mod_ldap-2.4.6-97.sl7_9.5> H HtxHFb< ?*}}r }Bi9\on&Я90[5CqC343070c93c4e5c5f9802eadae5a01168e516c554 Ey'4R=5sFb< ?*}}3y?yd   S *CIP\ b h t 7 <HWf4(z89:);GxxHxIxXxYx\x]x^xby-dyeyfylyyCmod_ldap2.4.697.sl7_9.5LDAP authentication modules for the Apache HTTP ServerThe mod_ldap and mod_authnz_ldap modules add support for LDAP authentication to the Apache HTTP Server.bMMn1@MdMRMF@M(QM$]@M$]@M# L@L@LLMxL7@K@Scientific Linux Auto Patch Process Luboš Uhliarik - 2.4.6-97.5Luboš Uhliarik - 2.4.6-97.4Luboš Uhliarik - 2.4.6-97.3Luboš Uhliarik - 2.4.6-97.2Luboš Uhliarik - 2.4.6-97.1Lubos Uhliarik - 2.4.6-97Lubos Uhliarik - 2.4.6-95Lubos Uhliarik - 2.4.6-94Lubos Uhliarik - 2.4.6-93Joe Orton - 2.4.6-92Lubos Uhliarik - 2.4.6-91Lubos Uhliarik - 2.4.6-90Joe Orton - 2.4.6-89Luboš Uhliarik - 2.4.6-88Luboš Uhliarik - 2.4.6-87Luboš Uhliarik - 2.4.6-86Luboš Uhliarik - 2.4.6-85Luboš Uhliarik - 2.4.6-84Luboš Uhliarik - 2.4.6-83Luboš Uhliarik - 2.4.6-82Joe Orton - 2.4.6-81Luboš Uhliarik - 2.4.6-80Luboš Uhliarik - 2.4.6-79Luboš Uhliarik - 2.4.6-78Luboš Uhliarik - 2.4.6-77Luboš Uhliarik - 2.4.6-76Luboš Uhliarik - 2.4.6-75Luboš Uhliarik - 2.4.6-74Luboš Uhliarik - 2.4.6-73Luboš Uhliarik - 2.4.6-72Luboš Uhliarik - 2.4.6-71Luboš Uhliarik - 2.4.6-70Luboš Uhliarik - 2.4.6-69Luboš Uhliarik - 2.4.6-68Luboš Uhliarik - 2.4.6-67Luboš Uhliarik - 2.4.6-66Luboš Uhliarik - 2.4.6-65Luboš Uhliarik - 2.4.6-64Luboš Uhliarik - 2.4.6-63Luboš Uhliarik - 2.4.6-62Luboš Uhliarik - 2.4.6-61Luboš Uhliarik - 2.4.6-60Luboš Uhliarik - 2.4.6-59Luboš Uhliarik - 2.4.6-58Luboš Uhliarik - 2.4.6-57Luboš Uhliarik - 2.4.6-56Luboš Uhliarik - 2.4.6-55Luboš Uhliarik - 2.4.6-54Luboš Uhliarik - 2.4.6-53Luboš Uhliarik - 2.4.6-52Luboš Uhliarik - 2.4.6-51Luboš Uhliarik - 2.4.6-50Luboš Uhliarik - 2.4.6-49Luboš Uhliarik - 2.4.6-48Joe Orton - 2.4.6-47Luboš Uhliarik - 2.4.6-46Luboš Uhliarik - 2.4.6-45Joe Orton - 2.4.6-44Joe Orton - 2.4.6-43Joe Orton - 2.4.6-42Jan Kaluza - 2.4.6-41Jan Kaluza - 2.4.6-40Jan Kaluza - 2.4.6-39Jan Kaluza - 2.4.6-38Jan Kaluza - 2.4.6-37Jan Kaluza - 2.4.6-36Jan Kaluza - 2.4.6-35Jan Kaluza - 2.4.6-34Jan Kaluza - 2.4.6-33Jan Kaluza - 2.4.6-32Jan Kaluza - 2.4.6-31Jan Kaluza - 2.4.6-30Jan Kaluza - 2.4.6-29Jan Kaluza - 2.4.6-28Jan Kaluza - 2.4.6-27Jan Kaluza - 2.4.6-26Jan Kaluza - 2.4.6-25Jan Kaluza - 2.4.6-24Jan Kaluza - 2.4.6-23Jan Kaluza - 2.4.6-22Jan Kaluza - 2.4.6-21Jan Kaluza - 2.4.6-20Jan Kaluza - 2.4.6-19Jan Kaluza - 2.4.6-18Jan Kaluza - 2.4.6-17Joe Orton - 2.4.6-16Joe Orton - 2.4.6-15Daniel Mach - 2.4.6-14Joe Orton - 2.4.6-13Joe Orton - 2.4.6-12Joe Orton - 2.4.6-11Joe Orton - 2.4.6-10Daniel Mach - 2.4.6-9Joe Orton - 2.4.6-8Jan Kaluza - 2.4.6-7Jan Kaluza - 2.4.6-6Jan Kaluza - 2.4.6-5Jan Kaluza - 2.4.6-4Jan Kaluza - 2.4.6-3Jan Kaluza - 2.4.6-2Joe Orton - 2.4.6-1Jan Kaluza - 2.4.4-12Joe Orton - 2.4.4-11Joe Orton - 2.4.4-10Joe Orton - 2.4.4-9Jan Kaluza - 2.4.4-8Jan Kaluza - 2.4.4-6Jan Kaluza - 2.4.4-5Jan Kaluza - 2.4.4-4Jan Kaluza - 2.4.4-3Joe Orton - 2.4.4-2Joe Orton - 2.4.4-1Joe Orton - 2.4.3-17Fedora Release Engineering - 2.4.3-16Joe Orton - 2.4.3-15Joe Orton - 2.4.3-14Joe Orton - 2.4.3-13Joe Orton - 2.4.3-12Joe Orton - 2.4.3-11Joe Orton - 2.4.3-10Joe Orton - 2.4.3-9.1Joe Orton - 2.4.3-9Joe Orton - 2.4.3-8Joe Orton - 2.4.3-7Jan Kaluza - 2.4.3-6Joe Orton - 2.4.3-5Joe Orton - 2.4.3-4Jan Kaluza - 2.4.3-3Joe Orton - 2.4.3-2Joe Orton - 2.4.3-1Joe Orton - 2.4.2-23Fedora Release Engineering - 2.4.2-22Joe Orton - 2.4.2-21Joe Orton - 2.4.2-20Joe Orton - 2.4.2-19Joe Orton - 2.4.2-18Joe Orton - 2.4.2-17Joe Orton - 2.4.2-16Joe Orton - 2.4.2-15Joe Orton - 2.4.2-14Joe Orton - 2.4.2-13Joe Orton - 2.4.2-12Joe Orton - 2.4.2-11Joe Orton - 2.4.2-10Joe Orton - 2.4.2-9Joe Orton - 2.4.2-8Joe Orton - 2.4.2-7Joe Orton - 2.4.2-6Joe Orton - 2.4.2-5Joe Orton - 2.4.2-4Joe Orton - 2.4.2-3.2Joe Orton - 2.4.2-3Joe Orton - 2.4.2-2Jan Kaluza - 2.4.2-1Joe Orton - 2.4.1-6Joe Orton - 2.4.1-5Joe Orton - 2.4.1-4Joe Orton - 2.4.1-3Joe Orton - 2.4.1-2Joe Orton - 2.4.1-1Joe Orton - 2.2.22-2Joe Orton - 2.2.22-1Petr Pisar - 2.2.21-8Jan Kaluza - 2.2.21-7Joe Orton - 2.2.21-6Fedora Release Engineering - 2.2.21-5Jan Kaluza - 2.2.21-4Jan Kaluza - 2.2.21-3Ville Skyttä - 2.2.21-2Joe Orton - 2.2.21-1Joe Orton - 2.2.20-1Jan Kaluza - 2.2.19-5Iain Arnell 1:2.2.19-4Jan Kaluza - 2.2.19-3Jan Kaluza - 2.2.19-2Joe Orton - 2.2.19-1Joe Orton - 2.2.17-13Joe Orton - 2.2.17-12Joe Orton - 2.2.17-11Joe Orton - 2.2.17-10Joe Orton - 2.2.17-9Fedora Release Engineering - 2.2.17-8Joe Orton - 2.2.17-7Joe Orton - 2.2.17-6Joe Orton - 2.2.17-5Joe Orton - 2.2.17-4Joe Orton - 2.2.17-3Joe Orton - 2.2.17-2Joe Orton - 2.2.17-1Joe Orton - 2.2.16-2Joe Orton - 2.2.16-1Joe Orton - 2.2.15-3Robert Scheck - 2.2.15-1- Added Source: httpd-sl_index.html.sl.patch --> This patch removes TUV branding from the default index.html - Added Source: httpd-spec_sl_index.html.sl7.patch --> The index.html file is outside of the source tarball, so we need to patch it in the install step - Added Source: httpd.ini --> Config file for automated patch script- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via malformed requests - Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in ap_escape_quotes() via malicious input - Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow when parsing multipart content- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted request uri-path containing "unix:"- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending a client cert to backend server - Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout - Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool concurrency issues- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value- Resolves: #1565491 - CVE-2017-15715 httpd: bypass with a trailing newline in the file name - Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect - Resolves: #1724879 - httpd terminates all SSL connections using an abortive shutdown - Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive - Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause a denial of service - Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect expiry time- htpasswd: add SHA-2 crypt() support (#1486889)- Resolves: #1630886 - scriptlet can fail if hostname is not installed - Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in mod_authnz_ldap when using too small Accept-Language values - Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after failure in reading the HTTP request - Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch directive - Resolves: #1633152 - mod_session missing apr-util-openssl - Resolves: #1649470 - httpd response contains garbage in Content-Type header - Resolves: #1724034 - Unexpected OCSP in proxy SSL connection- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation in mod_auth_digest - Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control bypass due to race condition - Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency- fix per-request leak of bucket brigade structure (#1583218)- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple SIGUSR1- Resolves: #1458364 - RMM list corruption in ldap module results in server hang- Resolves: #1493181 - RFE: mod_ssl: allow sending multiple CA names which differ only in case- Resolves: #1556761 - mod_proxy_wstunned config needs the default port number- Resolves: #1548501 - Make OCSP more configurable (like CRL)- Resolves: #1523536 - Backport Apache BZ#59230 mod_proxy_express uses db after close- Resolves: #1533793 - Use Variable with mod_authnz_ldap- don't terminate connections during graceful stop/restart (#1557785)- Related: #1288395 - httpd segfault when logrotate invoked- Resolves: #1274890 - mod_ssl config: tighten defaults- Resolves: #1506392 - Backport: SSLSessionTickets directive support- Resolves: #1440590 - Need an option to disable UTF8-conversion of certificate DN- Resolves: #1464406 - Apache consumes too much memory for CGI output- Resolves: #1448892 - Cannot override LD_LIBARY_PATH in Apache HTTPD using SetEnv or PassEnv. Needs documentation.- Resolves: #1430640 - "ProxyAddHeaders Off" does not become effective when it's defined outside setting- Resolves: #1499253 - ProxyRemote with HTTPS backend sends requests with absoluteURI instead of abs_path- Resolves: #1288395 - httpd segfault when logrotate invoked- Resolves: #1368491 - mod_authz_dbd segfaults when AuthzDBDQuery missing- Resolves: #1467402 - rotatelogs: creation of zombie processes when -p is used- Resolves: #1493065 - CVE-2017-9798 httpd: Use-after-free by limiting unregistered HTTP method- Resolves: #1463194 - CVE-2017-3167 httpd: ap_get_basic_auth_pw() authentication bypass - Resolves: #1463197 - CVE-2017-3169 httpd: mod_ssl NULL pointer dereference - Resolves: #1463207 - CVE-2017-7679 httpd: mod_mime buffer overread - Resolves: #1463205 - CVE-2017-7668 httpd: ap_find_token() buffer overread - Resolves: #1470748 - CVE-2017-9788 httpd: Uninitialized memory reflection in mod_auth_digest- Related: #1332242 - Explicitly disallow the '#' character in allow,deny directives- Related: #1332242 - Explicitly disallow the '#' character in allow,deny directives- Resolves: #1445885 - define _RH_HAS_HTTPPROTOCOLOPTIONS- Resolves: #1442872 - apache user is not created during httpd installation when apache group already exist with GID other than 48- Related: #1412976 - CVE-2016-0736 CVE-2016-2161 CVE-2016-8743 httpd: various flaws- Resolves: #1397241 - Backport Apache Bug 53098 - mod_proxy_ajp: patch to set worker secret passed to tomcat- Related: #1414258 - Crash during restart or at startup in mod_ssl, in certinfo_free() function registered by ssl_stapling_ex_init()- Resolves: #1414258 - Crash during restart or at startup in mod_ssl, in certinfo_free() function registered by ssl_stapling_ex_init()- Resolves: #1378946 - Backport of apache bug 55910: Continuation lines are broken during buffer resize- Resolves: #1364604 - Upstream Bug 56925 - ErrorDocument directive misbehaves with mod_proxy_http and mod_proxy_ajp- Resolves: #1324416 - Error 404 when switching language in HTML manual more than once- Resolves: #1353740 - Backport Apache PR58118 to fix mod_proxy_fcgi spamming non-errors: AH01075: Error dispatching request to : (passing brigade to output filters)- Resolves: #1371876 - Apache httpd returns "200 OK" for a request exceeding LimitRequestBody when enabling mod_ext_filter- Resolves: #1372692 - Apache httpd does not log status code "413" in access_log when exceeding LimitRequestBody- Resolves: #1376835 - httpd with worker/event mpm segfaults after multiple successive graceful reloads- Resolves: #1332242 - Explicitly disallow the '#' character in allow,deny directives- Resolves: #1396197 - Backport: mod_proxy_wstunnel - AH02447: err/hup on backconn- Resolves: #1348019 - mod_proxy: Fix a race condition that caused a failed worker to be retried before the retry period is over- Resolves: #1389535 - Segmentation fault in SSL_renegotiate- Resolves: #1406184 - stapling_renew_response: abort early (before apr_uri_parse) if ocspuri is empty- prefork: fix delay completing graceful restart (#1327624) - mod_ldap: fix authz regression, failing to rebind (#1415257)- Resolves: #1412976 - CVE-2016-0736 CVE-2016-2161 CVE-2016-8743 httpd: various flaws- RFE: run mod_rewrite external mapping program as non-root (#1316900)- add security fix for CVE-2016-5387- add 451 (Unavailable For Legal Reasons) response status-code (#1343582)- mod_cache: treat cache as valid with changed Expires in 304 (#1331341)- mod_cache: merge r->err_headers_out into r->headers when the response is cached for the first time (#1264989) - mod_ssl: Do not send SSL warning when SNI hostname is not found as per RFC 6066 (#1298148) - mod_proxy_fcgi: Ignore body data from backend for 304 responses (#1263038) - fix apache user creation when apache group already exists (#1299889) - fix apache user creation when USERGROUPS_ENAB is set to 'no' (#1288757) - mod_proxy: fix slow response time for reponses with error status code when using ProxyErrorOverride (#1283653) - mod_ldap: Respect LDAPConnectionPoolTTL for authn connections (#1300149) - mod_ssl: use "localhost" in the dummy SSL cert for long FQDNs (#1240495) - rotatelogs: improve support for localtime (#1244545) - ab: fix read failure when targeting SSL server (#1255331) - mod_log_debug: fix LogMessage example in documentation (#1279465) - mod_authz_dbd, mod_authn_dbd, mod_session_dbd, mod_rewrite: Fix lifetime of DB lookup entries independently of the selected DB engine (#1287844) - mod_ssl: fix hardware crypto support with custom DH parms (#1291865) - mod_proxy_fcgi: fix SCRIPT_FILENAME when a balancer is used (#1302797)- mod_dav: follow up fix for previous commit (#1263975)- mod_dav: treat dav_resource uri as escaped (#1255480)- mod_ssl: add support for User Principal Name in SSLUserName (#1242503)- core: fix chunk header parsing defect (CVE-2015-3183) - core: replace of ap_some_auth_required with ap_some_authn_required and ap_force_authn hook (CVE-2015-3185)- Revert fix for #1162152, it is not needed in RHEL7 - mod_proxy_ajp: fix settings ProxyPass parameters for AJP backends (#1242416)- mod_remoteip: correct the trusted proxy match test (#1179306) - mod_dav: send complete response when resource is created (#1235383) - apachectl: correct the apachectl status man page (#1231924)- mod_proxy_fcgi: honor Timeout / ProxyTimeout (#1222328) - do not show all vhosts twice in httpd -D DUMP_VHOSTS output (#1225820) - fix -D[efined] or [d] variables lifetime accross restarts (#1227219) - mod_ssl: do not send NPN extension with not configured (#1226015)- mod_authz_dbm: fix crash when using "Require dbm-file-group" (#1221575)- mod_authn_dbd: fix use-after-free bug with postgresql (#1188779) - mod_remoteip: correct the trusted proxy match test (#1179306) - mod_status: honor remote_ip as documented (#1169081) - mod_deflate: fix decompression of files larger than 4GB (#1170214) - core: improve error message for inaccessible DocumentRoot (#1170220) - ab: try all addresses instead of failing on first one when not available (#1125276) - mod_proxy_wstunnel: add support for SSL (#1180745) - mod_proxy_wstunnel: load this module by default (#1180745) - mod_rewrite: add support for WebSockets (#1180745) - mod_rewrite: do not search for directory if a URL will be rewritten (#1210091) - mod_ssl: Fix SSL_CLIENT_VERIFY value when optional_no_ca and SSLSessionCache are used and SSL session is resumed (#1170206) - mod_ssl: fix memory leak on httpd reloads (#1181690) - mod_ssl: use SSLCipherSuite HIGH:MEDIUM:!aNULL:!MD5:!SEED:!IDEA (#1118476) - mod_cgi: return error code 408 on timeout (#1162152) - mod_dav_fs: set default value of DAVLockDB (#1176449) - add Documentation= to the httpd.service and htcacheclean.service (#1184118) - do not display "bomb" icon for files ending with "core" (#1170215) - add missing Reason-Phrase in HTTP response headers (#1162159) - fix BuildRequires to require openssl-devel >= 1:1.0.1e-37 (#1160625) - apachectl: ignore HTTPD variable from sysconfig (#1214401) - apachectl: fix "graceful" documentation (#1214398) - apachectl: fix "graceful" behaviour when httpd is not running (#1214430)- mod_proxy_fcgi: determine if FCGI_CONN_CLOSE should be enabled instead of hardcoding it (#1168050) - mod_proxy: support Unix Domain Sockets (#1168081)- core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704) - mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581)- rebuild against proper version of OpenSSL (#1080125)- set vstring based on /etc/os-release (#1114123)- fix the dependency on openssl-libs to match the fix for #1080125- allow 'es to be seen under virtual hosts (#1131847)- do not use hardcoded curve for ECDHE suites (#1080125)- allow reverse-proxy to be set via SetHandler (#1136290)- fix possible crash in SIGINT handling (#1131006)- ab: fix integer overflow when printing stats with lot of requests (#1092420)- add pre_htaccess so mpm-itk can be build as separate module (#1059143)- mod_ssl: prefer larger keys and support up to 8192-bit keys (#1073078)- fix build on ppc64le by using configure macro (#1125545) - compile httpd with -O3 on ppc64le (#1123490) - mod_rewrite: expose CONN_REMOTE_ADDR (#1060536)- mod_cgid: add security fix for CVE-2014-0231 (#1120608) - mod_proxy: add security fix for CVE-2014-0117 (#1120608) - mod_deflate: add security fix for CVE-2014-0118 (#1120608) - mod_status: add security fix for CVE-2014-0226 (#1120608) - mod_cache: add secutiry fix for CVE-2013-4352 (#1120608)- mod_dav: add security fix for CVE-2013-6438 (#1077907) - mod_log_config: add security fix for CVE-2014-0098 (#1077907)- mod_ssl: improve DH temp key handling (#1057687)- mod_ssl: use 2048-bit RSA key with SHA-256 signature in dummy certificate (#1071276)- Mass rebuild 2014-01-24- mod_ssl: sanity-check use of "SSLCompression" (#1036666) - mod_proxy_http: fix brigade memory usage (#1040447)- rebuild- build with -O3 on ppc64 (#1051066)- mod_dav: fix locktoken handling (#1004046)- Mass rebuild 2013-12-27- use unambiguous httpd-mmn (#1029360)- mod_ssl: allow SSLEngine to override Listen-based default (#1023168)- systemd: Use {MAINPID} notation in service file (#969972)- systemd: send SIGWINCH signal without httpd -k in ExecStop (#969972)- expand macros in macros.httpd (#1011393)- fix "LDAPReferrals off" to really disable LDAP Referrals- revert fix for dumping vhosts twice- update to 2.4.6 - mod_ssl: use revised NPN API (r1487772)- mod_unique_id: replace use of hostname + pid with PRNG output (#976666) - apxs: mention -p option in manpage- add patch for aarch64 (Dennis Gilmore, #925558)- remove duplicate apxs man page from httpd-tools- remove zombie dbmmanage script- return 400 Bad Request on malformed Host header- htpasswd/htdbm: fix hash generation bug (#956344) - do not dump vhosts twice in httpd -S output (#928761) - mod_cache: fix potential crash caused by uninitialized variable (#954109)- execute systemctl reload as result of apachectl graceful - mod_ssl: ignore SNI hints unless required by config - mod_cache: forward-port CacheMaxExpire "hard" option - mod_ssl: fall back on another module's proxy hook if mod_ssl proxy is not configured.- fix service file to not send SIGTERM after ExecStop (#906321, #912288)- protect MIMEMagicFile with IfModule (#893949)- really package mod_auth_form in mod_session (#915438)- update to 2.4.4 - fix duplicate ownership of mod_session config (#914901)- add mod_session subpackage, move mod_auth_form there (#894500)- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild- add systemd service for htcacheclean- drop patch for r1344712- filter mod_*.so auto-provides (thanks to rcollet) - pull in syslog logging fix from upstream (r1344712)- rebuild to pick up new apr-util-ldap- rebuild- pull upstream patch r1392850 in addition to r1387633- restore "ServerTokens Full-Release" support (#811714)- define PLATFORM in os.h using vendor string- use systemd script unconditionally (#850149)- use systemd scriptlets if available (#850149) - don't run posttrans restart if /etc/sysconfig/httpd-disable-posttrans exists- use systemctl from apachectl (#842736)- fix some error log spam with graceful-stop (r1387633) - minor mod_systemd tweaks- use IncludeOptional for conf.d/*.conf inclusion- adding mod_systemd to integrate with systemd better- mod_ssl: add check for proxy keypair match (upstream r1374214)- update to 2.4.3 (#849883) - own the docroot (#848121)- add mod_proxy fixes from upstream (r1366693, r1365604)- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- drop explicit version requirement on initscripts- mod_ext_filter: fix error_log warnings- support "configtest" and "graceful" as initscripts "legacy actions"- avoid use of "core" GIF for a "core" directory (#168776) - drop use of "syslog.target" in systemd unit file- use _unitdir for systemd unit file - use /run in unit file, ssl.conf- mod_ssl: fix NPN patch merge- move tmpfiles.d fragment into /usr/lib per new guidelines - package /run/httpd not /var/run/httpd - set runtimedir to /run/httpd likewise- fix htdbm/htpasswd crash on crypt() failure (#818684)- pull fix for NPN patch from upstream (r1345599)- update suexec patch to use LOG_AUTHPRIV facility- really fix autoindex.conf (thanks to remi@)- fix autoindex.conf to allow symlink to poweredby.png- suexec: use upstream version of patch for capability bit support- suexec: use syslog rather than suexec.log, drop dac_override capability- mod_ssl: add TLS NPN support (r1332643, #809599)- add BR on APR >= 1.4.0- use systemctl from logrotate (#221073)- pull from upstream: * use TLS close_notify alert for dummy_connection (r1326980+) * cleanup symbol exports (r1327036+)- rebuild- really fix restart- tweak default ssl.conf - fix restart handling (#814645) - use graceful restart by default- update to 2.4.2- fix macros- add _httpd_moddir to macros- fix symlink for poweredby.png - fix manual.conf- add mod_proxy_html subpackage (w/mod_proxy_html + mod_xml2enc) - move mod_ldap, mod_authnz_ldap to mod_ldap subpackage- clean docroot better - ship proxy, ssl directories within /var/cache/httpd - default config: * unrestricted access to (only) /var/www * remove (commented) Mutex, MaxRanges, ScriptSock * split autoindex config to conf.d/autoindex.conf - ship additional example configs in docdir- update to 2.4.1 - adopt upstream default httpd.conf (almost verbatim) - split all LoadModules to conf.modules.d/*.conf - include conf.d/*.conf at end of httpd.conf - trim %changelog- fix build against PCRE 8.30- update to 2.2.22- Rebuild against PCRE 8.30- fix #783629 - start httpd after named- complete conversion to systemd, drop init script (#770311) - fix comments in /etc/sysconfig/httpd (#771024) - enable PrivateTmp in service file (#781440) - set LANG=C in /etc/sysconfig/httpd- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- fix #751591 - start httpd after remote-fs- allow change state of BalancerMember in mod_proxy_balancer web interface- Make mmn available as %{_httpd_mmn}. - Add .svgz to AddEncoding x-gzip example in httpd.conf.- update to 2.2.21- update to 2.2.20 - fix MPM stub man page generation- fix #707917 - add httpd-ssl-pass-dialog to ask for SSL password using systemd- rebuild while rpm-4.9.1 is untagged to remove trailing slash in provided directory names- fix #716621 - suexec now works without setuid bit- fix #689091 - backported patch from 2.3 branch to support IPv6 in logresolve- update to 2.2.19 - enable dbd, authn_dbd in default config- fix path expansion in service files- add systemd service files (#684175, thanks to Jóhann B. Guðmundsson)- minor updates to httpd.conf - drop old patches- rebuild- use arch-specific mmn- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- generate dummy mod_ssl cert with CA:FALSE constraint (#667841) - add man page stubs for httpd.event, httpd.worker - drop distcache support - add STOP_TIMEOUT support to init script- update default SSLCipherSuite per upstream trunk- fix requires (#667397)- de-ghost /var/run/httpd- add tmpfiles.d configuration, ghost /var/run/httpd (#656600)- drop setuid bit, use capabilities for suexec binary- update to 2.2.17- link everything using -z relro and -z now- update to 2.2.16- default config tweaks: * harden httpd.conf w.r.t. .htaccess restriction (#591293) * load mod_substitute, mod_version by default * drop proxy_ajp.conf, load mod_proxy_ajp in httpd.conf * add commented list of shipped-but-unloaded modules * bump up worker defaults a little * drop KeepAliveTimeout to 5 secs per upstream - fix LSB compliance in init script (#522074) - bundle NOTICE in -tools - use init script in logrotate postrotate to pick up PIDFILE - drop some old Obsoletes/Conflicts- update to 2.2.15 (#572404, #579311)2.4.6-97.sl7_9.52.4.6-97.sl7_9.501-ldap.confmod_authnz_ldap.somod_ldap.so/etc/httpd/conf.modules.d//usr/lib64/httpd/modules/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu?7zXZ !Xۢw] crv(vX0柨RJcY4E63K8hsB9MW]o;.T7$Vf7r#V o~Sa2wOK =!*/3j|27`ZIjq'tΡ(AH^2 fZ? =΢Ν;!ffP8+-gxCfA~XZ!Uh} l͒V6P>-ik-J*w8 ~E ` - eon +C#*я,OK˸h ڗ?7],dD^m Zx}uCVA=Їn.+'QDӠUR^a &QTB1S`m6nNb \u}Kvq N&6|>ݻڻibQN*tk8)۸ë|^2xvũCCb ף+ ӧ4ˬ*,7?#,ؽ̧87LcİccT݇{q+_q Q%'@:afèf֧+t1/!Nt/ ,+L=VuF>ӈR%k_;AmF4PRrM b ܅A$z]v ɨOr9kׅP'd߷l=R y3P-gX \RwXEb9,:1eoxXG?!&9k< .Qr"1KEOV^41@6̀.qܱjzsEn=>]LbWr_ߒލf'V==iT 99>taPu,ΧHWAOS4uc NSe鸲/@>7Mc^E,2SH :?t~tY3oݬ'Y{f+fΝ6K(QӒ#ByDw̓uwr6p+!h<*NglnOHkǀ>s R&xhM$Y}T@{b| z)j:`FϗBVoK*Yd ABϋdEIultD?&ڼ[MWXMRcTp#ؑܯ #O XM,lFHH2 &le׮: 2h ֘Ұ*^OP SUEasB<"li$cK'JzeȢ~)k-c|cn7HkD4Olr聥!<"0W]Gj| _QIt/PSw{#s8Z5U?WP9Z[Ȭ4c(#p1T4kC3kJ!4~Ŧ%zyiM+ue!`9O^ ct۵ókj&Uۏ*gIuИO1G0mKa W8fc@'XRhNmԢcYv yU0ew(oz ZE4B ƠPk[ۏj &K#LFthNxbyNxshpSN퓃΃ycladHu`s\s2(į~K  [P.?bqXoe:/?HΛe2}1Y?_l]Whoxu@Ln{ΙL|S:?n Y6sJ E]@7."\$3r+[W˒ЛJZKB}m[6xPi#ޘ2ҴHҸUotc=뭩eL&11m{5/HH<㈞޾4 Xnx!K.1iHuVGSߎ''W >Hx+by_(|ǓMh̺=v&=r˃-PcWRҳPɃ\Ez騼6!dxN$=گyb^i vIMH$&o8`>R[GxzArjzgc%5XXលn#pp<xЎ9M 8 6OsӎrR_rPo[2YWg:c~Lg.)RM5ͨ@Ն [[l)/"Q[; ·SlaaMnMYM3% *xMZ{T=!}J<7F#"/׬㪕p\8<@x1, `.D^LC/]?J޶A'>t2S2,ycQNbTPC bm|5|88hH)-M3n<!+1Zc2PCP\サ0%0 sg5@A߆sUc/CfZɷڜi  lմ[-sYV'H-D]%}7E 4l5m3_S]9toDƎPI|/G;pRġ#J0(,f٧ p3vO$nx˻"(096BSe)u^Q#ˇebw ~- LW64 r>1^zr;:2VTj I3 ZDp$ҠcM $*G(6uU>sO }A%%Ȭ&6, s@hbՄB~n/*yGS#uDQ⬎zЪӏ42cN LJQl6YkY]R1 VԘ>w=D6cYwMLմo)Ēmgӣ]6] odqބD |EZ|+*FZs2TQiI8ckQh@/M~^듕`V7,bLADTRb@il/rGESs"&5pS7vi5p<g[leŝ9hZv!=ª1RA`+&g+)ZL搸S2X{,dZ\K|z8ۃG= 7ҿ_g ހX (thJíH_T9ȹ8rLIrWgH|iEC0]n޷ Dg0ҝmw1R 7bPfd^WC0etoB_jFTY8}cZ${Ԛ>lanb3]yЋc_\ <"6*4iNQ u,=xB۫u>I/% $nWR@nGG-:@EilJBL`w_aT9 ;`a21f!or(SbKgf=1E$uKPPZS=)`ߧD4 U>`j啯pTct.jfF`f+hQɏ2 9~fi{D̀foЙn .Rɠ0(b$an=-ȎG#bW>c뱪/wtNjWfQzD(EcE(OnK[XGsZ?hVGڌmJ-2X 'TEքΗF g]O07zWb%eŌQtM ՛844HUfi>>W&,&xٶ} 5-*j{} \5a5K)]jrgTE @%( xkZX}{ٖ I[XʑpыR ˯_*:NP, ˝ !(Rvw\jVvb}M)$NeZ87n& V=dK v*כ~XӳJ+2ٓQk%A{po2v35 8LKV(qéQw?QXl#IWZ0M͠mUqbs}92*L])6'^76жLGńvjC 3u~5kD;;';Yh=:ՠ%D1贍:7iVN% VmoLn.!!ahd27js?,z@[)9ɸ}gֲ%Q7;+KD()$RCFVe}BD^b!BQFNGxeQhz$u<ҕ+•d')9<D5S#/ĜHm!^.ɭc$rD skG/PpQy6X7j"[%_P2l d> ŏ `%$sƹB/ztNjr[N4Ri{%HC?#D$K롑Xƫjjp#ׇ/i}]{} A4Ǭ N'=㓁/?ZyLٶjUj*Q 98{tA+ҴVyaI<ؙԍkɈĹnrcv]ca["է?5k %(궒 &m![&ױkfS~0;t-ydn z0q˒U-EQlNSf_DtQ ݣZ _ DŽ&g7RL I\DkŦuLH`s:Yƌ%6CJ0 l \*uBFQ }vElnzZoVSt.|qeY"c;gmyVJ?VPbCL(Fasw??`P+9e30ڨM6]o4YeSE‮&g, 3ѴB*c=Fs;,_$%jn>CYo ɻgz&:ѩ3/krupݛ_RrHqngD}&U&>ӿlAWou[UQv7. tqT-s6>:^XْT Z7>~i&X45֧gx#kU+莨<&0;yũj4O 0[/Q%$w,@)甊D6txל7 ㌇0<˿:EVxp, A. _^2U^ݮ%:$Vuk.fF$`~7-Yxt^eXG!)%_Spq0]K *swY50 5en}P %R"@/CT"9bwmMtZ`^C`!sj-߭^qGxav3s& ZCGY~qMI|,`.$3eO0/i*(cNm ChWT hG"AI p[˜'黖OphJwYcWASurz]aeگ5?&7&Dm=xbC=&b[(n&Eb&6H5e%_] URa { C9<-'N;T*_uS"elsp}8 lM}Cٶl&^Bt1M.J4l$877AU:JώD` M~{yP|; ?iN]*~Y a>4U؛5(-0#XcZ lE\nZ+<{,GH-wXmy)Y Ś*J epԵ-(0a)bE%Dmz;=We{GZ\+\~}qe3o/t{O3U~V{.'rK/NY<"؁ҋ /( |cKBL Z߲YogO`AMt';qaZF H!h'aF~Fuާp3-Ҋ]FP{*!B!Ƥܨ##%SSݟE[o5 UTi\sjp)P{yPeh}%FĐ!`J@YVaL9č 4k޴>cl4W^kEZ8F eyZ ‚'å+UߪQa& ʐznLy|(mV))`LjNgI3ZVL{R#)ps/c`Rǁcu8͚6wBj=qhXBjlYzQ0N40DI-B#-VZWj@y-9z6o,ޞUwp*X}TJyS1Mj gi i4>N\n<}y`mR"W<3pg%Q|4YwoK΢#88@tBĶel?b< {:N$ʯZDceD0RF2Izṿ rWf].S Ѓ{c6אDiЏ[Sْ^j3#};&TWڿ b 1`AFY[-AVlp%:b,(qɕq#=]>&@+7GNy _̝y0gdp7jC(4Xj=O\k r]`j#p-F]9lhDRFn `+(D{) C-u5^AbzZIUz=ƅP1v[!ԚWҀ/i_QWT+R-YwZMKlЉx46s/6ưTݳԕ`7W%˝D 1tPpĨ*RZvY-YD<\@U{Xn칵Ʋ?]NN-be6 1& 뫪}ȶb4X^lwv #4H&%\Ȥ6ܽ5uȹ@衺'f^ָ.GLS'gSFtmgu85P?:s-rUX"3㓋(n~i `!27A; FTC2_54f5o=!sT ZG@:߆]fKe SƷ/fa4G/H]M#I:N_`Q3yD4Q2߹pXr4(3'WTdP";E04\۝4%͍d^zaz+fȣ+a\?(=#f=._1is _=/ϯ}>ؙ⃱Zg,xO)>鄈_1+@[|n4;7F_t @9J-ڕa;f/7<131jCC;tM*k bק 9I>6͜&wwh,H}'*^a>Fé&DOE"*0Ɖd(s8bi5$#jD+ٓ@]^kl731Xoq2P!uwYfW.,L)#Km?_r} aQY*|ZtTX^ ?rc/O7nT0tKT`Zz;UX2 `Ĵg9\`A}s`~NQoS J\Ȁ5NSy(hq%d G&u#51Vf\(c@o{M `q^cK^<?trc|ެhxj{-=KNE*B'2% wB'D ̐vB}o>n*ꙂW?Q:C̾dP!?3ɏN~#xD69@^0S74FS+UJ㨫t~1< tt'?;B 泩c5<¸?WJ!6ԏ]>Asipd:;Ea%(EHrNs"ۋ_dhg-l>bOcZϻ1J0=<k:𻅳tx:QOfUv%&_&FR=%[εS d@Mi? 1|Qz7mbf#Ki֋ T$N=( #S!BNpɠ~EtsLXݹ{t‡m`{ph6ZAwn:m"ootb TC_$!AӒsDZ7嫧x-ƾ3Evxνc1}k|c'gҋC>فI?ŵNz ل/&ú"GOF`<([qll">?(U/(yw"!cuFEŐfN: k3dkp*ML1јz­&`WYmeQC фh/pN(K'oro"nZdZ|;0ՍE4D%?.kY,Ͱy`ArWG4X[5Om AWXurY zatH7x37, kzD!E{X%dA! uL+"ȴD@#] sC(|?Cp*sXJEtVNsWx' YwL坭1 e5<"E Lb?^n,ܑ@26-āSMȩ0'|VT:XpL! 4jE88H:Y\M–F Z=ZH O]1DwE <84J1'^qk>%!BKjxZ0Ǩ \^o4 e%0{#lńH OW Mg}H;?}W#ʾMU*= KY%{rf}A}d 1myE cU}ئO?.G~ƕKe*k.+@hDgz :Ka3 j),:vjrz ! 8INJeDuB{0ě1i1ci"^df0zʃ??{9˳E0>6LÀa< Jp%oxz&PS AWmuD l ;Yܨ F&,>^Fdhzժ1V)sDΕκ$ڊ݌xV_)%`_"A+w0!nSUy-fnz͋ub*߳IBLYe%4 ͅAiYZszHѨRI1FKlQlT"7`S؃=qG؎ &-/0) g8V탳o4d'崩$K'WcUg<S"LԒCEЕ`@މ=#=~[DqIV]> qtNyiΐ' ツ 3}`EYb!=fCTZ=+]a  ,P~$H9R5}AF0f;E_ d+u<g71 [;6xI P ]U =7),tR0oĜDMho];g(xmp,g5!z.d<8惧|=uյf؀y$i4 ?k-v+\qnK/\h$H&MJ@?Ρ$ l]7䦏bIX ̋x4.-#|Iz"c_: [Z5#"_ҍ@@/ fx24E9gz ~tf|o~CKzO([|Q s:i7EpqN 0]E Ga*]jЪL8U/i˄NV=ww tHT;`_geq xZ'!:w('ctp0 4E"!~MO  ( u<":fʇGwm=4nu¿7MǾn!0,b17Џ(_2z 3L d@QEihMr,g]%IGjv6s l?!0L{,GXf7{4tXZ:1ŷw[ 0D<2s})R`39^P8*ֶu] OH/T{en}'w)싯NWT:e!V''2!t(NLsBd[biFU~U\Q7hD)qdEW4B_Q; 5t,CORbo 3-[oXpo2Ǥ[2uqƴ0%͋,Rg&>r=+n' `ѣqTV G#[V5V p֮qo!?A HOв'|%.ܻj;6Xb=|G/y]cp9`7޿P*j[SŧWY(^e7 r*'p$(!ơh_^~]L~U@fBrxߕ{d K3(Q~&}3fp<U$ـY]gb:%mf]:Q:B{I &\kMA\¬,=Vl015#EV<ɶ_>Jߝ;>Lʴy &ܒڏAP3Ou,|2)̗eL]|:+#CdvJg5|P0V)_#j/!qhvmnwdf,q Pj><y<%t$i*3GWnpJ(۱sa$X?H Po@ Ë6w3p{P ^y|T׵"wTZI֕6edx̟9 uMK7G++6\Ű8P\o=ZMlyjDu6bfe9_, apTfiǓ.!nk,symn6M<3񧋓ا Fb|tsا:p4y%x@1M\ÀwG&,xfn̈kE?í̹H0S@ Þ3.s^F1(V; d 082:#<œ8G&s@!WؾT--0g e܃cA:1X4sgn!)-Rr2t !.mHt*낤RZDwM0ߝUʆʃ|Ldi5V!/pӂE˪Ɣc^bi*Bi㴥J:y͝<8|_DUR's$<4obd#Fjx@ajldzCIl6z"+CYqvUfRH_HH}G;vUUT#SZu:Jm1.!Z˱hwCfp5ٻvo0j;|i9Xu<'^ Gs=̎cF'dIݑ?ZC cr1"4{ w^PY!p:޴rBL:˿:MWG #ٜʎm_ZnI=uXk1$r/ƹ2+ō4 -y>&=_o bZg@qjYߠ"Bygs0^ef=?fը73TiVↆMmzግ8ptE?Y|)4Z`ܷrGp3˸4wڸf&D[FDYRe<>0}{ {x4A%]G Zu]gtOo S;b"9/PQ[1 Xn<- S1\}G՞rW#dۦ,L@)QhQ\1_f 2ʦaqWʯGPh< ?_8AqQ__kSu|IPW4e¬lw_"L_<0:wݹh[E$~IrO>Hm{^ZiF{}N7eL WCͶ6{NnZi,C5U*Ek",oM[sC.P@ r8mΆpLcjO{T_=xOuTJ%TAN*UƹQԔԤ'q aŐV-piT^F\k(# HW.lw;$ŇހЇőQUg\Ct5I|b㰌~@ շ:dZ@TŖ Q>5uh4`]ߐ=oL}xp4ڑs_ |kc 㜛>o砉d=uE||;ZA.~[2RUEi"u*J,`R~sF9z9yաq,7'wU>w5fo&cmlo^N2y~}&la/Nm>&.nMRU ,6IީIފt(_*gAl-p hjK‘.+ t44E֩#{FLby\EM$6-ڗb>RjWnv];c`hTɠG  Z5)=#AB덂IU睬+ wV=UĘe=V4pCמ/G~8 &FʹQEϕa#Oɾrd$1A”;:,l=׈N{ס wvl}c*NG4wT(nCQ_L)?·@դpL/4ŀ] ,hb,{ j ߳)cG =L*(fɖ]%5 0}{gg`[wc Pvb7 5c3'ts)ft. *EZ]Ԏw&3'&*ͩR%gw4ğ3r淾B"̓x=;aT4Qq8wT$}:;\~$hcD< +9)]b䤀!  OǍm;Fl24 %fWհ`:ea8:u,H7)EyTL5Cظ5]DyUŊ l;&e d~_!kםX })- !5D(,Acm8M%.Y+&CʩTrEj 8vV r2kA< sѶ)g-/Y"CV]i_z I>0vnjrK~wmΊ0|͆yO&V\lcOtV嘍So~9%]5Qtzۿ.&1Z|2;#D K-cVP@"6O|IsF%7+(6xW;ۅgKQ($ؐqG~' Skx^~ÏӜ"Ȋ" )$,4}D8 5bd gu89`^?/lד2aP8qsb,߱P>} ؂GZ,DAfC'莂 'MQЮˊѿ|5FKWod VU~B7 %HA0}XfɡjVB/l(wxH_ܢK;8gd%{d8#fJGt_dD8E9 ;2_ ~ >j SWF:S D8(ƥ):2] |OUZKXp^ݶh,+sMF%]>cY%g/pD 5\aHAJ@|R;9XPAZwށڨK'+Np9h O?Aj6~?loo6H[-%;zq0-4VeUǭU߹DE̶Z]Kڧ(UҘr;T}-.}3o-@;#sյ[cs3V<;QSy)rv@Vk2ݽv&OZnqoTR[o )ӷhƴj 1tOlm͛2:$%,R==% KUv ^ݘ,êJ4SX2ujKJm۾hȟri{3- Z/lu(&&|]kz#>Pz}X@yPO~Ke -JaraM.y2Ԁg蹎a1K\WČ@sQ. q??7_ֲF %D K8=hn Fas+/eKEUXtnOˆ&h<-c16X0V`6ɘD5(uJ5j# Ƕ$NLPTJF0oQN1I\x8]k̃XyQEqYKVHLu?ǜxrJ;M90N~H-R~U BVV/c0k<,!h‚@ʊ*ua{%{uoQ/g۸ 0e(p*l#R@oX-3Xd04]':LeAk2=aOD˻j>v;MTs;j2xD~:YmjLۦΞ.8wޡg_q3$֛dQ>R.E/%#i2ϛzLذ6GUn.0q~4oꄛ91>j[A Zً}cO_ 7CΠOO"}Xrhj pVm&0H͒K$jIp\K РLey׿n3J $`ıD܍ $W-ooHfiSbΈ>ި6'6`=YUAI3s!K5QuU3_ppPi&bSԱݤ+BBzBUdt7^O 'pt[WC*Y2KCCzS}F 2:C #*`A In=]gVQ@9Irr`,װP+h8Sb;f@}"Ih0P|j#@&iLh%!#i7NJm&Ek;]=w_gT<D1t@vgFM,,M)r%0^no>J0u<(~;&P!O+VXM(,=tDBHR)J QPp9>XqLfZl6Uљ?]4rw4Z(b# 1.vJB6"e|2=w]_(aJ_u3Xy7&#- X_q w(ζ9##+2,y~dz5i 蜉yH7-^?69& 4>3xPԊ+ճRWN&%: mCx9mlW`w!xx{Fzf\_s<3jm*pIi>:Anr1"di'}<0Z+"Gjȅix?`z`u]EUEuлGFh $XE4#L̶jxxTuѷ_vL HSp(#En=)FLJ4=HSԌ[,`hBzWNwn[.) #~-ˆ]{> 96Ws@vĔ#pcsN=gaG4庬vtLR%_t]\ϟ/^ș2e=' YE!T\RPDUV^f#(Aԫ~r%!>x=~bfҒ מlqix2=P"2*{0`^NC?]] (|E-w\bdt*Х4pgblr됷-d(z,!3iI(s3ע@^tw<_듼z=&ichj/0BWqpܓw^JƋ:o|S@9bDy!؋\|1/lG5G~ p#:^%4E;B}l]m 7-/GWIQx"%1# HFw;?+/ `)LXv|0m"3fKYU Tر͢dWM͢fz< Z=vӤoљ25h &EsQCk$i6ev1CޞI@,Ԍ(kF}x 0H8d b=yg4tȜ+;ojqvcQe# J7!Nl67ڹtQbzJAhHL1T1ׇ-K.G/S9 WNH#FQ}L'XX>pwI(r4b+ mJ^@s X̖MP'[_E,,nshK<9)A3)p+s )}^z7Cb{:!6\i@ W-W@d5bTZmq٬fj+BTҔ}[O6$6Ig!Ru"Ade)˛\at2'*%DVRƼu~p2'`(n7ЊPwIx<(L3xquګ6(nYL>+!sa 1P;]q]Ȇv]r>:B #r|ƥ'bJH{ZN74t ,/svf ;08R8mȢdMtdd"@M=Rê)C埼f@q7TJ0F 0> s 蜐 >:$Cy̙|Gz1b:Uэ8+-x( O0`0*E)G9әo ٫,S P>?ƻĐ zƨl}GF<ɩH~W <&h޾)dYW?[Hj̙z:̭v}&0[c3و2+~iy)װ)r2ޥ(mbT$n؋iz0֍H38_NGHor ;$6YlHe  6`h; @Z(5ٓNEg²'4:%GBiZ~@Iv i#DƣYLZH!xM'=A/ϜphPj8ϔ/c pq n}sue0N7B?A˶rxJ;m.AL|3feHD/TT_am?* }I&7,#S~ʯDMŸOt^Xwésb;=s.D#9&ŘdjߋΙq8 (Tx =I_hLYs[-eO&5INZ*SlyqOOL0i+?gsL񦃷e$٭K_1Mf¦6+2&W%{a谩k[M6t5ʳ>I:kѶA ZejMt'- WqudjV)V}=^AO ֥^ {G|4.-Q:z:mk5>bC;/U'K%kzL}}F +aDZo:M`nTמKBM(E8˄Z^7N;Gq & u4M5[8^ɐuԣlC2)b<䦾k`>qC aNKr X6[6Qt{G+}CP"a= KacCrETΡ;No5T۳4 [=7&]-ו*h r=QTƞar.Tm'3ePB}Dl$4w8Ů:kߍ; =ƙKc $|[K{ i.TIzxBE~G%zgBvS4U/)),t#gq 9vU*<-ʼQQ3>T FR#@rW^L%fc3(<9$"@xܦPӤMI,/DOeZоix-݇y"z%DX_@F)|!r~% 5P+Ӊz!YD> ^>zs5\Ka+$_zq!#ma5?p5}Q:Sӆ)t1g4WB/aNllaN_9J{$JvKX޷tSO<h,ʓf|jay:_tiG&i*t|0!kC!KcFqC0üރATilVz|e%vS"-a`X TF^4dនQvF Hr=n sd6asu*W}F0.#u=jzex˘RctzGULua6p0ʽ#?u4 l_/9bpWaLPS4.dz :\Рu:lA<=x @3nv}~MC3vЋ{d0]z0ilsB@||")T.Bs_v_2¶?roƋ+i4~j|N~b?p0b#lR(CѥfXwXMQsTyt>{}0tn>}k@/j _:>sՊ>:aprdx<ѹ[דaT/(9u}Z;2`7my몝L5s dk A8MW>ڱF']fnq CG Qcg} 2ۤ@bwMًVʽh!kn*MpPVv-Ĭ<6Iq/#6d_ eЪO̠d!*C%9aW9J c'N`~ݲYs0 {Ab&lCgExEG'֦(pG=Kc$Qk:?2|hkzI1ZE?3yZօX<[9cx;kK$ x:9GHw_peSX>@k7xv9gڗl^ŷAbM=%KXQFwɃ"w@>.~xyO){!\-b'Z/24䜬[B%Y@E.Ey].VO£乨5 ;g=gv+udH.Ot&bv?l_]5+nR/h4yZfmfV!${zDCGgٙ w%8Gq[u/1t':Wȶޱ6;ai' -?.˖x >6}d29K?REQ8H'v;9öo$j /JEl(PԪB\xUb][6F 4o,/N̬ItudgEVlڊ%s [lM~4k/Duwa%vƎ"(!1+aUoġK@`/W95!;YB&b@i=i㱾jތKbfo^"2TGmRPiVmu>y sT2lat hDLҚNF)nHms۾֭>Qa9ڦH)+x >*d쵐@(?,vǗuGBOä G:2 jW 'vpYFօR30KB2 }&lOm9[2KԶWko쇆HQ>ǟ#??,T9[F TYrI]B~y2C^2J]Ӕ_ 'E^j--sTr^q Lȱ'sȎI 81HbE'!H;. 9GN"G]F3ꕻ+  Kyo;OXs[V1"e~k\dJM3MưD}y(-Ν0VjkfٚRA{7~3f?kS/wACly+ % :Ȳn Yy@WN钜%H4{:E~֒]a#}g&%[ٲz&}@hV2lmV=s`@' `AƯn5xɫ(89Vksnqjtp9(oly(=Xخe¶5Js'6$Fzn,*NKQ4|XבQ<=96J9Sw3=꺌'$U=H48&w$(5ܣ0+-'^ b.>ؒ?{<'oJaxbYRq={@K|;^̭P绶 <',uԥAW!PJ߅ .@ԒH< g/!PeAcp+Q"{UةʑdH%Uhji6(a(k"j1_=N_Lfpsu5%aF>l02G[kOc-g. c /1:f!1UVu\[aHhVxk締f0UaA'r?\5U!΢Pޓk4IGёE9qȡhf le Tα̵p)ިFs)a;hS-ш\X .(J’MF:0l׵/<> X(LU\Ƀ<DNE'9oMd?.cB"@ר`AIGmhWe4NF8kTXh]M,MGqzv J[n-Xyf42)*դ!؉GCϜ!iKlf@0 P- ޱ!B$y /|>aroA,0Obо,_+*'xj(~ ,~KLdּLM6eOTuЀ˱U\WR7l(} 7-soU\tJ ഍>}ŬoV応JnNqx/E,MuY==t6PuJ`;lORoϥndޓ0$E^iz-Yܷ{òUZ&$ Rnd˄{\V rL `"]/ H:}j2@~Ds{asI[0gF @+0\͒:w8D?)C`ZQ'ͺLfVlx|{E3: !#D.h Խ d_R12Rznbhm R$Ƹ2rtF s74>\'k KSoH\KZE/%[ Zh+ie6xylbx:ZnEl^.< TXXȻD%iGc抄?<hD$㣘dyx-H҃Fr9L (@\9D^u>#j{H]#HlS!o;MmgJbPQ`T {A:z#t *upX04'{@ p9jmS3]kڤ=rzʡY6kr9ʒAuRvmAŪg@o^ݒϤ?,cf"JxlWX)g}zm:ԝ^۪c 1صճ5V ~ Giv{D Ҩ Bz"K@#hѷDdy;sw*..ԃ\p=B<7S7u mŋVLʸ(ܩF kEA@ );v5CD)F LЫZӈׄL!-MQa7#3M |+7%A€\%s4qE4◑3kp4ɒ&8j mtib!_0"QZUBSr`{qy\(Ce S1g BcOΞEqƿH >9UFӹ>J\P1cƨɷ8}Α.GD&}Ⱦ BϤ:y!'I YhKA*BnQf\^8AR㻭\/TC侵%Ɵxɳ](s ~igc٢h!4g#-w!po_$ w{ If|ӛB5vQ)X Yw~O rȄcZǜB@4ϡƼ9TīǣvM'(,:e<, c^֊U`5鿖<0b D΍;E9Z~-`d>Q?* R;eқʗRѵzsF;`)pjHމ#T|-69OL3Gq:>z>wD2=d7MF4[^+ 0CVKb `|:Eq΍J&D\s0Y{sdD8_&@qf z%q~l(Ӻ3(UBJfMqRw6rGy$ĝ`j`0IǕݢ>aev\he쵹.T6cr`mCZXWIuӸB?i v#ݺQt)ڰiU,C.s어VΫPz ji=L%pdRh_^$z1[H˂'R2wyL9.Ha,t0 nB#<}/p Hpk*()QVo2)$hsPů !?SAY z_gFYޘJ^K: Eh`؄8%~ho' 2{zsx.=wWsYh qS$X{xvT E >K NDzqDe,mPSͳR(|YIQeT@ BVXO0D,P[Vқwŝx: AS/[ܘ(t5"?WɎ:&lVo:kzϰ!Cְg9h40 ';04sV[.82 C +զX MQH̸9{kjJxIG ;DJ }z&Z0 D4,^\$gs:u.֦8MRn!ċ,VLs|5p@"o_'1 77Yh;R)33Xx uSq*=+Α}wT_C{ټ5c?؉SJ{].{\)K?Ÿfh,I2>p80o(!URVPaEM7J0ː7S p'@2\IjPD^פf1GAF, pWt#G(ľ^`ƑC5o; ~"ɀ,O*HDJ! IpXrwJ<;=F- K:p;yuó YU1/ئFE&(FєD>\emqy4k&Y+p殍-Ka*: UEDūuY5<*K*(B)?1oy72ҜَArNo4?:w ,rXUq;x3g3'C9k] 46/JT:PF٩谫\[E;|Z g(2`ӹi%d/gU;25gpG+y.V[Y-eTD*L0!t9#Z1|b ?1 M dĈ0MM{ sȅbSe0h$ELn9v[-g !zL"|2I]u_蓲?L#Up9B9@|;3d%jVB,YSJ{\sGx/iKm,T?TF}[1݄~x=ש A4]ـ3rvg6uGa=0;Wjfm}|V(Kdbי./JDHs=ѭy.%N'BN֔k@TX(LBʥt:4Ũ`~=$R@sϭCpIy_(Z@ŏ>ۇ"U_RYIC9ЧiZԴ˗ v'iw؎xqog4#T9YlRq`Gy֊빃Z:]謾* 9^Vl6ϭ1׀VDzB+%Y$ <'SDo#LKGw)0,\'w FnkoJ-Hqkz26Q`]{﬷ivl $o_%~mdPi<7)ab rHSP@(gr (o7n֏p~m#wÛZpl.8ʔej͂"9zpNqp T,|v4K٦dd``"U@IH/{bo2<C̱\hWVQjT]ֿGG&[E%.OY4chY[gCH ̋!XRANy 9)<)I`R~)7`L_LzF(p#iPȔ`l@]0U;?-tG۰g ض8F4rk.̒X&4QZ0lcVR԰d{Օ(hTݝ+ '_֬͢Xt}Z s!qjp S/vB&mbH 8~BI|·kb+8SdAk9XuvfƦlsL%J@&B`a*M: oS&mtzMs{ӼRp\1&&6<ӋL;f2@'FgZNj>uc WPxolF/,ķhkѡC" WP9*ނ=ͶtՓ<π6VofAlwT !2-\t\R)dfz9xӈTWۄh(Xcvx~;$`.l`mEtf)#ApiwLՎ%q$e K[6s} 5piؙj"]<*9A(3{hO^Z6fM} "٥La'n2z" ]~rKKUS 8]'4&:ǂc @F3^P ~*/:VuWɐL2H7rCi+FIZoܵ$$BX:;Ae[P"Ί ]'Ha궩Jy7>ӝTq&7SJo.$ WRɞSǝ"D +3T;ῦuDn^ KHX8j2Y'҇'e+A5&,\Yo[gQ.?a+v8+ Kӕr+怤Xcr1<R)ud13"-[3^*7')hU]Xqg٠]b폇M|l8FD|hG SΉV#v5G<"2t勵tQֶ YZ