pki-tps-10.2.6-12.fc22$>H\91pQO d:6><L$?Ld   G        ' B ` f l l l l l , .\0\25\5|7|7484<%4(<8<9?`:^tB.G.0H00I20X2Y2Z2[2\2]4^;b=d>e>f>l>t>u@vBwFxHyJYLCpki-tps10.2.612.fc22Certificate System - Token Processing ServiceThe Token Processing System (TPS) is an optional PKI subsystem that acts as a Registration Authority (RA) for authenticating and processing enrollment requests, PIN reset requests, and formatting requests from the Enterprise Security Client (ESC). TPS is designed to communicate with tokens that conform to Global Platform's Open Platform Specification. TPS communicates over SSL with various PKI backend subsystems (including the Certificate Authority (CA), the Data Recovery Manager (DRM), and the Token Key Service (TKS)) to fulfill the user's requests. TPS also interacts with the token database, an LDAP server that stores information about individual tokens. The utility "tpsclient" is a test tool that interacts with TPS. This tool is useful to test TPS server configs without risking an actual smart card. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Data Recovery Manager (DRM) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) For deployment purposes, PKI Core contains fundamental packages required by BOTH native-based Apache AND java-based Tomcat Certificate System instances consisting of the following components: * pki-tools Additionally, PKI Core contains the following fundamental packages required ONLY by ALL java-based Tomcat Certificate System instances: * pki-symkey * pki-base * pki-tools * pki-server PKI Core also includes the following components: * pki-javadoc Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.Vbuildvm-20-nfs.phx2.fedoraproject.orgFedora ProjectFedora ProjectGPLv2Fedora ProjectSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxi686޴ haE K..3=:=:88:-:@::=25^5s5..Eq="  " -6 a2:- >`}F ^ H#%##"' 8 JC  M6  38 [I x e  r :8  uu [C aA큤AA큤A큤AA큤A큤AA큤AAA큤A큤VVVVUVUUUVVUUUUUUUUUUUUUUUUUUUVVVVUUUUUUUUUVUUUUUUUUUUUUUUUUUUUUUUUUVUUVVUUUVVVVVVVVVUUUVUUUUUUUUUUUUUUVUUUUUUUUUUUUUUUUUUUUUUUUd4055fdf8ec9180a9ac99d4d8be5c849326014fe63c4d10a5cb5ee0f899319fc29859d67de3c16cc04eaf53b6f07a0606cbe354ec3e6e3370c414864f642e1907ea83a2c5d52b037a0e5d2f83054b96387b24caee4e0a60e3cbcdffe4ef51b6f038aa571cb7ceecd500a7e3320b5bcb3353e7182d90c2f17af6ad91e2d4e0da70dccd466bf0d3982f4071774cf135dddc999aea31cfd995a5755c5df753890f5babe3a489dade97f06c333651cde818e78552055d36e8836bee8015994a853d0037033766d21167332d436e4e0437ca0b70d90014d5a3995b07099a5aea2aefff016d213d817090658a0e3de6248e6d84c4dbc2306f8a40cc7a6fa7d5e356459decab195f4b529a85b38304ce5570e7c0525ec6758f54f7a0532544f30aaac48fb679ceafaf479c0b12b7642eb36cea3ff185e96fee46a2c72cdbe73467918d83992f37a6dfbc6f3d3c932801b5921312eafe1ac68a81ec9a41bf7ec0095240b8b745106c6a6e8c6a5ebf3588f94ea12b2c47b1525866998e712060c2aec4d3909802b96c40ae1870f649a81df1f8e2fa37de1a9881384e4e8e7e7fd3ce2678912d3ad25f905a5db878cbed3d5ece39a0548890fe161592a5bf60a31752bb1656deb42dd24a3879842a49fa414baa1f7b1869808a29ee820deaf03b856ff339c3e095f47e3e913023ae253daab01aec7936fb2bffde84eb65306f3118df57f69a7df38d43d1f023232551e5b2f39d556a54f7162d299321910d26337b79bc32ab400503084b256a62a97446144e552f2ed9d4687a75f62d51bbf774b9058d8734ae4b21f0baad70383dac29f48ac39163fd6675d34ca09d2288c2fdb825bd1807aa955b92feaa0ca54f9ed29d72cea64424630546c9698b738d8f8133667feb3f53138701af6b788126a489801dc2ea3cf19b09b86c987f248ae6d991117af59359395b1c49ab060dfed1663d1ebd1a7eb3a3f5332249e550f48731cd1f3dce4f1692060dd1cc2485c541b8fa1deed197370cca468a644705c8c25a3276358871bc00010166b241809c4413f2e2c3e9c630e98886debe5647fc9e95129df26d9decab195f4b529a85b38304ce5570e7c0525ec6758f54f7a0532544f30aaac481af16138d7b307a2f359b4bb17b28e6d2f3fb33492015a9e965405720bf6f63079b7ffc9eab59e310a50ca90d67a3c2815e53b289d5a8db77f1b9752d0388a7ee5ecb14b5f0b36435866562bc1856dff7f680f32803a6d0fa3b1cd61773f4963190016545ed5c1e9a3f5922988435054d86bd377de3d418ef116981a574184e72b5fed4f864c1e06ec60e537dbbed2d605b71263c6d174c14134473a78849b538f5d4ba7a2e42d03a586464d910a8ad6d5405753025db1e8d183bf0283ccc2dff89d32639f2ad8fd9b224ab6f22a13a3a73cf56579f076bcb4f31dbc1079b36f0268d49e5aeaf351a5ae1db504174a6249da660112d4d7c8d5ae330e5c6a306982deedc0f13c308d7685f1529758aa05a1f87baedef2fa09de9823b184885050d0b32fbeede36bcd2f3a0c3bc8d0ab8cf05af5fa507a551c3af1a9b4a5b672c9af396bba9de300ba8aed3585fec452a90a063a95097328268872813c2173b5e3500f0d8d930cfc8c5ab46c570a209a63d41c982088a5714c42ec650c9f25370372efb4e82fd09c4663105fc6b83dc3d72e7e2d4da373e815d492af0325f3a7e127ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d1521a0fbfb80fd11954d2b44c0e5c100e6e83f6ac6cc2f855e5e313b2cd92e3f8616408ccaf98da66e85c1e0646c3b3dc3b31e626cbd4f47a4c4630318171c0152b760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f68c20c6a9881beb5076c205b18c5872880ba55b11e3d30337994d569a1505cd976a8ec5632cd661e2f9ff969091c7e497609a09de915761a1e25bef0280cdb889422ec9893aa133df5fc34deed46284674e551cb55c031d1077dca25566dbc939e84da371d8eb725816070b5ef66cc7ddc2f49e7c9c356909028f78532da8c29b36992cf3881c61b1171fe32821aad7e20d392d6204f25e928c0a603a48c30bfbb6c7dd1fca23cbe2a322b593a55da0f48ecd80d053e5ec25007dd5d55ff1715149cf9a07a5e46ccd78ee29e691761af40572522c39d12162f9c7511f87daf9c43475e091f4a917df5d9cccdafff980fbb9d31dc9ec5fc11cb924581594a83342448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898cc277158a57cc5a4c98ccea71bd7c900bd2a8b69b1037c6dcd9464d8ee28075398c5473e295a5e093e13dd43a12274d05cbab31707239f6313913a810d10ecfcee4478819b84de2ce60b7e2a73b23d4501ea1048e3027f131c9b67d1832b9c10c639ee3a17551667e05961ed7fd6521580011834f22e46950c105348ed99f02aeafe31ceeff0f08c2ac83cc9465be0b91bb9d82ebbdb9289d955625dddbf82b13b948e928b1b74589e706ac17b17baa8f1d4617f30b8068ddeb3d97a9f6905860a5f5c51f5cd387c3207a755d356e2af0279e2dd31186b49781e5b9bb2f1f11c5627433e2ac852d9529d65d86733635bf938bc83b9450dea0a151a322f9476624a3fa2deae4ca46069ae6dc1df04d5514aed8860dc102e2222e2c01d01abca09ed612cbc28454a51066f33961a0a17db50636b45cd4c7f983e7a3eefc79c37671fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a145d994320e4daf28f124569492a40c02dac58304496bc9ed0ee8a32e1b5e3f280dece99bf8f04767d5b54be006cfd0a0314c5c3b7635505184f81746fcba127d5e93256d81d346b54ff8c63d752a80f5cf65d93e7a0518fc2a0acdac5a83444ee8c88a2938912805078dc5a6bbc850dbd27eba29cd4d6a59e7ad4499239789343e12a9fea267662450cccfc88876a23d002a9280cc8209308cf140de28d44fa0bf45c67193b68df286bdeacb35f59a0a696ec6721772ad9160d74a42c3908f054d2f68ef1a831de7aba2aa7e6777b66377697a86c9f14e8fa8d935dfe01718d77382b7aaddc8a8368cf149caa9ac7abe6b59e361f776eba434e6a16e3d4bc7dcddfa821dfd36fe678f18657c9bc698b60463e7f9ad3883fd2edde564cd625935a686a45f11264fde314aa8cfcb3480111a506744ae2f72b3ba79802e94ba908b0e13de972689ab843e07da80e038c744b98b5cf958e45c1ca515df9dc4b7cd1d7056dd4f29911048aedc45228223b37ac6e5307678512609a64fec8acf3888bd54e1d951d72854a22eda9c5426a909394c0fa7e996d5e7b88d2233c8d034c8cc2af038316905649256bfa5d0e1100090a982d8029244a0e573402c5af65eea03469e61b69327263e138d9e031f293bed835877ded3e50da39de7f82e1cb94e041e2cd6f8ee67c058ec37c8dac0c710723417c39315ec7f9e4a0cf3d9ed6450db29606a5211ebc7b50bd2f64abd9d8ad07970a67a0615219a6766139fb47586499ab1b88169a5a2b2cf65a4db792eaece338c9fdc8303ddd5def604c86eab6efafaa053119c2b0cbc901e2de2f4fa78a114491e7d9e8c779f3f274ebf4e0947ddd63d739bb6f807872cd5c111e0c63cc53e6489dec445ddc821d6c2a967a44852f57223775dbe760b6037e3fe1e851b3453e47e23927a4204700673a774b268ead8d98d8ef3e6bd7f716b5c94dd87eb86d80ee7df292b8d4a80bdabc5afe12d5d9e0a8e02bc6cac3d33f2a3718ba74ac1f0d58c510a7bb52af9a007840fe08d727f69c1c96667e698eceed90f99e8e7073004573a204622aa50b3ffbc4d4e391c0b6b11ba54f06bbe7d75e0fd47d1868de7af92f7a9fa4a7bc23ddf6794247eb61271ad9f150cc8aad65fc690a1b85d53f5a39347a1c13e0256c1309c924217abec4393a243e1bd7e808adbe2ff5c1c998a947d13e2751d83b4927fd213998763da46ff47700a9b1bf4c2ff16956d1583533cfdf615331a3837406602a6a95dce762621bd140b105fec9c9031757e715393027553514f1a99588d3460358eec9368af6951463561a6847bdb56ef04a4b9f7918c1a42d24541206a6fab10ab261d4fc0a0b39e7b4ecac75a6623dc37539987faa743d2d65e59eae6229a8892312646d8218475bf2526bbbc00bc818fd0349e9bc1b66a14bfed197f34a40a208f5349ba9006c91472d2a6c04f97fd83313575a5ab3bd42cd74e7994115dea392ab25b951fa24002c16f49aaaca20fa323283a28a3d206742e5dff2c9aff78eb7a479befe59f8e764d92cb8b9348c372c58939a227e09ba4fe7a327a19a12a0a9dbee24039ffc9f1248b172f3a21ae254ae2ba3e214e12ac72cfad59bf0f67af6f90f6526ee46a8110d211aa138949263b883b9289ba358c7c0b96352b8a8ed89cc7c1347a9f225b377a69c79ca493afc58c9810543b256a5af381218d35097aaf6cba62c3b9e3b6750e01bd517cb807c1b27aeccf28b40abc6956f3529d69b50efefc73a504d5f137c344e3b8df8f2456feb3e8639065c14b5f7690cdb232ce88bf6f8a75992f7b647a5438c062025a61486ed7cb48606bcf99ad88c2a4bd9ee2d4bbb7f9c0e645455d6e9c48ca3f124abe27ff01f631923554c91f6397978e2f103206d144516d1aace0db13ebc2f33092dbfa4d96e86ae35e4ae91481988ae05a6143afaabfbfa26285c31784d6b6154470786998c8af9c56f481fa57345e7f37/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/java/pki/pki-tps.jarrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.2.6-12.fc22.src.rpmlibtokendb.solibtps.sopki-tpspki-tps(x86-32)pki-tps-clientpki-tps-tomcat @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@     @java-headlesslibapr-1.so.0libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libgcc_s.so.1libgcc_s.so.1(GCC_3.0)libgcc_s.so.1(GLIBC_2.0)liblber-2.4.so.2libldap-2.4.so.2libm.so.6libnspr4.solibnss3.solibnss3.so(NSS_3.12.3)libnss3.so(NSS_3.2)libnss3.so(NSS_3.3)libnss3.so(NSS_3.4)libnss3.so(NSS_3.5)libnss3.so(NSS_3.6)libnss3.so(NSS_3.8)libnss3.so(NSS_3.9)libnss3.so(NSS_3.9.2)libnssutil3.solibplc4.solibplds4.solibsmime3.solibsmime3.so(NSS_3.4)libssl3.solibssl3.so(NSS_3.2)libstdc++.so.6libstdc++.so.6(CXXABI_1.3)libstdc++.so.6(GLIBCXX_3.4)libsvrcore.so.0libtokendb.solibtps.sonssnss-toolsopenldap-clientspki-serverpki-symkeyrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)systemd-unitssystemd-unitssystemd-units1:1.7.03.14.33.14.310.2.6-12.fc2210.2.6-12.fc223.0.4-14.6.0-14.0-15.2-14.12.0.1VJV=@V@V @U@U@U{@U@UnU(U4@U?U@UUU@U@Ua@Ud`@Ud`@UQ@U8U8U&iU"u@U hU@Tq@Tq@TTTsTJ?@T+T"@TTTk@S@S@SS@SS@SSS5d@RG@R Ru@R{RNRNR q@R q@RQQ@Q5Q@QQ(@QQ@Q@Q@Q~`Qzl@QyQw@QvwQu&@Qm=@QkQ^Q^Q^QHS@Q=@Q9Q8@Q8@Q4Q0@PDP[P@PqPP@PPPP@PP@PPPoP@PPPx@Pr@Pr@Pr@Pr@PnPnPnPj@PiPh4@PaP`K@PQPPy@PPy@PO'P?UP?UP?UP2&P2&P2&P,P(@PP@OjO@Oĺ@O9O O}@OqOleOc+@O`@O]@OYOP@ON@OLOF*@ODOB5O))@O@NwN@N{#@NiNf @NS@NBrN)f@N@M@M@MM@M@M@MMMRMK@MJMIG@M8#M5M.@M.@L8Dogtag Team 10.2.6-12Dogtag Team 10.2.6-11Dogtag Team 10.2.6-10Dogtag Team 10.2.6-9Dogtag Team 10.2.6-8Dogtag Team 10.2.6-7Dogtag Team 10.2.6-6Dogtag Team 10.2.6-5Dogtag Team 10.2.6-4Tomas Radej - 10.2.6-3Dogtag Team 10.2.6-2Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Changes due to F22 Tomcat version change to 7.0.68- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed [mharmsen] - PKI TRAC Ticket #456 - The user have a chance to import own CA certificate with private key [edewata] - PKI TRAC Ticket #1681 - pkispawn: External CA option: allow shutdown and restart between phase 1 and 2 [edewata] - PKI TRAC Ticket #1682 - Mismatching certificate validity calculation [edewata] - PKI TRAC Ticket #2040 - Determine supported javadoc options [mharmsen]- PKI TRAC Ticket #1700 - Profile creation (LDAPProfileSubsystem) can fail due to race condition [ftweedal] - PKI TRAC Ticket #1702 - getStatus reports ready before LDAPProfileSubsystem has loaded all profiles [ftweedal]- PKI TRAC Ticket #1551 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg [edewata] - PKI TRAC Ticket #1595 - CA fails to authenticate to KRA for archival [edewata] - PKI TRAC Ticket #1551 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (added support for secure database authentication) [edewata] - PKI TRAC Ticket #1597 - KRA: key archival/recovery via cli - should honor encryption/decryption flags [jmagne] - PKI TRAC Ticket #1463 - pki cli client-cert-request should support dir based auth (4 patches) [edewata] - PKI TRAC Ticket #1593 - HSM failover support [cfu] - PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing [mharmsen]- PKI TRAC Ticket #1584 - man page for pki-user does not information about user-membership [edewata] - PKI TRAC Ticket #1583 - SC650 format/enroll fails [jmagne] - PKI TRAC Ticket #1307 - [RFE] Support multiple keySets for different cards for ExternalReg [cfu]- PKI TRAC Ticket #1546 - Setpin utility doesn't set the pin for users - minor tweak [jmagne] - PKI TRAC Ticket #1566 - non-CA subystem installations failing while trying to join security domain [cfu] - PKI TRAC Ticket #1575 - Internet Explorer 11: caUserCert request submission fails using the EE page [jmagne]- PKI TRAC Ticket #1549 - Enabling random serial number management does not enable the same in clone [alee] - PKI TRAC Ticket #1539 - Unable to create ECC KRA Instance when kra admin key type is ECC [cfu] - PKI TRAC Ticket #1538 - CA EE: List certificagtes with "do not show revoked certificates" selected is not working with paging [edewata] - PKI TRAC Ticket #1543 - CA console: edit/view of authentication instance of portalEnrollment type does not load any value that were set during creation [cfu] - PKI TRAC Ticket #1546 - Setpin utility doesn't set the pin for users [jmagne] - PKI TRAC Ticket #1556 - Weak HTTPS TLS ciphers [cfu]- PKI TRAC Ticket #1523 - Firefox warning [jmagne] - PKI TRAC Ticket #1414 - Add code to reindex data during cloning without replication [alee] - PKI TRAC Ticket #1522 - CA UI adds extra space in Base 64 encoded certificate display [mharmsen] - PKI TRAC Ticket #1535 - Fixed missing cert request hostname and address. [edewata] - PKI TRAC Ticket #1531 - Directory auth plugin requires LDAP anonymous binds [cfu] - PKI TRAC Ticket #1443 - pkidaemon status tomcat list URLs under PKI subsystems which are not accessible [mharmsen] - PKI TRAC Ticket #1518 - OCSP ee url returned by pkidaemon status tomcat shows an error page [mharmsen] - PKI TRAC Ticket #1253 - Temporary silence InsecureRequestWarning [cheimes] - PKI TRAC Ticket #1530 - Client pki-tools missing tomcat-servlet dependency [mharmsen] - PKI TRAC Ticket #1542 - Update tomcatjss dependency on Fedora 23 and later [mharmsen]- PKI TRAC Ticket #1414 - add option to pkispawn to NOT create replication agreements when cloning [alee] - PKI TRAC Ticket #1504 - Unable to create Admin cert with ECC during subsystem installation using pkispawn - remove noise file generation [alee] - PKI TRAC Ticket #1515 - TPS UI: After successful key upgrade during pin reset operation the token db still shows old key [jmagne] - PKI TRAC Ticket #1307 - [RFE] Support multiple keySets for different cards for ExternalReg [cfu] - PKI TRAC Ticket #1511 - op.format.externalRegAddToToken.revokeCert parameter missing in TPS CS.cfg [jmagne] - PKI TRAC Ticket #1524 - pkispawn: certutil options incorrect for creating ecc admin certificate [mharmsen]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- PKI TRAC Ticket #1506 - PKCS12Export tool returns error- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)pki-tps-clientpki-tps-tomcat  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~10.2.6-12.fc2210.2.6-12.fc22   tpsclientlibtokendb.solibtps.sopki-tpsLICENSEpki-tps.jartpsclient.1.gzpki-tps-connector.5.gzpki-tps-profile.5.gztpsapplets1.2.4122DFB4.ijc1.2.416DA155.ijc1.3.42260AFA.ijc1.3.4255CC01.ijc1.3.42659461.ijc1.3.427BDDB8.ijc1.3.44724DDE.ijc1.3.45787308.ijc1.4.499dc06c.ijc1.4.4d40a449.ijc1.4.54de790f.ijc1.5.558cdcff.ijc3FD00877.ijc4003196C.ijc402428AD.ijc404E4697.ijc4122DFB4.ijclistappletdatesreadme.txtconfCS.cfgCatalinalocalhosttps.xmlacl.ldifacl.propertiesauth-method.propertiescatalina.policycatalina.propertiesdb.ldifhttpd.confindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestlogging.propertiesmagicmime.typesnss.confperl.confphoneHome.xmlregistry.cfgserver-minimal.xmlshm.manifesttomcat-jk2.manifesttomcat-users.xmltomcat6.confuriworkermap.propertiesvlv.ldifvlvtasks.ldifweb.xmlworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalsetuppkidaemon_registryregistry_instancewebappstps404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarpki-tps.jarvelocity.propertiesweb.xmlindex.htmljsaccount.jsactivity.jsaudit.jsauthenticator.jscert.jsconfig.jsconnector.jsgroup.jsprofile-mapping.jsprofile.jsselftest.jstoken.jstps.jsuser.jsuiactivities.htmlactivity.htmlaudit.htmlauthenticator.htmlauthenticators.htmlcert.htmlcerts.htmlconfig.htmlconnector.htmlconnectors.htmlgroup.htmlgroups.htmlhome.htmlindex.htmlprofile-mapping.htmlprofile-mappings.htmlprofile.htmlprofiles.htmlselftest.htmlselftests.htmltoken.htmltokens.htmluser.htmlusers.html/usr/bin//usr/lib/tps//usr/share/doc//usr/share/doc/pki-tps//usr/share/java/pki//usr/share/man/man1//usr/share/man/man5//usr/share/pki//usr/share/pki/tps//usr/share/pki/tps/applets//usr/share/pki/tps/conf//usr/share/pki/tps/conf/Catalina//usr/share/pki/tps/conf/Catalina/localhost//usr/share/pki/tps/setup//usr/share/pki/tps/webapps//usr/share/pki/tps/webapps/tps//usr/share/pki/tps/webapps/tps/WEB-INF//usr/share/pki/tps/webapps/tps/WEB-INF/lib//usr/share/pki/tps/webapps/tps/js//usr/share/pki/tps/webapps/tps/ui/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu        ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=3d9326f138d56b38661092a6adfe9f1b47301cf9, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=0c7f800f7cdf6359da1076b2cce85c6f4791ae6b, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=921ed3a447e678b0625becd6a5bf4724ccae1c30, strippeddirectoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)HTML document, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)Perl script, ASCII text executableASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textmagic text file for file(1) cmd, ASCII textXML document textHTML document, ASCII textassembler source, ASCII text4%RR R R"R#RRRRRRRR&RRRRRRRRR%R$R R R!RR RR/PRRRRRRRRRRRRRRRRR$R R RR/PR RR R R"R#RRRRRRRRRRRRRRRRRRRRRR$R R R%R!RR RR/?@7zXZ !#,]"k%avz2Q-b*1$lޟKewXT'd5R*r;̓6}2 (j~L#_cK HxGfX8;PjcA .mrmi,?N$(pa]ܽY3[Aa< !gSN$] 6kMTQ-ۢy4aa$!bl6@7^GA)`̝}F`n~ޏ D)h][^M' nf칂`Gk~zPUNM|Y|RNL,EEM5X[(Hsp^+NF <٩|f_@6F8|{rIw RR㴙}w{j>9B3I2 TA{d|A5eF|l b#˃iLS=L/0&R~a0stCT(ٍ^^Qn˳%A֮ywk_g(1oBOEr !ENO-9ϖ]" ݡN ;[ўsכw mssu]R) H;=&CYlV|_V0-Z_W$1 2ic -XR!g$˂*-KyV4_MBJފH1p5mn7Unh, }E/"c D6@ WQ[\wI#@&y)M!d>&B4FH9΄\PAt *ǓuN)QM3m<h4=6#M>8Tdf>zTN8OK_KrӅb*Y0ӕ6V/YY8=KJ7 )Hp.EQ {-U/Zt:_.F`3cdu9`9\`ϝPt 2VT08 ·}1ʖI(TPBǾEfx!o,T1 4D&);(Yh]Vc ,r)WW2rV+OSE4*VUeSiӝ s+"v*'^eݟD_]]qwMqk^RU=?42 %Qnwfn`.tpc եbו8L $GF AZHk|F[/N{o=0) W{܌M= #LrvAZ;;.A^n鵀Z I4Ê7 駌H4Jtc Yg{P w294b^81G 6u}`x'vP!H#IYҘx:W~#0 #%h0U9!lqa =VԝSU}2`m'dZGR<;}iپ!W"1է֭eaBّt/Z[o)ՎKIUo&&d:_̗[,I4е>oDjPA=rNN.i"PidCHY>fBd$Kej4tUfUƖ$ \+I а2cx OkEحjz&7d=sNt>bX!I`)>OW řJPQ2 NGsd샱f+c&s$~iPZ En`;{2jGMNm"MVsg._662Sl\!łlB0?Қ?ay-ER-ω었\Mhϓ4_$eɽzl#^| 3AWj' NL7cZmf# G~tn*$(AΉ8XAaJkzX1  ̛WO/cDIh2^v_ =XjhhOg*NU4:)oeϓ/P NXglrm쇧|}s@]|sP6,N +hzVv⻊ᆪގ} Vq!xDjŚ&N8Lٵquf6E5 *;͂lc; BV9WgąsGLr&/"wBpm1ţr'\UKv: m9D\loFf<b~',A; 5{t둇^\OnF6W=Bveyf5^2sl#+9ԧ[NQY+@O@e3: wFSK Q1R*=4P.gs4KlT @Gh ,.F( nfd.F5(r ME*5j2}튭̛]LkWlpSd1תّcIVꎯai]sKIri>/2$NV:(i\!'I + Ea#Nh #B-WO_ht]J'cv7H!za"@\Y%Ua?^&.&AD়q irR-N*BrB* JBoM)kn6uiu|#rMmkafu\e|~I?=NH%~qк>dZaeceiJeXxt;5uBi\(lE+P"pWs"<ҥW9M/1qx8&s…2pa[jaиQ:R39 īn{ÐzƕK"-C7Y1I^ bqyٙ06q# L=~),+zRl #!Հj:Vv$C-UB% |~Bpƚ)*+\ /Qб~^R!#LRşCsYd@q~'(l M+oѫ _RqL,tc [Z/cM>̟( p.J+kb.U,Et-uzpvdOMIStFn49{A0}۽rʈ Gi=fedBiCU: X`eE-CYBgMYf}F_Vm(XI+k$\hZK鰁XOi' lǞ.ۃX*$dtp{_ T0]3qkd9gy3ţAf|c?`55$]u2`YR=>@sĸW _❫s|i(,*Bk[é- +?hc%犉D3=~PvGY9".:lC*syȅsUff,J“_. :{03IY[*\)T(|Tj~~|Єsf.ѷti+΢~IFyo0{,W*Cmf;oYq:x1$Jt.10f]WˈQcl@D0m+2sg\3 A]uc w;aQi)WܰJSqcb/A8\^Jga T9s4egglK}`!jhnX,%QFy>+2Jj®̑Z$P L!=YԵכ{B"1װ[==iU,N #li.Iqk/*5<_-_=E[nT.sSJ(ǞN>OU~J"ހVpG(DHII ܹɄ >*$(0+2RٸQAl8YV {˥iI^]l9FmI=SaoCˁS Wpu %[և Gwnϒ ]>|_aT:X=v# dp&5.M.eAISWc2[ A> Pȁip5gS0%[~Q 9ThdQmW uB.l=LV\mD8I/D.LI;Mû;#O>'lv60rG8D_:l[MKt6Iܵ |}%јާ4pe)-rTF6$[*zE|`boT`'m-24޹Yr5Ȭ]("RMQE_쮵Żlw6uZ1oM(Aۺˣh׳Bw>dCvLJ=s1!+FحARe{=fȀx>&kLs~P*acq ƴȨ!+Rw8'T\$4Su.0`a:ykC,'~L43.DE7\& Ŧ%D8@6|e$o5h4s"< șe(7./53_|F)/Pr\z?/PAgpu#.4Ƌ8C8 "T]GS/ D59 "}7NGW݈ٚr h)ͼyH R=)mzQs.~zVRX8UjeD_8t՗̘C7P4) 9]@yP{9'NNG U%`0̧ݗQ>VA\CBb4ep;uy}h,lz޴:`v>oh,/)N-j27pvN⃑m>oQ9Ruu*NY(Go-@h[xFΒ8EG;ao_3R^3WEΊȈHqlhR(n% .fmn5rxl!۠ݰ3y,܁zz<V7ֽCZ0:c?T&9:3KϜ.P\3WQzW^9t>}tǎj-kQZe?'KJ7¯Tf{ZpbnM 䐜V {nȸf[ g/. v#Qp [+pvW7>ē}, EϿ+$Ks}+L0 但`U0k*pPH{uq 2>VM:љlC<݀"ܵmʜc.Ə:8ל{*>3 2SoɡOw!L^?x]EN>wZ#j0[CTF`E:qB'm«)* {h]`F!o^{X K>˼D:hQޡҊ1caDƸ|L_?!~Jr7{DLg _QW_xjMu!.:Št^r?0sb ej\~@P$οQ"ा|:YFLz1N]ZA(f -g-2gިk9 15|̚+|c6""w nHH4 dn7jtdqdW3ĺm{gvbf8'T@C4X:{?>o`2y|~G0;$R Nx@lD<6RT_e#1X I%=g[L4hl<"2T]ntX,s/Ujc5iOWաz _'AY{r 2BbRG>®> ,Vl⊨^J[G5? ߚU`̪sl N>FQ~MU4 b6v~_B rUzSA_ŮdmJ5$Z$oL`Լɺd_3uh,}؁Z5(&Vq"]QT*ijǼ%B76 ~ژ 5\h ڕy,«XTrmoFOTo]yѫb 4kh624q|v**Hw׈"&s}2xdƝqLzEJ &P]0%aW[պTtӴ)Ծe<؄ۀu5$kuaBG X=ta5@?vq^t=?a .<鋜L79^s5뢊ĆZ i;MSgŕtjW  6uuzP/=ѡ"WcZȆV>>#RhT#:3fm%8T3tTn HoUgOa %z|?Kb;\/6o0AwlpQ|(h2W(gI][t)h>pH^#I$q`g\NQE,WO_R,ysJBJ^ZV7>9bܙ6߄moi QZ.o _'^YߡG XHڼKlY:RB|WUWȆq2`^cA 4@0'zTq v,+:D ,4Øp,rbbV[F8pvRSwϰp߂cfYpԋVsizT rSXXٽcֈ^] Rp*]l Q觋*Nl"UE"aHE.K*ƟY=)(:囔 ϶Vj }̆Zy_2hbǃI y\w 8e7(A!u&SpxqjAԱ:evaFgz\v0bOTa~bKdO`69ޑ7ɿŸ郏ihҜ.|?ۇgTMT؆gEB_\Ԉ+e׫'y!ڇA:9#n@NirO7J6~|$Z'Dߟ9^[R G>ȭDKQ :J=ܒ9O0Ǘݒ vq<}T!:4@{ WVu5OO;yXsYDA3JBXF*NT_A'63v<葨P0һ3o.0d3ٌ͹c봑1cwkaGa=*2uDn]80,)+G.o(WmKsS¥/"ar/'ylT9!+Zf$_s!$pzL{ 4jut<P\XLDz¶Y9 =M[ӱFKstHa=U6+:I"hq9[ {H@%/:4'$EF ])O2M&:lPAikyT {XEDv/ε|*"fn1TO_.*{~#5(Ţ v1ߤq\DNjRe'Xb'8he,)ļ2g!zDuDDnOLK_21 ?'Z ~fNXAz9Y >y%Bb[vB3muR@`XMxd /^5[/߭!Zw?Y>Jb!˛j+d09S3ūr<57-R@:_ziA!7utS\@>q{Q+i 6)o `RϽ %sgC>d$zwD=CaŢVI%vw-X*Ky;\|Tܧ%5Én)uϿm _s"45d(~+;IB2\Fm+pǙ7>H,hE#נ/y&;c7n[|aPj[UPHPX>Dd_pAaE)hܡa2#g T(꾫:)lïL2qG+/tul|/17&LwM#R.!b`dzg&mvQ̌aۓq!ޣVTrr6쌠%0SX tZ#QDqcpX.h{TJ2Oz_/-ԼzՑSh nE1)=uOE*~0F(P>GY>U0TAT>ثM!X{!ˇ/; OF+wjU Lo:ٮ_ ynAk; 2w7&Ok{i!n}_hoAk!ƾOhnby3ŃKWjb[˶i]5] FK5N]XO j=1Ub[UL}{&˒uXi:o4 1>'YD֦Hȗ\tN&~in[b-VӜJ7ͳUM&W˝:5z%([;!tNfr5o]t*1E͉J j IK:Kr~&  %Q[ N31B?T ~V!ya I<"_huL*C^Ouyn=o3!5 *zsP1rZš67jx퓁7gI6PX9.oʞJUxR$iz˦9qNz; _la|Fu,IY kN"D0-PD_mhkdm _Бg壺DԵ~Z&OdQQz[lB">OFNs_̄tYZ`T0bkbj ]hдlKwm i-Ȩmji~ӔY90LwH`EJVa:2z>TTR(:XI\xeƉf"Ё(A=ÆX6&bؙ;n ,m>ƎY *cuʛNPf&4rn)AF)pN/$mhlUj?'Oҗ  H[ ;kft4v1{^\䑅tI_/M^ ֆ|{7AXɌPxgsҩ,Cݳ89'=o6wք,Wcx7N14v v7d2#T?<=dK Kcd ymXXf*yH4휼%ro[a!*/&u(L_w%tLeMMe/!W8 +1.ՊT띒Ж?kDZ<*pTP2B.Թ ̬S s"V5fXW\Ƌp0 KXA1(\!) U|Q_􂹚WցsZ1\m;/1R`6o?D0)Mgra&9d(tvr>oelHs\:G 5vz>4(!|%93PD'k?zh =N9Zx(j(uáD_BBU"Fm ַI~紴FmWwZ f6Ylmwf.D6垈+d=!8qD4B'+1+EK5c\(4R&Qݭ3z^]$-D j=cGu^r[YWHeX8 gա@pRS +2ނts9"8@Z)8Huss=%.@'f ^)NOJ!]K7Qm0h(8Ngh:+Dɛr[r&TtH v{n=MW]^22W;PbC-(>Bw=UMC}PetJ'_ tw9s\~DvЦzB!|<7e(/=#Ѻ\ {Kh~9I#zR߽*&L h@־U%) l4瞛' Aos8k奯+@qP;7UYӓꬹoVnĔ1{LclzVAwMa}%n#b@+o N Nm.}EGnPdgq՜xp Ā"PdMn&3@G׷>;>!OI /MO2ҳJs?S'SyJ{XڣvM,θ8'2M.=p<#/NpTC}PPo&Pam2>\pX $gr I(MCMT]XT~f'RB-?YD<(IO e&XVkM8ڦ< Cs؋- YD4W.ٚH &lxY'(;-_L-5sIlՓ+ξT5!cu&g08BFjٓ_$5: Қ,{ l=LiV7dZm=|{mp+m\6tiݪCgfOqik0NkEu l՚GGR#gܘ5DHwN쎉Ab׳?IU/y3JN˧)aDkDE JqDըo0xe"\*MSbH/ WN$UnõA.;-ٲ8$dٮW^ۗRNuʩCFWx yQP_b> Ҷv uh 3>+&q6;$㇇ٖ FGL7Qf2-)e4HjvLeӬ[ٿDqi/&O9 Ыx]ҩMc/xL#ѥlr=Xd1.A c,~w' 4v v>b-djQ;YGt[%$鷷?>RVY'Ў (?M4"KvoS) |1&'͠]EL3SXj6si䍮 {(T#r9x #k)Di 0Z"Z}+f;C #Ad@FgS0yo!6]p,kڅB9թwR#\McRd# ƩjlJvՁwt?Ⱥ}ƃ@~Khu,cm9V"~]dQc>vCLVfdZ4A"W+uAt=!2Xښ嘥ѿuyHPMn6^ci/|;x}m4< B9j1Fc! 6ج; r9C@`~tm+ȠxHGπ? x `D_5D<;W_R_# 9K(7PmY$p578$?767ͩ#`3Uwf0EQ*̭֡~@{?z^R ri^i?ft0Ю7Q0 1~ X#6SrNщ =9Gj=+4ep&(y˽VISw2ܝ s>1t9EAL_;GEG!m6usևB " )۬OH!Pl:KZd9VhhYOjR6-%Aj=\H{Ď%'8K >fܓmSLhF/-DqATKG`M6?wvd+6ޝ*[W 9_XI옳-(ܟ d$ʝ%s}[SZ3nJ+Xoyw'\λշVeIPA 4:GMgos77L#o9;ZaQf`2^Q.N#0*L\yjWvH%/eយO.+pL&}VriݐчaZ.q u:}h@uUZ?&f\(͓{C 訏n@,f;䤗j1Qd>yKeSĔ /#5CX͎=n~bYkq4L/42pͺQFs CLn?XفCRG!UmӴSpoQU`)$` olTŠ7I-: J8]+dR:.*ZvH?.`jV_XcY4hBM^*65}T@Q>`MSD3AYjpUb~3&]X+9q5GjA6Y-QFuzxNhoOy޽2JKailW vҖ ={CO29n#%Rp@G+ۯU{Fdďmzt]3h͘9NC4.H.)C8kW aPRd];Rq Ϣw[q(4+tCfjЫkRӀgPPxgVjDFVs[h`OFq"FF3tqp;'"dudJ(=G9|Po4rhc>vE ^ӭ'g" K9 8츠 % -bIUb(u{wU{ a!+t(&:ev B m8P{]J)S^=*33dsѦ-EI8Ű_&'$x,o<^ SJnVgK !ܨ+PDfa46K92R0Ŭz#tСv]).Y1irU ]I&35U5=b@?j=h0ڳSUzߡI~q(&i.bt+ {X_ WG8{mnepx0/3XO|YEEiU]bQ+o:Ig!Ao|+ҹ1B4Gsevfp]MFtȞ) dvduߕ|MŹ7^7Ü5|-HˣM4g(5Z , @UDq6U {T$bh5:n+Oݞlx*Z-GwRNlVᙟش3CCA#è_mh<7f{peBrH\xy\X$/&S]~ej@aÏ:#xgk2V$U0rǶ|va=CƯч>0\# WeXUCw[q*[6FQ^9. l2++~jw#{͂n$ᅜn1bsգG%[Q $h Ȉ^4nI rhsa5q;;# 6MWP (8ha׮G‘ 3I˹HĩnL||(VuX%B޿',S,n:磇% nwHf) ƈ-)j{bQL-NX.rk"EN0HO8XǣՉ~nZ5C@57WO`oF;Zݲ1he;n@8 <<L%yd<ܶ9BTyvEIgnƯ@O|#KUͱL$ j |6PtPFu2;b$q3uƴHϷ^8IHv3ݰ6:пT6'r[)S.df)<:+N%-u!-7@|<=Re('ZmrǺ.!vGb;ʛ/_Q7Sf (VvF/V nnRf6Jcy!V#f=Ec9 Ĩԭ͐=#ޯYVbU<,'9|g):,u|ЈZkϡ^aTĆ׫w֢C)ؖ&o#8fliS\YGZRwG/bzgtH01b蔞M8i~T!#]I%<D@/bҗAVTH!PZ!.8bC<6+Xޤ!^# % Gکy,9лh E{Þ,!3<Va~I-JyaϭylkJkQ̇' kfu4]g Qe-hY))# X;d˨5ۀ$EuUTj ]M*?X:w; '`:W-)ir7__rކ@iup~T =c;MX@ Itbtwl7q"O,WѦPI۹A}zKhni˻6b+&/[ v!g×0l[?>+X| T(^u!;k~g 뼀?N3u70}( U#3o1XazF -/|$}ks&EAF $`gixH+sGdفuD#H˕lC{'p%vɹc:@jnya%'Md}a3ok5ֺ "_/蜞myu&!e[ [jR1rlW|T$gt&F}™4Vu+.'v3:#>vP~)-m@bЙ1kakiAϯS(*h>YU~D_Suȿ"pB H ]GOk.֌g̃\;)Gon1У(xgO nS%tAC.7??%,jʢj@Fdo\e> D*?ݾ;ƨeE& _-Uٕ,ȓ[HAd[` CSxkL~"?ּ-nF*:sBa,cI&\=nѯQb iġGP_ e2^!:`37JcMх:ń)_:]D 4MAI{og^g 5@e64SkRxPGy0-@n!>ќy9h9Ψuv{Djx|2+LrdU'SR<ݝ˯i7z]a֎$"aZ*Kԩ0oF_'kb0@v|}m jj⭅[ mDA,= TG. %t*Br4`l$;,X]Ep2RBJR[Jr{ee EuL0һ>vKf b;gC>*C%wN^y2eXNax1ɗ䮲lvuZH- )r4*5|N~tANެ*+?'Fh\6#α .[O ^n0`{{WYkY`% ֽl:R'S/qp+L;UZ;[ |οHİ;v(MX;hL_% ׽NMAYn`a(/7EiK {EO^2]a e(٘tyUhc8e=8-fXg V]Y5_>$u]u:|om: 9酸a6%R; `yu_^os"d/y3ʄ/Ji6P0Lk!}C I nXs(,_[)PK>]qU]g]iLz&CBS)# jý.ܯH0AՊ?-mޢs?)> m(Ƨ V. % W2(8ǨZL.nݢbU䝟þ^(5F6Kظ5V.7y9*R[^k {ib]'EWVi$ے0//*GOSd8.7S>oGYog'ErS_>|O1RY)xI%{OZ y,zk]K&6z̈^:`X'hIZT4Ƚ+sP),IۂeoM_)O}ʣB[#Sre%s0bA*/I)\zHrQbYfX?=Q7uZ;׿Ʃ+Ygo༳:jp"$2iS3:1Ce*# _'wZdQ+$YcL.D<lBmUc w((E2 ho#)xPIRѺgRv+.~m(2eCtݭ%^6Co[8;emT93 t>z:mj1Qn둋 ~ +Tz%Az@z"!A)梠v4 H4 Rַw "7c~ӊ"mv9CkχK[8OwGqIUV(i ϻr55VE>9n8.4΂e@A7J;]S߬>_=v.P9zC?=#/I@O;˪< eѫ%6u}%  Si-Ʈc匛xmF&% }K"!`=”`DuK6 ޚ@ wXl;7-Md+ `oxw@zuj^svP8y]=y3ulm Ԙ eMd'@<BI ~P`aM>!s\L&'s2IN!g)kAqKXI:fA_+EEf¡LP7A+ҝoy Cgr.}1EdF(:8;[堋ERho'MjAY4QjLpOa62ޓ2QP?"hZAMJLэ~aM&A4~݊G:K21xuWMx$9qǙG'bu?+r?x v|=-eן+Y (? EQ:zC^a*io,c"&)GkVyU+pf*-OQX죷_pLacV%V^cb sgm\ȋfyɖھ '& }Lhߕw+Ɛ:_3=h`KCճ9pIH1@l]+#EP%dc)c(u D=4UzqYUdv gȰζ6~ՍhLm߮%y&48=> ?~݈pW7_ޒ<2 $ݿV1nY}JkʚP݈s 0)]q9ܖR"e_ (J=̪ U%P;RI?RE+L^0FWj,ƴ:GPe .>@/{L:`'m +HD[M1R4_51mqJ8P0*ƺX ʱa+[] iEew5Lуo]cT&GqqG` hƟj}C%%Uh7Y 9ig,{y&Dm7`n4,HkЏ[m(v]XQrlj4"z}qXcvQkzV~Y!jX(@̻:jUe^xs҈di4&n11>ڷW45GDCg=|tR}4b%CxRzAa)ʔ򷺺lƬEQS 뻸T  QCWJs= &jb./X ׯplt)ϣ2MQjͯ4fg:URNB8x Y@PoOc=-Mh$ȹ1oDrU1 TȺz9#c2Yi\- M]@QIK7\ep.Rm1=ag}Tah$Z)c} ds'c+8gF_ >9o\sVbވNl̖(3R[yZECV~ʰYOͺ 7l//[*BmfHsW<H ?Os|P j`3VlyM/x姮#(u:s6s7oKw"dȅy(wI0RrHQ;E[D#M}f)?}(.xy': -򗄃Gha52`$y˥x rPW.ڞNisJ%." F)p:(W^4ku3BΗx ^gatF KyZ&/01i u7فvJ/*t;]u #~ut0o ʇ#%WKz9*syKGYydux v]a.G6l٫ GnA#y'l.0;cRoz=3QNDܦ&T"iki%)7[hms\/]2Mŋsv%F vW%;N+h!a[j{!ԢmT~I裟_<)% mK+⁑qYwC3Xm:WN:RoxebOlt,v*L5?HeZp^^RSi#W04F z=Lt#<2M|@)&;,(V̄$|0?(c)u"cj F˄"HF(bӻUuW*V5/\.HcmDB& BV䲢ŁRfP`g^H!)>0Ju %^}<e55E*f47+ǡD%̋Ý^J H 1d,~_vK!T4"_OlVfˊƞA0Z2^`Ov/Ցpsﯛ5UXG2+7*봬'ӈ=sx6fzQ A~MtE:gbqK["ӽ3 8k]NsO4g[*Qnr7;+XԞcB i+F _F*ZD9p|9smFso]-+,_r )[PW^_Z\WtZZ!m4jJ͟nIOseՊamZ934ښ޸`0ͭ$ cx%.@4!NFߎ܊݂2:Ǔ͋채;˪`8@ ތ +_P2],]0Q1_`JfVZIl#$A : ΀u >/M0D[3٬l"!L_n9cg#@Fdc$E|iЦoǻP0sЫ@VNo^>M^u[ce=tn.*2"cM ua:,NWB8֗Z'<3HwԚD]ڕ@xҼ#9O~IǛISZJTc ȦKCmikv;v]svF͖ؿ֑{f'\_\M}svSvj VOpu_0nl:oŒ';e(eF;Lt`eF "`"0281L.Ƙ+⭶* vYa|N&t7 i()8u/` ;Ș>y_n]}9yiiT O#Eef}RBa^-֎97Qe pDIz]qų*Üf:^ d),ssdtndW*#ߦb M'gџ[F`l׋}7Q Qh( 6FSF\h!3UU7{)jr@/J V*z%3/X׏_~4qz$C_hW/18R+t.TJP#nS%\1"!(Iea'EN&+4eʰ i`ݒ<c/O _Vҡd|Q08=3TX SBqvtTC]bUr2*D3)N"\0;|})ˆNH£ĕ%X.iSe >r^8wV?12 ,;}tF8\z  @ٻ[T̔Bg:8hBm4Ty*X; 9zH#ӬHJu?g5o}zNQ:gIjԞjXŀ Iͪt>?P ilUÀuzE 58TY׻Q4dA{IG^i{D-T6sB/'E>`,Y3#fJ)=@;iq2t W]]2n,9= Gײ" -^_%xŜWn|}{yo;Br:.I%AsB3? qFmWC8)z\HqDh.!Z^fXw9' (eY ))VoQE} Uݓ~`UL?so:/@:tg\\g{熯I~ {Yx >JOR)˟_(0Ҭ~0i\ ;|ew/4@MmI-JK\1 ^WgI,b&2{Ҍ$B X]Ls!Gc]M!H6TDCv/a55x/Qnj"IE 0Z_q=xoAYikJ_L.."_жOQ0q6[% ZzDL#:νrpj "6{`KYVq ASJclbi-4gQY~OPgxD4L5>|?Q}!n LtiLC L j*o~:$0S^!h5sw¼n2z BIųnVQ8wa5* Ue#7M+x,7}/d-%/8ͷvH;.2c9tSegE0 zU\0 Y)J7"|$Sά5 Gw'-[S@v(7,P7!cB˖Ͱ(Q g2 @vY.P(+:Șj:vSduQ?xCXu$zcIn0Y!5@dd<Xs-UҔoB@`[/U. u$*sM5Տ>l|>/3 <*#t4X$ Q?jx0ÿ7e~|x of$ǔ>S+3@ LC *H(DΙ$W#~SP]I5EƉݢ&ʸ*~@Q[ǵ!A/S&I`r[CY E-,^7]X]5'J [h^fmVd7!9%t|`;2 W={% ${`Kֶ5=`"`7sI6UC {3=,Y_Fq \!!wYP${bR[Cf0OsMP[pbYفzY.)g{- c"ӌsgMKWtNv3%DI{"5ȸ!o{ﱶ>~ zT/D@qj@ g=q#zI:@ CV|X$)/Lm[C)v޳6K=l2=#tXk}:RWRΐ1?FQ0`w<*T`FCMNi?DjR CY ^L+N'domT{?QZf[hf~0~ϕA؊)aأ=Eg)7f5 5~hݘ)%[Hoz̃Ξ_٤|He.)sӎSp=87*uw!ѓދq36DDn[J\枘> ͂Ec9/clinvт%y~ܕ.nB0k@ hT/U|Eנ& (Nl:*V@HmQd@T$],K]XS r2G|!^X,sP\`o^ժ$X%_J6)1%?*OuXOঐ* tFHqxmyO s.U]p!t_j{7+%AL8<$ m[P~#?΅UQVGq7$sY-Μ'{Rq!eSHJ\U Cɮ~@B_YH'܍\T^! ]oREJunaU1!ӻ)_ iE*c%1Mt^jу΅P ZvJ_\ŞEjϹ:` (^ᦦKTz(M@ChT͆˔$Jn^5w,ޏ?r]*I^ eϢW ɯR[\Q 4pШ֗r qTN9٤.ʋ.e64 5MD+^&ZO6mux^{څRUEC+x꣎f@ k(w[,kȲТLf x _uJRuxMa$ H,)-@5 uN_"En3FĴnrr/Y]QL vywNڰ[To08ƄQjh j4?KH(1~SE]QbdW,<{a$#!@hx1}SovxYTQ?ݴn~iDN7j@/I}gv)jǙJSp] @b(?ɋP(^80e&RF|A7%j,aeWYrWy@\5exBf+W{ jT. sE6BIݕ47 F b廹1_xe';5@7&bO)4٪eӬ8!.c=_Ժ 1ˍK'=8 'nS%YoYĈϐ6B,EN=xㄞ}/1]kO8 &گ|3B; /d5{퉾l623 ߵފ-/K14wK_ZTѫJlH-Ppyq?S D({OS>GƈGLM 'TCysY)P? :yVx3 Ro%[ɀR%IgwsScD_zLNOU5^.H@0Pκ)T`-8s|IyRɶib ]~r)_UbY1FZWI^p /s9DQgfc2v)|;[Dkuӝ XcV/P/"TU]'&dRs,(pȗm!4 弐thD5r% G-xnq$J@kVU*(O[L!ZONQ]'GoLWkBEe\oVn%/CǛSoOQY6|(&@IF/)U'm@L\ޱz_F+Jd :Nui73U/Գ3/n#jptPzP2D뀧|6Z0XWjyb+ /96*<GA'TDA[DHoOHQŶўY|0p|~rXu!qnԣ'j8JW\?Î-i;LdغSxr! Eۉqk-.JuT/<^O( $g9pcJf1jI1#wעWېmrzV0/'9Ğ7A֜V{g"8_ qk<+ g_I !xUb[nIϨRqY&$y(3 Mv3Aw{ǃncO_dS3ZuiWsWNg&KM&F#!_Ɲ i,e8{6j@wȪ͕2ޘ͉=y)qˆvJ z2dwdٸ(mw?QM+~W^Ou1]4 pm#?E3q}.fn5Ӎ\#Wl%/.d&/ EGЋ-4e~٣@C[,.r;౱9gp5< G~(*g[l9Hx$yY ieQN#*"7#݃Jz:j:蕪yuR"t哺#jęs^agvS2FA}0TS1] S1Vp("OSp)Ցd[+}OQOvXU9]ڟ(hL] Bo$-z ^SIP".0@uUC6Gl}TiTTF0}>(ҽ,Nr>!>_`AygʔcY\M^5>EXs{d#;큠,1~mt=3?q9t1O hpxm̃P7nCitB}Gçl'8j;@o"ZmFyg-lXrump%G@9b1/ Pb/z3'\qy-O( p_<@WUb.8KL24X{-#hH0rtZ HV W=fw69D-< 3Ol\,՝6ʙhFYkq`[[dˢdA8dQԓA=up}$~mC 1ԖKo W㨇Nu!@jb^?ꐖ, 9NpV)gx]e`in`l#q>8 mufDt;n #IZ A@ x fƖL%m :|^{b\Kyhb@`dlSl:C~Vy9D.ݫ|0%6y%$q|RScwa7B,KnR o -qe݀(ݚN{eǾ5^h/=/K7pj'4D:)Pΐiiⲟ^t|쑵 ]cָJph%J٥hh0?&Fӫ.f0qۦڙG8JSfEjMSĮ!%@\S> ] l=B2ۡIJTXW m\s|]͍s+&Eix&-8ꢺnM2?Tߐ\Irȴr˘;߰H H`) DAAz#2-q;B ߗUb+nuVq%kVbcj=ʩ]ѽaY.jUh/J9[N_H妩S#W9xF2qiViTJE"6++l_`Z(nf2K &o/nG13kw! iDpryְ,=61Q2oT{!lU9P".]P/|o0CNoauءV N2"ʅ%ZZhx <ʏr)?a6L :_:/Pӵʆ^wT[])Ȇpv#Nt:߉GD{bX,I_Ȱym>E ڶ!/bwk8w;-A P3 {s"nJ)IdL(`JB 4 u&쀒i%]pXbbj;+O_dqKX\'4KieBH"/%;r߮O ߧM?ƿ0ʄp8u,{5;()pFfKt:,+p^b1cgM*;p}Q糐X?,]rx^a뤺 Z,EԴ<83G3&JOtsK;y}?uDIPk@2NY0r"!Ql̇~`oL|(;]rbp22$Oux!q&[)cn=8@ijNz(*0+F1NCmc*J\ y9j7Q$.Lʠ`ߐ}|Qle0yI_Eݴm]kgDI^# !94h1u8ɲ/S D Y Sߓ*(MoXmYcE'vr:5tR(HheA`muʴfB.Kj\yE@wđ+04Ѡ_s!OKjikD$ncmcpڒ mr݆I;8Ҋ!^Y*:7kJ gK:W]qpMVȴ,N-`ĦU~_VjNAds^CV7 Ŵ\-ο}FٲtLDO2ORN` 霝LL^: WSr4fY v?Va¿υ(N )WK'(g?*,H"L`} CxAJ#jϕ(IMn i7Y$Lúhx݌vQI#oWXg(l1yAofyvƽ xd1C)'u*x!͎K$q g;oz於dC+Tb!->u5z|ܑ')o{/NvGX9 {wod1s]gJҔhyP~ԨTM67`k?=)%k;-eT2SE8WlTM7Cuz%S-6,ĒrT|pZoyK>bz}j49{ԑzU%Ұw\lƟ5  /-OzA={SM-iٛVԜm!S^թcnq8%+eӲ2/W%=؝K39-& wm7%^I-Fԥ=WQ8դ%vp\0ث>f %.'MNqo5;™/uI4XsיU~S+ryy)߶mw>c7ݼ+?pp~NpaسPu8^[Y#{89O?mҙnPl,T_n$aXID!Q*NRr~8s:8`s踰ӑȞ$n$8&T ϙzcTm::'7#!aAi=^_EHl7UFaxo;8/HQ#ƷH卒(wG'M^d&ϭe`*믶@5"5b4JǨ0ׂ~0'5Lؕ6f.~O]57 < <1JB3ԓԎbL%a_d@b/ar9>yƋwSB|e 73n,f&Iʵr{VHS /q63 *(yitP;UrWQp}x D<9؞i^@zn\u!?-ˢ'@ *)o%HjΥ:4ٕi_<ۻ&ϼ3qbN kE-X_@ YrJvuA>%+JG1QduaP&\f5Wm^'av$ƒ#U`,wm=WrwF:U%5@+njT}[2W,N)iuՂ#Z7}ִ{;[zz *,-HԏrK @TJuT\hS7su@i#t AA,lBׂg_Kv* }33sٳ*6Z~?.&x$qG ekb"uF6&>'F^"O**\\ۢ]Gdǹ3zsqld~lWoIҧKx@a]PYj#1n/F`Qo@v0$*DVU}ns-E҅#eXsUM"A,z8J)cslݘWŧ=it訾q>!XGH]:+2~_[QP5S Wȼ}Yw_ cj_'&u+a!z=)D ޖB>$Y mgu; -mh ^M8N@6FxT[+9jŘ5DNdRSef`5Yc<þaw>;ϰa'd+qbïv#Oqj!$>oARߓ_y]hю`܌SoH2G\6dS%d_K΁A+]ߪv6/vƵc{Cgal6_A;K0I9Q5IW%O꺃ʴ`zK7}Ym)CMKEYF)ǤAMM}W6%),P ^E {pIC+=p/fY ^ֆ-` o]}ɋӧ-!a)Xܴk u\O o.铠eXs%E5Ӿ!c;v5뮸 -gKnK:;- "{d]:sdlyg7|!uzȂwr80Bd2;l_~o$U\$M20DRD!@ \рe;^HoȌ y-2Yx k(*sy(meUF q`dvtBФ?+n""W&u͈5D=D`XJ,r<~X~bkpdwX8` `=⯱/gͻ]drKݸxeJb,)t)=NWg=V$-t=f3ϚIKj^{4]] Zϱ1KUug>(W&{) rNrZ7+0%V_`T!#&z9W eG4hf:kHBxΛ1sԂ8, ZE\3\8( ńO`-]}Q+ĺ HFpOD5c!_ l?y?x=ERa8 hS*ҿ2ޞ%{Eb IT f{T%khVW ms(5N+/ $.m||DڹxhOFl1킜nDzTҬ72b/Qr)>uzռ;@cdpLB,K-jvy!.5W Hԕg7,2Q+ukYH?Y5CBfNB au+ٗ^\x;iA/LLRŘnFe+ |Rk$֔j 1M / sYc#l=aE["ǛoPFKkZuP yE:6Ӫ|E]n++qw0z6&tJMڏ\dF핷B](4(@34ahT-S9g4]/= ա4cS]Be-ZrU ty r̦{:*A nUv>h/O,cfkG;&'CYѓ1s[>2/gжoI\6}١P7𻄚4ydĽ'J U{9I'))jEő5t5.w@-\KWj}c ι_7t35gD]$iE,f#o`w_b¦-j0LclcN*5%CK%Ιst|^s,͹8KSP3-Ǘgs u[ W Š-T:8-lt_W{O)3[,ĭYs^RoXvm sZ_h%t5և(Wa!G˺\t3޲Rʻ? }ؿm9P.Չ-Kh .<q8V=o2 Ӹ ev+'e6/HT+|N* #vD E(`Q!mXeH6=Ě?YcXt?fŏ]b`OW!YV?6:%^;Ԍ6-z~G(#j[xD{΍3Xpd 14Բr"\ :-57Y]$a)\(:UJ׃~#J_ܨ-vU;?k2XH_V7X!&\7` < wcô?Ql.chH<2'>Dl]L)\8i_ɨN n}+18[>dWo淩C/M($s&+ygU%iZsO/Lw~cHׇ:;ā29*TA`PB15 ~HK.sQBҮJ#Nlڪ m9YCԮ 2*R`wPf7[S+b2 3{ix$&|VLZW4ocM ޺gKX 1OdFnct\T 9 3Bx(!K-*یVΜoܦ7}Eu1^ ]Y2MNvX >Wm1 RfXԒ M*\Y W=s-os2F$ fu糹!v';^ߌj+jky"_6lLQgSX;x@5@SB~WYk_+{E$)i@ bFگΊ %MQ’!~eo[Te66.d?1z.:ʹs7H8aXMn#>rj!)\;T5efO3H_s=Ar#j '59O>=C^g ;w!7~Se$yqO-\a=ʂcnp|yό`ߍtZh֒Q WsMN̩ т]ҫ?WJ46JM \^B^f)0f95|f`,6vQQVLIYr""@Gqo]/|* 'p m3J\sjQ70,͑djnkM<1y9bAdr^BiA{{"vG*Rn5w5ץvZs"⵪?ÆԔ@y1udb){Z&FBT%9)b ӰK7NqM U-}n/Y6YEq(`b4_zdzo@`sI{C3Fr}ADDУs8Y ա -g$Q*<]ʤ@FuAu̍ynr6ivUy$66g]0Lv;>O","mtj.v*72DEdb*K;B7W6Z.jlSڠ[{H&6_R=bh{-Ԃe"C{k.!`Ei7qzrūPam 19#3\|@,ܐf)oO f_y-VVG㩕ay U ]rypaԅ4ƻtdѢKaB^ƧUrnl Q60^w j8 ]ɡ(k2nuȧH7Zܰ_]ԗ$ozydpJELJ3:,i ^YG0SA~ kTz"bx &HhLdf<aAJU5}c_)![.KC vJ*Os$j4ނ*O!n|e&J34J8P&'6HH9uᅜh`JyUc}/l*VY_$Bv_ E`Q WWU3ӆ*K`^>/QP4BHs:$u/`@Evaqo9ۚ[9Ebv/0g]++u{nX^s|+Wf/[$Jrp U=^y犣ۂt R\ŕId]:Bo&~t-vjԆ?$[U5y`X7f&KՊ\!)u \{s`JY+TԠ0A *i !醍_c#z Q5.= XEciI$^ָDEw14RwqMRI ܑ2˃0ejs@MP0\L*7"b݈Owt&v4VYByRfu@!ǐCI< A@}P+ M̓ޘcQ#O@vb(&_g`qSa $ښ1K>e[M x% Ov`4/>ӟ; _潇l?HÙd?iuewhazv=f"d4Ǵʅl$?zx]@A67$maxudf sw4BܪEl b:5rTswII0oe9ed@\.10H{#B3US@6I$ޱAS?'4] K~n^M7Gw]HzqI::d$)Yb_ MnkP]pPfQ 'k bՀ> O"= /lt/&cL=Y c̔ 0;Vuߪ򌄮2IG%c`2b`lFbUq05hE_5h: =RGr~C"oi bNu (K~kL^%(ir H%[[4⚬/πj8hu4s ƽ;+L/L[L)Ɋ?!QgY !&fY-BW$+^$h}U2Z6XD58B_ 65N܉Gǟ[K6.6e ihUW6U<9_TWYz` R?5 RUqh 8#x6di(F6N2~9._EΡqr Lκg{y`,ZXgQZLN@ܰQ"1+rV:DkG 8R1*K'&X 8oB4pWR)rS o_=a sC\K%t]cj/[0M&$s7Lcw|vϟ!;=)vEGݒuz4_/BY?)`_qP5N&lL Bj/ t:9+RUj Ee H;eNaw +(GԳo2ge.;p8ʿyYwjѲ>Nói1 !=)b6(#?IX2Bfg3v5!R'\"ozC4L.'.!R[On? %bLo"L ŶJq_[g-J%Mah~MtLfp3+ /@b4UA0_i}iGLn6}}IL >JMfHLw`~b_ VTv.I^JL"^\ .%Gho+ALJEB 2]S`8kmAbì[*E@J]͓kMzAY}_i>՟Amϕ<Bq~8Q;[|"^{=wH#C?Hvd_ֻ\80^r!fv$bc`g)p-;~|:fܮ-XA؇D(&M.RO?Uт<[torK3hܢ =yf(\&>jzxݗǼ؂O/|-ב^:W=]tӘ΄߱L( &eDVVn̒RJJ;uÕD.HU3zr9Ig,|:BYi!y|&#_O{o|~ے|[ifvmy\v<Xߔ=Mᷪ5ʹ5qfݝ˴V(nZ-X;OVx3Sho3 J#qUԵy, wmLؕ*Yh oa^K S!H A4^qL*j.~J6>?Ze9>TUӇ(;RfDz]WHJn13]hd_&`rz`͆Z>Un}W$?ɠ6M IΥ#tQc&>D%Ii(H+9OLt59U]Ţ^) ;Frjhc<k* h8Iulhgp8*ZT)@L7.36"Jp Lq~+B眿U~cngW\`}( }e'싮]s :qu5?ܨj;kz/y‚6؜I9&hHnxqh@)}Ou \ c/|CIFIiIYdƕ eJk&L@3 z޳ubJ7۸l7#/ZR䠝@׵n϶r>sYLb~eRڔ^ nl9PW{)Ƚp)cIFiI8!p+I uX9 S*V06vQ{nxz0(flw= H9(zl2zG`lDNqmʍZ\?#+&h[)PAn+ '0I92h,EFE++*o`ᵖ 85u~hn'WD([Rz4[sȧ;\+)%5.7Tɪ,ho1$e<[Dj9c2k%殓9=.eq":I;|!q` dʉUq(޺NB)=BSCfs[Z^,%s w-pd2ihξ:,h`Lk~{c9ΘD x|Z=C0_h$%}E?U6+Em=aa-x uOrtN8ϛ~8Ldߧ^Clق7g{̚qnצ8'Q/N;ܴIr)baOA)X9Uh{3vJ>ELLwX(%+s;Sz@|.byeF+ļH2ذgYb4|r&약JWV o_~1*żA G|'ܵeݡTa7!s6 ;~IP]L2GbE"WY(gP zITq>V*䙵ְh+iM R,Ϊ*[߮ 3-BO[xA-;-MD%prf@ .݁e|Cb -A:[L]ZI87"zh)yT&.s`3R>%k^ns.c7nWn6 %l"$${'4 /G]-}Ly3 7~. 'zq;Kb@MCy@?",(/"zrf8S6d_]„Ǿ$q"p]$T'ugU_X(Kr}Ґr@c,2͡kY,ZMjRsj%MqƸ \QQ |%BwкWʾ !c۞>WTE8͗P2wA{ Vk0Cuc;u؜J9]l/0c?JDP̦!BmboASAz!Hnn_M=Kof`oqo],s"w7X:cu Z.4m%vFwi qRssmw;^:ܘkໍ^$/Ow>]!?@>@x!LOf "DX@Àɿ(pkCmKv]*?$5‚ƯKZFq "^\6-lG( pUru,m ΀ts>_4Ӿ҅} H\h7R%Kd4n2^|ӡX3Mݽꍵy5@^CO2 [g]JDC~ Jve@jQzG \Xu&jk:o!e$\ .n\}'xp%:4{\Qy {{ Oϸ/<{P1=V.%)2d䧰g>l=')ҢFrn;m(BP%*^MU ZϺ-?!h!BH:4ѪѲ&mb-B'z(WNigPp&\N* `N^]W3Ypz5疄Wm=CR7;oE뢲koJ-`r9yaC4s3'M?xq^z6VQߕ݃r"@VY¡$Q@l KYc?{sČjӥm Wޘ!/S%"A,0 IP cҥ]u7DoR-hm68&<#.)6)̰YA@axU6z4~>Uay8E @G T;"m0 VСmNJR^0iA?}CM:_iջ5).V4 B\]4VIOnDfc2H18H~jLu`# ݮ ǴOrrl O.ZMƵr_Go@@nV{oD'z?Y" 9+u;Ş`"GB'Z7K)sZHrjc _'Iǧ.RJ~X@߇^۰ и^}o)h_0դ> 4PE6*PbI̝"N (){K& A,ZI&';2Gт4Uj/ZMU`Pf]dmi.B?5i-AȁɄ:isK,o8#ډKN(pn;CVJl:Ya;p㊐`?Z?.C8qɌL_t3{* tF-$dL/!< q00vY2PGl~)8-k͏u8<|RrXwHϩ:sc~L>|LJԅݷqR [K$!%E\hWҍeE:U~[ï=;Y$.cR\%>K*~ _ڹ [g]2Wd΅[ 'eP=œOcE#x0;+vPHۚxM 7ҙ!Zaxث|fY\{bXuǴ+|us-BHb2K7KDtil/@bp̱H-TEC.,Z1 Y,;@V`q;oMXF}쌾yōi0k2o\Q 7'm)"ёh] .fwBWmK-聕a{MƏxZٺ#u˄NސV1UGCfVvZ]q/KKZ΃u)YU%q7:0sdYSJezpEW}K c+Q2iv4Ss_{[_Ƙ+ ې