ca-certificates-1_201403302107-12.3>t  DH`pYU/=„_|% s_!/oօkr)5fJU;W j斶7GtV.QUcaHe:ϝhOeT&؜i8  *,]xw^!t[Wy=Q ~NdGwZ !sco ?2 ګ8X-2C}"#TXy3Iij퀺K+j!>|\kMoFO:ӋD-f̢%q\iiO$t҄a+r 13f3c8c814e64facecd68e58ce20739c46b1d216PhYU/=„USuU o}"ɴ}xZT>@0p9*iG@և1I?g47yF)P>2@]ЦT'gdm>vH!X ;»-{f DLNxN!܎JMe=*ن#,llk+b'~0#zZzR2."~GF"?"xd! & \ 39@!u0 h     l   <  T    P(68@ 9 : =i>q@yBFGH,IXYZ[\]d^bckdefluv `w!Tx!y"4z"H"X"p"tCca-certificates1_20140330210712.3Utilities for system wide CA certificate installationUtilities for system wide CA certificate installationYU wildcard3maopenSUSE Leap 42.3openSUSEGPL-2.0+http://bugs.opensuse.orgProductivity/Networking/Securityhttps://github.com/openSUSE/ca-certificateslinuxnoarch# migrate /etc/ssl/certs to a symlink if [ "$1" -ne 0 -a -d /etc/ssl/certs -a ! -L /etc/ssl/certs ]; then # copy custom pem files to new location (bnc#875647) mkdir -p /etc/pki/trust/anchors for cert in /etc/ssl/certs/*.pem; do test -f "$cert" -a ! -L "$cert" || continue read firstline < "$cert" # skip package provided certificates (bnc#875647) if test "${firstline#\# generated by }" != "${firstline}" || rpm -qf "$cert" > /dev/null; then continue fi # create a p11-kit header that set the label of # the certificate to the file name. That ensures # that the certificate gets the same name in # /etc/ssl/certs as before bn="${cert##*/}" ( cat <<-EOF # created by update-ca-certificates from # $cert [p11-kit-object-v1] class: certificate label: "${bn%.pem}" trusted: true EOF cat $cert ) > "/etc/pki/trust/$bn" done mv -T --backup=numbered /etc/ssl/certs /etc/ssl/certs.rpmsave && ln -s /var/lib/ca-certificates/pem /etc/ssl/certs fiif [ -s /etc/ca-certificates.conf ]; then while read line; do [ ${line#\!} != "$line" ] || continue cert="${line#\!*/}" ln -s /usr/share/ca-certificates/anchors/"$cert" /etc/pki/trust/blacklist done < /etc/ca-certificates.conf echo "/etc/ca-certificates.conf converted and saved as /etc/ca-certificates.conf.rpmsave" mv /etc/ca-certificates.conf /etc/ca-certificates.conf.rpmsave fi # force rebuilding all certificate stores. # This also makes sure we update the hash links in /etc/ssl/certs # as openssl changed the hash format between 0.9.8 and 1.0 update-ca-certificates -f || trueif [ "$1" -eq 0 ]; then rm -rf /var/lib/ca-certificates/{pem,openssl} fi&: `FWAAAAAAAAA큤AAAAA큤AmAmYU YU YU YU YU YU YU YU YU YU YU YU YU YU YU YU S8k~S8k~YU YU YU YU YU YU YU YU YU YU cc72a6212693604d2e82e0bfb3d0681e10eec62c230103e8e06b4583fe07da9912f1752e2982c4222630d5f060c372bdaf90f55cbd8f8fd3fe3e53e013bec9ccc8e67b90abfc0f07e34bace9b144b59b0636e73ff0215e8d672dc4c32c317bb343620eab7ebfb9702656af60bccc5f1e5aa14149e663fc3e1cb1e9761e74f51ad41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427e/var/lib/ca-certificates/ca-bundle.pem/var/lib/ca-certificates/pem@@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootca-certificates-1_201403302107-12.3.src.rpmca-certificatesjava-ca-certificates@@    /bin/bash/bin/sh/bin/sh/bin/sh/usr/bin/perlcoreutilsopensslopensslp11-kitp11-kit-toolsp11-kit-toolsrpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsLzma)0.19.33.0.4-14.0-14.4.6-14.11.2S@SuS@SǺSS @SkqSB@S>R@R^RRQQ)@Q4Q4QONS@M6@L@KuKKKK@K@K@KKKlnussel@suse.delnussel@suse.delnussel@suse.demeissner@suse.comlnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.dehrvoje.senjan@gmail.comlnussel@suse.delnussel@suse.delnussel@suse.decoolo@suse.comlnussel@suse.delnussel@suse.demvyskocil@suse.czlnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.delnussel@suse.de- use rpm -qf to determine if a ssl cert is owned by some other package and therefore doesn't need to be migrated (related to bnc#890205).- add p11 kit header to set label of migrated certificates to the file name of the previous one (bnc#890205)- removed the version in the Obsoletes. The package in SLE11 got version updated (bnc#887099).- clarify the start order of the generators, as certbundle.run semi-depends on etc_ssl.run via a timestamp. (bnc#883386)- fix directory permissions for real this time (bnc#871639)- don't keep certificates with marker (bnc#875647)- copy custom pem files in /etc/ssl/certs to /etc/pki/anchors on update (bnc#875647)- Fix typo in man page- package correct permissions of generated directories (bnc#871639)- etc_ssl.run: fix typo - turn /etc/ssl/certs into a symlink to /var/lib/ca-certificates/pem- fix typo in README (bnc#845500) - remove old extractcerts.pl- re-enable the CA bundle again for glib-networking (bnc#825903)- make sure we have p11-kit >= 0.19.3 which has the 'trust' command (bnc#836560)- don't remove symlinks to other locations in /etc/ssl/certs - use the trust binary instead of p11-kit to extract trust- disable generating ca-bundle for now again so people don't submit new packages that use this file.- Explicitly require p11-kit, otherwise trusted certificates won't be generated- update manpage- use p11-kit to generate the files- give hint about SSL_CTX_set_default_verify_paths in cert bundle- require coreutils for %post script- fix spurious rpm warning if no java exists (bnc#634793) - move java.run to java-ca-certificates- catch FileNotFoundException (bnc#623365)* Use the gcc-java and fastjar for build to avoid dependency problems * build keystore.class only to allow noarch package- create java bundles- also use hooks from /usr/lib/ca-certificates/update.d - replace bundle file with symlink to file in /var as it's auto generated- force rebuilding all certificate stores in %post This also makes sure we update the hash links in /etc/ssl/certs as openssl changed the hash format between 0.9.8 and 1.0- actually install certbundle.run (bnc#594501)- it's ca-bundle.pem rather than cert.pem- obsolete openssl-certs (bnc#594434) - update manpage (bnc#594501)- include /etc/ca-certificates.conf as %ghost- generate ca-bundle with hook script - don't use trusted certificates in ca-bundle file for compatibility with gnutls- new package/bin/sh/bin/sh/bin/shopenssl-certsjava-ca-certificateswildcard3 1494373643 1_201403302107-12.31_201403302107-12.31 ca-certificatesupdate.dpkitrustanchorsblacklistca-bundle.pemcertsca-certificatesupdate.d50java.run70openssl.run80etc_ssl.run99certbundle.runupdate-ca-certificatesca-certificatesCOPYINGREADMEupdate-ca-certificates.8.gzpkitrustanchorsblacklistca-certificatesca-bundle.pemjava-cacertsopensslpem/etc//etc/ca-certificates//etc/pki//etc/pki/trust//etc/ssl//usr/lib//usr/lib/ca-certificates//usr/lib/ca-certificates/update.d//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/ca-certificates//usr/share/man/man8//usr/share//usr/share/pki//usr/share/pki/trust//var/lib//var/lib/ca-certificates/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:Leap:42.3/standard/faf5b04b9ed33df8522abfe57dd9a93f-ca-certificatescpiolzma5noarch-suse-linuxdirectoryBourne-Again shell script, ASCII text executablea /usr/bin/perl -w script, ASCII text executablePascal source, ASCII textASCII texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)emptyRRRRR z"=<&9YIVvCca-certificates-mozilla?] crt:bLLDG CQI!OEyکe7C=DHWa)3C'ylxk?"Q g ٦UsI3->ʓ,dJ:-fGKg}tg/3"FI2e:%=#OTQoSyݟZy QzKJW6E>&|+3Iz9x𒼢42]Bw+̓i [$˾@1]z?Uz-Z`;p&˳ n~p*l jbq!Xh';,8?##/ 0ã|^+o=ː7K|N/wD(_jpz >m;ӖL /NsYGWhe!s <(e˙,$>;/*x&MbVZ{i'yʡVtZ,jȖe((X>:\p) %- jŔ\Ah]y(?1"PJKNsjxfoc%,e5Ox=.˜4ߏۓ?`8XP)䎃`b`KZmFVXgfM.ƒcGұc vq죁H!SKH If`/G$\q9N(}gfҮrNҿQ;=88, CK9n܆j%C'Ӻ+ dj ɴ;^APIM]uS[L}YnX^%N"eF ߞh!qas`4&|E8E")i7S͏[Ai&ȚUBתEJt.QMw/#09y%s1,.bN() X?^Խ41-y {R鴘n0l30V i޶x$C5ݯMt,0 [K%~b>Aʄ="鰿;]K΄INu.[$o5$9eaJU-PQ V']pv=OP4[)zUw-AOU_if69S~c`1|f6(1qos~.7wtTeb`߀,Jߗ3f_ c^;P.wF7 9!6JĂVMF&rфBwٮ}%? NGV?c_ |j4∘W՜!NW )X|RFuM1rnH:x`>Kҍiv|)']Z\ <m^`ChKbŪ'tjl~9 @q4ߨ$0šm݅plČl#ioMq?Yiqyh⢐1s a.}/J t^%{;#whb [๷%[/PT{*$:T%1'{YO>-}-Te,Q ?3F:.eQ)v>gDA&U;_Ty-*of3 wC\P*)78/\S@wi%g0d-d_A\ښR͇x8џI%8 SQݓQSs*+drPXQCn 613݁5(7= 'HHĺp֤]R bRUjH}^'H:X88MłZhߞ6m.de_NRr`QY oourF֌ͭհmGV 'AnA>gS@5rg]l ̈ l.@V0$P6;a{)8ͭ88u[B?+ָZd1ከZCx7p*N K3P^cs4ěgNQ)Zk.lwbb?V?sǥR,~,ӑk]7j 1`!gyp0:a"aɰRͺô 4)1 / H1#9,ZJGAڨ".Jaޫ$ "fXXǙB%6"xcvsdX{8b!|dvD\B}rJ4 f$_ȝFθv`At=r1l[Ƴ&9D^%7#g@-]7HčLs'H^͞"2Z\\ 3h.f5_g.rvKڛ_-n@f61u=!ouJ˪AO?W^x zqC1&"d^1I 02侢|AcnĦ ,0),Zǀ̄l5SMp`C ˅7ĵ Xڍ +g԰BL֮PYǾ.,}SE:ǴhG+sT/n$S>Mu`!j{mѷ%n5 #gV ^ǕE}[(͒}h{,I `s []2G 62®PS5:ۤ:sO280qChޟq 峘DhW- VlBngK^1ٖ4l\lot%ӓ3^[Fs>; sQɽ[AQ.t.$2K`2-[9po0[O h&$, mvGw5B'3JUZ6 -_EӈϓcGCUj};2BsC aت)Ixd[*} r3S禱Z0@ ,@Ulh'fJ52 ȩ9m.FQ9ZP wxnWc00&{4O'q~s'avIJV85EU ($F uLХTYk.aC"S+m6l&2m= LO=@f`)4POb6+ ISA20;ckn/I&iIFy⏍v~==+tTů㿍{LMdޖIT6?AD62Cjx3` sKoNxo_޸a'  @q(lisg;FzʟK*/,100a5s8"^s_t)EWUj8OC+;Ω69cLEme0o OP&A90])]XFk,JCkTh~ZA|l5n1;iӀd֛3  ɏ=HIu7Au>jCěqS6Y[FnhSB$_^~ QN?%5ϸN=E //**:uΐKz,Sbvz%")]g)e#h#xu\-.W ~P21sQܵyғ#ۼlcҁ%FG$ٚ~rz~׼={FDj|('~{N MP}`,䞼ڵ6 x1WM ~ul"#w=lns3Zѵ_!J3)vb>=ȋ/%L"|/K5E., 0˰ \zlx,r :aUmQfqb> @^86hFq_RYu`SY?$SD\':@HDd}d͟Mf >궀]f{ 6hnUb#cޅMJ/[:S_޵ȴ0OʇX nʀs=W0ylrԠ L /cFCJ$lEi:n*{@pQh[Gkk]u һoo{+'F=%H'9va_HԈ,'ٵg5`fQ 9NyHD,Cq(jPRcS~'ƊU#++<:7&~Z*[+Hb rɶO: 曗El æ'+T60[hw&\GމDϙd5]b<ɹ<Ќ&T\8U@l1o2_2SAyZW{qN^2 d߃iZSWA֍@eiAW%+jΥkVw[YHhN{<3fv,2rQD$ق:m \ ՝sl{%?a9{5 It2IdkƔ5O ](Y4ajLȀup!+(k2h՗lܤ~Voqpt 5+MZτ;ڦl1IF\mY$)LΤQO+:Y2cKa*fvN!'%w!jMhp\!Tff䋷?IC5մ>n_y02z9[q ?]h\4I8O]#xr@7Olø?{ Y"8pHļ>T $I;T6k)+SYF^ǔi'DQP(wM 9WgB;(X' js\n,Ɠ^+-fd.7\5h +kνM/Y0BPP+6PVF7'ﱋ~+C-x *OET%QSRm2Z4 P D`|WVݻ X"eJA|XZdvQ<o(_c++u)94JpOQ.>n@:׈ 0S}hށ)a` b 'd_e&z0Vm@~ 1|RJ\o>Ujͷ,KOi˂^ʥL/wO֞-Zn *Ǥ]_w~ck攱ܳ/fc|k%~.9( |2f 6~p:Ӑс`z |,*NBas"eJ/ lpPݦx*|2sRWD*&C?I9coPktx-< i@!}J* c.9!1Xכ-B"2RW7ն`+ ir*'Wc`Į\cka0dPZEUFA-CoÛ_`囦*ܚ? ,9bkQR隦~AfX-^5X_uՏB 0sZ>PÜ;WԾvVU8JU9]1Q=ӥʰN`:e:_O,lsK8dꕎwbw.1X9."XH/$ g#WݚӍǏ94XՖ?'YPl8 I-& "QMRe <53VD|Wo[KdԇaŸW(**Vfm1Z-2[ 2AB&m=r'K6\Fq_B'&RwϞd8YfhAq/&퓈$-ӳ.;-Psd[uf|k$O?PJgbHk%p[sˉ+TJNUzdFp,8+o"\CTWw 4Hb9ͿZe0TJޚ5>ļ S_ (13 DTJ0lqj?$lxGvnwf(`qXm )τ㒉A&W͠zOR}8De"pA[$Y 1&E KC뻷,/+ȼ~· e1p 0b%<:i7%'p܀^@ @Ta7@>ص *IQndi+40Ө^☈sg$xs2ųJ?gC͠f".MTdaUE]hwPm}AJg|iPPyJn%di`g"'Ubɰ#sGx2dтDqhզrEd2mAG&ƥ}}J2=D?t%gIX*:u 홶GsEWK|)"4Qr&gyWEǕK  "˽*Hcr^Ĥ׀.RZ#{WTD- T[$蝪 ߽E\ғzTY^6ߜe_D!, T .d5o3ݢ/y=Ī-jafY Һ/Jplf6q3836*W>/,Zk2]fI6^ KnI&.ViмABl{ a Wa_zEv7rvQ(2aO#WP;pk/2` s߈LޝjrK`)jmM1h)R%Eh")ްOV6.*aG7"z?>D) eo2=qClg>X)(DCQ~2i-arU.0 zw#sVNlƐ+!:T{H6WOֵwd KRJ ; ?oJT0BgdQ1[-LD+mIҔotɦ N`a=(i,k>,._fUyP _5ᏺEޘ“k mvOC2k}X2qnpr_vaboH}:) ,s4I#W݀gN"ltӭ}6@@ٜWL=H$8zBo,Wd@@z@'~p#5̡۪}–R$^w.BzLĤ9űcm9%8 g\^ld5ݍ@m+(}kQ){.&uD~ӜHtλ#I_{Z}磻>2y~ee´Z9h̞Sm^q\jZJE{-%~P)j=AqZ?!Lf{:ZE{18;W kr{FEfuoB)r= Wz^AS^a/ .iAEvV\Cdħo@C@|V*V!k^_ǗhMmu=\[!ʴksEr1i{ 0͗'͢gL\zQ_;NwZU0~{ȆϛC񳔀t[?#YGÚ>̽_ r;׹u”_I?SD{{E)h"=?/b%@(Q ܻH(Ñ8t@i<&Pqk-&}ItzGC'8m%Q?$Ʒ^]Wؗ|GB2!TsԋYxgsq5TIb Czѿwk2%:vLA=ʟ%ۅ ʟh$:j]d]AU_E[;c%缳9u.@V'&BtݟP9 yi*6aCFY֋=[4."~Ν%mHES=ͧÀ 1*n