pki-ca-10.5.18-16.el7_9>t  DH`pa,w$ƨ8n"ok5UCNp$hW`8. bHH5BJ^z\ ˓Is)I$׿T/%,jH=۵Z' &&Y+"}ڪ1p0Pt8{v.f>fKwN36%'?A@~e,h_\ 25Zе&6"\+caM{?.&yƗ^En$OӮdȣ-@wf>京წc;G&ڼՈkVMp2;d lmx[vH%)˫Ic fL3ZyaZx&ݠU+!c '= H78"P>z'fN<=3:Sn t zi0o$;=٬/j~OE;vI'%eнvp,gzbr~oHD"؜ɊҒ z>?'O6ZRM&4*/Dmv`Qɹ:/9uK3#fGїMijgX*>=M8{ I=*?aT{v-<\͏-![y*"C1.ǂM >m7?d   E        , J P Xii i i Di p-i rixXieiri8@ d  (I8P9:GiH@iIiXPYT\hi] i^b=d eflt,iuivt wθix\iCpki-ca10.5.1816.el7_9Certificate System - Certificate AuthorityThe Certificate Authority (CA) is a required PKI subsystem which issues, renews, revokes, and publishes certificates as well as compiling and publishing Certificate Revocation Lists (CRLs). The Certificate Authority can be configured as a self-signing Certificate Authority, where it is the root CA, or it can act as a subordinate CA, where it obtains its own signing certificate from a public CA. This package is one of the top-level java-based Tomcat PKI subsystems provided by the PKI Core used by the Certificate System. ================================== || ABOUT "CERTIFICATE SYSTEM" || ================================== Certificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. PKI Core contains ALL top-level java-based Tomcat PKI components: * pki-symkey * pki-base * pki-base-python2 (alias for pki-base) * pki-base-python3 * pki-base-java * pki-tools * pki-server * pki-ca * pki-kra * pki-ocsp * pki-tks * pki-tps * pki-javadoc which comprise the following corresponding PKI subsystems: * Certificate Authority (CA) * Key Recovery Authority (KRA) * Online Certificate Status Protocol (OCSP) Manager * Token Key Service (TKS) * Token Processing Service (TPS) Python clients need only install the pki-base package. This package contains the python REST client packages and the client upgrade framework. Java clients should install the pki-base-java package. This package contains the legacy and REST Java client packages. These clients should also consider installing the pki-tools package, which contain native and Java-based PKI tools and utilities. Certificate Server instances require the fundamental classes and modules in pki-base and pki-base-java, as well as the utilities in pki-tools. The main server classes are in pki-server, with subsystem specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc. Finally, if Certificate System is being deployed as an individual or set of standalone rather than embedded server(s)/service(s), it is strongly recommended (though not explicitly required) to include at least one PKI Theme package: * dogtag-pki-theme (Dogtag Certificate System deployments) * dogtag-pki-server-theme * redhat-pki-server-theme (Red Hat Certificate System deployments) * redhat-pki-server-theme * customized pki theme (Customized Certificate System deployments) * -pki-server-theme NOTE: As a convenience for standalone deployments, top-level meta packages may be provided which bind a particular theme to these certificate server packages.a'x86-01.bsys.centos.org%'CentOSGPLv2CentOS BuildSystem System Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch=m+1l[#tR#1J6 _ S }F}F+ g%~~[G7(b)[J2 O,", +Bf PEml]P'nz1{{% *S*L$,kI,A,:+A+3u9 #%##"vS "`./9/]   Q q >#E/#+{B/'m)H nrtknvpyi  *L*?5%C%c*m;c=O? 9%9RU][  T \71 0VCCF6CQ& "Y"\><bc q-  dF r- ~->E,g>QB 1"?%I7Px]%A큤AA큤AA큤A큤AA큤A큤AAA큤A큤AAA큤A큤A큤A큤A큤A큤A큤A큤a'^2a'a'a'a'Ma'a'^2^2^2^2a'L^2^2a'La'L^2^2^2^2^2^2^2^2^2^2^2^2a'L^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a'^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a'a'^2^2^2^2^2^2a'L^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a'La'L^2^2^2a'L^2^2^2^2^2^2^2^2^2^2^2a'La'La'L^2^2^2a'L^2^2^2^2^2^2^2^2^2^2^2^2^2^2a'L^2^2^2a'^2a'a'a'^2^2a'^2^2^2a'a'a'a'a'a'a'a'a'^2^2a'^2a'^2^2^2^2^2^2^2a'^2^2a'^2^2^2^2^2^2^2a'^2^2^2^2^2^2a'L^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a'L^2^2^2^2^2a'^2^2^2^2^2^2^2a'^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a'L^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2a'^2^2^2^2a'^2^2^2^2^2^2^2a'L^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00e5cec672fc60ab3856ec0c8eba6554bf46a71c2384ad1eb376a5868f02b57600a8cc4d68b9f6f2d9f12bb1756fbb9bdfb34fa89f0930187032b271315665728150c582ecd379d442745e4dc6ecdb90cddabb88b8105da6d2a3afcaf947850c0fc11a3352de540f4e0681ebceae86ef8e7e17c4f8c0f90d500629111f5d265f25386fa50072f26ec25460e3bd969ef5200c3454c02dc9d2a1e84fc0cc57eeb3835e785c0a3c0f8351c3e3c8dc0d0cc2d164241ab800c121fd3c40147d63cb5139f276451224c5d8227f40359f7d5367ab5c27bffa0d734cb4a25ee3b31b8ca77da5a1829bf1b3c216ae4c9d4ee066772bc7f5afca577935c229d9bfdf80d75cb7d0aeb78397f439d16d5b530d8b81c119af865c0898e02a33b17d28d0bc57ae9c85df163a6cc55b9c0e1f32f2a347d19c5f9eb02f3bd07cbef7dd25c8d86e3bb718ce6ab10819891d1d8fde23cd1c90b6a065c008b7f7fb43733aaba5693b054182a158a8f0949c10819f646d42e8cb710ebd844362d97695eec5a6a523c9718a1aed1ca83010bd139dcbfc328398007d959d275a78df0c0208c207e960ea669ca55436dc0723559afae54e63e48d826c2ee0ffd98b3233b8c132be6ea1540cde549ab16a5ee0b53ca839bcc06b9c268ac7be7c8186aa4392ce0c663460c019e4cead500b0c90a7da7bbb8602f999170020f81dcfa03d16a4a4d9caf259911676449f0101595c93b29c3402277811f70fa75237715687fc5dcdcab36f7a7c8dd72da64a1f054f16eb1ae49493bbcbfa138127db6a09fc946014a1d137d40ca2d5c27ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d155ec67643ebfdcec431c7d61966510fefc3e691ff14a09438257c5c23fe66d54bb14050386b6df46fef8e6214e41579d09c780d19d242741f29c2809ef973cefeb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f62024c52fe492fc10e9af7a7f3dc2f08daed6d3f5bc13ce0c8bdda30b85f0c69a57b7994670aca2abb02cec14f3334dc5a887b85bbe03e19202a045111343c40a9d68f40546ce9caca6b76801039b97b1a2c53cb0975fd3f31dac9584a8a955704363832241c679cd009399b6934aeedec0b3755f83bc09a35cd5a292cf19b7525e0bffd207c4c5b122b085f9129e0470df5c37cc534df4e30ec140a9406a2850767d3c20dc56e7c6f0ba342130b0160dd473330845cc80f17f5ea872d0fd5031d37b0ad740db9a30932ac53203a46c4e4fa701f891d74fc185fcb8989f45d28cbcace48ed94b1a6cf7171f5ebe150102c2cde343df5b89acab2c2a6c29b9a04d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898c26d1e3ccc9375d6256e77b91817081f349ed0b5115ce58d43c2720c3473e5e4475b616597e5ca45e6e816149748a4c7fd6443ed8c585e675afec1f5317959ac93f9de3ac67f7ec677ec54d3e5cda612b21511aefd19e338c7f06a05c29006d6be1f16dfc4891efbc5f8b12d38381041f75aeef95dda09a3c728bac964a8660a1bdde4c0aefb36f1162726bb551a958e9ff0de0333133702e0312e1bbe8c64c60f940b149f3278ebe2f7040e9224cb5d49ad2e896b807877864ae209975fdba39fe55d9dabe5730b830109f5d6bad9227eea0387e9b425cbdf52e9aecb5044ddf44ec05cd32ac643ab96fbbac60177722f9b65e9e88234e89c434a691e079069d37b318051ba08e5401817cf220661cea7c9468dd5bf0c862f246b1d80f21c7a69acf0b3197a11d03adcc3a6bb604040047d335ffa81c8f548aa273a4d3cd67272590ff8bdf5c4ce6641c36030342b5a32395173e93bde51a9085c5df4d300bd66a4eaea68a3aeaa6f2afb66d32d060f4b66364eb137323057b41e15317cadeac4d6d5acb20866e54fee85799bcd373e3e1730fca6964bccf10e8013d3a17e47f96dbedbe367692626e7e482a595b66f3d8d166cf030208d11fe66ab03a23c2932ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b62ba6e2290c7c90da1fa7a23214b457d24fb03da037cdb5760e7a8d0cc402d5062ce39edcbc0f3951007855b1ed95d532e0d4ad8e3d9067a9ce3338346fc111b6b14b9f7733adbd8910b925566c7031f9ef5d4047f50445ada7a0120693e441254ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91b3e83dd6fd1336b0e2e1a1826f21a57a176e053a043aa8c0c6f2321dbbaa6f144ceb0cc6142fd93688a16af692f0ea833fccab83ff002b27becc311ae4c26c91369297a91044bae9d61a8f61046e54fa9059a66f2c5c4bcbca9fa651f4c5e605ceadedbe484214d4af828832b12d046b1c3fabd6dd2c6e92edbd7c299c963a01a6e93e3ebfd7fd88da8c1b24ea4476e495b9ecae27c557ab8c7ecc8914601f8fa66fcdca8b12389353b0dcc4d49ab89737b638a4156e04ae83b7fd7ed195da17e97415f495943ae49ce5674e09006caf13a8afd978884edc44157639fcef3a6e5dd07496ebe2d7f236624fe4ff9ea4654e533cd6f136e276f185bc4ee75cc6a63208f569c98c16c37c2fb2e287b55027ecaf16ea80449fed310725854dd848504358d4fe7948b0d5cf868fe9304a7c564127640a6e2aeac5c3a536beb0f30fba963740e1b6bd2aff4d69dac938811dbdb5d5a49c12b1eae220c314482006e9b14803e10fa13c8dfd44cb429d356a3603c079b3100651e429f5bb76d57d8b42d1dfd602c67136a59e64f6e463f78538691537a4d855d1034cf133218defd3a3c286ef3b2ddd73eb2a8e12cea6e1f6adadca373fa81c0f7c414e705ea46f3818ea8aef2e39c84cf8dc8f0af8abb56834c98fe36820ae871266d08e5018aeb4dcc521c9c398e166d3c99707aa883a5619dacfb98c3ce7fedc2a8702e188ebcd349e519f65778c5af41e0d14e2de103ab29f00cb99e1904b3bde1395ec5fde92c1390815093c1c33be89fbf3192f503fa8ed572a7d3719461befe87107a42e962d4adc3b45978f03f3b8724c1b89e36ea16e26e494b65e240c4dbd77198021abfeaaa80f6e67824852390447027d20f4455701d32e17ca30d2bc02a145d5dc335c5dd2484024db29aa2029e29e5c87372d20e5d57bdc9eba046ba525571e512a8d55ff6c74db2c9f816beb79eaa11ca44d91ebbad302da7e0e139aa99c867201d7cb2b5b83fec0eff7472964122f5fdb491916fed8ce15b3d179a90dddae767695d7f153f1da2cc4da0c4aebb58a3e85d0ff03fbddd02a9c8f28532f28fa8729aebc24e02c5ae1bbc67962f899866ad4aeff14c6d9097ef74a62b0db13c62b3b948b1910f6e156c5d656b3d8ae6e21f777e1a1dff4def65a9fb7493202db1cb41721801405498a15b16d373fbb8fd98ade8bc0c64e734d9b60caa3b7b41fdc8ab76318617a98a8a72661aa99baaed16b2a895766d878506c808d142b9c564fd9f90bf9f7423c5bcceb5aa7338ce528d057e1a55770f4f47a6d160f464bdd2e5a9a15b6df37a15ad28ff8bd1d1e379fa22a0a58b1462d1cb2bf6f91c0428442b261eaedf631f22563c6975207fa0651d350c9aac2064c636dbfd059a1c001014a7a57fb30afe2e8161acff9850a5bec7b0249448891df209ced0b38cae1dfe11790a5bef1eeff08a5beed53ce599b88479fd2a598a73e9e386c42d10c44eb6312f27403dc03ebb5131110972dc559286d504459480c6f30bc1fae30805cfeecf5a44424819425d088599d31c38f93071a8f888325055d9fd241c86a3a158a7d4ec5d403a32df2ecc86fe1aa69338a4a6e06d2d643e34acba65ea5c001f851daf5dffef55a1765bf7f3b0ca4bef450a8f796238b36fb8489460501bf94e91f1dcf5fafc74904a2f68124a9f013f60bf839a93264f7fa1eabe952c15f22a6e370963c902ca978def728703aab9cb9f2fb3b48731fbfe760a43a258c3785c84ca4be21fb50b0842fb84ed2c8445b5cf38f87865bf1d65ef7a597c15178cf7904e805547fd53ed053101f654722a90c7c718612cbb600f0e746904cca639c083ad44adc61d3b7602633f62681a0543a4576518efdf11838e94dd637e9b7f48a5c9b4e2303ff44b354cf3d8d22c802cfadfe0dd0334aca848e8984b34e92b9f696828891e4f016817ea2689a5402bc8f4f2cb96354c9c14c3bd20214668cfca82e0f1f4c7b29cf0a9749962f5364222fac9a330306af9dd905f0024aa5a1e1561a663ec16fd58a28b0619fa2cbac29eceee05b20b01097185ab19ae9d807e384a743387d27fc0a8d6d897676617cb203cbb3d413ebd6c093c27b4e3b4e86280b85d928dd21640e98a6fbff04f6d46220c0bb33a1dac4f66ef82fbb59b77d20640a54d8533590ec3bcd1a15d8f8190a27a687e0f9743e5422b91e23cd3670c0084032a94a645dc7b21e0b39090e6c6f6097d5b8708db4223a9313a6215b2e5fca1c539d4e5e3477fd81e23e2db0b4c4e33b16d4d2323e17dffb0656c598561f9d91ec04eee8f89ee8bb42b031bfd0f2aac1342aa2a5ab324f8f6181711d9172bef5dec9b4e1b2d5cfe69aa5aebb84a5a1637aec3ecd0ec88ca2eda7fb5f6bb3e067bacd789eeb5b9868e47eaeef88ac42301d77271667035e5ef559c4f00eb3e29f8dd363c43a4df10efd9412fb5f45b5c9837a9e149d0888593569c4969f51efcd61ea6abc2164637a032954351b16d51241c0c5803f12712b5043db034b4fe6ec928d6b57dea17970f7e3a0258e8c04d0a0156c19446f69062dd069ee1967bd929eb6438142f12dd081e5f9a45a2818963ea17a8d41aab0e9a951cd1ad1bd5b9c48858bd6f3bbc3d5350d5b2c15101c9869718d0e248a6261a34300f064a0011daf7a7b97fcd57215b937380865f10faa16912e9cf7fcc6c8001ed5ccf7c35889765811a449166c80fc6b7b677207fb040d9f7de00541f77aa74747b96a8c199e368a40ae7f8cf803c974c90bab10ec4d6af8bb034bb857d35e21f13a766f242a999b72ec4530ecb668be6082ed25f15b4b50df28164dd762843030bb98e81eb93b3d1cdbb8674ec4c8dfb3f600b90367bec83498d9724204d8e54b448583d870a563a74d08f05f45fc39626de7e17f2b9dc8ad6ac85e7b3d443767e183cd06212dcab461069d6b7456f1a7305335ec03066f3ea46f1d707a59830dd326fb2f2135f687984bb909cae523b0d8fc8aa095e59c31e5b1a1ab748de837cc47f311083b3ca72933082f4a4fcf0258b724d8be2bd7c26a70a7ee57686804b4008d4855be3d7fe7337ae43a49225c416f3a0fc11bcc7e6d5089bd03ce69902e13ed9208464a6a1d9f7d81d4795a672195815118e2584314098a023c3f249c95fe0173d9cac292db36550a3fbfaad2e31234046232cc077308a08e1780507c2549caaa07960a3bffd988c966ca03b37de84c114081aa4b31fdb94c7e07b8c00e726c312cc833e259dfe0ae3aabae0cce1d133c3004203650fb5a0a17375f1c598dcfe22d7b8fb04299ffcff251bac5ce33e8319ce83dd0bb7d21aeb387e17803d3e8db9ae1018fee9b3f1400bb8f3b28b996b1bc599f09f56dfbcbf564def419d90fdc71eb17056a9b8d75561de315aecdc25d0157968bdab7af67a9c60de9e265016bf50b9e293821ad58abf7b6d60a2b580a27813648843f4d34dc3120f48da361bab625d830ff8bc6c8ad5a793937f191b8679bc73170aeb5dca7109bfcba14a1e08eddd916dc62f4a693d3e8e45599d04f399102439436bceb4377f909c3f66c59877a083a5fda7898d9e0ac8b3e9e81887ed077758d05473cfcddae2508d7d2c77bae9dd2feb5d5c28b7f1a2d3a7036822329fec825a2f7d4b33352e9bdb5c8a670821dc6938a8185acf80285dd9c95a0bb6eb9c601b49660105d08784c52aa8ac453ce9e2faecddceadc43c59f45f0363e516facbebbf4f9dd59c307f5d04cc31587a7ee46977c98daf2a1507401550a16ef1ad2fa8a713ee85fbcea3e746220fbd9f31057112ff4f210054a6054984c3a7bd25be3d41744abdc2ddd9b3191783d460dd792439ca7f920cb7781404a4e41afaed4c27eb4788b4c3560fe15098927b159c3e26fa0212e2996d1e54db9a388eb07c1e94be78beceaa6ff0d36e3d5162f7dab7ad023de47293cb877ab808de670f28d2bd6499dbb2d357d43afc7cd23d86b4bdf3aa6974895bdc3bb4a3908363d61c0de2c934c1d47ea19483de74591876aab55f72cf4dfe9c88969bbd762c45a42b91b1396ad011b51fd338882a6ab602315cb7bff682ca2f5a26424d7ab5ce178c5b9e9a25d855ffc52e1b5dbc957142da46ab2e7ed49d41f75099bbb3998283617c5f590304ec64602cfb558ee28a6627008f27dd6e39d2940ed9ca211b2e9933622b08eb4dc4ae264f33952affdb1a2230e2ae72a904bc8e884cdc3e881037753f8918497e4ba574e2ff864e763a606fec3c2c42d5dafe7ee2df815e74f2bf84431f262525b45dbdbac0117eb16da3dbe25589ba27fdb16be3f624c580af8dd2e8136bef1bcf4019b9e820f9fee1ca9617df39135b857b478484f1606a9e54287223c2e6e8d0ef28e085d5d813a55de04b13112a80b9e97ef0a3492fd9c2bf504887110842ee75e18c114a2f01707be3862f88641212046222c357f82ddad68d899645f30b9a0e3411d9fc2f25ae2d5277a8ed29d19043a3b0fe056eb8d8c9a6ae446a00170d442f2ecc7c888dda6869747fe8e98d26730ff60f728d0e080cf63e44ec0bc72932c375894c729bda2b364a1272612c2005dcad021f513cc99590d3eddcbd0943208feb340699371199f997cf783a220f9ebf0c577f5211d831d28470392d0197189f131ca1a02c4ed8f581a131ab78fed3c28ba57a9b787edccc00ef37affcc97ec2533c8c7da5fe36aebe0ec8dd591db70d50dda2f299e8275406d7a9bf51b0658585a85feedae530189b95f4ccbedef04351ee61678ac468a29a45259542db3f0064ece7bc6c142a5c837a3f1dc88f8cc2e6060172097715954ec0ec652be99031c4992cd6f36eee6c911a9ab190ad2b2d7035c3b6210bcad1b5bd0d61ca737bf71e916f427c8d31608979a229f9453b1a59f1d9745792e11756f8bade632479f283837a0631512f8e5bccfd1c96626614cda4cd142db5f002bafe95c0be41773d65be80d2e4893087bba63a5f40732a33fabdfe321b102c6ac91cb5a71f653bed7ff0363414697b7188d9bb18c6f876290819145fa62b01487d8d336ef7432108a27ff2dcd1c2a1f928d33de86710f05b5cecb5d841822f94a7c87dabfbf16c2140c606ff3a9be325ad994e8bd6d02323c345a7f33b818493827c28b14cbda8196220c04eab3503e0d4a472ba33f7e7bb3f70f202bdd1c22e5f4c009aafe30d35304be91d9cc0df86fa67186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631ab9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901db8b5efddc795489b9971b83de53181631fafa8a4ff4e947ecaba4221b793786563b3dfdcd62f39e7ce4cc095102ec2af345a2dfd680dcfbaa5082bb2aa760182b34c5011b9d513f45561ca7912338109e1f053dfb2eba6c189f36043477b7e9c5f6bd93049e6a50aa4e2ef845c2ecc57b7c6af0b530a0483ef356a6b25403c4e7be438f97bc93e0db6beaa8b18530bdd0437eaa1597c589514b45e8d0b2b37490cb979956f60e953d627512ccdddd9603422e3a31e8c7a198f7adb725c2f5a449160bacaa9e40e728469050df5dc0481b3b19570152a01ee8c0dbdfcda5de202386dc5631c74d6d879ab522218c9dc73f6b56b65e84489ad6fa0c00b56ca99d16efc037493882bc2a7ff8684d7146f46f9c33f878ff7abaa21a236e737274c027ac570d8066c9a1e27d543385c08cc6e01c9f3970be6e184bda2b33b8b7d12c29844f5dfc4dc0a76253f66e30d55ac7cad9d54fb5ee25cfce90b2db8f1bb5542439a98e78f686688192339d5045c89a7c444ab265943e29e4ddb2814bbd2e5f32cd314bbad9a4fc256d21388e37ff2063355cfe40fd08e428eb00682c5b7121cc4ed50cf3ff83d76d2f3593d6f517835d0108bc192391b370a734cdc2f360b4607c571da9d704c39ce0b67c9ca6202bbcb92c26f338213043e3b36ab3fcdda487aca0e763cd5fbdf40ffb73006e3f1b38cafa9b2e48c19d616b701d439c6ecda6908a86cebf2bad69e4ebd837f93f4065b4d5ca11a5c0772167fd9769349be3ad33616e6dcd80b9daf13f9dcaf8ef6bc30f9e52df3da8ebe1393119b9b396c5fce3aba06387028fa21738a84e5d1c9ea15e75ff88b8b61fcadad11071b6131243666e2e04fc44d87b070697da0b91df3053166ffbad3e9603e116474d44ba83c56270532c0fec2d29862bab16692a5cb07943d9ac3be7384125bf8a087b58a6ce9af014875df6e9c91933b0e915d18825853bfa5f6aaa24d91957003503006412ad601f7f6e5d950eda140367a30f221c31008caf4c2712002aac3a387a37a98578cefe64dde557a4e36f9818cb66b18192034981ae4b1f5f392384d5f85bf6b6f562f0533de650daadbec4a8dae34fbbb56e36f87e00e507633e8599a4a9b78b8a244521bbc3a3c1e46049181dde51098bfbd4aa1f52e2ec058f907286b4c87c6552b361d06eb8a0a4b26a327faa8d2b6d446ea046a8414183e0b21a470e83555ab6aeff375b5660ed4cb0848ef1590130b1b331b1557bf37ebc4ff6e1ee9d90dbcc3cc48b5ca5bce8ed7df74cc4c2381961c9c9efc99efa0e427e7e1587a4f6673040246e3f1b800ef36d9dd100432bb957e899c5c37ae69be80ed4bb982d2380769057cee6067962b4ffa4b2cf40a6e5a732493f054bd27796ad5d9efa55bc8f59fd674f2835d9c1e7b625fcf076e7817d0d08c6fff38325c95073dbf9cd23ded73a65a8e569270b03850a6b9a9eb862bbd4cc8188e703f0e05ce34668aff8ed106f92206e688e301a625a06506762f07a9aced94c1f6c2f093d41f08778e8ca9059c14f314eb6d925825f834405c62ca90be20333e09958ea265ef5f6c000c5b62200ededa13f8521e87f453fbf48d6083be597d8a680471b7d41d1faea8fa0a67d87b4e3b1ac73cb9dcc6abdab00609398306c79ad2768adf66a6c9c076fb1c0d411571546ebb06736357218e00172e8ef00ecdc92587e712d04091e7a5f7805c2dde8e1cde90c570948c508e1e4294e0a679ae5323d68f551008fd9fa0a70929e47b1da01f19b724c840eca1d58cd30f4dc0b859763ae3beebfae87cd34526fc2eca66ca591ffd53f81b025c989f94ee3622fd8bb54341da3aa03208fe8d183ef96002869cabe74e3c0d81b49d3acfa70bd9f087cca5f74ce5bc18ec1ccb624f4d281bab848e1c617e716e922028fafb014f7e5f13a3877108c3a7bb4d67dc80bf0bbbe00134fd976901defbf35e10746a7a77d6cc11f88850bc66c047b2005f1984deb400e1a5f8d832c6da04d11caa82e03bf1d00c372c789a7a437cca4893de17d17717535ca11d09774b350d4b963d18d0c3ff275027f968a2025b3a2231b0e1d136dd67f65ebd7933a7291fb2809e0cb0c9f6b5153baecb3827282e259c1dea0192efc2b69481ff941ff7247846c1cab4d20792509907eb91fa50c9135ffba3e38a8df976b6646bbc66608f845d18bbd167af2cb621bede3bb3567b41567657e76727f9791934052c688752bd07d4afcbd7df95a9ebcaa5795e30f706768b4012c802aaf1fcd6e99814067613394950d130f61d06f25f3257278f90c791ffbad5b4ea62bd5a75035961619eb55973afae64b64b9130d3aab85b28d866416d91896845f4607d2099de578dbb060ddb83ad681e6ebeb51e184a4205c01dfd6652544a65b8d1895d26ee151f79dd076467a2655dc6a388db93697bb97dd2f128cafed56e22d589cf18d3a8117b8b82ec7840c34a149b833038abb5c1e08d3d1a22190b2b11debeb23ce1788f781d2ee4855bbb5b5b199bb08462c43558f7fdb0b4af9b879662b638abe8f56bbaca7f27d090c6cd68949a7f2e6dd41925503abf396908ebdfbe5ad1f2a628ac0fccff016e72febcd204a038d3b1bcf00f554cbe65b72a0f5c6e785d27ab6c76f9985162e4215c5b0a05c560b7ca085d6662f475887ec86730cebfc26a446ef314e84f39e2a916584c14a57509f6007d0e1883246d746a8f0544e6ed4a33dec754464db0852baa1d62df4b1460e09c277a63ce8fcecd84fd5eb127fa3a532265fd8ec62aff59246cc3e0c538d6a720f121ec7a6c61d2178a7b914c9d7aac0fe2d0ee640061c044bfd8a20e46587ae276332f2b4c58a1a4355c85cfd5b6b37aa2b11a9d50b6b0c7a98bfaaf9467c54a80a603c94c292eae73c5ae04a6eca92e9cefb27b28c70b9b6575b8d020edc0182c327c2cdc0a683ca9f527a435fa54da421a75f0fe67d39eda25030c1dad75431e7bfbd216132b8faea363a675df98f0b7571dd667d86753584d052c6780fff621a2f6010325e8de9871d68d2d176f892fa0e4d1714da27e72a8367734d4a1d8fac65c88c70591fe094e5cadb73b5437001bc3a9775233b9e1a6eb144df5454258bffc3ab3f6a3adbeccc4ba1618b73dc55bb5ebd698940a848814cb57cb1f140b0cc9a2bae31e5d9907c272db063731e99ea2be881be14106a43cf9deed98f1e580314927e2ac05431f3609635cf9dc1bfffee3d14836e3b5620b8f7d9e5420275dfde55010069686441ab85191c777c672e4c2fd5c43e9fa587d87623d3ce557186e454bf11475fb89e70283aebd7d3b913baa865e57d465418ac32295631abdaa01be372f6428157f7767c6e507f03d8fb0698ed26ad8764efd8e3b6ec1b1128b50cd72eadcd56594e2ce0cf4a266132526e7735f8d70abe796dc6ea68723b9902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd594901b49f79539224ca82db1a18cb19f706b20bfb31275e009c30127184199ee28bab665e6b28eeb70fdfb406fc715536773628274003066aefcfc27da268f50bc45154481c944793a119c342103c58aa95667e9c067d65e0b8d63e90c24f32285ad9bb97edd4626c9f3fe213675e77a8b89dc0064e69d17760c49f539df7f6f264669c1f516d640fe9809bf2e63ceb40100ce610aef9fc4ff097abf5e513554ab3aced21e85b958da061a7d2de3f534c579f55a783af34ee1f115595c998f32f2fe5b16de77414be3c1dbe1233334eba30a14bb7b5fa3e31571f6d6219dfd34f496912e07806d8b1f8a1c0cff9f42e6433837f7f2f318a9c03ee8a947ba0416590c87e3511ada3b8e3dd85c772c4fa857de75a0d9aee3a4f3133678f99fa30519a870f7110c082dfcf32eb01c004f6e9d6c1b3e108984f9177201408040b10dd5aae45bc58305e847bf7ba35c3f97bd413925c7094c9cb9e54a9c825367c59068423a2d871e85613498231e9f4f83f178ce9cfa85da466376567cb38142168fd804c0067b93558cd2e0d9e8807e92def408b8eb3efdce5ca51d392e7bf06b7b7d5aadd05227d28bfe1e6fdd68e2c7a8f275a1d359c60fd4f3a95078c131ccf6a47b40b799d9b581379b3321c1591c48e9b3561c137a48c447b51a1b2758a7728d57dd7ac9cff1db3a58000b9c1fe32d7dd59631fffc1d5425dbd75fb4f5e99ba7c902bfa413c7237cec4bc0cf0f59f17d1fc4959b7661aa89373efa9bfd5bc9403d82743aa179b0610a98eda4b028251df592cac0cb95d8d37720f88345d471da63526b6ce8a0f19f9cf0326784128890105e9bd0ac1e913d2e42d5c01cd9c8f8574e6d7d9b362af55379c8abd0ec8296f01340f2991eb274effbb0943d386716df1fa2dd0fb957b3f79b13cba530f693b50f84234f3299d45e00fb4be60cd95d2ac4101279fad4fdf9510d2988c139ef32593b2255d74660095f38321ff6c300555c60045434f12d9e68f6f28896adc7054788724bc34c704ce8c1e2f3f5fe90174ecefecb37ebbfed41e030bfca7ac60f6739e123478434534f5e60fa3733b81177e63fc956191312c831f77d80837c61771a3d4d6d646ae0ebd9de19f2d1c93edff35a2fc6a00481a5b3919bd6883f7619d1a05c62be002110032daaaff23f0efda24c4d4e472c9a35934a2db4ed4f5ad94b9eadc689b0368ccbb1314b5993c9e33ead8aaf6c1d937b7f500c760c15fcfbd8f7ef74c9a76397bb8dff93ffc16df95866d15efca4e9bec6b29c6714e527c0f1ead076eb9fc48f233c3f337f958d4e0673ed79347caeba4b7e7ef85cf92a6666b9a2f4ced866ab018915108c754d5dbf4b92bb761d8f519922d866943cf5d07150192ff373cca89881d43a3e68d96184142fcb5391ce4431630f1217d65cd1f6a7a3b5a4a63c615bbfc018d5cf5c0e8448edb5e8a834506214be78b70dd45bf3e5925fa3fe0c0c6410c017cc6e6ab30b4e2aefcaf4932f96eb61a6fff9fa4d55de821b5183ad89a039f5628db4869bcf4d6ade0a422df2c6f8bfdfbaf7fb658449d365321112f1186e497a89fb426e659391a6ed4a0788280982337207ce1ba6382cc461026e46132f6ede248baebf4fa9223e88ba83c3aa7ba193776ab336d42955bba1fc047326d615d332a5140e09ccf4b4f233fdcacf30f533b5f15c9ef7826ed14382cd31bb55b743ac7dffc03ad234d2d5566157b62ffd2426d5cb6a44fbfbe381a1808e529f26765ba9e05e56b3b06c842124bce70635f166ef1e609e99f8ba41844e9faf93bb7a3f81d2e8d8714f4727757ce02e32971f76b129fd97deb4ef3d565c4a58d387d296f5e2ae411ca8b5ed340056f76bd372ad23f2cc8c24febb3e836cee9b377076fc3934ab0df691855f8e19aa2413d7e54c00303b70dcfd28b0708974c470416bb08d86da68f1f5dbecb17fbf7e66f136977c1b5fff486b93d4760b608fcfad7d9e567f0283bfcd35006123d0fc54b0a0a0373b8ae38ec35200788f1c1d270cc00bfbee7cb65f762ec3bd80e439cd2efc8b4e6825279fb48d2d87190a75bda3aa29bf14c03eb115a5be6b291f7a9805cdaab6465c61d3290fe63d403be79683d806b12746c7d6fd5ede1eaf6e508e3a7d29023d7bea4db67a2337127ec0e911a346d8c582299ebe6de630789a99949982d29674be81e99c05f9167813a00afbacd30bd0763edf4dd8c10a03d16e92dcc6dbb27b0230fcde072e89f6a8581f1d4c5dba6603b6d5bde6d42f80a10ead1635750c998582d4c85a9da9283aa62616dd4bcbe8900f84d5171f9ab92db0f3b27571fde4562ae3c51d103ad83dc2febf8577c156a6447de30ca5a66f4e26961cf12fe84a11ec7815c19c02f1b793a0e91d7302ce9a650e13fb81fbd66d70f0f3d0852453201c93951888d8c785d218ed49f70b49ef56dd0bc07706e4c421dfa6625e1f1c25cc00f5c21b152f653d90cb879fd1d2d864c0eaea2527e7235f5ef357810d29ac3f21de79c2fe6cac5eb5a0f53d781ab4b78d65a1764e7e7626c31b779a8ac4ea0792e8cfa95001aef51535d7bd3718a575ec70d97531470731255e0f52a907b2d4ce36cbf059bc84d31ec949fdff5ea4c987f6cf58a2ad86bb944e011439a0431c8344fea545a0e3031b8e38f8c23767c6b67f36e1824b1b48f71b3dc52d8054317c281ac05eb8506c38368b37f732e55538534e6ce61784b30d5fd24c24062f8115e49ac49630c5e06fb91fa4bf4e049d5d98c81cabed3c2069a7e76aff6c6f1fc6ed429f484fdb9fbd369dab1749bb0985ecda1e03bd067b178237fd89e2fdd6b958af8e32e802c52f725d0047f2c67a0435efee12ffa020736bee7e081dc7ca5b84a86e2a68ed1c6978a050f6077448b201d2d1c23e13e38a0df6de9a02033fc479bb9f37e6377b64a119436024d9a581c0f137add81539fe233ca5d947ed65c6cef9a6114fd6ed6ed6f6372e6ccc8e28e611e07bbf8b9c3695734bd4a1533a7c38b8c0696afe1c3949239c7653522e627fbfc8ad866648f71aa19abe71e20f50ddbf20de0d7273f7e6dd2a7fc14ef0693069e233c4243a39a6ace0cf7e38eb0988c7bd2c68f8018e3727012f2457fb91dd9470f0670e3d48e3144973967f7d31b318d8d7135566113eb5883ca541ff63f5a999a97b2a7a32029058010f7b7f1ce9e7918ed9e45408943b8f8bc606bffebeabbbd9bfafd8bd13cd66e3df6b4e77b3d4690ec1d5d5721c3caee7f629bf25910c240dc2f24d1e487e69ee2d54dfa0f74fd5364bc8b06d9efb836eb8857bc64b9264e6105b0652f2e1e4c9d31dfd0a06568238bbf6bc3d58ada9a7dc75a26de4e324f4b798b2d8938a692f25e82e3da8dbdb84b3e646de7fe0f80a185b7c69838603148905e9b55c58db1c3741e9b4fe0621bee7d5b5f7709f90bc0649902c09334fc549604ff49152c6ab93e45b2d09989ed85c9e8de26953bdf3a4b9385164e6ffdf7ed7d738e1d7d39cee2ab60f6a66893c10e12c81c6ddd59490171e2ad35b4241a19558c2d90110e52a291f4d25b917bf027deb77dfb03aa570cddf7adeb90dccd6ba965633c2cb28700fb70311cbfe3e7c67cae417c3c162b29/usr/share/java/pki/pki-ca.jar/usr/share/java/pki/pki-certsrv.jar/usr/share/java/pki/pki-cms.jar/usr/share/java/pki/pki-cmsbundle.jar/usr/share/java/pki/pki-cmscore.jar/usr/share/java/pki/pki-cmsutil.jar/usr/share/java/pki/pki-nsutil.jar/usr/share/pki/server/webapps/pki/admin/consolerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-core-10.5.18-16.el7_9.src.rpmpki-ca    java-1.8.0-openjdk-headlesspki-serverrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)10.5.18-16.el7_93.0.4-14.6.0-14.0-15.2-14.11.3a`@``e@`6?`%@_$_@_@^V@^@^@^U@^=@^@^]]@]@]]v>]R@] u@\\@\f\T4\R@\\U@\[@[{[l,[`O@[U@[>@[d@[@[o[@ZUZ@Z@ZZxG@Zg#Z.s@Z@Z ZYYY@Y@Y@YoIYlYGY>@Y5GY-^Y$$@Y"Y@Y#@X@XX@XO@X*XRXOX!@X&X2@WWҤ@WίW#W:WWt@W{@Wu WgWV@WV@WV@WV@WV@WV@W 10.5.18-16Dogtag Team 10.5.18-15Dogtag Team 10.5.18-14Dogtag Team 10.5.18-13Dogtag Team 10.5.18-12Dogtag Team 10.5.18-11Dogtag Team 10.5.18-10Dogtag Team 10.5.18-9Dogtag Team 10.5.18-8Dogtag Team 10.5.18-7Dogtag Team 10.5.18-6Dogtag Team 10.5.18-5Dogtag Team 10.5.18-4Dogtag Team 10.5.18-3Dogtag Team 10.5.18-2Dogtag Team 10.5.18-1Dogtag Team 10.5.17-6Dogtag Team 10.5.17-5Dogtag Team 10.5.17-4Dogtag Team 10.5.17-3Dogtag Team 10.5.17-2Dogtag Team 10.5.17-1Dogtag Team 10.5.16-3Dogtag Team 10.5.16-2Dogtag Team 10.5.16-1Dogtag Team 10.5.9-13Dogtag Team 10.5.9-12Dogtag Team 10.5.9-11Dogtag Team 10.5.9-10Dogtag Team 10.5.9-9Dogtag Team 10.5.9-8Dogtag Team 10.5.9-7Dogtag Team 10.5.9-6Dogtag Team 10.5.9-5Dogtag Team 10.5.9-4Dogtag Team 10.5.9-3Dogtag Team 10.5.9-2Dogtag Team 10.5.9-1Dogtag Team 10.5.1-13.1Dogtag Team 10.5.1-13Dogtag Team 10.5.1-12Dogtag Team 10.5.1-11Dogtag Team 10.5.1-10Dogtag Team 10.5.1-9Dogtag Team 10.5.1-8Dogtag Team 10.5.1-7Dogtag Team 10.5.1-6Dogtag Team 10.5.1-5Dogtag Team 10.5.1-4Troy Dawson - 10.5.1-3Dogtag Team 10.5.1-2Dogtag Team 10.5.1-1Dogtag Team 10.5.0-1Dogtag Team 10.4.1-15Dogtag Team 10.4.1-14Dogtag Team 10.4.1-13Dogtag Team 10.4.1-12Dogtag Team 10.4.1-11Dogtag Team 10.4.1-10Dogtag Team 10.4.1-9Dogtag Team 10.4.1-8Dogtag Team 10.4.1-7Dogtag Team 10.4.1-6Dogtag Team 10.4.1-5Dogtag Team 10.4.1-4Dogtag Team 10.4.1-3Dogtag Team 10.4.1-2Dogtag Team 10.4.1-1Dogtag Team 10.4.0-1Dogtag Team 10.3.3-18Dogtag Team 10.3.3-17Dogtag Team 10.3.3-16Dogtag Team 10.3.3-15Dogtag Team 10.3.3-14Dogtag Team 10.3.3-13Dogtag Team 10.3.3-12Dogtag Team 10.3.3-11Dogtag Team 10.3.3-10Dogtag Team 10.3.3-9Dogtag Team 10.3.3-8Dogtag Team 10.3.3-7Dogtag Team 10.3.3-6Dogtag Team 10.3.3-5Dogtag Team 10.3.3-3Dogtag Team 10.3.3-2Dogtag Team 10.3.3-1Dogtag Team 10.3.3-0.1Dogtag Team 10.3.2-5Dogtag Team 10.3.2-4Dogtag Team 10.3.2-3Dogtag Team 10.3.2-2Dogtag Team 10.3.2-1Dogtag Team 10.3.2-0.1Dogtag Team 10.3.1-1Dogtag Team 10.3.0-1Dogtag Team 10.3.0.b1-1Dogtag Team 10.3.0.a2-2Dogtag Team 10.3.0.a2-1Dogtag Team 10.3.0.a1-2Dogtag Team 10.3.0.a1-1Dogtag Team 10.3.0-0.5Dogtag Team 10.3.0-0.4Dogtag Team 10.3.0-0.3Dogtag Team 10.3.0-0.2Dogtag Team 10.3.0-0.1Dogtag Team 10.2.7-0.3Tomas Radej - 10.2.7-0.2Dogtag Team 10.2.7-0.1Dogtag Team 10.2.6-1Dogtag Team 10.2.6-0.3Dogtag Team 10.2.6-0.2Dogtag Team 10.2.6-0.1Dogtag Team 10.2.5-1Dogtag Team 10.2.5-0.2Dogtag Team 10.2.5-0.1Dogtag Team 10.2.4-1Dogtag Team 10.2.4-0.2Dogtag Team 10.2.4-0.1Dogtag Team 10.2.3-1Dogtag Team 10.2.3-0.1Dogtag Team 10.3.0-0.1Dogtag Team 10.2.3-0.1Dogtag Team 10.2.2-1Dogtag Team 10.2.2-0.1Dogtag Team 10.2.1-1Matthew Harmsen - 10.2.1-0.4Ade Lee 10.2.1-0.3Christina Fu 10.2.1-0.2Dogtag Team 10.2.1-0.1Ade Lee 10.2.0-3Matthew Harmsen - 10.2.0-2Dogtag Team 10.2.0-1Matthew Harmsen - 10.2.0-0.10Matthew Harmsen - 10.2.0-0.9Matthew Harmsen - 10.2.0-0.8Fedora Release Engineering - 10.2.0-0.5Jack Magne - 10.2.0-0.7Matthew Harmsen - 10.2.0-0.6Matthew Harmsen - 10.2.0-0.5Ade Lee - 10.2.0-0.4Fedora Release Engineering - 10.2.0-0.3Michael Simacek - 10.2.0-0.2Dogtag Team 10.2.0-0.1Ade Lee 10.1.0-1Ade Lee 10.1.0-0.14Ade Lee 10.1.0-0.13Ade Lee 10.1.0-0.12Ade Lee 10.1.0-0.11Endi S. Dewata 10.1.0-0.10Abhishek Koneru 10.1.0.0.9Abhishek Koneru 10.1.0.0.8Endi S. Dewata 10.1.0-0.7Endi S. Dewata 10.1.0-0.6Endi S. Dewata 10.1.0-0.5Ade Lee 10.1.0-0.4Endi S. Dewata 10.1.0-0.3Matthew Harmsen 10.1.0-0.2Ade Lee 10.1.0-0.1Endi S. Dewata 10.0.2-5Ade Lee 10.0.2-4Ade Lee 10.0.2-3Endi S. Dewata 10.0.2-2Ade Lee 10.0.2-1Ade Lee 10.0.2-0.8Endi S. Dewata 10.0.2-0.7Endi S. Dewata 10.0.2-0.6Ade Lee 10.0.2-0.5Endi S. Dewata 10.0.2-0.4Endi S. Dewata 10.0.2-0.3Endi S. Dewata 10.0.2-0.2Endi S. Dewata 10.0.2-0.1Endi S. Dewata 10.0.1-9Ade Lee 10.0.1-8Endi S. Dewata 10.0.1-7Matthew Harmsen 10.0.1-6Endi S. Dewata 10.0.1-5Endi S. Dewata 10.0.1-4Matthew Harmsen 10.0.1-3Matthew Harmsen 10.0.1-2Ade Lee 10.0.1-1Matthew Harmsen 10.0.0-5Matthew Harmsen 10.0.0-4Ade Lee 10.0.0-3Ade Lee 10.0.0-2Ade Lee 10.0.0-1Matthew Harmsen 10.0.0-0.56.b3Endi S. Dewata 10.0.0-0.55.b3Endi S. Dewata 10.0.0-0.54.b3Ade Lee 10.0.0-0.53.b3Ade Lee 10.0.0-0.52.b3Endi S. Dewata 10.0.0-0.51.b2Endi S. Dewata 10.0.0-0.50.b2Matthew Harmsen 10.0.0-0.49.b2Ade Lee 10.0.0-0.48.b2Matthew Harmsen 10.0.0-0.47.b1Ade Lee 10.0.0-0.46.b1Ade Lee 10.0.0-0.45.b1Ade Lee 10.0.0-0.44.b1Ade Lee 10.0.0-0.43.b1Ade Lee 10.0.0-0.42.b1Ade Lee 10.0.0-0.41.b1Ade Lee 10.0.0-0.40.b1Endi S. Dewata 10.0.0-0.40.a2Endi S. Dewata 10.0.0-0.39.a2Ade Lee 10.0.0-0.38.a2Endi S. Dewata 10.0.0-0.37.a2Ade Lee 10.0.0-0.36.a2Endi S. Dewata 10.0.0-0.36.a1Endi S. Dewata 10.0.0-0.35.a1Endi S. Dewata 10.0.0-0.34.a1Ade Lee 10.0.0-0.33.a1Matthew Harmsen 10.0.0-0.32.a1Endi S. Dewata 10.0.0-0.31.a1Endi S. Dewata 10.0.0-0.30.a1Endi S. Dewata 10.0.0-0.29.a1Endi S. Dewata 10.0.0-0.28.a1Endi S. Dewata 10.0.0-0.27.a1Endi S. Dewata 10.0.0-0.26.a1Endi S. Dewata 10.0.0-0.25.a1Endi S. Dewata 10.0.0-0.24.a1Matthew Harmsen 10.0.0-0.23.a1Endi S. Dewata 10.0.0-0.22.a1Endi S. Dewata 10.0.0-0.21.a1Matthew Harmsen 10.0.0-0.20.a1Matthew Harmsen 10.0.0-0.19.a1Matthew Harmsen 10.0.0-0.18.a1Endi S. Dewata 10.0.0-0.17.a1Matthew Harmsen 10.0.0-0.16.a1Ade Lee 10.0.0-0.15.a1Christina Fu 10.0.0-0.14.a1Endi S. Dewata 10.0.0-0.13.a1Endi S. Dewata 10.0.0-0.12.a1Ade Lee 10.0.0-0.11.a1Matthew Harmsen 10.0.0-0.10.a1Matthew Harmsen 10.0.0-0.9.a1Jack Magne 10.0.0-0.8.a1Matthew Harmsen 10.0.0-0.7.a1Endi S. Dewata 10.0.0-0.6.a1Ade Lee 10.0.0-0.5.a1Endi S. Dewata 10.0.0-0.4.a1Matthew Harmsen 10.0.0-0.3.a1Matthew Harmsen 10.0.0-0.2.a1Nathan Kinder 10.0.0-0.1.a1Ade Lee 9.0.16-3Endi S. Dewata 9.0.16-2Matthew Harmsen 9.0.16-1Matthew Harmsen 9.0.15-1Matthew Harmsen 9.0.14-1Ade Lee 9.0.13-1Matthew Harmsen 9.0.12-1Matthew Harmsen 9.0.11-1Matthew Harmsen 9.0.10-1Matthew Harmsen 9.0.9-1Matthew Harmsen 9.0.8-2Matthew Harmsen 9.0.8-1Matthew Harmsen 9.0.7-1Matthew Harmsen 9.0.6-2Matthew Harmsen 9.0.6-1Matthew Harmsen 9.0.5-2Matthew Harmsen 9.0.5-1Matthew Harmsen 9.0.4-1Matthew Harmsen 9.0.3-2Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-3Matthew Harmsen 9.0.1-2Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-3Matthew Harmsen 9.0.0-2Matthew Harmsen 9.0.0-1- ########################################################################## - # RHEL 7.9 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu] - Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx response from CA REST API: 500 [ftweedale, ckelley] - ########################################################################## - # RHCS 9.7 (Batch Update 8): - ########################################################################## - Bugzilla Bug 1959937 - TPS Allowing Token Transactions while the CA is Down [cfu] - Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile Separation [cfu]- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission per LDAP group without immediate issuance [rhel-7.9.z] (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1911472 - Revoke via REST API not working when Agent certificate not issued by CA [rhel-7.9.z] (cfu) - Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version String.java.io.FileNotFoundException (ckelley) - Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching PIN_RESET=YES to NO [rhel-7.9.z] (jmagne) - Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base build (jmagne) - Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot be processed (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)- Change variable 'TPS' to 'tps' - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug 1883639 - Add KRA Transport and Storage Certificates profiles, audit for IPA (edewata) - ########################################################################## - # Backported CVEs (ascheel): - ########################################################################## - Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token parameters in TPS resulting in stored XSS [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site scripting (XSS) in the pki-tps web Activity tab [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile creation [certificate_system_9-default] (edewata, ascheel) - Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site Scripting in 'path length' constraint field in CA's Agent page [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site scripting in getcookies?url= endpoint in CA [rhel-7.9.z] (dmoluguw, ascheel) - Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab [rhel-7.9.z] (ascheel) - Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne) - ########################################################################## - Update to jquery v3.4.1 (ascheel) - Update to jquery-i18n-properties v1.2.7 (ascheel) - Update to backbone v1.4.0 (ascheel) - Upgrade to underscore v1.9.2 (ascheel) - Update to patternfly v3.59.3 (ascheel) - Update to jQuery v3.5.1 (ascheel) - Upgrade to bootstrap v3.4.1 (ascheel) - Link in new Bootstrap CSS file (ascheel) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)- Bugzilla Bug #1883639 - additional support on upgrade for audit cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user- Patch for CMCResponse tool - Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)- Patch for CMC Credential Error, RSA PSS typo, and new profile for directory-authentication-based Server-Side keygen - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1710109 - add RSA PSS support (jmagne) - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)- ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE additional support and touch-up (cfu) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu) - Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)- Bugzilla Bug #1710109 - add RSA PSS support - fix IPA installer (jmagne)- Updated jss dependencies - ########################################################################## - # RHEL 7.9: - ########################################################################## - Bugzilla Bug #1774174 - Rebase pki-core from 10.5.17 to 10.5.18 (RHEL) - ########################################################################## - # RHCS 9.7: - ########################################################################## - # Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and - # Bugzilla Bug #1774181 - Update RHCS version of CA, KRA, OCSP, and TKS so- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1723008 - ECC Key recovery failure with CKR_TEMPLATE_INCONSISTENT (cfu) - Bugzilla Bug #1774282 - pki-server-nuxwdog template has pid file name with non-breakable space char encoded instead of 0x20 space char (ascheel) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Include 'pistool' in the 'pki-tools' package- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1445479 - KRATool does not support netkeyKeyRecovery attribute (dmoluguw) - Bugzilla Bug #1534013 - Attempting to add new keys using a PUT KEY APDU to a token that is loaded only with the default/factory keys (Key Version Number 0xFF) returns an APDU with error code 0x6A88. (jmagne) - Bugzilla Bug #1709585 - PKI (test support) for PKCS#11 standard AES KeyWrap for HSM support (cfu, ftweedal) - Bugzilla Bug #1748766 - number range depletion when multiple clones created from same master (ftweedal) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1520258 - TPS token search fails to find entries , LDAP filter - # Bugzilla Bug #1535671 - RFE to have the users be able to use the- ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1523330 - CC: missing audit event for CS acting as TLS client (cfu) - Bugzilla Bug #1597727 - CA - Unable to change a certificate’s revocation reason from superceded to key_compromised (rhcs-maint) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1470410 - TPS doesn't update revocation status when - # Bugzilla Bug #1470433 - Add supported transitions to TPS (rhcs-maint) - # Bugzilla Bug #1585722 - TMS - PKISocketFactory – Modify Logging to Allow - # Bugzilla Bug #1642577 - TPS – Revoked Encryption Certificates Marked as- Updated jss, nuxwdog, and tomcatjss dependencies - ########################################################################## - # RHEL 7.8: - ########################################################################## - Bugzilla Bug #1733586 - Rebase pki-core from 10.5.16 to 10.5.17 (RHEL) - ########################################################################## - # RHCS 9.6: - ########################################################################## - # Bugzilla Bug #1718418 - Update RHCS version of CA, KRA, OCSP, and TKS so - # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1638379 - PKI startup initialization process should not depend on LDAP operational attributes [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1491453 - Need Method to Include SKI in CA Signing Certificate Request [ftweedal] - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.7: - ########################################################################## - Bugzilla Bug #1633422 - Rebase pki-core from 10.5.1 to 10.5.16 (RHEL) - ########################################################################## - # RHCS 9.5: - ########################################################################## - # Bugzilla Bug #1633423 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] [manpage] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- Updated jss dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1671245 - CC: unable to verify cert before import [rhel-7.6.z] (ascheel) - Bugzilla Bug #1671303 - CC: Upgrade scripts for audit event names (RHEL) [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1671586 - CC: Upgrade scripts for audit event names (RHCS)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1659939 - CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA, - # Added Batch Update Information to Product Version (mharmsen)- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1657922 - CC: CA/OCSP startup fail on SystemCertsVerification if enableOCSP is true [rhel-7.6.z] (jmagne) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1645262 - pkidestroy may not remove all files [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645263 - Auth plugins leave passwords in the access log and audit log using REST [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1645429 - pkispawn fails due to name collision with /var/log/pki/ [rhel-7.6.z] (dmoluguw) - Bugzilla Bug #1655951 - CC: tools supporting CMC requests output keyID needs to be captured in file [rhel-7.6.z] (cfu) - Bugzilla Bug #1656297 - Unable to install with admin-generated keys [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Require "tomcatjss >= 7.2.1-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1632116 - CC: missing audit event for CS acting as TLS client [rhel-7.6.z] (cfu) - Bugzilla Bug #1632120 - Unsupported RSA_ ciphers should be removed from the default ciphers list [rhel-7.6.z] (cfu) - Bugzilla Bug #1632615 - Permit certain SHA384 FIPS ciphers to be enabled by default for RSA and ECC . . . [rhel-7.6.z] (cfu) - Bugzilla Bug #1632616 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (coverity changes) [rhel-7.6.z] (mharmsen) - Bugzilla Bug #1633104 - CMC: add config to allow non-clientAuth [rhel-7.6.z] (cfu) - Bugzilla Bug #1636490 - Installation of CA using an existing CA fails [rhel-7.6.z] (edewata) - Bugzilla Bug #1643878 - pki cli command for RHCS doesn't prompt for a password [rhel-7.6.z] (edewata) - Bugzilla Bug #1643879 - CC: Identify version/release of pki-ca, pki-kra, pki-ocsp, pki-tks, and pki-tps remotely [RHEL] [rhel-7.6.z] (cfu, jmagne) - Bugzilla Bug #1643880 - PKI subsystem process is not shutdown when there is no space on the disk to write logs [rhel-7.6.z] (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1639836 - CC: Identify RHCS version of CA, KRA,- Updated nuxwdog dependencies - ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #673182 - ECC keys not supported for signing audit logs (cfu) - Bugzilla Bug #1593805 - Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu) - Bugzilla Bug #1601071 - Certificate generation happens with partial attributes in CMCRequest file (cfu) - Bugzilla Bug #1601569 - CC: Enable all config audit events (cfu) - Bugzilla Bug #1608375 - CMC Revocations throws exception with same reqIssuer & certissuer (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1596629 - ipa-replica-install --setup-kra broken on DL0 with latest version (abokovoy) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1548203 - pki console configurations that involves ldap passwords leave the plain text password in signed audit logs (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1494591 - keyGen fails when only Identity- Re-spin alpha builds- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1471935 - X500Name.directoryStringEncodingOrder overridden by CSR encoding (cfu) - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certificate (ftweedal) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1550742 - Address ECC profile overrides (cfu) - Bugzilla Bug #1562841 - servlet profileSubmitCMCSimple throws NPE (cfu) - Bugzilla Bug #1572432 - AuditVerify failure due to line breaks (cfu) - Bugzilla Bug #1592961 - Need proper default subjectDN for CMC request authenticated through SharedToken (cfu) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- ########################################################################## - # RHEL 7.6: - ########################################################################## - Bugzilla Bug #1538311 - Using a Netmask produces an odd entry in a certifcate (ftweedal) - Bugzilla Bug #1544843 - ExternalCA: Installation failed during csr generation with ecc (rrelyea, gkapoor) - Bugzilla Bug #1557569 - Re-base pki-core from 10.5.1 to latest upstream 10.5.x (RHEL) (mharmsen) - Bugzilla Bug #1580394 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC (cfu) - Bugzilla Bug #1580527 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access (ftweedal, cfu) - Bugzilla Bug #1585866 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1588655 - Cert validation for installation with external CA cert (edewata) - ########################################################################## - # RHCS 9.4: - ########################################################################## - # Bugzilla Bug #1557570 - Re-base pki-core from 10.5.1 to- Rebuild due to build system database problem- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1585945 - CMC CRMF requests result in InvalidKeyFormatException when signing algorithm is ECC [rhel-7.5.z] (cfu) - Bugzilla Bug #1587826 - ExternalCA: Installation failed during csr generation with ecc [rhel-7.5.z] (rrelyea, gkapoor) - Bugzilla Bug #1588944 - Cert validation for installation with external CA cert [rhel-7.5.z] (edewata) - Bugzilla Bug #1588945 - CRMFPopClient tool - should allow option to do no key archival (cfu) - Bugzilla Bug #1589307 - CVE-2018-1080 pki-core: Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access [rhel-7.5.z] (ftweedal, cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1571582 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken (typos) [rhel-7.5.z] (cfu) - Bugzilla Bug #1572548 - IPA install with external-CA is failing when FIPS mode enabled. [rhel-7.5.z] (edewata) - Bugzilla Bug #1574848 - servlet profileSubmitCMCSimple throws NPE [rhel-7.5.z] (cfu) - Bugzilla Bug #1575521 - subsystem -> subsystem SSL handshake issue with TLS_ECDHE_RSA_* on Thales HSM [rhel-7.5.z] (cfu) - Bugzilla Bug #1581134 - ECC installation for non CA subsystems needs improvement [rhel-7.5.z] (jmagne) - Bugzilla Bug #1581135 - SAN in internal SSL server certificate in pkispawn configuration step [rhel-7.5.z] (cfu) - Bugzilla Bug #1581167 - CC: CMC profiles: Some CMC profiles have wrong input class_id [rhel-7.5.z] (cfu) - Bugzilla Bug #1581382 - ECDSA Certificates Generated by Certificate System 9.3 fail NIST validation test with parameter field. [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1550581 - CMCAuth throws org.mozilla.jss.crypto.TokenException: Unable to insert certificate into temporary database [rhel-7.5.z] (cfu) - Bugzilla Bug #1551067 - [MAN] Add --skip-configuration and --skip-installation into pkispawn man page. [rhel-7.5.z] (edewata) - Bugzilla Bug #1552241 - Make sslget aware of TLSv1_2 ciphers [rhel-7.5.z] (cheimes, mharmsen) - Bugzilla Bug #1553068 - Using a Netmask produces an odd entry in a certifcate [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1554726 - Need ECC-specific Enrollment Profiles for standard conformance [rhel-7.5.z] (cfu) - Bugzilla Bug #1554727 - Permit additional FIPS ciphers to be enabled by default for RSA . . . [rhel-7.5.z] (mharmsen, cfu) - Bugzilla Bug #1557880 - [MAN] Missing Man pages for tools CMCRequest, CMCResponse, CMCSharedToken [rhel-7.5.z] (cfu) - Bugzilla Bug #1557883 - Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException [rhel-7.5.z] (ftweedal) - Bugzilla Bug #1558919 - Not able to generate certificate request with ECC using pki client-cert-request [rhel-7.5.z] (akahat) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1560233 - libtps does not directly depend on libz- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1532867 - Inconsistent key ID encoding (edewata) - Bugzilla Bug #1540687 - CC: External OCSP Installation failure with HSM and FIPS (edewata) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit event- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1542210 - pki console configurations that involves ldap passwords leave the plain text password in debug logs (jmagne) - Bugzilla Bug #1543242 - Regression in lightweight CA key replication (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - # Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release - Bugzilla Bug #1445532 - CC: Audit Events: Update the default audit event set (RHEL) (edewata) - Bugzilla Bug #1522938 - CC: Missing faillure resumption detection and audit event logging at startup (jmagne) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1525306 - CC: missing CMC request and response record (cfu) - Bugzilla Bug #1532933 - Installing subsystems with external CMC certificates in HSM environment shows import error (edewata) - Bugzilla Bug #1535797 - ExternalCA: Failures when installed with hsm (edewata) - Bugzilla Bug #1539125 - restrict default cipher suite to those ciphers permitted in fips mode (mharmsen) - Bugzilla Bug #1539198 - Inconsistent CERT_REQUEST_PROCESSED outcomes. (edewata) - Bugzilla Bug #1540440 - CMC: Audit Events needed for failures in SharedToken scenario's (cfu) - Bugzilla Bug #1541526 - CMC: Revocation works with an unknown revRequest.issuer (cfu) - Bugzilla Bug #1541853 - ProfileService: config values with backslashes have backslashes removed (ftweedal) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, - # Bugzilla Bug #1404075 - CC: Audit Events: Update the default audit - # Bugzilla Bug #1501436 - TPS CS.cfg should be reflected with the- Updated jss, nuxwdog, and openssl dependencies - ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1402280 - CA Cloning: Failed to update number range in few cases (ftweedal) - Bugzilla Bug #1428021 - CC: shared token storage and retrieval mechanism (cfu) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1498957 - pkidestroy does not work with nuxwdog (alee) - Bugzilla Bug #1520277 - PR_FILE_NOT_FOUND_ERROR during pkispawn (alee) - Bugzilla Bug #1520526 - p12 admin certificate is missing when certificate is signed Externally (edewata) - Bugzilla Bug #1523410 - Unable to have non "pkiuser" owned CA instance (alee) - Bugzilla Bug #1523443 - HAProxy rejects OCSP responses due to missing nextupdate field (ftweedal) - Bugzilla Bug #1526881 - Not able to setup CA with ECC (mharmsen) - Bugzilla Bug #1532759 - pkispawn seems to be leaving our passwords in several different files after installation completes (alee) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core,- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - Bugzilla Bug #1466066 - CC: Secure removal of secret data storage (jmagne) - Bugzilla Bug #1518096 - ExternalCA: Failures in ExternalCA when tried to setup with CMC signed certificates (cfu) - ########################################################################## - # RHCS 9.3: - ########################################################################## - # Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- dogtagpki Pagure Issue #2853 - Cleanup spec file conditionals- Patch applying check-ins since 10.5.1-1- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- ########################################################################## - # RHEL 7.5: - ########################################################################## - Bugzilla Bug #1473452 - Rebase pki-core to latest upstream 10.5.x release (RHEL) - ########################################################################## - # RHCS 9.3: - ########################################################################## - #Bugzilla Bug #1471303 - Rebase redhat-pki, redhat-pki-theme, pki-core, and- #Bugzilla Bug #1492560 - ipa-replica-install --setup-kra broken on DL0- #Require "jss >= 4.4.0-8" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332 - # Bugzilla Bug #1486870 - Lightweight CA key replication fails (regressions) - # Bugzilla Bug #1485833 - Missing CN in user signing cert would cause error - # Bugzilla Bug #1487509 - pki-server-upgrade fails when upgrading from - # Bugzilla Bug #1490241 - PKCS12: upgrade to at least AES and SHA2 (FIPS) - # Bugzilla Bug #1491332 - TPS UI: need to display tokenType and tokenOrigin - # dogtagpki Pagure Issue #2764 - py3: pki.key.archive_encrypted_data: - ########################################################################## - # RHCS 9.2: - ########################################################################## - # Resolves: rhbz #1486870,1485833,1487509,1490241,1491332,1482729,1462271 - # Bugzilla Bug #1462271 - TPS incorrectly assigns "tokenOrigin" and - # Bugzilla Bug #1482729 - TPS UI: need to display tokenType and tokenOrigin- Resolves: rhbz #1463350 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1463350 - Access banner validation (edewata)- # Resolves: rhbz #1472615,1472617,1469447,1463350,1469449,1472619,1464970,1469437,1469439,1469446 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1472615 - CC: allow CA to process pre-signed CMC non-signing - # Bugzilla Bug #1472617 - CMC: cmc.popLinkWitnessRequired=false would cause - # Bugzilla Bug #1469447 - CC: CMC: check HTTPS client authentication cert - # Bugzilla Bug #1463350 - Access banner validation (edewata) - # Bugzilla Bug #1469449 - CC: allow CA to process pre-signed CMC renewal - # Bugzilla Bug #1472619 - Platform Dependent Python Import (mharmsen) - # Bugzilla Bug #1464970 - CC: CMC: replace id-cmc-statusInfo with - # Bugzilla Bug #1469437 - subsystem-cert-update command lacks --cert option - # Bugzilla Bug #1469439 - Fix Key Changeover with HSM to support SCP03 - # Bugzilla Bug #1469446 - CC: need CMC enrollment profiles for system- # Resolves: rhbz #1469432 - ########################################################################## - # RHEL 7.4: - ########################################################################## - # Bugzilla Bug #1469432 - CMC plugin default change - # Resolves CVE-2017-7537 - # Fixes BZ #1470948- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1458043 - Key recovery on token fails with invalid public key error on KRA (alee) - Bugzilla Bug #1460764 - CC: CMC: check HTTPS client authentication cert against CMC signer (cfu) - Bugzilla Bug #1461533 - Unable to find keys in the p12 file after deleting the any of the subsystem certs from it (ftweedal)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1419777 - CC: allow CA to process pre-signed CMC revocation non-signing cert requests (cfu) - Bugzilla Bug #1458047 - change the way aes clients refer to aes keysets (alee) - Bugzilla Bug #1458055 - dont reuse IVs in the CMC code (alee) - Bugzilla Bug #1460028 - In keywrap mode, key recovery on KRA with HSM causes KRA to crash (ftweedal)- Require "selinux-policy-targeted >= 3.13.1-159" as a runtime requirement - Require "tomcatjss >= 7.2.1-4" as a build and runtime requirement - ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (edewata) - Bugzilla Bug #1447762 - pkispawn fails occasionally with this failure ACCESS_SESSION_ESTABLISH_FAILURE (edewata) - Bugzilla Bug #1454450 - SubCA installation failure with 2 step installation in fips enabled mode (edewata) - Bugzilla Bug #1456597 - Certificate import using pki client-cert-import is asking for password when already provided (edewata) - Bugzilla Bug #1456940 - Build failure due to Pylint issues (cheimes) - Bugzilla Bug #1458043 - Key recovery using externalReg fails with java null pointer exception on KRA (alee) - Bugzilla Bug #1458379 - Upgrade script for keepAliveTimeout parameter (edewata) - Bugzilla Bug #1458429 - client-cert-import --ca-cert should import CA cert with trust bits "CT,C,C" (edewata) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1393633 - Creating symmetric key (sharedSecret) using tkstool is failing when RHEL 7.3 is in FIPS mode. (jmagne) - Bugzilla Bug #1445519 - CA Server installation with HSM fails (jmagne) - Bugzilla Bug #1452617 - Unable to create IPA Sub CA (ftweedal) - Bugzilla Bug #1454471 - Enabling all subsystems on startup (edewata) - Bugzilla Bug #1455617 - Key recovery on token fails because key record is not marked encrypted (alee)- Bugzilla Bug #1454603 - Unable to install IPA server due to pkispawn error (mharmsen)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1419761 - CC: allow CA to process pre-signed CMC renewal non-signing cert requests (cfu) - Bugzilla Bug #1447080 - CC: CMC: allow enrollment key signed (self-signed) CMC with identity proof (cfu) - Bugzilla Bug #1447144 - CA brought down during separate KRA instance creation (mharmsen) - Bugzilla Bug #1448903 - exception Invalid module "--ignore-banner" when defined in ~/.dogtag/pki.conf and run pki pkcs12-import --help (edewata) - Bugzilla Bug #1450143 - CA installation with HSM in FIPS mode fails (jmagne) - Bugzilla Bug #1452123 - CA CS.cfg shows default port (mharmsen) - Bugzilla Bug #1452250 - Inconsistent CERT_REQUEST_PROCESSED event in ConnectorServlet. (edewata) - Bugzilla Bug #1452340 - Ensuring common audit log correctness (edewata) - Bugzilla Bug #1452344 - Adding serial number into CERT_REQUEST_PROCESSED audit event. (edewata)- ########################################################################## - # RHEL 7.4: - ########################################################################## - Bugzilla Bug #1386303 - cannot extract generated private key from KRA when HSM is used. (alee) - Bugzilla Bug #1446364 - pkispawn returns before tomcat is ready (cheimes) - Bugzilla Bug #1447145 - CMC: cmc.popLinkWitnessRequired=false would cause error (cfu) - Bugzilla Bug #1448203 - CAInfoService: retrieve KRA-related values from the KRA (ftweedal) - Bugzilla Bug #1448204 - pkispawn of clone install fails with InvalidBERException (ftweedal) - Bugzilla Bug #1448521 - kra unable to extract symmetric keys generated on thales hsm (alee) - Updated "jss" build and runtime requirements (mharmsen) - ########################################################################## - # RHCS 9.2: - ########################################################################## - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1303683 - dogtag should support GSSAPI based auth in conjuction with FreeIPA (ftweedal) - Bugzilla Bug #1385208 - RHCS 9.1 RC5 CA in the certificate profiles the startTime parameter is not working as expected. (jmagne) - Bugzilla Bug #1419756 - CC: allow CA to process pre-signed CMC non-signing certificate requests (cfu) - Bugzilla Bug #1426754 - PKCS12: upgrade to at least AES and SHA2 (ftweedal) - Bugzilla Bug #1445088 - profile modification cannot remove existing config parameters (ftweedal) - Bugzilla Bug #1445535 - CC: Crypto Operation (AES Encryption/Decryption) (RHEL) (alee) - Bugzilla Bug #1446874 - Missing ClientIP and ServerIP in audit log when pki CLI terminates SSL connection (edewata) - Bugzilla Bug #1446875 - Session timeout for PKI console (RHEL) (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1404480 - CC: Crypto Operation (AES Encryption/Decryption) (RHCS) (alee)- ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1282504 - Installing pki-server in container reports scriptlet failed, exit status 1 (jpazdziora) - Bugzilla Bug #1400149 - pkispawn fails to create CA subsystem on FIPS enabled system (edewata) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support for sc 7 g & d cards (RHEL) (jmagne) - Bugzilla Bug #1437591 - cli authentication using expired cert throws an exception (edewata) - Bugzilla Bug #1437602 - non-CA cli looks for CA in the instance during a request (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1274086 - [RFE] Add SCP03 support for sc 7 g & d cards (RHCS) (jmagne) - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1417307 - CC: Audit Review /Searches (edewata) - Bugzilla Bug #1419737 - CC: CMC: id-cmc-popLinkWitnessV2 feature implementation (cfu)- Require "nss >= 3.28.3" as a build and runtime requirement - Require "jss >= 4.4.0-4" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-3" as a build and runtime requirement - dogtagpki Pagure Issue #2612 - Unable to clone due to pki pkcs12-cert-find failure (edewata) - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - ############################################################################ - # RHCS 9.2: - ############################################################################ - ############################################################################ - # Common Criteria - ############################################################################ - Bugzilla Bug #1419734 - CC: CMC: id-cmc-identityProofV2 feature implementation (cfu) - Bugzilla Bug #1419742 - CC: CMC: provide Proof of Possession for encryption cert requests (cfu) - Bugzilla Bug #1404080 - CC: add audit event: various SSL/TLS failures (edewata) - Bugzilla Bug #1428020 - CC: CMC feature support: provided issuance protection cert mechanism (cfu)- Require "jss >= 4.4.0-1" as a build and runtime requirement - Require "tomcatjss >= 7.2.1-1" as a build and runtime requirement - ############################################################################ - Bugzilla Bug #1394309 - Rebase pki-core to 10.4.x in RHEL-7.4 - Bugzilla Bug #1394315 - Rebase redhat-pki, redhat-pki-theme, pki-core, and pki-console to 10.4.x - ############################################################################ - # RHEL 7.4: - ############################################################################ - Bugzilla Bug #1222557 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1238684 - Generting Symmetric key fails with key-generate when --usages verify (vakwetu) - Bugzilla Bug #1246635 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1249400 - CA EE: Submit caUserCert request without uid does not show proper error message (vakwetu) - Bugzilla Bug #1305993 - Add profile component that copies CN to SAN (ftweedal) - Bugzilla Bug #1316653 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1325071 - add options to enable/disable cert or crl publishing. (vakwetu) - Bugzilla Bug #1330800 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1368410 - Misleading Logging for HSM (edewata) - Bugzilla Bug #1372052 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1375347 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - Bugzilla Bug #1376226 - IPA replica-prepare failed with error "Profile caIPAserviceCert Not Found" (ftweedal) - Bugzilla Bug #1376488 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1378275 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1378277 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1378527 - Miscellaneous Minor Changes (edewata) - Bugzilla Bug #1381084 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1382066 - Problems with FIPS mode (edewata) - Bugzilla Bug #1386371 - Remove xenroll.dll from pki-core (mharmsen) - Bugzilla Bug #1386424 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1391737 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHEL 7) (edewata) - Bugzilla Bug #1392068 - [RFE] add express archivals and retrievals from KRA (vakwetu) - Bugzilla Bug #1395817 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1397200 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1399862 - Dogtag 10.3.9 Man Pages (edewata) - Bugzilla Bug #1404881 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1405654 - Token memory not wiped after key deletion (RHEL) (jmagne) - Bugzilla Bug #1409946 - Request ID undefined for CA signing certificate (vakwetu) - Bugzilla Bug #1409949 - CA Certificate Issuance Date displayed on CA website incorrect (vakwetu) - Bugzilla Bug #1410650 - [RFE] Add SCP03 support (RHEL) (jmagne) - Bugzilla Bug #1411428 - Unable to create a CA clone in FIPS (edewata) - Bugzilla Bug #1412211 - Unable to set up KRA in FIPS (edewata) - Bugzilla Bug #1412681 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1413132 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1413136 - Problem with default AJP hostname in IPv6 environment. (edewata) - ############################################################################ - # RHCS 9.2: - ############################################################################ - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1 (cfu) - Bugzilla Bug #1274086 - [RFE] Add SCP03 support (RHCS) (jmagne) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (RHCS 9) (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (RHCS) (jmagne) - Bugzilla Bug #1404900 - Dogtag 10.3.9 logging properties (edewata) - Bugzilla Bug #1405655 - Token memory not wiped after key deletion (RHCS) (jmagne) - ############################################################################- ## RHEL 7.3.z Batch Update 4 - Bugzilla Bug #1429492 - Add profile component that copies CN to SAN (ftweedal)- ## RHCS 9.1.z Batch Update 3 - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - ## RHEL 7.3.z Batch Update 3 - Bugzilla Bug #1417063 - ECDSA Certificates Generated by Certificate System 8.1 fail NIST validation test with parameter field. (cfu) - Bugzilla Bug #1417064 - Unable to search certificate requests using the latest request ID (edewata) - Bugzilla Bug #1417065 - CA Certificate Issuance Date displayed on CA website incorrect (alee) - Bugzilla Bug #1417066 - update to 7.3 IPA with otpd bugfixes, tomcat will not finish start, hangs (ftweedal) - Bugzilla Bug #1417067 - pki-tomcat for 10+ minutes before generating cert (edewata) - Bugzilla Bug #1417190 - Problem with default AJP hostname in IPv6 environment. (edewata)- Separate original patches into RHEL and RHCS portions - ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - Bugzilla Bug #1405328 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne) - Bugzilla Bug #1404900 - RHCS logging properties (edewata)- ## RHEL 7.3.z Batch Update 2 - Bugzilla Bug #1404173 - user-cert-add --serial CLI request to secure port with remote CA shows authentication failure (edewata) - Bugzilla Bug #1404175 - pki ca-cert-request-submit fails presumably because of missing authentication even if it should not require any (edewata) - Bugzilla Bug #1404178 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-base] (edewata) - Bugzilla Bug #1404172 - Unable to install subordinate CA with HSM in FIPS mode (edewata) - Bugzilla Bug #1403689 - pkispawn does not change default ecc key size from nistp256 when nistp384 is specified in spawn config (jmagne) - Bugzilla Bug #1404176 - logging properties and man pages (edewata) - ## RHCS 9.1.z Batch Update 2 - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI [pki-tps] (edewata) - Bugzilla Bug #1391207 - Automatic recovery of encryption cert - CA and TPS tokendb shows different certificate status (cfu) - Bugzilla Bug #1395479 - TPS throws "err=6" when attempting to format and enroll G&D Cards (jmagne)- Marked the following RHCS 9.1.z bug: Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) as a duplicate of RHEL 7.3.z bug: Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) and moved the patch from the RHCS 9.1.z bug to the RHEL 7.3.z bug.- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) (added KRA key recovery via CLI in FIPS mode) - ## RHCS 9.1.z Batch Update 1 - Reverted patches associated with Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- ## RHEL 7.3.z Batch Update 1 - Bugzilla Bug #1390318 - CA EE: Submit caUserCert request without uid does not show proper error message (alee) - Bugzilla Bug #1390319 - Failed to start pki-tomcatd Service ("ipa-cacert-manage renew" failed?) (edewata) - Bugzilla Bug #1390320 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - Bugzilla Bug #1390321 - two-step externally-signed CA installation fails due to missing AuthorityID (ftweedal) - Bugzilla Bug #1390322 - Spurious host authority entries created (ftweedal) - Bugzilla Bug #1390324 - KRA installation failed against externally-signed CA with partial certificate chain (edewata) - Bugzilla Bug #1389757 - Problems with FIPS mode (edewata) - Bugzilla Bug #1390311 - Fix packaging duplicates of classes in multiple jar files (edewata) - Bugzilla Bug #1390325 - Typo in comment line of UserPwdDirAuthentication.java (edewata) - ## RHCS 9.1.z Batch Update 1 - Bugzilla Bug #1248553 - TPS Enrollment always goes to "ca1" (cfu) - Bugzilla Bug #1274096 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - Bugzilla Bug #1379379 - Unable to read an encrypted email using renewed tokens (jmagne) - Bugzilla Bug #1379749 - Automatic recovery of encryption cert is not working when a token is physically damaged and a temporary token is issued (jmagne) - Bugzilla Bug #1381375 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches - Bugzilla Bug #1381635 - Token format with external reg fails when op.format.externalRegAddToToken.revokeCert=true (cfu) - Bugzilla Bug #1382762 - PIN_RESET policy is not giving expected results when set on a token (jmagne) - Bugzilla Bug #1382862 - TPS token enrollment fails to setupSecureChannel when TPS and TKS security db is on fips mode. (jmagne) - Bugzilla Bug #1386257 - Changes to target.agent.approve.list parameter is not reflected in the TPS Web UI (edewata)- PKI TRAC Ticket #1527 - TPS Enrollment always goes to "ca1" (cfu) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #2478 - pkispawn fails as it is not able to find openssl as a dependency package (mharmsen) - PKI TRAC Ticket #2483 - Unable to read an encrypted email using renewed tokens (jmagne) - PKI TRAC Ticket #2496 - Cert/Key recovery is successful when the cert serial number and key id on the ldap user mismatches (cfu) - PKI TRAC Ticket #2505 - Fix packaging duplicates of classes in multiple jar files (edewata)- Revert Patch: PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata) - Resolves: rhbz #1374054 - ipa-replica-install fails setting up certificate - Restores: rhbz #1319557 - pkispawn KRA instance is failing server - Removes from Errata: rhbz #1372041 - Unable to create system certificates in different tokens- PKI TRAC Ticket #1638 - Lightweight CAs: revoke certificate on CA deletion (ftweedal) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata) - PKI TRAC Ticket #2443 - Prevent deletion of host CA's keys if LWCA entry deleted (ftweedal) - PKI TRAC Ticket #2444 - Authority entry without entryUSN is skipped even if USN plugin enabled (ftweedal) - PKI TRAC Ticket #2446 - pkispawn: make subject_dn defaults unique per instance name (for shared HSM) (cfu) - PKI TRAC Ticket #2447 - CertRequestInfo has incorrect URLs (vakwetu) - PKI TRAC Ticket #2449 - Unable to create system certificates in different tokens (edewata)- PKI TRAC Ticket #1578 - Authentication Instance Id PinDirEnrollment with authType value as SslclientAuth is not working (jmagne) - PKI TRAC TIcket #2414 - pki pkcs12-cert-del shows a successfully deleted message when a wrong nickname is provided (gkapoor) - PKI TRAC Ticket #2423 - pki_ca_signing_token when not specified does not fallback to pki_token_name value (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (akasurde) - ticket remains open - PKI TRAC Ticket #2439 - Outdated deployment descriptors in upgraded server(edewata)- PKI TRAC Ticket #690 - [MAN] pki-tools man pages (mharmsen) - CMCEnroll - PKI TRAC Ticket #833 - pki user-mod fullName="" gives an error message "PKIException: LDAP error (21): error result" (edewata) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (cheimes, edewata, mharmsen) - PKI TRAC Ticket #2432 - Kra-selftest behavior is not as expected (edewata) - PKI TRAC Ticket #2436 - Dogtag 10.3.6: Miscellaneous Enhancements (edewata, mharmsen) - PKI TRAC Ticket #2437 - TPS UI: while adding certs for users from TPSUI pem format with/without header works while pkcs7 with header is not allowed (edewata) - PKI TRAC Ticket #2440 - Optional CA signing CSR for migration (edewata)- Bugzilla Bug #1366465 - Errata TPS upgrade test fails- PKI TRAC Ticket #978 - TPS connector man page: add revocation routing info (cfu) - PKI TRAC Ticket #1285 - [MAN] Apply 'generateCRMFRequest() removed from Firefox' workarounds to appropriate 'pki' man page (jmagne) - PKI TRAC Ticket #2246 - [MAN] Man Page: AuditVerify (cfu) - PKI TRAC Ticket #2381 - Throws exception while providing invalid module. (edewata) - PKI TRAC Ticket #2383 - CLI :: pki client-cert-request --extractable should accept only boolean value (edewata) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2399 - Dogtag 10.3.5: Miscellaneous Enhancements (akasurde, alee, cheimes, edewata, jmagne, mharmsen) - PKI TRAC Ticket #2401 - pkispawn calls dnsdomainname even if it does not rpm-require hostname (mharmsen) - PKI TRAC Ticket #2402 - Conflict in file ownership in pki-base and pki-server (cheimes) - PKI TRAC Ticket #2403 - Deployment problem with RESTEasy 3.0.17 (edewata) - PKI TRAC Ticket #2406 - Make starting CRL Number configurable (jmagne) - PKI TRAC Ticket #2412 - pki client-cert-import --trust option does not apply the specified trust bits (alee) - PKI TRAC Ticket #2418 - [TPS] Some template substitution didn't happen during installation (alee) - PKI TRAC Ticket #2420 - CA subsystem OSCP responder fails when LWCAs are not used (ftweedal) - PKI TRAC Ticket #2421 - Incorrect SELinux contexts Installation/Configuration (edewata) - PKI TRAC Ticket #2424 - ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full (edewata) - PKI TRAC Ticket #2428 - broken request links for CA's system certs in agent request viewing (cfu) - PKI TRAC Ticket #2430 - CA Agent certificate list is not sorted by serial number in migration case (jmagne) - PKI TRAC Ticket #2431 - Errors noticed during ipa server upgrade. (mharmsen) - PKI TRAC Ticket #2433 - Lightweight CA GET /chain returns bogus PEM data (ftweedal)- PKI TRAC Ticket #691 - [MAN] pki-server man pages (mharmsen) - PKI TRAC Ticket #1114 - [MAN] Generting Symmetric key fails with key-generate when --usages verify is passed (jmagne) - PKI TRAC Ticket #1306 - [RFE] Add granularity to token termination in TPS (cfu) - PKI TRAC Ticket #1308 - [RFE] Provide ability to perform off-card key generation for non-encryption token keys (cfu) - PKI TRAC Ticket #1405 - [MAN] Add additional HSM details to 'pki_default.cfg' & 'pkispawn' man pages (mharmsen) - PKI TRAC Ticket #1607 - [MAN] man pkispawn has inadequate description for shared vs non shared tomcat instance installation (mharmsen) - PKI TRAC Ticket #1664 - [BUG] Add ability to disallow TPS to enroll a single user on multiple tokens. (jmagne) - PKI TRAC Ticket #1711 - CLI :: pki-server ca-cert-request-find throws IOError (edewata, ftweedal) - PKI TRAC Ticket #2285 - freeipa fails to start correctly after pki-core update on upgraded system (ftweedal) - PKI TRAC Ticket #2311 - When pki_token_name=Internal, consider normalizing it to "internal" (mharmsen) - PKI TRAC Ticket #2349 - Separated TPS does not automatically receive shared secret from remote TKS (jmagne) - PKI TRAC Ticket #2364 - CLI :: pki-server ca-cert-request-show throws attribute error (ftweedal) - PKI TRAC Ticket #2368 - pki-server subsystem subcommands throws error with --help option (edewata) - PKI TRAC Ticket #2374 - KRA cloning overwrites CA signing certificate trust flags (edewata) - PKI TRAC Ticket #2380 - Pki-server instance commands throws exception while specifying invalid parameters. (edewata) - PKI TRAC Ticket #2384 - CA installation with HSM prompts for HSM password during silent installation (edewata) - PKI TRAC Ticket #2385 - Upgraded CA lacks ca.sslserver.certreq in CS.cfg (ftweedal) - PKI TRAC Ticket #2387 - Add config for default OCSP URI if none given (ftweedal) - PKI TRAC Ticket #2388 - CA creation responds 500 if certificate issuance fails (ftweedal) - PKI TRAC Ticket #2389 - Installation: subsystem certs could have notAfter beyond CA signing cert in case of external or existing CA (cfu) - PKI TRAC Ticket #2390 - Dogtag 10.3.4: Miscellaneous Enhancements (akasurde, edewata)- PKI TRAC Ticket #2373 - Fedora 25: RestEasy 3.0.6 ==> 3.0.17 breaks pki-core (ftweedal)- Updated release number to 10.3.3-1- Updated version number to 10.3.3-0.1- Provided cleaner runtime dependency separation- Updated tomcatjss version dependencies- Updated 'java', 'java-headless', and 'java-devel' dependencies to 1:1.8.0.- Updated tomcat version dependencies- Updated version number to 10.3.2-1- Updated version number to 10.3.2-0.1- Updated version number to 10.3.1-1 (to allow upgrade from 10.3.0.b1)- Updated version number to 10.3.0-1- Build for F24 beta- PKI TRAC Ticket #2255 - PKCS #12 backup does not contain trust attributes.- Updated build for F24 alpha- PKI TRAC Ticket #1625 - Allow multiple ACLs of same name (union of rules) [ftweedal] - PKI TRAC Ticket #2237 - Add CRL dist points extension to OIDMap unconditionally [edewata] - PKI TRAC Ticket #1803 - Removed unnecessary URL encoding for admin cert request. [edewata] - PKI TRAC Ticket #1742 - Added support for cloning 3rd-party CA certificates. [edewata] - PKI TRAC Ticket #1482 - Added TPS token filter dialog. [edewata] - PKI TRAC Ticket #1808 - Fixed illegal token state transition via TEMP_LOST. [edewata]- Build for F24 alpha- PKI Trac Ticket #1399 - Move java components out of pki-base- PKI TRAC Ticket #1850 - Rename DRMTool --> KRATool- PKI TRAC Ticket #1714 - mod_revocator and mod_nss dependency for tps should be removed- PKI TRAC Ticket #1623 - Runtime dependency on python-nss is missing- Updated version number to 10.3.0-0.1- Added dep on tomcat-servlet-3.1-api [Fedora 23 and later] or dep on tomcat-servlet-3.0-api [Fedora 22 and later] to pki-tools - Updated dep on tomcatjss [Fedora 23 and later]- Updated dep on policycoreutils-python-utils [Fedora 23 and later]- Updated version number to 10.2.7-0.1- Update release number for release build- Remove setup directory and remaining Perl dependencies- Remove ExcludeArch directive- Updated version number to 10.2.6-0.1- Update release number for release build- Resolves rhbz #1230970 - Errata TPS tests for rpm verification failed- Updated version number to 10.2.5-0.1- Update release number for release build- Updated nuxwdog and tomcatjss requirements (alee)- Updated version number to 10.2.4-0.1 - Added nuxwdog systemd files- Update release number for release build- Reverted version number back to 10.2.3-0.1 - Added support for Tomcat 8.- Updated version number to 10.3.0-0.1- Updated version number to 10.2.3-0.1- Update release number for release build- Updated version number to 10.2.2-0.1 - Moved web application deployment locations. - Updated Resteasy and Jackson dependencies. - Added missing python-lxml build dependency.- Update release number for release build- PKI TRAC Ticket #1187 - mod_perl should be removed from requirements for 10.2 - PKI TRAC Ticket #1205 - Outdated selinux-policy dependency. - Removed perl(XML::LibXML), perl-Crypt-SSLeay, and perl-Mozilla-LDAP runtime dependencies- Change resteasy dependencies for F22+- Ticket 1198 Bugzilla 1158410 add TLS range support to server.xml by default and upgrade (cfu) - PKI Trac Ticket #1211 - New release overwrites old source tarball (mharmsen) - up the release number to 0.2- Updated version number to 10.2.1-0.1. - Added CLIs to simplify generating user certificates - Added enhancements to KRA Python API - Added a man page for pki ca-profile commands. - Added python api docs- Disable pylint dependency for RHEL builds - Added jakarta-commons-httpclient requirements - Added tomcat version for RHEL build - Added resteasy-base-client for RHEL build- PKI TRAC Ticket #1130 - Add RHEL/CentOS conditionals to spec- Update release number for release build- PKI TRAC Ticket #1017 - Rename pki-tps-tomcat to pki-tps- Merged jmagne@redhat.com's spec file changes from the stand-alone 'pki-tps-client' package needed to build/run the native 'tpsclient' command line utility into this 'pki-core' spec file under the 'tps' package. - Original tps libararies must be built to support this native utility. - Modifies tps package from 'noarch' into 'architecture-specific' package- PKI TRAC Ticket #1127 - Remove 'pki-ra', 'pki-setup', and 'pki-silent' packages . . .- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Respin to include the applet files with the rpm install. No change to spec file needed.- Bugzilla Bug #1120045 - pki-core: Switch to java-headless (build)requires -- drop dependency on java-atk-wrapper - Removed 'java-atk-wrapper' dependency from 'pki-server'- PKI TRAC Ticket #832 - Remove legacy 'systemctl' files . . .- Update rawhide build- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Use Requires: java-headless rebuild (#1067528)- Added option to build without server packages. - Replaced Jettison with Jackson. - Added python-nss build requirement - Bugzilla Bug #1057959 - pkispawn requires policycoreutils-python - TRAC Ticket #840 - pkispawn requires policycoreutils-python - Updated requirements for resteasy - Added template files for archive, retrieve and generate key requests to the client package.- Trac Ticket 788 - Clean up spec files - Update release number for release build - Updated requirements for resteasy- Change release number for beta build- Updated requirements for tomcat- Removed additional /var/run, /var/lock references.- Removed delivery of /var/lock and /var/run directories for fedora 20.- Moved Tomcat-based TPS into pki-core.- Listed new packages required during build, due to issues reported by pylint. - Packages added: python-requests, python-ldap, libselinux-python, policycoreutils-python- Added pylint scan to the build process.- Added man pages for upgrade tools.- Cleaned up the code to install man pages.- Reorganized deployment tools.- Bugzilla Bug 973224 - resteasy-base must be split into subpackages to simplify dependencies- Updated dependencies to Java 1.7.- TRAC Ticket 606 - add restart / start at boot info to pkispawn man page - TRAC Ticket 610 - Document limitation in using GUI install - TRAC Ticket 629 - Package ownership of '/usr/share/pki/etc/' directory- Change release number for 10.1 development- Fixed incorrect JNI_JAR_DIR.- TRAC Ticket 605 Junit internal function used in TestRunner, breaks F19 build- TRAC Ticket 604 Added fallback methods for pkispawn tests- Added default pki.conf in /usr/share/pki/etc - Create upgrade tracker on install and remove it on uninstall- Change release number for official release.- Added %pretrans script for f19 - Added java-atk-wrapper dependency- Added pki-server-upgrade script and pki.server module. - Call upgrade scripts in %post for pki-base and pki-server.- Added dependency on commons-io.- Add /var/log/pki and /var/lib/pki directories- Run pki-upgrade on post server installation.- Added dependency on python-lxml.- Added pki-upgrade script.- Updated version number to 10.0.2-0.1.- Renamed base/deploy to base/server. - Moved pki.conf into pki-base. - Removed redundant pki/server folder declaration.- Removed jython dependency- Added minimum python-requests version.- Bugzilla Bug #919476 - pkispawn crashes due to dangling symlink to jss4.jar- Added dependency on python-requests. - Reorganized Python module packaging.- Added dependency on python-ldap.- TRAC Ticket #517 - Clean up theme dependencies - TRAC Ticket #518 - Remove UI dependencies from pkispawn . . .- Removed runtime dependency on 'pki-server-theme' to resolve Bugzilla Bug #916134 - unresolved dependency in pki-server: pki-server-theme- TRAC Ticket 214 - Missing error description for duplicate user - TRAC Ticket 213 - Add nonces for cert revocation - TRAC Ticket 367 - pkidestroy does not remove connector - TRAC Ticket #430 - License for 3rd party code - Bugzilla Bug 839426 - [RFE] ECC CRL support for OCSP - Fix spec file to allow f17 to work with latest tomcatjss - TRAC Ticket 466 - Increase root CA validity to 20 years - TRAC Ticket 469 - Fix tomcatjss issue in spec files - TRAC Ticket 468 - pkispawn throws exception - TRAC Ticket 191 - Mapping HTTP Exceptions to HTTP error codes - TRAC Ticket 271 - Dogtag 10: Fix 'status' command in 'pkidaemon' . . . - TRAC Ticket 437 - Make admin cert p12 file location configurable - TRAC Ticket 393 - pkispawn fails when selinux is disabled - Punctuation and formatting changes in man pages - Revert to using default config file for pkidestroy - Hardcode setting of resteasy-lib for instance - TRAC Ticket 436 - Interpolation for pki_subsystem - TRAC Ticket 433 - Interpolation for paths - TRAC Ticket 435 - Identical instance id and instance name - TRAC Ticket 406 - Replace file dependencies with package dependencies- TRAC Ticket #430 - License for 3rd party code- TRAC Ticket #469 - Dogtag 10: Fix tomcatjss issue in pki-core.spec and dogtag-pki.spec . . . - TRAC Ticket #468 - pkispawn throws exception- Replaced file dependencies with package dependencies- Updated man pages- Update to official release for rc1- TRAC Ticket #315 - Man pages for pkispawn/pkidestroy. - Added place-holders for 'pki.1' and 'pki_default.cfg.5' man pages.- Added system-wide configuration /etc/pki/pki.conf. - Removed redundant lines in %files.- Moved default deployment configuration to /etc/pki.- Cleaned up spec file to provide only support rhel 7+, f17+ - Added resteasy-base dependency for rhel 7 - Update cmake version- Update release to b3- Removed dependency on CA, KRA, OCSP, TKS theme packages.- Renamed pki-common-theme to pki-server-theme.- TRAC Ticket #395 - Dogtag 10: Add a Tomcat 7 runtime requirement to 'pki-server'- Update release to b2- TRAC Ticket #350 - Dogtag 10: Remove version numbers from PKI jar files . . .- Added Obsoletes for pki-selinux- Remove build of pki-selinux for f18, use system policy instead- Update required tomcatjss version - Added net-tools dependency- Update selinux-policy version to fix error from latest policy changes- Fix typo in selinux policy versions- Added build requires for correct version of selinux-policy-devel- Update release to b1- Merged pki-silent into pki-server.- Renamed "shared" folder to "server".- Added required selinux versions for new policy.- Added Provides to packages replacing obsolete packages.- Update release to a2- Modified CMake to use RPM version number- Added VERSION file- Merged pki-setup into pki-server- Added Conflicts for IPA 2.X - Added build requires for zip to work around mock problem- TRAC Ticket #312 - Dogtag 10: Automatically restart any running instances upon RPM "update" . . . - TRAC Ticket #317 - Dogtag 10: Move "pkispawn"/"pkidestroy" from /usr/bin to /usr/sbin . . .- Fixed pki-server to include everything in shared dir.- Added build dependency on redhat-rpm-config.- Merged Javadoc packages.- Added pki-tomcat.jar.- Moved webapp creation code into pkispawn.- Split pki-client.jar into pki-certsrv.jar and pki-tools.jar.- Merged pki-native-tools and pki-java-tools into pki-tools. - Modified pki-server to depend on pki-tools.- Split pki-common into pki-base and pki-server. - Merged pki-util into pki-base. - Merged pki-deploy into pki-server.- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 17 - Changed Dogtag 10 build-time and runtime requirements for 'pki-deploy' - Altered PKI Package Dependency Chain (top-to-bottom): pki-ca, pki-kra, pki-ocsp, pki-tks --> pki-deploy --> pki-common- Added pki-client.jar.- Merged pki-jndi-realm.jar into pki-cmscore.jar.- PKI TRAC Task #254 - Dogtag 10: Fix spec file to build successfully via mock on Fedora 17 . . .- Moved 'pki-jndi-real.jar' link from 'tomcat6' to 'tomcat' (Tomcat 7)- Updated release of 'tomcatjss' to rely on Tomcat 7 for Fedora 18- Added CLI for REST services- Integration of Tomcat 7 - Addition of centralized 'pki-tomcatd' systemd functionality to the PKI Deployment strategy - Removal of 'pki_flavor' attribute- BZ 813075 - selinux denial for file size access- Bug 745278 - [RFE] ECC encryption keys cannot be archived- Replaced candlepin-deps with resteasy- Added option to build without Javadoc- BZ 802396 - Change location of TOMCAT_LOG to match tomcat6 changes - Corrected patch selected for selinux f17 rules- Corrected 'junit' dependency check- Initial attempt at PKI deployment framework described in 'http://pki.fedoraproject.org/wiki/PKI_Instance_Deployment'.- Added support for pki-jndi-realm in tomcat6 in pki-common and pki-kra. - Ticket #69.- For 'mock' purposes, removed platform-specific logic from around the 'patch' files so that ALL 'patch' files will be included in the SRPM.- Removed dependency on OSUtil.- 'pki-selinux' - Added platform-dependent patches for SELinux component - Bugzilla Bug #739708 - Selinux fix for ephemeral ports (F16) - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess (F17)- Added dependency on Apache Commons Codec.- Add '-DSYSTEMD_LIB_INSTALL_DIR' override flag to 'cmake' to address changes in fundamental path structure in Fedora 17 - 'pki-setup' - Hard-code Perl dependencies to protect against bugs such as Bugzilla Bug #772699 - Adapt perl and python fileattrs to changed file 5.10 magics - 'pki-selinux' - Bugzilla Bug #795966 - pki-selinux policy is kind of a mess- Integrated 'pki-kra' into 'pki-core' - Integrated 'pki-ocsp' into 'pki-core' - Integrated 'pki-tks' into 'pki-core' - Bugzilla Bug #788787 - added 'junit'/'junit4' build-time requirements- Updated package version number- Added resteasy-jettison-provider-2.3-RC1.jar to pki-setup- Added JUnit tests- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #744797 - KRA key recovery (retrieve pkcs#12) fails after the in-place upgrade( CS 8.0->8.1) (cfu) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #746367 - Typo in the profile name. (jmagne) - Bugzilla Bug #737122 - DRM: during archiving and recovering, wrapping unwrapping keys should be done in the token (cfu) - Bugzilla Bug #749927 - Java class conflicts using Java 7 in Fedora 17 (rawhide) . . . (mharmsen) - Bugzilla Bug #749945 - Installation error reported during CA, DRM, OCSP, and TKS package installation . . . (mharmsen) - 'pki-silent'- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-setup' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737192 - Need script to upgrade proxy configuration (alee) - 'pki-symkey' - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-native-tools' - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-util' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #737218 - Incorrect request attribute name matching ignores request attributes during request parsing. (awnuk) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - 'pki-selinux' - Bugzilla Bug #739708 - pki-selinux lacks rules in F16 (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - 'pki-silent' - Bugzilla Bug #739201 - pkisilent does not take arch into account as Java packages migrated to arch-dependent directories (mharmsen)- 'pki-setup' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-symkey' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-java-tools' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-common' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-silent' - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . .- 'pki-setup' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-ca' - Bugzilla Bug #699809 - Convert CS to use systemd (alee) - 'pki-common' - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- 'pki-setup' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-symkey' - 'pki-native-tools' - Bugzilla Bug #717643 - Fopen without NULL check and other Coverity issues (awnuk) - Bugzilla Bug #730801 - Coverity issues in native-tools area (awnuk) - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #700522 - pki tomcat6 instances currently running unconfined, allow server to come up when selinux disabled (alee) - Bugzilla Bug #731741 - some CS.cfg nickname parameters not updated correctly when subsystem cloned (using hsm) (alee) - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-selinux' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-ca' - Bugzilla Bug #712931 - CS requires too many ports to be open in the FW (alee) - 'pki-silent'- 'pki-setup' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #724861 - DRMTool: fix duplicate "dn:" records by renumbering "cn=" (mharmsen) - 'pki-common' - Bugzilla Bug #717041 - Improve escaping of some enrollment inputs like (jmagne, awnuk) - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee) - Bugzilla Bug #708075 - Clone installation does not work over NAT (alee) - Bugzilla Bug #726785 - If replication fails while setting up a clone it will wait forever (alee) - Bugzilla Bug #728332 - xml output has changed on cert requests (awnuk) - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-selinux' - Bugzilla Bug #700505 - pki tomcat6 instances currently running unconfined (alee) - 'pki-ca' - Bugzilla Bug #728605 - RFE: increase default validity from 6mo to 2yrs in IPA profile (awnuk) - 'pki-silent' - Bugzilla Bug #689909 - Dogtag installation under IPA takes too much time - remove the inefficient sleeps (alee)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #720510 - Console: Adding a certificate into nethsm throws Token not found error. (jmagne) - Bugzilla Bug #719007 - Key Constraint keyParameter being ignored using an ECC CA to generate ECC certs from CRMF. (jmagne) - Bugzilla Bug #716307 - rhcs80 - DER shall not include an encoding for any component value which is equal to its default value (alee) - Bugzilla Bug #722989 - Registering an agent when a subsystem is created - does not log AUTHZ_SUCCESS event. (alee) - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #719113 - Add client usage flag to caIPAserviceCert (awnuk) - 'pki-silent'- Updated release of 'jss' - Updated release of 'tomcatjss' for Fedora 15 - 'pki-setup' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-symkey' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-native-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #717765 - TPS configuration: logging into security domain from tps does not work with clientauth=want. (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-util' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-java-tools' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (config file and record processing) (mharmsen) - Bugzilla Bug #532548 - Tool to do DRM re-key (tweaks) (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-common' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems (alee) - Bugzilla Bug #694569 - parameter used by pkiremove not updated (alee) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (alee) - Bugzilla Bug #694143 - CA Agent not returning specified request (awnuk) - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages (jmagne) - Bugzilla Bug #698885 - Race conditions during IPA installation (alee) - Bugzilla Bug #704792 - CC_LAB_EVAL: CA agent interface: SubjectID=$Unidentified$ fails audit evaluation (jmagne) - Bugzilla Bug #705914 - SCEP mishandles nicknames when processing subsequent SCEP requests. (awnuk) - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #707416 - additional audit messages for GetCookie (alee) - Bugzilla Bug #707607 - Published certificate summary has list of non-published certificates with succeeded status (jmagne) - Bugzilla Bug #717813 - EV_AUDIT_LOG_SHUTDOWN audit log not generated for tps and ca on server shutdown (jmagne) - Bugzilla Bug #697939 - DRM signed audit log message - operation should be read instead of modify (jmagne) - Bugzilla Bug #718427 - When audit log is full, server continue to function. (alee) - Bugzilla Bug #718607 - CC_LAB_EVAL: No AUTH message is generated in CA's signedaudit log when a directory based user enrollment is performed (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-selinux' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #720503 - RA and TPS require additional SELinux permissions to run in "Enforcing" mode (alee) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-ca' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #707416 - CC_LAB_EVAL: Security Domain: missing audit msgs for modify/add (alee) - Bugzilla Bug #716269 - make ra authenticated profiles non-visible on ee pages (alee) - Bugzilla Bug #718621 - CC_LAB_EVAL: PRIVATE_KEY_ARCHIVE_REQUEST occurs for a revocation invoked by EE user (awnuk) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - 'pki-silent' - Bugzilla Bug #695157 - Auditverify on TPS audit log throws error. (mharmsen) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen)- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Added 'DRMTool.cfg' configuration file to inventory - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #532548 - Tool to do DRM re-key - 'pki-common' - 'pki-selinux' - 'pki-ca' - 'pki-silent'- 'pki-setup' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #694569 - parameter used by pkiremove not updated - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - 'pki-common' - Bugzilla Bug #695403 - Editing signedaudit or transaction, system logs throws 'Invalid protocol' for OCSP subsystems - Bugzilla Bug #694569 - parameter used by pkiremove not updated - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #694143 - CA Agent not returning specified request - Bugzilla Bug #695015 - Serial No. of a revoked certificate is not populated in the CA signedAudit messages - Bugzilla Bug #698885 - Race conditions during IPA installation - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems - 'pki-silent'- Bugzilla Bug #695157 - Auditverify on TPS audit log throws error.- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #693327 - Missing requires: tomcatjss - 'pki-setup' - Bugzilla Bug #690626 - pkiremove removes the registry entry for all instances on a machine - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception. - 'pki-common' - Bugzilla Bug #692990 - Audit log messages needed to match CC doc: DRM Recovery audit log messages - 'pki-selinux' - 'pki-ca' - 'pki-silent'- Bugzilla Bug #693327 - Missing requires: tomcatjss- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Require "jss >= 4.2.6-15" as a build and runtime requirement - Require "tomcatjss >= 2.1.1" as a build and runtime requirement for Fedora 15 and later platforms - 'pki-setup' - Bugzilla Bug #688287 - Add "deprecation" notice regarding using "shared ports" in pkicreate -help . . . - Bugzilla Bug #688251 - Dogtag installation under IPA takes too much time - SELinux policy compilation - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #689501 - ExtJoiner tool fails to join the multiple extensions - 'pki-common' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #689662 - ocsp publishing needs to be re-enabled on the EE port - 'pki-selinux' - Bugzilla Bug #684871 - ldaps selinux link change - 'pki-ca' - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Bugzilla Bug #689453 - CRMFPopClient request to CA's unsecure port throws file not found exception.(profile and CS.cfg only) - 'pki-silent'- Bugzilla Bug #688763 - Rebase updated Dogtag Packages for Fedora 15 (alpha) - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #675742 - Profile caIPAserviceCert Not Found - 'pki-setup' - Bugzilla Bug #678157 - uninitialized variable warnings from Perl - Bugzilla Bug #679574 - Velocity fails to load all dependent classes - Bugzilla Bug #680420 - xml-commons-apis.jar dependency - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath - Bugzilla Bug #673508 - CS8 64 bit pkicreate script uses wrong library name for SafeNet LunaSA - 'pki-common' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #678715 - netstat loop fixes needed - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - 'pki-selinux' - Bugzilla Bug #674195: SELinux error message thrown during token enrollment - 'pki-ca' - Bugzilla Bug #673638 - Installation within IPA hangs - Bugzilla Bug #673609 - CC: authorize() call needs to be added to getStats servlet - Bugzilla Bug #676330 - init script cannot start service - 'pki-silent' - Bugzilla Bug #682013 - pkisilent needs xml-commons-apis.jar in it's classpath- 'pki-common' - Bugzilla Bug #676051 - IPA installation failing - Fails to create CA instance - Bugzilla Bug #676182 - IPA installation failing - Fails to create CA instance- 'pki-common' - Bugzilla Bug #674894 - ipactl restart : an annoy output line - Bugzilla Bug #675179 - ipactl restart : an annoy output line- Bugzilla Bug #673233 - Rebase pki-core to pick the latest features and fixes - 'pki-setup' - Bugzilla Bug #673638 - Installation within IPA hangs - 'pki-symkey' - 'pki-native-tools' - 'pki-util' - 'pki-java-tools' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - 'pki-common' - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error. - Bugzilla Bug #504056 - Completed SCEP requests are assigned to the "begin" state instead of "complete". - Bugzilla Bug #504055 - SCEP requests are not properly populated - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries - Bugzilla Bug #672291 - CA is not publishing certificates issued using "Manual User Dual-Use Certificate Enrollment" - - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package - Bugzilla Bug #672920 - CA console: adding policy to a profile throws 'Duplicate policy' error in some cases. - Bugzilla Bug #673199 - init script returns control before web apps have started - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-selinux' - 'pki-ca' - Bugzilla Bug #504013 - sscep request is rejected due to authentication error if submitted through one time pin router certificate enrollment. - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #672333 - Creation of RA agent fails in IPA installation - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances - 'pki-silent' - Bugzilla Bug #673614 - CC: Review of cryptographic algorithms provided by 'netscape.security.provider' package- Bugzilla Bug #656661 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock- 'pki-symkey' - Bugzilla Bug #671265 - pki-symkey jar version incorrect - 'pki-common' - Bugzilla Bug #564207 - Searches for completed requests in the agent interface returns zero entries- Allow 'pki-native-tools' to be installed independently of 'pki-setup' - Removed explicit 'pki-setup' requirement from 'pki-ca' (since it already requires 'pki-common') - 'pki-setup' - Bugzilla Bug #223343 - pkicreate: should add 'pkiuser' to nfast group - Bugzilla Bug #629377 - Selinux errors during pkicreate CA, KRA, OCSP and TKS. - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #658926 - org.apache.commons.lang class not found on F13 - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #665388 - jakarta-* jars have been renamed to apache-*, pkicreate fails Fedora 14 and above - Bugzilla Bug #23346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-symkey' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-native-tools' - template change - Bugzilla Bug #606946 - Convert Native Tools to use ldapAPI from OpenLDAP instead of the Mozldap - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #644056 - CS build contains warnings - 'pki-util' - Bugzilla Bug #615814 - rhcs80 - profile policyConstraintsCritical cannot be set to true - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #645874 - rfe ecc - add ecc curve name support in JSS and CS interface - Bugzilla Bug #488253 - com.netscape.cmsutil.ocsp.BasicOCSPResponse ASN.1 encoding/decoding is broken - Bugzilla Bug #551410 - com.netscape.cmsutil.ocsp.TBSRequest ASN.1 encoding/decoding is incomplete - Bugzilla Bug #550331 - com.netscape.cmsutil.ocsp.ResponseData ASN.1 encoding/decoding is incomplete - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #223319 - Certificate Status inconsistency between token db and CA - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-java-tools' - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #662156 - HttpClient is hard-coded to handle only up to 5000 bytes - Bugzilla Bug #656733 - Standardize jar install location and jar names - 'pki-common' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #623745 - SessionTimer with LDAPSecurityDomainSessionTable started before configuration completed - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #615827 - rhcs80 - profile policies need more than 5 policy mappings (seem hardcoded) - Bugzilla Bug #224945 - javadocs has missing descriptions, contains empty packages - Bugzilla Bug #548699 - subCA's admin certificate should be generated by itself - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #563386 - rhcs80 ca crash on invalid inputs to profile caAgentServerCert (null cert_request) - Bugzilla Bug #621339 - SCEP one-time PIN can be used an unlimited number of times - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #629677 - TPS: token enrollment fails. - Bugzilla Bug #621350 - Unauthenticated user can decrypt a one-time PIN in a SCEP request - Bugzilla Bug #503838 - rhcs71-80 external publishing ldap connection pools not reliable - improve connections or discovery - Bugzilla Bug #629769 - password decryption logs plain text password - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #607380 - CC: Make sure Java Console can configure all security relevant config items - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #489342 - com.netscape.cms.servlet.common.CMCOutputTemplate.java doesn't support EC - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #635033 - At installation wizard selecting key types other than CA's signing cert will fail - Bugzilla Bug #621341 - Add CA support for new SCEP key pair dedicated for SCEP signing and encryption. - Bugzilla Bug #223336 - ECC: unable to clone a ECC CA - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #223313 - should do random generated IV param for symmetric keys - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #630176 - Improve reliability of the LdapAnonConnFactory - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #648757 - expose and use updated cert verification function in JSS - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #451874 - RFE - Java console - Certificate Wizard missing e.c. support - Bugzilla Bug #651040 - cloning shoud not include sslserver - Bugzilla Bug #542863 - RHCS8: Default cert audit nickname written to CS.cfg files imcomplete when the cert is stored on a hsm - Bugzilla Bug #360721 - New Feature: Profile Integrity Check . . . - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #642359 - CC Feature - need to verify certificate when it is added - Bugzilla Bug #653713 - CC: setting trust on a CIMC cert requires auditing - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #659004 - CC: AuditVerify hardcoded with SHA-1 - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #661889 - The Servlet TPSRevokeCert of the CA returns an error to TPS even if certificate in question is already revoked. - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #661514 - CMAKE build system requires rules to make javadocs - Bugzilla Bug #658188 - remove remaining references to tomcat5 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #642741 - CS build uses deprecated functions - Bugzilla Bug #670337 - CA Clone configuration throws TCP connection error - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - 'pki-selinux' - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #667153 - store nuxwdog passwords in kernel ring buffer - selinux changes - 'pki-ca' - Bugzilla Bug #583822 - CC: ACL issues from CA interface CC doc review - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #621322 - Provide switch disabling SCEP support in CA - Bugzilla Bug #583824 - CC: Duplicate servlet mappings found as part of CC interface doc review - Bugzilla Bug #621602 - pkiconsole: Click on 'Publishing' option with admin privilege throws error "You are not authorized to perform this operation". - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #519291 - Deleting a CRL Issuing Point after edits throws 'Internal Server Error'. - Bugzilla Bug #586700 - OCSP Server throws fatal error while using OCSP console for renewing SSL Server certificate. - Bugzilla Bug #621337 - Limit the received senderNonce value to 16 bytes. - Bugzilla Bug #621338 - Include a server randomly-generated 16 byte senderNonce in all signed SCEP responses. - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #634663 - CA CMC response default hard-coded to SHA1 - Bugzilla Bug #621327 - Provide switch disabling algorithm downgrade attack in SCEP - Bugzilla Bug #621334 - Provide an option to set default hash algorithm for signing SCEP response messages. - Bugzilla Bug #539781 - rhcs 71 - CRLs Partitioned by Reason Code - onlySomeReasons ? - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes). - Bugzilla Bug #516632 - RHCS 7.1 - CS Incorrectly Issuing Multiple Certificates from the Same Request - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #509481 - RFE: support sMIMECapabilities extensions in certificates (RFC 4262) - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #511990 - rhcs 7.3, 8.0 - re-activate missing object signing support in RHCS - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #623452 - rhcs80 pkiconsole profile policy editor limit policy extension to 5 only - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #661128 - incorrect CA ports used for revoke, unrevoke certs in TPS - Bugzilla Bug #512496 - RFE rhcs80 - crl updates and scheduling feature - Bugzilla Bug #661196 - ECC(with nethsm) subca configuration fails with Key Type RSA Not Matched despite using ECC key pairs for rootCA & subCA. - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #640710 - Current SCEP implementation does not support HSMs - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #668100 - DRM storage cert has OCSP signing extended key usage - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - 'pki-silent' - Bugzilla Bug #627309 - pkisilent subca configuration fails. - Bugzilla Bug #640091 - pkisilent panels need to match with changed java subsystems - Bugzilla Bug #527322 - pkisilent ConfigureDRM should configure DRM Clone. - Bugzilla Bug #643053 - pkisilent DRM configuration fails - Bugzilla Bug #583754 - pki-silent needs an option to configure signing algorithm for CA certificates - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #640042 - TPS Installlation Wizard: need to move Module Panel up to before Security Domain Panel - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #588323 - Failed to enable cipher 0xc001 - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #645895 - pkisilent: add ability to select ECC curves, signing algorithm - Bugzilla Bug #658641 - pkisilent doesn't not properly handle passwords with special characters - Bugzilla Bug #642741 - CS build uses deprecated functions- Bugzilla Bug #668839 - Review Request: pki-core - Removed empty "pre" from "pki-ca" - Consolidated directory ownership - Corrected file ownership within subpackages - Removed all versioning from NSS and NSPR packages- Bugzilla Bug #668839 - Review Request: pki-core - Added component versioning comments - Updated JSS from "4.2.6-10" to "4.2.6-12" - Modified installation section to preserve timestamps - Removed sectional comments- Initial revision. (kwright@redhat.com & mharmsen@redhat.com)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi10.5.18-16.el7_9    pki-ca-10.5.18LICENSEpki-ca.jarcaconfCS.cfgCatalinalocalhostca.xmlacl.ldifacl.propertiesauth-method.propertiescaAuditSigningCert.profilecaCert.profilecaOCSPCert.profilecrlcaissuer.ldifcrlcaissuertasks.ldifdb.ldifeccAdminCert.profileeccServerCert.profileeccSubsystemCert.profileflatfile.txtindex.ldifindextasks.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestproxy.confregistry.cfgrsaAdminCert.profilersaServerCert.profilersaSubsystemCert.profileserver-minimal.xmlserverCert.profile.exampleWithSANserverCert.profile.exampleWithSANpatternshm.manifesttomcat-jk2.manifesttomcat-users.xmluriworkermap.propertiesvlv.ldifvlvtasks.ldifworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalemailsExpiredUnpublishJobExpiredUnpublishJobItemcertIssued_CAcertIssued_CA.htmlcertIssued_RAcertIssued_RA.htmlcertRequestRejected.htmlcertRevoked_CAcertRevoked_CA.htmlcertRevoked_RAcertRevoked_RA.htmleuJob1.htmleuJob1Item.htmlpublishCerts.htmlpublishCertsItem.htmlreqInQueue_CAreqInQueue_CA.htmlreqInQueue_RAreqInQueue_RA.htmlriq1Item.htmlriq1Summary.htmlrnJob1.txtrnJob1Item.txtrnJob1Summary.txtprofilescaAdminCert.cfgDomainController.cfgECAdminCert.cfgcaAdminCert.cfgcaAgentFileSigning.cfgcaAgentServerCert.cfgcaAuditSigningCert.cfgcaCACert.cfgcaCMCECUserCert.cfgcaCMCECserverCert.cfgcaCMCECsubsystemCert.cfgcaCMCUserCert.cfgcaCMCauditSigningCert.cfgcaCMCcaCert.cfgcaCMCkraStorageCert.cfgcaCMCkraTransportCert.cfgcaCMCocspCert.cfgcaCMCserverCert.cfgcaCMCsubsystemCert.cfgcaCrossSignedCACert.cfgcaDirBasedDualCert.cfgcaDirPinUserCert.cfgcaDirUserCert.cfgcaDirUserRenewal.cfgcaDualCert.cfgcaDualRAuserCert.cfgcaECAdminCert.cfgcaECAgentServerCert.cfgcaECDirPinUserCert.cfgcaECDirUserCert.cfgcaECDualCert.cfgcaECFullCMCSharedTokenCert.cfgcaECFullCMCUserCert.cfgcaECFullCMCUserSignedCert.cfgcaECInternalAuthServerCert.cfgcaECInternalAuthSubsystemCert.cfgcaECServerCert.cfgcaECSimpleCMCUserCert.cfgcaECSubsystemCert.cfgcaECUserCert.cfgcaEncECUserCert.cfgcaEncUserCert.cfgcaFullCMCSharedTokenCert.cfgcaFullCMCUserCert.cfgcaFullCMCUserSignedCert.cfgcaIPAserviceCert.cfgcaInstallCACert.cfgcaInternalAuthAuditSigningCert.cfgcaInternalAuthDRMstorageCert.cfgcaInternalAuthOCSPCert.cfgcaInternalAuthServerCert.cfgcaInternalAuthSubsystemCert.cfgcaInternalAuthTransportCert.cfgcaJarSigningCert.cfgcaManualRenewal.cfgcaOCSPCert.cfgcaOtherCert.cfgcaRACert.cfgcaRARouterCert.cfgcaRAagentCert.cfgcaRAserverCert.cfgcaRouterCert.cfgcaSSLClientSelfRenewal.cfgcaServerCert.cfgcaServerKeygen_DirUserCert.cfgcaServerKeygen_UserCert.cfgcaSignedLogCert.cfgcaSigningECUserCert.cfgcaSigningUserCert.cfgcaSimpleCMCUserCert.cfgcaStorageCert.cfgcaSubsystemCert.cfgcaTPSCert.cfgcaTempTokenDeviceKeyEnrollment.cfgcaTempTokenUserEncryptionKeyEnrollment.cfgcaTempTokenUserSigningKeyEnrollment.cfgcaTokenDeviceKeyEnrollment.cfgcaTokenMSLoginEnrollment.cfgcaTokenUserAuthKeyRenewal.cfgcaTokenUserDelegateAuthKeyEnrollment.cfgcaTokenUserDelegateSigningKeyEnrollment.cfgcaTokenUserEncryptionKeyEnrollment.cfgcaTokenUserEncryptionKeyRenewal.cfgcaTokenUserSigningKeyEnrollment.cfgcaTokenUserSigningKeyRenewal.cfgcaTransportCert.cfgcaUUIDdeviceCert.cfgcaUserCert.cfgcaUserSMIMEcapCert.cfgsetupregistry_instancewebappsROOTWEB-INFweb.xmlindex.jspca404.html500.htmlGenUnexpectedError.templateWEB-INFlibpki-ca.jarpki-certsrv.jarpki-cms.jarpki-cmsbundle.jarpki-cmscore.jarpki-cmsutil.jarpki-nsutil.jarvelocity.propertiesweb.xmladminGenUnexpectedError.templatecaEnrollSuccess.templateImportAdminCert.templateImportCert.templateadminEnroll.htmlsecuritydomainlogin.templatesendCookie.templatecms-funcs.jsconsolehelpfun.jsindex.jspagentGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaEnrollSuccess.templateImportCert.templateListRequests.htmlProfileApprove.templateProfileList.templateProfileProcess.templateProfileReview.templateProfileSelect.templateSrchCert.htmlSrchRequests.htmlSrchRevokeCert.htmlUpdateDir.htmlbulkissuance.templatecloneRedirect.templateconfirmRevocation.templatedisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCertFromRequest.templateerror.templateframeCRL.htmlframeDir.htmlframeDisplayCRL.htmlframeList.htmlframeListReq.htmlframeOCSP.htmlframeProfile.htmlframeRevoke.htmlframeSearch.htmlframeSrchRequests.htmlframeStats.htmlgetOCSPInfo.templategetStats.templateindex.jspmenuCRL.htmlmenuDir.htmlmenuDisplayCRL.htmlmenuList.htmlmenuListReq.htmlmenuOCSP.htmlmenuProfile.htmlmenuRevoke.htmlmenuSearch.htmlmenuSrchRequests.htmlmenuStats.htmlmonitor.htmlmonitor.templatenotImplemented.htmlprocessCertReq.templateprocessReq.templatequeryBySerial.htmlqueryCert.htmlqueryCert.templatequeryReq.templatereasonToRevoke.templaterevocationResult.templaterevokeBySerial.templaterevokeCert.htmlsrchCert.templatetoDisplayCRL.templatetoUpdateCRL.templatetop.htmlunrevocationResult.templateupdateCRL.htmlupdateCRL.templateupdateDir.templatecms-funcs.jsfuncs.jsheader.templatehelpfun.jsindex.jspindex.templateports.templateeeGenError.templateGenPending.templateGenRejected.templateGenSuccess.templateGenSvcPending.templateGenUnauthorized.templateGenUnexpectedError.templatecaAIMEnroll.htmlCMCEnrollment.htmlCMCRevReq.htmlCertBasedDualEnroll.htmlCertBasedEncryptionEnroll.htmlCertBasedSingleEnroll.htmlChallengeRevoke1.htmlDirPinUserEnroll.htmlDirUserEnroll.htmlDisplayCRL.htmlEnrollSuccess.templateGetCAChain.htmlImportAdminCert.templateImportCert.templateKeyRecovery.htmlManCAEnroll.htmlManObjSignEnroll.htmlManRAEnroll.htmlManServerEnroll.htmlManUserEnroll.htmlOCSPResponder.htmlObjSignPKCS10Enroll.htmlPortalEnrollment.htmlProfileList.templateProfileSelect.templateProfileSubmit.htmlProfileSubmit.templateRenewalSuccess.templateRevocationSuccess.templateUserRenewal.htmlUserRevocation.htmlbench2k.htmlblank.htmlcheckRequest.htmldisplayBySerial.templatedisplayBySerial2.templatedisplayCRL.templatedisplayCaCert.templatedisplayCertFromRequest.templateenrollMenu.htmlindex.jsppolicyEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileEnrollmentindex.jspprofileMenu.htmlretrievalMenu.htmlrevocationMenu.htmlprofileMenu.htmlqueryBySerial.htmlqueryCert.htmlqueryCert.templatereasonToRevoke.templaterecoveryMenu.htmlremoteAuthConfig.templaterenewalMenu.htmlrequestStatus.templateretrievalMenu.htmlrevocationMenu.htmlrevocationResult.templatesrchCert.htmlsrchCert.templatetabs.htmltoDisplayCRL.templateunrevocationResult.templatecms-funcs.jshelpfun.jsindex.jspindex.jspservices.template/usr/share/doc//usr/share/doc/pki-ca-10.5.18//usr/share/java/pki//usr/share/pki//usr/share/pki/ca//usr/share/pki/ca/conf//usr/share/pki/ca/conf/Catalina//usr/share/pki/ca/conf/Catalina/localhost//usr/share/pki/ca/emails//usr/share/pki/ca/profiles//usr/share/pki/ca/profiles/ca//usr/share/pki/ca/setup//usr/share/pki/ca/webapps//usr/share/pki/ca/webapps/ROOT//usr/share/pki/ca/webapps/ROOT/WEB-INF//usr/share/pki/ca/webapps/ca//usr/share/pki/ca/webapps/ca/WEB-INF//usr/share/pki/ca/webapps/ca/WEB-INF/lib//usr/share/pki/ca/webapps/ca/admin//usr/share/pki/ca/webapps/ca/admin/ca//usr/share/pki/ca/webapps/ca/agent//usr/share/pki/ca/webapps/ca/agent/ca//usr/share/pki/ca/webapps/ca/ee//usr/share/pki/ca/webapps/ca/ee/ca//usr/share/pki/ca/webapps/ca/ee/ca/policyEnrollment//usr/share/pki/ca/webapps/ca/ee/ca/profileEnrollment/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu       directoryASCII textASCII text, with CRLF line terminators (Zip archive data, at least v2.0 to extract)ASCII text, with very long linesXML 1.0 document textexported SGML document, ASCII textC++ source, ASCII textHTML document, ASCII textXML 1.0 document, ASCII textHTML document, ASCII text, with very long lines?7zXZ !#,] b2u jӫ`(1z&-sPqhCZH uA~Z 5~1Ŏ yЪ@yT9zۙlPjt .!p)Ž2< 3J]vG%Iɧ0lxYl낊+ ?$jfHg˲jZl~R OagŔˆ!HZL|u>FP>n4pM!ͩ㑛=3a]yG: S?vu$cQsgHslSTg9Ulj) jDC٢\"N߂^ݖ KG`.iA!MZrkV^ϵjsȨy=GHGRX8'Ӧ^wIʞ ER܌A/#1sYb/]T?_V xÜ3bOl5Clou>v jG!fSauQWLX$Bo&GzIedY*vy>@PF߮tzi@|@*C 'w|*$S}: F/\&9FRpǤv*аR.ܡœ5Hηʧ.7`R(M}KdU[浌xMFΟ/؟٬q̍* dk_|gF~UvUݴw2,Cvhe0$?aNwbny~O"gH_҆x\ŷc$8 ێ=^]_ķHܗ^BfI;\$3nʼnM`n4=@9#7[CѴ|]$}7Zv ڗ?Z>3lq -dl{:}lZhrLXlv:ukUEW'wY,6a2ߚIqA]ӊvT]r&8|MvɎdoF\2巌gW+üJ%D;kh=(wM g%lP5xxl$C38LD6;W/>9ޤMS_Eڕcoź|u"ݩ:?lGsL9.%&y L ѿ!#{s5^U4v%/_YY,-k`R#WPtIey7 z~+#QY@Ce}pLgu Ybˆ6 n=3܆BӕȕU嚂Ob{,2guկV7r]o53Sʏ4b)m'$|y34EɈmCQ!wUJӚe?9lI{[9t<J| Σ5Z|+ڃQ4lyEئo:bZ^EL"iP~9ae).JnI=f?%NдqMƷ4G>0>D9QG Ɏx߻Rpn_5}?]WO'h^&;I~DD$Kux:eK|" |t[ ׊A:$۔ 3l g9Ta#AI$(gs9r(X~@7Z|!JN1Al%B1!/] *rKXA(а(]Brc.ۇ%Ɗ;wMi-рg/Em;3s];'RE^Ӓ)),d4rW~+ݻ&[O?ص$1SNwM6NcX4WIcN[-k{6Ww 4鶼f hOVu5gVڼDQ&NQ /L}хݔ}8u**5WqO,kfwzk҃yq(0#;=*@(*(U-|Hr4Rwfu?|h1Ge=)Zsa\l<+ H7Xa{vqzt@b&3wV.oLNyO,)T !O+fbqe 2<}KE>ڵ=G o F#FA ]*Ҹ"c$MYa[tHʨAj˰)*k&,Ɋ^m-<`dVT?Z% Aw@ސ%͗tynu6Z▢`ڕ ?N=`u@s>"cTA>lRM߃kd0w6r$~n%ȷGvBTD{%՝j&> qqjG) #dw q H.c,vlS̎PʠM~7;?ttio [&HY,C]xfCd;f4DRC۷ؖp*]*AևE!q%uV=.Pc%-,|zPEmͪ~l"g֚BE\ bdL2&¹5ߺ^Bi rڨa]yJJ |X=A!lⷶo?%{wzߕr"j]~4&CaIK,mǽ1MaxB9| ;QW`™ ?Ff|Z/ؔ5hd <[Tܴ:=Gy('F\V  ",ue >kaBN%+ T=$\a/B9cDO5?n *(kQnM:J^*P?x eI^s=VbO 'O%^(Wv2ƾi6[ 0)|y;!G>E(S 2,+v[*ܳIFs0&QRƖ~5uDF:‘t?EWlP1.ma?Y0߸ϙ I\:#X'ɠΊQ,`qBtq:t~ūS f# ^AaDOjm:ܴyR"Q!_guTEc"Zs^LXܸ_ ؤ _cr/i2}YCˢRQmͅcY60W'V۵ vx2A4iEuQ0? ܧKaƘł޲g%wBO8-)nTz{4+溜̯}T}^;\~;I628~GDwLfݒC Ţ{Wf00yK!(4D]$HxI2T5"QZdүրJo]\>C9qsaҔX^foXSoSѱ i?QP.8v+/ ( F1HNhC#aTγ.-DnJ }q8F{#9EGJn\M wo o>z0G|tM"5mWzokOpr5@X6Je*K׈KQD/\VjwtyAdȄ| g@sWK&n3U8^|$jߕ+Ama cyͯBS/dR_JB[h"woTHr8PքhcWqiqվ ((xBpbMRjIݡO1^.XWDnDO瑵Rʛy FfhFbQITb-jHIC|\g$w?ɤ[;lv0QZF/j&ѧ/Pz D^:z*9Tm׷cWE*Eݲd;.&L:vC`g;VöZJvz$ĥ$&co_9e,33(G7\Jع"OEd:G WM֟w'Smg^B^ܬ5Py; I >fH:leԱɬw-鳈{3Щ-Q_J2vT!-Z1J%[UyOp>XvA`khf\@JA }haA]+aYFk;S]8(=E~ϾsFO ׆XUč9RUC"=5|ZcU_n59Xm+5S WŽBv[n Ň|.B~ᳯzP5-Ϙ;8*@gβrdsAݰ 4}(n'A~jU-E˳%@FvXM`,{(bYjf5opkh]K3ל:}Bͭh zFD*d; br.J[9f9(;w~k_ov+ϲCgG`(W|w,.i|5>()ÆA”n)/ir;*۰Ep~ >L6/!U)3.ܵw*&e$QM3ݵ:C:!%({AZՙyGcʉyQh -o֯͑۫ɻzԉ/2D;ƬCē匸/eƎt Q$ÔB9$ECJsK(Cq>n%(߷u)NI/xD/5ⅩD I]czb2#<ÓՉfQ%@ŴhїN"֝Nձ\DDž޲^VJ_}w~V0ƹl:.Rw؂W[4 cĞH}q4=0*[i<i'~Bb:h="\bz OS712lR[S?Ƕt)dӺDv]54{;>HFlZ3M+ lfך-zpa_]?s . lPQajAb NH5_Z )&Wd vŕ(^.e=(J-Siؿ45R]jΨj";r+~}a]3 ?m(oArac˿7v<.9Q9 6 CdκSҼ1fxN}WoBuLnd Dd&6H oxi4I䩷( \fC.x %=qţ!&{C?Ԗn"ڿߵE6Znw֜7. OsLWco ug,{!_onܵ<'vjMjItwNj 5`ZxzUx,.tz|GEK奦 [%?xm"t\e:@bN.R*M[33跳R B-9 Zg"h󣾤`N:`K<-g\`c="GgEbV:c=)1"<#DS"EEvXEW]gB?@^:,?2Ъ~/ѱj+ԚawLfo=[V0)uxqv?1 ogũʼn6؍,B%LCR)@-k*,Zs3kP5)ypeQmӁBjܓ. (acyG Jo+F} uź ^:" p; 7NdÇ@>(i{*8HyQ=YHܒ%9uOd$IߒT0Avb(湑5??˄{q>icvC ,l}]d.^QA~!uMyPi{xsU)']`U"ȬRipVYSTid/<"Uv5}.Zk2$,ԦML +V;r;\TϦ6\q1PZC(6_pm\?NE~F{M=L"S}iPbt$^ M _xf̲@$T L.VYL{/i ©KtQ Ȫۇ#qi"$-BIaUX[$iUt=q loLd%a)k9ߗMӺuE6޹L8!"EuJOjfu5 Rc?@SGvS׷2H_UMF]Ⱦ'T).n*6fX%KgHjXtqRXod#]xA8"Lik4" bijyO=>icbb?6 uE%ɡ+[)wT%;fi: '6w8SGg䐧pUկia,.'(J@K)˺wp\[{Ö9xc;_Z!=Q>Tu}oD@߫ g @DmTq23$nP*5Ž[|qxrm|v+n`TF~:MG\-I'AK^5H[ҘxR>"?S3YA%g!MPtI}tn>zR$lF=wH vI%O7&?PZ|òKcViӥ *`Toj`~e>D/榭80ӈҷjQßMTJ:yY& l87T$'4SEUglR7."] ,^rew;(1_";=GI#*5ĐQ_{XBtokmWZrDSx7+v6h&a-'hPMu 'lW.VbxWtA5h V9~}n5ˮԃxl͑.d^÷@kM=sTv7,dtW',dx3ds g-@&6mѾebwIΚϝ5֨8gIZM6 0 i f<%H9V܃<_Ufu@8k0sb`EɷfiE^L:t~|Ycn^܃( 'XSZiVhu|`F&5A& PLkⱩj^}X>:W|oci1ٲsOw\q[ e 1xp=xx)S,}{mSQEO&92k~ pSPQ]̰Ywio%pQHIZ~ME:Log9uhXw0ǡ?1U+>z\Y)jN![92 ېV_r"Y?1g"RX)r؃孴?=z%eՉl̺~kǬbxe9ht]JINGN$qXlA.lvO4%r__9`6s86wAaF JXjnQ8?*ݒ#($-*6`oiR%wȦ "noRj|O'qLCQ+&ԝ*)j$P#I㾮UMjO'5P;?;5v)<^&5PGhvvWP#$u*]d6 S H"Ŏ|(wN[ KY;Ht)O\Փhh<v>/@81c&_=sifvgŅ] Z*4latEM((TʷTּD0)v_y#DA6:ιpvgnbyTțS@tX Z>3E|:DC(gFziAqJ%|퐻P&uԗe@΀歄b a]:kҀr܈L+dfBT[BA J9dv^!j*DZs|2C a"yrEXܿyjO||bRW}9~,3Xsa=FƑj(7GcRzGZ.!S<`4Ԝ-Amc/qdnnHgJ x^L9~ׁ_囶AsmlO0O$0/EJw͆{ʴ@2jFHSHP,J#h70[Ro1,3  ўm)G7+Q`ILQ3A^TUw-{46 꺷jpPOgwJ*ô|m>XMJxa*T}JƝRyMV3,ٯ YCPd|񤅟3}tj#T(t 7`)EGꍱIlܫzyIVWѣp1Ds淤FJNku:bq5(L|V O.3_n厃_Q\AhC#1 -MQȯ' '-Vܦ;pRL^4G&sS}MERD r.1 z.G|ؐj|iQ<[^ VK j|]asV3ϐgnW1,_s!G/6zIcnS7pѪAnvkcPtI[aaXh78ÿߕkmtn%5 3罡h0iQM(zQSd >83ȬY^(*4Tg"pB`Ŵ?% K "`HtPP#w>| :9ZC8cN ,v)slU+h;LZDž2rB;k]v7@larm g" %ϑ>nɼ,h?c<5]"1i3x9D)_cN/`CYXByrg|h/s}+g)AT1뾬C3#ﭥQiۜÐB\Þ4Qan0\ DXTiB1aOW ⇒0Tdk Е]sR`n~ 䓇Ogπ)IeW |>S4`nogl#+e7Vcwsפ=gM[xLp&cHM^1Ì!'Jye)zƖT_]A6ݜ<%17χ߁0ӟ"ݩb$z􆠱6m@;I[ pߒ` 7Vw Fl ]U^[jw$k˓>9P~HS5rVBQW0 -15 `v1:ۿ~9Z~}ՁylR·i%["Q@ ᾧp+LcSActr`|ZUQ'#=,C?+a`&Dðφo*~S-? ^ Kﴷ z݂=B8Պ~$7Մ1Lby}!Au|%|ժ^s'@u;3{CZ⥫9&6Pt^p (Biaݕ!%2nl$־d|8VOOl"< c~|acͷ⓾`S sG1`y`?=TB%#[HQbeԏΐ& KX/=3%k۾n l:3עTp/UЁxߓ ;幤BP3_U'`s LT L~Bl7j^NrCs.d#۹Y A!_}M-=.+ٔ|[Nx~̱1|,LCiT#rYF9PwJDZ [n0" \Ql9 7l]wf)7$5bhMW-2Gb bllDpV7@'=ws+ۣ}LfxZrRPz2߇.i&50՞gcipaS+3u7F  -IYlIs@]x7\/2z#aGS%EgQ3RRY(*ͪRJwN -( *r袴Sm.;Ww]xN JhwΪM|nHZ, dWveqϺ07CA8h[a(`CLYv) %uCa"")k&)VI>`&҅q̃[D6E!tzW}_,/dVIuVBDֆp9BMp)Kh};6@?PG!_ qm@2mY& -Ayv "* Q;՞9Xw2R#{(/dN/bUDfiu[ ~1W ĠOxTח;aU> }> MBˤ5(c`kČX YJQ 4N>Ԑ3McSF ~6Wk =@Q wS0.; c}9YQ8x 4\Quӥ)iHށ#S"qXsR_ THpfSi 't$=2WhzUk,{w|U c)ݝ}iW+|02g}/ht8"H_8 iQ| :,AϏ*'Y.Q7782; SB̦eiReQ_@  OD!jpFz>P櫋Fhc5` 9Ȳˎv-c/Зq] 4v}lW44Ƌ>6"glؖ'-1>t }dv9zs$|a>A0p{T^\<1KEzXtЯ QUCT\d%2OǁEw r53>>bWs;BA^XqC.XN+[C ;3W}<V뺉>l&˒ތ9n)3sk4jh 6v^uvνZ$ ,Joo\Zxz~Iɻ4#ƉJ>|o! KtIrr< ْPe46LDֱZwOZ^r.un4vᖥe ئ Pc4&^𯌒j+䞸X Ku^t1/%gwrMgѡsXZYUQӷ`RLh4{ZA3 )`Zg&VB_Orrlnw/_Vs7*K+HxH) yiܵ?|Ur;V9ү5}Ɖ-;9cODCN ƴm[C dO aIfr5WEI` 8ʨ[=T\]z@OGݞB_OEY;Q_oZ×î =Y2`YSJЇKAM٤D1uŰ4ySJ2汐*7LdPQ*fN]ŽaBy+aTHBF?ym $*-AK# 7*「WO*چ +-F0^n0,?1 TiR>WKQ95_K{I6"ԑmɢݶu kDK_rTfCa-p'."gRT4u5- zrjgpuG! ˟YGOa6>:4K2^DXקfTu{N_u2X<`1xlsuO fKSVvJKH'ifnMW`xΠcKr{dϒBpBg/VWHU{#)$B2s(1`qhq̴mե,nȆs+lAz{cvgB;~%Ɗ OڡNJxk"rjojUK)*m-$+AuaѶO Y6ۏJhTbQ?կO7%Cj!:񻟜jmMCidH1=,Cd޿]zsSRfa8A:g1.2ŜFD[=X ^ S5jyZׁ7@RD{"јne[} &OCط:~e3DOn_X c dvfb1pSGe ]Y6+p /^n*oq1>SÄZmqCm3.;'-|ii7? V: ~ѐPs%\nx8z-'G*d.K6ݫA!G bûL\QZ$fp V9c!EP#L;XxwD3%@bSc2e.(X=hUL!ϴҩ"+ )^پd#1rJK g!a,Lױ yb݇ܠ#?,'/p<#CxǃC#I-ۿVj:FbxpuQ9U[[5u8Vg:Hef[n ^NFHa_Faр -JwyYK +,}_MLȒ`-nbme1m|kN&8l躞,N{!.b+riܙ%`g0a`;z~fu>\rRi~;+_EWpょ*5i4:CÝ6M3Dhv7(x1_M#O BZNh"|VJce761l Wzީ:ٌ)ѯ7\{~4N?-UMxV B#C]єL먚{lJ5؋0s9HqO550#C{+IaWn\?|Nܣ:le@Zd51]t'\HηlZU {Fi}ʭ |XTIlԷ x٫OW mv]4*ɪ# u` P뎗woƼLc뢪pUm5/. 9ꀹYfX:>V YO:]C^aQjʓbj"&<^Ճ5¡1~N{'A`7mZHo+4h3ڟMʈ[Vȫ" mQ(A %M911z - }E=E_#Ē\D犘e(fy hv:!ԅ-K2&%k?d yw<5̻#/:"[H)x < u*3v!cBpl.${wz̒ӎru0@Qt#iUexQV5-˓%$(#9ҨSQ ;wQ+c2̣N N&^ F{[#2Q`\A|] jS[>|Ez}NOLOl2lm>Я9TWPs7SU FTwɘm/yk$J!) !fjz]emx8bf?z O֊]ۚ f]ֹzzs#LCUȴ\ۛ+ҘDCnt3¤oU3h|O1aE1[_Yo>$YfibX W2Q3C*[%`v\%lw LrљakmfQRiŞ:+o 섪#" ` Q- Nd~pbȭ뿙 Ea~Ѡh ##[_B!>~ [:͐s+Eץ4&9vBԭ띻r.CxQla#1jRzPܝlW}g;O p@unZYniAR`(a](D=U+:WM~Ys<k ,ʔNUOUՅ%Ѫ([48 Ws- U}p(okV6ǖ^PFQL~vq> ?Kzy.!۷$^I?9Hok)?iqF= ~|[ƫ=VUIx0tLd3Dj6;k'g ӁAp%-iڶYL5g'@Ⱥ|gȾferL/k$ޖ.azo0jcn̳E8 {0v@<hZ,ì G>T_C։.~}Vj8UkJϗaMk>H5(Ձ9 ;5惇 & & jv)Gb~1IOOs7L4)PَII8w1UM4☫G-~ p+|VJ&r"i0TU(漪KGɰw|.i oa(_\j Tn|]n"L[9΅e4$ /AmK"QyM9+҉IܩPgC%pV~wN>`0iYFFAeTd7і*vMGz-̨R0N1.zT9C[a[~Q!%#$2@ sӄO!Oki%Bg,lHE7娔Nؓ<7ޝ?8K^I7qy>>D(vW"?5*&x'n_,aMHQ䔺+kO2 c?Of:֯>**4͸5r?fYS&H_ֽy*!U= F0.eB/!sوPjQ!ZhN OD';}tca huag#XYoiBhg֥8Tv|C?בȁ|B`QeЊi-bjE4MYX`>k2fo\+H^Z9lH :% _!9;Y`P0"._MNoաՌsP9fsDG00ԡQs N>àzHfgF`e҈oNn2!σ.4l:46o̴А[~$r[!~Vr(^Z}ws=VpQ_XSou 9-cl:[iѥMfOMDeWF\pAc¦ƅ TN4_TU6ds/vfHoڲ)S}( |W@azbv|7#5Fh,uOo <0)K-s|2=^RYsQN[KKDFYy׶p568ZgNrڈկAzI=n~[3Lj#;}[O9d#}ÿsqQ|$bĝoҗɕ᥮ӾԨP䵓$05JY^I#߁zWN4%NI<*SF&8 Bkj>4'(w&ѱM̘DAl>aIkgU9ߛHk|}QK#կ뙏pmv'Ͽ"Af@Sd8Ŗ_CM8 "x Dق|tڗBYL/1 x+ IuW}:`EQQ30ʼn:hBt .T딻NBV  ɂmMgIKzy#*q a=ǝYP%/YS?HI׃Xlx9[es!I0>D֠1VV$AqHMV( A :VkW`k[eoFm&Qh}U"'ɹ\m_yͅsmK)4{(U9[x6إ0٪)-W/3=ޠ/v 4&Y\HOh1\&eõ :>1i=1ZfB:,nB -D -RcU-BTOFkt ma'd,HI⳴t8Rg(ήQ蠰]4uqR^A#tEᭈUW#'AtK ~}g Iv):}iEȋCi3ZΏuGaH6| <(SCLj064}$!*kVqaɻF$?sڛ))tRJAvWus!L[!Dy+Ck*M{OZg`S e#d+yǕAo+mCNBDD&\`,0G}!s;uHn.>yb $'$7hr?Fߣt6.ZE,Y;%L @D}3%;g&&Qtz,o\ƅ|.xWmfPzwE); |<=5xXcnA~tL3iUîqrvdM6W¨d3*}0Uɉ,|2l]XӚ5#o*z4؏v;9m.<IZO[u$pH>]+h)2zP15z 4J]gІR/mb6P2ն\II]fe2Bz<.dյPOv~]}O03QSbPZ"=:CJtnhΝytQ#ƛtC_={~6+T:RĪ9q/B% 6GY;ZEW ʼ>($ XgPʷƭ)+K 8\S/.m csd-e%,!O,WDYVM:<%c 6Od.`R1ǛPu_UtzFf/ `4ml%9p` $cctC~8̫ƈ36`MT/?FP(2&>rj2wBF܇/6zI ǫ` paETӏ3,Fv3xCt/VLfLKHz%iGџi*|@=Tk_)̞hY ;r/?4 t/ÍoӀdZ=0lsB0-CX𰬪 JһDU!&HBS )/KUxFR*bYyX2q;B AH$ZZ=l!'9Ů=$.EE# HE[}S=ƭIL\(z' 'x"9ž:FLPb \f=^^uO͆T.:ي'8:m,!?'o|ئf.jHռΜfY&A 8D5$]7QB]0U$Os64žDQA#5[:4 |HӤMmjٵAq5 zSԗUi9%N9 Pz,o Qg`/ZG!gǗƣ&@p9'rCq9J#ѻ B|8&uc֊Zf{ '֬$CVɘ(?e[ltsv\.H hVׯ$pMN $ovcv1.ΝCy-%C:p@{qM=H fz>M܇``'5vSYOdo]+M5dSR1<93ۡ6MbxE)fkq6o$|Y zĝ^~Lj j#6kF~jB=ޮ #S|XYFces۞3gf|ǫ'52g [x :Aery1$ Q);=VÏg,[q]I}G/dw8q"K=`Z5J,,5t[-W[<Ց'g8GK|RL T*ϯv.; >NP%rSTcp u# -k@Jp7W^C_O0hi!Y9ZI5D5n yfeIh9'Җ<!2Ph, !tP3mJፏ!E3\ sxsH_0ؗE RÏ1,&$,_ۜOl e|oQk \_5i>)> d$J G]~Wqv]>شL lAoz6^Tp߄xY m&59vqFdqckXV/7ɯKؒ/c~&c\~l;sM;\A|u21+b:\gyBL{"sܑk"+n(E:V;۲p]'ƞIig=!^Mh85U6İ˾d(NhfkJܙ@넍y'>_L[h(ݝLcЯg9r` V WIȼMs"VJDc5BU\]JTzXߓzpf}]bUV~>s7`D?')'ρP`;^& Yc; ܤ5 <+{}dBF~m(Vu dY~o䳍ͽ&z)a[8(<1/] 2sm @!NU֛\U7yL4nxvH3rMB-R&mvGApA.s3}{]|qO&ɩG#;"}9> _uGȡ Q[7"jVtG(^D"۝~M aCK"9gshh=o¾&LI7%Iľ[Æ}dzl6Y}bf8&pM2b`(SͤJa^&w·%\S!yuQ]ze]Sn#冚N&xG)I=(EsUtB-,GH[Js:t^/Y@k4MA`/>vEy]FjIBN7G2#eշO5rG48 6Dqb׳ ce//NZGp@<#1$YRq_I<]s4SA%Y>pc0d>tteϯ$]/bֆ3[BQea`g!V2 ?>AWwݑ`_º#ˎNNGOE-5Dܟ/(Z%__Rzxo.xɺ.=L,pSOqiTXf|AL=ȏbC}b>AiQnF~9vE$bOFR;ȩeD-moE~$F A+r>jmTRM$D@bȦPtW1tVy. MUx9>P1uD5CJuD 2ܮԿZ6Lѹl,%NQ_^B8?M _xtts.ű욫ZCM[pTIZ]ajF,EZ z8icYd̦y-]OïiK!D>,!Rɪʼnt."ƨpr?cqzP,f>oO`bSrˍ)߲;ģ='jvpoj5*.(E|P4Sm˄y8uQ-,|S"Iwo@I:q2׺X`_1bM]?Nw)[b*uMJw$~J#Ҙy/^$EUYw0ީs\80H@XSxER,YQ"}Q=SeA"5أ'@u˷~rV]Q:\`9\˼hφoex"i;1E9˅  <O uŪwwa|ό .; b yEܕW ӷ/w\/1c~Ksի!*3]A A KU/2tr]`kOέFm͐2q!ig%djͩXf"$]ԫ grA6oՂ g?"劸D%.MLʠ<m,׍8\39*q0m^r=Bݓ)oM#}.l8C"e|#n:6pIW@kP#;ՌCxBf#@! м #Z-Yp); z *J]Vc654 F"~I60ץTr'v!+@:懖sA}!k0}M)3uǫ]ϴ; j8{.B֪aE I{bQp2 UF;Pn#u^7]~UQ[Y[jVO3ky{=zGFu6À9KaWh>踡m/MRT@&t,3[e]֒I@5k08&Qq$ϺS"B+.uJkEz{6@4R\GbYKy^MdXM/bKI<2?# +df{LЦzy;R= ݱ^n㫧P| A[V譢~uk">K!"(f ~L9AcԾJ|2FvJcˌn`]i%V-6;/ӐrfUdwfAx@&OFB/k {w-Z{h{)FA/%I3\.Y)]bxOE&Y\%>_ibOK:=,XKkjj?}ԛ)ڐ?.@Al!5zCA+~h@0|̀Q+wlhNgɨ!S|BOuO)ȿQxX0B5KU8ڡtle&~boS~L4>9$J t ` ':n"ͪjH +q.3UҲU#9JP+JKa?؆:Ք[r3yôCDAU$X-#x]'?i1amف ZcXUwvN#A0ezÞ&a#L͚Mo o[B9GH} %V_K2R֊.A^.10*K6^ .0OWBBɋwT:WUr`។ԧkW Id (._Ovx_n ,EQ]Y?1t c7,5 8Jn[b$A7_]Iw|᮴މýNuԡKZGdO%ѝW&.@;s{m sĿU i<$K.9;B21 R3d23z`,βϖ*PN]T\48mmy`s8.4Rॡ<Nk ɑGkY*T(1peg(Z@U}p 6+ ;Mj`p412\a BF[W-<k䪬U!\49&~۠.C5V=bHZM+\6O: n5$+n ]& gon~tq*EFLxV@ZH`Q{)wJUA-a;Uon#&1Z.M%֛^{j+*V]h(\zҬpybxv 1C"gu` ,p^ hGDάT4sRy1&|8uh _~H9oJ̜P,^kXF!ɩ7E .q4+|C;,I\n&"*<N;TZJx0"Mb ˻0B^ܻ E-d|jq!?ol-k-R/jlH1+:"Ub.,C,d~DaOvX5' {6ވ^5C'utasy+ϹN;}qcr%i}sg>*M_iۅtU0Ȏ1~}U;pkWBeSP`TWbhۼh>5{C'( ӲIcl>O5|5z^d}#C@¶IM\($1z2oI0J۸Lu凉wW!6tMr+~Ƿq60S17Q|3a7{۾Ce$]d6HR7 Q-/8IQ<5Zt 0~550a !ohQf-0YxtZ1_5"pE:t1d9}H 6̓آRKzŮFl7?JJgVJП),TYΏC*/{=:{(6lzaT!(. '.4iFLOfľbTi Yy2IO_kV}SN|xr41?$C/;~zٝ ^NkaI<x܎`0)NS>򎴐hV]Mz$Q"%|m{{w5$; $ K8A5Lf[g$.G(ilB?[V{`)|7bÈXX325gRp\߼uh|^ƀgn`BT$mrSl/iJ}7T!=RiEo5 cB XWb;le1Un9qst{cxSҜ̄cq{ `:ȔƼNp{):q0ʬ+(,Ek#EO:^ӘM !JmhZ q.%=;)ۛ8ity@y˃gSQlAx!A<}q.l2G_2ē h 6祩NY2JNڸبrlu^v:ڞZC| h cN(U?+)?Xӿn(#wTśgC'RԕF9?%49BGFmlܨzIKig $`JOȉ$&F >;8^,5Lr [H$|twI: 75^ҫ>u5Dnw|3G+> m/M|FFhX%#b 9P0 4P2Ɲ@/ JeS9_wQD`Dbs I+c8 uW5p!^7Uw|GPrBeh`` T]8H&ө/ Cgmd,OXIKH T3C@3ۄK E+ ̓:Ԝp# O^cLT@yĄ?_:$2`%VM>+ʑ]lvSv+)8 Wp(C?[MVN K$e8h BɃ|"^q]:{bd4pf}>.tbݛ!B7Q_pǟ\K8p۴Qf۝{K8nؤ{|`5!*|ZqHaZHCÅ. 籐ѿK#F:ԑQ_} qvIHPrp*Ѥ~؄i -JhQ;0mK<'H P[wB ]Oh&\@=ۗ4LHM ?i ++1Θ+0.3*ե.!{d(dz7 X= 1_i-.yo*V}hA%dFO}i0ܚ3`b_A0UnjH 4c*FL_eIv*mH$:"o(A >O +XR_?fѬZ6ں/NJBsIj4mUXpE*'/\漢K*LxP& .-lAxJh:ƨ$g𹬺e&gB)iXJ'l *8 UĮ$Z?R]C.!5Ǻ'/a ˍ9rTw7q9"^O*jkr7[| : 6ύE)}\rT(aw(vOɕpYcm4F\@AhVX S^ 4 ?oZL+RH@--7HPoy-RS,Hlꕴg-^6-_h hrZ5y^K1' %%}uէ^y~3,=L=Bʶ3?IzJ¦S9u,QDQibRookZ h$i3ں*Us@=:´pU%B,-mY og?ƣ LzMJrj, OiKc9i󠬆i%ae].PS&V6s\fmOKEL"ېABj]&ZAدG4'љEJ:|npdU@%jI\q~P' IpXPۀBj}jBS_i+7; l=Kx{R`S&o:u3B_-Ts //8|7T5 I373vu!xȆ;Ehxxcش]:?@}Ey /3S*fxq6,asUn^Z-(f6l70@h,DccLCm <#k fX3$zK!Hv t A7! |XY 2W韖,T%{>P&1x%צefT+/6gZDc늕4f[Av6yׄ*wZWب{~im!|t1O)N^0f# ɂ9y8ͶE+tŨ~,#Dz]6/ 'V$N<ȓ}/7#jͫ 3dcs36xcZe AT4ODf5꯾;3c5!:7HhԻؐI,GvsKԬP(J4*7!z>xxVd\TXH"9%(S0xut6ּ"Pr2)5iL"8ExƔMqQ^ TcR~"7Vosb;-TZ_ioE&ڬ#S±. G1@ ~՗Z;Wa }"ln^DK(E\mLG(!rwM?:Rs씂m෨bzy~SwtXPTlGȣ~Wwl}=\#"!JFcV(BicP @!ag w9G"/m%ۄ̋x a-x1t&!ED~ 3ZPqA((SKmxH}]:2uQcn5 \xӑuzܢs6:?w9C{uEi_2gFHn]&7۝7 ?d?Ģ¼$vݙ#Rw|,v.7xW7vS?n, Wj Q3][:FX ѽkʾ.V0V ^(gs<ф-X,3;][ /o[xWXN;%K3hI!q-fG'y2^ԄegLrsP*on}i{lK8CUF4Z(=k#_b<_ݯ@?ʟ?Ph[Zm.{%E<(<}2 -sѷ4@S%U bÑFb ߿%J^w~VV O'{%zi`dHhJOYu cpJhGoV,ke.v+a8tlv$Q ?Q銕ދE"2$Ͱ7>M<[.}N$xG +󇹝\qjhqk1Kyf9QS9C(T U&.o$A -@Ea0G\pM/j=IXnk1q=BLC=3.v*ؒ>#q7>X!W^S( 'mφ3"ޡM02Z!&G|m `ӱ'nxRSَQ:(B"1M]jG*%H1n[ +#s`PWaֆ2z&r99~i Zp1 +2*~֚DQШ߰ZeJ{/ey7 \=|B^DmPvd\wX,t含)>qRrE̩trOί1=|.= qҚ,fe y/Rf8iLqgޒ6g-cSG=F* Fo6/ܠoc9`&Hf~tLtZSB KI>myP0U_nChn<9N %tZyUw٨:AE,)ABQ$x"J@Ӗ(_RI +,dW9 ޏ~%"bNLhF"IhBmp1_I$Z1{O[w:uz$"A4bei[DHUPxe'=>ėex wM |>gj̿761޻G'uD^td6C~5o/Y(vY?|XO^]`ns|?e ` )s7RWq"- jm򊓑C-8uWl ᜻VG?#U >h)oADRb+eq !M k@g; ;ϔRl-~\l 2^ӂ T7Ф(sP"z5d+ M\>m8jGnv!c+FدWHTh h{n7Y5NF퍾|uSװeؔFX+qhjY>Ĕì[5<~[vۿ9-3| ȑHv^%c)u@Q3,$QoC,}NSy.y ͏4(e !:E8(^;x#~6α ¢t3o?(RP>ύ BjcXN&bP4.$Avl_r}fS[eҝw.K1x] bN;Of## ֡3Mh k}kjKOUSԾңHe*jSuu"-u7OkIh=|n)c=N*|SKi5PUt<~$ef hĖ LT4Pl2=w5Q~ aw0]K%3n\\{apkΒ+ X_bӑD?qX-ow jFXuXHKS x4bޜeP*,"6/v5/)7iυc7Ѵ7S0A.qt -;,J^?u5_F2^Lw08{c08*(i&XĹE+%{qP )c{1x a}aTIΪO3Tye}'.>^w]UUdcːЊ"PBavd<Z㖷l4]aݾ1+`#h\|Y?KplD1lw@:䠝LErCŽTKPOכt$4FRq'Nq,M'(52BiPOVge+g c+8f80Z~ˬ79zul#iBIz 4S|:T mun[Qȴ;߿`krb2=7˶tm{}kr%1VW,@z0vl/#^QPtik5~a ؉c+M&rSBHL)diԻ6Ŧfm#y|wyxBu3U^KW2`Le9 ׂ(:@)Z;- TB7 @#F6h$VD0s_OT p`s$S@ *{JDMRHk LaAM؍g?ӪJrgc2y>:h~B}J }8*xb V4K/r2ѡ Ǿ%/_9Ze薧{"pyeq.'+q>x1 2>y4_ZN+Y-V6z R5ܝjtWeE0Tw@ C I!g/5iuLmzl )3ǔ =,+ۨZW;7@]1Sd=*di #aסWA=x CR1gm-[FDۘX68N xd} < 9l)&d: N`;M,PWK¼3mR ;s)쬉b K!䌽=JzLWٸ: 22Bז(T Xuo KԲkWd ).Zա³#0:zHy B@%c_=6CaLҩF04z sم馧wi_j.?T(^H$yR*Д?Ԁ0H}uo !r@D":UET 1zǥT # xU՚A=Xq 9tm[:8^&a%Ĕ2(JXL4,dW,9ZDIajcݕVn95 Q=<$kM״9̛NjlfDŋeWnqk'-VH)8N$yK9z3Y^~훘{hhyԕ4ĆQb1">j,gȿ֔6'Hi={o.vp &!h7l"@}ǙkNj" @ ǢQnI"zC@x e9=>BR-5l͂~ aT@d x:GQ}٣h(wk͹/m$prZ‚z3.5[nn:,S\40`҄jvswyt{OT?Y`,jq1bK~@M!aQ GEHvjeɖ< HDRQQaI,P,tvx7qDVw/;ջ6aD>UB͉TV>.\rI>raz1,gf/E#hd΂@Wv~&NK1qS@dxgFҰM&!grJLdV><*^{ΘJFDp.#ˑoGe.]ͶT'C ^ׄ+{T` 濎s~?1@ :\YeaDQGl |g ͱ3ƘGӿw8;i;AH[0%uĠ H-Fbh[-2y.#N 潩~]ۊ vVefQn؂}IG"~OsAEl̳DCA)G.n8aj~0ڽ !nh Ycgf(1mIOen% '󈗭We4On$$YsC'<cm[M3ZvKXYb?wl%r*^fa]p.\3W<,$Ml?I};^PK#'UETJg}f. b$^4c"+Gt i ?}vr ]YrL+N'T1]"9N>€W? 8j<"^`cdfl߫ BN#}8 {f۱߫OO 4C7C3F;ONMѷ zHKΖW+((Mt>~hUPTFBQ2$J\W69]/}d W5/ï%=~ !Jug*3KnϴfjeZ !J z M^I9p{7n lS ,l͖XYYzm*~ !poH ؾ̟f1y:ow\UuK)y^2V%aVos}XO/50/OU ЫRt$-e$R wg{ψ%ɱ9-zF'=+i0V..8p#]DIϥ[{k74 ,ъyAB2)@d#R:oЇ}#Ϥ 鴃@nZrqWݥF"uG*:P0 u-ц頻{5esZ s\ c}YtI ?Vceb锔x9NK* NP[`,1r$$P&4#!:jںu`eߕ/mDI xp)({oQ%}xqfN'|PIz?>RvHD1RYl# v5kSXkeHq6"jS=:!yƀM~ Wc1r_'=A֤mt>o(!ӖAn?G-|d)oRF9=OSYt2!SaL-#P8He?ߐh4s;0?=yT U(uH6S#-̜-ډXZԡٖ\m 6ɞcoԉښ1&]YNp[Z Gх5LI2p! ߗy:sjNwOw 0\z^`/;pdYEפM7Ptmĺ<;xI'~t^v)Mh^Ky/BCg |r<${~X;'_ S6̲>3#E<P(For9h^oq]JiԸV /1xyV K\[^Wh}Z^A~B6IfI1墝;2YԢvNKH38uavp?0xc?;P Eb&18P WX!J "2 =]vf_ǢҊ,dp=&<ǠJ{b *Q4NF,z+ggGZAn"HML#ϒ׎:#+-w^@;ZsI~5Z|$ \6k ˈ?q {ڴ% QuL-f>O~ʌ{Q,{قw !'A5فē0ϰ_v{nc *x#kۮğ)f=hQuf l7(̜h֒s/jP~qI*!! V-4zq³M4BO ]&,iӝz)(K喌66;mМ4Sۊbͪ & >LA$0<FSdk3K-%)tL,1ٺϹ.  Ms.^YsFIDH}^DBthoL-}(ضG%OH[Ex刟H ArоCQ]v5W;^Aq.52JB022CdOpa$ɕwи&~Sλ6}47i0d6,fVR& T9(^yۺZ5]欮}k! E[Zj2q? 2qqobVP _4yza6dʁ2%ENݎWvLOzktpY)Y ? PAG2'2%\ώK1||Y"nMoqʇԧw5zԋsH,%ԶX(/L+@+u+nUT^Ł V'!6:!d5֕FzdhǡBS|"^XpQ`xѽyzؾ`s ¿Bu!1i^2ڊ52hy@lKvD*KZsw8o˷4Ж-{U )$Z,80&O PO p*&eӱ o² BHlM]p5 9Μx]!p ./"1;'ְSۧ{r"(&cn0 e?(GRu2ӑl;tLC怢K*W'O @^cӲT㵢eR:guG4ʭXDl;~O# ;uO݋mϢ"/MCM l n۵eEbW2d |B-kP-r:l1- @0-]Oyg}CO_SJXjgmQ238+HI GBHj'?+D6bG4BYR ,N^ƃ\%4sVEcmǨ9l|5t&: iSQ&.*/I=.!'HOCfWi5LCKm:oLIYa+}\KxB,JD %HiD1r7QSV :!PDS@Ɋ^X?7QזNk],˃x4j'?ܓni[u2rT=:_z:Bd $?{ qAPSJ{2Kg,11[S hndgNS }}-Kmnd!q^gt 4q.ܩeU_0DX]91U5Zĩud>mΉnW32D֑^?5Q YeG< N4Afb)(ܦ֋8G/yaM+!H 8酛xc$ =R b|kaRϬ .Ӿǡ ᱓ Ņѓ|塉D_kZilO *|8\s-Ge0l:eIŜAP5HxKg̑d%!bu@*SǓ)7,c>tpy,7,e$©RZNI˧H _㣾{ :V;kc0*n,s/)adtcMwO֛}8ӥ[Sr6I$=)ԴPy3ؒeizREN`qA h?]uܤ`G %G뢮^p?0Z}ӺD!Dڜc ,% 9P醀{3$.w>&g 0 c0͙7vq:,95SPggI)xPʜu=Ԍ-@+j<|{@~PuxHsfqaYM iUfw7QM(EQ&K=`^6t37 [^^9rjwA͇jh#ć#eL!TF)*kЕfn^M9q0M72Y7aIK~w܃ 0F'|[=hjtĸ ]-0;z8}cyu{MK`[\J<uVs?%3PRc>J&5'~m")N'XR70GȚ U EVҬ́&o-VIң*y7 V&<zj`@^{Z~Z:8c{BY8q%N 犅WhWV,Öd T0]nj@nIKYGR,GvUm8W֭ _tι2Gߍ0~Mg7L"1CԳSE5Z'8gӃa2x 4|nL$[qƮLh,~%xI\y?Me) eURBl1RS9;2h=zhߪՆG>iERyx/;W,h?d.I:B},_M DU\=i[M6Vf|fm}bRZbl}M~kRSCRߔ͎ 9Iॿbi۲CT{UCW@/hRetiINEm/S+F˃Q;?pFFy/x֐jČlcK-%Lh/yﳘXIrQmE vuITmTJ1.;B$Df"iy3F4p(L:un5#%qX$%cǷˆ%/DQ+fkTk^ub́gSo}rv!Bi&‚pX]Zl1iV*%O$0S:$ĜVˏq|eڀ,m8"_,=a{$o &4dO|xEE(NLp YJx4-'QcMu̸W΁="&Cb'L?lGR%OfK\+͍g X Zsv1J`7ﶫOd""[Թ1t khh81bО2MTi #( +ʤF/~\>ҞjK u}q5R-lϤ5'a%ۋZTwKA=4ޓ8\&%u4ͣ#cd _B`i^C5)fVʸu sP=Ӂ!tR$Կ<R2OTȌ 9sa\oS\V ھDr^}IJnvGc{ )ctto.KM`ELȇUYrjK}3zs}ꈀ0,R &>4{sR=D"mIl8C,r8٫[)d#$%hG&SZO|8Jw#Q8b~>>t,5re>imk'S FYb4΂2 +|Rn 8gTA ZE7 ֏OA<.c_UElQ}vpC%:whb *bk¥Ai s .}ݑѲʴB- J O8įv%Kވw$^h j u"?5T:\ۤS'%o]2^=|ð![3ԪC.тP}W#sFL 3?lQ;mu,B˰+H>l ]ꪖs"ѷ *ѭ&zCIezG/m4)?ɓ"6j5ַ-mïo2Tb,ߠulTwZ9++D{`V{c}*[<;$٠0sHwIHmc+D=<6Czhmt獨%?0) ēMۤli2yІ@zTޝI.ݺO6tP"x,(`?w LI3IXL]lTH wqDR{LbJq?e^}./GM~$1=B ],hS=|B#Qu]y8dzfP0]0(bYhd!C`4Qu"q>Paґ7>վB q]-I@tn5 h 2Wc5)0r1'DCP}޹^Lu 4vG]8ï\,6)eub{6 vS쬽"Gv^=msIL`_M=+t*_@ 7G8\UMsM'N'3=\ ce: +[Z YGWss- @PҭcEӟ(v[,z8Z.IaSmNEpYEIS7 C믻t<3RXФOfgqqmZd4xmO;F봜5^(1$|!Z΢AJB< OPͤkczRJg9j`&qBM謩o b4JRRJbLᵚݫTR2H驢֠O]IBLolAӉk:w,=Lz,SGTxU V0n0"=P0Eb\u}{xP5nK>Sf#׳Q%&Yq*wd 37VK;?M-ukOiHHP[~كΆ+g{w? YL)ŭ~6V @׶$bAE] ̽Uc0cUm+|]0"$<Ҁ\HރF7}|\ٲ1|B?`/:#%u]4Q4D3a{ HZYzp!jS|c`b(?).{9 hS? @,EDc,,!,o MHR{adi8XQTYiY{M*0drړ! j`/йQ+K*Y芧51SI`{+6_",7[pDD >2 ;y,X0:#RF ӘO[ ^fbkf7茙fGǐdL}\dn m0ѷr+cň  rpT|[I% 1e؛=ZxdaHagViBN uӌ&d 0z>7<1ۏU_w0H/l`9DoGF>S $jxf q+ow.Pׂ7IUwhFx|zs?Bq*@@uwҒ~׷ui\%KSj.4KKRn_=m2N?OـXŪKB`EHeCC0nHǚ v?ӓAiR[G~k1fd*p70V2AV W!UXP ?,%"aJԂofQڬŁd4:-fEPgm#tdʌ %f>%ԛ!=<C/sEbjD ~S!nr0wpWܩKgi3UR*tR2f#"\E zcɹNPLHg{zSI}KmٹçGtI߳wGԥ5[JT)E]^KҀIi|mM?Quz~MywKX,*^킞^: SC\/mEzr RLv2I5F'bdaUK|Net$ M5su% dZ ! K׈*uʷVEfb!I_j7Uc؉ܰI$ΚXg5L߅<#,I 1?)̍͛k%@m"XF ZY2J4"D3C[]Y|MkLsw:CIQJr+e}VSnx\W0ZmZ~R5mbA!G3S{ۃ$wI^*`8Gm((># > =ڪ/zU>)r򣓧fyzTg]GhCܨu/nl_[׀ _]㐊H*1?j!vf5UeScqD/P*#mYkvN X_'c ssi03Z*Bo6vf|-.u RF k7MZF1ޙwFtL]070)@G4f/[ g!$R~q⊹.J+c{uH5DYՙJSG-{4aiA o$VXzhD'6M}$:_y@#K *퐴 {ItKB_%# jR}o7!Ddq^,[bs9ϋ=OϐsOs18[f󩗛`"$Ju4UT?t\ֈ2Z_\^w&Om`b@aB7ۇs=4r Y)7i,-B/XU \vbhH p 寯:Tku&8lſnUWqG+~sx cʳyAA'+J߶6%cBxND@Ȩ]5c]*># DLz>N[@)ڊz$YvVtPJ=uf2m ,P<f l/rŸD,'GojBwg8#{Z f\t'x[m#Դ VU|QWOΩ}B# 1mq3׵0d8x?ɑ!x,P~Ti3)u -և&KLHċ@cR;+b"PjƆNݥΌCd[kTҕl5@jrJjPMg0(f큇<նx{,P4jc뒞Uҁ=΅Ls7ߦLƟ~yS@\,nzڜHȇ/I-,KT@uBe(x?/nQ}IUNRE)$j7 I߉ (ew[+vT9ʥZk^ɾ(إ_jVo7Utn)ըw*Tq` +ڙ1brEq=R;7/5 ݌D<:ހvCЪ%-{4 ?:?,KC'OMnyra1#!c:Q&XyJ֟y|͗Q)'OZ1u3[6I} U8-p^ϼذ4wy$ I`_ |Cyς @" Fʴ+fPN 7yFrB4|DPwz=nրv(Z1Vx1}xyP`gC:_3DZv{Ue;DN4Z(:s0TiSW6g;L|dp/:9Ndծ5f30[:~r ?a( ?r) ]}p j{! \ID3w#!P-n)Ͷ1>kͦyJj}vRx)2qXC.9|vKٜs$`f^$oQٸD}=/)4s fnϟ{fyvTB5|>0Ť$eK<ZRBpNx7dR%*'jq-SH7%h*"&Lyc&{ /UV<>}ڂepNM2t8^Ձ`0# 2@MHi>H~ʟT_V]{`B̵ d}ˈpn]7kT]8~LLy-^ !1R1w (35x~!%]pA@w*n4~R,/!3qSR8-Wm=֠!7\XgSNPkNr*K/e|9IԻ50RܭKX0~%j2Q|"|ڤV;Q}T?K<}x;zζp| n:$g X3xvui?(&O`XIXS%yfIDiMV+(ܢ!ˉ Rub7+*Uz|[(A+\j߬DC6{ӑ2=3#Ѐ x>!ğ9&>jV_D;%n=EJQ.N@l'WABnkڸuR@%>j"$U0|n#dD"~GNw N,ێ7-(;R*$(HnV6,rS[U>b3]Fl!4a&q,!IXz'&9D֖䛑 2;34+`o2sk#2@u[DD'ha jpK b˦Nh‡Gzg5:;Þ03z% @U pK'cFjV%=pcPw`ѣV^C[dzJ~X>>`3-63Gnywt,1Wto :b fbcH8WDoM0j=9Z9 aoWPg\\Xxc)_#' - QEYG1gpqgFAYqV-m2uDqHyzTn@!_fJeUF쮵$ǽxKZXsE1 $4padI 9t)' yFOjsɯ2 GBCF@mm $Vh""uMT𭭺"Qe =^IHgUJSqdjҁ섷g=q+Gk Ppȡ_ic[i#ے SN$|Ÿ}ZK$` $sJ;db/eѹj5BOR~1Ń&[b R{Jl//ްhU読wsa4fT(9muAQ؄ y#zڗ*Ez>Z*HpKts5u^z- sZqXH]8j{Fs'i[.%2W9Os\Cg^=% mY2Z׍b褁Ls]u9u؃[rC@h$MuOTaLlgV`a2a6}JxVfE[Ic Q^&Qy'];Ld{B)tM2L|^MwY^<%WEEȯnPshM΂CuUZ"i&O쯨;NHDJ~a3ZOb䗅yg3`TePJ^p#\|$=C QA rt%jړ"!dt5Oss5rM&AߙW)lnii J 6=vtTExǖi*hvt [ٝІj#WT7Pa@gZfkYKUݙLrf[ SWYQ kͦ^%!zȧ4k4*Pj4cͳy.g% ,8D2aX>$,}ÓGc|l[}. t \UH?0=aʳ-s$M/{7CzZ{(er2j1&8DҚ"Mg{q+dqb<rH#%n&sQWMp)a;UƑy.CkWip*W"M⣍ 2<~V*,)LQhoD!Y֚^δE Vq:qY$FV`5fnnKϭmWDẸ6x>z>z/³cM%Ue[}V2XМB]ܶ€ _FOPPY6GTQњo?SwڷK!ZRs (BζMO21kAKa9EԌT٫8nBk1Em}`M>Iޘ)j[5E=ş" f6gE+27CH!St>w` }8eSIexuV8[jJ,GȖg_BC?Yɭ**F u%oz]8:z&YRm[ւ=E+gT*կY" - 5]>uqm|I,wc- <}rL덮aU$[Ͻ$hq(!_,hxd/LX.'jsJbBrs;B? ]`5v @jX97 _ $ΉFe' ez0|g=>NF?)PtDw6u$y]JiJ졀nTtܤs"/BXĨ.?ۧp$7.\1˙.`n(a'!~97$m3޹ר3!#Ʊ'|iRl/\ޮ+>QE VpFUD=*tSNqzA8V^+wҾ`eA#\7'TWx>NjH >WЅkdRu8/Nwu5-e3gM^/#1h<-Qgh Ԫj'ݱ^JMLg|j<֤0TV GNQLEvҁ;W\#D:$mҭ?|Oğ Ii93J fR$;Zd{u^|g) ?2P%BQoLP|d'AhOp6:{ wZKݡ ]Do\霌ټ[u dG4DtӕӰ>}QFoG0³d!k0O@Ab>J̾u6slq*z w ۽gݱh`iO|1^ {%G~.I54g>v|k8\LJ}z{qv3t|7gp9q4|rF ~yPqqVGb4#{z p2Z-T,8;kl}yq!(oeR /ݞ7o@w3a'3YCV+a_޼hGt. >,ǛF3F⸐m fbqqVd.e|N9Ԭ;*¤j{'\ $4'^J?uƒwN &O&P~:)@&D Ah4>9D^%z UeO1bq)6DXwG[{=wBj18:bg[]g%p3 ™m!JhwFr6uµ)ਈsp⬿ǐIiVM*ۧidݴ,*BdFtC\VZf(l܈? D+ΜSFK]L}5٦6qn !wCrbE8ܕ1Q^OEş@e8ʚQ))qC 5.q}*7=҈tD&dcaZGUS^3sw ֕?'uCxˣY@䐒&]|:ʰ@m9‡t#YY5ĿLl5!jrrޖq[[֖a Cfc \>A6kUʫG3븲/8-{n2E S|mn45zhy|܍ (7iΌMn-OE͡(T%>8V"{Iz*\Ԧ((E|ڦְr͇XLoK%~ g\YzHD/O`ok+? [QFRʋ PŪxF3NFjcļ(Slv-(o9*GW8̽zӎ\?ʩrf<'"W/7\ 4S{Z#'m, _<#.03%@\i/bݲG!)15OBtVĿyb<{%/GPׇlQ]e^%LI?"G/?t5w"G"I%x{)| RݳM*Td1s*ڿnjM$]|BN<4 J昄oùU{Cl8q {)M𔄢HFTqcUFyY>́w{4jLT TV$b{[ Vr{&͟ `NJ{$kxl l]]- b<"c[^7פfURI#ȵe2;;.K3Ӳ# %L#4Լ3Ws -JJ#ڤ)p10fy4Ԣ )A՞Fbt.E?Z;/V6` ͳf s-Vv79-x+3vFZk~Zm?cpE{lXNIIF2]ffg -nbVRYT$lBk8KC؂L/sjN\pu=6 #1>/Ʊ ETb}4Iݖf06lDN]T]TVY={2Z Ӄ+|P 3r9͓/fn`K_<g8>a#j9u'ԣrQ +4jh'闂KS H&dTѮJLoqpP[\[<Vz]^o[wkr1WOۢaTT>v32O7LTcb \/M_9%㗑qn5A>0d+H=|H{R+?Yh &h{O} XG 3v D,wZYP$G6EaBߨE?~fiZLǏ>[$&Zi$ŏ)hbi5LN;F12V Ќ<m(Q]cr)û W^o{LlpEK~Ɛ.~(/!C'of& m QΗFXx{l]y9YPfCASyg$VTC!TTo+~W @/?RA=J0' ah6`dZ^xabLOš?}ŨKQK!޺}vgx!W q( }!1n6xJL4tO*.6afMxlO@"6mFVI B}]<RmP G{Z W^ Nz\`K!݁q霖Tr&{} ;<>z 3+[q9 TCO^ fKť}3BҨb*w- srO wRT/-&̧!=UcEK>ʼ!oo\buwwѮs.p2Ymr35Z4L"%ǢLiOq$E87U:eHHq-ɡ׶߸8/s?_ Q@p֩VkLZF눞t3hAs-߭X-*}-uҭRg gKbLY~ yCPȖ1[Lp+~ Cuh~z9:ɎKh ۡ$qZMSEÕRC<"d#g -T k%d(<np/ 5A:7o"<\u ?Qt0P)SֵPXEj=' $ 'C#;|$f;S_˪gG7^6d"'l%& ۬tL3oΕ26XQ436)ϾvN='Qv?.5EO7$t*qvl7 O^oI&-{ f"#1I]٣њ!!/WיA:%<ͧPt}ONEQc76Z+ms '39g8t$.e9D0v# ێKv|S=)8 ^/z^DWܹ~kQ'X^̰U"'ĭ?Cwb )R刵Q^􌹧q~(%+MHJCeur^ &*<9֙xbTH#?ʦ<p0K8@K}.MS_B&ړe]"4|/q\YrEc4^²-%hW>!,,@MY5H˻0}۴_uq!z Sl{p{5COAι[9q# 8QB[n=2\ՖebtfdQe&(a"1Ϥ!H  Y sYJ bGqZH'Em}'ra 6-8f(}am_;B }C=- %mnڜm@OAR}8$OLlr*pA[3LĚ{]c`t; IJ,& NwyX_yZ:]77IAnFҼCO|0Q`{tWf>L^[weҮܫMX Y!{-f<t,$R:7GUl?xK){dD=9i(l ?n8y/C,fUkp?>*QowVWWњ*ʿ'B| E=pB#`^q^?EKt^R;zʥ|!d}揊EJ1d7JW^X^qbk :naXvNTzÑآ՘ɧw DG%0~-!0ĩQ(N4,t*C.<*n~n,v}zN纲8閸?7bP|43PϹ<.4SK>iyt$-d#gy6Z V.wb@@~A7,n;8#f=ޑ/I$GڻJoMZ4:Cz?Y|d$ԿȪO{Ŭ8uf.lC(q{eŶ))**h$+ix, ǩtȵrZ(oă y>Z"_B{I5dznqw446Һexk]`+GB͹ ̞JD\~O0SJ3Ek.CIW`l1.*dy's} .dx~b &3䨾QS!VWտw\c|v㗮<Xɿ/8WTZbzB3v <VCWu^+'꣜Uesf@{Ԓt Հԧp߈51)+=߶xȿ ! cP.QY$KtF ?cM5Ya"^5Ϯo7 B]f0t{,CN.VM ŅK zOzo_CYGŹ $*^D{lwuF|U&wkN-ªCƒZ!< '3M.FYz*9|8Xxv g ZbfO6\XRJW U+'γ"_ VmFWX.YBLQlm#]~wdHm{4Ջo2 Zո-RsxZVi3}đ&f \,~͇w`ke7IBxjj?Ddʕ$Oq+Y5H0E'ZOKo4概\&㛏YꪀRake|MΓH;b~cڣxF0.3%p Hz$Njs `Siil ֒h\]%Ri*ņ4%7;."7_W ߡէk_ٍkuzؕ!dOEE*[ǺAj/_􆄕wU.7>-% ꙩ0b,^N=i~TjURbV\B,mOKWVسN4]^9?w y-d8"C>{6*T2r 竜p)-77%ۘMƵعJFYUf ^2!ult][uy(ȫF@鈮.{@`CЊq#.t9802pT9*D11g%r\mYf} `F *S= ?صqYws_4UC3P"FK&Sysf{Z`d>%m^皫*l%f kS$lO?lpG>7Am)s+yetɵFRfqi-E+#/U#jJc2Iq~RVKbyDɜu5 BVXU!2P!j6vEfD]w=@+}όI[/%5]QA*#, ~RTW ## lע3UƉP7&}*Z-NUy 3|4K5B]\m!2ܭY+j<PD%FJa%>>Jc:ȾTHoЙ+%?*GcXXDJYu m6 |Uګ{> DUi+K9;SB]L#!x}fco{=  Z4WZe FV8 q [JY ms#ڒ^WkN!Nrk eVq괬Idm⪖+›wyYQ,P_܌$TGYU)U#:NU]/}%fM^n;_4Imٕ/JFX(n2.;>EH ҡ6YםDࡾ=W,CMFEo ,JLqhuڲH"^~ftCՆr<M cQXb DškMi 7qz*fXWA#f,D9 #XQInD9۶Z d/u"Y4LBY2Va*pqqFHAu"S'dXFQR^&ЭfZq|Ǯ `0@tl>it_O$3@fvAbF[n<T9)1Δ);EHEO*!㙥n5ڨl 6w< 7kMsE,%T-=g^v2ċshT pSd;~:Xo4X dд&Wz{` ^ځ%2v!f"Jg]j=~epހ%ȭ15.d!B)QM Ҳz&.x iOTY29@78<͈.lf%[\ s?[&Fw{}^n/nN^y1&&64#OE)-5/!B@Qy0hIށ2][! v^ˣmb>2|qyB=,u hNCm_p:SWDxZG3))XѫE/@6k_pX:;޷dB~vCX>t Mc)RXxt&hwQc1č)]2LoQ‚K5q$HroЅ4S^Eo o9϶I޷LSr5г 1S5} t'oȗA*牐pOݲBKS#/gd=C=kҫhQSKG>P H4 |sj7;қ+sua $pHP@rIL*wa=k\0n _br{qnWQ%~)[G B:U@ K3\ueslm|V(\i%J(alEj*n֗zzrM] gׇ0y]]}0,{Mo3gFs; kMl%uY0`\ѦɅ)ˑw;.|Q?f%?zEylM|:yC2xe͈iW^=͚E27&1Ǧmpf `zNV+X@|D"Kt\5fMQv;?sݝС^g!Ceom1d祒[(s%$'N44e\Fl!2~4yR2}LH9YZk_q\1BnZfxw| |NUfA̻Q7sQ}5k!=ÚkGO<^8,nƶȭ{`j(fq]5)!ؗ{RrE#o6/GN¶V0=bv+e'[eоVe˲6 =)`;?\.gD5[fr K!?RƱw |2+8H-+xm2_pg^PKz5hÆl i_6Go0aqى1߶"pT_4h˕pGV^shWm_3̊u:T$D>Y>I JP'Jc?>bH8X[""Fcqg&O$|E}T#|$K{ mDnG_լDžZՀ+my3pMsh໶]QG1 ְ;*^2r\CT't^>s82X}hV%n<t*BF!NGrUSk}"6n቎у\6eM@IO&!z2ѿϘ¼GZ_(o9%ԯnn(sɷ [YC!]3mzASwx_j8o2Hk_Yh>$2󟂴?`PUti^)oAO3Qg<%~1+'[+xG +䎻HեwBTk6ʪŬ Pty@x€sK߁W`ʪtBtȡ4͸|AӪf٧E|CDmH<`Bu7NWhȲٻ\0^3;۵]Hܚ:>j%<+ͯL27 m]q8IW_8YPk'D/;լ/]?%CA 9{W k鎱;7ӷM~RT  ua~7 $/Ign"$PpGi-)iGhwp3b-J;PC1%XluȧT5ɋ]$LLYԹtB0P;Rx)گ#qYpTHP ZV_%9XfI__7pG,qoo kFeITG-FYۚ}hjر2-j]!WŵO֝h )FUҚK-3j D 4f{wp\/4| !% oJҲb#1 }Э9/ 9Nx D?˥<軮;|%0sȗC}/<*KӯMD{fDV5wYTG1ʭQB+;ta6x݁؀gJB& \[L$<Lڽ$M.ۚ4zMb;`qjR YySUL naglz$]dG&l0!hnzWtgg6fKLe04S<]$0O'mLAU}eo/UX8&3R{LۊV@63[ʻN3ChO0]Qܭ3P?-;H~:Kmg(ZvA:w4$q(JI=G aOW{=9m2}Osr1tt(c#ہInV_IUܺ)Ѻ[fN5&qpkUImaP Gr63d_C-Ҕ([EjV2$j`̃+96ZmT# ݵ=^yein[w5*lOU\s{AeH=qz[ @^1 eDrU;.*0,SLLs5xvry=29\#x`#'4w?`S`+Qv.LvIyY!6y|ŒNko|3!q opHTK9$jO:FDF)a.:$> YYu P*3INaJG+Qn/L1"k(c`@S:vVq ZY6oti 4"'_G9N!x TT`)Ő2_}sLѕו.&`iZ4kk%2[x!ԚQgHZv7S7l!hYqeW{ܢlsn*]a"NϪsX.Fr;0/> u@ [*}w\NX$= @lmRA5<^uiVGuh}qA1hud1n+RNp?˒_mUγ| 嚮 3-DS 7|1ں:^;Gڧ@+v9W 2<`NX@ #* @jӔy)M"gVRS8 ?P9M6YG/]PotB秘@L]ֺ:xDs7twQqL[+1)jϥI=zƍZ3ڍ7 Z[J[%mȐ3u2n{VjTPF7%+ΐELy/cVF` ܗ #[Cͭ?͜el=d?;lG[)I dx: ɒqibf oVXۮ`X~\I10 [C_qCD5"NmĔsk 9\pqުL[)_T:CSq>637j# D{j A r) f#.iKѬ%O )1:Nò&U}g} B|O]`]iBf|rPqʠ Y83Z{o߇T'C҈*B yGkhD 9kwi*h\'HV<567q:e!ðO쓜–A Z nXW//L2C߫Z*d..%W>Y #rhdݼQ&\Jma@5Qʘ$;~XoFQ ᇩ l?-Z{Xϻh{e_jr ٝM)1"z4q plX&w\Zh]ʹOGhc/LD {E j *F쉾d_@<6%(8;K`IDz]ÂpbϲJfiEqzANZjW"%~CA{q1S )Qq*"n Ƞr\ϻMk(i%Jf^ִT!{Լd&.^ =g-`z?uȭ6] i6k@mߧ8, 3[ g0<ةin)6j8{҇d@'?0XJՔe∓:7XU}2GY{CX.ng}z|"n'zheZ1 |?sa\nJ/<ͲYYfŪ;>.VW rV]2ɵD(s2֮\k\{{ r+M WM}|)Q #<=u*IۺY.cHT>4M T6Wq6KСP.I$YFZh"L5* 8,<ȞàOMՏMPS}d$h-`b C kkһo*H Q Kh?wgS%:(''7w{osiM Pe|%X" 2Db-eG=i!09Z]s XdaE]j,Ɩ+-k\ #F b*Zb_bw*CiU^"޷o咾rw<ߎy®;7ΐWu,-?OqfIaZ7E|y~QFfxS)ت_!V)0NlrĹ\yUە-,ڳYe'!41A<[ɀcм#7&OCt*E{3U8|cp7ܭd:gn8ʐ5,Xr#)G%%c*[`YYMF Ń/#3:͉q8Bz@3|@6Ah.Fsnv XFhdF8ej RW!@㆗*NDPm:]mϾ#7w|B⑿ź>uaoy?)l0WV&bGB2hZȐUo?j+ӖZcȮ*^} 4naB(<,[kptf^b]Xdφ3)i*~my 'mybg kE8 <\*(Doq5^jgSEOa[Etvk?ZU5&rG }]PWBX#So]4ƈ aۀ:8 Tw(p&kP!J|-nő@%KF}{^l%z;no[3%N2=FTh8nܑCuldPb6K7d4g{2&n"?L聱Z0˯\4 .y=~6h2VRs/th)8#w_/ <0W ">ό{>FOs@")E ZWu& H27dMJ~0M2L5`O73l uŻaiaN8y6Ԇyo4WZNֆM=ިl@!Px~X GEX C)[i7k.A}7I?x354tFBub\(2Q[=jqSx,)t@kD!B"Aw 2&*wkQ c zd'Sa'8[%k&[D'Y?LoEFwk| yxA+xDg&L/hFdG\)d垌T|߮Zu 2kF >>)P:^izTFB|J?{BAO"Gf7.j /QbeuuUFs%U)cոAE,md_^|T; dg ̧bJ%IO8‰;O;Ѳtή߬9[UMﲣ[e^r;/=0jaJʧӥ Z)L1~_ N?d[x}̷(,ʌ;r6qC폚 1jrv:t6WXэƙpGoUAH-ojM!ڨGXIq@IH=EdYȣ+s(bȣ9}0-7ZLF?0ę,`Zky7J&bij\J8<ϕ9`Ҷ@E eG=GZ]*,\KFC_Dxi'I GR͡HzDW?^J7 tk*|'|꘵nƿ14G|= BbHV,1&YP\;jNH*,M P׸n)!crT|VRv[*z|6&#bQ׈*h=֜]Ds:ki%9v#y!֡Œ|n0܅*M?Ƒ r\yLdL.p~FL"(>#6"9-ƴ*HGOUs|^suV{ad{ ,0\& δ7@q'~~0W\ܖ)`z9VLi:4CGZ?~J+ .ʎj\cƸUoKz|a6#Ͳ7z% sفk28X.m#EX9ܯjDl#`,~-J'9dʥCڤNm^d^OiXZkKCX0lvdGC٭m(Pl3 v&mHb"2q&J< V {}V +?.7~i`_{8p/Y%u; | CDE%ɛCޜy m 6+p:sݚsC$#tu١Ydΐ7 )ècA01U\zwU3e^IB/*H!xT 0AU&^ M58P+78w0 6-T`[,2:H]48LJ ɅqEזTOjpf|B٧^-lQL% a|B7~ C*y/_9oxDc#5<ͱ.x  p׹$PHWȤM@9?ۺRLY*2 Ǭ QPmN{Wg|.ċ-vEX&OyĀ%\և7{^mޘ|j%!+)&} ާjjtU6JdpW+ #=ƔQkY*IvwT`C'U1d$+6YZ^|8fp *9s[(3k-4xPQKޥяb[+'/vf8K78fZV1-︜tG\21^Axyg1Rb;caرnWA8QBvzyp)t'2<%)e_fMo;f; u2ܯ190c|'sNzC~m}$XSW)z]1-3!;{DIۅK+X 7$*~v?,m.mjL4Xw.x'jTKBwމ nh'(3"_ @& XuEɚq$US)/RaFj4/xЕۣq? ǍP:8O~k*}:~mt!?2Nجav4FGhsj7mWw%Ο.n0r,H6 Q 3cۋB⥌f7Mv\d)S,)hk BZ+>s;H y` h3e&Wc> =z[L7^R{{AXYg4g,Ӯ5-G8,/X"1҆Wx_+vB4%+2512m a&-lssDO{ͺYԓ\s]%h\X(3= )(+ˆ/bE1^Iu< j3[pv+X~~HSƓ-|.2F{9fOp`B+ clֲGȪfgR\ aS3-4'es\)UnϹa$&BYK4bHequ]dj`ͦwĤ˝ϒMS;}"@ΚOܨ~z:"zn-%Rzxx~1Z#pNSe k1%~/fvHҞ2JhxrRt>0 (૚f{2E2*¢iТժ3f+V⨞"(jp^a<Bkce͐k#t_^aN2=vv8A >}GK0\M0]NndXnx2qkр$ȹޅDCLB.n/tvlϞU,3"9fk>wQ͟K$V+T)R终D(MpTBB;&x@+J# ˄r@4Z˗u .H, >&s~X #XspXgq{@/n[86ڰ=Ȣ[X(9t*#;3{oqNkhc^rS$^OO{(ׄXlB50XY0F~1(XzU(.,c ⼡|U|@H|)}ZnuT :J^kU'ybβx̑^q0arW4+nJs:%[Sy0łڸX3{_bKlp1kRϤQqv%L v 3kzW޹Ӄ!c3tz\x{҉ufSY$(m㒸s/s˄B C7|톋\Vŷ6cK~GGqU@[XʮyR0& "Tflzɠ`EׂԐN멛بb$\IjZR_=؇JŠճ-/6u0`rg_gɐy㺂~F/7WX+tI2"TI{gɦZ ҔW G'Mw灕CEd31SdyĈwuJ|*ϭ5+J76 Vv>%L#FɴM8 /6BE.DGx<=2soy;>9y"'k,<ٗE^uS aӷwA˿1~wRX3Öz#~Cdι35Tt/Č2rʽmj@Ϲ[m/llc5bX/L4 _P-8hGfT~f9ٸ=m͘O sGj(tD<)}鵆rOKZI* CNR?kP %|?%(;<Cgu{k%m8;`Gu*!3]28?^SWunsHd/g ˦-hKv5CPz9US({ tuA(Oh9~hV)^x;[&?SElBgضiɧkb2JKl|jnvvgEҴr@VU7@|^@zToS4>MAmC 9WG2oEߍk Qrf7"3XM`/@h"ɱƵTUjK d]$h` hw[:W'XLJ\+ķ?Qjmzpi*`#}2A:nEWHPKE)z(XOkZ2: yJMG/skz7xȞBuMs,^&R5sHMvkRW]1f fJ%!Smb (+V .TM=ӠCJ{DϡI,߳vPP o<+RUܰ>SvWo P]қu$C qdž_Z4l}OW=(QE1SlXFM^NvRd )hMHCngr+ġ!p}fQev7rtY6YNŘ߬,=^ޥJ=Sg 'Xc4<9W&zeD6HFq>z]TtT ƝFbARQNNYRGS=mt\BDՉlx"KF0-d8~$]GRW`戃T6iet6ir)Q8OOR8~9J4$b!G t #Kޫ#ԘGF.kH7[˭\G0W^4ʹQnʹv hNqFfca|IU=xӻ`€/z\ꑩMNSG $sɵSbHobI"F}L>J3zH2Y ^56W&w?_DuOV^RC]S{zIb*- u/h! S|A,NMð'=ܙ$x4Qxwgf4J$7A.Ӻ6<а'z9  lD<͝. oq_c9y ە-\sԚb'ڛaw?dJN >.;s3Xg1DeKђhL@E;f-vJO.CE>4&dʒaˠ4fn<6/Hv0.wvsڄiJO]I1zxJߚu?A}QБ8l(c wSV=g=.vņBf˷عwas N +ȿþ> ELbO41 *@f vQ uY@1Ejʒ8>g!kU8 o*ӝWH[]+sMaE<U}%.b XEg-+*sVD-gN#\0T4JGNӓ;qCM%jP˛)Yk4|~)rApj:o̅~e\b Txy(nbeL-aʃLg#gpvbKP Xzlh2Gir c1$c^w{rDsgq{+Z3ØBl8jg"`S)5&eGZc܋E AZT?00D xqi}<u!((:-M.Q Pm H SɊOS\ujef.Q)[O+Ȁ a9wy|KeeY,#'\aܙ?!WE64͢/¯7'D翿Xp{'yXI**ݳIhQªJEy"8m20`+N-@*%@ W%owCX 'qo-ؠM lYOc4Qc1KtAAGE&vHboŮEM~ Ҡe4'vhPgܔK>XF<Ӈ&}4M4eF̵XddQ\8%@ &JhM Xj}/ĵE#{F!a R2(<#0rn&FUUI9T||'R=YlWWV=v#d4I*c]o\I/z8?7lu3N-IQP1+RF ,tM/z,l{Q+@ބF&N@PɷUgc#5 JUVddyhh{ Gb&2C!#0%ØRѬZUJ-" dgquGsy,(i㊆J`V \@#1k脄FdDxItF`AsǬ[ICƚRiD| ĿnX<<%ɔT ;=$f\寇')N!M ٪W/$!uocxbɺE|ȣX u{\!O`l&KaEm@L;INbgP<SVbA/:'ձCC?@' ;,(9fp۹U=K9NAcZ #4rZg6BZj##ӧrDOxX[`}bH֣~'GU/VY5{XP=Tr)M&xeN8HEwGPCRk>K txQ{[^d1.ei_<}^?B@ 8"yd,!H՗N~?W Qp4 ]鄫gR  ȓ.Dh^c6d_a$dce9D -/h[0ȶ̓drZfTm:kFtk ?  4|Y.Gsㆵa ^3K;D7\׆SnҼ=FPәץ,vV(UV 8St0qwSI2Zg! C 9uw3wXӠATli魘 t!YLyXT:Kr/o@ $#L+t0pz{1sX'nǮFI +*5Vf*vìncV$. sz02>!pdg,7KbضPChNͲB2<@]m_?4y{4\1Rr(!Q *{ToLGvC!wU\**(L8Mi[aIuwYXoHW$@=?K"_/v |B`Xm~Dwmyo u*ZW$&G~iKE4Й0)UD3;`e ֗r1LIkQXu-2Wn4ul\VVgqrk\fxťW5҇j.?m<ײS@6io-9, X4i2>T0dP~oސ@+HHH?G ]h12:t\׾ ?d. puNd_H/#.Q%Ђ&5w Y|\},55bKQMAզ%xYG/u|/YK (;_ȝ_$|~\N`r^>>F`&¡ov{\%mq{P J@#D߶ׅvp|761иl-$#1^VbaK ,v7V9R3SR|.,N&ߞ,mq=X&'I(m  *12}p0Otip%kdzHHĆt73Wϲ`|:Y`m|QDQ5t)`v&} & )zJ'N&/@d?^&@G?PzZ厈Wt^+ }&3(/Il[*2/VQr-Bu > mg#)HMm4Cm;}'N5CV zgeW?30\~=rMkbqzm)*3EJ>+ؿ7<.g 4H]7S (U͛fIQ% 01R- 2A˨+ry]ۨ@3wXNj8`eRaYq^} C-Є $ԺQ~!E9h6VrkX'Xq3~DЫ+IbodkIELIsՄ׎̈́'Cso T!p ZeI(% ->!;$e!bjcBzszc MMv5sROW;HYqzp{ '?ȗjR,)pA'<E(k># ~;ê)_3WC}5pϳy;q΂j5_ƹ?} 1Ǯ)R4+*ȆҐBm-䈪1ߞ!Gur {c7a}7#% r,9A1E7-;$ ӱZBW1`AaG~X8j"E 6m1`L^XWcHUtIK.SE!Yu{)x``fü/yVFzwAWKn0ʋ%YZ}$U6M/WEyuZݱLo]~3:O^A) _tDPi>yNꃻ,fp6遤43dějP|4b4ZoR_?hK30;b'nzm`ϲ -sK@a铄I%|א(#>a6?vjО%ۣ{ݴӏe2p쨺'yE\wxDYn>YC¦&j|60xPzΚLwܒXFg"qzkC5+N:4w:]A Jfrbr;螣.O9Ђ*D>s0ؠҤ r0"`s ޢyLCa/ԓio ]I4?X#q"I=Ñ2_waLW?զVCJuv,QI`<"`̤b 423Z{)0o@"-M'}k^EZKwk߈$sqys//@9©FWw+FG顔0PQ0vr ;q2޾U_C(?+Zx'y}@xȸ,^4*:! mu2g.t;ʪ>'=b{v&>##vԬ5cD}a<+P&@ks|9˩f.UTmehq=&:Z:1Ĝk]xD<2oR¨^5vy>d8Ȉ0>|[߲d 4;PF1!μ|u}jU}i=`L7bH[γ$GaGoIkT² (!ԔhWS s@ HҾȮ)WیT8&z1kVg/Tw"h 'Ux-ATe[I㛥o~Z .0*ݩ/EK$Ėi $UbrRf~:]M0{Gmsr])ʍb~l"87~\9/tȃM9rLZQmbd8mqPtX`rƀj_nAi7H1*'S۵3Ψpi~V4MQٯe<\\#8\R*W%uŇʰYjEj[#GT+5أeさYZ"WOࠩ-R.DW/RKw2@&E}{N]];ȒδMTj@KVM뇂5dnoMe_oHo`HbII-L:wy-9,Wu0 4vmF̭Wr7:SqsVh\+Y#*gmOVe v(uiZBX˲L)M FY`" #K jsE ΋%bj0^WR!͆NI 9EVr :" ;S-AO:Ќ7M$k"s p@m @4W$kS}Z;|+q,G_1I&-S3R}2;ND,I%cCO'Ib?ki8쮌UP897!}E?G;Û\QǠg4̟0#<4!^3j8,n[$c6ܫqntOYlip{mz ԐX y Z;Sqd =AKF]FA@=n8x#OH*O(0"yni`pIT1tB&YEkvW4;NY"+L,`aZ'(-($D?(; ! z#Kukه&KzLU. vL @'= mA*MQswvUkH&xCH!H)ޮW{0‡C7Op0YjC^M.S2,G P0";.M~.ErkAjO+U6_6Sp{,OE_/OəmC`YHZ14U)vbӔ" ؑ={*37v{K2&IAgoxe%kA[oi qE!P;?6(]\b=O]Cʶqa2hJ ~ {l DRS<Xu'gU,H\&AGTkhn_lLRC,Cy9L}`fCN* ++G*|\5vSśU^B ߌ(576? tD*X:D0$UrD#_gġ&MP}_g븫tj1`M{US-:!ڶ 2|cЕ`etVHG}nִAiiGTɋ(MG1T*7G5h}"Z st&~ ihKׁ$c7֠XD])(!;`]O8q {n ^hWa(,9cUK^m 1W#YX٪(r^tymO-Ycck:!(|Y Vp ..;*CSnZ $ֳO\Ba* K^@m^'(;cqE%a283;X٧5- x!:A,a/ X`LExeHYBw[f?E]DkϺWqK"|/<2tQ(Ͷja6),Kʗde' 7I_*z :w8NV<~Ti{=ȵCW5ݽ@/D`Xwa 4Mhs&Fn,vvzL~R.AF1\4'rcD=gST.%E o<} kn{J3EN5y:^}\$a5&Id x^ff09x_SR2όp;D/4KVKLNNr%ci@FVᔍW[ K'1 &8LXemQKIE%EFjl 5F+ O ,چM=jPZuQ?O!bIaT$eK2c*K9t_lǑͼ\Y T3XlQfnCSa, %A|0U-\y枍//fKkT{7\ r&Q | ]6gO%5Z2' HL[BvұJR`bxS 3DTP7`vuU`JxTw{mFiז lȹW,If01<:~WO"7ʳ2;uo]S{';  ?]uܮ>j C+(_]Fsd 0ωD aA :]YnBw%\؉18&EL>S$V'♃hEf3vc {<]l=yM-©G& `KKwJ:h,~Je #0Oc3=բJ&Q dx@NE(jD5WQ]SdžWHU@0Q`>y}iDtJf=`r'~1Jifc$dj"ڲR)ӄ^fKC0p(>NEAr=]J7_@'?W/hC퉹kfH3ל k;fa.0&iy3eS`yGV 3%+L~0b:0?s|#G q@m H>+{pJg'N+?[/x@7qBjXy׍iYz9 .T[ŋZ>8ɵcmKMvCi(U&a3#6Q/ة&Jgþr$ CZmKto@@ǘ7Af{ߦ+kRCz۟򀢗n ]$:K£ʍ18aD KB|0O6}$`Y*HSUq} >0cn+a֔@t͂XZ%7BL"L8XoK8PDۘnTɲMeCn=n ٱneQiY[ć.x|oo.p#6ǹ"KO>p1ԍU,X%R*5#^_bh*"zI[? BwHo ZgGs=*m-}` ^9Oó/(^oh+p4Qׂ17 ^rZ`5<}f!p4@9DO~LL%`)rtOvTo5Zf>œ ĚVyU k? 2g?pB*!ŒxŜ DXuxE={r3>P4=h{EcہQqW9 jϤӍM+rҸQMDPdB8:Wo [WUfX+p+hG,hcw9AF%僋Vʞ\ [rA5G[)@7S6 M)fweK[{=D.J=}Qd nsvMQ:y.{^N^o)y7i# ;ޗs45}bumg5Fi ȹr& Ԏo砎2Nތِ9OZh~\XG+`P|\d̡xW  .%5mHz@.?7r7 HG (%u^zvĶ^ؓ( # Ba,EL d>.2O,QS||g芪Bn]pǡ5%jnx0K㮛5H=SbKՠO)=-&/` 5VCD+s@0ZI ~*| ĻoA/jKn vqeӢ7gV)<#:1b^Sh `>i!áUB^(*Zڰ 9 k\[\wCaQӀ'AȽU{ዠ-ʾ"0Фa]eՃP? _3aomoe.DDU4jlj S}ТK0}x?:cXXb|UE;8ڽ2ά!^ޏn>n0#݌Ǖ`Spo*!x"%Y5Mq`SՍy#{xB#R VրQLV"2TQ))TxPU?}i~bb \q0IJ!bBn6K dXT㾥σKm/s#c4X鈄95rmLH=Ẑ4N y̷ɍ=sZ]KCzbaԨDX;ކ}-L *t\Qpx O2]I V{Zgi|D)h1*1 \k=,DQX!w.nP ,8?XM{;ĿMaݾ l\?QWa;pM*?)yi۹P)=ک׏n#XГ`Vx pɀ5((sճ'/zLටXKW8b[3]J49[p'>?Yr O:Z\[_'G\t{4%m[n r%ۺa™49}QR>#gtk⯦}(!eڇ]17Fׇ'G¼EѤ)D{ٚW'X^/#*GyIN|TJ)ײ&!5BBc(Q'HØtؙ? =q/WF~⪍em:Ps_/T:|Ş$4lyϾ O'ݩpT7 <7̨uCCPX~!וIo|u† T@2td3>i=Km uQCbaF|ƽ@xG^tU?>V$Ql-Jf\C(+KH؁7g_xeVb`s6ֳr4øpqz]+K0N=~`۟o+X/EWPN  oNG6FϦ\lH{Ջo5?!Bs Ttg<7"CC2:jɍCDBa=u ˤԘ^h?I~W =NVW6=!=X#߹Ox!2v`Q@q^2v.^l]aS3#Eet)t~fPx]fv|R߷~^#dꋙ,Oz0JKS7Ppa~Prg^!R-̙:\[,5J#IN @O$m> κ>اwJg3^hː~﮳͑N B蝇pԷ]AD:?F?]WhO0!ڰ A>XsTܛ:F()j:oh< w^H*698D\٤i xXr!辧 DZ>هSh[S|o ߄Pa5fPUH0T*"#hB"]oPnADX3g&z4+tuzCZglnBXφɾU=x5Pv$[\^NFqtI<ɡ9)RccSTȱ[dP{%ܐ&W4I+)ĶCȓ,āGZ ̷2~og/·_6EVX[-|߅]/}45%UOQCO΅:x]J^wk;>=ʍ7a(p bgjwg!g&k kgSpaAw}"5A${d>^25'* :kf8)fHUۤU) ?j$H ُ7ZTUmƂEv$%oY33t\ IiF)껨cJ|Da!7~Mܦh'<"*_\id5ԏRO \~V 730/ widx7OlٵU )ek DIpΘ|]j1M/IR3#]uB-ʚ>%km@˟2f7vz58& 9E}4}IPQIs'p"Z _ײKg/K_ݲjd9+}Wu?+48 ĄѢ2s6^kh_)n2t &wa bx r{u6 $#IQ]۾IsڒtXթS:# `R*{aX!k ;c? ZhKN-^0,9&PEw.<iOYe_mCɴS~qҝ~nvvM/tUZ$k%O vAU7[SSBx>&$;x0T^Jw6KYz953))"AOƒ,2y3]Ȁ8wVқ?.j}(yy"80 "w16xdZ|3 @7Ki1ssA53_:/Xa#H ?v"e]C!A/[ޅlE~gQ9kgE#u@w {u Z]vXI@ԇ@ux[d5ݫΖGWadEp,]qQ C^%ƨ˭%WXA8XP 6f)a ~t A-ah- H)؟4J%pv0u`݋:`C2(]K}{o\p9UGB9 Q@c@_m(e DRiةWbuTyQQaKSwah(X3sTJMd_c`i֑{9jVszYvq! G'/ dhM<TAᲬY5DwH#r_?$>;5LËkl=Wxy:]8~4Uh 2{X ͺ !~iCƙ秫5O~WJBG(9ʠS%/nv@XZ`$uo]Zs\R*3 6EʃcQ⒋e3'rZ7Dzo78U Uxm~{ ߏEv▐ҳ}*ٗsD0Up>xGMwskBl/ B$S+e.j݊N#;:غ? =ABIc7fgd"ܑ"ۇ{2pfS{elqNPŅk5|%#DK(â_Xɞ:OF|M#)dX_'?1/*ZbixNzGZ持ceݞZs# 4΍t; L&!V<,YV3"δ13Ɉ,L eե]=~~6qhFHTl$a_6sl|p^oV3mE`+8j=`7I?Oy@;;n搌annV D{A@Vo{XԟRUGu6Gr @B [jwq_3SB';g@pY]1&L̬3)03uLg(Qto{9i]ƃ%H¡!9C}= =!te΄/.)e7(sQVqσYe{?3Mkdx,3(~=($w&?s1,# D{WZ}yLc6C]tź-NWZ|v|S$`RRă=x]WՈ=Z vPGDSid4gbRKk$`TjDcj~p,V(xF}Cfc7Y7RiڳhzjR6颼 ,Nd2Ck.C{}^̗5o+HhLٜ_z1&ÔXO l O,aܧϭ1SmkY>䩩!׌4ꃞtvBL]ES_E>{o.7ކ52w &6yͳ^X ,۔E9GD-0=,QPf ONoIY0 ޱ 'r.87>@йYP+Wٵpq,`,*[QcbvIS& pzۭ')t%:] oSl}PwhL:JqFUYJf(&c N~`n檖-^#\Hᯅ?o`vp-"p9nH>}9UV6yM9xr8La7PW"3L K8DPkQC=^f30҂Ѫ٠dkIN}ߕڔk,}˯#dŝK.N']@=;^H-bQ1f<%=ԡvw.mZRI#zW55ɥqJgfH\PZN:JJF}I#L mnj石47GE)47C(5jDǠTp;/ńI5S~S?;a;C=xyZr ?jΆ\ OKGQ+gS6Dp-Qa]s{Ư_ʹ|A٧=x'XǛExq-\@{g|v@ǹ:)+,@&Z+tn$t3 7 Td9p3pwCĺk8k}8 |iXPsBOѵl`Vʍ忼o;uT;nh''-M,ڙ {enXl: XoZCS (~1 }I,_7Oe&y8[y(ȭGv?7qT&4~ DkPKi9=FxR6 iYl$}xD.NJEUx@[$qb_SJߏ? ueZGeu`jJʝs\8Q֙` :@6ꖾa+^F϶YF+"pvݫ}fƵ ˳zdهWTA}1 'ؗS겪9+htmU3,Zbעt@I_1p1cPQc&+_a״ :~V+9Y;iYNhQj Q1B;~sTbRUotC(1t*cT@9ęgRi#_(h0q{˷M6o&4 ^$ Q^tߘO5*X{C-DM P'4˓;=ሴ¿0x/GF/{02eO5:t޹l(w葼Y}luPJ-~+ MjjC¼fkp1x&p|ڕF4tA5 iKb2big J[fǠ{{7M\أ҉,6h8 MO݋9鷃=>e^P,9*9 PLl&-ع;qCU80I0# j_ c >*"{G gX2'+0͸/c6{[@sY?#e>HB+t*d u %˄4rP['^:"QPd&W6(I7qIso@`&~uPrMࡣ\*8Ƭm5|TU<56y}8ַu+\'( y9]y43y%>HݜZ WaT>P3-yǚlu!~,BA3iF~1$X;öVxBFЪ'^5VK)UK/6":^9pI_#TֺxڒSqMh$GѨn2.``pj6H` Tw[Ѳ%)3bӫѥ (FUa2-x=$7R/GYvEǀ=o%pɹD[Nr[S?uLi'Lnh(]0;uw* T8yF.<2`dp?!X@eN,\T;H@ 2MJ7'ԚtW,E%G<0s\>(}QecMMx4?SUI[T[h?KR4(jB@iɖԃ׺ٚ.X Q ?:36Iw¤jù85:, 崔&Q؞SI_ f1 W>e?cD\?x쥧KEZ e5 _%.,&Ar$|Z9)Ce8qmAÈ h &xumy_M> \38ݝ|9w qHl~ 6MnƷ"N k &x u5|zHUZ- :Fa76 l;€ft6UwubktFs!\Y`aItyH;|GR!iF9<_(d aNX d^`oMeUG5yjƥAqzb;H5gPG"(1(p y*L>k"HBCaY535-cxnZT/-&#pLa̮nNu2DVNx=v*T;X~7rԐZWr2}tp[竖k)ЉjCD7t3D-uVa;[+ Dd7o|ݞrRt7';@ƅn~jßp\K>ǚIԐ4ǥ*@tM04ި(bGs,ձ5L $1<=)\F *i8pA.;;en$酰XtmMr!b?S3I cC#7gvH?<l>w}"o ajފ$9ԩXyDyT%gB2IEU֏JOUi7Zi&} mHުuԿﳬGO@8֑*moJ! ;(Y[-֫N&ؓ&G4YUCR:zEX, ϳr=d$ac!&zJ c,od m1jd6bl&7; #ߜ@44]k:rↃRCcvx{b6M[̘s;n@u^3?Ca8׶uj =/WQ̔N Nx)(CeilWؕ?zidhWd0r?|ǃr0:}p/YG|b6G1Nl:!qqoy f)YV#R}\}oDmڴy~ GvvMBJj'A=e,m@}d bivݏ!6m$< |,1cɣIyx U^/*h8KQl_Ǩ Qo,>256xYD64=v.p,iMifgܺ2``e IJ몖αe/+ 'ɻMER^fx>3m&np.uYr͘2zgV*%AHU}zlRJ>kϟ:Zlx«YxpvAAcEّLVCuRU2cz#;d۰=НvEj4Y. ldUN|*H Tp$R :4@Oh>SlaVg4/$ u кb= Tq~Mf]1 G5'E1#Y La>[-tKzʐ@.yf &OJa"NI4%j1󳝽M9 mlpmaڽ%s_Ux]݀$ֵ\E-e+F'yaptA5w$?PwyO\IE6i|ɣM ^8hyL-0',1`m~lk`$5ydl諜} qь?by*}L%P q|5 JЗHuA1=_f}YINTvE7o(g3em.3/9,i\¨$M~sJ )wM{`H5FgUW5VXa4Fږ k=q7|O٢`[ a%}ڈCf'T3bCe&h^@Jz0K)UtlT'06}ĥ;dsfؓ=xsy3/p ,+EndG*7Ow ĞfT,X_^ Lפch_ۜ22JS ևZĵf>_yBo1虐j[͕!Ƽnݼs$^PS`*egxsPwi`{}1* fb{'7bF#/%Z>f" HzNBs*i9JvߠU5@TtBnMYK^:2W{a0$ٵ_)-yR'4*6 ŨLo[׺/`iQna7! _j(Z2;A! !ͼJ!jM%}g[h~ɔ<i|լh#!y4 =ZL*2zl7a 6j)qT=U/BvӚl1)_F )֕tiIkuOe }ֆBxʪxJLZe"@^=嶊w D,/H>5SO.e2MѶlzLumcݓd= TAmB(1+(D0"1A’\7u榕;=#t ~|~,`E8އN8aܑ8MulIvb[uc2K)Q]*h@=yX%T$iX 1kW٤ȥ.{&ԑ@gh |rϿ39`;P&Hb;iҕ~La|ye|8b@NT'hLCelYn;O9iSF 0RYe6 ld7+o zT9 |̚^$y+W7kXG-XT ;Ov铨"`0L D(n]w~\9&ʒ1\c'}~N^aj `mCk'aϒ llƈ>ݺ7L{`L k ʊH.rADйt)T:;sn 謓i#~Dпq'&-UՀK89RdUsֻ|b4ꡢ|cYUz)={j⦜Bw^ϣ bx'|l%/$n| H.lwJ nm(/ؗ[U?Y("n@h),[vHdš$3?!/jci>-C6FUe1!ыZQ)x,9hr-,WMKg5}t]>B&+rߗ3nP~L4[>4k&%DrPOp@PjNNPl H5xri2?^NbAV=c ';4XjD 1j;Zy0Іs p9ix`saЬ03w'$bm c?v ?di۰%&0ڤ&3IEpaH RswVwMxҾ乿O>-kKm J"Q+?=]Zvv4[$gmh`$ rzx)8݋zO7jbY'JGvP%%*߰fM&|zxhdK`dA6s$?V9ׯ߬ m^ϰ)N]f"I6/ivH_DWeلfUk4X6jC*zf@rU~@xtirSĄB֎SF} [dUR=4J0m`7i Õ)yAS\2Vֆ0͠hj*CX qYg ǤV-Mj%qcz}0!(1a3Y'mlMլ.`|ւ.#Muqi5˵˙j^uGk LWTփ6%v791:CK78USEeK/NwQ"\L4uρOxz nX;WKj毇‡Q j W| qOAv-^Ezb`*k] acKP?;З`H\?4GH`wX39b h&HoMlNZYr *$ĵĸ502k9-CXBr%~AS?$i4P^͒5C[Ҙ,ZNn\H"LW|ګU _Dӷ+v̓NE[h`#>z }0$}~"Xq|>br2daVk ]|P룪]߁L1-tǗ2x*4D@m.Q#s1>o;ho b7fDN񆋍˯\Ĩ p-Yն$D`@BS_p}-9G] ~Լ)YL d[lf8f"R\?Fl5RCr-"MޘIH⋍:N.53\CA4IÙ"2ei-8^=D#`Tx UJЕ U-1\&/ qS"T7K)!+zg=2@jcv jCQc Msf! `_Z^D2J~I?ED7^v8g}%TT%\,r/ibT1hТcPLvfy܋ک^m)K tX^i/&O)uV,@W9hcdN _ʕ+Mel'-@SKq0PQA@Aj;PxQd!jKeL<;Ҧv##HC椢z9ǦL)AhāQ ݊< nߨMGS}B;M1r_1]gBP?ˇЛ?dA֮P \"9XLSEաG2YٵyZ;ӶVH@^QޛBD#H?AJnI5_C9EkGSqt } xi8Y]..ːRص2@;og8ٜw_`[">3M/fa[YkY5C 9 h4ޤfd!5.#Bm BcG Wh KG-ӜZEN q\;2x֒t< }4]ygŧ ~J"L,(1^}ҽH+zbXDlN>4hT)΂`JZq 1  $(+k"Y!ڞ7"z^R֖V&vn#Q۰S{jG&92,Y-ܠa]Ы0b9=M ?A0'3KqHA" 4oVSyH?,,j՘{i g9'(WMk9mwcJ0PӐKp!#. Vl]*||H/IR,Ps%js;OlJ5m`f VD' g_8ښh/K4-AH)Zsf>QH(0B /nYbه@y'[â# '쭀Fb'cb~I|'c6?$Lig5?@` E;vt3 ?7*VB-QO+2pb9G=ܸT,M0W $%~7NN |\LrG-L%N {?{`详I37R]7G ͆KP.gO\vvq+z :bP3ȽD{%-d ~5t`JpOupɟp)W?`@ tRDRBtN\!H9_C{P×yN?Z̈ڡܶD+?my΢RR:./dp&b$mXMb+JDfLO=x`_] $+ݨ]SKF\H%{Oä RH4wF'%Q5k3t!q@E(I Fe]eIԱ')6ƹOWSOq1]jLMW^J2>Ͽ!µEA~Bx>yq V9gr4fjiS" !$ˋ'*nr*I?lj}LU?(|<r7σTy9Wup־f5K17nhsE-HUŘVuر)T֋ }ZF4y T ܻ$4 UlCJz+<՟Pgq]5J,C%7MJ e`ϦOaG:rXmCE|9;/э( [Hm2z \fz M޴d{?[1y> z@! lq]XOZP}zGtb}~1ܦxUzѣg5能 CQN.p& ("}:*GV|hC~̻ZΜI( +7 3YAy蹇E,Dn}6b^nJ?Aw{};= $v@A5gW۰9bN2Beg![iV}C'^Cv7,$)q=T oS'"i-<脥JKN%ăI`TH {XGʅ~`n3`v~%c_[L~K4Tx vY,z^V۵huc=P4_:@eCz]q^MFxi/Nuԕrf:oy^F`M٦j7 ώbE)dD1sX oK1:PbohO ly/v|žE# 6R+st(mHOV v^u@6'3N!.:D.iUyQ"߀WsÁt^'ζh|{[hfdwQP <qLa\K)ގm:N >uA򄌳-]fҞꮈJAk73tWfX>n\D +̤tHNXټ|D"@[ gZuw }]U:sTf>ΡD4 LC8dx #stcۢ<%nGVaS ܻ񍷴GLC 2Jp{L" ~ 5NY$1+ୗ=XxvH6縬QǢ#^ SsHk ݕ3,ծ1V 36Ȃ:LM;gm4&}WJ2RQIgvcW<. ;'€( sp}! #=F"l!  ҈h=svoK՟{ڭlQs^iu<5!*#.MLJ33}"9!"0osCNPܲQ c ~6 PiFLf"*N(5q.$94!)Ύ&&Y4:^L(6v$#ųX9 Ur٭RU) QdiMaٕvQxmՁ*kҩuRz7`ӎ 2u6*\75ݍ;͞67KqI#XQ 6B~tƕt0AUNÒeޞƽ夛ea~h_1ŋG,ߤ]7> [\ed7fx=7xg3O?fr-K^2r/%v+vB2%E-H%_OyMВBG:C.k5XWЅȒ)..yKRwgRwҌ DYPݻR_WO}>%ޑn]%#}#܍.DH߰56 O^[ gRSJ=mU@5f3\4UmBYn= V4]U-j!fSǚ/p>;Ttascm{72R}H)9ǙA%#=mY-N4TXԻ$@g3& AYtbߤ Vϟ[bMfmSCp|V ̝j&nwf't!*2Dxb]| w3 ת3v db/~WM_Lk@aj$,f5XfN *m)OHՆP1;߉lv} 1Qo >&A3Ju^[R4Q3ɵ^VQvv:gHOS aQU$OM 6_=e>@#̥2F1sb&{ѿ$xU,T8~~ԑ"[6ns~Hts+Gecy1 r❆;$.bHVo(` c|I[xgAy|ēsLԚg#LV@ Rt`q#6rL|KFzX0 L$b!Xkw1%/۪E'iinpۛRRH Z9ĢfPؐv nT_Q~]}lAr'!BD>BiH,krp!cTX8lzhlWT!@-5K`1$}( s&HἡAbbed9X5hWg&,UĜlG Lz%\n;hJBT}UPȨ.|KV6[#r*2D"()/;ܰ;!H ޤخN 淜a$;8z/sBit8?fz>ǚ&ܤeqdG.4 ZPcw0̒VJckނֿ :f;Sv%#q$B,fߖ j&)*,% _ǭ^DYdІ X~ptR.d?%b=37sO*d̠sux~3_yO:eǤA0ȟY T.=,G*\osbA Ә3 ~Ig&"l5X׈^e]㑋cät{s^ 3GNL O{)ckxnaY /phj졧 rmLBPcYaDF F$BRڰinc2Xz8 8IsіN;y\s9X^0Bal&=X,YNI"gZ,lbUww&0Qwr(,êɧMy6q^NxULC]&Sʼȹn=I"2gCP_P4 dž;,[mI9Rj%&$F; -8nv"uуqx8) oqx+ZZS7\"{sg^_qB8mes`ZQ[|dudPFfɕ^I).i tf !ꌸ@UtYsp6a 5V7i=SɷE]4'P^Pq%#K.|xnk$41>QPns`ч{@?hgw9~X<@wةAgLacx<}M,xO,3E:bTK.Q(XBhǎk6O/J|ݲ^<=Uvkˎd7gka:O }r@X/`uK9Q ZϘD/m! 9^ن?U@,SZȒ$&7;UAP|F|JlPq&g ʑ$IϠrCťϽ{sH1^󂄡;f̳ʕ(*Y3zY*GJJ7Yf8JTqK?~@\.AAe+ҿ /b[NjIHF2MJS# }E<{PBFQK_g !Uw?l6:P*;{D/F*m5K ;Cӎh fx5{&ԷtthL<>,-v,4 "+4! Ӱh5 woΖxH^rݔ4ww%u{_҈Fܑ:N6`6D>TK H:=Q[*J(nXLᅩ~lPRT1}7HMH/?= U ݟޥ6b {O*`;ITF StY..i2^~㢴߁>1{~Wk'Ѡ[\8CA At&Mf'p.A֑OŸK}8N' a31ɜ}!O]zNmY qIW=k9=)3wer}m'7T`Lp7+3`ͳ3wEZ|;~6hI,E)1LG%6UtT,vHMŖ\8ii`8Kd?g@ƃAA5N`@Awՙ!YTEOzD•\7g 7ـ\SY_& x5*m$]|._W[k/]ɧPP#46|y1sPۻ9BA:U̗ʴrC͵) + 383ռ!5Ř$-{WԦ[n6 DF3 0LD}+%9X H7с\qMQ7ۖ* ]:yxfi#b{zɯHFٍlSXkBM/S;Bu$,㟟?4E١W3Ob9f,4H y44y0 GP@"hPbe J౵~$kjSFfnx|%iF(I ЎB'v삲{:jhT_,"N_eQ[H$Ow:Q|H.KV@fխ:-Yf(h0Ѿge܅КvM4˷w`Rk_>\z9XD2nq" G[B!~ollO؈e> aYG&Lrp:{pAAx" ;XRLok4pv5(KZc֟x3i3ltVyuںD+-'1JQ$^e&>x:>Efo="$ʌy'5޼uH'1Pw'Ƽ/ [vѹPoK#1߷]Sk?CRHP(Bed|&n~l-u Rm}uQ Vy4=ʰE`h" rH +`†W2~UÝe0]GP)blJ -k~wf0`CFp޵̴݆+pꏾi;<@M{g(J>gS%ahފZ FnN+e0MTGz<, `sز;) Z@]`sL< Үtnپ5>/ b <`< UгC_ /ٶE5ߪOǞrM>cpViP7=@h#Um`΃nyɎ7'3ևcs@>&I_%뛸aMIʩ{r]*@%LnZ^FӿhTWKj%ZWl((oȓqNuv2y1D l=1U:J-_t`wgiu9'`\>z]-;l1;AReLɇ hӞe*.7O!2S f9ɣ6L, U Fh#/f8tŜáWfV 6TSWѹq \{bp0hwsl)}μe+_ $np\T Fԫ[l7ud ޵TxH:OdvC)Hx߿ F{63HJ> z6G7AgXG4ՅdZ995gנXAC>?k&̳$029 S㷆G|Cץ$et?""E̠=:^w#2#)j _ݴ-s^(:OD&pbܗ޶` ʵع\+ѹ%|Gg N%ljw&G~=A@$w~p%(xv2\}잚wchXQHի@%te!r-V)4]qah|rn&XOI7VQiܹđƁ7kly:7{v~e"?|]1~ pF)ȫ5jAŨd/2Ȇ֝VuȬVH*|> ɏ&XDTR"l|GpM҄v_O٠װzLk}A^ Ŭ{twQOt,(q珠kU惝ټڦ$&LUv5֔Z=H "Q:Dd&ÂNY6I ۥi3P`T=P;t]ze}-Fٮ\H=վ{p($rpc nb7rv֕Y| `Ȫaq^[MfL/'/m2a_:/ը|\vaj3H3_N6Vjt;6 ]#_Hl^Rf{m_óUa;\קЛ׫W^1֣![eaz9o9T9 l|m͢O6UHAD٫m3oiwtpwٍ-V=ߏQ޸BZº),:ԂY L:vHjz\`A-!$49 xǯ2VrhƏ{@h,VЊ "L]bNby隉GK[S2.N៲S(^*&& Y biŔ F) l$ln+{ͽɒ`sx DXdc~Q5/i۴߱}Ğ(`dk /YQ^lnTS>C6~<#gO|9gIz__T^1[b6.µ_5&o 5R"[*GQ"T^nry 1+Bd JCVr]pGxlBQ0t&bKы6X% =.I4yݯ-xϣR4HRK0)g=խ3uq+B 9 %@n=O`P hHt AbNn p$dYtxPY˲`J˹X)<:tmڽbKׅ3f|N(?tux kƠzP5iYHb 3w̬b}ĒSL_h6n& Б}D:4ckq'٪Vh"]#p n~p}#*O{g'?q$PĶFqڵώhv]y&)-C8?3Dy;H9>+54Fn0y!79rob<.cq }ϕ';NF% T|OQ`NXSFCh-+3<1¾dU,c=B}$j*xp.Gp1Ocyg1KNU oUJ@zn_ÞۋYȚkGÇ3*N\jkJXڟhL? %ёgyg De蠕!ЇQJGͳ{yVzN*nWyv4ףs7VGRbP|>N`Jo'Хiq1!J,-:(X_< F n1ZBcm W46{t\3/>W\2;hP] v/= w;Xs %6@W$I\G>gnm4 Y];JܺoeFk0tϰ(CN uC|f "'[+B!rrb&9TFac 2[SAf?T)͕b8 [{94)4[IM [xQON1ݗ,㌬Gpa(3sw1R׈anTOELSfH 򲸳j#vlřyg)cZߌHDR:>k$9ђ̷d'{M0kbaU#"0Jj5@8y{z ΛԻOr&qoBpC7+Af<;' Tigz bKGg,aٰ9ϛ;V0% pǢ#fgԅߑuS4ëȀW\"[ `Y{Rh(rt}`rцtqIXO q[v9ڟPn%uOK@@ɉN ? J/ ܆>|(c*ƥQNlK څ v¡RIԹ:pPB8Tq+%ŭZ2^^C7XnTd =_oJzqRv E C'Ryr`7/eug7l$ y[m K|Ƹ1zZ?xrbtu$:q[<$XbTVb M{"F*5H^2q]0iG0qZàoy|DֿG;2 _*2Kf'Uqi;@nD߳RyYG-H\Bd˨ІAZ* Zp+,1"7JesŠkлh粞nM+.TJ vʫR$$^J46 [fqaq`|e|ߨd[& IK`Dcդڈ/2sƊꗵ1ϐmg1iWhqL^FK9E|d&dh9(Ji$ejM|L6Qx+DzdbÐciHK!b ׸]eUf>-]Cx$%#̏0!^4̽[p} Wɾ%jz \%${84o̞FF[7(ҦvT}C L4d R<{<#+ݴќZ+OoEG1C턺Ŧ,1)Tn^ĐEೢ/+$?i:SVY~$fJAg6L878gU(Zi-gȉ{ꌯ+/F\'AmZ/S0&)n|fg{-7!.$vUDS`X|dI0Xٻ&2l[e읇oCn# a;L:!CԢ4&򑝗E_D5 lNdsMj":_d@is;-{LޙKco 1k#ǻ|z'`,U>i]D^yV`ssrŔ嘂WRNB](0{0f{;ܜ2M>&m`ͦ=ס Dx\\ XéS0DG] bj_*K沵G~>B\MMxYU$f'Y1̒3L;Hu>0P5"zAGf@7wK1YќT4"^#Go~ciwSb 0_ߒn 鲱=;& +r4\>]NZQuOpM ,Jl QɈ͡belNC;Ei,`k|dS |䞒-qm%{[1@Cw>ZyԤ|(gIjF@"F*vy$P0q{@R͋ |wwfc1, 3 w@iNaIb,3;Yo/qg78Kn<:aYD2Go|M|?b)F sǂr;J끗L%UK/G `͙E׺A6|>8ԣ1T ":WtNQ,l7Xy}}oN#D,D3`7N[ZoZ֒%QI{&|QئJP6ܼ\4WC?y r/`F`i [/j方OQ̖3ZoM1^6=s\-l$Z(6j/7+̪%dp,%`%JFrkhl^pj^`~JPC=hhM^-p47QGQ 9UG_Ƌ۝:LU"mE»h1rXܰB ~_dK Kcw I4>m0(`%؋Q)=Txhf^GFX}#󲅝v9*<<"f@#M,NΊ wvz%j%fbqҳ΄EM\Rt7e,9يV]F^x0LU3<$>NL~t10 *$&}:"5M g_o*vO+lUiy.Za[u=SI ="IM ׇ ~Vd>'r3p9^_VA{(6z `Go sMvo<\5&v B4szN^#䭤&>3_>OgnIÆ{Qg>q+(ɽ'U 3Qv;>grˁ-7h^b/p0UuB$wwx*2|}LwvL/ ~EЈyEI8َWexkY^: 7grt;gW޹f'nZgȦKÞ&){WŘ)JKMl|j~t¯HxR`,Y! vsw ͷuLPlBL-%_O) jΪUSv埀I2=\گUqa 7`_kta`Ս%4p TY 9ZDϲĠq[! ~ 2=S98b݇-kLzsS/ 9(%n3 7CX5$x6cU o[d 5 }뎊A*A=罘'QEGJP/P;4C\#h=;DuaH[40۝ٕVmZj#nZ,ӊ&L(g|܇ CרWVjDkϛYbNXI)~"cҨ1#\ícs;5Km5}>ֈI:Y`'P4L!\_F~H%!_ "p lD x$T'R>.ĭjW˻FKߝ~;C(2y-m+.A-\g_~Nrzȴ!]{2&{y$z#4z^TidhrŒ7C/ƬA N]FVrOxsCF'%l;,@1RNa h=zI^M\ N!.j 0MmƏnIzrS1c,1Q{`{Y?v֢)NO=bIhjt`l|Ǵ8sʁ/y9Z~%4{Vٸ}&@+_s=hvWkB %S{ƺM >S0Kϛ4{h {myB'AJEwi3qQfEELLQY)s(iUqn^HF.VK̊[."P T@^c ?Ox`OrolSA}a3f㲬 dqp&])6OjM%šir-e2$L,yɷ|iu7Ќy\s1&BcaFi,f[ojQm xޙ6SDrc=E| U46lrkK&̜|ců+]rDzoLt]c+ po7r p$$J/$/ؓ^ Eabyޯn&ܾnyVVFD~Ԝo^l?E_|0DŽ荼R{}6mLِ6hR=1oᶄ" i09;[olA$䪤q()1N@k=W'K6\g(ӱCm$"AU}3 ⴹ w %Hjc@P+@O~%ؠw_,0t#F>P͂a3$?tJ܋@G\$bbTp!C퇤>k)Po ٕ M>z;4V.4YfTWh2ccD1;O'oGLA9Cnr6%x2 Cg6Py9Vw%m:'#M lLʧ'0RG^Ԣ]E"{.MZ$Ti4:gAwr)44hU[gFP- eA.&ZiLԮSfLdRZaS/}/ޝ@ 61b/E݃8)ĝ:T_ж&Yc))><ZI~薵jWJ%%>^m+_e>ZFN3恷+E\=8ڲJ3BɶP ^MMnWIU˗]o(VL!A{whcDشjٝ^qv]-x6+#^AD+7 AWM|ub% n` #}KF1U$_hs_3]߄ }υ??c 6 E}c F7o1-wc/,m'~H`Bl n(&]74xXrldk8[=) *xPWy3anSěʟS:w>7Q[0L~'[V8CīC |m$yg]j%"Fj$7c[~D-)jUlXHHm N"%轓jX@z:$#o&prA]ӨpW#0ϰ̋#K!*Z~J^M uоQ(|dՔtDLK;D9F3Eg؇2Zrw֢,mБjBA^#vMĵG"M"ۥkOcYHߚ)+u ]wP,&HN.†`)/Yk,5J\U"S~d {XDCR x6)qhC#.[%F&_r X v^Ö!߽X{F*pqvˎ)\ Nk**1# ES ?׳vOjjta#\4]it$`LfR i R`PqHႥ|#Ϩ/P@9"Gmt! $Is5z9NȢ$շ@BUE:9iѯTu俹+ILgBzo1H8;4$ݨ8C JƴHC,6.N 82 M%yf 3a.QrBH (8pSbM5 g"&0ڬxLO LLv2G;y(r ^}W?osC#տkp&`h0%ȇ3F3N)?h\c7$==YLn]%Xs j7Z_AX@9jiɳ ($1+Yh;Ũ.=ڟ.Y ϸd 3"r}uy*ԃ*L]w†./8n1:/1_[ʣD"YO׼(.a!s-r/Q"ѻltuH˯<51􌡖$"ucG =MV}N3"ol/H?S]QqcF(=~ϒDˈlXI+\^nmBu /&ЕwK (>u`It{3&-9HsIq7ϙD`+AX@(M8@J 5f*_U.,?xW)f~5.$)?$,Ƃ_X?s,EebIZ71"mԯTt-he]2/iLL>#s-E[b$Sv:-ĸ`]1-nZ]Wذ{-T ESY-s>e:=F(J5>*;@NQdW] mOko)3lb`,4&IdPfql/\MEPN9; Т*Ռ9 nqLLЁ. H)ma8+W"n}"t*_WxDX R|.; ƌp]~( xY%h,>JtFNߩH)YVnt]bÂy)gW3Uxl1S耞u,FA}sm!'tsBVBq*w>z*i;G9Ef׀^U>{|q~QUۚ5^AP3HfR)2A9YtCT7uԋaŚ\x_Ԏ~\[wtf^"bWZA2ʹsK~TdO h< 0=ӝM eh42 ޟ"U'_Dy9 CMRM@y$:Jh(HXiz=z8f 0MgkSD3 'e㨳c*4퉒w Zc>oM3$g*@1:-+'꧿.̜-9PTH ~"p}+ᜬhC%9DSNk)4Kjh)=5K`}g08b 7¿ n6aڃ zLFpJ &4>7^FHouʴ;ctW~SWX+̘o2k cvld^3~! ލ{am3[ǏaOO:Vwj]2Ry l4"k.e+`I^lS쒪;Ap=i0lylZ#WbG*2nz zSNijh%AT%Dreg40݊6@PL'>7XoAN v5.ɉ;\5e3$*ȨXWucW0s_JpF `,5S54^oAG?삲E|Z i߬drx>pCp,;l|YQ5o d1fJí| Q#M{.dq)&$slP w|xlmK\zڧrvG:>ʒ=LZ/LY9<qB~>VMa]tT*?lKеa+Fy}jcdYFU VۯD<6@(oAnƿ#>[{{ΎҟKT?;,yԣ/Y'V]QqEGB9v1F Bҽ*bF YVsL]NGY$vfw,űGމ;0ٖsa-KכӷTy`Mrun Ps|ڃq6f#T:ӹ[woqZηlа+~: 俿y^j8,d_j9`ؿx6%wT -;cCbce'/x@ͣ+W_1߲T-^o~3r-H (6+2PكkSgkdCG YT, Iծ]B@l<iCm5Le)Rn@[Bܯ=hF•p|:4'u2 ?JxDItv<@$ƒ^ 7]?@^D>Vؠ}$˖0QW3!+kBܲ=n#)t:}a8 w0{v%c]N|ǯE{{C`p q\3)Ɏ0Zl}X%\3Æz5UF }x?o9e;' wjEs {~Hp[4'Q)Q$Hhdzx֮I/q2$̡ٶ5l >cwJpR겟nB6ROE3OB$](mNWbjsnN7"Vާ ] ~2WCӉuaF%jPo R#F+f48f9VZTQ&sZ: VyLq]'7Sge|^SY}rO݅^:M!{YO˲ppZÑ|lp<0rCO&:Hχwԃщ$2;;FP7=fuă;bkE\7E:|8z|7(0ﱼdQg4 ily?auiK3guEdQSnK)|PUi\ewƠg(\n(vKėqt`5hXUiB܁>UAo?W?w(ܮCo!&^Fo5`y(lR7e:g̓ /.K3_Up~O +bE̸ܹ 'tf΢/Hߪռ_[ 8AKe@.{j'pU){߉Oȇ4鐲dq1yE,N~MCP,^RC ýcSW|$q7)Zj#Ahzèh}+J ZҫCm^md'6?Ytۄo߼i#U|F '*/5%hvq!Y^KKMT5ˎūUȬ{)_穰Q~ :()^ZPЋ9~A !9ΘE^F}6柳lC*"8dD:@TKvZdʿH4W]cO`gbtڮd2h}zŦZp+قhb!7&pSY}BJ|h,jik-} #u2=C2׺ԉ߻XȦ"c3sC~t|:rphv}D#kBrǐL/)gN+& a[R" &!!B(Yc>z4ٿy<r3Rwܔ<&؃D6{9M114хN2AfWguYoWN؍dXE <;VAl`fk13Y\Kvv]kUzrh<>voᶁ>]xބkL?z?!b1#{WFJhѾ"CKUN2i!ZLz 3x[ n3( LhshFgw!墱6P`p̽rn6[ٵ֯S^G1F;Sĝ~5𝢶-wm{}'{TC,8VzSf(0}!:JFeSn z_igаD(ޔ7[iAV6[m~"5+THmrLt$4fψI4ee)zͧMr4 EzfO@m%DCo[?V8l31ҹt Cv>sՄYۇg?+q9n\E2D 4#UkZfzjR or6AYpKȍz^{A4/ 6k->2n2ڣ4(zʓXE+Mh~f wUh^'fdۗQ>Q rk16(UN Vv0H9ic_Uqcb?ܡT+C yvA\KYui1am9j弜u,` <35nh kIqߞix3 ˭6F8*\(ߜxPs|@mR8TM 1BiSg ZThf#%+Z?x9XJ scߡF`f^b¾37ĴLMo)@UOã o qfzBN ;&]duDd NAllC. 7b-)=O!wR "!b YR/W'=|"q;(~]C"ϥ!nIFu3yA7bOMɳ _/`Uꨡ_@9]3}iĺH ^xx1gFTMv-Qf]xgxX2Kkwzrs#8x| r'+.$5 χdbBq(s՝b;_:?*e>9 0ƴ=tEN oĜ9) #vv뻄_ U _`6j_[XJyX^p [")j<S9H4Ix46%X\k0fo#l렉ō*Pz@A5)x9CIK~OfvDaL;/%8,F\S "/k9AT#=e;pt QC9+iay.id6Ox;UIJ V%buxOXd/p_}soQV|b,D:FR/^5蹉ѽZ~rnw@'^z ARRN& HZp3!.&e5%X.7گDohu5Tg0ixkVhT:/yTS&01=UӮra!g|\| dWƛ#V}C.}3ƅP ?~yK&u3?%B%UCݩ/(=N~  b_9vR]ͪrm)GL l1yc:2L~Щ|8J[o:2ˉ$\~vElrX$I4Đ6yi`޳g?L #1d5=㟵\1N8B}¼tW 4o` d ܈P\G-M^J|mjם.7e~z!|Z9G#U4oh]~b?,ůͪ Ko[p{iU(V g8tD7ʐũ|?j3qyT!杇%c` O-IAeW,XKs#CEÞShd%o?!yylY W^ sۧi?5A4Gm  ˫Lm|ױP#u2JdUZ[:qrf^@G{$P[m(gi^t)!w, l7rf¨nB0ꭤy%aTk%!:'IM|9$h]~ɽj [5@*L+1#U|֣V#z֔ )6"|X廳k̄'tڗx)Ӧ nRY"9F$J7\Z8\TϫtdQ[:c$CTuYzj"Il~~t 3EGY459:nęOZaVk>y,V <{X]O*׾=MޫGgb4$>ӴbEǕܯʯ(Lƌ[ݷνO BAvv5.Hd.h߭\Y4>ѻh(/;1qrgʱnMv_UҥTl1եsUcY CL_i;Eɐ>;+grHQ!Nщ 4|るL R&><mgo16̠ :2`Oϴ+"!fLGMKiC_$h6|>,iD ̬9edJm tK% {)D(p$|6Od8+NA,׾E~.[Dń303..EBҋp~!JUv(﯇a:Cg!V-Ѷ"v\X68;Qp3M(ʋlA[bU2, B>{ Joz\4g CےH<Q0zg;Jb ܉w>&"cGV OBUStk6`elMݱIJ/5$|m4c^cT򤢽),.+hS#-2 ׺lQOfN8r_?*o lH#֤(Dʔ*-EG+I$NƄ'0J7^~ sڋ]}d C JEτNxPN"_!tZMOV z)$jɭ엕MقCm)(̔=Pof"0rQ.s;U\NCbX UԌZ5$ ' g2mW4G,b#yR,ژ (Q)g?ɧ,MgsT%. dk+hNjd|jSt'c9A'TeY,/r֏\t$!YpB߲h=c$BX ⁕,9T3rX |tAґXG9b|LpgRЪ$\>7R7BD blVL}&hf"v욏,(,fvZ N&HHW}.+ SMon "_e$.K?.HS4Fkr!R#Ќ(8py+oF#:!S'M89GmR1)k[l@ʻC۽ۼ(WGdV!Ц.r!pKcƓBdCJblҿe$c3πPyi`󝛌 }grOP5OFS37hJT (7\䁘5)Ĭо#Od;< wiXK`[mϪ4:MLk@D  椡/(|5M7,N5'N~:b#X /W|FUX>|d sv"#\ ۨR%8^0hlZKzNi,>b+tncZCGij-Ue9gQԀ{_qù|+mϗ[+ o~/#Z-<u"1Zz1[;S7+9fӏ>:لs 6ꁼ(2v99dO3`ݷ4. ;ڣduO=\b͋s]_et,S;Cf z?ާډ u$;2nMLŇuDp~Eoܦ3ԁp@o {ܗ=G_i+4A?%J:.|S520ױFRF Yc̋R|\JWeѕϠ{6ū(^ GK~{2ލv6QvHg&\^5tȴP[9qpa2#M:zQťY)D!zhPS8I_2E^&WXK#ɠ7P:pܬ_VlDxuF+7$7IVܫ_ ]F]Ïa.q7hGC翜=8eK`e1NkW^oWFD`) =7 ws'߮F"Dz6[WGZ H=f\Hr㼻 ~@][/.4ٝFH*m-VrwD^$yE4j wZWl!)ιjѬ[g >^4rj=H=MܺTs+z鴬{&!&%sNMeϧJ#4 m+s5lj+0 v.Z]#-odlߠa%q$&VHL7|FC7Hw*hL {&U+\.3\ 1UgId{1#0OPDFX- @-/-\tT)hFC̡A}+BaಣU'1 c@)Yy@)*^KA>s kZ*cW|msSg}pǺw(`:\߳_5Jl q36Z9Ճ*k1;I]LԠ.E'B@e ӅqO6ڋjxrs-Lr,`F쭬E\lR@)\-U'ةy_^L;m5n *ź־05Z'5%sɥ(޷5J=pXǾڴ* e|ewjj"j0qu+4'giD: \ZVpO+!,4+ILVr@+HPC]V@7 !ېƂt00fj MkD!+CVR~ A er "yhqigjyrr|lD3 s^mVYDFڑM\vѠޤ{ݩ[WZ ODhdE95Y~>lq] h Fs\vuWs_F*1 m o_LG4\ԃh[;wj )895h^u+ut+N3tTcv5!r[bnrݲveW a>"8QorVr" xaGpis͖r瘉%~8O͝ /P; ܴPŒmRh:v ڙاi\dĩ>@H.Y/erγ=SۊI"Яj}gq2wT=X1EcRv1ɫ I|,|0afוS'cY:Q{f*vt;[Ikq˖g+oſSjsj]E@bq&rądj\y8'*w]5q*sD4pR!+B#~PeYNsdFLv|cUߖݯ (RBupɇ:#@l(<|V])4($.kn{/LM$X0$E|ྛ( eVgΓ>G6xES H(@x:ts45?Bx;pM"vPUq^m?8-^#miL([/&6#H[%޾3bCQk:kMH n45a3&Q|\K8߷Oϔ'}y pglW/|`Fx*B=x?^vĚ"hT6C/us/ =vC -M%MJBûٜ/@UAF)=-AvZV.1[C>U1kBXG{pbc$wvT}rDf|ϡSDc%l%п]aV*8k"Ae(P  b(^'ʱnd6PK :|fD4vNvpCИt|yOjg|[ >vY,ߘip{ǯOV-C)Fxw܅g(GlF)B@8/#}[J+ M![}K@Lsuwf.]5\ u(5G_Emu!fR;k}99H F$Z ޼ؼk//OTYEEu>͐*@G=>_7FHzL!⢤nҊȨ1NbB9r@3\nd?u,먌*{6z:@rzΜ9R Y[B ׷N3?®fLH1jb>Xf;[ .4Sj|@[g8?k i\ 3Հ(#p`tKz%~)$*\3RO(ysXO>N\u-J^u>A4EbÂ*Ik}&KQ̼ӥr5E^k Us *м58e6.,~ b}D#2גɳ5KTR:?_Zuwta>j|*:&Rڸ~\9RI4vvњk?wQ!$S.'BO Sjt4Fgxc u˜xĝ5 r(VN]g #SYZc+G|8M{- smxL2U}O|_ęܔ]VL x ! #E(>ɗ*gһ-wA]XS;Q|i JɡL޺Ձ3˫ !SVzhDulpEN9%An=_i5ŭ a&JĝJ9g8 rMː|,,e,t&dY0W A*Rh0{5[1?tQ ET- ;7'1 -e"ÐwjhߔT kk&dSRS5AyAMNe۳b xW>¬A)#i%z Me3"FbvRs1fʆ*|Jx# sg|Rp2ota@Ȋ=<ǙרQH~jZڜg9/O5hQ-y"lo1)*ЮNבH+LljDD&|He$Zn2`&F;ߘ4;%|'e$t}6E$dܵcץ0Elx nkIs3\M&jQM.@SXm>a hևxOHAyƧzIM(Z;t3D³?,.Zq(δr}ʁ^5!(ٯv+vB7jէO?kIIv"8u9meaPfnmUGÒ-|aخ2 %yR$+ʒ'\90)"ZGRI^R^f64q}'ǂR(kh[|?yM}=uDAojaչqŷ.!,s@ԥWI0m8;#ȳQUx0==0ɋrjzTMLAdd{UM5a}p'4͂(AI`)b##2?ɔ@"[PoMqR/c=P 2\s׮$8"F/*1ӳޚCPa>/*F#fnDҖ:h# Q` 7l \V=+ϻJ]K7+&洯59=ORibfVO!=|g(ƥ?ƔH397+oGdI`IdBsbW@nGxh0 RF'y$`A!wGEJhE$YJJt5oXXL!^LJW? Ck3\r߇ aW-SP°ã&׉Gd6((,L1;T 'x|pNm(]s&!:?O[ aJ6xY{Yp#B@ )PzLQadEAiC4cu-e)mJC18f86\^6]Lt-&cm3Eһ{#1ewBg Ge`*Ds7CylnɎI< k.@%e_Yl+iKXmܧw7na& с"@{{@O5z<**7^['wgxo>oF4ɸ ,}qDFNFw/FS;#iȿjgPs,Mc\>ǩ pkuL}IA{TZ;q1tS_TK.٦1I>?f1N/\3{$}* }U-wasu{f밃c*楓.mf9coCڶlvR9j{1{+NO_Cڽ=2 `ϊOy%ɂao ,a6"A&?wi8BϷ5d!Jd_O "|,`2TS,Tӏqd~ۃAVS ղC,ϧ&ŐTZ'!XqRcd>䃭;Χ[۩zbfuAhE*+{ wgC@ɂ'KFu?SH~(b1ec!ZKO? 28 ivjI2ֱ=vd; #.(4cw Ub@.ly@u/KoW%$D ΅a4_l1_ \16-R4ϵ b+7@4:/rOZOөG uS3>>4M5'8e Wp@qV6&S3pǶoT<0d,_ Mc%9QYT )¹7jYln(I1];5͒v)d [;믇`;93~΁{g~I#6b{,q=4F¼:"í*'lTމf iR; o: &:.UB gs(|X/D&[}IE`i7; R}d HNIw:e'qhJؙ[A"#݇4Oi#/c=ll}jK 6%\4s &:α٠4,X7X% .+nאT#͓${IܲK 0h(B0s#q x606T'BE9zt8d,;Dײ5OVvn1 !uX,ͫ ^Rjb{K2I \VPqq4W.^*]lxJDpM6}oZ9|XQa7_NdM}G7Zo>@NMiL8q$>47*<{q_dNScjʵOtYM]*ZKtBm3`y1MI.!)mE1i{_N9̾I3wEL%qS5I ڊGv{kg/V1ee鲅hzvDBEF@Lz!h k~p{ʙՔ> |^Y4Wb&OH)676:3g 5҈X4)N ƀy0  ?VS0W30z@p F1P\k^R3'WvC ǯv(`#kqe_:>/̝QEƽb' CM3}[ŵ>!Xl^-)hN 3bi>SCړeڂݧn2Rflԛ{gttZ%%^yY k5%*K9#?i&)lצ^ $>H0ԁt3^D:ށlF$uO;_ڙ;LW hL9rΈPng 6 s?wR#M֪Żkd>R81;;FtpYq&a.Ohvm%5XO yl3 پL1.13Nov۷jUn0Ι줨.tɉ8uI:S.1_?x#a;SGI-~w(4AjŻ'mo{2)JU+ Ś[78ЕLCAc;xigWv5\Ao5jm][3v\̛`rM2psP)~v N"1st ȘjC(n ʔ*8x|RP0~P\"q}B:Mt/e(2Gn=vO,NzJ އzR}9 z_qy* 6W >0wB3"'q̆Ɯ;7Iiَ+)+2d<=`C6`f1WN룀K{vqzŀeJN"xe~;sW 3`Q.c f(c.;uF8Zfcr r'쿐2ჵ{y{0nw>:-f#s~Qe{GX% us7ݢ"6~֫ʿҹBC>X7@x[R*'oT5sp}zRm;7r Q?)0|Kf!6I0s^3 u@@z>"[qqgn:˂K4/m/W^a-,ұKU=}€;V *L6MݗNn6Ҕ^|uRַaL>!yTQ:tEoD1D3@ mfԛinw'acN{'SW8pצԍ0X#25U1AJ=3c6w+KJ3qc[T龋pMQ$"gaU:..߬sՀx`s]!t U^ Qwy$9ТppJQxp> g&a< +N}>8!ShɆ?pSǪR0L*"2]mZ]Ԙ#4g+X+I\R\%jW _+x:N>@ĪCS{YO}WS t"ܫZȔUWK>H]`Y4; >O{-琸ff/_P  NܠOa:73+<Egג)@\_~M1oBTN†0ו} i;8F9/^/`؜ ܧۂ+Xnq̍fMњ&Lb]qT%ȆfFl% wdUC6_^?'HŞ|)c&\:J,$&0c=o>̎!B߸V5dҊ~(dZGް|пG]&ZpŢxsDHџVEYb<ꏥ#4g áʒ<\Űǘ('9+RI,,S8@ 6؇YBeCؓq OJsJD/ei aJh!ԬNNG/ytxY(5?+$_'p>w#5#0 _v$; $AM1"^Nĩnop<n/>'6 З K6I(х9> Fsx"lS>SW-z9ũfbq@?v6r0U(Xf:`veSk _!-)ao%`VHOۧriyٴx?I?ۣ0f99.4 3ؼx^ӟ79+c~MVr nv,U@5`P+"|ioKr<2PMl%QuNw"1HK6Hخ]+KOr%0~R2S钁<}졢r!!|)7]Cfq(ŋv47^dy f.kL=d&4O0b?-( 2'g- &fO]4SVo],p>?:OJ‹%Ȏ#.X⥫1hI37I4q8ԓmNq]nv/ D*fռZp B^7#z!  &K^Z e/%Lx8*h:BasSY#6ćvEb跠m@\~,_GaXgu]+;Kk7/ !X>S/tEs˱^'GIs({R7/?pQMhԌNB{}@c ¡ W|QW4)N|]hQW &hHc)l[4w&5UL#\C9ɮ[ߖZ>r <3֟vNTZ6RЋTط~*2`7F"4ƃHzt]"t SEY{QKnL 0Ѫ+K)Մ - ?!~]A3E\+>WEΉ{,şѝW4J`dCEoc76Qv@!m'T"Sſ>iG)>*7cb%+Sa~"Fa _uR[@0 H\qasz8Gtӛ(!Tq%%zI*f*DB ?;#]6qa1Faab=K#P.myf*ΒUp೓ésJtIF4vG4aFLVAAK;?ɼlS$j?\c&.FOo-q4S|_Icl,4>CB}?}ygPKpY{ISkxÌV湉Öë9„){O6VMp5u,E;5x0vٸ!eY%X.m^B-_c҅ϛSwd%#Oa}z.e$ \? -޿ARUS`ƢF3}l:MX͇HJ$,{y\/^v ,s B@|G{ /,9Υs& E|IJ @ݕiFIRٚk~Zv} dCq_$ު/he$6n=I)BŒ̮N$LLQ_Z%IHNy<\㸍0lBHMJF Myz U~99q$# Ͳ Vu| i0G[sw!vM [ɾ6>c]쌬 kʟn*.0wrek*Űl4{)$_2%i#_닳dHV?k= |X3;u3F_KA/?/o'>B@gp| R-4CpVbތ, Rp;&4 a6Ā/V𹇘.D l fnyu|K=WR.N˹J!2,װ.+r q}'dV7uBqEmR^=pALtR2 U[B5ML qh#杓|,4ӑtwߵ~BK#ʈTȇeIZ@پx!";3G<=v#'Y['ɘ_3Kbĸe SNrhٝ!ϒ ƠDP\%C*OU q%tNV]b oz$)~Vq `8s[fCb.6gA|78?=⡴~ru^'%Ml{`cÝ^ aZX NG(|o}U7JZJ:\h5uϽiiKm`=5p8l|uoFV9,8q/U8!zڠd^UYbhΨ`u;xbP$wHnyOd*ܓA NFl23@&OV);8Vo FRPKCkb^!'@8 ΍rW5ݻ}?_yJX0V|X2pX"Ů ęZ% n P'=G9:ꕙf9fͧ"x+øP.)iǾ-hN0znawTyT?t,lR/JU.llVj)?G #g)R5Ar+.M"#^#$v j+ٺ)-'.Lv<<ȳGiONrjVfr)vhрSǴy./^ g֔淎HqׯQҨI`>PZì*i;3GdBZȎ "&wV[ ~sӀ"E63cFDN҈V- >X:ZcR 00W>%g8nV'$=JL.E}耛 j°`>؆7>}|EqI2~fU1 ϝ=<5Hj@: z\ Ikcqw1?z/L `nș"^6؍4'ฬa3 ӄCx7<ɔhjV$"ƒV4o TpԢqu\[(j ͵k"j^^ߒRTB;rlk0Wn02ad#XoME"%ZBn9#VJX Y%cg.xĆDN_g7jqE<-Uۍx') =5R鰦h" G{|Ge9P|MTMD 9!NEY6~ Yʎ"2Zݍz0Ēȹ'UzN=)2f@HX;G}aڞ)8ĆF+ aޗoC07>;dv?i.չ4$\T9gƠ]>(@C7M*p5ho1XvoB5Eq7i0锿 "> ɵoiC; P$шLQYF*%пDg+y:@ii7f%-b:&AKͿ#KD š{i HdF `>u%^(;dz??3ʊmonQ{:Hܹ*1Ē%Ҁ뤥cҲ^~X<댒¨nuCLwuTf3D"⇵d8:6l.s/Aد{.?97G@UoZn//>jceƍLUyq{(w"+ӿYj?Cm8930YP`-l})Ӊh)o#]k"&[7]vt7/cw0vڭ7:^f)+SX2I K; dRRs$͖#}*v5VW\Ѭ/1n6L Q@ @s_^WZyb>zDYT4PY5k2kSF hTfžZ uٝ..@~'ct+|E|p1mY+/x=w"ŗXֈ:9]daU'ҞN:C ը_0ԑtYAO&qN:".yp \/z(u?0nW%ܙH@šEYnJ&%l{⅍tR>'{b.D0OWwFp<؛A׫R>–;Ti9=S_^Ez>K=<(WÕYhfKD34cD6X=/dD3XU:]AZH)) U(G7S?#6:cџo^ MgyIٙI +D^yAutdtb "#[!D0#VmώaJ!׬y\{-c ͋zBHFB8v*cBKEJ@w|wʊS!!_/GIxDϭtnR2!\N c~@z IæHe2j. *Ij "BMQj9z/,KUhЇbj Hf}7Mn&%1O9ҐĆѢSfM9G-K,6U4^iFap`AwM2}wKޚ7vZ+ݤ hJ`w)&90*izqgI+ ǎ!QxTsMo_*HA7wlriMdJ:ҫɟ}AV/4*fȷ;s'㿙 xT$P9Uwd[lYUY1{{uBQҬ#n*'IA N{P"hѳ/"$!BXra£'ߌRB}B/EgmfL֔bG0X be`$뇟p}ų݌Dg?&'#Lhy(1,r?x%b[͓;&4~#R2iK,BMV{qRrq_!nAX:WБs3ݛ[2IcsÛGEj0,SP@87:G[f>?'jǣP8p5sV(8nEAn0ʋ8w-݊%.vA]\xZmY"=/'1f4D0n aϵ5Pdc )^'eHM,daF &*"c#ӖnAd2 X獌'i kL(Y8Y6ӌwh4>d( ";,p><5ֽcLK3+Q@^/oSejnvZ͔F"]tBUeR e& mX ġ;N|kQ:%L.@<52r9́K9pˮd_":?(٭:Lbyᆯ̍B,2ZϦ-8bdU:O&#*"+=7B1|MF˞:ZN xY 2CNmH-C)?t1$`Bꭟ VF6or#m0 [{lX.LUi w,*\VQYjnb X1,fg;wt{8]N/|`g %YXowg(;fwd2ߗv:| ` 󈸳z%6}f%4۷xNգ—ERK=ϟ'Ӆ8ً#OXH 9t FXOZY؁ӍA\ّ;R<9տ7Ko4ZT,X9HߞEo.ĭfK,Y@S\(DRmeJ\JC xCP;–0x~U!2ߗ U87J_nia dj&|6GaÔZ0Zp0˥KҰX4(CK&U{ƭ=VxQG.P vʂ> # QZG];``e2OE)lBw𭆹_#IRT<]b@(S_`u3d谹]*4ZA9j>"VOg "ln^ rh(*nW}rl{~l*آ9ڻiH!z y_,5g7m➗W/=+:<=PA8dgO쩘 @hEqgNL7Lmy"yUasI_kTtnu!{O|]7 ' 1 `}r|Gw0%|<hk1Ti桖+0fq?N<Щ䞲ɇse #oOZ=~H^:%W`/?lZt-#eVy `P>Y#.TZ=~]Qy‐uPT=9x UCϰN,inkdzƯaԵZ"młgOW'A#XxC7'ݽo'dyQ.*RIuC*Bk M4u 8o83!L{6SÝy)^sпK$K.ysq 2!Ah2qZ{̛`j mhdx-;#زg$ozV) -V-mud`I;T.s^ƙ_v!RT&Kc]Q`l䣔)=߅DJ{,!|:p}z%UHHN ˓"Ƴݿҭ&z j 0O!4-P ['nMtʊ T~yR:&̂bmExLyp!Vdgڏܯ4&mF&#cŽrv*DV\]Wk5{tk'K*3U ɥE#u kzzJ2=ļs̹זy$n~P l{IuGk=;;8~*t*W%Ɲk7~Tc42 dVWO5µvAz6  DŃ~j+N9O<Fm)sA%uy^ع#zOI[rSPnQBa&o h^c9; 0yMuӼf[;/;8ktT)Jު $.#b~.Q#ub\8ah+Eoew4p`IH,k2fn r/Vm\,:Ȅ_&Is"sq+ {BO⪵6 }iJP>YғʸTIE$Cp*7|7r6kI-:qL! -dD97#Dkl̢_,E<ңμ6¸鲪UoC+%Q1n> ~CA!#pc2g&DZ8WNsCh:9doV+ZL7oS%SM+RJdҕu`8kmrWSq Cǫerw u懱AiJnr# XіG>ƱFA-Kz;_.O3A,Y:¼X_[15ıd| t~޽F+߂]˴&@mr%4n:PU>~is;p49gm(`̺a_I$=wm&aCHJczkuj6lbj#moM(ɣw]gz'2]<ɩ2Og-و`Z13o>^$l{$ MKlD,,}{"d< F`~5I1p-D]bԤL;C E ŋ(߁ljFF|a^ C+6" ˸t R`M N3N3(ՙ&\>ٷ7;_uM+[`8wg0wwSS\ |: VF8Se*L##(u#T$ &dTmZ_Qzzƪyg^mk[ 5-j'I8'>]¡hkQ]YZtst&RۥlcO eI*JY8K=g΃oO4 LE)=m َWOVUUla!)[!t{_dG =UGyLǤ8jU`Ę>XCUP^T)e<{®{C/kVF@VKYbZu,i9avֶju`HDx^Va5j45AU0$"Q.㧭WPc#`ԢnҽΊ]7M%7gdPCU LHxc#UKz$-rƄ'nfIJLaY$HX--79kTɪ}y_7)U@ 1dH)wB"s*(H[DCq%&+vFͨZ>Eϐ`AԽ5Y!Iz xjOW6v(jG%X,7{p>!-ҕ:D谹c hxG]>&W!&A: ^wġU9ć/;c`]U6f/"FHWʝ<_6s->˃<8s➣>8ޭrOQ52w!X%B8KJ. M,;[ >|ؔ'|A~z]i4$kUkf =4}a~ž5A#48)>^v@wnM5ůBeqPE3YtkW7]#;ExR!?䈚Y7F1 >}-%}Y83Ֆgv'מ)!r0| UfW8lꀒy˴=L3_OTedֿ~Rys"D/ v ʣP3l`#xGv2 5B Fpi|Xɼ6 wIԀhm6RдH KZb6+X퐎,6p:CH,=ݠ-$E%|5m 7v~>bYW%Q]̖yz}U[-0ZU?JЀXnJ?52ex4>e>genjlW0ɏʽ[Q9)Y]jٞ}AENY 3+1ZA!KBB<ȌV`:B&sitlmZ~ӄ͉baRVGeTSpAT`ĸ߶#炪l=^/eaUleOCCk{\%+w!FJng==kE"AF3}4ZgX#O3oNW Pa~i7︹ "=\fF1Cți9]Zs3`cA?BA4ꢀ*`U{ ,Ԉ zW }#Peuv LxWo~LDRXf?]{֨[bfBܭl;M?Lڬ9UMM/U)XmjjȭE;7󠅉2/3P] ⦈9+7FG5 2Tlwy%RB4?4f&PNhɓ݋ KJA~C䞓o'gWM`rT5E&<݌z{̉S-N]ZR&a~ Y]#D6cK.!_2`&>M:ɭҾ.  1!,ir2/|i2nvvNiXƍWƕiU^N}tCPӆM Hfeg%l5,i>X mJI.cr* I٤U Iz>pΘd!zĸY{h,Vb[|zBd/dEәisx=0b,kF'hA|;Xi1Y״hg+XӫB;+xC!Xx<1"-,&"We٪Շ&%@WvlNPoXWPK_qb m'jfދWm7owZ-mKHX2lHȋuO'{؋yMnK[7{ZOT9tlj;(Z8{7?}"r➇IޙV]IZJY YVիE}JvG][ڙ۳"%luK'\B`7e4#)4.>үJHCy.`wC>T?{N)zCzaz{.Gl2m&6  Alf)!.(K` VӋmia#3CXj[@Ϸ メ;.\A6$`zQ%͖au7o(debu;MuT^3ݪjd2/fp-"#(Aޭ#WA+L[e"Ø92#%]ЦYeP3wxgy%ӌLU_t WQٛϒY['y +n…lPԆ^HvP15B8/f ]AZ5Oo qxjuR !(=Yu/>W]G[ѯtrU/ݔX^yrڸ&$!ToPTE>O?C‾HT)fŴ%3]%yc'*8) m则hoeuh8iޝ[WM';b d5(;qϴMܩ9сbG~J6A8beȘ@SVS 'Աt} ?zDD2hQPE?l,z됿(ml~((ew="#sׅJJwҒ |V{v&!?{ͯV _0%Eo 8|5D(d)$:q[Ĕ/.Қ x]ra / vHSG4(*t`gݦCN]Tn|wLO&XT\ͨc/Ӻ=, q_q}.>~}F9( G@E%ZA_/?d..2|+hd|l2ŖIZAЮ҉ >Rx@l8[Ȟ% ,g^A#0 4OIKvRB|)A++Q,WQ Opk a$cǡ~۴RfY)#p e 7N0(#Ū pv~eͦNto T߅qoO1Dž,ްDǖQIb84w ܱ}\RHFP&\Zt5JLy@ r4kbB^;C4(rMIqb1f^ a/Ii -4=2IY l L5yӾ(5_˗->vx<gG܀N7t0P "x:cwd~#C>|\65v}F\[˼ש N]bڶz ޥv=U7"jhd{#MMRKm)b>NI +3iΛ{4^}})=%9__\&ĒkتTUdVK,Z>u1ًnX3eH2Ιlt-*D7C:ANi'5Wv馠yݺ*k7ָ&.-^U'B.O`"!Yo<LG86i+dc8$Aﱒ. iNE@6@C'i'&EnK~ 6w(a÷̴)I=k*!g!ر (h+O\ mvD:7s\67Wl(K {O#y|v3a\YfTEŽ~'\~-Kv, jM<%X>ȱ W23a-Z)BtqZQܾpڃ.)%dy0D7YmAqW+n "5a8kpf`޻*مvڇ͗Lww :,CK6fvI/OM ^ꍹEOk*.DPRTmAJ<igeO^6EҙA֚e{Dw,߱*,?$+i˙,VIyRTn饐˕"j H Rԍ/?xºC·ިH%Ch0!|h;c \tZͤio9Y6}8!o+/rĜ!_R-QjYmPʩ"dqe!҅(LJQV%pEptBbBD3zד<+on,jzۋ`_ݜkh3,sҠ.f?E3:d773ii-sgbpzZ oмA  &eύt_zlLA?2r(m$iF[;FJ琶㊲Vfg(q X8)UrX10C6[JF&iIӋZ|ʿ+Z4,dSuYzaƌ{ :U* a懲mwyU_G(:SIG)݄|& [i]Zޢ\\Gf.LhDG7;nyg(k>%kj #g.8GkΘ 効oj)H;J1c@{O*)D (ARU@D Hv/Q߮"p-0GY,Gųxc),DғʲWOePu*dMz+V $ \Sn /֍،8/rsN<pyج]o++C$VJAF v`q`G{M>J\~^q4_`ȭPӘ Ypp 4K"GC~Դs(fM f584  S>'e;۩6b1wCc ux;k :DVU92 ֑^?<6#Lؖ \QB)tIV*nsCM$q}`P' >ڼ j>tv8yV xMKv:&:ĐH$o~̝My hI>d_Lܽ*{ x<|}~xpؔ[ ,kag'#dQOy,+[ J>M;;Qϱ]kp7GYu{NZ;sJmRJI}$φ};;|&Q2{#a +~Iq2Ĩ I-4 iBjTψB57;QH~S+#\Q_k@ .FiQ\| 2S8/Ab$9M'Fm6u8Mv'W`^a: /SB_U}DzRf|r5 Yγ˝U-76M.:7{Q9.Ui_/vw`߬r'i*lGoN.@qS$% s8 G+^fxIۄ&7Pv9 *1wegY 5XQ"Ƴ{Ir"kA輓Z4fs.A4TnNqLg} "cu0͌gGIfCHVF _`Zw.y/,9"ټ܍/:d+X\`)L >Ræ&DsƋLߣr_6*XpJyħ{-эV.l-ܓxʞ@땹?VWyЫ 13N?AQqо"[Յۓ'`EzN/[v>NI Msg3gHj_⌙di1 ;Awˣ>J숏`nZŊQD)ۜ,0V+oȂIzDɶs Q$,D#*kދFXݪZ7iZ$p*ulGJɛAI]XQVwlu D ޔlKz)꾲E%"}w\QA.{4MkBZ͟ByCCA^nwfӕ#ЧjG8RW6⼕3E: кlQPuTw%y @:-}f.LI78`lԓY$_PA`ޞ( <_j=]<}Pw=jv~…i?O_dvy }?d;魜x; +]Ab yv@e])$F-z ~'};#kAPGD֋Yn6AK4~&^-3M w *ZdQ;HՍHAS`ot dcl`۸Αbd"AxX^A}4Ea( r E __#SWϲ;=ƜwZDf@>аʱFg,jHW[-JL#⠜Pu0{I/~lXܿORmEKCVxS9WU'RV-˔YǿX ҮkSI SgRBb2)S)qGa"v1@9&(l}*[D MAP_bFtܴ~Vo쒑w}.dBHB +ܞݲP@EM7wUQ^Pahql`!Ԃ7LJ7&&u OnV1/z,8z}Xw \ ls:)~_Ƌ/=ϊ2աoT6Ew/ N8N)wsMv\1yϟrs&ZAD-C"5w桎'yTgeސ[" ѣ, +W4o쥀 /-Q|Uh3tcdY=Y;h!b6@z#Ei4T]{=<ЙQ;Vfɹ˘p{v>a,2z. :8\EPMkHZI-yAX"56kT[Lߣh :YדK͛;UXzemSrH zz^Zb7N5A\\pnU&a(hrPi.[ %揽Gr!¸;?OF"6q@_,vSoLHPf; yN)9+qZAg1pop[7|;ֹMVIXY0?xZn!ATEQg=|T--(rb[ħn)K; g"xM.1) @qYi\vzvϏ+ jc#Z Y2Jy'4|ںժ7s-r\xԁdX:@qڻ( j~5: u EŎޏ%?ơ- C~*2Vo\ O7ѯ"TkiIޤy+=X뼇r.`yejzߕ49nTS!g'Oo.G5ı^2^^͵IG \8QYdž Ԉ )udjܳ,,Foyw-Lz~dbM&DQWQ zZP :[H,5 E-ؖE0. ӱ7ѷ3GֳYPφ8%;`}BR*Ewhi0],P Qval E KxP5|q14Ug-Z˧2~clRU3 yJյO[ڤWb'&9QrУ@+7+-Ph%/An&{JeqQ!*$py Lnz4ZeDwZk^\oxQ:KLTڡf|Zu}2-10$ٚODq4σJ-c9 Jw8+nQ 9k]cX`~`0,hNK-m07#y DG~XOMelEJMȫǵGۄΛ7޵r.~T1Хd 7]bLހ+h[>qf0W LcLvы(ؿYV 52dKlIJ\==Nr-w'퍭!MHA%Bz.ӈQ\^г 8SvBARёe=W׿fNe{]5 0u BsAHЪE:)վ!]m[ǿuz'HeQ7^uc>?~:/Uj9T%5m*K x nnUWOӟa9R΀eYV-oR糢eHiËYO%YYΆ v:4DdtCVC;>BBsM]ۛrAf'5Jک@֯rN Kj21 '"iof&\ѫ,9{q^~WW,DXT=hETttwُݺêwe/ h޸6<Hj>zzpbPjGq1m[ gp6?NC.37sM 6wO6شQ>3uұ7&캟(qof"O`!ћuژ)7pBHV'ҕ<7P8YYAg̡ E{e4˓lCDF!:F4gcs,*=V*Rc. JG Vv[ܡ@l*77;Rp.b Gi!ǻTrF;)=oWL4H' >oU~!4^{Z O&E ׭P P"ߜ]wa@ 6wMi89yN;ec`oa@}Q:-؉`1 7N^`X\122a}gN֧[2wlč4P  `ċ-smĽ*G,2za%p*s/@ 7Mqt8S2#p*H8PqiQLm逸Vl.#.#7HSYa[~/>3h@`z )Jt/\ed, }/?=Ddh1I; 9J=СA*{c2?jFRwʌ08zdSQ0 ً]/򼼡g@@dɂn5FQZY dCۋ!FS$B =ReMY8AZ>/kD4Vo8Q{.q]pgk:8hYCbB$*Zs0&vnT|ćx(-I Dro9o1eЬ爱2?-vK^[^ھm2`&U+ZܦTq`"aуP%GlP!V]@ nf.ijWvNfk^O7h6iE_g0+$>e>ם4̓I3 *s=LcԖD1@W+r89 qq&y7PV~Es}!]B݊br\}LyKS7pfrrP[|{7o;殍7$j'RMBbH=̶4)lc߁qmx~%kMIaF>h$OsHgS\;zTBc|Έ6$@B,OS[lh C|S`~:xЯ4㓯"M46:@9#Q3-XnbsoFYDm#30DCE`u ؞ȋO8 P ꬃxKy~n\Wr)XIq܎}X H`:VxI,oV^bJ204ç.MLR'y8] Sֳ,1V v}rIt$~ }H f?GP/J).J|2Dv[7YSs+kkW낫QQ2y(5Yi[|%r K{ўQh`<:v̚2:(5trg¸0y@eZν7s/C<勇T- u[vAona5tDi[e̐Ίbu!F9ܶj yM|H`Zch ]m\=0{V}fO>na4AZ!JڴJK(n! #Vk g~W**BORA=-yUHʟIͻHEo]L5v2U J=K!`iVCF Ͱ@۶D&b AN6i팷<"8} J3d/8`u>,+ώqfPEa<e; ER(?l(#*%umez[fцC4|jww[]]ii 4jW_bŘf`>i#ӷ4T/6p?oVIEDT4rg(,y3?C˔s kZʮ `M̤Q3'* [[ݞ-:.S(Oģm!=;@tq'_-.&Eyr ؈ՂPIEg5ۮb<+o\ !8SF Bֻ(vĠ;{`ô.ǚr$# @ZN} nlrԽ{5a嘛tiF[wڈyJ5&ezK˿0fh!lBWȜ7KZ+ 2a KPt\y)h /BEDS4ĶO',V*BțJ_e?#vUh.Sl2Nxji㭚`QvoF3(9^106Jc(lSwX~O(%G) ?:ߴ:MH.*;*aSHH}59T.βHD=pWJ gQ_繥.cU@֩=h=\ri Gm.Aq?$Av>:1T7[1CQa$^ghQuq{97RW9!M"ĦKݔ+yg[ϱ_‰۷E3I.[Jzɨī+&?ptz39 監YOl҇5k?T$^ڬS9@>HsDL#/†mXg:9E 3n /)ؐ;6<+SO=!/l[mQ§W;خF?|ziOK;hyEVkS:]>%R=$LCJH OQC-KHd 49,}3׫:%_ s8>EѲiQyHGĀ p^|/kzx)_Q\q,6(bAQW;3gMBQGpK0mfgD8*gGuNd$ sMU1@3rVrtm\,(ӈc7lF۴Ɋ}B FmX3u̕P@2 ilKQa4 S@MxΖK>5ej(u`eLS4'D&ٰ1h|pR}~Tڑ,]R˔O2_ ύ/.1$Ԏk,E. zHkugݘщ|ҔI܁ u-?\ <- . v1& uymgnƀZ_waC:<}lŞ٠5i:4cyIVIKu/f\j'\5paDM30r#:p|ȇA`=(Y# oV1ı 2_r_-p㎛$Qn3aFcg&\A!ãb;#x-臄1 >67xv>p3E.aQ|~)#> W_#(n"SlZ+/cjgiCM="=j!AW]'M'MtH&vuC8#rϩښIV@@J Hb9oq-d8>fuZ, ۺ [c?`͢g)-Q{e>e< Wo~ pr⏲%!3"TޏYnG)7~g5rdw\y*!Q_;u_Wo bv>pnävy"%a lvAS}+ JA+:hD&bu>j)zX_B6,*Cb!dj5TvirHSJ1ȷy}c47 23J{f)ji|'KH6k_6.Q+t!GTk2uDthW򏏈)0l⬼]V XV◺E+0($Bi+_(=9JSB #b{txFi+M/upc,Oc lT2G5GPW޼k2YW&E~P?[!  U^oR㉇x@tڀM~3.$"=?79W3k`~$frI['vvo+,2x5bQz%H:H^zxTt1`3f!TTV@X l4pL XSe)vFsPw՝ӄ"]C`YO?҄C@ & a۟3ͪbwJV{]3Q_nҐSsQ=0̑d =ǒX2k4B+>/Ay|_4d#[5Ad?s| UGҢMx)u߬q#Fs:(`$$,B[Pem FkLze`wra32ux%uf1vFfE7dԇF7Sf=YbC#E^sf~iwGl(}s5)~nҷ;+Ђ0>!TeUC~jq=9bQ9+ rO ꦖDR=jYhgK0Msl{8U&im©C]Fu<3`8ksÍtǷ҆+uR7; ۽#>=v'yRlv(wo\9|jӐQ0Qk_#(,]ސ2IZ){׫gj\ZIj{CT$Y]Kt1eM sk Ԏk8Bj9L$X}I^U+.MwVDGεTҼ*cz:IzrA/ZM=oL3~P؛"* Mt?]TaT*yoZh¥*Q!Y4.5zɮ<8(Nm"9Tv3.Hzr1 LJ)ϦWcgBoe1`53s~YY` -A+dAh _|7PYl$Yۻr?ҷc|:j 8.eL^sqIx^{:9zι%o~:ȁ$c2PQ/|*l7쵨MԙҸ.wwS;I?dh<TJ`:ǾT8ܚonܤ8مfش=0/]BPJ,PG`$TGl.ю{9+!qĚv5+ڹ_kXܚf2܋=XlS}^j#7ct8~3itv1ǘj?V<X?;Yz4|A;_W}h&[:,mK"{MH u}X6npdU}V.<9D ?юvv#//Ȱ/ysm݁¿Kg,ju .0r!!V7B ^,B8_ʸ;B/,]̅F-2?/azBPv%{RyxGIu4%@){p৖B@ tO,Ѹr#N&ϪZ\&b31_ +P 8W++%- _~= v Tۺ60= .PD`ୂkuUμ3a!HV/qs}nKJV(pc O N,GT+L 2H'iJjMV=T\g|0b ` rˀyqX(4GomZ=ώciDZ ZR2l>Ҍ"!;y|R"Q{kRKz"(]i[$W- '.pvv]Ez=EgL{'-5Ma~͜PscE"*Lg+PgOMSDۈ:{CiU VoѴSpеyx{[AVr 9rg,DMbl}5@ܲ Vg@L4^ ANWr^QN*@Goڷ,1EZK9d}47k٧G(d]=IZ!)qI&xyCM3j"n7WϗX;Jn6UbKYOClꫨ>iSV&\$tvd C()AӡCʢℵ"~PNK^/re9|z=ķӟn&qf3w0V) *h'Q"60A@Lvyzܶш3%1IX `F~A}-4`*};ԄHcynaOJ]SICkdܣR#QJTӋ<o8iSf=kSeń^I8hqzqƾM-UէN 92ܻD֧E9y|u3]p`c^4k'!@9@}{¸_3 ɥ߯O1K1 ۙ]:5 zZ&E<\*z*FASў>v9x`Hi/Wx4JYn7?u]_P.NvT4CL+%dx$9~+u Zo})a ʃ܃-{^+J >ʋ-=xA*hgEi{cmh`-B'0 g<7-w\]`7QZ$k u_nX*bYDͯ=ጰBTJEĪSjGpN/}&ޑg S(0*%E9 p'FkLm3 SL ܅(A?"I~RV2>RS8q(; 2rOƕcpJ;B%aRiZ1))姳8XUriS9[-}Q6ra v+XpФ={~^p֗fNώkʯl ,1urArd5"Ke%GGga8Ά %']V8ZlK im9':891Չ7nЦyƔ~p:C"%r;-un=ӓl.LhSpL桼`,.6"j3Jo RXĆ=j ڨuH$\VT8[j9=P`1%c^ ,יVDf*Fk!{Ałzך3$i3#ADfDZAz+bVDGCys^=#qNȸ#(pTa vϹTjqu$ˮ-iN. fcl3ͬnfQ)Wr^pbAr?nMKn?#@w &I)Ym/ɟA* RȂ Q#uW-DB"SB7>!(˿` ѣ7dۮ^TFݞgp"}QgdD]9-fkhjG,1RnˋYX3 SJR1SB4}yZQn`>lJt) .%Qd i;QWP{fԞh*rz`U{yIx-nPQMnW4A=-gܝjDqhg}KO(`+XY2qi 0F8a+LxI/_DKNrFc;懲$ Qu6spl9g:&+P]q!$*\;UgεV#nG%q+#zwo˒L x~%Z^n;Do59r:4.o_x>EԠWGVkӲq-ˌ`M4V+_oPjP1"LYݽF-u*y[8w6 LKRaPB~vrcC@>L5w- &x63 FI_ڥ]\%_ƺ^PXDȬl>;AjJW iٯ]e`!K#e?_pSܜsR߹aGkTz\9=GcE,S'7 y|3iV: K{_IƢsQ8R͐ u]hc|`ŽǘSUm<E}F-xJmB(*2w%#݇ &pyXcm?g'v(&!w&QxƠ~D͆|ZU@ eozƅut{0B(RD7LwfnS* GYo[Zk‚$":vEȥ}#ĈlW*'21ӥ9'FEBQ%v{bb-1Z IMa9 >è.qHrA%T]qހzM-rTlX{'#p9+MvͣF"DZ ߋp ekL=N@<]Rl2 g JY_DHNCMqȪ! 0{=8Vj$UGR'Ybm^;eTi > ԍTL{iY0h h1[v(j HE";69W,j _a&2tBF21;ciq6$,v>.K:Q9`]fFEOCV˚??'6ICe.$)\ǹ?}['L$#"}hF*8< F/olys㴩|A~ ni^0b[n$g-_e xpIG" к0\@jT_A0 /5|iՖ]ռ1 [kRE4H[v!(MwgzE5>j"Dc{eﲽxM rJ/lġ$^|{RgH!CB7@,$^$Г d!WOX];M7qoHJ V.I>._ Sv,5"G4|yy"jwiNfNZbEvnKy# JB]$ *~ڥ9ɊݿncP;]> [\E!{"KO'-zvwYaA)1yH*IÕg f?<Lt~ZB2q ؒvA{KZ=Tw.y, EmcP,,0֮AV ?Up~sQ R ^\P- &ɶ.x0E0Iy22  ,7v`5gq8*P]Vq0 6vmza00uRreU'Ú@=tG @q ia$mvtg(,3U{-Tc2kBNQdZ-?'Y߼x=wFbtBI˔9:\ 9c(9}O<-2;S Bi_o{7:1\br"t5¥M-\O {P$;zԾLD;!է0t/:\mר[_HYkk^u:Ds@܆@g.Lk3s=%d*9ӭAэ5LR@C4rtO|E.D>)X bWV1b zo>Ȑ,?}@5RCs7fKU @S}KV됵?Dwb% qYQBxHM٢.S?;9{~]RYsz=$y~1v%%b._:O?j?~{55Ɩ!ω׭jF"S2*¨. Hr ~ EP| 5vmU8,i"&"|9d$Fҩ\m ^Lם$RMZ O4 u5ЬxH*6\kCΙR&(`{=š$LƾM8 YB2m-R;P`=#I/6;'@sV06WXsܛ /m[ٞӉO|m$oF11s";5V@(.$oLCڍP #SiǙP},E O:?6b;^\I25+wyfx^WCX5b> :^4W0*7hEa}sӼWHhǐg߭CI;Rdat/2m%YF#Nj޻6nF=m (%[rZMC?(W`:==ȇcG/BH$ ][BDmaz-~ ccj,|6u!W딿#$54ʗrkAxi [5ғ}xշHgXjZl̉O؇m&m˧aJgr9,ąIw]=j^D.?3ge!ϗ_uVvXyK)-#}LQ^(@Nŗ試=cXؑ+[7(+He.>\MCbIYnI+Df:?ި@wϬY="1Q>pbŶA @DfuP.&.߁N'L4 :%B˴Sk(| -KꁡɅ>l7W]x'?.Dw5bEs=-Q1n>$jŧ|3S\acJf0A))EvGT9+ʹ=]Atwh)sgd,S^2(gxA1%Oo4)˝A N q\tٿ?>87p;# 엒MSI:i|d\'f=]|oHC|6?F]^/k~J"{đ|?:~ _tt#K \_)4 c]qGKNEc\w)gdy SdzQdhC>̈|`R3"L#De^1ʺnp&⦻>`QȂ|AC+G jםvNdTDX(_VOTQ<ۖ`_G28?5hogX*.ڸ㥪5(l#-um>-8jm@Ľ(g:Ig 4f_8`_5BCK^Έf~ qθmU'uC0+ \]]#YF5O++!̏jғs;*\vᄈգo6.#hh6Ān:l!~3?aBW,g/Vp:g ВA9S^O@FPD~mf.˟G b~Q`L7<9Y$fÂ0$_`@$W x>rLmB /\ tAxҵ2EZIě!6CeV$W1&!,Iq>F[`WTn(ud}ʣ4blb1(-1Y^8i43jMKFտI#'fjzV#$p ŕ&ߪvcTagʅ}S5eA =h5W-{Va͟\U`,}ylv;ZL}Ȍ8ԾD閻 = M}O~VEmƤf=2"x|)v,pي@^&)hv,ƫDF|U9A1ͽ*"2w@oE,A.gAmyu[rF̯,f_u1vgFv#)ʂ;xR1t#T~`εы%kCt 17YY-=1^oTWA\j $b"kڮol8TN,#Q[j \Rw)ٌ vtq,M5gփփ{.d0<@Jjt@ەs3JB(?R5'pMcx%`'`渄6*?91M ٳSяT#u$-?*DAKkCaíبY\1l$O3%YYs4u~u*(:Ɵ,$?|))GMVwTm\r(Ҩ937ebPyI>{qo= 8̸+=m6r_lyB砰L\eŠ="8LUk &s%P[9ZŹ]z HEXmPDnCS:Xց]=B-Z5BWRU` = ̩AЪ}C"`_?p,l}0Hz/0DѦe?T}O)W3Q'1;ߥР|7>׻j=_-uǔvBe6z<Ks|\wtMqlkI(T,9{&wx!_<Ç-Oc39txu %UoofleFZ7^d$+gh^ d ]8Y!Jm "s~!&vĕ>W;&{t\6LOj|tR`5ۜ1ȍšM# @ZL= J,@cټ6"ۚH?gpu;|W$vynqY1)n9<:p0)FMT*jVo Vw+/^lVVr3G aٯ SO4Q/FO>4 ۏ8J!:P@lDd|0+ A_U\7EW~1&=uox\wM0dj!0 ^:6L;66oJ0Y%NJ_!z-W`%z "v0$D}2}p7mʬ^­>;AGz@Ո@g*> 2Hcbjbw 쩖jfwy:dLm5~arx#U48Ŀg~+%'1V40XzK4˩-2gJ= O|)&ΰ?-M#C$n}}<:&@P3Պ:%MX PV:6G$4e!0U 0wB+ ռduc@o_>pUq"k:xF'cO'Z+hŧbEйoGsmH{6$JF]wv1k}>`Lw4-;PFK l} U~PO]-&g\PQ=f,5&Oǡ֡-^T{.Y'DI ~g͖c #ȠE%fKz_}=k_%ǎ4!u 7E._`ܵٓz}upxE, ܜIlzi,p`wkvhs6l5 @{TwU&$c*n 1%ކpnZvlkB="X;< 8氓*KoѸu ?AR@8I΃-FM}hfhQaE6}'8~\)uQ< Z l;Dܭi Z diù1UVde jɨuh'։!mNA?:7@a䆞A56HirYn쵍ݭR?ejz䝏$so,gR*qdlzV.TkRt,`jA1[ֶ֟+ ~ yF&F;k!*Db&otȦ^P$ Km^@H#31_}NޗYzЬ SO "އeKscbԌBѽ}=rϭ@:Χdcg-4g(sq ^uc9dR.̹B#]u7s/+wyKࡑ_(".8 3l϶NjU՝ nj],)t?Jd}C9$jǪ-.hMup Z͸dڑԝOp{E|5E>j4Bt֪ʡIj (VA~T 8F dLx'ƑtPߴh^PKlIjtlՄ.CEK1fDzkg>vd]X| ؑ)4bH9bFIE&V( @Geh0n.4M0tW/m/-ǜ0n \^CddF^k0sOd庱J=#''Woꃉew5jV`6\%EXe }Xp ]w?T~bnsR-ZoA_mAp~jfm*fGNh-W,(sLT#F!4o-5~r#^[q<L< /PxDq+?9  45%|t _¾Y)DCb9uf{x 썱-L|j{;QLIw{7{k߃iߎS4o})X{Iђ z~|Aȸ8jdaԠE Ôzh m{c ?\DC|ԝo^t䓅dF-οQ(%W LȈM2NjF,2YCyu,(Х6e@qwl[*spbt/lsûgll@55V*VWOLR dwEiMlhlD+E,ZE}L U O|c^.vuƬ Xedj&al`Y pwe^vզ<4ălx7\3hW%D1 2T~LU3[ LcAo +GGN V yjҍ*WCRޖ]vչPdE `%x^e#!TiM8A͐YnjNjWc*,5[lʺ z $3/Gno~nY(K6G0{=SۯG&dMe.'侦vZw qʷ5J0?`qńJ;!F!a>(],* ;kfZZ0zK'754` yTfأ3LҪe?#0vIaٙ_aM-N"?~Йǚ0\qi9%)䏙6.xs8Dɏ(* %Bc?IЌ>ap>G#rCb}sYqT(a|~ C1$xތ`m4dB~G;-IzQIYGaC%R&c0^-Smkyk1hlTc5 {tgFE/~>"]KK6i-d2TA!;g&|ndO/Z/m^Ʋ9dSOM}G$Bx8~GkB\KmA&B6?OcNJTQ dv66Flo|M@7 ZW֒XkkqNU&J\L$=(.O$=zHI7=EWrf 6kY$T5?Ɇ B@ĉ;dZh_&lZ(nђ0N~!| 8S77ě7}*-6@|gk\$.P;Vɑ"d0TҢax]t\*,ĭ `}d|Mn-;K|GSU*D?n@;ڬgJ*MAO19&Fr%uHNU]9,3&i>N]4{x!-S}.x?jBDbcFhiͩT<B1ol3ꊂ5LNrL+uY%SM+qBY zUoCkP7y0c[ *ە8͜rT 26%` TDu+M`-smj~iYۼ@Q8U>> "~{~ lFMX2beB7-Q,24\ 3g* X8mfDꅸRqkռ8^ UAgB,5i0t|#ilVƈ$Bx8r݌e%E2HJ?t[SD.xR+.PZRqbHKm F*ѿKC<-Y~~l7fh2! jVQ4<+qivf`::ybUf*&-"XOY+x1@րѓĦ/z5[8GxHTfvKg~gGSBtZD=h)~"ߓtڲ\I(q9L'%GӤ`vLxoG T۩9u}ӽ^^?fg+y Nlk'G9IcibT Շʑc%CO5O3Οur8ka#EJ_/MjJ` p\Nm}F-Ǡ؎i@;z.9:HsX6pLŬTŴ!DgE>vԖ]L3 [aq&_-85.}`eZh3Bo/bU^p/1o'sEclO53Q&{ÐM j§u*eڍβ$?S/ңW.K`ڱ {Af]A?N!Ø`B's$~BCH: s+*?6N8&D\4jF)7(yA9L3QBcϊfѳjil ] ݝ |Z-#1hx!~#ܗaL~zukT8*S,h6n4/r%P߿ yqy{'<.Ơ,zf[B}[Խm - />9A}RَW\=dg>=s)=w8i`cl&8/MIi20PA(H")!e}z /1-/zyIQ3#Se3ݭ$NC%Cr5CSO#pD_ƾ횘 6})g&ҮY 9yoŅ̱Q=|,3I*(7CɟWMO{)PUr?YX6PI76 ?+)7kLE>kؔOYU,n%~s/C)NiqV.)m[N$;&ytd)FN>NƄNCQ.AiH-~O,Qh? +eEigB^-2ōR+Udh~jp^No#(yjU_IޏZR[FeAT @fc }~%¶ /Y ŹS fRn LDJO=3@xn?坞bfA5K0Y#EPox 3a4#!Yqd%8AE$*L.g g\3Ly Clƪ#tː5eCRN9ЧP'DjRgTh[xX5xL_d~BؤPZH`a#J 3&ÅpϨYG2Um~,p3^2|Ҭ>kh-]\DKL[t]?- ׍'xǻ*]m*"^,ѣ)75|[Jiԏ!{s06+b+pۻS+.d(i:),tD}]e|ޡ{}=/p5 ~-JS`W]XkN_L{U6! jgJl>ǻ{=2(=첮>w]q] BGFi<#yϽ!8;jgߩ#SoįV @].@N@)QҴLj"]^eI?/Z1=GK<&0o[ U-h} NHV$wm@[^holb&N!{BQݐGO+S4;p ̗ {d=OA[um8'LV_^]'$%?^v PMSRYπ_12B=< ucp0v|d$Oqn=z:Z삽k@4TpډbⅡ9`nauXӎKZ]ߊ]z=f৿g-2yj"Rc=ul͎S7zg 3?qV6;M*:6@lcD/vcm]C*6}y$2 38whpS.9IkCSC cs~|V^fI<`Yu1g(F~@$4䵝5ȣ$^b_k˔F(d;2fg-.# [Y"KD#vD0a$`0QdM}VdA nU9Q_ 7LA9- lTt#wsB`?JgA3#&$TӴ"Vb!UWsqlE8GcذBR99¯Jm?f05*}Jud;eРM_ԄWc&3I6k7#ZK9(;x?nՙAlȠ)kMRinM(l:Z6N2I36ZS (ejBk>yhȄ{T,JH}*%yUEdqrށ8ͼf,Qsu} lYaztAہ`;(; B}{fy) 2*h3&1cg`8VrNd^|s`Q'|ȁЭ@D~DAl8 _)\4;(GjRĒlT\oTEiNgUG'D-vR,)U jZ˺D.^.rUϟ(NG{;lBe7A,P,H%( T2XSWJ5m162${JwP>۱_3)KymW`l>ChsIiV- V$W{BejKz&ӻ;x_q`Q81O pk"ҁB s7z S!!gKĭG:u&WiaaVcn`&`M[ٛd<{d@P{uӳ$U~]4}f (apSk I$YXj˝ST60 NQzQ>x*JWtڭ"힦x?; x|jϽWNe2&_lQDa\l`I o¤|!/7:Ѽ+ jmߚ2q,ߢH< r7* oVJіr咒Ƀ"/{lZHgֳw 'HD"nV~Ֆgv$9 QD)ÊƺO-+y4XJ bPi$`Bj#cr;<}$Byu/WǢCY;Ri ؖG9]cGO vcn6pstZ\^i3$CY8ͽ1*j;_Z<r=A>c^;4T}䈻o}5AH+ܘ&su +2˥2DB> ]Cj/?NxAA@f JSgS0\=\5簝ik(xWDqE,ܵxɮٲzX~_ fL7➴\VdgCx>] 1y6W!ZHE;cv=e4>_Oϼ=@;8)7lvk}R01*n%>c-$mG״>zHǓbUfwblV~oA .$B6KUfU-=NP`K!?p&1HJi&"5*N(Ryf]/>9vդ U;a^|[k^jD4`۶,▆5}e+OkхuĨrxpʰnt?@V蕆^A/tL;?mh F]|#E=]"1SGA^8:|/yA8{icll>kHEmE=-=%sVKuKz)Lh3O+D23'*l`iz63r鑅.݁adNn"Oz/0%%<]%T8lѦp  &ЗV/JZIG$}&[0nk?wrlDe&"Z~ [Gmجm9RM䪌OqDŽK&6dHLrv5E+!SZN]1D0 b.9cMHnQiL8ksU|=h߉cG:"`Y>Wf<g}!> NB8׍l:pm{RKxs$%ќ$,a}r6Up܄o|!۶P5Dۧ=f!_V9%O`B3 Yx5jdN{)tapR¸B;HE݋Z ËȈy}D:P~5X򲷚Ic|6Au4[Df,xixq 1S 2Ľ9]&Hz<70u,(4ٗX(\>UjP uW/3?>UCԒZjAC.r6*ޔ <;Ff?qz-N%%cgnיPh(S` }._tהF: %ּS#}훝Ḁwbʻ:`?@w*߂g J99"UFhx80ˠRO^\Pt!jǃX=%V}# ;^ЙpF\Pe ^rHC遻nn)eV:F~$.dk) ѡiO@ 3I4&̐Yc4S]PӶz}2t/tڿw" LERu!rM`;(T 8y̳ %#BMia'Ԯ^/wJ@N% fָQ,\g(O^ s/''7!>ڭDx bXQ:.[ GNh֪Y Wpَq~2ٱf߯|\EȊ?S_& A `G)oG1dAeF eElU{'!LG YM/HQ|u勂Dt^fx* L?69E`k{o{=Ty Ŭ=iX !!?z,>sYSDE\b )9gCN+ꦥhD)zD$\`,0Ķ"js{O?]':v̐O3<4jM;΁S?gTtzn!Fh8rgB]r]4D\W|=ZdO#$t ~m3rz;S K;i3PXA+44gA;W E3ou+o#x[zP x JpyQU@CɁ4Z)3eF[_&>DtZU{O:” ".Mpcl$<ԠsJu%6{xɏ+OSj+dzb?_*aƈKL^i~g*t>:O|Q-?H&>է>^7zzb6J'cJ85'.dH7Pa~kd~3,SIy5q7=X5:u0h`%[Ʊۧ+p-ak憞z'@>;lnVƎֶ݂s+VGv帪-FH?J@D(4\.rM:Pp O!hIEb%A南Z5~i2MY-D۴ %(tth<?oQM8Y$׀e1a&|QַPUܗSc1+^q؎/tSVفB^$bc_zrNt{I9tnrݜ mjX*ˎx$n'0ogK2ɍ{@- L?0GaX|.G 5R}#)ZpY]~[ W3{+^KDm4D(*|"0D/bEmZ/Ljsѽ}P_c6=}gkLXE:7ms8ukYR^KGTOʦgHIˆq\Nz m4#Fؐu߭1xާ&=)T& ]}+uH% JtFz}=@7DX#Ŋ= >RJQ<5lFg HcKۖ=S=c|ƶYX+B~Go+H`Ą t7Lix)Fݸ^3{vDj 2 * ׼ch^!08E {/&~JsOI2`,O2*njFXB맷}wZ4puU#9;/G1?<4(Z3XcxWt.!qFAFODFoz[ *=84F@}+pppUM`m +{fLW X/80Im(IS;(0E\=Ad|#РZq}PקxZ|0!z28v;+S5y^i:OJтN$!,ȡ$N{e|OldKMG.|Vb W6Gd^U}%je,/KXAYz.&1AΤtU TeA`[GlBu(Vߜ^m.+5ȨZ0'9Klyŧ6ùjs5/ )]ЁW˚J涜Lu-m;E<0t9RcqH8=""b uvº +w[&cP;2i\Q_a.oOemsXfU]V2xf٠IZt ;/Y Ip7qzfW}(̗~aP"˷"/>!gr`Jiފ:PfGQI5WQJt͐rqpl`f?UUraY6ShsAKC6lbf) /ҵ6 *^᏶;B~k#6A`>:\ s{5"ti=T20/[L/8̌o1ŗ'PVotrsq ٢vkrzaN";8zgLڱ'W?@Q' /I!cG$!6>4Ys3{{#X)/T?z/1%F pdzC\tfش@{qHBWmsX`94Td=pƋ( Fej3(á BXF@P""/My-%F6:Hǐ<!KL͡2r{qbgRP>D ? S cG^̨d6ER 2@nsbienqy(s%H4Fe_Գ'Ϥ~p/yeBco .j$ۊxsW@7h EJ)GF|X ҜRRc=E@N D=NAUE,^ C6us q+F]-Eyw[Mc3M< A ɝ(eT]z>LȊt[q}HqT{O/tJဦ.c"dpf8J<+ڧƢ 'cNkѶ3Q-H 1`Kl?G_A]AbjtJS;A̶q82%-i1OOrwC ڧ)xgA%<>vcͲ]weFX} <˗oj[tVJv|`͈Qr:H4=1?gl{S]ѓ!FDK{1 #7B`I/^وu2`P߅A';͡TApF~) WD\+'gp+gmx#Ճ+F%CnA|Ev3Dga.[% .d_-KlVCPoo \tt'Їh7p|QP%RP% R˚RȺS,Ӻg.{O֛%t=CϜtaiDXB,/\hD KMmQNld츫Ɯ*2ҝWo2{ :|Aʄ["@ߴ7Ld2MG,wDèn< 1Wrצ#s(C~.5Mu8K[?>7fW*4j'ڞr?JJ.:ʻ%427{㴲6N@2ԨP@ zT5H>s :՝̈|frL}]crݎAyWNtztiޱ̝1rw#0MUH%8F+"DnR]Z'%ŹxT-S`p7Z`ADq(bF5dΎ0P!A/ &i}\7\cD8}t%RW FrfeW0AEBȣ.GgrMXH[+LXS0R Oi܃]bPMlm֠N2ZJ[AMV|A)E8@k /Y5$seY4?c߅ub#je4&I(|`[OQK#.a~ZoU{Ug ]S" b*[.a4 ,""c0[`jhkH1N&@v1o-B[:p}'NGM?W=A&!x"g7s *//DwY3kSCyY<*8x0-+]57`_~׷ĩұ p`Vf+bI/@$)xEɓfa;MJ1nHUlpͦ$)L;s_!W ySQNh?KI2?NvI7QťHjC-X xG}Qe6ii Pw۟굿&2Šym!#dXJŒ !RN}`>ѡ92m,ea{%fPׁeDSmFV\kX2 y':_ǯxKWtHM?xsrp4>ZEJݫwTT뒶KASuP$(14blï(ŏyjPbfs_J1A(Eٗ2ë}.s1fz.{W~=+Wc}MtFpz$x^XI-LCt#y3Dp+Flb=iǐfۣc=b^an"E`JŠËs'@ܘeʨ9?_-" t(JiV*ZӄaJ> hاĭ.9i9Oe m]wmkHTfG;RTo+Sn*Ϡ'Ox*Βmk'NR 6J.q>:KDyhs Gl^N~-Xx35 piAhKNAU+eFcOoC1xS6,ޝ.~OXo<,`ul&3:Z jEj ͙Hw™k;@l4Z(S%fW;6Zٽ Ɗm0c{ Cû,nϠ͘Yq7ӋN]W|6# r6;NvN7FDnJ>ryUZ:TRS++lRet`ɦDJ(M<8%4lҭW*hESjc8f}^"V5PKsc~[ 7:8Q2u[\:fYZɚ_ȫ%Q!ULuKۙk|[T4]6ٹI [ m( )CCIbjGm)NJl&Vz=-/!ˎ f4 58n$ nϠU:, ġ{<B=:a= c=צ[{3=j"}dTi)-{$U|_h@y¸Y#))Yx^hȢ"^K@U%3@%h17V-*$w1aJu:$x=( ^3TCEDџzbG$P4$?C{ /tz065Y,gE #'S 8v*Y9I$3nDK0ndZ+ܯx_ؖ/_)XE;MK@>tQ!Up4K0Zk~0A> ^0ZQdI0䰁<-NfdƮ:j&~LxU~/ رKpwѹV2-Zhh?BN2 7]l{xǩkKs9G7K^4kcL#iG*xUDzW/f+xTS=?ԬOⱨ>( O[.H kIî17zXPdr /P7"6Z)+Opwife'e"MAAvm/Wj\fˢ{3!VZOIORǔ)D ցu)bv1Ɨ#(XC4]L;3:7>fn./V<$3d!PȰcgZ$8m~-!#"׹ĔSuYurg5iI>[.x;I~B~WZQ%MݘK5+Z-R2 NveBO.\8B.<Mr@Vv^ߟ q} |WdCJsyjg͝d2y$ދnnYYFvu/TW-2j3W-8m&8s 𤌕@7=0vMa& 뀦}GD3l-0dc=Δk-[…S 1|GAQtvnY[*U$(Z+E;g(/<Yy \*chp$kHя-:D0 ҍhA($:{'׷ˆQf E*b@N6O*Sn:|Aj|ϔ˃qXj+Aj U"VN|H2Foy[c% ;`Vk)|5!!fLk9yw]o5mB6O;Qs mMaC7s@.BzV ]a!0Z^ Mɿ txvh} #uŘsDiz5W\PYXp#=#[Qے }/KlCT3 ÅؚJ*N"tr_/xB.8m/^{(^)f1VwdKߗˋ!jq倹2&`qs=(vn0^ql _MbJ]M묕tgrt=l'O򭧑RLlZdd/ch$L7=$ZSeA ]q3YQϋ*8ZQ-"ɪehq1\ ]Tew0/XH`ѩ:64 U9i K$uUl᤿]!&VH#-򳇎A2e$Ql9'3Ngn6ӂ ~̠hf-^pq;VRЫPAQtT$MĮrP94^Aط*׏nBbW?,\SUP2{'ş(CTx_VgW'_Nw8Sf! 3 EO1I9-0d{4++/xL@9Aigދo&&VSGfޟNŕBo v 1< +FG$~0O4V Iq MN |\cj~"^[$.yF0o-hlU$f=J@g9$VD9R'~~Khqi hЫITA M-O"J (S^4rD w H`+?!Uoǻ#wh6jdKO"MSji4ڋ(4xR[O|oHX3{3a5)vxX >IZ,x2pab.Ɍ>߿InoI% ϔZ9fe?a!)Fj|sbg!s{/  1V_`jx?p( P~GKWHڴ02$9wԊ0ě+V cg fKF,Gn\p_$F`#`~vZ8&NJ hEpB0G۵QO}bBsJ8~F^*]#ɩHLV^oaNܛ*9#0elNWzܡJ ZI%R!U-zʰh$ܑiJj3~䉫`rr=@?Pj|\ҡП`VP/P4CܟWAU>y[SN2NGO=\7teI|m"~ /y: )/mKHW3Ho,Z Vc@5ƥ}꺟u[mmG,Sa/bC\38{j>I9w!iʯ> q,aKW 2tQi9[4mE+}ۂm+䣺 ! _ L/%' oXX40DE읔8ʮz+5Dld~Cb==ZoXhnϺI> O~19n/a%K}tgMJmܞBG|uRd81U崥KT"|p ,#9[XV^/tw\C(,w3r/=7x'F<&ۭ]Tw]k!JgI\g`odk]aqra0Om~/Jmn8e>y|T +A֏5lv+ ‹w,J\Kf7xAT~ۗ# (kD*m#A䶝7 }rzC]بJϯ3o9IzX&j}[UyAuE@~1t-&_ow Z+ Q$e|u),-XHV QUNiBmA.U=L@>6`/wwJ\uFyaf?a)@hĠⲳ$PWCx&g"0d .c`eI>Q$SVkUYUZ䈆klox#9%9e>$ԓlfK^O?@]]ijՖ^O @D)vq^@r=c;q{WMpaWK縇pAhyHYs9([Q8GS><ߓ_y+'Z:mRlc}+By͝Dֶ8yN. \Z~7o,5STs||t?9 ؾ!- M;:ZLSl="G+tQSH 70ɅbSB(Ѧ6#Ik s T?FJ陉_,Zb?'(ݥ=u@ϝ͚.Yk4gp)viaIP o)gVd& zdZKu2Y։'mҞXd5ta3*Xp3p(uHbtpDzqzHzn::x5R$p<ɮIlX쵀WZG"/1 M5ESqLU8GA}9n<@0Woc*ͥ>ӣ\+Dɡ 2+!T P JO9\ࠇ Lbd\6 aK~;vm- o ӰqA]AoaD"_Y"Y N[21~_ `2IX˻Hy\&=@ݣӘfh+ L~ߨ+woz_5qmn1.k.Z;+^3JȁB| jJ̥!LZ8"i=YX~g\ S}O9pq!?a߮|ݪաy@fWsD,[+`J; r"Cܣws呕e5hJ#~bg4+2$Z34zzAmM3Zp>R'ʧt}yT |cYh)MC1bv{,K#CV@Q!) ug% e߇E'y@vR.Ashj#T"U'=8Li>mJ>mOGvD8#"Bri{q4C$*]ac2S_ j۷5xޡFWJM@aW7 K lGc犡L'Nɥw:w~T.-addJa͹ {$a-u&.j®R`FJJy5tgc~S#g#2[M KlYn䥘{iQ)NtTE-3jL ~Se0ix֙+]gPPl%2l ~/.մtrOUQ!΢m\m~z\O[ȀM=8qJ?;*TYŢ']X++ms2Gu4=bnE94 f@9n㎸67{}dffwM/$j/b'}>֯#. (fEa|rAHQ)B?I9=6U`U>7}=@^wY-2S 7jԪ~q_H_#_FǦhl$>ni2=5ӷ l5Wi#|PaxKY~yB+%y4:@ Ƽ<'"8QnZL3 . `ك[?lzp+1!n*|,P)YXIlLԼ.7@cD܇GKXls ZDž ߵL6A"\P(脨R.6ǘ߻繛xTY"nVuPv5ڸN>V'IVX48G |a I\NB6(+A2C7C1]^GIN9Le"VFfK`LɰFtιjMgI;_jDM􅚊MbҪ6RǗz:j̠bXRѤ!4iNOǴҜY1[z[Y o7':l GY`>{+#&/XsfqD;D-Tp"{lӵg22X8jBo1᦬ZebcaWAn}z# q*Pڢ>X๼|S$^dti7v!xNTdžΣM`wy[i8=ZX+[uEbcnn_l\sejW>RZY2{ *BCU73Fq|3942y^! ="xW_"qsOSg7D`f(>&+gNk;Hp[\M'UoK[Tf|Ӯ;fC6yN8Ê$bLm)slTdX' ߥD?#^h1Я/ ma}4,|F&ԏ8/7 Y45+p{1# cѷB?-o.mjrS֌#"~eCOAݤ.LM*YY72*׉g[Q~2+q͖K/$G- T E!{uV̻bQA)cA)nU /UwDNlA+͒^+RLeS eM\[`{ Il` i!6saԗ}$sy 8eЩNIn.g 2yz.@ܻdC4]k[u}bb)z'pԼ<T\^oTlVv,1&8xr'ddOHWmk׍+ψڝHZ1t&ww~1CawT/=/&'Ie2R0s->Qgy'ӱ3D6ڱ5QA^'gW`̤_*3-Y-)QBæ8/!ֈ-J^V"^rW7@FqخbNmG+qMOد Sgow! \km7u2 ~Cv8kҺ|/AJab~j}$MڛOn֕ /tlZ5Xj3*;Hسj5Hi%c!cJ&;5C>}gr <^m$^$(UԀ9v13~4UA"6 ~*lQ~y* C\ [< gd8TݧG4#ri_P_|"[Ad5ӋeЭe_-+'5D ^62)vdU/C7r)u['KM4D6s>LZGp+܁s|*\ss@K-4##TsD/lZ3o 0P\tg~o sM5C͍r{Ci VzL H̤ژ>.͎V`q>.^Nc8Bhޮ^#ۨ/un-bOOV%CuG%*}<HKBhx G'p+H$+*2@~Nپ2j0) ï4v/0'IWZWLC鶱&a7޿C-ʟzYM2=>Lr5{^\0Ơ1d&P8S|ͼܝ#/6¿\ݓ H[_wJaA/9P"  H1CyF?0 q:-UwDlnȎ;`.q&tZ X?wv>4 [3A`9SE"6ԽBNQA˴wE/o-?U9qtG: Lnxx+۟B/hG ;5 !O^P:&(Y9lmq 6Y:y9{^4xg;?l$\ܸ7<_w5"ғh1P^F8;D[f[z|Ph2I/v^k~^*u@{g_WjϢ!?\2zũZT 2w ebpLy>VFRd's,3S/$<} ҿ>{rsnnu6)zFȡtH >ͬazT ;Ǿ{ꑙj,{:8Liq76L#'^1UNq\ 7M%Ԧ׹]GJ^AF7Q %=;!M9,!UMWml`™euܔᛘHkfOC\`S\|ġMJSYR9w\lQ@$7F9ki.w5-X?$]cDbk#^=@6al;GP=s$p!;A,Q7{a*va(]o+*8--.M`=GH;@XT \#'^ u;*ě):圀jÈݛŚ-&/::ZmZ۔vm*"+!{!RBJm7]?T:0RMW^UJNY<(>zb a?}={ h-#>=Wcઈ ZstGS^$51w¬Dqp痿Y>p {u;)?q7cS'&2 4k߼5R"/2zm#q=qjb>Ft% vqJtLiQXy֓Sdxt УJqPa#t.YjFc^kAYj>)ݟYG/I/ ܙJ0hXI!9Y] vY³{տgsU$piQ m0Go'PB6%d9ǑBHu-u"d9'Ù4/PoLp0FT$-PhlL, f6c!AvQ*Wg rLZ-L)Go7f6ܗP#w.6=1EKbtObuSaɨ1I|2ܓ5/م~E+5sU\T$IFm*YdR>񥞜]֣!8Daa1a”,DNT[ ېqmYVwIǘзEHž֚TqdVl7E-t>lUjŚIIe6P\tA nתjgZʎZBă! Pn. z+TpHaA!`镴\b<-pltT]Na ykհeQ+D; ~0mDq<:u^sҧzI{q7 #uW ֨dJHkb=ɵ5+vITݟOt*3%|ٯ+!,xs,X{^c4h;@>2AJ |R1ΜA=fUcn;)yI2զa[2!4^ZdJgdL1|"`JNis~!V/?l!؃OxU}͹ +#wˋzQGkG )B'RiWBet0q2RoJ, ߰uGRwe/\@~w鯰Ѱ+Jj奖]0KhC&:+*Z3PC8u: %zVYKpgl?U6$%oߵ Ӱ+9;l[&P 41¬ qoϊ7/i 1mPuOv 0+>f}|{~B ]_&P0_8=+*Ir"]Lq<+veC2B`BЮS1A2sOb}Lhb$ ~wo+:R,}BHGxO *_hdd%3h 85(cD9uIjۈJ]d=_pm6GN _/*;E jGߌ*{’)N[U~uf U28M76 d3s΃|ޙ4p糄4 dpR0 17=lwBy/0Yw1 p~YQHˤ4R,ao` 3'Z׶ T!&Mx[]oxq @ XՈe. .".+ril& ][(@=4㤝aY Xyԗ"ڏzkG]m^ =D#$͑+ )e0fi-y bY1<(?[5lW']#hY)=Cz}w *J{ѣLɌ*|kAC 7-{͂t2|ٴp5mG7F@fD^fѶ]ާsr^0(!ȡ@Rm(Cf752g4@ 9SN߹wp֣JTo;wA#qfr$֫F3P&$>$|p @jokdޙ'1JhѨ[ є ?Bd$4D:y%H"h7t ˻6Xj8gfQmUd ]lCvLe`ު(̌[ձLB8d<^lf 3iwI%=ߏj<AcIRR j@aПXcT(Ҁ\QTc<u4rK+fbT)ݥ-gGIv<g?!g$fZ.7oz%'Nda'wD^:J E ¯$iaԭ7zhR!8ht?mMr(XA$o:#A$cOeXIV'qE?dU5` H/0$4.1I1Prn\AXQ{$hi-Fa0- IDH+c^́@nM,}(twG_OZIcLj9Jba~a1r)Ã.9.`:ZCoOw$ &zٱ+ t~4}xvJBljaJz ¥ d5".TrS&cjs2ـ n .#lpd$:@J6Ŝӓz& ο(K`*iQ3+x: oZI:Ic~7qwkK֩%Ug0Ip4LxWJ \9)l(N:#J]QdP^r qggYIJ^Z+<ߥbWJoxOcI d3^l&yn(A>28 L8aKutcΨݖɇ|>wyw?4/s9@xIm{5!yR'ɅW3= S l> D "w$ӊ!$BL$% '|ϓșE~*em )D|B˟m샞^r Yωw\IeldR U |*1"TJ~S}KOǴ0t?eqi5rga-1ZB6;DZ|6'Lvȼ,J&7ҩvJE\k(=b.P66.<̀ͪCC-a/e@LсE.Vnrphfj-c,aSyir@]!1hex0|2QÌq_jٞ?p֡p"3P[0$J6SclD o4džZE%T>yhuNmvnLޛ䒲4tV.ȆI BS϶?u12rƉîP{L3$ hgUlSB/{-!M)\=]tY\U,V@=`3ifI5,ؓ/؏@hKTѫk::kBiB\ >*-:iK+@br ^2HPi`82jk0acq85ZBWO(S/1_uk݈2ȍ8"1~x%Ww༪GUԙf?RTlYq{Ѕ׵|ͨO8 _M._WpifU$nxcװeϪ͘Zv7@r4xkOcky|S E<~u~u3?Gw[-U :ₓ7-g#MjoKDcX@o mq!?zToPq~ߔMyz+ *&AO~.$gI3Iv()#3F٣MO,lc~Ѻ[IWj፿hx3BBy!>Th.+,vw7C67P.Bh Sndl=]U]3:}NY;ǿ.q,E9zHwN! q?]dp-,ނC7dϾ|at H+.Ļj0Ew^m^!30x&(v*47ԀpӅsCt|}r;-ȫ.{"a.n+CCc2#z~M"A:!/t ^M7AVمMc|;{?үkY_&hgx (0Y< `/,2O?%MA8 G߹L}DѡgvA=HdZ{Z?YzfwaNG_^Et-ΖXHvT:DaFl(O}<VHCͥA? ǜP`f~>dU nC_pAO<>O5}2IXgڛ )ex}2]X,5W[aJ}D k6qUK*rBsR3w]n:T:%@r-C7e(v}&PMIDBsW [^F2d0BfLQv|}Y_78G$8GcxdD.זXD`>x7FSGz+Zn  b/rAOLK   cf[n7:p!&SXg-6b1R?OND2sh{3KfWzP}F;AZ~e.Ld[5A .0ѹW6@L8?_^>8EgBΆbGEr"ۨ3JC(<̯9@%9dd[xk0| R&yi`/UᝏBOssUC=' =ټc@ vOFXcLō=Lx4Hf`L SG.A]ȸ#G|c> TH&֨Ր籀Ă+QJ}7f35P5B 9=u'|3mqi@C}?ף4$PD1!+Y`WcdSW3-UΗŴi(pfho{)K&tV qRSnSĦ1pzMn&g+T0 T}gyLaF[НÕ LX+QC?Хz';z9tesJ7-R|8LY²l k`%?HrJeN4Cz]sWnlMMͰ>ESQFeZ$ R6Q>R&ˬp|k'H9?Y+*9:Tiݦ,g;wh`;T$re9WUS^͇Z14 \=x27yN%:,!FPp]dJQ(Α};25U1W 6ڤw[#2bϠbtǹNt*aaG oz\oz IaȢG]8e=R{ϋfMZ^nW" ֋'J<Î~!>d>QCH'}p ޟhl>u_5hL2>n%1jwnssA`m@%E$$O&I6``܊7NH)ŰDy>=ۑvJ[׃^]o 5#GTź#|])LY(ݠH̤k>J4'7GBʀ>P├4UwF]|@9cgS g`~ kgQ?ؕަ ]D&䡤zg}Yta-#u+ 5b5"ȥn +\<<`>.FyT5x*ԺYC[fv׊`q7 J89,ecD{PL!6m*xM8(bW6tEt}/uxv7{`cf*`D+IChqjI`*9{INZp?K]?<~8 Uo0M\&4 tR"(#+k5ɵ̖ke9%Ar)z9eB],W}lap=V@ }3 ^Ǧ^K4g #]#K­#J0G=}'cjuam;#;ʷmlrMZ+f~vTE4A\D_'[AE Ch7wV/Û?^ma Q=Vt=λ=ɘ8g*J3K-} tfネ_xL E(ݳSB"[Vڰ.)s鼣?FdYդDٷ*vX#D8㿞@zs~|}"ۡZƬ8`A ~;=k|-w8^^~ hrqQs1:铃(bfR B7O+[$v`ڜAHЊؐ -}JDXzN8yrTU@ t DLrPfQEXa"Oemj_ȥv¹,[jwKL5 C/x'};E\Neec0+w"rE):Hfd7͆w+]H]l֛bMR _k r.B7avUd f77 w8taH1u .]d͛4S0QOFz'6~1˪퍌E0:/2iul:qG+ĎM,Ijy*\3|=K"l~uBźhcGFiлQZbI!-”+@}D`DԸRTز_ ғ-˟oшdw8Pg51hoxA95Kvs,/E6e*sMeqO0֝Jv.=E6hy|ujeUnO2XV$PZʼn7jh[xt݆wX5(_ "+t3%jw E[k +}^N\~׳Xj }+Gg(r~of1``N5l Z?(O?Om[3^t!'u ^Ƚ~@YtfE*f.fT'Pޅؒ5P452ȲN\ | O][Y6b-W'_nhmXL0:4cz5NHeޞ u4H>IWr&&{ԙzZ edص?heӦe d3P-5i`KzeCN#fK{duߍ!1΢9Ch=`PYt{v&*UZk1`e[ZG#Z'eؔMԡX C 4zGE6zyB Jetڎˏ³* onOX2H+ N@hC-hJEvէ(o GKm3v EW뼫JHjǰܘ'Cmܽzu5l~ʖ8^*};^ѢJD(٩ Y4Y=I.L mSH^l^s7A J')ji%) ~'"Aln0۹F̳&GBb$͞[ԏ$Pnʡ>j[`qjx%,.2pӬ8.t;rO+CXxA:m}^ KtB O-)RP][$UKMҔ/l!"6]65sةRD^h1z,Qu#Ȕuc'Ҕ^OKlQF[ƝG pUnDP\Hu]D !ҸqA:dzIù&xKf'!aV8SʪZt;ۑFkd,#cTMY3z㷎 ! %N!t MjjЎ.|ձll+)m͕jX6JbxqUS7G)\ޅgľůum8q 6沽dKثŎ pA\G\!߇FWC +dpRt]56[k<L._/Q(4RRnH-1r(e/\kQaG-(rmh$A᧽j}i Y1:Ӂ"),]GtAgd㤤iqy5O8;:.Gڻ.-I0PikDihmx%"lUS NZNO Uȑ\BƸZ3XO޵|NmvyBo Yc154(~0w(1Xx2#X_x)?$d(k6) ! 0,߽j0 I8,_;G-<7 _ lxhOуdNMȤ=}0Aҡ2M(RSO ٤#BGیs§5AIvSZY'Y}% 6DEUh'5G&\f^>I/oWT_ۜ >F}6 =+~@b',WR ܬ侐w~~ŵ&$:h=z˯- 68.@1^yNdŝ00IޒLƴ4?; k@1nMSzT fa2R:MbAP2%mA5SY8k!JTr ΠͺQ2 ]aSCwOFRP.uIJ3g9Q[sjIx}zgGg3um6xQk(s~/-?3&̛s#*- oNe2b Fa^Vn4"|BOR&b]7aR;T5/5q6w@8j&: `wڐeB7A`<6]{O9P)hk1ۂnc8> [|9~v_A6ЬYCO/ !SC`pRL`;(aՠJ:$, 6Ru `0@l:$68˹yҠŌA& 4CJTaEYi6*>]It FIơ)y5rZ ߱m_`9hH{ V1K8Oj$m*N֟gvOs'X`Fam $kgة>jv%ͨ;xDqg'TQǯ\ͯۖ?=2+,iQN3H /%뜚o8uXyqFYUx}Row0.'.W>"UJ^OnGD0!?\]@1[?=)Įtw'/`6lM02\URY"&V-JNtGB?CAS:t;HHͼ~D(;S*cbpkpnNCJZĘWMS+əxWϻ΁+0pn,TYi\Tv4=~Jy-]Rc^RW`JE$FD]DI$tz ". kiVz7)*\>N?觯C%2ev ɕL>3v~y7o -ݢ EP PK.Ib~Y[}3>m,3- νKP!Go9pd"# nĒAw5SO}6 뗇bbX2G@J[15?nćᐇ >^7Z x6CL_=y1ύ\0>au91}5 ˟ zRRb.ON=n;"I],@o~'3_j&^TpN)EQ =ѩN3uZTkI4g pHR]8 $4O`UvmԙW[pf-eκO}aڃ3iZ^p*e(̮suYtY$T6r>˻(]toe:bvE8M}Tl)9>xA9^̴_`l jʨk/se5eqɩIڮLă|ԽTthJ6ǧ/Y_6@2pCq~I EI2:e»[ZLJ&E.FjG4vU/ˀtb஡[l>p(~k\Us~g_0Td9D?<\ǧyf!P5/cg#a8u\?#}Gh*dNZe"[3,M_{u6k?p Ιyus`{EnGG~r6Y{x=p JNS@Oިqd*9#GvW#!ϩ\.9IDпG]UtB`MbX?O{:{L&FesYx(kYklco=)O {Y&:aIqm2så/H%dZ_NglamhA bTX@ !)TmJ^ݨh]s˕ut?`[KuA>Ɇ=+xDt 0G#aEWFW=/g~KGv- rӗ3=ꍦȖA Lr7PPg1&[FGI;CSQgeA^ Y&K965ԏ&\/]G/$r'b?!TZ.0-쇐1 sN%mrg?hg/'xd$Xo17?0 3N7HUDGRE7=;gP$+[Ǔhnm"UաP"UW@^5 v8xdoXVE߂=$V#;.{uv,TKجe eڄ'{ )Gݮ'.ARxi rVzn#M'a)NoϷLJ ,gH|)FҸ$BJ5g+LJ' <=İ-=ߒ5H(dE\,ⴏtI?U0竢+ysù fA)[9UG&B"oUqz³mAdÄk_"c4ү 1 GQWb;&w#7b`/ MgB%@b?xkdV秮L\ص8[jk @ן4u[+0p༵օmi< ՎȌ7Zeݻ_"U%)TFͫ1SnUfp )I v f)W*YDˠJ2X56鼣>/3ɹL(U.x wgYMj?m4:#]0B^}+/["! Y%y SCw׾!-Ljv[ DR5u 9j2'݁O=6 UA\bZ.0<.9+gQ (i'XŬaM,&,;<9;`,8"TgZ|c#Q.5M=W*c(:N}@2@byZdr`}7Z):`k k lOhRYi< Euzmx:_-8| 5!>6Ig(}u7YfU)˝ cTDݱM-kLEt\.u K63—BTH[vJ,:&4XUn#c}/&wu@mlNu;!GTBÿN?mdyt^ r!\}10񫁶G+0WK|'tOF!T>!)Q{!qt+;ލE 08]%+ "dvw"x0ض#o*k} hƄ<Е S=kyU~d{LVXe9ףPe{.Xe'4 3`vSä|;Pv,l-z"iH롄%qc~)ځ#DBd >dQ/g%B0փJIt|86H=> JMLSeuI–!xtX.e9'{9Ă6ku6"q0L2Xh w/ũ7 #jQzA䍈ve5ߊ|WEyq\L1٢^-Rk!hD}GTΘy%y YTimduȎV(gDF%ˏ`r,NB!>MVC@ܗ Vs%QLP=peZQ6X#k |Hʥ( N=t Cp^spF\ O^pz𣸼zF67PAbǎwD_RrDbk擹g\>M_N H\ 3P6ax1k,w~U=6x uTח/ T3깅jpzrxPqf"5BaBzx l{n[Z2(|+{CnN,, }e n[ &c8K2}?Md[Z{˝:!n1YteE/c?me[U%hÿزJhIܩlciIxXSノ(||YZ-`95|k"ȏ6]QcH2t=kNшcT-bprدR=.ri|y@S\\H?tDy]t6`&̄Sr-rOUEWC/"*r O\ |R_Đx~TJя; 9d;'h`CP$8@^H[*o2l|M/4u}t43hE>+,*HnMX-~s.`1vtV=3 19шaBtD8ͽTCh d͹h?xF25z~CGBkTɜN u7Ev*L`ZEKX:VtQCxmU@U"tm΢}SeĜ9̙+y#݆'ɡ7DĈo[+S%AQu|`AP# ^`MU_,In-Se3ݑAЗ*z(Jw/K.]b1w E*ըr^[ _m k`7H]:9|q$ڻ'\knXPHٝ+W sX]z#0DD'[7RHKԃ@ެԎ]g]-ƭ_6U[pdg'\41`jS0ݗ8hB&8] dD?SPי)egO~,g/)kv+vThrrکxfTR9 >.ӯ$ _56Kk4¸61 [o~Ž.f6,|nRJ`el'"6ap0 ,dk>tC0ߘ*.9C,Govx-kx.bZT=miNgR0=R5K-haVُ/x(E"mHq4|δ^MLc Wb;$,Vpu ̰j)KFۿ%Hn=4zbCA` CgJԕwa?=ȓSz{xt OK1ޔRv Y- -)ӂpnfIulNݿ<{U:XBm74DlE1 ?k?"I,&qЃYuE!}b o6<]Q\掊>uX9]J e+̑1RlO"/-^4)|'ISYloWq&`x)V=Ϋ1Q} l8[=,Uc9Rxy%[GIS+yl!ţ2J̀ɽrjX٠X87E~" {-'0L/g3K58ieUhn{_Ȋ# 5GJn߁ϠBu؁-4N咧 BGFsI , w$G q}-p+8'J U@걭7ڗSs@S>7E7^[}%C9 }$߅(tծ(7ֈhl+HVNrX 31~ kvrTIg""V9Y@ET3WO35 -O'Q2CprA/J龴d;9nOtn:!}L"W@z %sܧ58#yes'p#k vGY`ꝻS *~ j)PC&Eъu`#e>vT-"tU*\Y- ѹӥ(:*sGdr/Srn-O5vuŤ>%jVR<GBŔKh}}=*sun0͉Xk8 I 8 \aB5#; ^=jd^z|(Z)tĶ.WJl^ dti!*,GlmBRBލ G} M,v!ὠ {Slh/T߹;"2k(4/3Ya\!e6($H eo1|_sOeyz @-zRGD[Ҽw,z+E3f\vvM(՗b)ђe4/|~R(/LV_9wJ]~1T JA "l4{Bm 眰ɦs AAsTStϢ>F̙aUՊ26C>ndbRgCN,q8:fq[ĕ8C&#~IoR&R^,viu7GKxhM)?)E*\h"^{)@? +iIڼoU:#v^.d ȗl }wGK nr X32y:j>QRpFY~xg(Vwi>{+$rU&}㹱4QhNt*#pQyk*;DNzMg^o &c!\~pg{ݣNM㒋TB:R^Im'gH՚>uSOfĨf#MacqrH kQNi  63u{I9ư{}lF*Ki&w;L *kgbFK[ ,jRi~~֬Mp#ciVz b\ wRu81B|2t8|q?c%g"g _>[-85滭bI{]˯n̄S>DH,%.ӻ1ܥi ?UQ3 &Kc7OXLpխO() @U]# cJx[G];Ei._}SyNn wf* ,bĻt J+6|nI$\cKYvUΠX`}:([E#TO$-f Ghhx(;Яъd&˄L]_3EN嶧V/<#AD>J`= 22tH<(yY`(7]'cAxZ3Y]P N޵zi?F؋G݄REXEvbNX08z'r#LCm+Rǝ" R fLX|TrɎf"['(pÉț^ z8AǷ)lauI-0Fk1=ekyTeddBu a_p 2~wuf2`HGʹ˲$. !9b{vG~LӪ1/gߏ^k?hlJSIkta axTi}@[;;覭-#re̦X[!vYx4-A%nXt(W$}԰'S;()MηvdG)+x3fE<^%`0eOڒ'Z[~&D#g.}X`ȄboX-DiKlbH&!`E݈ܾDX>R.e46J2 ŗ읐9x1uya?E%uO3;Ǣ'y K0ٴl+f )hTxk7=9rA۫B~/: ᕤIMzn#$ޟ&pRxFa}KD%pARloIDmT*xcة|#gیI\) ɲwwyu:Eȭ)a{!CtףWM52ϰ zܜm_Bw3n@;)~[3:~e|’98M=#"ֽKuٴKuC `Fz+6&uoC-Y6'^UͣkD1tf0~I,j,2(4tkI Qk)ζCKG-CBnjt,0dZNA G|QĂ uAO8 Ҙ-x9I)=9߹t!e%7Y1- P=x`֫YʙwXa.3t L֗6xlz T !&'x!:W:JԖuFGG6;wX Zd "]iEV$%U`ydʼn%c Ճ›gSoeT]<8'@_,fZsS݉vgƱVu7l= CRXqczmrA!yqPeBIhDjnaS=tSR' *e$ fA(YQQQVr"cDi럵02>G7x@r@,#Is@g# _xX@)FCV%xI mʕtā=OXn~O1ر{Z̾cٷ(_(|վbŐk ֺhF$CBC58.5wA YE'#޾۪:v5G2phZ{ ǍU  f ~n|%{b)X98B/RSȀ~O-'BY'39cDJw`$1NͬE' !!,DٱRv 4:0vwp)15xYUn}Lu Q*rT뫨6>Pz TgMX\g˭Q#ߨ͹k%p'  #.5Y&n%m"M5xw.#P4^dM.*Nf`?@CZ E%&Qř ]t:}⹩s-^ش|O:M6o&ـkOo^JSGNCELTb?pOCnPW7(\$=m%ny)dONjb+ FnK*<#VrU-@qVHWA nܣuÍ.Ob}B#  Xgwצ^o/S J#O~vEV0zovw G/014{ȴ s3g+] /pH*ũq9bGk'wHS19cD iﺒV) ׏Z*h_ǐ P4T&/H-)*4,=NljQecgs  NcG |^[mad;Dv`.ӯ+4erATAw{baϴxJJID|&%bjmY7_K* i431Stj(r3WY `Zr|o3 |5wI)P 1⢩ok^9L<%+67f2uim*" /A,_U-<һ뛴cF~Xi&}I$*B@N&@IٞAl.Y;1P&4_?jjn)`*cLA3!!z"\gδ(LnMV>!:DU҅@zs,-HNA@ʪx! ᜝۠bՇ 1q K%{rOCS uHȣjQs~Q+_h_U_GL.,?51=;E5 תn~׉pZBŴĘ* 7ܳߝO|!OgФ:DBH𰠺q#m<|_2tDoffЉU]4uܔh9"dW-Ֆ?fƱ~^u>X3y#|毮^'BH?fjvF]ljߙz JSN:=2ȑ.Y߹ &kDayڰIt7|3-oÄolBa#?;}VUdT·9yG7&F-1\mmzRVyلܷL3&c|i0$ܮd/ԺYjCYƕ>)g0:S:e{eǦ89"_6z%2P䊾ZsvN!!P6Iw] ꨉp Jg-JiB}M? AWw@75nL1GfBTs],W`\@aDR:}К儶rqj0 A؃NA3yD] Ӡva(K]8^//x]CͤL` ThhF i SXW3]Y.dd UɃ 3^?Ui ņ yĘP Rw*-9dO2V}U? |Z\ggBGnVpے{G't$KHFYU X77US%r&yIсXžo eFk XO)\֜#irS8I Yu`U` *?m b9x v #1Jg6_EW #I,Uh4,wm3ܛ*Er f[QZJ?P;i_*=Q'zw7^L0X'/1ʺ !XZd1Tj q78l?s3Zfu>staSޝIMƥʑ(5߀yvZ; J&QHWm+",ЗLߛ&tө/aK1U`f7hD+í hn'}]$9D' !@H.w{U;a#ء[+VP1mM%8#rTݜ<`S8|l*lʇ̔B1rmn4$ < WeE)PmW%hQ#M;&[`\/!6,8Cz:֦6m[HW=vJE)s⩦61-_0>pu(c-ͭD\qcWyA4Gr44ujng蠬-ԍa]jOϰjCFy]ss ==)6]h|.TNIOVx[djzσR%E"`s qKGiz^ςtC%x7x~ƼrgJY^wa \tU.;)~KD-թ_wo$'ᨍ/VaG12M[jVju?҅tjv6>Ŋis@4s䬼jfΩ03[PXJ&0ݪBaNmYGGqW6bEtk :K=\MwuG\lK&ib5">%>u!k&N"ser$闻glTK4&nVh mA4 J[;C=? K-FM¹;Ej[SWxH V:@∳:Lc' vvyɳ޼Zm-O\M㱭[Ud3|Eam~>4 zΔ%%=%j؁vp˩L/HܵL;6^pJ 1 k@Ŧn=YiTQ;EEp/ݽ;{f6T01iK\4:~U޹5y/}XO(FHMw#c&c yFxMOME bAG L[Z*Uԗ 3tFg G*-R~Hx&бzO4;6at.L[qSZH@"syv p-͇m ;_drG͗[*APL^sy HHk7 FL$=R@xU5Qer6}?@rTwDܵ]ETm{M-?)9Sޱ\%WVے=O@P[௎22}:QeQ.hnl~&gs,3\[4g8ۯ)WF_IVcEqs%1Ӆ=W}ڕE<Ϗ{؁}Q{Fhr-|5sq{)ȚȪ[ҫP"g2ߴOFy =yz#WUKݸć> GNA@&t6ֿ| "C Bҳ uD #`8^`';!@M˗k.kFBdY[%6͝S͟O\4 /aYLΰ|گu#_lRs.U/_P*CDɴ75Ll%}3z|;P)ijyOh]qvGI)myu6#9b WT,lJc!Yw 3rW Ue?ڲRCa|]nnia .kBpD{ͫ}#KT3) _T j4_!VZL@:')*2ua?B>I"V9?Z&9He])_P=5kCgȎ"RGHC sfj/n7?JW;SR%R-ɫD r&Ybv77?]_i).:=A%V9TބV(q%W 2ϙnR~,V׌`OVR51yy"GYy9kANȆu&D5 t‹|t t1^4`*fꪄ'^t9 Su.o,88$;M,uװ\t0#gG,@R>k+PAM旌}]&>,,>xN..=+ZK>2E s6^O̻d@A"ۙS0db5Ô!ĕZ`@6в6۸MT򏒖1+NPw0nVs%sT q̡gZ3(k!r 7mQk5U X ncyFYlW8r#+j''x=I6壋:_\kKp}Wʳ^ Q2sꤪ lrsDP0Isf=l EܤVK%hQbdyvFIPK/sL}bE8鐘-U:|GT3Roߚ`PfRL E$FFKȪ7 Ϲ/ns4#e[C 6~X#S7k!%O:!3IK za;+Mځ[73u7;B M$_C "sY*F9H7pUۘ{{O(P;V 3!]ER8LSC]f%a[m:k<{Y8.ô^Bfd FO A:"1ro'*:@X0Vǘt;ߋ䆖MPOǢt{tx1y~1\N,&w] vʺt8噘ϫ)H1 'bFru?+pQINzRh` 1r^ kl`_,WU`lA<Ģ0AAC:' "Be[JP/U{ #9qyFhYӟ @|E"y ANN*Ȳs,7U~(3=c%`Cͩ/ؐ>S|E }3c, 7ZU#A:Z3KBȧCn/F5#m,pkN.4o847Y l]Rx*dV9Ƨ!qfYXҐuΒ)>.67kZ!Asj<2xg/RV9Vg-еn@H'eGt ak^z[R°^8&cWCXNu/Α^IMdCgvuJJ44E6Do|YӊB4m>7OsW('4:K@>)7)7bWwld[':C< G{—$TPPU,ߊx+Ǫi={9k-EpKE;;I)yΡބauNDDՑ't =yIUWOعGӨ$eA9i};=MܡO < 6[%"Q}m~X8(kU&\rζA˵}`qHĨ h֐h\f EH37z5^_qkpmN1'wZWIwYgȞv)۳L^ VR =SZ"'h-<ZP%iH 1r=OtlAp|7^!My2ʙ*US9[!*BGڋy2ʛ -ߡh_9?\dS;gNK)řs:~tm!gbP!!FSTƫ% &Di*sԛ^QC:*߳eai֡AU{RW~K2:xww!5Ӕ֗D &*Q:NsD CiL[~aF8mK DXDI|I.2"|-Q2BSy`h ڙ3CWL89YODQ{[ፅ;rU#^.wW-e差 Jő3$aVm7g(4= NR'/+#gxIH_&n_PߘD\דa]v`xⱗACp 3en תA,ݴGr3x4ͨ!IfRZr<ٕ]Qt6$|L'4 [sœoQ}'q]J|hduĿ³X8ױZd9x8sgq-JxQՂ 3v:~Wynhe#oͅM8nsI83W{@Fm(@ /W_Ή's"O|#JmgDwՃ鳣H NW$,txQ^Y?wt(oUF> zYWKOn}bEmםiX8nKp@6za:b꟎sM}!P~Pc P)dȯ\ctez6 ;]DfFς|4Q5"=mFI(! lrC=ϩ8k Ma-#rk7smK:.ԥAco9!jTдZJ\B6) M ١̶z}C ^t`Cut̻ >uxrq!#4ī+zҍ 4V[uh\MewB&1NrVhXlM1<)w^z`ezQ(B66ʏ!nˍhb#o&){wa$_& ' "jK%⩷ԭ-(`eIJJ $oHvT\z~xQaG./ b?C}C;fdUcj7GkFY┆SKp.'C@ݒ,{Dz*!mކRX$؍;xQĻD(Xul~˃<`l >)XQ W.ⱈnC.R| 2oʍ3̻%q~%V.Z V"&k&$>-^ T(*Tf.Wav /kk,kTd=.~l&g-S(U s҃ernl|1É;&[@l^T 3CF{3&Sg:7f>fo;"zB/05i8kX c, ok۫J{5";kNT>&d.HV LHOj Yw,/w}3hC*ޞlm71r8Wt~ߒtg'4JbDg"#xɇc7&WIN%`s-Qz<;iAqAV[hF,fD 縄9S\uX{gŞ켜ZP-F6}躀'a}}]f~M);] "b{;v) ًbI_F4(yfՔz;8o~83>ibl;WhQb0%8F1ı\(Iz*c몋dZqhڳE}HMbuЩe 5jW]b/m_s{hr*-E#t@A Bىy6j`h N@1v|H?GxHg._gWᏘd " OoUxҒNB,E^94R$_F*ۋ@xέی)(9@c^xں"Z^>iacOв-})0uSj#q([c]>Ťf-^` zLŽث8-ʹ$N$7 LџM 9n.v1{~ &ݶn|RN P~3П[rO5r %Xb]sh,Ƣ)7 j^քX*.ѐG w-u;P&soDYပ$Xl-a+Ɂ%arn+.9qN):ThQ'  6]@hHe֖zyIaߋv\';i6Tm鲀2I\~Tx,/MePFEcT@/ X't&9Wx8SȽYGFV}s(P]^ԞP<߈$e+vz|Tl=D!rח@%~ $Exr L̩l[o-"-S&IAb<2DFoo  ^#p/{':9+>4.8l(.uKCzm슣aӉ?X k yDYSj@ VgJJ={Qܬ_JIB1M|`3Jx_&c &hRUh{(9P48F7w}=,,1TK 0#Q74XFuѽZoRoӎ.| iC{/3G7Ή44 qˋȀ@dY6lZbu?\yApUO obY ]\ IthCj( xt!h"ooׅm27J$&[!9oykPEH^pXh|0_[ݐ)p^ Oe|bHMfy6G}8cƷD2o.xy.J+ |V2^,:ֵ E&R+x} \tdoZ5~Xӎ8 ';-n1ww5}Ȼdwjsٱ_a[9+x88h4'Q5S/H0ׄ0aqO~`\*r$v{ڰ[ؔ>fq1x(tl~vo׫tu9niFYl!YlU!>GS[!tR |5vҷf8g@ISDA$EޏzC1χr>[ne=V5(z{$t8

a̘CLOoͅψ :^#&8m$eIJ$EԲw+bubHTjES*LLRr M&̟$xKPXV/!ax" 7@5+^@q:Pfrx~yxׄOzW>~WKTA̱<} v5,ukS_ /E1ectbL⾭5[P(oq DR9\tԌ;Ŷ>WF /΀q6Zxj<>t h_KFB6w;RtHs60VŅjTbd%+AH%Iͅyml7 +jl筈yD=*J,]#IoM>w܊(MpFj-9!SܧHp%#<7b3Cl7Ὰ*Ļ NlZvʀgBUg`8^X0'vY0hq(ThEj(q\մk/##eo\B&r o tv>[ N|x!&`Ղ>FWȕJ.LNsFIk ,`:b?#fm *J zf1d' 77AaA 8{`S4S՛x_ Eoyapty Щ`6$TG, u>AY&pX摛 b@M̙^!}n0fh]ȌTsB {C׀'"}q_' q`US>*V)Lm>VO>fX[`*d!-HE"vA 1UrQP1CjuUN|6(Fv*bY ^D_,PZ6>+5A@~j'gڳ̈d;T?c`a8.|̿Ckw !ozȁ{ B|> c][ǖ7bm_%J`^藜UL9*½.|!G.,sEY2Y  /o&_ӛ3D4N8@j#^4߮f®ѱV%#~w?)Lih BW=JO6P:f]>R3Ge~ⶹN f^c)}! je#'v 3g/W8y=>Qvg&B&ڰ<4 8 k㸝ۿ7R4g7 p,/[\*#"':"Vz@c_Mφ;lka#2v7CpV3I]7,ca.˧*hFDZbzIK}&gyV3֛0.@@-\n] ¹Xx8e7itp^P\RS(.=;شN+EUӦT1"uvBy*kMڱZ>HޔUz`_ Vc&KNlLr8vP24PTk'Q;5,0-""9+SY@bFF7nژ00Ο;|I:fpOXIΥG뭉O^%1 3ưI-pF^|}rAV̂} _ay߶iG c>F48 o6 |e|0X\OP/sfSs:HunZA^5Fh 'Ӄ4!M`j\Y/,Ecyٔ%1hbO,hl;YBDLg(F+ƐbI)nu*n %bosmXe=X= MDh%,b׿X!lҖ>CB!WpAqJ,6t6EBdi*Uǟ[#ga?6$gS}WB9,\N:=oݫe >_̜p"8IQ^czŢ?EYtEO+dJ~*5G.^wk֪3#cǩlfWle*U 󝣻`Nan%%;{SnXR[kr+'[u<0IN8}:~WrҢc"Pql wMf#&DN2"ɦ(3j߁pmNSB]Y-٪Sί0]ԐSЉ/+u~a# T jEU> R,Kt׻"O)H9- ׉-[|~DJx|"4vN;dտjprQ5L{@qܲ ҔM]W+KtFzCHi\L{d^s ?RcMi x"XځB9C'FOs%3 RV3*a2*iE͈E\LH[w 5[n4&U+Q+76=60nd!d!f'jgi`9 Py}Sx<9wY{mlYgIÞW@x89BU*JKU0Vx7% (}"f9xwzpB{6o&eék418A V8Ax97O0/>uedXӳ?г%Yo~Fv}0h0u~AK>p II0 bg:q)q+*}s׫ǯ-^i5E|F!WxI&<]c1E-wq" nm~xN5#Ry?G'z[mj$L%/2u۪z{G 0miƴ{3ƢZ% (cso)]B SL8igwRI恹r)<-{(]ΉP>\4& @ T흗eoQE~mZ:Z #w5ă & H\ɓ+]XjGz(ED6IpJO[է)٫2SIW(7FѬ.[ݖWY1ȕg Uf@a-XB, _9'q"]zVWԐv]*% "5Gt-ZRNS/ 5Գ^ #@qy*ZY:V=:J|X\5*Gch}KHeOb7 8ZjX/Ǜvw_94>ats%߳S.[Y7?p+`eB̙,&=EaF]@PO}wy0٬]?>2 $L+,(dg(t?>iP-u rm*KvsgtFVz{I #겂}- p;K7x#HwMb>%Br7O%eZٿJl\ò&M [^B\ >\Ņ hi*h>,T^U{0q"Eod.OuԮr7-u!_SS224N/m>?֐SRF $ 7jVPm.fOq 'PѸƍۥYdE6p )!{_'V=LJȑ݌3vŕ`ROK._n!y):j9Hhz:|sbXK{Pw+# 3pl\F"!yPv!-NԺ55x2RH*x\N0v sw1Cn$&1`?xOyˇQE,^wY{ū]3D#/Kfa#8D|/hŶ6Y# +N r= U>=cOAzBY95UvB]bڱڅL 7wAOÝA&p%q4WW:9Z!p='/GVhUHNhu',JӊxJ} F  hIU=ו.NK9Ӥ\ro3x"4 "W"yL*yVO 7 EQK<_ W9qpѕ0+K?ȚlAZ4S5%:@%~D@x!wWnvvw¹jx6,VH Oe}5iWTi?i0oVɑQs!o&M|9E6pW3Z9{ݪ>NN USZt}t#_oѹ݌fiF_΁_^{@E fw! <+J`v/t~w\ѫ C~UyYfyAqMng=#c+w nczг8䚟2r zg:X$DbՊE|Q#{tIc,[j|-?`;s "]x2$ B= i!@ g1ϕ#wrdEo ~Ƿm@Vy>j֬㿑H.UNW~Ő=,l >RG7h'9?9tTjպ 64`$AÞ Pc 0 UhZ>1snOIyM0[`eJ"sU?._Y=ecG,RM܄P_2_b +Khh@*-5u߫S{f7&1$‹p3-4 j{U_ "at~U>XwCPwzևG `b*' ^ubm*<"rY`9#dx\y_9^@Lul| ȮhJi.B}ׂܞ~Ԃ-d,οx<}8Ci!\笠90D\857%hHpdph$PIen`HΆw¸=p߷ Dj*h'Ǫ݊ʗpDO!ND&@UH:01R['uS\oRg8܏S+^V^`8;$$Ae ʄ"V}qC4T!XK_uR9P>a&=}ܡU2gcR}HZ˝[*@e 37QcoDd࢙>~ ⧯?ZqVd^~.} o8kF\8iNܑP1m=.kژӧ=p8`>-Hy 7vf|bx;fbc-CH> !x_@7H<0nNR,-1ՈTNJJ"m+ ,rJ p <\ mCIOS/ \?=ܫՓ{`أU}?U]9Hk7ZQMćxU<IJԱxƉ3[ssTH%[n5#0i?lQr {ʚG-WO"mf&.ŠoHt/ŁK} UV=H5XY:Wsd)Z~M)r:NIe8Ah(0dUwgB&*bO* K!4HMPVOο0] ߅CAK?i8`po[um@A| q~S8kCHz?*<4 8ŝugŬY%RI=;pց[UP~)!ep_'Q^a᙮UX*X\;9 %hRYԝLK ה'_ ,#< RWhz*Udd)\_ʈt½͏KH@iojBtqiMHZDࣛPkh0rt;IW.I.X:~He7 mEO90J-eRѵ>*9 ^RZUm?t azs3FlĊO_3{ ʅdz8y]m勬Vf\MPGb-O,|%Tҹ䊦ā(*Ɛ VӔQ&!q֢'vunA<}oQ@,!dEQ -D!..ڃzMstX"z۳r}M|soCiP׎AC>ݬ`V?kģ ̄iq ǦOg4:8bP&s3Yϴii՜j9!mY&b=Tw΃q՛f|lNX+j z8vF*0ts.Qר[(=6u|]bH5/PcȕO-g.@ssP %BM}Sm.}Xd#¤nL8ᢔYMBEǿ|Xh'lkz6~jk.FRK*$z$BؙcO/"TPGc|AP b\u9`ԙN.4 ǩG~tR+%bcE,np>>&sg~5eE&$8Sd>\ [%DD^*&ǫl t,e\;۬V(kl~QSꃫ>G)(#e!0;{6BHI(^]{Dijg}ë6JGBARKXF872[H]'>[|JTDVp``A&I 9 E=wJ="0e5{le O%;&~[ DGgɈI옐mԢY^Ȫe4jZJ5r|;&]v'(/%jYy1v1v9=B5~&ʾV|~ 5:Dij}3pGVAz̉8T<abe 4{V0QF @[E%X9 yaFt+>̽g es"]W{qGð_?~PqD֩cm:_)7D- (0MJނRڲes@|9[;Q2Y Ϯzџјÿ؃טiyTDar bC ($KDE<]3JK\fIuw dʞbpwrXF7!SNUԿWgGϺ's]iGލ"tž.}9rUe'w"٘q4}?1ǯ̈́*(߸q.v][,V<98]ѝMj;Q0Z-H DӎzqޟxNmBj,;#QWHqjr{)!c"`r7 |@: IGv cCHg aZ.:36oT×`b'YNVoܣI*Ӊ_9 Vkf\Ͷ+d UNb<!'dUr;G3BcfBjZi)OxfvWi~]"C" ,H< o .|6jVσ*9L;r{?T}ZXrE 1~@rcmT×?6ݫ\vϷ%9 im3 Y'?Šsor\B8+@TU#4I޷%9Kݡ^.u3Қp;}$PpʱExM(= $9Nv Pik=?;j* A&}Gq5?(V>S,Q`#.؀wmEɼSsr;MG*JJ)nhsEeWq uџϢE7$QcYM{%)"ĖG/۷TlNV[ !y*9d ,^žg8!G8v 0k 4HhhOIP8f|IX ZDT^ Nz.ABr,J6gix;<#D>@EQ mUrdyݷm_4@ 3;7=l +:q'6w*&[AnIng8ֽ|v yBxTFg73WGxU$&l)#a◨ږEl, sҰZXH*BږgK0T%"`$܎np[:8rש " !>2J9L/9 cj,h DQ "u>}V+>p 9ynI/ZrpV4}:~\)E#$~hdA؂Tv,aYD;?A$@\(xxkl-x6,VlP*킍lɿR%x 6z37D`|aHSvA)"KyywDeR%O<\,vӓقĜ0o꣢4iWR1 L.*JbN kIc٠ui&F [cY'f>X XbMh)ВNڥIgFMx)PR 4PZŢ*v/VO-˧s2$^0j4IxJ2; erBEhOƐ^Ԕ(*,v"#_6ps`ٍ6s)a`PlR.;JL SY?m*}zS)?h2,SA㱭!жwwo WDjOۇ;4pQfʠk.z(]PCf55\wFOX5!#1б0W^hr<+T x1ۜ63}swCML>̄Q%,w`KIM/T{{[wG(I1Z_"XgRb[9x6M}n&x"B)kh RpbR#:)pP "@207RUIl1dEo CA1k/oPusOV^-n"eۢ *'dϸĊ'd60LsòG-v5܌26}ƕ4|0; U_H"7o1"ʆfo\43Phg9"B0 ^:eh.d68upz * ۚ۳5+k_ߞ`J>Ш<:Ȃ:'e^E%g!j*}'g|;/yٖ qOߊm)8مS(DX.o7ì"b5z=XRBRo2ýg$xj5v o]ױv 7٭Ȱ|zJF&9 vF !p찃3fg]O "3]L p#XPii~+hK? ˶nSwbU/lnap7:@qtq݈Гm1Wo k^Dٟ^#EN/WzwCt lpҴP0,_Yh,OM>C,_^wZkd+ PGLϿu٦[ru3'Ӓ6t@\yr6&'jOLMG]Z+} qx؋6+⵱rjT#e' dǻZ'P4Efwgxp--wQx 'EgTۄ(i~oًX@HrUL Oy*cAȈױ^ ȉV 9鰹)bϬlY!A|Ciӿ:mPW;VMyS٢1^S v]0} BFiûWUzWs]$}~D7%"%mR>6iB3 Z-圩u6n:K%q}9ɟI3dUvPg]HJT w'u}qKb.mIs#4:G ",ӱz"}6*DRyWb.`"U.J>ۢDzuːr"ĻTqR?ȉ?pf^49l>ѸZͪ$bçҦjs?A *N+E}fR(V{) m!d\V{&8\p=vM,V%,΋ %$nbbTY]pd琜e'bB/jTNet(DiTz8+~0C]1?i3E'p̃$<ݓ_'m80 6zbB|44*~ғfFF P To/&H]6'ڥػ2OF$EN shC7R9&H/)B3WOSG葼"z S"iJewu:^Mv?f;xUD: ׹yY5K(lK&HEQųIA_p; jTb}E-,-7L{u"X Ύϛɟ_͒ Kpd\މ+zxܰd/4tEψ'-@[c[rG$ᱩB\]13M B7\JPLu(a|is#3,pTOR0n+'MU4qPQ1;X=zr6MH6ӝA4pHU/ǔ Zy{^g6J9A`KL%ֈw&0Ur./2èuzJZIs%Ud jRy W] &YYtSTTԓUke ֯;K}Tuq/mLYE TFputoy w?fJBAzyպ@ x4]>T,d[೏}T[S0H=czi!Z/b6/A]NΊJIԽp95[AV >Л8G?@e$myZTfP c_&U| 1pҮ4|IH*򬤕IJ.@NC;CLC/x'!\>m>#3Ǫ*#e(xgfzQw%e'P_TQ%W~;`v3apv\KBgÀ[.h94~<X/k`d@ōĹ;//l䱹j"b7\'GWD^YK"]*9rD[E5v;7Yerj)]Q4{N^*h l+?ک Yh612O?{mj /f ;$ivY,+A(f` V6Nҳ|?izeYcb 1)X5q8?kr괘gFXCUkZ影R|b'L;iF.aX[qM2bp1 9"l7qJ %p;|PtV)c 1Ƶ|ݚSƪ*vQP8RYZ83סu#aStPT^)$в|nk< 59๐@C!1DvJBKГ4جڣ}dϨ`v+1`x+(4DPei1 >Q{s6X*>:hF8&{dd0&ԳXi1TvaVBVYf$+Xb'u =6E8;f#B((ʼnU7_0a[١b"X7*qjaG#zʳSY1.Ȱ>, @,Fҿu0j{8%}7Q}ziet(fBQkk ]Ը*/l/aI"- [0,6Xu V3TZr5TT>KRWUՄi:a5 aC] p|:rXvjvdė˦AA4Vf-ن<6[*2.UaŬ&Zf8 |K .Դ?Szu~_m:l]a%@wpOVڶO)AMcGlac#ph<2ѳH{b .1Q]״ !ṱڏEH#/mu'wtUSw`+9_d+m) ,<27^G%c`6S } ?vT'|W,#Ӥ㇨M?(XbGgO4\ȼA fK8 qt[JupnPVtUr%{]·sm\+bq~O@ a]W%ֹTM4&IcNl\UFiї# DWRZ淅"~;yC&MQ'T(Yo?p2 ~P"7(hK3 (H'h;tQ\OkHEe0p ]߾C3Ո7xX ,\X>@ 5i;C˕s{XG¨QXLC<ؤ*?4EV/ţ1Z(q=pW@Kf 6H:GC7 w& QVVJM[k3X?\g7u1!1oav-ZD=5l)`|AxtƸ ]E8-ujo@grY%D@;;=9 Ƅ聂H;Z LX'z*+Jb^2s_*Bځf_@%yurDR%Hgx[]gh+CFz4K/줘d: YZ