pki-ca-10.5.18-21.el7_9>t  DH`pblb$ƨ@0pjl4FzLm:!Ni]PGQ4Dnv<~2̏Յ "`~ir"?_T>^%-za{㎙e0o>0Dݩ$SthAV@:!]f%?&t ``+krڹ`ꆛpH!ʍ8փp(+ A.A8(vb/-TCbGmԋH/)JPnۡDV[]L Jf$)6>$hco2cZ娨5x}>lo eViN588V ГPI ə/T>3m USkqmKIZa/Ry~Ʊ@7;[æa; i-є!w=}.:񮒾_} (:37e69b90476be28d86ddc28ad25aa5b4a7973410blb$ƨoo{Cr@Y4N./y6ZL O(˱ +%%;*y &rymbKϳ QP&F ܫafx'N/4U2VbK߭ 0{f!~[dЪ`[k@PIqwyj._̔Ů|i7'a5"_xJ{ey0q#쓄O'䚍yy_e{iC&M \%6Ѹ`C4d4кmc=2ZbSaGvhJ_L6/ë@T)5~׮eFA2<#Q@*AB[퉮jkn7MǼ! (=ODt/A1:r{?IC= 9)>;=G@?rDژRw{bA>#|ә":XS |{09p\EvSADM`SrXn,}&T>7?d   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P9:¿GiHHiIiXXY\\pi]i^bEdefltiu֤ivH w݌ix0iCpki-ca10.5.1821.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.bx86-02.bsys.centos.org%'CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEGl]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤b^2bbbbbb^2^2^2^2b ^2^2b b ^2^2^2^2^2^2^2^2^2^2^2^2b ^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2bb^2^2^2^2^2^2b ^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b b b ^2^2^2b ^2^2^2^2^2^2^2^2^2^2^2b b b ^2^2^2b ^2^2^2^2^2^2^2^2^2^2^2^2^2^2b ^2^2^2b^2bbb^2^2b^2^2^2bbbbbbbbb^2^2b^2b^2^2^2^2^2^2^2b^2^2b^2^2^2^2^2^2^2b^2^2^2^2^2^2b ^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b ^2^2^2^2^2b^2^2^2^2^2^2^2b^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b ^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2b^2^2^2^2b^2^2^2^2^2^2^2b ^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00eb272e2c1dc6aece61da715584e9c2542eb180b435954d8a0467c8e14151b0afe8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb643811c199c1d988747ba4d5689f9167fd42a8ed07039e28dbccc4b744f4cccd469e8f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-21.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-21.el7_93.0.4-14.6.0-14.0-15.2-14.11.3b@bf@a*@as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-21Dogtag Team 10.5.18-20Dogtag Team 10.5.18-19Dogtag Team 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 15): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - Bugzilla Bug #2082717 - SCEP manual approval failure (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 14): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 11): - ########################################################################## - Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu) - Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail in FIPS Mode (cfu) - Bugzilla Bug 2018608 - Invalid certificates with creation of subCA (pkispawn single step) [rhel-7.9.0.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-21.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(1jm)wZDQRS~ܑ#ɐÚ$flج jV:&Cm%9~rDS &`]$I `q\zʘr{5 A*ps ?w@8U~^c"Ě:3O"|g]T+%+P!~#RD,_4;f-psiwE[%7 Rr\=K5G]h"ʰS[KToolU} ,wb@/D ueeJ7cV@E,nz#zh>g4)LٹP\hh&P՟V!˯`CDidc!6H/- Rr*@Ӽ|gqsW&W#kM3Gv pQ6,Gޫz Ut?]΍YdKq)GG,X[JK\*] IR2bPI*U*RhkEwH,\ G aco]w cqsж.>+b#',v4RZF&C`}MJZQNya}2s)Wı xJAdim-*@o2e1۹G's ImB o :Sk}'RpרK3d {&ǔIbpŁDZuHXFSH+d$HݿVcsvOzBzT;aXx\,{ .,ۡ㩇!^WL4ZR(3f/ 9sH4e3l5czٛ۝B9f>Gף~<%s(D_0@k M5& L_a ʡ$h<}Y6mЙ]"bNuI"?vě+=J ' S,bEm6^K{lR! [M=$UH֢C#/"ayӮzXl&?'9wCL< ;<+z"!EG~Ә&pX2᫪GΔ0AO\y&qھ+zyeܼHhjtB?Òl˖eʅ[ (7)ZݕF,{s51 dEzd~8U"ƥ97 V _3ԙ n1n۔JH2r h_iX iA$i91U.9+/GTz{n4 |@I:c,dƝo$40p#O\AIc3V? Y*7zk.*hD7׭phsWSm8.zoq$JcSw l S'ʴ62W*D6}q7/洶Zfl0lNE~8-%W]RhP,'n6Ri嶨X(HaRNB"~xLI#l95Td%G uEM4)qr듙>=Lc'//I-]!snS_[QoQ:)9m{"Q %h cqKgC$BԦ*vSA`a^ۂYM̐W_ruo y _"G1ѯL!E) &&BM  z\,f4p71ɐ1o(픬c@Gt2;_ 쌤F/SrA98-> 4bd6Ԍd )b &Ò[c7"^cVF=h/hh@W3w(V0 ͿX@VM%]'k ѵ $.)2yϏ9yHF쩉PF593(AqܠK2۽ f1xAQ_pC0[M-;h egw¦;ft4ʨI&Fͣ~aU=@xUWyfnbcp5ĩmI J(`nďQߜu2槕m4ŕfii+#TPt-Q{V,)Ar y§=F N#뺗&y-tO]¹%Ϥ5AO]q82QKS A,5C^bf--4,^i Z1W`lѶ'\AS5ܝ9H{OSL3|bOfF`goF;Lcگ^Z7 4C<||tM\+YvxK |T|`KsfKL m9b)91ۥ % Ab}HKuؙgn6 DV~xjS'1|,̌ҸR|0V<`\M>zč n+JIE-hkْjÿCh6Q]H߲ s3I@ן2>h 8%)!Ǐf%ݼ>jr!p)a@f`0/B47zɚTw-Za| <`%-`Nυ3>L#W?_8FftgozTxJ}½(^z2`CDAÎan'΃il\x}W9N1g,=.=a⤂s ܙO=/paXX1zuU>XB\GIو&dI)Ҍ2wZ"59Ӷ3,!!=4/PL 7[!%tBYkF. wf.OJLdR]{.k^J%.FC?O묍eBG0 ,OUuMu[ &#DalޠqՒvPC$WΩ 哂y,r h)Z| WV8<ҡ&nQr0OL,~;z,RDr{[bd jc!/XPWkvx,YrGhߎ{sl 7xM*aG \N} C !Gj*.L9QR#'j]x#,g7ItQ8[% ;Λ!׈WM(R!vvÕ?6*H+{X[ E2SUJYo^uÉW_2֣HbҼ9,:m^vJ"y!BhdoU 4d\/eO9HX`3bP6_ۀMۅx /^_- ՂZ~!(|;-PETJVAs1tu .uٓD:3DX%" 03W\J飨+CdMXX}cE2E FmA(*`q8;nŽ| }Oo藂CyHI {lj1X~vbu/B=r>SFF+9POPo垦e ܽ>,)f0,do2C8VFL>&#UbuM78./ˍ),ذVQN03c$?wB?~QSlcVПKPe*.Zr2I&(,!rFy[}/ $fVDd Yĵ6OZ`z퐄jڳ"cvg!H&PD)O֊1nƠ<7Gj6S^*?u!21׉XNpZf.&D`& rCQ?K7j{nD?j [$ɤ-NvOiH\+< {2WnAJ?enZ&'Aek@$ukc{%lZ'BK waVQ^<EAyCFFʢW~_eO^%GR xu\=@@# uU!Xeij0M[M䰕Xv͑1,9{?DbF-fjtCȲ#:Y8,Oģ2kCFgZ`S (˿szKݻ&x'&=nk옰Glq0r6d ]m6}y/H0]¶a2A&R]HazO`3ldlxcbZEA&+@zPue`sHHU%͹E]wi_ԁ7xR^⦝c>J+'R'-V7rۻB`AԹ\p'B@*=߸x9)Cgq< Dԅ`F|։ٶJBTz|PNA1 #Hn CqxNRH VR 4m644SM.%B=Ftl!joLqP՝2мa€'ꈢO\'}=[X}w<ZXȴl*ˆw[o~X%lVtKo`7 "d7ԋf FjA#&=6~ktkB*, r;g[kũdTϑ (k 9M"/C$ǏAjSuQ1b0+O+{5]1ڼ檀}^KI WEIjDu2qk$58:{2ce9FE_ p0_0Tj=a\f3r PRʨ ?ZFV mb~kCˊ/%1clm cL)=H<[v-ն.-al GasAE6!TdK5@nIɠkC8Agb^u ,m륂$pGx\XoD!e>gH(iT}4)"ڻ1-TY`q@{j jaoYI43*'abvØ5w5])d\[v f!hUMXv6lW 6‡zВ⭮׭c}W"zLҼD曒hȇMZ0gEK 0FYY^q?:<|Tלt񺁒Aٳ[}p »0ji%0̷ʠ j_<+58DpE4ٴؽJMsh8t|ò֐׮b'-3[|뽳8;9?p~0?V4)*gHi*(y 3iD{R-\c ]UOߠ}sCY4HD]5 vQv!\0gl:M"+:TwsoqM9ؠ$o7ddr1BGL^]1yqY#f#ŭ)e ed9x1,$aО)(oTxx +LFW"v9O>95ÝbJmF~rY6Yu7[RFSmn.gR>E 6@"Jџzq䕉 ,:p!Q\NeB lgL 3J <3_gwUN2/8x3e (! 6l"+ _NC3;5uYdn0*aIܝe.b[&DxэƭG Dꊾ#ю47Ab+ 0&E3AG&$B(zրvlRJ=̵Ir[Z P9?fnQp`A}PhpZgz_;^=qKND+ހ~`WqRX;p) 2n9Z\ZO4pFW6v5X V!F˂'/Էō@O,{e Z]|0_?gK>V0𐊣GnXe n3TX 3/8[<>XtC]wU]aI=W&V6L|q6 PofD]['wkXM u8rX`ۨGahad2/0Z73 d+K~sUE;D.>-1]{g(ۑC[m@}5<Li_ g~[qCd9U;HZ|1nFW) 3oh.X) >[ 2pwiU)Mw|{7!ȕ+ukDtIOc0C2&*VVHS8FT; 簍b:5ΞgҩP qHYHywo'Xh啀Og]\Qcn~:B%ÆLׇ~B";1tƁD\Ayn(/Cay9Qʝ&X4ty9sdC # Xgo.5XEM⟀1*L8sj6LXS+# ,sm12ILM3] zpE9MgM|~f%(0Mo;D9|KPt?kw%O@ 4ܣ *l[[ 1dOhSe)()mj0ܝ \B9~l]ME.oѯ;(q M:W/]#F!Z6 YGnJBG0h`H3d:'C>aPm?e֕>33IfkD>Ey+J6оL_7 lʈs]܄RHuO3."UMAmy hM]I#n$s #v(5 )FԌ"Hh=7q Pu(HG`7/ a0w7llɮF 088(mjo1^hא$D1˞0baJ*)ƱWt8eGc~} W\U'[2;Bk_V+۪>f +\`s(chg`B񟓸KX>M: SI/\ BNn' ǔlq L!Pk>z2o5C9= 9jJHff&qL*?B(莦O ʙyGbzyXcdw.5-^]ezE.W5rsL/Pgx 磋p0&7;.@hɦ OQ<@ɍ)n7Us'm"&= ,]G.x ̂oCueR6 =y==% !;`iQJ|ee:sVgE#Ʃkr #MХ/VAU,zyC ,ev@VS|Wƶf̖vRg ;Â5D@]1K%}`Z>8O66Mc{+&:';Yn'5ȶ>{=L5_UNq$ KC-Q&3QiO+C([% pM:Kk@Gei,[J;$? +h!ڞx\,Yu%_0qB`(lLѵ8X$umNXi=Au ^hW"<{pv2^8 Pl\~_Ϗv;^[B-5,qCh`b'!S ֻ# km\ClMBT\ @?D#!۔wi]ˮ+n`W0&_y@ȶ:;pڅ͜L~GPJ&LƟ-XM{5BlADl5+/j|ܫkw7-~XbI|#]`[M`b˦fFpJ&k&"K"wUl(`+R$NѠ5c4 ۝]Kָwt&[~H&2yM [b4rF9]ڿ(0?J)B'DHc:u1- :HQq)˼W>=sLbȶzԭ 3,XTĥ,ldtbE%jE7B  iFr9֣Vm&.q)0O1zI2W͘&= #WD"5yq>'4|}8:B[K4~ܾ`žM]dži놓 ڜ <]_L0Q ?h9[lZjYը[B,]սJk)z]y6&hVƶ&lvx?P]_Зork̩^<bN׿|u>"iLjl+N&=/S܄edĮ6ZK.ȩ.u݋.z`ũKGHc7ʝka;Nn_S#]ƇPvƲӁ+17{tL,?8Ұh&u/ h;qӝ'㮾%#.z.iY &ykݷQPĹ@q2PJWC&f6( kOץ:jy,7Q4@qg>Me'Qkh\<'(}>[!!W+?ƽҾ0*TĖKk./ILm*dx{$+ ~tI&) 2/tR@}v<[<&wj&7YW塛Crs"0|YcMk),)tG=&e2ddwUMRSNHtt׊zW#-vh6[ ZSȩ.3›!|Yq *-ԓ]}X;"!FV {iil~ _ Km{فrtAq/ns#9$)‡u)+FwR(< Rub$9Լ0cN^HX!Ny*`:&q-29@I[!>L1mԝHx0x%r g?r km*GɻRJ-L8"U7n\Xk w3.`.?M sJmKd⭒^QoӚ:  sm9{3Ȗr5D2#5 ˰ n)U' p%kñ bd3w*I-!@!1]:x&|^v +Z7bB-M>W.mJɥچR7ε}ɘ؊%_PL<эH̻Z+DXd&ጣ Lш~ T2hMZ^0HhS:*=|f^ZdXf,8$Zڗ&P W\@h1|(&aY>o.wzHQ_12G'5⊕L7dlib@crDﰏq-0nM>`:s/ÿ́Z}ugtR'~B;Ϣ6҅"u<;Ťl&e:\V{_r_ gX˄$b'<[Nb*tXI%`z pG'y ypypSQ-+Эjx E=- :.l}eov8mEbg)1q\c~Ղk}zWi3-I!(JN'sۭb<ѱV` C\gVv|oyk,8zqvN!޾ۙmM_()ޥDtZS&ෆ.Nv"?^VK;{D{EPW`0}zh' b" @"OH1\x>Vƣ*90<# pO8G7O/qDV_XX?L.~)@b^TXus]6FtܰmE_$敲mLEwRe;aMRD:"m/Qȉj[?laFS*]>NI)5DG-DbFBdƢv59#kNiQm,iFj@nEs  UK-JaR#OnOLP\%Bʒ&֛}@Tv;AmDWgco@ i-)#) i}Iw3>qIMj' qJyz Vr+1AB}sa O`⍋cV'\jy%8OV|6JKv~ttũcWb@c$qrOf.p)3&ddv7&uF٥wԱ["Z 0j7 Wq2PJ[@?r^8kh:(iʢ {g]|[ft -j9]d:Lw:eRٕVuȍQȢJ䑏 )d,27J~&#?sfix?nQ9/ܭ5'ٲE@R= ԖByEo2!=(&λ @^Ȣ mkF}0Sx͏nz+e~ھS3u/C1Q-"clߨ۰C\XC` 0g9BK/bJ}gT&8񕪮bdВ%%u| :/!89xT$c_jk~ndj](z y)SjQچ8z&DpfCx`gR.*6ϻ2dOR&-"BRs7ˉIN7X,ދDdBUSaQTiYb~jDsݾc46c|rw =#&(2tQ+2+Ay8]TdY\q>:"P*9@igZ ,oC`Jо('+YbvOJh#aLgh eC%ҭ ]T]DKvKdm?+!PsYl= /~6W"m&(>;p8bIY{U NO<`,dy[4Bt%D8"a^ sʉBu #Z*# (8Jy)*dEbo0~NV.U 7*_)Txڍ|11zZxa͎n?[taQ@V&Qn{8{Uk`2n} Xbwj+V^pQ\:f2?1[CCu=\^.iZX?ʭI{:"6:Du^n™{FG 7] o?J*OPa -Nd VʽXv6tR59,%HU'NI{-|?$p[m vO)ʮ{{S$~65eIy kC0TfBU4s #w9RlxBTԠ"\2Z3|b(Vx/% KKWa(1V'k紵~dKce58t etDeqP4s%y00_'HH' 1Ëf;:Zn"^ogtK}䐡m<'`5R?U>Fjl}tl}򤬃:ݴeWeS1^fƂ+Mʠ '-!#Htyέ%>t畣vSy>l dbMXvH9I#|ʆBh@k|thB,OzsGǟgcj"X<_&JփLd9 bw93"XHis$%X&.osaa,wO 1hۭ$Of2G-8ZʻZU U#p7Hv:Eq")o;4xGQVU ~,:<qS4Pnq9 ESleW0'm>y*p @՞@csUϏr(ԃm&IHmZ㲭h$)Fju3x:3 J.g&&޶HUA:==hP_S8@"߯'&e1P[6SC2m fQcm Q̣:R`tcL̥zeNd!lA~ CF*UQ!NLVfX}+w^:Oh$]J Q$y<t6kC0is+K؈@k0ܡ{s̛c-l>^J/bjD+_,C 6G_;YFujsvG&sP/};ꣾ<bF$?,ÿ`ɾey`8 &kPX!qR>w'71+Ȝ*%Č'Eo%A:UWL٣=DJP)"{€A/')5D>)q ZNy]A(= RB9L%8!B&n ࣙ]x_7F#vg4w* Sk8#+;".51ky]} KFn! L*{翺v셽%H]Pْ r$r#YOg\+OQSNWwf_BV+~b8yZ9.F/j&4 ZA%E4:i.d3 - foq]C 2C @Vkn[4M+ _A0\Yzz8<4~FO+ yIK={AgžSwԡGԸA=wۯ:sNB]%ޡ ~Uk4UMc5'8+!k+p .(Fi @g4SS!p4LߒĮ )W B,bp O f`!?ͫD>NY%Yc0(lM /ʑșɑ*+h>1)M&Q]p5֑K1oDthg_C"n `/LWEIE)1s>T޺%ͻ2=WV%Ĝl 79OӘ,eiaOqqb=DPCBI.q`_RT.xՇΊSޠx7J&ÔN5KGpUs q_q:ebtm?0GTX\?$J}I;1_oZ}N ;pg,1#q}Yd.~'j/m!OR5H~uw6)h٧Wc=VWPN,sM5+!JHwcυZ 1w*q{j:6Z ēhc>s><\z_ezAv.VA3r|_i\Y&Kc_YTgj@{g7 k8>-_M[@D(ܲ9CBwCL5zƐ->X8(#΅(}CsڵYHeNwA&~9x@˳ExwboR)!,k&e@T;}#l!ĊP||؅LJ􀊋@y 9 8e!Fg]@=*'O^P//(jJKy{Ruhr9)^ \=EFsZw$U%PϒixJUF6<>|'ZMy0A=qw/bZ7 >msf#aTzCN,} edj9abZJI R:glrSNN3X0 +.-p) MḵQx-OӌQ>ؽhmꑊmv GHz&Gt ¿H ^,0 ߻rEs5a:Fn a":;dru8ʆKb]O޾eX^2CrflU:*SuDA kp%B 9_Rtժ~f3Qg?ĽZ!na`H]cif%ıAS*пUF^CE@1b^ rshWG’8'Ԅ ^rqrpcQKyT(ë)l@g!("Rݲ:ҐijLjwR (!0-_&7% bBYRֲMtJK|O1k. 6 h4k>7#!ӔlU%AK"CQwڊ0!ϫVCޔ/E[xڠ`yh-9ֵ;cuX:]qчP}w|͎| @m=>6.eKK`Ԟv̜$z3!vX1s !ƕ f6/f{qmyJ/Mj&:ot{|6 Fa_pow$Z T\ܿoҰو›RpgpĨqx\.Bg=2j񓬵V+'60Z##'-9ߑ%t-x`M ^iSd~Б${t) z@Hc\+cebJe`NiNm~R ɑOӞG։rmo0."S'5#_|61Ƕӵz-7e! ґFŖKN>eRB V_硊"tY7Ţ[0D9nhϚDV[rkQ:io-k(|<NH4{4a7ňM Fqj0*ehK篠vvt> Ccz/ue_q6;0߉PD\K )-&G8GݻssUx86^àh1PI_HO#C~YL:ouyGÒq\}b}Bdim4Z5UKm),b* ǂ}S>yi/U:և쳵]LhnnGY|*a`K \ۺVq$#G[[ηVL&:ȟcw =BpZw[M 9`%([QaWl]"':@G^W~Wd+%B]+tDO9)c*~  Aa()?EшH84!&w\cY4[pmF)s&sx@][lPُr`y@F;ADC/de~EQSi{iBDzPdF_PyR!yaa)'"LuY̽=tr5 YƠAl^ayRkH֮NlN]z`9]^$0 0(*1%u^wF;9&ؽ-|E!T='"vVe9^E`a-h!' +/ֲ!Y^^Vд!)Ԥmqf]a#>+gnÚO8o&<4tFxuA3G. 13E2YД/`7ɨioG,k+os@8@_XNm2'Uޭ _zOKFPe^!KwsHC>=8qz6`AuH ^.zAR *|4NW'HU+Q+Ytw{@kӵ+_@̘@єcaPWE'b[(X6^O(}Ti]$?`!WW=-JF`AY|?(5Wl@X8Vu_}Iӭh⎼SiA̲1l6Y*2,]`$Tpq" wJ%k38&/q=MN\b`]ڌ)7heWG>7!;(R;gI7%NDJ|n;^ i5,'uuU4zʼ{ؑZR" u¢ˌBZ5\|2U,-d6)br'[ѐ`fK#H'fTVd{ӅӖW}ʔA xޚs՜ \:|593CMsbhCl{ o!g/nY/PT۫?B<톃S$dh9PoK$ċbN^6U$|ayrJ@:.RhA/<+'ŀ¤׶ )Us˫9k֟[Ǽx8jk_|'VjGCs95:*sɝLv9JSnt [?qiȤ»S˫k(sNh̨v\%^@D(2ɹ>Se !-.=vَm5:Ѹן ͞=(PE'dp"{1zr7:^SHiWybm:=vC'NƂH6~7\;ݡmtZmQ=-ϱw]׹4)1?hXpG_t 'YlY٫VI(f}q-vsɘŴf*tXuYrfJJuc&a~}';e=f"yX~uA 8aV. &/e*ҨǦA0PVR/S\E͉;ح.0ʃ=iYvkqZ#~c KH'V,ZVQO%.kxJןdZ٥1<\DlP!!lvK]bƳ/J/3"*ɗf030}0 È NBb;!g(# R,Y~@t/H{!)Dlbۛ3w8X_2('*:uYcs|NqGt&ٵ̱槤Ɠ"HJxȵ c]j[6̆i4ӮϨ$PdZ澿4wƴl_cSp".<N>(Ae?GlYuuL`ڪʩ,sP CjTwů5!XzX` fKAOHy׈}3I*@86͝_ȉ@,G9f\)1n}+wjI-PKNfaKp&ˑ\_a{k-xl"52i%q}1>ث;:|%ޞ"D)%`OVrzf5'Ш1P8/`/Sºa5;+\!)[do@:P>oŦ];CIJ)+֖YeXfygټ2~^.2/-!UHa-/Z*; ^iw/ҋAIKE#0gA/ڀ }\cy(֫@0 Z+_ ui|Ix j^rctu ht/uܥ/یIN-0Lo,XE?]_Ҋn3?jYtl:I^5iEq !Ŧ._Ij`Y^!'XY2t_|2% 0#'x3! 5Wj ,#Ip)śO-dqSZƕ`}iu IqTѨD, %T8 yZ xï }&~`Cpۀ$*EI %Ӟ8Ǜ0ȯV ҫOڰ ~_ge~BM)kK J3?6wr0s}]V#?%!s=0)J'uN.|`2U/9>{P1pa'?,<أ@T[AWcX7WQ|Džu1JVVxfB pc8Vq }7dñʘ4+ ;q=q@ѤrUE>$M>6ҿoi '**d2'|!ʉ)1ko:qxFr'5)"|8i" gaD2cd[O(O겈|sYXq&4O|j`gJ i/'' NځXH-;B¹=RctW=a0*O*.…2켮UlQ˚Χ 0xEFY/2kHꁚ$a>0of˗Aq-}lܾηP>?!TNDJHûiUK s^[+y0Zt] wnʗuVړU}my=wq}% 3%0áNfg9Ji : '=?z7RB/r+95Ēq=E< 5IEIY/|VcgĘo2@$"xFa.E})Ħl1BFBBa+0Ϋ: ]Mbйܠ)'O_ ο_N/:3E2䗃OʣM`:'% S쿏T.4zuEκ1r3sDٝ۞Q_SEPNU'e;[ \bД䘖P#ؿ &5G[`\g)RF5 1y~a k'|EX7hK֘0xܫ.gN0 "eK3,ZΧvM?[á?Jhaˈ=mIo/u(^ߤ\` ?ɞ~" icT<EԳ=lBrGLjfT!G;F.Yg"B1bʹ*ykl%M&J/up;6tQNFI's)ymDO CêW2R6EnEVǸZS\RqcəqFjfa>FQkDT>1e:z&lM>4 ֩g Jnz5|%ӧ׸gUɃ,)ls=;PStjc?7## '@ɍa$6)-Y83cc 6iDƒLĪd;eLНt~ sS0ҹ1ː"bDPGVgޯBm4@ŻP0StXH ~( .ս((-:؞ ,7rlBNQX|a5@?˄Ч was<{/2S}XCcx7?UIΑ'sYA - m%[pa*O;U87`[8& _7W. / LE 6Hhﶮ쁇{Ls* Xb4.$Y CGk p xH}D?GeDJS ItպAEEw2d h#mj>ctȴgK~w Pof 0 kdZϋTfDCU^3.V$.sv6p$%4{/}ToX3E%]{7k1:@ѽ:DEzzn$#젒Y[b#Nxut+/U%Ph7mzM,b>|6 3>SHdDžwǾ1O׆yLW)mIxrƗP}cSx+Fzᖽl ' 1 (Iggp@h?]Ṟo8 T y? wp' ի[/!)%c/>Va;=.[N'3q[i*W=I:r牁$HeEJ#JZht8_݇dW,"Sƴ!ₔDs§V1B,j2^m*tS[YR~# Yfڄ\lr]-~9Z^Z'm63NqOL&OĪun au1CjDa7)@t5 -J@X\_~Q{ֹ͝F&勉KX3^NNωy/cj|%Re;G}ň2 H/LkZhDZUo^~Xh8+vnRz,*_-hP`'Lc<HOHJ=nVC@P;>V~c@U,5z^n{CuX>2ڧ8}pvt"Q O-6E@s8G(| ݋*~&G%?=U _r 0娴*qRð!`‚җ!+2f*jcw'uf@bdVWM-BA +yVҩ x'|=٭0}` wnC/Mxu+$#N9K{]~G֫v5T> Պ<4KoFg ʗ\&_!x@Vّ[Eܳrp9f^u͂ܝ9:Lv^`=a2ظ0Hbe*/xalQ4_( .0 8Y`ΜA$ MX8r \1#0"޵/Rz6z?(()" ^Vt)$#ت& d={J ؜e".sSe%>+7eK%ӡ_BXޣ 8o*-s;K9CYSG]D f0;(K#+]`x~,?)"f.At:b,_CzR͟i9r͠V>!6p`ÿ'g0< TCE-<$J y (higJ?F |WC*kG čG~xm$ɹ9rfP^:pۣXԍ_ϽV4m7}O{l=_󪤠-Pi&m5tbSnHff_R>lR,~ȟɗԑ( lj h g$zt'΂#4_s𸂿6v.c݋f 5_2$̃+qRwjig&Ԅ8 :Ѐ},6V>8("ՋpnDOW5Ooފt>E>yfFvP4A4}s/BhJz0ʣmC`B;e wO-Fd㿼=oqos,=*pMTשt"\RQ&)-@:~ג;[·&w_G᧑Z6nJn @#[gnv'6)d>cjU^a&[u\2ƛ[=}Nlu2QbcHbmUuG95}S/05 1=% M=džYu܋~ʯ_WCm#hBnSDG6O Q?Q!x[\s= WY إX>ʌ%5OHJ XI-Edf&De݀7ɖ-ZD]ӿp|J/542rjTtHmU8ϱlY[0Va P~0(]6W{B7$3ZZK[gG`bp i {eq&&lT].I'2>fk+tF&g/Ir D"|R*Հ*1q45BDfC[n!}s0B~^޵KU()٭>},8~}E,9gTJ=)vGF s] a 2S&h6*ZԚw?m|t,99xjxh*xq]ieu=5PD0X2. dZ V5;J&iYkPq'PӍn@ &D8]fV*E]dR!3\kT=\nĄ_oT 괴j.CPh{H/T6ҸXZIUP}X ](sj?:# H\ar;Kws졄 iXui0{c]zĔ`27H?oZWbLZֽ矅u A(軬 v8>e[qĀGC_H&4Q=!*L琢nrL޳Ƌ/ `ooU x4-2hUA݀nAٙ\ LQǐfXkPgvf Jٖgˊ~<P- [IxQYd6g{,FRoDgA]EX"ʹi9͉;GrbrILX0œ.UjU\Ȳ?!*3SR6mΒjCI.sg o,%PŽlqN=6n"&aq+OMwFka-"&`ݻgewqH3#tFSp@[TʾZe&fNʗ{n@UdX2{g4FX!M.ml;5)6UE$?orph.4 Ŷ arXC TBXM+1qrD^H$+{uv8ÐNWN,{2w֪<A׏a>;fB|˽)M-RF>`L2gsTA5UT1/O5H Vd8ީ# \D>'r|81o79+B+s+nDevn6BXG(mR$YvQƌ,D8Z1?,)nDs"k@h䊞4CcwzW _du,qw&b5Rڏ_OڇS fS+Hn@ <ǁ% eEW;osvVNBn܆I 'iJھ;$S"'/]DAJy#6#o|[M8rF`FWF~8K7W#!0PagTgk"5"Nrl}؄t@z!Η,b k {so{ ΢9Ez4YSUĺ ndl { 8M72B.eWdZ3  T4 ҩdb2|"m\>eub_[wjvyPLe_T, *%%]z TyI~âWB|B.+7͸ c$e=L}C~Pf!Ӆ#'̷H1(SҰ0NpVxF5z\a%t0~)FH ilfzl[RVw( 'v\8c*`#:ލvI?(*w VFZ-=[}_GþdIL_DK4i S/2x3a[n֩: dkz\|RoӚwz%?!e7a?:<=*(,j\=GM!rg5璄&=H5:i:͈mc(=ue1 ʭa; E/ƻ^S̭z2;A%߆访]hԣ@3QW| /pyv3D 3}zp|f=q[Oj嫊 k?t!1rAH}HkP:j iZ5%ځ334ʞVec϶|/B.pB sh QzS~x  χ-_C_2 $C<3|H˭Φ)WmM 5Z`1-tw6)u$Y[R7]{'ɮ0i;Zcfnm"z5bV;"T q2Xʟ5/Ȇ_>9xG}֐E6(A"_~?xXY7|AE+ly v,@i5$YH+_GFoC닓QآtKp.n1|p+"㇟3,sU̧ׄvWSJ}'B8l&|ٙ#@lwdBxaG/Djӽw<^^,]ɐٗ*dڀW%<.$-LŖx6C Mh#љkt7 Sبy @ ߋx2RKJ$nS0`1䜳+;#fwN_/J{ Gl7 M@.`a<}>#,$ЕUA1?b)5|st/C$5т N>[&4q3Oٴ'{9+d­4 vp !Xjء!'/eiI<=LLob~-GdIgZFJ(%ł,:`:̈́M:bdvL"d^Qyx2G"zn4hzWBە3D\ײ9se'7 3SGV/^P_oEOuaTM)\{#G1HN{92<#ڡdOlVr_*$B}{ZbAVQDhU==o 2 hka1IV&5iLxd֫tX$ 4Y,1.awjDG?)hdZJ $S`Zli$&/%D9w{mQLz/~ Nr_xAMPh/ "]͡ЍlA(81ؒoKoos D$! 2cITuԗhFW\Ym*|w P(֨Q#\c=,;C|)$L) mynӡȜ Njri S|T9|-itkXQMB5ϔmԇs597D}V963ш٠X0M{fW,3P{@[Ȍh pxw{JHz;ys 6{-(vqz.}GR2\ s֎ `pFAb7-u#aѽs*rPYͺVMHS~CY*jx/7~qqh~+Q[BQj"p*qwEJh4FסҴ'/\mBR[ V&H@&صsy_v|v3gU~~S)i[V2xZ  AE)gshWh0t`Wmד}́e?Bc&n\Dhj6٭7(#A]w$Իm _Fa:˚a*J%E6{5,bڡYUSct__)ܱ􇸳9ftPbaPfe}+D;S O:]&>NA[@kHnO>R~ iO rž؏JwZ=1}jyl$,^ccІ(^y "'Ise \;ST:Q&7ȧtqwTO(dHͭ#(9&=S m"Z fx&y$`@h9{[6U=?T N;sU<[gF῰ǷPѓ]B%h>1S v [حܹqՓMYse5~2pȗc6/p8^. y #5l +WV4[vMR҅Ȩ|\Sl ykKNBP unVKNElˀ":$cQz5,B^۷I9;,c)앒LY$*xav t\^S;󰩏lѪ:s{lh|4Wc5m0ͯtdV((d@[a ӃqOD(Zr<>.7߰ZO3qqdܴMuxj]~SXD+\+'f$⽰: EۗZ|G1;e˽\H UIf~F-AsIR=3wJ׋ F9I|\g:*/TtlzߵtRts3US* ӺO OBGWr.="Q蔵`#ubu_mOFSLIlV*N-=\߅٦Jt,J)Vszܛw>}H\3/[1 @; NC+xK#@&v=ju,~gnDNe3B93J-tKdO;'gjpqj{6W|- HBԇ<CJp(Yr@텄P;|fhX$ "e^ b7Jy/it03!JRt QҞ1$"cˢ;SW0I+L $={b~OYD@w(<즲MoI7o6`vp<' Q}shGFI5P쿊29*S:dDXNj$}XIVeWL~?:%.Pz-)kٚɹb. ڹ]KfLr,J b`X] o^zCuC,jqӣy1yu +/Sl{bǹ۵G_L|,?/~uaY蜏޽}7J v)^-ᇡ R{Nd s,#xٕj*ු>k x8sAWu}q0V6Ci|'awH34d&AIE8BŕO{IZL\7B XPΕAL󟅩S=",+) Pqf_Ws)} UI=gޔvs QIԜ<u?t%Bݝ$[ zQH _~q }0{՟ynfz'X >L6lJ@t6!&Ueǁys7aq({w632>yѝjKl5?GD?v{_; )Mљ,wkN!gDY3+1fim1e-xK hϰ[_8KA%/Q< `W Qݩ ɿ"A6O֨h C8tT&).+3l ")u <zΕ,9#v7*7u(J݃} 2n,0!;䷯/?1o O y"^~h"l}ca'#+ر ,.1]-}BT4<CnL*\wh#>6OovF݃3v޷hNJ|*cF6NST?+Gۋt,agJwtFceIK; mm;m9qKD>-~9@$ҩ䌗_/EjטRd8s1d$J>Cwl^Y}e3$ ^^@Ymie «3W1R醸^- !C0N[מ/2/Zz`WeAWLHb kjԷXH `V(n=ף յӈO72k*E-Y e ;;WMl'_}4h7t6 N-i;rV̷9)qF<%Mhޯkr;B6NϦ[1wDIt+()J FBRFwtrlc:tB{f?{OV"n) cӹkA|~m5.SS2AC M5\3 t= \i@հq(\u]vMSԕҗu*\(YQ3Sc\V-cÛ /_@wt jڐ,ywCr(8WK J sWfTe|ʜ:ӹF*_єs ь,(D a&Iцt1*-(xRgZ:)t9~QxS>JjjwYpV[W-M2 /qɒ\%bkA /ӹh#RcW`YꈦzFaȞ+|/t7[sÄ1PjR0;[:B-ZGsDe7VN %K C /OHc/{7`z !lb!>赉2eSƇe, B=FPH.)M[ºRGψΏQl]eǽ]Askw8?dA>w7o5;ޛ^Ñ~]]O|0sc˃i>EuC ȉ!}ix\R์7q"F^nTdӞĜ?lz%7TI,2T 'u͵(g,YYj$=|&$ПkCiSІk{$R{{3cY1~bQāl6S+oұ&tRա F\@ qֹ^) y8\$ (@Y ,M!_ERZ^j>^xaTQĦ2(m.'@#CCB|,RC{cNۛ$ i^_[F4ل>fLz*dX;`CJg r%=UAQrыbI\"f~Jj,z tsڇZ ^U㚈pf뉁5V=_~b=FHҁ;%ϗ[. ZEGc b]cEqAri904WDD ]5I/_$#drƻ)vh=[sOif T<(jM8,3Mp}XcE&kKk5 -+ж,^dfuy B 5r{WA0A\t18gCXiI؜aìԖ-@Hϝv1eeDu@5ΰD<{(+5yYϫ ,Yſ}KV|jR+? FNN }m&Xe:hyV_]U5̘: }]W,:洸"),LfGaa?2pBx;S,͛zJE?qLܫo[T82Xp{QՓ9 pQ8jgEe;҃2qxŒ4")0GkrM:VAI}Z,3BݜT'MkL\O; ;qbnyxm)<+C$oEH6SJcv?>d[966pcˊNoߒ`FmS-E̢6KSv-H:T? +6eĜΒr.$B\AGC*WtA O+;&\#5]T3WBFBRe w.ErZkhmƖPj8nPyr[7c9&,omƺXܛK^bQADw+yah^3"JXֹzJZp:$$MqBVUǍنAZn9bk &X5 Me6*e=B_;d`cꂖhRc"D{U#]8j[Y 1̝ӱ{lXKj ,_ XS]ftb`Ol! ap [1yH]NH4hˠb8X8A^TM]: b'!]$Y6b<~ߥ $= APSc.c7A*ē:ĥMu._,GRg̺Ltxh-+2x9 ŭTPi :(Z,VNP)J:MH4\Uϭz&e-^G.ձ4<" Č% OҖKvXC=~nxy0Op蚭`F)S'xA:d G\G e8o2A"i3$HĹsct4 䁏;qWGn#zξ2!rv8P*fm9 @5w vIO>WG&/a[(,B_7X&1\iE;N@@tz~z0[N%`ڬ _@km )?D f+3.slZթ́"W'o!f1ÚKD. *1cz&%6'1pW.-+'"5 v(0C:2z6G υ7G݆䑖v9׏Blͻ&*D_o߆g &Ap*MFD1KX54,6Tdiwz9ND6Δtf囗܊bp=pItr#3~:b2yX>_YݖW9F.)#dquUh B2. J= 6m,dCX=A횵 wܑ duoBmqhr'pz}Ȼ\yFA©r8$BsO$1Md{rx2+z.zȮi_EƄ݂2 bv =*П ν`DT>fsѺ,2k|gD!8 0"!._E;+$R=;0(ރѯ)ƻrgCbVb7sU 'Ȅ /$440{Ob0| y1}|Ak(MDk c3ߓyi_bK- 9Ku56CW F2&[7,ǽ뺖JvVbD~J)'pഢqՙKS`#Cul ]yog.v/8U yٴwy,}+Q@'fUZ*U-BhcD|['Ào΢yTO,Z Jb,s)f(WٌF19ʏS@,N VrObӘ@NA^0=:Tǫ}x7'wʜVZ_Fu$~nkL _0З/e~n_'6Y.7jȨ٧ ʧi.MΩ NN]tB5AĈmxO%˾6DŝR9Ajs1(4|6YJ"0$2[C9ssVA\nG5zЊ] D1 Wxn ۂyVH*Yj{#w Х$"ckS)})>0W,J@ۊuJ57}y4Ų=y$"A) x-}gq0i3@^>V--<|i;ҵ_s85D'gВyȭbfRIw9M{^fnO]8z•!Ɗ M7M|وDkyW2{dD+GX=b$(z}É>w>_uNOɬobA#^EI0=+xS6CCi|ƃ^ VoͳĦ)Ij}<\3ySQ ǧ4Hu{)u~ y5 p D|%bų(+v|챗U y)2]}2X̝3̸ RϊF]O]t&)6 FB2'ѿƨPKo$7XB 0Zx96#z {5鐯݈DJ`OY+ BoHn-et7<1@,EZ]Fj9]*OUX]вN r0"o{.@#(,/q_JdpgR[ljݻE)rzquS}<LQhY"1\v^DbJ.W: |R7)h(՜~JR _pgGnS!HsیMQY3.鋂AqmG)u[@$Ĥ>k CnsՙyҔ Cl [/FdP|&!='r7}O. zPkp*12KX||V1j@6i˫H['B`L%:)4c"KfIqL]h) ̖Vh'mfv詻\ {3Urf7.gfY:l+S<}O$< &W%o|FhD}`.)8y0e!.RYWmkгN l?=A-I}Swql>3KP%7MPm)SӃ!r4\&@2(X0f0(Β%HJ&nh,ąnb)9QVvӠN`y57>P8f͆ȿw/$_=KT[˕g${'|H4k74Ū*cHo~do]/IT``7*-$}0ݗq1HPvJ^p)lT|0:^/Xr9O9(Wn_BgU+eP hERgIP`v/#VKJPFG,MPm;>ms- gIvudԧab^(tu~|(DVB9eЖZLȟ\핷qW=y>mun x72N?x&'us{?-nho ")ݓzsrdЉmsX6&|DMZKlX,Sj#SfƗ_xQ].ݲu:3F2Q`PSm:Xwf{8SBvohكhXQg9z?w{6A#̲4dʗcK5rpiV*Ux`|:A<qFׅ;3ճ9My n_hn}EHܗqx?xD3P63c4FVo&~] g} AM`ˬ!ߪ{!Cp ^:ebkv]sx &ͿTWg#* T>‹`[/j hwn:!(,WuvfC b)uPL 7ր'mgX^z@,t1;r0,_/rMoCbB^尐~|m|H|zh1@Ï-ݔi[A /SϬ5̭z?M*y(<+rB>Nu$k`p.d9ECΛ<B GN|`Trd&bUe*cVv8##QjJ( ǞǀK2FǢBd/N/fTY/G?6ف n FOlyƛwW&`aLd0pMH-Tq.N76o]7'S1~ŻզU=&yΞf9υ(+#h DRT*Ƨ̰C!70A@LH! 'K={3ς?~8a҅ ?9NnӤvEXDj_ x,AW&áDoGK~~9,Ain5bi}ICj~ƺܧZcj'Y Eƿ%& Q)!76kn:OěNi8+kT2Qn뀼2#Ep!8FRB9 `UּXεbJqlm{a,^L^DD~j+y~dt5)kQ~(芎={ &nPwڦP Ln"|Q ƪaå:7bV\{L@ 34)n*c|)_L&Ux\gb[#iQ3u͗ErU`*V.X(p(0B:j9pTJ.g^q~j3܌iFXs^ߔosϏVnj6ć1 .ͦ[!3CyC0,s~iXI9-A`(̊MsǀpO9i ݩĽCy}ߧCDŧ`tOBvQko]`^Q$[H" 8ْ"ÐlD };RΤ&8'aݫW[䋺;}A@ tzǭf(clٲ˗cwTn6%g\2'`1b8cؘ˼]Ό@%]E0- "ceQ|_2:N|wpsMW=/" 'fuEySB3yEcLА>S`9x?׿:!tBʦJvN2{~pu7 N+Q:#]M5LݱV(=׋0j~/XVx ,ܑ֏)(O% a6رeT\D LDQ?`h0PvHs0Q:t }w*>Gm;HnԪȴhDKbAk9/+V[9|iGǛKnZeh*a RKqz5$ q]FiYMW8;]l[|$]E/>ȀBSN&l)mvU+iU|HY!-^!&=!ήgԮZ 'xmrW)ɫ ?%ۣ.v-)aB>K J4jkLl Uhέr%GUU!n b| <ۘ$=Uxr' i!(L{de-y}#D `#Pd\#>9&yL=eQCyU j;јHP)HёЛxICPVRg][Rj!s7Nk<32Ͳy4ɦ8.:Ty瓅F%ۯvRhP4^tPǝw)e (7X",.)*Є(#02 {1k Pp,kI% ٘Io34M$wUp6ݭHlw2^V+ǔ$d zqȝJHzxIzV~򊮡{ja?٨Sm~۽)9ˇUD 'sL!y["+W 6]Vy&Uh~aٕb $)Q}nE[2E>!L!н oiU`81#97> ϕqs:o (A$P nlu̶Ӂ^Cf."Hx8ߧf|ӗcA_0(srAs jTqT;i*a0 Z0lk& {V$`Fnrv5kIl'(cT_hT3g &LJN|\/* C\t,*o<_gT 4\iQFj» ǍGPa%￸>9AfC|?sJlF J9Z/bF/Zm hc!YOI`йֈXEف,$79(9f'K6\}T !mIPLG 2wF(]Ej_D@b.ê  CF3gcȓ+>l37@w&dfdgEisقgIf<3A}T4(9ŝ`a cP^2{q7a_"U+f;A77`ÕQO!y~zB H_nrԬb#97æ1Ĺ$燍%Wy;4yIG |}bUG1 hI('֭N8u2 xԓ]W1xw*kf~6=ޣ߄7\e=r|j7#߈Im Ԉ1U)ۨTH2jp6 ݈r2V 0W/ 2+-13o{TDM{AzcB{VMMԡ's iFnv }EJDq??6R3x< kuYiǡ03S#ĻƕlUk`FUDy~ nPI~*X͎tԑG8IzR|LVG;l>iYw`(DPt_b#ô$N  }?]Q˴FCA7Ӧ]h#&jಓV; %WMz Xc_ \0}LhU6 wy45gMˢb_qW-Kt,>&cqainMBaN&JH# &_?lĥGt%#W\%UnX"]P4$s>4bӁOwq]&TL$QT)LϏѩ LG^~@^{XY\_v/ף9ꋔpIE+C[.$:,uo3WoP',;w,_Dq4][Xj&5ȋfu}0sCVipNRN0e*:yP|YJ20wԮSpe~GA5~O ,7xLxz]0` D6znOKcvEyPkJuy>G)uߥ~.CLVavPސuez{E ")Y^_Pj/ S T:X [ `1Z8ruq( uen~8Ā=|~;l,`茅y:qNUq/1S auuR8a -/I1J_α Mv=LOB4AXVGl :%qn°=ٯVNlZ&P!T=aCby+l"*9*O@: fbܫ8y|G{a]zL-eyB$_Q2e/ q;ǂID5ֈR,>&-?S䅅hiϹJ=ih5?L!k߳ >}Nϵg,݌GA7RGsME Y *`s$[ iNrczWYz[πw,6^njkUuNKXiisNy 4!Vw/Pmǒf?l'V8+7%& {FvJ%F~yݏ_׏`Е6uҕzԼm3d9W헓D*)p.d JE=s>,}ҴaDe SzTQ0 `Oq+ޤ5zND v$KY3N{EJ<)=k$B{^C)K ݍ81@7&%9YWm2#+kPGImw!ir@2oQ&iat,JT Ou$jfѕ[j ?L~(?C x fQ_MEa`-*ȪOu < ~dlVwYhLZՂHq2M>i\A:YזGYsQt N< Wc,>0ҥ"w`t&=V9F `θ eY6aω^E;}J("9I{S:Yƻ 4(> ~gcSkX8_ĔPq?gIYZk |%zU7{7 uͅĀ`8yHtfΘ-1A)7cƼp iʑ'7@mx1 jgrP$Ƅ6lrw rtemX4[6:M ^eB EEˣBGF92"ܔ8gsEI:́ꆝ-~XNҕ& ^Yr=?4Es"%8hq%0(ؤ[Q ʼnEO,nx*0ЩOqHV=J o=Xslz8)ɧ甚MIٕ7-*aˤ11O=yܳ/*с`}f§TK(O@CyD({$\`#dz=nJ|9>-P[hT0s H Xޖ"&Od刱4[paa_M,d#>bi^#wٶ+ny0Mg>KцB@H-L!d(eF钴(aQQg2#2x^E39;uWO6qh^싈NvtGӥMe&Сg5j('5hM9M'b8Ja.54w<,Cǂl[S&cQBHkS6Es.8bg>_ZwvUbQvt|;V O~in0}xcha|^|^&NS4G(޾EwELXQC>ɝ) d̎AGsV2ědhd`<_Ex#ȧQra[T|h(e_,ء+RջЉ w҆9p'Xh͏WTH6L8*Ǟ0Kg4L5Rhd*Gq`Q Hg|boƁ;~ ΫB =;1v=o(8ʸ^j=nx`CD=En"!9*GU̗Zow!#x:nʳ$?uXV #HcjہSgLuQÃ7{.Δ8aH#{8&DG~kҧAc md܁. +hi*νCH. X'*JaOJK;Z֩>&vNE[;^24 Qmwbt\-ڞ$^qEƧf\m{Ů=MPz@ ;6r܂i#&thH?SRF&XOuZK5%0F'O -¬QylǗlZ~s)g-+T<`fpBivW~IO,p9Jw:$Xǝ$_bIJP+NeH1ـuCrĆym2/e@y/pH_Y w8: pOH0VmOQk=C^ؿ&33GֳsK8b$>t1;DF mb}LEs| f{,둌;lEᰨo~diNtY4狊&ӂ/%^ЦM} ;E"%[IBN}Gr&}T~4(ӆkMSg1)$\kʴCJ|Z;BƵo~Lvy"f ވ+N~, S`C8X;~-'~R7aQA vWK~)T̀8/M]*uxaA/<:`]#g6:K2,־gd9e@fᴷn?Ǩl&14ݙr\SkWŧ ^x׫{{$r ϱ!-uZvxc»>+oEzp8KIs.re^N+*U^kd& Rp7mW(Qj6Mm9=/A?Qfuod~Cn/I8`b ATZQcYwC6~=;l|%5eLZ1>˄+,ͮz?$״R/*ng˄|<3b#~t@ B]h\RY0ʥXώouQe OXXWVй Kco@%+"vH+*2q?p(?h[.8`q:YP\'`b+;2=<\aRfҮ32QPoFC'a0 nz ^Ŀ!WLwdMUeLVkWAf*[tp{$]|>+<;P.[ D̪Jʚ*=\tJy3G*[lpܘ*vI-0`ݏ x-@;8:[mĮ{OZrN|T #4: L/-7ZIJT8f٬1Y[&GdAC&@)rŝ}C ]R؆831%m+Gro'J[|\>3-VrEn7՛_d2r'5sߵtmKUϰolC?O`x '6jSI\ ܉ ~ѐ-8ΤQRP*" Y˴C&ߡ(]]pZ1[1EY3RʏS0{U<*S-t Ş9 -M 9>Y6GN)NfW97tv4^\Wj,Pi >d϶qDHNM]`aAs,{L]>R,Cǫ'v9׊!UGĉ-nB m}[K$ RiuQdgselҬBk[\E$Z"oDuA#zׯy[fon $4Ty W-BVv'KQ4tmEaCmqط"O&C\L\wQlI\{8t(d5K7sJAD,X₋-@ jx%Zxn:X:,߸k7T.accD''F='TOL䔢kާhi*C>mx9s-`eao|]pI}N+hRҵ߅,$ ę65}[{rjl D+i73饲b/.Ū܎zq4ZX0|AkYx ֎P 9@ ?%JS 8g{dU_ne¢CCxBȗ?ՀLRA}`m2 8Q1L("F% ÒqQAїz_7(z$إ1IpxME?`{>mUT372&4[=7>+fYynuJ\Ο R4lP(BE @oDi|q׉j7My Rzw@_%R)LHChByзAXe೛^3Az|4h'#o_/(#'D+\g> . D N훝}KQ|g;CF!Yw \-J|<潈ԧJ @?-S'ЏJ)#wJ7SJ w8I+O $ k淪J#1QZh E}dY::zf1f3= 'iyxY-Ds`ҹ؂L>hȣz-o%ʈP/&yKM qs;vb⤥Go[ D%@_jhd3a>, [J,USX}9ǰ4"uD{1]gԋA42m}hC`O)8s.}U<{ ]~im+Δ5tm.DDtAit}Ypxj?ܖ;,-~WDH+n#OSP}|cIbBi( )MO6ZfbYi{ R$Hx:9Sg7'XKgfx'BMsNlG-|cL7ƊFn@yo_BKM1'*B̄e<r]cKWϤ 7.)Z;ۃ)x孺;s[2NՎJt-$aj4|'~9# X?k{h+uL:L5A6|Y=T-,j-=5W&)D7#}-nq XI ?<欩m ҆K>  -~p o=1|2Gf5!ؘV \ع髦z4CD򖙖,3qy&IEb?FWN s#fwzaSMsÄZ ,pgθṲ9A=Q|doZ(/F%I-!mk8fΨQ>\9NY8 ]Cks\C+E.q d[(13aK gc?ʗʪHL/ڨeXU^ҧ0hIFr+1-ظJVof 7#[XɄ8.;rdrdC49MkאMBiEjӛ,SYOX낣#6v#ng"o-)1f*UlR6+E$=U5lF< Uf'nK&wf 0yN`qt+fLobuv#*˦[ٷs6׃7m=`(O]Cچ|_j7]JK7eW /ڰ'%JU"-BV"1l.րP'Tmo_?*Wڑxa@401֎76N*O66_`Ui[b!~m"u <_fWNqGzƖӄْxp×C6V{S;ėwu MF})0>Sͫ=.17 jFK9ѿH3 $Ƥ5GkV.AX LX߫5h.QA @p=@~,#)p .WA:%3Lwrv@HN!KH[Ia`r[Fqɇrd d6}laۿ|=mgWMd-hL_#L} |6z!{Zr~*K3k !8lO1V*=XxVHQQ5C>Js\9%O,c-'kStQ$rȐOJChDiN3qZ, e6մ[>V(Diս;jaU@G}PlSvDvr>p#!&PBt6' -oW$.ID9&hHXw *.yDmJz'ڕ+7X00mxjEȵaaLXJDB4[{v6ʿ30(BLAz HTD]Hط-?'nWM",>zh{۵}טּRuF{11DA/\\37 7!gH\G: ׉=܍q~v/# Q7`w  ^cgqz/=$]pmJj4x6Q5 e_^p''N~Ԯ޼8 gʋ+B5=<dNތ n$lhI/T)#f~|&k].Q[XmiZ*;G/$O-**:63- W6oip.E't‡wC0BryfgD͵ }0t{dc/b\8G74|HY V tpx}ܬO)0S%84?5yMi$d{x-XjŐݵߤ3mFv_Sܫ4xF=VILPW@>;?lپ5Ob# sOe`m(RGܒAwZҮ`/xگ޹9[<tVR^'탑v+v>JwBTNqYZ&`N7e`2CILm1.8] y\62 MzN\=rjB,Lc u(5S_ݹ$MژG Y4Ȧ?:lI[L,h27I0bS;i _`I4Pc Pr:GEqo6 3FZ-t GuxON} xlL1$hJ3 #9Bb6AJ5MV-l8K-З>^kᖦQ砑`xzÖp0j8q#T*2 nY'7,a{m")h(~U9p!IO98e'}?,vko3gTBn}$rF:Ej^B3aq胱""\t[{/# m̰AC}*'8lAڷ/ON"X"lѸ%$ Q9U_A}uEz=1kk:1AЛ8[v $ "Ś}``ll{F 0 Ùf;yUV \xg9vp 2+ L7]/RFmVI{Wj%ޙi!N8 Q]cs̏xf>ś,v4JaРQߦ8B[BX 䠪4 ~O[S!mgvc =B J= 0K][,[rH!ߙ~tR_Uu"9XS=S=W0fн/dpRFXlbϓzM9J .?y">* %ma&cUms˹X>XSJHlplȮl_#FBK1,?q]Ы3p=}ɪͥ38 &#ټoAjCd?BtQS{Y##4R L̂dV} ViM{J OQk5Ɛ%zMMʜBaCSX`A*sw0oӁ  $rx9%ڸ8|`5㼥8o3ytw 0m6"nB(,>e\a=/@ҩy B-|e1v_ Ħw;(Cfl;}B.ʉE^+(*sΗMvLɰa,K8>'D]. ;fqr,1ԹZ 3242V'ӸÈܔmj5#(U45QH)ƞMkTPR Pos08_VЙ5PC,PL"t_n\~^Fc, 1~}BgUdc5!=PnQ۔0]Q7|h/["ǥ6~e oE\'|@r2it";ɐNeԃ(+X%83('Oݚu Lue[VcUv;ֲ922f _yfm-nzシ"8R]}HPVsN+(ى(oVfO:iMTI 61ZRH˕G#MTh7uEqt ~cN 6t&=1Q(aKSD a(dK0S5(06n嗵)p帥_7:[Fp+yfz\ .I\E MùjgM%<ƒ]!G]RyzwR~A D6X8)~,㠮Zn.,|+_@ĐY}o\aФsyj5M"<5a{M88w(N@h/&8]GpF筝|B>'ŋtfg6,<\vXc yyP}YH LyX0BhKêȇT\L|/ވ#&yA~Hq~9f&h_?Co$Qn / `HoO% aMú9OO|aTTǻt 0qZAC"^HĪ7d@uol652j->40$W%`5W,[JJuyK@$Қ4I wW<:g64O<Țld"H U)k+w-64)tL(vF-J@Nѭ@0oDk(gWU /xyx;f<مZbQ&Kug5C!iQ#fY^)ќ:[ab}v,{W<]-~a8)݌gY^ ?TH@QY9.c,tȝ!r)pOC!U gUuX{2,-5:]5;umo @l2#pI`lK8R/ 3({1m]ʹdy*<֬)Bm͐2q|Ṃ_u `I uV]Mz]Gm>5h䫰e{LC26*`|R VAӈBQU9Fb<~sX{ Fr&w?(aqbU\G3ҁ';4ZM`]o۱).]ѾZdE\42sd  u}`x8!+.0W;[R_y^⽸u9 ,S^2`.c Juxf,ЖN"}UD^ T%7,5P۵cqWp]='|5S !Z57Ub68NUWkj7X^u RB" #j> ^vcC|; c^Իu܆1r! RAI-;U3^Bn;}l4?C$!NL񸗘#{r+#$*zSNWR 3' i*Wk7=%ygw_$˙25*zgt1J\%|ɧ ,=; v0Va6_f,tO7㣢R-s*G|9%Odt\?/'MRaVӄg4:MIY m̉Ε>[u܎ȶrw3hT#ړfCf-s~7y0K`K@zf{єWaP >*CXyyH 6Иm(a|4v~o6&Cϔ$Vwra^Dm3| \O& gBnD mQy;K-8kiP-H\C'A&n!/ks3 e m>?-r_ܛ)(/坰L7y>;d dc]wD$ڑN(A۵eXԙxa5{@Z'7ʙ햬Q5Ͽ_˛MI֊-+X> I 5HBh x ԑiba)8@ozR9Q@Ϫo+U&ܷ F0 /si?M?F[fCB-.V'/) q9ACZzLjoJ]<-Ю]`kە 3p(Ewi:^ cI5S+`K1'r\89 qEuc1m,#Tgpe6a$'OاZPcE-xˉp<^JL -WN9sۢzoPe 3?)"wNɚKvIE2-46>df`q;qKes5iz0%rgco-Te,U*3VKȽS^aEN&&m[2Z4`jt3>e9ķ}xB-%pjŲ%meh6Bխ[ˈsݰ'P[ @i0cQLސ_^ xnQx#$]evsȹT~p.(w8N顁QzqLp =r2SAvkxIJ=Y>ъ<{3W.}b.CO:բ QS0Bx=|)-vPl<'%1(R`!EN I F)eh3X~W"`˹k 1i0Ǽw7q0ʾk2T#Ku[O:de`O{65"6& ,|lz aī`{l1OQ9čTlG䮧%$эk@:>s`sN&JOf J%pc֑!f ~RJFUe)I .L Y{-rwPN(}[B{ N@י2C oN˅S}asp\U4UAzkK%],-ƯGMQ.C ^ؿwuBr/B JoThQ6JAh mxsv@NtMe*0G"*) K32eNekð5I`! ]&aq!Û+뱯azQ eӏ"!@&O|D㱾df_Y +z2q#1KS:/.>,Rp θkIz,Cw|؝} IB.:Ȁw:r SUk̯$<bc0ç9_"Ƨ3w&xm"D(BrXS# 'L$<\īI=Z"VBȃDPɿPo)w!A᧕rn75rPn5qt6+گO7/Ӝu2~ީ= O-. џC:VC?}<8aK$z^'H1ocIs{.ul֢[yG"q6vKT^z5%o W{oRޜnS58׸jcvAn]Hb+PKq[T HT2\SV}wEPj`r"+4\Ά!{ŎGmcZgMXnQO"ll_޶>L o.64W[؛Ÿ#.\lk[NgmH;CN#pZ!wF39Vŵ wmͳ?Gg5(w*ͦw0Vr =[ ITLukzwԩTI"6WCJ{>Ceeө\|4_17;.=Xm~Ϋz.KKADJz^֕.yFUoU֛G+l#H;O+1$;PQ)ؗ &WJPIlҕpMz"clLy,o L09ߩkOs^04΄F {X"/<2^歠w#2KS ˉQӾ\hY8i$n-zYW+⦕.,*G #&n ^*Cj2G6}Vz +W#F dscye.ޢܭ60sE;Mtw3 9eb?Ey^;'Ɩ%`EqH  m˒taO:~⡚| yFnFNY_"̟omp43qK)ltT#0 ibUood$h50U_Pg }@GZ`WM-D6)yV_5$ Ha7ÌH]5d $~WU[Bxg;K0n l aɤ J6"gl D_LBO-Y \BZJ.NnA+3VϲN1=O$AUL[|zm[,qGHkUQ ԣ*3)+QHרr֞(Lrj2f2!->2o_moOJ&mܠ=֘e"!~7J_mZPOKaSkV QCa,\{7kEnzDèttȣKtM&DF>M`-X R@|jj50d:L` e5ZO ȹ،ͭutvٸ8{c$?IUar_t <%:kc1!!g֎VP߅tĊCl9>mgԶOcA:<¾0f`?i!vPɧjj5 Eš#9(v\=8lmNܟr¨.}5&ڐ򖝪MdC8Uvz;no ̽}Iˉ)LR^˗ǮkTvchyoK5SЀdz W~Hj br.vvMR0Yǡ>_3h-|VJk0ƭ^w`˾(ivכLJXGQ]6e:>Vs$ZMH@εQ ~m4AXR7۝a'~I@g("*xD)x2p,m=<-P . 9avȢxEayc t؟hHeMV>{ JvB}r2(DEw4|x=u&XQ4@N-u_C[KIMԐE=ftߖk9Ϩ,Ͻ7uKPJa#ny1{ rӺ?f&8X,Wh:=BAzBۊxyE9nl'D(Mg\J0BnBs+زdo?I51c{M3,_Ex,~k%U!Xt$=n*y4:r23/\+K ;G4=Vmpku|jP np4㍴D;sp,qqz2w*(2/>mh"NNPsQ1 ]jcJ#E?k8g+%J[q\ !쬕/z(">Pt}B(trĒjy9˫wEd~8MQMkRY^Gd,R;-K?(ņX]r$(=ɺ ǔ,L5HBy#b[6>ۗ};aޏwAg'0_4BGFM5DitWc5C^F5 xʨT@(zuIW'WcNtDxΘO!dQ8 lH|@g_6lӃ@kqFٞnĚյOi{ۆ߲yU,6TzdQ-fADO{1ݡ62%}gzH4.p) ^ p.9=Sg [(Uj魯0BOaʴ,r.ƼS2MuoqZ?vIK/~io}"[No5K"^N0dT7+a5ggV P< .\1~-Re4=t /l7"͒s>n_GVO`=EcbP XXF"'@pF蹕 5/טXnhq. aH{*OWY돧!J*$m/ۘSh]ji"6h݃S;Ol nܐϜS=;wԧ3=3&V#"tVh|q)Z7eIk$gT %~(ݨd8O;a îB/9#/Aru7.2Ofr8j Gd-'ޟSۍʑOs ^#ynaysTHn Xwj{e ]8eUCR/@`Ĩ)T>Pra2r xuL׉OBvF(^4M; +k)2I6r/ʼn lE[^#ot|qAbO#^g"c22k!1.,ЉF\`9ΝN*޲sy>"߹j($}$fcmF8b4?&=88@J|y?ø{;{S TxJIҦp W_HR^FY`m&zi(p혤 N58 aR9j`@;k󠂌a7QLV?N*+*a9Zu 3~w묔(|XZ7\JD?B8䌜jq MآX bVXm/֊_m'_nLtV,20k8mUbbLo=C09ʲEfe>Vh{żgboLӡ /x =y3k,ێM/S*Frc{GI4ŧcbE#jNaؽ/nyxorR2u|mՇ cvȅd6 )mG#mҜRⴆW']9@8AC!t]Xߦ8_{Me}Pu*VLeaGr0s_IwlՌ!Db=mF51:VȐ|]?s͞I )UT+fp@>bfV+i 4;h''7Ŝ:,#Y(?¢] sYtRμ0p#0@I.?_&eZD3T0ՀJ=fI7<M͂(s1 ܆Yp _Z L_nhdr;&>L#.؃ωyDz*ękV(7Pת Jh0GE-wpɜ@ FSL6 ;kIfLu hQY[ʄ?m'/!LBeiz=)m$B"em:2TnB(;< ~^T-rq /z|S( .k\O\5\m4Mϑbi=,yvo]ԅ c?FAF#++'w#r ? .0k7/(Y_)!7\xHPO:z<w$6mݍdjNg'IIz'X} ed`kDb_+|aH.m 3M/1:]D3?8ƅnɦHԘ4,׌5 ӿIYgIp-j텑L4P})2@G2IQ.\G~[8Breњ5FVC˕hǬpͻ3~;"0Uy?b%ju W:eHW_l.ZDH'O(QU6il66J?TbjZ3|<i9@{`J ;1o2ueKLT_ԝO! @9jnew\=e5$smfWe/bXf@yMR>Bc<, 9 yl׊1x?N s* ^6Kgh`Md] IʂΡQ.MB>WA Rի0O/zg ᗉ*\wYYE$I1c#I"wǘ㷟W '%edt(v,Q-]}kwZ~z$Z@^΍Y[_.𢮏! i/_~]P t;ϺǓ',c^ } z4p< J(tx ++s'>BL&|4 ³ۥÍwm&!<|畧bxg#ܯ#9 nh?zTϻY~YY JED}z^8m_ t\øyX*Rӣӿq凍&0UPMR?=V|o}ztR9"* B'|?}w{pܦ?R?꼍$*K*H4iy=jR6ضꥮf1ZҨTf5Ce$WӲzٛS.m:oA99AvibcjlɎ'dt}bmܳi i V)+}(uTG6$,@ߩQ5dL?ښcÚ9Qg $ !՛+lvhTgeۣ݇?.O;}x,kOLjΆ0ez*Vw\qN^B9VO2[Fdw1ZM+(ؘ=|DAHt:kQ]V@̃r 5(p4%n'4Bem5\VдO{_{v㬱$O9Re*u uszUEzFmpT|Qs.À7S*#-9p4屢1vx*)SR-@;l^fK㉬ϓŧ&f0 Bȹ$cnG)J8x۽w2K-}AzP7nY]U;ܖ"%/tm#_JVHiW,H 9Nj"u\L/7أ|m8x,˞"`"-2~59]ц+`bO+h; xvyr|m0Ĉw>. T&grX3C"+8@M)PKnnuۄU lٛ~ Y Rk'E.US3 cg;'Lcr{tO\M_*᳄r6V[Ҕl H=oFn>T<3xŨ.hKhyS;{OkԀZÒI[$FlQSb &sjwZ5x[>k"R=aT?8׶ =",ANоNkRq:{LdA 9B`MPL]ֻ +svWUjPbe GhR3}ǡlhBN|:<)j5vq ΋jcZv;6ϒ:5$-Vԡr`-ŊTKD< EΌ}:eG~#]#F=Ks*m*JG# ɀWNH,AùԐQꅑ|\ 2G6KDpHQ TՃFzscK"MX6O&ғ3ܙ'v1n7d}9rۆ2⣍g]5 [fe>fr})3 1RXi9dDi I5BU cPWAVu>V6YY4sOnɍFxe;uauL@jB tRU@r_=ER6Wmw`oXp # -^^o//$p~ipSZiuXզ֗O//XќA.0d6לk'qjNpFD?6,P7}2FpP9h5d|JPKIDa~| ?O-:Ah` ?Mĝc>-R)꩔Q!ӰV4e%uťC;k#% /HS([D8R'X8]he%ngShbib l Qh@***_XKUd{Q_eSx95cS-PIqq?^ztp;,շKctC[']U]I՚:*]y4=x66ɎԮ D;ҩ~)S 20w'*1#GMp͙E gQ x-bK|vZ{F;wN;T53C hx.ʟ+۲ZaPtHd,uq@ssD CD`N TJgqrN/Ǒ<ϯcZLAFWȌO$l͠r, wm{n=`;J%xV8U[75ٟyB-JHGk:Ÿ,LԇDہ9lllK~s|xPz${^3 GG#vLRM P{)GCË:bYko6x6P.o,x;yށ݉X{~q ԧ֞{,!9D^d*? z6H\*\Mϖ3G47jû.=3Ί +]K T>բ{!5 3VvV5n}VRo6x̎0/.FonͤJK~ k.p52 ̻6? )EVQ<;oW@xD6\ 95KHkR 7 jȈH5NO$-P:d_xFv8_kdαl_rgU!J+cFu6)0;`FHVo8,GlSy:lng 0wVbTe%$ޤ]"|4)!M"P XwO$o /jKaZAԭ԰wI9XE;2P|qPӭҟ'Tf4kt$|0@rHnS}3/?|DuX`7b8e#%3 9?eO-v$C^ ~T#%9f \;ɟ@h3LCT=sRf 7 Iz @"nSFЮ.| VfO&h%&TVM #^]8#]F\6>lbME)0o.`"kH?鏙dgZxD#*|NDJ_]*(XyY2["ӳP;J4jǽgY-8iYx`)7s]46[ߏe[YpHbw6?SwRe=tӳ-Nw[֪ۍ &e OU8U{;M== ElyD-w5Hi fphU "O૦(|{.Ai*b쨡miqa|i6"LWnq(4"FR&$>Ej&CfE9;po הfO0W@V!aosBWTwDnPTwp lƯ# c> nl,11Jn[`JZi *#+a;|0qF*A>#Cwepۆjzj:?"{*m *6^+ˇwu"h?cts:=c:NX"Wm4'%4_[-Kǣ~ŋ>l5dV'.CjqR g8M`mԍm HmJo(` D ͊a~B:˛FܣGW'Ƕ P;9U3Cg X`}2Ei~Uػ t0?%?$~r1[Խj??hӡC. C-YE P@14E}(HawK-73gz`XE.CX| $!|Pkn;r+9?2d?=Tʽ;=j7•3B8,h̊J˯7k6XzaeŘB4i hv>D6Ra.\UnG=2=ti2aT}+'J+<u;Z:dVI|yӅ}`KfFҔ9T2z7up.̓ª+g"xm>;g4XMm߷7ƙ~V}@6(!OGUY4槽Q NO/uC pќV=NqN LxBBZ,,iM3 iqz^A q- O$TAѫ=e5ճvfHHWtML֍{R61( IBJ*jTj8 P]L;e~yOvjX#Ly܀ς`禩bF6&PG;a:icvsvW벻Q Ʒ dۋՊoEɔ֡S=)cDҀZD6: k\7i3u]}&:gAD<г6e}%CɓT)q-7U"feIy(hduX=]o2YKMu0>7׭r1f:fvS+HwxzyY1BQ6W tSv^e=BUlXE{o$|Y*׸y/r!kͥe*W R#jKk>G)2k{a"=9,xsW6?o F+/qŊ1= Y섊xodLM/Gz3l ˇyS}ɾxUhBءiWKշeY=ʜUil@~%4e 9Mk nx ui?7͎݊TZRF(gol,|a>*uS.8dmH-?MzGbAX6-&晠P =1?JQQpM{a3ͪ{ <ҿqu܌!䱪Rz<9ήOA*x M4m*j珄.P @^ly[]tY$#=&Ge"]}\9B*L | 6GOn?qܘ-v~{:g/y,o>v|V,w)66-$ na>L^P2۰ك M#36 RP0o=#n#6}Xp$yJD݈$!A "OŲ &CX^!DZnXݗ>>Cְń-,\ ]%K'@ _CK[%'ȪZk% v>/ݼqqg6<2߼Uԅ LGWFe2 zPWy&)AœӳHm[\}a>ܥRu/p#FWo$%1XWSz0G\Es/ b_[5םl9K +?UN:V/|X"i- ^=:4^)CW:턾;&8Y?:/}utF8g#G \.4&cU:7&v1P`3a[&d Ǝ?./l@X+ íy",8ui+\ʌe]pBP]q`u>؍sR4P:sQn'2wb$L-MqDwBP4L/y gݸ ַi$!MmJkRR:ߓ\gzoA?'/[u4n3q}Bg[ZEA v<.nNN@ѣ+l07:S [ rEDc԰jA'O54!|" F6_ڑF(8dt~fߧtM)2.!}&P @i^Elj|@v~hT\ݼvϚRsb1P9[3h^Nb=gó8 c5T7;|"&'MӦ͜r'@B.'( u39 ߃ եX-oFS]߭ 5Z=nBްmo^n/M Kue.|ik40&Y@TT\|v-S"MBUotۣ C4x-_*~VAUQ\TԒ ?+8*`7IZ=҆,z QkROh .OӶDPsV-./VHQ<uie)lV6O}gtmeaN_G'2j Sb/zQB"ȋ0~tU]9:һ~4+sthw}*3OҹDd.XćL݁YYƖAQZ/@jr_DIowl/%|w%w3X'`M9R){`XҞiEʌ960 8i;vtyǝGSilze_oY.G'foI5F*萟36K2٭~_Vy&ġg}k0XLٻ Jn[[4s,/_SwL>JɵwI~fM(9 D{,|jTEEPKӨ`@v̯)>32H4jTp wWxQ/H $}ͽ=R0l|99[W-#qs,hR-GXY[Qv9źh€x t=/g'Y3+W=_9)8hFsTxLbHe@vrGܐqbE{܈@UA]nQbHǒ=K'OCRUȊRV#k8J1[Z53W)vYQTۊ&NSpS|DХ Zŭ"wC蝕/+myO&aXFm7SalLP聰u% 1U`1emV6dQ^ %[AJ9_P Fb)erAV~/+ܒ^Py*G-I._gO6!$(@.z' V_VNꃫ*h䤒s0,AOi_!z1y ?+ܔQ/υ&wΰdP.bG§ws'r{{EV+j;A5vhn ?iЍBw0ܞsm»_6›)L).9n焲F~8{v!՟ىJLl/~B]xOef;"SXF3AA0m_#auE vKlk/>ohQyt# ԍjXWG&``)QAv`Z͋M+Y:GWKTFbȂTV[x-_k8\ gdE`T~]q@+N~ (ߥni1wvy>M~\ͬ' O0(\U&J曔rEٍ]{/ YFK8-'h>otN`藶 4c2[]_4G!#N%l"@8WѨ vƺܖ\q{!%Bx氣ͧgr4=!y_:jW&(22؈y5TBN(8^QtظӒ>!@q-yu쁶qKǔuUv Zzg#|ETi[G*Ѣ )ѹ$*Զp;Iɏc_5QM`S9C_ &5g5tT)Ł> J2L$K)-{px&ژ?? v {D!+.,Yx尦[5Qp||H ]Ga+_&^)."] زM G";7t@zQ?ej"hyZvrmC{\={GZQv<`;__.kzZYGi.n]+9?Pޅғ7y)hPWH|g;Jէ2LpQӶ}srzwHbu'DpmG$E =֛#L6%za|k{k>'|K?|ȣ$y8721cB.+@xсgzw{k*{TnjUBܙ1Q]$I0KIZC%KzD i^֟uLI? #$?xz f@d`h;LX3*te`4v 6% g翪($eE vkHґ8T^c1XФ3%S*IąÇ <&Ag'P PYֿ; 'uGz_yv<€(ak$B?$I,W]fe? rj wsgkNn{Y=ݲD-:]dr]'ߢv`}4MkW},\|D%"LOخc;TnVY%1^ǧ/$ Z(QNZoP_dЅsFWj聍}rɸ blW5SW^ݢ\>CK"U|^82 !`Sf:/h 8v[" EoV3X5xf f+ g3{~,|EX@sL:H)Z'L~#I)M!Yzb)d6 s=AK-L;_$d'5U " 5似ETn]*<{g,ւv/Q(P%BIQ[OIKt ׾u̦/|Mv򠾴c`oufŸvl'CmzdEcA ?1wO5՞qa &A3kpތ#VR]YXHwм73~fO%1UCdWn^[K:4QG90ge9z\ր,VüExa> ?Q0 D~7o$æY.SEH#1 ynrO14i'oS%pt,~j|t1e8G`$h[ ?ыY+:(!p HRDՏc>"]j6{-LN|p})҈Wҭ(;I+OXtnfmC^%9M |r|>d rOtX,h,aA> vovոL[/kISJ<꣓LmQ"cحiAWuSNOLhy#(F홇2(+iX-qMJAddXSG%5|vc+KH"T_A̿n:\#×!xw(ܞM>E*U9ZJ#b}P`z- Rq̙Cۦ6Š6L0W̔Iiz$3y~s.س``__4MU#&83E ґiZz,2RဵsChҾUeɁ&=#0t`9TM%%JK];M1oiD~o]45i ;f/c>A1>d{~lRQ%Z[1aJB$x)QM}*1_ + LjT+SҡzqNMGLt)=ߙKKb# u . SIFFf-C/ _ê,hʘ58ɧSz#Q6>$PcS2m޺qaqYkpvI?SwL/"ʴ*O}#ovOoI,^.=v,OP%`U)ZN-Fʹ[2*[-ƊJ8VDSw&z?yJpK'Y5Lq͉v+.i&s%9&RknVv'FoƷ5.ذ?Q7ܡcOe&ϱpb{S9g |`P1TׇYp8*T0jGbt#M55/$ r[ơcƳ ZnE!_ $_0O+H Kh+9M!sRП$.j+ .T\87]H[ndD%љ|PP 7Fv*Y4tE0xSxg7b^Oz- a] 9h8As#aP)FD^\ũf/@e=IXnR%KYeLYYe ރg(:?eB^1g2aPv׍wkv[."jZ/ 7mX#6J } _?X ߼辀ìw•Wlʿ`0({mOXJ`֭Pz.ߘoz% 0"ws H"r"R ݍFa{O*CXT)Ԧ D#W(xbF?%m,y!-i,M.u Y }թSp+y*AZtĶHI}'67!mW ODisrB1M0X +v3Ky+q~E]GM9ܙtlAv^Wx9bS;ɢ-kR35Y p,ShA&F:M1[a2jT{'Opj<<kW2b- *bZs;(9%!,r4DOIx1~j-K:C ^#gTE4'U{&A- .[roD&Gp!BnɇR v!FP^g1~|K z\? `+9`]C_YEsJh93>V*ֳE>)f#wa{2kGuyb')?f9Ʌ0Ps Ttz$'(\ osKr&ާOd2|8Ӳ?udǻ;m<} y5ZUpGUl,tQ=JJp%?Гy_pi I3׀BU= gD577wB_m[ 4PT$}h\R&Ҋ ,JCYqB+Cm41OKBj[Ȇvϑ;p/h#0YaPWKJ:+QG5^YuI-(ﭕJ('?J@a$9#4k[x 0ء#?whcc-#N^Ӱe2 7^L{ nz5sr4wQӫ/zwP')2].SS1&+7f]Q+uJ6>VPH,n)bp w)W/{zF3f+{!Y0(/W3dؽlpy='Կ ~h;:;Ȳ [s( 1cHBq^RMhS#рAj SLC'63RXvM>JI iI*QAC[.xb{cxJ~(l1֨BWV WIĜeO윔 cT.لf9vV{@3|7%(#?O83 |f< "ɮ -h51"@+Sy6nJݘ RUd}+tKQ) |-/!J&3&fe) ɑji&BI{ŏ=As5llHqF2*4}#%謝匶Z?~i%(σk.E2j: EZ9] dA Hfp^L\bch 2^$y˓pјOcn>dmw /vaf'k> (4v8د!הaEIO;Y0/KSHùb,.X 8נA_i0Z !LiμUDT8Y9b@\&/;TF_dcGu[2UdVHi1p{9{![BRL`wqCrޕw+lfn"O?^ez;=`hnN:tM xJC ZWPT4cV"aɮtz{Eo Iʳ1:Wk?PkJߞѩDUҷL |T2˾_ 0`5&PnدfY.Vڱ9)y9?ڋQ"SN'׌є Ƿmutc utor:lv͒ #Ihw0(8\4NmaC3 (<WuxY.]AL?3Y5p7Cj2{eҚca":S;C='eV T6j5ޯ"P!#-P4N UYD%6鄫6c&Q:;]|G+>T5`F##hThT$NKÉ0M*}b;`^P۲tZXǰLQre2tm1my U|3):GYfǮ}+  qv' t9X3ޣXխ{{|-6vL cITkM-)LkPw\,77$Y0;(g;{a_Rfj9TNH_iOBh6?B疁5}. E]jEAȾPqTf}Uwӳ{JaDp9.-dW2 z4IueuXAw'4*9-qt M3Pp+εѯj;ph`bi{V3 # @U+ Y,  TG륂+1o'߸Pűb)4t \4B徇Q)[9b- Ƨ@hT*q- 1'A4}\<Ù}ܘ#r999X"EU7ppZdJeMc A.D#aGۍ T#H T1s-nTh`9qi\!h^5Kbth(㗽Zko2.ғt24Ӊfoûѫ) 80lRj7Ցy8VrX{$BGf EWޱ0nh[p?D)OXjȜpܓ^I\Fo3ּSDP./w jKMUY"W mF/~+$#aNbۂ$DRǛxU]kŖV8RaV.%E/+Xk)ܓFV_vfg&M a~TQt毩%̘$uw)g2y6{ rѷitPD LF%j2"2%Tupn;/߭gK2C{a'"WΡ A\ztVD`up}s&L~'>D[5$@ HA9a`幓KLend?ԌSmnRjQfbךnyyNx%؎cB\eH:~")\nuAc5_-ˁfIbLȰzd#K(+0r{1DMʛpIY3@ =q#,Dp̯q,#R?6?>鱀v4{OnIr&biE\(zpo•CCFE':`̠\WDHu6C ٸc޻r[LWc#tӕr4J~FPrn^ 2&r uf"`#tR@Ahav|vu; mocztTst3MP$2ɚVZ@O6yGeC`*¬ H~v. ίB\ޑV9XX]>Œ"WJÇi5?eBfԣ|n)xךM*y[qcy:D>-F,{9ylw[l(%3q=vR Ȍ8`(Jd t,3dYB6jW8Fna>n`4e W3q;NT0kAHב82}X`$٨. wxr2#BlDLep٫RHlIqq B"b܌&rVf|7#<{Y@= d0 @f9Y\;*cp4[o>~y)١M'˘>^;F ( #,G$ҤqOĂmYd V d٦xaϘiPnBfHϝ"wl'"YQEu!!˟ w68YYx+:Dj#
.3Fh$Yo_֨XhTOn@1 z]pr5f3A!)wͨ3Ҿ?(#6^7W'6׍#O-Z?$`l$[Mn]>@վ/e95 !4]˘οf7oYUٴkqA0WksL[A^s7. qD_HKIa1/۬OY0_h LjY]]# #Sk:[\o8 ,#AI u0,>mg fJkEnzr3Z(N3}T|0UEl%?HkZ(?u KĄ{2LC2k[E(fiomVT7:}o%b*3$Pe!"%%7dWh' :*Kw8ٔ4]eBB,q ⫒1`{v,ZƤF6k(ϫ`W??61}NSe_{7 |AF+is@Y0ZLy UV.tr vv;1uhC(v Gz"Pϥ"U9LQv\|c@_`ZHn"0Gu4\| [^[=+Ь_ϙtW'8%Ѵ]'3zt9|gΔRy%:J4RYG7EZMm g|:Fߝ>|Nݫ*?9Bt( 2;_fG@":q{ ;S#ȧ~ikxlCLcVCB|b/5Q*@|Gw]d]<#8]#Aly>&-~Ѿ,4r xHfE#z*1jēctEnPOB\@TY4QqXCGJ{N& Ě96@$)ڀPX9;"^j"nWF<BH? !ȄdsACdzs0n3CE@v5gՔ6}kAEWt2l٠v-]J K9m' r7|C#4ۑ.Գ &h'QBza)PJPvX{4I(Agg ꥅ:ZQz?]lgTqMz#@>7407ݥ7Qɨ`^J?oR{al7 Yn_t*+x} ,IsWt󮬫Eu-}M^/qio6~i{rh}#=lP GomMJN޸jK&"{u=@IZZ5wdʨ;[vVF6c5~uTF;օgKU٢ 茹ωRXC{r3cb>a6R(9_a@5~@4 !kd0\.ݫla\+]G"G0:,ӿČɄ vOGt ŭ;#z =4{?13R$'Ƃd3Ʀ$ɣM\/ab \ -+|*t⻝n8ɢrG"x lHX/ OYpB7Ƌsf*edrI7U;EKڵԛ'D:[rc.[U -%*5qKT͟d8m8ƻΖ;" LH4]*|c S8é92`M@j;iwٝ}*%n^Rϑ|EڸCeWٍ0[1q++E=p$ZM ?ytlOD~R f$BDaޯ%&eB)1[T6xbx, So`W"!M:TQ|fw X.Tx=EhҨo.RCzmyT)˫8RAE~}f0nGd`xHZti9@OW֪$vp[V ׍g@ܭ4^Y6Rz=ϼ'~4oc`R<}h G, p#kH:Sv`:h P%/iƾg.R"lK/|%WP}W!>ZOg3hG`?scU-бQ!ZE!-N2oS*wl3n `;ps5uR93Xγxw˨?a4sܿr6s'PG @A<xs{ (pƑWk秢":ቌQ.mufȂ1D"a 142+@+{ڙtDAJ00HE!cWx.dL 2A [ 7C<) Э-ֳz Bp#͸+.ei8,Y|ƍA[+BX\ffưT}QI=:rWbeL|uT~zMS !_TW"?SVAc5DR&fY2}A&j5߅DGᢿڙ:fdq ? iyVA-|MI/rO vSEu鮛. $xqd7[_OMv>Ս*EQ,b`]LMwuGSA#b/@l'R2 X,B<@xᰫNxI03F^$6SA7Ɵt?v;mΒ1= ] x=`!nμ1eobMS[Z<&pT1O~IT=G\7Ƴ)S 9#(d>q"pN{G?Q3EӪ ^j/4_MӤnҘBu7%y )P|U?6D0.Fz\#c8-$wPpPn7ePf8^@=1%Eg"ӚetMdž܂ƾ޺}"dM@K̙%=gӈ-/K֎X'0kSGx kXCF^3Ƈٺ1AI;Bp+mCi,]cS.;671~gʠ`QS\J7LTP\PDBRh=wݣ;!s-:܌SAUCe[ޥA 7 As0֭ߪy*%f j *"z9/,QK臐yh[X> Dudu 8csC@[w* mNhIhgBKS'w1AW? Qqgb̓I怷t* E=O܎% ]$7m?lOJf>IDZqG5"e-dɈQKs!/.ǭ+bFB?#[@=PF^kVDaIC" mC-xƈԃi!Z1צ4d=6%&$\&\3b^lGre"ވ$ t݇jKiA0δ0[ DL zW1J0*[tA/Ͼ-ҝaN<Dqb8 7!?T=6v'UKlՏ/ <+_lqQ6R4 %+m/g|(o }j ? HAdIlGp%k~Gn)2Y;Wus%r=E`y>(m&J,=GCm.SDjFeAYh|-J9[퉘YX"dF]ȀmF%nϦfѦ|pt\ 3 5ijoԒd4rRkh}M<17WL ~7-Iav' jQIX}[0r N@Fέ,~vQ 7鿒P0 z@B%|'!++(6 09ćTznCak\m*lfl^mWu@|͛Ҳ{o|W+Us yrlbv>օ3 a/P1۞$>&a q !8ָYz*wepOAwg|F"f^Jpq^r)T~) n [Ff089k[65&yŸtz }yE ':i(_ZH)U~rodEA}DSiH襷MDL.ݏtᐙa9/SQxX@(]NoevmQH| ǴI6~a]>5; b>`pG\#NWɨfB8febc;޸$,25^1{ kɌ|rl ~LBQX B? 0Dj<i?) RK pzٷv(-9b\㝕o!Q32RCgwPS~rhTE9$V+k.5N6j"3<9ҍ\QKN_HRʝ9vnUEӎwCSWV5|t']tB(һ^3g6孙^Mn|zHcrؑ kޙ<+}[DYxkN˳-, \NMXyVJK:= ȭfGsr@:)ߧ:-Ww)cO -N}g/PaXa9OF n|O̽;Kk K۩]>Bu@ѻy)\2@]EGѼ6JeT9zv5˾)J)x ԒːfOZ8bӄ;(|3n(1ؙYZЄCV, xur̚(+=76һO?G[7jIVSS@GތpKM_|-USGB5pY" گy|7{v+]`"[ҕwdMeb1&9WY jo$m56}{Lю҉0[4`D:7/GdLE xj ƚ6$N1^V9 )3P-L*92dcP5$F4A#+'uG2@G6dE Qvž66mG,(*;~Lѓ5xR8Y[u+2IʅuI œPo]j1F e-9?sQӏ߄mUh'%+qAGf./v Tcf`KBgB}Eub n J3H5[%(jozO|@SFN\4G PdyHmj=}³MWW Z9R-찖%g :,wq Uu6CM0'^PWTTJuۚx/KiK^~;yQ enLcc-fij&K% !*WfwZq`셏uTzvn& u-P SF .1+|ZbZWP-֭i9V!¢t (7&P9Y<`41'ɠw82. &gaE r*;k6$V&X :"j~ΈcCxa/t?O3!z$p׏9Pj RC SO*l{=-ݠ*2coF|CE9 =^ucїbдBPvgY G|v$L3EDk̷ {%>kյ?0§ϖj4_ kb(2֘S H zo:>zlXBYgڐ@ Cd}f"_$;y$n- +C/6'$Oew툋Gf\PW xKmPF I `P*& =E0 -ft,f[&$LEѥf0nkRߎ@Z̍[\`#Pe9 l>I4PVtL~~Iթ3]a(Tc^m=}i5~W+V {"nO";c,vӣ\c?Pع'o- [ȼN>9eVP2`oZ5 ĚDt}Udu]⁜T.QHgKج}LA߻ u2|yBN '#j? #Zwt?j#M"!4Y7z2]{U:6|_}h, k*Nc)(H>JkvsD&>%,wX_󍰫 ^P5~2JU'I+ $#yWVa--~wޛE%[ wm.}(پ46T &hp"CdP6,"DM*[# /)ԭ{Ry_Jck0Zsқo,V+y9%(̜m^[$K.Xս1N9T\[66,c3|ߢ XT):zJ^iE]#(ݛ<ݐz5_/#*G2lx=#BEnv>.'j Տ9 嗿m>v*4OoS8|dkư;y$2ŸAX2{p4b?\RZ?U.|Σ 24@ h˟ܱ BѝD?*5kk/^kDNNґNH&"'x^ v4"oeօCH)m$h j,pls>Kk$S؋,"Ph'ג%8L7<\:œ׿MNBgTt*(pq563Ji쀒ZaPeyt.8ĕ,sٙ֝N4Ş&ݲ~ߵJ/6S>_?.<ޚ9oTz3h\'_ ҄]*}.&~0Eq8@B~F|^g+2RjPjޛrjdPg?;LOfcGD<߇iXTZc`w szrh{VAG[0{4Ķf-@3=̝o";ɦ·@XCq!+]V?o'ը`+5 *j 14! jEKŏvin=K"@m,2| '6MkEV;toIIVNU8W?rF(~_A׉9#@o2fVAUKg$Cg@k@iCC2`HT}|n.] Fp`l|FZxb}Ԛ&O7Xip(x`ҴؐGLlzwFϡ? g*ԽfcsUu@¼^P!c@s1pW{! x,'b> KP>G#@y{DEB>E \vME&a%c6u'&] Sޠ,|"q&DVR%wc : 6kU4'"CKyiZ _Ҷ T %J]"Yy6pIv$B׍2j3obZj) L*j (83J@8 LuIO5Aףyu Bruxi {c}ptY0a*J05zpQ\1X{Iߒʋc+ݎXmٹ.pL$g}!v0ڶ! "/.[Yʣ6 xOfwpgw s9O=Frg03d? ȩgH8dzj ZFYv0Mq$T>$-! o$s`75LK4ձ–)amM:2Ӆ-K?ɣ,p\6Ó+0>!^2a[ЭqӋj_ӓi$^ٮGZA}9&$\Ķo\{2Uxי2쒔 ğCb8 n+r΀p'uu5`'U *$튏.}h~4Q\K#,m.O(/i 쁀Wubjo|9Ԩn71#o!: Qe$by0ZL$/ZJcv(1 Fd^'uםdUx媤H9R`(ts\zH.~Q(gd8~K &%:Ӵx]԰Ո"íSqeyn - ;T7Q}x {jk,;3 zVӖI#Љ`UPB7͹tkvMG{5r#~_1u/y+47"!GD.GOR+Q[ˮmjk{@5h-uwqkGtX'OM+YM_?돎m/,}G5PQŤ<0+7*#/{9]~f3/س=*^4I򠄟CHkٮ.OdZ $S{PԺ?S8jUjka Ȭ+G=%e?ucxT(84"@SļU@핦oԓ@b TV%7c*)ĆC\xpď]m` tQ&5/{Ite#-)0h[6DwD蘳-SE O.hFR}#8ttDmAp#Jԙb? !4e̞BD.GU5?;Ik%4˕L_ȸVEٹU:/#^Cb3A#_3AbMoS]1RbvJ*i#ɞY?s=MfoOJl^(%)-X*';|ߨnyG5XlJ'ʫ;oeW?ݣKs8#2Ye> C6蚞+fzϠ+F2`~f@{{-XjSx3BjZ`LEY, -(6;vcAX !(WR#O+0KP-eX^Sx+(RG 2<9QsIP$S[p{ܠȄ <&eR3zz_vW֋]5 LZ!#]b7#:MۑB,ĩ50}yM3njկ{[ |z=##Gc9Zo+fON9!|yG4K.^ɿyOR&#Q위t^j ,X?u2uFPj8t;ihf1@=?}aY] F4a1ccwZ /۹4仺r/ #y(#5rϳHd>L}%Xv/KNWY+%ґ@Do(xt)|Z7h~5lvIRvi w1DFaWFPV1:mԷv{ҵXOO&UZgHΩ 1RyHWI\rC 俕Eaӳ`Զf(Ҧ fAI5"W;24̜-"ܬ+bhWRr'2_ěuj(4%磹27Z8.P<$*Eh}#Sz֫_CN }}ɕjM !=zP^̨$7!U\9kGWfD[危_upՍ ԕQa!@qC}5$ `|]tvH# GJQ 0w\Ung 1qb@x $.Dl2yPGC)Y#JdeXqO~a ZAyr<N\nҾXOmv +eO/1}@ R#^xY-O7rQ,Ll1ERҬ"Lhyע87Gvh D,@nt#In`-ԎWO oDC;&WqO DR+͉\H[4V\Y(#{f#{[.Tf26{+<:A)!~_3nHP``e%,^-9bz2l3x^4ZƜfD,%W$& %3j{("_M@DFX2s) N=֓H5mQr>y~sM\@'~:= \R#=|UD)',.݅9tmE qga݅XnY #5pYlPwkwļZGY x5!``E Ȏ0I`A$")Ҏm5M4ri B詪Z${,,YRҴ1LG^yJX17}q6ZL~ y?aa| 8E܋N}'Hqf<{7=&X 9~pDEIzGT8IL׼xW=œ. _e=('/CB2!l7_g$ a1op_ђfK$𿢞7X vZ͢w[Ǘ֑AK[]uO*.z /।s_Bc.Qf1(|#@CQdɛJFSZ"Vd-xuTq4bz0 躎, Lv^UR/ɱ%ƚ2tb,ܲ c@["9ӊLL'(?puf6\ux;Oi,m2 Gx:`<"5gyG"r 7‚ph[ÿXmH kДsöU<gZX4^ TxÇ#]8qv4%jbirH5z-eT䊢XxkMzPe?GJߘ{wvt?؛A1=#LApK>qmC'ۋqp"om9TO9 U?yɨ3bQ`:P~ٞpM1sbam˾~тiM3YX%1կb 쒪׈Sƃ6G572*$ kz:Ur#͓њz?rSF^:rD$k}tÍru` .u+~pbs,`-ֱH9V\|@us/;ԋ(k׃ʻM_^ m({yktspqdfIE}Nu n{-GԆ9io[F®B+[T\|Aa߰E x&C^\ tbFfBZ`V>]#/b@>X3B0Μ,+qC  H%&8Wc+KT+KDs2 ~~D;b.W|í䧭]a%X\zLUh7SIq[cy_tkEG!/% Mơ1n *PCz':8z3M-3܆n bB'#`[J{nfOm\!.3_|}Λ3$]l(%/B-ZճG28Go> z&r@td%V_5kO"s3D1 Y(ƚiK>}灗Vep8}?K~2Tv,PK(HZy rGC3ݓ1;R2Q5ȨF?xHӔ8U_j߈![ rpL|eUqubĒr`Pc&'3R4S7ۂpmPE'hF͎D U%LjRtGY߰נlD=[r{nZ@49MajHpqMb~/ !b9$z\ɿ{(쮱^vΦ-n/7G.R74Z fprVj*PSĵ~juWͼ+ãYRQ cOȑfȑr }+0 z]/|KaOěì AM2l/o-Ե &Rs4oj\3BE3 ;Vb;cx/U!+ 'vdV/;6VRk"ָK X騠Ʈ?DxRX8#!gQh^6j5 zNw)10'yyj3螙ɑOCamH-G2\hKq݄0+,b zpVռ8.0I q`E1ZW;zz #uxx;o~/HQ㩚% WppޕXQ U!6l:'U,C T аdmkX |Д-kMae{cSFҦ7E'ނDv֐d ɞu|hT _oΜG[m V7ݙ+@?jayo֑6\3&]I/C}^߇^GO@f1bߗvTwsm;c<@EM#,嚢ЀjVS?VCˋ8 ʟ_}PK)۶` *,sXmf*hXIݨn&/Srqx9WɕSLޜ(_ThM{?+C;F`OGSNxWo:a va>6#]Y*,䶤o'0$XO~'VSx޲m-38hm+Xpa层T"5'-3(>__BznET &FĞR}/JmZXn4,^ PaWSw^bP?綄аFiő-EEEG 4 B֨*&p7d+8ɫv 3|pWT +D< k4F0kDmy(x{Iٝ,p&{Ab(}tK{kO"x8j/TuY[#D2/K/%emA)u\}nCA3Z1٩|X %=>1 V [~ hX7SIߠz#s~@kzD=-.ϲd]x=`X[ɷgW1R᭣6Qy!#J@rƂqID9U}C\h9 1^\iw:VďW]‰(voCW:&^;6=X&oȞZMԍzvP,ϞѧW7SóNwZq+ph fGiiA|U |$g]&XX3Ң7)Rpg~/6 #W @_C\,j*x`34@A|Y)gKEjUԅhCbs>,L$sUj"IUPR1GVz}0¯lp%̆mYҿ\(n1 'v8smq7  Yb6.lkJGk@_OF:Lm&7gt 4)8Zi2e) zD껸j4H&GĖnUsF.u/2K !%.t:AR`r;Ul{/MEDpDuxI`hZ/p&tXYZOb1@;BDV V|FيssX@)"vK ̷D1і>Cn ӽmE}Ժ PnC^r3V) z4ӵ׈OoJkH@,?Ʌw  Eo$g`o γi$m!{ M|T%b5t 3Sk7P#ֺuYo/P D-2S`D3r4Y]%fΔC+tĄ>h޻P>5r- VU1lU4ֹ,#-T?\إ(~r[ScI}a_942 Ic֞^&&5뫯=l$AyQȋۊmi<_oM((hzgr1ѭf-]Aw7ĮJ(eB( T\l6gurŸV]]`m{3ĜQW9Ȼ]X*ϽㅷO %ɟoo~@{+ga8 P2UKna?y ZaLb 7.He=N)i-d?oCqh#aG*)J}pՈ .i&ٕO\_\WI kc_RS>v`#W|iz6G˪㍆R{*#T!./45vk9џ5Yꫭ,]P!N21_|g _ &j\nKS81O³@qYX⬏Dk+IF UL<&c RV0J,'&cVylC5Ɓ|";!>8.O|W'^U lwX]s a-Ե~QKִ)SnO^ .7i8%s=TpP|`6{C&!!?7kJ|(TFcӆ17i0&CV5&%kz JYeB¦"e{̧2}"'_avhyV G J5_ Aԝ;?W`͌3q޵yEB_5oϦm^hXQM]WwEu퀳YP6xP-R)aA~3|C3 NX є0\j+KcRPjk[Īzs/md?GLZ3tu~kC{jH?oK8;RB'[>RPI0_>)FlE&<{ ' 愈|\|ެ0M<8h_&oρ;;XR#ϱ΁"\3PFo]K=M5'Ć#v Bϵm[D!2qΪ\UZI[[锡"c: #8xoq.X5b>[ޚ'OPbe'b(^ذϾ6J}Nyi3mQ$4/އе У`X)$k>UdH%䔋Xo#el,1`8T~syLk"ūGuV񋉤S}-2C^v#Xף\Ty;k~ib 9q21~VeoIdϏ.9gRmPa7vO9ЍKv5ڨ-Lw2kOR[KO3lK\Z{24*E*Nj$߻utmXь?}/SiY1F,c?قVOJ,Z Z]{?Qʑׄ}vUUP@~f$ħBƈ!ϻgjQ/DtP1U>g؆Wgl )!cn•S^hs7Tv:]sܚ|K{CTmKorg!ż%U&hJR~jS\\Ng)碹3@ 4U{/ *CW9G_֘5: m[@JCtA*9_6ctwș͎e䈐8{(X|U_ y܊G8Gq̠?[W$T A)t({887'Xc^.]Ha8}>;-oh+c>-w&H'nmTHZR ~U%ְƹ\ai|†<_W 7}yJ%U~=^ŕ>9_ġi (w޼LR(Pר!zJ;ʳ g@4/n*}dg& { bmjz7]< ݍ?2Ο UIד(vT2.oͪK[RkN?>%wyD]: e@\V.-fJMP=Åo3aO"*b]y:$)$C*b+n\90L9 ,DI ,,}'q-V;7*<G_}S0Gf[38*B]5Jێm]>\.ʥP732h ~Hf#Y U4|kpfskdd2$Dl)_S&oَW0ۂ$L!1^:k61G/z#' 6$wJb~Z/s؟eُ5N:״lHT#'V̀hQ-5k;o㎲T*fƉ'ء[Wy} ze΃5Y}\P 7DŽx8enL 3r9@˛C}dL+sQ>5ee7MF>v7zSYfj-jΓUoŹ ^pNOMJvn ˳?op;Id 9 "lk9mاftISؿnt= hDLt]`c y RTr9e&c <QM R lEn/7w ıQO}#Ma~΢6ȝ3<WȀ5!0,x"_敌+;77"P ԦB )e0Uno&ߏbJ'/taB5C*WVY6,1E4IL(WK^-b bC>C>z.C3F%r**ܻ *sd[ru"wγ&NzsH^jM2}À~)C`SzjM5:n=ruxFDD \|f/,jaoekArq 90NRmvM~,Z<̈"W{0t/cYQT/tle; 3'ݬnFpN?Ą ݩ0u4yD!y+rFݽL "Ó\@{HL5Lba7]]QG;yO}-roL`ք}y63FaS zRƴqWbE0Vl.zNd1y71dʎqnvoYc/t TmJ[|ku}j^F`KoWP;*ŀN7$JGy٬[q/*@:T5CR_4ŌgfG5E/.ź>IkB; e2 X# I=5k@i0Sڱe=b۩+wna`/}&>oXej_ι89 ns Ga?g&$]0{++~&Dˋ p~߯ t~ᅨ,VJUx=P$n'ڃH} &C^m3ŶeҟmT\rsy9+!;P~ g-H&1C^cwSiVZS*~7xlt' "rJ,ӫ+@@KX2 ࢸ|vHgeJ?Ĝj:[yHJ84I!xKoL1 /?jkpzg§^dL!:bzL8CS&lMܜ(1yq 4秂f7nV6'.I'0z]|՝SC"Qݳi[IoK + OA|%5ko= yp\ĎѮʷIr/R<]Ku5jkEzVmAM.3@iE; C(‘ rxFġAD aɺZV.LiNaG̍gk(3VKaeow},fQ>(S 7g88rhDG;N,v*iCc#jqB\k 4K[if~k*$~Y)\Tm[c/eLW%:Pn:~-ƤGM%"A.sCc T!btːsN-.]Q)xsn8 T rƽhk4mRV>jus},}E0&zykcu4ˌ3U_qA3Uס $sv7]în./L-{wz1mGK,]A].%KJ+p 'uJT>- lA3iG1KJr>Xkwsޝ8cm% 7/vsڂXpgsLЕe/[WMdF.Ǘ:mw4*$`Lyϗ)/]TA5fnb࣎0@C5<-g(Utʘ9>nH`b'ڔns"[҉;86=Сɜ)F/":˟"`Ya?*XdiG_'MH`@5z,Pc(G1*Oԁ>#C*Kc H Tٯ7 ?x=|},- 4S[ۄi"zUlѕ@8D` <ؠ2KF9W5`5H]A/=T6|9cFu(Ե4yԡQ0$pK303 ցe?6WaL9Ex#QYT]Zimr+֧'p)ΟHzƿxC?j'Xa`ê9'gy)AC]}%Phc5S{xՖyar8SHw`ɐ$Hwb;e;sp:{>׬[*f/} !/[T2*ZR}dm#{{2Aw¨`1COͭ\I>Pn7iHZ>HW_?wIp1hV@ fh e4O"O ж7c5/mA;P4pOMwDU='uT>Zs0@訦.hMAcgcTی`006f?T]S;&6k@>r7UgqO#ъnmߗzlQdxeFۄ \Y*ʅ`TۇAOΒu"F2ݖL _V=bLarZp@l!|^b>gv)U(&ϵJKhB25HPRD ̑p_;JYf"h][4)SE|?dΣ^=$EMclÔmKbLH&X0IޏZ~ S(n6XX1ΤhG O]wh8I81Anu0L|u@/ȍ(oF5qmظꐾ>L8 őA͡>,6iaYc((R#7rݣ {qw,8[/:*}^[?ear^}‹ \(XwIhv[|R]0[G"e 8ξm $*죕gQAtTD,Lr"bGA^k*PN;Y!&%F"4o "9c_[~Ƨ$7⢏R'Kf =#2S㐥Ļ`zE BP;\ +#+5[Y31\`Niע삺Khq>y'Ɗu{,Li0N{pK6l!#0.srܦ /Aև*9Ȥ bfoq̜м9u ɧ~JP,;H*R#̴:?@2t=ʚ"*>e%ƘpSRr957Jd1܎g*6Y'uUů lTZ:,j CGJ>9b7TIA?ļrTg67/N6Ru}ŮDRb2]JH~xu!9i/q9i {Z0MUpOJ2l#ɗZdW'z;%|~AއXX9T.TOup5+^wl 8դSW f7#՚(TnT9)aR CJ>6!8j>#I"0[ PZ%m?Ewu%ڳ%s3q l:? Vzq{/mEI6~=΂% HRXkR "~|@ΐb/z=VQa_$ɨ/V_ká舸aYuVLr4ckzﷳ4J J7Q?)Ox8@ +UL9frxG撍ҙ@g0e?@7whJ<\.my1iU1_n}g3uL!JlP gЗMN=>{ :Cz:fҝ0|\\wn3[`}۔D8BP"5@Cqjb"9"qa1>/7#;Wͱ(z ʭ{Y-'ZXZ:(-Y}|"ƾh]K‰jɜ[V^")1C0!{9)B\wV~.->^]w7<у} zFydV&+vϥfܐfI`>w-;8hUe N$"QF$!&{CSJ8MJׯI-"ֿv6 cxG/ra8XFUHL6`$'lX7u"GJZrݜ! %xvM&VQ26=X6 _sHgz/G7-_ :5#tvޏϋɯ]eۢ'ΌQ_{}ffi%yt$q% *ng-q.| ]:ЙLxv™K"Cv1z}zV\d>Lgۯ +WaDW[:6ZG`2 Rv W ku#'$ҶɌwGtlэ@\ v prLҡeY=hT^uɦTZ}[ӲW>FY"Zѽ9ylwInQh~W1͕*N/|Ugyho(EX{ZK xzB\žck6MS79YG.`ܐn߆WBѼ]8ebæS+>"ޣ;9bXxIgb&C~nM ;;ǴGYW27H.,YЩ7R$X4 9ӓ1 d)hx1{0}sopˮ&6bXcrћ)`/Խ!3-WfML !qfZX'2 _5<2˹)n{ȵhfLt #:'YHnv'QWI^Qu_5{6VFVr۰ئK3H@_mxgv|}&A;镒>jyz"nkcp `(!=b<ؕC@rrn8WbҮqR=ӜebM :${S[)g?FU"Wr`/խ2ږ*j罜44.B|>xM>ZrTtQN`{CI|n9D#ŵ51])7$Au*kk{x?@k劣EV 9)iV႟'=Fd)ςsV"<|RkMQU !9n &4BC 6Ϭ+A{!TboP[F|}mQc(E/}/˱٘Z.Z{rue  kť0w :R89|Mt:IpakS6Usn.ε"2͇U#jfL\0raw/~0Մ|8F~?JHQ:syM+e7ĆހS5ځ3Wwd")i"ƽ̃يoC@O2I[ Q릐.%Նӏ~ _G"{{'Dg?ߋp>pKD R')iy,'\>?TʟJL0r].Ob0,sg'm~I;JiΧ2Pdr"vO{B5I䬂KٵJ )BL3*|+%{T( }bI+=rɁn. 1ّ;UGt8 9ȗӶt'vQ绪W-Ws dT)-Z@$7x_Y= ꀀAz-I̊wP*[ ̂J V Wm|RJ ^&K`qY!T+O)ʜ*EQȠ"b: ͉79b&U.t~m4QvT^ֿ$n>P˖薚YI^HcVJ֧eo`ym҂?4V_ǣzZdi ynޘL# {9x/.P&̔M'6R ϚDlWc br7AN Q v'nkCґl.etx Q@xLD-GYH2GDe#yeY63yEN UI W9o>B҄s휾ax[Q+U+^g7߃l>VfE<Y%Sb ~jn{1l1:]]qi^65+)Ο3JoA7?vEA}rY@=a1Хgqv>LD^aD/\nuzK㇝$ϔlԌѷK<wtFC=nO}ctDN>[1 YϜ2HU9 GC*~eˈx~Wc#HXR3 K|?[D O<@Z?Fx} "J_TJHa0 :;EN;  d³~~19cZݶ` 86I/P?hD=E6$8,:d\`72H*C~UDGD32!0{sAԉqI|PW2ܛ~`bFΣ_\{k:إ$\(x<#7j͋Is\7=sӡ:7Xl]#=nwH;nV^c@LQ;w/^rЩ֝O.UYa4',(R?|BVi o{|"zrXyGuďcr 㷻 V._]ì7Vp` >q(]xe `[!2QY@1 f?QK;Tw< KQ>7f53IdWL ]Ղ3`ciJGc*Ϟ(H>'N=ISeK" ){iJcjwr|WlYmDDI~qWߥ;g}ha53ĺyP_ r{Sm<;Z?`:B_3l!Hڹ5Opmx:^ƴnhN7V@<_p~l Bk/9hfy0wvp{ -WHDj4>c<پI24$˱$nÜ.jBT t]'<`foa;>:n(H)M?ߟAr/ u8fr #+`&У3@R%1OYFH죺yp`QORmQ@C7۬߅,Fd}k.B*w3:!f چ­AOywF {gL#JO*a$ eLbBOOHޱm{tY KyñTiJPoe  ~Ը8"Y](<]XBDV ʠSl~Ӻ^L|^ rп±4k<)4! ֤ޡSSky}{ˎjwIU]^=+Ną;ʻ?RM )oӧ4n<] }!ݨ'6C#騳]+ O . 7i,?URf1αc4t^_P32a %mZŅ.uDܺC1!ib'-Զ'-o~Kw &<M D5$C qph@"|kE%*vڣ?K_ SffIhG~&z?bAC:'iciERƀ~$=uX<,tš/GiM(>WފT8o8_@ARlbh8HR0F =1-~Aӫz0t5ҏ c0r8Au[xӻX9Hg]j"y!,UTH)66W1D}Ɲl?m Ӷ&dp?2&u|ގA0ddd Bn&[Z2Jw|#G*lT&vq Zh96Bp\@6r@Ho+Z.BK m2  >PK.mA˺%.Eb̡ 6KZnD\E۰I w⩎?^60q˅U2YVTfޖn)L^QFhib6݀ctsF';Ү!Qe<;.)I=j$xYdR_{^L6{]Nq _k9hThTNڻ X%TLhжJ֍Θ*TI%JOgG܂܎&$S'x~}_{.²x$3 6j 2O[wP͠lNtҞ)D BՍ=*viԓ& Q,w2~jtv9OAܽ orǥr).댸܋x$uN?;._b#ʰꙙ7wBfk$ WeB^ǫP{As-cw,3"Y]Sl!;7{hp)7R3ޤCTHM.ꖻB04^I[ggAXXi CY{\HʦS0;h||mm~#4g 8Cǎ-;m o65SzEt^.^ )q,Ժ\D&Ҹdf1mp*7êb潤yb?v JɫZF+'b t4vyds,,֑jYs7g|1*=;rMK[zA,'W7Me)|DCoC}ȘBkB`6I8t(f>WoR]0$o1=Ӡ%8 oZAn0x;BlA!"'>G9ʌZsVqCINZ8L:ԹH0֘P+as3Rjk!"U5i>G2Jev]@ؠ*\AXQW}աO[L\Y!oB*gw#a3x_h$ V ݝgH)B^0 Q:Ip ĴsK^zOTLq=$w'jѦIV|)OEzNJ#8P eCO+LN گ;?sH-G.H9ΞDjpy:Opy20.'LL(Tm|!)~}ZkvH:_JGړ hG8xus qcJ5zE_ǐ}ε AIC-}MO\sQKBj൫ošR)SZ9:-z-zpC@#e!ÏM_m~./zO7'fU3|*.ʺ᚛MۡiP*E~3ytI Zʕa0c<+;e1FC͖=G;4eCl6V?J$9]`4s{1MG => d%sJol6'׃~ÝߩvܘLBH72*.zq]BT>q1Ep.A14⋲/~Mpu[MpC~Mڊ92" ɨuCs8j2nۛR<'&\AftB5w;2(1 Xa^7 p݌ 4ɉ+!Yiq6䈹 [;*^|Ċآ魮t}6{s/s82ԏ1/F;ޙs/!&c/8ѲCIe}q=`&*QdBMl!09!086mk3f#izVxWV^38z#TxHo 469 тWk}ݩj?^9d|~4x+ ʧOmR.vk*Ʃ!)o&H[gaFnd1 Ao~ɶZ-{§r  "mu}MP/W<$'A#44sOlL-]E42X݅ۊl{~8MVXj{|OtB;*b}@9@LwAs,,X0mi cі{/cJ\>YW$B,cDmiֺBc K^5ǵa#FHčezWe `Orid,[+nKOeOW1&FANnt$in@,Qջ\%czKƎk#*OS!_9J* 0C55.X>N+ 57ib, ([w{5]b2ڨ1x5 Iр-Oe&n:)oQ\i ,xM58/.H mLYcx%[?.$9zf$-I|w%2P̦@}=8*'0eZU@ڜoE1-ɫD92~$^4\eVMo׾wHD&!kDzS4*^5]GQD,VOv 2%|\jLzF;$gE( ǒ"YPǏuexހnvI+=e=αAcYr vU.}f &\ݽ ڊe|r~F{$-wYݡa&K:PjUͥwiSrE@2;NdN`;!QW=BM-@,3:3u?VQ(T n-(>h(En`^HS&਍PCBKwKh";KxR<:|}Qoz~Ы1RbI g; jo̹j)$5 LP\EE0`jhi/wMMP6F%~W^ M? w25$>ZXJFI NuD&cff~{\4 x*'a\bXɳ =y yblXl\Bttm;:0bEž4MgW>(ŻnuLLqNq8|\:OI)9=#g-ϐ9C#B٤?0q5^ z9 Ryd`O,^U;C;-b'\n0ؔ",.|%[q`6@nȐm&nxyaD+ꨨwҶk  XȔG#rճN&]7*6jeu"76EG͙=s;E$AFD([4GXiP9lU7Uݤ6 bK:sl|q\jBpuwIH"sX2&L j9g TN$*y l:n+I0e%G|(ZO6-mcFsBV1v*b>ErD\=gݍ(-\=b'wO=)hk!W]`PL*%t)S[ BTr_Y3 v7\~0 vs Qbr`{ =ۨd{H'w7Ur PeJ0 .HEA t\}PiU~kHKOAPxxX 0jYFrjY5}rߢ$%^&?L-Xo8>/#?c]6E;sͷ)Uˬ``Y?!k TVm94ߴwZ"МEcxo(cdǧ &j}v96WRY0)~ar/N"-赍j^FXe 9*!\ LC5vA򧙤-WHg⹴I؄zR_0Y!3, {.` cxCHR^H _Mb@ :R$zmo)>!GƎ2decUl*۾m,Zd%-E!L$,@YN=oއ]Ǧ!aOJ^̀wJeO^,I]e".~2I*'(,Ծn)SOD,cmPTSG}\pX9ҦX60ΪJ.{M#c+C4|jq|g7 7V:;Ivvts{o< ץʃ3hE !fȣ[ӶXOQ[7yO(+($'c60͈1Cod[YpaaKTa'J.! V$;l Zw/|ӧ-\#֌ Fh9v{n+͕Lh Ж 4}U8$T kt cb#W@KgYl4]"LW sApy* 7*+)"ۣj36:A8O֔f/6Mˉ>H޼Z(G֔R2ޜl/dcXyt=B7԰8F6cſ}r "ɞxkR=q9Ivx_>RBu:KHcUs6+P {qVSQ1> F A A$@4H*5A>xlXW ~J`19%-PCAnܪ ړHIzaոL23_TuQgrTZ,VG\hk1՞οv%*iUpJ2 fEP_1H4:`?J?wÛup=hG`:C m"6+ y/EFbc%ػ,n]!!^q@um]X(jMnsyNh|CÐDC $O)l< R[Ӷ" yF SP(WXxlKrݚå5#8lՋ4q6D(X[|)KɑKi˳m;Bb@Q. ?/OUL;t%"\;N4QGğIG}e,'(+g<;{X{PcPvF>>T?n˾B>Ivm[}% ~범9=341 i]+ evc)pP_ӱ@܄y"XAb<(Gz@h6 |7٭&bѧzo$ e8h,5)ي^B4 шC;6"4v$ߖ}ܛ=Bw%r0 ,on]wky)dtRD6GϏ;bWᵫnEYe7`5Cl5(x9^BnR4ɃCjr88l ( Ҧ|UX9IZqj%Ά)oqtOC IM6Wզ%c?HOu!XEۭ]DTpeoo~Mrӣ/დ y>)ΜS%"Zﵒ_叢 t}/g~\`G @ο&Y)B+wfm>#0-aV5 (~Ҝ.Ev#lv= ?n7։l5p;d}UnP5S? 0r1g'CהMNg> qQӻVn9M̗^ 6uefJW ޞy|DcpliB8Ma̠hx3Ŷrfܧ`<溨MHR$&FޢS]Qw0$L%J]Ng-Yt1`UN1wj²D^ifO|JȨH5GGC5Mm)'JqйwhO p;]~kCn#,[ 9m @>|x ٪'9P[}x9j ,I&ûF댖gr2}l#+w$dd_b2XDk?;6lI+b9Ev]VW1 A>etl.f:)7icw{1_e-;<(|x5sK/K(c{3V]ut6p9'Ocu/khO͙׋ IG pTgiEb^0Qn~6;ϯM > c1 o7j.rSAuɐ+n#Y t$ip U"k"œ:?J"Qa>Q/Yr|Er(WS!#K![z8YeƄYez@;K˾[K@?lAA~j|{:^1We2krg*^3{cVVYFB]v<q/[nv ݛmt[c"-:4O?b{[9өo YGp%*Ike곺lXއjUݚeVR;_{L"|9B_SƗqHb+PK߆N~ݱȲ_r@i˭ܙmpī:GՁoTU$*6^q:Jm0YYPOkݐ %^u k.Mj]~`˱g?才bZr<$qH<㺟Mvl8X‰P4 &MI˝!2"p@v _|07-}(k¾ˣ =wlYC %X.R\Jfփؖ}?}/<=ހ$ihtDCX沐p&=PHWd˗8lU57Ф.;a# >\iB)?B9B ? iIu=YGzÉ*Ly;]ZRGx ۵d>Rn; tM`l߽/7M9H*J*h[i?,e~O F.b( p ho-,\ԗ{ߪgu< .֥ kX'.-{l-.sY?p VsޥД6ܓE 4uXZO!EegIo!_6gp rz #h$!x"Q<%Ҝk1:"^ 6it:1]McpQ=zl%Bf=1][{C91\u7TSmXt$B=.RO&ttm u2QtՄeB3GZT4ži#nQlEX苠.B0m_$nIWPd{N'K7V6H`U Col UL0kOhmaxSI:׌l^<\{jtGjpcd#,/ƪGNr!"X+wNzHm Juh#bLQ}X"&ΐQ$[3 [gMVm"֜$ҒBiXqTm; #O`ek3׋*'ّ+[ A\׌ c>K:e"q%rVTU1D}I=&)cj(>0?ȋR7ő5{g!nl6 zyNS/#1k-& ? e.Cϋ,HhZôZxDCY}1ju!+pFKwx,T?\VP6vZZzG Pis *d#(:lkƐ)]b/ \\B,!}.`{ Ļ9|S @Sלck3i. I,baMj$@`Y*"{&NtI Luu@ k؈]'xl0@y>Iè85꘢w{66LUOH+x*z"$ ֈ$bi5ZܵNA7q$$"I?&Pl}l4*.ςHug|6>#@@Fma^}` Τ9<4#+7nK95==hi\рo׎e,d~~~֯7k::z %>X0-,-&\^  ։msy]\ k i˿Tʈj{6fXhЍ%9NwN`h[cwx669u[Cw!A".;q\rQL+82o *TvHA}%fBa HuGUAk_qچ59;ATɠ=,Fv:0ƒ4=?ud/z 90~F2QfjdGa`2 )І`R*FدO̹1ZhWf&Y2r{־`"aıDasLiՓTE\F;y @XP`N2{P#4P PzP<jNgM\Wdg ؙ%c 5F lsytQ)'?!IU[+\=$y޲5M 7i[ \ ~)'ᮠ5MWCT}Hk.iTk|0}lhƃdj*쨏^ˊ$Yy!lȉeN3 ]*3/?F8P@u¤IV[`'XE#CϒJa8D V-e3yP4 'aXv婽KG WǯER4ö:,>gcNYAS$#W;% aJ0wBYZS6|s* MEMrGu膁nSl4jVq+- 0M̾W`;G uHcY!- 7jt̕6ڗouʮD^N.79,WM z=E5o˒>qQRMzӰF]u w8I ΐ(?oA7W,Ȼjr#4¡c5&7$E,a<0\?,ҲFN e3KA읭86Ks-b3Tajo}#Tҋ[0\X~rLF UOIW veBB) kƦH[l2f1M^j^э%[$}ݟ)镈t#jyT&^uYN0z$h:#y\cmF;ZT߾6L4:q9Kwn9,CT&C37e*rgX+Pev;m˟]`w3uLĒ\y&[$JtU[{@3wg1Q0جR KǣU>8,$]:K*QHd7݄cO;N/#W #> RtӊΔlgZs)4{*KXo5~ imw(.1$;Z+9a%$48pxh:3>eދU/L T6%=GpGe(P 8}kx~8›F8H;v=F&bSqw\D捚uu{VY*8OwE fn*|`гt}Cp.ih&gYeV LuʺUAluCJ^I3dg@!Am:LƃӞN;4]9iMii2 :Ck ֩l`(^O< rOȭSPLһigVvdr2"EPķٞ|>[cQץP|`AԵ-t*NVXi#HHK?ck)_̋ec.#o5zcdpNY)U!"k︌nR{6f,!ܴ&Pìɖ{'|t9nb7+]ֵ)x0Jz. ڐ8^XS*F?EK+c}'8h&{Rcg"_SUόoEEJ-8L?Nbnϋ IOIcE9f8k+j { Rzlc_=#oOv`zEy[e@с @dIJ~ (Spndt3ipQ*8{!A`FSim -b4J>< I6ǻ;zp$P?81MpV^/EkMqVbZ8M6RwbV-W!p-3YVkUڤWcCQEg3Jп|{7ُ2v~dgh׫UU$tGF,JxchwoP1AZ{5sw;?Ь/Uhh4T$~fC,,<>N*^F$NtEWHOkE'm>FHT 61`$Ȧ}B^*o&WS$e SoMC6e4`V54àF珜*o8#<6Uy ~9n^Oswiv dp屻ZlkʘS]nS}{ae\-v獛s+Z+KPH^tZ0x LL" O]3889 #~ ӥZ0 KyTNgf!]z24SU"@lu.hA4\/\C诀Z%ZF0Q{Hkh&%dؕ11\/Iă`Jeuy #W3-O*l]aՐԨ7pKhR 9-{Eh¹<S@0}fݛ Z&/# pBWt)l\~ T-93se>$z-deZ3zX kBc2̵Ci1wQT"!H%90[efb}qG7 /fa\恱3<?bi> Kd7' n?%4҃.qpb{j4$g?8ȓkƛ u-M֤h/%TwָZ+Wg ^b ^\kשœP)o$:J4mmuogg4X5L2W^Օ븊a ,Jk4TY Vvʓ?&WcvźQKJo(mB͗_+jpb]y"?D, NRa2T&7&"pq Ѿ{& =@~Oo ,wnYMq.]Z5'ὔaFdr?9z)Q.9.y~b.6` lC>TiGn٥tfe<HPrbldY925sZ4] ;Fy޺PBBq.=`p#4`w惊^1A>*L#Ľ pqςoçmQ4g[)*Z6$ WtV(7i8̅4@HKk%Wx,Apˤ#!=q؊!^^/E{p> m=?DLubޔ)h-[T/%;}0}iD7+`}Zq8K$hl16@g]lӠ~H)1e֞o3}1% 5M-+^Fb%K/a*88ĶH P5!^EךWƲ7]Hc˪ސcf"*¸{,ұhr*RFGm#VdtqMXcyLX n!QAAeoE=PR'~Lg#>|:ŭ!rLX\[)qօ{oti7}4mzxq1nA-"b|_ B9Qj!̶e+z,Vم%M9&UU4Dn(>W?>mNvߌ&37#y71Vl,[dc F*p)෉^cV!LUx3{rO1%%sT6}U!*cbr]ys6t G1gĦߋ;tm`X>)sЩ^1*i5,96+LD~ªFBIds.jS@NJ:Krk l KN-ztmfUŦ~df2W cb𧻓P$6 q&>C:VPKtN[.\yIUI&/WALy6ՔYa؟110D>. KJljA}Qt.r3,ߊ| S:*eCf([e(s/efrA|a6t9Iw{7*)Ňqr͙>`HJ3P @dawW.e Z>Qzӗ13nP9<$*mbW+R܈&x_1znE}9tr& le%ҹHȚ(>Fa}V-:RG?A"'Zxs6+pxp@3-KJ8$no(APTϺ ~ fpx$VQY )H~4%U6ǩ.p*c[W`(Z~H1?]2C.~ud#aiY|Tu0LHO;K;;v`~TvppV͗31mPfj#IG3]@S'm(ɼQhr?a2~PgO$ϓʑx*$3R}2l2F~ To<~inMأdGorq;g{NфUTj_+^BGKsƑECMּ., qq=&?[ &i9_W"g[TPA=x4KcVoS`_jM)7QQ6̀5fmҭ>@e. l$g( q练m D=Kj W: ES&j%-v H3|]V51+qvdț`;h:4g,7,4 la8)~Μc$Lǎp0ۉEGȩPm~/;PS 2>rUWԮh&ֶXekfPip<9V8!赠ϡ)Ynan̵|zK콧~+2lsYwHGy^f3Xo Xn"4! }bUԓA3aPUH3+XJNB*`%!9p[_"/Q[1}sAθYyMMI/TL$(&MgSt쥐Om&!:EpPh ; ͺV`ְiG>z.e+ܽh9;ECp\}GIAna;UtG ^{lX7#7!Pԣ{{Nv*iafݕ3"wΈ$si#5?Z2+,̊zӛ]_ d$a7ƺܨr Iz@V斥a$Sp0l:k;K-ߖZuY}clQ  ~62a&2Z\eU$րGe^ \+Zki%5G [v7ҽRFLg3HGyRKvL:3tiXoB& $+A*!90aѹ9ÀJK1#F,6#QxBgwxZ>T!6cxFȄjp.vNI^tsY.$YࡽI7$_z4 ||o3&M\n&Jș11Es{ʄm҆m̱ˌR҉z /TLOnAeqǞ?8s-[C]U5;Њ=b{$qUJpW? V*a}JXd_ eb@ 2H*d1S%Ir GMGO)P님4zzg^Nua[mA}0֚ґƪK(1'K :C85+25+u^4E X0 : qEW +#Pnz`>)"#r tE,z^N Ϸ(lv@Ou u,4Ê8I/P$X4_X$+whJr\&:7 :E hQ "TT3:AeW`XuN2m Z18Ls̭F,ϲފnϊdi/ܠ$nF~庩rY/9`/ь=ΏoCt0 V. J ;zD%6-=] `+y!S5xxeu/tQI=b(7ʉ'[m{)`Q֫{ n8srPجKX`;$g,|TS"+&|P2Ӿ܂1 CC?'FmN't@_ P H&uUrqb6ȳ0"s0N~tn|k]N\Gi;Â"{WLozR"6O p-We{L'-B+iL&^{EzD<2gԔa`516b6qGԧ;23QqKd+q&YnL_1,·KP=ԧ<ӳ F V¢>7SG?ek/4ܣB̙-^Ip'mW DG%ߡ2B\L87Fs p4ke!ET J``#3:hAQn@&Bn0?vENK|i|8&Aױ>k^e0Gɚ3,42!5 TĜ ݿYoz& WGSۨB̐-~бNS&5Ћ sgKP?NSDp`cP*+$_p@7N)chQ6}a%,og&tGzps65zWUÝsv:R4q)Gh`6#L ,8 <$]╾ֱ Vb6MQGHSWhbX7ۜCxU%\/%̯l/Jf[l"AO.őoebJ=@r'̰d7&3[?eAHcpߣxo~a?7?t H?zڿso3Q#6I?M^|p:s7@aՑoik${ MʋLf4Nz8q  j00AkJ܂|d)L ʅӽcc- Ĭ U"/10ތ7֯wᖼX1褍#e<"r]a`5I f1Y z xR֔HqE8ߌ8!>:bl\Ha/r!9Vgi lZ[3z .Aӏ*{"4{Z|#BġI+]}D^Q߹'78 T,;υ;IUEt6Ldu#UZNaO5| OܨBH#J,e[F4<0V.Ԝ.y#U-,[Z/vɷav*q'ECI◍U#ùWs sq57c\ g/+w:5@[a 6k U_҂TG5Б6"|Om-}fbͷ%hvgK/)'8&Y}@y\F9XT;۩D gtfv%~wwFdv;&J.]3,.Q8n E)qZ:)0'ʺ?ς,}M$ T>u&dsvO]0*/OG8NjW*Aa{qQmVO4\3P^7L ʵT#uUj-~?xuZh̃Ish hB+{mFrUGJņXzއ-BBIgp˾,7Z3 UG ")?Z-=Eu@0[=X+AҪIѕW?K;ch1dF>$ S8X/ 9wQ!skf7ϚP|9K| ǨLg|V("k- ݦ|'7xK9ԢbERdI:b"uuP{RbwvR^!縂` fZG賳IƏʸ7ar`==% 73Թ"yr ~{Zi;s)S*^2R@ :=IE)r-{}CA9&@dy$AT"r-{}M*Wf᯶~8cX/5HR ~ r]者oPgs0:s6Vzé8+!7Bod%g~ޅ52.#2f/ k&Qu ~B&Gj5p~=b8N$T3=|zBd|1pV}T/qe6לk@>T~ƿ#ݸ`0guCzѭRoօ0Է^ LuD&NQ8!+b2 %܇A.B3Qozl/6ee>=HŸ}}?Ypw;_o" '59m0XkC;BƜƈ],^i^l/\L´#ASܜ]nBpVUR$GO c A?Ҕ;C^q,s囵 n`Roh 'ogD@}7|XepCdrab`[5G>v- A' 1_M Oc PH6C-T1:~h 94K 'iЌ 쇸,OT7êh*z]yԳ~/3t>V)p^#smnjmi#U~t&}"A`:ܜ}*f蝊}ZN@'?fnІqq ¸;^ǦEYG"j+4umB˦uW(e :LEhs2VQm.0c@9N p[jv)21ȰsE7B :&+$m*6C^f|5.q^ܥs ra1YjX4  I>J-n ~:=/C!E wt&(zahP8MoB;Գw P֧JH, oxPy^% Z7 Xi0/aLojͩ.Gu;Ry"&\'T- qؑ,g'Ə2EuC63H5b ɶE᯦a!?&jJzPWW .;(١-hfp͏NGs+>DiE6fsT^-!22ES#iUqPx"'5m%Ju!&,,G8ܔeTlݭ'&3T .FŰ<;3v"bOLTaeE."d-gpw.NSy%ߜ\eZ*k.u~Fe̮[:D=+i-P `ceo MF&L;r kq3|ȍ/Y⯛UӏAc%eCL 6 t$td(~Z ͞{miD-# WIKNkkpTJ_U:v >wDA$t̿oY}J(!<9i  E,?FF(M#S^p #..\)m*4Kc~=b/h_AX<7ɲnZ`a}㘏x KKKwhH㋄=T FvMג]sn* j^iBssŪ8{]ό @:Qu #wzRk!-QhZtOR^Cm}+_􍾡<!0!``Ћ;+ȏ=LDy5=lD1!b$'C '6 :g=R\!!3Bx%3b 5-x]8n2=yxQU("ֻ>x '05}.VC!U0*ns;OW}x]37+n%Sc[}}T8|x]zM'{F Wi[+i؟Z~-kR.M;=:" }Df3,=H\$n[ =5 sb7a$_X6CW;f[W_BGT$0Pu+Ikϲ!?ձt=t4:6~"0^nz3PLIɯli(4OBB-YU3S2/Sqp/dQOo3L!;7UqLHfr'zPU\pYk;[+-$6g/n5aZa ʳf$9Գ,5$b*.|nVU~UQ_|H*s3tdk,(k5ţ;+TC>ÔVTX 1 J`ٺ,1$gUBG,"sh un4G*~i1v^-FVZW#*c1bp ~5zZ@~'{YiaPW\Ar af(z$WA;${rkbWK,=k]ZTk_Am }zܑ1{1Sqݻ=ҒG=X g6'Ch^c(1OL1($>"T%O;K(}Đk{c`{^b9"$JpiX4 "wBWnwJAuC T`QЉ\z=!u;c>0ޑX&Ek]8*Gh:BBO]Åq(%]X#ɃI`k&i>5vB! 5I2CK8\l wR3{Eb^"?k=(M]UX+Ώ\9lk>V 4qgp)!Z9V"c4aHkHΘ(q_ HF$ѩ7I-TF4%JAy!YMz5>%UsKjepj\ $1`]|:T {/ y(%f$cFzvhgT̩}X}IʣN DQwts:8~{*Ywq"0Yf4lapIBj,pTtN/6wn5AOi c;0z?E! o#6°q%7A`sOr2HA2~Rp9_"h}4A Ķ5-hNioQѠN&]@K_w;dRmQ4>ۼz`o| w(ڧ23ADjAYUV]!^\PE+W= hjǧÝC[-i*9xgߔ)S0}Qx͡MtEgװX΢{צl~=vu3?SQ~>QR3cjNa+ ҝQB(6:uBQ"]^G< ?MDn1D5*_\?lܻ鮫U?-[NeP.6!rw>?YL/] @[F@Ɛcr, BX{6{?(P =C1Wj͋t橅_ʦb#:BԉT/v<\&pṟ'gYghs\8Ý\EU& Q;_rTvލPa&6Iz/*6:}gW2gMFzB/%@"uBsZךU JXF{ k?{╎Y˫IZ^ ]ݳ8۹h|^Jybvd/6]{;C/KMA8ۀZevA/A ~|l<^Vaq{:M5@3kS%~ǀ]},Dkl0=G,2 3Em~ 6Ŗ !GQj@h5*hT"tr'Ml)iXb0>8pc#I3.DIGmզ1e cMp+yN,,$1-@"}W?^@K Dj_+LbB` WD&%#!(-f#c2U[z^AF<"sZApM?}+6KZx8J̹W£ K—?žLK14ӊ^)&OH!X"*#r$`8k>SgrǺJ.FS1 Z]DHĀbS*ʧ@I[J @G3 C3y|BAv\Ewy6QE9q1\f`EIyNR[*P Y0 Ҙ,U9;n]3[W/F:>FM$<#10nĎ # +_<128cjV h@z1nJ;!ۂOνh:^A0*30peEl>dLͺ5%GQteft}b z`aw _*]q̉ԑ0)/NU;󤘓tkρ1]6,/=Lh M fRCK\8x{3&t]>P|SӒ"DA:pXzgD6R6W ^i3GnxsՉ?K3"Fwx⢕9SkZz!S. S4\M(vzmm#0< *&`^{0mc ?K+[?uzAT|~,,A_kMyvCqX^T"!Ie9>&X`k(DSi^]%a3M|b*oP`nUd?&naϭ7sKUAi!E"0U{<>wS487d ̞ ž xRq`/΁(ᣪ䥕B'ln n!L\(II2Vz:I_}H`GbL ԶU1\l&66v u_G1F!J*xۃ:n3k'jԆTp@#dd U`*%ͷ.Fo]%-|a!}T\@Fw]NO"=*# {?8|+Y'_ Nμ!$M,+QoK4E) í_Z#bh+[ՂM(֊l. 5:aޚO0n S7|) ߀$dEϻ)NpX-}Ss7BXT%>AQH+U 2&&HzQt?23m嵓&?j  <CO@x֖kyyjmhR_-|H 42T[ ueqY=Q3lS Rpܴ-E%L@~Ħ̵۬ ;N xKoNZ?x..f)"xf Bf(ègw+ſP9lUFW|uQ'i麆#HQ XRDMEB<.(٭4 ~_5Y]0X-wUi{7QdO׹C`wqF={xGHT F4]$Doޑa+_{e1Ȋ*'ԥLt p|%ӘLo[{Ͼa!FT|tх4'xU8Ը['`|`=U:Fl~lw`VQ[=77*uԌ5k%T+ HU]-y.TkꗢA[:@*CU%Ԩϋ6T ͥ6s]P':lhUN_)L bo$y`9%]Ҩsil`DýBH|9R ,&޴XªUI4Nڪuj}FXs޹,a7{͂;[ Ԝ5!ҜT=]`n:\`sT"d B7 n?A/vA?Wo#ʢ-q̬b9&WM)T+R{>f ʁ-1hI9 ñ5""dLsS 7+nx':^ZTbt6Z{4aG~ԓ1E01i)2nKq_6'A})l!h-< &:g]֪={P \L-"q#9\&WݗFHm]dC(>)/UBgmQ[ĻQѯɒSh9k Y.']]N<MMv,*`}>n.k u{M,GO5%xQ5:iMD#h{/9S],/ 9v?w)L;eAN;w}r($SSCW5:{BJJ.ⳎZX[&0`P<l.zOZ:saFM=!.gP3DUR-މVhӓҞvZ8"_EwGV[B,Xз^f Go/zeb1]϶X'?䢏!gs,Uk[^fEccR]Yɚ]¬p-q4cCyO܈#t$d_WP š뗎R锗ɳlmp5jsi+`SBPH>N0 De4ff;.!uMC`g%ۨEUYۨx٪P$09-7.%jU *1vSin6 㶮6FYj;(۟dtmm>Ei&7,_ݗ2doW.0oc uJZX7b,&@ G>9Yb(:&EOu Um]Xu{zؔ~{]&89dYH(Odvv]^fyV \9nB2*MrԒ;!IFRqU,4Nho}& k 6lJ䬕äV[CC@SoYVi!T|Cs+n6O!uprFrQHI̐ST㙒/ͨTJ# LuqL nf*5 h 5 , 3.U7m%AD/IܒiyA`J? VDI^ {NzC?)|GKcI?~6l$=ϢFGij@W*E^dH*R !y1igj"mI"cf}?BfΣ fZݝ}ܯVI}4Q6F%@y e;ev12Eil?-hz1+D\&^<-`+,C@oJ ^⪇6 )Hi~Mg'PŎL>uzNQ`j,o8bESLn.okYxP9$Lv<ڷ E_-+8wo?8_p-b[Oҡ{o@teEVZϚVXEl=cv?ѰiowfKUH!;u=o-J^s}&bi-Mm:N,<Ω)RMIkj:*'K`2Xлyb3!H 0SVMЪ9vL6~D(`F/͸Pc8OQ꘷ܟg EwP=7#YE".AVmig  &bػhb|q9UnQ}Vv5< *yݹ'kM'aBӌ<׋56y kܘ-nxX1X^%`=ɮx 5p#`ʬ#G`~CMo%& CLңd?m6AFFѬRCgc3Z $`{YL/H7FTwSp(?9-(^XŻ(wV FQ6nR}U4IV~:0d^N.0ی91ՆӴAv nM/r!)ZF{R,~8 ?*6(?p0ě~(0 ƳY8:Gbbb@dޣ~PҩAuHrѴgtq-lspL8>LZE294WkdPުQF¹#oXOb\l J.,L ^0(cȖl- ƪV)mtjVLcraYy+!qaߏ~Բ-TM[6 ~y9d= ;3#K.f * R&ZimI)f1C,5fd&&svXqv7I^8lp+; &NO=+t,B$hZlŵepO*m Bj*T534#;E1G2k->ls [d!W5JfP{i}BOM0B°h8>,FuӯnA99Bn/Qc%o4A!Ζ''u3Yոğ0BM#uņo""(*UI[P(t٧ *fPs1H[xD_CZnid3GHUuFx=7`6dtlRn8fǘCF\'R°Dza/15O39L\-x2yߊx, Fv}glqu >so>{1I~@;i71n+֏ZG#I-ݓ*b۽*sr[ɈbsnN6 tqHQGʯ;Zu}Hw[);E;J0Q'X>V&:e#ޢ 3,mp7DmR-;#,SuCP@qC7Tw>1sAk&5sxuKS.zb Ez(+Ro}ED݀ z]5Ϯ?mp4osD6(MF'J+rO:n3tcyRYZ΄ЋeM*f/mwadlH'd'0C gs]Wn xa)`a>˴/,D]%{#Z[=yu;H`Rof c-dl $!Y}5 Y;ks*ySrvJȨDɩ _ cy%<ڠ1vFAIKh6? ҄Q,vRIB'CՐVhUy&}nI]q){ 'T\hK8䠓"iDŽ 8GF3ڀ.}@Ǐ掍glpx4gj "J?*eB{wK pk\ʶ]ďR!bPuiIl퉂M0U+#PXqDRly֟ͤ,k0рڄ.׼#سjaqTo c1*5,pPGIz1UT<-W}@9.`^RvA`})DYɴp|cHȞN_eCRce›;V#Of~^Y節-atg0NϕjeYmxMp V;nJ!ʲL-$ F#?*&64֐6tD.OeqjwH&TcD,Q~eK`^t_HK[&)&RYs,1|n4Q x֚6uFxN*4G M+J&ܖOe&{~#F1DAh;",U[2D']kr^vKmz6 K;ϯ7, %xpJ밵SMD : ǾϙMl_d;~p2O} F0B -֭2 hŶMuTM7^\}eD'#_&fܦbp흓F; JZl/Jv7"5Fܹ==|SJmv8ާM%C6$W1ň|W @Ikɞ̑6R!|T4=(F.v]}7m39G|' #pȾED#VM̎` 4kEk (t]ZΫ\JSx/|NbbT=6l(NO~B:*pfSc,\l]BZksDwwWlR"fe6V6l^KM \²3FOo{9U ~eKF $&a}Tf \ ~ͬr9Vla׽ЄN| (EJ\bR$e@8J%ƍM `#8w?Z12 a"T4;kwxA\{*GLP`2i0cYo=}E|mDL\jq0}*( `?hJsP-'i@v?xFoGN OK"Ht%W pKNԩHNv l} A#N[^'d9IP/8Lx,űÌqdh,&y)Eo#@EBfB15/'AD(VbM-2cU\qY3ăD7X& aحh? Ez}80c>b14G47r2>_g-ʎ̃[*&dSDb]%?)* tsW?R,:mNmyDL$dJ&1 mw_ w'!Wf/FNR MAād,8W0d wp6`,B !e~Tt[|jnHQx0$;j0KqywyÁ$Ku4ȇjPc@ /fR0'JD(IR)i~4$ nF+2KdZ_2*'VD!t!~vZ#o09%eCDŽ zgE#?n8\[2 qjW]C Q "^4۠L׆QGrIF amoA},RvQM|*Ry`A[hOH6f4ބC*vhhEhTmN$Q&W!'=93LfNt/ÇrMvaGt!bɉs -qGuXh5ɏgdYnN:0% q:1bݑ% Th8灔 N.<5m _n[k~Qǻ/[ u.j!CtJ&PzFkI XшM^e}!X9HsޔHC"PeAGR ^&iV);"㩻P+ [QϢڮqdO,Ik9Hoo5B!g k6ddlςX!R =7v' VMmc[7fl]b5jb(8f K-\5M_st{OSep7=Fp IvHN٘*cN2]`KLkR{tpJL 9໠C O+PcgbCy.= .EA y۳R)!̞"qM?5ᩃ wt&>DvPR{8oOaת_11Y))Q`Nc"3A%k%)YM2n苽##èVz:03Lb~;ƅI9NuCJpFV_Sc_$4P涹u zY2Xkn}Kxg: g?J 5F;<<;݌^'g-r{dC5SM>2ENM=ٔl#mrNʈ#[ 3P˅$a^4n@ɺzO2M0a)~P7̻TS<Ɉ]6 :,%MΣ} Tpis UW<aQJv#q ,.*B\.,XljY01$nQXס9zxnoh>Nk3LG };BCe1;ˏ ZjŽ.!N!yl, ?A}̑#aºB:fl!=oԶPݓf3fI200vz+iP(-֮Bї *~)KE(_ [V砪..^fk1 1x< coN /ס X1{خB@I!ɯ]ѯk>s_O۹4vmk~;A@ٞ_t.ˉt`b ~E8RkC)8}wIꞠ}X*d.{wp7rcD!y|YVfTqGg]ujf-y!".NzX$üˑM&:"x'vlS(O(/Z^v%:O(-LObg!T<$0& }vŐ8uC9kRÖ>՞[<N t@n5xGΌSդs]n{WU7jS3HyN4do`T=8yQ>XF#d¯—y$L50aD'f/4K \ ̇ gнKFzoM!A/1F3\9Ccwx 5 G^f<\!]~yWwWu⿸}L"%8#I Ot<'}jKRH;nn]GP\?`/6BQ1L[9mCs ]{WӮ-ľB_2u;ZVCt9\")sBB3%KC_zZ?c!Jn,ɦA<"(KgkƦQwjj>W g%:ޱ8hUb8q&[tGx$_`cyؑ|2 )}Nx69VN0ɋmgnCb'x8'M}]`ҷ+eTHH[;aOa(s=b8cׂ xsа41ڟ?ZIـ-]>g$F[jk:i ɻ^z>ީ/}U;H9CNlaraw&%שUǬ:QOkgu^ݠGC8tYԵUEmx@O!qu?wge-ԑo&Lںsvo)/:yATϠ:Zqk9LXٿ2@ vRq"&H8r5z_JVcI$'xї!#<3" lMT8@4ňCSZuϪ!4oŮO<=(Xn+Lǹ+,/C= E'^!?!UTZ bSٙ.ӹcJUN[8Yb}XϠKZVWot" X*Ԥ>bm^Uf!u+#6*rMɄ:5rdQDR 5B˱OLAXRq,AIqzWսZĀT4*+fo]+,?ayy{>p9~M7d+󔦽i珐BsyØ1";w x%\ Ʌ{"Z G>qB>nitV-GqAAx"Zz]"L$zovh_[5Sk7 T$e?5̙! bm|\es*iux>?n68givQJ@ l ]عB 2 'Z %Wl*ݮ*3tr;f.S{ ~Q|y1ud $\8ui/ϰiP_ Phc򮳘3oe͆)_9ƀs _H%m5pPO1YbںCf[BB,J/]Hg-*&Twlɧ.rJr&B֕$qd,`IՊb 8Z-'T[j]v׾oGNpg.P|jK_htӤD6' /V\}?=X8Bw&s7qC/R_]~=h+57玪qeZ t$dA+g-o-&7 ZFGދ|tZZkHs%!+;B=ӭ3ÕD6-U=,8YfM50g0[jqZHJH" [1m[֎HUkd'54ZЯ7` 63'Z[I y緀Ȁ`:a6dEGAbEF&@*NÍܧOǫyfZ/Vz4g\ zVsuK q`Dׯ4du_@f6B=xs?Z|Dhft3mM]lՀEwpyhw Z%TY{="Vbmk\%>m:vCb뭤$tNz5" ;ZY0\gQN[Œ]d٢[^GhB'ъfg>p=Nq i^(x]) NuCZ}UGR:Y<6u呭~t<20iѬ$4,ccPreq$m;Q|H1 W+ B,s#yBͻ>q[S`@]JzƼvTgŸJK g@קBmW^( hyʶv*8t5~S߇~XӅ2'L"csSE(J:%CQ)}/>ːH+%\W'C(\ 3F|FQWb.Qk->LH `w }80]3.!%!3 q㫥]pP/.DEFH) [1c|b| qbDŽd׺C_uPZhFj8L33ғH]M9BkSy!;P"?3}#rK#9gaT/JڻI2buQ573Ʋ(Eƃ!$B1->h0;oг[0oTQHq.Rv$38ެPPk]>h4_F!\nDnqLyUH$zċt"׬7IU_c6٫p,C(vY@ 1\iO?hQ\zPELC*LanWX7BGeaha-Oʝ1!pS׈22'#R6ws#$ pa 0UH7*BX1 ;bU|ZBʐ'C(>Tu7L) (m(5oVYB _|0l|(_ӝ@ +w5֊O';Px$^IIV4zUvr%jyJSc2Ls6?gGb5+ux-9pYpGrcaK-BUVT&PnE,_0AR ٲo:kz fF2DNCUmc)jN|&;|9I*}|Y!W?~c-)d08En,SwJ+:)TJƸk9nJ+`_#XYC=}RYngjT^mLhV97KH&*(Ɠs}r'IXU9GfgVkȞU5t vשzmY(P+-Jʵ-@+e*|t*[%ZmߤOEW<Н CQi!/L)/Q?uUj)^i]rfh)gMԜFg.L U[Zv-WE\ U#;g1پS2Xu6βlDy6*{?wUfLRTR,>TF55gF4G|uH+p;zBu&+gdkgEwǍִfnYwv8+(Vaӆ_ivlBTUlObjx,XHySC(Kb!H)9>z5RuPamQ,q ;wZDdߪJXFr>%Y' +WȄƹ+~g!gꀃwK zLhmm_Br`"^yqmrba@!/|׭"f[ dZ| 5zfDY fgYtJu.ۓN UTҐ&QЯPI: a kr7%!vE;:⯦k!Y<]vψ&2B,9 7)蒊/Ǜx`qC64G[ jZެXzE/&rjEvg3#`l;N@J;w]ڊIq ^뷺)mO*: mer°},/ot͗<. Y+#0ĥ-=~D0.8KyR ,Fme7#R24 ZBJI 5&q7o=⮏ " v,uL%!i @&oo-okHD :vt 9snwkL'42oACEfqjX@hY]YI-cŽE`gۡƸ|Fz*z /tAZ/Xz@i߸}aSZKNKadN:yF\Q)VD8ԟj%/-X,>~iX,C`ȯTdY=,B@'īGg6W;p 2䨢࿂շ R/Q5cс#TŢ]jޙf@s)FK < v8ޘέ^'b5y&r')tOr;4SiA a`K_*N&PRnJg5@]sE /NDkS/\اFh0T8 e2P9^/'.-g1~VVP7:Tx%Xy!-%F~-'2%Q=Q]Y Dy-O-U +"~Ilհr ; FW)-y[j \ғW>@>_cpp>n_:VSBR4%3(~]zƄV&$(/*D|X͛XOHX وVft:L>*ݫBJ3q:-W7Sꓳd.-8R?sIl5˼;1OD݌`v=oB @ij[AKomI`|ڔm F,ץ]CAw;ܞp`*om#0a9>Of.6A`0=Y0uBgLf|sħ`~qXNv9sM{8T(V"\EҦG`XӺpNOl3$'?8Gg!~App𥿖ƒ/}D&T;ៀ6an!u :{ǦFmx@kHNVHNdFCgBOϜ^ `F)qn%{td C}7QGc<TB -0G1pI|UQn#Lgkb4=~}}z4m\Arܷ"lfB?.|L9pB /R28D9dܚZ&t(ʋ$r[XGer?G{) Gdzp<%[v$Aɧ8C]+d3r~*y(gqQBA+wViYhQ2c*tڕ:IXթ -e ZI]q7p*\YK\>4KK/q|DtCbZ?`/ITTrRY/EY5`ͫ43e{Aj29WcblҒ_݃3xa@b"o.MPxs г:a񩹏iKrj_AphVɦL߁v*47 )B'!bP'pL$-7O%[ĿB+LPaeW6KLቕla SG`ɟ{D9yrx%jL@JS/e_*!1+6t^;f2V[,h DC|grz 꺔~ra.ڼd !F6dR/'z:m\}=$KZxz3EO; >mf;=op~\z@_ɃAv΄f}<̈ϋ]NrH *!01tG9m~ p%9a:*z>5_[; ->$cjG^lEq p9uJ럠m?,cQPɰT莭eFA UWn>j+nE~pq\Wͳя:e3g}FR)'ey(s"e ݺU&q[ L1G,`p 5SMfM&+.ዘ|Xa[ݩڔIb #w}Z^RĬ !_<N -7ցZ39Ԙ !)cU1"]r ʭlj<-vB`L~F{L@ 7gI"bz>9diC*~فAlr{-뻗+3ok#{Rꖶ _-MnXk4M{̛`K&! Dk9"dx"?FBo}gCaM@D<:;J&ׯ†+ &%/ǴJ[[7K7q }/PL1O?ә$0[.G\ixEߓT˾ϝ``.1ؚD@ 祱+;_l[]ifSl~ f)pOVJ2D@IܝR; q=[iTY.xKj7u6Ur.WVԹly ЏS)TkU[ZM[r/btiUw0eE^`5$U Qx4wD&C$?+{b> v(kIF xmC#g-P(?4 $b~'ք,'&աx2c| !UV_ CY}@YӚO1Tg0mRyb`= "h"@90i}u;T50;2۵|YHu[4%_ŨԹ;&|L @6]ȵTtir Ҡ{24~DUHu'WUQ5=]l޻䓆BȪ@AlHSrHIlYAzW j? wJwחBhO=o;*]Il*m*5~b3R 5l!*ۀSMD$5j=S7!"ȜERnhhA[Q"ڊbs;MT> ViRMfmЙ7[ ˻maq r9j sOrrR2jPOb=00{E$ᣲ8^xd[۾۹5ɝV?IVWI Y9bYfeS`I@:i ~FKF/+)&O43<"G~s>r ' ;(B1lk2w%RU9P Pw?D^ޝY3n$4<.5c3bWTZ=|&<`ȄS @Ngh0D͟^{*c۸k'Vo#/eS,hF{ǥ_=kuKʖ V/%4Mlr/]:;vSԑevv1y#svyr~cUCXm!K^QcFHsl9%j=( ;iyCÊ,.rIcX .545LKeaB#F*q(X~sMߓU:UUcEE `%QFh㎚$ԡw \:C$96FkԵoh*@.H2s*%MJbbo+V:%ДxZ~ɘzL)@nDJJZ . +E`l(&G?Z7q,݉bfv-JAnyǒtz*޺3hTh0S<|og\v ߀7Xh㯜 >&?lHu\WF)_r'xU|khx`\p٤1"YR ?/՝hhYѢW˼M EX+o9FCuqX1`oIƪ mO'8 FOU q֨yFXA(+ZwAmD\ԧѷe@;Y)|@'CX@a)34{?:,:w@j6A |*'n,Fe T@L:f˶9}4CӤ|mq)Ǖ߰y-%H ņ^F],3D(b{.c@͚9/Cc||JCJZ nS#4Kc?܇F^- [%A^W#deNW_*ˆTe,Jv\+d%g53c>.?k )ìltEsBጌi@|jz\ t, y Ej.JN؍)6r镇{n(ifuS*c*e L9Uq;8!*H#å8fKg:) rȸO~n\ʱ| EӵY #>,}fՕ,Kn'!NGfG1LjnG9Ϸ C%-6G^*G/BRPb-;._ oDy>KehOQLl6uE;#\\[/㵖Ahf| pjXr eΪ|K[#7uOx+u*4m,[9}B˞rjI?C8|5(.!H龁%Kd0.vJ(YFy\!|bGJQZR9+VEiqW̷ܑk Eq(!Kߝ+A_%6CSwl(#YS3~7ajMnrFbeVXӇZ.]$|QC=mf"š?&FV{fsIHM86Xz"fɋ($vd]_x+`(\OvFczmCKPUYzpt /8ڱ#$ JK*~ב AE}R0b-g.2|@65BpKHGYGm~@gǛo5Vu m*ےb[M81 bv)\cJgFs\-=%)!'Vy]H%hb+WjҚ>b|O[`z.Q L5ڐA:s xÏmʄ@XcQm5Zp?7߶ٔ4=/Sqt~xAʭgb,$f%5{E29{O)ܨ~ם3y;LWk yb%EX"At_R~%fvnC#$X-{?YSiV#rIk?o~m>-]L;;'즥OE_7gk`Rx@e% Lz`DEwʑ 8D`ls $)r'aEVe,2&#!{Y<$#F>6{*L9J^k T].n.Z 2_Nnѷ.F$~q}=.3{H{/4͟C>hmN;Q`=~Bqmd*64q~Ow; ?l{6FAۅ66_[aoM# ˌ#ubj`ks^PQd [EϽ(>~1?`tf=/ʥ#7KɆUǦUf=Fu ^l!#d +28Ab-wc 9tw`dR.`r޲u܏ fjr4ğQOk\$蛯WGgP~TxDsc@O.B=IO_PxhjAnIl  NF𿭨UXِq (ǎ٪f2].8/l:-V,؀DAY+Gߘ <*o+f zʄKUP(\G2|X+PӇ}Tb°PF쑬ex6U< ZJx̞gse-0jtXD AP &ms,tFh*9_}Mx #}|)i3'c:k_@0ʍͱg(S keK;Om1x%B%0rXʣjwSzЍqQpDǏ)ufUؕ?;V Ly]%΃2FRj0saǧ/ 5)F^`_Fd}p 7#EdXNs\;[ lzsT0 *~C@p\zU[^<s-4SSkRG^{G[8/gNG;Z Aݿʭ( ij7YMA2̶[ EkEMvkh_|pi:|_s4Wt29PՈW\gI"󊕂Gn<)ErNhg_FY.Ʉl'#Kނw$UƑt[I¾i([ +&W#ڧx2% q¹~( t2]?zA%2AY RڧHظγ2*{=yUFg|hC2IwU0MKM8YRuLq8fKO|;-Z'.0vW I"-@;(7 􄵵8tCreDlR )18Хd=7aQ*6DOdo()Gs<9#QBʬу6ЈҠKKeڣTFk5hVr(mn\ JZ6vD.1?bFDyp6h<:)TmbT_Uo\-&B+Oy4\dn9g#1.Ld5*\![{ ֠78F-(F K⋥GP[szˁbLE41H-ۘ }^懜?]fw#Vd&d5)_%_&RCJV#:"A+: y{Ĝ>1 =HR+LoS~?vPUXqD)^/"u"Cϴv?x>LYLwȨ^|x: dꢇM;$rL,X9uH`lUMW'?EBƱ2܎xko(>7As'GkQ625rr(dVGؒlsB(etHS3Z(M(/-X,ޙlPt=HӅ~d)FvTG^G*hl S.Q0|[P m%( R`O؂k;\v@gSvuVu3#opi: xM߂_UIgظ$ku!5IS pM)1A/9Юsו2u'#C@GEڵ]r1hdCV:O~qPCYr_pqFF_I2ӌl>uS<:+싧n78wwwG$Fe.CЮGƻ;p{a:+`AQMlz :6 2\V8?jI}3鋑}1QH́cE*Lq_+iXkLb(We+`a]Vfb`2WQ:.b4z$ǚ 4\>}%}%o"U{H,em}-#T`A,:H_rK#w#ZXٯf\g- #,-dS2i%6 )Z.uqV .n%;AΜjk#)jljgΉIF]wHI⢸`fFS~t}aqW1h啼._10v@ӻ{٥Eƍ oݬ-4Ԣ֩3.;kaby mE?-ZxQCdksV}N*D+]@/vc'fgS;}tt@1<4wxI"̐5A}=S23*̕g(;sѮ=䗨~TB=~ 2? ]4FdV2t ,FT_r9xgy;:u"qq9PhtmZBy0x,VU7Ė^e`m,dE*sSZGE3F kUrFӗJzMiĤ^F>!$|5qcپ{7 1WלOw(PV|pg9՞0~òd:yˮﳺtGԬ(f,x~ ? v|YXkݙ/BHCy֧3(~"tf|5,BSMV8ٓӔ4T:k=wFROz pY#BڌUE ]vvFOݴ[-"+ԩ~qe:U;'^:ko1A*0_j'ZgY7|ChzAF]%.`dN7JL2۱=u9k|#աX:{YPϴh˿ד?"V. 5qbX%bTP.STEP p^!ma'n"aw2\;XZ `nTډr֬}VuD?ad+녊9h~-/cx8˹~{I-[eqǣW(۩Wd3j/BSjI|ajN42܌-4{/ 6O"ul&DW6DLT(!Äju5u&$HʡQKvrg@+q FZEs._e*jB]5pfҶ#knb64i|*|6 HHXVu ~ވn>^ۆzU zO~ R2šPWS껲Lob*LTbaaȬqX`>ʰtB`ֽ?#է ʕC&;fX Թ} 6ŽXYk|!kЭ 'x댩0@ӆmٜG.4BF?W;nS5~*rY.)_z |^70ƢŞ}"wdse&N ..&Bg0`>\ntd|: r'=~pTr`'\yf)iNK`D6au[x{䤑t f$aܙa(qSB:!VI\f t[b_VEz*A f}voJ~i͵70Ը-E43|ݺHhV Q^Ôz@1t9O9ԏP#aI=\SJ~UǞAjSC[2߾}"5}nuIAunߛI ruo\axf]ƺ~G ' ,Ay zmG]ؿ w={'TG[$&O@zr9fOM#oeʕ!~RpmiLQʉq$3Ul@  \Th#J[Cu VTǛ;(mlp;{DzJh$o~0F>X%+UWf!^IB`ViR;A8A@1Ă01E}'i^<UYt;) @i!8)i~];.%3 cÌ٪/{J9]eŒ8FpWj'oβ^ʆG]rS~ZcM>.`gܼ-0-тh6r@=yAe.#~Q+BOUUV~M^/ Y PU"21j_Oc$Ҙ'-,#|]ڂɲՏo`~qv}M (_?9|"VI+NN&!KpZV {pN[D!Vݒ?7$A%T`غ[ N]*@jqBb# 8'5L?DhQ4 K)Eh{=y 4@LɶOr:N _2LD B]BmU6]kjL0N&;\/dwR)+YeFue6J4ֵԜ({[=idt"TL^$e$1Ίf til2H%O;vسm @zK^qj0s/k)cI2eKA$ bϖ}f=X0=ڕ]( me.IQ;)ޒVdԿf88i!lvj&|b XUX, t4r! AKjGr ʋ  {` "jKW[y7G{/Oد.?hST4ELB;=+(1GdS"~r.(^ {H-ϗelb#D[_aGY|q3ԇ~ |!V};e?&(YmP5yH]UExC^}Z !ps#kZBռ⬫0zpNlDé+;WԒaGWR0֌ޕB˞BP;Mv4]gߚBi y}UyȦsG*m(Ն3FҁJ2{M-i*>Ƴsom.˾C]1QZϐîkwm/.D!!bP/h5!^>'u=Ld(hbp) Ez,Y%ܞb`8_͈D&G'\c%+d9BA`>8-sH*?ec`U}uJ#cE-PFaO;< d:aj˜wJ9`oct=~>aVfdظ (VcrUlNBQZ '-g#I$㮂~Lr 9 LBG  S8aI7)+fͽb5u/dt&W32%s8֟-\ǾnMMX)? 9"n$ab>IV@%ȝjb:spo XYW؇Q1La4,W)EtںTu8=e}ZUf<#!.*RDM v-=7{_MFAX@&Cb=`iyep70u^?UH0Ozˤ`4Ҹ)UPu{Mozz9X" _ys.Z4.USv o"w)HY< CxB)weqMpL @%b7z͙ſ!;)vʆkKmr^k$(CqH©B>xdKDȻu"?{FIZcC'$aO $tULg?*j ?峟yUxNݯ˶3_י=VWh"cI>.v\B톟b|9;fU<0,x͆$_xڲb;Ǧ󊲠-@<@(z0%qdLɠR9\V7?BF`-jghc Z+T>&y'~FR^[Ei^xB](-( Vii_&lav@\фQK`N^1sފ+5d ]ٳW5YgC4pJH},p_^22 8fI3OEy-"y/>CC*gQgUIjw{䜉S4Ug"uf]o/8&U4>I(tc>06]a귄4^%8Xm!,ܶ6_}QzL 4aDR(]Cd2FY ZpNd['= wʞ~r"m o^Rhv+c ]PMK8 e%`ܷFm0bse8xHm}U3ntǽ#Xl;:9|uZy϶O`o _\e~" %ݫ18lٱF@/?8 25%#޸ʓLzÄ{<f d| Au]}SgWc/W3-|40/y)I=Du.&Qk ,l:mzsQf9鵓 F"7`KwlE`JwK 9 :q~ed` asSuк{5Z,--V`h*-@Q24ݍ~6\$1O#B67x5M"h!W]k8לTa9q-22 t_yQߕ>J<|;nژ%X{r BG)a5+ǤLxP~wYݠN(x8G/N[7 T}W frJ^$c!* ;z*O:\LCJtZp$} ,p$Ë G*M4q/IpVkYmR^z Tb]ZpzW(JAs t{Mp540yyS^Sdz7Uq_gAI>[K6.xEP'6PDy{7Jϱ\nЋIw)~fEs:k)T X4FҵQ {Fq [П4-#itm CC&Bʃ⹱w)^hUc2(G*GOg%S_)1~U#F^3[lp iח/{^92X`b.S 8rs=ɐ]7I*$/ I w6[LwPEEG< Lĭa_Uʗ>ZG>sC 91S&|S/.?>L}6#gARGAh TӗnH'%`y^O0WD! D x|9w.&&7R6=VB6J{m8i (ĵی&R``|1v44 ][>,clb/YMmJQ@'!}vlA5&ŒP2m{YpQu\8FfBɵ؉Lu-zb=ulϏqjnHNNgpv"2Wc%?XDr!KR2R5]޿-X jd y?ETdm~CW*/ޫmj$`VD~¿݇}{}F\.4Ůq$3aJ7N萚J!6BWr:/aR>сBO еf:9Z<Ӛ["q/xVcʶA}?WBewvĜ sZ, ( "ȝ؄"owϙs,< @FõdrChkvWt*|H㍪U1~pbN, fX ߏ2o3":"}>5015'2ۘ%y.l}k̫ u]>0ЎX{[-^1t)8=OCzgҝlŏKsάb细o6A2Qqr! &̫*JB]|%Id5Zs',h5ȑEeTPyDJ P]Pz~!t=!W+,̂]g1{'<BM)+ES9'4-;o.oKSi\]Dl/GnO X8sj>`p'<ʍuY4D@u]?% xl$~*Pt(hڠ7t vdr*rb^o65rKdxz "R<6Bdl4k]WL 42 wO%T'Up4q*Ltub f$'mz0%vJ[ H^Z76!=e\YwRs.;yB‡rͱW{4(׈:Ż@-YWw$<Ӊ%'h*DGmuLF'x<`Q*2 ƈEs2\D ˨KT47>h$z}B}Qa~R͍ևJ_:?^S"ڄhjю*",Md|LfݼudN%`fcmbz=H( " &QGp-GMwALA:~79tLŴ&QFwŇUgK]0Ƈ$lD/Ec\ZʃɥR!RTQ KC+drxGZ> /=A5 $lNDҡo"1(XQ$VfP^Q?=*R\8s  )KЫsޞ"{ѓ3(FBJsGF;rti,kJJ`[p.YBK@POn)KY>U@ /yQi6{zUtEH!!s"C|',.StI~Ř6!W>!lz @l4h)A9n|6ʝ9,y§*3@D ),`'Yr ǹ<[#̄_ŵ:_w9KWџuz심|0F+c(*8nOzAaX.ҥIw$aά4}(,E"v~VP ŢOH Q&`jcXi+ @J^HsǢƲ\_n~(Z uO=LoD4! qʋ 9]Pšo|w{D i!FY]#~~9c2azyyBL L;rf}R%JVEwK *?[_T9JΕ#Զ[X7{ҋ]֗Qè_̆T1?!mIdoޑq'B>Rbr+ւ5qS$Gަ9b?X Q8¬a@":KX8o;[k$#SYP̿ u7uU{3o&gF6d(S:no2>vzfn,OS.ٳi{ $rG̖)/V=3mBSD]uo1xwlEL3&}-)R؉꒬vt HAW̼$` Fw9˻D麌F׼RzjI.{CrҞ$d/3Ӟ  jc\Q]B:߅> seǠf&S$9 #} ŽXGe-:_t֖!5,0@Sx.Uǖk'k[nŽg-,֠IT(# .`0@2x )n^~ }YauX D@KommZl{w]<:K$@^aWhcȞ0_$-^4"TIf M:0}Q̗GH} ^\q}q.q\xEYs6> eWz(9"-2I݉ 옕{n[|PCA5t HJ#Bo| [uC7 [Gjk 5IqB$?3BqJzv20t%~Үr@DBM"J0|9<-h'm?T(ҫ,W^4>Ѿ驁z݁ g H`PhM-AV-PtkK1ډ-|JqxtIRq E]O Z,xrW*Om{ e^F]>y%^p#N؇FS[kZQʋ#ˡ_̤4#0.K"ڊ }}74|Pz,j9&4 sTSe!E *TAó]N'S%p9FJ8 +v*?JC.[E`f 0hKMDt()}]#ްۗ%Z|>>'>,zW{RYdFYt'+_&4PHؔ9--޻ /\hqqO?<Dy t]fBDWgoeuƸZś=p1-; NevX#Hak%8mVׇ{noG0}\}PkKkvʉ˾xv(bN583 j:#s rcigm#. "@)Ch[:YsA=JR$rnypJpY N&Y!Ͳ'mC}JxZ3;YhU$\JpL{4SwnGDB7Y47XqT=OpP)pVp1%yEEsyy[+Zh_\ٟkgl_5N]dG|nAeYӨ^uHp)_?'H,vXK3ʇ\5uG(QWghpXъ-J [.wjW)JÓhʲs-) ů#J|ΛHQe~Dz^e3П!۷C8EcyiD!>Huz+% CHÍNQfw}|pO.FP1'Lv=ݓ]TSՕc3Q?U.Ϡ[űe (4HӲdu^DRor?h!nUޝΤi3 )ӓBLFDCh%ytdaH1z-Utl]U$K~ U<@'G TY/T jMM9i0'6a8ȪO?Oe\L^ AEї*,syĮsE؇t{Zچ}.\LX<<%kڜ1 bi?]..@3=MYm`z Yi=ד;{4Rš &I1ˎ^"$(?>q-B:jHDJ _*Cp!h5^q1r`{pښ#2a!U =dZn7 fe-XqQ&rpRfwg=agp_66gԚDCA)m$],' ziDeKůw:@kB3/V[%hB׾B-Ս`6iءuK4 Tk8iEռgFN4힀4ʨca7U]: $7*d3Z{$PuE [H\jDJFWS >u8_Ʃ.WUE,T0ghk"f-6"^Ϝ@ժOV2HN5ac8.>dίP iXA-2G=ނQ;4]<޼ =mC`Ve}U-Nn&Q8W ؤ>579c6Tv9b;v3,DžO[؂4˚V[tӷ8EdFƒ`H-L}WƊ'圫UL I`p5mk셕/9į7:F6nQGP-F+zO_RX\k %~._l>-[Xf2QcvFarLk>5c+>ř M&tur;=9)ϑbvpH%5_4X\<~](pK,CuKw y<]GKN=*"_`7}A3Qp|1@! ;k $KhD6jH0OU oz;zcr k^a¥8 z//.1c7Bgc_F#g`@/UU.p,!Ʋi`5>BEnP0QC?ek:dKLi3v0pS({9_~룳vkp)R5J?|D55]56=H= %P$m^QtrƘ R{g:)MIrTSn> s~Cf W_SydX:0nE{ڴ"9؂S4kL+TU%D'q dņkl`\VIŸYGu[kB\w)S5'ݳe#FP]x{sL5xH3G?miu`9DS?rFn2'Jt bDzr(1}]zgV$*nPUT&EC?)('ȓR?19,y-g[Ci}X_a K$342>ɍ=~C \I74:XtEЀ3?P 4]z>vr :r̰0pɨ pK 8GB/xcvFU#$osSpx17(ZKX7u pmѣ@.xC5]VX`٤,(C7mR3uq(sjB<#R;0X,cp0c1MTCiîMnA mݰ:`VS`.+ @cBTJFZP2!ͥG:|1 4~ {*3 U~.d|fw@g N<{Òj*PGۮ3Ì,M&ʦedKښ e5eg+|DwA/qz3gȺ'!!yǎ6fGv$HjCRiߢR'ش6qP)2;[@Ik\QYvYGz::p'x?yZcfCe^5(p<4[w*iKymާM$4IO<]Z ƽI@*kèC ZX0Qy `Z~C' -vdY*yq)/Bd+DBŇeVw߾e$j>O]T$x>_Kpڄ>/?X5gqei*['xڰU p=021Qmr1{'ec{1QKX.P~ ~"=P~>KsKXwgqK[;CisIsb|RNu\3lwlI/Saqy^1LBd(A$Eؕό 4N@ڵZ6 vK⁓8qK Ų`rxcM2p$(Ƨ^C ; Ri͏LGx ($)e򜜓KZsEFcp v*f+&A]OPq+$ƼM,jP,I%bje#*EwƘ&ZJOg켘qlme"<yըl *4NL]e[wvUkeP>9x=+/[lXNfGcctL?4_JY6\飍Ӧtk~:cm|jtjۇ󴬺&OqXUG7Yz`QTcK=^ -Jn!g~_-Shb3f_^w^_]=uXz5+~:!A7 D>,tvsSx3вVRʫ]fXV0< 3:QD{M*Դ插Rud)vt ~cK3&y၆-*A} _8lAWES6%$֓痬Iy=MR[!1P<:N \}kM1vT^* |N " "@[pƞU?1\R^ȑҌ5CdI߰ N@-|T릋^8\݌1hR4'7TCK%G͠FݝaM -bfr4O)i6lj//Kf)c_Dy `p@ q־Gy#/XV3an$3:z;[V Y=cꉄ!%oZ#E5Ú|IlNpV'Cok5aqTY (L}e;+o`(%5WζZY=Lv<ǭ1[l9Liz V/j+l61wR^jAm=tu#!?yvYl[bUjAZ-int+{p?t]"|М,`CGj@*,|?/:~a|U)  `OMBᬌ'\mDފY`Gyh$mMe洯 1{Rd(/3d37 Xࣻ 6v(]G&ӥl*ഘBA@3#ZMEYn~gzgH_ǔ _{c{ 6zN S5أy5 J!{}𻯁mQJ2`'yc>GLk [M h |"o.eDWNW0Jmot; 'cm CDL|ѭ4:sإݐuO.c[ɢoڨ_1gukM庚*tb}F搉$fqjYk:jga|3>@RRJjXu[kr[E ryix*}Apv6ء> P YW: b.l$cX#"{i6bc,vi &(o94b|LWl t&7]ba=} :?&n]'QF5}0h̓0 Ŧk>(<94X^9 v|/;xMJ68uեE Kn!sh_Չg'o?'/$ӹZ#/k|֬3sg1>G,T=c jhݜ" ܧ@31]f ^ڔ}7MMƏgIs1+ >.ߞ)} P WH2})&0˭(#<2 Ѣ}Szf8QD9W)M*IOF<*`u:#Xd%'c)|7=v@FDjv7^{*D(ySLʷK,Pv]|]JqޔP'•z/:&&Y%c zt PaVa>.\ꆌޟFS1hqH)9)ҷYOkB_ؘ=w4:OBK7ӋD8cv6ş,l^"Q*=Jy% غk hoąOuow`"9%ߟV÷3bnlwjRVF !o{y]+4f^ J&M݁v87]GYH(i RnxAvroR4%\\rR@Z;TyiG=4V^!W0%}\~[+7>ԒNK`<8b57 sLWR?KdϤ"?tҫq}ߓ8q#DۀЄ3%hel@N"'P LCq?(L'.e v%ʅ@'5f` E鏤J 2[:zoJf<͹Q"?ޚ8 u y{ZK>Fp0{R`{wm|R.l2T0R2^ %A`v1#0=fYojXNGN!̐[O&CL툗λZ$(TXHi'μE "`X&~4X3Xtʛ\H#o>}]m{L}Ҫ4p;œc{bU"˖(w&歔AI[oĂ.Xo ]W*N`3U,d!(:XæϐT4iěbd.V+mX:|Vg~[GǰEdw I/X=o1#$QV>E uދg6|ǦDip\Q$gN{(U@2}@Jx\7tX39Xj BAb/ͲƑ7L1q+U%F|txb\OgqR/nֵc3H-|~ډҠVj33A]%.jM~NOKg-6A?}tzű<lWgU[Bzgx8G#8LslX< ;\jJ}\):ma4S)+c,huHG.ADŽw+!ܗɻd?&WXdtFd$<M}N]a&;C<пi&%^4dKSfAӖX̏/9ث?}Ten}$v\#s9=2?w|2ӪNQ\)6+ (c7l(AڝJM S34bIokRbWK./@4@ #2{ ٍH#s81sݚu֋/)&*`Ak^ʟx~W0%1(nTHV=#,\#y/iszWsy?E_%y%|85&@O}6&V4lܘ2ƺA7r/n[Ҏ{k;xfgkԥ(ۅ*ya|v^˧NN%\&&ᡭbd6/~3dM auC BܹCJ{sS*P䋟CC9o^eƩQ|ۮI^\iTy־K+'c5z7K 鿢Ms6&Ho(%qp8i"{it8f?1GrAO.؞l noɕ hJ5`IF>!F94X8&I_R/21jV=<=u˴ pcG9K<9JԳ WPXh ]Eƃ%x+7<ƲYJaDdQq]C2rH.v rlk>#dLײA\yK p1x- O4?+ BY [cP?*`%5j4_B7r}p({ʸZl"KܓKVhowkjieK7Bx( mZ*y+o| M]y%'q_j5sfP>#"rG7d]:ihc5׾W[r?γ6>y)/*;2x57/v?B-և0xe4Ⱥ<&;/c zmQ/1RW|=cPeYxh]ܗwJ^4:@sUjgu,}#evnsP %#%Fـe{a^ʌ%'~N%ŻFcA TKygN?+>"w 11nӻ   䰏Rk?rV>$'E[P[:`a{%^}j =Si$]nf]2y"!UÒ3V#$o`?鿜9}سKMA]jzD,.Gq%OzZ$Vy ",3ah^082#o<qm+TƊB\ Hw0D/@p.5{$&+6t7Q) Вr"cj̍Ī`wBkc[d̝*{&;٨΂IՌ 65s*5"tRar^{09W^a/A]H,DK[(Hᔿ:jgtM1][#'G/@+|йLGɔz!ӿWesWJ>=BcM~366#Ҏ!9Sg2 Ի{P?-V&hO.@elE8C`rF)iC,L_$)Q,Ido==P*D 1C޵&`3h Z ?ZtoNpp.mA  (`$=ӣ(}d*hXYjfԚ6#N)b"o[?Kxgfq UҋXMSFi2c]D4>tvcAɀ30`;J Iv{E0ȸBbT,fF,.z|4{ssKȏ5GY8y .>`(M xl׭%F(_/"pjJf'j~ӵ۷\ 2X%k}j!Ap.Bް2яgW DtzCnL6<'%ܟlA|` M&$꺖!h``#m̗Q5dbM  _cs^E'ҘkX,ӃQ8B/p#'' Z1P9)ӡ3 m bRO7&AJ9+&$-wp1KTy!c u(^ ExYMDTz36X]ˁLc!,k)iXjn~ɯ^D3I ={TKޏBhw$wQ<侎/r,|z 0Uw hong->h]s= c{LuVKB_%(`Yrq|L<-p޴T_whsP$*Q%/}(7^קfn/s.tGN f}H ;!8Ҟam ෶hFb=55pM 9Qsa~JACD!3llcѾ`2U15ˇmކnђ/|Qahu>J?WqgG Q2o/|Znm _ޡ"~w^["~։$z0 d1$&1{Tڇ PJnK hd:g-yr:2ΐg K l"#Tȋ<}vsB$?bvu:yIj?{52w5&DcY8DM^{NaCvn˺j;[<՘(u M!aD}`'Fۯ}C\%R \H\Zlk6kY(uR2TTza Lwe8T=?UWR ^`;k۾D 7c4G W2(k㐯@l˖#EH`qը:?7PfÄdxhINCVCޕxU,mpHG+p\MFJP7q(L9"@.ô@(@8$$pe%zQ5'NqWa7|%PNݔ;\^(҈CWE=9,u#8f+!u;ü\z|5&c4{oYo" \#~ 3o 0'H侸YQŭж؟ o*ҐZ¨#8#qp02 dya=ZrR^haAl ejT_wUl״,&$5gwL6w )!|ᢳ̵*6.f D2t[v)lzl謮i?dJZ>y2cm9-{YG%)42MEqT'^eV~A&sÊw/MkOhop &sɨY?x;ՋA\-et]@rzM2qzUZ-".`CbPt$'^ yÐ!a`+ǹU)|>8/J"#ovVЏ,Ե4•B;Ȍ8_kW0ՓFp-P]uitnu?.4hFy?pWX&&[P+ SqD!+:jF| =ɵDS[Nפe3ᬽː񿨳:?.'-9H.p^5^8k̀FojwHMjg=] eRwnn~XiVf.eoZ̞&QSD-Gŋu:CXobp =Kp@jK2.r~ @ n=rE\nĺjqE`RθOC;۞fA?7ә 0{5LWpOS$e6Z$g U8EBs0Y8B[F}Gpx-n3G|]ⶩ0ONQMF.oJ 7k$V.lf}dFlIAĘBŬϐ|+gcmN`"pq. [JuKEX̗/nDcG€KJjZz(k2opn ÂݙV_EK+.udnpHW$ɍ,n&p-?,&jz0o,{EnSY|h39 odô󿩾ٝ[_SclP`}r`̪["զ嚜f:ۂ¾♅S;)_o{D aAǴPJW\|BEߩ$Q_xK)Ƃ .  2V1.ܕ֕; Lpopjd%LEv%3#P0ՈD<:i(%?`q[ʌ2LETi!KU..#~ĶrV1:*ڵNK!HwΌ_$7뛁a輬A.>gūV4-.ϲFnt) lbâ.Тц,m|%Urb39Ќ9`F(ΐ|"#VotsV9޲qj6<._Y4Y(}9O@6 ?yЏg /s5zrʳ YhJ6FPd=65Μ`׈N|nxt1)MNS*_dV6/>l0)C mN7M.q.4+ = 8_[Ѯ[& s&\ڟ_J|L-2 8\5.xﮓnvq|0}ʗ@=8)!l P(Se\{&pK)'5d:@ hl{$6SB䕋io1$ |\?%:DG拽&NUmfџAq%ѦLWhҲQ'ReTe~:p?>mzy*@+O0c?}fMu>4 &:mlmQN,;h>Rd Z)&l#*zQq&)yjPF:$ْE^h _[ |bdI.KVr29 V{-C>vt})Vc,u2( 7ߤQ@Ȏ:3gTJu]gaQS>"  Ƶxq-͖7>['<"D h+RkCZ?l36STth6ޔH+h *M>h@@ݰ7ng <^4^xBr2*MV_RHZH.㻧p@Ajݿ+G^U] P mFi̸XS tŋjs 9/\#`frJ'u965 'v=2_/ ^GmF]Ÿv/ [> 62oG\DS)ƈxδj㛢gySiw<$>& >JeU[qjgmq\⬕W|n)hGOgbYB.TS_.TK.)]2o5z  GfQHk&= Ի;bi@GO1Fn݁,g]fdoü\?KBұפ3Ǎ}twc|*5|&U6g==G&'ĄʾaVO4E!nDf̴5l#;J Ȇ! QPЊNK:2`IQ:P| v! %D%L]J܏1(fCԧ#?،?~!L7=z #kv_+7;K-VMvA|8(Td>\JQݢ3C ;8dhm#_=mr BF|mn yTDucf3 0d7[Bmq `c#5,vP)S[Ut<'޸4L)#o&wWtVC&mC$5}l,.HɡS'>T{Tצ-j)MT{c+\|9wX^t jD(^GV[ 8Gɸ`h+K[Xz7He9{EpuvlRjfƤ9~/LXCϺ)pRɒJDr\$k RqGmGN|=ݞ;HT1hicmϩ+^~RD+jؓzaU"q!~@-z(^n\]%2L@}BHf6,ٮ|ާc!asujz#B-Ƴa |uj}qYͷ̦%8$SQg - !Ik[.\ *teÐ}q$a>OkpЗduUJ~@q]wp9gEU_ҢJl'87vߌ_O /W975B_7"ӟ'`Dj6!ވ/j+ pV zMzMuv5XYOG-8ʳgaTUKׄkrq^0o 88q C#^ѻ.pFl0}c+l]3Xwd3_(j@Ln6~ֿ;D(7aJ.ޤ5JEzMN ;=7rV/g<>OMA [2a9(UTw?YقgxV D  qYIF:)t sCsi `$9n XpFL9mEomFgЃ}<8<47:u?̻ٸ4՞͞[P N,odoBż@5koVSYE`~Ħ0WIJ![G["| @gAe{Ni|JJcgN $˹7*]ԇޥ8On>t9K?_m#) nc&n x>=&ryV|$lW\c<(` QZ ?Bwjf ];hn~AYLX+w*4<7נkpH:5'8wq5HT|zղKtE+$nzρyi 6Ъpʪ`vDtF(1{!8}O* YB@!lw՚U$HgjmVFԸfOpdY(g?u-HŚ(m*t2[ AgC,{:3j ,r| ncRd),kW?!khݳ&IS 1L52Cզz+ix [X˽: +B^rϒ=$v@2h 86=9xSܝ^ @_ϯNg<D˨A60f>?{lyɉnḾRŠ^r95#D5#+?ŝ3mzІe)FۻHD/Y"$[9 \""k;lZ믂SqS! ~SqHbe_XBq/ou>Q 9=<@F̻Z #$Q# `aO|Ko=ݲTրas`PIG".LN x1f1(owa/d8xhH#㌶bm<+čk`Ƀޭ#&ͱ|mM! U+wmfCM6QlS/ujWϣ"{Qعz uVOXhM's*kS!UscMX nYLKO }Zނ8%u;d 5zo8*͊x\xQ.V0dzGeRiN0!wͷmڡRZGhzD6m(oXH#No^K9 _<vn,i0UFA=F8#gƛP8[[Z[}:,^_BL~v{𽻗i 2:4 1聵Pg90T2ᏀԜ//7m̡ M::耂O#Tuπkƿ&pZ7>o~(w3/:1#?oiꀊ }G.P-1*VfH[)lY3=V͑CP8vRɅi_w7}S_ k.l8Ow:U5,=:Ɣ4bI:0!L/ڒ6@JH2<9ֲҔhgX8ji\po8@,=91V(Uz$E a, Dtܷ5Mz8jT6x]}5޿;_:ļPvЅ2 rdڮyu++P)%*#LSm!dnje#`͞!,'d C8=کV-Ki)Fe̷wEK+D ޼"]O{>{gBݿfDJPNi'i5.a?.k%>Nj`x&tvhF>.f>T6&}^ )zps٥xx;bJC8V4lKkv0=ji mz%wAq: 9`9dRLݓ3I)y87S(T"4)ٸWs,F> StO!^!ؤVtLUgt4gp*)nZa\6*ðUOuIqqF ?ۭ8+COUP ?V9HB,d?Q(jFۏaƨ5n\8)'vrҀgC]zfl0Z"^ճ¾[[wvn"<KyUՃoJ23"%mXDb mڵW|5sL҅1tVgQCz9 Y !&{ž/|oڈ!|iFU_,c󑇳xZv/XV/C &ڃW(]~u[]ܩ4pKs;~ ]pfcRk*=$)t{c*5)FqSiȀr0XMb"y8St?w<9_̈́t*@j^.*h1:lJ-wMln]NضA9U]z|  oaIz3"=P{sDC|^ -RZn_z3s(~*żmwWk8n^uZ܅Tyv͸{ (fi^~w5 lNτ5ѻcQ|[seҍxa406L6G&C^> G\`$%Ni^S~ YwRE?VH+lkk29߄ܻA~j;)DБH(1v/YDdaTGK4d LDQ=I2i6a)׎0 ]h/"FsyS#ٝPh9:;B]WӜ%{ȯ~$ͨ(>.}l2wTe6AJCVӛ%@'ww(DܑܘT| !tfb2hPt kDP$M*$$l #}3 %9 @~L)'cWM̏cQ@u3*N>)JT@Dw矑31 Oh!gNb v?9}+>whdi1t\\ЦE{3 Wǫ胓x&ؼ NW1Hs ?<@[& L:vu+0}cLn-a-rȆsZhUIM?%g=N::x'Ӻ떡f,&A T;%T51"iZ. ΄{x \iҧuM~b(\.rԸ~=(aCHD HaXP1<- hTs@ X}/]ha &犐cD@?odrQÙ|\?V#qR&W)kS_h?1p ~{Ѳ.Wvbr""ԸH Pc q hR֛="zW+{C\ْژc~d0j T˦pv.B*eT^PrP▽\ ܱgo>QiċF'c5Ң!a$}͞FZ:d /*rpY~! !VfXq: 95Z$ $M86='ϗrҍ ibBc:<>/ؽNtb O,[3)ٗgE bGセGtS3ژ-hmA3fHm]ۡ :#C{#yR#L3Ⓒ )l?FwB|3t~mz80o-GBV(*jEq/rl>GMKNiNz%1ńf]اz\q0.W46D=Pb(:U&X"[RxQ4Ao-YM?}`~PvǀI'IJOk M \5L•P8%]{eu+[APEkyOL.\LQhfFq;DoP'Ƴ ,KRZ#amh_ 9v)d2,v)RSIC;S&,§~ٖN ^7kH3V0}me(EK|4(< TOծq3jCҮ 27.1sZKG)Zd9ֆzPphndL?`O,4X^>5[-zcK>Y8c1 ȍj!R+,B_UГLYC1mBSTI*iliA`g.*tl 'dheJ7(( 9ݭOZ 8ڧ#ג>d)9' c^uѻ}b)B$sdhIaܐ) gyϭpx?#x䱮{s6|~'wMXk>T+r X*?x6Mq`WhOɧՖuҩVφ~N'T`61 XĿ)P8`Ď,Kg?&q1(ٰ'I,?-K}`+nts53>-k.|`w\ڜAw|hс1D?:xGN9 ŕ0 t^ 0RYk$S;Ӎv AUOLb.0}!~9`BuA(e=<{c-Y~,]Wo[<`ˌ4ͷ=A0n_̋I=% |3>ۘn+\)hM#T,=zYnXK>)?H+JVV2eGhQYMK[7 nuvw)ZS̴S [kK-9[*v[V5ف+?n:;?)^lE1V!%[BY"=_l:맓\ 2 $)JZ5x) %;Uǃ=[K `_bf̂?F )NDƆ;I)""%Fhӷ&L^:R1Pc.W $ c럈dvka{Hrꋱ\*\V5YjYLVs LִYxI?dC.ݤgKoWĭ4*e`x "⸖[irV6oF[ wƦzY];;g[Wnalߢ[o~WuG+`yI FgIc)3^\9dgdbnjSfNQgXZ֟%3,)VczYHHnVR \uN~?A2% ",V6SÙ`@li_[tPsu@\RفG5h\hd6J3#O|6X57iɄ?BO hٽ[Pkw&ݿJ"?G\Cd M/9=J`6*I`KDN퍧 (F%R읷7e'Rw@Px ZO H^ (aeFlwpc]K' ,si&1!|Dnab4 Kk<+N)Ua'?5X}Il>:AH>s d!p<~q"4? ǫvK")xS|קN "?lWf3'y1m85x_#ק. e iG]=@No6 G}_Nݍf4No36$ 24ɂ]]3@*@\NA#y^[%:r nxϔrzXgS4^6͇Otpwe8gP!c֙9{"@E8V܀]6]&Tl)3R2NA>=uJvM[wSᮛ+`zf!Cr,N6`7C`܏'..ȨAI6Ƕ,!0j0g] &}iiFm|ʦҦ=w=g Y M^+ 11nXssAV&?11uu\GC*!Ѷ3|UbGȶv/+8N5Vۯh3r$ j£5SN? p[j(q $tf`0:\*_x ,"HI3:aa1$\WbO8=&8fKŮ(<0d)7qT|^ctqt)n%' a*E@dߌoyP*&tPJc;m,ٗ=1@Kjz4";*&t@Hj#! Q`Qaf@Ȉd#(|JNdDu>EauƭrMay SV$\<|}+/Ւ^h:57gdhG v{;u: OGC [!>Aq m׍iV{+1`҆<D%Y+ 0l;߃F ws\S^oAV( rvr/>NŮɡI#S~իu擵Ô|,t`" =l}fl ib8˂^0sհN`8$`N?DI չ+ iDsKqNzIPV?_1 1hijw({;d3Ʒɴ ząvQiT/?Lm\Yh+"-yV2K\agaw Ђl\(U1&O'fmrP\4D*X\jIh%3I~jw$.ߴGuQ؝}fl/󐀴lbE!çE ,0P -'5?ߊzs 9>1MJafs; hN5.FC/xKR"]m7PT![o 5Әxw&3x<Խ͒1 N3imGNPpu<Ǡ= 9ɷ{Qar#$*zqhN>a`+ߥ3RGേz;YWx!`t~B+wCZWE鋶"]g-ފ}7Uxp[|<.Oe}e/$8zi™ Iry|ߝle[~%[E 1WU/yxBgN1kNn8' ]¦,$@a$-4{)|Nh}5acօT?ܡ}'<:>D*0Dq  w G|(x(^S5( ĥA&lFd0)QJ0 ^]fH U6sYg@. y/fԴi}i!ĉ.Lj~Fcw#^ǗSn13edX&JI5"\h0iWBJ{[y{ӀL'O&FOq{cR5V^yB}=9f{wNjIcJOurUS+4yq;_6OV~Ė4%(Gn%t0I'O7na{!J%sV@a U2*hb3:%N#m[OF'5Pdn9u`̥^Sқ1 E;laYLK]ۺr0Qnި<|I/} ' Ү[]1ȱj|aDuq%Dg傱n1=Bmf޴Foy+Z&Hpw4:zF]5zM"E-gpa 'Ih˃\KRET%F&cj-=4C:؈N>dѸlr!ժ9Si/r; ޻bm!pe+3D_ jOYu :,I:q^B n*"uC vI3?{O"#ҷztrTw(Rg$;#{{}Sn픖WX{CSS<4\/]ĝƾZ {H{S̍z?;s&?a >>\PW_9Q҄~BpJ2vfh3 G 8˳)_ ~DX=FU5/czhjN "C/JGkBPq,M~׳P1J1"b,VwθoR@yK6*`92mI.x0Ep Mq"iQUit<M1 Lw 93Gnґ! (- +_A:%8(JO`BMڒ 5ؔQ/" հ"~|~Rv{Vg*e)1K|zp 8י~2seWT%+y bbY87nfZH7i5)RۤY?RUx2!dZ\8ME2+>=ٿ:yx|ˆaJ&ux gop]q^ 23YV]7S rgʄ&CS0Ug`8ʭ1bSt^1PzEӥ~Iw>ރMtB\xdTK&|y|y@uSPAB[_o{b8sZ*3cQԝB2H{,psL,U Nt6MƀPDbm# Z$L~v)5͝CܬJ {+ /uGD QFelp)CnI@tQG2ݡ1gBQvN<;!MiFCO rn(0^"]u)"D*1~.ZR0v_Hm`[ϡB Bjg4{R f'#yc;Kc L&b`g4Ө =Ո\X7W"6L0>i9 ng}^<=gC)AgB>/@cѐ3UN2Kx5Fgk3%ڈ"VQs=m^5SzM2LhR1 JKGu]Aي|9k+)9% %b4ZT3&O"*G]Gdu`ZB. |tzzAwh4mt>^k /IS jvD 6I|¤SBM> `^w$ԡ#UzGn75)׾U`_eYZӭ}D!;䝹SgBԆ ԅj!?O /kY+FL{c~HY\r^{D$z9򤕤h  XjՐ_8ޞ*k,ˊケ`YgŠ>7 öٲ%__s.y7lbwcA<|=eR&bm}濨ޢ}2a []KQ. UXNwƪ^{+9%sqџpSץ\n^g~zrjgifTqGգ.wAe1FPy(a5'$z}jg^% YoO zQ3\ͼU7lzsؼ#v&~Z24'$c4Ph҃ l"{qVz0њF?@IKB7+Q;S Ԡ{NR+?cd&R9GK6~Mx B \6Ȼ| _ňڴ#|1@b{dSKc &dI9Zs4mm^c& m5JHN/ZCdVk3׊Wߟ?׍l^=8әo|*>w-2 "h[&+ĽV k * 6w ?%HU\OmO+DƵhzMu# >\ .1Tx7лHHKuoz.1[`v Wq;LӶ-\u:9j}N q M1 AWØc k_SHjAwE{Gw'g4C~ZxnB =z=Mi@g_z}N"VN9[l'x/%3Ll ov#0q MBlG{n C5 bOtRyy^04N÷>\4kk3h^ߎKfP4|L+? NA7gLh\Ps;j՗ -a\98۟LͿv_ib肐;r"B폤M ?2vj^6ީcj(lW[F^pS)Kf[3:/Y>;;n<5Aȣ;oYo^FηU7oF7%enQ^Lf.S9"4mʸ.Ջ~լ\Vď|BȻ\{~m@Y&ÞCM+G?%0 XTV}ï~cD m֗dQS2 R`F"*)V_L֕;a-Kǃ}4([&hi,e!'TTjddASK#o;_y +br2mnP4sys%jAcRķcY![h+9?S9 >N$0^O@uz೘SUwMZY)<ٓeAcID/4`.*rVk~ 2 SOZ_]<:PEoaQJ9-$\gJp 0rĘ!VkEொED> 9FmK?5K.%q~Q12F9qgV8":@uk -w\ٛ829W_1Gee"*/pEFY2o'{`7H4)>CK`J%x3% C+q< DʾA]JnUGQWCF꓏U\Pj9Sf'2S3 kNL%[|:9+Th+EQ X1I`? 'vO{ljZ9܏~gUїh}~G!k>4^C*-r e!XNQ+%Uaڶa(@N=)PgY4nM*#9B$qy!yokPDym1L%1n\p~2պYnxnpZPZ9f8 ^S?ư9CV+!!2pip5Dk%]͚1IE}. S޳i޾N}MY^IS3SKpͪr 3M) >lK_^)\wBޡ~̢ #u~i^me<(N WByxJBk٠v) xo4mJ}fp m"8/۽)Q iw6(f`C.RKI K/ ڜ'6っeq`PhM~gd_|ۄܻr ϟLྪu/n<%{5TrALvMU;HqcD C~~XU5{K1Hl G\|c.&0NM2_}7Rqk*3FY &D,vlyOYK;mƙd\X{ۃȆ.$.!ʮe6$LiuȎSr=ٷD\K۲OhvuU,^>0:/0`IYFCi[.z36; 7 Ů$bZxZH)ɩC!&' ӡZmp܌ ahfw\R/{J䄴:oS]WCFiC,c&):!A}VK4aާp"oP ]DIe ȃB=GR E\S4Tj raD=jF\CG siJg V1M,R5}3hkeTGI:) ?!9 mMTnГNO\L3-I b1pv2ON s3s߰XRݧ XT%-c`,wM|,QQ"5-'ϞS:+'!'F$$An}jFى ` &lƦ"&_ T-W᳨rZ~#gc]x8j\=לP +9h8ґb?IK} NB&qFGfm434}< J ?a'[DqXK(QAbyݧtg2|8R", sOe>m#s :ƺOnû'$HG۰39q6uX9Eoj)7w^sC IKv%07@S&({ApEDaj' Ѩ-_FwCJɛJ'CH33@, yOtJ9ݹXro69bOwWA_}+bLBlDdW%`0/*a/PGj<.ar ɍijݼehe%- O-.3A`:|LLy7rwLFtSnN^c?E.Ds7(<mţ}~iʇSc\"KrD `Q z'1Fw=Ny9I9."XU/}aqfUN_rtܾM֬ f ;:֫Y3L83sF*"&}pVU\G&AuG*_y9f- ?F%㕡8od/6hdzњŵYIi丽H( NH:ʼno UtFR7G>PK/i -8"} =_U#L hgڄ RŷdqaM6SLETamC9n۩z|@9-/Vì`$n0ɶ5_V[D=yq 1qZ(X/m/#j]Zd jUV K-OLH0͂.KݮlJRE*v@-Qs~0d p%1.|\ߴ>HWlrZtnvp`,DZ"2dKle =6UdӅWi sN3w)ۆlٶL&<jFx4~vPutWLE0/)>h^ ہֺc[ȱox'vbи~ꂹ] ۤ)C}S=UgVa`|5o$x&.YNgJ}}PTů `F'n I!1Y)'xr1 p'pʶ,>ojﭪRzN{jkW|鍇%9םydo5 I[{h*} ֽ"᠂Hd^.hDEw̗֕fk؁U ;'Q!aQK4T^Bi sG>j{ ,$6=Sf 3)+\*u?Fz՛{ Dt,kZ4vtXyW;=qB-Dq! Kؠ.\ZZZ$7lz.=Ahe܆(SKa*$|f y efFɥKL~lUwx,\7nLx Y^ )mԎ)`Uc^-0Cazjm3׎0cQm6e\:ِ98ix=B6`P4cJަs5Է`)N"5'..YH i?J2^ LM\tǡZR`k6L@|L婝WC%/fEr3pWIUs%L'iPbxmI'D Lvjgز1#1 ਌Uͦτ* j"h̡1)^o F5,~vɯ*᭭P{%r7}HFY FLӽ#u;V Ka'%>s zeNM%J\0#ʶ b = j\} ?Pߩ}/:xqr#?'Z]h͸qaP#bڜ3poԜf6TMc]U0 atU6COk3xܾQ#qIY;gʞԜ߱4cq7|VXa̷5ѽ$:]KWH*BȎhqG9/w?]{oPgpxd W59$비 K;qcWt@bAWKqlGiH\$f &:(GEkKPS"Y9],/Mx}tC`Ռ^g}/G{6yyN@y9xϘ g5hݺ ZL;#o2ŧ ;Zgφ~+GEW.v#F=lJE!ߠ W=xeF@;eh"FJ5f:=Y#^sZ^k2]4ܷ@}.+Quf5v<˥(Lg>:<?D7lhc2=ApQz!;cķs w+*\ug^stz* 2'[;\g:`97n Os[).{!N)L寶 WucY_ޓE5)[g,N՘++*`C.;YSE؏؀Dq@3w`d}WyD^ &/C& P 8,xeBZ,Y;0+B/<D2Z8ŏ<.3Qnkx&BA-ѤWphoj6Mπ"x?lw%ΊQ[8*]z`X <>QHX3z]_"fjlԣŞk&f#7"d? OeD^ ⭉x;qEŜ';WLY#l!ŒsH vރ KFg)4nӰQGX*n.{5s3`(l;šGB΁lO>(':3O9~ϧK,q bd`$%, fGltQ[I{ED:e55?~o9&r"H SRzJ~ղymLrhu~"[Y"ΐ‚ZF8tzRK"!jT{8T xMfכZL8%ɔ`1 68es1/ncWYڨ )#I )C_OYNaepQOeR*nG| K|Ը8X -ᄼ{_t:+ȒHQ9Y9#w=%]őp4EM 0.ohi?G2xrN҅3u0fLj+"S۞Ϧ 8YN T XPl`xYD7f^# +ܼ8a#°&R]ɗ/{GʖC5!C7ArkP(Ǝ9ȋTe8[(KNӦ7khdyߚ_ȩ[PE3AO5#^8mUds!- ? "-*f#YNBv'܂$M_ x?5'Wy %bb'~it<+Xi?rRȣc7X;toǷ_>O?p_L߁[{ 7V^VFC@sKPUϤ]:pi4}FqՈ)&' +Ɖ.d%kFUدp~'K .X3OHC"iϬ>{3s:V{ra'J 9Qu瑾řl&îXFz٭| {w|99eLaP@д#rM#`눷<-Yi`P; QeRa@/n!.4^| :ύ 63F(^3;0 +;^4ϔ2p^Y܅PvCCՕa>b@Mm4Ut^ I``/S2vr练{C1yJv+|V|\rL 4Sr?N I!d'HbS[2 W*ODgc@G e/0ۇ g: =cGVD)icoX1mX"[WzZ9mҢ#:욷^kŽVn1|a]?W T ՔPލI_z=i'D4Zy/8gX/\TCr ڃZd|^mDSUy2 +fht%0]fNJjZ>)tZ3GFSe&԰d+s=QpčhMkqPCzG.=a9*X?S>eKlbz #9,פ'S.e!͌#j`A ,R躔,K| M ʭ=or7΢Zь XmE̍tzA]rɣkPE$L>O.U`<Wa.HSV26*w(%Ȋ ?y/*:hs_KhT浮F|Geֽy=Hbj-T1Vc o1 XS8(Z,@R!R,r#ǹ=H3nxy+M+ j ":hro FUrEAS/tdUc }SWqVe|dҥXYSj^Te?*hS| ;F3N+hP3 if$EʾD0K>@9|í*l/EXWq3q{ r0, e@.yUS|޲piYSƎ~Jac~Lxm^_OE4ߌb #!QuNciA +gLy,.^qȈj*b QDX+PǺJeM1oҸ&RC_T w{U{ޠ7noR3O9zHB$ѐ0^IYi#KyAzvB L8:j~N&.pƓf- m#AT l^F*͓.ŷ1scNfUçH|o}:5IFq~R@[!gگEs;dF.6:LHFQ'X5Lv+XDD)!렗:nB!dh%[n23`41w92OyxC4$@ܘv_}%*/ŵN!)E_ג>{?s 0wWҘ$hpToHV-EA3x(م@6Ѭ&#fgJu"I,C-H@:SPyZCV3ﵰ!?iJP˘h) _Tg%$`EQcSR ~ 6}d᠅6\EϷQswĄaFob^]TAL/WsHo1j%*(nw ӠT͕H#*{+kt }wq?)  xfY.(L vv愵Dd<.d|qeD%@GZW~$Cx22r먣+j ft;\T絙kiBta[RW6Ѐ/f5ChåO* p_?o=~,i)VDZOlNp so "W =z^mx 8xyB{3;E|`q ƖSP[2Tht>LхCЅM 5#EЦޞ6Jkexy i\1"|=嘳}ak z^-ɻK2S`ExKN$9Ql-6Q"{;*,vO[:$A}{;+ܢIWIM m$#U5"sV8,g:o=o)q~"V 2'US9WyY1" ɨ$^&,Y|&ק͉L'`3鷳# K}5ս2\%M#޿et#* V5tWR?dK|kX %ܖN71ShL:p[]8KzusPJu(;2 !/28wFYQMGe/4Xx<ƙ&\\:xֺy]>,#O [CJ$ t f>K8NF BE|:UAX:~0bNsX Z$8Zc4P%wPc `,?=1ŁdIE|}G.m5i>2n*@+-^T4@CTD?q,6IbzY?%6<5rO`0rxρv4+ `XU%O8/(vޟ)7~55g:uNЯ,!I,U\'B:!^jGt@o+l('*+`у: Zqv bfk ?-[˼ĵ0}fhĘ`AAƀR~+Yuf2ƀ4$B8泣ũ}n*Nvp/Q{iMIwN vf0+|IK`2<t誹oIMZU4;Wզ@&(ꤣ2.]9fm_[BowEHiۼn ;8aT2R'iowZ}Sg3hMC@<Ȣ|ZSAM#Ea?G"{5Zy9iڭżul"KjƸS})*W.)v3X場eUxAʖ+t߷67Q^9L n<6t'8DZ$ErbuwS+X5_k\|5Ӡ&Vz%?  M-ScEwLe w٦iqd{CVa | $? UIShmDu%oB9qC|%0%@hکR=M#B/VÅ&ɥǬ ]Wi Þ]?`VkAp/֩'kЅCIM 7IQ6QQěp뱗%z쑘9S /ծś_wPc_Yg_Ek6Z!SC$7Æh Mayh*+t}5Ȍ7v)KِU]V>:qȚXdQA%5)Du}H[q+UR6:`rpaMyLT{JElYyy~S۵1n&b@A0F"{#BÈ=hH^[(xfo |^oOZ~FL!#c ':Ytjj/"pӡ/]0HAHoV!CR)5!G@]%Mph9W=zaA r 6 u`>Rl,±nkrov0mvvvExm_"_„f;BCq* @i,e~# O:Vq^~ٮG3v0ٶJ<|AS+mh þ>¥DӐ]*j$>0yP.%϶d{ŞL*3Vz H5ESVMqdzupƏĊIx_$AOxXU%pը:J`L[e[ ۃo^ik,zB>vY|>5#[*SR*f:̙wZJqCCǟkͅJ0Q"d()^B%f˽>4ˍ*~D8zcp'%Gmi) n !q~Q[6jDo+PgO T0R, 4v2%;l sQBf 4x9<6A:. Mޫհǿgz//b2aaȯ,D ^pHAHUQU J0}ڰX7|COQt琠WsFOgJM+&)&S+m:65н}nГA|pM-"XYZɃeP <>/pߩ$xm^ci߿V 0AH@pΟSnX^B\TcozwAMV̒6b~֗_m"z|XJU)eeھ=OZE;n9cT[D٣Ql_uǬ¦^cD+"躭әB*f`7Lfvu CYvǣDxGk߫NZ8C+>, YـM5{y ]ZQ6P+Fӿb<>#Hy)@6BCSR 0c D;^QLO3O; V 48M:6Ϣhկr<`e\V wSK@}00>i@[5>XQ$Ւx-Ew_ ë`PZRwepbr0mx f3B,mVk3 nFKȻҬ&->\mGm̒3f, - \0Ga1ʛ7wU I0 Y_3lHG]k&r002`06"1MVO3K.( FV|yrK}Dm{nQ/!B“i=?6'XF}4\u=T>{~z=3ԡ,*įR ?TE:0J|ց|F7&ʏmp<uLcK.İ<]"@љ=BQ \տ+=3fQxe;L"1lTNvH@yT}nKbټx>ڼ K%L11n70a%#_0A|% i>mMf)-vC ;Jܛla_ј#U}̪`OBˋI.qHuq!Y(Z_Z7ѢoXnn .REVo0" DrxJM'g \i&bk}Or34JnB)o` Cj8MZ;% */oԴ!by[`ؿ>sne=BaUfs{@F!JєJ*96$(¹D1'? RaoniX.8oōz /? wrzdWӱ(<&lPж|:XIQ"U+0Xr"էPkFjCz5[W% P]5^9ƕ~̀߬7^O>z *Xd*f~2kt5ua _"|&( P}BQPCp68Kٝ6AixGͣ &9l5KP5?E3OBAo̝5ScxU&%>~^ P'.u, hktGlR)SVt0I1 SDyp~X"8MNAHy@0-/O :7{38MjBC?/AeM#R0 دIuZKb쩌^HJjr]a03 A# dsǸl1u}2ljKDG9k7*YY'>] odUH1aյurU8(tϊmO>}fUU]4-NRV] 8-Hۂ|8&"c8\IwK$혲H|;-/nj%'x_6(&= x1A r նW D͙"o=7;0%γUp^mY|I6ېM>Astg(NiH*!H5;Z 0k0ۥ %b$Tq$/[}dwJbʍ[\Y1΍^p ?>4g" ;ZNQFuZMh'Y@Z<7'ܪg{# b%)?Mp^Ocd YL5e^3DH lP_@݉ ): f#'g\u}8A_K4Dh(HW,jZ :)u;G:#)R8=$-Ka ңx؛҉Ţ0^_4B̠O$؍!7gx.v73iyӷ!͹hslD}U=v[hT=ozeEI%3*˫pqKu1M*PEݞ:jCv $KFk50@YQm2"<@Oϓ3HP,<BTù TdAIĿzO WiN/\ѕ{B@S $,҈w2}d*ڽ/k۵}$)FfU&#]z{ddତv &*ɁO6GW9|V[ǖ'c^Rt PgFDkXK'TLQ1匂Q\,,#5]J/ceL"?P^wZeAj/ewrjd=Eڐuc c;VFXz6E/A0 'ӂG$vBB| ]ǯE 뛄* *wKuO`uglJ"]OB=H\u e d3YX]`p$HgSodfY#ޢR9b.Mʣ KZ_j77~/h4vWit`!U< .fE_]S'KFA%1T:RLO=CCF ['I{qxj !~W7|/$0TS3~ڣ|ҏ?+hL(̘Ź$Xd-.pʲi%P=bwL׸s`5SfNJ6i^R5 {acx Iζ 6$(GOvlgx(4&4fj#J1.Wbz}..\| ;*Q%!~\ ZRՠgkbPQran{ӿ ("H 9NjjߔP?'u3$gHJ]&;^,lj3)Ÿl&Hh$W񈌚\6%`9.ZDy'}<9rVtR'B&DgEcFBw8UyWC,U"aSu:~BI9袔> 8XAMF땅))}|:u>e5YOeLlY/FZΐޫUu!j{(и͐'q`trHMo.xGKD9yz| 0RŕY=@^/P,= AS :ZS=Wz=u4)V)&$m{R~ZfSXmzp"l./-lH2CabuV}y0b{^JLIMI^'ABc,X s"5:ߗ͋:c?] c`W{Kcu( ޟs m ,>Y< m/(XIB*YjYw4 I[Y('ؿLIwzs`߃۽ۊ,vw ^K23jւiR5\/48w7JAd!6c΅%AUUIZ!"$ƒH][k6hcT!W'v0a;g Żp!ՒfnZHv|71_֮͜(aKb晌}F͵m9bEm7 ֍PSvf@C|e]RUX{?1W&iWFptONX"oޯל0`KHiPX_.q%3Q1& FкE6,o,T Ia^} <3?LcJFNv:ٴ_ަ񈔂#&psH>O7)"}㫜]}rH75u~^Dl+i 疁\ kJK4M8/[Go@%ì/IDփ -?du h86P|G> {)K=jo!K0_(~vȩeXi M{]7%K [@ oh1x l \t:?LUT眤YHkCjm{[HJE1YE>rޮt r^-K&ʛVY"AנxS1fsXOwMK-# )o0zlYh#k|(<^" =Y]sBNy r ZȐr>uXBo }'QʸB3yw ]!4:`"$P%#ejVvVI1rwԸ,b2GI9˻s:-S܆M )a!߿{\>ηyPM̏(@%ڂb$GG2B\溩UWܺ#战&ZMyYut::#NK;JtI6-,SJxA߿dzC07x ZŤԅv}HF OPf-adgIUW"s'09q4q[~rFK„1|jP0?6WVt NݷmC\*@Xi>L驻a"=8OO3  tc/r׶}U+/b sgn.ʧ-T𻰴HKET?{ ;M˲*eߧIyxte-䂡ؖu˴ y=\ .;w _?vCl50vL;݅Q(^^7.E*&gb4`>9qbX1lmgv9V-ܞܬ_-T@d}4IJ Mh4ׄ bUV 5iù*F*Rw-''.ItZ>IWK*V3.L^{6$QtGihMAwydcAcRP,"=ۈ$P(oE̯;Au|1 -.s|M{چV.ޒUJnx+f68' KT`IRv}~>_:Jceқ҃nl>u0ݜxnCOC-䫚$c@҂}(unuݬ&s|}-1J7v2߰&'~QON9xC56ֈnz]v8~fzh؁FK}~!A"TlypGai'ێ8[Cg-Қ2A_͆Dt?gjȢxĄ\!/ Մ0(ΊW"u;Zh ר R@PF7> U˧HκgYmZ pb// Hp'~W]V1QX t՜65fƘSELwU|G`⎅_5Z,8Um61O\ďX2ӡ=&dyIkg(*dI +PS5..u}ن;?V72`a\|1\ 6·M_/xf=yI5zWsK é6+i@И' B3t= z{9z҂< eptY#<*c Y-!|gϩuk 4>Q]uv9Bm΁ri֟Eg %ZP&ğӎ/࠺xN 9X1u#[hO!JsRZ ]XԵh'rCJåhw弹 =w@M0q(&|,|.HB1,`}Ha O Gϼ+ ѐ'ƼR*=4vVpי #z@qP&J^G*ic/J=hnwД)}m9į$D\D7 GXU whp7ՓD'x  &Ҩ!rq (Տi1u+T)ճ$[VCeQ p 9y Nf^sMcT>sK?LD5H4%~ %;;Gܼ]I{,GCDВ 70܀ɏ(pVܝy$9 :"ߐ0ג5c%j`5j>} Q?5jTs*mmzse됋2.֐iG,e利RN5>mp7744dqoȆόtAb{Wl^b#4 Hj}x/bf l^DQrQvsLzs_#s:a!NbLwѳ%UoЖ>ͱTbm?8_7<"M +J8#E>5Ćp[ A- Z$Cԗٗr̴p(k|ZiڵZX=.X5;\Ժ,d#`xO-7mCg^?`r?#TVkRc%g#Cۀ&;c39X`nrEaNJglP{y j ;Œ˗/hPL 硟s UU ~.D9akcgC&Ď`%"g+0Ne r*ܕ1[&&N6IF_iO\i6•OU}Ob#/btsHn\O 0 t] KW TEKq*,oz̉ ~>&80q@펴#/ʯ{}s>񋮂 '( GuXB mΙ;#b'"Th_Tek8ae":YI58"-Gn:)Cf኉ !$DP FU>]p?O_v!CDF2GYtT3iɀa+=2Xl?E_d҉+ٳ=4ǹ*;Syc_TcP*Rџ/&<n+tdփU˼vTM{eӷi k䩩)Ґ )5q3_[R ՋIl(~1YN^ZWԌʡ"-rJB'xA [ ՛P{ 1ܸx_l.10r-9R{CUsu(ٹLW*jXo<.z"yi#DSlQ5xE߭+Ux{nc#H$F#&5]? mtt.7b_؝'LJXf٦ʆl O0Urk@C(!㶈 ¬/CPFz+ĵ'TaN8H=*bP6 $[0fnab]U~|ENuɵlsmN-{Bd{MqlaÙX&9eYSjkTc!Dɟ{>=?BCk8zxNh2/L@ֹV&TD^]JE6{2j'N_(<.6*R -r^fE1)guw+;wI~}(=9B(=HrMw֣nC$M 9hv}E ̯P,!lJ0oE:r/i%m,sڭ[벿dpB YtM֫$aL*pN\Iu4#ѨG:F7YOfI9]{=b='P|;UӚ#aT#ҮBq{uBCŐJ]< lxQKP8=St#fj簊!fIRoVS}#mD$KDa8ڶ+jzXZ"3 Vd.ȇ0`ZNaWod|J9ߍ%HCۦNY" 8hyF D0 4'#ֲֶ5K!BzsS5t/~*[)7!~]h(/9[aT(c/+}p)b#[q^Z>A/q6 Bɉ=ZGf>OSNaB-gfp<]٥W|b5FQJr7f>te$[F|aLb(ȶ`ɍ\99taKR:מړ7qf/C:Ue!J¨<~nq7(u{u,Cf1e~5%Q* FaCXnj\{0!؄נ_Q1/კ.tJO*h6U\6QeYrd'7qMl{U:7?mG0,\͍7oQ EQbdx Im2#. vHb179ސʨp3%-EdJ )%\wmO(%M=Us>-*>@(xh5aњ9ߓLWan>{dTRwoZ*(^ d(JjMz8쯯 "H /ijrEx%pS z^&Hz0$ NOӟ޼x:c04,.`ZҍXVzI3p5e,Zj.G?]?U_7׼٦Y=axz'g1k-9V Ϭ`%U˞^ln:D6 /w/&w\OM)?w&NE`۶nYmnW\P_v@óH:=q $@nS% gɕ|{-,p,vV5"\D kvxq㘜ۋe u0L^"%`h$v\/ܬ`eRf GrO_;vf͊ikE@?̳R➩BWU?a4v8o%$)$Ac?InZ,tJ/~EG`GQ]?BL[8fPq_s,֭wl+3:Du?w[|`hkoDf>Cbp`H鸇AȆRkn,#S= O/aBuD:FK>cq-ꛪH3϶$&WEp!J<N3QKTh%"ևUw!riL00NNh`A}XeknbPL ےDoje+3Zf2/^x] 13>32&yZo<+X/ehP':H;P\]*:o. ,e;@*ۢ5+~@=]Aj5eQjK(1ӛ^<3 :a08WrՌ>67~X e~9Zш_OK}mY[8WO@Ly ĆܯYKQJ D`EETRݷņv[538pǿ?OKY3OWr rMTv K'!WD^qu1ʹ)A  367~YbPQp3Zf s9k:Z$+uB*Y/*lI[ǖAw)7%EU֩bWwD珍!_QGG>yf qL `̓lgHĕHAqxgНuhI@Vv.Sp_XƲSu0 vS=6wdH% x% {I1,PAXOe #gAn:xmLb#k:#ͪD! PD7 f7{=Q? oznҌMׂ8k45Dk*y=ӱωQ\#Rlٞ5kրC*t٨U(i3> +nE':1bY2TR!|I:b& 9mK4i駽nNk\,TgSl3{xL$@)w3E9'V(1n.XPg.61522o7&9j?R>z[RdD4l!FѮʇ-&q- y)-V|2͍kmv++C@11 C!TkrIC8"7>xֲ,<,(Tq |C Έ,# G]jR])r 7k֠r5>.D׶g' >3]?1&Q KI+Y}w2ܨM9%[p99y`[u+p#şqTYa!ZEp;-SYh>O_]-W yDjHs:aQqy)_- aBcg]ywI2A?Ma"{'r{M#5J`Ʌ= 1`=$n:)ZBVa)Iy*Ƨ羁]^akҾoG/{E7/K(97Rmjxrů *CuI:ރ ~Z#/$&)^L/rÕF$2X1VT|S{/l5X7l&K:T 8" tG.A;RhqUzX{޴{1[NPo:"ب^oύVYL>sϻ{9q5-$L  OS J5jڍJx{X?TR/~8OClXv۽!c1CļLܿLWˏ^oHX: 58F%uc)3d/dhHZ?+z<ŵh%YH%|t,vP!kf8 (`Ti.|ئ  I-eoBy8>)ES2a' (5 OV7nQQW-}渐9kQooruK? )Q0ty8>^X.$]*.`5 n7"HE \ErgDԆ2Э?U3V?KO*>Xal1N)crwQ_%*7t#.׽Y H!3+!Ԥ/cx I _f~e-2)y\_R9 />v>nt&?6Hskb>be̿,jѽXmv>Gc?lJ_nhT38Au p(H:&w0x^, 0'7Tj|+ )U\?tvCI_k #T"aV=ǬN7d9}I(_sR \Jn5E"rY3: ,yVır}-Gpm_f9& Y>KbjBd~o;.9@-ow ) YEoHurS4LkL1d{+E ))7X ʷvY6 {CuyG#QfJf&3z2ŢOWo  _ySiB%u0jv."uo"0w]\j 28i%zSE lvi ^pR)uT<;(yK].P`HNI?8>Ua(d* 8s&0ja#q;Dߘj,VoTAmNh|wX-I7jXlb u>*hrلJ\šāZG>I)5 hG'kG߶W19yvdGsupV?0EjO }.96te#!PTt;*G[k`>\Ũw*(0cR<ޭױoux\+ Wixcqзy>Df2]xŝ4v/T L[\|mvi1~LyAY?0Z2c7v IP՟]`q ǶP՟1ԉWLE`)֎NCr|X-7؛}L 8=0c ̈́u񚴙3j4氵Q^ C֫-\ScSɷX4d6.n/=-jQâA{ѥvh$\*$@Sv\^.9yW,goL$^p+}os@i-w&Ah_z7}-<٥T68zfB= Iɴ_yPJ&OB}ѧnA^;rIׁfr%!PZac!Wcrn3YoۓmlRu6χ+҅jO6k}`#TGi ,Yj})HW(/XUwP淏@~+kSY`|1ה-i_{O.mt9K 2Up߻Y] _V#R.!wmLkx?҃ZQ!v]Lh:̕2pIjoKMuBfqJ=7 Ci߄,{]?*_\'ҺX8>q-A1 Lfa+NĔcgQ׶(~{щ8cngau|^x(1lai"̲[<$Jn'V*`bKoD%{+f$ 6߭$嚬\%*%"@&I0U ІH;64m-W"lMAbdd-1?@U>+{+pE򑈂i0qPfc =ӷk$:N \"HPOC*Uy2kUܧo o?H6GeSڥQ,$В S+*h#;[=DAb @$DC~aTIeCq1ƍʽ 3rn:V7BF //;mb&:Of&[71уLFIQZNjCMai øxz{!)(.ꙅG֩U%?lKE7`}\ASfrbsWlX b?g {[bc6=9n:aP= (wIN6rpˀ}+T c]"fm`Q+O~b|r/N 6P:Y [x}ʴ&?]N#0Q=y.LmwcZxjr¸jIYf6XhcG<1#TgKLG_iRC1#uNzGuwL*@rp'J"n%t?=U[v.sƂϲLVhg`0Yi?֔1y2ƴDDžt/ 5o*Ŧ͙$k+swmuN'k/w߼:g!"=Rv3ĝ '.HAבI$q#[Tw;b` zE\A׆B x2:2"-q(?h pڃg)zt 8~u˯ M|[6!#c3@z=$z0劢;wJtq79mae-2W7ޛMn^}xiH>;C#&JXFqhT]zqTyroStqz0 Ta_;TQ_ mjy,i6&XWUk_/ Ag/~+ܨhU1"H8'~U8&$ٶ],(eԱaMex̳ {by}BT5ü=m#`z~ZW֟!h+ o?Al[mM6drD}D>I|Y~Rī.K] '^); \/ZjLDd \]2ҵ&>v쏮-KPLiD7P7;/VhmVPC 9l2U֟'>DH輞7ʜ悩8PAH֬*oEoegjk m; ^p$CI|v?4ʽ5":Q@9yTe;6PT䙷t}ǎr )0Ԟp4PNsi$UsH;,lDx>!?C)0.z EtZ~TוhJNT^< ~Ц641^ WEbLɆ#1%vWxKfC# w"ULGtDCx1;G,Ii0YNY:ơ5_Ѡ,=AQT󷝨ވޢM%KNh1s[dtee@J3(BF0hf1lz0v?H C޻%)u+F蒽?*5% dTr?''PsAH|qkj:/yj:&=LZH:RR+(0p>xrj:i5*5=?Y.C7I+ђ=dI%ox]ޡ*3}Bq NqL!M?rMtDjv{N͜6(rۏ˽˵#!Zμ%,[AM bXoɞH [G'8}Go)%I*apϯV3 XHvqNAl7}>\ vQ6o}[]CIʬKŋǏ(qګ=; <>W^/(Ϝa網\kfkTy<7.#Gm*gW"gk1+t[U L !\TZmoWbvBEbtm:-GJ''T1G3m7߉*dFlI̻o{=;#te̿6qԂ|le zҾbc8uNj2_ F'.3 Z˦/*!p@X2)ABWij~#e Oe-Dh@":6e"AzY.ߵbY~ eTtF //=EDcI32#W(-zP}n@-;9Œdt?^mr& |:vZqwmo Oϙj,Ee !y(@CeNCTi!rkO"ཉ]^Ӆt.ꠁ,ɟWZP)#|q8R刕SQ~" .7{ǀ Y[LY_9ɝTXPwjҵwd[HXn6~@Kݟ56ӫtT/=^ nͣ2_'켵<-H<12X4>.+6 &Rny2O0,V BD*zЈ[?j"#+7$:J+Q1YV-Pޱ4Y0v;Z|w"LZnJE~F]_jР2$j2P"n,"mg,)Ac6,bJWВhz4nsγr/'}wʲ(} kBG܄\wMǁM}C68[Pkî.c~Wc.SJV_mƔH3𱔮f$r5gIFoI„[܃BQpǒ5Z &(_=:2ъ].zntzBSx=E: T)wVjNOk=c3,HpKdئOΪO&TzmAQո)8mp ЋS~G.Ƽ(2NM(щ8:tRyE@S<)>c:JT؍TGTn'}lݳN g 'h\/xs6}mtʢn8韼e.1љ_6t5ty@6H.](kZog8m&$^ /[bpп ^UR<A6CkK)"k@*xxŐ9Py#)+aӯ Zv{468Ztn}"c!]x.' 7P4i>jZj;%%-c< ID1<Du+w:I|zu+ So*rsdk.FVsQ3v ;DguiC!TfyQkA2,$nў Ez8mܜ-Z8߰U Y\L\bA5rF޵Y}[u9PX=`yZIvlp$ٺ%x{tS`T^F,QЊۃLJ0(UP_IA@ Xh,<4KOhH Es6kw 32d7߉ O[EoiNN1r< %0_ HChhv@y>/_x0uhc8ӷBsZe@(\5 /6o?4̋|̬N Vy ZTf!/V5C=|EQG(Tgf\rEHH${E#65#|4yas;˩%TqeP*nC6P<4WDfC,+|?3TOSy1'cJ5>-d%T~cߙH[NS$mqgzΟ5+9 E5M^HqPʛ\­eJ洸",) =ӂcuܛ ߼ qN&3 2~NZ (nmx[]*週=7qSqN"R -9{Lʱk#6$s| nu@@]]&Wnja@74qT^yc-.nf5{scĒ =υQB҃|F̐x+T&;%`DŽA= NX| ~vBh\%ҝ,9@\ 3 }Me\"z-04A-5JK$](z YOX#_nfJAhrT_(z9 yr&ѐgKqn)q ݨft|φ)-74@6+Q7Wɋ Lܴ<^EEX*Oչ)O/69 pf5RalG\NpbpQ9}}XLKAҕFuF9hFvi9<'XNHޣ y(fWĬq'.WV!֑'0S[>tѷ`'1yAT\9yKZ1I5QqؒHgJL5Kl˾܃TXH;jvzO][!҃_ bk{/uEPY-.W0PGJ~jSw\g6PiIWt8@D~o?I 8atlRoQmu^oM%bo%Ȼh%csG$?g=öfW#Myp1߃'U=*DL/S[>? R'?Q*+=һcskgI6WϑQ?D($_{o< V|Ԁ&BkA¸xRJo0zϓա-w+u[@[ciIaS+\ܡuJ/o, Z1 ]bX4G:ML'B|.en)#IN i.s&[5<)&sOt YK)D/VqI8 y6rϱv7^G&7LwnL5A rgKIs(;;Dg4L潜tPSNeG ]cs}6Q9tģ ޱ&dk̚Jp&>>R #;) ]Yl2醯$ *w_sZR_ 琷+9ٝbBnhf?0#&?^|)Y@EzI:VCAٶZ:n*4Fp*w-Z ɿqY :]` . yK~e~٧R0M@,@4 ^ǬJҙ{4⬑u`\oN/0.(>S Ȇxe \@$$X7PZ.=nXO MW<Zcw\W pgWD@H1bNYx/ἇI6Rwe3!4@F Tmcb8AK(t/Ӈ:@7w~(d$X{gYn5Er,МpIG FNE"]=}lx0|:@p*0fox p.pmxƼIV/Q|:wg/ٺ!cqFEd:" EDއFX/ï=ez[İm٪faxb0B1edp/EJܵϒkZם%c@S |S1))Gd!z8X‹R!C H*@SWk7TY̋7-.O`CW<,.=sXOLh'MYaow_/Uy`L֔M҇г,HKAmM i*蟴8-0xEHN> LB3D A-/ەA`O(evY|@_HLv+b݁Ot;FglKK.UUkZb,ntsm8At^nIuYSTEq9C2BdBz@20F$gjD<JVJ <{6\p~^{8ꑩ߱-"ÿ)6~- \|L :e% 6&b&sr$mu=iiPj 0 #{ %}HbCpX @zU<$ñ}r2t長)YhxLbG-18L Z`ݍNHgw\y v,l\m aeI #/H?Nec$jIr}8+Tt|441af남z}J5sw|us"ިň0_)rtL6]~a n:BèsOiܔ|,Sd)"钇MQ=%kc*fmrclڦnlYB ir)v8>^sC#!{PgG5Ii!gUTy69u;Qsz$`#--׉3.*R8@$<ʟRdyİr(()A+ˏOcH%hwak5 Q$;2AE^>l5\ RyΡ>9Z2(+RiPUu :Q)tx8Aˠib)FmWװd\V7=iG_3O# G3)]>rZ_7!UUOlA.-92`z*vtTP?KK`Oorz3 |>> !ˀQ'xU*!s~k Zیs#.cH?wNjsֱ|KGc`iY|PBA AxdA o*>?n-پSF LLgG/z\Qо~Kқq'a4"47/tBLEfl ,am甜cȉ!(bB8^]vY Z$)I7喠/}9 T @G[* M6ZG|DN>ͧb]t=%0/mfhԛPԠēIQ5rdHΞ"5AʲG*6t`%.kMFފ;c֫c>[Uew2`} YﳃGsMą?0ڤ13y {D?{,HVF6n옃k.qJ 5R mSQn$R Y?WQv;Ǯ[xB7vdmZ﹊Ek3Rk2F֢ܶ]3yo/ͻWY msSYq΢7 M`)>LdkbBx\8 3N( +92#BH~OJ<}׎,l߄{-8?6`[іz0iV=n+0rO4qnmG[k}ԁ <\ +_ҽ} /!%C;Gө[vp>~A`cӐq>Wb^c{G9(m Fb<@EK T0nE,JƮm{5-5Sw2ru,yɰl% ]O9ӓ?|MΔphH x]dv@9V̺#|GK"Q:~HWc](kZ>R J<6)0`<~b AGhփV%ʾ*~-B ER 7;j}'2+Ou0spù f(OX/Qvٵvlv$x.o@ [ S}KC޷K454u-OD6q]ˏzJH|e P:]WcTb1@.4pf"j 5IA(P7"|a2gE!՚tH;+ol̃7;7(Rcxl8*7}jn3K{sGkE뚁 QT3 _(5qI0@@8ms򧤋; 1@POK 7A@+x٢f:b`2*&ƫoCx|(x2S i^.TFb\јʹyԿ*bf@nWG̈́βO+(~LKPQ8gڤq `B]PqkW+&yb d$VxRt7;]p8|0RM)p]{P]7w4)荋`]A_T]@yoh悀j_DD!g1@U6}(f[6A78$X_)3PIBk=)CF&ݕmɽ=A_` T~#xR{E$X'@ ":!NV @܉F'ؚ[H*3`DΉ*y{Kn篤Bcv%]+ gzu˅'Sk}HAeyLA]' `q7j4og_P4Bv sj} @uj뼉!lY)jڢ820VIF0:LPm2icNFAA8 }'& b(!XvAL̈́$:qFHW,"+!j^WKZ LnbȖ L7u \~0#&1dUyHl _`K: %pE7DԤ N|62^3{ oPsePB6`g,Z>F:NUw#l}aC_'Y\"n=]1>P,46.L(ڐ.5:9Eґ?{lVdI94 fh[da0gȱ4l׈n2+')eP/#)(BQ.-QT'P0p ۓݞQ*DŴ՚l9F'٬&+Zo!Ej>9.AfsM-~伟.rd8eX^ F2N뿋4sPWh")w}aуa@>uEC%NQG=e*L4 JdRT:g<;Zz:bI%.ET=W$RVPo)jT#K&Y9,<`Qx\p? #oF2%&, vJsKK~(:tcYbYKذF'v.uê Y.K1 0Wc Q7q-.G)o3xx;A/O؞D.3Jƙ>;ɶg&Thcb:I4j0$p2@( |YP/mf_޻u! RXY$XnKkgOz^`q'sd.d5<%\mUR} ?GbkjaC2 Jе1y[U6|ӤPz|}K9B) 3DejCN(h8B{'F 2o<^\A"v\:$Χ;&Q: Pg'Ҽ6`Y15ǘ/1ΥTvLhV}?/Z&[SkvCޚIbk|@bK!L*_`̀'15jJDrVdWMS=5D~n;ev5(T]D~F`Sw}RV LpoX Em_ʫCZ`y ư_c)^ L7_D[d1xkJ_Ch "8gαJz_EH,-bgUU!_}"c^92A S:BC?=M5>`+c6(4dKM%/]Ue3O(e<=U-N|O Π¿]:&k Ĉ'5ƭ3k᭩ņeT|~M7JPD6u鈯rC^FvϏS⮶) [eCMq58h c M#&,oqd",$t􀀠@WpBk3lj$Ҽ &UV Vt9'Jǝ+C>@lmBWJDU |g%rh=6/:ʨBfU@ %v(ACYJib¦0tή4hYRa7gfW/NfCOt 1ʂ!`<j>Q^{tIpR}纋H@rJ2F㈋0ɼΔusIp@^RǹcƻƞxJn|~vŮtR!El)t(eIxOᶒҀRZg z\  ƾ!hY,K80(mg* ^VvBNͪZ '1>\<vsiu;]4<\2.!tVrѥԪa"X(|e^Oip.7]{yJJ%i9tUd i)jgCt񨵷7Q_x?~c 5-g̰]\:Y -7m S<={*:/'o*mjYm[ݱrjlXq!6ԀԤ : YZ