥwk2tb:8 p'ReN+[;K MМsU׵5os˅^φ`W+&k>z4yQ_d0̱Zno6迣U\X( $e v>Ͷ"t\]8f;j\^"iӬsC$o <]=r)Td:ש3K%A[@ƨC]OjHL͌CUq4ot:# &"&"_2oo":&p.H5(8_J} aAMcEkXK->d&c#?w BL-[3O?2g']G>rOt`DGqB𛷊>75 Ձ Z Lm(m;-gRv; *h7>?o$gF}J+O!Y10- $WG'ZB8?;&zC9`lJT"=k9zJm!V5J@um:PSrP.X kx/yYK4,Ϡօo=LshIwNpTtJ [(}P0%~u1vʗ"-[ AVo~NI#5@yz^'f oSTvQ؉H05StBr[68-/5(YKIt-]7\CD4C wؖE,FsR6J9' "FUOs:Z!FUzm[?5=gߢQ tLdPoqU5)ft :,ȟwŃKHAœe u 7!:e7!mܪŒg[M.eQ]HaZiCl|aA/z:ŕ#ɖ:"sC[,p9eX\׍ˏF}V5@o#mh"^rF)Z#T #y)hb?ъiv%$GjlJͱ'xôPS7U;oZ2pc,W\< &d`aS;US1LCe3&x1ok@wJ,_`Iv [<å+Z-|KI$Ӝ1[`5L3+X !b;ILU%>or'N$<"^ٶ9 Myz:XAؤ_;tRRy2g*s+F;%ʄyi̦6şZTd~Wej|MA}_ngrIg\R[bT%fCRN|M8n9Uu )t^M+wp^ Ck/@፥XfaBX8!PHX疐7ދӹ!fBNdF%_on"icT9޷K)+׽GzDže4jN'/p\+>\*,|G*vY 9|";ɹAGw1hA%!8J{m?2<$wU|DKdzZv@?a+%Ct\+oz{\<F o2H-MaN]񈎉,(/kM1|z-\W^?>Zeδ3 b{şY.IW5 8+6LIbŐ;yԞ!yl xDƋ;8wix3ubmjċ ..ƩU8˔ҏ\\lqN ^httu\:dR>h'7蟨Th _?䈎_Eׇ0ph2"Оџ"[Ixk x,ZP*lI4׃公/DNfAxc|e3W80/ n=SsyH_?fC' htgzu@=ƙzWQҺh!\وI?uVz^x&t;.'x 욠k7kTƬ/U ۤ3Q>sZ,̌D"_Wghene &`[-f t#n# Jweh>YJPbM}{l`gq+x1l-`BC0^%u!26qJ͕]0wtHxKyg_tX h8ROUm'0?Ȉ!UY889ˣ^#7<<-Ya? @5=Xn7ٳv]v'@=OE%*I1ζ`J`J uWfR_/ y7Wgҫ~OshtpvxKv9O$'Fu3vLSs \}D?bw6܊zT:l?5Fr3 kXP GZz' (\^{0%H0EK7kaO``Q#7d/b*GKrpuγyx:mi+B{ cYtO=uM7b3Wn%xW:h'rw::pbzkC>y!nΥW0ࡔ-G0,Tpl_'%qp("yqN&[Iٕϥ Ҕ#*Ip`QdrKTdIZ9''hٛ*$ӌEY|db`~K-8!$0n!Qv7S_?j8=}HCjN@0J]-ǦWUr 'ʘ2Ffq#g;LOft̐k5Ef."ls5Nd};(;fZ( e}N&M-ghп0ů JIP,[D yRaf5OkD@! RUi[Nxړi՚ae-8':R|Fopy}F/n{j\U\K(5S?,@`;o31laU[oCqΈbn#"rŌR' q$I `_2KꝘaXŢ1v"ТZعSWd7U5vhKhu02DaXIfDA( $sb%yT?z`mh2ei'2)fbdvj7)df}L7xu]#j^19dREx|)_<)K\k75xseRT}HVNqwI精4D ])߬S&-6";\\k2wb z=p2a~漠7ǸIelZ??@M᥋>bѥ4;l=3UWGV4AtqSHãtv-vC*]@ ԫ#N12<5n0]˧}-clhο0ZF$>3^5;>U]q,W/UMm`)Em gxiQ.f?MüfX`(N {K6lSè MNlA $ݛ57@,w9z:+_w^9.Use׬X厀P9im c `zBbώr%!^X 50V/l k0_OǦ x2gИS$aQ0I =Vɶ=`a&}/*QGEo^DvuSJ]7;ж 9;IZ~:J @yoD*Wp sW^\0sʩd8}VN<{<.Ik&IVgտƼCV?w9.C qEen6q!%W΃ QI#h&9$o r1$̗XlV;XwLM学]evWoMx*<}S}+Q3B]#3IϽbq//4}#:hVU%MHbd^߷|1:G_'r 42/sʁޜBW-VH?yr7I Ǝ3ڙXbd1a:kicR n&HT  ,aߩ6؀]Js,*ػ#<.I29_;(ˠs(5wvG~$rA} fcz;*lhG/4d{UT,ɞͨBi<76UR~dXH1XVz%I۰k~T-V-|9>R7I~wF7[ آksDeحZ39qYQuD'TаQL(4J8RE@̈́rh~ -:k}ߋx\U[وF4^"δS jP(} [dtRꅦbB21ذۦC^tQiKupޠ]>B$@ jĒP9k 3pT!%u;E$0&*b}L4{`KLyPJ` BNP9V?;ǵ;Xoi*a< D81n_US[%. *ih^b@s %-sXy 2^g;bKMc>%k^ qQl埜_ghEy3|otql@3t7DH|ZUiD7Y!H1ZIq;oTT)IV^ X".ٍ w/0cM0_Ӝr"<d@6g jHJkg/5]+<.|_‘7* } unW\PIl\][.p^܁#[ZE7 `1!<"1#HAf7|7{b>=)Uw^#z] f^'I㦕}Y/ ]aءZMڧgl5(EHo,}>\Pȁ |Yp C"8%hdnE<`!Jg^SjaRDmxDnE S &%rm[i}ۭۅ"'rc7s-1`f.Bx)|[Z&V{e+w[z\z0;X25as?J5#›)[ǕR:- k9lt{P<_Yen酲awKM8Aڛs!Z ` c{iSu+eͿ%h$V Vٍ=IJOyT߂i5vX_XX~M?S_O@u$q&\KV1ci:r/Bh'/@m;pcM9!%F;vxQ.~ []Ƈ aztcub! Eg/uHɉt߾y#H=8uhd]fx]K֑Cd0.Gσ W'mٲy[l yedh=K$Q??& 7xb]/}] z&vbNeph'2HvzDHViq8pZ㩶4Z=Zv=_ZȨ6~:&CW2W84@&?̫"L4OO(OpTylH?K5<(v}C_oN񉊙VqX#p*J:F4j/lSR4/B* l &w .H@˅0*y's3D(ӋJ2j/RT+9i3^wmO`J.R3Ty2=sY@zxvbrU18uYoCأ6lm{"Ǝaiv9:%uPWKD6El}&*s ܁^7?Z>#r2XP@e?޽y)h嬂NA ^ ^xO<m+G = 0q,yma%:Qa  FD\}/4fHCFYr{gބ<j}[OyBJnQm ;`ђ(TXkαc" Z%pȧŅf^MUкp󟚎*uJdo庳hb Ax(DJS ]F|,P|kp歷i,}c%%$R65xuY?5=K &Lh妜L 0i]*?" vˤ4 =^td յ伮ط#zF 8 w[ǨuA HIvm<3.MU>\fuzE9H*Ȼ2/wK' *% dUE Ga$`3_zg\8iˁ -[,vK,2A`Vq) &ғC l<ӻhڡs0O6`s+hߣ(? "\Btzty>_e-+lod1LŞG5䕟*Ոv~\3 8&aW~%j~p\hw {on{XҾ:]=y:3%ynz'{,vǞ|<]uxM28pMD qSHzOSXFVCADY<=ĢUrPEKM\T竂'vaIܹyP;l=МT[?)Qa$ݦfhbD 6_@淤,{"#nȺlbq=rY 풉2YV>΍ѵT]!}m 4i4#/5 % (k]P OmːuL$M?sڨ'P.Oy+o,*[O̞5r[A#\כ!` Tuo40?Yp^buOzy8,Gy˗_RMnw>(}_'M _wM.wvծJTKRt 6p '4䨞ӋyRrlHLI_25&{p(&"OzwƆe$WBeYee0fNx^+_1!P\W/\\W"6Fߵ#G`8!gX3XQ-ys>Z:bhj" \z9tWU낇 `=SSfJaE 2]#GFB4f(/y9cvJ<:jX#+VRY u@kh1m5&h=?{5yj+ӝlhĞv>nӶ)]N{piZavqP֌PПITژ =ߐ%$[2"={fw?Ah~QK{*5@FzR2謒}5B9*xl `G3< >ݍ,Bg;ۨ>0W|Uk#7š[l5?zY~d7HU"ՖƖ 5ʼvڵ)MziX JS7JPGdO)F'/1 YS0O6jG"2\W*<+*zP)#HձBf(%Y^AZ%H2gah^"zl/9`{!!Іs A;3M騂A:n#/bGoK5\ Tx[BWi {S Ùgub4OУYs5ܡd #' ^MAuw) i(CC"I, Vc``g} ,Y+۰}SFd1ޛ-3aLh4y|&BlSQ_2f΄D=CpMx$dl(̅s!LJG)۹AJN"5;D A!stOӮL9z`m0H-׻SA:Puyc (LviXǙ֜D椁 @hG/Iea޿t p4MJ77m{N.KKdk_Du-fn;+`]#a @Ӏ C4ӭF~F׆A9\xz 'DKs79;TvR٠yXޥw>cP HT^~,- byQ"FWJŧ4@_3O\!*-T0 B'^ΌZou!aIWP~J[1 >o"DM EGb7 "lW#wg%OYٜZ~HlƙԼ.Y]LKꖶ?8ؐ?ٰngx 3$8כؐ4A.翐&Om,-l`Z$=~]HHH-< 9=:;&Ԃ%~V E.'T?w޽w vv7w*X, DC=>ZKTǂp4.obn k8/~Z+@Ck/{q*a0W(bpd8]}'yفwz@vVBaň~sZ3QoeaN2j/U];StO;{0[U[I氏ojD;ܒ4x}m 5~I1a0‡`mV Ҍ8`IRC<-M[9ऑZeV&1w/,v0#%ȵXl/ sbڶwJova.}ϟ.]]+dcb.$M[{Lx }0aA6!aju2sqޕ`iW,["ObdJYaĒh;l!"S\g0[d`1hưyD( ނ򧬎l =JnC ԹqvU # 3k*mjA{&=O?Ȫ AYFjS;?S޾0J,5|^{hF6kfc.{@AOXP FHϞ8W;mԆŹ*ZkPtI?+Bp78HyTeeZ=I$I7 Ur%;ZxUKiPU\ jfK(/59Ux5އ McjVirDs^,-GQN1Dp$.Z֬?.wU_iGlt iAݍ ~UչŻKS \3lrmIܼ^8ªvM O,B3ځ460TmK!)cSk+4'!7_rw LN6yR(VNzx`#2J&0u2 BYb%FO3Wibu8cwƃ6Sk.r޾|Lb:=>S̥8_{M]'Y]w oMXsqlJ0Y7t)# }'l^PO|@adLf),Gs[Mk1XÊXu>__Ht:ܮg` =3}ѥUp>֣X2uUn+,r;zFrj``B"nDiem{SDgq'BT ^ez@Cx]|ߛ^~{%Is;:8 Ғ슕-2.D~_}iJ 7~:#aVz&b|URXn{jQhfu3oΌU@Q~=XI ;yhh)>Eϵ~~1}mCzWs"Ώ4H،ϩOs+6:vʈmBcKfzzyfQBRduaBչAmn4􂿜*GKsXp=t,O5_*e!504^47.tēNF/aK]\_f۬ G~TM@ )/-9e5)p2@(ӆuHAE9}n5TV9\.[6r$'M'^ow,{XYunxQf. Jw܌W#C^ϼHz^wzbP#bD)\7m/D6el:O ./}[mb##d|Ϲd{9-_ؖV;A{v-]W$S0^vrƃ, 9l%ǜCИϷr[yW[@.Ol G$", OZNP:5x^p-.383*L-P _ €r@SBzav΍פּ RASڶ)I}?:-<Ա b>"ٻ(H nQțu$CPmJ4E&vcC}Vs Kl8XmKe^^ļٔ P?!6Zŕ[$rǐ( Gh=:s HW<ͺL^3n5pRg28J+ .F&%~(a>@%.۠HՇNVT,ݹas'*=57^|FM t=U&?{6 *lL/٦2p CS =k LWZvQE:7_rOj$*ģȺٔL=({rVpqER, R Ot] U@{@Noׯ4ĻImְѐZV,Iz;WQ][e>Ҁ[t@1og>,Pƻ6^~T1*X?<+IE05Ǻ`3Iw1;yuVhAҥC>\GM *qP 7:6IKC>TaP f9¹B1M!#3  Zi#E5w10uNK`0Yo4y[ /blÆ1Cpd7^~}CS ܐIe_EYd-:&*Y+$턔Չ`jG 3]s[D4 D->߶9X hоo$N4֬j62&9$``4{M]2m0=V@c:Kγn<&08Ȯ4O_T3WW,oiP`wAK~#1Y?@ K ??aqtZcPxr|2G5XRy'hg –K/v8*2L?39L⻻`p ;tX@@Y'Vbۗzg= n2Ұex&ͅaW37 LS~?c]Zz-7%&צl9g 62c=M:9:/+.e]hemY)тdEkOh0iʷi!OfbW J<+GAN0!k6\o)䱯`ބg+~pusbW|ɢj iV_ :r 8YK_KIKނ>@퉆 {b":%=MTjaRl/~jOV3)##Pɡ+ONMS -GF*le9Ƭ ~jٸnB߻` srLOzdABV>5!M< ōdߝ?ww#Xvur$/̞Eabr{ՉVv뫪҄[nKh ,֋̈V{PmD{QT(RT@7 >,q$sXl,hK(V$`%L*WI(g]&u=H+CXfve؉UVh^way9܂}p’9koakHd!5}w"nصv\#{@bu XLC,`ȳ P4wrqlN4=ʯN-٣Ru)()0#MGja2HhWkD5rn.$<<%N+/:G(h}m8vIo#[ 9QK̓'j&ZQ.Yh.m ְSBts$2Jx#vz⸼qW)ʠW{Ш⬽z/jr( 5tQB _9Wi)]oS Z~>