libdnssec9-3.3.1-bp156.1.33 >  A fM/JI%z /[*h@\'d1u 2L=@ii2þ;;L(u!UQ{S wrɾdm> f7pm#؃ ԓy.SI9 {>ˑyP >BE|TLk2'b˃E)&-`UђYLoh QE%&<hcӋ&@>}Q/Y." YK~oX8߳RI~5[ a@ߦ] dfQdtDFHgE`spp{ QP%r zJ&٪:p4Ph'VGύb${|ut)|t#`e!]ʸl} +&JU=iőQ^ȖxA^> [(9ª03gzun.>jx]YMjX0+AS+)!aR OĀ10ed37b5f8d1c846d96a939e5de9fdaec7c38e5d9717007242e7cbccada0202666a8f4a71d9ac369c1552bbf158402c08c89621c^PfM/JI%z Z>,&OvKsS!l OX>KAA tE)| s|#j<&qA:Q-#R^trZ/YIq.{詏 bsU*D߮ٷ04$Qb*0Bb~PRwnG8=b}0]LJ,ExQSt"4ފo~& cIZ*' Y`91`Lq[o.^2ЌN, >p@q?qd   DPTdh      N dlv(8L9L:)L>n@nFnGnHoIo XoYo\o@]oH^ojbovcpdpepfplpupvpwqPxqXyq` zqqqqqClibdnssec93.3.1bp156.1.33DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.fM/ obs-power9-11pSUSE Linux Enterprise 15 SP6openSUSEGPL-3.0-or-laterhttps://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxppc64lepfM/fM/f3000a78f18e70df38fe56d4dd109dcacdf9a4de99f03f123189ab791757bee3libdnssec.so.9.0.0rootrootrootrootknot-3.3.1-bp156.1.33.src.rpmlibdnssec.so.9()(64bit)libdnssec9libdnssec9(ppc-64)@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3d@dd@d\@d}dq@d,@cۥcczca @c,N@c c@c@bjbDF@b[@ap@ap@a@an@aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- update to version 3.3.1, see: https://www.knot-dns.cz/2023-09-11-version-331.html- drop protobuf-c dependency and rely on libprotobuf-c-devel to provide protoc-gen-c- update to version 3.3.0, see: https://www.knot-dns.cz/2023-08-28-version-330.html- update to version 3.2.9, see: https://www.knot-dns.cz/2023-07-27-version-329.html- update to version 3.2.8, see: https://www.knot-dns.cz/2023-06-26-version-328.html- update to version 3.2.7, see: https://www.knot-dns.cz/2023-06-06-version-327.html- update to version 3.2.6, see: https://www.knot-dns.cz/2023-04-04-version-326.html- update to version 3.2.5, see: https://www.knot-dns.cz/2023-02-02-version-325.html- update to version 3.2.4, see: https://www.knot-dns.cz/2022-12-12-version-324.html- update to version 3.2.3, see: https://www.knot-dns.cz/2022-11-20-version-323.html- update to version 3.2.2, see: https://www.knot-dns.cz/2022-11-01-version-322.html- update to version 3.2.1, see: https://www.knot-dns.cz/2022-09-09-version-321.html- add keyring to spec file as source to suppress factory-auto error- use upstream service file that requires less privileges - add keyring to actually verify the signature- update to version 3.2.0, see: https://www.knot-dns.cz/2022-08-22-version-320.html- update to version 3.1.8, see: https://www.knot-dns.cz/2022-04-28-version-318.html- update to version 3.1.7, see: https://www.knot-dns.cz/2022-03-30-version-317.html- update to version 3.1.6, see: https://www.knot-dns.cz/2022-02-08-version-316.html- drop conditions for openSUSE 13 and older - knot.conf is owned by knot as is it's parent directory- update to version 3.1.5, see: https://www.knot-dns.cz/2021-12-20-version-315.html- update to version 3.1.4, see: https://www.knot-dns.cz/2021-11-04-version-314.html- update to version 3.1.3, see: https://www.knot-dns.cz/2021-10-18-version-313.html- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigobs-power9-11 17163343683.3.1-bp156.1.333.3.1-bp156.1.33libdnssec.so.9libdnssec.so.9.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Backports:SLE-15-SP6/standard/1230eb8ad0a87b6aac4a975019c42e36-knotcpioxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=fd9002443bacf83546ff1cb18360867693e1470e, stripped PR R RRRRRRR9"ocΥ?cJutf-8a587a77b31cf52d79ae0ed6b42b57929a765e9320bfd064b14dce6b748e622dd?7zXZ !t/ ] cr$x#d۟7ui_5+ Ic7@qWx}4Tե"⊭l"|7iUhlt`ϧ&pou4G2E9[+Zٓ_}g D3c_TnQ␖ya%MuĮ @?ќv}T`JʽoT:)0PP;WQ㺦Ȳヨ| _,aB :GMin& KNR48ropY!-Q+``*n_VL1A=tqf*ZY:392CQt(@\fvxd t2I-bK얽<F}J3ߥx{=̵uTA &&ijb5d ͒#ZE<9m1#6F0ʇ l*WUZ%u9Z;ӿ%FWfo<+X{h*_qvV{\kSWM'uPi8#/ 1dWnj:As򚥄pfH{" #.MwUn,~/Sﱌe0Dg~czSSv! y[yX+P/O^i_ T/9QL U#;3SȓFz~M DكǍlgp\Hp:߶wrb]-c5zϱS.}ݗjA(5:N7 +(^$trM.ϼw_Lm9v^0weeCj0/ k U:[:& od&nҼ lJsAɬK.ꅲA[}72^*5+BŻj @P_^@W V G G^z+ @?y17[#H} xYq77,Q\!]3]*xfQ[h}׮uqnM,!|4E>m#Wٜ3w;&UukokG /#()p$+yJo$|$砓kO'aF"7T'f~l@0Sw#' Xo*4S<1$'}ڔpϫ,j%!/>QP`r/`sA[ݖGAdŹI;k[Ğyy#z|kh]gw"-y3^ 'Ւ43;8iP+֔S2_"ϤyiQ9?>fhK|^LB×*ϗzr-< ȍQgA Hk\?=.jΈ^ bvIK6 5VEu)X*A%3It [~.o&)D;w>.ڭ#R+[Z 7ge, mbS ?; 쳞ĶMݖ?xS1DBc~H-Fij 81?fs w~zD0^鱰zqLٕ+UP"FљOÛ*UA:Gݝ.d0Htϩh#|1ӣ^d"k } ՠ7yU!5 kk)F(6ښ$~O,PX/W+>+T>~Y64»n/Gi4h"i%_meסZ@T)BrߋR{҂hJ8؞3*/ 21D }{k =_8PW<_)Y?!)u]33Χ @W|x2Eر̮ڈV }*ty;K/EZ=\&F6hӛĖj/w~JB2$u$q3N0{c{J8)va-?xr G;7bu)²PFN2QLh,Of^Wmk+g_{jF~YPr4 tdprTy ξOhlʐήsH_W=sV,z$oV|[6UKe\ˀ07xbKWlau9W{W]8HA=^|+4pWҍ8kHe7yRT:n5W%5`ET# ^GzgR.s 'S#NJQzfr \8,]j#ěg 0r-)] դgCX-ũk{?fE*J2BFq& R9`;tWql鏍i}07A3=",v8 FICuoHvN[U+V ⲏ[GdVvzxYIqڗV>"armm]7Xd1 /%D_8Tbmu? Z#%k՝ˆ%0y6 5K9sq n[~߳GgNK_\3[?k5CLdP Ÿ.+eEhrSKos@!sHb_gR20Ñlxcm2пqeM0@8/"?a%H3PEl^V.K(U{Ҩ-~ť7mV>$x|m3VjKٖ\ eKrBl`fFsCP{.hŽ ~XGΎȐ7X۝MRj?W<cɰC#KjO4žv*%HU$T>M8C`ecϒ0t 8nߣ0 \Of= +9yz/_JlP{J0( jWʽP3"1=KOU" 6 ݫrY-lA*xNO3 0-6 =M*"RxdԔ|fpIڙWnНs0Ld~;ZY ~4F ޚ;}7\}Pҧfr,:>tn(Ylb }mW=f<=c[l슦l1XS%̿5zB,T=q!ꉵYu-g1L'痏*ShJxkK^+r2o<A,0nfH1%57{meq463p S=w2,DdGrlKQ=p|VP4THY#4",Pkrk T̗&qB?|>yOB*In΍hƒLD|ln`t)e/6~ddQ^ԟLɹ1&L3b:ln4~D s)zsln=ż=V{B׌Zam-NS$3;vې`Zj K*fhOH|xh۸^/#iȢ,Z-g *Q*H|Á["\nfEz5sBlkS_BR[y-9Pm´8/_Ph7֊UrL(8@8Xllfm{6:lG*+L;5^4M+F0XYV8p/ڜc@)O$.bFM.ܽY;?`_MBи317h%}w0C7/atk)Ϭ .qdܯ͊,73qҺ R3>TKF3ɻ 1ٵiEc rے& :c\Tn>z ۦ#I&g݇3鞏{2%p`.Ӆ|Mh-#W!˝`X&hpv0@X%. kb4V۔ M0WKk 0*=-]{pm)I 8KLdF S`C,ݸ"Tt?D--Kt.=o^,@{O\8[Ip% [V𭕫H^PNS $7gqcwl\.o6 m:brt-\ɍ{XI O Kz"% qV(E)BNti92CHDr5ahJZ[ԖT%U+/eƍܯd.P<JGFU̼.;~.Rpr&Vg%$ p;u^A2+bC@~)e{ݽ;\G0[! + GswQ(ˉl8N S6س9,r ĈvD(Xj/tU D[.kX'Va>8(T&2`oEEHI*Tcx ?B]1 yoo̡hL<_#o ԙWET _u8 doڅm?L}}קj-\`1/(ŝ_bK^%/jeҕy$EmmfM_<ȑר'{võXnyxmj_[i^F{ xNYsDILT)hCZ0g|4gOk(лa?DImDQ*Gݮ GswaZˢQo0 fp "AH5M .J׀4΢,$J6:yw Փ4ɂLGԁ5k`NE!ѷ]?Vh#JF0ccLZ\vs'*xZCӴ˭nA N|ȵV\Ÿ{YY^ "QMN7``ikQߋ`R ƺ澍i{c$e{Q3p2:3gһz_Vul+X~F=TU=b;ߣd'ⱔx┍:>߰ûvj%zcrMmq$.S b~ܘ35s"OjD0aҫj7l6I12Ž0**}͐ʬ` W V|>eo"A1^q9Hx۴^-ml1\ 喴5yCx4}RJ {T?&hLA\11 Y{Df-o?1QÊ`zc ^n8 r8GeHG',j9m%L3‚mήqDP*fSZ~ Wńէ c$%' -bfT!bϭ~t!aJL)|I`[Xn ,zhd;6V> ϻXp)2aXa8km%Rx4JEh]O܀؄T܍ v]9?͒qyATŤwΔHaUxiw_>6}n @ I= UK1k󓳫> {zH6嵮mlIwf2Efqk>\J{DP%:WdI~GH7r`px)U6E69GIfwk Zx"Q ocաGfi;g)x^<<)2Qc 9kԿH&s,;FБ3B'Pͺ~; ¯2~VG lzT`m.55k0l)c;֓ɬQ5rB,ą@ө@!}%r dܞF9gɾ!|:$}aZ˄{våQ7gzQb% ,DAP 0ғs-!)6\Fk`\1櫡yca+HY5șHE=28I^wū'DTB'U- )sg,y)]%&`G{9LȱӃ. ]Yr{ YH77N\lJ4Vm'[[ڦQ1(@KH "ѫ7].]R^7H>_/nTΥ:qY:e,[]v6JHfN!,<]ä"U O}^۬!ٍr.lTmu=p^#T?w&k Uwn=G7NmXʎ>#别CB|P0 Lq& [3n%񿸂inW6^ᷗ/ 1P(DPxbZ6@\RϒULCI2Pީv0 2.%lmzH>uٓÚ zQvW9>q}d< 1e4ewrAF&NLŦl{葵!8 B=zѬB,E,:51xyHd\QR4. kqzjx?GmWmE̫R[M&?~PWA\m /g䘆zZ`y0sLf免PRM lxCT\e~7$x;1tH-]-@L@8]VZ93S-h$mak4\{x-kARMa, 7g~Büo¤W{  Ns:\PrwOd}$_Xg "i~0suq6A:+ nʿkX92Pkn {W HzR󯮘 2\_9аǽ-bؤ){n/6}^WhYו|tㅘ#s?dŧ1?3=}Uh#So3{\;Xh9Q9{Jd|"UV2oN)K\pCd_Հѻw1:#x͋~k}RH`x+,yaI7)36;JvK߾L~ /rA>r>AxF̳a5WܣFVZI=PӜCn.1ţ!4aU6&ǏegƂ> ,#ZxXN ^t^;J{SWףy_<]qÇOO#6fD ]GTkg׆Ёk0ߜX1ڄڣ*4rB %x -ccԾ]a3: : <3qmke.uxn~ I˒CW>!OlHu{CkQ翺X@^j Ѫ-"j/]ΊuI}#`']*%z׶h b{t:"b?+'c:g) UsR׸:)P 4 eW",%6HP1i'""D#dFJ[K[C?)5򊻞`x&<,1l|n"4[(?UtӼڢ ,E_!I/Vs5K V!C$iFu,(W,!8'R,ed8s>iʀ:6j_ (KM3 ?=Y>dnNdr z UN׶q+TJAo+) X_լ1>6StJU ~~ٰN-YjR}U@5;~B{cvx)1Z%9஭"I8{Uag%}UF*ﯻ(᩵)nF+_9׌ݫ`_-cD [?.17kq&4Oa;6L&<3#-GR8ꉇvVr|ql]<1e60u<Λ>V8#b~pi* .>4}h\d!Bӿ?AAIbd{ d8ZH;^x.IYq mll2[%=WqNRD;E"kD3W=LJ`.@Ty)~u"lbT! (J>Ee b}RSŢɦ3\G_]Fut-' @ځ,)JEd!=:˶NjW${>Uh[>Uq/n6s\jw.UHjQ\ȵifFݼ8"FõTlF_KoⒶ j7!o#Zϥ}tvȬI7*-f|P׭i+P?g2 gJ.2;buZL_(k#'_ u .k@B#W`(&;X~Y6(hS,, fj*`\Svl*>t*f`+$Hq$@>E.\X~7Awwٓ: i҇+݃&#)ǵ vp&^Q9$(4-f,YlI)g>ePIŗe䂝 }kg ڢYNUH%  cM@DXd@aaz:hF$^ BvD6K ͩdb" [qPL <Ā֝8gB{k,3ynlPs3 u\/V|A+1iccFP] $)&u_O IZ wӅȐA+"cbYZ - ynk%ݴSs 9Fp'EjU+GGAnlA 8ՇP}.ءz[jz,;odY-/V~8ח bcն؇OzZM8Ih񰞧J:|=1 b6QV 3l Rc/Tk?"A|+,!!$9h> ǐӕ#| $ p}D\V-VN }ZOxu\})qdU\@d Њ h"GB&m_>c sU-0 WI>\΃4ƶ:>X'qm3)08dZMw &Vze7L/+Q;~AA5֖hP0zׄ̏T-8Y媪'PIPJKm,b ]I-eX7~FʟEP)ј,o\WZZ hq)To Z\Q/~^P-]$cW2С cA~ RgqNUd4 ӫ˔J"Յ)G ҆qoVFCUjsY Qp+AlVP5$wN_;0ElYEm6.Hg^IDyvZj8b[XP3v'up.r=dF !EQOBCGuK$է!Ey[5>s 9qRN[Vz#Uѓn>%RyDBGdK CBS{W60%8~- f 0 1xrkfПԱqQBf!U>:]Yp=lX5{3nk1L \0m*u<jEk XqC^!m,xLlh(-_ #y{Бy0P8Xƀ rYHfW~jij](9#<<6ybXD%3!* cz5²Eǧ|eŕx1\̯*WN#Aݡ2PA1#tXBse*Jo.=V Oqȏ8:ş08Y<5ā d1h̝i'{9۬vei!a|pcגpOLMrTo/WogVB;-.3Ë"!;FrH$"= !cWXp.8-3*=Q]$x/DĶS2&32(Ii/5)@%@ ?T|tlXӯkˏGWU^Tp˔5vD'՜}=GaoUqdP P.m zz#aX@Z|Sv9Yb:KAͫmFd%yCϨx99u2}8@ڄDOCŦ?I9"9/PPe2/Gz'>Vxn Z!:M!9v_PSUg #E1&-G4&Yr3Ę qw5]/c PAsZ+Viς-b"i_6l '22@-ز*c8 Yc L *i{X=E!*SFOZ|/22={du?V\YVJV"'u(ITA:ǽ:&) ^ Y&? &Ka{Zc 2{VȾv%^ pʺZgAyZssZdTm 6uL5՘Ea 4>CiU+A M]WĮ]86ە>w1e(xFkIZoHtJ;E`0 lTt+%؁< HzoX{{R*u._ yKJ+i& dJpO_@W3*M ]VYKCBNt0! YHž0Ñ{~@ Vv.ߣ`}K( Fɷ%zǍIȮ[#m0qx}09j+fv/t*gW0=cY_œpsT|ܒ+&jAh"*!Z8ӏ}2>7(Pc#iX@|>`ϐN0AT>?T%0 PT*E"ܯ!{NkpG\QHn$mjvߖo&.gԒYzQ}y6H b57Kf`!scKAC~+* ē`]dvF:`vA\tW R1#S:29e%O:`Xj1ۋ%tb*8$c귦Ik^QuxbyZT 5p1qu)ʫhW+uE[/9hM}mve}ߍ[gAJgjCu[rUz4*w\<ք&v>TJӝ Ò&\P[ژ(^ñ%P6"0_xLN=Y m?=b^*ybk'*X7 &K(0GC»'NXrVR [h:{%!&Ԡ mWDE@Wu5/=03<;սӹ2CƈӜiGv GY2ȑkq2"/ͳS/ȐΚxD6+^|:aÕr&r6l٤#}6G^/'ed 1radU1>D,ã$ I̬na\-s7BC9@l;5Hb:USdSFrv#lOOx]" ur9%5e嵭a]\@E7cf;+4?pmVu(^soͅaOpȫ iFF#=ıcm/0{Ɉ%Xиfzuu/T{_"o-|ř\\he1q{Fi>Ygu04'aYFփuYpi^̀[0,gFdvWWڬ.D}5?%sDZA"68eRZ"P,~TkG3bUXL-,8VI<}N0HQT,4j "D,bV#bܶ"1 صL܃5a ܞAСr`2ݚ Oy 3 uS(ieTW*)6-!a^b+Ms-t~Mj0FrVrJ;r.NV6lk0|.14;ѿ` ޏV,@5~ȃ*,AoCw"4jhaHoL;S?)Ql4^̑ʆڌT*u[(Jmpb/G%ɷ\o_PB* C%%}{У,UZϋ2ƫޟ(Sњ.tCߦYEɒg%Y< hn #}(߅-/d917xɡ ks#"1PQ>N)Q{E}),"JqrQFETCt4g3@sVAL|<_h#T!-٭%j&)׷іpFga$=FDA:#gE"=÷V0h^ΌALekb\#*MaCB0Sc\6i >-JYZ 1n w %b+"NA]݈8X42n*r\3HlfVH^N*[M.CD큪u1ꎪ#l)oU/{Q -:aY&?|>z^.XG-QͤjʻXTU:8R,N!Q>-YT:|o#u{FXzȽgBCrXRgK6Ij?0N5OM=1[_ܮ;D:6N.YDNh4[r&$ uJGπM¹%0"HzO=LS쀲A `G<ͅ,{ſJڏ|JMr^n$*vvMJMLwMI[~6"o.ZnMiz,A.𠿋-ON($*6"2}Hs?i |5,g6COPC;qIW4 HP"/ j4@]YR~xo!MRx`ۍߕ~1T͖Y&Գ<: um'Y.b*f^,@w]t;6T揦ר/Zb] F=VLcΪq8mSg1B@ʑ7gE D Y)`dY \xjTX)mS -H|(ghSdAa+ ]l.Eq[=f+BzN.Jië yF˸3V0?Wd n4$Piz'qQEkr٢}+gJ%Te^$"((Qz/ jGM)1;eΨzgfV>6D=qf7[l ܟMoOCg.[Ź.<"ǖ`˵V w SA3~3!gh50A|-ֈ5Vm$RN"ؗ>}l&;CŦau-Aϑc @UQ'gc] dA0 颬ɢe܂f#^1|}G8CL%8D2Xg#qoahݓ}{@?tm?.pLBb9M+ .kV Guf&cwo*P]j:ǎX 61Z/e@?q2T@OV0 |cc|%/]xO~e k(r9t'IA\.n8>xsx®jBn֘aF0`_sv{ؠa0gV&<Еo|%vM nGX$VptvqV!865CۂL!eCsEȭa<6|ó$ʷv*~mA]ޠ7-ӀpTtw.<$*Qc z>SL pk#`/a O Tj\`])eK ˆYw~8.`IxiY1¼Czߋ8*j GLpͩ' Xr Vo 9lʔ AlA}M0TۜgC x9Ҿ,982x+'jCɈ_:y/ıh7ntm#\ncwU`ZDb"/\Dw HcX_jbEƧooXm*qKREuF3xtYMjtGdZ. UlKɻ$3%ԖD!R @,UЩmjQ>H)]\+UL{Ef23j'x#t)=j.69.#2MB=YhF68.A2uAlT TQtGYD3Z<o_ FQLآo6&X'о~rExY ='ǀf&}9 ]5 =5O2|:B]Jtu(=(-KҦx Ry&,ooMYH}󲞘ڜнna:Qؙp01f)Я„gJ:D616C{kS4>[(Bj<,g9LRnofᱢ+/\'O']3s]ςHU?`؍ 2pW.O}:Tf"& Hv)Z앇Xmw N0fZ·.]#n߱>coL6;x8H}x|tv-H {GۇUy}Օ?B&D|oEչ=Na:lcc< AWTNPalێә7#A3q >H{J3R<nf|PSu!C|P4O?j{|]ZKh]_?U eJDv)+u^u`;TERHe_44&&_"˻D,b]Yl $ԭGsL!.y*)JLPN@1ؿD' 1=ND2ь(2-5֫J򥐡PVE`Jih#Ŏ7dق'PHxAhT ה[ŖfS̀ e/cT .Q kY2} 4*mÊ-qSj"i"x^}Ov}u~tȥJyltџh"nJ8ݞL.Wg[M+unqXI7i $5t46-9KiQ58"ntJ==_&m<4fRkB\q6=.;O$N8& 6Y}n#{0Mz9enGJn979c{Ĺ௱%2-$Eo1,K3;YPWJ!8=ZN&?hjV.(eb:7vOQKRv*)/`{m)R _##x%U2Tc$'FDl'Y&}w~rf2dyBj  d%o SGeY$tfg!rͼo0e)s_\x!1NDLT }4EoB 1y r~[k\4jT[#6Ċ#gQXΑE px" k)m. mZX?I .,w˸ԕפ9ɴ~QcxBSBg9OuU/WTT+—{u6O숈EӲΓfWj9̊ԴĤ0/;{,pOYЏ-/q.HyUaƓ@P>]ƟW7/Ox#_17Ӳype|^qr8$L<A *=-7Yz8]:պyǔFnBXښ=EL_O?SdrQ+ u9GyC[̇&]s~]ǩg@2:z\.tXa{X|oQ55a [+xk}|Y:ҍWʦx6I{Ù7r9b,E) /Q)>fIF$\*} WQ()  "oSe>^(?m fG݅{ 91n!9EyKNsXr:@Og7t+ =(,ÊhJ9waU=9w,~XY u?8{VfHV' .)!R$-,SfUI3+@z'?߿2# wc; 9uiN([B Wwlr++<@qx mVҗlIZK5μl$̺٫?Z32x,|5+q"j2o-„NT$ j˸>T7cR=&c \RA3'=VK1û}/q[gϱ9vl[dZT ;;meLEJ p/GZ1+|uf%O*gY^}߾}_߉_*U]/" $ŧkdwKJ]%,=gu ܷ+3ٮ0p6j>>W&F. TMkBy`CM'a;Ep7JBO.Džq\ց̘t|VTWC?qْqew+'([9ucN%zW _e-_4;% Z%<e.P%R| KvCTE35H 3M J/> ؊p'M%51VQ_ F)&iW#hӋ{G'oI|s݀z$LhOd ?8Co('nJ֚?+`He5770]g_2F*FBP;p}c~Q$"JԏyU5n@%ۃY5 HԆvU'xf!ڳUkΑG(q Pkce=b\t7pW! Fɢ|c) b&ⷼ3lbx%$oG>=n!?4 `Hї,NJ>7s *+crw㉕8ȉi/QqVzhCۥIm(魢n?0-WN,2݃okn!g7E4?$aZhc$ 18m`)3[z<]X OPX$!'];0φTAt{d8Y[^mw "&hot2xaѮ*!lTv'4tǯ@upspq?/j7ӄj!ʠJaatg9 2|w2|b`̑yD F p&119 _ fn1 ei|=B"f)#ߎqf)cqZ.M/YY*o9Dp?z;JY;ywlȪskE] \XgBW,t+/%w]=5ƛ5=Bl BvGwC(~ (קx`5eDzOu0|פal1 Q@n Zw'3˯߼6y_P\0hq8il8FݶI}WNV".VLqCu8eu9KCuи$&/N<, 0='ȠI6^<7e9U&LwXU_t-KvBEFp_^e˄%oiɬs*ߛw7}y߇/  СqۆfTϯOTd6Wv+ k &d\b#-s~v ͠xy& v]&,"n?-pJ3MY߫-Y8q6=}2awu\鱝Kw,9V5wE푰0-#(~I0^y#RO=6cmb1u^%HH?}<S" \ä +1D YRbG$OQUS2s+n[%E&$P#n7_j-_RV6W&hV'^s&,lqy`3-uW^b̮=0|ţt`MUz4<^{xGgImޣHCoq˩!0n;YNKDlfhϺ.+>L%0듓$w 3J}5N7LUFZ*UhEGwB[31YAӬ|@bAEQS\/8<Ɋ),tQ䑽D(&/fj-3-1ώmʊa,>CS|2]idPJ2=l#Vj6Rn]m5%YtsېætWT`/>6C:;&4arM ΋m7ķdQCnAUID>7%sA.ڿQlXi Q!u9j=]m ޵L:Fqy6ݲ, E R:FLj[(PE|N<=TMqUIWZV؃`Q[߼mrگ^3p9?IR#D' g33hA $ BDYh G0޷pk'FہK5'q_6gsH("1Iq8P{1Q%u]P%wt4 d7@ko?ް?m8O/E`sM c&NB/_eYȬr|q3v`厸GԔ([O{,GiGHR0J; wEYedG'h2BZtlW1l (QRb6l ZS$ϿM2a'݇R^m,ȞZMťF.xLmq Ob 8Ivt^ǜ&uw)7-^.^)lR'9!lJ1F(|ccGpD4<zl,sŔڕ`!Leuq;+ux0R;f~A/vL-<}"hd$ֱ#C%?U$pt m wOeVjO7'+zpnժ3S :*cʖ8x@1"^k fM %3 v0e[hH]%8u^+A!'p}78<-W Cp{G6dRe̸TNg5-םWĆ9[9uOls OQk:iB_*5kQG`yJjMMq+GXYx4x*4 wQn ۗ5dtҁ.9tqD\ql&NA?8Ussge#.]il6@۳;!qcNe^@ ХMZPLf97R~vmF= C;}~l+]qL?sZȭ㓈ƎE{<; *$e3?Y:bS,,R3ѨXj+D[fZܧړuõ[=]̷oJRyӜ ਼'IsRpR*Di bLYqީޤpcqPjfZgOU2Iqӿn\NEoNp&H15j7ABf:{@~a=W峙2`(9=v y_ .t&W\-5D?&!LKtZi֟p8$!Oln>mC?t$zMO`g)G})-^2ÝB_'-!a.$Y|dK\0I_Y)n[#֠NqχW~x;pTIqHPEt|;1 pQ~NH _5'%ӵ`jO5W'YWeFG?Zbhфgе.=Nа.$F呕s[Unw- @Q J /`[Og20hhM׮JnRhK/3 LC]#m$h[y={iˆBw, xr^]3YHzyyBb9^IՆ)ٌʧI;7J=iw]8qeNLDC,n TlV(HoeGMQsIyhg01/G^ot41}2ݾ=d ꍃwF~/v Jy61=)kg1GPiJ/f́$T~j9L槮Zk`4C TCíԣs޼f gbvnFw{z ߻(y8alQNTX&zf LfϺ^bhOIAr y,~Tf䔘 %I"~u{%gۇ~LlL|%@8R {#dJ$/{l oh҂f,j!.1ICo}CxcbO{\)FOIY;"4z}iA0zUQd7jbAWEy2 "3,iH;&p:9Aׁ$U>(/HjLo}iFQ\Mg:0HP˸-̛쁏 Uٽ鬽]UD-ї+WDl:93C>j8(Y9a*. UzH8I'/D+%\)Ms9e`yf&K} vL#b찛;,vr v1iEnN !*ELB:*k!=hI2d؇B.jNvjFYU'(q}*$ 9#e,!L{8Yxfjz%%Kx2V98xw:X9]ޙۀ%a- rՏq26ye J.8|#G]/"J~~/7(H8Xۻޚmn|`RxXH2#vy$a;;όM+$BaN({nC}[gUn:i4_q is+QFNvWQS4Dא[&oBWkv'?5bbF9l^y#((z^2`'dCg-nBgOV@F< V?rW -?B((7R鍀c"o$4a.a4f}e6gt puխTT}=\J$fBxDj 0臐shDuIAGci|"̗˥J4iq(Y|؄ MR`rB"mU8=F~6*=`<#[hlZṋ7ӗՕp>ځːWG!uƅ \D2BtTtUVCsՖ<"Ud[H&e NV^ʄcSmkYF<!(S! l4u!Nm¨el,a] t6[Ju8Z4w"ej6- 1dꒆ3/rY.y7gWS^iT ͐@Qa)i?ρ*߫g>CWD9M)x2Qʡ}Ȳ#jBE&x 0srZ??&"X?a]7>9/O}>U{Ҋ7gx]yl'ÿ 8̳,YՙU[vÙ'.Pb h'l%^Cs@u)xA ]"'=9 ĚGkhW}ilΎ^⢱\RdiGozڞi:Η,H-a¢"TaI2H inKJlKKW! ^iULTf8y'u h?wcc䶼e - hBfY5 lŦN#Pgc,) 4O)u35/^% Ⱦ-Z?OIߓp ]{ϖ迆cPFZ@- sw06_ME?pOl/[n~* {"/Q[mAeSO]I2z!刣O_{HrT]Nrt.*G}UO˦wkkо`' w]Q5Diw8jF#f`(U)Lp {ewG ?&@%UU+cE=Q Yf]p8%A[G&܉O!5tJ_\Tnw;LoIEXJ'⎛˗/hϰ~o\wwG,E}G"4e>Pls%P%P!dBVÉHk[&@k'DW1 nϝn6õ׵aLE#M\~Ei61XUBIw%,FzF*.v :kZ-0g?=z!\$ L|f!>q1-ŊRgNX{$xl&$lNf)n&C]e`=_nR&]Atղ!: "vA&+LlWFXQv1O~{#-MtAIpUiVKGOn>ă5Ř+lPXflyaOFH090cfj94]HYa:7ȋPjyw-\Z-ʍɄIGBj:c[GzٯޥQ?jV2ȵ{7L$#8k5#!}G\fAl(BaȣcH}~mvef}ڧI3>r*k(Ji6 A& ݅[p*s93'>6g) 8B$5F% )Q/0<3(5C!M]xg<2K~WV tzK,#yURe ^'z&/N;\KN!rƕ}fDWIqW" ~ĀPGu{:)X'uÅ|-nn)T:W [Pa: LI1oWBeeO$|YwPC>)46 m6ۚ3*rn' +$t\ȖKaE *eE *XS` IZa/LuyV{Ѷ| moH W]{t%71;n<9Y'4W!?h$=rh:4юtUо9Y~[j_ n1Ua|z Ԍrf|1BBaU+K)M'\섀F Zz} T ٿ2Iv?]dm̀D]glu[6T{Np2WVq$09Y ojg6n lԊæ7CLJfьٱVRʒ #iI<4!Rz`t8DHvLdBB_^+ 2˒w;HE :I\[Se6k.v|HNY؎^~n.,!L"Uqy"j>!Prz{*HPc 5rrU:qz*&[/"坘mk|DGYD\̨LlY'$ltQt4Q| h(@|4Hn-ҋeZdRl*P=H%mbw7 mD6Rzu\yJaI/ЛFdצb G r62Ugn P6Z aoc֌b҃*va0PVc8.rl '@[ 'HZI@I 4z^]-6Z9Bӛ5/jK$]_gFlӦW<1V3`UR Ax}x8 -_{CV%H`"V^5mУ~YB1I]3Vv\[rwG\Ʈؤa^.gbf’:9L)@0'δ`m}ZhӅ`Õ&x+&#F/Y)&xlD 4C,59r@{"4p](Ulx\ kA=E%bg%v,>:KB6ҵd,RW{`/sc?zLgt/Zeǫ8&A0tNʋpnl>pdvo'!k1H?or1]2\◀YKH'92Axӱ! n |UD#z}@ Va1Ik' &k^M $öPנwa,VUÇFF^jmnR|!vI;#R] %8Ph;r<\5{!w3t`81l#yc_DZ9̣QE~"WQEL?dwIz4hd ]/+b֠q u"t\O-LF Gʚ%iubRB!rPh1LigT6_iZ G!Jk߆oWǭVõћcCYAs`(q{ôcia6'W}Nc) T+8Q`njgj.}}Б(Mo@#A\Q}VVG'FmHTL=(5o/l=] Nˠ:3=݃f+mI {?8N0X^ )ĸЎT+t}+¾>0bqL) >v 4O-2ph>c}pTŸ /}RRZ%h0P(,~[޷9lcL/B|VdE<8$U RiJ+;5U(:!տj _xE6)B3M C>b<} KfCȈMZNpҏrkt5qTf,"18DP3[Kvh4OQiCfI%̑ǁͻ @ E_Ќtr˗V bG~8S3IQdz4صoeu)ɘP ru@>FAwWQZwxu5~tei{Ƭ@Tv z,=;sZvy+900nkW8P1a#JcD %JYL^jUx zA1(=A*],;_AG)rߤת}4hRxn4btu;52Tg:ѦbM[(ƙ}#H~FL5G,勵0[\y.6t *ba'7Ǖ;`e=!7-~Igy[)&;CZ%JA+>7r  6^/B|䎎1d e#/\_z޸OMqH=9d'j^w쌋{DզDDd dd=HJgj$݇yKT̚EyY|;=5 +66C+HV`sŷQ0hPP#EPXA 4>SK͵H"ǝ},\Dd2&kƨM5NՉNPPifb,-&,8o^\o6VY Mdo҃-3K}Ö$k,7;swyK(t z!cz[{'$47庋Pxd:I<9V+="=8|8A [fyԩ . `H # dDjJZZj8 ״kЊڧBHN :;PEkΘ| fhL]Jfw׶]u4EDFb"$\lҾ'0lp;vy@᭜+깹 QOJw g}ɂj (4g,iE*^*t٧'O}CŻ }/»ģ 6 mw(U񷞮i5He6j3=͕.ɤO`~ULv."z' akQZuz]$p\f;v/, aϷ!ְ˜)Y(f &$KyF9AJqbҋ1  >T_M0^b4pjh +RI[+YQEH:0U {]; :NrM85NG*s %;' 9D1.caDj{-?c4xnx,A ={e TԬI|q}&N jQ 2ۥcp^ hG'nlGv4w瀌flH._Ɇ!ʦfrϋG5(b~U"Apظ́d4 ~SC?gq`µ$Ǔe*OQx˘S7C@;:oĺL uς"/Oآu pn_ħjiXX.s4+ihlcpPre X9x614o5#{Kn`0q$X'*KHq"lI z%_í4lC1Ft'+sGӷLyB*KNh*i!bv[ m ‹ YXw]t,<EyX6?XÓFlkwl$C]*a|rE.zA9ʫZ~8"L5ZEmjcӴMX|[.v (^enhC#0"/@7{,y{=B"Q7XNHc$ x~~WMZoLᐪh.!DZ#t%S5!0(MFg~gۤ|9<U/bニu"ۚ@yȂg*4y alӏ'b8W?muVl5hKf~y"|bnrOIrX&P`-Ԡ:DfZ >crN[^ N pн.m;\*8nbw5|AXcC6,nJT?p:Ȁ3X9ØI%}Gd;Q(Vl ҆w F@iXwCv=' h{`Ř4]3G7.X~. Ta߿3Aft s&pvӰG3E­!"6 .V<-@l%Xwwl#p<(C !iۿQuh` Ha7$ :zӣwFBe,Z.Pm1!jc;LY9NGjXBZ21~Zck=.-&p?:*+@t&Մ2'+\T5iF8BU<^+ONB=avMk1 /ISM&1&N@xW]IӎLl4j[ k>`@I7g2q1}unݿրY&rKoHB],zOMxH lE##> ~8N&Pf5Q>뎞@7Nz 9`.V4JnB`UREkCfNFruX;&UPa:rЃM3k|uLʗɦ!֍ hCR|B )N W{]kFi0\fSS=CQjO+U> R;#q I)lVU*\HW(/xS$[IOɲůA7^ E:/<{_ʮk˽I1xl@G *F9a sa g's닭4oSs+::c\֡CƧް{W.o+hmṚPP'PvėEѴE79^c5|)c0wnZ'7K|ѭ(s X仵@{MᙄB6'ϾxCFt#75?XttoMi,j+6 HIZaV8}|/*ȱW@x:#q(n|q5 CI?. 9#ZDgǜLCVSzƀyb=0GqPV"]^+]5`~t dwfdaRj}Zdu[=O%"22{c|#W_U` !J.1SEDDj}Ong0OHk4t6]CS92P^$ )b3 P)OS#l>Qt).M~b `HlXJva_6 2POU7&h0sq̸\Ϲ?>6Yra'xk JQ6/zų3_ld]t$;pѿ :oAi(?k'l,j*>xL ibES'q%e l"s'g.dbWbL' ؘzq+=-Ӕ,Gv qce,7DL)JA^m֣EHt/=FJ9K"#Z]rtQk ;e>wZ q1OOBbRv \^ŷYѵVuOy/[ hhhxeGiKDܳqw`[Oo]#@qs ӹ4:?r0B.!֭2'֙~r~=-G ЭȓmrԠ 8`vFr a!oCTWtlY; ORlA{x1ZXݴ(ޠ1 ]_GXg_{oTq*QcX[XqkR @:oZ;i.k``k(k8L\f/ҩbpOF> >8R a#Vangef"S1i|~BW:? s&2l$,>_a+){_sG14),֘-3nP"T#_Bo\\-7I=t30*@+GxŽ,V5Gnڎ*3e5%R][=],Yb f#2!u(EF`y4he=ߡލіӒy nYoqO4SN#9:Hfھ*Q4lDDf Kf,a\gt|t@s:rg%[xUx΋,dGW |}ۼ x*ӀPlDFU9qaqR5VK8>#CHe*} 6p^4Ex )w874-%>Us)3@K}XTp& )^vjߧ}XbDKu/0P(-ɶ!hʄ!"' 1%s1=LM Q6{fCNk!=ؗ9b?SS)2n^ެ+j̒x4V v݄u}1m%!J_[3m6{!g|s䂨8; Z;Lx՟޼1rY=VhС Ebt۬bc ;O{1AqYm඾ugVQ#UsC*75cs:<2Gb}Ğc%S@hCb `bon9%8~%fs)לf$x'dy>mREp<8ʾ[iU~L*/?:Gl[$Ǧ09]=u+P] 5|Y;nNHE܅]\@5J>ߩfQ x[^H/Z0ۗ5[=`u,h RR=tx~hʏ4 ,hC$Վ\yػVYnE tG7 rcXp½p[8ܒL1  . +U%$/2+H(}u*o1 k K_jzꢉ·<Xʱ^ee4~ lWl"lзӛGQM,2m`3[:d2z̪p#ߵzvvv^r^O/u&+xQ8]H==#8]|B!Kd;EdT]L-iWEqmW-;g3vVe)8Ni9r_wrZ$Ѩy>ؙitXnnenIiDMz# 6Qp=;KPNJ P$jgUP֤G2rab/Ji "D%0*ğ4 E9OǛ#)VFZכ[DdTZU BK5L4\Q7gxp˵Cg05 k]4;ld+Aszhj儺(Lw\|6Ůs%&S[{FHi(ߡ!O0ísZ 2 ̹Dr.VrK^C#Ndm.5RSS]&̩:Hʳ.^_Xvux `kJh!)l¸A%8q30gK<6X"6Hu,=/>c?{|t/SnUoYZjPY,X,f/nSB#avU" k #SK8ɯ|"S>C:H=)6f[]ӹJlm`%(Q*I)p1nwXL}k ȉԕ=i/;ni3RQJڈiAUn̜iY'C8Gk^^4DM[Q'OkWZa [E1G3- S)tɬi "&2`ޏVѵU}865,3a#/̡vl;:6C ) |dVȱ႞2ޞG),$?#;{KRWH%h.o^4J9Lܐ*d)'0/g{puX"3Bhtz[r*~,#1@Kp5fu;mL#<}EGDS3rbF[ao뽩E Vjb,N+~ޜ>tx7Vi2r*H۽ qx8x*\/#T<s*7[O/iYQF3ȑjC<7-[t†5`Ғ\:U:2綅 ;1u PU _JH[U _e${Ϛ]ڛ_!.Rp2y8s:FgM^pjȗioNX[c;۟fb?ό͵hgg-pBRḄJq 8N$Q W}0]|!kg t"oX0G{o $4S 4 gIfeh N{SA#@KqzA\FXZZ46Mgk![nCp3(E_,3 Y!_ H \l qkK9o_&Y.GSl=EEǐrh GZ1[R;#xU6)ƊYK.k7kg]!Q/dtlXft%˲R)*\\cP {m"SY@kE)!a6 <@= db7Gįư:YvSoڌ|iFZ2Tq} ͡X83)_B(jtQhwdCp8H/Mf/X eek苣)g"g(gDE98:A6~~>8(00iĪ{8\A)>@  u|DU^3l-)g'Fն%0xw B/$V/rWNrPmnp:@$?F:Aa %9rf՚L-*t| 3UnW\d̽4ԝm2"MDt65ࡣȼl R^Q7 ;s
۰&Dۼ~Bn%|-a:skF]`c,ۆA HuVM'1-:) p7N"PcՃos4ߣ$|ܵJ̸@ܼwH!+h! )3!AHD,0Da4aCn$B &ͪ0"}}3L.Ql IOLzEo9Ahx0L7E-5-p0 ^d2̌ y@M+A !|5Uo~#s`y VH9ŚjB8L0X+2Ɓ|e?i D n_j]KUs3'%7JzW%Y&)ޣS3{lLBI\4L  ՁoqLU2\3~t 6O$^hҗ`FS }esSiP293{ԇPO\p=iۚK^yQ=v[(?I9;[sʺز cѦʏfӞU[|fh:+E*'"P(^?f3.8cq+%ZIɱطk%YTYo $KNO _E  x9}x,1sI/\Q,;T&v: ,çSrY`Vc_*FpBOr2S `>Uc6ZacwS]X|1H_-ˮgT%䋲֦ 5(}Wm--9?R.9H|nbPyP6GЦ;gmIj"oA@r&>%e,HPwEkq&> $~a.AzCR(IȨh|h S_3HwniI6{ur'γy-t?>228nսn5A~OT&_mϲ FMilXL ;II $1 /aUѱa`_j9N'Hhӟ[d*="2lS f#frAE1kXh*nA:!X1T (LZ$\%p%DV@?KX *ߚeɨ@r[>/+dl|A۷G͜aZ6P6Uo@]Ҙ"Y?f$"֥ǟY3A7 }) &>UGcT9eQO9](wKԄ|- Wѩdҭ74sYf'VsrG<9˭5CN-qS>L*+ 2MÜ=kGiZ! `ݛ⩛Rv HBv޻buFj:fO= Ŷ,CEjο?_-!*FV*LНcPc$i:σ8\ j֚dŅǕm</iZ׉zv9{:泡t0$@̒-'r)˸}]l?R[S>@$#SUd?k&"JoQe902h xp P4?zmv1 ^kfY׫鹞G4Pu4(Ziڑ%AM_SfO5:Ai^N8|uirc'ȓ:Ft\薶Ғ,S#>뼷 L|eH8<̛ Jx٘w ێy?ZF( "FT@JBfdVb?:r q ]6jQ&7P/Hc |FK5fՃrG97VYNC,ń&K]ԍ#Z.Հ-Nd|6p4efu\ /ܰɽӟ:i9lK{1+`F켘J!`T[״e9=¸N!.vu>krN41=ҖňGŨ:[!(B1u8rBaՊVK}AY/PJ5[}jns FfSv n>G&_8 ئEy`*Fqy?uzvʍ@Qo4-Խm&g9v RZSgvCy1v7,}e1X옭wUc%_!'Wz |Ae)>C[Ip8ZC]KF'|4&mR{(WNp &IoJ7'+G~!y"'y~Xiմ+&=  uN)aQNdzP-ܝ1"A#]DH-i]EGB{'`'X/D(ξ)xg$T [KPۢ Ha{h/6ѓ? Qw$0_gQdzl[pU:=po$+%bKa%;>lZi9rhkL7.Qe(NWw]vGZف~踻YJdzz]g,]إ ce@:r< *zx!sL>X%56bx!c"1E%K3n71U Ֆ];˴| &]qM q@J7Z1n`p$ cP 3Pˋyf`+pR\B>(y#x᪓N=Ov#27- [gDڙm ECL#4d977ů8,azJ uH6!3LJY"X4я3pf:1~ېhPb\y-! 3qϽSf+[Φe_Q<8g1XNJؒix>& P]F4Ukvn$ȭdTnC oDqu/%ݟhcۑ>HoO@NPM膄bZP{z Jvq]fD9 p-{q.b^ڌ˜BzeLc"- K&&V!St+R%Zz#TeDJ""ge7b;wMxYay:ˇ,v]gHwGȑS5DW tKF&o֝,GMЛ-)IM,!#c_Wé Z 0'tCw71gt`zӈeXۀ/BUOo(C-'S|>FBk ͅ~xHlJPa8Pxјơ$YEUH%^XkY۲2o5Z &mqKWGuP*ѿ0^XYB1ǬLZj M uTcN+.cV2 "0EJz ƽ>@ZYq1݁Ii! iJ kELtdi(m"ShO}uHJ8K7PJVo*x+Cd2U#e3B'#Ә^2Pa@Hgdo~2H.-s'bt=PтrOD @iR8| &?+SL+?^3~e[5G9vmqq -*3.E}_Gc7mo4?S#ɵg&7UȏɘesFz`78ǰz(՘6ۙjFZAaClؿDq31ltz 5 Qxt/KF\0CH+jJt#35%*[J{w8Q(f{6կ;9 ?rM2p7;Z_{4%~,-r~=Ȗflɧ:VQ޿?x.\w}̬z2 adWd1ǷーYQ#YcȝWef `%Lg d#*<|ף .F7b@w[7:`vCª򌫀h_'@BAW)Ċ^~̫m̽/jkD)zhMf8O|1 X!G)ͩʍKn00WDnYՖwi*2Ql]#co+yyv5_:M]({/F]\]h"H}mݝ[G XY|"d/j79>RzYtq(ݜu[22lnN>?$Vnptw QP| n T5zA)gOr6+1f!m~cH`q6NzYI*bT`񿢮֒b<Ϡ&Sj.ym1"^$q hˈo+cUcNMȅ2EZq,WǛw7yAL 2^SbvwD蠭_0 Kh æP;Bĕtay:D%g7Li@ }_ctktXO_ ai()|eWEm!ۆα׺ Y&(#jxX F-Ea7D~KU`:wֆ|KU?n~Ke1-)oe88P7>>phEgXmFA%anid~o4t^A" |/^ʼnQ(0h'[H9.˄qo?א4bD9 O!-0욖}BȢca* Mօ,Q2Mt& c&)h1h] e~Nq"M \ʬT"ŋ>*)uk%8(K u"58D/Y"ggo8j۬N,{_bP!-C%.mb ͏UjDHTM-]pryf?釗,0o!BGTEJi3 T4ZT m Sl[hwf8igvK>G>ʥ;v+׼ .͏53~)$q͎^k"ŔeKo60FGaoF낭e foS'.ΆT)a13:|->Հ"8 xGuxpmh:Dnz|>'SIJV`;,M:Q2QP $IYlDxCmkF)eXbNL( gcAyX sdgЫDAZX34)]syTAץ ض7@e4x鉞< h VQ62+NG+pi~$0&4r]F;[-gUp9Fg!wj~NZ_Ɲ)72=WgW7޼2e B_3m[uG