nss-devel-3.28.4-3.el6_9$>R>o2RX3.>8ļ?Ĭd   O CIP33 3 3 3 g3 3h3g3f3P(89:OG3HT3I 3XTYd\3]d3^ bmdeflt3u3v w3x3yĔĨCnss-devel3.28.43.el6_9Development libraries for Network Security ServicesHeader and Library files for doing development with Network Security Services.Y-$c1bl.rdu2.centos.org CentOSMPLv2.0CentOS BuildSystem Development/Librarieshttp://www.mozilla.org/projects/security/pki/nss/linuxx86_64  YRCyQ - 3.28.4-3Kai Engert - 3.28.4-2Daiki Ueno - 3.28.4-1Daiki Ueno - 3.28.3-3Daiki Ueno - 3.28.3-2Daiki Ueno - 3.28.3-1Daiki Ueno - 3.27.1-13Daiki Ueno - 3.27.1-12Daiki Ueno - 3.27.1-11Daiki Ueno - 3.27.1-10Daiki Ueno - 3.27.1-9Daiki Ueno - 3.27.1-8Daiki Ueno - 3.27.1-7Kai Engert - 3.27.1-6Kai Engert - 3.27.1-5Kai Engert - 3.27.1-4Kai Engert - 3.27.1-3Daiki Ueno - 3.27.1-2Daiki Ueno - 3.27.1-1Kai Engert - 3.21.0-8Elio Maldonado - 3.21.0-7Elio Maldonado - 3.21.0-6Elio Maldonado - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado - 3.21.0-2Elio Maldonado - 3.21.0-1Elio Maldonado - 3.19.1-9Elio Maldonado - 3.19.1-7Elio Maldonado - 3.19.1-6Elio Maldonado - 3.19.1-5Elio Maldonado - 3.19.1-4Kai Engert - 3.19.1-3Kai Engert - 3.19.1-2Elio Maldonado - 3.19.1-1Kai Engert - 3.18.0-5.3Elio Maldonado - 3.18.0-5Elio Maldonado - 3.18.0-4Elio Maldonado - 3.18.0-3Elio Maldonado - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.16.2.3-4Elio Maldonado - 3.16.2.3-3Elio Maldonado - 3.16.2.3-1Elio Maldonado - 3.16.1-14Elio Maldonado - 3.16.1-13Elio Maldonado - 3.16.1-12Elio Maldonado - 3.16.1-11Elio Maldonado - 3.16.1-10Elio Maldonado - 3.16.1-9Elio Maldonado - 3.16.1-8Elio Maldonado - 3.16.1-7Elio Maldonado - 3.16.1-6Elio Maldonado - 3.16.1-5Elio Maldonado - 3.16.1-4Elio Maldonado - 3.16.1-3Elio Maldonado - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.15.3-11Elio Maldonado - 3.15.3-10Elio Maldonado - 3.15.3-9Elio Maldonado - 3.15.3-8Elio Maldonado - 3.15.3-7Elio Maldonado - 3.15.3-6Elio Maldonado - 3.15.3-5Elio Maldonado - 3.15.3-4Elio Maldonado - 3.15.3-3Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.1-15Elio Maldonado - 3.15.1-14Elio Maldonado - 3.15.1-13Elio Maldonado - 3.15.1-12Elio Maldonado - 3.15.1-11Elio Maldonado - 3.15.1-10Elio Maldonado - 3.15.1-9Elio Maldonado - 3.15.1-8Kai Engert - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.14.3-37Elio Maldonado - 3.14.3-36Elio Maldonado - 3.14.3-35Elio Maldonado - 3.14.3-34Kai Engert - 3.14.3-33Elio Maldonado - 3.14.3-5Elio Maldonado - 3.14.3-4Elio Maldonado - 3.14.3-3Elio Maldonado - 3.14.3-2Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.0.0-12Elio Maldonado - 3.14.0.0-11Elio Maldonado - 3.14.0.0-10Elio Maldonado - 3.14.0.0-9Elio Maldonado - 3.14.0.0-8Elio Maldonado - 3.14.0.0-7Elio Maldonado - 3.14.0.0-6Elio Maldonado - 3.14.0.0-5Elio Maldonado - 3.14.0.0-4Kai Engert - 3.14.0.0-3Bob Relyea - 3.14.0.0-2Elio Maldonado - 3.14.0.0-1Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.3-7Elio Maldonado - 3.13.3-6Elio Maldonado Batiz - 3.13.3-5Elio Maldonado Batiz - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Elio Maldonado Batiz - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado - 3.13.1-4Elio Maldonado - 3.13.1-4Martin Stransky 3.13.1-3Elio Maldonado Batiz - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.12.10-17Elio Maldonado - 3.12.10-16Elio Maldonado - 3.12.10-15Elio Maldonado - 3.12.10-14Elio Maldonado - 3.12.10-13Elio Maldonado - 3.12.10-12Elio Maldonado - 3.12.10-11Elio Maldonado - 3.12.10-10Elio Maldonado - 3.12.10-9Elio Maldonado - 3.12.10-8Elio Maldonado - 3.12.10-7Elio Maldonado - 3.12.10-6Elio Maldonado - 3.12.10-5Elio Maldonado - 3.12.10-4Elio Maldonado - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado Batiz - 3.12.9-9Elio Maldonado - 3.12.9-8Elio Maldonado - 3.12.9-7Elio Maldonado - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Kai Engert - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5.99-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-7.3Elio Maldonado - 3.12.5-7.2Elio Maldonado - 3.12.5-7.1Elio Maldonado - 3.12.5-7Elio Maldonado - 3.12.5-6Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-2Elio Maldonado - 3.12.5-1.14Elio Maldonado - 3.12.5-1.12.1Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.10Elio Maldonado - 3.12.5-1.8Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-1.2Elio Maldonado - 3.12.4-15Elio Maldonado - 3.12.4-14Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Fix zero-length record treatment for stream ciphers and SSLv2- Include CKBI 2.14 and updated CA constraints from NSS 3.28.5- Rebase to 3.28.4- Fix crash with tstclnt -W - Adjust gtests to run with our old softoken and downstream patches- Avoid cipher suite ordering change, spotted by Hubert Kario- Rebase to 3.28.3 - Remove upstreamed moz-1282627-rh-1294606.patch, moz-1312141-rh-1387811.patch, moz-1315936.patch, and moz-1318561.patch - Remove no longer necessary nss-duplicate-ciphers.patch - Disable X25519 and exclude tests using it - Catch failed ASN1 decoding of RSA keys, by Kamil Dudka (#1427481)- Update expired PayPalEE.cert- Disable unsupported test cases in ssl_gtests- Adjust the sslstress.txt filename so that it matches with the disableSSL2tests patch ported from RHEL 7 - Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests - Don't add gtests and ssl_gtests to nss_tests, unless gtests are enabled- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release - Add patch to fix bash syntax error in tests/ssl.sh - Add patch to remove duplicate ciphersuites entries in sslinfo.c - Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range - Build with support for SSLKEYLOGFILE- Update fix_multiple_open patch to fix regression in openldap client - Remove pk11_genobj_leak patch, which caused crash with Firefox - Add comment in the policy file to preserve the last empty line - Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not provided by softoken; this superseds check_hash_impl patch- Fix problem in check_hash_impl patch- Add patch to check if hash algorithms are backed by a token - Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256, which have never enabled in the past- Add upstream patch to fix a crash. Mozilla #1315936- Disable the use of RSA-PSS with SSL/TLS. #1390161- Use updated upstream patch for RH bug 1387811- Added upstream patches to fix RH bugs 1057388, 1294606, 1387811- Enable gtests when requested- Rebase to NSS 3.27.1 - Remove nss-646045.patch, which is not necessary - Remove p-disable-md5-590364-reversed.patch, which is no-op here, because the patched code is removed later in %setup - Remove disable_hw_gcm.patch, which is no-op here, because the patched code is removed later in %setup. Also remove NSS_DISABLE_HW_GCM setting, which was only required for RHEL 5 - Add Bug-1001841-disable-sslv2-libssl.patch and Bug-1001841-disable-sslv2-tests.patch, which completedly disable EXPORT ciphersuites. Ported from RHEL 7 - Remove disable-export-suites-tests.patch, which is covered by Bug-1001841-disable-sslv2-tests.patch - Remove nss-ca-2.6-enable-legacy.patch, as we decided to not allow 1024 legacy CA certificates - Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits - Remove nss-init-ss-sec-certs-null.patch, which appears to be no-op, as it clears memory area allocated with PORT_ZAlloc() - Remove nss-disable-sslv2-libssl.patch, nss-disable-sslv2-tests.patch, sslauth-no-v2.patch, and nss-sslstress-txt-ssl3-lower-value-in-range.patch as SSLv2 is already disabled in upstream - Remove fix-nss-test-filtering.patch, which is fixed in upstream - Add nss-check-policy-file.patch from Fedora - Install policy config in /etc/pki/nss-legacy/nss-rhel6.config- Ensure all ssl.sh tests are executed- Update sslauth patch to run more tests- Fix syntax errors in patch that disables sslv2 tests - Resolves: Bug 1297888 - Rebase RHEL 6.8 to NSS 3.21 for Firefox 45- Resolves: Bug 1304812 - Disable support for SSLv2 completely.- Add patches for ABI compatibility- Disable extended master-secret due to older version of softoken- Enable two additional ciphers and keep another one disabled - Prevent enabling extended masker key derive- Rebase to NSS-3.21- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol - Resolves: Bug 1289890- Package listsuites as part of the unsupported tools set - Resolves: Bug 1283655- Resolves: Bug 1272504 - Enable TLS 1.2 as the default in nss- Rebuild against updated NSPR- Sync up with the rhel-6.6 branch - Resolves: Bug 1224450- Additional NULL initialization.- Updated the patch to keep old cipher suite order - Resolves: Bug 1224450- Rebase to nss-3.19.1 - Resolves: Bug 1224450- On RHEL 6.x keep the TLS version defaults unchanged. - Require softokn build 22 to ensure runtime compatibility. - Relax the requirement from pkcs11-devel to nss-softokn-freebl-devel to allow same or newer. - Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1)- Update and reeneable nss-646045.patch on account of the rebase - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Fix shell syntax error in nss/tests/all.sh - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Restore a patch that had been mistakenly disabled - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Replace expired PayPal test certificate that breaks the build - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] - Resolves: Bug 1131311 - rhel65 ns-slapd crash, segfault error 4 in libnss3.so in PK11_DoesMechanism at pk11slot.c:1824 - Temporarily disable some tests until expired PayPalEE.cert is renewed- Keep the same cipher suite order as we had in NSS_3_15_3_RTM - Resolves: Bug 1123092 - openldap-2.4.23-34.el6_5.1.i686 fails after updating nss to nss-3.16.1-4.el6_5.i686- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 - Remove unused indentation pseudo patch - require nss util 3.16.2.3 - Restore patch for certutil man page - supply missing options descriptions to the man page- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Resolves: Bug 1145432 - CVE-2014-1568- Fix pem deadlock caused by previous version of a fix for a race condition - Fixes: Bug 1090681- Add references to bugs filed upstream - Related: Bug 1090681, Bug 1104300- Resolves: Bug 1090681 - RHDS 9.1 389-ds-base-1.2.11.15-31 crash in PK11_DoesMechanism- Replace expired PayPal test certificate that breaks the build - Related: Bug 1099619- Fix defects found by coverity - Resolves: Bug 1104300- Backport nss-3.12.6 upstream fix required by Firefox 31 - Resolves: Bug 1099619- Update nspr-version to 4.10.6- Update pem sources to the same ones used on rhel-7 - Remove no longer needed patches on account of this update - Resolves: Bug 1002205- Move removal of directories to the end of the %prep section - Resolves: Bug 689919 - build without any softoken or util sources in the tree- Remove unused patches rendered obsolete- Fix pem module trashing of private keys on failed login - Resolves: Bug 1002205 - PEM module trashes private keys if login fails- Restore use of indentation patch until another bug is resolved - Resolves: Bug 606022 - nss security tools lack man pages- Update to nss-3.16.1 - Resolves: Bug 1099619 - Rebase nss in RHEL 6.6 to NSS 3.16.1- Resolves: Bug 689919 - build without any softoken or util sources in the tree - Add define-uint32.patch to deal with using older version of nss-softokn - Fix suboptimal test failure detection shell code in the %check section- Prevent users from disabling the internal crypto module - Resolves: Bug 1059176 - nss segfaults with opencryptoki module- Improve support for ECDSA algorithm via pluggable ECC - Document the purpose of the iquote.patch - Resolves: Bug 1057224 - Pluggable ECC in NSS not enabled on RHEL 6 and above- Install man pages for the nss security tools - Resolves: Bug 606022 - nss security tools lack man pages- Fix the numbering and naming of the patches - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- make derEncodingsMatch work with encrypted keys - rename a patch, dropped the experimental moniker from it - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Revoke trust in one mis-issued anssi certificate - Resolves: Bug 1042686 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]- Disable hw gcm on rhel-5 based build environments where OS lacks support - Rollback changes to build nss without softokn until Bug 689919 is approved - Cipher suite was run as part of the nss-softokn build- Build nss without softoken, freebl, or util sources in the build source tree - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Update to NSS_3_15_3_RTM - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 - Resolves: Bug 1031238 - deadlock in trust domain lock and object lock- Using export NSS_DISABLE_HW_GCM=1 to deal with some problemmatic build systems - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add s390x and ia64 to the %define multilib_arches list used for defining alt_ckbi - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add zero default value to DISABLETEST check and fix the TEST_FAILURES check and reporting - Resolves: rhbz#990631 - file permissions of pkcs11.txt/secmod.db must be kept when modified by NSS - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Add a zero default value to the DISABLETEST and TEST_FAILURES checks - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix the test for zero failures in the %check section - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Restore a mistakenly removed patch - Resolves: rhbz#961659 - SQL backend does not reload certificates- Rebuild for the pem module to link with freel from nss-softokn-3.14.3-6.el6 - Related: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] - Related: rhbz#1010224 - NSS 3.15 breaks SSL in OpenLDAP clients- Don't require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Additional syntax fixes in nss-versus-softoken-test.patch - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix all.sh test for which application was last build by updating nss-versus-softoken-test.path - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Disable the cipher suite already run as part of the nss-softokn build - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nspr-4.10.0 - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix relative path in %check section to prevent undetected test failures - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Rebase to NSS_3.15.1_RTM - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) - Update patches on account of the shallow tree with the rebase to 3.15.1 - Update the pem module sources nss-pem-20130405.tar.bz2 with latest patches applied - Remove patches rendered obsolete by the nss rebase and the updated nss-pem sources - Enable the iquote.patch to access newly introduced types- Do not hold issuer certificate handles in the crl cache - Resolves: rhbz#961659 - SQL backend does not reload certificates- Resolves: rhbz#977341 - nss-tools certutil -H does not list all options- Resolves: rhbz#702083 - dont require unique file basenames- Fix race condition in cert code related to smart cards - Resolves: rhbz#903017 - Firefox hang when CAC/PIV smart card certificates are viewed in the certificate manager- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement. Please ensure that older packages that don't use the alternatives system for libnssckbi.so have a smaller n-v-r.- Syncup with uptream changes for aes gcm and ecc suiteb - Enable ecc support for suite b - Apply several upstream AES GCM fixes - Use the pristine nss upstream sources with ecc included - Export NSS_ENABLE_ECC=1 in both the build and the check sections - Make failed requests for unsupoprted ssl pkcs 11 bypass non fatal - Resolves: rhbz#882408 - NSS_NO_PKCS11_BYPASS must preserve ABI - Related: rhbz#918950 - rebase nss to 3.14.3- Revert to accepting MD5 on digital signatures by default - Resolves: rhbz#918136 - nss 3.14 - MD5 hash algorithm disabled- Ensure pem uses system freebl as with this update freebl brings in new API's - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Install sechash.h and secmodt.h which are now provided by nss-devel - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Remove unsafe -r option from commands that remove headers already shipped by nss-util and nss-softoken- Update to NSS_3.14.3_RTM - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Update expired test certificates (fixed in upstream bug 852781) - Sync up pem module's rsawrapr.c with softoken's upstream changes for nss-3.14.3 - Reactivate the aia tests- Recreate the distrust patch by backporting the upstream one - Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Remove a patch that caused a regression - Resolves: rhbz#883620- Fix locking issue causing curl hangs and authenticate to the correct session - Resolves: rhbz#872838- PEM peminit returns CKR_CANT_LOCK when needed to inform caller module isn't thread safe - Resolves: rhbz#555019 - [PEM] invalid writes in multi-threaded libcurl based application- Add dummy sources file to test for and prevent breaking rhpkg commands - Enable testing for 'rhpk upload' and 'rhpk new-sources' breakage such as hangs - Related: rhbz#837089- Update the license to MPLv2.0 - turn off the aia tests - Resolves: rhbz#837089- Resolves: rhbz#702083 - NSS pem module should not require unique base file names- turn on the aia tests - update nss-589636.patch to apply to httpdserv- turn off aia tests for now- turn off ocsp tests for now- Rebase to nss-3.14.0.0-1 - Resolves: rhbz#837089 - Update ssl-cbc-random-iv patch for new sources - Remove patches rendered obsoleted by rebase to 3.14 - Add a patch to enforce no pkcs11 bypass- Resolves: rhbz#830302 - require nspr 4.9.1- Resolves: rhbz#830302 - revert unwanted changes to nss.pc.in- Resolves: rhbz#830302 - Update RHEL 6.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6- Resolves: rhbz#827351 invalid read and free on invalid cert load failure- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity - Require nss-util 3.13.3- Resolves: rhbz#772628 nss_Init leaks memory- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Use completed patch per code review- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV- Update to 3.13.3 - Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave - Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes- Resolves: rhbz#746632 - Adjust the patch for new sources- Resolves: rhbz#746632 - pem_CreateObject() leaks memory given a non-existing file name- Resolves: 784674 - Protect NSS_Shutdown from clients that fail to initialize nss- Add two needed patches - Resolves: rhbz#783315 - Need nss workaround for freebl bug that causes openswan to drop connections - Resolves: rhbz#747387 - Unable to contact LDAP Server during winsync- Rebuild- Resolves: Bug 784490 - CVE-2011-3389 - Activate a patch that was left out in previous build- Resolves: Bug 744070 - Update to 3.13.1 - Resolves: Bug 784674 - nss should protect against being called before nss_Init - Resolves: Bug 784490 - CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)- Resolves: Bug 761086 - Fix nss-735047.patch to not revert the nss-bz689031.patch- Update builtins certs to those from NSSCKBI_1_88_RTM- Bug 747387 - Unable to contact LDAP Server during winsync- Add to the spec file the patch for Bug 671266- More coverity related fixes in the pem module- Coverity related fixes- Add relro support for executables and shared libraries- Add partial RELRO support- Fix the name of the last patch file- Retagging to pick up two missing commits- Update builtins certs to those from NSSCKBI_1_87_RTM- Update builtins certs to those from NSSCKBI_1_86_RTM- Update builtins certs to those from NSSCKBI_1_85_RTM- Fix CMS to verify signed data when SignerInfo indicates signer by subjectKeyID- Fix pem logging to deal with files originally created by root- Retagging for updated patch missing from previous tag- Update to 3.12.10- Resolves: rhbz# 703658 - Fix crmf hard-coded maximum size for wrapped private keys- Resolves: rhbz#688423 - Enable NSS support for pluggable ECC- Add "Conflicts: curl < 7.19.7-26.el6" to fix Bug 694663- Construct private key nickname based on the full pathname of the pem file- Update expired PayPayEE.cert test certificate - Conditionalize some database tests on user not being root- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Fix memory leaks caused by SECKEY_ImportDERPublicKey- Short-term fix for ssl test suites hangs on ipv6 type connections- Add requires for pkcs11-devel on nss-softokn-freebl devel - Run the test suites in check section per packaging guidelines- Prefer user database ca cert trust settings system's ones - Swap internal key slot on fips mode switches- Update to 3.12.9 - Fix libnsspem to test for and reject directories- Add suppport for pkcs8 formatted keys in the pem module - Add verify(not md5 size mtime) to configuration files attributes - Prevent nss-sysinit disabling on package upgrade - Create pkcs11.txt with correct permissions regardless of current umask - Add option to setup-nsssysinit.sh to report nss-sysinit status - Update test certificate which had expired- Update to 3.12.8- Increase release version number, no code changes- Update to 3.12.7- Rebuilt- Appying the changes in previous log - Changing some BuildRequires to >= as well - Temporarily disabling all tests for faster builds- Change some = to >= in Requires to enable a rebase next- Fix SIGSEGV within CreateObject (#596783) - Update expired test certificate- Fix nss.pc to not require nss-softokn- rebuilt using nss-util 3.2.6- rebuilt using nspr-devel 4.8.4- Update to 3.12.6- Update to NSS_3_12_6_RC1- Fix curl related regression and general patch code clean up- Resolves: #551784 rebuilt after nss-softokn and nss-util builds - this will generate the coorect nss.spec- rebuilt for RHEL-6 candidate, Resolves: #551784- Updated to 3.12.5 from CVS import from Fedora 12 - Moved blank legacy databases to the lookaside cache - Reenabled the full test suite - Retagging for a RHEL-6-test-build- Retagged- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- bump release number and rebuild- Fix nsssysinit to allow root to modify the nss system database (#547860)- Temporarily disabling the ssl tests until Bug 539183 is resolved- Fix an error introduced when adapting the patch for 546211- Remove some left over trace statements from nsssysinit patching- Fix nsssysinit to set the default flags on the crypto module (#545779) - Fix nsssysinit to enable apps to use the system cert store, patch contributed by David Woodhouse (#546221) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387) - Sysinit requires coreutils for post install scriplet (#547067) - Remove redundant header from the pem module- Remove unneeded patch- Update to 3.12.5 - CVE-2009-3555 TLS: MITM attacks via session renegotiation- Require nss-softoken of same arch as nss (#527867)- Fix bug where user was prompted for a password when listing keys on an empty system database (#527048) - Fix setup-nsssysinit to handle more general flags formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build  !"#$%&'()*+,-./01233.28.4-3.el6_93.28.43.28.4-3.el6_93.28.4-3.el6_9nss-confignss3cert.hcertdb.hcertt.hcmmf.hcmmft.hcms.hcmsreclist.hcmst.hcrmf.hcrmft.hcryptohi.hcryptoht.hjar-ds.hjar.hjarfile.hkey.hkeyhi.hkeyt.hkeythi.hnss.hnssckbi.hnsspem.hocsp.hocspt.hp12.hp12plcy.hp12t.hpk11func.hpk11pqg.hpk11priv.hpk11pub.hpk11sdr.hpkcs12.hpkcs12t.hpkcs7t.hpreenc.hsechash.hsecmime.hsecmod.hsecmodt.hsecpkcs5.hsecpkcs7.hsmime.hssl.hsslerr.hsslproto.hsslt.hlibcrmf.anss.pc/usr/bin//usr/include//usr/include/nss3//usr/lib64//usr/lib64/pkgconfig/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuASCII textPOSIX shell script text executablecurrent ar archivedirectorypkgconfig fileRPRRR?7zXZ !PH66r]"k%nÍdڴ4Yk(`<͓%BRJI[mFVJ*qzz{w+$#MySEm"9ṌgV0O9)glXB}X ;'u;jNs%ʾh!7;$M(KHmtMdd6SM}ףv=/bVR‡k<Հii*DUySBlEa ?ǡihIω{nTEhOt;E `͂{-beS]+U5UqOӉ]>^okd[_.g8 bۿ7BeI)Do(+(ZIk0b3v&i$p{~VID4Km.'çcDEՊd+a_v?ĦGurBF?Ј)i˘ww .B@n)8!&% Rƃj ȋe↽-/a5dGRuYeFρŬQ); 'uyXʶۆ2+IvJnn/P;PǧK#W,>ۇC]a\DY9^:ʗ0"4+D2~M|O؝Y}W62 Oj-, >}p&g1_oTgïȮ׽a!)OlJxbs k4jԭoI8+6g$P樨6SjQL6m]&SDNH,;0>۵b|';7FD^iPB P<̗KrP>${{n𢋯_H ǞVA~Zhp3utBK90Km d!_T@Y z%"蟻|Q?}ٔM^vuJ_MylC,7CzJ+ { DpsA?K : JN*&XD`b;u('MmW8P wibޮ)BM{oTa"3C O55T+Ȓ6o+deƛt#MgGS9pRQ]xl0,%.PR潢wl1uFx嗙̲Ou[3Qͺnf%:_>ع0LP?F sQ|thc) 7o OM&2`9 uSkqnl+]~*c#2FB1)JAM~YF'W/֡]ӀļPvٞt^&8ISN/qI+ {%UcRS/" Z҈r0PZp?&' 4mB'|fIEB JpsTd-c Wӈ "Dl)B+|1 zˇW9W^.(UBЧO9OU9 bEƼ=X7]!Q#)u;sJD+[Ae~i )CW^!`c>f, =E.H55,SUOsa'eGuMxy=5<]ՠ] 6]=)L9 Nb4 DW.H; 谾,M?'H_Zc eP)Sљ`U3WHp9YcM ,j"?)=U,>#sGX z_@No&w-׆_%v H}ǡ-m<初Ԙ淶o] fHIOg;cD* !i\;/c&gb'267GT{ 68޹{cks,@{vŲ5gQmBڵne K َON2X. PTŁoq(wT j<4׏>/=hiK8Gֱgc%!cҁ ^"1T6 o;(PEW,5fnSR`+p5d>Bpդ +ʢ! t t.n"QqfbQxW"N>[|'LL<7cKaȆ(v/55<*T_p3Og6\##4!hrUuK*U/ўfO(ƅpÎ0icR*4R[QH Zv.8!ׁ'KtKd*C'XBE7>`_Np/p{px/bu,!ʠ˻(9C{IlF;c+Bxg5B1wA7}m&:7&:&8M R,oT.`[+Х*mj9Ȑ3\HPp/൷:+G)txY1Q ϹrP2 a6i[wjng#gihzj"6Fk M={! PKLeM `>&v) Qڇ]P@w[&2}@Ox/E n#zU[9cc*=vn{`HdOˑM WA/O\fY|gH&2a- ]En/rCM~fK%=ȣvgJ4%hPәS@r"Sۙ))Vp@R }V>PQqĤ13TCR$:5wÍV#!(55/,*~<ؕH9%GI/о IJـ ӠJgvRk_zeZ3BQp؂+i,?"淢/ [~R~D%Nf[-{V]t+d~IHY2!/bH4RWVdvq?րR}وdSS-pz:j^1ʙ.?7x)iYWƈ1` \݃:qDS4 -hPfQ /1muɡry6Me7q+UEBqqJz"Eyuլ!ϵkq&>su w9s1KG6q$!?Tˌ͵RG⍏|K]l]_m =v~(S[{? M  Fg[x`e0飯,BI{!Y}0 z%^j<#g,=z HxUS74d4b?ns n`*/w_]6#b ZX|#-lY_G1Ҩ;HT} 安i;z\m@4@C~<#֘@&:-1]'B'hݡ̕#خe%\)VEH,Ȋ+٭"|_rk,jW&ZhzkCۑW/fe 5h-–l[o8u㇒Q½.3ls_칃JD_&yU>`f ;wZ:փ6 V uǣ*{UW8(kBSźǔ \q;Lj xLΰ3hT+YwPDPX7ijT,q{"U޸{]l(NpKz\JY&8g(񓸼;@C!484_S5o}ˁG*7KHmf}cy(JM. "cpYj#eѰYP#GLH6qv h\&,]`:v; Gh"% Hl |vͲ1#jj 5܍wP V+hW%qB\Dj#ˢY|gI۰]G ='  z:u{~ ؠy\H+q*{:Rȃ 2{&F잌B=?֩.lݣ\'+~"BPTTy%Զ>Fkzha$O5*dvXdүfzen;vBl 'DKTLwG͌/~rdc&I.u ;/ZVӞ' Fs8(CWzE7+ q"H&@9XxQ0|_XMybjd߽,].._rn?N,RRqil :!sw>"is}UjoDibw}A⤨ʆ8[|8 Z;LjV=Nĉo*ғKE* n6нRF8#A:\&n ?sېgo }Kw}=5VK) AH';h&o7s=i|۰$s=, m2CoX>ACRJgIF0DVe1;^ _M2ّv(rޕ|V-:2evVQ1?ZP t_ p8X$jQR2|b/5 pcӛXz\>n^7c7#oDq_>V`ԍvu*Wv<(nYսrMmnF  gn 7vv&*1QN,M&`hB,zm3?gq=J7A)QnI[b_\ S܌L_Y#qpamO\teA\8;̡2rʼqTrg6T:=Sb{c4vtƱG'ߍݻUij8\4LHJ׽fc>1oYEW5L-:l(PzY*?jƏ^,buj:zŒpޜ(Ș2*.TqyU~iboJlBd[?6uOzkVï%RuM6+eEΉ^Zd&-lr]ۻavN8LaJ$k'WȔrAKSrh&kF=vT.:0eJwNˡG D3bRH/,èS3@!;Lrݿl7S\aqq?WT ^.x,Eʺ9>?b政NQR 겏͹>_J, l'ximG-CoS?ƻISG T ^˂A§Ua%`J Aϲȶ n 888֎Sz0@]ƪQC}8i0hend` مl+7ן&t`1ߥFֆĎY6䣩;#8~3fOMѭ%^Xy4FdC n аB=vGӾS9HdqV9ti~Ti=xx 8Aۉ=!0ruc$m+Wx5] E$@kRUFY]cHW+L+:] jB3A}LVe7b1!+bXL4g`^M7kQm>&ſi_(+oKG{p [,@,N- Gswla r5-bCbfh\ %\ \ / TH_q`Ǥrj06cB =׻J-Tvօ Zp#rL] 0 @W:X)e ݁##7I ?O- %/l/}]!qWy(G(- f˲_Z9rV_1'6B*)( iw+-\ei& w!%pӎDL2*dW VA/D $pR[7jWPLu렃2`bȽԻY?74ҴPBvr4U=lwE@}, 8(MU6?~zEI"k]Tľ+#fS1ˑ22XD%!@N&>1iO #tۘYZU"'LpsiGƫWZI g7'&)/|{yPA\iؔد={gd`~נ֠(&yaCǸM+- .W򓷶>n Xh't*[p!/u sˁz TڛsQ_eu 2=#>|&>4`*g1؞88XuKǍ\\ձ}2 Ƈ)]SG9}D?+1$m[.!|lgi&f9~w{NL|0~4wkL`{NtT[*\g`Q~%0LB?x('HP0V%΁X0g7Nv M{)rc:_3Rq7KxV$,DrP>/#;’p^QTK"O&Lf/lJn(O0(ā5>!z"I Tܠ'F:CvO)$`k܍x VwdM-`J+>-y$c)1O@b#ħg+7[R|*9C*J1PL2m47[+q9^X(T5݌\o>ypuV )QV~X ꨇ^Mw4%b?ߐЬ̧gNjӸ0lK)KIЙ V (TL@{b+r 5xaJ_I)FH_·*&.NP;dN^/Hh'%T [/ st K]# Z6L|rBk˜j)V46^mw #IuYݦ;hb&i[zd!)k2`qj).XJH W;1( 5y +mVKvWyIˑN=> `b1 PUWhӁоR#\^XPͲ'ԓSaebmC =]B3GK+G`toeV2F4~DDQf Fl(: g1R-c1 <  BwF5lYFun8Aj5u>iLD~'h&jKMVr:;k %࢈*îfdëpD3^+jbb/[69HM)5uzs\k3a؄Qg V}x=c#z{YlQ 7PV ;769eDqUg/Teג/a0< wY7*sBiGЀ6) `6oKiqI[o ?9(4w5dA 4LKw}>H./ji=~zro()tzm:s b%]Ls.^rHULT}oz5FԷ!몺8];EK뫦HuQЯځD$,զPBa (C8ZhB~\P a+iAv<@! z(hkMPd>mn+/RhCCk2f&of*JPXasMLg3<3z ;Z? Ec^/|L1Ei2u@wY~h0no ~Ii s@aojZˡbVY-r߯՚VEgkai& _ټ7KH)4rR>ኬ|[O8@T9H/F#` y.6v2G-,՞?Q@m&=uH؊_AJK4<Ͷ+ Q^/;SKFs=#ltnpN >d[Ov88Fӝ"4\fM4ku_ɜ- ʲἣ|* <]CHG,H(Vālvom#r(63H; &3wkGQvJ|\n2[ۑn$\6 ʇ)~,`]Rahwp=@dE OBc%lii\de9Mg/!j\%09 !!H9\-]N !2im<%%5AWQ-k-A438Y*QÏT3 ^BqhteI,J% GӤPr < <`u9Ɗ/*Pd9m !ޟmT$KE0W*t)'RM^PֲqMhOMŝ& [pYCZ[]9Ӊ~wKڨ jU*3;Yφ,ڧ>-Ķ$'oYOdG&hgg1uD@L w,?;\_ ALkq,-GdS\LYޔ,\ڏщTǵ4/V݀c;B9'I硣"y좍IxGJ{2\:p1/8L#î>[VwD[_SDq:靼f'No7kgEJ@-)NS/riM"g%P؍ĸt <\GZr;1K C,ŭ9 @X帷DQO6(՗Oj18̴X-%s3l?aU20,v885Q52qRm̌^c2gRr3FZ[ҧ/k' n_81 \(<>Kط8]Mld9*`[0Θ]Cil#ّVD?X4Dzeېe& \]tO {96d]oAq=Z)Zl-敞ׯ=5ƨ8J~nF Ot(7s@u'{Ck`)o{|I-sӌ:pV5xЩFYD]zWsi"0(Ir RK4456+kS.1k"Wq""%Cm[ΉJ{RG'G1K2T6f66R;ײ^ƛWS_7G58khPrvOLuTjZӂ2jX:CP i0D~p\[\}`=lUlaPG_ȀwwKt *jJiw]/[dFD[ְkQ[ A>}_pz&2\%fnI%9G-N7. I!@~VuTADD-0ˬx2s[_3< "+4ū(S[?K-SoJlJKjcgzX?1;טN< 6f珵zI]dJ7Wl;~Gt6- chgzM=`m>;$ET#{aK/{ NF5!ֱ:Po2 LՒ |Gz6ΎD$ t+sڑnRlSbͯy9z6f ^zs`Q&Z1 ke2 XiEAre4rOݗ{* @ R҅Va#ͮ>E㜕(Ui S`,,b>"%E" ?B?U%G#LR% p6[:HojXq5Qs.|1v-:~$npl@ciO1v l`o62$#ژov[1QNn|띓dS*M؆i{-KWܪlIJKV؋O' &ۧ)JQz\; i4< նt]y$bn&Ye*y) LBLM 8fv&R&c?/2DY\ZG/Q?&yK ]v!bhCL8=k9oe*٭kY-2H.\񂟋dL-@;J[~3eLǷ0XAQ)f [iѴX@e}+4$#WyyZ%o:U6{%Yn뵉3 !A?Lq:!keUҲ, 1J UyG~>\$B|Fu}WPj2͍K$\ٱp&o)9T"d{)\@IWK!S7\+*o n}ŧj/4` lD{C~NhhD8]+)"udXlv0D.]-Z$t&,OhfY\%>`;: iLd9 9ftC76o8go5gNZ~? +,ЄKD @4ffqo.9PUp@WTz~oM큲"[ߗrB:TI92#"b/Ad5AtζNS)8t7PgҘ>8Q;CipʚϺnSeōNˤ$riqWH8W䭰Ƭ6 q|g '\3DpFJ 4<^ ZvYx>*DqAlW%½nmL({IXc~M{]Ppv Dgm٭M'J!_@UX ڈ%3tUNo tWï3i ̎gTNsT0lag PqWf<  l0>a;aabcmcRL#kC$6-t/Qbe?KRxyMBbJmy f6 \UtTޖ߶'?#2Bqqx=mv޾^w>/ S<8_H!_4uWc(4}[ӿ~`_sHZw؉Qf{?tepxoiò~<71ݫ> O|'%_>Oh{/4ڰ>i1VV' qOBq<}P^L1 v V𩝈c116B)(ns*z?a;{RlZ%;7"n#I1c6߽H9g Hneh#]dj{X rbD281s>2IswT,c%K `$BkRIǁt̼FA) ~0E,ɞ}S1YTj0h mJw<"ty2 74{/!. V@DK ]LkFP:j_9ՙP?{gCz:E)vzwJ0~;om5.F!0H oW5n:YQ2)tO3Rݶ MWaKi&mAqZpɦXd_Рx'R@Pa*k|FTecOA|p|hzhPܭ.z .n .s= ܔiw#XiLGfy9z8lllr)j:LORYp-+38"i%dXU{ mݜwyU[} =<#b1D{ $ҊSfGG࿶M|!s~GE5P:hucApgH`MZdܪ*5 `m?dx^44;}T[Ic3l4 /ɉY&{Z\/*P#Htf[ &zOOBX㪘N3y}?]y Qj'RHn?/Ѩ̴hfb*RBȒBIվ"p&?$T-qȵ# 45;4!eϯ]ԞǙR"rm!_8uэ KQ|"RNrQTm4^h/Neئ~`}wd^zlN`Co0|^x:!\n!9y=`N!{Hm#9O/"3V7?j\W?R>]7 zh恏E<:5Λ}1m hm]YU^[ܾ)i4xH}\:a@\I/uH\0>wnϞJnљl7YPg/l+ fo`Kspp4w6^obhЪz/9r"u"8oMuk>}w"j X$aeUly$FS1X03Kˤ5 o1rTp-ทJ KtgB(#*vC5|\Z 5,$'l[f qe܅lvgEQt6-,w:Z)p0Dl=ZٛNSQGXBTc˴)[Dm oM2 GpRPZu1S!2iL1B I?3rdg=706czLVDGɇv5cH Z^b:fܙ,h5b6 iT(лS_>!aAt4x^1~HK+\G>?ɹYAP>t9z +1Y_^5;'f1T|9& -Vy4†廾(К7ÓKL!:Yݳ[%Ca. s2:K׫Fc&oE;Cg!ڈaic$W5U~dO,+5UaB_R G*;CP5ǠZv˵*K^9+s 8™ЖsksRC_<]Q݄G[ DJ,óvU5T7A絀n3r)-& dc,h&Z-WZTYct1lĺh[ah^ibHηhJغ,~옆NHt貭X)G7$B%׿:*ҏtTSy>.lKt1 E .9!IN :0\崇M@aR t5OKzzW-W T笯WD!{pf"ԶzB qYxz|U}%[226#b}Y\M` S F ,F}N Y'2 t; ?l*M f)AjJ@ ū󜬜PTķ#D/bDU[- qaWyq4t_D?!w89bAiG|Ҕ.zl -H71yRNwA$2r<~_Cd Dae g59@~n%3qGDSVWz Vܮ#~"ۮi)]`qkTIXBҬ7H%31Ƽ&ZMXT3Iw V7$V&~DrY̤BQt|JC͏ekN$]@pȡNv[ͷ'Z' ])yBFɗ&R~=8̡8L5@M$K=`|R5X53_20b~O;tŀ`fQ]&N|3O3dGKIC\pF\*EujYHFG,j;͙Mwe=2M5"qZWp"NuLl2c~ [k2ᐣ AճP޶񛻅8BQMz{ZٝF>lh-QS$>1V&j,RaZ͛nl\yjYOK򰁘d>R$$`.Bn7,3SRLoJXKdXIJ< E 'h]LswČ P !n^~u#xFoZ y] 2(,X7Kv #¾}&_SG|4#`D0e8ݴ Idb.6@~XN@$(Jrm!q"XdWE~4lˈ'.@*'{Ž|!f1￘iJ^ Ì&s=|yq[b]:L]DI:/e{*W÷M$7ơIPPYNnPYP 6bV<µLHoM~Tݡi??w(Kz E'uqPLf@so3qb*"Ng{y_2kּ('eT֜~B@iPτig)b@V&]qUaP$29#=zMڜkm[~Qcgbωӳ= mryNofEY\"<+NT8:w7Q>|&eBgHQu(.ĜpB-FUпEaUrE$?^Ȏr[ 8 :r Cգjy`%xB3Zz9*zjO6W!ALJŇ">Wc+꿦*6 BgADbwInuB%5'EWH{s.&YQ/ 9n ꜡!$dr*-A;D߰:]226٢(E\H1GtUt61`1Aj c> /QIf'^S NV<|]JNDQ) nت(Ql5&{48lPE0MlKȮȞ1,~IܔNv 킆\8#OZVp.wLjϦ#&8Vy=ϻ˂ B.9[Mޔ|Dp`DXuWp#<Cê$fo'U+^Ғe; CAG~, T<Ha}#3[nZ)A7z}fn>NaZV"JF?{"@BXƏ"{. ނ)zD[E1x[ణҼF;2pc ;r)>Ew$Fޕ.r0]#KShs۱2guĭ{Jgw􊑵8j+HFI9`eչ %~:0.v#VKFBZ&h{5QN:kQ34K_T9?rW |7g f֞ξ6J-B'!,fVHHAݺ͛X8ȕ'u9rLNsEy_P|ƣ Ui P@ohJQ쎜WjQ0n#I;gv#΄tʼnW [6twz5ʺbȍj61}#e`c!tR;rGhοl$70.&K";:G_ nYhs(*kpA,RYnaj#F5-½L+\-3ɚ""d!iv2]HIBF;)qÁ X3s|G7HG]ZT>BYWifdpr~>C(W^+:ino KSՀ:Bj ȭ{1g-96HmO{fnȎr;hb$#< @W re$/@k]&~@Ha}r2jW*?8.eoʄ>*{嶣a`Pn~BOcX2:婒&0Ov8 .uTq`2H|AB:JНo% 0RR04 b*_y$ BsB?\]n_=K,u5$ Q/GV-RB2}(W 4ݶQ n$NGZ }mhd YbwXQ p9dN_^5f uuCn2@7lI2umpx5 j %/V$~94>VzL竄B0:?N`>'GgA&nҔ vaD tYy8Wm&l`Xh'v4U3d/Yӗ-|%]Ŀ*k#! ۡs!Ai!Xfh.|G_ njtM:ǘp4o0B17IeRGuëdsGuԼڅhYs O .#`mpۀ7ݼ}<Ւy'/ЛGiBc{_ߑfLJHلΨՎ4kZn(A4{?4w#ߖೞJ 82shU>]$ф& %R^? f)QLy<Lߔ`Pbg)]CRb bcU63DxUM4f1ivk ڌ(E;w09eh=Rg6!<76(H7B1{A+q~DW1|Fک%wj:6LA_>eu֪C=Ф+A,0e dߗƹ?ɶ&k&M͝r,^^#qp(˾Dz,wLj;>t֬ ,THU$87˻Aez?QNM2T;2]ߨ2h'[pVHb`XV.0 oDJWzj#EX8<^=Pz$F<ϬUt(ah^:\DCDŽɴ\NT|>jVʿ]fL5˙= ?& w$f6Bpn0eehw>ס1tWu(q݁EHĜDK6;ց?fg0D_3ӂ)+yz0xy4B ȶ+s2=wA}2xD`D- T~0M 4]Ac z]ex󆀹}C ?iYyv A>sl*T5D堼K3 # V- : 970Knoody)փof6=YظBy TߘqIzzD(uh$m?*iݛLtV QnY-r+˖2&  ^+o+xc)^Z 7V5PG:hʔzP:\E*^K Ilt bCV</dF]=a0D? k F xp63FIF9uI Ff؟5e}M8tnf[r\`%V`Ĭ^ qQezdӊSUr]f4ڐoO+{RrϱeN X1v{_2.^JyHߊv ^^.'Aci{oB*;h PlqV?cس4TUrQ B]Y Sgc]ۭ:p1Rn$kPP͟o4[Uz$m{mKbY'zH0a“߃j[# yBĿUc:0>ŰJ jU,yEǼ Mn[z^i)!CbU# \/t}Te"ɄB+xN3\Y_-O_ݳ̶sD`GeS4Ƭ}S'5û +?py9HH 9s;% >r؏ᐵ[w Sʘ-c4@iCR89q69ge.&Y?H`PF(˖Ng_|7/Ϩ@ i): ɍx!u6gC  x ?/84Dְ‡ڴxw0 _{ۮ]Jm蠆VqKޔC$[ CNAn ^Ii|nM8SߢMj^Spe]-R8誚p GUn` Ems$XoY#;I 3- i.97)$G^v0(o()7E]&y-Ǔ=ϱw??۽(Zߤ5W VB\Tn+CueR&Y/hmԔ l<4=_|ԯ3=̈؅zN{{LO{P}i?Zd(h*=5e!(uF4ZrLR8MJX@KLC(%f{Vf]vLrCK$!eR\bտүdvݫE] EY{@!\-jy&| DVΔk8>G`4yi8 ټ`Ռ?`*3Z_;זڰSs t0f۫M?d`L={`}56$e6;nY >3 S㥍{ۉW, `#oXt1 3wfKV2:&,gI ,MxsL’S65nKZ8f#ճnҁXou<:xj Qwsj8} :Fk1Nr'f*U{d%_8VMf3 B'֭9v|PP.S[a.>&dy4x0%gi_&xW/NB=](A%wc"N HAF'Krܘ/`kGd$j(7-uвڏn LP^æu%\-q?KvSnlK2in4WI !¾u\f|2L^u" څ/͗ =CGEڭtzu$PHM4vU.t=g8_#h[@xԟp$i ɈupK_Rɭau-EkR}u|GOiAR1)L:%r:sg9=|F- i(wq0ڮYBrI ,jJ8(6gutpAӒsTD;OhaOI\0 | [sZ= Z1 rt3Ӭ~j@cpb툈gvp#N-?__ɂH4wKj;E8] s/P{6rGe~-!vX59?g(h\vܮw.Ms c y_Fܖ:,5!.}TmRyʒ'B 5,Cn ϟ `гO||x,옜P"<' ~%J:D:X595HvX -6y|y"ܓӇ7dJZP`b?:-tQ#%vQ:ޡC]^ǿ:gĶ \eil# }1 y=Lpv[Iy~IqlyJpĪ w,D)nq+6d&oՎ&hع`a<$doZ'+X +jjP^lc>k#%1 #6p V-  AJxPZfߐqj;1UG"fj͋ri"{ 1#AHގqezq<#T9/͞JӨ7/!$]oy4ijәiBw˷r4ϵ6hJ`FǺ`p3ln'~>3M+1$dN0LqF, nV0L21iUӐߖ@K&Z=*\Vb'{:'K`uyKP)2ɺzyCqJ xWpf=Ϋە냞E!Ժv4teHCcecrºEyRsi0ߠbG9!T12k;"\ yZS24Rﵙ D׷5JB\riVrvz z T%*Brî*3II}l%g kLZa SxQ 1'z}x($L&%fN;<5U=kwU-տ<݄W6{!rSv^&}-,?:隷HtEXYRDpc,0N4hw K@1URrDVF~t; rƮY% /0SxmMXœma"( WȫAM*)7p.)B^zpY]5L.l]1$G&AN0W[? rnGVReԖ;*BA)Uo][׻j.\6kv.qqȽFKw9M9<3*;d~FW7u]/`r@bÍ&ѩ(B98,Wkap$dCkb?w߹״윒'V}J:؎OE` @(BTR}86;'(%cpKYjggp+,>tWYJ4@ljA4By j/P72+R%ĮJkdHsY [$C7\KG [FDl3I'0]K+k5J29Hމf #)TgiQ9!|oG6Ča y:k%ZH"1r:~F_ɾ##Y=ȺDc5zћ?_w&3>mIڲKY eK4H=bYd };ю$e{% }*6d3<.x88EIĈmV{Sl̶bҔ5~)=MrJq<4}FՋ6+71v/W&D5R[*_Ξz6=FUap஽4,WtE\/hwpJR`6h 1(ފBst5?4މP}C/GS]$6YPHp'-D^+/q-e۴>]3\E3#sTTuvat ⺫v%jZf%YU A65FRܪ[g\)pCDC'HŖ.|kjQ-K{R63E ;X_xY|)C[or T󺤋^ֳd[.M 4%`1C;)">)"OB= N%xBVBFD?G$PVҢz|q ¸Vg'r9MGMA_ hRo䫡\k'- t"!/@V/]) 8<C uL a0{MM0fK,!;$L:',| Fn]ebD4Ã~# zF'U`|=do8BA&L@H}o6R>66a|Xѥ.9b i0ℲeT c <[&mKjAtp'=39Hz]g%o vkX yǩ<hMIaVG?q/Ao&dOXަܞ#B%pGJuP9tJ0ՊJyu⡆"3J]f9:orB cc*ڐ`$O_h4~_6?V #No?sE`5(՜ӥiqpA`2S/Pþ4E'4X{g6ڗƮޥYW!7N9 +vB$es(~8=hK=uZY:_`X0KW*vϟ!Lzfh9h,5WMk6A&/M^lSf}Pn[%lk&6W~rIaE]!>$]yꇉoC%!H_'Q@_T9X=y[Cb@gfo}&["S`U6:0 D8*>taMMS4IwkD&otZ,O'e~!f&豮I d @m?c$̑Z4Y'UЕ3gBSv\UتNT̥[7f@$G-`7k+5%=10ԐIImI@_a7GwӉs ~J>ɹ(^fј8p18caVd%I" Aopx/q[խ+^IR0m ">C &r#Lga/xtu&du`dDEA**h>Ï6tT Əu R󠒒CTȗ@,JvS?B,eok pjɂJVmPq?2srk<4UgDqkiT=?*.\J)9Sx3J4m7{o;e "=bmZ+> aO ZKܞxh/j7Ycbt[b{L)ƁEA) 8c`A?B<.]Dnlf&}SlɝN۴:%t._ .\쭼0IcKxˌz1vdžnO!2ecYeQ2Ȉ q^4GT5 ;݂F1*s'A?rv1ۺ bhnIeZl}e9 FRvqTW;.O ʟc*8KQ7:'>1~TYpRb@UXS:˰TTI0X&:&O^oܩWY;p*.i4  vr)pc:eDر6ToE'bw,c$IiU͐?.skǖJCq+=vSGޯY.'F87jAo$ .by|RV::--zhaVᔍ{yaL`5p5Ee|:~ӁwXf[.]Nf\19n>D|/EOppm `S#+Y&'lZ^wL->CPagײC@v)[~~Wj:6QSl\XTR5Ƿ@ *Ueͧ{V7Re!0xJݩmd0Ӊ0b@gp][?ft|4[2ѭ^fކm׸֙p < \qI w/.]Ss KS#a/u&<˥s~X% )QAOGF唈 3=4܂eH?zF9bnðe+It@C#{z{WPS鋈yμbhD]3=/ >T(lZQ2&q)2PT{>B4sgENuXzY&?te0W9Ljݠ-a|CTˑDOyƯm¯j OX{`N_VhGlg(nz Miċ9rg\Ф{,:eQfY7 /q@PRL!j@Qe ޭқM$abLS.hByssKEڭy.4-}"{i~UBG q73)$K>:ItƐ ϸI9$17#eSki 럌<SQMׂjs}Qz RrX9.xJHw,nI?#O !r LvY;PkGbKõ4ǹN)O#>+#]cr3i#W{>3s#FfBA`2>d7R?CP5-bFӧh݌[=ﵰhj) G YZ