nss-devel-3.28.4-4.el6_9$>Rx~'pNgU;>80? d   O CIP33 3 3 3 g3 3h3g3f3P(8 9 :O G3H3I3XY\ 3]3^bdYe^falct|3uH3vwp3x<3yCnss-devel3.28.44.el6_9Development libraries for Network Security ServicesHeader and Library files for doing development with Network Security Services.YOc1bl.rdu2.centos.org CentOSMPLv2.0CentOS BuildSystem Development/Librarieshttp://www.mozilla.org/projects/security/pki/nss/linuxx86_64  YRCyQ - 3.28.4-4Daiki Ueno - 3.28.4-3Kai Engert - 3.28.4-2Daiki Ueno - 3.28.4-1Daiki Ueno - 3.28.3-3Daiki Ueno - 3.28.3-2Daiki Ueno - 3.28.3-1Daiki Ueno - 3.27.1-13Daiki Ueno - 3.27.1-12Daiki Ueno - 3.27.1-11Daiki Ueno - 3.27.1-10Daiki Ueno - 3.27.1-9Daiki Ueno - 3.27.1-8Daiki Ueno - 3.27.1-7Kai Engert - 3.27.1-6Kai Engert - 3.27.1-5Kai Engert - 3.27.1-4Kai Engert - 3.27.1-3Daiki Ueno - 3.27.1-2Daiki Ueno - 3.27.1-1Kai Engert - 3.21.0-8Elio Maldonado - 3.21.0-7Elio Maldonado - 3.21.0-6Elio Maldonado - 3.21.0-5Elio Maldonado - 3.21.0-4Elio Maldonado - 3.21.0-3Elio Maldonado - 3.21.0-2Elio Maldonado - 3.21.0-1Elio Maldonado - 3.19.1-9Elio Maldonado - 3.19.1-7Elio Maldonado - 3.19.1-6Elio Maldonado - 3.19.1-5Elio Maldonado - 3.19.1-4Kai Engert - 3.19.1-3Kai Engert - 3.19.1-2Elio Maldonado - 3.19.1-1Kai Engert - 3.18.0-5.3Elio Maldonado - 3.18.0-5Elio Maldonado - 3.18.0-4Elio Maldonado - 3.18.0-3Elio Maldonado - 3.18.0-2Elio Maldonado - 3.18.0-1Elio Maldonado - 3.16.2.3-4Elio Maldonado - 3.16.2.3-3Elio Maldonado - 3.16.2.3-1Elio Maldonado - 3.16.1-14Elio Maldonado - 3.16.1-13Elio Maldonado - 3.16.1-12Elio Maldonado - 3.16.1-11Elio Maldonado - 3.16.1-10Elio Maldonado - 3.16.1-9Elio Maldonado - 3.16.1-8Elio Maldonado - 3.16.1-7Elio Maldonado - 3.16.1-6Elio Maldonado - 3.16.1-5Elio Maldonado - 3.16.1-4Elio Maldonado - 3.16.1-3Elio Maldonado - 3.16.1-2Elio Maldonado - 3.16.1-1Elio Maldonado - 3.15.3-11Elio Maldonado - 3.15.3-10Elio Maldonado - 3.15.3-9Elio Maldonado - 3.15.3-8Elio Maldonado - 3.15.3-7Elio Maldonado - 3.15.3-6Elio Maldonado - 3.15.3-5Elio Maldonado - 3.15.3-4Elio Maldonado - 3.15.3-3Elio Maldonado - 3.15.3-2Elio Maldonado - 3.15.3-1Elio Maldonado - 3.15.1-15Elio Maldonado - 3.15.1-14Elio Maldonado - 3.15.1-13Elio Maldonado - 3.15.1-12Elio Maldonado - 3.15.1-11Elio Maldonado - 3.15.1-10Elio Maldonado - 3.15.1-9Elio Maldonado - 3.15.1-8Kai Engert - 3.15.1-7Elio Maldonado - 3.15.1-6Elio Maldonado - 3.15.1-5Elio Maldonado - 3.15.1-4Elio Maldonado - 3.15.1-3Elio Maldonado - 3.15.1-2Elio Maldonado - 3.15.1-1Elio Maldonado - 3.14.3-37Elio Maldonado - 3.14.3-36Elio Maldonado - 3.14.3-35Elio Maldonado - 3.14.3-34Kai Engert - 3.14.3-33Elio Maldonado - 3.14.3-5Elio Maldonado - 3.14.3-4Elio Maldonado - 3.14.3-3Elio Maldonado - 3.14.3-2Elio Maldonado - 3.14.3-1Elio Maldonado - 3.14.0.0-12Elio Maldonado - 3.14.0.0-11Elio Maldonado - 3.14.0.0-10Elio Maldonado - 3.14.0.0-9Elio Maldonado - 3.14.0.0-8Elio Maldonado - 3.14.0.0-7Elio Maldonado - 3.14.0.0-6Elio Maldonado - 3.14.0.0-5Elio Maldonado - 3.14.0.0-4Kai Engert - 3.14.0.0-3Bob Relyea - 3.14.0.0-2Elio Maldonado - 3.14.0.0-1Elio Maldonado - 3.13.5-3Elio Maldonado - 3.13.5-2Elio Maldonado - 3.13.5-1Elio Maldonado - 3.13.3-7Elio Maldonado - 3.13.3-6Elio Maldonado Batiz - 3.13.3-5Elio Maldonado Batiz - 3.13.3-4Elio Maldonado - 3.13.3-3Elio Maldonado - 3.13.3-2Elio Maldonado - 3.13.3-1Elio Maldonado Batiz - 3.13.1-6Elio Maldonado - 3.13.1-5Elio Maldonado - 3.13.1-4Elio Maldonado - 3.13.1-4Martin Stransky 3.13.1-3Elio Maldonado Batiz - 3.13.1-2Elio Maldonado - 3.13.1-1Elio Maldonado - 3.12.10-17Elio Maldonado - 3.12.10-16Elio Maldonado - 3.12.10-15Elio Maldonado - 3.12.10-14Elio Maldonado - 3.12.10-13Elio Maldonado - 3.12.10-12Elio Maldonado - 3.12.10-11Elio Maldonado - 3.12.10-10Elio Maldonado - 3.12.10-9Elio Maldonado - 3.12.10-8Elio Maldonado - 3.12.10-7Elio Maldonado - 3.12.10-6Elio Maldonado - 3.12.10-5Elio Maldonado - 3.12.10-4Elio Maldonado - 3.12.10-3Elio Maldonado - 3.12.10-2Elio Maldonado - 3.12.10-1Elio Maldonado - 3.12.9-11Elio Maldonado - 3.12.9-10Elio Maldonado Batiz - 3.12.9-9Elio Maldonado - 3.12.9-8Elio Maldonado - 3.12.9-7Elio Maldonado - 3.12.9-6Elio Maldonado - 3.12.9-5Elio Maldonado - 3.12.9-4Elio Maldonado - 3.12.9-3Elio Maldonado - 3.12.9-2Elio Maldonado - 3.12.9-1Elio Maldonado - 3.12.8-2Elio Maldonado - 3.12.8-1Kai Engert - 3.12.7-2Elio Maldonado - 3.12.7-1Elio Maldonado - 3.12.6-6Elio Maldonado - 3.12.6-5Elio Maldonado - 3.12.6-4Elio Maldonado - 3.12.6-3Elio Maldonado - 3.12.6-2Elio Maldonado - 3.12.6-1.2Elio Maldonado - 3.12.6-1.1Elio Maldonado - 3.12.6-1Elio Maldonado - 3.12.5.99-1Elio Maldonado - 3.12.5-8Elio Maldonado - 3.12.5-7.3Elio Maldonado - 3.12.5-7.2Elio Maldonado - 3.12.5-7.1Elio Maldonado - 3.12.5-7Elio Maldonado - 3.12.5-6Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-2Elio Maldonado - 3.12.5-1.14Elio Maldonado - 3.12.5-1.12.1Elio Maldonado - 3.12.5-1.11Elio maldonado - 3.12.5-1.10Elio Maldonado - 3.12.5-1.8Elio Maldonado - 3.12.5-2.1Elio Maldonado - 3.12.5-1.2Elio Maldonado - 3.12.4-15Elio Maldonado - 3.12.4-14Elio Maldonado - 3.12.4-12Elio Maldonado - 3.12.4-11Elio Maldonado - 3.12.4-10Elio Maldonado - 3.12.4-8Elio Maldonado - 3.12.4-6Elio Maldonado - 3.12.4-5Elio Maldonado - 3.12.4-4Elio Maldonado - 3.12.4-3Elio Maldonado - 3.12.4-2Elio Maldonado - 3.12.4-1Elio Maldonado - 3.12.3.99.3-30Elio Maldonado - 3.12.3.99.3-29Elio Maldonado - 3.12.3.99.3-28Elio Maldonado - 3.12.3.99.3-27Elio Maldonado - 3.12.3.99.3-26Elio Maldonado - 3.12.3.99.3-25Warren Togami - 3.12.3.99.3-24Elio Maldonado - 3.12.3.99.3-23Elio Maldonado - 3.12.3.99.3-22Elio Maldonado - 3.12.3.99.3-21Elio Maldonado - 3.12.3.99.3-20Elio Maldonado - 3.12.3.99.3-19Elio Maldonado - 3.12.3.99.3-18Elio Maldonado - 3.12.3.99.3-16Dennis Gilmore - 3.12.3.99.3-15Dennis Gilmore - 3.12.3.99.3-14Dennis Gilmore - 3.12.3.99.3-13Dennis Gilmore - 3.12.3.99.3-12Elio Maldonado+emaldona@redhat.com - 3.12.3.99.3-11Elio Maldonado - 3.12.3.99.3-10Dennis Gilmore - 3.12.3.99.3-9Elio Maldonado - 3.12.3.99.3-7.1Fedora Release Engineering - 3.12.3.99.3-7Elio Maldonado - 3.12.3.99.3-6Elio Maldonado - 3.12.3.99.3-5Elio Maldonado - 3.12.3.99.3-4Kai Engert - 3.12.3.99.3-3Kai Engert - 3.12.3.99.3-2Kai Engert - 3.12.3-7Kai Engert - 3.12.3-4Kai Engert - 3.12.3-3Kai Engert - 3.12.3-2Kai Engert - 3.12.2.99.3-7Kai Engert - 3.12.2.99.3-6Kai Engert - 3.12.2.99.3-5Kai Engert - 3.12.2.99.3-4Kai Engert - 3.12.2.99.3-3Kai Engert - 3.12.2.99.3-2Kai Engert - 3.12.2.99.3-1Fedora Release Engineering - 3.12.2.0-4Kai Engert - 3.12.2.0-3Dennis Gilmore - 3.12.1.1-4Kai Engert - 3.12.1.1-3Kai Engert - 3.12.1.1-2Kai Engert - 3.12.1.0-2Kai Engert - 3.12.0.3-7Kai Engert - 3.12.0.3-6Kai Engert - 3.12.0.3-3Kai Engert - 3.12.0.3-2Kai Engert - 3.12.0.1-1Jesse Keating - 3.11.99.5-2Kai Engert - 3.11.99.5-1Kai Engert - 3.11.99.4-1Kai Engert - 3.11.99.3-6Kai Engert - 3.11.99.3-5Kai Engert - 3.11.99.3-4Kai Engert - 3.11.99.3-3Kai Engert - 3.11.99.3-2Kai Engert - 3.11.99.3-1Kai Engert - 3.11.99.2b-3Kai Engert - 3.11.99.2b-2Kai Engert - 3.11.99.2-2Kai Engert - 3.11.99.2-1Kai Engert - 3.11.7-10Rob Crittenden - 3.11.7-9Kai Engert - 3.11.7-8Bob Relyea - 3.11.7-7Kai Engert - 3.11.7-6Kai Engert - 3.11.7-5Kai Engert - 3.11.7-4Kai Engert - 3.11.7-3Kai Engert - 3.11.7-2Kai Engert - 3.11.5-2Kai Engert - 3.11.5-1Bob Relyea - 3.11.4-4Kai Engert - 3.11.4-1Kai Engert - 3.11.3-2Kai Engert - 3.11.3-1Kai Engert - 3.11.2-2Jesse Keating - 3.11.2-1.1Kai Engert - 3.11.2-1Kai Engert - 3.11.1-2Kai Engert - 3.11.1-1Kai Engert - 3.11-4Jesse Keating - 3.11-3.2Jesse Keating - 3.11-3.1Ray Strode 3.11-3Christopher Aillon 3.11-2Christopher Aillon 3.11-1Christopher Aillon 3.11-0.cvs.2Christopher Aillon 3.11-0.cvsKai Engert Rob Crittenden 3.10-1- Backport patch to simplify transcript calculation for CertificateVerify- Fix zero-length record treatment for stream ciphers and SSLv2- Include CKBI 2.14 and updated CA constraints from NSS 3.28.5- Rebase to 3.28.4- Fix crash with tstclnt -W - Adjust gtests to run with our old softoken and downstream patches- Avoid cipher suite ordering change, spotted by Hubert Kario- Rebase to 3.28.3 - Remove upstreamed moz-1282627-rh-1294606.patch, moz-1312141-rh-1387811.patch, moz-1315936.patch, and moz-1318561.patch - Remove no longer necessary nss-duplicate-ciphers.patch - Disable X25519 and exclude tests using it - Catch failed ASN1 decoding of RSA keys, by Kamil Dudka (#1427481)- Update expired PayPalEE.cert- Disable unsupported test cases in ssl_gtests- Adjust the sslstress.txt filename so that it matches with the disableSSL2tests patch ported from RHEL 7 - Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests - Don't add gtests and ssl_gtests to nss_tests, unless gtests are enabled- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release - Add patch to fix bash syntax error in tests/ssl.sh - Add patch to remove duplicate ciphersuites entries in sslinfo.c - Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range - Build with support for SSLKEYLOGFILE- Update fix_multiple_open patch to fix regression in openldap client - Remove pk11_genobj_leak patch, which caused crash with Firefox - Add comment in the policy file to preserve the last empty line - Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not provided by softoken; this superseds check_hash_impl patch- Fix problem in check_hash_impl patch- Add patch to check if hash algorithms are backed by a token - Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256, which have never enabled in the past- Add upstream patch to fix a crash. Mozilla #1315936- Disable the use of RSA-PSS with SSL/TLS. #1390161- Use updated upstream patch for RH bug 1387811- Added upstream patches to fix RH bugs 1057388, 1294606, 1387811- Enable gtests when requested- Rebase to NSS 3.27.1 - Remove nss-646045.patch, which is not necessary - Remove p-disable-md5-590364-reversed.patch, which is no-op here, because the patched code is removed later in %setup - Remove disable_hw_gcm.patch, which is no-op here, because the patched code is removed later in %setup. Also remove NSS_DISABLE_HW_GCM setting, which was only required for RHEL 5 - Add Bug-1001841-disable-sslv2-libssl.patch and Bug-1001841-disable-sslv2-tests.patch, which completedly disable EXPORT ciphersuites. Ported from RHEL 7 - Remove disable-export-suites-tests.patch, which is covered by Bug-1001841-disable-sslv2-tests.patch - Remove nss-ca-2.6-enable-legacy.patch, as we decided to not allow 1024 legacy CA certificates - Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits - Remove nss-init-ss-sec-certs-null.patch, which appears to be no-op, as it clears memory area allocated with PORT_ZAlloc() - Remove nss-disable-sslv2-libssl.patch, nss-disable-sslv2-tests.patch, sslauth-no-v2.patch, and nss-sslstress-txt-ssl3-lower-value-in-range.patch as SSLv2 is already disabled in upstream - Remove fix-nss-test-filtering.patch, which is fixed in upstream - Add nss-check-policy-file.patch from Fedora - Install policy config in /etc/pki/nss-legacy/nss-rhel6.config- Ensure all ssl.sh tests are executed- Update sslauth patch to run more tests- Fix syntax errors in patch that disables sslv2 tests - Resolves: Bug 1297888 - Rebase RHEL 6.8 to NSS 3.21 for Firefox 45- Resolves: Bug 1304812 - Disable support for SSLv2 completely.- Add patches for ABI compatibility- Disable extended master-secret due to older version of softoken- Enable two additional ciphers and keep another one disabled - Prevent enabling extended masker key derive- Rebase to NSS-3.21- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol - Resolves: Bug 1289890- Package listsuites as part of the unsupported tools set - Resolves: Bug 1283655- Resolves: Bug 1272504 - Enable TLS 1.2 as the default in nss- Rebuild against updated NSPR- Sync up with the rhel-6.6 branch - Resolves: Bug 1224450- Additional NULL initialization.- Updated the patch to keep old cipher suite order - Resolves: Bug 1224450- Rebase to nss-3.19.1 - Resolves: Bug 1224450- On RHEL 6.x keep the TLS version defaults unchanged. - Require softokn build 22 to ensure runtime compatibility. - Relax the requirement from pkcs11-devel to nss-softokn-freebl-devel to allow same or newer. - Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1)- Update and reeneable nss-646045.patch on account of the rebase - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1]- Fix shell syntax error in nss/tests/all.sh - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Restore a patch that had been mistakenly disabled - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Replace expired PayPal test certificate that breaks the build - Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] - Resolves: Bug 1131311 - rhel65 ns-slapd crash, segfault error 4 in libnss3.so in PK11_DoesMechanism at pk11slot.c:1824 - Temporarily disable some tests until expired PayPalEE.cert is renewed- Keep the same cipher suite order as we had in NSS_3_15_3_RTM - Resolves: Bug 1123092 - openldap-2.4.23-34.el6_5.1.i686 fails after updating nss to nss-3.16.1-4.el6_5.i686- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 - Remove unused indentation pseudo patch - require nss util 3.16.2.3 - Restore patch for certutil man page - supply missing options descriptions to the man page- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Resolves: Bug 1145432 - CVE-2014-1568- Fix pem deadlock caused by previous version of a fix for a race condition - Fixes: Bug 1090681- Add references to bugs filed upstream - Related: Bug 1090681, Bug 1104300- Resolves: Bug 1090681 - RHDS 9.1 389-ds-base-1.2.11.15-31 crash in PK11_DoesMechanism- Replace expired PayPal test certificate that breaks the build - Related: Bug 1099619- Fix defects found by coverity - Resolves: Bug 1104300- Backport nss-3.12.6 upstream fix required by Firefox 31 - Resolves: Bug 1099619- Update nspr-version to 4.10.6- Update pem sources to the same ones used on rhel-7 - Remove no longer needed patches on account of this update - Resolves: Bug 1002205- Move removal of directories to the end of the %prep section - Resolves: Bug 689919 - build without any softoken or util sources in the tree- Remove unused patches rendered obsolete- Fix pem module trashing of private keys on failed login - Resolves: Bug 1002205 - PEM module trashes private keys if login fails- Restore use of indentation patch until another bug is resolved - Resolves: Bug 606022 - nss security tools lack man pages- Update to nss-3.16.1 - Resolves: Bug 1099619 - Rebase nss in RHEL 6.6 to NSS 3.16.1- Resolves: Bug 689919 - build without any softoken or util sources in the tree - Add define-uint32.patch to deal with using older version of nss-softokn - Fix suboptimal test failure detection shell code in the %check section- Prevent users from disabling the internal crypto module - Resolves: Bug 1059176 - nss segfaults with opencryptoki module- Improve support for ECDSA algorithm via pluggable ECC - Document the purpose of the iquote.patch - Resolves: Bug 1057224 - Pluggable ECC in NSS not enabled on RHEL 6 and above- Install man pages for the nss security tools - Resolves: Bug 606022 - nss security tools lack man pages- Fix the numbering and naming of the patches - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- make derEncodingsMatch work with encrypted keys - rename a patch, dropped the experimental moniker from it - Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL- Revoke trust in one mis-issued anssi certificate - Resolves: Bug 1042686 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6]- Disable hw gcm on rhel-5 based build environments where OS lacks support - Rollback changes to build nss without softokn until Bug 689919 is approved - Cipher suite was run as part of the nss-softokn build- Build nss without softoken, freebl, or util sources in the build source tree - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Update to NSS_3_15_3_RTM - Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 - Resolves: Bug 1031238 - deadlock in trust domain lock and object lock- Using export NSS_DISABLE_HW_GCM=1 to deal with some problemmatic build systems - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add s390x and ia64 to the %define multilib_arches list used for defining alt_ckbi - Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so- Add zero default value to DISABLETEST check and fix the TEST_FAILURES check and reporting - Resolves: rhbz#990631 - file permissions of pkcs11.txt/secmod.db must be kept when modified by NSS - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Add a zero default value to the DISABLETEST and TEST_FAILURES checks - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix the test for zero failures in the %check section - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Restore a mistakenly removed patch - Resolves: rhbz#961659 - SQL backend does not reload certificates- Rebuild for the pem module to link with freel from nss-softokn-3.14.3-6.el6 - Related: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] - Related: rhbz#1010224 - NSS 3.15 breaks SSL in OpenLDAP clients- Don't require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Additional syntax fixes in nss-versus-softoken-test.patch - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix all.sh test for which application was last build by updating nss-versus-softoken-test.path - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Disable the cipher suite already run as part of the nss-softokn build - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nss-softokn-fips - Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Require nspr-4.10.0 - Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Fix relative path in %check section to prevent undetected test failures - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x)- Rebase to NSS_3.15.1_RTM - Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) - Update patches on account of the shallow tree with the rebase to 3.15.1 - Update the pem module sources nss-pem-20130405.tar.bz2 with latest patches applied - Remove patches rendered obsolete by the nss rebase and the updated nss-pem sources - Enable the iquote.patch to access newly introduced types- Do not hold issuer certificate handles in the crl cache - Resolves: rhbz#961659 - SQL backend does not reload certificates- Resolves: rhbz#977341 - nss-tools certutil -H does not list all options- Resolves: rhbz#702083 - dont require unique file basenames- Fix race condition in cert code related to smart cards - Resolves: rhbz#903017 - Firefox hang when CAC/PIV smart card certificates are viewed in the certificate manager- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement. Please ensure that older packages that don't use the alternatives system for libnssckbi.so have a smaller n-v-r.- Syncup with uptream changes for aes gcm and ecc suiteb - Enable ecc support for suite b - Apply several upstream AES GCM fixes - Use the pristine nss upstream sources with ecc included - Export NSS_ENABLE_ECC=1 in both the build and the check sections - Make failed requests for unsupoprted ssl pkcs 11 bypass non fatal - Resolves: rhbz#882408 - NSS_NO_PKCS11_BYPASS must preserve ABI - Related: rhbz#918950 - rebase nss to 3.14.3- Revert to accepting MD5 on digital signatures by default - Resolves: rhbz#918136 - nss 3.14 - MD5 hash algorithm disabled- Ensure pem uses system freebl as with this update freebl brings in new API's - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Install sechash.h and secmodt.h which are now provided by nss-devel - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Remove unsafe -r option from commands that remove headers already shipped by nss-util and nss-softoken- Update to NSS_3.14.3_RTM - Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue - Update expired test certificates (fixed in upstream bug 852781) - Sync up pem module's rsawrapr.c with softoken's upstream changes for nss-3.14.3 - Reactivate the aia tests- Recreate the distrust patch by backporting the upstream one - Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate- Remove a patch that caused a regression - Resolves: rhbz#883620- Fix locking issue causing curl hangs and authenticate to the correct session - Resolves: rhbz#872838- PEM peminit returns CKR_CANT_LOCK when needed to inform caller module isn't thread safe - Resolves: rhbz#555019 - [PEM] invalid writes in multi-threaded libcurl based application- Add dummy sources file to test for and prevent breaking rhpkg commands - Enable testing for 'rhpk upload' and 'rhpk new-sources' breakage such as hangs - Related: rhbz#837089- Update the license to MPLv2.0 - turn off the aia tests - Resolves: rhbz#837089- Resolves: rhbz#702083 - NSS pem module should not require unique base file names- turn on the aia tests - update nss-589636.patch to apply to httpdserv- turn off aia tests for now- turn off ocsp tests for now- Rebase to nss-3.14.0.0-1 - Resolves: rhbz#837089 - Update ssl-cbc-random-iv patch for new sources - Remove patches rendered obsoleted by rebase to 3.14 - Add a patch to enforce no pkcs11 bypass- Resolves: rhbz#830302 - require nspr 4.9.1- Resolves: rhbz#830302 - revert unwanted changes to nss.pc.in- Resolves: rhbz#830302 - Update RHEL 6.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6- Resolves: rhbz#827351 invalid read and free on invalid cert load failure- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity - Require nss-util 3.13.3- Resolves: rhbz#772628 nss_Init leaks memory- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Use completed patch per code review- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name - Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV- Update to 3.13.3 - Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave - Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes- Resolves: rhbz#746632 - Adjust the patch for new sources- Resolves: rhbz#746632 - pem_CreateObject() leaks memory given a non-existing file name- Resolves: 784674 - Protect NSS_Shutdown from clients that fail to initialize nss- Add two needed patches - Resolves: rhbz#783315 - Need nss workaround for freebl bug that causes openswan to drop connections - Resolves: rhbz#747387 - Unable to contact LDAP Server during winsync- Rebuild- Resolves: Bug 784490 - CVE-2011-3389 - Activate a patch that was left out in previous build- Resolves: Bug 744070 - Update to 3.13.1 - Resolves: Bug 784674 - nss should protect against being called before nss_Init - Resolves: Bug 784490 - CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)- Resolves: Bug 761086 - Fix nss-735047.patch to not revert the nss-bz689031.patch- Update builtins certs to those from NSSCKBI_1_88_RTM- Bug 747387 - Unable to contact LDAP Server during winsync- Add to the spec file the patch for Bug 671266- More coverity related fixes in the pem module- Coverity related fixes- Add relro support for executables and shared libraries- Add partial RELRO support- Fix the name of the last patch file- Retagging to pick up two missing commits- Update builtins certs to those from NSSCKBI_1_87_RTM- Update builtins certs to those from NSSCKBI_1_86_RTM- Update builtins certs to those from NSSCKBI_1_85_RTM- Fix CMS to verify signed data when SignerInfo indicates signer by subjectKeyID- Fix pem logging to deal with files originally created by root- Retagging for updated patch missing from previous tag- Update to 3.12.10- Resolves: rhbz# 703658 - Fix crmf hard-coded maximum size for wrapped private keys- Resolves: rhbz#688423 - Enable NSS support for pluggable ECC- Add "Conflicts: curl < 7.19.7-26.el6" to fix Bug 694663- Construct private key nickname based on the full pathname of the pem file- Update expired PayPayEE.cert test certificate - Conditionalize some database tests on user not being root- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM- Fix memory leaks caused by SECKEY_ImportDERPublicKey- Short-term fix for ssl test suites hangs on ipv6 type connections- Add requires for pkcs11-devel on nss-softokn-freebl devel - Run the test suites in check section per packaging guidelines- Prefer user database ca cert trust settings system's ones - Swap internal key slot on fips mode switches- Update to 3.12.9 - Fix libnsspem to test for and reject directories- Add suppport for pkcs8 formatted keys in the pem module - Add verify(not md5 size mtime) to configuration files attributes - Prevent nss-sysinit disabling on package upgrade - Create pkcs11.txt with correct permissions regardless of current umask - Add option to setup-nsssysinit.sh to report nss-sysinit status - Update test certificate which had expired- Update to 3.12.8- Increase release version number, no code changes- Update to 3.12.7- Rebuilt- Appying the changes in previous log - Changing some BuildRequires to >= as well - Temporarily disabling all tests for faster builds- Change some = to >= in Requires to enable a rebase next- Fix SIGSEGV within CreateObject (#596783) - Update expired test certificate- Fix nss.pc to not require nss-softokn- rebuilt using nss-util 3.2.6- rebuilt using nspr-devel 4.8.4- Update to 3.12.6- Update to NSS_3_12_6_RC1- Fix curl related regression and general patch code clean up- Resolves: #551784 rebuilt after nss-softokn and nss-util builds - this will generate the coorect nss.spec- rebuilt for RHEL-6 candidate, Resolves: #551784- Updated to 3.12.5 from CVS import from Fedora 12 - Moved blank legacy databases to the lookaside cache - Reenabled the full test suite - Retagging for a RHEL-6-test-build- Retagged- retagging- Fix SIGSEGV on call of NSS_Initialize (#553638)- bump release number and rebuild- Fix nsssysinit to allow root to modify the nss system database (#547860)- Temporarily disabling the ssl tests until Bug 539183 is resolved- Fix an error introduced when adapting the patch for 546211- Remove some left over trace statements from nsssysinit patching- Fix nsssysinit to set the default flags on the crypto module (#545779) - Fix nsssysinit to enable apps to use the system cert store, patch contributed by David Woodhouse (#546221) - Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387) - Sysinit requires coreutils for post install scriplet (#547067) - Remove redundant header from the pem module- Remove unneeded patch- Update to 3.12.5 - CVE-2009-3555 TLS: MITM attacks via session renegotiation- Require nss-softoken of same arch as nss (#527867)- Fix bug where user was prompted for a password when listing keys on an empty system database (#527048) - Fix setup-nsssysinit to handle more general flags formats (#527051)- Fix syntax error in setup-nsssysinit.sh- Fix sysinit to be under mozilla/security/nss/lib- Add nss-sysinit activation/deactivation script- Install blank databases and configuration file for system shared database - nsssysinit queries system for fips mode before relying on environment variable- Restoring nssutil and -rpath-link to nss-config for now - 522477- Add the nss-sysinit subpackage- Installing shared libraries to %{_libdir}- Retagging to pick up new sources- Update pem enabling source tar with latest fixes (509705, 51209)- PEM module implements memory management for internal objects - 509705 - PEM module doesn't crash when processing malformed key files - 512019- Remove symbolic links to shared libraries from devel - 521155 - No rpath-link in nss-softokn-config- Update to 3.12.4- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766 - Fixed requires and buildrequires as per recommendations in spec file review- Restoring patches 2 and 7 as we still compile all sources - Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems- restore require sqlite- Don't require sqlite for nss- Ensure versions in the requires match those used when creating nss.pc- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn - Add a temprary hack to nss.pc.in to unblock builds- caolan's nss.pc patch- Bump the release number for a chained build of nss-util, nss-softokn and nss- Fix nss-config not to include nssutil - Add BuildRequires on nss-softokn and nss-util since build also runs the test suite- disabling all tests while we investigate a buffer overflow bug- disabling some tests while we investigate a buffer overflow bug - 519766- remove patches that are now in nss-softokn and - remove spurious exec-permissions for nss.pc per rpmlint - single requires line in nss.pc.in- Fix BuildRequires: nss-softokn-devel release number- fix nss.pc.in to have one single requires line- cleanups for softokn- remove the softokn subpackages- don install the nss-util pkgconfig bits- remove from -devel the 3 headers that ship in nss-util-devel- kill off the nss-util nss-util-devel subpackages- split off nss-softokn and nss-util as subpackages with their own rpms - first phase of splitting nss-softokn and nss-util as their own packages- must install libnssutil3.since nss-util is untagged at the moment - preserve time stamps when installing various files- dont install libnssutil3.so since its now in nss-util- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- removed two patch files which are no longer needed and fixed previous change log number- updated pem module incorporates various patches - fix off-by-one error when computing size to reduce memory leak. (483855) - fix data type to work on x86_64 systems. (429175) - fix various memory leaks and free internal objects on module unload. (501080) - fix to not clone internal objects in collect_objects(). (501118) - fix to not bypass initialization if module arguments are omitted. (501058) - fix numerous gcc warnings. (500815) - fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191)- add patch for bug 502133 upstream bug 496997- rebuild with higher release number for upgrade sanity- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75- re-enable test suite - add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass- add conflicts info in order to fix bug 499436- ship .chk files instead of running shlibsign at install time - include .chk file in softokn-freebl subpackage - add patch for upstream nss bug 488350- Update to NSS 3.12.3- temporarily disable the test suite because of bug 494266- fix softokn-freebl dependency for multilib (bug 494122)- introduce separate nss-softokn-freebl package- disable execstack when building freebl- add upstream patch to fix bug 483855- build nspr-less freebl library- Update to NSS_3_12_3_BETA4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- update to NSS_3_12_2_RC1 - use system zlib- add sparc64 to the list of 64 bit arches- bug 456847, move pkgconfig requirement to devel package- Update to NSS_3_12_1_RC2- NSS 3.12.1 RC1- fix bug bug 429175 in libpem module- bug 456847, add Requires: pkgconfig- nss package should own /etc/prelink.conf.d folder, rhbz#452062 - use upstream patch to fix test suite abort- Update to NSS_3_12_RC4- Update to NSS_3_12_RC2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache.- Update to NSS_3_12_BETA3- NSS 3.12 Beta 2 - Use /usr/lib{64} as devel libdir, create symbolic links.- Apply upstream patch for bug 417664, enable test suite on pcc.- Support concurrent runs of the test suite on a single build host.- disable test suite on ppc- disable test suite on ppc64- Build against gcc 4.3.0, use workaround for bug 432146 - Run the test suite after the build and abort on failures.* NSS 3.12 Beta 1- move .so files to /lib- NSS 3.12 alpha 2b- upstream patches to avoid calling netstat for random data- NSS 3.12 alpha 2- Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification.- Fix off-by-one error in the PEM module- fix a C++ mode compilation error- Add 3.12 ckfw and libnsspem- Updated license tag- Ensure the workaround for mozilla bug 51429 really get's built.- Better approach to ship freebl/softokn based on 3.11.5 - Remove link time dependency on softokn- Fix unowned directories, rhbz#233890- Update to 3.11.7, but freebl/softokn remain at 3.11.5. - Use a workaround to avoid mozilla bug 51429.- Fix rhbz#230545, failure to enable FIPS mode - Fix rhbz#220542, make NSS more tolerant of resets when in the middle of prompting for a user password.- Update to 3.11.5 - This update fixes two security vulnerabilities with SSL 2 - Do not use -rpath link option - Added several unsupported tools to tools package- disable ECC, cleanout dead code- Update to 3.11.4- Revert the attempt to require latest NSPR, as it is not yet available in the build infrastructure.- Update to 3.11.3- Add /etc/pki/nssdb- rebuild- Update to 3.11.2 - Enable executable bit on shared libs, also fixes debug info.- Enable Elliptic Curve Cryptography (ECC)- Update to 3.11.1 - Include upstream patch to limit curves- add --noexecstack when compiling assembler on x86_64- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- rebuild- Update file list for the devel packages- Update to 3.11- Add patch to allow building on ppc* - Update the pkgconfig file to Require nspr- Initial import into Fedora Core, based on a CVS snapshot of the NSS_3_11_RTM tag - Fix up the pkcs11-devel subpackage to contain the proper headers - Build with RPM_OPT_FLAGS - No need to have rpath of /usr/lib in the pc file- Adressed review comments by Wan-Teh Chang, Bob Relyea, Christopher Aillon.- Initial build  !"#$%&'()*+,-./01233.28.4-4.el6_93.28.43.28.4-4.el6_93.28.4-4.el6_9nss-confignss3cert.hcertdb.hcertt.hcmmf.hcmmft.hcms.hcmsreclist.hcmst.hcrmf.hcrmft.hcryptohi.hcryptoht.hjar-ds.hjar.hjarfile.hkey.hkeyhi.hkeyt.hkeythi.hnss.hnssckbi.hnsspem.hocsp.hocspt.hp12.hp12plcy.hp12t.hpk11func.hpk11pqg.hpk11priv.hpk11pub.hpk11sdr.hpkcs12.hpkcs12t.hpkcs7t.hpreenc.hsechash.hsecmime.hsecmod.hsecmodt.hsecpkcs5.hsecpkcs7.hsmime.hssl.hsslerr.hsslproto.hsslt.hlibcrmf.anss.pc/usr/bin//usr/include//usr/include/nss3//usr/lib64//usr/lib64/pkgconfig/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuASCII textPOSIX shell script text executablecurrent ar archivedirectorypkgconfig fileRPRRR?7zXZ !PH6]]"k%nÍdڴ4Yk(`<͓%BRJIRo8F%$^3 ,[2l?ъ2#'>0j[}D\lзh}$lTx{BY-4^<4(Z$D&@bO=pO"af\sWAvR)(zPbG`r5a;M1<=2M4U@^\+Ib!Lx ը}j$S)!HMiRAjZun*wbvFC3x@z^0+o!D?IGu!mFQUUʗBTYI^~~@C83K)H QJv $#~wc(c ;5ަ^nfLIBLG-Qis1i BKB.47'gu2z*#6_@IċwGcUH~݇~Knx y@:_٧<ⷫ[=IQ&x ]Nzt|9tzzȆ^:GiFCF 9 $m? LJgCF?3-~ S㪗;p.L`4r5ff`" 8ls5Kfr ωA(FziO(}β#_?1.w2:%A4v╎S)1{K-H[OoODh7&ɵX)LD$Ma7W ;wWm@o<'ܼޣ,lR&/X6SNz [u!FYn0~Z.:y~1Zfuʧh~-PwA*s di2=0rCs q<p1kF.#PgkEA V.=Pivn9LmtWD^6e (=3:@fҐvfWqTtueZLr~{tS_<>탥t~tvM&ڼsԦע3FALL>F.9~ex*P /Ϯ2YR+vKbh&KԌe1}O`R ̪ټ Dva6YGTzAHaaBN"8Gj{yVނl4*i?Xgo8WKҼ ꉘ |ҧ89lAy_GWU|UħUVۅ,41Ԍ>x{ləuoj`Ť|VDXOew]U`bc[|Q1VjO~yWJ+؀AVĴ=[ϙgMTxѭ:{ي o+oW"r/ʢO#c4sB/TS|@ϬeZS2 fG[l@9Icw!:0\B;ycM rw~sϸ]]*+wb-ZUn"eb Tf9ux24]G}z-OM"C8z>g9d2nv ˟3P)SC^XcqX*PgfBD!Έ7kiC$sguᑃ_A(2))Byc,i² [UvYYVd~?ڠY %mnKX pΰKZ T/HD9_#x޾l9Ū*RJ GT3qRgyWyym#628fѴXh=Qd:‹<_Ք\e88H >ƴh MQ(-aQKUJE#Tf:Qy|:eG$>Mmyvȯ5Il тZ(,+5\sөh "8<<ΛdAS ƐB6Z`tWeSkFo*願E }M'6:(e j]܌Pz.(o.N >?8ٚϦUR 8lRb.;y05KMF|{M(c)50s65r}q HB̽[ܣ0o선Ju9.{hYr`^?96&u xR C]ŵ*q^+$וTv?b dye"\;,!b80a|ZGx2Bh)a_dTF(X1' 4 AUߣ4zRn# G12JhBƒ]f?l^quc#T᎜X⚡a5*^*\)<8p)B;hZp\NRuz dNmt&萤{L;3BgoȨ+Anu M/H}%~)wgE 2$.t=:}~ D_c;5ս/`Ěze+ISH&+p~ x;.8գߊ0%Ns,t暓P6F SdJ^Sg M{;QIz wU Q'pQ{jqOq)xyxh/HTL"V TĤusWj|, r~Ȓ^ʇKBRb_PHF9{: f/%isdck, ;,pLnr }30^ |.z/fO嫂f;>Hf9h=TGİi fշ5>YlnpRƴO߾5DYŮDGDem![0YZbj{/ .C[|,%]s-hYM{Pf0Qүx3jy'9 e(;7'$[,j/)kE a^JU8^_ʐfzc! Iӷ|6񧛈إGHo6,YG+cu/ .`x(iaY$M?ާ ⧄鬐M\hw g dspx^wNERig8c+hp`2tf VN߇d*ȶ:N;ub/,AUJ|=O@qQȲ9^)T `O8oz$ة$Pt;'}VN 4i >.2nuHSz$bWiH?5aMYR*U>D#G6\wc Pm6xxhI$f FpHl׀9ɆKi6u)FQ֕G\0;kb/A:04$QN_`B<Æ Z2䶲DL)jqEHUlh*u#Fx3EO9Jn{T/1@w}Y7ߴL7z+@*l\n<ܸ$x z@gǎt# M)=FzQoVS^;bh+R=lX£D0<*2-w貭5U;U2Ox A/ݤ8x͖'ݽ6uXh4Tէ;8/јza`zwM~d4qS@3{@`9 ͩAƨ ' $-Æ\9s(T4CdQ> 5ƌY6b$QҹدUk/Vqk]*G2~Ӽ`μZ6 4\n[zҫ"s^ߓUeJmjsi:S{u<jK/XUɇ=2zAJ#d[݁u#I˂Z3"}U]h CԱh,GzZ}LD`@!'hE{U2b7U\ RLuv@N1Ou9p1)[pX!=Ω l>&2xVA }_PA;ewgJ瑙rD5>kp/t`$;) |EiTeN!B4{HIUsdz4a]'Kh_EO%xӲ/JiN:=GpP8"8k{=IlU@hSؾB Җ jl o[Z[F)s/,_X~7_( XѲI~P@AՌ}suLK~~<`kQbN'v+N+g[zK{)r,%@fpr Y@kq³qW)%{/DAn$ks)fzN+p= ^]16+ /1KmRL'7Xzkiҵ $͆/QN/RV4j}h8OFϦ\k\b2}GSdoA5<ē2 l$b[ ?Q>W,}A3\ ). I'˄Q z|-S(ScmO3u.&N]JQւ_'OGO]O7_fßf"p( 4ML>(+  ·mAژ E|gRk\/eu$ 8ʇ6ݫ5#H< #,:tøD_!B' D|+=!< '$8>$=hJzrv~Po;֭%zuQ䓈=hVɑYnusTEvKu,)YmѲH|y^T_'%*Ӧžw5!S=/ j"TiEx4 r({H1O8|v9p-eJ k4Lx[BCv_ɜF7;kؙΘs UܤL^#{RQ-4<'d \(L 3L o] 62#|Z,:'#Ʒ0:G2>Aw7)r9 ?{ׇun_\GCGw$u͐aҷY1 /9~m~g2ҏ5sjtvaw0}zWgXtN ,[rDyv޶Qް-O+-pRU_`1U_$9 Iq'?Yo"0"817lK`Ǿe-btxf~AE> myk _+Z3 ~hX[N}b.^hM+UpPf𞃋PG7H?'-BhW;<q,K٫ڻ}gċ_e EgzG"bչ0g&HҶZR?UɜdscJa7 ^N?yFͳ 秵w@ a-k@:adԕ({qk2wAR8FX~$oMzRk wiKgE{40qQ~i%F-L XR'Ci8%]aVճN6}(J~.z]:<ɘ?; ! n"İs3)8;(/VnY3E[du`SȈn6ܺ"ƌ>2Q[rٲ@N~uFPp'G =jPwA඗P8~*-(3[ܿ`DQ//k4̘q2yL';s6H4~S& N%T_a"#'xD)i-\a vcYbp3]ؗ~(Ѵ o "nώXs22OaS`d¿'B,b rcԍ.TRC+rW߿oE,; TYh QΈFmV jC܊)c"p<#U,7ZdƧo[/k{^a $! 2Z0X!K#濖DYeѳri# FX3f) )xZ#:4K/!%۶`qκ䂕–^q}e.9-6-+CVJ(8n[|?Tڂ vdPMft3&%8&3!>@ qY+ru,EaxQ̏JfYb̈́t2ڇ=F c9&]3|Ugeu/.qJ@; tT<lG6pyT[#dp9ee{0D`{ۜIN0Ȧ/hQ~wtM1!I$v`^|VPbN%7ttnLHel >9 l _H4.n1;׭RqAL S?LrQIsc⚍kb2tqlO=.sq.ձfEM%yOW}t%ZFC?,`2e1 ͛{IMf]lЍtad PN4qJkuMa6'i?%5' 2dɑ3FzH&?4`#eko*Ϯ)V^q+}vM>k(@Yt ]wg]5.guan+e=\F+O~P+;W,\o IhgMaHKN[see2/)KH4H_VD^O=[y_&y4s#Xr&ֲ1Ld_%}o`iQXJ, M]-Qzp ]Yr z/̀ RѱŐ=6b- O5 ߛ 0P\ܞio4XOX>}p)VsR[lk5 gݢ5 f>9ӊ`^>RlptE0˜#4={ iGeo" 4'DSy:IqXKa: 0,B_E-~}ɒtb*ۋ(KT%az%goe27n|`[ ?l]0r5wƂ/U.XKN/[r]e u'Xw2/g".PƔr5;=Ȳ)Ul7YɶkS`>FZ ?KQduDP-J|Z`qi5h2h#g˒2/;AZG*ju \S̒X56VQd^μ˼?F,#ub6$aoЖ-灌p?,t&4joX+dq\(ʍmY $%or}{-tȆ-m$`ouK\\A]as# ó߭x}W*Ik80w aV_Bk?n[k &9iRǸUNSڎxӷZ%MHG6u;ZnPv5rͱ֛K\(njsԂ[Pãb}8 v9+{j'8L6fԓ㍏n`R[Z+3ZT}~Df%jŌyo3qA\F47P#To$u E!U4B`XEWpJ:e /^sV<OgbN=мgvNJEMV}5 gLΡjTL\!L*py:?\AsC1Ҫ82_Kw2C/R ^T=r?g+f2}ؒݶ`7$/nxhҢxo b: |vnKU$K\1gj^jRqvOAmuNG1fcrgHGn6HYE A'M)CnN=gJ[ϲYD9]\#(~{h_n:)m͈穘UcDkq̌?^(P=Bc wqDEzO#=<.&%,UǃcDn]ovJHJ1fݐmx|1m&/sL'ơZ*@g\f"ʊɤ*Ppr ˢЮh^WH>@V/.'6sf6,`Tw9ރ@DP#˒ >=W3OF:ё2V! Ro{#K8~gFD7fau\ CS 9H+'_4A y[ WCf;b6⒐ϸp Vx6MbBN!2w+k4rإ 'In eЛ6w1Q%7@Ctؑ!7tG X%)wK ;Ws8>2ؾŴ<*g+vhJxG6)pLR$a&͖ O9Yd ⃬s"̎UĪC""N"UJv 2Zbl{ޒ@N{{jl\RTw~Z^ύ|sQ}FOa(С2ƭoKGHEIhC|;$fK>G?Pu7kjnܥ$ 4uo"~4:d{g&t8&NNx2ͮu*7 Ael[.0c$ԯJ|iY}Օ-"(CrY)aH~EV|IJ%rz(W%E=x]ԇ(|B*hR7WG1,2 zI#X1y;׾/"x~2`ejirg7ol(WFE} A-/\Q?۳Psڟ~ tgj4d_'Brr4"N^K S<(:$rҾ{O.EL^_څIyrw=*"ki nBZx3So0,#m495xzAӵ7D$z:P|*Q`%}qv(J@áQv8&Y~R ϯ+Q#88slꣳʃeׯ;=?'LYR+_^#$Q mk@za:M.ؿiq5C3!:E7Ԥ̊r+f S{Jd [7 jSg @5~:"6ˏ-`u5hL 1[mg c}V\Iś8Pwlʇ5B-wO%v7C|讗\ܟ+rMI&t@5宎F]ݦ?/ Dd&^Q'ayW[VcmP-VTzy8hR" գ\PQv%my~h^&{>^;72S,1:wک냑c#(9VQ?`頒N]K&R`Ŀ)9f/t%S?(lpSΕ (2ێ}l?m.*8Z]U ږsy ]u5z/!cL@BAꭖQS~]_wpb:F>m`OjZBKFq3hfO 'j W"> jPe*MdؖSӨx.nIb?xVs:!?46)Q" }$^jVUHY.3Gӡ !'GI7$@aG0Edbصt2nI2\'hLIS]&TbÛ|(a _|(top9KX јZ_u74"e(J{#zMTn ҵ7'$nƩfwM$gۓ/%r_G;-B#ݐp4+zɇhC|GS^$P&pZt2h3+ev; DSb.] W+֑6Ъe:ǹ$0ἲBo+#.j.%s^(H乇?{uɮ mD3)KōSLVa413/ZcRM2tޜOɑgS8 -a{L!ӑHYԻb\OB U{ܑ>"~rJ8cL_NcE";MJw0cvU VJ~}R* )&6况Jڼ\hJiRxD*'t?/eҋ]9/)dV. P xk9⫧W]yZ}N箦ES$-C7ɹV|Qe㴊9`-EH"[a;cFHI/k5v~n0RЕ d[PBסC;t&F^  X㿓M>;k=vh:Up\`[v=|Z6f)v35%7@;4mئ` "MR#sݶ_`8>7zCCR^\( B^4L4K>&hl,ɩ$c ,S:A.3B{L<Ųj)N2슬&w)fcpegjA·DI;B/QOQGoqkZ~tM"<OMkl8yQÏϱ㵝?)rI;ARVxg=H` bRsN-x{OOsW˧''!rf>u%?q!hj mix}_^Y{3e߶Roө!~;#~g;T4 = pF=K5d?Rf̌/vիE"ۜNov?8nC'{߷IU̬l :'~w؉'I{1;4w$,'VݶIChZ(W vim&D^)i"Gz!KF:J^ü+쒨D*_ɾ<pյϝp) ǰuREkFAQ7̧n*HWxj<È\ȆGQ łFuUodiy>UΉ%eJAx-'ާNrpȌӫj[1y`4D|o6jIi9N J2C1xkj~KGk赎xvHۄux fä]y""I߫"4 -:*芗},8;g)F5[ɍu߹ <P;DAOMA9r/ y ׀K>( Q? DgV: bK"=u G \v:YFld"aVR It^3/7Ff(/T_3D AdE\P 31v:jfϋFK\ޤܺs/ *wźRN!v .F{cj+>wԪ)w6iÏW!*Pz=ewtpPFDz!JOxFd2''v.4CmEU!bHVÙehB'['Wg_sBB@dTTc[h{  bUď_h@ ݜ^`jN-rCl՛Z 8ȴ^/h&: W *r9I+36+O,%S'q_~4{ C[{cv@(5IC5O|LPZI B/tQnGY!mg8@5W9l P_J qn!!\8KAJOFsf#^ʜ:yrawD9>\ Й/Y{n^5`Zݳ ;s<-]GvMˡ d =O{rW]f_r};ñuP })n٩}؉ ҁѦ}0K$%%ANf٘vq 'WiuΎTʷbXRPl73pDž90\q%5!ǫ^R4JyS@\%nƄ۔#]fP ZJmty9kqQK@cMwpEHpkp,r :!.628dBulbfJP-'Abee[D{[7+2 6tL}x7HOvlؘm\%.?o$ :*.lJ! gs&$" ЭCBZ{ H|K<n.]p<_P@>ax?(yarJpSLϓ3mcǏl`4u ._GΡO‡r3)!f5|LtUk[9nWŜU<9&]! \h"[]HAgsx-~Ƃ0J <}`!'^Ur@}1Ԃ-P_0h8R G&,{hM,Ovw^\;ǀC3)JrcHsON0 Qy簑|}~.dhpQ@<裎0s[#P}BA+,z  ʟhH")Q1}NuL3v)\'DYbcbWnBđf%uǸ#W,0]ғcM%;*d<$I!_t*F( 7k'4 =G.R RR-DcنSZe#r^\f"λ^Etg7eNY ̺ OK5!Dč:M*Q 3⥝|fٖ:s.z=x/Gdf+@ky^;'= o>^Rt #iEWTgm~DWƁ՘3Rn tå9H5zqp h!\Iv}g۟)-`RzO4N$& * ~ <|hlW<ٔ%Q pTmʤ>[/ ]MtdA0ޫf:1ITwl7]kNx"r[\1K_$jUDv/Vð~WwM? 06 \Kfd,IB{(j8CODkF} C4hJeZ.[hUp]tsN{$+b 3P!"럜>/u&a_k4)Ywɮ1_ e[zTKW˨};Ahw?VP[ +vvUPЂ頜.sbK)(acDaʑЪ*@Fy B## C{m+i`wF {07 ib:'^B),2EU <6Sds ^e5؂p)ytnn!U` #~Gq<>( (j9ؗTuS6ū ˲'}΁% fC?#/Ms C[UR-΄x04-Fh0KΝof@EbOh]GňoOA\ k̫ 2GG=h`%V=>l5ϯe(ߐC%,ANN a^& H)q4_9rJs!K50@X+m=fr/vc6 (Nky"HlΉJWX=&YƊz^p};'Qn֤:MnΩ7@6b2cd")YO ӌ# Σv[:5Cd|13ƒp-.2J}7 D~0r_DyaQʽ'P$IIZ9& O)0uZGFSހ(-Wh &N#vR[@lm OSLƹ堙}b`f*/W}mZ3YcC\[D"=`t[_Q|Zl|M{:5ŴpR ߤWإfd Y@UXPñIkdWR}8pT.qDToU-yO6{4 <'Cfޘ 3i pCRf?k\Fut9zqU~w^ЇtiI7X' q Vj7*]$Mg󤐢"Yk\IPJY{Y?7(qkͮ2|B?DDr]iéOp9br=)4nmETu }}g\T't? r.q,O Ni3K (ɛ hi14Vp~户rDAu0dG;`ij!Zm]֞:woRr3ZaC8up#ɤc+qVXw%삢K,^B&o~沟. ;#̓45wd?_3U_fԱ¼0H`s)UGaV8"3@',u嬨B8ܚ+MÈ_HQke>ö03=%"5`+9ŋ%sϴ׫ ؚka/~nWtrnXL;G2ȿYy\zR &5ՙ<>2uH2m|M=3 UMl| %KA{f&"}3 nqPA0:Q4o;`uFWfO~}1;r7//Tx#&TP4?} }hP"pjEf@5Xy4k5#Dg+lB R+: +!o:V<}5{ ӕ}ȝ`gl+3vbr^sS ]'/`ƇDğ\Jnޙj{HN)٭PJx1Զ> ~o9fW=Q{rW(¢qeeT# fo`onƼŊa9ys>6u1j61ǰg1/!kR6pjC9r&'+Nn8NŵL= GFDpMKK({ay5![B-q ()gÌ3ȨUVt^p1Fa:?T9k #:̍a>,r mCn@Fr$PQp>uO4J1x-hڦa'`Y*R'E$2ʌw!X.9ʡ]ϻ`݁7LDe8 EI]@`l}_N{^{spKRiOMY2r`Do[bH}L@a+w<Y͔40bVåmYn.VwrZjo5(Ya<ՓR w_"Fot>uH 'p2e9SfoVyMT_ ^hv,.q3/\~.9M)[ +?Jj)ڄB6dzJ)&C4<-ϓ;n_/M4-kIUj@£+*`:,d%_S?v& Itct}g͓q O>fm4ų^AffcD\i/^)jhja2x6|TQMzvpWFؒ;L>\M@'èM1$91raE`}Ȭ wn?9h-]E=۷Z`pDQRBƏҥ"$ӹФ>⮀pWZ;B#{?o* DVyBujTtӨ+t| 쉱#hR\jksG a`]SU&Mlo6hfnY&} dj+#~"Nݡ4ݪU2 L+ ];KFMsB#Ƌ b.peϝxi4TFUQQxhkC e3>+Vro;('w +$PKNcz@7r )ФTʛF&o~y>Q%YRY[(ñ("Y܋: mZ{ m6F<=v14an?VJԾDb2BR] ŵ:Vl~~@e8 Q4~ڏƫi-N)^5qڤ?htĖ](]ڲȃ@ e:T^E*˹jMBBw 'd40jAZW1 D|kZ74[B\9WL{*wVr- {+x4􆽢[NƂ .Ɠ]xOc'mf0R+ 0 +u '+G< VNo@ig})P퍻g[\3iΛ5Il&#ӗYVU=I(C#$̹$V-y?W䮺h%)I^ Ipmlys=S }e8ޣ2b?}-c8 G(5"3݌%$:>sHϲtI0Syfz.-Aף#s3p7sTPX]iD"lv^KL5yp!tѰkVJ{0M 9|1lE[r!wG@OASi7_QWO^U'/kёb0[dl: 2d?Qg_&'EJK -^wKϘO#t<.C湂lnX`95Rno(D}!{:./.;LdPNru2_WShzyrwN8PE ӗ㷹kq[hARIciﮦpjL 'n< O q: :HG@G|/J [t6.pe]x2OeMlFmgyق}ߋRcRiHEeWh9*mVCVBC8R $ z'#Z41P`,^g*c3XV `7kY}}k(lF$T?d9 (~u`C.V Om'>܋F(7ÔIT'"TE=]egU) ݎ;f4 *b/+:p!@QP/bce?x Gx0BLA^-WPDeNNMI*Fq"XR#C \Y ߝ9LNMr-0?a%cNȝ^~~.L_9.a`R@cE"8kK*/g|JM :2/c2^cAD;pF`~/9O*{8x!? fp)*@xiD?Hz+ͮl ys1oGbCe6˷.ug vWQ~ F$idh^j;YF}pHq6W[}Q +1۱|KK%/Nw*كyMR`!պ@)\pZJyܓhv2j%zN:O;#D~zus8)X w8$U P6]843n |'y#/N%8P Ӻ$Y63d%bŕU"{obnOUc}pݟƥIث|Nwyé$N^ cG]I~\UygoO |p׫^3N uȞ|ozib OvQiy۲da WEf*}ȆiFyGz9TAe*Qs1#IB64@z~^=Ţ+ 5{L?#gVKw<*K+$~+~HM&g C$B]8xGV9?8)J k;$oܿL,gLF,2p;Te- LUgq"2o4!>!B64c7W{פ@2ҫ$uB<)󮶾698`OH4N, YewD1\BuOE۽[GPP~(eFp8_oi%} t J\:z2m M#?7B Xʦsj%C+J6mC lQbi]FK\!gv#O,%0u"oܧŻGl!TKleԝ=0]Og؛_":o$J!L'| DҦ{SLj{{uԐ!!ql4z;H2g7{R, ]rd xsƲiowQwAqmwJeZ8]eu(wL #ڠ՝ o OJH:룱ԭͭYrmѷm\fzDwiTz5עm:] hY^= *:wC$Fu ~p#8Be&JYIW# ~Ӊ K8|E4C ItZ2fZ{U Hi=Fm]K#u:{c%]}ºz>jW3 ֥c~Tܞ/=#isٸaoJnUOkL αuhm9AgƄʚMPp,oW]bK7a6)c]˹6=r5!pyoeAcO:pݦqEjTS@6͢qhM--wR(Ձ]x1{frbAl+'+ըOx? 6llQeYE Dm8~Iv8#:tRž^_!vVf,᳿n/cxÒQ%(:䮹a1BR:Ř?I(skeg?A4g >ʛtr5H@/"E1p"jvpܠHC| ie /='Ao  nLCttiA-o;BHmICBbڋ݊[*V9(fzѡv TyN,Hg_)ExJlnߎ^m/ztߛJtYiwX:usm!?K1Yh%- !TɎ!5fr=xK(McşA'W¥O+'u\9.)rdR̙(U; JXOi:@J)d3NrL6k8SV!JJf_tA+Ήl^ʀ+ o:R{zaW`Dm26N~ce>!Cx|IL|* OxRؐ)eѷ>@@]/-@d4u_@kgg2][y؊N"* BF0<kcNpPb>W y ?+@m2!A Y>z䣶u{]"T>qH REۛB7:`Q^%2Y87w_ZyBI|=P { 0G( +ڡ +@4zBuPẨ"y[ma '{ȵI: {?2 o$h@AS&^eB۝^ "ī2 owho\)΃H +ͿpX)=m?nǒ0giHjf aMǐ ]xĵ=ԿsʁTjUZ k(;{uM!}]qfUxN{rkFg<_oͻڏSO>,)C^ݞ 5%څئ/-3W\ ',HxRf%`qQ/6 +xL Ɇ4wp՗O+>h1g#(^ۮ@5j=ڄ~4pxe=ZMl=f,&sϊ-Hjƒӂ pνaG2X7Ế  -?I{g$n&I[N`joLD+seڎjT>Ydu  L4,X(klōcfh*[Ic;?mRjX_dvLʐy~ flnk1HRz\ MA{~c),TjNxN8#j |#D`{ %poҪ)h:\Z1_ȒBw .S(QA_^F>~yMbG1o2U cr, K5rjcmit(ʏ #21QLUL̝" g Q澊?־)0hLfS)xCd}9^ Dڞh϶Qd9Xn>ŋ@UUGJɁy}eGM5J IgM.X0' &`vu_?#2ugUtF0r yUy5u_qgbxIJFCr$gSikƑ8L YŬ9s4I_d;+ )޶ ϫwxڗO]Hl-E$+RN5$|Ҽ9-/2&24D&ֵxf+-E?ӵQG<mAhS X!B:U*Ozj&AQ`G(i9 ?39V~:ఫL0_ wg۹=Kw?.=y@$QNj>KЦN7җ燂iflPeR@eYW;nAں}&"$z`6Ezhâsh5KdC`)5rorjȬh+3>4, t@Qk6HÄ$^uW%)T;M|;*,+T-]F"EA[8eƀN},M;v1unvnRz:@tEI{sPbIߢA'H'#kZY!qʟCтF HH]k^l9ávyJO0[U=kcKZy л/jJbO7p &  Í}s|}_9<݌"=sIXbF?֑ @*oi=ȠbG]Dsޮ9_:0Iڣ7ㆩTAzi:W!j08[Sff0D]~GpC?S$V< U_][=rFC|h?M)q?L{;y+iNC)A/4f)đ&(8[r|Ӏ*]j~D}V]w gk ZxN>HTNE+c7Z<T3 cULj͈D3>䉙 |;H扲JZcyuKƖ|X\܊ ւb#X nʸHu.5UCo@;h#;#pV!e *IXO;O8 xT^f`V>֤8bp(uu՝_ rO$n7#Zvq GIMOkO a* iǝϼ;=H&-cqm\'*y}u#pHr^ AJYWN=$cEحy鼋6^si Fǖ zv+wvZ21} , #ҤY,ٓTe:j D.z!`ܲl8C'Vy+VGg6is8`uPhiz#'Qw,LiXU8# tbpy,suI4}@#:g$@Pu2>{T_}/?k|H)X+.M.umO}[O>` <_9A3Nw@#?$ u%Qkzhd;ߐh,tIl]kG&! U^%V2Ǧ*Cerkg=w-~n?Obi̐T6{g|C{W#8] 7J1*r7e3mi\$3C@!,APEK9|\ +ouMWPkgVƀ7" i;MGTM%G7zva_%3i@MwkD&[XRm љve{~h&,?i^@5b|>w$EoZ4t KY]voC.lN_ې+Bd8g\`}dS>||np2kR1)v%F,[+~` 4P>-