pki-ca-10.5.18-15.el7_9>t  DH`p`*$ƨxj4IB-C_M=z٥-Ϗ@SΗ5{7"F b>ϞaFD3Ɖ752O6}ʐy<< u, OK#Xr,(KLVmA7I00{Pؐ" TgiA+ak7_>:R׈+ӸաnM?n=@YcWu?p 괖볪,«̆a06l|=~E8KYe˩H_`EIpA d3P\Ec""z{pվr.ʬ?`Vq"7)"KǼl%!<dgT 1fq;^TWU){uqaN`xO$J"!5P(9"8D^ń4.mMD\>&%%?2010489e250214c88310b5b092507eb1b39ca1f43؉`*$ƨ gOfBuaΪI϶QR$/bf0W`~*Au~ŒP7F#+l(̒V(Sᥖ_~Cbz{z՚ +/jjՀ)wF+QtNkgc&5Db$2SEӷb̈́Mh ~tҪ k`n}π8 ho_X f0'/h~ mIwv4jqHL1[L7#z;ߢM#QęM}Ip/=%FY2d (KJkHW;f^"200kQu$ ^'?,+W +ˎrƚfX mg`t|T-Sl8qH:GmS]N 7{+?1H ',<ի̵^2El$s3rGđ&>7?d   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P 9 :u GiH(iIiX8Y<\Pi]i^b%defltiuĸiv\ wˠixDiCpki-ca10.5.1815.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.`Emx86-02.bsys.centos.org%'SCentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤`E^2`E`D`D`Dz`D`D^2^2^2^2`Dx^2^2`Dx`Dx^2^2^2^2^2^2^2^2^2^2^2^2`Dx^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`D^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`D`D^2^2^2^2^2^2`Dx^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Dx`Dx^2^2^2`Dx^2^2^2^2^2^2^2^2^2^2^2`Dx`Dx`Dx^2^2^2`Dx^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Dx^2^2^2`D^2`D`D`D^2^2`D^2^2^2`D`D`D`D`D`D`D`D`D^2^2`D^2`D^2^2^2^2^2^2^2`D^2^2`D^2^2^2^2^2^2^2`D^2^2^2^2^2^2`Dx^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Dx^2^2^2^2^2`D^2^2^2^2^2^2^2`D^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`Dx^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2`D^2^2^2^2`D^2^2^2^2^2^2^2`Dx^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00edc31989ff618bb94fe5e2cdf6baa1bbc8923f301a7150f44939f5231f77a46278cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-15.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-15.el7_93.0.4-14.6.0-14.0-15.2-14.11.3`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-15.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(0ywji>>\>;qZ!b_tyNTDtlJIW4/<؟d 5Ig⦄˝-vzZ=z^ށDGfRkuNy[^4?)%Kq،[AY@(=“LYukuc.7+]H!- w'{Lhj2r`MX]m[ Qq P.XciYZsi;1h<4 kFK#=4]VyX@1˦ q #9 J1 5>l?KY2b4 :`Kp~Ķ*SӵmS;4*_J2wo=A!\ P)0 EН[ɑF㘈:#xS14c@MC@m\[^r" <5BV&F,bMO)I:?LN%-b$@ݿKyX^no HVSwc%_c*FhŹ{>trǡN:ܳ쀕ٓ&cϟa8k}Bebх3a8/ˁ! fuuFbdeg /ID l31iUN{vqzl~49Q hʔW~HJvp+A'ԡ֗_SK\FMjb3ݖK5|/66^k * ],Yfc-",Z;UD:Pd6 q]jtq ;f..K)c3 a"e _O-Yu\smLCxYe_dGK;1c,d"E-xM-Tq%=<[AwܖH-0$c3)pqچr߭z_`hÚ ?h$ *],u8мqw+ВaE*4?=n"= |};&Lk'Dje["&@OA>ߝ uGѼL^ 9.PĽU@ي, ;gӷ%EP2F{munAH3thU2fSsv_{Zn_w"F )15#f]=u* Hb ͙5bSzrJ48̢4 _69e-Ujkh%dSbOrʺ$$w)V5Z80 5fҁϵSx"xӺ 5C~ٓWA@ k{)nX2v\_9G{}/Ӛp"\/g?03K)7?})'IVW`6 5~`L]IPk&*.jܕm'pP b1Oe_w _REOwz}k'EqFfג!ZH($R"yl]/3do`g;O*A87nbz42]r^=!nݙW2ـ9DƮmVbu iJ̰ӕ]8:P((jqa?FEР9mV`yIl391%]2ZY8bl5ߖn4lȹ3n aZ2F!r- +c#cEaK@LFAӑ'X7.tX|];1 =ɉY#Y#A P˫lTqɥB޿ĚY%LI+/c3s[*8({Pm$19||q?Ξxv1\SK\=,#Y&6iah MYhRNI-Q&, 6'5n,ސݑs(ՊMXV?(ے2ⲿJx;Cp ^APN&{{G@LRB V曋BG3_pH}9`~_k9d #߂~ Iù^IdRzjQ0 _׵0 x1ηrQ fyMPn˂Q&Kp;HêS$gCUK̃9Cj2L4I"CzaB&,%UOp,/! :ٖ~QCE&rn{ !06whՂ5ܥn@EC%hwvan~=ԓZ4 CLjP'C?|n ]O+cɉ;໨2܈--9fvMPc\ɺ͕3PUq(Q=F2bC?Űٝ'JWbgN(Q8BHNzhWCCң T>PoL;v֋ՙt+*HѠxJd {8*dBAҩ⭪<ΨBK#V<`b}Bbr>өԚYg尦qf7QS RKz'V`R-TYߛ2jRGhbf$;2B*9QEe64mȢc) ߥN"CdJ.m"` FJK,KNn^DQy$=)gz祥>(K NnkՋ*۳&{##cc9p? &Ai3A sWL5Z\ӭpK Nӝdk(8L4l.}.ԶO,W_"M̟]p]" ]a\Wz/3h:ؿG?=DS~8֦?Կ8DO5S^;)/% ^ڳ`j6=)~bD8^K{ls "&J :y}AhϡS3ֱ}޲RNeǁ \C0`?rvv^ o|NF][HQәV.$FQV>y,EP x$؉/w jԏ,bfwM,TIIj?3[֯fY%퉨TϛI$H?%*O<:B]TWBaTzPW0× 9l*63vڵkA#/1< ۝nX|\]G. AUkc=+/$EQ̲ %A҅{ Ei45#S*2EDplU⶷ ɦAvZ۟}֗#EXqY#޽l<0gC4B "8PҾ,E}U3ayd#2+QOS_:E$R4 .CHh6E>kft|L!-K]gD'(dvS҇Y]r1⪢B.{[ffH1Vb|Ȧ4-a ]8ͰYK._{@Z09_4$ ~oKWКFbG4;,/-S!$pT!;RtNt-ǩ[ L?%-!Ƽɹ,i>#1ABS 9ma)NS֖(@VQ{ <5JJ)n3YX7:ĜNHGt$얪L3s@HY>U; h3A[EQ^tK@㯼0*/D4)6s.6Z $# :B ko S*3O 9%:U yO}*䷵@_/a2&W1[)ֺbM[⋼21뾹kVhN V!e;#ګu&. 1aՒ؟/ ) Ct=ZKzɿƷ :f6\~H0%6jzݙ=o-rVxF~bhuʶ6c_pH5g wÉN kTۣ>i xVsɀHDCg 6&$GCZKrƂ2V}vݰ 1LVJ9^C&NGnUς'yoH4?e FNi[ط 'ZMKv<\iW!I\4$"Y1̰1\ F]yY/u$~o`i˿(#>aN{8NDIlX="?XĒGEн ҁ U?TkG7_={I6|t32rX B.'zDZBmnM{m킦7W9LW[ ,Oia}hEp]{IL I^z&*҄4I'hCqns<;J_>[qg Cg>uOGy;?f'Z8yd6d"=αU\lP6~u'HZWpVrBM`<_2%es*t w)j.85K),>ZD`Yx${FW2 {M4 `~]c_C["F[0MwyH(jcx,[ ^do~ߋgf#EG1|@krNfm=2e1|EO ~0y#) S`RX\n߈PD._S fk?窌SWnm+逶֏<}I45cɼOX_WE7cK6ɹR5F_[)IX>o'\TnzsvC o9Y4AⅠ?*>`GXZ(\f3? ¡:t?63UuŗTNzס)b/fyDb6G}*0z0)و8L[<$Ђ"ipQ~px )3>d4mFi1yH'6'ﭪq|~Fd_"8Lى=zIKviJ!Ҟ>N!Az#M|$su $RNFNh v@Oe :ڤNX#.ҊDSfJLӲd`Q]Ŕyu |r1+ԝ_#iK񲮅Rl2-=JXFd-鏳9d;gwGOb4@sM\5%)STVI^۶?U<{|֖&XfCdfr+kl="%Md-:Q>Ps+=J,׷zIRUx+NS*ϊ_qݪ%`|%o#ȅI6YG9Ď &}^K\+ DI(=1' B\D'"4ǎϡ]d K PD9|d[f QW1fxLT6T*9˅Ehǯ@(yxP[6@j327.fsbmO;c1n  ,}ӂ Rrp&YE?8`gW8}<槫VۗH%$})-b(t@%)FYGc!}1W%9Ŵt[NX쮸լ#b'2l[,* !=upwչml7pu㛖{`i\cE'UݠKfJ0 ixvy n3^hGj4)cWLB!<#J#747.LFfUKxiۅM:Mnw~g-қ/O yduPP'.2g1 2d.om= /u2g4:0õΨ2'b׽\AbFvݷ u}OY|Ǎp4hٿ: wpڽ*VJt"[T]11PipўphJKu F`)B*?^ZCwo\igshVZ6}XRNS7E(!!L owCLt hǨ#F~ IGXdcSC´kxX֥O\m Z<>sHC>k.3x}u2}olI2.sERQi'^@vU$p/gc zжic 1"_1#ACE,+5[ޔI[,.?!-dƘakemR15۸tŐ[4g ё&E8t6.W .Q\GSK%:&Z7Yá ֱ> @& Z\cChV] To`*hFp.h`5 {pAΘy2AIwNxϞ&g$N=/(ǻ׬M4i%E,mS 2̥5ӈ'wZaɼJm^tZrm.(*^$'#%1H)E`Wf0ٖșR0tEʿl=>Lva3|5v ^yGjL@YpD=34ΜQ9'-E+ U1bNK f/])م7MpP3 a;6> \"xF ,?{|pExDgⷀv.NA.} ,!~­rTdߴ} +ACjcHT}3pI_Hf7v:3=#&.Qءi<)} 7t.24809Js8p>ᅰCfbb<_^JcXv0! PDoٴD}h|ԝOxc[ $s#2n7$XS)SYwt>n {/]Lh6_䨋9D9|Zߦ$`41Zr{ hIE=  };}xmdI(ݬeЅ_hNd0؎?jfҝYvEs9nWK=.鼵|پ,F-W="&xQyI"Xu0XYJet%A|FjĜw8MS(X7)C ;BR#uVs|07&xU9!aZ71CŲTZ)>d}EJY٥?~=]$P 4u.πɀyU6ʂ Din7uP()ӄя^.EXȩ8Y> )PѼ]WL8wуw׫z  %E6SH9bs¦\vSޑ1k,A6~;D4m3EauQp-*'E U_ ;>AҿrEFf?^1k 0{&t_Io*%@;%Qt A+GpHXx&rxR@@qtG%W+LB]wz4I,s( LqiX { w^c>Ő~.~Z媚W$e<1)~27 V68{6{l|W c5WׅT")IsY%)q&A_A6c+hR{+46qZt ;k.u 9; ĊVV F֠D̛jI.CZ sYM!hzA@lfGK6L{P^vz*#3#s{Ѐ-ޢTD"V/-{ -5HwOOu 3xP6\];6ŝX]gXw4Dȁ56'[@gIjf"fvytEg7:`d(fn4=j%1 FQ}[p"Fl*97+I+~8vkJ{U NL\dˉ'ndp ן҃hykXݬR$=HÎqdonU{e)!{w  NhE7q}ȮU\ciJ 5K#B+)=&gpjKv 3S~> ؆D-)z[eSj2=8i \; ڟO(J,h$hm<鉓XtMdg4iR-iznv(&q\djn9fZ~[0``cJpar~z"UTDX oo7E>L `]Go\b4<((`-;f-V@EXI[:30%"tPW 8H=W%'WUQv<_[WkEV#zvG){K/{|Jce_a=V\'jlK^@D̐ N~w¯ep=-Z1V} N}Wǥ@֫J1ɌN:,-6C$WM@q8쀜G]=xUGȸܞ.~ /e#-@(|p|XVJB0b1>.d˔њCQоk9Q%!TL4@=&TKŽ2 lV2캝1QZ蔕CG`l&օ'1a0~q]?F(un?5"odpdߟ*CSYS}3=`52>YiI}%Uh":0Nv=l"vr38Ӂ4|YNYndOE:wH ~vYiedZ⭔#YV1AހG\guIȯdF'Xћl J dӘo屆*`+2c4^8]hˇMrkDǝͦ=E.#GBPNLU֯RQ&$ mz:!6Fsg[ _,,4A R[UEVd"C?u ̢X %бd+թ.= j|y$>ܶ!*QTtmɦI3A#GNSxO @qEO$MILc2%aцƳ2$lwo14C6-*$]DBtaI32Ѭw 6ԳHӫKe?~Vղp('Ep29VVRk+*;.ꭃW3m_[֪kQPq+C`U Ⱦ1wwʥ)Z,v-\"#bo]q;޺1 ڻәӶ(dr Tژ"0F q܊ZJ,TKI[6CT8tcڅw;[j\rT#rGI !z+I-qJ3=zEr+,K\/J=d#Ľ=kPV{{rn8OaLxq9 v-7;dY̞;Q0@1Zv?:7F=hKRSAeQpq܃MT'mf -WCV`hBv:F1$>A2VshGC\֮{lQP$->A_eD6OOrkBVga[{@+:A_5 'B|Zˀ &Aw1{g~~6Or֙+0+Ch[XF(uM~:F$r|1/):}ykg$w +_ЧJb[ !m[bgBݗ' xƑ1Υwf} -/VP#`-y1&>GW|U=71ܬFX#jTe^An]^y Bض zmLϣB)m 7%ۢrՐe;[|PV܌Vc= }jnjߩHh)e/쬃?ٿk;W 2) }-׭o1=׵[pE>%=Ybej(~ D,bo0vA* GC%za&13?;6 |IC%HH0#u&RQI:/%ؿ;D5T;xCߗMnF4x7LZNbPjŒfWLq7:2nU8@`ζdweը?-4";l-VHI(f84u y͎fL)?3y3ppxg ɁwS90|K;$@8P_䩸B8ϣ0>1Wx`\Z!EMeQwX+ _za1 0bIYbR.&4wg[bSEV 6̶]-z̼o۞Q3 h޿$TZiܽ:^:?]n;LBY}nٿz@"אeXLTe}ƱnX 'LEﮚ;&((`^;GfL &6vw+]vQSY,e4Xr)=\@!D ܫ4fVJP ;!7uE/KMSE,z+t@rKsnbς} Qo}cnR-9dq;#gby2 Yc0D!t+z⿧o-u@9ic4=a^?O?%X\֍۶W W)At :1h8 ε?ȳ 8`@d(S?$Jo;":'K>݇ I#F2n[eIМV*R?,nώl%PX, dC@bfPQ?JWIr]Y_!7R FbP"3 U?~C3W&"YCs7흎ZndXZ|t[Z`")!d XZ<ؼ[]`>püxa:wM"[&YEfE}sYׂ M0YHeofG2HYr|/>-eO l9R|MPwK;X}3SɪwN/gǯj0)aVj9ևplt0 GбU (׻l^8(6YlcȎ;!`C/&my)OX+ۇF<$d{c5e72լLr0±015$&w5[PJӈ1'7o]ASnODnoA^w$nE_\h8|<)7xY}-Ov7"݊RޓIWgc ˀ%OԺܬТO'5o'i׃6}zDž-ģoiil.8ͲW֗MrfC^}^g%>`zUvԝ#8Hm0c㺧GlHe^BN_zFѣH[mMyhx; Ƭ5UG7άTry{*IH^IwVOC/)W -胄#`rYfgqX>gi?yϪ!vo?M3C{= 3*1'g.#12Nkt/cP Na*Z}gW/g|i[ͦƗtu8_3 dy"Pn ?]<&](R9 /Izx7nl1c1PH ag "=@!I]y)z1LΩLsq/]fWWq0,ʠ NB;ٿ1% =7ߍ@=?nbR~ǖ8cv$N(Ҿ)*cqL Y0i-9/XlqA#R᠜,m\`8tƂ,T@z>`/7MYQN{Oaʞ.zJeS_ q3) f4LwlrL0NUN'Ya'cf5G>p"'D?%eїIeq5e6c|J1?:}ً7A(㕱ÏYl?7Lϯ'5-?`--W@{`7l)Rs'qOHh.aC (w& SHr!-m U{dv||〱Js4B|X$U9X}o{ !,Sō|ف-WP~)"ڬJzѡ߭vl }jvvͭuJ`-J VA M8ZJ,U{h/~X7E46ξ^MS|}(rv11 CkQAFwӎBg_lFZϺ25YL#UNķͺ^:+;lI]%X ^~|lB5q_Z0T)so{t:2h 8s8Mkcd,$Xݎ_"ƷMTѩKI+7fV)vk~exj^P] ٹi.v m_Z B=:D&y_ߺL|C:olW:J">2*l eӠCT1/zJ&oʣ@EϜ6 (Mגa/RPhz D޻1\8A+\kk{Lm}ɠiSl۬\I3L:*%,Q/CqpFf; F>;f˟N[c解}~ MJ͠Cφֈtq,tbX$;cRr`zT}й$AU䱿LO,WWِx#<qQxчU7 ^&-כ`Sw[Z11!N6o׭P fJ \vΓx^Dmt45~y23H3vP'h*Շa pصU]X% B`<%ߑAcG;F et}s"' :Ǔ b·mdrP-CTi%wQ1q4U9CBR~$'kJxermi܃p͇_B~k(aDdz)!?.uƟH'w4x dsc5,~bK:Eodt8:E:=6lvyᙈidJM |!m/=Tlxuq1dWrA}ک%ln{-/QJ'3 yER4,  @ț!%C0Qp˴^D&W͌RYDq营oWOơrc>@*[ ̸1! L|1 2(kVn ܕ1_F&EWb2Hh:G^Cc-C2gS/&1|Q, o[Q =eJ*juz^ 5NDMG񞧶_7"ei Hg@ 2ջTrbLʆJE$)_B ,/hMGp`,QmciA iS>?~R?‘ਡ.5:Uo$R&tX3Md!aI5D` A2Cϋ bg2vDb*l-ݔ\aȚCsu?mAZ,f1wJYB2| .b_+LfJ}]rٮ X//N,#X1k7=]Dk+}5,%ׅAblWʿrI7+8MBk?vˣ[_Wu`-X<ފb:$|riMͩ0 1gDG:VTZCȆ*K}4 Khw1?d"c-kvy!vƵd-umUʯNQj2u{ ƺ"uA"AޟчG'H`h^_;o5ki2>:n^SO˫@;XvV\ɕ qHLQj0AKq,;[N_59 s^cOeq]ե4|'/BZEMUMnrj$ɟ u,B5;G[JQ]~,R1uq<H׬c)[Fu1\Ec믃>0+撎0AOIFνqD_6u;nZrͥǗPpK͓&v4?f:$*;gt-{-!,kUc` `=Ι% fs#1B7!ЋVWh“KrT$/tdZA^ ciR'黀"t\B[p&|]]@ܳ(:ws^u+^ u:ʗ$qWe_@ap9܂X[ Y&A'w!Db)dϋ6y4k<'E.KӝPm:1 *'ߋn ;ni ۫D[DÑDFD{ߌMQcҍ[=k>v,YrYۮ-m&yoGd$L5?-b4o@ig4& `D 2;BĿk' ^P[hUx<6G 0^5V@QT5B=d4n]PYӲi9:HL03h%5oOQ{7V~y9t0_s<,E\c+z8?(gf `l XwFzwuXK8 $@Ox.[omvGGte /Cϙldӱ8>֒dA6pClu|`fЋ{"1&(hʂ`=5Fx~# bF=YbE)l޵+\ +CdPd=,{3n Ъ2_ Z&_ם5-{-q 4DыI(~CcP#(.C0herHo]^ v3e{ٟ^wfWAel|I؏x-_6:ƌ3!/Ӿfbv5hW<_A${BTa8NH1s{?X%Vj20 ;JX"4χCqփЪIԚreu=8[Υvc:If*J< KQcpؼ*IR'@o2F KT9Xt;n]` Ϫ-N;ۋL`u)U \,@Lxrvg2ŧg򛖘:|$qhĠNZԶֈ'+|r>(h/js\ W CKzi&| OH݅33ˈ1PN Q`C|P?6=̨<`9-$%E|y}][ŲUXMFo)LburBGn\ T_´O~yW#M*#GGO]_r(L`Eς*p(Ȃ^Qb*"KD܋5%,d22K0Zѽ2ڨZُ?-bi$'Q aڛWr}4Sƺ!KQ;exN2/-"!nÈh$ǡP+DKtPbq*rM!RU@wq=I?!5,!$8hnV)[e2hMt N0>&ܴ{F*^94HﵐҼsaS>C/X.N 4Q[d_{reoihFd^7%*nꤾ_ǼQ͛)ݔ:O5|>SBa-nJyr4Ϗqu,u^itݧɓ՝L";r^3׼Ǟ17`14W |5ܐ#uh*,yпDBׄ)ܖ㳱Nwɍ82ݛw f $3V*"na MC9 ms!dAN q,inEI}Q5hrX2Sc k߀e@8EJ T1AQD̰n,C"Q+wJ/Ի)#B<5Y?<2C2 )Q1$ϰC {_ug( j]8V%4Zƅya;q@~&>f"XI.L+ĖF(w/BqR0}L*"Wp0B1rU9$ 8$ يL$7UWDŕeL̉./_ڒ7b?4])^Ev5YWiix!о1"&ku u0_s)rJ4v?A3;1"Pe*K,tG]`'H|,e"*v,E1_$q%%w0,$D˿h!Yi=1? ׯ 6#Q0OCG]߽/;78Kϭ_Xɳok nN,o9sfA詗2D6OvHX_N! YNQ}fh[l(dS|:(}f.iNlIid!5Q-Es;9\?6n ?|c2ROb x\P\ 4@|ߢuIi4 %~x(0vymFJҗ]p%UoԹfU*s{(`mGWdתt '6ɣKbvkeBpX]ysK!fy\1B)Q5O4N/OqI:N5D.!}Y \z"'HMޛ%gg -eBUHzɿ'[D'DBC\PRL?ACc7EǵP:ܝq׎@,T|s k7i# >,OJ|I2:-nrtgf/@l͚.q q/Ѻu.HxPḔC9iLJ9gJ'M]@ihaI5D(]{sei <3 r s1vJecIvg&[/e( -?eoʲm9Z_o6ߧϞۃ_o'oC|1?21|6Dk-ȏ_4Ua:K ~6S7 M4p,l8kQS,jtU@$ԱG/Z3+&rFF}]s`\[2Ofc]89pz~fMW7 ]vVE32.Ȫ=ӎ4{47R M8`L|Z{ߤJE WdE>wOOLPBZdRI@kpgou6mt% k3fIsX9]p%o!1=GqWC kJ:A,!/dm@J5u4^!\+3Ae~u1viI{f"̙l!ۃy<+ܸ6bc bpZE˩tRHPڟۮrogV2eZZpcq+{0OZ?P¦ ZG"o$ k+HL{I'V [-׾.fعUrs:b8qhsׯǐ|K9ʗU&v7?'VCVъv-_& ic? f?'".zwҏT;ǹu烒V'Ǿ%ȜwV24{ /ӌ7ȴldF=R@GĆ`N,Jt3A ` NԆ} /low{Bڂv‰jujlȷ& &~>+ ^q]u?yߌ82aܟF}qhs(cN8fv{_8JXG(M 6H-.MtÜφɋ}a`/*h=;<̬$tV8'҄3tg@tHk&W|H_+7``5pJw8HTy (uɑ%f+fA3Ԙ$]ĮH\LbEdBdә _tbaԝJ/7R5 vH[ ~Q@}kWS!xȟtKLR8$ljjՆhY7K!0y>Ȭ1!(6$R"Gh`gz^x-Q'M>v'RG*qT69\š-5^H.91uHPĤRBXr_}bB ."pqoz*P+6^OmUHrjY+bhL] dd/\ha<\6J` w:PvRNSHR|jJZxjTE)w1[ 6jo.:"gEM\LܿPynTf +Rݺ4ý]`lWس7eJމ[6_Yq͟6/zeϺ !TP4`LK!Jzٔ>>۰ I ꑨ@u}ihF-?9Zz@e脕FЍ2%yY֓<o^, fE[wG,EuC= {j%i7Qx^fryD'g[ceЕN y>\8wcoo'mīt9 '~hшyDjfICx3ked쬼ԯG H~-+9Kq+vb9Hf׬ &pEY! s㭓+9Fu!a?[|F|-ǔ^;ƛ#vL9r>)^Li-h!ՉfUaYxQ3c]f9J7w7لPaah=+3SԚ|'e/Gk([/A c?B-^#4zD4MZu0Lцh#Lt,|e8_5XOB@AĜT;'u\;H]FڵS2~R8pP=\~ʸ +[X& "L$GJ>3f*Caw,oTHʞs=95D"-rkg=On2޶%οBaF\q~'7ZwSdMG!\&/ O&aN J?_ELC |nԂAA꼳pߙVPGc*NavVV W \<= 铠>"1)VF;%I3 @܍doUӴY1vo~:PK, aQ,s >5N#ceDٯZd+5p |r/Οus:>фHJY?Q-Md-ۙl -ѧ2p"LdWzcG^~^QX< ٹZAF]W,^ r{ d՛7ADm$(iVw>B'Joy&ġr'ǯ}!MҎkyB%յWU=〮L6į [Ұ ޚTEwcuO |tƥ/zSW?T"HhCUWH_2G!5u8*4sK* Pׄf)hElT5o)C!YWk咀E3O,e,K,"^^`eZ}x%N Gu*+_an#pP{Xa#IsvKqܺXt̜ᲉfJqOW;wkκ# \+ NbO`6-mU:.6bGYw]Y ˜!ZeW3OM -/2%w#R-mT{h8eDQ}%řʙ> "̤x m=JʮMvAvu?7WScTm)AHh7SNu d.ڒm}ژ,id|s'+'h# 5Z{MmWB)&R؀<|"Y^*>]s[>Zh[d(YBWR~=AѼ^aZ ҅Ź|TR&vHNx:)apTo!4 ^ cBKSS>/Uow*9a1/}<Ϩ9 :%k٩|=M_ TNkB i :iI9I8бôsL:j)4o*+LLl=Ѣ֑q[/CS w5(9waBpG$ȑBJ.V[b^-ŏ ėtKo7% KB1(zDA'L$r}i l?=hUyV;lk9.mIմR\.$!tGL-+Ȼտ[:ǚ<;b`u\Tz 47>K<|D/Ls9F$ o2<[]gڜ34G=sS%S@^d= ˧uoJSuXCe'qeFbDERAYV "\⠃TPL!cJۭ?g }wx1C`5,N_t`uQZN:2Pϻz+yx.`w7'cW} z %g-bըlPiF _ưhqXŠ+AV!MP Շ]քꈓb@?"ez9%%>pmb^)p'UD"hlD >Ćx&zT_S`b䁸?YB&Y qxSU?`ڢ,>I5Ru~G@Śq_CcXk5vzLZn٦Òh;;~{zϡUx[[1U$(zL1â4“S! PGG%>Fh`.s/IPmF(Q?9bMѭpڶ ^}5}voЌFOM-`0Kx9 Gq$ 2a.GBa-y KCNug]0g]& .qݐLxpHZ z2L~[aX0zvN\6d*_XއAl_1ar+<*X! m㍅WLjT—f:빛 op p(^܅Wr=Icd} @z&-;>ys4 [,3tb9:<@ QR,Xy MPQ.Y]7I{!:pә@ðFYݭܼ$H8[wY''ȑEh:VXӇG5ƦQ DM@c5hwCh0/v2r/˝Ol0kP)FT: ''t/QW1PoYJ ;?+5\5-#l}vs+"Eܲh<6rɭ+З8̓!WZd=?5|5*ѽ% TnOFȩRGGI2dtGwC 0sCO'VKmfhFL?rI5.=8)NFDv%~9YVv V9'|hV& ;Z Oykʝ.4R 9%`W,6^H*GD}HWڜ\G!6PAGW{hDonrK7&K~WOُQIW2~PjhT'`~4%bh6M{(ʍ"'?rKϷ+"ԩaΪp"Q13i21fULb6@,F@t̗,[<8n W'zԢR"+ߕ2 BĻNzL9WOВ D$^ǫ-I 9 l%q>6|aK\HeqӾFaO兯 j$PVZ}0Z\70Z-*Չ@E2ؗpc#L++ԍB)"s7T> -ETe1U c)?LW1,VIԬo&8?ue$v|Q|[L>*≾'φ^Mt~ND[0H ϥ݄͡i$kZx3|`S-'y[ zGުt󫫡20 W:ڱǸJ{ﭹf7 koŻoxWtMFcKk*;ScҢͶ|BQVI_}V46{\Bw޻] |64Cp Tؽ0)AG3Yq|o/YC\ĔT2k⇨f V:;yۯ4vė'ky5o J.j1[`MHaQUoN %Da0Hn֧٬| 'j.d8"@n XNgw;*q,f{C U3_ZojD x3X@L.Q~u x4,k얥?Z(ĭmzo"C^y?7-;B2%IbCz[6p($CMYwp?ߗ>7ю }p-Db,rjQ" 'ZVkL5ܤmJNhP'M{-'> fFMYuꖆ[Lv+گ_ו%k Wd`|aK(G-^/f>fnNg~5=\hTDG԰1Hy]ȗ¨O*IyyJH{ VVVDx_Y4),l& ܜ>I ) -t+(ơm\UI8 |]SEl(2- &t/A쑔#V6=.&ٸY;\/HDѰ8M0"I=+Ff 2Dڨ%sL:xGpYM{6 0 9^l@@A(lEyֈF?@$7oAܚ3To;xǵqx) ›dhRm)KbuXR]9 |7Ԣv"F&Q8>g b?m ]p&`]gx3*T=Gֳ?n_p_"뺬5.o䮲o.r{%mY޽D;ELJf!lcNaMvYѝz {5rr7$OlN.т>.8ض ]@!0Ãv9]RJUB;CNvz=$52KSN+֗~|2rHĪ!d'C@Y5lEK05m\t;MRhR9`5Ef|;?ZcdpwUZ 1=P)L[8,,l7vCJ2A>}[\KԼo4i⩠M#>!7ՠ)cf5FpB#dY,qb˘), l*;Og`%(v* V4Hm~JZؘ>g#r'H fUwnҠ~1RuRslt\9JBvQS'#[{a0c uTe:hnfkh[e[1F\ 3ڑ?d(;|@Eޕ\<{ZbTSpjǰec#ϲrEk`T@wX<o 5^I(ҬGQr,IٯYLGU&p"WVm]ToK}h1ѤqP@}+/?<-M4n0}FfnⒹT(xs#vb UWumj(E>eZ̢[α?*ߎTx),SI!_[ש?aXkYhQԎ/ >j#ܖcuG^OܚiFt~FMߜ7^Z,hb'5N(Peb7 Q5G>crnqWҎ-W?=EP>]I%m D6߄pt MoWɓ6\UqFu9hn0vg^P,4+d}$MQ Ÿ$?&6׃ |ϯgo{y UfCt| 6w&~YBҵp:F9g?}x-E 40;4 x13mdmY, ;f/ٹzx+(݊Xij?01+WfLY!5ħ=tZ L~ OߔqBӃq|gTT5aj"u[:V)UJmL=pKצFU5kT2iR{;W!/W|*ȟNuЙ%e Fe_yZj>ZE &Y¼mDjt bJqMg4Dt;&*xu9r2"#]82_CP&RUDoSU_ ~Y" ]*7r~LSF iXxkt]wk!RqQ]E*A/x8`Kns)[7 B86z-0T9.-=:7uw6Or =¶h]P\A銰$TBF"~z2DIlf/S %пccEQ _("wL j ]֓s}]*;ye*XءHKc{)}U, >IQ꽸Jyz{]1]6CByS7k}=f"qT癙~橺p! g.:H" }\m=,XB%2V pƗ+~0hyEg@lZw^d5ي\ni/R = 5xCnXc #o9Isv$AN'!nJsJ 4h 0 6{H u8񼙅P!l<рF??q\e"5뢌ݎ4.Q~2nN"Sߞ6eH/s(aK/N!pYo<^dL)l}ī:uM4}bCk7U8 e_"JÒD%rN l{ I"vg|TFq* B8?lZY"y8It&ՓgvU.:& &SRWw CNv1d_35f$L%[;Z[zʨf׶料Gno[b5 ~\ƍ !pzx [>Umx4 d̛1 =>K>FA&exTל)ِN[[:|W௞}T6<}&Í;"l)SU_>ףDȼH͉6#byejY886HJ;V e]]!Zۤs5 ' reZ89eRQ5è{~\`;68§i% /'ře)D"^Mhw9z_d@ygo#4mxȗj47M¶:&w6+{%b6:)e}]? !:]F)xWlx"TKVOツ f$]TnWJ, anl;:qV"ϐ2X> F [(<7ӢUW5]@Pi'"! o8JfSL +YJ'Mq/o fM`A6bl $I[uJoHh(9kPتήDL2\\9w8o#?)=!p~& C7{y"@עq;*`CQ{}?k9Bj2iw5vyzq&ü9q+GƘ=|ƌhS%23sG 9cs^zI- ϜhT@|c7Z؉mr0-rw`ym_8L9+ jxzrhCt'qOg zi07A[Wa).p)=rJʖ߉M28k)smtRĻǩ` ӎs{-lX";HwrMCǦ_MPu:Izz*jL|1;uЍ{¾ms{kxu`Ϩ4];K1* "aPXDa78@'|F\[c̆u TMaT5nB$oc,aXU=.16\ER>=ݥ%}rҏ)Ly1?5:j,\ Ú23_/S.ƥ" p;{lGvwa{rM{UxXoa 1?)&ƃD: s5VP SC]:O{Aomkcmt^V-&|x'QtC|&>fj:lW)vNp; lCv2u0yyF*x/\U܌^1Nh\j)H-|-j}smw)Ts<Ѱλ**U l 3(6s q(O8<:sjoM)AD٥ Jō`TO~cUi / la9t<hى&O^77h} ϭ|H02=1O֞jXYkJsX04k4E$URXe~>!t3u=AkԴR[rI1}'W=+J,T>O 9h,m %{rK栠ə0"<l82l'dn] j!P@W 1aX̔+h? ㇃'גe yP1m36X^3"@~Xsɻ*цQ\_#vwC6}C(fK6Z91at⚢bE :H0o taab3 pqOY,(Oxj2ma&{R%WqGKl (\-`ͺv6MC.Ahe9 VfC2O\摔}o %JI7IA?ԐYCdUtrU:NPk7`6f]Tc`[s7T r*Rt=IhhO+qKIUO#RLD*=cOϕ\LTACБ{;YUT芸t vE*,~d.Yn`2 B/uftO8/t)\ IRSaN0쭬ߌOvtZ^:#i?kZX`8{c؅t>z!Mw#NPZD[" "߰br!= *R!~gEgR3' =w1Mw]8ű%V C xl7x1t'W^o:p~G895f3{'y#”7(eQ ñ '+j!,ϙvȠ)*Kf-=裵TQ89&'3C 9T.eٞPQ_ (Ȅ&]iORJ7 D8  1o|V5\TB. 9oI?h N|g+~f}S!rf6ǠFɂj SG-%b\gRܧwyhDX,爖|귆ȹ]'NR8^q㪠 ; N6<1 B;%RjmTz [ۛq8<}2/@M1Yl? ӡc|(R*r_e;֑NEq|Fxi!g% ҭVkМQrvGf֨1hAsA*ghZ?gėEOV<#+-˲ƾuST<3 ,9JT b_ rVrliP}킢?P (R\C!~/qgێhdv,:Hs_!d;1[t9ӷd%-*㶙J{x9B5-H>i>E F߬-1+>ֿ~Sr/3 ZHgh,wcu*j(V6! y測ȹ5Ⴞr>өUO7M *"!p&w,(7aIXD5hg]_m?{F4HⱽS4#K8ѕNᔬE`b}!z+KGGX lC ˛H3 >; :d=Nn{>Q9o 0LYx>DKx"ZuMH| GuM,|ϰ7pk&t ӪМ:zS'{_@ʄk8o.u<ۢfћs,mlRXcn$_`CECHls`e9>{snݳ -FmamQ+4!U*6¸݃i^xN?bkKU xn6M-2,4TԤ%UHo3Ĕ &Kk>{Q;(rc4p/W\&f*_Es^c`E"bҒJ (ĥ3l [=U[]rk:81D=msֳ#@߾;*(|oOGILUtHNJu6池{oDϮeU=JIR"ٓŖatQ[A0N_E*e*+5kʳ.[eDNv95b ]WlzD1G֧͒\e=Qwn̻Whxs\1bic=Z7Sϟ@5HV| sAחS!~,Y8oj}=o9u~k&̓O~x!'HA6@QcSm.ǂ;bơ}_c :hTI>jAz> toR} R#NanѶ0?J9WP5װ7A;(dd de#fgm0@Ӎx%2fLTf[%5P' Q)E,&c0.SW̯[ 2A[1a&ƦEBk`$f/Oi-OE qw<(tbG{Q 3lܗF_`ѓ@J#x"wwL:)9vlrW?&u[[GDmئƇhf}s6Rk0 TeﱀAƣ7͗\g9"ӕAIH fn,jc4eA@=WZ`y'c/=&:onQ^ng<@@rM_7Ftb5^éh j?ⲀTF% (d.ldfyۥW7Х< sm1':)X\iV1OH33BnYFnON#ˮ5 #کL Wc 1i3wC~U/anJXC1Ns\YZcey2vO>8~`v{D, }^XL.q|o"wWBå;ykĎ.[B۵S+1sr,_}aYxϵ(wJJthbrdآ[5غqz`.Hr_ץ:cPsvѺ@bgpHg,rɏuv)^Nʏhpy ~SfvWV?WX;qlp&6Sk=aeDYu , E\8#E 繿!\,'6H4K  Mq ,ŵ}*tU,e](Mhl&}5%tjbkDt+9#W H%lIuUtSsbI:W^ʶSxP 9HTTeoҵBXЅ.%%̓A09 \֦J;|aϴRE|F6JD0U` p[_9US,~$>^jvӤR/6fWvJ[<?=Z6cI3&IUg>Љ⤩Vj/5r :+ũB_Oh1=]BUdڲ!&䒑(9(n6Hf6+!L[뙲rPAʐsd?(/r9% A]ѪZG$k"6@Jz1Kv*6*(B227ګwmu=E-^}I)?*ehZ$YAyPG"QeYI)m UT%k^"J?%"emwLKjk#QÏ%{G3e' a;dW5gf"ǦI&SpF?1?ɹ"pRHcS$Kmn{ F/qXzbC9#wTmT)o4fJ}e2(d=c8"pO-&օ^f",TWBM`@ y-A,鿕= mEv)FV ^8m qx%-;O#q-شKx6]9by&r6y2ןSљQDŽKDwx+Op9A#fX} {:X!^i1pͦvӝM<%/pwʍd3N)yL+Z_ ı`̙/)i -6X j:>'p>;u~U<+%inoQ1DF@O32w#u&2q6=tv7l P. 㓏nKc1g[6rA[yފ{eNNY"_]?.%c] bfBd"tB*!9HA}JJ̉582KۮpVaMcυ)NNRĦzi>XzQx&:v~oNzfS6^u?zۣ;C jqrVT3IRTBڄesDq++C^69I\ɩ uL@p=$(E.E[%aSD$WNGn~ T嬨VQ`;eg'21m> D?59@Ҩmem>5yԓ>?> *oK]T 3%V ¹Rg9䖼ߡvFߢ HS#ȥ*SGkEbql=E甕{ +$Fl qCM8@kUTNq3ױ._!Ƙe<о- ;~8ěrfSh% E x^aLpCuSyAHj?m֕gBe[\D@[O˖$jnC仈=4m-$ۗ@j&R*)_Wsq!Ck@i+R4ņ33ǃ4pqZA8gkXUnÎ͟#ŶV)Cʡ~ŕ]4q Af jlg%9:nZԱH*~ѱ&F+s`⾼Oxf' JeL k'Vf( ՛]a~Q}Gъw|E[;TMVHi`k1&ĉu|fr_n>:1]󵒒ڭ2/b]tf7{-a坁 !٥'+- cZ~_rI03+*"s"Y0vRjKf$tdOo;ȏDXgDAU&Xc߾2RL}??HWtqz Ɩ5e&Cqe0]4-Yѵ yG2 mo7,U7ྒ*2$B *$a.Jlzj+3jtuװBLj~E¾1R r.])SN9QԊ3ZzZZ^E$jQ[%)9ڰFm<e[hze"*Dm/ӤDSX5c+|9?ɷ.wj<aCRN:<{ƌcVE 9F!f N)ywUހ"]e(N|Nʾ-˓[ͻB, HWmn%*;TҷD̹ ,;Uq2g;Qܽ~XDYRnGA&K#O̘q7/)~&mY|2bDX=5Q v;Qх\Æ"r< K{>Ў6bԿnڕt*@TOfFPyH׸m9LRceHnz:k-\@uGJBWDxhXgӌ q̾? Ɩܷ$Rzi{]̐Xa>=?suďd?M|ʌQ QCA]4huFqL%}맯zFxt:]åi`SmO>U7c)]ZMvg[QGiw㑨gK -)Cb=ڈKu5ƒS:?Sς.ؠFF?+ UjE !#}Z=}[7(M7U=z5P>D"5#8{EZ/oOwAƅ\xbY£0JzmG`AHwL7BGVO‡u^+UOs0f( v;FE [5)94GD61l3( S4v:$9JtsMIyؠ8c ya419CDRS*y*omEMQXjuk˓cPO-4RCU9Jh |N:-M 9oʈ;YŸ@ Bc,L>b /xN[iuA^JcHrO`.Rj7)aé Y0Uj>30 b f[ ?[$^I~m_5l½okΟY;N{qPѫxO>f߻Vؕa}",YBFv9a&+! A$hH H'V׮DUYوLD7kC'1VQ^ % j pCN;"ߙ N\y{ ;2~Dp*(ոnΗC'g \S ?8`{K28Փ蘞]JusnŔ"f2w< 72k>۽ + Ak@<`OAId3m^YBu7푫ѳ}i[VdJ[wJu2pP?#}.$R)H 3}f17IvFWz]RWl'cyrеC=L;*]}C6±А|;|!J$a 0D|lŎOu:+N8Rvr:C _<'fJe1x^:ei"[7~|4 U4,4x5ө7˻2Gfd"J<68@^}߀ZAÆc\ьvH=yI0Ԑ4ܤܠMtlbϬR@6鲰eUpJ):y˙.1j)#^r2%͞LTlp^^-[?>iz'з@;_*soẇ2Bsf&nC` ulȀ=MD-!#NY8Rv @ZFI"uFUP%/g 0:{5lO J4IsA^й}bi%a9%B*f͈߸HN2bbtt,9M>'[}Z44ytT8zv]ei}oS^eaKtvM0َu  ~j? [3\%)A(z*=ܔ(e^]>NtAmgQӮq$ATКb7߬y1 `@"ULMja{8qn /Rg2M&1תY^ts xK4} I{1vC֪ufXN; #ÚVii>2P=F㦷X~,Q4XY61UsLdo@FHȄ.K]NG2u!^*7>)`?57A _DsD;h"mYm R欒D/ 2z?[ :WDGRS[H=-ٟW-qٮ=st)&LI9*?v e,.XsI)jQA.nkhڧPa]JfW.RVZOh܄[e-RKP">P#y22[וGNjWkBbS^ `Èao&N' akizνl5e “ ǣ_wEaXGA^Q} P^/1It\dqZZۋc~D\I`"E_s4He?*VA,>vDU((@ ;4$}_:Ak%n,W- 528R m{tNh{WPE ȅz͘k 7OBkRXN]knWa%ڱxʰ伿c mY3R3@^,uG,1PgR0n"֥U\MpA8m<~uُK9&3٧̥ %A7''T¨F6g* & Vj#" ؀L^$ӭ+a&.NoH ,N1Pq E0z"_;-&M켋H/HXmFШgF{feTMNsK)&`@&8o(Nh+:}w]PpGGۂb2g9`u $¿S6\/ˇ}9ʨ7r1?"rO҄IZZHHW}%1Ii D?)D5MmPaR [LkP޷57wRAD')sxָcOn6fo7byjAgi]WbkGQ2sNƦN *UR6}دb-K'G19yYOΗ92c{+E#'aC9GC9͉[!aYőZy[Eq0:u;m-cDgkRMXz ewq [LFa2ͳý,Dm8G Q ?Ɖ_m N܎>9QRRd̬ 7{L < .>xܲ B6szO:KGrs E#gw\Dji:pT:&kLn-q0.)U9 14.Nk}39w_"![}.f@QUx#ș?#{&Ke˟'5狸Ԣ@E ̪Q6|vK5[0nPe`uߥ8 EV%Gs-?t?1TU7jIoPC\f<) ۝]<֗XRjXO{[3KiWV{DE.Z´(M syg|wT< G@kFrdO%*¾;|X(P>caȟJhWV'ﵦ<#Ėj#?IٕJG9U{ϛTs#oE-`KPϛSjy^\o?OKD2aXA}K.~7:o;BGvT/ ʠv Ø̈́Fp8KUKBE$k%jPPYy ;2%e#(aezE&FrRW&#I,Oa \K^FcQ@E+nZO_t3&كA}VhtSDZ$ձ}UjRS8 RrCCV!"&pnQfcЍ̕OUVPs)Vg.Wdz?O\^)I;6XS-_[AݚEhEӖ DL%KrSaΆ)3vT`T4QUɺKJ z{ }yiD0,Aۆoϻi"}vQ#b q;Cf|Lj_h27Vr\SqA\tJ*^<}MO %a"CuC4/N_z^(&epKᒔ8*YSg{ c )7-a1/0e?$եF% 徆ٴ3b d/i^t! W '׉]U_f/caRP9*]/6 NE=F!pqV;^ɋ<<)M8uFZj1٧(溑KZAE_pl90rv*v``oK$Ih*F )nm2WA|;\ck,9+㞰1 + )Y(^N|FQd zCxI.S8m^pY3 VR&'1bmLp5ql7"U6(Iy zR&FO춯\i[TƉ~ <2pm)\/|eEiOQ5zaUvK3u.lѡWWX~\FȽj%,∖fuPd4AmDї"ٞOSc%J~rVo;sxQߦD5!fIӞbˍlWhΤ+y@]ЅrmnD\7zD pLkQe8 $3[͒4Ny򫑽ۅpw[&[DLiOjAE]} *0ҡxVycy:h"4i%#eӚ_%^H@kǤ?Y_BZ-`dƂʡ2],p;:dw@ٲBU|ZOYre8Hg"TQOI.9>w<G \m*+ٷ`<М̅[Zn#gY[9k;^`D"tTBѡ!"u5`Ӕs?tăA3 gá3^/^׼H[R e e(9C9#B\U5\.r$xH> jI^o\}R4`"6YJITh:w:'4)[ 3#0v pb6FLsv U2(Tq{$!y4cٌ |[te@Wړu?*Ywv A^@XgkZ$]52TmJ.\ki?#Wl n-JHQש^@/^_xlQz&CEmAFgߖD*~fyF3B~=i׏E9 4=ݒ mb"SxcMᰙa>]"y45s4K>u;\l:(xPvGUv0jk)>PT/Nc}4ȷn5RE= x[aTFEfYõߥd #y~iOJj #\Lm`>IscE^rŖTv5*ׯ>`NZkRn_>z@$80aꃎe1}{ak;}&%a`8U=@qK/OB_Ү KV_.V2}W7x*21̬$(˹ߠytG-CrdHh zs\젨2K ͗5$9=ѷ+!0 $Dv?{yvKw8_#cfw7v^BwtJxcCR& f1R!7i涙Ğ"]gLpRzy"zE%-ע!SoIns&#' *̀P1c+Cްa5XwI Kֵ.Zp0q~Hl[]O g\ 2}&^W`cGGmPznsǴJud~P SB0"'?7p#re!a^l D>ND>, )2 İ{@|hGjMoojBo!č&V-ÿ~=Vr|!ʥF/ _}McmYf0ZzJKh٦ђ(;2 a}hUelpԋ~CZ9y;|gUe z 0)>dKT`늽:s }@VG7pS ]3ۍ"dPSȝrwWŜ+rkx%EbwNB(ڎFʬjv3H@lOpϾ 6(RΗne{}xP[W IYY]Dl}|;\(z dv]Xrf aLUKc7$,]YgZ`d5zb(93ȓA1 >qׇu<3ڶP[{1&VuzNA7C)Lljl]P]X _<8J&'~awCKkMufTscrԕ߃OyyU$نB^8-48>LjHj<;Vdzw\҃brw}[ yaBFxelݥnƕ$O:āb3j ߙ4fB uV:bͽ :'h1N$7S"%> 3 d܊F}ki\dfqMnw;0̢lf.,yVMy4(8$Mn =[$tBIQW|yy JAiWyúдT!%59gIabSy2!qfe ߼+ЌskG _:lIP +*DcG|/p\(=@ͺtU h)  z3q9"Ҿ}mcQo&z!oJ5eUH.[ŵbk6 b3Ib< ?wo؃uA! ^@I"T;kAedSʲo"ٝJUD DOK+N ]RqwQ>Kb`S2'f --]hHD<@1>uqq) WY<;Rlh!Hgnlٳ#CnT .[qvavW_W^koN_8 B3kG|ҳ n+&دůٜR]  PȥD8m]oιǷ@&RL%2A9³Tvy;({F\Q8chd,V3 \zTWXĹVGO%jz  +eϜ/Wxg>PcaY (>Z!+{zX7fe$ϒclK@Ci|뭞"( 5?A`A.4[RSKi5>䮎[SyzwPZ>ـ>qw]XVDcq+I!C|wsYրe}!{J^S*HwOhI40f4Tp0(b55/!Y}.oCEYhڳn񏄻Z3b6v\ܬ}Xr5, Uǯ9DFy0=;&܄LJŃ( 9+*-&Ôg';@5R1vA47O&fڅE$N)aމ+ q'| 6^ɞ%YӘCE졚L0Ȍ`twOQdiܠ߫[/>6MtEɓ6YӚ0`YY(U%b2:Q:q?VѺfm;^7J ߱)A&[ Uȑ߈' N_Ôp),d2 n^%C-T 6A^ji־(sm\:#zT2g`T_wa>Vvo">P1?Z-N;}39L;r -}GRH xC#%KNB}y!;9ԚN.wg{ܪ2?Vj8*jW"erxe]dL isr>}[xjb*u> /qO(]<ׄiŜ]mpc2DWrۋ.)ڡ#ʈyxԃNOy"uV*`HJn}$Qv&(\ќ:^iiN&ߣS7` k)Fr48׺J)PsIDНM4!b>(L~|- [YFk I`KM?I UKr~[EL7dxtWT @'%hD'T{9vpuxR }:2Hȕa*0AVloQ}_+8H\uAg!``qxJf@! q+Ax(gր߻GqF,"y5?@cX3.<Ӡ`gZ N{CWd}tV=8Fed7zr>dDW{T ގwɉuֳ⨀QEg7_6%p܆*w^u/V-Y(I QvDXqssfpeҳHUUa#:6\e#4BBPdL{x^!!"FJNp;e}iirmF/w4:ojekv~HbSz\6oulf(u*h,'t\#a&txt'"_ig3""=!9rI{*n]k*IWPZd L(HR]W\?j麖.!WVli 糳 P1Zy t>oKɂߓ&Lfg}/QXU3@fJB[TX |^ypHn1': O1;aEM6/t r6 MR~dO52₼U23aMLZok5/%Q/ZHP("  g28S x׏2Um?yH2w/ql؎ 1F]smrta[ ufТ1gc<ݎ)({j0~Ӫ2sZwOP=hG]r)thI`[h,Wݛ &oj$kWFj;-^آfVϭ;qA'TmW%yL ;LZ_-A ,ǮPM4s]〠:8[{:dFּe+eӱ Gnkڬ}muP21-D*06xZڬYbwF~_&tlHׄpHvqFC# xrnU];S)*4i\MF1Q=7z}&jBB /ւY˵-yUp0VǨ pJܱ12 ۽]v eK`a)D,A^ ı3!vֵj͙2.{E9Xg`{)9zK#A#mW5뼌𽏁NMI_{_]VBG=Uv*!S,x Sqp xXH-fKʘMiMȢ7S*8]NDzE_(Ovl>$-2Y.r:҂;H|#㲙$>d[ZuKBe1$/ހ hݏvzOHpJH ̀cXPZi,eS2[.n|9y,}/m g$}=VqZVKl>|kR W|tS0b[UeÈgo9e_Y^4<98[DX-'"^o7P >NȲSi .*<@!rW̒dyOѐ˱,;!9AxۋgGش%Ow`lkƗ*v6䍒'{]u"Y\LZ čm \ĢRӯUZ 2q$ӼΞ0!8FY.i+Me3Wtުaf ~Csj#{8oEqI>5(O~B̼G!̧B<%e] M\UY,QTOsE< I&w $dn:b:-LgOTCJ&8'"SLt_2 S}ovwDžw(Us|[90< {>j7hF\WP[ѩ.AC$64s[*%NkUԖhJ'!驪0pU1]>8l)QMpRi|@r=-fh˦uZ,~M0P[;Upv|XF"F{!Nׇtdlu7US̰qMq^fpkȲSv2y⾦M|VEHmR.{&jI DzK׈i|$膹Β)[C9̂,Nm}=쾭9y'F.#OJD87 It&lUbc PN 0ц":Ჯ}^V*ow5qZa-#~"f 2\A\B6 ̍LobHt'=ňONQOQ7NED͒>l5 QR@s8h𱁱)h z$(lH|8mX2]';TQ޸TJfBszWDa& |CZFkqX/bv S!.o;yc~ %_ G= ϫ8O81ߑVHj\iV^I;gֹ+wXL!ʘ=hnGmL--i e4:/?)A#fZ=%1m`}0֘zAd ߖo*uu7}<A.i"kĈ!kW]jgN9qS}0N 2ץC2ewkkS#ѿs ҉kgФ0 z:zGLC@Q(NZZBwĀeFȆ/a1\j'2H_ܛ ?.'edҧo.C&w^yGE,'RTF*L\= A,Se8Iw6# o WLXrޝ(J[7:}Jɡ'lׂ<)˩՗&Bv K7KߠG.eRRQ2H- օI!PD" Ԯw<7-*WI ҍ1TA~2;Js2u@1ԛPՆ 7А_3HDr 9jjԙd|5O=ըڵg\03]QF%a{ɳ mo#\LBI81)g7y(N=܉X&J3OX'E_>NIɯN=JЁ4:צ͒8xָ `E!gEĸ] {UQ=Ps1d}-B5tyѬiePZ֒~˅tZR)c1abJ/1A`|D(/Yi-R#ekJ*< ]:gCg.>ˠ Ӣ)@5/~saD%tѫ6oRsDwc9JߪNp=ʣCf~;lo(13rq|HDn3%1JjA$'2-@ ' %J&2Ov31):_y~Cc+,M4Hh}6TiW$Oft+nNuá_g{Mn&N/@nN'nmCZx[q3=QB~_.مUŕaƃT,&7) r|KDD9#&)c_nDžJeWsyс[1TKטnbOfK9CTb>3.. PZ D6ɜhoeD̢hS/Jv4}.:XP>ldO> z wXxs$=(jb 9_۱d':_ٕh86%|]'']9%{ [y#qL7X#qE`P|B7v-ӛK^KZnf,{at^PU x8[7JQm/fE06gQi"N8q&wE&ᕵ J4&~qn2q#Puy}a u9۩!w=ybHSˉVU@ yj:#tE&q/ng[cdˈwPNuIu 6}v1+[w<*L6En^87J9/nݖ3wAx6ydh*=w =N=)r1yc?Yz loSZ@XtŔk35 ó[ ,<=r{lα_#<ZPؤUWqq܍bTX=Va[:#sz<~ҦC.C. 1_}4Rq0 xZg .\tm5޴#+%[X5Ea* Au">#~KvW-:"AH!Q Iښ!"x~JЩ@PQqS4UaoM1K藹SLwBJ0 J2=v>@ZdXO2zֺqMZ/kDƚtJ|N 7=?d* 2=\\F ,j b:Nocvx3v.6GRPQeĵ-p8[Qْ_CXB1V*\_ʈkd%8zwZY {3X0Ub;V:w] ˞Q JMhC*-v ,`BOc-#By~.TS-6C"2e wC06+%y7Jw&e+[yɗ \ ;)PtnG&0Gsw\#[( pXTՎx-,6\吂}#\xR!?iη}VS4L*Kx)r;U@qi96agcEt$M~nȷB$0{2:2jЋZܒ9K85VԿQR~ dUlI`v/ay@^ *gi M{/ڮֵ;0 Dvoxr&w_l!!I.9R,$ & !roq-Kdl;/$|^h"Veh;I=JGGe<}/Xg}+Z;DdJ. S_p1…W9%w!_?*dyVf}ʿȧ%Ʉ \?bЧ b&d =Z?n1 x;%Q&q_'Ge:{폪WHi{x$F8QJA?:e6 Bef9"V-8T\ 9w V @`,ZdP5[JYD<_e܎Ni۵674'vݹz;Ym<ҍUMl9\*a1Fks™ȹ5>+ &b^1bBb!H=Qt*d1_PzYϺ*c)ZΌVIaW׿;2ǭO-;̿Y@$=7bkcجi` =^g[U~\ң~-$"B6 L =*Tg#;* eú47xO,+ tFUfW9S'PUT}ϱt$$cr|VJ߷VY3eku1ni]ͮ+߼uHw֤10uny肭`Bev~Y#%߫8mV͙Jin] 33U,$w[h(h31xy3SXkw뗌05~5y#7]@Dq( WibEoFVe5E,no|L<4Jwz3?fx^מ~QDZ4,fh[qCwK}{Ozz3KHn de8-2ClT?vT ^=Ҵo_g4S ),Lbq 2&I& 98 00'0VW1g9{N(>v-R2LQxK@DMkS2 xb)Ng7,jxl@& qkf~սta%'6<];z4p;pŕ3:ttm/)@.ɼ6]kM7Sw`"ܞRUwW\Y7ib'.-B\u>;2 ]s4W(B_,WBud*])clrgp(YC,2KP\Պd>;2h;<8B*E*#sU:y-SޑO]yA??NsLٍmn@C29jȽmL{7a6ز}NL)ﱅz/WF`Na}"M-o4;F#ַiHW+驜MJ(]D@KqVaiz%-|7d@QWj:,/lrP]r߾Z-_0d&Բi=J?@&2,-x RNB(Hӭ?rwyL>9D`%/Ǹ5 U <(""G-y؃ iȚfvu%TjfeBڮJ5ѽHn_*Ue|u̴@aStg9HEq̓lgܣbN]oӀg:?鯽bDv,V^F!|]X6AG\(} CU!5)Ct0(v4m]<A/E!!1*^60 vJζn) #(=v 2 CѸm_=32οeU4\F4Ac2sxVe\Q A'h˅2*d'G#G-jeDC'{"lpӤQ7 -B G ^U\}brݣu_nMNJlE'iNzo1~`)uMrkY?],[N@ 8̣jsp x&@K(lkX%Ͽ?;/&6Ӫq}onEŽ ܌r~ T眫F{`Q8!c.-x('0ޱq"60`##k=c.R0\ OOB!Bui|FiN̞KJ[iPi{wob6Z[TL[vsջ "C q"F5{_j0"\1#ZsP&B L+NI2 Z FM}9a'4H*oh v)G@^#t8jjY_ z>[\tEg橈 E?n#A1[)$--8P݆k $T!v|Hd_[& 1SWܯ[!6|mG /5! N$#ʤ_^͂\A,HW>x|XQ5vApWoAH~YmBv<+[K_5qDkC֐'נoS-7Wob7a#j!,lk ,{6`YIdsN~C|b4|u)D#DǮ; `vKo&O`< ;tD)ģ$ VrkPCˁKjV nPź9>\4F|*ʜsՓDW7ָ΍TT׊Q77X7fj?) 7ɜ K@Nc3*PKerZFPfyb Sj"ls7#}{PCԕJn;F_^y* $vAgv3xPrDV!"Mjfuz;vG(auRpΥAl <+`TIcn/;-C pai0os0~臀֑xh48;h5`Gܵ7n#O5Ka} ]mHX`/䭲H1淕govܐmy V*0LCbglp~o RZ*vowaR?#/X&Aܑ_.iޣ) fx8ѣW*QI|;!=_C ,ļ&4ڈ1:'\d+;3nN4& 5!za_f01MEu lO_ۂRkd+Je=yd+ǬGIqS2X8Wo4y?q%uweƘS 2wPH ]Z ;]- Ξ ;k,Vr/ɌFf' fG ؆G"Swy}쾳Y]N=ĩlew|'xz'}.1N"ТH' |ㆮ% ʑgm]=D ) U(Ms f'b +.!SMf_3D!"*/uxW heg3VԜ 7zz*y*9zH1Zk G= j޲hxCx$d3T@TdWwg RrQ)G\0K&9mO(le?,LaZ/ZRZ@3RzW P1Q͗4[LbuC:q9O(0_mY0Edť|kvt5щfiئ=\q>CD9l!E_^#+L2^N6Ɖө4µc3W$bÑI4=F~^>!$ uR,$]s2l2[ vV+qsHtwT¬ $|>]PIQJ*dzlX7 $:їm:~vCm@/AcaBTsnW1B@y߶HGK&e-C1bt拚iݯ'Jq[T?[[QnֻY[fWAsg(VѻC6xbh?/ϼQ sDÊ6d1hl^%q³T  r`&q$acل6+!,= hNݢkF~~+/`( )ram:Ps%F6gOOl&G=8/(!R,5L؜+:9QP*XS|AepTI?a2?z,pHYH䔗t.v Nylw" M2i;$BiBW߂Mt%nVJ9^߸H$*> Sv1?l`|U=l"uUя߸P݇j,Ĺd^û4Ʀ,ZoP+QzUAϳs+dyX-d~5Q/oޣ 1n^L-1osYuq0ZNAKJ,ZMꉳ&x @+9q7?cߏuc1)3l}0n8vPAF` >Sq5Vnmcr\0ө#e )ŕV~m-n82i9_wj"I-SOT;-0_C;B3D{`Ĭ̊F 2i>BU4>lj8p}CQ-錚m+mr \r_ƳX^gj='dGǞωeC(*7_X(0_7'ܑO~H_S^Hux!=B!LL6?]6rBcq Fm$D0"O{:4Z`TrdsDLm:?B+;S6u4=< FmE'g'tJlk&Uo8[rf89>Av N~}05څۧ$)U>Ix9?+~> Kv'j$2>@)xvY@e{L(&, &MQio.12o6;?܅h.A7[2?PQ 05A08q< 6[uMf J@ڋr܅@(B|퉹mJ0G2ls_[ Y@Jܤh(&UL*mC8 rV`Pr\^6ǔm}dܬMe v}3V!Psa4`j/p+;}h.SbxA4է1-L t2MMeU\mBּO'I39>k }: ,-5G7~Ғpf7]OB8AFL#汴 Phk%zHؒC ƒdf]XG)@_7Mm/=*׼,Zv:IqKp fLFw>T7mﲕO5ka"Ҏ̦8{Î-7Sf/%R`㏕ o$˶Yu9T0"7? ~NA7fT[f¸?[P-pkfvz:ZuLA&D Wl_4Mzۓ>M=z3(a92M]Su5%C˱W yKqnUDش჌ڣSZϧLwj}bY]B|pjdMm]k) C}Ӱ=60[+G&/{^9qqBT]nGMgr|#FfeU]A+DE'q xCu>,[{mS8:IyMjf9\R=ơKVQPƣ=;zc+*|*=DDst'=ؾBVtվhiOO[{ⵏć .̺0ěЌb;;t/),6okn, *]^?Iكxe[.Xuw4^/H;RJ&QEko|_L4(NYh5qs7^wslߗoԒj'5i.Bͼvוrb}s޺GrC}R-I47+A x*=H Vu9б%#"+iㄻɯ"i%(zc(|!G5&} #`aZ)k_SBbCHw?bv7ْlŵciztt.'&)v o8|"Y7.@) 7Zfyp|6]\6 -3{/^?[{ka^B+^0,B'vᡧYI[򧔁 Ni NvrڋaI+KFB(@Ȫi[9"`al1yks6DI2JwYԷ☱0yW[қK\leyV4{eβ&{[TUV)-tBT;dz=F3>i udSmNU`يp'J 9RU'/.O0?!|t\.>܂Cڦ]YSsHo{`va)ƍ93N1ϞLAaP;8u)nn"fW)!KzK)m="r]#F!gQt . ZyJ xX ˏ-l9bq/jzG//`d@a(_:|c\e[pS 6'%`hRJI͖\g3J (VDy'2)9Xc'IsM\4M}1"5ϣMYwZa%x5^A/9}K(PRGI/E$6H&T|ywK`L~ B8khx-@rMR )lyZ{м(+q/$ƕ/0yN.3 D1u?8+01=0Q/߾D39TS@'08B䲦=JDy5m%g|6G?_LY7ZZ]V!9 ԙV7+!P>-S``59w,xr!.9YId]ꍃX nkr>3f(U-r~&Y~mՕ"'GI48DP tnƵukhPe+YxnH7Ĥv:&TY{ L?:_ѐ=U)(hɖJr-z8t0a>\AW\gXF+IT_CߖYU)eV57%`K󋤕mtwBf,8 ZCw ?-lOFgD4!uӔZʪBWj-݂ n肺&fB1e_!=Ws̩As5I_?%VT`{n5ڳ'숮>cb:O3jx=vxXAAhY?zuvEVTńQ$:xeL% /zMeY+;y>y;0U|꼭YsteE2T9I)ڽ 7_۴1 ,jNԛ`.ahA7Ml*Yו&"( = (v`Șկ2S\fЩkb+7nv3G'hc=fj:2g93Mp"jIj!a Pb.uмy!Ľٗ,(_$Rc1t͒骺۴XT/\2%K#ϊӲq\ӥ1F@I EB)yn5T4 p|E۲c)X{xivw,Nz#A\dkkvPƜ?Rfpj{%*@bVCt9(%vfy9z$v!*J!OЅxtaRC vNȑV@0 !j5lX1Cg#~ghMEFwׅ5Z}0˗OŠ/$u4Zyg@ 8l wդd-GP'HqXo8:tc켪fx3~:[doFCWr`nKLhi*f傮} nxUFNf1!>P+ "s3;lJU]=Jp`szY3S㓦%e`H7dFO"U9M25&t3jDw114ڗ;[:! i闭 !Rs&/By4e~˄{<#P4 J0TP!b_lR5uW,6w!flJp^UXpKj!*5Lt_13@3LRues2#ܞK;SQڋ rh44QN}҅.ɫ>;cZw5qg!RtO,׹vv;}[?'S6PnSa'xm(VL:[ 3xYrE|eI٣x @#X^AN .1Sk&ɕɠa!tؘ tӅ5*Գy+'&~L"d:-ր֩}~ֻ^w!į}N.C vOI3\h@. :s^:-+,Mkn7({ǨOWc+oT6>*2%'Qdʵ$䛧 f;]0vozed2:̏SJ饾r@&Oy<ꜙN,EoCpl A"H~~R Z;WU]V lhfJA'Hѷ;(~vfN#a?v3 /+̍U+a &M8Y7۟3Vr8V8/X@ʵJYfp=Hn~xK"fI2 z1~^]+> `8E 3Ee'P7X)Ow ,8~`ci.w2UYUX*^eБZiD[eXL۔2=@b$"L݂H/ @!oLfǖ#|ti?H5`5K8p)(ӥ)Bkr/GD1T@Ń'S Lw'9.2"9:IJiv?Yⶉwq,x &尃8"l/׋)rbltWL{ ;c)C'R0?7\]K,iovnp'=5GRp D "Kх^ owM,WHx9ujo>d.nZ`MQN_RG,,znT@ X>N QeVfJzSbڔ@w%M#ߜt$ CiuH@la%_Ma(vPW; 9zG[Fq9,W?`CLmᣫv:$~]/~at >[gn`M-]_p?մ+TUfvrZh3:e͍p0pfypHHJ3oq,AwE-lU?GgU]uӀ#i`<e,#[#jL0:7ҁURX"!DX>̐h喢~ ,Dr?q􆥓mPynN{ܛob;ؓҜ^OvɻHr+Cn7ggr_$" -r: RnJG=$E;(j~HSMUN 0gq[yG \}z=Bn2U1k8d94&jN-2Y茙O^q'lY=f Q,>ͷ:b@=Yʎ/=xۏ8Vy53=;F"ԩVp$vt=p 4]~M&$G e*G]ե/oHvFum7.ַO7eђӧ,J eU/<+ENQwxlƺ~֮>$ԮU\&k* jYƖ/E/o޿K`qa*a( .zfƲ.?A !AMBu/#Bmw>X{OMDfE(꟱wjD' Oi2q /yw<r@c x \*vpz-QiiX74̲D&z|G1gMtgۜ8(uph>BQصlGL7t:Mp$tW&⟳ #xw^xMqw`ԋf$]A~Ÿ4J6=5`,FD迏^`Sn.IoWNP[C͂!V|\- 7FJ*2%5Ry?U9gzyMDŽf+V_u's~%Џ%iXzc %X RGL{% 7`&$$ @Yzcӣ)IJS)~F)h}Sfk34.]|jBdl7(J% |ۏwxj3b$įܣB@,Y^A^[ 5;'MӾS2j9VdNGýtqE<ŬƆ{_DRٙok@}`>qUƁ˥.Y9!M+ Ml ~ECSzt˛Q) CR"݃`'=uXЌ RL8Gbr͇bRn_gxail66J8g,o?f ѕYIn69߈{G}hCVb*P{ZNO i%R@X_Rܻɍ*пJ9uӫZN9;yOh{NZƻD}1 `E̗{cHv20iu8F{֓%]y[/1tY~] zKBN8y QPըr@H䮂Ҧr`uD0[N.ۑNR#PpSklK2FUU`T^g\*5cɊjuwxgBbZ-hDb昦 "Y=RxBαGN U2I2Q4 eൣǧsUxRּ0>CpZNn;&4VVDϠb?ĵ\8/l?{/f-[,AR!d']KI B nÈeoŚ6@f=Pv:90}\3KV036HJcDxS.a+ː9SMyMt MgATҘgFU;W3w^ @'ST)iJ=ODk1Iޒ DzRS!rœMdۉ+^]XG<3;S%"e^U'+0 wK0VG?B3V\ӽ "zʦhIYc&Zc\!|%b,&ykPukSN N蠮mTgaF^=R ipǤlrp+<_ 7}P py@Fa3{=SGg?Z ,j,^4@Vw ߷4]0S"dq1*!eA}24FiC@_}: ,Ƥr᫧S등`d=ȜV-ԜXR!FU=V b29@^@ʫ|86K :3ބoϸoeɣa;W?12sTj\MihxQU06 *ҷ?,' i{uQeC*MVh\dN3?L Ή*17 5"R~`%Rua^UPV?dUp Xth. Nly%k|6L< F6{ν=Olo$kP~C䨔kpwɐn;1 vІ1Vҽ*JpaF KwV3E?*tI|y-P)'E2nc[(v>#j=̿lUO5d"i-*@ yV^t6)>64(V̺Ri^/.va,.T7rWT*3pڸ=]"v~p"y@Qe'@"g}`S$́ <ǏSɰ#`|WNcl|4#UGֱYʿ {vO}yӹYgF$kQ4jDzoy]#ols \89kS|,Dn49XUy7KTMaO_H;A)͊s ֪1SDdӔ]oQLj77B 1Zc # ڙQS>H8۟G t'1FA:k[2ݗCm)] uxBx/Ia#Kҹ Q #F#'%* @fO/3h[`8K΂X"HK3$ "o6wqG^"|44?5zU A5"]2pD[/hfd̦x zprw{a^1s$ЩzZ&HY[oGuf/p)Rֽ &[M/?x[xpY:n9!,\] g! F 2q M [ȁEO`n՛Ka|C0.t<f| V <,R%1Jܗ7 edO!}]_M{γ'Zxzhш+,&8^8Nly76 گ?bhu0O:eCc) $ӃJ!j];. oco SU2Ͷ"TE2TALխm# NI]n0,33p;Ŷr+@!؏ǯEڃ$kHұja3L]Usj6_J]k6k" I) GIW5tI{iB[pa57$U7|Ob|Ki&8f9,+?~nTץu^tOB{\}`Y jJ'buHc 1 [b 6>^Ϝa;m"=Crtz,+i/l_rL5/X؜=wW^@b90nrK#ws mJ-h|u\0|4mn@B O'HR._HTkm:}J8m-0?\P2qH$yLdaRAAK9ZZ X&OF1ɺǧLصXXMKڂ߄BgZfY&L@ $1*e|A}25vH#h屬E%x-eb~_?F;w\f1gYhjWWDzmqX(J1AcEHij5})MOna$PS;%- /k`wdRNvD{Ӧ;֨gddnȲO-ߩ23H,ʇXV]7ÒnSeO_eaiyVF5i#πI=&H΀~gD9dʟ]AѯDZ^YvKw/j&~; ~s"7ۦpycEIrEOqBu?(+H)A *5ה7e]H9,^е+1G5vqjDtsj@C_SK@kU3EDm1"k6QTB?U!%D˅_H~WEƤ'd]&m, CwUi?\ #e۸;km0+kn%m٢88B'mvy1 ա㵅:d SSh*5'GY[њݲT,m ȸ{b 3&q[ !Q2=3UR-]:T2$%z^w=S]u+gaA`i-F!{ulKH%s>|CT) OeCU/URD]F Ǧhr W „`(:&B Vo0zż!׹̿CbA(V*t:QH\$D#OYjK%t8>VqiڻWR,Z~|Vu_F]kRNAJȐ;JJ%MvcHF2BynbE|D.g"^UaY>ҧOhʂf֣pr\=XT#4=arEj#lrӌlN {l4˱1{r"=Ɩel//(M*;Ȉí*| ',r(xO ~eP'CkJ+{ZBͥI;^mYԫB+^;j2)]Qc[o)X*3a0جV f9*rZZ)矲f6''-,c(n Yp*[n?pyd0DWR{}i x 1vx3VBVڲ8~B*яaOud/ =v\e y1xW1^M'c_,FSg6ޠG!8}S~b'X[ad I_xd+QvDx) .8*?MtiKu!DUWoƇC!XH/Br bÉeٽEH$4"fܶmR82,QMJqIރWCWE]-n eoq>ǂBl=X@tz0>ϗB_#08h:\!4RaCȍ[9RalC! '){,+Δ5Б҆ uM~X&H c:FUYvT$Y7_jie:Ib|nR6eQTrXU3z1:NMOnyvYNaծc%=!Gz f muZ8!~R<—~^h\IF$Q R|~id(.0ƀHSeoU@&Ǥ,r&K@8>  ` Qǚ[/:lH"jx`d/58GeLVr'CWS+kIƌ`<ڐL@MøKX T}Pr k.d&ec qK\S g\guijh1YVU Jnl]ւG9M4&̻Vmv<`"aq&[*~1S&^^: Xpd$yux&AD,/Cjϭ<tWКn6d휖z5mWSxZ=' 8\2E&w ,KK9HsK;:nx(א25 H2`#a*l|ORN>bn`N я3=!1eUrƕ'E+9ixݸ$n2M@y2ihp6ҖM%G{&̑W qdζ `4/HA[[\1wg^F@\+(Vv9dyse -VܯQ"V/B]QzKT:vA?4NLa :s4}FRBtBWG {˃AMз=ӂ1C0ዥvϤ|R RTQoԨ=tqO?h613@F`.Q};0, _%I拚Ol?RmPWa0=STh\8iӡCTE#D_U^ C^b8^VMBf%pnC-F%Zk9UXX_\ pl=3ޏ>4$Ы@aQְ{h}D8Z)ٚqBTwS"#kjArRk_6{yZXA$hM˽\[(7034b[ޙHuzC%? u&5C3mD`].Ʈkσ#|Y1 |[u.h(==DP"cqgX[U5(ܞJk|@b)SnyD5Tx !|x',78`aFr?],mVut* aYZAO6hŒ"Dsak&U6馩t필j#<%V/ޭHiAḟ1cB~_Jo }rAysD\S7}'d2 äSz9@g#(lz42Y9icyf!B{J =]OgT֝Yfdjd!nr?@vkprdѶATdQtfu_FlWGg9%+ZI@ozYEHLViș~ Q@ /Kv,fQ>. GA? [am!fv+ZBT=0/B&*+ 6.7"H:iSd\4զ%0(>&sYuj]f[z) ="Q螅, ѵ?Vy JcfmၺṆ?8>'u D麺IHgk6T/ p*d+t&##8,sG 2~BN`mD}q:V[7ⷩpD YVh#0WmbIPґ^{\-[J4PpR"?YFLڞ~D׺%W×CYL_c,u8p}aB45Ќ0EEA鎆c#$8 )P } c-jeFE՛X0z,3ce}+.={H׍@~4fY·33G=688$kSԏ? 3dE?0vZlfwNf"4nAƠE9K@EgJ 'ۢ] UI̓]Pr qR؛&O3M+pD.=3Gێt~/_'cc8_'-9VG`#CUau2̽n)Iz::&>{bj8;]p0l,&63dVCޯNA˷9ҠhWC t-cwfn1}hा KtL/ڼٹ~}j=hx>*n9kD:1sh#Zt⛇(o{Q2ƒj"W03lyu&\ ļtteyOthn(͙̪bw4uZn0GF8NgE2.봄J "OR >Sᘳ[SkktS_ԣW9XT1g۝AQ:B_nҠ64mtcd.[uDLpuK%4-؛-E \A]QI[fDټmǃ}e*)맯/M AXۃu/R's.[~8,!W#C -}nm.r;JbT}tav]#ʢ͒ ^+EWP>qߕL8_U+Ǻn bz`Ÿ)'sj=B;TF6FHhξ([9&1zSܖL FWdBKg6 "4^!ͺmȔ#fHeFi:q)]͊11ڈN]Ē+o`NOg|LbsO*Ј/FZp! 'ܲy D?{Dp\*@ |L+eS_V@crE%X޹ )?\u?r*eV-@\ey$oc1'3u+:nJϝ;2VsXŢw ,C}|ϮrhjʬB !?#sqX]Лh83bRǯlm` QBsU'}6(;v"f 嫸Jm3JJM.b9N2,U[e>Ki6!_3Qթ}<ۓdwdz?jԤa;wρqh|r"@/mG;!e`.`oU!V3L]hTbNtCe}xZ [O7)D+(fpc- iGo᥆7J LG<[߻ӲYY{p2'-bë'~OOpX5PdW&r#aef~SZ$gcU|ѫn*=q3R&qLS͕ިE , :)%W?8oZb(a*F~;|l m}gIb&Nz zF9!L.Z6(MB[kNxĕT(qhxW}٫3hF^ʾEzKԠo6.d{(Fˮ pcґ 50"Yv̀>\!pW8&gYp:;P Q%h F_{x8ϕ.2W?b 5Lqued Tw˭c9F1;1ųց! LP4 6wM@#K,,bccy=Pث$k?4~ÔzYPztSN=2E;yvR54ZJo1L|?n04AM`mehc("")xڊKCD?HA]pU vm ^.iq#3{mcx >j)+iA@!.Կܘ'$ W3ùe$bgϊd)`;DKh6=#kX,f3Y`rO:A1@Y·rL+b ѽ+2Ψ:C#VYz`Gx+^m[fxCA~%m:~x p&ôTHxDv&'1x1"bs_` =]] ʵSY*0¿Y^Jk0&zBǖ3oH@_ EhKF0;ф:̝ s3Qӧ`NDoJMsk5ü6XԄ9URwVv`KI&8Bȅ1\٢k:*jT4zN M]&k8 ph!}qGr"[TxmokTX˂mHі MDﳡYP) n m [c a%j ~䠉BO:Ēv16'bFlڳRD5=d4#[#=v䀘4#"+.t4<Z2J[rIYUWr q@kfɌrc`I˔1(z;ZW x*)s3Fϼ%6c"\v6WCrpX o},:I.nm7&[\K{!:lAPt@.$F7"UK6Ƀ\Z2A_J!ܮvA7*;Zo0NDDh20KݡŖVe-Ѵy 1G7H~,}q#L? pu:QUl!(F/$S?4e%ZrWe`ᣑQŔ—qwς6jclxQr2sZpR"Ǹ.]\b(~CR\y3/1vӲ1Og@q0wts8ZH+ =C%X,sϿζQGjG9#Gݎu`vY pSSH6$ 1#a$Bżo 6j >֟Ȯb[GF˵8`EIau#0F 2L*7Ƹn!Y- 5͔)^0L`QJ a@"C!nH?bS~5gf٘ƨJ{$ac7Ao\`Q2T bI$H҅VWή-)(&,*c.PFe," ϶7Sp=^G@_١̶h_€QAFּU>m~+% P60rT<]ȕGst$48%~O4̍=Ъ".@&|^L%VnT%ݭ?--vb ["5|lj2' 9L q#ڀRVmFuwFǷ5ua8-i3]B7W oU׸Qg@cfWuѷ#D*jqrرLi-Xm0G?CeHe^n؅ARGcy L**G*:Pm 7dž)4qnn&|q DAat@0SH-o[UFpYJz4H|U8F2;]nCէ?;E$Nۜ.4`[?j+<4ؘLk9f m_Me#,bA(=yW;".JQF4O$:sQmm@_`B"+֫SBrdhj!(&z69_*: Y]]#N*w[s-K;7?J{?(3|_Xh󎔤S> !CTlW$otr[k'<2kߠ!ޟHك7BO:I_pŠoxQp1Jrd=7,ID$Z`ihݏ"sʫ>2y:?D:]䶼A/G&H/qzW 2^p7I5e^oEhpsc4[RPM(rRTbCW2J[pqh ch%LP~);͙ttY"~i'QcEuq7Hp/1M3s4h62ˏT`b,lVSVP%S28Wh$:mf) bT4WrW+~(|@LR+ihN',eVdM+2Kse44:ݘ\ݖq{+Ҙ. VohId<$-y5 GO|< $y6w:9 Mlb6HrSծЫ:Gx "UP9rQUX\;dg%ѶJrq~rfUqFMKx }fvYUjYOFIV@a5#ij؅LɝA̷eUF x&DsOQ1/L Ρj 5E $莴?LDNŇtxD*R60>MŠx`,G&X+h9L>EcJ|_p]m@O`cHR,2SN`D1Oj@D-c^cvJ6}lVrqKEhC,`/ 3c{bߤEYSV*hxhJF4+Bڧ)$8Xy} 6x3Th4\㰓vW ߄iƯoQupQ!:!X6CH}|U +cJS:C+w}:<$鋯>Z ANw&wV#) E5fv})38D/(@G JUOL>o<2SX,+fHȺ3~>\ۧ,Zhy::hYi[c+õgY ( x1}80*DVűl= >""i{%k#hxl/PVQΛa8hȍ QFɴxeW0VhF"4xMJP'j VFdne55v3C#R #=ΚF%@g:"/F$ߋ؂_6d}nn Ms<^8%5p*Aŗ/,~insr e &cn0r6眆܅vRIa%w&> JRBVX/nFpr"t/k?O/` U6ף.io(gGzO;gFL[0Lu0z4ü!jER Y Rpvv>NWB؊a^E_X֓C ŝDaSDSa+R,0U0w) "|N^x6q'B;.%BY0v'`F9D0Q_G2=d\Xcy: ]PQ \T@2 60+ f l0 3MU禥SO bgVO/ ҎiWTe2 )zs=POٔr)]b)HofOvM]1ETQE\J p>;c*ظ5+5$۹mx^=tˏ ZvՂ;{w$ʶڂ=Z{DG([þ)A~3wbbYoyg%rŵP) Dԫ?Ta0H*SEH笵J-k@$L2A#`XhPG`AzY7sYWxYs׵t݁SQ@ޞaZ`8M.m̽C` 5|GzU|7im4M'U )R6" ^/ԯ;qԒ_ׅ{,/AۮJ,X45;3u9QyVDjE4q4-Ԅ6jwru!BIJ$֫w7{@4zhTA$m6#!ܸ)Oh)#JJggbf2Q*P6>HZa`AF26+{N aߺS23|ˬ*dE|^ڛy'8E3siJ>Ic3-Gܠj]rJ8vO;*?%IlaZ! V!h GMdOfݖ)4z<% Ԩq4zJef1ߊy έ /Zԧ'$ ə)2~~+ngߝ#|B9l謮-EK?5̨ \[e]ogz[P4@#qâ43C{m*R{ʲ:?6?ۻ^J rKax~Fqs +xw[a $Wg1&cDbz3bKWو,i"cJn>vHÁsymrFRcԻ%Gg]Np悸 M9>ɬ_Ξ[;Jvy0 (ju(o(:0ly8[ZPPQA^ȢM䊖 Cp v֙^FBlEXXSJO\NƧ;,\SO&iО2ǬߺmJF(|/IJ]4 {$,tyI"pO32@"i?,̧f f,u ^7N^!s Gb0;GWyK]442^L`W#pb&Ƒ ygȳMae3 1སԽF\*1esh6U)}N M$4;ܮiL&l:F#4 ?}"ߜN=mzsII],^ WtхOr"p^|o˝9W}S"Ǧ|Ϙ6v '6~H% fqrjɥ).O۪6I}UHP-rMmAwF\Y>( 3^OP^6N[9\'ѶxUV.t)Z)RΩn.bp=bGwf1뉽M\4<39B~<(SV)@>DMj),h<-ID(qoC[Cci2054\4o^AU|FP==pS8v/9=?{Yn}[zx*PU C*95$Qh1 =z+HuIJH4ٽ/h33..wnhF`RNdb:UxFV'`+TOGuRd.qjiw ,˻܄8 k|qDl^@5DO_oA*3D~4Vѣ6 ʫMb3)\Ɏ V_ ؁j\ǘUfRՁ.׊N{xMh&r ʍq՘V 21ccS{lW@_X여Y_)c|ZJB'A\|vEw=Ģ#*>^Z@*C܆8:C >/T>vO ߡ[{{)|Zps qݎg4H`* `4oMXQd+P]BjRzTwJv&0̮0E$\0T4ͯ΢xV*bV5U0S7!Ono`~02w!jC!RNվqB\8u"w牾Y}*qF((Hu21*s&)a>L./k@NGXXvfx΄J 55Vbn]U+[C/c[l㩘/ =h3A ApUma>PkPK]_ԡx`(?^c5k?!ܡ$Fv}w~޽6_VW zhوu>ӑ!a+8nF\Rrh>0FjtY*#'HOnuX473 >liʶ/3PD/ 0+2P;YAs |+loj4;촴RG<0_B8"sֳ42?k͘5%T^w|ʅdA2YЅ.O)3Rc- ʡtrh7rH1*= =7!-NNһR<za g:]e#?ȱ<d_JJ?W S#5: D{dڐ (%1z7"CnCjֈُow8"#qlb?@qtC׊xr3jrEzlԣ*_s0('p/(( qW%\~WDdCY wɿ6zakIiu͎gX}wN 16 )SrxٍH;cOFW@Dފ憎@q֯/ЉUD s_tMd[ \͇Y5-Hep+!3e#@xu uw]/.Jz-S8C\OVPa;F槺!6׌ ν19J5ԅFmcF|#UmnXn|$ymJ6zbH䟥Ê"5 "D~V'E=ъѥzN~r\U6STSg-06񧙘|\RYʲBԈǣz uaaÔlJ=\*<<].咀mI 恟Z"VGVu^;VTfx+ _Şi {#(1ҐH& BR#˜dssǹe} r#̗&X_ȕ`*tc k~%KƵ_V軴ycFPT*A⻸cI^"mΔO:jLf23 [*86Ղi%HplJW)SwY/Ƥ[]{YI'_8[d҅r/Yjc{eX_EfaEeu%i#siN=k`,1~د$h{Sd!@yIaMjڂ]mž5ʐRy`7^0U:4(q#twl&*8wӞv:|y45Z̉e_"D*5*FRVk˲tǽ<斂 YpMHfO>F TvA}|˚=1|12W+fIW'X=%J3.$ο@sRMxmOSx;n+_ә{6/֞bu>`2KbP9jU Ƞg<$dh݅ERHChi;T<(p9Npx:$|;Jۖ*&֨VÌO%#^ldc/sO-̉њ Gzj=IG'[-h6O"5B𷕄tVtN1"V73mб{)=SH&҃]B~:o뇒](_Ŕ}TVM5A3Ϲ8Q ٗyMhqlџ%08蕘xZ޻ vL @Z1_haOzcf;ً dĝBOb@ڃM1ak+)?l g3٦xψ12[T"mj%?d51XԌFzǷ\v9t0s<_C:;a k_fմ8k)=#E mkMET~*=ܤ8i3ޠR]D#x?h@Pa5pkbyoƓS6qf¨5ԶUs4o+3rjeo#e}4`6"Fc L!z\^|카 ܤi{_pĔBJ `*:Al*AFQv\Û ի$ *ԝRSE/>ϩE{Y"rrQRAƙo͆ݤeИZ$8O`9 W{|'i4.0CM/nǫ MG&JS7uӌ蛪DpƜ'biqsmu:5DB!& UuO*fNu AsZ);,~{7Hb;wS$>m ki1nI"P͔F3)!}/!ğ&e5lbzLd`P sptSM}2 x۰. oqB./ڄicXwj;)O4CZ7*Lp:`au<̗F_ȭF;W/[!]ϖMa8fS# o'e)tn1.ΒZ3#y7Xk E $3ngJyѼ6D~eptչ!dC^>HM s+ƒ7uEM,0M >r`R;"^ݧHsGyRA~*!4>^u&(?$c n[&t)P[%q9_V{̮HSm{#nم)oaظOӅlMYj +kua5uٻ"B!;ʠs:ld-mpKV슲Z8ՋP}<p8m)C&72.5gcHMb]wzZVItx9y@':ֆݶZ|#;;-N/@0kj>a 􏑛WKbԼ1?'D=7{`(\ߢl8:Lt{H6 T#+ AW͛[ !d$fK3E]5kNF_H~j<ݬ{G +:,e?m7fZ"gD1,zs!W4sSa[ hZvMdb"*[*1p5,5af0KA5ZW  Vo7 03e~cЪ|{Z5xN _$ыq P{|(#t׼rGgIg^-%o,0e,j?F~\\Z zBU>|2XX|D-aJyw>]o-j2 1DQAHYz@TUBVv$܏򹤑w iՠŻT)#wPkc.QQD*u!ZVMC1bi+Ő:CS fGeKke)JT6zhEc9L?a O!#1:#o X!Awvwjq4; Tri&{m r_ZE{ۜrTg60Esޘy4yX]^VPXrF` $j}H2'=I,dcꦴVȎzݧIˬNօԷiJj㮾I hF>x˺OeaosN%=.OOG/`J&㣔hf9rEIN&8XrDj2bQs^/خwmt嗵V*Lcn?b}:#$(fKN٦@ @ I6 _JQ:=L]2dW՞@pXN[t'״DlNg<~2`oZ *kj1>X ;4qOwe}xoعE§;%(pjyE/rE]} TYBSlj[}.~TeITƛ?a(č]ǰa%&d]/H67 PM d@nܥ;w ePS^¯|U Eva*AkHpt6$NvJґIm/||.wM؂:Cn-/ux'>)9$,C2:h/V(!5X⇪݂ki"]S9CIHɈ&PTD 1%y?loӐZ~.\~D+ddC&Deh%MϊlHTj[>lt5FZ{G*("eñr7x7$.E ѿ N O+#C<im S inߓN/$5hy*DY6)\]81?ZH k Y2qȴ$mq&0 kkߡ*he${kɫ/́"پpc 0M Xk *Um?@R%@%> =8m}!bٸk-P,!}aa;T r|֤+A̤?[ko<G{+uIї|5YpR .zYހaRWBzbc ܉-sIܢGW,sH]Q̼ 87P}m&_;lwlur8ŇG*8z\?)butg2QSc&7cT4=3""=N-Iuลg̽kh5aHt& p@նsmU> ֿ5M, NIxr/C.9hsC< y<.(h6CD"M8Ace\t6SѹOSV))'đXM/:gw cQh;ΦdIz)ckߡ:/P)/wV 9I4a_2d1uHTAHd~A܆F>> R;EIVz͈-1dYd!훴aE` %rM,fLӡfsRmbr9_~}[b,n7|}51߄ ՓlGKXb|tA.t%TvqdƨVvsH> ? d.lO4܅xbT۠z`H Ҝm!v5 *$+0진h{E[/Z̉'}{WlVn7~DY:R@YXVs>d!-9@xx 4-M:tF `q.G)甥38k!yBF>eܸMCSgA'A0v5dtnr!2f,C*'$둡ܠ5W^_83}U۟dž\Ffjvgoqs=֠vACbL.oَG ;+6ubSkrf6cA8c{cd[SYF]&o&5z),q[`f!r^戎Z<һ;iA j-Ky5<ԕȻ=t=$\v27\y~a> [r5 =\ FZ.!)-n6Ɯ}_Q ?tp[QI\uЩl/?{+_Kp` 8;z) ,2U'dHYӯ=a/mpq 1<t#@>rfÐtPٗ$|ĀMl1QÊ *G~E}'wmW6m¿UmoP1hf1@ۦ4R(SCP9f\z)`D*`bQU7ktN(2E0DtgUM,_cM3:4OY "p$dMڀ䅡N %z{ R.T>PptYAl-bQSMuIxe36|/l۩Ⱦ\'Λ?J9ϥIsOw"}/hMc>!}Rhlk WQCO^W*7"#)c6CdՋ$mWSlrOᐙis8v>MɕCL*/N[KW(^Lo~C wڂ;~ ul2 OQpJ8P6E@Џtwpj:"T;qh +-aRR1 G_C3(SwS&*57߰lͪ\TQ@zi6q#0z\`?[r9T>T%ф}tRX pQ--<}*c 4ăZ:xWi~qu6ف8L{ 6uTŽ7i@?ϩNTB)q(b_3;QD>|D. ؚEz::}yv,r !"uA-W愙gN~]?cIrHC6r(j\jAn8wU(( 73u5-c\;S" >: $ BKG&ٸbI yq%ET=z?2'1xL2{RJJ*N O=vfyێ$ ꯣE (a(ڟ+!Yt>;:!V&n^}f.|90xQ8 K\>MxJNjDCU׎Zv}~ށ.^hɞ, StB {fOMj3'.vP 0v?P(P413H8uu׭Wr$H+LM#z [>ϊ59`I)Fw R8Z+wnuIҞ겸5{B&(y{y^*HI݅">3aHFQ2֦ rRxksq_S9&qϯ+\8l.~z"$5CEΰ$HZ}#0 /(5.j[U{M#@$LOqGbԯuDV֧ʄ촼%(:Af1okoq,M4'm&5azt:!9y )-p 1:81Y2KQͦA:e=YM# d//6kRf3A/͟o}gɠmf[=^bfb='TRe7=pcHSCmЩt"l6r[H9-2]T(v-PpSQF!4@w9aኲ"IYImMR]`f*9A79Gd>Fjv,klq>[eepZϝ9٬$h$>u19TcGaYECeϭ˸9o%^Ƥ ڼ/ajcgX|<7VHҤM#R;Aq,:o0zʻ!#cˢW'BkMYj&\y,t %}Ø?ؕB܏IȚԄz^8Rxr[ST6\KÞ3 NO(\j \0"t1=bm&.;U>؞FT>  ˋ9T2wYPFGdQeOj bп4<ɻć2X,{38ԜЉE+9c=&rhw5_=C+פʼnC}IӝHTÞy!2EyFGapfU#c<0Q9ǽ_s]yDiX(l*2)/" 9XSg iJL8gaFHʴİa XpDilgGSq]F zc[* 3z"J4OC$Ѽ^n[8M>=A6앆0ה|N-d({d!yԓ\XAFo0gR@ٓBd}LEKFoTyImG"6Ble(D`1!7 f\AQj6iqo sc>bSUVf*Ms$G刳Zx;8y5CT%{mȖF|d>{yRԚ2/跎! {>Zpg Gl%Hs}Ւ,-%FdQ.K #Oagϳr_t7sPAL dqZ\Ą YؤC!9J~8(/1Ґm[eXnjV8-]o/wxfZvlq68xU'ׅŦXϵp ]$#jI!@K>EZf Ƚ~GfFԞ¥̞ +sy`OS xJ\9p7?V]Ug0:ç"+.H焑@٦=N=:k.ҍg3;#nc솚e~Q=!XPA{#m͆߶қび˘B 28:l"2mGaO `ntr,9Ge=`f)kݹjSW=W!q^2R0&8 wqOH=cۊO̞2 X]p+vӌNyQkuK$2*b,cU 3$̜w&\JfgQc4$ ՘ wJp};djwg>Q@}mly @4˂b);3vZ< bv|1'dl8># Y6M+k\, _g߰ΕJ?Sʮ V/#85/6(M@L, jx eT* HA^KKV<\غ1\cie.}̧Do$m44I@[Lo`[t}\]GgR4-Cl\t52wB.Gol-vkɤ_~/" )Vn:F];.> lg+BU䜒a*hݥ¿۟1OhPJԢcZjOgob:~FcH.po^NJ EOC:غSQ#Y/7@`oЬ?JK}(%r̾&BV A1\-HMy5أEw4j6!;fȒ.񕔀kb(.{2RbcuQ4GU}\,{C P 7ʪ6n_jB@5>4_?'RϡAKD?Bv^P4 @-ۮ\1MR)؊vZ oK35DeΈR AExNH=laU_ρ dRl`J8"I"ТkRÞ ΏcJX#bZVqXBy]Y%wLs OpVuSfυAxLp0AҭKipȇղ\)B bO lZ9T,;d!EW_QrGgUW D IB6RbIk~~‡Gu)sS{0sbe'afD<|~kSӳ~rmd4/*u37euU)SvzZRSdjSix̶7G38}ճ8A91j<]@rr_X3 ZO!Tle e&"n%LbuV7 t9(PQ鏝1`uJ.$$rRnj>A '2-_=)=Cυ0=Z#n)qfEDz<8Iѻ3>0'Юx8M86yi?/dÒҁef {U%gz|*%0Y6ʼ(|qԟ/e8Z"ޯ K!ԖΝ}6^˲-{KxEfkk Gҝ{ݮ9|^<`h!9T* ADc vʜaE1T&lx`\JJzMK0;]*{NnPq9F胇 Uk+*\.|d[ e3}Ő!`A>˸ ʹ os?t?R?;R"JTGԺDGᙦ/j5ڛhp =6RSuIo|)#,!ٲ<(?~LdZi6E`&A$̝N}Vp/]|!t@y?0ܣכC8*I[".1vFQSmO^J7bWo}ZOhIB9; &4 ,EcV͗ хC=6 @lz[?0ÿ{ Sh\32f24X(Sސ:~r]%o@7Z,1!X1&|w$+~su3n Uf^D6xLBW^`|AZ"RUc3 ?o e-S6OF x[%l5)!"@xU7Zd7Gly2* al;w"R)wզ5W֬ Q~TC$h>Y!j4e[M'OWxp߱v 뜒iq Hst\o(]O<C fcFBEّKYnt.ҦzYUQ]zTv,n/9S{qǛtͅ2Jq4Xб>!Idr6y: z7C5v;U:ߐ wg4o7|FnRAlKy89\PS*eճO^dPxǂm_\/eӥcP#E?dg biN7h T#p%:g}@aؒM6(sX ?M7esG6'݅mf0xpVDEƲGxBc/6NʊIsEJ=g*02T"NPkNƀ)3I穏O 9SmJ]7@cմ+XT ]xq.0p|ǸTG@ ;5zc8o.(8 AL9'Z0mhroWNU݂XM  gAW啓aEz,YKVurX$f3+;Ǹhܡ[k%×`ٲe 9V"%;0JzN:L \}=SZ] q1^>2d*yKOz R)GկwyƱ]9^Ɉ~E |׎74~;w9gšWͳ~ZuV+Q!ƟW HRxarI.i^^W6_F6zoS鷯vqcCp(_2u_:蓤T^09bMu04P dH+F3ste8)+9N)a}&GG7 S/e|vQwpUi`A49ޒOB7ݩ16NrqQ*6\XPlH?q `9R8_Z/I ^&qwb/6.l_ Y4cB?0› hګ- ww-rkxO ͘;ؤKn(upy}:#t:& ͜[g]Z:64~\S+;󣼄Tq .XJ!k r j\@( Hf:G(_u`nݤ GiSFJ٪jYuwqm0+2l"C9im^E+*yf(Nי[18n&bZ׍==+G{3~=;{48`s qon6!HUD+kъBH3Zg-GA.aKڠRb7l0>z /ؤ"63.saOG 5e8>s0s{'55N)4D>&J ]+ܮffNp bMFQ|OV8a5!C6~42*r=[8U,x@!Ֆbo3O CxgӲYggS[pumL[˵>ٽߐѥ/F4W3UȰE! 7=UѡS)j2%TV{6?"^7=Uhù m,Z2 v25C,@;gk6I|z,5!|[Sk 7n sA1z4bN@r%aM J-QnA~U.C_fVGrSԾuH8KFK_IqP2y^a.韶J]\(ީfЪ!i+ͽRqTX?jJoT| 7.HEzO [̡g8uDa ޺PMQYQ_~#UamܶS$rcZ6"%>6"!? >wcI7$H`Ud罁5{|C=Wf+ϹNU?,mSN~DD-\֤Hg!}YU 4)3K4}R lIk^'pXظ/|=EKN 8 "&`{&=l`7I`>en|+t_6vf.P #1FxoY8%,r0ʾ[p%N{[tۼ2|G65_x*`֨D>?2mMPc%Px'0N[r=[|| 2.na!6qKؑ5=а1e]>$,6[#_S^X|T4޹b{Wg*C}{ceՖⳆᇢ?ŁCutN1|鸧f'cvOeV]J :zĬm8l4Gm=N]0ǀ߀41@گq"6( :{lGTiڎ $6 L (bǽ6C˺W.ًB>`?oG>aL`MjDuiMFP' 7 #Bȕj.;U_M |]JIPV+{餘h&`,'wi瘪 OT+Y>"O& J,F=NJv+o+D}K&: ABrc#@#3,Ļo$@aCI$#t]CلD8Ar +*hܿ K4\a-\x8-Ii-PVͪ;iSJ@x ǐYN,=.0x4*N ]v׎~;6[mCY=Ag134LCJɗ“Ծ24*D.",Ҭ:OI+uUj}aa:M0Ѻ$W$6VIey[ԂEtWgFU ;pȷ~c5 !6>fvȇn8ַYiLjN ^ "5$U%`Ad!JZQ` zS3t3i>Mo.h/M7PiH. aWo$OAnM&Ʌl.|`cx{f*U,uD.z$BÒ=MykSj:]gb&^cky5,Ameo6ڵ$T;15 (՛(O]C~qdGFQ:6d-ǿuA{CST|q4vpkGWK?˲t>@QR:`@kr|S} g?Щ"OM|ۃ&`w0ͷx qo ӭ*'yUxnv8 UӾ:wl/ LK4n4LaZ_0QW\ wŋmi _n,Kη>[sbd{or "kf-*j)is8% sFz:Ч>#޳IK-*!$BPt僚j^YFZs),ܷR?xS8b \pvDE( ߉ìЦ5MnD{7$XZ5Я;,<BaWɝM<c,{2}X/88_<CJxHR {\DIohޠ#I[ƶ Qk$;q$ilo6 uR?HɮSee=[G:M;fKb1mt]DǑi-YZ z}I!FÏ~24.-`v\#Fz$FJR*"jO$JXLlJ|_SN2\XKDcOՔtO0/qM-]}#nMtkeF 7 ]$*-IfjkbyI4@mff!߂zUh 2Hxy% {f%&))v!9[Ll[/iEk< PҎ)K/tK0qq ^fJe]ajup-ҍgFӏИ/iC,?ݝI5`3xHJ3m}SuF)?&K_g.z m=h.ފak VK{BXW\K )PT쨦_`f+p1ޖ`LX!86d+X'7㝅Cb'FpMHt=LqO8U !x\t#NLp.ErRKMq5_.#j&ZK Xj)8M*/kڻտ}aSS +c?JѬg#_>-Eb0y%3z^pQ09_y1{x5~Qz}z<^D|¢ԞN?xӨfؼXi8ۗk~2(6 U!-o+䢰!`MulAҕzό*q6}]b7+ /ly42IE E} !^jv rV";"(iǚ݄jl9"=q&ΊMH9Ĝ #EU &XEDuz`eA /d\HGk9!*>gXQ^|E4 'O10zڄGQ&򓳃*!6sZ/G#" qm3k5%VYbnjx!Х* gQُ!a0 `MOU$bF5|%R'8Ӌau(_e)$="d3tOO4R6 TOi#`0IC_3@ >@e74"FVg=8Gsam.ɕlK݂,ԕb%UZI*M"X(S@a'<_xo.%Rb ׎ejceD(*1#ljJ_6b (@BF:] ,, x%ѹd6&]czڤ C3uuWy<ۋ ӎ7}먨C6CSn옖`^nC-&$`u)#W1]u``2Ood RYdv.u`brEvF@R-h#"5,q}. W8) RGZ$_X=9,K`gG?(zz{* V:]Sg٤U^D˞(+oPm_љ\W?<2Kw|bsu9pפ f'33ౘ!$C[e*cv Q*#3jb|M`4K3.>ԹXAKa۸Qs5~[)iMB9U; [r$b)j v>;@'J,\YKޜl8y $ 5E5J}:>{OPigy"FCFW_2^gQ"w]6T\?'= dv"#4JЯ{rGn {f & 1ǐ{AXX,|G; Qf{Yb)$aAfڹݳAao^w-\t1@zj3%o3 pܩv0|~kogܲ>˭UƔ~CnK8ZFduaMrOJ)#"~lzmױ|:4VI[DÕ;eLoڸ 無mjڠOJlNl#]AX(3$(qZ&^wɐ:)=|[LF .(-\%@EjٽT*cjafcO#=qUm-(.N?dG+Ь[~7sv3G6oxs0 M88ܾdۯ? ?YEK eZ hn/NVaY`z+†_^#P8aeeĊBP#d7@^RLl*fJ {Op5F|mu SلʾA/(=Ǎ,܆86&_ꑔ (t 4 ҡe69Z,W opѰ09| {KFGr`-uŠl05iXW:!EQuNXW=X(wE)˧nQQ-&/&d ^\?Fc'dJJߙ6y<6æ$`{X?-;Wm*7xLʣZ6W\vi[y uL|p&w&<c؞oB| %n6jD}b˝ϡIzpOWw|[\jѕsznFlH{dM S/oĵ3Mо9iܬUABxd?%S'`vV_ ,}'!:1Q\hpu%Q;jcA95ޢ.Opa{ϲ4` ٭yg]YLۭ>@~_ `t +lfT~ʼn_$k \KnRQno,FljZ7w&\$Uܢ9(9.xx T9xHµQn9q4̶й s;8)ޯQ~ }[~ 4AҐlj! ѯLP>*_6 e( 'F$Tx=`.`HXrz>OHrn칩# 73`Aewˬ!X[Aᫀ3iu}D(/ )>G?7|ʈ(ijm=v8{X.TX!m@']7PC5W|qP _Jѽ h)ܖ|Ml2sAi1Дmm-Ghg*vR]jL|Džjt}.r;NaF+B,毼LqF?8—;o#捸R 5ghk˛Igs>ݞu_)=-#nKb `y%PnREZ>CX+Nvc)ShQtYƚA~AͿO 4 & 7\T pe:eS^'\}8`9LbONw/M(3My1ZI[oh#61Qd-uy4Yf&Viǔ]7~lq:4mtC*58P[ƘWKDi.ɦT&G/ "oNTJq ^TdSK kx^ݿ ?'g=X1tqsĖUnH.!%jgq7J]68/ǵ~ M9*KV0t-)uA]/A{<,?aU Mg}0:;̢ Ơ fuϙt5,;.)sձ"[ًbdl]sU6#C:l +]u<8 S(n"so{J=OW'Bb `ˊLIeܦE_?Axxȴ+ ǧxqyknMucUm3̼p.e15jxa]KkxUlԯk6+9SʯČ&lO`„}\[p3K@QR~Lk<"d LX4TYD\.#[TS?/g:3QcT@`C"/,9DHb. r)gYu+LJp'zQB?呼܈p ޒQpͷ *vIf7>nF4U%ye<ε$B?TfH-#iWM6hfPbpOKA &ͨW y?<u_J웅*Rhq-.sx9*~L9~ @ѳ-:-?}|ǃVccn@]2 ?Y7جO+9r2IrCYEdفY ;rzݙ'$*)¹[@y.O Y X_lφ+@b((^0Y/Uym>UC *ţuWsś3bK`GK+gD#T\*s4V:]*C% Nv1|<{'=ߝ9=;hL:19j(sRP&$A}wR ~et$xsک .vFm`9]]3p](S,c {&kkɕq/c2 H)t%ˌZM=d-~}{E!P:6J O͙ϼӰy!tPze;X󆲫.9t"'%4!"V#E=\*/M;Iq@驾:%kju6 ݒёԞd_A3Gp=PPD/9aA؆mlbSog}I0UqrgQS>J9_RpzVRL/'e Ά)cz˖W*{gZPWv$0VwQ̨z) ÆMP@;`EU"mcZhC)+wddLv:F"=ÛQ˴~V_ 3\ٿl`Xux/kFn[0bCq9|@$+.)&&1x 2X2LoNTrQkO&j19WSπ}J3Cd4l;}ߠw6)$ W8Dz<3=UOܾ `+QAj6;uS9~D~A>1pkKi4#Ɍ(8TCuGŦ`*oݍp'>W9#g*Rbk1嗊-7 }~H=AhtM`D* Ñ @+z;67.W`gClTLDJ"gPSsumĤrT[\6x '1IF0n)$3خHD /JD)LȚXj3'pޓ`}<6f\4,Q;&4Q< LG0\]Q$.KmfK X6 hin`X-[ .ݰD"N(#ا-zm &+N+O3H~FmR^wEC_Ac:i; *9+x5Q$3r+ϣj”S )n7L=)1ٓ,"2 +Tmsde - q[X|,2V5fYBrx &^E(tj~9$wl7"~GH+3x/w7KVЀ[mְM`*F Wt[c A`8r\ [6]ۊ:8uZGoJ<Յ=0&wR{Q{|YMbmh/I|y Lhv<(2N'z6N6M4^gD.aCG(lؖ¾M,u4c$qqMYפM…ܬgYZTJ Z:!oh'*m-t^"hv˔{s;_j>?j Jo~lp;\bȺzh\l8'IFELjO9=Y"7SPt[(xYœ. X#ȁ-?Žh>iR˰3bf?įgB=NLQ\/ wV& * qi{P ^+}<1ڈ+h)6=V"v,#y_{jͽ;Y-#=mzPYz:iՌd#o %M2͌%ߟi;>zuh3FT&HI?mtXX̔5,5>Mgu ft[th\4hsoΑյU6˯q,cu27H ݎ6HEАVKi'"x~|$P˂[w`%-lS+B/rXv'ezrMYÐDZ' gMъִY%%ǙL|ܥFJa|חqp@Gtݭt-6]38XP@^e 0zu0 rW/$[ŭ02LXDb%\{ XFP j2VҠZNګ`#((o&0O#]>?gWȦuK`ˣ ޭ#IefDl}-bg av9˹cj-~^}VlS**?Za:SCz G(}%w]K xmw𸰤' XP4Z#'B/%-*F=>B`_QQ~0yˏIk./ԭSf?ݘʴ4 Ɍ:9hkLXp,0?a$=H]!˼4 Ca[IGϪד>^WTAq5ҎAqzAErUwcQZUPT869ԬsU]v #'"WNSkj!~ 3\7vr Ai@,pu+CGBi3,|>}m}rZi`!D> >mSԕs#vY$5qa6..Tj?`}tҝꞢ %LqFIg %,7КL H{Y{dž*0>VWlї P;LUN^=Wx7{Ql4Pxg_]tV NPM=Tf &Up`qqFT@S<|G>z>W |QNᨬ3J_ CUM̾?slW)/X^tE ^6yHXp $vW)JqQp!O?XW Ef V̋7ة..; @%u-VJN,z_nbur;G{%ij FZ: >~EՂgi' ]ͣlv4t uA^fI܏c3oQ k;I8M'_D׍uʼoJYyl{]h`1߬޾\VMK!@#5?dZHc=W,+Y$ͫKmZrO4ox;R֓Wb2yf33h ,kZqX Y=+`jơJ.]4wfbT;yB$2֧Aè|GP@ƈeY!yΖ|h7QgVBJՠt8HdEWQ++i% NG(!#3]- k]!B6,-_@\ǷH [BV]Zm0 ?-NfZF)pTcJ᥋ zZdߤjTކ$?O쑎䑙⣉#"kS#N j|:E%^୑ARѹ`V9{Q y\nLL@TOk1d̬T0RCs } `%MC0U &Y#QEirAb 0=f|!ՓNSˆuSmF7o_Nm .Ge}kFƌ g떆fM OwIQi]gq u  /Wr2R] 3w{#B{?ωA1C\&o+C!nAK1lyU@v*K\eCd@ SFlڳÄGGSL5kWRJH0֪08HTls2}µnf([4m?@ kwderY}VKVazf[nQnĒJ`@2eZ\seַ{>DT=ߘUM,vIë"(wLo x:ەi^P3>me0u\9޼LT(cXH$3NuJ]=ju$]럨 0VE4?m!rj}ymɃQlSvg5SO_3v6dmx漂$?#_ uHyy_̟<7;n[YbγumWSC̴d4+Wk0KvG9ԱfqDj$B{”cڤ3`yH4o§m:4.A爭w5 hoHcg~pz5z =r7"bf7WUE+zdc]^th&T'7<j.:dQ4jSSxXwDIE(.N?MFnF49[%eC#K~%XVczvj{hI뗝(D3 1?'(Mۤv3Pk햎?s#R̷o@,$'IZy~Ua[zT.e^n ww3zz@#߆wm' *iR|oc&IbOGnVkdڨsk4|I=_qSlţN~?_ \'i[:'V%jQJ< >6^xgthb;Z~5}ipmr^+) {O W*xzD2 !{W>pr|-gםKWKz3r^e[ #V-& PS̿w>lGت kIj_ҽi0?wSQK֑ -<5cv-8RG7ɋJbJ8LT ;#!3bg x\9㹝9WPYM`R`tŊjbˏv8}߾nIf. h.[fgH4A"Qgܰa~LH aY}|80R#Rb(M ֎pGh ?2;f ȌN< ~unW}V,STpfŸ}j^VJ'v%/Zڌvqǔ%2Hsђ$>yyp) u]6CF1iD]xY;>7!;!2cv?WQ_tXy,0m/os1R ʘ[]D<,# 8yB3EiyቧѩrIsItڐ7r5H5RUrv"V@FAjqvdrS B`VCQBæ9u2,`h۪"JNPf'0~@:0{&r.7 0cVQ+NG`ֱ1+qڟLjbLƚ.dJE,c=ߖͮǬ6Ҳs\P[5 Tz$NtrO~w>E[Xda?#x8I# .ag(Y9P4)^\jd*c1Fl@`AHQ"6=3b'CD̑~vD<|C{Բ+X 1ȻxY 9FNIC+'I/])=a. Lp[DTѱU5Ų<Dw+p@1=!7B̓'_c7ٯ$z_v6?#ä/:%j͇[XXR~is aDET B+mo!槢cZ cxHr]ΈhšdV*Do |?Pl *DhmHb#;S[if(^E뺃a4ɅQKI)0"U9A_P P#-ӫBik0l_ KUA&؝*ŶLۘ-ǔi`xRӚ2@D퀮t\׃Hp<3iY5e(}A uy"謒o J_YcۛPX#"QܘY)h Q#soH34f"B oND\0񸆄ȞbIdO y(u!c̯"3-")SKLжi-/XKF7[g/Kŀѿl1PxctvucCxTvQW_u r߿? ' RڈL_,܃]06Wzs殺FL08VrT^ T"N&B"G籜M& 3]Pm-Pc4,?U& Q'0w.-n BZm>lvդv?D8Y c .[i>;xD0BڷQ Y폂Lx6#'#XP-fBU"u )@-ܑ>X}L'q6{+U/46/et|6VX" jE,1KeVi8/uZ21PmA"XKxNx1.7ƣ6hVmȭ,ML:Du* i AjВ02׷e<+B3Y> /(ӼZbrSYvT J`%c P tA`?zR'Edl)51Rm?x {sxIlʹqFf 8d1O:nڱ ~m= 鴖Sˏ0x")^=sQIǚtb (d!D(* NЇ 5Q܆LީEw*+{P!љ׼c+kB~L=*2̖$GF㠓aw6.N!E 1( D+a.l5 W:Y|W~O'h"o{!}䫆CLw. \Zo}0*}; %A-By1%5yL=Zp$NG!R0gKŵK-f:dcu.'Tk՞س%FJErDy?Bᡫ$F>$.Qk5^Q Vw]Jy*ź%:,VxSE+JQϞtÕuimm530҇ w TtlvӘzrv٫կld =]ƭė/edZE 2EtG [na2Ꮥ02uK^E?^GZH!ߟ: WW6;0~LA$j}Y 8 UPq  Xمgzbbd 8gXB",׿X3av&WuwQCϏ-SyDF)"dEp DNG Ni]9!}b]EʼxQb|TF޷@Iׂkw{AuLDTy^#g KnO t]2"֬a4^mJ+ lr#s mDz֨3m mL/w:ychYO!Uei嫆o0&㘷zܨ2{?0CC?"ԛd[c\R|+!jW;քQ;vk*U"D:4GU!Ax#Y5u36KGysM&+9eGK4Q_R͜]{Ѓ]}R+=jN̲ Ț㠄@ʴ7I%LuZ (?6h?JF^7B-HG5Y/U|o;b\<菷hGv<]Rn7=8ACJͣ•-J]Ûz+6Ͻ֟t!}bv-DdOdz:D0|;9- /@FՐL%f[N6V~]GjQ] ceoeER&MySkP-ib8didY>Ge_#ᴃt}pV#k%=qxt5` LYBɀ|7}tdIYͫ:PjoumfDjMUbb5l50RbMȕV6_w\ѥ$MjQq]rYⱝw}ubfKfz ?eáhrؙH|[}7EF{kH HEH7lԭ#qȔ@\;Σk*Pjra10䐃2(6gH\H/!3nYι3*Kʖ+- =.~'ma&}p85jHDW)Pyu;nx8Q PbV MF)%ƙ %.kk(@!=IrQ lɱ?* \8,TƸ Q߁4i8l⠑pREMp)&N۞Hyv'~pVMK\m!.H6zuV9R{;)@qn8?9g91djg^dDb ZNو4V%qtW@D0]TN4=sq0Oby'Mߖ΁,D\felh`>7M'l7Y^{m xڽPM.]7)'4P:Z 3: NF ~PS4Lg}sϼnJa 9$Gx -|kHCd~Oi>mϔ1(:Y e{xŷa {^?kBlWn=$2~(Cueii˹XTFժlVh8Z S/AHF48IMT"FhsQF]:'fsbYѶ׾uhxlFK*[; i' rD?%;DTגџ'bkIğc7WcΫFwf4"SmEV1-C?˞&FƎ!- F%^Α&~@J.;7 i@Z%Êyfs$t0qo쇎7ziG!K:*ƌtkLؒɢ.X:[^Ik v姇69V:&C A#l #jW=>IR<8@'yPNJqX1O+5fɂ=m \Kerf%_^-g *VENZK ٰ=~.բYSԇɓ_:R/DZܒ+ڝQhHdxŞdd|Pd+Wfό-q/ x!$>m̠ P Vy R ѶqM}0\ԝU@DǙ1ຸŻB# e$ }H" E@%.6 ےfEY\w<(2;H D Zt~(& UjN=rכmɆnG@Δh\|M(/-v>ǒo,nwJS>a)q7-|22اQM _ WQATMkc>;돜gn{ÄUeʸm !xc@ g߾^Rsp ۊ~wZu@res-^)8wf\g(6uL<ʙWa/Gu[F_ٝ0cҔj4Рikhv3uM3IÚfkqx7r9Ϸe*(0Sx'@#b}]Q2_ Ew*tcɦnfU, a9lHŷ!ӡ5WL:8-Dămԑ/y)ݏl̅e6 ݾFQnFy9]LM䕺IZ5OqYܳ\O3Bh&T32 PQsv9E)-aScGw;`<侯܍Z'}KX1#$AOGXu \7$dN7GՁ; B H߾s)zc䡄LŎ |K:/E ~씑繀+I0,iSً[i%)8Ii}0\L_H (ۿ5.ג?]ЎѪ{)#ʱ^qD"2Bԉ@):͟կ 7zPW3bw^^< Pr5xacld}(=bbJϋnz̹,\M㜭˝Sۘ?@AFnk(3Ƚ?O"` D>dPY,ͣYYz u|2~@UKuN+tyG.)8̊,2 ʕ񌙚C59tL9r]p}>Ə\Z4LK }y)3EuS7%J [< 60فflײVFNH{5.Cll@vO a?kh\  &#Aa0>ʆlCx#_ :tNJ b[A?OȪ+Z3KU 3sI2FrkZM{oDj7LEq /ɺ:=$frM_vF9l= ? ND`OHª^8<3/«붗X_a'(9C`F~H9ң# cpy*O^Iw-^ݙ%ETm]"DF&h_gff;{YC{$翏c`L *BҲҩI,6&6#^*ݿ"emՇ hY~/^Pl:`t5x!?-y(.ᶉv8!LjCǢ,eO=*P': &,,Ŋy;AVC djqm`wʞ Q$0KG}E,`=uu^p q` U"+xJbf6|VcdTfޠh+.E=Ujf-Qpy .S6{3{v 5r^_ DazqQs[07-$/P+F-X@=oυ߄Av]}mGx#LE7n~cK@pa} ]oq+*fN5#zbآ"VPHpUy)ϻ" R\h#挿vJ˻ u<J#4sA>o[TNE4ppc'9(DBJx5bOp{G;2ۀKyŰn-l4 m#kT#}@5E BӵF֮ &]r+D~{"YVĈ~ O}D+LʵwW̆ߺ TEILK){ͺ7 y2rI|LجfϑdasdB6 kK dːt&LUrUf Gq& ftQb aǬNM' 'ᱤr>gnb Q~Tc[J?$PYmE"ys> wYu5MՑa圠*l@﨨RWT%]Nwy[.ϸ",zk8'kkOŽ/؞$͹(U*߿STJMFԬ`6<? 2$써_63Qi-MKuw7o3C֍&oVx 39j6"SeV뒺"#m:V[v& :rUKK蛗.3e'e>̥n2O']-3i '"ؒPt\Y[^֑y, &= 6BHV-}D@B|('`tY:@kc( ٴA['XVw7T%sKE+ƅ\-ʂŊԖ7jeO,MNv`Tq1ABK0`]eWjo+i/CΤES NR:, c pSYG圛6.%u;!o ._N/Q0Dq֡e\ب.dUiDeWg%C|ȏ-J$}3䉒]jp:xFi6/O_,JL`ĥǦ{cFX|HԸvQ{I5ilk߾lm`s꿛04D}ӫfPD%eQv GU|زP`<+x6[֕ R$.Ηr];fN?K$+a}p+Sntd8YE‹WYo -{(fJe=-h5\7']h҈[p_- 1 XT! 4Ij%NAذ|S=*4Ň]::x̳函9ԜVeq_FVS$) WJh${60|_1C$]/iTC374xQ2渷c5FD#HS.n ʹV"8E,S A -L BχtizcEh]) U\5 6Rm QI{CPUT QTE dfRZ8',#h;Ypؑ1$ŧyzŁ.JΜTz*09G f'+dN|0M&x)v3ԂSMieV!حn>@5Śs&>%=sl9aT*28sꗐ;ԥq;G r߄ɝ3IE(( G*ƭ8OP'Ղ'69 , lx1HN,u:T ѻ>jV4GXN@F^!:2"LJ`dx<rhBv28|8g(lшKN$xKpt4btE4_4#\P<7[B!PX0'S2dOX&uי/nI3h%vj$eJcrЦIU}m6%bk5/G]?CPd,E"OTbY-y6wUa~ =JrI\6Fs)@"HKNվ~p{ a3Wf -C)0qu VһU캻?޸u.gCЗ5zŝS@bA)%]w2SkQo(+Ӭ k2} f} b\YنW9E\j=Ke kK?{~f8)"H9e2YufNz,cz< 9*S=:8%rm9CwHa+=)mx1b5F9T|9p,tA{qA1y'E`VO6QX<'bdA']vcT.}Kq^!n?ǢgHgG[+(#{-Jt;fuʹ:+LJXn8g77kz4b&y/Jhx,3R4,SfZжa'`[x:=t!n3ܿbYu!y?tS3e R '&r*Ɉ^5kn ( V+33$'ysn%㋪bd,;fC '{d7NU\ݝ2:K;G Q-O%$]txiLzi(̴JcQHRK@ n*zpoT~FW2fG]8ұϵnā8X 05@3-cP w>5U+=)n|OƠ=Y~}\QsA<tB+ ntqd+C P 7|KE3TħV^oɻݔ˹cSqqq˄kVhHC$P 8~0d=\DDe///Zq.{&,Klb"ZQRW*P6 ^oƊDֲ*dLOy$NYD/4fe:.ՒQLIx r۾ |gG8Su<E,>Rn86p ~°9Ynj 8+/P[́UQ4ӎ1̞ Nyf KY^ܵ'M~=t`T@, JB3ײQ Q4Ne|W2St_8.>hF뾤&٭у*Vrh(%]&T ev& ᢆ sB4 oxoz\ Vϝr8_XKQ7'ATVE[DC|ɪW%jL9D: D@i6sTBSF Ve'ԫz6B.$ép@rwi"{um! ,W\IHw`ONA8J+竜GBA|!YO %~4Ez$Il.ȬR!(M<%puP ϭw'\ccWYN+I`Z:+ӓ˴&Xl=)O;QprH&, aƛSFBծ9NJ]mEzh.u<6U9&lz(d.aHrKt @ WO0A3Գ9}pH }h'r,a \6r[05N_Qu\Fʺ; US)Z(RY=p8@#3L݂EӨ2=u \ܔJ)M7A3hN{tj3݇̓1 q hI'8(E[M Bȳ΃PۚlToJ7MC g*#'hdk:h 6µJr*2E !hɉ?MBV=1H3nGħ.z߇cwMLa]q0AGMaE#JpQC8 yo";) D^H2buRҢ7D ;]=X~PgE`r$|8{>DÊ~Z 6Zb3/7\W4$#|е3X+;kEƔ2ߪ$ˣE3%Z}S3PRc6AUZ잹ɷA'DOV0q%!f HĨs >97CԂ[tN(. c6Uru{x4/I´nٟD. 78%MEC}d_yrt {< 芠Lx;Bg_\vZOu낾V=$ f̭1N7}o%LA G!~[ >MUq}vё6: k=9z# D>HA#1yRPMR=TapyTvNo7d[(ED_I'F~֖i"`rߋZ ,pK6bx`= [5&誼ƾ6rD Z VU(]!ƼM|!mXT)C*z7([\VE$=\;I*~d5NHÕE}%2,|'?W{Î&wˠK:fkU9BmWPjqJ$>y :Z q5[V|)_X>$wYזrxrvB>i; ^]&񫵮85h/"9i:ۅ f < p::ݗF$\p@Gof;+hAՓɛ*YF(Y8%A4厝Rg"277 ,pȄ_hpoaoŠt(K]ܒ~rs=ψ˼Y|DA~1OM}H?ío"khVu82=ɱbO!&D@vZWhmj\Ox*bKlM Yؾʶ5JL`rCGRTK M@I>WF\3" dD0riGpwQϠ \ؕLWCy/{0W%_ Rƅ Y'Y_LOeʚSONtKI@Ț-DP"9p1l"I'*}d [865S!aw̺x>vn`m2^w' Q6[%Z!$YS0έ3:<<'e﹤Ւ9uƕ #FH(uǁJWo mcF*RG{^.}oW<}+Õa1?2 oᚥg6Vm-.}&;"16P-U}9sq]<%;kqJ[M} ݋f}/tqhRd *d )0O%Y-󹚋)g>R0]ӹCVݗ$ǫ FS.] `۳pjW31 eU.M-.O::=Gɢ(YZN o.&!*2t&+6JV^v9j$|!%Ʌ y~ۤ*/"gzm kıfz p~G4IlB '"#}XrOtYY ۃJp]Vr3BFQV @8$rh{*(yUB ?x4 L#$ (Q]qd>O "^Kxt2{V::vo A 켴m7i*mA\}KZN׻s$ ¶,{`i +\xEUgz8[(~I@ ncFi=jHs|ѽs R-AʿAj3-)p~w"lO71?M%f|/ұf%{Yт \|d*acXV 4eCcJ̈́3j8 0bkIH z32J˩aoؔivBu5)[l{%\FEObAYfp,q \ ԠJ[{.}i1Hc$h/YVc^1 IL\ j 0ghR PUI#2W燖g8 쐬c1äP6` {'aL2rYw_vHormAx.ծy15FbsᢆXDqyeI긭|){|BdmܚRIdA%^r/ႍFhXhɆߢOhzvӀٚQE:]PC $zq >mLNn:-(F<%@LKeVnkɿ^x:,1Yb> &gߝhcR q IQV5l #&4e5 `M-g}a5-gєŗyKtZa@UOaw}kS 6ev@ h`ԓՠ}{0$e~J\_-|KGpՓyz0շtƎ9D҅Pф ajw+]{g2Dъ=F;+*[ОKG_rkAB 4 zFNxVS)n6}g Р"8[AA[wW;jl@5}ׂ Yl[3n,=?5;ɑAݏ _eC LeL{A˕oŴe(s\P]F<zO3@c}{^oav>|e Ӊ)4sh]d/:cq!bs c8iW*ǖ!#b@.ü9O*5UٸH 3( .l]ݠ`lkaxa3sFmǴwGme++O1C&.5kH[W }'w3XC @AlOxΚS}.IPhq3*C.zR<75n !R$WicV~0NLϙXψ*t]h` Ùbc6&3>Nju޸~ƕ hYv6Zda΢7:P:+EAG/I,m^ޓk.#@WkF/q^ O%'Ծ.wl K $x j L/x#\cXˋ:x\X;abxP|?Dr-B2ķ~1sgP1f8RY;^v_C&3v\*o wAiC ء?h$3o>a-^/q~ZwN@X;#`Ԛi< p3%"87Pa.ԺQCh}[2 ;7HKwE8pͧXW/WzYn1 4T`a\S.>G d^(`ed.Uwm*Р503Z@/{3#w}_[A~O) 5<'Lg r?ρ 6#{u/FiqW]fxυ.eg;+WUc2Vr7QZN%}pl Z &2Z_' X`}aƳk{${ 3]HP^G4Š/j TofJ"棎26ǰ?k~.;Os/\LÇ/Yn憠nXJ%qܰ @ԦnfD!AZLu!$ccx's9NY7*=Wq {mԏ[d:U3#յrc(۩\&k))4P?ĪWTuB6չo.+=HC8 (alFr[E V;-!m[XaIK+hQE"췂 vчj&_*.kn`e{j2h2>wW/Ar/{Z N놝rӵW~zV1b~Mq^l#S$R VI`Ⱦ-X,*"j_6ڿٿ2'jћXN|uR8d:&("[[[બggZht)B(a"4z突#L}o^V%P&8+,we8J$(/Z^W؜yW@u/7gIqX :Ogf iPټ}a$g˟\ltԣun *Ncf s{'8 A$C %17zz),U\T{%2:0dƙQ͜O}?fNٱU*IyPfٍT>/am9ݹdz|sHu=3<"ksرBGߩnj\o{k/p|ej2V=XL`GW~sH`A9k=~,h#fE=%eADI 2~=Ӟ5Un/LFTucl^O̼ۨT]CK$*&c4EB{-&ʠ`cguld/,]j@R/[|G'^i M ߡ=x5pFfʼN 4Bp5ǙYx]R;(9*|}gS{Ps ڔťYL s>C9 I,/kmAƨn ɏr;Xj ӿ|22b˺?벁;m`~_HiܸWI4Vn`O(&SF='ΡY㏽[D(TrFX~3lwp#-Dj<>6(:Y/!O/X>>zg7B]g>-7HJNcШ| Z$P.wpcE\>s1C*+Xް⃌ e— fFX,x&g %u㳟 2B?XF!]fQe ˪P U4՗Kь(>Qo ~IE5ed}&BǪ'F!AGy ֏dG c/ۋHO8N2^qJ6ڔRa3n?hR=[gЂzX`?O"L.6Eg ?Ec>2Jt䫍/xԶ?bԯ58m Mhxd HckύѴu|. * fs$]/Wepkr>uϥ{}R6}؀$a EHig&#:c$lꋑiɎԜ&6gi/e}tEPC>2Ra Y}= +K˶z6rx=MjC8IW}L8ʋZ '2z uc<]^%1$j'k-a0~A8h`gwo@d,gjd2KݤjLw ol$KZCEMA`3EBwK=4nBT `"XhϜzFFYߢgzۃw8i'Qz,_PQFgL\:)UWl> G;/FӲm1Zhm/lW/c~[n1hˑ)m-l}gPF p(ϠjTj}K<Y'Qo"l7dӰn2;@S4*ToC21zkUt:ihH9ca82?CmY(qTW2kn'WƏE!>M嘴'P @b Vcu-|6zt?GlsayCTpz[HZD~Ƭ;$<]XAW=BkJ娺|_) ][wU>P~BuqGӮ}IgNdS͗޲I +HΎvc ;\ĵCu=,E>V.-͓U1=K[`&mQs?I.: 6V47ف\;oOmۣ!t4ݦJgXPm{ԗUegCD&%nXK{(8c* 7bkV&ɧfB%$nY02Ӌ0}N

IːqsI9\6\Wt;ZNx/-Ѐؕ>( x6>d1`y=n@< {wXt(hc˒&@X3ң4$|uL3lElR8[t&|y9ȵO;<13'8RY~bW.~fWaASȰ/0Iҋ.$g{jɸ MU,o`nF{8#oe pjA 8/\`5%.z+1ի,E(By9K`bP/D.8>ނR%bvN P$K0E98636N*q<^,WCڽ ìY 3fRU0cN+7¡~Z8 c [JN“x2K"7 {xv< BGW_u.O ˇQ~]|3 -xr`X`%3Q4^֡ƹ'3tm ) wq0b|[4Ozypg^:G,Fn./޼Sh8SH0l-}TY Z+kVC;BHdDg2Gɤ쪈1 BGvxs's,],MXRfJzI]6crۀfww+[XLKTJ[w0K ښ5υC.*DL@(8ZphQnt"i Jiے:%E=.o>ɖ"k h.)/%e͛DRN!R2;]#J0M%]L6 ņ\܍ ,OuMx& ?Yp~PaIBhʍmJaW`9=y %:pޑZ*J-5 U8G~ GT er3C2FtKUIiPjA(6Jo(& S|Txn3aeMrMWr1—-41ƶ΋jLMuo5!1Si˟ź~ttmJ ߼/~m*e9Rz./;_yZ${n#{:}nGD΍͝§fWy9fږ_Uvпë,{`y]@$ӗ#ý<$t ;08 u?ܻPE\gPF^8J<4D옂 `mIs̞_KeR2nLM5Pmw^{4%< Q ?dTJ*mE(1 |oF<*.ۃRk%-!BJQ󐭇|8ݪ[< r$8u4 #5^VWr-c$hR{%$) "xiLc)*ӎ %:;h?s,l[m+Kn$7z2\DS$y~F#!U?M4uJ ͢it"{,?+==1lûюԜg#@O;| O:Z$Ef+:;R"ѭ-9x&/M3C3+sfg;vReHvhjEb:F0?D)3tZ8fUtagk_Ӡ>3HdğǢDv"iJ7 ăvɈY̤, X7!.eCZlE]{'gAe EVrIS&5s;Q̅әkV\ ZxQU6Hjő 9*,HT&pDuX8a 멊DGw"tmMv{NTY0u VHʛ!&{ DtO 7'ƫUuWEES:V%è80K"af(AfZoUԓ\p1_KˍvԔj9 1HeRt3Crp!rd>.ND_V8Lk볃K!>ٞBkR*B0Frr~rć:NZT?ЭKfsv,z È7[n@ꄬ$sؙ7v퓘sx0FDMT=oeii Z2=YX[@#ɋox I],cg-!ɑV4]Hx4s0[!+gh(1ك =4w'04cD >o=mrS-+pvf+w;ٶBB.:Q%n^V~{|SEɇNgiχ[iK9_A19J ^n;,pqaaP9{R[zdixljX\v BCmG5kHO "!M]04)6xGo hS=Ξ"&FŅ x1Z/L5x IPKJOͪ,ه E8T3KjE~H|N?dH6'W~5|DIQBtjyT.\ aˠIH[QY=ջKV˂:Ƥjг"]My[V;'RdVJz@hz7$^fx X ^<& @CZ7蝕%L`M#ӗ$3-I$_w*6L,g&zn_nB4q O, $c?U`v{ =Em+Mwơ&)8)gTS6w9=>3f9rʕRXt60*j5mZp2;s lI"H67IV7߽,m7z U&}"!~zxӔg > VAѪt󔟍fo B7EvSu5yK5?kbɉ{E ը/+Y ]U vn?@ d<' P GT`mቛ8Fc|u).jP>) ^␼Hs: Y=6rHI/jtܑ7`d:76Bw\jy) :k6cC+p]ADD36. IZ\.ᄸw~tZQ6sĘGt4opZL>+֪@>A!D83qӗ4fs©NF7o.MZ"%)Ln9I`C)$x'6|D,zKUJ.r@Lz[O,]p-KXD8JLvqro ;EyfDn;A7A6? .FMCjf: GI1\h-y~gZ80#=qfW#˒`}! Äf=5keo V#A `_RU_kZ}zT궙 oxЄ""Fjw1$[[Kċҡb1UD'Hp];:mAp>wSpᏛSAX&?#ku;R̳%KCq 1ݓ%U4EQPUiE܃XbSnc) Ue21??(X@ꎑg"C4oq`~G)fb-uggZ#E t)j!sla$~~=O .*g.0yk%k>*㍮Tg,l?)ci.`ͿkKcO-.PR{|nwjs}ޱ!vN>~eF? vW#pg {N\Tձt ɰۤv9O97=Ys980dh-|#@;TEYG*H\P;vjvPV!uZXiz*4P XLD9p-3z'J&-nCDvPBxo^űGush XH^+BbʕlQVyRaR9_ TU΁I =)4=\)>& UЧ~\5CCg[e"L},V`C]Io@ M&2sH]!aaClo{.AK4ZS 5"f+B!(v# >/]l[to=3J (1ȟo6,˵qJO0.d(%`̘=y@MQW]a[o!XK&5"ē.i:y1cr37"NSi}u۝S @$ɘT$_bj):^H(so1da/|@UdsniGbjz0Ln :%͗ &NY?K*o8`VHB@ǁc&V]s;0w!4 鉡dL""p X2):0˂bҢz?U+:~kYF<*r4e/b1| `а?knݩ,$ёV[2vJ1۵f\4r6XڱZ#eh4XD'Q竞#TAbl6NsgTyR厘Eۧ2[-o1cPJwmLx)f EBroa#j As9Xd!n g)>z͋`㭂'yAy|; * mEryo tj3uINxcm#&Ds:9uى, ?Md튊t@R}D}&KFA‚ D#?~(>ç}#eP_Ji.SZUWKi B}?*z@! iNx( X';R _K_P-$Tx!6kk}* f=ZE K,{(ǁHJ}C6ڎP"Q*S?AXP`BREsہrmIw "b4F0o}NCsjMr9:wlTmkX 3lZ@%2MU]]+ \r.b VwaAOv?SNBZٻLeTkAegoY̓T)sQt5UU:7@DOhMoO] xFQ*{*)25ᛦ D]?,j)P8ɄȬ'O7Ow̓7e+ikS.g$ W'1OybWs,kͷ җ`8j=NP(?"? s]#]Zo=_n)Q¯׮OKu ?y"X4]3Trl d>@+э r|&Ύd0OwJqmS)BwFmxH6"VM8Q9膹e~u- -kf! 3hLk̷粘R.!ɭ}4`uy>a>}a5Ɂieg=wQp=MP{Y]Yͤ/I~#\٣2 ^bWo z0h ܔ|U$H=zͻBfq-7 hr¤L;Y:sJ/u@+塤>;]D<'6NoA=ofjNPK0V&HjI>ǃ@i$ZA:P`lBwЪnlH}$[OX {[?3@*Wk F(g_d7S%vYYG_ 6;~B]ܭbϛ$́X![~ bY9($˴r!ŜX о4'UUH@q+ *xu{:!/ B&՘yѩp9"(E6_fb1Ñ4u7[)"hzF** ް5ͲΣWnG469ckx Jz\5#> jVz[2N{OnSݱ)H:7S\\IqiQ L/OFrRIGvro^(ezOx!0V-/ېBƏlKמMr9A6!JY΍,NV2$8u;N)eO>ڨYu|[ \ԇV@D+}ZKr+#CV40a 5}GQBrM?ZpU`c{юQǛY魡s8?+;O{v(){k-b'!-}\{,'8BMwަUmT}PTV_zہ%ӄZ'@Kg6.b>U!\Ztm<؜#'Oن~qnA3qkk)̾rڝmpA6}Pȱ;ˍ>32̙lfdn戡VJi"oP^eLXջ٢bQ(%@vz?0כЄkV%g=;#ZpC6~Jm0#|~Ky.I(ѸvmB7Vs)fݵ#2M͛FyRǮoAɧ#UB.=Hn4nu5M.8m҄:@m"{!Ϊou E&C<=W'Pv2Ct*^L*= %"`[=k5I XW^Kf.G1e"Z~cIbIM#Ԭ{fLƟO>yjͮ^c>\#`}06OvT6voR0*.X7ooDA'F90<~G8Xk;F^w7Y,KҔGAfr ?D|ó̃>?xSӊj.5r76ѧ o$5O*9`7] 1]f¯ I4q'Xl!BV._0V|c`A=.h܀U?+FYܹa/z-wQ [c͙Vb`u'<$n.dvUdG׬zQ:2iTDȇ :-cK;|}2=zxeA-%>iRꕴ4:ng TΥ >;5Q? #hqPx WyK>;N.U^(sŸ7ڡ0͆%:֒nQ٫x,Fb(7I|ӑuy*D /|،P\h^b7"tGTNjצIYQ@CkY Aq˖$-_D!FCI=ųV99BT͢j,RL[63]/<U@{ߏ?\]`s_|e20Mlo;.U;FvEv5 /0 | 9'#m͊O~7aO[}GEa߾^ Nt_Ę䟝}d;yZR(r6x-E<0-@ǰ|wE#{%$$i*&7#Tȝ *Py"E\@0UC3Tobmb\Geg$FFQcdLS4OqwߙLX??0EA.erᯖw~`+*mYEr8}NfTOo􈁦VUro5y4CB=-fǕlQ}09P O|Hĸ,9H:p}L&G#k~Z( )ZP)cb`<$AI&-ٙʥ깯 )`kP)4c~gFiAsnO.lMO^6XKp:h9;K,̯K)v=ikƑ鶿N(+UL:aC?~ 5FavZ5pϪ-%M $ºiEXe 5.LH` ˲#gҠV$uF+IXς#" {i*A#3iP.:jyNBȷQ_N;3 ̋mO{noHg"ys CmQB7@//-]Ƀk\kb"£3i8Za@f=˝]ItO2>LIqS7T(gfK@wo/PnJM.hCcC.y'+ԓXYɌo, wxl)C /)loI| 6W4T]>CH*BQng[?\쇻e(Öi~I3=w(7exOx@ ts~mjg~ "D]F1cm4nH^N^]C)J$6tC_,+.Lv-p!PƿoPszKOzQon(xд|2ݫU @VZA+VJl,g 0SrP .:Up!@vK*4OdB#n3RߘRu J3ho=>i2X(0NH7k^ vsREdB[ 0K+C:v^rV"o4nǶr<8@29{G+b&Ve58QCL!7@P)r`Hv+|K]iv1ꂖuHܺZ6^$C nenv:BbR1P"ͦ IaXzbH ]cѢ}%ue4x_}M)cb񆢷ᛛ=m2F +.j!x/ɒu`j% 3+ Rkh fUlk1JNξQ{N E8M)' }^#&<)+@t_ʻHӧMEfЏZ©ϋAVi8rL`j4zC׎(yӸc].rK5_Ge= oGH+ {,(w IDTssO|K4sEI+sH~uC01e>.{h-PT _ʦJeK۩xjאaahʏeykyfwa1A`|CR&4&iXvGC b[ h-g䯝^Ӟ(D{KMF}@&IW61' VZu˱u02heńbIJCw|D|Z &p_:6t`{Ǣ_]}kXR%~>DREPl'k|cEn̏8Us񼁅Yab& yGÑA0J+=qRjp9pr xslmb9q~bqaj Y GHU+~! OJ"i!@).B)j>Scl- ]7oNAC#5WXH"Ny[ˣ܏IkEp -6)YQZjldA9Y{cc.#wsUh H[ Jp ז"{# Wם_n/jPi7E֦ UՠK[ظ*f0#?>63'Ϻ=6PNx&j{&v|j:y 7tеD3zZe'{F<+S}L gh_}*1_.xc;>381n?EŖ 9GvLY`QjkWDvYX۞1MO>lUmIqRwv:@%O:[aˑ<9% +~P(.&nUά VLAE1xi)~UZ>m%V흹'sil(f>E1ujHQM)f]cXw׆0R5؇ ۔յ?2ش˿ O.?D x*hb'6)swk߿Yub6O|It9da3j 97a/KBzl댳u)v>QAVF \ n?Q&YJcUn=+8K">"ލ c- LjtA[,>12t^7̫{ \٧7h'&gCh=mM䒧$='9db0Ӎ*yQmEA7EFJH[QiҠ] |劆:@!h`ՏQއ*'$)dSB^P'?$SzOc\*?C`ߔg0J#L k nKY:dt0H mƳo?3c Z֌Rd Y@L C Kr0\Q5(*m1*!MpVe \gHJa3=*{!+v#K+J;:I կpV':7!zpX_GQѺ)1S>zੋr8揹/<:OHj.F*5b= u+$8g<[>UU¶/"Yys}$ȏ1F΍<r}O)jK[?p~̰%̚KkzfD :rwx r*əVasrFb{ ";-Euq5`HlYx7F&@oc/>E+DZ8B ཞ5Y㟪/7KJcIK)BDݱM!JÆwp&rއ״c n .!j\T 57gQ$oSHCr.j3h) O*Iµv 8 z,e20d\ !hȤ-y }?Ǣ2+B"ID2vJ(]F[>.2z'^G;^Wޏl3p{0ЪvFpvt|²<KJRFIJ@ϋC|7,j1ʉ@&%]?H`lVzFel/>Z;P#EyIf n1gү|Be^.8f{Mڼ F ,v; Z|/ bIfހPù',RG"DC>M , B;-t m+>%a_&Px`՛,%ϯU K_u/$'[0rz$%]|&=eJZ%>~NugrDMЎ )c>\0#|"}?䀹qSj/ZS@966!/5F ./ɦ,] K7smqZnu0g, SLŬ`'0?ߎP9GsUCm#cŲlwYJrTT4-i%.}]/5XR3tbP/ ޳¨9`uG|aCRN+(Er8tJfꭥw=ĉH0xyisvS:H춖٦iLH#CAzfXUQO mϩJa_r(mR>%'ղ."5MQi>W3枺_c]t5 Il'j@5|e=(HCH$R v*~b[ .GX kd612͡.,zw: "4LR5Hs<#v\(\$YLn!kBO*6@^SA)Pd:IBTY,zpDfUKDm޽gkݸ|;=hFb;uIU~ i cA֛SiLۉgytkK7DJ I3: J8GPJYaٞR6r{I Ԥ-o{OsV:Ih2 ew /硈ײ6$9ZL5K@6| 3$GF"6pDO%MSl}mߍv+Lm ;a*}0 x%W] /g ve9<:k}v''% R^ sv-J!=E?a0xx).[,8,ٔq#ʥ W$ra0Ȍؑ5$Bo? $uR_}ҫZvyE6*V~G|}ofZGXL`:H'!zF~3Q5[(_0\7ex!a tVSiYBmuS ;* 6V Dnѷ:v"- RAGZ]kTV~fC,n!P|CGҒR;+pqdGrC:>\?VVȓ 2u=^fbl^4;i{Z|uriKʷs0۾XyxWl$`˛7 D#^)脼ﬨr6q1WJմ&6X»C JHӌNƷx)`,'sǓrsÜr^e6])"a@wb"V1盢hwcx2t ۃeEl-0҅ʎ$foQMxۅr%|PV^H ;~k3SJ*NM#;fDFF!R\( ڗ u4.JOB k{=PTu&lq6F0rhHz46oPԧQX&̂O11Mtf0S\D,4O$EZr-m9udV(F߷-m#YdY9^L Fe u3!zk/34Hٯ H#Bi0cL6 RX,1M2~F_A~A ȧ/_ϴ2n7ߺ6Aħ nḶ3P2 ?2&~D2 \?F+1P(/x kC7DPqֶ&f1wQJ{R$ =SMGd )hȟڮȸb,eR^gM(pd>HO[`s-{NʊcOYr(gPj1qjP&4`[ 07WNIdh$7<]X {CqhӬ`wve Μl: *d&xק@:OX}2yM87 jUcM [+7Jx.țփeJZ x7ZDU~ҙ' SMт`R1?r0*,z5fZ6MMPΦ&>gH1u!ځm PGq:}٪oqmE$~N!e[*[NKVv AaHG3WFS6S֝>z걬mx;q&45? YN@ !d{Jx0Vm!ႜI6 fLY=uo3@mv kIOASc?6 ǠKFӠ*Y]P%D2GNEx01nkemPOT!D\EͬȭdFf)߇trG]bQwoƧje9r1Y[-1u.i(Ғ^Yi2?dgoA?r'.:h~a7[.C h c{eF+n ?{2IsfՊ>sq2{^Fv5S-0ID`ӳkL$UW~\>#jFZZ>Odb-'Xrmvǡj6Qzo QaFKǡ WA^uuW14Q@$B@I58OA3-4Y]Kp7Q1>SKJ갖e>AR$ĪX#[N$2Gk5>|+I#}636.1rw˻5!ڭĂRT4._'<_OLLY'ΐvHs4ȪR?Ʉ\IM awGgZ v?<du`sj9qVȭx34) r壶 nw@xIp8DR ցNnDxgp xexkT%I=n2Fzt<8"'r,PʪKe*_r6 k޷Zڿ eq2[Ul)dخ$q0LDE#,G+I_cg1/7d& 8ESDCq˹H{rg̜vr^ n%iOy$:|W l%"4A.Kh$ttWxS4C?kL|NʪрeY/\ᩯTW(?}n<[ON#*sm+e&pRu{M i!|Ҋ9llFGua|ȅ\F~~ q=Nb*V.J9hyQk; 0tN#q*L`An^gWI9}?Ui,Ɠ71:β1=Khvo7ZJ}Aj:Ŏ S†Scрx %ȥͭNi>&KB۷J׺/m @kMr!t6s7A=z F]\"gDN2ίS&[+s-p:r1U62bA26&AMKM]=~0qlr܏0"A\TQ9%ͥC(4Fr{]D-ub%'8EeOgR B8ǏBjz#o +5lSWڏŬ]0 *<0R{G̑-b*j/o6CDt4ށ"Q3t?88 %V1,Uw'D=3wn(L^{"ZrU=%"DNekv[ћ[Ś+OALv>0X8< Ő,tX-> YͭTFqs @yجl>*y  7hqְt BL)Qy~UtŁpqc g xt=M!sL^r 0oeqqB^)KCSp*=o6dI>"tådϫ- n9LCz}r-rIc}tӠp\܎D&F{ JJ>X.R(A ƚyW.c.SYlξ2 ScCe.0;_' ټ!yυŪ^KŹ׉%6[~&(71ez/%Rˍ5EE.^5 (V@K/ KNRHAI =_`vkI9ƪ{^)♈ԷP*i-!觭X( e8xGw-P0?8w0|`xֿ!:)>h|NFKjqR~Ay;kwG gxg@x_mHbI`VƑ?-bƈ=X#IN*'BBauEIM>5MR6^1r׼GC{g:ȋ "vc*X}FΫ儥p)< ^m66zk߲Ж)^*[Xɡ+)4_KP2oH y# [ۋkW9. #cVS\lU- ɣ!.SIjOғX`M?E<6zd;\ $X5'=z~c:pzBi.s,ib gՈV,ٸ&=uYvSO7c{:=JE3h%hP+F 6jP>]p@#RMY]:ym'30#kM:N.,Z+U,o_z%ِWL*R@r*hc6jhɔDH5q}NcQ'axX ؂<혋1AUa88Ŷn'ԍz%Kؔ؄fO!U\6xs%D?Fm1koNjBq{G5_,aGqN; LMR>JҌ!& 7 A*,Zּ2jGsqWb ܚW,KAk{Q{R" N,zvbOo%]sŋaYb(CWj@Cgf*T\14s?H3m^[.0ꃸoE5ۋ}1xv57ɼpWU( dS\ؽV>M+qSgFJoYM>ȿ.بk15a1O93{Y>՛R+wFEr[2V%F,(WgkP`v3L]8\#fzeVX4G{rHf7D6x1GcxnB( )lz*R!J:1ڑ[[a$duq#Y{n:B(e3 l̲?8 ./D:]=KS|"̮WKH͖k5°a#e?9IG!&9yP?z锲nմ 曃2ԝq[.M{IWK'Mxj\wTd/iQ )l^~ |޴4P7uz3ǵ%2(dY7 ϻ~O3`V1 a(Qa$+PmۍI SLl%zxM}{&|RK( Ԉi}[MB =ѐ~5 QK)EŀO,q򎆫ۙT{}_ٴӂWrML3d4{U"v3@Uis2- VmG ڊY;)~G{c_ց͓Og$"ˎ{8 ,%Ax : SB̅ajXO3EW!ū\=H 4ôWƐ25;3XFQLTٚS̐POHpjmoRS:S-(0Z?&V-4B} פ B &qP \# n_buޱa[Wތ^ưv!{v :՞)r1j) pD֥T1;LR?XsMTIh}Fih΍"PFȺ;")!D( 󇶣hErK E#z0o2v#V|oVA-Ϗ@+r18[oz4;$k6>}>dĀ࠼!֜%%3Ԩ{~'VP 42GmJf4YG=/uJG܍5ێP~KHH_渣z钮!:rOGjΤ]uP A2=;y`lwșNAΪ e$s9!+l$/)FOI4ľ}`Pt F=gQX[O q;\F顢~1APn6p\wCbIK[`oC2,Pb_iHNF5>BjO8nzw`\1|QF=nT{k8%1 oH%7q*]^&dG0)`Uj7 bq{_+S~)i\=I%0 j8;kI8 }>сV`\WUP SmM0R2 JxCVVvE>ӽ^I0'Y(YNDOUPica>59z^ԬVROC0X:ӥjehʧ !#ӥ`-BC[&q.*ˇz ]CUtg^TFy xD ?fa6'rc%|߄fAr24Ƽ*|@I8{۳TAc"I$q6x@ɗh(W޻xjxqS\ t'R.95&C!哑k$9%1" a_7ZhJ *FZ3U8tZ,$ASpIOtZǣˆYPEHD7O6ki0ŧ^v;GR1joI5Jܜq`G{nDog[h gjJ&_wпS+ 6K qMD܎RxGu2vG5ߌ\!%Y 4s[G@J6HxѸAͩ?HZ? vV4mGEUׂνWqDUQ}:>,cM"H|bWk%eXƎx]/@NڐkV={k-XlF.=@ V_^\ sasu)4MvJiNXGKx`TKiE5o*A \@k:؀6aKY9+R#Re:لɇ9h7X"qQ+t[j-kzGŴ5}5~k>4-'SKQqOUm%mGd%iǹJπT? \&Ǻ 1۵Űns:$, ZZl"BG00ᝦQrcKy&KZt]ܰtK@53 oepeH6$" ȹ; cqLWXs; $lqh;K{C[!%=<,jn#Ѷ,@ +mG%rKR >|h ŬCW Oީ&끀B_[6@'YZMゝ 2+ T|&Q"2^.ya`B^c)FҢ͡'-1uUG 诊ZHw07b:$ڻ?ԗ" Li;Zy%@\\ITҔEFfsc+x%' Hrn*-C 9^*`Gõ?{:S|:xzE:x>217O 9!sCZi]`a0 rWE \—4TnϞ eUUe0 fٿT\öoaoB_u|6KްLU> /r@զ.VbВ e 0R1i}}"_[r`Ҁld_4pmujI'}N\* ftyGQպz*َ.> :Ȓw=S ]gпҕCa|'fT-[r*s`&Sl)G-!cBX4 M+Rh>݌gt+QKL3S$ ֱ))ӝLGεh~0եw8*õ.l&pSJlye_4/7}Y71ê"^^T0twv~#\'4Vc]2!\Ċ Ǜ)& Khvpg',tQgFP,鑿 vڒX *1LbZz*6Ǯ[YQy$3XLho vAQ*4q4K?deQGW{ac!PJ_1mk~Ә;(ۑ8N,g (n[j'V;Nת6=%' nFMS;@;WbHwfnDɶ(pMJS셏]>~}MᕤVLj8^:*;_YKc|K[mlnO}V˅slY ʙei׬+[v+ (hkbe">eZ'nP\ep ?PЌ-6VYhӿ-L(ۄb yrWBpɾ=Fޝb|cp>B"XhpY|/z2M*kj"Q3yڷXhڦn&h'O/>6I2ﬣ?X{^DR>鞿uߤgӫ?p ,G^x9w2Mjh9,Q(1hcNJ5v`6">pLsW¼* 3 +0 7h"MksArE6Lf-O>^c|lF)KiI{i+ھo4RݮG@kax<%i&pzꀏYdʔe]HZ9FTg\iɕu*4z)uݡ ^DUΝ_UDҫe O8o )6UG׀Z]L|p Gyus$Pn^- ɨGR kЊ8R4zOW:c=H9&ad[yg0ƒB-sg??;% ,ϖ䮮Ҏ::/Pvak4IV0R{pa rxa é؝pu0-4w/bϱTSv9̂莖7"Bjer~t[@v*ه]Kɻ\f:k3>]h'9]Z]6p6Q.-*B` ΞSP-}j:T^I¾vja^+kUSI ԯiSYdAx uuײ(c"dx=*rhWv >σu4= z4 d-:=rH16nma**87vHOVlBmR+3_qɞ^DUeފ;a9J*W4T8iV<3~XQhc4"wG40ٵXl*BvyltF\KCI4 0YSa{(S|Q72 ֗ӷmS 'M##Q7<5P2BjPGfoػ|l_Z ?AF[3Hyd}V8$ob-hzdU'mQ$Yczt3OO}(.ҤsVɔХ1xCys.1r39}`mz#zW? J7!~r׌EX"3徵Pw5ٿ*&^T]n1+҂I/ > M,ؾCJ!.],gY>!9?\`XW%Q0edgaܛ2c` 7ٸ|#Ȥq"5VP7 : GIoHeA$a0k LNgΆ(-Od'wݬLj$'*F[*:Pٹ's+rDtыRpAʋ'X:]զ?t#d/qIE+fx%lМI&{LmAoYvAꈛINzj5 mt~[_Q85q%ߺ0)+ͰnM+2dV)d%49RM  I{߆$ܻ~X[C"çQ>pl!nS hJ\^úJݴ9:/ D NhitR}x*N:ؖ!)avLӃ+`ޥV:`]SD#σ7#Ģ~e_߭3 }@Uݺ/,CU 7 Qzy7&6Nvh9Ec[O*ɹ33-}'>)S,Ȅ>}GaR3X8e y7yAle|RCf`Actk&FM 9Y2 7D_xO|v sUC;BzOi mOU1.-h`9_%눥&3]QѹG~F/e" ,Vhu}ut=ɠ6[.ߊ=*lDvӗ9%9[$_:&|' ymρ8s!1]Zb]Z~1d:׌5mc1z:?Ca#c2J0ά < p fZxYXPAmg4ISZCLN}h*SQu8zayT İ:XKxA1b*4}$+^:,fDgO=f@2ښIl ?7hV-TEaL=R|ƓYUBeM̔]@Jxأ^n"3X1̱ANҍ1}EՏsא j/v4B i3 fVpwOQLOSe0I @|G7u#ѽ+""yqi'g[dF:J pɊz*b@x5塈=qfLc jP +h}k*lyH2\#&,QJaN}?1髜֚a$H&ӊ6Æm=f%nI[E[xhso "&(ZUqoӷ$/K#L@A7`?>vZ5 |])i!}4Ӭ4҅m\ zy).Hvԯ[5?@hR Q#jin iJ_Q^h9͎S^ӐAJiŁt 0MwD-9Ͻ6UkTT2j gݷO6Jk ]@W"$f Q2fc'-C]pآB˚,EɄx0r]mn_nTzA,g8X@0Zު:)q1A&VR@E$HM2h3Ae")SuI;DUC3A S-BK3yNȸ L$ ^T+ p\ ^"S[DX$:H?`!6:^@ Uzfbw!fFb좡=u?vU{9-;PN YTv20imaTw:KW\Fso5vbcFB?룋@;xXZwMpa՜8I#/.n;odM-$b ꜘ@l|}[7(^L-_r"qS;|+E%#+fjs$4Z\gSR5{y te-SScX=V*w+R~*P,X&chI D[H qax3ǫ}ᾎw52p?oO!N?f٪iYZl{8.(!wdۥFL|)-4Lȑij3ԝnYR)tpwzpOGM@ ,HT˧XE꺇ADBL}?K;٠GLLrtјh[evJނ䖯$w)cNkاWrG@ӄP=w7,.Jb4qi g*ZƏ!H(= אNF]>xv+؁0Fo[ ŷ)hھM%}-7B22 ,h/N%V܆p~ARôꡄt:˅ANF]U)&ę,,=X36K`c kBƕ@ ݁rܺ5SM5I!emh>}JV'\:<}z Wb?1 X]ӣ(j23>f!a.36u9r*muxfnZk %RpJ4Q55*G DdV,fQ0sB1q)~Qyq;/A'RCӪ_`u35>sk=0JFkD˸(@\R6xJ1&!#+Ӆ4ߝ7P{ᶜM֕_xQP^o'oO-NC\BڒYsft f?a+aYml{L<7ۢ(vwkVʸ3sT7eWOKhsd0'!3,:\zۆ S0LF䫹U$ ֍Ecg[LQؤ~x${#\|fQ+ˣ\}eW H[ߡڧ3sd*VH|qHcHVfbbDY(j :U`Ks >|s(J@\ֳm-&VŽʄ\.U;%x&PɋFo^&8~]еE`yD|=l,g Yv MGjGwʘ[49F`Vfzݎg&a8Op6NvFpQV~O1Ȯ EbQ |NZ&PC3@.VeW Lv8zР#ՄAGɈR]PR}K1hDiӳ.z@J\ϏʍU#DQp.!OVVQ kN0$tB_b pEnʹF &K6Emҡa=UL4Wl24heE`r@{d+W%:S2OJKݕˣ!G~Hhfˀ,=|sy K-Rs_DT|AȑؕNWH1Qٷ ¶\rnDwؓ7X~{*$dG#G$~g {RK=쁨mD<cO'Ğ߅~}W\ X)c)BQ )jd4~F  ޥNiXd:(# K2<Жb'LsOsǙϦRR 7!$l"%hCXyGEѠ=j ʀn*Z2sb;n*_Ʃjm<v)NƗG+tp}Wp)7~$)OK9ddˍ?J@f~ו17CqRͤ /ͬo[U-&T}9A:W挨T' \x5泘;O5%X Oࠖ.7 iyn7At΂4}EuoMNeto$7GG]yHxF:Dz}JwģB>M", Ez^[O粮sZp߁:wW`wwt/R֓&J1pgt?4ZC T e@hw#aj%w|m b,0E*)λ}#-7;3b8ةT~aQ?xt,34o/:-66866rH~0i5AJbV%Z_zHŁ3ԏBzC?4{J茐PSXSd}TB\%=*=9h?5tўS| m4f2HI4zAmՔ_GcI֢U<~uֹ59?_ z tz 3Ns٥꩕0ٔ[CHzw As=+q$80oiFɚ Ǣ㯵|c?Hu%X΢ȻК ~?#\=kkX^[m'YO3WC/MrxY*s4ߚK-AMKު.gH8-C,5>Q)p@4[ (r{(VGaKz j䙅CZw1]8Zdq&IQ "#+F+K/y"\#Tc٘Ob4K'ُTR zfv!d.P&%| ZiOUHcë3NA &K8,`8[$*5ZrsߎEŤRzyCXQRib,~1ilE"AN\h ^V`fZ:Vd s$ ^0jG-#[͵BeӓTY骙q,_(/NtK=zۤJ:KyN΍N>4+I-|*L)h(RFPʩ|n4O:#ƏC8BBםso{`'a\&&'ac B N^6|k9cqdH|mg|gCh3Mye{SrFV_.OB$󣵳g&2`$cR=?C9];|iF&| :"S02;16&lْo}~cHE:WǷ_nQ2a{^{y*ǖsD_zZ|&-VVD'"f3fm F neL)e6 ׷xdTgZ~M5R?Vclq*t3,YX~8 iŭӝb{Jn|/jP,d?{*%? U UA;v\퓸GLX7w rWmkټrpb035[P ZxPʡ?gD!Ct7m*) uV&@U|v,jk, `M6Zt/{+pq1kL~ϱSYqG&#lA3A6Zc!;ˠmF.`ӣ|:8!E<\5; TÌE 385$>)޹twsy-<3_@cH"+I]rbD9%{,ejg9orwLݽ8HS-jvFt,)hPc*uΑc]g .O^nQxDu~4Njf54FGl9b ("HIhfO@U ߶ U(kD+0x[KɃ $̪:dy Tzz)ci,ȮCLa\1,nc_dpٚfOn3&^R|p[d*/Z~^2 !ا ?Z1Xp vaG}O]zԪvC: ji& fI@흟ʈOgRi7g8t7~F1"*5] ޒbOW.T;FGe cĕEX )4 _ZT?>؋Ϭ aM[&8!'l4oˀye#C&f!X^$l~s-Ϛ9"r+è L~:6a 䣾A+)P;Q&D$MoI"pzf=?p-^9OW1֕bzt7Q TĞ1i3to.8א 1 ~UXuΕbaBqǿD[68_?ʹ;t8n Iz?WUU[1Y7 Pˆ%+- 4GR*;U \M,a.ٔ`q! J'MjZc(nwt/RLa7, Zti!f%83_0h[QDgK>$r0%z-+_q7.xc~x̜3-2-'TRn0+* ؈ I>:["-:xzVa;N$-qKmnP"n}v#D(DhtoR $hGjrgY d$_'ψW{yh!Wtwwɯ -UpO_<ѐEMof +:]4L ĵƋ7`|,;DD  OZC >E:XG_- b GK*LEo?&7}A":^@nb4I#]p†&)NyVO͠k {+e:#}ĮI1V#&\Mqfg6@t7cO+L 7q"Qf)nF)|r&vDUz}ꊠlg* q^&a/xK=VV~?uC彫+/іF"ʨȏzʪnYU-S-js,"x'jTt!rs3OnN}vӞK8Ybw84@%¿s{7Mv*4@1\0m\ )*l9GN`+Q/4jѻ⾦s'4;IwCWZ4EG*:wDi0=0OuRR+dm=ƺX5ޘ:Ie3x )G}'tWfX ^>Zzp5WJ0N -Al95)].yG3[>y @~`|8#G)=4stGґFj!m )6?'w܈&sJHX4qz,}3[Ά t6i 8a%,oo$I,Tbh_c~ҏeZ}^!(2k,yA nLgg)C24CG^1UrIfC&4!G$x. o AW/#l.SuB^ q؁ WZ/pMWOaŔ\) oon":=9I0vHH 2!8 wat4Zk<[3jnvCWR12c?č&Y@kN&@!J%3"\Ip8yc Fᦹ*Bx%V坵M:ӬUA Ņ\R(hQU9Ȣ?p,N+ ` U{ -m#8萛o=56V+?d^\JW7"[!>IWwV%kjXx/$)MhIM#@h<$iҖ_o-zm<=EwCztBd$| 6Nf~nyP(tQ|lD@-9ٖz띿kilA/r _e MwXF$r :jsw6(EF"e%t/2ڊ`tz1!fpxBU#Β*Y :/8R \'$3YI7hp{,k`Ip8HXY]Ud`p^eLi(7ß~NWbZ~7H͆|&:DmJU;#~hhopBsPs)VV3 1;5ddLQ \tր0j>HK P"tʯy$.6rg6k<XtTIgIg͏el__m,y # 9*L c]8q~f{8O<"qk0Tc $DE @mz0>/*H=lU}Ī*&CQW%ܗOüIOF2Qӄu^N <#FA՜v;:T: '52qo te#@*0nl>س$52RzRh$*>( IckJs׾KbR|!L re߁/ T7pMAav'Z~$[ s=:h"3LsJb +b.;jIH~TfwB{h2Xr}BD6YV lݳ j_U9)u4zs:Di Z #iMn09b)l`CqE{=J̦z*3 ^k3Eq.+Pn}m;дYj+# os3)H54[SB:,wa8e)j`LD;C4ke2}67@\a܏y*L\NvW^Ζn6#i} [)]=M.EG `u@vk4Þ!8:q ewC wd_{pDVLm,0 nJᴟ%,=o}_`[բw0s>rO'[8rFelQW+^Wx\y$hD{KV<7x׵FlJ9ס-yy+:)2ֹ6oA^56zIGhX36Zn@Ƚa-vEˆ)&XOG%,HX<zL*>%2ur R jqf6 J1eAW+Ϲ4NK Ӥ,ySavD`U-"22,Uʰg5Dۊ) uf &2i)^v|)kR(I?qJ{2uĤ@ddO_լwFGPc:lRJ6zc~Rs۰F񻐂Ԍr0׎dz eamP }ӌt=Ʒ#;A-A[A0]~ޏ,7q01!iPaVw <_VU@:4Şēs߯w# Pw}cӵ얹qj>DʹNB%TxG$>lɓ/4X 'j Z13F%enm }b;x$*3轨umAPt"nP:cb[N |)M(5o4m h1޲=g1aYD'H=h kQ!CGmٽE%+pBm>]fqErx)$&|?˳Arcbe7<ՙ5?57"@:=y@S[`qu> 3WU. ̂Hѓ2|r # ߷AX %VZ_So4 Io^(V1ODzRo1t΍”U ْARAƖ%cOF zxVv9+=_ŬI܉П%-(/90K$C(JZr;c{1e֡S"עic^I^ZLh.@b?,eO%)Dw`Aq'K|aj5bOvqh7IܴwK|_G1!~ بܠ䜑J;}y̮KU$pu&9?# ԫ*\EypuP8սgWƒU E^ `yyk `-Rcu‚Зo ];ssgOsKrORp6UW ąJ4u)o^5TQ.W֌@x鎇9gIfgK\~5Ǿ| )i!6uuY*Zkq CП9?7YH*M ӞBK 6@{ ^Zt* bJ]oIen] ]m/( W҃PFb"!zS;2gtoc79rAU<$j^D7Bƛ*v71,:;5B+%59xi+^;J#0=:ˢWѦ?LrvoåY̐t C8A}s]KNѶ;t+{Dypԧ&5oy_ QIWiwf}/hx _ؓjHJ5OIDKJ͓ f ԭг[JJJYLQٓJ~qyis{\sfgSh74pʢsU}9{1c򨹤ԁ2e: A%1XB@ JۏR6){!z߬ _4PbD,%&V #] "VĽk=A0u.zmb]/hJ07{K3G θw]A72r#?N^o&&K-wߤ=uM]Paf [`WNZ|k%y:9{E?9͉}ynv>ME!xsk~AsgFZAk ~@FIYʭ8jO8;[F,J թqIoQ` zxF *LO졃MA X*V"SՏ#nIIIpMkע,ٯm'R!ycigӑyi>US!y~՛ۦ~F4&Rj~­sЦHc$?⺲|\o:cѩbnk[mUzRS=wDNmJ6D4&,֨o1''„8àc?-=5.kx<ؼELߪk 6j;H~WpKd8A蔔J~ʚ;[nJ8r>f9? ~{K ?z9O'w&;ZS_geî7JOILsy3R+W4&EfW OU0䋋N`yjBAf$uh"|;zLj5l3ǩnKP;)Q#oNY0<$>jn* KM|yY}z$;X.ah}\y(P z̑ l57oIN.1cN0dM m7Q|jm܆0C|*,97ό`2qmSX<*hfԡGNG"N:A+)? wR.߮KeW&2p9Rz7je!ϵFp'{hRi}?Er =l̪ P(F&Ҋ%Jh)37MT{D|NW,`V Rj(Ym~qlgY*NV; @/HQ;" }8ں|o!hoHloE/G־T ˚{jVHZxkcpRtrjrPe vs}U0X(yxNv֬Opь72sŗRvve&3Ehh"4AiI0b<|YLpc\$XE`KYqJ@Ip +v4F;η^[1dSS-z`&mҘf(thD~s%k3+2ioԒ\VTмiPYϷ\zE=Ժ 0 2i:G׍.62kO*% ; utXۇClSY5pv'vPK^>G@khuGL JRo&?/՞}yzZEFz6CA ]$6C0'W[j2T`fdX iۂ,ZTHgxMg\>&Id|tB4"j5<m䮳 QOkpE OGs-˸%u%rɢ)O0$[ׂI%f=6 ]ܙ= wL8WkΟՔ+1 ˖XᡧGt_"IUsT꽒!g 8f({ ٴ%zN8X+>IƯ;#Ы%׸Z.iO@FL1}(}$_v %1xebnɝAy(tK+SBS!2 ] ^. EwK'` u{94@պ^b;]a!MΔt;_ڒɾ!:Y3EI0*; UWfқetNm~t$*cWtw5wxxy]f/+6y~}Ҟb shBؚsГ/ [}oFOHVxح_9kqK@bTM bQD; N̦ )&3ϗU (5?'鷞G~@ot7-1WDJ]OO%1sb`Zy{mVNW>f=b KP*R ؘJ <D4ÑPK}<fuڋ(SFby[uc# e,Vw3XG>)` 쭽_cA_VX'Y#0E!22ydxvK﷥oM|*m$kA9Dҋ~5Â0{-~Sj+2hӾpqŌ{ٜ=F@yNnk I(mH„RJǀ)<)|!}3=OeV=Mw}Mc1Dt^oEpejBA>|wĉ=\K0e;6Nx :0j90Ao2_%"έ@JUkd#UvlkI-+뤼cz<m"=F\'~t` @=Fmh;+Y%v]>"Xdz؍][OhҸa"či@ pdûCęj0siOhAcE9a *I>dqp*Of÷ER0P Lfk3?ȲWyI@)?'>pL(cqyvnkVmch7Tuб3gNZ! J&$O:6\׾ߊt2$/Ir:+ EE.@F@0!$V2aV~LJ/& 6״%ϭZ}s$&OȤÏ/z]gq&)y*ͯIzlm=Kߩ*UgT:kJB_@ br*un=-x$\,ٱۤLR>ׄQKKt :pI-J s QNc.ܻ@ƹ1UAsUø|7%3DC ?э\@dj@w4RQsټv{+%F܈q$,4Xc}1T\8h)5h,˘GhOgSM,ɚ?8r~40sa,8|/Zvp M8JH_غ2| =GGI+x$JFC&]>H $imOkl-v8 u|-4'Ze:~F A i(Y*HCD!K5R=tٲLgy RC4O_ 0vj?2ĈnGia`3xXnnٷfNz`낌e JKbҞ-u?T%tz[+W&   d&(vt^ [Tn/g.'*eTO>L7iԩxc;Kflloġd ) Yo'o .ewyg%Kqnu"H3'G~b=Fb72PuPj$qbK V;dl9W&E{ pЏz;iT*_cHG<~%@c ^>5_mcf97r H{;C*F0#/H",Rq`Rg6CiNP5;!bm |absZK8ʎڜ8}^("r]˨HW0_=u.;u &^V}G%!V1c2 cFw?S([ A2#4X疶@(lu&eme8ׄ{&Ɔ1<nDk!,*Tm]xnssJ!vہ5 k߰ci[fC6t?ho^ c acwUFTaI&{=q]=$o/o0PslUf5=rIݥ} IKTͪqXu?_rgeXGdasHG3 q-JOrr&B0arRҌ 2w7BtƧ_K @Q ,UuuRy8]R˯Xh3o®OKCmCA:Vw:ux4# #WHyMO"esӲZH]{oe û*0Q>)k(B\ -A# U"n@Dr3ǛeEL/m/_KAaun?߯fUm֐LyR(xEf N"s-i0(ùj{ gT~&#Kt'=Onnsm՞Xk vbwqH k舤AaRV&iޯmf-J#9b1ZK4 ZuMLq* Sr@ZW+$۱^ C4k;ϩn  q~ u y!SZǟq9h]{ǽ_FcVL -; S}ECkڽ$!IWz.ڣC-7I8AcJRiK"r ؎I0<.8dXU<ܦQh%b6hcTPؓ0YHn@ވ;<~-i[DVQbfO9I)[)r&@ؗ. u_[/0HZ6|:hqDs?`-Rmgk򉒭8$w,} “4 PB'/e ?lqI$S =[Aa KFb&wlB&[sB=k/ދ5cskC%bpͼ_sptu, 9 v\Ne#pp4Y?(g ,I]f(B;cO!yVb~ Rrcwk{r4saV RfPq[V)@*ﭡV6^ȟ)m`q N |S2w'IoᰟH#0kd8fv0MyG3IK4%k$0>a^a a (rUӓM0PqSc?JAP e.YddoYQ*āĖWLs=%IQ@唧Gu)W0ȢK3I-Q{A>vKjbEWWmZq>CNϽ+8¬D4ژ=dLT4sS w)zN Joर+{UAFKzNY4iTC*+zAhFŏY~x+Ȋ<`lJ;Hh2ܱp>f[lN9S{ ;_* QU( @\d؃"Txyiek9""^Ez1^(o=ਨ&Yo8BNjD[lpKgoZ3UYEebY0 zѡ-;j 7C O04= AHMMXHc7+Jk9 ztL'/Q'c2^-ZiJ4; jACНֿh{M% w`A9ފRL-٬AA(C+*rLa/dZ`N?K@U%y`q뫓|_I_e#9""+/Eϔ,MrSef!XP ²@ -D>JJ:U5 ñ-N<,V3,Uf9ϖ㇑yLyXH/Z(dA䅇(YEJ6VC Eox9!Docb2<):)^&tNMU\\10(Z`N'=@:`IU-s}=,(brU`|7F<쿻ݳD[WtdC-Փ*'m%5CY z<$cw{ A.z`"Lq)ýYcL  F_|ګQIByYYS{oµI ,(p .O_N{zq!eJ[^N5"PŶyљ@e=g8 OF -2d~E?cq%\V'w<:$s.Ul72}|~* L%YTn=DI#6YQÅJYYY2z4nq6T̿In>' ,ˡ q2L$+"r2VZθG4&wBˏ(QY ų ϙڂUMX|EO)Ѓ|K[٘pX+O1WV-.WBWU-lP ĈHRR)WMv-}q~Gh'61j\"Eؕ2:ȉ5֧ɚGϥ.D@HnyeLTVz%%NޞeQJ;6|&ÈDp=F, .۴TF©0S_ջL5yaͯqdzQJojP+lZdē; PWqidF 犏^߿kT,Ϯ-)Wk'f:\egi3dm"&tT+wgʝ+G'!~;aB./[L4F&~/ւŤE–k`n"8Yr ] Goj]Otj-z5u]\#8XZRA ;.4`/ϨqCpBf]3U]-aΟUFih3QM/IoD։Midnc%SWAitx`qMZ^ Cf:Gv|$Rk~{+Z i a}%+pi S$ܩ(C984=v szieWQ3j T26BΕ<>Ḭz'TyӅgGYpx1;gWH-*/۳93W0@.tVV9 I *^De\y6I5αk[)fj>Q͉߭ sȋm~rN6'H>=eA|pR$)saR ;#+^c`,žںH&X;d(hw 44&_xA<]kfAe#u㒐k[ܹ|+ sjo6AݢJ + Y낸aBol !f}ddhvLqˡH'Z>č[&PErn!5ScڗTD3rl-<~iH$*+-@Y/<'D)uw_)ox+Em$sD id" +qgVWZO$0$U/̤oaK~Ȅii ejvF%žSߵ32KO=i7>Q)neh״+C=he]6]1~ՍȍCDe7'fv GSIA6D(fMoW@3ٮXY*P4(AFAɠ׍.&rL2he}IFtoe7n6Ӆiq޷8P؁sس7DeҪjbߘ}M @9` ƹu5cz&zOkT#BK7%ݐ6̓z~Źp 3ĠSbY06Ǟ8=Ǚ+u=RaC>f}i.ze{qVR#|[楅S')ɢ_IÙ ,b&HCs_h &0=u8M_;3\Eu (h:%qO ]^,f>>$x}7togD8V3b_[a# k6RnG`P|x)0_jtljo_j3Z O1V9h1G<}>4\{pJ> v )Ԃ!]IPX^?qH51d7K;+/ه{/٠SnJM2!tΤ`tV+6.m_WH$stz 0,~!t H`-tN1K|&}E?U,r޲λoG;VxϵU'fv;x w{IքM^y/H %=gݐ5/UI ȕQ}^YکTp6cE@ O#iMT JBʵtz&[IMjnmPDk 8(vusR2 ĘloW"0;|1!l1jk I#o5БV$]=uC!/hb/R|ʘyiᓔIŸ`Ԟ{2W6 'ǝ*R6ݎ ݓ.] 5 ifmȒ=nS nI )cYl(wv.qG| 6.@ۻKZr²8]vb*o=%D'y5p\CΙ !2)"Syd<<,`]v>sWܴptoDmYfyAq=^IH,?j"BIR/] kT4f( ٴ๨QRAߓsU86"ds" ANy}r'MiRyoNTXn7޳]5×-˟-;Zف}d߫?׋zM?_,4#k`0URHF-z16g D6N^q/voL 9m]@徇_XX邺,zk L61.MY&0ϴ{`Gؙ7˨OwqO~ȷ(t,k6[bqdS#G9>\EkY)C=TlnEa"qFRGGuwǼm)cz}gnXg#RҬgU+(R$ɇ&D]5g~JW+8#{vqߓW] =kԞe,6U0S?k»gq2[pF-6o*+y}b:ts"_ڐuhڠ׉ж'݉0sKhQl'_Wxxo[-!$U[$ѰZaR"?Fx*l[{ch/U_#HiB;=Ms^mb֡^z6 ?Б>䐺#a]YW m`f KMKeX}›JlZqȈYq٠\Rm8'4$Q[K=$զb ^f p8t I28yN3-!=vzQ.A3\r&ăV&\5RC)c[+>%2),tB38=QT8nZ؍[26T.+zM6zsBwвm m.hpL9̋.X, 4Vڞ M >rH99 #R窑 uvP1ϐHK"/ f Ld+0E\gYLdy/)tC jms|AMUA\|/'jH&f4 Uh2$}m津[LǗsȄhNr vC-VP_Osdl144"͆.er䍎cbIjht'윜א)4-m j2Ѝ ^k=@f?y1b1<ɩNY <`yט ~Kჲ5%J6Av0P31 <}=q7.`8{hRˎSG|-RtNӕtp>q^)\IV]$>3q ;Zs ʢONd ޺[N*78؁[3|Zi@ڑa#4T J2M]I b03FPut쮋H0$H}=az{ƙ(8f]VA{Ŋ>a_9N V`ZDg0햆Xiu)XGmc: 7e\? G8QJ6H?쩐2%= S@'Tgn\p()^TiҮD;O~ 53@GԤڤ:{UP u=p;ɷl+15e( w1Ʋi'O $ = u&6-7Yw*QsWNw# `}h_nD0ו%stO0ઈD_gq>t!>EcBCv (^;PS!zx& qS꺥*p:ܵN;RKD.ȐQ8@~/ɦ"[p opgQ;ˁ^@6)|F@Za42pp|Df& KG옏zO] UeFrHDϑ1iV骮o#cm_iTQzb _X <9Z0\;2I*ZKU7Zi߰zRU2m mYGo4D }&1X,Uw&f#4pS_DJEGnjhJ6K6c}`T "p?oIc 2<"}qbqÃ1[%kpOq A!3™Aatn6r5@/KwI.R-~Vu3nxwR uEf~~3Hj"Ծq2㦯iGlY>$rց'*#|mdqPKw0<[Ÿ#c u=̍Sccg$ƾL~DžJ-:`Ps1(A6 {/OWKg 4\Y>pvTߞXohdf9I9;I DSߵBPm+#ґOjoMSoK*+l%dxҡ)b/ej Z9k{TZyvAVy 3X`QTsw/8qyh<~qvQ"f ?Z TǝS_H=Kp= eUaU'!Nχ Z}M_f+@R((a%G`(ѨX_Mʃϋ]!vw jN~kOoYSń|;'0o,l{~5*XP2v*W7&r)ˬtOK`uH6w<ם_mEDwRa׭ZSmFkٞa!puvs/~suahW~-g߳:͏}a᳣_N3 lG^gwzaڈ28n[dE( kX!DzZ5R9ŵKi% Xpz-)[ XW/#C;v*I[C*8V֫)G=75!n({uņ}WŅҜ^Њ|qMjnٽ$,[sid$Amɝh!WðM$q1T J%']a>Ty=u12vGxn@5}˽_sqC55S`[*N؍7'\ǰ<]^tjQ2-Z%u@72=+c,ec(EۂA&Nݳ(0B`/$գKԅG5SuhjvyYRQ/}eoN~MJ²J^^-#z*Qt -F:cL\;N3]T鐟߸hb-\4$:Yqlҏä)*ڴ rRbWE=PO8hB'zn HJ4C=4iN+\`0ak odP?6=@}b=yn}LG$Cnc- wL $JA`M\F,` 2S_=L3z`[=#[^M:P434zq4߲x d~ c:˝W6ܬEXCI߱8Y>Z3$47EuP@!% B}>+QpE3TNB2iu#x!Sot@̇)cpZv1LF:1ữfMiVN Ǟ aZ5YpycW~,]ɨ iU>,S&if(1_\^dsk]•eM>kâ8b M$ce{y(uI+fZ J;+l^[3Jb14xҹdjDuyu^3Zx n/DExUӝkx)C?%ᎹpUh+sUUOZW BzQNNB@ƈE+nX7o?ʪ1oCh;L'\#1cgd,' TLK-} nL/o#ck2;qp*YUK;胹e|ٔ]`f<-y` - ޛ76 M~cZvKz x  n)ެ+Ǔ7ߤVAhRCk%Xe һMMJuNgS[X 6(KdqH[=.rG}$`; j-,Opgw:H{><:%#(ᇦ)3w9k{1bzu0KƜ6_ 8X˽r*PC*?f}57CqǹPo4uIS1#ڵaV&Ii,ǿU޲^"񻽌l@5ݪ{D?tueYi3{p^ BqGTۨƊT{84 Y-5!z,>j$eT_Yi?ԮJAXA;/W(Iȷٻı׆p/DjFи$ttsfio8|`V(ysH ~O DҔ~~D^=|j}#_6 $DTKUekL%PDQc{.ԕj EAmy`7CRX k!ehږ-XMULأ@- .-Sd#ffMJJ ROUQ" Z=Q?#Ef:7|^ I!>}`3": E'=q:e9c[x*"4,yQM>8i%aUC.=5/:6C' QQӎ\,ҳ$0vjH>R_(k,$5#h^$Kţ߮ɾك|ºdpضq~ܲJ5$=-o@%/$,gW 6"\' VסAS[X^..(*WRߏ;΍=h` aU!ZN LoaQI#FjƉ[ຩ=̃?FHmcD>7K$Σ7pv0q-$$BM~xdsPw+b}B8pZj qrU*c|Wl kvDK Զpn$&=hO{@R~;Ab$(ŽCr.uXe* =gj"?%ש~:)u.:F^e[>Ƃ49}q ww>5fSU @YwUmQ;ɒpVxJojB<{̗ :&[5:UEizvh8ǠD8sʹˋ?;ʃkȤ0+L.'.^m޷&}H 9Z)IZnvRd PT)gAh׏b8_@O8&{oWC(Kx׮ζț`zi7ĽMEtZ+#tGw~+i'sl ߲y"yhv+zkQu&TUTOӡ!nHOryupg<Cb^!~ 2tS&I2?J2 q hdb>k'Ff8owZC3{zݴ͸c` `Ϥ"[ZшӻNмr +B"Y K<ۉ|>L?$XZ8$BA Om='VSG';To5#I}<ͩ>}ScB/)|)~!-RΌ)⎷d6[Kc򷎭ŜJ\dprA4t"*6gra"zQ! v0Ix}7Fkͬ*4qKop̳낒fKvCaQojڜhSe --y-8)Y3*t&Q,\ Y Ĝ5J-=Sg00y2L?])IZ}1Jn 6k]VS>O.Cu s_5@Ð,j|`k4xyn1묐o#]TFr3"Z

ɾm)i{w$1 /|Q>:|pŃbra@輲M*ű'Eajtn˹BqY%mvs1/mX|M}\4E1gOft:Iր6Xip#C_s` hQPSV}',Y&,a[KhZk ÒKJ5Ff7LO< 2(! f"XUH[iW#39v#zPo41V|FAR.#?VLJCE7; L6nu5HJ9-W7rj!xTa2?L3Lk2L,@{g@tɶc˵ú, +\)@'z]% )t8<\']q%&>Yx6l@0j*6(Ӗ'N0⊳'gI#Q~B5L\%,*0sP{I" (#. Ӡۀcid0wecn+dѷes\=>c>ng%/Kzz8@~{a6`SRQ<޿ţ5\!'ؓm q4䔶+~qh|M=}7D]ۚaM˄Wʝn^9vkT8s|b*»Yܢy"EGKuB!Ko#-V̡Eo^ Yj׶A7|܎EnM(W US_#,#~͍]hdޚ}#+]$Y`5Q}OhI'fS( ߀%_6pZU®D[TeI1?a #g%,tx-r|?bՠ)(#~ ab_Ŷ%"v=VrCL{F8i5[YþlS]w8=c͏E{X-I}#đSwdAzϟId KXU?vC cFDc[OFbW'Xu8-eA27.k T9 W[jpmYC.}--^d.8 ) L3YNAz $ϕ]DG3S"tF#Y8`+w(0d&M;f2xO_8 ǧWe~[R 5AgxN:PK*8-o^hNYA Nc**>Շ7_}pXf".(;4]_U.{cew4-oK:GmL1mhgq*I;auRO y:C`ࡏhPQw:L⬕Z{M$|m*07ɖz{KhbgWr8 bHT*bB#JhH-0 eu'oq^_z4AHQ7)O=DD}ŗMU³{wHn?7-tw|j h#r9CnvX_i 2,3r$KB >Qӟd|A"q"d`%wv "Ӏ@ff2D.xHރtCd_mGx1<_fцts*J.4#NFX,:0^?aeuu`i׋ЛNuGO4-ߎ5FqZZ+ 6"t,QI<6U=@!SNFG QФLiZO1kޚ[6(=Ik4eӲϨQfW_ZjUثت@da|]㽨/9Gب5?\-_]99ALO1:lɓn(`PWnDba{(u&Q{ /%&*>( ,VU>ٮ)JX@'izrێu۸g^ ̧Q@ 6*5aGO`tHQlN4(T&#IP @RQ YΛ=:f PB5Z+֢z7{;CiלOqn Dަ[]m . vBY |C_`"_ [HIue+ȔQmɲ~̍  xdz 7L3~.Kе0e;6U$uDBx\,qiV(; Z^9TwF:}KύW fD :\-ʪ_pJ'TY7~C%qa+GQZu EQ\GZ)bN"ҫdOpPA4 #ra#~,3Wvs$?څܽy}Z_|_𼹮:3`/*1}MidlE5=b:wĘE%ďmv m3N@I&6!)/Ucg蕎fm+InF:G}Q iyX$3NDk7.t7q2E|N"ЩYEXAta7+Y u*7blw^\.6Dz"4˲ۆon&|Kou۴3?̒O?y!`ke_,\T&#rU4A"G^P\wQ$ _-20~twlnƘ92!GA'~ doѫYCy,P&8K~@Z£e"|n3 S~+pgK(#M(2n{蝢W4|X1ۑI|/`iu)|vAg?D Q/?k:6:sW ~D  hU@in{ rSœšrzlJ 5?w ]dnAnX5G}|Gٲ62򭄈w{8i#dojMN/jR`;fCfZ޿@br8ԅ+| B!Ba\M^L Y66nOЙN.4u h(oo%E-z4-bO`ڡeΞhM_.є~E[& |Aվ0۶[ _F3K$($(O.?:ɥ<BeB:5%\!* ơ@7*^<ϋ4OLQc I>0& _+J{7нmKf!Oa_ce +Nv)_4utʝ:9Œ0r^ sAn~-!#A?#WI-[5iE<"ig)|)_~oCm)[] 1n BPИKGng㣐Fi6֤?a#=62,- '_[qih"{/Ͻ! U.wf+'a[N/b6I>z &w/=/磻 ~OO_W5k!A1)؆F#jp;F* 6@ =vn`-w/į(3ݔP=[-T](7#1)FIO!U17L'waOJfKl*EknK-zk ss\I`{;mU<}]u[9l%Kf!Zne:B[ hXn 6bNyCWM:.D^ݠ1YB9tȪx"KX#'ذͻe P'[Qٮi1nFC\LFs!u|h ˬW~kY; < YB>=X:ّ_8Vdhr"sæ-O w(i㓠Lא.b^p!{dcUY@ 2FzX.f5 斚l zIh[E}ƶ֓GS*ڊ )\[jD0 ,f5UFY- ylCwר7~ڐEwќXרe4#?nezU\KHO@ƀS93n[UXۧ3c_;2=iׅK񗟨m%NMt#o.,~)=ԸUz_qlsU㈁EŜ7֦:$$ ŷd Bhͭ2Fe|Mv $lz@}DC-,6Ka_H`@oAfZa?jYTK)e&\_5#~*vgԐI{\&DX`[NYBZt<2zv6BÊėG̑d ? !_Mcpc*>-)+t n|eaGJ:X{bƖrkUw@2-Du< +lfp} .2[v_3uK[$QQ1 j黯 W0{ t3iH܎NF!łeAؓeD|iU+Z{ &otKG^_ވfM7iลxQoerz!3i+5/]5y!D sƇH1pILz""wS8]Ԑ(Ehu=;"lXl"Iinyi-p0+Gc|zlr5G~fX   l+9.甪$9s(1IXfl' An'Ew$p~P6>QR)'$n%c]|XDl#Tǟ?iRG"%&sB2d!-U@} Ű 93Pn-,%Er-wWɗ 4K eqkF,GZNr{ ?PZ<=\0Ȫ{'^—"9m }UX$g(FL'nnx;-G[xFece b}"%13V GպwlX/lntcn "3 NT' l1 ;l: y2`zj3B=RGeNrӻ q?{ ^ ^ΒKx_ 럝M3prQC*b@˝m|eBؐPYJ $5EunlD3¿q"Tr ةΔD~ϷlksB8ծ1L'IzܗDy[~ޡlEXz1]p^3,>cӣ#mzÁ*a/`b L֑{nd0#^B|u&$1kc2K9 { [ڄy'dX]]8!V>U6Жg ܃Z,3RM. ЯDWʎRʘ7&޾umB`K_3#. djcĿO3~riPRCt^Au;[MѼg?Cjb@dܠ/6( ÿ'5GR@O|*Ͽ}UP_hVWF&,upl[΀4k[KS6ʿ>{gC3Ե\]ZD8JAbN*j 2}'xv&G=ȣ4)0V?[ asd>/nRjPPKfU# Ka='97[lz2kIFV{S{'T-b X!]ڝ[$9pœGZ.̌C 3iU~#4z }e$"?1MTڕ;(98aF7q5=^(E_q2 |^6!d]W &*!8*K{/Pv P&YSMI@i6 ZRk&;%JrH>t9CU IDR[3Wi屠";K@x1F A0-aV\F#&񎈾BjC [%뷽LA hSQLôΫLi.:X0pXS(3!{%\E|ngbM<6Fg6 !T+z1|K{p@ZM5dUuj=vN<4) A.&fOfV@* 1)4u=wo^Ki{ی>~@VjuulKnݱnSqG1 ȮRh;Bt.XNS\_Ss% / Fr"ht/xgݥ %':!c<"If. ܣa:CۛoI-8kUU!dexR^|][!* PKt%`akˁNƄgčTn+_7(^(8]}u Έb 4M'֩N:ΏрVy\έ zaɚ^4<'G#xy}WM`b D+(i׻U5: W/Œpɤ~!BkHNcik.!] w 'CFCGcY[t+EKB}YHJΧswxu{e xɔvEAߴ.DxzP U$'EP؂T6ݮRG\V/5H/^M.DO`1W؇(u}ʠ^{R $0!-XDxa}C jyX_ٚmҋF 1E5eRRX"yz>ҙu8 KQe 3'hJ}QLƈr+$F9 vm"/#4vMcrB Z,98QSWbGRmQ#p9#KYh a<GI/eJܦ:`>7Hì5~Ä́ɌY({*•=A{ 'r՜H]&]={Oj_F$(رykՑ]bz\G\/ȶhGu7ooEQ[I6o1$vV0 wf%R'âgN,YHh'd-`f],yiƏn2i8cPRzcWƬ:,_)R e#禮D+!C 0ۤFq7/}H-|O9;ʿ>ӧ;C?{S=QUR[3I&{k On\׶F1ts36m`q`FZ*_刘ޣ,&?D9#YHt|lƺW] Wq~8zog(W![ &4;_pҽ4IV?yrd%zf;2x#لrpY& " 7Jl6&\~CƮaa)BPB8$V'(D tSGj=L~VAv-T1粢# GۡT^aT .fyp9q=EZ#$ x50v.0 g 3cJRWZNwjh|Ɛpm@*'hhK|5gܲ;[eL_yh 74QF^7|"dkCܚњ"gף%f3kpp&ڟcYc32C%\k-5v\QjvάVzʝ<\;O;zXWd$10+Qb֗҄^H󍾫N 84Z]P ;$F-RF-DI+0US8ZI.bĒig.p]NH@jڋ̸ ^Z;Bg"GSdq\JjwҗIE{nqq>g73g\f P9Р'!QjŒRjRd(yuq뀦G5'h,SϤzW^TF jcC 4({ SD94}6`En}o;{\rYW~ץGULNpW{!mޭj;ʑitFu9Ӗ 8nv7ғh6N5XCwDs%\JkRNhMDwϱ%҃x}UJPaA }XoMWϿ0n8:Oʾ?CN_\sr] N\C&, i(r;i )AJxUj}ua~6hZQ$$s4zCyYDtez>O$6=ݝ 8q5 0dVۨ )_" *N[OƋ&ZO ?hSr#dmZO[B9n[TP;f`΂sjfYhG*u91/XHtMۂ^g(ms[51|"Wd9b6VGC?1lvLe|kEn¯z%`ǭA&݄TwZWRZ˕cjaP4,RFoatyFz hڂ&vy~YE EOqPoĖuǹY`&W+o댔1Vr`0<{v{(BaR6iXFwwg=V'/Nb!#^ rf ޚFyWw2HGRoXXoNg?Ա~c<6'%LGBh]њԂ"\U|(a֝Y RcL:PkI@kJ@ĴS;Y%܂%~jH͗d/l)ӹQ pܻMCIoN< a#*![-YTa)ǜ7@Y r._05yY5suu_bU4g4B`pw/=B܉p*AO,|aCX(1JT~Ft*SvM;/J$6eL7Z|S5@Cc&$)y!1SXݹ7 mx1!#>7񎥚f戕Fu-bP=\p?:z#,6r=`ɒcHM^ۈ&ay8Skscm%W!:y7M-3=Dk{YQ )-koI/a.wx-a+C OаT{6L G'E_':RZpH)"1S~ߘ4J^lT70kCp0( ]DJ t ֺ9--8t 2 9a?d! Y젱\r\,CDx5kqR`5{/DuClڂ@ bLˑ{~Ϩ0wogGE!&EOĜu?=MbpJ/s vZM,M=Bbxiw۱WvE65/:Q)$ 4Ȼ<,ΤTyztTOLmt%6 {Qj>G58 =d'j6N>g뿱6 C߇ * a띈){_C1{M|a4M"n>{|oZzK@C2Cےc;lUu#*m8VFcJ/qJ0CPmc@5 g걾81;f|}s5z fՍbVeǪ ~G*Ųe»c 6Dz~)Q4N*xcf6-vo7-ɸ5FÌ-zHɺj~Y}IOߴ\ڲ7Vvf=,* Oo8jnCбD~o6+ }6ʆ#n2V &}x~tV 88]tj@uba&´Z8@<Kt+{_TCTL$ƺ$pO_sH8(R Z+m$Z],lS0FH{wB(͒7z=/}RR R>M|qx\j?20G 'U_쁊#QLz=L̯&P_lmcsqR\Rb)mE`W3- 5MfÞSsIWuLMj&@3q:VQGdC bK|zk-sS\9Lԣ鄏n_ =5u^cw'Dch}; ǦT~-55糢C0۝ L 2=blF {%P]=ݕ]<UDpRӸnG9knXtJ_3T݈ 4GDUX f܀.@:PHePNOO~m9[h//M 'h?7~, t$!FB\BFvXV9 ɯPW9_]r 2JmOdr]ogaO|o?im.y/çr ~f`(n\Zލ%\ߌUp[*^!AU[xo4L<5zB͓ä=P"S197o4%Æͥnc/nF4W)J/ς{ЁMn,NvM e'[9@\TyiS2 MDl; @tYp9J,d'Uf8hzǠ>.xL"CxUԵݪ]I ̎D}s2O4NƯ, B61v^|,:gԠR[]j[K=#%&%YpئRЉY2*#p0kJA0yyM{,-5P .aI;ZH8[)7xL]D?wNyUSvP hC hbe2PڲgYyQiCh:7@, o8gg v6x`D7> G" ]Xݕ?hKdS^㩺CgraDb2h(Yȝ[?М;I]?LjR;hIW2@߂w2|+cb6 ]dgС5 ݹibm΀=0JrP}$J𰟕^Ӛ=O-!3h,ty  _q1R;(=$kZvs,)fXKxnm}~2srJCq\kƫ[UJΈn.]֫X"AD]CCjYNGv#&yt\3ѕ~#^B!IO:x, {>< Z`3y\b.F:W#rCA( KSPnU 8sU n<UcЉ0N2(#1%uޮ l%gqeR878Ma`Yc}*0;XYa/2zyH\A9M$ax€:!G,R_y&[rA?V{.00( `~۠to3(24haM,ę92xt.jXx_ ej]voIm,b$}k 2DLXb,jyӴ?* {\c}FtaK^b"\^ n>bwa^m^ ^zX^s˄x%sbBTiإ 7Uf;!qcu'IB0a:#cqcNAC^u 3hr ϨZeޣ#Ǘ%Oqza=O2m~XG@GOXUQ7Df@Z9UdCĐº:4g珈WZ\od-0=qӚ^*a3I.74iLГ'4Ƥߒ{U5HPwG5HtQ1Q9MDwӸqԧwBbT6J;\]ט-pM"o(j=4º>hK~ <>5FC6x.s6[I07ImGbչ4brT?+(MȎ*!k@1is 7#rS>k,X䠘|f2Yv\f a(| _Uq+D2ʜ`S<]9l)e7)2RuׅGpκd]&tf # mE@e>qk/Ǚ5k6{Fg䪕w A)*e>N[gki >zv?`98'rTXOkCXr4QR};*%\ژa=*0@:es,;f7p nj3-(S+PкJ| qVsJ1VU>w`H1t{99 ZH*lѶC >6'p4XE;P\OP}BDVJKnz9\/kOZ&!WgQ Еj M;S6FG@N_qlKmvY%}LS\TnV%so"eA7Idw@% "6* pE:cPPcDq,|;g'T/nKFr*Ixtn|#' MC*VMd 7:D pά /K}Pw|]xעŃ48"zmE8P;``0jlMnuي0UY>$AFRj:oots8r2ڸ!+Q|ךdЊMT-Hur7]zNrH\4ɝNicJ.M:kU"Ѵy'YQ!y =b/p)휑:vH|i<2DzЎ"[@ RN vd9gttM gdKļIIM#5B9.` BMgQ-ξ7HbLM;:rW}/ꭗ~hh7T#ƲH[=T ՙ/Hzzj%E/#UeBXhd-H2d+b X 2iQ~4*'= 6+T:.(,uBoחQVb7D('Eˈ1oj =nO~~X&IJﭯ+'UkUOnPߵA:2%E̍AF, & u|g`-%)Eh^!ڷ x$)AL=ۏ鵨QtEeTؼXS;8fd/JP}F{.C; FG`RuŻ8 ԇnd, (T͖GɁfGF/^ȴ)3eY䴊NiR i=E1FܤTwae_,Rbd)Zk&^ )xmu o,U&OǯJf-^cM%A*wa]/Wtd|LCP@T:t(U {MtM6])JoŌi$0F>jUkzqQBSpI1z&+w%М|ddɨQ} OQ?s7U_gz"AL C1[{aZ5!_ҀY AB)zYL'). 1 ;hDc?R4 PDU "u,$l':iA|_RnwOrv@,YNdKSg^Rk&Tz8g72N o@#)Z zĞ5.?Ur֯5Æ 1)$];7}Vp/X] . 6[əiY?P`UH>ǬvU"!MP:cC'L$G݄VFpK^{ bXXœgIeUҞB#hNrP:39|'ye@u`7odՔŲZ??aq*Kѕ+ՉMHÚ8>{MZ.JypJzF:=>>20.d0U:i Z *E^,JHb@knߝ^G= "DG׏GiRǵ 2s_s" EȂAG`s )yL]\'Br2eE-RC:rŪJZ6m:ZW~ÖA qyע!u`'Y XVSvaz yi6?A;xZ+- 8hbW&A s7;BkS?O5g..Fg$exOca QzY`9!iJmN%6*dqjU`p_ZŁ(,u:_+9@{)Jy ,L&pk<уgVg>gv{~W6"f1ϰPmmH'G=7%iycUy5=EߜJ!<A&yޕ.{2o_n௷YSo7 v}5R`  eVJu#R潪` $FTbc(ᚼT,+ŀߚ{n\U^1A@P6$@H+OV@4CТyDع[KWqX'}NӔ"SUJ4bW8#>2Esa6Uq9?fE8@u@8*bo4@`y#m:r)n~ͽ9-?mI]Fj ܡ"qm^'F~E"1:ވk`  _=`*.ͼ C91p?M@X.6𲤓Fb\ED-UuVeg / - +5KBrfB΍m)3iVH-$|ry<_#HY9<寢\z;+.E~YbBz.ta(+( Jgг < 9n…POAz-B<42=܏$JH/JMy3|wOV K 0['žii杀wBqY(_} #z5Bu2߱C#o>e{ՀR)26PÙgع_!g]+7pK!|,Iz.Tۺ ;T$D -J~GuԻ3DFƒ y-gn\!YiU;R.6Ĝ1kS_R@K6Eڥ-$_}+DSP)[1X}g{~M|oiՈ坟myrPQ,jX5l'>c d 3~0.bMFY4t RVG>d˿MkR⦛^ASRzW]rIދUTM0 3.':1:?/ b2&`({P(*хIaø&flY)eYF~uXq-[`%)f? =X"Ataz?}vW%"Kb/_{lf_Ͽ7ա)~K&x5l9蕌y2S_Ϋ¥}LkK_aIАuF`LL8I]ha %kWlZ Sa}U!ԹQDW6IVRn=;BIL!Ȃ n92x00ntV xWTbà4%bK>!ǘ~оp\TJ:Oֽb}oi CA2eZ' zXi&LwKgiBV<.WVWq(7(YHiLtKPNbnAXyV"^n1 $8c$C5+%*KˊM15YZ K$+rv k:c'.!';=6J҃K1FsM;1T2S EnO[56F݌Wi#,bhVU(Y^ QH:H8!Q'q'CI{ȷcՀD4VHh}7ơWQoȋm]ǘM 5A=f#>~xM#sėջo:[^q fHHiR5N'K*A?uF9d24@j.)A@N%kqf%3C[fz2pyy zM-!YH= ʕ2wΎ(. &cgG]R3uaboR6;GRDw4=ɤ>&g(J;y_݊YA/uنS~| sMt-lqkDI*0f#޾bO_j"8rqGI[hT щ{+{lyΛx/Bm*;0<"#jU (3DfZm*Xءu)޶LNQ}*HG<˾ 63=+gu!_BD`C႞wEEHG!Maz^]:?Ԇ6=+s`pU'n dj8Ԡo ǀoL7۳T'p5UPr$UH[Ð3}ku;M=˄BnJ)O"X|nOyubh,-3}]0+P-;lXOlgk~Shl"}N7J-L5Q.MKP~^|̖0 o!ZЗKUp5ZmCɴFuBu'Ǯv 9]Iv3kl]u]PtdR& 18'pN ꎅa}9kYzȃͣ_# Xht*ڤTϝv:Ktb.bNA*8>LϘd.]@ 7(yazq@sk秃˺ ėò!3N.bՎ"=*@ .֦YYk>sư銌$y{Dt~6Sv%vk,E%dVujsas\܆Gc={7lCؓ+b|xdFMחP[M0W^m98OiFY4 KL ~ҡxj/o!UA( .ËMd ì}EJO[ )BuxGarUߡO[1UY#dvu(|G!ǚ1H5#{rP2GZɄ(#mOW]sRhBz\R%M=/kWߐ|kvv,e0 Rz  0նzz2$Kڎ6%EN-8ƎE|x,5ӒDx92GX|_t Nr:zq)kd"gMKia47U GK0C-NFd3Mm\`woXChIqᇁbb{tQ(?. ]of6kw} lq44SV ՞EE'PN'sor[yĀgE4ZOBНq(Pul(0(麥8gbP khSJhB"FqlK O̝S 6^L Tcsd]L?g Fؕ:s(|Q7rꨞҍ:{w#:`~qڣS $C9 ϖ%,0`(\1 /{ˉdAj&/Bߕ:'FufH3P"r;5,P׸" Lh:TGB5whҤ{ax^Edm;dwƮ*tѤ^loO`O36*EFx b׍UDon$(vD.a,seBڍ"rJO< GCth?烴ޔ2[+I$2R;VASur1/8r۬Ԝ3#VKF?|xKpe>ݪ3*|wh=F=z[gGzod}8seٚG3ȍ9iT[Vsxڿ-a/*2Xe^ ƸK0'V) :|4i*Ӌ}'zl& 0* }JI9p9bk8Ym=+) 0f,{:sdwIE}vf1bvLhxo {KuT`sXh M]n"\%Ooص4zk}v q{QtZHߖǥקD ʷF#5LPys#G'w'㙏\PcۏqBgJNfƫ|!qNmm'voo>);uZA][}e'5 J*dkی=h7 -+; I_ S,E-f4s~@MiBEdF.bIWtorGëDB ab3M+GT7EZ[Yᦆ4Eʴ?*y*ÙC/ i Eȸ4h,"6}7g {v+>#:WYTx4G8|?ͩs,4q F0s,ɖkyD>NWYƘ z~Z} 8{6KT/!AM) 8WzWυzb,D!BU])ģ>w Vˣtq/=lu`߮At1#,;q]rZUC#u`(-!p0+[}& NKD6s|C$n|E|:jf )_6L2ZT̠R?q61UY6472NF+QI0*lc_vk(X.fZ7o d8ijĠH[JQA)(grNEk#%KtDAvEeFƁ{$@ńE!Q|Z12xcÐgDU񪨌tF5ׅ,;?d@ݻMؚ}J/3ЋT*LѴWs(zk"]+mAhl&us@o}oLl׻J?]+%q%G{/f={Bsn' ukRaRWG?xM;݋ǒ ^u| QZ'l%! qsٓ ^N%Rp[:ZJKEcdԉJ.:EQ"S*ocPREɕ$m6gu+ͨũvGqXWU jʊ0` aA"!D]jknng&o Axj*{5`+^_,DQ\ Cbn{P3s=A`ojw3qm_{p[sF R~#GJ|E_`3NqєESn;IwvU&&U,,%Ʊ'\rCu(5`3bbW_Sf>Gv䮏E0L'N_ 7%R,VԷ6-"Wnj4$kR1_σz}UKFrhrZ[A;(-!_+>^Qsy_1UнXT`9V.:Xvcvzj$ fPg/E,Z v,6IMP4<(dmtoH".K+=}A@DbOy`/RCƒoΤ&xBMn"GS#D d)c3$J"{ QsUAG}}=9"N~߿rmgO"$)4SRF۾X?7ykdS?]!ͪ6+oⷷ[,vBK↟7͗v٦ʘ.g}@D3k:2;Ou5rg_X&m RDսX,ρHxJOFqU?D9{ |hjLU5[Sb$S/9,%9:|G*^\1(fjE|?f|Y kF %=0!kAgƊfL+ ›GYK0hBi}X_ $<D)ڒe~QSA 9M@,(^jG@@_(c;~na)ry gj9ӫj P˄dً|-wiU_zJBLsCb+0]uS3饋c3L8/34'c#\iUε3<ʫT sq!1dRkbIX}*.#-a˜q^{YUU92R{Osvc[׃}c D=?h>ꀱ68(+Atإ(J.f"j +V6<}%ty˔P:ƢY+>x,NƩ7I?ᠶ6Voe:q=7xA6x] ]FkyMa/݅3fVsǯ};SĜ s8Ut/8x[*x4mX%H|~ XW uy+:D#!%^yCްC_u9\q)\I.#_(?m씩)kx EGa?tO3g"pSpϨ\|M8JpY\!*n0I Zj@4wx&c`Z6\ZYqn4NbđV$;*_|=džzX!#I)T/nMrk'kc"5c5Ϣڗ%Ne>K si46%<"\CBQ2gF$tW 潈7S!H\b;J?+`_NSY=~ƉFl~H";Yt^#wjB#VcH 8 ?Qޟ]Т|x0f6YʺRldbZ`WN]9%hTJ}*]hS#K6G%x$:MkIL%fB+7͑2n Z++J7㞠w,7L&e Tݼx^JT+H=FhkI?b hz⨡ :2gA踞^Q6iO@q3ɤі ~4o̴`Q0(%T>V0Ai򶺢b x7vTeB 4Fs LVP|>^a3mxYL[q'n\\SzMX|Ƅ]aM* u= U:?Wx+Bå <XC-xRigGmr8PS[Aܞ2ZSe`1wK5?>l}XLiL .nar.Qw&/DQ@s=3d=\l.5I o_ ; \3qt&s;!m_qnꪠ(-9pf}kj l 79uT!9]RGͨr n&0L'oIIBTv=l~ADmD)UEqsFbh7ǴHv[8f3XBQ=5{ڗaJ2X+T.,Yi"؄}gbm([9:"W!bj?h;M˨~~(DlF vKxTal ]X4zSқ"p(n5ߛKC! O^_s`_F1oFqf]8y3ZniI{'z0Kc]E=0K|5{c.U!T%7n0H&B-2Җ@*IΚ`w=^:\]bE l̃bI K!21]D6.#06}v*h2B=KU󀂀P `hNޙAbr:O@ r%yĔ7eEKE 놘YTP㋩ՉTuǴ#ܰLFfdjLse5c+ <<<Ξe% %Ԉ+%^D )k\zw :H:)m an .p> X)_F*H~{pژ@>_ >BrFwE]w #Kg5eqۧqaO!jq/craXoC>xiP,kjJvHv,,v8W:jm)t;ߗH^&yk`H<;\ʈm16wbԨ ZO,*R oAWpHOFBJMq 砕9 %68 ̰ (4袧ᩃr䥄~*[qi_? 1eE6lĺ ulDʪl^BTZ\nDͧQȈDuj:UR{YF_gȣzNGuT!Ҁr{=:կ İact10.LFK!`Np?JsKf݀x/Ýs?4Żw+BŖyS2^1y2Dy*,6r% pdH E {,?y}c_wDLێ*W sdQي-JAțKx+?Ax&ƞ[dd#^8?t; ^`ʘ=q-}IPx*/H o(VVngBFR&QsvNԏ4}Pdy\3'WˌfNTZQ saDOxQݫªW_ G0,Kw1n/A/tA IbT8"{ZjMDl9L%zqB*:q˿E'xɀ9A#u 5~*:~h>Q -ypK.ggbjk.,umjϞ&~1m]^U%ݎuᆹ9?'[>ƘrtY?tsP(J6ϧRUf'ؒw+/k2pv<i40}^V~0,kV5iDlusc}Ҝ;w_FJ(EvV-ƒR.MfA= PeAX :e~֤kv]^27_=N(+~Wr=<Ë)zHJ`=2NۍMK! .57aab*_ZmL28$~chθo(}+sZ,p©K %:ω`[9jˋ4Z*B#ok^i^Ch:</eZwD_\:KEq/K{M;x߯>dl"+h~Ooγ^}\ɷg8([DUdA-F?ȣ` g80)D;):hrjEHYk\V>fT~<) <>-0Po]31*M3b738-lpk*]Mn kR@\ּbK)IU]PSmoSE͛rc/NZTGs<%7=oA8TR"Kޝ 8դ}f4ҧud0J քZ"[o=}1/qBѿ%iqS ovj \Z{~Hchvz\$YZYs)u)'6PTu_7u;O#T GabvZ%uR7p cgٖj/'<n$jE\2{ѓӻp}B8.XjkJX=O]Úy/6/s_k{`<𴽗bBLF)O-EH]vW 71,!ƃ>9gX0p8y0تod} BRyFW~/q)ku(df4xNF\ %WNwK iuNY9$6/ԋg(z݅QGGEY2Jaܷc0ԄnM=)blB9PU[2~TPaKh[hؠH  &m?]*=藩`zFevm!;+HdVYk`^kj7BCЎ͎Ss6u nVr&KFa6ܳ˅*N#˨ػKzB|e75_xYf;%ȳfrO$J֡)>pj(Bc 6G:d$$o,w٥?vbg`KeKrmDS]$|WOLg֦EW&D(ݩ,Hi_ 5Z똯|CJ'2 XL|(:F$=[fz>p2W |MAd*kv,he\cP>)26 nH9>#bN07p*RwnVXgO#T ~TEpt̡IP?53WߩH~o $ZGuck/6Bcz+>KOOjeшK{ ~#ap :Մ OjBM=2Z 2c4tv:= fe؆# ^7]+@)Mzi-|_?S B˝oU>#[ ޚAQtՊX]l5K5:󿂬=9=bIJ|Yڹ)=]r-Mf.U$T)i#dV*IVH}Sc .@^x:0aRQX.SWBĕB;K'=}ڲC1Nvi͵t hmCF`D̹dm:8K?K!5z+4gl5%\ekcSIIf1F b&pVyY_yU`* 't̂eǭ_d{Ê<~V^[l&8ٴXLƒᜭs|Q'95"3!}So;Cϕ Nix>>"p7O1ؿs`-AeÊ%Y"'9b!m!Ю)L !PfČ~;7@7kZ K(zԸZ30#П\yՅi[~ Ʈ.:*n iioEU}~TYL2uzHG _';\f!ߧ GQ3iŎ:lõyZe2k:9VSuMn=q֔(G7Txs'ĉxV JǛ \蓵h7 eu@1J&ERtD.@3t?(!,&SRg,,Ǔ7IpaeOULp7P$2AЫ5d9(L /^Ttja_m/C^#jx\V[t`hzQ ;F6ӒVjmzl _.o:~)ӬTǝt_Y@ImNBfj/E;)0,dQl\;] 7>3^)@A>6Fׇ8U. dL[,l2<5Rfy+ڍ?qiF1ӀLj4OYd*$%o )+$=ZXx{ R5Nt]kq߸MrYLCy*6r2=vK}j ĞHy%?fcqâ 1ZU->>MkZ!I˗r'?mE6J~e MNd)oo%|ƻ2P^eC`,*!|9 3r{q.[$k7S#ϑ?8õ_cwB/[r19jKС"+FGٕ*%wϪ*= -X Ǣ)`fF ;GeؚmxU -U_.dYE@<{SAxQ tIVP&龴;7c7ƻ\ 7%bhJ( ,D.3cA*!STf=5CTޟ:Yse%,kMGy2\"1бпty",|ՕR7巳$1'lrm3d?̩BekX>HY-Rq,ѦX j݊aBy=16%55K#\jė}vW:{h+߂h`Ў6gy r\^p F+{ד.9HrĢ_&=cϻ`AS!rpAi'  $EuGjϗ>#FBJB:glDnܵO|?rܴ9S5ݛj4ff{z~R?^dy}&&BNzP:Sģ{9Fu* bl+Y3~[ٺYY ڥte{[MB74A1MJE'9&\1qP N9{$T925r\ׯo28[k1/e%D~09H,ѫW47rD5qm_/U 7ҫBR;~ nEuDLS.p]XuH7}iJ`HpA6 a'׋]tHyz6خ*6Nb4=2b UdJ. 2E ֪C; ~cy]drÌxgs+>,~(G"i}瘉MWP$տ?IX%Z4Ct:sf5x=5.} Ɵwcb{_j~6 v&ObDݟCVj.B]arDneIukZkCv[&?g ?oX@OGܯ=P*ky&-m+TAހ2FT/x42<bckE'}sj}0[T̼D'%j( ɋ}"<-YP+F_õ4'dIivSn`ydw-X깟X#=>gj̸.sirzUeC(Kwu98ekx{6 }U*SHH{vE{"sZA*+v$ sJJjdsxqZK?\Qwg5$(B6"H#7{a/eʛ3hW*_{-*(=t4_RlOASv(y 0DfzإiOkz*Ŵ6F5?Z^YX/MԹ%Jߩ)  WHhCӌKlm7A#`.G:H]}&O5$>o<,w| O]nܝ3-#lpɥl9PFcM:gY ʸ†)"'HHq(łx)r {@O4XHhtt|9 %15G$Ōom$Sރ֝MV>(R&q Ro'v]  1no"~j]C/=6&-PuG?2sh\P^Y>ןm̊^~|+"K Ǹ&T#z0x9;,3'Z PffleL7̎VEw3H䙿 L8:vO(R:"hA΢s |j(᪈7Y>zjgsDV/vins>y occ*1 0WZ ,^UKߨ[S|q |CaFz_dodسwbiE*^](xdT]0p/ZxNlaP @ϥT$] +x{JGЧ Xdn5Tr5nŤ_^lbAN{QHKsZb%)+7f!D _j0X+ZgqhCػ얒v V?sn:t (KF[RDW˶LʛҼ/0ն^)l(n}"zРh1+ O=8Y[)w_ȳѫ~D:}| $zqyL[q{'T5$#ф8BNӺ)RIk P9(  p/fg+q<)P9pjP <#l"/*n۰eO8.P6pZcZXrz,d7υ sGo#3\XGo :i{ˮ:RRZJq]Ž~H32Wт앬l:9U*1 z݈O}cjEl$uX֕1 TLђ3k)e9)帿qKAgV*b+/⣩nF6umO s ))MkxoQ; GP2HOU$ '!~YJAH״ O}xҵ^jX<]}[׍?XnT\2^t9s7Id.{'o݃T~׆͢˟b%P3?EVl:y&N%eZ1|_J>j9l7А.jm0fXբz];;ƃ䷞~YVIn8JARHu<Yഇ7F5Y7'z«dU& Lk$`Y 'Jv×G`0;r:8Mq]L*?#ƥJp=Ck4*76Ĕ8 h'w ,_w5+!,;ݺJaXRHUtsVF< j?"d(mx#^.y_ݠEq&Æzj~gAk(bUg K | A_:%S']w^IU>X2_vǽI{<$#jαS { (ёF]uNr~ !ҫ᪥j7 םkֹ@(H!R[&D bYqiK;jLfJu-"N>IԮ^n0!G|nmΨmӕN{s?J>gE`> !b)LBEEWe-|=:?P֬ j#Yon|dߟbML@_ /ZZS 7:웙e*r/ޕFR$KIsS; dPye)88@20b s#-7,1.t{En1~ҍocpo)*y,)bs8Wg=wUɳr `J!=J>Mz=/:/cerLqGKC ӂ@'cK|\.:d![&Q:XB۶,Dr(i0ݿT0~l 5}W y,/9DGIO/vk"9əjѩT P#68-| \]>90-xq[}UP΁g &2[h_+ݤ9[!";~PizcD ŸP̲is~`{WH*gqa;a"YY⚢td][K! J,}R֝p@MV%(ggifˆNA=-O& l8N}{ ӄ˨W:;(.U{=9w r1U@5{.\~1A.ߍk9u6l0DfdŘoV[N)q4eD!3)jgwj)@ôh\""$L,ɽ+8ów[8jfñ \6Kvfө !mF %PmIj`('OR9JFפiҹ(S•i*1 U뢮C=g 㪁3Je#Mҡ7^C|){i$$v[Kc}^ڶ z%2Oy)ȕЇdxT$7Q$RJZ.%(;Pss {W gÑtW-a@]y uJ0ePۀ[r\x`ZLAA|i d+S`.7(8TUdvdi3w83x6rr2ݞyљE0ZUrC;OፙS@SֲhzO]wLtt3o_ҳS\ڵ-]ugQN?sW`2),)*MIɥ `|G:Brdۖm]ǕxªtD% LBhBXHęgWx M,w\V;lY }j4:;Dʣ" )d^,[O)Qc9OMwنWEFA 5A3NS$os8swyIۀyXĮcF1/ ^w.L9"C&҈? 84fnH:1ΘԃuRsD|T4QmTb~N.\ MMb.pRwxZsꕩ3Ӭ>LQȚZ6n cm=*pqQYr+ >z gSmd*ҷ57x(‘o0dmb!W/"qʋ3n]zipF H9ҹ&Va٧["kDoy8'ņtdģ3&AŰ3^4otRAiIӽơDyx6^_+ (OO2ivUqf eG~_T{T7C]f7R:Oq`[wȠE@1X˾NYWEqnזR)-+Φ&]+ יnkHFa^F5Gb}zt'N7m OJ”J}50M1s=YD1W۷ߕsu45 ,ݡZBߨ4-l|Z,b Vr" UP]1jz,R`2GNI{5wF2[,K'dA F}?D>i&Wm0Z'."u7vv5p@%񵝽XP[{rF?;%l%n$9UCLHb:6zԋkxR5Z L@6NcGPR2{_ːe`v@wGyT7|nHz 5~Eٱ_%r0i+1N^Xf\[d3s!ܑڂ*蟚d󘱰N?ؘ>GLj/m q+sO1hnk14BhR|ZmspT[Gy E+T ڦ)Lwv ;# =Ў~Y\M~]6_WB ֑c 6u}+9ZŶU *8nX(yi/In3T>@*8X~A̼H3F_>'ƪWL{F#[[_ =칰k5BB:xrl8u _=nn)(ZDXr`1Oc ɨ0 KL cPҟow%":u"mʆ};vșf^br$UBgTn$ 7_|^^ԩsI7܀\@ HHã;Kpr)o}6|sȠ?Oc)|$Iedŀ":'7a[Y Ԉkǰy{6`_g$H{dny'eW"MQ~g=%k{}{ؘ 7QctHUӖ@nD/%$ DB8!UoE%n+''2ڞ%JP=K[$W:{ "g;$,) ;"t3SR :*a9SBPy"􁋵sr+VE<A(D`һgY*I G~s3TWN"rV&Z/I <ޡp‘6FOC@Ar)+ɝbb( +M=u/B> &Wm'\Q9Z;!1`RYl{YF5dl@rDzGVhw 4e$oyH^p͍k3SHY_" xhW14VAQ8(O<0I j.Ɠ l)dVWNtV. ~roXj6=bj#w!ٟh@jL 6$Uu"5.4AҴԣ]^ZI GzC #>IGKuw朼m6(3Yٟ i)\b(sJ$ gs|+*QFk`G$sC +ڣ!tk= H0kBНZ흨͸PF)Kch">se)jAO,4Bl65QN)ī&iJ.h _P:Q.9gb}cdqR#ưx~f %kld5pv|oCi(']ɂ-  ̥kŭH| YXUZ$ˢ)Z'uJo%wʺhș N|L?^ na mf~O~oGkh%.w/C%uFe~5i5bb9&LGȷP:!xǫ`6 I:;tC3 se$)4Ӿ^+#@(;Ak߽l ElI[ a\dMi aդUw4nE7)e.KseL\8W>e%홢@o:uoKJ ( !Lf$le'$\1®KW!}d.Ul&NᑻdQPK2#p2*pT$$zR Q`oPl/$;լO:;iGR:ptvMSd#/\"zGr)'ד{9:ǵ8;z7귀:\:+YXȗ͚+m dCB`{17ÛaTC$iة8(s g?ngjV}mN O>͹) (O(W5jY_~)=}=|k sW^ĖRBF'ZmAQyKO -hw⻽sg [@48q4p<mAލX@h1 ZDcIYՍV;#*)6t׋jgqcZs&џD%cGEۊ ږcQV?7 E_N񸤀93*r< ׌~c.oEعvγ 0ndp: _Xrz%" @+>KzۮprT_ʟ&:KOFna0x?d7ԓJ^' (CdĤ`[5L!Aэf+P1ń.kTpcehgڳ-ӌ 8]KS%7q1j}9FP&䗅n{Ε"pwL]pR3'u;AnǴ`Qv̔LdN8\![It&gSm-^SpH 97K #k$_'څ+Ξz5m*=%ua$c4+m-6>N.8uB;,Ⳕ[ǘ˶T_E9}8Yn:)қf49| Cޮr^xN!h"FO6sWqH[3]#Mw~>VBWu7?M~wSBB4#!X&],렚RdV qg/pWQ$tKd0)[l!FL$V;M=]ɿ` $9V? m!ӡWƼv_ 3*O6KsKV2Ƶ|;"4W&cKFrc( $Xʁ܎Aq=Z( $Qv٬n&f,ᤦJl~gX(F 6KI>4j>_ě!8էyQΧݮMl[́(-*Wp5G+_a ھK>ߨR).4Fj6p& -7ID*o9@[Q1.)3\O?p}J6ё_R>mݘryzLUҮ`ǵո*%gD'Q>Z<6%gapt5_E|':~ w}U(J)]^_59oJ/P>/x)- 7X0iK>\s.fv;FzZ車mB|p~C}پ@W&INd'B_>sMs-iJ(+vQ{`jwsZO:1g֝WDc*è35$ IƖ"]u-`Ч}iy-ǜ4?}5 ORgHM|j2Rn '-?7T||T2p\ݳXV \G3yK K&Gcbtsv˝;7CvHRË9JZ1UcGZՔcC?o6Pa"rP`¨RL2)K`f=ġĈyMiۺTǮ|XXsݓg͡W}7&њ(7@DWqH0Еc\Wl#_R b#AߟkXPjlv]~..2%kCud\/k:e@ .A+Gm7?m٧bѫУQmVoVnw c4 m*^[ڈX В@;`%Ԧ*ͼ_K̠܄t1bd|IPe!5bl\׭Y`w]q1oo6ggb ]rna2f<eUދBF;@ɉ%-Nod@"v$2F JU( Lx_e9/I-#gehSO].h@L/&yZ)pAG_SǿMciWOjJ'9[$~^ƇPB̀cTZ>ec!RCk><_6NRZEΦlsk$5䡢kᩑ*Fby s/ׇtezg`6=P,kOP1wJ 0Xƣt1,_`J1n3>]@Ype}ղ{O3  5  J]7ZP/3{P- H9j?74O-gLrQQ%^Ւ7 d؋OTkRwk –\T Eciuȧ6NC,~/w232qT n9B$Y6Y!$HkS, aW0=òw7c3ӡ湹.f&,/]vͨ2lOMr8NNmsJ=L0z=-C^cAt9ao9r\R\sl.:}Ff=rF5`QԝMm,9NJ'e 88/3ϋe@a-,=s|1-v IO-q!Hh`nMҾFciKe/>*MьX s%b%x !0+ٌ-&|}M$74HVbƊ kI l((qgfG<&9AʆÁ9.X RC2j͛XYnd~0&|RIny=' kE՜8S/ F&`nO Mqdӽkh (l9󝻬q }/]LxoorT1)T|*vT~s_DNBg6k< IA`MZ `n=)KE!QD 8NBv^bzOKhM;|3,#Xg #L#iXB+54'#NgT"V7+r'&N`Y0-7K5{1eɴR?Ei<opZL{Q ]aw]wG`{FQ+ni3m> s4:G3Z M|MwʘR8Epu^F}'Rsmr` ش~}v=+rȗt%KTBF7r:Ӯn\<>@Y+rN]K&Iq)Y%WNe& ~%]O,)ɛc:[jj^%MoǾ/L }3Rm܊WvPQ*0jW-ˮB=Wxƾ'GPLgVlY.α9J@uU=S#^w1{p}-]1M$QMЄ*2Jt)kTPk~^SjU]8Ǐ6ҡXRAvB=%!k#*qX(#QPhDM|@wZV ˌ X71g: vvչIA7iFNC >l7 ˓Sc9@ A9RÃl걄Y$-0)WIJyx^%0lzKTQġk3=V Й"Ilv6gZˍ.lF)9;pDҺ`t;ݫe.I3ɐ"|J-b0Ůi6\X$uט;Bw>bNBd|ԭjl+r'X͏zưU]< *:=#,*1ՅBӉ/`o %]JEiIQ295dƠmx qPInMZ?چʿꆼ?@3 BaWQ}Ek):wd R[ wIsA5o:YW&(ҙvpsezN{RurSJ8Ȣ~N/SN J Ghi30C'|`$&jP*EӱXxݵ1|BSxy1 vN ~RdU"36ΕT )i>).0fr@A{>ڨiܧd-Sq! nljr@s~VՒ{Kf.nQ1RMQA;8ai22W˘=:EwpWWj2YM;}+~Xu#z]$|%^ޭTra |/k4Iym n=<b຅e9,D:hi\K^^K_T@yF R5`Uz;'`, =$Hǝ` t)M^AEb]v=b N"fu2O8\շc7c&!Qcw%SċM;#Pa l>oAGWļ^>Ǐ7_.X=Bd7ym%~  T##Q>{oG.puGS,1Y &lϘ%׿r !QtسSm=+hz%,-1,QD.8W1j,KyiSY>ʼuR܎.` ߼5A zGR`@1peu3{;3}Iے2hZ۰y6%+b}F&2ۋ=.6ep{+'v~lP{1xeļ)>i!G=//ĭCEX'&^ǜ l-z1Y1GX(T(2}PRUYJ ^U>=VPӨ--g+ER~ aʩ>+tJ{V|򎉟nU.f H"rH8[y`^$z`t*z{Օf# 3KV FyV4*&j{=xІ7AUhqAP͒hnYG>5% 2p#DZ}.>hBm{|PuJtNiB[ `Hsu8n%k,ˏ#ߋAߓ ˹:mF RFjYq1@v%! 2vq CMF Q,GuS:;ђeO<Τ0o܇ 7&)D6p\^_ɜ`wN=h|OBǯ;peC|~ Yɡ}hv{æ~CBo1d@:\ ;;ؓF4R3waoN'שT8D\pq(充3<߫t+5XM̀=ooMx`œ͵j,2M_}NPڦ9lAa^)}7PIbVR$T՜]^WKV$0qPDIʏ_L!o57ek`|Ҋk)x;A@ \py"H:"-vmba_U=5\(g+v$b$RX";~>n* zrwZT|5n/7i]& m>=\YxS8x~PٸdPe}q0L ת&(y 7ACe8y~| ?dϴ kj5/xgSeJV.l,. rM(R0tv~)fh#E/.YyʴZ 3hDE2W˽&+f-q6ŋ~ hmw:=iݴ"H1&lYom7,8^l(!d-!2%uZG4-BW/H>0gN*)\2g(+QNLQBkِͭV(_Lomk /bqUrPڦ.U e z@D2l[R"!qmalp+Yp=lz;THK)ai7juaa'x~f#G-+9 <&2|7xAYCb|"tL?p1^ךB4>f `1CK萚lLCMg{Xӥtk1>)+ӋbNPuނȼʗլ%rpRA-xGۛǯ]$9v` k͔umwYl/ =(Tp߾dX*>' ѱ|!_$Z\}/pm j#_+9˳ <&0ЀioC-f'_<j@r " dաe6D4ǽQǮ}9 n? 0#)u٧])qzzݯY0uvT9^'/Tzn9>7~_0RcL =g o DlRN|R0\GS BUKYp:/E>gT\c%(@Xv=sVRK(evŌOv9PZ!װ>U }=mc^&VxA QńvUt\ï3|7!25ƍ_&L_Y :4]5H(kA5 RR x b< Q& ^(AAV~=;ٹF, `j_ DQ,RGwS_Y ~vDKѸF$NxwYJ"gQZ~wy"9.`t}׭xٔpt^jqULZuRUI{i5q/ޝB*g(W/iѸ>YE{Erm~ZfVg3sLd .\1z'8|QMvYzST%|&,Qtf '0>$N-jIs? MC쓁oU$g{(Q Q֏ۥwUZf^R1+/OQˢEYy܊G'7y(*|6C6\ I)[b>p!NTS{R5:=ds21-=sx.8FFlVg1iVu9OB~gf1vq{oaꙣ f^"@8>_DAuA%@eN.G^5A33d:W# F%3?&7Nd'HJ|Q0ޑd~RdQ(

93wT%,ڂf?R> 2 &GUu! |Y|P3/d' Ɍŀ|]@ߡt5ݔUt׮qQ1V5I~qM+(H?.UtR!n]K9lw3+{;Qo>%VQ5̇fސ =-Dk9|sNFwwF.+T~#o5xuLGP$k)7"l~GE:McHं,;|;Qt距[eΑT[G7, iD88jO>hSN $UD$N<(Pu|A>N|Ǥ,<W߮Ԝ&E+ XV#F$ta^ GRG/ݜ?~~bŴ`ְ:Ai{EՉɯJ SF}>erOoa"R;%f7y~MCgh3S0puLR `E #cQy,bw%7[9R9Yť/vGg㓓'$aOЗKXBnӢYiQjyY=?-^:c d*3>#dy嫬,WPF3=IvڜSE9cs9B)ܸP1>f'-+;$S$d1 9[I~h8ܟif;w=16"YK<;B6x*MM=tH( 6[{d Z[ U>17#Un [LJ] .,X>_y'ӓ i.\#Um|T-ۖ= dѴ4|N}!F:TgDܒlz}xw{ڵXީY?9`H댶cF8furO8Մ1B3;hڠJ/& ̨0PI`scxBsȪvr?َM֢hХd[UM4ps V؍XǵObS2LNrD)7|eD\ U tbPxroSEt dx|Ab8GFd'Ŋ­@.8q'HDCk=!yi.Nx8֨ϥ طKWQz *Z@sZ@[>_H:Fu{0&.X$#[M?-όb3(&RK` u3 LH;f(ø6o(Z9NbP[ Yb )^xqOo\~j;@)ܨ̯>!#)v1lա)~ ?kh5N^.dמN %N HSn:VV9staNtk6?vdYq&t6 ظfWlPFGC RR,`C'ftF<5]>=O1*Y:(ylyKsTώ%GM98ExmoU1ZU]ٜ,u!%UC$g:b4x]LAaR2wWƹ0J Rd-vqN}͵nԇe#xS4AJ5twFٛƾ88/U4?]oV}vs>-\ƖGyU(>hLeW(.K}Hu#ic(>86$t([yU(M0]y"yo[4+okwZ</޻rUmAK;h n).2 ҳ6<7^d^#̼R7imy}H 7~s [b 4u @)*+lZ冘\iz _' G5+$λե7mF>- թ+թ ڨ3lfNg wy<-8*B2Cޗ&ff[I*go!W&~O]j3PKyRu=!&dz[ՀLzl&mȀ(H5u`ܱ}7+4VR]XYBˢvAE4Z{c *~=PEf<~n&QRpEQyY]_Qc Wjb+CUc܉vw`Ӌ`Xy˹APqp^uMCA?7Ua$p29X꾲OxjZgy rT͉gv#bY "5A5x0C5y&3sVd`=1L(mP 9{dY9!3I( ZX0DTIRXvv,D2PL| -d_H>9YPO$ XYG ]Db MTy붠fxQ4se#0?FN_wYyq'L#c*M]\K~<', _, 9J}Ё30{XX9z2dgݩ/ki[CWQe3/*YNXMaqGƞ躺ѿ Ώp<↌g˚o8Ȑ "o9%y$T4q!` =YGg㺂҆jN≧ld%x6^G'k:j3znq\I)ks`y[/Y?-uTeWDȎ,As)!4eJCL.bU&0 G$&Z'%j[1V9Щ{gjƶKK.*{&?([%gpuy&?wG3SŶ(|V} ߡS Ydp#I*8G c͍2w.=&5Z>6u)Fn/>Z5OؤjOnG 6q[6OAs4q $\Ĥ M.p"oonwx6d7Kא 2-z+$ra{ qc5TV8vӃyv&ܻ=]{+%98^YV#aBڼIL'J w5'DѼ'}>#CԢSc!Qa.ګÖfWJHƣnbaZx)j!kZdᵨM :sX{Qtʠ ]Eŵ] нW%Zw/Ip ̣&I1oѷgΙ G Z w2(?,X =vVcK@/2]#hSkeoPik*bQ>W+<4^ߣ&v/͌)u3=-!hBZ X"\ӄe90,97_@gB浿)5]糳Vrh\CBϕr1H/fG5,Ѐj-d V]ҫ{˳(l>K|Ga7=M1uMmYew~d[wrF/7 sr>ɸj5Onjaj1n8PN }@4tpC-DQ+B{'_; E'蚂$x跷z2xg~l[,GgKTob 9ǓĘA ؖ>k_*09@>GfC%pjj̇QյsNmtD 6]ko2v\,[*dɎ6})=x Af^vR'=4 I@ҝj8;m}CMS$<*127RQM_73>K {6Hi62ID?}#8墀/MWE@W)X ߙ'Ҕ2^Έw둧-ذm!hߛUTE2υŲKZBl;I% b/ c%%Nsט ]OT "8S8^gZҕ%! +KlEqGg.اfB$۔.pQiJj*YNcTZM) ^b~§ʻp4BAr 9dΊaH) ^j)~.|2b==\q*!˂cie!68L~A`Dt<4=s]EeV?Krk e"˼{٘ͺ / Pib/V2Cu ھ>&5x\:`˜tdz"C[{=۬5Ɣx7ԃTrpx!O|; ? *[嚡~Y*,2))uX:]o53u@M,!;.E,#`Z*ic U{x W"Wj$])uPEfҼ0m -cY-f`t|M [f~sř~'UG0yqE_?0Z؄5>.{5nҐ&fdsq ZmbS Db﫼({Ë.#M ($`:-f_X g,\̷pʟbUGܲ7]x,5i_ʷZ .4ςwa:s'Cv>a((׈E{څMD prqD VLcbpn9d^I?T/ 8!*p<_C%RN:2ԩbȲ8EUCw&|ҡxt dH؆\D>'ï+ܦo:O=qmd# 4.IjU(Qe=R w 96eޑ}u3'g-4+Ee<С X>,ј k:U;{=*atd%D|LyGFSX-"%9Ik0&8Uj4&!W ݞ%`f>V8\#MİEppЋi8 "0<剖g2Y4)%!&n$:=tLKqce{21IBû/5g9c%c.P !d]U+,zD iW_r*! ]}px-fb:;Fh1; M;R1\Ii}1ps׈̝V0 N~+s6b)rڋנ&I<>dvS=W.ad !ݟI|Lh8SK zL6 aʱM_-ncˈ@E?VJ`>|'iLVc9͕JQ˚TfAY/ D"j'6"sM;< s->~|:G/=Ic ';y F8838,Vf"SKіΒ&D=8xCK`TV.ʪOAVbdรK`J=ǟО8?ThOizJ ެyPͱ5.3І.JƂ+m\o+؏sHx~LXȥmww\V"R?=q(|Uq9~n$No8EKe)Yatekߦ8<"Mq;Ntv!c؝t{A{,$(C/MO 0Ļ`b|1fV'&hLh^ZKÑ%5R`hR`4?}xt@>^HO0n9 "d֣\k,QN2AS"}AD !ceqCsɚyCi"; cÝ &@o0vW!U$ S;~$D{t;u_`ܮx3-\5}mjc1mҮS]4=MUfs^J\;Jw JL@{Fvmz^οӯ /,\vu0j3#|bq$4=>@[@s٦JKyR[ZG C,ZupE$H:]d&ƤjlJR#)ySoZFD6K^K FG֨=EIf!G\0o+4xm~=_`Iۋ(-#2~8?Ve厓֪mt\{$כ'S'.D9[!xAN΋1uIŏT.;7CjL lz8t&A"-ŧ\V&[ 1ijB"35:PB.7'؞ʕ5rR8 gte]y%\B8W+|`cFox\fD"c^{g!3Q6L=/(ɵLȤk8mE sY?I.,nND^Y5ӡC}éT\ؿ=a\̼7Mc[ 5*TkJ2^>!|ɇYxzi3& UrPIJI>ěn\M#m¸O`Dƿ@#Ju_fJ$isa֧}Ƌ6"w)*/O}:LXE RsNǰ]XiYi^Hl4J765LO^5 i~OE,n4exJ##PyMpRm5UȔkq+SW~=`d6%9Aj[ M!/rm=͘LSPU ꗰA<"w[0'S̕^UbbJVutrC?:SV4xTq꜓kX&l0@uD=2FX +V1HuQs=>`ݶqs:G)mϣ*<['*{GzQ%4S~xjfa-9l ^FmU(M7@b.+zR[ik~YJb RXUEwB_ESVsY] <ߕ\sgjKPr(X =$_x<՞I!Nsz Mћ5GYZ=50VcB@ZJ[v{W]sI\xCM3NIH]{ "rrnKOE `V>|\58ʜZY"Ed+Kayj)Jބ~5J?p[`iOȕ!`N_+h70H*(sn77o8q u(M5H gf4њeVʨ fn+ҹGq f3.C(?`-].Ѥy$ 1/ntZ:LϧxDX&$-X dƙM5`8sjboϚ#t|Wˣo]PojZaGP>#Į.w1!D:d؟׬O'c ʼ?pG۰{ʶ@ &([ cO%`>q)~;zH= ྥ l1x7}J^5Jz~Af̋U?M1+j7DiO3L{#jr⫙bZHX7QF \,-~1A'(3c,@e.e=APNA^'>}ii7&+>pBHxpeH]C<ڎgTUvNoOoÖ%+дe @RP:ḫ$P_*|?dhG @zٗQXTESuEww@iZbVr)oJLA(1ˁ]C$rUB(ьfĸ㆙&@`_ʧW醚2c!#pfm66-B$$FP"$!FUhcʹܟ$-9"|L §]xě^YG^@%v 3_TjL2/UA5cɋ1R_]s)~NXuO&ş]ݐWׂ7JaZ[ r6uV{# Rj)'䊎v‚Z<8ߨfQ|)ۗqRrQԵ s}9U<Ε</cSKxۜ|pԎ1^%1J@zbz!@:xl0ߍڭ g}k'em|^Uk@<뤝$4g4%H1+Π2 ##UыSlbަFew WZ"B'd8GqfHyDƩڿH$]>ʎᛕqȍFNkgpk lF($",ۀG%9fjg\d³ɑ-BxS OjTLXdքqfa)B(9%@3V.ٓmPN_qG4IW~e Vot-ɯ0V}W/=ۆhSЪի>,R`]$AMgYH?o/1Zknf4_\.zeÏ@%㢅I=}P12ȥAH[Ry\04Êg բSp̉PDS]S {ܑ/H\gGc-?ݾՖ#z42`a=jP/9PW2ฉzRS&'ij fZ|\ddfTcEлS_.;30݃OdY6W߱<ȲF-u7`ᵆiYEyn_nHЯ 9!~+Ixpk(Wiʌ(Cl"a`ӛ~ ,iviW&#H9RVGlS%X%s b4ծrUE>i)L]YdV >ub=gj *f:3@O?(Hft{@3U ZWb)tc Z8(F:?6UGy aDC%a彂 .*ZaZkml^ FPf%Bir\fj& +tj~!LY0/v*s_\I@GOmt s.:ԯ,{,|Q`e^v}G(Yaɍ(_w/~gDʼnBh"L/m,)+(I~Ei yaݐ+* a'(ȤjЕ!N1z)3$tGV2:M306JЃ"/?fLʥGj;}G'"BA}`j%Zl@|_N(0hNr$$3zn`P2ك"ϓ'_hu\_++sOkNGPnMM$-aR52 k(v}xnBUSDwolݫB"{d1ܴ0CL $06?JB9=l ZQ*&m­ŋR4$t𠈰,3l;pz{v21 Iťxς0wu9M '- YW^rZ)+&ĥQ9+ݜ r^SPרSц,$7kW&fVG6~ adSíMoxdGfh 7K.G1vC,0'=^F-bRQxP-:\.v hvJ*y56{5^hk Htd~ɩGrGm dPEeBU Kex3QW -qXK4d8t-͂=D.:VS $[p\]qXz6&Zب'qxB Pn} *8jboDoM'#V|HDrXJ4VY췞'x}HEncsIJ-vBYS"hm\%m <&YT=ׄ;|Ο&u-n O:qaAk( ev֋8;΂\o.{I}[fcNA*SZI"tWRN![l gu6DK}rcQ9 M1e){ Z-2@[ᳰ%D3é8x6[x=٢ 7"SZUGXed`_l۲S`#,S9yv2y0p愋nJ5HC:|kUTq rcqKEN~VDZ~|` `>43+rDn{!L6< 6.IJI6FU%-X~|. 74/qiC j35yme[ H>-%(n3!_,O4^4JϪ#yȈ3@ t!fM]'d6JAs1t%*;[ 0:tPp} >WS 1(ϠoSj((v+޹I6UH -`ն2ZETAǗX/z"CjD{e7qo 362 9{K&RuN G;M0S[}Eb2u!\' `_r&ƻ7rWu졤?QVSY龵r9ʇ~G^S9!nY;^Hڅ?ZlIDv&q+P)!bF}E&v?&?ԛJ,V}wlmy{T;釀l{oszf 8}ks:egtT $¡8ƕ9ᓗ7(3:HрJZBnL@L3zR@!fud{Z.c{:X =t+G;KþM.dŤ0F#QB'B+_*6Yb;1uLco4ÙZ~]xm hz/b)֒ZL(~Kj*`n5=ǼS1 Z-x0?'=Bvts`DWjj|Y3l5dK/Z-.Q*ƃTmA8W5bWT\?\J G$2ǹ)A(RvՌc3MntqcFt{П/޷9o  Ⓔ"Hs{=3g:)Gs*1:F?SsslÝNYxg8.i5gR)uIobzmʁNnl@j~QmI2ʸtR9 RKSz2yaPzlTb$#CwXɿiR54Z= $+hP>3n uP,WPJ۽.irL,R Q[Sv 3'`EtY9 UGn\f <rLC;K9} BqT dOReTv Xu* 5S'NKIҮ&eN%Ұ&wMtS՚[ZAT^Ma j$?+ RoʹI/c5Gr" 4(X$,x+@ը 'JY!vq=(UN:e~9* /'>f4|ߨ.d}f=!Z?Rgwc]XYt7D111 N+Y~>F)gN` )&hY;8MgCwd+Tū |$PK/=Lh.^V+YAYElҊ5S>: YZ