389-ds-base-libs-1.3.8.4-23.el7_6$>tĚ(3v9̌a>8;D?;4d $ L8<TX_f  . L   0l(d44 4( \8 dW9W:U'WG2pH2I2X2Y3\3<]3x^4qb4d5e5f5l5t5u5v6(w9x9<y9xn;0C389-ds-base-libs1.3.8.423.el7_6Core libraries for 389 Directory ServerCore libraries for the 389 Directory Server base package. These libraries are used by the main package and the -devel package. This allows the -devel package to be installed with just the -libs package and without the main package.\*x86-02.bsys.centos.orgUCentOSGPLv3+CentOS BuildSystem System Environment/Daemonshttps://www.port389.org/linuxx86_64 p8KmAA큤\*S\*C\*X\*Y\*C\*X\*C\*X\*C\*X\*[+؉[+؉[+؉\*'c87cf3b223ad1ca2ac92171eb6675336fefd20f13bf53f7c50c17a91fa9007491ee70dbd188a261961b4e3aed3e212a03a9bb146ce57a2bb88827319858495a3fc6b0fe0c79af328356b9bab420b313e360893d7b7861bb6655ac402877a6979a4428bbcc4d36df5200b7bffad701777d912980fd29d7f1b8d01375588a817cdf58548669bd002c1160047d37100093ac54bfa74a905280664b26bb3fde791e1495b7c1e22dcc0f37d78076a1fcad786b69ac78f1e806466d798fd8fc4a5d10d8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903a73b7d3598e98f46aeb0559e641d3e6ac83c0fc34e1e5fa98cb9d4a6050bacd997a6a0413ce3664e192dff12a29bc3f690c24e8a0d48d986478c56cdfe370c3blibldaputil.so.0.0.0libnunc-stans.so.0.1.0libsds.so.0.0.0libslapd.so.0.1.0rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootroot389-ds-base-1.3.8.4-23.el7_6.src.rpm389-ds-base-libs389-ds-base-libs(x86-64)libldaputil.so.0()(64bit)libns-dshttpd-1.3.8.4.so()(64bit)libnunc-stans.so.0()(64bit)libsds.so.0()(64bit)libslapd.so.0()(64bit)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcom_err.so.2()(64bit)libdl.so.2()(64bit)libevent-2.0.so.5()(64bit)libgcc_s.so.1()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libldaputil.so.0()(64bit)libm.so.6()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnss3.so(NSS_3.10.2)(64bit)libnss3.so(NSS_3.12)(64bit)libnss3.so(NSS_3.2)(64bit)libnss3.so(NSS_3.3)(64bit)libnss3.so(NSS_3.4)(64bit)libnss3.so(NSS_3.6)(64bit)libnss3.so(NSS_3.9)(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libsasl2.so.3()(64bit)libsds.so.0()(64bit)libslapd.so.0()(64bit)libssl3.so()(64bit)libssl3.so(NSS_3.12.6)(64bit)libssl3.so(NSS_3.14)(64bit)libssl3.so(NSS_3.2)(64bit)libssl3.so(NSS_3.20)(64bit)libssl3.so(NSS_3.4)(64bit)libstdc++.so.6()(64bit)libsvrcore.so.0()(64bit)libsystemd.so.0()(64bit)libtcmalloc.so.4()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.11.3\Z@\\\l@\l@[@[@[[:@[[-[~[~[m~@[W[U@[L[L[L[L[0@[0@[+@[@ZZZyZyZk@Z`@ZX@Z*~Z }YZ@YZ@YZ@Y@YB@Y*@Y˒Y˒Y@Y6@Y$$@Y@Y i@Y i@Y i@Y i@XQ@XQ@X@X9@XP@XX@X@X@X2@W@W@Wu@W@Wt@W.@W~W~W@W@Ws@Ws@Wi,@Wi,@W_W^@W - 1.3.8.4-23Mark Reynolds - 1.3.8.4-22Mark Reynolds - 1.3.8.4-21Mark Reynolds - 1.3.8.4-20Mark Reynolds - 1.3.8.4-19Mark Reynolds - 1.3.8.4-18Mark Reynolds - 1.3.8.4-17Mark Reynolds - 1.3.8.4-16Mark Reynolds - 1.3.8.4-15Mark Reynolds - 1.3.8.4-14Mark Reynolds - 1.3.8.4-13Mark Reynolds - 1.3.8.4-12Mark Reynolds - 1.3.8.4-11Mark Reynolds - 1.3.8.4-10Mark Reynolds - 1.3.8.4-9Mark Reynolds - 1.3.8.4-8Mark Reynolds - 1.3.8.4-7Mark Reynolds - 1.3.8.4-6Mark Reynolds - 1.3.8.4-5Mark Reynolds - 1.3.8.4-4Mark Reynolds - 1.3.8.4-3Mark Reynolds - 1.3.8.4-2Mark Reynolds - 1.3.8.4-1Mark Reynolds - 1.3.8.2-1Mark Reynolds - 1.3.7.5-18Mark Reynolds - 1.3.7.5.17Mark Reynolds - 1.3.7.5-16Mark Reynolds - 1.3.7.5-15Mark Reynolds - 1.3.7.5-14Mark Reynolds - 1.3.7.5-13Mark Reynolds - 1.3.7.5-12Mark Reynolds - 1.3.7.5-11Mark Reynolds - 1.3.7.5-10Mark Reynolds - 1.3.7.5-9Mark Reynolds - 1.3.7.5-8Mark Reynolds - 1.3.7.5-7Mark Reynolds - 1.3.7.5-6Mark Reynolds - 1.3.7.5-5Mark Reynolds - 1.3.7.5-4Mark Reynolds - 1.3.7.5-3Mark Reynolds - 1.3.7.5-2Mark Reynolds - 1.3.7.5-1Mark Reynolds - 1.3.6.1-16Mark Reynolds - 1.3.6.1-15Mark Reynolds - 1.3.6.1-14Mark Reynolds - 1.3.6.1-13Mark Reynolds - 1.3.6.1-12Mark Reynolds - 1.3.6.1-11Mark Reynolds - 1.3.6.1-10Mark Reynolds - 1.3.6.1-9Mark Reynolds - 1.3.6.1-8Mark Reynolds - 1.3.6.1-7Mark Reynolds - 1.3.6.1-6Mark Reynolds - 1.3.6.1-5Mark Reynolds - 1.3.6.1-4Mark Reynolds - 1.3.6.1-3Mark Reynolds - 1.3.6.1-2Mark Reynolds - 1.3.6.1-1Noriko Hosoi - 1.3.5.10-12Noriko Hosoi - 1.3.5.10-11Noriko Hosoi - 1.3.5.10-10Noriko Hosoi - 1.3.5.10-9Noriko Hosoi - 1.3.5.10-8Noriko Hosoi - 1.3.5.10-7Noriko Hosoi - 1.3.5.10-6Noriko Hosoi - 1.3.5.10-5Noriko Hosoi - 1.3.5.10-4Noriko Hosoi - 1.3.5.10-3Noriko Hosoi - 1.3.5.10-2Noriko Hosoi - 1.3.5.10-1Noriko Hosoi - 1.3.5.9-1Noriko Hosoi - 1.3.5.8-1Noriko Hosoi - 1.3.5.7-1Noriko Hosoi - 1.3.5.6-1Noriko Hosoi - 1.3.5.5-1Noriko Hosoi - 1.3.5.4-1Noriko Hosoi - 1.3.5.3-1Noriko Hosoi - 1.3.5.2-1Noriko Hosoi - 1.3.4.0-19Noriko Hosoi - 1.3.4.0-18Noriko Hosoi - 1.3.4.0-17Noriko Hosoi - 1.3.4.0-16Noriko Hosoi - 1.3.4.0-15Noriko Hosoi - 1.3.4.0-14Noriko Hosoi - 1.3.4.0-13Noriko Hosoi - 1.3.4.0-12Noriko Hosoi - 1.3.4.0-11Noriko Hosoi - 1.3.4.0-10Noriko Hosoi - 1.3.4.0-9Noriko Hosoi - 1.3.4.0-8Noriko Hosoi - 1.3.4.0-7Noriko Hosoi - 1.3.4.0-6Noriko Hosoi - 1.3.4.0-5Noriko Hosoi - 1.3.4.0-4Noriko Hosoi - 1.3.4.0-3Noriko Hosoi - 1.3.4.0-2Noriko Hosoi - 1.3.4.0-1Noriko Hosoi - 1.3.3.1-19Noriko Hosoi - 1.3.3.1-18Noriko Hosoi - 1.3.3.1-17Noriko Hosoi - 1.3.3.1-16Noriko Hosoi - 1.3.3.1-15Noriko Hosoi - 1.3.3.1-14Noriko Hosoi - 1.3.3.1-13Noriko Hosoi - 1.3.3.1-12Noriko Hosoi - 1.3.3.1-11Noriko Hosoi - 1.3.3.1-10Noriko Hosoi - 1.3.3.1-9Noriko Hosoi - 1.3.3.1-8Noriko Hosoi - 1.3.3.1-7Noriko Hosoi - 1.3.3.1-6Noriko Hosoi - 1.3.3.1-5Noriko Hosoi - 1.3.3.1-4Rich Megginson - 1.3.3.1-3Noriko Hosoi - 1.3.3.1-2Noriko Hosoi - 1.3.3.1-1Noriko Hosoi - 1.3.1.6-26Noriko Hosoi - 1.3.1.6-25Noriko Hosoi - 1.3.1.6-24Noriko Hosoi - 1.3.1.6-23Noriko Hosoi - 1.3.1.6-22Noriko Hosoi - 1.3.1.6-21Noriko Hosoi - 1.3.1.6-20Noriko Hosoi - 1.3.1.6-19Noriko Hosoi - 1.3.1.6-18Noriko Hosoi - 1.3.1.6-17Daniel Mach - 1.3.1.6-16Noriko Hosoi - 1.3.1.6-15Noriko Hosoi - 1.3.1.6-14Daniel Mach - 1.3.1.6-13Noriko Hosoi - 1.3.1.6-12Rich Megginson - 1.3.1.6-11Rich Megginson - 1.3.1.6-10Noriko Hosoi - 1.3.1.6-9Noriko Hosoi - 1.3.1.6-8Rich Megginson - 1.3.1.6-7Rich Megginson - 1.3.1.6-6Rich Megginson - 1.3.1.6-5Noriko Hosoi - 1.3.1.6-4Rich Megginson - 1.3.1.6-3Noriko Hosoi - 1.3.1.6-2Noriko Hosoi - 1.3.1.6-1Noriko Hosoi - 1.3.1.5-1Noriko Hosoi - 1.3.1.4-1Rich Megginson - 1.3.1.3-1Jan Safranek - 1.3.1.2-2Noriko Hosoi - 1.3.1.2-1Noriko Hosoi - 1.3.1.1-1Noriko Hosoi - 1.3.1.0-1Noriko Hosoi - 1.3.0.5-1Mark Reynolds - 1.3.0.4-1Noriko Hosoi - 1.3.0.3-1Parag Nemade - 1.3.0.2-2Noriko Hosoi - 1.3.0.2-1Noriko Hosoi - 1.3.0.1-1Noriko Hosoi - 1.3.0.0-1Noriko Hosoi - 1.3.0-0.3.rc3Noriko Hosoi - 1.3.0-0.2.rc2Noriko Hosoi - 1.3.0-0.1.rc1Mark Reynolds - 1.3.0.a1-1Rich Megginson - 1.2.11.15-1Rich Megginson - 1.2.11.14-1Rich Megginson - 1.2.11.13-1Rich Megginson - 1.2.11.12-1Mark Reynolds - 1.2.11.11-1Mark Reynolds - 1.2.11.10-1Mark Reynolds - 1.2.11.9-1Mark Reynolds - 1.2.11.8-1Fedora Release Engineering - 1.2.11.7-2.2Petr Pisar - 1.2.11.7-2.1Rich Megginson - 1.2.11.7-2Rich Megginson - 1.2.11.7-1Rich Megginson - 1.2.11.6-1Rich Megginson - 1.2.11.5-2Rich Megginson - 1.2.11.5-1Petr Pisar - 1.2.11.4-1.1Rich Megginson - 1.2.11.4-1Rich Megginson - 1.2.11.3-1Rich Megginson - 1.2.11.2-1Rich Megginson - 1.2.11.1-1Rich Megginson - 1.2.11-0.1.a1Noriko Hosoi - 1.2.10.4-4Noriko Hosoi - 1.2.10.4-3Rich Megginson - 1.2.10.4-2Rich Megginson - 1.2.10.4-1Rich Megginson - 1.2.10.3-1Rich Megginson - 1.2.10.2-1Noriko Hosoi - 1.2.10.1-2Rich Megginson - 1.2.10.1-1Rich Megginson - 1.2.10.0-1Noriko Hosoi - 1.2.10-0.10.rc1.2Petr Pisar - 1.2.10-0.10.rc1.1Rich Megginson - 1.2.10-0.10.rc1Rich Megginson - 1.2.10-0.9.a8Rich Megginson - 1.2.10-0.8.a7Rich Megginson - 1.2.10-0.7.a7Fedora Release Engineering - 1.2.10-0.6.a6.1Rich Megginson - 1.2.10-0.6.a6Rich Megginson - 1.2.10-0.5.a5Rich Megginson - 1.2.10-0.4.a4Rich Megginson - 1.2.10.a3-0.3Rich Megginson - 1.2.10.a2-0.2Rich Megginson - 1.2.10.a1-0.1Rich Megginson - 1.2.9.10-2Rich Megginson - 1.2.9.10-1Rich Megginson - 1.2.9.9-1Rich Megginson - 1.2.9.8-1Rich Megginson - 1.2.9.7-1Rich Megginson - 1.2.9.6-1Rich Megginson - 1.2.9.5-1Rich Megginson - 1.2.9.4-1Rich Megginson - 1.2.9.3-1Rich Megginson - 1.2.9.2-1Rich Megginson - 1.2.9.1-2Rich Megginson - 1.2.9.1-1Petr Sabata - 1.2.9.0-1.2Petr Sabata - 1.2.9.0-1.1Rich Megginson - 1.2.9.0-1Rich Megginson - 1.2.9-0.2.a2Marcela Mašláňová - 1.2.9-0.1.a1.2Marcela Mašláňová - 1.2.9-0.1.a1.1Rich Megginson - 1.2.9-0.1.a1Rich Megginson - 1.2.8.3-1Rich Megginson - 1.2.8.2-1Rich Megginson - 1.2.8.1-1Rich Megginson - 1.2.8.0-1Rich Megginson - 1.2.8-0.10.rc5Rich Megginson - 1.2.8-0.9.rc4Rich Megginson - 1.2.8-0.8.rc2Caolán McNamara - 1.2.8-0.7.rc1Rich Megginson - 1.2.8-0.6.rc1Rich Megginson - 1.2.8-0.5.a3Rich Megginson - 1.2.8-0.4.a3Rich Megginson - 1.2.8-0.3.a3Fedora Release Engineering - 1.2.8-0.2.a2.1Rich Megginson - 1.2.8-0.2.a2Nathan Kinder - 1.2.8-0.1.a1Rich Megginson - 1.2.7.5-1Rich Megginson - 1.2.7.4-2Rich Megginson - 1.2.7.4-1Rich Megginson - 1.2.7.3-1Rich Megginson - 1.2.7.2-1Rich Megginson - 1.2.7.1-2Rich Megginson - 1.2.7.1-1Nathan Kinder - 1.2.7-2Nathan Kinder - 1.2.7-1Rich Megginson - 1.2.7-0.6.a5Rich Megginson - 1.2.7-0.5.a4Rich Megginson - 1.2.7-0.4.a3Rich Megginson - 1.2.7-0.3.a3Rich Megginson - 1.2.7-0.2.a2Rich Megginson - 1.2.7-0.1.a1Rich Megginson - 1.2.6.1-3Rich Megginson - 1.2.6.1-2Rich Megginson - 1.2.6.1-1Rich Megginson - 1.2.6-1Rich Megginson - 1.2.6-0.11.rc7Rich Megginson - 1.2.6-0.10.rc6Rich Megginson - 1.2.6-0.9.rc3Rich Megginson - 1.2.6-0.8.rc3Rich Megginson - 1.2.6-0.7.rc2Nathan Kinder - 1.2.6-0.6.rc1Rich Megginson - 1.2.6-0.5.rc1Marcela Maslanova - 1.2.6-0.4.a4.1Rich Megginson - 1.2.6-0.4.a4Nathan Kinder - 1.2.6-0.4.a3Caolán McNamara - 1.2.6-0.3.a2Rich Megginson - 1.2.6-0.2.a2Nathan Kinder - 1.2.6-0.1.a1Rich Megginson - 1.2.5-1Rich Megginson - 1.2.5-0.5.rc4Rich Megginson - 1.2.5-0.4.rc3Rich Megginson - 1.2.5-0.3.rc2Rich Megginson - 1.2.5-0.2.rc1Rich Megginson - 1.2.5-0.1.a1Rich Megginson - 1.2.4-1Rich Megginson - 1.2.3-1Caolán McNamara - 1.2.2-2Rich Megginson - 1.2.2-1Tomas Mraz - 1.2.1-5Noriko Hosoi - 1.2.1-4Rich Megginson - 1.2.1-3Fedora Release Engineering - 1.2.1-2Rich Megginson - 1.2.1-1Rich Megginson - 1.2.0-4Rich Megginson - 1.2.0-3Rich Megginson - 1.2.0-2Rich Megginson - 1.2.0-1Noriko Hosoi - 1.1.3-7Noriko Hosoi - 1.1.3-6Rich Megginson - 1.1.3-5Rich Megginson - 1.1.3-4Rich Megginson - 1.1.3-3Rich Megginson - 1.1.3-2Rich Megginson - 1.1.3-1Rich Megginson - 1.1.2-1Rich Megginson - 1.1.1-2Rich Megginson - 1.1.1-1Rich Megginson - 1.1.0.1-4Tom "spot" Callaway - 1.1.0.1-3Tom "spot" Callaway - 1.1.0.1-3Rich Megginson - 1.1.0.1-2Rich Megginson - 1.1.0.1-1Fedora Release Engineering - 1.1.0-5Rich Megginson - 1.1.0-4Release Engineering - 1.1.0-3Rich Megginson - 1.1.0-2.0Rich Megginson - 1.1.0-1.2Rich Megginson - 1.1.0-1.1Rich Megginson - 1.1.0-0.3.20070720Nathan Kinder - 1.1.0-0.2.20070320Rich Megginson - 1.1.0-0.1.20070320Rich Megginson - 1.1.0-0.1.20070223Rich Megginson - 1.1.0-0.1.20070213Rich Megginson - 1.1.0-1.el4.20070209Rich Megginson - 1.1.0-1.el4.20070207Rich Megginson - 1.1.0-1.el4.20070129Rich Megginson - 1.1.0-8.el4.20070125Rich Megginson - 1.1.0-7.el4.20070125Rich Megginson - 1.1.0-6.el4.20070125Rich Megginson - 1.1.0-5.el4.20070125Rich Megginson - 1.1.0-4.el4.20070119Rich Megginson - 1.1.0-3.el4.20070119Rich Megginson - 1.1.0-2.el4.20070119Rich Megginson - 1.1.0-1.el4.cvs20070119Rich Megginson - 1.1-0.1.cvs20070115Dennis Gilmore - 1.1-0.1.cvs20070108Rich Megginson - 1.0.99-16Rich Megginson - 1.0.99-15Rich Megginson - 1.0.99-14Rich Megginson - 1.0.99-13Rich Megginson - 1.0.99-12Rich Megginson - 1.0.99-11Rich Megginson - 1.0.99-10Rich Megginson - 1.0.99-9Rich Megginson - 1.0.99-8Rich Megginson - 1.0.99-7Rich Megginson - 1.0.99-6Rich Megginson - 1.0.99-5Rich Megginson - 1.0.99-4Rich Megginson - 1.0.99-3Rich Megginson - 1.0.99-2Rich Megginson - 1.0.99-1- Bump version to 1.3.8.4-23 - Resolves: Bug 1672173 - import task should not be deleted after import finishes to be able to query the status - Resolves: Bug 1672177 - after certain failed import operation, impossible to replay an import operation. - Resolves: Bug 1672179 - cannot add cenotaph in read only consumer- Bump version to 1.3.8.4-22 - Resolves: Bug 1660120 - certmap fails when Issuer DN has comma in name- Bump version to 1.3.8.4-21 - Resolves: Bug 1659510 - during MODRDN referential integrity can fail erronously while updating large groups - Resolves: Bug 1659936 - After RHEL 7.6 HTB update, unable to set nsslapd-cachememsize (RHDS 10) to custom value- Bump version to 1.3.8.4-20 - Resolves: Bug 1645197 - Fix compiler warnings- Bump version to 1.3.8.4-19 - Resolves: Bug 1653820 - PassSync not setting pwdLastSet attribute in Active Directory after Pw update from LDAP sync for normal user - Resolves: Bug 1645197 - on-line re-initialization hangs- Bump version to 1.3.8.4-18 - Resolves: Bug 1638516 - CRIT - list_candidates - NULL idl was recieved from filter_candidates_ex- Bump version to 1.3.8.4-17 - Resolves: Bug 1643875 - ns-slapd: crash in entrycache_add_int- Bump version to 1.3.8.4-16 - Resolves: Bug 1638513 - Message: "CRIT - list_candidates - NULL idl was recieved from filter_candidates_ext." should not be critical- Bump version to 1.3.8.4-15 - Resolves: Bug 1624004 - Fix regression in last patch- Bump version to 1.3.8.4-14 - Resolves: Bug 1624004 - potential denial of service attack- Bump version to 1.3.8.4-13 - Resolves: Bug 1623949 - Crash in delete_passwdPolicy when persistent search connections are terminated unexpectedly- Bump version to 1.3.8.4-12 - Resolves: Bug 1616412 - filter optimization fix causes regression(fix reverted)- Bump version to 1.3.8.4-11 - Resolves: Bug 1614820 - Server crash through modify command with large DN- Bump verison to 1.3.8.4-10 - Resolves: Bug 1614501 - Disable nunc-stans by default - Resolves: Bug 1607078 - ldapsearch with server side sort crashes the ldap server- Bump version to 1.3.8.4-9 - Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user "dirsrv" if there is an already existing user with the UID/GID 389 on the machine.- Bump version to 1.3.8.4-8 - Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user "dirsrv" if there is an already existing user with the UID/GID 389 on the machine.- Bump version to 1.3.8.4-7 - Resolves: Bug 1595766 - backout this fix for now because it breaks FreeIPA (removed patch file all together)- Bump version to 1.3.8.4-6 - Resolves: Bug 1595766 - backout this fix for now because it breaks FreeIPA- Bump version to 1.3.8.4-5 - Resolves: Bug 1595766 - CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default- Bump version to 1.3.8.4-4 - Resolves: Bug 1597384 - Async operations can hang when the server is running nunc-stans - Resolves: Bug 1598186 - A search with the scope "one" returns a non-matching entry - Resolves: Bug 1598718 - import fails if backend name is "default" - Resolves: Bug 1598478 - If a replica is created with a bindDNGroup, this group is taken into account only after bindDNGroupCheckInterval seconds - Resolves: Bug 1525256 - Invalid SNMP MIB for 389 DS - Resolves: Bug 1597518 - ds-replcheck command returns traceback errors against ldif files having garbage content when run in offline mode- Bump version to 1.3.8.4-3 - Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user "dirsrv" if there is an already existing user with the UID/GID 389 on the machine.- Bump version to 1.3.8.4-2 - Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user "dirsrv" if there is an already existing user with the UID/GID 389 on the machine.- Bump version to 1.3.8.4-1 - Resolves: Bug 1560653 - Rebase 389-ds-base in RHEL 7.6 to 1.3.8- Bump version to 1.3.8.2-1 - Resolves: Bug 1560653 - Rebase 389-ds-base in RHEL 7.6 to 1.3.8- Bump version to 1.3.7.5-18 - Resolves: Bug 1539082 - Fix memory leak- Bump version to 1.3.7.5.17 - Resolves: Bug 1539082 - Child entry cenotaphs should not prevent the deletion of the parent - Resolves: Bug 1540106 - CVE-2018-1054 - remote Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 - Resolves: Bug 1535538 - CVE-2017-15135 - Authentication bypass due to lack of size check in slapi_ct_memcmp- Bump version to 1.3.7.5-16 - Resolves: Bug 1542645 - Outgoing secure connection is failing with recent OpenLDAP- Bump version to 1.3.7.5-15 - Resolves: Bug 1533828 - Server allows to set nsds5replicaid=65535 in the existing replica entry - Resolves: Bug 1535515 - local password policies should use the same defaults as the global policy - Resolves: Bug 1541108 - Allow CRL handling to be configurable for outgoing connections- Bump version to 1.3.7.5-14 - Resolves: Bug 1519406 - New defects found in 389-ds-base-1.3.7.5-3.el7 (fix regression in -13)- Bump version to 1.3.7.5-13 - Resolves: Bug 1533828 - Server allows to set nsds5replicaid=65535 in the existing replica entry - Resolves: Bug 1519406 - New defects found in 389-ds-base-1.3.7.5-3.el7 - Resolves: Bug 1534379 - CVE-2017-15134: Remote DoS via search filters in slapi_filter_sprintf in slapd/util.c - Resolves: Bug 1533571 - memberof: schema violation error message is confusing as memberof will likely repair target entry - Resolves: Bug 1535515 - local password policies should use the same defaults as the global policy- Bump version to 1.3.7.5-12 - Resolves: Bug 1459946 - GetEffectiveRights gives false-negative with ACIs containing targetfilter - Resolves: Bug 1507194 - cleanallruv could break replication if anchor csn in ruv originated in deleted replica - Resolves: Bug 1517788 - password policy: minimum token length fails when the token length is equal to attribute length - Resolves: Bug 1518287 - heap-use-after-free in csn_as - Resolves: Bug 1531153 - Indexing of internationalized matching rules is failing - Resolves: Bug 1517383 - ns-slapd segfaults with ERR - connection_release_nolock_ext - conn=0 fd=0 Attempt to release connection that is not acquired - Resolves: Bug 1523183 - search with CoS attribute is getting slower after modifying/adding CosTemplate - Resolves: Bug 1457315 - cmocka tests are not executed during rpm build - Resolves: Bug 1516309 - After cleanALLruv, replication is looping on keep alive DEL- Bump version to 1.3.7.5-11 - Resolves: Bug 1518069 - heap-buffer-overflow in ss_unescape - Resolves: Bug 1516676 - gssapi authentication fails after upgrading 389-ds-base - Resolves: Bug 1511885 - Automatically load /usr/lib/sysctl.d/70-dirsrv.conf after installing 389-ds-base - Resolves: Bug 1517980 - stack-buffer-overflow in slapi_pblock_get- Bump version to 1.3.7.5-10 - Resolves: Bug 1464463 - Replication fails to start with CBCA (Certificate-Based Client Authentication) while FIPS mode is enabled. - Resolves: Bug 1465383 - Segmentation fault in valueset_array_to_sorted_quick - Resolves: Bug 1510865 - python-ldap is not a dependency of 389-ds-base - Resolves: Bug 1513467 - IPA upgrade fails for latest ipa package - Resolves: Bug 1192099 - IPA server replication broken, after DS stop-start, due to changelog reset - Resolves: Bug 1445188 - Misleading error message - Incoming BER Element was 3 bytes - Resolves: Bug 1498980 - heap corruption during import - Resolves: Bug 1511462 - scope one searches give incorrect results - Resolves: Bug 1514033 - opened connection are hanging, no longer poll- Bump version to 1.3.7.5-9 - Resolves: Bug 1271208 - Fix copy and paste error- Bump version to 1.3.7.5-8 - Resolves: Bug 1509016 - cleanallruv task is not logging any information- Bump version to 1.3.7.5-7 - Resolves: Bug 1474100 - Use of uninitialized value in string ne at /usr/bin/logconv.pl - Resolves: Bug 1506425 - Improve valueset sort performance during valueset purging - Resolves: Bug 1505046 - [abrt] 389-ds-base: SLL_Next(): ns-slapd killed by SIGSEGV - Resolves: Bug 1271208 - nsds5ReplicaProtocolTimeout attribute accepts negative values- Bump version to 1.3.7.5-6 - Resolves: Bug 1488836 - directory server fails to start because maxdisksize - Resolves: Bug 1474100 - Use of uninitialized value in string ne at /usr/bin/logconv.pl - Resolves: Bug 1447308 - Add option to show full un-ellipsized output in status-dirsrv - Resolves: Bug 1438526 - Server allows to set any nsds5replicaid in the existing replica entry - Resolves: Bug 1185774 - Missing warning for invalid replica backoff configuration- Bump version to 1.3.7.5-5 - Resolves: Bug 1476207 - Enabling instance service doesn't work - Resolves: Bug 1434335 - Errors log filled with attrlist_replace - attr_replace - Resolves: Bug 1453155 - unable to retrieve specific cosAttribute when subtree password policy is configured - Resolves: Bug 1459965 - repl-monitor - matches null string many times in regex - Resolves: Bug 1463204 - Adding a database entry fails if the same database was deleted after an import - Resolves: Bug 1469567 - Activating roles returns error 16 - Resolves: Bug 1498773 - Installation of ipa fails with crash in topology plugin - Resolves: Bug 1501058 - [memberOf Plugin] bulk deleting users causes deadlock when there are multiple backends - Resolves: Bug 1352121 - [RFE] allow to enable MemberOf plugin in dedicated consumer- Bump version to 1.3.7.5-4 - Fix coverity warnings from convscan - Improve atomics- Bump version to 1.3.7.5-3 - specfile remove cap_net_bind_service+ep from ns-slapd- Bump version to 1.3.7.5-2 - specfile updates: add asan support, make nunc-stans default, and general cleanup- Bump version to 1.3.7.5-1 - Resolves: Bug 1470169 - Rebase 389-ds-base in RHEL 7.5 to 1.3.7- Bump version to 1.3.6.1-16 - Resolves: Bug 1444938 - nsslapd-allowed-sasl-mechanisms doesn't reset to default values without a restart - Resolves: Bug 1447015 - Adjust db2bak.pl help and man page to reflect changes introduced to the script - Resolves: Bug 1450896 - Manual resetting of nsslapd-dbcachesize using ldapmodify - Resolves: Bug 1454921 - Fixup memberof task throws error "memberof_fix_memberof_callback: Weird - Resolves: Bug 1456774 - ipa-replica server fails to upgrade- Bump version to 1.3.6.1-15 - Resolves: Bug 1429770 - ds-logpipe.py crashes for non-existing users - Resolves: Bug 1444938 - nsslapd-allowed-sasl-mechanisms doesn't reset to default values without a restart - Resolves: Bug 1450896 - Manual resetting of nsslapd-dbcachesize using ldapmodify - Resolves: Bug 1357682 - RHDS fails to start with message: "Failed to delete old semaphore for stats file" - Resolves: Bug 1452739 - Zero value of nsslapd-cache-autosize-split makes dbcache to be equal 0- Bump version to 1.3.6.1-14 - Resolves: Bug 1450910 - Modifying "nsslapd-cache-autosize" parameter using ldapmodify command is failing. - Resolves: Bug 1450893 - When nsslapd-cache-autosize is not set in dse.ldif, ldapsearch does not show the default value - Resolves: Bug 1449098 - ns-slapd crashes in role cache creation - Resolves: Bug 1441522 - AddressSanitizer: heap-use-after-free in libreplication-plugin.so - Resolves: Bug 1437492 - "ERR - cos-plugin - cos_cache_query_attr - cos attribute krbPwdPolicyReference failed schema check" in error log - Resolves: Bug 1429770 - ds-logpipe.py crashes for non-existing users - Resolves: Bug 1451657 - -v option is not working for db2ldif.pl- Bump version to 1.3.6.1-13 - Resolves: Bug 1444938 - Fix backport issue from build 1.3.6.1-10 (part 2)- Bump version to 1.3.6.1-12 - Resolves: Bug 1444938 - Fix backport issue from build 1.3.6.1-10- Bump version to 1.3.6.1-11 - Resolves: Bug 1410207 - Utility command had better use INFO log level for the output - Resolves: Bug 1049190 - Better input argument validation and error messages for db2index and db2index.pl- Bump version to 1.3.6.1-10 - Resolves: Bug 1444938 - nsslapd-allowed-sasl-mechanisms doesn't reset to default val - Resolves: Bug 1111400 - logconv.pl lists sasl binds with no dn as anonymous - Resolves: Bug 1377452 - Integer overflow in performance counters - Resolves: Bug 1441790 - ldapserch for nsslapd-errorlog-level returns incorrect values - Resolves: Bug 1444431 - ERR - symload_report_error - Netscape Portable Runtime error -5975 - Resolves: Bug 1447015 - Adjust db2bak.pl help and man page to reflect changes introduced to the script- Bump version to 1.3.6.1-9 - Resolves: Bug 1442880 - setup-ds-admin.pl -u with nsslapd-localhost changed - Resolves: Bug 1443682 - util_info_sys_pages should be able to detect memory restrictions in a cgroup- Bump version to 1.3.6.1-8 - Resolves: Bug 1432016 - Possible deadlock while installing an ipa replica - Resolves: Bug 1438029 - Overflow in memberof- Bump version to 1.3.6.1-7 - Resolves: bug 1394899 - RHDS should ignore passwordMinAge if "password must reset" is set(fix crash regression) - Resolves: bug 1381326 - dirsrv-snmp.service is provided by 389-ds-base instead of 389-ds-base-snmp - Resolves: bug 1049190 - Better input argument validation and error messages for db2index and db2index.pl.- Bump version to 1.3.6.1-6 - Resolves: bug 1437006 - EMBARGOED CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages - Resolves: bug 1341689 - dbmon.sh / cn=monitor] nsslapd-db-pages-in-use is increasing - Resolves: bug 1394899 - RHDS should ignore passwordMinAge if "password must reset" is set - Resolves: bug 1397288 - typo in logconv.pl man page - Resolves: bug 1436994 - incorrect pathes in pkg-config files - Resolves: bug 1396448 - Add a hard dependency for >=selinux-policy-3.13.1-75- Bump version to 1.3.6.1-5 - Resolves: bug 1377452 - Integer overflow in counters and monitor - Resolves: bug 1425907 - Harden password storage scheme - Resolves: bug 1431207 - ns-slapd killed by SIGABRT- Bump version to 1.3.6.1-4 - Resolves: bug 1379424 - Reset-agmt-update-staus-and-total-init - Resolves: bug 1394000 - dbmon.sh-fails-if-you-have-nsslapd-requi.patch - Resolves: bug 1417344 - targetattr-wildcard-evaluation-is-incorr.patch - Resolves: bug 1429770 - ds-logpipe.py-crashes-for-non-existing-u.patch - Resolves: bug 1433697 - Fix-double-free-in-_cl5NewDBFile-error-path.patch - Resolves: bug 1433996 - retrocl-can-crash-server-at-shutdown.patch - Resolves: bug 1434967 - rpm-would-not-create-valid-pkgconfig-fi.patch - Resolves: bug 1417338 - To-debug-DB_DEADLOCK-condition-allow-to.patch - Resolves: bug 1433850 - Deleting-suffix-can-hang-server.patch- Bump version to 1.3.6.1-3 - Fix spec file to include the tests- Bump version to 1.3.6.1-2 - Resolves: bug 1431877 - 389-1.3.6.1-1.el7 covscan errors - Resolves: bug 1432206 - content sync plugin can hang server shutdown - Resolves: bug 1432149 - sasl external binds fail in 1.3.6.1- Bump version to 1.3.6.1-1 - Resolves: bug 1388567 - Rebase 389-ds-base to 1.3.6 in RHEL-7.4- Release 1.3.5.10-12 - Resolves: bug 1384785 - Replica install fails with old IPA master sometimes during replication process (DS 48992) - Resolves: bug 1388501 - 389-ds-base is missing runtime dependency - bind-utils (DS 48328) - Resolves: bug 1388581 - Replication stops working only when fips mode is set to true (DS 48909) - Resolves: bug 1390342 - ns-accountstatus.pl shows wrong status for accounts inactivated by Account policy plugin (DS 49014) - Resolves: bug 1390343 - trace args debug logging must be more restrictive (DS 49009)- Release 1.3.5.10-11 - Resolves: bug 1321124 - Replication changelog can incorrectly skip over updates- Release 1.3.5.10-10 - Resolves: bug 1370300 - set proper update status to replication agreement in case of failure (DS 48957) - Resolves: bug 1209094 - Allow logging of rejected changes (DS 48969)- Release 1.3.5.10-9 - Resolves: bug 1364190 - Change example in /etc/sysconfig/dirsrv to use tcmalloc (DS 48950) - Resolves: bug 1366828 - audit on failure doesn't work if attribute nsslapd-auditlog-logging-enabled is NOT enabled (DS 48958) - Resolves: bug 1368520 - Crash in import_wait_for_space_in_fifo() (DS 48960) - Resolves: bug 1368956 - man page of ns-accountstatus.pl shows redundant entries for -p port option - Resolves: bug 1369537 - passwordMinAge attribute doesn't limit the minimum age of the password (DS 48967) - Resolves: bug 1369570 - cleanallruv changelog cleaning incorrectly impacts all backends (DS 48964) - Resolves: bug 1369425 - ACI behaves erratically (DS 48972) - Resolves: bug 1370300 - set proper update status to replication agreement in case of failure (DS 48957) - Resolves: bug 1209094 - Allow logging of rejected changes (DS 48969) - Resolves: bug 1371283 - Server Side Sorting crashes the server. (DS 48970) - Resolves: bug 1371284 - Disabling CLEAR password storage scheme will crash server when setting a password (DS 48975)- Release 1.3.5.10-8 - Resolves: bug 1321124 - Replication changelog can incorrectly skip over updates (DS 48954) - Resolves: bug 1364190 - Change example in /etc/sysconfig/dirsrv to use tcmalloc (DS 48950) - Resolves: bug 1366561 - ns-accountstatus.pl giving error even "No such object (32)" (DS 48956)- Release 1.3.5.10-7 - Resolves: bug 1316580 - dirsrv service doesn't ask for pin when pin.txt is missing (DS 48450) - Resolves: bug 1360976 - fixing a compiler warning- Release 1.3.5.10-6 - Resolves: bug 1326077 - Page result search should return empty cookie if there is no returned entry (DS 48928) - Resolves: bug 1360447 - nsslapd-workingdir is empty when ns-slapd is started by systemd (DS 48939) - Resolves: bug 1360327 - remove-ds.pl deletes an instance even if wrong prefix was specified (DS 48934) - Resolves: bug 1349815 - DS logs have warning:ancestorid not indexed for all CS subsystems (DS 48940) - Resolves: bug 1329061 - 389-ds-base-1.3.4.0-29.el7_2 "hang" (DS 48882) - Resolves: bug 1360976 - EMBARGOED CVE-2016-5405 389-ds-base: Password verification vulnerable to timing attack - Resolves: bug 1361134 - When fine-grained policy is applied, a sub-tree has a priority over a user while changing password (DS 48943) - Resolves: bug 1361321 - Duplicate collation entries (DS 48936) - Resolves: bug 1316580 - dirsrv service doesn't ask for pin when pin.txt is missing (DS 48450) - Resolves: bug 1350799 - CVE-2016-4992 389-ds-base: Information disclosure via repeat- Release 1.3.5.10-5 - Resolves: bug 1333184 - (389-ds-base-1.3.5) Fixing coverity issues. (DS 48919)- Release 1.3.5.10-4 - Resolves: bug 1209128 - [RFE] Add a utility to get the status of Directory Server instances (DS 48144) - Resolves: bug 1333184 - (389-ds-base-1.3.5) Fixing coverity issues. (DS 48919) - Resolves: bug 1350799 - CVE-2016-4992 389-ds-base: Information disclosure via repeat - Resolves: bug 1354660 - flow control in replication also blocks receiving results (DS 48767) - Resolves: bug 1356261 - Fixup tombstone task needs to set proper flag when updating (DS 48924) - Resolves: bug 1355760 - ns-slapd crashes during the deletion of backend (DS 48922) - Resolves: bug 1353629 - DS shuts down automatically if dnaThreshold is set to 0 in a MMR setup (DS 48916) - Resolves: bug 1355879 - nunc-stans: ns-slapd crashes during startup with SIGILL on AMD Opteron 280 (DS 48925)- Release 1.3.5.10-3 - Resolves: bug 1354374 - Fixing the tarball version in the sources file.- Release 1.3.5.10-2 - Resolves: bug 1353714 - If a cipher is disabled do not attempt to look it up (DS 48743) - Resolves: bug 1353592 - Setup-ds.pl --update fails - regression (DS 48755) - Resolves: bug 1353544 - db2bak.pl task enters infinitive loop when bak fs is almost full (DS 48914) - Resolves: bug 1354374 - Upgrade to 389-ds-base >= 1.3.5.5 doesn't install 389-ds-base-snmp (DS 48918)- Release 1.3.5.10-1 - Resolves: bug 1333184 - (389-ds-base-1.3.5) Fixing coverity issues. (DS 48905)- Release 1.3.5.9-1 - Resolves: bug 1349571 - Improve MMR replication convergence (DS 48636) - Resolves: bug 1304682 - "stale" automember rule (associated to a removed group) causes discrepancies in the database (DS 48637) - Resolves: bug 1314956 - moving an entry cause next on-line init to skip entry has no parent, ending at line 0 of file "(bulk import)" (DS 48755) - Resolves: bug 1316731 - syncrepl search returning error 329; plugin sending a bad error code (DS 48904) - Resolves: bug 1346741 - ns-slapd crashes during the shutdown after adding attribute with a matching rule (DS 48891) - Resolves: bug 1349577 - Values of dbcachetries/dbcachehits in cn=monitor could overflow. (DS 48899) - Resolves: bug 1272682 - nunc-stans: ns-slapd killed by SIGABRT (DS 48898) - Resolves: bug 1346043 - repl-monitor displays colors incorrectly for the time lag > 60 min (DS 47538) - Resolves: bug 1350632 - ns-slapd shutdown crashes if pwdstorageschema name is from stack. (DS 48902)- Release 1.3.5.8-1 - Resolves: bug 1290101 - proxyauth support does not work when bound as directory manager (DS 48366)- Release 1.3.5.7-1 - Resolves: bug 1196282 - substring index with nssubstrbegin: 1 is not being used with filters like (attr=x*) (DS 48109) - Resolves: bug 1303794 - Import readNSState.py from RichM's repo (DS 48449) - Resolves: bug 1290101 - proxyauth support does not work when bound as directory manager (DS 48366) - Resolves: bug 1338872 - Wrong result code display in audit-failure log (DS 48892) - Resolves: bug 1346043 - repl-monitor displays colors incorrectly for the time lag > 60 min (DS 47538) - Resolves: bug 1346741 - ns-slapd crashes during the shutdown after adding attribute with a matching rule (DS 48891) - Resolves: bug 1347407 - By default aci can be read by anonymous (DS 48354) - Resolves: bug 1347412 - cn=SNMP,cn=config entry can be read by anonymous (DS 48893)- Release 1.3.5.6-1 - Resolves: bug 1273549 - [RFE] Improve timestamp resolution in logs (DS 47982) - Resolves: bug 1321124 - Replication changelog can incorrectly skip over updates (DS 48766, DS 48636) - Resolves: bug 1233926 - "matching rules" in ACI's "bind rules not fully evaluated (DS 48234) - Resolves: bug 1346165 - 389-ds-base-1.3.5.5-1.el7.x86_64 requires policycoreutils-py- Release 1.3.5.5-1 - Resolves: bug 1018944 - [RFE] Enhance password change tracking (DS 48833) - Resolves: bug 1344414 - [RFE] adding pre/post extop ability (DS 48880) - Resolves: bug 1303794 - Import readNSState.py from RichM's repo (DS 48449) - Resolves: bug 1257568 - /usr/lib64/dirsrv/libnunc-stans.so is owned by both -libs and -devel (DS 48404) - Resolves: bug 1314956 - moving an entry cause next on-line init to skip entry has no parent, ending at line 0 of file "(bulk import)" (DS 48755) - Resolves: bug 1342609 - At startup DES to AES password conversion causes timeout in start script (DS 48862) - Resolves: bug 1316328 - search returns no entry when OR filter component contains non readable attribute (DS 48275) - Resolves: bug 1280456 - setup-ds should detect if port is already defined (DS 48336) - Resolves: bug 1312557 - dirsrv service fails to start when nsslapd-listenhost is configured (DS 48747) - Resolves: bug 1326077 - Page result search should return empty cookie if there is no returned entry (DS 48752) - Resolves: bug 1340307 - Running db2index with no options breaks replication (DS 48854) - Resolves: bug 1337195 - Regression introduced in matching rules by DS 48746 (DS 48844) - Resolves: bug 1335492 - Modifier's name is not recorded in the audit log with modrdn and moddn operations (DS 48834) - Resolves: bug 1316741 - ldctl should support -H with ldap uris (DS 48754)- release 1.3.5.4-1 - Resolves: bug 1334455 - db2ldif is not taking into account multiple suffixes or backends (DS 48828) - Resolves: bug 1241563 - The "repl-monitor" web page does not display "year" in date. (DS 48220) - Resolves: bug 1335618 - Server ram sanity checks work in isolation (DS 48617) - Resolves: bug 1333184 - (389-ds-base-1.3.5) Fixing coverity issues. (DS 48837)- release 1.3.5.3-1 - Resolves: bug 1209128 - [RFE] Add a utility to get the status of Directory Server instances (DS 48144) - Resolves: bug 1332533 - ns-accountstatus.pl gives error message on execution along with results. (DS 48815) - Resolves: bug 1332709 - password history is not updated when an admin resets the password (DS 48813) - Resolves: bug 1333184 - (389-ds-base-1.3.5) Fixing coverity issues. (DS 48822) - Resolves: bug 1333515 - Enable DS to offer weaker DH params in NSS (DS 48798)- release 1.3.5.2-1 - Resolves: bug 1270020 - Rebase 389-ds-base to 1.3.5 in RHEL-7.3 - Resolves: bug 1288229 - many attrlist_replace errors in connection with cleanallruv (DS 48283) - Resolves: bug 1315893 - License tag does not match actual license of code (DS 48757) - Resolves: bug 1320715 - DES to AES password conversion fails if a backend is empty (DS 48777) - Resolves: bug 190862 - [RFE] Default password syntax settings don't work with fine-grained policies (DS 142) - Resolves: bug 1018944 - [RFE] Enhance password change tracking (DS 548) - Resolves: bug 1143066 - The dirsrv user/group should be created in rpm %pre, and ideally with fixed uid/gid (DS 48285) - Resolves: bug 1153758 - [RFE] Support SASL/GSSAPI when ns-slapd is behind a load-balancer (DS 48332) - Resolves: bug 1160902 - search, matching rules and filter error "unsupported type 0xA9" (DS 48016) - Resolves: bug 1186512 - High memory fragmentation observed in ns-slapd; OOM-Killer invoked (DS 48377, 48129) - Resolves: bug 1196282 - substring index with nssubstrbegin: 1 is not being used with filters like (attr=x*) (DS 48109) - Resolves: bug 1209094 - [RFE] Allow logging of rejected changes (DS 48145, 48280) - Resolves: bug 1209128 - [RFE] Add a utility to get the status of Directory Server instances (DS 48144) - Resolves: bug 1210842 - [RFE] Add PIDFile option to systemd service file (DS 47951) - Resolves: bug 1223510 - [RFE] it could be nice to have nsslapd-maxbersize default to bigger than 2Mb (DS 48326) - Resolves: bug 1229799 - ldclt-bin killed by SIGSEGV (DS 48289) - Resolves: bug 1249908 - No validation check for the value for nsslapd-db-locks. (DS 48244) - Resolves: bug 1254887 - No man page entry for - option '-u' of dbgen.pl for adding group entries with uniquemembers (DS 48290) - Resolves: bug 1255557 - db2index creates index entry from deleted records (DS 48252) - Resolves: bug 1258610 - total update request must not be lost (DS 48255) - Resolves: bug 1258611 - dna plugin needs to handle binddn groups for authorization (DS 48258) - Resolves: bug 1259624 - [RFE] Provide a utility to detect accounts locked due to inactivity (DS 48269) - Resolves: bug 1259950 - Add config setting to MemberOf Plugin to add required objectclass got memberOf attribute (DS 48267) - Resolves: bug 1266510 - Linked Attributes plug-in - wrong behaviour when adding valid and broken links (DS 48295) - Resolves: bug 1266532 - Linked Attributes plug-in - won't update links after MODRDN operation (DS 48294) - Resolves: bug 1267750 - pagedresults - when timed out, search results could have been already freed. (DS 48299) - Resolves: bug 1269378 - ds-logpipe.py with wrong arguments - python exception in the output (DS 48302) - Resolves: bug 1271330 - nunc-stans: Attempt to release connection that is not acquired (DS 48311) - Resolves: bug 1272677 - nunc stans: ns-slapd killed by SIGTERM - Resolves: bug 1272682 - nunc-stans: ns-slapd killed by SIGABRT - Resolves: bug 1273142 - crash in Managed Entry plugin (DS 48312) - Resolves: bug 1273549 - [RFE] Improve timestamp resolution in logs (DS 47982) - Resolves: bug 1273550 - Deadlock between two MODs on the same entry between entry cache and backend lock (DS 47978) - Resolves: bug 1273555 - deadlock in mep delete post op (DS 47976) - Resolves: bug 1273584 - lower password history minimum to 1 (DS 48394) - Resolves: bug 1275763 - [RFE] add setup-ds.pl option to disable instance specific scripts (DS 47840) - Resolves: bug 1276072 - [RFE] Allow RHDS to be setup using a DNS CNAME alias for General.FullMachineName (DS 48328) - Resolves: bug 1278567 - SimplePagedResults -- abandon could happen between the abandon check and sending results (DS 48338) - Resolves: bug 1278584 - Share nsslapd-threadnumber in the case nunc-stans is enabled, as well. (DS 48339) - Resolves: bug 1278755 - deadlock on connection mutex (DS 48341) - Resolves: bug 1278987 - Cannot upgrade a consumer to supplier in a multimaster environment (DS 48325) - Resolves: bug 1280123 - acl - regression - trailing ', (comma)' in macro matched value is not removed. (DS 48344) - Resolves: bug 1290111 - [RFE] Support for rfc3673 '+' to return operational attributes (DS 48363) - Resolves: bug 1290141 - With exhausted range, part of DNA shared configuration is deleted after server restart (DS 48362) - Resolves: bug 1290242 - SimplePagedResults -- in the search error case, simple paged results slot was not released. (DS 48375) - Resolves: bug 1290600 - The 'eq' index does not get updated properly when deleting and re-adding attributes in the same ldapmodify operation (DS 48370) - Resolves: bug 1295947 - 389-ds hanging after a few minutes of operation (DS 48406, revert 48338) - Resolves: bug 1296310 - ldclt - segmentation fault error while binding (DS 48400) - Resolves: bug 1299758 - CVE-2016-0741 389-ds-base: Worker threads do not detect abnormally closed connections causing DoS [rhel-7.3] - Resolves: bug 1301097 - logconv.pl displays negative operation speeds (DS 48446) - Resolves: bug 1302823 - Crash in slapi_get_object_extension (DS 48536) - Resolves: bug 1303641 - heap corruption at schema replication. (DS 48492) - Resolves: bug 1307151 - keep alive entries can break replication (DS 48445) - Resolves: bug 1310848 - Supplier can skip a failing update, although it should retry. (DS 47788) - Resolves: bug 1314557 - change severity of some messages related to "keep alive" enties (DS 48420) - Resolves: bug 1316580 - dirsrv service doesn't ask for pin when pin.txt is missing (DS 48450) - Resolves: bug 1316742 - no plugin calls in tombstone purging (DS 48759) - Resolves: bug 1319329 - [RFE] add nsslapd-auditlog-logging-enabled: off to template-dse.ldif (DS 48145) - Resolves: bug 1320295 - If nsSSL3 is on, even if SSL v3 is not really enabled, a confusing message is logged. (DS 48775) - Resolves: bug 1326520 - db2index uses a buffer size derived from dbcachesize (DS 48383) - Resolves: bug 1328936 - objectclass values could be dropped on the consumer (DS 48799) - Resolves: bug 1287475 - [RFE] response control for password age should be sent by default by RHDS (DS 48369) - Resolves: bug 1331343 - Paged results search returns the blank list of entries (DS 48808)- release 1.3.4.0-19 - Resolves: bug 1228823 - async simple paged results issue (DS 48299, DS 48192) - Resolves: bug 1266944 - ns-slapd crash during ipa-replica-manage del (DS 48298)- release 1.3.4.0-18 - Resolves: bug 1259949 - Fractional replication evaluates several times the same CSN (DS 48266, DS 48284)- release 1.3.4.0-17 - Resolves: bug 1259949 - A backport error (coverity -- unused variable 'init_retry')- release 1.3.4.0-16 - Resolves: bug 1243970 - In MMR, double free coould occur under some special condition (DS 48276, DS 48226) - Resolves: bug 1259949 - Fractional replication evaluates several times the same CSN (DS 48266) - Resolves: bug 1241723 - cleanallruv - fix regression with server shutdown (DS 48217) - Resolves: bug 1264224 - segfault in ns-slapd due to accessing Slapi_DN freed in pre bind plug-in (DS 48188)- release 1.3.4.0-15 - Resolves: bug 1258996 - Complex filter in a search request doen't work as expected. (regression) (DS 48265) - Resolves: bug 1179370 - COS cache doesn't properly mark vattr cache as invalid when there are multiple suffixes (DS 47981)- release 1.3.4.0-14 - Resolves: bug 1246389 - wrong password check if passwordInHistory is decreased. (DS 48228) - Resolves: bug 1255851 - Shell CLI fails with usage errors if an argument containing white spaces is given (DS 48254) - Resolves: bug 1256938 - Unable to dereference unqiemember attribute because it is dn [#UID] not dn syntax (DS 47757)- release 1.3.4.0-13 - Resolves: bug 1245519 - remove debug logging from retro cl (DS 47831)- release 1.3.4.0-12 - Resolves: bug 1252133 - replica upgrade failed in starting dirsrv service (DS 48243) - Resolves: bug 1254344 - Server crashes in ACL_LasFindFlush during shutdown if ACIs contain IP addresss restrictions (DS 48233)- release 1.3.4.0-11 - Resolves: bug 1249784 - ipa-dnskeysyncd unhandled exception on named-pkcs11 start (DS 48249) - Resolves: bug 1252082 - removing chaining database links trigger valgrind read error (DS 47686) - Resolves: bug 1252207 - bashisms in 389-ds-base admin scripts (DS 47511) - Resolves: bug 1252533 - Man pages and help for remove-ds.pl doesn't display "-a" option (DS 48245) - Resolves: bug 1252781 - Slapd crashes reported from latest builds (DS 48250)- release 1.3.4.0-10 - Resolves: bug 1245519 - Fix coverity issues (DS 47931)- release 1.3.4.0-9 - Resolves: bug 1240876 - verify_db.pl doesn't verify DB specified by -a option. (DS 48215) - Resolves: bug 1245235 - winsync lastlogon attribute not syncing between IPA & Windows 2008. (DS 48232) - Resolves: bug 1245519 - Deadlock with retrochangelog, memberof plugin (DS 47931) - Resolves: bug 1246389 - wrong password check if passwordInHistory is decreased. (DS 48228) - Resolves: bug 1247811 - logconv autobind handling regression caused by 47446 (DS 48231) - Resolves: bug 1250177 - Investigate betxn plugins to ensure they return the correct error code (DS 47810)- release 1.3.4.0-8 - Resolves: bug 1160243 - [RFE] allow logconv.pl -S/-E switches to work even when exact/same timestamps are not present in access log file (DS 47910) - Resolves: bug 1172037 - winsync range retrieval gets only 5000 values upon initialization (DS 48010) - Resolves: bug 1242531 - logconv.pl should handle *.tar.xz, *.txz, *.xz log files (DS 48224) - Resolves: bug 1243950 - When starting a replica agreement a deadlock can occur with an op updating nsuniqueid index (DS 48179) - Resolves: bug 1243970 - In MMR, double free coould occur under some special condition (DS 48226) - Resolves: bug 1244926 - Crash while triming the retro changelog (DS 48206)- release 1.3.4.0-7 - Resolves: bug 1235060 - Fix coverity issues - 07/14/2015 (DS 48203) - Resolves: bug 1242531 - redux - logconv.pl should handle *.tar.xz, *.txz, *.xz log files (DS 48224)- release 1.3.4.0-6 - Resolves: bug 1240845 - cleanallruv should completely clean changelog (DS 48208) - Resolves: bug 1095603 - Any negative LDAP error code number reported as Illegal error by ldclt. (DS 47799) - Resolves: bug 1168675 - Inconsistent behaviour of DS when LDAP Sync is used with an invalid cookie (DS 48013) - Resolves: bug 1241723 - cleanAllRUV hangs shutdown if not all of the replicas are online (DS 48217) - Resolves: bug 1241497 - crash in ns-slapd when deleting winSyncSubtreePair from sync agreement (DS 48216) - Resolves: bug 1240404 - Silent install needs to properly exit when INF file is missing (DS 48119) - Resolves: bug 1240406 - Remove warning suppression in 1.3.4 (DS 47878) - Resolves: bug 1242683 - Winsync fails when AD users have multiple spaces (two)inside the value of the rdn attribute (DS 48223) - Resolves: bug 1160243 - logconv.pl - validate start and end time args (DS 47910) - Resolves: bug 1242531 - logconv.pl should handle *.tar.xz, *.txz, *.xz log files (DS 48224) - Resolves: bug 1230996 - CI test: fixing test cases for ticket 48194 (DS 48194)- release 1.3.4.0-5 - Resolves: bug 1235060 - Fix coverity issues (DS 48203)- release 1.3.4.0-4 - Resolves: bug 1240404 - setup-ds.pl does not log invalid --file path errors the same (DS 48119) - Resolves: bug 1240406 - setup -u stops after first failure (DS 47878)- release 1.3.4.0-3 - Resolves: bug 1228823 - async simple paged results issue (DS 48192) - Resolves: bug 1237325 - reindex off-line twice could provoke index corruption (DS 48212) - Resolves: bug 1238790 - ldapsearch on nsslapd-maxbersize returns 0 instead of current value (DS 48214)- release 1.3.4.0-2 - Resolves: bug 1235060 - Fix coverity issues - Resolves: bug 1235387 - Slow replication when deleting large quantities of multi-valued attributes (DS 48195)- Release 1.3.4.0-1 (rebase) - Enable nunc-stans for x86_64. - Resolves: bug 1034325 - Linked attributes betxnpreoperation - transaction not aborted when linked entry does not exit (DS 47640) - Resolves: bug 1052755 - Retro Changelog Plugin accepts invalid value in nsslapd-changelogmaxage attribute (DS 47669) - Resolves: bug 1096409 - RHDS keeps on logging write_changelog_and_ruv: failed to update RUV for unknown (DS 47801) - Resolves: bug 1145378 - Adding an entry with an invalid password as rootDN is incorrectly rejected (DS 47900) - Resolves: bug 1145382 - Bad manipulation of passwordhistory (DS 47905) - Resolves: bug 1154147 - Uniqueness plugin: should allow to exclude some subtrees from its scope (DS 47927) - Resolves: bug 1171358 - Make ReplicaWaitForAsyncResults configurable (DS 47957) - Resolves: bug 1171663 - MODDN fails when entry doesn't have memberOf attribute and new DN is in the scope of memberOfExcludeSubtree (DS 47526) - Resolves: bug 1174457 - [RFE] memberOf - add option to skip nested group lookups during delete operations (DS 47963) - Resolves: bug 1178640 - db2bak.pl man page should be improved. (DS 48008) - Resolves: bug 1179370 - COS cache doesn't properly mark vattr cache as invalid when there are multiple suffixes (DS 47981) - Resolves: bug 1180331 - Local Password Policies for Nested OU's not honoured (DS 47980) - Resolves: bug 1180776 - nsslapd-db-locks modify not taking into account (DS 47934) - Resolves: bug 1181341 - nsslapd-changelogtrim-interval and nsslapd-changelogcompactdb-interval are not validated (DS 47617) - Resolves: bug 1185882 - ns-activate.pl fails to activate account if it was disabled on AD (DS 48001) - Resolves: bug 1186548 - ns-slapd crash in shutdown phase (DS 48005) - Resolves: bug 1189154 - DNS errors after IPA upgrade due to broken ReplSync (DS 48030) - Resolves: bug 1206309 - winsync sets AccountUserControl in AD to 544 (DS 47723) - Resolves: bug 1210845 - slapd crashes during Dogtag clone reinstallation (DS 47966) - Resolves: bug 1210850 - add an option '-u' to dbgen.pl for adding group entries with (DS 48025) - Resolves: bug 1210852 - aci with wildcard and macro not correctly evaluated (DS 48141)- release 1.3.3.1-19 - Resolves: bug 1230996 - nsSSL3Ciphers preference not enforced server side (DS 48194)- release 1.3.3.1-18 - Resolves: bug 1228823 - async simple paged results issue (DS 48146, DS 48192)- release 1.3.3.1-17 - Resolves: bug 1226510 - idm/ipa 389-ds-base entry cache converges to 500 KB in dblayer_is_cachesize_sane (DS 48190)- release 1.3.3.1-16 - Resolves: bug 1212894 - CVE-2015-1854 389ds-base: access control bypass with modrdn- release 1.3.3.1-15 - Setting correct build tag 'rhel-7.1-z-candidate'- release 1.3.3.1-14 - Resolves: bug 1189154 - DNS errors after IPA upgrade due to broken ReplSync (DS 48030) Fixes spec file to make sure all the server instances are stopped before upgrade - Resolves: bug 1186548 - ns-slapd crash in shutdown phase (DS 48005)- release 1.3.3.1-13 - Resolves: bug 1183655 - Fixed Covscan FORWARD_NULL defects (DS 47988)- release 1.3.3.1-12 - Resolves: bug 1182477 - Windows Sync accidentally cleared raw_entry (DS 47989) - Resolves: bug 1180325 - upgrade script fails if /etc and /var are on different file systems (DS 47991 ) - Resolves: bug 1183655 - Schema learning mechanism, in replication, unable to extend an existing definition (DS 47988)- release 1.3.3.1-11 - Resolves: bug 1080186 - During delete operation do not refresh cache entry if it is a tombstone (DS 47750)- release 1.3.3.1-10 - Resolves: bug 1172731 - CVE-2014-8112 password hashing bypassed when "nsslapd-unhashed-pw-switch" is set to off - Resolves: bug 1166265 - DS hangs during online total update (DS 47942) - Resolves: bug 1168151 - CVE-2014-8105 information disclosure through 'cn=changelog' subtree - Resolves: bug 1044170 - Allow memberOf suffixes to be configurable (DS 47526) - Resolves: bug 1171356 - Bind DN tracking unable to write to internalModifiersName without special permissions (DS 47950) - Resolves: bug 1153737 - logconv.pl -- support parsing/showing/reporting different protocol versions (DS 47949) - Resolves: bug 1171355 - start dirsrv after chrony on RHEL7 and Fedora (DS 47947) - Resolves: bug 1170707 - cos_cache_build_definition_list does not stop during server shutdown (DS 47967) - Resolves: bug 1170708 - COS memory leak when rebuilding the cache (DS - Ticket 47969) - Resolves: bug 1170709 - Account lockout attributes incorrectly updated after failed SASL Bind (DS 47970) - Resolves: bug 1166260 - cookie_change_info returns random negative number if there was no change in a tree (DS 47960) - Resolves: bug 1012991 - Error log levels not displayed correctly (DS 47636) - Resolves: bug 1108881 - rsearch filter error on any search filter (DS 47722) - Resolves: bug 994690 - Allow dynamically adding/enabling/disabling/removing plugins without requiring a server restart (DS 47451) - Resolves: bug 1162997 - Running a plugin task can crash the server (DS 47451) - Resolves: bug 1166252 - RHEL7.1 ns-slapd segfault when ipa-replica-install restarts (DS 47451) - Resolves: bug 1172597 - Crash if setting invalid plugin config area for MemberOf Plugin (DS 47525) - Resolves: bug 1139882 - coverity defects found in 1.3.3.x (DS 47965)- release 1.3.3.1-9 - Resolves: bug 1153737 - Disable SSL v3, by default. (DS 47928) - Resolves: bug 1163461 - Should not check aci syntax when deleting an aci (DS 47953)- release 1.3.3.1-8 - Resolves: bug 1156607 - Crash in entry_add_present_values_wsi_multi_valued (DS 47937) - Resolves: bug 1153737 - Disable SSL v3, by default (DS 47928, DS 47945, DS 47948) - Resolves: bug 1158804 - Malformed cookie for LDAP Sync makes DS crash (DS 47939)- release 1.3.3.1-7 - Resolves: bug 1153737 - Disable SSL v3, by default (DS 47928)- release 1.3.3.1-6 - Resolves: bug 1151287 - dynamically added macro aci is not evaluated on the fly (DS 47922) - Resolves: bug 1080186 - Need to move slapi_pblock_set(pb, SLAPI_MODRDN_EXISTING_ENTRY, original_entry->ep_entry) prior to original_entry overwritten (DS 47897) - Resolves: bug 1150694 - Encoding of SearchResultEntry is missing tag (DS 47920) - Resolves: bug 1150695 - ldbm_back_modify SLAPI_PLUGIN_BE_PRE_MODIFY_FN does not return even if one of the preop plugins fails. (DS 47919) - Resolves: bug 1139882 - Fix remaining compiler warnings (DS 47892) - Resolves: bug 1150206 - result of dna_dn_is_shared_config is incorrectly used (DS 47918)- release 1.3.3.1-5 - Resolves: bug 1139882 - coverity defects found in 1.3.3.x (DS 47892)- release 1.3.3.1-4 - Resolves: bug 1080186 - Creating a glue fails if one above level is a conflict or missing (DS 47750) - Resolves: bug 1145846 - 389-ds 1.3.3.0 does not adjust cipher suite configuration on upgrade, breaks itself and pki-server (DS 47908) - Resolves: bug 1117979 - harden the list of ciphers available by default (phase 2) (DS 47838) - provide enabled ciphers as search result (DS 47880)- release 1.3.3.1-3 - Resolves: bug 1139882 - coverity defects found in 1.3.3.1- release 1.3.3.1-2 - Resolves: bug 1079099 - Simultaneous adding a user and binding as the user could fail in the password policy check (DS 47748) - Resolves: bug 1080186 - Creating a glue fails if one above level is a conflict or missing (DS 47834) - Resolves: bug 1139882 - coverity defects found in 1.3.3.1 (DS 47890) - Resolves: bug 1112702 - Broken dereference control with the FreeIPA 4.0 ACIs (DS 47885 - deref plugin should not return references with noc access rights) - Resolves: bug 1117979 - harden the list of ciphers available by default (DS 47838, DS 47895) - Resolves: bug 1080186 - Creating a glue fails if one above level is a conflict or missing (DS 47889 - DS crashed during ipa-server-install on test_ava_filter)- release 1.3.3.1-1 - Resolves: bug 746646 - RFE: easy way to configure which users and groups to sync with winsync - Resolves: bug 881372 - nsDS5BeginReplicaRefresh attribute accepts any value and it doesn't throw any error when server restarts. - Resolves: bug 920597 - Possible to add invalid ACI value - Resolves: bug 921162 - Possible to add nonexistent target to ACI - Resolves: bug 923799 - if nsslapd-cachememsize set to the number larger than the RAM available, should result in proper error message. - Resolves: bug 924937 - Attribute "dsOnlyMemberUid" not allowed when syncing nested posix groups from AD with posixWinsync - Resolves: bug 951754 - Self entry access ACI not working properly - Resolves: bug 952517 - Dirsrv instance failed to start with Segmentation fault (core dump) after modifying 7-bit check plugin - Resolves: bug 952682 - nsslapd-db-transaction-batch-val turns to -1 - Resolves: bug 966443 - Plugin library path validation - Resolves: bug 975176 - Non-directory manager can change the individual userPassword's storage scheme - Resolves: bug 979465 - IPA replica's - "SASL encrypted packet length exceeds maximum allowed limit" - Resolves: bug 982597 - Some attributes in cn=config should not be multivalued - Resolves: bug 987009 - 389-ds-base - shebang with /usr/bin/env - Resolves: bug 994690 - RFE: Allow dynamically adding/enabling/disabling/removing plugins without requiring a server restart - Resolves: bug 1012991 - errorlog-level 16384 is listed as 0 in cn=config - Resolves: bug 1013736 - Enabling/Disabling DNA plug-in throws "ldap_modify: Server Unwilling to Perform (53)" error - Resolves: bug 1014380 - setup-ds.pl doesn't lookup the "root" group correctly - Resolves: bug 1020459 - rsa_null_sha should not be enabled by default - Resolves: bug 1024541 - start dirsrv after ntpd - Resolves: bug 1029959 - Managed Entries betxnpreoperation - transaction not aborted upon failure to create managed entry - Resolves: bug 1031216 - add dbmon.sh - Resolves: bug 1044133 - Indexed search with filter containing '&' and "!" with attribute subtypes gives wrong result - Resolves: bug 1044134 - should set LDAP_OPT_X_SASL_NOCANON to LDAP_OPT_ON by default - Resolves: bug 1044135 - make connection buffer size adjustable - Resolves: bug 1044137 - posix winsync should support ADD user/group entries from DS to AD - Resolves: bug 1044138 - mep_pre_op: Unable to fetch origin entry - Resolves: bug 1044139 - [RFE] Support RFC 4527 Read Entry Controls - Resolves: bug 1044140 - Allow search to look up 'in memory RUV' - Resolves: bug 1044141 - MMR stress test with dna enabled causes a deadlock - Resolves: bug 1044142 - winsync doesn't sync DN valued attributes if DS DN value doesn't exist - Resolves: bug 1044143 - modrdn + NSMMReplicationPlugin - Consumer failed to replay change - Resolves: bug 1044144 - resurrected entry is not correctly indexed - Resolves: bug 1044146 - Add a warning message when a connection hits the max number of threads - Resolves: bug 1044147 - 7-bit check plugin does not work for userpassword attribute - Resolves: bug 1044148 - The backend name provided to bak2db is not validated - Resolves: bug 1044149 - Winsync should support range retrieval - Resolves: bug 1044150 - 7-bit checking is not necessary for userPassword - Resolves: bug 1044151 - With SeLinux, ports can be labelled per range. setup-ds.pl or setup-ds-admin.pl fail to detect already ranged labelled ports - Resolves: bug 1044152 - ChainOnUpdate: "cn=directory manager" can modify userRoot on consumer without changes being chained or replicated. Directory integrity compromised. - Resolves: bug 1044153 - mods optimizer - Resolves: bug 1044154 - multi master replication allows schema violation - Resolves: bug 1044156 - DS crashes with some 7-bit check plugin configurations - Resolves: bug 1044157 - Some updates of "passwordgraceusertime" are useless when updating "userpassword" - Resolves: bug 1044159 - [RFE] Support 'Content Synchronization Operation' (SyncRepl) - RFC 4533 - Resolves: bug 1044160 - remove-ds.pl should remove /var/lock/dirsrv - Resolves: bug 1044162 - enhance retro changelog - Resolves: bug 1044163 - updates to ruv entry are written to retro changelog - Resolves: bug 1044164 - Password administrators should be able to violate password policy - Resolves: bug 1044168 - Schema replication between DS versions may overwrite newer base schema - Resolves: bug 1044169 - ACIs do not allow attribute subtypes in targetattr keyword - Resolves: bug 1044170 - Allow memberOf suffixes to be configurable - Resolves: bug 1044171 - Allow referential integrity suffixes to be configurable - Resolves: bug 1044172 - Plugin library path validation prevents intentional loading of out-of-tree modules - Resolves: bug 1044173 - make referential integrity configuration more flexible - Resolves: bug 1044177 - allow configuring changelog trim interval - Resolves: bug 1044179 - objectclass may, must lists skip rest of objectclass once first is found in sup - Resolves: bug 1044180 - memberOf on a user is converted to lowercase - Resolves: bug 1044181 - report unindexed internal searches - Resolves: bug 1044183 - With 1.3.04 and subtree-renaming OFF, when a user is deleted after restarting the server, the same entry can't be added - Resolves: bug 1044185 - dbscan on entryrdn should show all matching values - Resolves: bug 1044187 - logconv.pl - RFE - add on option for a minimum etime for unindexed search stats - Resolves: bug 1044188 - Recognize compressed log files - Resolves: bug 1044191 - support TLSv1.1 and TLSv1.2, if supported by NSS - Resolves: bug 1044193 - default nsslapd-sasl-max-buffer-size should be 2MB - Resolves: bug 1044194 - Complex filter in a search request doen't work as expected. - Resolves: bug 1044196 - Automember plug-in should treat MODRDN operations as ADD operations - Resolves: bug 1044198 - Replication of the schema may overwrite consumer 'attributetypes' even if consumer definition is a superset - Resolves: bug 1044202 - db2bak.pl issue when specifying non-default directory - Resolves: bug 1044203 - Allow referint plugin to use an alternate config area - Resolves: bug 1044205 - Allow memberOf to use an alternate config area - Resolves: bug 1044210 - idl switch does not work - Resolves: bug 1044211 - make old-idl tunable - Resolves: bug 1044212 - IDL-style can become mismatched during partial restoration - Resolves: bug 1044213 - backend performance - introduce optimization levels - Resolves: bug 1044215 - using transaction batchval violates durability - Resolves: bug 1044216 - examine replication code to reduce amount of stored state information - Resolves: bug 1048980 - 7-bit check plugin not checking MODRDN operation - Resolves: bug 1049030 - Windows Sync group issues - Resolves: bug 1052751 - Page control does not work if effective rights control is specified - Resolves: bug 1052754 - Allow nsDS5ReplicaBindDN to be a group DN - Resolves: bug 1057803 - logconv errors when search has invalid bind dn - Resolves: bug 1060032 - [RFE] Update lastLoginTime also in Account Policy plugin if account lockout is based on passwordExpirationTime. - Resolves: bug 1061060 - betxn: retro changelog broken after cancelled transaction - Resolves: bug 1061572 - improve dbgen rdn generation, output and man page. - Resolves: bug 1063990 - single valued attribute replicated ADD does not work - Resolves: bug 1064006 - Size returned by slapi_entry_size is not accurate - Resolves: bug 1064986 - Replication retry time attributes cannot be added - Resolves: bug 1067090 - Missing warning for invalid replica backoff configuration - Resolves: bug 1072032 - Updating nsds5ReplicaHost attribute in a replication agreement fails with error 53 - Resolves: bug 1074306 - Under heavy stress, failure of turning a tombstone into glue makes the server hung - Resolves: bug 1074447 - Part of DNA shared configuration is deleted after server restart - Resolves: bug 1076729 - Continuous add/delete of an entry in MMR setup causes entryrdn-index conflict - Resolves: bug 1077884 - ldap/servers/slapd/back-ldbm/dblayer.c: possible minor problem with sscanf - Resolves: bug 1077897 - Memory leak with proxy auth control - Resolves: bug 1079099 - Simultaneous adding a user and binding as the user could fail in the password policy check - Resolves: bug 1080186 - Creating a glue fails if one above level is a conflict or missing - Resolves: bug 1082967 - attribute uniqueness plugin fails when set as a chaining component - Resolves: bug 1085011 - Directory Server crash reported from reliab15 execution - Resolves: bug 1086890 - empty modify returns LDAP_INVALID_DN_SYNTAX - Resolves: bug 1086902 - mem leak in do_bind when there is an error - Resolves: bug 1086904 - mem leak in do_search - rawbase not freed upon certain errors - Resolves: bug 1086908 - Performing deletes during tombstone purging results in operation errors - Resolves: bug 1090178 - #481 breaks possibility to reassemble memberuid list - Resolves: bug 1092099 - A replicated MOD fails (Unwilling to perform) if it targets a tombstone - Resolves: bug 1092342 - nsslapd-ndn-cache-max-size accepts any invalid value. - Resolves: bug 1092648 - Negative value of nsSaslMapPriority is not reset to lowest priority - Resolves: bug 1097004 - Problem with deletion while replicated - Resolves: bug 1098654 - db2bak.pl error with changelogdb - Resolves: bug 1099654 - Normalization from old DN format to New DN format doesnt handel condition properly when there is space in a suffix after the seperator operator. - Resolves: bug 1108405 - find a way to remove replication plugin errors messages "changelog iteration code returned a dummy entry with csn %s, skipping ..." - Resolves: bug 1108407 - managed entry plugin fails to update managed entry pointer on modrdn operation - Resolves: bug 1108865 - memory leak in ldapsearch filter objectclass=* - Resolves: bug 1108870 - ACI warnings in error log - Resolves: bug 1108872 - Logconv.pl with an empty access log gives lots of errors - Resolves: bug 1108874 - logconv.pl memory continually grows - Resolves: bug 1108881 - rsearch filter error on any search filter - Resolves: bug 1108895 - [RFE - RHDS9] CLI report to monitor replication - Resolves: bug 1108902 - rhds91 389-ds-base-1.2.11.15-31.el6_5.x86_64 crash in db4 __dbc_get_pp env = 0x0 ? - Resolves: bug 1108909 - single valued attribute replicated ADD does not work - Resolves: bug 1109334 - 389 Server crashes if uniqueMember is invalid syntax and memberOf plugin is enabled. - Resolves: bug 1109336 - Parent numsubordinate count can be incorrectly updated if an error occurs - Resolves: bug 1109339 - Nested tombstones become orphaned after purge - Resolves: bug 1109354 - Tombstone purging can crash the server if the backend is stopped/disabled - Resolves: bug 1109357 - Coverity issue in 1.3.3 - Resolves: bug 1109364 - valgrind - value mem leaks, uninit mem usage - Resolves: bug 1109375 - provide default syntax plugin - Resolves: bug 1109378 - Environment variables are not passed when DS is started via service - Resolves: bug 1111364 - Updating winsync one-way sync does not affect the behaviour dynamically - Resolves: bug 1112824 - Broken dereference control with the FreeIPA 4.0 ACIs - Resolves: bug 1113605 - server restart wipes out index config if there is a default index - Resolves: bug 1115177 - attrcrypt_generate_key calls slapd_pk11_TokenKeyGenWithFlags with improper macro - Resolves: bug 1117021 - Server deadlock if online import started while server is under load - Resolves: bug 1117975 - paged results control is not working in some cases when we have a subsuffix. - Resolves: bug 1117979 - harden the list of ciphers available by default - Resolves: bug 1117981 - Fix various typos in manpages & code - Resolves: bug 1117982 - Fix hyphens used as minus signed and other manpage mistakes - Resolves: bug 1118002 - server crashes deleting a replication agreement - Resolves: bug 1118006 - RFE - forcing passwordmustchange attribute by non-cn=directory manager - Resolves: bug 1118007 - [RFE] Make it possible for privileges to be provided to an admin user to import an LDIF file containing hashed passwords - Resolves: bug 1118014 - Enhance ACIs to have more control over MODRDN operations - Resolves: bug 1118021 - Return all attributes in rootdse without explicit request - Resolves: bug 1118025 - Slow ldapmodify operation time for large quantities of multi-valued attribute values - Resolves: bug 1118032 - Schema Replication Issue - Resolves: bug 1118034 - 389 DS Server crashes and dies while handles paged searches from clients - Resolves: bug 1118043 - Failed deletion of aci: no such attribute - Resolves: bug 1118048 - If be_txn plugin fails in ldbm_back_add, adding entry is double freed. - Resolves: bug 1118051 - Add switch to disable pre-hashed password checking - Resolves: bug 1118054 - Make ldbm_back_seq independently support transactions - Resolves: bug 1118055 - Add operations rejected by betxn plugins remain in cache - Resolves: bug 1118057 - online import crashes server if using verbose error logging - Resolves: bug 1118059 - add fixup-memberuid.pl script - Resolves: bug 1118060 - winsync plugin modify is broken - Resolves: bug 1118066 - memberof scope: allow to exclude subtrees - Resolves: bug 1118069 - 389-ds production segfault: __memcpy_sse2_unaligned () at ../sysdeps/x86_64/multiarch/memcpy-sse2-unaligned.S:144 - Resolves: bug 1118074_DELETE_FN - plugin returned error" messages - Resolves: bug 1118076 - ds logs many "Operation error fetching Null DN" messages - Resolves: bug 1118077 - Improve import logging and abort handling - Resolves: bug 1118079 - Multi master replication initialization incomplete after restore of one master - Resolves: bug 1118080 - Don't add unhashed password mod if we don't have an unhashed value - Resolves: bug 1118081 - Investigate betxn plugins to ensure they return the correct error code - Resolves: bug 1118082 - The error result text message should be obtained just prior to sending result - Resolves: bug 1123865 - CVE-2014-3562 389-ds-base: 389-ds: unauthenticated information disclosure [rhel-7.1]- release 1.3.1.6-26 - Resolves: bug 1085011 - Directory Server crash reported from reliab15 execution (Ticket 346)- release 1.3.1.6-25 - Resolves: bug 1082740 - ns-slapd crash in reliability 15- release 1.3.1.6-24 - Resolves: bug 1074084 - e_uniqueid fails to set if an entry is a conflict entry (Ticket 47735); regression - sub-type length in attribute type was mistakenly subtracted.- Resolves: bug 1074850 - EMBARGOED CVE-2014-0132 389-ds-base: 389-ds: flaw in parsing authzid can lead to privilege escalation [rhel-7.0] (Ticket 47739 - directory server is insecurely misinterpreting authzid on a SASL/GSSAPI bind) (Added 0095-Ticket-47739-directory-server-is-insecurely-misinter.patch) Tue Mar 11 2014 Noriko Hosoi - 1.3.1.6-23 - release 1.3.1.6-22 - Resolves: bug 1074850 - EMBARGOED CVE-2014-0132 389-ds-base: 389-ds: flaw in parsing authzid can lead to privilege escalation [rhel-7.0] (Ticket 47739 - directory server is insecurely misinterpreting authzid on a SASL/GSSAPI bind)- release 1.3.1.6-22 - Resolves: bug 1074084 - e_uniqueid fails to set if an entry is a conflict entry (Ticket 47735)- release 1.3.1.6-21 - Resolves: bug 918694 - Fix covscan defect FORWARD_NULL (Ticket 408) - Resolves: bug 918717 - Fix covscan defect COMPILER WARNINGS (Ticket 571)- release 1.3.1.6-20 - Resolves: bug 1065242 - 389-ds-base, conflict occurs at yum installation if multilib_policy=all. (Ticket 47709)- release 1.3.1.6-19 - Resolves: bug 1065971 - Enrolling a host into IdM/IPA always takes two attempts (Ticket 47704)- release 1.3.1.6-18 - Resolves: bug 838656 - logconv.pl tool removes the access logs contents if "-M" is not correctly used (Ticket 471) - Resolves: bug 922538 - improve dbgen rdn generation, output (Ticket 47374) - Resolves: bug 970750 - flush.pl is not included in perl5 (Ticket 47374) - Resolves: bug 1013898 - Fix various issues with logconv.pl (Ticket 471)- release 1.3.1.6-17 - Resolves: bug 853106 - Deleting attribute present in nsslapd-allowed-to-delete-attrs returns Operations error (Ticket 443) - Resolves: bug 1049525 - Server hangs in cos_cache when adding a user entry (Ticket 47649)- Mass rebuild 2014-01-24- release 1.3.1.6-15 - Resolves: bug 918702 - better error message when cache overflows (Ticket 342) - Resolves: bug 1009679 - replication stops with excessive clock skew (Ticket 47516) - Resolves: bug 1042855 - Unable to delete protocol timeout attribute (Ticket 47620) - Resolves: bug 918694 - Fix crash when disabling/enabling the setting (Ticket 408) - Resolves: bug 853355 - config_set_allowed_to_delete_attrs: Valgrind reports Invalid read (Ticket 47660)- release 1.3.1.6-14 - Resolves: bug 853355 - Possible to add invalid attribute to nsslapd-allowed-to-delete-attrs (Ticket 447) - Resolves: bug 1034739 - Impossible to configure nsslapd-allowed-sasl-mechanisms (Ticket 47613) - Resolves: bug 1038639 - 389-ds rejects nsds5ReplicaProtocolTimeout attribut; Fix logically dead code; Fix dereferenced NULL pointer in agmtlist_modify_callback(); Fix missing left brackete (Ticket 47620) - Resolves: bug 1042855 - nsds5ReplicaProtocolTimeout attribute is not validated when added to replication agreement; Config value validation improvement (Ticket 47620) - Resolves: bug 918717 - server does not accept 0 length LDAP Control sequence (Ticket 571) - Resolves: bug 1034902 - replica init/bulk import errors should be more verbose (Ticket 47606) - Resolves: bug 1044219 - fix memleak caused by 47347 (Ticket 47623) - Resolves: bug 1049522 - Crash after replica is installed; Fix cherry-pick error for 1.3.2 and 1.3.1 (Ticket 47620) - Resolves: bug 1049568 - changelog iteration should ignore cleaned rids when getting the minCSN (Ticket 47627)- Mass rebuild 2013-12-27- release 1.3.1.6-12 - Resolves: bug 1038639 - 389-ds rejects nsds5ReplicaProtocolTimeout attribute (Ticket 47620) - Resolves: bug 1034898 - automember plugin task memory leaks (Ticket 47592) - Resolves: bug 1034451 - Possible to specify invalid SASL mechanism in nsslapd-allowed-sasl-mechanisms (Ticket 47614) - Resolves: bug 1032318 - entries with empty objectclass attribute value can be hidden (Ticket 47591) - Resolves: bug 1032316 - attrcrypt fails to find unlocked key (Ticket 47596) - Resolves: bug 1031227 - Reduce lock scope in retro changelog plug-in (Ticket 47599) - Resolves: bug 1031226 - Convert ldbm_back_seq code to be transaction aware (Ticket 47598) - Resolves: bug 1031225 - Convert retro changelog plug-in to betxn (Ticket 47597) - Resolves: bug 1031223 - hard coded limit of 64 masters in agreement and changelog code (Ticket 47587) - Resolves: bug 1034739 - Impossible to configure nsslapd-allowed-sasl-mechanisms (Ticket 47613) - Resolves: bug 1035824 - Automember betxnpreoperation - transaction not aborted when group entry does not exist (Ticket 47622)- Resolves: bug 1024979 - CVE-2013-4485 389-ds-base: DoS due to improper handling of ger attr searches- release 1.3.1.6-10 - Resolves: bug 1018893 DS91: ns-slapd stuck in DS_Sleep - had to revert earlier change - does not work and breaks ipa- release 1.3.1.6-9 - Resolves: bug 1028440 - Winsync replica initialization and incremental updates from DS to AD fails on RHEL - Resolves: bug 1027502 - Replication Failures related to skipped entries due to cleaned rids - Resolves: bug 1027047 - Winsync plugin segfault during incremental backoff- release 1.3.1.6-8 - Resolves: bug 971111 - DNA plugin failed to fetch replication agreement - Resolves: bug 1026931 - 1.2.11.29 crash when removing entries from cache- Resolves: bug 1018893 DS91: ns-slapd stuck in DS_Sleep - Resolves: bug 1018914 fixup memberof task does not work: task entry not added- Resolves: bug 1013900 - logconv: some stats do not work across server restarts - previous patch introduced regressions - fixed by c2eced0 ticket #47550 and e2a880b Ticket #47550 and 8b10f83 Ticket #47551 - Resolves: bug 1008610 - tmpfiles.d references /var/lock when they should reference /run/lock - previous patch not complete, fixed by a11be5c Ticket 47513 - Resolves: bug 1016749 - DS crashes when "cn=Directory Manager" is changing it's password - cherry picked upstream f786600 Ticket 47329 and b67e230 Coverity Fixes - Resolves: bug 1015252 locale "nl" not supported by collation plugin - Resolves: bug 1016317 Need to update supported locales - Resolves: bug 1016722 memory leak in range searches- Resolves: bug 1013896 - logconv.pl - Use of comma-less variable list is deprecated - Resolves: bug 1008256 - backend txn plugin fixup tasks should be done in a txn - Resolves: bug 1013738 - CLEANALLRUV doesnt run across all replicas - Resolves: bug 1011220 - PassSync removes User must change password flag on the Windows side - Resolves: bug 1008610 - tmpfiles.d references /var/lock when they should reference /run/lock - Resolves: bug 1012125 - Set up replcation/agreement before initializing the sub suffix, the sub suffix is not found by ldapsearch - Resolves: bug 1013063 - RUV tombstone search with scope "one" doesn`t work - Resolves: bug 1013893 - Indexed search are logged with 'notes=U' in the access logs - Resolves: bug 1013894 - improve logconv.pl performance with large access logs - Resolves: bug 1013898 - Fix various issues with logconv.pl - Resolves: bug 1013897 - logconv.pl uses /var/tmp for BDB temp files - Resolves: bug 1013900 - logconv: some stats do not work across server restarts - Resolves: bug 1014354 - Coverity fixes - 12023, 12024, and 12025- bump version to 1.3.1.6-4 - Resolves Bug 1007988 - Under specific values of nsDS5ReplicaName, replication may get broken or updates missing (Ticket 47489) - Resolves Bug 853931 - Allow macro aci keywords to be case-insensitive (Ticket 449) - Resolves Bug 1006563 - automember rebuild task not working as expected (Ticket 47507)- Ticket #47455 - valgrind - value mem leaks, uninit mem usage - Ticket 47500 - start-dirsrv/restart-dirsrv/stop-disrv do not register with systemd correctly- bump version to 1.3.1.6-2 - Resolves Bug 1000633 - ns-slapd crash due to bogus DN - Ticket #47488 - Users from AD sub OU does not sync to IPA- bump version to 1.3.1.6 - Ticket 47455 - valgrind - value mem leaks, uninit mem usage - fix coverity 11915 - dead code - introduced with fix for ticket 346 - fix coverity 11895 - null deref - caused by fix to ticket 47392 - fix compiler warning in posix winsync code for posix_group_del_memberuid_callback - Fix compiler warnings for Ticket 47395 and 47397 - fix compiler warning (cherry picked from commit 904416f4631d842a105851b4a9931ae17822a107) - Ticket 47450 - Fix compiler formatting warning errors for 32/64 bit arch - fix compiler warnings - Fix compiler warning (cherry picked from commit ec6ebc0b0f085a82041d993ab2450a3922ef5502)- bump version to 1.3.1.5 - Ticket 47456 - delete present values should append values to deleted values - Ticket 47455 - valgrind - value mem leaks, uninit mem usage - Ticket 47448 - Segfault in 389-ds-base-1.3.1.4-1.fc19 when setting up FreeIPA replication - Ticket 47440 - Fix runtime errors caused by last patch. - Ticket 47440 - Fix compilation warnings and header files - Ticket 47405 - CVE-2013-2219 ACLs inoperative in some search scenarios - Ticket 47447 - logconv.pl man page missing -m,-M,-B,-D - Ticket 47378 - fix recent compiler warnings - Ticket 47427 - Overflow in nsslapd-disk-monitoring-threshold - Ticket 47449 - deadlock after adding and deleting entries - Ticket 47441 - Disk Monitoring not checking filesystem with logs - Ticket 47427 - Overflow in nsslapd-disk-monitoring-threshold- bump version to 1.3.1.4 - Ticket 47435 - Very large entryusn values after enabling the USN plugin and the lastusn value is negat - Ticket 47424 - Replication problem with add-delete requests on single-valued attributes - Ticket 47367 - (phase 2) ldapdelete returns non-leaf entry error while trying to remove a leaf entry - Ticket 47367 - (phase 1) ldapdelete returns non-leaf entry error while trying to remove a leaf entry - Ticket 47421 - memory leaks in set_krb5_creds - Ticket 346 - version 4 Slow ldapmodify operation time for large quantities of multi-valued attribute v - Ticket 47369 version2 - provide default syntax plugin - Ticket 47427 - Overflow in nsslapd-disk-monitoring-threshold - Ticket 47339 - RHDS denies MODRDN access if ACI list contains any DENY rule - Ticket 47427 - Overflow in nsslapd-disk-monitoring-threshold - Ticket 47428 - Memory leak in 389-ds-base 1.2.11.15 - Ticket 47392 - ldbm errors when adding/modifying/deleting entries - Ticket 47385 - Disk Monitoring is not triggered as expected. - Ticket 47410 - changelog db deadlocks with DNA and replication- bump version to 1.3.1.3 - Ticket 47374 - flush.pl is not included in perl5 - Ticket 47391 - deleting and adding userpassword fails to update the password (additional fix) - Ticket 47393 - Attribute are not encrypted on a consumer after a full initialization - Ticket 47395 47397 - v2 correct behaviour of account policy if only stateattr is configured or no alternate attr is configured - Ticket 47396 - crash on modrdn of tombstone - Ticket 47400 - MMR stress test with dna enabled causes a deadlock - Ticket 47409 - allow setting db deadlock rejection policy - Ticket 47419 - Unhashed userpassword can accidentally get removed from mods - Ticket 47420 - An upgrade script 80upgradednformat.pl fails to handle a server instance name incuding '-'- Rebuilt for new net-snmp- bump version to 1.3.1.2 - Ticket 47391 - deleting and adding userpassword fails to update the password - Coverity Fixes (Part 7)- bump version to 1.3.1.1 - Ticket 402 - nhashed#user#password in entry extension - Ticket 511 - Revision - allow turning off vattr lookup in search entry return - Ticket 580 - Wrong error code return when using EXTERNAL SASL and no client certificate - Ticket 47327 - error syncing group if group member user is not synced - Ticket 47355 - dse.ldif doesn't replicate update to nsslapd-sasl-mapping-fallback - Ticket 47359 - new ldap connections can block ldaps and ldapi connections - Ticket 47362 - ipa upgrade selinuxusermap data not replicating - Ticket 47375 - flush_ber error sending back start_tls response will deadlock - Ticket 47376 - DESC should not be empty as per RFC 2252 (ldapv3) - Ticket 47377 - make listen backlog size configurable - Ticket 47378 - fix recent compiler warnings - Ticket 47383 - connections attribute in cn=snmp,cn=monitor is counted twice - Ticket 47385 - DS not shutting down when disk monitoring threshold is reached - Coverity Fixes (part 1) - Coverity Fixes (Part 2) - Coverity Fixes (Part 3) - Coverity Fixes (Part 4) - Coverity Fixes (Part 5)- bump version to 1.3.1.0 - Ticket 332 - Command line perl scripts should attempt most secure connection type first - Ticket 342 - better error message when cache overflows - Ticket 417 - RFE - forcing passwordmustchange attribute by non-cn=directory manager - Ticket 419 - logconv.pl - improve memory management - Ticket 422 - 389-ds-base - Can't call method "getText" - Ticket 433 - multiple bugs in start-dirsrv, stop-dirsrv, restart-dirsrv scripts - Ticket 458 - RFE - Make it possible for privileges to be provided to an admin user to import an LDIF file containing hashed passwords - Ticket 471 - logconv.pl tool removes the access logs contents if "-M" is not correctly used - Ticket 487 - Possible to add invalid attribute values to PAM PTA plugin configuration - Ticket 502 - setup-ds.pl script should wait if "semanage.trans.LOCK" presen - Ticket 505 - use lock-free access name2asi and oid2asi tables (additional) - Ticket 508 - lock-free access to FrontendConfig structure - Ticket 511 - allow turning off vattr lookup in search entry return - Ticket 525 - Introducing a user visible configuration variable for controlling replication retry time - Ticket 528 - RFE - get rid of instance specific scripts - Ticket 529 - dn normalization must handle multiple space characters in attributes - Ticket 532 - RUV is not getting updated for both Master and consumer - Ticket 533 - only scan for attributes to decrypt if there are encrypted attrs configured - Ticket 534 - RFE: Add SASL mappings fallback - Ticket 537 - Improvement of range search - Ticket 539 - logconv.pl should handle microsecond timing - Ticket 543 - Sorting with attributes in ldapsearch gives incorrect result - Ticket 545 - Segfault during initial LDIF import: str2entry_dupcheck() - Ticket 547 - Incorrect assumption in ndn cache - Ticket 550 - posix winsync will not create memberuid values if group entry become posix group in the same sync interval - Ticket 551 - Multivalued rootdn-days-allowed in RootDN Access Control plugin always results in access control violation - Ticket 552 - Adding rootdn-open-time without rootdn-close-time to RootDN Acess Control results in inconsistent configuration - Ticket 558 - Replication - make timeout for protocol shutdown configurable - Ticket 561 - disable writing unhashed#user#password to changelog - Ticket 563 - DSCreate.pm: Error messages cannot be used in the if expression since they could be localized. - Ticket 565 - turbo mode and replication - allow disable of turbo mode - Ticket 571 - server does not accept 0 length LDAP Control sequence - Ticket 574 - problems with dbcachesize disk space calculation - Ticket 583 - dirsrv fails to start on reboot due to /var/run/dirsrv permissions - Ticket 585 - Behaviours of "db2ldif -a " and "db2ldif.pl -a " are inconsistent - Ticket 587 - Replication error messages in the DS error logs - Ticket 588 - Create MAN pages for command line scripts - Ticket 600 - Server should return unavailableCriticalExtension when processing a badly formed critical control - Ticket 603 - A logic error in str2simple - Ticket 604 - Required attribute not checked during search operation - Ticket 608 - Posix Winsync plugin throws "posix_winsync_end_update_cb: failed to add task entry" error message - Ticket 611 - logconv.pl missing stats for StartTLS, LDAPI, and AUTOBIND - Ticket 612 - improve dbgen rdn generation, output - Ticket 613 - ldclt: add timestamp, interval, nozeropad, other improvements - Ticket 616 - High contention on computed attribute lock - Ticket 618 - Crash at shutdown while stopping replica agreements - Ticket 620 - Better logging of error messages for 389-ds-base - Ticket 621 - modify operations without values need to be written to the changelog - Ticket 622 - DS logging errors "libdb: BDB0171 seek: 2147483648: (262144 * 8192) + 0: No such file or directory - Ticket 631 - Replication: "Incremental update started" status message without consumer initialized - Ticket 633 - allow nsslapd-nagle to be disabled, and also tcp cork - Ticket 47299 - allow cmdline scripts to work with non-root user - Ticket 47302 - get rid of sbindir start/stop/restart slapd scripts - Ticket 47303 - start/stop/restart dirsrv scripts should report and error if no instances - Ticket 47304 - reinitialization of a master with a disabled agreement hangs - Ticket 47311 - segfault in db2ldif(trigger by a cleanallruv task) - Ticket 47312 - replace PR_GetFileInfo with PR_GetFileInfo64 - Ticket 47315 - filter option in fixup-memberof requires more clarification - Ticket 47325 - Crash at shutdown on a replica aggrement - Ticket 47330 - changelog db extension / upgrade is obsolete - Ticket 47336 - logconv.pl -m not working for all stats - Ticket 47341 - logconv.pl -m time calculation is wrong - Ticket 47343 - 389-ds-base: Does not support aarch64 in f19 and rawhide - Ticket 47347 - Simple paged results should support async search - Ticket 47348 - add etimes to per second/minute stats - Ticket 47349 - DS instance crashes under a high load- bump version to 1.3.0.5 - Ticket 47308 - unintended information exposure when anonymous access is set to rootdse - Ticket 628 - crash in aci evaluation - Ticket 627 - ns-slapd crashes sporadically with segmentation fault in libslapd.so - Ticket 634 - Deadlock in DNA plug-in Ticket #576 - DNA: use event queue for config update only at the start up - Ticket 632 - 389-ds-base cannot handle Kerberos tickets with PAC - Ticket 623 - cleanAllRUV task fails to cleanup config upon completion- e53d691 bump version to 1.3.0.4 - Bug 912964 - CVE-2013-0312 389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data - Ticket 570 - DS returns error 20 when replacing values of a multi-valued attribute (only when replication is enabled) - Ticket 490 - Slow role performance when using a lot of roles - Ticket 590 - ns-slapd segfaults while trying to delete a tombstone entry- bump version to 1.3.0.3 - Ticket #584 - Existence of an entry is not checked when its password is to be deleted - Ticket 562 - Crash when deleting suffix- Rebuild for icu 50- bump version to 1.3.0.2 - Ticket #542 - Cannot dynamically set nsslapd-maxbersize- bump version to 1.3.0.1 - Ticket 556 - Don't overwrite certmap.conf during upgrade- bump version to 1.3.0.0- bump version to 1.3.0.rc3 - Ticket 549 - DNA plugin no longer reports additional info when range is depleted - Ticket 541 - need to set plugin as off in ldif template - Ticket 541 - RootDN Access Control plugin is missing after upgrade- bump version to 1.3.0.rc2 - Trac Ticket #497 - Escaped character cannot be used in the substring search filter - Ticket 509 - lock-free access to be->be_suffixlock - Trac Ticket #522 - betxn: upgrade is not implemented yet- bump version to 1.3.0.rc1 - Ticket #322 - Create DOAP description for the 389 Directory Server project - Trac Ticket #499 - Handling URP results is not corrrect - Ticket 509 - lock-free access to be->be_suffixlock - Ticket 456 - improve entry cache sizing - Trac Ticket #531 - loading an entry from the database should use str2entry_f - Trac Ticket #536 - Clean up compiler warnings for 1.3 - Trac Ticket #531 - loading an entry from the database should use str2entry_fast - Ticket 509 - lock-free access to be->be_suffixlock - Ticket 527 - ns-slapd segfaults if it cannot rename the logs - Ticket 395 - RFE: 389-ds shouldn't advertise in the rootDSE that we can handle a sasl mech if we really can't - Ticket 216 - disable replication agreements - Ticket 518 - dse.ldif is 0 length after server kill or machine kill - Ticket 393 - Change in winSyncInterval does not take immediate effect - Ticket 20 - Allow automember to work on entries that have already been added - Coverity Fixes - Ticket 349 - nsViewFilter syntax issue in 389DS 1.2.5 - Ticket 337 - improve CLEANRUV functionality - Fix for ticket 504 - Ticket 394 - modify-delete userpassword - minor fixes for bdb 4.2/4.3 and mozldap - Trac Ticket #276 - Multiple threads simultaneously working on connection's private buffer causes ns-slapd to abort - Fix for ticket 465: cn=monitor showing stats for other db instances - Ticket 507 - use mutex for FrontendConfig lock instead of rwlock - Fix for ticket 510 Avoid creating an attribute just to determine the syntax for a type, look up the syntax directly by type - Coverity defect: Resource leak 13110 - Ticket 517 - crash in DNA if no dnaMagicRegen is specified - Trac Ticket #520 - RedHat Directory Server crashes (segfaults) when moving ldap entry - Trac Ticket #519 - Search with a complex filter including range search is slow - Trac Ticket #500 - Newly created users with organizationalPerson objectClass fails to sync from AD to DS with missing attribute error - Trac Ticket #311 - IP lookup failing with multiple DNS entries - Trac Ticket #447 - Possible to add invalid attribute to nsslapd-allowed-to-delete-attrs - Trac Ticket #443 - Deleting attribute present in nsslapd-allowed-to-delete-attrs returns Operations error - Ticket #503 - Improve AD version in winsync log message - Trac Ticket #190 - Un-resolvable server in replication agreement produces unclear error message - Coverity fixes - Trac Ticket #391 - Slapd crashes when deleting backends while operations are still in progress - Trac Ticket #448 - Possible to set invalid macros in Macro ACIs - Trac Ticket #498 - Cannot abaondon simple paged result search - Coverity defects - Trac Ticket #494 - slapd entered to infinite loop during new index addition - Fixing compiler warnings in the posix-winsync plugin - Coverity defects - Ticket 147 - Internal Password Policy usage very inefficient - Ticket 495 - internalModifiersname not updated by DNA plugin - Revert "Ticket 495 - internalModifiersname not updated by DNA plugin" - Ticket 495 - internalModifiersname not updated by DNA plugin - Ticket 468 - if pam_passthru is enabled, need to AC_CHECK_HEADERS([security/pam_appl.h]) - Ticket 486 - nsslapd-enablePlugin should not be multivalued - Ticket 488 - Doc: DS error log messages with typo - Trac Ticket #451 - Allow db2ldif to be quiet - Ticket #491 - multimaster_extop_cleanruv returns wrong error codes - Ticket #481 - expand nested posix groups - Trac Ticket #455 - Insufficient rights to unhashed#user#password when user deletes his password - Ticket #446 - anonymous limits are being applied to directory managerTicket #28 MOD operations with chained delete/add get back error 53 on backend config Ticket #173 ds-logpipe.py script's man page and script help should be updated for -t option. Ticket #196 RFE: Interpret IPV6 addresses for ACIs, replication, and chaining Ticket #218 RFE - Make RIP working with Replicated Entries Ticket #328 make sure all internal search filters are properly escaped Ticket #329 389-admin build fails on F-18 with new apache Ticket #344 deadlock in replica_write_ruv Ticket #351 use betxn plugins by default Ticket #352 make cos, roles, views betxn aware Ticket #356 logconv.pl - RFE - track bind info Ticket #365 Audit log - clear text password in user changes Ticket #370 Opening merge qualifier CoS entry using RHDS console changes the entry. Ticket #372 Setting nsslapd-listenhost or nsslapd-securelistenhost breaks ACI processing Ticket #386 Overconsumption of memory with large cachememsize and heavy use of ldapmodify Ticket #402 unhashedTicket #userTicket #password in entry extension Ticket #408 Create a normalized dn cache Ticket #453 db2index with -tattrname:type,type fails Ticket #461 fix build problem with mozldap c sdk Ticket #462 add test for include file mntent.h Ticket #463 different parameters of getmntent in Solaris- Trac Ticket #470 - 389 prevents from adding a posixaccount with userpassword after schema reload - Ticket 477 - CLEANALLRUV if there are only winsync agmts task will hang - Ticket 457 - dirsrv init script returns 0 even when few or all instances fail to start - Ticket 473 - change VERSION.sh to have console version be major.minor - Ticket 475 - Root DN Access Control - improve value checking for config - Trac Ticket #466 - entry_apply_mod - ADD: Failed to set unhashed#user#password to extension - Ticket 474 - Root DN Access Control - days allowed not working correctly - Ticket 467 - CLEANALLRUV abort task should be able to ignore down replicas - 0b79915 fix compiler warnings in ticket 374 code - Ticket 452 - automember rebuild task adds users to groups that do not match the configuration scope- Ticket 450 - CLEANALLRUV task gets stuck on winsync replication agreement - Ticket 386 - large memory growth with ldapmodify(heap fragmentation) - this patch doesn't fix the bug - it allows us to experiment with - different values of mxfast - Ticket #374 - consumer can go into total update mode for no reason- Ticket #426 - support posix schema for user and group sync - 1) plugin config ldif must contain pluginid, etc. during upgrade or it - will fail due to schema errors - 2) posix winsync should have a lower precedence (25) than the default (50) - so that it will be run first - 3) posix winsync should support the Winsync API v3 - the v2 functions are - just stubs for now - but the precedence cb is active- 8e5087a Coverity defects - 13089: Dereference after null check ldbm_back_delete - Trac Ticket #437 - variable dn should not be used in ldbm_back_delete - ba1f5b2 fix coverity resource leak in windows_plugin_add - e3e81db Simplify program flow: change while loops to for - a0d5dc0 Fix logic errors: del_mod should be latched (might not be last mod), and avoid skipping add-mods (int value 0) - 0808f7e Simplify program flow: make adduids/moduids/deluids action blocks all similar - 77eb760 Simplify program flow: eliminate unnecessary continue - c9e9db7 Memory leaks: unmatched slapi_attr_get_valueset and slapi_value_new - a4ca0cc Change "return"s in modGroupMembership to "break"s to avoid leaking - d49035c Factorize into new isPosixGroup function - 3b61c03 coverity - posix winsync mem leaks, null check, deadcode, null ref, use after free - 33ce2a9 fix mem leaks with parent dn log message, setting winsync windows domain - Ticket #440 - periodic dirsync timed event causes server to loop repeatedly - Ticket #355 - winsync should not delete entry that appears to be out of scope - Ticket 436 - nsds5ReplicaEnabled can be set with any invalid values. - 487932d coverity - mbo dead code - winsync leaks, deadcode, null check, test code - 2734a71 CLEANALLRUV coverity fixes - Ticket #426 - support posix schema for user and group sync - Ticket #430 - server to server ssl client auth broken with latest openldap6c0778f bumped version to 1.2.11.11 Ticket 429 - added nsslapd-readonly to DS schema Ticket 403 - fix CLEANALLRUV regression from last commit Trac Ticket #346 - Slow ldapmodify operation time for large quantities of multi-valued attribute valuesdb6b354 bumped version to 1.2.11.10 Ticket 403 - CLEANALLRUV revisionsea05e69 Bumped version to 1.2.11.9 Ticket 407 - dna memory leak - fix crash from prev fixddcf669 bump version to 1.2.11.8 for offical release Ticket #425 - support multiple winsync plugins Ticket 403 - cleanallruv coverity fixes Ticket 407 - memory leak in dna plugin Ticket 403 - CLEANALLRUV feature Ticket 413 - "Server is unwilling to perform" when running ldapmodify on nsds5ReplicaStripAttrs 3168f04 Coverity defects 5ff0a02 COVERITY FIXES Ticket #388 - Improve replication agreement status messages 0760116 Update the slapi-plugin documentation on new slapi functions, and added a slapi function for checking on shutdowns Ticket #369 - restore of replica ldif file on second master after deleting two records shows only 1 deletion Ticket #409 - Report during startup if nsslapd-cachememsize is too small Ticket #412 - memberof performance enhancement 12813: Uninitialized pointer read string_values2keys Ticket #346 - Slow ldapmodify operation time for large quantities of multi-valued attribute values Ticket #346 - Slow ldapmodify operation time for large quantities of multi-valued attribute values Ticket #410 - Referential integrity plug-in does not work when update interval is not zero Ticket #406 - Impossible to rename entry (modrdn) with Attribute Uniqueness plugin enabled Ticket #405 - referint modrdn not working if case is different Ticket 399 - slapi_ldap_bind() doesn't check bind results- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Perl 5.16 rebuild- Ticket 378 - unhashed#user#password visible after changing password - fix func declaration from previous patch - Ticket 366 - Change DS to purge ticket from krb cache in case of authentication error- Trac Ticket 396 - Account Usability Control Not Working- Ticket #378 - audit log does not log unhashed password: enabled, by default. - Ticket #378 - unhashed#user#password visible after changing password - Ticket #365 - passwords in clear text in the audit log- workaround for https://bugzilla.redhat.com/show_bug.cgi?id=833529- Ticket #387 - managed entry sometimes doesn't delete the managed entry - 5903815 improve txn test index handling - Ticket #360 - ldapmodify returns Operations error - fix delete caching - bcfa9e3 Coverity Fix for CLEANALLRUV - Trac Ticket #335 - transaction retries need to be cache aware - Ticket #389 - ADD operations not in audit log - 44cdc84 fix coverity issues with uninit vals, no return checking - Ticket 368 - Make the cleanAllRUV task one step - Ticket #110 - RFE limiting root DN by host, IP, time of day, day of week- Perl 5.16 rebuild- Ticket #360 - ldapmodify returns Operations error - Ticket #321 - krbExtraData is being null modified and replicated on each ssh login - Trac Ticket #359 - Database RUV could mismatch the one in changelog under the stress - Ticket #361: Bad DNs in ACIs can segfault ns-slapd - Trac Ticket #338 - letters in object's cn get converted to lowercase when renaming object - Ticket #337 - Improve CLEANRUV task- Ticket #358 - managed entry doesn't delete linked entry- Ticket #351 - use betxn plugins by default - revert - make no plugins betxn by default - too great a risk - for deadlocks until we can test this better - Ticket #348 - crash in ldap_initialize with multiple threads - fixes PR_Init problem in ldclt- f227f11 Suppress alert on unavailable port with forced setup - Ticket #353 - coverity 12625-12629 - leaks, dead code, unchecked return - Ticket #351 - use betxn plugins by default - Trac Ticket #345 - db deadlock return should not log error - Ticket #348 - crash in ldap_initialize with multiple threads - Ticket #214 - Adding Replication agreement should complain if required nsds5ReplicaCredentials not supplied - Ticket #207 - [RFE] enable attribute that tracks when a password was last set - Ticket #216 - RFE - Disable replication agreements - Ticket #337 - RFE - Improve CLEANRUV functionality - Ticket #326 - MemberOf plugin should work on all backends - Trac Ticket #19 - Convert entryUSN plugin to transaction aware type - Ticket #347 - IPA dirsvr seg-fault during system longevity test - Trac Ticket #310 - Avoid calling escape_string() for logged DNs - Trac Ticket #338 - letters in object's cn get converted to lowercase when renaming object - Ticket #183 - passwordMaxFailure should lockout password one sooner - Trac Ticket #335 - transaction retries need to be cache aware - Ticket #336 - [abrt] 389-ds-base-1.2.10.4-2.fc16: index_range_read_ext: Process /usr/sbin/ns-slapd was killed by signal 11 (SIGSEGV) - Ticket #325 - logconv.pl : use of getopts to parse command line options - Ticket #336 - [abrt] 389-ds-base-1.2.10.4-2.fc16: index_range_read_ext: Process /usr/sbin/ns-slapd was killed by signal 11 (SIGSEGV) - 554e29d Coverity Fixes - Trac Ticket #46 - (additional 2) setup-ds-admin.pl does not like ipv6 only hostnames - Ticket #183 - passwordMaxFailure should lockout password one sooner - and should be configurable to avoid regressions - Ticket #315 - small fix to libglobs - Ticket #315 - ns-slapd exits/crashes if /var fills up - Ticket #20 - Allow automember to work on entries that have already been added - Trac Ticket #45 - Fine Grained Password policy: if passwordHistory is on, deleting the password fails.- 453eb97 schema def must have DESC '' - close paren must be preceded by space - Trac Ticket #46 - (additional) setup-ds-admin.pl does not like ipv6 only hostnames - Ticket #331 - transaction errors with db 4.3 and db 4.2 - Ticket #261 - Add Solaris i386 - Ticket #316 and Ticket #70 - add post add/mod and AD add callback hooks - Ticket #324 - Sync with group attribute containing () fails - Ticket #319 - ldap-agent crashes on start with signal SIGSEGV - 77cacd9 coverity 12606 Logically dead code - Trac Ticket #303 - make DNA range requests work with transactions - Ticket #320 - allow most plugins to be betxn plugins - Ticket #24 - Add nsTLS1 to the DS schema - Ticket #271 - Slow shutdown when you have 100+ replication agreements - TIcket #285 - compilation fixes for '--format-security' - Ticket 211 - Avoid preop range requests non-DNA operations - Ticket #271 - replication code cleanup - Ticket 317 - RHDS fractional replication with excluded password policy attributes leads to wrong error messages. - Ticket #308 - Automembership plugin fails if data and config area mixed in the plugin configuration - Ticket #292 - logconv.pl reporting unindexed search with different search base than shown in access logs - 6f8680a coverity 12563 Read from pointer after free (fix 2) - e6a9b22 coverity 12563 Read from pointer after free - 245d494 Config changes fail because of unknown attribute "internalModifiersname" - Ticket #191 - Implement SO_KEEPALIVE in network calls - Ticket #289 - allow betxn plugin config changes - 93adf5f destroy the entry cache and dn cache in the dse post op delete callback - e2532d8 init txn thread private data for all database modes - Ticket #291 - cannot use & in a sasl map search filter - 6bf6e79 Schema Reload crash fix - 60b2d12 Fixing compiler warnings - Trac Ticket #260 - 389 DS does not support multiple paging controls on a single connection - Ticket #302 - use thread local storage for internalModifiersName & internalCreatorsName - fdcc256 Minor bug fix introcuded by commit 69c9f3bf7dd9fe2cadd5eae0ab72ce218b78820e - Ticket #306 - void function cannot return value - ticket 181 - Allow PAM passthru plug-in to have multiple config entries - ticket 211 - Use of uninitialized variables in ldbm_back_modify() - Ticket #74 - Add schema for DNA plugin (RFE) - Ticket #301 - implement transaction support using thread local storage - Ticket #211 - dnaNextValue gets incremented even if the user addition fails - 144af59 coverity uninit var and resource leak - Trac Ticket #34 - remove-ds.pl does not remove everything - Trac Ticket #169 - allow 389 to use db5 - bc78101 fix compiler warning in acct policy plugin - Trac Ticket #84 - 389 Directory Server Unnecessary Checkpoints - Trac Ticket #27 - SASL/PLAIN binds do not work - Ticket #129 - Should only update modifyTimestamp/modifiersName on MODIFYops - Ticket #17 - new replication optimizations- Ticket #46 - (revised) setup-ds-admin.pl does not like ipv6 only hostnames - Ticket #66 - 389-ds-base spec file does not have a BuildRequires on gcc-c++- Ticket #46 - setup-ds-admin.pl does not like ipv6 only hostnames- get rid of posttrans - move update code to post- Ticket #305 - Certain CMP operations hang or cause ns-slapd to crash- b05139b memleak in normalize_mods2bvals - c0eea24 memleak in mep_parse_config_entry - 90bc9eb handle null smods - Ticket #305 - Certain CMP operations hang or cause ns-slapd to crash - Ticket #306 - void function cannot return value - ticket 304 - Fix kernel version checking in dsktune- Trac Ticket #298 - crash when replicating orphaned tombstone entry - Ticket #281 - TLS not working with latest openldap - Trac Ticket #290 - server hangs during shutdown if betxn pre/post op fails - Trac Ticket #26 - Please support setting defaultNamingContext in the rootdse- Ticket #124 - add Provides: ldif2ldbm to rpm- Ticket #294 - 389 DS Segfaults during replica install in FreeIPA- Ticket 284 - Remove unnecessary SNMP MIB files - Ticket 51 - memory leaks in 389-ds-base-1.2.8.2-1.el5? - Ticket 175 - logconv.pl improvements- Introducing use_db4 macro to support db5 (libdb).- Rebuild against PCRE 8.30- ad9dd30 coverity 12488 Resource leak In attr_index_config(): Leak of memory or pointers to system resources - Ticket #281 - TLS not working with latest openldap - Ticket #280 - extensible binary filters do not work - Ticket #279 - filter normalization does not use matching rules - Trac Ticket #275 - Invalid read reported by valgrind - Ticket #277 - cannot set repl referrals or state - Ticket #278 - Schema replication update failed: Invalid syntax - Ticket #39 - Account Policy Plugin does not work for simple binds when PAM Pass Through Auth plugin is enabled - Ticket #13 - slapd process exits when put the database on read only mode while updates are coming to the server - Ticket #87 - Manpages fixes - c493fb4 fix a couple of minor coverity issues - Ticket #55 - Limit of 1024 characters for nsMatchingRule - Trac Ticket #274 - Reindexing entryrdn fails if ancestors are also tombstoned - Ticket #6 - protocol error from proxied auth operation - Ticket #38 - nisDomain schema is incorrect - Ticket #273 - ruv tombstone searches don't work after reindex entryrdn - Ticket #29 - Samba3-schema is missing sambaTrustedDomainPassword - Ticket #22 - RFE: Support sendmail LDAP routing schema - Ticket #161 - Review and address latest Coverity issues - Ticket #140 - incorrect memset parameters - Trac Ticket 35 - Log not clear enough on schema errors - Trac Ticket 139 - eliminate the use of char *dn in favor of Slapi_DN *dn - Trac Ticket #52 - FQDN set to nsslapd-listenhost makes the server start fail if IPv4-mapped-IPv6 address is given- Ticket #272 - add tombstonenumsubordinates to schema- fixes for systemd - remove .pid files after shutting down servers - Ticket #263 - add systemd include directive - Ticket #264 - upgrade needs better check for "server is running"- Ticket #262 - pid file not removed with systemd - Ticket #50 - server should not call a plugin after the plugin close function is called - Ticket #18 - Data inconsitency during replication - Ticket #49 - better handling for server shutdown while long running tasks are active - Ticket #15 - Get rid of rwlock.h/rwlock.c and just use slapi_rwlock instead - Ticket #257 - repl-monitor doesn't work if leftmost hostnames are the same - Ticket #12 - 389 DS DNA Plugin / Replication failing on GSSAPI - 6aaeb77 add a hack to disable sasl hostname canonicalization - Ticket 168 - minssf should not apply to rootdse - Ticket #177 - logconv.pl doesn't detect restarts - Ticket #159 - Managed Entry Plugin runs against managed entries upon any update without validating - Ticket 75 - Unconfigure plugin opperations are being called. - Ticket 26 - Please support setting defaultNamingContext in the rootdse. - Ticket #71 - unable to delete managed entry config - Ticket #167 - Mixing transaction and non-transaction plugins can cause deadlock - Ticket #256 - debug build assertion in ACL_EvalDestroy() - Ticket #4 - bak2db gets stuck in infinite loop - Ticket #162 - Infinite loop / spin inside strcmpi_fast, acl_read_access_allowed_on_attr, server DoS - Ticket #3: acl cache overflown problem - Ticket 1 - pre-normalize filter and pre-compile substring regex - and other optimizations - Ticket 2 - If node entries are tombstone'd, subordinate entries fail to get the full DN.- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- Bug 755725 - 389 programs linked against openldap crash during shutdown - Bug 755754 - Unable to start dirsrv service using systemd - Bug 745259 - Incorrect entryUSN index under high load in replicated environment - d439e3a use slapi_hexchar2int and slapi_str_to_u8 everywhere - 5910551 csn_init_as_string should not use sscanf - b53ba00 reduce calls to csn_as_string and slapi_log_error - c897267 fix member variable name error in slapi_uniqueIDFormat - 66808e5 uniqueid formatting - use slapi_u8_to_hex instead of sprintf - 580a875 csn_as_string - use slapi_uN_to_hex instead of sprintf - Bug 751645 - crash when simple paged fails to send entry to client - Bug 752155 - Use restorecon after creating init script lock file- Bug 751495 - 'setup-ds.pl -u' fails with undefined routine 'updateSystemD' - Bug 750625 750624 750622 744946 Coverity issues - Bug 748575 - part 2 - rhds81 modrdn operation and 100% cpu use in replication - Bug 748575 - rhds81 modrn operation and 100% cpu use in replication - Bug 745259 - Incorrect entryUSN index under high load in replicated environment - f639711 Reduce the number of DN normalization - c06a8fa Keep unhashed password psuedo-attribute in the adding entry - Bug 744945 - nsslapd-counters attribute value cannot be set to "off" - 8d3b921 Use new PLUGIN_CONFIG_ENTRY feature to allow switching between txn and regular - d316a67 Change referential integrity to be a betxnpostoperation plugin- Bug 741744 - part3 - MOD operations with chained delete/add get back error 53 - 1d2f5a0 make memberof transaction aware and able to be a betxnpostoperation plug in - b6d3ba7 pass the plugin config entry to the plugin init function - 28f7bfb set the ENTRY_POST_OP for modrdn betxnpostoperation plugins - Bug 743966 - Compiler warnings in account usability plugin- 498c42b fix transaction support in ldbm_delete- Bug 740942 - allow resource limits to be set for paged searches independently of limits for other searches/operations - Bug 741744 - MOD operations with chained delete/add get back error 53 on backend config - Bug 742324 - allow nsslapd-idlistscanlimit to be set dynamically and per-user- Bug 695736 - Providing native systemd file- corrected source- Bug 735114 - renaming a managed entry does not update mepmanagedby- Bug 735121 - simple paged search + ip/dns based ACI hangs server - Bug 722292 - (cov#11030) Leak of mapped_sdn in winsync rename code - Bug 703990 - cross-platform - Support upgrade from Red Hat Directory Server - Introducing an environment variable USE_VALGRIND to clean up the entry cache and dn cache on exit.- Bug 732153 - subtree and user account lockout policies implemented? - Bug 722292 - Entries in DS are not updated properly when using WinSync API- Bug 733103 - large targetattr list with syntax errors cause server to crash or hang - Bug 633803 - passwordisglobalpolicy attribute brakes TLS chaining - Bug 732541 - Ignore error 32 when adding automember config - Bug 728592 - Allow ns-slapd to start with an invalid server cert- Bug 728510 - Run dirsync after sending updates to AD - Bug 729717 - Fatal error messages when syncing deletes from AD - Bug 729369 - upgrade DB to upgrade from entrydn to entryrdn format is not working. - Bug 729378 - delete user subtree container in AD + modify password in DS == DS crash - Bug 723937 - Slapi_Counter API broken on 32-bit F15 - fixed again - separate tests for atomic ops and atomic bool cas- Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error - Fix another coverity NULL deref in previous patch- Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error - Fix coverity NULL deref in previous patch- Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error - previous patch broke build on el5- Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error- Bug 723937 - Slapi_Counter API broken on 32-bit F15 - fixed to use configure test for GCC provided 64-bit atomic functions- Bug 663752 - Cert renewal for attrcrypt and encchangelog - this was "re-fixed" due to a deadlock condition with cl2ldif task cancel - Bug 725953 - Winsync: DS entries fail to sync to AD, if the User's CN entry contains a comma - Bug 725743 - Make memberOf use PRMonitor for it's operation lock - Bug 725542 - Instance upgrade fails when upgrading 389-ds-base package - Bug 723937 - Slapi_Counter API broken on 32-bit F15- Perl mass rebuild- Perl mass rebuild- Bug 720059 - RDN with % can cause crashes or missing entries - Bug 709468 - RSA Authentication Server timeouts when using simple paged results on RHDS 8.2. - Bug 691313 - Need TLS/SSL error messages in repl status and errors log - Bug 712855 - Directory Server 8.2 logs "Netscape Portable Runtime error -5961 (TCP connection reset by peer.)" to error log whereas Directory Server 8.1 did not - Bug 713209 - Update sudo schema - Bug 719069 - clean up compiler warnings in 389-ds-base 1.2.9 - Bug 718303 - Intensive updates on masters could break the consumer's cache - Bug 711679 - unresponsive LDAP service when deleting vlv on replica- 389-ds-base-1.2.9.a2 - look for separate openldap ldif library - Split automember regex rules into separate entries - writing Inf file shows SchemaFile = ARRAY(0xhexnum) - add support for ldif files with changetype: add - Bug 716980 - winsync uses old AD entry if new one not found - Bug 697694 - rhds82 - incr update state stop_fatal_error "requires administrator action", with extop_result: 9 - bump console version to 1.2.6 - Bug 711679 - unresponsive LDAP service when deleting vlv on replica - Bug 703703 - setup-ds-admin.pl asks for legal agreement to a non-existant file - Bug 706209 - LEGAL: RHEL6.1 License issue for 389-ds-base package - Bug 663752 - Cert renewal for attrcrypt and encchangelog - Bug 706179 - DS can not restart after create a new objectClass has entryusn attribute - Bug 711906 - ns-slapd segfaults using suffix referrals - Bug 707384 - only allow FIPS approved cipher suites in FIPS mode - Bug 710377 - Import with chain-on-update crashes ns-slapd - Bug 709826 - Memory leak: when extra referrals configured- Perl mass rebuild- Perl 5.14 mass rebuild- 389-ds-base-1.2.9.a1 - Auto Membership - More Coverity fixes- 389-ds-base-1.2.8.3 - Bug 700145 - userpasswd not replicating - Bug 700557 - Linked attrs callbacks access free'd pointers after close - Bug 694336 - Group sync hangs Windows initial Sync - Bug 700215 - ldclt core dumps - Bug 695779 - windows sync can lose old values when a new value is added - Bug 697027 - 12 - minor memory leaks found by Valgrind + TET- 389-ds-base-1.2.8.2 - Bug 696407 - If an entry with a mixed case RDN is turned to be - a tombstone, it fails to assemble DN from entryrdn- 389-ds-base-1.2.8.1 - Bug 693962 - Full replica push loses some entries with multi-valued RDNs- 389-ds-base-1.2.8.0 - Bug 693473 - rhds82 rfe - windows_tot_run to log Sizelimit exceeded instead of LDAP error - -1 - Bug 692991 - rhds82 - windows_tot_run: failed to obtain data to send to the consumer; LDAP error - -1 - Bug 693466 - Unable to change schema online - Bug 693503 - matching rules do not inherit from superior attribute type - Bug 693455 - nsMatchingRule does not work with multiple values - Bug 693451 - cannot use localized matching rules - Bug 692331 - Segfault on index update during full replication push on 1.2.7.5- 389-ds-base-1.2.8.rc5 - Bug 692469 - Replica install fails after step for "enable GSSAPI for replication"- 389-ds-base-1.2.8.rc4 - Bug 668385 - DS pipe log script is executed as many times as the dirsrv serv ice is restarted - 389-ds-base-1.2.8.rc3 - Bug 690955 - Mrclone fails due to the replica generation id mismatch- 389-ds-base-1.2.8 release candidate 2 - git tag 389-ds-base-1.2.8.rc2 - Bug 689537 - (cov#10610) Fix Coverity NULL pointer dereferences - Bug 689866 - ns-newpwpolicy.pl needs to use the new DN format - Bug 681015 - RFE: allow fine grained password policy duration attributes - in days, hours, minutes, as well - Bug 684996 - Exported tombstone cannot be imported correctly - Bug 683250 - slapd crashing when traffic replayed - Bug 668909 - Can't modify replication agreement in some cases - Bug 504803 - Allow maxlogsize to be set if logmaxdiskspace is -1 - Bug 644784 - Memory leak in "testbind.c" plugin - Bug 680558 - Winsync plugin fails to restrain itself to the configured subtree- rebuild for icu 4.6- 389-ds-base-1.2.8 release candidate 1 - git tag 389-ds-base-1.2.8.rc1 - Bug 518890 - setup-ds-admin.pl - improve hostname validation - Bug 681015 - RFE: allow fine grained password policy duration attributes in - days, hours, minutes, as well - Bug 514190 - setup-ds-admin.pl --debug does not log to file - Bug 680555 - ns-slapd segfaults if I have more than 100 DBs - Bug 681345 - setup-ds.pl should set SuiteSpotGroup automatically - Bug 674852 - crash in ldap-agent when using OpenLDAP - Bug 679978 - modifying attr value crashes the server, which is supposed to - be indexed as substring type, but has octetstring syntax - Bug 676655 - winsync stops working after server restart - Bug 677705 - ds-logpipe.py script is failing to validate "-s" and - "--serverpid" options with "-t". - Bug 625424 - repl-monitor.pl doesn't work in hub node- Bug 676598 - 389-ds-base multilib: file conflicts - split off libs into a separate -libs package- do not create /var/run/dirsrv - setup will create it instead - remove the fedora-ds initscript upgrade stuff - we do not support that anymore - convert the remaining lua stuff to plain old shell script- 1.2.8.a3 release - git tag 389-ds-base-1.2.8.a3 - Bug 675320 - empty modify operation with repl on or lastmod off will crash server - Bug 675265 - preventryusn gets added to entries on a failed delete - Bug 677774 - added support for tmpfiles.d - Bug 666076 - dirsrv crash (1.2.7.5) with multiple simple paged result search es - Bug 672468 - Don't use empty path elements in LD_LIBRARY_PATH - Bug 671199 - Don't allow other to write to rundir - Bug 678646 - Ignore tombstone operations in managed entry plug-in - Bug 676053 - export task followed by import task causes cache assertion - Bug 677440 - clean up compiler warnings in 389-ds-base 1.2.8 - Bug 675113 - ns-slapd core dump in windows_tot_run if oneway sync is used - Bug 676689 - crash while adding a new user to be synced to windows - Bug 604881 - admin server log files have incorrect permissions/ownerships - Bug 668385 - DS pipe log script is executed as many times as the dirsrv serv ice is restarted - Bug 675853 - dirsrv crash segfault in need_new_pw()- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- 1.2.8.a2 release - git tag 389-ds-base-1.2.8.a2 - Bug 674430 - Improve error messages for attribute uniqueness - Bug 616213 - insufficient stack size for HP-UX on PA-RISC - Bug 615052 - intrinsics and 64-bit atomics code fails to compile - on PA-RISC - Bug 151705 - Need to update Console Cipher Preferences with new ciphers - Bug 668862 - init scripts return wrong error code - Bug 670616 - Allow SSF to be set for local (ldapi) connections - Bug 667935 - DS pipe log script's logregex.py plugin is not redirecting the - log output to the text file - Bug 668619 - slapd stops responding - Bug 624547 - attrcrypt should query the given slot/token for - supported ciphers - Bug 646381 - Faulty password for nsmultiplexorcredentials does not give any - error message in logs- 1.2.8-0.1.a1 release - git tag 389-ds-base-1.2.8.a1 - many bug fixes- 1.2.7.5 release - git tag 389-ds-base-1.2.7.5 - Bug 663597 - Memory leaks in normalization code- Resolves: bug 656541 - use %ghost on files in /var/lock- 1.2.7.4 release - git tag 389-ds-base-1.2.7.4 - Bug 661792 - Valid managed entry config rejected- 1.2.7.3 release - git tag 389-ds-base-1.2.7.3 - Bug 658312 - Invalid free in Managed Entry plug-in - Bug 641944 - Don't normalize non-DN RDN values- 1.2.7.2 release - git tag 389-ds-base-1.2.7.2 - Bug 659456 - Incorrect usage of ber_printf() in winsync code - Bug 658309 - Process escaped characters in managed entry mappings - Bug 197886 - Initialize return value for UUID generation code - Bug 658312 - Allow mapped attribute types to be quoted - Bug 197886 - Avoid overflow of UUID generator- last commit had bogus commit log- 1.2.7.1 release - git tag 389-ds-base-1.2.7.1 - Bug 656515 - Allow Name and Optional UID syntax for grouping attributes - Bug 656392 - Remove calls to ber_err_print() - Bug 625950 - hash nsslapd-rootpw changes in audit log- 1.2.7 release - git tag 389-ds-base-1.2.7- Bug 648949 - Merge dirsrv and dirsrv-admin policy modules into base policy- 1.2.7.a5 release - git tag 389-ds-base-1.2.7.a5 - Bug 643979 - Strange byte sequence for attribute with no values (nsslapd-ref erral) - Bug 635009 - Add one-way AD sync capability - Bug 572018 - Upgrading from 1.2.5 to 1.2.6.a2 deletes userRoot - put replication config entries in separate file - Bug 567282 - server can not abandon searchRequest of "simple paged results" - Bug 329751 - "nested" filtered roles searches candidates more than needed - Bug 521088 - DNA should check ACLs before getting a value from the range- 1.2.7.a4 release - git tag 389-ds-base-1.2.7.a4 - Bug 647932 - multiple memberOf configuration adding memberOf where there is no member - Bug 491733 - dbtest crashes - Bug 606545 - core schema should include numSubordinates - Bug 638773 - permissions too loose on pid and lock files - Bug 189985 - Improve attribute uniqueness error message - Bug 619623 - attr-unique-plugin ignores requiredObjectClass on modrdn operat ions - Bug 619633 - Make attribute uniqueness obey requiredObjectClass- 1.2.7.a3 release - a2 was never released - this is a rebuild to pick up - Bug 644608 - RHDS 8.1->8.2 upgrade fails to properly migrate ACIs - Adding the ancestorid fix code to ##upgradednformat.pl.- 1.2.7.a3 release - a2 was never released - Bug 644608 - RHDS 8.1->8.2 upgrade fails to properly migrate ACIs - Bug 629681 - Retro Changelog trimming does not behave as expected - Bug 645061 - Upgrade: 06inetorgperson.ldif and 05rfc4524.ldif - are not upgraded in the server instance schema dir- 1.2.7.a2 release - a1 was the OpenLDAP testday release - git tag 389-ds-base-1.2.7.a2 - added openldap support on platforms that use openldap with moznss - for crypto (F-14 and later) - many bug fixes - Account Policy Plugin (keep track of last login, disable old accounts)- added openldap support- bump rel to rebuild again- bump rel to rebuild- This is the 1.2.6.1 release - git tag 389-ds-base-1.2.6.1 - Bug 634561 - Server crushes when using Windows Sync Agreement - Bug 635987 - Incorrect sub scope search result with ACL containing ldap:///self - Bug 612264 - ACI issue with (targetattr='userPassword') - Bug 606920 - anonymous resource limit- nstimelimit - also applied to "cn=directory manager" - Bug 631862 - crash - delete entries not in cache + referint- This is the final 1.2.6 release- 1.2.6 release candidate 7 - git tag 389-ds-base-1.2.6.rc7 - Bug 621928 - Unable to enable replica (rdn problem?) on 1.2.6 rc6- 1.2.6 release candidate 6 - git tag 389-ds-base-1.2.6.rc6 - Bug 617013 - repl-monitor.pl use cpu upto 90% - Bug 616618 - 389 v1.2.5 accepts 2 identical entries with different DN formats - Bug 547503 - replication broken again, with 389 MMR replication and TCP errors - Bug 613833 - Allow dirsrv_t to bind to rpc ports - Bug 612242 - membership change on DS does not show on AD - Bug 617629 - Missing aliases in new schema files - Bug 619595 - Upgrading sub suffix under non-normalized suffix disappears - Bug 616608 - SIGBUS in RDN index reads on platforms with strict alignments - Bug 617862 - Replication: Unable to delete tombstone errors - Bug 594745 - Get rid of dirsrv_lib_t label- make selinux-devel explicit Require the base package in order - to comply with Fedora Licensing Guidelines- 1.2.6 release candidate 3 - git tag 389-ds-base-1.2.6.rc3 - Bug 603942 - null deref in _ger_parse_control() for subjectdn - 609256 - Selinux: pwdhash fails if called via Admin Server CGI - 578296 - Attribute type entrydn needs to be added when subtree rename switch is on - 605827 - In-place upgrade: upgrade dn format should not run in setup-ds-admin.pl - Bug 604453 - SASL Stress and Server crash: Program quits with the assertion failure in PR_Poll - Bug 604453 - SASL Stress and Server crash: Program quits with the assertion failure in PR_Poll - 606920 - anonymous resource limit - nstimelimit - also applied to "cn=directory manager"- 1.2.6 release candidate 2- install replication session plugin header with devel package- 1.2.6 release candidate 1- Mass rebuild with perl-5.12.0- 1.2.6.a4 release- 1.2.6.a3 release - add managed entries plug-in - many bug fixes - moved selinux subpackage into base package- rebuild for icu 4.4- 1.2.6.a2 release - add support for matching rules - many bug fixes- 1.2.6.a1 release - Added SELinux policy and subpackages- 1.2.5 final release- 1.2.5.rc4 release- 1.2.5.rc3 release- 1.2.5.rc2 release- 1.2.5.rc1 release- 1.2.5.a1 release- 1.2.4 release - resolves bug 221905 - added support for Salted MD5 (SMD5) passwords - primarily for migration - resolves bug 529258 - Make upgrade remove obsolete schema from 99user.ldif- 1.2.3 release - added template-initconfig to %files - %posttrans now runs update to update the server instances - servers are shutdown, then restarted if running before install - scriptlets mostly use lua now to pass data among scriptlet phases- rebuild with new openssl to fix dependencies- backed out - added template-initconfig to %files - this change is for the next major release - bump version to 1.2.2 - fix reopened 509472 db2index all does not reindex all the db backends correctly - fix 518520 - pre hashed salted passwords do not work - see https://bugzilla.redhat.com/show_bug.cgi?id=518519 for the list of - bugs fixed in 1.2.2- rebuilt with new openssl- added template-initconfig to %files- added BuildRequires pcre- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- change name to 389 - change version to 1.2.1 - added initial support for numeric string syntax - added initial support for syntax validation - added initial support for paged results including sorting- final release 1.2.0 - Resolves: bug 475338 - LOG: the intenal type of maxlogsize, maxdiskspace and minfreespace should be 64-bit integer - Resolves: bug 496836 - SNMP ldap-agent on Solaris: Unable to open semaphore for server: 389 - CVS tag: FedoraDirSvr_1_2_0 FedoraDirSvr_1_2_0_20090428- re-enable ppc builds- exclude ppc builds - needs extensive porting work- new release 1.2.0 - Made devel package depend on mozldap-devel - only create run dir if it does not exist - CVS tag: FedoraDirSvr_1_2_0_RC1 FedoraDirSvr_1_2_0_RC1_20090330- added db4-utils to Requires for verify-db.pl- Enabled LDAPI autobind- updated update to patch bug463991-bdb47.patch- updated patch bug463991-bdb47.patch- added patch bug463991-bdb47.patch - make ds work with bdb 4.7- rolled back bogus winsync memory leak fix- winsync api improvements for modify operations- This is the 1.1.2 release. The bugs fixed can be found here - https://bugzilla.redhat.com/showdependencytree.cgi?id=452721 - Added winsync-plugin.h to the devel subpackage- bump rev to rebuild and pick up new version of ICU- 1.1.1 release candidate - several bug fixes- fix bugzilla 439829 - patch to allow working with NSS 3.11.99 and later- add patch to allow server to work with NSS 3.11.99 and later - do NSS_Init after fork but before detaching from console- add Requires for versioned perl (libperl.so)- previous fix for 434403 used the wrong patch - this is the right one- Resolves bug 434403 - GCC 4.3 build fails - Rolled new source tarball which includes Nathan's fix for the struct ucred - NOTE: Change version back to 1.1.1 for next release - this release was pulled from CVS tag FedoraDirSvr110_gcc43- Autorebuild for GCC 4.3- This is the GA release of Fedora DS 1.1 - Removed version numbers for BuildRequires and Requires - Added full URL to source tarball- Rebuild for deps- This is the beta2 release - new file added to package - /etc/sysconfig/dirsrv - for setting - daemon environment as is usual in other linux daemons- fix build breakage due to open() - mock could not find BuildRequires: db4-devel >= 4.2.52 - mock works if >= version is removed - it correctly finds db4.6- Change pathnames to use the pkgname macro which is dirsrv - get rid of cvsdate in source name- Added Requires for perldap, cyrus sasl plugins - Removed template-migrate* files - Added perl module directory - Removed install.inf - setup-ds.pl can now easily generate one- added requires for mozldap-tools- update to latest sources - added migrateTo11 to allow migrating instances from 1.0.x to 1.1 - ldapi support - fixed pam passthru plugin ENTRY method- Renamed package to fedora-ds-base, but keep names of paths/files/services the same - use the shortname macro (fedora-ds) for names of paths, files, and services instead - of name, so that way we can continue to use e.g. /etc/fedora-ds instead of /etc/fedora-ds-base - updated to latest sources- More cleanup suggested by Dennis Gilmore - This is the fedora extras candidate based on cvs tag FedoraDirSvr110a1- latest sources - added init scripts - use /etc as instconfigdir- latest sources - moved all executables to _bindir- latest sources - added /var/tmp/fedora-ds to dirs- added logconv.pl - added slapi-plugin.h to devel package - added explicit dirs for /var/log/fedora-ds et. al.- just move all .so files into the base package from the devel package- Move the plugin *.so files into the main package instead of the devel - package because they are loaded directly by name via dlopen- Move the script-templates directory to datadir/fedora-ds- change mozldap to mozldap6- remove . from cvsdate define- Having a problem building in Brew - may be Release format- Changed version to 1.1.0 and added Release 1.el4.cvs20070119 - merged in changes from Fedora Extras candidate spec file- Bump component versions (nspr, nss, svrcore, mozldap) to their latest - remove unneeded patches- update to a cvs snapshot - fedorafy the spec - create -devel subpackage - apply a patch to use mozldap not mozldap6 - apply a patch to allow --prefix to work correctly- Fixed the problem where the server would crash upon shutdown in dblayer - due to a race condition among the database housekeeping threads - Fix a problem with normalized absolute paths for db directories- Touch all of the ldap/admin/src/scripts/*.in files so that they - will be newer than their corresponding script template files, so - that make will rebuild them.- Chown new schema files when copying during instance creation- Configure will get ldapsdk_bindir from pkg-config, or $libdir/mozldap6- use eval to sed ./configure into ../configure- jump through hoops to be able to run ../configure- Need to make built dir in setup section- The template scripts needed to use @libdir@ instead of hardcoding - /usr/lib - Use make DESTDIR=$RPM_BUILD_ROOT install instead of % makeinstall - do the actual build in a "built" subdirectory, until we remove - the old script templates- Make replication plugin link with libdb- Have make define LIBDIR, BINDIR, etc. for C code to use - especially for create_instance.h- Forgot to checkin new config.h.in for AC_CONFIG_HEADERS- Add perldap as a Requires; update sources- Fix ds_newinst.pl - Remove obsolete #defines- Update sources; rebuild to populate brew yum repo with dirsec-nss- Update sources- initial revision 1.3.8.4-23.el7_61.3.8.4-23.el7_6dirsrvlibldaputil.so.0libldaputil.so.0.0.0libns-dshttpd-1.3.8.4.solibnunc-stans.so.0libnunc-stans.so.0.1.0libsds.so.0libsds.so.0.0.0libslapd.so.0libslapd.so.0.1.0389-ds-base-libs-1.3.8.4LICENSELICENSE.GPLv3+LICENSE.opensslREADME.devel/usr/lib64//usr/lib64/dirsrv//usr/share/doc//usr/share/doc/389-ds-base-libs-1.3.8.4/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3c29497553f148fe628d1fbd3012e4e66b846b55, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8f48c8d1c8a6a4b3169d246ae4fbcfadb8b13b01, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ddc29c5a90ba9b916d5afa6d7123d1a0b78c6692, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e9a8beb3769d6dc0fcc8783f697980e8440dd3ea, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0be40687f106c623afcd909ce633b4ea920a1853, strippedASCII text +8D ! *PRRRRRR.R RR2PRR!RRRRRR$R,RR R RR R-R#RR.RRR"R%RRRRR R+RRR R2PRRRR R#R.RRRR RR2PRRRRR.RRRR RR2PR)R*R'R(R&R!RRRRRRRRRRRRRRRRRR"R,R%RRR R RR R-R#R.RRRR RR2?7zXZ !#,k]"k%=c7B♶6? z,3CWuaFڶ H05J!zN iƞlp w rH;Fӂu1[2jvqH*/Ew(8Dnu (.M1XBPB?vWM;U0Uc ԿON\95\!!!{SlmVhJPG:H@'LOOՊE=<сp-uoJHZ"jC;r&ݖ7/pZ$o~bCLɀU,Y˸\auWO_an0UTr*/͇Jx;R{oF5F~e+B')!R~: bRl߾?u|pXLPEŧ2t1C\ :vp๎lt !nG2Js~@vu \]Fѳ:ab>S%>o-v>)Ig|Ny_ρf5`Ϥn]UDqG- Ls榟F|Vpr|7 4_xJT |U9ѫvŹf]΅U5[Hhgөf?Or D{..U*o=*ܑ3$.c *qaW OK"8}TD^2=p5Ydj bbQz oiBɒJE4щV<[5 `'͙d|rToi%@.=kKIbb~!JW'9QoHWi4ZLxvB\Agj4;i]`Ovc;U6!J~QBzZP@ 8I,a.j '~-x÷ |vc2Fn˛uC^a8VN!Q^,6_+o?ӮT^Nd+Hٲu#pdԝj03;MM,)(G/̊Y+A$s" !ߣ}[b+>!ȪǽF=GBzkKfVp%1ܶ B9fչ֧niv((h7ҳg˴h]2JT tfoC$\ VPGYDY'(}f?w:J 1u>X ܬû^4:~vF*2dc ݾ*ćJӦkJzinl,@T֏,:]ONn A{+ZnW@VEg(ц\r\c~[ED TjvPЙeEovc^D*e T>3dOb!$z!w`,.;Ь VVD?_~[-PW_}J :<)mH;4 ɃA{NEQO-5qZ1[+Cb#IӴig= T&ӒJ|U=݂.3r5W,RfVl732TiE8;5lVXNeS1̃b%W/,wNl$S'&B[^.J2aOzz5`c 3vވ+@ryD8̀&îDS-m.\qN}{6 jXsCtQ@"~YR'KNANp- Ϝc,^+sSݼ k x70<6} `R͐-sY1l#V ˑVLi-v!_ނiʺi;WN#t8;uX3C_^e<-TaM)@75.Z?h"@]My%- iE|KEA}-`E'CK=?C"elUDv79T`pds6~~k 3{Bӎl%ܠq붧+fiX6;Uu5X[K`AsA ԣ.mAN- VK$/Nw^MmR 3,Yy| xY]Ѵ G_VAѰy`{g+A*/rl8tTo{F_BnϴKgkbS^J *OƜ'l5fpԤEtzr ГB [YEl/E`@ٮz"aA9**wu;_B@IBF/#A֊<HcusavC%ć)X2`UD XU4 F;u78j3*]2]NO&|t!/s'vM8i$BΥl}#;`LZ/݄KYf;bOM$μ{k78RpMW^mv + Rl6d)ydͩP:"]6_SJ!n5?'A) ?jsLCI}(*챷'@2Ƭ`F mX +t̽$d շT+2D+$CL XqBp_1B(;n}m;A47`GDf!i+7,ʓ DUhdZv8Gu.YՇӑ. ! D$f*KMi"6Ӗ" %?O@a[4ץZʼ,X|`0/Q|R;K!_{)@\o4ha1.4g5a<azD@3`Ud7Tl7wwks[VrHx"XEkCUzroӯU` 8oKoPkv!8L>.2M-+iAg"׫1,ۻk8hn]ɔMlj|lu;WdM>+P4G[:A_SYt3{&o&#ZuT8ͱss$)6惮;EHeMM?= 9H3Qz69L'QArTDA @T}Ce;K^c͇(-b]Q\|NaAM-Bߙڸ“\2ǃa8'Y9yokZG? :~P4:MQV) "C*6с~E4 €CHeqV͍iu@vލ-0 >$9w;Ê_UiLBpiWx"mlApա;J=p;y+* Wdfeq` !%L E݈flR!PcVnS>Udrp8;f*{۞B(oXq,i^nj6ivk 415 V7i`uQ5B9A 4<ы3-$aH),m8rjii,\A1x2dbdHA!O(vt\K/2<Hx%~ jF! pi<@՗|ikҲVKzx}}B_89BRG a,Y\)J 7w`Q4gSArP+*}d 65;r~cHR>`;oi3YI_] ipf,+kznej81 K> haj+ߙ5MÔWC?ŊOX l)O4NMz~aÕJn wYj@#u*j%)m|#DqIs:)4xJ£GMZ-;^;DVp7+7=nSn- 鸔y&'>5Ne,_Ue_|F}sl6ƵMq4In;'%#~61]l;s} ]]` vʕ {*|DB$#Ս3CcwK$P]f.s39~5N?!0ou.uVrQ6YѧזK}0'uLn!<^ghH%ѰҜЍxbX[iMMr]}kX,gx=HqNWw.k%T5k$3Ό?)5bYKSS!1 u̾~G<uFXxB@HH7Kpah3oxC$_n*D7Y,6h2-nOHl?͹#Fk*,kr "'C(H7E:13:$?gۣ9K oU{jw ɾBW³;t#A pU!!!F"O|:l6:},U TV#q_Bԉ+KXr؆ UM6u1X;.z& mޱ5F&*ߴ6iaG&qd,Hl4_Qo$xF[ *wHua 1pW *3+TmTW "b`q" @9N3LrT@"uDL@u0[pI)N'L4PvI MUs3駉bn7/dUc;d) vC{|F갣9` 4+֚Jx"|N:sv;v $)-hIr6^z#w\  Ң(ˏ/"ٻ5U Qڗ6io|V^S$븗.DĘ\AFC({҆sݮIs)oda3ƽNH[){J/]Ҭ'^}%(9cIu> vQ]Y]xkT"CvGJ͟@5 g VwgcҚycXn+KU 7<<|_6'pfVX! ;8L37X!lAZ W0%Kh<;Kqt}B'a{C鲃+(º!u2G+F`P[D;C=JbW2i˒TӦznFyyRkMZWlLVdt<\$x z d4O4j`X9訨 n%UY-nK~Ph[E7X"P5/X1'>VTM6 3}y[#$.N;R@vLjd'W>-]-Ī1 *Ri+ TQ}ܵy> /ᮾ2@P-?_`4-+, co0H:j)0a(_ xNqRudƌ-,a!m*xyAZ ȩ>=`:ysthG01g ؂cl$ނ3( <̶VӣԒ1(]K``\rkX1&&:-B38EݛQ~1:?e£XCdoOVW'][pu] `̨P'"gJ)䟧tN#xvcYK&)W@ 7̈́ApN%ʕ8ZsB2@:ӅJC$l] ŵD ]59sӖ,H}ڨaJߞtN޷k9` ]` 8צ|UV)TB tR tTNbM)8d#Og_ADJf箼S~SuW^/mv?D3>[#h2%p;=kӜVR0^Jjh@XM\?L>+U܂{}bG6dA`O,BsFaGw4C:6)|Oi>y1V~9: ->`[I.Jfh.Yzݵ/i|*"\~&&FF&ZUϪ 6~7kږѬPRKN,)=8Mn>EihsΙZbP)g|'/{mu`41F ݧ?(g-CFY/QPvn“]V*ɢ{:x&Øq5ZGݼ}WCkFH&${XCDj ;g}x3 }?_p%* N@= iZϥcُx Djvm+IAgkz*O2IsGsM4uYh"N;aM_Չ+ K}[7\,ԋ*>Qv_k!Juq`%G`nA"XzX\ m"didװYghc &^ժ)d 7WMIUK&ȑU1tOWd`szѿNџM܎QZ͟ ^5q&6Q4Y$gF<7/cL_N^- .9ge t5_ s%1d1xe(L[gd̊ tn,p `_Z"9{akdIpբv͑)8YpU8ªP`Vt%qf]*"y`=ւVDjqhs+Vʃ?:z` *y0 [w1Oc Jz+btOG"bS6iX\y;,H?u3[R;El L(vgATt8& .ia/=JQ2>UǍ{69pn8&.'xy{;on_)uR v TB8s5`IډQt,_Fw 0[DI1CAK,$G pwDy8'Q5ҎOIsX`ČvKZ[p|=NIJq31X c6.|A} ]:+< |cp0"ɮ K/q?.)S%w?7b=/[gVi~ ,tsvzleKk"|ADYvAz|b䐰iGgyÙh@f𛅝ube^0Q5oƘn_ꤧe,}1 vކw1Mp }X[k +LFE[eyUOHolW kp( n"@dXihU 0*qSy( ɲ&s4X!,\n$ELym@k׼=P1UO]4Jd^-*d3 J,Sc7) +&{˽[aKĐ-MBz%Ozs3"ukʬ Jt7߸㕀0L4d9zYF_65li+fw ؤ8lG\34^֞D-LhaV:bsJ= Q>b<+ q;-a-50sD+ݙ[pg\s P7HxՑ _b~>I4<~9R7g4}U3T%c3e6T51NjNiK'2Q3h'J?@-B+ v3)^Za,8L|_/$ 1qᢣrxG^uqw|K#UKZEԫ.SݶA! ꫵ\ꖞMlwn'F=w]P(ˤi8$A3b{.z#ͦ Ÿ)cAK]KL#e7b*E,y3wd~_ *ƕf5;抧~#-W,9w4ˇh'S貀̗xGbũV$RQ=llkP>Ƨf/ٔyhR`x%!j1}yI&߁(zSf/dv Im.@[\0hXHektuݧBcO4Huԕ PSg*wA`#5x^o3w<;Y!R;K^|"ڒ>8 yNG0\Uw d P`ѕ+HiϞ0 4Q&Kj3^3KEԧ\*izKX-GON1FiאfS}!7vh eM|{˪p0/GFT/ 禈6>bv![S:]M&W8ǦF*DK5_n_8UTҐ("v qnPDZXׂ@P[T}(hc~ZF'%p5'@.\ʣyDd m Dv4UeLWbxt k;0:Jj% ?x%E~I̕!>E|O1o8+JccPd׼Jh)FC|֐+*p*!ea[ph"g0LJH/lkP@w,M^ȋTu8I BOo"K%Z*,P W{)hp'=YJ>=81p xxjDajŊ{Dkl\Zӓ_<dnz@2UuMRxotcʄ4Czn5:KE5Kf}OnM7A^HbmS aJ‘8Ә /\aE0̮U(\yIH2l1ɵ+#ˢD{&#xt`j)?ejH ݓS,}ҕI#GOHC%9l;o1/=S= J^OC5bEP]R;1',7 ։S\mZ3'V{`QFM?!V8&%KLlDŽ}OzW^4j ΥH#*Fop]ӭ8*B;8Cաs#-,/Zd@nNqfiHۻkXtU<;= /"@5;c]#!)1G@\~ GUʝmc;*/\ڲ5zzEk.h[5vTM&IHB'.;.AZ)Ne)W^/,E7Qќ/KlW4-zs1{&3- a2]+8ZZM j[;(l&tMյxJeQti:wgG5b7n"#(4^rn!bp' kpیy%g-a)[iWyvF#dKQ_eLkKܪX n4l;y )t38 TP˗Iݴ0(ø>7 6ڊ^– ~hD+#xo[CkJw+&@DSjoQ-x H^:x%Lum}OEo,fiNQJr<T;Ewv ѸiOh ÅC4=6@Xcc#3ls¡^j@2ޝ%foYՏ̲`S0x+' P_Ȍh؀Ȕ{c9 d!AM>_'He+?yM:bC(Wގ;Ko5Qfx54S Fax֕5ٻm4zӇonj$}mF+]fn~7r*2PB}EAdX`w/};;+uCZzUD1jE-D& բݴEZ4Q^G L羰ucnr9KȖbŶ!#|YN&J{q/zc?"̭:XN)boȋQxmPC,{05qz^S^9 ?H}d %ە !ZHϐ= ? XIrz1s:Mj1$tL)1Cz{B#F!Ygy!!(1e?<GEUorz7elImeL "vX bGYsR>Y]Ldg֭l攽9u:@.VWv `K1 FXY9i=r'}@5GW-~kN*!Mr֝qݶW~K\#Ե4Fcsn1W!+[6kWPD5]Ab$]'(=+urzMթhż&:ސ:b@t f%RZTGSznX(;S ۑ1/a$f?82o! c2Ef WboEFXyű/GczVj0xҷSDĺmcj~ PqLKuV!H!_rʁ>;Oi>:[)4irFǖ#J"wjg5ṇ=EՑzH} 1M8ꄮVFqc;7 ,pF p$a(OGsMdfᒜa?%;_'Fᐢ;<"3+]ެ>M}@$bK ["bPo'n]E=xmWrhf >):ca dQ{]Y [4R~Zħ,1{]04ѹfQx{xo0EO= u(NBCYۯ<&lh! &*d@~qRe쮠X5㸨WNQQt0!B_* `AV _GmbTTD S68; _Rnt2נOWPj 'C$>"Y}NANfd ʷNڙΠ_G&C d%D ?,7U+xBq߳A–no4.?`ravFμ8xD' Zuu$o÷娝a~>be%%;r8`G8Ji s0˗TUePZ 1Z٫*_FU}W&4I~R%ݿD[U`s^5TIRPG`'4Ȫ/Fr}xoVxnQV?84ldPD>y~vW d\zj(DV~D!ܟoҗ csFyUsT6ۊRE|td;e_q37CsYޱV]pyj , Po~&DjHC効o`kJ())n@睁yf*}nKWObSY-2~ {p scSo}@?C0A`AS"~I=OvHƵ}g k LH k5‰͓l]b׉Lۘ<Sc!0/$iR=_b'Q0\X#3X&cXb~]c,Ũ~r$KfhMNEҰk2!&Aw/y&w*ޤ$)]Ә|2E](cGҟ5@v)@*c9i%G614ȠDwwcT[_哆 ֞OWݚjDp 1U4S=VL{6qϴ\3Lh[#3ٮDgH% x:F!by<;{ Tgp c%0/M"nhG]!?ɷ<` FWآ DvFfMۈ8!̭I}[ (}n^J{HCǛ-D*o?͑JbVp\ l.9v1 7hJ t7ZXf%=9ul0=Ga/@26zpu\6Y̛vI5αd~:ӣhm?v3<5#D=n(CQ7͏ˉhCr'ppv} ܺװIc0]ƜV`ԩuNWdJ45r=.LxZji8H#i"XoRcEk[Ȣfn ^#%$}ޖqcUu$ͪ6l50L1Eݩ@MǨ/+vejaĖdn'<ܵ3݉H";)N1rsD8M0USl.Y&%գrN#O:chvC}#}zspV~{0wrt;ffq`G5ߕ?m/5T@%\N=pkډ3=.m XSA5`I?cO[[#lВ"z:mɂ)7V} ZHEo?\Tuv dJ:5Ҫ\ o!>LD&ȋ`j0`k$*Et^yy42> H$xZ ]r`vofAl3/kѾ1ļ 6-KH-lO@dNy; PjpPRd[/%u-,8%9x[U_32@7C|&X0Y|e S)Et% (|ּp[մ2F>(  BNnڒ7L$.';Bb ?Sb_Y.(ɂ8+zVʿ |2 :K]_.=Mua/+Ѥx 3G*|h{Ϫ{< uU,LJIP@nNl:aJɡ O[T<j0͉aD3ofR҃e35tLׄzpT~Eɉe|6LI:+.T»pvA޺2>6=DKMV5teb`zs=e'1ϊ;)^8OZ>ರN BEp= .,?L^:zcَT ry=F`#@ÜD'TqAKo1_pD7@O6^29P$B★Cp4's{'-1Mʵ;,bZuhAb[Z Hj.'|t6-3g"T0ƧwU1,*enm+^*@Np#3t (JsuTג?vNcn Z Pk9*kl D,u I98IQyM4`YAs90*j$N=آn.4xyG9;3iHx3dݽbwnc:dev7LzY+ Sp} e_J7Q@AޗmvHC% V-Ia+m˄&arnט 5ӝhh6N2B k'o;7:Dk=%EXP4VWX9}oz~HWtdrgyˢN߽{܍ oxoE]t)P9l'6˒>u$7b\x\~V[ .g|1rA0Q7Գ '!"Iuݗrw=PH3[m5_LMŏRJrXGSL]zx N }V8]$E?R!8NкkRYiC%AKX3;k[n4HK&S;˭6pTG !{PDP FP"#PۢRs֣= |]ʎkI@ǁgI•Q}=2Ǿ&)M KE2p}:[ZB+.#6$>*ƈ*9Bf1y?Ǖ!R>| H,C'ۂ %_Ytӧcyرr 7`}L7;$אzQ_܍F'~{m(15xy.? qt}m f4>A-J @aߞ+pL ѩ\2_67G: 8ʃBU3n :mxJC]wYKkfby0%d F VZC?v(P4̝wvZ|PZ6}H_ME}22vWsS6Xo!Zՙ8H9U^2mfC7`hXO2C#z>%U۫ w(&1`|dynjwt6FO!fb".&#cN2j•ìFqr6{ kCRi1[$:T@g_4bsI(;lY|'&ݳǞUjGhn_]O/q2  .|Cn ~5iY.NڟlhC=]ŌmI!*QYr$*Νik'=oH;"DfH/>5a1),M|nF;ID5|eCMsT=Z1/HրVh>5;ȠƎ#ݸM|[0VI ?M׍MI;-f;ȏZFY1$Ez1D>f!_&r}sI2ZUdA 8^PI&vz;MAP24=G6U3ƕ &:lb=V g]&'@=[͎iJ-bſ:Y6 i}Jݿù@fEe(l?TD5?UK|VnJ &|'+|t{lr-UAe\M7 9b ANϺ(5вvD]煇"E,pqG`iN&'m2?g*$!۶Fމ:N$hq` g&~&N[Jf/&RDY?w}YjM*驺 >Wƪ-voۭ(rH[NN#@XaqKdeSR`L^t OUnvew{a}\&TWvQ Zf0LtRBMGoJԕ=pQhA灹]cӲs/SұoC* $Ӟ^6ss$3`G X%&].8N_͒/g̀t{㟘DUR7|E#.UJ廎ڣ T4gļ^Φ1`gdr;)v[?nم!AFr|HZ[ } ղ}rJPFPmNHk>l$biC0D;H*.o0鈉}r*=Q&y%ܟ-]^ěSCx2:Lpe$iutyyZ洰{c|eV5”y_7dݿfJ|g00|yI&3A5Hy/zBJajkl2]ë i*M1]&R/ڤsLiޚBBY-%_Z6o),m]/gFP7Ѵ#`ޝ'_seYR+vT8ĔvEۜoM՜h2!n){ѵFȳ^iEpaM{+ϛ=A{-MN8|π)j:b OiԳ07A/-nUP(P_3 'YlFrZV_*bۓ;6 =6TA裵*l2MgO {f7B^F &rK@_W3MNPI )hf.Mn#&gPRB: ߙqnR4*YD'vwusjѺiLOоW}ly?vNxwc唿L%'6ՠt݅Kgt31L5&) gweyr-/M?y2?k0@ql -^FHGX^=`p6!B$cnHd] p7[“5t Kqȭ%,1p{bfdNQP8OſT/6x\zP ]q.+֎K}ĕe1,څaf.) z[ηk E֖*M mɚ5t6@52ME7M{B@+:,Y{Ƴ4]rp.-c̩͞uD~Ê !P +XOyCF"8!ܾ,ڂYO4 ?HAqÆQ rp&SQֳF8Px'Jz,ڲ 0g{)R@/6_v9dAϿHEU{:@!u@+~bqб~WGo!*]A#k[@w2XKs?X?6Z&P @DrPTpU!uA4vX'g% F[@Pf&s!׻JrA =L1e{ג p8^] M*)" &4dbfmH0.9!'>JLJ'NHxW(p 2rJ 8oYa) y@b iC[F{$nꔄov -ʮ3-hr6WB_gQ;R+fvGC!CS56$^w[ vK"Ķ ŧ|E65,vy$uza,oa^;)y?~j^R MF&<6_)_`gj{ gvͧ\p#{9RYδH:CpSW"d15 Y=K< 4uҔ̙S+ +3QC@rAQ񗌝zJ7J3,\x6 U/mo/,I~3D&~ſ 3)6"ʓS )IJYqm0On8$^_B7{rHzQ$ZT]'0/w>_n/,OFEn,țu5?>Bc?Aj  Gl 5a tAl~J 5LC&&EX4WTWվ=^ױdEV261N@[!1f5b^fm`/tPt%+BG,*ѩ4+$1uK&JBxcZ FH:}~58Dzrؕ:QnO_pFDA{ǻ4e,R݁տ>z+ס\SxIu) ۩(#Ɨ_"Smt |윞XuyvRp3`VJ!(WGL.8+;ER#6˄&c<9 @)v,>o0CjVl@p1ӐsG|LX#-(.;FH7 'Nov|~h! nYuL9P'C"G3qQ-OYj}bv~6`b_`x  UѩlJ=3 ig!m8G JFf!k{oPJu~'-)Y*wi lWӟ !XyΪ}iCexy hl3+m Zi2 3# KtẻX%1:: d_YڎrM}䛥hI]̊alxzLy}֘/鐧pUfQE(px+:ܡ_. d{h܏ghz¥*8,y e,H҈>j C&晼3WI\;79#hE"nޥu,Mm Y*W_[h|)˞ "uqd&>[/ 1v\s1.rWA9[$n@af{7*u$e̽Q,ޡQ I;CA\ejbC 8v-R9f (эe˪{8*q:PGzH촚wc/Vr4/ '6q" + Ď|5@B[$ԆV*)IW|5NUATZoSO5A&hD:EE% hIr~D&#q_-Je `ɡQCPкto4:bOzμ#4%EFa!"ǏtE3!Aui{wciE+(8jϢ+ \F!w0JB!̈gF?k :,PȈNx$G'5|C" N% Kysd[qbfJ۸PwPSRy#;&x-6½+r_S涎k!V*R! 6*J6#0 URK>/^}u:Vix6"6]\W9Ca&!5C0.W(zta[*<~ysu&AI49fg,E|Vϋ꒕ 横PnuI]JPҕc8Iдcmbֱwҫ_PM~%~MŕNd U'%ߤC\Y#cߧq|*ȉW֌x5|6KDщSlc~?@<\pF쵇CfdRo rhop@1ESd2)fBd"T;plt<< dEd@#ҵn/WQA ^-NS{G#`~J_miVѸvmqy0;._Flt>Bȵpd{3  ύiY,-f{>>+>CO6?>>1C5Q,z$4l5wKA&nh094^.ŝо,o 뙜K#*]U©bG{Վ”4^ N?cw8.zkW j}wF?L}^adⶈ`|`_P +Cy^JGwQu1aZ ktWc?;(E>Zr]Eciuiwjp -ڿq%cnVN Gģ|_ jL/g{+Re b@o%uJ9A [F& _oO'Pe5bRce 6diH|r$!@mpN#xAG*9 pڹ1C@~<0llٺokkt1l _+#P?D9ȱ6kHa\_t*6ЖҰWxbNԤ40>&XxSOs6U@Ě|ZkiGѼsrhsD[Y!=lqf|+'h@ҠAˀjgEb9^'Jƺ=23b0=UMH 4SMR.c"RI|.Ha }cK \Rj} +R)aiK ˷2+FD}nIۑʶgV>&>-O(CL=$Qxmvv[jCO:ʱ.Ryܲ |^}&r-J.=kC"H W(/Sỳxǥ 3a% m""r茱o2:>MLvW!1\NTcɣ1攓!K^<3DQf*;d1YCu&yr`}?ׇm/ %EUus&5\qChyַkgՋ,|ńsZn~7luMN(S 2z3hWwȾF $s(d=0!'啬&+WFD/Kx P6|1.t,É>F0<ū p&Fy u teg)WQZ&z"X.^bQLVFU oL *lwWQyIП5ҥ4NfM=Q#G/D)R"KR1DՎqz)Iۘs/fsni!>釕Kdͣ~A:7`n2/T-x`|=%M&桌K% ]MTKw&ذ# h;)#>C2313˭u| Ц3 *j}9{{½ C0F+4j4D\ _(F6߉Drlg%B/P=t(m%eA@.קUv#wGB2RaL>!8C1 9I.X(φ_z֜50$IZ*gA[vh󨟅jϬ=*Őr0yhn>'S0cjo8 x#e$G f]{,#YmR>=rzCll@dffjmLr̦-A9 f%O6: Ș <1μ*L&nD IɁbjz &"4!2e#Z3AhQix]lz`zNa`b#J])#k Nˢ)Q 6rJX2ٓ7T~J-;pa">sy6%SWC s9 IXP*t W6sUu*~CqeB_dj򌜍5H]ʘ:BSV]).1?>\g]7XzA-UKTo$:tS} LtdA6:R7N쭈^)_(238g¢(.z|ɽ̆F ]՟ّzb!#e$`6b3pO~+gzd ^HE[h}5]$ 81dzU6u~^6!jUҲD7_ ]u9d¬\`KBL"/jږ"&ܶ~Fh0ZCa0XLNdW&1Kgыnz>*iN?r5Ͱ`|G{܋Qc\À:*HV7y:5"6z2<P AnGJ?Ho8ƋExxG77@x>F>5{TBzrیuNYss7vb2}]Eu픠 @z3+L1n{\D5ht.=E7;W̑1#&iXպ)DH)jоS\̛rʏN^S):yFN˴LA7^=UT!TzsE0,e<юxF& n5_- lጊOS/B`t8Z#: d Uߒ FgFy،2|%+U @W[2*ne\B=k0=j'1 x'hrCA9垑u""8o@#M-x2 j.c%=#q!5Q!дjbz4h )jJ#@P'ݲZVc,.loDUb~.9eh4zMhX⨼>ػ~7BHi~3ͳ@8gȶ 2"tmw Uxf`*xHqmtycܛr=]ۻӰ"F*.һTwKf3 X@*~8+?(k6}دr{Y,Iys?x JK3BC]Dɥ"?9)!AR`#~;$;(8ܭ>XDy( Iڅ gpbFR1Qp·UZ+Pn)3Niu=@rzzw;_*8%1kZIN&@FF Y@S).ԩ"~*IrꓖebSC\0H^`A3 a;{dT+93md*>vONY G-By58aؗ3s]:Ռ5A8zIs HS.N*[%dz{T]Gnh!" gF#kcWKq^߬aCٌ-{U e&TuO4k^m0@me}/[X3ZN%Y'\Gn"R4Z'B3]kv9 N\svﶷ4T:`?FJW,FB_TS$,%ojf3q4h$om 5؅Zh#k3oER!pƱقnүx]?&隄 jQa ퟼{LlLy&BZ5:u5ѷvg8\DX+4;$'r)ʡݣUᎸpt121L)" =]@w𽬠Jh BRR0W+^Z}r+KUhEM8A0JQފRQ,4uսD0L[fH !Ę=vDk9t7lLSy;Χl1:)`3ϥD/6/P"m 0 }#pI (OM;2@;y̥YZA1_so@;z>t 5m1  &[ n:1*/.vC(y8ii"俤.fEbbx!p0+pyp\׎mҎ#N6khfܔE|Q>[ECe/pj&܍q+snbIfk0B}?% p|:7{?Jr\0\&,Y#mbD=?Cҡ.\}N!lN\ݹ{ݼs#,`?pmNZXtlG}m >c_Z΀}@ۏkUE23݌GcZ\#Yw}.hEd*n;HPyOTSAI ` 0#SKt 5$X&:- 7_(Z-%Pox@5 +a'IАhl:0&,»'9;_o#.5"'N}@L[܋swHuzi6bu 8*إ a7A; Q蔨Ž[DEEӬp3@⤷>(KkI&R##T&HTLLB܃j赿$]VD ELRڷLdΉSz"[IQ)i:8$tgKxNx6dD!(*j,ްI aMfw\ 逪v,\g;ĦvA wZˆeCDv{AD$Ns&7.xW,Zoz4^ n nK7 pX|U.T`;9~m:A~ ¶Y.MwŁ#T MވW,$%AF m!{%({ 45NeO)̂ 5ib,A~P nVfvO!J V^*ɐ-8l i*z=|{w%;0/vmڄJEkܐ006FG]^FučPiՌ6s&g] KJqZ?ldbI>ݱ4A0PIqϭM<߇>["MD?RXėZ"3Hu adioc(C-u ֫aOmjg:_8+ÇQO<2@9(uK RuM̄B0y>uxf liY TjSUNN/ÈhEd>Nվ-j&w]v1Aaȫ@EKsj1E(0; wkrpr[d ?mX\)@=֍r8uҍ.:ޏT8UhN:&ۍTLs|*ȡʘs=4Mx; йolIit/%~>qPy8H8f~|E 2V|BeonC+@lJuɳC&(LγqZ5YєK)@ZJkA;slzgGLw%#xѠIM8+~Qу_dK6ZeyHE.rqiܪbhi`vٙ"TE9wF2-..0Ó _16i}a{)֊KܚRIy `/}Kq,0B(@n 7=}3PQx5ΧPAY0b6O㕇8$|^\)bUY0]crWkg~N![!֖#Lts_'umgձSO S@tc;z-wbW:w0uZ?ν.=ۖ MIC%`Mj `DOl!1850sDM'P@e{I+ uN9Uj0U6+& R•QF.$W`$'h#mԘ#^{?5ѓ6an.Z_IN_{>e>rI v5ŰC2CWy as5*Wߤ"}Q>\-ɺ im(o;VP*u}VI!l:SkE ]N|EYE ] ߶>DO*\bί iP85{ $"eU<$Lj$8{1E{~&Ql*=I~,Ж/=qR%PRs+KASںY,ÒR&J{n^i&hytyɸ>x;6a2ަ))*P|n@,Nd ,+E ?UxC5_k'֐@yln!)HM$GZ C;Qȗ.YTG-~ BܰzF2lls9Kkl +71WcK5[abQ&HDjusJ=\T"/ȿ7QƕWLl3#1LRFTZO0dCKUa.nь;\L۞%ZqQj`î ܇#b4]ETQA ,i;\O2R. 0 i (Eܚx|܋Q>Ӫ!-n;uq-BdShpcuL]EhVu2t痨հcS쫋ʬɈgA*S }^ ]#63Y=|yqwQ?> XA@frU㋚Z_5KICHe ^|mhMV߇L-ʾq 8%9wͿdhBi9WIIj>o|p/s dC(̬) KӉҸ[^qVk FQ .c r!*˃ 5,`6>]"t-!BN4vZ xwutT[*Pr;hD~~DW,ܛ\hǛBh&amjVsgX3JK)Zkh|ĵg*I]L]Ty#lLS2TiZs9W.^]L- Ĉ$q<,yA*H [:GS*:D7y-|[< L1_1,~-\j htol4]Ȩ /EsE졩>9,(p=@`KBBf̽ dK+.%X͙wbCfdT4[s|מ-(&,F5V;I<w`0lbLS@jj19{0N!;b3֡*1o@kwh a=3⚔5-eVoî(O:0G5LԖ߬$RK6kicZXf).XdSU-u~.24P אI US]OK?\™ sV/YU`xʊ暭Ku'^;JTLX9n['p}%ݮHC D-Mל(U7րl' xiQVi쥆/Rg9TQ7i0v۹}vocx\tf5kJN<ķ+ר 3\"\8|z,ծ%?eA5z~f|{7  l QYG~_)w=vRt;A@[Pn~Fꕞi\0Y,#7U'N!YcIHq*(vǨaJj +2!3Y\LeRzʲ漑 kviL5 >x.dR [|$2פ8$5]SByn?I,1`bI/o[h5Ru<3 ΆtH2'.X3]~ oΏ̗ ri(wR+K@D'eM{HIԁihW暄gWIC']nY1{oQ3G|ZFa]h(ZCwCĈݶVɠ;kbϓA)g]10<}i& 08V_mE5kVֻ5gwuNV]B$970!G6j'&T&|N\S7xzҞCeyv#^XLuNF`>vJp\u_QPo]ŵ᠊uO8ky y@d$Hb<5KG(ŮE%)S  Q?bRܤjׂk%f?LJKnj3SWu2#Q\#T3QbA>E}ׁf+sH$`y?kwR =+7~_v*l;4tc\nL쯿{^bn +'"X/3zYH7f= e~U oؼi{lR$%w%4B" dR,qc<cDe&8TPPw<'z{y0#Re#[sr(c6NQ֥GJRX{:O2F}%[FtRW=`LJ@{+6=>\ǃ@ܕTyWMM'=ܐeI8&rR*qw*Oaa?iнQLk˘[%^7Sܵ V.PO˸eml!mOR4I}liR2Br[GѷDYw֓ssBR8X\>4Wǻ6cnGK fĜ fj]$_ZƝ.75%Qݤԇ=(d:󖻣\,䥻iy&\B)¡>Ѩm RջO^dJ"\1v;w-:~ a3GVj)kXj[MBܫӅO-zޛt"W ws*)c5DgWQEӟ][^-xb~L嵿ے 0 m jKo69\xK cqF?Mi4pk@:0T#M¼PĘ2;C=QF'(G( Rl3RA1eTG;Aո:Ob5qX*o{BJ9`t3Aph}iLc=@:ûGry2""mk(6n2k,q6&rYsDKp/MϜP"fU\G 6eq˙Ϡ ¶U ʸ5NhA$: !!OX_zM=ILsFW1?y$_fg^iY>8S۫B;,ܢ5Q͋rd܉3˩jmAoSJah~ށ2;I tUuC Boh} ^#I$EIsVD g))lWnxYXf*m[&72j?&~V*-Y3@K᨞ᒢ) !%rU|:,۾^!|GxOKpY? s#$qޗj03b0?2CK:aÖu*U[+drߊF#ɫrGL@p_ 9=XdU3p,zEq+H찐ظ*>SC/sM@.feA[MDPS*d'M F1m KX77#ue:?Ah/66.mDR pmNRG]2@*&Mwg$u2b{`T J r7Q?8W{c蟰RcewЖ5!q߮.}SCOBx02>Gp!~gDfj9Z?xhAտayyq!&NQ/e$WFI#ˡ;Hi8g)F lv'63n=r5 HSf:Yf<7Ufb!R^dz.Cj'E}rbڬL.( 6NWf9l:ĘI!s bs-uF{[9 Xy]&g5C"r; ;"Xk2$1)$U?2M7KX|":ė{gwsBACkкJޢvKrU;0O%YL7B{ ]~e hykVE!@%N5r*n^>')@6T21nstq$lg@q~ ڰ~TC1*)Lq4:ԗ#!>ca!A\0 1mqS"R- ڃ["gn;  )Ocm ob95En3}$X(b`~GA@Z3>7-&Щ&K7ijߘ0ar:_R\+eݩY4+A?$Aҵ0l6̫8y7."NffўN1A!5G@9MNy^Z$r$2 Nӊ1˃zҙq=gwGv }Nwش!UQ @g]/NA\!bߢR՜pdb,}TQѥb'NnFd5_Hx gTt}Bmn:>h(y=v+2]ͭb@9+KΎ^n;y]B}.7wrc,7%LlsV,tITA[ π?Fz MrKF!h@40v*?ҵe3POaCk9뙱չҤ BYBj9W# ?>l[zM,7һ Α_sIvkg-!vfӄaNr$Vyc_4$LPP&} Y!c>5xv7)PF.UKH@_ILloN*ad{ yW_]Fh/2j^A&x<%Z8Ŷﶪ䙤G҅#E_W𬡱XvNӛ>5kQJYc%tv!015RMi*%iu+fϘa3g};H՟Lڛt&P_[G/ F`ڃ~|32kV wE>B yxV^n(G .60cY_xnd訸yK  b,(Kc4mYSdS76B|Z/N|aA.-JΓjA{0rp=z_aa? Ar-ʞZ@lXX=[Fq@KzvռnҌ~L};K\7vm,P},YȐ{ CaM C}9EJry^i CB&&LRzϥܴB DB D)Wj֔q`͝_o: 2rJPڽ⧴<=F*.4OSJaS'tԖ,U[1xZ3 zDՄN{RM V4جv EeҨS2eg64[D¬FpT_T񟩝H! ҍY܊aAAٴĶb\x"b#ÒPEkEi 7x|eDl1Ȩ@bū3.#e=eYbnEDE1|>)io Fnh 1mbӢ_o{V_$ƈ 0\:nGGkwTXS[#nB<$<֭fǍ?-D'9AnR\jQHЮ?Z>e9W=!>z}'K IsB,+\2}8o'//o~B|ЉHA|h;O=/T^j\#h ⡳Oj$؟ڔu.,CDa+sM:K`ɦ!N3c[ :$y[8*F2 >E'aټb߆<\W6b`>`4lc]" TCB15sLԔNeUwI+&'B#Uhas !Մl?1Q}@19AT@ڰ'Ea$C챪u 6, j̵^?5.*< "7v@3Z;(=o`o}r`fj3.ȿlEKS(aW:qI86%jp[MY kKd*-)Z$>9k.6< n$Qa`BF>nvʼn<BFOjeFӋdS wܩ1Goߩ!;]M˰鸙 WVR9Vy&$t5CǐATIƚl=nL/ C (P"Z_e>_3)ΤbUakzҖ|x?* f>7 rs[P dCPWŸPH_U#vN'y'(h|7ݠ@W N՘e#tEbjyS^.'Jkn.R7  ߯M*JRbSw3gaHtfMp0K繘.Q)X+|LqDA01RgQ.pq 58Dr7( .YlK|Фj,3AėAs gIʉWm*<}f[qzw8s+|jƤ&+54TeL8? ]ώ%+h{WAPvW[VesƌJ@5XHWD$g`.:Sv忓j8cz êI5/]3um%?gc.G0"u  ˜(J{|y " P); i&4tIp);6RIXn -ũ;$fVI0aGT(`N p!PQ=lmxPGq C^Tsܨ_V@ j;r&,bi.w */WC$/+=[@(j& 0+pɾ}n`JAw|CXlsHER;Z|QKˑk5{grAS'Ba^53TkvMHdXv]m@ƺ}nk2]t4#0&~T]a ҰpAw)GGoB0}FMl8QshgGVs6P^og/ aAvke2$Ѳ;:O/f9ú enŊSf/6Fl!}Ks^ôtMPR˧^it鷖?vq|gjM2D ö^nwZ5^$e4^uLݍ$`VLƏ*u oxd|""ݣH栃9u+G@{\.b!{!$))K[V\Ap`HIV۳v+%nW)nƻv?L!r]xR}UxdP$ ~I*kp>lcYp:&V/4-7 nVE)(*LlYZL \yI啑N27!:&uUQd]ٞ[~i9%?gpzwi}mM]*کh>GSvNV`6^D6Ĥh߀?S53bbVA҈}A9y*JFU-c)hІi9b/$jiY1MxXՠU|v/eKF]ͫuӑm->$yR<j#!3&gGLP)+;`+O}^&i"kHIZKl0QK͖d9CͣjG"/䖂zJti (\#S޾j>q`Jy1jTџ>N`މ-Rٮ'zW4ۗe< e;DY3[rym2l$ wL_( iG?iqjđPk_C\2%\z"l?=jJPA8/32Ml: ȘDѪ?x l腩6:L-{ neFƑVuj_۾aVsqvͦ[[EV$T?opMssC )QNy*7oM?x?2&ZcgyLnܙN(R1"S YpR)~b<6 wbϽWXRNyU/P4$]OVDB3/1KX:+f—Di3Ӂͪ ~ozf'egz?*eѽ".p7_..qVYdAqR놎Adt,T+ʧm-&"e%$db5=NxW:l\ahX@pl y90㯐EMpQg9Ṣx3rx81Ixզsuܲ.  ;LN JxB L&9 @ 1#:=Uh\eL6Fء ΁dv9Hq2piTy)8}r71EP*AX׏~ډJWGD{+OGxv?5iDQk;u$N,;hn(=k}:o'56 .˽~.Y&nE=Sc "Fx0! `l}}\ϰ鬘+EEd z폓 8Wj^ AX|G1IrEg!!`a[#'T$0ݮEGf*RbpgHVOj,4Ŕ[ gW,'~p!@ pd[1cn_[M]/X*:^@A݃#]RWO+XM=QjFt҂r`=Ĝh} 5,RIunZA<ƮŒm"% K͙(9=f(5=EqU Zd2Ȩ~v0%8cz ^mw . uAK1 0u_S8$̵Sւ#FD”6_Fva{9CѹP&dB_qS}#9o`3z,+"|¿؛BKYxdrd#.T9-]15˭-W4 'R ajIq aehƵI=Gԉyn̎pUK|;: >-7&8H3rK }rtDY]([_owqݚw*]ݿid,[j7=S*c9hGzk<*7HzT٩0h6ee>kͷcdVrA~)'NzkGz@6c Xד&{|DDNr/ k#.BMN %ڋ\ Uj,cJT-#`^>f!%Up'!wO0%ʰx7Pf}fDK1լV{i*B˷.ءgOs5Q҇zMwz+H@cWEyu/ *IRnc0:c+͗]28!с˻YL\GWXp$ ϥmŢJl4fYZMolA7r="ۧ/N\^a&Yfcef7,uꜬ ghC'I5O\)*c2h!ςMm<$Gؠ.pr[ccK (Bxf`vV l~s˿U̼ƥj[,IkDyegTͭa!G eYpչꊱB5X֠LG*&N:DHwpRo6Oۢ邅E;n0&wY\m_Uk SyFے'CKn 2А LE}iʿIKi@Xow̟zEѱ`;2!ܴZ{Z>uӋ_}Y@ҤólC41;JwJU| ۍ"3pCH*bsbbXTH U|WU[ !mlVcuA=8:2^gz8^Z1ɓ("? dUV"o4MCFV0nħn׮8J=V>9Нw#ed<&b<⪼fհCN-pj\;<;wopKwT!I$?E/ÓUЮ-~7/h\׵92a$%7=s\\$D"n'D+!Ө4+/BdVv19 Px'Rm0edmfr,E6׳F)5aW35Z=ܽE?`Är'BkXs6b^邾+g\Ա T!؁g{Duy }M6248E2ő`sOm 0aM~=Y2C.q5u8uI45Gee/e(?DSG69`rF8; -_h_gS*1U^j{vG vm)n>*VFFgq*>|Q΁ -Yڿqګ$16K򲾢ZWI-Mk [T^_Ud~u=\DAVyr˒ e GUKJv[zO9#.fyvU|6 =u61b'v8dȨRۑ"nzvZCqp.L }}x0xcYJ32-b4j4Q}:ቡ1-䎨:RXK@r 0 as6GbWI:MPRI nkF!.~>ek]*\v4%u-.2+mns@tn Otsh鷈:8ڪhY}x6ƭsfo܂Z,%Yj)ꮁ>xIfA!D1;9'T)AΩa>a-޼!m|^L:^Zq l +_:$P:o&Ɵ{%)G!KMۣcQMR dh)nh{lO=Es}^NJcgh.|FڽU 9bEk?\㗃NoG(AXw1,B<"> 8dw76a.?"?7#7'S=:O󩅅1v`_{PⲅŻY;;&Zn-!ܨ]'VmK;)ds <&ꞥ87$v$N~M~TR{mkf@ WnצKkf%g$ p#nq]%ж?6vІuR)0f*̑}A-‰ĝxR%1}=4M|\&S&*-r^ ; 6zeRYVud_'MUiW]ʥש86/3_'p 7[C^ iey%J7c8[Vd/nM,e9}};f?+J|+tng m'ݛQ~@oTo!PƏӊPe²kiQu+007i|d|L]GwlL9];#u֐-IbiH~^ hY>ZAr`;&#Ut߬09YT4R\n EߊCF0g9&R(@FncS3~8.'#1Rze5mB겒Ut̙%w[!81Y;1󢂏ٲr~Tq6%4fV u=Lg]ψbi. Pg!: 1nY "A06C4Mݲ|?X\0+J/ bGnyI0J\N\?>"1|9>&qUhHF y<lm,uOSG:BZWK\ ED tF Nn욡ۣ]FbҪU4L,u=ML-偡?C4=VȶC%WЍ.pŏqx}N$E:;~-pF{REFюΪq&Pqr i1`tB)XhQwc{USISi,`GhO3` 3Q8P'cCe)st,Fd z(qd`(7}t٥6U+ʸ8S_$a,^R/Uu6&}  sPH+ ],1 T4KN 0LUex۽ٷmPf5\:GQ]ȪS錁tDJ Vˎu-E>fUYzYHUϸܐpV)+RN_TB'/ׄ,mNAmQs2;WAGE bDW@¯j%ݤjܞЩHwNM@hLCl,tMܮ&q=*x RQuH9!i<zuPӻɖWiIkCx\c$[LDu\{ݯפ\ج#+D\$CɣPhR^E$gu.h=o+Q`]-D# ED}HM<[.]BF`U8׉)RMQj&DB[=JBo _ 2p{IH9!  IX+KR4_,f8\MhmŴQLЮ`wx4p}b-:l(2R*")bӠPƷ?tJ cTjJ,&KiaSSCЖ[=EO R_œj/xV 4^QռZRߛ,#wYt`Qh9**=A"$͹,2 9b/䌘D];!Y7L}u1g+*bgrx1j;fr&mnSoO+:`#1Fh.B<%Nq"MIZпqz!_ ;}d݌`jH [~]ЭZ1ahmbW2ruP-H{.<6Gs{؜2~,1l;ht,sr{p,(WR6O)bBg:zlL$a`&ZhdFW 2۹c97 MϠurE"{hXt% 3A7+Ʌ.Q48Y1d랁!6R"I bRg GX퍜]j`ҭ$#e_4ǁY'~RP(JBB4ו7y$lsKpt1bXQQАfZ+j9J3rJm43N ˣNBH|;P VH3]i&B؎d+C~Y߭SF'A[;`tl0'S:cnB%z6&\?S,4-{I%~9ێL[-iZd: :PEB=;.g d9D% H?x#W.kkU`,!i,+' [+KΚhʞ1?M{ZwC݂U**QE4Bk5JM̓솖\md_iPS: ,랭uƹHA,\}hyKg-W*3K]C\,zQ3A_Z)e4I8+je#M !u^]Z 1:ӧ5O[S#8OY?x!sS9$׿};e7Ƃm9mxWCQuW1f`p k%9mȔDU]nw]iL:]\%"[bX 短kAƕY^l{-g pr?Lj}fBGUg4f2~̥vHItrN5wYc*Z$&;l(ըKܨja1{(eR6TMMge@cw}@ rk |)=\K $z#E[0\NQMmiߙ'j$tB\sKQe|/:0b(e\8z#4߮j&d^;% =e{{^g)BXZ/U ?ꔍ1. WbpT`%~dTؕQ}5&KVd>&405 :@Am#b"2^wcnh|ܱ=5xLM~3RC}C_=v sݪ#S^/ u!`ςށ$(WD@^pWFI0ʎqh"ے5|yBloo}i¨|#>2Ɵ_1\4HG] #foQ=:~s*N{gM3d0!j3tlKE5?2`tEv# K;&b{n^:>S@vJ?C{Nhn%FS-y;РNfC I.9Sg(][NCT鍔첆c!'vpUZ9rq\o)Χ+b7fۨux/g55 Ӫƹ"ʱT2Ghc)KZ3,|1$6Zfv2l0&(ާ.|t|iCRpl#hx0yVlgfcjBE` .lclyFrt5pFvA4-E=XilΥ^Clq1?b`^\j|v 8Uݰt]l~hIv:F;_{ qAfS0G;KnB5/sx 8z@oUc7I[,l/ͮWdͿ9Ik)g[ nqQх%I%" B@kH y&ՠfHF/xb2u4wwtW-I7YYVv<0~)MfC4EYfphs0-l-Nv?&yO!) Q}o%-b$}S{sˀL!*0Lk02]hyӱcQcɁ0[i5"e27Svrg(4l)}:D*6"ב-n)[>yr%`_([v- 'j&kC4ѯ'eIIfkU2؟S;2-oC^x i#EoaOCbPr!ޢT\!nut=^$QtlBބhVԏ1vꗆ$,l|}*IKfN,SZ;j@+f9cPx(n 9ҙhWQv5ۣ*M8jGwǬ{vgoV^p5. #pCvQ9O9`g ![͐|E VvgΉ4/- K-܈gZ3PcΎGNTq24 Js$d6Z*Y#{Ro̥ 6D whFzٛR]*@8kZO#ߡ\Jdzr*%WKzʪtSK0"kߛ4ez΀W ie߆G{_, J2UL]ua0QΔ#wwL.Z$ 1{Qm(_Sߊo>u3 -E};!]f0ų@&V98IyyS@i4O,Na}*͉$."Ɗ x8H[Ycu[uS^#ʊ?Wɩ'?Vdņ5|H)D (zDZHӎ}+XZ2[r@V^?*K9C-(YgG wg atEGjZXE5hxLP)X?OL)>pj;Ɯ:~QW?*4;?#2$x9 1h(EO֟D܌oJ` eEsW̥Cќ%d[ˇL򴣋Q #C/(ށ<#<Вfb_mZ\KC"^ sAǺiUKIӲK36 ; y}H*Iof,WW ·9؇іiK!֊F@v n:#^= %+9o~cKCe$.O[6lj&u_Ʒ mz_RD2cI+ OY>nCBƛ:L6n刌hQ f>tov{XW=ZهbNN)7(VVv}Knd:sm-ʺQl!_20Fr踚úf$B:Ѫ5hI`41A(pe Fa?jseHMNH1fzgps .ƞ;λY!uϕk w }|Jݴ |x(ީeݒ|9lj;]_%l&H3v Ƴa!<%T {Fե PZf[4dm\"۞T#KP-_9A)<`Z@w7++q(*~JVăbkG7 ?3{y1 aQ5 sX P|V'5=+,Ec4h(Q`Ĭl5->gF4 $!Y*CZ 6{PIq|o}}g,댦ޏ{HSk<)G *yasO͔@0[4-E1Gt%(){rWӂ膷EbYR-$pD^[y0WJen6KZ~%A4jsգ+]˾J".e(7[E8q05,,IgY$|Dd@</rNjϿQۊOұL2S@Sί'9!BrξW0Ab3HU(tSmy6d[_L}zQ㖒%ʔ~R1@(h}dL%jVnajzΐr]9.Ӈ-xl l ?jј7H&8bX,s=< !Q{7A4,]:/K`߈&L{5d[ u?0u}b571&R×-U4B_n{BsH>s}v"ҋ- \ ShkAlUz,l [0%[Mt?q8 [f"_;ǍB2nК{3W z_bB 'C ۋ0M[P_ wWڡеh 0 ͚XS5A1x$6΁0~J;)>WX4Cɺ̟DP,|,JaoTMm AL$G{ewq`kUs3m}^IOdqpg+6Q,q UHx&c9ʮy̗~Ff7+7['\^f=\%`&xm'~M6 1Ro샳 h~ᡥCӺ]ۀӟ`>5jc+zF(Tda[]Nz @hIum<~fF~^e-ؐ]{hEvZ<~{.BULKm ȼ\g `B4>T3y~&UӍ> TԼCMB8`)L;'ev9c] ͻUÍh_.2ˣ .aapΜFg{!ct0FŻ*W\E(j /;ӿ4&h}1i`O>GhsY9he:]j|z 13"q-zj5TKQ="ѕJf7 7B]^DVq7$#j>HI*f@g+xfPu4z͝'0F/_lA^ʸudz_~Yi׏{X!rׅį#ky\Y#7 \ e0/.{;v`+!V|OΎSQ V[|gzԪٟ(_2[OpLfY![/HkN޷LFy@Zk&&|$b^ 9A+X "ql26m7Dc۳y2"YOQ8XڞItGD*G )d@yl;i!4% g9`[e3A-AϠAƿ٬Lu`nҗөCik9kB*<[E|Sz<2]\ƶQl{{NRοG]j3NwAm _{^U-BۛȐLYȪmj5k#+ZC'CN)T(X kڕy^c$MUi.^n6n͜-6K5U̵v*mԳG6ӭ_zb/֪Rn D{fX~չQ]^m  ό&.<)R#=P͍v/5:,'|e#Ql&f U-⬥mrf.2Mھ'ΜP$KV<=WA%b_u+l7{<{ņ#)-S쯴<մ YURO7A!G&@]V{v 6"07F{E ( Mar#a=*9ՙIP A]2Ïv7-2r0Y(Jw7G^Ӫ]pmvss|mo 'W W^#@³lPї)Yayhf'>z#h^/q-q'Dg1eHd=4of"tw\#`-tXXcƉ=lP(¢ "}]M+'3j]tQb֧p(#==޲MjbO0 Zfdщ9eIt*蚝4dJ;(EHt 4˩GN?֔%$8XTY:d85D M┚W pRVl&`hIȎ=ZJ]>7*DuF5edDzWҮfe'GSHg 0tN\ߚ58vy*O1II¢綸O+8).񯯨8o *;X JZӿ?FgMw7 UؼbsrWW=兂'w^)9:j[:~$J-uX&m!_q@N*c*)SfaE6SJ*ھDKzQR#$XS~yip yC9Y"c %89v잞$TK1?z`3̉[Fv̾-£9U^{%cZRտ99TJ3v'QP*WǎUy#e?ړ}}@{Kވ؋F=D-7}4  QJ~hn&R.03&^%f702j:Q:w'B)6b4I>&>ʆzG1Wf~] <`7YYp#[`)EJ[d4jhsZb$^h޶"VdS|?L'qa٨]j 셩{M "GsBk\EDD.zaTxk7|=Pס3rsOV9~G0++R UmXuKy}"q%g&F *jw n}W;ZAU{ou^Ld\,F3EHu´U/:!*-ηev8 |eg`YIE.Ex•kaݕVkI]$g'$xGE* ;hI']I :nN/Y-=j~N_D!hDVzB)!@<# (xhz cb0MzOix-c)m}au $dnc:}g51ox TD4p[7{ѳ7UlɌGl&DAξV9k^@=N8$\+޲"ɾOY*G;P;K:c xHQ膾${25RZ/RѪ:*_aN$EGvg'H{HrxuJ[7+v[dIn f!r؏G)VN'q%lD(jh\@6֡EzztHoK !Z2ۃwع. XIqfh{JЋd"zC>oieP 8\Td4 Hy"HK *$궣 Ld9i후;^WkC\-$NY\lL=+Uhwk/RA')=C~?| S@sɿ0/y8%PT]_Nv|DߪRξC"sAT{b\{m "R`l> (2XzMgj^ < 3UI+ *4aŲnb5KH6Fv(KDY`SG>?KJ#+9Q dkGKcBu(CzdEFG q`!3"/s\eT#\# o0$/H RH췈|SyҾVjR 45|D ،(ԑ AAwJ"»:*+Nۿg?@xF5i&f_bYᘅbN6Ibq}g~x:ZrUob[7;]f0⢐/TE+FO!f \G xlAnH+kBycgBTBymQJqvAް j$M .(5x2mR5쭙 X]\ /.12Յ& l5PrLJUD M0e6O@m_ta^Yҕ܎1pHCqJfz)B<0_KLBTa*V\NƤ!YuR¢#yjg_ 4%S{R3r ϺU瀧K oB;#ĉkO,Z/* 5U7n?KuԾcj\((eu 0FD4wj(1![(XSFrIϖ@5*eh\vҟ\SX,f ֯)=TV.8l3AFZ]#jq-N2a*.ߘ|fT۔.ׅp-s0-IBQ](65FN~W?PՒuğJhowSj WTrmrr+T{[]a<IĂ]v.`-Я,ciBQ;(%E 0ϨÈNY&d)g;uPscQߘ>\]tNX„v 7`iϛ̊vR #{"my .:5 >BN&jq$n}<#*;m\}lv Px#Ud\l{s"؏Pe_~dl8a䤚#jJqp.Wo"^F>\4P_3mȗoyux dXLhģλBY‰WTG40U#tRYxnyJe3hOLΈܓ6I[.u j I5 2F#9 aEBX C3D+`F#,Y 'Y wjåqHJWTcP\{./{0paFj:dc8)e5uSEhMqс}qhc`jlQo\),JF5pS;'~Sm[|1ux]#9Cͣx!qqKhEE? hD){7Wŝ׶.L{'H泩,YExro| ̿z 1_"U!tKcv'Az~7Nwtq`]Ėr8x76Pr$iI,_%󗟂Q,5b.k$lDj/κ_H8LL1aHss_!Y^;duID w z?[1j NaUr"݄Nـ:#Rpcp 񭊥j+ 5ո!0RVB`R.' *X̲3OKnnA?#@E?2 f9hkhچ 'W@>IKvWP%Z0ʌeoQ-v;}9 >2.TynQ+5},15`z^ו7@b )hmFevedoQ,A%Z(*p?|.kG8o4]W8ZX9c&W{0ԥܿ[W<%<|TMH;v#hT.[wWrOp^ҺشxNp3!B\j Tu:߀D%/8rr1vpu20S?')l|iRj2:c$g1uQҶU,l n!7NyVie]06G•( pH b#k՗H!(xoLA^̣BOFsxO? ]Lmc9ή eUrd0:h(闛Ty55Owc7a.':]V>$b8 SDONOҏd%SِĕGP)Q;g7bP~VQzw|>{9Hq3`OۇU$\$4yQ Ty=1"^XIJ40S~ I5zg&q"9G? T :*c+S0M$|~~L,| aEtcϋM{}y2ߴNefGKi}h?x7݆"{*`V1cFӟ<:ӶckmG&MR7E34M{h]C]0pU tW'6rҔa`j-ji'`z Tls %ۆp8m|ay'<GgRc[w'FmEk}NΧt_qvX{i7{Ĕm%9Ҩ b%D)]o߆1 )jhDĤ70o;){ ><ijW0kS0q&msN$IrMPRSt!R:RXankKf nPVDmmk߹`I=9LP6awP1,C2đȡE R  o,%d' !1UKrg3"-'%H(Rr7&47F/#-&:=  {t ۩\&A*  ҋҢ?t}vWnJq|rl g] .{jA+( ? U!J@jm xuF,b6,F @P# A'j^j1x1浱C"h:68 @DhCg dK;oy`)uSZvV{ц&ͷa&]y{4oTf0݆DRcy. ed[_Z>ƫҧ{ $J4RV-gi[uj%z!(|i`Pa 13@5g>F,IN|ʹIX Dc)FjC1B Uo$]8՜d܈-Q!!P]u;y#1ER=^uN^ #i4n^[_UB!8ԝQKd\z*xpSe>7P+׌m#NP9w; 7p:nfTd {is΋d5FD4濇חm244Tڀ<#&W9ɂ'^)O2րԥj3@i$ :Bp[!l809%#+6&̊ {ޢK:"ӥ8Kެ'1Ct!cR 4c@pص& .zr.Wa\e1ưMzB !IAoKLzHX%?],l6(&MՈ#';=1Gx3u~&‡.kp=`֮Po&FE˿y0,Sym14?MqI.@T],NS/־No@.U:\OG"h8DKkQ4T*}"_xdlXGmsl!G%ۧ{ڷ5ЛU 0;%W~ӛ:膤dlVId68|bSuu|5\|Hs<`Ċμ%ň*0N͑-;˱9(& Inx=9 [}1c 64g~1qR-F1t!އkԵo\'dKx>k;d_Bet!gc{MQƴGwrJ6U}3 ޔ+L ,~t^s*ACN\~.tͱi.t%OdУgЃuE\dj_2g պehP4jʄTi#IyHVxקYңCf*yY|@dew@/;J3D1qKw2Δ71)VcAjR'WA:2%OT@Ц^QQ>; Q50 Ų̨h/OFz"fzJٞMZvFar#%RQ@WD"xc:~K9*}18gmn8kЍݱ!u*Xc}ǧ$K2fO@A㔵Bʆu\wgsj8aysXƾs;p1t$jL rqCSl@sNWgdT\Z;."BU_Kn7B׫~BjLTT^[Qڸ;gQm^C7T1U1+"u{Y[c."#׎FZ srڽ~hL?H0dLͷ꾻I)EmpP;.pś *6e "Kc ҹFf,Ֆ[ʤʉ8I3-VBUЏMkc9ݟܽЂ.F޼!,~tS R*W$lq/xjt2)Hę24F/Ö10V/9TؘH{E\$@ٶkK-6¸hXdh\2\):cV9B<Jךa6苟K:"x,U;SdUI$DF3K*`+{yҺ@33VnbV`}k ifF)o҉}#w&xfU.Wd>мtS7/3C,JW7GJG w:_HT(KK ߝSgC}»3('+UH\p%LJ$.`<ӔuRqyrJ%PTۈ)Ss'x}Y^5 ]*_,'$:#/^R6+D6q {#r6#S,jNԿȏY>h yF>Gnm3eO;mA3+ot ݡ P$_PMúCnH޷{ J9>ZX?8?):Ou{$30I?)^[Rylz:98ĴӃ-Rgf&o602WYYFMW-mzJA땒M(ZV: Fi9,(tz(_'Y֊yۙ.*$}RC̽B#ymij~/?&@,?-w,8z,C_'&{A8aߜ 9w%0%*vuo!;-'t .ZA>$ Y%]nN5F]Sy&87qxo@ bmզԔ^!"b\* lcM3zu7'6sO1CNJyӇJI&Xn!0/F >Rg 0okH*kt2uzo\ew; @G[Xo//J'|~<ϐ5.%Kz "|sP8 ɩqB|ODȸ=(ݱGb^]y~;Tpm?FOk'{&2DF@UyE4$N4!%|au~/B;]0TL)ں+ѼϺ1~9킷6lձԕe2TJ4shp4HM(eeᲢ+u'+3hk_iQj:=vYm3>If;~ҎPxX-FK|,cx)0 ~I?&jA36]MLP)[G{ؘ_0Ffg`"v4F[u K$\홆ipbuȉkYyjK\?uv}3Pef)saǾOҴ~Bww J,"9Jӑ-xJF , Az59bk ۹J`Y6Z(#`hbB(P֧6NlxG? =jxQ 3aoqFLstZPA=[Ҷ*TxV:4’xxˢ ܧņ0;A۴Xq|HidsZVWd~5\02 &R/dOH$׵<<[-qczݩK4>OqmElM& i DG҈; ; -Tʈ4tF@C:{KC_~-u%xY"X(sYf2?̉iU:]V 6X ĥY+2c}n2+ M&C@Q0;+ie THܦ[#DJѴTY߬_VXj=<(cfqN < /NJ~<0(N }k1nKT1`Zh  5nБT›)Š,ASI_v$"@ nys  ^L>̹zNBHJ2'$ hQl,  r?poY|WA~:;΄HU:s|zBtFN q%+W[ע*"#pZW<5O6$qlUE˘4UrihK8#O8E^k|$DP#9%#^%hn!bm|#َŎ)괛VᐝP.pTI*{y@RFoj.})8}rj|Q,?&H>@ipa3`<56C݂o>#<^&29,%Z˨[[Z`Y"4 ZbqЭ]e<-"^K|Kez[M☗6頡 v"Sr6Man=N^gxTa5Uvu-#`x.>B )WpC3VG6ptF"#KervK0CfsIA|"ɍ]b #bs:\,4$ALx nOI|P~Hf>՜TfӜٮS;] Ofoo{z=k|X^Ջ_1%t *|gt#NzΣܕ0M,BSZ;.AmrA J{tSf#M c?uJyT?:.;lZ /^nٜjuq~+ abnL!I1^@#E!`ť"(S: N #-=* 1](T:T\dK)K(ʱ}'v Aj5\g~Ǯ@p0f_/k٦`PLoIqh;ϊ`%Y{ uHt#j˙:kԭ+O2GpXfCx Q+Ž69xQ5΂ӥ`8v*SR5/4mL➔XPpV=ِE;{i;EWND5-fDϨc+Ln~7 Im/ :C/w' 񾬆3`D4eܷRXdi]+ -"ьWCN.R %jw$9?R+?^Up~t#A#D !^p -7T.Rٳ 7A &RH%VKL‘/!p1UmIٹYecJMePr5.TW#ŠhV]cUw%A>(qN+ Dܾen>~ F=g &QEp B׈FDV(SNcWB:fZ\Sf'Fʌ TMMKhQ/`'&PUF Wuv)E{g[6'c.Zӳ-}DMX29A:tzE8336̿CB-\)Z4S +Y'%(L eˈt+B@܅&GwA庲.t̮s,aihiw@H!5f開"F/>( i3_(i^tB{ v#f4 1l:mDTz`FԼh{0Όhrԋѓں|<" qDl2SΩ@_XKÊj[΄"*)rՠ7O{P>,mT;8uR'ehCTgp=~?];4BjQ/*ΔWhg ye%! .s-406zߪ$RA4mItg+eVrPpmSk9k1X]>Uٽ Qv,c>q\'Q[ s|q%R6䖊15A>8l?[drC,8!yȉ J=^@Zab,K6 +K$SpM#$FRjxU8дXuVoPG>;_,oy] wkrXQbV.HIW>pX]arB6SbJq[L־{6BTM>cՇ<;&x xlX;4[M&[%ӗ٨9k8ђ޸0!t5,"r?gZVɜGn/x;蠫>0Hu"usT+j3K ^$&2z O`CcԜ,?adh++΍bxİ8دMh+NshJ̓z zG.>" CzV`hLx5)L;|[#pKD+bӻ*4@e%>L5ʆ֖fP!Tk b0,vDo^gB44f2R"w %G B-?`EKF! DxXM\ x,C?H[>[aTaH0 >25ΕDNzf2˧wa,t=ͪ6=]eQ-ugʖǼ_B_}ȹ'[6TʭY薍))q* "xѸX(ߩd=Y%>Y[9t}Cwق@]o& Bjo]3^y;[tˠp1"NTcߨՖy =!.]]];{"rg=|+(E  ]n3aH !9 װOBsL_pl> M+1i=[:U.[/8"gEETڋ_e{.=m<?dS l`Rj}t f8^C f:ƕk?T*P⦆4T)_<'&2 } i`$?sS褓 Ys}wPZ<.ڴe5v ^ՙ 鿸ngJ=Qiٵ~2 G^n'~⛂>?#H~H2#dY!MeMn~-YbXAoYg H:\ٲ:R6Ael2X7s]SO÷r'ҽG42 %$jl,]l:*`.(8_>]lXPUsHv: @ }Y>"Kxlc SOrptTSqB(7Vr3ִQőQgT_9wjH =05~1)5|QxB|ڡӨ_QIIB9(]fuhJ^m$$`͘{_de6"*v[=ZqBwctNڈʽ~0QƟc)ew-:rE'U. (qͿ͏<ʙO%5|1*T8Q+K.ıX,/2)s929av= qNݨ.g nʓ I u=hJ~]@;#r4f0X fC?!JV 3xzA rD!q~[zVၟ 3}l) ۺ:WW^9Da2vrUO)A\ |z=*pQ>XwՕ(.U[Pm\kE{:*YsM=@<->ʌKC"upUEh, _;847l (P !P>wV-da$!+RDtE$\D81g%woDf\m#een5ΞSm} dIA*;RCN ,nxn9$@ /|ld,ro\]9E4//…-E!A#l7zGan3O êX7k/,kNSSPGü5SZv+XHQJeƂ|s ZkM ڿtE+Zb(s`u$$ӎK+?Z) -Uنd*x%oxݳ$JA[=ŢџXXavN)a>d7z#juڼm!fwi5YR5*@?rpMlj~sT~jXDsp#wmc>ɫp1O"}ͧ0ƌ>s"%&T!0)KIUw%qoA#]N6r3*SӇVzT 0@WFr`T4wϕ1e>]=bRCّqnܟ @Yk,K_3%ԡv@0]ھJ{i.lI5$&Fs%B.D  d3S 6LJ)ىɬƯf!Um9 (WZ??>eo+~[5+ӓ,.V]jS>ꄊ8qs@i@{1T,;`jLPq;2kx;}tQ`(@Ğ?׾ǩ~K~Fw@*no %(Z{tqpʖ0a2ŪRhWf뻘AŜ?0wzϨ)ޞnycbkI\*SE>ɂnC : M[v! FQNNFj) 9k׾2o),r_:?#&uOL6-BGkG_oׁr,:Ѣ|}Ц ZouMZKH6v "[9*#2R l{~W/>7Y1"[@φ5G-tyM*ދO|K˝Zds|r  QEz MM=en13Baw^Ām>-`]pݑrGzDmdIϫd>ă`+2n{F+.ˇὃ+?bRq>bL:ף@?3z4̍}&2kbp0ʮH'Ӽ$hvlV3F`>[FO.hK?u9@O/87z9%KyT8gUWctN1Si$~0wx'JӨ*]T./ժ;bE,5-n$V=&eU΋3*dgf@!Qkm  w$aGM0l0(8 pm>5ǥY/eX>, ֥HM妒ZSyqYh9u`¢&CTi̋tB5G@+x</S[I蝽UǒW>t@A/1ǩ930;JwL']QmlXLx ?f?AaѳqUG)?4:rp5 =1V5t3*oR;+r(lBAm-n!w};8ؓU̸L]W>?e+pORդ(wiZ_2 `UpuCkZL~pP[,E.XNt#,\-1(yAL hl(?)Q^e3aӐAZ˹h~,^ۘn)+R^6M{e!D;5BoK x3uDZܚ_ۜ CB17XAUp )JtŬ #;UBL Qk,Mנ4bZ<0y[hJpp>@p1 :1Gwhl1\xmJ,jX"}M'3,`1Ѭ,FZJ\ $ԹVf@+xOd^8* X_$I`7[Su=6U%"A6jR=Q䐥B02եfUمYed(qURm伄J[}X :mblFE+'1=V?Ttjubg'4l;.M<ӂfc1˥`cqkne~<vl9݁Φ 2?#3^e;{~PWCPQa-i`fBGiW+O| i~]:*$w 7XlNc߭_D+Lɡѡ2q=q+)qzl.baʅW6nA,9Ë:%kwAvGTnA9&ߺX^z>Gt1Ŀ5~Ai]ZQM6J.ӓf:e ~;'ڸԐ ;~biKt~4r: pV$nEu"fFPNs c[]e%.d)D"l?FWYKA$Ń!TG^F]E&^w eGp5 Ot Otyvh}6e@$|0Z 7 ,m_1v*`O#<i#^„'1hGX`+y<#(EZ"tihs/w O.d.I4-sPW+#+⋰fjyZJWN:qS&4Z5ȼՆOьR`;ta W"أj[*I/^p$0}=j &HRE B8 /{7PJxg&(y^S0YMv1mADLw3\t `6Žg>E4;p=謤 w)*SAG{K_`v*Pa=8(?V37eud: S<@\V|)sMC5_v[CEm\{;'T^\|{vOG&{eƙ 9ˑԃ LturFl ٪:5¼c*|Xm(-LGa/)BAn+'[jH<.xMZqes3nx vߦچE3~l8g2[s{;"RY ^9-ˋTgd1D_ߔ 0(ٳI{ PC4CSn[p꩟hm`YD?K3Asor/$tDF5ΌQpg2 #vRr׼j4x ldSSv}[tx#Ԑ,dsPtU- *`;9HgGyD i癊tl|1"ِҽraVcWM$yM(a!*5~ ۷_ ӈuu꽲*.pV0)I wڑv-\؛Tܫ[XoOAuRYpAvo(;avSĹ}@>bs-`;2inIeW%yXސh(X;u_V:šiѰFWONcg_9.xߴOބwMkȳgGj:0A L3؏$a iNjϵZ!Y5j&av3cTdiB6_U-wQ-ͣG!À7Y~!1VTtZV`S1.q,bPTI2G只Ks'f`Y⍐9^cmg I('"%P kziT6+RH-а6d >D(WNal9Tx1puaIŚe*9iԹ w?$>q]g+Q gJ,mj-ނ}?֭uy 12x|։[xMsb/.k,y9g1:È #۞s*Gp:i wOeDwGOӂίل͵6઺m ϲ,%d6jMX D/#xU O]ߍo ǝCJļwr!!(ICt[Kq _\j{-Pyevz-l_'{fCOu!f +EBsTyK g"7>Ht}g\R8-?Tǡ@/:yh%ٷ[E'췌^c{{ qΊog-`]._`y%; QLȀg,@:#Tv4dXs *sF  .dO~yrWQ[)U%.C2bc9 0xt=5Bx \%@9N&!ԳOoNj z 8pte;o"N$`ڙMM,ȺәTE|kImr ׄA"-OQ El3Bd9Z*`8B7 A|lmtKTӯĻK/SKBџUi;q!CA^`?>׳&bYH R\H&^.=YJ z7qF+*鱰hĎWNIxMW!7Kʶ,Xb/=; 5o'칏 lQ+3ӓ~x9F9aDϏ{B-9l؉ 0%X4U rnnXST!# WA"o#z a_މm%y-&ׯCӖn֛>' LR:GB uAJq0&<ƭdd[S6GslaSjbPI^7"0p {"cAW<\4dC {#1kB2r=9#;\@"HvO$AayŇ u2s[<{RٖᷨX~/=ƹ_30kHs iE đYTurnsg_OՃո{z^=ɒ).ύSk )2uTy`{fQ{:P 9Ved,m=%G< 4uV~ј7U&*+ttE:QE7۔VW.DՙW`vşUDY4" 6趜.n}t%7V~Hڋzۂҗf>lir x`_*Vy2hR:m1 ̀㙺xWm{Pܓ+;lD옫n0VOkuF.~oϮ YCF~ kYRMU|P $$;3ם4hnLwKUdk00Is1f!\2x+_gC;a% Bj! xK"IrGABT!9nFDf(w&dUAwnȰb;ȎSz6=&Qa}ṹKjl2quZeBdDd4*( خ x'[͔W.V' 'hka|^=| veb?fƺ4"p|GڲOg {V}Day`0SwHSbG\#9Ǧ1]=?Cmi4%-VR!H ٓ}bx^ !v n(=# 2=X`xc [{l##gRȣVE=(P7SKl.^25(O=C.]*W0@Ue ,N4=-tvA;`_IS6Z~\"@ۻ_+,2jS]M\** 7t(2t:eұX:'ਹ?F U V\|^ݝS(A^ l+*"1=-LcSR7eO-N7oXvxb={P"|/gJWgQE +P{m oT[ݾ"d ˅/Cz7&Ft l8#(q,, $*egErndY`\׷y dȵZa w^+Z ѸG'xo9@@@, eZ9T8}8E n͸g/Ƥ.܉Tt/% P) %'uh:UPm\ULKjiFZfA oJSͽ.X|:IJƲO# )ћ.;ļ%Ưbo^nob3(r2c.gO8veLN971uCN0}?C9=~awJ4W7(!#z?ān>G>ZhmwO0i pWh׎^2JTlW8nSt{Υ}z}&`eA1$#s)G[ S!g#LU:C5Fn희pY_XԮf!F꼜+촊GP@`%i)Ӓڳ=ASte-sM. JѨA& ,ٗe^dSN- AHb`y):OK !ep$pl"ଦh1u CC}]ٔ.DHѦ=e4({XLoB4&oŵX>əW\ƈ~3yf΋YQގB~BHr n[RGpe-TMJR_x2;QJ@ 「UΕAJh^>o }l2g6OJklqgNv$!A/E˦Gd6[I↟}%WuBuk*(LiǠl9׻is /W㒺v`oy_vkv"=h%R.f5 T|RD1Cd,Dv1~)sD^zn b9X}M@hњvs#"Q `AlA/ؑ7|w7-/CTQ X(gՄd%LWTl6)!zD3ЂQ%Pș@ZXJՇ^RldQ$ Xeh5;k,2zc7eF`ERDmwO#gQYDr@g9pUߕ[Z'8IE.e,>IƑo( dÏS4P~3a/!::wנ{*ү$cӅٕsTeu?eG1~dHcH\Rwzs QZ6;) CUk 9={05.:.D}ǜ; -+n{Ê|} %BvZ Eaǒ2Hh^L1h2l'd0:6@]%EB8>ɺshOclq8^ (Dž> bUriۯ^XCCspGg}pv3zqosȠ$2>yodP;*Ekab?%{J>JH[҂*5`7܏nc;m>xEqDst7_G67X)T촜~|R}INYӴ%ZH9Q{\蹜ր5=Up"M+xLه^L>znIpPp]LtMJYFNoGSyAilꆐ٫IoKg ǁk(2}+rL^ 9b65/nnfRv`T L ín{_k'<)\ }8b[>7CSڌ˞A#`񪑒 ZUƪV]<ޛϣP9B%MPMzDpr0ya^}HDD@5GO|`Sl?Jͣan7WmC& |jh̚{3#VIӒ &I?S,9[CS:&d2^Tq]l-PJ16QULlu)  6 !В9ه.jp-; ֡(-@zdmodB-誳AjXo:;:3>m3EK٘%$$]]||f4%=\lIWZHDktH[ 38 284%/y3E`^eTlzE{ ~N{>+6 lkNE $ąpt:#~%տ"T.~Gh%%%G0ES3lLJz0= +7V[4PCsygD~zÂ/Q'ESqB‹Iaz}\UA'vĨ:сoG[/?)tvJ kl=:סDDKN[$Q ?TȆ}Njgp"TR1y2h09c~8víR%x:\!& !fґtFQ.u*d+#x ̋FK23u' C)Xƃ4uD|ȆI\ t;SDڼ`\0 J@"G N,NSZF8Wq)|6 /PjBL&zvT(ΑἀP;S##ZvDxhǗ/l8uVO8wЭ^R#@jmgc5-a~2Jq6dDO79;a`%٪2?H,P-,bGЌHuG:V`I3pRX TZp^dZxɛ Ot $$Yk3T|[b?^4=!yk?Y<h.委 R=Wd1S?N's/\2hfgUc5%>#Iw޳vR^QI7,y8\3?LH}hB*WÿKòS ^su(ǧ6lDPoQla7a"Dg:Av&S4w`J`޽T5:CCpaHh *s9_>B.h57?]i>&Ktf@ݦ0s e@J;QVMqdKX0BlƟ58QVC ~ 3͝p<sAE f>{ )'þhF6fX;n:Z;tڪGпG%FEE}ȋmg0!đtwPiZSx'=?,:Ji(pjh7=hִּTCߦ)ltvw SRO"Z[#Cws嚯{>X ,\_aoe_ 5;h+ 38G3"KY}aL n`+wW| n|GC? N<9Oن"" Z OLL[ԱrjHʈr?0@dyʱ:IF\Dz~~jS[C]O{uT#a@`p|ًt>9"<-OŹHCk#sb=1Ӽ:jEڰYQ A҄5 gq϶8G#b$%.,: i2WfB%#{#awY gV(`ۋqoVKʈŜd#6Pĝ?Q%)Kcm2|IHѡK,c'"x^ѫ7 kHH۠:w*NZs1[2zHPXHvrhjF#!qSezL"G6WEL2eɠS1B=S]H$iг9LRفt҇S~&m*-! . `66^vxݲuyYǝXFu~ MwJlbi:§ ֝&"vkT:},?V= M!6Ȕ 4 g'[ԇ ^L Vdceġ-lYUb؂(^6 `K*@%L<zW~ XMjzJyz_G4 f1\vR\pq[N4̭ R6×٪ Eo_ A ?WhKBzEv ,#`]2.d2$  B ޔ6j]:hmN4iy>Q@h<.<#R9 ^K2TZrAȣwc7q-0R a)&HiZ | {Țƌߪ&¿?^$\3⛚獗<ݡy>uHKf61zps!9("ɐȭ?—5?Ŭ-P 7Wi>.$OW嵲_SN5U)^Yb$]F;zm[͆f0F<6)2b:;Z qe;k@U/ƺzHfb4^1K43g(~ c,Ƈ&ga{.̌p8i;,t|xi8F%Y=>sY? ;Q51tB;m -K~Qnj1la2Kw-y^$<ųcu>m"Zhgn*`l;aIoQ`> N V4+ gpl5<HQ 7o^e&Hj7Sv356\2yWrϵ}P>Ԝ)rЎ~S̝=k:^A~h rMm= ۍղn(n8E!ʘPd[-9qN7D>\HQCi81t6=Σ^9_xXOeYc j12j 53J5 QYnx%P2݄E6gd9j*h|#nhMM&:OP$4|pTC%H"`o### aGV{P ae1<,T 9eu^-MSDzc#0!*x:х]óxV? X!=lU I9a4u > Uv3=׺F.胻B1~\ƞBɞ㹘ScQ@0q0>%>i G S:κa T3QU|dN 1[2i`mi%˺>ڻJAR ֚8'ֽEғ5hh{[Egr+*#ɢ!Ôtͣ *uHA˗Hk4gɩ[) P6F5K1e#yԊ$j1U_!]u y$ORU K Aah+75 + 'XF15R?ѶMeڪQ- MBJ/ЏהqCP˺BVIjUV\g:pߣ8x]StBjp-7knLJȔ>Yـ1V0^v&; ekXzvV7{vE:!>H2tb_KuMp t?@YvPE}T jp6\{P}XǛ͜ޯEY]Y?b nk<Jidɝb v1o0QN< C.]J{4eh D2yjSbG{DyaC["!aMCuG!*%Vh^Ρ$]:XX T 2f=rU5KJL7RJ6iԙLK~+>3nZ/;GcA wZ %C-Z]Hp VSL>sðby)}n҅A)]^8ZqpI7k `[(hit5ImA-uDÅ{+9.KB] [-HX, KTjEJ;<t 'bݷxL7 r&(}#ɶi^ڈvdD _ZB1[{*kg̞DbiiXV`]tl.O0b"z]::AR=7d#wF<8I&$ 4wSp/!) w&LulUn2ir煫h5k3ƅ VKT:$HS8.0_H,\ê.!jٌoeʖ1H'!~6>co5aViEb \>BÿaOC9=_xg\:|_ <2 r?UxrS:{r*O+^hha6y_Q4BzmZRQ$yfUZ3$4dvws*׷Cl],z(y-bؒ^ xVHNzE 88sFr-X>3CAq9z.z>kui)DͶ Eiøq)"C$( @: Q@DSq0pܠl\K6PC43maI|8Rh\Vڿ4ePcxۖlǛ"̴\nV +i1^@v Rl:oEs_ÙR)| `4EET[%1 >I :aO7e~,l u%_ٖ9%!c!%(m{)HZ " MO MVɨ!d{BJh:p@M*$6q*@aKY=А]#Ϟ>͑6-7Mb3<'/c073`\[#NLq5>1+V I ESDۇz4Il1uT9‚xQ؃ў(A<+Gdqh2sႆ{ٺtw}reht 8d^>l}I uٵ.J9ҤjHT[bZB =1HDNXKeQ]B}2x!!)ZÓI;+<k'n_?/u5 mG7a>$!&`<_mSMV_aIw5\ _:e K|jy:[hZgRX^KUErRAN4d;l*΃0BX3ECt(cu]/#2i?{d@d{‰*"Ӊ3gZ#<{&~$ڰC+XYx  Xup._`륋&eLv( P#ڝ7 G T2Ӂgoks} i E+s{Vݖ,SpBe5|'wPp =ݿ$,}ȰQ8fP- 1}0z epc3ïAvZ8bU|U:xߥh^;G6QoWEX [*ծIrJ#M$ܺ UO3Bm엺 x#<Қ[w;4V1o@ :uE0'5L&*Sޓ\)ywL|!H芙MYzz$|dV|~|>0OŐv?eB]i:dG,;>ϻ 8  dq^zwkOgiM99f:¯МPǡM!%7CU$qYP_^7Y_Y)}$N.|jȇUE._4ȺG{#Q/L [Qd$b.3yULkJZ0׏@-]]F0|T9*9;1)5?d]\}8m iL8,bg㚳z^#:(32-d ;z d[7irq ?.{Um LaүR  E{^k* B9Jh**vSܞTE ΰ>B&>=jr+a7g%̓dlukI"j[Q0 WiՍWS?آ)[†d}t-B] T0vV U4co% {Ta X!>[/$MQFiG/RnSTk߬i?2QwK1XAjzQa**YwDuzSmYBt%㹣HG0M-q #opq@^8w'YTz<eT@G/mkFf.|dL{B|d 0#NyYŚt,]3_*p5M1Dcr %_ 3Tb&>Z~yS onc{%$8fZNn>d7Qe T" Sfz,Bra=kJH>tM:+ s)8@|L6ƭ0 A!Icrʣ2'*`R[mR{a`}P5o#T60:.S@AtDWIM+Qg6cޥFr?8֍I~j9H"@Z}BXҹ;g|BQhV`N e17"$ c"6SÒ"U׵&;|s7t '&ϙހ[`NIʬ濙gؑg?f"MQ0xs ~؋CNû4P#i$jI.9S*E7߽^MĘB'_kNxLUy bш$NS63b|Ah mVDv'bq5b栃3[?lX#])v6M\6tF\; J·SLzIB|'[ H!B"!t-#P_Zg92Μ] %bh1_@ϛS@AYN .bB7db笒7;bŔ~FdNx;*Kd786ǾH j:('v A%+sU-$Rzg(H-P; }iQ3M^;[N"_& j&kI$Xa#Z(cTdS-}jv`̣ů&֤Q][:H0$Uhg']^S- ͳ BğV&ۛ>;N6hvKuLzn}amXڸݘxȭωÖC kv(PF~ȌW=dF1Ǒ}7 +n+TD?g =k9.?>WU륁00c1sJ¢V/'X ;.]ccu˭`=5mj9gAH5;wI8 ڷ·+/&p4 +A拏#޵gNX[*מl%* >Q9akrGJ%"$0dǖ^Z\9DMOJ)zcj){n:ɝ%e|jxsZPk ׼N~X7եm&6cҤM5;i|ePcۭȐPa'u5Kg*//=WV;7&P* +DoI2$j[q|cLDJxQ~?ꊅ/.v9'% *?"9 3нCiVړKSP=Ca95<iSjxz@ '0B)&sA~AⳞo@UF-O\k%@ayN˟*BN㎗X^M˧k/@v@ɡQZqQJz79e$3fͷY,T6Kaou¨xޭ0r%[*0CY"Xd+e1@%g9̛huD(A#r-绥WNN;(DZ,C3G*1k. (&jAi?|$$Sa%}&`EJ CXM]k ª["@4c/AwOA~4tK=H} ViWb4TdP#zL/?-TpH('VXgٹ]-sfZA˜3MMQ){2ᢸ^̥ X%R\OalU@ȁ04Ԉ޳W4mĩ*!'B6Gڥ$q4l= c\7[=3H4xM/Ȫ>s\=qY3IL> F^0pπ,L' Ui䇚#|X({[ <%͉3og=&z CX2v{#1$f Z& ".*X5@y4#\dacRmn3FmCفiyX[nrxV:q@m0 (s1u~T]\Hym1++Y+/ g&i 6 ‘! x/ˍ>-\o>]t 9k%K@?ԻeT1 Eބ6mrL`4:p݋P)P;ogl%k?vy jAey(Lb9׺C>0zSoK90L%V83'el1VE'1esW5ڮZ ) ZF9nC03=Of޷ͳ?CIm YZ