pki-base-java-10.5.9-13.el7_6$>^zQ>7L?<d  D          % ,' '  '  d'  '  g' P'''r'0@(38<9:GG8'H'Ip'XؘY؜\ج']H'^bcd2e7f:l<tT'u'vތw'xߜ'8Cpki-base-java10.5.913.el7_6Certificate System - Java FrameworkThe PKI Framework contains the common and client libraries and utilities written in Java. This package is a part of the PKI Core used by the Certificate System. This package is a part of the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.\.x86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem System Environment/Basehttp://pki.fedoraproject.org/linuxnoarch Pb !& #-+,).*)&##"!81;8+70#%A큤A큤A\.\.\.\.\.|[!T[!T\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|104e693105a0f33323a500b28140eb73edbddc312c59aff2af732bfcbe4c468394551476c6e1669c47fcfc7410317b2cd505bfe5c3ecefb1e74fecebcf90f871b2df657063377311c021e0fd7006b3ab5ad93e365860dc3ecf68ba0078a90481fdd8d5ef0c8813c633e77997d6dbe23557a5112937962d5ab7b1053de866027b643b71cec56efdc737a20687bb05ccbba40c3481b2c0e100ccf53331e0fba620/usr/share/java/commons-cli.jar/usr/share/java/commons-codec.jar/usr/share/java/commons-httpclient.jar/usr/share/java/commons-io.jar/usr/share/java/commons-lang.jar/usr/share/java/commons-logging.jar/usr/share/java/httpcomponents/httpclient.jar/usr/share/java/httpcomponents/httpcore.jar/usr/share/java/jackson/jackson-core-asl.jar/usr/share/java/jackson/jackson-jaxrs.jar/usr/share/java/jackson/jackson-mapper-asl.jar/usr/share/java/jackson/jackson-mrbean.jar/usr/share/java/jackson/jackson-smile.jar/usr/share/java/jackson/jackson-xc.jar/usr/share/java/jaxb-api.jar/usr/lib/java/jss4.jar/usr/share/java/ldapjdk.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/java/pki/pki-tools.jar/usr/share/java/resteasy-base/resteasy-atom-provider.jar/usr/share/java/resteasy-base/resteasy-client.jar/usr/share/java/resteasy-base/resteasy-jackson-provider.jar/usr/share/java/resteasy-base/resteasy-jaxb-provider.jar/usr/share/java/resteasy-base/jaxrs-api.jar/usr/share/java/resteasy-base/resteasy-jaxrs-jandex.jar/usr/share/java/resteasy-base/resteasy-jaxrs.jar/usr/share/java/servlet.jar/usr/share/java/slf4j/slf4j-api.jar/usr/share/java/slf4j/slf4j-jdk14.jarrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.9-13.el7_6.src.rpmpki-base-java      apache-commons-cliapache-commons-codecapache-commons-ioapache-commons-langapache-commons-loggingjakarta-commons-httpclientjava-1.8.0-openjdk-headlessjavassistjpackage-utilsjssldapjdkpki-baseresteasy-base-atom-providerresteasy-base-clientresteasy-base-jackson-providerresteasy-base-jaxb-providerresteasy-base-jaxrsresteasy-base-jaxrs-apirpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)slf4jxalan-j2xerces-j2xml-commons-apisxml-commons-resolverrpmlib(PayloadIsXz)0:1.7.5-104.4.4-54.19-510.5.9-13.el7_63.0.6-13.0.6-13.0.6-13.0.6-13.0.6-13.0.6-13.0.4-14.6.0-14.0-15.2-14.11.3\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'10.5.9-13.el7_6pkipki-certsrv.jarpki-cmsutil.jarpki-nsutil.jarjavaCACertClientExample.javaCAClientExample.javalibcommons-cli.jarcommons-codec.jarcommons-httpclient.jarcommons-io.jarcommons-lang.jarcommons-logging.jarhttpclient.jarhttpcore.jarjackson-core-asl.jarjackson-jaxrs.jarjackson-mapper-asl.jarjackson-mrbean.jarjackson-smile.jarjackson-xc.jarjaxb-api.jarjss4.jarldapjdk.jarpki-certsrv.jarpki-cmsutil.jarpki-nsutil.jarpki-tools.jarresteasy-atom-provider.jarresteasy-client.jarresteasy-jackson-provider.jarresteasy-jaxb-provider.jarresteasy-jaxrs-api.jarresteasy-jaxrs-jandex.jarresteasy-jaxrs.jarservlet.jarslf4j-api.jarslf4j-jdk14.jar/usr/share/java//usr/share/java/pki//usr/share/pki/examples//usr/share/pki/examples/java//usr/share/pki//usr/share/pki/lib/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnudirectoryASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)C source, ASCII text?7zXZ !#,]"k%vzIRG6"il'u fl/)57nVUz&C۫C.CsSZ<(]? zD5.w%$TXzŖ:҅# -?_,эLZ?1>7F?-Qm.tT $>w5W190g䤽ewңƾ񲏏|Br\*:ޔ><\aJB$4m<9ѬFp\Xu_n|qa~N?VdsvvTvk&ula\ &φ?3)Bz#N:ʗ6<:vPo96{_Ñ1079 J[9h9Ӯ C7A"р..\юve#Xzti%JJ[6 @߰eLw) h5;:*bJİ@18^Y?ynUݗBBdk|̪aA1PLi\ sY棳 "ϩ'[nTdH)aW&N=#~FrNE!eV'_Q.JCџkfNG?enW LɄ֦``<~Z9ŀ{$ 8KR_WxXDXd@7WM!h *Powihud$ۯD**V8{%#2#?W¿z|nDXO:_&{$J/ y 0b4hɲZ «6NGc A]Hm(/`UG7Oq g5Bu@UdkO ?#z>Y&a7:P]մa_E! ; cHOOJ@_iM |rH /^ 5]7..Y*H)aսAjn|)D9=,6y7!? $3,g_mqؖ=c, YL_o4Ʉ0Jh3ׂ m _l9#jAy-+ 9Ss*B^˅T %5cW ZaNOSa$X%;g.\fLf^O@>|.H@1i3ʢ wrY: ;gCs@JN\* \08>|f!\N)2  ʼ,YarM~vߞk5?9RQ"V" k@(xeb s=@Wq-b#Z0CZeZg߇=V* pH 3f,l4xx֋P;d_[t|_<8IRHy%/w7K}iUdJ4XG:Z ˜r ׅ0e[zQ!M|;:fsAU@52(LjWck {^lzE03ɝbEȭ@3]ȋts61M}0U=TUT00%o/ti^s曚\IBWӥ>ǁ F`+@I^J_Rd?1֛MzNe-|;;n7 ?yJRtB#0mr ZG MRt9at˴lDCDZR1, UBp0:U ( w$Ãb$ Oa?ݜ1蘱b$(IxiX ߺEE2IcR\&X4wc_S޶ɴA:A/ +Znfg_2z'rkޠ fZlQ٤bd0[֑S[RcQ@GS7V#`18iŅ%t ^Db_33W+$թa'tFD2lfk!E^vŻ%1㑹Cwg+!xzyUhgWI7ye[1?[z x軷)SPNԁFJ%@f]8SQm^ZVi 6;$_ 7!_->:dKYw,HPD Vf~'95 s;͊(Rܠ_/"$_R|{wvB%⩔tzdc !c&/ӱޜ#1-+-|'gԖ rޥ R6jєĭD8#Pʳ>ii! X_fI aՒ_L&0ujp#LQ+ iN\o[&%QfiSvUF4~.w1z8d5&:^/ZQ$hb)[n~`W^JB1*ġk/ ٖ?qWh`@Q 0|@3> ] vĚbCw>9̃eo Do1#TMQӀ %ZnsQbؙ p&1(`],wcqtTB[*\=JkTń!A=i֍eTZ FEM>r 'Ra_w`|l- j@`r{H>UzyԝRYL.Zf3zaUml !oO^KZڍٗjVdvjcymE-I={rqMj#_aze1Ƭ |f7RqKqVXK. 8`})d/7iEWyOgIcFѭx e{Ppv mx(3&ao.B U9qـnN wbk%.IChGZ8AѽNzՋf[MNdQD{Od`Rl0M(t[s*" pQynnW , P'p5Kwk7uj㑥ےaG>~Bi.>l4/ -!aPc~i(fikU3ψQ]6BY.qݢθsO\Tvy63EZ_H HUŎPz%aNw[!I ,<ﲵlQc϶*pDYq/sHQ- 4Tü[5r7@odN`zhTb `D4ۜh#lTMVfas;w6ů6p n Sn& %y()IAY+2Z98ޘ JB^|MϩrO6޺m>toΙ#[:8k 2"  FΧ'BМi'/gL>]DÎ /zztTc~o=aѻy$i+3V-kZJТ]AbQF;J{%U˿Xz%gKnК[{4AMUkKJY~V/K%t{ FAO!HcKVEfrU7)(Lob5!VUCϪaKsMK+ݗb7~%-} K- /^L@o$ uaCM,kȞY< )Մ80"h`CR mp^` FRc>_eT e kG.ĴU!sJuNذql1sJ>|u, jtV/0'J Px&K]~ b`',>/vR+eLt^1*>unƄ22#mn5Yu0מz'N^^=p*WAf [ XŚZ3;?pD2}53H_>$=t@)Qk8 )#Ea_~oo~xչI߮g9iF׼,`=BrBtJڅ+14LZ/IWݿs6fBc%,a4A_7րxLiAGeش~O{6X0 {r7l* relpP1z,9 z""F-{))+e~bInMԆ!eN'B {: *oy9np%RI~X˝ ϳK)_>vJҫS;u.[h|4WQ=o"lǵ< RjzkB?ྈOx@h>̖鐡6 ťT:)gիɗNY#sv݁yHDP0FWjS,cu3MmKC| u.z(<gT)o |"+X`!v xKS@Ngϓs xUdmF)N[{B"]ܜk Mхs\ ֢G="pu3<(׫q$V* -yV0aI!5 \<1mFd =Kso Fl4R qs<P# M~O>,.ڤ](*,hM}h V<)n,0K{*wƧ7U#z}BL']UӮssΩz0@ Pw6pk W'{ 1c`RUj~$;_Yst ~p 譚 X Ɛ:g%^Bᴗ{Bw˶6^2Yt=8:> ѤNPKNH[>E]2zniY|g! Wkƫ[)>&]"G4'PE *FVZtJS{6@"=-P%p'*՟3%My(g֍"T="s e>n̐AD4{ϡ\ [wWx* "[~iu[v,ro&VPl|Rru([͜_0dA@e3V ͪhu)LQD!~ζ( [o+ֆ zs!XR؞pe $fխ~ubror$߯Y}1iC[~hmGӯ)]R|Q=7,.8qu&o\Jr3+=|V̑\m wA0@-OzUZ{ s!j"IU>W| T1Wxk#6F}l"|rkFS_  ,L|nWwP#ռPuRN ҫ&iM߿kR9DF+ryHws.1+55jTsy*2tDZ9@,`#|" ic1(vpjn)qlzN0e<`5Wx,{^DrvvZmXk, |Aޛw1YۑC :UڥyvdVj(>[1E[xRq+ki6Q8P1&@* ,'QҪlg̕YZ?wfTMzԮ`T2[jTBNҥum]E#cR?D>/ldQRRɋPC|B~.ql>=@aA%:g/ie5q,r)G̢͆ifߊ`R~xRm{u/ȑA-X[-twjY1{ Pku_6=Azlɷ>6_m;'eĽc"H[B V=li(V!bn,J:oQm H g&`OR@&JjUvMJ,CC)22Sؙ7jrKBfݨFs8l*g&$}T6~(d43TBPEW x>ӑs4$~%SC}a2fTmc$Dz̈,#-2/qIGL{:bg&J,MZ_]_ym_8vQyw#W,?S?㦍1Z#~ rWK;/VMEJ9`.aLG ?>EKͭ˥T >$+2R.S9u/i?-o^db7|,M׽` VQv#׋<u >2T̤AqF^{v^5R8ͤn4jFטuh2d!\qi;2+YEDb(v2ɌڢD#hj @=q} 4Q8>sW {#)}֟#;,uvjZ6߼Ynqqc˨2zhPܡ. !yy{U"}_5v(%P|oϢ_fY~)0qTТGX>#s-Ԩ{ѬuN_jwWRfo fp7wO$.J/>M9-pYYICxACJӘN'l}רެm* X̾gvzCcȻW3 sW>zaC(XꌒGV=C+J0F[& 5*=)x/]!AuIǪ&,ƚT-J2bz&sNQsG?UbX$[~ 'C MhhɼG~=D7 -4{ $G9F(ET{T(:,<,?kD+q/CRV2o(jًZ~ $CSݝ$T0ܻv3KvRhUo$eݱK|jJ S 02}ߧ3 '>z벡al^>ĮLoy'_p]ր*7 p#g-iM.oF?CZ`8d4' ^"0w~K2LDMwcIJz%j'ϥ{b:=;$VN6w*M0(< D ,ƻ(Cj K ߗ[М{yɧ~AOG硷SaǣBT([VJ>v/ +dSqa b`> 2a==qOx/ lu-u$=B {49N>$BmsAGvIBوEVz`CD}Z;v6H^-u(Μ~ S {> ^"u˴h/xDOo" Pw/Sx`^p4I=  ,mߎN!0  򘙖jmMiY^w0 pp  eEsLGUw3xq8zz2B/ky!;w8;!:bWM?j$Dly>WXM{DŽ!C02\D|+Oۑm5FiS[9+@PQx:r9Qf-0]Tx.68% Z򤇗.SsZNAi豇| ߕc %llr^ָbinϼ߹#XA>6^wJ꺦ҹNep7υsCoG7҃4O-ӝ9 T╗æ#(ڮ`Zy<+U 3Jx8W z,K 䋈\5 amaq"yzybV Y#KZ߂(yltþ+ʣ*w{gD Դ{PV,Ӆh#%aӛֆ$nSo'Ge^T&SuP-ڐd^x'b̍CcH:a{=_ߗaoTOZ]l-FL3s tK8Zzc+! %I*5h8IcQ4] cPțRf5|wּm_ nX?vݍmpQT͐ wLVϗq?(a2&,N/W&o$0U%HQ u47''-tkJ@ %2:]Eg_|$թ$&X Eu٭3 08i"@"E)06IOb&- :c|̏E׵Nь2y0u].ƶݑkҝ]86`b!ni0?=W2ڋV!,N.2VGTJK"L}U _{?pι,WNd2#``  ~NMR2Ր^ml15]:ȈsdMJ.aT{15pW|1vm5-tgVyW}޼J(t|ψl6exZ"=+ P~M+UIy>rSHלO_X9[jn[ya5!8>JCNáVECk̼R,bGɩa󃮞3kp}zqgU84x?1!{̼_sAbˢIGi3Ռ Gyn7e~ Z":J1OGÖ^#cRWqVNb0Y2LHpҰpǠ؜yqrqN9.|B#䵯S/H$B et7GKӚҕtJ43/2N e쟥Y_\WHsz-p)iix\/a8Fh8=ITF ObXGcx]1Dpt 11n.]yJf?ܚ-9!t!U8 v P6L`vù¾RUܙ50)ePZJ=*kgzLu| C%Oջ]7P[(~p\aq*1 +Z`10%fwi c~Fڒ*Q<"#/p=~_%Zd j-PDBxk;5dlk,"n/.Ɔ9EAi SЉ#l ogv5BH¿_!!< Xkt> e P|ʝ?)4-i 3Riʯ\r_ά nh+SEBiFe_q j'*Gr'cC\t7$va_>Z +*@ O`Xv+v0O7Q[zҬqsX(K)ZG[]<Nj<0 @!(vg%wYtR" aމYx69a/Xx~c[*Dc(#0Ҁ[6 G3NNs}q{MC8Z9<J}XRy㥲,VC˒Ն=BFʹtR\'`,GYM@1( NF>a`ed4}q1H/ei Awʅ `]r$!ŽJ+^IXQUzE.Q\_Y@@,\[/3{ԋ V¢w]R_Wbm-Ъ:UYEѐyk cj4Mh[)ɬ%#^kT]V F520=FYgs*9dz">4n-YZ;=Ig•?y'QgCQ{x7``c'GWpjvC`1o1w_fC~ǩVO坹x|tNK8@ 7:}{=0iQ^X}`.;tg9p|}.)#J/0Җc)꾣B;czW*jw<@RYLģ ,Lw:RXˮVf4څLdj h"QjpW3#*»I\=xe.;`ze0tZekP})N$!"TXmT@0P⩉ϟ =6C}Ȟ fz xs;ߩ`%}ӿUփ .IQ(W3s΃"K{5*e޹$(ҁr5Npc<k3VG`YSMT'rH0iLNwՍfJ4zw6&TZ2A9[jr=ʼnaMלqh*\7M9 :]i'\UEѬPYjLz~`p iW8+XvE^被%?E2cL.nː/<e厝+]̈v?Q#h*ef?>+Kby{f}!MXM'KEh1zk +u̬\4eh´+)ދ˱-xŞq>q' jN ȕiLT)wZڳymGD>T o\~ $EL"1i-+77&"^(o? ަ̹USq᭑0ꛨׅi}<ŽMfֻKČ!ɟbƉMU}Y0LjI.sܶ4*+ދAyZi)r7QN 8IHv.L:ְh/M~瘰E3Zmݺ&Rfa~v&!"gM/\MG- {!j%83\Oe"C:x |++|EV8siF EôוRs, ~XWU^cfx1s2U= f!N-#VTzY4PGA_鵨 NA8ޒtz@P0Tʹs=̰ԧ_jnv@u\1? P ŢBAz;}İKJ*#UA&h.ѐwH' JYINǀ^ !U0 9 7'e uZ{_ŝMSɖpP5m@ĊS:i˛R K| )TeΒD{V۵Kg& Np_9$Le鍦 ,ѶUM,;%8ή^:Df|s1VFϜ9 VCZZٲbBd/aK3Q_S4l>Cϡۚ7O3;p. ՘eؤ:1٥5eͥf7_ݒIdX{}tWQG|L4ne`ŗ֫J+&M' ;sv1[]!Pn{ZZ:G%>6!mxDbSq2* fI3j  L*ẸTSGڷA~aDZe2@F%e)X:Qޭ8ʸDSҝ5  7h "/؇AG/bRjz]6K͘}MP C\?D.KJݸT$ < ^-jw-&HUyǛkY jRZi,B[ީC6ԫYكY" P2&DH3@S]ۀ,5(QMwGc(;·G|h T(.0G_~KPքHlo I)drπP1ށ3߮Wmm .KN El Wb\/',} ?H;d뙍ޫ:BJ!kM}'KIBVFŵP054atQ{i+9,޶%J&-F20+(#"-w'LppAˬ/C2E Tr(^dM@[Zrz楞!(QÛ+&.A&Y+gbpbWkDj>d.BQ]\N?7[?AO͌kY&_EǏV}~ ʼnu3<,E>7(%^k5q>cvFB_$!Vqxh٤>1د|Azf F7HH$P*}/+K-/oG$+ƅ!')PYW(EGt7UYvt,d:J7uO?p(+j5_:Jqx'We>^"a]?l=h0J3 Y˻Ή×֖ä哤R<.1Y0XMZ>豿BU $2h#׊FGU2 ?N~_bCClMڷ>1=:vPM(,b]5a'ʃP63O q]4x3]oϡaINbA8& *KNh` Dy, JGIv.Ml ȗ-bXS?&J(W9pw0LB ]R~^벆/Ϣ4?bQ,]&x7G9 t+ ^Ax^aXYo#Z_G*-O}/a@" Hqr`5(6n`n8m!K69x U@u^M7捓MV@1ՂM?ry'IV*p{IyOxA9({Y`lpk?޴91A]:: d-n#G0'5@l|!-aI[zp(=yevc8ҹG0d~wD1~TF[3b˽VY_6C/ 2E{E<:0wrJ23A2v9#|5 WZ27`V+s|9Curfbf|9QZ<׺B|+ˬԞP6mᖰuRp6H _%$++v CA+k" rs&*rl@.#?: = Eb]õAXq[}3GBBGTz 3A"(wz'tqɹwᷔmhۜ8YS)Q˘*lf:94]^81:z’K_ծED߷42l7-r7ٓQ? dnU' OgOw8WȻ{"P?2N1M1W;N Hy։( 1=[{)>zv@qϑ/K3Ap_&I[7dHFLax0"by1)aI3=u:1N^øK3G&sR*PMpX[d{&yH}UU\Yw+0[.[P h^FZ:H&0CiVF{1*)`Qs Jn^z.ˇ; k2Jb_8\4/h''x?wMV^IˌjQq`'ad_! C} r\%71k*NŦ=}9Dآ7^ !6b4FDnǣA>eUu9(m6ؿKc ŎaU WB23@><4zB<嘆ű_Rq}F[P۝5\`U+-}M ) z)ҟ+sh:=ڛeJxb.+ z%)'nCnա7(jPɟt"|&>`%ʼݼ~/ ;#1ᖺvŇ@Wvöt0`dyyU;jۧ‰}WpT؞͵jA8gD%Dg U a!Z8ֽ']v?+qnk(À*: δwNh;0ƎۜὝ) 6jC5H&\":k`XV>ZߒNhn0tKy퐡qPg[H^`YoCsڗN^v6@%cX2ݷdkJrmt?#(j sfnZ O?H돨 s@%61R F0\ts*)do╫zs'aO\U3m 6lSд\Uӆdyqd] CքI s&Pj=s^<^N7r'fvq I{ 0spÞ0:?K~pJ4N`n' ȵ6Ƣ3dzB HLi+A GYKG@sf񟟀HA~H; NIC3,Ea5pmf {Vd=$u1w}* p#/l̋J^JcvGnxޡlXnSvd; 5[V-BXn?A QӼZĀp'9%ڸg{ޞGh׈à$٩Q7p$cy&9)Iic0쩪cjN.hu+"7<'VH#,Ta ڔ"~m ПX.A$r)>*^W@'XGiKɒ^"B\=Zo`Ѹ7όl *ZJk0~?t|̆x\p_r";ɸ~fmfz煥#(F Rĸũ~|Z0W*'< ^ftUbv<ȕґ]*ܶC472$ ~L L^}AfV']yd?ލ:Ð( f{Q%~dD<aol4i%1Ye(ǫtm!D}F$5s>Tct6mi0ӉҝI8@T,I3te$!+]}?F}pmmb)gi` `p+qDSr" I5pl2r%G%M|wBbZj:ISp3oQ-\&H=;Z&C!s" !Fɟ*&YgoVRfNbq0. ~XDZPA~TJmH,dBi:)`?$},GѬD]?XXmH?d.L O8Q_Iɚ*IG `Trd)44r}:j]Cm{?;$Z,amX+@S+R>jh:F4{1$1v^%YlBcJEy_g~aRWk۝ixmH%9W8zL玙Jj Fy_;μUhiO-uYɯSX!RuUlōJvfQ_Q=]BԿQl}/]t#ٹq0MJ꧚٣P^mɚ@ y2'lڵf&׵ˊX0i 6&&gYyfa\Јv9BH\ףy! HgJ Ci;"G~@ ^~^#&u*&v;X=XJݶ <˽Uޤ; ;zlD6YZG'SÞkĂ"B;O g`&=B/ωi*\8WLRjq:Oe_/~re-H]QF-\yGX3#TLvBLp˷n̺AUQ=5ߨ!#z KA9bù mWYk25j4B'2@K Դ @x30W!6 |h;/`gm aF[JȱuCA3$1 :8Cz%hq&7v&K/8NDiv7!zj lŒu}Y-"-)Tf\c&w>n-r|aB ̻{f|2:(, ݐk> X"HƗ=wbl t!'YCsoRR֨ Fӷ{B/]7YWT n7ڇ"=Nq+9 (zρE{Q򪰈GnakI;Ê&Bw;KyUx.Wzw=+8jk'Ox"?#5ݯ",Ʌ,HF+s#iI 똏~f1a̐!fJM6Mw`B*5Wy9Ѩ`u5m!4 x^g>?.ToZ-WI#( 8ZwC^bv?cFcgnI2ǽJltJ5DH[B8>cfTim|f7a䢎xh5Ojf,SD \@ 3$eOEXnţvשtYxڳm2qoLCIGif^؝vyy>Ló!sWR}fYBGg}Chgq"F6VR'hw]CaLMW&aZv‑[1e.;l/QǕ ;E P~` ZhO򬹫uݬde^bI*S}RkM3kT6ռRr3Bbȹ8TzM=$Td@wWQDpZWdjx4 zKq8(R*4*cBc2m7r/~u(X49%@oםё5-6bw=J&ePQ98Du9e;k1'5s]L{'ʢjxreûL3@HU7e~#Zkۋx8kΙ O4\qp, PҢl8}Le!=cVII~x0E mէ1^`)Nn9"][\>̑<r6?mOȳ?7N^Qw~!UGؿDb3CGP摱 r9ьf\Y{m Z,u4QT| k۸]K"q02CBK9gКZUNBC֌/"±f>VVx f=we Fxw!8hҷq&۫ nyG#j@qQd&v#:&YkMh b25HaJ "k{|^6M{5|0[ALV)>>sX 4joqh.= +BQj0oԂ; }jp_ *jF :f},,rÞ݉J}Y*KՊ;=7G8 [EaEL6}%cCiᥰ =F;۫gWS8^_}Zo]$ZsKN"5iC%Kĸua |OnVm(Ø:XY%}]?o;9/.eutβ~>8t b ̈́k .\)~*9aT|b•N}oÖ&HLoO ʿAWV#W=oNlk>_EɖKmkM кflZw$;'A]|X<êlc9)X%=^K=\gz2--]C6̝G'%FʟsW+GDE0Ƶ@> /; r|~Nj8."}@<'tܷ|Ь+m0ӢL'Tiy g-A,)ږww#'1K@峰98E!!I`JR1ב/(xƋ lxЌVmX+[Q}`*o{Lu% vꄽvŗf~Y/QJ\v^ʰl32oW>Ńmuz7֌aO,7c_5t@]4PRjJ2O|fM5ؔ- X&(8gj_6@eYE'|5;;q i[ŒI\w:zT?{̑۶q_RWR @BbvF5 2Z; U`tsqq' |Ac7(Շ>cԁGȷC%pۇ6O1fOS6 .+MTū=W`dR^j_V8|3*\;F8zqP`3LBiP{;!Jxy 4sC~+! 1pD >L?8#s/cpk 'zv#fz+ɝڦB9g@j4]H$}BIrvkKAŠi2m@9}ޟXIA"G֎IvSBe\C{Kvê"isxjߧ,9+Pxoqd*)rwFj&[C@/|f[l2EJNlB7n-,|F&qj@n&EwÓ|3+f׋K MҾ3,ߑ!"Q"ko*3e1ɛv|؜Uލ FCmxH;[rInϷRsLV]YEI:/vtN rSv ,f8/JzuΘ{΁ن3yOsù<;$ ; |9Gv'fEXnuq!xjmopS1}^a8tۯ|i%:äwJEJ9gx'o@%L'C[B=шytQdP7$Ȍx@QytŠ5If<>A Ò)7WM?)-Zq}IsU]ImJq/)`_M.?4}&TJS4.q#*R,z:bׂ< ޯ8͕t?7-PLJ J2R㺏Ȃ,=RZ(>k3tK#8sxLhF2Ai14 uy2M!v2ccaYczOK&d w<`4^8U˫+U i6mgKX6!WeG1ћqOn^%"mjyf BnѲa$v N݊'98y32w26,ffB=bZ$b+e!LzCiqPP7O^ כvGqWK_C/҆%nCO] i6+ª5rnD]00h-TDLd2id9e}0G6aߤ"{Rb'z](6y~ycMeJwṢ.Ie(T@*92+l}Ky'Y AQ+:hJTm%$e67 5td5C}؅Y;S_SDEXrWp6D KB[C5?[u}D7pb,=6熻(TrOW/RDIwX|yāGoDJ9@1lX9X ~ꑬF!q8x$m!W[!ɟIBiHḾAcq`pJV.mLBfhBj|鿢  a ULԼo’odmG92p)VHBIh˲ħX;}.EG`*d|"Hp y`{5P.}FiY?YTe8b7idF5v&JUCsޒ-isto&q3[ e=%s2Wz6őt ilFnp@Q v3Gx6ħ/͢F)%`70e-MaInIJɔL\Oab!y*5Kwܣ 8}Q}#7Fx (h}_A!\} \P9zVl C眒0s(Zw`ލ@;a ct/D)4B35D AW-%0ٺRo JDDO<-`.l&hZ| ౹+xBeRU9?r()8~}CW5$bV'šߘ7> c=x8M30$;#樗|yVS_^{ٙV^z$stqAs& Z:1i!&ş $BU#`\"<ƶ~M.ӅS5v,{W X W3-+-ӇW& Ќhk١+0yko:>e[)ZL a/R[y4[.d0@~\و574ThBgل#wN ڎ- a"I:<_$]R㥞C=_k~@r|ƈrs #rqs{ (\m8 :>i4wNJ{[S ƷuPHjjE 5rUF̭@3^A 1!-=-4]5@LBI{,x04xFKjƷ` 'XHr{ހtX.'$)Wil+[L0Mg#ۻ-v; drt)[)%?.RG!ѷ' agy¸.JԵ;~^a=ɑݐ` '4+IH|3 f9L/.ܩYZn~ӆ5'FDls@^n;X[vꆩT.sw]@.m=gp M;aI07|O87WU(\i?OqO=F=v N921̮:#BxU qVҢK0JFD)eEabߜ_2ɾ烺UV$|Wa6+5#D($i:P'ZGScR&$("geS=>4u}&P'M|fqE D^`e4D(pN[vqPAxynikgHi]3z5bzU (O)-a{xH1OΉx]ȗDFqӼd#rtb)QLIϰT47.͞G45> yнu5|'Π8ܸo]D,ӍlмG2ŷ# ԛƒxY^b&OVqXZA*銚dv{w\A:ɠq|XzqQG5]QNYj[h9`()Bz6MǨ3~u= \bI{4Zf{ڍs[sݕ#O7;WŘ,K-%Vp"P//O ?7_CG{Z`yb>7Fk]H5Y enP osZ^`6}4M[^To6S UXgYD!8ujSh]n `Ib`YUͼ6Su"Vj(<M݋G}b~B#{&!ƏQj诏zHa:Jm@%5ƎDQyB툥@aA920Ga7fm$)/HRJʨR 8G J*ʒ z7FWJdϾ.|3 86ِa),̯An(0|{(Ew~bN(;% W]eyLm rE#tǿn' @@.VFW)G Nlˮ2WjcV P:$T-1690e.^̪#V =U`/:tc\Xma mZ9[T3Ƣ\pE{Y ?=&Wdd=D,B]1Pb!~FeE k5ԪX0U9mӳԄ.qfjUT5 lf[dgS+n!8%~+x6{IHQȴiZ,WH~0 2Xq3+Ͻ!Xԇf"d1"/yLM4י`G'O˫=ni z 2Ё\8Fup:H0vrW-|)3{zA!ZC"bR} df Z.NKM!U!jdclCX"p}32vދ}nG b9*K͍O0zU+k5AwO)h9/ZBہ5=}$Oi;7=.ָEEh{Ke;ޔ|$ͬsgݍ[K88 <0} 1RM\TI (&u2goVWm*z+Lj.Kp)ꁿ%:` -|€ӟ$*cf*|: X=W`3X03/BɞuokZA8Oh/vZ-dfXUMK# e R|vHa R `L8OmcEJK3I^5]sH  ,ੁfqXn]U Oo3؋>i82< L)>ֆG @'p1Dd 9mnڳ`֞F7wvIs{V{UF-5ڎVN|w] 'c`2WRު Qd 3Omrxmwv=Mv2 dB#Tni"f h'3yxO|,F WUFɮ?=Üb+W1k 10YCC ~<&覢tc%J]?]-W$|^O8@\Xl!ګ'?,-tt"$~@H=1H8jhVn݀,UqT2a٣P.! 2_,V&'&B)O-Lߣ&S7;^<~$ȁAT-6=ѐcEjpt?=#1CuFxTuL|m@Bu&eN.*@C°\juedI"5mzeK_f.N3dUX BP n!>&ӯoB,._5G=a]c>'XT>Z6hmdM#XRH HQj /FzXq'f(cߨa.;~nc7%=W3񩟎5Z4ٲ%↽X;p*M/+IY8IiI2Ox1a+g>SZK<.:3܎HߧK~Gn2/"Q=+Ο3Bjiƅ+ZtEX%^'yk)P@i2K >O^ x g>6JOš-qI+@U2\2 Rr ;{ e~qfUH*7P:()|[9HӠ=ڕ:zYd3U+4GT5>jA'\fLjBaBY f!HifDӆ ZKɴ zD vhAz+R2Wm "ՔvJG E13Rv>sn^g4'zJFzM0T//̹AZHnL01.#>_/S< b8u0h eZ[Љ f %b t\GHppyGK\g,7!vDյx:ec9$t 8=, jX|KmRX!}'KD8M|2Q kJ`[@JӄiL~̮ XeBnBJȬ͆_ׯ2 %7ƏT5w7śl62 Peu"^0 ?3O d->yK ќ=W:r74*Zewk#MI?~vZO`!Ew8T6_MKkjt3fC#i}ӽ`'ɴxFO^st>iU38/M>]% oRPڌ7&kMH9vuCs&'oLfIŠ{# kߘpRo_(sJ[9z<$ef>rhcwC3 k֋4"h~*dNj^i Q϶A2I`21{p)*0hـїUM|VƣCKy2 ʅ앗gI ,P?ݿ&`OMAiC}eZK 2\M|9 eQZEGg C􆲒oneu73/BYtѨj0rc F,QiW\DS؆Һb I*W`Ţ 8^EL(p/9(JZG`A#Ts>I]u,8eoC w#W /lDH]k2+mȾQ ~" fȷlo#ڤlH\q3хh(?Ve"!қ TT9RjgVrQ2k{Cîg='`H\UX`eaI |:yfB Ú[_9G6i.mv>pÐ^q5aޮG}%#%8O#7L.XќB/k5WqIuhu`Vfۅnɿ'Σ!QzJOoT!x nW e|QDPj Pq;2QMaV׿/87U2$> xziXq.tf"]ƪŤ u͕YR77_STS_8x$(_UzlGiڃ+"X{b1Qs)Nƒ*Ϻ-(q}~jʙnc! 5-p8prڙb #*Pwv&!LSFpKz_\Y0_&Jp hx_< J&d-o:sjTa²_W:g#MfE65 2r`eЌ23gKL-/]Sݵ[mm!gowoN7i5_7ALm5P,hkGyj#O-9c9IMnњE eov_'&`et8$W\-Ӆr o>h%ěRqܑT(8kuƘx+]t/Y =4>KsNE);ml lL.%@`7R5>)ާXi3P@vj$l|環GY孫acg.HMjU}'' WvLDhNuDbb4zVۦ;M ڹw W]o>g|@t|#ΐ Q/wiƐqأ)4Әy;5'Wn2$Kui\v&]K4M&MloC t$Rg]Vt=}0^U%<~'g &bGs@Բr"JWـ+P>uYÊ,H!`ZVJzџ[g,0UXFX M&tA;N <.PP YjljG4Cphrb 0NH^G==(ǍG'YZGULgPLdJ^}$|30K,tfMHH~[e<ê`a)GɛdpZjm Aا Mx:p׼LM)*劗`lU.^ yfbӵ IgC0c~Xe)ۺo`m+^M"9axHHyt_,"RI-ȪhD4Fr&Q|oK Yhئpw_e>WB }m/v+X,+lo3X]Ny"۬zXߙH_PdS[]篡;e0R)X*s8WPR#=]t_v mH{85 O.PPg/fAx_n::`Y{kӭ;)9a"$M4hC?+S_%}K2".0xIcqv*WYrik{ffTWTf?XuG&d'Ac:05#}t`x ] .)\@]TJ[MYNaG]ه{Yaf#F>?@`Q!G"UC!_ gC>sN&u'齑A골! "Q~wBb1$y'@yBxgZ Yb̗"s !B*~6 1%iH}i/FK%zc]b@Xv+Uu!Qg"*D(v8yIEQ6mjbh1;rMgbG JWZhNMԅѳ'D a0%vƎU!*Oam+A\dUfNo-TF89`9e 8̾]b \'7eeYjޫ:Ɉ<^}=ܛA9g} q`}8*̘}mFHJ! oVkxrbZVY\yZ-Ki.`nh^B;DS뢙(n; 6[jTŶ. g35M`5cMsXeOvw$v~Q5X7isi׆ˬ5щfUv>Dzzwzr+#BH7f=S-CUҔ_vG@)>-:Ra.}G.*eL)o`puL%L].5huoYj/$uokqE?RzCPr(olL 'R=pjoȬ+bs,N;}rػ[j*|] oߟ$B`_Ѝ!J.@籽xG&HLUK ff~ X1ȎKAM r' KL/40<[ RgS %_ϱBk0a}W c…ꐳl6 kYITDx#Тx>M.kj6k!,bYE ߗbh&&G0V˝w+Q%DƗ7󒚣eUZ6-bbm@4K ̲w_#zUNfN|ny0d-!_)vaG\Rz%cg̅js>zO*TB>$~1[ _^6jnYiT@9}u>!DF4Mz+4OkLSӛR 搐Wt~~8$D$EŦ?Qɴ+hgoxpėU%gη֝aRS_{$' := 96Ø\ɚ 7Q}zA 5ށ:0\^;YcgnKP !mT'LVIDe]9[$ˉQ_{  LJ?s`_ 1"MF> 9OIƔ-d m+=!_2E+e 5oif但# ŝQ]S*9;3FA"ڸK:-'"]PS~4hd\S|vu 3ƵFSzC[>W1b;V$D(P䏿׽up }CHut!\X s2"!l[5,o7ꢾp?u*xjSæljrܑ5<'C'{"cօᘬ!3OFʙ c :RBqRyuT64g(PDF MPMx!Jb{vH_,]el `$N&}^6JV4l)G3^΃)͛ǒ3f h 0O _J]lTU6pTU@$3e q.{4c&ԠPGeE3iA~?cT8c=ɃS' H/OcւfT'Ї-X.-0T!@ý`b>8=+$ Ԣ^ԑ4+* A즤˂γ4ùPR[M˟d E’q̇?r n;aLi1ٛiL9ں!&Ϗ*ӼLȩr2_cJbo&q!YPa]?鸪q$uʕk=\stwk )%L&ċȚ4/]!J}Y'HLAmHzy~9 ]eO*+_R8F<(B.$bF۫no,'KZH@u =A}Y d̅c,-xEVOpNIufIliF䴹q]^FT:q:࠯/A(~܋4F,nAB' Z{N%[F$d]|4Ys'4s2Z[Xc x65]8v@H\ёypPf2JA_ձiڪP'y;0aҀ(:F7K4;..lܲTar8cI-fJ,{9(wռÎh:dHCȑp_ZH琊zffǫfiufRh_ {P: _VtEww G}Rk_7ac>}5QJl5tR&dfc3i1J %S5gG(x xNUJJTaH:w!~ìދRdqQ/N0%Ȉ!<;]r#΄Ars/$s؂)2e88+l⤦L~X㼐U뭞cWҝvV ” EXNzǑg *.]&YQS|a|Yq1J$6*x,<=iOV|CÛ?evk}c pvYqw')G͘%JY\n'İDR|G`zTNh5"xpe)!Y!AB$b{| 6쐈O"nm\Lܣb_Rvڸ[.T36Ke)£(溙Z31C_ He2A SiZ~hA@;!s\(??wfʾY-=hL! ЄlOl ņl @6t[qtAYנ$¬}̎cL,?֗sjm)xQd:%b?jD;% F%`2tn]W(qRj%[iB'k{@lz9WaԏU<'}Qs`?HFOt.e, tlkqvG#^ز+ [5KMIk ;Y׌.hZ'H/|YފJ0?Ю0#6klĮ)l4AӮje Yq5F)^Pu-YƱΖd\FqXɟn^`wc+Ю5QsFD0B3ȅo;t4}0j>Jy%Ú,?FD=.7YLO4뚼?vsb^ FNJe#3@Yx ᧙)ZG5 .ݵd=~s$xwn&\u&8EVu)X9]Rf.f\Zcom'r;j5'΀&kE,H~VyoV:'\Sv hoAXh2vʎ8.N,Ir4dvkV(nfhu&4þf,N.篐w^yYVN̤6gL:Vh_ >:{ ^/{4V 'Zh:?,&E`ȫ&Dt^:4zjfr}pE4: {ǾcU>Y" xE~5dn,Տ7(r!{K[F \;rK~!MqYn_fD+Ns1$L<ރ%I,ɤ109L Y ̋ݯ5i1ZMAxirt)p8N E`Ʒ%@+r Հ>[mra~vC< ޮOYKlҜ4uNޭ>AםJD2[t$)}_&d4P+iz*N qPq}z;bxJ!‡4: dvaEBء҉LL//:D1|`DK'= QOSv [Yg|gF `b? @xXNݠ?'-TPtY:/ o.RVCt:+Ѫ6r,bmKi@ˍ{Xcqf@65Yϙhʶ$ ECd 9=Ko^W88$|r2~Z v֩ s|G_*jlO^%ɄOCsƟu#m5aAOR&` ,"܁{Ѥ\< 8GM^;;4B*ЅNٜnXVҼrOHBBpj pK 5@xj ᑨ95<}1@Nҩ2@L$8-]X4mA릾ջ/+LX< !C0_s;Om[2qv:kY/N+)f@ky&K0TFOZmXUvnQ:riUnUc9 Y_܄j7TGL= {&=)^gw&5Ƃ1(p+8o"'+a%X8lo˸g:Bh\][`2x*}] > s[o CeXjsS7Yt R삙H @؁ʚ{G,!Se hIwJ7/Ebo5ygF$Qv| u_T|(#32nR~'ќ=D {; ?}JȥʔjUYbJԿu+q|\L`BR:P]K320+E_.Lpa<I܉^d0K^j$;U8! 1 dE 0ņ+)WD +힋a\S(U]kHR0WDפxg[Ψ!#%F5H 6'zEXVi6$k/,^P(% |z{R lxׂpvIJQ r{JdVW+aqu5jWTK?2SYr[>>zߣMV{7b0E$RNEgb.udo{*  Muìp5\hݘ5gӻL6i;Q41U(}`Fw *a{}f*/"W)wSB;D潩\_T[YN+i٧YY:dE!Ě]2c0nmt9N]+Dꦙ3FwkYC>ST4Stۀzq9bjKU/(RZoy hl]=C,ر)CN_eȿ\Z`k m:v!y.B1]љF**Nb$1jT8g# ؒJR @k.$ F^YPOjYb(}6>L ӽQ^/. 2 a2oa .{<?= d6՗ʐE qua|j zYoQ@GoPe6&EC H@eM>Nl|{R`#N,MtmOa[g٩ nˋ:؊ C [#ikQȞ5g$$R,Ꝃ.ތ6fQK@Vs׾G;Lp`a72SF/M];9ݱ?Cҍ$m9k}Pצl)IǒX o%Af6Ik<|Z$/׉(Y}hdٲ1E"a Q26?Kh}PCFG(GJO߬^R*FO\At;[֪S]jvt~b#_-QKk$\uD:]p;i5>9(Џ1=I%%[ECS{g7!y4aqW:+fC zƝ6.ĺWD \K:6V,}70w$lB.aĹ\4ty͈:CmBC2AIbC Y+sP)eW )?"]"mjK~ hsٛӴMPEr3q3v5f`Z;0ftbط3w5,ldVWg L5R4HY,>^ЕR׀ ؜?7{>yHlDžиqh>u&s&f?HRh *p3 @HV7A j15`[?ZJ:6px}7xY:N@RcǾ86vH03\r0pg'P,3i΂~{HF7{p2 1x3zIƑ\4ģd*m 3bL~ESm+<[.Z:"*g ^_KJwbjШ4KM1ȼx& Copxr7u痩j+S[Ә0yR r⪬ T5p}@u77Epx{,NgJhwk]h 6r{S254q׿wL5]K{9>wRa_x7WM9׶bvA@4_pt UkUPhG)Q sn6 rTK=HZ}W?Bn6ʻRhqA(lVs앍뫲D[-qh/'91@TЬ^Z\V|LTԏdS 6.(QUX{AXpsj*XEuq9f4BcMw!X0[D9@JΞV5Uc?]wFE9b|۠)=X7_p\Mv/msNw6e=y%?Kʞ MݸLYzh;V?N2朚w.GWhȏz{%-Ň !i Bk*2MJ:  ǴaN6Y0`<VT-EE";v#(3Rwm_1PGB!y;?O57BM*;Ն\0uD_`@ū|6vͻ$5|ׄ{WחPV01tVʱYO(/V7;IX1^Bkt?v唣AHIB^c-?|5ڽQ7rR!ffQs%,χ Z"UL[ bkz4Dwx_I/Cl vy#錶2 AΨy]=29Lg1[*5~vp.*-Q/|{Ū!D.DaHnI^hfkDOTdNlD,vV6qb2h^Ǝp_fx٢>gW dq. 0JPzyN'+ <\(s^jvyg[0l(jv1YYܑD4g,s!yzEa%]20#)j,JsVͮ+6Mm;XgNdˍ'zS j=C0.lh<Y3xuf[9{ŝJ!c C<%X|tM7ddƏծ9t@ގ}. @P!Vm"MvG>,@gV6u<@-C Bc}FIL]՚'og>h]mrԦvnHyV^=^[&(UyPca/ ZZ'KiUORLH[E 6[ZY?zw|L5IYb ܫB'3ӆ:A,:*-0_P!C]'@n~O뽕@j D̟N0KώΘnhZA!/vP #I yͻ cl3~mj959ףҡns1.Aj4_+>60dGj$rtrb ͑nMPqaQN̩jnU ԟEOA_ Sli&7LRٮJR|htDbvYjCm@#/7񧦛Z0ĵ9qkG)%c "K5RFqkTp_ֻ&~!R2w]6uڨB=KFz3g8]N6,yW,k#[I-V.5%6uq8Ey!k|qx){P\#DLJj]ٴbao& œ8UKz%}%޼GbD=*˝ЋLNvdMk+}OV?pbW 6Oxa 9%# M!ƱݶC9B*Lv愫CC8'`vf<-/ӈ/ӿC8#c#M\mDc!)LdMge!ҒW];1rCIRoWngE8E*w`%:qpU60]FJԄ<89d!vU"Dω Xcbޞ~5ڎ*AXm]ksr98lO1τ;߶=kcL JnʘmыQ߁}wE7_:=zvwy*T Vu^0lb|CI8T׳>3˥ri|Ac <'ו'yS VzDul2Kc GtRܔ,+M Jo> HE O RP}|AkDt4a*4 # qwedZ֔6q xydC4+'vI놎VQ=l I*h*cݿf,QC /;A:`C3R ""(i YxԼmu=tDp3 U8DW|&ˈV8 )!ā[cI--Oȝja7 &C6zu0;7%)z䰫W'0{;Q֪67U @sـ%_7I4o@j)+X#Jf&6Fhڞ\w}"g)O#%Y'S`ubqO rHc=Uۆ(?A/2zi_&yl݄{e=%DZ, #^F4@aD{{jt!'O];oxɝ4 t1yH%0P723-,'%>c"[.MM\c7. kqĆ`θZb󹯠&>!Cf{pg"уZ] '\j+1d3sܷibD:1DeI& &~*;9xϢnݵZiүMy g`zj}͟^+gKPf[xu,)zfgsuṊ%Yp| hf摊3|Ea4Uz}fY?L0ZR;BĞ8mk92*fO\ScTm'o)e- IAT2sU$[ 8A""r+) 9tp8ųPk. M;BBT.~[B<V|䷉C=F-sA. 3GKD,KĤTAd7Ý *j* Ӹi^h E+X-ڂ4Eo XDP@MƆ 1됩'SsxդǗ7SI7rE;m򷻆m2ZABX{<p̫l!gpny0[Vu׸$7@?ڵ8Ψx@ KCuh֮ʗ)Hp 9;@ 6ο3/hX3sHNdq. r1<`9vR "t@lT/qa[3= A^::z~ImcOχzVK>y9ci |ג⍱iޥK½>+HʆUIżn {TfA5u:z wHPV95s=~L4_pȼ9@z%IR"&A⭷1LBJV9ns>KX8 ?&N`%P7S"<=0xObQtEMXQ#b_"ir{>z&CY"InX+Ǘn,0l|fYR6yamD?Q T䙢=ZL;4 O'5'T@Cz}Jpb!' \%>)ae UȐ줳D L<9pLO|%`ګZ誘C LN&GIC:-"VeQ{4nA\`e[n'Rv"njϐFՔIFǝ~͖9n3FPeyHI,k]eJs [u9x 84++ Ӥ_KR⒣Lt_Hz݆-?(sT&&,BK6B!Cb_f0^M -z ibj'RGhr߬]E=RmC> 3vwxW>gu|r^aǀ%hYko6%2x jv5(8-3k,RQ("|O'av&Ş9j1NQ.,PrijrP˜P[rι#Ҳ^)[]uu"ᚘy1 Y TY8>ʉX:PZFli msjQR<7p \˰@*Ɂ>ŕjd Wվ!=GG18jNG:V ֔$["$v]ғC+?Fδo_EDl';"csخ?ר]ݙIJqɢVOMO<Y_rpGYA ZG +|9JTaI?Qś}F!( fFԩ4>6Mifb3v%?Ҳ (i[i`=zxv;Ml~ޏ.YRۆCs 3Ww{0tS8"ӝkto&(KY*)s<(אInhƽQ:<ޫ A\Ń|:Uy( K!`]r^䀑א#hcFjTW.UD<҇&s'så?,%|'>gUQh1&|¡_Nsӟ㴽D|ʹ!${<Ӽh`z# `їe?v$"ɋJ}a}Sx0Pa *"7 ]u׎0ZE$Kgga9Gc>yEhI~+Tj'{pCQ@?E'Kh/\=>4 \&^;ܾޥ[09 Pu lu80,aXTxPuu6.fH7,0tز^;9f?bESi^M#{$Q }"68"ýSڲQ_S_Yܭ#jPEȔh]>3i$u \gKSS~4sdWx)b{ȴ@*zg9&0워TCėqs'$Haiɪ4 ӢG N/TXA\ SjIwEAVw,-Ƀ6x aLOh NpCЄHH{dRiXT^]Q U_jQ}D3VTk|Mtyuyu8E) 4xꜗkVο鯅Qai .wOy'V9QT p2 _?i}euf%$s$ᩌ}$xŢ_SS4SmH--Y'C r=r(j}{(EԯnBQBA9a,T/)hb&回 o9 xg݆p/i.AJWL/D._@pG׵qYfpguwo J?l*B{R|8G]f-AFBPjT@#Z !!/p(/zbNWSsY]^ɲ>ԍKcL`\_e]:_sf z}TY'.[]W1Y0@ 1髓;G/sj[ty73oZe-\tPJqa;]^zCHlٛl>V:fԸf4V~WRy^:0wvQu'[8XJ#M6YQhGw:[LKۚyB .'ʸ/=$*O&+k܍2Y;V(W] {b|W@|zV?f(bfV9Nqc2ۼS_ 7`A8pj)-~S֊r(F\wI (g?6`ED]1׮R?e)25nl";@\f<-fp'di%$et7V) n~O"U6.{F UI 94kkYX=n fW\b%3p%䱠( 8pվ{a5uB/?lk8Fd`٢p#7̝ ? "ƞ?Eqmz/ ehY ɵ9F*Khii&l/nf(g7c2_z20~JUl@J48l%w' &~a^Gt8ܽZoe)8a9C-p:5hvY`TBܕ6 R sfmq_ t*5@mvlIP"CcU[B pTi~/E 4 C̀$NKT䷀@klBɧC>JXCqTHL%Hd 42 ˏ)JG|懪&~k7(keU)$u.ndxn0h$5pW2>s&:C֔G#&f{Z/"j{-ϸB"TcYM(tC}{Gԧү>@/ ѽ{ۚAС W K, Vc۫ݠ3t\-O޷|!4#"[0U*/[`e5HkbR U 0~k.0e:TG@d]!H> xd)Lڴ xTܲY&D'~0tw@.*YډݴfP1&VsAT T ^"ZRЁD@C8W!Q y5-óUQO@݆xioŐo_vYXxtVe;_ *M H=\%Ӓ9pA޶=J60TP "HƗ&¬h*5``"X| NNJ0VD ӊEm H,[vv^1^Wfr{>SnO*!mdV?/I1JJnSn_u*:[j7 1d8; u_FPEoqSĩF7sΘD>'-^=$mBRkGzd;B:Ǵ`rW a(K'O/:>)^iTmzJR|%AY={Q*ڪ # stoi"yLlv%5Cv髊#k&zOlw̴vޒIR~hղZ ,$9u}fp99FIQ6u VSW[{N+]|@R0~ <]""8(ZRHAK-aT| \!\"'o"@sX@kR,b;2Vj HJjFãC$+~< +8D`eCle2hP/t6pt ݢs$ ˇξɐ7Q3,G9Xy*H}߂8ZOV> ԛ~Zl/Pݪ,Z̍9,pC"3_QZ7Ο i0G7,8K.|tmy}oƲgR+ugQhvAҬn'8ͨXSnq͞?N?H&,Ӎ Ʀ au#0` >!֬@GJ DpqFڤ#E,+- \wR'bjﰠ<&$:oBu´ԑdklJ1w#'HP;~BVx ҃3.[W2X0uyN ]N14vwW/J-K]1w 5U?ي/usjX9QbDi"rsHĢzs_@1$aEK+l-k^1DP )6V^쨀1-c4 ƀQ0v U6di~\M/*\wAIos+ЃgɶjARvp zgUEثOVZ,Kس*-Z/sxY~$U2NG}}hOJ}uJ0)F+~JOmIQ `RM-DuQD?> ZUpip$^@:1@^E'30?(^RY]͊ѥ`'"*F̭QqWւ6'Rhe8=3dS[":>CfϖQz[Zp}ے'||mhG  ؑ/:4idH ([GPõ`o;4Cbn)su(HIdJԻ0w6*\Zc>#;J3!V ($_~Y{Oa3-9R߈[*!Le4{\1-sE,L|)/iwyL>^_%i(lNoF݌A+suvsL>N+"x8]1t[w{$nl8h:t^M!F 0Y;UhT1ױR-0uL B{LbN6u,3p.K1z+=j=.3cV¥7U7u!)?J^|db@WIgLG'15.E]̫9/P{r>M :E9FTKQ3r!xP.zci\R?Z8~: a1c~|̣e4&08A~0G>!H{t<Dt.j0̠Ye da9|^x7mORg|i9[!sZV3 ?.]_wȘr\"hT唺(q27_ ( (h02&-rL @ivÝHDR,R" r*dB_HP}""%j] 2x2cA57Go['~l:/hf*?Lyd%_U"}spq0SaređeD e?J^Yչ/R3=dҌע丠PMq̇YORl @J|F뷂gz9X' - ڶO}!5Ū͉V@̅]E7}:~6u"^[},+sb+56xR"3 ß_ڥg$ ”NDL' ౾KRXkN$?]'`[*1_1 3.YOB0|sk+Hu6KS}IoU%wڬ|Z\]nv,Ӣ.-[׿YXRv6Y`uo X*xBZyh4͸)AS,\/6^yKW{}^3էKNA@z̒B8_XWHZ}ɴ{ɦ3jKSH Z$"qzX晐4T7fO'Hf[* $Ѷ;2v@Y\ 52)|ҾQy >ǞgڡEw Uƞ1ݻ|ivl̢7@mt H6EBσE@Qi-Ƃ/O4Ąg({e]VsM43e̙& ЈZ0wtz K9QIͨk-MŨ۟cT ŢC5”, B7mx:Љm|=U$ _̂faÑ8bMe (8i)EsBKx ߷mh6 (g$  S VQugzղQH ~Ր"ĩK7jb" C(ANi)^ׅ[S,K5W 6+'#ο1,?[`stӚl< 9rFfIV}":e+%>yЅ1Smbe+\dh@CTʨG #8k-8K޻(W k{VTko}ufyXIjߙw;.YzTsJyDUq|\^] 86])0r[ZU0Nd#N#:8/cTg|V3<*3-uW &pM Shs.d3Xm[%"DZIr's>!l> m I| gM=ʡFyܮTUx;V߮\$FX\F!8h̏TOƾ,\ ,'rU|揱K M"葪6(N2V{Ƽo:s! Xʓ}u)XiefMf鼩t, h0~LKK/B{rer1_v.+jH*F'g e[->ad=UZYh4%YZ=lZv=  >X;Wiv[+O2J쿧1k$Җxf׌e\L ώ5{gRj/H$fV4|&=,@-kYW`l-Ik 4+ǂFbgy)܄?37s̓fqG_h2ʌO(y\ӿ֗Q'?^"yh`nAц~G Ǜs4hM˧uT2'x5  H\Z.~:)I_+ݯgt2s-߼Y&HE|4rɨn0Z&ԛT@Ru):m*zpmS 2d#f#esTvEg4S9}QYb/?C -e4HXרcy}.q Y/ɗ.:򅪍'Q܆n,cv2\p$_JTGu]S ˽1DҐPsFr뽀>XN㠺K菹mC aL6>'> Osk>SY-1\t7 Zea&gE!InX < gIr'ɮ4Pa mTC dZGʟ~%-!\0)P[z`8g9r9̴."Sۥ7.Ǭa5RxsHpپ0j=` (X}$+`[-mܬ<ifj:5D&wR&@Cm_rUِ|em|lt' 7Od6 !LOî۠&X)NBJd ! ](KmnL[w&nE`%.ӨQ>p[IEl^mo"h:]W*[)Y(Vw-#SVɞ㳅y@s%c9s\MK}wqAэgk(usobpX 8ؔ+c!KɮwP9L!qRH{iFm<9Ԙs.\Nj6-*!>Ova`g 佱M~Y|灊$2 Zal6/<EmC"lXvKOK~_/╗}tIE f~%Z?=>$.!`z>vbw+8ɯ[dF}uKza5\zPZN%Ep.n`Sfa0\# އ1Xިw^_1s峫W@&'DZ!kpGN= ʱIafPTb|+tp[IBF 2p?j˔97~j~mu ] `垌XirN&9H+|n2CA?DF<| ~{%ǭOBYb5m )~*# iv_5a܇"]Wh5CrN}BB HH^LLsT q% ̨6ypO^k KXxPgW%X>*2Euorwa+Kv5d]2QtUQ eEDK_)S JxbY7>'ƶ2k+r!7;h[1<1fmWB㘂4<R[S4!Ӧͅeg}.#zK7tW/s03sM|h@48Ї,l2+]eϥ1Ch27U'iޓJ-U d=,xºe)\X P+VSM g}[nG fIlk׫hpU~RnBﻘ"6}*@=J'9;k Zv0ԁWta? S$ $GK1'No񿱲q:-R |qչkATPgX am\XCÃSʿ(Mf u/kelwǨJ^9PV`f9{,|Cݍy./l,"o+LCHdU+=A V^< O1 Fƾl'N$#}uH_c%\u9Džd^ Iܤ $Ohȷqacn{g53l tM߅}:Wlθ2)Ȥ<2&VbMb5JCxRLt Q S- X˾oqjշH+VCu%JchtS(F"N(ҿP*w o*1a%g1{h j G44*}[iKfRwJstc-\^j?,.<6a+92X3cPBlfeA3Xy`FHVFSod& !B;HY qض*(gY’_A9[7 Ls"ء5º<#Y?:ޡ@Jk !xKER#i #U!gYse>sm:+S%QYԶT6hĺE\v| j27e'q:⚌c+iE} ԶU2NN՚}gW`ي3^{H[Ϯ?cPq= ;n44-/NsHq8C%B]n (WsbW(~a G8K S584NEgrA}t/aˡ)P쬁zPJ}kлd>r6ZM.KLqIdV| kcZln-,rphkͷ2+mRPI}ow*D6[SE[{R}HP-v2+9^ 3;T^Lv {6:!U&f v*C~鎄".8cĺqKЬ^[qCJ;!d3(`h5Vo1#0bcsCo#ew@T<'z^RbI º@PW)/̊%Aи7~O5*d.)3đP2iRď|wUy< F.HDO#~/ !RqF-\v LaDB ݅!g|P q)'g݆Z=xv|L˂}D EEEz3#AsA)I`î_p0R^Odk5޺]L"Մ=tFL/OG8̨i}9n(dс@08!+Ip+1 ThįbV$jIl0z'btg|k,0CdrYzmRb(\Kː%DBW#RM3"4re2xsbKPL*v O҂le׊8Hw}yf4"*=+ќ{:x!]WJ'oIv0Jlٻ i:-F5i(aԡ((vt]1`% Uh2^4[d"Z3z` {=pc?P^#{;&_R< RR$Dj 5 r{$ݺ`sPfL*uW~4^ J5*ZKZ=.{ !?eWC_' aNKB>ϻ &/J򣰀iV(ZVɥJ-D&X~Jq+gM[ -LHѝ勸i:ڪ^zQ^+hXeTg"NoD|{O.Cp\GX'a+Xͷ#G7=Oc %CEvՇL蒆\0JydKO$ o [ ,pXGWs"vwBŪ"w1.:wX)a Ͽ)tm>u! xR}Yl~%7u\Pʫ޽k tS\Iqg9#\ظV#pJ5gCȮz|ng2 L[ocG1Qmd1l"2>&*ӝ5*G8m:yg(n)Բ$Ϫtn=ɘV' Nezq\(!YD:rAhfD jTb <8>0ڇvr@\Et~sΕc3YuVǖ-;'@ZL S(.X:(, -oąies jjg)9Ty =K?=lqZe.Gz-Yݡu`޺/| 7+?4DgiWrhie`*)$L%! l@v>7JV GWu#͵nU6ʴyː d[ ū* KfoJ{rJ'rK۟Žmg$4٪1~ ./[xkR E7RèFZV8O0U!]zh{ uۗݛܬ`[;iR:ԭd9oJbZ}p|éX~F$?B* $g|~-duO9(d cbT]~`Ė?i B"O;ЄHc#K?Tu-djŁ<;% Dv,x nu$ruր/]DU&a*%J^{Cioۨ䨋4MM{'HB\WU]W/;Y&"g܂ KƼفV m>yqX'|otgБ58qiXRP;1gzL2sqYũὔ kզ樐"=K4hobv §0jş9 J4g7M|%/$XH2U.7)d<˟;Ezщq[jK%%7\1чdFyqݰEI3;AL ÙLEa'y{QIzST; U' UTZ u0NLE)0\4᳄Ez1 zVwK+*&*#2̶*h^exDAB9ws1c,wXvor繥owZ$8 0|s'/J\ #l Wſ e A$8Z5iWY?Z?LE}lF ͤ<}GGwӂ:HҲ8{Tv5`ΉGfpBKP,6r̋^KXC߾ CF|gBo'/ɸ>KAU]N@K#`v@~mԸF՚a@qrlSP 'XJ;&$^Ά?'`‹:T+{Fc+nǪRS9,8: {( t[KtPJrj4qXr)C%24ۦtd gp X~5WΗsD9<'AfGèrSD )tۑ'}xɥ.;HӬ82݊2f;E{LI] ;ijޞEyt)7XNxҶF5Vĺ!b~@p:/Y5@:1,PiWp>u}Yæ9|1Zt0!ziŵE~Ϯ0=":]5hA#̇zm6 F|o\.5%߄cDrJYvܣJOzP3JDk2 櫗|π¦BFbGo?&FQ~ޓRС7[%JtoupBZBie9QQoĘS.PhbZ)qmdlj(Opw\2d;Dt\kMq< , RD:coJvb(H?V(·J cȀp({quBkr!4їBdxË"'4OHs y79W+{VO d2L^h(WlH?'-ȏ52l5GP'G "(LTA[Ĵy%nkr xDz^6cT(K_OgF;0~ֈ"1//[IfVdu>,2OߌlS_PI},\pƔ3"Dn4މ "bE'RfFHt5o??G84 M[u{PSyU50)bY":aն :(ok$^մ:AfknWtSQMO@h/-w8ꣳAN$gaMI_TSx(Ƀ1׼l 4ōr۳ Fls_?>zI|{r-*2DRkz ۨ5QҤxlr*kBnWG<}#5ҥX YZ