mod_session-2.4.6-97.sl7_9.5> H HtxHFb< ?*}}{J z\ PM`+i; mk-8RI,B688af3a107a3a8ef3c50774c3f4933b4334d10bbL,D)s3!,ӈFb< ?*}}49 es"K[A˹HU-+Q}>3{|?{ld  L :SY`x    . 4LjJ(89:*OGyHyIyXyYy\y]z^zwbzd{Ce{Hf{Kl{M{hCmod_session2.4.697.sl7_9.5Session interface for the Apache HTTP ServerThe mod_session module and associated backends provide an abstract interface for storing and accessing per-user session data.bMMn1@MdMRMF@M(QM$]@M$]@M# L@L@LLMxL7@K@Scientific Linux Auto Patch Process Luboš Uhliarik - 2.4.6-97.5Luboš Uhliarik - 2.4.6-97.4Luboš Uhliarik - 2.4.6-97.3Luboš Uhliarik - 2.4.6-97.2Luboš Uhliarik - 2.4.6-97.1Lubos Uhliarik - 2.4.6-97Lubos Uhliarik - 2.4.6-95Lubos Uhliarik - 2.4.6-94Lubos Uhliarik - 2.4.6-93Joe Orton - 2.4.6-92Lubos Uhliarik - 2.4.6-91Lubos Uhliarik - 2.4.6-90Joe Orton - 2.4.6-89Luboš Uhliarik - 2.4.6-88Luboš Uhliarik - 2.4.6-87Luboš Uhliarik - 2.4.6-86Luboš Uhliarik - 2.4.6-85Luboš Uhliarik - 2.4.6-84Luboš Uhliarik - 2.4.6-83Luboš Uhliarik - 2.4.6-82Joe Orton - 2.4.6-81Luboš Uhliarik - 2.4.6-80Luboš Uhliarik - 2.4.6-79Luboš Uhliarik - 2.4.6-78Luboš Uhliarik - 2.4.6-77Luboš Uhliarik - 2.4.6-76Luboš Uhliarik - 2.4.6-75Luboš Uhliarik - 2.4.6-74Luboš Uhliarik - 2.4.6-73Luboš Uhliarik - 2.4.6-72Luboš Uhliarik - 2.4.6-71Luboš Uhliarik - 2.4.6-70Luboš Uhliarik - 2.4.6-69Luboš Uhliarik - 2.4.6-68Luboš Uhliarik - 2.4.6-67Luboš Uhliarik - 2.4.6-66Luboš Uhliarik - 2.4.6-65Luboš Uhliarik - 2.4.6-64Luboš Uhliarik - 2.4.6-63Luboš Uhliarik - 2.4.6-62Luboš Uhliarik - 2.4.6-61Luboš Uhliarik - 2.4.6-60Luboš Uhliarik - 2.4.6-59Luboš Uhliarik - 2.4.6-58Luboš Uhliarik - 2.4.6-57Luboš Uhliarik - 2.4.6-56Luboš Uhliarik - 2.4.6-55Luboš Uhliarik - 2.4.6-54Luboš Uhliarik - 2.4.6-53Luboš Uhliarik - 2.4.6-52Luboš Uhliarik - 2.4.6-51Luboš Uhliarik - 2.4.6-50Luboš Uhliarik - 2.4.6-49Luboš Uhliarik - 2.4.6-48Joe Orton - 2.4.6-47Luboš Uhliarik - 2.4.6-46Luboš Uhliarik - 2.4.6-45Joe Orton - 2.4.6-44Joe Orton - 2.4.6-43Joe Orton - 2.4.6-42Jan Kaluza - 2.4.6-41Jan Kaluza - 2.4.6-40Jan Kaluza - 2.4.6-39Jan Kaluza - 2.4.6-38Jan Kaluza - 2.4.6-37Jan Kaluza - 2.4.6-36Jan Kaluza - 2.4.6-35Jan Kaluza - 2.4.6-34Jan Kaluza - 2.4.6-33Jan Kaluza - 2.4.6-32Jan Kaluza - 2.4.6-31Jan Kaluza - 2.4.6-30Jan Kaluza - 2.4.6-29Jan Kaluza - 2.4.6-28Jan Kaluza - 2.4.6-27Jan Kaluza - 2.4.6-26Jan Kaluza - 2.4.6-25Jan Kaluza - 2.4.6-24Jan Kaluza - 2.4.6-23Jan Kaluza - 2.4.6-22Jan Kaluza - 2.4.6-21Jan Kaluza - 2.4.6-20Jan Kaluza - 2.4.6-19Jan Kaluza - 2.4.6-18Jan Kaluza - 2.4.6-17Joe Orton - 2.4.6-16Joe Orton - 2.4.6-15Daniel Mach - 2.4.6-14Joe Orton - 2.4.6-13Joe Orton - 2.4.6-12Joe Orton - 2.4.6-11Joe Orton - 2.4.6-10Daniel Mach - 2.4.6-9Joe Orton - 2.4.6-8Jan Kaluza - 2.4.6-7Jan Kaluza - 2.4.6-6Jan Kaluza - 2.4.6-5Jan Kaluza - 2.4.6-4Jan Kaluza - 2.4.6-3Jan Kaluza - 2.4.6-2Joe Orton - 2.4.6-1Jan Kaluza - 2.4.4-12Joe Orton - 2.4.4-11Joe Orton - 2.4.4-10Joe Orton - 2.4.4-9Jan Kaluza - 2.4.4-8Jan Kaluza - 2.4.4-6Jan Kaluza - 2.4.4-5Jan Kaluza - 2.4.4-4Jan Kaluza - 2.4.4-3Joe Orton - 2.4.4-2Joe Orton - 2.4.4-1Joe Orton - 2.4.3-17Fedora Release Engineering - 2.4.3-16Joe Orton - 2.4.3-15Joe Orton - 2.4.3-14Joe Orton - 2.4.3-13Joe Orton - 2.4.3-12Joe Orton - 2.4.3-11Joe Orton - 2.4.3-10Joe Orton - 2.4.3-9.1Joe Orton - 2.4.3-9Joe Orton - 2.4.3-8Joe Orton - 2.4.3-7Jan Kaluza - 2.4.3-6Joe Orton - 2.4.3-5Joe Orton - 2.4.3-4Jan Kaluza - 2.4.3-3Joe Orton - 2.4.3-2Joe Orton - 2.4.3-1Joe Orton - 2.4.2-23Fedora Release Engineering - 2.4.2-22Joe Orton - 2.4.2-21Joe Orton - 2.4.2-20Joe Orton - 2.4.2-19Joe Orton - 2.4.2-18Joe Orton - 2.4.2-17Joe Orton - 2.4.2-16Joe Orton - 2.4.2-15Joe Orton - 2.4.2-14Joe Orton - 2.4.2-13Joe Orton - 2.4.2-12Joe Orton - 2.4.2-11Joe Orton - 2.4.2-10Joe Orton - 2.4.2-9Joe Orton - 2.4.2-8Joe Orton - 2.4.2-7Joe Orton - 2.4.2-6Joe Orton - 2.4.2-5Joe Orton - 2.4.2-4Joe Orton - 2.4.2-3.2Joe Orton - 2.4.2-3Joe Orton - 2.4.2-2Jan Kaluza - 2.4.2-1Joe Orton - 2.4.1-6Joe Orton - 2.4.1-5Joe Orton - 2.4.1-4Joe Orton - 2.4.1-3Joe Orton - 2.4.1-2Joe Orton - 2.4.1-1Joe Orton - 2.2.22-2Joe Orton - 2.2.22-1Petr Pisar - 2.2.21-8Jan Kaluza - 2.2.21-7Joe Orton - 2.2.21-6Fedora Release Engineering - 2.2.21-5Jan Kaluza - 2.2.21-4Jan Kaluza - 2.2.21-3Ville Skyttä - 2.2.21-2Joe Orton - 2.2.21-1Joe Orton - 2.2.20-1Jan Kaluza - 2.2.19-5Iain Arnell 1:2.2.19-4Jan Kaluza - 2.2.19-3Jan Kaluza - 2.2.19-2Joe Orton - 2.2.19-1Joe Orton - 2.2.17-13Joe Orton - 2.2.17-12Joe Orton - 2.2.17-11Joe Orton - 2.2.17-10Joe Orton - 2.2.17-9Fedora Release Engineering - 2.2.17-8Joe Orton - 2.2.17-7Joe Orton - 2.2.17-6Joe Orton - 2.2.17-5Joe Orton - 2.2.17-4Joe Orton - 2.2.17-3Joe Orton - 2.2.17-2Joe Orton - 2.2.17-1Joe Orton - 2.2.16-2Joe Orton - 2.2.16-1Joe Orton - 2.2.15-3Robert Scheck - 2.2.15-1- Added Source: httpd-sl_index.html.sl.patch --> This patch removes TUV branding from the default index.html - Added Source: httpd-spec_sl_index.html.sl7.patch --> The index.html file is outside of the source tarball, so we need to patch it in the install step - Added Source: httpd.ini --> Config file for automated patch script- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via malformed requests - Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in ap_escape_quotes() via malicious input - Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow when parsing multipart content- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted request uri-path containing "unix:"- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending a client cert to backend server - Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout - Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool concurrency issues- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value- Resolves: #1565491 - CVE-2017-15715 httpd: bypass with a trailing newline in the file name - Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect - Resolves: #1724879 - httpd terminates all SSL connections using an abortive shutdown - Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive - Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause a denial of service - Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect expiry time- htpasswd: add SHA-2 crypt() support (#1486889)- Resolves: #1630886 - scriptlet can fail if hostname is not installed - Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in mod_authnz_ldap when using too small Accept-Language values - Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after failure in reading the HTTP request - Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch directive - Resolves: #1633152 - mod_session missing apr-util-openssl - Resolves: #1649470 - httpd response contains garbage in Content-Type header - Resolves: #1724034 - Unexpected OCSP in proxy SSL connection- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation in mod_auth_digest - Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control bypass due to race condition - Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency- fix per-request leak of bucket brigade structure (#1583218)- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple SIGUSR1- Resolves: #1458364 - RMM list corruption in ldap module results in server hang- Resolves: #1493181 - RFE: mod_ssl: allow sending multiple CA names which differ only in case- Resolves: #1556761 - mod_proxy_wstunned config needs the default port number- Resolves: #1548501 - Make OCSP more configurable (like CRL)- Resolves: #1523536 - Backport Apache BZ#59230 mod_proxy_express uses db after close- Resolves: #1533793 - Use Variable with mod_authnz_ldap- don't terminate connections during graceful stop/restart (#1557785)- Related: #1288395 - httpd segfault when logrotate invoked- Resolves: #1274890 - mod_ssl config: tighten defaults- Resolves: #1506392 - Backport: SSLSessionTickets directive support- Resolves: #1440590 - Need an option to disable UTF8-conversion of certificate DN- Resolves: #1464406 - Apache consumes too much memory for CGI output- Resolves: #1448892 - Cannot override LD_LIBARY_PATH in Apache HTTPD using SetEnv or PassEnv. Needs documentation.- Resolves: #1430640 - "ProxyAddHeaders Off" does not become effective when it's defined outside setting- Resolves: #1499253 - ProxyRemote with HTTPS backend sends requests with absoluteURI instead of abs_path- Resolves: #1288395 - httpd segfault when logrotate invoked- Resolves: #1368491 - mod_authz_dbd segfaults when AuthzDBDQuery missing- Resolves: #1467402 - rotatelogs: creation of zombie processes when -p is used- Resolves: #1493065 - CVE-2017-9798 httpd: Use-after-free by limiting unregistered HTTP method- Resolves: #1463194 - CVE-2017-3167 httpd: ap_get_basic_auth_pw() authentication bypass - Resolves: #1463197 - CVE-2017-3169 httpd: mod_ssl NULL pointer dereference - Resolves: #1463207 - CVE-2017-7679 httpd: mod_mime buffer overread - Resolves: #1463205 - CVE-2017-7668 httpd: ap_find_token() buffer overread - Resolves: #1470748 - CVE-2017-9788 httpd: Uninitialized memory reflection in mod_auth_digest- Related: #1332242 - Explicitly disallow the '#' character in allow,deny directives- Related: #1332242 - Explicitly disallow the '#' character in allow,deny directives- Resolves: #1445885 - define _RH_HAS_HTTPPROTOCOLOPTIONS- Resolves: #1442872 - apache user is not created during httpd installation when apache group already exist with GID other than 48- Related: #1412976 - CVE-2016-0736 CVE-2016-2161 CVE-2016-8743 httpd: various flaws- Resolves: #1397241 - Backport Apache Bug 53098 - mod_proxy_ajp: patch to set worker secret passed to tomcat- Related: #1414258 - Crash during restart or at startup in mod_ssl, in certinfo_free() function registered by ssl_stapling_ex_init()- Resolves: #1414258 - Crash during restart or at startup in mod_ssl, in certinfo_free() function registered by ssl_stapling_ex_init()- Resolves: #1378946 - Backport of apache bug 55910: Continuation lines are broken during buffer resize- Resolves: #1364604 - Upstream Bug 56925 - ErrorDocument directive misbehaves with mod_proxy_http and mod_proxy_ajp- Resolves: #1324416 - Error 404 when switching language in HTML manual more than once- Resolves: #1353740 - Backport Apache PR58118 to fix mod_proxy_fcgi spamming non-errors: AH01075: Error dispatching request to : (passing brigade to output filters)- Resolves: #1371876 - Apache httpd returns "200 OK" for a request exceeding LimitRequestBody when enabling mod_ext_filter- Resolves: #1372692 - Apache httpd does not log status code "413" in access_log when exceeding LimitRequestBody- Resolves: #1376835 - httpd with worker/event mpm segfaults after multiple successive graceful reloads- Resolves: #1332242 - Explicitly disallow the '#' character in allow,deny directives- Resolves: #1396197 - Backport: mod_proxy_wstunnel - AH02447: err/hup on backconn- Resolves: #1348019 - mod_proxy: Fix a race condition that caused a failed worker to be retried before the retry period is over- Resolves: #1389535 - Segmentation fault in SSL_renegotiate- Resolves: #1406184 - stapling_renew_response: abort early (before apr_uri_parse) if ocspuri is empty- prefork: fix delay completing graceful restart (#1327624) - mod_ldap: fix authz regression, failing to rebind (#1415257)- Resolves: #1412976 - CVE-2016-0736 CVE-2016-2161 CVE-2016-8743 httpd: various flaws- RFE: run mod_rewrite external mapping program as non-root (#1316900)- add security fix for CVE-2016-5387- add 451 (Unavailable For Legal Reasons) response status-code (#1343582)- mod_cache: treat cache as valid with changed Expires in 304 (#1331341)- mod_cache: merge r->err_headers_out into r->headers when the response is cached for the first time (#1264989) - mod_ssl: Do not send SSL warning when SNI hostname is not found as per RFC 6066 (#1298148) - mod_proxy_fcgi: Ignore body data from backend for 304 responses (#1263038) - fix apache user creation when apache group already exists (#1299889) - fix apache user creation when USERGROUPS_ENAB is set to 'no' (#1288757) - mod_proxy: fix slow response time for reponses with error status code when using ProxyErrorOverride (#1283653) - mod_ldap: Respect LDAPConnectionPoolTTL for authn connections (#1300149) - mod_ssl: use "localhost" in the dummy SSL cert for long FQDNs (#1240495) - rotatelogs: improve support for localtime (#1244545) - ab: fix read failure when targeting SSL server (#1255331) - mod_log_debug: fix LogMessage example in documentation (#1279465) - mod_authz_dbd, mod_authn_dbd, mod_session_dbd, mod_rewrite: Fix lifetime of DB lookup entries independently of the selected DB engine (#1287844) - mod_ssl: fix hardware crypto support with custom DH parms (#1291865) - mod_proxy_fcgi: fix SCRIPT_FILENAME when a balancer is used (#1302797)- mod_dav: follow up fix for previous commit (#1263975)- mod_dav: treat dav_resource uri as escaped (#1255480)- mod_ssl: add support for User Principal Name in SSLUserName (#1242503)- core: fix chunk header parsing defect (CVE-2015-3183) - core: replace of ap_some_auth_required with ap_some_authn_required and ap_force_authn hook (CVE-2015-3185)- Revert fix for #1162152, it is not needed in RHEL7 - mod_proxy_ajp: fix settings ProxyPass parameters for AJP backends (#1242416)- mod_remoteip: correct the trusted proxy match test (#1179306) - mod_dav: send complete response when resource is created (#1235383) - apachectl: correct the apachectl status man page (#1231924)- mod_proxy_fcgi: honor Timeout / ProxyTimeout (#1222328) - do not show all vhosts twice in httpd -D DUMP_VHOSTS output (#1225820) - fix -D[efined] or [d] variables lifetime accross restarts (#1227219) - mod_ssl: do not send NPN extension with not configured (#1226015)- mod_authz_dbm: fix crash when using "Require dbm-file-group" (#1221575)- mod_authn_dbd: fix use-after-free bug with postgresql (#1188779) - mod_remoteip: correct the trusted proxy match test (#1179306) - mod_status: honor remote_ip as documented (#1169081) - mod_deflate: fix decompression of files larger than 4GB (#1170214) - core: improve error message for inaccessible DocumentRoot (#1170220) - ab: try all addresses instead of failing on first one when not available (#1125276) - mod_proxy_wstunnel: add support for SSL (#1180745) - mod_proxy_wstunnel: load this module by default (#1180745) - mod_rewrite: add support for WebSockets (#1180745) - mod_rewrite: do not search for directory if a URL will be rewritten (#1210091) - mod_ssl: Fix SSL_CLIENT_VERIFY value when optional_no_ca and SSLSessionCache are used and SSL session is resumed (#1170206) - mod_ssl: fix memory leak on httpd reloads (#1181690) - mod_ssl: use SSLCipherSuite HIGH:MEDIUM:!aNULL:!MD5:!SEED:!IDEA (#1118476) - mod_cgi: return error code 408 on timeout (#1162152) - mod_dav_fs: set default value of DAVLockDB (#1176449) - add Documentation= to the httpd.service and htcacheclean.service (#1184118) - do not display "bomb" icon for files ending with "core" (#1170215) - add missing Reason-Phrase in HTTP response headers (#1162159) - fix BuildRequires to require openssl-devel >= 1:1.0.1e-37 (#1160625) - apachectl: ignore HTTPD variable from sysconfig (#1214401) - apachectl: fix "graceful" documentation (#1214398) - apachectl: fix "graceful" behaviour when httpd is not running (#1214430)- mod_proxy_fcgi: determine if FCGI_CONN_CLOSE should be enabled instead of hardcoding it (#1168050) - mod_proxy: support Unix Domain Sockets (#1168081)- core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704) - mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581)- rebuild against proper version of OpenSSL (#1080125)- set vstring based on /etc/os-release (#1114123)- fix the dependency on openssl-libs to match the fix for #1080125- allow 'es to be seen under virtual hosts (#1131847)- do not use hardcoded curve for ECDHE suites (#1080125)- allow reverse-proxy to be set via SetHandler (#1136290)- fix possible crash in SIGINT handling (#1131006)- ab: fix integer overflow when printing stats with lot of requests (#1092420)- add pre_htaccess so mpm-itk can be build as separate module (#1059143)- mod_ssl: prefer larger keys and support up to 8192-bit keys (#1073078)- fix build on ppc64le by using configure macro (#1125545) - compile httpd with -O3 on ppc64le (#1123490) - mod_rewrite: expose CONN_REMOTE_ADDR (#1060536)- mod_cgid: add security fix for CVE-2014-0231 (#1120608) - mod_proxy: add security fix for CVE-2014-0117 (#1120608) - mod_deflate: add security fix for CVE-2014-0118 (#1120608) - mod_status: add security fix for CVE-2014-0226 (#1120608) - mod_cache: add secutiry fix for CVE-2013-4352 (#1120608)- mod_dav: add security fix for CVE-2013-6438 (#1077907) - mod_log_config: add security fix for CVE-2014-0098 (#1077907)- mod_ssl: improve DH temp key handling (#1057687)- mod_ssl: use 2048-bit RSA key with SHA-256 signature in dummy certificate (#1071276)- Mass rebuild 2014-01-24- mod_ssl: sanity-check use of "SSLCompression" (#1036666) - mod_proxy_http: fix brigade memory usage (#1040447)- rebuild- build with -O3 on ppc64 (#1051066)- mod_dav: fix locktoken handling (#1004046)- Mass rebuild 2013-12-27- use unambiguous httpd-mmn (#1029360)- mod_ssl: allow SSLEngine to override Listen-based default (#1023168)- systemd: Use {MAINPID} notation in service file (#969972)- systemd: send SIGWINCH signal without httpd -k in ExecStop (#969972)- expand macros in macros.httpd (#1011393)- fix "LDAPReferrals off" to really disable LDAP Referrals- revert fix for dumping vhosts twice- update to 2.4.6 - mod_ssl: use revised NPN API (r1487772)- mod_unique_id: replace use of hostname + pid with PRNG output (#976666) - apxs: mention -p option in manpage- add patch for aarch64 (Dennis Gilmore, #925558)- remove duplicate apxs man page from httpd-tools- remove zombie dbmmanage script- return 400 Bad Request on malformed Host header- htpasswd/htdbm: fix hash generation bug (#956344) - do not dump vhosts twice in httpd -S output (#928761) - mod_cache: fix potential crash caused by uninitialized variable (#954109)- execute systemctl reload as result of apachectl graceful - mod_ssl: ignore SNI hints unless required by config - mod_cache: forward-port CacheMaxExpire "hard" option - mod_ssl: fall back on another module's proxy hook if mod_ssl proxy is not configured.- fix service file to not send SIGTERM after ExecStop (#906321, #912288)- protect MIMEMagicFile with IfModule (#893949)- really package mod_auth_form in mod_session (#915438)- update to 2.4.4 - fix duplicate ownership of mod_session config (#914901)- add mod_session subpackage, move mod_auth_form there (#894500)- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild- add systemd service for htcacheclean- drop patch for r1344712- filter mod_*.so auto-provides (thanks to rcollet) - pull in syslog logging fix from upstream (r1344712)- rebuild to pick up new apr-util-ldap- rebuild- pull upstream patch r1392850 in addition to r1387633- restore "ServerTokens Full-Release" support (#811714)- define PLATFORM in os.h using vendor string- use systemd script unconditionally (#850149)- use systemd scriptlets if available (#850149) - don't run posttrans restart if /etc/sysconfig/httpd-disable-posttrans exists- use systemctl from apachectl (#842736)- fix some error log spam with graceful-stop (r1387633) - minor mod_systemd tweaks- use IncludeOptional for conf.d/*.conf inclusion- adding mod_systemd to integrate with systemd better- mod_ssl: add check for proxy keypair match (upstream r1374214)- update to 2.4.3 (#849883) - own the docroot (#848121)- add mod_proxy fixes from upstream (r1366693, r1365604)- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- drop explicit version requirement on initscripts- mod_ext_filter: fix error_log warnings- support "configtest" and "graceful" as initscripts "legacy actions"- avoid use of "core" GIF for a "core" directory (#168776) - drop use of "syslog.target" in systemd unit file- use _unitdir for systemd unit file - use /run in unit file, ssl.conf- mod_ssl: fix NPN patch merge- move tmpfiles.d fragment into /usr/lib per new guidelines - package /run/httpd not /var/run/httpd - set runtimedir to /run/httpd likewise- fix htdbm/htpasswd crash on crypt() failure (#818684)- pull fix for NPN patch from upstream (r1345599)- update suexec patch to use LOG_AUTHPRIV facility- really fix autoindex.conf (thanks to remi@)- fix autoindex.conf to allow symlink to poweredby.png- suexec: use upstream version of patch for capability bit support- suexec: use syslog rather than suexec.log, drop dac_override capability- mod_ssl: add TLS NPN support (r1332643, #809599)- add BR on APR >= 1.4.0- use systemctl from logrotate (#221073)- pull from upstream: * use TLS close_notify alert for dummy_connection (r1326980+) * cleanup symbol exports (r1327036+)- rebuild- really fix restart- tweak default ssl.conf - fix restart handling (#814645) - use graceful restart by default- update to 2.4.2- fix macros- add _httpd_moddir to macros- fix symlink for poweredby.png - fix manual.conf- add mod_proxy_html subpackage (w/mod_proxy_html + mod_xml2enc) - move mod_ldap, mod_authnz_ldap to mod_ldap subpackage- clean docroot better - ship proxy, ssl directories within /var/cache/httpd - default config: * unrestricted access to (only) /var/www * remove (commented) Mutex, MaxRanges, ScriptSock * split autoindex config to conf.d/autoindex.conf - ship additional example configs in docdir- update to 2.4.1 - adopt upstream default httpd.conf (almost verbatim) - split all LoadModules to conf.modules.d/*.conf - include conf.d/*.conf at end of httpd.conf - trim %changelog- fix build against PCRE 8.30- update to 2.2.22- Rebuild against PCRE 8.30- fix #783629 - start httpd after named- complete conversion to systemd, drop init script (#770311) - fix comments in /etc/sysconfig/httpd (#771024) - enable PrivateTmp in service file (#781440) - set LANG=C in /etc/sysconfig/httpd- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- fix #751591 - start httpd after remote-fs- allow change state of BalancerMember in mod_proxy_balancer web interface- Make mmn available as %{_httpd_mmn}. - Add .svgz to AddEncoding x-gzip example in httpd.conf.- update to 2.2.21- update to 2.2.20 - fix MPM stub man page generation- fix #707917 - add httpd-ssl-pass-dialog to ask for SSL password using systemd- rebuild while rpm-4.9.1 is untagged to remove trailing slash in provided directory names- fix #716621 - suexec now works without setuid bit- fix #689091 - backported patch from 2.3 branch to support IPv6 in logresolve- update to 2.2.19 - enable dbd, authn_dbd in default config- fix path expansion in service files- add systemd service files (#684175, thanks to Jóhann B. Guðmundsson)- minor updates to httpd.conf - drop old patches- rebuild- use arch-specific mmn- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- generate dummy mod_ssl cert with CA:FALSE constraint (#667841) - add man page stubs for httpd.event, httpd.worker - drop distcache support - add STOP_TIMEOUT support to init script- update default SSLCipherSuite per upstream trunk- fix requires (#667397)- de-ghost /var/run/httpd- add tmpfiles.d configuration, ghost /var/run/httpd (#656600)- drop setuid bit, use capabilities for suexec binary- update to 2.2.17- link everything using -z relro and -z now- update to 2.2.16- default config tweaks: * harden httpd.conf w.r.t. .htaccess restriction (#591293) * load mod_substitute, mod_version by default * drop proxy_ajp.conf, load mod_proxy_ajp in httpd.conf * add commented list of shipped-but-unloaded modules * bump up worker defaults a little * drop KeepAliveTimeout to 5 secs per upstream - fix LSB compliance in init script (#522074) - bundle NOTICE in -tools - use init script in logrotate postrotate to pick up PIDFILE - drop some old Obsoletes/Conflicts- update to 2.2.15 (#572404, #579311)2.4.6-97.sl7_9.52.4.6-97.sl7_9.501-session.confmod_auth_form.somod_session.somod_session_cookie.somod_session_crypto.somod_session_dbd.so/etc/httpd/conf.modules.d//usr/lib64/httpd/modules/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu?7zXZ !Xᢧx8] crv(vX0柨Rsj\ӆؾz2ݩʯrZ:cfKpv8l-bE4^{` :ɖG41e7y'Vvu&pq-zh̢ide`B5IcCA]-LÄ`Znly  liy] ρؒ嚔V$w@?!k[#煾~^{3P,lKrI06O2{.cdm 0*9RNqW23][OE'2S@ (c,Ybcx(v1y]BO_CIZpQ[k24.e/#x !Z> \0EB7D᪀4Ť7r6՞9KHZ YptApϧFM/Bc+٘(4bٮWŲ4R~޷Q#?$:1v2؏sFQUbN+g9vl/,qwr,B@cxM' _a +iݕ2@7oF#lW@]yPXW4%,,s\1QXDy6IslBKDK )H\j?xQ6l 2{5PYz0L̻5­Z쮮yKt;ٔ:'5t_ީZUnBj'"v턴#-p|Ys9n˻h5SHn"oVso:mh }iܪ]Cx*Qh3Wy%-cS 8^Ήe `#߱OшR6Vf{3&۩ L[f&= ׫.TUO< i~yMu>4+Q+7lO3la4"4Иt3Ĥ`K%h(d֛\TN>V|} yBw#1fnf׾ŘWl Oz$\yʤvK%ctF~.Gw7,epٰ^:%Vi%&AĹtsċ6}UMp.Wq&(qE00W]N}RLٮsG#ю9|.R F k΢mι |^#E&& #[ƙ{‚Ɇ[@8 K')y\6gנsGMx 6_0+ß=tփt6YHHl0yXIMѥoOpXKvmGӸ|27l8jSf ү GPP??oDHPv :e@')GمØ{Ao5&S,₺@rU3&oT3h)a. /@kɟ+H0]`r3-PˣAT_y 'p!ɤR%X^oY46]PdlX68?ޠRMa8>mWT"4=NY*xJk@Œ$KzI:S[#'O2}CY הXJ, ͰeAqBsqE%1u0X>4j*Nu75@wqK ШN#3rN"ȃ6]\2df(Ns4hqPhz%e5hRnKYXC @(?bZ &  džE8H[#r#UAGBep&Hp;0bY'AZH9rgb.#oSfv '?guRnYI8AgASr5H+߰ _i~J.8v*fy;/m<{U:BC^ īԹ R12}.ԏcIq󵲶e4Hno &d ,+qqOWضܬ}WjĨ$Ҍ0v~ae@۸+'cDʋRfy=18̚GE yތU"غYDOn5W9ODS;\#fv\ٛe+$`2k\ 71r^wgTo˚!uA!m<$44$i良R\t(;O;IF%2$VQ_%Oӊ ufix9(YF ;>0tȾR ^5Nx@Ho$@iE֩g&S_SY7hL͠+ӣfۇrk&P~p p+)30/dԁ0%2;԰QMx }A-|ro'ݜRm+탒HF'ib#I3wL(K;ﻝ-KT.b$At =E;0 {+fSr^iE\}ek옑e |Dr1ERW!db<9EQPM]Md$͍g,gSD6Ԙi 0º4c8V#.KJ p`db H\(r*mQ)~ߣ;k'u3‘_OGtAU7?Bۺlcs}LȽ?(=mKf;YN&HFd?33bd?+xcu7vq8\K[o"b[ ^oq(#:Q[hOr Mdfs0[i`ѱOڎVH/Rz\޽[C3iЭ:;1\!>-&$B=>#?4hSyRiۼ6GBdvC9햦kީBjz|>|.>VSrsfDR.ѧ-rahUB;\=h̟67C]7v\(G3p: frR(,kQW`.|k|iD##0  VxODw/*&r-Na?t%3&8qH13΂dʪf矿\kL^6#-wa\}'SWȾ\PM:+)wBy ޤ|ڐɧB._D$+87Tp,1<"%'?< aM&38ZMFsU F%V"LE%Sb`S KTd#w?1<8(9jlql K+L^!aZxк% vNσ|) fz-O4Cҡx޹{;FxGKb&;%Nq.Mޅvh< B&ݬjʂuGThbFng1V;f#D-#osOjѹO,& kss6 3]w ߔCczaX5uwtϻ d-$ږ(xnbԟϖuNVEYX9&}8 ٨7N1H 2HZR򌟢a,qmOPg,ETI9XNk%y!OEݮUyYhؽOɤ=6`AUVf%2q d&@Nedچu7.߇Jx=_S*/\^2F aQ:58FZ)lE6reG'ヾ}v6_XE53 ډ׮m+3! |3}ע@8Op*XM38(WLpYǪgUM*ԣjB}fl"kzjxtq PNvb3[PA;b5SZ9 Ӭ+ai((n͚X% FVYm:o/=cbiUӟ!zmgziЏ4֡P-7nihyo($P *Oj<'*gٺ5ͳZ6jb.f:̦pC ! 0"ńA#D΍A5KJ-.MJ{wOk :7SxtR4IBǍDVP`=*w$; (,rlUHD(ِ[4.Bcf$7\}QJCEFm٨eEHvPO!s!!mH9|~kaX8,v~M6:W*\T].#eVYn@fi*1hj34\ ;|nDhS(.V"b#%Qf썽9m[;/\쉝DcAG;ܕ4L?e F%d|>^W+YݪhRɍ ՗8:R|=-יJ,;EaLqM7?4ےca,kDe0x[u%n֌(6rMcK56G!PCW[!az$g;^_Ca9m2veفn[=νN.Mg $ dbϚoBפ}9I:-|'*37Hd%Ň,X\fZݸDg8s@rG`!, $x6 ][ShG+GaAà ː^[IVdǣҸME8#ջ/CϠJWiirFk6Aagx͙TK\>褮 =nVSOڴ#$V8=:N,&D@;d`U>RV6|j^8tlN NxQj0^V?2=ZL=)2R-F['S{s5.ΫjaLwޣݣ< z!hNYL! ׈hԳ]ijSpγ{?h&T\ xjv'T\ Y )=%< ^zOfK/֛:}5@$i,x5yW xYJM]<]@R _+'&ޜrΦWMӲAA\1/ٞ"6G|~JM ,@RU rE߃#SDF:aa/HqTCohfTr @9h6ǕnMҔEߍm>MBȕO,oD (Y54wb݃^2EncNE to,ho1QZ-\8Y/?8Q{@k;]4v9j;yXP:ױLhjtkcAQ-GK&&0t5<%ף&dB7l wLHح[/ UG$kR6C$;CPF~``wF^}s'I[Ԙo ;*cpmo'UGJ6*ãA'@Uc2>۰72n}gltɼ֧N}bрp^M^Dj8Mp-VXXֻ&(S|`%2̻Yf)zO! Un;uCqݓv$TY@csNBC 5h&e5bV6CѶVߪvl>v|f1nTGZ>fĽi 'mg Qh g{*gMoe5\tR@11N+x֜n[ &lI,_cLxdHdyJql|x#O0+"ռ9w'HG3F%_xxCS܄(Ch(Z8v4OLwZXyMEw{?HGrq_/Ҫ`颮2^~S,TCw(WVC& Fi YXu- UY`&BR Oyn#UoaW]d ֠-m߲Y#@0[b3B%8Fo+O_=V~}p4c,Tuht OD>N`B2Q25MEzpiL#XUi~tEoSW6EӕFAlm)P3աBc%XPu2Řtf;~ b>XʪaLȧ`KY57' Z_XZFkѝoV@'ED$typL'N餘wܞS!l> #i `NX2M}=gEo\E"t1;x=hat6Ƀ8Hv-Y%<t F} -(9@W{߆hX;Z9r4:Ve@|n_yrSQ\=.R*mAWS::ztH 4)$vd/m_q8N;`Be_>YzSʗH{>Z;.>vH9@~[(Ll~m^s_3\&]ulOfonkx9 'rRNYW A%@929_3)u 1UGe.pD(G}kl9k y @ќ1م7=R{Lw5X/ 3|X\9t 87c[rkzvnG_AܹF*`vXr\x2!*s퇤r]Olv[DKМp&hkWpQի@d3^'u/E\A1vú _V3W (k#{?:?٤ȅ$L{rѶ. ܔUadVQ 9Vk/雰&Adnohb|Mϴ1|E[/tI%rqĤKkX%6,zx8Z%%H%zCU*<ÝDG] )[1_QJu=*13thc Ǎa/ I\UjGada]Miwеv)9&>cSU1̔57*[\A+~]ڶ<`/8~r9+ZQ1\EiJ5@*-0o,5>yÎv$!4' 0p^ÌOnP-])76(ހ^ٓ2.X 96J\hc=1Zm?4n'uIAu(o m;t˩~=K}<+z 龗P::4,_I^ϯcf?: v5b>h*?ke (5rSfﳃyD؄D2#p|S8xQSNQD' U4wVS#2{*$ 4lj \ޥ91vmupo^@؅~BqvO: C ^F#[LIŭk齂:6< 2x&7#P*DZKݚ NF^ uZv%^$U o+GL R͑v;%wQS?{@e)$Df!JWwk a'*B _$O5 <®;BM3mrﰵ+n@k$ L-~A7B,|@.Wwbx>Nj3'g+6:kp8pdZ9"q?[BgxqF?aYer2ebB}SJp0:a0m}2;']I$) ڜ{/J߂r;eޅ4 ԗ+|DYxE.}=Ot !14pv; 51αcvd9/FuWFlfS#(b +{ ]~wP{DžX۫˹6J b<91-vPݹyQdӻzts᭒"Q3k]΂=!$QM17 qkPf}.CI_X`f<6O+_D%d _fM"@Bxm2l3= g]AH͝*|%ܠʗ޷zP*`:BFKG^MH(of)XlyũdhINnEڔ^(k26jmCOaA jҗhf&: jP?gD"}Q "AyBL~^T 5S3̿{Vp8/XnRxrI􌭫+:%4" 'x8hԙ?'eW_U]z9T=H!8@g]xό{ z(q# }V^(+w;]K`o kRmOhZw˴Ig\+4`2:j#URBz0).WLGVJ2R<^ݨtpO`m@_v4vlHNb6 RxYPL\%bx|z > (=yvYy֯I[dA l܏R 15OnڻPʵa0`QPǫb;XnԨdqPࡇTΓܙa;t齛\&W mΎJEy4T)z,-9''1P>3D'rDmlyKpcO7GG,V2qi=يo:dqS`7?OH}dCK ts.)?ȸ!A96!(*ptcGp[{%c:Po j/'%ve?,&J@12C'10MOrUdO[ɍ͝/Evjs9>wV66 DZ[uu/ !ş)agcI!`n<>i&%zNshvat(WPh&a}(^) NH{%hGk<]TC>5sQsB>6 ՟TC6G{Chk5촉A^-krL1f xBˎQ^𞒫[mߝZOXE;z^1a^ǁ\4җZU7L.7$&/ح@%o ̣c)q<2լ 07kt}4>9U'a+n=`^cOD2*A 𗎴VC,e7 \ϴ6Dv:۾ `/+qGݘpu-WDJqeVD p4uҵB˦UklTH'pFt49&)gRٮwhe!E}žƛv j4-E Vo3|ϫ66ZIZ]Ҫ:Ԕ]/}4l8u,FSE;qU0ޣiGzkkk-vȋ*[|DI[n)1;#֚SE؟͠;B ~{F ;߳\vG2M+I,FM Rr4*x9&*`a0 A2Dt5Γ7Ebaqf8U`яeGo#버r+(һ(ErywZ.|l]~)b-Z6ظ RH&)ok|_oqV(d5C.ʰ?cg"ƒZ1iɝlY |YJOM8ŽQ2c4:Gc< 9();"3Z"3 H-l!9>HDBܐpx֖2$-4R( Šiγ zE'J Cs>hP $a ħXe-˩[rg5-NxJEd):Hߗ!7tm7Ra j0cO;M% B VvuO?D敾%^*ؠ`uQ~)7ut(n<|ߑ:,.|p\{A ^<[pA#=nQ-x]%8:BZ9olR?1׳CJ~Ae +'ybu=U쐔Z U/|ƿ9 }1)#ޖ!yY"ߙc2S5F$ ƽ/} %;Ҥ㫈6 ʸe !6aQ>c]?}¤/ʒjY&!@&1|*͐ܫܭzȊלl;IOTO2*Z~ny 'RzFY9G^D,?&4s( F2H]A2Dл$ Clw#ᨆ`.=\9ƺcX~g/$-*4p{IkoUQթu,(>zK &4MLe 9͆yR:^hǪN+uQZ|+'h=vC;©C[戣˚o0UZ؈P9!rSLi nY|ooQCȽJޣK(Lun<|fX!"d>$-UJ[ywd:E3jϯþ^@5;LN~l92=#w7!Ż'>Okc<<n 9f{'K17'I\ˉ&?TO<2DM5jXq U̔βfZ{v-#t.VOmveF&\Wi%(7y:ʻgiRY4-צJIܙ\ۮyM5-@~^ >‹ r䈚meYu7AQ1TVS%!_ w~$ (0m+Jʊ@Tyـʼ%xU18"KfIʧ ^n: vy빜(o|Iݓ}@٧)>:/dM>ˡ/DbG51^N_W2Z`R:S&DִX(ĈTPnLψ8dž}x9+>=g69[s(3`2.eHF +b-fwof#{z;i͖IL:U8P9{NX×DVX̢8~*,Txs7hvsbwWM$bv|K%pdz.:vlKdS%ޑ<|Zh76xǰʣmj֞Vx8OهP6v|(I[@SgtF:LA>7/ٖ2w_3S'k8)d+Dnˤ_Ȏ߮ }ϩ\㐁ȟ䅬LY?g3ZߵŅY!Y֪jm%hAQ+Ub6U7JM5޺sˮA@4|}h]`oQJѤA^N+5GajDVNP9eUL%X4 Bbz+k q8ZqDεQJ"Xtрcp|k;SYǦ̬ajŠ8NR25mHHT>|;Ucō}^u HRl{.U4O-wȐ^NQa]}.#%dHVCaYJ5Չ_u8x>&'s 8T%QmUaJVAyMCކe"Aav=֣Z0lbx[u@ȪDod-(^Y}c׋!q66~3!W2?==ZO SL755[WԆ5޺B%>JYՃ8x(X,A*;4k;u^ð .ih%Xr*snG䑟}n1 r ׬~n3 IpMt`[fW BÛ4_śo Rތwg1ZuH> !&#Z8\8TP4.s IҎSIla2 <6L8J2F‰I7\ouᄄnCU`q |O31'I;F/ *# nD1 2]C/*7:)~ElJΆ`?gk^ڍ<::071kX` <`p&,ۺ "͘o@}s=7ؙ $2T ~"^^$S,b[O`W*9i4=Ds9 VcXO&s'o~ OG$rfypցf"Nmvr"8}8(%9 K׋eğniF`׀]y{6A^S+.'E_T]^b@$$!xJ|NHPECp;ZTjU B? ^y gJcޫ`h-qW&2 xVp9cIhlrbbCzDv)iEW(i9)a\6x> 꿘x ~ ͛n߇6 LS:Wh!ry)ɥ ÷JEC?kRcTbdb}!˩(<%t%F5zK7h/,ħ^ {e4OSPw8Qrб,^p85; WǯvECx-ㆂ~ A;I^X)+Sne n!3.P+]Dm*&u"6>-싯)՜O}S=2tk__rb8qcpp5,\K)e?;:'4|A#u\ u:;P- p=# p P/Ϸ@GIa͵@_*}η!N)6cCNkjygE7:x<9=úy1i:pJ|ڢdқw;`%2LlFv -_ƫHvyJwSGqAVIՏ ڠ&F  G0yIymW1"KWڨOHzވRLڦ5e/gy YO,9O>٧R*. I"$S=ı_χeHP~ R ~;dJ_<З!Ro"aIP nyF>&/0caəVcN06BT#ֈ7{!O@1/= =HGf)'icٍ#rҧuENiM٬,tnX]Ai}N7u']S\*ChKOlw ئʌy^TM%gb% P~pږՖ).@Α QӆM -{Rtg46/XmY^iv%MGugOx{zuiG!04ֈV#jKCL8ySǫ'E^⸔uVQIBWg. d`DH rLy'N ~3CQ5G㋈i){?gጋ 9W,RMn#v1#-z/ VBVq`;j*v% x#cmM}Ǎ|pχA!jP) rRochmԫ k}#/B &\,Y>˲GǶ)*ALĝ~/kN:y>#WK;7~AϥU*)DzKr6}vGHJ WD1ω#&\|tS 7U1`釼 B);2k 4,]L97jQjzY흡BG1fd 7X%8XPk-逍?}=!~'8)źL;GB5DX8DH)A>+v <TNewAGV03UgMS^ɵj؂M9E;I8SCsҗ%"$BgtД_1bAGK9Ub:LA|Әe\gL/:gʣ- T8jf.g3.Js YIbȭ0Q9W jI ,!՜65 t+IB9?c9Y{8KKE|{iޯl$//7!ɜ(F q[6V/ə~9.>~qM PTi)zc ?ʇ:.R:YAddzn{cQhOKe|ZImC׳\ąUI9oɬ~ XhQ]x%~%e;rqµ݂kU{d`_{8 G[XƷx &Ui uԏL@mul])K+𲳥N֬IEtT@Mڿ{B80F$ЬTF~5!03,6izmI{Lf͍s2?? ARO4jRjAfi'}- H}Tjx|e,OsĖ`nOXl)Uj*EPf&fcHuY4 aWL=arIE T&h|tYh?aiWa.߾6vVu7P,w(?<ٚ=2dnlQtX\*zX~J0 Xdo C"ZI>Fc q t,ƔPnY|ŧ: CāeJ ?um&#'WJ/7D̃3a|/|1解&-KpV\CYwAIErXURkbȀM1}΃j͔Ir5`m1۾LiQ(}B8[u);j}K WVr[b<@!q/𥢚vqH{twGI4Ã/a 9k.Ġ<}vE{AlLUT+V 4e09IWs!kwDS_R0q>HgJ^+uDHl U7ߜyӹi߱1O[ <hc#;{ HA6rYJjv5n^gYa@H>!9ߤ-f>Mb(gdUWо5|NK]v=&o 6ϣkpLPV#͸_PeR&6ɩe0Hfl\rKT}HmryV(bz.ʕRUリNlO\R}ıaowc6g6P'I|S躈w5R,fb5tIl_.D7YdknМy?M㳻bETy'akx9'L=YO t" :kyiXtZ2s7/̏oSgsѨo-#qy%?pE>Dhg4GK.e\!ϓEP[3Vp5S0$WRt6dni0zq 8S~M5 n;VѶ<x:* XmYn: nþԏ9Lm0duK2z~~OSg+, !'y·q%R#΍c^\9pz5Oa(!ƺLSx0 <ĉׁr։ѻtPIi ?g/\DqߪFkįԱ ]g|Te29b/X Ws|&= p;q<xK%dzcSp_p~xϼմK`Y5"%-BR9.(%$*.KavgFx@U#;a ҇F?ri[R/q[DLck_\O7Mv^kӋi.y&Bueul@ĢuV,t5yۨsCR?jw!An}E*Ƀq) JXkc~#{V S sFzFUm/V5LEѩѬ^I@JUq^b]e&TIW.tǘp)~?ѓ bf L%,! =_,5 5Z`{o28卧&q e` [b&b%z~(Deu]6{́ Ѡ8Jӭھq=f`fp{Imm6+ _T=1g*LHz2%;T>KHlΤשЇcc8OElvqMD{P6NSەgrP1 &C[7f:4[(zMՌ) G *Lᦖ?PP?+p/..1 x(~ԥ&#I -bao*a ,"5p?7Lj޵[\^iyQ+к":@+K|÷WX7\[+ LC9dSjEyYrSdI8en9&lmߠwVTn#py'99s>w L[ l1[ ? .Z9Z>vB&UͦEsSn({L7-4 _LxBAO$̰ $OUyXCE5fDcjù3 /GXV;~绮$ߒ۠H UDuCɇhqOp>7)4)?){ѱc{7܅}-ÔHkmA-4KN:w5Kƺ>{K8?bTb\rP@$n5 n^2ߠ`;b%uia cޗ-U293hz\vj*.Նrm.׮ϵ*n,|˸H _=SaNQIIFgMҍIdǀ\^qA:2,3ܥIA] Cpi%˳,(d;.Ef*$hXZz6Hu|x^ӎZlUk0,ȶ4؏:ڪ?ѓ )}oGvPHYIeT 93g׸b|n}mї]z{ rh[W>3T6Ci#eKS-Цc1ƴaϨfC-c\wI$I$UgB}~ta@(}.,IΝܙ[6,|`rm^’?@HhaǺ1 q>}gtB:M"ۛ,ac0;W.tZu'~6c^50L,Ѹ(hֆ,!l]>Ӭڕ$}l$dB3y[ h*i"㌘R L3܏Fi} 1,!ǩ8HϽ./`dPoe#(MsHuk;Lj1'pcaPan)6]~ut8͜ӂ X- c^IJ/G ÔЕ+F0R9;3J) t2~NQRS8eSSZ0M( Ay HK̚8Mh#i;PnLxUel5)^3,!{Ef9hcA6Bkmx9ӰSbıP5~e@U C蔡4 uf&Q4O!#F6<*G1-XkDX (b;!$vdRwK|ؽ{:rv)+kVI5/`S%ЗIPE% uFZʘL~k"p?Aƚ̙, e,'FQ {ϒV1%t ~9x3ydRnGf=3poJoacL/MO O%ǔEO_\6Y᱆FE{@ܘ>iq;Xy 7=Ff}i: Sa>;Z2l[Wѧ=ڀwʅv웰%G\8ڣh $+ASl,%yޮN@jƝ#Gy(.YqPUFT[W< YgՍE^6HV덐ŪqNvt~ch47!N k1|?Ot`"=c _kdKԫT'Q"bϜi/TDAD ]YXyUMKV݄Y4ӝ/إ֏'3j'7&[wiL%$)zܠEVtB_"ՂALLjgy$У{p_u\A;!Yw&݌q+o 8=:O[U']wCkD:3E|&7q^'[`\ |v 48̗;%Gt)4(<8ϲ Ud[Kn"-0zGx~K vR ei)@:ǝ{DϢI x7el#r,Kb \hHqL8.uĭsL!v$fv"Rc=`Y:'\!7[bY;-_ 7'%l g8&:B\{? I3롙ءZoi ~vqX TťJ9کΒ0D\9JAPY!tΆC/t6\+K$$hV2nZ/O.#Ky]D". (6C5, N>J4:qL~/yZHJÔP%Xn19Cv^=I~Qa Q"j謺:XE|Ԍm!0T^dxɎzcQLFy?7'Gyw-Z397b-5/pK wY =]-RŎeډ@zr-č$TB^P ORO,M8Mf)tǍdT& c"~A6F0vhAuH* v(oћ͏Z'44\Z컃8gHWݻn.NJܣS}Zv <\PKz_ 1|3`@"YUi?ua>qZN~8cb[HY!i;h$Q8UB#j颏1w /Oq.謫\C]0 G:P&j,Gr l92h@ kYd*91w@^zxLe D4*aih*׉zJɲ3.iybPΐ-c Rc4ʋs }vû!Jfف<,2N}6=p9?Ҧ1xfg13eݗ(򸙫G+O#Gq;.0O✯ BZ:eްf z ?st\ 7VU`"_\`&ϬZ%EA1_mVz#|xAל =AF%[f^ e$➜'pe3>x*xnh $@䫶s+pYDT6>~Ok|%S7wp$L*TPS8ҫfCQ GdRg ~ktޖ˯ D&AeӢ[Gw B/ЦVI{(A'k qޠp@M*cѧM]E""­n|#]:#)[ݰy$j0d'`!{n\eg?pʸ9-Ƽ75H 1f)?6vZ. IENCuZk*-;Zs2kZ5zꘌ$.VMȯ@?a pokM_7(.y5M0z&ekQd{)UV|:eI)ǡf}Y&# P$~Eu+ޠ%PRy,k2ujHKQ!h3tc߃rfMuخڂ{ Y5u F79fX?3Ê40y'9̈́ƒkL;d*i(']JE#4ϩ F0~RPuůljE[]M-!_I7DNч#u[;PMi,K\$gl W vy~G'x{iNX+`-|!ֲdSx(~L%O~K$N@3IlEy!{p Rʷ