nss-devel-3.28.4-1.0.el7_3$>ocU2&8H?8d   Q CIP4 4 4 4 4 4 4444   (@8HJ9pJ:XJG4H4IԠ4XY\ 4]4^׼bdeflt 4u4vڬwۀ4xP4y 4Cnss-devel3.28.41.0.el7_3Development libraries for Network Security ServicesHeader and Library files for doing development with Network Security Services.Xƃc1bm.rdu2.centos.org CICentOSMPLv2.0CentOS BuildSystem Development/Librarieshttp://www.mozilla.org/projects/security/pki/nss/linuxi686  YRCyQ@V`VpV'~@U6@U6@UAU@UUUݪ@UUȒ@UU@U'U3@UUx&Ux&Uq@U?v@U8U0U-@U'@U:TTq@TTto@Td@T)IS@S@Sہ@S@SnS@RJ@RRUR۾@R۾@R@R@Rx@RΏ@RkR@R;RiR@Rz/@Rv:Rt@RrF@Ro@Ro@RnQRe@RW@RSR@QQQ@QKQ@QQW@Q'@Qq1QNQ9Q7/Q#@QQ @P!@PՠP @PqP@P@PAPXPd@Pd@PPP@PP5@PPnP;a@P(@P H@O;O;O@OiO@O@O}O~OiOYOX@OOdO&@O!@@OO@O@N>@N>@NNܲ@N`NؽNN@NuN;@Np@Nf @NA!@N*NpM@MWMc@MM@M@MMfH@M^_@MZjMS@MQ0@MQ0@MQ0@MQ0@MK@MGMF@M6@M-MM@Ls@LOLLZ@L6LdL@L*@L@LA@LL@L4Lx@Lx@Li(@Lf@L_L_LT@L0L0L K @KsKsKKCKCKCK]KMKLd@KD{@K<@K5K4@K,@K+nK*@K K@K@K@KJݦ@J - 3.28.4-1.0Daiki Ueno - 3.28.2-1.6Daiki Ueno - 3.28.2-1.5Daiki Ueno - 3.28.2-1.4Daiki Ueno - 3.28.2-1.3Daiki Ueno - 3.28.2-1.2Daiki Ueno - 3.28.2-1.1Daiki Ueno - 3.28.2-1.0Kai Engert - 3.21.3-2Kai Engert - 3.21.3-1.1Daiki Ueno - 3.21.3-1Kai Engert - 3.21.0-17Kai Engert - 3.21.0-16Kai Engert - 3.21.0-15Kai Engert - 3.21.0-14Elio Maldonado - 3.21.0-13Elio Maldonado - 3.21.0-12Elio Maldonado - 3.21.0-11Elio Maldonado - 3.21.0-10Kai Engert - 3.21.0-9Kai Engert - 3.21.0-8Elio Maldonado - 3.21.0-7Kai Engert - 3.21.0-6Kai Engert - 3.21.0-5Elio Maldonado - 3.21.0-2Elio Maldonado - 3.21.0-1Elio Maldonado - 3.19.1-19Kai Engert - 3.19.1-18Elio Maldonado - 3.19.1-17Elio Maldonado - 3.19.1-16Elio Maldonado - 3.19.1-15Elio Maldonado - 3.19.1-14Elio Maldonado - 3.19.1-13Elio Maldonado - 3.19.1-12Elio Maldonado - 3.19.1-11Elio Maldonado - 3.19.1-10Elio Maldonado - 3.19.1-9Elio Maldonado - 3.19.1-8Elio Maldonado - 3.19.1-7Elio Maldonado - 3.19.1-6Kai Engert - 3.19.1-5Elio Maldonado - 3.19.1-4Elio Maldonado - 3.19.1-3Elio Maldonado - 3.19.1-2Elio Maldonado - 3.19.1-1Kai Engert - 3.18.0-6Kai Engert - 3.18.0-5Elio Maldonado - 3.18.0-4Elio Maldonado - 3.18.0-3Elio Maldonado - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.16.2.3-5Elio Maldonado - 3.16.2.3-4Elio Maldonado - 3.16.2.3-3Elio Maldonado - 3.16.2.3-2Elio Maldonado - 3.16.2-10Elio Maldonado - 3.16.2-9Elio Maldonado - 3.16.2-4Elio Maldonado 3.16.2-3Elio Maldonado - 3.16.2-2Elio Maldonado - 3.16.2-1Elio Maldonado - 3.15.4-6Elio Maldonado - 3.15.4-5Elio Maldonado - 3.15.4-4Elio Maldonado - 3.15.4-3Daniel Mach - 3.15.4-2Elio Maldonado - 3.15.3-9Elio Maldonado - 3.15.3-8Elio Maldonado - 3.15.3-7Elio Maldonado - 3.15.3-6Elio Maldonado - 3.15.3-5Elio Maldonado - 3.15.3-4Daniel Mach - 3.15.3-3Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.2-10Elio Maldonado - 3.15.2-9Elio Maldonado - 3.15.2-8Elio Maldonado - 3.15.2-7Elio Maldonado - 3.15.2-6Elio Maldonado - 3.15.2-5Elio Maldonado - 3.15.2-4Elio Maldonado - 3.15.2-3Elio Maldonado - 3.15.2-2Elio Maldonado - 3.15.2-1Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15-6Elio Maldonado - 3.15-5emaldona - 3.15-4emaldona - 3.15-3Elio Maldonado - 3.15-2Elio Maldonado - 3.15-1Elio Maldonado - 3.14.3-13.0Kai Engert - 3.14.3-12.0Kai Engert - 3.14.3-11Kai Engert - 3.14.3-10Kai Engert - 3.14.3-9Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.2-2Elio Maldonado - 3.14.2-1Kai Engert - 3.14.1-3Elio Maldonado - 3.14.1-2Elio Maldonado - 3.14.1-1Elio Maldonado - 3.14-12Elio Maldonado - 3.14-11Elio Maldonado - 3.14-10Elio Maldonado - 3.14-9Elio Maldonado - 3.14-8Elio Maldonado - 3.14-7Elio Maldonado - 3.14-6Elio Maldonado - 3.14-5Elio Maldonado - 3.14-4Elio Maldonado - 3.14-3Elio Maldonado - 3.14-2Elio Maldonado - 3.14-1Elio Maldonado - 3.14-0.1.rc.1Kai Engert - 3.13.6-1Elio Maldonado - 3.13.5-8Elio Maldonado - 3.13.5-7Fedora Release Engineering - 3.13.5-6Elio Maldonado - 3.13.5-5Elio Maldonado - 3.13.5-4Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.4-3Elio Maldonado - 3.13.4-2Elio Maldonado - 3.13.4-1Elio Maldonado - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Tom Callaway - 3.13.1-13Elio Maldonado - 3.13.1-12Fedora Release Engineering - 3.13.1-11Elio Maldonado - 3.13.1-11Elio Maldonado - 3.13.1-10elio maldonado - 3.13.1-9Elio Maldonado - 3.13.1-8Elio Maldonado - 3.13.1-7Elio Maldonado - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado Batiz - 3.13.1-4Elio Maldonado - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.13-1Elio Maldonado - 3.13-0.1.rc0.1Elio Maldonado - 3.12.11-3Kai Engert - 3.12.11-2Elio Maldonado - 3.12.11-1Elio Maldonado - 3.12.10-6Michael Schwendt - 3.12.10-5Elio Maldonado - 3.12.10-4Dennis Gilmore - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.10-0.1.beta1Elio Maldonado - 3.12.9-15Elio Maldonado - 3.12.9-14Elio Maldonado - 3.12.9-13Elio Maldonado - 3.12.9-12Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado - 3.12.9-9Fedora Release Engineering - 3.12.9-8Elio Maldonado - 3.12.9-7Christopher Aillon - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.9-0.1.beta2Elio Maldonado - 3.12.8.99.2-1Elio Maldonado - 3.12.8.99.1-1Elio Maldonado - 3.12.8-9Elio Maldonado - 3.12.8-8Elio Maldonado - 3.12.8-7Elio Maldonado - 3.12.8-6Elio Maldonado - 3.12.8-5Elio Maldonado - 3.12.8-4Elio Maldonado - 3.12.8-3Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Elio Maldonado - 3.12.7.99.4-1Elio Maldonado - 3.12.7.99.3-2Elio Maldonado - 3.12.7.99.3-1Elio Maldonado - 3.12.7-3Elio Maldonado - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-12Elio Maldonado - 3.12.6-11Elio Maldonado - 3.12.6-10Elio Maldonado - 3.12.6-9Dennis Gilmore - 3.12.6-8Elio Maldonado - 3.12.6-7Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-5Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1.13.2Elio Maldonado - 3.12.5-1.13.1Elio Maldonado - 3.12.5-1.13Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.9Elio Maldonado - 3.12.5-2.7Elio Maldonado - 3.12.5-1.6Elio Maldonado - 3.12.5-1.5Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1.1Elio Maldonado - 3.12.5-1Elio Maldonado - 3.12.4-14.1Elio Maldonado - 3.12.4-13.1Elio Maldonado - 3.12.4-13Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Rebase to NSS 3.28.4- Restore ssl-server-min-key-sizes.patch - Disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256 by default - Enable 4 AES_256_GCM_SHA384 ciphersuites, enabled by the downstream patch in the previous release - Fix crash with tstclnt -W- Always enable gtests for supported features - Prevent ABI incompatibilty of SECKEYECPublicKey- Add patch to fix bash syntax error in tests/ssl.sh - Build with support for SSLKEYLOGFILE - Disable the use of RSA-PSS with SSL/TLS- Remove %nss_cycles setting, which was also mistakenly added- Reorder cipher suites for compatibility - Re-enable BUILD_OPT, mistakenly disabled in the previous build- Remove mistakenly added R: nss-pem- Rebase to NSS 3.28.2 - Remove NSS_ENABLE_ECC and NSS_ECC_MORE_THAN_SUITE_B setting, which is no-op now - Enable gtests when requested - Remove nss-646045.patch and fix-nss-test-filtering.patch, which are not necessary - Remove sslauth-no-v2.patch and nss-sslstress-txt-ssl3-lower-value-in-range.patch, as SSLv2 is already disabled in upstream - Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits - Remove local patches for SHA384 cipher suites (now supported in upstream): dhe-sha384-dss-support.patch, client_auth_for_sha384_prf_support.patch, nss-fix-client-auth-init-hashes.patch, nss-map-oid-to-hashalg.patch, nss-enable-384-cipher-tests.patch, nss-fix-signature-and-hash.patch, fix-allowed-sig-alg.patch, tests-extra.patch - Remove upstreamed patches: rh1238290.patch, fix-reuse-of-session-cache-entry.patch, flexible-certverify.patch, call-restartmodules-in-nssinit.patch- Mozilla #1314604 / Red Hat CVE-2016-8635- rebuild- Rebase to NSS 3.21.3 - Resolves: #1383887- remove additional false duplicates from sha384 downstream patches- enable ssl_gtests (without extended master secret tests), Bug 1298692 - call SECMOD_RestartModules in nss_Init, Bug 1317691- escape all percent characters in all changelog comments- Support TLS 1.2 certificate_verify hashes other than PRF, backported fix from NSS 3.25 (upstream bug 1179338).- Fix reuse of session cache entry - Resolves: Bug 1241172 - Certificate verification fails with multiple https urls- Fix a flaw in %check for nss not building on arm - Resolves: Bug 1200856- Cleanup: Remove unnecessary %posttrans script from nss.spec - Resolves: Bug 1174201- Merge fixes from the rhel-7.2 branch - Fix a bogus %changelog entry - Resolves: Bug 1297941- Rebuild to require the latest nss-util build and nss-softokn build.- Update the minimum nss-softokn build required at runtime.- Delete duplicates from one table- Fix missing support for sha384/dsa in certificate_request- Merge fixes from the rhel-7.2 branch - Fix the SigAlgs sent in certificate_request - Ensure all ssl.sh tests are executed - Update sslauth test patch to run additional tests- Fix sha384 support and testing patches- Rebase to NSS-3.21- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol - Fix a mockbuild reported bad %if condition when using the __isa_bits macro instead of list of 64-bit architectures - Change the test to %if 0%{__isa_bits} == 64 as required for building the srpm which is noarch - Resolves: Bug 1289884- Rebuild against updated NSPR- Change the required_softokn_build_version back to -13 - Ensure we use nss-softokn-3.16.2.3-13.el7_1- Fix check for public key size of DSA certificates - Use size of prime P not the size of dsa.publicValue- Reorder the cipher suites and enable two more by default- Update the required_softokn_build_version to -14 - Add references to bugs filed upstream for new patches - Merge ocsp stapling and sslauth sni tests patches into one- Reorder the cipher suites and enable two more by default - Fix some of the ssauth sni and ocsp stapling tests- Support TLS > 1.0 by support while still allowing to connect to SSL3 only servers - Enable ECDSA cipher suites by default, a subset of the ones requested- Support TLS > 1.0 by support while still allowing to connect to SSL3 only servers- Fix to correctly report integrity mechanism for TLS_RSA_WITH_AES_256_GCM_SHA384- Fix checks to skip ssl2/export cipher suites tests to not skip needed tests - Fix libssl ssl2/export disabling patch to handle NULL cipher cases - Enable additional cipher suites by default- Add links to filed upstream bugs to better track patches in spec file- Package listsuites as part of the unsupported tools- Bump the release tag- Incremental patches to fix SSL/TLS test suite execution, fix the earlier SHA384 patch, and inform clients to use SHA384 with certificate_verify if required by NSS.- Add support for sha384 tls cipher suites - Add support for server-side hde key exchange - Add support for DSS+SHA256 ciphersuites- Reenable a patch that had been mistakenly disabled- Build against nss-softokn-3.16.2.3-9- Rebase to nss-3.19.1 - Resolves: Bug 1228913 - Rebase to nss-3.19.1 for CVE-2015-4000 [RHEL-7.1]- Backport mozbz#1155922 to support SHA512 signatures with TLS 1.2- Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1)- Update and reeneable nss-646045.patch on account of the rebase - Resolves: Bug 1200898 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Fix shell syntax error on nss/tests/all.sh - Resolves: Bug 1200898 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Replace expired PayPal test certificate that breaks the build - Resolves: Bug 1200898 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Resolves: Bug 1200898 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Reverse the sense of a test in patch to fix pk12util segfault - Resolves: Bug 1174527 - Segfault in pk12util when using -l option with certain .p12 files- Fix race condition - Resolves: Bug 1094468 - 389-ds-base server reported crash in stan_GetCERTCertificate - under the replication replay failure condition- Resolves: Bug 1174527 - Segfault in pk12util when using -l option with certain .p12 files- Restore patch for certutil man page - supply missing options descriptions - Resolves: Bug 1158161 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Resolves: Bug 1158161 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 - Support TLS_FALLBACK_SCSV in tstclnt and ssltap- Resolves: Bug 1145434 - CVE-2014-1568 - Using a release number higher than on rhel-7.0 branch- Fix crash in stan_GetCERTCertificate - Resolves: Bug 1094468- Generic 32/64 bit platform detection (fix ppc64le build) - Resolves: Bug 1125619 - nss fails to build on arch: ppc64le (missing dependencies) - Fix contributed by Peter Robinson - Fix libssl and test patches that disable ssl2 support - Resolves: Bug 1123435 - Replace expired PayPal test certificate with current one- Rebase to nss-3.16.2 - Resolves: Bug 1103252 - Rebase RHEL 7.1 to at least NSS 3.16.1 (FF 31) - Fix test failure detection in the %check section - Move removal of unwanted source directories to the end of the %prep section - Update various patches on account of the rebase - Remove unused patches rendered obsolete by the rebase- Disallow disabling the internal module - Resolves: Bug 1056036 - nss segfaults with opencryptoki module- Pick up a fix from rhel-6 and fix an rpm conflict - Don't hold issuer cert handles in crl cache - Resolves: Bug 1034409 - deadlock in trust domain and object lock - Move nss shared db files to the main package - Resolves: Bug 1050163 - Same files in two packages create rpm conflict- Update pem sources to latest from nss-pem upstream - Pick up pem module fixes verified on RHEL and applied upstream - Remove no loger needed pem patches on acccount on this update - Add comments documenting the iquote.patch - Resolves: Bug 1054457 - CVE-2013-1740- Remove spurious man5 wildcard entry as all manpages are listed by name - Resolves: Bug 1050163 - Same files in two packages create rpm conflict- Mass rebuild 2014-01-24- Rebase to nss-3.15.4 - Resolves: Bug 1054457 - CVE-2013-1740 nss: false start PR_Recv information disclosure security issue - Remove no longer needed patches for manpages that were applied upstream - Remove no longer needed patch to disable ocsp stapling tests - Update iquote.patch on account of upstream changes - Update and rename patch to pem/rsawrapr.c on account of upstream changes - Use the pristine upstream sources for nss without repackaging - Avoid unneeded manual step which may introduce errors- Fix the spec file to apply the nss ecc list patch for bug 752980 - Resolves: Bug 752980 - Support ECDSA algorithm in the nss package via puggable ecc- Move several nss-sysinit manpages tar archives to the %files - Resolves: Bug 1050163 - Same files in two packages create rpm conflict- Fix a coverity scan compile time warning for the pem module - Resolves: Bug 1002271 - NSS pem module should not require unique base file names- Resolves: Bug 1002271 - NSS pem module should not require unique base file names- Improve pluggable ECC support for ECDSA - Resolves: Bug 752980 - [7.0 FEAT] Support ECDSA algorithm in the nss package- Mass rebuild 2013-12-27- Revoke trust in one mis-issued anssi certificate - Resolves: Bug 1040284 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-7.0]- Update to NSS_3_15_3_RTM - Resolves: Bug 1031463 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Fix path to script and remove -- from some options in nss-sysinit man page - Resolves: rhbz#982723 - man page of nss-sysinit worong path and other flaws- Fix certutil man page options names to be consistent with help - Resolves: rhbz#948495 - man page scan results for nss - Remove incorrect count argument in status description in nss-sysinit man page - Resolves: rhbz#982723 - man page of nss-sysinit incorrect option descriptions- Fix patch for disabling ssl2 in ssl to correctly set error code - Fix syntax error reported in the build.log even tough it succeeds - Add patch top ignore setpolicy result - Resolves: rhbz#1001841 - Disable SSL2 and the export cipher suites - Resolves: rhbz#1026677 - Attempt to run ipa-client-install fails- Fix bash syntax error in patch for disabling ssl2 tests - Resolves: rhbz#1001841 - Disable SSL2 and the export cipher suites- Fix errors in ssl disabling patches for both library and tests - Add s390x to the multilib_arches definition used for alt_ckbi - Resolves: rhbz#1001841 - Disable SSL2 and the export cipher suites- Fix errors in nss-sysinit manpage options descriptions - Resolves: rhbz#982723- Enable fips when system is in fips mode - Resolves: rhbz#852023 - FIPS mode detection does not work- Remove unused and obsoleted patches - Related: rhbz#1012656- Add description of the certutil's --email option to it's manpage - Resolves: rhbz#Bug 948495 - Man page scan results for nss- Rebase to nss-3.15.2 - Resolves: rhbz#1012656 - pick up NSS 3.15.2 to fix CVE-2013-1739 and disable MD5 in OCSP/CRL- Install symlink to nss-sysinit.sh without the .sh suffix - Resolves: rhbz#982723 - nss-sysinit man page has wrong path for the script- Resolves: rhbz#1001841 - Disable SSL2 and the export cipher suites- Add upstream bug URL for a patch subitted upstream and remove obsolete script- Update to NSS_3_15_1_RTM - Apply various fixes to the man pages and add new ones - Enable the iquote.patch to access newly introduced types - Add man page for pkcs11.txt configuration file and cert and key databases - Add missing option descriptions for {cert|cms|crl}util - Resolves: rhbz#948495 - Man page scan results for nss - Resolves: rhbz#982723 - Fix path to script in man page for nss-sysinit- Use the unstripped source tar ball- Install man pages for nss-tools and the nss-config and setup-nsssysinit scripts - Resolves: rhbz#606020 - nss security tools lack man pages- Build nss without softoken or util sources in the tree - Resolves: rhbz#689918- Update ssl-cbc-random-iv-by-default.patch- Fix generation of NSS_VMAJOR, NSS_VMINOR, and NSS_VPATCH for nss-config- Update to NSS_3_15_RTM- Reactivate nss-ssl-cbc-random-iv-off-by-default.patch- Add upstream patch to fix rhbz#872761- Update expired test certificates (fixed in upstream bug 852781)- Fix incorrect post/postun scripts. Fix broken links in posttrans.- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement.- Update to NSS_3_14_3_RTM - sync up pem rsawrapr.c with softoken upstream changes for nss-3.14.3 - Resolves: rhbz#908257 - CVE-2013-1620 nss: TLS CBC padding timing attack - Resolves: rhbz#896651 - PEM module trashes private keys if login fails - Resolves: rhbz#909775 - specfile support for AArch64 - Resolves: rhbz#910584 - certutil -a does not produce ASCII output- Allow building nss against older system sqlite- Update to NSS_3_14_2_RTM- Update to NSS_3_14_1_WITH_CKBI_1_93_RTM- Require nspr >= 4.9.4 - Fix changelog invalid dates- Update to NSS_3_14_1_RTM- Bug 879978 - Install the nssck.api header template where mod_revocator can access it - Install nssck.api in /usr/includes/nss3/templates- Bug 879978 - Install the nssck.api header template in a place where mod_revocator can access it - Install nssck.api in /usr/includes/nss3- Bug 870864 - Add support in NSS for Secure Boot- Disable bypass code at build time and return failure on attempts to enable at runtime - Bug 806588 - Disable SSL PKCS #11 bypass at build time- Fix pk11wrap locking which fixes 'fedpkg new-sources' and 'fedpkg update' hangs - Bug 872124 - nss-3.14 breaks fedpkg new-sources - Fix should be considered preliminary since the patch may change upon upstream approval- Add a dummy source file for testing /preventing fedpkg breakage - Helps test the fedpkg new-sources and upload commands for breakage by nss updates - Related to Bug 872124 - nss 3.14 breaks fedpkg new-sources- Fix a previous unwanted merge from f18 - Update the SS_SSL_CBC_RANDOM_IV patch to match new sources while - Keeping the patch disabled while we are still in rawhide and - State in comment that patch is needed for both stable and beta branches - Update .gitignore to download only the new sources- Fix the spec file so sechash.h gets installed - Resolves: rhbz#871882 - missing header: sechash.h in nss 3.14- Update the license to MPLv2.0- Use only -f when removing unwanted headers- Add secmodt.h to the headers installed by nss-devel - nss-devel must install secmodt.h which moved from softoken to pk11wrap with nss-3.14- Update to NSS_3_14_RTM- Update to NSS_3_14_RC1 - update nss-589636.patch to apply to httpdserv - turn off ocsp tests for now - remove no longer needed patches - remove headers shipped by nss-util- Update to NSS_3_13_6_RTM- Rebase pem sources to fedora-hosted upstream to pick up two fixes from rhel-6.3 - Resolves: rhbz#847460 - Fix invalid read and free on invalid cert load - Resolves: rhbz#847462 - PEM module may attempt to free uninitialized pointer - Remove unneeded fix gcc 4.7 c++ issue in secmodt.h that actually undoes the upstream fix- Fix pluggable ecc support- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Fix checkin comment to prevent unwanted expansions of percents- Resolves: Bug 830410 - Missing Requires %{?_isa} - Use Requires: %{name}%{?_isa} = %{version}-%{release} on tools - Drop zlib requires which rpmlint reports as error E: explicit-lib-dependency zlib - Enable sha224 portion of powerup selftest when running test suites - Require nspr 4.9.1- Resolves: rhbz#833529 - revert unwanted change to nss.pc.in- Resolves: rhbz#833529 - Remove unwanted space from the Libs: line on nss.pc.in- Update to NSS_3_13_5_RTM- Resolves: Bug 812423 - nss_Init leaks memory, fix from RHEL 6.3- Resolves: Bug 805723 - Library needs partial RELRO support added - Patch coreconf/Linux.mk as done on RHEL 6.2- Update to NSS_3_13_4_RTM - Update the nss-pem source archive to the latest version - Remove no longer needed patches - Resolves: Bug 806043 - use pem files interchangeably in a single process - Resolves: Bug 806051 - PEM various flaws detected by Coverity - Resolves: Bug 806058 - PEM pem_CreateObject leaks memory given a non-existing file name- Resolves: Bug 805723 - Library needs partial RELRO support added- Cleanup of the spec file - Add references to the upstream bugs - Fix typo in Summary for sysinit- Pick up fixes from RHEL - Resolves: rhbz#800674 - Unable to contact LDAP Server during winsync - Resolves: rhbz#800682 - Qpid AMQP daemon fails to load after nss update - Resolves: rhbz#800676 - NSS workaround for freebl bug that causes openswan to drop connections- Update to NSS_3_13_3_RTM- fix issue with gcc 4.7 in secmodt.h and C++11 user-defined literals- Resolves: Bug 784672 - nss should protect against being called before nss_Init- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- Deactivate a patch currently meant for stable branches only- Resolves: Bug 770682 - nss update breaks pidgin-sipe connectivity - NSS_SSL_CBC_RANDOM_IV set to 0 by default and changed to 1 on user request- Revert to using current nss_softokn_version - Patch to deal with lack of sha224 is no longer needed- Resolves: Bug 754771 - [PEM] an unregistered callback causes a SIGSEGV- Resolves: Bug 750376 - nss 3.13 breaks sssd TLS - Fix how pem is built so that nss-3.13.x works with nss-softokn-3.12.y - Only patch blapitest for the lack of sha224 on system freebl - Completed the patch to make pem link against system freebl- Removed unwanted /usr/include/nss3 in front of the normal cflags include path - Removed unnecessary patch dealing with CERTDB_TERMINAL_RECORD, it's visible- Statically link the pem module against system freebl found in buildroot - Disabling sha224-related powerup selftest until we update softokn - Disable sha224 and pss tests which nss-softokn 3.12.x doesn't support- Rebuild with nss-softokn from 3.12 in the buildroot - Allows the pem module to statically link against 3.12.x freebl - Required for using nss-3.13.x with nss-softokn-3.12.y for a merge inrto rhel git repo - Build will be temprarily placed on buildroot override but not pushed in bodhi- Fix broken dependencies by updating the nss-util and nss-softokn versions- Update to NSS_3_13_1_RTM - Update builtin certs to those from NSSCKBI_1_88_RTM- Update to NSS_3_13_RTM- Update to NSS_3_13_RC0- Fix attempt to free initilized pointer (#717338) - Fix leak on pem_CreateObject when given non-existing file name (#734760) - Fix pem_Initialize to return CKR_CANT_LOCK on multi-treaded calls (#736410)- Update builtins certs to those from NSSCKBI_1_87_RTM- Update to NSS_3_12_11_RTM- Indicate the provenance of stripped source tarball (#688015)- Provide virtual -static package to meet guidelines (#609612).- Enable pluggable ecc support (#712556) - Disable the nssdb write-access-on-read-only-dir tests when user is root (#646045)- make the testsuite non fatal on arm arches- Fix crmf hard-coded maximum size for wrapped private keys (#703656)- Update to NSS_3_12_10_RTM- Update to NSS_3_12_10_BETA1- Implement PEM logging using NSPR's own (#695011)- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Short-term fix for ssl test suites hangs on ipv6 type connections (#539183)- Add a missing requires for pkcs11-devel (#675196)- Run the test suites in the check section (#677809)- Fix cms headers to not use c++ reserved words (#676036) - Reenabling Bug 499444 patches - Fix to swap internal key slot on fips mode switches- Revert patches for 499444 until all c++ reserved words are found and extirpated- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix cms header to not use c++ reserved word (#676036) - Reenable patches for bug 499444- Revert patches for 499444 as they use a C++ reserved word and cause compilation of Firefox to fail- Fix the earlier infinite recursion patch (#499444) - Remove a header that now nss-softokn-freebl-devel ships- Fix infinite recursion when encoding NSS enveloped/digested data (#499444)- Update the cacert trust patch per upstream review requests (#633043)- Fix to honor the user's cert trust preferences (#633043) - Remove obsoleted patch- Update to 3.12.9- Rebuilt according to fedora pre-release package naming guidelines- Update to NSS_3_12_9_BETA2 - Fix libpnsspem crash when cacert dir contains other directories (#642433)- Update to NSS_3_12_9_BETA1- Update pem source tar with fixes for 614532 and 596674 - Remove no longer needed patches- Update PayPalEE.cert test certificate which had expired- Tell rpm not to verify md5, size, and modtime of configurations file- Fix certificates trust order (#643134) - Apply nss-sysinit-userdb-first.patch last- Move triggerpostun -n nss-sysinit script ahead of the other ones (#639248)- Fix invalid %postun scriptlet (#639248)- Replace posttrans sysinit scriptlet with a triggerpostun one (#636787) - Fix and cleanup the setup-nsssysinit.sh script (#636792, #636801)- Add posttrans scriptlet (#636787)- Update to 3.12.8 - Prevent disabling of nss-sysinit on package upgrade (#636787) - Create pkcs11.txt with correct permissions regardless of umask (#636792) - Setup-nsssysinit.sh reports whether nss-sysinit is turned on or off (#636801) - Added provides pkcs11-devel-static to comply with packaging guidelines (#609612)- NSS 3.12.8 RC0- Fix nss-util_version and nss_softokn_version required to be 3.12.7.99.3- NSS 3.12.8 Beta3 - Fix unclosed comment in renegotiate-transitional.patch- Change BuildRequries to available version of nss-util-devel- Define NSS_USE_SYSTEM_SQLITE and remove unneeded patch - Add comments regarding an unversioned provides which triggers rpmlint warning - Build requires nss-softokn-devel >= 3.12.7- Update to 3.12.7- Apply the patches to fix rhbz#614532- Removed pem sourecs as they are in the cache- Add support for PKCS#8 encoded PEM RSA private key files (#614532)- Fix nsssysinit to return userdb ahead of systemdb (#603313)- Require and BuildRequire >= the listed version not =- Require nss-softoken 3.12.6- Fix SIGSEGV within CreateObject (#596674)- Update pem source tar to pick up the following bug fixes: - PEM - Allow collect objects to search through all objects - PEM - Make CopyObject return a new shallow copy - PEM - Fix memory leak in pem_mdCryptoOperationRSAPriv- Update the test cert in the setup phase- Add sed to sysinit requires as setup-nsssysinit.sh requires it (#576071) - Update PayPalEE test cert with unexpired one (#580207)- Fix ns.spec to not require nss-softokn (#575001)- rebuilt with all tests enabled- Using SSL_RENEGOTIATE_TRANSITIONAL as default while on transition period - Disabling ssl tests suites until bug 539183 is resolved- Update to 3.12.6 - Reactivate all tests - Patch tools to validate command line options arguments- Fix curl related regression and general patch code clean up- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- New version of patch to allow root to modify ystem database (#547860)- Temporarily disabling the ssl tests- Fix nsssysinit to allow root to modify the nss system database (#547860)- Fix an error introduced when adapting the patch for rhbz #546211- Remove left over trace statements from nsssysinit patching- Fix a misconstructed patch- Fix nsssysinit to enable apps to use system cert store, patch contributed by David Woodhouse (#546221) - Fix spec so sysinit requires coreutils for post install scriplet (#547067) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387)- Fix nsssysinit to set the default flags on the crypto module (#545779) - Remove redundant header from the pem module- Remove unneeded patch- Retagging to include missing patch- Update to 3.12.5 - Patch to allow ssl/tls clients to interoperate with servers that require renogiation- Retagging- Require nss-softoken of same architecture as nss (#527867) - Merge setup-nsssysinit.sh improvements from F-12 (#527051)- User no longer prompted for a password when listing keys an empty system db (#527048) - Fix setup-nsssysinit to handle more general formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build  !"#$%&'()*+,-./012343.28.4-1.0.el7_33.28.4-1.0.el7_33.28.4-1.0.el7_33.28.4nss-confignss3cert.hcertdb.hcertt.hcmmf.hcmmft.hcms.hcmsreclist.hcmst.hcrmf.hcrmft.hcryptohi.hcryptoht.hjar-ds.hjar.hjarfile.hkey.hkeyhi.hkeyt.hkeythi.hnss.hnssckbi.hnsspem.hocsp.hocspt.hp12.hp12plcy.hp12t.hpk11func.hpk11pqg.hpk11priv.hpk11pub.hpk11sdr.hpkcs12.hpkcs12t.hpkcs7t.hpreenc.hsechash.hsecmime.hsecmod.hsecmodt.hsecpkcs5.hsecpkcs7.hsmime.hssl.hsslerr.hsslproto.hsslt.hlibcrmf.anss.pcnss-config.1.gz/usr/bin//usr/include//usr/include/nss3//usr/lib//usr/lib/pkgconfig//usr/share/man/man1/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnuPOSIX shell script, ASCII text executabledirectoryC source, ASCII textASCII textcurrent ar archivepkgconfig filetroff or preprocessor input, ASCII text (gzip compressed data, from Unix, max compression)RPRRR?7zXZ !PH6Ნ]"k%nÍdڴ4Yk(`4T"^KcࣘGH @@)^hya Ȩܶ&{bv_ϳPu-4{3LZ4^0|zDX:[( i⊣-,-qlojrzX:=f|1Te)MzrOjQS@W9߲;퓲y+0v!ĶㆆqM3͂@<~JxlQ6!A,\:+T9gQhᕣւ ֩|Jr}Zl)Dj .k⤲/b%S#ajӑFUcܴ`ܜ|G:b[k8sHjN wЗp}FZPfɫ92IM΁8_v4=AXZ9jUIf 'Zї8dcߦcg{2 s+2gN A?V^?XB"KD涋g\jP^8O5m@"{cBϼ72Ixy>QsT> q8{7u 1GgX# x}a 9vpyT!C8#UK P NWlϥyzJrъEӐQ>5h7 kQ ,0x/Ikp2 .Zk70Xe J@X9GіˆL͹m^S~6!i6cAxiVrL33X|dq'>G\Ci^ b -e Բbz+lPa9ړZŒa>>zLG̪I* _vk dC oMCVC)DX )~ܥ^H|+;Oc1ԓz*ӯwUIP.=#_iq9f;ǁO`Z}$Ғ#7bFd|@/5tno XW #_VzI5~bU24LVFXqLǞpzA7 \b.j`[7"#NE:B P&J?l߅ \d3]]T+>i?zei-hQ[ɯٜcSBjP_oHCSj쮲a$gҵ/ODƴfi= M[ '@IGw͵ dly\~>O9IȾaŒ>i^4%x[--ߘ >] #c]2הuЦ^˖!oC/ŵ6XG;Vgv[\>7[os?Z&xF<|5&sd'4!f{^wHS Lk0J&&m\-ٝZ ,5̱٘aѺNݸꂾ-V֠ɱdV&E&9P%s: BVxxEh/ך?&7Q+ 4ٙ1՟[gP=4gة(7_;ߪMs3O&yvm-Լnb/ijQgRVNgPJo: \ 7,19D<5=Ex?d100jx#}Tu>}6FͮyS+f7⩭_dfx ~#Ӥ+ڇd%d.ApFsq@vQbSb*2|:Z=ڞ.SwsRdrf+\~{Z*V]FNͩ|.rBEeB G[;s~=o! \8=xh-rY@hC3OuG6Rϲ]8TilArAPt~:y8ЄbՊXsLnCnЋLbO:o~g| ]6pF:R-:-zQw%4mP(  w[j}RF2]*hȩ 39n *S]vXcƶ Žin@q3N.+Sg;ᛢX]-\'dA*c fmne8uWҾ"՚ > ̐a]ԁ߲匰Lh nǣv]/7bKcHqA%|i[vӀThYq8fE {޻g;[-[ PY\ 0TݓL${66z̺֋#QGu+׆w(r9n%'u``/&UM Q ~׳9CEr^M!zi]5e%ޓcM?:J{2Sі=s|~$ۭ!@/l0]oRTN[]0k%8 iAdž[F^m[,i%=/KG^EތV 5hFBP ڴW[jlDs^F*7kbKo 2m~Y!\؍)کOඍ VU9Qhy*>h %^xT$,?gZWmk W-ӏZh͔">xh歛-}^5HO^㛫0EB9lahf%Yzїp@n~tV~X263 bSMtqx<.G+V瀒8N;%{@Y ^Y3݈uyFc/aCeӺZNDotI@ӲI)b0ö[ T]u/SVh&cuuB%|j+١9xIF O&i*a&f>t3^!2kI2(pP-#oN7NjEi]>!Sm #9hicpum(9"|$7 [@K8_ۻ \C<-g ԝ'6ypP#6E&B,Vn.]qP<+cbRjU^;u|L~a[~ Z5ٺ8QgY%l mOzS< Rdv;Sƀkr.Bjvi$/=E<?|L!CIo뀈KvwjsgQkkWWr.E2U݋udŇ XG+CLJeu#ӌ&4ςK9 ׇ6~O(4/$sw7, M`x"*%n/VF %W F1R g%Ĭ9?Xi ƃl?~.G#ǹ`A\(vsoŬsbG5Nft|izdJ{L61 j/~)P&6-^lf`t`8]~mpoKeooӢQiS=A*S< [|$~},9 \y)& @#s#BO@n*ӗ{Py۰(P67V}zõqWg_ƣ##7٪R+ -,5W\t/zECdRx~. ХP;x)FUȚͺV,mvu{xm>^4o+`fewQAEVĘdZ9Nv| Y+Le:ɒ}X"¨DWA@=6nmvMAʱT}3&~++p^40 5*\`~,LbB1XfMA/I+ ɘ>Qb-v&2-TsV?w.Ft@XX.,FxKQa]X䎣Tݏ%}ᔰ5fnpB֌H;t 0INrt% [}i51%Py \e'}#w {EȲ{jMmZ"}5o NvhD5M~5{MsӝX QqM$+V (;c -68d^͍3|%ڤ) gUUwT #Sש ]aƚL`p^{:E-:P,Cvgh 4{g^:g{aOnG!R=_&$$;dkOcE6^Ӑ:XׄEf\0-qUӉ ~dxxb YUzQn)=[jP j!/ʸ#$}dv֓s݇y8K83,:-7?|v|+ =yz6=8/u)WsjyX.j#@** b1 U-)7q9C;j2,v<|/{KeT0&xi!0mca{9B0g]M >skG(gb=B R4꟠(p 4 Mӧ0-w<trqsQM`Rh$\[xᛱNOwC,w˪ɨVC%4nC]s2,39C8[pFWiyt ~+,3- "oo}/IX<6)%nd4weH&1 v-ر׾!P'!]`sY،>.澏 aNmsIu 7\;l4g)/u52 ۠uNVLǛD9.? "k R9QN-IO;tANOf3sJqeUAa#Vjϩ"˵k;>( jt_W].I5hbJ!ٯ́[ b wM[)CAgL;gFgp=(s] I[ZM h->y`L1I%3|R02?s?(ۗPIN`>HgJf؁B40$#Rn8lj|>@kL/`}'#D-:n-6CdbUW Eo+4XO=*Le㪯=>8ۡv&M4xgPpDu-C'lPjRw̛ }vo,x#4K|)z0b*}jRW1k%EO&9̀ o{!jj;n܅xr/]| ߏ ص8[bVVG8$dp?;ɛ)$Myt=[݃N_%ːvL}O\5%jҢ*,C6mR}! YO$c}F*vDۻlW뿓UգhpqA!,,̺'0:]v&#N%> *@"j$Sj"bUdtƸYko BxJ 緇'SgnIG; l?ΰ@$i}I=nyo'' #p<,tf(Qճk}DJV5Tah0QX96 $\?,fhk}|, T.Qe}-IΊy Ahr`p4aJxg< Ħ=6;+ ϩGƒ:f+p6.u ꟉWQpG)b듼L2H27:ɋ?ZkorBߜ4MG5IOC2ǿﱇ\dsê2+Mxg C}80F#Y@3egV,u}' kǑ3%[w8yNr݁i i|L+LxKv*ɋC @ETh[LdZ R >ᨄ=}0Id? ((jtS =^6XunUJmc1Meu:zX5eH+LjߛGNlwor3pWWn\\Gpxӄ\V٧|sVV}r PjfA(׾W/S%FȔf4؛u&QĢZ{{LY)仼ik7 χeA] /mdrР@Ӑ]i&|F7 93]DR*SS9R|vKϾۆ(FK-0g Ko݄؂)B)-g^D js8ebAjEx@s~1*Y+m'츱Lq`>8I?t^;_xԟ>9'T:+ћWZ(sd_1ĜQ'cc܀fyL7% r#m74zRYgύL^!4}pbx`W+t+bp}*y+7oOq- [!&@{Ҙu"N!=r0(iDd9|CHzŮ|@v6/G6@OZqvB"Bn@rd7Ƶ RLBxPz}Ǖ Eʨ}f<+1qV"<@,Rmr7+QŇ瞨k=穩Rj,=)32uV=]? Nj 懠MJbokXOj.s=[g#(u[_ål!!*/2I-be Kfy Q1{H{Y5xBgGiAX~t|:Mꅂf;KkGgdaD[!6FЌEe;@1#noi嵗`Eot$Pyؑe2[Y@\Ix I4Dd"W|, \^P_.!Pib"ުRP45uЏ ?#9-)hYCKXwSO>mZJN.rPA "zI9|4}Em(!5&3^TCz.F:Щ8nh8dSߛ"cfbǰȟ7/+]W@ʤ`N@*֍[U|lq #5Vޜ2.趁?H/c|/.y7.f@(\f4MSY˭kv= pS-4yO5AHw[ }WwbTi{|`}mXmFN_>Ζ spxw|D=s쇧QPĴ+.?xng +!_ ey?֞`(寤Yz֙tv8+ D }{L2㞛EH-馯%cy2"K>,K\2~4 Ș M %[0 K×B`-2=]ps_qYVҰ@dw3^{w .oXzu"p7?.3ݼQyo~kG`u3&܁ E>_wccʵv8*q5#0MCk*p0=ʃ-Q u1-HNZ[nFQ@:W@ԓ4gIL3)Ф$j5a =>aތU(7@tUtUK7  e׸v^̎ DZysӕ0g! ({p5=!}Z?QLzJ#|X۽IԊU3zj("jb$k Kmѧxf? XO׽t2A2ڵѡ!{3t Tym7FӎC!SrP`|! M qmr# aӏf(V" N:=F]ǐ$ 6Am%2M<|ڲrWt̗G)Vz2j\"k;E&o^ qAzeL|r9֋skw{ir]\$O&.7rö7E5]ɤS=,|sr0t7_m8EQ {m]$@a4(L¹tN&]^D3җpH(E&r8_z-Mg + a ő|=(3rwLׄWjmus[ TN𡥣7/rJyZYDoȄulh}zoų5!urit|7ɦfY:?R*+[ ٣r G@eaA6mbM(sν\fj[2j`"[45'h֑)^g»f΅F |>O.o-Ci+Kä%{so/2(23p@2ՃN&#ȪA26qnN;nY uSUA q4-Wg7ҙ 6ZPn FqJlZ;tkuWds z[4{\ZCjqTr*y2{=y!Id{!I,gƿYWS*U ,aO?{p( i0fcKbx3J pL^Mi"\q9txwMB4ڭy%3d X-)8 GLU 5"Gj:J{z'?LNZ}mA=S%_+OB{ rr3z] v5|0^ܕEǾYC81,D\s釻Uχ;KҗT5Є@6+kIhړwrgJ%py~5;qz1eZ0wYjlvgtXDKB욥6e-J~9Y9l~bJzVDlzTǝI)?n+--1#*MQcqNRK.VLK (-|d(-w^/~NM޴TCw1/XҒL4S̾a[30S[;gPSU "wg~鄄oV&%ktBȶCu$>Ub(qT^k8YY"/S{N= ܆0BhH3bn?~Eu/Ú|tMgW1vqPWߜ99#p}0ըy!5B#Pjve,*)zP4. ;3ɜǯ0l֪k5)_I_War^TWnSD% NJ1\ ÝR3,J{u$n+~WmݽMaL0nK΄MVpBqaHJE:TP }nYHbw/!لwWq\A*VZ995M NIOԓ9sܕߚT={zH;OA8ja|^Gʌq.! +*K ˁH? W/{ Pۇu2Fbq1QrGeCNC61E ^?F'YNe_-~~pѯ; Dܤn^z{&{}sF`6}1lM*=lW6BD޻Y7߮ jc1*b4>=Rz |$h>̡.\BM$,咖B qI3LLuBNl{_} f &er!7c,^fv1Հm'좬7Y[cZUXWŊ1*xNDѵM9e4-ǽS8Ǖ0SQVUfh/HLq!O;i :QEU6=v$fseE ӳjrWDr`-LLPtvUUI1>$XաFG~ȥjrDT ὤK+#B>kUd[j9օhv~Ms>XKpk}kChdqdB1؂%C/iӀ\ěvX9mCHVQNggL Y?b]--<5] CqeN뼯#N7 [6^C.R$F^yg5FDpE,V^@@;smTI\eѬ2 ,D9YC mB6Jeymm7>פO 'y_*j] FWU:|3<3q## 5Nwe;f{~Gse0iԞ)L"i9Y'6l@Y!]?YW#>))GXxcwʂ/9 Ĺ$:ҎۜmIDź(K52d@ގ4YŀӼ U_yutHS(,Փ 4~2Fy덈uhqQa SŬLlqPO $ BA$w̌_JE74 Ci-JyytsDY Q_ͣ ͦW ѭf9EbqAINe@@0>SAz B5Q]/.r. {`Uls ta~V釸۵B?H( w}T/ W ! Ni24d^nH iYѾIȀ1=A%ȷ^L@[e98s6IDa)AQ{'QHμMm0ռӞGj= s4:z]l\o(5$+'RʶoPfDJ< \d*tJ,AVvrUVr=!Pm`C q;0VV *&lj/8gw>#_Úg&d K!*WmO Ŧmi1tŮo"]w_ȏ*N"I= VBj:@*4S@m2Xj |JR#]rMA(LMIIKYf)Vց`'#_0A9StK&'RFiI#%tε2=:7@ShxƫkHD )kZ/F]XV20o C; rC:Ѫms:*-A:$@v''Lۊ ~ Pd=H:k :; ~ #P)db;C%;^ ?}>4m)jL,0ϥSMbl::xA)ف@#O !#%2 YU@+GAS6ۓM͈U 1oP]@$'}OKo}~ Ai+iLabB`(v۷5WE6y4qIQIs$+^lc ^\v{#R5fƆ S %♂*Gfn19S*QmePw%wSZՄI~%5xQ|:Ѕ6A$yt.ױUtC!]f_  G{^X=W3H}@Bn<oyC q0s'o`g{fw;ն[hM'蠾Ъ^н6XXX_.>ڈWC1*U,ߏarAYVrIwK43t&ؐv܂]&G 3k0b5psrpU" ~i LK@lq| _w@^RVӔ>+?vBi@'v.t9EF>xy\l+h^ֱگKi= ]]N<4| 4[=cs`MXfPG̛"ݔU QOnq^ZrWJ(<1˜3הB *dD4Vj#yR %7r PeRmu? WF4-Rwܖ$n: L2=ǙְX2:0? eUBt5 q!\G P}Fu`yfy{JT y^(z&{`kgߡc0, ) H1qЄ9A8 YƷ@X/ӲSrdo~--̊*f݆om$Kf_.m>k}X"yhr  $-#bBq4a G#cg)EC낳-?V=.}pM)G ]Uq7\X}x-f5pR|G =L+x2b}Wbf2V |Vetaf} Dkg_@Ks/0e"9~#gTB2o*) 8eP#ٚUcq&}0_hCQFpP0oOj{g"+:TZaV ۯ{-}AKʓ:A@ɀd:ΆaM&Wv5yf͹qgty^);Lbœ:^K=>uh28_>1$M\dAis\G~yl(ׇT3gֻredX .ՒC1zЩQUrխ[]I_:w_!Ƨ*,i#7ͅ%31z%FjL-"xe<'9`@XF*n[8w#bl淾g؂>Pl;>`]4dPk(φyгv=ߛΌ-&!ĉ=^DKD+ɎYqO4+*tk`A׽?" ˴* 7%yb`"A"׌:Z; 2Q,EXjW Oby@Ӈv3VbA͒ U[1񁙴詻Cnd]*Y,F}̖J=xb34Vm|Kggzů䣡N BzslkbK');O{xHJӛʚLN!.;d={ lҍ{6t =cCd8'K8PH`@bBP٫)SOC1[}dv%3`g;&0!"%IrR#X.d@'!DpXlOy0/9|DU(8'd&UK?&`;w| V`ⶬz7W_<&@k甌n>elOcaa5xK9:\Eω ޾,)c># =jBpVԌIi)?O:f^ 6Mяl;(1׮Nyc{nJ6z.w_gLekܟԭ8s(w~;j<)&( گ@EY?/ >kV'Wv> K,jl`FuKvohX* ;A긪2> Rl3 x~vp6vFn bZ*P6媼d1ҏGmJ[ns2[8gldhdX׫H(]*>bD"nuniܵ DiIf"!J T`6Pi`JOC|(޹bM%j$qa B d4o =Z e^Qm7]PD}wÆFHgIкu#lud]HTu<,sN/û'y"xYYgA-t_ TrxxUE'`iiDKTԊ) l8'{5 Ye@S73/vf?Yr⺶Y +=2Idz1Dj#>_6R@JI%Ph[pPFȲuE f}?Modwg}dT+ω޸R;0bY!б8 NP$LZ"3w Gq *,zUSsELK"•'b8wMD)dV*ΜP N"zƐy_l8 AX7z Վm&hx eQxL[|0Tioy(Svrv y/d9jA0ΈK~+ӣ&9_o{jlW^' Ryv{cg wT!(p]17#?2FlGrpiPp[*D/3'3z}}V#+aTd\lߠnRɕQݶxpZc$9dHyE%gVVJYCgRN>R,hPdjUb`b5-Պ<\c2t}p`KjP y =p1.qhajH.bCܛձKÄG7 &1_@D=_ܕJqЅ!oD!~@!r% рosHS(SVT_9Fm"(뎓aPWB` Լ3xi#fUI8z=+"x)SJljz%lM[o1ţؤg^_ojY&,jgAs I`UF5‡r4d_P5Md ⿓g(6^?o$)-~^L k\JG+ި>Wn7B^!nVt+T$$4)ha tciGW "F +d@#p+]a3dѩS&2kޗ2UH邱-&ej6쵖?EH4wvD,{ Lx<—8B=Pn-L ZQvR&?G(I)Ұک~h֟o7zpyF/꭮t;7zST*I=_EjuQ*JNIY]s3!p!a*BuJ>EȼMRV; nZy3Q_ B KVS?'԰/ھ Y`W.gH@tH<]qK'͜{9IRi>K8].`xy.5\Q}Z՞Dtyx2 y~x=әc!]j rj2i !n˵LsԅԆ_XRF}%],A1\ztPh2]zJ  'T>P-1#jF@c|wIJVKR]J kBL(lvhf#Y #r5j08פ:tDˡ\_tT1e8p&4a$(I5)5~'IJ e`ҋgdp9lg9kZo|{,GU @d_Т~o5'h*wt 8O,@jOU =j9cwܯ&ʝ`,Ctd7bf?4iFhxyN uL.p?x/w6BOZ4.5<*( 腕_~L^d2j@~ R¾xp3DK?'ƿ J#5Z 0̤zt3\$) cs;|mU C7Wsh.C"0>ގ킶w$)RfnxCkbTHr+8F; !CAAxl[mx)΅gN(XZ^ކ腥W,7)N15[s"wBXNh/Pzxs䳒|բtj8C`c~eLnӻl%/R5沾 Qv"MZu 9 H̜]}=F 0p }8+G#Z"MEJI\h%-d\ c.$Z@muKvKC-c"Jjrh||59Ɇ@ ]O6!0XI_afU YӵXMT(гS$R[^ HsRs73$- FQEKmE+׍@Y 7rv-͛S>pΛT*F?ZdxaE( DHN#mJx4q'U 4!}΋ǡ)JwMͬV9X}0FUyY\sa#ϩo#5I*K P=f ɆAǫ)'pFˌr7 KX\ͩIJT976x&IJ ԇܺ s/}~*.gu|< .(Ӫ1#F#$FSlS><j @6}"08:X xJcSN`,ĺk;^9:nfAIݞvĘlGݼ3bzze`~w}}R cf7+.7J6\Z튑@+~r #k>XFPY~{}m/PSR .v N3(Lsq@ܝvL`@u4U+V.̯嘈CDiyq_wc5_Ҁ$֫ci ȫ0odZGUdӟCtXKJn`=FyZ/=x cGR, RF_t os7|SYKrPU 6`AVmЊ!EsD=?D [Q 1[1@Q9;a㟛z5ob:AC3n>_ PTοybèa TѬ GwW_Blj2hSwcp\yBfG Be:n@?G^+cxLڏ͉#{T:FPp*;2Orss,^Hlzu@JM&[Mw>U˻Q YmT1"Mxx率pRrrQӕһ&j0(YbVמ6qN\:Т;rXdas6s[6?xk@=Ybrw IT uoVB7ga'fSU$M|"^XFlCk#+0`@.{YⰮz=z+":y)Li/h m:ƩseL !+0;>bs>gq ͞| ƒѐYH}Q;@GM|dh"naK#)Y8Co`E4jl CR1]HkWFɽ46ڿźH`T\sm Sd='F[ωNA>J")2+^_z4g.\hͲKb(Q5}?qH̗ ]8.U1:=0&O$&S ;]3I14j4{;& `Nc #zҖ TclAYxst4&*1 {{L-4Uץ3Jj@x3xsU N oz,*C`OM![v/ӝQ30h_Uŕ-6SzmkFQHV7$rVȭ+µ%ONW] Pn&h۬n2)?fwqRӓ`f' F 9C7&@Acß+BߍX4SDGSGE5ja[E=!D|\Ar-M+T\62R Ӿ|l{#i+ #~XONO6!SJ30ܧG:l78A8\do<`$v. QcPX8P2e>Ԟw lG 򥨂,"yYpkpXhG/e/p9v=H ϰdB4֍Q~߼NgHbH6d^N{dfo}OW[_ܩJLamFDޛW FYO^t̸b_ wL q-pXb};boͨ7B&:1 .C0(6uTHAtB+$[.5Ggckz3xl-[y5XOκEbh'1F?vv-`rxle nW n_Yhf&w4ae7?ngBW[B5>5ئw)]Œ|.Vl?4S_;@Ri8kti@A"n+\x':QvSgw: 5e8Fu'~)T<+A{won5udU "z_?(,yz޹ :^ay˩Eb_ukmS%#à'[j3"w %?%4#eK3ʈQ,Kc#?R %EkЭ߹M+| w*yHrpIKqګB\UEQ;(-,8bo4 ؋{v j^npT8j یfbmh !8_~nwh^a]Dehe6B]Կ$K =OyoH?{5sսD=\NHDm;Aĩ&f4?TeS0CwI@X^ݾʋ]r"9*cjg4j s; VI8l&sgFZ,4fJ7ijdF`ۜC z@L7P)$?HwICݿxz hvEJ0 vt)ކ>QlS.U@}ľގ5̉av 4!KYW?f,ǯ/5Оxkۃ{$aK}: &SsAO'}ĺokpKEH j fQK.ιy(+ϸVg RJߒ2 g "x]v)Fe4^79PYlZ>;ɆKb J);O#J?"VK';~ 3 8Ջ۽]R[7};J4 jlfBĮmHh2+%-d1Dtoih=5a߉rjC\dڔE63Ƙ$? |1]3!Ǣ-s֞֯PA Wѳpe!(\37!ʕVw"F0=i. ju)6)$E oxc|%pɸFxT>S>gTZ`txq̆ ; a:u+gk$]= >ARtG{kNg%;1'HK@S wj$&W޺ցeطxĉ)[릸6:lתn*ie8F '.`w식u{3p3[,m$I R2Gs}9P# ć63+<6hwYS\^L _"g$zX1RTYXjK &1QS4h[NN|^y OX{+ۡ95ӢBCDGtv"As:o=gCl\L$8wF2g8ZhZF?|tJ^} _/LJЩ4QT6Tpf>-li'6q NoP&5°VNi *G]S"s^Ѭ3͠-gG:<7^e>8ifo/4 ٹ" PFL8l3.pFNoźzr5a^ ^*  Tg@ߧgo[{,;NGe9@p+kDy \]_CuN -VnrilCUY\Ńw3V},:Aixxti`oS54sz9FهO[2u 3 &-Ad7AҼ06Q+ԙ(27Ivҗ*|3j6WYb" " .s4s::Y-S+?uvkF^zz$)BO\xYϩ9oҞIk74 @듌iwsq kGkD/i=C[3/"n-- TIlWdGj ?SSfGrt*Io&lz:btjƸ֏u1SܟkcO5q0 :aFb{@˙e5&1?cjgu%nC.P̠pIa`;q\l3M(r,rjMgB8+MagJS,uLgK;v* 5"\gE @ɉm`YJƪeVΤ;O4ɪ&:ԉFDm P^=i5ڊ.1\fy{(.ͅy;޹!mL]FP=%F/sg# QbYəFg_b؞Ty|/ >xSx[G e Z X'ϓBCz;mͬrs`Jwj} qK\ `41Ni-j~; Jl`͌g;$NTB atz*ED ,olb hBdKEk(y_}t؇OtbwQc Be^"şa]=8p*.#E!~)lƽ@  D22SCt!'Q&rW@֧ ^i`d _txJȹ?͊_cqiͩ,1o8q2 yLnmq@5D \et*t7uh$C .?t?Q%gzpu+LurLÖiD{BGcH\O.>-WvrW.N2ɤ 0\tr`IfITOqi+Ò/;wQMr\guN&6r b,;ۑ+a % ƎlbzriXD6<^$ٿ ^C,Oq8oЮlMMWRWFg1&=@Hzgi9`و& ]IyvIA 2^=^fn`ȤM$Ug1e*¯;a2ѕ0,OW;u-,#%Or(Y1  k(`zpzQ/f Ac9oK-`&b/y.H ~}./Zm6 "E`:GdB8Yԫ?!z7mSF<5L~GFsGѻRĔ ,JI z=/Hѐ%L% D$q@e,rWY`Kuf6Ju @:&Ɇn6FDbڂRWjhH9F\c")B޿I- yKI P"FQY_vd*W@}#xŇS?ΪR=h]Æ*C0jL7Ρ?NjoǶ Y3r?2C z,ξݫ"2&TU (-HXY ˚@(aM./fc5^wI4s:ٚgvLnMrGl+rr3.׎"[b"RgJ~@Jn&-GXd?\7iܖx:( lv*KQ N悯rCm2[㦭2iŻ"䑍NmƜמVy*Gs8W}Pg/7*m0܌px8Olo )Z l42FPsxfbgm FO5kw'kKrj}^Wvɗ2Rf>F!iijB!Ay\C7-BbCvpns:"׷t9`b %@p<%7 T|]A K<ğ!Gպ+˶flx.~B~NOș/9.$_iG\x@]mceSQ ;?EŁT>pafD5$^Z|`y(brԄ@zs;tbk"/y{$~`o+4Q:#Gt1DgϞ|PD't8#`_q (!?D˰b' {2g ,cE%"0cjŔ_ҕCW՛*iͦ{a~\Kmtsijwq#r:l[s,ކeba/ xJ9&}6(\V.@WQ 0>OCbCk:?wEtFsf6[G`2!ٮxD_3xo :D#nOBz V3qr-|?AARljNORk-:ۙE@‡&ɶD4;X_R Ͱtg:cx%Q% #!\%/L@*a,>;}~+ {qC# Zg ]JAW+/sʮe )}':^8!WM=s74ۉBnj:JӲvFbt@9_!޿? Ni+_YvIٴl당(M~}z/d%/`5[ƀ+dyJ0bqD @ tO0YST -@k̽@ّ%V{Ce~sNFijOХ膔#L{Uh#2W=^n[WѭʬaT+@ ʭyݨoYJ:5Vr#lɎ1GP[Z[1fcXMdX۸:kenl@aN’44)E+k`TԵkt#̠Ծ@x7pTA X0IP1+NF{xkO-H^ Z.Q)F"8̀^"[?ryևg>"6߸8oSgqR8ޡ|^Av\goQA5J=',hnikI;`FJЅ_JO)$+F"}tuf<;9B&-m8}Imv@mr-kmyC`(o%vPD,E*OtU;9lU=^)e# }% 8՘ \}ak* ?5dqd!xx6"iϬZfy/; @KBI[Bp ~=mi8 V#}ɿ j-pO+l*$ v<=lP>O F蒩Ēx V]n 1{Mb/rMqjVmaVU̒è&L.[o;X Sn[|OK5XWCyuXs=TɾbYQ"ϛ[>z.iuri[_; bUJ8:UxݓkLs<:f( Ƨ lGўR-o88&-{wW5k79HU/%AXFHN :`Ź ?> uS"f0Ÿs߻!U-dPya# $ POYr]%Q œjV `dkl*$w{?N7˾]QKNP-\KĉxM؇^GaT,4DbZм<0;m_/:y&sd,ݢF=L6 ׷e<,W6I 9EH8A-+Ȕ%n!,] b&FkBGSW"*@N{Q8wjbB4ٳ`^}&әFI>5#ClYBx,! adyzjg-4gyK 戟g0V0}~%F~}%˼N3VNgtU-=Lޔ>h?|"ϟ˷WNzHЋh0 :u#k3B)37B3ݨe RBG\heض^@FW€+p-q~K  /Fk&ނNOl5v*'Fj=b#cQ芀;*Ⱥ+ "!J\ON=6zC3D+p~lvT݃j֕óB؎t$#avD5I_%ݺ0hZ^ؑngY SAY8Cfgi'bz&T"_+6呄Kow L\mP7:kʴ#?gsیl^ YK#P-&pձ8qY^s9FIfnMKsGdD  µW߆Ʋlf[eowlrޟNFytNXS.v=l8ꔍ=}&%V\dӵw=X7uړfXuQH!cCȔ&v[ޜf9ƀę6.h.ouZJP}$ji\it%/]HU yU *=Usz~ubySVKie(?j8t|f:= 9](>]L+ŃxIɎL<5V¾Pg: 5zpԜ?K):WB QZh u n ᥯RYW}8ulJ,rbcj!A5xj$cUaRK;^lҦ*N'5^cǬNE7`/ ,YdTE Aoó 1;XIћ%CJk?mENJ^h\e; DxOTrFP=kWSbM$_+%OC:jRz5;E*OqJAh;GwgIW6|bWc^I8vp=@:IfDu)G;ܟ&jZ|$)*