pki-ca-10.5.18-14.el7_9>t  DH_p`|$ƨkpyz.FYiCit@vrjphHP 6f(j忓4ޘP׶~gpr^Gx@ʏ2|N#cmS8YXjM4JfVCtM=[c l P&{%~y9 x~y =};d sx\5pDfwLM[IS~ dvkedL+G#=51NZev(S%ℜ?0{; @F]^erI@7!xWr9e(pʺ\=&Z-l0iX&jH\<,&,<@9q1Na*JDP.d .hUUvܝ(w`2sG̶"lûp xf_7 -X-ܔ yB9Ç^`jw#8QHeRj+D${560484a82f25dda369473c94b7179aed14eff9e9L`|$ƨ]v&5g ś{ }Km.c8ϚƖՖci07ynΝQg\X0hz۩nQ R bAr0^qVay(=1s` P3[2ѾWЯJZ7Ng cZcV5t|YӮ.Nr9qe8AFK;0Z#uw-|xݙ#Tg]<0 Ido싛^h7͹VU +C\{G忨z?}xwT gbZRƉ4$Lqnl#>hqq WK VDӊAuo'Kͥ%*%{Ζ0!!*%> Z_?y Ѷ|0ޖf&>7d?Td   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P 9 :> GiHiI4iXY\i]\i^=bd\eafdlft|iu iv wixάiPCpki-ca10.5.1814.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.`8x86-02.bsys.centos.org%'SCentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤`^2` `````^2^2^2^2`^2^2``^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2``^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2``^2^2^2`^2^2^2^2^2^2^2^2^2^2^2```^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2`^2```^2^2`^2^2^2`````````^2^2`^2`^2^2^2^2^2^2^2`^2^2`^2^2^2^2^2^2^2`^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2`^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`^2^2^2^2`^2^2^2^2^2^2^2`^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e29fea2bd3e8e0d0012b78f9bf531febf01cea9a110048cebc6d702dbdd66a58d8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-14.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-14.el7_93.0.4-14.6.0-14.0-15.2-14.11.3``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-14.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(0xn SaE1TXގO_w/}BN_WEa!65Zp'&@p9Q? dIWzZC4#j3Bju^NQ@曮\8U՚z+KH CKk@Ny;5w&y(UUg)j[A( ~Y؊OQ- e!IE&f!{!>.QD ڬDqߘ5oۍJ 2eWڠj?g{LB7u}mc;l2T)$yqg]юTRs$^y `!Bky;aR rvyhʲ+vyz'ZFs//ޅJ8[3K❐g=E/'?V&h F?2U$(FLFf>u~)Q\[+JZ{Ћ~D_#c,ҿj1Zۗ} = TX/cp~4t@~E^X8}P'k3B2Qp||i{<RG> W 7#L͈kV`)w-llc+xQqIMϴz^*EH2,= twi[O̡檰ؒXՅ/E0lg3F 6ǢH_V%a6eR fᕭ7Iy$C+\OΟ$!)P]]:Y^\N\8vƮ5rOg}?s6R1Z%R;1y93co.& +hc{cz׹56ll'ޡP?͉?fye.{et+ u!o!T ̱DW_l r3z"n=o&_~Bcs#:l.|JCEȨ>6Hhm׷J%{H2Il M͔pi/z*!D\Qj(u7t1R^3apLp0bH0u$$r.=gJ|`?pnTOԦ{M:AZ}xBՓ$d7<'p.C︔N<:D6Ix/XWv" IR. #SB8md3D+f;7t`KSx$&Yqm8S>ZPه9a }shPX .MըmpVD:uAw)/02Ih\+"\e$\3r#v==yɅ4cx}Pa{ۗRv`V!^`aIapg39X-#DH(ȺŁD偕 z{ӖmHHLt΢^~Ң)?4Zdka",5yCRpCwGD vJ>΍2mn1hSڝF|/CT28*i I'f`z>x?0hsMw8f/Q+YD4GB[)gIA~u!S ʌſ t_3ޅ 0D8^8jf=lw~$&pL"k(b)-"WYB+kX~.M}1 X?tJN9OzlVdfpV%: JALH  جM0`ox1ho/ /^s@A(Z1L1$'3l'W7J'*_ɜ)y87 Ak%~` Բ{x96 /VLW3_qWST.k RϸC?H-!"B$MJƄEʻ%"&S$/ vN igj9 M]f *+r] 2.e0r~vf׬oCdCHxr_w^H4>X3nהzѢUC^E~OKVnpI?"d_:#-G+@J_n/g-eOPghIgT,Ez"5yR}moȉ[W $PR wK=`9< X;ɣP)}X^ kg o00$wl<>!6@Mu-kBaYIOL^:Ւ*8\.=/O~H(!s%d1ԠT7UO6Y ;XZɝo Zǚlπ~ԼXu^@u\_=]Ӥײ{' ="=r)M* j9_*#ъQƥFЌ'O`>@rxg#H7b; ZM˲K/C(=.8Mx OD{N6y(w9*)mӒPj%tV{v|&~KFFK(A $F6+wU&GmB ױR|E1GwEPQrwQw#鑃%fDv}] h9ȩIh+XC1Me){Jh!i$Bq "Ju˒ŠVW4 ,A'NPPR`` Ss\LRfB'tE20APɴ82g/D1r|M>ƘGgddʇBV('CI$ ڞ{/ c7; Я +bqjgLZz.\9R&^qVWcCץ5z5ܠe~$<5^0dc<#E+:;b10AṚYǜGhS U ^_FgC}FPk&Žք]kTjP\92zYi-5`y>2 jBeA"g[ɞ&#[)!kqoV{VI!LN?QX 0_km9cz V~r1P8Tf-y·hT uvS a5.pu*X eyǰanj ~V]{? :1ߡ),U8M_ԟ_ȑN<搠%#1 vԒʋkZGC]^mv- vJj =L&L{q('h, #h[ _cVJ4.2i cY&ug?U V%H<I' zBnÛO5+"^t[[w%197zKJ>q@>U\nR4]$IsQ#$q1OИɑ6-|ɛjg!̰1sKC{t=ՒV=0|t@<Q^`0˖'DZ=άir.'XuR\6ŋz#xWx s:_HVGhD.ju \DS,%`;*T=<3"|S_?t*Z)|cZV7'bcK"e*LUh6^_ ;ZXZ(@D">(ZځB YnunnG,\k:#Y2%'.Dl?l fq:5zͣJۄs'34*yu1gئlH6_nW a5 ^zWʾS|`"+;يxjE[9@Zfuv-C͑ ~_)LESrphfn!m p 3v^6+ԉ!oBxN()?Kv w֌@'9ApX=tNp/iɩC1˞&n>sȶv5yXdЍ+OEIa+T=^moEZ%'f46rj7)OrXנ}jĈ*A |CV/}՚X͂ޛ^OQЍ./Cۺ{>pڽ&ݚsE+IRO\U s( X9x\ 1@˕Z ѢZ΢ Yc)m$J(w 2|Eq9[2oiڴ./&EqP *Ü{I (mW%\l& M ͛ ,/jӥU +X\wT >C|f3qQ!֠K0 *>*A~%(ͫ$o;_ˆ1z~&DV`F_K,fB_NIUzEt@Dh|G˽v.e"c7.}H`+Rڹv82EҼ|W,G"㵃/h1q@iȔ8 p bbh~_scf`%[l?&r7%!wqFWlH3<ѹ)slZ Դ)N\<%;\ gr+#t93홖nmZ=詀o=dUZh$MJqwe?tl_5G8V#bMϔ|hyQxh>pNo՚<m)xΈs(z;aS#Cp*d;vSw+!ʏD[/qԯu|Pg 䣜9?H|,P_!%G@2|?Lo4Ջvs:VdQM`oX]pUvVMk`r"z{Ա]YQ)McCRPH:,ɚ%[ 080tnp7DUU_Z _ rlZ6wY>G>,P\Sڅ P6C*.#03J`|03?gNd/5_Ƒ o%.?HTz68OÏ)ۮ*F +t,k穨 OtIA2oʇ* G!qY Cf_P2r|^eg 7Dz\4=>p[iG;n M8 TK@{J~QKgEb 䞬E^Kca*mB$w+Z2ז;3lI[YƇ؃_Ƴ56KGJ jvZ..m#Am-潑ři:Wbt65@+zHۧL}\I6O}&i&,812<BRM.z -os:DZ|&m &h{"4^d;j=Fb1Wןy7IiSҌQa%R)(PNz7zR ze/! xD%/ wF`/CU 4s;3g1MA͟|7rbzKv%,|zЭ3VJO-.=**9!d ( a'$o KbY x(ٔ9JHW ddQa3/*O*[-K q EmZ!Y\L1G-B3tƤdxKKi] 9|9B9QP t? Lݴi|ce9Z! ƕ'}NBg@aj'aŏ[&6/鯧Rl E{}r1u|hw&{`.rP D .}SWLuuBv߇BT $~V׀`i0 x</"(_^`Ϭ 8OmTv$=ޑ[&|\[Y!xY'ɿJB oڧLI󛮼[T;n7PMCz JǛM`4; KX|!^R6TqO (5u6]$ʌQM3ۥ@l1"zoCvP5EtNI Z{}BΌۧ6{ jzpe&Jg .p[v=dl/Bwjv"(94IGnC eᏳ`|;Lu(,\GNkB{qq*ۘATS7I}š[12dG ub9]&e~¯}(z l@-reGX+3݌1<Nu/Hf۪n4.S6Ÿ /;R o؞]ةJ5\OZE!a1Z ȂB7x~GV=/ۥrkpocмw s@<m1zJ}\t,K:gG}u#ވ#)=ŕ.mM>ySPvu'xcQ1YHi%]SW|-'`3Ϧߧ5;) YT9>|f5W,M~ޯ]Ǟ(m=Ѱ2yLy wϱQ DxWm:xEcU7(`7Z℀Hˉ`X-ݧ85^$!Bqs yٺkI>C)6 7đ`MZ섛„UGڦvd3Jx0A vAt;. KxWi dzd|&xh1`e?aEf}%ϫ0G=$kftA@~)x %;db7`Cvc1s(>KGSں WFO7&]RXPߗs}EG|ýęv^zPvvBL@ӵ!-)}pw7k26z|%po^R̗m0OnkD%J{jsdj@c9EcAt.].Ə oz+2Z迒9S4؍pwǁН&iY)s[v_8;jۂ4Cl܅DX/UUv5F)#Q/ eZ?L7= _adnkd=iw ^D l#|5V_hA!]}=2cAvo[XӷdUޕw2s/[d񐣜P +C#%ܸ9Q7 זh..e(6謵HbD>5eI7A7cqBDAXEc h>Ai ,phB`-W{7($@fLQU0`jVt<5mF洇 _b$˰&yO$40\\8Ϧje@/I|c,4*@}{E,w!2h6TrA69(phgѱ"A#X(~E-Bj8Qa[FdT^0El>#6\$e=wތEMj۶W&VBq}uޙX[-C7jmXԶ֙Ff2c g%"41eS(I:] jNsx^:\X;q56`^Qb/ y*#p k?AAH:g {|7HgX#'I:]bT䘿\FYAM/7$1豦)+bBӰG'OCZ1]w*ZheeL,`+ףS1bj dzaTl{e ÓHW$1BO$2!@ӒN3 -A,#2LׇO‟/%27x-"v){yG(Q"ݸ@-!9&Ti.D%QvpM?[T Lpn vׇ9O0|fҜDoD1"LQwмܿTH)~Û.gL&T^+cYyժ/G GnZZKԄʡ߻(3'>%H1oP\|(y: } R!S]r|W $j| 뢲ɪrbfWWY2*s}T[|RVe`/ Fej1 )u8=甑@GӣL$1`Vl.6mP㋗!/LLF$nm IԨxk!;f;J -\.z3 | 1&Cp0 Cy].m0aƲ˕/,~&MC~z|ƛls/9ޛ8V:UU+9Ĺa~sn8'"9;Ry=z4rCmv2O92NASѢC)f੫~qTL T`Sf_eK EcI X8;mV)ټũ*{1@se sprƃK9d؏7VQͨ1d<Îs>05s(-!$lJHFNTQGI"b WjE'@G!~>ofCGVDKd['Eu[zµ!L Uÿxb,Ǚk'E!vgpka,NK'α~:6n8-^+;= Ғ:2hE.G`NPpTB%5,%Qy,[󔈹>9ZB-iǯK_F:o`A~}p ZY\]` ,0NΞܰ+J)Ǝ^ALrP0 uW4sVcДC74n:2Sy~q ""`|GK|,.Ϭʼg7EmP1+F8p`H5bhPvhuD$D|:8gҲrN E5Cn3B|RX&Sc٦,@ t0͒9H_ ~`NRv]` 3; cx$  cK*F! xna2GDmh{rEۜǪq ٓdLq79E^GKr{׽9n~T#lwÚM}$ދ%݊+UMe_/~+#kц,JXA -uJƒ9oI~ OS}^:_2\7bDN _-7Yn[!w;a#Ђѭ$EI:Y׹54?E&RL:(ф.8!g:z?O6zv_ye$tWVb_b3\uRb0ʾ5`[ݽKd=[=-H7j6h` }l ;ߞRRk ]TT8?TRAƲpvee[Fur"&tx7Iu2hg_%w\] BlўYl>5Џ-k upP\$]R>;? }!W<5/"Fl͹ mP 3Ifl7*{hLwM<=Yn*'Fϒfsh8B&} =V&vqѕ6|̕U+ -9~1i~}OVձY˕bگk7$MMk%hx DP6`D*IA5.6,~79}7GG4Ah%xG9GdjꢄR;JR8*+Z6QL#O(ߙՂrUúb G2|c A .0;=[)J`-)S'n=zK#G""m-O?|Ug2D'BCRw${ĂG`]:(!Zv%ҩ YVjW 9;*$b:"`y}EP6yo.E4 It8br">nmCSN094!*:ЌZuGu4{9-&+ mqc1Nբ=^#QoqOU u! 5lz J!wswB-uCzXjKh-[kDt57>eQ9_MK: T@"69)};gZ4V:a^*²^efX,׈22 >_ ׃97:|uvA_ % y#f+_SUSsi}Eiv}h&-DYǺUE2 TXܑh\{$[yawJk!5?kюаh/AYvC9+|ɿ`?"62F0XJk Wd,7wZIWQ@!X<&?0av`'"]vNIt2Z;#))wKWmMy &i{\JTD,u@zC=S.?#{HjlĀEN ; "(SLA^٬tꊮ@{=L-ȫfNd:m_ 0F34 N \Cl?E<'I0Rg@yvwDz[ٖ5ZN9eA|-WcvV_ACQ|S!q!9(iCfli̡ZwlrS['"] `/q+a&_!2jAZR>8\{ QG/D,Y Ehf D|@0=R̕>) 0LpZѫov:= kgE oރ_I',0 #i2?~u }0@vو&ʥ-UJߟނzHJqc4g4w#Op~<}'ĹI{!X6;+ B[WDq03o&o|T8e {o֭+O_?+v-ǩtuy,hOQ yҫXg+ /}_=fsJN,WSܕΧ n 1Ӷ5ByBTG'w'`;4,9'dE ] . +AiuTBP.6p._A$vpqYYnl9ɵs@\p#KJk#9_h \{%:3_zڣ{;(+,KXdibhKɋQ V^%Y=;u6Wfv2^_*Rߧ珡 ڑCo2x ֽ :@K3׆)z-" I' L"0ЦSﬞ#}d#~R L?X!om IIUzYe\ya$>z)-56i =nm:x7pZ%d0Z. ⨲+RܺniP X}r'.uunmֹv3TH u8nA UwWjbJ`qcL`:[]Y+4+Vk^u!;(!O͵ 9vRUf#Cfc15dSѤ3:gQrwC+d~Q'ΰXWۢ* ;q J4xd=iGI:XAz)U?Q9&Bw{gW\I5J6#3U~CDDR5Ǔb[nJv_KcT UtXy XL #lejtCj[l|4MJc,+? /-)7jt{YbcQ.ܴ^)mgKr:Xe>2MFLZ!4l|ӻ$<"_io*i`(0[ vBQwUٝde}΋#.6h!݇>A.wV,(T_BFK6;/oޒdiܚ rjz=v /+<(jLzQ􀯼'N3kWܪ'iH-I迾Vۦ6O-a*s E񊬑):v_7J56Z^mlZ\;(D׼C͓i2]4Қ۹t6%dYܼ6`.cHjadGe -"&PYxrUbܙmޥhnHVXhi `_4шc7ɰ@dG&ϋNxt'P? 2 ȏLflV`}\c=YKw ' ?E:`oGȫi6|y{%ܧC#0: F^pX-ߥa_ܺZ8<majV"W>D?SZLf_v τ? L9mJf+e q3SuyJ,uSZ)KQ=x3䳧Э@Zv7fielrc;ׁ5nV4i52UFxB&@Ex.)e>N`cBBٽOn7= N.5;%dDejQg`И`^"Zܸ\ ]6ݯݢDT6ƤS=މRIw^%)+\m`뮸!.o+U=f aA,!O.8S S$uXHUNzS$_ J5Ŀgidt.tb* ]EUX\x"^̀tr=?X )YMc[KX^M-dXWnhOCNJP[SXon2Jt bj4X :4e23 7[& ^t(.m 'y dY>A_лin@Z 42úyᇀ5j<(\Lhr'-n/E ]Ș=y]~Rc|7ɞ-YYd:mϮ9XOay(A!uո&{Ⱥ(:~_syvb?eQkPcB]E ")*N|5l#EvZh5z<=Eby\,obƊ D@@2}ѯC ruЖ--B)W1Nhm_)[ύ|3O݃sc%+D\b$,˸R :еY?/i h\it8"_,jl兼`b8hK >hC+ĚN[[8SZo+`^+!y 7ޝƋa@B*# *1V9 [&NF~HvQ7&~HB}6h9[(Ww7zbm?j[/Cq5XbM XαHd8C/{xHgiH(-H{F Б]p%91z^)>ӕ:ZeUpp 'j36+\>JQJ^xoނ8kߺ*V0^E n*οA*)5wy'd%%.5Β}{ y$E[X[ʻzH1l(NSo4ۃ/2Wۆp439s L,ڟٛ7]X:ȝ- dƶ')y+9ާɧK+5?s.뮨AM쒨xas %lf{HnC8A#Yy("/MGykˌ45^*{hPS8۬Ci2hjk2WtƼbL\{d:aLjP]5'n(:Bb5l0%RgGVHQf"}|G2+5Dѥѩ/I^1MY_Jlun#6nA u*挾a-aKrzgA759ʨk5s6{ rLĘ.{Y\@"%LTB f ́Hv|If-MY[T,TN¼|=>kLCE, w4Kpg>fOᕏ4xXS 5S8ińy)Za(Zc v!m0DYjCI\F|w3>z>S,?`I}p6.;&F[HyUS_W#\>9{hMq Km'ܻUڄdL7 KKr%Bix%'S22<|v&n~lO!T<vhk9T0~8;J)תwF\:0I%([m<_8ɝcp5_ؐ&8C%L~o7f>̲qbA+M)J&N4w]: pHu.2YK,]X Sң]c.ct~Dxʁ5e6@[`8k| O}GX>s^@>ZN "a4K[d2з[otb{0Fm9,2*3%V^w2Ghݢ$~>Dכ{ oF&핡r rkRuTh"Yd^03VцL!@:Ae+KMlaL+2 -G(]Ɗ2DZ#/F'h8<0j8{yGWF) s=}Ě'~׺ѭz Ra5׭sR.5 ] б% |qNXc,Al&P`̒aVMk͝!LbIޘdjRPܱL\=kPu]ؒdX pS4kUzlBZ}[e>Ê8(!fב,G}OO UH?ϛ+7BB2K01"dYuckTP1  }((ٯ$'G/z(X*bo@/iW 2ۿs0,(R@" gϭ딁T9,yC!Jpc{}}[T.SIrn< h bM lmcupʕ`,g'P@> q{aəOWi\>ˁe(P_.}?ĭⷕV=5BR(Wj Ĭ9=k)"fβDhI A0 G oGe3Imjʙײ;>&Ir'`6/ nNu:NVS)1mmQC\Fcdҧ!Dct"mUR3 V|ZWf\d[/EzeJ}e:&40iF;9*qvU5I87Z9ixb_(fcwj1. |<4m.ZELHj{%җ q3KZwl3ޙ7[OWD=nL&#uh,]aOgvCJd֥BTŇ+"igHdV$1+ ߺoqaAXnY&`'v(GcK'@? 8+Kx QysTuh+6ZGR#z$',JI;>6wKOb@m7-T'QkUч.XykTDԪᫀ!,(OzϢ-A`KؖHʄR8%$"mfXLNbl횳b#PoȖ_.֦ɑ|&|aX~!]J.*̹I;iUF6{z _mXnw=^L͐S$TUEA-2^FFo.G[9i?.9gTW/޵t ,b|wSxQϰO$yb $[+j dZޘ{^wIk3XH|t{/]uHJUx%b@Y%tIJ]N{ysd%mWkFQҐ(+B*7B9''4-N:)Ek3Q SM$_ fbga}PYMy=*qԧ-R3MhL{k3uthBJi_GbW@34+`GW7Ŭx+ꭧpFB!cBSs hBqS]],U@ /.-i_Ljl5' 6iڒc~9jy\m$iU_mќ~<|zf6ұ]ニʟN!|kgvHz-H;ᶦ#6H\KF]&u,pgJպJ2&_,O]TYW̴ER[,rPYtcaն(e`9ڿ\xHj$I_S6Mܟ?BvDQPܖReA6܆#;Q0| p0ؐ4&pYcԓqSp+wS "pc\5fLƔ}+Zj)Je}gBB\!rlށ$ؔj͕?/9(Gɖ$,7J q=}G8S ?' [ mYs]fߟ!V-#f<A_U-T (~ӭ3bpt`qP S6a>n+v.P8Gqճ ;W(x 5aCbpϓ$L5w&k?hꡡ$:0i<xD@+^pfhDT9di4%[&z֏%?);kE=jE-5ĿQm&F>|^X(,ͮ40N^MI_k&+iýV7hC˜+*;d'/~+_>n`;|J&* ]MW̑莵`6'ָrڸ4:Zy(xf_Y;9ցs6kɟfIj6f h˸c-yGGjfFZmafu/$LxE U06h-v5(dv<*n[-,n!i[#!Jc!l~Jh#8{t-)fJ(1_ \);]ke;4.͍"vT&r47/Xniv.K0OAu#Y2j P9OG)_H?ŅDl(aXJw3]FKū (>+17<_<;DDW.A ΜVx*BJ"2.~ApWtmѢX zmJwܑy\4K-jEr[Ø`I@`J#9M%L2E__7AgxFGiE_kib+|qTZpR xuSEW_ay05ϵ3" \E!Ƚ$oYOdп#J hX!.(*v~evQ Cvw9U+1DFq=ڋ:r&=tA>RqPg&"+9{ so,Yqսf)z<8I+VOѪ0lbn# űPީ+ųWUCc%7X4}O=R~ɂ3hg< E`b'?IYfK<|QZzv ٳP:Kj j*ɀͣ}EPd `l٤y 2k6v'ԋ59ΦFXb=MnKY#I9J9@ edD2oB_V$>{r 3(afYЊh[1mѸTo'G^x/yEuftfQ)z|34^;&b&Q꺆ffv]^_ h.$ *hJ6U6߿=9_Ř.Q{R'TWB sZgFZvt O7_Oܚ}GH{#ҷjR֙,wbX(zIjm_}R._,L]*K%H1\ܢ$= JF& 0` ed` pԆ˷r/A}U!ubp,e/z+F+zwaڴјXIkPέE/?{E o|S Y>[@?Qx~fl(hڤ) xw y^M%1$w9%UbkkR*,ޔdJτKMSCr<`qUYy;HH\4ne[V H$BTgM|,?1!ĤsC]H(ѻB \R )\Yx373%kU!){t * baBν.V} _QSnI O{ڟ`B#އ\^Q\ȝ)g! - O?Vn%N =-ɕKפئUA*:Q![L5u]$ҭ4--|O8evF$pX?r&1m=M:muKZU) 1p5|-7x}?L 㯲y׊BsV)-;fJ7xm7Y[{Kn7o/!xwtko+#!OCܤ ,xco+7:E'2MZu$Á믌 y7|hʁv7B,j6ρ%S] 'W:p'YMgioW´n)g! vP6_,7l|%SeNۏ8]KŏAD# og>35LX}јo*\<$"Q^QUQ!.-OMgq'9+n2.ogw՜= BT{;fF9Ӯfq: V5&OV{8@i,L)92pV{QY?!:&l _:VbIb9_)}2<ٽ oUnBJeV1N>F ZM߂_pRjt]u2ue1 e}KmF>|%"lrQI;:qqF~0L8|lBJ]]{n]&sAf4{;*ꉿk2X{dyK?. uq:x`bvVd(ccJ0LQt' o55PR!VzqD:Y%,SC1[^D]8@ PMl4{CI( . %3厅m8jJG#=[dOy s\ىm&;joC~DwĬv:Ne#IΔ_ Ao K)ź'pU[5!aۛ2,SϞ D? ȭ1;à1`E \ R]ӌdޮ2.Ga'O&#T8sSgԛjRȸ~Ҋy>Fv吋Oܾ9K i>8榹Av|AG>X|c`ߢfKW2n5{]:Gӳk*}OE8{aU8(w DuHSCZAy3GM2j(㜩B̧{o>PP2A>2iZɕ8S`v௔YTշdk~JNluxbn!ӓ UJ,6“Qj~-%hFw,%cT4 |m  g-d]-G zapf~YVi,n~t_歺}"\>XGGyJۊ2Gͬc_tyU?!mB qx#BDK!4쫽Z]fp?:Sab>銃ڻAO7(|IXF/uӍJ.|m05!&La@8\!H"_"4=-%ohE9)64e3ylD4zG_"ߺ/˖1-z-I}"ɴR#n7 T8ow,NIQíp@+,zJH.añ OQ!!: eqטZY&ҳjtI'x9KhT0)9gc~"óƹƵJ }^cN&st%D5-;Z ~R/,Qw{#uM_({ w ;uv٦:$D$`AF$ хUpA8t*(pdHP7;r8-//d,Zs ҁs7: CD\L)`<~JLAcXL[8p>ۓ@%6X n7B`hMJ|o^M{ڶ[]bPPZU9 oUzrx? #lq gl6i%k<8%'.xРtNPWF [&~&l}G kd/ 7(|_3/af 0+&9׷EfBɿ3+q"R:.()#Ƅß sGVlTgQnFdB# zOwno8]$HKifPQŇDF8VKcTT>-9(ichbeɴ=ԈbIyOO2̴O$)lv 5:֕L+W$JO{x|Z8Uj1fi@+j#Zz++I;ٕ2tqUYO)W ؏b'sUP̦mP'qgŊfa`$4L[!skZ,ݚz!iqm*ka|!> ZX0dswT4HoD/DXs2Q?Yo}Z4laКN-(^S_*RK6i SFQڭ%utt*}?=T> p¼x6$9f "n~B¢x+qe+`EZTw X(l(XlؕZ[ڈ`UmcG7HKwiaV=G6'a'"~^q%P >&a/ӅSy"ݭխsIY;6)teE\ ">!J?tJvK4=찁+0'gh<Fml#Xچu\&Q6ߢg@ǥ72-tU~j{BYr„Q ]Œ6|LOn?x\Ԗ s<ф4NHP?&s5!(x%!D,^kh @)x8BC+6ٷŌ(@ozlu# müC@#/ xwķxKafmUӟもi* `/pEh n/4? Fuj'>,&~mAh!+]K?˺,4o'r(-T>=eBf" }v#3a 07zĞdYF@o0C+5IPG̷rGrNQZBE)-\Y힯enV:kku6 WZtB\ڐbwdekQ2ndpjbU4fyWATm3H, m ݱdqNrFY[ť w\GJ{@iӜ`Dh?+V'Z `/CVl:LMp@Yd#be8dXԷj'9Яn6C'*ʯiw`752;ED j[5(d[Vc=<7fQ#Pw3xJ՟XBP$ŞQj7$FEc,TB!@³fںTCAoo;ȾB8uscqݸYPUbQ~KNP/?"BO;\{r'gpytH.=!9`\TіY  tdt4Zק<ˣl=~-(q︶_'ԉOs+8jQabx1bVS-rIZNK0$n?-ꑼb3וv{,$(ZW'c1 cv#npra=SL]?W} 9nl뷚,,sOFP }PRُ%-$_.Yx3c _AK̼J^X$͝C;(.Xubz}q^mO[3[y7G{ܾaty&B|Ija4k4޻pp7i9b^h RȺ| ;=LhUvniƟ:\>y+jץC0qVB9R#/N $P%؁{,1%ⅣQho~zJ?Ctxy9k j V7M;p/KΆpW3*yjgMȡ@S-y:.ȸR>weġ?Kn\ H'rz嵖$\5?@iߥd1"ˆgq'>K,]è C^9`mN9;{=XLdL€+[-ܱPt6@kJG^7: Wh?X}P#1T3`mHyO=/H*ڨM2j{_p)ԭ4$u9m:fd@"0t ehw6k&.Җ(8L,Ϡ"fʬM4ScJz}`$FC|G1eO"=lx{~4qBUOW?NM;i'c)a0sDDsG@םKZ$={hO)Ad ՠ}u ysOWNd;,rlO?+&G|9Pkx4gbKVrj//wCM^76f)^vD5dφ{Vs̭ij&ii ߾ZRԭj:HO0AC6&,j=WimމWkR]pxC!3*뽭'Nһ i=){zt|V[ Zj]yCEFCƨXrąִkqs!m {*] $&9,<\xP;F{m;Se߃J%Un$.zz/.;Y}nWK%aʕ)p\^Rq9n0E1ɦM ޹ۅ-(4y ~"nsZx8wZ;NW ~>.kx wݵq8pK[Ş+~>DZ9a]z, T@rBAI#“NrT1v,'ଛ 5D'"zŴw1scH)ˊ``C7"슜{9LjW5:zM0i9VZ]:Ѷgрʤ]d*̝g` djD3%r1 .lJ'=nzۂ5#<)Ȱ^05t&RPeN@P3V1?6ot t1 6$MqrT,fs$Vϲc9 *ء+@3R)sNg "b"HH*YdC%URd(?P 5HEn7ڀ!dYb?0{~X̘DTrguёJD:`yVh!*mjA:k+Hѿ\h4G2~G>O|x.\9?H@DǙg"pҼ!2!]&Ӊ34vtp5NX6Wa`śyQV8mۚ7d{|R ġڃqvRpFTЈ{aҿD97ߐ&RwPB. .iQg5mEMe{yjNޕ`U/rIhd}]VXLX2}[K.Mc] .S39^+ 0!mbqpeCLip8δ]|^M%%ǒjziʦAf#$\ $А+> \YVSрKƝ C(hf:cu-A@3=Qh‚_ǏK vjVfb(WX<`rP/`r\aK{pgw.xm.c~ҟFΟK\Q^EΒb)qt}c\{=T Cl!P@NE]yoeFBK(yQWmˆhsWO:?=0 fb}0 [M8< XX$ĦץK>4g/+|ߌ] u XKEI=gn)iy{JVtq2on:dv/ p V̐ܺTF,>qfS]OG Nq*l*s$ks*Q޴iQ*՛xt5B7*<_ q'3E ROSvATtrR7l^?1J"ܼJhѨhsf]4ỒQ>5Me 2)rg6`0QE.[;>l|?YSw7:QD;݊?IӁeui kn9ZS5U ˤg*|8AZ=̈́t,!Ǚ)wFkFymR:a"r+߲dDD=S/z\'_7ȿ $k-Pl)$-߱LY Lk'Hɧ&XSᆀڰꞢ1dEgrV@ !}p6 20+gBNy+ j)r?^sbtP'Ii|1;6z:Z6Vgt?~}pȈ1|")8?>UQnoDyjH{9O 9}_ND}59k< #z۶ Z\mgj.8Հ$ibjQ6{$ 9kxu0kErv_AQΎT9F:6」`(| i c= B`!@4j덇7H"ml )d @3a""-um8(1*ZqJi)yQ5[B + LY̎TżcpF;pIиvM;8ݎ"s[7qi]_cvH ۑb}i٪8ӷeI4Vȕ{A%zk" sn ^ID7ja̮`46F_D lp’vhVTե`mYib?ߣ{LBOSp/:P}/3yN]hxz @Ɵ.V,$|wVbS-.3mH-ʫ 5ٹԇЂfL&֌KH4P]EUt!FXu?^^5:S9 lR$$DqvmCA><X@r no d)*ZũeM0-LDUc\?aH E9;XЬ׀i$DAv2*q4qG{A% DQƧi%]rc0P@N:~l YA*d; Mv V OJWQ<0ߝ!3% u0KBԳ þh"yUT5~Q A\!_RUg7B%% I Mݡ_(44nLԽ p-&no+ߒ4fH?$yE|= U:'؛\9jgSf^g3%~Ep-Pc<k&u?QFY{Wvj $N7p5&Rs =͗_8nYr_ko̧YVZ5[Itz+0F:%e R6ع6| &tx[U_MhQşm:=,?NpQL0JPӐ& ?JvCX(5\/G? jJۃ8}bLdţot_2CixBG|YzA3=Ÿ7ma0<~U׌FMЎ{l2_^%u}"6ڗD)dgT3o6_^h%b_FNn8ywKFP)5 8 TθMc|ĵK>BxĀV!S[8Vf]M숕W|“w?EaBtM#WJqmngzBjI˪Ɵ*+ߦ0QPdK;i=x_V`)AGk=%)\`9Sk䭣R6qX}FejO뼳7A``1G"tCW. 66CI(CP\of2->Y+Kv_xg;ɣdN;4z$h}0xK/SUUqDC:j2P-|Z^!n\!XR{(AW'u,2QKK(06z@X˷Fl"61$x`lC'Z8Ba&d~qŚ/e| =0uinwS ڧIGSUtoi'^vait]?R-gsCwk%K<. lG(vfq$\vEаUL@ㄧ 42$cv0=? 4lZd t`H"2Ёb_$/p> M a%##)*ML_{:K 40hj)qvuvOuu4nm+O64 Hi5#\i4JΈaF>Ic9AOJ\7P,+㾀F}Is5uz"s!@j"@ N\ehOě v um 9-'b E\9j/ FBF@IxԂ&6kh}]]) Q&kq_+e t*u{gkL~@۫?PAccvF9ߤP?rcC6 Am" Vlk5֠9K_Ԫ!'#-5b_aXcc4?TX׫mx56y=azmGf,x 6E9|I7IW [R^OnhsUƣyVrStJQxg”!^g%af\hp2ل&;5YWd&" NP**9v@0ח]'p\׏>ґ;nVZ)} w/}XLee"O=Yp@Bc,>6ߧ9i/ZW=:<9%5) 448BAlDcg/?{xp NOMY=dsG(&%lwL4y_WVE~Zݣ f݉L#yZOQ ,kf~jpFU1ИA+~"ubKG^xsuƟ~S8'1-xHSI͎ p뱼g=,E$58;9jC1=.j.Xa%k%xO a"<*5 tOԂ@o]%&YkK]̭턆o:6#<~DIKPul @C2g( _cGn?~r9oFH*L}kdȶݞPY?)o9mt/LX.Jgh^\)QG,Exg[\_WUCߋH0K4!F _*vMZŐpA pj%CrܥF5buBOXKP擯ڴ _\3Wr/-uNx.LEA/4G$aPC;Iu\P)":*ݡUewmƦCdP%v%VyԸ3vd_ GJ^i[*%tՈmojijU9Hݣc2l!0Ca qN(SI KHTWD'>&bV ~oƥ 19rNJT(G5cP-H7v:ۉF?!x ٍڪ #"#TV}de.+ << "}qrV?!7$BrTp?RӪjF{D8'^HrR;8|L ЭFe_xbS؁+a9gwYt6:.Hrw"Fm߷3I`A8KQ  7x95tP5 :N\7D>QȀ,.΂P,K!5՗-n{n& u&#4 3"m:&h7$TR>J~4)d0PWX,( p*᭢/_#>adӢUi{V$QEp1b#q[{3Ӂ|L]M~l4#>>j6^g+ Hg.O#x~.ea .=si.`9"'ihްϵu@g UmG1@)*z7tt\./&3N1p3kb7CP/ظTtky^bɡ{vv’)[q* Ài9UG"K8pץZvsz”QhSzc㽩Z\'Vr|ϸj_nn:O. 3suf5auT1f#~& :̂5#ph\p&;:Sو \i]mtxKCQ~D nRbM J˚k-ǣObhFxBy&QjTlR@>#oI _]cMҝ}7]lUZ3>"L=`ܬ܌B![[󮉖d $0 3KEn}% 5UhO ] ts HI/$Z0KToJ<9TOnGi/ܤh&daYf#)MM~?!WEMĭѧ_쿝Fx7Sr-oPK=2>ޔ#,NK5]PA4lV#i_\U.ek/Um~&siIwyRpEǐgK' 7T]zyJ䆲@H&@BH2I]#iAp_!x(5 ~މωLG0{4O]տd!yHU T%o B {DU,;?FfChp=lܲ}%W*b/BBTS5Qmmw% f.ȐWZE c6 漱f)HKg{sחj8\d|`xԾ;nfM)S UTS݉m(C;m@m[Q^GZSҘ %;0vr94NTQO1,<mdRǷю2n%g⤬:Lג7+!G>4/:D"NKJ]˅59T]փE[+OG8D;z5h u }Zw::?jsIcEB#d3 @vM%9< R"\%|躆XmOpRahWPm12bo!X KYi.4YeHAK72D'uJiwAM Z#7]p{*cI FdVe2i4iB;I{22_OyTL R.AޑGs8Eח1ޮbOxu@^=rWD8 PL פVlj R*Gc?7d]RSWh@ػu&qsS[ZXrbO^ wV^\38m"0݊12Śhsw>'!_xu" 0Io .3Љ\d@!k@ rD>A,HƑ u!#rx?ch}$$?>q{Vps/5@ Ō a 爆uGfIW hRZ-xm~)q?sBFz@i&>~"LildDDG>hno)݅;$Syhj4Q dcM}H}jAI:.Z;{^^&).e=.xӴdy` dS#ˏ>L KfҚҭ=]xEe/m?Wdj)BΧ ԟ-r P ܕGu D6`Ӭ9 J&[l+)@ TO5fIۮ] ~ط8ኝƌ7ԅa_;Nlt)z0į[ڈ;Ukd\rb6q>)tQ%tt[2g$KPSg1Dʨ`r$ոqTȽ2/='d]0v_e' B^xМSm_!4*‰>NphL .XhKTC]McXѮcl{_Og$ܦ\~/.9Ӽ cpK"_UvvAJ Z|PJG{3joKʽJ17~tC`g,, Gr}co~ z<[B~_=hK >$QRO8i">>.Wn5""Heaeɯ/[J i!M᰽ڊ_ܬPҕ׉+3{Ѡ=dMb/LW\̇5h# %Qv:S/_~ c%ci]Xo/f=|ڭi&"6bGu"sCtA7O|zխk{CXk= pk"hR(3IX,ΣR/rx Ie.x'=?uW na㛹fuFZsW5̀FPԭw^rx+ϮO *  EV"~St+xaG\&ERBW}(̱d*`jwS܏u"%XO?[qHtfR^4Uڅ0^2ڂadĿ*Hn nf2_ܚ V v֢ M+2xPZ>pZaBM]VmBKZ8gݪqZ@65&Z jΖgI qK6Xih\5#HM(v&]5uΡ_ҜQF _ _A{0ߍ3T}3.1g\6l L iJSb,/$;i|(4(o%cd6?wRn%igy #_!uuv>_ }Xx Ӝd>J9PiipZ{(cO;ԦtY'SFv;UDDrO)|⩾r ‘bY{Lxmz% СpNT6xȠotXĻ^c-$sid<3kˇklX:XԺx{᳍o,7OC&"Ӥ0%]-`R5g ۊ*DO:\ 67$*w%c t|Ndp~764u.4;/ l)vM3ܐ? e$ c:@KuppEsB(\\60d!}oamYH?64 BUdΧZ aS@9-.b]ZPj o1Ǔ\ȶ5jSG~ Xÿ1nZ|16z}gΤ{A i)x亍@RBk E yTx2qG&E7*t@k5ڤCC@GNܒ@jtoH`!cc$=nP/@v'IR0x_0#tEX$wfJNXh.кh ,AıGAֻV5LX!B,tETz_FɚonZƯkvF= ?18M`J= d9\3jXꈒ8CȮU`RR30M_Ӗ$'Ė*EC 7a]Q,8[^GL.$&CUѧA*u)%| mdºm3Z}V<_k%ꋑa?,qѢ`ved罔;`+AhKW,WM좄 i@4kO %R?V(W 4d>]϶(cX>@KK-/_n36:6BhͻRLϭSض|TGe̿& m ^ -Q1 +~Qt5 a, B*: CF*ũicb?QK)",Bk(ytwƄ%2bk+.! ‹W P8,-j7*XcڱPFp)f 5X}|1(6;7PCהԕq}Ör"\ א/:[ry츊y ,ajNE}t@+0:4-9^ٰ2b AR8If:)н_,x D2 L2?q<+lFm|Vk1 q1r{B={=t'gjo7mnNy6àZϵA'\s!MoTBjed^/vDS ݷ9%kRwJXuHdJҀ vjZbr'yuznALws'u9 m#ΖT+v҉, ŬICakMkTQkѻ;q|I$ج>q^y6,ӇW͠Ɠn1<e}6dnJ2ut r_>L(fͿF7# Qh,85C0{Kӄ'Z.DRDXuxf%ݔ.9+x6EI,XڞHLH<(^s`qچi=1*"b<]6T!.qD60[ Kq: &_I~ gO'A!k, ='*`%ܶJ]"|D[@:j8QGVi[=B'!p&ڶou45 Hߙ'6:)s/J shToP~2cC?JXNn)- .RhEIzhme;<E6L?YZX<_N'ꣳ;UC7c"Ew )-2bGFrn/z7, $El21F#֑gyΨpig6ϵr"ԇ q+kY(J=5Bex;'J(UTgӬ&LIpbFZl( Oo@Ec Ph@ݎC CҴ,2$f$U&TSfΏpmN`&@ ` .A>f vX7f]( 8H/@CAZ &m| F1_^}1n"Uq4,o>z NH!I_Ud\#xAC^/_sY#7$r#jEm#I%V1Oُ-O29)eo2P.0ۭtޝ%o2gBp^2(<.Yt yWVν1F%avзzWE4e,L;Cy7\{$g,I!~T˰5.afS]SZ,V{^.bbpyCiOB#4/2Z)A;FOx׀l7jT D(jуKB4 R{ˆصu5ܚ_}T_}.fjO}]MSx붑YFmN\0 )~kb݋mMUA%xmADOtJ>xP6șWyH=kUDel6~LSHD?WW7eZ +L3",;JVt2KCTM H-(w 75& I7{}QUՁUFm}U?\qlK=UFM[dۨb2wfi :.NV$ZH"ɿ-N~(4rDLVu{;2M?Z5`bk q˘"()Ak:j Q6em/_ <3|gaZPW%6b0f8Zq͙ҔlWp9qZsjIr)Rkdzp5f 73e-k}#srwi\(:,PEG衔&k4^5,:[G sBs]r(ɢ9K];tc.a0kF#eP1 Fjͅg^uj"+;˚̶CTIFiljDwT.>dj+(V۷ 4X Y3Q2s'H4-Qpty##!No} Lp[=ƒʁ0YZh`T^BTy_q!#Z"u$¬EdɀMW x0.ż4ܙ|tX:Ht{fl~8}r @(]7^ow8J[6>#*)YW|rU^> 15E`t-vgJ~`Jz1ֈ_iNd9 %/4'W(ԇD^q5;,m^h~( !|kPKeX߅omdzm- x T݉e2FhS.qT/VM׷wF! L珓^d]N1=/ڨ)Q-CZjRXb8 /@8f}}vv6\W3@~rq.lb$JW?JC;kzM"(_ԺS:I"ZNFKRtO☫_:S4,xDݰ"V%QQ9q6qK0twd`_RCbmKꏗp6)bo?.ZZ7 :/T=#gaKGxC&Dh~DnƸKPg;d刎䳌 H"Ej{H .ZА+/CA|A6Hp?-;Ι#"ce%i #6J]z(DwV"]~2kǖ9Ū3l#z /Tv;67Y>YhCñjL,5.|*,0YHY0s@`mǜF @bOtm]܌n^VfcI}_^Mm5.v{N1vSjX/RF0Xm z7O /w,{Bܔ,;r:UGdF]~V(p!7E>u=nY^6hr]T)hPbɮF0Ig ӳ58f_`F2X %x9l<){sZi ;~.l JNvv)Nge4>XL(~//:W3 )Pj.Q00Y6JӃF`/G]VxLZ * [%#d]=&\@&@]V_@H #(zDSw rDPb*LXpm}+"|onf/HP>|}e?heSTpy*ܕ0}@@T  -xjSc_%e.>cY+WEfGJ+hA1k%<j?vm@G{B.1&I2ka*>u"hOvbi}4]z^ǩ,sq aНCm]M]dVF364\#kuh4}z=VV\ie9 NțRP'G%6$Cm\Kx͋-}x8Ů혉ߝOshFː$.Dۀ_V8txœQU=O?}ș#8/yM_zo0'nOB^"8Jn]9`p:jhD>t-\M]lavf*3˳00Y˛5L3(K19P<4$1 /M};atf\C8A+޽7!2LHO ۸Nȡ;? Y]A7/P$3q=31p$׮6pa^+װ$` Cqt16xʷP㎥Yw9~-UDc:+VXAa5L$yX6hǃ N Rؿx3d%~^CcqE^qR\pv#f['V$U5fTz+Rd[ql>X"4$cZ]6iu8nq" ` zR ͜ U[w$8a?\_j9v ;W;,X.wo; "ݣW\B4L1+,r >Zo؟쏞ŪhdoțD:!k#|5g*+bRQjyQZ9xEG)KK81"RL@GiG VrJq*Ox\Xj >UVWtƕdGPea.W-U=JF{"71;% IXmqXG,DzxАë oSCؖIJP/&4ugl9"x%Bzz|0QLUO'Vt.Jrl!{trb(A^٨C"ـ"rqMS_֜ʇK76?=:e f%5eowC8jι'02q;_bc]_" }2':V9~#lnUI+}rH4w) ]()j`=ӔZlo%(A5X 9`lū4Dy;>Aз MCCQ YjC\- GFll ȓ.9B}d6Z7 VQ>-Y8 ,ϰ<]_8 MNQ-_&,&*]b@@g1"=Fc쿒x7Kl-a%QOV*| M=~Eta\vp>)h~E} F0[;) $' IXnWC(EPDgZSv%jN6>eOx4±/3YZpGM[<i/5!.BgQ :RVwrߩڐOqs#T}) +p.wDtU#Hk$1p:S*|o[\>0Z7}J;F[A6(c!`>i[]7-Y]r&* 5>tF86ZBш!*t#3.Q񞰁ցt{ߑzBi 7)+/aN@)+:^3P(ɍkbƷ7)%sTJ-~"妞bnaN#bL50ڔ2>RBFLQ "GI-*: } zifOHȝ΂_Xy:ϻ<$x *8T|f(Ǖ2[uEE0q}ab1NN7Sdh7붣\߆_8UیI?7|S!Ƒ5]%O0`/+!VSpB"[& [(#6XC~f^K0nagɫWnklKu6^"TDG! b\61y@(lM~zSD]kalP+ ïYxKk I>7С D/k-%LHX9VCs71{-.ERSbf~9+$SCGQ$ No:2WNpPgz=|ZˇN;q="z fPGw朥K.0 &WQn|FU6>Vie摣ɬO A[D͟xLvoW60|=QܣzO8@vPAE{ ^R)^W F>BV8RݷS|S\r}"Z7JdJ2OJdkR\f+S#uCrbꐈAii `Vi 8S_bYM ȵRпܙ{pab) &BY?$űQQSnfaRϟ'K.>[8 >s Z QttdZFC|*í af4I0jT'cH;e9 |,H/D| C`홋za#.>`+MDquR2PU@uzj||йT& !!#Ro9|J bOs Yѐb f`@qѡ@ؘNJ EQ\l-ArOF!eQ4rTErd/:}8}Q$ޣU1KDv8 M gjwb&d7渚IueM~dFd{p,uSZ pmgY뙒 friJs㍊}9 +=pqlBDH;l6οl:_w\nJ;WYQRq;:3-t-ˎ;HMzAԊqzj3v^fv p6(AC4A6TQ`Ee0}[R97!Nҗ^1f'7e-v h j,!*Kq; Hz-Xi1 g-D0*Pgu{l^vDQS] y4[mRsk%N"TѶzMT: `7q"8`:R1Ie;Om$?/-P}:h-G id+S]. -ҵqO' P p$3֪;Ƥ^eǎ7`]ɯXymc1䠷ꈟj& ۡW +_Ah  +pWh& 'twQ1%3W ($ 5]+19p_kDy]!݀цp솫pݙ^}%nbSnTtW.iB+BKk+z2Z>TsSlar L7mRGbxxœ*G,QO<{E;?Nܛau[eߤD:_ ^>>&\FD5iקrdi;Lp&LQ0ɞ :;]DA/8oWǟ=+л l)nxJ댎e,qP^(dpP9}?p]^PM=|Q YX&6Gcob^)=Ya P *jRGןu'D")J; m5; >Qz(l?e DgcqNLG=^WVPNAfn&uxZtN|9`r ]aڡz t]vmZ1W,#Yv^kk>} z W]w#%vA31M%e ZVDТ{=̞+pdp.**܈zqk|OڡzB%pOlޮFQI n LdW%F(Dȕ:d)ˍD܍NAXo잢!!O5(c%Zu=q{*}NXH-Ћ;Mci"/}P@'/rdآ }eN/a<ӶT85cp>#LwF 2rٻ.rP9m#d(#W.]7*w dC'<>-p`&{`^*nFg.c!VTsZqڶ`ՀSr6Yl<# F<#Nh&8yRpRIO:aWЦnjdѓe0AJTC?QoC46:vKȡHs;/Xː;z 5q[q.bIK.1]QntP65O$OBϒ mk՞AzCmi;gv:+Yay*[!ar)@\9:ibDP`,t2p<3{)?(MI tF!TE7:|x ^Lܦe`h[_ KPr3MPWitR;g.l:hA8Ba!8-ی,c|Ϥ]H'߹0fsD|ho ^VOSj'e+Yȭw԰oV+j ǽ鄝_B[g+J)e 1Ӥ ŁaDH)/qn;lH3Ǜc R  IR3:D념Vm! M>*BujzTdFבv_lSa=CM`&.f_ʩ"E"V=Wش]p$%Xs;CU7#ucY-.@5PǯJ{KnE%G P 4ٞpk͗>~:¼u#geMGДPK*(oRfc}Jx/tF4c?m!+*\0dV1$Z3=jT%Q2o W` {^Ԥ\wgns'=!DX>^qOl+ 6ĆA-,vpXMa8 Hg#plY< x&j_iZ><Fl V_*Os%<m&>CK@st0HC a~,)7Q&IHqYq C2|=Pư-#ᰚ_0j΅+'ɟ{L͍u6֌;_[iR &:B)Q9腝]ujTg <+ɠzaC_MZ{=ijA:ba63z5!#F17E#`8=Ux'D> {}G5&f`Z졁:j[x#~b mh^+ |tRs{$dRK}v5c؀Ҳ';YP0 )rV?u ſSKC/]Bf\`3Cݨºjڤks~ewkurGmRR4gc:MR9NBҠڏHCXdߠ`Q3=tp6^$Ԇ6;E=v8ƖjFt2]{%fC;~Ѫ)嶓KC狱ql,cRBV{ݤE}pK_QbSM^d~p/4?VÖUoB]n!†mqVYb>$>WnY*~ z=*9lӈ^wj$i 2>YCj7hh’~ *keg xo.#2sXUK3 {*oPoN93ȵ8)4Wv$!pF`16b,f:YЈ/TCB΂)Rc@T|!Fwc"M5MZS'>&CzNM&tPicz05esD4؄Ql7B\@Fc\N{@v˜gƼĆXa?C .ٺ'_͌PK$٣b\6(} &މ4\4WW0XJ^Y :ٲ|U B̽ 0[Q[F@MӋNܙR˱FxG>F}%|k6O@$@`^I޹Wtsܽq-9ԴL+:A$zl=Mabti{@|"%hmfp[~Jcfd#4i7Q'd[<[ .C]1 Mǟؑd1jRm1H&8;*N YC5G&]gwXi"6 c7G{̶2ڴVN[HecjTS/98D] E$v wz Y&d ! X)P,ܛ"c#^$ hg7 =I'YYO-dumӔ%rČ@Ep*--ϻr8$h"=3RDܧ)G y:W>B1KZBirޥo{ rpX;*!X9;rĺ#ۗKoL:ĆO{ \hlԤԶWPɘbIj!evsJix49Z۬`%{@B|SHOIu'Is4VϰHc,'mڋKeF1e",]}^E#6JOklR4E) ߕ6kX');6uakh0cv|{Df~`{ٹ-"$輊tY <3w'6x ]:(Eơv0+`ȽM E4RH+be $OB˓rѩnupIgBf\/zZNɢ#Ls`=xZWpPSp0c-YÝ|B'RgNe3j]>a{\E*~3vsQP0[<`{x.8΅5W³I &EUs6(#^4f@$.kfp׵! mXFeVF%jo^I g1*s__߅6߈oTضj>0 ϒ׌[$(5|] (",c'laAZV@F+VŰ+VȒJLE _ fu=YijhmM@-NjweFlϴd_2%&M؂>esEu^xmTEZx4.>>b;Lm92hWvSsmr D*x4Bѥ2@E P{RslKgko^ Qa8s=Dï$xoto1d80{9]Ī|g=] zgha2Μ[{gZt>ͥG xbmrCCThRB\X&um #!&y& ˂hy[5#.tbw;i6Dmy +#BxI8B}V::ݫcz, sڝLh h(o?t׋Tf%04>h!1RØD '9? aE5I8#ggLAbanm˜CVbI~\EΫúԻ# s j25#(/cNvh%Bq9 FSD-x*2\HO6ӗ<ȼlZt=|:5սhMrV6c?dF\ƈkY?#z3 Lw+xO*hdxo"̆{k@CDGM6w֊3mr"hygϣs aGEI3L~ RSQ S-Wqco *"1ŞDb\RG1ZWå<7~sxyav [ܷGȆչS_Ba&5tZiJjS?ynqyorIt{P^׏hm KNF.CMW]V˶$bF9V8&/+Z#"kEiKI "1vRlHN# b@ ?oHj@@AmPŅQnsmRKa13_o_vϲy:9\oQ11hHU̘Џ HUaݮEm<}~ݿ錣, fxq?y*yaձB_ob^ӆ$SI2:'6tf4&UY T?<5nO *6ߴo\7 Fo7@ 07ƓtOjDijOɝ?uLtN>%Qa7UģrB~S4 8V8vf.j%F+hW_W}@g}j߅W퇽`Z,~K^$ڿVPoJ"_2?bΓ9pu2\hr0)#g/Z F"7©ۘtl}bÌ[#{(UȇUE*VNwhըv4)(} Zwbng}0ç(؊r?K#[aX8?xP[ZQk-4㪽 Hg`K_w+iZ!3[0N8aw8݇q159x$nRZLbID^ыR윞[nxes04T$TLWY(BM4 `pg)) }eۚ rE]s&26`HyqUkl /ƙ4v@D`!0AK, ?2--{qFC# #]^@xJYڪ11 fd ~cыfϮ'|$xH~mI@d7~Zjй_K:Ĵˮ/1Suu8:~:5rD)N:iT{"ڊP>{bޚ* AQ?\N57Q YW gnl:ձ/, gqX?]IЋ𘝄s`ex-kH@NԭML`@s-Y]VC AdԐݨcBBA ʹPH8u?b2L;L *v06P_25ȤZVGwn&V;EO:*EQV7ʪ cɝ2 < g~NF˻4|} e W8$4i8$ .35&aB0Kiʐ!*1_ۛ"KJ^@~h0$[Cgj=5^ 1*,~?ҋ"I[zDCq-`0'SIL9(e|y1a[ =gIń`G6[Ox sh"Iڞ N2׈I2ʉ ksbEݒs"+Wsl=be)8dpnYF&cxz_JDomê7|"=,Tp@(kD,UX<#8 Kp=^٥Ad; N"…zq 0{"m%J%+j~S8!O,#x'/cf+A4z3-FCxߏYhG,rs\VX#n l+? ڎ:D:xkH:s}:q|k8JVBٙsoz 2.]\Y]F BB~Hpʹf7`UCtfhIlwjY#}=Ңk^zl!5ƸMj2z؈Rm(ؿS,Hu fu>Z4dT] uނZGcHDH -o2qqih534L+\Ń/yؿn՜F0 [M<Nvߦ J,ZO$&Ond4kyMhpV_թEGk4skX q3#xɇCMS;vfp>,ee6t8\Ug|3#݉DM{x 7YFv3:ϋ$R];2ip`r>b$KՍ!'dˮ [+$#l圚' r5-)7C5Y Z›/UYg?.dG/3 BWH{?$+*q6p/4]glKe:X!([8>JiPNCk>6-bQttn%l<*=ESlkSh#{): B hE_Ei  )UZrK+yxf.3UI"AufԱ@tiOe1ivM╓aRXfg?El3f^ް7ͽ:SUdۙj,QK?Xb)>AvAc#hG +qJSr9k(-bv먀 sz ~oi%pXsn@t>U۫cR4#k`gl"QRnكwAt-ĥ1&&{IU~z")r{Άe[ ԘU4\BhwJ9 Cjhl\M($wfiU 5('˙XX!&<}DOyT}㵺"[^]kUuȳ?[^^&֐<ĺ!K/ƽ{D&E]'iLW02mc`řtc?(ae{-yWgaemM2d_rj+]Yryn+f.J2`+)!z9"hRvZ+1gR CޔG-S\(X?o99,/x{pzT; )-k>Dqԏ7zd"a@iu`b :Ŕ*1Ѷ&,`o~O2bnPY&/>B(8E,aQ\NOk6U!wSnnakqWq얽^Z2<oK>`*a8Ev2Mۻ.[ )3-q Z!3SShY2,S%4|a}-OxU@{kxJjfIUHaX۠ HukTU8O.CPvE۴ӧ7`V*] rlE)|g֘XmBDbT౅Oq[1$r^#XC֐.C&ՍU#n'TY }Pi l R%XQ)+͡[ػ#BHsC\ϽۆRACdt!<8tb\ZJhָNNoͷTo `=T][Cǐ4D %#e—%g0A%K@ ZޤKo!\ @Gtk;gȻnGF0,_!{gEl#ͳX $Ξ i]4"#lI8L)Bj qjGE7m!b;![KܹXJ8+~cO)j7]-S۬8z9N:.C7ۜ^_02#R7-Afw# L%Y*D* haeϧWh"ֿ8dP2sSK^aD K S<`-;^UJ)'[h0;Wҩ@N,4.Ɋ VzippbYK9а& zL)N3@Y/4?,->ƞn}ا \˩MadkE[WLElrl,].~+l P΀${G@49*7Yky~ yVyZ7l֒tGiĜ! ;8S'yedTWhBʧ3}"貒"hVf0zÍc갩c-~:g~)jzާRzٿN^QK $1[(~b_#غ&`HYekov"O&2+3a4IA"IiR}STS(滭UN e# l]n]Gs9Na*okmi඿lq9vK!6ྞ\L7_HY.dj&eIh.g/3 9fx莌BUwxl!ZC~xq+3Qg'@MN -t`rsTR\Og^G%p9X1`bsƢ(kzp2msf0y.K ( w'gz Cbt]~kOc-u$#n/|yl6D}Rjd7]λAKL#UWT蚝9meuv(!baOqO&+S d*_yavH['*Z $a=mƣ ׄޠl,i+քX#w6f^nv)d1<: ߘ w1*4ҙoa ><]/EyJ脓-fK/ůRq;< ]i=ublkGw mQ<#jrAf%v1D89_66AwT& ._ *`@u+:5Z%#/QA oѵo]!id5Aa\9B9<2xş#wP28 Jt6c=]yebEOx!AFZ9^{'Uռ F]}O&?nW< P5C(%7PD#kҬby_n:?L2i߳]j#]fύR1w[E6kD櫯sϠ8_=jbxs\xXm[-8&ĝ`30(\8j6aV/Pljxf/%L#yKRS ‘/[c[!D*#Z|'8s4.خj-4}2b3Q~ S8nr<97GRcyCďa`Y;ȻTi'DmQ'gTEOdXRޒ>[Fu82 I}=Z(;89Vѭ$̎*; O([l%h6cjC|3;z|)b? _<%^6bT5EIзLgBLCV!0ytdr# e*vKK\kt_@ #ԄJ)?qEeJиt#yki}vyyq]ff&KaÚ$lrrv.!>-UlEC>3=.NVqP7fޘs-2olcUҕ<| Ӵ)rmKQ]73|.**\J0Po{&^e2,}((?;weLP1Z^:Msm_LPYT+ۘS4W]Iܨ7rXf0OöE4D^NQm#!ӂUNt[ rPSOOgVA>NXlۗoiGC=`uf} @pKyXVqx?3wdtA|kZ4 5{aєVy>c쩰܈r`?)S^iA|b@"ޝ2wH/};ik݂`q/"uXh;6Xq:SM(@(%׋7hHZm$'OȨ"a]{XH^%;K]RR*㌐VSA?gC(I/vDolƋx Z{TO;Yb7+*Պ;R(Sit"ʱ)} vz˷'U>`.g:C>ewM6)J"櫵G!ދ.%2QK%׏J}2vJ}a$6ԊU^[p=MU:GtJiZ LJ+xЭ$x+OJ)u%?G.E7!z,wPs+hs6"Ua$U1S11ol*Ɂ0&{I1^.:YHC[ܡ;*Q|nky.oWzbH͏g8 w ~z ^F>;uҼXx-/Qoj<VXqWl^`jI)a`wF=7R;±?#XbNWң2k O-1K{2X:_ݐ32""Q: ~m\nr~EM*$RB@@eH hzI=igÿHUas7,O`ihOFff?-mph L 8h5(FWQW'v1ڹE홑M1HI7: y55 Pz&sp#ϗ2]j{ ,NaW%f48;Y9d5K*/7݉3/e6sʂ+! al&'(UCU?{v5i 13NOOHlw6m-z NdeL?0 v ҫSzJ4C0PF }r`e}.rPOTٹU6c?ԅz1zЫchaocY wUӛ4Fq D!Dd̍êB/Q }wkG{#|P9aK7,Zp.m6mBixT1e=áY8\\4l![zΨi3h>2, T@"65pe>kur[HЀJ;E^G+$"+\ 79ڨ2I.ԩV:GjUZwEp.[9.7uc)L1mDU~99钓C*ŢC.PwV6 AQi/t ^[fK7LYVؾ{jE΅X3pͅ&GB**Mm[lz}a2)z:ۉ-b`5(AX+d IO2`PtD(4A 3xP=Am/lj!$cHK" Pʃ`>>zr TͺUv91hhGȾ %XwtKS*Qmx#P^%54Q&4fb^}9PJ6zo0qID 6g57.`cX\p0qi qMdq/m;!YzpɭPe8_,g%ٜ"-]x5I89V=-{#jəO ̍=WV!?;/jH`4]Cbc8|4R](qELGgd<̒x߿;;p& НW nZht+J#K򁟧K]H1>땩p"~ GvxGS4e^I}Sjh~Sd ׮"Dp_;7-;C)9[ r<rc}+H_/8}xد]&k&ߨ+O~0M2ޱPޛy|U.w*o<8w5 [L E\/ ZUp%wmvGL 4u45~aT#.*v/ Gk{uUmv1א W+W2a޿N ׬M1+mۜ[nݍ9j_n`4¾(0 ? ^$~ф/;PM8iƍq/o=J>KZ.] 3APk\hpN&gM?n .8-agQ{6}9i?^p "p0.&b5 61mW: kui԰l8xD!'={7zT4=}ja[U1h7i ԛF Jڧ$pDd !vy]6Jױ>Pml:G *v5^ZV{:HИܴ c\gح5!:)-wuq6z^ ޙŴ4OHP}MĎY&-:| h&dL(ki#¶Gküe}>Dڱ;4axXN<*2J𚈒멷RL쟋jD\ƴXM%D'*Jx^IK<^A@p):rI7,r#"!}-K[]CQFE!+"`G,g۲PGDfEqrg eF cR,O ژ;hY5Bgx>|yCg}PIx>S0Ĉmi"9dj\&[f>Tď2t 2IHt)eY$$#CfG{<pc)r],/o<⤵ͻ>X#ك.C͜[|O\O m !k  3%4Ul-ђXlK]%ibH AAϡj%֞UfH?涭~8bqdc 򔁊(n4>>MQYG?n/Yc+żBRq]J|Waի  XE-;ꥄG>sL1>k{3 P7[m9A4܄2$( %Pl T?u+,9L&p98RF҂2~2zW~oܘjL;39Τ@:J~Nj(Іw?*~2ކ}9mB5~pOУ\s@e? >ru*~Ÿ%('dz"+0M2)"%8AQi#MZEfG?fǝm)GFs\!m*c~}?2Y%ҶEE Ҹ3}PAhM[Q;IP>ԧͪmQ[kQ.plbnCo XDLyfzP<$Y6BY3/:j}R-B p\x,T]uL=^XLSRfx|eL;%deb{êX)Y#2Z@NreK5~NbKP&=kK[YrGޯ?A Mw =غCު̗s<\ue)TiD3.:8|H ޤ8YMGx Ye]3Ylzua/ X>;Y䡲rC zʃpFz45Q0 < z1iKj'=ٮM̏#-y%qKiAX)x8q姮H8)* )khej8n%xq'Li3X&4[ Ǽ&U-˯lma%vXҪ- mQTI8D8UF@٦ddSUSc+x6\OᓑNvۡNw})%gYz1w]幔FyX1Vx`97g>SF$P[?壽,js{v|D AK[l تH>߷@mԲji`P쇑K+cjt272 Qbbh `8qҘ5; {& ؓH$T EƉ5rÍQ(E,YK&I[/^?2]-U3D) J^& /_nR!Z,qdPۅM8F"ɗ!߆61 eV'×C/^bu2n N>ü_.0ddsnTJ|_sR{QflZwOcj!r?7zwM3ay$ KXC(Z7@4M 18!w K MLY>f.L$=%V[:`ad֟dp,Uv^?XlJ81ϼ3kBYit{pc~Q@MqAW* <"ZM:v <6qO}Rf~y7"c#TF+Q>hQCWJiZF T`,InetTFF}/W; s@8mQ $(Ybp.3(:݀J}\7́{#}2ؿL)Tfsh"G>P[aAȨ 'Y扱NgEwƠ'4o wkfPqAjI)]$nѱal:~u"c1]t]JCץtv¤[+J=jpG? ڔUZ3MMWN+2[IQg~Fumݒs =YZqpM~>1YwH){1Qԃy=T 劶uZkL~8U~QMJ.He1lT"$f~k1woI[ r=G.xn)or" >5X}aT 5=È#bNA#<ᬀ2ͻՠ]P9rT9GlF4 1k*'$Ѥڰa:NN"?&ᑢ~͑Ĝ\ Y (U<]PJ'c֐6Ȝ+7; AL zqGHLDr1lˋ5"f6G/6uNFyݨю1g<`pFay|=oe^@%aM}Ah5% ,@Y"3| e)(9p aliRd^)GEQ3"aJ6Bk&L+y1u]6kr d-Jdܵ:ߟxJy[{.P c5+ЅHHQ[x&j]lә"g}C|2 cD䖷N6k;;=_Hfp6U&jYq6$byَEOwZ_CcԠC!e7w4ig"Ia&t0(VZ D6ŨUD?CHw uㆼ23]Tmy|qӺ~hGBCUHHbj/s-|>j ]Dmz%"9-16\ ;0C\*ٸߛl`h$/j2۴ dmdۃMئ7E{#lO ,e Y)ۘGJEw(󤶩FQiXqޮ%mP].4ƪ$4D"vg5E?u1ʘ t ,Jyhq}1$AQ0]C!MNjMNR 2QNEgӐ0JډJ6w, pZpQe@>kqSx[KLPЏZ^,y߈Zl zPqd /$3S:O[1qcqQVjuÀ;T8R~J}{%"*8Od;tv{ܕ#&JK9' J"mU&иv=5M-sWc֓&b뚰*My晟[zVy G%".KrlEx& 2˲y -ro Qu&=RC*k126.ONJ0S+Hxץ`oH("XJKb·[!5]g95 %o/s!(Fl 19)qW`7;H@eedl-{coog⻮樂c8Sޓ}ugw|ǾV[ ҏknBo0',&bIau't/ §ThkqK"AþuJrv]̄ +zG8WS>fIuMٞPP4jLYgw }9نYىB]τSѼvbe^˾Ě0|%TԢ\tI;}3'ot2ym'|})qx~Rf`:E%K2 !3H|U,l]CuLCVRw% D [4\usytH5:)gPN7<+ SHr<|O"?Xt_mE%A0_P$ &#}#osR6)#:GG<ӝqW@! x[MB-R$޷tA5Uv+X=J梧IEDߠeqvQ3Uf x1MӋ<0=U/O^E~-":L`g-yv-Nb#u?ӶU+?ޏFnH$"Lp+M_/?Xg9-$CDŬ$6H K\d^w5vwm)21{{$,ఱàg kiMGqh: !P OUZhۊX4s hV*'{^$/bk{TUEW&|h2? Ptf'/Tbo+RdLùX*1t ] Ԟs3#?~<wmңZN;R8A͓\{kYc#ZS gO[d6i/~ilx%KЛeVm Omي+.2߱b RۊTfϿm/7Mzh m_9 + O_?%z%O9Py%2]~~(ɞֻv0Ǖ)׹_M&1L$\,MѨ`n~XL]jm)MUeA֨#WA-Egz eR^ӓ# پMsqXYoS%XYGAQiUttd_+BBT2M5$~nFi 3wҜWA;ŢZSE%ߋ_aaYhf_k:JErὒ:LAYE~zyydѹ>q'(3hsݪS=0kzOq׬wBm9Gm\ [\"=4RizJix죰8WH:x]r<%K%;ݐ?ն1j*;EVQc-E6AY!< q>EUe 1SG6׽]z%j):;꧚ɧ/ȟ82n9T+inͬ:ņKP;?RQTuR=m^Q*06LDƵo~ $o^T 7V;z !:kS?:Nw1,/$¶|M_VW@x3[DW0޻zhtʞ6tvIs,T";/ nKb OI?M]#qeJZ6.ndArM9TWj_|+ ,+=U5U?q!_"WM:. dY:R%TŨ1-OsZSshTӸLaГήT@b$x4NAlp lHI\r6 8rEP }VCRk{[)er|}"L!b-#p ~ :t> B Pk%q(BZE)P1^Ī]sqm$J"r sg P ۍ9vwW,ts]%: be"[8؁1݀=-Ȋ#@bPyIb~$ &yk!P* }Nf!0 ARŜDTZVX 5YޯZ]8D2@O7h$VqZh5zrŢkI\-1["`{\]AE~QM:a\Ti [lj0/540trq DRNH.pgR[`\nlb׫DeZ/pj 2K5#vyy; uѣg+\(~F_ ba @|)q(ymq-E_e'=t(:8VcRo|p`,c(K,}2-Qݮ 18/uvIU@W;-"^'F(S%o!~_ 4i\%]krM:si9킦l0V4BOŴCO=mF߿|@)HDenZ}0*ve;O\jlRkw#pD&%fG"69?K<@>lt}  +hUwI HqK47z'7Չ5╩J ^ɕ̼H2)/dWtgN|ҍ[S*BtA|s} 59#( 4r89Oo3X}l3 :O$dA@ykDE<~FzXŸ ;nJ2;~l<TMX7*f2C{q1xe qLBҡЗ(@9X>z3K?Dwؚs 5ar/TݼŎ036:_T,Vr^ eT@k3HwШcu BC!Yrv;oFo2 z ڪ?—ʾx$$-XRw?tmG5uzX"ctZ#; cպėA1Jr@ pG =DV8`0ΤQz\ fWBRa*# b㹙R JW_\gm %0-UVmh.o|úo~ JvyZZk fڮN2?>>GOT02 }f]5 ;DM Yp,?6:|%{Le&iڲ*!1>]Gxh4f͛LB<*riEdudlуR?1 .xu@1 j׃aҭ`iotwjag= ˜:4MܧvvB742$!O0u'&CX۞Zcd@?/TyFHM_DFM@P+8h{tSIo:&*@5:Jv*~zԨ>uv*=I}+ACncANeQk-ǻRGT4YPٿį'8UU0?v.ct?C&*@q^no[֟>c55աn_&вX̙8-QY<.H-y>@%$B7as`!hsAdS*NbCAKޘ#^V/{E ݍ.v1أ/z D)]_ ;1P\v􄕧1dH`FL'2$_dQ`&Lo-q6/rlO%*-R,4ʗ oB/Xٳ[Bzbob/>f-;UW*7/CG7)vf\{%jYJhLPaVj , JY~OJsVkk ,&\Q%:`&6Us/y}Љ3wD+%TaX|Č }6nxZϰߺ"K'>z8{06xiNͶ̒%LFبTZp@DԤ3}V/hŌ1ߛͨ#" br~7(a}T@]`x]7y:'tD혋fGEV80Z Gmwli n͚] +bb3Sos4![?^/7.D(* V):Y9gܣq~'F9&Xz^ft ܘP[(es'MvQichfޤvrג$GѬ}΍#iZ'4pǰ Дd]k'ˉIW7}U 1k u4oDFj9OJ~ d󓢻ba?"FN ҁ1 >89M\tYzyHFd{kx%6u4=FǡLCGm޵6&jH "숇78`V˄'}B5 TsAm(\)O8^WJ;D)I&B| C0EU4}䁟DYbA|$3٧ :Ѷ%kx 3) (KIGLo?`{xJcA$mq?(y; &UZ`BA};>iGSbmn찚Jtkj%왻Ԙ9B;o`'6) V um^YsLhO#`3S =xXN6gdJHrj#8oŅjWg1u Ư>JhYرs{P u&:n,lg~-.lbppc#`;V]36;IɄ\ @#l@ůkY "=Mǥ-WY6[oZx^4yi <"R!1v/փA]\@Bb ?ȟi^uOH$/XpЭq?՞ 6ͮT;J̒Hhj] 04&%X/sLAPA{{ E,!(#aBk2 7H7hg6sɘ Hɛj_#׹y7"щ"Ҹ^ТWyML۷{s67'?_j|9U{Al ~hWueȣzz3[bJPMB:զ]Q`MKBodDmKuQ_Wg'+xwr:2t $p-cۅH=lbh{u*B p`y4a#{ߌo լqk{}2YvrUFu^:q)GI<oSQ: q~&{Y e6tsYOꦱ$b>yJ<QKscf[Q;;ȈqYB> ' +\Ӻ$y*q?ӿO%XrA7`;:a%/2’I@!ׂ *| c7^|ָ\ިoЭx_6~?tA$+#le/>IAg[N}-(63g;g[s^h/ +IPh0, P0Sx3a+G+I?fVa`w~!4:hs`/_|&tj_GΕ%a051rx!WN~5U ;޷+hwq6Nj4?>?G;qKu{vн9O ~Y7Ȣ68rYE;|"`6զq, ro, nB"B٪cK.WC$2zAaAlw+7Q[|1LIL4ײeɥA cL~p"~mRnZg8D\!V&jW.NPiql4drlYHlBCc4AžG6juƉ  x韰ϠkÓriA6|ML{A0 X>a N۵\ sLJa4& vI@w/F8OC?@;˹7 kgSew¾E=o͇ _΍#t7w6q,&{֯|o]^]>;T'9j Nł", z^&Ѱ@f;[{~T1ԙ,JH5 W7Z]1q I{dKuyHH"cv*56o*]oBpaFȲTxZ$y h?U3f\YB8Zk_ eg MٛN~,O"Gc谏n!2׋ۢ5J̙KZƖC/F@U1!bdۚ}ULMzA4#'·=h'c՝d'_ol{s0m4Ʊ΋tk {'AIo-0²$?xz'6~B] W-"{q'#xal!#n͎O^xd T6e)BC?PQ4g6yJ(tȸJ'_X‘`y㉈ڊ֟HJ☁oahY1mJSYj=E<(DlZd91O,gG9 rTҥNv} tm%wŵ4ć<ekmhB^\Y1}j>!((矢NDZKjH.E;êiHVcmDqyVloɭuo/o?_(T?C? g4cSIP 2Nmiq H{Ҡ4n:Ý`=usuAC!cV "ZD>x :- C䈩*;pmKf#r} \?xV88?y!}dF3lY%Tj9'1i;cnᲟFFfi^Nl (ηQv_3!NN|ey:#p<5HW1?{ zU[>%Q@Y`r+-!~5сiف| an{)ҳm``d|t131Ih%I Q ط8kI5)0eҏYJǠ eḰIj &yEǡƔ젓V ɝYGU K詉}OuKxU4${|B<,W[m$]P9R>-V,h [}щƢGO nS-)m&m ?|2~݆%U~k#!l@,p?hhT豙(4y`Hm 22V9ٸbBDRߕtpћ/שe7}~{oYN8N2=/LN#}$M(Tѕ.;)qkط׶9GAk: 4Bcc a]lU8:X&&SVLA`5aLڴZ#5Z E9GPp&5>!Qr1Oid_T^$0@s8| 4슝hҖM/v?->KA1](G:wA$(Zݴ3q>$L {;2$}UP-,!X?lg"5m]yAMׄ?&C;0dx!GFi"R@;ϭ=͞rkUkTØkPzɓjBAIṼ4BqQduA R%Apki?!ˋ00 N @-zIm-!ʻ7iM1kHNvb7.I^hB|i_ #Eaj!nqCKK 7gI)vtspw<[2ll֊(T.\X";RͳflvA}=~Xk |W,6u~* _!H܌VP2Y0CneZ^XSԧ7rƙs4;[vµ44"m99,sPOFrPP\EbOVɊ>z9!@ S6s$_,1/O+<:Gjl3*-}s܂mS-i { tՒ,襪+35Y{[&pahE̎R0ΪՆ@P¯[t#.;',pƾ+7gcgo_B}ws!#66=LЗD<"Hcj0LlxiS[^,2W a]ĺ`Vqʂ6j@3RS" rJ1I'w³EȒmh"QUOX01SƻY3\V2f)o"Gb3dz`xoUNm{O/7B]E"JO1@0 W,7]H]?Vg& K.H#.>0T=C+qQ+|܏wԳGQKB(1mJmi<n'|YwlW1c”7Q\}4>}ggjH\%9,w hXV42g Àf_# iQK}է'ʻttB|QO ! ^b=5S8kAr?w)7r*:m+$2(RG4iL.Cz,.qF=N#Rד=k ^>cDebM A`vA0opiEW;tL*GA6_bfqnI^ H&D4zEibqkMvѴQLo=ZYď{}޽%38iRl鰣W9=ygl&%73d;/ЃZeImN{}/pu5u[ ILm?ڲ6F(MC7M{;U\6P^T9R} DhK qxP_רAd͍=[yȼz +mrJ=,[GM Oԓs"n}YyD){Q6<3jX.Dc1qEo6xyONF#!6jQ/h3Xj^һ>~YunA;p7FO`fSCc |7ldNU XF@X1Z Ă:6 a>6j Im4,BŵJ D#$1y;B5GTDZ)S<`x=`cY Շ$6rkqD Ӿ:8Yh$ߣnkpiar7ҚB1x 19XE VtFJST4*;ve4_DPENAglq\Gub;]4z 'bdG:Ř (Ze3JKS|ra;[gq2cFKh>%%a;މ6̓ q XL2ށ.QY;QoLw~}Dcd@sNo`?EǍp=fa V*I 344:/FZd gŘY~S,|x~Ybk2]WsRT?U.+SKfwKXv(dB]!2糃.WJA_E;E(M;~X,[dž)] {GAZ\@xhSy6ܗ@tB0/5͆f0r;ZLi@ԠJ'ݮ Ц]Ҩ1pb"˰6ms]^5Tzo#Jλ׬h{rr! M|ʞh/aH~JֺNXQB1*$dZRԯ&x"g0;1\wZa0XS髹X![kW56qΡwn&\6ܹ3w:;£A"s&78cQ&vio'\CO(}V9NyoYGT8-.mz{oIBxc/j7gj!y{:wf&x$C0-Z9x-+93 @/硯y0X Z.AHOO~4h]h&ɜ[km1cF|W+@-NodqA5XaT|9Bg6 VAP$j1laST:n] NPʶ\D==6H&SMi9&SiЕ)|S )?b6UɠFLNȄ)`fwdp f:H߶(J`< +!T[D j5ݥibq&gJ7>  dn% 'ꕈJ}[h/cS>63]!<`,Z)%FgaR|} ~fQ4pncZf[nix@1|m69~q4 t[~j2۲ ’%bɸ^ܴK U&N/ʼƛӑKꦎyl\@/XO#D;窊pЖp,Ҵ^w 'L#;20 ,h:n8Јo]!fFA ~Cy6hJ Tyܥi'} e -OLfDq! x3ó+7'ibe"ܸ >c|Amxo18< ?hP@ᑄ EVMФ)CiE:~XM` aJ wU=7ڹcl>a1:lIUUhU%Y%EE[r$}gLck*%ZHk_↉7>*4j7%p޿c2?kHFnxs0.j̇/ec@; m4}OQ{2j>mdƤj1q!ĀG%,H]L7Vi0pRj<ݾ:2~A:iPQ rj0Bz,Wl͇ jM~1Qz:;'<62[^l "_=Ĺ(YƃN6|)Uf7]:AIvTE$.Vnu.$F_'m\ -/39\<[QCZtGtE z`t`fU֩XTcifwxα'6>juz $LjP;'~$'r}  uׇ'a&:[#O Zo$w#!)Jd0:zy(p4IdÉ-ԅr4bbif >|xlZDm*rxNǩyu+2iz7m6BzmReU:! 38 >SEĝz([)e`o`8C1R `ŽHS I2 ÎuEddX t7yk 2J$6x< +nJk8(bn/]a*\vsZ8 Tɉ~ON8!ZyP$hBMw#껤UwL"PHՠ\;Gb,}'ɥw"P1Q%ū۳E>`k# ! 1M߹\Ca /^3q+f8V^qw<P jU,:-$vn 8]G D >@n$p(-7>8(_剕G͟oW23eSQk$-QT>QhrR '\&39z1q~k0!Ozo(|e@mM:nγ2]Aum&|<:4fT,b;A@OY\|kz|z/o<́)mu&T 38,C mJlKVq'wP?ՀIZbbA:PqU@TJsYEX4J=%h _"qjP>oԲIL1inxeM5~D#9œu J+jʪ|D8su!7~&8{,c/hbS#cP_OcG!wY]OH j ? hG{<[A G6= RG;Xz(_ qTVڕfu1ꦩݫwC\@NjY2ɔ"TA^U0=N]^zo`Á;Ə똥ÍYϥ޿&qѺ-qZ G`mELK1>" yTH"G6'yP߽$E|& Fݕ5JkJk2v*1/u9)2 P 2ne۪= =^ON5ldKe5eJ(gHxh  W'U|x]o)&gO ^2 {#PB~Z t }ޒ<+Òq%Bn+~jrODoB4e>)& Gh"M:BRtJȍXUӼr, ה 8*ˬfȈ/nwD1E;l_!a+ miF0*2U )C茽w"=,%eRsp qs%!y݄9Z{΅CpQ?oJ=*xjOE%[}mN-V2I5wᱨG޷_hV)hX!@wh" 9wOי?I5 ASS kv-psq?}-dhUXV(nk5((fLL55nG)\u3e2¯ ;Ju E@0?5%sqv.da;UHox{&J+ߪ\E}G7d[dE*`().'e˝8TڠV%s՞[oLT6(˕[ts^OUZUF-x ,1Y:yƊj8A> {V~2UUNWK)('9^g_px,;ZHk^>YLZhíEq huG0XKakszdiOX?R a_i#Tҙrh )cc5nR}l%FVp vRBpV5 c+穂G(oI" :#,]ac~wu̦@3J͔']\~㉯[o%UNkt89C@WNRWz &=*W AZ,qkWR*~հ"7ݣC(uG*Zm O|A>aHX,fhJeR/O[)l̉6"nLm$/^|bCPQdM^qS>Mkg[OHi~L |P?^,e_gUTqIZ` }t'':Vfe. 3lH?xe*f,B--*=q`Z#kyGe~~7ZMZ$ѶԾA.N]ncיjNa˗0%ؒ1pT5ljt} e{VB4!‘2o񌿣<<.v'i,nm}1"r$RNJVl'Kcئ`nΩIXL~{if}!-sq|:宓]ۣP1 d"J7SYӄ] pwȏk{}ØI~. (JC DdS~%݉ x]邰-}?q>^@ʌoB>{WBTH2_.K(Mw}ơms / 욽̤Qox:˭KvX9$3/~T6Y-}(ċܹ N%Z*gn{tZ42|;O,tjJ-ô3U3 Uq:`6 '׻JvX0p4\eFbˀ& ǓZuԟ.`,linaomS#˸>AYм@u&C@܊6h<Õr{y+t8h)C}_dO>ASJ+4NƤɈQGu)Lu_&kEWs. $ ~:&k6G W.UY_.YO. 4*D2c 9|Ys\ֈXgh1lڣi8bVև~Juu9/ħMږljSðJ7GسvU[0UAKq+RϢ<4QqB:|uSv@H'$N>ja=HwC0}~i;˶&axWL7;W|bW|sYE5/1zE)!'>sPVp,N*b6_R:]n\7=ݓ+$K1i+t,re7w\- [TއE-)!z d7O}J +NJ|pTɩv}V]=D [qA]%3T +hQto]XJ).&*-p0/IB_-SrG}?:SpOŤsS7DZtTfx#uC~ʼAj僨IڋGx@oçT'{85w#7Ʌ+.?T TQ1ݕƃ]%IƽGwgi~e/"MTK+bI$Yϖ 6Ф;dA(*8 @FE^} ܘ}aNrA|^v\ScgŤ '0LenFʗ3ͦ Vd}*1Z,05 ݲy3ZqVyA:K{Ǣvژ7@-8K؋2j] >̹P59onK=p6Aunhq[Z i2j@~#bUo0'kp]?z.AZh1A|mQ\+aR{>3tfje1lÑ,_ Bt;a }8ߡRMW846_3S}BQLtGA,FX%pn-T V IhO3xt4kdyPbtM9.wߕD9-GA0Uր2AZj:Đ2Ov@Gl}E.<szo9 {mSA&v0F1Bܲ4tpX:m;"/b0j |H=F,<3tBh传5^ȈPY)hDd%k?ѲK UlYkJvPa^;|mJ!<jCEq6B,!@ /Ĉ^SӯϽR/WBs<+ft.6oYY[ 1t-',}H4KY~|(y=LFLƱI~qm4Wv!g7 S;Y%x-FJޔڪzohc~'Sj03 m"5< d6я\VI7e(7,[ O$*YV(j೯+ԼRA=M,`+0\^%:aP%qɵֈm'\ƜR 0U+UJ)Oa~SjJ ;|>Y&}<papVB> &ǰe*yX\Rkqĩc} TBm^btrj ]u(r*[S/0_pHի\M#Y7{yR`ApV; dΥ&D_?]q}vrcAMoJwDB^܏;)?3qMl(j'.pPZ٘6+} _'n(A2[$2koJX@pI❘@85vyo2dZ)DZ^Sߒv/9LSom+#= as3 qr>^U .V8JΌzGy'2.qӨe)߾X+ރ&^DYxϣf z"LF5j@yCDƼFlL~#Ś _w`vHa;}[ZAi2W{0[Smbjdo:jw2FOzE_;]*ͅ>'w9M>4V RBt5oItԶ\7 ⩂';xirHD FK\C: a+MZeRT{f'biY;#`J%z%L8+-H I1Yd 3 )rU=gy8=Ȧx>qlj.r bb>7ZlpXmwC##{.a--([L-叫?:~.XSUBu=bR@\HI:zStߵdfj.'4xX9澜87bUņKt>gnB%IvvW[6F,Uq2. 6ڇ=TdfC-nf.;~㝭͑.N<sb#zFt3BMt~ja o r9[Qe&-TFkdi.$hFKUwQ48ɈR\9 eČٰ#= SM8GǾ@k|%$8l7_6B(nJ\`Δc$Jž@?TfG;yG)ܹHTbV-6]<ȡ=!s W HLi;~')P}Z*vN+kXZ Xn:D*{VYu# OBzٰ,,e@+B ̔,5 OSSX^4ksgivD!JGӱ€OaC;"iwZ[k38nN.I^0pbE 9CSk  9` 0$/4gFXxO!5Z%SPjTnu=y`֜zeMJh8eAop3;^dח LLkRs]Mq?FvyA g4J-3WE^_g?Pѽb'w_а Z ->vǚPsѻ4^Ea}Z7T$yC<x߭i-G3nJ)n堟bv^9Z۹~{䋪aMJ3cLeKJOt>\\nd[w961&տ+iP$Φ?6LBr^5S]=MY_/cΨr/hV؃D` i釼uhwld[؞10 ͞{ꍱ5THۑ"vTuߍFJ*G#T fuY9Tm<$dhd4Cы"+ˏV5 {Y,p&n{w6l~\'lm 8?lu-&FP˂G{jAjW6MS1buŸ+̩R=ޅE>4AS-wh.(UC|hhJC^LêavXG(s icnqYm_=bqu.HJ0Jċȼp1pjn3cQLکAﯹ8Κe>ʻ^ћr|~n/ X&{mA08TۺikmݫKh1r"1HN'īX@{oYw F S/&~Bo"ʲ>YP; [QB O9!_TJˑlƸ>"M tbggr5M*=ϔ׊kcjӁ񓯄wdY#J[U!W 32/Нբ㹍Q#3-[׈U`8˨wfWkoup/:DA$ ۈgKH̗di#2>Z-S)/ @_X[XGF-$鴱y@yMy!AqQLq m)pyPbh  cL;ǖ:>QVK b&b`T>TtБ˙xT:K)ff5O;pb`2%",ݍE\=l>?~[| !(]Ma^ ܏ႁj;LOQr"aY%3rPj;MQ IiĦMG%qj"TU$Ry$fq]I8oق>E5cIF@LD"rZaQ#蓻~g"'g'L3 7@^{ٚHRpқEi4X=8٠2P a}UBL1Tj3pzj HnݷѸ V.8[^r57 /;Zp ޑH%Ҳ|.G(vVy\o<@\=/ޔvVWj'k4ƇPI>dQg,ף$_'bBԒ.% 5LO}X_-OG#6e~QbP(io?;sWߔaHb=ǖ5hK` 򆕲QIRO!<-HN:7b\ xJs8 '_DWZ&(}?HKdbw^y {v"7{yIrYqo~Ԫi:Zy|t]j5o+'&o|])$K2݅N)[a$a,QK5vTcVQvɭq2:ee >rXۚ3&8^j7 !*e홆>C&{Рf Xw>w{Ih2ˌ%\ Zv#hU8"^|m@2| ]5&kA8`xq+LF"S:bLY6heBH1s3ee6`|Dž/C#@bxm4ߡV*! Ʀ}v=Ps||.L7a^KAn?2%υ ȨeYMw0JQR\kW_,N/Y23 ݁ȎbfvЏ#O^M3,v+AN9K4xc5~-EF|c KoP$:mS$/ vZΎ}h-À勝3(PZG5Us!6)ž> pEd r`ss4}:nS= l"U6^-M:GDZn|J@7r/rk<"C |f?k;FdhpL_ =TD/lŒkXoN`>yː`3\V@$=ach'R;ab JL^LAބ7dGg7Vt5.{qD6g8ԔY6ːelVɶ c|+菱@`^ #U e9 tvv׭-14_ 0DfҨ+Ϊ2cSMXj yU{Zvx(}KKsABdOPO?o,_g7ce$yÉEu @B˦czxtooOgQ)/H~n~gtu3i׬휘e*c 3bn[CajgFT/gs&ͩ$[VݧD3֛X {.; ⧟m{rKDz/- ?}ߐ8y2|T`asIC #wvo´?~A=KR5 w_.l9<#y?Gt+7̂|h)$璑\"@<%c?Lfu)?oswSmQ7=+~9fZ?x?(,U2~?TӔh慛с1kIU5w託i@L>ķ1B*{^IBr_=HҌ0rs]]7O-n6P䥒iBGtj l^fNi,˕iD?3- s*A O",]4֚reQ"kfWLe#e2&m).GTϭČ@h@Hv Eu>},qo6TBae{M?@߭y$~p{0;t`ͯ@ƋtFoDx`gPB~W ɄGW!r|pG[2H uH2FF^k亥L5q/٨|Z}[F aCQUDnJDnCrFܤ(s*Y 2j7]j;rH' '*oi qn=:U6u+x&\umt@B堆*SfxEfrC7Ak(7m$ѕ%ttSr=Ў1*h}W+,}7YlR|C6Z&jɔhԹ ^Nsk[! sq!1/pNax!6}P)7Q)x";FAݣpgW p O#dGO4`A(}oH}A 腍t\U~~0w"5=,boe$Kib`>(\D 2?%v|9JM|>mEFі1!w2D ?A}[}֞-GEǪYDf$m F '\l5:GV roÑC@ {`knc3Iz(4 A{ 4Y0j4ߟn]h[S%LoqJ'7tma.<=1ɆqWtaU!v(wb^a1u$"Nt&H|wD˭ZC*Wr` K&}hG!Z$Q.JC1{ol:5KU :.q$+u}_09laz &!X)XesDH#$ou+2)UHi5q[.(!X1]/3NyZVAhIZ =WgAy0]-xk!7AE +rĩU5u%$};ZJAPTZEw0u+$2ޠ:숈ĉԇ/ Xذְ€6E8մ'@:1aqWK*uo=Ӵ2,oURZ؆q ZH}D6;`Fd3!P̋JK `id<h9"Rey!(&wIS\پ]VH-TGVN{(!g=rRR\O /E?)W/lU qJyjЭAyl49q#H/YI-˸e\"c6Lb:k[^Z=؉"R5c-4_Ql[NwVv4M|p13[ؒ3m"ɻ#n^#z*xKsmVAavEqK1ۧ]v~ivju뛿i.b]Sq#Z? ~|Q0` ynҰ@w8w̠MkqDj6NS0XԔFʫXrCPi.>($">>g4"@q @"6GkB sGCƊwcĦ85BڌklH:|R#[NNkHm5SE Ǧ](56Bew Md ,yY?;9((܊t)m-LJNߨ$:5L6 ) ˓i= k|Dr0iTeCw?gs{0Bk,Ȁ`^gcUNZhH! #a-X}Ds[j__'d?"(DzrLѣHaZp{ 1p^+?#z4`A)Ơ7&Sk:jW bkHpф>c85U%88g+5_fƿ@lQa!ȠyT-/%Ś^L * g+c;NƶїH `q8b hD9l[2߁И\&-9O\RkpN+ 1hG#퐐o NgK \P9 ^2 o3 7Uu"WfM$[J/eQ$A : oy@KK2߸3Nr^(p6D76([Zu2ƈ9-DdaZ`<-BE н<}GUw (8dX c*Rc7_2%ǡmVE-%J:2'aTjVHa6tӗ,W,y}{P8bSsS=rIwZ~}67wixAe7E_oMAWz2.zfFX06k4Ӭ>z'  Z#\߱|4Tq%p\foD t־bϮ8B^C%4\ĭ%L9H-Z: b APOL@w@>ǫez(+i*6 fU,#0i4 h=T/n B≗ȘС4NIlܤؼ@MЯ /&]"5}mw.S{Vprn8NzBwFIn 9rDWrZϧV.@9 Tqy|,.EM#_ҐL>@*F8bA^$LԎ|&iEё+ACa^^ի vEyuHOQn?}QD/;LyA[[{uR]#&\AAAnxF\Hط dGϴ 8|| (2(LS?* =U;@v\ m̈7G \Ci?oK]}OGQ ]'Ҳ,ƌm!V0ʾI4{;Q#Ǒ)\:+vPm2dǕwƄq"; shMq~Hx<mV(ۛs ÃTۈH ^kC#piP&Z/M..to'0984+?(61fx{s!N\u4@)Nxц@*48KRRdbC662u 1fR"%-j\JcLdnu@HžybSs]cFΧ*Jó!ƝUoGc0f6P))]Xw1р L_7sB3ێOCl ]Sm}cԮ{ L4:I*utH>e{rA ^C Sש;c.!X!obYπK,]fԉ/BjnDk#'zߴ+숣 U!K4]yt υ|yV! C=+:bU$|g{ %oo$~~r6I!f[YCmuR&;w)H=GEp\tM:i2"ۇt C*8³u=g+ nʟ;+kg"Ј7v ^.LC'ZiEFQhd' /.Zr7~{l`; AUt,6p.!oq}泙zayi ^Sog"2T5zj"=ΏYs2-#?,oMᨙ6 ~b"]Ks~רepY^z[yʵ`I@}_UU zQv C.^aMM/yxC  !sr xH /'-O9nȤxe+=-sc x6^e*@c`;i4sp--lZT  "@_vUC<¦0KSy;3{n~ḝl߄|/f! ^ uGi4#*{Mݓ++sO0˼.LEGF(^rpDtP%9e%&nE<+}Ovd{vuA W8U#Ndvݱm>-Bq1ht54)Wn3B Ѷ`qn6Ph"ߥ,;g.uY0CSwm@k>q'9;>/VEXVt^Yj"e /VaS(#!|ؒ #ܞAM05e˂\9D[Efp QƂTҭ4dsD$t>@#Ҕݭ HN0`hzkVl˳YT׃.z8WS'.+DM]#zBNVs!/]O|YM; L$ ˸,]$ :P|1U\;INu< kN5r'oV˨(2\~*oS(jźW y<卛*"BޕѐY3* 8|<#qtƚyGG`њ!m!h/yb=̗B)1&U:(P@Ej#tlW{Jl݁n8E⵲)Usf1Z 3Bh]ZP WU+(,k.T%N9+$$lo#I$/,qLd3(-'VcIoH{w:?IV _ݻOefQHN W>L_ah66 ?O{8uG &>*ZKǭmBt qmN5n\Y ?.^ |1y3 3qpFq$DM{*A=*'1$"Yc/pb9ִ9U*WnjL1ٞ95!wfwohWtQޞUp$؉5w{x;ϼs׌r߅jMsQy=W~G բlOA>]I^03ي~VHm {qnTNjڙFnqx_#+ם,v|q{u/fJo'g~h}`v: Y^i,7W*YLHPR3T`ީ_5LNQSJ뙱h 51>](Wzr;1/kxI^;Y\ZS l/rSWb U5ojcg?ۍ,+Nr4oGf( -oAy)5~Y C֐ls0ޟP [?Ir6LR<{ho{6,j,qCӴL ܾhZGP#sL'^򶏌ـUq%0,`i`ȑ@u6%4 /Eni-w?V6-r4ġF$PCkj/w1x=Ny QGA1b4zhtQGt R#OeWb2}n#;CFٖ\5R㤁Y;q#[Ch($ E,§$dg:'qab 3e݁[%- g5{ʰBR䥪L{v GKr h2"Bl>)ںUҼbJ`,8EjW9p* ϔSX\fB~CF4D(, nM-|?]r`' /`ÂΧ_}uIECX[&) cf&otc~V<۹_LnF )[Q1 T)q 0fGz ڭ Hڙ8e//u* D\t"(VkZ@zS>"!98BpIr.&Ege@5?iŒgyjoOw!_ad*@'Q[궃7kKyqdMҊẗ́[$ H+K{d:] C}y; >$rx I8LtrMVZeyU6 \p:i ]dqxHHc̏dB+ri)=dwFN5 udW]9ħu~9O_Z0|a25gƪ k^:Q“B=ӤQ}1DqZGH~D#HҟuEA ~咮e HThbiyXNf\dES1H'B *"F4[C㉦n=+WV]&U *U8 je L~=;vH-U)tsq{4le)_F# /`{]Мt{[œ{䒺Wha.ʈf QC }#KbFtGC{t̋2 Opp{{Y::,V|ȋ&l&RvUձi*J"o*偤 tCQ G{9wx緛fx5Z 3Kp8v GZl'KBȶS )OL8w [ܨxX Ef| 3W$U(As Ітu4͉qG粣%s.>^m/G<Ы)8[:Фңҷ K9b?4Ur}= 4(@Wzp'kLfw qy[ | e;:ȠmwV4WqfxW+A7ю!'}=߈UDZGzITbOǪ+9[rpHM 4@|BtOfM &3 wBX2n].Xn<aa袳E&̺E~|洝;O08XF]+2v CܬmC[XozBKׯO5fQ8f A!~$(hXR鱝E.[jsWSxPe wqӒֶ} >ۯ {K$~Nh 2z ZF7xJ'Ib7?LXeߙs!TQ6Bq|9!:2I QK@MƷL8cM2]lPSb*W\ր砚0&jZ[̆j9.=cͮ#H!W:We'֚F81]\eK_'88kt q._~6IdnÓ,%DFZiPڵ:p7X|t#EX oӽLI27Z4uQ} ko&eTڒ.0AxRkn}g5w.3<>ȫ۷"85ɏL3h:3Ҳ={{}޲ޙϨN"b';t\?txS (r.^F~_ې0y'axj@Ti%%QKHG+Dl2:i&[K9=OL!r= +6$ސyKa\ OLN87[7iSUIQڡJXGF]V<8Xr舒nZЃAn oybST+!']_ bb*7 ==zmF5%iZ+X0Yy?CQ]L 9s)fd~w xVuɯFrm&F/7֦XiZo}tOU BSyбQt..@{ 0iʖb Ui5|١j3e ^U=ţJ.]˻u~y~t& ͷY0tw;8 (OPtL#[d&'ULvLJ#ᬄVo5PZ VYC-a O֛< gCw&$pSF!Um~=ٓh!tz}>!h~iXjp, Fkc+1[~(~ls%=O1&or+݇uj T*N5 QahGD$,7T5F"blTd1o<ȪF>FsTZ4$YRx?)[\SN堦yr}oC!;UbKv[(#m{f]=f i2>k߃D' )ւA5WZ4rfwi!ˡpdG2S1tħ(qC%zg0MJKBU )d ; +~Xc1(6ꙚV1'̺7?N)З1:F|H؞a1muM?^?mEZnyiplT-ջ/.Kt⛛>.bRj{95 EG"WI~%jX;.]>0ieMǮ .C gv#]o=k!H,\opkqD-}nw;=OqKDvY#U-vL~F;؇]x}.B>zϊߙU]Nv>Ti{pf}ۑy!"lNs`-ZM7^mhg\YziҜpPk땺v {c~ؓKׄshoEb%P9lt?OjFB\9-^@i9`ozXΥ|CZسq[2&%ܜ3Gm_ޗIxg hY>fѶd* #Nos8˖Uv99H{@L:wvaqRRV> 9)-?eit.PO~jhOY\NQ0!>3r@^~v0e} q0nZV36j5j^Z&Nwbb:F]\\}0t_U ͗* a`8G⸋1/Yv*4GBd{zWL{_QE!U8cЉvOٔBp4͵8B 夘Rtx/{liF Uv\!AA(f€(fQyTaS]%5X /ITVA~ ytZi>De*( Lۃ?9S+¡ u4G/;ṖUFv&5ƕ*`.33g^xY&#~Asi>ɐR!dS"YMH89uݽ#HpZ#1 Q6+"p"0ۀ[Z˵㧼SYA>:`ˠu|.O.)`G]@'jر8}$K JHHTxL=NIf:rFu'X:pSHapt'ȣ7}8 MW,' `=rz $W|1#c@HØ^=εnbbZU{7Psn"`qo6eo☞Dgz%02^W8v[dL@ܮn\lQ9>qɿ/?lbF]1YgTb(b J{|iTWu1Is-=v84b0'x8u{'ӈ62ByLSAY.;H 1OSqF6X YuoQ ,nlEZo\4kp9Ɣ}M[BgL-}娑&kYMnܨ.#Gucb7U$S &5r5.ʃkUV7i7[tz:_%5 ҿldl-bU#7{>Y*g +(6n蔬y %{Dߧ )I !02cM6i?bmwOi$|l6^0 Aq!y覐,NͩɬM%"4:lx+__۽c*lΟLn#[=t,w&]G0jsYh,BKOr2*#~nWC t㈻Y׮ a<If+^$B-ޓ 43^֘{%ʦDU{SKqX-qR vz}j*BP6Uj~, 8\8LL.l˘m,H|lڵGrҷ]hsu[SF9W+Wbr)_j7]վTeX(GBJS)uA;M ؑsi"CG<Эߢ:񌮱fsƯ¾2C9hmYsR#Q^# ]gHtDt)$NoLDv߃ƏăiwfS$~cs.jO%l˕}a!ÓWVȔqxG*jnz m~f^Myqygʝ&VE09u&glMLd*W3~CO&_ :EFOhFe{kʅ$ ghP6Z]ס8r: rAյ,15ņ!k_iH\{lMlMڱcn53nw>Q5v|8V)*O㡘eG\ϫIB*ؓZiRyI{/*/*3glBS%aw(O[ tW@&\8LvPfO旷.sK&&{Z(c-=T,[i>VZK-7&\ҸRa6 "ڕ9*[ ;)  ira%?F97V4 )k~ȚɛEj"c =Q@NDeu/2| z}Y[gdh-[}ɤmTBSi#oh4J}u\{3fpLY8C{yщ0'JW5|'CUE~E撣 pܧ,⎧%KFljӮ6oRMщ:-p 2Ru;Ά9eϮmo)_s~ LoSta "&ZΓXa#Y)(ۋ7v1vmg!(1S/ #+2&r?kȆH"Q"6o0:Nz?a&"~ BHR7rێ2Rwa4J=; _"IB4bBO8Ⱥ0eQJ]c,ĽgDEo<  -$Ke%Zmt\8s~/_z=kk%s$:YƬ)iJw5H~4Wt_S~,"%UyOEd!gUo|ǙywXN閹.N.؞ ;р@Xv/Qi=:A/?[}-h{E120cøye+ Ju Mc~@vj{#[I4sc~:qp'O؁8 ֤ 9wIDdg(#_!$(7MK?L}&~$ } IJ@Mܓ`\V Q@K#(z*u_'PET9<ՎeU ,CFefig V i}tpѝc"uW Ud7$RZ6[rYDY;g.b@Ĕ26vAJCGp-wnmІ)fߖE6F_LWyEֿ*'1j\WRegTR/=A + 7xߞfSލt0QSA  E"s8[ėws)tc%r ;+R1bŰ/黃j4f>4>š.l}b3R|7 aj]I4 }*A |Ǎ]~ Di{߹s65z/wjPr)sΞI Vzfn,$>ؤ6h~Qrġ̈QCFNu{kȑ!yU?jrC$e){1{`1Us+9U!5Cv8HCԣ92[PL=#XSJ%?)%8a% /=fE%NUhχ;ޅ7W[V6։bXD>#'O+fri'%CZc뱊;`rC6ezTff< 2ï93P#9 :1E8a6bzq/M #]Yw& A4U߲̒ nZ3\ո`WGK?ua}ֺPW"OŘ]KVa6ƌEBFkSE'HPH L2v16n5߆aW5-7_yo<⁝ͷ Q 8$]O(PaeNL3D\@CTnE-~G OȁnURF~`/s[oZ<3QdyJD-M} g=SORBݢdӃT :-y5͉yX7L٢ۄ3)`bpMU4lbaWx7=4)hzoeLgH&̿9c\:KU&6V ʥ|h+_R'ku-ИAt_#"zxbJBߑ<u4E@adS?[wÕ6`@E+ZGW!g7AdĿJ_=R羏BXP=iqjtq^(gqk`Lfn_ϒ9\Р<gQ;JjKU6CMoWV/pJR f+w? Va[;SwVmFàL2ya-;.(]~ &}ʶ[IH+ 8YAWJ8 ^ztvDLaq%abʯ/oe[9']xS^a5?Vjq|}}Jox[uS 0ɒPK?%G]̨LHt`Y]T)ukmfW$Lk-}߇d@m~̔+W 3ٚTI(:%k&bs $Y"9+BB Jo H B'bZjAN2Nhk~9E":Hs@P=BYNθ!a/fdA)9*4H|Sy3G=@:[2(%ޛJ[VXOE D#.HHs:DC !觯\][=e;|wzdzu Fk&/7z?Hk5׵e AW~!n/_hLo12G ˌKs~@A`t)Vu{H7{%h ☗QPAɸtzh_t V u #:ɾHn*D,A{ &yV0M9s-vh[a*Ctr3|u~\rS;ѱNve`&mҔm2 /͋*rH6EzHn Px:Il rO8`&N݆v:H]R#TsD},iRȣ.̊s{J9~? Y$r2fQ{H-*mjLY΋ue$iudd6Y+'kЖ֬@?ti#2гß9Ef L4ukT' O|eJy=t$ ~TrQ%,̡<L^: U,m@7?| B Uu֦ͣ:EڨBeTRm0BLgxmQK\(lOvť#Tg!mHbٯ #Ӊ@u&^(yųfCncRMu Lk9DXqJ8$sCuU Wyj a G!!;I.!aGp榭7S9ԨpU:Pvq|?gAhj+x>N*M+L1]]kK\W#ssY=C5{bV`6;mGTStZޟ|rr>+i9Esy=Q&EZUTݵ.ėO;jYpǹϱ̳Sg}^{U 0nҳ W>so4T9UK&Ziz(f\IZ)s=Y׍|O&62#%+ƥ]EeY6EX>5^eyniP u@k+֨Ⱦ4\ U(wd5pIRx ! =^Du RySf9:̡ZY N. \0'=Z 6 eIؾq6Z3TIZt6|R^r|1U= k&_[Ot*?|5aCcC1[Ulf~+coks rQ_<;S/ߘa3ɡD{FՐ#/~9Ä[!cTu5@2uNG"JHK8m6#6EooЊX Dn9ʄ|<)n:S P!ߣm'ku}BL. 1L5z`V %>w+Y&EȔə) ";~уߥ8+Ytœ'vνMWl(:몔oZM9e#p{t6luhzhg$mY0JO/ 5.D3iB/]blq_Vu ~+r\ߺ7|mJ Pp9F olVNynE$/>FD}ո ?S.tlYW Ps䕮xq FHKp> =:7YW-m[H5"2]%1 SA~dR^;!.jn|?ܼ™z"ׁ s]mbR֦m:x2N֏JV a$o$~,Hqv2[Ef~Q_U[͂Fd[hqwwT煋LvXu]\]{M6{tU,rsD-%.Z~4zg*ݦc0%U4(.mwkV|qvzҳDO=| F"=_KQףfƫi*=hU4=Wt[|DŽ>Ka9/cM)Ξz-ln1{)c3V |֒dO@XyC_>9mI\4X kEpoWdaZ͖)\ssW&SQ.+Dk1Ⱥ:},r^%&鐝j\ h&Ic7,vM#X q.+"T%<^28!g8W<;\ en+Rb:߽|3VE\yΈ($Ild%rxGRL#4b4!Ϧ,c;b?!xo̕.m nyUYwivLlB5ݒX%=#Ɯ/׼DY4f .=ww,=j__de2y}}*{4)-؜M7+<iͮZ.Jtb;J$FK֗VYo lպ*yl[[XɤVosf茿4H3t Mbbɲp}1 >r !CV8kMZh+H٫fߥC-\HZVŤ G J'fΊ}A* ~93rk|l:& )I}~IėOP }>HLi9R$^-HD1|(KTY1+O<0 陶ڡ?ZLҤqU x(wKF)Ip5z^ w串>z`al2,fN Bl)Z_QM}$'0"hD uxvr ?B-!栄/Kآqa"cNk4<\r6=̄4yzL>qB0hib:C/ASßC:Qs1b2@rD]d9gXO{avwV2s֒I!h#xи7=*~ sH.:z0/$-!?I3!bQ5:>)aTFU.2NW9.}=ٽVاa<;YZ}OOxr+X_X;~<-FjR:0kOOEsOE Lт~V~U`V }׍h~]v7g'G %R{;4Wsh3J׻Y6]q.4Z+A#8+JŐvZQ1;T$׎ OR +WbKd&&q У@\.0e\WQHq @4h)"Tdt/x܇p_; Y%9O;?QUiPF.vlkGPAQ瞕ISlDz$ˎbXwőu@1z"Ĝ ZQ j.NAOycZ Q5Wgk[fA"կwSO,)JA?xE< DF۟`Ͷ.BCe-gUx/T=zEj-Jـ@ :DXw8t T,IZ2/t |8:󔦋qT[mZ !> '%P=>a9c7誴g*D V!@t#P^j%mlY.Sj}pXyTn%7j7U~{Ԑ+ l;g5eP l<))7r; H^?UH'ȧ !EvnXPsp1nqNxj~cnq؂fsH0Gysg w^xAxbztB͞hue` ."XBgh=k?Ĩz_IiSokgN5 <8^n`B@UQ&LـS dUFijXE+'Pu["|Xc*s_=(#hhZib_ s/͍*EsWp'|+O߃ʼrLyJ^ar C>&oPu"mbi.S 1;[3^9芰v-.; TjnjK9zo(hjB(Sb+ 01.$uVv$,9}K;gHz /HIw^y .M%lvI ^: 9e]~ ,g^UTXM6}LoÎ*9b1$mL6dlbM^ʊ%@) [zѰ .?xq/y"F}WÙY5-A#,eA+@ ׺> gf䯎+ӎ)@Ad)Kj'Հ +3s9|31X>2P}DwRY᳖2 'ZEt.P}ݲ.ToūlCY-X9(AT9ރ)s郻iWmw~s&Aвզ&+ -fxMֆ(̧ ,>&^l[uhuأKrkB1 O2F3 9g[S  ĘtdhpB8AE O4xTǮ)x2fW-SkmF3ήes=Ps?S4|T_K<@,SQ1w=-Fd>B,@2@fA&kk y5IcQ !)8K Z]xK'D1Ȁ8)kU6݁ıӟ1r9# l4GrM0ȹ^E),|f_0uL 7̑S9[Gk.^pΪfU {Z,0ҰlyAX/;oJ jl6c @lc0$LV5gѠr]/HAU=a129!N͔ږo8r3MլDMFb|aPQǔ}35dnPHNȃk.ah8|ZIHdt흋ݟܝ=(0 dg(&1G˩ "{]~,¦fP1kCv}nE] XkHt9LtT31&|mYʀβZsYdž 1kgS ' ex> BYW<@' ^ ťvyqg߬q%u4E|ʽP,ɅΩ.i(GbSŅ@L ЇF[HKNP(hꤺs>ڟpO^GOSU5g˸)i1e^Ď7R- ~X%G$G)׹a,=oap\F<|KT`nGVO̍CTՀ1:b˩/EeD«7rOoHsmN ch`@I1WmZ@ fl9o7gXl {*Mj7vL kfe3X&1l/zZ|M l˺v#bm+"/j2H5x1 )W5Chz Dp tTJ}q87x)I*v&Q+1((7$j;>s".-Uk#/& V´^o}{i(y씱%`4:]@(*֗]fUɟJmf>`h/G ƭFLYn-=e0f݉m玔r wW[ Ųirj~r (uJXf683r<$mROP(XY` @mKtg  [ `rgev9`sL3VFDZ)heVYNr$/eZaY''uSft Y̨ءЎMkt|sw/VUU}Κ-' w"Lg.7ž\B vW1 khUaSs20^RrzQ@;^_ONSXE.  "vE=G;%c]Ђ9^| ƣ:"!K9P)@&Ykvk6騾$[R~P Q%D>Gلuy`降foM~˫I,d[\YTcxil&ՄuF6:ML++N{p-xwBϓˬ%@a2~p]-NMMF A%.3g>8j}-k7\$PtKWd3>ayBZ'B{|o*H"W7s:'U+gh]qNpP[DEY7DDa~O)u(=+G}\$cUhQ}*sLD׶w%@TK?(*K%z&͔-]CQ,?plm >ی oV.W.89N9w&Գc1yXeGt #t\f9EPltᯪZG9vbς[<:]A3Ȉ X-EBRiE<M+RJPm󱦦TS)9Nݳd?†ʘpCQiJO1-oBGP g}My8}I8<1ZC祪1|GmqO%-`i FfDQm5-tF@ue:?︂EyCY ҫB"M*:^rDCPmuBN|~)"M+@WlEBVœroVh ް_Hk%41B ֶ|P}-+AEX㧐fDDQًl;lף}ټn|гN -кG[ 7cAGD5 otޚ.~Wd-?"kt҂{ B;9 V wVQ.?{'?<8$KB:%fu~r ELCN>~wXa/oAa3#{>WY 5v $zH$Yq~+1406">J e߬ltl4-By,B U'Mէ2a*[TTI+Si\]r7$`D= GKNchƏ{dܹI؊cw3hF_s#05]$&mF; 4ް> CNb0;$lo<1_qxX3ǬZ |t eHe#)2aնJCdr=q~Bs3y1o&y!8BMe+qmn3u>5o;?, fB?6@vx3ܵp@T%L,ZRG %fY3{WW8"a3?\ & *v%m(] GR9OW\6.`"n2uR{EFu~JZI๩_D/\11t !iX#KlnQ66RzO V<̚`Wa=L'>sTG?ZP#:\ՑuKd4+Q@Tٸ0cIwM6h%\^,?l|IU>7 "%a}C)|Nv-t&!Qalգe"D]ږghxjݱ (H w O8ۻn;2t N,V1/jCтF{f78E)~„:-Esx0?Xva2wnN@bW\!Etl86ZO}}^!5EJ#}sΓyi{l !AzG/ft,9^?*]гSI"q2D; :^H#uN*hDZ6vݽqr8;%|҄>w0K9nA^is29tdWQw~ +G:іb]@0T|ٰcj)N=5ߐ1adzͣԺvj fZ@lTE[/a bIbi U \ΔOe`+T 8CՅt|6TËdw)"ߚ|9j]ፉv rtEmIL`BvsA|*Yl^O[@y p8gm̔ g,bl E-;UgrMJ!ѦSS%L@~rZzYs[܃L9҂Wiםzl-BzR^:`95J X. &{$5tl ).sq~a }7E%έ1.kz'v9^n޵bZt/] r2s8dS##J"'˃&AδY% (wc"$N1'8\wzoR.ߐxCXe.N{3EVr@dfM`N}XT{W#̠Mئ$Y~j it-;i٥93G+PxJfL`+X7{ÀHC'IPp#h 㽙ǐ]Wt*1 mȄ'[[%bLG2ח`4eǗ!iGÉ kҼA?d٠hP۲ŚAVm~]`$+!/L'_9y_Њ/}w"v &JrI׊~5v6'qT@ BXJ_um+yS^H2 T}X33d́wIupi?eZ}۲>3[NDmΟ't,V@f乛Bp8_\Q%{ye<K^ev/N̟иρO{`= wEpX'+4PBjKi"Bz'gC 6dZB2bLӞ}>:{t2P*a`M!5ܗa2Sg774HJ%%ODu;Rj+(~`zzXRm:Wը{Wn ZyNWh]^N݉Ўqm)Eط);Qܵn} Bz5(Smgs!wITE`+Bus &TB&@pQFfȵn4. MvȮbʼnun:-<)V=5۩B{[ viܮ3,sa6yNcT6"Ზ|Nԑi,1_ !pXTN*IKBcIT;72Ljk1ɔV ]@IWR7p)u Q3MSjɿMcҔ(s(4pePb3Wux oz/MXK7+X>6'[2 i1;"SḘ{w[>&q?2:#m hTjrE]='!25DDZкnP8h U%sMdILU.3HI"/8sP[̃Ob{s Ƴa.Ypѝ-4bn`şJ62P,h$ ,=Ŕ3WJ݃' \_C+HӨy\ZleN$su8Q(`Àmgk%( 5"lm9 \Gc-@ ԑf@<86r8 C~hv]z*Ag$~x}kFީkH-ij\ )W){!q>(ma[hm8܌!ۍ9^>,^ݲ@-6\5gGx<8MmwxLѹ10 7IꨞyN(x ]Ynw(|25י$Wsap{jyDIpݽ/0~ HFuq>d_Tݓ!U{܅X1|2f< * 0}Ap}}$)8Ԋ l"_ڹ?R|ִ%qat1 WdW-BӅ 1[~ΞoA S0J?b>]XW񕯓nñ1678xDJ.ruNԎoqZOKRTghN+ B9sn##CQ,N=ŊJZ K/wBU:K;ar~f㱲{[}llVxv: MZ7")s+ȭ,X2IUJM RG :HzXaR:f:):8))Դ|D*+n<0O%_ HMfi{sR*O͕[~U^"+6{6>p=.˱c:͝>E2&Sto'{+. e`]w` xe ` W)VP&9%-N.Ry' (Pլl,le6[RGPS+{h*$efBkBn1N1"^7mV)Ê)OibeHh295fhnJg Om' ˮ>];5xD׈g3JJoyl@= mZM TM.JL ‹O4VH/F P$į9[Q5nt2flP`HDM ͵os5cB4Fo ) \ı$v:ɬte_wYEIԞq.:EbDpXWS~<F| _=Vw޹Eݤ 9zĮ2RfݤBѓU?pH6!B$ZOf"˺ָr ~]eĂDHU/Uؕ|̧dr6{9}ϒ%LܐI6Hqs14Z,|&s'KvmD1daSlcf9`^FЊ^ $SB&j#u_%IVbfu,nTiDUY>4$Z> k_ElVIAX sYr,}10ရp&O[!+vɟUSXӉ/ F-?9 X᷻%o<ŭi.;y5e0Ь\A,c&FacދDF҂p<̛昬RA,EaI{&5;>:5uǖR E&Ɓ Pzmj(m&?|VфaMLAIFNm;tՌiYw!}IƸ!W{73o8NEҧ(휎ݤC<FUNFs9dXr* ?bAqA)Vn]ʳk&c jDe/SцAcoC-h۬xZݏ|1{`s nׇU`ei~ r`-++E~T +TWoo(Nq?uI!q罀*hrx-j& (z0IF⨼ז]bysgF/M?hd^\f]nuˀ\S@JmٽݔQ)@ש^w+?O_hcO[+Ӿ}H8wմl$eY,r$^*ԊgY}54׶Xn,DG_\%N+l62l漾 #ɮT߮p*vwxΡC{W"tUؔ0{ڄe7TB&7%T2&sҝru zk'W}P* Q\5B!1nǡXr[ށ)h4F .M<: ڨN-rv"~iP+4r;`*N+]=7Ek~C4Ug@!g(>7Q]98D Dt۩7ȸh*1SL|{J846/Ѹ4KP>'Y -ӡ$?uaѸrTыו$ ⳮ:m#G>CݦHy偲JψliXaЊ{@CZ b7.G`KĀםU~:aCp=jЏ/>^Cs{a7j^e/ƺAAu=2ǹyA/Uyý?PQ#*,7'mk%]XA'3EYN6}cL8_Y}pZV'MuM{r(ui;'bL.faqH8 BdR݀2",w=׵ʴ:R}e14,3`2]TøQFuR{Y~H̝̱{C/0c[EyMV 2iڅn^=џkµ3?)΢559z(  Jv^);4oY㄄^PxXx(2d,wPh 1eAݓz,& ZF'u`;2AU6ԂK_zh7,GhXN,*5WU@w1kd5C- 8 +[|z>g&jY)*<ԌV:qd7kG1JN3ZDgI1w?rXcGRߟNt/??`87<ӕo$"51[8cCy?o eqqbٿ7pr%VehʗȰ;{lҷ%C!^6R$Lb9ΥCۨ!8@Lup.vٛq";dC)293Z0Ѕ4{򺋐6kt N&s;$ y5߆h ,~$\U>߹qN]RVgŠ:Mr4: CI@J11+BgX3}XrS5sH{kQ|9]uhz~wUWscxJ0t.h8xC%ib,D̘u%$)s##mFasb`xҪW0"f2#m#q~x]%孴/^f\xҢ<>\d>l??j%5# ];y9 p0CG&U1"/ T E.&j<)Rnޗϊ61)s$3*M3^i=?O͟Rke-T&witjEM,w,gEj:xd*P&cl+? 7MW&z[LtPA}?>`(ae^"JTCJbbg }l,0$YmyyI -vt7Y-lrLڳ\TR!S%)'Q&aGUC4Rǔ;&H$õaW(EqY4ثMV[B+w8=XFp*qtɎrJ|}H#iP3"^fo•IpljA4 θ^JnnL;g)INM@5:23i'mܳ]8KnM8FuXJ]d7[I7b 9bR.>M;L <юP2hKP, |e4'քᢦU?T$3HVTAfK˻4Mn (jf29 Pɬe\{ƻrVJ@n}%yOVe1%5t\u"n';&%^.8p=n¹X'y k/hu _tݑ_l467GlR B:c3wrg¨Em)/Q($= thuϼ>ݤRW3E't3.Pq1Rs.["f$sR) _W*>`N [b~?}E"McJď ?3C|a3^W|`u^PrǜUN5b&X;y5`z2e44aO`2SI*" M.C$8E(9xԺ]9ɽL*C~44LC]C}>|-+$ѱV7Uz 69~U4Yub %~Ǝ{N+ݑ3S-7r˕<*B眕a+Y{{6:f;K8PDͰM|K ='x]B8,|&P_*yWCu'ԓBZw)N!$d}WFq|ch/egpX%hi=Ns%;EZ 3 9]dj{<e(Be>#\Xz@."* 8@e6΍aVl.nͅ](X?jujMЖ("œ: s(=ykhrY΋2=|ܪ#0 f|gڍF@VȤ! uT,?U' +vm oױ4Hr';(.TP@(^, ڥGN|/Jb2F -_QV - *wTäGqG292{һH AbqskC|;] K!}ma*f )΃:ru5^䦞 O~63bq x5#ށ}: q jFgOb+RAyIg :GsmsAw?^&]l7ݩ"`=ioNK.<cbL3U\ ڠl"ښ] !2*6W~U~zaf]֪?9?c-yxy;qYl[^:@dM,6ukrk? o42|hoF㕨p׽@Ǐc`d.>f oD2-Mjq %\*)hFb@x~vDf3HbT#é= wfρY´l+?0\m_@9m+Ѽlu_MUpY6!pX~Jq֖^܏-Hb!}WDZS{{)=k-K뭆V=aAP |Њ"RJ3.lP/:de]pЗ~#gmObU&![" o#XH[ZQ$%eT#I&Rē!`wV]9lILlTM<ɑYmW,,TC3_hhLy}H }T#AhI\t}n[E HĄ"k%dX`$K g[Fy{;nf(+ķImP$_ʣL;YmGKloOFUSQܩD e j4oNfHx̔^5jNIP7M+p$ypZMMٰP8Z+SS1:qnh&M[ۃIAڄ\lْPEFi#gA{Hk1}{B=[ d;u[ֺd3(yt&T"vP=+`ez򛐮˜> ^-3[*OumEy \ Uv2$zHi.p*rڛqα;\Fx-XyM׺\h1x#jZUOVL,M:rDri?Ѥz.B&ߪ%ӤK/ $׈7sǡB>ï&2B{kLf>F~9tR'tl لkc}}30m-^eَ; V>SYT>Q!+2KyL]L",q] r3Q;igm ~ Y:/7TER,ؕѧaIwN`(L/Z:R'8xlg,P)ǙRTa OS_l2%tWpӛ Gp~XJ.j<* {(Bb$xC\,Lw,51rό<%Ql%7)W) ˵:B4W-iw4̹ 4R~Zca=VC2tЄR:*C [Jp;g&-yY,pG?G??M9kbF "aSϥC5 'aR%SDK&+f O:tߞHae&:3MO|@Nr:Z' |@+fr8m.nkXm7apcbT@HԞcr5&7-4Ji =C-X?IXYhDD*Ր+ 9tᏴJKS%{q]H*xg|*2 'H6DfZPXJqQW tok*'̀E~8$L=q,MH *lݧ<6w=ZX8ޑ59C 郗K+P? PX.3ES>My~gaJ1ؽ{¥E&/Ùgrpo+*|P.Xh;g4is; zºՔfP0P 3Y8N F0WMwϼ'd&5y{Hg^^Qׅ4*,),*AA%ݲ~xԸӋ=vb:`;F0)?Rιrfط%N}MLB(p$݊2M͢I#\U5 ?y7ei@v霥EDgBzN̺:R^84#3B fy~ܭn9 P0#("2sTD$}d\!)/{\;_i0ɀ PvG~!EZc>cL;Мo&Ahbp:1q,W݆=Lv Gw ,!bDDOS+Xw\2M9>sauC-wV^,8PoL &#qR;@Woc0}zw5 UbIUZxh]u=1JfqpEd`|+C|A>@m~h$35\7ZK Ali~4.Z* {ٶrcL08{7\-X:[}~z1 N1C=1I0䂂hsʽ&ϛKD ͭ][/]̱"ԙ7I& $7۳497O-v{ll: oLUgZitB14*ԭi3Am~Juoy8 EI ̥,sEAJ׶FݵBZwW x5ǂb:I\: 2|.M5g`z$@~"be$w *:qF}h-s9,߾_?4XsӜ:~g҃ONa 7}䱎9OFz⥚ rAN [*▫x+ l:j|-naf€/*){~<UΪF0jBZ GpM/ol,TШh+- Jayl2C!mzH~_'RȻ:]fe2\p_axح'DUX\1CGt~XX}F^jmL'+ ha7>:F <)]*B%T=  fWBé^akU~ ՀxbrJrz:9~.˚>XIYrOL$ku55`Cyꢄ2X)d`&x$gib̟Z4UHP Zچk.de~{)nA;_})ӧ=;?K3a'Ln5zk.i-5/~W3]k71`6Yi3KDIf^!9jy,x}Z:Wgb*%MM3:?LXcDݛ-Fُ=."1a.ee$-1%`*ӵ%gUl;$Wx%se@uJ 9Lk!\=EUL2Ghi. ۜ;p~NёO")EQ$Ӳcp+8>mI.(.|P;J7""=]:0b+ 泥3,]E2Q\aӵ-Ju]hO}5u{P L)J gSSKsʑh@Ρ/jf_NZ~>bC/m EȰܲNs`>J K(IkaEzx/>7]Jg.uiorԲ?ReI\ !N皽;#HP.^D@eР@u8O $ "!R5MEg<>@Ö=)%g@"L >t !Un_kՂx{20Fkh4xh頡S3D2;?iB fe: <{Gr6W/F8U%쏂 :ɩ肵sdqHQQ "D.J wyK0:p׉? GNUk/m*I>!,-%|.k:]RVCu9 9'LW\^%)0fGQ.ɒ믩LgvbFܧČ{ukP-MiP­ͷ`c"FK*^—($Kaߺ)oDwPd<3#QE_w^g@ӂ=La54o]kA|ޗԌ^ݟ+g&8gNFVmDр Ӣ)p7i?T|Ԥt9AZ31~,X®iTw4P˧@:vo;q_$$XiPB_ !vSѩv,nѽ$q%ك"5Tkr&ƺȮ[jRkGPN*i8"hQw#<uSlߐ~'ɄMDDhk g-~K%?ekٲ"b/|z(v?(IP+K*yT9|i!mGstRB $ȪL8{cS4'_ ܌Rpdfw̦nW?VP8^I(Ɵ ÷)z/.mT]8MANnM[19wJn۶H99a(5 wqXo6WΡջD~)a& E24\UM:"[XB_O.v?UhRɐr0]E$8czŰ4+u3&ݍ'2xZj2y >5cMf ͜x)Bngm&hL[ȥˢ8惩-of4%־ژy[_P`fR. :%:mҮernѫcDZ@sS_V?LCtDԀPY[!`O]=6jfg?U\Ď].q-*@ ;`@ BP%֊:Cxp }G<,r*y<gAWr곕C|`Y-nHtu=鷡Ka1Tʲ܂YUUccbkY kX3QC*v'"9vuPc]$^&+P$~N_ I̔:5L/hg8!GZKDKaߵs)_3 R?W]E KYP$E,8='}{ǽkL}'  P8k'S `v@狆 'P&ȴu.,k^RGS]S7Bp9J~uF+Eϳ^DmG{ˤ 'Ń+e+v1sٝCHO ܹ O,Kc\7vO%P_U!v=B\x|UTAMĚ h-חiZcCVP5P\PgNj$gqfzԞa9M~ZP5RwJ)A;mYqdGߌxL*q|,&缿4!`GZ,hVB;e aq> M9Ś/AkfkxYXnΦ:99ߕ%~=9"hR{ӴJ j0BU%Z{ewzoH7skTвrk ;~LU2.;0sčVx\X $0In ϗ,=¸0N X`p ,Ņ](ӠV;Ս 9M~XgVs6$`G %tۖ\W(OJ2tmպ"FS9:B<=?*/c#Sj[a(NʱtE{gpTwZ5vcp}M}W٨[X/L$ /LWvd`55ԏF2ӶZ<5Xf߰h|>nw8GS -:P\&z zsj623rh UĞn|a('6!/Ֆ(qtb& ~Y1 N-f m 2?:3fO>5ICt54rY֌^(0B? KGe'`O  y"IqkI6&ّ-lP$cR&,d@{p~ ZiʐroVi]en[vX(8Y5`M^љbs~MIug^I{hRwd#KZ[i3 ø^=#ldY##ݴ7UZfs"d$tѿI3Ӥhŝ,E0tRC8pks6j".D`; ЌSx\ NJSpCcVYyNM[\hKCoJ|wA/RqX9zhYs(x?Avdݩ&5W,n|vvኚ ^5m/a/ZLX+szg^4NXoP6^TD0>,̿N7qo .?QJ^a׊-QKJ1s_5rfmu{nvzմ8Rr-0&;p@C&pGfM}>~&&`쐩y܆<}##}M_G'4#bViבt\jC3R#6hZYй}U~E#+S6XM] J B0p p6?w-9S筺3u.ݿ?Ҩ&[[] V6wɾ鳯@W !wkj_}H5hh>@A;b4eBo\ k_lZNݬ~87 l 73-$Ti)/\G}aۡFE!k2RRN9Q2;j'hQs<1ѤH/x@p^$8GCx{՞ΤbK-2B=y%O4Ɏv;>*SuһN>4a9R|t1L/lHFTBEXUr0lw^rʻ\+w'1*wC` Cmx B''kA!Eƚy.QlM JHR ]%?ֿ*7@>Rw[l$Q`ޑC`w嶐$Ud2mskUA!N|˛Ɇ efb"Cf][@c$ŶˆEב/3S^U; G\(!4$4[d\1r7Gb/%=rթ^x;L,\Ƣ&`4έhߍPEP$d4kI_ݴFI {0)V,^tI@NwƢK8IP˨/aUbZ}$Hˊ\>uGgCfW%9  7ప\/[NOj)?DodDbq xq.6DZuu(ڲD:kJlS$_&85 B`VG8t5c&[!!fEaLÚM%C4nQIKGKyz}kJv!mv*>yQHtyCCT boY8d" rQIV^&(];Ô#$r9޼5;N%ɱF_S]c!x89lʅ)!|Mxhosy4qXóE|mM8ʍw»AmLplIU3j#z/=˧f-bN؞Ia&*'qcBm wi_$&x?G&凯KYf ZWPg*;[(GZe439@RWN*,=<2͈ Pɇ-=L8x3ݯɏz Kʼn*(iY&tɫ=e6wIx'#LԱ*kJ$UDI/%g s`lws}Z˘|8F.;4}ϒGk=w!TWTܽUj;~9Rϗ J&v1?]4gIS0Pm) ׏o*Q_H{&h=5-2WN"*Vi p*(s5?T$bك4>Ehp^(ږ]ꍦ`PW k0% H?(&`!E! Մ9_aL?Rd5WooeJ@Z6ᶜ-VRpaٱQ=MmZRq^M6&h$E@1~olInXCx"jJ| _64v>09ʡD 7K}ܳIL`zO_";C">}C|v=@)KV5;vgDU&I7ۡ{nB|Fbz%D*Z4u$Ѥq !z:`*[cjy;6y/E°euɊUYa?Ϡ/$KB0ӯ%g5߇ ?tk ^Q+ݼU(Ҽ$Y.% #Eg0+.͎M XsCUs %fn7yn 7ӭPF/tNjJhܝUfMoӭKhUx%C~-F{DpwT̚Y 8tl7\ @P9vüVxbAҔWK~)DGW,^jc9/r$"c\[{:PRу.É, r qۨzF D~ 2tz>u.&_=9vap]^.CPE7Rz:ʏcG]u#\wlw{b'ݬӿ=zqfSG:ZgWXKAs{J N}L Jϩj6ac*L~JsF8{=F#aG>$UI owcrDazQB#^Q qi(V̯* 3a{:8*:BigUH&vo'r&un{8݈'TK߇MhnV}CI%j[Mәԏ-F \dȜ`~C@n|Kx}mX ^b.yT,l"^qI;?\JTƼRkkjڨ6 %hWHG 06B. !ߒ98Lob0HSA3MttUŮۓ㋍,-?G?O5n m!j3a׳Ģ %ytrt{SBk4J`9ZH]w]"\bg?bVavѝJ35ɾZ@&ǽ)zeW[T>g.?L5nr6$-]c?rukE.IQ &!|WI}Mz̙ʰuW(޾> <{3ۧC\$zB#DZ&\j|#Ɖ 6˝ptg8dq5Wi*fޮNޚl|UŸNDv=`EvqPӰq|^cFTkےX?XI|YmN|g=m䝸:I͚~s짷m_o.o3)[9 /ۜJ8a[p)Slj悒5ȑᱶm DX\}s^(XWM_u6[JA08 Y> 8c21@䍝ҘPһD#7yHbHKC# ?vxPz~y~-+ql2v&YbK2U2stdvtlNn=om7 *fi\`Z9jËk9)zմI\L^PPƫу4r1U/ nrlgq_/$ב"hsKPߵkVK*j_ ԇ)M4P§$jpm:Rp~n4!ڌȳe撚CI|zqr0\~n*PU@Jse5-((DabY1hG"Rnu#2r,͎g;sv~1\/ TP{hDJ0N\*Hjӆ R<(J׾:[U<mmB(Ϛf|R\I=RV!I@8ժ&:OMs?t(6kep?~?äv@ o^Fyt'_a&ƻ[ѪΟ- &U=k-/j=w ʌ0%D4mD*`ȖqH(IH)׍ kadsw2g^̃u,j|)Ե>TR҄i}<3XPwg碑 e* `:CޑkY 1{D/Κ\Vl~ҫ8Ϗ WM9}+!X9j@ɪHL>eﱖ^ܤlҝ4| }}ǣ]tǷ`]3BnaqqK2^ZVpY{8 L0Gu?n3Fqg~{ gy?V-R; ŷeȍ{|-pԖ8j7y:[ӊQ" wl@u^Ф8(Uܴc.ߓ`:CD}tʹhz$l8*%jyv^?p*`g4 @gZjnh֩*Ҫݽ! 3QS\wP"٘Ji2^3_ 9>wn(%V S]E@7ae$nʕ GEI]lKCl4pc&R/ jd)ĝ5Z-uǜ{^:2B+Яjnjk[Tprg;o#|{ K ξ \C J89uO-0P:-w J^='\w&Q,lIHi]1015[N=/XʒRxMUޛ ϡ> &Sϒ5BݞH EkB̪VkCЬs.#p |8Ѫ?#V88TC{$ضN=Jdž^At 6]5YQE{5߹jSF~UZu=:d[ CVRSo)X[riS lι{FB/{$$](K;A,} P&P\Z نHe0quy^-uŹ|=«p|2)΀EQW+6"=am_f,=O~gqyD,bWp$s'g# 鸗#=˿@^yHJ,ǕGH2$9Fz.w 3Tx%6$avcJ.qEyᅗI'W>H2."֒;߶ץ/$K[O<&|՞^6盎!bI !A=G0yƿ W,;iFE-!川DݍSژ4Q7CcG肛/L4zw,\xӥ8_6OhU^@ke TV-t f;5|,cI*RaL?+akW&ZtG"d )GZV/ONZZVqiٯ)E1; A'l\sr-}j|tH ]اO?P 'V0ti .菜jDk0!< P6/;0FO+ɷ+{+#q*c?!b~Q+Tf Sy_*̙<]> ޮfStLV:ZЇ7S{_ Jki_؊7d %?4k( TU^x`ıfBG7gD5 A8תN! I G,bG. $ jN+BtgnCϠw38r5.CCh<4لsU@fqZXtߩUՐbB1j'^k XN֋"2Աʩoz>!,!> ÚPˇ5pcIG\/p񷊙K$bItQ:3mĉ<S>E},tδ%JuMٷ'$~4AGf)@;2r#V= W-qO_V PR"}XBVrB[l4>l g-ot1јb+roޯFOStkr s0{H)\WQ ,C8CZ6{z<K.+i0t ]|Ӷ?gZxi)/}bG%n:4/m}255tyӑ5dB*GΒY[/NItRXj"a]=~ؼdhPI-^uҜB Tڌ Y'DSdlubY-m?''F6+쀾i](Y{1@<' 4xRd͠U.ӁCyږU|f_ԃۂ@v{U1U뀃fkY";;cF<uMk}QDZn3)<;hE!D/6E\ŋb| C{=|ҥ^<0,m)_/ժls~Wf?]A-8y10J7",1 {U ?Ofs20bB WZ8<]rJTsh *Ȝ?c\~\ l ⫕$&t8G\ D5UJR(2y0iS 8vRr Ylʤ^.L0l;X,saGr^ էnS20x>c<8mc͝3%3[_" p [2⻭G0tA?ˡW:4^~* Ru |v5O!esG<Z[ΈA{P}(;TkG,_ZbՏW/aR ,S?fϜ\zAy`nle5[c>zZQ o_h'Iݐ66xto_&"8-\{cR[qdzxUg}#%'p`X'iX[6$G#&j &Y GrˣM774}ӬZK\9;Kuyؽf:Y :Gܯ :/ YMsKԋ"VU ":F=>* F\^Pc-v? 8,bIJ@ÇKrtq` Ҁo&c'w{׺f`؃XH{\}6K'Y*jO nV sa8I|]1-w$SUx 9lHXJŦ+i A'gtR娪Ok%wOS= kq)Vd8GL2[wgt9v#JGFpQ6,69[\80wrwR䅧F#K#LHps ZLtv{)/_Yy%5KR Db] f%JlE~\ؕNpv겈7k\BBR,rLCx݆f[N3Ȯ­WHJ>mܰ06{T0(ߌmS)D4i\^5:aw#]0?'M5hIjzсh[|>RN5VogH=9;TB,\++w 6X>0D9O^KCDd}GguL7 Zmz&=mso1'z|Ϸ$4fAM+yiH2۱ <:\իs,e?!+ S&rAGob !jPbsƛkt}dp,(_ gf6e|X Q V'D>gԇ/ սʅBnUfQzed>H?NGٓjer :t%q҅3\ eOUj7tOL@n\77cǤF+7v/n: ۘBZcֵAum<6+`v-hLˢ/su#''Z'Yۓބ-N}3MqݓǖS5O;GjkC#7!W̥ziv#צCGwSXcFLr_V-X KnA l0}E0"bt[^wֵӫmp6}n SuS WҔ=)^`z5AzzOU3AIj:V<_dKpnőHesyI.(6KdrOְ"ژ6ιO jI92A3_h̶Iɕ=Y`>zߣi漸<_8ntiNpNrUZ^hZtj4i3gi4t#`^Ц\P:A#e=jnz_\]u!?{~)hiRK57:PxOuVOX+wc.QOI7W;{qsa.lg+ǵB 5yE|+n[ݷ#:ԦM #)*NuԀ9fSiD1 @QbR䟐$8ݛ9wDAշ#wQ $ >vrG۸J"lq^~N}.oR$oRAւɏd6-!KrF bu n~pFm̦۔G }ǭbs,Ckoz*[mj|?T2]lPţфfk8sdz:lR.Y89ON~:lQ>-)OWwcD6.I6=0cZ`ض/:a4hxVo&lыzyEY Pdg- :UCK5zdE9b\L*Y,{Jma ;,# [cHJY {eǼ]dh#Wȹ vؽe sP*ۂUW2[xK>2a|3"j'"ksȈr /1J . 'ϰl/滇Ly(i0Bu`8}`/%"#"d|^xw!Fȃ"7(HJb;k1#EF"fM<eoѐu)Z78]]Aj\Bj1ʎl4X)ϐreKE ;HMd@5l(  z;h;bݳn "z G"h~MJ8*&RS:=zܬb HRXeq$ mVSLΛ\€=M,1dzvIw4b %=ƿ;j0};hۂ )=<UtSmdG@#h9+@mqzKʫo~lқKeO"@|Vx{38l ǝمsOBkj[]-sPփbm df5$Y8vM38a§Wr1!i~c ̨ftF`KA+ň[w @ މCUӇ:mK(x@J9ְ]P='fa(wh{DN vªgN'oS>%n LWv ,jfȇNw>)UTQTvFd[|E¯o)oQ)d@̲%99 |QZ=UA;ki5xE-nJ503Z;515iřWfb omO3ٸ +o FZ8ΏX|c`˓[3 A&-1h7"@OF58/*8F B2C\T{5 gC)>޻3Gana rt?jL_"xpQ6Exx09gslz ( ;ک5$y>x,wgT]S)DUȠh֠'Y|VWtU~`]p7l1%P?򊜡EyMbظ>9IHDe&,=F~JͰ*"N,BxE@.HU}ŠXe&<*j؄wڅb2ouqJ{Q6^Yr/,jNg_)-MsHJ*@E>+9 Dnl@/o|29eM-;^源dҒ|_2nF(KI;3'>=oǴBƾea0O"޽CK =œUhKs"Vq;޳@o1qhQ!,ȯmG{QA*z~Գss+88bd5iRptd7l(.6ǁ5U3j|{< |YP`#7y+S IJs.\v0 1e dTE ATuDV8]|*p+U&+.h|Q?"AEFSM"*(2MDj".tf.!(a7(d)9Q E\PJa0 J_ퟭ{mZm>#'Jm$T>%yWi$YXuTknr̎!)L-g(ǙO<& ;ljn "\Rf3 5=gд*] JUkưlsºyuDP*ZVoֶ+G XU?:jYp"u>pZ@o@r&]2}L&Z]5I ,U3bsm=m`_a*);4YHUޱenYH6e`,?2ύ3,>E2BF"/H;w$^pw_Y@8 şK^<_0O]Sw[߸|ƷsjF&!cgu;<[*]А&K3$?h;"xmV_Ak(pg;w쨵.t& wD%AWX`'FbH)n3;Oj;?&aEX5{Q$x0 8da}eU3|2Rک?~7 +9z-&'y1LRZfv%׬8.:1=е;m֑ot-ŴZ'ҥПh6>  3qcuhc?ޟu%PZ;oqZXuKb?*ɨztA mY*Ӏ YAC6Xݼ6Ud B[N8yuʿz)CZm|\S[kv;-ymy#}bUY=W Jii7n.W2z/_1~RJ%ˠ7{}{).;y P.H3 V.ZawM>KeDQOL}vfً 2uoo:J~#$h[jO(e2ٕG!VJY#ބK1'O^hYQE cDj0VsnX*GGq+;v6IVbGv%~t)D_OP38oNWV/)Z`yfDjyl/Z˺ |^#O3wxֵp@,aLG}fSέvh\6: ۳7jJLXviWx"MD3C2&Kư1y|pĔ3}]VH=J9#Xor<뀈gJQ@y-h ߋt.*mQLB-P?۲idwڜ;sVb~7 oL& :#Z#Fi dcvoN"6Fi>s`zj2fDOॶj0r/tpʐ3;d7͉uww@VܖN_{~i__x̌gB! g2,6TG? irx [l5O123 o療RnO@%x+&ŧaa,=~&7LyWc=Γf0@ SY~!~nj@Y\qf]^Rz[*`> V~҉}A/G#sПh xI=!Ndž*T[qA25{JVQ+<;OE=C3r ˜g0Budt9l*^J:.YCTD$8w$/,8}M/ (yk,#>SDe&.ʕ7F 8[m LK-'Nx Za 'u9'{ IvGk7jƭ55*ɂ|WNXejtq&HXC.̏[D?ѻbJaФwL{FI:F Wj3sh#IDI"t]78m_us@=Z9SMO0SrhlݻuNh\PɃY;fƄ _LeCoQ Eh1wV,v Vzj`k ` ԂugF9Q %TGر&[z0J_ ҶA+TUSAPH؋qʽ3pT7βՈPRJH+wsv"jMi kz Ώ҉/G,KEFPu i['%H6囉~tkD^`A[x]/AߟTF`-&1+ +)`3_ lW^[kI܂q>b^]# dYyi>Q*YW S o$e֫> c]* paX`Ae :h2m~r{%cG ڐ7rj Kb7܆gX[zNSkU4ҺY*Q;HD[{;ĬjqSsgyf1 wWt8h* &ckMI C E!C=^ X0ětHo`IMm0|^eu5>qBEd>B>]kȬG1R^Ʃr+۔ "J1HABjGJx& R!Qzyzk[˜47lā{5XJۖSϨ]PNZlYt'g}D֎iU0bST)x oC4`D N(XZ9cӟ%y4 |}> f-p;0a?l?DzP]J9g/O#-A?{5̣6b_)} r $E]\L*gI=W$3Ǻxmsҗw[t$ `sT m7X9+mnUʦ/$H;˓6@X|fj( Н)Fy9Rm3.}OOOڼ]`[$` DACZ3efnߵx!)`ם J Y9#>KJR+At5u5 )3'b1 3S*tu]Wpf||jd΀4ׂSGOSLnh H Yt>sx0!# 8\ ^PY>Ըѽ̜R/p_Ijp|8D׫vtj?D6O9 Q5n# yԴN=O<κ'Ȃ`9 ^p+26:oq6j%W "@`%j3o?YIbUu#ix D؎޴zM}UL8"P>kVg5n_;m礖S!b:젉e]kZQAL  -&6)QL p0ΉJJQZBXŽx$wt=}Ov@#R@"9?F9(+ڧŀavNPI24qaZZ(j+e!n >c¯/6}|(J\3PT ̣$V4(JY)|tGw^NU.L_GW f16jIS:1W-n+2m8](= gmI>P2{|LZ'2F(oDk0˝2$}JGɺp!$8#߬vW=mO G?uWt/bsIkKPf6d$myn_yU߹oAa^4g*^Zy\ƀFobдziirassakF \3l@'Q{st=5r ECa&†b)ޣ^qilzUmܢFfD|=PgJ`?[ds t_TSϨs\n^l"5gȟølHN3lLÓ\LpdSVr,n\xDz1rrLr"gl<ؼU=sB4o sx)ưX[u A5;G;`!5ueQ5b).xLuoxt$5g f֬owנQR}6#CyMьFZa0ٙ&jX%[gٵkVt+=89mFb%4~ 5EQMuӧ1еPJGjrp ϐ GGȣ{l?8y, 6н#^ٹ)31wz|ru"JF1l7{L]Ssv肹J.cp%.'Kl9Y;8F=h::h" &n`)ϭW,jz+H&PUƀ 6a) _Jlqz4k?fvnݯ!N(iΦĂTTJoT#1 Y{^oMyDi[qɌN/ޏ@ӆ70)`?©@zػ.09ȭG+OP"8[M iQX'$F4y*JY!hK$u]R`UQ:)6`BWFR@fW{<7gE.S܏> SvgLN[p@adr;XT+nidw} V9VZڒ4^*a|~Wp]5^%^_6wT+?22|،%:ǣT}:U_]91uH,:9@w|me{}4xO8\;4"[t'*ۯR"îv#U17hag>ˡ +>}=(%`^%h?cT.B@87?"8$MϯE-IIT|xs4XDMYua͡pq< L F*toiʗKE1n!ݗ;&[]Tl?70x DՈݩt}?TȨL^U0Οtg'5v˵\8cZZ Waр;7  U*pm3pt C$g00<U W:/=|x-KA$5-Xm(EB!7tA͓ b_~GC@%L W4.P ϊUl0>Bᛦ1[l~W@Y9[S#O[ ͪ4c*2 ~4U‹c_A#ODGFA<|DWd&J)@ťqW˖Ҙb}nk>l=%N'PO~^<b"ޯ5Y9" \en$-َ*VGJSlyy >4^΃kQU+K}-^ZP=)M۲vt,8\P=uPw FGyql'%yq\=@=\eSqe`s|>3~,6DȾ|MT;{Y$MyuU<[0?fJHs@e8Mvx8Zi k<*D/3AEO JxOglXm#Ӕ0jUJȀSAg ^_@dz2$,YZL6o-ڬkѧm*=I]9R0GBGnAsŧXV2ɖMMgjHD-\XQod9DgzrFXS D7=Hl<ێGKǷ01~rA]nAS@/eכl=8|Պ2oSͤ z3GVyJ}ɢ W3.\ * ԈR `'7pɜŘޛo.G[jfmg%4jX z\nQ;i{?. >~+M⣷ k=&8rN$teIEN V*1OvCMP2j,l X `Hm߯Eiw1s!>l85atG%kU/=!W %F%Č{Ây}G^jt9<ؒ\+ɞcyM% aQMbu^b1ZpWG =.X!J mFlXɕ#[k[Wg0v4]1[o~fl]zSFWw-CeܡOOl+y>8FC~uJ8p4Od(PkJ Bk$tKVUʳ Uu,[\ A S:4 ֺo_T2ПЖ!ˁuS 2FO}?HdRwKy@,+AvcBz5#k[Kkv;,8Rשkq<-."z\H P%l|y"s.K*F)^Ĝz[{D(B`ԋr.yANO4>V@ )|3$-MW)n@ù<è;/8f>0)Qöרgc6nW1g$7/-t[K ,-'͑_.Whp1ys~HE!Gb[p~A;TbUg]yĨdfxoܡ}ȧ@>[-+'Kމޢq3g'%$^MC *dZ$Ia(,62OaLQ= 1zbf\Wʓd$D&Dxwɓ&sdİqY1};7mۀhgң4HQ\" Zawa#p4~I .>m,\aͣ|÷(+ s8E.T ІKE|bf7C b&2 snn>lPT X@!qh5U^7Va:EY?w&.B \(v[QLf/=פњ찃PjlHHv5\r _y찝Ul*Dh07Xݦky$cQ_4,iIxb.etn;8_Re=f25UL$]E>هěz{$ڝ"i4eb,V֚:mK MRh57{~"g58${{LxȢ$*Z? }#}Ff%[bTGËEDoRxza0cf$*׈}hA& .^X*`βPN`['}"z\Qy9h`Ѭ~-Z4{hGrdntI YW6'YUX]wG32~ <{kAdʀzwv${0>a(aݽ[H^kUYGOSBK)"$~mTЕ&(RY&}% 1Xg_MD 8Y0VyIp0݅n9Htx>lt}$A,M '#V]'6rr-tɎ|xbAD*:0$o/@>u"5L4n)t|1V= ֜VI.>jYqЀnV؛ xc=IR y8O&6RFާXW9GTl8 吉~@IMJil+&Rwd&]g3 7b >`&?6RGѾ|iS|`7Q>-nH4+P\ i B̬pёSo!r[&!`!).hxrWp\": ·mp~Nyv ;nL*61/KdoENs疭ޤ SՎ37w8vj ;PU\  (y 5b7+MP d5vk.CLI+cZ޼˲^ye ﲚ2`!,x!^UZpj"AyD\rBh#^zo#5-+g׺uLūk}ED 4x; 97 0:{PJÙsM,ŅzEK >sxmTY2+V!Bhݤ\˚¯n)=Zచ??^ݰ;adh8KڜaPgȆxaMwnuAai#ݔ- KKĀ7S.oLJ[{*#z ?e-Eg%[Һ!A"q95HY w)p B3DUnj]7qZ2:< KnQv|:(lJ&js^fk4/Xu4cdi&53jxmH~̩O^-Qg.DzGHf4,]Ǹ 엺ǛӦ7KR5(44#rHhACO9$w1EGdFx@\݅úlĆxQ L+ ,iZLx3k%_rtoLm.`"Re VEM MF-C^n;z) i*~|QΔxPe xY#Z?3ݮ͋"q?0a$-cS lo* M`b"9_0bvkZJȺ@Z9*j qXOإqiBu YxN8n_ (k!$!- v pA$*D~5a1_5ѿYkr6*zF}y(_OZV0fs]7.cPv*Ƅ+~p>k?RtGhTZ$f'9Ӓv'b/T uSh%ӱ@8a(]bPF!} /mOj@O=9#6r1*>Rgb^90=Djg~M egAAR7sxygO2X8*7$K4toJSFQ}w-r z/*Ő=_I+NTKSbr/]tk =dɺtO G95J352XQ $,Z~ "LW_@mWd9~WR;e[,aS做K`<G6y.#XopًʣƁk9 2D2bc(ʼnGt=AA:Z"oa;IW 1Nc#5@ǸnѠ,f075Վ9ɀ1a/?%dTE*fƓWX)6-^E^Aʫ(T͂qEyE7|lh1XIZd E.¥CfJCfGc}cՕX-NEi7\R\fD(u\&*Zw'bLn$-p[ ɅBpA[5 =*x pU;-`NxA-0Vnr3' YY(Cϑp6F4qm6ay-xO1kKPFo߆@2 @5UR^0 {j|BK J+ "Φne^J̘lK?[)g!|!E7=>2 @!hڴ_*$3VUHȝJW١n]ZBG[1fH_}b+`=s}ž D<7iv!T,_K`F; ߒ39*[Kcsϗ]'rKE}4<;h[&#AH0T;O}5 AID@M)`^ҋ2D;燝B8ېSeY e_btѿeB4R "Ú1~{Ŝ\6Cjsu=:O!M"/* d[ɪtbhw2H)5cq ֥{saǀM&MDyKǩ@|Pby6y5{ey7\FG"y#6De-!&U2>4=8PS(%qEiջc\rl1β[L-AhM̓_ %{"Tʊb$}F2ahCdgtGmLHvBJZT6 7ehsCQ4{|Qޚ0ć%J=Ҁ Psz<Ѩ9FC6ǃߗa<Z\n.'QN.by!JY+ `QmDT:!C,;B-KtM /t<ߓ %ZW I>84 (VR.lBsYWf`aK(=mhøt4$\ҕЄz=%j@Nfwe4)4GY~zהP$QNaX[}=!뚯]Dx;hp@ϼqBXwV"2&_N*hmq/Lr6; -<'M'b%i5%R[ ~:l+@WDAv/ZC dFA^WYJYnZ`ZwGb>Cm&ygNsWDqT0G#kіv _-'8)shC< ֤%ۯ0,,=yy2 *9H]Q, b"NV4&A5s0Hˍ6nyY}@^/ C.j kms& (:%86>EI .0Gdy(tVxhu06kz1@ Ek*& Sh*ȯ@cb ЭŖX`%u8-r+ FZSm;5xȏ; d,jexytakYlGEBpǹ;J)|ixhgjZ}On=Qy۷)bٮ-Fr0Wk o W~Y#&-Ay'@yn,p+%rIe:lXNP*Gx?:[!=W0bj!4\Ia:1%X|σZ(?C`wYDznd 7qdЇv=]L8OjqiJ6+l0/1,Kh:THq"~ kx d5+RtP|&ɿ0k4_D. 7k"Cn/;BͬXƎK|>LY1W lP&'4 G0[k,g`Y \ VÒ3џH=G$j5VgU}2:Jh')4Zohq ĚAtlJm wmXél R;*ֽ" Ep2#@vq`1{y5eR# jdUfuk*C3a쯘v({q"cp վqKQy&g_bAзZPmS) q0Ϟz9fi׾%6!0=Lբ.}z҆\.QB(&^mcv)el%[0Ib}502 r"ÙF нѝ*8ܳJW!gl+͘>*9f-·IPi=Ԏ2/ Zt//1Ŋp{'TSq~[2; *Q>b2+0Lw9`q9*ƴU݈ 3F0~* o> iɭfm KyaY)薚D+8+d58?Ũk}E~ >>]ٍK.4--p}ShLy`! 3[@Zf™s SєBP d\pc`1o2Pkc͢u_ G8Qb]jK|au¬`( wvO.v*9Mq=p%O j<4š>cBm M:c͸ѻtS_$nlN/mʨ$}KlL>D3rVYQaBeS :nJi#QD g_gȄodAA:dS*U7!}x(72bMV3[Ma,ZOB(vi l oEҰd=P!KB[5r0$Fj pgh:'OGB ⬠8 Bޘ"ɞ =k%Ztn2'=3|@$1ł%cwߑ^{6()Yv&t 344?-$z/nz>"\!  lO~^t ti .?]e OWUNnvt~D\ЏE Vޑ4ʎ*|&tI?,J(*幍%!uLV][a`ECsy@񹌇wR.JppUсd)`is35俾&hS>zKM :OXs|D UǶ/"+wz S[()JI j힬?課 \jBb:@}6G5$ 0޼b%m[zA'TrK8uCoL3 H3ʞ߉ӮE9~ 3BaR!w\1j|SEv~9m 9I<˦gi^kF}Qh_2J>(K)!V)RdPgg " OX ;# z a˷Fir ߊҀ|沅dBi30(V%([v7 -iХ{A%/%!>oDK0'oL6%UH,ȵCqc4}tqܲ_Q ˲ +#1I2nA> :N{EE!$84* GA3Փ|h4 YKT* eq*AK i]v;P@D7۹̔ Yv䷊vah/5Qej{E=T* W)$BveM{f8.fGb5:go!,vO%0g02hU;u=-V5K4 UЃT_v`냆Lef٣A"K 1=(jOm'3,~+ :_R3fwx\jޠf%S1nx0yՅyIwP9~PC~PU#c嗀&[gҙ?u ʏ5QWQՎ fcFϓ$xݧ ݆E$0;<`]K]7vHoi.ۯ}AK6G:CH)6V6|t8Eġ<ܡV&oJ90@(_+r6c&`lt@弸u׎?T؅H뜆K QW* 0&^.#Q!1z8 aJ@toOSi`aNJ8&"L=y롔.ei!q)k["4!n|%<}QȲM͠}U' M: ~C BR1ACV[W]m:R]CT<om*;-dշ}'*|b~N<ڛ$Q/'MsY%wRp6oEy1A*6a?)8>\^(XK'ȕ +2HiKT؇8p<>bbIXgh̾oz~kzI+FaܟA*؅9 ^F0-DkUe= 0]1ᴓ'u ёXWL׽IjR՟2!J|^b {Paw*l:g,ObDJ I ]kQDvb&۾h~p14-#b-FD(f>-Hz.L3Pyiխz׊b|>&L"-wL1SA^rLnl +bq}cfaZ,v)Yk~W%Հ`/p!6^I* i>v 5X)B*nuj4շHo|y U{a=覐0BJ_!-oKLCzg{#U%\ZX:u-xΘ~Dm2R ZS,y?*XmQWcяxONt0.㫵U34\8os:- W#r2ckJbAEn2=iIGk tA~rTĮEKV.A{ :Q `ީI!s{IWy2N T|ʼni=>`9ofM# O(░bH!38a\y{VLDtuˍ[(y6ʟx]zaX3Bvrϰvlchk(M` >|Q@Σ:Ӊ9Od\̺}enAۓ!+4=9z\Ӡm~~Xt/k>_jt*i!%WUXtka]nb[i [so_hxird*B]+7t/J%_j 8仒cV3\{ pev˴)qDt@G|=[ȣ1s=?gE[d'0 1{whNkosI(qc??茬&4CUcc#wm+pܤ6ur dur*Uvj'/UW5)#`?,?OV(e"FIwVz,eWT-3 ^ZM?%B`:\C #YbvP ^24^@#H˄]*ʷHބg s@S&U 0wnkx7&&Ehó/3؋T]vކk(,UʛUji_1q #0 M SU͐Zj|lWZiVѴ&氍dT%Uͳ' -[C.J!j.5=&J v&GA9P\9]6B-M,vn?`I!q4iߩ1֞9l6ҝ;ֶMT?TDV7j@-ȉp;ur ɟNZCV߀u" -ͼJK/eq+o"?B \BGS[Q4b۴eVK_qUsR Nx<: /d^'5L -C \eνQXh%^փvBPja Ucjo%L&4'̴GRC=ay֎-C:&/!?ՔZɗ*bLDiR ~n($~"!qEXvaxʎVqz%(j#.$yGZ ܝ4]U0ɪ C"YGzs Wh$0kQTPqޒ,X >c*ꕝZ;XGaoX2-U.(pZ $EZhcL)@b7NPot2e.,EyG"ӊgCF>GQZPoywؑKSYk{/ :]*pG>_x:fCL^xw`bur.wϗ4#lzs^\ɸu$hmE_UJ~te|HbBYʬp i UhvQIGN}oB~:2 PǬKv- oGܸxφ)X\ ]8 ( rA4FOXMj>ˍ='<޵+<; QYlX;mAdښ_ }G# к 誳E$x@[gBV3",E"L> a@3};l;s`1I4n V7NhqJeW Jjb<*Jz ъRU %"Z/$jգPci xtբx#d7_҂߼mF&2I WXq-kpc*%pvx^%)?.*'R;69| \(*1ްd }T41@%e7֫;,V T9rF SŞ_5By: RECB3SZHQRdYt)+(d "3]1L+\$<%Km7ƛ Lr Uq/g/& z֘Em{g"c\H+UGR:7;(dzB\~ϵ:w-` $rp^(N2h)N/zI0S󚙰?=w `-!˯@b稢߽X-ZLp9fgpk3(} yo#,g?U(Q m.kCbXjSF"Yϋ^Qg~zw7R7&wN粋?g[fC.HwMe>ަa"ts0#>Zr+Z%/Ff #4C .K{MrCPNUs1Ţ'I4q_qŽ*yPG(zÃ>a~ž"|0>P>֟5H琤5UI¤MB~?ViSum&pɫ19]XCa gC^:ߢM)yP(%qY^&`:7i]#&ɚ$֚ $ń}y=6jT"(aA'ܙ!L%)2l|]]0zdz X ;>A><]| %^.TDc={5YDB!/1>wYaFA϶Dڧ 흉 KЁVF"pwOHē˛QgNj|mPk4>G O3tr0`nRzJ߸Ձu9oEZRB )o*QOY 5#4ۋD}8>2Q|؉``*I7g'YA#R9xL pL$3\XsΫ:t]W'K^G!s5/KԶhg7)!pR{ʱq9n擣Ss\DqgEdu*f"?2M'fRr\})te)~0q~Iڝgr4n"*S)pϘOyyDXMvT/~F8HT8e\xLu&MᯂsjL3I VLĘjټk?M:Du鹀d r>Rԥ7r$qrrH5aƙq^3^:п0 "Qna2,6M8 gd^]%>we!^ w{j>QO,_g9C9f K|v URgmXt^3|QB!$t71辘셦c]+ Kt>pSy392<3%뭜,Uזm14%7Qg_Rai%36Ub̄3eCbɱ4p ƐRR+ G-Bi/=L8?(SZ:? q}bVh\۲\,I;|aS˗3J3Ԋmk(G+9.EZZOJ?64`G11^d6*khW0p nAߞZqu HCIjVe!D{4gh$3LkZر-޶$N˅a;mF0$H#ݢ˺%YQꨆ+:JUO9E2źZ*uUf-܁Y6SgVXbc50+IStSRzY6*(__K^ߐ' G<[PWS&wz7㸔TVXX{BW=.F|AB&fd f_#3EJ7@?c]a7t0)ˬ0DAm|i;%Y@qoB4|x&Ƭ籥bTƋ˗j81Y>{.7H>G8PzQZxdE1O @>;"wOcyUr4>| i;)W4pv谄M7^uMOO$#>B4n7M B4Î1!\dy(e$mͷhebJl\E*LE!c~oI+`<J^ND A 3'SP#~*r:2VZn #i\Fg,uoXh10'QDe)=n sֶHDKxr l2H?i?ܰ]t݄+Ot W'2S <٘e@@b]nlR\"|=~Y(vv}viuY4J{QG \LQm"O5F|7(K9"n~DwDhHCh`n 1 x@,\?+Ep EzS>vqFM5[:ʶq&DEcҙqe9%d@>oS`FTfK0VDrRS%Jyfڍp6p-z0L߁x,Z^%fg`!gxLWY ÎC|gUC7 boYX˒N![L(劆I?v 3(/ޖ UTgwXc3Y=WO5M82g-G"ގ d(E( /#,jIq@lӿ`a m?z4M?˂/@^G*yr q(20y'/%,4tFnﳩm1i.,[j\זp]8C`QpqMe 6PgeKp`3;2nqaQӒ奇8Ccɥk$2Cq-ƙ2sTIo%7TT<P,R^=%X[.`o=#/ Re1mTr}̰c4OW=HG9?kD#q',Q@WWfdž.Vu-_H+њqP纠yJ@6iE/ڄBݒ]; 5ڲ8\4t.ba~cZ&j/{rw_kGM+([r ۏWF2&u@Ni|\ I1OwX?$.J4]hpA1A ,t vt5դLz7{BJ)uZ[6Ijyh(BVOY\lu|7qJ=0l@_n6~/+.8)r4<>ZG `yo>ԙ4 6pjF[-Cf58V~zk8RIyC0w޼:vHʉ!,ь\&)c&7[BVy#g,g6#l! u2<:TՀN5GQYbwql4K2{XcOsXs'4|n+Gؘ@!f0i ;Jdt-n}\Y.@G-!We:bL>k[ۃ)TeFj1u8ƗXՓ^3ᨠ[˞ V4 Z6ELs: ۔|ŴoY =DBaw9xKP]p7zCң-nsǘly 7E 5J.=-Aֱ1ca!D>S,Zp]F1zҍϺWD]$ErqA%b;H/BDvhkP .}G&ַ5Ǎp6A}|qAMț]*ԨeupQ41)q -ř-R.q@ZZt7E|ZQ'Pߥ*]Csѽz||{&1WUΗ瞒j\"yMhfn iWU:셹ZT5bUzz.抢E%e*@"0wª*Ak!@`637ޞ ǸA ̦dǮ-}1@]}hWbȸbeTl*S(^*hLNl.i ƙ60q_D@`So$eW[inH" +d 6y]ͩuBe#6Рzܐf4oͮ("C̠@;V"DyG4ٶb0e_v_u~׿\a;tvA*+]]SM, jP S!O&z 5f3}B[x#^Re`5GQ\^S}\+-0F::b͇<|mRo_U9J2΄8Qn[7:ߒ_ʱL@0Wr3EV0hXba_ք &%msBS MObA14lS.5ўf _[hg|}@덌hVCle5{61!?D=`# YUq << |Ôpz*deW$52/oqm#I rlx"#l.e 9m*5ߣv6`V;rP,pS)A 2B`?vc?0+ƞ9k6ϥ{_q:] _v,]jH1'0Hu WC Dvƹ gK9!p|(e7~!UvNR`MILRb3'3UMG%섋o,zh)MvzLV;$QiJ>)1]U@2(T 4JĸBOb<97[/#;x Jggn d_ۀL/# Ϳ`!r74ާI@HΛF{mƫFkc5զk@ζzeTQ/$ʷxJݵK9_~bU$ͅP_Ml b_8]|=@e@!Axٗaۺ?u Os[掊W+gHF={kɵD6j7L s*.<_Dɦ PI;y %iH>SN=1Q0emG„@ >)D*X<`@Rb-+Reb_u O)5C0?އj*V}w,g?"+O^h3ekk62ڶt$tWgh#T#Zao=c\(Q>J-S4 . =4ۛI'R>"OP>_I$itt/-|D@SmSE8w`}RqKu$;af!Y(􊄉/sv]IʏhkKN'̗0xn֗^ݵK { 9p4T=yW삅e+ihsXehkJpGBH.vΌ7IP90x׸*sM1]v6\qؤkHH(4\(E&!ΝS̕6lJ1x+/Wa[Z̽= OW<[ ŗ8!afc-*`в^UA_Uz,>{l%9[*P"=^]uZjƄEA~gS=[5z5ś47S5"{BIM7[򓨂 D9-_|gGfHi*HWbjp_-Rǂ6 yuw0z? HwMAw.W܅_)f␣;f};k qC.&v,핺>tiyxx*!(8Qf;8(DVGTAjم,.St+Y; :.τZjba7##3Tb NXW`!o=/MػR4p$4*jLJrpq֕?L<)N{"PT}ҼRK6SFVqRų"(ې:د=$=BuzFdًIw1 XXw|W>߳vP*s&fI<hY7(#mMF6a|rb"YPca+]~gۿU3ٙ<껰\0=ߒYXGkSHc;zQ$59a?Iď^09(_0X9u!cdF@wߖ;ET>Do'%+͉GQH&U8uo  גһ\3o:[|e*}g$Cѫ{V曪Eߌ$XI:I 6LPUx[hL Cmlsq(5]|~Ӣ7Oe]*+Qd~sAD%H]HfΖ쮼Ֆ[@641[Z9O6{hZ{&eY*J(qgeEp{f~.FH(h NvCRx 8mAxe-ĂgY)o8Lj5t[r5i -li`w)K-i-CC4h D_qe+fQD#]2КE^WP@9!zQ +M!$| |hAۿ&}x&Ėv1%$西T=0_:1wRPDNK9,Tߡ҂?a(Xe|/WeACb{>k!Υ*$Q3bPY\ lJ3zg ָŽPA&w6gV:"),S~pjbߕK^9 ENcㅴ]/6`u:qns'%+wZNZHD'uSC!pK֛pE, v?~۞2%ysѢ*CykHέA avZMb*dKٔ<\J+l77#~%m0/O^u9AyG\OYwY-Yٽ щ 7 KU搌Yx|H8ٞ3Ywvoڇ+Lb5ٞ<ܔP.*5f6m#OU(/^l6n4E PFT/q_ wQӊA-o?[S Jdshܥ\ Y{0!h*=(!}Քq_C=D"e~$je'}*KȶXrdlb8 Iy EFUi&Ua |$ iJտ?>CSNN8/1|C9 (IQ<aؓg[k'uɚY]A#ޮ&Q6ZJ&{&; aAy œ)N#F2-%)%ٚ m{qH_cPV8"F4a ~tt KX[Nr6ꪽv˒-#wnA?~q&-4:'=-3`H:9/u9g=:4k.U2:総2u?8<*Y Ú0-'#3U+9߲q6d[9 _FtdOm6݄I]O)u7 '%&6h<䊭M.o "T #uR6>"RJW3s*yU gZY = ?7Hws̟40eoVB*)P8,c˻tWʵvx5_]_R)tr'MG]Vhg}ǁ'5Y̵j, K ׁX|Z$Sx[EK]`7NFM#0_%H gc $+RM\w R7%ڟF~d\6@C>XN *Lv6 C :N@_= ;K&v5vNex{,If bf>"&5`vOTdW4&mk&_L84rXUͯr~,2XiS_5V];_VƘ=D|{ _"ˆ\7G~]]W .G+Wۨαg5w Ax˺˺~.Ac#s#L!w\8{!3u M^{k}8|{/]\ c>T_͚CO0 ]X0-hZIP=hHA,ƪPqG+FS# ?eg0}]p݁-eazb< 6*U5;9Ipd8O4bHZjF[C,6;G&'p2j;+/% S(e;ұrLhVtܸ s:͝վ˭&fJͧ=B?Hr䐀rc%y[jڤ[8B,eW 37$U9',zp7'G#9B"c&RC5BJx7?Yd4@!r"8t 'У+C)S*M=ۅ01blID-!bHF_wu@7F/K(`jDZtekŠVxxghܕ~A8qcKC)Zihi{F27эj<X2Jy=>/ʒ[- dṰn>'.6Ǘ"' 7+bi+q $Xzٗ:{JTo!\H*Kl/7hK챊 Oޤi&٫t`#hjne9:bqk>t⍐yTNU\VIĔqd"[**ouIjzU E-Ԉ,;+$yY_TA^Kbqj8NƔC_'4| ; !_7 e,xRB'drBufxF8*WM׋kzƋ>]V}ҹXr5+.w^gJx,C֔ҩy\OGTx;fVv#ߧMXtE =,JvrrȹFBm .½Pgn`kf{mB@TB{ o)'H3é"h W`z.)y)rԄR>.hD텧Y$G"ŵǀV|7Xm*~DDrs !BR:Fs2숄'BL]m ӑqșVd64;Q,N /XDK!v$5 qܯOb#=42 KVI< Fb>_#/xٟySCĽ9(_(6 sp9JKG @c9kԐwn$;8T. XC:l9>Se}q|a׵p^r ,!p аڋ1k̝/'*JX&01гY =x~@ROg@Dy!S훪0<ԕ_랽xVΩ~,XO!P||W֕y,gsl7نuV3KXOLW[|a` prjL\pt>әXWsS@eD[0<|U5)Z7gzj4rDِiS~ozt@`VBI,{#{B6VC)ql HfwPx$]){&  7@Ї쉝:xw4czx~LZ1 G>O;Ō|ڢRb} m]w^J+\đ1'Ư=%Gz |-tk R>ʯV]/`7gǟLd}q!EtEi5OʩzVIo88)bݹ\q+3/ɷNˑǔ,6Q l>X#bxaf b,} \h*'V)~H&yS56j }Ȩ3~M<,_7E\uk"zDF 1x,hw;GqCg`hgd |fr2A8kg.I:Ljm 4]"sohx9- dU"ZVS xU1V;fu82Tsh,BVj2VW>a:7ߏEW”gZS-A򡉅5ͽe9Q "r~ 3N"Wլ2@>2W!M y*ς%뺺}HD$k5l``]bR$5/gcN_Nn\N{S d%Z#2pPpŗt*(Sõ狙#U,!#e奓_ԴٜDSe倱LZkq:Ro'Pk|Bq))ʁ;ZʯBj>}eDqB3B7 雚."0ou9v2p<~ݒU-f_4H5Ul' ElN hoQʔlSmdk$Lk'lԩ'(Uq[ D/_L|Z=N45 h]|i?S@"~ 5_N9TXYzqKqeRTrfh[A3PU=I (g+2W(RE N.i7 !Mb僧SM;h$UcaqO)w%h8߇ !sگ\}lP 7E=i ?$g٥i6UsH$,ˁ7t|=t^6Dja1B4Z)cy`DEQBByКHZa`@0#ZzVsCS2cE府zJhA4hazΑuwjXdpHEko r]\€/Uw4!80TysdK76~>VlDKOsHup ~B(,"ʓ>%H3\3Hc$Ū(UyqykφKj ԁ} 7jwoQ: xս)?:ܣ"%:Z9Ee~ >LD] -]g ]:Lg+o\9u)U69;~CifD ~Bc-9Ȳ.H[}>vMao/"YH<]+*U "YZ(ddFkXC22E .tERy $XN"P?fpFP;wL@h.Km^s Wgb=z̝UTH&9at)}͇oa'rEoE0u:>|d!",o}Y2K(0-v^nR'Wu{c:.1%rГ#X5S1,4<#۬V# @O*U'$"v02x lv$, SϢ)==ȃ)O6a0kJ}/Njb ڴ`6Qcwjyل6 %8ɒӜO#`c7f=!^aH[DZPF\꒾\zg/2-ʱ+2buQ6_̎p]&;k}=#vwZJ>'~ T]yy ķ dMWpnmХP*sC(+?# f4AnZ2zk=HV殾 fjRl%"Geۛa-%N7&7LxǬzjc(O?+sf&+M 0d縱Hӯש[b,3p*6m S-puyS7aVS`!q+mxr+Q < ρުN>hd<%i$c, ո[ :-8D) 8AtًT"Zt^C`5 5&n1vq?ej( >*fWR;{QHWCpfuρn-ͦ;A2hv a*U)Q[Y@dp6,Q׳u,Iqkbsj͂t Dejևi Ge٦dt(,/1ͼ'h >QsKN^w;VЩRgުIuB%qK.}'3Py8nyA>k :t5>a߸`R'g'*hy2I?ܬ)?H2Gn rYa35̑j}mD*8͔ZolGR251CBw71#5è 2qGؒ׍Ns)~w]T{]0t[A+f1s¯$ 5OQlj9xى@Bn$MUrCщލ%\:Gt,#N j8%Wq.tcR"*NH0S{±kU ɹE H3o}Trf`v @959ۨ"W=j>8JoU5<'yY) j߬ l֝ NaUgm0f[ː׎G-ڎN_'!D;qsxdؖNE>$*x54icķrD2X"d{T/-X3l7T2E!ϫdHV` 5|T+|K.sB{ 〈꺝  A4WcF'w=xCmuJ4"&zIK8"{1'#rwnETIDqdtae]e\B(m%/l`@b/نAVYxC Oī4edx x`'9J:X-P8PX\9mJn>Vʮk]dۤ| Lfbp2Y3,J<$gjQa40:g%kY4=ӃQKژrc$S!;qT J pϰdr o)/.%4dh9p- 1 8H9R<^bE)=䨍P> H6ܟtAg.Lfy,}s8ީƀ~pLL<@pxqGm L%;Tr(X82G;oaD_#Mı8DfQ_ҢPr OL4pۧ~֧*O!j"Ŕ逮:AM!N਎bvLqoJ"ғ,n'=O,!RGWKPF*!:n7L$_ 1f~7pcVS,fy&ʪ'121#l<M5FM|S+H! }tđ[ΥS=Ptż #o9!+0 7.9vZVAlG=!LԯÉl77-_yo״5&ko |I,Sj _A,\Sx&I+$\+TX ) 1z^PD:ٟVs .+)+< gFAaaDm} Կ_F{%lZYYhG :^9K.]?跻C!G⻳Dg1q} Tp]i"F,Ѳ51xe5iL$>43)F9B޷a`r@  Gn 7hzl{.ÄɄC>Y4R_O";kƾt0sdպhhoJ|NUe(# T=jXewx,6 8V S-B"z/,fȹ*1NTAΛ_ybsS5}C~-N9R GD h kd#(7"uˣhg6zc*x!ûˈu5/GtY*:0$3i:O7VAֆ ꆗzJ Orܟ=.\ʻ1-FVqngC3ZH4ѮSFY``hb3( |Ե mD_rTn*4t,Zq/@6ӹ9{S.Us)Sg 7D#ajVX9dkN MUmCFdlrA4__VcNRyXE}Ǡ{:܀p^ zҭ)5jrϛosKpԋvγvQGpwaV6Z '(ZQҿ0y̶R rD*@d;^iiƻz]ce-+Q_S~^ЙVZq5˄ڠ9N826;.ht|Y}a/ vqqzg;ԆM?( ?GYGIe߰E>nswGpF-l3k]M8vAT: kTRӒvdu;z5I0C?l!k\oBzMnfOD[iFN(3e¹ ?h5cĉC(,tx.kiJQMoԙL(8, ,$\gf|vF7p1xH'AT8@L`\:鱭^o^̭xg%t6R|&sIC2863oaoEϖ: Vh'9]u! ,%FŶ_ȐR}gaa%mw#^ dMA͚m'.y]{s)/F#{ΥݰХ"tY +2칮nmB \ Fc ro`i<+͔F'BqB~4a] қJé/n)Dj;Z44Vo]i=Xta)SڸZt8k<1XJ m6\.e  m7vg" *'2u(V,fݧD h9bej[$/If ψI;C[qv\VF!mE>ild]_L1 ^'s&g+Uˮ`` dǦ_cHJ&GQeb(0 bămjnYEufb`>iIA&okvAM^6 uJP,e4op+%L*lZiБeڑmIC@nS7ײђ>@I+Ț![bLtQA@}W5:gNr3uB@z/<ёWĎ*-r[nUg#;+tB`S3:'Ыzް~Ci֡yY-]_4I<Ab G#Sܧ95$.Ԕ xӬDE1 8#t;!`߳6cUE#&]/S{,"@5D;}rDKV=$vuK+W$qnԭR1:'a_,!Cs{:UpK""M\V>A3겨euX ^@QoC̵5,s@4UC1:a>#W4 ?tDZd (2H$@e 9Hhw3܄Q&d@kCuTNOɜCSLl J h@߰ȼE82v#E0jfX=cܰR3rС؂0håoa=D=*t@p=A s*qPΌ2l_f;~Rh\>>H]1yzh Vȯ>gb2өݯ Wg E0nҶe֛Op6Q%ny I|zgULP'CgƧ&3g (ZϣhG.4LȊH sRY$zNﴳ 'Q)^D+ߘږ骰~ 4knO&BY-jlB K4NFpָCfL}ga0_L[Fgh%}_Stx kR?s=Y/IBh61͜$igiAq%}'ok?O>bPfYgS(V.+*ƯK GOuNh%^nHI&4'dȇٌROU.!wz7JؗԵ\PL!`bn0+/|2Cz&v`_}aJGtdG]97G u@z Us2F6RV8K9!Skѫ-)SDL&]E!Yei(J,Џt{=N!&(WYg_24Ƙ{ŌOcFJ͜#vq%o1ԥ\tXArT&w]Mj)VaVܸ/ͣ1۲TvFc-^5bW_%h0!5v"40n6#j6Pr9҅ꆑg=a&v2 -z}< VIqSG `ZM}44ANo3C[5|Wڕ'X'??8ÇjEc__JOq6vL%ci{N4k]"g5  ˉ2VH{j@ T<2=θA_yPS4 p" A!+z!$CL8bs}za⡀7K=~lR*Xzh5릈66KBNȹ9Kc-8#Vj ` ؒ 8Yxn<U7 O}j0-o&XIP? 3o#owL%>d}zRhAT]`i[E ZNlXv ~xHSFq"ި2zgqb]w%nDt1uc\zqК/~ I"*' "Fwc !c(L$fN%~`lz6n1H'ěԖ1NT6"(I%m=Ytw&˝eeĠ9s Q`)6|Ulgg #9q$kJEó`Ab B}Ua=mєgϱΩ9v7ۯ1wWRPv\-'vY(Cp ^ON3(whIԽ@|I[-&ԓC":oA.b@-ՠ ph Ζ1bXZ 3MctwZ@֧?rL, H0XL54Rэ~C%Eό ݭPB1ål 7s3]!$P%mt>|4"Ǘ'א^rQh[a&@nR+أ׫\Gy 60k0L&=3;G,J=U[ wM=XA>aH4hBV4cyrK+b(Ǿ6W!oq"8h28%diҗ4-2{K&1΍XTʌz)9{d8s}Kj/yčVT3NK,)kݝcLRdsl5Sʚ ~]S# t+PoBܥpFg%7_“3쨰tʼn@tl;2dqFY,u=Q3IPgsZr|h"vjA {<ݥ<ڐqo-!Hz2c)$DyaX47QadCv1`_Kc7RaO2PnKT Vc9F /mnnG@ zs1]BD$jJw$uͅei"(YܬT.Q_aI& {BpEjq@O7:?p.%e]!9CƝ"Tt%ro_ [֛Kx-TL3!96.3]GrXX, BTq23Ð2ueXF-#Ϣ:nxEslS`jM˖8oԱ`sBXBc u+8Ǘ\fh*:9^dXC.~K2e'Ǎ+aE EZ5أd} Cݟ 7kRӑ26 -h7Sŭ3U pݫh!ϯr * |օ3νc 3YE!S0lF=;o# ˶&jƑNAD}{+땒xU<]4Sߧ7 nᘐLw*yˑPifYzPwqԆ^i e*NCfnV&sd|Rm`X?冘mϐ3nK8U]rŸ8]D8]?P{%ғ¿zegoE# ո\,(lcx=۰~-GR{K߁ '=V7i:s0%٣ /QT7i6Ω9:ޡ"\5_(9VKQiR>_@`q6=)쒋60bx,4)2o.W d? =q)de,Ǚ3y4vKU I*`ͽ#+j*M>s;h]ɋ[GMX"Z}pcbE QGVR=¤֣\'ˠY[1I_37&z» }lt(Ƴ[MO#%Q<](G!=K0$`:.[=M1Taz-,f2@'%T4IQW5Y%̒ VgW)ʘ?*e '+&OXc–'W4 Rr xpz7_\,U} }Tk{?mȚs(kpL]_:3f6Rr3_1+%?[p; AWeƟ#A)fHE"\905^޺kOԃ)vwZ$rv7o>eƗKPyo4 ( "d~w[ݩ4fNl\XoBztbh1j,F=61vEF}c? PTdyb x ![W[`V VΏr3f(2}dvRFԼpN_訖B!(q%d%aLد*Ɵ29HBBqkխyBcN}|xEۥ W~ J5$PxJEdTZhLG |!" 3γ˶b`M'pٰc# 츈(ϚKtSs_%%nlHJ.j!\Ve8xJְiκTd9s8 8OR [ A!t+MYW~K%uwF:Nj?&C1ݴ ?;8Ss6aN[>s;2L'גnR O BVIp@Qկ}ٝD => 3\: B K'$mcA qӶhb[-A㬆^5ɛ)a }ϸ=8+EE&CD㐰+|HsxMfr)yiZ@Qu=ʸVbN7ՐoDO0X㞘~CѶfX6 Fg5X.4/. 'ɐuD7K)yåv+w(>䠐C&%$ t"ڧ\h&钮CSgtN z7rY/@辚^R p|g3<[+ufug}A Njgl g}EĉZrn#U$y= KC!CG䦿6 G!/jhB_]ŪX[a.Nka"g{Q3gZFĵ[ҮAϐ6MU*(f0-4w^iXwK Ԕ2AP,<"aqɚ9lpEB1i}ΣkK@e}|/ qD_hs_ir8¦Cg<=@xaМYd &][~u_sugczyh׎;.aTȢyc/jAن5zQ*%Q+>K )<9(=˧;@wӿ WP>uǗzU3݌ x[>/.]h"V[,1iu1:Eck0<"#-=]vZ4]=),fd+gmoB%qTJ7^Fl>{Rbt}mH~Qf04>$+r}_ye\ n7/R#1ؓ\Јy_n2}u0>T>xtT\RA"kg<#p#T?LMo+GUgC+h&~~a+DC`C Do-nXP~ 3M\m\ J\$_:$o="˪s^%6.>-Ť~i#}J,_NVjmZ)-3wUqQTzˤE1>/J:*CSgi"tդ̰y`3b\Ο%& DyEc_qI@lCO\K3UncXv\3o30拾{) ĝĆ@:>Y)Pr "EUz mKU1}7K+:ŚB*%-.dohb-%> H]/%$Dy^D<}(:&:7<#D"ɴ6'Mi:Z,">Z-O G_n2_m<:aȟCz?(\dM7HdQ_GxHwX*M5S7W0 =FgN#ψMUNj~P<$aF>neȡ6r3qB͝YDH yhr!9Yp4# RَJO_UuåK`R^$6hSKDN: [ԦM6kvrt~! Q7pA5XR^)jV[E\cpWAMdK,4[`I'<շ6%mS$dC&%`CZ*z@*cp[<%g:I`NN|!:s CWf~[!-མ`N8eB\32q|PYg F9^ 0ubog;A@Q)t{bVUpQNJXz 0rM/aV ;Oc(u;yQ,\a97|zFE75x,tg'Cy{R UsWb]j\5Έ7ʚ]Gca//~5a&ait\MWmbwʜ!ܡ縉P54"&""#|"gmaEz\Y+`tǭ[+WdSkv1tpn@´ a*-)XE 1H(j:C/- nuerH"l"R~-Rz_!Fp Xs{J=Y-wU屴  @]@NQR$Ӽ{Uұ_^Q:w\]d|ǁM.er#q8` 1_$C+U-}_@Oӆp9Z+˪p*Np}]/(xy{Sk4d.AJ\v6I[f:d > gȻns-O7)Ds'?M\#NUԍ&>|;>}H <2[ O^a'[vx.X\8gPo4!s 1`͢Loʶi~ @'>qe2:3ٝ薛w>r6"]ňblIQ^K!C lc5x,\jigޓFQw^K Z AF)oM+L UcDvLl}oֲ3?r?>տ$9oFxdW_'bqExw0;kFQjV? oh~#w痡DLhXu`,=ZuD7THqW6MOfRsZ V˅Nt[MO 9S.Uܶ5I[m8,f5?S3Cw[B2`Yh+ϑ`F@g@r u=M"h2ZFwn-g`i6_m(1TŀxJu<ŽhQo=Z:li9BցAK,ZGn $PT"`:^WMA0 _H)S#QT(;ϚZ5i~fPL(Ҷgs* 0w AX!,ɠD$i>CһG3Yfa=sܐ3w5γ㖣is+ |zu;O-wъME\m&f2E~FdetHLP}ԗvɑ|&C/zas'?/8'tY[?Ah;)k}3#~hjf{qwsfp mծͅhk'U3pGHZ KQSB t[u-8ӏV# a)Gڇg=L D#e.L@_M4BO rh][HYt_zO! 6\5K(qģTֻpvy&'iPh&7A|o#!xス[ubPS4{진|Qd`{!N]>8p7P "|80?y:IZHG!qAFT-H  $qצ4gJ|?y⫸,cJ&yL"EɉoǞ.7%G\ Ruc7)Z 7.o{K4!{ +qR oe:ӭ 52ʜKxS.MJ4c%LذdUQ[Yat^:x2Iܝ\.nݨeTFڰWbB Z_ ر0\1 ϓ0kKp `]K6QVeP+p^<@]Y] %2܊c 2zX?gιZِ4k-U ΡXB0SyT0}vG I%K8/ǘW%KvczkMw;T3 Y ^#eX\;5Ԯ$$8vRźihgyUַ)Vms^]ǩ ?2ktQId?z1R删gS\#&!9sj(6Ɵ0Ȇ2#+ªMG\Zaw2deQu# P`VH\$)CcN+ x^#m9&NM n2{$z5))q5ۅ4Bex.@ OtizTEyZxa)DV+C? Vr{tF pI,S[ ʗP nɒ n}t<[3Ȍ|I972fWo$O9I$>s umgq$<( :h>j3RT P]+%js_q0SR|w!u85H24e>K=`Ijff#/5kea1$T%5ܩ=/+o߇žPJ&4IkR=)ٚaZDDe198sq&t !Ծ?!;i?ʎd%f:A@}: ?AKIpeslƯ$dx]iPNpC *SjDO]65L81K>3Cuf %4`!naZr(7DO;$%00Լb#cKZ[=Rי|\-m :H+`7 uɂU.K*6UtV]94[!-&*$af-o-sz`kee+g#ěeِA,0>w[)#5(OjV&et7+V(jtmIyAR.3lGPB̳[Hi] gSGhVpL=y9w,e0g"0uNS oWGX ,ޞZ>Bl{Uiv>j_1kx^j H|$fy_?Q*~HΝe#,\g%b`?v>ռ&X2FLEHXØ6R2"LĐq&tI]oPr"@:x_9UfELEf1O:߼cn]cUI47?M@ŰcѲFDbb[Jm [7 ǯL[QRz`F)9+ Lݣ:kx*MVî8N/;fWy Vͭ2 ;e5pY8f|};~KcY_$9jUR''6 {SSUrfj'oCࣱ~G~LYU:?PǺU!Ջ$[{#>rg$>BI:yDD$iw=#*MJ݄~6<}X5>#Ok &H(TϰSj`qlnmBUGK[<=Y}\@̦J֪*8"V&MQ1Y $& *P7>ߐbH3}.Sa+a5%XjN僧h;6va$K9( ?> oa#-xXK{}:uP!Pn%)kGIx񍪔.rnUL:=eg`偞!a٧dNY~es%'VsJW |lXK}:tRXf2L}ͷmZ2=|..EK;e-E s u@[{W$rTTx=0 83͆hϟ}XIf%l$4F#ky`_M zwUdvHR">۶?E y >[QB]Ǹ ^YlRzԇ H6Zɭ,NyBgC6[<-}-e+WI0·^> ExLAGhO2<%@u1Tmfd?IsvƟry{hO|!f⏀aTs'k>"rA<';rFU5(W; 81.rJ?N۔Oy$㰏7,4RWLĭ=d&U7vv DY?W5e,=پvNw Z+c^p~84P^$CΉ2j.jZ|FD*/,`pg;|)+D:8ɶT8dNۅщƳc/666S'$H8x`<&Dw8eH|V-<ڭ7'BYWC:G\[yޡr;?G"c<0$1iˬwźC7dsŻ!PCPvʋ,3T tKdHqObWl?o,I >+h_HG+1H*^XF-M:64c^g7zlS)Ou`|J*y"e_FܖُbN;8=+tIL$ۢG3asP mn+KzgyDzڪ\M(~<0m߹IFMoioA)%~F_{hssbCj.H +; `9.p-eA4%ceܙLRW}@mtd kup.+vNss+:aR%A#g: $ȅ0d%tvUbn-GpTvU_!฾j`5l 'lK\0h3AsYe79\%MYl|^[h9/0Q8t{L*ԃ|ä?Do:iA)#]d4G0AGHKM kX.`1̅p.GP \*\aA~3rf#x`:I7aG'g- 7[g|Xt?AV¨-fͣ-YƄ2h5dt~m۰HozFe'7C|gO3`g0x }OWTO]{ F~Wzʫ5/kڈ5,EkcPD*$Zeؙۆo`\ ptI^\#ad,w;K֤NPl' \_vmNqy}EyX=F ciJDo<~ū:s!-VVGH9!Hbя)$:Ч'u^Eu߼8`םp\*֗o 2`^hAe|ZEJޠ DH" rNRXl 0s=T"PMEvtM"~J/ ſ5K ~X~RW WQr5T~vtuJp"ۭ̑ ̉ί¢5 ߎ@eUpf[M.74C2MŽx2e\sPCdk*-CңOBW&G\NX= $~R6^@? ;ӚmFժ p绋7h@0|B'Dh.aSO'j^Z>ԧ y~N\'`/Ϳ:6"(=uil).؏qG d17MEu S~=u62Ũ\}O:>+8s[+$i4!Jo߄|a'ߒJ}X +θ?MM;p'f:m-sK6CAq,e"mmQ\j,UjZF_C/ȹzwZޔ?+VEm2Y-7$fDŽ,madwi7;7"6,x2^3Gk Ge|Wߕ[qׅO 6>(4%nl&m "`;MM@zDR  TQ ڐT)w+YӭISka?P6;:ƼGk̇QZ؀A ->>!%[Z`y@aVG0+֢nDYdH6j'qQh(񲖼͗iN8Ң62[R)5ED .]S<M+9Tm#[h}2  3O)s=Zp@s*xl\={Fq"+[9X~KkKRz647fPcmŹ-1GH]kN]2>L:6H1 5D7W ڠ)!6PU<+tDC >i1Xبj1Ėa\Cx$:l(» \+`Fx+mg`&U9u259\lT(/kUH5P O_ ڥ_d+;y/>/ZMC1⎃D]̥p$WP 3GA tEq!{-!WC?b (.jI@yol'l7ZNHƘTF30LZcjV9){4 +gٮJin 9((VW/h?JHIJTWZU+I_F 0̏mrGވ?qk& 2qYkWt//Iג<{@Ž`?li^t\L*"XH{B ,~#UDp*/M)7xxD?iE1Efc0Mxg=BJ&&hb;E~K;0.@i=lK/GOOA<Gn -kĎ=D]؄ȓϙ. vdUW1{Tݕ # =|Vhˆ2,~mdgWbm DW7-S_/\5~%Acrg %L=.ALDܬi+w MϏ-Ԩ|wgv}O@{Q. ¡ME|Ei?=߉88UaxWႛv*U$uSCoTr=WYIf|ߗ:B@-l99:[ q[{Bz?'N[9c~.~/3{Mt >>6X}`E 䯌0zL֯+q9,@BVYA[ViZ l3\OBEM%$ݿE2bOݎ|qJ͍,O=ӆ ..FHk7 66|( pӳ<lrև{VK_Ɔ%.E0]XZ0MyJ 3r{q6$8tf,kFN˶#,GUW3_)aE&#Ҡ[;zmpX,fYX IE\;qAĀ69AwVn2cs@GfqH~D{Z,SΌG]L)7`DڞQQV .<Ȳ*Tyj/F%jւ3",ӂ6+UCbD78+,JEu];Or[ !E"dQ?P\&E&DY\ff{ s qw)V? ֢w#픾|]D¡ 5fvĐ0$bZ ADu-N{|\r68o]src}xr;bL6bE7wCP"9TRS-r  _yYC 1k]LfƫwYV0tite?("fʥɊӊ-Po}$@J+u.8ZaKP9`,rLttR:rwZ%hϋ0N>1S.Opu!ljݨWGdA ;쭚H:'֚~|$`r7s2iֈY9A뢻^>,O{-2LrA딉ƊDA*s%5N\ E& diTOAV0O$R_KWܽpZlƗsJÍrvȯeXJΤxU&xE%y.ӓFP8~*[sW< x66(Gﶳڧp=>UAQ >}>ȕ1? /`^_s%l*!:"΃EXT1@/Dӆ9s(1zSrł3L@- W}.QCX3Ћm9}oTow9:%3jvi1m1um迤z"-PE"]K%IعIXZν#_Sbf4z7 NšdS.$ӚM3\xxsϜnql㥬28~8H~L@a ! q~5 8\-%L_R#XrftղAlą"_j]+F@>FN47a f'd×L_3#M_5NGC2kgP zzHKPĨcm~G n;osV%c< Dg,pxx*;Mʚy(k]5Y~|7ܦsu1 Ya6|$w=; oEI(Bs~]EP]󘾒XkP& P前 }$ bvmNS3`jD^5r?x6qs)Ow$be0.M.x똡ps#1SeQ#%bc nf}p<#`=`9D  #NǡKVL ;0*qkhq ݎmnX>ujp-TGyغU:owIۀn[NP+=xḏ-)wso{R]̿q`š =b QcVk4d=(YdY1Pѷƛ {iqi]OUo`? ȶu[*δ^R}$Yr^P%qM' "x|7,h明?hOjn|?KFKj}aLަYX9e(Bg5uOeᗊYW q)}b/">#r|rÁW,2ĎnM)'&4,^(c$A#9uorP:)W֢WK8lcs4Vd9*7`pD>X(.K4)^<5[a !Id"va@Y$<kG$$SL9߭ ̀i,iUF_kN"ֺt"H&X +> "M0qVa}NA̔ w?G +i'{5Nlki_AQ_TQn畖#8_``ڢiCG* Б[i}M97\Ab‰Iw`-_]_f${H91noۿ:ti*!r#{TO^ôy I(>c%CDW D\y-v-z9v΀SyBW~xi W#?p*Yuyg=Lյ0&snj-\$ 6x ΓxT!X8. @ VkEЄ|O0!Q7KpG&px% TM?v\i1K6YL5-uBU#ך*ꅕ3/^'r&e6<Xgռ 3!d,ϛz CH\;J#'fRE=cKy/*V2xuT3 rs@Ӕ?3F[\|ENnIo`e%@ Q'h!Qri*U7`N@}seTqދ5ތBO9ɡl\· Րu_Fn`+Wnqti=8>21Uwi {TnP*lHh [4Ⱨ~_^b|!Uޠ2M%{Zl"L 9AuiuyW̗};{c ^UMN;FT`EP8@/EHwMWt.,pB :4k[ޚnկk|bN?ȊUp-8,B*X5Kb}pc ϠxpUz;Xl!^0ܥzFtJg;4U-1Rx]m'u -y㑯c lQ_P_~@.X7$w@W5-*="I=q?IvSߒ|c@K!*&ʅKQ1˶]/5*+FK-r7ms/XK:}ڈMR|ft]}Gl@n>eql NF:A[mrOUih?ֲΣ> 79p)8s rK'ǥ=I-SBL(; ˫r 5\B"ZFl’i @щF4C^Ba% YpW6$yq* pcrDD¢kc`)a:`&IadN9zeR 1镮ł"ÙQ6")MVFq2c챂4,5s϶}Se[;A {i;dx: ϽC/;z-'kQ.;T>ͳ'I:)"tqq.c /K>юִ%BiH"4A&!8؟ KdŸAԡVX'̤5ȵwlbic(MP{ۯ)9*٧a8f$BkuJg0lŚ Zw΋nŮ~iY2ĥMHR $u"r_*0xAy$yf% 2 '$iM|2M~h\b:UnQȶ|]7Z&>a){0KZS.IS/ʣ;RMC|YKȣzh8I $Pg 6\\:DXta^9 %ϟ:1`˄rgTKyN2\(vn =i,X] =*c`'2w 7$/5G0Z'RUwtkA5sǼڈ7$)Hz֙eM} y5$lcx5XaR3a+()(T9t9Pl|28ager"UėnǛwocYUVU Ri(gw.c b@$9#N"1x!n-K.LWO+Bu6ɐ<$+98.gn3_VCn[ikM"aWD>G S1^'Ԗ#e|c'X\ȞshŖzSr4kl̍bX7yy-.i,iuHLСٌ FHu^my ;-9/>@EVUC)?+NJI^FyDbEz(o>v1OT^C;ѵreّ\[KVNBz"-Vdo {YzVJЗo_>Zdi;!tNku RyX;ߖA*C,PIR\`[l!PL? *XKv+ԇߣ;=w7;ԊҒwnO3 D$0|;qc-* 0əEe gZ x<2@ZfEE^"v^OLxWRs4 MlDQ әT1ݵ0%eW~bT"R y s)qKY#ꠙ>HNxHR0\CL$s.洌k`zȼZxM8[q̧[eUq\3qdSbz A9.Z\F&}c/FTcEIjX?dny,[Z~" ~|d2џK #hΏTb,%X{ޜU`E+7\PK4F]aHncRO={3(2YYʾ-jٮ+{ aG(զQGщfS4-ߜم W 0LN(˺;a8"+ɚָ텋(BYw!A^jk/Ul/4ӀPڢ?{K3 0 Ad=\yQ yiCi&-PF#t 58,/y _HEU~=rp~Xr&2͗3)nF3%^;'щo/l4!^B1x3LѯR 'YKD B9]!.8BN}~in>?WzwSV.dokw>M7U?k^y(cP#=mlL/XRqlW@1!\oX|WawZ}Zf1 ۂFPlPb9`'Pٗzuwy2@+ճkܚ屎2V!!IM*E2 4 hwm( ϜaBdQTt4[UBj Cr\\Km{8sf=k ܒ*dd~p'ԩU,Mc!FwLY,|5_HTOJ9,\n1Tv|E54Vu~Ԑ6yA'v*V{6Ez4RDYM8yPjqKҵ603h[Rco'[䩙JXgq}lV8LQhVޙr3}yS>ȲcHOY Hyː/ľkP8(],HS WK Q(jlЭkZl lx@Oc7 y?=(ϕ7{\F bLq9tPY*nWncf.z1:֍Ŕz^Zi\@ "DLm\kD.`[h#`("reAIJGw#%C{}U*Ck^f6+ /Φ1 bokҚj)0rƛ ua BKCr}Zl_b=]3[s_=Oes||,9A#p/ͭa0MT{3/(*6#+MW[.7xS4vb~bȊr<9PՖ֗)_8ξUhwۅzQffؑб>{9Ìnƹ8[~ٰb 9iE)[Y30|Am6 +[WGX ƦWy3 HcU#αˠ!0gP ur??YI^vj-vLE,JJ%<s-Z؜Ph+83ɠ _GL6dy蛹rPv[2NJ 㜢6=2_Yq[(xKO%Ű 1i=$s!P?b+=~n,}9awvӱ5Qi5U.X VFpcVB;,M,=ĆݲB7+!ֹ.i# ,x"p\V¢O6B al7CK:"Z)=q-0ma@T-TE3AahwX#%VK>.KI E_*FnxjIIꦗ̿! zN`c:cE)) 6?~D'PH7 Qb'~7Y)xZob8]fNB>"\bb{I4:ɛ{+%'{h~#IiyM]3Fr420(` <ɣ-%Fpc'<ѬvvϙTj'}S/Nfo7#O"~v$@1lU_e: Kb |F*@ft$lx/*y*#Z,n\L6Vgf56\,"g]9 %e3zgǶ^$|^.$:@EwiNarg¯ڲ3fkV᧖'0m *KW׋%bDd/[$S ;?A26V'-K1*kgL>Ux[pJߐnH4KRQV_Ccɂ*\tqP3(5D\ݟB8A}oRWmyBjOW_wY᱄ |:۽AׅA;FoDq%^3oG S>"8ɬ{QK%2?5m8R\t]TI }zDIyV{n3L9%<&gSUF@u<#rtP|'grb{ap`HҖVUBxYnLoDŽ9L3޻/NϞHh?q{ "ҨHӈK1 ?Fc<-ѣ2Uč&g< {^pY}6' a\CX5T.R[QK$6\}FsGkrṚ# Gفa&XtM`"ٗl]ܛ3Ps t.tv|Yb\yF!-K=:֒(d:MxLPa֠?dÖYĴwhɖL,b'q_8U{)h_70!7JPF֍y Av;kҊk5֭Tcژ%8Ⅹ8D_sˏ."qF؋乃`\Y vl SaRLuJJ} 5znՀ@z')~FVh:a|Cl&:wR1*BFt0j؅GY|pr%W nO"fv a$୸sЀ9Ъ{U#?-DUds^KVݿP].ygߢQV+v1Hr~$NX;wƷNjirr3_g<#.v׿06,$rwns׋.UgfF"wL2V ֙[ni5ۛZ;ako}Y"*lrxWP٣nW$5^Cp{BVb.V귇 @][Ey9h52˥$.]w#@e8uGsXvD4ë?@RoU [ԑF.a}`0vMV3F"xty=OנSC 8ѻֽs@DՖWD؋'_hdP5XV_t*`b/r_d% o#Y[.!86%ⵊh ;tU A ΀zekA^%F?[KvUaUQv!MxfFɥ/l@Rv!BwUݟߕItcĖBh|wt/!9ʐ/-%RrhRW9*8 N3SF.bKMoM+JJY+ l&U< RJl:h[@O+ 1xO M,a ;:2 $[G $><,gmC33Ro2.iMJRq71->m˒/p)@6$s?T$:LJVŝH>8**b՟4z_8t qʨ >I(xt٢z.?o_^=b^FkؘcwqooÙ=~m >{UZeX$L~b$ 3!0<]hmIt?nf67- jP-A׾4-P9&-RMR=qbD!s8ӌmK7sƃ~"dC?n}pz|Iz$Ģ>_㵮B%-zu&bLFZ!R?Ҕqt}KCZHzWθj=C83Ƙ^|6#!_fn ?Β#mk9lPxx 3$>wqkED%KV2XwtȇΜ84, hn2# \BDVFDoYȄڌ#`lǛ'e57u}">4maH,çyzu4/UސLOӪ= ݳWUJbXQ}+NNnγ8*޿^1xΈVK4KpS !vm N] @rlI=}sY y|67S{&oz;{QSmcQcd\Zkο-EruIFK2.6p*_'&mo .t^vLRy9Vb[coy :]it )׈2_p \w EZl6 =C2Ǥo-@@-nfÇ(-*дgm"\ŧȕL{ hu2`LZEKԽ/M,& /8|1)QWS^?}$XujTAyT5A}S,U;R=[+3QPixȱ@bW#i>ӕ=:OY5 _MPT/kϚ k [yqLM<,xgxpMro)OEo-lr><9*$rP ڥj8&%̞ؓdD/#NCDNqᯇhY?UPQX~oG_Z[|7[b ly#&-tq j{M:֘75`>#솏^D ЗZqTP-qG)z9zeNwCsSp>Krƽ5cݪq_Qx?kC?ۏBbTE Վ`a.l b2x /e' @lԚF[5k.,CBa8`s, kP,w]DJ{MKB hŷ/@z7˙u|3W!"}T0Ў=jjOM ;=eWeujLXWLF UYٲ6 aUg}2ǚ!+{SKӫWMu`-lHa SjCbeC}qF~7E nmFO}I=u:ԞZU&Yrutu @6&aLJx#//d,4i*h%9V4=<WU~I#_+e~qf";-Ҿv0rn2r0dB:g iBg h'2@ށ!1\ D{ƜlO7'RrcՇ.9 7(My-_^E! /|!kHU1FŝZ 'BEs:>>r, (u "YBP]S>aZQ(,Tw=ҕ2 4N(.D=&S MXR "@P8I/Tso'~3|fy3=?A]֦7wS:-D~Sid_,@-a'ʧ^.?֬: |$D& gѢ^UGU)n;CzԙdYxiYNj K/ iCN|:/ֿSlmGͻgek %Q! G=f;oMksP $X^O~XfXOeq9:$],>n VUT[ړG ̎XP-fViiB}t!ڸ7eASRZLFoL㪶}JD t_ mX{lଲ.F}$+ wKgK !::}ש(c6 u'DpDaN?ZLASH^;J|Wq o3.#4_e8 ͏ˑ}R!Sğz] (^(6 *DS .;kknq ;yH7~kn>i>M^z) jkB~୮&Qې4+FpQ3;mW Zw(ѹE]#"Ek.V 'zz4Q#qTƆ_C'pY߷}!Lf8ֲWI{d#RePG.O&ag GW0S@7<Ѩ@Wv3@lƹg Zhf.~O.Ek="N}­SP"_[tGOJn7_T;oX~q>e'B:eY' 99J S!3xˊr 3;/u'#,ؾ OlԌ~aO UtTnw! Ϫ7k{{V SK=;rʛJFlrQ4\ R ROS3jAL yt"z3 ultZҒ"QWNeJ7>:2k#yyNkq y%\5{~V ȯDK*bu˥`'K{QUj>x Fŝ [,ۺ[rU_~*Ʊ+.5uZ3ԤEOJ'Qlߩ08NSC8蚊 Hy)h됛1G]ʠС״ֳ Bv1bi㡗$'4i\}H5i*|Y9 \$9la{arQɜKp, ~0a{H BbTO!<c*YY~SxkGf]ԙu: Vqr>5F犯Y*Mw|p|e=:>.By8I^N58Ig![yx_f_;t[⌯B'h.0% <%(5/ 9_9z>Wō c gm:HfJ_??~JR싮~Kf֛JED9yT̂qB<“M}L2>*b GdĸMJ+ HTGUƂ8$~(OIwU2PoX^3w+89h-`[]Cqh:* 5D]3AU9!cck[<  8$} xQ%}PڎR2s`SAm_B*' }vI[x\)$[Ԟ7j.Ias[/Hl F0${ X5vs0ތj#9= OpX)i_67[6KTE 2#f~ Z*Jvzg/2_S.P>Y>YdӾFǔz m/2Nwˉ9J-LX%{&P˵ԥ? @{ Ȟ))Q?Ѭ3bm7w,>llukTOZ`wB 95lym՗[-R)8u IHc=3*MH3z04X Di`XwFnW-oH?X O[Bu1-` LmFe[g5hsh[E͝R37pC:cE\'0+7H ,#\]& (3q1yr|t\U/m/(Dζ:@tE fcJ.[LvqQ8o'Mߝu KRE)(*& DŌ&Nn㭬!&7 3IR~=.}7|,Qߘ;G)#=B:{ўNafTeZjFI{wk2A-F7 hRk粰z_9sSg ^`R2I}1 Y9>m3Vqk8Y;~ =)I% U3Ñ Y,vW AZBJv}Pk;yhX>M19n!e'zQ["ToM_Qŵѧ_ X^25*hR8d6%ITc#>z1A˛Y. <{I!gudR)0I , ϡ[;& Q1k#-;iW8 m^Y]ȓhzLMN&>_mz(瞐HD+mcg¾b-TdfyF B%DŝDTp @%u_*a#^Lu6uk15պҍ4ֱXǝZ6{m+30 (~ULQ~ MfpŒ˽nf/!\[b@EE`W]ÁwT|,\RIQ+%S(,U?< hH#*؍`)҃ՠ(QXz<5U/.,:0`?i5|mMEd\qhkF'ג*HuY(V vG󌋎a'%=!p8nhIڝs&Gb2g32S`j[ wk΄n7R>60 1. U'=,r`G1$'5,@'\¡ؔǘ^d摱[2e#uTSE+E '>V,@n/ʏlK6 q 5 78f46R13-QD%^Ps&?:)#3nOΆN:3ʦq^Hl3?b ,I~22Ryvsܴރ/4tdYJ}3E jE΂D" US$yխOlVfS)UΑT-wfHѲYiޝ|alL"k_ nQݛxͼ1`Q)YYtU;{Ri"* G&UG"/^4 5H)uGo|5ǰ0`0S*\xDpQ&Fy"b;wpv;4. 9)]Ȉd]7ޯ(݈>6p suq=|Wg{hsA+tG|k 3B|Z8jt)v㜅PZE24cW_.[jqX/9W]:|^D*D}L'r?C2^[{T˫m^+%u.r/Q'p|钄vneIPBڸ~UA 9C6Btw?z'%Z5 ;򊦹@+*@C7uY\wP9Rj |\1.|: A'A@y~zv!4c~nHPREWJUݓⒻ8[ij_#Jt C aBSO}{SVx\k`<0Ih]װ@2fLEtA뭗hϦR.~{{вz.Fm'{YlNGSgUR@ YNբ¾LhfgdIvzq豱vr2`6 !3Twu/HV)?qBKc~9dukaaR A8KZepH\(XAeH)rp͡.@6<ÎiT mTO}S(]c#_="+Tʁ#! MI-.yۺ"{ukۉ5-K#"oYu:y >SYFPZ^[-((9_C7ArÂceB[ ;`v%$@/mۨ1z ;4x<πuՠ{\PrYcmʐ||ݟ xLh/D QL|54IBr5t5r f jpl6'PMq>Y΅뭚,脇up;?0H1@>`ȢYzvfZ |WGR]XRO9fm0  QɀSʷ_)7/<;|>= O˝@jӏAW:QʑL 0e&Q>j9گ҃))Bljtp;3nr|}#ϤB4|~fGur6$bHde$yX]aT\rq|őۧ,Ĝ8ߊ2cᴽ:tؤb c%a= I3?Kðt`k)8$c|-E$ <^s8rAdiɾB4ez6QA5'CAR(X+ࠓi 6K I zhYA!Y~H1<<|wa+/e^ʿĬy>U)r ?l/TP*L7xy:_swfEAa\(L2@S4hhEީ3M,ѯkt}43f6+2yTĝ_~nԾN_+#GX )ۿ "xgdu!~$kpLJl~˥OX LD+—=-ߟ =e!}$*W Xk6,ɸW$sOs=6vw34d@8 ҡ`!D ޡ91W SNCk_S@˝1pD5{KgO-ApIJQ@~ LNA V;Da3BLK ž-Y ӗ|J9O8dĨVnRaYXɨli챕X*n!)[0!MR>Wj =:7f [RIKp;cQ9GRq)E'~ Htk1L߉K9q3onߛ}0M: `ҺNwC,;1_UkRZ ƼG,~_@+ [(P6o]9F񶕣?7Ma fM)q*8#\hrxw|cQx 'b'":-M-vE>,n%r+ -xJċ_ZŖp,sTozQocؑŜejtRQPla ߳`z@q ԋ4kR2ԙFg@eKiί#\u X lnUtWڜ#f~ewYad`WOqVy+ʓAX)%V:ye_@d_L6 ͝mmU :2!F ~)r|vyۃ78r)e/eso-vrnG:c]q2 L_Kr9p,s@D|8dMXzYT۫VBGdޣF1"ҷlyqeP5u3k%UnBcb!g95 &G"j@>LDy0,7+ivHnYMѲx^kV=a)2#ܛ!WIaZKFkIKf1*9bmaID&W$# SN3a{3/2r7>jr&Xd9;ݥ!vTnH+yv+? բ4bdg60|Ql &gH4UT i(y㺖h<ޟA7Rԡ'Jlt9t򸨱igL սЌGnhL%N|;'P6n"2Hf3D8 8V?Գ/ɺ"m't @ gʴ<6w/a2? SPe@U`"jVy YF\T6_<.z`a,Ū|%tA :8Snt f<-`n$}قK( Cp^h]3^7e)ա,M KYCF'>Q4o\[Zi(|yCxONNݛ?C0lj6'zBc >Vww6;%Ķ7߬pO&|~Ő.|cSbX*>-ƺ(2Y4gJ^䢯C-׏_0Gt%Z}fl䨙CKy)0޺o}j4 [E8XUZ1K(k5WWi}MhyRnO˷܏[tM 6/,]0r3 _7'y--ƒf 'jYSx^xz{DiTC a;[BSsg%$M/EyN`Bky?t^mQ"n}pƭ aʂϬ9.ñ`f3GMGC!T]Ų{.6u:߼v+͒H./G ~"Hv܄* hLaҩh2|+H?? ۷e{`~<}Hﺏ HDz Кɻ$%f"1cݪ 'ZyIE38"Ս!8G-)<`lPYYw9eU-+[V8 \Lt FPxH'߆y`V>k)L=G#?zÆ05UvIq;+ q8;HO;=`saRLs3"9?F6%,qmoͼ%)S9Fo;'}Qb9 UzhJpR?".M*zI! ϑauw9!B<e_464_D3̬(28@h|&PX} O %i$/kԿKhvT3 k=j;+9 ڭNR* (ahxbT>ntNXo; \ Ķ쓝蜡~F\Kɨ`'n8F뼣sgaxK:YxoS cc!:&./Zc}Ca% xnJ303S~M1YPw/S<TmKQE{B$iK.+wF!d4y>9x\ |~ɚA~1o[wb}grkJ^O-\)Ɯj8>_Qȭ!:4_btY8϶ޭ({v \.˒*ٳ|.ݲG=G9?CJ]83jNaRL4hٹ"bٶXv`pc} "y9(r-9\TKѻUD!b2Bz>n:LU q82 M9h>Z` ٱ[z oB>#]f7->=B^HqWHdݰNP+Sm6ޜjW@"4Fs ܷ,6/e6HGGo{l9 cKo**h:Œ 4E'CѠQ]k0+pg.}A~ˑo,ZzǺYdFxZW#*, Px(?ܱtoҰ= özIJ΀PVF!2 =d9GckS,j)ᙞ#f2=ۨZ:Gs1Q-¤/ڳ#3r6߾B}?З˒*kBީ/FB6nV$  }Wv1 \y5e)i/e)1dI,B-MX":nV=e|0% 8LHt <173P}OC`e";z0V^G }.SL #LA)=]b ~s4bcΞIac}=P d,@$Q%irYɲl-]9LnN_!,%Dk.a?Y#B:nPdv[(pqOxsᴺJ#zmZk25-\8Լ;(Ï?`U'!;()DA!"Mh7,%v)4ɧ$gM╖A2z JIPlvG}HHcѝ#@tL{ uM(>/x{/`͢Y>D;0N *3i$׷}B%xnVr:f:(c4*L pcY׿+1^CMzl*Qݬm< pcRA@04:߇k۽'- ?d| sa#] bv:i`OwH#㗃_d_#mBZL I^9Fma&HBv6ql!^Ոzrw_3ֈfx%ww D0kSڽ$]Ψ$d&ՆP'"$YTDl]۞lxG:Cu/FI@Tdr~!=%){Z7݆ Lcr;p'<\,V$P]Rhe2j>|tses)p(:VHDfԽ\е,.1[}F@Z{y^ʝǩvgZ#ŝ2umճLB!0&?Tyg Fa W%rX=-r>)!eSG\g1=XȧBw=°8.X 5Ȋc\t,ZA3pm˯KTtl۾&O%+7ɞS7)WBKe0FvΔ;W %Y10zk *s";` r`8FsMp|]¦cjV2_DVg"%8rZg9b`3;NFEo z" S]I; JXG>!gqW3 a#B@J&=\{&|eh_wo )cWoḧ́[Xn8U _{)"6]P+?Rxzl{6)|8'q^Tu*Ep=JdHmkl7rn0WJ,Ƒs:rG 2EV% #`0GqojSPKArc|ɽx+,A>^MT\:vllMDlKKz`b|{؆uCh̨zHW(>壡2a-MrtG R|(`*˹Y(޺:hiQE,c^}2$5xoaeg5GWexJ hgM~φlZk$to^֙ J&{manσϹ @zQ60ˀ`|3G`h#|4Te3 btr/pnuhmdXfEc (BYUj^dPn_B-$OλpV qvJ捭:kXBc YtK+ʃ C?8'c.`نQkKu튨hec9 0)&[JwDXInWӽ}jOAZq t=GVϘv݃^<`^Ѓ9&"vstЖ&o[K @|>_PK5\+= .:Z`fue;S 9&Vɛ/,P JȔeݽcGfJzIn":ZƘ@Vtu5:C]oqKjL3ϺyE"XS sG]^j!N,6_%tkKէδ%h `<رo$"bizwIt& 2(>\^?V 1m/:rQ-ec3`.@<}; {? C׬Øٶ|:<l^4`H?BE %QA0\rH72hyT nS/v} ) CB܀> ­Kk" DzqyKo@dYz`Hx*빠/S@soc|Š/ZW`}-x~b6oXEֳB&ʈcHܛDrĮ5A_zY1|ga~lt Z]\Q_BF!?uWJB46s$9"2><@7hܨ?-tT*Sh-F kϩ,bRš'YMxM3H''L}D"lD½R$dX"Wb4RV?7~+—ׇ(FG6i,0l;Nq Q ퟻ H&/GL f Bu1>5?qUyS&c36 2ދ$ӄ39)L\A艡n*0mcmn:3WppK_Tf3B8U͛E&ԽF5-DTՐWH:Aw\>^zz~!F@_Y*lOxHA!g.(zʀC偳YBWVX `6١2Z(#RFNPrOp'n3UFew#'E/Lт5O mP~ u_,Ÿu JAir7@ڠɸaaAF Y#ò#utC{Z^"|tuJ j?jeBHlӽLNhD%8)(yEA) M.!QښPcTěcoO[oC;cxZ57AvJ .[4F~ZmϭO[*2Ne8?%ܯS:ؿxNgQgJi2ڢɮ^GOd 毯6nk,ʥe]!ԁ']9 W2=nim<{xs%0:*?/s3 -<=܇9gr h'&M[맕AGMxўyyaۼP#a3=AH-$*VMQhzω|}\*KfD+K?rg6nnb eLJX,P ,QR,%L(BFW>$Sޚ>xxZSqY$Cħmcԭ [& jNPv/om>OhP7A-#offej4aW1EK2m]DOh&SȅGfˑQ.e N _ +(V'af|go >n/Wlϻp*'@w Q2 G4uƖ { Z k %(PkJG1p2Z4t5\n 5jGeH2}_L:ArHAuдW/8z+<$B*|+5uqcF&hϠ+ffli.h^݀ ;cLCl4w2낦PUńQ' 9Fa>Y83vEW f Нk4}Pc藤|ȋ?/3<{GpFgF&O879j#`1U?GEԂ;23p\.~*=N2R-x #8d'EȯbRBL6+jxC;dTδZ$x7Rʕ{{9V 6+ȃkR(#!TOVRیKPeywJ7w0[򆛉x3"fGkg g :,i1qWުtMMņȈˎ"vM!/N1$a9ǯ[;H-6)4אqkI`WBWOU5)>>Q,PZZ#HojY&@wA4uru(R÷BqҮYq(.N2<e⑑ ӭ]L}ܘly ! J(}rKz>([rR<7V7)|\(Dl M?{\ K?Zr;TD0M#Nm"xS$1ktL/aVIU/, ؅3'9CD>-`VK7R>?!āno35j&¯h5]= C7QG7G}ڶ4F&a6q_ ?ɂǦ[Wt>z t}Y_D`P Q;ݣœ^MOC/@cz THuvy>BQ{D,? nW_g,d=o{fu}< zg+HC)^$Gb="vՍ~_YUרGkP?yFt#.ZٕIV3Q3B,7:XȿҕVHdrTrƜʚ EY3 1dν(=F*ϖ=0JgVؙ*/cp.b7J{ӭ@Fm)ε iC(!hA2u{Ra ʝ$Md8x>zJ/^vF!Y5i_&&בq_03:ރ $#;/ [g /n?gg F(yQ0fn:%L ]D`7+0:[+x>f[G)1[ub.UԞ8$S?yڜg^Fm9zs ٸن\Vp j9a8r)Sۻ<~ wcoS5U"BIQ2s_&j|ls~Q>ʟ3~ۣi!Htb *ńu\ M7~䚄z5Wycx_Gll|.oVg d(H]D4?RLˀx@)hVGG8KKH,FF~~|#*~|B )e.?Hv]$<oHH*p~D#yG?Ϋz+IAQ#e;+#KG祷w"H& y)c?R#>')~.14RܮZ U͜5io\R*#`e>wMg yV=n7\@$k\})<ިbgZP`^hހNJ̓vGQ2ۓ[%M,e N!ZOHz+7*Y60aw?'C tWR65c\' - r$[ }B+_qatj? J|`'Sψg&s/+dOu] `!R?kPެħM,]ɛSh7)9b4}!9ʷ=r[n]'ttpPi8ok\eG.q\{eۣeA0F\}ew-LA _i a-9t>|m 6ExbuasRȋ!,p TfI"J3 Qr;3 LTCYW !b.0#ђRͺCю%jx|Ӷ+L,<2u6~:74TAnIGR-ZgAN:~FKD[qJh {ENYMGq),Ȳ!(UB@Y|lFD~NqɶkZ&9hl<5R Go^v\(+*:+h`XqUd*^}@+Tf]_;G#:7ѓ[ \"ӫP{?G`9Ni,7oly0fpY\=1 8+SE/CB)-mC`myv{>G b, 8Js l,q\cECH|`\Q7<)sukv]gmT U$u)XE0frV9޳Y,2~1,xɂueJCr" IoȋI&a4hejZN=DS,)4tOVx|;΁@|J9 - OLʰ}6loȞFe ;iDө~ٝϺ~T}l>F )O_vMX('yF@G Ò*g ”_yũ hF}ElF~viK<*d9!BT5בFjp/!t @Ɣ;9H5HNig˞95RpcTiwTR>Yؠ_n~wTMh|}fB5㼍%* π6<[Q(~Q_i{Gjp+mok#p*НfNcN T¸8[0EǛ&_S^f<fq1!Sjm4h+Hό dv!NnH D@m ػٖ"F/?Ԁ;n#rI z\y'6Y.H4@-#:ԟ[@Lj?X&&hS. wdCIꂴ0p$em|iM OwJ=49MmX 䞛];Vz^ج8F}Tu)*G6ȱm)JXBO(-Cf2JGf;PKY"3D4l =ڝJ6^O.*ʗ՟e Hd#KQ`h9gnʹs/dl^k#}C6ʩO %9TT=SIRy["+<>ǡPd,"e2#JQ:%=0@f)Sj#Gs nd 1҉U&}<p$M+8:-`rҔ%W˄2.@3*o%b=b*",XisoI8S>$FXr,1SJ<FR?]DyE+Mxy3}POmJ .&V:hݙ3c_"1~hPhEg#+^e 3<s5c6o u}[5 &( лp_Zn ?>zI=5I] /: zEX2V2\x #qjuuMtc$}lɶn/JO4ʪ a;׸!< EqJϪukMRL` 4j]Y@^>TKiD{e6uJgk-.#/):gI]iS<dqY$@8)b j,%!GI4W{xkQNw}c&?Ɔ/nnGM_,`|TEuk LhkNdƑ;};<9?[u}?pǷttUxImDU܇i`cE[O{ RĒ$:),vYmUTrѣ \Tʐ/G=@b vn6BW0r9,,7I 1ᙡXS B@]S}?U +K6|-B /F"W;P\#K|4k &1@/uӣ=NJ"Iͱ7P[cX4>yh\mw8OrjAS9{H+alNq[VRFI1Q LAv$iE=FFRLOdÐP*VyN&Z.N/c}? 4uca^=rx}1PF3S|$;W4Jitm9K@ eܹ,(à<#lHcvsh:nV+.Wz0* Z_IWpD-F("%Fε4ecX=\4::*T!ah Ovh[$SBqp:yDff; mV-.Bb|: : j1'vNױ^J& ګ ^NJj@w*:c{C-G ADFh.6u\tĹ`JIs;__ ˠرTMlV󝳃'ؐG+3b|4k!3zK=?U`s D_(+m0P(sZ] жz[C$^O)ª◛ ˛ʢmJ Y[b;Q*+BQ‡V)XL3e}H \唷]>{٠/AڈnՀ0J,K)."WA_MpkF/7?J4 G'ԡ>t5ག9$RmI1P@`zl24#,Ҁ߮2a޶|x'4{xh5(q9b.wj%v|g{3a f>B $X.7Ⱥ^N0&jBu+_o@:Te?-(_-v:wRpYB&AYG\]()nynP.GbӲ(1s%Z/Htr(Y,qH9;b^OϽET[a Vh6mprn1=)zď>3b*>Ag\~뀏){m=}gkMAO,\"Q5_I+VwVj<;, Yc_Džh 1y Y׃srGl*ߘa%j>9S2 ʈϪvN!FL'4z6 Q8MAx΄ŀN/WN '1'Għ1g۽ C vR q U!EbFҒ>@Cqu dxJ >:׬qAz%f3 "fcB$҆tG@Gc']c,*@=xKHLq0;{LgNx 0餑@&S[ÄM,88ZWU? !)iw&Ꮓ R~;2q9z'h˔VfJK)5#v_> 3U\ )ϴ =!Z^(+ wN;@Axks;ƼrqL*\aM,4NEK_4 -. L#kΟ>?& #-# ]}?C>Ry s>2o&34Q嫟n^}͋C/'mLylR>U~0&VH2sL'{BH/Fz^$?hčLVc#J ڈ<psgkkXnQ .4ǟp J#a~):Ov.B{Q91N>dL X \_wmaZ]| 5bCej@p 򌝣xdk=di4B),{C͎_PэNK=x܌U03|5A']U<]t4YݐTek6g$u|I.o7p[RA5 C[1Ұ2ӄ0;xI1I؆- XA a&uՒt}WUB|{*z_r b㵤=>GZ.a-/!ktSN pc&盿Xo*#?'ޮ‡gU0%O TP}e'cM%j8@#Ru{hxP5Ua^ЯHLT5XÈ4.!5Gae>]2bcq-hjr‸ZLDʂ>?ƹt}tZgk? c:XV$3LfmQpYIZ⹺􌥆Iej ?bkzރ' +9Je~|ƙ}fσ^оЯ+ܤ7DŬ 4U0o]/c֣xc?՜/256@|0?O28< XAC(@b&J:.b.69$zFC.0ucWJJ*PK8In;RG/䑗A%@Պ@r;ywBCwT稫7ق2iԛCk)4ز,77ķӱ*>WmlԞfZ >?(ωj%[xt׾:leySqӧY ^ Fg{>/=u3/<\cJ1n̮RVW_閩+T\\OP3gi!~(aY~Ә9 2!J$3qa7nU_||WOuxa#$|h7LN"}śOIR{PI(VVh#ҭC 'kP9.1!nЂ>zfɰkGѢO*Gl2z墔hT信4yFQ~!x'^/pd bVoFG'hICSqFI1#Loʶ)[CVs5qhhIV m[ps]GHm87ַ}Xeb'"XwDIFis&F|ٔƐ|kf z86j_)R~#8#ab9v M;oǖ7}MS]e\8HU< 9 bL?c>abci }a5VK«3oi?ʣaޚbE~TG:6K!,Ԍ֜g.,+i.8oZO⥃(&aZY(i>E~ZM݆u2m G;3-DP{(qK"RH5w@3&qiVxH"(\~ƚ!~+搆5$$,נG-&h42dzvvi3<ڒ@X H52~I<'ju$&;O )BڲSxfo?m: iIB⋴*Z|Y!%A.|EOi/qYnӍm *U6oXK Ԃ2 &ߑ`w 5Z4ӥsM1r)؁K2fq})[0c`JmH ;3ng/hmìm`Z<Lķ-GD XB:OJNYBpY_|ekCC Ջޒ eyWQT/ZV6;}t Ӏ=. #kw1ϔ8SINS4ǩo>j+|z)!OPG:V`H,p5:vu'Bf :0YUQ)2FiƃM1p~M~ ȼNyOH*%Z<WJ~?Ij3VRn"IHЭR&d&}E>w(>(y#"^Cx~v{4iτ`EodD!t RMAmi VMNԙ! ^DJv5y4b !j*y}xHgX ajD%YGD(|reTׯ^Yu5Uvl*N̸p♭&f grbL C47zZp[)Ү:bD́%=yc낎 Z0ьH̓1"(@(Xo|2p43!-6Vw3SMVP O\Ț*6-g̱u9ܕ@풝%/)hz`B_7/Qo6kAU#& S݀. |dgr ]_^l&];ֵ#کEdܫ 3 VB!dj5=W'slI! ־v5X+Rl#D&oMBEV9NYE)3CǬg6ރ9ʳJhtA̢O=O/[~Fw^cY; φiEv@֜\ . YiYBھ3l;rjP,*MXYYzɼ`XZTz3Oyr|%0W5B8Uȥ'uD.dd^J-,M[ܷf(xoWw<ڋ0kM];}#E2HD71, m*lآi:g2YUŽWc҄Q_![~N M;=)Nr8Vbls; -C 6oq_; 9!Jӗ/C#v7#P~L$E%FB`*κ:}48R(MZZ$XYشExkKbƐ[=,@ ȑK~?*q5;ANV]Fo% W~Ĵּ sHrD^CrN1D"#^jM{5_5 }k:)Ψ_XܢZ!¸I:WS{PlOR$p|,'҉-0Oo"mMnO["A\iaHsYl!{) э-B`7CoQW2|m$ZS %Ȳ=0(!b*Lz7jWh.61LtểJgv)Q`wEvn%RH\zX}QQ5_tGnX&{gP؄* ڥVyzyސsm}r&4i /O{숼3T` b'ˌaƌy4[\7nV.ᔸe7tGbS?IORaz+d͏c .[$α;`s3O.\'MZyy?ǿdxl[nfV>ȡPpVٶMja R >A=9&|@p̑*?yqF?[n:q.1cNv=۩tM a zdsJ`jx#kcGm)<&,GM*Ƥ{.aiZc U~lkpR&ayx@c`OWhAAp?3JOxcaB`r[`Qwr_ƶ[X3?=Xx!3S q>vg}CyTQ~Iqx(g|L۲YBdZɱn6i/>oh%I2k?n. VN v(nh70TF%So). va+D B(ֹۖGwo bf~C{mY\-O*[Dr@/c`. 'n/g CB)olYa"%vEr梛7\%%W6, t-{_mۤ+ y*V-3<<&܌fzRL'~< 纬<:JЏ}qjJꞺ-P9 (t<ӗ:(yZ.ԕ\4D.HTz uRdf{OZ&%USpc8yjUMKg˪ǃ8hs2 "vҮ3xS6YeVI޻W̋_8|ҕPo66WFE{%sE䟀B[]wBgx&:#B^ZT˨iJ>Zvo|4x>$$5 =|轵۩[-/ jcN-0㔩~f\"ʯ x"s`(R?n- ǀs %ʩƛ)9p1QB|SP7CHZ>?j? 8If? (˸Ş^H ,bbnG˵pg¯@]P5uծ#HܯTT [-.Y:@>@I XϦvau/3ʸi2g@&jΖ-KU^k Nm4W|xKWws_ z^T5[/G";n Wr汱bL3W\