pki-ca-10.5.18-25.el7_9>t  DH`pdj$ƨ11w V҅7ԜC.vw hRx!^KVteqRhvo|o?RQ{vÝdJ Ws'6C*hV|z-檩vя^bƀA*CUx#S xJLK%;V$4p"K- sEQ*g3e#0bv OٞG5p ~9CA[F @W,fn/4)*+0Kg_~-Y] '6a;a-NfwOg@sbg/P)yKI+*۲Pqw% =.{-L%+V=bq! )yV2@O+bzo *y4ٳ,\ôLk1?E 2`G7`>d ${˻Qp<~g2Qɧniv G gM2]s Znjt:+r,w4Vv&>7P?@d   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P9:ÛG iHiITiXY\i]|i^]bޭdDeIfLlNthiu iv wixi<Cpki-ca10.5.1825.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.dOx86-01.bsys.centos.org%'CCentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEGl]P'n,1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>aB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤dO^2dOdOdOdOdOdO^2^2^2^2dO^2^2dOdO^2^2^2^2^2^2^2^2^2^2dO^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2dOdO^2^2^2^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2dOdOdO^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2dOdOdO^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2dO^2^2^2dO^2dOdOdO^2^2dO^2^2^2dOdOdOdOdOdOdOdOdO^2^2dO^2dO^2^2^2^2^2^2^2dO^2^2dO^2^2^2^2^2^2^2dO^2^2^2^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2dO^2^2^2^2^2dO^2^2^2^2^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2dO^2^2^2^2dO^2^2^2^2^2^2^2dO^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e1458b28734a567f4a774d647adce94f20133f3c013cbb560120d812e090150878cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefe0cdc0a0a32d688202334a77982bb2d63244aa5b8570dab545db1c29342b3895a2024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb643811c199c1d988747ba4d5689f9167fd42a8ed07039e28dbccc4b744f4cccd469e8f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a10a6cf49b1f62522a0f22ea1b12339ed6fb418b2e1fe1a30902aaa70226c4d7821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e09f2836fb367185d4cd4da6b1362006d666ebae9dadd433785321b143889a46f5b0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-25.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-25.el7_93.0.4-14.6.0-14.0-15.2-14.11.3c1cY!@cD @cob@bf@a*@as@aA@a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-25Dogtag Team 10.5.18-24Dogtag Team 10.5.18-23Dogtag Team 10.5.18-22Dogtag Team 10.5.18-21Dogtag Team 10.5.18-20Dogtag Team 10.5.18-19Dogtag Team 10.5.18-18Dogtag Team 10.5.18-17Dogtag Team 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 21): - ########################################################################## - Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status [RHCS 9.7 bu 21] (cfu, ckelley) - ########################################################################## - # RHCS 9.7 (Batch Update 21): - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 19): - ########################################################################## - Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen) - ########################################################################## - # RHCS 9.7 (Batch Update 19): - ########################################################################## - Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [certificate_system_9.7.z] (ckelley, mharmsen)- ########################################################################## - # RHEL 7.9 (Batch Update 18): - ########################################################################## - Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen) - Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley) - ########################################################################## - # RHCS 9.7 (Batch Update 18): - ########################################################################## - Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [certificate_system_9.7.z] (ckelley, mharmsen) - Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)- ########################################################################## - # RHEL 7.9 (Batch Update 17): - ########################################################################## - Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen) - Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley) - ########################################################################## - # RHCS 9.7 (Batch Update 17): - ########################################################################## - Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external entities when parsing XML can lead to XXE [certificate_system_9.7.z] (ckelley, mharmsen) - Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)- ########################################################################## - # RHEL 7.9 (Batch Update 15): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - Bugzilla Bug #2082717 - SCEP manual approval failure (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 14): - ########################################################################## - Bugzilla Bug #2074722 - user password and pkcs12 password exposure when debug level set to maximum [RHEL 7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 11): - ########################################################################## - Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu) - Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail in FIPS Mode (cfu) - Bugzilla Bug 2018608 - Invalid certificates with creation of subCA (pkispawn single step) [rhel-7.9.0.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 10): - ########################################################################## - Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen) - Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could have been worked around after installation [RHEL 7.9.z] (cfu) - Bugzilla Bug 2016773 - Directory authentication plugin requires directory admin password just for user authentication (rhel-7.9.z) (awnuk@purestorage.com, jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 9): - ########################################################################## - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedal, ckelley] - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-25.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(3nS_HjeyX#{gk.5d܀@KZHR;[`3ErCh,P3J b12ܾeVnO#rZubGr.xEӴY&5R;,e~#k!]zdĐH<xf{E= I-.4#OѡիP_c[gg>s2jYFlY3)9@[/a4Ւd9|G5+'8̗LwZ6AD\G6䪕=4,w/ё^ WowG R of[5;nE:v5~,p J d"D˲Р#xw&w|A9UX:O SGzpr㺵6FӑuV͟hkc=(lDofaڳC+xQ8' >ɞ;L.1=5EVpVoC!G18!?s-:7k ni0 q aw 4  -L~x;.Kl5|I#84Ww'e?Hʗ9ζ'5\Wy'5G +1EY/@"jgPXwT~V@l!ŢNנP 2JxYD8B 5]Ἷςy9UGMJLئb<&UFJfxZ<+B 6BPZ',(]ڕ7C`zzekRP:؜buZj)7f7|z-}4D `LEld]2v!Ll&"a:VQ}mZO!uKß9ȇФ+6ij g$b'9TX::]0bP\#bQN-EG҄./l_ :h07k2OHK"pȘJ1W5${,_t:Yre5銅lյ۬<XDO6eT?${%:Bj8k7-hxqQ|R GJUMF6䟅02 uWOg-h{}@%f&=/$Z.GZݓUMԹޱIU \%Rz+~/ qwnWdώ47njYv 4YTXS\Vhw%̮Һ<`C&Z_#PYS#2MgɯP֖_(,A83H0cȋ ^8XKXZݓ2)&בx# FnC3Uuqv4LA JK|Zs +~4S1wG|6L[c'UΉO0 sH~yr{3R jrF|?/Q&yfɆ݌j*h}猄4#S AN@?h'%>,G f"eIeR4b暫oj]+KnEn[@9AA%|8TV%ERdN٣?Z8}o9%8F)Vt5)'js8ma+08)9Wm51z,lhq!u:1(*h~c˟5$!a8tHП߷JraY6e!n[{i3Ķq{'>E|}S7V=;R\ zRSv@݊jJ{v40]<qA/t=#?tSa'VLuB3 % +c$6]6ip鎋2WwR Sbfپ/tܩ.*btߌM/JcIΗ.C<̴gJxD~l B·yPMzYa=s! eD_08#)0^®o0ǿHpk 7xxw-AVO[mLb>Pp ,HݶaH}rElioozg_`v7yr2!-K7Մa[붟NJ9io3Y-Zr @tK*|yT5dU}S'HR r>jZ58>_c/ghtԑ%1 as]4饓(Apc Yd!RIt<d_( 3$GVȍdB[ΫQjspztKyąD4\GZqhT4WBXbU!8 ؝Rr(*哢rCUYӤ 3;/_*bA鉁*VO0 I1H"k(aCb҅Ɨ`h1|c'}cK&4ej @_|m>â m7E<uWppm 4?sgS!^ocx+@O LooRRW03^D_3)хs =OΕ iW}ݤmp .OsBJBK r\u+E(^8UZSu̹t)s5Ϡ";-Quݤ޾e_0(sq3"p}by0VT&gJVҡ4avP-<4{u<\5 g@vAtiQ +À 7Njcb:?f?Q6lb]4io+| QnU# E[$Kȩ%[ u@X&3~R tA=n488 $RB T5%Ymv4& QQؔB)(6NWVy@ODkF>vRpG7۝ r|q֭16F=O)jjyUbGjmuż#!L$3Ma{$vR` (OIoV(#zĆA! 5wL(gflKq5ҹWw{g+̶Zߔjؘl"@T[njդ]~qPÌܩ:8Ĩ)ٗw|xKD=RYfbo3n5;#lΧ ia[mǑSc-[) k'Z/xN0k&x.)BKjݧI9d= XJ_Vz5ܞPŏ';Z:5ՃF7 5ﺘbS*M'%9;"w~QR}๒h8ɅK5CR`ׇMlvE[/{ʐ>|!w}.v =xn|ēy]B_Ŕ'F :`σT8VTֺ[aa?B]gh/ (!vI K r,d˚hx1Ae/r_bJ=0KO :p ~bd*y9[oJe"CR]˼"y pٳ=}zQRdK#/4WoAݧz9o7Śۣh z}}[?І%ko!&CW1_8L7qhFi^AQqZw)3PqɖBGX^7<^sGp^+.RLMj'0nmd Üoi٤0I4 A?"ن˭GT-2j$QA2UhLXɐjin$oeռed6L1pOkBU>C8Iiq:L?ۓ 39$yWi~XhN\Lnq2Hǿ&1zJ3hYz(uDGeޓҳĎ:w2d"&=MNV ;āSv3.A,V ve$x(f.kօjq5)L00n7Vb"cO:VV[a8WB@%XZ&$ȉYKJiq[ⓑ7{W >;qN|%"lH0 YlJ Osm4yLmxҜ[ނ/ f{fgb}?A_eUd!F9]{y/h7";b;(xj'Hjq L$@l@;Ip^ VI' {Ж0X'+Tpn*)[! #jfyrcȽ4;۬@I6PNP *<\V׎GrfB4;ï q)*H`FGۈkA#;&%t)*Ozd/RW5k(ꀳ'Ng%qDjfb>9}!5M )(jN(*^xϨn j骎1ƒ P==[1.夈S׃#Az'/NrfJ7䎗N&yR[1->  (sN ѭ]cڅ.Յ)Δ[s5Y).˛.QMݫ ox>#c4G}} Syʓ n%w4EPD}:e|/v6M8r%~qDGHCQbà=tdM%lFx ҵ@Gc#Q3£EC&BȄ\O g͚;(/TOu)(TXD{kD HN{Ѝ0+4TͶb 5xj@@2s]OI y T-& Yf/'K"NP݈]+k;5PcaYKR#)}P]ͬsvErb۷3ɬWnI(KMWBRBMb蒅᝴XfF0ي`, }ǹِzCpBvI:eqA42z8i:Sk]E2PǨOPif\53&]s*IS $亼7'EVbnIYu=nw9፰It<˦Z$: vҔ{/Zlasx`K0wUR׊4nD@ ]56#㕥[8AyNa:H9Ev ^a)*HȌJ~d)Xq;@z'.( -*`V}k6'vj{/Z9Ib1̓hR 1c$B.zjSE,֗3U]r XU] ﳇkJ[̳ۡ?ߥILvJKRby;6z4BU~J1)ά>.3p4VnFnMibc}5hVMO0 zw\3*l܊"wXB>!xWSrPCZ"36?kZ\BgA?ג< 6Z$VwkSgCֱG2xp8:)0zIr+˭ނG͌ ,iIB];쾊k,@Gn>57o$v僃dfL/bR؁J)qGRt䨻.1&-q9mw@U`k%_HK%'+̀(($ kV.,3IdtC4A/vċk\٘z_m% </3"ײJM;4* ꆛM(V9Ơ4X'r+\kԵ`6GBM߸ÖԍqgKR}]ly\@n$nLF=mM Atsv%GT ]GE/qVAg8Z.]GbG3Edua]e3P&,ySE=0Ji# rRVDN3-NWdto˃j=LYMjĩdӐawek-4 ;LZr b.ԼiX>?~T$~d^}BŖϊyF@#1#wl[=.VFL !.DVJBTjhfuqoC=m rbk9$N7kT֮@BFI$#5| И"-5:9"erH=KrKIV |iJ~}D—מW* ]'Ab[c1ރqqnyyQk7GnhdnjC7RKALU}iyA=\0 &p^3ӿH0ue%יuy)i5גn=+Ϝ":Y?thO,mnձ-M(Wͣgx2FD%~IrwHhi酢5Z 5 )EE17YʀQKe6a鷍e]!n5 )Hv=*!T?nXZY"Rc'Vk+|+sƔ4NycSpVEtRUr%]qY j*@K6:{ѡ LE=U*ߵKFTr=:qٔw+?<7.Sg \7.تtl;9BDv'rIPĭ8jC]frv?A /0{h#G2^2Kk8SL٘9[yE{?DvF4ҍ{aWGRkE@YD͍F ?1awH/autcՄh GR| >\(#M .['}qQ3>cW?|' YMEperrKt^0<Ε\نSBeχx(:Vw3pFa\S눁q:+ X_K WQ-쳌q)Ea Ë>jrJ Mx"Qj bGKad~0Kv J/ܱg $??rܠ$IWF;êOTM/jE&zxTi*k%EZ5 ‹Œ YD\#RM1ųx\Mn~&<@q^@"xWTrEXZuL" P\_:n F(K\2f'R(y~L}d1b8b^a)$L0Ei',dƊe]FmR_5u}J0%$9 (r'I:`V!aLGӭ0 xEqWUO %2AިgxtyXb))O7bI*#m:9;sZ2(&SZ DQ!,R~N?gC_+~:ǥ) IXUR;H!FVwSr6MI@o&U&Ɋc ]e%{(O%lfs3Eߪt|]S RC#L|+;-c?2T_YaҌg9ؗpBxJ g ɰ %9cY˾f䏢")#{jѵA<?MnMm:ڄ3_;R,ѹ.N#A3D?D߃" y)@PSP]0FHK$YQAaTkI(BvBv满d"^I1<SB;=6mܬѳ-ڇ2Wt $P\wΥ^= K% #wZR O\/9aBne&OWk6"S,e%YJ^,ŪH2~I۪@"yIW/odAhS ߯b5?ݧI${-+Xp,yc$Z7,IXFۯ+ `yF}0XtܵH_8nyB. 4BiBb$8A*\  kk׺r8yYrŏGOK(a'7R'R09cK%(BȹDjsI1k5E Lһ&GunL1oWtMҦdks`R IށWbw( ~|֮3߉ĝ2e_B9%jk8bHi#]r7bmehR^I ~}ީCTLSӶ"mi.$ (6 .a_65 V!d&as8b|#!Q }e5?%(?)V6%|B7Ojɜb[}Zp-2ؗ3 8xhxTR1rFI=p,tyfr׺r?5:mY9`4}ܼzyl4t/&PG.M-=2AEw KBaUG &񠾺x_^y岠H߇XKָo *RȽ[qMtI+:hː;4XLÁf*B_{=$Յ >:-řFvA{|Zӄլ&Ȍ,b4)Ƙ\kwjQs6"PY89Վ xx6#4pwۨhnb؂G,?~< |>YkCx Qrp.lV D$Y.=`U\l&RgJm|7L<BAή &6M4;%k%nYh(>ըb• 1J2)0=wwmgx U0'޷᠘apNBZa$ `3) Qw&ecŝj I]JXFLNldI1%SD@;yrgYo3G" a~7!s`jfل[';·1_\(Hj$TjYDk aBlQG~귑@ P?̤5ʌb|$%2L;\ܤZLλU|O6 i7xh]뇷*ZE:3=րk d =]7fucw!t?u$Wq"ɯN8kBSϟ-ix嚝JsVS!Ƙ|iفEN=>V%EI)t2(rJ֋@适*_]1S 3@n!Vת3 􂯷QWc?噪x Dۇ0 pbf6˽4G7,kO+.ܜtK') TÕu@NeL|-٫o-O)COq:yu6*[>\aYwxۇelN̅;7d-` ]()o+B6o]sr~%gI@ukMO;K-A:c z5HhO\-f$Pnn_wlۢ2Дs $`0_nW&U?!@(u Ps~W dJWBڐ&!jډ;9W\`Ё0~H֏ZZh8Jxz^ɣR2j^ꇾ_6Pv$P#nKe7j>lm" nj\1Ɇ!Ƽ'1ӝ3p^*i#@)]/Mשƅ;8ŕp tU͝6Pd'vu0PmaS8U}.66e~R=Z-"X`h6bN諅Ķ2Γ6W;JѩMjcw;luTAat꒐`"$>ܧF7IЕp~z:dZZ4k RvoT{LMaiU+ 2ol W:ړGKb%%2x*rZ u΁'rK/3|MFj>jHdNQMT6n~Y`~ᚃ"3^wx 3w_i_ ㏈(OR"Lx*euqX /Q茸:dU+e$uk`w@ӋA(ޖ,>w!UtL?ri6fp$Mz"kP+;O'O&/h_^0}9E"sS7q!, ){AqLE(")&v{#+EE>4a Hg?>&u&\>xwU*9Xd Հ05qu1 1dM n)~az1ǫ*5v)`vO{H/ *B =JϷ5T gGץ*Зi2@b!q]+$W7+ ө,CF8I_bOonN4M9Mv)kq{ O8Gk4K=XpYVRvnӦ Gz.C#ekobzMإ&y8sx2qk[t)eJ~#`0j }DYaZ6 %7il>"np^c6[$Q$|+˦!a$ `60Lf]j{{y$YUڥ))'1]Bi@~{9sB4Q FFth4S 3r724 +'~m}6e|# q[ɕnXe\S ^'K^^D2PZs&.'Pog["˼%8"w0n|9(6Xgw-HR>H󚴘BJ1"aɐ-S7v0i??i_2%R<4cj8lsAW&zd$uWLyN)>і>GAxI̫*rf XxR/5tgKaI=۰K٭N3oCL=b:"xE=L/nJZE 1(2Ky풓%W B.W) ЫbC^󭰷y 逑}*32UNJ4kr/*ǿ_e(mt/"'eef`E-v s8Y ]zN|9]Zkۍ-M01~<~ەj̱X`/iJ&+gJ-]m:QHiH; =Sn;BXAlcz/qݘr:F=1 & bQAH Oh '#Dp`O}Lp!Xiq|k14ϦhR9J]ݫ@7x9d1x}וgb2zBW[v#k RCil0)e38XTˤlHDzeӼ]x!8)3_ѩ=x>U;Ѹ\UaI#Kli'įhUS!'@It@Do@tIEC}wK]\y4?'LTpU^A`! n:|/]CKQZj Ҧ Ԇ̽%1JBH )猖-%`!~E\c ³p-7 0Iοlb>hIUGO)Z[ߍjC 8Pϴٜc|E/4ZhK5006suG͝^!N:pz W[1 eՑMn[8b)N;JReaa?w4`k!i3ώCH8_Th Z&Σu`t!/) Y`z#!wCp[~?Kvg9rV=C* X#,D;ܰ/ynrNx2';=mEVy$9Q-JNlpP[3ieY:ܰ"ld#8F=~Ta):xv>pE3hME+寜sxzi/?]*8 Y:#%yajU5uox ?^UL9m}6m\K>^q2E~m(`*{'Z9E7Mi#Q"DcM߂Du{iFAIc#vI_\9d ׾L?8rE-V$.Cn~Fg9(<5{= JR:0.2SGBu.ٺ ❆Y/o$M8ZcуٱD1,. 鬤J5<PnzB\Rܰ%-*t0z=P6:rmnS@n,!"6f8P#vųHSlΏQ]y5Olf^9Y=S"E_|+ruQ@@C;uC_ܖwB|Y=Ϳ/^^8,jzDسd$GJc^V 择Ҫd(O9|];w0 xƲ"܆N,,"v.Ɣm_6 grmQ9QR1?4X˷x{B Ǐh&B#i|}h6@J;U!r&6f\w`Y`aat?;=(ɇwU^5u 9&+8wv- ďhbE=ECQ{Z Kdt< &RuQ'۶ꋆD>TKg5ȗ%;[T W*\|py CqF)q@P:aC F5+{"hoxա'W \AtxZE+k~h0P/FĂD{jm)J|*b8) )ѹs޲te?eI@PG+|j#vW=UkE`d[żJSH[rXG_婰AQ66j()f !!](0"tEV;Gq~+B,]9/t1uv] 3gofOHb4N4=3P"!еw%e.(Q\jƍp/.Y\a')/efcvJaI #$sVW #z6Be>Ph%LYQDғfӪnp\4f1e ÿ8q@}**cp;r˜j\JdL{=7ͭhF! Nj%\,ӂJt\XUPF޹;#jǻ  ߋ?c}Q5)K)0=svVmNZNr pݶy `uj9&Àb,e[X}WɊpHIjc hڟh uf|JƮM ;ȕp-ЙZzn[T~'1Yt B@x"r0{At!-559$QWZ8(\=<]+3K{v)c9QpY'}M-)ZNCQP䋔IWP$?si7, '"$ l1qc˚NЪ79.$PHyx^abu쩧an)43$5,zDƿZV= lt%Il6rv mǢ&R!yJ /LS2)}/ʭg hWfˏh(:Q\ͫ3o"Mwsm귥UtV[4RFV\bk PGW8Jcfh 95^: j5UT4]:)n A_A@(T#{")Od[ Vu''"KV'[,Aw雽k7*z#L4z%kkcnf]9ZO~6}u&%wnB:ĠYq?7p%(8  _'Xl*|@M Z')yOx{$Pw9K_}P=q덢|lIQ'']Yv6 &h_( o%+n"h;Lе_k,&o\WlGVWo\xC2yR (khjr9L4ɦhӾN\@C7w6YLTp%}IW`F-XaUkb74Q6}U23WxG8VVK\XH߯{+w`SBWZro'ҽ6/.Qt2 N&&@BQx`yEƶ"a N6=LB}scC?,ԁ NVT sYFo#7Q=A7'#gЍyP8qp؍_ 5 N&bo{6f>0yKZ4vsF䪻PC* z |G l>pdv!UFx7'`kn+wFEAZ8] Tuh=YIְyZUq#*MłMUf29 n؀̝`XMK1U ϵ0tt$Wxju+cg+*Ԝ o֭'8Xc3g@\-ҨVtkv\䍞ڵ~oޑ]}3 иXg ~}A],gh'7I: X/_߉$>GҰ}>Pfݺ[Э=50es}xb M~Kz},;U PF DgDE'bQ^EɢyW8ݸCaks )/S-ϱE3cu'ulX)л6!䕩Da'ER %Ͼ*~6 ywufBէ$/iYPjV.rDZO̭\<${R8lFWzmlek+ّLX9tHu!=5͠|<"єL^HA_2iN2uRfy; /^)//W/.L,UUMa{[Ao-)ƖwVEbx^/ Ϳ$ GpEE[3T8 )#Ƙ4:Zv)ʍ:Kj7ul-năr=WYkV1Q&8pX!L X,&AsX>x4ǥUUm\ = c KhLl3Ίbf?(JGD)p.HXh61CHٚ)%h7brojٳ ~.td:g5%R]2cLJ0q;T2K/_4-O&{a P˔oO u3o40akjumo2uvTWu퓎%V'[:VTdK h7ܤ7\qJ/ FhmKE5L5[`J'=RL\nx.pdqKC`܄S ,i*ݼ !F#q?w$y)Yzȶ8(ŏY[V>+/v1#€2IM:x͠!Eۦ@e>_o+'jJWtIU 1q[Գ3Y0PaϖrRV-(py-k>30O3yA;r5tсwMJ3[ uAw:-_ 6l,cklꡜ1L 9(vWS]ŭZpsj *]H\2bmcP-MI7B>f$iZ~fCT&hx7sR@(o)}Y&LpIaWjW%grDLضQ w Bj<;ئMt C< %[S3&7}\/\1yN"ˎKhs7d7ⓏBHTFI:k2\k%ʏz8esNtA$d5wx jlg?Ym34hk:g)xa& P9~Q俖sa ׿ 8h18dѴC|QwJȵdjE[y6AV8R)^E_B JstttZ}*D="7F8ZI9@t"={Oڋ5w ,wYb!ёhLW!nz*G8B1Nyjܮ;)ˀ1XM$V#YJ50gE$xG%lSM'{F߯.=H6c݂D~q8i]cBz] 'nJwJM[+n,Lr/I.匽p|^9|BKq݈aKn+MBx)B!LǠs|X$bLJm-k>Hx]F0`.譜H=*wنu͎HoA`@#%me9B^>O`kJj" ϿB=4`W0d*wn`#nj=)ۇr%a4Vhy  W;ҙy;킐[Aȟy-%G-[IP\-5dtAxT~A ^GOj;-˶4&uQ=xЗɮ2øK tcio?pd~.^r-ջA,'w^ =/)e[S7~=0PZs6HѪj ϸIyުE^:)Wt>ц;rfi雑l=*SOuRepaMPc)Cި ճvx9QsΥo﹔qK+0`isQ(YiFQi59y/r‘@zf_b ,s;3vP3'fLc_Ԟ`]3(um 69 "gQrviLߟEB|gPJH4|qܰ.CzW`.32S۩n+Ek~5jA/_kyqiveNB䟛FD|R_~ Tf(zG=isy\rLG25'bHiNp2q cs-ڗ0'*us7(Ss[Ei> 5繾|_ҕk!Z]TNlJO}Qz Y`1Y2c"wr ^QzY8(bKuؽ7^%RY+@]oځ!xq@pl&{hb= @lܺ8U*aJ.?@gV8rEODH\$KzÝ1t}(je5.hSea`ɠ(w|ZQh*DY 1^>DhC::C~S-~)+=JN;o|S [<Y WPx/mLbT_” ލ\M#800Bk 8̀׫ Ww%rЕoXq V=~$!Bx[kzs#tCnԑdIדj)J\_os.<˭) ?0(G\606 ȥy?- d0n?×RαF%p[?4j7̭Up0;s7#cy)8ZSj-L[(Ԃ Xs_"ǀ_;`]h֡+b-\7]m}qb8ښF{R31eȆ\寿pV{Rå+=H[ZدmZI%~-ubqcANXuVƠHP`ú~<ɿ %¢N+qx!l<͂JwѢ v㏒,!evXo ,oX5}Q?:`HȊ67g98Osƹ"L=FwA7Kc{! )uUaR6S!X:< >l0 Eu/ɃmqXrNTzc$2KaggĦy' v/3e(Td;jN;]A܊t~R7d| %s%4NU+;H TO3xG.@LsgŸW üC'!6K1;g.Oh\-X=n;&4^?;AWRLֱͥCHtypP& 6뺨eFHZgab㬈ag;=KUQ8jܨNwɇ]2U.fNڜRq3Rbl!&h{ʩ߽ddY'hI5nnQh`ʂcW5p&1GK%}DI$,q ACՃn%AKk Fd%MI ֜lmKhl*/ R= DF+4FқPkD*@`zas=%*9 OLo ^f np% ] H dy9A$].%狒? ^ـGƱ.5m%Vhk5Z]Z/7"d?ՐO XTEf<:m7%3{\0}Ѫ A NEO6+ 5"m(w=;\)h^q_Dɍ6.ȝ%SM,˧j"PLIp>=VVu#>mͱd*ԍdoen2 갌co5b w U%Oܥ?KlJV p+қ3P_9hmE` 9ڡum\ލmE^̧6|ϫP"=G`IiNz"^-IϠ4"x‘3ոjMqDBn#c4,l 42!5pe#!/,#lAvNG`sdڣ0Lc e%<@޾ꠜl;r%5X9ѷ`LpQ/ ޙ/}BG: 4Xhb65`M<S\>(t@imߔÄf<2׷'cDYGcşEv1ƿlDt.ݑ *t\@wg)67 +iKCLv wxˬ|_tkX10iOaJ)Q736`N UcxPDvDn)TKt4P# LJst4KTGIؤ_78ʒj^v/{DlrLT8H 9&9T[Pjf3p+[ѦU@$[>A'R[T-UйY/kn346<;`+MȢ݄D_*ȺO=(d0甉Zk]>J콇2~TDeIϐ@|ufaxLdr)chh[NESlU n7|2Hb ,:/V>N*_RvagWPcì_c+esf@c^@b#osӄoC/-#ZQ7vqv#SΙųsPt{ hq`|}֚# Kڟ PGۿ)GMiRrB9 S2׃͢Nej@ZizC4}Oh,_507>7 A=CHj׿;*Ntbmʡ?>?;ݣFER* 3 c] "Sp]DBl=d,h 9v&k 8De6`v:"UOGWsei_t5֮E6zk'f>J޷Z;)̕WsL9yE%*hiK")ROEoMלv:E0ƄnrGy:>& Zŝ9<yD˂Gg}c]PNrE^]ZvfcOm]lAhܠ \2-Mr ,2E'T4(R,dQFhzpUwG*0:NČxpLOY'Kmq.0{dN>\?+/~_Q,kCUU5dgDg E1N ^oVFNY6 iI9`jLPk"%Y[w,hǝn ֆٮ Y/JnξuLjԉ"{x{%YDdU F ¥68N.nf}y3BLƗ%x8H.3NPߋLrƩl;_oEZ珴W<L T?\Nc7)Y X hej. Uem4h3i$,3uŐ x83=;6yȆcYIc.{=FGЀ r]`c $9 `Vn ܷ1Ӥ%ll '_|-Lk#/۴e|U\u^N+rY6Ŀlg hxޫ}V#2ƨ;Ka~ai .HQķ1ld6";S3|tJMA!"H!g dljc.{c^s!G>wS.hNC5D8VZB*KP%zqNȧ9W(\%IWIy_RSn!F8 V& jc[tO( -pRQ/{APr E&[,z)A~ 'b|ajM DPZ';i "l߈B1y?2&d bIDۜEpN倗6~SDw$Z@*nwyOP5~l+o3jR[o?]bhSFY诨CӸ~5ETIudzu[oɽ#TEC@ԀJHh E_Nj`j-)@KYpd=w9b9AcmdU7P@Ϡ%r%].1BP~H9-ҭ3|qb"nX|_:Efv jg5y䍜BFяUCc"`0M^͛^n`1jQ#T7f_wi:`6a/_i{,Ef<;c4o+sTzd/,;R4M[0ICQy@N+hz^ei!]E.C.v0{Qjf ~Xfq'PF)=QQPLI u.LKunArb0975;aG_tfm:!!s: F˱䋲3"v߰p|%a~ $Qfkvxn׳Dv# l<hHZ,\qzo U>^|P\%oҀz̏+,@kD^1-7fjӹZt +,n(7L53KYM|Y5 9Q >Aq`&UB #q$yXUE7ˏZ#Ia~RB &hB5<4b}g{ri$0WA:YڛysJzV MR,!@7W)0FF%iyEՉAȫ>W̙J ź{]v2 T rm|JaٖM!n:x08)R_2S__ߜ3K U%tE{2϶b_Lg iB^9 PCt%]'Yl 0׻DnY ZPWm+PQz"H}'`/h '!%~m7zҲ4ekaݒ}sӘ܃(~JidЀy ɟy]P?2&nUA`l~?LӒܵ 0xӳ*.:asH 6v?ngv[>wO-'ė"!.i&ţ$smqϱ4eaDN:.=s-2|HwWB ZND+| qIZY:6 SRZ1Lҋ+ت?NgŤuz ۦ^pUe U¾VR[9>>;PA}Kmג.j[LNOk~H&|p?hXiVuhe(&Oӈ7ǷWIdLCHR)d\]}Z([wsRG싼\oC3iNK/DJn{v-霄v6ws^^iA_ 4h4}}0#Ş3JIIr[&jh"drJ+ݛŇi|K>>k}Pv݌@0ޑ;\*Wp0ψMW ףK&WVDOOsn!JDZf"Q SLZ6QX~k$Ǻn94T2|<гi.'j{psm!%XW[x 4[{傀͜ݒ(c5l԰lPH柒'hm¤8Mo=A' _T[2*M4+J6@pNƁ%ٳ\ tiiLŞAJbQ#udý۰MJs&' ?źNVl FC7~`\  :YRv=0 {J8=u SKfއ3U#[J8i9n3Pyk Ν6҇I4'N[owB>K[  =[rdڼ#!)q: $ă% f( IZ%Gd^$(,zكLA7$vrv;47>g׹LrV}v>wT E"-֊؈G5aѷt_Z re:Խ1XH V0j$Ӳ:#G}*JxЀ`6R8?or% 0gNE ܵo"GzkI!%= _u),o[U:ISfw(RǪ=Ce=A tHY g!2 -I|/fTC̄\ vkdѯ9_&s vƷw}cCi\ k";˘t|*Lcݢ Mҡ߅8^,n(3_zAI]}b < >}"0pV6zuG“J7㘴ZbBK:0Gۨ0mDEl҇[p #A=`墊<vU0OV{ KdMUŖOau8ރ;JQ?7SC2Lۀpqoؼ"e-+4-麍$8q`~>\8s؟Q ]?+{EOtEx>1ړՒ~9|# g?,HV%0&I|V '_NW+j|d2Mꏖ>I4]ء$}*6D[x`j#lnppQsaiКxuKqtPG>6ݴxM*c2G)sWL )(-aA/!~cʭ!x7d.eެ w^&!B܆@p6@'`4y3?^o3^;k]O 5}N-gQD;H~}poC2"L%S9: `.#(.y3q)j%%^JfjBw{цx+d(,Ip4 DsDG e9 R34yUaܶ#..,y㡂Ǜ8ьf YW\H>#϶Fb|촍lX N}5O/쪮_Ѳ[|`nǠUed {0G7_]ʠ3."gLu6,*ީ9hAFq[xh)v&::[LEӜPg<Ӎ/HIئp'/\kB4*eP!l y6d3mŘ:|w}C<?׃\ǡLrDn|ƺhZisRSM=h*t`׸G{ ͤz8iZcUȋq*cH8'8ڦ9gL3? q@iUN?a?]BWft`->A`5$*|\:`Og6oi%z_-k{ƅ%7nC.zvr! Q2c1v:G*Q`#ǕN=1:ehQo0thmזnΔK$DgaOv2&-yҤN#W\|TX|wYazDm0ߘKaƵrnUvKf%"<һ2o3IyׄJDtaF= ]pt;l[JΧD&4td.g_n ijgVbo3kb4._$ww+-S>g% lN^Bj%(W8gki0G9Y}olyr=^B19i3"? (5Χ C;\Nykh$_Y\# a`e,9MWrjIǍ_#Ⱦ BH rʷl7]yh&e8OȺoH) ,lq$L2X펅9"[)%hn,?/&e+͇?%7+_ezHN<;zs?( faD:{>i?odNg27~o;)~F861jC *#G9$puǤoq<ʅ% 1a :dַ KzGZ*ׁSm?CF_N7X޵"q@yg|p!paɏSӁ5/P՝(_dx{ΈywL)*DZ`cZEE;&w,O2XyxZPYwl[&OIddW;W58M1&Un6cn/C!;Tjaś WGj7`ZMf'alAU~`C:Fv$tAƩB[ó '_a &|zq=N4%ıZ3joiSqלMi})EGɨR0/lp'g~ 솔T j)CΣ{'[=ԓr?f6vh>eυLPEA`ܗQO(+UU~D0/Q(/{䘝[L09}jzո.qjZߦz5mQwDj[c}PQkq[$ ɾȝ^"vJM"dO4jzb M"U)Ge>u¼j/ @Bf:fEFcZ,q(D_6ځyPvnCYj7QLgFMOɲMFs'FAD=g%xPv^F)H@T+ |:W,ܺ:̅ك(1g+^=>fIgq1Ѿ9vQ@-KnEd Bܴ\]zYYZ¡o,P> 4e&j7׼Oi oM<-/ѷ \o'&2%[vW4'إ^״GJ&K".0-ӰݭxX<0]xxëߓeK%8}d:]6˩-I#w} IClIuy0`, ̍Ҟ{6ݍ֐H3ײiy㨜}__z#8Z+^˲NQj!tKZoۑzĤ|!mMf+>&;:=, R5` BdCll07G1C" v{q 6D.t@̀Qt*b0'ZfK=Xc,")=*0O;_ U&)l7$Qs51i'Ƕ!$"`<,|t_0q2$>ba'8Mb1 6cH/ab3w%rQjI\ɵτgUE.#Sd`yE E T\ SoFR^ 1#%xQ~. ^妠[Vhm)M, 2FFzIe[nFVxwWQZ`]3bmПA'@m]_s`*bh5 Ct: wNŽ6N/U BR+ Hy  ir Ͽ _WKuW|WB*BP+Dёw0R{:k>*Fh[xvY-?L+>gb߮rFQ`.z>9w@]IЂ/ejthȌ/\1񫱥VC2hԯ|?)."c{;x '1pT2t} R~G5,b!Hғuy ;Q8o>ty\,O!ռar&_PAzށ0R@#ZqªܨBM4k0:_)Zl!LHQjJoV(H\ ũɠ2WX5nDK^鏢P˝VWTFM$ħBFu^ׅE P<f7 5% rO8UP!C&:.)^ˌNj.&A3UĒ bQN"1Zc峤;7'aZϊ b)ѝ$X& s%-Mk⳹YX98 dyOܬJO!38E$ [` ܋^?ӆ@EE5/6l2gqHzz1ու6ɑN,@8~xj54E5t7\qy;ErUMs!QIK|pP!!? F4P5#lT ҃&WG0!_*zqńhE[J3{.n1O ń(aҊ9e11s*.BIvߝ\\fdt",Q^ %gm*p8r3hmYWdgI*fC=U|k1i}e503  aV qV#3iTÔٷ_ImhpƠsr{munO) :XUK^ o}4L%L6AHQy2'eOQL~Mݪa(nh9^ RFČfpssi; *t>It.(sx ܸDqbs.&4!> p(%̨IDh3Gr8kTl>+qYk ye;GfEh~*x9;S<68ԑL,:& JGdž|eD0vTeo.e xyrJI0 Q-)d^6Ec+핌3iMbr%4!&8mC|oeǴ39Uk.҃ʼdZRQ%=1QBW<"hvf wAњOYQx탊NZ]&`;]gTib~F> 7ZUw 0Ìw!{`&ι,]= &NF/MJk6[ YXӕZB88Ѻ]ѻ3/9nD=_ΔT"RL菸]N"~ @:z}i TSku+IgsD.vp&R $E;,_: ف ȷ*A4#@x\~o< $_@stѼP͐+s4VSyfMwo$ n2)ӞW"o"F+őn&,lC[R Xtǽ5-#$uLyYg?biu{w8 J0L]HM[[-+r$8ͬzxAw M'&&׏\%^e|l _kX |0Ǐl %iHzN‘c!gGO^sSXim]YA| U1˜dy'Wem/FdL޳WS ɼ#C`ĚK\.?PF`3ҽ^*K'"f]޼E:,ЏH<7nlB?a)dAЌgVdp;XNk(0)1ohCP\VP/1ʮp$34W$K8hڟ0= 3A {+D!zgh҂A[_)Lri%61lɐ=#(8bP iX' uxeҒ)d =b8wrh0s!;@@ؒHL{;;od\fp %ğ3I_E۲m~&$/lwLx'N}ak^y?#V >t0cL%9& & لЖY.6 &鿏o` oT;{ nVwT r+D1Z6F(n~OjV[ o҉ 647WBpG"XeX U֣w#S|_57G4@ 3|1@{dhKTk7Dtٱ5fYzi=r4Ħ 5/RŘcߒ-^Q;:O40ItkCE$L H3p`-wT=!`v V覙hO=^a\1ڗ4:`m_i|*-ʯd67paM5M=n{ !*~coJC bl(XN>57}'F/'XJ_+oX^b<1E)A]mvYZFZȩgvB>F};sPDE {a7.U@nd eFD%wRpq0W^5;p/ak7:x*/q$>s-q$3ӳpΝnE_O|t5`#;XmN\wNc!m#纴7Lί@ /1Z|2LIR+m̕nwYiSp\m}}!W~l,nG2͂2K[ɐ24=4Fj#=]e#X"Qo{^u ^"UahnnD\ݭM;[:F e>~8T3P*P"qby4dr46ݾ)i} )>n;#knCuN1,=G>䉎߯.Y9clƮpՑheHR#ChݷHS\Ĭ ,DuScME aOPc*p@Bƙ)N ,U\Ƹdɵm!P;TJzMUr].ok Y s XDAv(/5V%^U(K˄Qy,oqjϰjeb@v'K"@0ڐG~LK|#5m|{oUWMnȲz,wY~ֵkr'ؙgDciWSq'Y4ʉmË#̵%ezGȜm=(o/$ n[TM8m%xYE̟'wumD֙[0hجGv 6c9U|~+=Ǧi6˅ `}A%1Gߛ:⛌*W0~̊5~M9Ϸ('.=olsmxAr5ljtm2Ѽ;( u 4B*t}]XC\ z|yn Q{(YʶV*#@7xaPx zԑ!f&*&}cf/t\0)l7JBSXZA}2Azwp%ڥ\ebOzvBa6E r[V^0uH%c !{ȫ"\Pg͠'5+"G"R8 rfrN|F܎Dz -:Hdk+bw~@-Nu>^Yᄁ0#%%V%U&&[8|5SȨ8Ki{{Fq~z^.~q(]c FqPpp`N⤻(+ !|?AvW&oNKib%`h04!y\FL9YNX2-/K P U½—x؛L ZHg:<Ӓ?7q$fX.OUtJZJhڂ&jN ha*_)اdr۴9jA|T$}42Rj>]zliv{<_"NxX ZvSM.QGޖuP6qTdaY޴d%P"F}c5M\B AE8^'3*zi6u&2t1OIQDi %ƁDzv^[Ώyt!$)qtn'+)qvN(+$T'8rE/$ p_7ϩϻǹ&S_Ҍ5xݼSP1Xc[O1F,6Z"|uxk(}+%ڤ4c_Gez6_|_9j[7m,q[,ך6o9Is[I-a;_Fa8LDJ];ù_lTc4i:<աyVC48QE%^FTxj7Ѿ,E3 Mu"t-$I}60[׫ Z= ^IJHQԩqR p>ˁe@:(7'!q"_+ M]vO+be0v gM<15οOUS$] ʃfOht[2݋.x|$E@H *Q9}Whr0ն6hp;~Uw{˧-%6 7z_L}~ATƧ ȅcPĨs4&ŏvNrWK]RLgHGu>&%W_ n{,oQ0 󗠪r݃Sbm2}#˝"'hx/)Fʯtj7ȸiq bBd  "0uOKJo@Yƕ`v%,kZvxW4 #&G<R Y5PP9/٘ c, MUqaC XZW1xfpޑؚo; *IwvTu )I%_;ZFרw$V6eVl.ΓM=)BV5UOۚ5XJ1*,3=Da}>F!څ7[`c!Ia,g'Qƺ|}c%m` bUHdmT{:eRDr406G?CB2)2_C]K$˙~c'&4%@'6i^ Wpj66ؔQp YZa@xmNu}yv;dkԬ*S>U1ۊ s,:r2L0q3Ea9WZK4ǹ7µA"*2 D J XAR i&j-.ɒAb7j1'~(FeGWϼq2zBw#$'~7G 5LW3w3;㹰jM/0.:A+#gYB{ڛ21{%LTb7U{+ʦ!j7I V?vv ͹S:oW9-m_Aϣ w86rlև!p7 B[.V[ 1_ϮZxxyήx?|M ¹X-H3H/M `#t× (Qo2{,+K'wS~6X* +tBt VOtԋ3-m|sP 2Gygok&LdN~~-[p=!Zp*hcFk#W&v{hCxƋ "Hk<] ^ BHwЃ߲*>} Or5u׼M^dU 4X f=qHBh{sz7Cr4WP;rwn4IZE8Mj< O>lBն G 7Cj1Me_OnW}? 5ŹIPXX)TK 6`R4-2y)`ʰD8p}L~7V3L:JYjXAyY H4kгu4]cP-} va6h`eL(y-@ڻGVƗ|:TcRm%"oMR2Er ]ltߔ TzyJGV\ıM*L,Xhv+큃CYk_seB{t(ڑ4l8Soi&Ku}eVi* MazQ#_/!IjVke*c[=$U_zRblM˒*, F^“}Ak`s1@FZ8)3֑8&fr\oh~,ɎiQC#Reј04]F:9,Y$Μ8a_:!Yj\$ҎjMHxRAeudw#IO)!R'%a WA"v[]hbj䐾- )k=F@c^4DqxlfW>_ U9V@ 9tc=bX+yP )Z=ĩw3Czͅ/\)~!Z_;9pY#&Jvp]e-o^10B'g•_II3[i-%["\䋿Yđ ?Zu zElCg8IMhr66"'Jr̳$l[hrLbG7A¾tf!xц]ErtlxUV/wsb"Y9DMz|79WSoܥKֆ~Z x=pTVJOuJAݍprmN>&9mEMd M[[̹4} ;^R4R%J[:7ͦ f^/0=D pj3SA3B"WPN~1bωd}A'虎ޜQ MV`H} N*^"quz[D@L?S4Ƥ2/U^"nD?K^qx_ % ΂;-<;W?g{ݩ tڛb #,YWƜE}Y!gtthꥡ3㏨қ?J(< .D&U [2-T4=ҍrO!cL[OuWE p;[R!/[b;鱅ύ"S%Cy'ȸcg3F,iCxo" B*\'}0 S)Q~(⺞=l[4Z}rkz Ȥק^94(vh*J ͙*]$Y-_=A]E. =3r>Ȣcy+!Zv90j7JFw2tS[_2lCU14WڽwE[ozy:q]8th$+ vy <~/7c.K2ٕDeHuo:H^ \qV' z:WHYQ\!8[@tReLy@EAڨjj20pq7֩)n2.ƠI=M,-Z13 V7+9P^ @SM\_'S'~3<#M CeE x@9PiF 5n*ZqܰS&?0|!#[uM|fAq S2A͒1X/[ϛ .W+ EzɄX,YdYؓ|]e}l/6EjG'Ai'4+s7pe}$gRaOKC4cܛGH=Ys6JlS=&ݿ t){J}Bl>"{s!aȗ =F-O c4h U#re !77x(z,HlVU\Qx0y!NQIJ.=WBEn])BB97ȑ(CaaNh\<*%+ȡ=t ΦoIҰѠ<{>zWU!@,|=qqs}pfD)TQEq6KV ō/`g\ Sp3=@T :~(Kn 7+\ wo"cw![^ޣZM+(-`(!eU.-+,۩BDS2Js:]}c!Lr/B؟l%gzP>H«v|1 ѹLXI,m8Wt&^!Te?R<]')؁2888NAXOGn0T$m#. 7lE|;l\r9aZ-LWpw5G>d2͎aߪ)*#M 3CTIk hۯ|{-ͻ.:chˤRUp@7 (gj+V],Mb _U tt\n zT]}VB&gAN T}( sXV#_o5_=Rncg^pʭ]| ZD-'fp|J߽;n.u6ɀv;UvE=gK4%$k®)u顰 !܁3CK| Uy A~^ 3xi(1GQVxyA4 |RG?s%A[s'rQ,ؘzn47)MP9T$1'%2:b|ؒv-3vꎑ*%ؓXD2F` c.}3CZY,UV.$k,A藺bE(͔b2'Hg|Asmw:,hawBV0+Q"[UH~u5jBF}(E1_l~9:DlAuZvD1mޏr?KDCƖwajNjh ދpTXPL37 1d?7;BY#$͛wd8_ ʋM wLw4"FmƜ# U|S%dɩya)3:@c$(=y%H(=ݏ(˅^p,gQp% ˥3:q¿i TupttQJ~IODghs1&u-Qǐ+(Y}}=`Mh+<%e4ÃHGb|7W>*́oc6.ɂ !>8 [1kLL*xtRN ImE BL?1ij'Y,_Z])xMYB |yױN~=%FKDI L7Yiq j]t2msTzlOF4CCK х&Ւj'Ki &&K `-nM#~ ZխMt&5"\u=4XnĴ̕./A'thmY1 8DhaNyGzVؿE^1cE+#._4X%h {rbNR%_"%`''_ }UJ?rj '%:,wh˄?iݢ /p;5_b-Q-oja- Wh71Qs*hYy2ƽk崄#buS+-;Nݔ'YLq{27I"Va&q`Al6utYdZVVKEA1цjۜZSt:}~]ic-A@j7V(R;q0de.fD~h  ZP'ˏc =UKxI[CX8B|k-haRCe~=:~O؀3A/fh鼾X#-F,/}P%ŗ1wCİ㳌cs֝sZxe'B B%YQk}X-Q绢.Tm)ZCYpo)b:4{T\4kcsCJ""wwMT⚙2]ͅP였_9IINfxJ~UW^X4i.ie;q70sb}Z Q Gt>Hdn̚W1tч.~75>YÏ"'lH.czD 1eC(g[YgD*k&Y 0Z)S+lໄZ7zX؜; J&jz:`3A'M<R5:uz4V`Np 8ش &QfBf,:I7!5a7?&o37$+_L6h} %68LcQr;tb IJfE#mC6S,6Mfh7+?1guO?[4% ㏹9p%Ũ8Sk6sR#ƬiXVj1,T%6DyM!ŸIM6(Sj,.@\2%{$W1ENΊiH817Ē 1W4mZ/sَm\~"%(sqARw8z~{צe&6ↃZ#.0ýD݃OkUycH0n$垬Ԡ哗eFȆ/a1{vtvG#ޞy$&=yDWeWlAi/-B^'JJOQ&~ZC@>ŧ^! l0VɊ~ 7#}1.&{}xXgt[Μ>΃ Vn8gOd*3"慞QBvg;Q3yӀjTyiMGn 3ڬ'CwZt\`7?|ѭ=)bݪ( ,Zpk5q " 8gD=x̰&ak=Jњ/@_.OӃخ:35ܲN@ְW9<[st{'{ݳ0P|R Tʲ=[0~)jtDtUJ\R;WsRk԰j˝jX;Ց@һ+6h!~ju}ovhErsZgFM<&v/M|2g+,lMp_ܱl4Fչ6^fi0yRc#riX/xBcW3{5M8NN$]."@)\>pgJXMڷ*h\N.CTPpjyDEgK Vl~ΌڛheǬP6o?q42}}%ksbqCE4thi3D?$3'կlE"b = a"Vխ8`7:^u+`㓤T.ONFa&=ػ{1#Y5Y vƗ./p/+xgFh-N8)6yDfbŪ]o,'qG &xϺZ~K1ӬzwA%ap20h2dCO&c֖'e%t;a,ҭTмFE&/ z~!2&Q$E~(dkyIe[?)M wbXwM,5d!Ν ,wiBmQϻ2 11Zd3+,s,5 OWB .XWjNΚzhMaى hI,T*$le/,3vvSVMF0G dܰ0 o(}R?3-EAO{ɮ0aΒx/}Uu||gW#;= R/qc׃,Ɩޑ7Y ;5+KJ&AIӺ7D;j~ _qY=V[f!6jNN3 {E#_ tf7 %Dvenr1s$춳tY+Y碆zVXbzH'Fbjm/+B0'pd2T"V-c#[!ng]%y"0)5o S^W-l>= ?)0# ev7,$a 241eؠJX X/4*ŕML[S|jw^ E[kGHjȰc.ܿ *@k,\E'R=ʝ%/:TrAe/y3D + %㚭ɰQ F.!9 [[b;&eC{)tbgUGu,Zn|I hWߗ2MYu\Y"'Gk4iz my;P9"#ϐdm/PFE@Ii5꤉Q*+ >Q"f:_b2*R0׋; U{Eׄ2J6 [O)Ă1S Q@2؀ͩ>y^ce^H3c0H? eO(u8K16=K-Uoo(_t)|īo 袏[6OCbY!Wd9Km&t).<(Txjl+ͩpT1+δ/TP6?#͇7ʻY8FV1-D![aT}-YdCrx\9^XkN(^_xQ~bӿ?Ba׵,u+4˫`ύcnT%C2!Ѻ-#-6%![Lf]rҭYV g>Z< -ǯ(jmJ>۴0)t仩Y&YDfE`Hnq`%R4HE}#·'kbyq6r}+Xm|NB8tAz̝-vO-*{V @sc. PIa~+K\VH_>}s9 [I!ſM΄}Ѯ1}^rPYX0ZT_~J4&/+&ZRPCVW`Ґg~H2zUUfZwS LT"c,tjAw:Q{X o3yzQMYJ%a}rpbbXXы4y޺@`9nu-9P)~q??0(a~:l"f~(VOl%)P:~ႈeW٬X#dC ^* ( +Y(V*[5lR;񡍁gUM4Պf^m`I9z !Y_X XѪ}rmb&%5K52-JՎ VZ:ʶ=j}(PKJ)ptUzTtE,&n5"aq+ܹ]vT".>_Xiw!~;41hq7n]74GIC} b."@ζ@IEb>|U Z ^1B0s{S /.MӱW1>s- /]$i {=ᛱo)Il,TP|`tsG'2T LCFEȭ6ov@-|kaݡ3{]Ȏ#(ȧTfBs/!P5ϿIA,iy:X jxԎD2WպX]1rn;ZBTNNpYXy==dA-|L4@5{f>k]H*luN~;Mo)9[%!%pv K^+BF ,mRq&cZT0y@tOh8n\\$\ 84BVO*|M LJbGj >x+"ƃߴXRߙ0YdXyдD;nJϕO&0_-[@ݯASBI%jS`0'B`1N焮rb4\%^.*oH(I\ rGg¬soa٢HO-7i>pee{p(e;ŗɂ~i_?v\&ܙ¾q)X-R-]F[.Ѫ7]:%UβbDd"= ..kx;Ђ#Dz1 w)hDz|-sP08#!ZwtEN}fHKNb-(3G߅rYncfh^>*?kvy+m~+TQj/_# rt C_؏4g?ƅ\y/ ?I!>P[1)Ҭ(:U7DN p`bK | @FcN+Fg̠gUk< 1WבI/Ql*q l]#1'42ߚelFDAoXFϭ7[pG398OS&K,E9?6+~U}򧗣[E=%C!w-ܤ>r5/3m7ZJr\-&ZdM$5͔ljnQMuyɏ/%L8ϡ& rVK>%k/'5i8~dD|]*r8 ԥp65x~F"yE i& YprˣO+(M}ȊYo\ $TvH'8 Iܑ{1q$2 ގ.&.udT>ibTc|ۛ &W)~( Bp%F:rqaDtgQ0TbjT/]RsZfH8ʚHc,KwkƢ8ma#(:5~?'M&|sI|VAu0Q*ǥW=Zè0t5iT6_nK2HzWPgmV6\$ovYe2#uwwsLYk-Y0 Ou9Ho* IV,H<~#z *&# X"D=R8Bl'lJ*t˙ÙI!:S3}G,VBq]۝R383@ Z-`^ݩq{ D#i0W?q6bw=ځDkM΂ bC}@XF0~MàR iֲ+^þV%H#.r:EA~7}0 VkwFTymT[ӕ媴.īT2F`̞x!= jᇌ>3 fԧ,  0_OR?Kء;!U7VwuSK$vSxd=1@Uac*kwl]8Z>Z4A'm# J+H4GvOnB4NdJx 2j(\顯8=a- `lK8R/ 3({1m]ʹdy*<֬nL$=!tN+bSl=cQ'>~02uAz}AO< p,a'ps".h-["ceLQXVsa󁈲:ljoDͲ10ԌݴϦ7#AYv|`J;/c¥1,O6_6[`ߑT LsqSVTwx$_*9sFotBퟶݛET1i#weDh| 8@xc w7^t. )/(3~&/İչ97 .؟Y B@J!U5b^!}e9DX2`=-Rv[kx5׶VԩN P8ӣ5QP|vPM[0Ff LCfОk.o0_TStEM"{u#w1OuMJpޠޯ{* ;.lXZl9}:K6lxmXd..''EJ5 `GX~c ,l,LPNwɪ|FPU%0< J@~i~Ӄkp^&ݏ._. qK`RivϼQ.^Dǵbs 6EgOa6w6ZX 9|D)U""~@Aj .s=8UB68.l,U+"$`ݝ®p@՚,ΣI5l670'"-MX*t Slاro>hf/r?ࢵ l[W5lq7ޕ0^1w#pdCbhK ߗx<*%p =9˃20I(jJ.( m7b1̒#|P P騘>n[?٬|c xbdxM37 '+ǾPݎ{c$ 4ǥ<1忑)fL;B0L&ſ*ᚊ*!Sfԇ4xGC^\{s^ ϋ` 'LpǾm0,)p #HΈXP nwEx <LV*&X8@'Zn) cE }^pJЬZkD G,u@fɧĈօ0K//E(q\9{g2fEo1,8>4)<t$dI};K pj8qRн #cu8XzGrgN ĔI*L""P;4I=|2T)d-hVG\YFwu*Gx3oI|]0_0yա(VV*9%lۨ1:CƟ17tۂJR]oP:LT WO8|7vpϧy|r{xyOۥ!Dy8&]| ^n|>~ַfe:,)aܕh7Kġ-z4 {v8/mT|.ܯ?.9Iq/Ȳ vd+>G(7^ {&-XK$z`/x Wś`bg@e۝$z?d$<;Nw:>8V8C96|bՌ%iAjZEP>ŧ Pw8WCg2C3Xܻ %姊G<9h΀օ9!VjpܹacJk˺_:^дVT^D#y*E 2{6_s9HPfdEJ "B<(=ȶw?ڡUrYTN^٭;͗?==7 @V )I 7?!KlM'[XUumtIcoLsaM28A+3Zեoݬ֐\"붫A YAAvdX? ^K5E+Nug o3ljVFy/v pt@ƙvz@ m2_&O)yragc..GzԦE }l،zL0~z mLvKGZ1|MaW^ABW]4f2QNVR0?<lBZׇ7й!}0G#[#NIjGi4zEG7M{MunU ara useH@qʶYF=>n]+2 s'"KoGھ1K5dWhϓ},~QaL[ ڹMBTy1 6'#ymf֩]!W5KLݘ2gb-KF ݃10  ׵9X2\bB\Y,Ձ=$6E-\ݼpN^KjHNg^rb{.˭'e a -+G~T?W$gub]ĪKIsl+P6:y52yU81T5<и5(/[[-(2*n.LNY+}O9bՙp`#.DYHi9o'm Dd ռp 2H(Q沋4b:> ,$usa30^m#muí ]ܺL6kZO`:,WڬJn*Fi/.RwѳWA!T']jY[;At߁ F5IR`%XPK4K!:Ih҂m[4MW&СF uLdK8@6ZOf #-ZkOfSG8>HzpΘ!BU&,P,_%ƴacfaổ%#禚uo4 SZ5ᨖ_K CІװRwwq[|[(#+/=9!T+hD "_] RuQ>GX Q,B-iy7|%!=z0e੕e1]TIUڑjMBWo(L/x.5F0um~28ŢN E{=ԉEc{` =cv;)&el 0G.~;fI(GI`m$R6z 688NR>hhƲz3V](#З2;Й&GWBXsj} a!Z>pK=Q#FjڧU#SSeP|Q``(,:5J4 czNCL% p 9\JNuy0uUTQ &Ke 9 .tq;WŁ0T@z2եC?iJ%[#F J~I(HjG"xH oǡ/Ȳ^-sHk?YB^ΛiUat⣈NKNM4:cq:"]^3'B&{w (4!^#WR¹Epr﷙e>/D?mJz .#Z /f]D 51M a{]~a4P1XR$*M@ [# QHX0Xu%ȫOCTSPU_'v׉c/Y*PuX,Ɠ2,1I$E!G%b}7wr7øP=:-7ρߙpdςI/ 2 i3g_W@YQ5oܿ^;sD2OWHu @\PؼD~inHEm^ZyJ`aUvz;no ̽}Iˉ)LR^˗ǮkTvchA+pAQBMEM/C̾ qd;a]"}b&YSg 蟂Wf LẬ`GNqnϜ0%}ƘM j2Bv)Wi4mcM| @zS*7T<ڭ>0hjeEmAu+cp=#ŖnI 0*JLZá4/v`A#@"$29|(Wak g7Koω+>}> ><,U*" 7a| ƣ\L ;qK!6/P6ílq |s%"% ]pumyD@ӻ5'-)Ȁ& HMwXmNf]RںQ|+Tuu/*}kCjO0諄^]"#hZ\LWWCg艹4;k0tKoA< Jz2t:d1ĎyYyL-^y HA^uROX[':'ZKwq2:Aݹ(ll10bw\_гգ\'JBoqmfygcltqMl qDnX:=sX&vaG!Ez_qt;)-#JB"~gOwj5 \r$! C/8 cA!4yT]P*h)Uٟ0Ibz 7#@g nO-7ug<umxR,Rxz˷Bb[/Kn3gݨpnQ8D 2p laBy8Hmn*=G^h-I.ޥjgsZ:K˝k4TńjBy^WyN{Z^r5=lH<sKokdž&'?㿕wZ|*reX?{ ;kj(x ^s~w!aIFs=M#>(@tNIF- iTnCD%6˓Wa^Rqq%u/0OT,V$3zHٻI8xYW,Zht`{J`O" íʊ}BK x(k 3'I sĎnqTc(=q1cdfWjKL% $!0T7<^bPIO17o29P{댦lO !%{=.=Oʈ(X\4q YQQ.'>VK:YINsatT8#V_b:hvZGPJ,gKiE8dHOOȯЧ˞h}ZaΪ-/w+uƚɡ[|#J('#噃|Bx4?$}MO1 ;Ƿ?/`._x3Xg#U%Sy1S G "躩kEWoP7e*)a|t73`d(/$ J%AgUy%}z<mΊ`!+&|}+ ++ duC/R@W%ڪH9hI\ך'h0`MCNV#.i`;FbY6:r6_ &y6aj'N'ExdeN-<MsH8$^bLRџt+O: lşVtP EW`)EOteuM& ˎ_Zd7b$2KR<';u%¸ԪU@x@Hq8* {ߑֻR~u }r,nFuv&ƗO"̒qߒs RcCn˰fEpg!~L"DT#lzz4 3WPjd$8z?Sw B몙]C&cL0-s  N=<]Xچ#~nwk!ף&\daΧjfQf|̤VJ|6stƎwI=8 }"d)Ì7QC0a۲G萡WkJo㛰X/_G7CJ$q]qge!`{E 4XRLlsupa} &wE"H~y>&Z 273P2?3ܟ[72̺*=D˭:7D]:?2ɯlօzϾKy9aHT x|ͥG]uD(2uZJ5J9v= ;?#1Xu#d1J)ިIj\|gK?.Gh7+ cNjz9 iB5]a<ߎ}aoVxW5DGÆ uwf!uNHI6AVŵcJ*cbVӖ aZ>D4t*}++g-:ߩAddQlЛ;g12J31ݮ 3o[ןb8''z]Da/"HH-3'(4C@eTͷm%?l`Gƪ4 Mљ<׸psLuP=w1 >bPfzuAqIQ8;%^jq7}%d/E ǁAҚ_$EYNd+\۲TN༷*t~Dy!BZoϜL!g&[˷@!OsE,1j %5Z<_ťi C.}wC4/=gۻS  (f[1?^yG;~P~ h~,p3Ӕ\|)Z*CV!ݩ;ɩ3sA'Zl;?|/8!,;DyMoN,CPt`{to@b~qvc|goE %ͯUyHӮ?l]#;-2c.ɏ( fJٿŗ88VO'0?.9 $ 풁dZ@jь 2nY|ՙ.R74boL9Mtzh]&kסNc`4U5k[ 0G:@A=V,Z?mÿ{:fJ_Q,ԗơT-eْ7nd_biGpe#xT #؁'fMV~JW fG0xqB$Cv`2rs #d됀2#(x0%&?ƒ|JjNSĻ?.Rk[H8ku!Jl$Pnh(<"x)i O@k=n*ZZs@A,IĂ{*eLC[5iB9A T~C .I}׽ӺAD=/GYdPi ]҉6By3tmg'2X0i)s`y3l)4dgê Z2j&/4 a}FpkR0GqۛgV62ba!&pʊtƮT۟}2h ݘwE.&gja'jBIb? ``RLL&f8ݿ+V(މC;LyJ<-CFIXÒ%iK4s6^pHy-&8YPϤM1\lQIja{ưrtѳzS3gto&u9Fp?L.W$sz_ĩ*4Nq`ܚ\rșN32^@u} _q}/WTkf9uZ7eϏќ֧oW!١@h4s?v.D@Wܛ> Q!/AڒፘP-'a-ip#Ypl.fy'M|yK`zolo[EyF싆*2 zThBD #Ș̄&&F%^$I0I )k ټW5B aTNJ* ķ@#y労;IpU΁;"%Ҿ7ιkEqS3 q=nXGI'nڪ#6L5)E[?@m?` xFUv}1IR`_ߪ|Gӕ"SӳU-= v|mj~Tn?X˘ǭԑ 䪰Enލ~&e6MW-m(˫V(x6nq վ TjJK_fLZ}vXn"%;k ,-"oaP~>%9$>/K5:[ wXj]S 3P8tdؗvmi?F 4*:~Lx*lˡMX&#t!FRz;7@t(_cڔlG*>DU;˗1fSջ8\Mw GA>9`ZH)JbNuEf25uFb0TqBlL{qגV+Ә!:bu({<QmUiHF]k7@EިB]}r _Lo=z4O3x,HqZ3uiw6i5^ l٤1y7IN _HLFhz/!TlQ>&඲0NҊX]4 |/\Pp!SYȕm[2O_kc;tP 칝fa2-4Z waFSB<:I 1?*+fEИw-A~9Yۮ29f6vݳB&C5AH]{O7Ao7̰/p2Wnvk"6M>'AǦ䂗zGD?aYn B1B#}}T^o`^^\s+C$)iB͞ |-9'| ׵s  Cs苹?'UaruУ<4@itiVH坥tb'I׀rM^{ܩ]hN‰ q`8{aYϓ8C^tej% #էP%~) 9I?Nv͉ 'q~v=6M W\2c-Egis"+ g9&0t@}ƻ~Ǝk%)>{M6Iʼ7mA(9Kէ k,8> EK#:-gh16 .bn*貕gݾɲ~fmFĹU2UJGf#Hٌf- īj-> I;Vbx gdB^VA))ToyIyja<&"{c8uW:1nübSOUp" <,苓Ag)w%9mND(ig%k8{Rvp[RG R-)KL̙sg TJWEY x@f)NnZqMsq3#8J9DtGn-Bk雉䲺rNDy &mZ_Z(p_Gh~o0 |& 3^INk{Ib¥Jэ/1MQB@)dAc-zV`QmQu^cpl#bU塉4X&`WK@yt3g 1l)H` 9lc@aY*`fYahlo,G‹e_и6Xs*v̱Qf?Ջ.?݋d|h:4,9w%2 Z"U8xګLi*Ki(?scXMvTR 03IJqbeQY4j_m?31&ѓdmDj P▆pv Ie7DDyb["}M $֡#FVږu+~8j񢓬hQ3n u\1㔀o%D{"SM&$߼#~_IsČ&Y~5HHF7%J[êy9-K9x6yѿ0)pv$@bOρ<߇1VS E`-(RvU(}a`QJvjTH;^1ۨ6+`X[2`ھsW ѡ}RcQoD_=\ d)VR.W 9lOca;{{6t%| B.AĦĞ4bPw. jyݷv&eDZm]1YID@2b@bȹfC/v`K-, oO^aJn64%ѥ'TveUvuPJVܹ 4Uԍ ub)c|r5Ta`q"vOѢTx yq"XC\!_B /ސ*#qL'_w,:߻1*Z\G zwsnz7w 0U 33: ϭ͝G'8ْF*ZCGu-ߊ:VtE9 0yFT=_SIHui/L>2=Ob=ƒ' #0 hЪ>@$ PZ ظ]Sz 9 2@{֙FmqjH5usF# q ~\TjciIh"D >%y7*͍' VM[|u`ԞE3Yo2L`"qGX_B`Np,пuB,h%COG:<-d17fKKvc(yXqYΨ udbm2 c2M8>L>*5P7MH9l*_+pd >W%y|Ӿo7sjwO oW7CY̱*!⁗+\,WW:PӒ{ ?fPP>~:@9P5\U$T}UŹW1P8(8? OpӾ( v):t7i&Nfۇ,PAh9diI^OyX o-)D? |BxF:FuIۼv̕@|ݵ3$hCbPg ӗÒ|֑;Α ,PycC CV'/9+U )/a">UT!90'NuQq5^E'3lnhajZݢM~8{dY^>;4N_:|?0W>tdoAxH~^]LyKŧh=#:տJvkGQgG{Sm.^^kG \ ~ZI?a Q}u#ެS.`- S(ڷa_Y.U_[TVW=Pn)3! $D298@]tś]i%bLDOCy6H |W1h4^ Ӂonȃ$y-<|U>tSa`B+6cp:\!5 v\yvW#z X@FRKoe7kYxgrƊb  cQ]eMc{Uބ_胦K8*^V|^7ha`W?[{[wbJY6L숷2%O ܴۮKOzYx=jU5vFgt* X%C5˔E-3ew ݤFVy# jH{ms 3{rQEs6K%E/h€\qV\xhߓOW(QX&B1pR8C0?As(PL./I)fSI%38R7Iyb&e %@X[/2c!@ +q v_'7;z{Gv~6\pfuuc@.J5I>MwsҁI1c M\Mˎ8Yo2{5pIu(X<M0״$̊k-D[.KG{g>qu&Zw)=BSԼ4xxK]h'Ȳ؍4v;ygtK0g.cUqrN=׏Ff0AQC;=0nn.P(Z o:HW'm2cۡ;wcS=5.Y̴>Zo^]c)uuteZ<`m>Ff84Hq#\oҧQWıo>zI'{I wu&k<+MbwofCOi]YKxVjE3XLD][( -g2)?pM{a3ͪ{ <ҿqu܌ؑ'yX霋yTZ:?<3o߼ZwFd[xF8\f5i]=颪eQ4{=xvȧC73Ys^؎ȴPHC퐙`!EAR()*7n;8]_+{P>5L|['{n2>z.$b}(՛ 1g%2BY7/둇" 'gJN+b86:\ӯzxviaF 2\hAIO\9'i鶾sL7Wwr"M sV{=ǥ Sڋva}HNv\ 8rW-/P sjj0#DQQ_'%mu=o<7vdoY_V t4fot?>sի9bu/ ۅT_5ǖ /C΁K<96j)@//n {^$9Ц>VI8r=7c<+@Y&жZ|fKMg;H B +8=GwZc(вdȮ]ز< R!8 ±#w+_Va9rIil_W]lDA2{8R$DT#P$7MLs%:lk3t4)d.)+VѠ /Ioq `)Ao>{I\ʥ/f~4w^ 'PBP֘8zsAl=Kb;O غL[S*ls:t`uȒ ' H\a@[Z6", 8W+/zz TQh;uawtď@9ӢZlcv>!ҧdxftWѰܑ @:=3JƉđe"Θ͸ٷ`:kF}^M^*,KZf<or'a&Y/% ,s+N=S JȑQxKs0djiR폦5+K,Y/SD & .&!ʴ?zV ބC#9V Y xÛsצUH񓭬[t0vKv+HJQ1q{8`I9>cs(ZVpUó{THq?2Xi_̀]<.~>te &*FT⇿6j'} mؿ-V 2dˆ Vn0x|-qyl->+eo`C0Yc!lgL@I\}ݫFBРݰ^pwi`QǹP( M4tJ ɮe]v>f3Cm\AՅP}U"[S+Ewlӷ5vdEL8ס'h0_"0Wbg7(Cڙ1:\9MɌ;.Q!( $D͝Y~OAvHV4;8nuBMM0ne>WOL)zAF{8oZ!+kOm0 -ۧoFeˠ:ߤ=5p,wa`2-nvKT-avh9}An5{Qz/ m8#ۤXrPU렏'ʧGu'a)/z$XI 3d)fZ+ .c[i*%b8i({!QRrItFbxlf8az}mCbD9A8`>N[. V*˪bʾH@GޝqM83bFٴk)!B'g4d9&RY\+gu8~GERJDl7gwv>E?l BSHJ{.]Cb.tZ-Ƞ-#͈Coin\%M9Z:LHCrRgYG zxE!>%AQg$OCYoԤMòiD: r߀)7">&YC) ]ݐ;~:A'7xMX^#@dUg1r(f{̉K Jά{ax\nP7csKK`ctgݧ u•74>U[a{hx%'ZY. #$c.m2-w''g(?)C 0ޗaI9clڊjoP[ Վ̣_GpбP3otw g!d) C$odT%f7Jf"zB66sH!˯#^('me1^ pia% y5m:;#1x95(^;z`COH]E,Ф3%S*IąÇ <&Ag(xF.fd'tn") xD "RY}!7+Bkdqj?Kn;2A$DzMs6o(qЯ` 2afpnOUȋ)zɾѾjDo'?t~&Ե: KwhH-A}+b8i 4 g-@0ߕ}]6~;m]?uH?+b78ϒ@×`PQqY(@~oy.SYW5d:xD7FiwۡIu9XDyX͝4#UC[z9q0dF0(]LwH_ʒ;c[P`#FaT:5yUqDYhq1Km"d 1?2C}mjCpЖٻO3&:t>qša&^"a46K턈m~i4ʖW: bnNFGnӯ30rl('תWaEj1`ن.ڲn]wMwl}R5{a؂ɩ&x=z4o 8Sd$ H/|&Vu߮IqA_>E;!.J`*/I&t!&:>ގ]n&aθ{n∟uX=$[ۑfsyWʻs93; ј],b G魂[)Ae qT#´dhHζ %IX7xNL4?z\3<^1: kSY%<{O^i6)GԋX {_H3hC!9% kZj*:oFfvL==@5o8t2q9ߨde]I/H7{Ǡr}?cNk+Hyv&'PRy' IK9'I9YQM&m*w"=hFoH4@s?ؙ[-Xk6W=!R{YC%GR+vyNs(9O(ܨVu75fX8vN:uP!2*fHxN3 9͗ƥpϳ qyE$5qnoMXdDppt,*%0˙|^Q) 8:: Uŕ;wM5Yp$̑O/f.=Ry0ICR2Qxw~`6ULc*GJK`U$L Qo>Czr+ .UVOzG[XnJMU\침,4z\mn`fkMW<-pvtmz!y:Ex^ȨNV$O^1!ƽy0^SHكYIj wM(#&DAuwtoCޚm͘/"Fsyo9؃x)?΂?ǍpCmtlof7mRW<&Mٹzx1E$Ěd V!Q4q;"[͕=Q\0.tXr;|zVh7 ."gFHJBpl2"cfozC5[Z[ARAR%,{Ұ7S@Gk@ct<- *ZH"iXp[~@#Q|2f>l_ zőPr*K$v*˙үYY/ l}F'o;6w=zzTJ2ꘐC% EpxMCS~ vzJTf:sD@'3BHb÷r$ÃE+` Wv+%qpG"`*I5#NY|`];yD]vf\Hq@< r$gq _Wӄ+s 8(c$TAĵT,+vt_?1Y/7\op (ؓ.8zO\o* G| 0 !c(ZΘvR. = ))}[${3[~EL_ZrHpE@- aDnLvf^5o= ,vy#IҫIEـ=}oHVAmޖnȻֻUU'V㠉aծ΄R6N@f;A%)s;?MYH~`Z_Js5Ou̢"]r/Nq37HշǑ@O^5e2trm|"5 B]czqoܓ~lBGPOM{p6BJ3-i_9#&ZOah1p$Y8pU!x+2U= #?e$ڳ6#s_Sa9%'T&fQ/CҫnwrnXȿ6D)\5*y iBWˢC@F~&pU}Х_ aWĞK}wf@Z}eY}'~,:K*e h)VACk XE.ZEB2$`ӣaxAZ-8(ޙb AF^{) cXmv0$/tʻۚHw"mKږmx`.?u1zɦƩCr0lC~)[KNW8/9\KU%`IeI?퓳F#rߍ*ƧEܫOȣs{Uwl̟9KˣQ:h!=iؑ7BLpqjZT.xR/(buǙl"UNIJSg>r_+V9vW0rs c1vs[5dk&ʙ d/J]e_JɣF^#.mǝ^^l{8LS_O40B .=ֲg<< ^7! U t@5Våw,m~RJ'-ܒLq +V<[}Eŕ#)@rOHSLhǴZM 5SA)h$43'Hs4؋o@mh }/ 'eIC$Pl.L:$M_;wC64[MQi%TLF3<8?SlEh<`nEYDTi?bCL8HMXr (Cp@&WEkJ.P,;6?"O\PX+*_9ɼ%q?1DID`l-yhV kAGo+^tAT{ U1A$|i( *Û}A'3-VSg8o;y-T% ltRN8'࿣!]aSXE٭VE6vC[ _q≢8xhS3tpԐ#~5OƑD͛kԕ"HpY_?jR|NYuTiD&.,Գ xe102fX=yd: ^,Szɷt_!3~jוr94qh3OdoR&C,&{%n01f󹱡t'؇hV+P`*59Xq:LF>y1 Oo o!Q"X) 2wi5&[K]  r3eI(/%IF:V5F09:5ѹE٭ =<lQӇ8?0ev<g~:!W*O/5OVd 5x37m*B[&8H֤wP L/vZa|~kvƝ_LKxS.##b-5j:BJ}鍣N`.iNQZcGJV-ЀqF(CFGuzvZ8ػ|9J +pk41I/?#=`Ļa? QsN'3߭pS39o-Ri +%$5K7q-+ #h(??lQPW7TN/ri铘0ɄV:1;ʯ<$%>+]qn(^ ĩP=d1֐ɽXc:m:2AuQyv-ξEt@j}L| !t6~q:u%!SWwB2AڮU* ? BT/Ғ̢r|71U Gnn`ŻPoofGiXF1ݯQjX`? l^|G!D۱w;WvL眓Ph}B۞?y|n*BsBatЃzl!lD16"ceK iw;z]5k1W&J'psIY_^d ~N/M_qP?R(7Ű{uׄ,#„ DrX3с>\霙oT%L+jE6fj0g9XvM䔃qWÙgzvV$*Y[,;#N@ ,El`f@ OCȼ祍*TӚ#41码eiEF6.:4 [z-C6W\v(WT[b -)wѳq[_,,,38`o ^R Z^[OggX(WAAVp= [q]VŨ$`vŜ%fD9LJ/&ϦCf>} &?>8=#;0j}jf`Jbvy/2H ’h ) A7ywm4v+ o*c-MTR wV)Y0Bgw7eҥI'dpt9;t{87܄_ AʆШDFßHfk+$r|*1̱7{~,9TQZnbn3(֩ hr3'"a7|K1~"S`1a66sէ;?IhJtrr{*Ʌ]7Hq50~8>Ym:5scq2$gNAu"ۤH)qPˀ G4/Hdc~$8rk%F;2ؖޞndj|ͶY ![ptds,mwHwNSZw\ +m-K jF=pPSj(zw}(JG G;< LlPD1橁`E{9-xee D1IS:q$S2]9Eh^淋#<' K˘DcF)և"UĂ:<#ԅ:ᄅr{šg}꟯\nbBTVIdlu | [W#nF, &cX틒Fqv,rG!q55Q#WKW>߬DkW]2D&AYxvM*BW41i*$}~XR@/VX )P=JʫBλ\OLB,vɏ+E!`[ٞD/0t\et=ژ8>-qC"豋Z@7л0!"NOk:{pa/A崅6 >BSPVLJvm2/2t‹狠2(SQ[ S 4Uxa+`IѦռR]Ybx/zP+3kZ)Mw8!7Rv [ݥ\П]qu% K۳FzUB|5IL/PAIZԏ+"晓<~PZ@1xOػjg`)rJY6ag(v4| EӇpdG_{,Yh $?*AlO調{n 6 #=|@Cj.=V˯d $1*r}X8Ya?vGQcrOl\EQ^/FfzvltX>*\ X$na:divp >wgc&D|7[N z~ j2v͈.U| [4ҏf)1L \6B"mܦޗd"}Qx}S=r.UuN^ Z >tm fDw,nC2 0A6Ƿ_zYu[dvak2PQՅXR ]"kfJvaEQЛPUǬ";D%>Un14A$U ܬ#ːٝf$Qrϋ.r|)_P3+\݄sFo`%,oh?"V4}R|i'0{6O"RXe 2aЏ쭝c YH8S9[gE`dC1*δHCR8%x8ו Ay߸ pzLL{|o'I\ J6iؐ3D}[wsa 3 ̀3 hLp7/_E?8Z)i^riLO%݆#{η+ m9BVqu:H  &]Ϛ@Ą𯛥ҋSϿ8I--x| ,}0O ruٚhǥ0Ce/ 40p28%]TP(\' "֐1HZ3Ap3\z3@ 5:b3XmX ˀD\/lE n3^k ?6Wr-@}/`nbyK g-l!FO^UP_ +QĠ@nI\+/Go|K?cz Eþ-WzbS8ʋ%<}ڡZI8; ¯G~N뷱{ikY;RKCNc*B2B#VY\CEɌlW/ RJV*&$.p|'墢Mkc۩hdHi$ޚO(p vf02𹧶Ċg _-/aw71G!O%P!8&h>&(o]dbqs"Urh)q6"kL4xs?|xu0aey()sQ y>DY )h+ƒyi_9;k7IxHPY3 \dM?i9?v}W 4y1 g,j&cB=7m3 P o+C$c,v0qk[OLB氾r#q87}DQoCK@@, 3XF:T_(0C˿Tu@RYyBBDϤR~O`c!v57 n -CY k.5J4LvdQוlSH& <k/o΁)m爪}?-Xkߪ2U|]0K[@;QG„ztMVqpbd_!s!vZ/YTEpp.1:?#z# 0 L /1aPh!f 9*%e_S ~T c^s)ۿ(GYZg[V7Xf>VMFJ`?6݀ݹYɒam֑hGOscXң ܚ*˝v_RTc.bBn$7pk'yy- %#/Bup*E!L@}Ɇjn)[*y,.@n~I9ijyT\_{Fh`˳N0YK>oq=FK o Z#if=L]$LBQ (p>O t o ="xY7Jd3D= cϬF84,p)?@hn(64o r'{9՞3u{ā@6I)aI"1;đn/FM]>F50Nb~p$7ON :X,s6ȯ>fx%a@H@k \7d c!ЪsƠuge(%[[N#h07F<1b!Q)? 26 K Tpgp]+1qVKOaFOX^i񎒗Ϩo݆ĠiB@#--O"fkfN=:qo%I/qEWvvU,1GoH}W@%1&Ri`*ȝBI;|^D R:*ڛaY;j G >r*m/ȷ6*,7?RP?&GtP쪂*$}a/55 7+ѦC$l๲9&"Gyj.7@ L#CCڇz΋x  ]?Yf[d7N]D_[Db2 OA<:SmP%M١bE_8z>Vw^q2?Id9Tg(/">Je:i&\.TNJSC(wާс7SK:ntQ"2M֎qy/m"fz(!:B %FP/a2g4RqWAGUed9;{w*R>N:&A? BŲHu7o&M4@P P~YݫO&?(ϙ[J8D@b .fOk)|~:؅,>T7:.Aޣ&as~8I8]kmO8B>4EĦOaj\;UYAlnk<.j2Hud~ x=`~ saŧ *߳f\hդ}m"=Pmn+X^oU!.!BbQ Z ]H{4ږg}qs>!LU3r[ MGT׎aBu4- 9pb4龁]&w2ylb{P4"Tihm &0:2i8O?y]nS8վ`O_CVcgh6fp"eGT^a,նpLmKmpxk@u#s,;zGmKaB 1ִmr\AeЎwtvxp짉&"H( %s>v6P+>X4$$*0]ne8N]%U1{Y!u5|z U, ]rnnsY!>eR z1 ׌1!NAn`v1;+I!̔4QcUQZSz]k:Λҋ}ʐam~~R OY!B\"N *n}A+[`H]壂@=tw$l@?6_5<#RlC5LV2b-}+0tke5L~i!p"3֕<'b;ޢG=5Y%ҳZFS$ȉT@ }^ df?6=!@+I7{#Ɋ2뇟 3ރ3]ݪFg,Y:tM?KRNA[r"jRC}nG>"QcH]I,1UL8T NZ9HF!salH%5F ̕_!m>\r*>_K2M+Mۓ@e !kbͳg)f;5@ G6Rxd7^I΁GᰍAlՖC,%waډywwpb0|co,T,I!(Vo;ͭ^@7%њ\ R~V& `OʛBMeeqk3;k葓rYO݈ԽN~6"2[7c){M 9;`>Jj/t+Rh:wH XFo^w[7`4,vPe մT# 䘩yL@&dSwsU~r;1Q4#Ɂ}oZǝ|;tKQWytoZ"Vo憰? IYl&d㽛f{NhIfo{q:ށ zMq/!KES-;9i#V>1|E~*H,Hj${~)0H05^_SS[x/Ŝ< ds4902Y'1]ދea|KJ@IILL8lMķ}^,ujx ԧ@-Ëf[ 5B! O,{{~_I%)Ykx! f5K'sVj?G1e`q[cd'ݭ DPqG[w/=*YT \1$ "!p6t51}8Te.>ӻյV4@Ml亓kdt*us҆n4 ,@n1,U -op=QdvsfnOG_x{;7;Ѻf1z6.%Xm (EXru].۸ Am'-Tמ+A);LZ|lgx&u04)&WyXRkoM$+>iGFQ-_\Q:D;\A#&9:gV17"ŮA`9W@rBon#>U0}ⲷ+Ѯ;7|dDH#86GԶJ ĸZ]9wهH7^x .9`pbOZPovc1!`C4rӭN9nY)+1 "la!-v22rh.q *ʿY"E,,)c'WtIpR+1ls*䌔Y)JfܾQ̅Kw + tLO*PڭWX{_wD5pMimG]ẍ!~D:OÇ#KX8ǰ> P2(RotTGHUˑ,TTO?"_oS9ɛcvnZƵs!ךݥzg!Zl& 7 nV{dX2EMS_U8KWǂf!c_1Bha#Г"$tS/X)afOe#7$UQֱvqHp:]iIƝubV%lҹyrf"ѪNCOTZ`>^g3Fx`+Mkh5i*Y˸85z)/B,X[Kz܋h%m4,;2!G1LT@w .|ӱ/Zv`V* eof{Mk!{W EcAtAn=OyQR,$5XzBxAnb$Fi&9Z7#p_̱EDtaPVjn_Voazr9soN3KPUQ ة{te uk&1. ŋc MXMBUMm;dUCGh8`YmNnX=7b( /`PFAGq4+oEaHڰ Oz( ~Wo"ۈZMd_ ;#" NdǫnJt~1F)͐Z& ~wSaZ7uҠzhնcit2;ܽΒ,a d$'g:1,Wտ>mC"mx-CYܬ)eZYY!4tk G@?"`ɦ(|ODЗ7C$8Ika :sS_8Ms*Dq~\0hB *-/jj|n->?/g b dRw!'K:J^ ijkH\< A|R{$k-L .(w3#"7'׼?Yb `5;d7Y湍pYu<b6{򇀹}gKSQ~S:IЬ#N~C#(oTx~$yp U( p2,)e_K/$q㊴tO(UeLǽNX oдĶ 0,rc@i`ZP(]tm jxs=4<;F)?Q)UbT!2Fkmh^d ضnc<ܧgV$HYjK I Gi4XxI&ʲeEŋU{zmlN6l|A隿H_tWF(B{B1do! /KZu,:u/gsyQ/EHO  @Z[<6oI;]?'quLhL8.o:7)O'd?Xif>y$}| cqC!BfqyMSHJ Q`eD;(yJe4-ô Tq[g#Um>řW)xLc}I4޲Z+`,Cb0ǼPLרL$vPB&pU$#(׀cY EBjZDkƃ ٴ#8^$xe6VƹnXӬ^WNJ De]/ rk*C@Ct/RPhTn*PHD37M,wbkL6:L]:D4B>i!%^y0N⼩H; 4?X4!} 0h D0l_*[m- uxq{…tL# rEYS%TfRsJz9'E(96iL1w#Ak +,)DbLO"ӍV(t,|sZ=jp:ѤNEĖ'K@X:sCAr 6JWm-WD~q ޑDP0e+*΂$7S3kVKI(p_ow#mmgz Ixf},3/y!W|+EΔil$В0S9C1T] XG1Sf*. PXq%xrv\^b{<|/3{ȱ(hIOYUƦ[Js/s*9 TfK0ŏ@ۘpO>xfQo'ꗤ]omT+{T+]?")* ?#: ~߉IljM ȨotEA`O^`XuAS_`86jA>60 4"AYt&ggyúw4ݦ4]MO#y0`$9EVRV-0B q Z"}\@b5cCuvI`1V?I3Uߺ5-sAZ0e@?=+R>` &)P&[%P d6c9Z^8C})Iw=.@tۻ|t܇o9v&6w}΃9ƛSJvU1h]:D" J|) vv^k `ZkxGʋ\%S8 l: k#\=-6ϾP>1-k, ^=7"1y@`5SXݿ3[SWg#<l>:UuL8jCV% 4#Jؤqa9c:CDYlȣ8xa5WRTJXGw< -S1$ȩruB?1’#9}fvr.ܨtcvCV]/0OZ ޚ# ﱫG(bL_h7 z:R<* l9E[82e Qj1ņ|H^X'GG51s M|LfLknyU#?.I. acKz+Uwm=ţ J[BI"8CiUx!1_[B#Vxg^6@+˺5ȍ1)[2LD^$CHVTA"H69ުgV0vrl nNk<ywu1rGίEoebC;jc),XD}@, 95>ELeyڢ9Kb,?RHμ B2K]/ͤ[{=%4s;a;w_ ]Lt0M$ޭJr[qh b4gQ0n܄wE $㭨QvxhȱzyKKSNwXsRI/e)A!j󠍩Re1Ga~(a=};`53ukJ}ӍkdcJ6$qsLMxcҙ)\W(C% ^G>r:-j=WkJط5{lܛYB֕qP̾ ~11̠\\yjڗA{LV *E!MACƹ].;Vݫ򼌹=@.W؇`9$836Dn=s `a6"fIaczi{m񏂀WliMl/LkOpS,`_oO#yK=4C ĥPXyB^RizmrrS / rA/:>}HxdPY ސE?U]5cʸ[b2Ա~ٲ)`P#~"Z;Y\VXW`Xe-#b!lL).# &EM'ŰDw8Q`3˧6 I;ihUʝ Rb5( jٞ&n5ݲbCzU=, ?PӠ)hnESwjS{/2 2K7F)f_YR &*ЛVmF a.N bD8%^i'n"Hȭgj k}Ay.+lN! CUݴA YDN*"1LJ&pq-Fԃd|GGn{"ؚGڨOl\AҿȜA3tOK![q2N;:U H۞TJև;{`qwyꨔWk5u;⤊fNA z6[D^CRL8zo9x1ٗa(uem{{D4Q֝ä'$m i'ŮoуU:#ѳ")lj1i%Ce ռl&i+Rlcf$HIw}pzbm(m/&@u]9cXsWӮtᘂ{:&# s*I; :yu1 ϳ'&h!ˠdCcjcO?'p="HD%i>@&Ϯ3yJ2XcAgzO˛rÓ2*V${Sz^'AH;c/!'Αs*҄:&@t_R 3mpAߧVKuF]r[yn SoݨˑJ>3r6X@lb1bXI^n \ >J Ѥn{ s!1h-ܩ[11ᰪH矯p*OjƤmU\ nCzּ=sN`n(ϰH2#9Y 2mOg}k^W'N3L?sxUQ Iy.ג3oq"  !}_$D:P59-CYTc{hh'*Q`U'_@ScVCxl$ +S)q7J"BR*F r(]+NPA1ԲScp^8taH)"4{֬ƖHn+^}FG *lB*VuEtohY`HӺmi G×8KkbLIv87bQϜEUrf_Ɗ%-;*4]bQ3kMkJG Ut! C8K3)A.E_ln᭺A6~& !S-9N*9THT(uES Uu\n` ow\2zyi8\kiX4DQW[rZyu=",O|M_"Y{ՠaDz-8֬ͺjר-G8vi O-aӕZ+6@~} Q,(>]5`8\o^PvBlG)ìܣV%x^i]kߒbM+zS!MR SK'i'CPz8gsgɲ|ϫqĂZ29h cwW!+τ}[:e_S;/$6%WB_:V弸W:jvPlNN:Sܦf4;;#:8xDIyuQ}YND};$pCA CFja{SMH+ڃ&6 T{7Cmi 'Hߦ+jL*S@"YRKἫ)jb^su,v;/s e`C¬=+D[yzȋM692ա_ϱ t,j{ NT/!h[ P͏+QI^ifXm'RT>~|X@DG,/YbFdNwnzBJ̛,;5>9M}/05P O wEInJ=y ^rַڙAYytGl޼"p4b4p"Eta2-$'GQҌыNowbtꆝcrc~4%z{$dxd MTXmQCzDe/gGקu /sg+_Q_V&[, i?Ͻq![h=$.@ҫb:iΘp>0o꜄g9=6 \ 6q#[ QXА;&+EBs{0Ӎpj0NJƘ0s+w,js`u_a9/SAf.g$LPgnph-FӶI Ahsh @.{zYFRp{\'ONgD7\9PՃ6ލ/jRd"BI:|&黻YYE5"t]اm(,e'-\WBZ/VȁLe7${@[Q)zD$M'%(O81 uzU+STbs-Ěu_7&6F#TC#SxL'(Sx&+*hN#͌z@)fl8B\(>j=M|h;,rx_(yC,7DO.̷^ zVW}Y4w<eN"UsjU2(}XBb0co5e=9mw pfɟ 5O NlK/qwƣnU~zqf5%anʿ*o 535ȧ_LQvvdLRFt巐˥S*O#u,9X`XwzgW.콰A`uΘՒyH=C]6JjϞ݅_ToUžpWqOfEpɴȧF-ޫcxdJH;DxUC <]ʘ=LήrRt0 yMqQ@t[n$TYy$W[ty?5 0Ki` O12w7\\ z* еƅc[ ,&p~=.<Nss\Al%Sax$Itޟy0l'u9EZBdcO@dAUjlE59IP<r0X8U:6ؒ=x5$9B 9(X۔M]Re.蘨\3PE=Vk@%fwf!F?aK^F$y肭ݽ, m;5Ů=RnJ#{a,qm&5~u$梶) %Lm⾞\TB]A;]S4ﻮ |Z7MXNZSƪ>tkRbۇՊA#dJg;Ia/̘ǻ hțtA׏J)`Izԃ|j]׋+?n.j(` wi zrٖPA?ZdwuJ⍝WoH2=~@ Ҿv]wJKƳrZ6EOn %5۾Z6 $ZcCZ{ۼV(OB:OU7/ OtZ pPef kt-p6ݦh=xLF鸾m c1B+[qQ-#ɜSb޴ҮQE8v&`+w[f!3a~JIY"{J:YY?"Nٰ^%]p4C.=D~)Q{C)9:>xZ4fiNlkhӌq;/rT{p pej\\ea כi)=<]eo,Ȓ]| ;WOI4d`0o:8]_[AK{xQR4*H"&' m3 HqvӵT[ ]-PBX RχIuG$a][,W1lV>ӽ]=H56o=B( _N0혠2ҹsa;+J?=o;8O 7KZDWx`٣FSf>%'%-ȃ%yɭOZ4/J'#Ä P:[{Lp9|mV9M|`aϮSw.Ǝ|ɂM2RGjlAnB-7TU$Z2Jl%{Ar=#ܟd\Z8nq_}* ;rY{>%OX/? Ub l3X/mt? ז`T#!F0Y+eZ B$)BWDК o#OVYփoL/ Al@G*FUmXm< R2ڼ`&k+R@)i2p3 %i3psf::Egs5S:Еvr>V>~qu᢫7J2Ƀ}c`AGb`&Kz6keVj(Сj<-WHw`9CP>|BRwGZPN$Ks![ W ΆHɕsJW dYA&Y-Hx-GjU*ẕFzmo {yIE# {U1x{H"UDH@Fm&_zC`l{(#MHŌ5\xu3U$\+.m-;3}z| *F A2lGM;\`שN}xCYGBBGsmPa#قeO$].p6f&p>^p`; eK' hh4*a%b?VɯX\@Δ1uoJK=WNtxx`ԭ3 s?f&63iT(K ÚFczjmv 28xeAq@͠N3X#^d36;1%}m!l{op=+XG)2t@+Ӟ%bERmk!31heWoF߭*i.\>;HIu/ў߃n9^*xx^⇏0_3C[dL:b,Bf{monTp5MH,:LUCEjT-eM _|QI%#)YNr,O[3[j&Vp#B{V!7V`SStU5-jaII$Hs5qA5>[ϘNǣÙS+TqN*X[kU{%,.7x'\hvcpZlPۆJ9چ a6L)APa첨ҐBWM1$.2H$T(Xq@;{tmsHXcߩߟ9PP: PY$qx <QYAʳXVo|"kATD~~M1qέ_ko4ކGh}DE֗ށlM{e=㎛H?>RvjwWk?O/Nnyg򽒳MՑũ-]u1nT=!wcx#l]@u-Ƣ+̨N?|/Q=TC ]wM^_Zi Dk>}wp__BԶ=;OOM37!q$wb{'2qT՚~W%Rjnd|oʷ*lj'"!N94 ~q&}c0MXפQN×KC ,WKG5"al#j +^NxWc\n,mNei Ş;7Q[gnI[8I.~lbqZZ Ci.ao(F6A93@%!/# Shl)2 %Y*mR\!Yյu<!X&&`4SlA^|C;#%ya6¢l3Ak*ҙZBeV}):~(P uXZ(a "w}i=Js9U-yrǶJRr>3}ޑ+ aKʪ1A/.iOiҶ rzإްGJ/Nh(P56-%!>朻< d`}YĿ3nb$vNRO:Mڝ~֦pJ7pM+{qqW<Q&6\c:4ܫ̜ygMjg{yО]$M(aVwQ(i<W\˻?w؀k瀮 \-?:6^)bVpW7?uA16 ~~ ?cRa%9ْO|~zdWZyGLN78x AcT<˞Le1q߹m$Y=N5h+]qYRx cak t)!I% |ў恑="lx3e1! &V[#gO9u}N6$f%/UԆP5!BK4},-.]@'kcy^[ 1ZFJTYi= "8fJVIܖI%DL|lA֘^ &ƕ(,La1V+-^4q̜?Hk JMYS3.H><v;Ù3g^2 @fDǖp0.|eF4У]9~a P)p9rЄ) Om4v i[K"HM*d'HEZ/1m;ğ v&/Հ?/ZN|'bۓfW+p^3gf:rcT%_iU 5O($?n0M/c,k\/蹭}&Hks3{Ln9ܪYgYI-LcɔfS2GAya%ϛ] 05Y}[ȇ_.'Xр2ȇj-}?v^'UZLD4O2bz]R%4C^آFvbELhgW$Ȱ .* &wnl7)4h=}@Kfl)PTydbK}^AsMRB\p4ޱ{n--Wemo6MU0  \T}uX G-f{coJ!lS;Gy|끻ׯ-~ZW‰~2 j{%V k 0/ILOoMR*b h[%]#Iwt޸m;{u _DI1^.{)- ﲃwjujb nT.w.q"`sVZD,jY ;@( 9<$Rf:zm,hk`VahFdtFǐL엢t `K>L kQP*Dum:jd5Ϣn,÷-~7,$u\sNVX!gR70eOf:{me ^I&6W^n32ˢXWǭ%ǩK*Z_ N`jWF+ ĥc_Y@:LQ&$Ws,;hN({>vJؐ{(&), AmhzOZ(谄ep۽<+F~J)2rPF@TY=#fJYHq܂`&{K{=@cD7!:0Q Zosg`ow/}D:ngu@p:"QRM㈵ 20OF+mqfԉSA`1W9&OyYb%qaQ$"6@zt)ieEYn00lr:;`0- tO4DӑtY {tّC(y[W1p7LarBU)-O^m;lzzl}-,CJ?nOU^_Gs_O@GW'j P# >M,eAJT.oG1br4ť fXdgWnA͚90ɯ͞,}jvh=B,/6O~CD0pKY($׶ cTDn[kP)YW k/)z sdGwuVp=|2T͕J@}%FlONV:micߎg RաRPYg!:U .B(=]&E}F\ uR g?n'K3E$(0ϭ}HFhw|vm1Ozs]gug専Bx`){V~ #Rg(UEd$؋E{'wvnJҲ*OUy:^ )0mcːN,0߰/$&":*mDŽ\j^uuuR[X߃CTGTRX{ qVHuDjLiǫ3˙H1}/F.3)cyQT~Chrx5X S{8'dvɚ;>$;js|ФFGY҄b11W/b:]Xފs՜bP tTCӲ\|/)+1:g_Ov"Gj2p`vd\m$e8^.@yh7r Y "%Lh ie F|X#CzocLdN1L aš:n-lxDY,zqȮ|+IbXG^-d;6v <-U75gϨzf=v[.ӎk_a3 ^(|Jʕkg 7/PejɓC"-NjqG; bztӻ9m5c` < 2i[V[J,`2X vԮ`0WNKív^P~B+uMGYgA$%_Z4%u[=TcR9CebSB56WȐŚY?˺#AW|Eˋ{D5402FUwƴVLS'[>Tfyf-<'m̰GaAjA%S+Kƭ%޲( _䙙ۖbiѐ}V~}w"wP Qڭ (;6z2xUt'6S 0֋/<"uu5[b)Qz( ֣[%XRI77̞>j6 km(@HٚU04 <Ҽo ͚E)+}9gqnK#w|9,j|^UVz>He(M١鐗[ LKʻ7h;_*IP@"6^5Gܤ]̲Ub10ӣK2$tM`9p,R"duZBJ¶1:޿5Pn49mMWhe..V+1b!^p%-/\b2s+0pN)7v{JAY+ʲKBtɦ}呤𚺉@/#`uGC lJ2SyAm%S*:I?[VՊЗ6dZcRˆ2q;ZG=˹!ˁr#/,%˯wy tANyEH 5L""Zj=MK"SgK̓@G<2N(lN }vj_NQdêa}S>aŽ u/RVasQ_`hGg!u4x鬊)+FV n*bûp:йgj.|1/Vt2Wjaۂs-Dk}Xnыccn A>& WHdk (KsAa<%n(X6u@%N$/x: P+dJx;"(|!y­x5cؒްn6s TMO\JUbʛ!\>I+IfީblU?`'KPevy h YʆWn3]C%%71⸐_q퐭-N,FOj\J?9uLjHgc(>ź*g''ezU$4FCn!96qja+%BQ;L?;MPOxpM<%skj4N^BmG]3錨'-+)\jBgپlSzft_^>i-lH|Ŷw@0Bݦ{Ch ^}]KFp>柜ȿbP͋Tq~QXn il #w c[$vvoç1cxZ/o`̛edr9jmVҨ]̙}(xMj"TrUJȽFO $3} H4eLZatGՐ?` ,kjP5lyA(mJmel~K,+faưf+,I9ߛ5K Y5B?i\*Ҿ`.=cZ9"Ȫt'⼈I|O(Qx&Lzӱ~m' g(ڔrBJjIuXL'' WC\!9ځz3d=nc{A9añO:ȓ)O5\՗Sr+k f>]8FjF ylSZleZ0/5f.ځVQpN/2b+ x:iJwix ܔ6=a\5jB ;'۝2v6'D5c#d$,g'KBT*o#r6eƚ@9g+]Yc(^5, zcm&A-+v[p(EBZd*o/y򔈼D 6rL/I&9o cDTJl!ua(Ƃ(^U̧-a >D/>8>$qQJPVIIM8[m7|;55eߦ 3%6P\&*p,l/AF˰=^GyNgӏh/,E"; P]J(_B;19c/5H?nq/)ch~5חg;,}mw\ƍil:evw/YFߒPUبl) ZC2 WS|jb-ͳyH$"|mޮ>p&sp7nY-8+ñ3h .b܇^}r*Ͻce)#`D3./Pgkl7dҗOȂrfzyuG;֤ BZ.Pʲx7E?.8<9f"K*M{YۉIEEDbl\ZuNK*.I7Zn^ ` *P xݙl gϗ N=MДj8] V69FV|=>D-/)S؝"o>w>qN!̻1&Z a86(61e^BJ3S̆aŻD0 BL$ũ^ԁ~:ƻ8"un+LAzD| ]4tF?<{N"Aʾe$9uB^`: 99rZ,o E1XD E ,;Kό{(hSN[hn LduZe[8wi&gwrqiB)ĨocJV@a )7ŮY_ַPs၄ <<9`UH|WQ6Hek#yC1̲>M`78TdwFu >xfSYW~ !UE; ؛.>^3ƤË;|7 FtnA_۹S?;)ѽRf7FGIS @Fb E YB6o#+J=Vf뙕ѣ..c*[į=X  "Y!V:DR%;55n$AeEB/$3Y-r6 |m"`H,s%b W]S{2nka&-697k6 T_h@;[HqQ0>s^,&\cɷLn$_d~ye1-Z{T h~#xF"3H $ I)u0o [B() zRL8ĺ*]$C/驱 Tiɦs[ pCc4T? MLX1[!OZ:e2N_=2XJb@5QT~h|s1!W%,O8%pE$ 0ꝭ(+;= DlzK55'v4 %짡~m# }lE$v^лQC(ն\H#.BZ_B~RZOmoɔjx-CrQ$5'>=pї(z.v*ÌS2f hJF9OMz y1t7;۟'?<Bv#?I?g[#XTOߕYQ'&[Vx)I' C^M"Wb7ZsѼ݀`Z\ʨoE̊Xp<aS߃ cp0VW>:+cS.CH};B⏘$/0`fW'$jL&yY 8&YLFX!Wé9/:mGݻWpdUYCU`2ɦ;ꫂS$ K$6f$lKq[kxl?ZL5QL(@J)x1/d}K?X%LfAo4~9ltQ]LW x{C9SS&x sf璇^M*|2f&q2,0ZT#Z4qSboAWQ1Vak8ө޳‰,*4<[ϱ|`!" F-#Gׇ( r.30OaZ:H^iNR`AuCۜDn>zbR3Xu Wci] cJI &=j)25EJeVNK uXkG K/P=,r%<΄#Ğ#D/[Ը^EG9}6AZ=Qgixw] \LczNvnLji/1KBα-[\ZQ3<s PIWW>MWIXW+MX_9Qg9XMKӱĠa]5{7 t]|g(Mj[4J2 YڈѾi)](垶u rŦ>1 ,W])"1,ȇl5π%/)9s4XN%5]Ւ\+XhAW'ax]}rLlP6kf%*Am( ʄ6[tN#zKɴhsGq. ꐿO8~|(cȚ1@(I"uޘj4~|F"gh2UD.LM5v\*Te$qER9GfG5X-J >vea.9CCK^kėƞRm37#vaeȹ̺-H՛2!L8Ї >L# {P7 "]x!e4رf>=S<ҋRzqu`6^>sqtjKЖ@FE\+r2?C 2[cAn ]xC;q=EuЪdbef4s,8 ً^{hw$`c|c烊V)5R ;p } {4<۬eibX7wo`a'"Ѣ|+_@KUʲqeN[-\[NJz[Q~霦?\O$] zbZdU4 ;F³"Q0 ۘqN&#d+EPeĎHz_j=lq.!v-p@ժ wSg+ΔU(VR@XdJjl ד`< Z軚\fg_p1PB>|'z"&˵O_̔ }֙6]s:eCSWł"F W#]rt+l0Р0B)3%M(Sr=Z|c==eh*-5qwR[bXҥGF,wڬY|jRy]aW8&c"ACӊmG3\P&lX}y?Op|)}Gi}BwFtJ+ސ%FuaL77xsb`}hE}H=l|\2,'$77 ^5N$O}o3Bf_Upy[^Z1Lgn7n &AD.q]ziK_K>:hg~>EuuΩ&/+s3JR3^DR4-2duW /Du{-  !3p' l6x 0bՋ豵L"!.X HxUDő1DE˶1oߊ ~S{Ӥ&@Gh;ǚ$aocGBǍVnؾ/* ta"/ ^+aiP&FXp 9.wg?:;27t@}H*rm baMD֋ Hu'f>Lxs`s&ٹՑMf|Jg#J043ploCo4|5}:7ZUpީc %T뻻.V`]Ƀ~?Gcz3(W\W -~}kI0i7 Ι?,1kL.4Tl2~xinCl}k9X˶fyԫ۰z%Ok-=!4#O]H!yNJٽ'<- īCyXJ}i~s0etDa(XSHzNmDxsD|Y՗QoicQGSJmQbE_?_j+=e-Rv d5cВ|]|l^  D~ܪC{5`yYdIu-M-!Je9EPHD-;~1/kDH˲P"8%XYFLH|#q+p|M1fB~6XH CzYD.\! 6ҶJ!)ݨe!I2|x`ofdmO A1O{Uw5Dnla ;1)`΢C5-,\ 6fΦwD &]L>͆Hbȸ.3bz:m c|A7bŞM$&3Ckq 6$pt=;]T/[DZII61^e|'4{%-jWv8w!+=Cr)ė(fW~׻M/eET]/_^ͦ/TQ*/y|U/k;0@p;Hg>r-,hEêr̥-E>,#C¡iC+}5Tb[9d `0ǩx7ZCl2>w"(nHtz*c`Or/ ?|Y}*TObV}D)w>n7_kW1h:SR@N'jҷ S2O -*瘞6@fXi ^ƞw.27oz1CuU |:Ϲ4UJYG _G}xP`^Rce]i尩_Pq3#zl[;S*1F JVvzy}>К 15±zTǸjU/6]Ddp(?oaHsyw;s06ֶ\k*]\XZHï" GrsuJvѷ"}>X(gp4k`FXm<ũ"Fp=QNdb;&ۋ::dl9/ğE Y:2 Q^ƪM0?pFVZ3e} e렮5>{ʬ/.9z*Sysl0A_az_;}[, БJ}2gpҊw| sR\?GG>.Q5^Yd2\YW\Zpљs3 p. Ba[;RNSֻ\h>v9)y\=_ũ 4!gr=T}E\ʂu',b1{+fk%;&5O:dZhELJtԏFkSbu3}KK'w9t:9ՙ RZWK{aj{453CWZg43­eȼGНu=+qlBg?Y +&ЕJQ@cǤ;HG.#I3 ^mOFmqU/ IM0QO),sMD!sn8uTP_0m*oAC1w|xзKQDV~?@&2#"V`-=z 'qXVfr ybpfCJqt0y6^퓋bsm|h D[qzЫmy,jR(z09gBYU~e_埄>Q|8:O EjX}ģYe{吣2sc#ͳ?)E!àZ-#$7h8?m[ ﬧ4m}קh^Q.+;͒f괽i3|is v2/9<1JALqxٹR\L 1E8cr蛔 i+h?iWfpnRSיHYKx'rq>&Tz2ڜ$`*R.iyG~54q )\m ZvæGL+,g3ܘoQ7^ߨeϛ`EEH)Z!O;Ja߅7{,"2%HNHA)Ny_yBO3l&EkiO.R5Uï9#F0lmčl_)jM!ݑdjܡRۗixqY%?ΜH}b"y ꋡ$jn.+%"ð'f4w>"K4^!5Nݻr| @`ǫUIigO_Hr vAk1UiI\˰ma<o\ ¢VCBdxEEIpY " <ؔiCn~Xhɻ^=ĸU[y9BI^.qU?Cٻ$ɦE/FU! Cy_~["#s!tU^g,c9;8vfL 3ݐH`x(Yݘ~yx!bd_ݼbdV~1=7|wkacHoC*+C5'Z rc'^*Ȗzc2/<wl&d*Ġ:ECZ o)fUooմɛah(.*F˭_qPPdV$8fbdA"Hw/WS} r3ӈqI"fh3%LZe,!K>l_w(0}mIT0pZS[%荾rۺH@`\nx)rQ[DS}iBW%W[hjK[~VkQX7#2lb~~ CcHOD mPB U)3Y_W52sd; zF}51ZY$)=X6bweD^0"FGeٔ%9$)Sx~\9U@ڄ7pEzM7{"4%[,Ik<;x (\`nf4~0Vto0Ch,bA ^FI\">R$}zş󉩡G&`Is'|8_ ϟߞ8CӭM, =sV|0">8U6%!WCGfItH+euB'Wl%l@'EI^/NM=Su`fi{MՠlqEA-D^Y{D0b== ˞|C":z@yMߥ,lOp(+a|ĮOpJ㚒R{I6c3BȖ&wm3LS+6RzE7p/vpݢ PC4N \8|rehurʩmۄoVx)Nܢ+c@(\Ǯ6|V *M48Rk.֖wf/|;oi$T mWiNı6"Ìcŧs䓭'Eɱ-TZ+Iźp_4$71nreg3v9k.IV(I րlT]=\㮜:Da,©}-mLAO-3g_{Ur6E5=-Ņ^pؐ(i!5@3Ce$ж]?:_9RuIpQEGMz#kWu럢1) *3p{ %_;Kjv`ayb}tNZY{1ItQWU+ uDZ6 }W<ײR$ &_ݛ)gRswZo(ڪ^c3& CM nhF:D(:|8xϜy/XE 8BuU*$|֔qA^}&fWߧ ҋTLA~nիQxlLDok>ds5> c?FjnU=?7S˛9KAՂR7!û͖#ZT$E2͆Zb=g\EY=O_ݤIЂ8=x /,g^Jn8~e{ϸK4ZIl)0(q\o˖2nA(!Kf[$`x;◴r_Oʩ% D$Q獢{tAd /?ph<v)P|GKB"eZ{7 H3DPv,Ǔ J?7Fnd o6VA#vc.s3*{` 2;AWCr``pOVe,iՆqL|WbC؉Ҏ2' ]b?UA:L1o;}vͿ_/-f%Ef318: 0- yxŵdxkU ز]S|>UJ D$R~g>v31HX^J#03Qrh]mqӡC2UAyqPc|¾oHd\:+38qlʜݬ)u_g0άDoݔdдzHmR]_v1`[@􁎾eHPt̏ߞZ ?ok5 ۃ(dac \a&KZ+rP| ץIԎ{\wk5ǡU]dnh tĝ %&Z'4ړCY%kgEVN/?뿁euQXAy׮"gLty͗Oa^| ݰ(trs,g2땓8n8ۅ vdDXCnM9BsoW7ޅZi^zuu 9Uxz<4K$?e6N&-%F {2ju>4B>Aºesm#k᳷q7HķV7s2ȝu=ıK9‘̯<,P>ʼblϛLesI鲲2n}.ZV+0ޡ{|+}5͉ۑhpX?n8ZhoHDI"g-n8C}.۝ċ:H2^6 ѾB p2zeS:d$]˵S' Hܴ,U{$*#e>{3kD-vK$x=nB(80Vl{JN+u[h`5@[t 1?Lb$v.FK-8"ӆ=  -]F*AdğU>Ot_ NPE"cqSq : d.5,r[er?-6M3F.-?\5koCB)eæ+ ܂F*Ck]0Kſ U,Wݯ2ӟ IǬug(dV77hםS `0v睋v, 'LweWMcJʰkb]u˕eX*kQf杠#!}9iBaO"O\k GD<4Cxt 1-'"qiXʫ}$@Δ4<ӉrLۮ;"%x xg6 x~ |W:[Ai, YO{L +ė*\S耭!+qܔtBSF(2M,_ao)X.UWP;;Ξ/7FlN*X ȡнg_emso0ɄDW67圁J{*%vK\=WA#W@]`fQF f?c}W'v)NaG6Fj\o⩔s!FGN/֩q2=[p7}ҐE%Q#ZOO8 ?]b.*]ƌRzܜ4I.mUR&KRd@HofO11*MFkޞV6P7\\iˢULy~oƚCYvżHz_o.͉YUI(_dc،? LfB_ubL5F~Bg<9k'cGD2{IGJөտ+`\h;:Ѩ<\-keA ;i!td-/1#Ҵ %(b2 Q޵-MI~|dƎ avɱu~P(q|zU'θ,wd7GiĪ|HÃrSseY i>2tj $Vs:i464:LJ];[mEgjhbm $;&~fo\Y31\Tg;ދf"[lup`>̙G2ޜT^E W&\*(GfKLeҎ]`~NbWw A\f󝬦T޻X CԿt鱎aE oAnfx o{oeN6 Δ5( BTxy-» `POSU{7~a~T4\bɗBE&%7k4FHcZ9'R!_}殛1[sݸ<,3@0ʵ9ѩb.WRB a}a*bʠ(.g]Cu*uH/L8ο뽔us׸g%D"ÙX׆vVm܍ecʖ^GJK3Φ *{.9 X0In{%>p@dg M(0UMYl#[%z[U,x$Tvޚxۖϭ7[f]u5H'}>!|n4B_P Ku)Pu ]!ʯLk"yRNS{SbnUeݸ&'>_M'Y,q9ǘ?$={Լ9@gI,9dp 158 zXJc+Z0jWB~LX|R\RSv_ E-Ip@Wt:q($S*ͭUFsUCߣ%ګ<]%s5C[~YCT({E78D2f$Ph?_(l9%2j!vwvp~ϢDbPu#qbOPi L`vxlrmR :.IׄFޜY oxXg4xpq_jU GCբ$b;\p ii{VQfxՓ wYۻGm'h)S! B{= ;J;Yx6$^|An֭"B*rJ [ʿ'}Wef+D!ciC쥫zlCbRY ެ6`Q*U#n癤juN%j%dfMw8S!}c rd;2r9CCG4V-{J_G.h,F&O2! QVr>6PC)(vxWoqن+T<+ζX+' -]6iSɛ~lgu92щ/APoCÍ"n#j8 %lm塡xܗx82; q(_#Ru!xYF1]lǁ3a=B@gG?SjѴ1q~7j^ R c r(]|>NM3fV 'geY;tCGZ-X.Gj4gвSF-Nք&\ c N`;V{ =vsۜޡ s2`uzsA$g@xRAfB r-3lq1wdcP%3Nn9L3:|_*-F[><i!@E- @|.hY]G`Ix#f !Xe'#A,.E{ /:0e_s`=W2$Rku]x & vX`~Q@F؛PXe;nqf"vzs:s L=0I!>^?`pډMׁ$ ձעt ?PH- {I1 ߥ=(b<1oE>Y*5hmՔ4[U ^v6!kdZb`}ͪN٢_Ƴ8%9}`[Uo@oߪG˗iXm x59r`H?\TC)DIV̱4"`2V_3lJ;(e~<*3IA'v`׸ @|Fߞ/sѳYǽrG@Ԣ2r3LI=e, dWo,X*rOIfcsAܹ ..7z'`kB33HYk[z}~) b-:wq*iz_i',) H$gE2(X:HpVKhxEu{ Jڧ}P7/15w`UFZ,3oX(brKUc6` q!m"$N#0c6sU8HJjaKSڳ(GutDsL+n}1,#݈!.=[p$1+nm]vM9J>ɍDVL$ N&E,zʅęoЌT7+pW.ەB7d>߼E : Y.uKh tZ&se S븐C< $|mY ņfZ+mEF ZΫ_aEs]bzV:uq#fz)j@m''!x"˽ #s IbUfo|tBL&Lr#& >+)?s nědqpڍ(GI% ϲu7ʑ?V 04)f N]|h|v.R%K aYJF8@FҫTlКO{Tj{s="K d:w j#7l^K¶}agfB쏷{5dEG KtaGd6,+"feȷWcYXP_,/F'F~AJd˱O8Wfn p@^:0 7ŵ3\D)L}eO-\ :[~ YZ& S82ޡM5b~_RA?SLե՚I&3~YOF-8ף(5i4F:ߩ0ƨҖP/aOţ@)͵ DƌC![m/lTX7ـbJ7V#k1v)bE-/w!-]7QNr7Ƚk"`== QB4Vl pC~W9n<>9$.q tYMݲIom9  *YX"5 ¯3`$xYBBr)ކY%!9?\=Q+OgETb+U1b\l~A_UJLd219,\^"ř<`{=n49D{r_y$lpW`d0Ϳ׋ۛ=D B_9|K"Iio1=7Y~f1n1=k2BɟD&P8#U_uxYvqZ@ghd]$:xѰ[E2 ׬wMȸޭ]!G 9@Қ(=9 tn߈#nCָ\qVS~HG7Q&4uVc^z 4!X;E'LfV]XK059Y7P0)'I(ɮZ:%r!OJtnWк979ׅup}a߀LHo4yŮG;{&V7#hIoq=\ 4dJj]X>PeE7Rv8_xaطgL~K^S69\~-grȥ @K_b_^FdJ|\ 00_{znIS[t=t_pA^ s\Xr!IKZM*;c`:=AtB2ƺ:K(f=$V5iBLHb7.h"5YNGEؔ(e'k'U@&ƚYknzH߲>굷*F̮T#A 4Ffs0lIqD8y-G5mලDs')/WŇO (Pp}e#]2 6СJY}r\~$_n1_BGLO9NfƆe)lJ\JdV5vpp2{EcC0x~(o;,+Rh"K Άx4Xrn ,R)ϑޣ׳M0?reiʺb7YD ԟ 4ԞvrJ;lU _Ѫ;B0:*3u&'}v  (k/Rd:?FGX)V[U;[.{ORgRjrkA~?hU:̖"yn77ϸߺ `#euʡwݵCar&NJS|V@$?flEppa,#SbiXԇզ+kwBBB3[]x cU V:l]S_#Ej{_3}KGՔCpo]m&C-?pQ@rvK H˨o}OMyH-rDle_qQX+;MtBsY\6m0 _\7I+\hfc-o)F 1?]K_;*7lOI@&Om`Ζk3qSi̭P,l N11x& fA@8vR+ɮ!;/eEa7!poA{j߷ASyUJjpWקdmW{Ʉ2QK\,H]!V]zX״;l2u'C~0yO?_]N3Vs`}x56j7j}؄ +ߩ9rC 7l~@mM89m0Gl1q0'M_%)CR&[ۇٝ3W#k8Z9ĭ0ڣ&pK9 "pKÝ-Dr̰7X"eb=&!S)-(HKRlHSZ/N0b<-Qp8Ow@ 5TYFE).5%x"AC:gӁ`(.kchWS ܜ6;S@k+.$N"7#^FP!///y/HJk=.1;N\MC.$|ݨ?vs XqgCXC̲LG]_mX!a/#v3r&"usw}!1b˶B`c6(n{v;|3%7s.b<3XXmBGKV/p?Kk]*p"pЄHlA)V3BD~ Զ2ec7-CiṞ8O>/&7jSTX6ǰ wd<\z:9e̜]pһŎ h(x _l6uzJ@?p6."XlWw=%=J݊oqܛv9dlsy61{j&Lhzl~uD6Q_jb.4iP~Z[]x@r;㗺!+:%^w'P&.{M+m4x(Wy}) =6ݖ@ld^r񲶅^wb~sM|#]U_]Q,EGz+AzMJ.,:͛ ἃxo {2ц'}#"2phR*_:4ˆgFts^iDuE#v/j!>:rbqh[=VNDs$}6p1EA,ΰHPA%4@'z18%>yc|'D, Qɀ0ҡ1Ɲ>OʦO/4)ӭ'8,צhDK 12v=,/dt>e kr_Ⱦ~}ۿ&%ZQjpD}˒%ljU,R=Vx4DO"E4Ɏe,_"}R[ qmk+k)ɠ C9{;wgg~+YaX+N?u'N@;,"Ož>Y);8rfNн-#SO_h?~8b"5kuv㈻kb'W 7="A&:\gY+ie ^.r\Fϼ; /"2^X~ovI?ͅhf+fv= 3?d# ֶ[JeSGT|½hg_^m oYZQufMQF/$?QB07 ZQ}d+:W3,e2akcNoyt[=6`IީRXˉ&`%q =$KQ^O 0," Gb-00ڻe<&NB4DcrmshFխ&H"%O&wܹ'2zz,m5&$dZ[  ҭwcN%nm Tm粛|Xcႆ4 !|hBpxې:mF9.#Bo ksz%DrR΢o")y㢢0_ELpke @fsrn> )!MPohFеE(;MLl5mkW uqL-T &kpdqǺ3ctqB%,!u)`plìVٛ{a`N֔1L=d;͋4].׫tϊi!Nt֍4<6~ |v€$.Y KloYba'gݒM^T%f"UwV=Ck?'a R<=Ƅ,17vˮ+bܡǧ]"IuS}C.\Y{p zLe_ˣ`eL'C8DS| X#{^ :a$<^T˵gU񕈙 q-+rPT5N7b<ʹRU?]`@DK6AUsWL%k/㦫/dI dQtv "BiƢZ fW:)I(/$Qۑץ܊TF(WtB;KP]i e,)ݻү!g4H%7.?3ق$ak2B |Xobn0Q8jԔMzA&*"/W]{a)4ML"fpը\F7[磮HP&L[U K)(D[R ȍ8fEƺOYC״zknkܟM?<;?v 1U}?|} yoj)_N$eq8y9˭A LK9x ftRuCdsiH#pys綃V&b7ͣo=G#ܰx<3tqEeUma7faI}a6<`VU5hR G e!/Rv't,"Df5o,zˉ,=w VeJkrr`Pf.),bD*VWK۰|vgx87t!Ǒɍnn~$!,+D<ئ>pKWNp+SD#Do rϸe&#=Z.v߰eJ)\wD#.&b֖Z,[OU֫^o)HuW}|VҞt "OZYE:0+q`)PCI.cѾp" )wH17u BX؈DT dd41L'H1~Zv!U!<t;eAݍNgx *BmHQا$7Sg<^=ų+GW^q #o\fsh@ {'ߒk\Y_>HM Q۟cO[mӁw1,U0w >7Ϩ_KnG8}% t˓Yj6brX|vlNtY#2HA:k62,qkw1 ߀u  RS0E4HGKPBC[u)4k-{"7t=lwV%,ʒM׭*Ggq0K_MÞW]q\VjfX3DQk&Aְ*Fۘ?ɡ07CvFe(?N >ƈPż˚뎈",p:je :/t>]x*%svO5*`*q`nfӧ([$ (_3}N6Q!㚤 0tk_O;Oo9 A+DH>I\k<(Jd|@ Bhw ÔO{ZJ|$-x~ggn6/c* 2n kqlS;MDGx^=`20Jm6} \+>IA@e<0eҒRxCe+dט $; Ge&]건VC+]' ľjuK$fV VLDᣨ+z1yBZBYqM98?dqI.k"鵣/~.؍4f( gݕ.o.GPwـA_ 1H3$C8l 6zS݅˳ i/ܢrvW ߑ4 Zj+_%7`[ -v?P*JҤ9%3N}pg9Z Pͧy> 0 u7 ]1(qdr6S4#s(ءВw& *R  {m|F;x>+AmdS'pP&M+kzwQo ѯQZpZoXJ2 wN 4;y%%GW%ֲ+H*^'{҄UH(tJnsQj,@mwuKXK*{&HY%CV̉\t9Zp¢ِG<ؚ6 s5U;/yEߧԦYQӗu8|VǮ;#mϰJ'34DזbY|E㢷'a=Dp@}'ńMJFo5v 8: V^ IPDzw=8jķDج)=ԻFL?un(cKT&>u+0aj@|FK(nTLQ/;*H:vy7Ftg, o=.L,Юt,ܮ0 \g۲ d?O vT|-GGQOۋGI7ӷ ͤ9z2×"=ve]T֪J(f 't5<"޵:蚦 ->@#N JWio0+޹3mY\>*]s3P;3XRe1]ˑ@n GFJ`\ GOT\bÉ}eaC{ rˍ5&6elpEXt6zߕ^ "lqYZtXËH;e]N"o Z6u~a:7HI5v$(>:j7ȪM[HU+&*-: F//±6cK  |`N:ape :7ͷ'XpTuU52P?BN\G:7OwUw<={NarWޭg} &koRYO#Ɵ̏SӒP $1 jz&;[B,@W(VŽӕ89L5;?>b} i HXlb䆜k/G)aC>fkŃ9,MasG8Сb!`B)"k{dccdj}sǭ[ ̋Q_Ps̬3dIҟu~ Tߐr~WT6knzqG9:H]g1쐓bEZ %$G@c$fLX(/ޒn5AΨud[YQ" :Ax)_^$Yqjqwȃ:wb@!ژ۹d+nGAd>!*.f_T,Fc J֟e/ŝclښ:XS 5k&hv@VG})o^{ jMj_!☲uWig ##x6y٨ryCLu-Ջl8#8MZG3cOtNR?#~ЉL:U+#eILh*f\OVmMS$Qއ(E_c t8g#HS rZcs 'p+,D㏚sn+*n?G0#TǠUbM8s$2+E55 2ɦ:l(2,>Rl%荳3  nk+Iʈ׭lbfA|ѡ.p"~\j(e@}ZHW1bf 8Ë% Q$s5jMZrc!#rHdy(Veehŵk]$ ?fCGox ydefm5J=rf?W)l?j^qb9m.y}1OF@:ȓ9Γ] @](jLLv' ?Sib7iKV=MO8!a6 g#z~v|d`_oU?0`pHˈY"L䮷ͮ{Q5ܟ6bUE'E]#3w- VHIe N\$|6+ ^xR$D~#. ?*9v z;-"&ȝ`)#T9 -TwE3 ̃_Wǰ2跹 2e㠇T{ZvՏK39$at ȑ*n6"7&)&lw\ֳ> sII,':*rX=\'Ogǵ^zE p5(2pSP7у4kx|ۛнfnm쫽jy'ϘA. 6szPk{?tcpM-nsk DS&*x \䯽5DλkFl u,"pKR+2tZnΏbB z!></mCڳHӢǐ-_u"QtOڈ3 1LWx _yJW!%wC"}ONVZtb@ ~=ie>(Ÿ8u)1xٶ[oix3hCS@ވlCwbǢuXcoS]nq&AΉ:_ym%^ߦ0"H~drzYF[d 9s^sP#fXd´L1\T+3KnGWWbe֊!N gn.lV *͞JCF; p }'ݹXd,n|6y'J ~ jϽM=PscsRJ_EJdlG#m&IuVVBZ`;&a.M 헢ދv~)٬䐩8_P9#bp¤}E E7̩֯PRoޔ'ml4ؤG|պp.g4Isw^2lw3 KPUeB n­i} Ӵj^#pc mN"`Y|&/hC>dH1x GqRēwtV0BIzoP.o݋9faV|~a以cP}0d(a7ܗC!cvO|jȒHN|,itaPh(i+^`A@Kyud? ,JWfɀ^&-q }󢊝=3O6\4=pzQTK;c5-{1Gevk*BV9e=Gǔ+ ,wJn;q1MͮμP|P0 0s&jp|ZP̸~4S7HN120mM*bVYp#]YVU;Gƅ e|$fۻ괰xm>nÃkglЧyLŜwj%_^ks_Hr [vB-K jR-(wut j{!5pjgI[/Y r=.KSC%>S=# 7RM J T&""'XVkaLZ*F"@GiY+"]ZI@.h1a<"c~B ?|#,j*4XD"6r/=^}ȳTY<5B,tz7__ US_-0xgTǔB͓lrU9=@0!vzԂ? FsZF-A\ 0` a BO'i^[ mgvhE8^*EP|'8$- l&( mW-c`!@[:sI.IyyDEۦ-z{rfΛ:Gw}_լNFa9=O"]?:غTJ?؟ 񰚻, )8oeNȏxerqJbdLkWIJh_TTH-=\6DdOJB26{O=@вɑE[ot t~Bڣ9-_ L%.Gn*2F!`,L'Ad#-jK[7-k)f5/ S5C5{ D :峩.w>KyJ.;oK G?Kq X*_־~Fnf/_"V24`#8 Ku{v/YsUַn'La7kD[s&{D@3[̑qjd"o3jײ6swOY(AKvuA )xiLTB   Vʂ}7j$( JBFp561Syj`Kinz(o1a-TlF L撴h{uD+g/4JhP >EU~ԿG!11H0us[U5t 9$G-AuM $=<,MmKiزiH/ EM qKYXpRkt}b|6V?TyZ RM'BY A7{ĝty|tUc5'T%@uj([xsCt2Xoss?XQVbr[gqE3 EKF& J3Qļ歖xSæDh"7E8 h<1zwG Xw&U),Jmam{;ꆵF{>{J>! C Ar#'Ss^VkMgт:DtuYz_RZ++'}' w$ݲK=7.#nW\+|q]o2%9WJTڹR NwSRԡ6 nq71B _*PWx?]*rDYi`Ս!( <@#-Uw^Z I#~N' DAvEG(v3ն(oD")#= ~f#~o"_G(Z<`fƐBf@A)/VչC9}$kK&"F$e)z4l)*g$_Da)8a֯Sd{_j= ?K 1Ps>J߭Pk&YZwP㩰@_-q= 3ǞF9VY]@ ]BܶǴTZJ&w@^ޤ Gb~F?m]_X68P -(=iΜ%^쥓٦bQ3umE*,Ҷ7G ֔aMϗMqY**O?5AHAn"k7!zM]4DpTY{Lk\)Hxk|_1e雚*l $yҎs@U}PIb)5C1$1'7$Hb '2]!Jc5  ŔԷ|'c?WVG%)$Dpu5N׌%Z hcS F'SL윙D:3]G!9Be*$r"?LݺBEk;YW\܈=ѓl\<0#h߳XPlUlH&j܊X*X e4_%ƜC ̙"+j7!ߣ6}X0~+ |I11xPh{[>Ԁث!2Zhn!(zZn2o+f>OYv`JNuxNf$>F/n88;/jU6Y)0C֞H0*Е!u*I׌oOxIi韨sN}3 y&HRC(=kyWպ#ܪ{Vdz` Ҝ1%gco(GJ@W?4?┞.2IMSwBmH/O8i[uRPED t;7HUE$\>6E~:"ҔN%hg<֐]\  Pl>[XJQ_0f֌v)HR.f LBqSN)RJyiN=hos '4,OqlK m=T٢tu.&Oz/΁i7@] S:ll(d='DnN~.}" O2ǐVWg r].@?\:z_بB?hf,Eby_W [-oy=)5A%鵘q{18'q[By@ ^&/gKx@}v;!lF{8;0xSam óSt+#b8/k[jaiN +>=#[߼ :F 읿T*GkX?(U8HVŐu/A(Ґ~lLF~*y`p%X,5} }#q.?򀳛BC[b7@Q%k0w&j5Ō!bpt//m/fYzu:yU!":,~A"Gc-c2D:O0DȰҗWq*p&kGNAeM4Qw㯞<)ntSKo3@JrwI.H̱Ჽ%] _ X+F8 "'nŦ"i>Գ2Ltcw \InhI(ʇ9>PGlH a9\@˃;{.Icqc4d$ErC#y .qR3fv+uE.wjħ^fP='n&LJb@*US~IJnU-ub ˶]|@QuU}cK-s bBߪ0;UvEﮃ:{%X@| 9>5R^ .}Fto2H28fC3g?rpWr2aKRơ9(\BX Tk!Eci[sN%V4j?g-IgyA]>FoUW Ewx:ӞQ٪&` ҾAJw.TtNݶk:FlG׏\<49A`șNsc4%M MLܗ֐3p ]5Wh2ןTw>y-4fXKR}{egVOo9z6 {x@^TfLWS DO Sqmm~*\ A18]J(p#S">dKaD9DL^f;fieZ)m^iZͩ*%.oKdʞi>}Z#O2jgꟑ3 mJPyCm9 _ ?9Bm?Gfʿ]-RD_wYPM<"@07Ok&,H_vMtBD<X3`5u> s(%"JA@ס@aWU .4|Q2/ %ځIIF"d-3 ]MRĠ09bY?8S笸D޴MNRu:#Oxq Mv1Z5q~qѩNɰ+.ˁyC;kUה+wPni<]s n\:Bi` P~l΅dGrUS"o^MV韓f;wk/˰}>"^-$b. Q5zA_d[9Dm0E?>Oɗ:H>NJU۽ 6by V>Z|3 -CxeCī?hG},Ηӱ9ŭ+(Sژ0xF)1L.[K)S;RNAV;ņ i6?̳F]8R<ң@0ugXulmaOL ,(ǓЎ+nDW_%iV6g %ӎiɣ뤲:/{4 :G|Zy#~Mu@_c$ Ο W `ؿ$<_ t+LS,9<)s-f/ɫz͵-N9'Kz_{pU[X[.K A ~\T/h]H٪70=W/)5w͌XwO /@{9M/uѫ!NEU3X 踳 RAtax)Dk$T%-Ln\Ê- h0Fpm f®єEsņ$(Ղ&bDߐG_׎e FSz+Z`y@NtؤOY" xҦ )vDCat|_S\S>"q`)|80@@QY~f50#c9=n}ZBswu= J} smFpabzvq6~ҥ0bd5rHF8/*IXM1߀n초ա_D$lޜb[ ,)G.xG!;A[P\GqIۯ"Z%$*ڶ,%Z֜ K} >x7ڙ\33 B1\\=t ,"JS~cC=ݴ7"xcO ñ0ݣd<JXF$X>j/e! ]>$ɷȶ1krx<]_|$ H6gYgf5g uzѪ*6 F-d4ڧ+ׇ.QGHIPZWT8{&j ]$4sLA@8M~jXbz"xA$̾[f0G6,B'P4 M,Q?BИBvlKm_Xe&ڈ֜zjDfv$KLdT<[Y ɞ`2q8 l;8! .\R!!rozd&QiPζg0$̯ FfPJ%ż+! +sՃ+- iL-Ne3bslLhUsgZ+nH!r?_  W[F)'y?hUkBu.dA eIbB#)9lyPGUqJX9!eCQhy1p+N* =63t@.aM唔+ld:Ӻ5UH:-ڌ;;Ӻbʣr4r;-.Eԡn/|R?Fc,6z[} 2-=+,#@f/]$𡣀Rexc$so-1#˽NiAIb;uVUwAMTJռG 4<,t֞/a>L!I8>lpn*6L~tgܭ ,0е|m':Mu!i(!C,Ú }lU,[X6!k|yԟ[N/3s.jIlC-]rAZ*7d zjmG W^bI=Ӿ+XxbʘҾ!hQV]wvC6vVLYXVWU)m͹`wel`T a3-y~4HYB:$x$ߵ}M r^\+:n?3tGsVsnw~[S:<NkiZ9|O偏)\y2\2Opj:HŢ5珜V?;@{MA MF1?B {LE[##zV9%<"@%uZy=9"Q`f5{_G2;x?u5~B>H%0#B[0c1JAplR(/ggQCO?H=*IzF8rʢ:  OǷ&tA3 3_8l $.⣩x9 Í9uX韹à u z=5 mZ-yT ,o \.з0pEdqRŁAJB%sh /7I/[M2+vL9K6o!`哯kp_g3x|SNPW" I$d ͅ1p,_4B>`u9nMC=%ChMϚYc.D=IzP~g:ėOt~Nw+%~y dh^A"{݌Ө$& N -W@r @iO[ы%lN;1lqA4|aQԩ믲OԹ/1M o4f8{k TN`Է9r dbSX Hq¡e  UzaŹw[F,y3J/0Z(^.)t%*7GSmW5YͰ~$١(;拍jڮ4{8VK7!-uGŇ6UTiva]6:P[1`*|vU3X$t]jb|c;wև":K*`M:zSS 4r@ κ>| k^, eO jҗ|C 2@yuwirY[]|U^ҰdyX`LD\u9D?RCT+oF"Z%89|íăx쫢Wt˒o|avC0LԇU:XOI~ WxTO*Ђ)Z4׏()d%;//ݰ`ݘӐu˳js{2KBhn9dZ<LWB~@% яQ5\-Mhꡰ!Qo:Ck-oǜ_.i]׋sޜOaL0> Ee6+lP~C4|oyzSo.;9Φ Gb#I;*?[.]Y>(XMEc9Im9-5pU^,TI=$^j;P˻p=:&]ɫ dLv ɯYlnE>dB=>EϜV^7=)F϶88Apɤ*>ӏDn޽t^Ӡ`쮎޵a4oBEQs!M84pyerH< 2yz(Ef#SvW ֮Iw[ E%Qű[2Tm|C|BO($lFXޚל (WS,E艊BF`Ԣ ȑ?u e*eX =~5A&U>|o}rEy>JwxbJZ%ȴ`telt7Y7jv ѕWTUS7 %{T,7'Y\/ 8 L +%"|SE'q.A-cA.sI!V|mv:2s\5 Oh. $wrY7Vhǟ-ͬ3:lſ,( LZ>VgႿoV"{(=si,<~}VdmC/ jl5 a~h&e Ld=5S8DFo+-NL_JD[>H0\`3w]'/hpϛ 9R%DƂ!KpI:&R?f߲<{f͎~~m%3 =3OHkZ8YiĻ?1q3+iqp-"aNGgONWnbĪp $L DcP]A<^hX#/o/A I+:* X{߉ m%А !!V<<0''@*L͢dI1oj-M\U1A:"5 wzJʚT`jQMPvs;&=LgvCq| =Vp.+z5Aی0܌4:hGcf/l)rnN| ʷ[m KҀ{ 3-󹷞VQDGWFF^ǂxA36R`[ @tjy\aev$" }N@y0+jJ$xΦGry|5PxZ˶XV`LvQ -|*~;+I.y[OjYTfp}0hS@CVt<9L YW%].cPΓFRC!qc}wN18<}Ti'<~jsۋw(yBUƆ$g"0騡?9[f4~CCeHykKʒȲytDgbW}Khp~ueXdO-f =1WBÓ,eR2#Y-M[8#\>X-8&rKC@+qp`hpt90x1T+\'¬׮=9 GSx$f܌`6>aq Z$!9dr0iŤ؎{oXћ2hz@Y闙-Sp[d`ԀU)kd{ȶQ6t-$DƱ5^/G]8@088b-Ϙsb?+U/ėE}14ݚk'TE-6;JuưqNID} jרŞ⠒F8:yD{f HhI-W1c/7D[pJ"9q(VX,wa*ư; Z+ΐx!CD$GNm F{P,<"-8 e[sqrs}1f,3E%RA.f!Ʋ)@t\?ݜSԒ ]⺩ã98a$ll(?,1` ؎llr TM{]| cBszD7qcFϮ.րmEt&f$eB) bk1ymgJpa6M $e  E~pхvAԍ: .>vhG #O?=0%6^9`$%Ƈ+D 󪢈WK*TS6j<9-xjt e.cpsz!STG ix^g{GF|g% f O%o ]ś\MiC-C* u!Oe%{?'G>u^no|УkHs Rf]t~XAj2Lf{1K>l1R#^ u~wW'(_p%&i؇n'ۏ< cKyMe WC$~LZ`zK*ɉ:. k$FHNJ%g-& TїM-o/@O=<wBNtM\q#NYzVDƧڏ򳬜Pw}}& {/]8&/48xLRQZf7,EQ\lKkt?ݕj hA ,P6z։ Jn#i|IEnw(RqTKe?O7HVƒ;9Yjj]7l4+濝Dے/}mHrtZ9GX ä?NJ@ f\x1ad,@\Cc߂;T(orRuAC.FA`e(6(x"dKG+uyiXIGP"56u0]|IN_^7ɫ%z,aXFZˡBR$VRN}PCĻD=h?}U5eeVqN &%O?J`oev<֔aHem{e*՚м شH%^u+^Z!`h$w^ mT~OW SbCBbcD`*v;&K/I󅗾}(5+LObV%J D([|AFEy^ٴߟax'& #a)X4oSÃiPBe@bXgq28h(XrWivR7mpӴxs(# LQX*6cc\JeR/ D 2x/[0b`љu2N"yoЭ5Nlۿ؈U48_nīg*!NU5 ?;VX &(Aq4ܝ}V@6w:2_ChwU"WgMݼg̏B@75cFJPW١a+YT&G0/V(>?$q륗_2{ F.}spsջCqc2-b !Gm]O]!۽4}d;)~d3غ8^( [IS![\hz б xPQ?QL6ZeŔ鴋AnT6Fu/V+ 4Wè&qIukWA{n#!2N?YXl٦i',f])eWi5yĶb!>EGQH{=?Ǖ5ޫi:.Fhk}_4`w*"4l-^ hA!gU$IPD}z4 z,L@ؾ1,N.,^[Sb=Z?%'3-n1TN- 1jႠtDSQ'1~ F$QO>Uyf_=N{C+`YI*ݶ"bT;6OTL[O%<{c`TzmL3~ } t%Rr3f]:ˆ5ߕqϘ!2Yr=޿}rqgucWHeoׅ~M-]PSo\*{hkGݫ*;zQ2hLDNߎ<{oiTF8 LovԄy }h|Rnu7%*W]«!?U=fvQ^eL?`1f/JB̼[Heoޞy :7:|AMmA+5: z2+¤Vca\&(K+!8QuyFd>]u g.Ho؝vJG<ҰfOpz=J!;9$4`țya]g//S4p`E*6=Bb4`m:(WaۇtcQX[^p"co~0H$juN)aCa ڮl]6w^߾(kh`|x_a-a/&aS=\Fʿڃt %=;NǫcP@:7&s_"(Blpq \O?ZQK1nKZ43ט;>Xˢ' 耼\Ai4]NLݭfV7+#۲lfIȻH9DDAXH&co}%5Dȏ8>dq3Th/mm",ᐏ|M?TJ|R#KN> fmZ<Ժ&Tgq峬|yA%K/Ma̅xJUVSR9h ~X7T;?knXod I`Q˵~xM526|9Юc,uNt:f-m$E ߼N?lgkH@q b4>|8aws)_]Ɂ?uiFt iAA&lbjt 2QbjEtSiwlۮ=d$p0/de83bg1%QI/qd!dT1c6X/j 2EYY~ОY}"slws-6+_EY0ShYORS$V*8`lL\yxQ =*d՛_]qrϢCAyj# !O>܌FMK5@?qg5.g+0GoSBu`/%JhWH'PIꤔL8vY`@ڕ5NZ͗{ sux7vE&My4dQуf%qgEQʏF6ؑ3Je#B )nrлdM2ӶToy->WHA,Rܛ_^&^5-&D,DLbmJxڪn2dD]i+2Жd7xu͗˵\Y"gvo٢Vl<VZB}RI/3DD׶ DIYۭv"G=ܵDڃwFԃɋ|3JLT͓5 ).$Ѫ^ngpBXSj3 "ojsb`tI״/K8I0W'F5FҠ+w輒 pPC1 fق&nCh LvŜT~E> V\O^I14%=(})f2d7MC1m  et 1XEeF gS~Jxz1<t/ Ag$s>ǒ6P@J&K.(:I.h욭yDa0󉑎0޽މ{V?"atm^d6s{% K [^Y+3pm]D}ȱ+ǠKOh)}jҔ*G LxCi," 0 EeJ{%!/a݆TwVRB-t ΠIGX/$y/l8bSs%HϾ{xVkbJh nMG09L,?*ӰA,-q˘ZocvRPIp I1&n3dg!> ھ++s^m\bڷz$^pwa8?5hcvftJ+s̡^IqmK%* 0 Ȣ2!#NQ! Z9[˲)1γ J50H &אߏbXc2םYRR1#ratKP;* (Q\~-?W> n(bxzy8= lS-ȖR7}ZA'wOaỽx7֠H[b1*ӤRKӞ+v{{.n,z`UhJn0sOo6#LnH`j 6|Lv[gD[Z:a)Ms?Fg֯DJT|TX?~^4WH=Joxkr:+U8cⓛvEpAߴm$a=;KhtIt2ܼdg϶Z"^x(j6+Wҏ 8݊Pw;h|7>n 4+LmrKͫ@+7ۮWM|\TN[|2:C Jʢld)&ԨNBoWpp?^-Ҝ('H/Tzgf,w-vhQ-?NUC"PTmW+\ .(G.FZS!mX5A7a糝J;0t?MdM⍓7SZxnTVI@OL>zKIʽo_2Z@:$Ȫa*#M ͛ӑrBBM[l T5uUѡ 0a^FLS46_bGL 4R:=9Vij{8IN¢Iώ< р@Q؁՘8M\\-V,I0bӝSI~=*,RG3FN=ʸp*P"SfGNcbSYdesN(\_S%Ҿ˻[࣍"VłMvu'~O,f=U 4e2 cCC>eP iz0 .]WWF1"7n'ɼ!ŤY٨J@2B  ?p +L9=6XiUcp̳1~Mw mϯ{%'|(f,#ddFW5 gX ,3 {ɍ$=-us_ulq6ژ)DP+ڊC0dA&Er" B2c;GMh|1ycj ׹R81/eTF-5c\[ocO~ϬFc?n 9){;9alil}1:ǓԂVN ZtF&ˬU<ackӲzuD|J#nk5èWM`zuc\PdltYdP}Rb$}$w2 >fR9UB+:.+͟1yLIOuz7yݪLQNzf,WMf90G78XuƀؗQ2)R pWk` /ֵirf]k&JES!* ܬ,4^!Սy}dHmqc2|ols(d'ck9Yl4/-ٴ?^`\K1^oŁ7۟5ypv7)ִa6M,e2Uj|qiלOt)W<{Hj{V?ȋT];Lk3{Bxθ(T S 4jݼڙm\T>| 6Bb?ĤGLyxy|]Q#|DG;r g.E1jҀJH=w3q|ȹx0[]bAQW[@6MaDx5_K0'S;t 1'F= 4bOϓoEeAbtR~uϙYB '(RpLU ;; {/].gTXWƲ}6zvQV[IA  kA(;*r!H VYI=qU \ת.R! z8Vk_bͣsTm#tVX Cb;:Nպhraxg<G A *5O3)/Źp' 3ܯ2i9nS1fZKm4Gŭ˻ۭ!qХcGMQ9E f>4gj0[V/{hr>6T JPv_$T|9Ĕf!jѼp$e ` %Z~!S'# %U@`,&f*Z!.'S&N\[vC/ؽ E kIDVޭr}yr<$pl q8U{qG]S^>Ytd%H#IfKaTOt'F6ۄi:!GlpUu6ERslᝆ'wzyR0>O0+k6n%ͱIrGoPzBM 8 C=kq=Cs@;)PYJVa؞ tnw6MHY_VmcIF&> H&!B3s/Em[FuPk[Smy9SU9wMIn챂y^*U}^GJS2Em/ʇqu3[ppa|ҡ K-HYjmھlpk>-&ɋܯ3$֣K[ zP0AumFvQ~oj){zG|ڑ~SǣmWkI,/CSNo<"G?ڥ#ХVY}2]&j&d I; n-t W҃1Y9vFmD ߇͝Dc{%':xf "fPRy"7xbOxȖ3c~O" `uo+5Y~$Ksav <%P諿)pGUcso| $Q'|~=|5 a%^C,Lo?āҩa|}.pnG[ԠqF *7+/O$FjtPjpdФgg+ Kee'k|0O # S Zlۂ쒌~1#S8I3Ffn⹖ƑbnGz@ 2n{^4%:se{mQEYvEK,][,X2zԽ)o*L"vT'tj\5Yr7 @zxzִC\[`7+RŹ=u9eZ5A=u KD#.\\dQ9!LQӞW~uYADI;ʬ>M2nl 7'ls*XrRJ[ǠZfTa[~ЖXHf} ED_ft'On$Kw!9&G9[׺UXjz|:|PwǿO˚7^+ !5;QV%j;n趜cb{&9>2(UzDdH,# b!p̣t}<ZaL4A_ysTHV'W\j#]]ۘu/>悩{t!vz.fā.{xpQW9xXn[ČS0Lb+U}˕V>D؟kd-ޞ"m/mE߭2I?nQ +t7aݵ8SȬ; ycpGȤ}sC dǬp*Wa.]XUqorMV |AvjdO3tjC\gpO1E~|!ɪlz֗9C*P)?^秽r?i[ 9p{K:&tH A~Yi[hŭ~69\? ZK(pb璑1'NS]œ~l]ZqFhڽu~,=1&|x-_F~F7_i}a=te'^3F҃G_H}݊lϷU?3 '_}1U*x)H; y0&Q#D+BaKרSSiIm~~bʃY=gtA׀>&Tz|d6^*-ss0k.N95`dZQTvCdȏ8Ф2ޚGM 83Ets!5c 7.`dƇu .&r!G?iL6-9e30㙆:KHyD2w<0*Gm ;!oBgOnT8Hu1]]D< # iyB^^]vDt JtrJH(Rydgr䶞m7]Koٜb-Ŷ?SBVg "' t/[] OOh2e3)bzTmCewmvR"i0Θ. Cʀ&bgOΡNtrykZ{M|O4l$Fۙ5Da("Eքr.-'!fbJIy'Ba=*Ԍ☃~ݕpC%Sͥϳ7/8 r>"hf?Ms0{9Dr,17T%ךՄ O(+;-guluYX̅m919aη1&C=USkKX+Ņȝ?cGũ,--Sm U\Wl4}*UI+14;8o[0yu4z>p! ŗ)@g'HL'<HA{h\xw+/zafFF'/ԐMwj:7j w}`M:,)\?Ʊ [HK62i\p&5ZO/E3R!XQ7 Y}̦FU9[( =pBEp!4aKwp)%fd3^"RVcß:7GrGIv;WM"O㼝7ƾ ܶç-*XY"oXNTq)aox:kD|(o$HřjeVhHߗ慎CDFXM|ѰH0Zph;#->T |GΞ] D7u|r (sYJxӓ [gPlJHh gڧS ޖƌQ-)XG_ߚ;½pGiWΈXmТlusnWD:}Z0Ags[$ڂTUS U՗nxb\GK 13G`o}0eB<iB}j΋;'cӼֈx?sF0GzL: HSgΙ'ml-N1*BLp]8z%g +;~Î6j9{{0Uvv a5_6o]Y [gS닧4Xd 5z}[>sŮM+=FYT*"*ORorDY5Bs >bg Hh/!T7%R)edvAȘ "n/bq璝Y輂i0$yŃ%ߺ+'˹U1(Stl͆#"V;|RإY\RLIᕜ~.!4}TM}ʭ7jEYk$ 5De JYAYNG*hl+oD%(!:P''pg\kN5WDږ2SE@fZ$*Ùsڻh*u_}; J L}hfV6-$quirBV`MtlJ6'P1v$6g:-S?R*`:d *9֫ːÓ@,[xyTVAS%ސC>NYЙa@!YMg\n߷݂o̍Rve¹"麮uV4Y Vh^*8=Sm|rTi<C, ozN$P*0=Y&ꚠ`UV=ϓR$,h{,E+1pDV45ГR1OFY@UJKDPǾUySٛ;2 Ixte͗zP0& |[iZgEɞߨ|~`#٨bĕNg/xNc6TF"]΋A?ZuE17a` 82A<CR(j?[5?8: lk `OrD{ ZadM]fY{kGWP/|}>j77X#N'k}ڦ!f¼9NǓ/Q@^ Z b uIg\^lќpPɋ*/.6 k6d?5`UwPSF(9!'.]V;f},q21Fyb"eexslX}ao}%Fʼn Lt8͂עX"; &):E,~;(?'[2m s{jh3أoUApaР7~tmiA4n&vtsE:VΤ8h>Q˭*#[lޛ*oc^qZg^p\vōn ! A@ںDogE@h9$|(wE}qO?:+#[ǰCzW +MwՁ]?@L y5,[Q[VUI}(؂NGTbD *-͂|-]/ag%bmrje0BJFfݍ2 ^DqP #_ *`̢j'1YӋT}q 0[GL6 ;Zţ=[Eeoz-cɣ¬vJZMCAʎ^[C HH6#߷ڭ];M0[?ga:U[P`⿚3v{0{,'h]eVnD6!?$)1ջ'›/gG1iƂ/\Q[*ʋA쿮&)Nr;GMY~G@@ cv$6ܳflBB kReH+<߲eJj2 Bu|w"m_{h HJK/_cv6(g*Jk9J4n3ԽFU:D>K?2B !'P&,rn-dNd׸,W__|+A*wY/0]T:gCZ6:((%d; J+JrB~=ELRe6$? pr*f8hž7MT̉ dAky 0\ Љw_Μl^2:fwF wjO$hZ|@)&Vz*F'̴\fB$~Ssg-Ǧt3)C~iK RPqHkwV  : pTah-QyvM/4gd4 !4P$7 PN)jFI Gq%IiF}=:BGRi,&Yc5'2r9݀VTƄ*k!l=W]EG/yGSKZ`a`TH jnȨ>hp&,bSDM6֜䍟yR?Vـ̓"lQM&}g`u >ZQT֍i6Z %ZWkqg,v|c#냋7mO3!4"h~z!#Dugw39a!48TW 5X:&X\P#ϼIFtQǧu">Aqc`JQv6vڡKTֿ|ҭ{z>  Z%#6v3|bėIs.e8j®{AD*&$2k4seَvxgnܒ~vdhϮ(ORMp1 wX7"7,QG&Wt?ܡ?ABS2aD CF;hWON&ZY'?1l|}{z?&,q3wI,cm*yl([ȁƙl*Zs3bi訤PB)L9cQ04ix pkTLC˾W&mN6rwOJ0ۻV/Bh bЀb5 ǘ RtNg/o6? ccMO Ie,#լ0Ym j8F1ODGTҬZF#4Mp:ʟ5 _#7Zs|ՀHqb7#Li6HjǐS~&21؅t?Ad} D8[˦s4~}\rKWOC_ Ck(*bSoUhH>ݝ$J5jEtcT٨HLګ5I8rƼ %=zŅ7.UljymX@ ~Gh[\Zd˒C vŔ7&a}֖J;(H4Ml7Q/mz "c&׵\(7*hA*!;-W^#_⑐{WebzʿOnsXkmȖ)$boz%ڀ 3bSY"MBhie?ȘUnنJVQYΎV)/-}۶.3~$֦XA)mMnCԹj 897 qZ|}!84;Z L"aؤ`J7]t&&YIU͓CzϠG#l$=2QeZWn"abH&%g03Xj6SfR Zfh ̡帤$?b (,sNemIs"Ex,ђ²g&i<&Z1Ud)arKFr22pg :W(oAɳk&bѴXÊ7~k:=N6VhNX}R dq]ǮM2 6%XE58pI=Y$]|>6 ?#/g)$eY_f}_5;c%1^eGoF*."oY5CG~v7 of5ˈWZtӓJ9(h(,Y޽7':-7.C]+Q }4#%2 Sci!7[PM%qk"cXئrxT; ^^Η>."9y6J_ظxDfr YjfX?#o̼dܨ >3aO}O\$PV5R9_9$T\f="fH4!^k] T;ЉMADԳX=vpĐ N^U;>Wilk y֩m NzIVȘ̫ahy[*o V<Ȟ|l̮ZkBb)N 2{A9dˬ(5i]h#9#Pޘ\uY|ge .oˏ2ڌnRTHd3U $zf0&@Cg#6bAOzkە3ŭ{tmd䒉 kU3c\C}6s \$l}ECŇa6_!?zP\PN1ޟFX|)ő&.e?;V LK'_{ [3#!aBC5j@s0zK.B<7MkvEFGc(q|Yh%3̋m_Y7*I#yHJePe$f_tsk$ BTI`AT9 ctEO?'I/iFu7ΠEV$0Q;q<~o: O/Y,O=rV9 r .\,!P}E)<[(񊠴3lwg{"p@VͽzͣLn@z} <_7Nh[P9 ӤrW5ސ%c~l["֣0Fq0_܏[nF}s1s5gX'qbe$xor=b *fM& EəDIlRxroo"hEr(~2n]&eD6K"ŖԚ}.UϟwEXh/gG\[W[ %z}dOP4fýn//ifުٲZ BR)쮣 5EdK `H?Z6X5#؂"tWl]B㨫 |ԯO7ifԳ:`vSom Det)tfm$U녷>̞G?}'?¾woIzj狮.])Q:ԵvA]Wuʥ e6UGGsi7a;Yp 9Wh l8Lx=/j|ZK$^B> ʴdSam42iHUW¥&9 hbftWү]L[jgw} tNﰙ3U R-d1:%A͏O u'P7U \]dx(jT{-(Rf6aKx'R$KD{D8G]\1vjvrbxg性JP3ϡILkOP>t/UkN,*u Kz~ų0QF#JjhLuq FP۔#8gT1 95`L~J$XtJeh15bL|(Cu_+HQU3["ڋ-S,hk=: REZʴ!K@ME~?0KX! =(gY4脷! V*3v5F.ŶcSxenrCKOF/%RG7.bh_8p]*MV֧ @`D))Kg='ʜFŐw_RZ҃&ӊuv?KEv3֖^@yU:LY`5t1T nt"<;2 kⅭ{^'{uCFcJOdX=q\o|IE:yǒ'_దYGi_ ̋;X,6/6<<.vGEd ~D6*Fґ -Pz8Ljezx"U[, " ܁+AXbb ֧B9TCFW/V5G>='Dq C,v\^+NjSƪ- +]3='|4),Ј dn@C ӺYC+u}ҫl݃mO"N&fcl-M av8ܽSЂ :)+率R Le?on7HYÃ3jЊZb)'V;oQv<.hU .yVhS,fkW_hܸpa1Agܷ}xE%{ݏ;SAH4`E|5iQEDOC | ŞRv)xnMLD]yq=L(?tdy,<Ś4C; 3\.k<64nVl;7tKX~$x7kEUqhxnZ>OvN=,Es6f}uhd 1r#G&-^Ԛ9EiӠ@J\+t Q4e7)WTݚ3Z&^Q&(hxB-w+S+XF? -O(FyWsAhpi|u2ο!WÖzW K x4I=k)d|o 9d/ [:>' i1[h~jrCЊ >v L6d5Ы;|e*nfS։Y%V `]ZYQwL= 5(z|,9Vh+~duKSrƄ3Zbt~`j}a2v8K,S# yn 04eC'iXotӁcIߔƥ~DŒnq´f>VHH}dIܨ\[&1z#f\<𘒈DUH]SMLF>j 1[J9y!~ER46̽yQ-9?9j? ?9 ToO(?Ka@2sF̨ns҄^{9-_Sΰ)'`C*O ݄rV/ӳ/fp1DB(S)3&[w @+,vF\;&hszj)mSϕ\TN/̳3eٳˍ|:hp' / D]}4B2´\ yi #҅K$wPޗ bm/) sbl?"R+l= ddlTI" a2iwv8 FC7 L5(3iSnO%2P{d',[OM#EP ʻ!;B'yBOU6Q7| Oxb]_'(_!24O?ALh$Yj?_i/x߭ 0HbEY}M}]>O~oUc4Gp4U~_nfv10/x*EHMU, LRmg౲Qp;Ot<65ij[=ԁ (ʆ@V1{5fm3u1,6&9;|$[0'YTiӰf4}`E/ &3G+M(8aBvGWUz؇eOTWce4(EΨ~rG*?&/s_N KL]ۧ9e$.jf]Zlk=~TЕmd!oWާ2R]Eⅅbfv¨c"ʪ}܎1ՆA/*IҘ륱{͎u,^~#00EOߙ'"FQy>YG. V֏vj@} !ʲBi&<Ùm0eڛ=ff3MX+=h4 IBdYU6HBW)TLm0=`óy_KV6BPj"~2n\m9gsnԶgε㗦l;W/aWo,Jv~_y=>+ ]+GHxHΥs2!!NSUxJy%aQeK%f>kaEP-YY'TiMFd >:2%"*+ލ6 |J o…8fJi5qD C2mF/E~vuD782% ^F)u/&m9 Ps glryJfqv88\E/0D/&z4tD'Ŷ؏Y]P 2g+ȥ0·pR7 KmϬSDj95 nY隵eeҥ:iFE4BЂF Jw@RΪMP !Ѫ#l'!^OL2E{7IV QK7aѬop :?A  ;}XF(ug$"X`Y zԉ+/+M쭪@VFK3Y_(Zys3>?;@kpT:.ZdJkZJ< ot|?Fc۪%-4,)m3O*9f#g*wlt4!P"YP]9'2V5Z`"zzir&1vZ){W%e^zZEHќ/N㉱j•$Xy t6Q >UW"!ܚn(E7ۗ&],2lFtsyr;V3ӱg#јs0I!IB96*EEm5Aq%l8q5eCjӦ=e|oɦAU|\^QhQ UܨQjZRQW5@+&9˧RWE>贯Nm3 b#y)[_t[E>-iiohɍ'vΎDYz?hZw,3[U q1raZɨ?ޡ0fp%41@ 3'Q> H*Dit>'+d} Xk/<늚z2'ܟGQõө5@'I` i*-=!R\kى┋b_ӊJ‚s&PqYU4 +{ cp ȔpǍHc(?CrcpӀ- 3.N#r.Ӂ7p3&ߓ;.<=QmA\o`ҲPO 9(`t$ޮ b PvnwB\O !V]HXF &1 a}uF&¨A^:4F:nY)3<'RVLթNzi'cz͈^oCв{Azl̥/55 [TlR o+g&$I`%WHT37糷teȟܸe4ȐyxzWj Ȑn7<r՜afѐKHNB9ܶ4] 9M9lL^o2Q6.ֻfpB#r֜arIBסKtqep2&/}/h=:960K٪'*Ujyܴ3v&߶Vfa~d3=Zjxb[sĸ?h b' ^d/VQĔx&rHk:R^]^Ln[v~H@x H0L_apfa8S%[lNWZxD1QŢ۶KmxKaM(NÊKMl 3lVз޵RuK-i>.a)+{gϤՌQR^ 9+Wv&#iV x.Mhi=3kݾdԣ:EnF9PnG@):"N$yQmuuء리_>JI7}N'fzԀv:yX;6K38{>J::ǼU*qu9Xl$Dv(4կʽpt.zzv3>䦢Э[LRCWMUhp:5:w8X| ?"Zs(s| $+[my|f迖FN]O}@ѻ{:72w5@sALK߻7DO_=kŸF ;Oմ=7d c@3Iݛ?sxZpfb-]"3'$k>e9Totg%nxWPC) yQ>QJ?^3H|G>S;\QQPv&G#NAʮ8hO}G+FsK>,L]Q46} !Zu0ٸ2C>Cɦo-+#54<>iβn͵5-C-_ ކ-VyfCyaC8Vg]=ySau2(v!XM> 0*Q? \ DcmHlG:9##t%>Ṅ }MCq~ q-O8 `Abk=`g[@i7pTΖ$d.cz%B6aEʟ)M {M̜oOdxu {RFDGܤ,t60*t7EYʉҜٹHaZ.7w|bhbW| ŭP`PTz{ 쫲qlX2_raW`a[bAQO~50O"Ul? 0)VtP`}> g|r:K-&uPk~4vlZC_#NTz/=%{oVdtn5G;);nVðU>j6KXNW;Ç 'PIu[Hǰ5C9`)eߌ12-S-n3SIZTv6 e*@u>',(ǻ@ _445ʔMr@BQ mQv5LT2MrIv3lo9ks[SF=e2xJz P?5^Yj3ٵ)C:ee{|åv[x{X͸{`+;J ;vbjsƗ_"Xtr"͎7( Cjx;S\Kb͵ Xza *=nfO-a .Hj KuC/ȟڔmN}w}>uM[*-@v=+7suOyr,wXT@l%cAjٜ)+nLT7K7pRpT}R&RxN< aUX81Ŕz91o!De[dA7mP>(*~ }RgB;W4vL(# {3wgi^g|f/*+CTWH(v˅dW}DedF# hNZRF0t٢V)Ęj|! L;ls%q~Nl}Eʼ@AT3&3_jN8:Kus30 (K c&ovJN GkՓc#fa~xA8^{fs"Úa"ADA_jFH'㖇ʧINK )O?64ۣDhг@ŊMs}|}_ӅpJMY?S.F ErĖ[2X|1ml9Cݪ!Er;aSz_O(j(3;ڊ<(UH볢Y!/ti m a0y|;G9|q(X0,޲X+iM#xr$VKPs!N \e$`@-嶰]%a _r"JVt _D8X1VRӪyߢT+q,Ѝӑ{hi?7djT-=`Q 76uzٶɱ 0pa̹8A{(`:־Оcqgd -cH fx(@ h YGT脩!Y1.CFrJ9ePk1u{Ick4A=p|["4"UыI ;'3C[|o}A>}9U.@B)}N^۽Sh{6fPG7Od/ؤ'_i ?}f-Vk$*铺Plcx /3Q vuzXjەTc漒aP;Mt(⯮u6vƽ{ؽW0LSx\2Inh6wʍ ?_wM\oJqVe8_nCc0Pȫc6VDe=Jse+B(x"yb rxcB"jo} u{#!IWN ;w}%mPUWPoaQl3|4 a~(ӸgJfԩiyLi5MX(uxcLJ}`*_ 4_HxG՗pݐ(QEbr~VՀ >o &RFw-ȼ%[gvk a eܸ3= :Ǹv-SA|E3.TqFQb:xAÎbwv%y1f cRêR#?DtU[\ #+1|w| A#kw[ LfY|n]o:ÎV,A=0#Ajbg00~B+HV%cU)"wgV ô)TDQOo `mi5 Ȍ`K1MGQ=us7D+1iGiA"Hj'YM\ lE}/"*J%J85xwc;u̖XJ"FPVSrȯB{zItaD/W:::~u0dj69Tm2+k!igv6Oeq )@!8g4ZE<o<'l>tI򌓱"nVvKOFAAFj0fX-Ң !yK[, THVEa(2%aufɵ+c'xq거>ig,J#y%LΨW:(U n~9l7s{Ő e*!T! 93wAmBH8'BF[l,Fg= |۾-9ji+cŽQjW U}e.^@H%CK.c)Tw͗W% ܵ{;“ =1Ag ȭ48x+K}rP\b!Ҫ'S^xxHcOKWErp鴴ÜBkdF J8*[nyύ#>#2RLߟ7]"un1ΠgBDD v ["PcHKVYAZHN }IG:嗿#)q\W&k>u*u`Tt_FCj'!եn4|c\`g:*EsҚF ~$<& F"Ecprz>O ops̨U-cUnM'D.2r.6 !9KTgD'`'l7li-sюe)MNAHazViBD*g s6*D?(^겆y}U:WdLm=7 kQܺ_uj=:pF*@ C&L{ 뺗ưG9x\  $wqRe j!:XѬi9aUa?I<( uH{=mgS"1zpQ-Kwb.nvog7С^8lXpz7&e_Oz˗$ֱI iP} O5;^inB CLf/|kGF ͵JǨ=˃M=7zA *E%Z".[oGQW=m#5D9d.I232*dok vsLqn!n_䋓\X?K g*E) [ڇEd]0*}:JG#(wPE.s^sOq8GY- ;:Լa?Gt׍xmf:јQQ<&GXz #aM0H5a.9:L(,h0{` u,=oWYM0R5Y+=;K !yq=o'|tjLU~rD zzߪD)=dk C6>2G\IJ~AR֪L\U[ {iº0F7P}:|[Oqv:xzFUJNApqhII1+NU,\UT&Cꀜ@28q؃ȼPeyWveOefKpЏK?x :XK.\tEw ;xEԫ 2ֻtw6 ǼœK;6Ñis8xsi=(0~<Q'k4vcKВ59hWj 5 ;t͎軕2z~y,dؖ8zi=N pm!fA95LM>L=;oSJ/+ĔըӼDSbP>l~s+x#@v~{ZM}!eگe3ʳ\f)ئ[BalOA>ˉf=w+ڀH< 96Y^ӠVipaT ? 0iT)~$J\LةjqoGO d|IlAڌT8w섢KbLǺaQɠ԰w괻WRs}EA1&is^hk"ɲs‚٬3>8{D2F U\lɧ٘~'i?IH;Y=fJPRVXJPmPzmu}^;;7G\S[7炫r|܁LP F𳗱9gA<6 `:t!*sBykE (6D~e;ڪ1-G< ͠)p˂1r|jSc;KWf\3P؈>!(2 ˆ"FP})BIQL{+n-9`&q% 6eBɋGw+m̃E,۝:D>30 P?ޱ.8oѹ8Cތ@m90hz΍a+ҊY9Y Gi~3_E3١3IE s}-O|w :߿ 0~^Gg5O :ͷ1Nn~y(`mhI)$!WjD.7(%j3%JFr <FPOZ^fdvdGфĝծVQsT'FMI${ z m{A/)x: " m>IU|T]T!M23Kt;S7gbϒ%8;N[8):Xma€yN:ՂE˖r82irS&5a~@H7]Ohh ;:Ŭbj1OCTւ@0wӊ.cl1; 5br]{7p3$"ŰBog0f_zDdR%* ei0 ,{c;WbKD  PKf.oܞIDpg[DFB`SzzIsc22+ȦVD-4Ju?f q)ƲNJ&P~^ZƘ ~A Ҝa)IVYDʲ"k u:5g;O?0\ϨS0EaI[X#‹0@9X̥V 74p:U?w.*$l|Gvk|EHmkŷqy8kOp$<qv}Du9lU×d[a[H}"p_CwJW_"#L [t^0w*rz;ܚ;/S!}Yx8`.2 {.= K/v(m/!~L"]>?ң`ؿd3K$ Fu)W0% ޅQklЁWAu*D^t-O9 +ᆴ!(bQ-[ \unsiKu5͵=w>Փ.G[N+DH88 ZzGpnxg57Ew8g9H p(cG%5t](쐖Kf-eS!8df]1U K|?"/+G Z1{<  %G1!E mwRh;D{ G6Ӯ"F yc9!qb@ @f% kwx17&YCX0,PW9c_r%sY](Pֿ"~s-LCA>Lāb8:3NJ&_ڲyVdw1XhQBa?n16ݵԂI^H _5v~Ϭs#fu_<6F화@n֎^ѕx۰18*w5n,IVEC4KP[|vTWd$ss5 &Ѽ,eJaBZpmm~B@pB=E۫W?"z" z*>>MU=Նg@QW("bTECԞ 1FpL8Dh9sӷO&BAˌJEsR;UthGe ]Ok$JakaPx}1c:fM,Ac]-XGxeRP7y4-a*,y0|DCNٔL0mM')HbȨ)wFկ^Q9N 7i`77 7HTfq-EP; o,*YBEy #Ft2; FJh }{ bk쩐tsquCQ)\VΤNGIDuhц՚\4;eCnCL I2j%. V) SFf& ,,{p'$ݭ pc<PTL׻^tKRX#(ZWܯI$Fed^  $l m 8X?jͯUkFcznAҶwmu.hB?YZ:͊]&/S|DA~*IrKVCɰ,J]V>WgB8d<]C&h-P*:HfSMҰ(?wc ~Tp"'tj03w@ٔtn"AQTb <ͭAyN<]*P[8J4X6M [xL6/l-V"a! s _:uzvZd HʔjJ\?zD rt|%3ԡHɍdZ#"Je kq][3 =WpFPb羣L2oM.Cny|р|o "J]<+|gu]]1^ ae/+LἋNRBڧC[#.{a*۫wZo '{r`0 "9E:^[ D#X`/q֢4} >l^ 4L`ShmH"+$CFLQ56O: nN&N\] XX% -j@Mz#'Uh$h fψT^ ]{>| @PuwmN!'U%Fm)Ni۸|̘|?ъ}V4|\kek+@U=伟]1LnuS0FE=gNWlKGddѣ(8;k웴h=1phR~掌eJTvbot\9@,)7n̪Pn9[IFJca\;Xۄ&U~%>0WTuKVĖyf%\!'c=S$.>[ _bu6RC|O5sܱX'=弅;Chx0Obz||6?"r*Z~Kmg\JSVXQ56{so9Ӗ978&-~bvX/4Gҵ'mGpGf~o-7c#›}yl =_?P'*o$(W(b0G4m|mBe^;~"nV)&'â"G#,g(|g{;~N={O/9W`QJcؔ (PZ9}TdV6?RA1m2BQ׻u}Z#c S; y,D! ]v 8"9*X.͚ƛ^\1K.:r*~ٶFL^}CֿMS 7C)W[D?ǭ]V7ęݯa.)ߏ(e2n PdmvդIZ/w辂o|kJM/h-S[1T$H$QPS+;,ςq. &)jx9]_heEITbIĤO2E1&oZ77r*xMx7.bD-K;ϦCxlj% ]{IcU4=r9K`@>ӯ!‹Q7yV2nO>_/%5},jNȼN66#kLxHS\7w-2('=y{M*5`>{ 8|X1jV5-e[FB<`Q^;΁FW 쵱o=Bnhmc:Rjiϳ˻ S2#5 ZD;Bܴ]+ |7-VAGJF._7ʧqJw:!fzD%=$/0/Һ𼌮k#)Dp=Ozk?ć4(\m|b~!LJf #pvLrMIiqƌb) N/uaGM^Fnoq:o=7|#TEjrrVC!FGGUsD~!9~-~?b~'SD tn/KԴv u~w bpU]2)@ַG&a.U 62 4XNeHڇb%!6ŴK# 1tе71JN[2JG?ī):VXr g`LGUgޜ)]D+,"Hy5PXg, 4M8{ՉBf} _>Yq^ˋ: K!h.kc+_6?#43cpn;O e^3ޝv.' J(S:L#1?C:!;t`\l%A3)ks2")آm){B3(!A?n+CBEL%D vٰ_"4֦8* t y}A鶭N&I.x0C;9v:2XK菜`DNs:J93| iS +BOj B$R32ҷ %"6Lٯ @d1L lim Q?l i8Vmr;#h= \=PA! *% 2Kyh_o4+H'*4o Ԑ,ʎ# xJV٥HÁ~qKsS}ʤYEg@2:W5 .&S:լR-[n]-BU T׍GarתEZ.1S{C:Nʼc)%:&cO<NRnp/auz>MX'E =>pMJ}uZaT0:m&w SyWZ bo:Ll'm aLD8UH֒|,+S@C,3?ʁtGD#9N^G=>$3߱!sUIQWZ D[*z߄0Hԉ;u8 J>:-C ME ȝ!Dq/C-<{'`»gi87>~ʲr4w+w08qQ ,KMNb*'_)}zFIw5˴̵#&a~l0=Ru7*"1ٲc@}GYv܁A)ּ`a= Y⌏Vͺ56 Yh*nEHxSf馿J2nOfcGMgٿ5MJ+\`1Taw`na(BB\Oƺ٘b-_,$)rDȹW6{%/ZY?ӍRa_=_:'_ vo)kZD+s _r7{bQ!GqxC >PV}Z׹3%(Et6,}%6(b.ʕkSևCp ׈EAղk) oԊȬ' }r-ͣ)lS¨hܔ?- 7ds ~eg `|_*ӨڬS (P *m^;t Qx[o)IWB+l ~)AT H!0~E]Otlf|cf47RBi1J9[|$?(?w냝>Ls5?idImYΓnjOی"Q$)fK߄<0rcYͥ26*"갨ڞo`b;$!K9_]|TFt|#:BߣzοŸzHX7?^(o@z ܀yLTgTp< -U7 wmV,fd}::zMg:g:C{b| >|T5^0ZL1rD뗙77 7)7[E2X.;fON07JNے9DفԬ2z8$> ,߾Q1}#oHy^8_//Z[R$5Xjחx2QN1 !fei,pD] kQ)3Ă*"2Xp-c"0>&[y.ښGRQmglXr?ؔjQ5?N6znH儲|XPزȈrϠ+p&K2"8Ӟ Ռ&`4Ή/`\=Xe! 0'^"&+D&wqq-M߫pּܫ`1:PCyeU7ߪFѼZiX3'򩍁sߨ T:XTekg%Rm3 p>{pq0-i2nNCW>$7L̲D1V執X ?Xʋ(;_7ʴ7˾ zft{"wiE3~Bt*] (r+K vW 9A-pZ_w/1GS5=OWQc{DMя⸝sn5da)Ʋܛ†x+\swM`Lԛf $ YJz՛&uԠ" e=m 뼓hKNFM3565:5͕Q#1`e@;ü5/;^HMM!#g3t;P\4m:܅gž {d$Z?FA>hfu,LTOu+,ēU{LL>G.L ӂrܽK[MЋGߧlZ\> A0'NZ t];9uX R,UF1N"5'ƹX=݅0d6%àνs4< 9lÛjG,fLlżͧuSت阸eG$W;]Jae9r˨mo:X( aw'P0Pj)և͖B^jl{3ft`|L@hI%E$v紋BwQ\j!*?$KEJ!L8˥bHO0CPsN3 D8z}o~A4)&P{ GAn^H?1/{?-;xK`wOWzYoZmܰ޼ s\l7_aHdB Ošرx.0B߲Kv-OSD[a7Q4*\s/QJ75NfeX@Qe*=ʝopN7ͨ5=^Z[*S G[M%wʸ Ϡz̏~7We?dGFY |s^>]CtUja~]X֏Q4N=QBdCj~sNЉqlɭ>!diHqR=@BQiɮLn/,3SgK{:[8M#v{SlnBs_ZI jR,e<;}I-h&o`i ,7Mpԛ ΎLv`L[+$;1g20YR.N.qJ:SD67Rl8=rR5!,Y#z3]-I~)b+'Ar|i`45Ap$@d7U,FbU=Ml,EC_ih1AL0*.4cv9X5_ Z+d2Q6 nORL޶vX Sx[DCJwZ-#%iJWhQ5ӹ9J?U#"g)y!#aF/n\2pxz$1@n!T WM6eu47unfbiceSk*+s]v,"!KM+w%a&$f Rs*W/"ۤk+ԕLl8E@IX\Ok:Q5s01QŹ~BސYLF ,u[dLu jαUmI謱/*I -_`z \i#nsc,D zNh! S@`pR័-Qb^vOE=*˚IЃtcW إ7w롽+K#G0';&f 'D٫;=_H4i":Ō`Fb:hu`{8ΎU:ߒܸۘ+-jf_M] mG 'v8322=o>e 6/`,tV~m/O#HCV N$!Z_io؝4rE)RC4۞'*̻ &ix"iMYh~-฀nA:LMGt`i]*`."Ay(n@0x \~|]}'0u|bx!K8|.HꝢbFIիMb  ڌǫ *ێ%4F31Bx*pBӜ49!( ֗6D,5YmWD\M+VvS), tvfA(me/&s@xXU2s>ad0>1l!ʴߘ]%9FN]"x]^=^fR$}@(9nY|vʦU!in;j;Du 8ai7qI8ͷ(^9BHu+N㬂E2QѦF57_E5M<lT7~ve]x.Pp3j.̐N{V=T05Ѩˏq Ŧ/BΕż,AX76Y$ت1 !\B Ŕ^Y.}xIt)k̆.i0(~ ׯ eV>/S8{O'vaL@ iCt4C`,;<4I1xaJ=2'vW*k8`HUwJòao)fǺà3.*F|u|:.iC"&e؎bٮ\vǢ7f 1 &WČ.sh~`'#\18^NxA# +$wH# W-\ mdr[\ :38./O\m=NpߦTGJRt'M1! U(%8>lDD(. B'ͬ;7TG7ِL؄{uŕ&v(@۵lKݏ ]w5NBg| ;je7:'Oc sCJSucl#pDmckbrLޘ!9zcK,uՊoY@CclQk5^go7[kM^&vXO2zXz%lCb!,ш,4j0Ru޲sэQYDC1y>YğhH=-p:?E?g(%νHb QLX$yx2tMo[_'XzxjJUl o#dc Tj^ٓґN:}IŠj1:jD)D#%kfߍSj^۫׋ڋxg= vAHNƉIO%E`EKXpRGOI{ŢFW@D}e2/sgYD#[{I[E|<&sT$zgdݱ;.g>cvt[FLueס@HncƝin+q ^J8_.ʒh9կ5PLRɷӻJilQM94y@oؚ &vU1R}9_"Ďxw|_t \a4"f ,"sѮ Xs?ϒ$pOrݺ(b _κ 5hp ~)/QS-oREx" b5gez'>!g/_Z\&.w:*{YJNp X&k2\-G2`[vc .-c[bžwp\& :~%.Kɚhju!{%_;-?mfNv_~v+O c$Cmd9kOVAy1e_H3r+H_:ܳBd>,LaoVr0v5㦩,65?KeCaqҖs3 &sB>f $:/ 揌Bg~M晊?VRu]U ,RQLu+&ӊ:inL㯭'uwPK:6;p۝Qu'W&1#fcAgxWNG4B"p2֜YP3sI 5ypt9IEɬ'TV/4׷Pо#Ʉ5^uy)mW:ێ,oM dk}s}}(wn @V7cKd`fc3a}k sJBDN2ɢѦU/ #Xw:!X_'AN&MK%Zv}xo7ãxrz'/#)Vpg0], 2x*@>%7MZES!R#6=NJqv/͒xpO`~ɝ䄽0oQI _/|56qnJ"ˌ~zMn} $ֿ_.9*+j* \CUg%b)~G\H#FKT@l3}?<,0f`rV9`ԫy=Pd)p8燔c(`+.,ýYW$:!E(LgFTF$#8׈hʀ!r +b.{c@0KHl,V^2 z\3Aןdۃ~cP9g1V+g1 7U=='.G[Qa:DKgpǻ !EEdyRܑC Zv}sE47p?F/7sĔԿ8%ׁg?N$1@ rw׊µv5!2f%mFj x;?IvOްH;*\"Mhgz4)3*~1IQ"nKz6g3$|3C\gPGI:@AI(uhQ"-YuYL^$S11$8 v vf5&j-N/pЇj ZCsܛ ꕡ:fu*f,"5@`e06j}uC* ҙ#F6WNY3DZ{MC_w7>6]3Cr$t=?ZtP/*}-<uHײ# !:3vOoqSWWJ{Kζ{Jugf?K6oRG|]R UuAOeI40F\z7 7H7G.u˔,)Y(\ B( ŋ< M&l$MG~Th${2mKW㽒Cح6(ȏr`3#Myʴ^8 QJ'?9ZOIѧ5]ݘ=&Cn6:I[72Ф4hKhf΍a>#jTsu~ #rK/ݚ~zf";E6ގ!k,28S\K- ¨8!\B. v&Hcۆ:-'}YSx91@_1{!NL89p&:|O}2.` >ۮO8a=iA$NF4R3%C~N0轠XjEhm*/d_CudlH- t : 9+jgf r^AdߦBy@,DLVδ(wB~2}U._wNHК6֥atcu}WFʼo b dit@iD b4FZynU7F><NR|p.@R3(pSWvςJ5ƎEπZkF^ !-H: 2.~󮣜hYxfN;nEZ+mj2~GVwX))qhvWΫz,Oz85ff$ ebG8\,3ŗK#h2 'CERmKhT(.3%<G趲2qGm],< M Z Z7Xa!7 HIl%eqQ,S :?"{7{gjL<\jt7rXplI]M& '~ Ms`[\d!eJAXE%źP퀠/3U~Au$%o+Q!݄фڐ7f^.~hV ~w?y6LJ$Vwh <7CF;$Tᒷ+/~DVGKW_EXj1jx a3dZX#>bE_0 b;X2OjGLr^2c}}E2xD] ADwa㠁=⃭9_ޠѺ|icNywٰJ];ڐ& զ ~TBD6hQѽ1{o6!V?Mw԰D&ݡGZ RgT U+rY=[3I=k&Q[gfPNu\GVʚ[".kFkg'|OZq#ö pn2eSMѰNt=~C {ݵ 2H/t$B*4}*#<^zb_ 'Rڲ㋧*' _?,P@:s|% )SJ.d *Õ7jp_MR0=1_&滊MvEO~J!O*{jgbYyBxZy͙1 `knXbIt̼+E2V}J#b'ؤGhw/<njD[?[9Eh':q'\_dt{ \Q/RY,\^GOvck#jF|ʺDX- 2ZK_+{Rr*ONj -Qca^`q]Hxw!x#AU>ؚWDJ FkK|{&S!%y:PuYY5 ?bTn+!GQ/z|9.'.) oi )ՋTdxaGѨ@5xV@vwÊ@/,siQ |R|/(M#>vO ƃbB4CsZ;EF}SN-\WiM-¸rKޘG|nl,(eC5/xUF(̹͒0'䡊T.Nw"^ЩV;@'FH DC G$L-MT+UU~EmI_ %gLXC&Tkބ`]Ą10ѡF }"V~,LC}=<%xUb7܆Y2se NAG6{5/; ƆIh;1Pui۹窄5C C!`SƌxqA5RfPC[J;{.7[xL}ZST2] tLʸlCslȅ?5at^.ԏ`!:D (v $Nyur$c}I? >F %u| tftqlCp#Ѕ~bu! -8r,%3I fTj͉M-'x#5z׃ᛉ Fn`'#%MxA x-w6 JYMU+a]8ɢ+$Q +b}7EXd暅 _5D}˺`{*Myt=F5 sфP[MԏR>/ޛ4_wDoK")  l$AT92I7xcKǼ5YJ( Xw3TeDOkzUSCCXn:ףT\)$,XPb U6d{ݵ+E(vj]@~8@ oYNp'?4]+o}R|6U+c^e;* -e3NMivF:3^³leKyTk_d{X.QHl Z}AEjqؿM,{P?Y Dh`ȅz2q&wf_%a3>SkEf p(5.*)[&D{@U!͗yڿ Jy@7 N.Ŝjpw,7`~_*О1%@O0FѲ8դ  6v!ӛ>c(R>]XTWEчxI Ha2|H:o Fq<܄)ٸ1}\:E9M S}fЊ, z(RD@7q(OЗ:QH~S+wRu+KfWD@%NQ%&^V§N^r uP5g}Vp'vjH)"{ Ň]T,4RN[Vzd@}b*v'\=)e5ک)L** <׮MmcN۾xT1bn>}[TKu^bŃWމ&HCXw HQ,a(.5i&cCfB\N|T:>u^ב> eG3466*{H4vR=P!MR0@WZ%q̻/җmGRϨN.y_(2hSYy{isRN9$Zr]}SQIp#"7aܐ˨%|wLTj#˶bI $ឋ\75^Rv.CqU"ʞ'6g9x*"Ih$fByGH@|[i9P[ =xCxaJ|[\zUكmboI384s6.O6rQ6=@J,ewuBd m=ۢLR=*`AمW 6a\y4TKzSԒǴ@szML2qjM['ן]QRukP Ωr;b61ڰ{t[ػ*kE[ n)Dx8kwB -X/ZŰ&!fZFhL}g9moe|eS ˴f7 ΪyyVkPsng;sR7sL{. kVR,~8RQݧe04Y Lqo}H  NUUg"'KGoLxr CuEjRr 񼃭oYhW*`HK]vR|9>9]C6>Iޗ&x_hX;5%rPB^/D6VlgR$y'f-!W.H;2,lr V(Z ӵ "u>CN56dW&q,9mi.5]&_}\*qUEmE=RqQAr\ŽM6_:\@Ou%ڢc* 7iFJ=?`@B{< `0#^}W3hQ+BFGTFL씔~y?(iC ۘ+3eɅn^(SNZ2'f wβR!UlyS.tӲ78m[O~|:qvpMGS7.~m2q3to}&cټrqAci 8?'^hjZ0攁'x3ME.lODmǴNTּUk21z2X96:3XF_8~(ǍIWOܧ0הHN<=;5J$Pڬ9A1}> ezzYaHtznxoqG ߥA)oc8Nƕ_b`!39XYtN\X1Q9uk6η^`}FK3TQUgYAؤ qK$0YO[ֱvA4{BĻ1o,Ad]/;{7I9oP/̃MrCU4:I.@[R>eh2vgIOߤ1wVL8,k9$J3pADBH?[ hLqz#onrHh ?Jf[m/#  n we O7t;tϸ Qu 损D_} "ޗXq3o萋8V. aveOjYP\Wݠzh+:R6v J&+:K :D(;0_S{^6z1>LS%"ۇfw\7ԝϸ]Q䭍Gμ~њ3`ڐC I=\g%[6׿V8%L_&+{"ok3h ׊Ê$W=4lX=Dhh_LqLOyފڼN}ǿ嚵%O<եxo8NJ_c{BvƩ%yw:?ٰ[CGqwGpM)xܵ_oP.2}=^|_V QWEXu_#lڄ±؛(.t\9W8 r`ԉZ1wğxNy}T'^}RIyeá:ώ3`Uut^lm\NRd6֦~p8dV_Z[2O4/> 0H|_@l 䉊N\4*`W 4_0FEy%rw! |j3FzYBlxӟ=cYT|I>)q"׽sD2>WGke̟`ƸO7Ehz --ݛowJ6GޫyژS&`p_kBaǸvo.cv˙(R2jzB<0G|6qVI$VqfW*%e-c&,n Q|Fr[ꪙ"Pt4Me&< +0ݢra6LQÊC v )7'b+8&PFxK^$#4 D}@IzYl QEsKZGch:VS? rg:yZHk]L]i{[@c'11$F?hv)= 2߼0wb܄V˺|'1y> w;Ÿ3v֘0Z0ms' %(kc@[T `|3GU9ΓHXAĭr#wx"e,pcĮvYgpd۔;&r[⪾pMhoPΎCG97' ۋfTVY[R[<YZz,t/˜Pw'~'xSWR4?3Yfs!N֋V@' R] $EҩPG2ͳ(FDT-TiZzuvոџ9z"d!vAunmOoE2EWhUf)3%5z:漷PM(Z"@CƦz:|DepBAa u{#lg<)ǜwF > Vj&b߷c|1xJ?Qڲ [S6kPA$]I1<_?b6 n/cKnuzbmv60龳R ON0<4ioJA3^WDfdZº(u1p r:9Lq*CI|'|UL0ַaJ_z4. q+) H̹lX㌿;I\"t)dnV]]B4&d7*3rcUlaMrjj 3OYlD=kq̚ ~Q&!5.2R-8I ݣ.TWzD Q52}0 ~O"耋T9Oh𶱀oe3t M)v[sCs,,WJ ~4ά^Y5]],(|)Mw[}j d?0^rU_tm/-?q7nO|`#\XUd Xu,V+s73oEE)61NJʴ ڝ ۳dg#?RrCveǢ8' *ߣ })݊6X t%$S>̳~MR${1nZ9,]KK8MgF<U7aucrZA8JOM{Y.4űI#>p?M:rљiDyp+Ib1W^#'z~=!xP DMX9/RYqܲ[q@? ؃=^v])+av[Rv=24>0-`^VcГ쨑Mҳ١z\zGOL7A_]Mg?񶄷)KRm;C;ZB~A.Qp=\b>:rMEUmhcbщBsD7EW:( W`Rvw NFN[iߦ3gAe}j0< u6FAkV  dʩ@/׭> %J\Ϫ%pv %1 g_s,tW|u$QR h"fK|5{XE kΏ`Tf!erx&Y~k|(+9.yPtY>@))eiGJ'B e}:*ч%6<y/WXu7A4ԛnE~VƜ6 !#&]1G4h|ĐѡU)\?yX\{[Q)!ǾaB[tuVH W%;O;Mq5Ѽ5Aw]]&qJ[p1W'i EԮί,fJFHoKjg"(x6pW,@? ȶ c?Csi$pSaiJi@D_qŠz.mR8TIg Ѹ;2N;^&Am=^lM&F ׎TCrxsvNaOuv+ɘP`v_{2Ω.ݜػ򸇻N+6G0O,+N[ qadwT&gkv1._8 spmR8$ J_6:kSY.ڱPlj;{ǴѼKGYTHl3}r:-N51\]4ۓiZoe>8I^J}9L𮿕{ v5܄I#ѿHL 4fE5~%`auU fHH*/4GLŴ}AtbOѠR/%j{r NZ/MѡZFF.Bͪ,U}k6 4u?ax~.|w%/Jw9Q '__DCa6ESc?k+5¨ _e4RE FSUR?B&!]l7eddrg\ŵ k"ycdowp2k܎RL@E"Xʡ=v2m@^C2d,o1 ,Dmu_ab1Ҭ D%aw<B_~CInp"UE&;8 vW!lW?I/ TY sDëa!DuHC'jڔ;r!pel6Zh5cw'#|J8w#òixNޭscIu UF6:ݻ[! .jm U~M$qJ;M5}3@n29L$/NPJ+I>[UT1-:ltE)O-l2=l\4:W^U% ez/fTJf\k?1]ЕoV VւꟵsC̐i1PA'': p-:ԃr,OA`$YimJC1>EaXJ `ʨ2%tt<rpUns.N{%~Q?<kނmH'uKV> K[]ZI4lw]^~ͶH#= zMtp?l]{eLc"ߕEC# ª}4߄sMĸjGf`قk,`Ӆ|,E;\CQN!=ɅOqA))A{hiGQVo2?ܶ՘9_ziE2/(XX4# K%`JdQ4'Z2S'0K]_QºtJgR>P\.ddEN;QY830bTtK-e\[յκ dԀ_/썁h0+..ςbzۮ~E1UO瘴Ӝ4f]Zn>"Q`]~+쯫Bv2z@|jEvq3Swh\'ϯhDyxI̤:Tâ"eVu[5H#s Ce9V<]ߞep)/-Suy!a$A3EhH`]OCu3m/TL Z%yxp*H>&n 8SP8n\3Fz& )X> -3@V"$}2'ER ,6}&ֻ A0x;iZ+g_F۸L'_7fT`X4H % E[$ S@M/%,Ԇ7[4o~0Y]cz2M ̔qgIpw¢I5f=!Co2ftY-L/-FW[i3\1՗Np?C$;B.XWv0yyS@CS*]OZ>zڱ jF%z |b/wO-#jo #=Atr( ֱjHjX(o{I8 X}@n oߞVd?T2U񘾨ZFz9|`X3k `$uW0Z im1 *1/YfQɎꇎI9]trH|JE?VU'2/:=:wBXa23d^F/zR b_-J%g t!ibzǨ nڛ ]ԝ\S|SOܔ2h ԙ/2.b - )Vq׫ r͵/ɼsJZv]Z؋&ǞR]Hf]ڜց;g2V\.ĢA4Zbn6-Uxgg/{/7/Q^|"ǃ.&FKUYZγ{7p$E;,RDi<kWDs/M&;o([Dqڣ2g2AAae[xD0ͭU "K 1룶qtd(9@Wc:etYev魧~8Z!E-\ noxK ~WH)pk? Cibңp S#dxVx`_y8?a;"-{'ħHp2SDa $U1R"20G/"v.!gR>N|]`BG_[#9" @bqp;89r:ެr6}P 5qz5"J?b3\%xW'3Qrk5܍7<]{xW;\dA z$=nď"Mќ^2W L3N3%ã2{S$ѦbҝsfZtZ ݔ>]#/l.h0CUt[ѰIy!S ej7_9rS wcӋ7jڄj܂m|6Ƨ)YKJDB貣~B{jCLզ~^e䀂ϕ(;H-o澀D i&]tc)aŏO_c߉FeߪբmHlњMl2V'*hUM4`r[Y! PR1sOQ+rJ+F鐋yOx="f׬a oBb< p+~ +a)N ,xHY HLq x_Ɋ!e D\Gh+Uu*(>;[p{x5pEF;VM9Aϓi&~z,?mvڈ{as#Iw635UpJ'7JܻXϓg86E z4Q.|,ػrPa?/bZcZ`$8:q%%Gn{ " 36}7ݠ 3}%|/N^ B|&G @k+u ,cKLOB5{~P&|z ?Fޣ6dC$: 6=z;B|!L-+6𢩆}m Fʧͥa{WAp& WH-l|wWk-b_2T6/AP3oayNZT2v^#x+TV@촹ӗťr!Av7M&xwS5?^חH,3G3hDZpb M>|-SV^ m1R~}[ 5ZHgN?e8!Z+S.A2EzRBRW"ؿ57An678T.--V#Cor.QdFyj4Kۭ-aZ_@+NVdӻ<<č#4􊯊vY"zr H㶥.Hbwe*_2 w4fǞUnlKzV}A]޶p@!i+NJ?]6AH:G%kPrTԾڐPR\p"\w"3r 2 _aT)ǿM]Vat6pTeD% |w &BQh%%o[|r_^3á놄lk."̗ͤ3:uPE)U/fNu3$YU?'8yƼXZڑ3/vlpȎ<ע%@rc EF:gLQ0ф ͺৡ T(K'/c:Gڎt#Dy_>G|!!g"d5ZfGΖzpI="v"q_B D 4csD*ٱv`'ߚ:( b ڱI0"%tsz O>_c ^Y.4vl$ga8rA|ow9z%׋9>f {+b2FΕ7FʋLrgM#L!'! (T!&bӖ 1M۲KAI(W wNo?dwZ]j3z>O<".!8uO)3'ZvtSe%F10y3%ddcs5:ʼQhAxXR'9sKos/Z-Avpy;;1#kEC Qz_,^w~fע5BL9V x8,3`KY_z7Me3^U+ ϾUwx刖Ȍ5JA tqTe~"Zf|3} R굿yAϒVC$@Jz&Pb죦kNt C:Sʐv^CЏ%&r!_mJ~g%]Շ9_K25ѺЭ2a4@k7MI9.R0O|n_u)2Fhޜ$8"E[}t>f}RyudP{48+p AvmU.Uh?%%R 8ܚ Sz_'Dtq0˰c Zp`Ejss7F i(8vE<=dѺPĚ.Hۭ=>Z',&m$=}a3j6;- "Ls8_IOSqߑۜ{mLUD76Sf^|$lcTi|ji$!Jԅі5'cJS Uk>U'=\ Z4r $vIz3UԎ!X<+/t0ۏuRڂ97'!ހ-EWߏQ|zi-,[_3sdG -+Cku7=V J^ gMkҗ-QEss[]E|fr~`\qJ5lA˲Ȁ5 pbd @m޶{#NNH>Dw}lFɢF^eĞ䔗F苜#[l/t@%D\OwXx]=͔T}PPBp" Z;÷O~["XoVEŹ5cHbd8$Z@>祑sw~<x}gl%:S/wrĂ!Mβ;?51`'2$O7Y&WX2ښd?r&'`/yL(hv9oD3C'u@z+IA ns 'Ў%sS:d`o>O2,)izaD*$y]b&th0G|,3g + `xZ7KEQvTdbѰS[F&X2)hPtG(9WS,ST(AEطljpNQ']?΋d(~}[zg|3KYp>ն#&4 Gay&:, 7p3;wUOᕺ)/lTb6knIL1YĠsILoMj4 5BV=p!T x W]ǽKx$IxFCf7]'dd65C17΀/=/NXC@ߓpJ41Gqs* V&S 1דvު7Ffn݉h';{['D S./_1$UjO1sQf0KSH0AjriQ·!A*4GT3u YoؚS87dp>\51DPzXs BC=;_E@G"ZOyH02~Œ]Em`rCf\bk$)rV ^<;֍t+/!˃T:!2+1:I-d] `A"0S9BťXxHEt9wabixj$M0-ܵДek!5PBHed b Y KLWXL?4uٝWav y+޶ˎghv$0[ 1R]^4aZp,xtHW*: x69Y[:O-~z^qKEс~_;G.ʫt(է)<-Po{b42>'ޏWPt*x | <8u9SKʼnQӱߔrϚfm]Me @}T1E0`!a C$$wiUFX_v'x)c>uedZ!Dynz(+^lbVbקNR1s2YnIkbfT׏5Jn>q#wY%uI1msl&JY";}9\p*}@_~!<^_)2{sm@Ȗ'w'h>]܋ 1SBL%u#~#-7;S/XZ !ZA;J3WJ!>zH}B5E1U>;&S`3(C^t/'.h(فV5o{#2DєӵXh)bىBi$IFHd,JtAW%TܪQPRk2 Η O-dC &,sNr dhf. s񳲅tw%F}E|af?cZH-W [o#G[`Q^ +"Z$+TKIm]+$uv;f! kƉcDO劻r S)=-I*4$$lQ!/tMo;>z? :.o?xٌWtO7jeX\.Q =`2}=M}/=ur!l-ŵaږDFj85?~ hh (i=d Xf?_A ܾ0ǕߥW.z!/+R:}0sqSAp5?)˖M~=yehFX-D+o`Q;K4~-Zi@\Q٥GfW)j8 pKsQ@FQټ(Y촢<:nG{@,#]e2\~_pXc;{x~kJ>\md3C7% <1^ [3n^M(C -+1ϰD.>>H]9;t\`|\۶J!nc( q+r~tʚK;#6sp0hI ;:S~֗e 06y z!Ñ?tm4<%%O"K33Be+lπ Ħ? hSw&&-EǨ2jZ"6oଧ[_p:tCyS$tI@̭h}GVX!@BAkH)uw%\&+{xK)ȝwoTbyzO oF>|:=}T%" I(Pu"ڔpp,dxƕ|;VxN'`w0 cm"Gj?w  6gvTT:+4!uE}$.߆Ag9!oQ/k<b*hgl '`1+jfF}'f"䨲! {o%Yq(.iVjf KCӄ32 Nؓ?w]ץVd &۶4npfػK\RX~D z @l EXm HUMv$w!O^RDX``YoÏ|{?d}r(NO m!U iժ6nQ/W* sm\2Oao1;RWC,K cSHON\)] 2"XFOP4 V ԳD^+KXgHH*ut{hOGh%xkO9u`<.͌(ku5>"(a ي6%0# d&fZoʰV<}9JR oKlW_]/0RGuqC@iYJWcAB!{NUo:;c]rr0Ht1M&aOg 4#&2xo>)=pjWM`9ޝo,ġpg`ohAa$]+Vf{ؕx}<&.ZP=;& 1HOt ף}!Gf/d$H?_S쉘`xx#xcSY]2Y/DIBB*LF~SZl=/.NqM2n_11Q?;|j]d>Q W aD2v,ݻ䑽pRhRAp5MЧ6OЎ }C@|D r(zᮋ{oFax6IpYl=< j|Pocʳ?&F%u[C/ v͸F>hZ[;4^xu1b3 ]BFufW!gWMSJB.P8=8R\Jj&AnU0;yqsac0uI ad˦N4^K:m{&/A'S;c!@_ɞk^c-OӐ Lae2P|$ I,\z:*y@`5P7fJͿC,Q1*i ^q=${J \ [;U`$ujОfet6cU~{e k5|!ZџOu3j LskCcxz Mb N)` 7V 1xA O;X= jMDIFGWfw'5G)2a{C\9A!ݒ)B<xmY2zVv@)B/Z6lL AzlJF'x. lTY6*7z)XEyi6^v W2M3m4N\e*>$(Uذ C1m'Sq;(ek:ϾVL-oF|H&Z{), !N6\j 4!\3}Sy ͺ|4Xܜݐ( Dāz𥧻F\'1ԍmn;~r.H3qJZ+x_ʹ@)}.W<ʨZ?ZO_Xp3'lWOe !}̉fGqp뿱ʐRNF*q_ 0B 4cLnpIY:`CKŻF4hL^SYfؤbg$Xahykc:JOZ u06]mLM9%E|HfM!IŸh:uI-ވ t2O{TZ ErwuwcN$r Ft1Z S{ݦdWe/}T׹]RioyЃ@ at!:# rؘ4 I`%+9U}J]}`#=ݎuTU1X:O)ڰ+ǐ rK!O7v7Nir1FN]6hlõ 0tj?캳=)wϯށ evr۟#ä'T8Ibfg+Wkx8sԝr,/Bz?EJǧAS>A7#Fx Gr1f;0K\V= J}Nco#g%ez͆GgΞX@7Dx y AIn*g49^͈WΑO; fBr@?p~."dGߔ;vRuY6vPD$bߗ>7[L \R~kj y)yq@*22σW1[Vc9Hk<bźrXwFk?=yW! }ً42Ïg!osgfz#ysnL4KF{iT(I UtRIc&R %*8>aZVPJ+Sp[Z1PQkZo0gV~L'Pk&-PjotK>3O<pU;Q qeƔ@f^SXL~h?Q 痃~ R, jT̺]ٞJN@:Fu)&MΫCg:-zN╼sR ܪ`]eDS 4<84'5C}b깇‘3Cʐ3,DF-`p xJpEtwE /N2(#gC%НTs׹aM88o>UXt"co-s1tb̾[ Gݔ 3z <ށ^ V:rŲ$MƷE1Q=VЉO֍_v!Cb(Cc=FL^ס`Lג7˂sZ"*M`L?UJ_Rbdc_ѻ%:uݹEg:zW(?Fޯ@~ryɀDz05}@H[:b JZ Vʐ=P\U#%V٠)DkG{i@Zb?eu'ZѹGtI4jaU~yQK;h B[T]?S&3ӱa%mJ!kTjQBw{T23\CCBzqq"d'5rEPGk䔫xItiFıG r+1 1LfId5'n2+Blܘh^ytu }H(jHEÂgQ@3YEA=pḢNFLEY9aR2{G?7VnW\G≛7kn*`1y]cRvkX[UU z/b_&GVh8ыC\-ak肑jWttq&l2_;0s筓Xzt'3 L:}c~7C5y&AsID8&$(t'.$ `S9R9ҙM(_[ cL _y ߌD{EͩR(0?`fxm^.\Y~Bn`U76&O]}b.lKK(=NDATxy>pKp^w Nr#+ fvL|!KDSd=Ӧ\au:\SX`UHBGub 2wC5#ҩ[vL๶!iuBABeX5({`0|;ף6SלּTkg剋d!>(_ۛwצi3|lq48adwdڛlkF.:Wgxӫds诖E&p'6h8ţ3K0ޯk2Caj.r@0hVKdq4bNPYUǷ*u$s؍3crҋb٫5ǘe!S^Cd_J-,D@ie#&3 fAĉiUaOhط$FBt颥J%3\}+bQ{˜cuiZN'[{'h[/EL H>ܡ1U?j^6^7HR) Җz_ĒQy 0⥪$S)X,IfXqu?@aܛ#ft_ w;`4d. 39Zch5-Kh?ԁ}t=nTs͖T {nexR9!x?Y3\duB=3rۚƒZrTO X3ǥ랢I{H[.=82vc+2@Ύ?y'sC&s-T=1jdqBQb6@/XluHYEo\2V:3 EdRd\rTm| CYd?VgYo/sQ` \b3FJF:>Is8VyƱy'"^[$/ $V r43O(GXR|Lf KɩBT{})2Ph*_$$Z5M#8?\_Q9e"vM.8|!WΧae+/@zD)p˷aaHO= \|Ja& LUlRCݕ=9jP6AM&HÖkl$kJ-ّȿF܃$&&L7"ػ?(D+KzK)_A6LvXAeX dmN.׌3_ AB x' 3Ir# cZ8T!2IP4:*K<Љ/|(wcihA,]Ok!/vBnA9J מ' ϡ":xG54= }f {}!4qDkЩ 2řLXP^LaC 0řN1+]Wa_YI=B6.h7?Ix@{i~O肕&{_~C C.]5zu!ݝJÔV+jfK๑D@+Q)\vޖZ&73kߩ8BPzpHV':}l n wEko[nAroD3q޿Gr+0y.hk1qH0JڪW`6㡋xՆZ佒Cae|aض{|iDz鶞Ze&]QL|f?e Q7RvA_jk3YleTl`I 勈:."]:Yh Ǘ$,N>w P Fğ^?`g9 #4^h!cJF5Jd֕L M!{'c$sʬ) zқI6ʓ|K:-jЗeZ4IZԩj#?ܟj{.4a FRQh,`^Qma⥘ 1@!m2 (Uv%0/tn!6}4׸rtYc3 7>qCn*]9_`\@r+KD8=ݱo,U`řm$/OT ?zESAMSBQNQ+Rx!LI>{5$]4_K$ALXaiQȸ~GDfZ瑖Ve8be=d/g 12; kn1cҫt ^IB Q}U(k:hdWHu_ mgX?jjhYx;d 7Q.  8M,z87\ nhˮ:heĹdaal gv;bPA]'QXG (X,~bxG~YHqRv2s}JP. WGI;ٜXFM1Zi3-g(GӃp$hEv1G94ABJ=Gȍvm$b~"J*C \cjL'EҫN`i'螡 s4$ MN R#꩚4U14>!nf^L>"kM,oo1-%KT(+znYKVD_BdOp c co5Fjޝʹ^ΫB;+HGv{`w7HEYΗ\{z)N6nC Ip!4gX`0ЖApB^C,@S,Oضr| di2Þ'+/c{+kľax@hyBŀVjOk1,bm<[.w=_{g.ĩRJlP{B49'K:^͇mY/nOǿ7I׋#@5Lav4*?ީ|tZEA2J>I4P6Cqɛij%]̲H]7Q.'Md@ԭ\)ԝGGL -˺~s}QgX˛3dq\O(oۋ6%i4T_&>1xb G*s,^D+F'5=`5" W枣 <ٯ\u-Tag0<:(ͳ`d$é\m᳴Ef #?s#\SG?֡f%[ܴp~K+06tҩt~B')ަ A]jgރك3Z6mLyR81 3U F= >Rfy #^r3G˽`_WtG >/"TrZn;V̮Jkh&1] Tw"Hi\zkX|Ig1g0?qPCZaGd>E'y4u&e[ã|hq#ТmE"Q- C6@q ~1K]D# L9א l5ޓu= 8@${΀Sju6$y९F;-FPk@o퇯y8Rs,f`dH"g.`ҬD`):bbP!0=ث تgI xtE..ZL4%v=b/M 4(vۨL߇QF6NLT3wY7q oE& xS%lhu3kA~YV1Y-k 3)ȡBwdW)aUҦGveV"^x:u_M:RU$өRđ$-Kf'[t hX*y`y00<zHWmH2fWE+Ap[_w{z QxnSF>dĂ~0]IĿ} ҼFIۿ|/ITK{H'^ՒRN8 Y"=qc=қ90 `^\m{iO{`Ph瀬T_wZ"*O)dԀPЭ&ǯ6a$0?I%Qh:K"$P{$\x[4𐅾5xH2E6J SR灢l.m {x 9Z_ImU =ER ƗM P ibf_FUզkMn'EG u{:3n>jgq !x9ؐ?n6uP,f;i?]S؆Hi0TEpؼOmgG0L74 #K$z&ELu";5:zGMԫ 0o6];.TY>Wgokи5QDU{WN@F^rc@d}[YMEv) %%ZC5*O$!xIwC5Rl~ݺNzZ9`קsBξؕ D`_{wcN+4'+q`0? mxa l\k 2 iO"E7Hښ"Ļȱ[bKTu{^hcs̻P9E Ĭ(#VLqwev.˦7J5C6%Xz{g0AAüct2XG)v:s F"*f=jp!gLgTP4+I'gl?xNLA`9-FV=q~ggbh&ICi~᳡01KxM8#0!v7e|J44^n`%C/*ɮ|,Ѭ]vjɆ< ys(eS;( 5C `>Tن$)[U=-A}&T[] h|ba mSY‡AhԬB @DU ^8cqp,!C3:"8_H9ƈ,g%7qmXyEX| >A/OP_xꁛ=PYHϖv :¬u]2}O4x5sP[xc6R˱zUe(/;J"E$=K{([iLOb1N>+g1DK#E8O}voq6T=}llX59=_;v7N u'>g$+)Z ^ V Svt6|qңvX]sɒ)Ȩ=V} \U]^=x^Bٟy>ۖ%9nU;J)X;H)iCF% / Wr$Pm~v0~<3iʗ8P~ZpшrvۡhFb&\-R k2"^OhP:.3\jdk*e"SpƤI+twĐd뛗-j:@%f_!=Ch7WI] 3$X&gwy ymǻZ9?J}MmqZmllFu *JөÂZiRP^~$H$3u%A7~K }G|-jH4C?DiU"uHC|݊%va42Vn3rSV+NA9V3Q-zO^p:" pw06s5rEo^O FSwT@ njy?KCW.9^]$c'SO)Fs<3K3_21|MlQ2V%E$d~/SuXsN%~!66h*]ٶ8OM*:;;" yVsH~u{(ۤ< `rSx9_f4VވzAiFy׌,'CZ-O9/~Y4,:ѲqZm?H:9Ğ2*G3z%/ega;~x̋!&J,tW>ҡ{697?0$0cs{e^f)a0-a =LDuF$}K⇽pAEXk "A'왛*B3g4VWHu"P7Ɏ9[*sش2}W3]YHwAh'moK1}\BJHg'TLCd!;l[륖*Tdj>릉05W,vܣ?J K駏Hzrʙ )Ou;yp~L28ܬӓ?To#gXxcErX5D$>"C0h!Co_꾹jJKh# [4"9v؈@`NPe9[䏆ɚ-w5f Y>J;'BXaWԡ{ֈg J}ػdڈ&Lέ -סeU@`/hՓo>UֹtY(@h~zBWqoVF,EZ(4G@q_H"Mw>*^r2zc1P;6dQlׄq #M[(%sЪ4hJYJ^1ׁ*zP DU (- ʟ]t٩~T1!5f 43!Hҁ }C qvY\~ڦ|tZ9U};YtaGw1SZ1g\ ή\Kg1M^;w lTV ˢ"tPͅ!0]D'·Uݡo<-%X^IoZh^V !t??i |@H8VCsB$7F9m7B4^;6n(.3;bW>kr{KlUCRdv8uwE{>#iDt<}xZQx\*;[5[#xhc-y~AM+;K(,^M d}"v?uqYQ- 6TBY o';wM4\کUW"00~`" e;Zrkn=Vcy1/RtY>~ oӪ Z3 L!783q<#CxA+S'u6jk{H}hTY+kL"Y|Jǁho[O/hK4O=J畇;T8 a=Fb-_܇"Ń/$;<6.Vtv3-;Fh0d?ʄc*\rNU22Q9cxj}4ҎomaߚMJ6%ypHmP΃cwn?9N-Ę"Nb hRcoUS| }h/eyd3Úiuy:-coX?+QsK:+OYFo9r.pc NLCr@p_1ve/AhO.һ%PU~a%I)o_ oCko$r1_ T7쥣܎G)@}GgIʣLЃ#kL,7*(4|̅ T 'Dcbq!z}{N,.jLT)i(*479v`p=h@9%as_gyI$(5Sjy+VP?|q+jgxbX`=Ziu P`k%2%+a[*!EE4egn &ɫw TsV_/֓k=ɾ#a^wIivm9%Rc໋\"E>uɞ,MSh}wwcxruv҃dó{TuP=wE6~_Y7S܏MG/c-Bl,6 }DVU06#՘8r)R}c]9'CCuCKm& ϙ8CM%~;S?o_O{'vv `H75 iC-0ʔ3F ^vg< z1J0Z=X" c8YRU k{$nj躓}dc8+]9j%LuJj >Ab?%31,5x!~cge1 e%@|UZ#}&a <'zLN?RCOᄇU)Urpw Z1ݦlqQd2f[9*ʢ1*G*Lp> O-뉀`c^1!f8o ]*} (vcݓ$,bJobn @Ƶ]̋K zjkTײ;m{sV_[6U/ eƎSX n/mUZh R#\KK4 ƩԬRV|ߜѻ DFBUUPlWW9vpLX @_%Mr@y?ɦS_ܜ``[y*GYhrJPC=4LCj\uʘXz~|PCy/^%-BkM_A;xQrs}~6DbHvS:Vf-ЦUvv8w^CYd*{,'qX[{LC)Pp}FmVA}d;e_/ARoF8vTJgJ?'d&6@fj15 3w󨑥=siz!|}lb6G2X.LgJ.!"FP Oywklj\֑xq>FfCx)Wc鏓3T 0ps~r0IɁ-#Bg//2e^#LW;Ғٓ{_q;UƔ]$+ p6!n'ʩ R =<Ӳ/YU_̡'xK[ovNn_}*% ` oQ_ڎI/?J{Y` 0 w.6È.6`:J$νo7^ 0SW<*⟁&GG켁Frxl$?`|)^ bAS!J%I#ڽh2f2[JeFvU+4ɣIn~A졜V΢Gbwhx/d9D/K ͔ +sƆ2ٸK 6@PB *O5rGE&CP؃ |׽>w ~ HYmO). gl46˯ )!~Iצ"􋑭*AumF.o}G%mcn-I95SƘ@hhY x]Н'`#(f!N[yb˙y&L@!bʹU4 Kdc,] _,5=K" 7hbݞRZjQS&Y8օQ>&h L 7}%Fpӊ WB/BVYϜUT4GEku VKt׆XPh m \EMPvӞrd7h>e-r3KmqfQbWО&qKm҈N *XaUy(ryWcFӮķCtSo䜐"+$ ..(4m#Gԅ*ܴUwgt'?ut'Qܺ=׸//)ʸ"寧Ceu=, aomg0w#x.ɽzȋ(M{~q{X8rPݠVO:=&QP: wוm)8ۂ o20Rt͟VIwwf b5W=>Sc(V3Tؗ]e3e9Eñ,pHΤ(-a?[Sg/#-܁NCݳ04]v=huve䝿x>'\-R *4NL-k}we!j/,3:RߝD\ `Д & 8uqtiyCjc.Vm~Z$Rm?IAKԫF ӧ5ȭXʰ/ Tc?MÂ-Ymol`NrSnQF,b&@4<B^9=w'] ϼ{L\2+;뵳E!Ƭl=)G@} d(Pk@OJOV=wSZiFr3,1-iVM+Wp-|Թ`fBBm-w]fss^*}?F18xWi9žQD>3DM? ?][PB 7O7]~s{5KcS\7 ru"\Y[7 9=CCX}eHv<RAnZ4cv}Ispkg${j\EzH(f}m74Ea!G4qnD$R24+@ [b' u5M 3-,*G6xF(K}&~-?qk@2z _1(!79ct϶qXY|>Kblv{NPK:.DAS?Ԭd1" ]|z7_9_q] K)PEo,\ʭ~H?,\2[BkE"97 >M<5r_T?%x-^Y'4\Sۦ^^Ժ58*:RGIsނ*@q y R\1A1OT'~p7|E/3킅ib9CdV(*1)\4)½QgJۨq(!U=?EL=UwDK#qIen)O_Ժ{lQ檏zfJ̨b<Ec"`)L* ErzcВiDtTb<IZHALAؗvHr-eK֖0+r9[U,]C) *xWG1YX\6¶9S_CYD=ӅT~^-CdW2о%>MM4s$ ^stW׀Q( Ê2JG}-ѷ,d7 WPKI@|&s}4qv_9|ѫ#T{Qjz,8+1XkcH]S'6E Xe_h -8KMKJ9IÂfbSC:{Aeh{,'&$s2ʗT(/m|_^E9;ؽ\寈6irE){iDq@;3.j~7F+ whMx%*i0[۬x,hTW+Q(8ʭjZ[$0*R!X܏ uOimԥ׸&;xkl?M608M6==ճ, |8).-`hze.98E$T!c(vo6` \ºS&P2C%m)M/GnWpv8:(`}'Umyёu/'L=\J.g:hV%r*^xC6XpGYϻ&=^,yb|}"P3@:_y*V̒+lst4S]x9w-zMĕz”Yi~ Db6Q\E &a]2`*O:WY1)Q r٦e!G"#.Q"ƷK+,- %/G tBв"q/a#BzAV \T끚SfӅE+ԣ0(/:?2y)KQh7chʶ 1/;}; ? BwSN6瓜'E.0)ʪ&Q"/MɚbPFo~051jZ9Wݵ.aWk l9>U\@@N0?="> "鸅<F)+c+qx[B$?!k_F0\c%m &o&`j"X֕k:|穥"xvO#$P52)q|ЪuU>ڊMN 6+ٺ!jeˁ,AkE/Ljg{_.M톦\hHg7~ty-7+Ra0:9&!Ѯ)~i83_g2 zʗw ,UwZ"$Ntˆ+cf/y»=MY  1G-M 9k#JN1 ɯI.y.veHQ0ƛf:Ut"+MEB']L`%E4\`q;_Y/.:eD m`a΁WO׷|=s2U\.fl XbJwHVxGS>+UP>\1;ȦQS|+Bz}YzxFvb[* ҂LS|>PHtPiUK}8FGrHCWvºTl@׵X+Wވ7qgSGôIO H :c=L0cpx=):r%ЄZ"&/쏎ޯa5QL4po RRD"as_S8Z|c(|9 {ߺAHeg\6˃F;~"֔ 6]ytc-?-pV,P @]N ]^8[nKt#kOQt8[ץ>A'^*{p{p!H"pCz:xJ3r@7Q1f0>J\9a5N=ta@|LFVB[,'>":V|^ZRִLW$ՋlRY`{L4苴Ѣ2Q下n:s0IĤ_1S䘲(#"U79xGt5@KeH <HF;ZkOG2br;vO1rqCH?<K.joSFoe1_Ga3 ' W0ژMҽ-!Zï5%CWuxZ.Rf6*|j !zk#C213Z" & !@fҭE3V3Q29Jx79ʵ`hJ9c.ҩ/5`}"F#3]WP†щ"R"XBSE\b"MZb WAJךLIm̳ =먠-M Us4i誢0eӯ$0Oŧ= } &e(T?#(4KCO90WU5FZXX~:ƦG 6 !lvZF]֕AC? ]bPM֟h \+mL#Y;X Z_oHq?OeRd2^6SX{'q]2;?hZo)FMX.p:-h/֕ȷVb':2?MO%DmiTc@2]cFt'Y?Sd 4t]gx]'־f*=#DCB+==>xd-1gw6QۊVnS<4!Cr&-ns YZ=%oJF*AX=? J@I jQsRfB+Ca*sgs0B<H!o)E{!'J BnΗ]5ϕY2 ٮ(r4w-e (Gf~8s("bH26jN~{3%u*.s&gQNxDm(H"ܻC V7s4`i ::E*#(\hxhC138۠dJx,fE| F1LI2QVXrPY}UGtQk%9u?J[B׺\10Sxcq0mŠ6)8[ Xʈc'g2aw+7VV-l'aX&0̏SR?uc0O$~6볖ZƬ於$B%C ,\:*C8ƱI4ti>JqiU+I(ոBR Q^1ZAL¾Q2DHVMRf%{4m/v3<=f6NZ  [h 念l8Jgf9;!RDr&{FԄ#=@Y P]؊?L*r)E7PYvqn)&U32<Ǝ(3A1؏N>Q,˦nR'"M.6Q͐E D 7Q@7!Rh dʟDe}^YܳYSg`{C0N"-=z\c &QE$y^hJ Ska(q\qULOVrN_Ze8x*:czԐW3ɅyxB}aYǙ]OSWol;xkrL@{ \Yd2r[a jʬ)*5ߔBE64 ŽwxgÃ2_>:3ۛ#*Qxmw~X žlu۟vzcslZ+'}iRfOhlqfD`c!ϩVØҋ+6 RǸR'm zf2I٢LoiSN rRD&KxBp ¼@ wy̴J[':EokCƨv rf]L{FUO5v?nÇy.6H{~Zyf*XH 1uRr!_[mC5-L͚46#/HsyWFjeja"i0(.$*omBxdZ#)ًO,Jœ7 jJ:YPC" X\/MI褥=rZ|eZvl}1oluy|.P?*f ((\ Eg)d 9ݍJ;X,jKhE B[ %ȔPsa&@:y)_6:RE}\zDBߢ; Xڲ/!|S%S懶]2NhV˟~\Gw$Yоy`9Z+͖rBK@qō}iMhɀ9]DC>r|kz?c^pkw tby0 RlhK:UN)0kGq<@=L.xQcCn[ P4\0'zHҹ(-d%Y3=(cR~WPW Jv*hhlz2JdDgT;@<3 u뤶KYc 9*韩k8H^s r[1)GgPbmp7VJs=ƢTDZM5mĥ:$ЛOkV!+_I Q?HxPC8,*k7 `T*G99M ᩬf nl A[ |sy񒎯Ü׀Tk9`uJ~WB5!hFܝI#H{ |G-Xw/a+L7CsA\d2;=uN0 Ǵ)}\=)XidIA* \YyQSj֮7{9Z~]¥b'ͻ@Ò7խ:^ODQGpvV#! QUܕE_Ne0.]5;t\PRm$]I6da›8muhL-}k?2xDrKHD&}GL>fV `ڴ Lͮ{͑\ރMu[$IϑUg@ F9gMg 'lbL<'0rn5y3 6se-iVTGE$DFqS:XȶrhTQOF?7[^szˊ9@04V(_I3#,t!y1ZMz(!@c0+v 4B_ʗs~kZU9gT.L/6(.PLq4tlc t%wD#vgׯFb$|ɂ-y5Um^j'i~u5cD-%.ԐV4f܎N a-D_ЫO(z1e{ށfR.*ʨ ٰ|LoL)[ȗ{(h2:]?v{qno,w{8&~%,)UϽ̐[h#irԮQՋ!;1ߢ*Kzԋ^Cy4&^?Ht D>uи7|~^&ͼ%8lkGQY! ZNVRxkA+NnjA<:dYf}ty*~+ƚj[Z JU 1_ڎZx4){Tn ‰?XHkny у]]7܃|WqF maQw79=5U߼cAABkCeA}}:vNUH2a'JP/̯7__e7fx@Ә􉽰h7aub~ !E"z "Ǟq ߤ`+C9h6]Ֆuy+#%~3xGjI"1YO9@khP@Uܡ$~ HF@"2jl1Z#}qy0QqS/Y{ vO.0H&VA#hZ,T>5 kO]'ox]Nkgkչ6|ύ [j-D;]tY;C(iG:~t\T9y">(P>FFHɌw^2&.DH5c,#Ciw!wJFP{a2O cq!LFa2b^ &*ԴtG48zPk@q{9I z~ާNu.wa-hAGT [^N46;KG5ed:(8=KUBmlͱq^(ŵc')jXt,xHFyfl?p-Fz˳bKKXDLJO-FծC̗L¾P7a7A P|9X PЁ-?yb#:UZt;!e>;dbx7նFnhRR@<Zu @rf[0]ߴL3PـC2{ j/ڞΓUu'x]JktdA@pU;aJ3Ǎ/g! ?f* ߲)Mh2\_fW/Dko[L)]Ve6՝\zծȲvC ^[dݜ`f,kWW AAD<?̟\FL*3S c ]eTZ<Y9_Գ)Pov].Jܫ oK |˭(r)hfn-aPP/.SW8\}pS G&|\GҘh~1{9K!9>0 Ilk8!adYӱC\dbgQi93\xY}>9@'3C>m{X) Hۙko N:HH.&R&ۆ3l&_p[Ⱦ\jzO #}JTbSdh0i<7._qIXsYgXw-UCW19'kYc[hBsMwaquup$l%$?SLl_5tr*NԘs5>^ y 1^dש䕷T:FB'T{09+csm%E H4 &;m}hW?(p+_"RYr6ﰾ~ʩ`<|$U=*Ui7ޛ꼌]7 tdsI9?1^jaA߄KUiNhOj99B5}8/v>K%:FN#bc1 mZ=cSY$X!1KwvXAX#\ f }$=z 8\Svt6Jޛgk@0 ]`A%}:0pKxjBZCՈw2@y4viݜ-b.$a#_+c"Lbz-˩}MR+.%,%gx sMxe1[gč$x|`wQ6j903ť9] .^9#Zzb0_^4MI 1ldؕ׽i"}ֈzc=;6{3l3<ĉyS灉&/l5'D07 )g{bSW k`y/PSw%8ʇY3JL>L8)a`Kp.#ZOd 5ag6̥t (:ۣLP|jbmڪW9 n8IVjZX_d/?.1jۃ~OAt c, `u٬^\gp 8#D,]]'m՗c4TȐuxF%E >߆u 4(LMKw0%%65Q^}dZHV;D ,/#Fn݊&(BD=8$@hL%coeiP(Y.3ucxZFaxnQB8yHQwٔK9nzIa;Qĺ*B[; Sm~OAjj&gwd&A(&*X=ers e2,)|5_!wa-dd6Z}dWUSUX}>^,&`L1',rgz8Mr|̌ s7;j-M:=؝ ,~u}}ŀt.hGbA'0J |- e|_.lJ|MR~5QxԢDCl-/5ƧwW~H )p6ͤMUÆV 52ч}1wȋ}]lAC3ơ ɵzUdMj۠w,Ě?wsoa{+u?"N*DRV|ť(H]6~陫ņqrVKKYVi bJ 9thC߼ԳM=2?jz͏8IwJ} uk 0;>q -L£L] fm5t"_j=B<c[H+Cп~X .Y/5'hG{ CCBݡ28aevzRr!A&1^Ѓ\UѬuwzU"ltKwld2Kp7{ 'HbKs"\[Dм`{<^)كTqE m_ ^ϜwZz8@a3s1)6z632l1;dYx;ڽFpC5Nt2T[W99(*#4ZspĞVpA؄ A'6~Xolʪ@LKo5<; L곾Nhǹmp&u#imJ7AY_\wTȡSj/Ѝ38Q߾J.&x1u0ڋ摥s*wEKb&"em:V@ϴBLAij_~Zqv>ݟlp&eE\N$rUjߚUnu7'V{/deAkr# *oCØ3';$V" )|D?.bx̖Qdڢ'#Wb*݅d)n}c k YzCJݡe< z&>:,Qeܪ)[.ϳ al*al.QÅgFu@ l[LDH4Sxϖr"f.D'>o_pNN&c\3HUVOEm0]_Ck$DKZdRk6\R{~0)mI%Дwa^߭ ݏSmHr\Hgѿ ne24PoA%~ "\c${S )6Dڤj7I| 9mbFiDr8}˹+||A9ׁsms>ť~0HNEc8e.답w<>|tw=$M\NzbV_@HIkSZubJ)B1I51ܜDJXhir;P_C #]'""ϣOgXm$RGGbeL^ ϻJd[gRb_M+OwOBKd`vrzt8e ]pa |<1reQIqZ3=`O$-7ap'Ld;}~jx2=µ=`::X1hqrcjxB]tdqQ-+7j Ӗx4nICc<`=8#~4*\0" s~@X R{^i lCMv/kyaw"y @G+OQGV" b]MiZ Z{5Y\( g+n&9Q a-o:8),~A+~ dRlF\/ Y&tVJڜոnV(kH7CJjmӼh#)ᜂZJ!pUxT'p Oq<TtC/oetB-oz%Xa./!fxbu@tO6 {\QGuFa((o`<0䋆6y-)òOtvqjgwU sz;i sOl̬FtE?:5R(w9H[e+0f %iLs?PUq;jSStJSxJcո$}x@ r:S.Wn$`adDn+z`}/4klOI&eٟ^n0U[G :t`qf=K) k5Ĩ$i DצTMІ^7QAS-~]5mɺfeG;6s: l kԺ/d5)ȧgN1A C}\DgKnS664bRސqkvl4=GL:<2x a-r:+ oԬ&80$~~QZq%f4g{RB!lZ_pV(S. i' \DКljm{kߒQ)A`E].<%be/2+F׶{MkFyhzhSֶ1u%WݙYBɇAH1 ?< FD iC .rb貜=X/p8\ϩ3v?8S\ǖJb279z99J[ZOzfoS/ԍoh±{얠mZ2N@=<P$<@OGHVP0A/Nԥ-?? dZ%1&h'MIVȒ&vqĉj1{ %ץ)8} ^ 8V2՞bRwEa+&7-ԅTءiE3 BB5~J^^"ur%r!҆ˡ!>9 C.ئ(i2xQ'8\EFOe #( -`szX.'@}cNA42c_ڎ%`b1*bLN̝i]`K7V{jR3X*f*蕧\yߌz溤7R] ?PH\/"w?B ʽdj^ qIF#Y=j2N¦gNn(%u`UlxxL7J 9U 3(Fpjt&۠n>dOy[ApE/Mxd>J3G,-z("QZ>TutLD|4C"6fT:>{79-ww3c3TK 76Sً8=^1S",kb\3g|3%x:戯V0a"䕂v]#C蝛x*Q֐Y+5m|G ^#BBY; Xa?x 5]h?iBY; jcHOvbbT3%Jd[^4 lIϯ\ټrZ깑S&MA7gtRɊ#`bCQzީlw\U/ 8Or6^@Ah3LeJI\=wbIΧ&0;gܐ.ؐ;)JCE$tn-z~E۠}Ldv9'# ow=%|>2{|/蜹)3O3M|\,ӌWfUylp 0'XV~ڌ+ּb ,>|lӳ7?kՍ{ ]cahMSڌZ{ Y'=r4gl=ol25Lwr?X;[۠[27ӆ"5y&ow+B-±S'xdp(riAZ<OGx)4+q"z@~-;1 woXn^5p& hw lh ISJ`%Ғ:H"1mPIu#7i~5R[y ("ՓBsߌՏN4)34@N1a6ұ.hv#Byf8yk#4 =~/^[/(g+Tp( <VwĀ@fa @) 7Owi}ro^TU,=f=8akNB6F9@uc%+{5qC{8㹴g9=R|@5;eLa[thxNNBMZz֜=ZEFkjϰ!G@S7pbz;m_p5:i0sLwjp'x<y{7f9mq~|5meNIn+)0&"#>o@Deus0]hʪn-777;uEjn)&s,2Z4 ȅMv:sI7 _Do&_o1 +} ;2bnm9'1|QR=BW-|A2}9GdَuoQJk"!{)Y655&b^=TWLoz~U5$F9P!h|':n=I: ə<@!SR^q@*>F %%tVM /7yߘ]XMt ت HZz)` m;W~=T$|tQplU$i0|<`g7 "fǫVnŒH;9E͛uCQ4& g UO+du }!"mti2&B؉ qM:g!P3ϻD֜6ʁ45YJxږ/[̨#񔰕*)WIs0ǝs[oymsڗ h޳1BE378jBUU[0o4(BvfU[%zsBi5ǚt5^u|q̒,)"bS`i~uF->]ל1Rc3XF^tz],(!LDk#Q:Fn!YP, 5BbyQ|l))z&6o'eHK`4e2B}0{|b5>+R0SK001 WdVKXۏĪcWdڀo|GG@+G bnX-_nB/CmMUBhŸIeˊএj˻xov6WL8`V)ሹHmw0Ptq`[wuJ}y]MWfv-!?]MoAD7"ءdsY;\ŕ+ޗ\w ZfNF8z}1]lUbZM D;\\ՕcugPaňM9CT8)|(k.hɃ h8% 7%6*I#zh8;|r?Gy <}V(xa/fME&! S=>#0lݜfMS6.h K@L0w?~3/W=No&ǚڥӰ!Eg[Ӽh^pTh9B)r\y) zhv/ͺT9>4Cvx<)OmO"PR̚^.>P<#߶[!b̺d2_p rHno3LОfx>șf@KyvUmcr=zXMZ]ѽBCYKC%QC q8J!r+v`'ytȮ6ռ93p xXM,m$~K:L/Cts O5K&v̈Hc%܃MOXN鏰tfh|$zh#oux o4ᦝyvŜۈsʼ5bz_spK}k(4v&K-4DX1Kz,@))jEX5ڍl*Hfy ,Q1#yH6tuT l![ b/XZa=,GLr KߕQC{1B!ʉ! M:Δ')d/WC߹ $e-|0~K@qV25V3l|<]q-˒D#Yg]18`5,<\~JEȹ(uuGtMzp3hd5 }^'Fܠ6qE/-oFphdM4eWuȊlNw88z&bd!/B(:Icl38S<=R>b}{~8)X 0vIU3Q̈́j`+X؎Cq r{1>U֊ q ¼(EjZOX}+H2I rmnFE4|]wrPIɚ䶙w XWAoҤ>b[DB#l3R;N S# OIe[-57NjQ篟h[rF<3ueIt aBj2ǽE&1:d?]nsQRNFER*&K?jܯfT|jV|tG0lDI热^LuMF-ئf (3lvߑpmDYv\ Srпn"*8)eQٔRV|H#w<ĸD('.g_Ҍ.L,L~{KOߺx 1(&Ly|2ư )H`?(Vz{Uq:c JDvd-))+2!̪Bsj0U֒RԯÅ|bka۽ r}zK~t-_!6sNwr_ }Ւxzp3hM}Lɥ\17kMDT_ݵД(Ex˕(!s~8OqF6 cJo;l!Y`~&ksб?S_ΣvG":YzFz$Nf aca_}+ 4)x1Q;M.h4O\P6co"fո"5UKvuH@ؘ́ޜa)h:]zbxul^%rNKʅ `ЮZ.-umw(-g蒭%fH٪UمmNX=} w](Zޭa{-m| FDlr_Zc~@݈d 5Rx27~C<um e;DHxjnCWkѹso;U~_o\s*meB9$\mis^G,> )W 7 $+ ƍuwUPPS|K޿Ƚw06/ia^97Bb?K>ʹdcT{n; zQKg i\oCZ~ۺ%H]4 znjm\ Y' .PyӬ5h'3@#*J~u"5斋ඊdzXձv!< 猞AwģBd`ߐ }KEt$SK^:*bC~{S!h%]W ,m)~?hP2AXsECG|(C`Nc|߯AndѷA;(9cK:oY%f[aQ:#L@8j%CI|f^*NU:s+n/R-q.y/U6. Y~ /+0'֞c  yXat~SI~ͦ_ 'PŮ(lN1xbGF~TIGO~-$P ^xf^Ո[|SJ5^ 8kѠCCo&WS)Zjݟ?tIzxoA,vՙybnB?o8qO[!Qb>TB  QlTbc@quBo/fI1⛯ R@)p0>˫'!Cåj}7lhKH !b"'86VF*Q}k2 [xξ̱0 yTJm* ÀEpR!ϬJf^!^4UZ)_T5-g=挙Rf KuD8.&*c+Cb|]? :<9QІ/)bXG8>;ᶗ}Om{ք$EVύa@?ˍ'mI]C.^[1u`}"j 'ߺ+m9kNBq9$֯Т̴eyS726}a*er;nKMCvXNpJfʥ4ǎ1FFPԋ]e+6f+?_wֻ?v/25AXϊ` LU4dKye! uja*]C5tkOK#bE NMJf*UQcUMGKO]dA/%X3}xXpF Ʃ̆ay  ﱻԈ_{\Q#e/wc#|-:P1  g@Pfl;(#,ډ t\!,Q!$-@sre\#xVJu'd ($xJ`/IˆWMR|>Hy}sjKش-6I#b p u,t +<7᮲VgꞠ64{s }b _}T/aoweˁAk}skʾ< ?RdB~.;.>&mF,ɲ{6ƺ?,( y7u=2%eF[1zGJ1mHֶWo<7vUO/_ t}9+Bveo!Te3 (p.J\Ħ՚\`LW6=}fWgW NZߪf=oqP>>î<Ֆ#hVtI-_p2_FPA Drs4Zxa Cok\ˆrU{9m="\߂k]@ij% NeO@fG37( +-'R4Ã=f*)eɎ'&Q|l+>3cޑ0"9W,łlb$۴ Kwʥ>鿢 :m<@||^)p͈:-XƋA{ 5k*g@SX ds V3}Bv-0}}t!@8}e#6j)WS^ [>; 4ЈJDa'ՖvբCr%VWaq] n݌WIQW:bв/, Nml UrliO{j(dʆ_5Nsa`Ky킗'#_4ExoI!Em[ P];.̷GyMB'XڣxvĆ[ܗ1ɽ267+)]:F=J>KkǎGyZ +_ܚeb(zazfzi `7ڡhYm Ey鳋&QssV~SOF4&3@P( :v4/WE]$@}sXÊNW+*R[q*>H㭽<鞫C!fv`3i&a>nu,SDTػcx<*Iwp +ƐOk؋S *p5Cz$o {pE@#|o"oIB]GPQGCԢ2/PPJOq3d?DW+{N&9H@ׅ.UٙReLKɄ^tgdS3px=com`}:َuV>81bqc˓+ ̮Quk:9\Uj@[Kn/GѬ%y) ޴&{皌3/AAXUH`1[tؒџE@"w͍P-ҙ=0Xέc5ڄR( Y8i2FeEPœvY\M^=,U`pd.:5er 7j "~=f$ ѵ%ǠvlMwnѵA)$ň4¯(WZ׾, tѾ0_N\BJ"Jۢ?P$Q#k c"^f=\F˩I|3?_%/fӿ4ZSf*}֣$!rFhCz Tpݦ5**oΥ؜֙ÞO/@aL/+ fɐ)qY!Dh_5rgsbB~胍VTPj) ]Anm=keqMcDkZzGKJ(nFWWW