pki-base-java-10.5.9-13.el7_6$>gD-YMuN{DMݜ)h>7L?<d  D          % ,' '  '  d'  '  g' P'''r'0@(38<9:GG8'H'Ip'XؘY؜\ج']H'^bcd2e7f:l<tT'u'vތw'xߜ'8Cpki-base-java10.5.913.el7_6Certificate System - Java FrameworkThe PKI Framework contains the common and client libraries and utilities written in Java. This package is a part of the PKI Core used by the Certificate System. This package is a part of the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.\.x86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem System Environment/Basehttp://pki.fedoraproject.org/linuxnoarch Pb !& #-+,).*)&##"!81;8+70#%A큤A큤A\.\.\.\.\.|[!T[!T\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|\.|104e693105a0f33323a500b28140eb73edbddc312c59aff2af732bfcbe4c468394551476c6e1669c47fcfc7410317b2cd505bfe5c3ecefb1e74fecebcf90f871b2df657063377311c021e0fd7006b3ab5ad93e365860dc3ecf68ba0078a90481fdd8d5ef0c8813c633e77997d6dbe23557a5112937962d5ab7b1053de866027b643b71cec56efdc737a20687bb05ccbba40c3481b2c0e100ccf53331e0fba620/usr/share/java/commons-cli.jar/usr/share/java/commons-codec.jar/usr/share/java/commons-httpclient.jar/usr/share/java/commons-io.jar/usr/share/java/commons-lang.jar/usr/share/java/commons-logging.jar/usr/share/java/httpcomponents/httpclient.jar/usr/share/java/httpcomponents/httpcore.jar/usr/share/java/jackson/jackson-core-asl.jar/usr/share/java/jackson/jackson-jaxrs.jar/usr/share/java/jackson/jackson-mapper-asl.jar/usr/share/java/jackson/jackson-mrbean.jar/usr/share/java/jackson/jackson-smile.jar/usr/share/java/jackson/jackson-xc.jar/usr/share/java/jaxb-api.jar/usr/lib/java/jss4.jar/usr/share/java/ldapjdk.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/java/pki/pki-tools.jar/usr/share/java/resteasy-base/resteasy-atom-provider.jar/usr/share/java/resteasy-base/resteasy-client.jar/usr/share/java/resteasy-base/resteasy-jackson-provider.jar/usr/share/java/resteasy-base/resteasy-jaxb-provider.jar/usr/share/java/resteasy-base/jaxrs-api.jar/usr/share/java/resteasy-base/resteasy-jaxrs-jandex.jar/usr/share/java/resteasy-base/resteasy-jaxrs.jar/usr/share/java/servlet.jar/usr/share/java/slf4j/slf4j-api.jar/usr/share/java/slf4j/slf4j-jdk14.jarrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.9-13.el7_6.src.rpmpki-base-java      apache-commons-cliapache-commons-codecapache-commons-ioapache-commons-langapache-commons-loggingjakarta-commons-httpclientjava-1.8.0-openjdk-headlessjavassistjpackage-utilsjssldapjdkpki-baseresteasy-base-atom-providerresteasy-base-clientresteasy-base-jackson-providerresteasy-base-jaxb-providerresteasy-base-jaxrsresteasy-base-jaxrs-apirpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)slf4jxalan-j2xerces-j2xml-commons-apisxml-commons-resolverrpmlib(PayloadIsXz)0:1.7.5-104.4.4-54.19-510.5.9-13.el7_63.0.6-13.0.6-13.0.6-13.0.6-13.0.6-13.0.6-13.0.4-14.6.0-14.0-15.2-14.11.3\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'10.5.9-13.el7_6pkipki-certsrv.jarpki-cmsutil.jarpki-nsutil.jarjavaCACertClientExample.javaCAClientExample.javalibcommons-cli.jarcommons-codec.jarcommons-httpclient.jarcommons-io.jarcommons-lang.jarcommons-logging.jarhttpclient.jarhttpcore.jarjackson-core-asl.jarjackson-jaxrs.jarjackson-mapper-asl.jarjackson-mrbean.jarjackson-smile.jarjackson-xc.jarjaxb-api.jarjss4.jarldapjdk.jarpki-certsrv.jarpki-cmsutil.jarpki-nsutil.jarpki-tools.jarresteasy-atom-provider.jarresteasy-client.jarresteasy-jackson-provider.jarresteasy-jaxb-provider.jarresteasy-jaxrs-api.jarresteasy-jaxrs-jandex.jarresteasy-jaxrs.jarservlet.jarslf4j-api.jarslf4j-jdk14.jar/usr/share/java//usr/share/java/pki//usr/share/pki/examples//usr/share/pki/examples/java//usr/share/pki//usr/share/pki/lib/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnudirectoryASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)C source, ASCII text?7zXZ !#,]"k%w#zIRG6"il'u f%Ug»MvWjѻ7-tIʧk*! ƃ]f? +E$mE*\O +?:EEzR1B?U\sHOo1J'Yh7hk>o-+_a5qsҰK>v1c`ʘina/_F ~H[[e^Fcw Jl/TrB-&sV2476oe=r$l֎}]{)RYJil&>Ksrba+0?/r)b \_yO׀޵! "VJmbzqrL 2H. :D\0!c$Q\P:6i2ɇ5fY96ےuBQ>>I^L`gS"fy 81ֶðYd=\ms`rkAM=WȟsAb!=$D#Y[Fl1*60̞s_>Oa>~ }ѹ=gj7n/_ПչΘ=tk WOX|2H&؃!B.l:j~raZUexⷸ2bzelVzxfӘ~/6H6O3aoB%`7*GʳvwNE[,YM/;Qb= ,O7nwžS$<;Is¯u5Qc @ޞByI4.H65JW0L1AX4\H>ZbsKvC侯҆qy`&7=!ؓ\/ `z`7? u7$d#׻%NJڷDe]vƅJ18Fߋ'\50>9\6:%Yʤ_%kGNKnڰ@/C s/-5= 'Fd>R"P+u} }O*>L^X9v2DZm|Bjj|3C {ȏ Њnʫ1VqQHuxV25iVTj/q(wv.52Gr>^k ҍ|R`əe&jTn*Ft!j?Y>w<6 Qb_S@|O hYm"9!IJ=QJ$6Xg&v~$gAM `4F=.o~Up"%鳯VP'x̀S UoK}%C48f_7Oh0gw*@-xR5ܔd#xRB|[m95@YRD)y3#IPAPnj>|EJ5<#cL2VUT徥9Jъg=ZS}޴Q&j*SBZI6-;MioҶsS -:Njs'ۇzu44@v4Ȓ_jJ7^>@~- 1wqaroeiI.r4 H gGixXZch&MvE{Gyi2ll23"FMl[b<{rIzw :Kŗ}^3:-.MpoU%NNt}a|^a =*j.1y" _% w>R~P-Պ&f{-~b:ahdWRל.t`kصT]RxlUN*o2};$}a44H,dB餢ؒ,Yӹd⸸xaB ^֪lTIO س $d-HeUn[dU`t`&tiT9j$ .;d>^C˞cU Y6w G"q$SJ4d5bʯ^[qpp1M3bQ6`xG5sI&.8MDttݡ9YPڛ0ŚI'(RQ\gQ_9_5XAh]@syy$G9Z.)*X72]Yym ;WpMb?A 6#S"b>=ME㚱 1Y :oG!]5CJJZ~jK`=1Hwڼhgeg,65څ\&ޥU`J Wӥn*̔`I5z!ũݴ ?ʀf mŌ6õLI ${DoU;J#{[Z>$v*wT(+J{Y(&wVwR_%5ɂ\A(jciCGn,*w3iS0 ViryJ|Y**s>:-ic5VEe%#q {#FVU=IEk7;C|8k֎솆«I;zԝ$ebj-Uuo2˒n.:z.9xVT[N35? /}D"]}Ko`Q˗B'޺,l&u>>P^i{$g hj? tfDhv,h⺠s4Tei<򃳈ʄBBt0&`Yn-:Ԙ10KĒIMk\U1l< 7tȕ=[̯# ):x<C U+ GlJ);lD !؁ 5 *ndD1ʕ-xoj P;γЉzOS"Q6^Ff EjX;W]5{[kd(\)3E&O? X̛o}&,*["<aR@Z7{!A $#XN6^(%nl)wHX]4>xzY`ڀ*Rgg$9*pCTW>#JTBv >9Lf guXx_A(5LʧhCu)!6pjm!']&gGt<$Ny)`iS^/L׀":v'ȶV*ʄ3G4iurD,)t,ʅO}g:|q;A*\vPBQ2N7m(RphSSۥYńhoLͽ"g,(Cо$["m[]ƾ&s>Uauy *v#[ѡ<6fv?ik69KКhgA #d. Lwo]˦O@$LA=щk? -b%]zQD\aaoXI5"o2Cx8 $B8ܰDT|75jbQMX<ɭRrzmQMW Ë!O?4ض]0Cޑ>uTHo1\X?&m~Qv vnҲ3 mcIѱi׉+N] QYo/ c( KɾU/"Ε\IW 2,iVoLF-NjAPjS̈́p8]E38`8wAلELj}r@dP>`Ss)3X:9?8#404GUQTkw^iSήHRC[ {H_p/t6P!ojK:V5MȿK)gκRm(_ N]YmYhUKo!#icVH2zDnl>].|f"bOd~ 1 `'r'7?K5Z 6?@,8yr-'Ʉ.ʣHkwﺛSa}A1Ž;.WԨe^I`=Ӑq ᐽ } ۾aI(yד,Dt;3-VўEQJ=":qN| v-nTʞ˯RDg#)YQœ?`c^Ie=ݸ9Iȼ.lA}( ^\9R..sʼn<IǑ2ֹ$I)7G3Q+[)dPycM֘ʦ (_gE(xm~ vuab6|@E~.?L5XV҂a6'{[rOEW8a-#Y@®ZGoQ(w&(\`QzֹdCS0x0oԅUMOiBGNfu!0a0S+pEـ"K~lT;|cyPpOrdi #CFWTUS1 NK*N2U?:U /s͓2!tO!Hl/ט@n$%u,?W7VCλMCM ;x}"CLjms)k.qxg)ڜNLtKFLZ~'ϡLABǤ&ρI+_P>8?Ti6'#9س 0qܫ/ M2]ɛ=Iqړ3 4cvF-}yT fp@wh&̟4iC@ͫ8鈷{hC?~sI* BSZ9\MR xH;_k5k:Zҷi]嵸"N/b}v/\Edy#1N5j\0LtqE,2L{Mdk]C=^̙+ꁗVRe:p>e6)Yf#yݼߗ- lP\3-K2 rX*rO#\+{,05*,)}DH\͍F^Fv UHСl@=_P"Xɦaיv8[!T6>mJVT];Exq›y< Lh˯ )P)(Sm <`oZiU to9Lh"l[|I "K/C_t#ʍP=W[.QO4W!Z Ce11p*j3ԧ'Ei@R!%%i } dlh$)ϙq{ɫ;B܆+=Wkߵ,yy ĵoh&==A :*Yl:T:E./u/ H6[ů8RGa%кSڢ0нM#!e)1끊 :-1LuM|D4b2go&5S24ֽ`GkVO` }_s^ .%@ 7c[t!@(!E`TAKYʆk6J?&Yj73|9<1psWUji%tsxepzIoD+ٜok< n!U`ӱ}+νW#ER,QGѲ}d[:= *X` ڞFu%v ;hSV( fM.w(=kIe)("DO΃,$ӂB+͛مQjn/z$3?YX \Kt 5JvVrᕠtV^Ė uӖNjώ%)쬁\\"d1zXئYvL4l@{bĎ 7 u.MU,+—`A?yȍb$zZIJ[2 [oFLQZ=˓Db)+zp)Z7X<ր}6@rueIu#|,"(ksDUmxLׯʳ44ap@:YCu`ŽkL6& /ק-H]H]W3l>Q1 gق[Zu(R孊*٠0$SHYS& xOfuo~ cϕHUa*vF>[,-A*ԡx}з5Hixs {sSXT.NLvVH=g YxF]il1yOcp|1NjAɣ x \mV6v5)WȶiJO- {9RۏOfaG zw>bk'Ԣ3:FAcqUUO5!Ee9˄=zOD_n8;Q4sE rpǡȤ\M -nsN,@F "so_aBw~uB +rqpgF}.P$ KW&_/"P%?k F?eJb <&Viy(W:XnaO{I:=Sqe>Gi[Gs84N@ބ |Vc2 K;գ-W6B]kMгPğ0yRc?̅HP@ݽ2 WjT:YZPclU%_~O44i󒚁&uu3;RƻiK:(Hyr%< ?zL<:\-(>I%Cxa3l\ H-{R [,N ׳ ]-K^o0rr#4ɇ71 ㎼i'VWWijz4HŠEt',Ef? Dx0m=Tg5E,HM=IxqA 54s# O. rxo*ech.aMƖ~ A;1mdJ+v^1w`Ųml]u v}])#*f*v(a(? %#ga"o  FA9%`^䠤YCj}R @):OЎo+ޑ@U_ke_ʆEQ7+K-e̓_g+RrΦW\(zT^sNQ:YOj37KhH%~V" r/scq;9f"?ɁLeb9bLn\YT^ cT#\0Ul/,Z!Wͺ%=9!£ݳ4St+ B?ָ@)-fJûU#nCH,m†=^E; D(y2W#W0uL_QH%}47oܻL5@Rb?>BCC\fj%z @8X%T772C@S#|GjBKYW`?\v_@1jWF['5SxehG囁5M~ *78Soe/ xn`jp-n'3q=*o R-r.ݔېc0os'6E⑘^pgraO C\)2^ްhH'!8i#dL"٣=(#pP"jQ݆FG5^H5@1m k?㇡`4_k'ƴb^xm W[XʂWLl{-N20y}`9S(:JG݈Y*,:.b.a I7 kO2ecTTD&9]6Jf~ %s+_E6uo{@6)ef?va5LJ+~7j@z.y"Cz2*}~>Wj0#xcy}z刴/7_}JiwV!EH9" =CZq[&'V>$Z th8K?O}#Q7::Ȼַw̄(d\ևm҄k-O$р;ZGGpȲ%XBXV:DZm \@!|bc_ [azɷ;cZlO_rp +pl^Rk"Jr7o"@~j|G2{, ?҉2cDS*%;J u ?n6:^'_c>a]'h%'ȠcTR%$AP@(558jr;aT1YK頫sMpE/^>tpou7Hζ f"S1۩DDrE`p  BΆ0EeSpF95Jmwff%Ό EL_ݿ\FgѠrXnP*N=6r ;!6S;mIxI,/ǎOZwKNBRO)j^D$/U-@췗ũ:;- #ROV{vETv,宬n k&EjYt ز}zE |: E{z`f\xοvXk5؊ö/1Og=qvt+DP] k'3tf.Q!tU7a缗īiZ^wLg|}PXtN!4;Lxק$Ԉ3PHX}`ŤM!E0!dI"wyo;Jsmថ9L8ٟ{ cJWIBC8;#h쥓쐳JS"g-S7]0 .N;陃 @<]mr_xkZj%] Dt#N5)u0Pnq>Bi`f(s4bw yI nV-Gݾ}iV186p ťHhZlR|BσK%c4vnyL2B28W"cHT'3o- (t~ 4l֕cWCBoҺ8{]Vdry[7,aj`"4jb 2xʖ@΃vyv,_ܘA{.VΕVkUm_M'H s?&eGPhJaD\LkU\Njyg x#{[TpNm&t]?cOWuɋc҈paEn@$ZZD"(2P mR9s Gu%ew=UsxFD j{lӯfI8² u[J׊s9u@"j"0nl0DMxshf큟&pt uV; 1-FURYWUͻ2?;GlzRУ?׀ʒv􈨋jotĤTK]Afbb!ӿK@:>o;?^P6fH>6ڌB̻DYn,)aluQ%:⠧}I4C ƚlYu9w$$HjbKXE;zM.{3.$Δ5M=&ո{fe<7*BT9a-Zpu2.~wDO^N-ڌ4ASCqGYk/I|9v-#lw2yY2ԛÐآv"' PUOT+^ zp86ATlإu[~rM%gn _a*!r{A4d1Q;v$!2ʟ~7)ߤqvX~U21o~5)Ҫy/H8lnheҁ}qNE dZ߂wQ+O:L9wGK\|I [9l#Ϊ5V<-8L񊶞cSj8@fg}A<ӚC8ߙd2׮ 8UԢH7UnOKl”BlAjѯ$1T@QB$.P-0{h)NaOv)*u#za+W$v,rej:`VUhܻt';4ڱ^(Gq(T˜;\l-V` &.x9#%MDё"po4 =&CmJDS:2"@-Ӯ,<Pt*\{Jِ7|P\XJ EPw2 o& [['ᱨ~Iؔf-vϠ/qRa7BLeRO'ʍ% aldEC# ?ϩ,.4~eyTDg1scٖnUykG$LǬi)XA½ρ=.LBFOeVOsU9w?@ fjsv QhDQCR}ӕ]RfX^58!Mw'6D2iI-~og+ ӏ{* 1IOKQ0|t{G kqny.EĠAUsHmDp|crT< +b"M vzYRYw0"C.lxwypuKA[i . MY^NL( $^ ,-=Wґe/4%ٻ Z ej:zlz,І[.)%ӞMeܽm_zb|#qE^pr_IY.g,=̹_ op Ha{i*kkZ*Zh̐'C9tpD8 F1i)(dn` \C &Wj1u=$2GԦ'hGоl;amZS]ǔs#Q2_LЋ9g8jLXg sܠAUܝ\-٣07&3tlf`Ax@L yf?80F!~x.`դBFZSf92An}X#UHF8It Ao]#_ \PyBm9lRPzj8̰iSdSx}Y-b.oM!!|0{;CR4o'(=2x-[&48P|Sz 芢X0o["iW>t<<.l-?#2ܸғ5Ez+@5^/S@l ߏ"XHNk3}4RyvԢ` $~{9 fԑaLYdȹV]1x4mZ(.ErH!EU|p[R\ڏ=4 AǐE8M瘢@FgmPT-1:5[K~YJhkNb;vtqm8Ey+3Ht?<$*F;[r/1.>;ʃippC{Bpq&j.a;n+{/&~ݬ6;O72/ *gqQ[;(\GvHuDN"mRWH 3ֆΊ3w,p$mH.67 f"KqhTXM7bM&kO g;E3~ͤ~^Hi(xQUk#I\ #ӂU^Iiւ2ܔtQRns &rÊKR<s|\P·bYɍϹ]ڞ!.F[JLQBv\ /6;s4\h r <3*e}-V+f*u[@vwgiK)05y<,]OO9ai)6+\ qa+en.5'vfHg_Gf4\ow+욥c)].gի3 OM4 :&*v&70r-kiSG#L/CofbjtImLwVn)DqلҌ9C"3ܲ ֤WbLJqy #fW^ "BddX,SG X0tQV!!R1۶J_ө6 KmcCP{ ?21 3+o pG"A’BDd PxiuHHз΂|p?LPH%*tn |_mq\Q} eZ֦g\H0l~dC)}Zّ&v# YUZ(i#RčҎ0sy"tq'.vPc(5C]LșئTi-Hϧ~ TϹdq҈waƬg}T!(|KtK7변tErl㮣G Q01dtC}榚B?օNqEAy_Tlh3E=yeh$fY+eWEgH?hɃR$H 'lBn)1Wqv0qq>b[ ybXxXO Z6(Hc(L'&|4ـXHy[U/xO ,Q0 A6r)i-3g9trZ>ߨWW%xhjZ{6OJy<,w}A!ФEG̫pƂ`OmQ=Fs@b+& RJWV%<#U|>TJ$$'_\Nq*S|(i֗`t~g;AUMMsxLttQᓶx0*/I#:5^0X`4R_2(YXԶ.k!tl0h,Ұ5NQ>~#8PPsrV$dE; F-07 lRNh#lvb$c?Y-B^#"Bv'u6w_Rab0lx-EEQ{/f_C0vш YoDBPwXMi)ʤE:S&OбZ.d(:Р _+ }3b۸r}bC['ȫTfd+ViV!VdQ(fpl8*9(&/G\>sz(PJn~޷UaIEPu#[B*wκ9JZgoji|VW=!R0ľny3mϫYem|#M*$5B'Vh+9٥˵mk}9Z\-@lc/M0I`kDz?>F2OB~G Gܾ1NLi*HTb؀D wkRKw_fξ 7a)v8! .z悖{ I8 EыEa%nvk̨.>6C s$T jlD}8U+܍2ڗ5q#^֗Unw-VI%yw䊚.t@ʑeU ST}ܪltHNu&VSk^9W?:IAxNt~KƖc(Pbw*Iei_ r_λK-6vIUpeH!Th~TwAJPPCսG@&+B{+g,1 (RiNJmH34h_!5RӸ;^lG)AªzUK~Ci'ãҀ,ݘ*} Oe>B ?. 6Ut0d<;ۖ+_&R5ڧA) ґv-N6%šHUW=_P[:u,j[DGI 170owNOf=`/ _pDظ$z/{{Or狎+042Odvr_#"n=qJt} oT pfi Rvdg9BëoxuWڿ 2OrXUj ƃ'=ƕ]O7sYqކ (./ۀ#tғ|i"-;2غgAg)W´o{X[Rrع9],RrumQ.!ϙK1N4">#tO&.xWZ̞HyQ-\ .XTvU5kmG=Rq?={;98J/XfY3R0, 91iv@E_pS' nIqc똔D|p;WSnBrSW ˨ߑ C6\+AFGSb_!!d{;qH#K$3gm*y8 |(Ȉmv|ZH>>cKrCK `~>#3dBPQ/n͈ b37]w ?H^BE:=}4u/94J>2UΞygÐJ]?Ɋ>;M9b $vN ],34TQ& 1[rFZxD!. 4Ʒ]u|=o95sqXn2=5m  !PwKFA缾gXjyi w_|13L| PsSmЀV/6r2ٳ\u1dGLVf)PH)eə?S%幫j2 \DZDqN /30tAEz>8UfH[gMHkw挳jÉ oCIחĂkY|v8;P~5IN^bwVG+iq O*o;`6%;C̋i%\_6?˫ ta+)ˠ _nTZ&XNX2.siSB:$)d#ryVOa9ѧ_Apjy.5S@:pS@dMY(.[П^w8 #{DUqM{FY_ t,`,ɥAfkqk]y6i + $P;|ˇ*{l!NakoM]kӀ̱\Bz~nU&f NWZ&q?tPTul&Ylflcsp"t8.U7Y5"[L-=lv|:>,em>T$"NHt1n:?ɫ*k]mG.0l!I3G}͖/|# qj &؋NB&}OvIoQO2\"D@]:ˢD `y$߿ WAڑA '7T{U/J[;#*cM10(wɇuېiW_mڿ$& 1d,&i |»5@03S/?ӟ|<( Oâ[d1Pμ,:!(/LmjQ6?pAQﮥ?VzUP4tU[(leCg;g|zC%Mx86q-[+?yY+~Wg^&؆vYCRUCQ"e3y(u.L}s#F,9kvn'r,mc@k2<6\>hv[Ռ€'̫p7SU{${JuW\Н8󹄱Y!|Z 0:{N~j9(vʴF&_Tg_Řt $ +`mSc $ΉO 9ƪP<_o>fWA}UH`Æo*W864Ss–嫲$nZ{;P@t)* BЌ%P!JL/m@N1V XrMtLjɗRLJY±ܲ 7ӑ{':› \PU Sd߽r V!0y.Y}pQeIH1{7ym@~9ٻwx0 Fc8}Z5b ST%7_NMTo}w|WA~װ R$( gm-{84Oɶ+}t7ǴLG7'lIA$Kt_ ;. #*QqI8 {m};2Nק?9=BL8 5"@ %6L"WH w3?t~$YDY?2f[a @"cE 5u:|dDKĜZJ b{߂ڂ[y›DT3()gbj|4W$\S!A?ںij, waim%O 0 U3_:60!q\h,v߹yG&@jU(Xn˔ƃj{|S >$b (4&gH%u̠S=PLat]z0S+6 !ն~3u]B$m_W䳯Rߣr? UJ4^l[hTrY*E0v3m(!O 3z4&OtlD壋 wZozqD`T0I,qwjq9$L,no,#Dc$`1nP ]ӦӗhҕKfhy N G.fx(rQYQE7]PҤo"vy@;> 薡~1; m: R'syeA5& /.}ZLAN4G|G$!a?+κ !;,v,S>H) $do}G=djNvN2PTB3mH3}ܳ~r g4|ieE Rn١EK"9&"[?>^/cHvE?lF 'F(Qia01^?7i؟'$EÜPN d/OW~-n"ImJ@Yu,{DZѐQ̎B}3LgkHa$%1!*|DSMmuܴwD cbUJyUSŢORs*1M}'Y4XSvc; VJKFz-ܦ86^B;Fh&v`ڴWʅ`6UH S/M[xH.=Z,jRYȉțjinCޅ ۦ}T\Os4¡TijVkV OpeG%{^sk1c:isz shl2IKfyfg0n'?ql;u&Ϊ8IQaLxB:Hn˯z" FW% :|Qk  ``$ٛ0vOcyKy<NJl}3{3οKuL*&KL \ QHDr vC5Kh?o@01dBFL([]ZϢl^Ŵb#>:Z>R'6kȃQm% )XrsF+9s0QVU`UZV{ܵ@ E>.JKom@)έhiX8ml2g`?܁ҀVŐ];ҘQc; DP&֔?+ QYarD V*loz+ӏD2IEǼnt{pnf-ib>!8pږ14ܝA+:~+iG&i 8Gy i,ĵ_=1¸Iw^U6[P_.- i6`l؇&h3T>4HXW$1 HD oeԪ̷V >Jk%ȶgv^wuu(? xCɌŋBY$jho2KoѱߵDL\cn-R JDT_!XSUuN j9Gľ  ?]68 IcNFn-o$vR'a wpPb i6p: 7CӮZW4K镮ì+&B:9ou 2V.iq,RXsJ^ /_U~ dSHsj1<?KYIhLA3&?B3=A ",9S0?8؊_1aֲh%@Q,V5̋ NItۄyyiy;oFLH'63:$vץ8c{ 8}>“mOYcwk,ۅFUeܷ2x'g:tQqpo{?JMFKQ@)U=@nr=DġlN+p/<…8Z|\e-4 YVE #*[[sF \6C9G&=@s2!o%H.1( eԈ-8U 9.x;8 }}}iHv3oxmA<ki&gX <#j56`BWip]!ə-<sphd|pgH^L5S*$yP5-@$J濽ȘYŏO~Vh5yz}hADϼ.Gx)q=JJe;V'xmܧEΈ "L@:8@[Ґ=y˩T84P"LLcTk,Bu$DYFթ"G cR$iAy^ea+2+3` Ye5)3Ҷd,鞿Z$O;NAH3.*2a] OӍq%C,ֲԪl[2cbV1NBtƂ-g1O3~ZD `:.9D~Y0 =Zr,DHv.(R3 \] ~,u>* i7jV"KLiզ 3^f! s|ЪOP Ek9OZxDZUZ cL>DLjN\3$b,kx7IûW,busBBH"5¼hM繰*Jb />!ܬr J! /gl^~)pY K_VJB-'A42>4!nˉ%gPSz!+VP A%O`ƄVCy"I-Q8cI8)dˉEa' +ġ6ayE U.;C5[ =Wf%!vЪ͕ʘXW"ų)n2. | .RK ]aeOk0[Fߍfv=}2,Wsih?P Y{ʏ1dI O r!xMvUla y۞5 8h« MJROVpL󇮉~Wn #$dV䋣 ;8>u4A!*E} SYmKG֭ݚed/3=i:$jn{6" imtݗ~hX+YM ]$Ч}eSvR Bxd~3k`Qi$3y O:`cnHpѷIaUGPim5RKБZĹCUWEl$Mپ$@Tq^/mhclTM3*|cq=ؐ'ATnlq-#(VO0醄"1wiTBWXPqŦ mJ kHP:5v@ށ}x%"Waͣ@p|YH΃+u{S׾ʚ0ӻ8&4~1G o/iY1;g0.\vW,?^hZI ,epZIALSr1\"F8O.jSz[SN1N]\L*;[IuI@mĐ0JgjdZE#h' 8^)NFKw\ВnMF>N촯Y/_o!O<UDm$)<ȓ„t5xCLA_SÄƴ 7u둚 g}.J$E)sŖPL _;,n4nNg:v_waxοۜ:d{DSo8Ss]x9㮑b[-uJ'žuI}"d`8 P6aV$~$g ўz"˿Ͱ3FoZQR#leGc 0gŘf4l{+2KrJö78`Ϛh쀮U/'T'vŢ'KKge[l"W?GsȻ*L b\]v%$5R#%8qFCJ)<Jk hk伬i3~~zlNEJgQW2+-)?/WlC@1 0ɥ'Lz0ȵ- :zX =*_6ΜH GPe ?~Ī?:4D.F;yb0ߚv8T̎wlj22(v-f="ٰ FWDoäV RB6XKSݮ)w4X(6/~sG&r ߮Pm hm 叧_~S페&Tð UхMJm=;k O лr ^qI"F?3ɪ] %m/GZfpѽӫQ30]/H䘞(S$$#[ywm_DIh!j\!!eM%on[HHIֵLph *0)h~|3I9@\]B0^ynZs5Rk~$ sBŧ"rs@^nz4UlZя}Xp foޯ \6 3cy- @n$ݫa^7{̻ DA14u.HXDcΗU`pҫrأ.{k!Mf{VkVKr})\kXY)&2=ҙH5D&HxF.j"ĸ[rxeWkYd<kUͮAȫ%(a}/ii`:w4Zz6+TgDerk1Vi"%!3ꙍL$.u<pZoBտъmt]zFq>13A^+$n"=w'mY9`c3^;$8gzb랗 ׈Ol]~Z5J+Op-բ[xcӵ>ɖe{mH$o]7nzvgt WV|EϼmSK|!8yC\I7uLaꊬT EYDj4FN{ak{5뽉gk&UIt%--Fʈ\&65ۙ_|i_n!ߔaYsi)gG9>q(,4BԤ.*]ld; ZvJh74(r.u[28>Ƌ 0{'.1VrMr%;\>3k H8'3Ɨ xTq^G=)Ҽf%.b a}zQAIx?=E)ta )L%CxiM,u$z_LYlK yH+|h*@!F>Z\5_^tfĭ~]>fԮzڿ#wk 9rʀ(8 vr+iS^A0&`<{^}ĪLQ]5P}psIJ\ >k n_7HMH缥|9Bo{PK xmYz]7;b?"l{\׽Û,(%'?AL^A}UQZ%s%Γ&zFM~n^H`g #oOrϿ9<= љ,jraV/'k N;f#ēӗR(#s 9divVf]Dpu 5[G^fKM b{x>b_Yr BM g1SRJ><UT|9*]VQ Ūѹgdf!_ɆL|D/e˿4=B 37DFQ}ǻ|fx:K^a ]X=8)wޔׯ5GOB1m}"p; kܽm16M8ƱhzBhF"<6HybgV}YΙ1F:`^fJc- TRJaT\˞h_K' Q8~͋-_ ~sQ3gujXa$cwK@ʽ/Q뒄ijfYikЭ3(*+o -JҸoRW!󳄛q 8go͌9SAC?G?ܟ?˾}D@+nXd<=Հ"':o?;9(5 AB2i,ᦔe"9@, 3P^Jiՠ_5nd,a^Sr^jT W!42BS^LҮ2iĄUw41Au+Xμ>zZx(xF610晻O|m6O"Iqh//*/6Brհ dR)~ *՘B*,-s#,J VyKbif1 No )yKy7-m:BBߛM!o7r]Ҙ~Ey3'Ucp:-S i5ЋgB_S >&tZmrG 4z?;Z^厢:+FV/_!z"b=5hr2 z'ÈJ hOA]D5D޸Clm|y$7`bDŽ8|sckԹD1 % )($az UQ_{~PZnH7hu1}:ޟ#~D|q{Pc÷ Ny̽D…OHc-׬P(jꖻnt$f;A{y'QOP9;-g;N0PoPae#oY1!Un" ҘӰ(Pa K=_wHֲmk/cEoc!~/芧HAΪ>1 6Ѻ`(<Ƹ>_zsdc 7jѳ<*ﵽf}FSC³5rOپ@J1H/ـ|̺1(WRцfb!H-Ơ9ToQypտϸcWt1n_u4mJ;YAZ`91fWjW4@{ E"ɵ*~NHU,Y=zi/z?(MiĕD+T|P8 Ư Ua^rja$yyGQyQ?&w+5B)5~ xߤD"DWV ;}|4EI-x'ra|":Tc/`vA nP:f Ȯxq&6ew%cBfy^%l&m?w1 ?23%=)n릅V*eqQDY'UE`_kᚌ"}HG^=oI$ &\X_RCQJC)I` Vrhbzu5Χ^c_ gqIfaP"^1.LFO4Hb⫵rlp9f,ѹ gf[ i!5Ga9G\TT7ҸfJX\-/r9Qhp&eIkx&g0h*|UL_}XûAUrQ|1 % ,|F>x1@)nπ{@Q&V*L=H2EN\M5e!NYo +-r9(J3dWpZ +=pƱ'#8*W6\H-w8F,4E4 Q(yWJG):WThQ)Nʄf;2S$iΌ9 r\_jhܹ"ZHzL'ZdRyYfR Ǐ@}MvRUrWX>~%QvQ>  w>`6ײ1 a)⼌9jIe 0CÔFB\S8'q@H4ۇ7W%pKCb}{= U["ǕLm-g51p.. Uћ<]K#)dFOIMo2@5t<-IFfL3GiɵR[K5;9mq,,wW]i4 d8AD*f[F\ jXaOQn:DnМwՙ H8Y SBBf8=,b:^ }]%C*mm񶚼Bu 4/3~R7P(qy<`}G@;7Y͡(49R-,0@TLn3d7`y :hsPx"]RA>n~cW|G9@7L x ϗJS"|~8ru$5a2- Űa۷aj؂ gRg,{m+Ok`]\jOcb|Hk]7sLu>wdQ;PUey2`uWc08!hB]u%QW]kA"&04;G*evĠJLU6acs#̟-t` K[5A<>? n$`^3HM#~Ygi o"F*GvR'”9mXSϠ6w]WI:8O>=lˁdq07a u27މ~ w{ o> t@nb+&BDZ28 tpFN&GW@# RքH8÷Åoj,{3r^+b:XP2c.zH9@Gh]kN0'* _`tUۨ6LQ֕vJ)|&E~~3T,OZK8苓5rf&L;4)PA;"OJi{$~W t>hCd|3gUUY趒c6KS+xEQY%;uWw;J׶N#J>]w]=N#.ܝN,zI"!{voB9Ob]׺ )3jψ_l3]Ԓ^¦ >-S92@Eg^]mFLpdY1Xsk.:JƄL x,VK[kUJt@KZw>VrrݯHXNW0K^'T11b_FRP72$4WcPZRcZ O604՟hDcUE׈ &O{U땋'=S`5+y:!5]WMPFjPKmke:O2.݌ sZ" s.xWETS]*rs54Zbjsge2`oxrX]O6ȕlFx 20Er->8XC2U2\Q%Cڼڬ,1i/̍^@=}@eڍ@2dwp}6;t/z-ع&* NdS\uI>OFE{0*܃P=!Ƽk=#Iņu!VcAK揢za Qqˍ:U|˺W˯L7}ȡ^s3 V=cz֔v_?j['A\9{$n$r;"C#B=‰Y.;9 O裮Mmog?Mk^lq,}?w'ꔿ*,,Rj&FK,l6t2gtX ?$ -i+0&ƿ\FӴ5GO+$hQuVEhzU׻ƤFKz{st|gm6~3XaPZCmq5hr4% 䏢@qeNKyO4IK?1 +ќ|ז)N/~;/6Aa8s>vjG,56.]Wbh;V |jL@Stn 0 P^F `L ֆ U^Zs.u/7Ci?\2-Q>*d %$2'+S ':u7˽O~Y~:zBqCFRHUn-oϤj~#y1ɈbpP3J2 rʸR|[~1P-o)6xb:GD!f)ZmP(jJ@[~bȎ4M:]퐞^@fj 5T6h 662R{/ňl[P{ JS;J$WOu~g(v8"٤p҈GfX̧=pGmֵz|5Ix MU~F^2l K&h߀ zׯh ^Y.T[]DbQ bXBޯ_qL+DeHar$q jAA[5Yn絮aY}~Ǘ껷FCo[ho55t !ڙUNi5pEgSTgh' 0D# jz#n\-`]Gȭ{w쁒 @l+tFc: L+rRTNW{+2ȝKBvr.( fœGvr;blNl/wvx??#<ah[R 9gFQwMQ5C1Y %ـ}߃/CRL\Y'ԃॴ:~dCbmMZw2c??IM~{HqSI{ҥ.Zʣ*:0d7zbC6ީ]jE)^# ? G?gxRBOEz;{A[~9n z?7ehG=yȜW*6[ VšH3aUTGr޿yW"Zd _fz,I.+=@#C(QsjXЧz{'qI$&^_i! At *4*N< V{m"h̓Mdf ֈOv: [nFGnʛb߭zf+>@4(јE9sSmT$(kpYZl s)rsh'7HCN.&Q%|fYR;2 8(Z饾} tFx1 y#`fuec=Tf?aJ7҇Y'n6kll% bfOץMj;~+aYؗ }.B .a_ilGӈ;,[-$PʑXew`B 0ғ-ėފFH+<b>melP\$df!E!]ŰOh |/ ~+`])oNv2*? E/߰&8G')1^.=s?}}}eDy雷u`7gB{4k̿\E>s_#knU JTxbيT*5>P Q bY9R9TJ\H: ⲁ22 }M Of_x.XT. LhpBB~G)}.j?$OYmCJexspU*,K? (&";>l5ɤbGdrZA _:]&˵RXJT]!fF^*aLr=Y}M_ E{"9*0+x5R"_OUhjY?liKV#< ˰ ' p]_ Dmse)` TUQ!IMS --▘gt_oS< 17hw`GzCK ލq[g\CFC5*#? yDS Y9rҗas6#- X6r`$8 6#t P.N>AD:㲇Sw$-}>Bq*aBsOL*-n[k02&#p!fLՠq!H[er^ٟ*axQhmE΀: rY]b}`j[g@I^qO.1 d) OhY\B{ez,[=eIERYگDif4 բ I(v6i4^-r`jʼny^嬧>lDq#$wLE]:Ͱ,6xyv){8LrS9~8%GYwϹG{00;=w[^OC jcisf'7`r2vCGtŴiDw.퀻XY\=a*0tR}/*j#t&gD/UY sׂ(vdJ@ѳw (ބPȋ"p!2-;\)- qO,Q9rLb{22d箫f.[ku+Ը͕Ţ:TO/ ,ym2?a漹yޓRxU=*]Pf "w1Z>2Y'4ytUt==^ b("|[wc,Y76;̲6/VB$XF y$!OPWҲ2 q21^ߗ)k\0HfJcTBjKV3B8^$GFOCؒp0 AގM*7ـ3L͍&xB/yN`,MJ,U  _q.*$+JfwUi` xW(1̧W0+ܠ5Âb.=wg0ԲscVМyyq1 BwfBge<5B0+gX ||hBƏ-1=KT#ݗP5J6%Fvr(pAA5} Y)_5^ΰRyX~jZUP,$V~x")0YHCbn,N."sQ"gw{2fͿ?"9dc'XXmSLZߣ7Κ/s^ce_;.B@!2'An܄ IlQC.mk!R0`E;.6 b Բ3->hL8ND4^y"WԲeZEϜ'QiyfBO \Үfx;]%dЇ~HH6<0&Ol*_}mEC:"VCU65Xi=zN)oAЋFz@8njy|HQEX {M8F/ 7o(GߚD4'T Z234CvEsiS͠%۩*_6[L\ Ӌ13"/D;%OFNw&5p>_-cF_gg0 j d2.fӣM:_ 1L#'}׿(exxWJxǕkDiXuH'`v [ Z/+e@(3=Ue2Tf-lCg9Js̟KEl@ۣ>rs_R]{L^ŠVw`]c,8Iܯ>6B>K4{z+s#A].Y $Ӷ ãkX忦Fny&"h>HW .׈&6CҧHwoLRaLQ܆5+g=>i:eŎ+)huе p"*~>^.`_fLnEx؜9)QXjG}r .cNaEj,Fdrr9]03p0m0sL.Er~{ULv-<Ԯs=}䀱2ԥE z_/h u6-39>5֧mېQ1ת< Jl(S{LsDPpƞ?F'qJfrE;~` CPU)k[ؒFN>34GtZPD坎xZD9'/a>!y{'G  MT4 b_F~{h]?=P!Fڼe_`- `FĝƑvC:ߐ=,fcu&z:>X=\jf@0|kN#̶G]w/rfwRLHٷA Ȕr*%ӑja1vj8j^`0Vr9'G^;mݍVf:8ڑ81uqWw[:_.>X @='%ӿp\rm %՛lG 2p9mSMq$-?o5t@a@!Mу L,'wpQ/eb褘nӡ1g>Ύ˼,!I,>z9ncd'8@ꑩxAU2Wu"1=3|ք<ڸb:ns©1ЇhlLj%T\]12aV݈/QM7͈.2j%M.'a6Oߑ幢H;j. iJϝEk^Q9(20HC~mr*q#ZL,r>aZSe:2r_'WCtok)>FCi),]X~\bJe- &?'Cat> 6֑-z#=eIokTjvV19X+#T@XZiOrgP$; P87Mp9#5%dJANI0tbFG1<ަIX !uF_H0}k.)]1XʱΞnr<6 8I1γС h|qYtiRs,M,b<&AJ全 ʕ3.gzݼ! ob !-َPp0+Q(<\[KC2hût^!xB1`&н0eFj1qxi vC&/QU^'~Yq:$=WA'$8amx`wbygPSVϱtaqªb,ojwh$3~ 58Y簳e lK 7kԚ0R^BLeINVD9) 1È Ĭ3SU+r֤u|pr:Y0QFb4FLDUs)A(۸fBgC:#8-Eم搛2uPٟ,1}rQhf+C vZ2>9&mS ͫ!ƣkɁ+ÝsYӑ%^iE_n3v =%m> }" <'I~ݭ~g{#.'D\˲NK\yDWR;$ۤgksE5ʹ$C)X7y0FcoX֙ X,"V<=(OFa6"e*#oF+RFz[G!Z(};BŨxwUdihPGucJ25r&TcUJZNbBghHGxjaUbps-P?muSgoE}uaٗ8wC HE.],A_$ g\^:t]5i&D 5by,N2(U]8 0,\)W1QW mG Gro1PAw HƓ,`wqDž05*Gb̕TZ3K9=^3 AlDɴNK8Q Hn=~cÛ"ԹXo$o\ܪ{ |_q 9t<q`_ UGߕ0 H`e=, ;JsGllg"mئyq'ηoүKSY}R(x?vnpz6l+JWڐc`Fo`\&9cYwHx&J*fJ |̰8E^w77侧6 1 'N"95zY7EA:EliDlU-ǙDK_2SBl?Hy/x,0Z6VL&\ Qx*bu*@EvBx" v$w[ˎfztriG/ӣw1ex$:)>pY{xٓXiIMWT>$π8 DܑJcn'~P`¤ԅ|(Uô%.\$ YUv"=f;lJK5X+%Y}oQzΛ?=F8}۾Q8Ђ*7'L43tNj7:q$k ,W %($$EiH& cڇ|5<6|E)A)Z/S{qVlA&uR:.\blO#r`ef2YIϼcgaD5,F$9v]8])@;B)8ᅏٍ6ڽe1z釳'-*#, p Y^s0,*i-k `P(k&QyZg6 ~IB Jf-󩒽+VrhZ]}~5TKȶ{%`?s^^Yro:y伫< @V[c6˶YOVG Ewb7(62B[/P9`~~WAR?VWΟ@< )"..yK-9qQ P|M"owdOƹIt ਠy U>;_1(e|XE~HFFf- GU8Ŝلā97H܇銲J0V?n&k Ea-1 r2$TG-d=enN8!_6~Iy@: /H b?E)+ӵoG6Ph@ȂV^q,?ka[oUmaCXCnIc%UN!I,!KƳrVݸ"Ⱥ -1܏{ss\dbir[,~6`<>U V5 "N[eA_EBXM nͳ G*Z =%ԔqDŽH Bz釢7MM˂ )[!%0G*Q vdatC͔J3QRlqjA^l ben@_QA$RɄQљmWeZڝhk3ך?*9'v{Cg3&JS]>e.[]tB7ۻN:1nQ9,Q|^/Oc؅Pǟ%:6;dyn?"%׌g[ܞgV/}5[s7x/xqPQcCS Im v 84`yF٩O: CXaQ%#yu{՝P0U6) tB K<ħ_!)3Unjf#cWy3b0iM$AM[Te6wc~gLeZ jFNeum+Zx<~$ZZyc$y@Bcݥ$wW]'=fTdr}8*C;o[42`KR Ul^-`[ffh]tAԙVϔ.hv~O=Un_*3䚀+pl;:]Kh)t4x L@52D+fdž{}^58]h}044QK& X.`!1ơQ ^-8)Ix:)*Hųdd3Pgxf)T͒MP|I9lMڬ8GwZӂľ\$vu/J^鋪N37dxX#H ~rUY*O6K O o-7x ^e]a7fvv]ne{n(WfWe?g+"ӱ&ā"E.Fp;`"}³4/8]g|s81d%aZ1IpLqm:-27I5iCG*΅Rʬl0wG{`m׏%[{MFkyC'A8H, lY^% rIuHUغ-kAH y[?-}LWN e<.KUhA "t7h}YET+L늪 )smUzsaa Wm:4ÐWMpb;U9Tzgt랲ƫ@j64WE-^^ͣa4)E}.k,ɼQ~>HT+~C 7ˌM /,v†l2 ˑ")r}U_ Xnn ՇQȯ /6wt__E{HI ~%eV%qdgs!  ydm%  N=ݪJ]&twjgX' nJrtQj-<xyó7y \/ r=!)\9sKT*(o n9o@W #oy^o\a0%080č 8^QTL{.5;߲zxm12Ŭ5h׶%|Ӿ`Y9ϜH(i'r2xeZU0 6,n$::֖`qciqfdnK沃KY 7yzt%6# sђt%׈Vbϓmvxjҧ[ hAŞwkIWTԠP(7Q ~Cp/BsR&n uYfb޸Kx#ޚbCkD.0:k^v]9o]O7/2 UvG/e:bY\THv>#QNaN FytT A;}랩yv,93-hVܼ-pgIɾYAmI@.݀\Qtje(Yũ 2%[ "r˒6ј?. S GD4$&4Xtϛ4<=;E3'EWYEZk!4lD?\ଵp_y4I֡y3  >>:h96)f? .5 ct4>F> UŐo\ܑ8r}!U)z netrUjFn!+/@0mG %VakCvSVLѪXК.vsea=qp!kU LFН?JOy}LAeG:=*%u;, L-,$Xo|3D O΃\/^6>WG$).8*%^1ɸ;f7 \RKDSy/|#@+2Q i`&,t߿eK&x)nhAƈ#::KaI)'W緒YJ2L5D{Xڬ&1*oҶa@ػ-ء´ /&ngt?q_=ӷd!T!ZЌ_[m^pvȲMl6(SN1pĖr ZϦU "8yZ| u~X@3S=Z#430^9gG.:0`1%Z s.mrA7Xoۀ GB1$j lYƭ{Wxۚ+!2š`;"K6(u _>%NkZsmŨ4f:DUٔ;F K8Zos,%~ymķb ub d,8Ը xgz[80u*s KUyZ_`f\3Ɂ1v8isU1niҾz%؃T//!+U?5z>V ;<0)ϱI߈9ӟ|ͪM'О`jƑ̥Y+bTwXX*xҴ~,=Gr̮߸7B |I&+jOXB̰/j_95A]L>ڠ(e->i oiOV%8d|Y mjJR oz>*u-UMy8,jEHdH[huo .a }#՘|$Jzw멚|Ck”JKqw^a@[9gdFdύT*-B t1B`hpȱdȡLҜϷ{3?j2XɳY<:1C%8gY`uplirCOr1cJmXeA/`fqHNԎp\tտIpQHb:':Z3Xl|5&>u(k ZF8ÿ331W2ެ(&%uj )yO[d5Þq%몮qax|J]ǚ g%VgfZ" T,k3\bLN ЮάFz7#ro_ P=FwZ0=SA;{Yl(HC٨q84]519(p݂bJPU }j)1Жy 0u"87iL`kއ,`<8G =:CJQۜY;_HJd/;fb1sO-J4p{1k ?K\}&g?`ZfDMhc+#R* 6V<c~h҂cA97wOFl9kX搜*kW-2"ְ!_*Ǻ{Thԣn%{ hJU8կy4^,1=G0mNi?bHAPGR/)CY7V1N=a0JvLHS>5: _[&mibm5%s)iK[2m;g0h pՀ:SYCIP ۝I7~VJşGRdRH6fX=x]f0LIQJGL\*\"g4Xo8O>/ 顖j#Wb !D{[ŶJpBhUx^!J .R d|VT2Y\gxA1~(_ޡ@W@3czeu^ 8MD遁mfN_6bo b̿_KQmJ61?! ]_b5jm6]My=XA3TP˩"! JoQě5o&5@z uUBhO3LHri)4E);d?e~A578[=ut=jd$\uV;`m0Biڌ!Xgy49&ø,ps@%tvNpP2%ug&\_)J9dڃݮ2Gܺ9Tcq}zSi+c#:*d B7mIԽP)hМrP2uc`7R=4@Q-(_aGo@JPL2 >jQi]E?Z(' ^鿲^=W,uϒ4`p?Q:Ot#@v, '3V"U& Ԗ lQ˒,U Aw&@T#B8c ,| Zm(xYq16\t_b7ٗ IBvA,3s6$ 9Yc͸XK˾qI5h kFcY35%ǖT37SKwc!-s޲h؎ESt~hi?AƓFy!ϳR`:iQTaYT/G</2}'qC\o6R8f;GَP[ɱ t 1}҄aNǚ`O\؟bHuLi.ͅ~d1CJ{%N903Czu~8]{PZ'; uy!_ Iy';@L P*Un{gUZW֢R?V_)c9q сk:0;̅c{"֦q|Pɹܜh"g2pvo1Лl蘫D6/pyH &~$ KGAPP9Iڛ PwP8qA!F)`ί c@w8 _*ot &BB~6jS$Sx RmgY@[!RCX@2)ם.5/]bpo1 2\-tzQӕ!򂁺bMo)sй.qe؏E#y/^qczTXIdi-`p vܾxaSnѯ>WedoR w?4*讋t-/iWI4K# ^'sˑ?e{oiEֵvD0Aܥ cW~?q,muPH+ DYo\Ph''!q@gy^r(UG5i F&iZ`d>xDjRd:=DINOaZS~R OD߇櫣; aX$(Ҳ#S䳸o hA0Fezu7Pc!-Eƫ =U*ÿYT~jL^9*7@~ah$RA=v/%Iσy|c}\F2nÚr%I8ezlU",L d%%]أ!ThlFUؖYiyjџ򪤞e*IvgO} VC?we?@G}Yx9,dȕ:*8r[NI[ܔztN 1o7|7l9Bv8gۋ ;8Xۡ:׮V2Ԛ|S_XE5vn|gLc9}uNqs.'l%s=K(4"bE(#'앧 ] ebZ'=ghz %X^'aPy'JwllA9M0냄~Yץ;?dzf7 BANQ#ʕk<_ھ!V D5<{=?5`:2)X<$ w8%6(9d8+"E"3w}zk;^̝ iE9vϯk<%G#Kۀ;soឿ5׃LjD3Y#^2>~Q{^?Q s=i5o9qkQ* 5'v,%ſlƜLZ)x@ F; LtMcm:#ڥlYOF QH¡G%B:^M0`-77١D]J2mK&w\w{`3YRtA@֤Eg=2/$\W?:踲So%Uۙl^'rvnvOaW}Hg_\R7kb[T!clXptʆ)3$0*DQ?LRyI@Tc/< ܏ߚ3__4 V|72+Lx\srByT_~rBCqq_,2|j% ybVizy 5+o]T_NQY1J6z #_%$ltUdVJ*ż 1shH 5v^7ȋsem˯DMJ*qHyI8 TW:/&xS5hD4\PXZSr+!8գ3}3ړţ C Ԧdm iNW^+F2D @3\ĦC "IKI6$.Z2=Ω=nUn~<{|G R Ы([kYOl6b|yPx[ PXa.uw(9W=M"{󄻬'^( T45‰ ,ۥxSvMʱdXO\A=* ]mZ";OBCDS-\ziKg4O1 %uxL [&Of@+MG~hV,*t5ɵv38eL)w ϗo> 6JmJEYT~%Q <%NUcͱ&Wrgi騘:˞'B>8+s0 {-2?À-gf)e[֒/zAXtGB3s#Bq7{аnqϸo&tW9v) tҎLpO>%5DpS.t_[q@bC75Bf3?bf0=^d*P'͏kc&8ni]~3jl?}N `Sl} ESK*klJ p'mB˸@6; |§۹qPӇ%ºK<--ya20tʑfomPًIrl,a @wlYmPʸ1vVJ;jxi,9kKJGΆ9^ tP8\dYUa[zCfY(7n'jo,{ 4gUӡ 4诏PHU@^YJ73O()ת6PCئ`0~-+Ÿ$ńm3L pJfHDx7ů7h [Ux/?F,!7+p)h޶KYNLquXra`KsF-H-!X&j6ɐ#+G: l?9fXU$FEs|r=Qъ+B^_H7di.&c)|2M&x,n=Kڀ>'''骄DAJ=6D jO4;tSQ_#h(Mf3#}.d{hgk[R Ԋuf'&ǐCхCL-ȃ @9:pɎ Owdp1pcH-9̂(&&'}p4i-d2<?^jj6I~OS \TeL:?>BФLI_-.ԺhyW"S3F Muj#_r" 4$JS;96qOy3cD府ȏ;f එ\IX9,ϥ$?|GHdHHWZwj||"R4p]He#C, t!;9;C 4:8Bd If NnD}>IJˠ:kxɴlA-z\m/|i.\G7eΗD!Ijd~l F9\(‡tmH|>8jaZ,M?lL/ZN,C!ԍsX]HjȐ'kcY?ĕԏ@>tбݾɌhhM~;5N6`iy WNr1'n0P0Um Gh p<b>.zǛY!ckof#huW+;rbY"b٧̦a]KRDPRHm6In[l.Ff̑>7!wL;;;R($ nb\EjzJs"\qKCvGX7Nu]zE˝MA1i<-,tr&"o9"~(-p|]Iq rqsZYF]SE*5(S_X1$amh>{EHo|b޽1Q/c;\:w>aD>pϘvf4n,E;na -6xj}b1݁=mp8pC_=#C\в,j<_ۆ'u+1m[H`.UvFbn1X׋[Bcjٺ1ܭ2hAyױS=)Ν i@{FI_NGQdFN{`YrGE}hKħ!#cդiY7(UP |zGXjb% k?By\O B)k+#򝼩;cͷH_* );x-Bt'}={ct!A=t2V{y$ANnD ڷt[weo@mՐdx6`#{ŭIx@+ 4}8=LK^~'4?my(i ̄lf+Mx(IZ`^mɭ%6j-wMFh5EǾh{'Q|%thߔ:Ԉ:2j.-%I~`*MV<X~g]Wp\2ĹH͌!]̙ \lpRF], ^LSKa֎LF$3íM)/eJhuڬi4ɪJ6qe~UXEQ}@.OP Q9ltOHDa7} h1yhgqqv3`KJЅ3͎ܞADH!i:?LA "D(͝b TrnEk>nʜK2|IHf`(Gd_A1dFvPLnpf2gS B; k>Ea)VjKLX(Aw__X$8-ļ%I[6 QLwLӜI22ؠ]xbjjRgp rRYs;YWQOzbTL4>ҋeir*Z(gXb$ ii3u* QP<uU0 ? z.@&FmcI3}lVq9w2Qu̽lb$ea&̡];8}?FMVIkUۯ10bN$ʈ,z'}uE*4\p\*_Cm _hkt?-u2Ö$[b%҉Ly9.@('vK' L9tDFΓ ؆Ra~[j9>/CV+#8\h̊+9m ϝ_2##VIh?B1G~mnZд "ڛOAU?gw`݋0/|o0yW 9+ˬ)B|֓z寏~V ]2>(z#RV& {|]*cU[U[TeOK-Y|DKBU!z`%jVAX@>'rVyW7AQ*~Dch^#VfA}±P y"40-Wo;ֹ뫄Uj-CeY\ߥKa@R<6Ky0D]j-&TVkPY-ľְk؈5l)Xr5#|S B/JKaTu7/+dmxe _E* HrʣNm,mX+YQؕضP*Z2Hx(^2i)䍃LMBD=[&,j"*kNTYXzj+wR2KkG2Ѩ,,a[5 wzw7#Zs H4@$3^Ȯ+Frȿ]÷HRA:4#&VfU&a TA0YP}Щ^CpD}VSG!~ ΩOÄ ރ}>Vc|l}t?.GЯ oi_:?ԟ6]j-TAΈ>E|1`ӇFIHd`˰>B]OBr49 ٷPf{&7Ὅޱ̶Hxq+f!v9B$R< Z6E'lK'a)/" k>i_uX}ڷ` ԾjRuVEAD-hn3q^nB49xmM)DuEş-]lo"u]mom{WќmP}q3?DV'XFas 0MwawPlb; 4uzP4vpl*cĥbv®ih͘ J`9؋Gh bZ ]:Pwv 5hoB)k v\B{ vX{[WT7vZ܅@˒xƐ{U/¡x",hYP흆0iXE"WNʹ tX) 9c&(Eo"g&-XPI3hBwurߋ5 7!c*ʻ8;m涵m4k[l#f%l555[K6Ьȼ a ir5+JůA3Н'QxPX^炇m nl;0=HGRsp; ǯBU8ѥt'B:=,*T7C{P1 iїD*;n4{#>SV f p/J-+4 #m8k?;b؂-^q-VkvHB#\s~݂ YR@Oj_d )CU|*'젥vP T4;FR 98C'?x\V8CgĐCӷI~]:= 8@8|)_c"v^hb`a'aMXcMu^lɝ섳(sYofh՜k",♅ff1Zć,(X׸bC;b~( 1$ude2Rcօc-~67`(t2>4GG 8/} jȞm6mI'p*$Z| _QyTOu3Pžr X> 9Uif g`<.ה1Z4n..BYVĨɋ8V/2-)=A=9DkHXϢx"{" ;ٟ~v#ͻz5"u@RSCCxy3W|9@,Km:C9x(* X펑њao"|6-4͘ǯ YxiQ`azu<:^<\Rh}KK%%*IDiEi E" pPDETKov'O?fnٙ}NT>*8/J\~V]*I<ɭ̥5}*v)E_WEi C <} |ik,֠gE ]'|*0rs}UTQ+jwCEW6ᵊ~z%wxX8QXNx)uUb;:.i x-*+o0UfKst6K`T {;2d'd0Y&ee*dGrD^SHNސdI5rmrJC~89֔r}In@MOMmrsPnIЧt^L g*SA?XGM]|U,RǬ1bzҐpc}^U`Y*`=P$W ɎNY\.B(wY^Q_Mpi-s C~!A_ 1'>0W@èX 9XlAqbgE bK  il. n:Ln;[ns@C zHB<# <:ȣ|tA/ya< Y WB1TU!‘IСnRp!o4nX;k+mJ!ӡBzr3qnKaz_\=aSC<ۡ< ўOcqN>bjkǎ19``|fqQ%/B C]^ T  D20Ɇxf "c7C p s+x+2"^8KqAM+T4HEEG=g|#&2Kݘ],ilIWFŎrR.PWu]"0qܷ%6LU'Iޟ'8'W`4ծ0~/!9xVU/ҾR&_=CrG 1a?u@>??r>$Pu_U^ʯ>Fh*c4%o8&=-[ފc \ 3rHX JӪ5t4nv&0_͂>n !"O Cp9/EJ rZ.MV@kك&4bA[y?t@Om/ `jL6[{~ 7 40ZQ!AnC'pXH9҈H_DYiv^+4f.9^ -]0R[^dWs?_ Y>#]H%~4U#ҝȋﺂ2"L0C/J<՗U~}qJ//-$ϱ%%/ ï8gx[~?+ _$0DQ#_ yP@(t!½KAT)T E LHu$0's(6,% c"qE]1 ]FJ(5}d8% &!NQaGӯ:^b"56-bX3'& )>!$MJ?IB$7߱8C+#1`J;̕ڃW ?$^īF$R))\ ?DjO)I, $Kb$<9':~rd|"%☥ᘥi\׫IF4 ]B ,L%H<M10BNqyMOs]0zM|ˋ%xM[q Ar^ oϛP,ywy@">~5(:΃69 `@QAGlq(bg0*á2Z)#2 (cokqTnLi$Cr2b.U݀"]! [[^cKpJ0}ot4rj+b+BC4UC>+BhIKP( ITE<􌽓V˾p(Ev/S40g?}bѣ/DqK 9w$ lbI1Uj̱s,RLs/@UND'| TNc| 18:(?B7W1@F+g{s0wJHA5I|lMVd8E`x] Mzb,MɠE{Kɐ!IU6<%VT rU :=~![]EIϹYY.wRPzi.< 1mhAH4ШKPkzYe+.ATdC#D-#(Uv+PFUcld͠{6{R5S.;" &k಩MFp6#nphQmw#]ECdTE W1]ecxPUX8)Ũ>:ε=k;/"f ɄgcKNtJT&BN'jPԮh\ݡ'T{Ao\0UxDT Zئ^!uRuQ? \T4u IWu0*=/s *(tҪ=+pwO*Ԛ [hdíķ#Ny2;”6 k)LO2^&#}4=NfVIt3ÚآUu'7,H2^Ƀrq-<#vdʜSYN]؀z3N N: ,PD7sz7WBGutUP->B.bX OAz?^!B}NX TեģMR'W}TВGԹ|_:ahb"lC~N"<#Dx҅0 /&>lې C(Z+"ŖŖ2?Dat R|2Jlˍ#cYF/,|9?k~42_C}oHa$j;殂 !9!{|>bu"WBm@m\~Z*úr}`#rTN~)!/R5^*nWU?LRyQ\dN]tMJBc1`:6bLYd9Fx2dbUݸ Ak-袽χ`>ރqa}Sc0]fjG`ܩ9B8ܣ}k#vN%z8:< >M|fMOq,#BH[dwy#&?A z38~ŕtb*=&}lW:TS)+ bQ_"$9#Ί`hpa3,DOͮ^h\L)0_/h;7 ڞ]@EIdHB@3ɛ!ի&o pHbEܞxsKZICOԀfzS@Ozн0RπqzLk\hpsF3/c!*pԫ$M 66164c9ĥ,H+#1E`T=[ql't7Ǝh j͠zKhz裷~z[_oa3ΰh_lLu/X7|*{Ty"k&cLG ճ1/~5IzAtGJ> ]:!=HFoPpQB CA_J_قz*fU:!>XGdOKW#AGA>RwJ 52vhe䐐^Nl1Чc<~[TE}#E538pŶN՞V^;{0|+#li Qb4{YH@q%vMaɫ94p@Q=W.ߏ>>ReسO?4kPtJ?w~JD$,-i6OȻq`B80|COP)a>3DI>+c6,/aEe0CC}z86C}TlitX_Ž3oit_俤";_S1N ]U[W[_lF?z.!_[ji'bC8_}O>^gJg᳼=YqG5hƈ91bF1cZr?L /WyT8*\t1KP>B[wy*ue<݇no/<~^&_3e7eW~;.PND8b-_U8b#4`aB<~N2VJ?ܽ\8y3YP]2v}Ҍw |8*!8A0`)%<Ξ j@ci$Nۑz]KBTǩ,SgJJCy&4./ƇiJ#1DCnR_JyMބ2R>@#m7@q#d#1 `4d}p @c 3&$ݘ N0V^,.c-A{,cǠ8So,G#[ Ce*2a0^'aQWa46!c`l^V~5F#zl0WI԰7h\q"jbG~CAOk؋A .CA\4іF c&Nlh/qxi=O %_J΢+ %34skr"c1ki@6Cmpx 07YAaXjeê{.Mbdc e4}?I~/&uȝʩ@a+pptA4u ڔ߉/xbwtchmQaWeC;8.8_@+K'q_鞂1Ad41yȻ~ Wige K.BH9[ܟZrPQ<~SBD5,"F ̲Z3iO r"-xn-+)*7kƟh@5.i\II@3S YxM,鐆j ~QV^yk&a&AiU 92yG\ՕyA73P^f5y5,ׂ)h3F6beAefȬl{F(1lRMfm-dbH8ۡHj6Ŧ7$y5uN.>> E~q׹GTN˗ o](gf*e_ewBٝ!#s/:z<-hBf ȃ&C8;5?g\v˪^s9$؛KDE61Q>x?H3YMBʼzay-\oa  S 5WTr$8E$7#!{VA/}UcoDGVeRzeDJH0V[3)~;_>ZJKEG HDP-:21_jb:b57BsKՙ5'-) \6%7vB/ 9 ތNNQU܉*V ܍ 8K߀vl~gz?CYl:_pBNqFy#(j} >ZZZZ@w[ʭls0UDt3EZ#96#[\6o78ڤK꘿b#@+7l?a4FZogY՚ZnbS11:]b۪1.UUƙ AR\<%@(]\􌳠o\JUǧrxiVngk=~+%"MJ͈R953J%_0‰+.Ⲡn\-hWՅq͸u.4}=GE CI޾(;cY2h? NA]b]V:g%tnWJo=vR.mPY$,;އn =`Za8.A# }E"x, !Ѣ!$YqˢO $[I>jѧ, BE#x-!â"dZt%BM>eU,E Աu-!ۢ/ Գ-BТE, BcChbW)Gȱ7", E7#4h1BsnAha\nEhim,BkXEYE#Y4;:Zt'U@d]v#t=͢{[M݋Ӣpٿ$â-\wC0=w2s}d|0> #a caO,L?GDDƗ0=7az:{d0~ ӟ%LE[?Ɵa2v ӳ80·d\t´2X `$(2ÐLF00Ӑ; #Ld90K@F Dd$9 +̒0R, ft5, F0#;!hf a4&90##0Y3d4w-,-F0k6mCF{fa\fKuEF7=z fa 3 OY?f(tׄYd\0 0`d qׇYCư00#ƨ01cl݄qWyoI`nMrӷZlbnzŦo;T7uT+:SOw{t79cyMĹx7Г&yjb[y'MIry,7y'M>IqzRC47'M.x# 7'M.t k>v#ѮCbOmudF>J2;?"W_ʾJ,v ctZZ3"76t `8LW4#:y7] =$~H$Ej1c kB<Қ#pҕJz$=Jek` co2"?tI!42GjLHɽ!iY*M"OJw#d(ud>*}Eʤ?NY&oȩd܈ۑr_<|"BNs򽼊"o&ȻY0=/B/?J߈Q$Fd [R3g1J+)m;0] 7b?\AAVC<,Q̒i1KÒyX KU .cirD\ü+,CYe*e)X-⻬rQ!~ʲSrV_5PB<5ReD5VY51:,G؈f,"aN'k\?@RZ7"a[Xu2tVSF\ګ-g b}"R8A} {H=%VR=Aϖ +IW;i1ʖHc+:9b#hV-۲5F7[kg/%c x13#^5{c h,E|m2VjXm16!Mom;5?ﳐ +5>G?rgv< vv IdZl^7"K1syѼۼTR>ɾƾe7VFqlocW6vllgcksmlf&66ul̲14mL1FFFFAZi?m&G|\' \*P]S*>B M8,D*ɀ#LT~9#` zF߰]0U]&xF ŢIFHUsYhJG҈rrbq*Nc{HMS)@zCɑL7̂i#&ZEY0">*B'*2,SoN.N+Pm$}*(8\jA%"Փ ZvDPTy4i#'릊]T"h$B&{5爘V 7avY[Сa5hXunF.װ5܂j&kaLk}x U4K{fCDf4dK"(bخ`~A6o[,ߧU}./1( ~A > Ikhlá=FG~h[z3.Rp͸R4`*ŠT(lg°Y fA/+^o;~KM+ xq' !lea$q?c/{[T^5T%iA*S'U1y=&s6ÈZ;  ĸչj+/&ܾ_.4c30k=8B.9E&!/+)cJdiDV1-)h}(bRRPoyϪ܋.iq}ܣ%#[-ˬ`KWoUv cE"EX<[ -G9ά3b}߯Ęc$b4j>7wf-6S朻uϿ؍O4l2܃!!'<"Q1 E 8rFňgB$|FbTa5J:aӰ%*&4)C[C&5LRV TTTXՃQ#HʌΙ7l-o:i^zB(".WKqo˻Vzj VwpM~w1-I`6f⸟ٳEc-[wQA{͟fݕ5靓nEP/d6K6ΗNz+i>.R{Ɗgq7__ Ĥq6/sN:BB\Q~DLH\HBHeN򔓮Et;2wxN {kCo顬*&데wװ9N *#2ʹˑQ&:c0}*p.v¸*_5x,YkL:E!}ݫdCq/ڵnUW&d~@*!~#DoK%`hAm˕/G["M%AՈJOX!9v6Ja%< h#q{*yw᫉fpwQc03} 4 g8;¿ 0r1\8w)ѾQNA;~$:q]cؓՄ**Sg6QU[qC%ݕLu0W/b07]KhkYQ^dPd1O˜9Ϲrfdt kՌGңVtl'W(xm}ԯr G禀- hW[T=DňDG2 *AGHfpf8:51I$4KkmDMij4 Xfw߼7?޳s~s}|_6la##bNH9-##2b>)b~RSb~Z)1?#'b>-Y19 /&E/xY/dqN+6,/UzM ~eůmhy+~cVoxS[6wNJ6 ͸de㰰X^ PK  "؈+Nc#*X*w#ڽB[yt;vY' ,.񞉗UGӛ$:vJtR LtHM"̎]x2>oK$lvL'G\p$tJ\D: Gbt&欈`p_0{HJ;IE=Rβd:ϳ2 BJ Apok^AlFN+X> 9R0(txT;irNBܓs>*\`}QOB(bœ`$|Rnh)G&S u,dH C,{V E۰ҾcbLU\ӄugf`kWKID*Z֞7kֵ%ְq+(yw ާ(r2pĥ r[Rt{xnuw z4[-aFx{(ms_K Lִ:h sr&eek~OkKZ2ioqQ\x>o`Pn(PQ]+U0(V[pVJ"T*nPʥ_9:7mrqwĵ%){,`MFAlKBwy oVw5;]?OŪ!5|S)º";5'f/up䷈䶈ϋd:%ghxƆu ~2xS^,5lႧ;QTxKK a5}p+Eђ_9M2tܨ`)8 nDy`Bd/l'n3n8]M&thaDo!D{p9Kg8' ]BBC0ȪJs]p_qV<`sV02VILPHT,QEbATcsI3 1iLLއ{%*e]3،eԮjVlDsK,Ո,a׈Fdž]gJ'DZ1s x!\an'؁?D>⑏Q~my?a8Wx1&fجPlJ1O?=zS0QoG!&C_o-BMw3Bп / . tO\guts|_|Ie|Y- 򐆇uGuIg?#o< tEu'Mƙ!{ȟicE qĤP]B&&r 2}RP$u̢VK&ҚhB4'X]' w/h 3Ew#XeKFۅoe (9I`M])+euN+U-Ndv5K;)lqq<Ǵ-B+2v,QzQPg[R)/+e=1Χ)9-ʞeeq(=GLM8֑kRXW´3)FyTۮqNF6o)3Z[S|2bc&nTЗč[,lJ$S=f@.3& iPK4irȐ*In#>>`\LuE^}7MFTeDUHS.4DZpVVCJ~CnQ[1Qn[k-*Upb6K iW=j3p.`5ƎfR)+asBU [.[],L3;*kwÌ:5uň]4\*;v2ߗg𛽽V ?1n'91v)(u.E9*l粫3$a1[d4:r=1[dg I4Aשt:͉uiƓik01{n}j.Y1mnq'z'Dܭ\qw,qVՒLGV34$Z`z;m 沔hxeBK!\qy(sYw߼GhFbaބIub1by!|qM\ߌ#x nI8naD5$U4~ )?ݒ?3(CC;y j{ m!Q _+KP1mU>tH`p 6{}ro0];yCWI:o فY\;AꜢ7QP/cm f8dK3ti; %22Jxޫqӭ־Ikڷڷww ]ݴ=<}~0GQ>EW.aClЍ? ^.[@,lQ[T~VL迌Y |{ʜ!|z73c%]*P"Geپ`eDcН|ĝ|r).hܭQjvvaiE0mfi*]ߏy|lVxUMw_Z4J bVX5Occ0.dKZdDEbtk>>Xyʞ bΞ1Ũy1?M}a| _`"y ?6<fŏeɗY %=LYQ#t٣̠af>Q'.ۡkx[U,8z aOW^lf\ޅ?FaV@c~zcP^a%80Cy+L'Qo`!rT3P4{ s$/)HzO!I>GRdI[ Hz(S$Ißd+}YI[=x;/aBInUn¶OBC5Np}nBUd |)]Fy, XjumZQ1g~1W^ձem߹xv{e;Gnuݵ왃ޏ _!`rW]cJzzT%??zLx^ T7ʇ\nV] _y>lۙ¹]鋜5ߐ+to@^a#uc ;ℎ& 4~w6B`h+~9!+ERaos.§jNBlÃ5S-s( 6D%#hV-|*&3#w #*A?zWzvNG(N MHuz:ڏ|t۲ɾK_dX>bqz{+fIw/gjFjKA=M|hw0͵ K< uM%YվA,*8WS3+ˊ(M8+7/ e CHx8Ef˥ &xCL5A9a԰e0 Ss M57T5l *wjiyQqyYMKj*OT!]K/r9@JiY+ӧU1ΦrޠRm$3sd#ډBj#jA\yR֛WbIOYn?ddj)t")ԝZ;Zf$3suUHcya+(ܝ.E":RvF޸ AmD-w{x[ tuvhF?n(-*Q9xFܢy3KiEXݘǑg#M-.Y-I=i~Iqm~yoIItJ}a;OK$&Gc#i#< +r3ƅ_T={WubInʾWTIvf$ь~,Bzjp I=~YC%=7?L]f/H5Ut N1-P%!`n+k 4z9vTyUgZ8շTjHņ=1iQR4Q .mo\bOF9*)zgbëFJ)iHZ2%_ @@u%$4UmNBg^_#ͨ.7\5S8Trrp- g6xЀa1 adSXZURAkmKٺBbdu <`g騱y°C;-~p!.e6+=T 2$S :̀7Y?Yiw"dGѵKM03|BkL|G0(tl`xkLc>&~ xL^`"&2yL>`!|&2L`%|&]Yejd}F3fk)j&)s!LP5BSj5B7=鶀g!܁Ʈ3&u_t6䫭3wM%A~QG7-?TѸc!+;\P x>jF5J[ȞZHQXN ?'tT5r㫮.om궥 iKOt`Q| Ѱ  ah+d?ҲMq;?ؒS!D<*{ߧ{IşRişQYK/(/)(55늿ۊjx+*+*+_*_+Zj)?(?)()()TI~\H@Q;)dm@tuJa)!'jLEWӹ$T(SvuIpBBFIK}0d7+vb'8=Z;vc7DW AhX?D0j 70{ɀ@F9-N&$5wzWx;!&Cb"}7%CTo`=ek`4@jV\uNo{ȷkoAvTj; wx^G; C<=6 Y0Φ#96{.$@PWB9\a-f,87yp+\p5lK~#54(j'J [5Nf j eoN8,w@LPB(A&+h; D-b% h#ݐɩ нaH(WvbMA<0$#clM{MFXPh{]~ Kפ|6*6vUcVѼvoXjrat?s/J=tS@u$%8RAΰ}`vad׻! Q'w~4<FEO,Rʷ{殒YW-5yM`޵}*yr,rCJ;e)t&}Si$Qwȫ98dwyTcѱ6z] .o n{ /7{:`='REI%+)Pnq=|k?Tj8TaD0-pSTsAd?@:;&|SyPv5ꬊDJ"ٔ3?g5̕&,:MX;#΋R-C\:G*'I>P,M+IwvRZj%JG .W|FʊܼQ.zƒe<ߒo$p8#`0!GB.->5y1%m}|Imfn=acR[gJ`%{ dHLԅnI3H:ӒYY$m<CIJ/e$clGZkٖ[y>RϷ ,u?R/hK=ԋ,1zXK]iY%RWoK-u k- DK]GzK`-uYfKBҀ%m'tI\iٝl٭ 7K=b0x`4N8㨖S  G@΀f,U8 Nٰ*,X 7\؉ ΃(x۸Dž V_x4ETౘ8Éùbiqq9p)^5kq>ǧF'6(l1*(8<ƈҟax[?V ;\`l&Iv:=LI Qدpµ 7)\*&8#|'g*m֗YbVgK(GsQ<HՐDŔ=/9x),8*hµp6_=xUa/?Suގv;)7c܂#.wclB܊3p{qnAN]x |PF@{^F R05cB|PZ/͝🮦/Jfګ\=ųCV1jXp`CՋ?#zh?4}=G=vU-T89Ľͬm\= =?~79 ^4j&f_)2(-\F J"wtCЋ>]4 6H9l޺=[>O>,a^O:!n ^vpmK *YD,MMg9fH}U'T>iL]t%O CCr%AE;\zA5/J1b0d!0KKD\g PI+1>[rqοtę6^v#!:/>@!ixt v!F$H0vmѱQqʑ6bVD.žl2f OI7} }bD Z9ƒFF[ǎB, 2'?H&ކu7% 7,jf3HMzaM\ A?o1J溓CU >z6R*6m|!Ƀa&.l64]iI"AP\Ho mAE6Q>8BGqܞtta]snhY97)YxK4P.8A&F YNl͉2d(Zdd`a 2<|Jhͧvϧ2&.N! ݉ _-Q&'|4H8cDSB24q^ 8s\<% SN/J8DT#Euj!ciTn6)_|1G v]PktՌᄡʊyJP!T6%gp<隹X%Mri\t.ѢkiJZ$X"pah*]JLQ{ 򲮰3)8Ԯkcę/ 18hihz;CfG F=hiyBaF >a&JB[0fZ&btBґ; %$Wh10r{MI/ 8#nERq/3ΚKΘqKEѴh0T?XiE>Q>/l}zÔT5։795!~pJjPÒVC-)|bSoPQ8|!iԇG)j ^vcɆʊ;up؊j6Fw*U%*H&ZU5(u:^wJ{)iR%n³nGnԠc)7^7Y7䢞_>ƍ5h8r}N*ԛ(1ʥak]fcL kmZ:M#6VjKtQqlN\I ;m/D^CT(ˇ#aC-TfS!:UJN m|{%e/BL;k'†ɘy46̧Z͝[$Я8} [iUR1T̂Bs"LaJ̈!0H4Og}a`}.6gMO3@@Ӑ&<㓐JlEYc983xq! H;7D&j!9/pN=AX;\vH]rD AD?nR " [ENÞ JWr H}Kp[6 K;>)/?y8A3rQ*$^ܭr\^{P.__W$}**`dLLm2d_jq@骾t6&3[K9ӓY϶-~E7[FU^&ʗ$M d:i8?.mnjZݹLלV1aoU_%P.r]VJ\3m3kȶ)0nlNL2cٹY6wF?Ӂ,m^X}MeݎP%dǓ53̠ò;3m<-eg,+(~ m9,qIfDu@UqH z,^K.2nɾ}Ւ۾Di sa%i'ҶHq)]=JI*m-H"*.!H62Iz쵚:񀊯xWjsBqN\TxU xG$14VLI5LnvxiLDa|2;lk_RsFha'sP ?ᇇG(k1,-ͭPl_R(|(.E+`zCVVj{/1H!"$~!8mae s".c<@'SQt1w7qp<.櫸VŦ: |Z>̢)cVnFxDqVa:7_Ѽɴ Uo`SehGP7V76٣^}E^Ne ZLK*F7Cv/}ФPØ|~ [XSu1% B#8?FCJX;( 7C( !qZgݭgwɇc~Y#cW޿ƒ)Kg(KJj*nBmoQqcqu1 iZj]{hʷF٤ NLcsh'{Rc\3ʺ:V*hL +qM"JMaR%VB_*l"H oޘ^la;`H _^/C=:ǵzGaЃAT䗔6KMp/ (cL_ mDqB44}E"swr*UI( CdxP.uN|= N7`{xOl ʙ76˽'z/߰Ί9]/`|K16Heԩ)KuPN@=Hk FBB a!Nh;mJK@GgD2ǹs?^cWú y7u2m E %)<>y#j{T ^q1h72r.X7,}O"F/H"]qTňzا˱˜z>OȄ\.uD;aJ[!hС!I"?㓣`6A{M"bei2ǿ`6s`Mlc