pki-ca-10.5.18-7.el7>t  DH`p_Og$ƨb.?9?ȸ\~z g1!X%]@[u\" ɺgBco~; cW^G_Y1g 9/YM+-TYM,QZ' eXL`e?hg}R<X4rYoԲzs0\NQaY,KdD4˜rQc}ƉK"Q;)HZc,A2+d SPPT蚐#X 20û2#""[c}p:KK`brMЌL!yygɈu=8)oZ*4p*q4910fe6afb8b50195c97b7eaeb5dfa073dae4823v_Og$ƨ\A&7O@L!fG(Ɓ:|GBTt,\ Weɩt{B\LDTŎ:(XBi޾#$|NWG~s|t-"d{wk(際Zޡ"y4g$~-q0m+Yoe \aZ7 N?Kt^҅r"Ox]8ng^X#i | %+te(\( C 4l&Gܧg`A]Lov/lerxd!bį_?VeAWj$ȥ$6.x)?֪RSoLwQF)-?+-~:{`ς]v<3&k yvafҹ6ĉ* @KJk!?ٓi%#ݏ6~ۋ`&xfmivN~v@N*<y=r9R}vЅL4|NX6ɐCBVۼNug yڸ~ܗjMW%>7?d   B        ( F L Thh h h 4h oh r`hxhh0h   (89:zGmhHsdhIyhXzlYzp\zh] h^b:deflthuhv4 wxhxhCpki-ca10.5.187.el7Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages._tcx86-02.bsys.centos.org%CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m{+/1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz109{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9Q][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g=tB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤_tE^2_t5_t0_t0_t_t0_t0^2^2^2^2^2^2^2_t_t^2^2^2^2^2^2^2^2^2^2^2^2_t^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2_t0^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2_t0_t0^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2_t_t^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2_t0^2_t0_t0_t0^2^2_t0^2^2^2_t0_t0_t0_t0_t0_t0_t0_t0_t0^2^2_t1^2_t0^2^2^2^2^2^2^2_t1^2^2_t0^2^2^2^2^2^2^2_t0^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2_t0^2^2^2^2^2^2^2_t0^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2_t^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2_t0^2^2^2^2_t0^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e3be7696d20e173c59d8f52db7b047858b299dcce8b89479da2c1d4aa72119395efd59456967cfdb90a3326a4638e26565505d89d686cb3d5796b9c16bf47223e0c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f400b2c58282cc5958a930f3b3c7c0379fb101fcf612156c27ee2dd8ac254248d5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c139dc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd681d2d2a28ca9431e881b368f6441b64a1528340971b15e644a105e936a293b3f66bee0d3dd1433b23b1014da8d4fa9362985fd87d62c19bad1ec8da612cca86749166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbe74bce5a29608bfd7763d1f5a3fe7ca85789ac6d336c1915d4acbc15bcd3825208f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff68bac0bac0009805875096c6bcfcf7a374bd1ea53d21110c909edb0c63b1760e62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc693559e007e87c5447469c8bb3904bc01115fc62de2157d7aa2c662fb29e4bde896aecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617da3eebf593bc1bdc8d23c5b86b4316930400e8119e544f5f33d2f770c2371b8453112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121393548048afe663a7cd33536c81b530e559e6e8c13229f820c4dbc167383ba72607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab8fca203559c8bfd115dba0a393f9f573f8a100d9302dee0f78d3207bf2a4c02828b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e046bf1169d8c217afe1ccb628d6dc722d255413ae0b658637effa7b39bf832bd1b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-7.el7.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-7.el73.0.4-14.6.0-14.0-15.2-14.11.3^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefgh10.5.18-7.el7    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(}xq ֳyl-l+tT?{ ''qz$U_#=Q>禑 nKׁ5.]4h`Dj>o`䢇nr3Qi~hCC^εO(5ޠUth0ycXU^<]Z[$}-w +"K0t8g 4{\SMRZrl>%*o; 媧6C TݫR8f+i\^\WTI Xi`l/8JTxh2=z5;^<ʰ.{@ISӯD~YHēLfP_0 `ZwޠS]x "ӬPS'@sg}Y``W2' h ZsXrg#(a>;^uރ|ߣtk,w ofR-@8 /ǻ"{B&?V)Vj/_P^|oЫZ.70ךJx4hνqK;T%L;eyQ)ਕAڰΰᛄ_ 迼1u ZIuvC+@v=˴N{+#t ѠmuZG ,5H$u_Ѥ9]SIۯ~vNh4d4KԈ92xe LS?CGå;Ǩ)}\C;e0r0_W/!ݏw\j U*׌mFU>`6كk7餐oec \ ;c(QG-') [ rYviޮčFv=ȉwFlm=XJf C.7f'{3{_lcO{*,LVS <6t@;<6W(yV{>DGRлLM"NxRq~y"},֡ō3KH0S"v8oTxSx&v??bmY}z!ۯo_z a; P 9zvlMeo^&vQ bSJcUP!d%c [ðX> K: 1?Mn_J ZAs?0&cYYkZ/KTg] 0*H zOs3եփЁITe,iV"lJz??ًb!l&ާKd :.#xtݙٗƒtuHF [eG?p#8ij yH\Tc P bL`y(-Vx4`"Lv3FLiYlœV#ntM]UcHBً3@쵓QCkAF/rlQU@MqSl_!Kָߗ v׆v[֦: Yv^lX1n+=t"F흧/J|"CӐ,V~CŲz{ŏvS3VcwOЀr,5lڅdj4in}k)U]C8Uhe,8Gy8Id-f6NF>tÐM#R0UȾjH`] I _,Od(t?"Zا$i =E|ފ%'45٦66-U<|HR?aЩt,}_](FhZӨ0I߆#z-_'\|2L`ȔS~-E9 Zirz UʔDLl`vC##xt~c)@RZn(x*\_93-HMhPۭ[]8 xJX'zπ]Wwy7-Exڱ6_\6J@ާܞ 9z[E/1_F!0Hv|c,LSGIڤ>"!V!b!E`9uH7g`ˏ^2f1!RÎJzvp(KrZ "Uokm-d^,6j-󲧏r%~.%PA(yt[ 5]?4F,Vob'Rqr*ޡ@/рE?%lYZ%9w;K]R Xm`C[hMM h F5|5ݨlptm\=.$uC{ AM68!A@!aٟ_e@CQؿ5"2B!4[ Rpt0Z!`]! b2M.X5mKcQ2ڕOrs;]ё@LX1(!'yѕhi6qE1/-&\#c59U'F4W10EŬ=-Z@2lUVL21qDg_X[""4jf?=pPb(>"%CD*soV:~vཆqs=Oڷ _(i8MT4i$T웥dU=.VY-H1}fZ ]aI6غOT`G*IJ$K0X7MN OIgg}N$iپXQ&UT=5d4Ư'uFmLc>(w6nJshViG% | ,!oϯ&Hعɉ``NuIe"hoND6|{'Pg@7١>QEͦSܐ'zGdH'jZCKA2/6kx@ 9*B)5Rȇ/߈HT2ODY,v']%5iEc\*K8G|E C1j7$7D/mE(PeTm XEi8b%{p2/`f*1|ɞ`n49) qsߙ ?̧h';WElR>A'M[|hd'rXz] _v= }I/CGԲv{g7paC 6ϔݽ^=|$tL?<{}Ҹ%=21drV{ 5Nn9qI&>Ր ,N@ `Z DZȎ*S!^ʲuveDxKˀ~W/nvgyйU04$\mRo DqS®"EX2nka_rPSAsxY$\/o61֓U ]& g‰]1C`ytA$1?^߿0Mo?]ƪ& sh۲694 n3-ʜ F=;^\~e?{JRz@!#aU)Aq.Lt$x:/[t(dg6UiL-uU6ރg-Ӝ*KrWX\ۓ-iR)v 'idR*[&sYJ\uPh<5pZ+/; _u3q4gD|x*$ʚx٧rfVjү؋g#Do:ѣT#bӢ; 㒵_CMr? bRQ3 Y)#ZG yk C%?hQTL}4|C#]fQ%WR/U2`Z\< {&c}qrz|_#A9RfˉBK9ڐ׾-1-pKW?gP]U$Ao^sp {IF39\>?P3`HgoA]p+\(,$3=5p[@>/wd5 (zQ^plB"T:@0H9[]A0~4Ť_YBQX^-⳼NH) _ss6RtzQ139(*\^ȞWƤ+}^~t쓥6!}h1dR3ȭdpz5Qf pt<0`8GMVnύ!E,10D[-W9dBBr6}OD&* v&gɉy5'jpFspE*T23R=[Zۡpyn$h5IfhVK?pkd? 蟓YBR@L|Scp&ĒufHƌv޽FuEYVޯCK4Ǫ= !Oc!Q4 D{H篞@,d.*4EiP=\[K0|&+Yؔa3'tq_{v;uG5%ȁ~?s 8/ 8-1@Oc ӝ=3R j HJh ٔջcIcI6Fɝ&d)S9cuع:j:@QX4VI >hCA?J:w#?_@H>-i[1-w'udv/X U]m͓ג+o f[8'l˸:_ 8K%xzs.~\g,9dBD#HuR ⇕TOG+TSZYFIU^ Ҏu氷W-h:seBY'ѦB;5CF' qx(KNⰡ:sCFw:X iiTwcKf _~IU&m4HyC;٘3Zy'<H㤤Utp *=wB1GaRC`OT)qGO "7 4U0($kM65Ə})8`#19]#G[eo2=!rJAza4t<~k/ΊvZK- Y*v9%p0QwLbs?¸X{vK/f+d`./C9u+Ԃe~vJؙG:W%Nқn<@Z83x_2B,W`]g=ʂʯ IP@^R^-/0>V(P)g'vDh?OJòihs@^ zTZh)m])~I +!&ϓ/-`LT DҊ% Ps# #[->mSZ3Lw1' Ev6&n"2w6^]֫{[9^zvn6~dlg'݈-xq (//K:h#7QJ'3 qv"Uf[0ry3Gtbg!N pXN>p;˹eGeEQTtjj i8L7>!$Y)B!%+?S&]8 b 6U-8(5>7?}`=dnD@|a/J'HM\7P|j6gCy$3 (i;O^yOpoNkMXPؗlQ\to9hBEؤ֯N@G p$ʒG`"VXxLUJoA dUA9q[MG&i(/)pY坅7^}i-v;7"URaEmuR9ԫ«30BeE/u4B~Ny]t0=ݳ̢yRWh>])??]#=l0{Uq8(@Nף)$M+'Ay&,GFܑLMtѪo,g2ecC5I>a^H+D]ұd,6(2j^mtɃ.Q+31-= Ц2L_]>>12_48phVr?Ls`( '!x$ Է³]GMo_݌\|$42|-&Dd@};Xշ e b9уn˨TżGU'ZyN[D;,Zڳl.qDM]2m DMW  /of>-3p]0* X+-W mQl_qmAŃ ;kQ^_H/GqJHvVdC=Í\ u\f%zᒕjW{d벭5X7/kۊ dd7:c,xO !hJܵ9S Mv/G._Kh Nu0Z +MŋXu;װ<3#;Z(kLQw2(W HoX&n0$Z{g#8$HJ-9q8P2܀=F%6Iaq ̕#dXGFڭLƛ:th7/UjXeF8(})/4m>[r ^6/-2{wlҌխ,`+1dj^t(dI-UGdgp`ΎP|  K1ZRQ~l~bu?)Mv(ǫ7c$ {nNMcFGEr ᣠSP$H*ܒ n)`I%SGnUܬFYm/HZaVt6C >Tohh' .2f_O\enS;w*BP_-MPJEUG*5U[ʗVewQRkaCaڝoG8z[B(K|v1L%X%v)F#;ᙃf4ѿ*B #3ّ v W?[2/$2[]HUfm/7 QL]^1+2g ji*$ EOCDqɿ3͉ \e^`WgMx;sSVScJaͽ¶e&XEPr[C9J ~6CځRTvb]4FB+@~ 'PfhPUuz05|0eD'#(n[=ۦ\2Y̞pխl3e%&6ʹF"ƍeqMM0 hpy[(䎰=-cIN <.->7 6e0=J64^ cfo݌jbn:Θ}Y= ; zܢ#Vdr:#/`!rA)Oo1e,fk}ѯ]4颫';HLsVmø7e6$lN{`5>>0]Z(BώQx +kwɦBSaCI'y61^9nj2yA\~;*uƩZ##-Lߪ@#[MKw&j>_nűiIf[oШaOF9 DWLvr8)w!fo&j!r/Y?QU?A ʋAL]SVxXW҂x¢d`(S !St}[t}[ gwֿMML#lNk"변;\*4N8d!k*X6[nY Xf/p2aC3S4mR|/#P'byS+ ՠ':( L8Lp4j}?A /!NS&؎}wrT?0J?'46:ֳ߷9w~-3߀Q75T@4zE9ރHL{mk FڔGT\'G(֚aqnE:E~trW޹>/RV3 ΈDqJ;TEۤB>{hڐZHp:S< 9Gzdcf3T>OhIͯH5ݣuboeoB.~(*::P miXB_K6~-%Aհ=s+!;lCb9 eH&Il-*?2cӭ]<?/[>*?AVb K?Ԕ U* >VC10:{18|x;Efօ|Xd氕CU05&5KrߔC!suoYe+lkᗁBQ{3Wӕa 9"Eh Ѱ[Ni_^33j<6in&$# W/BlȴW<`06G- CI\eTP?[6YRJ[Nn]OzHVj:S0O>9VIM=i,SLD҄S&ŀ-4$,Ol7#8Vgnת=A0hd[JQUv0Az}L[ai8𳋲 Z~ 8 vIdpťrѣgV]2F]>Et<.4%rH/]i𜻕 yҮ Ok%ֲmoo'*Y\:{M Fyㅅ\47E4sMGj1Psw&ZW`+;L^&w*ZS7y3pܰu}LRkKJqïP}>O:,|\9hs=4ڧ#$uc%Ҍ+>cuJUՈQR)K \ L$͠.?2VbV+xtOFn)t7CYnc9@04 V7* aݪY3KnvFde}ZG%۵J & y7\܀ RAFd˙_0,L`(M™Ϥ~-Ep13m&!Y,_z]Za*Ly C !#,m4R޲'g?&:AhדKܱLu*MJ6R$J3 SxFFY3be 5%ۂm7NR>٘< S]}Axm( ̚ A][ƫu >kI6cVsxȽ*bgB",e'%k[TMiWְk^qRjqArOiˌ}n-`wrʒ#&Δ%K `H!$,5K1 氎m|&SB7* izcԇl`9?\Ogď qMa2A'̬*8*Y01o` ѹ9_秣40T1&5]|oKQ?Feah?bK9/il_X|ue*N-)9]șisADZyą=,-g s^Ff=s|i?*F$!ژwduyGV~ɇ>"GqqF F6O-q Z5[TUX(OW t\d㑑4RS@'򓹠X)¥b7  ;A"LVXGkFcF9qB{P [(*n-ǵ.3rP/7! H7U9cK"h:r?&-{m*kH)N{0 ⠡;A +@Q䩡]uɊbW J|=_r [MȊ pjz?o{LXP9Վ=t9y,b[FRzaG&*x' a[ٹ@2搐~-΍ˍk:,#=߆M|)de^-=g Pbbfa8'&.`L4@AXFgibǿo2d8tQi}׮b!ϟ-=xmxC+Qj NOG?\ޤ/o_SS۷+>YFy3YNGmC<4Y52x&'f.? -(%uNUڣgF`=q,[ko<B0Nw܁Ot%G!>IH42qd5EfD֜gYa2[졷e5_C3LY?SqʔJE xK.]?yt'pRoj吴$T_fBnNy#uuj*h_yp"Sk#@<tXqPc#͊9%mOlUIحJ/* |cN&_o̔6(=řa| EX1'KD_&!̲1!^7$)pF8YGƀ˛jȔv@:#!LN櫵Qԩ[ lP!v\D<67c} A$$@\>- B!ldI1^4w9Dz6I=TdUr,mP; 'a 7_.g Pj^RvHiHXC^/vÛ1^G[+"c5a6G)[ru4U3/`6-LtWPY]wXIF\Sü\ sgtW=0@S,P YEb(@`[(g5;$Z^ hŭ>җqZeyGDﲅPT\B%oE齷'IJǠ~>|2F">92O.TyE{̒I e4Z JG1roi9Yߘ~4SwdmN +T T"2j $%t$zٛ+l =|i|#J?qs^M_!BOq]ܼ gxa'bbBM 2=IqpW"ڽ-.9;I%X*Bl*UV:Z-<hL{F[sKNڊ>;Z=9T_`,ANzgͭEn"Jƨ b̦u[סg:^} RYΚԎ܆'+0v[jT49%,l_UWDv]ߦu~`¬E_Avp` z^}d>eCà ua5,3rlېެ~@7?x>MA@nTt?Y\o1re>S/zP/#0tibU^N\139Йߐ6BUN`u/r 'ae>w悸 bfLſW:~ije?{ wՏclRku9AU&U4)DC0Οx]Y $ h=#ߓ(\̱\^F6pckS2ˬՑY_]F2HxLȒ'ҙA"_̠s;n3C$%KP G۱H8r\/RPkhC:lf|tX930+ JZ*j(o~ x-9ff641ל1:]vGnGUq0l-f8XD'VR_@ O|s F*OG VɊ} SHs#19tr<%Q'ϊmQ# c ;SZw %(~Sr>VH):Zxߜ}~GDF9c-˾CMt(mfZ`deӷ4V1XJh1>3G WQs`5籁go&󻡮VWYW}!0ELm]v tFꚀ&)_2rE4pvtя8H-9^S-0T5h_Cz` $$#=KHWv:P>kZ?R j$Iv۩u A#O|ֿ" Geb[NޝKTxh+vf-,Onq _+h3Hah ⚹CSFc]$1εQ?Ǽ/0QzZO%I RRUөZGVSt댜R>Gz/Ie$5&g Lqy%?P]szk'T-Q9%A*8r$y`0:e h3:Hm+ .N}.*E\>&֪^zN+˃[L+Bdj}JN o(1U/Ewmxۅ=i~mP#vms=ѓJm4715[T}yu{W;^Ǔ9D~5V49PiصSe\Z+&6'\TOFSD+8-xC^iF}xz"S, =2ɼ6<*zJE!78}:0:JUmTc`]㰾ަsw1ι>|C9ck'~ŬBvjdQ1 ,3[2 Gr UgscqK]'{E/@$MS׊PB%Tik5Q-q/CHҋwd/mZx=mL_)܅ NJco xVلOqԞc&5kt[(%2΃kySjw &j:P<YیKKB1 ]5i.`긓d''L~sק_?_K jͧq ꨕKԃ$%y;ךv+ۿDq4f\늣?S[aExbuհ JǫFW`)ζ0.WGeB0s$NwP tUwEg6_9f-9) 6vf;(,ٮ8"MNExaUXgy{Kھ o3 ^3Ae;S=քHrZZpd f;):&T/7hM/.}n ;Guʵl $t8kW Cf9|æieaXΕ"szְ7hq*\f|WC9~RsB4SKlSёȽ0g zsyn&cqFO0/ms̈́ۛT?o}'O 趢֮ #3XVN1"M&P+;moKԹQȉ:=ǂاDWzdVX +SzT2%B~JNQ9pמּbG]AMrf#JZ+i m%쟬 5*d|%'d̈ 򿼃 xq&.hu RTuK(QFms KGYnYc7u@u =1Mu\譄`2׺fmlE &CriyLt#U6j<^Nїϕ;=3JXR>Y\9Tڅml1{6(I^}m '>6#eL2Sѱex>u2ۻ:]ȞlPKـf@=N<  >1D5(L>#$V3S"`f> G&DZVP:J 漤JIc~:sqxRC]:/'&5`nWx>bݨ.4:BbPLtU91S*GŽ/&h42lՈ=EC@YHW%6t2aNnzqw<$BC4`r 3C$,_=i}z {HsMzж8AFB,Oc)A®Yܝ<ړh5]nw&?ۅX愐\'pbaMG=#r~n{%a(=[Ż$>SP{ s4N ޝ b;͕1fOY.u~[`i;Us/`M#8QhWAmCVZ  kC5y ( X7 '2; )n(ZrnйN -~=Pltd bvC ?*^%R>&{Zny*X%ENm6&p-iŃoi@t6'jZ!Q̧)_q^4JXV#L!Y[^֬lX(rB W%,|QUSks-/"8w!oǎ gÌTBvZ,(ILÉqb:T"d(Mn։j߇ cKa=)T^fzj<4*s*i]dr ,QpYpJlA5cKrف ԓDeƘݥ]摶1ALo5&V')J) eX6wIk]x$qo5oUCRjHh{9`%Pf}sF9Iև+|ݒZMy} lA$)iDpS&[2Q&qIT+yt^]{Fd^oR'k͵蛯@ץ烙z˔2. q2KjGdsQSӍ1Qp 1^jb ~yI>V嘡?|oަbϑ׳[}qcZaL;˲vdyK9(1 eB|)-υl0+ z+A@@@}fkȵ+GqDL𵞇tA՚RHjcܝAhͨʛf*o ʄ쟳$#7x_\>qq]dpՀ縀Q~'@Q[4"mySQ:Pe<"7T۱kP2bH w<؄ÈJG%jP%dr $|nK;P-юʟʨs_d֣S5^F_4:NvSS-W0YF=eg+lWP?h 9D<-ܺƝ[ioVJ>ȈƤiYˑ0Z0.<I s6k$M2mUsY Wh֯/]4RjCd&`84l2|/{(Z:YȫMXT"=O~oxa3*mSd/= -Z|oz_HtQ7JJto^\A. $uqw,‰/Ɠb`^ZVa۸|Z8S֎4}U e^w`5vC->̹NT$پ>v 1I @VhRBF_G(?v<:;-3D]+ѳi\yo_UsV̵+ 7fzyƼ8-z][v2Qc3+gRaP_{)s]V"$?>exݚCoZ0Hk Ejy8$[[bbG"MI[ qhJ*fRjہXMx޵-!JOkP:RdWF6,sXF5X򌂰}dD P$w]h~qn0mh#<XzT~?z(lW%>Bjt>\k▀m9nj .GBWU \=`2[8UquhbBQ͙ vRޅq#g~g8J՚gPg]B -< \EMdap {{Yex6qMI 3m/CC: E:l}1gԕΦ9VMp{[([zRAH~B| !t@)IoAT˜ ^^?)W?J<;_=A2JlԐxF` Xyo(Vu IDC ;P;MQ{i'i`3J0ar--5.PZGGh4rS 7fږm]But&X/lm 74~<oZ UC3sz|DGeAa~ Dnhػn5A^ \>3| ?U0q}łFe*nM ɢKU9}`m,)3(YϦ3j\"|JҘud#}d bKmՎ{X€!k=s{ {`)O+{ފUhiY`HM_0Kz3Dy| 7lϠڰgRT| 6<$#߲šJ;eg3%:o+0432r{`Kb]|6߼?63QFOƖ⃐W%Gc6 (TPЁ$y4m-{Kn2D\LU[{gs[UWp_]ۢ*GwWLPerhy4Hh #qpܟbI)$)w *J/l ٿ– vkΠmuӰq-An$hD'I fi(T9 KMrvm݇u\qk99 rhax`=U5:p?1~Lt 0\:jL99\^4F^Dw~\m(`&ΆZM5A9?1xk]'\Hc>Gk4ePSCzsZ;1y ;CVC㒗viQc.hg z7He~ #SĆ `B:FRS##1Q?s vx0)U:PN6#oѸy[H^m27RfiI \2Ry}e \?TX+bT.>J܎-m[vVR1v􁞍?s^kmO0 RCw<4 m>_!@Ea,/.]~c;,VD*Zfyٷe570թhdkKq _Rl&%ۡ<=h^a\Ip`4ܣcEA4OyQ#bVG| *dz#ifkx:͚:y&xk8֣e`zw?aㄳu5:6=S2w0P[Ah;ApSyz"E}_ΟM){a#p5C\M5kurU-`]P?fjQŇ{\ӱ{ykgͳ*I!N~0*5y:QF,HE8 hx@lSsn~lLL"/IZ;*KM'qQ&OڕƳIm ߜqo? .?p2<@/Xo@9 @MSDP Qc26…qBŦp3`eoNџژK7耪_ЇX:tl[aoHc/_(vX@"dS87zGeD^2mL(X`?)9q_1*?Jss.:OYv{Mm1,YmZs䝡فv5+Y\7)24(%u ] =);o=Wbux@yoY2,jlv_BrkD<<>F"Q@u^X zs/?z"S50rw N”xj=]TŸ RP!߼՞{ZN} \y֡5ʒ}Wc?CUp` 'DYbΓowIJm= l+Wxho۠x(73|ѸXe\9Z+8$%M-7ZӴpm: ˈ`>Zh p.cEcٔ N&cpRBeQ˭EiwD:=O7[=Iyxi[09j3P7IpYiɋS9@fHۏ"wPy#  !lB f*Pm+i sK3UvĜY&ДVweK_kS|<.n]g\8Zb,bHˏb1O#^ԱZqnc2Ml<8IP}3ةVZ½.G %`XAU*!%ͷ+}J'm=ϸ`9_^TTI҆ZV݆@J@ճ//뱇Wq60+ɹQYAy#:HLTc|;GH^B@7𬥨?n#H=}l0( 'V&Xu&B[~?80ƉQҏ6l.-V+9m, RsVGA^0;*,\~Vy3QB4VF(u_l֧ztV2JUsM;prs(dZkbѯ"ȊdYmt):-fe3&RǦٓZ3-ۢxEJyhߵnHC&s9׈ WॄI0tO+P|:fk,yQ4D9 9R^7^c Iː;b<;w7!|Y݀۷2IR\bMX'Nؼpߜ _3 ׷oe_ ͛3AOT]ق\q9=& \ w ^KituC{]k[#r}xNF~"W 柔&¿ %vdaTL̾M*vzUJ)A~ᤂn^+ ֜@!D[Pd6=^K*u';/η7*` Hq謏;ٝb8*Q LtY2pEvHN-ᬕ˩KzZ)Y^7/ح  f1<L D|p)I,yjY}sTaroy|l@*߻fUg0>N%w/{T|5hJ0זШ,؝O ;>"tX;o{0}E"6,%,rQmGz2j3PUk["KrO;;X>l4Z߾zw |XؓͬؕW\D%hn~WtRH0T]P'":+!ZΩG(Kߒr=h®)زˌ J2twyQLys٧޺ZPe]lĥ?Ij;腩Ԭ6D^no*S*tq;*Ġ8~7ޞ.XQ&s#,ܒ(Fogqywisg u4 qw ȓ}Lk4f |r0WhAOZf\eGoz&҃5B*B乥_A6ίNW K} @yXV|{>NMg#fTdͥ2)–E K3"VȊ"2l@%8kK`h"d"2@iEŕ fIĪQbgQHǧSQ*䅸@ D61Yv(;9ǕǀpHHvjΫMveXX\GIIag(pNJR-u-_' (P] t(W,`2F].ȩ//dsMm`VL?Vt e߳Pv>^jfψz}mr9(QF7cRapU /<@oI3~2/,#U>+xڃ ƀӟQEx6p Qկ1Q"}{QY㪘9Q?4z4'cp(Z ;36¯?EO9e'ſ?|q3"φ[>*"*=/4.@CC\}^{TUHꟌcQ9mt} cȳ/UgX] \ C X_CtF++=rr/!8 _8dBr:V{=`B &zQAY<*hc|?OaA b?W857ЯG]4Mݙ"7Rv u>AXqgy\ݧ-T^po@HsH, D/͚/N@ `*DF0P 1`mJ+ljsk{Kݓ:;`t Xf{ҡ|OնyW' NL6F2X"EĐD(eIs% ~eŐחghCϏ"2Ur{*ɉ$h'D.Htf/(v3蔼)8M{߯ri3{ U?Z@7B@-+.;qC>C VPzsqq":vW>ᢱDR'[b ,TH{e]uHߵ$2Zu6j!=,"~SO¦6mQy/pCZn[o#d38WU^΁ީ\^u֞a=Wr OSMiq9Ii;'k0Ko ŗ+u(e6]Ua1K:zJlafq"A7LM|U `-2SǼ$^Ao̠ƛWu-c:S{SlCe)51\p?,߆Ĺ4V]L`>M0ɟDlvZ_~8$vcHxy?>z5w{VHa#NF#DQ Rmث s" ">E oNAi82Gn=V%TV@=܀8'I).ag!Iq/Ӱ9k&x-8.H1?:Z%? özLY<ޠu7x瞥H/oF*߳h}|uoPo-KzyܯH.ƫT٨;jdt.ëNX=ve"W]lG,֠C/(k5#ϰuhwo`+p +^K}2}o8Jt' WB⁅Uϕ¶cAM깸 .Y A_="z.0w cq.5 xڥ 4s`t˦~ڧַJ@OҼ;XӒ@<ϼ̘ Vє~+h}z&3P%Z|}e}G?hB-R{**enN0FYl{VoF?Ɨ))q2d>ݦطԍ9cxDhv?3=rƎzʺ24@?^]4YH/zdg {ݶ FŬ _׺nz<(Ai])߅01jzCkVj+p bRnd.9V+i37`+s{@!hbcJ(#2;[ivP[~b1ad;Gj[)~σd޼cS K3GZw,ͼtYqAȬ W"T+ 裀9ERq6tvǨ|YfWs ev[cnəO.jw&BYNݫ 9a~bPH)*Xx0>*,GM7{=e eQn&΄IXMQ%>"LCAw] ktbPP,Clj0Y# ^`3b ޱ\![f8W|P\ۧS57L9xjM3!?,x Hxe&t3w%z[N'D6cY6ECSde)'!oFul++Y'8b|:&jCoRQLS2R7d>qD?%륫mc֢iq x}%V+Ptf1F?kT ~eT0 1soF||C],.JΞBђqfU4wVFP"zYz_0PS*zqA%wSYH [@8yp|e }nGaO;+TRn),W$0+} :q ՜6D"y_pU+L$5qbR+-$jL6u>zw,WfE!3zS8|#7GAX[ :ł5\L$ kk|NwHϔ"}B y2VP[e~jAE* f8傹U"ɭ|.>)ጺ/0|c~с%kQӎpc#g;K^a+AQVTth RWnD0Ip&BnT#ğugCPqa,da0~7Z( ZMxS !uʪ<"*jQ& `WtڟU9oiad#>˃=*HD粁$\cK\??G桜uNZ(_^`Jd<ܫd]3K|Z)^ZJD*9ڤ֨}%y >?[3BF@ڸz]%p c>ֳ٭ʴ/ȃivǝjK9/8bm3N.<+(c B^cxةKB݉ Nv˜4Z@@aY#l$#6"F5QU53_ۭaxz`/m牝.B \ud'E*v MSVE! ZJ6HVRM() g1cf NK4LPʪ4;.v]3!(kR;Eo6a`=֢U~n)sOj$ Ϧwoy1@Y& VX0|-sQ&9`6uxPIpp].?%udQs&XnQ<4QYN3V:nR(9(ĩ,&1- *+Bݧ9/Nv8P.񱨎30HdxS$Ssi8},̕ Dwu}zAje{zꦸb2`OrYyvUr}%h-Π0yݓ{$CEWTTS Zu2U.3l5RPK/h],] ;9vC6 cx}Ƃqx |aŸT@Uk Tj.%[)'*xv7it"AdxxنOZxf˰v#,g:?S# PW1m۲8Q}%e-7p0ޏ]@Aj1h]c$LXRH7V=%*}Nc$,1AI(>s3|/@W0"BR9;MAmmRX'D)ӭmG:җa+C$(lv6  6NR* 3e :Es58~!2w-o~xFZޯ jDJu )4,J$%Q"M mR{}oΤ5jlÉk<%[ Yش e~64?x1na3RNŒlL B[ eu$sx́*ɷU~1#dN17f-&\pUZHxhU.a,Aq!нdw:P(޾-B*nhv ryU2\PWIT3l1 \ t#@T-qYEׄG:2x)8m)[kqhJ"({&hC7fRmksm.MIs\T૬?@v%sp ,ٿLߖi[K PA/B䒘ToH4ů$_jIk8 |1Mu<]?m&סxcm~sX@ӽqcm/M<0m˼T Z?< HDgdӌY Kjj}䒘 G>>qgQS6i**- }E @?-YZ(u:?Q,< .[Cֆ:CN0n͓ZÈ`β/|MB>1r*o%.Q͕+ g|6P3z"եQ=\%tMyga&_N@g8}"L2kT}l~9a}\KRuڇS5<`.$[3/)ӧڅrf/CO dK>aku8" z qO"K{vDA6r,G=Xy&}+r,Q#UEU +L(0XK6vdmJ'/`u~7Ɩ(&"n[#P%1)P"L&)ׂ*]O[ %<ֆbK `;Z+Y_Sv;)b%TZ~ pY5oܯgOY7fƀ%~3i9;, Bzx A5OR  +~(zo?RXw.rŠCzؼб'3(C wKM蝙L8C:Ņ(!Yx< 1"i@Px+Z+d{@fӜtș(ky3Hg oHv_$6Vu/'0iDTsn քQX~pYȬ][)KڰJ *.mM=7̼2C"yS8x5#NW&+lN-j Ez>ƲNUZ:O s Q*yyfѥW&]bi+l%('H ITW]*$ DQE][8F/|%WRlcOՕusP:kad szJv;r$m^;P w6c eCM>NSY4  6{ֺV}ULֹz γRSdz0yXH]owéI gi^lpdU8'-4Z#R-I,ܻO ]fBQ IQZ:Tj,\ƛยF=NXdK:>=^MM/bW~t0ezy?"w n4.SbOD (x)~O , [4n$⒘]Q߸'O?S@d2|ML ʸ$0WU1H51W\z;m@qekQ#iIƧiprTњծ91,4puoG#.:%Y2 ^Cפ5| `xg= /O *I}Ag\ppLnH<_y dЪzʛ醳 }u;FB n D? JS2<:/1j*>-:UMG_8=)Hl1p0Z!Bp@{\wRImxͧB)?QUi.3>-Tz{-,Y0 n֮^} aeD@#Jg^[ ͂@ L+M RIl"qG3TD 5Aا䩎pg^X!jG^P?I޹q"qv˲9;) @)ᣛ'4 "ƊM@'}H".s1uI $JuO^D)O "ߞ`5~8?!Lcd7b[:{Cpv\P^|6"I@;~-Erq"ݘc(#]=?l yR SpDy-+0~ 1ԏۏ z<|MZ=~ cI<d-aC76 4q"Kwvi# >xg?S3<6ctb' Nmj=ϙ6O"'8ҫ>߮1\R7&T^r:F=09H$aSOC{S X- ThZR{m<qv?6.qlEDw qt9%ss?,jnq^8c쪈'|`H/KY3y!K,\_:1(t; L=)i,J4\6x58V/%*AD*IPHk[,b'hz^ۦSZ48+.O/?U>R3LGy玨WœP|s Xd( HMcZ9 }ȏ[ӡ^,ֽ*﬒~1wɮS@Eb&RVCe:Q(6벬 {vsS CH7C [$,iBIO^1F)/VG!|屟o^KVW54D E|hRwOO2@ʢ Xс&9!MxZ7Ra\N;SE[ r2bxkd$'{YQ.Z-.؝o+"asz9x;=˸%J!Yߪ} ]ܕLJռAǻB3}<݇` m?~><-vчR3[A9yq?lWqfϣY'C@kol: HҕSARtFU{!fm+&57[CwM(.Ȃu"hD43uxWqqY_8?o&siδ/V+Bqr[ws|W ?\OY4^w93ehc7m4Nd)谓""}H+OdY"Ħ*u(U6*b9<~ƅR6q-C0V2Af{A:-v…pAQ'eWpѶbBuU=g2P&#{ZOVa:`7nPׯSN?[QXC6MT_q*7# 8tIu6[ÿ_fSGUypHaJ¯r icFUZvdY<eLF1Qe5$j1~H Ug>m!v5@~t\Y%vʁ(+=Oe(6 tǛ$'4so[fdIʭCsWC4̐,r7gšN"n ҧ2I hīH2bCP7I^3,T֥L>trddzvs S0;]OV*LXV&;pnp,i5Ԥ*"ia+TH6б+P.%2ҡMyٴV$O5셬]bttt}H%'F gOz+T!'8]g@"ol~ y!m{T=x[G^' \@r!b"By@ *9]vavB^p5iĥ 0ًO]2wuC1s#MX k@Leš}<#dDFc,LΝ'+QJNٟt/^ 8*g9k(G2 0sjasoqQFIw,u'-Gve(+ʗXak|)~-A>]5w=Ƙjk#6'|A~$Â̕6,tIT!T@t4{)?7aA\A^$(.aO|0."לѱ(viBtDi_kK5DoCJ@O>ɈW;'^'຺ctی.R m7@͎Hlo~a-(p?Z: ֯"dXїR%(E>X6)IG4MAO|QLJxS/;>EYc˰, '5n8me)j('2a1Kt>xj׵\ <䋕CxKJ1ZeN1q)J/rt1UsLLg:&Dv˾U;-yIyb؈` J<*Ā W.:{ n gN&T+פ* DN.YncyR)i8v> ;A2 .oOQ1'$H ܴY|c@鯞1GL Wˋ_]mf(1dvqW l `xJ: jWAku1XH'-j`yCOr;LN|bS0(|QqD$&\Umhޤ :4/ARW:yS#` BFUHڜ0l 1+f|BԜNX*MlɅv7e߯Brb[K}TÕwY&ƶF44jLlC&s>[QGgELEp|T*z%=OA,{1F;0ŜH$rWOo,'7fZM yjMtG:I8bTLV/!Ɠ̌O}L -E1B*> B)ngO}, ɮ{7lki )EKK!2#6 hƀk B0֦nt2 5Zte+_Q=x76wRRlQ:H@aȆXoVr3{;# EfGT jgI&eV]QVa\ԕu9Xؕ')M9$*g0yw=qZкkOeH}k4Т&:SL~tsr9!r $ Ƙ|'לq.#8Wq%hHX}/y>F͜gpc!e8J-C\)*0t07,@thFnB" f|]Èb-^nP.Yl2%;E2<3xjXލC_3?^Ž>tm֎؍][TZ5[! QE #0Ecl%vc&EߦN9TsOs겼Pċ psο^Eof*l>sMNNz_ y\WNX뢏 8Ȥf”4[?8wrO'pt]}R٫'2H&SjӰ;se4= Q@ b_=㲥:Rïy Al"}ğBEd7;hf[ȒFGy~CȫG Hv̱yH[%l_jߒt5&36yqز<"6ZiFQ )7?IfpĤy[^~[l>h֜nYݽ` %?`sZ󹫆x+ 1a9pFd.4fcTDiy*m+Pp؄PBR؁Um'r{ێrJpt`oz"Mos?!@ 5(*KL$5|ϐ$ܜS&#7,`vem"*tT`k0=9yS칣 Rמ˿yݬҦY"㾎^ Jx@0œRg҄Ģ.f##go8P+3^n=EMRh_Z̓+ 4q$L0|>E;ޯnHrHJgj{M p{pԌ_≮u>Xp5ūv҆$XBOɳʸ}(BAbl#oOEλH~ZIy}W 8ZW(\=^|ėuhe{EI) c-GRkqYh8Fw>$% !m bU~ "`m7N),);I/IGV"da'Я.?JFA<)|o @>^f!P=嵲_#ϺU)*6 y+xʈvHHēfW dXKjs.՞nYs A1*vہW2Owv 'ZH:H2lGlN9$8*-PeZp n0ZǬ=D_/8G^Qb~r泃3bׁe:v3`8+08Z>JR҄uY̪)^삪.ZA q9iE^.,. $òIxC5ʢE4\7!9Z@s&by."l`DxZ^s]Qm]gI9ۿpPC=թXKB.x7#Ww e=` [V?N,4tXך\oCbE5C ' ˟1c )H#` WHku$ {(% _f)ߍI֤(i}q9Cμmp@?L@LrCvDI YA' 6]ԧF,Uŋ~ -5FbZzz7`pbЂc ݳnنzU^P(AXZmUv?0P*+1FD wQς#QXu;{$eHw ˣ39u鵳F{󘍀%n 3tCmU4Wo%F/ )l`o%6Ⱥዊ<{fxE5s>%`̽n7_vtaLczn;; eY68Ksa 1vC] 8l-lЧ:Wz_|q@dm 1hhW;=`EK 6p2qĪJ'o5mң{, (N-3ԉpz^R 26DPn|xr~t'4,0_n)a̾9Xpuu(/*RH!&͗TҸ%TC6(9RY#C1d$OZ[n)ӡ6/8Rw^`|]7áurat{9nxްD<Hq%GYx5(k8!8cpz!V,N2juV9ni  Cכ:o <칯L^I;}Rkq87ynM񈳨"{v"Е2Æ;CʃC( ZFukvcqM?ڊ{}ku I0ԾĆ}wrŋhF5@Iz#MxMTZ+}ĝK^Lo)Q]q뢵> SEX Be}j7wWl& \JM|s&P]oѷ1\PmKMۥB8R*~ҝ_" 5V 02r}r 503䚘[KVC%y)my c}|MĉRQ=.f Q+F Oĕ,Oi)Q~=ߕ]HWM6 0b/wVAq%\|lx&2L<[l$Fe(o}. M@&~9U*&m{SѪ;Q~&3q ܼt}c7דh98`Z>p-L,dQKFMNʹ&RRTNEqֱb{Y`ݎ@D!I)NqLːS (8VK]BP(Z&=6E#:7`&W]pZN*#D(ZAF %sĚ+%60z虾sΟk+ @mT\Lkb"x1kzPzWfgZ:[k/3\ְ5ၦcޞNi ˔ 9u CfOڃ>a*ۡ{| xO}Raa 7cLʝ"(DMD[HFD:`ᮜ}[F\W>rZGj{HO(<o7 ¨-9!|Vz&Y$ <kկe@ )e1uNao-t@OUZ$o9,Q5LT9:r*F1P7S<{S-juqP3bxfGT6]*{%L-7c->xhn G60߄PCVc[pA}i[%/ n<"~Uu7> ^_}&."Z~^֖H\ !*K^X׎;KĦ\: P 03vߦDC;V]G !D_cvsE$r $4 Z: 8 %C殨 <[XH.Gk !Ӕ~n<&(NO%M> :+_e+Д'3,g#1:J:хŁ:YO >[XܥSLc_#F XeuY,HN=7_Gx9 J]T: ^|s(CMºϼ4㺘xF(PH4U_%zs+-+e%[7hm+vʡ'9`$els*Υ3հ`-)5բpa,;x+,p^MTbOǪ~ W"v?$Nl'O?WzS=VF$'fUc)IڜdosK~RyjE+xpvN7d v@)Պ*ܨE)S[B M_n2^еA`R((0NG\A||zIPsf]N RBjVa;U @T`oりDD "Xe˒R?6 鉓&!!F/~o.swwHJYd-PHW [&7z 6F%Wj2@-% ۦr[""Æ] h (sC$̃M r ls@iSǏ{#/t]$&VCtFPc=ꜵQ;* 8V>,t(D~f;nn*VXe^k;D.MB#fT-G8[0ah$vRSQ2ZSz9Tp` y=)\m%y0R/ ÇxOYc@rvAOx e!r)T F1z=lъ&{̪=f?Sˉ)wu7dtAN7'e4O#d Yni`!+iH[LJ*cyt.OCssvVŪ"USUg |cF Z {< 5x};1!iTfnFp\*{rKh7u`%yﳃN]hL]LlinE-qOK#VH\"ҵQC0](A./ DԏW!3`} WÎE~~+EC\"ietG3E}(5ޙebCI4>I90j uݗ+o&e+2)j3 Dɘ>WdEo:Zv[%\H"V\ F0&J) XAծj6Ywx58@rpD`Sb&jR'xjwi&S'v@Ty^ɕ Ykik*3#ր M; s05&.'}5~o"PrܱMg\M<}!3l~KU5ۉi Q֥aůk-%l ǛC eY͜sXXE`5 `t78)xvhzDj/ؙ:A=#UٳW~B *;R؜?m^Kp%**npKo] k`BDJlBS2HLM}}SUИbNɈ>.ʲ,#In."'Y?MTҧ68Ptq!#W"1-lfN.ok ק>7(+BAljdŐv~s9٬&L|g -QmHC1i']xk㺸ŰNQÝn P!Sw(nd t,J6L% h5GLg!"&:%&- p=i+$fzUaZ *Vo0Cw||ɊWxom*֏GיGk)QdWP.;J_)vogkXSyƜľ] ceHA :< Y84IAmOGa.斉o hkC3Rx`^EIo2_6"o;kgɮwRYJ&s,9+a` Im8&lF7J6snh1иMDm2ۀZln[Qy˄a3 )ݤh.PT_KeAL/2a<ͬ^ ;L="GbgMJ1S;qTǸ0ܭރNv7}r_/!oX|-Rb_n>|k}T P/_> j>My=",|GntL LC8>9^z>~Ț}m"22sCN_s78^E\ηt.ZMeyltdK6^K/@XǬu~ ] Cc{Q𯩝q,9c2Ivļ\Ds x*DlՇjWCu/3ϓeZSQpt$8L|҃MTn22B1w.-hFp"H=Q@3 5f2ml=e g? #G?bMy\jh04'aSjrJP7|P,hLA/%q5 >R"v 7:)*?phC» [Dv ja܁*t#t0^ j(}ىE=t^|hXj Ne"4$-4u{rӍ(U-ܥR,`g48|P#] &c.@ӆM' )A00HD-s"nG~%3J}\hjO+>Bm?e<_zӂa n@zx(靣ZI=u6+9J9g& MY?u%.ae"T'xo}}A -izoZgטR?mrZ)/^kDn@T"P^-Jrw;Րͽu%H~(Bt{I+4_^aUYsa >ۃQBvʶ:ik7N@.8zKmՓehLu1j]Mt6QtM\W@-F+ tYȹ!ϱ QTEiסk(2TB5Sf(ƣQi{AUEkv.Zi>mvB燘$_A vܷ<#@B(۵5Up#{Tsnud^(:$AUPǽ& ."lg{Y^ùWQ9sSVfvTVN "b_[ )MZ+}UPbB뇐g0dګl e1IeՉ(jv탫KzkKrEIˁZ$:kl=iYs0dP1Gu;d:%Yn[m.pPYPZ U|7 !v!w(-ELʥqc0 j>iE-+fZ3"Ώo|{ޥ6 t00#E ?[4(ů /P B0@a-H /+D *h;?px?kzp@>'PDp"΅kֵ.,_JbnMQ]۶ ~@d(ID-NatȰ)s%5éxl;W0^4a9RJg'ùsvخp ,iuMV6670#s\p◀0%/ot͍MRsop7mѓebH))ewq:jdsE;KY =c#aEk~yWlC@x Ou&AYr}\]^2@6 ^7z j2BD|ZGT.%COXe6YKq0srfYk{'v! "Vy1DnQEI?[ٍ(7Nw 'D1)4 wu<1 X?>f_?倈pfp꽝\FMSL-/!T|cG󎗨>!?qcU*@B)c|YG pW ;0anQ2 RGDsKHP-˥jHw3'JUٻ|vUݔ!krȹ :abm7T#d۪xpI7߆m8F#K13*j( ŏjэz {Bߘ;2Z,ɬrn t.QxC(2%I)3Q f$8@qFR̎C(`* ~\O`IY6[ah;N?`SܾMHgrwF?]gTUsmsOiGag'"+m=M΀L|Rt#-cY`?7VwK%Q-_uEQ>i9>A@ޢo; V e^+b 7[7Up?T:"^sV\Hdo=Yk16;"UɽVc,aԶq%b$ f L!]Cن`‚DkQ5"GRVXaQ fN7E,؎~k.MTPȴ?`:U:[p ~'{(Q`ca"B\r~d-ߙ#d6VrW<Օ4utnBg>$Gmec[V.LxT]$+Ŗ;iSsg_;3蠮 ᔏ{:5cyr.٩rArg(\2Ŝݳ( E33?cZ^Jxoˡ1*(w'-?ǦYpUu!Oy5GoFx@DމmbZ(`JfJ̵,nM[ii;QJ{Z,^菶Iim9[1{qOtjJwG' yj>pM, FB0[4 1j+r*MwT' beAuRZ1ো0&4Mw@33T^KairAm?:(\!cKu;q6N[qwŴ?!DVCk{fh7m|,Ch(8Zf^X >c&"ax׋8dcUqAJpMzbBz]jSܜ >6ZjAЦG7&fd`xcdCJI;[?#OX½0ifPf:[ aA6r[KX7[UJMc )\00EYqtdln%W~{Wc/6ꬔrm3|^uCmj <ɣߟ (&uv An/ ;`4>i*z'Sjp -C3Q-д'H͌ |H4co5i5?ޢIe̬ic{ .qq ݴ\#r [A"bI|ae]f|7QٓFaY:)]cGxDB>Rѱ]yJοʰECFk +[$?oF@_)R~j!T{H+]2)"UhspebD˳ "x{l8>[֠"oS0SOM&'ոC%:UIȼ!랆?ex^:vYWwqY`щ< G#51:}sˈ9h#QƸ;+y5_,=*09Lǖ  L BgYozU 5 VLh>/wĀ꾹 ha/BZv hmffCuenjoۼK#lz !MFr4sc4.D`b4j8p'xC<DLKX#.oœɄ8گP8AHkɵIB9CEDSB(x]<58X4[6Di>S,2|Ed.UȔt3MUM_t`(ت xV ù>=TA v5wCVǝXm1k)EH0ԓJqǁ ]'[a6/PG-ƓR&ӮsL"yR(X6ͼG 9y,2bEl];yoh}uW#zǏlJ9bYXiP6pϹT9A5 Kv:B3Hknu?~ B^XfUE06Wq/īYJut={C?gֲW+ oUo,nʪNtY`}(PyN N,Iy48~m8.O-W+@y -Gڣ鮞U5+}F Rav7WZ[]]vAg8j^ hӀ砟R5@ B`sߞ; t<s9XLF"fq5wyjo"3r59s7*jNig.i)rZR93"21(2fXիPH:3b3GW-v]XB的O\LS"L3ː*G+kFVUL- Dk:1)g cvGqLFȾpejV8iZ:*oX`S:V`H3~az־`)CY6S@.窕S0Ȗ4XR)/FSX9[98RFzkF'L%nhW]Mө`:#ٿSmMm{ QuIؑAq*=A9ENV[|h3)Fpw7֡.Ђ;r!,dJm%aF*fG௮VWad Lj1yoGΘZ"tElDu&%9-ܥE?{8z{]ϝ! 6-c!>w`*t/z A-@БRfOMToeN3Мip#.vw!KI LcgAZmj0Up8}l$v_[ JRbN+uR'X.^b5 $,=&- *U-xNk] ]M5x MH-A)fzjb2UOz4r W`k|lE}8Py7!cVDJSV݂0Q^Fuy8t[рQ3H'JM}[EOjUq(lE558^UQvVѥv͘<K+"e+T:|r]  Fg5c6E`\ #gb Ѐ{C_# z)r3/:Q[Lt}l7|2Dql.Mس7`s@0zQXfUn4Mur׉OW [X1j(hců63RT׺26M󬝶lRkAᠺG%—ar^:v΃jx*u(ّ0rp%6nFF`_is4aq@Htq̏}[QHj8p^ ==i"@&~`[ Ej彜L co>ns3jNH3&"Up^JL;% ~DM+] &t=F ^y G" 9CgUtymjnM`U|E2LNKaQ+p Hˠ_(pȡʗ?\RG[(1N )nmh./c)&9:}GNoe*FA<:UuGƘ)gg=\MxD8K㰊qi #4\AN]M.ʟ-q@jyXwalZKmGH,:qgH)/&L½ֲvxc23x8@H h+^%Ye,'j`UlɿڛRNkUĒ`WoRf#!㶸҃aL?(\vyL^xjR(rKi؝p u.1}c:21N;mN\S [(0 9IJ[krGY\m {lgYHH( (dF2:V U\wY.X؅JgPqRP!K8"5{y»>3ޖdX݌ HQ7g >F$O@`O4x /^L%CBTQA̡;+CSj4qE]!dUL*Hi',+| $⎲,-s<  x:DJ&U5};5.at$6 9B4lSqa@T^m,.A{X_V כԁ"X G,l q!EHLKoq,jGhoiD94yIżL6Bѝݿ"IX)#!"XlBPγkz ݡBōѓʹ"/g ijk .OG5!ec]r{!P,X8 (1amdM4`L@[%Ne x^N繇^dȆP(lc ]JPـeTv-`$&uM &MŸ )= [J#O @qҨmsd+<-N|H)^dO4#$]C rۆv(kah$7JRoWz"-5WENf呟P@1Z[<ָܱ>1(l9j%}}8_,k^ vOcϺu>!!{k)Р w|ȵ93JB9IF#̡F&r2Fr/J@f72\&„Wִ;k$MWO6<['ĖaH;kvSm/̲6ڈ}1/u9wO8+M{H U t@tpEܪPR~zG[y@%:|pO5k͈^s48DitJUIAE0MCdsq>Zi0< ~-K΂P3mJg,LִQ% L!7CSKd.zN \P eg)2fp(뇿vbA?jԨ/Cݓ(fe=&5_f^M C/(Y]vxp'܇~ aMis.rKC.STաo:InoٸXiU⚀/l0Q5X~")#jr؞%c@g&bL?,X×Aל(/0 OUQW 5|9kӉbyΝ%FLYjk18r[$lP![S[+qd d1P@и -ebx_uzST"zLX[-h>@AV_«\ѶAYĪw]b'MYbFlSlx[I9ys~)\by$A#0gd۾ lj'"_/g2!U35!퉬o}~"QEslHoz:J$ hDKaU"Ň D&2'G}HhyQf._E-GͶYŒԽg{ad= k6$Iŭg-:>Qxr2څw.]( BE-W)\mc,+#$$*i>jةj,hov+hb{6\5u{r֬Jy/} 3HXvM"\vqeͲ-@G -ӎh'x~]dʭe|T@XN mP)yaH=J?煴LHEdZ' Ίo^h } T׽Q2 ͯ4R {0׊nŠ2|ܩjQ9t`ȃMSj'{Pn4 cBֆr֜N\f ҺoE+I( oE|0d&fW Jr ALb 400ҸDJjqiZ᯴bZz7M'i[r_2 }?|])ZZ/C+ebPWya%,<h\ #/[;I2*Ԗ !X0rʸŮV*3׎ZPS_M.Ź4 e>i'W ih >9?4bF1w/S" fxb5D!Elqж1 Iǯ5+6d8YU0{ fbyWg,#Y@ThR8*jzNs'=,޴wV<Г9q-d4璺_eN쫇 ڳ"e,0+@poѾ{HcJjXHmHk4]ӧME0yDvg' RJ"rGd_]ݣb#r;{[{|>'l%VUEI_BP@2y&b _ڱ2#$zcls2HOYq~uT [<@Rw7v)6|10 Ew Ǡ>M;u$/|m4Z,B' D8qx,Xm[0c9Tk:ZU?JQհ@HO92ĬP8LA_/DgvHO>/'{3w,RWpe8ÒL1/Hh!h ^$3̞E Y7e!N*'A0?|0퍥yLmf)Sh$.e⽾iӥ)P" U[:}'T3#`žP[rǴŢ+qs5fESa-^էi*$T nin^VWqWZ+^bID'AJOBT9}aAf]y љߵr-A!BJDHgG] \Fw`SuXL ekP?EzKyʊ ٜ&ơ;͏ڥuA@5Emy9:8kHV>-A(8EWme/H+f*A> N >K$:b0֟VȌx)3oz<5G iiЏK(Q2Nod !xSBlWP5kd&#]Jm g b/fIW Op ÚǻnCj"WC;}r\li_~x5ߑ/f&!Nt 1GZk=JtS~QҐ/mR]23DhmJUyuNVU$b5[irs ؊$ zH\cW̽Ϯ'P.w&`/Tˡ0^ 5!gko2 . 2U!( .w^TP#%z'iOj!T">w尳26^<%տU8X $-gj F:G/=m4-uH W{-GnMֳLp̀*YIпAC." bj{¥U J׼lB@veh$@_9RsҐW,`H;C'ayj_s៻!iYYr^.n ΎRf!ښ*IWk.}nK2; H 5THfڟdǬy~|IXC Xp1P-$}dVŘclӌC$Tf6|֣MB:4Wz${\1\Ʀ Å,2+tF:O7חgҮOdMvTl钙 UGV[?oT%hA았N^:_@~ –O¢0nVv.aIL߀̍F{o։ %qPuT~D)M(i!jaFzGhh 9Z$i1gUȑq$|ʉ [M NzMA>1l_4?Gyweg)]\CK'-z*aWU\7:%2\fl-BXVv ]u$K>g# Ðaޢ$9-ݛSb`l=̀9(m_ } iO<^+SmrRV#)3놰'P0o4l⿒ecITdܿ/n g`1`n|Kܶؗ6E'b0aJe!rgu4͖Ln& mU_LBC'g#ESsfT"׽L;Lհ3sS6K}݉dzQ5=J-W-' bޞ|^|+Qټ"Ag#+]ğKX勒 7P[_Yb} JjnKbxDV<~(N ˰doN` hV^$SMQ@%KL qX}f^nglH؅&>]@Fe*Z "gu$kN{?}f$0= xy^ikW<-:D[:G/`RSyܿ@#Qw-:bEW5D=!RAqo;%L!EP ͍C&3k7c^ <ioY9(WEzfZ#l?{3EجRb !Mqj/=ɞح<#9Y2TLio <~P\RGTelp4*X /h]f h An O 8=Lњ~SySqܨ9#p \nj1ATGˤ{,rӍhDA$b~1W~)`Ct,uhvOnF :V?%0 nd4h>`1 ԍ^}DLvHRNpGW{K~^tb&, ,$Oi>BExn*@Vc b4Fҩ/E@-`L֞n鎔pqQJj>9ZrO#nm3w*SPJrQnJuM@\:+.d ǃm#Wi=fWB&+r@H]\~/"mO<w D7FxH '#?]?|sVݬA%cfZă3Y¨"b,e/R^\xTނ$[K| ɩʗ͢e{R/]1Ͻm6,ʜ&;=dO%a"A;Ee|>coCSj5oX4rU~˹'0_`&l'gm^$M~EnȖz?g(y3X؆{~ݭGH[T÷]1!z'bstbR@p$64)('ΣMW EzE'r%FL^&r43Y%َF:i y'1haIsqYXcBy[d7#L~TigK}0%f9(9d76bZBd7 mr2+?m*_rL52DZ q A`EqŹSbr'gxz3r0쓕 [W{5q ô_Ŧ}4J^B/Y+w*#Ld"g" ?+IҭqVZ\ˤ\9t߼)t >DlAi#a=Rvg4HL䮹ɧ,]?q=EK58i!!Ŵ%L{#t^l tKO@oE7どɈzq.L6hWb%$~~31MM4;Bln{滉sso([2֟~;٨&$AN\%i{RDZLڥmC:8J31ZLi2ҕMLP9ؒՃ} J%aѝaR8Y_OI%0d0¼`L|8{5]:4^\\ɿֳzp MiSԏL8hɎ7u6k)?}FH ֧Iέd0p#` jzD=FY*HRC.溇\|i OEakpwW.ȑ'u@߰ZBۄ"&[b)׉aF AXpY5Rrr`;9!A$^8`um5aG{@[ݖr8ϼ*leW&3-nC&sNqT{u'RWӞc ?rDl,xX~C*eQw^O^.fBo4N`Hľxʊfˡ(1w>ևl̕3s-NQJ*~ZA ͌R[&hluH qAL3n<-z>)&'헶+HCz?0""d[=OQ gXr}2ȾN\+C3|”G!;INw RAG@Or9{ ф]\M#K`*KȮuDž[ ]9x#d_WJ\^gX}xoٽsֆSdH=~)Ԝ %\ c-6M c8'fmkӉZbny~?@[_}# &E( %/M@6^ siP(0j_rNJH?FjꧪyIl&0Q *lxA5M\p:\X4Z&F^s0 _{.Z~)tFDu\ ?pmuruWΏ7vc68;h:M -cL Jv3/b˂F` (=ytI )7<Y}O!9S -i&fIc~?4kmݝu3_9I8 fw=));+2A}Khܑ|/l=Rr{[YogXD8y8HVpI}:#t58EVlǯc9$v(=C]6ŁRⶉvFa1GtT@y6׭ g̀4tQ8;ƈD^Nk2G̏I^%N8D='|Mq7J8&C45Q0& Z<̐|:#}E&l|:t[j6aDcY+rh.G+ M)+po4k͙mPu|=кSA7)~߶   =k4=oaC ?3j}#w!hwG%!!\YhF[߶jpi6*U=w''H&)S?@=9 q*jwFeR5U.Eą OT1LjG|$.65}?f`Ӭ*JTZW _{?o~&u*(&~ڐi9-W#(jH\?maYZޕϴ^h~}u/y5=PH?F {{~w:p flknSvOYPܿD)g7&^3 %o(K_$ٝ\9F6jv|N?AI`8 ?wuMc 0têNL/=Un'):.Ub?mYG (ԁ 6x{ ^1a ]*R0 cou Un_VՅX+Palj@Q֙ȳ<`v&]@Y! եRY~ ii9ASl?+@N*Y}Ygkl Lpϟ8RBn\B"JJR%vcg4N⛥ne 7-q@\С>TX' <)iD¾Bjl;EжIfѽ&':c8|aЮrw1Ԃitպ;/+[2.mxR]}|ϊr7'y|KV;1(3UlhsB8bk|hI ^NYJ30@nﲏfܤ|-,_Y,<IM4^ j2ܢ÷̵H@zU},]=0h{d 1On/S}p-S':^ݺ`MSxIgc \M=c]:֣ CCzm9 ^z D9v9oI4V T& xa_ctrMVGϘ0.00 /j|cj؂ϙbnLp|ZGcQ*c/W>=7A@{1zUn굹!bL`%=1Y '& RCDMwݰf>>Uޒqҩ=:hY48;S/͵ԜpB̄hp*Fw03jB]Zv\tfGer'^bXuo7HVKFvDO^#m:R$?vi%G6o\q|Qضp(d=Ltʐd ~ y"txVT':bzL bn#>w=ire,$^~,ٹE4k:g%NyRR*ssB'N1*%2Wb/F՚N m ƒ 5#w rg~QzX]^7Ykn޾x.[Jt˪DNeʉ[X 8\?\Ut yv`\ ~U\Dy/H}X@ rIN(t# R#C2m-^N*FUUqbw `ے++Ӂ"_9՝aЄ*r&Z}\[Z;P}GrR6'l8uL]URǚ[nd$%K 'S ӐݻB  E'h!DAmX8ZZ2mO `y~}׷F߇/e6BQݔ;9IZ>,d^ЈÔYo-N%dg,*~Tn]]alP|rp$N<f6Ҋ)^1k?,)q}>HֈzNy= A uӔ ˃hC^nu{H7޽z:勥+PdYV՚UqΏ1+Cik /OrO̎|s܎K6)i[ۘq׫s老4dPvT9hy]blؿn#=&SLYd(F۶vLekt40&OY/ |lB"]WrvW>Aq/WS.kNucBn|ȼ:Uu r6 gqF13MotsmJX,l"RP14@ ̭Ӯd1>2V=%I $Jvd<#ڦTvM{J|e,%u"LaDU%8aw̉pu)X[_EcWMmyֱR^9KGܟ`RdỸxNqDװXE)AGμhCQQL MGml=G5e"% תy`;`P%hgrs3$[vID-tQ[[zB~P*|h^vdC`YzMP%u]>)롿81lXż.K"OT?Pn)@jxB1X[$c,޼b\?6WKio6W+PCHGi3&Z** ټ˪ؔ]= P)=sfI܆c97{0BHdE'JK@39E"'&P偁G%pN.-6B`E\$* 8K':8e 5*gfw3J(p5*i<{-gcŪ"$ikhɌ-ύS p5E~1?ޗ9S~̓~򺠝v;"A݃:QM0n9Q u`^wa5)^[&|WN.XC=Rg"BR c@AeҜ43gR'i(JY|Zi.Ad#j XLng}"[yKk~ _;paKjQevٞw$Ȓ\{lܖXPT}:A C^ⷒ r ;{Nwy lGML-vbg+CoIFIE8\] >R&$G܁:W847[c:e!#+/k6]}[uո>qWйyA/ˑYfNWzHDxg?GjdPhGfUq;޸4hKٮz.">E$G4|h.Jc"jsg~A R1)!؍h3H2@Y RƳ@Лj*޶:,N nI=P)pz`Dx03,abUǚ$ C Z߸ʑl!V"QKZ|k{0Q7B[1& F-PI ,׀f>WTc>B:YiJ{p7^տfS{8߀ 8T#VwhnB*;&k@MJH*~I&ь]zҟRbGvH];10~x Z3ԻAF3y]gVGMa鈦k^@4 Mx2 p=#Y0wkkyQ;eB9c~Of%4Ҍ ˤ.v`i (|pON  p%T+D=G4+(IV0zc#!cVJ5n~9rFNyWϋ,G04Ru6հ| {vWC/; ;*cI ڛBbVR;UlXX2E?*}T9?z0A2Qr g--]j]M3X;I@TBfDZ!=f&؇Qgg_y^ӏި=C8Ptw]:34-۰?jJ;Jo[P%Pl1 EO&P 4{>,KB?{f 㑢nWJCwU{}b;o[r:L|E?BJhGҤ]$_4uZ7Ȇ?!ZNBk_>@aNL N:d--/<äПjU+_ Soa2葋Pc|brAtAWS`MX~(4Ykq~8QXlZXڶ唜xQjAȸQP!S8 TMS6 aE[DŽD-H. Y"Qr ;kc[%@H[Av`huNrˣVLtc>HA%W_hu>Pn|_C67-N-T*`N Ƈɐ“*(3wH- :lP:`RM1'+W;Mݾ#&w#Iâ} p/>p+N`vY/۽^h ]er! {\ 颾K:j Kl#R>aǫ_Τt?_ Oan[Žhb!m!<'wSGN^&қ5~ 菳wb!#2>פn>.>a ~Z.exU V˂(<]|$ef˘sPkx6f]: AXY/"zz꒦.7`+?&4ǨgFtX*(F=Lۓ7 wp ɗB\?jٓOԃ[οʉlW:pi-"յɅJxU z7QaGN;IS,5l \*O忧Np"/}<sbW"G U6cBYfjХv<:NMN])A BŗnZ&rbg6$ $>m fEQ)U?`l/eA8oa/Q>ge7AnU!bsBM< "gMV g h|CPrYjXϗnVߞ`un՘fhĻ1Qx25}(~[g#LvSP=Cxs;Lsչo:A6j/l{Tݕ8m~a蒡0/_qTm8\P0Ƚz{U[aAl #ǐglXmvd%Y 9bkrx DI< &K'n(gSJ{^>jwYh]?RYvby<|LciǮ 1EfgU []r*_ò I[B"YYu+~>>&11ބ*\33(yR&IMEZLZ8=~E.6LpK`+lR4kYEƒ;IJ!eRR$;p̾/3ei5 1 =tp174ۼRv˧J!$AM& )c(h3k&1<I{\b[$1%SnJ2_|jg# 73Y(fl*y`JE^IZ)m:rj:<Λxn1p/4 XDx$5J r×bN3Z_OW`Aha7!+V(E.=~F9c|ݢ<.3LWUYCT#}d00zӱ @[ \w[7[C~uqccrQݰjngll/9 X%Gg˫`+/V_utBJ1} {?a:j4ۜÝc0: pfҜسŘ*/.8 #+n2 C ? q( b&D Xvͻ%p@ŸP@Aچ̄oՠ}Hf~#J>B_ NJ_?bqNwSk>5x!X)_g+/-W-ػc1HcPqFFMBF9%a_ &[+7M_,%;[ >n*j&l#kZ.#&07A4cfĉ_g"Kk& 1 0 @F#FN~eS(ssŞbM,b.dzkԸyjr[3I&00"q@SL3彬?EW|2<?{|Cكà)F!1٭P\%mQ @D )-j*ۃ8)4;Z?W1DЪy=Uܠ`qq!q =?ޜp ivW-77.-(P[vL$†FCVѵؔ]iaE{h-u0f%Qŧ-XE|+ll@у?6tfꔀ4sqhO-NVncJ\ڼN~gyP.2͸"H0UF3=ԤDPm$ЁU!;/;e3۠H7=ͮcye :~mH:yצޔOiV9 5ݤ|x"(hڝ1/j/A]L!RTnФ;dA #ư/GvI">\{g2-kӮdɔLb?SC !QQTgeL`RѾ;ľ*/k6ΞG+ կFJ_ʖV7TK xkgl 1AAdy /OW-coF 7mhw[cPT0 SѓtP]@0l,Zt <W99>t8uT>um si&CvZS(wAx68hlVYܹܺZqΣ}:94&3Y83KZ^r߽Ihw֧xX.ATeX[ IeKwyLoY } ;v&^yvACbhZk#!Kl[Y6_xU ol߭$=',[ʰ濕|9(OU#V]j0c^5r񻰂i7F0[ ;*k[I^Xf@$S5h;%BR j}H;h/AGp0JB㴏/SsYC U7Xn:[*d-=mxXD\,-q;@5uՀIdŷɈܬb^U02bWQ#w~Q,X0'ҨOmQHۊm>뵾13qE9W,h`:&[uf:O+5xJy֕z}o5zD>)x=efyX.wYKz6lS˲vfo<ʯ)cc@+gd*8UOmz)#!f.:ם11`XkAQݎG.Ŝ~a̷By}i2PH#>F|wt++ǧ=#IC$E-j#m Je.3ZGҪ3o#gZ{SU W=$@ Z-4R8KrW$#¨Bv;/ rWY:I3XTcVaXx\{f3J:ל%VRrCLP^z;Ž0N%%E1#7mf7uЛtJ L_I-*v)-mjoKⱇ/q?$ةȹiu9Z vMh2r$DQƊPh#‹Vn񐬵ʒ䱛1gd2T]mFJ0YEOvSFWי:c2ȰNălfeuz&o*SQMvY>ඛ2^M^gq_aAe Ei:,8._1+xd8'SV> &DTR0@~,umCw/?w#-`_'yy}΢Kd40?;y>vUZbʆ#fC43xc UGPbX/ipQ@I1+%"jKؖGD~ uN jFY![ W}|Gr7r'4d< CL*:!d8ʲ񧖲8y0T|N`tE95cH Pc*,$=Q  ' je0\$ >29c8"\,FlKy%D&%ے$WNT7Lt뚐i [ַOn{Ԏ`M@CqBi[kS8rfef[wH ^4iRӭ5v&3L']:n18gyyE/(ľꆇ t( >&d@~|>0XD9M,&97%ιYqb:G7w?T$5Q7xfMDɄʡ_Tp$ *>x9XAe4My΅=bk%޸HR:zZlnԖD 2w̖уu#S$Af}[i<u@&}!yՌc=ؾ ܴ3?J3"iARy:_qשj7|u){8 D]*i쪛HMbئֺF~Vg0sQX8Sb T _+U?XIp1$UqP.)7xWe(QUt`HULĭ5>DD&NNhR^jʗb접j˗F /GwxZ {o+mŌ5()q{EEx DNƌMj E$!Q: $P4+iS0[W53"Ͻn׋5)38r^ 趵J 7Օ79⌺V ,˺rSPo!c\m y͍kX[^ kq2“9#hԴ_:cv@Kc2s* 'L͛D'v-jE,RF[30heVSV|XtJBl l j!2?-aC M&HfdjoyoeT FZՎRS^î-O B})tfYW>оIN*F}Z OZ/j/CNw+rp'4쀒3t4(S~Abhsxؑjc%=. `rLBE4!"=YqBc*B{bDێ쌴l#$q})6í4+&ϰI;'ĞU_3݇7m@IۭVqT&-.QyWsk| WNn2#r`|3 6g{M+&G,Q},eW4%u xde; /DVȅq1@̎)ߜig>]Yk͑K}z׍'n֖1tՙYVl^qtI|%Y)C!vCBpkVs @wFS|qEWOȊ:P}~:4ɟqt%d qbtI\YdUCs~'T$QYZLA't7wSpB>}֦+/&J Vk+BߓwjhYT]̯ae JM B8 $C:"E>8ؖ+QtT}B pvPr9kɧ4 wo7qf] 0Y7d'#׾p0cIZyqxl wt7ØK9oM|3" Gl#Zcxv*;*G?OnXDб07_$&ѯk߫DFB s ]&~b|VeWܺ[ 1k^ﷶe-NZNS{TXM\|^*rJ> ld;Wv[A8ܡX#q8exFΟ^r ~elr3s~Yt13ӠɼzuGR]d 9ն8KΆ&gbu. |Nv)4d#pT">6D*mGW ؚ4M9-.@kbK%B[WDRA5{uykT;g!#T#īMd7L *,`ۭlaFe݇ͅ曆.[`b}} M:׎om:QsE "sꮗTׁ8lݔ#\xokN64 ]xM&uWi-aY|=TF%1Ls;f,p÷^HE-Υ(9z|jKͤ @[1dwd$Oc [@=VFv421LI|Ec>a00/ ZI9S_33hM>VQNjthvw,ogRDwVh0=p[9dR;e2_#2cBRW G{ύd⚧ꚼv%QYf!Z'`'+qxnn(Y[O5*Rs{wJ_ۼq1q,|9.f׬8 r)sHcE^wnzABbs%lqϏޤV54jKiBZoꯘ  '^5EkՅ8d[4VJF9t+X@~Cfa]!z6p?|צ1BJq׉'tD^sFfi3e7j[*g> BAmٗ F{U:t2(}+;o;Ň[nINw0Z+USP7Qgj|GZݰP~S7Lu/ȉW=@}&.b-JJJ"®H\3eg+TXnI!P6hjCp3ZM+d|iP("խ׌xUTC}LL:X/%ؐVS8MOK;x!g}axܨMzYI7DTMXB. xӷ&:I)A] Gۇ{R4<ĸ 0A) ^K kP w-LfWh4|2ñw &\GU۟-?Pw_lRW ϘE|Nڶ(#@j8+Üxx_)l@׬CKɮRamX\e)}Se;8Vɴnkzt(7=m,ڧ?㫪[pD ʻX;%O8xpZ5R'ک#T5l{)iB{f0,}\6'G^`杆pm&5Q?D6}ޥ̀bczm[C#|3>tX4ҙ+co Lq&6@ZvbҼ?%GiR_~g>l:!h fV ͱiI)}ّXd1A`Zzpr`@Tr(BeސOt!Sχ>n_t O"ӽYۈitJ}C$hboz2LA 'щUi9t'Kmx2x숆O>t3?kMr)9w&lT&.ԳLzǽu$@ >.֊eI.A$EwY^*mTi.%PEBi[7BEi*)QԊ @M7o]ÚnIͤpa`t ćkSQ8 ]%jH[3.""J1`EB\衈hf"X.M #t:Y1: *8Szg1V6?cDJҁp2>C '꺿es+u yi$ɉ/©MC:[UHϢw!7~r]!G-njO';|Ej~孍tb{"#L\[G82' 0 =E pvk a%dvZ&L~Uq:l| d([rwV =i[ZoGWL7;{LC} Z$Ur1c$;֙HSS%ȉZ-/(݇!7 Yoo8*`VzyZCHfͼ s2UÃp1 )<JH_|9ۅmډ v&~V^o WN0"A ,{CxJ G8\.ձb@\[nap= cNÉq1Bw8. 2w]\;U.'z:2nҪz ПNy H83u/ <j঳4쓫os1s SˡcHD]eIL]o+5=M!޼1lZG[b 8"{sLto@2@f:F^P@:df' !̽Kq$Pf+RmuY@JJ $J>Y]}vaY)b_J2US: ֺ.6պ`=0ϕ0Ϋ{if? F$I1)ρv.=${uީ1'Md}w ,+=nh'tP6_Q}uƞE1߶ZoPҍB:+x+͚O]eÅѴOd0{P˗蒒VV0@%,dCPRیwޕ\Iq'[͍"Ut$~kHE}#pܐѭJi%?\.^(Ҷ!ETC V]FF#HG_ݱKM&?^SyK rsj]0A| 06& -%efu'\불ԏ.xIאNׇ9 ^cltPC>ݒ6!snnjqR2GҪhsho8p1q^(a;q78ާM;Z>°l;u+5Y@jx0rZԂ PEotή4NմSu0#m`EXunnӦ;8 Du4WncGa(>Q["ID ̄s]g# `hcIRiբPt"8 \g.Ʒp uUx~Gnc9{Bxy^Suܼ Ѱ!vFyE=>A~`du_Ww" Cճ.Nʴg0)yc[ Lp:rSކte_OPC~c_;ޕ?6 t8@a.!U Z:[h65ٱRLa0þ۹Sȅ N<~өTg?``qZ!AIj/tC-N lH6ٵdlD0ʼv9SИGuCES)lUdB0};Lg7 ^׀KvH_) l7KJ:,>i֬ש Q;PcD#4?1;L 9n#&|gNBfa_9ё>iU7`7BUAvsZ+>mDRR'%ps}O{0mO+`gZفE=q^HU᪾ږzOFgDOQ8)7oW(¯1 z[Y=E6x/}Ӫȁm<< ѐKϤl3>Aڷio 47Y%b*i"] 3A⭺ ء0M/L8J] & ;^$Km+&vy{d'tSaܱWꊆ:!tmG[U4vmoSbx~GŵYkZY3@"7%>Xrx4B~5@Yٖ8ڡ^7M y{[`7,3B\M `E3gIC>_J#.2D>$xۚ¼ZI6D3t3.[Qge}GEj=Kc}m? k$mp t'n |;p”nl?g檾5t*<)ePu2)/"[ܱ2N9hHQCN>8 FqvLx/13u>߸@\d@sf sSqd!Gwكj@oaD|eSO,Zy5JoIjm tұ]ڂ;YX]+ e V85l-8H1Q㥍y !y9aM6l("N#JJCR>R, {'-S;ui 9۱})杉uB^8-Om']Rtفbubs?>^ѸO/jf+ؼoE⥳y?gWCt#|Dp5~`;>3)tTɍo>b#ƯH/l,4_qځ@{Yy֍qK̈CQ", c egePq9>ߎ#3NgWi@r+P5-/dn ^ԝ|R͖dGxťn(_shF &Q$JfjmI&Sb{)tF"s{pw Ϡ3qMYq >|CX2N,`R<3Q~("D6~pb+cQYJcz  %pRȍEƸe%d+7K)R> +Np"J 0wmqfZN1PIrOH"ca ʻ[c԰Q:jV$[Ͽ_CEnȩj#bb|<iQN` }F_s0?uvtmO"z_ d3{;?ʒ zN_ˀ~i,i5\v \D$Nh >Ge.I-VL.IRJu ֒DZs#P>~kbq?`ڮLgSdtlDRb4٫5#0Ih}8Jo|@8&7A t$AVKQMM^]҂YG ~;z}6KfnptnʭiǭJa@,#-#:pLNBYʈSNԛ X0.,{̖.}N:Vv7{gm>w8^v^^ K*% #uuV%!hhTH!0DؕchcЛp)[Oq(GdDrtbӑ2z"-h^)6a^' :\^ 4.Gjdgoiuػ*| rg_CflLj}8`?ۣ,;F_?X)$x* ,ePxX;wOd)fedocipJ:j22>i K$շb{Y*W90QeVO'KO`ۥ˦Ρ8A~EOr˼,ӢC u/=tqe/Tl5y[ϔHS_%5#i5U8[~JQ\(,s#CJFVMcԤ7?7l}h/AB@z'Iv97VNTeΚ@svȺ}kvfUT0eБZ5ċ5}H7?d}+`l)cP Kn:WBaf>`KvN3+cZp\yOt =:T+ D 47|]FG|[xwf估tI{Yf*yGU|mn! 9Pq{ƖAaͻoMX>oCD*Iw)0boS y,c߼MT ױȋkǨ Y5)0[GS8T0z7SÃ7bPU_TԙE6T^]Ndz, Cx{rgN(MD[qAMs0fÄ [U4ߞ }amI 靗U}Kj83^^|kV6+mMԥ_Nɢ۰|h@4>K`F;M:xiH8l>㜣u^[o6=VYB% E`"=N|O1&{ c5vSi#>G{Ӧ]9[,&)%L/ ቤT{Z~UfeU^#9VmR1^~7t>0)DtcXŃsX.CvuIڧ^f A25yFu=2^4XlEt=K鯹OCZ[m.,ޙoVe\ H!ԸvVcK Vf$kC;3j<0*eh Ŷ޺Pqcn|Qr~5L ;@}~B}8qhW,Din=m"<>diUnxioS (mߤx^O=g߈u{EfD(̾0U7h.?z+GRK|dM;–S(5I}P}B;h~OǠWDt3z^,[}WR!KZh̹y2;N3BW$ \ ;%Bpx%pcø{6!FD~Zi%lؘ:D zxmUm Y/㋛Q'y .]ڠۢPDAޒ0τrPjk<J+ϐ)[69BO: gqǥ.v `O{٣zloo=]X`Bw#cVv('!b&O$ aΦo_a^ ļ,s]:ȃI}T=`97lqCU7$aa,m5cm_O~@@IUYM .&Azi:h=-؉p7gMU+ H|Zkdֻ](um)G~30Ŋt~RJ`Guߋx'uXcmfyO)b,äa<&!N &g7Œ;.Y;oBA\dnoR+8+tfR%u/aآUYlWu!dKMUyDf4%l۲iZ\0ȋ~^!ԩ"{ċf9k0ī8]tWݞ;*``ж^kdCF<f[ }yn;MA|F"5BY͢W. T*_pgbhpI.G>~O:'VV!,r9-u1 J1g&[AۓHth^mʄJ W9'_y;>rH)ɒS-KW c3&",`V41$J:bwaRe9qhˈ8Cj߰Ay /QvOAvɡݠ CSރwmG]V|V4T08n>څR[ 6媷ԆWmr5BDfXu_(bX33=bmj^s\Ats,QB-~F~ڂ\P֍HMzZ|!! /q+J5װ(a7IA.YE3ZY/&JMá> p 5W<0]p82\Pw_2e\j{'JI,{WHo%$yB ٭AU;uKmS:4T=J]^h ~Q]<ψNy y G] j.:co\6~vB28TۥI[_ Vi5g}fw<ԠL=XmYe%`qe^S0m37Ԓ R+ VfހN9Ygg2kYcE1Caؠ{8kϾ ezgZ܊-voӬek3A%Ad~AAtXJX'^$zk2KuZppRz?~h˗V!]{L‡NП-lZ\rGLeQgTTR@{ZL] ؤYaPijJiӟsڄ)ɱ7񎅄{ :83fcŤI*CO+"1WQlMUZr0yI[փȍJÔY7D*p=1o'0Nj4{@r`"Ӻ桼+A' b(5KF^OFr[ 13㷷5/s˷$|N^9A SE5t2-@qq3z [߉x&? %/ƂS~1۞: <] 5k9[4DZDf)ڬ Έy)cH:o1OMȞ0p6ϋˡrzLA2搉&ܡ)Anx b0% 2tl ~:#<S:Qe:BޝLs.QeHI|NU.Xj=ĜĝO+#`? 5/Ym3\#\hq/ly#fv`zKܳ9DS]? \',j 50:N,Q&҄0ϙl80d\:̤^ˆ<`83d7Yź.LߣfF^"9`n/\IOJ)7pfP5p,_my1Ѧ=NyƬfp Ib .Ĩ7YsISDNܦ54l߅iχMT>3]]@इPq `<;yFN[Ye -ț͜vP3J4|3uw\(Ei0A6Smm4`K&=dm;}@B'R)2^#ۢHf@ؽtBD3.칱Fhn_t -MbO2`vS ]V~`@CDup|5+K&uu$`!Y,QY[ћ`y$!)4zC Lf;[/O*P@ƺ+'rDffbL.9&̆eox]ZoL$%sOt;Q e9 e5W[`!KITG~r4x 8k['&h uX-iYBv^0bliŒ/i-]>3S\`^SrJ.MШ|%v1\˹׽#F_@s");~z&Fh V7QqTzlLfƅđT)q78iztTN#Vh!)"LJJ-g;خ4DNs mE\WM) x$9$) Q\]J-!Gv-ocQ{y{x[}ںӉ,R4G_8F;FZ& qa BWjDrV{A㭍d^> %~˒?19e.V|0OzW;u6 21|-4V~]pDhWUX˦"R+ $.IK@'r߄,vDY˅ @iNrxJ4k\ZԴ$j P&B k,QU\Nw@fe^|+|QZMAUWL#.O _SǺ,-^ev;?r$P~Z%u}VBtdu#r0҄c.U Y9}| b/Q|}ѥ;Ҙp^/KnR]cn5Ss &.iMЋf&wW016VۣK1 S^YU0lMh Q}roD ?+箆iD )=HƺF>ںq\dg;fQ`L^Nͫ%2){2I¥Q3q;ɴhQ`r>1^B*PvX OٱΘ5B&]PE.8SwHj+SDiApoB(Xn*J"nvZQ/BidL-04~\v[.Lhdk&9qP,YmÄY#mIH1ȘD`Y?& + F?u|mnZE$Pq4(ôT',B`֚Y|=eϝ[m]a؟5ե~7%ܐE0D~yG[v ɷH+KX:PaQkOL e13oRZɥ"y>4(5}WsUFK< U,.o'`4Rzbq2,U3V̕% \!-5Z>p&cҾ4h;ƹkf''8D^.v7Ҕ,g!s˜LqLKwXVa`(":j_G: ."bMUbN~OExn+&5L%\i=EA7.D_%N=oxR-޺]V?c!lNA~HM؉9\n]ze  $Gxkn!5Ԝ.[RzarGkʟcr2n( "i !Vi m>uAt^\-a/9FԬGը;̓{ Z0d}BI:ɜ.9ëDIW#{7w$r`a48X\^M ]\nC¹x+2_ߺ4bLInA)M ¦fi=h)N!qeH˶;鶏fJ[Iʓ"՜_!QSYoxe&diP}1t7U",Il_>!z1A/kAqidz'[{tXvxlYC8&-NwYy#"YwbEðatرp-b f,.VAvå^mb?J4ZxxhYΐ&G <˺72ehrAwH aj<܃+-/laL@F,!6SOZՀt4 ~W}| c@^,~, MIԪ`eB1gcO7ReıEa& ִ/`Zל.g4W`ユL5Ic%|֡_cȴŒm&o+#BtPa֕&9 |ͣZ#ux.m`sULb–K'R+;R׍lg =gZ gQ> 9^$5$B`9U0.1JDPA1f,(Q(V-n$dOư~ %,BH"iF Uk| `5ŪaUd@W+aJ,`qVNjWF%aFݩw#v&+Q}5s~Bh'á%)8^) Ї:' ~mr#*^uh}u"HA\8ǭK1M™pbŰjbƞQSh"?ÃOq]k ZRZc)|1A<@5IE8K%g,49 CFQP1d;~؞]9}@A9.:?IϽrԃ0p9M "l0>gѨZ SyЫEmuC-@k@_y~xT4rȠϒr:#?d"zmU l؀+Vq~uf,ӍySE( סx\o/H4ru>''ųaT%PO3%+}^FRH38|.EEeӑOwR*L,?)GekfQ_Ø b^4f귔ydR8m0]@]C.:\ujZ'[ kc 5)h+Q{Zlf[Gd"ӏᾍK /JPrCh觶Av>~s ]|j:syI^UA(BI c:BxA5֊_9VǵF]R(>e(ft8 6\lb4D^sĽ f _42Zn;U3,ny/AQzuX9uxr r2Q#!:әVVH1`&%@c4gWvGSB3b!#mv;?TL V(&2͍ ̯[{3 G)Fl v a۪h"#1WmDb u]eGٞpqxU}aOb^6BnGp'g'jWD}5-L5.K&ɤ̭Hx?ذgh=K;ez@'L^*T&2JUo^. [((CvJ&˵_L~ _%ܪ|VyShչ5Ti6KCUm5 `w e-l吃ǽ/2OctŢ,ׁl0-DZXd=+b@R?aݹB.bBd l+MPZƵ1[yw(G@kY>BSC̡t>jx`P>F8^7:xeo)c8aǐc .DZ?N>QH| l&]ˮs7%~w4xq`z#-=3l,QְFIAO*OT O.|; y~im[nW]]vש7}f ,OmwCpaϻ2L*sgr1”p6 [V C*C'[+Bڜ`VuV~j2> %H</Ձ8L ĉ#tQ - 2 1I,UDȉ'iĪk\j&]W E{K|iϑԡT`>Jwk+@2?;,1R3\'%n vmORv]fF1H.祏׀pdk~sU^qmWG6!u,uyW;"CIV;%gEV5K[SRm&ÃK C[H5x R^ȾM9?5Ryr|w :?5Ehp9pgzo/7 3Ŏ(F+!!n8?/kBG)WF=ED[KyX]½/~V)0Cn{kodǜ }Jy҃ ̱L:ԷXMbKTµamt6o[BC|Y\o2jۡN9UqĎψȶa^Wb}`7/RJ3q;@,boo별`vC j U/Ug$"Zd1zj2qXt#ǁ|sT0ﴞPww#09qe┅yA~xZVZ!d:cӶ$A EDw.ƿCa"V'}ܘJoسL@إXWj4rxy~^:\' y&^qw`ێ~^-(qBPNHVNZWfAɶ2 aHMVbf+RF+]t`2VlQ9qrٴwD/E9ۗ}S9|kh83ҥf5|7]w3tE4!yn=Mq:96r8S ̓J7G%݁sbʂ*5GGyBi@^;>fݟp@8l ;,u׌Α\(鉹aHأ`D8\y)NL.yn! V['\60e(|olPwSp!x횻Ohw'w.eMqCEd3Rvۀ|'DZkyX<*&ٷ0.˨4W=gNn.oCHrF+n~FoK}Ӡ(:4@x4!o8:kYg!5OCw|8MӫdKAӻHB?\-GբG]K%g&o!sydbIZ[F- !5A YEpEy uy\H*1ˁ}pզvR`pT FL:jA1O8us|޵ <xpO7,.-yNDGꜢ4WCW `L'g ZmaAفsM&]k2Kߕ; =ě-$KVQ pI(֙Gk<"( O/7Sdipl\9f_,,CapaM[&Zj& %{czzgOլ8R-M4WIexocu,,\X ǀLc) >􂮕zwo })-#/Y1o Eؿ֘ߙڠAE} b-}6Qg׎5`|Q6EV+/E G_]Iݽ s/sϾ(J[՛+M>ǏB>JMcu]ӃlkyC7Bf);?n'l/ aCDbVU9S|㤧jbcZ3T/63*@Zo](,=#2Dpb~uAfPv#a6 8 I ﹎ܱ쇍wPTR tY "qF(4SpY6BH؉׺W'&ˇKA i{k d 3)g2iE- C-_ &i!NvGYA+m֗cw ߱gI1ɰXvtǕ́"i?"6 P}m;LK&n =]⣇!?&#oOۃ+]ީ åtgے~3pІ x.^֨xmvH F Z:ss=yPt*ə4 kj|qVW5Td;),5[N|3@Ť[͆,tpCe2/\G$SCoڐ;uy^%#y\$ջG鹤q|E-ŬŬDMB&\\llC#l}9{ SC}NhTR~o[q7w2ENAAA gqEPV (i`Vԏδh/.3wEo: #1-춠C'=_ĎY}K(s̺iz;yE|8_->ϡA-K?nWk\BD {. f5۩x q60/}؄23jL6Kj[G Ϝ=1w08pk~N<1#X{~-r?Fv)ۭm\AꘫS?gzdC&ZիIN?$Ižij?]1aa'pܟy$1`Q&oJ #0 h[[=fE%u.)Q JzDዜREŢn^))B Yb,P g޼./8ŠHc}GLTA7R މq_IBg}׮=abN5Gƪo.oX7ʆ+g}>ǍiÜzLAGL !`oJ(F6X/_#=R>Zg^ ﱷnF.*(4r %aE+d2k3+QH;]M%k·|8 VO0'=H Էln7TGGɐ^`N -|lo`{@(/DO+q!Z;^L6ZW^DEP|ϋ6)c?x\w}~7XFtW&%Cʡ Yzu5pLӌ@/W̘Dq,q"c&ht2GJC/NB!3:Y!6I,\7gva Foz(^z)+I#aB%5D!2ְ-ʵtl+&bs2gy$;*dݹ&u&a>ُ}@o y=PUa'~[X=m:)|Mq G~h" L'Uϝ%q>r e@߁.Gf`k= kdU~@N,dAN`.J(q'k@FY^$\kђ* j,g2EV$EIa9kR$P<^@hxP4e~Gmoœ*p;~H˚\+=9|v,e*0%8P I,*zR5¿^#F69"ٷ9t#LhĔ*Kw찁L;TLɀsaPP4s_1VbxbwId{hòz(Vn$aX)(]?S$@<>sab \tj^ͺVMfaR G^Yv$2"63&єv;- Y)}睘`cmWzͤqMlL0Rx>< ŵmϊףJH *E>_h&=h#%f͞,YHG Dm ol d=$ȟ;N *et]W hP%+< שRqu74`LsNQN]Qޠ!epc11æ&a9?'X} _l2ag-9");ATvlԪP/!\W#)/6 0? hdN6΢|ZLŪ \ #\Q2 [jP ȣ;SY(D~K?$cӮ ^PǑŶJ3/(/{cR.>Sc;3Ň V2+0|^-mXv0 6O7?VXJ0.5+6KR!=<;@Z2%EFUl!uUׁ2߿P-?o3Pqf2޾T6 i f R909m${>*(ǂ%cMEaܑ0a@ Ɗ -A&qvF g+m[3N?=
VI,7^Y5),1ն;reBN4v\T)G63%}*UTrgnv7}e>!/9ܙSs=g@T<󚩼 E|-_=0Xl@Plsq},Sx%^Z;R2@ؿ}Cv,;w(+K0ٹ0: UD&}VSZ^zpT?=sf/?d]ZmM*y!z;x-yO XoGUCe \gԓq0!;gik1(nb-n]g&"q Mn{;'2rH|*# ;m2L46vAEyiæ=c)'2DA\7e_ř*bQ [߾5>y2RZ 8F;(WTԃ6W"!,dF}1*oK=cB"iD aNa"}L#h7;QE<(Siy#/ŠW@ Y n',sړrig+X]f=x9,P3TbC GۄͮwhP 9# RJXҋ<X8Fš"m ݷ7 3ʛ.6rXzDش[ j`ÒW1[y{5 T?N7ȅ;})XrQJz.u hV8094nkgs.%7SCiPApdNRU\:;D3_Gu BcOJ7z87])xw6n9-03^Z6ؼk ,ooܔұ1j0/9\ G {HPFHxXG77GDrkW"[K[G SO6MIx$P6Iwyc  gq&e$$$ hY!SV2p)Ѩfrk gꧬ3GK8n)`5l@ɇm1p.QMLӇOc |I7>$8[ ݐ j0Qv]ݿ?"P͂0_pLY jżqܱ`WfXvfk:$pƟ"^>aE؆h1+OΞ_zԕ]C'tYX1,y$@xW0~NNW3Κda",D/ 3Th7C-3sq}؜;tnou_4lju򞘀6/]%BjڧȢdK4F`j3ˡ[|PrWrYr\XO]WVsd`% `i*I`et2^AfcDZ@Хn|km]EBڟ%\gO  r+y}7e#/g$X}#c8#E2Kce?˕E%9ȷU>W[ Hd$:Yz7!$xpxD%!P/t` e*N<IBut}?ߖqSdɀ^/wƊ'լ, xN}04~&o--57+w(e_@kdž ,% wwv: ~-:շq57q]Uһ6`f;za5: sI;`1/M 2Zl/,iRdZ磢.I`3E!/C:b[^6 3(}R,ݲ#%s7#Ra7zRTI|$а?،͈i4Qcz*GݡmcF;nl F :4N6}R.3r6q/T:(OsO&U^}8|m(4}r Yh:\pcW`v8 ڗ9{5T'ql?H0O콀~Nnj3>fG>'B\=" 2{@A<>O1rPn1<0`֙y)UVdž*D/z>fP}N9|Em.T?*ru7Dl:se`Ve;e=4jU ܀D,yH/_i2v%F&rckK$N0׏\0Ԉ[$ZΕйz$M^mk~|ybq(r{+ͦ__qk,9,y'4(j%2IQ 1I<{VcL la:_TњlV_%i+AY(w# J`+ig JOR]vj*'WfW fy VWDxUߐY;N(rcLlE=nq '%KJn˟ݽlf\(&WH[% cQg4 (m[ɾmG:/d7#;W{p8WaTq@ ;Ng`Nm>|{UϚűZXY߷Iy?Ue2Pa^'fE E( l.X;G9@K_=- 1)nM#,[jCQ[ ̇ 2ڪı^U Ehg ]s"9U W@8o~~>;4-Xv2̌ϟl+9#mn*[ E6|Anw4Itx CgKlXNTjf\3+ƸަAUMqo7֫W}]#~<+5o 0u}96{42?Zi`"1.,?bnҌ^lǰLiħܭ+ Ĩ*wuUmQ BĚ,ϯ*ڠ9LP)w0cxQ0ؔ; Vmq0exK#5d Anr: X?PEOrZ^/}vtK(+U?Sh(X.<an͜@G9ٱj__T# EI~˝ķۈ 7+- CʍkHBm橑=\!UYQl`֖K{?exTwr\geA/6~V?!|]҃dTOM+gs}b_,̨lGkuTbڪɿ'i%QRִ`dcKnlnZ-y\pޔgn1+UE晖` a4.)<3K NA|iU1xpR/{۹n5~PԞTMJS^81VC 8^)){'"3}Z3rV}FyP ~ [ ˚`aһœǃx(]IإA5?,m7)"gBz,1"3~gY|o/Axo) r&WF)'QXK/uj2pb~q%Eju^a2$̴f8>&O gĮY^ߟGPMo&ftg{(25pՠ_rR9^qQ*˺u^\`BtE4ƹEYooTm^3ZCsIe[ SrMY,pvt_{C*^o<s'9KauϏ$.0wp|&|5GئWC,ԈUVX4$ZZ [C^145OGOgmf=L,?ߓUEaxiDڎ~j6 :=̯Ylnj Tj TYj闤\8P A}M.zB ') 455eTHCY;.ҋ%V&rkR_/6m,r fGZR>F|?VZ|p~t]b`1Rҽ-ZG,7R#S sa)Op𻖉hc?+?yœ'1 dE;l~/DhA8+֖ӂ\t ?qk|jN!b( XƓ-9ty)#2 R[a Cv`OH>*$*- E@*ibVIar:֓O9JAb(~Nt84)v;"\ ,wx=L^*L*#( ?1/UE¿_dSꎔ%b*M>aCy`ɗg *x`g6W%=p`|dc.w=;Y/V-Gxib~͏T`LKIIӶÞ0ԻeȾڭ렚]X.0\ 枱ûT(ίz<lG8pDG ʶ?+md54 ⵩RMcnDG:Дtձn9֩c"2=%OfO^H,\-:M4U .{ Q 4) JVH>xCy NJy \^zy2DfW~jF7JʴOa}o4mpe| GiL Rw=^^esA|9raje L#Sɓ%!Chƥ%Ɲ2"|ٯX /s##c<&kge'6ִ!r'Ir#ѐ}gyTuy{ZN7 }. v+27jYO:[n =?eeyw8XևUw}|WK +u7.u4JN;PNpF/ wtrS߂cdep]կqwVB]~]akAL/J%HIW@`,jj帢L|)rPBAEqA˷=剺# yz`ͪ!3 UUOvA?=Id=[UuGvA@c& 561w"3Nfh =4> ^TqSK{P hf=iy{jQ^ SzE~GrZ<%tʵ_(h&#.:[o9r3; jH`@KOWK3V󻧐F* >a5+YƜOȂmvO hNg`:%1f}lj\y>+٭H7i|@c1udDtMQF)dn Su.@daU"|7~I$/qm̾^{ X=PBX ZԞoCxlL >Xʕ}KE Ue, Dű;'ט̿*gk48k62\OWx1irMCr-VG=k<1}^INfX#׾FM?WEC!%2 v +)n(c0nɕ ׿'b֡wPGN72۝h:OaqAd0F :T;tzImbY#1W]45m\h&_;?6aKC䉈L#"F\N;k2壮s1dV `AV?DPWC{>f6B p(WYwwc>tU@|3ӶٖptRi`'mmK]?Ja-iGNI%gzh]ElgI.  2q/?* ݂B"}fe7f>)2픽< %`ue j=[l-FK!V?z57"v7l3N:2y4=,WfGouܾv^N+"1DӌzueHT۫;ߒƜ)b+Ym?֒m׫%;p9G*%9[*G+l i(ΕTTٕ 4=%$YIq 5ieHG-ܖtƧ EŬ#A70.DdB-: ZM'}:f{}}P֢3Yd-wA>j(Eb!U'T:bba<U +:3{Ep"v{RQ]-;+5 h8'+𚓹T_uR \ N(i_xYPѐğ$?DQJx!Z#:=]=VMoi7VN\8SlQdr_Cu1c 'U'@5s`9<~#͌(y# "N209wL%_3 ʼ\Y s>Jm|4J?p^N|`7Xc6pcrRQL17f{6O+VL07e[B,eH$2װЃ@ސix&V^РUU9JX)1i-c#cғJAg;qcVkAۍ`y[mk-xpHl uORF6 '5xR恤NI؟ O7&0 ,gyW!!SAN0Ud'ϋR. lZ@-AA.l9ĶfQHWM6 c\߲V" K 3gJ;`¹C‘ϲp,Td@Q/I!Ł17qY]k* r%'x˛}|{3UdX]7$p6Ҏ3Ҷ8l\}y /U=hpE(k77!s $Ѫ4$(jωڟR<V *3,Kc,4]7|~ rW".A%ni\E_PgچH4̮;(~lW> )3~C@gM[:0B<}L{@[Xv( =mdz"[lru_0H|MҊا$msS^u5-KUs^k9ܿ 4+")e3/(QuK$p{Nu`[ EHu` z(׬39R=npt`NJ%йv8vf(kyƖahER9ZHapYfծ{O{9X+H[U<RNoRixf~\DV BF6v4{ٚ}'F5}/ k$5 ,v?\,NUyԊ?ڠb(hV$R ,!_/=Tq-*q2`(D_,K\[dQJz18e`>!gO1Gt}hVE6u[ s_<)'/ւ9F8S. %D8jMBT_>BUuAu=)MvLҌ[]{@H< e-xU?:sp$n>QfڦUPC~ `bv$+e%dcdj~4 cU[(@EPNC0(U9UYc+=zqH(-yR3_nG7"A6"m횴D$q/r;D#/m)V< [r7(DJ}@9ڗFn\y _HAE]#ędD/vh,:fWO="^7shYtp3z鄜.yCpe|DR.ǩͻ] JPqq9}#. ,Sc\ЦG0l1Wڍ-ڑsM3Lv2D%Wl% ZPƠ{ 5)>H9gaaRB@Ӟ?|&%o:&gf;jx^`;P6nYSpi?[(J|,e\T@VOA= 6AaLmvs@D&HE5k)ʶ@ 9Um%2;I6L4_(: @`u JZ6qvTI"~V1~X* SknT_or=5oqj]aDAM)DlDN@ښrt_f˻oӣa6E{1w;.mv+Sȁ& i5x"qdK.KIr|`. H#Xflo|tw*]?oZ|]l S$lfF1Cw c8an 5` Fr*;R0G֢Gh4 D⬂sKE)Ņ>`/]U*nCxߪ=]s.~T|X1cmb;Z&hFVu ^H{ Zw<YOf*Ժ_\Ff@BG=D6u)3_zv_`. ʇ E9{/"Zr+e?xOF&0R9<5I.T hvIaB ጴ @vv-vVycAwEm쁊7C ư:y$}c}mڗNK8Zm V FtOR;"XQ}%AQpfyϘO/@CcHsJz.IНCXCrᗊpooʵ6yŌ^7mj_UO"0ܞ\oj$赙6?,y=FiKh K^V; cyg=*tcȊ/%Lڅ8nmɢenC;sN 0LՋ{x匪"='3Ub^Eҡ_dsÆ; K~hJ?wNl(2ogWz%\ծ$\({lM3XH$~2~犤?g?@NOƼasx/U=9S 3.cK#e $J}2˿%pͿ,m BBA:\W$t"8IV{k_ˈئGLpqYtOnfu֍A{dp)n/NćO#KTLL^LݖX?۾DDgP>sŰaHGv?T9(J 4:)%- KWfzz%l)k5ѴPXDYC5)^i+%^Pu (DlԀEB`jVYE:N ^`+ ^|l<`d5H{o-<2!mW[jVJ'&h];wՃ}.qĢ)j6%Tq/6l!31 .ДZ=Zv q# &@bF(I5/khҹKPoTnt" = iGg]Xk7ذUS#̎R i@a1'OIrBz8\@#֡*iDMn5 d? `PH9(|jGMD/Z,vkptx `ja FK-oO`xkG\OO"613;k'̝\ͧOE ].9P/*l*~fV6rN'E1@m5 YuDDs" UG+zx;tY`7a3F[y1s=zZa苇RZ\~ړbȠ:Rc0Ўib\a5C+-c$Q)LXW<#պƇIR YmN,?ϕO =;)T[{1U^_L]YeϾ:8f_xQyꁵ\·6Nw+yjё[MuwZR mXGWhvdom) +n= t&@UZ?b*`?` xkBX -S;S²P܍~t၇Q1Ȩ#"dӥ` |YeJY,o3x]$ O\8) /My(tR olIx k? .Ƃ@! ře"QJ?$eu@p'Ţ{#?@uFp.mM:7 YUH0'P+.7pH)tPЕ'~QWJrSC=~5|Ζ il|* cdV] {.,JsAwq2 $: r\Om)pWsYTV(팏3x .B{E>FMTNi~M).wfx($0/>ϽO|8N0VkWy|K.R8]F?Ue+N$w)+;s/!JM4qh뀆 KpIBI{o?_2U`̡w'Nk_˃Q?vޢb7^GkZXtkZx [+h+8d֋تF9 d?jv{YY98D _j2:HdA#;UjF !j?,qUP,H.Uo`O㰛W#5@w\yLϤo8V {ɽV$롰ki>-LH]wUgnu&qV3̺U1ٲD۱lgiG:8rMJ I 3)Y &iu^c$r+1iR[_AKYH,yć@]΁h_J0W(SU84ƬS* ",J?}KmۊATW~ʱiX9|egMydfJܤg/7VXv}"zq`8f8礆kh )@Uŵ q^&E,B<?) iJ(_Hk +B9P& J~|.Z6GĚUƥ|C:<,IO#tI'=_Sא1E7-Jc``4v ћg7k9 /DJ~h2Zޏ$pn͗ ;Ѵ:d =otkW`BU& @!Z i͈avOS:ΰC$G׳>AMܲ@QzIRZ}[a qt)ԙ=D4 }x cj&vt`J3s2Z;5ǵ ,v~ '57,Yo嫽6veFG|23XA4`&ˎ{S 2P^Aqe}eSLx^[:1p QTM4ӝsNLank)E4(@w z^Aۉq/;AzX4|9DWq^(Qws iC'* |`K:oIw$ҏ\GaWҋњ`CtCh±EE<ဳz(sgqMTԎFwQ'Cy(,|yzrdrsvS,OFg*<!wfg~<ޚ}ޔ6kk7XDąy2 P@ E`6mOCAz1=N e Cm{B 4'fn?{>pz]30i<9M C"w#S(X|$FM`w+#w5%LШƋ;9c;hhV1'M龙24n_VմV̒|B*KJw2SF}C. 4UtX櫿nT9ȧt#5'uT26cthWBA\9H!"3-J>.Pcj[6I Д%");{ZVW֒5.]}S`LZ)McG{pCv  hQ]> q&kt q4aAXbq>>{o(R<ﰊT~Oq+1?D&v}kq,tـFgUO+st;<},ۡe:&!= 0_8vsjfIM nZTs( Ĝ`yŽKĖYO:>ek5i\S2}a҅N+=*8O!-r5S&W wCf[@Ty+6J2M|T6 Dyco::k8ڞ/1 \!Fg n Q|i˙؛\Ϯ4A:C4̗#L3"f+A+<ݑ cjkq6l;Y< !UtS^fK5ۗЇ:0MӊhYꮀ r̊'Tjhi"w /IN"#TߡԁT(Y1~e*'@X)JkigfQ#dyFf5>jt`є),|M?J9jKNawr6Ѷ_+n.e8u]gņE(lqnpI'4:Wї5A>-= SfAGu|D+Y1p%̟*p;oרL^~9W_]A9L=?cpDZY*Z O O1#cͱ^v7S'7' V}ɓPPwp|QLc$ D#$WͧHY1]@DX9hI_ 3vT+RVrmur׈'wRg9뾎s7S{0(F%PdrjÓ?z_)t[Wq\R,G2ݺr])TybZNp-aIOV[Rmv1ƍO0oŊ|_ iL84KA{]hո D_5#HoiǏAȩNv|l=d9 hEUÛip HvoKXq..Ώ`xq` X\Tz[䬷Yɡ4`c\s6cݧQ2* j?86D3okpEʌ6bl!1" } 7h*S$DN}CZ5>Lta1x^G=A%r(3"*UF@=զ6!ʺ9 hSԧC`P#* N|&uviUYju-갴&t8?!<\WF4óQ7o[4ΕR^iEVV? 9pS d ͩN\hEQ˸Ks%딟s1z6q~OۚT -7- x̟fG@w=gŽ?Sg[Fc.#.0BٴN WNE|bt}lv W}/ONf>ޜijZ&) '۹ʌU.2ᱽnBjHHr.w"}XS'}'76^L|LOs@El`KytZrb2CG1#cM$)IřY}D'iU۩)"=,vr=[E~1!+[TKT,uT95V]IA:wP8@1{c?s=;p5 E&,T~QEN㊾pQ-;qenAw\E$93UXJl-ۙѷXa7e4(1] ` ഐG\A󦒛/M6iAu5+`v@?BlsXNd~љRّ':~;Hcԟ冿 uvr8gǮ >K;zQl]7ÿbcp4kIeV- ů Z؛3غsYu wV6T@U%Ezъ61e% 8Z4P ,oº3hNS>Ch"Qmbu3Cy?+QKtPkYEqzH9П_[IobV؊VWxT8"CKʋMI*a@v8)dghIGS;D%O$`XZnaﱣ1_dNFU"5.5b8ϯ ͗uH:^k/kh;[rДe!},pQÐ Ї!n褭@->O˃PW+[/%4NMcakjr ? ^kr/NtW2 &ɄTs|vmq(}uX (!S`ؤ'ghᇳBsB. Z=,3Q>&{dh+.y E$׳ Ru`#~Moj s6m!tW+l+lG G9 'b"vE$İ4b2 aoV6)hLzOޜU~]cU6S}qljq# UPLjpyTh "풃`akN®ԾmRK5vx7ia&sE=d0~Kg{e|{Ial`6ETiN6L~slN>aRK2fE)w4&FL9 -y djNR &=7=ⴛΥiY%`{,=QGy^A#CGbV38^Wnw,>4)e9`t` Q&~@GZuBT(j -K$Phobἢ6%caQJ DoX(Pf>URmU>v D2IÐ+;/8_N<͟;YԌ e[nmK{ 끣>:I~{(PM ,oaozE.z ;}k]<,Sc׌=p9|.vl!C5 {i@hg*|f9KZC)0O׷v^>7AmtS䣬XN&&PBbUsTG,O!фUEZqivGځrѧ8-{#,#ieBs WQBqR`dgׯfZhDuZN/ʛX@5%Q}[<^2u/ 1Ckؙ]+x^׻$ Ǽuquɸ ~TU%4erq*.dMD'9DBIŽo5GyG%> bhU$EJ Xm; v$;f(Ǭ*ΈA 池6N]67W"{jҟ?΂W󒥰nd86Q/u;-g)"$_u1l2ڎG~>lk*Ws1,(+I5ʺX6Q5Lz ;6L z.!!p2KDÚ{f^asqmǦdfAnKŃ9|8+/.5n~>r ef&` br7Ybv!ng")T,džbKZ"RhIlWW+q]8bJ, -qQxcw7_ױُņnt*Et2%ZH^}OMdGJkX)lQ8 s upiv}wKԪIDLn}X5]3y ;ZC ek*9,_4a~B?4O5Eϖ9p_J2 yk/g2m❚N-ǘ.~xsjx7as.z.oNx# 'kE% 10B II-,_]|/|i'[PCE g;aY@cZ#2 Ch(ΥXXJL]:! L<@cAch47I(F!nm7F42>. C!`O }N ΩNqzxؿv7B!Z}$ |Fk<0QUqC[;$s[A9T`f%:!mqw |it+ q 5 W܍Q}[E͌߿g)I@s#d wt ` I|٭G,OH[>pnKm;a,)46  \/1B.9P('4LӏAEC\LfLfp>gdwOxr:v0݂RղۍJIy(’HU`c?ކZOOE׷{sqVn,? ڝH'ݿ<WˑY**]N@~iKY8`U?p0I%uw:/{Mkv]z  irMm+CA MM¡P=yX* u&m<\1le/s Ai M3ܽ :HxovM^Ua /p*|ڀ)wt Ew NN3ƒ\12P ץ0XUHy"Ү=Okx|a ZY^v ;LyK_Bz3m19ɇi1Kby'=_u SJol5]P8Ŗm}@s-}8LB+%Hzw൙#!d ) dz!!M43i7BB/N$@Tњ Ưpa wvT57Lp3#q8LX} $#腠tOj %3nAIn֍`G ~gڒMdNj:JH+įuyz|&֬-vAڋ'Lj^y75Cj9+Sd|(=lսVhҨЛHd;suZJٲt_; (!$Bn%)Ŧ4_/ȍ|,t:8eG^ &vIvd|%kn?u' !O$|*-3 7'{R\ JGfp:V3Yg SFf@߫!ګ3%DkAA"?ЎIpwꏽZUZuбlT`H / `ow\q!Z_LjcKm XQ.|"1]UD4 Ǻbe<^fYi~#1poW'_~]:gTi1AN8s'aGlSM%.fOt4b{i޴bS0ʮd#K'W$HXz  }ڿWJkxME YE tM4FcFs:6kl=&0 ?d[= cH{7Pvcy<W'" h%06Q&L︃+܅ ZbY^vٍ$S]z!,^˱*H“JSn+npQ󻼌yNdMtau \%ٕLx[sC2}'jcQ4B5r$vv41@֗ KhX k-]hbYUo/c`% L(pic&L^%euZJG9'x`Wy|hPfXc@4zILi`+6yA͡ΙXvE u:iI$4PF_@te2o3%C?}QʐA+{H-Q'3j#a4:|MiP yJRl߆7#k~}w;;L~&xa : 껣yn[*:pm\^K?M #~eн nxl%*5aʥhL^"g\?TS]E y٥zO| Dt.@( kef~;~RgdlaOYqm4v*S'XnOGwN#M%gPVjg@aeD|$/"`& 59/fvC@ !9oqN-~萳&^uQK>V'4S|gو\fYai RF~v#ԁV>! gvn2G6`x{N?$ӨA9,dK\p7d;.D(P q^Q'xfjT=,G$o ԚFP?2! e1 pW)$5>}^sϤ`e ڂ> 86> reٻ208k=A\XYWM G|Vzz!1 €W^m)*|UJDU{63}j`A{5<󈕹vxf69}'cWɀ1ހ$uݝlj89\ ր_'vzkѬdZX&SK]U|? unY;L3X|$=#*F{G0U*c&=26z1eߨZq)Fz\]갘"lEkS̚Ww?sv09= \,lMebc 6ituVH|O 8D|Κ r:zxD.2sԋll0ĉ_|1 +GocDAUcWVDl\b|Kpcs{)"C -tݔPXW)w~ݍڷ(*P~=S#kĴ#N.B,2ua5չKS9HC$ ;8[‹_Mi29 \[d%,uKr+Mj sEdX⾤=rR*n:fxY aw;75Åks :0}uV?)oH*kp8L4 nD[@ UEƒy_M^qbw{4k|(.?}J<&Ig9"yd@ѥ?>3r$rޯ{d3eO7%mJ:q|Tv"eK+ @Q,i?d/jdTȪ@L>=ks/2f˿N(5_as^l5D NlYǽ@D9¯oyOĎ@2:V) g ѫߘQF@$7݀fsn2TX\O'&hdF߀"A Gf^,rvhBsvϪoٸ=po(|T[8 N%ʍXik7 idՕ n%14 4l=4o9-h*iʆyT/GkA;uBfwF f  C@SZI`z&* ޖͺh;7U n0߈U:-+^9sk.ROT.Hj4]{y FAڄBzSyG]҇)cw"߇yRИ-zo "b> h0[ [YNδ xE7*/zɆc0~)0l\{~zɏ3{V.CWZiY#_ /ҔeZ~ 6S龔3XA&7[P}4k\?^htǧ:7Yg?d)g`+1PNeA^Ut:nixJ LVz ɚ}Lg՚յG:^dp&jc}5ʾMǼd6,sFRդA'|~vi+#_?昝@OʅM𘥵m sbHZ[5S 3w1j ] t.t]-:N"5k24ⱎ\D?GE(kNq_-İ+OYJRK YZՎ#\՟7ANݮT.GA ^dT?^uԗq.wMy7LOfC8{@)i(B EFJ0TD1í\)jg?6pG1Of7X#sFAڒa} aYCσS 2+u+}.IW鉹9gx_BaãҒ;9+JHP/|? P$2=MVU;Αri@PC!̿=UGem\qdq A>Y@(3H-GmnO^~N3Hxj d/> d,ai\1&)ӒҎ'B39k] GBTEN/ BH}Si˾xSU*F8¡]iB`7`^opCh.6g+&ҕ ~R%9[6n$6")4O*~}Ļ ;pyoFfGH Z7sĥ仈C#})!}d<>^',oatǮm{g[us 11Xtl*}u7-3Fʹ{N{ Ad>R>`~f^iA0HX7H9bma߼Oɷ䇅?.Oޛm'DiXMB?S.=j[}̦ms8>P1e`zjX"Bg N}yR*ß1 ߞ[w)RV',wffZ]_| I>vswۛD*-YSc)mf!Psm _sQ1jh]c L}sa~!!}iXgk P,A82:^h7D۵tJ{7+?6%6:Y9ͶܾOzRRvbPDSuB`->3g<961e ]{樉e ̈́DѭΔsA70q҄#IM;)qrbМpP} Fbb?RxmsZC7Q)=uzv hM@,;/RqSC@MK.{;Jڗ`  { ,SO'wv{AkLVc"ZЇuc`fyL2^ (f#Ae*XPSϳ~W2H]2VQk{F ÆуӼM[h:篮\k%p6͟v Sڊ,Pď>:¨Nۑkϑd‡825PI.,QqGȻ}??,9=crXH,Z 7P9fkT=c\ J=tqӜU\^X=vr*x4P}H*&#_j }pw˹i, :Ll _cЧx#<2*ӿυ$;,"-B1cgSHl9&Oqɣ4La@_aR 9Z+듳je穊:aD"&7f@1s#{tW39]0/w]=f(!挦.!h(#&[ Uf1D3ym:DUER9QxEߚtVpS[hnrU]PA%=r")i>Adj8'v2w7򗹷Yq`ȍ Bt%> 6S̟j 辚9U2b)P=$Z̭?#D)N ;I2n_lP/</v8 /7SFڝZSą2uBK>u~C{Ei Z?<[Zq.XqqjT %&J{4;rn@jsLZ _ +qdjFSs. N6ur| ٫R۽辖8kޕBS.ؕhD@X|ϖN9"icٵ/MF6g}Pd|t* @? e17N&h9^.Py!wLgM՛ɸiK3O=Zd6.l~+4l@VEaB0Z&L1k_eqs}}=4xX"C5B^ ݦSg{cHcKʎ"lkyզn'bk%Kg6(젾oyv om%ib<*S2 ߿$ R[#]BD df Rk ,3FjPբK:Hc-?nFD+#Rļj̬*b`R^ॗbte̚}I}ӮYYi<-.ލ|Gn^(+WO"'y~AY/ul߾[tNR'[Z>rӮ|潮D*WğqSMz6]:PYx,@IfRqpIYQK@-$Y^;?/! ɏ"Fy90wI(ۺw ^wŪKҿyo06)q.G$R Oj|҆ $twt';4SHm~ 7i陸ó&r*s3r<19P')8"?ljLRP/W=?U\MeUVXDG ‡VP4m>}YʻX /,(]PÃV6 Dp;5g\P//XƑ΅._Nrπ \ǾS"Qc,}ӳMиu/L8GvhcjK^JC _FŨx/x2n[‰l%=~iwSs'Lu?.ˤղdR۪r3aVxP ~3F3 u7յi!?u11` ~lM(5[DL$M%WI,LZ}%|LP#!M_h.g?)E)ԓd=dX*"t9h@:!Ǧrwt%' 's@ #( 5+r\9,%,&' lQ;/)%OxԫM|KB S;!/Y;,s|Q>tF2ϰ_7 !+Bxa%=[  E31i'm;~+ VT/x5\ceؗ(n]%(`q~5^@piK: ~lxTxzQׯ50 D D׵4HSK ش@=U8wFY)ݖV=۪ =ܩID dȼ iI]732+։-LEh ş3}l=om;SFKE5bYiGoQHt*5~$}$+h H:_(QL??PVY3wY9 ^l"6syJn޺&2Rl^?st^8x%?5vvg5;@b-CbJ:Ҽ1 Iim$6!gsDӦL҈#|82R2%x ,wP i8=RBZyhÉFSztC9wj,=_@d߲nO16f#uHv8 gZw.}˔ I5REzIhz@Lh+M*v,# } ٠[5r,Xi^wY6!'xmԻ{{;~9vP|^n!^h : kbJ<~ujũ ꙜX`ZKA?HoHɭ6Ϟ=XmBͽ|&÷$kT~r&?7|CKk e&\SÝ>RuS](q,51$?Lg7̙srd5vH|HSp. NRBq#9;!ο2cB3R0m⣳թ)V!o"'֧ d%H$)!;cE|љ7ގQ+pL {cjid!̭Q9ßу hEcQ4FVQ:iO"wV9 U՟յe`Y2ۼL:#(;8'Jъ geC7h\ݫ3H*5WP6/r#)s42g[X]N6w% Z[Dy$Ibӧt`L:[ƞ!THd~!焻,rY-RGi`JͲޱ[ר뎁OsEGMJcM:čGQQ7i33^ncz;A smaca$ƶbA~g[O_Z;ۥB<IJAk>%p" Wه3խT{ֵN4Xt!IQr &IУ"G\&JKo2YxB!gO//kaz*1$LM)n_C ͚ޘDPBPpt)?E^l KM.!N<՜p7H[d$.{k/ѯ f$1hyqHQL{|^7[>D]89&aGzEH+*zE"C >N^"7)Q#}^V.7u9-Cz Ch V\:t,ivoJY\ɬ)NXCv$~n֏X87TS8-`3Fx⚌.&d)&mz2?) ƽ/8p"HxGS*cK~6ӳӝtٕkK+K_kbdy )#ׯܻ '3Zm"-04 48cF2fڲ 6/g0{y+ 3XTM\iGiG^4 ::@іG{|\Pe\yoU M"X̗WRA/tDC OwZ,}6rYi4+(o2Z+=1Ԁ*ڻ8])JZBrq4"'qƱYq'{-̭ W2f*$ -L^ia/78PxHDD!Mq&e xet:#kaQ+gHlrO-7V@tHgAud#d]X&`[.ZGq0lGT~^ _:'! %һsX$R&=r>DqIH:D~~zKQW۠IFbhDF?Vx{u[3ci-BF-2twW?h{8N x>l[XI('x0;k8-h<\ZٷфD51Efa.iy(V2Q̋Rl<1Z]4,MWe0ׂ'R|f@8\K[nE97d1ŢQpO&1L)]TG@(QY*Hú>SUduifF! gQ3?0rqNVש^^ۋyNwX.H!3LgI8נMd{IHasl^6&  EX~5o|gJg^$/,P/ bG_ dLcЎYݵ!ª4|I9`]D1F2_IETh('*Ӥ,mqA0@=]n # HDйCN,Bx, 2]{+-H"dJHji,Tx;%%Rc 6/H\' PX=Hq w AS- O rS+LhSE$'v*O`ZV;PW%@kU sD__)1ɯhHZ,9U"<@3<1 UhB9qbx>9)g\f=lM7 T%4ޜB`I!QܥT/졌tْ:NLtE$:&I_bn5tmpx6&Rab@ 3DUm)$/|&L!>J:3'9KQRLC8OLV"'(O}giUBg#=Z+ ^ QF0enn7./ (q!kL v RvBW x_Ox@>6{!\cS/n>}ٺ$g5An} YڒX n8BJw솭s%<59 #G1ĒAeS.&#ba8 joڦSTE_R|@"SsK)C"Iҥגw}yCxcu[o2p6Kь[ z?vV0W)q]{ngڡ:"dFDľFmO*&i)%_ӵ4Q04u1\a,ųz8}alࡁ@LT ڠ G M؅-JEL:u`''\=D_~~W^i+@/"La3 A]u͓~ΉorEA Ze t42? {#uw6S]{!YQ _BWFCUgiϳNovqBFPh| TvP.AzۖՐLłt 8)-/wIx9jN*Pr ^cp9u(>"`~@F$F2%tf<鿚fW}zmvfN߮3YDEk kxݕh1>j4Fd.}ΌN}UP7ps ,ǺnuNsz1btR .{>lA*V0֚ 2сؔ07s5(2&E0+0ķ$# *a-g@R~-M/lgXnDJ4!^^r L=:TnڸY书kE I8&#T&?yڵqY~}`SԭG\@uˊwșmJ40gI౤<ʗ5ێ3Enc\F#D>KUDN Ճ͂Ay)/9`*i+tyriS{%(Tks$T#h>▸]-3H/oXoQ&" #M0s߾%Jn{2XP85 `dH$K>{ <[tF EOs`\C_! Gt,Lelp;.hqz^>۝m]&B%`b]J@8]aпCVvtG &A~ƣK kkqo(vyypz,VlB_AKs/>(qG,EӅ *蓸wG^%} lO)S]3/E7/%d /MCSR cPGl;pk0|8Ϻa RLqW3(H`E֪#~kNV?azmX9 _x pq'4%)l{,_t)i`l0.hS}Us1MΆ( he} HBrD"$zkV;9շ!qFe4F߻r %CT~Y1-wJ>ѧ^( K=Ko ?)Ihބq|?7˵HuV<{wPYg7cL8b}/?SW[h]9G;V._i\ңxcK"\G K` C?9;*IVf@J %K6ް{ Ldmo?EƩ$HVi,[̬'tn{0ڜ7v85do5_ Z/Bݡ_nsĖ=i?LIHpR[*wlX_\ b6oAʾP3k.[16?X \hq펙N8Q#t0|yل%~~Q, ub.<-`E \U-KbݔQi;@J1BVNd 5|)ΆSQ$"W TI8$":*4 -GpBILd3Ty:NڑW{AxUO֧_6Qb9{FK[=򁶛xzr3i$D:^9^הgqbK< 9'7~m׻VD0TLQ̍RM&M7{ ]_^b8 N}?uiAw,^U%Qز{|v0u%^b؂݅qL\)Amnrl7m" TR,бMOoLo׼slz^ͣ֊k@X ћܱ=Zc} Ld y  %'Je>̯$+K |dWʼn};$tuk+o|[ZtK#.aJoaeD09UIBĔ##,–=`lvCrƖ!R(_[Wx'_Z\=5e ѥ -a ve%N{Yj"lQkUe/0*PLFYhGt=eE62|r$Ͻk L?F%%aWኺrEe; +ѮbĆ;sP#ký('_F^wC7p)5O^8o/:,\_֩ 汜 rߋhІJ|Le3R6dr\гB kF Ȗ:Bc|J&1N5egvA %CK'@ ŁS6rV3N*"A%:peAPc.C5E2ɰ( r[vG}hePbXv_H{h G}=/Gfjcjmߕʜ1.O)Ϻi_ TK MagFkKiiZ3_&좏P~Fk~Cf8=q}. Dox}N6rR3S ̜uIiu{Ī>G&&C~ux(14S 6\:l/O)hCW "I XhX[EH0*V@$q9zbLh5z5Bw_vjHƨOB%mЍ$&-dS 3f/gg3؊QPP3cLc6rBp1d33PqWߣDKSuסºW`zwg:e0etm` O<; "-"21{V 8yvjecw-G,MvӸR'9eBЅqh9X>'v]9nPs{ަtH[#D.j[-MHU?q2a?7N\ldQJt$v%Г*A `FԳ;Gŀ['f; ϰhQ z~n@~2=؏i'zk[{r$9EyKY˝wM.7+3Zka/r6bb7$oU?.ru0hj( b=2} ߻G-:^DN2- h$RV:N9VZH.Cfv{a3Q /A^\xw[0ߧZvўR v;8>DڰrY һZ"h @qCƶ[_+ ̀A4TdAyoC LK,}zW*t?P6!"a "l848a_fn!U0?i^[`ٖpA[.ʩ0xmA4\'s` |vW(' eӌ`lAk%VCNx5T^o(.P.>Ȇ& q 04LI f5.=#oѣxeS6삆m% }*y)(s803hS6*"Onanh/mQTHŰ*-XrK|JuASi=ܭ 0856e=Mɳ e'u!!.F!J \H+{7 ]jQPR ?W1^ &+d ֓rb?eg>.I}ǟOY`N:N}m'~IW}n~cM>!__kce过3'Шwgt[qB0 rjrОDήcۨ6LC%+m'8b2$Ahl|P-wE< o^[:Ǽndٮi(/ErrP>- &ј]|\ I*’e5IiE8ʛ4ٷI]=Os ڋ;ZU\͚p gjg sFƿ ux[#Rk [ (2x^e%<]b|J&"q`D:&eFBnTu XE1!a'Pp4$]c{m┱kv)DMdj%7XWn'ġ(R?|A@:X-AИܡQ{r0˺O. R\D8WQHILȁU$f A,71{aOJ.@xV'uϯɼ\ZqBy 6e 6KrxD4ؽ&Fm:QN@^?6/}oe٥^j]k3yZAi[nPd`:H\Qiy9N HLbG8a< lFq&h0N6HN)^` \3 6`Ԥ[3 ^l p<</ -Ӣ_a^Rw?tÍ* F#A!SU x{`.wk8͏8LZd&41=vSHiiA"|I4VqOw2-ō]WJu>5Cj:;MGiǩo5dQ#{3GDDI&`h+OB.,dru81LTR5OR?DLo=o9:^+əK;såg`;yLxYU5FN9LZdG/A5ʏa$+AW郀ƴnĻyR%~@ٮoƀ)ťDÍTȼ! m8@d/1ZWxN߉r>,t1Rqu"=WZcHk5jo'߹ Ժ(kw E*?-q M--{(sV5ybddanvcxP]T^FwCPnZ/eK*M\aԈ((:ȂB +8jcyd*GJʝ8 cm9QȜ};2$vͪ&Oº*CH'zΞ 1/_oڵkʹ~"$PsSbP\5l\}-fa䓃?G6{aodBIDtyvmRo6Ń^` eJ7'KD/n7_'\ΚpR=V/kTV.-Ôy\i]Jib}#52)+^``' =͘^̪_|i}lKkUzgh+'<e)O g1¨ -S0ΆK~wd4e9ΫU[ 㘺wź;< brYuf<$iB9 gwc@xn{ .8pNBLAl2ssTra㈜ޱ V5%UACχF5)|ėBioŷ6~$6q "yC_IBo{;?^tj[E9̴$_ZG3r*Dv3eԎ-Asn0MID&JJ96L͹͚  (ޤh }Õ470 &$(u?kBhxYmJTh&lC#5D }D=MpX) R3fG%Bts!4dh<)LKa8Cޖ@(3YX\egG 6a5ǖC Ztoq{d#*z<`ȍ6A.l#wK$7x=[Pgb'5oYwc*ΠQk0gyI^bYŐPLĶ-)iꮇwg![VR6i~S)Iakaj_oA|NjaKt`XO-)ЋG>u$`5Dl(?LEq3L88rs81*a&+de$K#cv% ~Dؚʆb$2#/eGFۥo "դnYG!t HE6λbզMWC2dԍVՐ=IJ1-*!ZX?jy0IU)dlNbȻ#^.MЙfbܕw8 ePV/iҗF0zk}6 {;2rdN02!D&{V3HU!(5knC>R3;汣~TAhMCWE,ȁ=ɴ/og '!Z-Bu/V$|iX._!xqVd #]VrήXjK7ԩHjھgH*=4]!QܡdtG@hG*#,ʔdz͚<gWߓOtiv4ǡlB @!C}IK,{B @xPq5ۏ_ gP%%n ] Lg!b t :JPbuZ`=e,])L<}OȾ"뼠^\={fDxinG%?P5#T>$2-1ukMC p~w)VW0TC6ﶦL:gyj> w 6[ZBqE5?)| )ERF@$M%',exSwNw)By*/ʲti)֕OjWt @ʭt~xveYcFj-Lv_#!yc$e,]wZ+aEa4+mhe>4 s " to\kE)OdԊF$j1TB‘gSwͰ05VQؙ9KlXn _#ӗc$X&@6cn`@̀u!8$ w^܋[!k !#!;џ`r(GwxY*&~"C MErѪ6"K'B%sx]zؐL|Ǚvl1eb(avh,sEtL65y5] 2r# II?LYc3qk)ټ@E|oeS:bêaA_hV%m;DnҬ9VQ0ky˞UA~CgINag vZSNVx'$.o$S_ 5:FF2 gγӖ(TpC]Ӥ-1#7J{ &#$#yąoB8K%w_;QH#/:2EbEE6>XxJ\}.f+<1B Sbiq|P^r,,X`}Bzsxs+$Ma.``yv.sC̞]MJ)Z_eN%{ɢG7 4d^ȂL_4l5K}9eʰ!4#Map?y7AbV[ּsR`/W}ʈ|JU:1HQѽ}("LQl1p>YZ jud! Xb l5U5l-S*&+) 0-!A&ϓR f|a obU=pZFFVݾ;,j:,J&u DGл|.)&xSxPBF#?Ͻ.b#lG,f1}ʹN_B]+h TQi @5DvOnt zOBYcJݱ?XK?QgeWiUNElt"u3KZU67O󁁛}gjTŰ4tS0PXla~"FfPjy/T,+$v@( }lFDmZGR9}j R9QHi tyRA =,;c(QJ1yǔ Ҿ+W+%tWI2t_2"ZhtW)C#򿶏#a$[=ܝ.3a%n^?hKⅵG:e*]/:,׵Fx̚擪}0ޕU:Ξ:74w&L iPr/g]) bGߤ z~cCw$q^:5 #MNzU /J*Vy>f5mi~{ciBnh$E'ڟȄ b %?Ϩ]ClgUYyԭLR: Ywb,hnW=m.V~̅ -%%=lzJ32Y?^ ,dgY$u4L^$WF!_:ѩ-yx+Ì{ׁ)rU5Ekgm(pNpv;mCJ^]c gj4FUYg D:~=e~źYgJ**, A'/TӠ/X~nm<XapTtiK]I d`(4?ͦ$p#.!"d11SF* 4,{s}w?L5LaKV܍@vao@b 5: 0b)$ե- X~ i⛆ʫ'Ǽ`LYL2W7  CqɊ f;1rKP3eT|NJÞi+T}7wI~PC{E7%I#K~ NZU`sFڽR}amw:9L Y+nL~IsY0 3$wkCO?UpPq3&7t`&+X =FZ+"w{$FH<"xW27+>F[YmYΠ"]u[ٞ)vn82@USPRkʡCOd8AԸ`[YP)|P^~֣W\-_3Y*5ֶ`a P~%E Aڳ ?/8̽員gY/&E?؎yL|=i G= qQ2IvH*UR3ō53..Z,$$<X1,11 i[W$I~UK)3?;7aEZV*= >kJR OTi3[Zة{O1ʰR/ h½!x%%O:;Sc[>Z Y6Q =r iY1ϖ7UAP exځ%H 9wy5,UM$[+ 8hyOOR+|[6"RԠl׵s f͵t=Ҫtqv꯼Z48"D3 =/ⰬY]Y* :l. T(DO8n:AʂT\fl9Q*Wh*G&MX}"D3L:W Wo'0auo`x5aYy{LjXz(% O&Ғ.QuaI 3̱deg+pPWy,:P삈G~:Y Ce#c$0.hTq,Yi.ˁ{OÝDa'D4=.+fl5jx߉޾/,PzQWxxTTI\%*Azȃ蚟P[I#rkyr fŽfDt+d6'Tp ꇇRj^K^gv?N!XVoi!j}IT;o;/=:_:m/Ck):I S/hF3QG.gXπn~&b1mNf~984ZBIGs%Y|A t"iy*eTʅ}=C}9aҦD^ DÜ9޺LM$Q Ö`NU,6Xmmɽt_ٍul#ta4exNԭoøНj^(mA X>8aTsH}޳-"jUYi`ӵ}bMw;= ^Bk4zji{MSm@E=nų$(΢Q'GdD[߆3׫c͍CJs0,59G2/ݛ6m /w?=#R%'ahs:Ȥ\<,cȐ jQ(,Kw\p’zل ]Z/ xl ?ޖloJBYQ GlpuDGF@o_v*$ wよmx- bs wz? :N9FP;6!baI(wobY``+a,n: SLC[ ~Lm"J}gLD-:a%P'{=i&fv!m|Oxnp.(Q:0of{t҅M53Tig4{ɀцO©Ų&fyt‰If]O2>ɞ}V芢= A-#iƨBvb ګv%(r U>vQ ;^D^NU4"V1`I=eXSMZ Ic7Ypj\jv{s* jڗd}w ȱp߿ y/-͉wgEXKT)(:`߶ˇk|? A^s?zo9b}")@|/]gpn ;ȅQqmeoT!g2oķ3Os`7>Ě9L07 (njXPѧTb\sJ>5qݜ2!+qf|yi;+wBV6Wf ";uHB+sF/}OoHTJ9~ Z\ .GV}l6I{J&o~{*]as촡yG#X;[ ͪ%-hm(WnQUf{%Lwqׂ JQ2:Zb:^(p6z܉PPh}2`FV ~̵,A`jZ=epz #$Dxw'1=Q0Q*5AŬ;SPƯvj/)Ԭ#{m!υӕʟρ@OD ԩaOGYRmG`!`m hle͎z1JEr b !q@B[q)a+27>\Q,3wB3S MAV޹ :G3Tt^mh-<1Ih&5x_=|ÎI]w} OFn'gkh36&sZ9>W ]QEpGv{Ycw^4edExA}[P[> 4.Y[MMdvS21֨J\ԽN] ɢA &qwIm!ؤfmT͟ x2nXŹV* &:>bva)ȭm^s&LjZU_*BI6B}Ģy)%Aŭn~UCzueA?9rVr  JwĶێ~ T]:0Mg6u "wP*wiȰw9<\gA'-L{a쩚o`b {3tu,P!]%_)0/|$Mx鉵TI&}/=*u?څ _}x8HT޸dz>%wQ323 kCjZiZW06cz!N:Qև~fa>Fcwxt0S6{Uw/ 8U\_FnHQ&㠍D/h@Ѯ X,tRjduG& w>1WL(3G0;9',5OŽRA7Q]w"CɕILgcJZ 0Y>;CC&V\`MpIBV=Y1ΰxG\U֥Bg.`CۦpGVmP}~@m{{hIߛ"k]jZ- 4 iw4Oi="56짙 էGԃtcIiJW^p( $#N|td5LyGǤ 1sжVz+dr?qps%[ ,E T8Վx7YȠ N^SƿڍVx78&cy"  vR4.?ȴd0n k-44Z _jɈ .p%GՁ?uNUfv\O)t^b؍JP YJ_eP,[bq.7ߘb]NdrHZ>#7> zhCYjj:u-KZY [3=?/V:+˅/0x ZwC%d {x:PhsݲYC^7CF#m;0f/πYbג]\mϲQU٬C'- 0%{oVww6H.:+%EY<82.r9x?&s1 C;Q<܇ >]qtYS 5y@kuxTg9Ȥ߲#2#+FʽY6v$G^P+. e[0ыЧ>:|)N[d7ereK yp>e І5H.}YT8E c2U9axQj6r!Bd'{ h$]LcC!Ckw՗1I:X\;A;Dd:;)oxtv&8^9̚E$''µ'~ӯ-)?.rVdv) 7gϯHLR whТwo|34SKFZG=K7>&9Όp*}I3s-9x)Z1|| ycH_{/1U@)Ne`SZJw\u8 _z`ʊuc]0n)o]\&1Cټ$Cq$B\/?ؘqQh'f=;N[Tm׫U1#*}dk[{բ1wJ!X 3@a:/b'Cb񇥶}K-6 9 "_;L}O޲`:8fF}I8 el!(9_Y~b5s "[rbKjAi<7 J0Iw&3xB[P!Bq}ޜGb # zU] s K3ų_aitS$mVtU쩾2t)+XҊvŐj0hAdtǷXlst p ]$~ bR*TdD KKh=g~m2?Snb{G{+&cJŇd~\kRO8op'߆6/ox2\M+?咔/8>As/uj#"oY G5r} CXIu@pٜzWĬhh$1l?*Gzt9G .hƽz9+t& &{0BFz)|n+uT]ao_Grj&{t/z懜- Xq-,t2}(v ƺAlR0&.r'd"H_dSe]?kJneƽmԭUG,1iS3nx( @1k7DgEDCyf:ǮgXuh|,LQQ:#-9-mhy+>^[1ABys Gםs뉘B.YzB3D8>4ֻ&ibNbdߵ&űp_H\\c.q95bWE(Lut9_'8(  '7; sK^:yOyA\:x#aGkz֍E g gbh^9)WkRwe}\]'cv4gnR4x}fh ?͌"*m[Qďo&UmeT\}%.uN^]h.zoB^^rQ$l'CE`iDPh1?W(ݙr | y#!{P@nÑM/5 ϊE/jܘl#A*4ݸyČ PJZu B#N(TN"1.?=_qBJ>/UDߙG͂ޑHF:߆ճT C^"ZZk5P9q>yyfh"NkRWo=L kԉD Rj?@|%үLJUwb+AL%va+I(. ƺL5G=Wd79y#8*Tt\,Ȳ `V>@>_ޏLzOs6rc۝ $O@ V/K"+ ^ Ӫ^gy;;VB77PZ@FfwUIĹ q#"xiUo?(Gzk,Õk7 4|f,d>m>6u=Oӑ_H|,[h<=ӝer*9^B{OlA<T7;U`v ġqH`7N~Q/(X @"DvuAX3Ⰽ$7юyqf$OJ#GAjiX,*\X&Ѐt*N2+mT;Ѫ 6CbH\rFC=åHkmکF#V}8@(ƸPoN +L{m=6솎w!+9G>-#*k^(@|dtGhF|:Xi Kj#W؅RXV7[}-: ycifW&E~VEE۩:^&U?:Xנ%䉨qBݟJ!8ƣ`>.ҮWQejIٙe.R4WH6>HWk)ۘ^ԝCg8a0`rOh',6m(/kUKȸ^ ޏo'渫е'm +KNV>v{Ά'>qdZ R|vEAxUUh- DBg%Ox^ȎLUPJ;ϰ`T(Fc;Ow6/[z2!Vu| |$cLQ l/0BS@ ׂk|>,us]J%حfA+p`BWRl)$!~l\6Bx4a")1W籨gN/HU]6mw15@lަ"WWzoH[+"(M`,oo얌Mb$4:׹~ ,؃()r$#>ϥZ?ͺMcMR?ݔ4G@"wؓgzNYaUƆ5i7ryRWQj;b9i?ySxY}fiu2r<o]T'퉁sDCc^Oe m#'(o_<[;wR$UhĞ@{rDgƞ[{~b$k\i|+ௗA}Z,d/Y+J靐!m3ֶWHx8ոvRFHLS1&KŝQw[9[K;z#Ykčp^`N¬\ v~ Z \Y cbr<}%¬a>TA>Ysjocm c&33덀YD76c5\Fn7BryKI/KvmyzidM ݨ (m]+{' D>@ ֜UtjP$']b6f4gM۵ MrLC7ElJ%k…]ulyH+ A?i2{~`ž1N~V&0ǣ͔5DX=F뛢SQ R';DFN4 B? ׹7H%vUhl|(O04W Kԫ1+`I|mEn,LZ>Bv &X*`76쏤:2OokG akjwIJf>`~t`r=}V09ˀxАaBSOn?2!#x#RA#҉ߖڡ(U{u.۪e4Ӳ$R#RP!9GEpurc ]tٳg}#.IWc=eiר>ڶZ>c6LCXhH{Hf(7G ܢL}f/FCL[y h_Q)9W\:;5$c k+}9N)MwMȿ;l2 #'{+e^eİrfu=3h M}[ps@nn:6z>ġ2R zblvNa7_.}Ыգ켾t6ueu  ' x'xe1EtR9RE7=S"W+3œ @)lu 7իl ][\=/K Ōv 2th/\FJWE*k|m!&%J6ORޭzP8D$j с;ϩ [z"|v}ԥjgmoz`^?]V =EYuh!8vԬEt|;!ȰA5єN7{uPC9:fc@ҵ.;BhrSPmsX -)HHP;N)4q(/7MsQ ެ{iA ERĜuYJG>A`:?ӫYh AEFxCS C<@ʹL˜-p}I5=Ln[DȀòs d?nU>DB+X S2d%%*mq~.\+5dZ"su[}ý(*I`Nurx!N+⤙iUpX$a(866p!ʌ&}J΂6I%5$PG`k2VAگGB[/UU[41=iobpȦxY>aj!BUߖ؅o167A! O\B\ $֬MK,֝?(۵Vg̓MǦE %(dA T6ށƱ'G>k`vBQ.?DL"5un\@M/ꌬDB㹍d5DYM?*kde#RNnkexl+` w-e.-f&j+r' `sb LPiV`le q@,a(=ʩWPL6scaf8[t YTO8//4&oO *LUUrtoP"f%.2vjo~45>JߣsXO8PMʳ5va3,cǵ@ֲi4ږ9mxCȦ cdSZ{)KHX*_,nD[`]a׬kЛ^?gsh7']9j:k3Fexqwkҽ` ~Lq=ŧ[dfZJ&>9J\Pf57NDN[sr_`@~Di"._oD!h~LX*OlE&ZNsKH; e,QAX芢_bJ.!+u'N zGFӇKrBS2QƋ5j%yVxk}f6pP'ム^_ɤYzYE&{̝ \}9:g 0Ԯi{(nEe{ֱjm14h6I$@a0тGE3g*XPk,*>H>eMNq*VZiz'm?բ%"O,z,MU!8;'y Tr1 *r!VHIsKņ pRW#҃y.@9!mO4}QsTmi#Ͽ!TlMJ^oLďT=w6wO.(%=SMy Ϲ?W34`#YSt*hͩʾ gE#m]B|oj?#9 l U#X"s4a[;gE+{:S$1y Pv$k@iW5}|Q ؙVC7[|'Ѕxz6e9rii)0IJw<>5ԷڋQY1yÐhHcl욵y*q/Gs?)jjV#,K  6%>c 7 Ajj"HM_dbl26+9C%^EӐp=; aGu-1'=l޸g.CA/#<xENh*jff [QU)RHKj`9`-h̕n/BhюeG,MF]ETeDxBPI+)7 :3vXtjA9I+x2͇ haD2T55dtH:1` "K9N?"SGnq{t}qrL";Nx:KMG{d@v;s-'uҪ(7;p;,XA /j 9$幷][#}26:3lXna,KKݥ^/ΩZw}pEG Q9 Kc_UItYߺ5|CmS鲰XE~ˤB=A" +0 ιwa86+U C> |oݕPgG?}vm~ xHҗс+M۾=OEA[RxSKDIJF `l 6N^ icyDŽSos! ,F΃u]Ph3*)CSĩgfRwSOyIIY`8;i_S+8~DhDx '%ȎLFh/eh4CKۼ0]>QƮ@ /rC(_@ z{YeK<)Q\}Az*՚ae~/Bj*7E1Q^WWP {TA\!>p7uG;mYV~c%[\M <#SyD>=_k(&.8GDypsDJ[Ua5ojUnٔJ;~_{%wғ?Ghc׹cZ`3O7zN+?iX'4uG0z^9o'1 ,iMZ >$6a 9% ^i#s>Ȳqڗzv^dN DwǛ_ab##vgiqj)q-,XRz&k f~KTZAZ fyc&|r ͽ&2( k_ $.bP݅9ۂ+^jkI*$Q}nFcMP ;HP;z+َ'"0,2C].y /@{IEmʯwH'?6P.fpGY7VVIJ_4~W}:#zZ+w\q:%HN^Ma/˫uߢsaT[q6t%a $_3UHD]PZY3iR:IGY+~`,3wͧ-g!l%q !#'9A;+zfK@#E ƨ 6U'j 2-Qe6Ck(Y>|ۢ'%axgk>FD$;ٓMnfuHZ-Ąͪ丷Wi9RP^1oS+: 0e{sd%jqҳvJD6 6 9'^$l=pؖpd:;My)Du' 1xlU P>{7AZFy霱Eq`+s*}g-+Dq=[[۝MZ*=!屬vԄ{69)C_Z8ͯϱ֋X̞UJa_QD7uQ(eNoDz Kbc | Ƶ҅tu#_p-ۼNґ\g 򹭫as U4 6/ c1&u8R;B+D`Tb(󂈱<B4Du³9w<ڭ52KUkp2h/dI vb\ Y`&ќ tZ2;?e s1u@L7 d}r t6TPKZOBf[ VzU}L >oM|GSʙX_a澌gjGu_:_QNR:o;|FCj5`Djiqsv qmEFt'%XM΀pR!R8[$ 8HʢM2sj m@[T!3bnM)ڋ.E(gBԾ [E=S]]:nᒰm\Ayٿ8s!hϪmg'Z UtZ#-'{aϩ$<:jc3H?f浚 }~qxܞ`X5fI8r[x`[XoMmYǧ'N'똈P؄AST߁U޵ic6-C Nh1BKK^Bn3N~''cbS8QqT6A/ߥ MRNN~ȟxc%|"q!?zI /[WćE;k `J04W^ @`8Z;R{`+*G{dDT9v?h@ZI ሃO Pxb$a >F~Ss[WeVє:Po:*GӚ*&_L=1! eGjCj} e!,^(82M1[율J7{y-I1<䭦j_cݕ!S)%! %/q> 4EGgn{)WVwbBfY.=z*Eʚֲ O  WDh8Ū1_}! B)Ⱥo?~ ^&+U G1&fkipkmrJc3kKX WvI S~L47X,_ק`q,TSa!Cǜs t+2 k'soŻUk=@gz3- s?e  \@eHAKSJJ$rMSgDOǯwZDEFo)u9rۮbG5p:1Bҽc1օkid H%%v!nX;=5j8"iڙC^`b>e)1o`{(嵨o1Yp [v] Ğx l5f}ӽ%2xF% < y6y:6WW_+ynh .mvWO}G.nxk:J{J̬ dRUg=wA%)z9q祙K{%Gx򚯎w|J3mk릞X zuPlKV&PSoAdƎ{sc[4ljvF2&,\sroDE x垇@l4WWApKȐytJ,mGБB&h>^[y]Z"GJ#f_`P,p]J\xCzm.lsZQ#|z)r)F2&e FӽLI9_ԣp'x=8|9'8mŞ%,3]bIbҦH5j!"CA6+؋Oh%C OC.( C*F (Jjth !J! C+U8m鑆Y?c ˮ,@գ=/kfXy7*`eC6@~nG44p :&,ž>bzN{Uk@JVS^ԫq<]+$JzjmN/5(ǾIN2=wVP}fi21=}A,c\HqE$_ig +=b,R^I@?XמV<}|rV` BVAf؍*n BP,{23,ĸvxVo5 ),yR Q<ˤ-P6g=В8ڃ^7XWVȅERC 1-^lA=~V0NR vINygF4&BYƞek~=en}|nyu Ǖ, ) 3- rXtJu>@(q܎GK`..M_n\+>=͹;?eMШ¬Vlô4?waLq=~&z#rr.ڽŬ ֻwP#@!U,n(`OSv@ocl=Yq3 D1i 33 P/iD $;R\}&:z?@BéXgW9^#P~">'k;\gܮ)ԫ1>W!3N]K뗒̅eT' /ooTD  393tE"ʻ%Z-u1+E 1o >'+kJN踬pIwO^z{XU[ юxsj*!p_]ƛLb a{9cP,MIsTbq(.qkCQ\-tu0)0?XI=ZܔyJx)#x*6!swnpp[G9u!s~:#@(s%\Mp;SX-IxݐF‡H+ ,fk~/d3e5S0<%x4}X 4 4\p Vu ]6ϫ(C[Ksuy0i_%yA^.>FA$oqtAvy/HmЁV3gV3@09..R`#%5̋RI~J5}k8QeMeg8⤫%#g2B^y/ xwU=defj]gtJvkvgd0Ccʳ?n{~-ԾAnHfZu~"r8+@qCpgq5 PR'V&#v %|ln(|8|]ެNy]Bem|k2h-yn@w8bnTyT3*ϧdʑMǣ`6ݬF| NSu PmYZWVk /Za+V6l1F^H^m3ӑ**Bp P _P eg!cQNɂ-0Χ,K1RHk6\~ݽV~8%y˷ L`XF;5g[,oڶ˟43=cTYrŠ P؊VlĀW/)㩚1"_I^g,3ۍ]V<:Pwڙ8'bo}"kX>h}fik+p;6l::'q5u#.< Mz@Ɣlչ|:ylMKPXD`|Zj#}ê@؜@*=ȝz}++rVt Y Hwɠ1":?h` e!y6goiiò!3$VPwڒn4y_i+ܶ.oGz94q`yJ}s3.hs`NesFe9{M/9b"r`irI*R?y R|hw6Ce $vOhؓ|mC*+Ne vwюvFܢ+G/vCvm o ;K]BṘVt1npG1dܬИӿT\끱8\8% cNz44g\ r],P%]+Rur,IA=HӓV+lٽ>:{LAHŽbG{?X:mQ|$oyHxgg%HͪZ쟊I\O,t,|FgZdOqpY+W{ li 8cIB GFf å3E+aVX7lS £ֳ(^s' b%uG1Ɂٛ:46u:8m']/H+xa 6(%Q?K/wiE]u:ѫ[ Z =I9ԃHHZcGܬz44Vr/cGtJO#(GJD#\q'"NFO׌FSʻ7kCRk-xM8`V pB!I΁G%ثw)0m/Y\ÖC}Bxt N7<4+/b>x7Ki[8s$. ˸*"e3!2N#+Sf5s<*=b#lG=)sV<[ '8"#X()^gL'[n`&D݇ByS_O:~ahoi淜X=ćmW 0pT4^iQ/k6 QH0.\)S?nEu}U`B;rՆ܆SóݰiݑNu&E]ԈVď`.9m ?'Z5n ͛]]@6"s]y6O2:W 5KqNt^VSm?|aע̤-U]fpI<nXb.Qj9B]YSvyy%{T9~H!Xq`|ӭs U'"CbO~m&ZY6SA}Q0O}|gLCwD; ϩז%}a_F-6N.'τ=-/zˮ= mZ+<,~Et[>).% S4,Y$˯ '?P|VMvsܹHBKZZg;3-g3 `dk4ZI;t5vYC<ȘXŷd(KdHaՃ cɏ.gXpS >*_MŸۨnFVOq8 01__FSЎs{ Zvmݕo߿VLAiOc 4:03w/Ca${oKԼU5ﳠPк̶:GY wQ+ѭTgn{@'X8ى>b W,]^,93i= F2J6@l yx`G,>';ͅBs[dGڑ=Ҝ\;j;;b߅9d* #H8­_[3_͙{`G܏D42( c K5}*:Ȭ9cQ`"U0ˉX.|L(ס 7=&j[, |Z5;v a٭%&%zͲ?l{m#W@9GW( PEbȼڇt́/GQBٗ:ٽ/Y@Bg/v,ldӪRyZhxǸsASaN!{C%Dee52S$UxI Tɢ]uGS̀FPߵŻM%q ɢmnMj&$,X_/oxF3*'C!t ]U}g=0.'u&EsQ"'fW?LC1"WTCM' 'cbM,J^\/gbpǪ__m86ą^[7ҺAA^6^9ys܊vy} Cѷo+HZMs劋T(EAƏH6ZL+b]_435`iY{`Cr.z,?KpGE f 2i9rMZ,$a6BpuI" d,O)CCIJr#V~E ᙿW0 0дp˶!Қ5BP ^FUn.@W M&0㇅Og+7R`LLp';#8!ϣg_KkCșo9sO^ X5d7h,9~7"U[nޯf&NGO%>4 ֣G.([CX&*6q5h@4ץOox6UۉwL}6*q5"g;;'FX++>nhҺ{W̺aO Zt\ `rKK'&!/mO_ĐrHCls`k,CZQ?Yk<>}Y6aYNV]trx_M< WNko:AoD2d%֥C9@9nݑvWo ۓ#nOە~0+H=:470Q}oqU?@kkh?pn;"YWq(DZ|؉-מJ {ڛ#>!;:qa8 P8cM97 waW@O6WQHDY;^W{^r.t4nTiq_BX!1w>F|[wiۅLH;F۰w'xaVB'ٿg-'JF KucLjPCd}"ohj zMCXBv:QZ{ᬲfSeM|[k-lD0J1,csXa2h|%*^-IdQ]J#/q9v +cKm|ןxdNZ$'=u Dg t2Aw Ul{ry/ @|6$Iܹ7 wO}v'GkK{9ws*VҗVUH܆*λ3gSOq%/ anׁ.|hMd:B6swDH>R$eLRR:oE5Vƚ-to(9"#hI!D?L>YDov/ј vZ;;y­0B#9.lC,dr'JWO":"#Pe kFzٹqt4~B܊`# 븡Q;xՑ4ryYYalfLE(Խ [. ԇz4_Q6a[3_1Gk‚h"SN{B$ A]*Cϐ+xd?bSEf{eڵte]'kchG>y#v H)J#)j,"=/պZ0-7|~be+ݼ/N1 Ĝ(_r' G=ONFs0 c1?/fUɽ,]s1).ـn"PDx{qIG&"0 ~7b ,0}/D9hp;?v"7)K]?UK 9Ċx򪘘+970OSS$>ҧXZ%|Lwj!h7>yrXĚ~W*f `dh=U0p$:Zw.V}`."$e霧ҝZ~TC.DrX?|.# wh=NK@=vL') [^mj9yM]>=QmUܘHHKІ5B M<{9XNm(!YAN0W} 7^,jFjԔFl+abo+P^)Ɉ55Au ufvzyz&{t~BS^JΫQ>5W `\/!]pFײ!Cn+9-M!tÁZ?p:jTO >hZIatNw }\-ҕjz~~0b"K3F^`w45sh1dkHH+&~!5[X:#YnEPBMB~ኢ}}'uu͊bsSKd}&?e@g&gL% "͆Mr7,e*%ZIQt~BZesބ3fexcIuLF ^g]ME2 ZGsh^|mbbaXrHŌ0|`gKn-;ZڡZ86W##iW:/pN9U+nZDK!T%5-[?q8$-rBdeg-'˵,ai(B֋hb+p& p[;F8/n7*䬧ҧdw^SCRk"{dZrKjwrցCo\A0k&Z0ɻ Jp䊑^M2ԫX~{B?MpgCnKibט$.[͙LQ!hy])~!so\+FߔCkPvBX`Yf CZnsɂO_YHa^Q4Wf9F5PJ8KgUDocqCξ>W@y+d6p RMk ¶-B!.,Ud*y'X9.^b3p`YL/m@UPY>U+\IT0,V,8_8) F{ IVqx'[[;/!po4@vV0@@ O|nBz?]2l}Gαpd.?[?ho68CsohP}Oȍ^J4cLQfD,ÏY)f^B2s,jBKq&۷YVl>":HAn4w{(3a=~_TCUOOe!nZHj|Xa] hMxMBd;5rb&/AvG~o}Hs=s.$-H/Yt v/n&WBzE iv]RYu-0X..1 FNݔ@ڳ5=$-/&3`ra}P)-AVi\%SJ^ˆPTD~S3H㦫XW|ҕW*' NŲKB0$oAפa^Ϥidp6I]!zzhQؒ;B$|"H=c?rU`|RWL qhE$$ݢ[Ke\#ڑU9Ii6ъ)9xٙfJn2Lpr959(Fo'hlq$]}f:rЂ]UCq-5v t%lڬ Ne{J*B\pe28²ۮ2}'s0yzUidr6u@t$:pv919 Hqpͣl在eA̸9cZaؘC'LJ $,-IR::xEx sc'Y\="U9LsƦ6 CjwK_> 1)IK 4×, 222BU?~GO1Xl<A{@>_v=v.5O .5#L0l6F:Eo}kj9QwT-BU US9)) D0$ x$lCaG F?EQH96Mɰj?l\/:֘n̠#KsNg#lɚ)UDpsAf _R_a%)٢>R:lH{1 RzCIZA~K譥y 3zW?Y[%eay,p$*Ȍɢ"#CkhDJJ8W>yԧXLPifUMUa PFxP#@>yƘ)>ېWkSST Ǫ$us<@5ZJ7$Gh~ $6R%%&QV#@&~.U;>j ^E gDSJpΞ9Wa:OדKceF?"ix"UW@`Aw޾\6xi MH{pO,IK5u`NGlDQSalUsNzʸ.h8dr>Ws3泞,ƔHbK'4=6AR+ot 5lJ?WY[ g)NdwzAQ J*>~*[UO;݅a&Xo~g}fs} r]Y)."|A?ņAdq6הn!bg3IۀmT(ŸobFѥUqL2FԶKfg3;4冮%m}iX(oar9U01M'+" eP#z?ʓGÛ!8x2bL&2MݖiPEh7QFdX $΃"݈j,x5rr z:;R5OSʘhP^GMJ謹b&?R&m@A?Ă;;݊J.U[&ܗR>"4v9F"+䀢'"nqo/G4̣Ux,8o@ca&5 k k-kg6HU#g0bBU-fFn-BFIDf3*̒Ԟ$[5A5(9jU0爣QDu,WiT`tV`/{ϯݎ,C|q*apPo~,+iOY0G 5J>R `||+lS`FPj*<+h^NEh̓BMn)ԨbK1;z 5XP4C7ĖO#͍ gDCk7M XleWJ<ϗ[;(i ,uՕ)|Z)+β_1Wl 8C6x/L޵w`t)*+lS\!x 'C|FheVj p:!R3Qx0f2X ^e LgfT{ฟuVȰM%wb~W BC>Ϥ du6ah}HAv,/ 4 'GI<ˑf %8'OI%5qaE-x f`GS{;C;0^2zdCCjHU:LR"旫Ca z&Ѝv7c?hg{jN'dIsغ9./Bm9 _CbT]Nr/*7K=y|/_o[ukO[ՓЅrv LmЭ=хK"4'MK^3S!3;UYtYq|Sh^xq]u&sp\{JG7%H!>zfN0 ]yub X47)@6yxP}"j ͪZTc0B=*fG^fz sgrG8B]7[~P}7*cTk k$ ٥~ޚ=oNH}S#H.>/_ODW#m >H.C9]pUD%hHVVwĢ.ք.gKͶJ|FU&X>{LYzx\hxzJ[]N$ 6-ʠuͼ ]o/2)ig< Ysյ%Btx싅TWJ~L+EBYd =*p, +Bt8L-q&wL BO"b{eѯW VoA|gY~, 5L?c=m9XTmx>!MGދ`mKY.$ҳB]"!Zao}i>CIOb[pvJCܒx_c`_I^2p nzOW솪'DjOPt8g\rWܺc{jQ Q [v q6:^=(>JRKdy)Eά{ w8+cԁz旨*Z7 j^[ȓbމ!qJtJ99-cq6pր̯ ɎvJ"!uXOy{3]nԧ6Pa@#?QI4sb=>v14R" ذ}~&o [Ct#7txhVQhf](8e{ 7|A=£dR!t /?m.î$TQǏ)Q,wo~N v[k`]QD>w,1(a\?o6$WG2)H(ڶ!cN|l/<[AuiFz"%o ~\NQ_Ô#=yD|[%tϰbKA֬T~H-'z,x-E]j%}0tgTrfEf"c,sz `'&nhCdë|+7BUȒ\qd;m{""3BY_+yS4%O̚ݽ(1PsW7Ƿ}f4 A|َ 5=,#TaGCn 7. \AlD=cPXxĢ񓜣;^^}@Hb U1pZ{JBMDB O1uX7ݛдKc2g<|P p.Y0i7 ;eԑ:ӘK*`ڍ?/jtffiۈ6#{x6Ip .voX < Y.dj"+TkMy$V:DL?K|jy;`:JF'i,^Ghm)a? r[dwEwf-̄6&WO:@)"J9[xGZJL 9ȁ7ut'ӍCfbG`63ES=ל: *Ҭi29 tq"HlӰs0h W̶_AQ3䆰6u9#$\h?,9cxbT&2 (tTw^ (FjDMtu!tuvsgn8K\ȢoSshOg@7(zSRh ;[xf9zciY7O'$Woϵ'A<7 emd(J{SxG]0.+藍II6=TᙘpC~f̥Xvw]2 7uWJBאg'ҁ4s61 P 禍$Z0eU>cO]-Z)C rk@,_gFq 4A׷= ^ b,jh6DXSON/l=D6_x"Mh#zbHF@PxZydh@4D)kZUI^<vYk*q{'qgՃ/xuz=l cZPx]˨|Ds*rR:dtj0ګd=JgsM~k0oPg2+CK6ıkZ%X,ujQ^#9-87 %Iv~kb_!nU嘅vyȪB42}*mv\=k-+2b5 EZcy[`Y\h| PZs1 ©ƕK% C˞;{!/EvhzepKZjlYP[e<};Jm稔 N20 &>zZ-rkmsw.g#A3^o,5MUvNdL↰g: 6E64xpzք&^mz['PZ}ڞh,As|lLfߞdr0 48*DB_B~F%毈x 3o%tCQ:=P6/uUNUYfQ8I xޝX"VcLVo[dѲhc:WAFejgEޱ'lO| SbY!}KMgw#Ϡjijb xYr(0y^Mr@Ю ziݮ{h"&?l:LU c\ñ)离WªZ˴?/ljh2)͂jSb;$v1h+'` 𧻓Br}#CagƽWCqGorp eԌ;] qh53Xԣ^-!+ ٪VV{պܲHlNڟS`"0kQk 4 ;W-<jUzk,0Pu70káY@Q\}f DB+ۿIS1sOWtn/IxV5#(7~r@#jRxA29znH{doĘZU#m_-Y<`87G$kD1'{6cmReg+k."T2.&\ ~O^1\#LWXuK Q[, b!mGrVy-.Lz&2_40 mr<ՠq|/H֧dz8jӞwtRt8]QT,y*!~tjTТ}ky\"7̗͟Q24)iP =NAQE-3Z.UsP GEPd`x`N߫Ǝv9ܴ^1ՐR3<%,a_#&5{U¾ AFҵÿUb7)quTy T". ų=ZG ~@<p INPC>?L㉏4xx4yy2 /4 @SxC$$W`ȁ#0,]5IN()s#8~8N jHXA.r}6#Imǘ>iz衮-1+ZD<*a!{B¼t2c Khf#ټ?ϡH߮&N[S<k,GņXlfYIoV'+ UcBwŜS{)C!+_%{vf+΍'PJebcjFua҅8D Tj., M)^fT t XŴEcƑFE 7QK QD+^LJb5f1)MV cʣSu҂)1i p/glQjNE;nty2~nUT$&F<<E^?fu1q>Qb I"F&,Ep[+<(4sͶ"@VS)_'GS VۈV[;RzN#$k`\Lı-HsVl_YfJnF3&`  93-YbX+ <.켷~mG&,cvJ$BE}qݴK+@ `$nJ!Ve|2}H |왋p?Cua,gƭHgOJ+Ƿ(u&k7^ 6`sB]x"sd$:{,/Wp1D\Cu'Nj!^xUh3A²4>#<>UnBj()2aj2ڊC&et%lO ?H";CveY2 VNPnz3'|XJALj1h'mn̹+10ϙ,!eSM:'_1qӐAsl'=V{uʛKbLv,ĭ݆> *%s?=*lhfڤ{E#pMyl6 Bu6&6ͱ'ʪ2]#"K=cA6^wϱXIK'U/ic.gqJl*G76(y]Y a诹H3t#}+;m(Sf.?`d/ ϡLedF_BvݠrwAc Y%rگPe%lt(ՂC+Oy[p5Zd=/CcgfjQI%o:}ìQQmJM$åkh.|*ꍩC؇;#/̂3DF@>L='%/h0d阀~| tXOWҊ-y1k+r>>-'Xa?@bu`j5Zڟ̵TxꞭ~ʹy_^_ mN&Sai⅛DsdJ@6B5sdd k) 7schGp .eA9;s 泠ά|pLncK)^<$Q֏gu[  'kIIh]Knս}RUc>0ʹeHggOVfsO,b95k݂ANE," ѽKV!|,nzyt{ n¶l(PFtǷ`'qԬREp#A"8g i" DmoNe4ّ7f*bwttpQ- 髯iЈݞhgW\1ji-jQ7;81piK0- a}MVM첶?29j$ZOu.p\snC{$k1)JD1 `JfPE'(@ ~82{CCXo\pМDw?>e>L7}{-J/1h= Γp 1 ޠR*oȐ1ak#vQp0OwYsA/8Dۺg-% zJ|Z{0&Ճ#>Whjӱ_>z`S :|!HVmIJYC6[s?myzA*/~1'q$9eFaK'MrB%l8bn&ن#*@mNH­/)ۈWҹN4ݞQEn\a9]:= :z\VuAҩd =68L}}#B,Ȧ&\;4y»myMMPG88!\j [7^+;ԃ-A.7gMY B0"[Z Rs+1I)Y2yHl"mM_% C!<ʎ[p+Q0  v:o2i:q<ʷ߳r*Bb2dAM+?i7[ br܂ IUrK>Ȕz&>BnDhԶhڀL&X/Dž,"Ն&l^1S6^mkv/4 ūb֋K5>)a4hYAv<:414a ùL16H!\ #xcH~0\s~[Fy JϽ&Hh^m|4f=@K;W2)'X{cy\w(WP;lOVcF3Ax7<*ivzN.,fMAUfq]82 -3zn2@P 3l<TJ*9g^>uP ;jiP}2Y0A uq,l?(6}k%]~dZQEJ?krhpKu?~nl0E^ _h!5D-T&[`tG UVwa=zCq60t؄ W03-3c&I^UA@&QJ(ԝ0{SbB]tߘ,ʁ\Q_'{;L'QTÂ\zKJj9,c`vNH@s¦#?A uIi:)͇LG@4rŁ ˪63?peL:XdꛄU]*操u<^UƝ~uaDk@SzGK~7|3R `6|g61@ZJ \"O 'T@NXE(!p7rHҲ]97tXdo>栮4&F[k~'$YMnfD iRb+ٿ0G rMmŢT!K{Lq 9r;] @n "z~*' -_ڨGw&g䉭aoVK 7] `7}<{*9ZTRJH5hVI|M%%a"= fF)?!1dmwPsG+2Z 9M[aa](ֻ1yṾ:ZHQ-A;-9*>18eq(Wp\l vPLs XOdF& RH3r͵U*(zt6{0kˡMT_!w8x(3.:w`O'ۙ ks`ϦPc~m0Ds YD>dI_ֆ KYBLq7?xNo, ]|+V{/ 6tMn#r GL;U\t(vpMyqIHW` Q8}f^ b;I-_*;g~\'᾽iptu(mkV`A\C/|P!IY VxtǓHӮ x03QsnTp P4),h±+mSoro=딅u^q0<>+)YW^< *z֜ -QrNdv cu*g E]NuR5bB"R{Iɡ>66^1H(æd7ǘ# ĸ0KYm*1i,JK(J%P>#TGۋGgDM!wg &pLb BgLwnݶ$D6<3y9_#SW Wel0KEq~[ijO!VydWL?uLؾ|9OƟ]a{q?b=h߯ku\;5;9}*ӻ:5t!k9eu:TPgkb-w*V[/tے¹af#˦ w-sqzw/OȭXC%uħ/"sҫY%'*doSDfP]/^%)qE9{FKߣQn%9 ~)R;Ao6z<Yupa1vvP~&yb.=c}:tWqf"e ax;A_~e+2,映tG#߫k5*}c];?睚LQAn\6Z%t;N5[F"ΐǏ s⃆z՛zo'%t<},n Iٓ3&v]Kkz{9AKvhD" oR5B nD#nR$YL<'Ft01XFo;RQ‰ 6`=:8ãc:r6:c̦{@IOk4/_,DfJ?dQE$6>*CT..lmEkg뮿^jF` ثrbjvT63H!<4ĤuZ^sRxI"by e#-ñv.fH= *\ sA3.$lB#1sq6M -5W>Hb{'Uf8 LMHPkArpd.@gI"z.(ufLyC0Cΐ1etmґzp~ve\O~(f&nY',cW?PjpZ(V,-Miů|4um(>R@[vVA N~-0Aʱt@g@RM$3ƬZU#nΥpT"4?Lx ֝ sm̡4~//_kfI|YiQSg@UvYs5q% lhϕVX1ԛkGmZK#䊉7(j8ǽA~{&(( X9T*g^Mady¨Cyy5 3pWTq_cL&Sq}g\4<8cPJ C:I{" 1^H<.GA=9Y@'Sz-ߐH+Wۍg- ƒI 'B"bU<ՎUtpNzyn Jy=_U$ -`\jׅ+~c[ߏ[4*+B'&AX-+/:/αÁ!b7jYS ̤?tS*.qټ!*Pν3sݟj ]z.͵"Ocs|?bBr%d[JrSj.q>w< |!?Gj2dMX{o)aH"xGE}1`pw4j #>DE5ޏlQ~3JdOB>^@ ;FLwb-SB7gdD`BQǬ6y{meΓXE0dk6Dފ֩W'g>GT-W ΰ.XI I@=0BFz/*1O!E2fyQPD컳d6$ {|m~ɭ.fmΉٖ:xƌ@s⺷;|cG 9U 4]Qä $޷Hj{s ~|':~Ap~E`n"TP>,5ae[bPqP.1oO4ӸȪlQMN]N<_G%_ϯ TJmR 7&:g|_u+WGԣ;Oxze[l)Ӥ6xG"KphO<:grQl,UMyHܩaxd A<&65~()~>,)J354PEf/|p.I #C |p >lR9..鐱JgoȂmFpk駐GxǨ >3BhWt_{*U2ECW nsVG1) ęiՂ,[ECz''UTwE]J/ȒN{(VV'hW{XT>JAV%4m:\N)0l`7glƼDJ22؟lNͤH(:$kZ?o ^32 *k08-^Mu5r'-*{օg6 R8f]:?ٮ5"kP&9*wm j߁@$sAY=m-Y8t?GOe\jQ7er+VkhOT,iGnkat6RMAQ(8&a\]Bz@~~QO3cu$ |fBypc 9*Lt"p|sw\ .iRʼ&(Gj1#k Ypt;K{c^dPHza2,5FjŚg2skb%Ƌ(WN|Fk*#31X` O>ң5LzI;XoIY=l߸nF%RQ"m^Oh"!sno\KYOzg> ҵ?jJ= 3Njb"Yxq68X8&mPM(aT_,ZOKjg,>Ⱥ5zb)385&غzs>7L&hѕi<r XMQVMy̬"بLpo-F9d="=&2j8 fgd~qr{'uq.\8Ү @!W$`ʏ;DJX=]{/}$M2'^E_M=уّߙXޭz%Zԥ¸27Ի2ʠQUް 4"YQݴLti:Y"::ZY[@!xZdeN tfM*(ͩ5LjdHbF %ij}x!:1Va5eGGH0CoT[YRhx-*1g='M|3䵌_<Ҿ:uq~zi+\wBсkwD >s3_uU&ՅI.m@嘳 )f>.{<@z\+:!@e\ ^W+y[_e `7 m}b'9^%m{U"sǐ1H#~/i726cJ3?ߔPE2[nD1R{/*@ ǒAZp`s?ji$Y!O-@$Akt5f8 b~< \R 0?> {Z~pϭ jfLaQʽ*x"!&,[z`v _ ?Ai]ɹRSCNbvHD?}Y 愅YfS~Y.t;Ž#$X<'!~|y~H`IDO)hrb[kI+i7EvX*1J uCq~G nH`}Bћܷ&qf%}^G<^xc3s+PZ^,W }vۭ1a'-lgY(TJ:מOq\dnr I*do`Lv.d )Q0PVHn.(yϋU쑕(]qz`b'O DՊ+NnfV\`7ْ7m~Uv$L%H(S^{mIKmj@NIlv/VO Ҭƍ4t1hW43;*9=ՊPm:lvYH2X˃s\,tL%;fk)UIk  ޑYeD]鳮d+)>fw[qVgNx>5c*ӻKƦjz͋PakkBG P.:+,CI#iCiuS[t{'sʄbQ FJMP@D ȹ}7v_ϜYLSũv& ]aڋ`_lu-JE(* :1T;ri}LC>[Y#-L>!U?+* JG+i}mXj* SśM9K@ H8 \=^T(N{]ՀJنy9r ʛK[l#2DQ)9<ⵓ2xRҾ(yZ2irpm5 E" oKO=eA+~KA*vGOIv!;Kzb߹Rgo Il0yEMAx8@↛jh /sYVk-U}}եGcA9Ęqc5a/1]0LrDED4Mt𔙦L?NӓkCw Ԝa^}8mՎh=8?`Mu f/̔Ug;=0`x<9Q@?(~uٶ3^f87\. i%pQd+mLhU:W^!Y7 g!pd綡l@tO#,m>5Z*\ރ%1")R ČSxp6sӇު_;;DKg+rD¦mܿ+UVSzlqjT#'.!:*КPrX&`|'M]3\# u`>c1Ky:Q7j!*Ax>~6_*pm40|o_)e_vg5M( '6QXxA)@@p`#dKFt5~a*~W/-vnN,d9a_<\WiNRk 0lot^Lnu0E3'?m5PnHg4+R;-ށW1,vpB ɖy ˥vWgz u(5C@~F4ͼ_/M6w,4EZ`m ZՈ21Q)JJȾj6{ǻ[v[J]虝-(h:Y@ϕ7h;#8XR} $q!r4Q>X ]_u[qٛ|~ >>o抄>< v@c<^"!we4 V`}TjUOrq3EjQMyUBojD%f|B#33ʎs"!_m" ǿ%3 Bj>I0ɻ juW˜ZtjDs>sӟ:G,+;=bFsJ^udF‰췛Or2lNN[K> jXe׆YPx`= &{AaDa+̤}e^3Z2=Yi+zkHxSDkAQnڪFK̎|euoè`IْE&W.i,1csDO7GLlnJùt'qNK\nq"WB$+4 Xo}kn\DsK;4] ֕f_W9/Jg]\kgncOkZ1S&Ӿ`RzJ8INmW  +7 veqwt܄#jd4~\3 zZ{jv|Kw0 xXR0/yA"p%s^3O YWy.3C9aA+'}/pPz\wb퓯aZ'*xS<،@UemQ# XV"(0vBA901iI6_9[McHh?ftp "Ł\o=oFءZ$\$Cc ADldD673"ˣf qn[cڧq'HfikTzrCR-;{ggIKP6RB8&|󘫸t٭50SZR.}B wƐͯ'^FOuX'8ojϗU|AR&lh6gRhoq+=\Eݠ'{^y[}`}n"0aaPӞH@CF:=IN&PfBkeʌimH7l:7pf?2= VUz,Z13a]EʹhHoTCawA.4_3plf5Z)F;.2'Z^%Idڤ)d#ԑ_P a^&1RW ot} 삫+Gwݚ_©EZ0f7=c}%wgY)F V4J]eDY J4%V)1{ c>qjm'GOFÿ vF>D)XQbL'gUfA`0,k342R/siZJuEkӠB&&IySHeK8G-0OQK'%9WW`LR!U~ łZ s!%2މ?xSK*+_<: aWSxġe u=QS[<]2,#l詉%QQ }* M`b~(G,FԦ+`?CI@4 E.A)*/![_0N%Z#յ8 |t!J$1(Ie-%q'Pdʍ?ń4 s_^kI FЭTBZ4ܕ:%dyu$/F;~uFw` woWR2'&'j!'"9ҺrDp$\`h%-Qld' UN=M3 "ϜinֽU/^XWv?b2ITzQG*#pTq-Eb/E& rcL1G Jv2W%'2)]yV0 <FU~*W[?o5r3="{1&J,i_#%i }Z踳;CX{./#g u$1?sQMܪo`!" ^1Re$ k2) ]V98o$* [BI/KPգކ9฼$m9x1<{ bW`1Aج~](QKT7Q]_QbRZȿ-'=gKZEl0]UIkQƥ 7tHya,SExsf<]6츣"xwP[${HO~WڿvTe@?`R(3N}  uz71mLF^d\eǍ53=-uR6B/=~CQmQDh:uvuSo4SpXv%Om6\5/]} \@kU*j*աq@bsPW9+L.>!T<?+];[8TVŅ?*nT%eȔy6ϗ (wq]pľФKfp/:f~@qInz tu t߈J:zBkkTCO`*y+RH;'\dȹ.. dS-sYfH qQ,|srUTcy?mX%Wr&6-io7Ϩޣ).ήYTR:o'!wzyKS7 ]O9KN >M0Vӟw4@+'HxGhQv40 h ]}cr~L;Q֘AeVk*ޅC@ oMqc VѺ1Q"ݲKqgFq '^Yʳ5 jn6*QۙRKc^AN|s$>$CfUvdB}Vg׌Dw/#upeCYi ?jhھi".2U]!Jpz4h]~Dz=DqwpR;GFL-q 3Ḷݎŏ(iCygZ WA`x uA]YCS6uDRIU98Ϩ/q;خ|dU^A 1*V|m ,-^4nIKӍ*kPbL*J QC{eQ*Q^%{E<2\!=#:CB>G@ @ǖUɻb~Myo?4ǗGUXGD+IPeRh EX1HqQJqc?o %/(P{y\mkoF)8Hj"ОxS}T*h{$ɒA.?ҧӯvbgi~1B{ ٵSGV6KE9PᩱEj»9M;1fcZMtjRΈ/ɢ-<l ^峛~, Qh wUלOji(e0I)=imQgU5hur@ͫvNԊ_^9G|MIW糈߬jdu&:~4_AE[\$'n0o9"gbSF !{u*j:O:|D-O=E}/n ~2/*AwcXEPyMeyTkb&`8m|67Y\rPb0(5]?|׍daA$!)Mvc[%bŻZ'Xwqĩ.@l`j&[F./j@Qؾf6&>]EW$S3\JyIlBv$ H;j$EIN"\K_תdͣJr!%8gԛeV+Ur}-.[o }dG\`A3bnނ{{m~"hբ]ᣄ}4h wQiZF訁7_`X,h⟮ޫ+ϔEG_791JJ~x@qy6zɟp_H+ Y^fYax3_>:su(&xLz0Ir(J?it Wy\}mq K@qAs4@Y5\kL˲v&K UFd̂I@EEI4r͏ BcC}MhCq5ADG%^4_^ηW\LL"ILRԙR9\1ZbыHWU(d \o`E1xM~Mǃ75MC.Pì”GC,R?VIlqN'Lm989r2+lXhG$n |抹# ҙj<' ֟Y`7jRxHţqy/37P }e8b0DqjE{Xpp O +[gwɗ;xBǾ$?XvW8͏ik)%e#>-" RtXR"k4iX?2reUҡDSd8M!*=Zl]xtҥBY 6nёuît!л[nS\z7di#S* ?+Ym<\E-*MW5ߝcJE  5@#v%/mZ&"R!Isx%r"^*nf^$LB@Zo 8& p,Bd:"T?5[Z$0T U()3QFX_!NoDt&;0շu}6# 2mjLu6Ám1d4Ȳ$-j[ZnږA GJqCE8ʀݖ߉t ^ti$^t쵙6Q)Ovrh#^G&p[ ;Mn$6XqJ$%W#(Q*26*:9b9d +gJU:a6֩O{M%bTÖUz"3 jmpߪf.T%v$ '׉W־1k?beUN07J/-"%WYWtߓ 㺬A[sbH?6LtM=}S n)}JI/yFͬeuig'A7 E=KJ[|:lT1k:"7y&XFk+FRFacuZw,,RcDW෯j&YI=Qس#[ xkN]9̙|!q+/^r@iv|#-8T(=9[yr\>-.c KM+cCF Gg̲xpTPbV}I HHɛތ|''2xfgȭ0lv%-GzR#vÂm i~JF$5)~c臀Ro462S5QěE??u0.Z?`ZRb:8nI(7IQ9Ihn T#m9I,PPZ7Tl$ =v%Œ0-uDyPwm?v1ac+5C5L$RF^g@H-rixYΠ+~əA{}bX'41=(Pk4Υb\OH$p֐0AQ ̲ s rat(W/=n I G>I,~3BRg4 _[eTpiD`d'ULTJÞ3.M꧈:mJ4o3BOwHCh,ve2ҽ?сizlEn_} k;2{rqU.R8Hm]3g/2;@]+f$l㞧0r&zlhMMoƭ;hD+I8W>|  d͠Zp%.kta[N+w#x?չo;YP%q=K"="X/Vm58><\oGH7XhڢWQBcQ8#rx步0r9?#l49ۑ]ϧЍu+,&H/0#({zuJVL>\Wd-x#s b,`B6D 6ci+WvJɑS+0oAx;:ulhH_&_)Rs~W1޷0u*Jם|T =[>ehyi%X/}07n{Oj0˶.q930߁S@"D6$b3#+J?hhNVܡi7_#MI4)l;O[%)jt\c>$Fo/jcis Bp~si_]ųrFlkGKv4a|='RF=jYuMld6Fbno :IwF$$\dC%Nk8XwlkN`kԊPDLcDgߜh&7bd\o : ߨЗbs=a ¾FEx#z;ئ#CkD;@e':J\ȬՔL9]VVb+>v6G-f:nH#&(o,JyT{@v4-zlS-7_!w+ALfG_'S.'W),.{ s]xc v|ᩬ}+;ӌH? ^X?ladfπJתsXR:JqnKnPb{w[K3Q d/1aA_V_LF$ :۹Fun5xS%|*HJzXk}elf}&kY zAG9K6n!&KoZ Sj|&BƳ:~AS9g=Y۴q.IㆿOKK0K\d]v ~hbl\Akqur;y$ TrT,`xp3"Z2+G?oFX1y NOzMpHZq^B I3b:G}g, pgܯt{DŽDM,>~wXlngk!}D߳%̓xSKA`gy%1}f&v=#$Bܠ,ݑRħėkܺvk*O+=X\:$l/3 Cu&csATh_jod]C{LU-R2!28So|-`7'&R\+>)m9ѡ '/8P ЙSk42\ՑZys7'4OW(ۊL҉s =X;yaNi.]#*da!N~)vt7 HHibwzn ,a$36abPx;Ka<7j+/{@Zrdí6+5˪lS,;s ޡ`1G"DX)"H^ѩ57 DuJCNi=kfo. >0wPv=~ʰ#gM%qx |Z55`noo{Rw`Jsl)e;,v?(+&l!]啧[,hxcz,u()^b*Ά B…sهz뇿p}(mQ,3Vs(%'5tIr#/@Ϯ5F@#,OfS^vV(CH*NGdъT؟Ճpb=Hr3M AS@iЪn>b|r5CKp?`8"`&aE` xe}m CNCD}~>ۂd]K˥b rs^UCեulyxt4`p4f%ҠLEKP~(' >W2bŁf<9hSr_pQi=%p/>&Ec}{yA r%=e݃yd T/ߌ~WWfd\l-͆QnX@S$W!FӺ 1b+`ȓDȞ;& !s{*\ 9Msr]ZauT/'aƭ⻛@RRzCmbHF&>[ڗi:kCRyԸ='c_? ;'3+ɹI&(1+*?e,8 r/𽈄\s{$DtQ:;I7"fb[{Uc m&3{.ss ԐeJjGdNmYP(8uܣK+Yw {? Lŵ24bPoh;s>=l ';OfҔ+sAJ6v^- V2܋JwPvIJLښ>S}Iз1?|j-}P^\cb7 !W?rb>%K%5Zk'S*hj'! $b拓p ө?T}EA:Gפ]Hfel𱻛8ԣ+b3o;^撲Zzdt ]qREa0muZ#ZFQC-&-4B; (䐻oKOSt> 3aUOHԔ\-; e4]Nzh"6_k%ZZ[\ϺmD7IeĢVSV4IŨ\Zn)[ffbO$EIklȇHw&PY rqLYOշ\rY"J\S~!Am-2c2юCnxS8 u>GXAoJpLrLmq$Y)24龉e)f:)*¸5Vy;)cCVN'xS 6ϿӤ{8r @zLWѦ6̼kH8OcePL;}o i$l(e~zJ|Ħp4*,G;lgB 0Sڮ߁o.Nxwi?_20sμqviS*魛rPn²9)9o8'siO2v_Rj wY.ˉ\[賘a< p4 27_L8IUg-۲>Cm'_MxenOʦd\ʜ= "*(ݾNMa&X[,YƯGpZ :G`&rPrBv%Ǜ"\5u}*ҕRۇZ"~%Qn)ryF!{KEqS<2\r[[~3]IǟJ INpG Eml0iӣ-\f. ]DGǾ縡! PqkV}q;Ѽv#9M#6$bijQ,yX|n`N=jʒ屩3SU凵o޾/}Q@geXnM^/cnޕt/(sa}MR:x:AWҒ 31jEvbwL]9̋l}#i6HM_gO#2#Jd/Z:\aqrK81"@1p5qW;crGjf;]Ku|'Cq9^XT~eF<`5[ kHwQ֐\C&-*xEul륊,IR|Hd =}Ώ;L8X(1ț/Ae%_{sHeK9&>[{oɐljHѿwET ya7W32X\lWH%}T6k8#>ųRC)W?P(pGN%GJw!ѕ95A+їG 7? 5%3W]2!&\\*B:N,Ϯ'ZmCr{|`Nr:Z"bϮN0)oZ-Si9/_4roPԾs8T5`Di5hh~i\˒0]]9\JDS2J|ՅُK(cPw =v0ϬښݵwU+%yS}! +C1r\ A SoXp>@XHO(TDwm5׵.|Hd2b22Ƃo%CE׽*fI$f neӠ$=/嶲9ٵ8sĐED=qC:ZXT7w2.5A>R_QJAclfPRC.^^* J$4r0҆%i2T'<:˟pJR3 Pm+B4Do&X%Lطwz2VOlU0a7{慪`$xwq"M4~/ȑ4v`mBmB&i^8UM!S='ޅk9:+D񏹣@Rsy1:2اEqOxV渰ȊG9.T1iqR NFE r:s8 UjgeG΄ W9*X8;N_Úo Ȣ.ib;9}'0ْS/c<l|^'$kKyRZ<=쌌4uf h%gbfx!pԿSK^<[ xx,^q<ajB7 ]/ިb<_~Ye'itE"Js㬶;Sc|.anƗ$N mcoEem-ԐE 9T:=2k{?Jyz^ j$+i G'xTiE9[zF_1z᝽zD:P)Ww}8ܭ(c=쮱sH2ꚫm3"[۟0?ZZ`p};n$mf/ZK20&nբdČ+Ly)d PܜZ OCLd!kpN$fqpV#^b+F2ZA GVuGqM\<<#?<]q<[&Kq/hT׬ dp4xOxkKt4Q5ext4lt(ϼV9KU%pRSFM(C"F]aYLǏ^M!'\qۀbu\{Z,G L`*L|>j ;0 #6 8g-_$Qjpo.n})nFXq5VF~$<=\apcOѮIo/gteex@]RM@"`[62ԛ-@qf5JzG-މu53[^v | X69ؠUwnܫ(y4TVS:hs=9q瓳vFнR4~6NOַ`uf'+40fUڲE1w:'#qt3h6:1T2W`&mS&iwĎ^V,Žbig5p*rbɓ͋4>CI1)zio[c ݏMZTiZ x荃#ђDrYN'h5:N#6o#Ov]]mwGQHk D"f1AwR dtD4@~-z]S4pư4Z<nbTVGu'謊K< ¯d r\X;Ƒ=#Do`r!ӉE8N$m`r[Fĥ9GM?:҅aީǣ ׆Z_õr'w@L5j3J^ n!p(M~PӘ\y9G+؜.7/8xa31_M5n59O_aYczY~d U2|@HP=T <k{-'<?h(zC1hIS/uKe^ʗWCс-;<=hD;dDΒ-5}.ྐEoBU7:(K im$]as]حX4(DurTS;J*`z kďEIr˭ 9yت]5DC}vBuWXNYN~ 4l"sv`C=j'r_oIQ ͔@*HЯbǩ5;kk$rys`U~~{[5Gt팒8p<ιWDo7JȌK$k ڻe6 Zulh2I;@%jG̯#SJ+$GC5+w\XķZ5g60=4Wޱ;0ƚ헁w KG)>aICv+g[v ZnM m^x ooXH:MdŜ( 9,:"Tx ;Xdj|)?SkX8ÈU:9ׄ΍7)4L=75o޲BF=F/w+$zQTi6x $ YN->-(Z {$iSԣѣQxadr&jX-:S^i8u+v*g۸(tL2B99;^dž#%{<yCzv ZTJ# Za_?LirQڄ~&wJ2Ѹ43|aFC=hFvMG4;{hC0)JNu$19:# (<^G@)q %c֨_{!/#ZIR͎GHVXu0cl0O\g0Sܦr hdny; |?Jl޺QG]إpWhXV~WiɬƒҟIg<&r] sh(\Zy],Qr9W>Ў9ͼTܰۇD?X,OV&y](+F'?~)펷: ma^w bp灮>ib`鬫cfR&{Að BM @i6CN~x|s]` ^弣)Edf?`N]yKgpdKXKk䳗Oi58N,S ݻ$@4sys\IƳqX#X/NF8  =_*9&[ZWT-PY4Dx|#XL>)=O Nt z9ҥ&:8Ag5RUWGOcq݈P"ڰ&(l:jz?ͤ[~{ڏ]#C5rFo =ye)̐j`톔2,YvhZ{C¹"gs#`= oyqt%{WiֽY+= ~.,>Ԧޘ x`HGC%s[bMɁ+r!B^į- Wmֶf%Vlpv l_`}l+3HGkmؿFw"]3Pjل0M@ U֋1p۹ղȆHN#U ?fxT0ZLî ̹|`T ..{DРށQ(]9"zOB}ɸ,KCuMU&3(צ)UA}F3"#taA:̂ɼclf'Pq[e-yx2-¨d2n=Jq r rAvseAx^Uf wNGIx cwj&GaFp&=:п}f5)Te啉ֱoy r$*_COZmxȡE˜J~u"g{ε&>ʍo?i!|+".eWa.?R#Xrd?ͨbom52oiǠ`a"v=^~?_l 9xF}\-Y]]nv B]h\`ޝ|p!NzS,F!]? oߦWBi,#cA[Gj>7J5O\Xqf(Z6 =,y4P1ЅV,Y2sK巜~WI{7prr8H*/Y62cGu.ixoօlz^b5L/3U9UTv%MZe"M7ȕXL\>޷|n3">=]/ w,dE] NtzЯJ:x`U#}Pto^U< 4qe1\)JGADKkCmt6BobgN.着_8՘GUiegk~pW1NzzXBĆ6ܜD<|%>:W SXE}۽"H#KC2ΔLMմAJZ++Uսd0ϒ}rԉ/G!+իP;ULЊ<;$0:i_ q9kgpE]è<ܣP- e<6'1 U i p }R6z7|&h`U=17@ $00<4 22uqӡ.CNDFC)d$.(C\+P> 4M"/2d|زC"ȑf9a^b1GlE52O;hO\qPA\UBA5ԓG_Af9Dۉ_*A[6x5mbXCxhr0>Sw%9Lxon,zulhoe} i`pQm נ *p |Ӛ6Gk I%t.C}s@7j;gSt̖DCˈT )2e(Ι[MivY=]Ō~SDi3預٦d6ȏA(39l l"[ Ii yo\ZBMG6c{եUNFXc Y/X%B$?^ljA 򽤬W˨ Y*!ȑ%5KX C_̛b )5dɏKR%y&KKBj@|!U]ҍ9|F2 q1k@2X"$,yO%a{з=uVkȁUX>5/[D:N>w99=[FAB\w+_qAЏ&ˈ$9L73T[6U!0 &{Q:x9:0)qI5 KYs!ך2Gڤ%;"$u&/musQE|-h)3^BQ喂QSC*VhiV+ _=?8O!"#Ϳ#`Mxn,c ֑cCfjf@#geIF ym-UqXQYMUgbreCz$H64(ʹW~vT7WEQĝafOj Xq+"=fw#Wjͣ`ZT!L% ِ!W\ozq 2{ iV -ryT$¿L0y9O>1IuGWY2΃w+Э4 \ PGWDR E~>t_Nc59zo%7Ǿ8h|9VKUῦ=[$َ`Qu^h日d@oE ]EC eUw(SWS> C ,5'``^rT7Dnv?hr/jgӑ7eA9 5 :n0BmݹմMГek  ]#m$r>tta_tg^4G&?ʵnTmk󼴠9P dmq5Dr/kéZ{yY^^ͮ&uiS2 &#| #Q>*k0W7&, 2qvDpV,D?Ѯj- 4  )iAٍ}?fb`q6ƸO*g:[cOa@ NNnPK_(<ؙ?)zM\B$*g$%xrjgu93$VܔU9Rzϐ2(|Pѿ2dg`DIԷ?%+)WHb/˚ Ll`4VƌkI$ -hv]J'»дi2MudNɖ9c=XeL:Ur> e#IR7mL|+w6dM1{?e$K=ƊT1R|p9iʣtCsrzńhX=, nѾ#WMT_d97m$:LZiIr2jr<7k|ǻ~),;PZj^%B8 8P9CL{"Q7=~G=ꧺ{1BO`,fē䋎BmqGEA{>M奊60O͜mS D$x< #w2yF;.Y$5-k wL" Nۤ={IFk:ǫN$r;;|Rz C YQI4蕈R'qdB%s.$\}HX5CKMcH80 &`vvɎ pbxM !5P̛ GTWt\ &!:e7i)5dTܲ0 Li"l~چ_y(T@5eŖuQN)mޱH˨rHihkiF/ܔ9e*#NY#ݡL'X T>:ʙp_U돹jt)R:SBUa-V9V&t<=Nk2圓 l'?a— J<=%֒%M(wΫ,]ώu {N MTDz,TWzFmm͂҆6J"^EmqM\a0eam2&*,I4NlLb~V #FL|R43KRc%#E_gAG<1vGhxHdVSQYޜ3sͦvJaB;c QbfIȜP8smǂ]u"_(&ð#ԊSBdpfGSêC|^b8AkoO|)nI>Ҙy# `1˻|/t ޸ػ&O=QT (2_C vmNtU.aгIJ~4'JCdnX˷| %}AEQ1LP@ Jj9[X{GN]&XW `VȷPO"I.MIxnpڤ+l 7Tmro^6),F-͡}LTHhKCJ^ݮhj{MNUKǝ!LL$s՘T'l3Hv NbWf]q=pOp*b03lԄ_yE/ )}{~C:#Xz*ZଐFKb G]Cd!htcjod:e<0`p EzUǂ,LXrg8ȓ> ӐD=zcm/D>CRmSD/pKNr*=گ[ c<&jN;yBl8 0d_L!;&u&_0ڤʤ2j 1uv.A"bDfւզ[#q O$puĂ ݾpz'ڡ e 4>͎ש4dP0Oi %D,<+4ݢ4Tm# F [SꚌu2Sj`v|E{oYNPf4m9 LU#+I$ʎfw&1ӄk;H\[1{=.1$HVR63' rF)g-XOlU.C1R!=q罣ZfJ}EJw4iXtdosV\VE&h|M`Mp-.`A0nPPt ;6ˁr+S[;_,KN qi9*A8  rm4iRWfC×PyqM)vlXz3{LdL ]Xd/ DIr시Xt%SM{Y!\&GSqhܺ۩gٝ 0 a%qb6|9ISV&+ViPe1T\8H ߆Ci#g =nZF]״$  ;<5:*n`hX#xٹI~fȮ 쐄U1/ߝv*s?iDRE8/_ٱn YԆ?ꞪoJowakfBRMɁmN?x<5 u݆HϜ?h15S-*|jU} 503^-ۃX( $~UQ {V3&7'tLs9]t,aZ`YhNp:ﱖ""916zV{ǗZwMyOT!;-y|y_0$!JBWaM))}$a9x?>xmA9TjI=x5 ?DZ_ o>nrړF\D_}47ήj?DHnɩ*bK65+UvF]@b#yO N7J66_}X^7aVTHwO)j IrU+ ]F5Qk<9FX8HOYICl=49zh07268ϚE`3'AXpt-ٸ /% #ꂸE*:|5W97y|d\:L2ɉM2OU:-iSї) pl6(b4so-$UwmV#j)RƽpIl`.^R$/Ζ?=QHxWg͖=p rw*%O:чQ芵#Țq}(~>=Зg)3>LH/kw|W[?ʮXG}t f<8?ճa))dzaּ5]2p EXkdW A`OVWDe;vqXj$ Bc e݄~YzfX~IWMiP=h6/)VDTheQoQ"7M̶a7%x607!dk)Jf w56+g#G^,kˣMY瑅zXӫѕD&iTJc ΁O_!aW!Lwd+ "I~ ѥ4ZviD2ygpݙ"6AaSIn8+5Ÿ-(DaכLoU1!# PyE>Ϻsh6ǁ?; ks$-IG+o-nAl=}`}=8+|Y#ar[VV>hHL6H٤' +c_11+&BNm]V\{XjmJ*X="5QzrB]-*Z('\(v 湬vd?5oG>Cgk@@) e)y[(:#X y0*D(x i2,w0f ح>7T[݇vR+(C~}W8E,9h˨>I?%ҍѽRoQdn&Bа[L]‡Qs_Yaj 0{MA֏Q&9S^^Đ#MEpP{:c`_@ꦼ|#দV.Fqf?,mkl"#v\;a?R$Z]=¾苊YrĄc7ҹJu~R%Nm\x|#ڌWC]}~&Ag ~k/Z`q:@XF,LdRM^sVd~3<SD9"ftI녅>9PIRx]h;2e],U8L~40ʹwǍgGP4*d2w =~8"܉l905YCd ;U?|tR&2;a4#nIqi ͈/)B+{0nqPlH&7Azĭ:Ň"π1+; @ւIDPPC%l%;,;G7 vG_*?3-^L{8\[Lkw(ahA(;d0,)~Ǜ,EX[͛T~qdT3^cegK؊frV3ȇ~{A}I@,>iJDNc:Ć`Nr_ɍf0_6jb^RVsMw}f"gxw:ŴpldOΔѪ >ysVY%̈́WoY>0@ۖ9$F&_?(g9pT*zJn]^1ʘ俰ДxjJ1gYӾwBDYߑFO1J})2+h<pz b_'( OtOF u"*: b}é6o[p 3D fl5>}n0յ* ߬S^wƍX&w~߾0VRi.ORDeޘ@a4οGny_$FIJv̩D!,jNRD-ˇS@!rSoǜۡ=ZL1.R;4:a= m5vi~O Ap*3;A073P4I G{"Ճ?>%[kbU2_GҪƲ]00j5#?J}'L@ՅssҰ C&/AU$':d6e\Ն&QesZ` gݩOIӯzTU!d9}cH}G?"`6ܪ$I <><:RqNR*8"4[}1Oz6UGWgFEL :eF)p O82uG酝MA8u#ƗLӏxJ.,8ҥo?N!$®N00ڪE!aϔ, J<h"ITTaǺCzXbÍNlΕ1~E4Ԙwn{;0}mo}&-Bԇ6R-&EN(gD#4tQϋ2ߝ7)IeֶPj|Ua"lkf{'G gVX\(1R̓kAh0Htqe7`l2ƾ-RG?bp[s[-*N gz> L]pD,#I, 0T+`r;fZ֐"JFZrhs)m-oor/ea/?q.]Qt.zkNU"wvE!By 801Nﭟ<ٓڄX)j89c.JItQV|8{̳bn#_؅mu=H<_ Cm$'gyu\@K30菙OF^50hu j[gî~o.k\ehb,yl.6D)SuXHb&./\GL醦,DBO,fw"O,wkLRSӉ3:^z3#xaI}Ջz-^è6lmOݵ`SD[huȁACu#Es&,n jy[S0;OV\xTdi+nvQC5 .I]+G{)|O- ut#lA"`]|! rRNӭm#l_W!8wG&trL{F0kikYHŞߣdsUA-cKl>&:)B~RA/:Oe MCd5bY ёh܉}#7jB_ޖD!9\ 8Q.^:&[9-F8HVxdH5$rbhdZ0$]iªIx!#E}8ӆrO\E%JhN;]{Ajc;r}jwVwÈ䤽F@aNddM1GAO`5v ;zYi٘6Dz5!N++P-դpipǖZqȻrPͲO;GNX,OZ¯T]^G3F7 %˹H7m=ڱѝuC w90=Y+띄 :OYW2tsN<ή9\P\D!4͂T`XhëtL߆GgdX_e V?7$(`ysc7j?R1P" RX7?5_h 5w:?^- ' [K-@(#BdXK~I)VjvG4S;諿~gAH|E`<5'tvDxg۲<6U&L 4L&3bxIzYLo>/cyb~ :*Or&T2{?9ߡ MR0ϷK_ s:b+g ^&Zzu63u18tXFD%DE/jL`brr˵6-9pdZ+R<3 !+:2ОkÌC}DFm2OG5a41zl$%:gu Тh%M?gz*@%4jut#DVf]9x9t|;D?;S:Y˔z*iDvi:3=,?ssy#))|o aؼj>pN  B"F*n$@L$1xjTnQ{/O~q@f?2 Ldpyզ.F|hS ebe\x 5"SM0!j# @޻=Jp\@;䶸*5~M`kWsM\ŚoZjb6|Á#a>H~ř$_%*xdXƱO Ye%)&Ǚbgs̑v@aGI!\:Kf/Cɷۙ.0 c"=4=DA;CLٷ+my@ ~+]n"F:`gkI % iMKtXخC؛EPSYE5:$WvA D6nj {d$<:+ SFrlHv\rm$˪i\GO,0h@1omJ>ܻV͏VZ`8adTK$lOlPSf{|qnK`B;Y:f)>M" 32ւD3F9vt0%)&Uڝp$P_kF/Lf~[_̆:]y%c96~?nry{֤F1j?CGεG@O{[-vJ^T jɥxy2 ]%VzQH˜5~CGF;A*[G 2?GpM,&xd'>'GMGρjj2q {f>8VU8nk,`Pb bLJ 7MZ?qކ'+ΚcF=JlZ*8اodZjP ByoKyĠ ՟UJuv(^'_:!^{C:h}ҭ]<dU*q7nf!C)%-kР}wEF{-3i)k M1nE9+Y"G2?[6:<ކnY [9jm6r-&_h`׆\XsND/yj҆K4muz뤲x[,F(]izӻ_C_AֻA6E"x\viR~Q} ޴F.#3a7%B-ت D|h M>dVjqji}A#7sv/@:3ާYE }#7A%M2emT?vZd=Yr'#ݟ'f{@(Ƙ8 gi"rl=j\PhHޞ1'2NjmLZ uټK]NR7V?ѭvjva`M6e_qZhz6'"_E,1Cʾ>feGӤNR7|ܥr (t-nY(ai՛ @ DUgxytՈEP`*r]JX9[$kPR,\$rD*͏^ )zŴ",|9UVgL{|=4(펿$VLh\β:چ+rK`_5gl66Ab7;)ϡp<_>2gTj/rB,*4{oAe`gUf*o$I/%E $?M H83NU5$(3KaQX,nռj( [q[FAZ6u[4!J=)qEO5ĸE?+{=xŧcqWjQcF~-zw'O,F,7Җ$p9LGbnoOT!@ Ѣ\iȋ/[dŒ: =/ hXp4lweYaTxGNƦ ϗ;SPW)nᜨzFग,>3t5l1Psߜ7+º~,_9I2b;4ld6)n-ax $R.@bOk#,z4rn[yҾQ,g`+$3t4b\u ]aUw-co-~I׍Oʔ=G+[ADt}p"j0B,M.(Λ5鼓Sx2H9#j6${q\kl!"^#;2 +kW.u{/Gv@ô?_,"xƳsyrKz 0Q eSRB폚KȰdpK`)f=‚[ڙC(=<t&ց8(O\)Du#oEVkP!f|Yl/C O`ʛ')p 6Gi~lzU4+MfSSGfhȶF[p제rv M^Xl\)oF>ͱs7-fˢP\a#jaqii'mf?ҭv4\0sdğY^;|m|[01y=~?ĢI ͨ8{# H.)}񖕄5n)x $f+׃tvdw+.a:qFԃcQ7RN*f72{<Tie ssnxPG2-MzecB>׌qwKvBB&"GcrVU^ZjR:WWym,UƸ?CsU?K8:tA{s~q}8'L0ߋ]gu07)PZaD=I D<3W'#Ziv2Z Lm1SXoU0;lv b^7ehL ~r'ў(b:)N /DN}k18.{dZ4-#m ֻ-`Ӎ>lfO qqfj`|'t,Htfgkvai{ikA;IhN{I/qk uݸQo ~{Ek J a&% jiڀx6 s)X4YCؠ~+g1ն%nTQL)K [0"Mk7w>Onz3]_wfŗdFb7$d`^MZT!Ax/a8VVFX^ i=wh &mvHA`'9귛^ު<(6uBxFlBgʺb=x/j׌_Lmwu5QЃsS 4:~e_m;6> \gh4WE6k zA{BY+Rn~1ĂHe69 ݁;1F:%Mpp7Z5606Жa$oFL|ofƿ&۷2%ʵ'űٿ f^݇VjE ҍ&E@8} {[%FH43@ׯMQWeLړ3r_)ߴg)@5XHekAy)w­B)YR#¥BZ*9 u>hhg3%\<]4h`oyڝLV68 `"+tWt4Fը69S/ž0b!WΏpköjBx{c^4Ƚ7taZnp!E&!׸4 "M)W0ϺV4")N}R=P:ha+Nyqg4&(\=^fWwL;L̀sVBf~BK\_gBpr{V~Ts"hYc)8`sEgJ05Eד׶p#G͗d4LZDۇc2%[LH2-aĉ%ml$^HW )'eǡkIyYfóRתPt;ᯒ&-lL?'. vcaDpQy,yӛFF:]&ULOti]~O6^g aa6UP M^˃{[mPa&hBŒG$!Ţ,ngu4qp۪π[Ac6N<33KX9#ґW}RP퍗w'-hK&psT׶≲t D KV1kUaY/)]ȈS9*4~ڊ#hl5T 9'"_Np#8Ie)dXtKAf-[aQ,W6CX7|4;r{2~ !4+Pt3Igr_ GOBRV|wNK`9s2> /hCqT DYeFʳ6:nYIn-4cp'Q> VeBi4ب%j[~T6y)JCQN*yEJ'%ܘUDgjrDF5Vƽ+=q++T7Ϯ!v۰5;Qv#~Q= `PAqxƇFˏpmbfhKRA( 1R<و7E0s| cTgܩ&4U$kS%_5OFDm҇?L/ ģ G7dj@ Ku>@kȬ ;١,%*e$KWyٺ l75:3QL:/A.5oa) zZ6 QҫKTaۻPEDԤ~n3D$E!ߍ8$k>OY.)'DhUηo1\V{6f J];(SM`d0-[{k3y3/ _S >]{f6-w~p s(l"͑Z r ԉ8h@Fq~ 0"tף;%˾٤F #9DUES֩~ *ƽh$= \qF+Γ|oZ(; b%drN/m|_I;/ÿQDU糹`d yWc[GwnXЧ2OzR1Nec4Jc&<aXAu _=qDX_',J a:!+f ӏ^IBs{1KER&ۍd[rLoZL˂zλm[xSwpQ\5?꾃iQ73s/%OjF~$1žRVXdpKcZ1|LoD ɘ.DzҲ7vxe8~8r43خFڦZ }U*=,;aezE-t"[ G6vu+u շ'=EMw|vy;ΣYؓXB_qOT\ʹo9&n|3(WZ%ؖ\V@"j璐W/0̄@fr[=-53 bpwRńe;H=č Yu GԵ6Ƽl @1 :mpUOv>A*,1Of~%L CS tL%QΡݐG9m|BnZ iL}5F9ԇpYdNY >o pIu,XQ,a~}et\}IqK?Cvm$䮴sA?d&Ԫ #D \m!'I%tLT`yM&lX Z d5ǎPr'MDZίAX`1%V󦽂FD]#wL`p:Ī=!*~]nL$عY>ŝC$#( 71[0wyocֈnOEM1k?]@*+QU#c=t9N*uXM^YqD)WLJ }pT{G#^U'[e19@Pؑ?H& Q p_AֳB\9m_JT˳iu),=Ӡ" ,q2d`WlQΞSv f0Ͻ-,SߖF^f 11<뷻tPšn趘}4ݐej9WZ.ouO~#X` )<|,A+$@UCl1SvuDF@Ba~7|wns@{eZ^6ۖ<=:ĽO)^\0ϖ\f&B<}3 ~^W|-u=^5A{@&*)**Xs^QhXlG_BQ(10U5X(\53 B{X+DT?Aw*ߔI$|q6:tJs) @t+QckwJ'{Ru[ _s“TF.E[Ԭ5* Ih 'U*^Ml\bOv$NL.ᜒ89puϐEM=QC*Q>y<:eNm,H`}ͳ{V ͩ}H{&~UI큒:d)UE4nGVpr7R@EQ6\ ) _12/^ OI>|; m ip6aMo+>Գ~f'O]5#=&xC@NWn t2 7b1(w][Bh-^ea_ l\;lEx1..a5M’(d4&G￈$ eow3$CSH}[N3fYc$MQa[SQ+һFx1U)1җhv:$09k WP;FeӦ7w呗i<ޅ?AcsNl.*pjkus88Uh/eD%0`H'G+JMʑkjXV.DZRsG4)Lvțۤ}O iąQX.M!CX@{=}"c=|^ZLEN_e)|w!8]~RLeQ'(kl*-dǦ!,}WR[ke.VuJNZ?%n gK52-S5j,)>wA Kܱ%~G+ 7E<~exV/BC_g$)/AZf6Ѐsb>}|5[4a4{H&vNQ){8}h'o@mLBſb-|-_L陥Sxw+[F8P5/v4#ESlH.XٳRL7`tXcQq~.6p$m?@١|&K(XcWs%dگ>RKr?9,xD49qÀ'DIX"w2e<̦h_.i=Wh@(a *y##BEnl DG H$^G6ϒ5klo\,#f^H*RM&ѿYfˠ nm[m5nʐ-o**U=/90[fɍ Ucu\]NlpM5Ú0B5̩=)MbS+8Jܔ؎ w|-/L &~[GFo p 8Q0xb=)kVh5."5ѓӛn=+..} oM%3.\=,s֠_6l'`wAMܗO&'~9 MYWW_u\>/HԈԴ);#!, =}5BWqcخJP#;Ldw~RKLw}Vج"R8 As蒍IZ(M,@'O\F`[l0эh|b3"܆uH,[9 jBQS^Krvt@!mذL2 T7%{rEGҌCs2ދRl1f'˸v_aّua+2+k hn.1jt!H9T*RkKej 1+]Tw} |PVD7}ZZG7Dj̔vc9kOwX p5jǵ*-;7$`Q * |2ey8 *B\2q ׅz> ;} ALg}hI{{㸨 IRvd,Φ G!zaWs#@ڕY}@\@}gou0jdQQX+MBρnf!N i0R&b`h!1}s`%:;ۿѕqgZE-ռ𰊷!!|6utsjh"_(8t 9vw.!aKcJGX"2kn\Q+g{6 :ro% Pz& {كaTDIN"3#So#[STDȭw5~GMh2q}`-uޖ: n>g3˺ N9ͅ >j^G?'i%MeAu z7]&n0sx80޹C5S虁zū?t~>>g ǘگަ\e::Cr>vz 6+ ;9p7`~V@fbn BO[nN<}6IbdzOHe=@)I6 ɇ CtB(ؾ'˄VKxk]:'G\1x:9_w4}#v Y#53Bg{sz09 }|=zF_t ~+/yel=ehdINQ*} DK) 5Og2i$^U]σ-ŷu) EV]iQfs!OA~kSI fDg-,q(o#+.mZioR2ɋ1*_գڠ1=$s:m.feʪm5k T mZ^cMA b|T*uCO_1io'ӘCR6y!`X5 ʾh J_?c74#LXmpK6 Vra /S!285]xpZéle󠫺8DGޝI&t b6L8kU귱T Z(JdtwBmG Sq&j{u>HZYy w]XEV*,jY I<]?%v =)*)pqO3@il:.0yY^ АPsiMG,5yW]pM\!<)uᬊ 2)ʹ+∩"Ѭ.,JNFMl 7VB^凞ً$XivwCv~~psAqَDЋhɱT귣dzk!7|Gn\剠DXu' cF5Oa}p}LtOl^ -w?v? i\-$P AAFs;5Aˣ&\ZVdnX e8V.8u˅'iHBw.ʀ3ns- 'ߢ#3iu3@U>cd3@ cջ~[C%C%u _v{oZ uIQ3W/G/z!x77s2F~`;u@;PmzlqK8l%k8Cت+;k hJoյe!;*^ԪW&ڹI;=KGlMXuW7)P#\`XٞB v}s,o+Ixvx ^r깋gwt ǽa|:Yu8KINiX‡dYz8,Z B2пWLLj f)$?4ؿ?5!p&Hl~4dٖl$P(hfEe1ew!(z80Z\L^MNJ1T e"gsMnHO#(|nen!Ad_IQQ`>22ՃPBVsFp:U44ȓo;}ȧӯp9}U9Rm9HzdA<Taq½:+4c#Ѻj b@dֵ\3ȾR͡ .;1ٻ*MJ1'\xIhu9p=A^ gyѣ]mRF!^N6HJE,I8:#֥9^iG;Ue~:1ɲXXM?ggM !\rh UCXx1cT].W^Ƣ"Y9^p؎A_ʫlE)!.K6ڐ~]tJ_HY`-Aj#1v!>hWn95*[q!YR B-[1ſCꫡ>8a άk1.&?sejWd T$O940WcƇ7( J 5jmU.MHy>-#4lGYkjd"<Jֲ07-+I˭Ċz[WU'n!ᏼ] ayfW#2- λuD؋A>F xo`b$1ջkJMc<:]"V7a"$;_o1+#/9} L k*( G:0';f&wj-k-xbAmD]4v5[r ߐ!lf=mKR # \޽pⶀc(*PCB1{b8jzX ט)t{0 -TMQH[,*v8O+7aIk^uQ>#_-Woc"^nf&97j+jW3! VdxܱcU-o&7X G*u^IyZ>Rp,Cc4蔗wYrٮwzۯOEO?CߩyhŀfL(W(}pb6(VMJ4O[.B̼}k=!6N4ұ84b&}10Y_G!i4`ؐ\aO8fxj `C֢Ö@dcTgbh$M՗ hGA'l1Y_ yׅMw/l]ňS9v<@R@=[%#"09Zs2c2.E!VHOD %(tǪU3F[#5N" g(Sҗ']<7xb?XSJ^G°%eeI8-rTF'lYOg}O5ѕq Zp淗>*$qB=$vuOk*/d(Y?Xc/(SwSʳ.5& !mf: 3!8y ~o;@b3^ >*v1&|w2)} U嶘+ ,!vG=;RTʀO^gH "r\\MOֆmٵn!28, VjNcj@ B>tFHd`,r<+s[:k"_x+Ŋ%Iu`b-=+"&~E17\͇hG/[l,U/.~@DΞDHXfw{XTx/" ! ð5(={I"0ŐOB_iH;_I͚zAJݾ,1ﬤ2վS48H Ym]90;kR>N< EWd;n1=RK9*~R-sVpK fY BC|6y, SJhA͢UX[wIos/|\_4meK'PjD"9u hЮ‹eٽtSH͠ga(N)J) 0KMiY"񺠾, #{&^[= < /c#t2v2'[/:] V#lŞ0!ei_ҶWl]X.^c͒dY.zZm@B&]}xRޓ8 RbE@ӿ5f B9X֢%,L>7Hu.P0~!<ӧ\OLط_Myy=*$鳦V~i:yf_HYn,g_EnWU$R" Һ&L[TXE6aEDsUƫ"b?LP-䇞\ùrz#K{͕SȐ ,CH[=Q%3 k$ЂL@:$;jm9Zy>MDS)vok̥asn/dypmdy+(m]jğv[T@a>C`-3s/w)<ujs:/EwQχ-j [`uSkUC\x𹩖bk7uL!kc! ;p_r>+a홶1[{;՛G`L~vH%߾ !ȴ S`1qX6}n=27]i@m,_PnHFK݄-lm!w8exy)$ `^6~!k Sgv»D7<'}dnT̐)sQ]-1ad*rL}|BBejw+B4Y[M F!T:UWGu~P$c5qi0hY Md긏ޞ3|I): }}`.d8'Ӧ C69cA?[sy;YC ~͘-FKa:} cDPݤޤ,g14j%l^o3؍ ` PtiR27 k܌GP݀RF |tlw)祜Y(Ih0+\LR8.%RyADb}3bӃgG_ ]k|6E'~2RV8-9O?"ޠ}<OsbtR)dj !'a%>ʭ hMКoΎ9}.`7#g0z*?!I %O[o/VJs_-5l6P}C/l[YM)4 .8ô !kIT_Z0z1n95ĸ)˯μ& G,Go]_QVA{nay4=_M#r6]ޅ:dA6L x9O~tY~G(юMn^TrcҊJj@/[Gr&ף{Z0Ju8sn_i s¹RlCJ[ d>[j %oϋ̅֬f1I=b"!W&]w)Y hdۑRH{o%WBDkF}y| +aND<`a%R}71[ n8AKSO&FJ/Ҹo{gFv5Huɀ \R\9M+C{zQ&. [՚hSuk.P>X&2v*NY<ҥqQW3)WWfkuͼGK E/8\VQ2uU<2j7&_;4 /&"%'ם <ԕ\}Vl֮~4>@q7oղ8A%r)f1*)gUt,N 9_~؜*)cYt(섗v}3:[.{G3ʴwzTnjAU{ӡ/[܄0 `K0dCO{n:44< .aHxB>L=C^hG!)SjdOKw+Ǡ-kK7'kwStxG ySʏIQ\xd0-l[egBȑX)S9(ϟ卭jdd~]oF>[ 4"x۽;A4ʑS7>883{dE?[Bx9񅜔6P!\?4!/~K/7W.BBsEX3įEY= E͈ȴkgr"}^&_|\Y{9UQ/zK̈́ hlE,]Yދ-aYf ȩ+e*l'oCL(4H1t`7`v._ޏ9V+qof}Y:jr(Ghw(|Hd)䅳"N n)-pt양A8^Ճ@F&0:6="@Ec]͏w[IAC˗I H"pML :!v2 q8 #KUt#L:4wJ=8)y9ow9e; 0to+$m%ua 2?%U3:G̊YSzj$rler $p].vnw}UB~Uz,=r!L<26RՔo囤Hၠ6؄rϔ2?iGx1uUkZ폻aYf\7~tԝw͓?\t:W] ?8?E4H}8L%&^|HT;@CſUk0 !Q Hϋ;S4ޘcl,ҿ¨$:pg7)A򬈥QHûljŝW2EM>\?{S0_5McYsz%Wc r(‡P Ew< Ğo8WSӯ|cȐɸ;7l8 ` # TD^nW.'9x<[:~!h ʐKޱ]O:f]8SzIQ$}zԞϯc/>FViF*uTS&(è^Xr3!/JhicSSU|}p$ev&IsWUPQK 3}gQvdg#?_=Қ3Q(GnH;nZqT]1c|Vؚ-JQ|[(l+ '~ DM op͡I4^'\b؎0lD> {bL-Y^ÃV,{2M+}CwegBueq5!:Ad mX>`O-42="6423MqJ˾fuKlj}7pZ4`Yc׽>T7lhsMQ @E :n`BkC-$Hw+0يEOjI۞fͰ F,>3IINy<_hf$A֡pe,'TDi)ѱYj#1vDhHz2[n/N+y‰n aMj8s^1"fVg,NyS=̄xMXVj>w.8qK3;}FJØFKr> yKq P`Gpl/Ǘr+"pɴڬ|.F!,Vk76n 4g>>fWkǼtUOe߇$Mx+Ңl [f3/@A<4ٟ UNHwXW(||[jlBcc!Em|~@XlX&1弁>S[cn#\[ŁOMWr[p,XQ철E6--}&dy.Kbb<,u` ~ٚ1*|?` Fs J՟y6kM:}|i6z^zyso.E"n@fM(]m-{'u6Svm|k d=駴N\*ۅ rIN&|ХS#BCI> 1D)?ý|̐sKze)׸ح_-h~s< mlz*/Vg^g^'&C_~wcf;"!d3"sYkBm;o;&w[*YD0-drCt_ |ʊJ?7%ue}sS~|k;a"JlpBdN}pg7%&*Fz&eW`] XRF|u+Hkr| hz%Dѩ9w(ZO5S9rx);LfB5ڿ~,W]:I&KQtTL;kQ{+ESc05$`Hu|mv(i-W1D<7ÌôM2lq~D5Ƣ,dʎ$!ԄVb֕Hx/XXbրXFKpXS."[I'l$ġn0*c=~;əp&kN:kZ1}; Mi'1Ec兞Nuy).*٘CO]!^c/ [ g{,a!铻jz7p#99 (">^B_akSaȖs/+1K ::7~4[#GoZEg!~7*(Vjz8ڵXiQL & >c]Awm)U} , $řgсW%wz?QX|UVQX\pOύLr)o\Xc!nsL'9)K:VtӤ~8]T'ېu([$"U?9ɋ`DK E؝)60Sih-K1%Ҳ'X|h fr6&H˯v挹\hqb;0kbh" QjXc/r4w0F=&xhtemAz%>)lj9P?kKl8j[tN}/]_@iBSbǍ@{Rכ2Lz2%x^|Fl=؊{ %J yqU&86ki&avS/(\)HyߠM esglqs=t "hOy:|Dw]rk&AfmxbN|= 1TedH,*U}ݥDHo9N[ƉHmM4E4}^Xxjv`(+ !sqV+j.d-glLPRV>Hp"idfyPGޯT4(N =` \a7Ă#j=+JhlwDE k~ix0kSuLtqyߨ4.-zI-kz_MnUBͣ8CHn }ccמs0.?f5`\F5p(C4x)B~g?8.56):Þ N/!moJR+zW4}1xnTz~Ov+Z8xX-n7*9g\ i֯J+#ː6\-XJL?$R@.HZW[ú N_^r-s J=#:{>!?m>t("΄ s .~3t2.FMa*,i!FRzQߴ g'Q(nZYМAPjٴݲ#hH;z\E74]S9xԪX r/`wj:Wg9D{hʺۼHq Z@tca6C 7$7ڿdZ}%-~B!l>;فWZD: +SQPl::BGXgL4dHe{Ev%PiJ 2_T ju/4o-9Y^Dr~L+>C]Y E\[DK-fH9qV,&?ƫH7@t#e.6YzߪxN[:\$YN 1t|W` 1h-eDz_ܚ#aAժ."<;he;AT x"A> ˒*WLQ1{B.!#Pln](eޜH7ʂ:ʊf9m9Z4򥜃 :£E x33JG(N6V쑆ĎԿ& i}%` t;vh^%7#fddZOCDї?,͐V"f]2NὙK@2:r\fwBHB8uKA`Wo}3,u2+:n0(mg c~GzF?d]8TX2gB>mUڧ~'F~D"gxcjLob]J/dgj?AxElOxzBVM`EU{}dlWdI4|)\A&LX6.n4 0Y_Sʲ,UDaסS)k_U6MK.3Tym q~)lcR$W{T&pGBez E#<.jFp^HPLO(-25 ϫ_n~mQ\T`c4-b_G$@d=ۄߢܲEG:3-qYVfPUYM蟜#pw_EAP]H1cK$(z"*Vu4{̪LnuSU$=Pq>e}<$p~`R9٬$ .Hޮ><4Z>j+ Ox(gocR4d3I2$& N,y:ï* dVm(X٦?=3?wV8-߁w\Yv£lN4 ӔrA*Oޤ*a*ONouw %}bhPb~Y;8" Kt:H`ڙ86 <%SNv]Aʦ[o.5A @Es\Wɿ 8m@ OAx&tOz;)DV mVZtLH*ŋ!z$[m=:Qҕ=Xx@;7A2\5/|ִLE f̯<_pƜz&qE)T&Ss{8DL y6`>x:u KS?5W .A^2R|(;'}L:p Nzg.L ͑'uH',h;Jˤ4)IBgQVc!cd^oa$# Ϯ|Bpečc+KWqv(!J-xşBn-r[n\B)=bJWB=)@p@Uy&g:t\KzmxH(>>KBU˶L9~#yT;T5]0I[|MTc]/jT c;DyBKnhY&d?{RI62-N-8pSQ>~nCrr75KQ)]y=vv+qv*O2A zÔs) 80;2$p0?h0h`j9I)WL!,a;n"̼*< 3ixUHJn¢%!з>ox9yHDK~;?H)IEңSW O9J{UFN.M߸,n<^rL3QBCՍKx9/ӕZ5+Vg"<M(+'amWu%8 ʲyAzͫxMz)]5m3Da)օ_ܳc.kk= JSmֳ0ۅJeB&= \2̀10ݭ6f/i!lu~!t!@z(#Mfh;zĜSlfyƶL&3m@Tp.\?;lEkB'!hֺ=A z?#m.Sc`d[E-OͮM2/W`v9V2lSf ooɛN+ CЄLdGa2J(Kễm\NV?S5 Jm:F]Zux' K?~XѴRg2 hKp#wR'aK9MwMefŰ$pgF>CQ~;JȌM/ #K1hi-'N~j1ct_V$_߄ 'lKj4S0lԝtߟw@o2.)8!B{ؘN㇗'d gT@T֔|`.hiڷO,Mb{ lD{~r@MDcNjAꈪr4-[zWY|tέ_prHn2Apv j)ۜwQ+%0vHR Y-!H2 zXqcؙ b9Wrz!%-[RNxNvqk3|gwJLmQ !w}yl7$|2)`:H k6c*סD~$"fr@/!!3I^NIm~C"Et-PzM4W=dRV@_9Jkb@weZ5])?2a!1zƚIS?#ރȋ)Dk\X] bBKLPCݝ=W"B"qZiHjKDY$wȔH!b*z݊[ܩyͨ%c~{ 1;]#OCiط/h%#2).6E멂Thsy(akt6Zuw}/f:Zá)sT<.R'+@-Kҷ<[AwR('U)8 kcJjIy~`DyqڽOGR\3M 0iD޲WMHA6 N%y[RIA 4hP|`'Ӧ .Clh>fTvT{?NCSZ.o3̱䂙ZgVAz+$*O] .s0oxZGḦyEa/-p9i76OPҪ{ّKVW26mךVao1쒏mpL RkcX;/azdпir9eI:HBi.u|ƅО;~o Fdtfj2*I-:j߾^vP7Fha[! (A]NKGmŞP?F, -]ggax>.QlJŹsP>xF";#P]`s>":אXdfb}o:d΃d_ռ]Wbao T p_?~o4 Ğ_Ptث.zӘcxS5E$[Cu_Ja-w\b5FЙB`NhߓMw+4»˳J`H(C/76P"X" iYeTɞQǨ:gr#2+a CQ g5scc,ݖF z|'r:vw_}爵-.* F**udzGcO%.E]Z0):hAc~P7T5ŠAmbEhq*lzfg Pgr^dY٢SM?s>&Nv[KxV# gdކQ"?XN-Eq9#Dg|n[~h-W-n&h@l2}7YOw t|Hu7&miOp}6Ygzhr.=N} G~9-L^3 Be:Bi٣y-X@QWA2X\OC)-9E4hW›<<\Eи1eduԧ{M ߹A&V4.lwD(5B0xBH[rD .Vј U.KO!GLݔ]>3[P݊:Mq*[ zDcixV\C{(̦&jq MǟwOa ''@vC16At|42so^T_ɊI An IrAO,9,zB؇4 0^gH__N[݃L%hߵrf8s2$ m BCu(cib)3Z8M~/-\ jK '!<\*`1ZW]+c<~ 2jSP3XkR+WHqџ+іʠ+.*3o3RǏC(p۞v m'vodp,K^g&A(FlQv۰8 "C)Fb<$v=6 :9ɾGfߖGU~07CIkJp&'D}*XdlSf q珔 #s5fۋn9E_D?y:O zscy "~a(`(qe2d6@n`K 2BmOK%+sHU*S&{2+WR֋{-]s?+v8~QgƵ5{' Ȉ]ѹ/@:V_2E&CyxɼYX>|Ҕ*r^W:m2=6 FqQ,Hpd6dL7rCm}Z@r/:+YީIEtm[%JjQҦ]F^:1F'"Lnjh \o~,A2JN95]4 vDĒ^yf 'W3|Lƈx#_1o%DU̅m-P7p8|f.֣u| T]OK4_ \1*MFIdq{ZZu-gG<ódWS<H-Tmݑ5L(}Ea5h^ny9)r ,QyⲨ7mCػՓ+ADԠ8}J\@xS #mTy9G+M ,5ǷY:S=R%zN,ecE7ʓ9V@Z5`n+v2f2 Gqȃ]0f2`ׯvA[VJpKbXjDBAJ-Kw;akɭ+y \w' wN>]]_DfLER_p#v`EjV6;XNJ^8dbf )<&S{[Re~ _ُ_.Eq+>qcl'} 6[ӌ zD]l8)Tnex}\>O[w"t֝- MbSkyYQ갪bU͓MΔ/($]ߙMXV!I,IRX(2 #P/e-mQ=)L,!fe] F(?DNX0:!ɭxЪ& mz"@o# 4.>GelԬ2{z/[-7 4H"ur ;ߺ@kslR 'BttәG+ ]|8.6C}?7&E vq8>~W];a,O^JUi)-^>]:3ot + `xԀ]aO? NɊMANrZ&l@|@WWlS qU%i-;!oF_u(ʁ66_'տ*L jR(j"j3/ni /qߤB& =P$d@d平!cnxP ux븦(|( ~wD~FIuKi t&2+RYW=7ԇqnN!mi3[Hu nLTǏh2y//gP|^;x쏃HŽ sDۧJ`;a6OyҏOVIIVOү,.\YuKcc+͛jƧm Z%Tϙi \ۧ7 xṔL]yI$N46u=(O&AĬէ,A[e[,T(#paL3`bAڦKJȃq0(qK MCÆkBjQUmwK}u5qPŇ'+*X>nI/VzМ1}Ķ}Y;p,֓gԶ! ̀>'푟ze,9&v*c0n1vx1`s'd';̞*h ~doڞ!&Y$קby!`0P#CD_!vڌ_;*VᕃؕgS0׾JgCb%[Y6VLhڟȬ lG]ʰ)V^##Fbꅦ>/?K:b3G"WkUD'$F R]l؛-*~S7\nF[08 $Nkȼ%Qjaۥ®uz&۲v "'wR醯 ;60Uѱ$h9CJ?=Ɵͺ0WR {t @ Inv8m/趜U }9h\֍ /_Fв /^G߭:X7bXy?JûEecڲH^2٘kW Kh_i]M;!=8Da!0\9qww8P&kTD*b1YD\M' `y d @b0K5w .l|). DEGP Jt^|Jl v3Xp}AW z&| RAkC^vҏ[;Eݲb3@J,_9mC*Z yM )&P'|j:!=i; ?2.e[+{/$.z6_yIOq? :.>|gЩ)M܉x2]![  c5 =A~Sp1r!;,A˾pgbVS6nHcbWx' PtO[bK}F1F,9QFUNSkUIU%77g'錰FkQD625Vt/9D>?w.ag+uGbcwo<2y6LN@B%Q$UnRȭ$8؄C $5N6/}%|l}M;B"BO}Wcrrt"e ;z_s37'LR)PRo:of8:RS.~G1 e> w8ޝxITVjuփMXOqTEM^\\77QJܢN^2_TEpgx+&#o8L45\=RN5$m@a͡ЭlI ]4kgqqx8ņX"9s10*imYL\g^ wX7$=7PˤhsR$=VAj U{9?NơSuR}lsUhSk6G7YO/M~B^ )Q@y_&g  p}ٶ ,*cރ:zvt%/n:qqˆnZ_LSuJaqj95LR0(ZcKoi+M7]k!(N6 Tm2~yu2xf V pM;fx"Á &K%Vir#_,qPSx )o{ (_"u3ZoIL:v*Ғ{2b2ڤ4NMo!7-4p]薷$b{: RD Us7ڣI5f446 Rk pYVW*Uĭ{x'#,sgNCϴCPC?|Xή:6%ܱ,%>ӡ?UT ] U&n'tB"&VfH@.TeA*AX"2:$L&˚jY 0d &Q]{(K*gT"Sgnr쭟}~j)Dm"CW9o*nhIѵ oAsgRjXs{]85swz-?fLyߣ zTӮiGg&qi"l@ч/"\E+wMq4̗}+XƱ3^pJ X(c4<5nDtK#]0G.:aet: &1Z\Z5Xtl|?:Eu }D2~`ȹ:w{z^8CkX>ք gIiP?AuxZi$lo~򌦑DCa]jnM]C1R"V V v8َ9mIl>1?&gsthLj+6iU~ĝ `\v)LO ~BcW)rN)΍;+wP_҂K&{NjV C-6WƕW$:(]8XkF` A85sYh$W7=jXwq"CѦL3BmezG4z˶,5Xᙪ "kJb5H΂leبM}m D՝UȖhugG2#O@_i@+qʋ*;#U?"ƨҋ2A'uEdU/x~sUن,]Xm RVu[\9tC׋AQ l 'ϻu B/H9Rdb&$8MLj/x 3jNjY/8ļC$pW> gT!',qXȁcÿ7"lfĴ#TV# pXVx;[o71iwㅳ)*HGK[Q 7Mp*AfM;peR|U98;ic⓱oaxHz{Kna^S '%^zsi,8AS0MZh&}᫷3H-Ǒ!T TEV8*w6W֝C^{PBO꼻,Ӭ΢fsG.gUXG\pFDh>Yc" OE:/:+κ/":fHYAd7e9*u Z xS]yiQ~V0A42cѬ FEOVfc4Vm,]Vf$Pů* t_(eIF< 37% WVx8 `&3 qwL8 %|wVjS.QuQw̓~&xcmV;jW ’8κ&]zқs]M)!d}4NgWN[~y'*Ϡ{fC'"ivhdtMWp8ZQ/kJC EvU{k*r3g14P2M!!aI-)S(V|I-4|/zDm4<<ˋg qa6숐D^`D./k$좑:;n\M$Nx*ɽ~+o}󎈟i`]5 w@p:=X:/[cI<( OL7E!yTg-FeТɾS>3(;jzMQlb=܀_ɂd& M64ϯ6B)p`d:ʹ-EtN1~ ABp|eT:../c QpVT5͇I-¾>O4rT?v^[8+C5'r"e; I6+7Di^%G4j֔kZ;K.mIac+6ŏib˙́-ƦA" - |CJ6=+֮ψ\񭿸^|Q8 ȣeD1(WQR{LG],I,]7OwczkI,םVSȗU\ƀs[T %t}ϔ "^Ձ&N~>͓3mу^Z%e>Eco/Xhʜ۫R:BSekc9h|f㎸]i>€c9)*lf*q8m[R0R;!ÎydGQfQ/ﴯtY$/Del_\Vdh8V!K%U'SnPG ZF.2R`4s>+{mw^=-plGq{0DFlImf%T5l GO !Jܽ04B/G~4aڋaeR(p;G8@>:}K#?u++q%4yG?ZLC^1?z+oS7>4 聊 BdX <=xҊ1o5f emˠ2_,4|sD%oc(&Z9]9 z)!biFСdZ]:J߄"42{b\F`WI/}7reڣɥ,wY@SY!yX *~$O뤓-w<;>i2lֈA+_b@pY"ȜdT/ԯf3'nwG;<))IK*V22c6t~c"ݡCؓ7X ?uɃ(&sLII""RZ7lUx-/ FT`.5w Ϣ^b0Mu!SΒ+0hBrccpr8˜O4_:*ARZB O>gmO.5MLp'k՘Llrx.w2-Nǿ'.c">͠GΡ\ .x RquELﵺC96;qwݟ0ΥܯB܇MMØ'"56}yB aukX4d/+f vYIF :L_p7 ~tPL^!‰iɡQd_[bgqjS lmefGvJ  $#'~2S9wETD+W`ءA4m<\ 5yXZlm /V}=%3]~@22Iv;b"e(%Uʾ[Љh&d'8O_:дw fb>+^^lL89ǙU hZz@e@c4I1Qʽ%ꓒ_R#S|r_'{( -;dc-xmk\ᜈnDv@Qvό˭'ˡS:ME@h~ c\c<)S؜etIMf Vyf?ne-kћ(y!Ho\Vë+?[S$}X-.[JfRۗ꧳[ƀ \P(Eds:@ulp]ER?-#r~aJ_hܽh6f?Zlu,Åa~=CL@X&hZouP ,=D3nH@ɽH~DZ? î+Ӕ agRh1vLAM):Yk1iAHh2~Kr\:jv 'ž@O\h=Jh>Jg>*N;jeȘ属D: }S,AG+qcuv8ht%}1vjݐ_L={s6D0]:oks4EPOQ`ui/C-Gua21v;Y"7r[gYzG>>ؖ37@̏n 9` otu*^cl:a<IWBWshcE$@bjXcsඵX:IJtH<*$͊Y?V^eL`ռݝ-!MD>#$Os/@dWLˋꁙbr U2T'f$PIT91 F = y /+_  * P4*x,@YuiOpG`q.VtsE4Ao--`},|y}nl0߰w8jf ;7\ QAj1P'OUJ,\:((b Aػ2pvH HYOF[2p~0s:`),M #`D4o\ٔ"M0&jtJݹAx%"|/ [1a PL{D B ( J.~^ bs`%1MF xuqo=꓈ $ÁRW$gN{YX_lI-(k1әn>kw{XXж.i|{??}5HK*?P0;jkC#jڵʮn=ak?M7aWCp0Mk6rsV;?y1tw,.]O}̢gH6loF{hOD54*4vtGb}_0&%C۟$eܞН-|-g۽ ܅Cʺtdn2e6 Uh=!+ #jRbh\!$8>N57R^1E*9A[Z+퟽Q IQ;Ocw"߯H\w'NAF+LĴ3uU!&E7w5ź5(_Ps)ghHePBy5kja\%1 "=- PN[QKmRdw G8ؿu$R\e.,U,9"Qk<1=x֦'oˠКN|eҷҳgUSB>dߝF͛cX2%sJN6Bc7)Jz ĥԿI٧[Du%3 H;0-5uk&ߦv{,̜E9W"kIo>ɕ?҆b_\iiD"+K zڗv7sc$=?ㆆsrA'rփf򦐠+9@Tϖps!͑B4X_ǜ|@@qt4DnQ$ʹ%NfT5&]?B dWZ4:(~/JϣU: YZ