pki-base-java-10.5.9-13.el7_6$>9n W>7L?<d  D          % ,' '  '  d'  '  g' P'''r'0@(38<9:GG8'H'Ip'XؘY؜\ج']H'^bcd2e7f:l<tT'u'vތw'xߜ'8Cpki-base-java10.5.913.el7_6Certificate System - Java FrameworkThe PKI Framework contains the common and client libraries and utilities written in Java. This package is a part of the PKI Core used by the Certificate System. This package is a part of the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.\.x86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem System Environment/Basehttp://pki.fedoraproject.org/linuxnoarch Pb !& #-+,).*)&##"!81;8+70#%A큤A큤A\.\.\.\.\.|[!T[!T\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|104e693105a0f33323a500b28140eb73edbddc312c59aff2af732bfcbe4c468394551476c6e1669c47fcfc7410317b2cd505bfe5c3ecefb1e74fecebcf90f871b2df657063377311c021e0fd7006b3ab5ad93e365860dc3ecf68ba0078a90481fdd8d5ef0c8813c633e77997d6dbe23557a5112937962d5ab7b1053de866027b643b71cec56efdc737a20687bb05ccbba40c3481b2c0e100ccf53331e0fba620/usr/share/java/commons-cli.jar/usr/share/java/commons-codec.jar/usr/share/java/commons-httpclient.jar/usr/share/java/commons-io.jar/usr/share/java/commons-lang.jar/usr/share/java/commons-logging.jar/usr/share/java/httpcomponents/httpclient.jar/usr/share/java/httpcomponents/httpcore.jar/usr/share/java/jackson/jackson-core-asl.jar/usr/share/java/jackson/jackson-jaxrs.jar/usr/share/java/jackson/jackson-mapper-asl.jar/usr/share/java/jackson/jackson-mrbean.jar/usr/share/java/jackson/jackson-smile.jar/usr/share/java/jackson/jackson-xc.jar/usr/share/java/jaxb-api.jar/usr/lib/java/jss4.jar/usr/share/java/ldapjdk.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/java/pki/pki-tools.jar/usr/share/java/resteasy-base/resteasy-atom-provider.jar/usr/share/java/resteasy-base/resteasy-client.jar/usr/share/java/resteasy-base/resteasy-jackson-provider.jar/usr/share/java/resteasy-base/resteasy-jaxb-provider.jar/usr/share/java/resteasy-base/jaxrs-api.jar/usr/share/java/resteasy-base/resteasy-jaxrs-jandex.jar/usr/share/java/resteasy-base/resteasy-jaxrs.jar/usr/share/java/servlet.jar/usr/share/java/slf4j/slf4j-api.jar/usr/share/java/slf4j/slf4j-jdk14.jarrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.9-13.el7_6.src.rpmpki-base-java      apache-commons-cliapache-commons-codecapache-commons-ioapache-commons-langapache-commons-loggingjakarta-commons-httpclientjava-1.8.0-openjdk-headlessjavassistjpackage-utilsjssldapjdkpki-baseresteasy-base-atom-providerresteasy-base-clientresteasy-base-jackson-providerresteasy-base-jaxb-providerresteasy-base-jaxrsresteasy-base-jaxrs-apirpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)slf4jxalan-j2xerces-j2xml-commons-apisxml-commons-resolverrpmlib(PayloadIsXz)0:1.7.5-104.4.4-54.19-510.5.9-13.el7_63.0.6-13.0.6-13.0.6-13.0.6-13.0.6-13.0.6-13.0.4-14.6.0-14.0-15.2-14.11.3\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'10.5.9-13.el7_6pkipki-certsrv.jarpki-cmsutil.jarpki-nsutil.jarjavaCACertClientExample.javaCAClientExample.javalibcommons-cli.jarcommons-codec.jarcommons-httpclient.jarcommons-io.jarcommons-lang.jarcommons-logging.jarhttpclient.jarhttpcore.jarjackson-core-asl.jarjackson-jaxrs.jarjackson-mapper-asl.jarjackson-mrbean.jarjackson-smile.jarjackson-xc.jarjaxb-api.jarjss4.jarldapjdk.jarpki-certsrv.jarpki-cmsutil.jarpki-nsutil.jarpki-tools.jarresteasy-atom-provider.jarresteasy-client.jarresteasy-jackson-provider.jarresteasy-jaxb-provider.jarresteasy-jaxrs-api.jarresteasy-jaxrs-jandex.jarresteasy-jaxrs.jarservlet.jarslf4j-api.jarslf4j-jdk14.jar/usr/share/java//usr/share/java/pki//usr/share/pki/examples//usr/share/pki/examples/java//usr/share/pki//usr/share/pki/lib/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnudirectoryASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)C source, ASCII text?7zXZ !#,]"k%w#zIRG6"il'u jogsl+kn҉5n璄p2KV,evwLҋC0u)<>SCk/UgAbtd6ss 8T6iS_%cn׀ۿ|C_?iRl0I!>%mYQv(oG埋-Eڦ=;Q6hFvN-kE {ҕOGh::#>zlGZzmxes+{whgZ+ y ^beVH*/c Ri@~ſÉ.۫2{[ӹԔ~);-q1q݄Ƀ6׆d~lcc9cp xaCIIy;v(G9,s(?388{Ǎ'O< GGiMccCΫa6y_lO;swY^됍Yd2&Ob 8f@2gQx4d8_D}j2||a W_u7Kmr: E1]B*dokt?iWA&qSSFk]Fhaϭ UtB4./uɱT q =!FWx .F/裥H?@2 JR&ox"/~̹pZ!4 ;p@26'RXW̰q-4IF  y%+%Ww'pے6iHuq99p(.su [vxijg%4ڴ[C@X-䃉H+X׈ih31Z8 !>DN7ELqD"اzy)vU͒kNsoD]-wUCX`{^_t*m:)%&v8s9іtU$j$O.UllaLG =*J=gᗴWyd@kޠq};cO)!lr>[ VH+k)Q@C@^R[M'0t8wĘifu8V|nw*',dLHwvZGH6/s[vvifc^&<92eH.Cy~/L&&qZhՃR/;VRȟn:Xu X }Pӛf_B@R^&N"? dB'쿜̻|gBK3#UTk9a L`* K^|ӵ~JW@($H$*8μfMk;(qlav RBN_[p 1 п+3Y%I+hZqD Kj*v+tah& M9(ac zBniT!\cSz+i;SP:|ntepnu~6"ƒ+N6F: _0os{;㗖vP[so cB§F A:.HLYi-wW;^1"|"{R }Bc 5O MGCW-tCkd@-it@1Z qI%e6n /qؓKUf<]fy<|KXqQ5Zny{, $e.m{b&.M r XC|qXmǯJ)ck8 kQ\N;!d8i^n\Es3dL7Ɲ&:Fi(dF)ڬC.#`LE9Ƨ^J 2X?meKϻ:p\;B~IzJX2'q!č#RP!wDyX";`ӉCa)Q\{jHt%fyR3PK(1Z@ VTB9iM"s;\U" De`)ĕ䢻ws9ry XO6/vU0T×{Qx@SېvvY&`E5?.!68ong?\gs-h[ۗ 'ዟuYʻ\6H,~7M3˹Y!(d64r]1X  tVOHY5*#E؛♋W=(+Trc țH_NםZM舎aLZys&0d)V!bEѥ{= >X%P#kS4)ǮO Ne*\}, ۙdy6cT:@Z^Ua莌ffxKS͝fR*jݏy28%du\#pwTRy;54Yjh2)A/4$oqLG9)N[M1{ضUȲb@(mDXO%_<JrU!Є8C0<՞(Э꛰ t'!>MzxuEh^RY6Gw?6lD/U"׽u{UN1GNC1O/j>TIYri6'Brןh½|^x9|+o4b ԔTU$8 BR"7⇰7Rw">2<i3RhN23ڴLچ\[dЪ;5]R?? ۛ_1+%*#Z8?x|=Z++,@N"@5{*.4Vt$*mm0q+VǴOzOWFm烎c,J /9σg,mO2XHdPrpb AIE :FXEC{Rc8ץ d7(rqV9ݕcbg)3Yq&hR Ẕ0o y:34x Ӱ=ό?DKjB;.ՎHYYI;MӄlB"k]5|3sLw7kRRe J{TEt>QaJ n?D* XHcgr#9t*Kt4n~p.Hw.rܑ4Vȓv+W%<~( SF^Yh|GCds^l$mnl;;o^}룠numD<ٙۇh=S-ضew_1Qb!X}70p]TGMNFo}eȽKƲ\,}Ooȹ_cMvJ[,kgwtl^PR_wMyߑNY[Lu!PCu-l?qNsڇLj\\/aAӨj )*<zh#}vmYhw07+@R4WaN?. z$pR5aۿ|vIx ,%8k|/rgy4G1tx!/> , r9@eD 2j7Aaj8ohă>N^oVL 6nYhn<-w} o(%...jW dOB!ҟS%!}P J.ܗ ň])kmq,k(п@,USؑԡ:O"$*ruW:o1gT ^UB5:>GVv@X5S})jsX@I[9HvSr#yp0(8/.ɲfjX;8ò!ŒI];!y!8jM]84?BO2URt/~#,Ut.;hL *HncESj%'q;mC Sq-/wUkgr,q1 UPP3?1<2OdA 8Պ|bMPTM[Ldᘠ578b {Qz y`(lžz?iPR#Uy.HjpVqzbC&QߨGz9>}OC/9->!$D0ibp)l] Q&H&x/7EZމnzϤހW4%n:n,166N͐Wi9),;WEj )" g"0"b2s6Ļߨ4ܡeMcv,> jlmsn(]H.khq`gE(S5jfiP^I)92tˉ9!l˥r&Du Wj(/S@i {c6^ .9qz3iCn dH'XbœI%[3T]Vh"ׂ-0+"04l)tmmEn$zӼ U@BPNx`g1 zI.$P+^W{IIh-s5 xFZ /v3&pZ"j%O9;a_UK5 `kPÕRKLje+$4sETp*agA&u]t:hVxpW䔭v<ϾXXq%;ҧQ͈YAm\=hrHy,ȼqTzeOn%twz-o98r@s[NUkk nRq9m+LHD|mjLx٢Mx @ i@TЦmknbst@D(ZѣU$Qrf@+n^4ާE!j$QHyOUTGlj{if"Zܒmڠ(%Dl;sr 6ߘ(ўD?yyq*_hu"$ 8Y6fY@ *t>ٶᏄz Y:zc2ϴ`;:}_S kwNgHQG.ҐD_*&,+pbi O:D0v"b2~64R5R}=F\ Q%7m/g:@&NUGnNF%ҏ櫼@ҙȯg Ǒbϭm,A 8KFE KЭPѐT0rgɗ$~5 BF)@\s"Bu:HH҇k@hZd*@1c*XKU0:ʞz%sXqݿou ɥ]5/ѵKs~${p1j_V D~Ψ08)0j]=0\Ɨ<)etuwLrkY4UyƂE ǫjFvLKz'N|6F8gAfzGƒFJa0 < 6'G$˯OUL"(5ujڰ}P&en|}U`b^9YJ=RγpRV Kg͚aU&o6HHWk_,Ъ;>ɕDM85sog68XFʘ5ԙ>R'NJ;':3יZH,׬8ax$A/Q, 0~]ZّBєpI3k:m R\b/nw,`s)X_&ҵ7Mѕ;H΂. nra%5m9'2]R$nrBl[Q3jz(iyH]._}]VJpO&)֪$k`DǕ&O/ ^]^,v^4$mv`S)Eլ:+BH߸GT/%_Ʃk%a|g G=kKWWBbnÎouj@AH x՘奜dG{O  ;F17ujzn|Pסb.[i-r 6V_TXαY#yHPbmʄ~ +1@FyltW;2v uj{)g`|7WX2/t4\f`O5v6:cV趝(NTAlrºX\t ;oԳ _~DqIڃW{-&=:4E|%C9!FZ<6(NQ7cMbeӖojq6SNAGhn$4h]%zkWmTm ;-3_%7/lNk&Iզ " z\.ȅKs Lw&nQ BokB9Mpw-!{:aw;4`R=uJY!L1"*/P^%_hKk}>_qəD>o-z4r2y_eC1y\HͥNB NtR=(^k*H|S#xHlh( ݠK0=f~һR&/)M2M9B n D8{V) 0|fdEͩȐo}X/m\VOM٠Rٹ*:\;cp` 8!ei`PNx|lIBRNFC+;},Sǟ!V{u-b ']Jd2^]cW6>s՗DWUQG,\HRPFrg-Wt޷Xj+Pժx=#@"kn(4o;U#ݽD' dwbW C qZ(cvonB Jo06r@YW VXS֘H%{ ڲljG?zϛ V3%qW+}$*ͩ@ \-FI/ʡ:p%bS-bVΕ #B&"i&lFߦ0CY×rMOj7Kd"=|!aà!d0k2yƵHc g]YDtIiWOPCF-Z7Ha ;u5mw{oB6O7OC~"Je"]&xY/h,\O^oX1 dݽ2{SM9>ߚR&B}&"dyVպKSqadQ`󊾢7Knn,I>=G s Y0wLJ暜,y6^KCp%7&9 kii6P=|uhɛ-= j_|qSM6{lTy|DX~o$l <+!mA%j"{HT 3LVWdG IPӸCEIA2T$[jqt6lH ^ciq) LA fJL4C_mD0ny۴qPꍗ/ i0w ,۞X8Wz LRj2!aէ9Ld-p z~ؑ})e>"^˴{΅TYdcmbSi!J|!a]W9|c%;g{XD&|##aNdZA4c33\(j uR,!dj}0_]@Miy?ݸWtoN{<$: t҈'UL_&J_6\/ӵcWerdԕ/&Sdُx)5b$njcI"M&䍗WbQJ8jz+j  MH/?.U3hwUFW/sUລU*,ꆓyKHw6{tj훹ZL駱䲊8l0M3a"c͗*faJ br`ʲBq }P؋},' FNӝ)(CbD*yb 67>F"n8_i ?$˯Ѫ, 3O _2dwgγp5`ʩ\(Qu^q@XlW5G K D4v|06i*8eSșd(.y,1G#D 'ౠz?6 }b/og#pyȖ=VG}gg-dw#2H:fzL~JZ>R&k{# n"E. tqG_2f\OVIA@2fs9/,--ƵYyiufM+;b6bhѡ6ai)=2ԛ>DZ^5J▧$r꫑07PhOwR?e>{hla8ԧhX康 B-2ռmhcIL>e=; A^Uf0A^K#@wCV߁jEթMdW`(cAt"~n%?$8u-1KQ|8pƏ~$4$y> TΞ67 blJɡqƑbm@YuyP6i}0mTX -UxzX @+q43F%csS=ꄨ)9Dx<d0㘫U\[sJ B)wo~qUI6+k^xteX!|Ĵ53l^De"Y YOk#6HNҐUk&nWIn3%FV8!|?=5mg?6X[p(򆺮%{a-I#'=Š5%viБ(2䩅qA@On$Q/H@Ff\?=j!c]PD2u+~ rz(QT\r] Au +X3J>z_Zo}(.G!#ҫz`Me8FJ{\+]y42mYoR$)\NzI)</]ې3Ikԙ5KUa8W=^[1վzE\awKnrHZxG#u9 i0UȔ$'"?乚J{_Z'ݙJB^:K_)q{^u_G5GC qKMȁ\H OoW-l>)l(o@08=w$jK [,)ÙO  ` O=FxwV}%9|e߂6bmK!;?6. S n|TdBBE5'.ܞĬv6\TM`5G㔆dwу\p0̌T")VY#HkX#+B`N%"Kϥ#Ed+R8yRpg ºFÌViUo#MFpW>_?(_3U|dƚ;d5NHRs̑S-"Ir=iJ@9#j˅@o(#G0=$${Ўڟ_@:6 eb/9B{TH= 5K$?ECC䅞^YuR$DMڱ(`r*kTӂ e(ӑycP淃po:Mi<| T7ZdǮ%~yBBȝ d=+D%`2g?hlGVE-ޞ*.:&-Z6w_EZ^g=ѕ_xFH+g.e>ń[bȍB[;.^QپGʄ5 5CAK?:hq K=]~hѽ=Vў3.>|XMG,yޏ?QLzxdЁ\)d5V4 G Ɔ?T 3KoFqf7%EºZD1xoBIϺUTT&+dETpѨLHG.cM6~0E5&~P9:GEҰ @Uu"Wdc ;!+<> [$BWR+L/BdwwK[ I ,A;̵>m<ڕ]O<妗s2y w 93PҵaDh=YОa(@C(3ZރTk 02p86i_S+h[vR:% ]"Om$` &J`Q5Fί+2`ʖ:ɵAAj:PS4sTrgŴm!Y>uf!\Rbl8g? .}Sp (/,YTM*Co) "b57׊Q- uArd΃fLX2'wp:nFHɬ( )ɷY7]sS2 |!ÿyOVPi9TȘg֏:w`:|a&>׻X+벰o\p.{%o( 'w7 M)I= e`[jr7{8G ">:UFhqtl @KEFŷϘqQ5䆍U~ R 0W_r\"kٙ$/xY'ϥ/g[AgFSvdycE2e k7Mw 5Ðrր:S-7}!|MkUSs!9p 7 ~=18yW\"Kcս$ ]kE pݿ` DžNk%,Og,[\v LT]uH &\ݢʹaTDenj:NbhWoVkkH,a\Rw&,lY1wKC j+d'gm߮00) Nv8&w]%oUP5\pKmqP|@:U67qMf䢄 ]B:Q$ R <8 ѮT aq w>D 0X̅&U}J v[ !eLR[X^ ɴ܆7ŵ~`HLHQ :^U3JY|xEqxf"y5Io`,yE5+; Y:PAze.凢q\eg,I&A^ OUQ i (v ㊇v*hWef#fft} EEA1^VJ%ߡ')ސc 7WIC;;^~tz Q_[T]=9tD2(:īgcp&BA - ks+U\:}vkme!`7~3Wq6] ڝm.,eLk[:B}!_hRl7uKV8h?FHvlň,3I:`K T,QuRIxo ;DT+Q>d=`G􅔻F!=FM]7gzټp'ﷲ`0>N`yV}R6lm: g]#nToAK0A[ؒ*ނlLjZFwe;$v؋x5͌@ j_)Au@oNTZC}dyHXUj^q嫊1 W# gΌ4qmBPqI#[h*0!I7hk%9nHBY_K0%'lSfۢFB 2ɔ,z[AFf-j -qr 8tό:N;ݪXvaIbt0z&ޭGf缌| EB`N#!:e^Y4s-hmL}L2 I٥ɘY'm~pdJ}ae38+fQ4߂HunGx-+5X_S2[0\ .=*eηm"J?I6{BEz~O}㦢s4| |i0wrϏ܁Ucn;s? nd;uj&I=o4uSM~E؜d;DR @V,¿K`ظ/L0vxqJx˜"Q:T'O,g|{LM\B?.A: j䊞8*iyIq3Nw䞡ό9=xzq@t/}y"t/Oy ͥg!; Y=(hب/.xTRlC=Uf15F:q4n< I@8"[a>cC*ӔM*3ƌgQ Pu+9%SZCUIج} )UH:lJ]QA6 bOco q#9/0\x`NDX;`lGg=%F--u<KHBwg|Ȅ7mO.L}i֢ʕY-[O+@;laZi3鈃%bȟ IjҠ֟NWbu'٠4ggPT{^H%m (YC# ~_Uɟ>7"g"ɃH\! gQ ms%oޅGK) T^ 8U2ZԢaCxJHґ-쎏L_E‹~|+|jSԸ$Nw(vIxx~ܸ| )},X"T}g9}aJzE8':yVqbqtPO"gMQ{P>N22[k p)r>BM狽u0)f$5- oWhkg'B ҡjBă3aHetS|,{xr5׋X{+oAm*$XG#+#0PѸSJP7q 7,WY W48[۸@\u.۽U_83.E iO]௝BT96fJ"ŊNe! KR!YmtdODk R"Kūb.U+ɘ9Es|_-kގ( CGe2@<-/jw,ͮ#uyMڢ7'Kh+ '' \{1F,yK Id^qCc[S[ꔿ3OQ;2ʁ!}Fǖ@ 9U$_]Q6ֶ!ZoqkFe[c/ !P5'S =c&Z9VY˥ja "xHAeH󞜋3Z;^F)z_lQj'za<#I&P =/m-;4y{,SIRMMv,~f{!BʥK^9 q1!t[FhC(NL֘{fEbU9[ )O4<Hf%ЅOr%KíR :4 | l+m˹8#;T֝qXiY#CvEKG +BF;}ecYF&:A:n#F.qOv TXa0EmA+4cPS[ejUC& !D"LcS!`qdbs4ﺖݲմN"bwٕv3'XJ׽YAz7(H6`/;L[#`;Sg 尐 >=m̈A{Zew1۹Q%Q`rKݴB MqX:!J|4ϫ<ώo/:)Π}Nm%9 d]^}3!`KwuÚeJbʛ9 5ӹLny09›X-j! I{ό5UFоvO3@V3Y94epYkjίUf;cLÁ9kv,gQgj y(@o*S Z~,:J0&8ҟtqr[Pt':N5JXfLj9620C#XhV<ƮL}o٘KþCLu?@>uust;˓!Tӛvmp1>"nUh]ΜuI‹p<^+-Gƿd|C\*?!tkPtd6IsyB HZci"OΧ o=u_$ocnVr ÜNrPy S2ԋ >?* C)f1Bs'}щ2 tWG5 C (uU.$U"1Ӳ;2q4÷y%y֣!O 2uN >lƴZSãkK pQĬG&+@BRrHe+Urd'a]1ѣ+ߦPI¸,ӿ ug j6I,꾊qJk@ 6&%hRW OD;*#ViM.%ڵV= o 7 YS`9{  "eUAd=#qAW{biX)mZrwYUx5u_-֫+O]#4UV-ǍrUO[’8GW.=.sg5H:?}L!ߙXgeQ@B?,T4VUf„1Ivf)D67P {hu SkR]̂NWITz5K#Xuܐ_=<0>cϪTh%Xc;.RuONL!>sgpM%p2^|`<83psp sL%ɯunpPͲ.TC-kH>pSQNw"Q8;&vP2"IǙfvQǏ#tJnO?jf3B\zUsV`mk)*4Җ2{lCY_Ss^]Ms8]^gext$'Yb>>!lq|Ȩ$%jV~'J0ӬH<'Zfp07рrGCw/[ɳ]B-"H󭠭$u#t} 9hK\^/0R;@kizCgMP ME(wJT2AD-" kM>;omw4|*KA@*\} #eygȚu#&k% '8Gm;nu-TNJ:.FGm,!Ebd_&7Y|OIT35YHL!fݢ1sz5;OJ.W& 8:SFN3mRIL峄oOlT־awBMlz7Gi^lCIT%-͕[GAhNp5QXg3^L1(9P-ųeMvð6þOuktW.ruPp߈{.b{Q9FDJ o([QaN#047@9Bxk@~[3 TyH/'`uIؗk!K [Q]q}tDip1!Rq*@j:")>cy,Du'KR(ydkL}xJHVEUIąK.Xxxd>rKTXKϱ.|Ikwa@(+#y>}~pp˲/u%%uhV g֨sȽjT809?,u`q1In J[$g|%Ut@y#Ғ&I+~pΫ2Afʆ3Hx7sRRGwQc*)hMeM0T9EBbe$ҚRP~#ݝM thl]з)E-Wp7v:ӏyK"PX<{ C:[^N|Odr@#OV5Z}]%E/c,V׏y5UT И'#ld^qYm|" Mʄ@$-:~s'.2"J \vv24vLjS= jgD7yxUnhD \w+ݝI(v @C7ӫ 2፨j*j0K gPN~ v%u{aЇ'EQnc) uQ~\>xyh@6rov/R.Rou Ye > \q/F[c]4~s&'1'c"߀PEY'R"M òj I WYSfIone0%Bʇ 0Cs`7X@"M?cΕ$~1H 74FÍ&D.#3h.P~ǘS '/DW  &Wɟ15fӘ\ݦMUmx M@<('S}PC siMa4Ϛ}9wvqLNZA=$hv3;-ҳw7_RgRV>@;~L] û_GK&q萱=6\{[gwrxPn.8(v mYSQ%)S'%!#|mY6?HL݈;ckBEh{J=F9`t?k݀ rk8{=~oYx-p+MЇ?A8;1bvE1uQ۰ !K\4RPT?9;4<V]/Xl:ut\ eat@ `//kbWwʖ]Xuݶ|n,ZLR+|S)Қ%^?? ; 6W?kt֟%dOmJ9j^`GڠHt@v0~_Br7vM[shra fc VZsr2(3l}V"hjz2&%dH.B5G /26tt9-Ŵ0klD%(l[-o&WZynĘMH/'^ M'3p[$rZ<8|H\~v\zS6\ZU T_xDlL/jgK+DŽLR-h]NOӟ[ܦa*HTsS)@E{η[$[@2Kh^R=҈N-B0S$JSJ۬2cCYF>"[B7@#Y'7?Ut m?\Y*JrZqm>Lƨm#/BZt #Rĝ~ .,<[vg=J%k[nFi \!o]R:0lԫ&(<v7dQBKddX$]*q 9C\k+Ž&heU=8<^]O6BAt4H] (&i a4pH̓p$5 a[l**9h}^moVxbiM(C: _a!ըr7dγO{qeU͒Za=*fIZd&_O{ s43 d;1L<ԭcBZeUx oAYST~`PO)_ D٫Y)V+{?!v $5&WΧ~J;kqZI뼖u7?4^-6|c s*4/E[U2LZ4D&;Ԁ3=2L EO5wp@e&KW㽯zfL?ϊmL8Ӥ0WjFTʠU3Ru]Gw59ɒ) dpݽ 0Ewe4rl.*Dw|ۇr +6zb55,i@{չ}_Wbރtvph#V%K* HDۿ (OсTp%5-? Wڻ(p|P[FS[Vf jmFbhkjV[p}R3펞@R %e, ,EB]`C\/8tu "iS *f,U Yyɂ_fz1:"]2QyJKkEkttxf)qawxgh}R=@ (uOBSR&nGvrٰԞ͒ ®']QaϽjC8Ꮏ%b,瓩I C^L%p΄<{~HA},RVf--F_ԣ̗k^f5rDUh#\rLDBRQ(,![~^m&Pb5d:菢5~^G &Ⱦ (N׼ٺcD%`"~26յ92:t-uYqb糓\)NJ9w)CZ .5 lƅ_Z+וU+_,9A1rT\xFZvVBU>xӷrox?OǚK"9myE*8{ @{+j9MOkB;`}Ƞ9Jg޿'+O&*W|Ž,5>M}FRXO$;{%Pq/ģ7ێGn?6K6\]ΞДDgsY5#̸TmIVLJs{z@^)Co\I<{!$٧c[ҍMe\zDj6r_6ZyvyiiTOC&pvj{!$! N*LaN^DEs@&K Rkw5ٷN|Up5mw"`c>zgo3 Fg0u;e$].s H>hWk.sHY_9&1\骚nT8=9(/U4>LEUqJ[ Ij=8[$H&9枻ٓr~,̶o+ѭj YtjuiF/jq'tcw I"#k%h!F=jvj=5LԈ.lRsnyl_ C-AZݐFD$ Ӥ~W\5,r_aLP`BWm{fZퟲqX m-&tsL;=,Q2UX(Z*%㞪#,JEXXzQp|qeOǜ3 XSB(BSeFeKȗA+ZS} ssK9C4;%'TAP*n>(_Xx{xH4_C} !P)7rhR#-WqcGxֈH+{|yGČފ_wTgs{ -pМ;tBXNv) \@Jk NRR65,(>Yv`[Nups:lIi%@jjD)DoW֫ݲ}/ur[N[[6AѥeAMNip"d<Νc,b\;j" tca$bhcu\{Fx%(A<.*)ܳu% 6s2˟#Mgw?a&R}Qw y F=d+0UyT?T6ʺp`=7k*yT> jl㒺osYgg$N?[;EXV f^筯\o-Wo9:sANF)s:/*FPxW#`…P@f1G2'm&A/E1 zFw 4c{=ܪk#H0*yd]p)0mY\AǨxm~)wy VR 3a|N)m[Pܣ\~.ȿƏ6[p6}deqʎ%0~/ُՈ#\gIbu*)$%el!Z2RƊB]3I+ .6 dUxʟ RɎ}ppp()r}b} 1U'IB4!Pڳ]D<)᰹4MVPXLuUVSE6.TpScg+k(А]8a嶇3#h,gJbn37-<+vS:sg7_9K$6˝%5cpW= LMZ*PyO t (-*VN|b\^<0^ 'ro8sw>"#jMnQf7A-y G3e*Nr]hR*cM%4Udi(%`;%Es4:c=^ }k>Ϛ˝098 ``=Uٗ o2X5uZ}vc'ـRrKI:tME2f_wӍ%ڸPz&k{:#tp_á{j3.Tm(W0k= tƕЦQ(V>͙F#4=#wP+^Y¼N @kZuv▸<զ;"2hn(Q#8~Q"*HҊ\TK"Jԉ4wCFӐҜDw1 VUN8<뭪7T'ѱ f8 /ﱅc5B=56/L)cJ=Bhm!%@d?uYfpzNؽr R9fh~?ة OdBB}k_KUf>O"zjByh1l>$eyO^])bt#bqD, 1SVѵAt.PR*Oa(Fti@.cOWV_hꆩױ)>*\I{!c[op;Y LxֹMUϯqܼiag7Ѯ[kUva%LPLm. S끇C^l@+O6Z valRqk @HiZT:I,[I0~oG;CNTZhW6:klbvbTpI50Xa:XIp3omS-Iz9::1?);A"4j+z[ b@GgC!5&g~ ü#t Gp7@qxLV^ߛЋ U3)Á +V vum8y9oc0A-/j=lbfFG[J|?)&^fuWEjU4T!q# huu,)?}(j]L*pwHH~)!>CQDJ08ݼ! |Ij;7F">}yUaIW0¤m+@dxV7 m6u5-ymDӑ6L,~A.]%O z ; <ʠj{PG pYmz co xR{Sxٓct\zNH4̨bQd:2ʮߴlBδe 3aP35@W˳c8 _pm^Ip),H%csD ^iEC<A#XЩ 7MGQb.z=2͛-a_lG7&u;ݖBŠ se=L?ӝu8R)? rL޷w+TUB`5kEߨg ~,(UD [8~U@G Q~w^I-B܍{IV_ /^wK d?+bb_S&*ԫx뺬A~0#D tرˈ9 y+Иu,UΫ؅p۾q6jQ/>s2p&TTOU(-РA ’!^x?.B[S{'X\ $yOF9D/լ4'`L|\Mzzy XM\籨Rdc%JG+Ա$'>E^7{=Q~W L;Le~iׯbN\f(q)j6X rEExO=ծ B*ŜiG8=q"E "Ym?hܡc*DkroyY;*þWtnmo7PYJ@$q]d|C}ޞw axF|J ϗqTiA1!:rcğ]pgk{LFVoGƦZ)3 V Z'@ӽ9fMe?Z+kԻ(Ulg$QtIO-X畇g )Dol9V@4"9`7J>zu Y3Q1Ÿl`8NL ![E;ǣB &U$rɲ$%E 2cS)(M%͊'cg gP`DY))fzz~M[X\1-\yp!X? eX2}$JpL\jpGlz@~YDg0W$Dל'qCOyNDr녝^=M sZ+ƵQL0{g:Y5?}=Yk!> YoPV_`> 00rCkWk8#k?xN{ V^:jj ;gXĆOLM( #Rjj4{kLw:n 6,rZ'1, 0igA;%YN zf!5yɄؚtD ĉGXU}7@/3/:l$oHMg䔪+.T˹`_1k]YT4/!e}lff6$Tf~,#%-hM88Xa瑎ݴ) svs?j*;3k@7-ϷLOvVGF#FhVnk̻p]QP>US7N@n89]2Ӈ h89ݚ^~Cr*2X8k6\F$`l8i&ei9CjA(2}AsI8?D"7= }Eƚ$CZy`b{Z3zrBYU+}h=^Q]ƪ_y`ήU?|bbP0<.s2sp Y4H#{3@ MzzWJLh[y_͵hCA`6X)8{n8&k)Ǔt B515P-% Pmrk:ߤ4LEN|*4a7e#u&~J$8?R,Ӡ}zšGmx؛OCZIYlZzvq=N2 fd4P,+Awf+Ir%@-8+WgUB`˷шƆ+f;`fGr("(HnwK}Ln#)u^B+=F@VhuғNwQ!<`M/X[V*mcPL PX /,S)w|=?cȠ08#$QWNRLضFK^N߂V2fejXKTw(¼;Ѩ5<9$x81|<%_fֽ[u|:U5 t'~>2%'rE6zv5;cQv.d;$J )z^lMR`7MZ1c}A^Af0#ONF0J=aKD:D~z+PbH˵ZtaPX(Q\JN\"|rպO.כY-y!lI|6z_v0᧕HF[5pᯣ 9 ~s8<C? 5&'0Z:M^a83Xwxt;k'a :Iد}UӠp,(^ܓώShEęl`1R}u~Bb3k r}{0DOjRFKTfbY9yD %\uTiw Apĭ2c ;SUL[#l˽,)"ɟR`\6ĢMGn?"1|Qrzn+Ll0xƶw><yK!msƸV@cJ@͞w ҸM\dq亳Qm l8+/_xE9>d4zN՛֎Q .m%KH-; USJW?۝3tXnZ̔Ofh Am#X6hz`I Jccg-}UB} = 70K>vj?mro](y AS;D*"T'E5w 9.:q6?㓪+v w&[ke<],#[ki?6`~l[~Q Yj{bxڭhc괊nI\2wn9&(Rzƾ_m@ e%b) WKID[qq=Qrq ->u;Y2P #eƒהRjK(J16Oy鵏Ą11,Mz=D 1ݺQ{ۄ9:K!; >ȫ]Zㄼ K63zh#B捠="Dn֖=ZA;:1XB `\xÿNUE i,v$~;F_9 ;[ջZ-pE_>  &{: IO%rmέFeNw Q ~^8bgHB ^Qk_;Sp5V(,Vˮb+x ص?Jj?Od V5g_]'xwͩ?`mL Ag!'^5!-G GN\E#xtI}'ֲ鄠 wU;xSw/d!w%"n;#g$Ȑ'+ӳJqG{vÔBC|7Ɩ^ rԝ˸c3n_6p5ou7s^S!T7zV:}lRFDUNc%lS[$=rۀt%G8%MC˸\6~@q_բ]FC;E!e|ʑH\dRĢ tQ/֖(xah@)gԟ+xia[mkJTb*wZ[Y\V֢ה=Ǧv*2+D2k|1?<Gv^_Wܝ%T";ۍGQn~~jL'?;`WV72_ g#ZyO"ku.) WIп3gJ&տ֖O=ἠ/II@h.n$c> 6*#TC{ᨙA 5xv8΄!@8p჊ F2g (8;:ŗ}QwiT@rYlwWZ6LQE9-c{3BHօa1l8fO͂F/=<7_𔸭 oɜ? W~ p&d5[YxY& qņaMV}—kGRmL*>Y-Bx}&l#)뽩OZ(Wp o[AqpKJ,5nZ|i W9wYC ;3Kgo45 _a\14\vN$cϓ6qsNl:L_S[2mqpIִ=>dQpRWočzXLCm0KN|`.2 soK%nMIB8N3?hY7 R5Kͧ @ݳ\`=1;?%C0$(mKCbjYũ1mܿ+~ELJi6}2ZpgǡNČ0Nt8.:x|ę.£ 5|9JX(7Uߐ>]pȑZb2iX{?!d_X m93tҍ6S3O6AY*X `o?EF C# 0#,nu͍(Nd˹yCF.a8WM:lEyR |k-hUd;Ve *>O]$ezkW_}ײ AЉNE/dĨo_gc8!H5w6نtӔ; (;ẎZ=^Gœ'iڔQ8TfZHbbz煅8RYjYĘ\ 6-~)Ie}Xt~p##A u%xse#CQc٨k-5V"s1}a ni gs ~3nXJ{"?DoIL[X$a ;+8xGW_#l K+5~7ȟˣ#sa~KacTIR|m`pgq1 \\b%}kb+-l7ҺCPĊR [a +i"-a^vJIjC%")`?)X&K1*GKoM6"=U},X(Ϳ ܛ}  ʳ4"8\i~A|e-_+T${DC o8pf5t??=_oYZLjˣhÉnso~rwmd{rj_xZ}R !ӔꟋaOo"iپ`J5QI)NNߌS5*sLǕ7>qI #zdu$58db:4;ݑ-3w ,'9le>/HDgxk" H,5^;eR ri8 Y28o@k nNq͓/=j0AF0wt$_|PdS5.VAPs@.)m7nğl*  Ihcggxt^X)T T |T ⎫a/խw4WFQ(C \r1 w ub!Njm1:|kN\)~؞$ _ڹ| "zO;#4nk7L2]dFdrt_>+/^t1sw/H_CWGt%E&eG_ yC{!ܼ)9FhthEgKò?Uwۛ+#+v6),=z"2[ M潱 3bFS_إO $L2t7w"?I_e`+Eny"09D9<8ϘƜVH{(FR֠9wُuV8u?ŌPHTE-OWj hLI %>Ŀ5-O?09ynj'6i 4'.bN E]TYo"nH7PI~~@ ڒwTD?h_53cCZV2@Xg)uVҍb/sC2CHj٥Q~sU :X V:/B;s-\>c@BږS%$Glzt/Hϴox+6tUNt$A%AHQzaPYB,x^c &{jHsT.iJ0&XG7]cFȭ6uBRh.;M#k}eW.hC2nHL`h$,o r6 5/E2rM'3kw{p$Sܼ U]ͮu&aVb- %hgVvg##UZJVZ `F"~OA?i8)KB_k0/?&4HJt: ]4K}îXPe9NQ[lY,ceeEr*AAɩks͓^· vȃMĒI'8O"8+vDiկk3ܥajUBdoΝ=qqF'B|(\"mȝ-"tH1x.0亞V5X5>\J2kユg"ȧW]&L%P+=截T'<[0e2x*sP% PVlk:=$Pp4P!jc 5؃QfJd)F;@b8z:<f*:[5N\b" ~3^S*툛A,8B0:{ɶ&ud|u#vx  8FBh휛vX٪^K~c%tf17H8X&WH,s:j TDWV DiC9ӽ5/0YBm[;!nAѡt=!x zTP>V^z_Lgأ xyp\z`0iH5VA͌at*0S<)RP`ry$^> qYA;^I}Ozz TPE}~HڮY3 ar!Ц'1SNΑ@`c)e/sG`l^_By~?l ;t1#zgSH[)/e:ɍZ_%Hp"X `j7WӤ D'֐*# uw}I8Lԍn\ o:G?K9OhBf2]\)H< ; :}r8^Q>xroໂ=m%s^Ѵ! kp׸抴uM^{ yPrrǥi!#c1'LQǿq (}ÿ9;"=7BdVF_l<2+t1&ӄ}ۗ率ALd`#jaw 7Ԋ*ڠxo*D0˔zRnnDmԁʓj =]I >0]nF'#F5rbrOH [0l[Q@x31h-ߟG)86XBOIR@a r io*smN.X[$ҡk&X $ƀ(QffymvL~Ki6x5%ܧ [S\c/2\WtZi-jB^ yn܆zR; /(Ov;)1T٠0¹c'0FW-6 S^OSB5pݒ+Fg#'zhk~mQYeVaZ8nh Hso3?!;1?LeVp(^BF/EE.=˃O'0\xFLoƨDľA,k=+V8icǟkf qkX`9 ^eHjM(A{Kf罁V.Y3d5]E>FbM=jĦVS/iNeFds*-E2$DkUUN5 Pִ'yVhWMj 3B8pXH򛦅hܒQy܎3INn0fJ:T'Є . X.uF(,Uv[ڈvLbD4bebJļ+8!+>FvuNrUrtM 6&2O4pȼHx4"+yYxA?<~C:,Bq;&n:sfr|w9#::9q͡?r-*~1HVa83 (,R zy[o2j-SnpZG9 2#P`]X-㣟p4@JYMhˑho[TU}ZKI_S%t"äf% >Q[h;}{( PqQuo-\4ѪYz|3@{u;m铮.?*-HW`NEpі[1<߲wh:  oCC yrmDzX)Wo'L .!}^\J;)b`l5c;?@>L}Rihs7xlAp|5>gz?;C=u5\mW~$/ dzaR Ԩo{%`Ƭє ] D<)I:O_W#na5uh‘>vE-;:x{=rDӅR-.+9 ~`_qә F ;n~.?,ˌJXpMrz".g%T̒x)6=gX,7CnF"Oݷ*co@l*0R.:wH߬?_-Ua.Hh2m*ȓ<$7#,zg߿ٿ,A=g>IeKQ$8W%r*?ǩ9[>,Y>IP|d>H%T-]!śQ|ꆍ)_/;NG=f 쾷uNl!@Cbt)~Շն•(" r1aI!{vKG 8>U3l6HlŽ,De ţ?YZa~snh-u*2yLtϮQ㍪vٔI|W 6-\2݋4 Ť@?w [\z 4Ї#2~Щ21ĒAk7p'ZνSb Aь \ LuwI7C %NM0/QOhРs!]=:4G|ߛφLOD]`cfq%'O;w u)pbXĠV 3 *Z;^EW{OFF}kR,@9{;׌iF)_ #4=-Վoa,hwOz0iDz_gݯh*;'xKaxVPΦ0}~hcG6g`Ƴ:]F p ?^}utyMڈg{cCX--ǚ ~BX|Ph _ V7O6EK9T܄tn+=;f>4M9BmSU@xKGSWaWrԘ t:H1.wHq' enoƏ˚9@a(*!<[5d~xԤ C/( /PQHQMѕ6Q!Ll:Di]55 XB"3ޑ`^Aq́a (J}㼁z$9{`,x]"7#-126mǴɶ04/;djg3A)"IyDS2;r^ sr)ܲ;- X 7SRSKQbqulw?LU&@28yy5qc5~_GzJ+"PNڴhn(ڭc3ЭYE=8^o)7i%d;̛^3`";:2O㲆n+%Wc3lyL ֱ+&gGѦ2ՠlSHg{VdsOW5%L ^I~IUGzA "lg*YMɇ%tk?zZǬ bua,h4Öy$a~+aHUά휒$@H@nhU8mb/"Qz sh)6B4&DWߩK+co@YUڶXx ׶ xM%*`?4{mB%ZF r$x >(sD))o}Ka ՆW.3>}+YHp2{HWeQs֠ӊo7c7`A(7AՕ N͵^ q/]i):B@|4^ n8zLUQ RQiPZg IE!kK^icMU/ 4R50P&! 7pg8%+U8iu X7zi<>YoWZSQ #g<:d ‹X-C5>IwLJ+.j"^l6޹QE*[Zc _Dklo \m"`>ծ7ԏp5 JA}tͪ@w݂m .is+:HLJGрe  זJ4@V{'|POU,XrD|%}gv\b@jX@=] -ҹ4-tt^ Ԝu;M*u5.'JnMYi 8ݐ07'An'a&Nw{ ĐE߭z+\H+4FFkAύ\-׷E٪wQ-E{Q f}Eˉh@ y<4dc$K˵j6۞ےZ©Eߪ V _y˿J,;mm;,Jm3TW0j)(ɕ2,r ^:lSJ*Y⢵B̗lTPi*;z6 k? LV@XI4Zfte5SE?Sm&?F5n*ip3^"G] zMcI~C59.16*ŧN9`wz~7r;`ba:/_1|ȵ$ ٩=,k:-"5x =JfI=Э1/ j!9hu`e3H#9ы"<}m"yU|_7vA`1Z}΁E{YLzC VysE#(tjSý>:)г3p822>`=)bz6$!TY5uAhB]hٗ(Qka&KfR!, N>y (MEt~m%'3r7߬PRx0hF̒Ԏ59dGA8mZ~x{VMX\ C:Wk`#X dK45T`XƮ3aS7/wCx8@3C/wOklZ[?96 &%ha4q}n8=A2XU#wW\e SCEn`7TpkdzAHp#X /K V~e &҈Cbo]T=(OVe;>)۔ԥ\h1#2\*[5&zHNZi2l;T⤿Qѿ?󮦶(ⶨzTYޚy+LkȄ CH3+pVawiҿnB`Z bQn,8pZwK t$V,:$jm)X3miku%:oP=M$^y$FISM:bܠ1 `?(;3E^PGVރNGٜnhFԞ$0M4fRb,9:l}D2AǺ:-l Ji^k cԔ.doB-*E,D,L,d\sGTeILY/dب8Qe[-YD;̰Ckhጧ&/Vn^'Fz3mq;7d|l=7$\=roo62lS쟪ve#u;vPl$y%"˜TX}KsKt82]A׃0 NMf ],؜ɎYZ3oN8 vNPÜSF_3&YqrK}Mٮcb/kh`GM"ʒ@WOAb :?Dz]""J8첿Ɖ aDG%$nojXdCuEnNh_=ڞ@uHǡgIw@(I `ĄslQ=9 b(/țP@?!nGz-Cm}s0NNb\+E)Z9jخ/#L NSy`SR1Ҭg+0҆9Iπ"j&Nd^Cm%EK:n҆X zlVgdw]TYG%+ֵؘP^0t\E9SxUnJԍFAτ;q#?UZC.{[}i'S;*x&9or9 -gMW(ψbX0 $ũ.E™lX„qt$Xa꣠bӑ3MkT=&w f -XO#:Gd>a׺6=;ԫGq) $Q_R ls\V.]YI\ Mf[qaܘ]Lm8<ַՖ6d(* 3p:?pQSRsؘi dLBg"3gRq}q(j>!taĉ4u;4A Mc=JMrXHMKQlaEbwM*W׶coYuiNSm}dR6gFfD^Q̘c,!Jdt9~w EAA!23]/sfB3C~ (|x hD[O!fhlq{>K4#Ni+J ^bm୺Po%Ro>lF`%"rC#}{K,Ƕg*/Ӿ;"x a,ШQ,lOځ6X/w>ox+%ǁa͔`;ٚUZ2=h_&[zBr)ILvҶ^ 35w<88Y/ܞpBvYWXFWϱk׭׉ avDyk{aޛ œ~G]brYҝȧ ]QKL0ؙw94"? h87;ux?֐UJSV@ \ں/$!J'D"%ԯjX*xGs`'A~wl-YgǸY{؉ as3[EAGࢽ *JnS%-PE[t"!KthSᕉ7:9R)4Uu*INE>^I=XPDm(rcoLkuO]͒^Zfޘ]V=_Yafq %1 :+FdSJ.. 9IoT B?AJyݑ.twѩ_1,"NDJ-4{z֪fױu.': kq~ܝaH~cXbWKh sۼJ՜)C9,@ B;N)wSDpؙ'/q$ t\ 1?!U ׫ӟ *ZdNތg`C0{FϮS6T!N9dw/^r}~A/'}[ #N|٨Ty2g{YI ]m 9ԗ=<~{Z&zA+[p+pAWim8Ū< FmcePqM݂r!&1*9G 9Qh,ah(l;p Me1w[1 }/uID WOwjGoȷq˭rsP%pA` 9/ۜam7 {fy!F."ťȔc負vk$X}JTRwq |-m6HX冻/g ØnLxgW@IJWꋶKnS6SЋ4cY %(V*C| 6Fb_ޅ|ak/֎عcslq@y&e(!+}Ar( gN;.N}IT]sY!&}5gGkQoV?r .=0M0' N=Vå(bD7+P7=rB~ (nq=tT)AZ7}1JoӈuȥvdpKLlI4SgUd$dw [躮dh}ҐDDdĻoi06D4g,e|*tՆ2=cˀ(p+WДtD chs 9fq@'LA p41D^+ wk(K9.(E9Z޷…ifFYp:gKHp%gXv9Ad:g?"XkV #){j7,=>TtFGަbX٠߄Ö|Pw ePoߚi ˝>kIDn, 'xj͖cj6tQburLߩsZle+8C`f78j;d9I靪eKW{zs5iOC..g"*qb {<[ھe(!^`Nv+4)wNuNC|5UۛM>橙n] s!c13$rmV!U?*Czxhf(E"H&ߺN =܄B-Wl]- 3 T#Hc2[駏?NezC}% HuG@MZ/0$(-kvheX"?ϥlt\=O)2_Z_--7E/mxMe\0<(Bڪ/YvZIP,%YPO- (eͲ{;Q-Fus eEQ}+|nRpb0Wdƪx)BA&Z}sp2t*a ߡ!tk.d tX/Nx_xt$/VE.A<QeM _dP8ƭBS}CxY}Ob לC>]b+Vq}e#S LRc=9us){g`U5" Hm  Իiurԯ0L'st˃Ι@X]UKALh*gJޏ0N0Ð+:^pѹp 4+$;Sl t0GػJïQ%1!hU\j N> +/aVh C̓BU'3WƄBc&?@ܟV͖Ld |!SBsAMS'hAjDm >-NT ,F 2IVÏ35M^r:A$SIC$.՜ɥfnx:;sBvmm<=?0u%[Q 9,b dx,MM4zN Dɥ@nwE\ڛ_"Q( 5H5(%c!rnBYr^Ⱥ*KY-r_ ꮰ2@_`Qwv8ۨPB'٬sV!Pı'ti>ilvtb+H2Dz D9Zl,ji֦V#q "j!Ԕ#]ΤNqڌ I1@N6(]giY&}ndMEgtk( 'P8o{Dg7؝BT`PMA$b  kLCD~4T͐r׬~[bHiƚDxi)G ޾%IF FqŃ1\Є *oS>A(6Zv2﴿s&xCIc-JŞnQ_4%aª!8aI6Ӄ~O-zZ%UqW0*'R,JZgt)tlSG7*aO!{`idtp Jl=_MK&[ |<P^i4[6&h$F;SG&Cm Nc2@`F#Eŋo?[k@HڃlXףX@ě]G0sn2k$ˋ&W\;r¬ZO wg'YYT:!ꊿsaV:ϑD#1'^ Ry޲ 嶟 0hAid UQ)Yt27Z!&(c3$aD/|admy=Di1xg^ ho%"돬AJs_부~h#~E%'yI!S@b|19ߗavW{K* OڪP2K|!La OAύz=9rNefVsH`{i)F6O inCbEzZ1J7KU> 6lo".G%ŷ 1~I.t pZ' ߙ-sSǿd-FFh +  ^KyÇ->Hקޝ*| _VqB>s-xi⳰4G,(|c2.CBTUXt#$<(yGcT4#wT}&U/:-RGBV[ˏ<ћQ_72},`$TKqC Q6mq1İcv@h7 {+ij3!T; [`sHn\p7UWS-J%BOYWaBQ@B^ޯ@Jpɔ= J&0a-l.O,9MKyf!,s@0~ܦx\f#yO)<-j@d$Hsw_ 3)kiR/*zA=mgS9l-MxDbA]֜KN "BDs-)ܽ KwLUΆyru,}(I)_4X19}%B-oiw4C-kU:1s(XL Nz4@+ $GWz/6Cj6ˁ(RDž3crLҚ, p&>,kx:ڿ--po+Qq"C)OL{7蕥ĬgE眚`'"oȏkC.Mӣ|@~B@K}PhJpv$XV*~=p{I.4=|a7ĶvKbrK{oL$zCkBp Ps`{9n&a=IM%K>r:A*V/bW!B{'|^8]^TwLUۼAr!N Zm+0 77ZAvJ_[JvT&Yr CLo%{uw,/oQ^W>jAo%Dvc~5Q`.xz]4룚V5p=:C5k4ZZ7/ -3ҽޥPBbX}[a>;oۑ <5 Pjk?cdWkZgߵMWq0?^X,D['aq">`tU Kq9e.X3JҹN"J?EYpM6dj8+R-hhLd1[?Ctk@ߔ/'\Wi4V11ōսlqHf6n^׋%VS^GlKe^Ӯ2C4K~'P[1\ˇ Ր<'2N)X/2@hc7K;bv$8 ݗ8PՕ4+6e.5M,EZXP/lPMlo#'ɺHa7#fڢT)M\.Þ<$H0ŝ.vD8QWDϔ \ H>Cy$J*~sJ=3zW!M`U!] RY5hqOy;Zk kKeϢ}Wtjޣ+`IXՂ% !W0ȣV^BqXRl06^<%b`3 lr>PRU_,I:3@ރ+gDX>Xx?ؤ,{>}S>74U@|ε5m-ZHeGcv!p!g%09/n1h_idurR6RL32fZ0Hy Aн GטX bF˹ڔ;ebp #ޘ6a5=c}'R?]ܙ[.u#nL 8tki $^OvRAIa J]ugؼ`qҟ'% #-aC2IjBaަoRoc |(M6!M$?dZ8 ~3ns])$cG=}wbTp0r2,ZSaClb0Rv;,} VeŒ~"Ak‹ƌqMԨ8~V0u0jw{ |CɍI+qz.0A,1\>PDIzB_/ۦ"|)bjXu3S)RҤײ-Uؽ 5xcAl*Έ%NJ<]N[2PWusr}bDcE71N{D?zdth">0|9D#'vW5dF\|F@ ϕ=Gɤ񪦠жW4TA5 f|Ko5Q$'?|1MeEC;X=Jw,ŲؐeLwVNSYb RQO7xp:=e40e_o;d5diMD)gGIHvfw*cw}Vt{\cV!6wFw'c cOƯ9{L(.ϲ XAa4h5=U< $$x&μ!!~g8o=td+?2o;SҪD/](yU@kT6} VuG:ms\1t!e# n^ /?`^)`5_ .^LUmo/|,[y7ĕA=҆fzXllG-(> *dK$nšda{ql Mh"PSNʜ^ FP 5W{Y? ƊeX6*ɍL ,J|Cע&g֯RT"Y)TO))G db&ZrnCcM ?3@e3qOX>գna@o| tZ0>BxNk:4R&=i.' W _RFkTg*&?#ZrS?rf/foY/xzԜP1Ȭ65;Sv$i@o,_@T*߹_C ;r*_ȴih<xʎ q&lY,;mZ/3v.YYf*ǯPAqMj5voƻ|?=KGQHi[#Bڣ f{xA(ʁ@-*Dm1=U~X=Na  lyDacr! 7Zwle;HMnC(uHB^zUӀ7X0b\%՘ 4e˾-bx^ac|'7ߺ]<96,ቩ4o{b&AA{ךnZVjY/{*n 7{HshRNtAV _V#Oݭo_H8J]҉IAվ63s5&y[HU8_Б@%W-ަmaLj?ö m+LhrS_9L4iy&Ja5~Ac`|I.XlHJ~~+Ξ?X('OM:wd'e14SX"MBlPa*\C! )D1NT* (fB3aʕXE 1ê% e`I]yH_2Jz3ҲC{Gj-;::?!v2@gfʑ7D[ֱmxB9Vn0: o2l6KZWӓǐ)pzzP`z֓>(!ˏ`k/@qxnY@ꒌ*j4'>~eSpzxKb@>"7I 0ޛ͆^,eׅ>NfSUꓷYx 9%"6wᮠH j H`FÂȤ@GYcyy_Sn:kV [NEH4d0<ô$L-AFo 5u- :wvIǃ F8 ^-T؆yp5fB2Dhљ+rv^Ibr*]J@{d{`'ӃpE|٘7b~PāC)M#X8/Ʒ<72x +H%N U-v.6ܩ"M8a>l|ՋC)BY하МockR[jgYz*00`4:[ǩgu[*UL% ޹$%|Z"wS' ܙ !qjq5s9NVq'O=|´@L[yJ_o(t[oWJ{C7]k -Fy)v&3w$:MtyvKx?Bd%YHp5Kq015Aoj5?s_A)dj? 0`r`|^Pޱ&y滟Z+q؏8(<^Y$Q}l1^Љ|eR`O b6mh8ui"1jDIJ٨.$jxUuJCəx HZrcx!u{ ! -&$l_-^C%J_/^YB ;ѱϏIe6 | DOYǝZvSl s\@|XImt/6]_}SXV(Q4ޱ 1ƖP81*[VH%\J 7 nŽ ]-ms ZXnSb8T/S$Fx5,D'+taK1ʫopmlw?:87J!=ZD./g;6O$ݷMu-29Ϻ d<ӹHXj<(L%}(;gVs#q h=]r3K#Q&6mݙ[E.WW"s <Y>̨c1'eVpR60Rfe=wM$tZJk Gw*c>Pq:mLn42d \`[eʏUL mڞ0 N RA]#50Bly]{'[Ӷ%#LA=\"mU.^ӐWy%tƜUs3cOś/ X{-]j Xd/4Kw'&}|(G( MGL;[=T@H0QWaT5onSI])3*7!(MMIz7 "J*df ϦqR܍! ss Y55h(gY]`_fSHN'rz-z.2UFP&zPY*Ƴe^}>dJh ?`4*_Kx &')"Z6(%C;|(ю(f4_Eq*(tw0)9z_Cr`ǻs sR3TK| oZe;ɪ-v\ ~h Fт(fu˩Հ#1j$% KceZ Τ_e]Ndu)h_iKПЛkY{#/6v. ³,܀Z1xeJ+b"3n\f@lWlo,ǙX_z2ym/A_2SI1Eɚgti<1}5WS.P7;((0;Ue5xJI0TuG՛᣸|H:{ OFp&HdˉA'yuMB0LK)bwg)Y)6Yt=WcdFж%'G 팞᩵#3Ja!2Ly=N|Dm㔻-͞<f߲P3ܡN1' (i9;i`!?;X&f sn+9~؅>m)L=6HDwJM0PBA\ Իsr?cq xO0p ] rKdz_IKi]*䖕blēGfy_4F3 Zt"Bs[ˇdv04;vl{u‹z8/9Wv5#]ViHLr;37eJJ9LpwxAAO"1kE=ݰ<Kҗ E")rcܲ8;nN Y].;:а|>ɵʒ-^ [7735Dfʵqr|\L%wN1iUPfn 5:PWAH};al$!,-tLLwpnZ>;%#ocE;oJ*R8ʼ{ZP~y0Q>g\T\[pD X[#jO.@sFA_qbXʹp"xT,jFkֲԶ,$㲅4}jA?VVj9]O:+-wf ʮX oX{܀q_ ]H}_g{ _s1AMh)7Jd1 w| VyVzĈ0^˱JןI7uD #T dW=HڃFU2 E@~M+{oԿ7ӹEDhoMozKiZt96))p/t–Og8*։0^f鲤Vw4 6ٕZh\?09A *ryDZЂ' mIS7nu9P~8H^j墣KJWU8ñ}3l}}|s`1` gs{0p,1yaxstlk!Rx /EOԃY4^{b(o]] A(F2 {jN}%U0@, SZZEZM5ɢ6`zuZk|5&kEFoz0P!1:H_o$j/`w TR%RAg=|/; Y=3_@| HWibnKwЦ#bBwh X2}pifsOSnɜ.m-g+$PWʼ#ν ,hRoe I֣98aՖo, ETH]s_!օ8gA3w<6̉ǶvPk-R88ۣV=˖ۦN([.(b4CQS()Cg"l95,)Ofvz6Ō)H22]w*{K4w1"k/ϸqb +͝T?c7ʁp$'Zmg;R?