pki-ca-10.5.18-18.el7_9>t  DH`paB$ƨ7zгS@5V1NJJ;c^[S:YJySe1IC/ qH}ѸTw;r6J8C[I;^e{(%kx@8[τ{ټOo`'}^.yM-M x7:5mX"85  }Ce4%!²) `݄¿Pu,})n=~c{0}%l,XZ/j*qğt G[x L-S9xdAZhs cb6!edLM@*T))/CT ݪ\!2 t+QMQK.@neT 8a87510f96e0dcfc5c3463cfa45e56d6b443c6fceĉaB$ƨp#p.a H(:*=סӠ LPxweB=:f]ԃ;`"$or #`TJkx|"Ȼ`W, Nv\lpsHUxN9 R%䋺PB5!s,H|6+J-%vL}r4ִ'q,K`A+E_**di'W3.7}׭qrH1/T<ϻې 4_6a6H1˭dgj)PӻFKg d$,;&Fr f@M^d|U/=EP3^k۞mGWoaJigz3gg9ax8rhqzIY enO֓I諤 N"pX9gV&>EYg_Uj>>֊uQ3ڒ>gh$Hؑ vx%[I h.%g#Dq|w > u&|>7`?Pd   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P9:GiHiIdiXY\i]i^mbǽdTeYf\l^txiuiv wixڨiLCpki-ca10.5.1818.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.aix86-02.bsys.centos.org%'CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤ai^2aiaiaiaiGaiai^2^2^2^2aiC^2^2aiBaiB^2^2^2^2^2^2^2^2^2^2^2^2aiB^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ai^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aiai^2^2^2^2^2^2aiC^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aiCaiC^2^2^2aiC^2^2^2^2^2^2^2^2^2^2^2aiCaiCaiC^2^2^2aiC^2^2^2^2^2^2^2^2^2^2^2^2^2^2aiC^2^2^2ai^2aiaiai^2^2ai^2^2^2aiaiaiaiaiaiaiaiai^2^2ai^2ai^2^2^2^2^2^2^2ai^2^2ai^2^2^2^2^2^2^2ai^2^2^2^2^2^2aiC^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aiD^2^2^2^2^2ai^2^2^2^2^2^2^2ai^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2aiB^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2ai^2^2^2^2ai^2^2^2^2^2^2^2aiD^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e009a97873f1b5f7fea2e65e6c1c61c09072b0193a618b7fafee22f1208a943f38cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-18.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-18.el7_93.0.4-14.6.0-14.0-15.2-14.11.3as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-18.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(1% q4b o9#ܜ͐ qk,P:[D ;3&;; DN:$r6z@O͆T4PPȣv!k"rH-.yCPl=[ .EdSQ~}E(IJAZ3) +92A޽7 k5uO­_p4\=Tܐoľem:fmxm}J3 Wl@@=9G󡂔GS*ڢ7=émifLSmW'v4&{Bꛃs7@v &0J \wUZFUE fXF:j1ur z?0#g<,!sxka#d*:]k /(S*@F9\vtܫ{w<3R|[Jo#6b=Ԛv~-NJ^D- )ZȪSq!ӾpRaZ9JA( !Ya/ok Graȋ&\GÕ.}c+<_4~70e޾͋)ow@҅swKѿ\@TgJ h#*78>l57=Foι0?+cm cnDÅ'E-@<-6>z4^pm$s<#GR8[-9.&ʠTRP7l| Fip9oCK)!2 6dIw7֡AZ١#'R@(sJBk~o@txo \Ђm ^#8 Wg܀ AøG|]?Kk,~Tmo8@iǐ4pzHojZ0o>LkI9+ধZ5 S}';Qe`mZ@US(+݆K[/6A`L8 f~ L_(q-/5jSƒ;/'6GV?\b" E hFQ5"(gǒ$Ct]l%Ě4Z7>\}h~,"b`3t̖J1X8"o_B֦- ʸE4wn2#QAf)f 9گO6šn*R>q?s%F5OIN)c|-=1JX (iP/%)zGල>PN7ФDEdm`ޮx@V;$2~;n`Q/FjjK>kme(5z@herM2b%g>f,bMvǙL %DyuDJltRG3 tPǑ$WYgC %ǖgd.#ی}{ڱƕjҽlMOm>!i/i)܍0 l[oa[i;2@OMvK i@*`'e)2Rn3SlK,E^OY*C;Z-<A}i5@{DAwAt⛳|32\|l }8z6U{;bQ0q֯$ϳđA8aͽ(K;US҆ E4QT+BcEyGtL,ͲPo,/}TkO#O}6.!Cϝ '@.|a~iBC<= :nT>●l:(3x%DΤ?Ng6DQN!8ۮv!;X3 ,Qy4L&-6|]8?=ރ*aG[&uTs ;5 Mw7`2{(k &p;I٣rUӝRo`1)ՉZz` u:fv.+ta)qv߾-M3&t,jcGk3hgq!7^|+?ZÎ>r|$+z"\X\u^CE L2tr=2ŅO1[ ;p[g bf4!O9j]{GzTz Klc-jb{W{Fάp WJK,e/{I?dHog;|= ѫ;:& ?-,sWr7Nuc`OdlJ)9a{yȯO ~s |v!1]v Ȯ3֊.®# WQ ~'J#-H嵟t'2"yn%o<0\EK$ eu2ʹz|މIê0n;^gS;]o+ Mr-w􅃆%׺LF* ޑ,p7ä5Nrw8r_`%`H3CHBvUnrl6ys]VՄ޲2tc[O ;tobз #GqcFz6ۉǚHg!iPxU%}9eg~F_|$ g}ω`mfN׍jsi!ܝ\s D$nz;2ﯼ{g5&[[D i= #/"nR؉#)[&E3t&9Z6~1jJv&(݋-ӿTͲya)c) |9"(빼1L`7(#kd@Oij՜-rN^aDI?Ƕ}V؃sv .dڙY%Xo"IJ:FsV%~և FyXw(h{:28uyvKh.:-{GjA+QfC>N8/OICNZxtӺ#u5EB~4;&h ]bT+F$?/D1g)"rGqZbs>_1!kX7Hb4 $Ў`^z- 8YM{%4xNiA瞤c7 2yXצ-D/J HFpH Av-eXuhGԓ8b%J=޴k SI/t! SlC8x4||O۟&* @J0GJ}<:Ա%QhFk躱E#h#kjh m.m7HlZ!`aHo';TT+@\MKk{<-QJ?q-8s!6zCK &_`A!_]nx4. nH8k&Y\PHwE ;&`שׂ3gJh6C-TDхum4hhK67$2X27$DO'>aS:2@./ls"f<'- O̖ډ3V <. vTȎVve:׏,ko}WWϧp-.1ۖYac7W)W}?Q -! @B)_:몯:k$~$yªьήEIJ{^g}t5tu?!祧7nh%lOk6K@t0BK?|UcQ.V[$;q 7pu\o_Q2/*p(PoֹBHBuYYd}6^!N`5J_j9zvp7!ސaF@T})E+8,ϧ=,M~-0QEzƮb>stNbrCb`Sw)o7 *JN͡^!4q #2v&y\Tqxx6_Ux`F1:R rn;*'8{qLC NsޑM7ݝ|䝮Ͳr{@x%޿PV|t_z?H  K32$9>bEl'{+:*-85ݎ+GZU)vBN4Ҵ۽=z70~|gh{-)-!eKAy);Kqc \ڽZhNw`Ge]Ml"Tn2O}AZyفk Ns=ߠTee;7-VI<ևk y}`HB}E&n&pcˢg Z~K$ sKT H=8^jţ '-vB5;kyZ D@<,HDrR%%ϙ=?گ1KB2sglW3Џ0S tO zͣdQ"%UYV>E-\Bf57\ҧS矍Y{v3+O ( !W#Y0uK׷#RiQ\/_< %GTCV/ޞMNqUȑİ"?S|~֑۳Ņ6؞`#rLA)DfJx4uշ!(ChVn [`Jc#ۑU}HL)WMtet֩ voۢVOvsm&(J,Ǹ.3A㽾.1YLhd{w_ci@Aބ>z~D^]\ >F3Vo 3RDM+Oc F>c 70ъ†h Z1=;)wַJ 1,gC"oěN[}[f!,ٛ/yȅW[Eew?^i7M vP~6D_1[uVb8*801.ؽ,Ż;5T(%A[Κ%ۭ}R%rKslCtep+r/a~FDk hsB*}'ڤ^mXZT U/SpRWTdMD'RFBRt]5 䒃 'z  ʣ{cO38h[NWu?ПTs#! ցOBQ,0!-}vVW5e#O-Vs"f$K7hXjv C8h/BQWVü J`;4g (p8sUgK}YSq،窝wRn<L:X9O9$ik,渇@eR6w)(!Lve HpN1)!$ߢʚY}2wbx{Ûu>U3b{HbR}*E)sP}5,l>/yGuH~FQY1-9̵>D ؕ&!jŒaK#ܖw9 3w mYauOS@+f;VЯmi[6(zT"A$4!'֜au)6s[K62636nq[9Dp [ {1pRbi&6{o´7lOl8P ?0(Oʜ)!s#R m`x8x:Mv67j&[f~M|PXIq#!LXEt= `,^ ̮:,ܩ`Z p2#OS`"m|8,I2 %evF*"֦+eCy }ݗwH\{B#z|[h1R`Tܭdt3ap9:&hb9&/,ߏ=nSAUԖwTA1쪨Hfαy<:ŵ$ywkTFbj;RqO֏o4 vB-+Vxυ~cQh"]a( O4yHrQ#\ ]~LXl?J,973ӿz7?*H:1ys]n*UцSMCx)yr IIW[rW9xq-e_1;F/i 쿖IDAɾ~tMq tӵ$ksTtaVܟ?2X6p]Z%.٣4Vpzf(2.o)othd# FzL*S h#+!@k =~n5A-!x\ּA"m,,v KwΟ_7CF|ʃž=Pn2sQ\s@їATA(p¤ENeU 6࣓ - Yu78"DV]pAgEtqCF]Rzt(͔F ,O~^4R(O|۷NGH/hS}lXSKYܔjy /^ 7!Wgm|ֲѐf.I:P3Tjk;sՈd<ɟxL7ک 6A_HBڬ|T-wZh֕qo)Իnxж%Ol{J-#_XY ~qx-l=+e6`qx!FnPQUXo|^{,=xqSq/Ƭ8K~Ba՛2k]=ƮA TLyД8͑O za )Q#K E2WMELbt xѠGbcCcޠ4SFu d߄dbTj/Fq2LR-˯A@-[7*S܊Vݬr"פy)}!rpAgz?X!;5KQɰSpsk5!O!o^c.|♳E5!1D2ST]GnEMӫbmd2+(Uq|bQ y݅x*#E\ V'!Zɴ` yr,x,F=I"KC4I_r]YǒK5q zr"cGZv0fd؛&͎7*mBQN_o9ߥm<* GĿxω7C{7IIeT۫y / XB.7¼^V eӈ!xxxg+Ϗv &Sy, }fvjLP+i n&.!mܲF ^imAG0TX6-5 ' =\}qY=ڂPX1Y;NI+um&T*%h$]k*lf?t1[s$A|K"E s'xH%&bkGsU70< p!H]$O4'o]ߓs2 $`qe+ <59os#߬X(7~SC9{dqKaXak>ӡIdrWulHT!񔕌)\y/>S9"|@Xǧ$U Gp;5SywdM(”_K? d2of g!k^\NhHGd: \8QrQD7yk7iYd%]c8u4,NDw:`6M ?xg~suKe쒉i#-ˏٰcrtڙ%;AL1C/$r^Diۘܞxt' lG&/ly4='I^:$cx`ȶ^{ M O=klS#Er(}x!T7B}N2SR5{29TS8ӇD2: ǔAwO6|.ډ=~wBCJ+nxj.tDzuKh5 cAQ|>J=y FU$vl[F0ݷtN[ͷ(Y溢S$6(sGCX%x>(Rn655$3߷9"){1[:X,j N J/`g+fLսSC{pk`-{5*qn͍g0Yv;=T Mʓ>Jغ !D*c6N̆@aϡ%pl|DdI'Iߍc}GEGZX9I`8m:M OLkX7'&̓SפS[ʑUL U?EyaQC藧Okn Kqlp&,:2OXgmԥ=Q(Q;N-uGu*mk!N(ћ5RiFGِR[_vdzr;?hj-gW[޹)!]"BG(nlc,`KbDmqMxf1}N1wƵ%% p;C_@S2vWeC㦦lJ%#cKڢ#$#| 08 WQ]leKo'CO)z^SM&GnkdوѤ@qI1w\}t)KrfDEъJqH's|6T>@羘r:`ߑ#{ RD=r&kͽķ݅cg,u΀<\ Ծ8^Y`+fַEu]D+h-H$Q:fI&1I=¶4xL–0Q{X'ӊ%-͑u!} qwa2Z3B/$JgOy#_}6nd`dI}*+u\Ɖd#˓MR;vw $_: VMz!V/_7Q{RpPNJ)V}P?Ua8bx(K6MH*at?! p>.Ì8K0HcOdfWQ?7F ?8T\Hb-|QenVE3S7AlY("asa #ÕR7c\qBRŃITWaݏ.)S`}b+Uൟ$̶ۤ:~;\ f9"@b lz|`$ö7Q1q֞J!,m2/W/ JE|lG;r( =s *SiНBZg4 jZs1TрLOZ+!%2JTlA!JHB-q}+x1$ΠE8dyxIcXP߰,&>؋F^ЃRd+ؙrqS+y/^)OʧX=V.ӇqI]^0=Be@W}yhWbɛô?pnŭWgyv>Y:F{%@Vq( g3!XQ;1sVA{n%L }ȨQϬ4RYQTH8LYR,a#_Y6 Ux6~{@}Ѹ&"tPVnAD :0),qaG(p=e}_3= ӈ{G& 4*ydeIkPjX&1cggק0W}WkE 2LVUY'}܄ܾNsqc݋O9o^=<5>R@(VzJp] Tr:֕Ev|nQ~]@x(Uw*H5-[mߔgy8),WwT-gTr7XG+GA~]a$O#1ՈDAɛG`JuB<07%Fi!pTL٭D :]# $]WclEgB)"f̫t4@:}^QQtRл3EXbYN~kh~Lz.9R}%-38}o848+;0{cH.y57\䬤<0|)VdX 6ߤUae14 H%'hL] b梋*i9+h$fM> ke(Ә>lb Anj 'liZ|s\'"ɴ".9t4$(>yPldmF"oAH,'G(7`2BO:|7jEi1D\[3G /܃Q+yvTEۋwlWM_ %unc6oGƆ2= Ռ;詁bBwzԐUK坆tj.;vZ-+y4XV` `iiƋZn2[~]*9vz*f[d7cDZQw'*y{&<+6ȭfP&p{ͼ} Jڛ pKNL*EDؑw Nuՙff:mZNC6LY_u]vD"l-Mv\҄z ȩIhD累q [cG]6Vdt*HhV%&1-}ADl',& B]}v[I>?*S y'7." 5sP H'6Z7P39`!jCrXV.1Ucu b-Nc5϶H1O%alۓHc(ˈ s2|"ܷd!m)ljel_mQդxFODk0~4xA8>ABf`i&3ӛȑ+ p!DQސ) 8QdC~xA8ffTFFAΧ }/uz}R\ٚM7@wpҶD6 e}YMlAqK9\Q;>ϺNɌJ$!~eo+v<>O(NYk~ 05KoUbYH HKbRBb0Y_`25U4b/^F% 9 NXjɵӋ\2AlomlxpU駜vwY2S'四61+|6`J+. e(ͷ6$^&j1Xyӗg5׍r.:OJ#Կ:qbBnp;pnnCs<"@{r5j4>%.foa~vpCDdĹY[OE25b_ES(/* pb.AK.(#T! snz1nPOLW!øV )gK^(lP ~_]0#m_?׃a[n0fWB_kzA N&טAÍr( *"%"8hUYllyf"'$H_j`tnف93sr/l%VemHІԶu^.uqQM4ϰjř98c]dugզX?4c}И::KQT|)8ϥ4\{܇hesE4пKmGqxUe6c‹Bb.`N/e[3<⦟ٲS'r Mu7}F䵱PITȺ6=QߍY˩3Qp]I{b,$[d9 É{YBp)WᚕIīB iSgP×Ȑ{;jCq IAF1+o'\/ـJ^K3RXURIZq_B(_љ*g\tPV1U"/+e-?IةxF阃9}C'R|:`ܲ\/.m\=yȜgV\,7VDst_q~'4-HJ1L&=!8Xr F|:˗fī`Q,,%[34^gSspmHl3I-={n}DSŽ;4/d28ey\|Iv4Mf{ܖ8X[ɺ|sB"K;(hE7z+;hgjZE}5u+dq˕Dl \nMavh#M4!ip,@Ҝ%K4꣺EUBO-nNbgܟ8M\ zcL*`"´",:RLJTaP'M:=*""W·.ieɥeEfm9NWLX;\b6RT+׌'y VK^O@g(t\ߙgbKu)e$,å<ӟa=y}?-,>PVqziRS'2'yf>YCjτ{os`p?|:':TSlU%R/Aj B]5xy}XlW]ܢ(ic9QǪ̟h{bGn< W%"_?.U)4ƞ,l."VŇ' g¬h%qfLdVV63WPH|}yF1!6`!2DӴ! AB0bd=!r`14؅ЮJ߇wCwM>>EQb?ߵŚzi?gN|G:Gw@HDs^Ĭe1fTUd#GbWk:ahEz}x@W̸ؚ7mZOf"78,0{ `uvͤ q <"r]U2=,P}$̄gS[PtHhܴV󀕓;Bw9ʌۈs~s/ݴ:FQ_Jqr$mYq2<;f޺8e@4V>KP1ɉV/1ŭzE)5Wi9$04Փ>"B^L ;0  {~G (Z~\y۶]`>`,˰GҌ9$=,Yi)qV?$\y Tv=N+_Q+7xI5=eXc/ `/XRJY%KNSTEP) ;QԋEm8xr1B0AVL|Md+O-\~^Nqg eP+_Cn/G FaWuJAe:W5E`N7DW^B"_?` M._&=kYwDitn[%Eu](X16/(q"xk5Æn\9A y0YK|)º7bG ư8prowWnrKPHD4#|)SWHzK?|ׇ}s i0M3ku/@U\Lޖ>R$7 p=cysٺZ\ YӺWK7}db%iA4_~"Nڹb܈kz+e[OGkD*~=XHX/59$8L6d Xղ+[^kJ7cR}Ǻk@,AE5,|6Q {%FnSa+E'1Mm^`q=1bekP^Bl 9R} [γ0\LrxpIV΀!O#(a`sQb  6T[aBjG?A  zI|q_7хCDFDKr"^{Iaz=mn eӳ-Wˬ4tQXh8#<$qCR"tU3\0%c̽' S0=&0fcB,vs3c;e"D?eMA({$1r@7z>1RKa,CbvRӅ4X1^#4p1J>4\A}Va@^I\em! jj Q?٦޼H+`ʨ6YQ*町9Key-2=Lg|PW`@, .ST<Ɏ*;zmT#ŠOU;?twZ$ѐ3!BQKQ= :Xg*G˗JGP]|D]le+s3U=+ %fXebMܫFF9o#!0Uvƣ?:\}l3/➎z < F#~1Z%^=52fb\d>#{-F;숐='_ s-\{Һo~Kx́#|>v'[ ?10,iK%v)2a/[Q|1 `pZh?H&.Z获ɑ* JlE$nvR+esaК )~Rڀhm ;!p3oz5(9lpX&KP73=V EC 5Rmq~87K Za!vj+P(d.E[1ʁOȿɺ0ݘ=V-GBFrlIw8oG_U.?ʅcr@Y.+y=ygiVi ZeD*VjX)n 8mSi,HD(g*KG/U8=QVtmunQw.uI}W{kIU-.q5{E yԖǂ[pOk$q]e[;.C^;ZPt@vѥCiБ'ar4 Vg+ev4 [Δ$̋ yg k[2U>gK7.LM$}؝J~o䃇x[ W\!5!O<*GC=7.s[m@_ZFۊ"{zy5˓_ڿ@c8Pȉ T*3Xt~.twGo͠~z&BB zRꏀwY- ǁ WHW_[@d§I)/n&(R*g* `XS5]9Bf%yxAUA+0P$G&j0[ ێU|*i !d#4Btu-J@wA'Ys!tY4nl+㴽+d'/dR h.mToS?G\DG1Zob0>[knW'Ŏsgʄ Wo=y^&DeqM~@ H|YAJ#k2ݧL'Dx ;Icc ^FH;h(&`8d{v _=kD#@\Z(+_,[Q.)4H7sY}ÉOxvlUԋIl6xCvM|aI V G] 堔+dʪ@@vgHSoܦ_+gWO u qiBxVv3C5~1R1 8.5]-K>ISdknQ{]C@|'pE%EMC誋7TG³̦*GEvï2,IvanN+sHB!]cYTT I3frh ݋B+Ϧsbg 8Id&i[ڻ(sy cF/`R(K=|P/B=6_E-g"p3m*UWCasVj#;-ʐS}~F'X #]\c:"CB¤ H^s+U$^-,#NEzuEw~#7c~Ir7 z|` Vv+yx&VH3D[AyPEd }wU"~h0N+e{S%'abO L.RZhfꠖCe_hb^A1i٤#,aaKL# e7{w+U|dXN1|MdI;;zlb:i:/en ~+'oqdosZL Śly0t,PKvhZw3]]Kik5$؄jА M\j>F>c8ižCAnF+(*N:Z9#L0'Tlr5W1FhMko\4Y'n`W_=] n!Լ ZOw%~8uV2772FBywɿV?1nd!b'S5|1&-wL!8\ +cV48DY|+I>"uW+tUn̆`48"OP'Q'BfJ$^C%Mes-;fNaVVX3亳+x L䏻p 'hY{˜bSk$]>OD8e ;HSIMa/KLy{ { 65[5Bc -7«i>I /V#—f8}Y D% ժldl"VɣvƷ]ز@`ij^6iK(1Qa)A86Bf۠H {+Lk)"TA0CsD ĽV $m\Za\:R)7p Xߝ`(޷UOM WRb:mE>dx  aZ)_|GzzZ]U^ H`f.DԒ$&E ð)9zf]:< dc-IFbюQ_ B{eN &v}[e"?&Ȱ&mJvPq,Fg76 0&f~tM~sJ;X$%#9qsyxɐWgو6g@<ǒuIJjIC9ŵ4lM6)`D1^ެ;3tN2P8u|zHwW늃Ր5&U 9$ҪzǘqnE`%q  ger6 푝$8) >EfzGhPǧ_pvoøO0\ x6 t}l6v!2yu(e`N~By'> CTXUsF9JBJ 4ac^32dj'3K4zX*W -韘kOt3osWuZ=wa $g鸜o-qI {pdе=\ϩ^Ÿs-}* ˳@%\謈Nj7,a,>ΫM`Ý GDydUmf>4!z-oB҉|>Hec5GE͇ϵj}-qó+41Xÿ}^~wTl.\8%ІˀFWSVe6&ק=~gOnluVO۳̯$Mܯ筪2q4pw,!F'ϲ+V]9MTHCۖ=' c)ĩNq=mZNj}HPH`{4ƒm6sf@sV NjP1Zqiݠx 6xm%tJ̈́5)9=ZU/a/BcjWjED)E^HSK#K~mI;uȪ!쮃jos義*aNZs#if_m}WOthA0O@7A.\tNNZsdKE݉&wV ɮ /_,/g}-i|fZNbݯnzTC8a)*i |NZYOǨZwMtz݃'ܑ{}5.rle*o~NAoOKw;>Dba f%G%H5/pʸ<²RNn8/9lѲTy;iO+%2? plS-fH儋kF|/,IBtМ}]hneQE`h͞fly q?3oK$#8}Lfiq{oQԉ UV6JaDÞ$G*hX~nBS!A,\a]&آͅ =814=׍p_qz I]bбҐz}MWPT%{Lw'nBrrn=@Sm݁iٳp{U.,ex^9bjg&]^ղ40y5+`48w|Q5 ߵb3/a<:%o{dܲ>YS{1"PN\V-+Dg_G2Ӟ;7IȢ̪?4n~\XЩ~ ܣwAрV)^>pfr_ cm~V?~lF٧A'=zdN!m!Y IYJ(P3;O-xqy...b4=s 6r Irx0qwY6*f({,YFK3Ivk ,_%*EH'NCֶOA8A^+ &j&>!h)SfwtΒ.$|M ] ]&-8 v?G VTX+T}̹6UI#cE g{}d*wrTI$1o/`O`Nwi"rְ힓#ﯕBOͿm'e|Cl;b1<=a^jGݥjb݁7YxTBx?~a lz͞Gf&xĿL" QՁrB"jڙkcCГvl1\UYW6x!rIUkEuUr-B*٣hP@h1ޮ睂<0!6- dCB!-Q֡KLe)~}Yk]si;KrZVV&`  ^mW5):Tcm6D*wE1w{oz#aLOn^)7vLFUQ6UgtoĹn}XiW2l ("RsXPVҺ%n&3]}=zu%Rpgg^;0O+^hSSR1TᐙリV}iL6G=!_u|@˨ȋ*5 to j1 $s$Z6_z@yӥA)$zK/Qg[bǏ(TriZ0ώk Db s 5ν\8Cp 2C f." |.n1O6Լ1sfT4N\6a@c9J%@Yы.Lؼa r Ÿւ?oO1wX7ڙs3*T;;r pǟoȽ|R=|f̬gF97Nh|kc0X;fC d'rp.4Nn ڂƝVd)3*oAHT_eQKDXio@y&œ_)PsBj߇Qk2/5ݟf78vⶅK񐅎_ãnd3m i.BͦS>Pʼn )PNߖs=q4g:3 Ihogl`l˓pP7T..")ڸBZBK+J ⓭g,JQw.X6j{, :@_߱Ro[<qF}v,t@ bzũf %n@FЍ80no!!dU%E*a"<!X=_"eN*I֍ ~dwE,MSZ0D/KbGu7 sg\Ёfd< Qk]jhWC + N澢#|̠6QR\)_ioCcN~|}? Z[ZY^V[C)* ߞ2i_<D=FXJA5`\XQZӛz*[tqY30EW}闌pdJBB I 8Q2lgh1"ief#(q-9Idc^Z<6 Tʼn_?@(P3)S?CupZ| Ǡ.(nP8Ԗw¹K+:m/H~Wg&f lzq 4iD`V.?_ u tlߜgW4*mu1NZuՂd}.v.-Z1L= V&8 17l1hn.:D:Q: iKkD_͠.<넑EWP+>(&]Uh*ao7x 2_ ʫeI69>oN%?';ӯ&O3y fU+9[͋E-萱t&,8}17Ta5{~Om6k7Xl]DžL#uH~$}䁊C;āxt`FaEI0, ң)* *MԘqGI馝HmgR^ok>QpPKfsH-a8R })EK)mLzX[[PL oU >lmI#i0/b,hGuNu#b*)*&ˊ# ,9!/2v^.B}%`8Cc@S"{*7g_Zy/֞^V7~¹tã^72Rbqn#>$;ƀVp5gnpZ|lQZ۫e `N(޵Ԍ$XK Pu B QӜR|/$gh ]*naW7la *FMt[C -BWy%PJb Wa|CFd7ɂnPV.Y Ăv.ӮEg!*1ds}&MTZ3 ^0pA6SlÕ40@658u> f͜*i,Pʞ"kQeӎ3=neAYνI⧜'xꉟDPmؚSAl< 6U0%lй"vL 2% t ^` >1p륄UQ 7aYO)`k1y~B~;tOY֔({ `+9f"!^V?3`^= -TW2ɓ4-tʥvqecWPH(\u_Ԭ~A6BJ:[XZLY4 lzT3PC7Z+@*/6<;-D.n]028=оe0 }ՏW⎐85\"EfKK_,$<,!~gAhDy+,գ}ʕrDh,OZrmwSm/}AdudYl;Ǭs"*+Su2:Rځl&:̡"c[fL~e&Q +qcDZaq/m4ú%y7 }tf. [O[lTd5lt(ŇNNRmh[|myՁD;PZ%#[^CW)]/KtG `aq/%ϧVYLE mg-ZU3d[Pyk/׳{:Bo V.J+OSN$aFtBk|*VG$\2bQ*Ak4MLg _9!ʇ_7d~mfw#в 95rrJޛ 1461KRzۆPp$x#& :H&ܶ"εUıa䑗ϱK;I=WHz0 f-0oP{>Gj ]"jEUVֻ-Ϋ}_qVL;c[+=I',s1ya6o֝uڧ_SEqzɕln6iEaPLc.vZ4' -7(FfbTXK2i\j>t,poT>o$Vo"  Zn&Y mͲO>^q;j(NF?` B>15|㺐v3RO[{(ldj϶5be=A[9T6,gWZ:ƛ k#v4s^Z;7|]7BE-mE9){#Ԕ= VP 쀈 1`eN 2wvE{ >~  d&w6nK^y/]0*U,?a|UDB{Vc!!0E IӼ?}*cnq)h Zfp`sAH$w #8# KK'3 XMևuo~XbvokdRM'2iI#^x|I{]s?s]n %9?S̀hޓ": c/sDʵbWJ$E1ٍZbZҘ.aƓu۫Ca -ӯCo8集^DHJ 9ү&.,C*ܑdCYh`E"ڼo.(Og2=%qn&DF%l[N@'20ېaNp_"ϼ{,Ӹ]ŚG_#BOd*~'I|2TU@:c%䫜붼YUfG0i#T*b*mDhMi2e9}Xq6_bdp"+^B珒qfjU{.9/-bl/i;ӼG_p s%wWW -_X:ʦU0cl ߞD΁f$!㻍ixv6 @t#vݥșF4RR^ TsèLa)I"O7_8v'&juRx&&s>בwwRB3#zBexH[a@/$C lzBKC#?K9FpH?o"f4c$\UY KV1߾p\ӰmZk4mEXH?\]o$I'bxFPqvQC/ ԘP˰|ݑ^[tvo8udp [6M`.!StP:F] `B7F BdEG;ǡv"ˆq rqD[Pl"X"uu1yƩ4b;,G0HFTEwI GZV9QO(Y(J|2mDUDΏPDPgQ\;nIyS>t.Of9FCb͒T ^H5m4ӴS-~3<9@mnWLm՜vKs';: ɴ* ]oF8Ctd|@o6F7^f{*ȝB)&w,T[ TxCAygqEwBRc@CEGl6?uCbfQNMgDF'9# ˬ s C@5. Pz˶[[H3|n8pHmugƢ8z9Y\!HֱҼ$@oR"Fe-7iKkDw}ؽDX 6M,z.,TJ#I~ 囻 J7yˆ)&rH3g`(,-#z6=%Ft`Tp̛(zgu|+A^90W%UjVu4} + JAGaϙ w'qF?կ(a Ym(t `=-VNrӚl|T z7sW+Nw"2&IGrQݴ * YZΪcg-NI,jC=N#[l5.ЧH V1 SsB_ U1&>^ϡֵpɳAVfW;=Hob:i[c[zX84Uů m|̨='Bs mbCÓcbL>tm&69\E֩UCh5]FO@`!V}aLAO(y-=2!e1#֢[AD4}fgAaF[9dh١Һ GzvjߔVw霶w) wyR`~~3G AW— .u$3=q|*}IE vysw=rRPIũ3|[ LơR$ 6@fPcGŒ*)KK:nKr[1& $tgpۆe<Y;[.cWWNh"`n2f#8H:+%]s䡰҇M)ʱ uow$xkCaZ"w,tq5.60`2LwAݠsO#bƚIX ]'U:VQapF(u6 m99F̅øۏ1'F#(zm]I4)g\2-pAo 0Ş&/kΞc?Hi*MkÑtb A?D{u)ٷ="۬VE_/!W($6,pdE(=\̝eÚym[7k^MXm9jw`30Yli* hYi!d' YNcǴ9U]Ndc2-D:0\%jfb>Yi[^8c<+?HՋ[XB&ypj;2TJY+? OI*SIXtUŁmm.4K!`ΑI1-ܝ=eJOV&GfG.g{NdiftshMr&M!qѾ5f%|ْPLGYGۼ)jU闟E-8agP3䋽ZPǟT\)8?̙"8"8xE.{Yei?7HMt A\_ q#ul&ln3'm, \RJuT 9CPZo.U{o}YxKo`&T;Y"n9uPiÞ\yRc̼DޅkkT"f`A/CEvdLlu=s 5͐9徼VZvĕjV0.b~( ^Ofj6ٹ7fR,T; 0%D" HCM`VRUIB+< -:B 'bXp24K(n=dHfo=.F,4eTZ@`n8٪ǫLpi,` kDyY"E. r :pަ^%+8@3ip9 uzu1r7[${lmVNysO;)<,VU' apfp?=O8FRۑr:(<]SF zN/Wl]ADV-\$.N :\kJ _v伆0/4cJ>Hܨa(z`%x|ƣ BX[>'z9uPisz$oZPZ-n/x0ߥ9qؔWRRYӬ %+c#!ޡAnL d @U5oLCr("J؄Ԟ+P;EsnܬB@EPex ?B:eA9\~ԙFAݚjcyxl=gv8ި#w ()_&Xw;ß{R򴊨!\*xlX[|oh/0k{ej>L6}9/9XLr0˵YhbMˈ⍠e&P"B )D*Z:_IT ҪZkg]ÌTcyx}`a"v&->rW6O8(ן, pA{[q AeͤɄN(Y:Y5M\mV[_%ye_b"j!DC&Qm֡O1hPYK uu=L2A+q-;>U4EL>YFm|ܩSCsG ~O< S3qiGnį8%u 5܅&SRȥ0Wc^&v$P2 Veֶ0M$G F{W/H2rCU9~ + 7=T^mڸ10&LWA|RὯidED}wnh:3f)x2?v,:Ke:Y!wz<YUm&5` 4LsejyhhF6ݧB8U.} V)JrtpSX?X6ނȾBtCw5O#*Ucb uk"/T*`9;iz}qn8rt<&`ZՔ4rsvn?5%\Zײ\MꘘR,`D_SArANN8`>޽j>>7)Ta m{O&oqku>Ngsa-q, Aq7!* w-70z׮]YwXL%~.4λ6bҿQ߆'A_ixA4ͭAP_HxF <`Dӝ w\ ;UߢƅA2~S;a,vW<ɧ֝ v8{ǸisZL.˞S\eb^D[{,0̵Iq2u>*~||8mv CEӏ(9ݭ̽}=GbozFOoG]騭 5J4~#d.乞T^ƙpOF حjs۽lɎʁyTEwBbţcA])DAʁ, aEo/*f[1.odFp[EUckÚ0I_'z`!~Eq454]G@lsL|a"R @wFmЗvPDF 4,hu򭃓{4 U1^zq|W7Wj .o߶{A ,L>6@č* o70f`}YH"dP=le`vϳCNpP)I` @A ѧBswJWM)~U %+z[0܏"WN)&?P~P*5NQ=/nd7z>`BҨbGR܈\2X8ٶۨ=J*1sz97>CRfpǃlMdрy֘G#(%9 n-74EW%uAMªtS':Szj&~kCJ̃u˘4=Z*2͝Xq] wn:w Ai}`i/eJfV5ԝA(Rϐ5>W"-yeԞpþmYBr@tk-X-3]1=p{S^/rJq ,6>OGLm!2=o 鰢ۑuM~a^!l uUX}0LJcg#?.D+mK▸aJE?uovPV@1dJߤfC.oTx]Pl}3鐭^rSYR,[U :Peg=_J/ϙߗRVPF<ɜ6ԡk 'V8씬#5) 9m噅o^6 cL#43 (z?rQL {E OM^"\DNB 4x ~8_ĠUr"nm ̖kaG p\~0tL0egy-!*r.s- i ~sgz~ʶBv7Y;141@{w9?ۊ>SrWsjU;I s3oYN%5(tCd>}Շ||$o$ʊjP]Oa&ېTɥƐ]&PPo4Q."!S%SEnf˩K-/ A ')H]!H7n;ŪvV;ra)U۫'v|6zs2%ƭ~l'trkOdhZ"UoSLBz WTĐF5tR%.XbǤ(P(VOb$K& V,690jٚjB(vBEP\2"Sѡ fL(6C*n]*v#ɠl^vr.350( 0r)[GMԥX`$)rwi۳a@XAiXjʪјQ< 4C{mH wɥ8뎂Ms]Sש@O׀#!K)54Ig{$nVr#^ez+8o.7ѣD.WRF8x}cSbr6D]!m',%|4 mtYbˡxZ8n:o"UbZb/-b(oe$k=/[ҟ)6X qR=oQ9LXqii OhR"^m'kk)k JIYy!e Wޓnt_*0؅Rf6٠f"wI [hEv"aF/wV&^I4XE}pj=LTo.S_7/'|_yBTO< P:Z!:g̼*m$/wgwU{ LGl)Cy3]fs:N\ b;FFi0#T$}R-Qjo  q6K̟* q7Q^sun3=y<œ`$u_f$ o^dp,#a$[]xclx:ȅ -P+œB?"jzA^Ku(M+FިX@xOu궩6qIJj| Rq +nT<D˦PV]a [R@rfB2-sI\^3^ѱ-` wy= Dq)m.qYXEpȞ ЪH+U.ϡ(qd x*њø9g=CuB#Tʆ\(S0339h* 1.lP7kglqƍm AlOE*S>geXNP A2=YƇ~"H"!}*':IkqYC⭘$L~NɖNm)46a Fn3iR u se\Nܱ00I}z:ߞ5) ):]zhzQk;0w8 )7jF݋F4y3^k(4Z.H1@s(_WRnT?9)OlaZW sീeuC?ܪb(f۫ĔE'+^9PyBKp-'F K#j8qrD^nE4(nJS"g.defZx?n'}YejثQL ,SA̎GkY:B! )L˺91aM bh*>SA3?̵ҩ?)9o=${+]NX;i 6 ao Gj2EJ6MWF@]c@ U%v;ه{B6OЭT鿆}(G Aԍ1wSRd=-%}Ax!>AA>: I)茀h%]ۿ8=3ROjYY$ڢyk_','9ѧ͖~*ڕ1d̢v{~6ƙ'9t{Ƈ)\mBMx\Om.dhG!֟5n J샥?kV +Nui[REv}9&Fd:#3as4?r|=HO bP翶J/yw?ih7 `L6T NՈC?f!WR\!K^by%SO,Uݰԣ%alM;"5瀤Dg}N։ #!~4C')ǮTUJMIs#Ϳ"M4Ru5RF=G-MdæPYh8 4p+}/6nD(=,Ia" V;to y}%g,kF1jsȂM3ZS&:k3siѪXH}tDB]-a3Zد!27ߗM}Gf4/:)S\I#* "u1Q;ܪ")R7Hy :e!D(6)U 7fĊ~wD:\#3D!036*(ي$hԶt]#g>3l6a<ȑA֩M1p 9ęjuy,a-N7kZ[hjˆ~|\_*)$28F[)4k*,i\畂bvH?W77=K5J4"rE޶[F$"~!wQDHAc@5IFPz8q!͚[$M?0ry|E wll8-I?;1caJ8 _HG}/#d[Cw9,VtnngrACqW-~ {' 9p]W接F 5βwQZt 9g=GS{+:DvܶTc`z@JC  ~Ǯ&5Vfnh7\HBLbX$ =n׽ķ Bzk3NzQOag>pz fPFZckK $nd<' vB^J?[Mڟ^܅Ǹ}m2w7bJでMoHcvllc@YuBLE1`Ey6 x\<0 Hbr5G k\|dS\\IDz9j*>:/d< x8@o.XwjobvE =P<YF@ok)N~V-DD(BUΑ~-Idk MIě#HbRGEopd y:a=U2(a2>5/x{8ڵև6+/'-vbXLaoidmL??oG 3Wfrwo#ˎ{5d-LX̄r 1a6'DamN1˿]jn",4'T٠SЇf. e\B;K o+ZCZ PH(ESF,G6['C__,g!r5*R+X!!F;gV19w[n yM̥w l9(/zdP2J @`*˞#n#Bf~]z |~dsN8׽Jz33h[JPV2)byJ|wv㝃MqKf",J쌎CQv/ A>8 e0p܀1pbG[c!%A K*Z WaIX,.Ip kH*1|N~cKB*!1wc)Qa#kRsԃ5Ōu3 :'Rm-D Zw9 L^XAP;٘?a:B;`0u>J|wdB1 ĐRs1-F6+R&K_8gf`2clUH1? ܟ|@Yw :^|}tO1c>5BNk-y Α Y(8W$&C-hu`pBZl%ho`jBEu1iwuRWe ;WZ^#[X'#PP+4.Ԩ~(9~:`>{HZj\;V϶llʛ*󎮍)Jq32S`AZUu&2/fG>fK]p %[YqN'o?&[:hlrIv#7 mO{/c'.òLD 9sRy^BiSrא!U+ozମ88ujuĮ n> jS(BǤwy jH;lJ݄–A 䊻Fߵ S/4eMcYj>H܁V}]Onw1|>]7‡or6Aww@@DOvΕg 0mຘ-O>s§wM,xS_$9Rª~5.(Ezuhԩ*\Py]n<+28-?>u[o:LU5$Y: _dYC쇴в0던|%1^nEeAϣ~EA  Q*^Z2; Ey `\sꪷEH$ ُt?5΁e^-:a<>?GF'X%]ɔb:]e Qf'Po=]efw~gWX%AOIv1ރU O|zGiSc X aDώny K- Ä<¢E0nw݂BVϠrތdzy:´M ں@M d:2DŽ(*N`۲!|y4w5nX(ŞcxUȠ;8 5+Oњ0`RVqE4ǑÇjE(ze/M'Rqc=<옮S1PҜĞCP`"O )ggs4zŘ-ЪBZ0.?HĞbymr` (>W^lI>~eȞ&rEݒةΗn>Ljb;S}Pt6?DtY="80:m*E@GrzBz{JC wھAsՔ`2]W;/I\":sTJW1})ZG\^!CFjUk30˪ɍO1hd4'Q1+aM٫kC%$Eu4ZU(Zo,o\zb&̩˔ ݷ.[.PQvӛȲ )2[l(ͨv)-z1xҚ*J+e)-:3CuulD6U{m'U LM;\gD;.+p.\\u6][sd?֪lSofb \$4e~^h\ vQ䩨NBʴ:92V˖3{]5<ܺ. ;ixܶ4[g@eT=&d3"8(ڼ٬_-8ab Q ,s=;~Y>L3Jځղl̜(oz`L`Q~Zn)MJw9l0q|S]G%=qraoZYʰwc^!v!b"ܫiPRH)PX&Ɓ4򇱕cbZw,;(ϗb6TOcS)tp1_Y܎"vBHNq7Ny !7̂IΔ]t_wWXtF!<ۛ>$"4Pfs;oN Y=yPL[&d@ҰQWD|w)Yv~[)~"l/:i(ǚAP%N3ؘf A*PHp$ȭ|i]+J!]+ <~2aB)>?EB?S}sϊK}J?LzA+VW;"ݮY.&M/ NHw~#U]sѼ,u̯% .{ɃSHըЭGR;W N.v$ZשI));gQXT/ ɕs7'"Ķ`8<{㝂hI@_(!g] mt>!˶/8W^#*a,I^dk=£Y!Ct*OS>֥]!E)8y[3 wgvd"*0gjEF&DÛ[yEq2;݌s?Z τ@G\ ӧ4n[:snBN] mRXߵRUp.GayZԮWѹ~,i4 |4+4 D,L\~_6$A,d%Gh5Y([$rY`p/c y;궴W $C&Ugp>77Jיn!)T5>1,x,%vG)D}Fyllt2(5XjWeA񰘲ɦpv;PWPIZ] ~+s/bGФp?]X" ucFv&m%Ù`Ad6 e?:4KPW(¡m>ndK~$+i\Ba&sdH'Dzh*:q6IB LvV<'Ξ&h!sED K2݀_3F]6yY[6۷bQaeu#(㽍ǪTe =h5)npALSﱥA w`U2av@YEafo,͆Ӝ7%dn9}(? qSs%c?gS6a]Y~i?{eR] .q*~'Uv,g))&P \a@E}bqv RT]c[J h,y,FOQ0'}h AY1Q˙/>hN "A?&uұj| !}tC252`zIDQe_uUN*G-w(z8-3eQ!~j"G4Y? %&"v'Ccr@L YYz_"Z~ u[as769 &+t|GĖL25%,6Ѝ+̗D2y/<(ɣH+ ;쥲]dUI"oo4sbY{zJARD|8&bRtM1=[kH\}Ͷ1.wBcaGWYjb,VAHP4O:Oc1'+gfÛ4xFDoղ b:.}B W` +ݕOjx1ODzN90 ~x( 2DZPsd씷mr#4bd"_Gp,],pi)<>i_ L3l.WA_9po$7@H#Or3F:ߤ#@;E@rqz*=4g'f!" w=1q;B]nqZKms)pOBwM wn٨|GEv''0Jdɞ.NXA` eP]if0ē=+Ḭ#R֊<[Lnt=(Wq?sgw{E~0DG#䋝k" yg޼zc/6U9Ұ2Ǜ*r!Ь{fGsn p_ .־NֈO!Aɩ4o5 Aa1yr5VꞫTtyRO/4Y&H^ۯuUG+-pNI;5h>YL"$ksG3Xű P0' z(-W*w _< ]>cy #4oʙ3?# 7o+&R4F5A+Y^\,VUjźn\Y\4:xC\5Ä_J%DǪa\N/p9J$ɦN_6--P o8kJd$#!.GfZJܛ[|\#Wo 4)8ERc(J_.;T~*:GDÅ=p*BC-/s9Lۤ_ٽɣw<% J'ZCۊ ۺ׹Í+rƗ>Gg6pWz]1[3^d<97Lco[]vܙkuzZ!\z!L%utvc-n%'gOK@c2Xǡr@17ne#w:yЅcF[ ;dGz5BE8w0,nf_/FԵNѠ<ԭ?o[fSV>k (ZM[7~eZ\_HD,%R*#i3 ]ɔAc:#o~iWO }@͏b":2%1̀ڬуÜnZfؓwF(|PGim]x&\x1_ T;}b8!T=YxGcF|xMkT4cqisXR,2×~UUД_p` C{FEVs}F~,6Rp (H0XmT4|rí ~%lCNN _y\9[57`6Y!8 jYf #¦E2礧>[pݶY Lש<ШPOW$1X@_*8t`k` /^?zJ2K~>(0u ڪL? |z%_xť 1B%1)b4B*cH=(:b^c;o6ӱ?PBH[`~zՂ0 4u=1ڤgW;?}rzܧtM\C&nI߮tۘ%)Ck,F0Nd&V!u-ܰZ: e֘iMS-*WhK%:h$91kkL3S!fFa懓  }wKH p0QDžQmeҁvFT#Vŭ:PUi293'jv57_j|爞kitЧ9&1OxQNKT.H658,}M 9=t| XuvbIvYN҉j|0(niת`u!-"1n `"O6!vZ9[x׍3)/*4D-S"UXԢFYhb&SB`#흡jasI/C0(y ݯz#?f ||4uuDǩ"87mJkHqej!cRW7tԊD$2&Kݑٹ1eQ*(d+'HC gl#P H۶0PRY^iDثL96, Fs+Yٰͯ#`_Xt|@麕N@zZ&*35|T2>GҨضAJPYB>I:^me Z:]½˗ͳn%Hǫ{<ݝ&gbѝ)p*)TexgZkxɦO$ _V,xqf[ /ړ <JR@hXpewI2.}G/*f^>wVN2#?X5f]0lSȇ2*թsKj,j&x֋aH:W }T+dVC8@kA'$`4?>o3 92:aƉTVPbg{LIװ'muu%RK!]kNh7Bp#3bp:6SkYVZS6o~TXK @ qX2 z 3s= iUTvkSFaK~F3i ]h_Tє"_r&mRS&R)i_5:PgSɚv8ñiN% {_f_P-jiEF`@MN'C=% #hP % 7!úPq\;OIz VUdRNsKyJ#_˖7zwDLAꋇ5Lceʭ34FqV7%eZW7M4J3K PW9./b";z.9#y=- ®ۃ֪okalr1LU+bઽͩpx á % zpco؇缒&Η?z\B$J^ʫYď?doTh~90J t)S0ga$o,@k= L)[+ w[||leYd11CU[UC SBS_*nPbss(cEmEy*mY*%rۖڮӎ  lWe 8ȫ{΄Z!ϡh{ ?:`5#{~(yĎyK5N"<;5'.`ISC՝&%It6ߞCǠw!H*zP88ο5VNHN i6#(q g &)a!Dy* RbB ?>iIܗ7(͋RL9 yVz#,͈71N$!@NcrN1dz>y}Uk) >^S5V4}Q6zI{(SG)]#1BQ܍s|tn8`pRlVRv/c O,n1aŤ,f[*?SQΧm֣i^zX qNiފc'.9~`Wߺ/_$2s#`6KvR߈fXdVFHM3 '#`O p\ޕVy-B< nkҔ8Z}'L{ڢq0]?2< <|'9U=!:v#<}WFbtK+#ć!SQlKF.?x5J it;-yF2i̪GKӢ@܊$֦:8;!@=Ѳt<#4A [yop R0r)hǨz"np@u$E$Wy@|3=\yn3H5յdwn{1x=bK5KTQwsFokj*_]I _p)P4U!UAyu5'o7&(\ىh2x UPNbW-Zo>eE[ HOѦJ/q5" cK;hf/7oe+1 Aw-BH-M)l ˺陚籑R(o<2m. h;]NQS}:֪AHIϲ,F]'[-C?"r }s9{=%4h%zsgӨv>K i =g]JR#r-v|䜭BX ,qṠ`yGedPB=N69"o="UɌCa> 6}ReN6GM (Sq=R8' 6x Nj Ȼi^T( [0oO diD|H$π= VlN7(тLJޜG0k)~nDg>!QT+aX0nuYO *&vRA"x+V81h̠'np>km@L!~v4j #3L$ĽuRQ)9"*ގR%dw|^\RX\ -1ߏuiN6<<9l\nANgbsױ }bYي\-A3>Dg=/j}Q %[FZRisء 9Ƌas}/][vV<dNaY&M3K> r976z') -ÿe$PK3^M],][%۵3i`Gci8x @k[&QJk]<"~6类x(D;!5ZDǚl9ne{8#QY,0zsWH I J} 1C?lDHĚHbN‚L ;Gz$9o>zu`ʎQ(_9 PT`ޱB$YpmނpR:JLh"HX40v׿Q<Vw6IYי8'}*ae#H Z&Zp< ܯT fש-LL VWijR{jC;hFE>j F4FÎ7>DNU;;҄-u\yG"bܑAJb 7O16nFvB? ϥ*h3*X3gӴv-xђ%blVIl#u#@iGdG|E5S̄QϢJ{v>^Mp8.X`-@:cd%>{ђW8-NĹV?2nſYtgjDtYm:۷ʹ0#a^F#{]wޞjNMI'x#B0 5u#49lQ5BuiSgL^O ~G\'obG2)TLv]Wu>u,֬Dlvgպo;zh3q0}[Vyz(b.+r6WFv^4V;~Q$1 %) nBj#B/b|89QH8vJaA`5:u 4IU0Kѷx)slzAs|%|Pz:!7^:1@Ƨ4HKϠlz5%ZFp=ɒ5hƊ?~2a>* mag#*/if^z@9h{>HF<]{XBqB.>b+¶NPY>Q‚= ɼezyE 2FnQ).%d S!/XJ7c.I0=)=C3}|Hjl3wIF&m'T"ږչXuσ&NGA>F,q\Bn J*F£ Fe.pVn}n[kI%afd?/%ݪ\AxjmdAirߢYy&Vr+S LlO?u[Ta];=qaI|VػZY~|8h0zq%q]$g8]f !Ύ>&=PT]eul1%̎;X ^VxF)<[,v5U XA<PlE2M{@Uk76H UB݋V1@2DgU>FJbbZىakYSGQvW7t KῺP{Q]%O(#" 00}z ՚b̀ yDrR?jh~MMҙRCd 6I j֨5{a1ns}Iy6NKD̦Yt>4O־4"%)NEXCmx } ę: ЈsBbnoʵ#Wz+nn=tk//L lK>q.$dkH8,ɤ/ \&KpVRi? V*i{"_@mW dVj'\Yph$чI gۭ%C<[=FSB1'O!l)T:)l滦'-?{]f %3: ̃Am5,@#yx[_ 3@V㥿?[DGA{;"k qSyK-){Tb$Dr& yXfa{)gi|D3~Y M8 aPbX l*I5Ҁ/]:Iju\7a*D'1G J2Loim~H{9.4nY]ӝ5RA呚okKwwU'S:__Qqg@[.Z?t1~D@O.ġp@6hC( k_x @\2A)odbI;ܨ;kzYj[TalMv p)kLhq(l5Du"Zh935[$ ]U"tZlm*[UF̾op5^ v5s'X )!دv|Cɹ)r_yJjO_7]U~bӹQe=z˲4Ԁ#!>md!n~ZgV"үYoK9 9phv谑$z<~S92I5$tA06toTzƒ @tmz1B}U"v'&,Wݮnf%pIUz$wzc^oZ0G3!ܮ(KXg|g9]=%p:t*HvM]u10@huIkޅWRL~u3aq" yFfMX{wA0F'sU9k&Mc=e.Obrˀڇ#wC|̸Փ >&mE :fWmQ[o$~ez;P83:/%/(EbGNEL G(PBR9]g+vKFP` # ocr݌ceN^BIG{BEVG#r,=qVu\lFItcF"eP1 13j `#Sx 1(17VVQDa2wqo\=zOS+l>2G%{Ulh( #uҡ3 %;2SJxun}/dqRz0֋u#&>tUQn=4sJST-:?C$v孄33Y="om}JK|,-Xs1Ż' ךMȽ`JH7LMroɨ)t*_d#DK)NBq4_qW愄\w˞*ۛZnD6Ŧ"İ >Y͡ Y5?:M@wdس駣yUBaoUgk_.)m:STE[pClMƅ4 8BfZh+2P4p7-BՌI,E@ᣠ0ABh ]% sHG<nd l,-Y/XKS)&ԌD5\ۓY[N*F鷕N/p]msu9ʑk[ mB67fO(YL!u+٨qy*76m~IʦSFPnҝ !֏C" W&iH!4\5l&Z4t@_CT+yn>&„Jih(JI;`S]k@܆v^*;S_o-}0"EQ}Ιc}r{ȤԬ;@XL|U[?mr}0鸇gDd[tYlbU: h`5_ Ξa|uSL0~|Ay-0wpm"1G'a5.+dkU> mg^u[Xq{)`3jΨ yxt ws4#w:,W;c$U.( ?$|sJowH1D2bgva-.nD,S6(ܕxzmަ)ܡJG>H7i!,aAEXJո&ȁMe<~%wYڃpl+wBXqh[uc2;`űй4ڰWTe}QA#힙o㍥}+}Uz' rBMËXps6$Wug- M /ԴcV; 5昦 ,j>2 ɟ_!JF3)+)} M/XpRuTgLTs(Q;6i:^\s *yZ{ >1>JMDe(I9wr!_̈O@ ٯ5|וɟi&ΫOR+$wlO?;us@lnEUGCSdtL 5i~SubCi !XOʛf\T|w$ywݕm#䱵xT-0&re|,a 67CطRSgͳτ{gM~ O?bt,%yJ>|ފR"jvco"THrK5JfNEĪN,$.ǒ?m[%^<ZS EL=UC@d8 K7љ~:C_?f Piuޥ,ҮHU o$(i98-Jrb_"nܭb&UڄJe*av{JO8 l,% ,#ckW>f TnISq1 [G'D[Xد 0A?괳L=%Z3?OлDIQwa}_5gVxݕHulX2SMSsN` ;$ZJ4sF)Ff~ Ff|"Us^_,nl@5 j(!YCkA@rZZ§YdgS8m= :!uPk' ; k%mgޓɃ@|. J3MS|X\ jU]5u9ixLĤA鈢,qȪ$==^{(94XolK%A77 XOhȃY{b-nH,Hz KITDa0','5^E"TSA QRz>݌7ρ6l trƵm&r06M.|΄BDN{Km̳QDP?`3&C%1'Md_nT,? עM _In8js\tM &"x)B]4N`>^e8T3~<7?ygX#Qa%Rp(SEpW?3<+i7{~ S FUZ2(lЬkFfWwDx#Ehd`F6|v(6fvr31+& %;+ ޿_[rVGRAO^E tKOoE(uk~xjOߗ,*>G,TJg)5!43wdkG,~!I"ľDa7_ml 9YlvIVڇM,C7fOŸHcTS|JJƹrl7?IR2%Sj_+UȺ(6!ig:JCsA@q}j_v]8eT2x!mid ˻PAiGrgfcen/V Bj-, /Imgc<7#2ۿe-/᫨+`=:\E hކ)}_-dοue~E=dɌ|_!T-n׮Wi&-mz<jY|>|DrؓPYܨ~P);92q۟+|x9b+!"wzopA=] Ƞ`~*l %;c3]E+ uxft8r9\D㇗~ӂ4~^VsVXLuL<6Q$L"JPї* X-g_?%9XPRuqEbŋ ym\ʻ©kznwљ-kQ^oq3Yt y@PףW1D=q[=睸Iו; TɅy htW*Q< 4\h{𢨴S=#OIPݕ)/;]댃!f|dU.Q$,i-:6}'IȉV -!"v)6T6N'qhW-s y<¡7 '>HCƭiL}Vewi)*v.>hy5/,bAh=Js Cnh@ٝ+CewFuwDז k~{Ǵլ*=+]mz"Qܔk@ޗ``8/=PafdA:!W2^rXFx>Rn*{A]~8X"Q?G!¹% ӽ _;DI! mF D:e2cU땗aD@҄rKަ jQ}J-竐/~\2ԩp| ]HR ޶dqA|BڮJ2ĿfJ*b`sZ+()y>CIAN-T;ÆfKa#)xcrnlޭwoK[ơa|@޸G̾P3.0pwcbm|\=쯆%T}kuEUM~pO {N鬝~\=Wy"n$,EN vgP_Y )nBPaHs0ɂ4bim eQQ䴳75 ENiګo|P? 4xi!qQz޼4| !cU Q/~ώvߛMNYqat8p&8SjFT;DjcB,qI'}|&KĞxy CN_֦g5oJ a- )}o*S28w`n٤?/7u'<-+ndh9xt0Gp䞧~HYnuƪ+҅L=Q#x9_irM(iX,c&TCK%egill݋)/㓰?w e#T_ddfI)^R&`AfJMV,[SՆ:QacG\i)u|J >4sˤi/P8 g{c,TkdR p}91{8Z+ c9\&Jy<0a*AB܂Wkbf1O7 jBmAfm<Ɩep3nE(;C4ҵmb7S gcZZUzs3bKs-5Zdԋd;qM2lҺd2ފ>ȠK3STi4s$Um]~]Q5BeEcNSQQfO6 ߣ WBjH,ߒ Kr 64Iǁx oNvg)IK0R^E-Sp*yJpK 0TiYp'MpwIkSn~))=eιerC|䐥JMIsb=n('8cbs/^i͜ ~T*v%R8n e>rγy&JxĹqL-- ,A7k&Hm9MHVvBWw9fÒomFi L6sT_{lSl|y(Tgcmh]7U[ٹKh-9Lּ 1/~wPIn\g4[s>G\KB-}Z"D>G/pMV~ z'I#k٥*C7:eD6M<*wGh"^(x׼Ɲ$)ogP~9(C=]:%eL!}Uw j>3eK`is{ޔlziSwo/Zˀ#7+z&=}g ݑă2xov8WK!&&9f6hFoS-sճLCs) .9$ ܨZ냃ǟ{Z" BcRm;IVudh3Ѳot0{kCtSWVlX5>ءNd+?K^ռ{>95dj.pcXw.GMu1/39 ›J"ޮX6ںsF;TrS1͞6(4l?rb|KZʑ_xzTL <[B2glD%NZVF~zSdr_PH\f"@a?\D $w80"}¡6 &}P'9y8pw (/sB^2XּSL%~[ v3}]c)m}!A1&4U4[ dⵎ~@dE2bHx8 ٪J*篠L"a& $+cCv`^A \i7-] XtL,]Sݥ箛(t y*}oV|~!ucC/sl0nd3[ZHBgK}QvxkXj*5}MnI %dŊ=wy,P紶ZR qxqjeVH&]=Ց/Zߨip ?ϋg&>RRpk +,!8aA_M0Zhְ+zYvP7^¢i +ߤrCT WQ9TNbk eHbڪ#.F4$WyйX*$ANghIiz`Gn! `6G=-p^m ㎄EtDH9]0ͽ9\y`_y~`ˀ jJO]8y-֯=/ai S" U[7k*%;9ok[b!.= G|5[Q Al}46|{[1%Uםf3lg| *4*۹/M[S<%ܭ XT9e7j1dL=QoP}^֋ߝ҂hvPF8+ ](=J$P6EQ. YEt0I[ݸsbWRޑ̀egPZrE"7(cJF؏*VCAv#xZwS9T_2e-&uw~Fueᵠ T~H7k+_aV ծŅ-T!+UA7:yAۢ&q ԡdWc~xs67U%U*eҩb&!3`zsi3+7T:t)O dWK?K, ;Ѣ LrV%\qW|(u>3)f l#;7% NcF:o\8b{~1Aԕҷ)N]k!"ge_Ψw^ڍMN8ZUbE\4W6I Y'Vah/ŝ, YbxeS]m~-S3ήVJ}s%{FGrRkZ![qla :6~|g."6-_!ζ+W -dn]˧ k_N؀=.( AIpZX9[-@Ti'ϵQ8p^XoonfmK2>|vpz6F[HOJR8D[9Γ19&¼%r2 z45b!HI [$LYpp;} Lzp Ғ;9M*١H&֊Tk ;1jG͗XRp2jbQ⇗H݊4:Ƚ Hy|Rf _jEj'pҝ!gaSXZ?^!Dͣt2xC_+R2re"W'8JVTufv fΐ͞R\ C 9-[QBbPϪ8Yem/OaF~AU5 lrk x3M7<=XSa6u}+dq&̈́W~2=_pHOcB:P ? kQλ[da@'HIusM {L2H'Me9b-2ܭ R'*_(/A@÷X!K9i4ARGq$#Ԛ[Ȏ+RkwGKgoܧRk;: ոN63~E a 7ba.3P-WC{ZZG/u)BI;i5,3)蠿1tj+ey[C҉lITܦμ[I]K$ʲ (XBHcnFȞsιv/@ۨ- f{^AfXv8&,b`$v~RKS&5>63!\Ut_niS^b/VvetesPsT?"{\dZ+jgI"A1us:!QIr*61c*R )5q?mGa.PCNYjq>" N+Ż%M) Tl 2x#~G݀or$q0~uAؠkf;L"|(Kd0LJ2% { $76}iFd5{(Cʥʹ呍#dDe4{$\uZqɩS*{npK26|~!}.=*X0 Ѱ;:0ISrA=&DWDٖWpŧo./+V{~O9e6fK y ;iRs2f&m9ؾ;:khOV *ܵ߃tj*Pa@K:}cP:,"@קS30xo]hoF `1EBs>qQ0MĆ5._EmA5KWͧ]ʞ}()GsoidpCl)lh.&]0:&i@#mǃB&>B`q8(j8( >jLU :Eu=2QU{{ dE\Sn5H0(jND5-#kK[;uFB?HX;[oM!ׁK:je9E7I<;ldA߭P5-#0$=fOJ%{buPg`m!3K 8VFܵ2Jz$YD˞NU!y}ȇ+-I|x}5[Q1-VUد` `:=B1}] M4jZ ڷo^:qfj)`ƊUwF^^dd|7ox/ E($&;0aEL.#nWA׮%;w5"w(ͭ4EֵCWpyqHE=#vƣ3<Mg.YPZC/ ߁).7H'2YDL]_h n=1e% Aں?{8-JhWO=9JxڗMA~({C jB~{ƫ_SGPSC$cHf_uk113{4VيD⌟QG=ـJu~ӳ[Zׄz_C.,Kb9Ca?8B52t]s`8$d9 p1X)tJǠ NYQRkڸV3@FMȑJӦYqj.4vb !exqp1旇F-C(fÕB0]R,cH2HECĠ(Z4r@IEU5ZeQf _-!]HɚvӒꞧ$zWd;͹dIM1h=]VUЏJ=ҭ{ מ 3bdUP!H7oڌYD~),?;6e}PeOȭJr6=Rג `U=(,,pI̘5bC 7r#iVtkk/%zA's8ހ]\NmyR!IJ>8"qS?fgɡ)_YVQOLg+{z{b A\m}+^bKBMخ?0FK/9]0 l I}pmQje ɕu~ncrg|Ij6"j+BMwyAS ;2K2-8;eyˢ3iNț#l6Բ<۫s+| KD 4]2)X8#cΐ)y 69Ia )ȍ7H`v_mpJs /![CDi7u??2Of4v߇"(=1CV CS`YuFHy1cSC= Pc]I|SI(;ZMo^+i;Nr~N%Pa )d1\4+Lp܉q  h^bqÅj=ukI's "wP%|\m@$-n"W47?D"TDۅ1Qj HLHY]b~י0񓑕!VCS$3uMC$l7-]dvfy P̴rd+%Yzb Bg(n+s*>Ac:$~КS ")aV-vIvJ,{NJ,:t|d3iD3,ҥƦiޠR,33n]) x : 1&AQ@6*ڻԸ=E >SRVǴjx@&VS**|E ~V*zx揮HaC)u7zl|@gz rw646k0#CDx߉(U6%RݻxH ],F~=^#1( hvFjoh;ܲzT#%ڴQ5$"L@ j-4l` Ѱ(U-}٘o?=2sDңhR=mO< iTTS O?DՂ"z H~8YV'4o.Y_s4& +-y>5Lږ?\3EBЇ=Yl4˜ԡb4T E_>2.8H6 5{rR[Obawxl1 X-6 jJsD-NŐL۽f򣞛ꕤP9|~fUrmf89ܔapص&䶐1m6U]\ɠ_.6( 5>=';fm3mT>sv́*jP'HI>bL'o$p&gj2u#Slrֈ/̉EKW﵃N_[N |+MwڎT!(2Z7 23,Cl,Gi&=J#dkJmQSm˦C8y咯=Ֆv|I̻@@75{;;*nV*A(NS׮w:-Ge?)) $CȕFzhQ㢉s7A~' ׹v4w3kQɗȡo])kH}ݳ ыG8<4ۗ[A3Ŋ]ଠ"R[~.2H$w6MB%5ki5wh mw *qͯl}i ۬iYDaV!a &ٕB8p6x y16D52_ڵd>@`[fLo6<ԓk?/څԑ9_pכ?q"2`HPFV6FS KZ_d*&$BtKl{*n8t3%Vuқg:*ډۘR^6νN-Cw.QL9ڡ;Cr+gXI N̑W-1qaPznF}z&0eo,TD@Y  Rv@_0Q薣@\d}4iӧGH$5p)M5\;$s .}}NZ9dYO{n2F6l4>R Iw}Cb?_0{5ƢQl &Oڽ(8Jn!wiw 8{45-fd;; 7$7`jl]y0R&=7"eMKlTX[̓r-8 VN#rL7x;/5}mcR慪YG_AaW"'c8%/~խ> vTx!O RgP2$W*- o=yiJ ݫ٭5e*FuU#+PyUD_6Zh.ez| 2.*mBi!Oj7RP.x.=:ʉɅH )?szJ֭xy`'&#ePi=sl(R䋺hQpm>q?̟H(QC7 +vmS PYHO?sh:Nc~w8`B3:@=PkS BהLczf(6Q4؝G2@)X qh~_YWt͞}-ns^gph\I Xg[۬ŖGuH'[J9 hz돚s9taK%zO/슖5EG 'nKs&S(Q)HwghCj {ϓaU3[LP7;@L\/9;w߫z*itfxAi;/=BUCYb"{Y`]ӉWܸr^ 6]1B,3xE=n1G7`^"CQTS]հ8}h\!Za; 007&|y'ˢIFU3-Cyr%?̲~f)d.q$vrփJ}L.CHv>c齀r T;3Jstз(fۓur_1x,L%T ~:TfXD~SJtd=`" #e9M *\nQvONɄ:VI֪.jEʓ,TS A|;QUn˚9ݖ 33,//eo19 t5@a=RV@s$M"ژh̍a8{* % ;:M!hѷ^pɠ̫܍Hv}>fn&-`l%Ha}lKߝO#3B q?k^gAw#փ4Ծeٿ0g2=~Ie{c}Su3GB?%{f |?5a&ټa_\l;{;ߞs9XfhXDj>U]1*K!QJl'x9 "/8クMiz6Y;ĕޕֱ)1gW}F?_mg{y|ĕ) LD=eɋA߫K_< bFewwXڸ1lK ņo+ieQU댻7WFci5#{bV{:AP*E;WJi!y^ـ:J׺pɫNTώ>Mf`A.2OH f;0NJ&H1- ħ#,!u}Ki VԄn{׵NXMft.K[ְV7#@w349nc6c54Xf7ص7|-'=opMQĠ1c)q43"MfJz/+Ӆ_f/2rCiǹǒQ)^߿!EeﴸjH2u'}]^Fa pL[y[r%Ժ1q(5wNn坹,SH7 1|FpWougܡu  Սdf6ARi/\V|3\`MƆIɉ@)x%HR܀m1#vLWnV l\2Dotp?cQu\($ ~j7JUx{xBՒP>p, \݆6iHԀ"vtpw3*I3*_G_-몒+aC ( K#jR3t4V&ngqQl\l$&#͏"+oc9{B`Tλ#hP%6RU?߆vB.)&g2orz^F՟7q:U!_7%GgŸ)b_Pǥ$#i@xn.㷾h6WEP"fDB6B=H_!pX陃)7F[3tS°݆1ǪDr1UX{$3Y8O6DԦSHؚR6^ȉˍEď_j YU ;b'R l皮,)A9)N 7˞߻Lo<.̟%q)fcug[S^k m{)l`FD1Dʨ7B}z;++͌Hy,jr鹩q#n&W))ׇP$Sk׀vewCЌ69:$3!7Pق'!pp?O F\g2B a4CQ_ssU#PY9_Pg>A1$K^s57uLXa4Qz|`h iJU ! u5(GVS(Az3Š4ǚ pFG9HPw]9AcZKGua-axxԈ*__7|%ܙ5m30^p)).oSX<ݻnabCI%Y,WLfhrH@I/`P߃CUBV$J <BBkO BLv~^/4,Y* )HipIKJ..δKv`YUAMz5X+b,vˌsl:`X?#fOB(vڔBHP+}/JåY?euTE8'䭟`#J~؉&+Dڷ:*,ٕРʙdKyXv^t3+ZXph!( 8#MU+w#} w}LR#2`U5QlϹ(@gIFb_*|pj)~JQ0G"ţ7QVLI$-a؍_H}f v`P,V$9,'ǨBLۃ$x56Y$+3V/ FB#/S=5F ÒVP5|\* rVSN% EץZbւ pa*"͟ڗX,ِud؇o D֢ZRIIhsZ!oK0Sp G,O;eN-ߖk;Fb(ܽ޹_l\2 7,NNB EuWV w*og\)rg|~H%o^A׭PP}2 hŷ+ܪl@8ۧl{^: maB-$cG[ $,)qnO$ e]M*OeNړOk~)0_4KItAknr~qS R%.e -4"@pɣ CP8ba@uMi\ܥKWd&a @zrR ̀?lK|j$A MV b!_O!F GM {] bG1C,r^fZY qeL'ыCCvF p~cXxQUc6ŪR5l*GnѰ ,$,T)caZ^Yx*ͨRBw+JεbGjIP)FHOрœξ?AWrOoAIbρ8Z_ӥςnf䚥Jk)l^!uf?pv}lGX;{Wt)Ob&]6EVk ɠVqJfƸdŝAJFڐOԻZ֎}\zGLh(!)\rgbα$qZ6 mFӉkr>jNun}y{mW`ì^*c2Ev*򨱶b/QpqZ( UmwƻK{1d~+jfA~ 6P歱m(,Rܨg18Y&_@b~seJu(먰'p)LSTpY|.ʅi%N!KʈRl0h=uo d\<?O\Gl!JTWܺM m$wVT:%QKk6h\eҦZ#0ÎE ~G:ALlODˍye"#گk = nr({y=Kj$ ]ATGdV`j;"J6г \BWD3bq1PbC BB%fuS4C;7c! A:Z,w)Z*̌XS>-- {dBy>.o ^OQ!_xF&蔔z_XԾ .NaSZz 4%z|Uc]YiLkM e4fzv҇zk ;Ȗv*;x$4vjl'}b̨:XŸ=A}dFwqϰ4r– ʌC7&L)t YKQTeuݞHCX}p2/ i ǒn Dކ+R_3vI h ね z_Vdk eA&#`1]2zz\Y#i#o{gۦ!e v{פ`B:_rTssm90_km,uį:k YBl&х{Y록dVۭ ˋ;kMxо\eZ]/}7 >ąIlg/j|)Hxڣzpzʖiaɳatl[,yD6.NsnZ|A nݟ-'Nck;nL5txWf2#,J%QLߒAK;vj9wbu%VZctBk|f8[u3*otr]yH`&Ϲ]G8I\vm@(b2ʏd`!ٕ߄VRJ&#'\`ݧe0;bIgM`hwM@璏`||k_P{/RVW&u LTYJ?\>{ylh!?∺y]Hy%&s%F.3]ՀL & hf~:VRtm ){!ޣlrE7l{lEf}ꭎ9bSJDռRrAtڱo+_kހ˨+CK\?GQׁ7iҒXQ2F)mՄ}":_fnvWeD)'n @aN_F1_2=h>_z>e"<\nPeZչ^8u ~^0Oӎ?O;}{g4%Ub;tG˶uu `Ё}xxp]~醺U!& Nw_|Yf"VF(=Ѓ-QVho2 تXI?徫S<1߅)av]CRN[0$'G!VnPaD(|M10鿘2r:g*, E.1XsҪ}BZad"~;i.]`9H88{dO +A7֕Lz&ڝùQ" `ڠı!PyJZRÂWEOJ_  /U\8߿qܬAP[Kw{6BpяAӑv8 eM%qXҁ+OY$)8‚C]::7SC/lE=+k/)LIJ2K4Jv\Wkh2H?hý`\/,,=|!D : f]/ooum\+ '`R:ftj퇘b4F~€_ s.82E>Ȅ+I%;H%vU۽0Ÿ[2ET#x4ũ7Il+@CNV_hcלƽA$=t  J{E%ϙ 8H677]٭,72fUОBwTi?qϯ`ΐ6.4klڟI~[`UZW:Ӈx%Q $(j'.L5v)T=hWqш=$Bh6PՃ/=j;]D^%B1Us bwcAbPea'}¯S'yTd7HQ46DԡHL/58S_cJw47逥r@8(4 ޥibFchQ< &Tmx (Gy.Y)?-g*ژ ܃hx谚T'!Uz2njFm(6h\]`g$;F-:/}h|KMZ5m-lXvvwyǎIF;|>L78-T7^= Nxƨl !53 e Q#7w3 mD:6gѾ1BY' sDYa5Axj|).t S-T'iPB#ud+YLv&o0 1doZS#H/z# 5DYFTg AV.)oO|N*[1N&۵;H2j~@l= aԷ GuRt~DU@n|v,r+| ?B Ƨ&/~^Ay{q3zNTkXSmlGCWg[#>jM)v*{l[wKQvyR4 [</)w 嶎0` ,~ (֪0+hytxHCj{+ӆuѭ5)ێ*/@aB" Y7y)خCdK}PiT~ @YɪPFIb$,a::h!8OզxF[~z~7-Myof7zvJH^ǔ72;iPf3/x8pbSޏ!iε6B"$5tx, ۢ/U|"cg"fYCBIմmC==Iia!rMCnGUM҆U,|4`~+VV4qFRP,:Be·bI.xK<5vExrȢז$WF4}QH?(ViG6^ӫ6Jea0cu%"@$:J.k.Tq/+!U/LJ|feܞCyфx⓬jۦBBf!ѭ% ;sZ G 9MeLፗ/pvyvĵ>vϢph,;S\٫s10Y3QX>~W?,b'H9Ere8^~z`Kmed>{\Ƿookpk3U!6#Ӄ lgR蛊X[֠K׍Gj`*rmawG QI[ 'hE24iufQO`Vdz=mV # vN/]bdQw겱;T3:ռc`VsxqڼBx*ӔIz$sKQk7N|o| 2l Ȧ(7b`Vv3F3oxk2_3h=x?UNU+K]6WOI3;*vn& }diK;ى?֜/2q -leSfUL/l%1t$3xgBAg Wjċ`O{}MDlaV@킱uO'SW屢T#J- % _WBcK4< 8k~ɾΨYXa\­\d +[llDP>K\"GU|4SfqlA'7Qd*JFke5:]=^ڴ,b9#_1L㌤ϳɫ<;]Ne {&ΰ_օ8.BgwIޘ4SH( M$ OK:J[0CA֖aeO0bx )j!Ε/RpSi?-,Ks1J#'qBk=[er |!'5Nv:j6ҟ!keT/B…kȅ>?60(oXRe/(QYMulqBY94b^h03?2_]Iq±8< -ۈEhtmxE )CQ|#蹰2t1V OKZnsùyoDJAǑ otj'0l* WhӆDG̶GC^/Y'ƀ>z?h2uSЦ:X6emX[Z zb8.1?\2|o70sJ8,hijxSCh\jN Ǯ+ZEC_׭(͇FoTKq}KC;Mt(OQ;kNlgBp<%-}FHxT%wEZĔxA9+O2z>e睖ˡVb-jL6At򭖼 &E42H#1pW}+mU>xBcKCꗦEB?ߟ[i|ڗYj1>~EJCj ɻj6v(t.Ug?)!qq5LSm Y]I~V;h`i7$#QN$tlP?uSL^CʼEC6Jˤs1sp>[/%d}xzuYH1Q|+ +Tn2a@ ŀ6čtRuBb-!Ya88.hp=92ɵt; n_ O{(~(]uYjc%g%+CxK'ن/<--;+{7Fx{8!Ͼ*m]<7>BZ0E~*fV66wGkdGqQH^\L lJ`&,&(tx2j/g;OAQ랴[.9^x[.}ķp*YR itnW '~4B{%N42^)ȩd2-cLb1g[  \ vO8q0SLqX//;"޳c}DJ> Vjl_ēup=;Z8֛ߔk'3&)ˎ#D^սЫ~fE5澝Wc 6 E*nn7~rH8NP3F wFp>-9IO lR9GQfŰ_!SBSƦgD4tki1Kn*FwHa ~܃gw' Bo^^ᣟp<1KO. j>qʒWY x*FخÎQ:tW%W kV[7qP Vp_46wzmWy=?nʭD|ݠ?Ek@ ś d?v{t|Td2lOɩ:pj96rbZ&~HnڈLG^vQ;(ÿi%0aqG9`7|uV4I7_`,_: di`:$$v(QQr~Aȼ:UY/{`s##&޳ŌǶzC/t wIkp>;ʘ&+8W6Dn7JG]Dz^YDs81bQOjܚX7&(!yH eȊF* ΔUv)"E;bq5,aqIf6VټHv4yJ@΍m'tBJ'e ,լ٠C~{90vR^M*h^o*n|C!YF YL8 ~3KP2?-ڙaIPCyrwf.x f{ <2jWj݌ӧR|X " SEemUL=K4\,@sq1Um&9}*bU͙;V. W=]iz -+ˣjB%DGMJmf҈ LH:ٲ_o:'cXw;gIgPd) V01k5%NݶW)AK``37yN}IADs$ziU^ Ć- ç?8$H\ Ň$8"bf`oxڈ)Hʓ^Q9IM4PGaj'7QR0]bq0kJ83ae24s426 ,IUs>tΙO&{(Y/S. t=f.FxvI >}LHE\๪!DL."*Y.>eU0AJUXB1.YW uoKr9]ni1Q'RRl%Üo [~4TϾR #g€JVSA51?u詮(ˋy#N/ <׊+px^~z8dVc^$[+O*4.[={T݂IJIw;Hnfe߯,|*PZ Y% ->%/s% 0W#=_m _*&gOhvj1ɺ<Ζ{!zTDDuGGO IqGU 6$+umXC/X3Ji~`՜@+@zBE迳Y,ݐLǴE F NYpm/o ` nM1[|@r,R͚,fa80hy F JdVr澙킕]z[]7:H>qcToA,# Hzۏ/UJ3=!T78 *h꿊Tf/G5'`ou*Νk| ęrI4>Q'PRO т=_A襛,h&֑UP6܋ lrqҙWz28l;Ǎ4Y2:K|KB5 DVٸ-͍T|mLYC%0`uT]`b"]GURTbVr甄@`;HɾT.q)1eO5B샶C_>N % gLS]/zlF'jUTA|Hgk__c2URGjc62U½C1%i7Иܕ`_d( ={SL 8v@ ę_:1G9(4ّ-vcd%яq9KDE9:6aΚ%NOA J$l֓Jh\Tva&ݴwU.MJDMd wAY\k:[q!>3lF*Mr鷡 s!߲m݁2:nfwKSxd4oM#$"^R$cBɌ֔v"/_m8g0.~v@k:p7b"JU'5R$?DO j=JQk @D*!A3h:EtrW|ߞA_hS˘y~ B?>'`pXJGz,8bPBdi6N/^ht{ϩ[IZI%Dpt+I =_>.Nh1h C?|nO{$Β|ZD8IH'񿃢McssqŽe?F$fɧHP\Avj]u(ȣeل[*Z ._`F0xxA,uC.pSkY ~YArsxgH*mtD*l==U@$1Eg,`VIUD${q(4l.\0̓w4{רqhWʠ bDMP+Ə5"u ȊUCf!Eν  X29_%A2tv:#YBZ|.W 1uueIX+u~u[m7`d0 Tv;kLs:Pa :tigZ7F \yxBk9/-XvMl{BǑ,d /LG`ĉLIeʔ:£9~߂S8*F༭<iL'A_,3 `,b1x"i91FqYp()m#ûpJ,B[$(hc/iEt^WMjtD1$It @`I1anz`Ɗo(vf[?YC~N ev?oUtbje)KCdَB1Dpujʣn KómZ߆]< 3)q m B_6 c.[]b!Ƽ'4[MǕ=|U\2 5-;ZA~6~t"x՘CW>|.U pA/5 >[uknJ s"$b>WOXLn0a̡c:ƓZtYFŨO Us1ChEu_@b-j:\AUӐĒٗIfQ-Ez<_}}njD2`PlFr2Ct!OO҄heڬƋqG\VN#Vh)*,zH<LD&ےxݗ6Fl/O ۰O 5d"ɓ}Yi\_%+c̤TRIXt1-\vjTl,ZƕzƘFWrY$lҷ"CC̈Cxlڍ-ŻRmt}&4sB.}3#&Qq|y _3fJ@krj޴ٳQ'bHyM)*x7]Jjj_s>CY%'3-YgDϓJ{E%ºT|nѸcFI;_PZ/"OUUF2 z1A[5TIJ#t{xh \- x/:]Ŗ,F/ƄVݱ^|fsF,&K"=6p <Xmyih= I{RN4,wEDO” k'-! =T I!f! s wkpL'j1~죇HOo`Dx_>ЂάX/Cll2ss$];~X 9vΟBՈ4ó}Ha$ߚrSv\9õT9>$<~C"A,韚d9j疖_kfWd^:;Q>Od Rj1݁ӄGM*P2b %c+}2:Pu`/;i`AØyt6=j 9.x SKc^TfHp/#"~kULw9~Iac%M9Oy_)G+E_]HwKFHYx7AFeh>}9e_xU b± &0`{m%&kW˿$/4GbrWCPVgx6X){R0&LJ҄='wo60lI*\ pc!+b~,IV ^>Û8=4 LgAa0t\:7_H6*| t'v1Mubu5lDMl" =Vuk!VV"W`ӈ%J<7:Q?w,$D ȳm_uN<u(9Ocˢϒs'ɇ=zv-4F` }<6iybϨfH+`v͖PA(b*/l+LR>mB?%_UJ!urFbI4Sl{-(9CHBC{I{^E0Ewm o t~"EgD ;Ff#:S {f,3qL\v87_hvkH 0Cn%hDLmGb^45k!e $J_(=}ngZ/=W>3w5cbzTP*KFpqw" ɁվmPڇ Vh{0p32+7A5~ZiGmb@h͵'I"ڤ(2:4l4u3!p<ߣqoKwȸZ-ԶgJ=,gHځFeA/تy,R>a&Sqj2+̓MlkNHY}ÂCA0e4VX~3DO}ly]rۭS簜r?ʝ5)/:mT yUm g%v5q dҹ{m}|[|f~vKEZ?-T%I"s8l 'I=5bBT#8Nk3xĚa>6&\5 +l,YV(\KMoޝ:^XMoɎF֫RAC76Ad͖">+$əg UkHK#η$SxR46Ȟehf,jCscǸ#l\G!wl((]aDS)oZcR +kdF$uɑbz8 zKu}:G\-"M۫&ms=X~D+ Rd\Dr%ùRf;{epY_Ԧwqw*Ž[1D(NY26F`  'kiZGNQ/G-; \?Ǡx٦"GW =@}{b$- j ~vLY|Pcq<юy3m'Tno;N]cpZw^";ۂux,ǩ^`vؚ KhKy#c}^@:%/G|A&/GO!gн_竚g_Ĵ 9Ͼ-kj(][ -F·ɋ]po&@MR*%wCQ|K!zHDDZ;S]~Js`+RTis ૾u,3mܺ47ʨ~Rĥ.MZǾοܻDoak,)Ĭ٣TtT5֯ C&yۡ]OȤzPX/4ӈ)bTJ۔P5|uvn^Dž*1+Z<!6̿ڲz/d-B(^ŗ:f%EN OAiW.}?эf5d\Y<MږF^@|[le2 ?! 3_^w mmFs?SgJ/yǾB U  :/,"y)ɫR2q[÷R̔mmC /. ]D$gVy[l'Ɠ]}%#BEDmyec?ĮV7oބ rN bdkTCK5HB"?j/L( 0l&L-n,iDFt(RވbmFV.HF-S%5.d^*L M(g%oVHI?i?dENhT@r,tæsBI#$+H/8:]d5ZSVtX$P^Tx"J]_dP<)–.ITmK{oANlB8ui1{S!Y͜[,yiw7zPAOx_$)ыbkQIaԡΧn4'3l(ҁ+Xukz uO!X7 |av xH3`M#ʴŶ0$Z}l'}E6ABLwmcJ %g ð0&˔q޾jt; Me!]_Fp.NY.m*ˁQps\j$EU!׶[&b$9Py+^Ebz8J8'ӇHLtU<7ěx2UlX=#Re 1@ Blel" dV6>zBW dzYie+d 6^nVL'B+C ̈́xz۱_ Uu)sGmY/{&yr5 S4[_1ӂW>#[a-hYԡFyw`"%f %J5,^}u⸽\߹43F/7_pƌs$8o0՚<-K|zbUO'? ST_hV 334DyF(5)t8V)|!G8w|u}U b) CZ?Wf¹5w5%BmLpEaY5.*$56[3Kg*q#)Jхw~icM#AP[0@o7 t ie7,TD|"G B;IzW= Ow/MD4K~jb% *pf|]%l=.ۗ}+n8cJ\s~{[/~~M}}xw u/$QcBUK[4!F4pO,vrM-2nl1:NTR2˴v1%Lqj{ `c̹5x5 Kj]qy _cfUYvO[_ڸC|FJ )TLn-2篚<$gzÔZtvP><,'W34r sNDT3To1)lDW5I VT*Õ>MFyj>R"#\ g(:1k]&,3gǟ@MjBMeǦnZa1~k9"lq5~$Z"t*56.]wiճhz d_c=7 :(9n̍MIJ[Iq*73=YzgM2!ps쟐e8͞]HgtT(58v95q?]oYU#V@Uq)y,4tdL*t2J`2OZLqiT n3XFl]#0|˓?va}$[p}D-aZDQkcfJeW:lWV65cb`FGRT;om/MۈP icӭVy22<(x=/ׅ߆L]tXEiæz`'vѵEjx `#AIdYwf;T}G "?<2}7_Wc_\hhh|>ɪ6 ʾRہ]7*0ds 7Ďn,jWWFuWf'xK D ..El@#\AD NkJ &tik}3"m.~n~ P150M0 |obcgۊB4ޝo Q'ހ妖m(Q_M]N+- (ō43IFҩgK0~,]?}AUVѦ`@6PMrSM7bY>6E4+J`7-c9F6v~ybWFsvt!G pc аާE2lj W/I5i7b829>tvZmL2|'0ثМb?MṲ=p(_ަS3 hO,O:%vC"1{`ª+sx6~K*DV"م=qLTv"WGm@uߕHX?9w AYB Hwr`kxnW⽃ptko!c`@Ŀ:PܜtL?mu =̝Ӆݏ&am11fV WNTH BE:?IJ1vn'(㚒T1Yseه,x<*zO &4hU7,i/_G,/kCa_4 =jX^eҤy V^EO+px/mvhmkQiuT x,4ӎRsJ>P%>e̽366/F]` Mom} KHMvInE'Gܩ9'c^ =r]C X~hrtBYwWP+e]:4/^j'pb;aɪhq#xC!ITlsǵ,%luoѡ%%z|(F$d?hg#i_0P4Yv Lmr5wuP(#4&KP a7Z QE` o.7uݫt םWdXOueXfҝ?g\xUQkj탠v6MR|c35>ήHC:uDu Q;LhI#Dg;, h(`U \ژ#~%XޓۗN&ɲ5F,Q*H ,>=6`t3yϏpԷ+Mv_ lćil,[H?J ws7jXs,Rja2F@0➬';'/I#.u3%(cҏO J_4Zc ?yCW7;YidC7vrkL)T#V}k4X>陊}A "5 FBJ;[.W*|z獜2N=&|Otې]|2cs$].¦w,}s⒤;>?@H~"}A &lnTrə߫ Qיx,c g&XlGgFYgeǺ"0!TRf3]GWi- gkK]ѺY2S-M<{/SQdC(XQ(A:|і幘r ,JS?wd+<kdS@>ډ&xz<'6:}HElOSVvM jAou=Am%y_F╕d*%_@V Mw>XAz6jCd;Ǎp[wLsX -|k/ -݉Yd!Z6 wۧF!Wi߷Otnzm(I G=24:R LV*~Em|5%ߠTAG\\i~1byEFI_nZ`_6|Z,~R&S/P}w'bQ)Yڞp,!'*Fμ4)K\kO­ r^ z;-4NEO}>CM%NEՉש| ' U. 1dsJq[ Ĉ%dD}X V^T}RTh kT+;-O]'Ś q^u(`gZcBj$v"CT+mY*2`ӂn1v>| h) 3z ֺ̉HpQc:Nl%A JO'܊,G&u tVE2#$O*l᪐×Olr'т7x3/FPf !b7KNFFa*#99؈(jf/n Ó SmlA/S(~6@I u*ԀMvP3kQR^bO|nbsU-\AԒCcZ'`tO!41[>Ak#ȌŨCiV -6>s< [=>.بFE!=~9=b%vͨ[T'hފaPD,0L_6qX뤞rZbwX`ޞ6cnX}@Oѽ5xWB;P|>é'U;GOT`kb%+a2\;>C u> !o6#ٜœ[x[4cQOɇi5fj+Q mW"̒n'ډQCmlͳkEܷ*)e62))|åNO(چ5y PntI[3i6oKxMD[KMۅӔ—udr7%gϬ"Pn)\J&gIFL'i YvV+ˤvj;< f<z0\}$Bca,`7#<9af¼- JQ|w``iH. pj-%I;֋%ˡ#I-;Ws m< )ؿ~J}&| vc'z^?<ɱ{\8"-*aJRg%R9hZ i2x@n'[' dI]| ɭ0C鹩D+h=_ %|a#BBnzj혞;P$*7N|Et9{,t3Tyق=zH?^)EA~^@o[I7+kF͆1x1W_ #OO$}|䚪3xOEGt3-NnZ쭥&w9 u?|IL3l^dح>4,<=Nǒĺ)R9G{Cž$Fk'%.#i`(lଏa\Nj&sb=tULXT~bq ](\-B13d+E(qS.!kf[2Vb }g@aΘ-CO,šBD,u­_.dq7MR/R,p[`ft#zq C,-jC!\|J$FyHh0`ϑcIh*'P:}+ W~RU0Jl. {x B53z^350_#)-4'۵#9BqˈUzBM3A8 ̓PÊL+~MMcDCr4W7ȉX\%Juv QB(;6&yŅk0(fsL A4dҒ)=Xu?`t僤dr\FS ;Ej]{q Sxt ଠ>eT32"\@WJ8%lJw7o{w{r<ҒXg4* :АoG틟z'h1` mg[J 4gT@񏉲|~1Cld:,?(\$73. S\U|{ѪBz!:(y)/Ofh~i=ox ֚y21(e1_ifTVT+-dꕵ%6q^9+perГgVZ5b[0EI4\I2҄X|]odnt24,\Քepe6ihE,;dG?RV`i@nY]?EOU[WIЫ)vfixǼ?fFH1P{-]#6 srD3qEjUKg։1QB.I;1b0FzhWM]CF ruJ;򰑈U4rA|VEzW.QbpJ6R\"_, Bc㞈߾1/l,(b)%^/06CЎ3aRU n5{W~.bvPkڣ"BL67W{`أw#R gph_4Ŵ(=7>!kVŖ$thzqET%eBR) uYM>GhŤ:4ϞXV}WD7[Κ_8 ɞGOdH-a{1];FGUao!ԁfC[E{k J7gZ}mˑM3|7枑1I.&\7n1*t֍ugRFfjUj ny }()r] 0e=7>iY0t#EcW6t;\P o{V+ ۿ5:w!Al 1.[<j^jim(c.'YfFH@= d& (1BnH;f#,j.j2wN~zB0HLl;[gJ{;Q8`H{_4 xB[KV{6l·ufl ]JeF>;⯔YʹQc*\^= |?˷"҉;}t xoB'SG$XmR& p;K]k‚J &}Ds3O`0 ۣwߩok-!סPܟ Rfn>&.r8YH|h5w)|&3-D}( (vnGoN5W5JU-ȧ>3m4Бv"Ak#N+ ^07)=r&:>w瞺D&BS%`LWqznͷTaexGru<>%3ԣZ_g.&&DiDž#Mׅ+鉗ՖӔ ^2( ~ o]rͶm$*ìpr69 eeWoBSn5څWa0k:kZN ̪:G垺&#(wJY$ILPvzm*Kdjvd+h8D]MHi38〺j ϔG8 ayjZy2, ǎ w(.^( nW ~,K'&(oOEZRN6+S{ <+iq0Hhfރ)]TO8wk+ouƟyhH; s3!M0,ܭ;'z};Nr(h|T2t.`a6 #~*fMQFH_TcG<`Z^^TIaMȫJU(ƹ4a[ [f[Rw{:NU?dtQ<=qRPkCu.C̸*|pJUM%WϷ DLIrqM( n 8س[!nq4gOQWEBḳ6gƠF䉹:d*Ӡ[:cqv!AÇ?DLmf.1Un\˭OBA&Q@|8* X:DU6&>yac64Cʻr~f&IYn"$toC]PnoNexv-"1blv/2d79m aڨňQG.~ u(ժr¬l c$wCH]fs*Iқ*յAB NT?88]ti #&`ŠU/ .bȱk[y,ܹ^ui˦:Y5itu`ty&wU:D 9c3tP1#%9YeM'nS r)iӞa2Y\/f JM1\v6NS,CNJΖ^h:bG謚TѴUl] INYpyUE~&pp'3>R(4"\) nP=%kj Fwk]ߧNsp'v<$@c vѽ/"Xq3PFqTBvgb-ƽa禊/:1j0Ӑ{(3e,k_ڶڏ E")0pwY1}Ozkw͋GF Udz' Ym{{. >".:٠#W=|hȑDKYZ0Y*%:2o[̑ܮտ:5l*^|j }9ۭ7YrHuL;4[*.tQ!rE+2zdن6< q#0(g d#2g'o:o@߃=ۆy!C=X qrn!uˠic.[:*|fʪbvyhxT|`³}$]w0Ql-NkN[4}D]GRoj{m$v!Yh>\V}.L;>߲ 秙ܦ}E*O.Ncaܨe-6 nl7xA^[5[@Aq6+aaWwszY6< ފZpRsuf㩡%4(L3u"c;f3!|>){1YTe`KM'"~S5fҌdCo(Dط# - Sb%֚dȷ'<&>l#oG׵HA=ׂ3TΦ %r2: ,vാM-g_9$rd^JJ)fOk}'V=^mʎt I~Ta"i+̄Uc֪IR+Y5zD+4qJfuճx8p;8f}48) iB]a~Yr[hԟX'Ǒ@Ϳ3jQNwbx-ѐI=|o \"'' B׏4t"Xw}(4iiA5HC0}Fʹo{TJ9UHpʗZz^>5-4Ĭ֥ݦIMuQ4~GA̠] ؤy2] `&j4RDE֒)E0=4n/#Fj5B@\C(~ǼT|w/vA*_!'U+'6oyAmGD >]$כ!1f^ ϲȽrdjA9[FL4h4q2b4ԬW%s*| 4-ye *xe%yO cL]Ǹ"XE'hF͎D U%LjRwk=W*)lۚ5Bz_Xv7GQ53_EМDlw¡[d= u%z-tƦ$ mtS @AG@ ӳĚ3Rql "I(h]X{rP5* τ[Va=B pNuLP`})菁8 !;/` ~n~A0]`o|}$e.s&W 3fl{|p"J6\:YdD$ ' f2W80A;2͌7q]m%5# =xcC!US\K_:Į=H/:sU77]vRΕ,4~M TѽH-)&up0pbNg~?r( T_C-u1A"xK$>GG3tX<~q2$"RF -/df'6(jm]HuTqiT0Z˶|~ײGs(e1 0э@<@ *BZ(wsh_X~䬿byV_]P}osu1*0څO ZYlUfU>B%-WG\钌^. V *,W9]wuQr?#(No\*܉˴FAR%?:ĤvrJQŦ6'ɀ,,(>f3Q{ǙK}9XBǙD$Xa=)Lm–PWLxj.=:\| I=Wscr*:ߦܝlz3!mgRz*{԰XjLVfgŲ\4;b/% *cυBa%'^Y?sr 7L9`w K@6jvA~n|A @zІAq󜂔wM"F}6߅YK;9e*Y6:%|v1v>`KP !⫱2|V`0_+o4^>Pٻd\ "XyFy3SB`Yb nvk/R;9 uvjJ@7W:r$r}[,NnOBUt'fx>C@!G&;:zc9Jͭ΋1Go跡(0*ܫ9ÅVUrq=Dx0r=~oVbоsiןh7*\ IY.C=/͚ e8_ym}C5 bt5]WSoyRnYyzb Y@|MWWnA p.aմqB*^i#|"[0=7:J"Ep8)|YyR{ JĤ`[ ? )Q_SϘYXcG~#[(Q=Y KA2ƂD,숵oF.\N>5!z%2RB#B=X.њ>6/\$Q]"hCRn>w0԰ @BS0ST7_ui M]viRnK^SBлq@Ll|w֊GbEmUS+B˫N6X,~yKăǕ~_Jhd 4vzEk2 #k::~*K­Xts/] ɩמ\\Omw$@ r aYJU!Q/on]#%}g}=I#OgE 7"$M7pi5g8"S 4= v^ 2'w#2̌(N>v%@-,~0l׻cL#=gϵi#s#U{ $ҨO*Q k=:!z/^It\MZP &=6Ns|xm -.VR`b!9yR7t{F`K}թ I!{sRy}$a,#ey fjD#uVjY Gއ0 P!sQ򿖃uyA6Dh|M-pC ajW }ִ>QEΣ^  ;x#AzC12'<<|mD}fI6n*~غoyJMe|n?6^~.|Ƭw04FR 8wO*H(d^X=hMx 8p(@yWwM;ʵe>rx:_VWjσgHe]Ӵ0&ؘ qNGVsߎXLeN١&S 鐼|1zE029u&7_0{[t+q{Eݏ5%AKa52gAUPHVب4 aB{C18%P[0{lޏ;IbVKGv9gz'Y6[k@%ch99S#?:傝YV~AL+$:-AzvLA.=>BMپҖ*on/oID!ōnY \gR:]P7fuwJnemNݥFk0vu?z$[[;o@ ~ئhlaXGSnEMrcb0L!˥ ggp5>;"qr^vD.Blmi:` qyqBdoxZ$o(!xj7H6';K1:2w^c: UeTN m-΄LB R/DN6M۟!)Vwamtk3=z)!_F}^-e0ޞelјlXxnTޖиX[Tf])(sGiXm暑@$xNey= ڄܝj+;+|\-d/ *3e`qhǶv;TX ۘ;DzEZe[p$GB•wsTN/ikb2x:WtsJEmr"K$]d*xEc}`'ʌvڈ6 قPɪ.i:t 0hMU1L&ͫq' zY<;gA*}sO,#7{~dj`My_ڕ5߮Ag;~znj{}Ww'Hf߰B%AA#R'^ 3ry.V _)吺,>'ڀ8CI\qUgpHG"|9L5d1=~{[B!L`u& -< 7!׬Uz0c—Dxo ƽL9RVt@Pf'fuKO8_vs#8_ӼB.JG3| g}ED2=/'oIn:$f-'w8ak:UO;%CC,ud]n+p(ޓ0}aʥ pIkTB9͑$A;:\t9D|)s,6#a"v.kaQupx+#F!59r~!}ݚ5_-#,*mqv2wDaT=6EoJ1Ԅ?;*m V~fb--Zg/cCA,7z}0 ķoɢ '1a- [kΊڐφ(̩˹Tv3NY f^)>:n~LuYC )O@1yQE`bo?7TkġQ=*9[|AN4JL p<ԐNZ[77/W7h*gffbn|8sYEƹ ò_’!ː_VCOzw̃v\U Z Pd$B [7҅0ha82釱J;FCT2mCl2pן*Ri?'Xo>u*Nr.[{~v*b0.v%9uCؚCsy1W!V }7Չ7ZԆrԚR(L 5z$ 5MG饿S[4JS9DCߨ}jaQBRd@L(6Du5e<Xpl 񄰕!Ẹ)4)YMiPi&d׈˶w0ƒ+KFJX[he=/1WY)`&sP8LNIrz81L{,yeo sNj%5ۯڮӤ[)>rgm#Ideog0JA =:c0I+0b/ nY3=ȐdvL-0V MQ&$gF3ku@(My t6bsw&?<oq&{U.iR Th #+\Z~TnU9>xORo-wzG-tʹKR0"cJhj 5CdmX7dDxaZjY+q;0d@;<|]Q$x<SDrfY *dk;HD9nQ˽&Ku#o֋.VWKWq>3P@a-D̍] a]k!Z„?]v~N &ظ&g?nn2hqKzB/M0" :,ayd3U-w^y"bac-s9ZKaOvˬlb Yn9 A,3[&gqo[<4 ^~svX=ѷjzպkJ>Necov䄥L"q0UN Hg?&`@P{wv2G&ۄ$`k=~·/u0(k4o7o G{NUN6Jl٠mT6XL_͉6+aO^H}1_a4EV@xm+[dPTA [>--C߳Ns"%Q.rIDO,_gY@yn t#^T/QJaej.&O[~D nhYC&dk-h3O^ݿ˷Eϖۖ<{k sl)k1n{J pg̟@ˆm**Bjl@1$\KD|gH5FemKT84VPG![ɫsμb=z kYh3[] ;qmU~!Y1&fLTW) knBLN^= 'OrlH6 =cK Papr5>zC]|t,W-,bP}#څtMXGPin&/k_SB 1p1SbCl8#kiwi/^;Dn5yvt }!ƪXSx/$*ˀ*1DXg^(kCx''ϝ=fI$q#dʁۻ=/7-TQGbꮈK/ŗt syPTOkUǠZwD3M/*[)AOKEe<QC$*3bt,V4uv3F"ܐQmJW,-pP\(D*?8_&=`Ha#YfB#VPK2;9_*]ғȉ4/j+6G)'*tXTɞf:bAkKt;@YA[]ЂٴAuNBLuE0`2m:)>µH8*\бlL{oM>N`S|zo[T>Ado2jCYsC(ƤTC2 X_:{eVq9TgTReg+/S)|@#`eA}Jni@wytpCXck[Kg_FCh @3qd.x!6(΅IߢxN~j`i=Xj8b(|+}y\aXG~^ru-3£{cR>gg%XO!VLn>Xȳ U* "~J7ujeC6!G߂z>ݭ?D!w$tT1vsUjMWIv#1 dv.hBJEE{ і1Q**Omq1HEjIk;* :vξGF6U 9yطZeGǾ{ @ecF͵MW3KC.)¦~: Uq;&@?%jBNz, R&RI9]컼KPd~fYj9 z~U"ttF6*VL^ZbIȮphr'\@o>t<ږ# )o"gq4IiY @"B1'e HTǷ{XPQgUFjfkд/nИ0_oz T [QllmU7_H] )%Q^:qƏP!Xmە>K iQ:2e^ځ>9;P!w;S”xĢd>AF/S$N7'gt_X,o2Lb+b Gmm5f7"GeA770>jB^G1oEM7 y7_At7y7ism㞧P6—n9* Nu3^Pm51;k0YwOJӖ'PWďYH w7#&em_㌬x40CzFܡ8@0'З2HpަsL q,\JX(ecCiq!tgӍⴔ4.`sRKRv$ө_&3k:px-rà5A1fyo7m7ܯo<*|_jL4) [cJ׆0}DuN˽i}+ke<87,}J 7\u^>/O[cQ[,D܁ˎ)~snWÀĭp UOLxT1ANلPS즧DܡjU7t m𽦶 ")iu/MELĻ'-.z)eh _0 , 3#I.(zR,^=sQOluvp@2hFg}gvW}5` #9č=[tT\0#vVpu704$ WAPf4D,Rҗ2ĜcXcz b=`goЭf1T H x?,MYi(2Zg)jz\&>od9EM1UCvDS! u#υ~ӰA 9^ϰ6TkG^[)Ah wDiq,cUVȔG s#5BK3jVXak of=ݱ;Bqk"-"˿X(3FAsڗ NqJ]ěԜ oIVF? $-3aII]P}8K{>Q)%kq az׮mJ^j%E۰{-J_Y4w xT%mav6,Qɾyv*pD`"49]}d#t>h10DreS9;'mfXFiy}V[ԉkJ~“I"jńhuSzQSS,9ЌW\{lܫց0/x|)\֘KQW\\fx^k.W}~$.mzv ke(:הk2})ol*vWnXwt c'?bR wy-_+Pa{3#P9T8%qWQR;̀[kC\ Gꛑ`$WV.9z{h'g.\ Ȧ2]%,琱Lkڟۆl~<TSc-!\10Dm*$Wӯ-ef!ChE^jTߙq%jaڹIf5$B)=(jD7ߑ~%Lo7a9'$#v| c 0 @<K'8ؓj'Tz<{: ?JO%fn՚O7mᴔF⺰fZ,CMr\{ OƝMʏg=qw8[+cDBѦ}𧽉hdhQyP]wݷ&J_Gm9Uz29oMC1ޙƟ =a }KL8I;wT(a %WKBpgU-t&Hrޣ,9DeŨЖ.q#lD5L:%F fsgEɐ{;4a>f<=R/93ffնN6"wr! TDNl iv {?Y=fɉj F `W2(k32˕ȼH}[eq2ω1+ G_ɈIJSZ6a|Jғsd/EEI` Ydo;J%@pQLsygd x) >o36,jM|wxc` ǖJ۹k.~qK$ "qf~F .pZ=rP3~v> ˏ9P4S:ic!ڽC#a"R2ȉ5cW2<_8]7faA|4ġ@1AmMaeSd2<4.KEo5c˗f.ˑ\DQŌyVcD?rdvE@@mX@P1W>Tp)Wd¢tgcI ;H $rsDfӳu7 C Σ娟]BT#xȃ6݃)$sz y$zg 0-n}ńY=ƽE1\\_ p2RG;c7XoNK;:K[OrPg?H:JFe,lK4kUоX Wz}g[/8m=@J\q(q7X:sɏ_b>A6DW׈ƅhRڍr)cЛ2p+_LqW L WK4S /E$e^z4H \G1#XU>+K +m +>` !)/HS(C$˦t7 hV<~ sZVﬨ0g)=O[5kkΪ,;+ J W[hi\`3m6vhq"9!~]|Z΅%L׆l&]eJ)7Gt8+58jk —o_X+h*:Ŕ7 ʹ wm C[.iq6"+5s|pM"IPj3,!pwpqQ! 2hN&ve J|jj#;׉zW34ƕu̓WLH&Z5L^Cbhf(bl:'Y\tu4B(sIa#g AxR`,HTqo%װ7YZHuގ{8p7b̠Ͼwq/lsxc._9oK\H́E_ SU5jXPRAY5 X u\1:CIa@_ s\-g/}$˸~;黫Q46Me-秏0%-ڭ W$JvY6sL1~D֑}Z6<*: l|9|fՖ~*&ZFjVJ-4e858$8< k YOם3U>=C%cӉ`zxXvK'Y8ńN`f;p #LZ S0O-\~gZ#tJ8kUڸwj:@3(]o !zB{cNe1u&P$: gp:?ID[ub\13s#9Y>VM38e{Brxץ`(p §==@l&u5BU[/|ȑ!ª! JXρ=7X?P:yʇo59ّ[MiDVCuu -ԇz`Jl}m7\^!9\KDlh/o7[E 1]BkWmHf{ UI߹pQ% $)`iA 8=)x-F?` ,\)T-H ~踢ދ}UkӇqkD~ӭ`sۆ*i0 [sL|hnֹ1ohh ,>=xy@H 7Bbk##һwӴ尹wh$7_Z as6{! ('(Gx@Ҹ] LQƺ^߁SxUQc*~Lڎg{vsWʑX[JXe|@*XU|J#C3D X 4ru[/l3V$J j6<΃3J#}!IV RF>߇G P[ZQݬLi0,MixJȒ}fEUxûo&U)gd]=*]5$jjZ e( %#- 7,rc*FF- z7"w^yixi3l>G;^Q{I?HFfÓœFʄw)&zXT>ڠ 5JSAVJHI42hw ? ϋ;Ŀܳ "Zߌr#hx Ag6ŴBu1^(]n_0cś˓ƅʅ4mc%yJ/9߳fk&ll:s;/mj" TGYl|8m\KEQd`\l.,šy7c"ubKUNv:|zO8&Q`d k_@Ωל~NHT6Ww[Mz otvXU 񯔜`TƝ$^YȚ.ɰU/LT1~Nt!7Gº Δ-+J< T9%ݴ1kBi[uYxv>u>?t}ǰ(xR:x@#$P}!!΃ d0And?ڎ_ 1R?ѱ`Ko -gzܲЁUc-ͽ97E|Q6m,itҶ˘54p])li=+ŀu8W EKI3)l,M_}383tI3-&.ջT:_^.Apw1o84N^J%_{7P[d\v.ڇNUW .=vita&Js3141ʃ y%iʢ) >x%^U ZEA' Ej#x)< Əqn-DO"ؙ7rT6"57; ɝ$bΡi~jL jվPA]TU\P[H,`K3n=D[D[~1w8p9K-H<&+ W$I_VϹ|`*4*ŭQ,ScG&'6׃9u>?q3N_:_|wQcJDq˂z%şڑ Ȝ+ {m];ޚ2cFE$%f;|GɮGUa|aqL;eqvL3 C8)+դ:()N8ȽTQ$61Ɏ֢׹t;$02Ь-<cYx?J򌝵qZPE1a,*OdqX `g ǎr.[ӛ3T`dk\)JG( t[@/ϑm1&p@)k.+GIcd%tsYۡFEǦyU dNm]vٯV=ijո֕Yo5gܭQŗ R›:kG6Yw9fbD֊B@ufzYm䴙F:Ui^9: :v|EdFe ]^3yh'Z0.1 ƣO6` =\DGFRm'ÜF냍܏̱zLTo~cഃcYH-TjW^lIVpS\6iP;`hXl?"'tiGn5~ЁLDް Խ2$"M7+~}.%Bܲg3ɀLh."6ž034;<"Whw ;}@AN3_rRh# >%:26͝Wt9&]~lfeqSI]M,$-sЄFx|WQmq h%ьY51QA6.k,[1;I*!b|&~W^[Jҽf8m_g䃌 =#m,e,rk >'|D7ZQ,ORbMiAV281% Js"}jOwVcѱ}Ñ Etܲu[0יk=!ڂM@ߴݜiD\D2yN=A;dXSr*x0L;m".$tb١sƳ] ֌=Nm߭i?t1k/v_1fy%*z~q|4%,W1eZdh&1,\Df k7Laιb_V i~JG{L}s8'rD[U@Ü}N?#\ՌAQ(KjYkU\^UEĩ'~kV^qяX6cKxGVkHub^n?S2fcGmh6IIR'az =;CBax/MHрȷ$A {b9KnbզeDҮbsJqlKZLThNKN]W?mxV>!LA-@O3B%F(*>zF~$'nFIϗ8^C-%E@B1P'wm5\ѰE{蛞 ''Կ8( i:#r 7]7l@j6d'E: .2<,cQ٦փ=^Sd0]PjydJL Ob=aJzݨ?tO}?bPU0#lFLti}#B~ xgܜ瞎ilҦ2{Yaï2TrtR2!~)mPiR=r` cnY3N8O^jPWuvS_ Ǖq"-VM!p͸߃xc>L&v[O^XZԌ(@09fv1 ,sH<Jq>I+;PEm"(zoCr GS:0:Ԯ t#`u5WaW>}|xi#ڣ"h:>$MkbDtloUqc Ha<KikƵ qJ B Y9࣍tٸME>GwDg7;΁k"׵Y"6wF~V)J}p1`壮M ЬD7!G'.5)qpTorݎB F}**: j0-oƉLiF${*bn2hX }ETӬhH­z9!\D$L&W}ڕP ƈ]H{#DLcq;?l3[-Xg8rd=ЕR\}`8In-]=Ć UȐoǵhtԍѕjhXZ7z} ڝgO7k|aEVO֞c3At @ωFXg+խ WGk5ed̝ȸ>9\+?!X\!qAˮP"Jr5fl޼+p>r'R̽x!In(YpŹ~0UFhNmS]׸^9s Q#Vxq B}3U6[r"*Td2t^gLj2'9vLzr<BT`F"i3i~@HN')SEC.Cn9W .mla%bJLɘlG2xj!yޖFyϹk/\!۱H"'oSxPh}X͍Jj~L,\@t{1dXs}9gΓp(4T&߀d9\)(~+/Iu.֭e+5{Ө)`E AA.E-:RHPmQ/*<n{xGbTtUq<=qݦŶ,91t+.u dI܀5s "Pd.C|o"qcUqj!%K6-ՋeW+`V&\ Мv1C/8E\rעF<cqI)gQ,Ji~ ܴi3 7 y^54:x6E.l!gv Klz[2թY Kv/.U ߀{g,P (%.[P5wI@+״Ht?ټ;/YetB~5L r+c?0fרz2 .BLUڢ̮|^6r[h/c6|g'e+K l9g Pl/R05vP\8)3H3sWc0osq:ׁPOkiEElL``gN^I2@%gtFSBg`k]2 (R{e&]ӗ֘gRlj+p%Ŭ qbW~J>=SQl}hqO kg=:%({~b!:rBHZcyw$!DwaXݲMMLkDQtUfiԧcMroXpTT(c˟hx_KJ "lqkƍzS2OgA" ߻ʯK$t؋'۫}EN"yIH=P!k`#ξ:T+,!'1gF~s4pD6~@&˄L]DfCio흏-MO MPy._"cZ $37bohyǣ 88)s`OX8(;.E-zi _ r(}9X\yy܁cj #G&7,ҿ;%1ST|J}`8)9ZeNl%#)#uNlO[4b9dbǩv)K~T=Eբ/rqbügNk9 {D+) J[ݸ"uP+޳?>v -F\]CfŐ#=MO%# =p`Eؠ!P;ݩ,] wAG~vˆj!\=Rf[,*9)n.S ?UqXVWpo3xI *pcP+S&o=1%tUS71^+ `(Y160p߳eYp/Atm(\ΖT_,Jp1zBfUԝ l>c4ʥ%*~;9g Zm3BX0a$G͹p\ s##1)iV;Z94.Bͺ_K#h2-oY ()H7/>BԾ{_!<Ϟ1۝Qw1NhVM07j1%tV ;6s^q"9.dMJ>MiT|-bDoE9`'*D츕x(kBj+.}XEjv3'πD&SF6ĝzzJ`i჻ԋWZ^aH`\=H~ηѯCqYOة΢XJ\  F@nk䭸!uU<%i'`z0h epѧ˒^N"a P~|v)TTх1ؠRYòC=Z+\ iմF\֯3u)(Yg*+ڼ2~ĉ`g6WM[cOc*ש4c湞5Y纳EDGݲ_к3&H+7)5 K[i3Wĝ}\BQdkTkDoMr}"4|% YZ,KP2,%`mip6Ie /:M(7tNx)Kj`PS꘵L=(-sۊcYJ*ig_4{A@z3͵[.gIyI0x$;G&j QH|s;9/JP%1iH,<ǜ*&e9{#j0ݹ CLzL#TJ0rِ t-m)El\J>p{ב&1pPٖAH2|BLJ !L*y>yk(.})܄?v2zYc! C`щb[Q u4Eӓ)yZҙC2:NS؟zxI}?)ҵ H&.n39PkA,$<&o#|k z=_ϤHd-̕|d.[O*MVuh<=7Wt:BTk0 bLi涎ˬvYF{z`y蠧oiPuznNvP:KWMgokWArŒB#J(W&F5v4^vY&25v]%J Y\}8SqBVjO K4E {i儐*]f\siRfG#}"jVaN&δB2BF)|gAj'ꝅq1uR!4 s[F9'̰}b}F)˭Z8 mh(K*10,"F\Rl4} q߰::5ж//MַՑ+VyS^2],Zrŕz2G C^6i*N9zԇ@O(!Vrn^ӻ49~1&I=mXLvN.HP|ڳl{ʧoLE2ŭ.z8LKEfYW8op`zU'}?W]9qJ vn\ tѽ\E2`a&H. ͸Zr]tifrȨWV櫙@:\+ZBwy0nNl4/xFVLDXqN-Xo%3=h׿L`=RQl++Q @!@"ZqoQN"H?憽-8$`!i e5܏V 8_;Tۡt;&5U& WP Vr?h_Tv(UYP>ud0v_ic6veFgG`䢲'd*8)(եSi-܌V?JA؏k  RJʀHpys?Rü̝[AO¥!،_V$KXjiA쉩]0pwR@|н>%ٿ93F7 v 쯩fqʀ,{J#/&͡ȧc*/n򷣑s80gO[5K,&y;U;delt7]~]$6wEy~$VXskp'jC>uptlv޿r"gJm} 460) :{m6Q\eY/X`֞?G E)-(b\$;WVݯ 4gH1^ EJEV%8jYM~1Hk7yQpj#(y!tR&W+oxf~EBT%t xQL. ep_?3`բ%r E"DjC;5<9F%h!nΖ;LkJ ht dtЩ'C (C\sұz?X`7▂;rM*@{%LA)I)͆vxC(u+iW?;L_dm)>/=ָ[ƚwwA.V1u$P&4UZ61rJ`['ȁ3 S"4zHZB!)Yi <șKT m 6#aYt3$IrsSЊg_ܘ\uKq^4YE"녎3|&RGpVYUV#P&VCz1"Dt6RIih3oGLIMBg;~(Eѩ$69HV'3#?ZNQUQ+\/b }LT:ֲb:sYZb {U˕Q,* /~ϋx:GqB@! 2aSPY}cdjdu_k`YW김s*>g<6ZXGoB:[nT{@/Yu7iKjkOMŔčׇc:I C$m{ė45 =)FHQ='kawխSP$&ֵ!-@)O/G.@dYs6GWerMfcpZ~D`2LG>C%~reԯ I`G3,:âiӭm&=!34iB}7Wf07"E+L(Ys?6 /fUSRI r~&5%ĿD޸QO`-i2ƭְ9E;w 7K{oe3ÿKH/A7{rCZDztuк2UGoA`\N ICn'|~NjVZ:[sh[]`Xs}G&k/reS)9:@O -y9XW ̰ӗmtKCg5^Y$#ztF[٭]0+cajSf<"{5pe//̅Sz<t޽?ITd.] "j@[{Dƪ*v A{F CIou<ږ t Asހ46.c'İu_GQ ~>Yrya{gR;MC|1#֝l8XrKP)$:1[a$ԠZ40> (ᨏRUoyaCopr׶Y^.jc3d̀u eZ*! IRz|Op&hЄ-,_c G>@.z+\=a1UX= #\Ykjd~傯wS mш }$Tuۊ+xฮIs|aOF׋-3jT'p<.%r5Fc)S/7 "bx+j7G?q+5}Qu3 ~\ñ(%pi;F5z;Foل2Ԗ>+[!_A<&.E /d2G,>feJ4ec$zWc:h$|| tyQl甮~>Ό>WiDRn58_P-%;5lK$->ab*+B, qnFRV-S+D˩gYAST)bSQR+b 20RYӴ4N9-2x30VVA6"nGR(Z4 ҭDۇb-EF1 :#N316gX 8BI'HE_4eT *1{f 2U^ɾg^þp-& 5|GvUMm",@uHV 0G5K,Yi?N`Zł8]: Y|,v9{{^dª=.s܁1Niٶ &/S L-;q"ND@񸼿ĥ `1SvZdé7%Z1ݦ/!K&atJk#,:K-5#'f YÎB/!)xP`#.)]kJ/5AC%vQi1&kt Z<E1oN[q`ؔQ7A, 8EIRIj*xV[ &W_1 p®]=&/-$l0cɍ \2a"0 &:r cN5tyq88N5+[_0Mw"ii~r]\G//1֐@g8şޅ?oۋ?|WF{a\:{쥨ԕ-PlP?Bt\o<@pTXN"ڵaF\>49鈺RoTS~df)Gf)0d/[ c1X)9f0Y xZܦؘl&W#< 19'iE/hVtfE"˲JZ?1Ny.e9ɚR'ɆlAƠϐ YTc9{Pݩ/Oa]YuLmGҌ`1ևp9яoB;D6ZԄLLY/O'3I)5H-R ?tl:@l24DڌA[#`+bԜIiEN~v/fz5(iݴ_\w dI|∫H-_[ӧР(jyzF*==OBoZfIpߙe,KPyb:(Lvisj/+i4Y}> \jfwλ9Y.zĀ1Fzh]h[жs֓W@% 3k%{;mM~+V{6x+ 6ia WDy wWT[gD ߐd\[Ѩ` &u b{Sq [֢GjhtFaeA3M.\xq%{{ kh<9 ׅDzE$*~7Bx:Q#].=k:dUnc:'ge}v`vu^lu< kS+ю@%PJ6Ɨ{ێNa@.&wZU+frݿ(LES.=Ao3!ijX9w.|TFol ^ L@|mC!$ l %h%\?Rm9#h92F&l'xgiŎ/.BPQwc )V)%2ёYB:ͷ6QI;vojnӉ{RV+j '@: ao~҄iʽ5<0Մ` %I05S;}H%N_OQQp0&^b/KTSܜ$يτ| "}k@?@pʁ'Q?tu-٥ҏ(ŏ^!wڙMw1ܸot(cl*‡&bX~Qx ںk`:v}zU9q w<-L{iunFƖg t.;.)~ROU_րxBU+OZE5TOuxl߿jX }'(HShO"A-'A䒯8@ɸVkTLi.FSV/ݵ nҗ%$BL0}QfFzX,HC>m|"'dж@T̞M%|a NRRqv~8Q41[op!9pX_'iYe ,0 7l҆M1~c~l"1RK' {Khw6Yh,/PZ 䂳`%F2md$3hqDf*dF&fRGfC,:QXI_ O߂Ig :('|=:0X$WPF>˧F$`X;7|Ͻ߈EgIZI -%q  Hf)_@XW1JI!h=Vڬ~f44 ٖzPsSƘc}3r1X6l` uA]&RV0k_x$!<3DϨ[aMҌ = lĀGMoM)\%*>#*zu1]e>QHqsoۯm/_i 0"4EWeȯMUߜ}Kx_ z0r^Q$2d"f\x A-H7 aLT@vQ&An&`Ww\a^ B]Dz|UU2*ϋ(6cqwS9=0 sgb*?jY5& \`9dJ@ЛVxC0hMH2 P?d'fo`#8ID$f=﵌c_||ԧ`˫<%ޝ@udf.&Ǧ'Y\yGo_ -@wX0R}|ock&$n&MN5- 2+I!ȇm.DM[QI9u%쩽3U b!WTa?q<)6[z1 >;fAWK&_B%%ĜdD (qvH{&s}7NV'5H%3rՖ"7}PrOZV;=j7ЏuM!aA !hֲ zKMc<=HKفXZtZ3.9 # W z7mAG<tc|cgR]M@t꒙+%i0T-% ۨ|—+|0cff)G=h?U_M \$ba*뜍Z8/YWc̭ '4@Kw]!ؽ_ujOn9ydq7xqh[U$5~F}rvhڅ8)G{ BClo/&>pp)7yp5S 3 x`7yNP's7vMTmѻ\BL,Bxs b(<0Q9:X},#7es\xzOfE~}m[~VfR= m8(lJK7*ؿ:T8Ӵ4 'aspykX5[3q/0V5j6paͿ4) eĠ|H5m(~eɮ :"Wj~SPƏțm]hh$O?hs[.jF| zot ..&'؀Ī8J-,/i]C}*uT2(8)X: ZZ/U1eJ Q:"{Rفx@i&좖̾fp[KGj5:I3+Ǟů"رV(Y`"s+4\Ŧ HDl'SºW 5 ڣ/rQg!ݯ’.&~ ?rkn½AYw1VEncѾ,!ܶFVm!fNsdq<2 IrU9o{-v:ų[硫Ptk=mQI7lgliM 56?'N >=D@Z|k!c& < T t7ţ[m؁oV҃1+zg2%ATZUR*$#LgxzLfʗ?7.`<5ny")-' " ^jE:qײ3SS|:M5ia7aKN=P4BV 9%s(N+ >t[ .*t|CϋCZTN!PϮz]C E4寯nx }*Ue}L t|1D=" S|s^+YBsRm#K "=l#+NY[lzuV]f{>dmaL{nKf n;@@ J:HntUdR--AoD N|⣽<\%GRsF۽{yM-"!{-ZE'LG[TWcTd!Eݩ 'TBu~a P0މ4>VΤb!^39P\3LO2|@7!c.Wr_ZGZG^^B_K]o[h [U^-<4-ј*Ntȯc͵ LGfwפTt𪷍i:[Oh:wOàqK{- =3 zp̽YrOr=BˇW[GtKl/c 6]YuJZY 4`tؼ^r8 &lҎ,ΐmC3+*?wG$/{̗j,1 |כ NduZt95U`s~_ckEsBzs_ Ŕ䈷uՓaMR2#uRf1nX]ckϳ%}؜k~,~'r+=B>{gmB#PhIxZ.i|} #;oOn쇉Q (,nhJx|S%MF,ڵJZ9G@*bN?ʴ_}?H!fJr _nhJR[]Z*0J{w6Nӥp^h-(ՋO HI0mݙ`FE/);+ܜdț~Kȑ~B)amoQHʢt7tT*qP|ahx _G+$|;ѫ~uX}-fl2|p#{5-@/qL*aB͠~&HÙJi N,mx +GpKU5g"L,^Ud*!VTGYoiǦZD/M/ ~ffA{M=/ 2zbu;@X*S7McSO ||&}c2 v d@旑79`ʘ}Ɵ2ZLsd.RǐRGvv&ئQɴTq*WLj"ҥ{"W*O_[}'QzJaO%Q6'ҕ y lg=8vj4$2$Lϓ3 % .*U-Qq!:c|[%| ùA?s@S)q@>M`V㖔Hx?uMVCT0vM3OB{]}»24Rj/ŗw .r>5t٤@% f@F o'I.N`&H6IYpw"m!LR >GGU Z̞ly88R;"e{EQ#ЉE~|K,cIWA;C=-Ԑ9m]iia6v!OXzsQTt<eSjN·9bP()\fy"_Ⱥ-K_tWe37Du<8oַ…fbE P11(ĉO5NYU*/YdQ`+=o*}w\R 9O26 p1}uks#mE A!WŽc9ӱ&qm;" GFۛHHBfG#u.Aj~o]o3)fng7k6T#l{$d,#s{IMLT =![8I{O$px 8$i־üVS2-36`u*B33HQAwYgD6ȉ5UrS6Gyr1T~֡=j0@NJ+ۘHRX9Ϩ?Rur~c%%-=gLa(xҫּ s~68ԃu |Q?; K# %% ^߈-]괏FWKL€*<8K|uSIĈСf `@)$ x\{+Cq+5iɈ(*"bԌT_DECJvvym1O H:>ۑNJJgp/Dv197DJ]tWU2D66اH{BĀ϶E{ ľr.4da/(J6GÝƗߘH]mDc8iaۥˠ}~)3chpOɟ@!H=*k6x;W2`CiFfj'=ݎtXfoB9RrhAd^p̜UQ?YJrj:aws/]xr[܅FQ|z!xcJm@k($bг|⮘Xϩz lKK6qyr9LE L̤Ι;C}o8jqB>@r A~!7>/\kܿdo`@Y3I|W }9~=#z~n+tvffM[=0Rv,p#_3¸6M69=M4=LTQIG˂]$|8uzhOϱ'%EH%&S.Sx9'ፈ=c{ 8{h1Sztx,Mk0C9}cN`2#{Ry i׆$o؋'^:ż^q7R0 z UY28p 1z 5{o4`Yf$Prx_F?Xn3a,;\`DzBO8dG@jW[%}\e Lʪx͇5DZ~W{<3(+=d!ݹ5[2w޶(ƫ#LNop@}χ\xzehJPG"|k|䗯ձeEX?lۊIܫSYJGPiX(VQ3+d&G'TLu#=/Q~Z86PVt{,ό5t C,8Xa>K9p{EL ND@pSS!𘴥NzDhQ(݇׃ wo3^6ݥ/s17M2ҿmJK(ߡ8ncׯVN|9j?l꾫f$SaG}\!ao\G#o.6'1j6߅n  f :ʁC7Yn'澀9~ScU0`md ^Rvnx۹ҠG,X7Tua߄5UXztMl$b p9A7DW?њ#AȽBڼp*Jk&D1`[H*{}!n1{f $z, d(IT)mTA7<2tDV1\'HiI ;ZuaVb311c`'fCvB[fiJ)ˉ=4-9$5L<@k)bFcŎk')'i~Kd`ƉFB 궔.ՒVr& p(^uM0Oimzq$w "gd%<Qtbr[i.T=䴼a"ܑv206tƚ0O4}RR=b1 pMy\@AC!x:ӫ jLXMy)Zuϊ E&׾~VwW {5&b?O( (j0y4WA[c<[1J_޹-9SJxlOcy)q,SHlҖ~USNP!bk)&{~JejRWjL{Cj WQĒnۑJ$_(e ҿR3yW`VWt^uAK벪4vzD^ XXhGS\Ίȗ(i h'} z$950{SQU|hseY !_ BrHS7F`{T%I|-.HXL@E'E ۥeڿ9@}N'=< Y {T@yi\C1a.F f 5-VRW#=FS+cҐVOhJP`k7(=R͎G&n ;!n 76~Eg,{F EVZ XBl_y|[#E1K%WgVԵn6}ϭQ % TMbE:<` c?iŮ kqÅpHoϓFipAݧ#SB88mu-;=IMdc@G*bQ} )&^LLEqjB1#ȘݷM 4UojP5p]8=@+ xϰ9kתߍVȈUeD Ժ6_dN9l5Eo@=4ej[kKwBKdZ] WUa0jM{}^ݠ5l~&e0^ydIӷ֝dCGc6D@jM6VBBbڷšŀ}# /mHE\Z< #jP"]6*!șPM˃ Źn]rǩ/>r;9;) m0 ,ƅ/!OgX(? D@VCb$jhXGj9\鷺׍Q0%AgW2/`68>tkᥜGh#}L:s/|ҼHG(BSUB\ӊ0N1=Mw^^_DI4>Iؒ*&{%4wƞCp G-sDc][%W\9aJEdp8J }[49_]?EZ]CͦyL9Ǧ7䶐bjD* 7%ׁ[<~!,?C##qlB/oy.zI-ØU{=+"}] Н!˾_uw3% pxb q &؇_=嬬/Ԃ&dZr9 EU17P\@ Wp()WW <>c٢B{cI{Tk/VG2_}}w?/ ht[Q8% ק$8disOw@SDtIhd2,;{S_hJ& S K WO4B|(h][aP+g1Hp'0J"wtRxPgp&ZP IXvYC929zْ`)GJ֛!/E֠6t}zpVȌ/:6ϽAtvE~fPLj.BӼwk0f[Z} E5h R ,¼O0T 2iڶf&RRVQpzhVW0%ק0B'k:u[m~sE֯S7>?7H1>?DMjpOƘCff)D"'K7l!wOXf"w/?6_ȉޣhńˤVKҰZEC27)7X^T`6%Q iCEe|u?ӵ>VYb2/ *̑I堢c 4b[|Cn^=,ԄN] h:ނ~sbk%Im 6y1WP ݛ* S!Ӆ̇bo tT@.ۃ$cC'1l{[&GL)t@$\ Y|IkYG=І'>b 3Yx , +{SzTS]?pr6DZ:u/#bRc?G[&leXHMuAC21M˲n>ɫjZͮG  VaPz3;1ʪyUƀ HNSMe~F7 61SYH 42DmZMzIQ$]'1dY.g2!J)MM}> \tAEX(ztAVS9:p2vb,B=MMCrQ>ÑuO߻ģVU`0D t=5F3^a'^B"ҁ#z}^54VPpK>5rK:h۲--F?y&M=2z@hC޽08ҚLKaDURN8z|5: eޚ8lq!Bݓ lU۟jp႓i-_s/g!>wNx)ObVаؽp1 |KE@*|B+Mpacο0[?A1n|?V̺+ 'n~&A=\LG0q#>ڬ:1$)*EQWi%TlAf|vPu(LwKY]\ C鑇ˤ IlYl-tAK_ aYkT'R2Ik*,FTn498hz\k;N۬]R3L:hX構;p@9cQfhb#Lo{R}=k܀FU)(h6|In1*g\m{SQ7w% 1<{6!3(H9}H2}7 mMjݢ ;:b9O5y%%88=#SY&fɝwW\otS#Tx-:h=c]CnB=]qͰ<()HCm&8.9N陧q }Cd/ ň\i #HF.:PJ5TF4rֺY4I6$ DRfܖj{#\$Ȅ0RE_m:!k##V bҼsˍv7z:0TPmI2iWbA %*B᯹pf [E*Z?5~h'i(ꢟcg`%CXᴺ ~t>uJ4 e/fF.ީp8cF7' WvB?l$DۮņZ׭wii}$'&Mډ&FJr@PeSuQjmuP8 /s,ܫ,g;\U @v7ڕT13}гqU 8h^t~0[J,͂(TRsa|r9:7[dUQU´{h6(m޴Z7Է̅ј} ;iy&لs .M9w[Nh~5R! 2xX[1F!5FnmQ׋w0K34fc8䆬%R0kejUl;\^>7J )1.`3٢_Y x'hIPsV=M&9׷^M`ߪC/BZd)XP_ pܪn+=ޝ@r[tIvbJA yqZ[L,T8‘:V, x+Wo/dΆL+ҍhg}C…*mb2ojn7g]YR_cc%4F:De׺MQOYT])0٠NXVc#aF19!."T*ޡ(޿j 7GWpk܆?{f Pk鶔z66gX3/TfE׆(anjﲀV,_jqꚼ\IwϼHw̒dRޢcCeqaA厛<6ry6V} C"k4Lw۹scInqj%0Oa3ij7#vgr W 2W6k0#OUuuesrh7%7 >_.'bڇu7a?y4~c g]cC:brrӆ+S1zz-,"sj.sɶ(Oܘ8C/FxKXqj{Xٍn@&b!8;ӏH-gszs8 >OLG r92[]Cq;"m9" @ǿW5s "jry#yyq@@N[E~MBL9##Eh͐뻴rHggAh׍AP͹64/PL &|-RX˟Qx խeZZȈn"ajJ i/C4s H@uXE/ȵg4"Cu"R#I>RVQ}s!q ]l>bk왷i=&FQ>(\>U>Ϟ v[{ot;RGga9A*m^d&6|T3S#'g/_.cZtDIu4qgz.? Pw|(ָCTPPy]v_aYxr[6J̌L5 P}_/upDw݉\Lr%Ώ]õē/Dfc*z >;}ɷR:.؅w؏0:qm0o y2">9OHX ~?*,HÉB'PK-uU͛JN Fh AqՋc7=1n戣3:bh NSyo_Q 'o+K*'8wz /GZ* ޏq%%{oǘS(k氚iCM0Es`Ϥ}7g⤁$y$ >bK-VQNB=;jKϳ͍lv?1<J% 1זͪB`^{$D\I!/&um.Raͯ*DzΝ Ѝz0uC_ SX"D n+H Lɭxbh| j|t;E*0|Cj\ʉn )fav[#~<;$Ƿ+aU+䯸 )S;E+Hז (1Ò9팀UH!Ś_Gnjʑ&p!nQ~r5@h|ΰwoPwgd/vTXJj\^xAt)0\\eF 5ci={2 j| ѣ]{:c~0BD# |E0FV|$fCdF=C'& if"S37U  `W}R+/Hݝ^ ۣ5TB1>cC613Ȕ j2ӚSGڳ5քv~>Ak($Z}  ՅNdaYTkЂd^KT<,+YN ."8پ-3*w9vsr,gլF%0*d:ԺcA l8fu3HHV㾣|[,.qM?7 1`Iiodn:㒮OlsN'é>q1bƔֲ=[%Ԓ>!Ø|Li|PW.-I\+-c{B0(>/uO.;w!cL ʙWp\vKcΖ[/ \T3eՊm})#U‹Hso|tZJfլ6^]E4*=5 G*7?׭ר14MFRĩrƠ""Q?CPQ/:U.0tA KwcTɪ91Y$ەVst*;.$lBDDd^]Oiۍ4cKœ$KYh)tDu8~gWL Ŕo`7prdC oaGӜUd *#kW5 DQj?B' yRMR-'kMW/2->nVeށs pE ~qvu8[;p-o \4;<nzak]=3rc oh-0H@&9= [p`KoigIac90:.įХL.:֩UΥ=jf+шWNCt=:.K00-hbu]@Q/u{?s H,>[2]kc&c>cԌ}7׿ݭU$%2wWLcXv2O0xUH$\BWULk[q{3ȿU5<!*(Mf}^Rxf;gzʥPUnrf4r%'W.V_bAI+[T)!t /(HB / O*0t`uρR7ۻqB_ NN:J!i!L޴WZ4Q=tqHK{UX0ҩr롳Uj'F %`G&c PDŽ=%>x&~?őd8ַ .Vg!,QBB 箇``lgl`=:D{1)={xU9nzOnCSA'D8-̔=M8[_-^0^oj["Ui 7@+(L|!h@覑'-MK5vŠ Mhk͘>.ՐvJ`?ǮDh =Й_'R ;\2+L<52jq"JEǫ%[;RNLC~y hAmmޟ$؇C+_(%>~Ccڗs'ݍ6r#%HzVnMe(B#aO ٜ"xiV BpVzked`=R^#@Tٲג0ĿΗen+[ɖFn\"Α޽8,s#AМNkXnv'ժ7g7~< Pl1_g!ϝc\R$3 2bPqIM$Zl./~;Dyz>GކȏD >Nfw|-84]y"Gk6$82/oP#uU?LJ>JGή=M㦦2xM=7 9:weMu#Iizf˷Cb\-(` W8݈SUY$IW#ʙ{E^U ~-ir=pMOU.iE& Q3rȘ J^fVǿ'YN^q2K%J=e1wӿ*+ǀ | FF&KVTЁ:}?*& ڛL!3MxYm} "*j u#-c'SZԌgc/[{GlbΊ"+ոWUp9l@ )ޟ=;%?֮PzZDHTf(fCR^:p&TWkP:sXIw'2hx;l:*Sƺ:eB?f[Vk`ݲ/@t07x4?/|녽~̧`-{\Հ)|sβC.`t mkYzĴ|ХFBqLլȨ1;փb&`I,yEՆ9͌jspseA'[Qu)Y9q+qi^=gزpmZ)O)xq6t&k> sSZ~HZma,){CfWp:DXdY_TcF_6.LnQf7gk d׳Ӌ|a",`fpI{qiٚ^M7[!A.Z",7?j}#yV{vEN;-pKĺ0 E8D-v߶bS{39".LS4(U!=4w^yl+ ǟa37-+*fY+׫/Ȕմ]4l乡nޜW.#U;S @{2why^wwC>5CE\ `i` z )\t3XݪleLz'|CNtʈY׹(eizw{Dt/UZ \Jy %C58<+qW$BC:FbW`1:j:Y 9P.-Y0Y Bl]Y"6:^"s]xt )s|<A'dږKt2u笾J\DWbSS#9A`WvIK|Zkj,y\Ue0:`tefI+y ag . fusReXY);$dDq2w ܺe'bRn^i $(R#(Eͭc@kKdvͭ&4tFIqf1_ydk|8XErBTXT7q f.yGZ[O_h6Y.lefĪ"aþi"yfS}n뷄56㗁=C%'^DP vJIt.rgC)>Yh\Xo)VlDg[ݩnrR1ÍnȰ&nfeX!L:dJ+Q;<_G&hXk"@.,3典F8)+^WfҠxBT׺:9]' *IT핱:m' Q-(X-w[LaV0sA+v= N7u e,MZABQƲ5JM.M烔Zu]srn ښRީ׈l|ɣ&$LE DggV}Pr]SDU . =;J%Q!sdᒊ J~t)檊Zt#O]1/Rp/,JzӺve$c[eWU>*R-0ԽNJ;u|BOp# CSrtE7N>לcjoPLmqzvuĄLexp5R ExKzmdi Ϭ, )jX|Ї@hsyB<'`ILڹJ,\$KcaN8&kЌ*G x9@RM9 -c0~-d"1k]V+"7_OIv`oQ`c4n, bvYw"#M>OE a!FP0,T^`yH2ҲDir5ίo{'8~5wn#jD%RJX9$S$=k-wVNuh4:ݸ>\Yx>?!ƎXr]"+ƒkU:&,4coR5@뇺˛E9+@?5d5~3IrC`O2DQ=Hm*FwY!'r;*F5EeVda /lhzelp.]Z~'j7M꟝÷6Q\wn;\@h&uBbi0$e´{rѹAL:[J4TAuw/#YME/uA~2]xBY*'hqr5%C5nEwyXO mӏx+/wgu6ccDECC!nw43sI8[վAAVkqQJ,XiL'ڪoH-0 Qvgw"K:@oNӔq+C_FBrU GIqIۋf(pwIOEU,2ӗYv˺HDS?(BWj1˜a*G_=_bĄ6Tݞ[ ;ld?ArVFG9wj4H:Sm*ΣSTR?яfZ43eu`D:¬MSҵ:cWZ姃^ᴌG[n}b.yS0}nۚ>V9 MY,}*+ =$L1}`TV軆%݃I%>0:m$[Ԟ{ zM;i3Ri}/e4vp"%\с[HXɼ.usC8Z@M9S~h; +BuīgsfUe*眾]5)I\1xP Oojy<bV \q,,g-߷yuft{͹X;AV͛ݓ{1l^`VcNOSMyH"*|IJ8>{kgޝBމ&kʛ-cC1% ;z3y+ؤ{[~fg+5!@$:;Lw[M&l0kوg"kR xА˞AծFWȳIZ˲|"^Pr:"!uDOwвT`JF6<@-X;O"|a(GVIg:c$6pZ}~qFQ?޹@; <)Tz>V`[$rA5@]6t8q}Q\/&؆޳}bbqN}'Dq4m]<omJdcZN,*zrB'z ro{UUgB_*\5e @;fⷍhڒ޹6>f8Rdr ,ܐgV價b8!BcY&bY@Qp-b#hyd(܊wXj aޢjł :\d'ӈujt0iVY6~AzYxҔCj36g>Heԑ?hN䩤>*?kJڡl$k~TAA !,JAvUfK= y o\oC\ e">7L^v6s&Zdj' !FE. i }RcYjvbى n%v~e,Rb)Hh G~jN%T(M|+r8o.t7s5I3MhBQ*(aHkb‘.U 5YƺqW҉Ziw=o2/I<{4ثw)m MXэF*!|]Tx KCPY51*8o_MԁPO|ۯ?kqqDbpQ Uօ !DN U+d:&{EF F7{]}sy(N;w KJ27Q Avd1 NJHf#I4v`D6ez]9s/\n4):PG"iR}݇ؔu^r,T 3)ej :j,09KgJ"&7J'x}|ohs_bC[FsZJ&mOYQ+@kRTĂvQypky<bb/֒cXA)$GG2yԬ+SCȜ ~dJwɽ?䡥٫>h7($SUx=X"2^4mEQT|2[lb2N;"CX!ѡ9nBI }$A#iM9=JgF`֦ /?PmaPdEҍOp? ,0&MY,:IGu~:[X-UtǸAP?<Xec2I%f8Uk$6#\Rت@nF<@#^孍C{!BJѽ7lmpTݲ@tGvlOK=)mnxY=)\QQnj\/GjXƗ\*y G_j":?[t}Cߕ5UgꃲS^GrΛ=- v݆? CDo*IQQP.r,j@8D՞:B9ԦmYsFV|򓣘 dyC‚XgTK󝐥ؑ8Bg~Ѣf$On&lZp~_$ *lWL%s FX(H80Gc>VE@o7ΐR Ta(\ Wk ; M™ ]ZICzd@,fSCvįĿt#Vj$1?`{r{+75KzA`yEf"tgv"ss9wd+y*s/q%Ej@,d;SXR8{]yC? T RLK[SM:Ʃ-`v, gwu鷺SM]Wxm!#r&9,]d;8^xjBz{Me}zb ^VFӎ' 2[&|4{,X7:qWK4Q+$3Z^GPlr"t79`mR[굳Dwo,xi*h4gV.k'k%:NOZ*#>G]x\ۃü5Tt=pt1>~Үҗ[.`1 -?'E]2L3ZݣPDv +?͎ғΝH6#QNԃjTސzk/m@ŗV >:_WJ^~2)!1FܺC+z('LV .4˭ q|qgXIIX-2/]q=pEa`}ĀFͭ:DSAe6AUC(a5Dq&vln>Ndݨ_6$ǐU~Vq뛛8J6([Ei"roUk x;@b`χո>_rYlF[)F1߁q~w(t2+CVZѵ\qWڕp۪Ne1X<=:Il}&.x -\vyb݊0i$w!,qyD-+Osb1^f^A í BDng\ڟNa)IGb> W \` 5sKӧX@]-=Vfx.͜&rVf2i__4mV7{H _@(x[N(sJt.>k[dUrLF(^A5I2MW'SyѓK,`;[}EW $btPrӖIjRIک&b$kyl6^hn*zNG_qm(qnӭ|ƣNFOr;X{i-F[AtBNzzbvs'ngTl.k l @uKŊr~0,OˏG,}j2es~ʎq»C643.w;elIJh˙ (}TZTk 0B}ޮ a *ǮM{ň &eH򰏹txY_0;!V0!@'i_<- A{}|ߢ+I=ãbao0)nɠz&,@Q-CK6C[*ja _U'EBRHv}ӟr`n3I:6r/̦Cц;t&ɈnY$IHS5nۺ{|*|7!O< H2lJ'O0D]B~8ROߺ  p6hſȔ@oM^PDk+߅X JY MBIc㢛oE opASey+hV p|&VЊnؒ S7uf6wȆ)'YuIěm e )t~cQWƭ\6;Dxwef>x9cBiCFZg9t-wxFCvLFbB9nC6Mۅ[ޘSM9@ʊHۥҪ`]uVUϣv*Q:5"7;eOk`. ~}MS_68EN<_-ĉZ#ƍ]80nlډMB䆁ϤUuG8N%WSQ&16fUT"["z>Sj})@'}`Iynk*3t5K0OXeHxhk <>xr^ AP OdP㽘d;Yh8[7a?yW3IPҨ}H3({ ~ ԔdZqp"Pg:+QFf0F>| 9RM;} =|swxXBFQ,n^3WP%/"n0Mڙ 2 (Oh8;TonENNWw'e R8O `x(m.L~ֽz57 lHmyPyl,5'Kޫm;:HZ[bM$~3S0FM RB,R~^'ö]K-?'9>LdDw56 zb:%tɌ8kd^8 / XixFB?Q46hڜ=e/Vk\K4. "&{^,BeЭ?߻5 s_ŧrK1_0qdKD-aДR\ 6'/4xW_[u67X7I-LmͧH+=ʁ5favl=-26jYǖ_vj篖X*:d %&cgTz/z3юk 4A0`CX5#  y F )3XW(厬3 :E.Sc{(&l)?^>UiQ ⌕Nc_3f~{lOdD2]9^F~ؽ֐(cT932,$Fadz )0 &YvS>f(õ;H9)cZJimx%y\i.|%l)嗮=VA+Njq E2U^y*d,zC$@S(2oe隱0!| ?Ib=&SZ˴5IrJoRYK:/L',m(d0 m|zW/ @| WFyJEh}LE~hODmLA(TR9UQOyYZ_u2 ^N|O(P9fXzy_-f҉(CWEU-W?A8$ ?!ž2ڄ XJ\ЃS)jOIBA$ZS䃁[37ȥ*ݼ&*Z~,Z)cE4ɗ Ԋ&\n33WQ7C mq7"S܈*2345y<{D&|P9^ t]O 3]ZҔż! 7NR-q ЯTSn0gyM x۟bP+ ')Uf7r ]P,8}-D{g]f4:<)p<:B͝#v(, qkzw%Jnv&d+RF.{-$,ԙGV'}EA~Ңڛ[+f!|-h}Ob8:NĿw +uIȃU܌rCs`}KF΀~YnTHGz|$D-[#rhi3f_uqL<h Vֹ\9GR˦Ozk=.`y?.yE<$r5 E/ҫhAhŎI9qFtGRΡT|MwzG u; sBoKYP"KEkuVQ6naa6/p%W/LULå5~儼ώqhy?/Ɇ~k>`:!:P"s)@LϒEK>AvEqOZOa Kg ąR'okC%=1D{5"M?Uz YD^-/"b)(p5 B5v+nE 'P.}kL@dK Xv 1I_12I-UvMl_])x?-l hj@Jl<2ϠzzO:LVퟲ Y |Vj[HvvctP_KGsrMPgK$b/L>%J%޿sΠ{HF% &!8w[:|(#V*V~Z 5DJBDN Ɍ][훺N>{CZ ueJI8\`[c $r}:Aȥzt.V4:^̛\܇VC<@2)#٢ =@.v4~{6Ig׸O/F1hhfrF+*V}2{U:}ݗm a(Aij{JCx"iqavۉ573 { (RS)Jc.Ƀ!N{i)oJŨn_̪fVj`M0@Á$:xGVSN +&#iJuè(ZhQWgЌM}}ج@-sZ1Z꫿cCv̎Qj.DAi½<7Ða?nHQGgY.kFQϖ5Vր]ud%bNj1@&0ӟk>ŎlwfQ# 1Hi +K2%Rܒ(A |pHcni,!Q!?  nO Y8seCUm䘆Q` &&7&!&@NރK-$7kՖi [1DI^ mlk AJ:=4IKNGz!=Kk^ OqQ)V Eك$\)tHu`2y;-eeܗ/Y+/Mk˦}d0m/n:ɴ| ș^\=D^B6V5i=&?|7{oE4$ޗ"9_{ʷxm^0rH\HOzPD}5FGv$.) H(L,TQ hXXnpAcb.w|3ӆ\n$F՝0sy7MQ!H͋jEvMy3DpGXZו?ڒUx`>6i!1JyHŸ 8=%ck:n؜Œޡsc, "y rȧH-ktd\N}w<0N*4ИNق,'bB+A~3]XD%BRy>H(3óR%W0(~8K*3:YI`*UG([d,Xo ^QGNF~86cd5y#v7sq q{>ACYJ;-l/ B,franX*̃B?S|@eCcI茪u/=Zs&`^PmIVS6Ap0ԧ!ir$oxzZ0v롏*zl^l*%.W;v?[QEj`QJjtϿNk^'{t?9q@JҰQm>3c7iD݈'aIK#bmsŸYf;U,]ڎ9*4ŝt/ T'w6](kgJ.AWDNzf{һOY06{b[X{odђו+J_18XѨ-qRq]ky xslIs7mtaݨ/+>;0FqhGR}(nߑu:L%i}׮+5SA~4ļQ+,2\TcgPrM\矐bNU;מY@s,bkC>jpB%즓"%3R$bvĉG\m>ceҬs;lWȹhBw=2M_Y0lQN&E`oMVK2$'}pђ$ldsnt^MhFmV`Dbv(*M/_] # iYБk,9I?JGAfjO@z4V .ƹ !ƋxE^ ^̀9eXvluXסq E) THTJ $󪮫Wˮc=az:FO*վ>ҟ#4<&/ᣨL 9fB]S:;1ʄqTRUnT C+^x _&4x'ONxp 1^&g]O!@an4n+g釓h, AG.tuW0 Ly~&u n^el\2[p_DXbsw:pR䆾6Clq|z6ltP>'p7a(S\%Јogޒb*y2A;D^N9lWȖ!9+.90k#ly26ܼΗ(Q6^5yeӞH=nL*wC^sgKK%vl[P/yH f'?i*㪅o^9[:*t)hc#"eqJ듗R| NtH$ꨁ^]J7U ]om}a%YK홆XD> ̋_]VrOEH Ybjy@yܝw!5E 5"FM4)<2I׈k# YgGLhIVi#-gp'D:eKQJGjAzFeB1&ߠ!)HE[ U4g4b5Ut*Žh`_1gd_ΰy]ʽb ߛG+#y!;A!u6SlqDyk:p8mKXs$h7gP,(E5L'AY&X F8-q|!2V (RB~=ĮIpORUqtwDkl!3^ !A| 8yMIPzo׹tDwkԘ4HO7̴CA23vzYBE ']_!{?y|Bp"Mafr(D k:7ɳF9fg!Gyr 6-ebWx D+9Dьd75QAra\n#~T~("X.jn}%ĒK5=[ɣ|o`D;)(1CsDgqӧ&Er(h,攚aP8|HSh-p qv.#HWmĤ*?g_ϐ\K|K< }Rowޞ!JsC?=Q'ݕis"k޻-=QH,XJk]E p9gR˸oMMRa/HrӁ%,tuv?*UcP{iC޷4p)gv^Ж#@YAa)?36R~tmkUWe'0P=^̌RX##10%*zshđ>,:6rQb>NR]q^K?J_4C ႎNr92&BKEnHߘQu&YWWkIl9;/wovoEb.aC+eyD>i4v\,G~)AW7ːxȃ۷VU *Bx3M M}&g2$0ٝ0YxUjZ]d<IJ7~.˘u8KSqJ;2+$YgD7Dr!DC"q +m3ǽoOMz.M yfHamx6p;*9R5_#::gƚ8 eg{["jcY9s)|4ko Ufٽ _-}hmi1hĀj$pj&79-Yێg y3<9]%~?T((/}cs}豧b%y~%*ÙZzl4g1(\%[n(Y 7 a ⵯ{rpI4^u2̜~|ˀyhG#;&sPB-]m70")$M\M4z6o`%$J3o2]ZZ. Pfت-͟I\VNՉ[B(o$iues%R0W=*Ť7SuqG|..Jv 1(f C[n-cJ,X3Oz*W(\Ѿ߈WfN\9J PJj宖5hJQYоtl7J X@v)8ABilwZn@迢ߦW֑d|#c:dI>M l=Rw[8Rj]xi?<9Ay-SƵ\PEMXe"@vepX9\OQb5M|I@ְWWCTH9KRAqiۜ)If?Ͽט= &jڢnˣeWyO(|dX Cu+74A,~*jc0| I_G^]U1˾VfsR*d`E խc'lUHFo QxoѲ>K*͹7P"r0'DF߇c$4uJQ+Q%WzlY` gz)sأ~kz" }& 2 fCG hǐ待Q˓F))wHEb+͔7@ ?P-8 Vĉ6ع4[Z8@NB^j J[7d}lDG_dqWإtCBrJxeEa,﫮a$ҧC`- 6@\ʷPBށ U2"؈ v,d)324&w Gיoy\j\$Oax@=<XwL|KL5(IV*x"C*l!¼l‪>ZeDȻ,,339[tDDkQj`{bks^La>p*@X. >d } M#1!>`D/ SKø`9|%qIoކ4l-K3[ԫrDLMD2!qkŦ>oL |m7t6ϾA?c4_TuF)e;Ҿ>ְN88Fx,'Hg2,"71\:Swדf{Y2V3T~O:lUaBF%PIh(9axm4cgA,X $"kɃx]ٝT41*ﺃ`W9= (rz`(HPBY%( JeH-Һ-K$q$gt2 JG&)/#s Ctj,^(j~kBXdܛ^qN쟬홀7J}iJCO؋ 8K •~ 3g4:Orqo*Ir1uYj&/}bX7h i֔]bA?JD]M^+$aT yEm@& ]`}e`k;YҬ t uH v&!=s;=vp>M{itx,xXVtG2Ep~onaN1&-^C֢tjqcJk %M6ۮ$MyFa_{>eTg9yt=^=pdvXnrWb*_=.OpPhC~OƘ0l't_!۴l._Ͷ8 b/ yd$JQw^; 葮Là4m Y5qb*Jztc&vMpT`):@\5L,s{7:'@TBr4R Ձ"2_h*jF/DrbEחȘ T7g<7Z?}H=G˧,(}h %5d.QfQmrůTA' *ޚѦv(v N::cj.B6\LMo~#t/}P 2, Kx,%M/gpf;}޲Cb"fd3wc?+R|k\ql稭JTr>頊3߯wCxA>Mg 嗀 fA4w'"A MiS?Hk_ CDSYiK(tKm]/%-El#C8 ndD#eRToT k}"-Ns>"VTIt4sj$!]R+J8k :ABXÔ$?р^# 2 DPe{UzvS8# ˒q1PѲܹ=ʼn7T^tyE3B,"`KVK.&~uα, xM^YE{<~%K)H>8*C㠬 l1UN2ۭȌi6*яKCGvO `XǷӾ\(7<@ 4 7#Lƣ:6{Z>8#X6|j>Jj\"/pH(iM>*Enp+']|(j-p =;6wDϼ(X';+A8;tH,{wP7UȤ%;>N{٨` G”"rٯ; &4;C^YcTaRa'݃R}: ~8+L1}$o}7mHJ9L]Z*7NIOӏ1<"G|kmv&_ijzH8!0V>aK(gv!nZa㢙 7IaFqfr:k^0ȌI<>r뢿'Q~z.*5@VP=C[>g *I9{V~CQJuEozZfSv!]N? kĦNF8Ї:tumuG)Wt׈J8UV!2KZ+x˼*%KO c=Pm6ޫtd[+ml4'\:>ZE\^4x0~cK 4 NJj0T4VՄnX(yW5fEzmTdwf}ZOrqJVcc\1xU)>& 6CgW|hJ(?m{ ?,Gkf/ndBY1E̶('W\?喨/"F'gunnWE\URSpne !Z4?aq)Eȵ ZBLdU;+~*ә=^/Yuw͙Փr3FY\SWȮ#*QYVf[>6 7q":`[leL)4Oo4͒6߸9x1\rT$EL{fCi/u^8aos._%ȯK(*[V9mmbBj|iiNߺP4H~uePT]^L)yhs, /d-9l#pNԄ>t>qu툓9(pEdȄ0]&;)B 27 ҖCK4RƱ7wEUI U I3zei%S`7QԎDKa`d}~u. 2 5>u"5]3 r?k7"4O̯$8NY-$0ΝxhE-]hA#׃o]0v ^QA21#9("b'E@^zXCz}H 9ӐJ"r{Kz>W`Z/ ܂P}y6b$CKc+P8ݷ7x(MB/V'p+QU 蒀XeVP"zLvRI!$FŸ7>]yI y-6D蓮jXl}]hp&J[$yDgq,4zkjP`2KZ}s ڴHXTA6Fi +DKْۿTdK;cdSZ&ZZ-.$*q]j$7# SR_ 6cͳ.EM.Bm!)QcZuT@Ɣ?tmy|D _%ς>qPa( L4(9-nHJ7B*~1_NʦD̺@ib V0ai#&SFtnuT^$\ԡIu$3&jh.eJ/M*lKN)q(dZ/wj<9[Z7EMQ[1W{ 5d[Z.3'&wdj٢b2!x:sj S8ߏ%f$'Ý_o<+2Q`#Vk7(}^NЭ) `${őRY^262=m>yw2\vi;*PybJ0 lH>wyf~oiwk2B+Vu wFR צa-"ttPmYnE_+(fbT'F7( F-נQ_NoyyE=.W'@]6j#x2wyFu1_Pp[vo$khVjbK?}uEs[NUP^8LC ٫l(O74ˠgY 1rO0OVf,SA,j 6YQk3$a~N\ llnK$CFj>nHF6 *^1WgRr6NCy?_,N2Z罧0<>BSqȷ?gY%}vz<`!bG:ew#Q?UZZ.GF U%Ja^`O#! yl+kXz HllS)]6; #o"/EF%O;p3Җ _T'sFRs2EV;LS"[Cmi`?>f9Ac=Usg[,AuJ0OSe[D`D]yA=taM) vZ t1?L,X8Qե,kЏiE*rt4V7xJC y^b*Xl ;FO溺A oB>kP[sAqW5/H Rh"[>v̌ A?,h@?l_%vEuf^HU,57j+MBڃ{9!Q1J_BDsL4(E"g @ s#B#akƞ\|y7[!.}O&rDZ> d}f/[-hܻ/(49i"qpň--Bd5ϧ0#cRm{W=Ab %f|Sā617xuٹsJI7.S.{)WFnL1_QѶ;*p;AqMn_(*d U_gN-l@Qኆ*a6T XDE>+n4~~=1hz|~kjC|(F9k`Ԏ{(Hʑ7V3*_}opC-c;{0FGȒx/A1ѷ'yI$d) |K^_58G5VyaRkVqaHKȟQ}6eF1\56'DLTgng(4N2G-Mq膿F@"7fb:T9I_0۔"/t%'H7f#7jF8@p."#y&0քq'kgj%8k^.ܬS?YLPBJe@BR^޵ OE\ a<]1#̊iҳp7/9n5ћa-5lj?ދ9u,Gz~Ʒ#g瀝juA6 Zd]_m Hvh,*)c4^Ѵuր%j-g?HhvLneF4a[cQ>T0Y"PC;9.r W,}GG{t~4Ph v=rW5[t}GY9G&g[\ 袏:3^=f&'xQ6 PzjbD{1I‚p>y < or] uYj=g_ :sZ.Pk;wSM; nZ;! Fdrݷt<qg4;R9 <-{hGJZ7w3aL!889 cRJx,w]q<UY%^otյ _%o( +[1~YuC.h2#A?~\;!e#Qғ.2IviւGjkݱ+Y6OUZ"ZqA0˸jṹ}t`:P.>+.L^Q;GuzaSv8rHW%AՉIbY!w@}kaV#y Ԟn! 3!ѵ.A$ͳVA->ju뫿a"pԶ^uT,e6è DV~ukTg?vs!W_P5T&ZDi!~%1=r% }K Y'/^Q+L| k$KִL3\4ZxP=VYpר9ˣ"uMv^.V7@ w璖Ns`p$Im[$m,ې(7,/]^ƎF#Ct6T&,*0 񮯺C`|Ayo^r׀L$s^,*q" `yjsmuۑ]3v Ypw|O./T~9+v4@%BL BƊ=qpm;C\FTtS3ī3nX>X-[R1[=1FS p !Cx2%UQv|M/ݣh fa+Rn Öh]]n|eb&WGU GOV^s\,]}/p*dn;Z.T*ΝFMM]Oj&@|N.KxqVhM YhwUHf'5zJYyqj=_OL rGd"K(PzznÑ 4^Σ;7LoD\;Ya/p)ɍ 0}퀹@@NJU`$J`$g;FnJ*ȳcu56L;\[M{:"ܽ"X37](0=rм(y ̯`ڒ HBSqX%ﲅ_9`x5s8rg!2N㿢JeW9{VJ:'VFiP2tzݵ[` Kf"uA ʏȥmiU:D {WqXoڟOU3a9- >q9lh5Cs@>1n##ξzC.)7Htm/1ߡ>isTtjc#6'蓐KNɵzYҜG2`1yYU#ń-gf:`BƏ#Evg2@+鮤ѝ+N<.]kB,!獑Na'}_>SNC*~AviSZwea\#gӛSK ̵4ݬgv< `'MzOHLj%0ɍg6XP, kU,%ti-H9Z&N؅8CKԍ|Z}e=JlI*Flx4碒JodݿYTw'gT+d4ỖLM(9`eveu4 ^k*6@o"C(zSO>C>:.Mi (w ϬzAMۄFB:7 ?Ҍ;!Vc )G#elU*%.R]г(]]h|OB!nQobWvˍίu$a-PFj6Ok\5gC/v#bjQȍd3>Ѷ&|;iU#OeC D 0QTXZB4o8F$b*uߕyr0v֒7%Pѡm?F=r.}5j̜Ã:^nôsT ӿ,!=]}PSz)H(/&1T)@sORM`n]c:1,} Oz_NtF${d ȒrQn 3&:"bkɌ_D.A^[qFSb 4`Mz|5(6i/*F<ё=w_-PCm9)Ql꜕JRnt১x9s'`/ץ`'ܹdpVBkoN#X$Ӊg9b4@ xtfٻ#(, !qIyz _gR瘵9t>Vjlm+N) CJoL'-<[ǀQl9OMâIk"NDqfn-*0.3El{Aٟ\񆲇?u&\MRLcњnkLiyn]~,cq),}*t,<)sHL`>,&zRvbUoBuc^:g2?\@c j^jQru/Ngq~ǗTLm*{;5cJ|QDPʢdžF܎;;h3+o5t/رh 15Yg^ {LK8*G (4r Ujn ?/%JpڃL:czq[췄QkџIWj..S3>gZِxB.ԼLe-LGQ1ģ {9Vt{*'<׈ek1-e; 定 Z ɽDgosĴ]}a[뮜Q[43ɉpP &jy'R!g7q$Қ%ԐDG@UOnr2RͺGL%|dphrUbS3eĮ!'p-ɵd7e'(M)50B 9}aP"ݮ^ I cW+~wh;6He=Ó*׊XӚn ijBoEiM`۠b!:~bqu_g?,>~!*Pgl:WD*,L*Z˖ez-)eq ])67>oC+!c~F]sy8ť=2%G㨦U S%]bZ+] H 3Ag.64EW旬23yә_ke[茛jYBK(Lv듃HEL+r;Q*&SA(J|1q$Ҟ&;&yZpDػ%W*_r-L>?Ec: 3v{0AQttg{6%=?RzF$ lD[r9nX<`A0n5s2u5"BA⢬a*_1%"DC5$֘(BBR$!3`; ILw=r2֛ <=' %cͣJCbݿpj)=z֣a]㰵_?:țZar#LF$\CA/+e݈Utc6u~Kd v63X~}Zk;:sYCu> ݥIeĄ`vI'jnTab}PX߇mhī E}--z-r;n6 $TǔZޚIs壦+H"&`B"9V*ʹwK nE3D][Ҿ-Mp G0Yti`G~c:-7kifX +"QGg,K);>A<EV6dNlkWbO$RS0-uNdRf7Đ[ طl/u)ڜT0pg),`EޓXXy=7[?ImmM*!4tj4ހ SO gLO`7hPyBLZZ+-&31&}@rDH+~@s,kT9(g^hnnʬF:] ;C䐟k8Ņƒn!ATìT1XOLA5(TϽɚ]=Js-Ҵktl" Y$ :efv+| ߥaѬLgf\PGRuAɊXs_1ppvHrв徘8p[s$#O{ xh0~S={:];WxIZO0(f57WH DJgɛjώVE[7ܫҞ~=!>wNh-9qPz'k%, T&G\~;^_)8x G^@ƥHJPی\ C.8Wm.svr5O`ڠs.SXOM㔨[`@:neMDf0YK -O7n<(`e Qs@368-iJD_QrG`{wP|ãCr5§XEuWzncID8F];A'9X4,"q<6yDqGO|w5Vٸwu˴n=pn׆AXƟ|V;4菾XKMAG>);c &A&ItOTQ]^BIe^B0Z^iC<[A7_9ŃzGDs|Lrii#x %4n ݚrxza8Ee$2Bw!@)gl,7 ݚ;BZks0ei>Mj}&D/e(kӲ#|.͋El9O~`E y^5L9%l|GDs\K;&.LJ[pMe{Qa?L(žŘ6e5ARUpKԏ]! 0+#_ P noa@i[91qoDMv=x| Z9L T=rt4?(B`{Lh7RWFzIH)#Iі1܃tM,Ita [|ɯqFό_ $S{|<68"rrz~c` CAeXi&h#Q _^8`Ԛv?y|Z66! -Y,<.%uη3uQVfN˚4Er|{U|e%) %lFCw)L*e" x7{sq *ԝ0gq\l>L<,%d4Gj5O 4}mpPci,KJ%?A_} @*!M:%c gyP;+ai4R=w Uk`DM)wT X|.8^=AbFH´ܠ_CMo:QbLf`ٯx `C*YC#|K D@U'OWQNz'a`cNrVeHִB }2Bh!pKq!'OPE妠܉MO!d+-o)_wb]RQB^ T : \bnJPnL7 (QvqRo?EmM~yTo6Q锧I -GU#2&(~s^yt `>lhXpc%3PEkt{OJxyGXDGZ\DθIpcpBKj#G%#\b=hKݹ@0OrvBL׀AM wf@Q[ C]Y9IVmQ߶ρOtBf 8rCegf9.-":^wLJ }VٖVT4o(P7~PZbq;USj梶f%_9+KŜS `a`뒈s{WW0|0aD:,cP~uh% 4l _'z>›wsg믢}ߡyE,v2]Oc 2mp/~qH"M1WyԦ yK;UA#W=-2OjV*L$U?zW@)69မ, MRkj΢=@eAxg.FB? 4~l9%Q!H飛8T@6YL|+#_F<ףoTOv%}#8g)4sCCIXas`ݴfi*X$Wڒ 4D96^N(҉)`y%Î:C9jFܽl$4 X#^RI8&04g9><u R~.y@?׺4*qUT ;r}B5U AtBVxC}9woGЉ{V9niTm&_B/ f9X򪃟f5>+w:aH̓=!4z> .2,~Wrw(IXYo0:vfGCM![ Ŕ# `lU#'9auMʖOW5#(]Is2d:eޡJ)_0žv@ݪbhT~~Xـ\[:[_I])HA0W͗o;/fOzq>ВOk^eeʕiQ;` 9':YZHPa^<ݫcƞv|, KP}תz'05u=$V(YsMfKs+ X9/c`)OMwf+ޛoD?5o-Pd}i& ~UiͥX(aoZ% _1RBGAБ$w`7͇lpX.}K> bUA m #x{RwTv1"Hxy9kma( W)ybɜ,}+ܒ"w|HeX&.(v, 䖏b~ |yFP)Ev^"G䳰 t -pb0AwWW+'4K|ɇ᯳c] )4f\F̸ p`eG @v|KYJnV2/D3y(Kڜoc?Z8\;ٻ@[GMG0ͮIlfGň*Kii(fsr;@s6}Dw`^-رZK{}嚖Qk.8+Hni"TQd*N₆ aI .pVMD&{פVT換ǫT[P%&IF澫SdԤRCƐ`YYӍ. .#A]ޤ8SA&ˀ9[pRk[r1|L1Y6|H7쁴 1j5ŕQP9\8+:Xf15 rO:\-=ȆY^N#̒.Ka^[)_V̾F,V3zN.]W^\vx8XCs[yØ<яۊK>gUy: ufI1c;O*=Bluo_|VDoK">tMN!7CDSDzN u"QpG#X \.yGs(^9U$)mf*qWHןرs" uf視4)a ~9j#6*2ZߛN]^tsy)(]xxZ܊ESz0e`2<>eN7I&wqPD[aBK_eXc(n9~{2>{LV 0|yP ljdt'+-d'h{:DZj*y0q)]L7/ol*r esFuZ>,{0Rp~F+pћL*r1k(3=8-8Wd[YֺT`~=L!.ʁpO枣4ɇev;b!|m |Jv?؞)CWȣ/*:};ROZ;t 9EcE[PR2,SW 0ԇT@@d:OdZm8ps!},a1zkN?êlx d[YѲQոV;w;%쾀ݧok\h ƿMu #>ž(a{EK^zC:ʑI|w=_yJ2Jۘuz.62l_ ٘]EzBgi=}\n>%]8w~u79/DeC]I >d~_C@#o*IRJ=ŒΞo& "邝iQ ?,䴼[ goM"QbfSQ5g p!JC4  8 T ӈg巂n6<ƍ>&ER;MxtXɬ%%S:ؿgse`*XYr|,"u]E%.X8z_/xknݿO/q@xC=yZX_ US;O&boԑOkq{mo:tݾ4rٸxȱ6P};Qǿ?Ck2؅${1ՄΏh˳a݈k.Y񯮰ԩ.2ɖǘKxʘYǗN<`\y!P;U'RR<;N[#q+ȱ tHt@ }km+][oFҼYTG@ jnnf!NLŽUw?~N"!ʣ=$hliD;DZ%~dFC`<> 2YUΌC)B>1bi$P9j=gCn(K7.;H-ӃC׳*3Zlˬ.h,&j .~Ex G*Ao(&HA~=W\_çht!f-ф^r9wP}X79 O}=?CQi1[t7ç]yA[_mEO~߀{nqIPӜ[R1杒6֩FRv4\se+liƽ?nTewd]:%qRZG-ho!Qk"'U{p˦!|PFz~-ّFᱬw6C !0 dJ;wsfbk#X 4h:3A)7gI_FAz 0f~ 2 i+ :8os〚0Wx|Oi%Q. H$13l jD!bw/q S&7'ikQ#pCYW[v"ײ{i9‡:0~ Sv AK @V6taײ:P9)ypLɢ7D!~,e(z;w‡a;4X+&e Nl5LD}9{qZg")&SXָ=i݈%5koGC+QM [0ÉBOlɰ_L]jYawK5uGq@U%n@7cȅW"e.m[ym$')H[N`WdH] 69-[fķ`V{!ǎH%9u='tn`q.bzg>P !Ћߤ9P]YU-';&܃j &bwp)7nY'wz'`ϫ5ܪo %(<#}(+Hb qEZJt{:~}wø>_+N0y!e0nGnisp&4f^Mi\DNeix EƫboLerЧ\*U;nx/7<ʡOrQ>1^za)J24)Y ]hA_]}ßD28}ӡy;J.p$uz!uͩu V8M3u[B _!i%#bdϽ#3]9j q!6 rt<Dgw-;JeE8&k5)'t^>]x \4W^$"jlScttQj3xGd f}hc_z @e/a僁V-в3i͡2|%.T=6iC.!ż;XԀ9 8"D|[n}w.@WJ`!6W *t<1,eA (*Vl?O iR9賆t&F?JLXV&)Yzvd ˍ'"}S62H7݋>7MF*SLmuzԩ[HіX_]bh9W,ONJSޥfpvQ'@YeD8Z_ߵwUם>q?UvskRpQX(=LzoH)},v\D_,92Hg]:cX5b%hTdQy& W"ҳ&lX[}9 UBMo~~X]!- c35*,=͌ӗ ]<r/FdԇƳ?2<貖-bblQz;یdbwk"swK*zbj|*Η9K[6+C/qUH雡S([B% V<,5V>eS0ا$ |rt #"Fe* Ch<ʖ2'0'>MG1ʋ^sg'R_*ݤ+=Eu&ywe4d֋egt/5* QD u H̔{. p\PSf)l+ m2јl'HBN ԦW hrIl' >uC7!ö&wca_m,9 zD+ ɵGjﰾZ=(uE0&¸-/t5íx1u@l;V%UkenvM@k%&,pO4F8|hƜ~|0ؓe.c!FQ>Xa_N53G; Đe<Ȍ_¢dxqzwjgMbDY?@t}cKAlOgb&iq &t3a,-]%Ab(k!aNB/4z!z%"y%(' s+-+BN++, a"agw5 l .RsKhnrE՚ Xfwi155]luBu5PϭOEpAZUļ./ s}򊌅{QϿY_u 6[hHj\@.c>ă((6}8v=yHb?.KyxVÆNHY%Z N뛊 /1ɭJdh\ox-YDG\璛(jG.ϨJ.|7rpcY gS[,ߨK4T/ߚ~j4y 7U,^2{#0*~ү/34xgu6/76Cglnf=XV>A,+7K|81`9>ݼ ) /lCrI>:RzXg"llVHB#E;gϱ,Z)NٜcX NC媜EPLw-X WBA\vME)-<<(F Zh`BB4Ƕ܉"7^WpQ&L =ڹYE2, Z{1:g2LxsW |k&uD8X$A#{([iXQ7W'\ 9zkgz~ -A*Wڏs@|Xgv~}3|&&h$"by1̡@-ob3HiIN8,?W h0tɑ>D?i@mHC((n P(]HCOΙTE%z€]6o9| ykfϨ}9H§ d2<#> k]7zyH$c+_'.^Y^kya@xXI ]tH+ M?2^܏I1˧LS.@;t>[[c{(Ǒ]l5a"9$xQ<)}6yƦ4kMsFU{^ _y%؛e5jPVCC6Ri@a7nX/ҡ'bfȇN&o.V&\ SʨpQx,8#317#xM D{v{mBMه:Z KVZ$'H*yn=$ ʥ WмHt1*߸.7Q#¥)HUlޒמ*bBNqlE]l翀sԽu Okr(% qA\9[漇}rj{Ba40icMD؞MΞXF ҧY ۺZHqZY5ToB&h#wOD(O\l0I2_pK.سlIT!ũxfHȵ9^l2ug\-_`EPeگbaBjÆcX1}'f0!UkB,;=< :h>4%h$ס|R)v!1蛀3&J2ޏ}վS^FW\;6Hzl'I_ D.\I@*T+eݴ=ޤ@_@.7;^ȖOxlEIAwxVi]~c1T],vtUeDY SaQB4z2濓4~gPG3qgo g0'dMHwG[Zo9C zޗvj_]eX%ӿyqŗ{6eseM#eB$U+)P-֭-*i4[99NtSC i~_dC t 5$üAwKJe3WgEٙ! Ky(GW٥agЖu A`*QVR\DWȌcո~Ež.2?]<d97 ܮ4΀/H2d_ta||[fC1[nm /cLD3cZtvRtdfx(Vb2k7ِx`rRr*BoE<: V`'yC *$7a([*ZiG,+RcG1D1q.8F܅jZVK~IOpNYsdF7&n.B!B[9 hnטKkR_@lIq8WۓBGbkWhȭ .i 3`CQ8VMmQv>I8PRd\r:bJ(Xnks]_qZjE+݉JN?B4 &i@?E_2g6iragZ:hLb uA}r]«QV*:!t.(5ќ1)p@vK:Z%R;sj#`4$o*c}qi wV0h`ԠSt69VJx+lK1v5cD԰"c ! y9+/e|2f3/mBBa:z75lFU@ԉ R:4E@7&ى %A4 Kp."lDGbSLA(Ӌ}߬BuXJ"NN U~ ab sXJ֦>oc`Œ:y!࡙xBʾ߸dd+?QLq.IdX!j4KsXjg2ϴ2$PYVz'cvM[a 7`@3:g 瞃Ps0~">V!Il?p P֗[p6x7jxs!({((s$}˻Z!? ^UrK \!0H\I=y_~ǯN!V03VTUu)E5њGp_0u98*Gz,š1o(o&♪¿Q]`LuB;Y-N;|@7bS@ WTB1|;E7*NAR. EktҢ߲Jc(rZ3HuQb)%0rA`GZD!/ǁ Q(VGs9%{Y(Kt8`;s/ZVNN4xթG`XV )%ͣb-yzB R1eDvU = :h E:"B•`()3%'#y=XYiܡK M\H ίA\U OA? c;U/Q H4*6"BSmn_"tBa?L}Ѱ1ڥ lV}j >:p{ [Y$|7H"&p]嘨 31=4MC *wrL"Zc2 " :݉1 a蕛+R`jDTS6ŋ46 lM 7~Z2frD_S޷ hĈ?m ːHN*jzh~?fC`/B9Y,)Ѓ Z_ D{W:PD/x/4w |3`ޭT H#TMYk`bGКKK_s6xʠ-E{Pld9 ?-rЄ(q`~%q7hlWa k{.7a_9뻠_`PPB~;I4/ |ȭJ{yw^i:*gr9R[i˸N(egbeE++:XCO JGfY[6`ɡGn,klfA!Jͨ{S~Cn$Zqʿj@&', r(~~tp*dp5O^  ,_-` #y@]d$Yh|fwtOV*=e|Hx ֌-tOE0MITEhCtM舘[Ti|hm!]uRto` Z"Bzpd~yC*Z!4%,%Gv1|3 Bc5UюNHunUB)~nzcޔAO+?1^ L? /id’&"7xn:` ]'qEɓKrסXEh\C| _x,~:L,̥k~]>'=BHhG`R@b{~v@l9H))&+ne9~MRU]Y))t'$*5*M lA"Mf`{_'%]kq#(f>Xm C`ə/6"> ג!B h<͘G[*H#3ˉ܄Cw4sZe!vpa\=*,x}kO%װ{0wA{Nl^Vu}QD&kI9Ԏ*+(Kt'>߾r=@V@4ݔ"YMGq lh; 2KhWqx+֖WyIG&$f̍Or#Pʀ-f%ߥGkO7\K]ә^ҳ0k>Yxro%A_m]yJMcr ,h!]{Z=:- f d\#:-m1nqGҳIE>p<_F?Y7nM:q&i+m%& U*>wḇ WtK7uRIwt#S~;K1_c0lW<ħ>^ i *VcKy7y.2-L E|'#{.=9cr8SncZl ^e>w C"P^J(v܎L}4JEz2|?0$*tUXA^;HX+Eդ[v}X~$7Õ!=l@ZF"7!coĀH4]ȯ˟9Zfe(^KUH--C86ؑ# 9Ro9Vy*ҐR;v:1ozMصHF䃨sd{6^W\8r4֟$B;dW (A@[}0m`Siz<3=C'qB ܛ^=lՉh'OMZ,ErT5ZC_NU*\ҫRuvrym6)\jB_3 05yԢ@!IƉ0ެ3vZ!ƿmhjL},;4~1Qw-$+5#ұZBWuV-P;l@n5c*7X!| " #ʞ J1=Qw@Fn! KUE\Tӻ3Ucp3g(j@S9DUï>S$`B"RG]ZkdvLS2i@2LͭW^=',# 'M%b 66EϞ9Ap/9 pٿ rr{WgQ7oXֈ 8WiHx~ϛ(1m!^;l#S#g 2w',q1A s|?[ MPe&9IK:Jy~ZGYuNZA(` bSPQvcm'14-W7y$g pa@͎8)3/؈8V~1ǽ(VoBưw&4ΔyDR W}-$^f sFSMCbhr* G˓Y4]v:_j$#CF᪇;."axӊ'G|Wny/ [%4TwmAOw7$&nM>exlq/Ѝ.I,"C rЧ#b˟#;?!Ktc y[(Wy<nn0mO\#W9q=A#Zv%1"d ૓pzpA͡'l7O {\[­2 w)%▔&:1bWw7n@:/)eWFx ih{FxO+_ˈZ{t]cSck ܞYc*7]fx@0ٕ69<}%ĽH cr{poQ1s 80K\JFW5˞yԖ+# lT=U< fcx]& %򢩖[S困}N^v I`̢ž,"#fyj^of›9P31H%/-Bevr؝Z8Tŗ!y%`KOIˇs_:IlaϮ S#L gw# fPx(Ŗ!kv ќj{Fڳ( q3y$Whrygȼb->DVZ YN'H5JKam{jVbRĸ?ʅ14B: @k% ?ҙ7|iza8PLWsgc pVr,L|i*KڬszYATkAs?Ѣns@.L4mBzrNmxw!'%aJ#o8 \ً:UA4x2b9*BL/.EZx?-Tz@KTM%qd2bQt5t%fpnmf*34Z"[[ߺ>Igpc!dt p}"'-`u;x?@e!~@jx3 X83V%ɟVYqLʶ>pna]bBGbOɜ/vE.·ePn;5 -4>rހ A_ynj(Tnqq#_/13F₨3}ld%=R`;tbS-o#kbr"}B"6:NzAM;_ԉ%-l%3̶rgm:$OAmEG(i9PO$  gq@b;"*bHC7.*jhv!T 㜂qѡD0k@}JwChJ>FZ>Y-0r:+Wrz))ØᡌgVʎ~F=ͅDc?߮Jz]q `m@4oх:NAR7BI+OM=xJ=QW'f厧3=6dqu1m&DĮ \/gkkvI_qA% y2hz|0޾,D{V4 l+'4}®BG(.Y`P+:#.bjGP8\cVK3RC%Wbf@vJ]7c\g[26dqhsᴏH"1y%j]naT{S{6g l{Aܩ'E”<;{WTx&*GY8,2S7#7몾9h(!L^Nn{:d]эlS#i_ה>zRgf LJOzc>d`62bvjSA;t(WqveQNZK1cQ meu1JL4om D35"o<?`3 Ep+NV7̇eaRJێb`MB(~cg7h-*B$dk2G/e ị~ a g\H?f m̲4@DmP$]q nמ!(X/ >󭷫u宱0{Ww)wϚrVJ hOȽUq>$nVɪ~GCVsm1yXF wWzny \9;NiQ}uYK Etq(Ҿ6aWG>@ 6}xڦG]A(\1Bqy4Ay;{Yk?xb? ,!B^mY5eL7+aSS;!a|b<Wqj1ݲsM-1; BH:v}wNJױyd@EwF[o8oS'!GLtsMFC,tX"GNl:ri0 "}Nޞ] QP~R ;u)NǢ)D>vX|䈌ZZiҷd4^kŞRra {(2f lras !x ux*2mG"_B>݋:k3^k!@8&3/%[&@o bNmK;Rs ߜ-d~qO "&~[>%a쯏aBwK,)oak6I=L'ؑ}Ց̪31X#68W6yg?+v@v}ٙꂻ%5gI:)af&.%ETȽ}&ק|Eܠ{_VMsuac7|9ЃA* 60>B ޲: JPk]J2fB`QJy~PXpXkvA&Cؤu9KI%eyD$* Br7j+32Jjb<YcŰ|X:.09] 41 Kٛ85IF;S02Vkl91a|]H}gcLc >i-Æ%dQp%ቷ~i+{*nuhڻR6ۿ6{hixYɻ) ҳS*0.huTտL/^rsۯzGXnךRQGԟ+F6Ŀm~xά*rɌ(nSB>^ F5J˒۽#Z[!N~\FCS[GD<0F,y_Y=wQ2T0+58H!>OSc4hp'$rԟe5ܥaa;iZඦ{Ѣ=*K56\"9pzR ʿIQ!Z*aB'yG[Hy`&7ȁ1,+D*3^r!>*x̋Κ-aڙ"ص( ;vk$/Db!nAd>㸵$ .;FG pk=:1 ԗ=\㎱s>ئ u8`z/E_,j[At C1 a .y>Cj|ӍV _0=z*Eΰ '[&[! _*X[;pc3ͦ-^><$AuTo9k]9 )_gͫ_-ވ:OEu%ȄIϪ'1aDYiZn3y1?hY! ?Ƶ@5au &2ٸ~9]3vO>r H<GA72@;2Xcau{K y#f@✫0{"3fD=4&ef2UɯTTGA1u gy*Jc1?I0os>wDEUe>:V2ދA UKiI>x5"TQγ7rnY&DO=lX5"Tz Lxmw=M{SQ[9O6Voޚ^/qɆTŒM~@z#]y ]rXW-}\k3r.Pltd[gh5"}Kӻ/\NbpMjc&da@HE$n-HY{Y8hf+UJ}d_[wl p/d^Z;z?OZiP5eW3~rMaMM@K=~t}k5_EKmσ2w-tm}0NtJ(uW@#7쯼+sR]:Z\lXdOu]^Q`q3b3 hr6 aWєC<[4o+j<{LsllE\ % d$|wx('gmLs' Kco+7@mEjYv;]3=|(úˤ7N]4lJBr9!aSSM[a&#ؽ:=1>qy߭Iܞ$+HTAjuX:8 ߨ[ `pbg⍈I=|RZ muVzoݪ6/O8GÏ[x! ˔+Jy1Ƞ/6lZBUoB@:6he0tYҥ^#{WP&L!D .3v,4RH%(/w%+jٛ /TpYe6 Ił7MT?fGsdੑ{Mo=oG"Z 2vdGƢu:˱ 1 ់-v+ j&wR#6ڰ JX{BGys wTo£ 6$}IPyEN/>@u2$LKI jŸ1k oy (B :I.bHR; Qp84:]\.{f 2":tn!b5ȊY\[T>j۲x6I@ޒ.x2tP,*yɬfÐZ}?b"ŕ?H[auVytsv#əh:x8b['E*|ࣂ ß@{lULchELYGV9A\ BUE}0x=T> l\0txf3Pp{E|BXd֠" ~n9_zvhTqYckvcQ)&g&p)x#J0klw9}~o:ZC]þj7r:%gQ҄ޚ4"n/bAC5 JH4 J<[gaS"k3VM%cTd3TSUU1~T=V!pRa$?(u;ERiU1S)_TK;,`b| ܚbH> F "!t}{ldoh LУx0ڹ] 04޸63I@6~Y;y5=n0YfV_ن,{EɹMP}9\Y1n&8vzg잦}g@1=i:J9ܻcJ5l¾Aɂ'''NE wryg;> d!d=mSI;xhAav6qj.82ڋnL%=U¾pŎ>tQǒT(`/ E%z$<[$k zTFUhж"y5[p^ތ$]Pbŗ3CNX]UlFqR SD΂W&׾OBhpF#28=Ɍ2j+{5jyL6w裨!0s8A,򵨰Q\Ͳu)$#X|9EM mP4yOfa31mKh$gԀ ' 0j"zB-7t=>7}4g/[^iw_ԃf}U<[?n߰tKn9#De SZu%OJ ﺙap m-0r'´h] W_S &"ND+(")Ql'R^|-P!$:cԬ^i<Shlb X<_2$7tP,wo{v@ЋzK\4"n~(s@lVSo2!'HCq$t* Nu,ԴJ4I{ץMu Ҁ_[Ǹ)3]]|V1-f]}{l^8o=iXO3Oh'ZViv̴j\ ݣq }vwuo~ʻ /6$B1ISU=`#J +>|I jD183Mw Jcѳ {>Ekn|5ªl{z; +|\OQQGT kq*vQpdu扫GEH=]7Nk;аb #v~ZU{^t(nO*AzЎj:B. 2kW;p l\duIu?6A69}bÕтB §x4ߣ*?\dL+[R5C7g?`W=+!Yѳk1=4})<`D8%2=ؕ2]+iD nu kD>0a]YC,l@3Dʷ^3oom~tX]Ben) ,|\%QC+$[ʹ!h82ęO͙Dxx) =l&MJw',a͒F)KNw:+7&ƽ˗z{DBE'Қ{ci;!G_uLv m(VRe?X*{K}!F3M`KRQ*-Y@Hvܕ63bC]_fv ׎'cޠqt ē' f_zbyk!ob*AC]Y-%)kY)TcRY4mz tQv=8!z#~e;jPsb x*li[ 8lrʎXMT_Xx 1%S~78e3z2(HgiM#q0l_ta l3 H& Z]YZD3I87wn=0>\8ڡcVYVdFi|́SdžJT-W:q߭xueUET$[Q v;vV*]Y4D)z&%JA`_̃!SOxy ,"4GwDW ̞BX_zǐw'p,8$g!ju. b1PQ5z IZ,1y:uN9!Z6.]si)|:x3oRaˑ 22HĬgmTqo1spUt Qxr؅kYp'%~"zRTb3 8$q.h.0 Coդ"#IIp!Ps[i9U StC[js̡SXET9c?"Ij訋ȨV7: Io]QAYtݰR lb<8PQ=6(ת'3E-<8cM#X-T(O~χyf;b[5\FYe9WL5'5YVDW^Q>T [mY]0HU9z3%p!iRw;íNb3$JIj|TM2(?KK0WB[yWy&zKzμlm 3~w{`qha\ iZtX惢W_!Xc.D0ߜGsi S0X@`'~ 4xD"xy=d Cⶵv^ 9iz4-lɖO<ښ_0-z;7L D'0 :w9Se>i/[l1U+S{c/$ y!sy,jzt]Pu /`*ѮeMMX ^xTȩ~6= ]GS sG0 NF X}ڹZKhwdF@?҄\$Wg#EnAGϭv 'S; 9Z0HL+z52@CW]#=ISOlk k-ύC@eTK7$eZU׮ƅl]@mjsb`N?=ͬʮdR/X_wDCKNֱݻQx^!OpVzn#s 3!Fl\ .M~+`,`ctמ8>Ւ˷Z0Mt?] 2ᷓK | Zث1ڍ>j(q&UP)JF`"TPT.jlo> u8ҿ"H{n_q7oQ,H3u-y1揹=7VHCb>r%AHa%@eB]qLA6YE5VQ$'j; *ݘ`/qf(u 3x;as_@{L~{){ 7r3|[uJZ%}3ckl{ճkܼ&aV\))bnk4WP@y38AFo). u,yi]DkOn.\)nV_]-A1GQBxet!ƺ#[)耜1&[`VI,;_ ٳą] DŚL'n7O O yp} LY`̎cj fSj".09\EadICvD0 Q7$D:[j:U 1&I#ۼ(򺿶;"FSy26M%vQ 83@zJ͂Wl=9ܰtG~[p1PHa dcaƓX}NlsR]Ș+oM:91X `TR2(z/*(y.L,5E=H-{%!})*a7TfV9K>?W٬, B A㫷)+TR ́}\.u#׏pNKfy6~vxk+70إӻu#̑FMI.ybvM "I;2FDV\ɔEc̬uԊImj 2q8]=`’Ȧ X&$)RN;IYێ ZޘQNIpyN/T$ɦEgc\%.H߂q4nsHV>#û6߾ON5^ θV-1wrƾ{"݇ nֈ 8 EE6CHI#]*#A~H?tw4_)BXz9mR&W GjDҽ6B zW{$!,lUߡ!x2J{_|~Gt)v lwbIg&rx:32w1w"*H8WU.^yyݿ~diQV2zۄ7vؖ1xʞ"חG1'YkZgIN>RsBȚ#&Pwj8 ѳ=&sU!$ϏlcbQV,73ф ;E4~ƤE?RȪ^'{Gf8q~:GqG (?߾oϬ |=iq1jG89/Z Pm'sw@:8G$-Q41s\oմz Ÿ;`)J&ha cDN#f!/'X{ >Lሂ6s7yԗIzVUyT2Ƀ`2"hUg ś lW:#<5J 5-ULR-KI;/Vu3ㅳ|LGZ5ikG֘"YFxWP %ivZU;j"ngY]xAc.R  5g }PGa͙~VHLtf67r;"o{5CV/Y4n,fr9kxIaMx 2`q3f@=)8z>4"Kiqc2`stm8r%?uU\}oj7nDe5;"dp1o,C4֩d`tt%aW6"φ,òz6n%<c߅ZHlX-ZНGBLMT#mTN2+-a-]־-%Z2cez(;>aԻc凡mie]S N_ t}3 V=*dKDdy ApN枢LMVg dDL5a:aIdzgpAca[7!,9y7a$ft"lNUk'`Hiи Px4Ÿ<=.Fݵ/IiG|RK10N5r!7ҷnUL=gkX0PG \Ht)5uyZZkfI~%_oz\Ys+Ssyf, "1?A];bv,O`RH/2+e2+n Zs7aqS~ڜr 43l\ȳF^\m!Y HޗY3ӝBdƛEHn{\~2-S,!̛x43r ۳a}7XD$"d=]N(v{' v,I謖nrJ_˛LpFzBt}*$Æ ؛e:`.3#)-`'l@{"x-DTjVud\`^~ gjZɳa eFs ~Zv<ݺ %]v T)x3i ,3. xoT_s J;sHT`6),|oם{jIMm3~B/T/4"Pdfl?)9wZ6h=l<]`^frT+a=]s/QE򭶵wTΡ䶖@9oZHk:?0}$N^slU LQZ{ 7G.s< JMbǣx[h\lK\zfSȩ1bʲU D>lqK#ޤsrϟۄ{yﯲ0Mu CbVbCEs i+UYwqH"CwA^ *Gnb%@-3`OA;֝ۉ-ʲou+SSS5aBZ6뿗m%tYAL0voMqF\|13g7uZPu\Vg/vT]طt)~Ou] ӛQ#Y6Ћv氅)~SK+t}mDݘ *@40挍1C3P#JWT0ZZVL`cb${(uKKӜueN?Rs( }Vٺ1g,K-E!6A65ÒTbjkKLW)݈ xbRGק2 07Ww.K-= #cY-;d ;lbrc-&7f C詔7ۭj 0bb242Ddwr.q` kjt2/Y i/9os=nߞ-PUj*-aia /=&Tk+>C<֌-'& 8kNq┴,Qj>_/sa= ,v yK#{trߌ dW?6.e.D!eȬ~si VB YTo6,i^q`8ʵ(v!y+$Z:S}%$:I O +c̸Oh,4ߡ1cI:tyMƖ4@>+渖K'w E +w[X(ֵ w@]RvX(qWixƌqu)z+q檷'(LPnJGO(QZh{~X{6x"#?NV8E;> ɨwt\^C:\Er akR-qTInR:d\YwJK%coqeAIntO_$-(Oޏȸg!×0W ܐs;V@S=@"׆ -e:dJNP 7557< 0F 9Pgh1[r0bhU-\)GRۣS Ekӥ p`ݕ>unS\(cb2z|fX]a'rp=C5.SVuT02ˁ#7hA͸LtXG fHsfS'+ZpVpT@dY!`_]S#z ,^uaC`=`cТµj^D!E~v\[c_G'#~*vH5EfuJ暖}!+ I^-E"x<@d%9rK2.)QPè{@ng I{w.I,YN &j1[@G^(Vـ VZ%ouJ8D3VwىVwwkU^%dRD3.+/B`j]24^-?d@ @Ap_-|a<gO@뾼dyFҸ~'-B}߼Ť^(ݘbYGM+UrN7O%-U]J;4!簽@"Z!BXc9ťk\+=|YwJtUC/~c|X SIuƟ 8/3 "MGg(W Rl-^$1bSc) "Ni{_!9=':1zip"mir^rο%g@y;2n5PMar1qGgDPˁ!.sr}F~,k'>2χ鮋Slϸѭ Υ[b1Pf=:0~ѻ\OwV7-"|D>5Ϫ^LK8q 7cFk9_ѝfgKx׎OOXyj)Tf vNjL1c[7T%LAo=tT@{HS,ז` q6J uL5uC oX#0p~HEWR+2>ԗ yvgI1Bw'>1j7ry'6_`_4I<)" :WH(NF]Y^HuV,+ſ\#(Q3sP#*878ZP7R`ߋ%jooΙ(n}#}+ _Xo^_Bkl9ogko^ѦI,lE$爬%bD|3qwyTgu eCE_ "EᭀOlcp}otRPe<|٨8'CV GC,X ׍VÔyF[ 0%X!`Dv,l C3f@zV~- v@_Y>5vE9 GO"G\&lY=\}yZ@ g蚬z'$xPqw}< r%e2 2 h$DȮXp)p!^ҒU/0VDk^RӁ.qI昇l7>\\4]4EX1+L8ΊO-j-wWD_XoVr) -a>0"ox>.hkN1ItzDcl Vk(Z|< ju/5RG1JJ9>c5S5-\:&(k`'M$^*w3yD+=;f}iz|#Ě55 01hRN.xSYd|ޯdd_kTy<ڙ*G_ʿ\N|i:YKuGA&\*F_Wm: tEg([8 ج pG[_< VtU?܀usuy WVp{Ǚ>-u6Vx/ŷϕe ䷓~*:&Se WuA:1U]ݐ4ijzݳ "*&~KCp<$s W ^U+-P۶YRSUuo:.#/K2Z$6w7{%_fy[+C`Wվ/Љ ϛ_ !v%[LܐLfܮX.)@>e.WWi7>/U>ވ oAȷ5fL䀪tm6MGwgޑǔ?_>:u6UHx` %/  TEn;s[7q!ϻkv@>!? s!GB_DCcoS}ǖ#Ƹ; Ai9Wǃ"WUŀLV5aa6mjY>?“wc\@:I|92/2>rk@ VWl/V6ykˠQxU\fiΞ0Z"EEF XSP*CҾ!nBg޻P4԰wCb^`rA-7z۔!0s-4]"1I̍\Ua0'ŗ nj#]0{+$Ϩ^N W#God(MVz8: קW7f$ϛRغ &kM:3 >2%w)83\JQ|'.C> h7Ǻ E/#h}Had<}gK$+''?XOϝrcmϣvC$_g 5> ]}1Zm5~}h)[\*%Xd9n͎U^7bfQ=Ը c$zǪכ&#9 1V˟6=5ds'H%ȃY/гr.ٻAlOS2/4l8r{l"sI iɭoDX> (a{8(T5MHM9-vso͆1"b3~k k04t:7#$/,nJбذ֥cInD%y]qU/-kQC/7VV  2lɚXm?cSϫ+^3RY%Xr;2um3jOlNc{yEAP!bXjCU5l7Qi3]/E&Ӛx?Wd1U$YK^'&>mݯR73pw] MlPcHS4\' mw:~]!&j? ؀FrqjHQ,j NvP~-~W,ܸLJ\ 4+1j1 XC˳=<-@I59_oJ4?O<%G{$"4Mb '\ė(z mR5G)kYrf̡{yIp` CEJyUum")|{Ha bBT bhO &wLoƯE˪V,Vd~G(c%x |ZmMF-Z%jsN2=QD. r/$=%_ KϠ1ϕi hn-ZxnuGؘ'yOpсbP^' 16AAm>=r l%rzLΨ$ʏ$| ¢ؘLlH`TTw{{ W":R%䂕j(V $VCE֕#܃ǔ6TXm3rk~c{?uz`?/ev[6\ ̮jHgtb8;_t77]ddI7d1 retd N#&6s8Ns? \4"fMH\%T ^/WiJj˛/N`ha"KĿzc'ȣc|yn㹌3` нꉫ]QdL,/?RBr"ȴN,f'٭QiZ3u;\^VlބzU#ħ~+ +uϏ~TbTA9ˍGFVBTvN/}м3dn}j{O_Pc|.=! Ё'M_x}GIڱˮՁmlF# D'2_$ZaqB<2";F7^}idpEI;etohhrHόF֒Ԟ`"r zH&r}諲YIoEXm 6ѥ9ϹETIWKܜ bɵ8abCRhXzjAp6!jQ)DOsS9? XFbhutU^r[V{k#[X^ "a,f6 N^r^T&KߣvXav0:'ՀyymztSJv]8?3j.Dȇ2e TG/P !bdǮ+Tjm1݇2Q dkDc(Zce2$1@|6k5 ʾm{ g ^ d=n4gdiYi6R^=a䨁-8I yJh:zIlfr ?^wvPMm=W3A f>o=dv^πK>?&9p=" .N4IN19Bf:fH">$&d)Z۰b' Тgg9",#wL+GªqJe$KmD54M.|=F^1+t&x\< ;! NKHpX޳Ύ[neі >`KcJ0F(`vTgUD~F<)P/:t4Od-a6XkK7/#62Az[98n68p(,BrFI5Jehf2>k}K2-Y)~!|znl?!UhjP̰ʤU:?(?+X\cw`9aXlqJzeu%e&~YW8U D Z%jPȤ05DJ30.wt8bO蝨m3+|ŬH=M1Q8T˘,mO;XtƐdB ,=ʼnPs9zO/y~ B dXX zD n.&OYd^ em$J.bdS;,1W]1A:Ϸ:'@8FWyJT.b\O`E›e(a ˋ[iTMDro*b& Ȉ&C'(9LD0D?~xJ#2>AOJ-|ЯCj$&.x.&-G$vy.+ 0 nmM g| sbf=WՉUkd:YMLes|aTc;E*y?n: .4yF$3ܐ GOٙ,u[t@.}|lXV]r8Hk*quCE`tJCWUq8Waߗޱ0 %hǻ=8OIO͘uBAO'9, a֩% i|XVj~PGN_McrW>k ƴ).C=X;>5"3q=oI:iSs! GHQ_V罌&wrz.^9nrM#PU v&(NLÑl垹v`b6(6[wjң=ODk@~JDdpXD4> " yӞ>]`z;vGe-CQTS_M5]og'y "XZ^P" FJ2[& ;zC0m, ̉k0h$_k1{=܏A'YryuxRX> ,,,;;:H $J|Q}j@}E;-#v bF 'O~m?>ϰM_-bo(3@w;HM,ykki Mfq"293:/*2.O{k @ˬ̴: xmqDWWT|y @Ԋ(Ĭ=i''lGXO@{::+J{FVaaSc44Ҧ;h[ L  "ķf"S(]2,So$*MR#d/κ8e1eu5Q%/~IH7Dn5X,ȘNP%k$ ?T>~\^nS㫶L t{ /Cy κ`%Okߣ`Č ma՚DbXEⰅQcLQ %q `u}3j G.a+)x-:K^ T6 65U\`cA {w >c;mZZz5]V JPknL7M#qO>9`krFfeT7""}bk@IF 3cr-P{qxJzGSX voT?6Fv܋Q{ul8s悚QD7U֢/)]تY+ah|+XSXHws(Mmk!K*QJ~2EL9iD'#ñ:CRs%x 9\u֎"fGhZi F\/m9l!S, 2kunh/ݐp]ueA:ؒ*'49wXR4k:GCtðz!I-w/'y%jk5#n/9lfyVIi(r5=5>. _+Xo]b<W]g g%ˬ;Ma ~.$)Z"IkmsLF|,Lu$+I AʙiA–^3S9&?z8Sqe'R!2bmNrl5T}~E {ҙUBD".zdTf0a*Uu4'J%L[p @[Fev}A,)X,{r 8(ˍ`*#UG+L3|5=*#X:i+cP, ԯ>%!u# ՠwb;Bqk5Rt_"[r? H|M鲗!NmxRR!\(Ɩ֋fk竌@LnGN埜ps4`5y#ȱtU෉<,zU- Qw0H-Ǯk"ޞԳ@*yP,] R܁ź߶UYUN֢l7%j9uء9:RoоL,0Jx`dSk7* Ydĵtc~uVFlO7+2"ƭ8Nj,_5G7,cM.e˾ɐf wC 7U;r ={]Rr"O$TUKZiadځ%jg`H} S$)\]F\09bHvZuD:@iŪn?T^ z__֤Tr^!,t`ʔrv467|C ¬r}|< M50^ĪBTd:m"R-3Ǥ,X_ <$"ss Vdakhv榄*Q {L}i 8{x"58$D;hE_@cC7 i}#E=} O68U+XY~](6y){'ӗ v 50._)(MׇSL)7p;1i&ˈxTg+b rެFͯb඿# i#yG.=| u07c?z>r_l[fYS:py"CdFi}zd{&=0_]<9j!A0_CpNe#N,0@RhZ%`nUX:j!gnOWMON_9V7B uGSe HAlaGl󫇾댂LݭOu1:Z'-v='"Joie%qw$ >W2ڸk@  n%&~cıF6'9,$Lt@LFoąT8sI@5ح`z07w}^Lw_$(wq44%zƜuH*ɑOձqdX%~r38 'vrzueEZhttNa-gz?'WԒ4ف\\2rږ ]Q6mv(CG"w;wj"-gԦe/l[D|s30V36"QTÍ͸j'n'yp.3@KT [tKДwnqz3z87.w/%,@#E e4EkAs+m X(%&W=EV?"h?- cٛj.h-a):wT2 ۰3Us#[%إDנ 4S]c8}ӌ^V$[\Bc%@EyѤ[8jʥh: $J`k"`Y`D ,Ox,T_7믻 2:Fu&Re:8"orW(6B+$ Ccˡm2nF1˹eY;][EܪO'! F&j+I PZ_A߅kwcno!xtkSdXFOA/ Dt6ܓܭ?$|_45ۊr:6JRf[ ̴N3@.,|eam&9l;mQAvoX Yʊ, v}Kfkv{*UKsTK,W -:-q` ԊXdib]',z4i̫kU7Wa-UEEul!qOܖؓѓVOY5$^\-@j-QM1GTk{ߎl ް⌙QEy߳HNشfK1o8:Ro,;(}juL#`%MDAUxRSmss1P`~yF}v^j | {EIX\־W PN߅wv: F-!O5cq #l,gn(1OzF`+f4@KP98Iz9Gn/sNi n9H#۲rTgFtZ7zû=2|< rb_ Aa+/A& ·qFjlNك|?t@m(0DhE߭D6d*짎;%zEXX<ﲖˈn$ǸN?z.<~2F1*4OrtPኙf oZ8 $G"!foL/OyUW\-ؑTڈ`7]M X|WdRt *~=cZxEeNTqSKQS[Ղ7BYXBf;Z0lЪ|r7%+^'I3!KSK=Ry8W꒬=R܀6\Uq5uoeb.If:)t:? ?24U3Gc&?"Jٞ8]||JE>݇>nA\[<$[]SO;,7@{kT9!Xi"s{D/JLѨh8o֎@+?$\F'թ;viJt&łrv&ƽ)UZ]WͨGvAw`]+G%@EEYyV?ulVLc-r~YMe*IXȧ6ޓףX -mmd% HJb=m.jt\J~:gQoٜl34g JV\/BIB8|I=͚6j)]e5@Bl$(6 x.Yܵtp5~Tms#XŚ%|9'+D61ȐT / 4,U"[񘐨dĕR4 l DE< qh k0gf(W{L}0CHN;5lS(V:5s7& =m.=Jϰ!xⶑ cǺFQV/%Wx7Ke GYHwSnR f);9ܻNU սvPܹȑx#D@x SH @H4:Jce '0TMt{#%& [,bf#+M#0-ArG!}HSs۽zڱe'dpI ":|SL_!Mϴэ áGʞ1c뗼'g=ֺ6P9nQ)(KC @: ˿=o@y$7ή]*xeeE4G6Igڇ4h ja6HxK>+*E7gE ڽ L͸Qr Dkt@?UpUgvg+*$y)ỰG[|El_愓NH0k ^˅*KdyR`C-[ s^ Lg1zE^gQyjm3G. y7M /QkъWg|B/nZH(>5:2N( ,/\0 BF!-g/NT?(}hHDfGP(rkd1p 7%RtOHFfFɛ*)]g@2[V-}ٌx~.ToxR2ʍqGEЭVk =d-mbz_ч_8]aׇz|~j^ƝeZKpM3n{oJEeK0 ޔEq4!>=K[Vx]GzMH ?2"e)z#;D0wՖ-5K)Ӭ3s[er}9^ F@KCX] kGV* ͣ;wuΝ #pg/!vF->_P׫+_Z=9')ku*w;LNF>G. >Vj B&ܟ黩U*h%o CcC ͸Ilܖ\~fKi=UwuKc-U= !sßyYQR }!GU4aEc OĻ1!a2e~ܢxbz͛rZH,Ւ wn(u|X{~"G'ɸKoσw89°*:3(/* Gk [, øgES`z F?J {H WZK 4Z22aPMk*nnD{4lS*k/p7& o( w~^k&3}Nr;8 q%)L16;%^li C~7K@9?.sicw+ptgM-#qDc]TOk3|?1*MF4mЍ,^Qsɓk.հnpqp#5XYY!&=?S{؆&ߵ 9 7#ֈPFj,fvTA!7,|FX}X;S޺[,1EJg i[ A[D`$CX5p?r@.fl6UjZGx1ܒӆ+@+ɱ"9\S!"G4D5fNhߴV>kĜmԀA&N=_bn rge)l9ՠtՎ"ڽ4FpXj TF 04EVvdABUM KT#+N`.(Su"{W‚n¢m*zf*c~X0Q6Sn,k3R27DPOMiB&SG[^3bs{}b2x@ޑ\glXZ<ȓ1M41c23/-4BH,Wp=m|.iVդKW魖C51gys8D{ y|3JͶ tErg):+%H'K0p+*8;@e` GLWSü[pyf\47xVЭf{T'z~\Ji #n`S')B>C\~ʴ͗bPNl E;F4c@>ާ0ƬB2Eqt!֢h;'qo$xT4\fao5(ifB' 'n7wYtsk&X#3@)v5'Wi>ΪͷWjq.tmZ(LO=*WЍQF$31f= w)b^9^LݱDdo[hba:#)it6N L[elhWGD8%jۗ(%=DZ#sH9ʠY#0DJ@tGBSY 1So-۝V`BKs T6T`P+jD~u9dXK|r|Fn8[(_jL: `WPtNY1jU?E4۳\DHOת{TDdhaD¬s+E-KG6ϖ'T<5t&||9f-f6Ӄ@zZ A͵lhCRCXpU}D5`&U |R*!} z3 =.knKS*xssb(&; ޴᫬Zlwa+O.%tu(whrTo| Czp2Vacun:Jp2 w R_t& Eis1AM4jpY D9 Jkb^)W7DY]?zYӨHJҝ՛(=&J*9M?O9e 崭laN~-FǒMo $@\;<O[ms6T Ơ:@DFS Эնϰj!?Q(4@1f*Si{KgG!'KBclo>|yTc-2x\8[z+Ug2ًl]<fw {K;e7VP`W7s\y%)+!;!`ZoYzmnd@($Y%Σ5|WIp Jd8e]7(&Xw`K% v.#\rq-jxE}xPE"'1S!qS Jսbts ɼɔW<:tљX$\{>W_u&F)1.f2eervg9 5zw*8GG1V]?9"M7xcO@+>]>, AHҼ}C~CQҩW zhgc-r12hґdAW ]6㎱ {d2zE~zezH#]؂鈪tNcIr!s*Xűpp1͔DLar="?yV8vRoa=U6>yd[(L4@4f?!DF3=íwa7}?ހB䀣IuYGsOHS|BW*dp}ncn<[Oy.M%zX.SL5;$zn-áO]?#1|KB&AOZ:_䘫mhkUy:̔9eNiMS VoɦftUO ƅG^~NO{uҬ.(mp=Ru}b3Mv>QЀP sC}vq)oXF%ojjNP7I̎wTkɗĦrCXz >Nc&r(;4њ;oV#e(C@;=#e5gY"ʃSj bPzӶ`H)!c SmpJkuK.9Yn*hz:\WOɉƾEP遦[Slr-"bE\Y^-\ !8=/; t8oFDYxxnL5>Y* ʁ+tc\ V6jê<7 &6V}65Od{~rOŨ- :|MkbQIe` 5bC:]dENZ\FvF2G%ȕ$y^ %^p~^t3~ +D`V$ѫxGT.3^f>M2B;|V*ԑm`15+v0iҋp:Ay :CMoqiNQl#5}X¬C%I5:Քh\02rL-g#<1B @5Ӿ9O+Zrc\OKʎ\B]u |V*w+ZcSe;avu"zuM>ݠ;M1)l[<-4}j>*NI2\UJ)P(vt,8^˟!]g0DvsCweTQ Twd_JjRS]078k3fAΓAǢ.M1ɨ 'qc+ڴv-j40‘,k#zG6V;ӱ*i|d> FCoʼJ|!f7fW}fAk.OOBUO%eaĸoja3ucwUYoSv`){ qυ@?rR뽅&8r\wMf_©Np@~59nuЌ6K}8+@WE=/jWF^X[r5Li?EP5fo$\UyVg\Ǽ d=xSCM-;#Y ]ޚwKXE`'I &9kIUDM 6Zjh氇lзrbI ctzg+8??]h, @;2; `!ha ;ui~:3;$Iz:P~mV{]4P!AJu}49lqpr K {扃 D (z쿸xMY&>~.qg=[zV0ܯM@ hS&UP'C'r-cq7^3\%[<8,!y5uM݇n&Ch{z/X>t"EyO~UU)p9 -]]')2XT3 U< mX6ӳ!/`ڶ{c4 v^!}NqS6ZVPLǴ'0FkB:ƹ)P$bP8mHO[Q*gsÒYZo_<h.ak[= T}=2Jlc6̪7`J/DZa*VrVSG?{YK^B ƅy.ՑvWv3%)0}#i֐1ԣ[/`zPo5vZKE(xŽ՘Z+8Br\g80?*G:󊑁<#k"Û% f/>(,0t! #m(-=]ʸKt YUJ?/Ψjux ZbbX\^=bX0$ I6fHhn%8 /<-"E(x1K !7N#dKy!us" ݩü^k:/4@4b(4>,ݞ-]3ao@Nmif#bݢ*Ms@fL\]A#MvmVVKG>"^dD,ժ_DB+sJ|Y#}`~@GAaQz ;JXy~?V}%U;)LT~ŕw)n lZ;fY.nyxaA9\7!2r.<!0l -|| eR^9 2P;\1+$)~3s0>`;tQh'Lvq$櫫9&N9Bq8KWP|/Gq| Y%~G1|Ԝ՞x (8O4_J|g|/9Ŕd  WxšB~4X6)Qyff8ƙ/?ܱ54V_jTgq?kZ q/GLVw1Qq0 @/njD;k 1=7zdd&8V3a&hRvd)=Y;&Y\2'hs+Rn΋eFbj]ٻUD79iC {A:b^Aډy}m5?~Ti섵 O촴xҙhԽ*ֈVlBaE`2ɢL 6;o@% 4V )'XUj^vصa&)ZhWs -ge8| l>o,yogD/[o}y9<>-869jĜLj؇C.hAB$1G؅:#jߒr~%kaHUCTV$vytkRzA A/&9Fo.>tǪ*l%RJ )-=ET^}VIUnń:~[3qBENHt9yd,z=%" S{ZF;P?KU#aU??<)R.} 6"hy7`-eq6B 8 i9Ca^hMhIG _88= %+nV6BK/ n7JueH}cp)w&/t!c)$0'›`ehpKGq7 shʝvL! @Nq]#4 ]9snjAL=|m^%L ,S:*xWovʠ@)h!؀#܍zbvU9BKը{烨7,E7[ǠiżY04 L2O㸰r.2S{.U,.8 "GhD6 3I֛ϕuokd9p^Pavft][6FH |"c:B˿U1u[Dy}b5IO$7_o4$11R\7|i1XjQD&dp; }?8\! j JXWfO#"cg "1*5 ]7CcNU\ÖJ֎шz$v}qB E {9.ֺ<|mLa.E5 4ŐEFE &eAO}5#tvbwV |ב]βV K ԭ WUb`:OB.%7;" MNOE-7Wؔm&ۉ0SP;&̟e8QlnmkК?z9tJĻ-?:!0DʯD|sl2a8u{6Od^ @Ӓ8A3N|LtUL{Izl`uy0%hVCWgI82Ð,MAG&Gw[XJI P/([#QI:aW{`OrC9?ސ9;Œ*\Q '- n! m0X#u8 vꬌa.ꤐ ̏|i΀K0-z/lܰTƖ6*lY:M~reHُ*(emdȋ%!9+2'sÝ.گJ U>_{eGn4?`,uz(d^/so46pQGNPeWC4? !,5zȷĞ^9LhІ41&_|nVGܞ!\jH8۫ E~ӹMy/WID9yk> mzwPnc AHK`w)1f*U) #SUǮ^Z#P,;hRpQPV܂-G gٞk9Y6Mʪ@w>BT1͉N}J%D\[]}y̗! )SmanG`̸o2dI@oX۾ϣ!l}x~%9%5 bP3*3 %[5m#y#v%VL:;HLjD xPЉ4L,EA;%8]EHDcIn4@#`%XXb>} j r8եUjODuǕ:[wyǕ-h=ľkE=JV|9s(e>㘻: ȐN=HFeVl*PP?yp H2xS*WHv%]u#yd{NTMϜO_.}нx$'_M+Q>N/D!7nwp ):jG4^;$~h"* Z/]X* &TߴN$Ҙ=pjSC.5Oe:"Lb/WXz[fWa% vNך|"?վJau} 9|.Օ28w 6!E RTt~3uTK]. I̓WpANH ҵ2 z Xm| gΜTB*la~a꓇[ (Q{ث]{5ES Ox/yaħš@-7fˋY(TF{q-xVGafۥRM:ג򠌚R>;-wuwFV0DnH&#U"v!GnқzPFMq6``=+`ܣ[%RUÌ0@sW p>bm+eoPu6nom(X`U`Ͼdb?ً3ԼVBnЇ`{Ë9xa&POh/" \8U.h`uPsιujkܿl6jĭc8zp&y}yWo(-,xi t&XIվ0NAZ'E KѪM@P#i[1]D(OXĮ@42vNQyG{ 4ۘ <ԼOMD%/UMnFVw%U N' w~vPmcYDw}>>&lĎuzi-qEu'K."e䶀Mi>;FChƞcNZCl}_2xS<.st!G-* \4Z&x O/3DwwkC u0jf mc' e8)IJIڛ*Ka'z+Q0#5HhRbaIS H'Ug2@FLap +<8rLG$kpGsbrYdDZ-E(.ճ@lX:R%¨HV-`>s/,=_g"}e2vr/?7:F+eNġ؎w\0drbt6fhZm6K`M!hQïxTiD"ls=k:{^OxZDRb㻿-b.'CpٟZp )CLZ௽8Hk 5^3ҒCH:-NUIwoaG>%ٲGpafLQ!?K-$fܷ?H)2+QF5,]EI:Eo5hrzeL>wHe>ͺU(RDwUG&h2m-aQOo* |dfc/"- <'&@1Ki'=-B>%b^%[%ߊ)Mܢߓ\iI̙ .fTֱfrsvTw=*}B-I*?;/}xE'KXn*l?{1`v.+vm'Ơ80Kߋ%M\XMUA]ԏe\Q%D"I>4ˋU\J հn~e `6tڐt˷abܭb3֢esP3EW&v[ W\5k\@ uf"ۚJ$NCމ66 +zXZl[鲪-Q p޾һVžбr:Iڌ,'r#SaMCxwo~8Cuh}PeM6u&)D?UԈ/Q}h0u bMǧ_烄ەȶFM (u]y!!M.ImOv^_x%=t 3qZP+7y`ɰP> mJc+?j1>qwY]0Vք^+ #'ʙ;[KtN}~@Gd 1b [9tG 욝6DyL̚KT1k#Zv5> qs fpj!Yw3[*iR45a|?pB$pg|н]sj.CACs::y "qrE e~0YI`1ٛܝ9j~_{Pע2150KY`9u13Y38yk3{bw =Z8AJ5elK&{=h|OG%Mi3 F437+Ҡ7Yz$4eߝ!-g1ЁQW./9oɗ|4tH _ EE^|@yZJŭg{ȷT'g|S1 sLNi b&swNOه~9q#ZP~(G !-NM-:KZpScfY\ٸ,+0t#E2\R'ےۘvY[%CszQyDVж!ogXPW'ɰv4XmuHf.B4ZF/vic?T4x{F͓ ^upӅ .f9,`5i``:'gW7a yBt [&=npSlʃJ&U, ~LJ-ܘ6 JoaID<|>Zԋ' ^H*_&GXnMlpd#*o$##x)Xj !ᙢ{f3__M5WSNN CXSL#Md_bQd_:+]`PF~å>BpGXִnZ.N dGK:a! (}D,,CC)]#AC3.'dpGX,N!aչ-1ʍhB ?>džƱ^!Ոqw۽syxF6|{Q<oqZqGJLB^)I;<@(ڠ쐃?8F:CLu*7}m|tdC2)3f#v] Mq1 7bt벡L)aE r֪;6#{WMnaf>ԊJ8lrROKAֽE"'j%BA9qm EJwÍ]OF"WpvNM%co?J:C>+piZJF[}9a<_Mp?wOJ9!!="&^hOz6w!Ri_:g{TprG_51}x+ r#&MVN8L n:PK F [1^pU]1gai#&ULulzQB6߫RרiH#+ g2T#?CIeA #B?k B&b%є(D2 IVTܧK ր(Su b6&+rY!]w sw(q} 邱6ckjy q`2Ӧ"Oz)1 ߍWX.aoC(;ȡHPP=,f_ !K44G٠9vguΨE}CJ^EU:ȟ=9:ޙ#dlr(nYv_ၫK0/ezފy4g# |"9Klߌ#/leI@2 ɧPT "I{9MeZd,DW"6'd"xtcO[*09p򳀍uLĽJ,;NZCA"#YU9oF:RT?Z>ʸod-*4mkZElT M+ﱓVXZ?ju{sJ%i Ò_W2\:NKT# 2ngdB3"K]L^N=B 7f(h'c|缬MMϐc9 jArCE{%}kDˑ_9% Lgj}a@C[+ӡ,%U!4mcnD 8I;qy~햭MƏG8)CVuʇϞ@;X*TUBUrILzԘgFKP',MFj!fM=x~tA8JŇ1h'B>s)07 q<-NRpmi=ntnW5]CC7chSlvWv*7, A 0F ~bQr=x;b ,0Q"hL[D>0a?VdbP둜V&+u؍ɹ PrESxi(,KE@ThC*]W}Tk4GgUSnrBO,)*~]lYMZ3w)`=e"]k~o?wf[Rv:a̡FI]K|zX,}n)9 .iX͊hvh=f`P~!=fڔ=f'=RhW+^ ߦбf&B렓4[t05s}m^uG7.8i>pKxtR2Z?\_ƨ S-,mRWZ`91Ausϟ"0+,;u|K@86.!RwʤvCRǹIRQ %#:y h=|Em8031n[+ SZ s*\qߒ=aB]1weP Hf`q>RlǨaHM5 Ih#-+2 t9^k|sԄ0 AEZ KTTa9 1 Tbv{x5x G9n!h^SBڜVyxpzyB@J1]!繪CRRkFG ׮dPSB6崃KL0?)P_xF ѹB@Ue {3XqQ/H~Q_rpzd@ SIDgq\nٞQt}#w3qWV'5ta it tw(~FK[ s֘ze::  T*c汵 ۺSb}`‹*r/MH2ly+Ѵ~ ѮA>*+|f"DUWm]i?Y2W [>DVy9s[ uO5Pba-grM0TW3AX E-B,6c|a"7g| fkk(27 PDM&3XBPT )X~.\^fҎVՑ9{"#re5+$^<|TeC6jzrAf[9~<^ъ)Uu`nw/](nE9PdJwYxuBKצ/cGơc㸞"4ȸV6x\m]aX"Kn; pa˻[:l<)oo\ &R7Vs5\B4FpXwr|<0lֈ'ڕN$>Q;l./d 'W}z =鋀\um6\|?%ySeJP"8nN/:Ic,9OM6C3CTj)${J!ܬ/~ͨIFAw"@#2LDPLSh4;0U/K[2ūmiQZ{t V*}E2c׭S%>YGN7T:`t@hÄcu T2Oz q> [4c,(kЖ" m}__CTT s%ia@\6`}H!rs:!Р(r!M covEr֨^q= ܐ?Dnre }c(}3S(h ʙBML Lf6..)WE_7)L04 UԓVX% ׏K)`:Entљ2ƐT'5B-1-gnJړ6ҷCÉl(9i^2w,һ5:0_q7p[K:Ќ\XEj\ N ,0ԖC.ͭlڋ(n.8C^ؐo>nfa9[e 빋$F4Oacg~_EeoR3q۽ dPu=Y.ᜎ+P7$&&oy^.|o-}L:l),LL)_o^Ⱥ4ՊJ I„YgrLFgXVn{G߄?ns3_umcǶV-U&0Vdð;w[$x%itrL.`u$5$gDz]fT5!&lPmsFBuMp opJu͹|Nj)?,l~qeCq5[f,$ qӡd?i+aTG`ȍr~S# } ܂>K˝ ո /kBz C٪Wj%+2E댓LX<IeaQQeRaye^\Su|'!xw/ Z!<k(q ]ƿI+٧EU9ūؘP\]9SA$2] !jQ oƻ ~lȂB5B=MjF񘵑|(58߄\v*wMC~4ET՞bM;»ت_5Dbu>G=#Z"=>xe9(uI4+rj)Yoo)ܖX@YYOCD 5bfLI1{/t2vD䨒Z;P =o\=]+fK6% ]:F| >5 u3"DH&y9T-kȆq_!lQ(-h19}utF6uG@@+dPm`$ ')FL /"~4ީ%r>"Ռ[a-Uk( Իl?~!wU/ Uƽz)#$@O%X W#@a>.~ QPyo.W\Wqs9N~xSӻKo)`Gy\QNӟMQOYQ4IЛ/2|w~in'" Fq[F>* P:*]~mD6͎[mungɤADOuhEMᱵ$e YO[;X[9;xvB);TMx`kBiS1H~g&Mh+ysh3hZzo`\Ha(.'!*]ԻNUaXwSx U.볊(=Urap*r<%{7'%& hPR,c凛sA_hEGQK.O待b #eLA}lUIgA E&8@~+b~Zo~|U81j)57 6%"~1##́xI7>g K+-_,DEeelnGJ9(i~qٛDA$D}6 d8areQc29'u@+0lMxQF뱥nԖP_)|[=y}_<ʱa~.xlQu8n,)bRzV~m^? ʞ2/$ dz7Cx ۯd[$`$4>JkK~FڰGܵ|7F%2&0"DԈi$6Vo"Ey>TL'7Ռӄ cSv wwTr PD&kk"߱rЗoߴ̑0N%CCXFJz &͸3Q9 ^$v+y񂐉G/(5?XCecjD10(x*E5mD'&yY3xɰKXAG #(Eٖ'i3mzԁ+b7 3bV/s|OJ?Pۅ< _G}l~4^Ip<g7׵]`Nus DuNQfd:$&<|];d_7 LSH5rV4>TupT%ZZ.\"SNf܏ilFGR$J~Q%2/qpT(仜.@aF*(Y =ZFdgGW++Aq3r۝?c>KwU))dN]vSuNwK0 !;Ӑ)F'4εzqRgqR3ݑM??1\D&`4P@ g>6  :tHa&Ňcij{FtjJ/7y2㽺u1&a;B>C ;$^T3wMdwI=?n\[{5T +f߿I|j-wpaIbHk% dYs"0}iY][/0Pj$m`Oxw/44\Xg\[=[ uá{5@ ؘsAPPjqC'k:eX!m}56"3YSƻQkIozb\heQwzf|jd/^+ 9c/{ jbtѯ\uYm}h={l$+"]݂H$L'ßNFerOV ۴;7#"|&W$XZSO=,">JFHD웢3*Ƙ%n7'w٫I6 x]\q'g[^Q:~#UqҾr颿͸ldNH{ȶ {7܆ϬhIp'%iDg@ L2@M(HyoSڐ"(r+<W?ൠQ 'F,;!2ezl@G[yTb'%, ./%C{J :Kɟ۸GE{Zذ' /zM@%ޙ'JYG:G2qA6.c/2n;zO*xlpfI/+B1\[CxF9ELX:I90 |֙JJq9rcVSPP헞lۃv6ƐTêhu,w;k DCUrƜyQ9l.-V' ʘfJGЂX$؄鞋sL5qǹvh/.HU8|% @-6rZ3Ts2B&&Le'o±fFcg3j9rI:K5ͼq~mF#*c[TS6+ HN?SҴ?Vfx\½܆x1FesVsSmdy&Ы(q_oʍЉY; A^W8J: Qp73QFZmF2N됓<&b5':]3EEvܧ(FI"jLJ4̦B\5rBH:06BW6m=7rqN_Z"#I pf)'@8*(SͲ[{l_} e^34#l<wNPN^DR3v{.L3`+1 Ez“mО+Jt \_4i8!"BĤP˗~Qe{ d[X {Z ٞ$_"ۂt7i sf9-=Z tlCo*k]wQ5eLārAb|I`kU VsyR^JEMO% 6#toޕ>/8&+t^>'HnK%LLWyjnV>'4i>rh_/0&BTCu` Cu(A5z}+&L 1ҨxETZ~֢rC0?Y<zEK*rH.)ڝW[NB֠ J54@Ytm60S;'}OEOױ )<[>>#\ڡ9пZ(|ruFkD6/чjХ#jdYѡ|)7gZ8{=ӷ c6?|Ux~qkRQ1^I |ub&#pfOdK)vAN7[i*4 :2AlS"%N 4kvRi 9na+/-x(l6MXYyʻXbʫwz'[ʥċO ҍƘs L9*xgU<WZjEN}m[CjYO,W,<F ξ5zbs"OGI+ 9Pѧ|zs}K`&rQ3h[^ 8O >D&ѲK{i;Qj~gtNjL#5u>L`Z'WcQ %ӛݝ˽G 8xgL|9`] ֦].}XӂNm^m_LZKA| a3HŃl ӲŒ_'Ơ"ƐAc*̋zXgh&yHx {Fp;Fz6L-bǥ5Ҥ8xāQB2M;ON ׆Ɨwk^<'+sʃ0P] ӀCȗȯ[*1pMA岂86eb|G6'uGy}3&LESy 5l2mqR*bG+VG!jnߣM)`|~[yD$݇6=h^9h&L@/+S ʌg򛓠RrVF}o}yْ;D$l+_& }[q9otWW]>vXJI}~1:^meP"> 1$Z{(pJ7y!./&t6r&2޷4=b hԱcϮB? CeHw]B7*Hj(57:I"4HkBʱMI  -3vffIdMAoQF)CfM4%0|G&eb.pZL>T(0X4a=o<Rr2xITue)`Ěɦ~i8W>_qXKcI`ymZn{E:)=|Ẃ]/GkQ|k 2,&LS}3θqClO!m<ҧƹEH6c=IHnI)/E&zEe3%eѧ ʝ '[tmQ4Eu`L~Nպ|O@Mk주Z~_&nYt(E3kݕҁQ?=:DldaWW9jBSl$J[ȍvfЭV< W_: HxH&qd}y҂s!&' $e;xD QaAT6otս\1/`/=J4lpĉo@(F5U;s>L$Ph 3ľ O'˻i.d!I  WD nEhpד~B ^<}3aժ+0K ELӟ&|[nXl[:ZZ[x̉;eUŸh/`<,Fk.\8ʗ>/˜BF(7.1׻a&53b1$6i!A"4y${E|^i!awhwo]ZN.ұkk␽0ay 9*XMZ8^Ǫmq?Ep7\')SlӅ/x8 Czѝ!,%CeoxQ̛yXnHrfk,Lt^Zݱ-|ѽG(-*+ŦT4#&e ,uP .Y0Djn䯂 l.*l0hkH ]09h&"POKO.E &1>ih=(pH&'/m'eA@t Ь}j$x\!hwXA`]y"LL56N> e:1ٟ| =̽<P:GXA(.?ΪG/Y-b/ȟNǘVC֬U|ZYńo<9i8o\!ʏљv_c2 /ωfcMQcm-Q*w|My]?N$TwsɆmc*E7Yσ:!qˡ;&@= [#X:;&HU~ XKcBu?71&[26NR^ֆJ^|ΔA%mWB_֌!ꏧ6V5i0mCA\G|r)=?@G5O$a8[L3Q6lԝ uP 8*V=D#S.kҦ::v䎑&RB!I!p| Sx'| ?f{1fx1a/KTWȜ: Uз+w\qHjD 8M.6qkCPrS=8uU~ڑghkDNQ“:Ҷ*:ќIvOʼО0`rՁ[rH׎tn/)Jp2\tm,LsZ֮RBw.)G~}\4iؙЦLn#7ޭ({eh(ORW+ UV &8v_pʀOUQ/CH1B2IS㰕$l)|}Ϗ]67Aĝ+<82ը`~t٬7G`R|w\3"o1D<ӻT Pku=skV0l(#h#(]8,?gS[ _؇|l|Ag6XЦ_9vpw,ޛt8manc~@‘(i!/f=7-Qn8 P}Jc4-[/p Vc0rG+CƏpn8ffLa*#Kf^A/X!eñzhxv}/g kKiIC$`-l4ձGw$%ry7KwRbl.AgϸKȎ*;XoeT-ot>]hY9X*\L;&1=0:]iJU_F`n]8ZJe>@=I_Ne[-a nrGU{Oco"يpm%m0*N]տzuK~`|o~!DMhu&,rG{waĮƨ\UlNAd3 L3#^-qb>|P G;ž3YAg {XΡȵOZs O~}iyh l 0]GXM({" YzbپTBG呃 s}'M`<Gg6+S Vr `?2ה=/] iN&۹ ?;t95ρ_ ̻[uX Ne uo0)dw[RmL$,# ޼lH:QCJ׀fٝ +j (tZ}wo"˔To]hk+¨iF0@E=fr^Vr\zqtO>} i"[~hQ@=U XvF`ou0΋>gukWjShU)WK0A`W,A.@o k@r22Y$[9%Cx?Lc+H:3t?Ts##"xW%:?0dR(ug5<b Q5u ak~Ie7B2T;K,N) B`~[ݫ->5:z `I,-5 ٳ/)crH]^Hm`⯬ H(,U%% @$&){:;ő'd!?y+ 綢y͊jd/F}8e1*A}FLLc^tiN/:UsΗw׳f@ishX=9?abJ#+$fn2$HTT KGٌ(tjsI8@ON,M>aN댐X-ĵhHBkR@;#JA%%L3dlo'6',ð4LKjm& _ר:$"sYD]eTX͘)úBdgtaBȅIQo  ^Uȥ&R|j[Īkj7ApAwR  dIb!%պ3Yu}ܓg,t}ZE^*|:YػbR(e \[ȼ'KӱyBmKV$'O!,˧w<ưy莂3Q([&ssHzNǃ#SyGVW+xx{jP7)u_~^}z^N,,+CxvoƳm^)3miAM0\Z^uuW>`rr|ի+;RgiĐ]:V^quu)nH8i`_ʵi`k~w DLN\>}a]PDՏ, kI"$jIFBTK1u?ĐPU1sP1m5MA_{Τdk]sF#jxi.\&nZ rs0߿v5nva}֑>=_i#v6/҅TtB6Hƿg!ytUL0'q0+ 6E-7l{[UM֪%43jǗ ^(UE^)U/'n 4ןMC&CAM p؝Bٕ=B:J؂(O'2Jኯb\MH{9'yIo# 6!9Mi!α*, :H+)l}٨'"~y̎#Lyj#!MP -O=cg); Dm HL>T$;hbL$,9&7H1ۏo!R Ϩh{1aDtT >iۢ3,!5lꦪW6p(#'Q?^T$i_wGa M?o&YX0r }^A{sIm&i(SZ}dM{4㦇ߏ-גEA1H? L=ƛeUfҩV ,&Z%Jhls/ji菸*RM'jƱm-X&gIpPh~'#?S剞˙ٳ|koU6TVǵ:wrۅYDZl \0Ծ/ۖȑ|WC%Yx3/*ZFAda]CmEӎ<  FZ6R8L,)6",e!1Rm2G :bu&cilT\L5Iiƞq`:rfDoJ$i/>zjAI4%/|3ad;[_ #G[5&p.%:hWN+3پ%h@3 M4R$r[4"|C2,#Ǵa6S=F<5Y1].Ug6KUET|mDEj@( qZ.cwz"9KP+ {:wP'lKPDQKZ+]cNQ3F*n >ǣV]%GmdUQ*sou[Nhps/ܐSh2ό It@#@nRXR%9>险+Ўƾ̳, 8DU7p F"m/X =pntwD$WkRiq6}mޘet:gMՌGOum|͇7k9B#_dM)݊ҚzQ1P0۶U9oZ[d 9 #\d~+d8 .E3K}O XoI(X!)\QGtƂs֠W7%,(.3iY܅Ccw_lEq3^lV0[Q˛ɖ~#UH/ &0H]1β%5ٚ498-QRm;ԉ qF"/zmj:,ĤMJ߀cFm2qlFu 4brRz^͟^.%bH>