pki-ca-10.5.18-12.el7_9>t  DH`p`Sv$ƨd(MO IY^ ſ^R:Tʯ2GTrxh!a-{E*ĤHxf3ȗ^H kd~2:Hq>2:[O7^V 3Jb!=V O92+􂛚fI ,e6/MEƿŇOf9ALa.)Ŗ;+26k5qnWL0jW:œ5}bLd5}CZU=螳%NNlXu A$tr-c5>\1\2fGߎuRFa6ڝF=oy_ Uqox 韧3Odf[%Zܜ`G_%Dm=M2 RaZ bf StORw̳h 8IU*G9[6 2ZjN܏|y@pp(o15e03526a4a8f714a1831a77bdb789f3b3e732328`Sv$ƨe\a~=T)3'iK8¦Wp22=;ӂFORy=b|ӕ98`]E-xͽ4 KYQE;>\U[A2+b2Do0te.S! V6g(9"/֛U 6G-} hsK1*H%504KL;9o*W%^y!"5)(:D7$NSXfj)%;ܴ\ mjzr^RH_Ӟsm 9u> ߪKcNtk ^8KPZq>Q0}l&L͗)_0m5= =E|ף6)Ҥue߭Ɛ<Ado Mo΅#o*{02J:\N07p?`d   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P 9x : G,iHiItiXY\i]i^}bddeifllntiu,iv wixǸi\Cpki-ca10.5.1812.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.`Px86-02.bsys.centos.org%&,CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=ms+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤`P^2`P`P`P`Pm`P`P^2^2^2^2`Pf^2^2`Pf`Pf^2^2^2^2^2^2^2^2^2^2^2^2`Pf^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P`P^2^2^2^2^2^2`Pf^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Pf`Pf^2^2^2`Pf^2^2^2^2^2^2^2^2^2^2^2`Pf`Pf`Pf^2^2^2`Pf^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Pf^2^2^2`P^2`P`P`P^2^2`P^2^2^2`P`P`P`P`P`P`P`P`P^2^2`P^2`P^2^2^2^2^2^2^2`P^2^2`P^2^2^2^2^2^2^2`P^2^2^2^2^2^2`Pf^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Pf^2^2^2^2^2`P^2^2^2^2^2^2^2`P^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Pf^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`P^2^2^2^2`P^2^2^2^2^2^2^2`Pf^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ef1d1a14e507e74adf0bd100525c45eff61ecce2468a24a900a3fb1800526b15b8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-12.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-12.el7_93.0.4-14.6.0-14.0-15.2-14.11.3`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-12.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(0di$N!#47s8w~ _JVfLA Nyl,#;0]]Y\g?]K򮎳7>_z>: _LY:UJ<(vRX!boP˗voTزwu۠F/:BU׿jV 2p4=@rl] y(CÌ$K~+ΊD={߇ 91#zmK{ua958aR`^JG]IkS$`?ȻN>,x}RᗆJIx-hZ/ʡCn=ZcSϽBIrvځѐcO"%7/dxRdA򔟕wSeKp%F!%GTOYއzY8? L4Lfu*k$I.-|%كYgNnE$61S-+2 2(9)`m!k<BY#1|k<ծSoI=\ղ"2t FjUhZD^Atեt$V Rw^` DGF4߹< @5 WYa?bSkEr3%P4EbMRlMX2qbV9>I'aV ?QVrm $2ػjv2pSવ'gJz[6A2gtV|mx (8Ҷ]<|28v>6ww\h? [ vT]ۻH ]B֭`z9@ӏ`a ΋L49)骀 cnRxiY7s07kR̐)TP0[MJYP%SR$\9BwGOHT ܓG ^>~vX l \zo#6^ e~q͆OyZzukW7H6$ "7>XKs{\*Ȕ ff& 1(1/tANAKJžmuaǘc[j6'kADn^O~ԅ=MEGfH:^iԬǹX!@ :s%mGzao LRPG' [^<|짌G;3 b#]g^i:Fx4A|`)q#^'.eXKw\]:=5r`ݶ.TH(r>ZHJ|`L7zMUUQpHg2LK=jr#2v.9Y]o5W6%#ciòu~'D ~TP7ڴ|(?|'1ZbY4 en| HwϽH1TIu38:+bix . 'N׽Jpδ6b5V,p*JiB#3XAz]E Ⱥ/zCৣ?S,xU6Q&˙@/:^/H=i@}5_i%!lk`푑J[|RvC;K0gs8W۠: Pڹzc$:)8y\fqt)gd ~a]$4eufF@H(u ) 9?r3a/hq@j4t!6e lDEPkm>ml':q؟f`)$MRc8]lnyG#CkúZ"s )Ckȑ^E\p 5Ov̧ C촤ɓð\k|!rQ4]Q.y]Cp`4?)~!K+a2!};>.} eL}o^HZqFCO`WF]Y ۮ9lt[\2XVZ05af/IC]tD8=j`.% 2jDA![Ə} fb]*@m)/jYdKdy ۚ=M- k'aGe5[ibuQ-:mtHg#-NnĕXJ/ xiCs$Q[qgR!/7m~Fy$X)sS -y$&R9~|AYR>R/.ĶV~sܖZH~ XnKA#Ҽ/~ҬP_U2*j֦,h]\ʘfE4،2|MP x%D1dҰj'SW̐%?%ɪbYӮ.WYj5{߰p0JstnfR"/k(2l|\9PN/>b!4S~'Q_!VͣF& ,DA+M=ԺkC<GVgFIAq? 艔;RT (hj5+*it\c"ϕmUa1[ ޾ ^ StmօiJĠP&h*wp@[d,Zv֣v+RJ.Ɖ`6-р^cOUUhkUf~jA?ZhȺwcm!h~0Lɶ l>ys֖[ p@ᘻbk|x&U1l'X۴ɶq%fs-} a >3+* uG+Fv dj;^XIL}UŌk(&N=7ŚO9$FH5WtAy9d(qVaiqtyO&p~FA,rfrW<"ϖE rWFR.„Ҭ0?lb- tn#&GƸU$IՎx6qY`0')q[- Bx^Wv{Fi*3 1`Hu}>T$+- =\ψ6p>K/̈́Ҷ"|ʭ|q>f:OCRhX%{N|uXQI+"p?zl~!~g\A']&͋l Owd@S I40(՛V !&nkB%ggޢ9oޟ.CŞ&+QB9t5.P"o-KZscFԑJ$s4$l.9} | 瘡z;⩦y"?UmhU'%oƢGS.^I9FB]ͷGҰyjJܞӤu>ٛ.2SU9Fa ;~eRtRѲ]z+>ބ/H3l8 zwJA[ "Hh$̠HGц ,_>zu7mzWz qNjKpDs fUc3wjY`ǕR0ᔢ[Hojpj]z7-"n(]u_v^N~kh:(4X͠ 0Fl>>0A}Lȹ{bi:qC]ĩV!:A*j_u o{ k}4wa_UmnBJry|^4v_s۞u[[ NIAla0~{❖oˉʓٛCO/NYsl¶0&_dڌ6LAq5 a900`5w#`X|sA3 ]0`~>LMaѕA+ 2#,4{! j,ǣ)Vz8F,oD8A3PhwϿlVH+|uϓ@g'֔: s ꖿS7Pv.v򕿁8XQ9;ڜ 9~c@8$:DVaQda7X3MZ4fm7K˹68>;l 9"\h I:j6,aes~39dEHs8N:p\OEM T}`{PM*;lGekkB/O$+xڈ S˵|ˍ98YJ an9_@{'sXU '%=e(\2& y%mSNȤR78-F|WHg TFDkIjEbptZ_# aOyEXl>EL:LoysBW D3݌\`z;m!?,Y9I,mP/zs{*gXjRug_MDŽWۇLZ]"6QI[d$g&V=KIZݞ*Ll*L * |:mDĝ]Ŭee騯^y/x(M@Q9L@9^CJ^ۜIy^W7}bz<m@[B4ͯ|ہJYn@IPS;Nʩ"KdZ˃9LA3kxUKlRDutyXh2.;-f|1'q:,[?cTk =n VL E9<5&YD3u~y%.rbWXop,Rf]ǹf,ᑱzKteN0 c`-9ThFjJJs)NbKᙄϦ)\̣Gvjh \L8^(;=>M XBYMRoTaB'ߙFHN4xf ja/Iuu%vTWN,]Ns/@jrs~x2UN>gT" L,~r S#id:5E?PGhJظqhAhϽm:Qr sF 5M{Ą 5.4+ ]lGVپ83d Jo\*6uKmc})cJYIoNџbsr=}xD]L ?s}NRs6"*S4 R>SRD|s24i,ͤUTr)zQqdi{ܠ5T](|=.@WܳQF -4~'%f1!(o;羍1.I-X_4*`"v/K'v;, <߬ҧԠ z.po¡zDs@DŽ*?Oݰ<}DӤ24%X+"v 5?6"X?h@\&^R?~5kJ?XٯCl#;d<7] k__ʫzk؜{+:lv cӿK a5}kCL2.r,2:݅@YCiSPBȡJx`t1- 1n 1LgV{iYil y90 Uq7X) XD3m@~9O3XET4 ~½29zG=%*ˤKr8UVk+߹bxMQ&3DлpU( @w'Xp 7 d ("sw;2V7jKCfu0j.iY ȐFvY(سޚ.2)WJw. ,xd"qT  7!]Mˁ>;t9,qX_w~VKλN3ܥV [9i/z`b u2w4DOt2/mV]6Xf>"ֆfP]Hq5@P'^Qdd=n< 9?Kvija]b*OmII< T=&=1an73)>IAsv}l`fi^qA]yKgt]~m7!;R0H]~ߋ56[D1f*`:"' I6!= )$@\+qlzwwU}Xya7ye1@ ;\rZHu Bq~֑lʿFc67 kKݑPG-Q ;1;6x}AKl,ͬ3hmy1+ N+\66ns.9];QPnH3|LPkizu4rfEÿbsThcK:5?̦y\0:~ ˶jXƗVcq 2*hB"y _k1 )#O3$GBOaj5͑"vm u) =n ,^x/Wqr-kFQwYݜ͜Zkc o~qNY^HPLb@TwU"qb{/"fӷuF·^1b@.5>'NtoJ~Yt~pAɔy[Z4^` ۺuȮ׼0aEWe70ͽ$:W@o8[Kރ-pt+b"6d겓A0(Eq c$li"yAy#rG&=7zya`u%;4~iwuv_^YHy 6IhnO<"JR*%I/ʟ'k|ڐZg|ꆛ-ܻB3^¿KY0$*FGu2mJ'QP!9(`R~Łd)ټ$k@!gHe-1$!_8H?ngRAj^BSp^g`|6JrzR yS򒘕\/Kl)kRm՚G W02 px] Uҳ^uk|ԝ"R)%ԝs ӏc2S@./yIg!N踽 v k;glxM0`0kKrC Z}1?@-'iF >~k]0Q9 Qp31j=O;e\R).x YG)i=p}f'j :0duK9:jQ!z4v9PRJo l=[T7!"5ֽ^ͼ$m&?:o~ vcwOω?#쥠i߿r7PPxϡGuyG;8<9yiZ|Ԛ|>qd kvv+Bb{O%i{ ˮPm2ƷoO,ی;_|+fg{bgN@BF :uj#6gVm?1:f*hʴ9wٔ)%Ċ)"Hb (fمno3a䥗KvV|ⲵU.* 0S,Hr5u* 6QJkr $ <09B?lIlpAFЂ*#Мm,|pm?ȱ ڣkv(;KJPK#K!{,.N꾕R__랧qN0/K]f?iT#CJ+6amȉagDC]Ck"AgvLL7$s̲=4bQ5 * O 78.,ዐ-=ho#%ho9J4QX\n)\o!lE͹_jTV>֏'oPP@~pBm rMol{0IECizHH'5 ErN@$(Ac4Kp}.=ܺ3m&k+j{;b[oI2%H~>ʔLm;PkȖ|!5'J9^[358TOnwZOJW.oyW/b֜wUN3bp/з 3>=:a9%`A$=A ĭC./-g i.}#q}jIkb1@*!U\>4=ʀ9R={?)պhrNȏ*X>$NBFyo#cAP2g`5z Pq5`,=7CHP65DPTd6~ G VM4NI$ũxDY7X"&'hW5}eťECuZwR=!Qoýij P:yJ #`kr_;tSYTX Gm8//ԈEsg!xb "ְgOVITRkWQorQmtsW0Bn]ěl >X˷@8 ځۈET@j޲RMs@O!FtTaa +mh amъ7ڋhO!j:<" Py.fr <) (/n_PsG/Z0wfQg^CYTM -F`b}%{a7rFaL'>T6K"Ases (2ٿ;cܪ,8oc-.rXI=ԕqЌBjA >naG_9*+Lϓ-OSwr^/2Hiҡc5uHʧ/7u&mRV"l pg ݀۷9nx3fbp?F2s2:-*"0mv̈u>.T꺵ۋ#[**}u}vYZ_ R "azu6؉-¾ܚEP܅ %9IlI|Fl9 mBxn p84T|ۿqmLqHڍBmrOe[dy i {XaC#Hgf4sdѣ|\̡WQm-qVT!@ɂ.eGZJ)Qn?F> Z1[ ar4w*"X-8-A!_!WlURj'}B+Yh-2k(e :e=Rע )u3;3gqӛ{yCz)`3]U*g݃tC΃[C6܍n$s)iö$S faX4佻:ቲ yb{&qsW_y"vg ,6 E YCs*?'} _{H HIJJ|~x4%ڦ3[3tyS/j;B3Muk(-0ޢ/__pv'8RܘqG5i|h'RW<. CdwqWx2i40ahVǙ)_e1JHMSk!v?]iȩ w927T߮O[':C-t&[!٥X^m沥2WTDwOPs(ᾧVd2͸b{;lCBEx +kA+  BS|7D(80ODcz0GN{Il! }oԘm}/XAB:n%Dg}3g³C!x=ᴢYfE}Kҷ!"!2u5b*&VT  nQԓ$+l5 ߨ{ >;4.qu.j{bhP}*/Z;h-FI[86B| $'`hN4P;7W' !zh+!mC]0ju##Ru$ zT(X7WmL^.6mn&ywY6}e "Q۱f2l Bjm#B9+K/$410~5Hp[E_ iSTo8fqϾ~7hr3JvZ۪,!9F/YG[q6p1R2醿UxGIvpm'XuCY 6* {rF:`jrvsV# ǏTyCc<]度śR0I=_yC 7Ł[a1̉\&]v_0(#aRna끃:ѭT;N u+^O>S%W")fP а+vV,2F>}nTՎ Yҗ7mughRn hϵ1ѡ|L,EKfTBzN[ >"fPyNOlG${SN-/9vx9'P%b'=FB Ȍzz%v1EQ[_A!z\(TЬ}eVh,fzD9gѯCڢKVʏaj{X! c2lsuuCUn ɦsZF~C;S aw&^o"Q6o9i ũgm;pєM8!J6 60[-.L:RaU4 W,3CnԒLcH0iYFmٺ3Z&d#Ѭ[ 7zR RB]g߯6g~LA+f\"+trfqNZwG`*'hIcTg`XkpFR;X5z;eջ{ ]wًjaM&s+ wߚU?k8iqAS庱g4IQL}.졭:H_! AMMbnƸ1?ql+4StZDN$~J,h浯Q8܆r!ܬOdi3 Dͱ3AW9>]$pz\XjZdx2 V@H~~ *kGYNzd<dNho|}?C,- o8dZ6D!r[On5E3m,B4Dey#"-_$DB!i2ޒ̓pW'c!DESm(P-c𿙡hYJjmb4O\IX✞X[Bf?.7e?&ё ??fal16S:V3a!"]$(4b<cyxz^c^?yIp h$Q?mڕfUZuhpQ†,.]Cl$Hv&ٌz !i[#e9ؗZ%5C} 3/Gcc䜫Xj trDNor+ɗ-W}aQŏK鷒LT_zءA;Axp0!WK%u"k IhăxxKN#vYUyQI)ˋ4-֭RF؏ÿZEd1@-2M9Ɠ6:t"y(n^^c ʆ΄ԢT7% wr$Wyf*󺽮!Eci&I"j͋,_sU$iJaxG4~c[fH-2Fx[?>w@:FOn1Y^Lw~/s3>Xs\Po1p[~8VX!qڎe$i m6ZG۩| di!O ^|нf(4K8CfVlϢ=N׮'[I8o5e~2"՝݅#-};ui7V*t nR`m1]hy\/Z&#l&G b5/՝IGL?HH qrCݓJ6" sLr$ D9idmJlNc4*A]'o8Q{@dld+L@NJl~l6T@(1fIX?8 pOm ĒUV2LmeV յsb.z56.wX*mrP5CMX+k_X虴o:\ 5wN^,"yf|!}%,u6,a^RKn/jɧ\Sݦ8`lRJY,[QBg AO`^ gg;Xtvzuz|U}M"D_ϊl|l߫.BnA}A-C|@98zݥV ?쉡+7FG.s.-FN5R̾/_XQo NuIn@&Xkdτ3$r$6dP@L R<(&N59iBy8uL0L}y-=[I2\qqVqʖ{z玷But>T!W% +`4.:-0(y;,B`>$8AQ#QƴT=S5ԑ}SN OB#B z ޢR`׏3g^Ă[4yZ/R*:%@e)m<40#fY'M׬[7\G" P69`"p+WnTú&?lߺ"9PQ&ဋDvv{HClL[<;=x*9t|Ė̞m&Pת 0/L-^edRTyt+ 50Lfqsq.my))hh9GЁD#yvv-Q*Z7 Z~ nV,VFN0SBHzI s4Ua7Ixs$⥧Mְ6m>J6OaIS믘@U| :uȐP|5b>N}lFa.jzJהى! I+tZ:5+^}EN\ WR&9?NMhE+ /8Jw&\1rtxPrDF)'zȪ K߂A7D!*}1c:Aq(|ۥ@jUn/,lرH_&en@+*CֈyߢF2'  j+B*: 9yL2(T(pϑJO k@LyGzZ#Xo@ +}%Rdc8쾟m$u+[fF\L.>ƾ6d .ɠ͏{t;'X9b/wF<ov|Ә_7"nDrz$o^=eʺC0*I3D]e1k/'I%8/[iiTK==_+-ֈlUeTbƉ9f{e0Z:w-Oy"cM\}( i}ǧ; 6E%3޵"ژ)/nNCϜ .Q?-U S52{Un1z ȆRd Ql#VNR% O,y1~fΧcmK[6qr`)\7]TI~+ޏ[gDML,(;ͨ2yj?6#Z%MS+~Cbn-K΄#g^ױ7H;%5KnkJLW3MU6ژ#gPEH=򵷷(֭Q?3lYPƈhqUs"F֧n ZUcS'kuc,ZҰp2zL((sc= Еj%/v,b^؜Q/){s "6%3£kťE;.)Zџ!F,G݉h]Ni|Q%[\ 2lXsٞSFcr0}tZ)xW*&7Q]nii<@ J@-}g{muvr6Ϊ t~cdTĦ$a͵7!|䦕zjD7(r +i3d ʍ: +?tGȬl RqJ!!a i`c>?2@Qڨ>=ǐ 'cXlxU[ɆO4%6jx8mR\nwzC):;(JEaz.?fv4FuB6\`5TIۭ}#(`{l\Trog=mtrYV=:`{}ec6$c4no83J O?g;hv^N@J)Lsx+1TJ**XLfDH#.7+dO1.U,hI=4$7VHA(Bm9 i.uf 9\\>śTtIe2Ѝg G҈LP E- IM:|[gk"0jXwD!llTmjH ؑ!AJPjIDӒ:̽TnZ|3'Yx>?ZF4+_5:Q}|m. yr=HWϭ[cyy\k9[J^6(N)ybWo! Hػ"5@Qh8ݻIm? dO?Dd kY^I=f3Y'j.KDX!񒜀9tk~א} PSa]2X]~zIƘ ?p2̑tOeVf180 T+ȜW:޻}2WKL"~70qi4"_?J w>ߘ oChn ~ɭu& yEqFXĶV9Ntj;"ӀQUm&&N2^%Ԙ:jD f,v~eąc Š$&{=I|MKW=p Smr]̿pgc_r{_a'W3(?B/Uft2vZmA}m}AA߉l^X`]>Wrr8شe* q6^[":A'/GӠ#Y0t`&`;qw:|ajI,w'q, $zӣoJog<0JۨW-5_ڸ,ݓ6iU=_ۥ *g t}4Ѱ?xdcH}pJ,AzZDW* G{p\=^Σ0d9|fAҺbr}P^b7Iĺ)/ڷHD2_V;k8$ڸʵpˁ-. dP6Ȋm-@d /ܕ&Q.Lի&wSF) qh T6G|7>7CeHNq U$_֨+vᒭ|]=SFD-}xslYs,hh0 ~27VN;d8ݗdåfFj"-j4*bP;>[ k 7=~P~۹=<0H^z'E}2=<=MŶxbtTN) `@K6B2{̵|1cd󻍇,Ƥ&6g8! BuF,o_J#QǨ ( IPk3B!L?,5x ĖIF`J:՝̤ 3@HNMSw?/l?s?j^Uж:C ƘCX39Eo[hIHF'n$}^me]mE+}A/ZŸ Tޤy<:G݄\&J҃ȌzqˡۏEO^P IJJ-fk嚛#U@?bΠFMZY?VDLyVň|w'4:ۀz:$ n<X2JNCq_I֋i$Mj))bW6{9 nӑS~ 4~ŗEUj;7ЙO&'SGU x}9 i^։\|iRTH>Q^=># X+tN6IBt, b33"o$BھZ#l7ؐ,SJ6 /?.#hWOX~?ø||7ƞ L#@g-oǬG})"YKZ]^~TI Ud"ъx|!ȯb*8Sl[lYZa@'_qz. = 5Cǡ οp&pIAJ,iݞ:\6pO&NPw1-lbTk2@;)^&S>k\`i{qs >x/1KT*8/] V m|,Y]vy% +u{T5o*C0Udb?y d|yJUUSϰԆԐGb׎ҚP}s_;7{@:;y#>Oc^%ŞE!y΀C(?NشZAC׸ϝ 9ܭN$ܴYe9W6|}KRWkgX]M)s lZ[7j3`c;ɏb{+ Gx#Ιɪk MLlmo30 ,t11ރ MnRBAs;.Ww;>9\mnT UXw[2#=Qh\cO#InvgJFfKw&k> 4Z>?&侱w1}sM)Ss?ciYT%T{ ĄLؾܨ"NIڽEzROGq%"o}0 o&țC8#x+ cA>Jw5֤!"ڪȃ'9C<ܒ-|M*˥x6P<Ĝ;iفL$sn\fr_mN(>2eʹR!! GY(f0ʪ;^ނU8cը0Λ0(cf v6M2oA >CuP"d\|NI 7^fiw@ޝM\+sRvX}SKz5I@RR (Qʍ;cV׍A,R$@ذBx7cOXmTъcC#X2iS\pf#= Mkxk"'ڴj$}(J8;4̃t I܉ 7n7VPZx MwѾ `n}N㾈hJ^ˎS!'`̀Vj%6p- fqu ѿnYI5ڛH=~vȟ=0 }}.w j@cGٿ$ W=㾧AMD4ߌiA0Pg$txy]*cSm/}Zx >~4t.+-a]0H7P0RcVHOfPb`Ć 'ېp=b[cWƶ2ʚ~;ʟ2' Ҫc=K1/N)ᝐ 7p[FXHg'V%%at}QVDZ5+D4B `cp)Z_!7g(jjsS OR.+ ^~.V80-KOH swwg?I~ mV :>N12R PPcL#܇ Yپ*5:yO5-GaS$udKC&~s:ev&/70t?~)M7L*R@\6M9w{UeR¿B*X _*JA16.2! Phx9B%A3S5%g-MXo\e ꦩЩ̱mQ7^#!'dqj{~:h$C{~MʚȂW].ۅB8fg](+MRNOY% Efݐ쮈7B7g4db4X9RtJƔ W$mUa0fgƈᩃPۏ 3sf`BymSBYm%c4[u !Cb$NOW-8j(ߝo+͞VW$m^qP #du3רTѢ"^-i^J_nlB$7]#f>g0EΞqٔehBO؅tq .ZUwjˬGYy+?ʥm~`. |qGڻ 8`,-EPPfí#\wn(Jg:Y`9[725vτY$%}B[bK/;́_~NttǼ*>IYZ8>[UǾw> i!RBkVFq΀or|QQ֧k9*o[{^GsCE4t4XAq;8˸p[[[ z2BߘؾzWzVX<n0#jEU/ea CG=,Vmy% x69WsGJㄻbMkEF},=?\"Id0]Q>^Kz8ڎEۅ/mHOm4{1|vWLO/Yk:IQk <2F'~"/{HUį*X $4iJxVݗ$/f]C} Wk󠞾 (CnJϽ= {$N’)ϨgKk/vd$'PN\1 b U$*>Bq|Ni'ng/w  5euZq8ɹ@ECvp`%= )2OG;,[,v/!b" DR0o9^ rwi!,P(yÓf}8V$Oh?-C7A6b}bM?h6A;({eͻ j*"l)EYƈ>~@{5ʸ3#]] q}uZZݒYX*fstU؝ -A!|*UѶR;SwRbN6cjgߊ1l5}4; 6y!f4!it? $z Zkc>Y$ T 6a1$CWPqdPлe1PiłgKn5g  tKjmQaiz6|*k#3$ȭR+ L9 I;D=I{Qo UƊ=83.TB e`W(0!U~h#ȹaP"E8('}PHkRRn{zg`i?2 \-ΨgnIϺ$TEԱmMp NS+Z8KSfhb0"CpCJkIij~Xlԋ#Un{LmX'H_=;S::T0dc&Hj zpd6|>#Mi0)I{1,*XgF%Nilb8}!<%)ZÀM<K,_ֿx:װͫte\ MS)DH@ROVQ 0^4F.;V|i.-UOڱڮ3"<,Vޘ@p}rJߑ4Dt1seCQ2klzI4=mZ~";g>:y.7BnN}HU[ap'$YZ]nu<Xs9#l;ws=IEĻ>C_.~GQ?!?ΫŶu4~ƖbG彆=w| ˆ8%Nı`m8/r6qk„*ʉM#@Su ~UBkمµ+>YXM)=QMsH°M4Ϋ28ɨLwq?M?rAp7=*`6)I^<ûIVf>9aw]w{k-ud'@"R0BƅQ.[naH2D>2Z*5XtpJ0=qID\dyu`y3zp㸪.-%tI6,8S>]&B# |S#1$\+q_88$K/խ1t53~lcb4T+CŭTk/ƦV/uo_2c'MMT3Yzhȿ ʮT񌉓ujޓ~c #sFӅ"B^(#t/?o%G㚽) 7VF݇u.j!flԥ0, 0V Kjn|Ɔ ltZ8]irEm R;L 9qlLhr)y* * ?u(YIo&;d:OJ#~張kѓX0Wk\]vaԢEMb):ׁh| coHqz{a4 ~?Z:dg%QD$lD-%UX6:-nadaLEᷪ("~`maz.tz**~l#{_\6.Be (pnZ2UJ\a_cs1l ͪifk;@6pւZ}l ur&#F p_dșpc,qB,JkUY8yaq. YMC^[T>l˻Hi"wPhQzB$h ]mCg sʻEO#6oaxPQO5Ƌ?@o[3ZQR4[_K[`$v=y:KګLM7Yo]=d_3yk~k4%:khҤ C~u ƈR-ܩklFmK7uﮩ]$^IVGߜM/sCAy3 y75sUkN1z΅k @;]EX 02cYqae&SdDqfUS]>N̐mkpoHqNN5 cm՜uK7,? 6i26E4jFV׼GԞbk+ c k?iYҁw.kLtbpˈK|\-h\n*ߣx9 '.Ǡvo~L_q0w.n!9|DB䏩bF;?q 3i@Ʀa6#}ʳ~`>f6P#T t Hy4OAᯰ!ZŢ3kUhi-OǗ5oVj_)}I\]obhD%c hH:f!G 1zOJ!κ! s'MDKv [":`.մܞ-:dM0}|$@7XexU.gcͬm'HX^~?7(9jIqvt*[#΢ Q )ʺEoXlMnV성3oS!VށKsy8fܑ43GMzd cumJfj? kR0!n@g!U:cL>+ [Kx6Ѱw 7:! i}}-N2a!D]Uc(&oz.Āa^OVt ?|u 9&/=Zq4(mׅO6]LY% .oTo7xKN,zeB]$LPϏ8Үu"pǤ³W ~UCơD@#$4?jD"Lbz=,Qw )6|?hN;!tQSg%[mԠ@f1o;f3[>eHu$U <ˣ4Uy6u,={Oqpͨ"n"K'2K)/Xc-րڕ4c[l(X/;?eRBie'?3y3p〉`hVè_){\BǤ%oTH##5Om+϶&©qWC7d]lFe4lbe Gl@˿oHű *s\#s$x92P=j^ufd $IOCCBƌ I%;XDY/lRB&1n9(P.9C`o>禎͘R9 `$ئgS @A;߁lPWq 2yP #!R!ƺB1F-;9"%!k(3d?>./f|Em#wj.]K`5Im|IKֆ]&tKBa65w=WGvE?VߎR1%6~ƫ[G|5"TXGxb@e[G"C s$!&g|kTiv=A&};y,u7k_>qfpϢ ?QZF(TQ/9M9ބ:qCҩO*&R1T n[_IsBjME-B/\!QX&W#"{p{ )I ҴKi"UH.O7`;iÈӭV`x/':L  @f8܀([{Y9(vEAT:=?M=ֿJ<ԾU ~d*\u:*!ZomKdmg%Q*!27wT7r?A&ghY.-/BF H=[Npe4}#Q;>c8M: 8pOK7ɚq͡PwgS:ƜMT,CmҡwR⒯ &F(4'^lg$'']W(IV,|#ۿk~{]asSX4XGA5Wy432UƂ&CΊ3&jG8ux!G!f[_yRQ$RmYEsr:@5SQ]ꭣ%Do3n],p2Kqt 67.tp5La-r q^u [~.m@Pxqsnuԃ˳u_Q?aj$[j6%*CQKT?}ه_CC}ybaHT~gDX:wn=&>po _|v̅u1`~gHUSe)[ҋjQGϢ<4k-|.OݪaO$hW'uiqEϷ&`_FG}9U H{9}9#jp!m ~cX>8$P v"H݀ 34>Y_{a/m}bm" 9sO$`=(!ĻXsNRz+ޯE,Q5^ts)Z jXt!f̪Mh4Tqx}s{fC*.vi,z&a .WE`AtPNknƣ #i?ȝ6E[ acXտ;ViJ6Cw{SR -$H ,Ìwn6 &fEKLѦ"N]>R.zS N:O`"b}X~o,#cSYs_syPQsX0^a(,ʏ/ꇭ%jꌟLP}^Ua-uvy OFEYȰA0ё E78UL&5 Qx wy7&nXL+ &wy&PFC*V[N|p,8BI~ʹԘ%:-_WDc2Sm>{i.wzi/Zݐoػ0 C!EÍJ;x]_s^/BVi\T][^f ؽ:@V7Li͖}P?O{>ՌݫA$5s_Ɨ&W(όQ43xg}XP6ʱQBIgwUEx91T S 7+>ߋV#@#|N*QMa&ˢ/B *s*ozlJq`pRxE%惁h pݢ+gDOaH c+-樿w1d<ĝ:㣣bT5v+ZΜzM۔IǘdxS٘j覅$Ǿ,uqsOΪ.A}=WDi0ѣkV A^hR?XZ>~Hs:"c }ɋ{"#e^Iķw%~@ěXȲ&]CIi@ ;Skz-{&JB)1,M)2{K3r,q|#Usv(m#񹑓2M#oN"F^gmg? 2bNBp6 &*U{oUV7'g1rL=\iHlǣ̕oC'ʤ+۹s?0Dh XUM*c/4(+g4gMBL wew#~8<҇M4זr)DG?CkI76{R84 pxB/]*kx քe݁h/ P us6 9/S0j ўMAܬM_~hZs<Oibg:8c)ezD'v/ 0~r&&jR^?\ᮬp klc0C |)}XO삜ޡUz*WQ>n!,78c8_ru.9J# WE0"%ߠUꬼHNT<]vXbX_=u:t)('K.sf~7a>v– 2&YCZ(V*Kۂ9|z,\MylT~ZPb$g- wxF:\c>.l̎XYKLk|MH=l(U:Qkn1LxZw]Vbs̵'},AVD|dA>mLWL{`?=Ր^CTIbwpe &T@(51 d=@XENf(Oɼ}\x,KTtceըm${ 45s7dYzaj\2WS2vBbBdoX=8`/ !rNN ૯.-+|/ U`׃/pF(#o(ld{eXHWkX]z=Y/ޞ5-Sw'TRL#ځ\vaKuL/"vO LFeg\m@v-H<#kL|yKTp&YsԼ jnGBh :<1ZE21iѫV ó9U_ak Lhge$D6u3>-AĈϗB`TT.}ydAc)Cpl7{ۛZ;l}ˍWX )fa&X Oo,O`Ti݊{dl̙p0Cl.Ր"4{Ԩ+MAh?)"(K\ê#RXNlJ!i#qi~ךհRx'G$yr1ҙcpV*32r&`q.{ pp(h"Bp{[@۠0o3 ;`OWC/Vi͜-v+k)X #CêZۓwTY@D/D4ߙIdҎyZV:M:Ȇ@"gr%GJui9Y Wo9)},S#2hH.Y]?01؞ qVpD%j#bA9-ym'CgF^< 5mLP0 ~c g6K6s{ƺ(WrZb "˖H{B[pȂJcJbbyo"W}_!27g oO-M"&rgA㸻~VqL{Z黨-|1 C;|C !Tbj&otB}ꊿG #H20)td(aL嗏h,tK~LŐ Ly}|gox"8S}ca%{&tDtZ2\Iڀ] -qQzicmUiDA6__ճ{llK*r$fr.ۊ [ FűvRH!f9.Un#s@` 'C;A@ #m X&yLZ6\Abh7PFɃe˰[ Bg,&"GazO RCd)=-ftv7sfNYXuQIt]XYg-[~ xtّ&fCad/g(SV|UY>7 VvW#26`GP*tkR O.Xv=̨UCz3pU5aƅ p63ӽ{,0Im pl_+Nq4lxp_x$Ή#0'ub9BU]G`R668ߋm`V =CVZ]+][0 ;-wt#Z1vtIhl0jjCsK³JONUY6qo eax/~aYw_K4{%i#Yb?:<0#5 !@J&Pe3s#xA}EDKPq(pmwЕR|Bb0!ugv/598abz6g^REz{Si!7#Tzq7t"5"2w62MuO 2)@VN H}JC@BđO9o=^jnMu}o 8ҳ6M25<+k/л'8Ew$LCy6Tw~ΜhDI߳AyRn.KK]ĄS%)e  { horz)za,FZ^2/+>]@(םF8 gOZcfUW\a 芌Sys߯ dT5vdN0iG3hPGR6ͥ5}SДk!m=ڏ[a쨵#q,a)!HQr6 'IZߜ}4O6 .q/H},<@eS1iV˭9~WR5noJ+F܌`"уy0s,Yђ HC`ZtH %xU[`~$pLȳӼبYa\14x8^1y{g-(2 ï%n~T gaTUa`)ָo{74H䒀IӧfCsRB>l'~.w׻(&šE2#h1kd'aý8JLu :ҋƇb &'UPۥ[sՄb4(!`^.84JyVs[s]`)q1[r2T2J$?sy8Q~Q'+f/vI.t5w Ը9tBS̐b! ;\05|H3q˝lǘ&,aqf[eU+{!~ E}swin&~鉝Õ5El!=8KȞiOn I&fCl@"3DUٗPX!7-KfuǻPQs5drMtT}=,qa)sʪ]$2H8O&Xu >,|_Ct'lS⹜t= 6]":/OKZ?#ґhd>f,{nL I;iEɥ ɉ.?waI+oۋh\K7FEqð,H̩Y?w;tlbGrHX)Z\-`̀Թ*[ɪL5ؐԥfz"`Q!Lڟ+!S ,j3I31XH@x@P|~F:< ٓیKIJ`gA &pI2҈~ڰa~՛ʵ_k2MWS܎ ݑgc+kQx!86#d ЯY[02!x= J3|^Ec/WS*¤yշelt q"kd|LHJ1 [B/IU=쏹;1nS6guUPSDsbnIBPڡSΨ$=?㊗5MA 1;X>jl2XUsz/^^!H4:аIƨpÒXa 8o{rc>{?pfDmZmNN-FLA4;Kd~:/\AI6~h~p-m@ol,pLX0#jm*Ƴ_vQk[Cd d&D4H^QuyfmyQqQI2K;wZ'J AȚCN<ej=6d?CWq@m)>`٘{ٲR¯=V}p~$6ծnٲK5=y%}jښ Bf$&O?Y dCKk;IFX,D߁:zi(6ݕH.5ﳰ;4jӑ䡽v]òYa"iD = ;49GygY=&= 7z)V8pX蛚3Z_WH@ _.&yr^`|}9UKaruBj:Rg" vPs["-UUK^lK3qF:y=GCNhHo/">)& ywK}N1\r<!E/,'")95)QSå6 GUsb|H 9@vM S5 \[]FLø`¢:[h:Ά,͒\̜1|^S8']Ô>Tw{.b6,eޓ+~;8`xs8dۊ{x3@{͉fBfLZo,T奻K!7Wva"Odek'{aM tP@Q~4#X{$\5.]2d8iqaw^ܐXZ}qۭ IG_J o*{9z3J9W:wp)vtb[zWM3r9 <{-G.l0蔗,ƗQqV򯉼wB5Wfֲ-I'X+C83w*͔ѵ L# B uQ ')`0tm,j-R%-/Jft/qY/;wwvd.M7Gv/7 x_ʏq{#mr656}ipN޲4 H)$)|;jϊɠ6- -eC JʨidWY_r;̯BZWe>4󕝔}Ռu%;Wǻ eʒiNu"i&g,v _#IL8D}Gpp8Rh:|zk 6 "%L j]x2tQ^,ި"|;$ '7_ txE' +L=㴇&ل'nԜu[52~Z+ hਫeJ햱 \`eE,b`*z)k' y{=1ʖ|]e{ZW#MI?dv!dcAe t 4jɶN A5e )iԠ_ K||1s?8|\.s_R`}o0ѡD%KmJWN:k~s冷12ab8u-I +zmnyV!й:Bһ%;>"dcJ_[[6RBoSӌ[Vxx#Rx~FFE vQy 7MJہ#eu_α:Bͦd]}h??dxgS80?SHrnns٭cLM? 0i_(&|4>OA`pJ~(7j s7l5ckGfVH^m JL^~}e}i\v%_.F bct_dm998$B KgҼѳv;FT]]L?l|P>a@Yikf:׭-qT%RRZUT x(К}!+sCga^4R{"#N0EdJ> _83#T')B'pJˑa: C++s>i,5K|K+ydAQM*VfdybnMFՃ/b*rLh\{]`$_ޗ/[߿1ZHUQ^=`-6c؂95N3w'kV`xcR]Yd /n<R içnZ`=GgYj.?bk8OOlHL&.6ԜFRXE0$vyIPE+>d\54@S̢aU \kTͱ!>(C\]y>Хmz=[˗9]E1 2c婀ptvcg[יpBJB Ɍ$ ʗe {.`KE`k/!B͙uhGFJﱄd铄.=0(^+iLGR# U{% imgN!li:si?+DF׌|%f+'T 9Ac%I JS|b B..&^lD&ݳ) (g^em[=13,wփ7W2$i|=.⿔/4Itۮɲ Er($6e>V( izhv}Ug@CmќI@aPKL%*W"=!bM1ĎO(c>MN樔IĢ%8^<.h᠄Y~+e# r$]/\^^١ Nao7묒f%VB)c̻)M*D {PZȽel\?'B+M򄢬jv)D)H5^#o {cWpiD)uƐ;ZW ydNHwڼA!bM$sQj?uM!P_ lc)F2nG)`Ve rȤ1vpe4Xc0R5|FH>ńTQm{Lv5DTPՈ_x괁TWx+!S3:BY[>֓;ぐtanvw7Kftja $ Pk ť`-dף}Ym5//;c EvaPMҤޚX9ǵXU|ecdU{fZ@ՆA8ք '/ +o-Bpځ2`JL+6é QvAa`` o.cڦ}fМrzZ:9'35~c0d}9fa^sB_0#O]˽2:^GBK뜦9[7lQ8އ'y_P/0#pNǥi>fs^T" v&+ű=L[8>{) #z1}SwI kݵX9 2ShFN!^ueݕs`Ѐ_ _o1v^Xe9*u=\a kxưIF} 6.ψġ‹0W*QR, pmn c Lm c!lF^y P$inyc(D?\݆1@hfM "2[9k$ z@(dyNCNFЊBh`VW Z{w5,Hw)XtrnoT{T!|PzX uOZpl*۱ a4uR,RH㭨DVW&a1$w}'s.,SSme]3>`r,rCzX n*^f]e9,;ܹ^ OP/4@ c[uL&,WLS\1:x=Bj{$Ŭ1 to'[؄%X ˶.qg\~zil)>po\ԹBp֪7a;_|,4薄yeyAD|` oZ\T: ;O¶3ղ:4oɲ^_ݒ rc2juMm6()ՃD![$Η4Q0@BZD}Tń鏵vZ?yϒS[f[bˑUuy"Z &Jm-A(7ZqL_5Z^= GajFb+qD%ʃ6w6`_$#JH}lf!.b 7 qqsm:JT\jw>E ΞPLbzgo)bGFo,pMS:⠱彠6m*1(>0ff#¥~p;4zU0=n׬)C#  hy)Eґq~MӅ=14TǡQ1;֌?%D1R;]6l޾n51,n+hL_SR_mYvwϺ&ImR!Ȁ\]QhE&o^g2IΑO8g^ wk.Bc咣_f 菩l9H 9ЩN^y_"}~X_9b * ;VJ_{]\]x45ޑB˰wbV<$$FIБstGOoЂOA]8So ?ˠb{k!(UxNJ1b~ŦpG? Noi.m _r*sr-5Hr^S f>lkA;z*+h*X%#V9~'v`6⬒q.nH Mr"6blkKw Bij︗WU({ gqU.͉@">Z*3iS$Ҥ9|\ao_oG+ٿЧC4[lwuTWpT.  6*A`O6EB/,EBqY Bތ*4f.=6Q:z.Xb`L[_zN1C'%>J g.u1*};CeْvZw.Ss̳HGW[bEv% B@>e&Lj$0Ar1wCT~A <"o|ۃFa#@E6/pI+OE¦~dȯ"F: [lAsO1d覆$<̝nZ&lNCk`Mܷ4. StL3N2+@1z']WxPδTDM8Ӵzsxu{9G%-{ȏbEqZZ̥Eܥ[j؛53>ǶړcrG_'|o!o@CiѸTxB6֩rjNMj#' sO7+#x bpE+a1Tr皊Z5e aS`? q-e]Q7s26]9AƫU Ծ_gK 9cigQOYn bw2E#+*q͸||9iЮbV g9'Q.H?oiNM-\dp8#ڠ.mra־yq2.6^Zr(7^V_qؒL ˟J>!hnI=t%c3ф-+ڎ9Ý a'$ְo4?Y CdEeɨRuv("aWyᜒ*mx0|x"hHZXdUp(3ڹ\(Vd!Y"{"B~}5pNͅ2:;)Kdv-fE.ΚgD >Z&CRJܸNND1,PVmn $ =]K#QkIʯ6ӣK8+:Fր,0+J䲳O]9%lruNBGӿ\0!$zTm P ~d +XLH?~Q)S|9 [U F||s{!зZ` }@e6kUl(~od3}E#qhzֶ;92x@7ѿ= 2H$FND_dpN.4x{T넆̱biW`L`^T|buR>'z@B;[k/[{YMp.õQ,Ъ7EuE 7o͙ƠL QqHV~}E8Β&iR (j,u L> X}`Lv+ĝ^.։{5c сҘfˊ̤ KF{׸N#!1 gfb;1bH*fQ69Ps|`(.߯u^8G˾QT.?lЂJ/+:4C.<MC*NF:.ȷy-SSiP$6: /lzc4]΀#-j9 udZKZ2Ay@D ~yWjh9;4GDzV M9g,(K_O)ccOlt~&#AVJIF1y,r~ OjO42Q94lg{E;$`av((Sʺ{#R7997vԢ/% v/C] ^-u;ٙ|AN0qQqaT0Bylxr5 Yǩ,C6o)qV^2&2< "/,=3-[D܎_StS w@rd7RTSÈK,\|hg2e+âh6S8[F5sYr/\e:r:D)0fQöہ/J% I^ 7,NStA WH`0uPfבWU'*V/:?uT+/ ';/n[4fYI \Qvm J!y̒p2Xw;A͈yY\eH 8zo穌6g4P<{6)MǨo.ۃ G~HS׃۽{0Xлۥ(KU`Y٪ \^-9!'`J|] ٟ6x!ZT#=J%j.aIK  {39M@s}^m3k&91b(\1D$*ޯ:vz_.6&8VTq^ *}w&"ػ]sxKRyc1ܐjcճKr&{Al¬Y.VQlW! *O˽?VT!|$(cI3H=3}+5u&7@ r:QBѽzP](&K:3 >-S?*cWVV@0ȊO+epvbTta< WgP %\JFˇ7 [{~!ǽgwPϰe6aL~E7BBN+R|`] Llhށ1|. ̹$@+6BA`W-ʚNϨ5mY$4*8F["׃Ğ7kpx}^_D?Qqɔ{r6 *{BZm ~'9Ӭ *06v)t·7J;`hJJΨ: u^fE+gUD-ig/`w^]5b}!@D[W2³`|[%\0$nw g[Քn0XRzaE0yFO|ǧvpd[fvC\aTO-?Ҕ4dU-U={X J6xTicOn=#x`D a:7yXȶ;zϥ2ToK ]XG3e(u)o $Ærŷ:?&*9zZ/wh .f.D svW}~cۺW`0kC -y%͛OsKXl^rc !)u d-[G?mpgVj6慈jaPlr6`N3^F:ى$9w\PuVYUTN-``j6Ljxt4QwHە&E?#=3'C|-JQ YEP#Ef;D]ϳǖF S))-5Uΰk[6q24@J,[Y+ CK#j(($AlӠ6%Xi*{@+hsheǘ=Tg#9~pX"r݊hhEm-no9.QkQ7BSx%3!4i"nkMJ-$jmJg&|3a\j|VrȊ8ΥWO RѸS{-W9K M̝*EE'cE(v]Gͻ vVOw j1ۭw2]pZ[D*CFuq 6l5)GRr/N6c)! >FɃKMߚMU!T?>H+q,4"hbGA@鳖qCkً.f1?k+sawѿhȡŧʼ g2`]mq:Qd3t9M9aKqs_k>×:NQb0kL^CY+p2RkI4t;k}q ؉ۑVA*h!."wj4`1Seb^fD+~c \%4ôV=oZ\@1qe1j"4]j1~b|מ12["1rhN'9Zgi!tfRBeC8c+m,5'u Td]_أ(Ȳy#I<8KR$ŵ $F| ^OQnURh|S~c_Re~s4_;؊W ƳMEY*D*/8OBgPRO8bׁPNmr%B6 #JՀ MǤ2jfudd~xk?JnJY"j Unp:dT_;c@it$ǿC^OrE߅lip"q{1p 7eLK)#3;xK`_Cbf%NDW_o$)8u"ߏ'[;\HB2&6lk/]mHt YKR =dx] YݺrkF׼͞)q XS2˒Op,*|pį҉9K\sIE5}g2q xhM|A\k LÁS}:f'.l s}t)e#WX빰E>ʿ^ulqVs|5[k*@h"h2I2@)wؐ>`XN.fN%1qTB禍2*΂ !`jqEv؜b$WMQݏi1*NV|8z@ґv;UO9[iOE #,qvOUXܴR R1y~9zitdb'1PNy ITTÎ<.4| ӯt.!0ntCOH<o|ĴD;NQ+O&Gάz 1`>bYӛPSwS{^8;L ڀsݸ7$~&|"1lвua(7ںbw};j+'oG{ +Pytmû1#f=DsHNo(Rw8CjG`oAp#W m.Y-GR"X~z=uL_B&ɁU-Nk 8bp9 6 ~QJHנRf _ݕI%m*JǃkAh6ޑ1{Ӄ{7XZ9;1w5—#e#і3/%#BW 7^.Տ}p9?ƛB0iXz`bH) +FfF T`I"ME O9I9 3LDAo6͵g`ԍ+ق~A5$m!"V[^EF0U_"wȻ;O?HNfFM]fcK\4[kǹG Tr+ Lvg8vpJ5DxJ&5Cjat)q(%9+E?Zn5(2{ >IJNLJNҏ{gc'$f]y&z7_NaL|ǐBLFqNId+42aN%@o"-iYm'T9̦R|#x$*RORbH86l02LB獛6L?_ޙ FH4OOG.zs_io/kk":Hf"Jȣ ݸԃU0Eَkd Sr!pQ)G)X< 1}<0+{}wv$csj$t&ķ4W$p+Բ;` O%v1!l5]KXxm+OC]Ʋ|9evk&>F2+aކZƚRS.dɄZ}+,d*'6 iNB`hZZ+Ʀ}g}(>>`P{f`}3~+\?%BQMq;g #A_ݺ`t,L5唤ޏ2JKa +\]^(#E i3q47av d#g[/עa-nTgJj5bD!0k#-'U#uK>t+Kxׅh_wQRA6ٟvZzZʩ^3I>5P;f=8]~ 8/u&xF)>dZRV[UW|Gڄ DTXSEVX9Wn5^88荆ݥP9uuoPx4p.imdOWQb ׼:0Җ"-->" n *KZS֔Pg=m b~XsָGKbfy`4)C5^ J@9`ӧnèAjs#LH5 qN>\MVduÝBl6'&Jkf_")64nt PpeЭf F080r@$K2ZOb{0# Q<8E-yҏ &w9T8\DT<$yE|)nvON')\Q޺̅wfxo( g4+WEԿ>ʔ} ^h>5ñ>e:=D@#U]TɁf}VkMzؒPO&]u`uLNHjiM,MNfv|0ajx aw˩ GrS!P-H~x{ѥ9p`>Lf;]EgW__^SI6 ,`zqA`rRWm+<bϻ{tƁbE3NEs7tY4RwLs-ϯ?KCh <Οsݍ=ƗOPW@@r] 5;sYo@iu\cH/zsWH@߱In> !HBegXvC\g&q$vW?2B 'Ί;!} 89 &IӃ]`?}jr6a35͒1M!5WCM%瑿-BqkJf΋곇?c 7GN.KѼ^.W_*!tANlΙ޽}s%&rMFH$lĜ8ۜ䇬6_qZ`YF8mo'}LyU<"g,O rXiD[ˏFrϺa%{ I@r/ b>Xᬘ: WŠl&8 Ä51Fi=4Ɇ \91xK~KFW/{x lwᤄF@Φ m2e]qFn#"F/2L $>}m{Jyj^N)q;Bnq/̍ \)n|P%rsYU C8]MA0E1"q+xq MK:s\fJlY35aLqfFup(@B6W0p ^*Ebɶ;9QΏt8r0Ww'#mGfeq.|8y$҇z'NQ|l?8.]%ite|ƙ̽JrNȎ~!4o7N0 @ޱusD:]OkAp_({5Ds(FʰwG=%'|Qa]hEDPNp,=7^0DdqlÛ'To ]1_汜!ߦ l$= ;=Y϶:?N5⫝̸XuY#C}YbO~iwM2\eHg<]t@6^< 7-`s'Be6p:;g^QK0Ϊ̓^!ԦEdM˳#}gݢWC0WN%i-2n&uk!@ n|D%ĉjE䢄5Q93:0b1lm 0&$tΓQ(i,ŮZhk4Aū[Ÿ M%C_Oo!p҂3T%`tOGcmjԤY4>ŚC`Cy/΋OY(ԉF)hw<ĈQ:aZ g$}~nWol9 %/fcVS oq7qГ:>耬AC{RxS|O +:K֊E=E ({"F3qPcɃv. l}__p /$CT4'odtS 'IMLs @Dm atjzކ"k>ꓲ0!CX#228MU{4X0 䝦wJDP; JV*('&|K`ܣr9%j7 ԫ --؊ɡ n ѤNyj$(6ߧt_m[~Lyfs|'{ŵP^C㎦\ O;b}/F~Dj ѥUb%S?-V쾍mn*J7z$`?re=L3䂞~V\ByB@n@l fv>Y:'8Sڥgyp8疵/uבr6S!pwj3ll'jmĞp?pW`\2e߭Ndp"ƪ>??>zc2P\7-Y~N$*|jqEW59Mk$ԃ@"yN9 {*y2P-!P9 uy▻v"+if]v\R by>DW4+"B.۾{N'7m5CeW;5A'a!XZCb ?j}y,)\2{e9XZYէd䒪A}h9-d<@,֓eҙ6zٹ[r=515 Fhbw0͚mPSi=TK-vW9fvUg5I?8UCÊ(/ViXF 6qM-\aM :Grx0(ױ1n!> Aɑ7[Wّҥqb&a˛rO&}&z ӆ9i!fbm;vmY uMY672Jӹw勋MfCFαK5HQ-2 ژoe`cN;7S]i0XdHVVgq슄pJ2Z晊"=%VG7[==ށIaaS9EG a ~^|AO4;b`H@ WitbnI,;k, ȥA]A_kxRQɷ͗ٻt`I;c*8Avcl9Y5S&5Pf~P|.i/lB<#zp_ rȚ- f%A]*hgN":/*2@?:iքvNrQ'd@]{+zә{\3hZ:H,CLMP|mR݁jU__YjrMX 2%&lR[Xnne<5歋'X[^oa@_1mQ3~3?5;uaRB֛n !9AȡBnBj :#($<) !/g-N*ۛQG9 smϧ*hANυ?x|3Md6 MW&d7|"BǼt6\dge5  W:&OIm9΂,6’TlQ!dJ "l[HRM90_УuD T},޼ } c=(9]&#-J$ >[9 ӡT7%yyFwDոйWBl c` z !ӧlWµ6V L \D['`kyyNvg6č!֙ ⳝ 1^xm\Sɞ*P|B׊$7M^h0 OQ z F[GϼWc~ꃳڐ+v._掜8r)j5QĴXBrMNU 2aq-hSRtZ)A嗙.nOCڬ(B43^\B$ܚ 7o  )&Km#̄/EK>K4Ʋ?̇3GRyFeFD3LlAށwT#PnHGD4,X€^D=-٪.f%̺3@e7C(9*& ! dÑSF]7 (~RS^8Ga,<šC48@e̦n6=>n'=.uZx41Wha{T`b|ax?2AU |㿐}H3۱l Nf9Iw~2pvu3Z~=2EAl/HAy!'.}_766rk1=CXR~͟H "cUg B9kjs=UUdT |PnHo"x'46E#pO /qI,(LfT*Ile ԡ;br PM;]wcaK25UŇ+>cD] @ zd޵k]v73mGjX#/ZEu@yZ0m\Kj`)\؈NZ Co' 0/8rnЙԧXtMjSw[zd<\:٬%uf&j}i9`XF@S(Ap cFQխxf8ü„kZ?7Y\*('rJY1VPr %tI'PRWS3$5&$qDBCL6}jeNr<ys.O\β gLAaPmIIJgUʹmg7M \]VrKRG9~T%U[Ѷh`AX(p824hL)1p̷vC%Np ]\K<"7[U4mfH `,;5a ȡn$9 %Ξ}Dk=Q j`dA>&p+/MaJ 7L@WAfFS% ^,1 x'.bAǘeʡ8N6EXyq8E!#L։$$~@ݐ_4b%6mxF$&ΐNI> E t;a@BP^b&>MldȀ|pn;8'6\#Ȳ,!}Rb/%RC25mJVh_L E#[7l65VM,=Crxw=mhUn=D9GB0A6{Af<ڜV٥`Ǫ?Gqó5.Ua8qb ֣=Q_ˍ82~Mv'.(lQ&VN8'¯Eݫ}˶bӭl}.O@5,$͔J 2}]8VY=e9j*7l1r (qD >tDȹNUaayl". By}9!)|7/Z2pB_ Y+C(SX7@ n 2_庁+=ZoX0?tOŒ`#-r\ !iͮǼ'yJe ܠ)<\3+# J-~TW LmRSsbЈE}Ip @͆S-Gy(}G \eHMApT3#H.cWZjSf + \e|7 o< .,.t%2J#%G(!P]ΑR/5䌼Aj.YPVidjq^7t!f fR%W>#Y2yǺg(Uڕt &n;ds+t-hC0WN8ÿ^vB0ng)~ֶy,\;na a BӇ cM-5\V#4:vO9^Ai!le |MN3:Ԡx5*ݑ uLSDlgoK2rmi9MɃSU* Jql:vRwG=Na&nȖeM&gi # dˍp-O9$5Kpy(r>BZԘgW:+ͪF_&|XHFQ[F{`mbo]L0owb×hY>mPqc~Έs; ;o:{S\셋cbG2$肘.]3 ,=NJ ;h%hjݴQ?ɽ( j5EziIE'[5jk$?Q=HUbPղ)`}_)fRGvĤ EW 1SCWyLI0Nǩ!eO }'2:ǧN@fھN9(B a@0ϥ{Q=<}yƬ*B}G2 ?׫[lt|( -t[oC5쌾]$" \lJ(M\P2:m_M]HmzޫhWM8HB5dy= >.[K=w྆(; Ϫ He R(cp*_Iy>.xq<Ͳw0!n3};s3 pl+?OxDNA7Ec$hty6UٳvgYr+5tnУ!^.d%i&%yQQ|8OaS69>GͯwHEqfzhN\y@в0q^ ReהOѳM kqA׬ٌ 0>Df)òIL$:lu{U*s $q#97~Y(Pe#"!#kW}t(jcP):[SAcp[ V%o\-zo%zrF`8/aX^2ZG^d94Sm`# ,+Ң.z<5_~C|gF4\Y!#q!l?y"9`#ptލkNY&Zr< 5v(5alor?ϩWh+jRGۆ"C(1ޖ!s3gb}2gl)p NRji [ d?lf23=Y Hjqi>tX '*{s@ .NoCzkUip̿87_+|/8vfFԢz / }+F\ k* ]h31yD?1p|Z{x贬p6K늹du6BwBwAdXa,zFڧC-Ung68|=T]W%Y>K CIMul#G93y++VesMnMMFv"]_]NY?W$bB#:Lp/9|G_GŝЉ{R=x+`^)Iv'кO(xbRAd0.:ɺtګj&LOR&8%ƯCc3; ˭+dF9:VuL\"X/IC)1 _ui!;Fog`#qa^JHRK\J]$aR1+f}VFuVdV֜ta.P9Ќ{R:;(14'Z(DiDR7r`:(~$,l^3|rB;m*˲6k z{' vdN\'lRPV֞dW@YE*d'Ϝx*4ҁ sлN9E^'W *(U8q#A#qH,SD?>?lڋ5rq#ȏ$ lb㥪͜-$d২j~V!ް;='92ب+,9dRL/.*1x6 &/H K]vOĤ*SƟ,mAvS][( YdfM HK/Wk)-KEƒR1\hh:b($5DBa/C*rfntX9`'^Dڋ%i? ` ;k?mI-ޜ7yJd" #>g ]HR㝨Ft+-Hls-̚hSA0mtFw\|5nH<7@"NOJA+Moڑ, ;:}UAF5?S,6Fyͣ\':=n^$W,0}LԾ:F]V.! Q$7^$\5ܟƶ2h\Qxv43L`ۺ| J5\G3$՘pPDK9-TjvGLLGi-/ (֓r*%yFK ʴTyڢg&+POffh֥~Ϻh*Mݮgfcoa ڝ;WNI6Z~ S 3rrI>x~v U$P^C0"cɃR$ɫ&XnȫFdthԓmiDNJK,ȵk{?d8$3_eykcA?iˀ47w & <[s)uy)8R-K%0 }7p;GD3F+?QR -īobTQb'޻:[YS$̆MH]檼yb"WmՀ6كfȯIҾ %&vQJ'NO)4)M P5MYnȨUوJeb*, /PZ.WTFȀVqpOh=~@@r(;dÉWW4Fg (l{9DHt(QЖX޾? NMV)vM0NF<.ȃ`9B 'XIOUA>x ->Id aZ.ǍHzP|zux7S]OHmUu O40ejRKҝoJL|lB0I Oت e;eO8ġ kNo #H 6lNƉ$Z~s/82({NkQVI[HVPڤ*!䉥9weaxw]_vҗ؅*4#02;]8H9`?RGnp4J=qaW _6a }Bm^ PuœmJ?u!tqSTn:z&knQ|4$3{fvd2 HkùpvĮWZs THF*+ `z 2D- ->FAd@\o|g(Mv3C-sXA%ZTex[0EnҒɓ F:RuYJ* ?(M*>vPlx- `Ԕ'83S܊Uf.u 2) Ut߂䦑J4Q%07yݞCA K1aպX򀯲Iw"x%+ڛe]M);^Miit'U0 :j\BeN.qp5Tbn- k| N;o c#P/ƙ6ܵ_~U^ hOb%T .y&D!3Z͹bͺ3FoBВQ1N@]\d!U"tDnۢesc/; r|e>"%~\/3?7f.Y> ,u?:I˺ʡ-+ !u:i D|xaR45Kp,4f-aY2/! pNFr9j;aZ@0Z,Z~v`+)YlGXh @|YQAJcf1S%TFp|'h6#",Mϳ%؞kVu2F*[KdЭ/\y  792º-f>>{' 3 &&tT]Xј^;|.Hu1|pCk,D׿qf͖E:O$xyMЕOdB5[)Z!@ ꘔ^*TX!wzأ`Ml6jΰKN!e*Q2(q$ɡ  ԮۤJ*Tg ,2 l\tIDv6R4pP3j :KԵ;0'Mo!WrU3@q56Ť_8)Ny˒PM>k˪7㉽ 2`>J$Jൕ--})0a#~s֋ʜ X83 ʔlWXILCeՄ8d>2qyH}!>*wo89}Ԧ&P"]eeq⎳hhGx}r^l!RJ$n<>>DMC35BvH<*h8Sk"S0-C,0eOIJڠ3uq =8]4,c(ZtWRNXregVТOҏ~*w8gL|ޖmfzڮgCeǨgSo0㱴:>Q_xӈqf4 'U \4YcnaW_ 䪴jĔt;b m'"@F(Hc'0/#1NEqfcqyWݏ718xX^+ѱfe!5hDw! o^N]ٟ\Pq9f:(jH*:L)F3Z)GzO) OQ=7ц&{}EJ:3Am_2~!=W|޶PVNrwuen"#M$k2X.QLLvUeLLቡLP WwCt,x6n-h5<<ZmcҊA>7vܳ\ n <kob8<1]i4"-tY϶AK )nΥg˖76[{ic> ^u7]rlWu_?xHӳ~WӼt$aފ ;V1rǻ?ڐ>) G2QOo΂~ 7vD֌F]9NxO23AVl*bv BL-􊼻;ب۩zkIKPsk:I t<|1+rL4k]*:>:'RQr},*di\h䓁Rn7^kʌ6u€0BCyş}AfWՅ^7ˌWH$~:iFþ_9El Nm2FVcqM^Vm XR_T?nP/=Z9Zy3+Kڭϊ~ځhzCPšv5QyZq|V+wPF*oN0P^ qX=boZBOh=FH3 :ԉٚRc9my&MVMU0T.A2E Mc:|=+F66`=/GJ;.8Ž\ O3}vqbv25H}d Ӓf,0Mշ;悱\P&#sԳB_I,$Ae^@ǩ.D‰g%?mc$v[?̸nZm0LlA{+U3\'^K(isfrIZ{)hu s¸ׇw4W;vjOKD;J /2U![%=؆4U Ę [cm,e 6"W>-ϕ,qPO g#^k̼¯9"-c nv~B7&g.Lḁ|ƐңS埔tDzEfNi jD\B_Dk+fX\(-i2@8-شWP5oKAMFQqKf*,^9kr3⯳ثz+ gK/s$ɻP۵KC`YTtwp~q?c{Zhx3rYjtf\W{q*x '~?j=9}cӚÁ璉^̮] eILQymHPڻ0@.vrV4v> ewwN?ki2_q酁D(;1.X*Ԓ1f7 >cՕ/s~i{U,~ ~ $|*2 i9vYNܱWws'`=dC؎E=O'Ҕg.n c_C-AL"8NIz5R$SL:֩YzqeՓ;a`(  `!ML~/]ݧIϝYS6\L}ɡ"+"6Jp~PWRX$4ȸ@JPz޴O 3@!(yU쨢ճn?ƕJcGtYSY(oyIL+3g̢p6clk9rTD}IE w1WYtpm2#csIhڼ2|ӄTG7&kAr_r y SʸOU {rʑ/cF^4 O |rCs,&C+\-9F .RsrbN<#(=&)Ɏ]`.т,!.MlmS&Os28,>Hϴx?\2!ꠐTwԫ^c*"C6f?{oRti?ebliNףIz dOϮtl$vQe {/Q'2)XR&e؃[^6֜TE(|*&T}087t ]"<1Q}ao$U…Zt+Nv++о?].K("[x۩h^bUךow9]꫓v=!E9uׁR~ Q~~RyB8EcJq p_E(>5Pg0' qzS54iYD8NKv|-%#ߙfW^,A_6/$4D+\5}]yrɪˇOz z$uC̆ bV?< vkOFy`D&gdRb@\l ^QSըEu19QPuz"Skk[Cԛ *|.luOsf}cH"۵"NkO=  hwbm(ՠ~p >6G;QI7CnBnZj|!,̞D'3U7D,ĚP;hRçNB#ZPR7S{9K:J?{JCS‹|sV:x]M',AHLqrcAb8(\4I-MNXuİD3_姅dх=Q5Vex>dbkK׎$F&y3cg.%ً.q!/ۮ R$RK\Of{Ab"ORg(])oPRHu,Xcb7ѐM~XhLʎbbL"l"5j<9:Ż?J1؆V4Z~co:!opPxupU{{}6 q!IHv;Fbh6w;L xhèJ+o ? wI,A(x SRW"kȩ G1x{&M p˕7&]SWaAzrJHql=k?dnN_:=QZezQZdFZ9)Q){֢2yi+kdfJ=}"@Yw 4D"'@KmLHVGݓґG"b!-{Z #wzʙ KMfEUI?9j3fnmu~7#{Y_p9SrRAj sKGK;:Y ҽ&tWK'(xљaTL$ztSVN[3!4D}_W8[F=/_M3C&1m9K죶13rqK|USA%-wJa!hJl=N (8M H@^%AE9}F% ޡm_B6@ fW9_7#Z9wowuǒ?8\WoE2` 3vo[`"ɰ<3k4&E V:cjφ4F! k=o/ EH ' QTre`GZ+uFg7w/\Gz\g9[έΙtt+,$7~?Njg*H/',Fo :'/fwl&imSZ!j]Ŝiq0u?N?N/3`(f&1J*$*3y:Ssn-r/P~DC>x1ʋό 9꧲"&>s4 c3&3i_pE*LT؟2ԫʺQ'#!5tÔbDɶɃkQ圇xxu*/9)ĢiIdsՋ,hO9Mp ֤X52{HP# IYStƐsÍV90St?Ϝu ? l@\Lom3mayn><(ݫX.sMPp> ?ӷO 7K̄uenr}eiUk> "DO]B$~Yzo%̑oNs^߃5ՆpMl}=zO&A{^fj()F|`>uK`㮟βcx_V>LJ~֙r3G[9Nϕ5pfX Z'qwրΪr [ IJ9K=',K(#})(;S? U棢fƾGȽжsqPKar)?$MpԇN*t}kq-3vjImW/n3uKČ|4'$K櫍5Y^Υt[P,Pĵ\Zy<},(a@R*Q~^Mt]61n6|5IXcx =x?BQ6 }pmxW*6D?HL4 &M)k~r*86gHm--Lc.jbx@0,~{5KTFX`4"ZTzCBlt@GM0FqNl澡Ep%lw#4@W_d( ɨ.Z5o3F~~HL~=RS<|+X(3^cQ)"զZ@ isYJާ jU\\Мr~8Te峅mh\|[%Ò;pzx3]樨'oIIv$mu":LT VM Nvĺwtrg%onZB t,V8¿>km9\Ӭ{ŰxCs!qJMwErkq*r}"p׀w80]p^U (bn<_XLCfVihEl$0ȫpN[<vЄD2DS]B4!BDj6d$'q*[o@; 3R%\I>RA3kɅZF),0sS ߑc?kNԦv+@4xu̚M3?b'HM.# yte ? Oճ$u1{AF8g Gu}\W;:ڃr;47mKAarpЗ]-I-2!p\d}Hա6:g4G QrrB:Rq-gՍikXci:pz[G#F 4[Shz*UTkGdf zx5Sc4"HԨ Ynkdw~8̹7ڵ`)["m& x !t)EugS>ϸ\Kr3U#nx:LCl^u ´br\ |QrC'әIplZ:_@¼fKYE2>2=5b1#?9\-bw֘xMEҹjO3kI|UuL;5rz΢4Zn4T  KDhtgk F0`$P&՟bedȵ  1ʮH;IF)_nҭzmȎtڮ|\M'U.eؒ XxuBoiUʭUtnπ(Zizr$Q}<\sda}_s>dIY V_wߐP鉠cl TakCjHywN7F͛oͤ{ԭ_S`-%j@a"TUu G|޾琔6m*,Da~=TR ړ\N4INiG&J u1-}gI$_Nt A(܂F_; RЉ5T~y$rv=K3ǟ i-1m(_,`*IsW+̃kV\{/7I ]:~ C!7TV0I+l{䏀fJN⼃ZuJSDe_i8 ic4R3Z?v4egto;픂gT^[ -AQ2k ALqc34Hѕ_iLRm}W"Ph0_Ik)Fw0K$m+3OvxICөs 卧]w͏4{_\nK+W_;4AoN5B>ŦDO۵dAE{Yn75[/ 6MNg,A$ ukd/>m"q]'ub5scaSL_UR$ 56ok\+FgL}h|tp\>xRp]H*&Rz`Y$e 9=B^aDd~B:Xfg8LOo9qAbOD*"Œ[#j5Wkm8+sxo\/yL"I-P_ShixoMMJ}鷃 :gY|I(;S|XD,WbWT-:Ot9x֨IjWo=Yx/E.K#DA@ղ)#jALgG0MY&>Eֵp99^*x U05ՓIR ܘۍ5@yL$ވ@Z¼pdO*,o ta-Ѯ :}v2Vth;$/RQ;^_C)x],0ٹsPS>a H봞vj~㱝WѴPQ7qc@SU (5s6^+*ACL_n%)'~@[<cMXJ=m Ztj8v(4,b[֒T@QzTp(FFR14#r@9y"SRȔ{MJJΎDY= ǑLU&7fޡSڨܞh|AB3+ZTINb8Un.M0-c0ꀦ2T=+yAfB~9Hmu iJ.[~{-)&`e.t˖ĝA^`npf6o$5f>y@F{;[NaﬢL:֨629$,iBk*zlIܠs A8ӭ>b1&`rE&]4. Υ ۧ>-ЀS0ަɤ B҉9'w@aN."_|£9 + 'C9U~^ĨWy+헚6_`]GrV43}|xSl#J݋hռyF/9t0-ڦ42YU@@[~󪉱 t$-קR I,x(:BGtmM"5Bxk %tr6,|SlҀX̭̀GP=j LzS̈́5wW`µqM^a-A&[{e%/3z#)!F.APқtɄg{N.Ӟ [xIG H>nRijoXՎcŜI4Zi9Qi\)GǝN ܦ>hgj&4yM$=|k`h[X^řcu._ R 3e#0DH7z:+F65^b檵j 7<ƉV^Z(&"WY 3bBQL C|Gz]m7MoKTSy$>(r9Η*yc0D҄OKq W+O(k4`,uv4P-%`3S84YE7*)r}i1%rzu8PN4~'Jf6xSG-AƪȎ^@şc./ʈ_ξȇףĺP O7hQF٩D1jJU s4Q}P?فbop:gqi#V](w, dF+&go =wڍ.JZE9]Ce~j*|/ݨ q8!=,0XNx9y+%O-ۘdj9#{OOc^`o+dBNkA휱,VxS]1_ܟu'UA}Sp=a.ow0}n@9Zgș9xEOK230 b̥z3W:;uو!Mƕ^w`C@+e XS"Ž ?.4D6$ qg9RQ^UG\tʶ= Vt25b{!6+X#3X:^V֢5Y?eKo,M+/|#&JƉ#L0Ii?x}P†`@9\9MJD M]1Q:0K%ωqh7k6p ?7"UP3^ľwe*`h:T%o䬖a~6?~qd]3Ҧ}Sol6hle}b,I+Š3=\ E~sBMĵSDmFא$l"yhhk"Ti'ʁ){eG]XG8aRbc k $ҦP#5ڨxT (`-}3iJs7zG+$oe_Q[7B[%U(KBt"lx:3Qd z6:.):K.T+E5TMm%lh_cJ B`qwZZHk'뢌Βab}ս  ok,ڃ8{ 4,y':8ڃ Np"TV= J=_,7G%Pu7۫@熻!.${{aQ-Mq-az[D#E/XgW WKG1-8 coOi,jrc[q,u$ܽj|c"e]I9u =ʣ!fSJu-uףu!PgCj_2\~[pOWjۨcuqIΔ엖s=m}#8q !Ճ(ÀAO )ߤF(˵g.(~` ,32: mn) YHfDQc20r_D;qjLIS)bD7>J𶮲 !Ʉgu(lQvæ5,nk*SE5R8 ZFpXl7n&lI ՑNY=)8=YkPuѮɫT2-1FmpŐ=e!Qi ' we%@* 'l055u@0mw*3ttpƒIrk_wK qe{h._GBj;F=!=dIXhx9-O{ZhP㦋ժ3RMtf˅vF8z"[[UZ_\^ ǡB_"].hTa%Z/}]>WekndhQĹn U_CK# sܹl qbg{ڂ]bwv/mZ35h +0YNɜɵ4:_aի]Ԫ6uH*`2SӡW>\9}ys\Q]Tڅ/] ֘Oeȡ})ӻEPl9a=}tcYNr}B끣l )pi-[ ?!26U &#a='5VA|@$ D)- eR2#wy[r'[[A'b&?>+QH)BM:ާH8>TV G;> 55gtV7ۡ^^k/V0LccOʏL>( t8tl=nCf_O[($؄Rd ! ,~#|06e=o -c|>hfn1KàFQM -G1M*#5UgS }p^}JP,LZܑS;L݄E NxÃV`yn|3ݨJ AvkU-)66~Iežr/=\@cP*P ǂ5UQwL>"=x=Sb?/#GK{?/QGuwȅ>|n2?G6zYT""P? 'ɐ՚>0'0(79t% ItlX k_])STG(9SzPP9ix߳G?3^A{l`i }6N=m<6c l5W2 S~mtl @Fgd,N8§(TkCUv.!Fd8O3cS| p;ɨ Gz;q՘~QĪnpN3HE:]CoI".Q|$Ƨj5d)Tfڛڢ-͆=2 [D':Giz!X&D3<xeu3TL*i@:ߟog\ X#YR! b)j qp뻫K/M2hS#NU.ţ_tH)8)ZlHAqA1Mk Wj]ƃ,@6?zIʣmx03IpR4}wE+_ t&3}&65J++MN2ȊЗz-1*5-Ľ%.NfRj8#vNb" ˄+6KHe.率8y*.yᡇ<~oiQhC/bє(%aW Tc6@KOůWSŠ<9} ]vMFĺ5r<" H_/'Ű:\Rcf.@pfc<'*SĔY0]i;x]i+`,G=j1xP~0q(.njgUDWjBKڛ]\Vc]\wc(mn lRe7; a&,;Zr$Үbϸƺ:|pt ?iJ^X]Ͼ}V{9%ӈW^S‡c|f L7#F@\-1"w E=WaD/ Bd'v{'!QHB&t7vYsbzv0\/yDLTId~&$p{n>[WO!pU-坞6(=fZrREDlfI [+';ù*bSfGY69H$BSUٶGDs<;bQi] AȿhTWW*ҞA'<7[aCD!RUU5ěwЯt1mX&άjB;n9 mzmijU'y!䰌 xxayx(ޱ0=K鬠 YiI_q/L'Ņ40k-_ޤjT}„|gӷ:%Xcf*3!X3gx x^PQǮV/m]7̆mZ<'a0f=xcH3 Q^˥0CNt&/ 4AF//{)ퟲױgCG3d`P=3s M(d+ҥz@kv U"&V|T:"UU=3;! P{*#lRcY bBPÎh,;]Cd3F݃ bLcX%LU2urX-`|͝{ ,bK sn]aȧ')Seu DZDkZ̈ ~eIn+P: 5h,[t vGT|sP=J ͇1>z qk"nspx@ mhu9}WIPe<iá1e/5D Eg~;zuYUcOsj0 α-%-n~p0ʛ("XNn&RhD.ԕT#Y$_YU'OzAьItMP~t7 ~QwlZf1,"b9,'Y?_ 'QJ=SZD~֪F>gOhoq(DB ~ 4q z;AWd#Cʱؒa7e<1k = ͟~c*"uJ5( ^] g9Cc9Gm =1[ m;cۖKCوdw͉4䍟q6i>Ym,ZS4gx:&:%_q*&#Z:u & ~qLW0Mv{9CxuEG;Ea>lۮ*S$Aty ՖMɔmRPPoYxֿ.B.0/=c(tw70Az‹BH%]vt>ut p<7Vh_ͧq;wF9\2ڏOOŐ*:[GJIkwJxtApY}*hS%M HlJB:%KTG=)Jt|ECS<Փ )n- b\z˛}x]{Wb s8^j)Xm*߷%'~ό@IӤ/۶ v,jx<l%)Np{O0O#!?|_|!c7jRЍY2;}}$Ώ0V9T0gUx?nFSFQ1]CA4y^T@WJG[߿}T!$DCs<$?<;h$@ y SE<]#D$`¶YJ{Ne=_>N=4۝qa7NY߸4T]Et%:bcmC;Bd'`1'̈́,9,b*2H_V 4a Wc{\>a2x:)9)'a"]u"4f8%qˋ:Zt|1; ;/~b?4V[RNx6i ΧO&usD[*A2VX*۔o8jGFe@YTm!1ߦ3 *]Ϥ1{ d֧dZQp<\iǛ˶ۺ4SWd}Wae$1u,'yX?oTy dTx\ 1LHҲ4=v E=o!~3 r$R.dqyv鲪5ipƫ I y kMܵ,jg=L"+H{o oO{zyHtkx:CʿZ"A7fTȣ]щ%¿$ dGLrw 7۔q$xkĸGLTJw@hiq"7q$!3ITDy0VCaWoٿ~hOڷ-F@!v7vai`\w>B:wY ׽toYDP0k  6i}/jsK+YA5!OQUb7t^F$d)pv gte@OsJ Dd}K*+,G(7&iT31Gr;8'3"n])ԃz6DY^ÃW\6ItJZX9i'J5^u:9dlDpxpi+G+Amog-$mbvT":`s͐?z "Z;ۯ/@KX$ #Xh4Lh8 ֟"gK–9M޵2T0TdC˓gK˺Kjw!Ϣ(yr GdM,7'(a =܇_,-1J(n3 wIIoD{5S3~XM…h|ҧ'73'c*gPzX(`]is)>_">evv C2c  B!ei0KhtxĕvY{2꽻DbC-Bb׮vڴ,E(ˈ\7%|#bDAYxSE:TlX|ol*vUr` G:zQ^XԅU.pcl9|q#ETZ@V~(Xʟ$<[<{YXS}Z+ﴱ|[?,Z pB>TtX<#Yt\H?oxρdohgz''VT( ;ք!խVD٪4Q9fǾfOl6Ԧ:0QoxsFEfkiI@w/ikBp|8˸৓H_q`H& Q&U~ u 2KTNo$Ӝ oeXn%&kgO3Z 3+(\*P)Oqz>.ۄN["l9FTJܸhԒԢXEVVY6ߊ]/KC?]vŻ`4Ct1Y.%xѥa8\&$sJXz0SNӱeޔ8$@7Zn{Z Uk(l2653ђ/Ӕ\ʱއv |qorO/7F f|Sz*|GB@:07r@?sK7 n8{\D!iD@ ㈇(ka`JXy)8pZ9G}sG?s]{yaOWŏAsuHd`7JX *3ZԏֶB\e(6Iy nB EBM9\) H>z.~Մe*q%3ɥyS% \ݩI d -7/ZH\=Ʊ$ ʮ\˿I͹=y$b(~ GROVb.w#d>  iҹmC&1nrmT^Bz'^L&2kuMn@^7mT9VMEݼ7y[az= y=q(]¼rvip]Pigy ܞvӳDW} 8>oޥLy@a:0'_c!h|'Xyd#پa֭TՒ +҇ [ae]]hZd W tGn[DyDמCB1`ް: 1=Y-V g*aRW{/5ۿk GRE$/჌Y Gٸvb!M+R|" %}@F\~ d͡rI`Ըv 髖iTB)9L&NL٨ɑRfaꟸT/!(jD ~= >E\ƭj!( 0c~>~A!= DO4j^[Μwɗ7eGԼM:cHܨ@1dF;#!FH9 =-¦ϑGn jĬNJ cDɊQ2 "^o.PKZ6kPtےczRa >Oz%b~sa"MּaKKĭ7U7WDЈ# ❦k]\l/ѱ/8N6J uT.fdZ9oPhq%ti0^:HU+;&qh-v@Jt5/yбm\@Ҩ[Lйi*).iWQ::\'|NaFYJ^VRa@NǶ˸Fz3s\~y)KPc>9c]뉪Zw]2j;J;," SHb9=7 |u1ҏ"jxf/g _P/=}_`_2PP\[Gɰgߔ 7$bԈjS8Aj%nqU = CHUvvGE /va>~Y,Ws trzpk`9a蔞DVU&k,!d[!j 2NM\GWl!4TI̦?sJ)/M3f<)r? gar]%0 ӑ>2zl7JeĶ{C\[6;2q-"fc{B z-ӿGLy;>KȦ(ZZCҙkh'6ce ^8>iXN}_硊~jYOYyV9P?b +΄COQY4$ 8=Z^(nYiJl+]h}ɿ0hTdx,fc׿]gw=qNjxFtc&\g;IJbyCΧwӡsHat?`8\`o*CBKCHa1d<֜'1ZMNU AV$GQ@^K|S`mRV.+&vFcm6_L\%|gY>6R50(@4=|4~3 #d8$⣺B E>lu/n:ǡr#9IWe>Yv*,nC,*tȣ留];P" DV|ɯ*qVx5뻐 C/3G)"-O!2aݞNj{0[/HjLWo~t]ZЗ?oѤKrv'Ezs&j|_DO ҘuHZNIm>fJN#Fq ԶTmYKٔ 3(?v/3wH -*&n e#GyEp)u |#c71ꌕɟf7vĮczA iN]0igNn>Ȼa!TDX/oepyj0^sX=xŗpsyYF\/,XHR4No=7 cj+4lx{󎢅K{wEbG%j 駴-ٛ%tim(]lA\c&}3ݥQFO7/vkOp[k9b k-ZnS{]BVlc(uDM⢊ ``HB6)/*S aFpC!KhZ(Dm8KT& 6LjUW{U uҮt43p]iU Hu3wU^IwqVayF}qGHv2zqIO25L9_W.xf*In3n`' g O! l6䎱L[A9)qo8vw9Kw.!RRvFJ֒%,&.EPCg}Nم'q&YjEϡ?HFp"'K#!surKCΩګ; `fZ,>㤮qk_jbd>D.['8Aİ3 MhCAW :ðT%gxkB/9ua#*jh 72x#*<@q@SfϪr^nPiNmE|te_E86xg|b]'uV=ywrk3R?CT&G{N bRg}8OHl1ZM633{Qҭ."祅ʈ0D#T)0{ᗇ]fhVFamP VlZ7oK nOG"}1 zz?HL*fRLzΩ,GcàJ=ơ!ojlQDw PwI.#*${BkG4/OMv߽%cWI+eD.zOjQ|FLR]eJk~b(Jcpg 6 g4> TW^Q!,6.ʵ6ě&Dk`#ޤd_qWK&%s@gH8xgnB=`-q{K֊᪐6=QM{Rȫn(yRU-J`P:wiUSOJzZt)>aP鷉mF6`V!5`&Jf xQg3Y[cRIp 7CitFθ31~;) ~vEWRTmn5|E&7 dB6S6`)w?yqjF$<|iAt̥H#ɃviGhe$'l|{niվ{2;p8[nvR$C=i_D0 M -Y8~:Ӡ.-2XM4`Mz7d*@oK^Yg'q "bnם3H^{d^&.me@ܜ\fh-ÐLlJ1h^JKW}l%(~5c'3$;3=Y/ޜCs<ۗ%EZ+MӟR#dJH2^+UX{o^G9p W,my U|tl>(L+Mwu/aJ= \vsJmy;W0J9#i>O)ˍ^f.pW KD4k+n ̨1Zmҩ0z B~R쥆`ĉtgZOI=MPGǺk}sǕ95 o7S'ՙ{oO(&Jztfl%fyrηQ(tshN vvQјsERQu:5B ѴdNCXrRNԀ39' [}Ɏ.w^ r0eBDBҋ _Izawn~Q }9QަhP=|뙔㤐PH 6m+rz?k$—.M?ʑj <3Tq*Ŋh:'?{Xז$q[_"nQzu@wKwz0HPo0 dF|yWZ xA w~OUocaR,#whGua['wAn#gK_? HJFqXᎳTJ8P@ƎhT~ţ}9W%OHPĊ.[UP6*bU9קn\ӡ jE 46LKOB;Fǚlx;e/4稓?;B,wfkJFIMRTb4aI~N ;dojrlE_EXE<}vEjF:\BR[,d3>+ΰ*}orŦHd$A1* x4ɈizX ^y$$<9 ?4K$57I>2PFUev1()RC¾ c.t:9aJG_R˜UU(I;J?yIeg(-2DISnuGd; ,'03\tW6vb. z ӯ{@w^UxTa .;Ց@ |c6:;P5BY-Yct|e9xq&}2?z i97+Hup5cɰ_?db^}/G>nqv/ĝ0zq/&ތ}m;, # -(8hqDp٦o Bye*s2j'U&kV0ͭeQuc@w]h? =;USBC&JANSG8P,t93|k΀ķK `(2B'̫$ʛ1T @,KmMCm_W]լ\76CJя3_iOu \>gyz[n;h7PӼɬe-L8"̡ݦehUV)46DPYZ@'o웑X <8i ]?ϗ.o)~WBX5wfa2%0nנOp8>x;Vb[EX!rğYSowrPЙ5"Gpqt\w~a!lCmY/I$9Ϧ`m,jBCExD)X]58$6ߋޮk 'QMHG(j$9 *^rj+bz_?+-Ejf*}QbS~Mm*f g0b! mXF4p|<X;VDhRT2&֦Z &؛rmUQ~SQ+hVHՍ*J gJ`=0[0a uiKѩl6My̯V\$#N tZS\c>zF0n/篑eܢf0[NPKF0̾$uي nbceӈ12n{zGEG1nJ,[ }KD VE?jIG<0aN_mCΆf @~~Iyj^EB9{A}w)ep5Jsu̫UjMo5-uiJ^+Ǹ ү,#7|;I52{Q',V7K j&rޭؔfgJ#iO6q3Z{VOok}t#Y#d Ʃ(Im&7LA(!e8 d?cq r@53HBVsg|!jxgK0 ġ{K.wOǃWKCJu] s~?H{yB;:-S D^ZwjgQ9U aSåq-!9d CޛZ8HsX *ƃK Z0&go!=H Uz/8R+KK@nC~º58}!R~i"|ba4RtS?.ܷ(_5t%s> XvNU*^-y0(us Ln>%jҗ 7R5-85^ӯ/ˣF7Eg-hClJoYz 9YL͠eT̝(#=Pu7ɎY@ gN?_֍@Ho!N>\&[$%b/N"h5ZtiEA :TP,DB1bF[Ϥ4Ł] HCVGp-eA"e ߌj^!sO:KCԿ {tj?JDDazoe% 5#m ݁sݱR";IҴ[CzaqG*i>rYrM #*;ic,6rKqMP !W퐣Na2WK s`ڭ:'p"V=bԦzPaTjS^b^ pC9mG2"EK޵bwHTnUڿE|n=Sϧ^m.è6 o\txB !.'VBRA>71ބl*IO : gW)yM~k׍04oV%IX6",mھIc%R1z0T[h}<7 OIǻdTJÙHm"m\k?A'ٝ;' kRZogLՐ'z.yَ|jʬmp>M\3̚JjL.Lf}fXvkrL !=y o!$x Yy-Pۜفdu4pZA[D 7Mxz)26@=h6(֓\I910ki@Lѡ5ME-/U|- CI9. >*F81%8`2.ҋ2f#pȫ,[ Yy{1Ym ,oS~/@9b"Gəʐ Ki%ԺClӵEʄ17^myxPE>20!TZGDƅau.Ov/1٥icEh9sOfC߶[ Zخhr,i~Ŗ q2)H%"4m8qU3 sy|Z"j 4>е`5Zٷ{ =>Qm_B{ ' \Dm% JeESݮs !s5N:f;:E L i)}g>TÔeU1x7P*U/,.pcutr({ȸ{];2 SEJi/H 4h o~七.jׇE+ãveF ;Q:ܴo8,|63 {pa$:*L=c d/`vƹ5ɍs5r#@Je{R)&ܳ zC 1X#f0,c5+d7nʁupLq=@iT`37s״Ft߫eut> ?P@*JG0(C2cIHome^p\Q8bN{<Rt@-}KYoG:λ xlWEi^w/e?]M=: 0^[E>5ĹQTwSF:D/KaC}F:F`Ks1Y90%F$dJ[oOUBcRj5*ې (G jK&\7,8,nhE(gQJKGpXSQNVvJe5ӖLȆoDf/lU - vq>W"v q?2BvGIH7!!LWdޮVDZƍ߱/,ֽm,٤?cR~{5%ٷk[0q]#j )M?Bk铋Aa"76X::mhkfe2?X$Z%,j.sEYy{kݻy ^:r|/=#IquU~ gsU{fՈ{[hQpgmҝn$u`=!P=<6ŷ>6v1G[鄫7KzW^6HƑ]j+~v&.u  ARP:b{.wyKn1G+:-ҙĪ |_y(<{esSkI*d @s?>7“P&MMT/yԥ] wYSZfΈQ2HR KH5v`qɏW2R^KF ȡd$XGZ>>BY\'rQvMt}52,Ļ7xgne9m(noM5Pxef cx2DJ.Y"27?&Vx:+@BAuFy.5K|:~?{-(I3~ QT-!ͥJƩ}J\(?1":yXf'Ć_ sqjj2բ;L!-qpn߫$_p^&#;whzz~i|U ,ﻫ)(+00j7C^|q Vi;x_U9 F7꼼Q2G,0# .VχJH+֠*%e.>$'J#XfQf61$RkV&lTni#*rWZ֠V7Eti.:LH{ޞNyv JJk⤑b tbȓ Sx^b߭G9ْ@p8UT2 :ެ:BU>ŞTDcԨɏp7]L/ʤE~O\$+Pw{ @ǃaf{[qU !Jb£hy9m,s+D1ֿD+5X9%v3fDD'븯) BvC O2!a7w\A|atY@WM Q#˼D?<JhTxd[AquH#P߱Â͑&Q9Y6VM3kϳ{4r۝XOZZ1Bf" ,&U{~y)y:c+CmgrIQ,8gĄ*n#%r/D'7m mcd5*7RFLLY8wRM :6a^*Lv_Й%JUj9%93dp޴YjZso\RZmkę6LlK#G,j?1=Sr} i;yBjGL\;S^<1gյqFb{s+f47(zKݼD/Mzfh~֚1r{Ɨ 0> ASI8ӸT_b*wRޫ7֙@Qq9FѸ bKu{TS3T{&?H!o^d,Nr0v`5ncܽbIsT#.a`;W+z7PS_?sgNn5gdYW']oэP)Ladb.OW- :WF΍/m\̛턲%TȰs2G+XXx+I*|1:U]BHPӉ!%Hmÿz4<u&/gd|6ɮ|FX§^p JڍIJjwW5 5h8_">K#SSڜ[ $4W6w#X:v>~oh_TZ2IN<"KJ^ lK{_k ڪ^.h-MlbԠ|*]Unkh!5s;(=gS/.?%gN6u+Ly^QH;wr:15Nz#?t}p7*/:w;P3E+xo2l֥ d[6ssG҉nocĸcyJ}AԆ^\PR B! JD{\it)c6Y#0Q%MSaUcw(+Aְ{q$∼Dxp3n7:jrL>FY#N?X꠹4:ȪZipYOǵN;xγl-o@c.K"2#x @y٥l $K!|QUθ_tu>x[IUE6Rwq-+>X~&6Z0]}[g~oo+H|,V&V;V8[/HD|[ ''0 u_Ճ/3.J^L'\!̄ avf/::\j n6yafÏBS͗RVlaW2fΏ  +/=%Jm`+nK /9k L*4ǸDb]V Q-h:##x^}]PeI:2N>(+ATD )!Ottwg,60>iӃgN-olia,Au#!m@<P0a g'a"B׮'Lo>8_,0XZ*ם8coSdퟦEFLe4g=pIJ1EQ9t\uc>Ih?pCτiF>'/>boJh le;Pzѩx.W}E,(tsKE:kٔD%"PɬH6IHH0Lɐ3@lz%IjwJ}mGO6S]fr2Sy_?tϔ#)Gtssu҆kηM/mV|[mڦ-則%(zœ"Z(fJOWG1PHY.X*"z|Ò}uOismERk9:,롇&8 ;"F$%Vg?Vlq#S>U!!g@ˮ]S_Z?b ctɀWthe2p9)Y @{.-2nG%t6#}i VٺҘg'byTJ] Ƿr_)4980\M'ְH$Tx t0 t5j8Ij݊rL0?&4s"#IŬOEPSzNYаI/ca0:E 8h%~P9MI2q!\ ⥌u~HˋsڅQ#&N;blK7(}.?Sb&υ٬Eǯϼs¡o_(o'6Xܬ}tQҫ  R>&WU00^-")mHE&Gf)ON;vIK[{9-`m&Q~0ɱ0sW.0~I?&\„ V]nn| l&33β[ڪ} 3U᧗i`:JX~2,._- >觲)TnK4S:~2Zfo uzxQE#RWETv{Hݩf\nML6aq?{i0O]URвchR39LmӪ׀M#6 |[WXnF?0ߛҮhTzn11fȎ ߄hHUK8|" k _aA7Vu%z@tXT)oWN@c^,Iod--,X$ .Tgqd{h&Or{$ý&AL iZ2 TsލP @>d{a5q!qī䱄ԏ!"z{ݨde@[<.DWP,͸eQA5N)H& ւt'Fz њAm1@cE\ NxV:R;B&*(jA|f:1.ps\8a񋋝Awuj"`(Dʍ Nh}-[:tx"tM]1‚5BhfWj sK&6+N7jN\]˽ʽ.|Lneғ% m2ݠ0{Gt" PɅh` z=bCPƣa _՜U?+J2gQŞ_- n_L D3;}&oc{Tg-ڡ7W5EB` be:/bY Wp(yHO:{biܿZm\t h d =l}ccvs4o$iM"[敽Ss jRf5 %]ɦW{=m 2"YVc+?"af2wr6b\YsA ߂XOO#UYT=C3/N)"Uuxܶ?-ֽحj@}Q~uv;.儆/NMjogбM aFݟ6<)#a $0<5ߗvM!͵`y\}7E];u5[5mP}kĀ3_l2X?BtEmu,;RO/*">=JB,f{oQs|R}*`XU52lD6PO/YT8^E>;^zx}4])|3I9ſ38nf!  \HE3z% >'y6{=ưE51Mr<{@ 0i@QQ`e-.ZtjXc_'O[3lF/S`[#ZoC?iŧwغ儭W05*NwhQW(TW͍y R}UU=A;{6z䢛 D7~/WêuQƼn|vK6~w~PX,>ЫiJ 49 h0h[Sƅ?99qf_ oS;1qD_jt/? ?gJ4NxBL>c2 ܯ* ػeKg#ϥx"$ 8q|-YB#z҅ RLO[0RjR \vHOِ˂ž-} MuvYc~$u݉luI`'Ve!܏Q!N'4aDqqm]%>z=Kn}O)Uzsy,|%@`v1ea+/|zි-W :Ѱ/I+d@"NQ4ޕ]HC/(Ytw89|~$7NNEDPaI%L>X/HYѡ1mfr@AEE>?q]h.S!63nj۶ E $]-怾0*:؟D |01n^\EߠTH}]P޶(hR?غuj&!s^@> }Ɏl@+Kp*j>}K`Dɔ ٪ўcNhDXrkz[ l *ðT24&XL .WIui%U7CmUKP&XM=8D>K1* JuC-u'pS`!',*W1' B0`i*h苯6L_MM3 {vcKSꖜ:0L }KyYlt\VHaAȒdGʪ%bK[#7ԅ9QDo3WVpb堬 92hsB~Q%j2pO]jx/uMR8=L0SzDHG)Y&vTJjlްd` PpySyNWQh4Qbr-|!VD,-A9`B4Ѧg,uƱ Z#x`` Ɠs[*1yq[C*2j8t-+>y Z% ?~ bE~X.lyە@T᭦sjy-νR0Ct\ʺb7j|lq1y6A_|E3}!ΣR@)`$2]jSW)%`*+Xaʥ'Ll(=StM_FV,d\m,JeSQsSYNTр')FV9»'@eQOs p NJ1fjȵ9)> 'q4LPՄ2;6E2'C?\ĤN6 gӲy\kj}Of~QrPj:W DYUgef$b/5ܻMj߅n>c@ HZuʉc)mhr/cSQX;!TԻRuN!M}m<9r5yVVMo݋EB7[x~~.'FƧh2ZZ>zD$iR&r4 ;͛ /?Zo[ǎۥ`GD8se@Z+#}_=u%-6D&QN|x4FE;h%1u]cwh$N39a)'C%U WJc\84kх4} B#b_N#k 5~f V6- Phev襳_z]dmQ3M0F wn 9WĚXHMd*j[|,BR59bjm093e!ߍ=A); z+(wr93j]OWמ[/]t͵u2+sP=Y'װ)=gi ^O % }a|%\-u Iat@q}ОWP:"*jhtׄ7Ԧj][7=ȁx $CH8fPI*1E9oV˫moBw (ZEd!xO_xNIêLZ!=H;R] a;#T Di\VMVG,?VLOY/ܽn,${ "-5^1\3t٫ō˗l|'&;JbqFnm~aZ*  2b m_&C7j(::>$́{C[DA'ϥ1K6YiTWcL1X$Xe߲A &r%%6O:/.JtZO}TJlRR)]рɮ SI0e]q_jDqTW;zf."L dRFՖa|gUYᖞ*p⳦ bRķH5v|BOAp u{Έ)-DCAEm~ w1gq1#{d*Ri7:}4G|_&5DV77!RT.@~J:Վ>uO4{BihBc~ލ,62oSyBPSb<-=)k#wA^ao>u>KPPQ:fmm<<a]!Zp!(%޶&r_`46臫"r>,|#ݠ̸Ƕ". m"̶[AfJ)T[<6R|Z9<Ѯ&"ѧCY,ZsםO%|[}E3J&4zԭ-&[T-y9Ǝa h,chWS.h%:Ȩ#?dkN$/OIaXa[u\H1f)ޞ@JTJјM7/z ]5}I36J{e- R4A hJ9{//u87}4 g䫌eR +}.XMbAʃךi`yL@UIiʥ}jڳ!h)Vne92wjKN.Xpib㘟K)tl ",A :^}Kt}.#WC[l7 Lx&tf*!#67f{'~ɼ=p!sr0Kgo} ~wy[|FEu5)6M]3 ehzBjZ{Gpd#f n$|>;ez3e* 1ҵ(& ӻ]~KT c(!t#J~miiVPMt+~"q Iq\B0*?cQavW֩JDNЎ-טDae(MhLG#cQ:M%TMz'S |:RIF^V/1~cu$,rbyJܬKs`S3 cЖqf0ñ1_7"Q􌷷0_7E;sX)e)d!X‚<`bbwQq ^= 3h X Z/@@^{ > b<p!\O($$F3gA ^l['Xu5+d*Y l #mJʹVX qX (dGhQԯ6lWS;E5^p`ÃQإ\۲|X K S%Uꂫ1 Vl%,醈(ԓr C.#ϸw֪em- TwpZ!<-DV({A@&gA@vRv䧴SFzHKD􏽵2g05P}81+1ܷ1-qhA\ 0cC[ȠtB 8sY*Bӎ=Y5Sl: vR"SFSv֕8#وFܠ. xsߚO:/piY)mcHS$ЅMfd cbꇮ#)~i%dP5 V7'Sz# !1|ĨxNTDl,z^R`G0M]r5|OE<[gَ&^.* pa<ܵP!f5W C@|9Q!.(QͩS:1Q$l]]@$EEi-zq "ڏ!2Zlc#t&F! |DxkkUq>:~ϠgD+6Z'ֱuh3Ii,)`dY0AEiSϾwM վC%5hLOgƯt*ch<!Cm(8,g9-zv:QMRO0rxdy 'f5H)p,8@c>eb#斵ҏbns1:Q'9̲\D%RRErD325:<O00UKA*V3.܂QptECU(G)#mv]+l>?w? a[ 4ˏ_7(x%Fw PB~!KIݔ 2Ln5rrs'YF..P!H]2E,y!X _ep:톤x2L%Rm)I\!T, \#WIGx k/{?O<4a!&Dg^ 2񾥲`<eϙq0K3R}"y#|[D Nܲsji(.UKjctٓūu>0:,k Pө<Aؚߘt"|Nt:sIAv!$0YfΦX]/!SϦ)Ր8i{W ~e*B.e5Јjei&0 ߞ3Nsxj|W&f` g\_[X`'i-t2԰>eb[Ni,ֺ?m݃NJ{K(O?"<ۤBs!1Ԥ?jq&%t ,9@`N<|x`?yQ .™`GާvxQҒA]{JʲӺl#Vy2} \+Gral_PӎwMw>jy"w|!+%Rj*G Q"B2\5o#C4lc L >FJy P/\Y[ xv7(f H⭚{7R“;]!T-\onk%iܺD(e:.k'7 7,CW}(`VtG6PGJUÏ)GLd='|^a. ۱oWR(I`^lk]Ei ~\vcQ"wx J ]>n$k p+hHJ6dYJhsmgPV)`"5!"`<2|5vsmfJ"=1dc])}G}Sh|x}^5*SJ+n 4$p3F'82NږG( 8c51s[N oY4*G*[8lF.a؝vPgmpCQC5N>bA)ck>Xre)T~#jS|6ʣt,LzxFeE4s\!gS]:S0}`e_m!` |V|WܱѐT8Wr߅ iw6/_JStR[ѪU~-Ru&m?@9֓Wq2ĽC#CV I#$k?eg@P>+!C6S p{zг6{(׮h(4"C )i ;Gjj/ yXwgJB|Qs癫> бZNbbm "9,& pI\ ; c :ky VJ"b~t@OZ9n[ :fBtϥrFFyLvg/w$z ^7m/ Az ƾ 1 :"Y]H@ ov:RqyV m^rk339=iWhm*b. 4qz&b/Hu~~ToA^ uaXI/Ԟ8MOqz@=_c:雊m@]/h*`9`x~YfwU-sQhkPcCNJ,y7u_a@_ܠ6 bPz{/I,D"C#8E:yYUKnXwBamǃL\#.kّ'Vl~N'n*{@.l/b1aҲS h\S45Dݝ $Rm2u#!k7 950|fFb$bI*6QyɬWNg2Q,ta<ci]?WxlXz H2 ,6[}ft g$IpZC<@8:X(3?ߧ65y3\St(#+ÔM,!No*+?Q'a C+ol`(40(Mbb}~m ٍg-ՒAh=Q<_|kvEx&H^K\e !B'؋:!S =!9oP ӓ믓r=LV! _j#Gc!zxZNtDPDƻ {aJ\a)q⟊azZ{A=lU>8% QnIgO2=veJ kϪ*?k?(;n"rIp8բK~@Z/!Bqd!̭S{}_uW4^Qe?]j.ok_8Rm]Pp{sՖ8eǚs cI6>K9q𮏲ld*e'4h*n|l4 ƍ-ta:̐&3d|]q!Nm{ u~?RJ|YƟ{~ &< `xH ֺLRl,| UF^Pi(ۃxUr.Ga͂y&\2|O37`>U =}0H ,N55j8J28'og?8w nss0>rSGBAhn+O<,(i|e[ujLӂh> 5&bԊ2A'N/<Y'ѕDYn}0cNsIDm.uYЊ"iW)>nT";xŪ, ?oSоܔa TQ:cOrkU*B[I,CrI$B+`ZDZV95=I- "̽SV҅1$xFrZWa~s06[PgfVH, 죙A8n?% = ɮ)3~ص֞ݗ%޶7 G8'š bXF}lbD%Z Z`IwTom%M}Q %L&ʀ3W*NSٷSЊj n%o^7빻-p&7~nf 4 ffڟS`[ 2h3;Sf'j͏hpc0@ $]YȾ$d" Hq|b]`Ev|yR[D1Xjj}10}m(`cUuP :U2@LjX^Ң^RvJ3aRZ,Dg/`A< 81Q>fWΌs 6zvjtCRx^rE g*zz'8It2VIh\ϠL"5Mfns!Bxшuix~UxsUK..:CwkŦp 8 L(?>1Өu+cpm?,$Ok$:/!Ϭ3HLHն7lٜL8aH׃c,1А ևH-p g\k@>d]eLq;(s]ao.xCu/xEըݱ~kpbm}N.YEx3oRLT@£w0QKr[1mv4c4ѐr5Ŀ"ԛܫD"9rr MƠ I7 h]x1cW>,rבjPoy0!R\ g;E{.GBOvzQɛ8XL텼f[z>֌7X&sж PhQBlq5@6ۿ᝖::n0XnMcw C2 +̮=;ˣyOjG>"A[JC~][Zkb!Qk3\o,ߟ8RU m9V?}5B8vfvp(̄|lHхFo*rH͚%|fqJF@[[0E0(Dm8IuIun1EV:8qWKRb~^a֩uA4ٸD$B^F4seQYΪ:=V(쩚M9&.GWvCecF{lNz-x'fۡ R*8T:Ppʮ$M^pe /7g:ٺJ_3'F ZÞt;&7]=tDMA ƒx#t|& ~#^5(I5o9?K+[%YlRVC_z-k_ Tn@T3J)h6o#SI`H= H|bɞy\RͰfNzbHć%"`#ȉ.BJ^k۠q4>Ndˁ2<4Pfjsr{M}f}I &Oڙ~SaYH_p$q(BDYE(d dD2 Y{TۼUy"6)W+m(eP\,VhI'ɻS- ŒQBWlH iͪFϹpbݭ"mH-9v{迯 1_¯},lӑm>|AC =K\ k v?]xm9Qr78td nK,fOIK!czAL7RlMGqUM@8v'k8l L)8@\^o#5T<% Yf7^ÒS!i] hM#B+H>*V "2AjHcFjn< g+_&UpXXܤUa7hg~Eƫ4[xk嘀l"]Rr x[t*.7e,l, j@#ߒcn-sN]6_ɃAaŊZz+`J\uÄfxwpZܰphƐf- ap0=. &r~+$}*v̛,ǥ4&6 Z3u{:翀š׺pxOXfI`Ljzz ҋGxR :KZN$[Vei*p8PZaOA?0p'& tJ`L".HzPDX02XԤ23=GEhGdn1˽+inȶ{P\)%^fAд.nSh} 2hkX$II啤\z_b$̚jj3qqE+E߃2.|s"T\RfD!|;߿ cl,}bǣMcX i4iA qk;0T{l%)㲨x~}`P\updB8WjtsEPE"6x+!qaTwhS%ᇬ26s;, :ˆ8~qnLѹmg6HLCɖ"sAI%tXs!6hP,l7%4nW{XTRh o\\ODl:I~=xd'fba/5C܌IuAtN 9{ %ԙ4ng{}*9Y(SOܠ" ľD!7Hg"WG w=fYi(F͟Ně OYZ KXi5ϕ>`)m"$"_"Zg=HB}JBy$C;?Prc_5NO<#T3W/WrPW7xJ7 Z¨eEF$CV{#J fFirxvpDagQY7[M8oK<9ʴQT 魀ϸ6Gl3&!BP$ 3WЙ٧aۿ.@jƪX%OeɗNM!ێ}k ,ǯ.$ Br1ksԆW'hm`ڼS#/kzq!. T9C|C"*iՀV[zͷP%Ǟ9]|@>Ϋ=70] D0xňlJ&˥R6?{8+0[lMP + T™N!V|7SIB=jwwYQHYTqPMG4;9ze `g5}Nz=޸axĴg^;#'R ֑W!5Ԥl7[MGWS3+.EeQg|]9 VD}}B)D**>b\; !υ% ?c~gF97,vCjD6-گy@m5ObE_L(r9iι=/:CRڀ2ch6 {dS-U*W۪Dpho~BP>k0Ud9eT/4Xro>šOq]oI[0 1U o aœYZS J'3o@BW8>g9 < llLdF),o:7ۓ 7|B LqOd*!Fͣϊ,0 2e3kªyWLg'C~L mZg?NÏs9]Ʒ8D{ꡱ';.9pgwa96' ՘n-ߚ(~t#u/1A&dC!{fK[ϞHR3@w:GC9Q0m3=.'>9$Z\2jD6 ְ:1oF_9 FU.UIlN@o"֏f^k^bf[]tJ# E!f8fmQ9k q6OsL-$(@cTL6*Wh6+'Gp+ K|!U]W =@J&l@7,]VRBEժU%;;Sn-nZ N腕W/N/Z7qa_T)z1PǨ]]zu5b-t:eTbBCd.- ֏;\)usL#m1*e'E8x" @ ڋP@jЭzϪϜ;ܧε˸WWzԪKBGyM;_2:{0b-P0-f)4[\F~dX,j/2m(QJ1#ha0\4H bYb Ϣe"Cx.LӚb=:o؋r^N,=GroTHLSSIBy9t J>>@hSC WQ5 Xg(@)l!\:̋SfGG]@HE#LrC]٦\9Aji[.BrmB=:MO)0Sȃ ok)x[>ʛd:V,{:T\4I=,7@O]/',(7bp{f,\kͨȣHqD9gRWXJ`x_!\nГ$~3Ԃ)ټ5uC*q{;/A.6^w$QsV4ePGyr"#/ siF>b4+4͞ h" /W5M:G㾓v}z hKɏZYPmZNnF4 * 6v"l}ASh)s,c=vo 6һ? Sr]i_JVkŤim;bie U 6/0OǩTMp阃cͰY5.21HFS طA)(Hi7[htS:QkJ.\\#:N FvNC4(͊ f,k%Ψg!ciJ ` ?ĄbJ֊Pg/<*@3頪2֠,컳q>g[񱿖~]},hMl"(=Gib|S{L+xU}GhÚ~mҎBL6N0kcOĶ¾UO+PUZWi$^re]?{Ǭ JwSлw嶈!opKO0>0:3j).d83liԀԿv_q;Y Gx /$PtDEe,*-:|ɸM aˮٷ6gu mHy. L1^ʦh[heīY,P 45Zau_Gv''uD0'=uK>i#a~ΝH|$)߇*| 9mrp9?Hګgrg2%t `Gc ͍PYO*}QC܆v/jT`70hвl#" ņ*QJ&j4g'>z/`/IHP``<|,Ȧ'54Рl9*[bjf\tXH,q ч`xc|!l1OP۰] p'ɔȪPS(C7? ,7(i%~Z)Rknx [b $FAxdp Lͻx]Jv| DbF!B"q5W?: EI^묀FtCϢݔ᱇v4|h;7|Zt^~])]0>soogi:-5FgɣlgUH&ҴK2cQRH* ΈFniT8^EA`_ƴh|uay̕XSPK+9)||mPWrh8Uu3A*fUj!~/~c\/NPt Nk{L`y{/mc|gg67+d'FB+]w4rn4_R}Y;fj*bZQ8$^CL{Yqc}viy͸ *V̾} ':CbfmnMd2zvgVp8tD;-oOɔv`'W+z 7uo0JY]F ȰØ(īY6uZ# '|I&nh<ȳzO|ɒvy4ܟ%94A'E2Cj3h,QX9z2aԢ6Iaegz} 57^M쮹xҚ![ʙo8 w'*K`ҡu91x>vV(< @ 2=8e*PDcSQKY=QS3e *Ne3  $b |몔=g1Eyد$|G*Z#}5k-YȌI\TiS-,nu0FQXOK$ zN61˄܄=^|]gW ֫TE$oҞ(^X _씚:O[=ԦpOO!JfP"%5gyBxfC;_Žٞ/a /A>o8<˰i( v{H p퐗 z75fj́߫V TK(v(z:]Hy"wUzB+ՄT簽ʖ5A/LʥqO\G ɁvY'9 Ka"(Uf\p̞vBq3]y/1lvc]y[etX PVX12[[ke +bA4e7J8](F -Gʹ*T&$#Vܟ~;×a]J ;~]wgvCfx6[.[&a8 lӛ+ Ky Sdxs f㥡F]׊őe? R[a> V[ v35k8w^~ݓ8s3r6;1Jgoin}F:ES-ѦQ6a D=# ) BÂbzF5Y3ɀsϹē# Ai ~fdOWWAz8nйHSaa\Oe9ѿZܕ8x\ĩrC]GQOܑVsZ iso_ I @GM//cDQD?Zww\W@mWԢY=㛃;RSCr{1;'ѹb66x3)'xt;9* kݓ!kVw~/xϯC hKh^w(ZbW,SG:S}/㻞:/!P!Y&4+݃\ R{Xo&lv%?bB}g*¢Jhfen@ CA)Y[-'+%oO)_(ӗ:b\=-^q9qvH[o*.ˉ2$n:nzH4X/!kvXzC?͟{ rXe~qMhsR6?(ّ8"ŭįTh2|b9Sn||rSl+ =d l*@l~W!xR8N#m\LXI0,(!-B4BDVA1eej}FHcjJBa3c(>r!}V$ǮK4V}$S*<)Sam1܁L`i5֮R?ps1^,"\6Nn. >1'gɵr Ʌ*bi}.S뱰Awz`xս 5k)$8OI%*Q;2x`h0 1m~E&-mI)Q3%U6I% Fu"V%1SVg9C,X㴷e'Vv,ҷ`A;=ZC+NbIOܾN®@Bٙ˲ף^4r@%[A/Ny$LRN`cҜ W $nɺne"3Wwn/]U4܎=ĝn%4fJ)&ׇ H8@װ?kȀfq}űBAfPlm+xDNNgͳCF]VN5R/&);FH?LJ]UCnjhKyLIxwO恹3raB AXeu$ нF̤(<ӊK}Jomg 8B#~{VO-] ZG#|3@VGqVp%̐9_e i߈fF4sj#mSک<Hm8]>q*3T(hhivI=}]Ų-)*H`Y ǀXGcCU,HخKZx؛C8y2o$8}lot\o*$]_ —m[t%wQpLp1p.|7Ѐ(YBθ`K.893k^YK5{Ϟ1W'mxl- U9k^!"95z· /&H7.q)Un%r0C-+<,U;{#XTyzOաَ>':$Bg|MC!D.A̟epb6 !Dhc/#Zę:>񿮺%ZcFrQ' ahً٩ z\+4@Hۍ Hqnq,ݺ@ ͠6`/'3AF{ #nR7j?>gaޔ}?ҁD؛RY `YgbfdqH7^LHd@`zD& yZ%ζ92$Z>m%3>+G2am5NcIS)"߇'gZ}#qbٹ*Zkb ,yN0nƯFF@eN"$r{`VOϒ(} [J]QźCSqjnDkdwUTQ%ay`mdөhX¨*2OrEWSߝN9u>6K:0VtE\;DGyS@p jarDYKϞ?4^O.AW;f:HenJ\ܽP 4ipdC ۖ+Ce7D+sM[Nnv4;ul3Φܔ$;s%9t PlߙYl0$Y0砂L#j U>$تd :4:4qEQe0\e/NᆺJ@LPPzk*r4/[PKUlj_ ڎk<̂qgW@Z˵lW ND̮ZzYS5jyk.hv>_" v:42ӓL#lKɽ ՋӫP~o-ߌzl.5"2w-CH,o>32וq&_r*gQɁõx|h+_&Hލ6W)VmQ6$B\RVPƗbBqDl{C]0D%~^_nj1sqCt4PT Sr.2 {n樊Lcjzh*9q"IS -:m?a ED: VboĴD&NKlYPs2ZyU!O{Jg=e"6l`z4Rә&bCbNl:QBju  B?(gq@VrSRP(L]ύ[O5Ҙ t#Yp U.rX E4R gї9iL Scl7d >BaF/8hoЉkeHv"e`oS IƇNv?y_/Arޅ>EߟH5=+֭ҼZ ->KM,J#bNyN5I4 } Qí580Ղ[=SH˽C$-yq;*d[ކZ6a4L-2zfQ "Vy,P{0(OsN(m8LjՂ,+7IS!gaJ mR/L6t&O9p+IճOf9ي<ۖk:^b?N~>ԺyU.`րARZ)Z>e_oן}3=G}E *i9E)]4%o,C;e'^-7Y-Sc~y2-SBH';J~PH*nbq=r96)UHafnw|Xb}5Pױ@߷ͷx.2HZ au՛_cB*sD[!)[5LCB1AVvõCYgmmS\"sŽ-N $KTh͗~K<0G]qZVG݅ xp?9oVgp].n`ธ)&ԨBg>zvR̄()*QE%+W럤 P *!$áR3'ZތZ8 NJO1(N8$E݀ǭ =|ER틞hzy/DP8#k\ޗE۳ fa|`Qx0~=jeV>B7,goY{9m-\@H7k6vG'PHS[)RW/|h\w;Nܬ> y7F (̘ht v"Py`: {H0pHEIL>ͲG?Y\|31lFP.z(PUBD2d}lG\AzF')L`C`) "{rH~i]rPdRφw`n"͕M 9X8{O5 ^Wk JM,.4ڊY*͂3O^J^te+>ځJzLDg83WiaI*(O,xFX Uv=J`jR¨N Ƌ3E!p"7XŇE>g:P5MbGX Kg=׺6V w>ך=2/1 Rיzg*՟7k3qHr ^3 lW?RGY`B{D_}G GԲvE# .{.ד9roq'F, ֓՞؞Β>%Akv괾# @'0J8ގ(p4詭'/FZ[/1J?wNcV\AZ[tþEƳrw_#CS!abClԘ1ȕˁ!͑͝,VG aXwϞ@\(O!BO(ԸrFnUoV ^~˪\/dï?v_bbB A\d ÁRΕtX}>X?d]h]nܖ$T^>"fFev%B񪢄|IWlS#Ga<`$`:Mm0?m Q2vѡs9:B'ֺ~xߍ+j{Q[Qfw1ܠ+N+xYRAřn/ewz"%^S)p%1kAX] &o,=47b]Z媣2 uMՖ!r)DESdl02R\\d?C 1xs!K}-`VE ڣLHVZ2)(rfªU. rvpCݲD=jq [ws;9LDyf闈!.$Y,w;BɡBa7dc}e}7V);& Q7ub1Īb=ʓp~'b?oV*Szs#ϙlGl[V칲PaQF5rT6@౩ޤox(Ǜ8 .`|7C!&~ ֋AeLxl`jP+~CjF̥654_L`7pF;@˗9/#Mv,f])UHq(Qȧ||p ]-c6e(Qߤ 1)~ X4巵)aGm,Bڔz(Gɟ64AW9(њ$C/ 18w(ed_hAR0{'emZ'R,[`gC#9SW֌vT;a tC{RovJ:0njQX w[ӥLvR=p54Tg^mIvaN5Ꟶ`-hB2nG9bh>xehP ^ ni}`Dn9Tb`ٍ._&=џjEV OTJ?ڗtYb2K?ͰSv8#ɿfF3 pzE \>2lK%aոӞZkq !3D'Nq8`V yNy~>K~rU>~OC/ze bApwa2 ltk~ˁ(l|ө~^}<`*'4DMZ;Ah8yCjg 7`"ψN1T8K g\-FlЁoR|0pY8K&aqޤ~]Sy62 E3f]Xd-nc[# n@dX%PTڽjHi&+‹-L*@m vUgơi_w\{2ЧRzTS`\9aH>$Zqɐ] :ak=V|X:rӢgD5Sj2,$`3id\S_&+HڢpvRJV5_(h㷳T)+UȚgyCaYքte'R yJwMLTj5 .6u :eŴupb._@7LҠԶ?#ǐ5rSTzaUV t mÒCB?60ji_T]mق4Ei@緦r.ZS羢5GuZ '|Y%@nx $icS~!uypӾG|p9knsIRѺbz rnxJ gTN5EL/`˚GuWPkRnNOG+ڃZ'ڐdN:@vG_gyeW,mS>'In6n۠=f eJz,s; F 9NJNw7\,pP'x,s4ħ@CGbYFmQ+l-䵼k#pIQj(RZ / ۭ&Hh'LKȄOJ ߱Nmꎕ֗]Af4o )'0"v;6ohV@4d^Ƣ`v:-/Ϳ1n[נ:@?|C 9 gW$qMV?"I*;$[2@ޝt1la',;ӿ)|,Mi{t^oKl2FJ;~z*Ioi[زH† n;G `& O{{)c0VŒ'& uPgD6vA|ؿt,`::Y'!>LB/ gMʟ`*L&`s60wHpSʽC #S.&NEK;N[ H`\d I%'xd]*`+ZFm3obPR|Ipt^`$%Es}Iͯ+GJr8S2<#Һ$x+M ,dF{ \>JUsSkԖLd10GOƉoJChuHe~;~ U*e-:d`CiblKf4UyCӁ'|z#iO؃iyѲ})irֲ߿}jDZA5TʂCܣ=#]jꉤ%vC("[&mVm +I\H (:EO8ĸ"07san1:иXz Ҩs&S.pjaWmRsXWAvS<1&XWB <1/Z .稔6Kry_!6_A7/iM$|']L=0Cfr*ː'exI1b$Q($rO>GLӞWۜ[&]֌iYW0 B I(* rEԢt/GĽl]WU:ƥ#f0#ly6vvJxO@ҟXڎŻF>;ˢ wt &pl;PRv B;kKhe_LatD`gEqSR;Ղʥ1h| "SyqAKvL*H~!0cԐP+ߝv * QV #0=d(Ξ"VM觓Xv ,wZjh~+e703zƵ_gf 'ji8;C~șSw3_IRˠ\1%=t2(3wEi}_1ZԻl$ l<֛f[.4OFp+KV˩/?MDa:οjAuPT&&/í QplGaQET_Zǔ8 t==!67ow%Q*3YP$;JBǽU2wVuv$%np儛iXA6cQ@[ļMrcW}f=oR9O|+DL6HU_j"T٘vD4(E7I kH5&;[!댣I:3y~u;$[`n5؁l,Ps9 X`o㞜#L0^h, E;N>m08ϧ{Ōt`^>8*]J,Q(LcyWmTv=#aݺN]r4* / U zL0s(W'g_j{k2:$` ,2FZ^H+RJ?3IU6~vM 1W&I NIK{F}Ûr(BE:(f^,eȷY ݂"I/ _%/b=Q/Ǯ)@|DL"~q(!%Qb`F2 1 & G8"8H# 8bDΤ00IgJ\-o*PCV(MOG>>8DŠ0a{K>ɇiԝ!/ @\I#f,pm5<\B '!vڻp_6|BuVLx^S?ѓG&)%cE2Fd>Z|sybd֠i>xYÜ[BdžAe?ļO3]C#_ Yn^uE =mPVO]9Ӝ]SkQ۟>QzYW/ˠ&H%z[;CpBGnMvNB_aW4 UgI*lk5Wqc?qDϘ/d"uD[]ho%[4ʑp'29d5I x/M 1 -X뤛OYǂA-^h3= #YR[Gf<&01mhLjo?4j,âW9D"Oj6cP/ YGyRas_mLi}u} .#U =EZٻMֲK~Ĝcy 6z.q˶;s:e֕HI͢A [xo̢9.$UHmmW|'3/ Zk/T\^0?o]C6ƒjrЍUoIR /Y_gh=(l1I&KjBQDy/RE b?k99X4ٮ!Ggu6`vqp-/[uo֓} FAuN[z~T!;͜<t)/qBҚ2\f8MxfMdT8# n뗈}f,ĿX[nyL 1a@l$R`edPV(t̹יD%Ԧj[q}Zwz+s0ӌG92o[03FU\"JU;ŷ$m4&Z_m¨UK)x]t|jx"1O5hZ16ⶦuV2BC[@Eegx`P5T[XS2OL?i- 4K0~QOǭKsw&YXq|0!5/9=e9+N63@ׇUiJMb͓^+:rojXN  #y K NXؔ^o'g4`noR.f)x|> EHAؐ@/e1߹4csūAW ZB[~Ӿi69 ͇=?ggi\NCIESCrpK"4KĒyI`R] aW{%\7ڥ 1H릨We&(vb5L59F[ LcNj7< ӁkA@e)M nJy8oXGkE%M9ɮ7h .f36R?&Ι.Pжy|K}=]#Ԫ[u*-*چe{}r1ng 34xZō6(1ɄK*+[1Iw\6:?92R<Blk'Azl"gt).j!U.Ԭo׏őa_ ~L#Nqa9:G \B9+]SKh\r3/gNol(ki4p& rĢ(fz.k<.8W]./W6my8of7dQĐЏ[Zm ,Y˸Nev#3q3Dz׶:=o4KoK}9{JQ,(~_XN3Ř\Y56|0j?~+J7XR-oqe x~xA\[8E_^*ģΉ @VϢQ")!S 9֣lm"&4iV>m7Ok^d7 '|~~5O+F%GFNg[lJKµT`CCX.ZR,lb'-ȳ\֬2AJ]Xd.gbh ćȈ2ӣ8=S[N 6h Ajn_! C`@R;/ dj_pR[DRlGӡiJᡳC3oQZ8<ѕA4R]a?yBN&bpMAӳ78fA_' b0]vnJa:]^ i~O<H}e}&WZ܃Ն{Hcuф9[|3YZ1<0tvU2U0z  aIGWW/.;I2 -A6 ކb51AV$"2qy7E5f _ɟ /hq)QsOϘ|(=*ؤ=,Y< ~wkuV"J_>q =Bban) c8g 0]NEU2\t#JRW@`zvp8ӻ bdps<,C <%.O$;P|\A JXT= | wG6.IKؑZBK |[+2fCcPQ/!Ny+3­OIDu 8Q l[VAqbȾi0! Wţma] )mo1de{Kݟ kf74P2Z@$7oOLʢԨJImmI6V15|DdP0*+e@\ AMtEϠFE#]; UtP$Qǧq]f_>+Q&w t}O2P.o_jz+еOG1mkkAg TpŢ1S RBcV@ v w7&_{PLʐsMyXٕQ{krCqY*- sUu4g(GRtB*n1>r5Lٍ-1rpFM #qԖeI:R#~<Q?3bxw$hAi'FM(9s} w_Y')~U. ??jS]]ݓǿ 1bC%J9+d̒T!)݉`;WCx񳨵69>W8Tgs`ם0;`vq(V?%HhDe-NOeYy8$q{f;qX)[n`8TW)(7yWrk盹zp¡Ztۃl;AjK3 ^s{"´Xy~D!glml(xd{+yP^8/.>yXBBMkm3kˮyyH!P>Wo&=TWHKM>3-MܢQƥq&%Z`,G4&pu塗+KP.cl=8+frLkNNPk*Y~= ="r"PK iI, :`W{æ50I;F)XS\0' i *0|DK ==C'r8}5f #t`^k4"hp5fɜGeWqz\E͘%1\% mF0wZUM苩e*>4ZF91_}'\[d|n"Qsb.{ =/q:Vz! "[N (Vp~5 +ીپ14HƛVrM|4ss0.lfH & =ÐWɢFOOJ`~YatpL^Ěb~8B<"f+%@,x0L@~>B;K<8U7hC Toͩc3w׎ ̶]_F38?1IxÚ"䊹;YʊCZv8y# خW~,+m54h`e&߲sxD;,D!/OM `Q/[ԀY N%g4fKVT,gC7#[+tZs#C.ʄ2~vHldzk0W#r^'!<#4c qjWZJ ye_31u1^X~NCD n,h;~kBuVN!U2ӝxX0Hln'X$!1At!(ZHUzU,۵wsjć C`J!#ZTqډ78Ŋ/6A6j"")a 2 43-˧i!^c#ߓc;ENO`]QR.F6CqJ * |E!(~Ws`j]bwNlcՑc5=?_J'Qa/YYwV&u޳^ƵWH.zf u*}*S`M=N'"wEyOk(Y'AFHnOp(Kw߱)+?J&z~ i<(%UV+a{/wJ[Ji$ShrU"q=tgh@@m۩vYHeā;AX麀kGJԗyl%W)+}U=l3$eG.V^Y([FVVb$a![47"(ؾ_mr*2v,uO">Y(9z)QuT : &y֠0Ac9\0@>[YC8 Ms 2Z!Ըif|u.Jʧ`#e4lCۧs [s2+8gq]SOښ^+oc94גsdҪ+=5lL=f+8Et@|dɡ7^+Մ7F.Iyxd 6AAA D'mN`i]hxuF&΃ԍWM7[BLu)jTv׺yTr*`gvyɈ.Om+h-!W=qMc1њϩXV`c"fWexZ2o~tIP9|[m|."* x M-3h?+`J6 -t3BޙG$,޷:+s:/(fLyCC_jzDAwW;Ltz$\t<]x>xma9ʐM4V^,$o?( )Kn.Eª-.gYisCa T@1:Y[ \4N XZٟt}3B aJzm r5y Q#+=;9NYRrtZ/&EB`/"%NB +i.cq+J_r&c^&@MEXdc{CKb" ;gb&x_J>|V. [GQdE» {J_{n1E}}uwSuU1}c)vOVc7+ U*'IS02K} ?ɯ]+l-[=cjM"1{M"M&tX_?D|(AL+PՓ. a;E X;߮lXV1ཉٶuMu4@QMoCt%u` )~܆Z[O 0&69ŴǡX^/#2abquho xe )7A.:kH Ez*Y( X8AW[r%+j.-f 8hs1)M %C羑ڲ6ޝqX*bpؗ8ķiv,; p ,Ļq32E+'igjC5fNr=6[+Y$umYYuhZyHdqZ";%]Yos Irk`HH["?V Q-U 7(ѦٺDž|g@@ Rf0VV=#K9qq#˺xH?(ȶV$ &k۹[81XZD=(%hu 8GEȤ 86Iv( Cq$95xX n^-˺$Yc԰l j7DIlTYTP0nij_kOa 1Y`JwJ)5 !2,#tr1TpN]vJKNj|Qf#{nǩp0Ū&rOYBwr X8q`6iTO\)Ѕ>UWB-f=*H#_gϘTq'ˁ4 Ͱv ʋ GU&t«վ`ZM _˒:ڿT\i'"n1Nv)l b՞n$Q5 {wdWZk/)ߊC)ĒrwB%Gf騒JL͎r7CX%S"cpHӑk\jLuBtD[4UV#5`V8D4 ATLKL?Y>GPԸNu$׼HwMF'.\#-R'}kOZŹuz΢CQ1xĊDR`L,=2{uҩHZ5B]y|~`vHu 9}rl/9s7ڬБ1;I'U8ky7uܚ,GˋBF;. Ig8$)U"HHDQJO.bd.ߛp7qazh\&ƈKIe#_xeZ$z;?(ۭq ޯ!b"S H<P{UY.AKDPJg8^K_R-\b8dhUKw޾\{Gǽ-JtJG;2l'c6'7xŪb[]/Mޓ)vTAPvKk4L. xr'%^0BAh=@ ڵQt~7Afԫá6,8-Jg~3=ӟN{hҵg<`ukXcڞf .|JaS{@;"}/BF5e H ml5X:.g'Sԃ5ke"{#وz~# B=):bhv,/Wc:cl@o,!7\ԏ1υ1zk] ȸ{߸69dǙ$[r%r8]}㍋7(hŽ?fG7ӀU'WjbF˷j&$%#]O>}ѓKZ^\~)R۲ȩ?)REY"*gxz>98YAwy+%,8;8 [k$lC,"BY<:E+*a@7{QJ&+a :TF('۪Y3l|#G2ɟZsO_wN|UϨh -"w*sz@PnM; $ZѶ v3S Q :/t&oɇ|t5`3)3F 4ˆUX'ònV'~rfv"O$b-݄x =ArWHV`jk$=[P^5;y [q l+dYuc!򞼢V:;K{v #DE-HJ\t{"MQ*U ]z%wf_.PŹH_bA1oU?QrFLCzmr'Y@!S`1RZ};KTr?_H{jT% Gt`s'Y+z,(s-GT h͛@ҍ"vHrbpqx 녩u;'a:ct{}"i_L2do;>{ဴצПkL#4zwnLKK\|fEkC+$ge1XxQ,ꐮ=5tL5䣿u3|#D[ɪ[c*paD:ݘm@+xSWUeN|.efܠƓI#<}T+:=`O"/SY=ht%c&q#YJu8 PlL@7_o K BЁGM246t/9 r Z t ^BY>ŤN7>jKKmgrg 2$a2`:$ zU$i-gˋhȘ$u[OWO"ZF:@ \^P *[gJ'E}$f;CHX-iUr5|okQzZOI06R12-3!M&Nٍs/E;@Ru8jxޠrn157W藿 JxFدx_R4 h\zXf\RruM瘛) :_4(|ȵ)q|b{!߾.k2=ڑC3K|^MߩUM7Uլ_ŃPPB]?i 3X{uSWk}5|D:ܞC8VXrmŰ :9H"H(E{Ƃ`< ~ * 7erAv*~IQPW*3^$(CJZ*@w'ac^TskWֶZ,I-qu!izaܚꞬ$%׳ש}-w E6Pn6Z*iArpSylkpg*AʳM= P+ss `Չbc꿯꛽ ;Q)hWg>w ccYg]ns/ȍS"IEXoSz=]ə3g6x.(W7k־1u{#@قQ f,,,JgkkV#b Z5|\hIW'A^vn{FPQXcC7OsOAufjR Ot=il˓fmv^y7(aZ(@cʂzBne}1&O1<,*qqXU Xrbt9)LS|ҫ3~ijDāl|, ASISp~F,-S%zAx7ScּuKZ ߯="g/4$oQɜ⾀t҆f'v]vOj]Ľf~i)gM<8M%Ux%7"D tQY[=@ kmHHPU0 Ʀ_u:0okL/l4f_j4`g&E)UaMB9U8$6aOl[XY:Q#I:srL6;6*$5J?{8,9$J֨Wʰ]w.ӘlYgho:Zn!AK%_X"ͧh(bvTT-MGbKFwi$}'=TdL O:hiSl<["|brbFbö,`NS ,Gcm91՜0s !lt Kk ~>6XU@rƎ\*uT JmvI?)2)EzϾ*ܨ#cX,y qU)QhEh~\@dYLHVa85N괱~CzڑFaEEp+a/Pql׆7u$?d0,wX-to @i"J,K_i5+FdQEa򵯛՜_4 _b_uTM62aF1KV,얷14HWLRc\]v. St'mNtYӓuBz%jn$`dp/#H9k!4)'Ob1GIW ,_u(kEg-7# dS%2 xjL*ZL90 ^񠬱x:ֺOq-m;J0L2rnA]̠-"ᵄSZC:l&jf PXsIEwCEƽ"&`!U6;43smDmNfaQaXgں-HM [C7{v>"IQvrC;ǿT-"~F1~7xas|PR{שVÏ a⌿cvؼ paՈkK\,MdBEP,,3 =M*?XOcaD*hPƭgC%ZW%eH,}Idg=G]hHT }ſj$VQ쀙߱{ W0hj_/ t NbCXse7F!cu}GaR )A-?{<}UaKſ镤 Aw-$'<KR~^I>R<Ҳۖj ?Tl:--UxEiKƔ۶4ɢ04Kt*em^{`DoE+2*<a~P㘗rݐ`zi:7zq֒5s'Illfal?b/ML#~_u7qbrz(y [T6>4W|05D9sɷ[ r w@|c jWozZs"|f9\I.Q-!j%<\IgW>}5Zo}⒡ @Oԁd G>Xj܁&?f(x|v_|<%RR4P^}ϋAc#Zn}y {`T(QդW'ۖBks:+r6OZӕ 4B={%ˋȝFD*ck u6ku"b6ˣ >]$*G98]uF#Js%*%,rS|~؜>PM/0d!<~Wk,pH joq5ũde"\ݸt؂V ;(HQhHfXm>ibjsl?fX4GҲ cQUyp-L},I>H3ZsY'6m2JN#[aaNt%O&SW)VFU WLdbP*ajd%:F>x"sSb{LfQ!Ð+ Upoʟ -W#0v"`K,cS3_us17ܨ\X}Fv7a{w/Zjj;b qH=\R1+Kwoy~0QdJPea4mCHu@+J6ctR;zN]~hln1¿R9,oڦ3uMwT +{w~T#: 88O= ޹B39։}l[?T 2ޘ&~3I/ Xx{8JN&QGaL3_ic[n~͘PfN֜)Og%c "w3KU[.YdEdlI^S0ӬȳqadM=oNF*ۉ,/VL=7dkE9sMȏkn8(x&F6SޝLWwyu~N#&A7yC4WoIBd5p=2TJus}P?bQS9-~](a #k;/ Z@ ؾ;*L'q66sҢoy(`Ґ ;q]<^ {l95 M1$:̙hCϦ~ݩ^#_8u@U =>V6x;vW0Bbka{* l*A ZyJ.t|Wˌ1yaDJ;yAm!na9z,zَ $~#Pp 3da6LS?,j⻴o$LwQq;VDOcWYQʙٌMc]NzK.:sc=+G+5v0/I8h^oGϕ8\kg,Mk WGèxN6j &f?xUы;6[뎾S(!]0||.ciBhR:}i2pǔdљN!t{<[x<<1A+B "S9[tk3hw_DR~\՚P)|?dg ^#@bt)($aSݵ6UCbH]]Q1Y0"+q͔2FoGuf>Q7IQ| Ɖu3PKPQZΒ,)?1=9Z0+/Dml0@J?%"m{Wo՝%88dE$0!v:dB/Au Ԥȗo\a]k ѽ~i`E2 [B?jVm*5c zVXUf֩5Jْ"'Ae󙨞j^NҲ˥hea>B]3N-Sx~Z_j0ZX@OʟȤ<88QnKѥi;CL7jY+6 a}_>5>JZnn݋0#L?3(3M{2y6ę/yfn'8t39p]\qôZxYǞkNXOSY؜; 67 kNA\9],0)R|aփwmEiddeڱ@ v)o,)TPbyxܸ$&4,Gw-gC3.3e9l[ΧG!']Hcڈ=(,3pV ?TP!z2. Q^ƅ;Fni72צ.Ķ_Amt?Ȇof9+ O$jphn?4@n`Y.L,vA&e;Zv5*_SڄBLg4%bkt!$}aTץ5k -įџ}Wk:rF8.SOu1ꐝ36п;2.E"Rx٧TָjyfteX@[/UhNA{V5rpߑR*tUؕVx>/*GC~#Pn8{8t5WpHUM/FeYQ1K5i֮R%"퀮~1ޚ9n&yjƮo|/} SMz呒͸;FtjUc@Ζ&6=cWɉQ7}VOIoX{պ m 'yZ-,| KuQ5nz^L`u.:q2J^^=MIꚤ! KQS)ć+=F&MAU٩%D0v)24뾘fWK/-ೖ% ?U=8@G@Зޤ{=KUߨin%n~w_{-' c˲E=<#\(S;D^:"ɬmO77~0K!0tBѦ61Uz8QX~^c^qsFQQ1UT[=zj/c?[hn6 VmKItw< FkIS(i%{xcF:m/,G[@}w~EEy>#[>6i99q d* V['EJIwHv&h,_sQl̿|Dz',fUfLG" ٱ@~ޟ>萬v؉S A` D A''^A.p&ڣ>nlBP;fژ_Z* fyygIyi7+?.rw@e%tXhWze$rC$&BX&PS}G׀d'SnEwOG&k]ҰC6!U03v͎J ?,u#۫eۣXQD2Yb2*ea L R!V\vNKG3́ap Yrxhu=Ӝ`v& #ZbT臞ϺAHJVYwݑyC/q>7ų}1>Vf6C W9lzF^˨LfHֳНg;#WW@$B[{NݔP;K0~ Ni+'lMJӖC);(Q?ChPLJ7qʙ3([f-Qqf&ŻYo7iӇ1i"HM(M`qJ&M*/Z{W#7rCsKG73k,y SiF%cZ]G/hSx1Ol-.o`]2f$.!).5S$BAWZ2Me&v~5&5:Jȁ[.#?Z; Q70U[T# ?|52q`X@h"ֱ=>O|(#N/e<)RF\8{K* 5-4k6\ hiilc(|JvfoȽ x݌~e+nRc$N/LL>DL?{ Y5׎pO/\ֺU}H*6@f*~.K.~qް)&Qђ'5^@Iȍg2!īZN cVMyBd6جM,&f`1c7fD3ӆOyx4l8OU2ΟXF8#I*1Nk|%mtׁ~ƴ7ȫw2 W!#ؔznKs7B[nIL!lDmQ|ju–7(R3T0]$0NȟJjk=R.)#É~oըG(6>| ͸J.)<:vJK%`z$UB- 5vr|)&ə_̢08㴛x:Mj_}BeL(H[aE(UQIӑm+K%mrwqrV&%xY1Ǎ_'~49LNk(< aXAmh;aw*γM(8]И[W|>!zZ/^Ζz%bDOA ?aiHəȀ u(V~S4ETʣ`sj Id0-Uu['KGy ZN4>yXR 1xJjJ[C5lxpdԐSm<%ˬes| : Ɣp`eş%֠ƜY;@"=/n7% GtT1]G>N]"n ޥ ¥J|cyOۡ쁀bcء$ buWF:əm7DJN0L(a K킈j!BjXKjj=Dݧ͟sǭT,0cLq܃e9R{ǶPXWG PW ϗXQ-hՙ#O'}]m&W9,9"GZWy 2ϸr~9@;ҭa0-z"Ƞt/JL JWzFMLHƳh#Pr3:hQ:7~p :re']J6{a|G=}nXAו-$";? <(#sNc7zcg&F W[`"/H=[qy}Xgn:8Nbn(W|~|:NaCK~ΘhC$a ~]xsphm`.a'ͣI17b.JEg/^yRk+v2 Ag!8lr# qQ{?,VQYרJ58WQ `|ܢ#scLJ6`8TT;#+@D!Cv>ߧ*?aK H$!ug nPqdbO3k/+N REQ^'ld~NѠ(r)YRB9M䩆c0jX1 Rz}hcE|H@w+t p)EDwTBQC;dk{KGMg;9rޗ#8ֶYU6Yc鰲q#B w@]ރp4f0SiW.9=y鍬!:&MR^_SzEsnnݻ8a.}Iتdg KrRz`/`[$cAN͡|ȥ2֮t#= UȤQm1z*7p ſihƸ^AR;rbst9ۈܕMQz+vt6[ˆbD}ZүDSNwG8M3chsTNK檑-Yl(!i"!O!&D&!U? <&/$2U\lHI5(Tpa9}A15{ȇq>[M %tB@9Ie!Q<+H˪Q` /b89* "\ ,!㪄.yF"]_V, }_bk9LlcEYRu OOC"bձ>~uXHEœPI㞈~P}QaWI9H&I/i2#,5O$Oo '*SU8} #~MIzR~2Ȟ-L36G2}M88Wc1}cZZiȚsm ݚ?.Z$JYoшڥڙ%>S z6@҉#RKi& 7[bwjiT~+gȦ~bl0He<ZNvm/"M2(FԿqiP30 |rPR݌SodtΉ:Q&H֓nvܚM#? R>r Eˤ/P4bV2,סuS( a7o1.U)\I+ næ1|jaڤPμs- ^5<ʸ&!wBSL*"d1+0у QwazꄢR/GKH-鴚| [_ &g+Aeva(R׍Ic{+m"~&DdmZ戴pT9Rc!N8xK(0~6 %oy|E6+~A[H&b]Q&! ܠ@fmJ94SҲ @ AA7& *'#U+蓥fiA'Ipj/p!ql.SPgVT, VPyEjTVlZoϔ/zX ňb{XwgC6)]oFy"& \zRBF*W:&FµJPfvspoeN<=P?h8DP$b`Bߔ7>cByw |KRC̩s#fwo<+%8CyZx:GW5[E^HŤ8a tZ"UX3WAY)H7DqX_pl2rk(eI&FVgݿ^'{4'iYcU'Xӹ ݞIx3 #P rtxeH4mAeh5 @ذYNjT *Sp +)nT(ol|2EG'm61r\w;*o_:е|k@B *.+0xႩ3T:C$"!,#5鸼CCuFKu=s5jFyOg#ɥxjb<dqL9 ?ppctH}^H(deVfDK҅t:YSjvYUvxV13~ @{I4C֢dQ36)@ًbZv.Ot驣Q+ig3hX`v9GLu0I,\!LI[{YN.,g7[i}w"g`XN %N'qa ^oU@L -4Q :}C`Ɨ}wj-gN{/SyGPc?(]vDWPEQ>֗iT3e>  TFztY]Hي$荠;S]̤I įK,VzgR+t h`l˚K!7@+Peg;[1$5wK$4Oc:b:q6[N4+DL&zRDJG (7\M<"P [={4ye/M!?+kob%;0 ,{E\'b){owfkZWudD: ]8\EնtK;5(TI}8L-FBOFy %8o+\B73pmn P8͒N$`6[hyz uo,4R҇Tpx2mVJzI$ gSvIGIT,N t'qΘ+L9A+|SYQ\Z`BC$g{c29o%(/q9nQjs P,2t1k\s~PvĻtx!܎aD7,jOC]:S{ءӂlpq0:]AvKdƃUE$2yzL9ϧspn(r=y ~ Xm{ ;Z_ uo^ʦ.KB2I2/TM3pz6l'(Vl>eY(y+ÿvGOACS=iY }HCu/-!_5S>fo%Zl?! )'u6 Ojq'bD^dpbm%U-؂2R=SLJH̖|mYrӒ_Y,t=ZE}h^(Lܡ/Rxf n^bxBݓ[ brW'JV%Ʋc ?;wk~3[>W^5qԓ3ȓs>͖G&s~(R\&}{Xu>g; 5/+j 2r!x9[ F g;[{Sg=Ss_p1?b3NI[ 6m]|1E-d;?C֬9S k|b{A=4WP^W 顴'sOZC*X/|bJߩN\Cq,>;N;kCf9ݳs 3oˬI!aonD@/"B3]>>'eVkӮDN[>ݦ႗JICElSq#L&;6CR\^V,쾸884E˨7Le/.9k@K1s:7 âJi.pUqd:ޣ*A~|Zbe~s5MmzMOP\?6ZK O@6o2nC&#H^ \q ^<k/UUcZTamKzط2\S$QXf NqYw-]QEu> 饪 C'->MI ?^S >bn6xPhRp >wq3SA"P.T @ ˂$ gaLH"ɀսS2EyF:ɅJ Bcb_I'`h>HlRH7FC:LAYb!'fNlTw]SL?3h[=-ЇuzkOe='U3v-OX1BhXm˓ R&6HF"&:tڋ=xM%Y< 7=褑o^{$-WDu a鞒;vcknAB%X[EAJ !P_ iNmsߨa oZk,/C%9l:<.@HrSDTm,M!7vt z Ɩ$ciu3( ;sQůZ0bYmiqv={w ׭{עluoQ49b') /L-}"5^L1h "/,|`\/&FN0DOm^xlM߭."Ot!wbkPMhuk^Z]R7<g$nҽ!0R F'{bÍ3+;\6Lcd[v(bGd\3:KQ`Ѓ)l.Zӏ;5{|zobvHI%9#?:(q/D}ʙѰV nNyX)9 OOlSsUxCRSH#= phMe~sp'={Ba!pA -$ֵ|0A=ku!ŽCeՖHTBB($:a0ԜVPrq Vz)4n]CX!씻)91c8t]c7!Biɸކ8ΞU! ߠK.DzjyBϲH&2XWH$)5^H򄯷":[gjb^S{y!afWiHhʟ.D ZA-|h?<{ Ms= 7AD@)OuNqoMU۔BI ^if5ѻA.o"rPjH}F-fM)ԑ|;DP*/?>s,?g>̏0a uZn4~\2Ċr:ʺmeR f.?c 4Ϯ͹rIPGm 72ۭwUפ 6BfޒQPۺwki1W0q!Mk{"3)Q^6?OK ^%Gi/GyԹ\Ml).pJ(.\->DעwI9Lvn7Q̬xᅎ#60K ;n̎7{C'qQBEAY4fEZ AV~贳h +K_LΠ-]mH!#%fɹ^El1z0^g09\8m=eA޾*i狱KEK?N ?%frq& fU}3fM.>Sԑ-!Ii_յ=`V087G폿{yV˩ʓ;pô|qOR'={͎uzhn)A2w0 HQp>/*@%F=uİxp/Ԅ iީu >%dI:.RSLLT7jO0=&ELaUve8$|e ea54WI. )yi ^*t 5Sv;hhz5.MH?/1nПF*ʇ sY{t:^@]JLZqտT0|9Eq&ob`Gv[ BMRA?K?j4N2n &ao'7MAEPH)^c#d D\c %Lo=݄nz҃N])Px]ƃ9ቕ0pao5"'Ϗ_FLhE;ߵ߸ڎ9\IM= S/˵(s߇'?ޡvhw:+\`|QUVTXTɬt)x6o\/zk!G ="(9MP^{RvoF5|xD~t$(#4^v =+l24n)m*'bfc $[k̫sVW :H~Q )3̈́D:`.*OiTǫ'Id&GZa-Ѩ&ĈP% Rh킮B^=Y GBI\^B^ &g:TK-n|'29<Iu=%VĨ\aV/gֶo^j0QӸluiU3g_FoJx+n$T(Ј|}W!vBL8&iSLLV(n=] /ё)]t?ظS۔ǯD`\yzѹ$rf ; zYC]?s:qE ;1:?}kJG~>,e`evjzODN\<@ywљrH v +?'|InՠI[?$c`$Gn[."%\# Ok[H{픞e{ߖ*ˮ"!/xD!]k;u(c\)ޡ wryDMQS!^M4&gcCAۙ1@Ff-bQC RT:wTw 3QL7Z5|'b3E܇&wJRl@bx1N`ˊ>+O,0R^/1G]b/$¿,Y3o8*LOgkld{_ ְGۇCb\{!yFmքH zzy}0yD<38"}u)E!gDJ*B~(w9[n:|@LVͺ).v{yYƽ P X%'4iVZ<.%Zei" Tъ +tl!!]-mLKZBȃj-8GURQHM8SV\b'v- @>2_fiTg߶ݰW8e I΀X H7՟f nmYhwɯ) da!Ԓ rquUAogAIOW@f\Sʿ|ԙ_͢J@- =h(cs,WMbUS()സ\I_Gw]ap!5sav\9=ԢP)KJu5£_ 4̌0M7vnp 'OEaTRcd@UoRiuک}Q0 K˷Chkkϑ8&`hz}YAV}&{n!l_8V̘~t%9  x]vEb{+8$XD1^ '=ϊ! nOO*ͱ-4/CVt'žMNӕ6bƂ,R ۺ p5of^}3qHOGL쫥sH\#CB@L?0z%f$sxVN",2CQ$?2zt8É[$>z'VG<P()^u/+pDPnBZ?)钱]Dn[c 2v ` ؉h[3`+B*W^'f!)W -'Gx.lp +QURk8Jި j]zm>Q1 4R/#_afʇ & ۀ?qfւ6П%  ν*vs Ut6.4^]5YδK([^2pgsu*i@Ul{G<6G7áGl?axSnLVd&:@|oa&QȈ߆y8/OF-q2 ^ZƲt Fd8=mPS|as| 9~Ob=:Yߵ)o+#\b/5E7ʕՇ(;EJ"\G}g2YiM$(L⢘Oeؗ]sZ6P3ws^uΘ*pʟ?8Z 7ND?_q?>_^NnrGj]r+W5! 5Y]_=T>aE.>j +ݪ%uX6(=k-ѣ#;aLAoV4Y|qV '3 U/Ηߣͽ%-3 ~\P 21/>hۥݍ7̿cqXwD7,mp-%=CIX|HF D :4-f}(ÂV>dp8kXZṰ%UĔRV$ΊtB#6UqIH^ H2Sg71wsgaYo-]R1u2֓*U Ԩԅ Зa5wr&yl7=}4ig[,c{܋ 湆([O!q~IAGbسdx1Z聉7CeE$h+)9Cc_ ćߑjOʳ#䔮xU^B Ֆp_z 2SF!fAYkq~VtIp1oNwKқ~4"PiZ q#ٺMW";^Mw ٴ{RzcyyS+Ytw-P&񔘦خwp7g ~ݖ;Nڣ~kj;I,Lr!I{ke^%DWohtn]¼[o.'D;>-uLgQ80$^[H}ZC:.c9'<ŗf xk&SHiO+{@/n.Wk-Ln@dw-LXԨ1o2[<"E_콓"{tT^[Ym4* w]*⌋OqZЮ=+JGI 찙@&.ME2$2" @V+ Ktk VHf8ˍ/R[/,7Nq?_WoH.E5mO=]'mcյ΍ĺk1W nY*/ pl2I r5DOrU︶Rșo95iNb<;3\?`o͖ \ f Xw5RDjѱ:Zڻ3Kst>/\~jI< :7>ɋJ&_FMbf,BKBBY]eV6nfhvjuh1j*(=)<]F)($/iI'A󠺆V~%K &D’c:u9F7#cj< KORݸ=+B{h4Y*R 5"ީ.!M#zrxVV( ХWRYJ/a.{Dyu\v%>c<EjܯC w[ZbTm ^n_Ȭn@tZb&rtvSq@q/Hes씙jwEњxH1*]\( s&YC426tTLcdV=`OPy /t7 _øp> 1mA ^iJE/ :Xs W6D(K8fYRj~UwldjHE-(~zNz散i "ֿ h' ##UC0[+mlE|g|堆7U=XKm_88_. e| 46Ɯ.]ϭ蒢R$ws2 %Osȅz U} n_#[& OpdHLAW]s)*6C'7S3C!S~-uBa#x_cfa49DR1;'$nj!5 kU5hs0f۸ߏnRQKT^6,iQ4%`Ħ}KDGz7(`?G4mX@MN;9Gm0gZ~K,\M]NuLxVE6CjsN$[C^^~9!c"km!h/*25CbM'DIadjԙ|KfJ[v j7P$RL-a6Fx:GAjRpxm ۣM!$-='Ej<r⫚~dz@æ-KS<gbwznQ")!~ ~tBjсM\׫츢;x{!)j7V|4m5ɔM8wpWTXڏζCSi yP&D*1ea?iu!vuTNC-7,j|Rcr4gl2#$2e0ٲj 3*o4 [۪DΉ86ýCiKar@`4],}f3qW#S,&}f Nx,P$ښ3|} pSB2uV}J%񦫶+m 0)8stY&A@0+SwАO C2NTt&K|/o|42siL]ōK`3 q)ka F L@U2(-xh Y﹌F x9-$ hϴͫVE%-ƗkF Kމ|?3Ib= aY3GP,vɬXpg=/"Suf&ʘ;R1R-I\puJ25͆c~!C9I'=>i֋N/o2Yzr)YT=>0vgC Tn4u +s6X/=yXl#1@;`bt< eR 5 jG N|8Z\1cmRh6sƦ{M yy%l'$jO~'H=mvj)] Z7P[q\amZsi,Vpzδ.lMaf#@YYӕ F"ĦfλCkce ;Q^cfr+!žx'o|g:btVn*ǂu`<ùsFq9 )RC8ms<{;!UD1s[]eDP?^WT T!MȐ-3I@m02``q916PXH(WqEc!DL\ww X!C G zԄ!`Z76++0 Q\A}6\fLP2CgPV$i+ŇRc` JȐm` `n υ+2*\iI(zMZ7ޒix/G5yeB~8IYttrPcW|%Jgxz̀9P&_+ x")P+ Yeu>+xR<  $Ŷa}o;yf0>a,<]Wa/cvǞ 0 ҤssȠEn8Ņ%m_!h\)&^`D{щ,:2txHKXis(S;0&\SlBQ$Ԏ "KDNKz3]pfd ,5%׵Z%UJG {UϦ??m?bG6{|[k8.̒ }V闬>!ؖa:߯Fvn8K: +8$WzHUL'~Da %m*'p@d6j[<=" V\( W伕;k<\-MLmʍ;!^ R 6I7m~'u:hOކK~.XȻØ7勧t1DMES}MAeYDWU<[{ >VZ$WV,Y k>欽9 Io.,JC^L6/]ka\w9^v D[==h-9Wo݂+'*j]?qzx򎙸rnc&*{Îk!'v yVx%-6V3b[}zQ \J*+^x'fyfœMީB,5`i( `0ZCô!QN:s, dgq}qojDo/[[de2d Ԝ(ኵ{jr4r]U\MjFzH&-&9MMC{6U1ȫHh+Lҗg(1jGKXg?ʕk&hsgU$7[ ;E y/~y6e'01rPFŸ%/kT \qZJ9$rQUy2-]TS$9\[;،O/0VDE8^ S;ؗmߤ)?27sR˙VS&>Zc6?t8ax dwu!fLJ0Fd 2lO0G!%䰭B8VP^m5 fܛFd9\҄Z=1Cv<ҀP 맆*f_]T6߬=3Z ,5 ;>^2jRIT ^ "YJ(„P-W:һ$1sݼ}%,@L3*zc(@֨^ o*>yWAR*:!M/Zxc==M*u$R.sٔQ[m/L g䩁J?3'^vU1O"}8ڪl-V+D6rɪv7(R3>ʻ#p6K_Ľ%k)NT$L&1Q+vl@_,+Q}w"29Y?*,. vL$4V0Gg@/*Nn)G[,Wr+"B<`( E@Ϭ6: 7͖&<6"d@آ>bU qV#fO|.ܼo#`~rcslօOy@- gm2jP$Nr+% Yԍ o~Mu&ֱ__p&.}5UBgT5Ml 0BC_9+ѻP\ R$돶1LH:ζB_<@NI d?^uDVfyT^?,T\&0glb4zN.'Ysd"^7P.-OX,KAɇlܕ 0y^-J7Y!h`:HwZH /AlОwL0+Y ".P)wST^T`,~8"5啃b4cT\<\e|fStv%M(OS\%qbdv+9>)*VwT(ܚ)AK[#PّF!N'3RZ9zC nLem~p<rQ5a5#Yw\;l\2>I &.Xa+ mc4Z*"[L=-u_$RG~4vU`4(l%Fx~o8;C9kgHѥ1gAlSWE4Pc*%IC}sK6|՛6T48ʎXv?SBtI3VIY#.\E*gj8օPKy.Uֻ+FT^7|ACʽNwoj1$;,~|")}F {n2]jCgBad'qs zY1M~rǏpW~1r]fh{fS2ʰUU&Puh V" F{d)%TGuU@9o~ٛ3q/El EB*@8e>Gg Nx75djbSMAj@}t^=CV}ר$i'+v\Ɠ/aDA͎Bp' DV9rlfYQD=JMؽ8~vYzط6h o_D\URWa=fZo*vq2_s>"$f}pvl ~(}L¹)&.nsDv_$B9!jm6l g:4 W7lAAu701ePT:>PG0 i.QjiHk Ld-p {?Fm#_ Y|eA:"7陴ָ%]]ץG67]8~K_> |m:\!=kfbdwJehp-702=DS9#+]]qBhΐ"(Jhax6Wzp.=5zyC()lIN c[)VI"hv&i)5# ׺$zd[|iCuNOې%bA+Բ^ Ӎ};#Y1E^1,n TQEA؞,+OA^Q\^7oJ4bK8$m%B+ .`O]etv?nuΥ[y&{72m$auBI~ ]~ig,]C`e,C=e'/9/$0 }LG3i_9aytT^>ú:x:G=PLz>slGdv<o_72ڳ6_Mv9p7oh%SěކJc4;nv{ʃbGR+-@g8dBSdqDI"w7P\לŔ`s^hjI[* -Lx7'ew "Jh3Z~ځx #Ѥ{{, ͟_Ao+l6G{{/M᝽ fIwHi% "` ۨ!sQ+;?'!: x%- P;U c߬`\vYV#hN"HVU,մVR1;Y:$`^)>fZ*B-y2"6';[э\G,ZQTgZQV9aL7)_Κ-ImSIA҉_-:HxX;~,] @L9NUU=/xG]FlZa4XaQ;Fd՜B.ZB?$ }'RKj,Q/B%_ٿZ)DM7/_pz007 ΍ш`3œ>'𖴙]S$`ΦϘ15w}Ч  Lx4Y YDe@ 0cu|վjұ>8+D}ݔw`VlhN-RL53P34X feZ%VHMp"n]tfr YAe0 ܓh<[\|CEC%E߇]O`XK ﳬ3Z"Jģ ԤmK f$+gJ9-ZvrZͶ]; }kv2( . E 95{gzeJ<3ABѣ< (Tz2V4Ej>GZ0' ?p?1|>aD7^ Fs\R|Re3E:bx!{5K*0D^ )Fwaat>8|x8]٪RXoT$cSG,P mhI4Mᣂ?)T\jn paĀf3Cۺ)8jW!L¬`W4OJ<b^K}O`%u甜G@gɉ(넎(A|y 8W(W{DcnuT_Z> ő\F%VR.ꠈ:tcpD @6CGA@>$A|\|Ӑ;W-CpڵpM$Kks.TC 9f34wSXT )^"Bl{ d6YAkzۊzw%H'u6k!-fOmL4v 0hb,+'ʽH3-LXL!2δלE t#:oqrP?y{~*SY@U =.i {U@ɖ<۽QHvVگ\|00f]L -f(L~1XE7`Aegv=>vj w4y-;k;U`z.>mxgW9|"x[&h9)ڕrxaדo›"j`6 ly =Vޛ]%M:#Z]|ӝ }/sVj324('+JGf9H9_v{驫CfҊЯIL c9p sR5YsJ4`7YWȫbaEE:D%3؛PkgT/s@r9'_DzqױHM8ז] ˉ dj7V!7]7)F.F\cr}.u]Fr==|:Ct26ҙ'Z[9 8]KN|hJƪ0W9ƁRQD=>Pw(̈qNp$ZOOڎ^ H 睖[7 _"6잆$";r%KqRi-wUKYNd8 ƶIl`s؍1`&9|KJ₝ǫdb1d^; vN834Ӫ.O(uKP{ᕡvA'zF`./`"d劻Ƹ;2Bd~z=3zѐUbT40 |롞i-U}:۷`OTq] j7)/Iި#wܹSȹt&p N8Cdu&dPiy?<-""5rv-yQ +U0{ۨ>.opkQe.!UDg.n2#vV7}N. ݓ&bEpZBV?(tD%Ho%[7ju xVz {L“ƀЃ"u"k>pd4]X q"Hq'Z]$;ѥֳT f m 6ȥPO$uvFSrmcE"'9Lx(RiQ(ZYͥ'p4MQх ;eBy]Հ\ 8q>UYh?S޺աqeZuMr5FuXUYo8kVd>Ȳ)"hynݠLK棭2bkeM//h׌+kub4xb  'Lcy;~ᶊ/ݺL)gnl}biA|+Rw&M):s BN`gힴiCTy$<#͸͉Ics˝}r2P%Y r}j7f){t}dQ^It/ԣ Sy|M0)]Y#rN-QY)u+F\ϥ2՘I0 Wig- "wvv#ƈNEUL?Z ߑ]"JB즂Q7tMb@͈+&[&uP -'7gh&F ?3E=ߊ38jN! Axjp^#8&&y5-EG& Ó\陙 ikqD7lwNJUw6Sḑ%{zNm/PHo!|/`# xHz[ A:3_-F u2;<H]Rkrb{cRH[$N6 IΩNp+:e% W#8ncX.jO DU]|+Y(wjfq&"SHGYFM-4?HoƇs-"&Zu`^:KjffKdNMkjڨNeh.:i R[,Y(DgfzB)Q,k$iq&hvX| akpS5ߖC:\~8  GEIYUOߐuq-XeĐ:%) IzSq=L`:'D%Ң`y=iO՟QAMvvU@%(t>VajG5P뮾9Oq4uҎGzށh&{=ϒf|`-U3F^}0;A [KB 9bׯC8,RU~*qGX'҅VS]HN7J\KmW<->urATUw+!Q6 vUA}## Qi-`̇lM'ۮoۙHw WZ=mQfuryfWSGe)I.nsqT&DɩTcz4 fbxYx>aǼIYmBeykD>C{VS$P "3 xtǯՓ P3{H|"©CmL' Rg!6 b)R،ѻ]ɦ$Rm#b]]F pP  T-~Y! 1]٤{>-n8>R;[N|eb㌏Ώ//pcc+a}LY #SʮrPkE|$P34ŧ{;:-9Eg[ bXy-#ctv~GH-EM3CbW SVXj-%uTܚbR3 >9`JFzZCu"A3v5r*-4,s T>Hѽk qJ)- B:5C˱l?@GRU%3i:IO;+2CyFYȺd*A$^Ɲ[jJ,&3$&&V]K6W`#| Ǚ{P% 47pu:} )̂ },Y5[FJ38 E fORXHjHo'XLVqW_mCY=eiIQI l:[N d_ F=H;FOY75Ֆ'T]}[C?k!j+ite%4„ܪi_J_@?9m,xh;9JU #XQ`&[TTiflS`vZk&fKYh~ xc5'9@v{˦ ~=1 iBJF iՁ.=Ad}&j3_\/SkP?(u W$hw@wŞ2$2iC۷Ӏ[BǾ3HUMu[&jB,tm-{;޴֯-F|5[WC}ۍgvF l)ЪY9K,4jFA s BF?C9۰bxRj,ĎK^[T:U60J;;nOF~^O*gƥlo2ũ Ura@ ~+ &Mv26;G@)0xp/=̚PHv<:E]줵,R2ׯ+{@NNӗ L6N&Jshߒ`uZma%riV8>O3 3ޙ%CpUt 뺵&g&eAq,T8 )`'#λZTVTTg;DA_ovrY AΏcvUΑLb8)B k.sy(=t(}^*^s3|YW{NHQ (%SҀ^2`]/$O4R [U) F7q,Egp"E0O+mRl&'1(\y+Z+|QA6;T y ]: !S)`V ucc%NOٙ(͹qbKZ~Yn'OZ*z8z KieG8aOQ!0d Ϡ'yyzVQ)t<&A{n+Iͬrd{̥$H[Kg #yצDa]y-#Go+ TzĶﶭ9XΖ[ /ei;oTM6(py7"l4#4mI5[nC)Q2QǞyɃ:%U(*Q{JM11\af*uXM3@ UsF' &J>?V]̽@tfCb QPwl: " tQJͩW?o'D= o+M"\.6½.w&E-}rކ @tMU⛊#OL(,⑉1>GZ'"Az(QvC*2b"2d"J8T~IKo$ա%|D6)~M ?v3NCε:YϏi#y[opa)ĉ3y4OJiB(еErpgc%q#*g]%oQaL1|Ϸ[dD^&1exxXSG`9/&<; mm.@-j4 $ e 7`{)\ w%ɰzCA!h0ƔDJSĕa1.93VjJ^av2 S {_QW?GMIR: 3u70\.O~QRG~+=›mBa=cr8&j' awޘRTjጳu&k vQF ɔ'C W.Bgt: +.Z0N ؉o-K$8?">-NC*“dH:UE>"mjcd K۴C-[O:VR O/ډOV:Ц¨'׻9?ꁄlR(}Ϯnl;]8t"# YsmۅBUy_טod-U;c ߷'EU{H/\C^?[lϳ-t1>}@6fTov$~ƙt$*]:|(oC9%jJST-C|g^Y@F{[; oF6'Q<ŐO|f%qRtQ>_895% :UnG:AP l騂SKReTY-i^Y,D! i+Σ=Z% kd~JD";Un:2[ % en7'DѮ-> HP}*cM]S|`bMQh'k_2EvDX^ GhhKA:{ Dʣa&g2L'\K#@<,;^wL+G"Ŭ]Uʂ僞;XΔ% TG߫+fo TzWs2/^Jiw&=~;쁇1r>]^R 8Oy9KJ$E>{x[]YBUyŚH#4 M·Gݥ L<zTHX#]?ţn|90n' #:bnR9y_왫NōgPBtnH:>6,}˵wLDZlKx&s۷9-M5c_xs]I"&d pQ\5gGG4؃e#qKȂ,L0 ӯ1|k ]L+voKc(ђG!d24`L( (WIߣXT-+|IiPTg PV]܀c ,$0U!tXƯ;SnUN1ϱjf1ճ0qJSMtU7|L-!C7 QMW=ᡜ,[><8-Mzx?ٝ_X6ib>2R8g<ү(^4N>O"uk}^mK@@ċӡ5Ru}a%.|XHU'7 o/hy^?i"NI )6k! B vF1:Ч҇Ӯ(y$pQlZŃr@ˑyP`+y5ٱ}z~aCu񌂰% 1/\h(.񻯀),=00i ]~2$-,$6{m?^WzB@șRСY=ܪŠ/ *믨P b61g ŝ?ZMu6uNH1vLr0[;8`\'c<+U,8a,\0D[ٕ‘*t+&`>0WcuH~z&*b>^`/%̣I^sAôUVxd q؟;bU=4´T~z.cy>sqцBg+ΤyU ulCalM9:$ZOwݭ@4xz0f7Fx%+)n"SHD&VD'BYw~J#j W}~LwUc6pSX%-'|ȈU;ӭFPMV4aUKCU>9LT`RUIדu Y3S8|WkR럏cۜ2DjыgD[Dc"Ǡ<0NCCb-)I :/$y+q괠;N/&YJ+w]f RӝuqI!J|y|wDHAԵN0䫱贸'eP*WJ]*Ϩ)ZԾܱdZ>iEפya">g}9^>.6 s34uh% #-)>5AOיæ ف>0}":;%9-evbkWYs*<8OXN~VG +Ձ VeA%$7%%xU:yX7h6ߝܶ2|VZ/A+Pn-Q[Jo]e6Gt%RXq7/&ai( 1ݪu;Z*+éQ7ԻMĖT X5 I VtAȫph dWӿ̰Y~Ggj^[%P0rxB4.LB>-w22ggE}41\]obwwFbdKG<|`:H/Ge' _^E&< Cw>r!H-%NZYWǡB}g&J}g;% J+ 95UXp/|)pv\)j7P$N\BhnJj-zlᜠ(2Z@#t`ҟG `򐶬"dwCs=[myq ziJ Ѹ'HBG)t1M0oI^D`6Θ2݇o9NӋK[j(^KwV2koLڃ:-qLA0r@BQ&WXxvqm,b&O ͳԮ~m}Dӷ8J*d[IfW3{GuX.t 0"4j7fopl,FB2&,l"]I#e7ONt.UG׿vJF07FvhVD|KABFKt ;1&[o/=9 wJc,މ`fɖfUD'}ǴϩAI3㑵jo.i\*/I="?:y'߾Uŕ|zh$wX*넷z4E0G3;u' =tW_WH(4Q#VbJCY.ܩ>x%%<74[%K%"zAkeަ`l<$dD< ‹k!ՔxE20||Ua/#tWe{+տ=Yӈ_ʥ"w%~: t__5lǂNn@NXϿkYjv]4Jr8kS2G'|Ep0j [R~֬$N0D.BbcҀͅ}uih;%ZZp*KSgNy >.nwV {ެKAǫX :6KWΒlc8R+tiwيcZᷜ sz#և6xN_`Xq׳|v˻M+CVQgVO-fWN=1]f@vᇾa@c'M"si|Hf`~? ~:GM8!}ɲb 9ݻR̲ƛ@W6ZS'.SYN4suDMžqR'Xp邸RCD6wuq@'C.QtTnTcƵiGZtJ&硩(iVPqn:M34X>HD"{Vr凚 %Ѡ7Oz@0XZc$e_tXi mOjxth4nڹ[ewvh<u8LGOO3U%fām71AkCs`I -DUΩΧ~Wf#-T8۱ޝ&?̉5kair*~! hMu PY4t~Wg `C2aE=cqJ X7G'NHXL&?^,fɱMq8nGBOCpAknk B4#kM /Z^,ULқ2cHA+ؿ>ȽFVYm"#M1 S SŠb-f^zIxO5/e^F_6Դ_R;$~Uzti~M+/_Kohwu 48+}[Y1CХ.22#m-b0*1U֌m "].L@17ntޑ>Ihxf_|)- Wkkx_򝼯3P,? %go6R _椿$򘍿*GcXWͫYbp"M`„f;6b>m܈6= )ع.F,AZݭ [a3;9nƓG-QGEExW!ʒEw 7z̹E}/XY[LP_ ㍹CŁU0CTM[b=gJ;r<8ik!&NOExD葢'}۷Cv ?] RfCߏO7n,;or']Ugh}U=owR_˾,,Q}] U/WƬu;"^[rDJKRBc?X<Y9ZZTF3r>N-:h7R+)=T0vɴ;%CD3G#fԊJ~wm(Z蟏)~H BGjsD.~( ; H{Br: 1gjR+d0n>74(-6$6e3'}I|:W!A{0Nᆩb kCꆬVnnŷ5_ϑmkYS=80 ir :d`'OQ|x&:MQw[\/N_#ONL[æ ||p{ѫÆʝEeM3@3'T,}>RLM0thתCދcqKi6b?yLu`p`QV~r(9*t|%d^a& L$7>]5.{(A,6QUHE%x/3^7W$gAds|/rSN~<呱_׃MJUa]F=%aA}Jx߭QJ҈ 7, +WQTRR4>,T50X3GuUYe/҆!ɾPSJ 7~c*iA]@4|JrԵ]-}A 3F4/BVg*Tq9k)w0c&j'2=K<SNgtwu#KGA #?fyyO9r"?lR@g~XcHHg҂ȕ2:oR[e/_jtPt*%)lT#x!R)RHA.&~Zƛ;~[Z RQ!z]@+zr :6a_m(VIl*&W+U&3SC#Tσ6A??'HVE66f{2?6e~Y`*ˡsJW# QP.o8p%K\T!̉Z!~e۲LC4VXUW3:Z\-^D  K>oN({]sabn2ExgL<.RhIc2NBu2 b Ͳ:Y%K ,n$Rvre(kuSƙ!6 (/ri.k $x֋K(MOjbNMk' GOhyh#(^7ՋUؼCeCf4\a"9+)LtnK=¡~W} UDrYTEWmYQ+(rr]>R&?8Ŭ*aS$A)D 9.Ek)]D#V'YRo&n%/Y&)ZKk MCA*= [BIQe9tl cLPٵQveByw\)$O=SEaT Mq>R)ūT7؃ 6n[Q`)TPhl49/=Mq|0=hvBEnN%6tWb{ȟ`GA&|K_@vq}7xRi*j=E4n%6`^qDg1\tE]qD#rQkhb'`@Ug@3f<-%5s$T'sk1]Z8?.[Ra,&w9P_.'4PRf{옞H[Qǫ#r,5BܰawA:'jaXT5Yשݛ`=,;Ү`-Ys'G_vT<vɏ 8 6QykmoT(;ЪY).x2aIKմa3OAm k uwmpv!u<8f[紋w../<8vGnt{5Cw41ʕADP*Ą!ttzOQڠ/7z!GpsW6iDnk9kX)Ů?v-9%[yi.2\9Kfs-m +?= s rbgc0 `bPO`r~T\Wf_]4_;}v ㍯[DL::Cf+4@ *Mu䄷o>?ͮm25B%ʧWL9J̔0DdT.A_u?|ͬDlmH8jˁHH;2B '7& D!@0]t>_>ș*yr;廏[2[rr?(X2 4"xIR;feL(&྘Nk!0=n|r:sP'=Fxz?щP_ 9Db뻚xJa|*'LH-V+^JDM턮aE$,9h 67V*J]d۪ӊG{6jGDmuyx6"rR{Idg'J[&57XIn< nS]쓰(YAXi%Ŀr[4wbQW~ YJAmSXJP` ,䥣6 xu@>I@F=~ĥ~(moĥugz1Kz"1|&˟bt"X\hFHmong^VBpGܛ i+"wTS_h߈;=R`NA^]&ؗK+/d%ܪW㴐_p AN5>ϼЅK*;\t.X)Q ;P(i%PHIٯcDe{+m($s(^R~EfWds܊TC߅a+wK^| '~!` W s=3P1F4ЀVK&|8m:M*\;ZV۱ Os児 &1!XP[{MVuu{sL7J'(d|#VSxiB?>I۬9`YdOykk^=@LJQQ T}S$&S<7ZacSƅ{pRE_zcU%b'u8`tmg[<=SrRW}AfbS5r>V0]fIjEQLzN{'R"OZ./*ƱfŏDADynGWa,Q/xVneج;,IJk"'pd忨VZ˔cv[ 0>䑉\'7m/5蝒2+? ^@R2/## hDhFG?wl6mV2S9tK.yAiYm4>h%&E0I0w=4k*ElW.1?|0 KI":!qy5jD^Ǟzw_S.Jh_?YTaTx/#<44؍_IH*a/RNqze+W^_W3}|! u]MȲ' wVTMJ `\;7Wa*8ٜ%-YXe9t< ;h*WjoMxifP\/|~Av ~ۢgXX}BSYY0YGR$G˱qndTp1@+ߧqي"^<c&fD|Αm9? 7ydgs^j/Vg.4WkA4WHO#]^2ho.;pWŒ]uo]$TO>т}Dxf0&Ӌ&%xװ̨!lc|NCc|C7_+EF%Gm%ud|=3fF;dͦx*T/wWwU єA|} uoQaRej{3И& rA@pSg.8 /J;9 .ko+ 5\;Aj$#[?E(8vlvr̶Ӎ`OX #ƛ1+5퀊n.12EJ\`< -)wxCa2D]⨲KLR\0%8 Qӧ rWH铍_%%ET_T [|'5tW&~Ǒ]?B\ܛ<^V[R/lKgga 5)UOoV 6; . H]_LYio[#$HS]>y|MJu F9DMb~B \hx3O(Od_X cYL*[=M>.pz )@LYpEbzzp9 %SHaAC`| Eد\[l6R~kK 6ݳ s$BW!?~myqno#wnK440vJ|gZnkB9cxy, <]Ra̧'$5ퟮD&P47`i͎ ~8wnpwۈjRh%s#:ZA$$<$\>%R/;qo1$Ze5mѨ'̠'za ~]6 85sRf5 An34gAq}/Z' {L^d๲|{DM >- /:H0s)$CiqŒuiRb]s͞0bwTDiGЪaoONp,I'`j*=xG?,'vT5ۀNyћE499U3sޚERN!!CH !iS+9&VYE+5AY2b2xt?{K JW$uc$6Ev91lȹ#PV#eio ڛ_Cdħec68"kٹ@›lyPC\$iO$ġi@)-7arTJx(c ; Begvi{Vc'TjS"JQCOO? Rz0\(|읲qpz^/G 44=v&vtZtm7My' * x^(?aXa^FQx[FrC r8)."T}x6YMqY`5RK Y,XycO~ `9_gG>" җ¡QeRV:^1"KLU?#O{r%Ş7 Ԕh,˶A{\85/UTxfg\(˙0\}Ny֌T9}>7wE֡% sB)e^*R4Z݂4xHV0(2jCD{?yhMd6CnHQu2E(pQk+^?H-'kNV8]K,Sv.ɑެ6_c~i%C"hӺ#z#$)1-[DzCA`òl,ѢچxbݗYj;y` Fp.Y8wwh_cAخ)u5"DQL.TG" L0x*3~)=-dorʻ6":`@ؠKneH5c9X?4P+mwĻ/*rLPjIh [+0~.HW(ϥbu@%뛚NӸS5ye`9BFx%H)egjI6.ˑ/fA b$S7[8 ~N-*[ '헩抢e_Q|B3iVDڴFYm=u[ E: cPm" ";"!cO *40ͽ_۸sD}sj7z״ĥ;v'y4oF!J_'CA]h㱄CaN$ bV` jUB+(-twgied`Ȧ=+5h';^\L#"sԥj;ƃm.냒0MdCWfn,I[vaDc@%6w6tt!hc3K06P-26WfkqNFs$O#Y(̨.Qr}'?|t͟AZ`ZOy^S4F8JRЁ{/3M323cA}-ڊmCZ3LJJK ,ut ,R kߙ0tn| -[V6: 7S[B %0j9zI O3LBV8 ̝h\9L{<܋%-Mg?:nt^C!InTBϹM|^Dv=wA T~PएMNoGXҔj-0(zk ā0}ӎ E$QWvu’YuQnArze#eW6USdJ/F#rTPh8ﯧ#`l9یC 5с0 [bVnY(cS 7ѡ^C>[uq>%@R]$xv_ h:sYˠAߋJskxq<(DO=TV"S-4 ΋'w9 (GaH0}vj;0w(ŹP":HZj3rσ]Tݙ#~DQM8y 'Qid 磇4&T{tHAЅi"5f3'k2s[^yj}$7* C= `piNְa;iIC12Vk*(ۃGjN"n]fzFZ6do/@"_ 1cKxjOMJnwN+D#F}L'7r kKc9?|c=xe#Bvs)!!$KY(Om2\brR-KCNÒA$ RhEş`~SmQ" &ߗ O,*(Cy2ռ5#Ԥ\QiuynniJ3{ =/N{-@etgA'P`ׄ`餣%MSn5kxk z2%{B>~5e}+Ūj)1.X*Mluahz#Gȿw~;*OhRFArwcц *XY ըB*Sq;r-?O69 WSyiqyc 3 c  N PxjHm@m{\9>zu3IVwY?x-9ks;݅Wڟ18I{O`3jV Ń1>pܱ`Ⱦ`#U}dP~1(F<$ Hvvf`R꼍yLRV@iؗfl..܍w*=FnBȔ),j~EΠI 8ȭ']CGTȁ\ٯf&!dpGgC^Fm2D\XB6lj_6Bvl@ɿ2xI;Rנp'G(KJ:͔9!N7B$}!1a򪱁vNjMXkYsB\(Lĩ .#ُ j$ǹ>w~5q{焆&!tiNw],=a V>ap22J|~+&UW*UFt3OjT@: p_@b lRϻ~JؘOrk筘ʊ6كّW޶ .KLi~6)S6Jfx=h&z]cȗpNƽ'rz¾W9UrIGNw|"!>snLc'H&Tj=t!j_c+ \$3WZ6{=B3SeB&x)'K|P[{F.[iU6 o#.? RtI)>'`oSLt>eۑU@g! {V7[,OvŘh2VX A!YX4D{[^>iNFd~G)=:iCT܌68W/1 ,8)Gmȯvqf#@z"`x3Z7V5̠HW\!E2M.@[G# O,1DUWݐg\R( lJGIcD XO;K-s¶Fo3%DTy:\LQ1eǗZR;- 4I&),fP*/5z&$rfͱ["xhoQ᝜CHYFR~f6 w7R#"'%(*p33:>fv%|`EXbM-:FofM`$ze1$xX63e %Zۍ8ȭ~pZ S16fN#22A{->?֡Tϙ7 lmXP*X~h|ezcvb9? j-K.K(]H}58sem>˒ђVTLSY\M Ut5ᡢhDZ +s^&hS+DoDSxhEb(_tHV9,UZqڷ3A٤Ok>.%)NM/DY:p_3{`5_mj j!N@ $LJ,cd͛B ϹiIi/?Ҩ&'=3:t໡5CiVѹl4.<$'"Z0QIFGat [qL`ь,r3/ASn}z;z|blPyܒFETJjᬚ`p+ߍ0ئY A7R=oOX $t|+?,`xV@\SLƃi$C&\I ԷF L ww^{X-//LNPG#Fg~x}~8&X2h-8~V@^^G %m@+ө?g5܂iox*^qBS K0TgA9#-5s%^'R h[aoE?c@ҹ}9YCznvteá_\$D̔Hl"p(RRM 4.&nz0{,O'f?G$" 3Q|bk_iȷ;LGM#a7SwR?f[PB[ IO7 j}mlETH[Я߯bY ԅҲ YTĞYI׈S Z|cBJ5ivFJ IЙtW)B@eHQO;u>; .taZħʞ+Ǐů.ufEd|RaC\u"A.U{?x #!?)%|#ݝd,GS2{D!ܬyK'.FmGTDry۳ J7j/6ˤNw'm=U.RPq" ї4' *9Ym˩y d GԌHHTIC{vMar[6+h ɝvUQR08%>&4s66/ 't7T-G{29NW Qq}HSb7 R jÎ p tLlߵPa@ mHcZ`סq@nqx={S y!TX qt]X> f8() ?>,yyU.a_9|߁ICdJN#zGdCbME. IavgU^|m\Ц3Dt' E. -? Ob*C$\u+s5 bS  slҔ+~DvrYpS* j4_ >Fg檦b:bIh&H'+!ʎydY˼SSՉ?TIl%وEHpiӵMBY;TSj,zw!ĆRӥzҼLGlYqys!|x/Bd7 ׷-~1XI?rݤf}go+S!#|߇7G4Kv[, _d RpP\ZʊV׿6G0Mnm.,$ +ܑ )K.@(b [RH*O94jhWoͣd=PPܸ=jpDNx+uc#Xgh@=ba5[@ >k6-G|i U:G@ф=H;4 J L@SkQ,,Y0:cvy1~\%GQ'خ\VRy *?h sTP'R>-\A?`35_63n. o ǩ .x #b um^nJ\YW1YBu_|Ku1-bz;ksߞUⅤTN?¹I7J`P}IGpy:BBfRطnqȥwVe X.@uJ!ڙu"%'So)V uWEF#*gȭ/ٚ V|v9>ěD*9oB31` ]AGX(\ aԵFɿN7iAτ(HIK":Xxa| zO)e>>D(O| JᖋK"1@%Ӛ0ʛ+jQ9Of㱣 kڼ=4}hriW[OPI?y>h(ʹ~I*}?b 4HEĮ>dN>)lխN-KR{5ɺXp$lɖBhW^B|9j\(JkFVp #@ /n@w4(,| =@p4\JNcK5ʂ՜Z11p澁@n̜- J\}Z|@>kSnwȑ/hLCq 5bAn  d_Nq+SK @ECH'~7dJ^Vp"s-o%$fkG=\A84lRtpM^'x0iQ-z5P<Qj}p3w@lqKmFU"BV?tr'lTή2$aTNdc51.! ChykXr G*< Ď8N|NT "(CdŁV :b8rOڭhŏ[8R߉MsXo@_W_ =ue<ߙm9,QzEaJGޝY6k`V$zFԄ]fjcLY& c'N2~˩ɠ W *~gP̻5,F C`avj־d]zo> ^T\%?:]C4J[6Q …Z]4kqgRMecV ZNzz(0g2՝)qAܻ un~j #By% V9e.AdҡȒ"N;4kr@KӪE:1ɒ`LjUB 1$򊟲i'0@Yb-$pD߫.wz! BZV\(S gb U5IqǢE&oyV4y ]Ψ?^Ъkoyy9fq{pdOqAJܣQ-xYzJ↳_&Z>aKq%\YYE"Fԏ:76TW."0{+8495qD)}AV^!vm[&nd۽#c9p|ٽuJv(Φu_f<[kfNߧʜ܍F籠[x*V}@=1 /+;_063P zT'@ClV7t=1g~*SO*w|=mw.-ߪ ٥R?27 iȗXUX|wo' Abg'nV5;o@ W,'6IArŊG$%ͼInہh}{Nq6|zCA\,vAb[C؈\묪4}o JTVs"+=xou vt44 f#G۲-.(&Ya$׶$wer£c%Ai@<15 hoQ /-Xg?VT0SPNcc tN+ɝ4c-, j4I ^ !H_F`}H3cQq8&Č{AuJEQ pיF9Zch:0|f^|? 7-Y'O|2vefOB,[LsY5Cew6H}{a1*qQo<(T(W3CȟYwŁ'!ˋ GɬrDz+1CŘT]fׂ}Q4SH@>asdA [7~zI5:uLĄC. daM~YtmadPX[U2ٽ7jj3u%ӤBצx7? @vӰۅ >ZoI1g)W ,TޔG ?7ʶ5O͂"* D1dYo$qcIp/J'h(qr_e?Zĺʐ7vY.es6<\97PK⫚CHAl`l.<-W74`'BRton+D*1_PE 2Jҗ}FnwO+#sP[4\5eSSM0uHYǑt?(YtNB%bTKm1uΫ5eV5ڎVx >xa(·w(cI/3rq}jz6Z|Tj86 `mtL2 FWh Q`(.z0+A(pɼ<کvN ":d-!Y6lUDb72fLH 41ښ$6],,`s4xmsu?ю*i C}\َs:DZ}s1dYebŒq-YT]*Ev:*.Y[e:oSAdIXAPb}z\,1emKUO_5;}[嬅_vfq`XnBH ҩՎDwI<ھ/H$b1X!EOgಘox+wܝg̊{ช=D$ )$ceʸB^1g@<{؋'dB3i6똠W7z&me L,iao}Z-lt >ݯ{Or1Xk6?dtYJ;˗r$dw2{#Md1_L!1:\BS4"pD[kJ=oz6'>N#!'p.>MOf&v`+ Jx [E;a#Yݷ7RjncRn#o"s님KxzMfT>i 23>M;03k%q(OH84¾)':r;#AjH>FhJp(v.16>:3/=IyT)'NCDoPC I< 4ʛfoͥoG׹{#HNnzD*L; &.L"~Ȱ0\U̷Lw`xC軅MQ%dz (X;nb{BҋwO7n$z_Ot,.A9̬[S٩X!.UVYZWE<+IfztoK-.tG*yC>b fZ+T"&˄F.y$I{}: Ezq xvK-͕~ˎzל7J2z{ILV=JG5}k^r=Řk䒎lDvpbek5Cp,?/3*G|E 3Co P|n/^Ly0Zw0RH+5A^TEk$pZMYolAH1IHe7srrBJ'Gˁ$x4 ߥgR ZO7Q'3V;=ol5*vU&ć&K5G,D "4t!l(VZ\oaUݫ!,]ÆEK>YK5Ѯn܁Հ vQkȣܸ9O0"ӪsYʄ$qS }?ye!f ֝\RGyOPm2$v8QhY>`ׂe̒AЪJfaxfdߑY땥^o5n\kY0x'3鉎M>ø1zlܞؖ&-J鑔}Es0/u[&t9Hպ_:^)4@%|Pu%4͈U'1n1$O:V#ZۥgJީ/ Qn`W_lAFx4 㺌'F8 ͣ W H(S/hD%ki9$FcFdNh :+| z`V6j|X&Oć̞I2rܿ8TIrԋPlK2sE>x!ZZQJپ͂V'N%2sϒ^r9>̧;'gše?- P~*GG* a촥ա180/I9URsw\)Kf4pLCثzpLQk>/נbUiեV:qQ@,ആbOpQYrW^dri#2^3 遦TUH6)Ov/ T2#~u_ǣ9!Y!5*;cFy<<@Ϥ.mVTN^xjdTd\(v[C -葽By>Git#O5^'ym8qdaC ,3ʇw>=>f)%v)Ńct,]mhQL)qM->UE~CM? uѿEգPMc-B [Po#tTpXe\&[i|RԸT̅ nӟz}Uk?KlF'/ %0]5!;$r2JS|XMk,镣 5t;"Gaʣ X FK#3UK Oc4v>;VGAL|>%+=͕7Ag0Bߙ;~J3?@(^D0e5zГUU Bl W xXȮ=Ժ̺5 i$BDĻ[d%lYA:#7L=)c͡<-7ZZfHݣ1%'mh˺y3pޕ #C@/ +GXOZ&pE2d%K:H.,e1k)}M%.I KOʃa9;'=,d?30VmCLkIB%2 iN4VGl)#2y]D7 y_ d@DbĞi(PAhEpmtػ>!۸VP<rgm CÌqDV@z>〱74=LEsh\rK *&f=HS/~$87 pE]ލ?cRg;,@,ީ]9:FN"qV[io ē;f-t~w#8fYM4)>(o,֑7>z4ieyRhJ&~լ^"]0JVŚbt[YeCUFdԎ.G^x$nT MF>.ps $lgZWG6uEp+vSC^ m*ՂU֕ro٩h-%Vb^Wgج_9QSm6z]ޜuT8 @Kɀ߳  kF "ԫ&-}-N=7/aLVJ !~ZTLՄ*Q:lt [*݉" naugsw$k@|fߩPn ٧(*í ?S$b2h3{-q֐5N;Q4Z{+ fnшvij3By#Am+"%_J5/i{s-2^RG "?,֓\Α=Ec*!6#2uY[sDH4[P:Y6apX"Cm&#BEMyg}=ZTv>rVpN>xRdKFBX?@*2DpgfܬyO(`#f@ɯIx4c6Ύ!m%`Ģs3UEu"kYqfcRωKzi3;_͑O{!,2u  XP?Et>KGmzAba>WvJF;a ۷J~?Jfl.z:-fOO-;ApELV@37IρW[*{*Öɯ8BϽXXFҴ3^Y9H# C̳ʗf̂aێE(pH.<<]TukZ?fK&G;XK^?n+K !%p<Qs]7a\|qm-c/S!~>:r_t2\N˴ 8($QkG!\ Zei+_28DC RZG+'oCq(Tn:\٥+`nnf3Yʹe͢e)'3Xx \B0_\{aK]Ga`(}-%i"pa% ; .+hͶy܄_ <;89^(?_qu}L˂m ?lsq-&T@ {c9sGs|[b JqrRs6i _O 3Z;}<)Ya"U/yR2oȋ0|Qvݮ!R<ۢӗ:3KU)n}#Z-JgGE :ZEWf A9VUρǚey kAWTY|֫ ^!Ɏּsϡ #Z?4)}FU0Iʆ]m!DIcthhp㪏ύ)kfa4PYH\OFp2iG|gDE !mM/@o^a{y÷ M瑃A97n􏺗ǥ׈ zjU2D͕R^6;Ѻ/׾.?tRBb^86G,d.Hє~']GP!Vc_TG7 ؤDc=;Q-Sϣ ҺԷXHC^t{Ñ{(Hb,wIpu& x-;!fHPzAŌn$bP^)gPb͑vg2wv$HPMa v O )@* MʩZL`3Lf:ĩkYr!4 )Yf7 ]oknֳA<in(Ќf8",g:c'*}'j>&&¯&^^Im5  -Bo6|^F89Ay3<-F3KT.yTBWܴ7Js )Ԝ*q2пc;c}cޑ%,E'?kSqN18Hs4}Oq(t$D Dʛ> 'th{+5h+"CW'enEo`p܌UZY@CRDujqUKxSի[ *$Sj<ؤjB &#@,qtKƒK4 zyhqdWQgZ'gi'`V4lo$S$~d8Oaܞ~郈*3}]0=?3d/xp ƌ tfឪ7PFE츗!l]8BlQ>7q]wm)v95yCeǟBl qnh-G[ql?MRM6aB dgji: 1Z8"R R.,xmrY,NYur2N5IgN,ycLzߴ6b[?j;l)^ Y4D_СD}& B&ʂp}( ix$K|C"UPhkmރΞ8ѥ QMQu$RmIodeo? GWQ5 cEFx_DD_Uh8>I)3` azL6H"RdU 8L5&|}:ec^@2'.j@Og#8d$cUt=^wVZa.gVcAY'a`e!rnD3}3*eȤtC[r=E]WyIkvrlI>OڴuYqv!$X-rR9{t9@^YBKh/qQLrnqv !GS7*_HYK]vbCD?)I\|! yd4sd*q'3>BS̶`%>-!vUhRg E!>?cl~Z׏~t\2=kܻvfV-]Mb%ѣ+4GpE#0RCB:;G6=\)H'o VinRT"61R1u -Qل荏 fXZaǾp%`M)qŤ M[+ܔY8|E3Ɏ)7:GOR IQTaGcЬ14= ѭ BC~ÉUҥ!BCVyK9=ye &p9 Ti2mGpN͚[ VPyҥTo>%-XMOtZ"U1]p.GNɚȴq#MX: ?> 8n:L~AS]r*ɶ_v_0%L,z)*C!b#42` &6PHxu{G#ĝ1F)# A_ݩ-mάh{xA# ?d[ʀM!xKr]x?fW+0b 4|)6V`x(nR*GH%pRN@2Bw}yQI ; ~$|$;]v÷'9'9 ;SKO~*,D%_dՙ}$:C]u<శS{u1o/~(}5F.e=ɱ[ƽZ5ȼ3'a .=V>yLtsR] "qfp6w$Xs\~+@:9˖O& -"4#Qbbͬl$(*=#3з/b>) xWhak1:UA{/%#${" &{htζ:ZĆ4Md'F^`bƽnPgԢ}\aG7vB 0?b4%^=<EQ1 f?hwg7\V*⏺X;peT⾇8ni5\Nq,;2-UKh1~,"S*_$Qi"Kf'E^EUShPJ'!TTȀªLY=aO?˛]­B譬iQώOR~|sEwp!_Fdz/05)8l^/9r s` gC^qodҁ@yZN>pj9dXIaoIC YN7\=eW ̫lj´yͩ!izsr{¤ ֟_ O5>gv3#jwbbݰ[4HF(sn* - _/C /4x"q,* ~GB t1/趔fy'#0kѱ9>dQRl΀f⠪5um6)Voa5AF0@,%/Yu{{·%rI2R!\juK\dP sZ^kmA^Ȱq >&Z OA^(Wef0=vdIS)[{ďͷNGr/u63#(~ω-xS˼|] m9q+Vٟu]]%1,[) x>bt2z(F@66 ^ffcM}jsPV h<T"p':f.{#jM jCyf~8&̐KG9C>U hUM t0V*Y%]6Qk~EƱ>&M"fZ"E+QSs@x)P8 l{hDptNNH&͂a C|8MPc׃1J%9QL+@p}hSU_D.3nzzdEqammSZm5#ڼ Ucr6D: CNOlUz`Y($8@*.gK"(:GpV?(4ZĴ)QŦ]h|]2幜"[q-hhM9QDNCۑUH.)V&:dma['PvN+J&\}D[GjLq? ^D"96yCP05bșYȂY\40[3 !AI%UZs,4g,a,*E͚[O5,ȍh O#'$wD<뜳a A#"Jk.y2G{PwP/HB)ڔĘ8/[:xƹr5R+> (\.0 0!XA-6=J<kdlbX_  1p푚0EH@.mY=ݟFO]cXYC3}ه.XP-U8(|_̸qؚ`;ږg~q"W\/A&G1ӅCs*w:Lڻ몦PIkq~R&]4j`ъPg+BIYI6z7~lAesɟT)dڱX?ÑLt0lUC_d[j( @0w,Acm.H7vLxξȈ淯2R!G*&(($$zȈw_w0fBāz}IUhwV^W@U=XNqgj;%c$啦;4p$Ʋ/5 /$<ޏs*z{ibH|hE94zGs Da钵r&(Q}\{ Éyr&z:T}<58P}h^f icRC2o,!t iu!T&LRrr*oDkR$vU)LC}_~ TMZA6>hf{a7 ܺymp꧓67NDg- (sv8EGBξ1u9CK4x~ɬ /\M 4IVzdH=J|)҈jze~7gl LJU} Z+/YL[Ͷa]i$Ųk`hj%ᕒʜo::>jSfHPȊ>́(1Ǖua^fw;OU.C`TmvV~s >&2;ld a ۗfxA #v0@it}Va6"FhTC*Ƅ߯gi9ikqThc!iu|Q-ոqŜLRrLD18l%G\ aVҋ I(l'cmƍ;~w2k Oܒڿcֵ"x3TL<3nk+(koae&{=#CXB"I &m{:+ZU:j^}эyu:3讱bqgWvR2eu6:AÊPobo0Bb2SJ/$y~nV*ErTKep!j!%ze:OkUG0C•::ў\`gGhvJ:!0’ڋI}ۆx;<ȳ+S7+>Rn@7,MGUJṄ1ي i^ {srf} 3bQ6yf\gv/n6V${szնцe>C:Z.Y#5f sAC|}b0\6\wF9V8k娃C^MbJoHA7hv xm ."ک|w_d6i#Z*iH(̢q 3 Leז(/=?08[K@2BICuu ^./<^椟 R r{tl,;/5| 6: 9y=)L>^H7sC?;HUvjZwKq \4|a ]fC~*' 5b|tըF>|' ?N(Р}GMB* X#rCw` $5~DĥdRo/5|wg# P`mQ]b?MZ~ؚq' R03 Y1"egw`.6$HU5k -?2$OoN_S߷ Oq_ͮ)"t§w3GH$ヲ|v/Y>_P vwHc ]A-*jn:kU hRhm3c vZ\U-#X)wMUrkb΢3qh%J7GЇ#05%O;Z5% T0!WIBAbJ]ɗQXə5Y>JqlYJ/ǁSۋ@^W>#|ڴY] 1EC~sFvN&Ä=;zm9^1#\mEN-IVbp2b2 Q3igM8Pt^r{Gq7PX =Z_Rsx yq'mp@"sq>lIyeyjQb3.;Q/$k &7 qm ݧ |46D$v{ wP]T{kGYe5ulD9B$:edzv(S 1#NJn$_ jB1<{R${,Vȑm~Uix4Q |Bh?%7LeB@榶M' ʓBW'tg j9*FeAnq Y(@졘5IAl`27tZ`oJ82#J|PID֤z1y̅9arS )B8>OjeVLwԲuHAL6J.Vizo㘯,$mb͞LdWZ|òI^lBGJw_T8'^-눕7qU*vxx`}D꧔ © ਺0a~vD]2O ">,ǟ6q<{1yVYEf{Diy'ÍK%2UDt(TY3hC]{= kxIV`BǼЯ&Utlv:!cQes<T @v gJacP j e |6ʎ XA9Hꌜ@iy"@|8 -{(鏈 ^DCܘʡ:rJ" h)%^XyֽFn=io]7b֢6c jE ~k(7QuAP,Zh_4(94GI->-Z#ٴ΂6P2A2kXX{!OO+ JW!!I9-;o_aʆWy=%;x ])C[ KM ] _{BDf~suZNxuuH,(wz2gs8d"~cSj*]kU%ׂjÔupW1s *Դ2~POY<&P Tr%(i^z'/xJWo<]nGIdmuSei-gHB,-Nڰ.CqSA~0$Q4 7fc84WA ZLŔH֓uIʟfJApܫ`k:4v(`j'ro[BD2j:ЦMUYۇQU`+U<5\#v~ݎ6Fas/D>X~` :N*bE9dE0J"_ U&Gyxvs^# peH6bwѢjz CʖP>C,&/%C%Lwϊ]ToW CaC]L$MLP&!S?v-׋m 1DTT{h׆F+TgL$P4nYˆ$+Țn$$4q R}\G4Jy՞Bڴ_h/XZO&L: 9WF~%Ⲓy@H]Q==җY0.-lBfáKzYX #<Á݉Y 1˽V׉Wh.25܇pAhȓ"ҁv:u%Rob}/76 3)" xa]Uɣl)b Uwyu^*'^J|3ڐ!hE2\3-EڛDm07[ ev*1_ N,䥞=s XXV~"Fh`hD‚y-4 ζ޶]`5tFO424 <ڟ#0d; Ch oJA1G,͝ÝDXBBSaX 0+-J/&VvOӐkֆ~#̧󪢀󸟥X H@X`P)8)C{Y3{RNL:W"B /x/)8yrgZILF윖7ڬ*֗n3UVOC۹藟;F٤ ChXa:EŽ ֟bC.h=3Kx{AgO4ՈmO2bbC>{Jj9Pq?U:0'<0Q@*!%(]2fDt@0~!GHk̏Z+~*"lnnh N(⦟BWlc쳚Y_l֧S^WE$f\'TVf jl7\۹f& d*iĪFL\=Nࡽ7hVq=vYeGPjt_:H` (-,Nw8$M,.SP#{-U s>4E\N6I$_1-77˂ D{"1m ʷQc?+֤Uڼ7QRR >5QQ*/5AU- Vf|P KO_H%* r'4(`+f@pKR;\tzD&?sOx(d{rDLx^%a~$t RwAFF&+0ٍ*6:J_*)Vd.(Lr,gRvH%VTx!?HXA{g_\xǣ: 0ƥZ릥@4Hyf^Ca3Sٶ-7`3!ʍ%U@G1NJ X{z> mDu&q}DB7ToFiXj"Ғ>[*>TYLbH# V gw!#Ss$UT$C#.pZE~Tam~}D$B8I~yZy'cgpX+Uh' Nl*5va9u%*Ĕ"&]W˜`@7yWTR:-P8qRCgjBe|,KzqP|(nB,Do*"'8!/0J̠-1.5ibe`N ;l5jO x͠*G-?dHEUKl%:ՑvVT<}A%` NІtˋu'h1췦T$fp5>c琱$5X% 1 e @c(Ñ*[zm:H6Ѯlّk֨)T5mWpO{u޹zdTuBĽ4zUv&ˊ7ְ$)f⽆qṂJv5߫&noƾٰC_ FN&hLPi&'*N ݏn2ϣ88ݣFzCw9uXd(7u@[r+&-Lx\h q&UJ2s )B. 6n`KtJsUVt &Toa: d-( Tc=䈠OLXBzl}̬ pfcarC:YwqZ+^ȹxl3fݹ{8ݬt{ `6>@]`ӵQ`|6

PU|jsO#bgg$˨d2(^x+T2CE4J{3B]x%}i6Y&ڻ -ZLQX^d A9aM r2t-⬦f0˦A XJX:|?!;5W244'}צ!O>B)?MmA|k C-bjtT۹EV7=玭Qa\HH!\Hu;%:|u'j`W!jVT%+3u!/y ! ]+đ.2|BqX_]Kw\8dEb1 K2_?F>A/KrhBFBdv,kRuϔ^wxv3NDS%WST.L@3_nclBԴB5hf~a`uU^+濼r* !pzjc2}2-Iwj:ѐNDL.,G$+L|2-{aEy_+`-$kn"7,i[j֡;|#RA.Fy'E30䊙MQ YO$rW۱Pخ>̝7>J''\bZmiGS!u;5sxB[͞f_l4)j1ŏZp0S*+Z_ AÀ;f5ƅP,94S$j!XYaUwel<&sWQx5ܪU t!=!Tߋy$DpSJ3#,~ F#zN؇c9KsbO$K5QF_\="gy>g0 rGdA,)i5J5,b^ydjb՞TEbd.NEh6-2;G#JVߎ @khNZsY8dҩmt)C 9G>\ybv1Gm rRe۶tWco%n(HdTUӉR2i'hf@R~%`N\D:qoY :/#ڠ/ѩ,f{V]Ng0&U;^.U?w >i ńf)Zd1_*-R?N:ߎd;x}|3BϿ~_PDcc\7]S!] wa@i*7/(zI.ov<aH!~BFV{i|`؁f ޮrD>]q" }#&8f{{Z?58u‰ܼcjaonCq*$ ݙj@'e/k~˓QPRIQ ,V+G[{<^x>ؔmr5zN+ׯ uwS0^i"M=lG3O>mR_U} =|m}F[*b 9{C'Wiw4Cjdފ#Y?e7*9Afs |(k7nXi5® qbZ[!mzf]nVĝS|ꛆT_8UZH']෺D~ZVq4:/s3 (p&VH,:ﮓerb'xIyJlZy<=ÞU ÊH'9@ ߤ_ڸyBK/:ĉi^A.b rUt݂yk:.u2"_4>3\w{v;NzB*C UFܽ&{y34`Ý|f*ΉIgL'a|w=KJ\W%pbH<,^oٱҊ`9옊 xquM`v{Ic<q~8qy]QH@JD-Gs`Ws8χۨAGB3yћ-F e hm A ?s vm]VOmU6@E](ETvK5Ҕw/ /@g8;hhUS\DN}"A`8~ooT^T_`\qcJͲRK&WgtNd0 fZ|_}M>ۑW.*`&B7Lէ)U\HOgR![W(RR}k7'R%+ lѥm̰w_w[JVv5s2&m#| o=9 Je$sg@Mo6-Hjd&&  /k;-x_ \`D"R,7uJ@Lz]u'ޯ^LQufEߩNZbCZ7(sZl%2 ;HU]oU| 7mT|9V\-V!^-k"ɲbT\ca߀4jRC|x&ho%:*ݥmR "|4$_H+!U-^\|n8>6%]1/1v5n͉۠C/{Tv#4E~WWlحg+UN'[hVHJ[N?s%JAuVCn]M8 *|^*vfJ_j @BTxJ H4/ FI܇_[}Z@b곾e+u6Pضa|2TDwi+N@>2KBS%ejZyfl* HArqX:XcV3> 8l;-.R.2:nYF1kyVJqJG@}Ld锖zR|Rl㲭KF}1nm: |]&Yr;J/Iao!%q^' 9 לM$ D/yq6 +b,.N|woRJ3{~Cvt.Kғ02OQfD;q58aNkيAU=qN}x@|hb ag@S)_Л@:XԶHyz_E~ TZt;g?q3r=w* -Uc鳈%= 5HM%S4Py1!߹$VHN(cj@3bW#7!ݓ·tiR3.IWU/`࿷gƈ|y)(Q8lkC=c 2zX+!]']S*WP 2Ogs'1:*TC1ge)V.6!CzowTo5+yz-%+_I//,|qv#dVV= ^w)u顧| J6=P)-8>r:/Yf;ygvw-!|DQLΥFϛ/.2݆*DMwZ+l, };UZjJ>r5PRf),QЃêG PXȪHOZ!A?vo9i  Tb4?;Y9ZA0P}B̘>^S%O^ R2?NCBP C p!+LX:~ZTMN/M=mi7: Jtogyn[ 7L$-̊%HˮdR.ĵU|7HG=gͅ,du = oVOo2sCY5 <rֲGb-o:޻?ZcN2'~ІyLmZ;H2F)ѫLSmqNi2mDЖч ,}Dc5up|KXާR\o3 l)̃~G'UHv/gvPټ Sdžfw!r!#^/DQ~$*Zڗ.آYow9ş>$\eA%;I*k۩v{'Aꔟldg^%m/N: fdb󠴲Tko@wö &A *1z. 6sv`gⰫQʛD,Y U֦B$.vC xrE R LKHFk@"R ڲމ}i}kn(p<`@Án'zG|R_m@V,)ev@qTSdGF<Ĵt((%+O0CTuA @z^6$?V.{ Zs`&y`=5@P\ƮkɣGQN>%i\V4,wc$1Ċp! [鈇&5eDe|9u 5&vOQ4Pj$W ԅ3Y:ZPkqdRyRoJŬbIYhZWZ}PB&l]FH8([SB_nG,J&jW pRN%Z ܌f$<7cN_sEV\S=]`2M *op'ze tl@6|m?h)'n> ֌klip_'w ZhĊ"jD̎iz{2i:;*J5&#s2ە#\lZWh\KtG-.mp f[WFlaࣳu<zRDhnH[2K=Uc"#[ Q|Y]AQ3#l3_;tn ʦm2/N!A>lŐ@/C]69ZTq##("b>\7+nxU r_+vV~\iVs4W#~꽂N90}[6P*3 ʈ`2)xG}Yc"C,WzΝ}O5t#Huqπxݷ,a#fhܳ(iǐJ-mks 5eui2t-&Iӗ6vE ʎ+|2vҋU9P% J5Y`=f)QͭAD1 -+W2jɣ%罽w؝μ:n1heu]aۡZDk6ֳi @(GV Rx!P?)9$(ǂF}X0n޽sK6N{C㚼\e K[ArsZ4_ Rj Q諒~OL #ڠ؇ĢjdLA|bJ]ΉАI1k"Yn[́ s s44R)rqA ՟L `mV+|Ӣn1Cx]fxW|9$1a *Y!Ckg7봠߿`Gn]/cZlO" [S,tZzf~o(Y.=G{ SӀP}yI:WTX1XގR c(81N}Z$ -e7#l8 j[TT}h`j1EcY4c&k'eGUcE_PPx|'N34n80oE ¡Zӥ|{nl2Pы)xjZUV^$0t<=Gr#cS<6/nJ*BxT^?qiO/6N;ݥ+YI ++_ vy2}k{d~bԎ,b̔LsO"7xhۇ24,P !|ٻ]:ú=SHjEުH?^ %H6rV՚_ }#7mx90D;' ,i9wC LU;.Eͅ/HdO]%wks^fQivA &/Q G.",T包1|7f}ƥ+ k3!~pS,tD}kƁ) {gDv҄KLsɚYSg1~)SH N E]/F vJʲA{my%3=&#;o/6"G_Z Ο*=E2R(j yN_&̄!+ lB8y/aMU Jܓc=w@}毗rQ*xgD"4=t7ʱLU|F8$C5=&3)cl(^hß U nMFfS ѵ\Y!]U |Qv$shKjrͨ) 6 =/M&QDʈl.yl)8*9|{]1 x{,%Ϊva6@n\K'0}]H6V loCfcy׌#Zuq?uO!J`/v3Mm.92H⪤}*N#~“eVS{-gCA̡Nlz~p-,]B;#4l$aE3sEh0"ު*Y^Os tVّ.{I=p-zw һ{֡v(l-=16ϒ!-ƶ,~hpOvr@'0 |@tB"LW0WBl~Gs-ȥHSϘ0y |.`Da 8: t yEx{ ADOg:,XX,1C­d}wE<8I;?bnG_!<=kC54ŀ@:waiU]dse6+B+ Ru$K ԧoIvPCo~zP8Jr򸙒zmtW` n `zU'e|{s:xt|AB~i>hfQ,RkjA`rEjv P 56pk,+rƕsasq9EQq;1KD!R8"qo ziT(' oDh0 P[d(/nTA1,-,حW #C)$.x=@CG GE)1O?m >=6_c" V*߆Lz‚ Ɔ~_ၟs>=*:g7#Pj2#oEjP;GE.9S&V, OA/TMT*ȭՄӡI+q?cW;yv2KQI/yU qR`r:rYΣfkQ:~ X9ԹYI]QgIWZaԾNE:~"`ۊTFP̤xX I9? @7ۀ-fOٖ2hryOx?[Uah`VOAӟI.VƮ*=GCv(k`KlLJݿLbVu*R#n3JykP>YҹE[Z\Z*ԘLۼ wzrUk37WaΆ7J$!Fv4oVUՆ@VBB'3/=d0!B_&/*=jLZI*%TlZy.SChUC/۽V1#ĦEQxe."v>x؄:&ɚW\MC~.0`ZT*d&+pax}XhV5C4ʖ{M)aMqW"=䁋W>ԤH˲!׺:S[fAS-5PF?-b3NO!Ll KZ%#r;}EAXnWOڶYйl<4-sqS:ܩ3.K&N2{ |T Y9\}'h/-wx)7wڡ|;Hْiw=hW/vI-}-j~oa^6qH9 l b7)oY_C_0]/ d_jS9ԨtA _`g8-ۢ@)-!B 0.EVSY;{27!u>I2D݅: IfPNF&u*od,wG4Zaʖs?K՟/Vy'אм\ * CU̗D1Y X1OM(^ap *e~kzm]y#!zKp,X+uń{ՅPH&Y f5x+-R+ZJL鮺~ɀ^tQЕ8 ~iCɪFO)2rvиAbnn5(rM:Ļypq+Fr Miw=،Gj}2?4zX鼌uPg{)o{\V*g={%&Ed?J>b!)^ICPD:fC53ug=CIRK&( oRg`WWsuA jѫ8Ϲ}zpU>m.X[^$@9=6;aB M6 DIU*po)qb㧛i&* #2(L}E_#ȗŻ,ױVM5uڠkr?ң:E]~ F1S/|ߐ~qhCze3>tHv6diLܰb=&3;8d[];7ab<?'94ccf+z=d;M.*/cXz)?z+[uKNJl?deMa2P8ڭL,i׾K\2e8Pв؇VZ=ks uv)OCvP*&# DK%s"K dIr75q'k'ҤI; F(0e$k*泺,%݋+_#%>ќa99F0}5V71hHA_XUD%\qN8!>uJg^E գ/Ԓ9ôQ3 qP<o=2.FAF@=Ix:~j69mԃ(!yτ{V7Z jy&(47ii84PD^CS@8XlGѢ%<}F2uZ&<x%N+} 3 y#:cǍa> kOb*G|kM?ZA-z^j?JP= ̣zln )) x[Xc-iYrDaQz>Jm<Yc{S[ ɾ %䍜^A-/ZRZ1?]JeX0/2=R'9R1( K2X&|4!U{rFĜ1^_çy4<+`;T?}1̍V74tiʴ9ُ*HͅjMhn xQ M.u]s3N=lT#) b/2}$';{ >ݞ2Zz?cEe)leM+!AE-nWXKR3)k!~|oS,rZ A,Od6{VLJ?d];3s7˔~D5IW&B6z{ "}o,٧Li#V5]5rlPmX[>@obsc)寿CUv/s(I]ɮ2 /Tu1 h2oGZ#Ln\`]qh6hlh5>^kI7eթ~ 6 AŶH`e$h82=/Ȁ~:FERy!yǢj+zC5;?fj\KI1^tVQ+)O JyTPo; dFr<DT6K/!B=a{y1@ƨ hw&_xؐ_ OZǢyqm\9y-glJW"5 1İ:ҁEJ5%#_΄Y՚x1?-5L>VFRz~'/MLSGpNje9Wֺiց.("@=> ڨckr8BN|Y*`2UASW YG&*0k#(\]qzSb .:EJٓ(u׉&9L+J3Oe#w>u7fQ㩐ό F3Oc]B}$'_pimSS~M~N<GH`)9GC!m\~+[JK}.*|! GL+ #`90Nn 3 [{Yu\Q]spI)go'C^>5<٦6~A6 V5t,G"d:.ƶrL ,9YFq)/TᵱKk\^Qe0c.2NWx !_PX0rz6RZ7SXJa䍤F΋vQ-Dhʄ*v|*gV7YiM݉ET $)U"v}f-%p$v~l "zJ({ӏVL_APf3Wuߠ_}Ju3m=gdEy 2[8LC=IȽۢjaM,,Ѹ%x/E5C&B MpTM΀LbJ(YT;3! H! w >|Ԥk2ggm%zal'TV +J4[W(3"KZb1R#e݃BYe"RPy!7<^G'F[?Wɂ~ | (%9~"Cí-mg@/?!A]sЊD=yfWMYX <*'M+OV33\m `/hg9zt; q/mlԑ#vK]n|OϜ既&\#)bAs^C+ -1̸)N_\uj9]S m.ܿr'ڔwp[T)wB\Lr0y;bVa ԰*84NmxpejĂ.eA2 J2qNs+ S*<)C2I} sTF4U-֓KJ7')T^xsZE "ޟ+N "%lʰÿ8ҥ!}.2a;2^<΄DsȱL^ߣqߍ5pMB61p҃r :ֽwGVhNF۴_fbtPNH/ ^&W~/.쑙(j汹/.-^l7 sar'AABeA9ו?:D$:DuT7BSdIT.tjJ0d)m8|LhwYHjj-5G]lRSJb>JrʂRFi"uw,OG) 6Z5P|W9f9 2Ⰻ'eoU|BW]Ό@Z OsAꙜ֘h CTv{^r31}wy@\k'foÞ>3Z lU剱<)~=vncstN;4c]C_*)AɎmnyDLŹ^OVؽ6OH=?|3*t{6ܐay1l_SZ8Y, }#Rm׻g I]6?~DTVofc}@Zs#)laZ e$bF އ̫q0 {EBc9pԦf'+Er!I(fs1y2|Ջ-E7 Ĥ3k[#*$V ?Ct)[wZGHs)îST O]04p_3|a%)8c6o!UYASsfƦTH4-O>xꔷ>@KB%`‌y!zs=B<,mC~am fAkDYp~lA7=w 7z?n~tԇ4Ɲ!a`$chnWF&oϢ|p/PN׺ 2r2Tfٮ[zZѫzF&hCvDQ6|Ec0t-RS~l?Aiv9(qgUG%˓ 7r$@ޕ`_G;ebSOF2c hHlt>홣e)B}BIrT Rqp iBc7\dI$ȾW S|2hRUW~'P^`PDTry?,)-Qc6 GѺ'Px\](JiO|A]Q:҂^|,y:^0@`NܛQUK"z&z 6pT Tgl:ep{U_S3]YOL}I:QNP T\Y`rd~E/ʯthryʦ!kzkS gr rtY~DyK-Q^!l;ܐD`́Zbey%4a"-sL`ޓzJ6]4vG~X618].t)[ˇ9{]uH&a}6Ү.PywQseMFe͞D؋C ,EqV=7=8X`jt9VZMVx+yĀ{O4n_:ϖB ´OyޒO?O\RՕNt(ZV(pU|YprxI4_ul~ifb$L+Fs$vnlq"&G9`QH<h-nFB#`ʥ49+n/!G~D#bXl#wZ(cQtQ^GOHџK*G+ʖ8ȻN ڸ RQf5P-q1l,h͛"; ߰c8䈜=]r0#o(2&.~^qz j˺{q ot'd<8q'D RAg H_ڹݔPZj=xl}V3H|[_@|!%KBh )R«j#%ſ'fu#+I 뮖K$Y c68%бJ$ӞIKXzŁ9g|˝!0!SB8'%O#o#~"v|ˍǔނ2Nl\DESu):dZeнN4?DάwPEZcˑXհN~X&B@QJ#*p̫#U KjC3 !(z!bU/UaxxͯaWL=IO3s$@8eg Rf5`%ϯz1 &\:EsS 9ādɇ/oא厌n5?3߈+p30ZnKHtUiCL6 pru}< oayxhvRi9O8a"I!/*~RO%8jŬTPẸfL|X`S+*fDN/_7:|jCH@&L@/` ?ja1v1iuMuLOWa6_͌\1(teXA {鲗zIēVݳD %gu?Ieѓ';MmKrI7n"-?ͽмS)nJ{ 2YM&Fgz}-I8$WSItaUvvyԲ;y,ltҜgoiFcޟ2)9 zVj88?ѢE]a#μJ׳^E旣ğ_ZNِڇG/3|ǹW֨v(أQD8̓~5:A(PŰZ zG-@m[OS!r6`/+i] g li2;{,HJj6Olvb/je9r2 h/Ymhlݳ Uؾ N,e)rIn%,x GK>keWVK~v -&Uy"U{G4zV8{KnF;9T 3Ƨ$tȶkw_HH9v(e Fol^XZ%;!*@ϛy*Њ2_sf"F 7#d7nUp<M z:M-::տ/ЧUdO•˶k=WӚCA'$I?i/-JYҡqQe~dz~/' h,=ֻVwhCOFkn'5q;bǛwhLv86ךǏޘ.N+O 1#Wt0ϜSJt~ªJ@["n&~~Qepg:vF~:ΰϺOԅ]zq>xmuVlhP G$G1Vi`gcV.ؽO7AIƜ"C ]>gȾFyQ@0,Jw(.S 0. ŗ .\ %H%f/9NeGJR Hp$iefӾjQ0`q}]NnE+iWaT;jVmEYU.3Z]꠻3,,0g=@hs^\q[s4p dУe wy>;.-Z. DBTӬ'w+s?'g5ۣuP"ȧIf1bpRרN ?f1^"[2*n?n!ei]ԗNޒ;ʡgʗG;x)#euÜ,|>] BMzi"[:n<ڔ|Fc<1svf''ZDŃ(FkFULcrRL FϢ' dtF#G܄v]D5kG9f c}JJ S#}Wt_pzԛ0-@,c]r6'5^uvOlυ;]p5_mZm^=ܫj/]u!&9seNZ/y][~qZ&^ύRzV >QOkXӰeΏ3Kh_ w*;gͿ1>obSpg1S]N]0kzC;A_d(v|41``œmE@2>+~mKeRTQv1ڃL@4}%D<=du2xBMM쎛gT18f?C}s].2'[%t ^v!0z}ȗb"ҶHVCӁ_W7AWQX:A c-XE ' nK(|;n@% -nfeIs6!H΅|u_)DмzX ҧ cPBLǸ&%}ydVA}gaqĤS:IJ]siJc[4^`yJ?;szhLݿ]9HyePl[]Pk?u @+ko۬qhrMyZW;& ;m>+bQ{[iF@^I 4̉`?J&;.iODA*hX^M쓜-0d_F>֗x LNj^"Bw#fR[օV"Jp7VaZDnw! =Էηѽy^|ICfg)-LOBf鈠SlT )2 mbAYE*(԰%) V3B FzTf*&Oܝ Iwwi)U,vU@4" Mo `C>ChLisG98YFCc(T%/ ɶyw2L|Iz8fĎl؇X9e%! My.2y>Z+r5YEIAbֶh~Y].6)^B{JF8YJfk5S=?/4*֜U0Z+`T rOm B1 $,>SQ: ֲN@ٳA'4Jݫ`6;P`#n,Plk`20m sqZ$c&)76jE(̅&RHnTM-ٱ|Q'!@Qf1doVPZ[BxEhU:Ξkí%@I<>ҩzӪT"J`)r:sRHu~d%IkE_ vҔgvL=WKzDV{b.e4|X\n9%u" =+vpeAɮǻ71pol\uܩ6:E J//OzY@fS{͏$R8ʀwu| /."LOݐ?~"ّዾo)Lo#Dud#)u&޴92' dJFu|_wVYb@&zLZwgBa8 `J_*aVzcVl>:%Ku. ?hQagP۾/S)ky}{sTTBLb!.NKŅ.~ok" \"Os/5oMnWJ-7j#yLYaPwV4s@,$ ߠKYx 6! 2&iz]ԫ?S:=XqbP1̫~:<Cd{5%Z.;ͭf`&6^m_XTn;!i !xeGrThlN8X=]i(VgN:e 'M'+bV7} e+ mMN~[na #Ģ[D#E&3Yr91`ް)WVMTb>YF`WWk32qזw751!.5N\63nt\z@*U;#lz1-[33=$,t2J !z|+ 5).N:5G x+2Xvex'v`\Ly>™O1$kYfJFbتkc!{c(/R5M=uӷ?rwPW\N-.`$)˼C.hU'y9E\,8`42NXQ>Mu)4'$˙Hhi&>7$b(9KZHK]EZa6<+PZ6J5B$FGF"4vy' qJ,W\)KD0A+ɕz:Ӣ!E sPޟ$!;=[Wtk&|l'Aq 0߿ ``:=q\3ߐFwBH$9%jͦTfHUC"K \b!?[hš(dW㫦 +Ukfd+ eW.O@v][gruXjIt{2td{Ѕm62(=l2Gb*?!60=VΤp3kW`Fy}ؓDxVG1 8 |+<"Dw+'i#"qJ5}`Y]eAPb-CJ  m>o['%㵴=YaU^*'"r~eZ*{_y Dw„(%0ǁj:K(hOeX&&$mQkY߽Nyz05 / U_ZF2cޜyFv_gbfm\Eϸ:ymB{wKغ7x5uc®Z:RK#|%r;h=I€~t<#CZfϔ,,cznl9Q>>+XrKƶf e 8z NH|W@o3{?M&q_5#H斷A1wI\k Q[U'(jx?nUKrBl9ҵ|`Ԃ75G}ٽkCcuAxN=1o&JfבY|"1n1Oo]C4d5{MGAyB\)O;أ/]/xj4\c xf7ؚ}'&Hv} IQN2kɋj[hW*YD0`-Qt L̔w3`M0^Dj8R%1t%کM2fO(Kg; wȫ3X]j9kK I4~@ U#έ5+f0ѡ)A{}n0WC$mg)//-#wN1P$uwlw>bTuJra8}qʝZ_˘i.ŪkRn$&57EOgw!٣S6c<h 3`6>X5`0TגP"R"~;F> az n9t꒐&6į#?Xq^$/Nddpۘ-wuS5BqصcpmLCa S."ɪjqCÂ4)" q:C̍A5+~e ,*ЁĽ 8\" +lA\* flwQa}vM t/P"h/]F/8|9j.ͶlFE,1} ?т 7fvx̝@SZ?R-tbs9*͆l!gUK?V:B<2̉}UUpZT\wi'@mxVfB巃U<HhV9e>]1~ILOuF$*Td }~]u򭳘 6뤟bb׵LM[Bq!sTnX|!Nf5Zv4YMJ ) +s%Z1 ӵskekyj.񇗤#Nmx6o-4I|!bZ,9>鶻N1( ڠpJ,;+GW--aUX p遾F]FnZ#‡ZjIEf&leZjiu利WIEB1(B)rTL %JXV# )1,{3vV=*MWIş[[7il[P;0(xŢw>U_ˈͧylZEKWP@ >;C,Qu/V]ћ]owl@*^}]J$ r8u@Ox}14W-U y|Q`5HZkD8v:6b!oyS 4>b@9isO~x X`bkeGy( k#g+rSzzB0wܠ mof59qSԪ3dh+a E:GDB| YͥݳA9v1=r[$^ř{$FsMk=@,p2_I/fтV{bD ϟ|l [c3"Q\!m#~ĚR6=TapgS!(0ۘ5"^ MbV6D99texESۤ[JX;T^?n䖏QBf6^IqբO;xYPOo { & s|L͢tyIa7*cUmY3dq/:?q-r)oWo^/;:)oWkdā#x 0//{+I?>fI!cy S\EV*cPNx%[@~,ky3ZNf|Ii!YRr-C%h>8x,fs|KJCթz` c:C/aKexQ@r5 Xw,MBh ? Z~U:ɔR1;@Ӟ)yߔ@E]Qlhnʿ U7~v?6-t:J*xR(X2.hsSc⓾aH"JKE}Sk4IejڎD?@qKuF7.5Ӕxo2[,/u~tr)ؘJʣ&#Or2iWKHjq~(j5>% FCo;YYUw#PT̹%q=ϱڊ GEr̶%]?v%jɘϊ5֞q/=..YhݍV$zJGC>ryz_Q3Lg6PL ^˴|8*uR,ȫ;$ᔡLg$h> 9د;%;o&_ٮ=|8'왁6L%ډ1cCy 8\G c*=숵 Jcfxʑ߃v<}AQIU"T8| <c@ "$Úo%A{!OJlna$64)O{I5b t$jk#Y.Kk# uNTZI909#\[6LR̄.zuqC16Wj )1nߩ'ςӂ! ҙA uq B %Toή@-J ď\%Cq-GQ (dPlX^hߚѬw?$pG¼cCJܦ',H(mf5pn,"uK6)ɏglK&~(gc;$ҢCNf~w9ªap"q< lXC$4NEO2]h1,\A~OGDG)`:?[m9yR;:}xJR#W{7Fa_ƀ['ed5.m2ڿo"8ؐu/}VcFښM"O݃_)a %>QqXq'h:<`$ !IPӳ Xi>,/*@FՕ`j,ˡҚ {#Ou}62ȄiNg/IzZvvt X1>5#Ie0;ށgs=έCCٸ.TdXj8k,tVźzo1S1OEĖ!/G֚PcpM]ԗж!,|R5PwBNL*hn?7MS i'/[|p0LS,`> pJk+%A^M)6\߭'. wcxx ߡ"~ 0]=\֮e%DYX¾EY{pTa4!hZnq+,;' 7?"3,rbsdp$S\VfS[> |u?MW,2A[,/$FI 'ԀuH3fC5X6.emm:Y?\{HHKAw?9cʛΫS@klzYI-T\M-VGGaȌ;`P 15BbNQ nN#'zOcC-VnRGLILʓ}ỵ_X#}4c6[y :我brf+J)<ըMP@ʑ(U ;5d?oߦ'"a=f;ahK^_n5ei~TqKR'?g7k+NLNfU*,GC"mo̍j3w#P~@:"i[zo6O1N;DbQzGH4}@@^LTKɚau1m"z2x .J;wgnxϞsb"]GEˈQM:HBNUk+G נtQީܶ]N+}(Z]5{kٞ ~NgHKߢ0~q䦏¾iq.Yqk7'?CwMX!C}cv~J }VrX8g۰GT[-Vu,N3(k\7Os_(U' ]1~WNi.pÖ"mb3 =-~vi*lN23`h=Љ3C˛~y%4rk}"*ϊ1JDW~dR'D9Qrlұ ^bX*uO.RmkNS>E0*l$'XlL?P\e_7#gPz|7h 4:9/M֌ZSFwؒu.߄{;2r^>Ԙ2W/x5<<ފ ĜfG?t*gy%R'rh-DWIF'uˠArR;+] /b#6| _zלnK%=/-Zvw!ӟrdjءMzb7M8ȨzwV~}8V昲xPՐp}=YyQGHA&&'u?2Ip>%{^m]&0¨j$Nj0S4"jOг)N:qBgiE8A'+m|ڹjr'gIie8kR?C.2*5&y7W9`z~/ggSte\J"xίvnƏM*  ֔@9Pһ3l): }jݔӂPZQt:~MF *֧a?+ M:-YԏS;4fq'"|,.fϫWQCorHʶ"J . S~\b( j0S? aD}կLUV^6}3bCVl쟊+ |ΆF ϙ6tF]N=K qh'@|u 4 v dKNX1$j_Ս{y 5$}rHy_ѐh\fXhPZ^M&,}oc|kf"+n}>㾘 :D☷YP |o|L+fe_?-:M``BdǪJ+iFX/+.活 fx&UkCF>{xo~S-b2:ion, [xGW|9a4`҂(?6m,UӔ{9 ~7Ry(hv 2&A8+c.}w>p3-F(*J,]Nv,{͠7^_2mYj(:.E=5he݈`u?/5%bsh϶($%#mbY %#g;L[θݿhͼ$Ql0vI=qy2H)OM f|Fp-Qm-\h6TmMNָH# ;KRx0kTʛ/"DG.&w6I)]xt(#[|&"Wd>ȓ]q{w+R!~=q965X[_}BIsk^BCtkS=I䳴OV@|q6s`gey Nt$4zFxmpAEi:#k++g%xmv¶s,lfx.=C|)kj>;L}s7x]bo0»$'!lD4$L)E8"v,|0{˿sH<*ܚ.bxd9Ge NpQo,aCWb5*|Nt1 GV+쎿?cː⠫3ճQ+OI"6Nb2T>ʙOrW*v_mwtWAr{OI_* P{ ;4%#Un2\ 7FP"안rK`?Pظt8}i;+pO:p~)TNוG΄aNP9NV6PYH`\ʰEY50cuBU:HW~C-Fk7΂xTaڣ@ fuc'c$٥24-ny Jj}luǻYdwp0)C"UtWe+deȉqȄY_?):@ b7߰*)Nġ{8̲)ER" 1`|)BD彘 D"|d1}+,D-Rnض:G0YYIV<ʆrRy-:ظ50r]$v`=ײ5Pc)z|/HcjPJ?(yqM"YNVÂ;[]{@v>d;9HIX[֔P"e !h!`ܓ?= w+DG̶ח㏧i'wu\L'AFH;& w8oa1{#|bUz9 ŌFl<hI*NK?#0Gh㣋Z͂1fK3DORQ.y3sT"m$!͖;Ƿ-E:<]ϵV.+jcM`r}X|k8M]QP6 H'@Y{. x_mLX% kܛ[KWىzDŽ#.~=]5mhyVCԦIF:ݜ?m3%=C'wC^e9,tJe;@džŅHbTkPiĹ] VjB_ܙ_Of͌a](J^]}Ŗ7 T,HXV~H8xhoEp[j羰ѕi +(*c#D[\Z;R&6)Q5Fc2}ˈlj`(5;&MA9wE*M͖0Tm.5#H'7`@O"8x?e;.D_KO 8a燬ִcnŊ_> U4AgbS QNjf;GqGH͵+!!\@b!r簑<{{RMcW0j8EF%P7*Cϲ~u>v>Tio~j*ge o悹[ft?K%"F]8B#i+;PB3R*p$x-ZGFvGia|$!iޯ$-LmE~ jMecXhHD8&i٭j2uL醷m rnD~}&ڹI ]?Nй|"~;yi*B&r7rd2ݐq&"]"R@ٍ:Tk | U7`ϰnX{\B8s]B7{e>GYaq0;V!(YNyA~I5M 4t{ÁHF{i<h'GtosP[ڶ6C:VÞiД-p6cѤz+k%Q>0ԖWú\ bi"@G?>3'Tl So>]o`:w"qPvJ'7X0?3m"|96H0Ytt^ƥ͓Fbvυba&:,!r: pp@0T_=SS-B'8c% [?0, k&.1a %u~߅!xhrB$hr0`0mf>ȹb|%pOiu\F(8^(_1k5ifۧZWs>D ܌4 LVV ziK7bNUq$ǖv 34qR},x!9#υx6FbCH,3>GW& ūqttR)f M[^?~Pd3wu> 6}B&aQ-k2p*wC/kVUfqX>*k6X8; to^ F+& =+]+=I8|A5Ֆ;~g?s:'#dc0Jkڷs ǩZ=^|"[x'qD-iYQ7ԨCf+!tVψ[P{3m~4NI賧Htj 0ME۸Qdެ$d1pz^G4,}DsjAuI1黹GZ6?0]Q YeU(@s"p.r4@}. l~ ;MYY>Z]&rǏ9t;X2bS-Bl[AP Cep}QC۲i~0ցۥyh༆ɟ ͚ }]$1;=*/aĈ$ilo퍣s' ɼ5TY~Q`\(יC8mY)1 (vr:q9*@V:PP;U>\ Gq>1=Zo u^tb&8&OS6URdd~0U10 U/V G3]|Iym'XE^g-x&NJq+ *6xd0} HR01z)jm`EIc3z0!ܝwbG%kw Rմ *H [o8V*T3~'h@|DYa֙VS|WZ>9C+MN57#s\ z=0D!]7Y2 #}Refwh(6 S׹4,?B{{GbkzA(s%Ǡ-7m'H)2e17V2[  L<%Ydخʟ `:e\(R[p|stϐ{z>4E{-JLܗz}{IEJ-8 6I >{y7LBץ0]jr&禈y͇] -#n**va 7( 2VSR2m$[zISr,m$`.ܙbro֢ Ϊyt(8JW:eFɒzjqpAK H2og r*3 )şP D'J$(rlGԬf&xXr9i,*m{7ϝE(AX`U_灮>حm tz ha}\1ǽgjbQA7΋~S*zxqQ턗٢^:6* vѸ?u PvmlPP0}^~h{er+.V=7cղ+I~#(_ G5 T9(p Ke/tǢDkkn!kp+PNDL 'yvO+ 5]Рj 3$V{U#;*x5@5M ſ(t-Pi~e R^ioic{nC"+#Aw%r5,[a XƆ@X"FJqri9'@ߊ 6fnp?hy$oـ]ӑ۱ i tP}}SJ\؁-B-j~D j}p=)}"i禔nFOys^D%g4iŸ*QߵImȂRӲ71%au{N-uC}Фq$SsBO^|h:؋dԿa:y(|0^;u/V*Rcl/ "=v5 tN5<lA DKi  \p_pb`^|%kеA-#W ӋSB$S-Gc?#F@KE+"Ƅ0_sO іe*gV,[m`xx[Pl:%26G]vAӏZWC%ck{MKN~Hw:G` YEz˜lOW;(3K,A+v7cٹwTc#@}Za/RȯZ}tq;0 8ɁY̓snC"SPK^f{'kTIPbbTr45ᓒmJ 0pԜDHՋ.̪zhζ@9>2QC":!tԱd+cF&H(UN!75a@zڲ0Ҕ _h~ncXZۖ 2NX4$i3fwqθHn